------------------------------------------------------------------
--- Changelog.all ----------- Mon May 11 17:05:47 UTC 2026 ------
------------------------------------------------------------------
------------------------------------------------------------------
------------------  2026-5-5  -  May 5 2026  -------------------
------------------------------------------------------------------

++++ python-lxml:

  - CVE-2026-41066: Information disclosure via untrusted XML input
    leading to local file read (bsc#1263254)
    Add patch CVE-2026-41066.patch

------------------------------------------------------------------
------------------  2026-5-3  -  May 3 2026  -------------------
------------------------------------------------------------------

++++ nvidia-open-driver-G06-signed:

  - fix-objtool-warnings.patch (not applied on aarch64)
    * Get rid of "'naked' return found in MITIGATION_RETHUNK build"
    objtool warnings (boo#1212841, boo#1263834)
  - remove again disable-objtool-override.patch

------------------------------------------------------------------
------------------  2026-5-1  -  May 1 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - crypto: authencesn - Fix src offset when decrypting in-place
    (bsc#1262573 CVE-2026-31431).
  - commit 66d7b47
  - crypto: authencesn - Do not place hiseq at end of dst for
    out-of-place decryption (bsc#1262573 CVE-2026-31431).
  - commit d5fe1c6
  - crypto: authenc - use memcpy_sglist() instead of null skcipher
    (bsc#1262573 CVE-2026-31431).
  - Refresh
    patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch
  - commit 3e7ba77

++++ kernel-rt:

  - crypto: authencesn - Fix src offset when decrypting in-place
    (bsc#1262573 CVE-2026-31431).
  - commit 66d7b47
  - crypto: authencesn - Do not place hiseq at end of dst for
    out-of-place decryption (bsc#1262573 CVE-2026-31431).
  - commit d5fe1c6
  - crypto: authenc - use memcpy_sglist() instead of null skcipher
    (bsc#1262573 CVE-2026-31431).
  - Refresh
    patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch
  - commit 3e7ba77

------------------------------------------------------------------
------------------  2026-4-30  -  Apr 30 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573
    CVE-2026-31431).
  - commit 748d5b2
  - crypto: algif_aead - Revert to operating out-of-place
    (bsc#1262573 CVE-2026-31431).
  - commit 02b8598
  - crypto: algif_aead - use memcpy_sglist() instead of null skciphe
    (bsc#1262573 CVE-2026-31431).
  - commit 28e785f
  - crypto: scatterwalk - Fix memcpy_sglist() to always succeed
    (bsc#1262573 CVE-2026-31431).
  - commit 620f22b
  - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431).
  - commit 429a54b

++++ kernel-rt:

  - kABI: Restore af_alg_{count,pull}_tsgl() signatures (bsc#1262573
    CVE-2026-31431).
  - commit 748d5b2
  - crypto: algif_aead - Revert to operating out-of-place
    (bsc#1262573 CVE-2026-31431).
  - commit 02b8598
  - crypto: algif_aead - use memcpy_sglist() instead of null skciphe
    (bsc#1262573 CVE-2026-31431).
  - commit 28e785f
  - crypto: scatterwalk - Fix memcpy_sglist() to always succeed
    (bsc#1262573 CVE-2026-31431).
  - commit 620f22b
  - crypto: scatterwalk - Add memcpy_sglist (bsc#1262573 CVE-2026-31431).
  - commit 429a54b

------------------------------------------------------------------
------------------  2026-4-29  -  Apr 29 2026  -------------------
------------------------------------------------------------------

++++ iproute2:

  - add netshaper support (bsc#1253044)
    * netshaper-Add-netshaper-command.patch
    * netshaper-update-include-files.patch
    * netshaper-fix-build-failure.patch
    * netshaper-remove-unused-variable.patch
    * netshaper-ignore-build-result.patch
    * netshaper-fix-grammar-and-style-issues-in-man-page.patch

++++ sssd:

  - With the 2.10 update sssd runs under unprivileged user which is
    not possible in certain scenarios. This update reverts to run as
    root with minimum privileges; (bsc#1259436); Add patch
    0012-run-as-root.patch
  - Let krb5 child tolerate missing capabilities; Add patch
    0013-KRB5-let-krb5_child-tolerate-missing-cap-set-id.patch
  - Add support for UsrEtc; (bsc#1257643); Add patch
    0014-UsrEtc.patch
  - The default configuration file is installed now in
    /usr/etc/sssd/sssd.conf. It can be completely overridden by
    manually creating the system specific config file
    /etc/sssd/sssd.conf, or partially overridden by creating config
    snippets in /etc/sssd/conf.d/ directory. Check sssd.conf manpage
    for more details.

------------------------------------------------------------------
------------------  2026-4-28  -  Apr 28 2026  -------------------
------------------------------------------------------------------

++++ ipmitool:

  - Fix bad pid file creation in ipmievd by removing the interface
    number from the file name (bsc#1259310)
    A fix_pid_file.patch
  - Use manual service instead of localonly

++++ nvidia-open-driver-G06-signed:

  - update CUDA variant to 580.159.03

------------------------------------------------------------------
------------------  2026-4-24  -  Apr 24 2026  -------------------
------------------------------------------------------------------

++++ mozilla-nss:

  - update to NSS 3.112.5
    * bmo#2033783 - reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max.
    * bmo#2034185 - update to version 2.84 of builtins module.

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 580.159.03 (boo#1262749)

------------------------------------------------------------------
------------------  2026-4-23  -  Apr 23 2026  -------------------
------------------------------------------------------------------

++++ nvidia-open-driver-G06-signed:

  - disable-objtool-override.patch
    * get rid of confusing objtool warnings (boo#1212841)
  - -> from https://github.com/joanbm/nvidia-470xx-linux-mainline

------------------------------------------------------------------
------------------  2026-4-22  -  Apr 22 2026  -------------------
------------------------------------------------------------------

++++ libsodium:

  - Drop libsodium-CVE-2025-15444.patch, merged upstream

------------------------------------------------------------------
------------------  2026-4-21  -  Apr 21 2026  -------------------
------------------------------------------------------------------

++++ opensuse-migration-tool:

  - Update to version 20260421.e72b645:
    * Update ports temp repo url for Tumbleweed

------------------------------------------------------------------
------------------  2026-4-20  -  Apr 20 2026  -------------------
------------------------------------------------------------------

++++ haproxy:

  - Update to version 3.2.15+git64.0fc44b458:
    * BUG/MINOR: hlua: fix use-after-free of HTTP reason string
    * BUG/MEDIUM: mux-fcgi: prevent record-length truncation with large bufsize
    * BUG/MINOR: sample: fix info leak in regsub when exp_replace fails
    * BUG/MEDIUM: samples: Fix handling of SMP_T_METH samples
    * BUG/MINOR: spoe: fix pointer arithmetic overflow in spoe_decode_buffer()
    * BUG/MINOR: resolvers: fix memory leak on AAAA additional records
    * BUG/MAJOR: slz: always make sure to limit fixed output to less than worst case literals
    (bsc#1261626) VUL-0: haproxy: bug in SLZ compression
    * BUG/MINOR: peers: fix OOB heap write in dictionary cache update
    * BUG/MINOR: hlua: fix format-string vulnerability in Patref error path
    * BUG/MINOR: hlua: fix stack overflow in httpclient headers conversion
    * BUG: hlua: fix stack overflow in httpclient headers conversion
    * BUG/MEDIUM: jwt: fix heap overflow in ECDSA signature DER conversion
    * BUG/MEDIUM: payload: validate SNI name_len in req.ssl_sni
    * BUG/MINOR: http-act: fix a typo in the "pause" action error message
    * BUG/MEDIUM: mux-h1: Disable 0-copy forwarding when draining the request
    * DOC: config: fix ambiguous info in log-steps directive description
    * BUG/MINOR: cfgcond: fail cleanly on missing argument for "feature"
    * BUG/MINOR: cfgcond: always set the error string on openssl_version checks
    * BUG/MINOR: cfgcond: properly set the error pointer on evaluation error
    * BUG/MINOR: quic: fix documentation for transport params decoding
    * BUG/MINOR: tcpcheck: Use tcpcheck context for expressions parsing
    * BUG/MINOR: tcpcheck: Don't enable http_needed when parsing HTTP samples
    * BUG/MINOR: tcpcheck: Remove unexpected flag on tcpcheck rules for httchck option
    * BUG/MEDIUM: mux-h1: Don't set MSG_MORE on bodyless responses forwarded to client
    * BUG/MEDIUM: map/cli: map/acl commands warn when accessed without admin level
    * BUG/MEDIUM: ssl/ocsp: ocsp commands warn when accessed without admin level
    * BUG/MEDIUM: ssl/cli: tls-keys commands warn when accessed without admin level
    * SCRIPTS: git-show-backports: list new commits and how to review them with -L
    * MINOR: mux-h2: report glitches on early RST_STREAM
    * MINOR: stconn: flag the stream endpoint descriptor when the app has started
    * BUG/MINOR: stconn: Always declare the SC created from healthchecks as a back SC
    * BUG/MINOR: quic: close conn on packet reception with incompatible frame
    * CI: github: fix tag listing by implementing proper API pagination
    * BUG/MINOR: acme: fix task allocation leaked upon error
    * BUG/MEDIUM: acme: skip doing challenge if it is already valid
    * BUG/MINOR: http-ana: Only consider client abort for abortonclose
    * BUG/MINOR: config: Properly test warnif_misplaced_* return values
    * BUG/MINOR: acme: permission checks on the CLI
    * BUILD: tools: potential null pointer dereference in dl_collect_libs_cb
    * BUG/MINOR: acme/cli: fix argument check and error in 'acme challenge_ready'
    * BUG/MINOR: acme: replace atol with len-bounded __strl2uic() for retry-after
    * BUG/MINOR: acme: free() DER buffer on a2base64url error path
    * MINOR: ncbmbuf: improve itbmap_next() code
    * BUG/MEDIUM: spoe: Acquire context buffer in applet before consuming a frame
    * BUG/MINOR: acme: fix incorrect number of arguments allowed in config
    * BUG/MINOR: acme: wrong labels logic always memprintf errmsg
    * BUG/MINOR: acme: acme_ctx_destroy() leaks auth->dns
    * DOC: config: Reorder params for 'tcp-check expect' directive
    * DOC: config: Add missing 'status-code' param for 'http-check expect' directive
    * Revert "BUG/MEDIUM: mux-h2: make sure to always report pending errors to the stream"
    * BUG/MINOR: acme/cli: wrong argument check in 'acme renew'
    * BUG/MINOR: acme: wrong error when checking for duplicate section
    * BUG/MINOR: acme: leak of ext_san upon insertion error
    * BUG/MEDIUM: acme: fix multiple resource leaks in acme_x509_req()
    * BUILD: sched: fix leftover of debugging test in single-run changes
    * MINOR: mux-h2: assign a limited frames processing budget
    * MEDIUM: sched: change scheduler budgets to lower TL_BULK
    * MEDIUM: sched: do not punish self-waking tasklets if TASK_WOKEN_ANY
    * MINOR: sched: do not punish self-waking tasklets anymore
    * MINOR: sched: do not requeue a tasklet into the current queue
    * MEDIUM: sched: do not run a same task multiple times in series
    * BUG/MINOR: qpack: fix 62-bit overflow and 1-byte OOB reads in decoding
    * BUG/MINOR: sock: adjust accept() error messages for ENFILE and ENOMEM
    * BUG/MINOR: mworker: fix sort order of mworker_proc in 'show proc'
    * [RELEASE] Released version 3.2.15
    * CI: github: treat vX.Y.Z release tags as stable like haproxy-* branches
    * BUG/MINOR: mworker/cli: fix show proc pagination losing entries on resume
    * MINOR: mworker/cli: extract worker "show proc" row printer
    * BUG/MEDIUM: h3: reject unaligned frames except DATA
    * BUG/MAJOR: h3: check body size with content-length on empty FIN
    (bsc#1262103) VUL-0: CVE-2026-33555: haproxy: Request smuggling via HTTP/3 parser desynchronization
    * BUG/MINOR: mux-h2: properly ignore R bit in WINDOW_UPDATE increments
    * BUG/MINOR: mux-h2: properly ignore R bit in GOAWAY stream ID
    * BUG/MEDIUM: peers: enforce check on incoming table key type
    * BUG/MINOR: mworker: don't try to access an initializing process
    * MINOR: debug: opportunistically load libthread_db.so.1 with set-dumpable=libs
    * MINOR: debug: copy debug symbols from /usr/lib/debug when present
    * DEV: gdb: add a new utility to extract libs from a core dump: libs-from-core
    * MINOR: debug: read all libs in memory when set-dumpable=libs
    * MINOR: config: support explicit "on" and "off" for "set-dumpable"
    * MINOR: tools: add a function to load a file into a tar archive
    * MINOR: tools: add a function to create a tar file header
    * DEV: gdb: add a utility to find the post-mortem address from a core
    * BUILD: spoe: Remove unsused variable
    * BUG/MINOR: spoe: Fix condition to abort processing on client abort
    * BUG/MINOR: mjson: make mystrtod() length-aware to prevent out-of-bounds reads
    * BUG/MINOR: stream: Fix crash in stream dump if the current rule has no keyword
    * BUG/MINOR: proxy: do not forget to validate quic-initial rules
    * BUG/MINOR: http-ana: Swap L7 buffer with request buffer by hand
    * BUG/MINOR: h2/h3: Never insert partial headers/trailers in an HTX message
    * MINOR: htx: Add function to truncate all blocks after a specific block
    * BUG/MINOR: h2/h3: Only test number of trailers inserted in HTX message
    * BUG/MEDIUM: spoe: Properly abort processing on client abort
    * BUG/MINOR: spoe: Properly switch SPOE filter to WAITING_ACK state
    * BUG/MINOR: sockpair: set FD_CLOEXEC on fd received via SCM_RIGHTS
    * BUG/MINOR: mworker: avoid passing NULL version in proc list serialization
    * BUG/MINOR: mworker: set a timeout on the worker socketpair read at startup
    * BUG/MINOR: mworker: fix typo &= instead of & in proc list serialization
    * BUG/MINOR: mworker: only match worker processes when looking for unspawned proc
    * MINOR: memprof: attempt different retry slots for different hashes on collision
    * MINOR: tools: extend the pointer hashing code to ease manipulations
    * BUG/MINOR: memprof: avoid a small memory leak in "show profiling"
    * BUG/MINOR: mworker: always stop the receiving listener
    * DOC/CLEANUP: config: update mentions of the old "Global parameters" section
    * DOC: configuration: http-check expect example typo
    * BUG/MINOR: jws: fix memory leak in jws_b64_signature
    * BUG/MINOR: tcpcheck: Fix typo in error error message for `http-check expect`
    * BUG/MINOR: mworker: don't set the PROC_O_LEAVING flag on master process

------------------------------------------------------------------
------------------  2026-4-17  -  Apr 17 2026  -------------------
------------------------------------------------------------------

++++ librsvg:

  - Add librsvg-CVE-2026-25727.patch: Fix denial of service when
    parsing rfc2822. (bsc#1257922, CVE-2026-25727)

++++ python-urllib3:

  - Fix regression in CVE-2025-66471.patch (bsc#1254867)

------------------------------------------------------------------
------------------  2026-4-16  -  Apr 16 2026  -------------------
------------------------------------------------------------------

++++ libpng16:

  - added patches
    CVE-2026-34757: Information disclosure and data corruption via use-after-free vulnerability [bsc#1261957]
    * libpng16-CVE-2026-34757.patch

++++ selinux-policy:

  - Revert OrderWithRequires for openssh-server and systemd
    and move %postInstall to %post as fix until zypper moves to
    rpm single transaction backend by default (bsc#1262083)
  - Add OrderWithRequires for systemd as workaround (bsc#1262083)
    to unblock the product increment bsc#1262083 until a proper fix is developed

------------------------------------------------------------------
------------------  2026-4-15  -  Apr 15 2026  -------------------
------------------------------------------------------------------

++++ mozilla-nss:

  - Added "Suggests: p11-kit-nss-trust" to favor over mozilla-nss-certs
    (Jira: PED-15633)

++++ selinux-policy:

  - Add OrderWithRequires for openssh-server as workaround
    to unblock the product increment bsc#1262083 until a proper fix is developed

------------------------------------------------------------------
------------------  2026-4-14  -  Apr 14 2026  -------------------
------------------------------------------------------------------

++++ Mesa:

  - use gcc15 now for real in order to fix build
  - switch to gcc 15 to fix build error (bsc#1261911)
    /usr/include/llvm/ADT/DenseMapInfo.h:17:10: fatal error: 'cassert' file not found
    Unable to generate bindings: clang diagnosed error: /usr/include/llvm/ADT/DenseMapInfo.h:17:10: fatal error: 'cassert' file not found

++++ Mesa-drivers:

  - use gcc15 now for real in order to fix build
  - switch to gcc 15 to fix build error (bsc#1261911)
    /usr/include/llvm/ADT/DenseMapInfo.h:17:10: fatal error: 'cassert' file not found
    Unable to generate bindings: clang diagnosed error: /usr/include/llvm/ADT/DenseMapInfo.h:17:10: fatal error: 'cassert' file not found

++++ mozilla-nss:

  - update to NSS 3.112.4
    * bmo#2030135 - improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey.
    * bmo#2029752 - Improving the allocation of S/MIME DecryptSymKey.
    * bmo#2029462 - store email on subject cache_entry in NSS trust domain.
    * bmo#2029425 - Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation.
    * bmo#2029323 - Improve size calculations in CMS content buffering.
    * bmo#2028001 - avoid integer overflow while escaping RFC822 Names.
    * bmo#2027378 - Reject excessively large ASN.1 SEQUENCE OF in quickder.
    * bmo#2027365 - Deep copy profile data in CERT_FindSMimeProfile.
    * bmo#2027345 - Improve input validation in DSAU signature decoding.
    * bmo#2026311 - avoid integer overflow in RSA_EMSAEncodePSS.
    * bmo#2019357 - RSA_EMSAEncodePSS should validate the length of mHash.
    * bmo#2026156 - Add a maximum cert uncompressed len and tests.
    * bmo#2026089 - Clarify extension negotiation mechanism for TLS Handshakes.
    * bmo#2023209 - ensure permittedSubtrees don't match wildcards that could be outside the permitted tree.
    * bmo#2023207 - Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag.
    * bmo#2019224 - Remove invalid PORT_Free().
    * bmo#1964722 - free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed.
    * bmo#1935995 - make ss->ssl3.hs.cookie an owned-copy of the cookie.

------------------------------------------------------------------
------------------  2026-4-13  -  Apr 13 2026  -------------------
------------------------------------------------------------------

++++ Mesa:

  - bsc1261998-CVE-2026-40393-nir-Use-STACK_ARRAY-instead-of-NIR_VLA.patch
    bsc1261998-CVE-2026-40393-spirv-Use-STACK_ARRAY-instead-of-NIR_VLA.patch
    * Mesa: out-of-bounds memory access can occur in WebGPU because
    the amount of to-be-allocated data depends on an untrusted
    party (bsc#1261998, CVE-2026-40393)

++++ Mesa-drivers:

  - bsc1261998-CVE-2026-40393-nir-Use-STACK_ARRAY-instead-of-NIR_VLA.patch
    bsc1261998-CVE-2026-40393-spirv-Use-STACK_ARRAY-instead-of-NIR_VLA.patch
    * Mesa: out-of-bounds memory access can occur in WebGPU because
    the amount of to-be-allocated data depends on an untrusted
    party (bsc#1261998, CVE-2026-40393)

++++ cockpit:

  - Add fix-CVE-2026-4631.patch to backport upstream fix for bsc#1261829/CVE-2026-4631

++++ grub2:

  - Fix missing install device check in grub2-install on PowerPC which could lead
    to bootlist corruption (bsc#1221126)
    * 0001-Mandatory-install-device-check-for-PowerPC.patch

------------------------------------------------------------------
------------------  2026-4-10  -  Apr 10 2026  -------------------
------------------------------------------------------------------

++++ libcap:

  - CVE-2026-4878: Fixed a a potential TOCTOU race condition in cap_set_file() (bsc#1261809)
    0001-Address-a-potential-TOCTOU-race-condition-in-cap_set.patch:

++++ qemu:

  - Update to version 10.0.9:
    Full backport list:
    https://lore.kernel.org/qemu-devel/20260318045608.7E1B513DFF6@think4mjt.localdomain/
    Fixes:
    bsc#1259079 (CVE-2026-3196)
    bsc#1259080 (CVE-2026-3195)
    bsc#1258509 (CVE-2026-2243)
    A selection of them is reported here below:
    hyperv/syndbg: check length returned by cpu_physical_memory_map()
    fuse: Copy write buffer content before polling
    target/loongarch: Avoid recursive PNX exception on CSR_BADI fetch
    target/loongarch: Preserve PTE permission bits in LDPTE
    hw/net/npcm_gmac: Catch accesses off the end of the register array
    linux-user: fix TIOCGSID ioctl
    tests/tcg/multiarch/test-mmap: Check mmaps beyond reserved_va
    bsd-user: Deal with mmap where start > reserved_va
    linux-user: Deal with mmap where start > reserved_va
    hw/net/xilinx_ethlite: Check for oversized TX packets
    virtio-gpu: Ensure BHs are invoked only from main-loop thread
    block/nfs: Do not enter coroutine from CB
    block: Never drop BLOCK_IO_ERROR with action=stop for rate limiting
    block/throttle-groups: fix deadlock with iolimits and muliple iothreads
    mirror: Fix missed dirty bitmap writes during startup
    block/curl: fix concurrent completion handling
    block/vmdk: fix OOB read in vmdk_read_extent()
    hw/net/smc91c111: Don't allow negative-length packets
    io: fix cleanup for websock I/O source data on cancellation
    io: fix cleanup for TLS I/O source data on cancellation
    io: separate freeing of tasks from marking them as complete
    target/i386/hvf/x86_mmu: Fix compiler warning
    hw/i386/vmmouse: Fix hypercall clobbers
    tests/docker: upgrade most non-lcitool debian tests to debian 13
    hw/9pfs: fix missing EOPNOTSUPP on Twstat and Trenameat for fs synth driver
    hw/9pfs: fix data race in v9fs_mark_fids_unreclaim()
    ...
  - Add support for AMD-Turn CPUs (jsc#PED-13174)
    * target/i386: Add support for EPYC-Turin model (jsc#PED-13174)
    * target/i386: Update EPYC-Genoa for Cache property, perfmon-v2, RAS and SVM feature bits (jsc#PED-13174)
    * target/i386: Add couple of feature bits in CPUID_Fn80000021_EAX (jsc#PED-13174)
    * target/i386: Update EPYC-Milan CPU model for Cache property, RAS, SVM feature bits (jsc#PED-13174)
    * target/i386: Update EPYC-Rome CPU model for Cache property, RAS, SVM feature bits (jsc#PED-13174)
    * target/i386: Update EPYC CPU model for Cache property, RAS, SVM feature bits (jsc#PED-13174)

++++ selinux-policy:

  - Update to version 20250627+git363.7b84cc7fb:
    * Add missing Nextcloud file contexts (bsc#1261535)
    * openSUSE uses /var/lib/php8 (bsc#1239177)
    * /srv/www/htdocs is DocumentRoot of apache (bsc#1261535)
    * Allow snapper sdbootutil plugin read kernel modules (bsc#1259867)
    * Allow named_filetrans_domain filetrans flatpak homedir (bsc#1253682)

------------------------------------------------------------------
------------------  2026-4-9  -  Apr 9 2026  -------------------
------------------------------------------------------------------

++++ cockpit-podman:

  - Update dependencies to fix bsc#1257836/CVE-2026-25547 bsc#1258641/CVE-2026-26996

++++ gdk-pixbuf:

  - Add gdk-pixbuf-CVE-2026-5201.patch: jpeg: Reject unsupported
    number of components (bsc#1261210 CVE-2026-5201
    glgo#GNOME/gdk-pixbuf#266).

++++ kernel-default:

  - powerpc/crash: adjust the elfcorehdr size (jsc#PED-11175
    git-fixes).
  - powerpc/kdump: Fix size calculation for hot-removed memory
    ranges (jsc#PED-11175 git-fixes).
  - commit cfb9cde

++++ kernel-rt:

  - powerpc/crash: adjust the elfcorehdr size (jsc#PED-11175
    git-fixes).
  - powerpc/kdump: Fix size calculation for hot-removed memory
    ranges (jsc#PED-11175 git-fixes).
  - commit cfb9cde

------------------------------------------------------------------
------------------  2026-4-8  -  Apr 8 2026  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update dependencies to fix bsc#1257836/CVE-2026-25547 bsc#1258641/CVE-2026-26996

++++ cockpit-machines:

  - Update dependencies to fix bsc#1257836/CVE-2026-25547 bsc#1258641/CVE-2026-26996

++++ kernel-default:

  - ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
    (CVE-2026-23304 bsc#1260544).
  - commit 51fafb4
  - selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15
    (bsc#1261669 ltc#212590).
  - commit e7cec47

++++ kernel-rt:

  - ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
    (CVE-2026-23304 bsc#1260544).
  - commit 51fafb4
  - selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15
    (bsc#1261669 ltc#212590).
  - commit e7cec47

++++ python313-core:

  - Update to 3.13.13
  - Security
  - gh-145986: xml.parsers.expat: Fixed a crash caused by
    unbounded C recursion when converting deeply nested XML
    content models with ElementDeclHandler(). This addresses
    CVE 2026-4224 (bsc#1259735, CVE-2026-4224).
  - gh-145599: Reject control characters in http.cookies.Morsel
    update() and js_output(). This addresses CVE 2026-3644
    (bsc#1259734, CVE-2026-3644).
  - gh-145506: Fixes CVE 2026-2297 by ensuring that
    SourcelessFileLoader uses io.open_code() when opening .pyc
    files (bsc#1259240, CVE-2026-2297).
  - gh-144370: Disallow usage of control characters in status
    in wsgiref.handlers to prevent HTTP header injections.
    Patch by Benedikt Johannes.
  - gh-143930: Reject leading dashes in URLs passed to
    webbrowser.open() (bsc#1260026, CVE-2026-4519).
  - Library
  - gh-144503: Fix a regression introduced in 3.14.3 and
    3.13.12 where the multiprocessing forkserver start method
    would fail with BrokenPipeError when the parent process had
    a very large sys.argv. The argv is now passed to the
    forkserver as separate command-line arguments rather than
    being embedded in the -c command string, avoiding the
    operating system’s per-argument length limit.
  - gh-146613: itertools: Fix a crash in itertools.groupby()
    when the grouper iterator is concurrently mutated.
  - gh-146080: ssl: fix a crash when an SNI callback tries to
    use an SSL object that has already been garbage-collected.
    Patch by Bénédikt Tran.
  - gh-146090: sqlite3: fix a crash when
    sqlite3.Connection.create_collation() fails with
    SQLITE_BUSY. Patch by Bénédikt Tran.
  - gh-146090: sqlite3: properly raise MemoryError instead of
    SystemError when a context callback fails to be allocated.
    Patch by Bénédikt Tran.
  - gh-145633: Fix struct.pack('f', float): use PyFloat_Pack4()
    to raise OverflowError. Patch by Sergey B Kirpichev and
    Victor Stinner.
  - gh-146310: The ensurepip module no longer looks for
    pip-*.whl wheel packages in the current directory.
  - gh-146083: Update bundled libexpat to version 2.7.5.
  - gh-146076: zoneinfo: fix crashes when deleting _weak_cache
    from a zoneinfo.ZoneInfo subclass.
  - gh-146054: Limit the size of encodings.search_function()
    cache. Found by OSS Fuzz in #493449985.
  - gh-145883: zoneinfo: Fix heap buffer overflow reads from
    malformed TZif data. Found by OSS Fuzz, issues #492245058
    and #492230068.
  - gh-145750: Avoid undefined behaviour from signed integer
    overflow when parsing format strings in the struct module.
    Found by OSS Fuzz in #488466741.
  - gh-145492: Fix infinite recursion in
    collections.defaultdict __repr__ when a defaultdict
    contains itself. Based on analysis by KowalskiThomas in
    gh-145492.
  - gh-145623: Fix crash in struct when calling repr() or
    __sizeof__() on an uninitialized struct.Struct object
    created via Struct.__new__() without calling __init__().
  - gh-145616: Detect Android sysconfig ABI correctly on 32-bit
    ARM Android on 64-bit ARM kernel
  - gh-145376: Fix null pointer dereference in unusual error
    scenario in hashlib.
  - gh-145551: Fix InvalidStateError when cancelling process
    created by asyncio.create_subprocess_exec() or
    asyncio.create_subprocess_shell(). Patch by Daan De Meyer.
  - gh-145417: venv: Prevent incorrect preservation of SELinux
    context when copying the Activate.ps1 script. The script
    inherited the SELinux security context of the system
    template directory, rather than the destination project
    directory.
  - gh-145301: hashlib: fix a crash when the initialization of
    the underlying C extension module fails.
  - gh-145264: Base64 decoder (see binascii.a2b_base64(),
    base64.b64decode(), etc) no longer ignores excess data
    after the first padded quad in non-strict (default) mode.
    Instead, in conformance with RFC 4648, section 3.3, it now
    ignores the pad character, “=”, if it is present before the
    end of the encoded data.
  - gh-145158: Avoid undefined behaviour from signed integer
    overflow when parsing format strings in the struct module.
  - gh-144984: Fix crash in
    xml.parsers.expat.xmlparser.ExternalEntityParserCreate()
    when an allocation fails. The error paths could dereference
    NULL handlers and double-decrement the parent parser’s
    reference count.
  - gh-88091: Fix unicodedata.decomposition() for Hangul
    characters.
  - gh-144835: Added missing explanations for some parameters
    in glob.glob() and glob.iglob().
  - gh-144833: Fixed a use-after-free in ssl when SSL_new()
    returns NULL in newPySSLSocket(). The error was reported
    via a dangling pointer after the object had already been
    freed.
  - gh-144259: Fix inconsistent display of long multiline
    pasted content in the REPL.
  - gh-144156: Fix the folding of headers by the email library
    when RFC 2047 encoded words are used. Now whitespace is
    correctly preserved and also correctly added between
    adjacent encoded words. The latter property was broken by
    the fix for gh-92081, which mostly fixed previous failures
    to preserve whitespace.
  - gh-66305: Fixed a hang on Windows in the tempfile module
    when trying to create a temporary file or subdirectory in
    a non-writable directory.
  - gh-140814: multiprocessing.freeze_support() no longer sets
    the default start method as a side effect, which previously
    caused a subsequent multiprocessing.set_start_method() call
    to raise RuntimeError.
  - gh-144475: Calling repr() on functools.partial() is now
    safer when the partial object’s internal attributes are
    replaced while the string representation is being
    generated.
  - gh-144538: Bump the version of pip bundled in ensurepip to
    version 26.0.1
  - gh-144363: Update bundled libexpat to 2.7.4
  - gh-143637: Fixed a crash in socket.sendmsg() that could
    occur if ancillary data is mutated re-entrantly during
    argument parsing.
  - gh-143880: Fix data race in functools.partial() in the free
    threading build.
  - gh-143543: Fix a crash in itertools.groupby that could
    occur when a user-defined __eq__() method re-enters the
    iterator during key comparison.
  - gh-140652: Fix a crash in _interpchannels.list_all() after
    closing a channel.
  - gh-143698: Allow scheduler and setpgroup arguments to be
    explicitly None when calling os.posix_spawn() or
    os.posix_spawnp(). Patch by Bénédikt Tran.
  - gh-143698: Raise TypeError instead of SystemError when the
    scheduler in os.posix_spawn() or os.posix_spawnp() is not
    a tuple. Patch by Bénédikt Tran.
  - gh-143304: Fix ctypes.CDLL to honor the handle parameter on
    POSIX systems.
  - gh-142781: zoneinfo: fix a crash when instantiating
    ZoneInfo objects for which the internal class-level cache
    is inconsistent.
  - gh-142763: Fix a race condition between zoneinfo.ZoneInfo
    creation and zoneinfo.ZoneInfo.clear_cache() that could
    raise KeyError.
  - gh-142787: Fix assertion failure in sqlite3 blob subscript
    when slicing with indices that result in an empty slice.
  - gh-142352: Fix asyncio.StreamWriter.start_tls() to transfer
    buffered data from StreamReader to the SSL layer,
    preventing data loss when upgrading a connection to TLS
    mid-stream (e.g., when implementing PROXY protocol
    support).
  - gh-141707: Don’t change tarfile.TarInfo type from AREGTYPE
    to DIRTYPE when parsing GNU long name or link headers
    (bsc#1259611, CVE-2025-13462).
  - gh-139933: Improve AttributeError suggestions for classes
    with a custom __dir__() method returning a list of
    unsortable values. Patch by Bénédikt Tran.
  - gh-138891: Fix SyntaxError when inspect.get_annotations(f,
    eval_str=True) is called on a function annotated with a PEP
    646 star_expression
  - gh-137335: Get rid of any possibility of a name conflict
    for named pipes in multiprocessing and asyncio on Windows,
    no matter how small.
  - gh-80667: Support lookup for Tangut Ideographs in
    unicodedata.
  - bpo-40243: Fix unicodedata.ucd_3_2_0.numeric() for
    non-decimal values.
  - Documentation
  - gh-126676: Expand argparse documentation for type=bool with
    a demonstration of the surprising behavior and pointers to
    common alternatives.
  - gh-145450: Document missing public wave.Wave_write getter
    methods.
  - Core and Builtins
  - gh-148157: Fix an unlikely crash when parsing an invalid
    type comments for function parameters. Found by OSS Fuzz in
    [#492782951].
  - gh-146615: Fix a crash in __get__() for METH_METHOD
    descriptors when an invalid (non-type) object is passed as
    the second argument. Patch by Steven Sun.
  - gh-146128: Fix a bug which could cause constant values to
    be partially corrupted in AArch64 JIT code. This issue is
    theoretical, and hasn’t actually been observed in
    unmodified Python interpreters.
  - gh-146250: Fixed a memory leak in SyntaxError when
    re-initializing it.
  - gh-146245: Fixed reference leaks in socket when audit hooks
    raise exceptions in socket.getaddrinfo() and
    socket.sendto().
  - gh-146227: Fix wrong type in _Py_atomic_load_uint16 in the
    C11 atomics backend (pyatomic_std.h), which used a 32-bit
    atomic load instead of 16-bit. Found by Mohammed Zuhaib.
  - gh-146056: Fix repr() for lists containing NULLs.
  - gh-145990: python --help-env sections are now sorted by
    environment variable name.
  - gh-145376: Fix GC tracking in structseq.__replace__().
  - gh-142183: Avoid a pathological case where repeated calls
    at a specific stack depth could be significantly slower.
  - gh-145783: Fix an unlikely crash in the parser when certain
    errors were erroneously not propagated. Found by OSS Fuzz
    in #491369109.
  - gh-145701: Fix SystemError when __classdict__ or
    __conditional_annotations__ is in a class-scope inlined
    comprehension. Found by OSS Fuzz in #491105000.
  - gh-145335: Fix a crash in os.pathconf() when called with -1
    as the path argument.
  - gh-145234: Fixed a SystemError in the parser when an
    encoding cookie (for example, UTF-7) decodes to carriage
    returns (\r). Newlines are now normalized after decoding in
    the string tokenizer.
  - Patch by Pablo Galindo.
  - gh-130555: Fix use-after-free in dict.clear() when the
    dictionary values are embedded in an object and
    a destructor causes re-entrant mutation of the dictionary.
  - gh-145008: Fix a bug when calling certain methods at the
    recursion limit which manifested as a corruption of
    Python’s operand stack. Patch by Ken Jin.
  - gh-144872: Fix heap buffer overflow in the parser found by
    OSS-Fuzz.
  - gh-144766: Fix a crash in fork child process when perf
    support is enabled.
  - gh-144759: Fix undefined behavior in the lexer when start
    and multi_line_start pointers are NULL in
    _PyLexer_remember_fstring_buffers() and
    _PyLexer_restore_fstring_buffers(). The NULL pointer
    arithmetic (NULL - valid_pointer) is now guarded with
    explicit NULL checks.
  - gh-144601: Fix crash when importing a module whose PyInit
    function raises an exception from a subinterpreter.
  - gh-143636: Fix a crash when calling
    SimpleNamespace.__replace__() on non-namespace instances.
    Patch by Bénédikt Tran.
  - gh-143650: Fix race condition in importlib where a thread
    could receive a stale module reference when another
    thread’s import fails.
  - gh-140594: Fix an out of bounds read when a single NUL
    character is read from the standard input. Patch by Shamil
    Abdulaev.
  - gh-91636: While performing garbage collection, clear
    weakrefs to unreachable objects that are created during
    running of finalizers. If those weakrefs were are not
    cleared, they could reveal unreachable objects.
  - gh-130327: Fix erroneous clearing of an object’s __dict__
    if overwritten at runtime.
  - gh-80667: Literals using the \N{name} escape syntax can now
    construct CJK ideographs and Hangul syllables using
    case-insensitive names.
  - Build
  - gh-146541: The Android testbed can now be built for 32-bit
    ARM and x86 targets.
  - gh-146450: The Android build script was modified to improve
    parity with other platform build scripts.
  - gh-145801: When Python build is optimized with GCC using
    PGO, use -fprofile-update=atomic option to use atomic
    operations when updating profile information. This option
    reduces the risk of gcov Data Files (.gcda) corruption
    which can cause random GCC crashes. Patch by Victor
    Stinner.
  - gh-129259: Fix AIX build failures caused by incorrect
    struct alignment in _Py_CODEUNIT and _Py_BackoffCounter by
    adding AIX-specific #pragma pack directives.
  - Tests
  - gh-144418: The Android testbed’s emulator RAM has been
    increased from 2 GB to 4 GB.
  - gh-146202: Fix a race condition in regrtest: make sure that
    the temporary directory is created in the worker process.
    Previously, temp_cwd() could fail on Windows if the “build”
    directory was not created. Patch by Victor Stinner.
  - gh-144739: When Python was compiled with system expat older
    then 2.7.2 but tests run with newer expat, still skip
    test.test_pyexpat.MemoryProtectionTest.
  - Removed upstreamed patches:
  - CVE-2025-13462-tarinfo-header-parse.patch
  - CVE-2026-2297-SourcelessFileLoader-io_open_code.patch
  - CVE-2026-3479-pkgutil_get_data.patch
  - CVE-2026-3644-cookies-Morsel-update-II.patch
  - CVE-2026-4224-expat-unbound-C-recursion.patch
  - CVE-2026-4519-webbrowser-open-dashes.patch

++++ libselinux:

  - Backport commit "libselinux: retain LIFO order for path substitutions" (bsc#1261639)
  - otherwise we can not add equivalencies that overload each other
    in the policy (e.g. /srv/www /var/www and /srv/www/htdocs /var/www/html
    in file_contexts.subs_dist would result in /srv/www/htdocs not receiving the right labels)
  - https://github.com/SELinuxProject/selinux/commit/b1802386d2ec6a2767927abef4b99b4575da4085
    * Added patch: 1261639-libselinux-retain-LIFO-order-for-path-substitutions.patch

++++ opensuse-migration-tool:

  - Update to version 20260408.218e5ee:
    * Add support for Leap Micro to Leap migration
    * Add quick start guide for git installation
    * Use .tar.xz for some reason obs service tar fails on 15.6

++++ python313:

  - Update to 3.13.13
  - Security
  - gh-145986: xml.parsers.expat: Fixed a crash caused by
    unbounded C recursion when converting deeply nested XML
    content models with ElementDeclHandler(). This addresses
    CVE 2026-4224 (bsc#1259735, CVE-2026-4224).
  - gh-145599: Reject control characters in http.cookies.Morsel
    update() and js_output(). This addresses CVE 2026-3644
    (bsc#1259734, CVE-2026-3644).
  - gh-145506: Fixes CVE 2026-2297 by ensuring that
    SourcelessFileLoader uses io.open_code() when opening .pyc
    files (bsc#1259240, CVE-2026-2297).
  - gh-144370: Disallow usage of control characters in status
    in wsgiref.handlers to prevent HTTP header injections.
    Patch by Benedikt Johannes.
  - gh-143930: Reject leading dashes in URLs passed to
    webbrowser.open() (bsc#1260026, CVE-2026-4519).
  - Library
  - gh-144503: Fix a regression introduced in 3.14.3 and
    3.13.12 where the multiprocessing forkserver start method
    would fail with BrokenPipeError when the parent process had
    a very large sys.argv. The argv is now passed to the
    forkserver as separate command-line arguments rather than
    being embedded in the -c command string, avoiding the
    operating system’s per-argument length limit.
  - gh-146613: itertools: Fix a crash in itertools.groupby()
    when the grouper iterator is concurrently mutated.
  - gh-146080: ssl: fix a crash when an SNI callback tries to
    use an SSL object that has already been garbage-collected.
    Patch by Bénédikt Tran.
  - gh-146090: sqlite3: fix a crash when
    sqlite3.Connection.create_collation() fails with
    SQLITE_BUSY. Patch by Bénédikt Tran.
  - gh-146090: sqlite3: properly raise MemoryError instead of
    SystemError when a context callback fails to be allocated.
    Patch by Bénédikt Tran.
  - gh-145633: Fix struct.pack('f', float): use PyFloat_Pack4()
    to raise OverflowError. Patch by Sergey B Kirpichev and
    Victor Stinner.
  - gh-146310: The ensurepip module no longer looks for
    pip-*.whl wheel packages in the current directory.
  - gh-146083: Update bundled libexpat to version 2.7.5.
  - gh-146076: zoneinfo: fix crashes when deleting _weak_cache
    from a zoneinfo.ZoneInfo subclass.
  - gh-146054: Limit the size of encodings.search_function()
    cache. Found by OSS Fuzz in #493449985.
  - gh-145883: zoneinfo: Fix heap buffer overflow reads from
    malformed TZif data. Found by OSS Fuzz, issues #492245058
    and #492230068.
  - gh-145750: Avoid undefined behaviour from signed integer
    overflow when parsing format strings in the struct module.
    Found by OSS Fuzz in #488466741.
  - gh-145492: Fix infinite recursion in
    collections.defaultdict __repr__ when a defaultdict
    contains itself. Based on analysis by KowalskiThomas in
    gh-145492.
  - gh-145623: Fix crash in struct when calling repr() or
    __sizeof__() on an uninitialized struct.Struct object
    created via Struct.__new__() without calling __init__().
  - gh-145616: Detect Android sysconfig ABI correctly on 32-bit
    ARM Android on 64-bit ARM kernel
  - gh-145376: Fix null pointer dereference in unusual error
    scenario in hashlib.
  - gh-145551: Fix InvalidStateError when cancelling process
    created by asyncio.create_subprocess_exec() or
    asyncio.create_subprocess_shell(). Patch by Daan De Meyer.
  - gh-145417: venv: Prevent incorrect preservation of SELinux
    context when copying the Activate.ps1 script. The script
    inherited the SELinux security context of the system
    template directory, rather than the destination project
    directory.
  - gh-145301: hashlib: fix a crash when the initialization of
    the underlying C extension module fails.
  - gh-145264: Base64 decoder (see binascii.a2b_base64(),
    base64.b64decode(), etc) no longer ignores excess data
    after the first padded quad in non-strict (default) mode.
    Instead, in conformance with RFC 4648, section 3.3, it now
    ignores the pad character, “=”, if it is present before the
    end of the encoded data.
  - gh-145158: Avoid undefined behaviour from signed integer
    overflow when parsing format strings in the struct module.
  - gh-144984: Fix crash in
    xml.parsers.expat.xmlparser.ExternalEntityParserCreate()
    when an allocation fails. The error paths could dereference
    NULL handlers and double-decrement the parent parser’s
    reference count.
  - gh-88091: Fix unicodedata.decomposition() for Hangul
    characters.
  - gh-144835: Added missing explanations for some parameters
    in glob.glob() and glob.iglob().
  - gh-144833: Fixed a use-after-free in ssl when SSL_new()
    returns NULL in newPySSLSocket(). The error was reported
    via a dangling pointer after the object had already been
    freed.
  - gh-144259: Fix inconsistent display of long multiline
    pasted content in the REPL.
  - gh-144156: Fix the folding of headers by the email library
    when RFC 2047 encoded words are used. Now whitespace is
    correctly preserved and also correctly added between
    adjacent encoded words. The latter property was broken by
    the fix for gh-92081, which mostly fixed previous failures
    to preserve whitespace.
  - gh-66305: Fixed a hang on Windows in the tempfile module
    when trying to create a temporary file or subdirectory in
    a non-writable directory.
  - gh-140814: multiprocessing.freeze_support() no longer sets
    the default start method as a side effect, which previously
    caused a subsequent multiprocessing.set_start_method() call
    to raise RuntimeError.
  - gh-144475: Calling repr() on functools.partial() is now
    safer when the partial object’s internal attributes are
    replaced while the string representation is being
    generated.
  - gh-144538: Bump the version of pip bundled in ensurepip to
    version 26.0.1
  - gh-144363: Update bundled libexpat to 2.7.4
  - gh-143637: Fixed a crash in socket.sendmsg() that could
    occur if ancillary data is mutated re-entrantly during
    argument parsing.
  - gh-143880: Fix data race in functools.partial() in the free
    threading build.
  - gh-143543: Fix a crash in itertools.groupby that could
    occur when a user-defined __eq__() method re-enters the
    iterator during key comparison.
  - gh-140652: Fix a crash in _interpchannels.list_all() after
    closing a channel.
  - gh-143698: Allow scheduler and setpgroup arguments to be
    explicitly None when calling os.posix_spawn() or
    os.posix_spawnp(). Patch by Bénédikt Tran.
  - gh-143698: Raise TypeError instead of SystemError when the
    scheduler in os.posix_spawn() or os.posix_spawnp() is not
    a tuple. Patch by Bénédikt Tran.
  - gh-143304: Fix ctypes.CDLL to honor the handle parameter on
    POSIX systems.
  - gh-142781: zoneinfo: fix a crash when instantiating
    ZoneInfo objects for which the internal class-level cache
    is inconsistent.
  - gh-142763: Fix a race condition between zoneinfo.ZoneInfo
    creation and zoneinfo.ZoneInfo.clear_cache() that could
    raise KeyError.
  - gh-142787: Fix assertion failure in sqlite3 blob subscript
    when slicing with indices that result in an empty slice.
  - gh-142352: Fix asyncio.StreamWriter.start_tls() to transfer
    buffered data from StreamReader to the SSL layer,
    preventing data loss when upgrading a connection to TLS
    mid-stream (e.g., when implementing PROXY protocol
    support).
  - gh-141707: Don’t change tarfile.TarInfo type from AREGTYPE
    to DIRTYPE when parsing GNU long name or link headers
    (bsc#1259611, CVE-2025-13462).
  - gh-139933: Improve AttributeError suggestions for classes
    with a custom __dir__() method returning a list of
    unsortable values. Patch by Bénédikt Tran.
  - gh-138891: Fix SyntaxError when inspect.get_annotations(f,
    eval_str=True) is called on a function annotated with a PEP
    646 star_expression
  - gh-137335: Get rid of any possibility of a name conflict
    for named pipes in multiprocessing and asyncio on Windows,
    no matter how small.
  - gh-80667: Support lookup for Tangut Ideographs in
    unicodedata.
  - bpo-40243: Fix unicodedata.ucd_3_2_0.numeric() for
    non-decimal values.
  - Documentation
  - gh-126676: Expand argparse documentation for type=bool with
    a demonstration of the surprising behavior and pointers to
    common alternatives.
  - gh-145450: Document missing public wave.Wave_write getter
    methods.
  - Core and Builtins
  - gh-148157: Fix an unlikely crash when parsing an invalid
    type comments for function parameters. Found by OSS Fuzz in
    [#492782951].
  - gh-146615: Fix a crash in __get__() for METH_METHOD
    descriptors when an invalid (non-type) object is passed as
    the second argument. Patch by Steven Sun.
  - gh-146128: Fix a bug which could cause constant values to
    be partially corrupted in AArch64 JIT code. This issue is
    theoretical, and hasn’t actually been observed in
    unmodified Python interpreters.
  - gh-146250: Fixed a memory leak in SyntaxError when
    re-initializing it.
  - gh-146245: Fixed reference leaks in socket when audit hooks
    raise exceptions in socket.getaddrinfo() and
    socket.sendto().
  - gh-146227: Fix wrong type in _Py_atomic_load_uint16 in the
    C11 atomics backend (pyatomic_std.h), which used a 32-bit
    atomic load instead of 16-bit. Found by Mohammed Zuhaib.
  - gh-146056: Fix repr() for lists containing NULLs.
  - gh-145990: python --help-env sections are now sorted by
    environment variable name.
  - gh-145376: Fix GC tracking in structseq.__replace__().
  - gh-142183: Avoid a pathological case where repeated calls
    at a specific stack depth could be significantly slower.
  - gh-145783: Fix an unlikely crash in the parser when certain
    errors were erroneously not propagated. Found by OSS Fuzz
    in #491369109.
  - gh-145701: Fix SystemError when __classdict__ or
    __conditional_annotations__ is in a class-scope inlined
    comprehension. Found by OSS Fuzz in #491105000.
  - gh-145335: Fix a crash in os.pathconf() when called with -1
    as the path argument.
  - gh-145234: Fixed a SystemError in the parser when an
    encoding cookie (for example, UTF-7) decodes to carriage
    returns (\r). Newlines are now normalized after decoding in
    the string tokenizer.
  - Patch by Pablo Galindo.
  - gh-130555: Fix use-after-free in dict.clear() when the
    dictionary values are embedded in an object and
    a destructor causes re-entrant mutation of the dictionary.
  - gh-145008: Fix a bug when calling certain methods at the
    recursion limit which manifested as a corruption of
    Python’s operand stack. Patch by Ken Jin.
  - gh-144872: Fix heap buffer overflow in the parser found by
    OSS-Fuzz.
  - gh-144766: Fix a crash in fork child process when perf
    support is enabled.
  - gh-144759: Fix undefined behavior in the lexer when start
    and multi_line_start pointers are NULL in
    _PyLexer_remember_fstring_buffers() and
    _PyLexer_restore_fstring_buffers(). The NULL pointer
    arithmetic (NULL - valid_pointer) is now guarded with
    explicit NULL checks.
  - gh-144601: Fix crash when importing a module whose PyInit
    function raises an exception from a subinterpreter.
  - gh-143636: Fix a crash when calling
    SimpleNamespace.__replace__() on non-namespace instances.
    Patch by Bénédikt Tran.
  - gh-143650: Fix race condition in importlib where a thread
    could receive a stale module reference when another
    thread’s import fails.
  - gh-140594: Fix an out of bounds read when a single NUL
    character is read from the standard input. Patch by Shamil
    Abdulaev.
  - gh-91636: While performing garbage collection, clear
    weakrefs to unreachable objects that are created during
    running of finalizers. If those weakrefs were are not
    cleared, they could reveal unreachable objects.
  - gh-130327: Fix erroneous clearing of an object’s __dict__
    if overwritten at runtime.
  - gh-80667: Literals using the \N{name} escape syntax can now
    construct CJK ideographs and Hangul syllables using
    case-insensitive names.
  - Build
  - gh-146541: The Android testbed can now be built for 32-bit
    ARM and x86 targets.
  - gh-146450: The Android build script was modified to improve
    parity with other platform build scripts.
  - gh-145801: When Python build is optimized with GCC using
    PGO, use -fprofile-update=atomic option to use atomic
    operations when updating profile information. This option
    reduces the risk of gcov Data Files (.gcda) corruption
    which can cause random GCC crashes. Patch by Victor
    Stinner.
  - gh-129259: Fix AIX build failures caused by incorrect
    struct alignment in _Py_CODEUNIT and _Py_BackoffCounter by
    adding AIX-specific #pragma pack directives.
  - Tests
  - gh-144418: The Android testbed’s emulator RAM has been
    increased from 2 GB to 4 GB.
  - gh-146202: Fix a race condition in regrtest: make sure that
    the temporary directory is created in the worker process.
    Previously, temp_cwd() could fail on Windows if the “build”
    directory was not created. Patch by Victor Stinner.
  - gh-144739: When Python was compiled with system expat older
    then 2.7.2 but tests run with newer expat, still skip
    test.test_pyexpat.MemoryProtectionTest.
  - Removed upstreamed patches:
  - CVE-2025-13462-tarinfo-header-parse.patch
  - CVE-2026-2297-SourcelessFileLoader-io_open_code.patch
  - CVE-2026-3479-pkgutil_get_data.patch
  - CVE-2026-3644-cookies-Morsel-update-II.patch
  - CVE-2026-4224-expat-unbound-C-recursion.patch
  - CVE-2026-4519-webbrowser-open-dashes.patch

------------------------------------------------------------------
------------------  2026-4-7  -  Apr 7 2026  -------------------
------------------------------------------------------------------

++++ grub2:

  - Fix double free in xen booting if root filesystem is Btrfs (bsc#1259543)
    * grub2-btrfs-01-add-ability-to-boot-from-subvolumes.patch
    * grub2-btrfs-09-get-default-subvolume.patch

++++ iproute2:

  - fix package for immutable mode (jsc#PED-14787)
    * drop ghost entry for /run/netns
  - add CVE fix (CVE-2024-58251 bsc#1254324)
    * ss-escape-characters-in-command-name.patch
  - add post-6.12 upstream fixes (bsc#1241316)
    * Parse-FQ-band-weights-correctly.patch
    * bond-fix-stack-smash-in-xstats.patch
    * ip-support-setting-multiple-features.patch
    * tc-gred-fix-debug-print.patch

++++ kernel-default:

  - scsi: target: Fix recursive locking in __configfs_open_file()
    (CVE-2026-23292 bsc#1260500).
  - scsi: target: iscsi: Fix use-after-free in
    iscsit_dec_session_usage_count() (CVE-2026-23193 bsc#1258414).
  - scsi: target: iscsi: Fix use-after-free in
    iscsit_dec_conn_usage_count() (CVE-2026-23216 bsc#1258447).
  - commit f1d41b2
  - xdp: produce a warning when calculated tailroom is negative
    (CVE-2026-23343 bsc#1260527).
  - commit 72b74a3
  - bpf, arm64: Force 8-byte alignment for JIT buffer to prevent
    atomic tearing (CVE-2026-23383 bsc#1260497).
  - commit b5b5e19
  - nvmet: move async event work off nvmet-wq (git-fixes).
  - nvme-pci: cap queue creation to used queues (git-fixes).
  - nvme-pci: ensure we're polling a polled queue (git-fixes).
  - nvme-fabrics: use kfree_sensitive() for DHCHAP secrets
    (git-fixes).
  - commit 5ccf382
  - tg3: Fix race for querying speed/duplex (bsc#1257183).
  - commit 4d083ab
  - KVM: arm64: Fix ID register initialization for non-protected
    pKVM guests (CVE-2026-23425 bsc#1261506).
  - commit b02fb9f
  - Refresh
    patches.suse/scsi-scsi_transport_sas-Fix-the-maximum-channel-scan.patch.
  - commit bf87874
  - net/rds: Fix circular locking dependency in rds_tcp_tune
    (CVE-2026-23419 bsc#1261507).
  - commit 2e0e6d2
  - RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() (CVE-2026-23335 bsc#1260550)
  - commit 2c8db95
  - soc: qcom: pd-mapper: Fix element length in
    servreg_loc_pfr_req_ei (git-fixes).
  - firmware: microchip: fail auto-update probe if no flash found
    (git-fixes).
  - soc: aspeed: socinfo: Mask table entries for accurate SoC ID
    matching (git-fixes).
  - commit c6e2074
  - net/sched: teql: fix NULL pointer dereference in iptunnel_xmit
    on TEQL slave xmit (CVE-2026-23277 bsc#1259997).
  - commit 880dba8
  - net/sched: Only allow act_ct to bind to clsact/ingress qdiscs
    and shared blocks (CVE-2026-23270 bsc#1259886).
  - commit 82e8fe9

++++ kernel-rt:

  - scsi: target: Fix recursive locking in __configfs_open_file()
    (CVE-2026-23292 bsc#1260500).
  - scsi: target: iscsi: Fix use-after-free in
    iscsit_dec_session_usage_count() (CVE-2026-23193 bsc#1258414).
  - scsi: target: iscsi: Fix use-after-free in
    iscsit_dec_conn_usage_count() (CVE-2026-23216 bsc#1258447).
  - commit f1d41b2
  - xdp: produce a warning when calculated tailroom is negative
    (CVE-2026-23343 bsc#1260527).
  - commit 72b74a3
  - bpf, arm64: Force 8-byte alignment for JIT buffer to prevent
    atomic tearing (CVE-2026-23383 bsc#1260497).
  - commit b5b5e19
  - nvmet: move async event work off nvmet-wq (git-fixes).
  - nvme-pci: cap queue creation to used queues (git-fixes).
  - nvme-pci: ensure we're polling a polled queue (git-fixes).
  - nvme-fabrics: use kfree_sensitive() for DHCHAP secrets
    (git-fixes).
  - commit 5ccf382
  - tg3: Fix race for querying speed/duplex (bsc#1257183).
  - commit 4d083ab
  - KVM: arm64: Fix ID register initialization for non-protected
    pKVM guests (CVE-2026-23425 bsc#1261506).
  - commit b02fb9f
  - Refresh
    patches.suse/scsi-scsi_transport_sas-Fix-the-maximum-channel-scan.patch.
  - commit bf87874
  - net/rds: Fix circular locking dependency in rds_tcp_tune
    (CVE-2026-23419 bsc#1261507).
  - commit 2e0e6d2
  - RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() (CVE-2026-23335 bsc#1260550)
  - commit 2c8db95
  - soc: qcom: pd-mapper: Fix element length in
    servreg_loc_pfr_req_ei (git-fixes).
  - firmware: microchip: fail auto-update probe if no flash found
    (git-fixes).
  - soc: aspeed: socinfo: Mask table entries for accurate SoC ID
    matching (git-fixes).
  - commit c6e2074
  - net/sched: teql: fix NULL pointer dereference in iptunnel_xmit
    on TEQL slave xmit (CVE-2026-23277 bsc#1259997).
  - commit 880dba8
  - net/sched: Only allow act_ct to bind to clsact/ingress qdiscs
    and shared blocks (CVE-2026-23270 bsc#1259886).
  - commit 82e8fe9

++++ sudo:

  - CVE-2026-35535: potential privilege escalation when running
    the mailer (bsc#1261420)
    * fix-CVE-2026-35535.patch

------------------------------------------------------------------
------------------  2026-4-6  -  Apr 6 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - icmp: fix NULL pointer dereference in icmp_tag_validation()
    (CVE-2026-23398 bsc#1260730).
  - clsact: Fix use-after-free in init/destroy rollback asymmetry
    (CVE-2026-23413 bsc#1261498).
  - net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
    (CVE-2026-23293 bsc#1260486).
  - net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
    (CVE-2026-23381 bsc#1260471).
  - gve: Fix stats report corruption on queue count change
    (CVE-2026-23262 bsc#1259870).
  - commit b9e6af3
  - net/sched: ets: fix divide by zero in the offload path
    (CVE-2026-23379 bsc#1260481).
  - commit d39e420
  - tls: Purge async_hold in tls_decrypt_async_wait() (CVE-2026-23414
    bsc#1261496).
  - commit 2db5b5f
  - misc: fastrpc: possible double-free of cctx->remote_heap
    (git-fixes).
  - comedi: Reinit dev->spinlock between attachments to low-level
    drivers (git-fixes).
  - comedi: me_daq: Fix potential overrun of firmware buffer
    (git-fixes).
  - comedi: me4000: Fix potential overrun of firmware buffer
    (git-fixes).
  - comedi: ni_atmio16d: Fix invalid clean-up after failed attach
    (git-fixes).
  - counter: rz-mtu3-cnt: do not use struct rz_mtu3_channel's dev
    member (git-fixes).
  - counter: rz-mtu3-cnt: prevent counter from being toggled
    multiple times (git-fixes).
  - iio: dac: ad5770r: fix error return in ad5770r_read_raw()
    (git-fixes).
  - iio: accel: fix ADXL355 temperature signature value (git-fixes).
  - iio: light: vcnl4035: fix scan buffer on big-endian (git-fixes).
  - iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()
    (git-fixes).
  - iio: adc: ti-adc161s626: fix buffer read on big-endian
    (git-fixes).
  - iio: imu: bmi160: Remove potential undefined behavior in
    bmi160_config_pin() (git-fixes).
  - iio: adc: aspeed: clear reference voltage bits before
    configuring vref (git-fixes).
  - iio: adc: ti-ads1119: Reinit completion before
    wait_for_completion_timeout() (git-fixes).
  - iio: adc: ti-ads1119: Replace IRQF_ONESHOT with IRQF_NO_THREAD
    (git-fixes).
  - iio: imu: bno055: fix BNO055_SCAN_CH_COUNT off by one
    (git-fixes).
  - iio: gyro: mpu3050: Fix out-of-sequence free_irq() (git-fixes).
  - iio: gyro: mpu3050: Move iio_device_register() to correct
    location (git-fixes).
  - iio: gyro: mpu3050: Fix irq resource leak (git-fixes).
  - iio: gyro: mpu3050: Fix incorrect free_irq() variable
    (git-fixes).
  - iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and
    gyroscope only (git-fixes).
  - iio: accel: adxl380: fix FIFO watermark bit 8 always written
    as 0 (git-fixes).
  - iio: adc: ti-ads1119: Fix unbalanced pm reference count in
    ds1119_single_conversion() (git-fixes).
  - usb: cdns3: gadget: fix state inconsistency on gadget init
    failure (git-fixes).
  - usb: ulpi: fix double free in ulpi_register_interface() error
    path (git-fixes).
  - usb: cdns3: gadget: fix NULL pointer dereference in ep_queue
    (git-fixes).
  - usb: core: phy: avoid double use of 'usb3-phy' (git-fixes).
  - usb: gadget: f_rndis: Protect RNDIS options with mutex
    (git-fixes).
  - usb: gadget: f_subset: Fix unbalanced refcnt in geth_free
    (git-fixes).
  - usb: typec: thunderbolt: Set enter_vdo during initialization
    (git-fixes).
  - usb: dwc2: gadget: Fix spin_lock/unlock mismatch in
    dwc2_hsotg_udc_stop() (git-fixes).
  - usb: gadget: uvc: fix NULL pointer dereference during unbind
    race (git-fixes).
  - usb: ehci-brcm: fix sleep during atomic (git-fixes).
  - USB: dummy-hcd: Fix interrupt synchronization error (git-fixes).
  - USB: dummy-hcd: Fix locking/synchronization error (git-fixes).
  - usb: usbtmc: Flush anchored URBs in usbtmc_release (git-fixes).
  - usb: gadget: u_ether: Fix race between gether_disconnect and
    eth_stop (git-fixes).
  - thunderbolt: Fix property read in nhi_wake_supported()
    (git-fixes).
  - commit 61dafca

++++ kernel-rt:

  - icmp: fix NULL pointer dereference in icmp_tag_validation()
    (CVE-2026-23398 bsc#1260730).
  - clsact: Fix use-after-free in init/destroy rollback asymmetry
    (CVE-2026-23413 bsc#1261498).
  - net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
    (CVE-2026-23293 bsc#1260486).
  - net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
    (CVE-2026-23381 bsc#1260471).
  - gve: Fix stats report corruption on queue count change
    (CVE-2026-23262 bsc#1259870).
  - commit b9e6af3
  - net/sched: ets: fix divide by zero in the offload path
    (CVE-2026-23379 bsc#1260481).
  - commit d39e420
  - tls: Purge async_hold in tls_decrypt_async_wait() (CVE-2026-23414
    bsc#1261496).
  - commit 2db5b5f
  - misc: fastrpc: possible double-free of cctx->remote_heap
    (git-fixes).
  - comedi: Reinit dev->spinlock between attachments to low-level
    drivers (git-fixes).
  - comedi: me_daq: Fix potential overrun of firmware buffer
    (git-fixes).
  - comedi: me4000: Fix potential overrun of firmware buffer
    (git-fixes).
  - comedi: ni_atmio16d: Fix invalid clean-up after failed attach
    (git-fixes).
  - counter: rz-mtu3-cnt: do not use struct rz_mtu3_channel's dev
    member (git-fixes).
  - counter: rz-mtu3-cnt: prevent counter from being toggled
    multiple times (git-fixes).
  - iio: dac: ad5770r: fix error return in ad5770r_read_raw()
    (git-fixes).
  - iio: accel: fix ADXL355 temperature signature value (git-fixes).
  - iio: light: vcnl4035: fix scan buffer on big-endian (git-fixes).
  - iio: adc: ti-adc161s626: use DMA-safe memory for spi_read()
    (git-fixes).
  - iio: adc: ti-adc161s626: fix buffer read on big-endian
    (git-fixes).
  - iio: imu: bmi160: Remove potential undefined behavior in
    bmi160_config_pin() (git-fixes).
  - iio: adc: aspeed: clear reference voltage bits before
    configuring vref (git-fixes).
  - iio: adc: ti-ads1119: Reinit completion before
    wait_for_completion_timeout() (git-fixes).
  - iio: adc: ti-ads1119: Replace IRQF_ONESHOT with IRQF_NO_THREAD
    (git-fixes).
  - iio: imu: bno055: fix BNO055_SCAN_CH_COUNT off by one
    (git-fixes).
  - iio: gyro: mpu3050: Fix out-of-sequence free_irq() (git-fixes).
  - iio: gyro: mpu3050: Move iio_device_register() to correct
    location (git-fixes).
  - iio: gyro: mpu3050: Fix irq resource leak (git-fixes).
  - iio: gyro: mpu3050: Fix incorrect free_irq() variable
    (git-fixes).
  - iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and
    gyroscope only (git-fixes).
  - iio: accel: adxl380: fix FIFO watermark bit 8 always written
    as 0 (git-fixes).
  - iio: adc: ti-ads1119: Fix unbalanced pm reference count in
    ds1119_single_conversion() (git-fixes).
  - usb: cdns3: gadget: fix state inconsistency on gadget init
    failure (git-fixes).
  - usb: ulpi: fix double free in ulpi_register_interface() error
    path (git-fixes).
  - usb: cdns3: gadget: fix NULL pointer dereference in ep_queue
    (git-fixes).
  - usb: core: phy: avoid double use of 'usb3-phy' (git-fixes).
  - usb: gadget: f_rndis: Protect RNDIS options with mutex
    (git-fixes).
  - usb: gadget: f_subset: Fix unbalanced refcnt in geth_free
    (git-fixes).
  - usb: typec: thunderbolt: Set enter_vdo during initialization
    (git-fixes).
  - usb: dwc2: gadget: Fix spin_lock/unlock mismatch in
    dwc2_hsotg_udc_stop() (git-fixes).
  - usb: gadget: uvc: fix NULL pointer dereference during unbind
    race (git-fixes).
  - usb: ehci-brcm: fix sleep during atomic (git-fixes).
  - USB: dummy-hcd: Fix interrupt synchronization error (git-fixes).
  - USB: dummy-hcd: Fix locking/synchronization error (git-fixes).
  - usb: usbtmc: Flush anchored URBs in usbtmc_release (git-fixes).
  - usb: gadget: u_ether: Fix race between gether_disconnect and
    eth_stop (git-fixes).
  - thunderbolt: Fix property read in nhi_wake_supported()
    (git-fixes).
  - commit 61dafca

++++ sssd:

  - Fix ldap_child process started by the backend process ending in
    defunc state. Add patch
    0011-sdap_select_principal_from_keytab_sync-waitpid-synch.patch
  - Create the secrets directory for the KCM service; (bsc#1259253);

------------------------------------------------------------------
------------------  2026-4-5  -  Apr 5 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Input: synaptics-rmi4 - fix a locking bug in an error path
    (git-fixes).
  - hwmon: (occ) Fix missing newline in occ_show_extended()
    (git-fixes).
  - hwmon: (occ) Fix division by zero in occ_show_power_1()
    (git-fixes).
  - hwmon: (tps53679) Fix device ID comparison and printing in
    tps53676_identify() (git-fixes).
  - hwmon: (pxe1610) Check return value of page-select write in
    probe (git-fixes).
  - commit 00e4cbf

++++ kernel-rt:

  - Input: synaptics-rmi4 - fix a locking bug in an error path
    (git-fixes).
  - hwmon: (occ) Fix missing newline in occ_show_extended()
    (git-fixes).
  - hwmon: (occ) Fix division by zero in occ_show_power_1()
    (git-fixes).
  - hwmon: (tps53679) Fix device ID comparison and printing in
    tps53676_identify() (git-fixes).
  - hwmon: (pxe1610) Check return value of page-select write in
    probe (git-fixes).
  - commit 00e4cbf

------------------------------------------------------------------
------------------  2026-4-4  -  Apr 4 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/amdgpu: fix the idr allocation flags (git-fixes).
  - commit 5c5d353
  - gpio: mxc: map Both Edge pad wakeup to Rising Edge (git-fixes).
  - drm/ioc32: stop speculation on the drm_compat_ioctl path
    (git-fixes).
  - drm/ast: dp501: Fix initialization of SCU2C (git-fixes).
  - accel/qaic: Handle DBC deactivation if the owner went away
    (git-fixes).
  - Revert "drm: Fix use-after-free on framebuffers and property
    blobs when calling drm_dev_unplug" (git-fixes).
  - drm/i915/dp: Use crtc_state->enhanced_framing properly on
    ivb/hsw CPU eDP (git-fixes).
  - drm/i915/dsi: Don't do DSC horizontal timing adjustments in
    command mode (git-fixes).
  - drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB
    (git-fixes).
  - crypto: af-alg - fix NULL pointer dereference in scatterwalk
    (git-fixes).
  - crypto: caam - fix overflow on long hmac keys (git-fixes).
  - crypto: caam - fix DMA corruption on long hmac keys (git-fixes).
  - crypto: tegra - Add missing CRYPTO_ALG_ASYNC (git-fixes).
  - commit cbd9b43

++++ kernel-rt:

  - drm/amdgpu: fix the idr allocation flags (git-fixes).
  - commit 5c5d353
  - gpio: mxc: map Both Edge pad wakeup to Rising Edge (git-fixes).
  - drm/ioc32: stop speculation on the drm_compat_ioctl path
    (git-fixes).
  - drm/ast: dp501: Fix initialization of SCU2C (git-fixes).
  - accel/qaic: Handle DBC deactivation if the owner went away
    (git-fixes).
  - Revert "drm: Fix use-after-free on framebuffers and property
    blobs when calling drm_dev_unplug" (git-fixes).
  - drm/i915/dp: Use crtc_state->enhanced_framing properly on
    ivb/hsw CPU eDP (git-fixes).
  - drm/i915/dsi: Don't do DSC horizontal timing adjustments in
    command mode (git-fixes).
  - drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB
    (git-fixes).
  - crypto: af-alg - fix NULL pointer dereference in scatterwalk
    (git-fixes).
  - crypto: caam - fix overflow on long hmac keys (git-fixes).
  - crypto: caam - fix DMA corruption on long hmac keys (git-fixes).
  - crypto: tegra - Add missing CRYPTO_ALG_ASYNC (git-fixes).
  - commit cbd9b43

------------------------------------------------------------------
------------------  2026-4-3  -  Apr 3 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ASoC: ak4458: Convert to RUNTIME_PM_OPS() & co (stable-fixes).
  - Refresh
    patches.suse/ASoC-ak4458-Disable-regulator-when-error-happens.patch.
  - commit 5c2bb96
  - net/x25: Fix overflow when accumulating packets (git-fixes).
  - net/x25: Fix potential double free of skb (git-fixes).
  - Bluetooth: hci_sync: fix stack buffer overflow in
    hci_le_big_create_sync (git-fixes).
  - Bluetooth: SMP: derive legacy responder STK authentication
    from MITM state (git-fixes).
  - Bluetooth: SMP: force responder MITM requirements before
    building the pairing response (git-fixes).
  - Bluetooth: MGMT: validate mesh send advertising payload length
    (git-fixes).
  - Bluetooth: hci_event: fix potential UAF in
    hci_le_remote_conn_param_req_evt (git-fixes).
  - Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
    (git-fixes).
  - Bluetooth: MGMT: validate LTK enc_size on load (git-fixes).
  - Bluetooth: SCO: fix race conditions in sco_sock_connect()
    (git-fixes).
  - Bluetooth: hci_sync: call destroy in hci_cmd_sync_run if
    immediate (git-fixes).
  - NFC: pn533: bound the UART receive buffer (git-fixes).
  - wifi: iwlwifi: mvm: fix potential out-of-bounds read in
    iwl_mvm_nd_match_info_handler() (git-fixes).
  - wifi: ath11k: Pass the correct value of each TID during a stop
    AMPDU session (git-fixes).
  - wifi: wilc1000: fix u8 overflow in SSID scan buffer size
    calculation (git-fixes).
  - ASoC: Intel: boards: fix unmet dependency on PINCTRL
    (git-fixes).
  - ASoC: ep93xx: Fix unchecked clk_prepare_enable() and add
    rollback on failure (git-fixes).
  - ALSA: caiaq: fix stack out-of-bounds read in init_card
    (git-fixes).
  - hwmon: (pmbus) Introduce the concept of "write-only" attributes
    (git-fixes).
  - hwmon: (pmbus) Mark lowest/average/highest/rated attributes
    as read-only (git-fixes).
  - drm/amdgpu: prevent immediate PASID reuse case (stable-fixes).
  - i3c: master: dw-i3c: Fix missing of_node for virtual I2C adapter
    (stable-fixes).
  - usb: core: new quirk to handle devices with zero configurations
    (stable-fixes).
  - drm/amdgpu: fix gpu idle power consumption issue for gfx v12
    (stable-fixes).
  - spi: intel-pci: Add support for Nova Lake mobile SPI flash
    (stable-fixes).
  - ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390
    (stable-fixes).
  - ALSA: hda/realtek: add HP Laptop 14s-dr5xxx mute LED quirk
    (stable-fixes).
  - ALSA: hda/realtek: add quirk for ASUS UM6702RC (stable-fixes).
  - drm/ttm/tests: Fix build failure on PREEMPT_RT (stable-fixes).
  - ASoC: fsl_easrc: Fix event generation in
    fsl_easrc_iec958_set_reg() (stable-fixes).
  - ASoC: fsl_easrc: Fix event generation in
    fsl_easrc_iec958_put_bits() (stable-fixes).
  - ALSA: hda/senary: Ensure EAPD is enabled during init
    (stable-fixes).
  - HID: mcp2221: cancel last I2C command on read error
    (stable-fixes).
  - HID: asus: add xg mobile 2023 external hardware support
    (stable-fixes).
  - HID: magicmouse: fix battery reporting for Apple Magic Trackpad
    2 (stable-fixes).
  - HID: asus: avoid memory leak in asus_report_fixup()
    (stable-fixes).
  - HID: magicmouse: avoid memory leak in magicmouse_report_fixup()
    (stable-fixes).
  - HID: apple: avoid memory leak in apple_report_fixup()
    (stable-fixes).
  - platform/x86: intel-hid: Enable 5-button array on ThinkPad X1
    Fold 16 Gen 1 (stable-fixes).
  - platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to
    dmi_vgbs_allow_list (stable-fixes).
  - platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix
    touchscreen on SUPI S10 (stable-fixes).
  - net: usb: r8152: add TRENDnet TUC-ET2G (stable-fixes).
  - hwmon: (pmbus/core) Fix various coding style issues
    (stable-fixes).
  - commit 053df39

++++ kernel-rt:

  - ASoC: ak4458: Convert to RUNTIME_PM_OPS() & co (stable-fixes).
  - Refresh
    patches.suse/ASoC-ak4458-Disable-regulator-when-error-happens.patch.
  - commit 5c2bb96
  - net/x25: Fix overflow when accumulating packets (git-fixes).
  - net/x25: Fix potential double free of skb (git-fixes).
  - Bluetooth: hci_sync: fix stack buffer overflow in
    hci_le_big_create_sync (git-fixes).
  - Bluetooth: SMP: derive legacy responder STK authentication
    from MITM state (git-fixes).
  - Bluetooth: SMP: force responder MITM requirements before
    building the pairing response (git-fixes).
  - Bluetooth: MGMT: validate mesh send advertising payload length
    (git-fixes).
  - Bluetooth: hci_event: fix potential UAF in
    hci_le_remote_conn_param_req_evt (git-fixes).
  - Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync
    (git-fixes).
  - Bluetooth: MGMT: validate LTK enc_size on load (git-fixes).
  - Bluetooth: SCO: fix race conditions in sco_sock_connect()
    (git-fixes).
  - Bluetooth: hci_sync: call destroy in hci_cmd_sync_run if
    immediate (git-fixes).
  - NFC: pn533: bound the UART receive buffer (git-fixes).
  - wifi: iwlwifi: mvm: fix potential out-of-bounds read in
    iwl_mvm_nd_match_info_handler() (git-fixes).
  - wifi: ath11k: Pass the correct value of each TID during a stop
    AMPDU session (git-fixes).
  - wifi: wilc1000: fix u8 overflow in SSID scan buffer size
    calculation (git-fixes).
  - ASoC: Intel: boards: fix unmet dependency on PINCTRL
    (git-fixes).
  - ASoC: ep93xx: Fix unchecked clk_prepare_enable() and add
    rollback on failure (git-fixes).
  - ALSA: caiaq: fix stack out-of-bounds read in init_card
    (git-fixes).
  - hwmon: (pmbus) Introduce the concept of "write-only" attributes
    (git-fixes).
  - hwmon: (pmbus) Mark lowest/average/highest/rated attributes
    as read-only (git-fixes).
  - drm/amdgpu: prevent immediate PASID reuse case (stable-fixes).
  - i3c: master: dw-i3c: Fix missing of_node for virtual I2C adapter
    (stable-fixes).
  - usb: core: new quirk to handle devices with zero configurations
    (stable-fixes).
  - drm/amdgpu: fix gpu idle power consumption issue for gfx v12
    (stable-fixes).
  - spi: intel-pci: Add support for Nova Lake mobile SPI flash
    (stable-fixes).
  - ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390
    (stable-fixes).
  - ALSA: hda/realtek: add HP Laptop 14s-dr5xxx mute LED quirk
    (stable-fixes).
  - ALSA: hda/realtek: add quirk for ASUS UM6702RC (stable-fixes).
  - drm/ttm/tests: Fix build failure on PREEMPT_RT (stable-fixes).
  - ASoC: fsl_easrc: Fix event generation in
    fsl_easrc_iec958_set_reg() (stable-fixes).
  - ASoC: fsl_easrc: Fix event generation in
    fsl_easrc_iec958_put_bits() (stable-fixes).
  - ALSA: hda/senary: Ensure EAPD is enabled during init
    (stable-fixes).
  - HID: mcp2221: cancel last I2C command on read error
    (stable-fixes).
  - HID: asus: add xg mobile 2023 external hardware support
    (stable-fixes).
  - HID: magicmouse: fix battery reporting for Apple Magic Trackpad
    2 (stable-fixes).
  - HID: asus: avoid memory leak in asus_report_fixup()
    (stable-fixes).
  - HID: magicmouse: avoid memory leak in magicmouse_report_fixup()
    (stable-fixes).
  - HID: apple: avoid memory leak in apple_report_fixup()
    (stable-fixes).
  - platform/x86: intel-hid: Enable 5-button array on ThinkPad X1
    Fold 16 Gen 1 (stable-fixes).
  - platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to
    dmi_vgbs_allow_list (stable-fixes).
  - platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix
    touchscreen on SUPI S10 (stable-fixes).
  - net: usb: r8152: add TRENDnet TUC-ET2G (stable-fixes).
  - hwmon: (pmbus/core) Fix various coding style issues
    (stable-fixes).
  - commit 053df39

------------------------------------------------------------------
------------------  2026-4-2  -  Apr 2 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - kABI: Include trace recursion bits in kABI tracking
    (bsc#1258301).
  - commit 7414cd0
  - tracing: Add recursion protection in kernel stack trace
    recording (CVE-2026-23138 bsc#1258301).
  - kABI: Preserve values of the trace recursion bits
    (CVE-2026-23138 bsc#1258301).
  - commit ba21d86
  - bridge: cfm: Fix race condition in peer_mep deletion
    (CVE-2026-23393 bsc#1260522).
  - commit 11e82ff
  - net: add proper RCU protection to /proc/net/ptype
    (CVE-2026-23255 bsc#1259891).
  - commit 9473781
  - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
    (CVE-2026-23274 bsc#1260005).
  - commit e8d0573
  - netfilter: nf_tables: always walk all pending catchall elements
    (CVE-2026-23278 bsc#1259998).
  - commit ef6d5cc

++++ kernel-rt:

  - kABI: Include trace recursion bits in kABI tracking
    (bsc#1258301).
  - commit 7414cd0
  - tracing: Add recursion protection in kernel stack trace
    recording (CVE-2026-23138 bsc#1258301).
  - kABI: Preserve values of the trace recursion bits
    (CVE-2026-23138 bsc#1258301).
  - commit ba21d86
  - bridge: cfm: Fix race condition in peer_mep deletion
    (CVE-2026-23393 bsc#1260522).
  - commit 11e82ff
  - net: add proper RCU protection to /proc/net/ptype
    (CVE-2026-23255 bsc#1259891).
  - commit 9473781
  - netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels
    (CVE-2026-23274 bsc#1260005).
  - commit e8d0573
  - netfilter: nf_tables: always walk all pending catchall elements
    (CVE-2026-23278 bsc#1259998).
  - commit ef6d5cc

++++ python313-core:

  - Add CVE-2026-3479-pkgutil_get_data.patch pkgutil.get_data() has
    the same security model as open(). The documented limitations
    ensure compatibility with non-filesystem loaders; Python
    doesn't check that. (bsc#1259989, CVE-2026-3479,
    gh#python/cpython#146121).

++++ python313:

  - Add CVE-2026-3479-pkgutil_get_data.patch pkgutil.get_data() has
    the same security model as open(). The documented limitations
    ensure compatibility with non-filesystem loaders; Python
    doesn't check that. (bsc#1259989, CVE-2026-3479,
    gh#python/cpython#146121).

++++ vim:

  - Fix bsc#1261191 / CVE-2026-34714.
  - Fix bsc#1261271 / CVE-2026-34982.
  - Fix bsc#1259985 / CVE-2026-33412.
  - Update to 9.2.0280:
    * patch 9.2.0280: [security]: path traversal issue in zip.vim
    * patch 9.2.0279: terminal: out-of-bounds write with overlong CSI argument list
    * patch 9.2.0278: viminfo: heap buffer overflow when reading viminfo file
    * patch 9.2.0277: tests: test_modeline.vim fails
    * patch 9.2.0276: [security]: modeline security bypass
    * patch 9.2.0275: tests: test_options.vim fails
    * patch 9.2.0274: BSU/ESU are output directly to the terminal
    * patch 9.2.0273: tabpanel: undefined behaviour with large tabpanelop columns
    * patch 9.2.0272: [security]: 'tabpanel' can be set in a modeline
    * patch 9.2.0271: buffer underflow in vim_fgets()
    * patch 9.2.0270: test: trailing spaces used in tests
    * patch 9.2.0269: configure: Link error on Solaris
    * patch 9.2.0268: memory leak in call_oc_method()
    * patch 9.2.0267: 'autowrite' not triggered for :term
    * patch 9.2.0266: typeahead buffer overflow during mouse drag event
    * patch 9.2.0265: unnecessary restrictions for defining dictionary function names
    * patch 9.2.0264: Cannot disable kitty keyboard protocol in vim :terminal
    * patch 9.2.0263: hlset() cannot handle attributes with spaces
    * patch 9.2.0262: invalid lnum when pasting text copied blockwise
    * patch 9.2.0261: terminal: redraws are slow
    * patch 9.2.0260: statusline not redrawn after closing a popup window
    * patch 9.2.0259: tabpanel: corrupted display during scrolling causing flicker
    * patch 9.2.0258: memory leak in add_mark()
    * patch 9.2.0257: unnecessary memory allocation in set_callback()
    * patch 9.2.0256: visual selection size not shown in showcmd during test
    * patch 9.2.0255: tests: Test_popup_opacity_vsplit() fails in a wide terminal
    * patch 9.2.0254: w_locked can be bypassed when setting recursively
    * patch 9.2.0253: various issues with wrong b_nwindows after closing buffers
    * patch 9.2.0252: Crash when ending Visual mode after curbuf was unloaded
    * patch 9.2.0251: Link error when building without channel feature
    * patch 9.2.0250: system() does not support bypassing the shell
    * patch 9.2.0249: clipboard: provider reacts to autoselect feature
    * patch 9.2.0248: json_decode() is not strict enough
    * patch 9.2.0247: popup: popups may not wrap as expected
    * patch 9.2.0246: memory leak in globpath()
    * patch 9.2.0245: xxd: color output detection is broken
    * patch 9.2.0244: memory leak in eval8()
    * patch 9.2.0243: memory leak in change_indent()
    * patch 9.2.0242: memory leak in check_for_cryptkey()
    * patch 9.2.0241: tests: Test_visual_block_hl_with_autosel() is flaky
    * patch 9.2.0240: syn_name2id() is slow due to linear search
    * patch 9.2.0239: signcolumn may cause flicker
    * patch 9.2.0238: showmode message may not be displayed
    * patch 9.2.0237: filetype: ObjectScript routines are not recognized
    * patch 9.2.0236: stack-overflow with deeply nested data in json_encode/decode()
    * patch 9.2.0235: filetype: wks files are not recognized.
    * patch 9.2.0234: test: Test_close_handle() is flaky
    * patch 9.2.0233: Compiler warning in strings.c
    * patch 9.2.0232: fileinfo not shown after :bd of last listed buffer
    * patch 9.2.0231: Amiga: Link error for missing HAVE_LOCALE_H
    * patch 9.2.0230: popup: opacity not working accross vert splits
    * patch 9.2.0229: keypad keys may overwrite keycode for another key
    * patch 9.2.0228: still possible flicker
    * patch 9.2.0227: MS-Windows: CSI sequences may be written to screen
    * patch 9.2.0226: No 'incsearch' highlighting support for :uniq
    * patch 9.2.0225: runtime(compiler): No compiler plugin for just
    * patch 9.2.0224: channel: 2 issues with out/err callbacks
    * patch 9.2.0223: Option handling for key:value suboptions is limited
    * patch 9.2.0222: "zb" scrolls incorrectly with cursor on fold
    * patch 9.2.0221: Visual selection drawn incorrectly with "autoselect"
    * patch 9.2.0220: MS-Windows: some defined cannot be set on Cygwin/Mingw
    * patch 9.2.0219: call stack can be corrupted
    * patch 9.2.0218: visual selection highlighting in X11 GUI is wrong.
    * patch 9.2.0217: filetype: cto files are not recognized
    * patch 9.2.0216: MS-Windows: Rendering artifacts with DirectX
    * patch 9.2.0215: MS-Windows: several tests fail in the Windows CUI.
    * patch 9.2.0214: tests: Test_gui_system_term_scroll() is flaky
    * patch 9.2.0213: Crash when using a partial or lambda as a clipboard provider
    * patch 9.2.0212: MS-Windows: version packing may overflow
    * patch 9.2.0211: possible crash when setting 'winhighlight'
    * patch 9.2.0210: tests: Test_xxd tests are failing
    * patch 9.2.0209: freeze during wildmenu completion
    * patch 9.2.0208: MS-Windows: excessive scroll-behaviour with go+=!
    * patch 9.2.0207: MS-Windows: freeze on second :hardcopy
    * patch 9.2.0206: MS-Window: stripping all CSI sequences
    * patch 9.2.0205: xxd: Cannot NUL terminate the C include file style
    * patch 9.2.0204: filetype: cps files are not recognized
    * patch 9.2.0203: Patch v9.2.0185 was wrong
    * patch 9.2.0202: [security]: command injection via newline in glob()
    * patch 9.2.0201: filetype: Wireguard config files not recognized
    * patch 9.2.0200: term: DECRQM codes are sent too early
    * patch 9.2.0199: tests: test_startup.vim fails
    * patch 9.2.0198: cscope: can escape from restricted mode
    * patch 9.2.0197: tabpanel: frame width not updated for existing tab pages
    * patch 9.2.0196: textprop: negative IDs and can cause a crash
    * patch 9.2.0195: CI: test-suite gets killed for taking too long
    * patch 9.2.0194: tests: test_startup.vim leaves temp.txt around
    * patch 9.2.0193: using copy_option_part() can be improved
    * patch 9.2.0192: not correctly recognizing raw key codes
    * patch 9.2.0191: Not possible to know if Vim was compiled with Android support
    * patch 9.2.0190: Status line height mismatch in vertical splits
    * patch 9.2.0189: MS-Windows: opacity popups flicker during redraw in the console
    * patch 9.2.0188: Can set environment variables in restricted mode
    * patch 9.2.0187: MS-Windows: rendering artifacts with DirectX renderer
    * patch 9.2.0186: heap buffer overflow with long generic function name
    * patch 9.2.0185: buffer overflow when redrawing custom tabline
    * patch 9.2.0184: MS-Windows: screen flicker with termguicolors and visualbell
    * patch 9.2.0183: channel: using deprecated networking APIs
    * patch 9.2.0182: autocmds may leave windows with w_locked set
    * patch 9.2.0181: line('w0') moves cursor in terminal-normal mode
    * patch 9.2.0180: possible crash with winminheight=0
    * patch 9.2.0179: MS-Windows: Compiler warning for converting from size_t to int
    * patch 9.2.0178: DEC mode requests are sent even when not in raw mode
    * patch 9.2.0177: Vim9: Can set environment variables in restricted mode
    * patch 9.2.0176: external diff is allowed in restricted mode
    * patch 9.2.0175: No tests for what v9.2.0141 and v9.2.0156 fixes
    * patch 9.2.0174: diff: inline word-diffs can be fragmented
    * patch 9.2.0173: tests: Test_balloon_eval_term_visual is flaky
    * patch 9.2.0172: Missing semicolon in os_mac_conv.c
    * patch 9.2.0171: MS-Windows: version detection is deprecated
    * patch 9.2.0170: channel: some issues in ch_listen()
    * patch 9.2.0169: assertion failure in syn_id2attr()
    * patch 9.2.0168: invalid pointer casting in string_convert() arguments
    * patch 9.2.0167: terminal: setting buftype=terminal may cause a crash
    * patch 9.2.0166: Coverity warning for potential NULL dereference
    * patch 9.2.0165: tests: perleval fails in the sandbox
    * patch 9.2.0164: build error when XCLIPBOARD is not defined
    * patch 9.2.0163: MS-Windows: Compile warning for unused variable
    * patch 9.2.0162: tests: unnecessary CheckRunVimInTerminal in test_quickfix
    * patch 9.2.0161: intro message disappears on startup in some terminals
    * patch 9.2.0160: terminal DEC mode handling is overly complex
    * patch 9.2.0159: Crash when reading quickfix line
    * patch 9.2.0158: Visual highlighting might be incorrect
    * patch 9.2.0157: Vim9: concatenation can be improved
    * patch 9.2.0156: perleval() and rubyeval() ignore security settings
    * patch 9.2.0155: filetype: ObjectScript are not recognized
    * patch 9.2.0154: if_lua: runtime error with lua 5.5
    * patch 9.2.0153: No support to act as a channel server
    * patch 9.2.0152: concatenating strings is slow
    * patch 9.2.0151: blob_from_string() is slow for long strings
    * patch 9.2.0150: synchronized terminal update may cause display artifacts
    * patch 9.2.0149: Vim9: segfault when unletting an imported variable
    * patch 9.2.0148: Compile error when FEAT_DIFF is not defined
    * patch 9.2.0147: blob: concatenation can be improved
    * patch 9.2.0146: dictionary lookups can be improved
    * patch 9.2.0145: UTF-8 decoding and length calculation can be improved
    * patch 9.2.0144: 'statuslineopt' is a global only option
    * patch 9.2.0143: termdebug: no support for thread and condition in :Break
    * patch 9.2.0142: Coverity: Dead code warning
    * patch 9.2.0141: :perl ex commands allowed in restricted mode
    * patch 9.2.0140: file reading performance can be improved
    * patch 9.2.0139: Cannot configure terminal resize event
    * patch 9.2.0138: winhighlight option handling can be improved
    * patch 9.2.0137: [security]: crash with composing char in collection range
    * patch 9.2.0136: memory leak in add_interface_from_super_class()
    * patch 9.2.0135: memory leak in eval_tuple()
    * patch 9.2.0134: memory leak in socket_server_send_reply()
    * patch 9.2.0133: memory leak in netbeans_file_activated()
    * patch 9.2.0132: tests: Test_recover_corrupted_swap_file1 fails on be systems
    * patch 9.2.0131: potential buffer overflow in regdump()
    * patch 9.2.0130: missing range flags for the :tab command
    * patch 9.2.0129: popup: wrong handling of wide-chars and opacity:0
    * patch 9.2.0128: Wayland: using _Boolean instead of bool type
    * patch 9.2.0127: line('w0') and line('w$') return wrong values in a terminal
    * patch 9.2.0126: String handling can be improved
    * patch 9.2.0125: tests: test_textformat.vim leaves swapfiles behind
    * patch 9.2.0124: auto-format may swallow white space
    * patch 9.2.0123: GTK: using deprecated gdk_pixbuf_new_from_xpm_data()
    * patch 9.2.0122: Vim still supports compiling on NeXTSTEP
    * patch 9.2.0120: tests: test_normal fails
    * patch 9.2.0119: incorrect highlight initialization in win_init()
    * patch 9.2.0118: memory leak in w_hl when reusing a popup window
    * patch 9.2.0117: tests: test_wayland.vim fails
    * patch 9.2.0116: terminal: synchronized output sequences are buffered
    * patch 9.2.0115: popup: screen flickering possible during async callbacks
    * patch 9.2.0114: MS-Windows: terminal output may go to wrong terminal
    * patch 9.2.0113: winhighlight pointer may be used uninitialized
    * patch 9.2.0112: popup: windows flicker when updating text
    * patch 9.2.0111: 'winhighlight' option not always applied

------------------------------------------------------------------
------------------  2026-4-1  -  Apr 1 2026  -------------------
------------------------------------------------------------------

++++ kdump:

  - upgrade to version 2.1.6+git9.g60a2898
    * fix VLAN interface naming (bsc#1255300)
    * fix bonding options for VLAN slaves (bsc#1255300)
    * fix return value of kdumptool commandline -d (bsc#1257471)
    * man: fix install instructions in kdump(7)
    * kdumptool commandline: ignore minor differencies (bsc#1260535)
    * fix sysconfig syntax

++++ kernel-default:

  - netfilter: nf_tables: unconditionally bump set->nelems before
    insertion (CVE-2026-23272 bsc#1260009).
  - commit 7374f2f
  - btrfs: fix zero size inode with non-zero size after log replay
    (git-fixes).
  - commit 4cd09a5
  - btrfs: log new dentries when logging parent dir of a conflicting
    inode (git-fixes).
  - commit 8b6c07f
  - bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
    (CVE-2026-23319 bsc#1260735).
  - commit 08c179a

++++ kernel-rt:

  - netfilter: nf_tables: unconditionally bump set->nelems before
    insertion (CVE-2026-23272 bsc#1260009).
  - commit 7374f2f
  - btrfs: fix zero size inode with non-zero size after log replay
    (git-fixes).
  - commit 4cd09a5
  - btrfs: log new dentries when logging parent dir of a conflicting
    inode (git-fixes).
  - commit 8b6c07f
  - bpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
    (CVE-2026-23319 bsc#1260735).
  - commit 08c179a

++++ python-cryptography:

  - CVE-2026-34073: X.509 bypass of name constraints on wildcard SANs with matching peer names (bsc#1260876)
    Add patch CVE-2026-34073.patch

++++ suseconnect-ng:

  - Update version to 1.21.1:
  - Fix nil token handling (bsc#1261155)
  - Switch to using go1.24-openssl as the default Go version to
    install to support building the package (jsc#SCC-585).

------------------------------------------------------------------
------------------  2026-3-31  -  Mar 31 2026  -------------------
------------------------------------------------------------------

++++ ignition:

  - Add CVE-2026-33186.patch
    * Fixes [bsc#1260251]

------------------------------------------------------------------
------------------  2026-3-30  -  Mar 30 2026  -------------------
------------------------------------------------------------------

++++ glibc:

  - resolv-count-resource-records.patch: resolv: Count records correctly
    (CVE-2026-4437, bsc#1260078, BZ #34014)
  - resolv-check-hostname.patch: resolv: Check hostname for validity
    (CVE-2026-4438, bsc#1260082, BZ #34015)

++++ kernel-default:

  - btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (bsc#1257777).
  - commit 68a8609
  - xsk: Fix fragment node deletion to prevent buffer leak
    (CVE-2026-23326 bsc#1260606).
  - commit 82be0c6
  - xen/privcmd: unregister xenstore notifier on module exit
    (git-fixes).
  - commit c843a07
  - ice: set max queues in alloc_etherdev_mqs() (git-fixes).
  - net/mlx5: Fix crash when moving to switchdev mode (git-fixes).
  - gve: fix incorrect buffer cleanup in
    gve_tx_clean_pending_packets for QPL (CVE-2026-23386
    bsc#1260799).
  - bnxt_en: Allow ntuple filters for drops (git-fixes).
  - octeontx2-af: Workaround SQM/PSE stalls by disabling sticky
    (git-fixes).
  - commit c1f367d
  - phy: qcom: qmp-ufs: Fix SM8650 PCS table for Gear 4 (git-fixes).
  - phy: ti: j721e-wiz: Fix device node reference leak in
    wiz_get_lane_phy_types() (git-fixes).
  - dmaengine: xilinx_dma: Fix reset related timeout with
    two-channel AXIDMA (git-fixes).
  - dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction
    (git-fixes).
  - dmaengine: xilinx: xilinx_dma: Fix residue calculation for
    cyclic DMA (git-fixes).
  - dmaengine: xilinx: xilinx_dma: Fix dma_device directions
    (git-fixes).
  - dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock
    (git-fixes).
  - dmaengine: sh: rz-dmac: Protect the driver specific lists
    (git-fixes).
  - dmaengine: idxd: fix possible wrong descriptor completion in
    llist_abort_desc() (git-fixes).
  - dmaengine: xilinx: xdma: Fix regmap init error handling
    (git-fixes).
  - dmaengine: dw-edma: Fix multiple times setting of the
    CYCLE_STATE and CYCLE_BIT bits for HDMA (git-fixes).
  - dmaengine: idxd: Fix leaking event log memory (git-fixes).
  - dmaengine: idxd: Fix freeing the allocated ida too late
    (git-fixes).
  - dmaengine: idxd: Fix memory leak when a wq is reset (git-fixes).
  - dmaengine: idxd: Fix not releasing workqueue on .release()
    (git-fixes).
  - dmaengine: idxd: Fix possible invalid memory access after FLR
    (git-fixes).
  - dmaengine: fsl-edma: fix channel parameter config for fixed
    channel requests (git-fixes).
  - irqchip/qcom-mpm: Add missing mailbox TX done acknowledgment
    (git-fixes).
  - commit 264b815
  - PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry
    (CVE-2026-23361 bsc#1260732).
  - commit b836028
  - net: mana: Trigger VF reset/recovery on health check failure
    due to HWC timeout (bsc#1259580).
  - net: mana: fix use-after-free in add_adev() error path
    (git-fixes).
  - commit 96d07db

++++ kernel-rt:

  - btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (bsc#1257777).
  - commit 68a8609
  - xsk: Fix fragment node deletion to prevent buffer leak
    (CVE-2026-23326 bsc#1260606).
  - commit 82be0c6
  - xen/privcmd: unregister xenstore notifier on module exit
    (git-fixes).
  - commit c843a07
  - ice: set max queues in alloc_etherdev_mqs() (git-fixes).
  - net/mlx5: Fix crash when moving to switchdev mode (git-fixes).
  - gve: fix incorrect buffer cleanup in
    gve_tx_clean_pending_packets for QPL (CVE-2026-23386
    bsc#1260799).
  - bnxt_en: Allow ntuple filters for drops (git-fixes).
  - octeontx2-af: Workaround SQM/PSE stalls by disabling sticky
    (git-fixes).
  - commit c1f367d
  - phy: qcom: qmp-ufs: Fix SM8650 PCS table for Gear 4 (git-fixes).
  - phy: ti: j721e-wiz: Fix device node reference leak in
    wiz_get_lane_phy_types() (git-fixes).
  - dmaengine: xilinx_dma: Fix reset related timeout with
    two-channel AXIDMA (git-fixes).
  - dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction
    (git-fixes).
  - dmaengine: xilinx: xilinx_dma: Fix residue calculation for
    cyclic DMA (git-fixes).
  - dmaengine: xilinx: xilinx_dma: Fix dma_device directions
    (git-fixes).
  - dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock
    (git-fixes).
  - dmaengine: sh: rz-dmac: Protect the driver specific lists
    (git-fixes).
  - dmaengine: idxd: fix possible wrong descriptor completion in
    llist_abort_desc() (git-fixes).
  - dmaengine: xilinx: xdma: Fix regmap init error handling
    (git-fixes).
  - dmaengine: dw-edma: Fix multiple times setting of the
    CYCLE_STATE and CYCLE_BIT bits for HDMA (git-fixes).
  - dmaengine: idxd: Fix leaking event log memory (git-fixes).
  - dmaengine: idxd: Fix freeing the allocated ida too late
    (git-fixes).
  - dmaengine: idxd: Fix memory leak when a wq is reset (git-fixes).
  - dmaengine: idxd: Fix not releasing workqueue on .release()
    (git-fixes).
  - dmaengine: idxd: Fix possible invalid memory access after FLR
    (git-fixes).
  - dmaengine: fsl-edma: fix channel parameter config for fixed
    channel requests (git-fixes).
  - irqchip/qcom-mpm: Add missing mailbox TX done acknowledgment
    (git-fixes).
  - commit 264b815
  - PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry
    (CVE-2026-23361 bsc#1260732).
  - commit b836028
  - net: mana: Trigger VF reset/recovery on health check failure
    due to HWC timeout (bsc#1259580).
  - net: mana: fix use-after-free in add_adev() error path
    (git-fixes).
  - commit 96d07db

++++ libtpms:

  - CVE-2025-49133: Fixed potential out of bounds (OOB) read vulnerability (bsc#1244528)
    0001-tpm2-Fix-potential-out-of-bound-access-abort-due-to-.patch
  - CVE-2026-21444: FIXed Remote data confidentiality compromise via incorrect Initialization Vector (IV) handling (bsc#1260439)
    0001-tpm2-Fix-retrieval-of-updated-IV-when-using-OpenSSL-.patch

------------------------------------------------------------------
------------------  2026-3-28  -  Mar 28 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - hwmon: (adm1177) fix sysfs ABI violation and current unit
    conversion (git-fixes).
  - hwmon: (peci/cputemp) Fix off-by-one in cputemp_is_visible()
    (git-fixes).
  - hwmon: (peci/cputemp) Fix crit_hyst returning delta instead
    of absolute temperature (git-fixes).
  - hwmon: (pmbus/isl68137) Add mutex protection for AVS enable
    sysfs attributes (git-fixes).
  - drm/i915/dp_tunnel: Fix error handling when clearing stream
    BW in atomic state (git-fixes).
  - drm/i915/gmbus: fix spurious timeout on 512-byte burst reads
    (git-fixes).
  - drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
    (git-fixes).
  - drm/amd/display: Do not skip unrelated mode changes in DSC
    validation (git-fixes).
  - spi: spi-fsl-lpspi: fix teardown order issue (UAF) (git-fixes).
  - spi: meson-spicc: Fix double-put in remove path (git-fixes).
  - spi: sn-f-ospi: Fix resource leak in f_ospi_probe() (git-fixes).
  - regmap: Synchronize cache for the page selector (git-fixes).
  - ASoC: SOF: ipc4-topology: Allow bytes controls without initial
    payload (git-fixes).
  - ASoC: adau1372: Fix clock leak on PLL lock failure (git-fixes).
  - ASoC: adau1372: Fix unchecked clk_prepare_enable() return value
    (git-fixes).
  - ASoC: Intel: catpt: Fix the device initialization (git-fixes).
  - ALSA: firewire-lib: fix uninitialized local variable
    (git-fixes).
  - ALSA: hda/realtek: Sequence GPIO2 on Star Labs StarFighter
    (git-fixes).
  - net: usb: pegasus: validate USB endpoints (stable-fixes).
  - commit ba7e9a1

++++ kernel-rt:

  - hwmon: (adm1177) fix sysfs ABI violation and current unit
    conversion (git-fixes).
  - hwmon: (peci/cputemp) Fix off-by-one in cputemp_is_visible()
    (git-fixes).
  - hwmon: (peci/cputemp) Fix crit_hyst returning delta instead
    of absolute temperature (git-fixes).
  - hwmon: (pmbus/isl68137) Add mutex protection for AVS enable
    sysfs attributes (git-fixes).
  - drm/i915/dp_tunnel: Fix error handling when clearing stream
    BW in atomic state (git-fixes).
  - drm/i915/gmbus: fix spurious timeout on 512-byte burst reads
    (git-fixes).
  - drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
    (git-fixes).
  - drm/amd/display: Do not skip unrelated mode changes in DSC
    validation (git-fixes).
  - spi: spi-fsl-lpspi: fix teardown order issue (UAF) (git-fixes).
  - spi: meson-spicc: Fix double-put in remove path (git-fixes).
  - spi: sn-f-ospi: Fix resource leak in f_ospi_probe() (git-fixes).
  - regmap: Synchronize cache for the page selector (git-fixes).
  - ASoC: SOF: ipc4-topology: Allow bytes controls without initial
    payload (git-fixes).
  - ASoC: adau1372: Fix clock leak on PLL lock failure (git-fixes).
  - ASoC: adau1372: Fix unchecked clk_prepare_enable() return value
    (git-fixes).
  - ASoC: Intel: catpt: Fix the device initialization (git-fixes).
  - ALSA: firewire-lib: fix uninitialized local variable
    (git-fixes).
  - ALSA: hda/realtek: Sequence GPIO2 on Star Labs StarFighter
    (git-fixes).
  - net: usb: pegasus: validate USB endpoints (stable-fixes).
  - commit ba7e9a1

------------------------------------------------------------------
------------------  2026-3-27  -  Mar 27 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - wifi: libertas: fix use-after-free in lbs_free_adapter()
    (CVE-2026-23281 bsc#1260464).
  - commit a8cb81b
  - PM: hibernate: Drain trailing zero pages on userspace restore
    (git-fixes).
  - platform/x86: ISST: Correct locked bit width (git-fixes).
  - platform/x86: intel-hid: disable wakeup_mode during hibernation
    (git-fixes).
  - platform/olpc: olpc-xo175-ec: Fix overflow error message to
    print inlen (git-fixes).
  - serial: 8250: Add late synchronize_irq() to shutdown to handle
    DW UART BUSY (git-fixes).
  - serial: 8250_pci: add support for the AX99100 (stable-fixes).
  - serial: uartlite: fix PM runtime usage count underflow on probe
    (git-fixes).
  - serial: 8250: Fix TX deadlock when using DMA (git-fixes).
  - spi: fix statistics allocation (git-fixes).
  - spi: fix use-after-free on controller registration failure
    (git-fixes).
  - wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is
    not enough headroom (git-fixes).
  - wifi: mac80211: fix NULL deref in mesh_matches_local()
    (git-fixes).
  - wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down
    (git-fixes).
  - wifi: mac80211: Fix static_branch_dec() underflow for
    aql_disable (git-fixes).
  - PM: runtime: Fix a race condition related to device removal
    (git-fixes).
  - soc: fsl: cpm1: qmc: Fix error check for devm_ioremap_resource()
    in qmc_qe_init_resources() (git-fixes).
  - soc: fsl: qbman: fix race condition in qman_destroy_fq
    (git-fixes).
  - soc: microchip: mpfs: Fix memory leak in
    mpfs_sys_controller_probe() (git-fixes).
  - USB: ezcap401 needs USB_QUIRK_NO_BOS to function on 10gbs usb
    speed (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Nova Lake -H
    (stable-fixes).
  - usb/core/quirks: Add Huawei ME906S-device to wakeup quirk
    (stable-fixes).
  - usb: xhci: Prevent interrupt storm on host controller error
    (HCE) (stable-fixes).
  - usb: misc: uss720: properly clean up reference in uss720_probe()
    (stable-fixes).
  - usb: image: mdc800: kill download URB on timeout (stable-fixes).
  - usb: mdc800: handle signal and read racing (stable-fixes).
  - usb: yurex: fix race in probe (stable-fixes).
  - USB: add QUIRK_NO_BOS for video capture several devices
    (stable-fixes).
  - staging: rtl8723bs: properly validate the data in
    rtw_get_ie_ex() (stable-fixes).
  - wifi: mac80211: set default WMM parameters on all links
    (stable-fixes).
  - USB: serial: f81232: fix incomplete serial port generation
    (stable-fixes).
  - commit 2fe4f6e
  - nfc: nci: fix circular locking dependency in nci_close_device
    (git-fixes).
  - pinctrl: mediatek: common: Fix probe failure for devices
    without EINT (git-fixes).
  - pinctrl: qcom: spmi-gpio: implement .get_direction()
    (git-fixes).
  - media: mc, v4l2: serialize REINIT and REQBUFS with
    req_queue_mutex (git-fixes).
  - i2c: pxa: defer reset on Armada 3700 when recovery is used
    (git-fixes).
  - i2c: fsi: Fix a potential leak in fsi_i2c_probe() (git-fixes).
  - i2c: cp2615: fix serial string NULL-deref at probe (git-fixes).
  - hwmon: axi-fan: don't use driver_override as IRQ name
    (git-fixes).
  - hwmon: (max6639) Fix pulses-per-revolution implementation
    (git-fixes).
  - hwmon: (pmbus/isl68137) Fix unchecked return value and use
    sysfs_emit() (git-fixes).
  - mmc: sdhci: fix timing selection for 1-bit bus width
    (git-fixes).
  - mmc: sdhci-pci-gli: fix GL9750 DMA write corruption (git-fixes).
  - mtd: rawnand: pl353: make sure optimal timings are applied
    (git-fixes).
  - mtd: rawnand: brcmnand: skip DMA during panic write (git-fixes).
  - mtd: rawnand: serialize lock/unlock against other NAND
    operations (git-fixes).
  - mtd: rawnand: cadence: Fix error check for dma_alloc_coherent()
    in cadence_nand_init() (git-fixes).
  - mtd: Avoid boot crash in RedBoot partition table parser
    (git-fixes).
  - mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN
    stations (stable-fixes).
  - NFC: nxp-nci: allow GPIOs to sleep (git-fixes).
  - net: usb: aqc111: Do not perform PM inside suspend callback
    (git-fixes).
  - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
    (git-fixes).
  - net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
    (git-fixes).
  - net/rose: fix NULL pointer dereference in rose_transmit_link
    on reconnect (git-fixes).
  - mmc: dw_mmc-rockchip: Fix runtime PM support for internal
    phase support (git-fixes).
  - mmc: dw_mmc-rockchip: Add memory clock auto-gating support
    (stable-fixes).
  - mtd: spi-nor: core: avoid odd length/address writes in 8D-8D-8D
    mode (stable-fixes).
  - mtd: spi-nor: core: avoid odd length/address reads on 8D-8D-8D
    mode (stable-fixes).
  - mmc: dw_mmc-rockchip: use modern PM macros (stable-fixes).
  - commit f3a1015
  - hwmon: (pmbus/mp2975) Add error check for pmbus_read_word_data()
    return value (git-fixes).
  - drm/xe: Open-code GGTT MMIO access protection (git-fixes).
  - drm/xe/oa: Allow reading after disabling OA stream (git-fixes).
  - drm/radeon: apply state adjust rules to some additional HAINAN
    vairants (stable-fixes).
  - drm/amdgpu: apply state adjust rules to some additional HAINAN
    vairants (stable-fixes).
  - drm/amdgpu/gmc9.0: add bounds checking for cid (stable-fixes).
  - drm/amdgpu/mmhub4.1.0: add bounds checking for cid
    (stable-fixes).
  - drm/amdgpu/mmhub3.0: add bounds checking for cid (stable-fixes).
  - drm/amdgpu/mmhub3.0.2: add bounds checking for cid
    (stable-fixes).
  - drm/amdgpu/mmhub3.0.1: add bounds checking for cid
    (stable-fixes).
  - drm/amdgpu/mmhub2.3: add bounds checking for cid (stable-fixes).
  - drm/amdgpu/mmhub2.0: add bounds checking for cid (stable-fixes).
  - drm/amd: fix dcn 2.01 check (git-fixes).
  - drm/amd/display: Fix DisplayID not-found handling in
    parse_edid_displayid_vrr() (git-fixes).
  - drm/amd/display: Wrap dcn32_override_min_req_memclk() in
    DC_FP_{START, END} (git-fixes).
  - drm: Fix use-after-free on framebuffers and property blobs
    when calling drm_dev_unplug (git-fixes).
  - drm/imagination: Fix deadlock in soft reset sequence
    (git-fixes).
  - drm/i915/gt: Check set_default_submission() before deferencing
    (git-fixes).
  - firmware: arm_scpi: Fix device_node reference leak in probe path
    (git-fixes).
  - firmware: arm_ffa: Remove vm_id argument in ffa_rxtx_unmap()
    (git-fixes).
  - crypto: ccp - Fix leaking the same page twice (git-fixes).
  - drm/amd: Set num IP blocks to 0 if discovery fails
    (stable-fixes).
  - drm/i915/dsc: Add helper for writing DSC Selective Update ET
    parameters (stable-fixes).
  - drm/i915/dsc: Add Selective Update register definitions
    (stable-fixes).
  - drm/amdgpu: Fix use-after-free race in VM acquire
    (stable-fixes).
  - drm/amd/pm: remove invalid gpu_metrics.energy_accumulator on
    smu v13.0.x (stable-fixes).
  - drm/amd/display: Fallback to boot snapshot for dispclk
    (stable-fixes).
  - drm/amdgpu/vcn5: Add SMU dpm interface type (stable-fixes).
  - drm/bridge: ti-sn65dsi86: Add support for DisplayPort mode
    with HPD (stable-fixes).
  - drm/amd/display: Add pixel_clock to amd_pp_display_configuration
    (stable-fixes).
  - commit 63d8be5
  - Bluetooth: btusb: clamp SCO altsetting table indices
    (git-fixes).
  - Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite
    loop (git-fixes).
  - Bluetooth: btintel: serialize btintel_hw_error() with
    hci_req_sync_lock (git-fixes).
  - Bluetooth: L2CAP: Fix send LE flow credits in ACL link
    (git-fixes).
  - can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
    (git-fixes).
  - can: gw: fix OOB heap access in cgw_csum_crc8_rel() (git-fixes).
  - Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
    (git-fixes).
  - Bluetooth: hci_ll: Fix firmware leak on error path (git-fixes).
  - Bluetooth: MGMT: Fix dangling pointer on
    mgmt_add_adv_patterns_monitor_complete (git-fixes).
  - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to
    missing sock_hold (git-fixes).
  - Bluetooth: L2CAP: Validate PDU length before reading SDU length
    in l2cap_ecred_data_rcv() (git-fixes).
  - Bluetooth: L2CAP: Fix stack-out-of-bounds read in
    l2cap_ecred_conn_req (git-fixes).
  - Bluetooth: qca: fix ROM version reading on WCN3998 chips
    (git-fixes).
  - Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before
    access (git-fixes).
  - Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()
    (git-fixes).
  - Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
    (git-fixes).
  - Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user
    (git-fixes).
  - Bluetooth: HIDP: Fix possible UAF (git-fixes).
  - commit b7580ee
  - ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()
    (git-fixes).
  - ata: libata-core: disable LPM on ADATA SU680 SSD (stable-fixes).
  - Bluetooth: MGMT: Fix list corruption and UAF in command complete
    handlers (git-fixes).
  - Bluetooth: hci_sync: Fix hci_le_create_conn_sync (git-fixes).
  - Bluetooth: ISO: Fix defer tests being unstable (git-fixes).
  - Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy (git-fixes).
  - Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed
    SDU (git-fixes).
  - Bluetooth: LE L2CAP: Disconnect if received packet's SDU
    exceeds IMTU (git-fixes).
  - ACPI: processor: Fix previous acpi_processor_errata_piix4()
    fix (git-fixes).
  - ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2
    mixer interfaces (stable-fixes).
  - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK PM1503CDA
    (stable-fixes).
  - ata: libata-core: Add BRIDGE_OK quirk for QEMU drives
    (stable-fixes).
  - ASoC: amd: yc: Add ASUS EXPERTBOOK BM1503CDA to quirk table
    (stable-fixes).
  - ASoC: cs42l43: Report insert for exotic peripherals
    (stable-fixes).
  - ALSA: hda/realtek: Fix speaker pop on Star Labs StarFighter
    (stable-fixes).
  - ACPI: PM: Save NVS memory on Lenovo G70-35 (stable-fixes).
  - ACPI: OSI: Add DMI quirk for Acer Aspire One D255
    (stable-fixes).
  - commit 037720b
  - ceph: fix oops due to invalid pointer for kfree() in parse_longname() (CVE-2026-23201 bsc#1258337).
  - commit 6fc237a
  - Refresh patches.suse/nvme-add-partial_nid-quirk.patch.
  - commit b0acf62

++++ kernel-rt:

  - wifi: libertas: fix use-after-free in lbs_free_adapter()
    (CVE-2026-23281 bsc#1260464).
  - commit a8cb81b
  - PM: hibernate: Drain trailing zero pages on userspace restore
    (git-fixes).
  - platform/x86: ISST: Correct locked bit width (git-fixes).
  - platform/x86: intel-hid: disable wakeup_mode during hibernation
    (git-fixes).
  - platform/olpc: olpc-xo175-ec: Fix overflow error message to
    print inlen (git-fixes).
  - serial: 8250: Add late synchronize_irq() to shutdown to handle
    DW UART BUSY (git-fixes).
  - serial: 8250_pci: add support for the AX99100 (stable-fixes).
  - serial: uartlite: fix PM runtime usage count underflow on probe
    (git-fixes).
  - serial: 8250: Fix TX deadlock when using DMA (git-fixes).
  - spi: fix statistics allocation (git-fixes).
  - spi: fix use-after-free on controller registration failure
    (git-fixes).
  - wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is
    not enough headroom (git-fixes).
  - wifi: mac80211: fix NULL deref in mesh_matches_local()
    (git-fixes).
  - wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down
    (git-fixes).
  - wifi: mac80211: Fix static_branch_dec() underflow for
    aql_disable (git-fixes).
  - PM: runtime: Fix a race condition related to device removal
    (git-fixes).
  - soc: fsl: cpm1: qmc: Fix error check for devm_ioremap_resource()
    in qmc_qe_init_resources() (git-fixes).
  - soc: fsl: qbman: fix race condition in qman_destroy_fq
    (git-fixes).
  - soc: microchip: mpfs: Fix memory leak in
    mpfs_sys_controller_probe() (git-fixes).
  - USB: ezcap401 needs USB_QUIRK_NO_BOS to function on 10gbs usb
    speed (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Nova Lake -H
    (stable-fixes).
  - usb/core/quirks: Add Huawei ME906S-device to wakeup quirk
    (stable-fixes).
  - usb: xhci: Prevent interrupt storm on host controller error
    (HCE) (stable-fixes).
  - usb: misc: uss720: properly clean up reference in uss720_probe()
    (stable-fixes).
  - usb: image: mdc800: kill download URB on timeout (stable-fixes).
  - usb: mdc800: handle signal and read racing (stable-fixes).
  - usb: yurex: fix race in probe (stable-fixes).
  - USB: add QUIRK_NO_BOS for video capture several devices
    (stable-fixes).
  - staging: rtl8723bs: properly validate the data in
    rtw_get_ie_ex() (stable-fixes).
  - wifi: mac80211: set default WMM parameters on all links
    (stable-fixes).
  - USB: serial: f81232: fix incomplete serial port generation
    (stable-fixes).
  - commit 2fe4f6e
  - nfc: nci: fix circular locking dependency in nci_close_device
    (git-fixes).
  - pinctrl: mediatek: common: Fix probe failure for devices
    without EINT (git-fixes).
  - pinctrl: qcom: spmi-gpio: implement .get_direction()
    (git-fixes).
  - media: mc, v4l2: serialize REINIT and REQBUFS with
    req_queue_mutex (git-fixes).
  - i2c: pxa: defer reset on Armada 3700 when recovery is used
    (git-fixes).
  - i2c: fsi: Fix a potential leak in fsi_i2c_probe() (git-fixes).
  - i2c: cp2615: fix serial string NULL-deref at probe (git-fixes).
  - hwmon: axi-fan: don't use driver_override as IRQ name
    (git-fixes).
  - hwmon: (max6639) Fix pulses-per-revolution implementation
    (git-fixes).
  - hwmon: (pmbus/isl68137) Fix unchecked return value and use
    sysfs_emit() (git-fixes).
  - mmc: sdhci: fix timing selection for 1-bit bus width
    (git-fixes).
  - mmc: sdhci-pci-gli: fix GL9750 DMA write corruption (git-fixes).
  - mtd: rawnand: pl353: make sure optimal timings are applied
    (git-fixes).
  - mtd: rawnand: brcmnand: skip DMA during panic write (git-fixes).
  - mtd: rawnand: serialize lock/unlock against other NAND
    operations (git-fixes).
  - mtd: rawnand: cadence: Fix error check for dma_alloc_coherent()
    in cadence_nand_init() (git-fixes).
  - mtd: Avoid boot crash in RedBoot partition table parser
    (git-fixes).
  - mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN
    stations (stable-fixes).
  - NFC: nxp-nci: allow GPIOs to sleep (git-fixes).
  - net: usb: aqc111: Do not perform PM inside suspend callback
    (git-fixes).
  - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
    (git-fixes).
  - net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check
    (git-fixes).
  - net/rose: fix NULL pointer dereference in rose_transmit_link
    on reconnect (git-fixes).
  - mmc: dw_mmc-rockchip: Fix runtime PM support for internal
    phase support (git-fixes).
  - mmc: dw_mmc-rockchip: Add memory clock auto-gating support
    (stable-fixes).
  - mtd: spi-nor: core: avoid odd length/address writes in 8D-8D-8D
    mode (stable-fixes).
  - mtd: spi-nor: core: avoid odd length/address reads on 8D-8D-8D
    mode (stable-fixes).
  - mmc: dw_mmc-rockchip: use modern PM macros (stable-fixes).
  - commit f3a1015
  - hwmon: (pmbus/mp2975) Add error check for pmbus_read_word_data()
    return value (git-fixes).
  - drm/xe: Open-code GGTT MMIO access protection (git-fixes).
  - drm/xe/oa: Allow reading after disabling OA stream (git-fixes).
  - drm/radeon: apply state adjust rules to some additional HAINAN
    vairants (stable-fixes).
  - drm/amdgpu: apply state adjust rules to some additional HAINAN
    vairants (stable-fixes).
  - drm/amdgpu/gmc9.0: add bounds checking for cid (stable-fixes).
  - drm/amdgpu/mmhub4.1.0: add bounds checking for cid
    (stable-fixes).
  - drm/amdgpu/mmhub3.0: add bounds checking for cid (stable-fixes).
  - drm/amdgpu/mmhub3.0.2: add bounds checking for cid
    (stable-fixes).
  - drm/amdgpu/mmhub3.0.1: add bounds checking for cid
    (stable-fixes).
  - drm/amdgpu/mmhub2.3: add bounds checking for cid (stable-fixes).
  - drm/amdgpu/mmhub2.0: add bounds checking for cid (stable-fixes).
  - drm/amd: fix dcn 2.01 check (git-fixes).
  - drm/amd/display: Fix DisplayID not-found handling in
    parse_edid_displayid_vrr() (git-fixes).
  - drm/amd/display: Wrap dcn32_override_min_req_memclk() in
    DC_FP_{START, END} (git-fixes).
  - drm: Fix use-after-free on framebuffers and property blobs
    when calling drm_dev_unplug (git-fixes).
  - drm/imagination: Fix deadlock in soft reset sequence
    (git-fixes).
  - drm/i915/gt: Check set_default_submission() before deferencing
    (git-fixes).
  - firmware: arm_scpi: Fix device_node reference leak in probe path
    (git-fixes).
  - firmware: arm_ffa: Remove vm_id argument in ffa_rxtx_unmap()
    (git-fixes).
  - crypto: ccp - Fix leaking the same page twice (git-fixes).
  - drm/amd: Set num IP blocks to 0 if discovery fails
    (stable-fixes).
  - drm/i915/dsc: Add helper for writing DSC Selective Update ET
    parameters (stable-fixes).
  - drm/i915/dsc: Add Selective Update register definitions
    (stable-fixes).
  - drm/amdgpu: Fix use-after-free race in VM acquire
    (stable-fixes).
  - drm/amd/pm: remove invalid gpu_metrics.energy_accumulator on
    smu v13.0.x (stable-fixes).
  - drm/amd/display: Fallback to boot snapshot for dispclk
    (stable-fixes).
  - drm/amdgpu/vcn5: Add SMU dpm interface type (stable-fixes).
  - drm/bridge: ti-sn65dsi86: Add support for DisplayPort mode
    with HPD (stable-fixes).
  - drm/amd/display: Add pixel_clock to amd_pp_display_configuration
    (stable-fixes).
  - commit 63d8be5
  - Bluetooth: btusb: clamp SCO altsetting table indices
    (git-fixes).
  - Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite
    loop (git-fixes).
  - Bluetooth: btintel: serialize btintel_hw_error() with
    hci_req_sync_lock (git-fixes).
  - Bluetooth: L2CAP: Fix send LE flow credits in ACL link
    (git-fixes).
  - can: isotp: fix tx.buf use-after-free in isotp_sendmsg()
    (git-fixes).
  - can: gw: fix OOB heap access in cgw_csum_crc8_rel() (git-fixes).
  - Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb
    (git-fixes).
  - Bluetooth: hci_ll: Fix firmware leak on error path (git-fixes).
  - Bluetooth: MGMT: Fix dangling pointer on
    mgmt_add_adv_patterns_monitor_complete (git-fixes).
  - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to
    missing sock_hold (git-fixes).
  - Bluetooth: L2CAP: Validate PDU length before reading SDU length
    in l2cap_ecred_data_rcv() (git-fixes).
  - Bluetooth: L2CAP: Fix stack-out-of-bounds read in
    l2cap_ecred_conn_req (git-fixes).
  - Bluetooth: qca: fix ROM version reading on WCN3998 chips
    (git-fixes).
  - Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before
    access (git-fixes).
  - Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()
    (git-fixes).
  - Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
    (git-fixes).
  - Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user
    (git-fixes).
  - Bluetooth: HIDP: Fix possible UAF (git-fixes).
  - commit b7580ee
  - ACPI: EC: clean up handlers on probe failure in acpi_ec_setup()
    (git-fixes).
  - ata: libata-core: disable LPM on ADATA SU680 SSD (stable-fixes).
  - Bluetooth: MGMT: Fix list corruption and UAF in command complete
    handlers (git-fixes).
  - Bluetooth: hci_sync: Fix hci_le_create_conn_sync (git-fixes).
  - Bluetooth: ISO: Fix defer tests being unstable (git-fixes).
  - Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy (git-fixes).
  - Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed
    SDU (git-fixes).
  - Bluetooth: LE L2CAP: Disconnect if received packet's SDU
    exceeds IMTU (git-fixes).
  - ACPI: processor: Fix previous acpi_processor_errata_piix4()
    fix (git-fixes).
  - ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2
    mixer interfaces (stable-fixes).
  - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK PM1503CDA
    (stable-fixes).
  - ata: libata-core: Add BRIDGE_OK quirk for QEMU drives
    (stable-fixes).
  - ASoC: amd: yc: Add ASUS EXPERTBOOK BM1503CDA to quirk table
    (stable-fixes).
  - ASoC: cs42l43: Report insert for exotic peripherals
    (stable-fixes).
  - ALSA: hda/realtek: Fix speaker pop on Star Labs StarFighter
    (stable-fixes).
  - ACPI: PM: Save NVS memory on Lenovo G70-35 (stable-fixes).
  - ACPI: OSI: Add DMI quirk for Acer Aspire One D255
    (stable-fixes).
  - commit 037720b
  - ceph: fix oops due to invalid pointer for kfree() in parse_longname() (CVE-2026-23201 bsc#1258337).
  - commit 6fc237a
  - Refresh patches.suse/nvme-add-partial_nid-quirk.patch.
  - commit b0acf62

++++ libpng16:

  - added patches
    CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754)
    * libpng16-CVE-2026-33416-1.patch
    * libpng16-CVE-2026-33416-2.patch
    * libpng16-CVE-2026-33416-3.patch
    * libpng16-CVE-2026-33416-4.patch
    CVE-2026-33636: out-of-bounds read/write in the palette expansion on ARM Neon can lead to information leak and crashes (bsc#1260755)
    * libpng16-CVE-2026-33636.patch

++++ python313-core:

  - Add CVE-2026-4519-webbrowser-open-dashes.patch to reject
    leading dashes in webbrowser URLs (bsc#1260026, CVE-2026-4519,
    gh#python/cpython#143930).

++++ python313:

  - Add CVE-2026-4519-webbrowser-open-dashes.patch to reject
    leading dashes in webbrowser URLs (bsc#1260026, CVE-2026-4519,
    gh#python/cpython#143930).

------------------------------------------------------------------
------------------  2026-3-26  -  Mar 26 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - audit: add fchmodat2() to change attributes class (bsc#1259759 CVE-2025-71239).
  - commit 9071781
  - nfsd: Fix cred ref leak in nfsd_nl_threads_set_doit()
    (CVE-2026-23297 bsc#1260490).
  - commit b452925
  - Revert "drm/i915/display: Add quirk to skip retraining of dp link (bsc#1253129)."
    This reverts commit f73088654455665292f21760fa5dee5345f8a25f.
  - commit d6dafb4
  - xen/privcmd: restrict usage in unprivileged domU (bsc#1259707
    CVE-2026-31788).
  - commit ef16009
  - btrfs: only enforce free space tree if v1 cache is required
    for bs <  ps cases (bsc#1260459).
  - commit 8492959

++++ kernel-rt:

  - audit: add fchmodat2() to change attributes class (bsc#1259759 CVE-2025-71239).
  - commit 9071781
  - nfsd: Fix cred ref leak in nfsd_nl_threads_set_doit()
    (CVE-2026-23297 bsc#1260490).
  - commit b452925
  - Revert "drm/i915/display: Add quirk to skip retraining of dp link (bsc#1253129)."
    This reverts commit f73088654455665292f21760fa5dee5345f8a25f.
  - commit d6dafb4
  - xen/privcmd: restrict usage in unprivileged domU (bsc#1259707
    CVE-2026-31788).
  - commit ef16009
  - btrfs: only enforce free space tree if v1 cache is required
    for bs <  ps cases (bsc#1260459).
  - commit 8492959

++++ expat:

  - security update:
    * CVE-2026-32776: expat: libexpat: NULL pointer dereference when
    processing empty external parameter entities inside an entity
    declaration value (bsc#1259726)
  - Added patch expat-CVE-2026-32776.patch
    * CVE-2026-32777: expat: libexpat: denial of service due to
    infinite loop in DTD content parsing (bsc#1259711)
  - Added patch expat-CVE-2026-32777.patch
    * CVE-2026-32778: expat: libexpat: NULL pointer dereference in
    `setContext` on retry after an out-of-memory condition (bsc#1259729)
  - Added patch expat-CVE-2026-32778.patch

++++ openssl-3:

  - Security fixes:
    * CVE-2026-28387: Potential use-after-free in DANE client code
    (bsc#1260441)
    * CVE-2026-28388: NULL Pointer Dereference When Processing a
    Delta (bsc#1260442)
    * CVE-2026-28389: Possible NULL dereference when processing CMS
    KeyAgreeRecipientInfo (bsc#1260443)
    * CVE-2026-31789: Heap buffer overflow in hexadecimal conversion
    (bsc#1260444)
    * CVE-2026-31790: Incorrect failure handling in RSA KEM RSASVE
    encapsulation (bsc#1260445)
    * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS
    EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678)
    * Add	patches: openssl-CVE-2026-28387.patch
    openssl-CVE-2026-28388.patch openssl-CVE-2026-28388-tests.patch
    openssl-CVE-2026-28389.patch openssl-CVE-2026-31789.patch
    openssl-CVE-2026-31790.patch openssl-CVE-2026-31790-tests.patch
    openssl-CVE-2026-28390.patch
  - Fix NULL pointer dereference when processing an OCSP response
    * Add patch openssl-NULL-pointer-dereference-in-ocsp_find_signer_sk.patch

++++ xfsprogs:

  - update to 6.19.0
  - xfs_io: print more realtime subvolume related information in statfs
  - xfs_io: fix fsmap help
  - mkfs: fix log sunit automatic configuration
  - mkfs: fix protofile data corruption when in/out file block sizes don't match
  - libxfs: fix data corruption bug in libxfs_file_write
  - misc: fix a few memory leaks
  - mkfs.xfs fix sunit size on 512e and 4kN disks.
  - xfs_scrub_all: fix non-service-mode arguments to xfs_scrub
  - mkfs: remove unnecessary return value affectation
  - xfs: use blkdev_report_zones_cached()
  - include blkzoned.h in platform_defs.h
  - xfs_mdrestore: fix restoration on filesystems with 4k sectors
  - mkfs: quiet down warning about insufficient write zones
  - xfs_logprint: print log data to the screen in host-endian order
  - mkfs: set rtstart from user-specified dblocks

------------------------------------------------------------------
------------------  2026-3-25  -  Mar 25 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - x86/platform/uv: Handle deconfigured sockets (bsc#1260347).
  - commit d2d840b

++++ kernel-rt:

  - x86/platform/uv: Handle deconfigured sockets (bsc#1260347).
  - commit d2d840b

++++ freeipmi:

  - bsc#1260414 - CVE-2026-33554:
    freeipmi: improper memory handling and data validation can lead
    A ipmi-oem-fix-several-memory-out-of-bounds-errors.patch

++++ python313-core:

  - Add CVE-2025-13462-tarinfo-header-parse.patch which skips
    TarInfo DIRTYPE normalization during GNU long name handling
    (bsc#1259611, CVE-2025-13462).

++++ nvidia-open-driver-G06-signed:

  - adding 'ExcludeArch:    %ix86 s390x ppc64le' to no longer get
    autoclines by buildservice hoping that this wont't break RPM
    descriptions for -cuda variant again ...

++++ python313:

  - Add CVE-2025-13462-tarinfo-header-parse.patch which skips
    TarInfo DIRTYPE normalization during GNU long name handling
    (bsc#1259611, CVE-2025-13462).

------------------------------------------------------------------
------------------  2026-3-24  -  Mar 24 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - RDMA/umad: Reject negative data_len in ib_umad_write (CVE-2026-23243 bsc#1259797)
  - commit 52dd89a
  - RDMA/siw: Fix potential NULL pointer dereference in header processing (CVE-2026-23242 bsc#1259795)
  - commit 41503e8
  - tls: Fix race condition in tls_sw_cancel_work_tx()
    (CVE-2026-23240 bsc#1259484).
  - espintcp: Fix race condition in espintcp_close() (CVE-2026-23239
    bsc#1259485).
  - commit 3627070
  - drm/i915/display: Add module param to skip retraining of dp link (bsc#1253129).
  - commit 6c67fea
  - net/sched: cls_u32: use skb_header_pointer_careful()
    (CVE-2026-23204 bsc#1258340).
  - net: add skb_header_pointer_careful() helper (CVE-2026-23204
    bsc#1258340).
  - commit 096c21e
  - sched/debug: Fix updating of ppos on server write ops
    (git-fixes).
  - commit 70e8001

++++ kernel-rt:

  - RDMA/umad: Reject negative data_len in ib_umad_write (CVE-2026-23243 bsc#1259797)
  - commit 52dd89a
  - RDMA/siw: Fix potential NULL pointer dereference in header processing (CVE-2026-23242 bsc#1259795)
  - commit 41503e8
  - tls: Fix race condition in tls_sw_cancel_work_tx()
    (CVE-2026-23240 bsc#1259484).
  - espintcp: Fix race condition in espintcp_close() (CVE-2026-23239
    bsc#1259485).
  - commit 3627070
  - drm/i915/display: Add module param to skip retraining of dp link (bsc#1253129).
  - commit 6c67fea
  - net/sched: cls_u32: use skb_header_pointer_careful()
    (CVE-2026-23204 bsc#1258340).
  - net: add skb_header_pointer_careful() helper (CVE-2026-23204
    bsc#1258340).
  - commit 096c21e
  - sched/debug: Fix updating of ppos on server write ops
    (git-fixes).
  - commit 70e8001

------------------------------------------------------------------
------------------  2026-3-23  -  Mar 23 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: smartpqi: Fix memory leak in pqi_report_phys_luns()
    (git-fixes, jsc#PED-15042).
  - commit 02cf1d1
  - Update
    patches.suse/crypto-ecdsa-make-ecdsa_ecc_ctx_deinit-to-zeroize-th.patch
    (jsc#PED-15986,bsc#1222768).
  - commit bf86f55
  - Update
    patches.suse/crypto-ecdh-make-ecdh_compute_value-to-zeroize-the-p.patch
    (jsc#PED-15986,bsc#1222768).
  - commit 2edc156
  - Update
    patches.suse/crypto-seqiv-flag-instantiations-as-fips-compliant.patch
    (jsc#PED-15986,bsc#1194778).
  - commit 0c9d6c5
  - Update patches.suse/crypto-dh-implement-FIPS-PCT.patch
    (jsc#PED-15986,bsc#1191256,bsc#1207184).
  - commit 6e61d6f
  - Update patches.suse/crypto-ecdh-implement-FIPS-PCT.patch
    (jsc#PED-15986,bsc#1191256,bsc#1207184).
  - commit 00c3bc1
  - Update
    patches.suse/0002-crypto-populate-downstream-list-of-drivers-unapprove.patch
    (jsc#PED-15986,bsc#1191270).
  - commit ceaee7e
  - Update
    patches.suse/0001-crypto-implement-downstream-solution-for-disabling-d.patch
    (jsc#PED-15986,bsc#1191270).
  - commit c3732b7
  - soc: rockchip: grf: Add missing of_node_put() when returning (git-fixes)
  - commit e54adb5
  - add mainline tag to a mana patch
  - commit cb76aaf

++++ kernel-rt:

  - scsi: smartpqi: Fix memory leak in pqi_report_phys_luns()
    (git-fixes, jsc#PED-15042).
  - commit 02cf1d1
  - Update
    patches.suse/crypto-ecdsa-make-ecdsa_ecc_ctx_deinit-to-zeroize-th.patch
    (jsc#PED-15986,bsc#1222768).
  - commit bf86f55
  - Update
    patches.suse/crypto-ecdh-make-ecdh_compute_value-to-zeroize-the-p.patch
    (jsc#PED-15986,bsc#1222768).
  - commit 2edc156
  - Update
    patches.suse/crypto-seqiv-flag-instantiations-as-fips-compliant.patch
    (jsc#PED-15986,bsc#1194778).
  - commit 0c9d6c5
  - Update patches.suse/crypto-dh-implement-FIPS-PCT.patch
    (jsc#PED-15986,bsc#1191256,bsc#1207184).
  - commit 6e61d6f
  - Update patches.suse/crypto-ecdh-implement-FIPS-PCT.patch
    (jsc#PED-15986,bsc#1191256,bsc#1207184).
  - commit 00c3bc1
  - Update
    patches.suse/0002-crypto-populate-downstream-list-of-drivers-unapprove.patch
    (jsc#PED-15986,bsc#1191270).
  - commit ceaee7e
  - Update
    patches.suse/0001-crypto-implement-downstream-solution-for-disabling-d.patch
    (jsc#PED-15986,bsc#1191270).
  - commit c3732b7
  - soc: rockchip: grf: Add missing of_node_put() when returning (git-fixes)
  - commit e54adb5
  - add mainline tag to a mana patch
  - commit cb76aaf

++++ util-linux-systemd:

  - fdisk: Fix possible partition overlay and data corruption if EBR
    gap is missing (boo#1222465,
    util-linux-libfdisk-ebr-missing-gap-1.patch,
    util-linux-tests-fdisk-ebr-missing-gap-1.patch,
    util-linux-tests-fdisk-ebr-missing-gap-2.patch,
    util-linux-libfdisk-ebr-missing-gap-2.patch,
    util-linux-tests-fdisk-ebr-missing-gap-3.patch).

++++ util-linux:

  - fdisk: Fix possible partition overlay and data corruption if EBR
    gap is missing (boo#1222465,
    util-linux-libfdisk-ebr-missing-gap-1.patch,
    util-linux-tests-fdisk-ebr-missing-gap-1.patch,
    util-linux-tests-fdisk-ebr-missing-gap-2.patch,
    util-linux-libfdisk-ebr-missing-gap-2.patch,
    util-linux-tests-fdisk-ebr-missing-gap-3.patch).

++++ cairo:

  - Migrate to xz compression and manual service run

++++ python313-core:

  - Add CVE-2026-4224-expat-unbound-C-recursion.patch avoiding
    unbound C recursion in conv_content_model in pyexpat.c
    (bsc#1259735, CVE-2026-4224).
  - Add CVE-2026-3644-cookies-Morsel-update-II.patch to reject
    control characters in http.cookies.Morsel.update() and
    http.cookies.BaseCookie.js_output (bsc#1259734, CVE-2026-3644).

++++ python313:

  - Add CVE-2026-4224-expat-unbound-C-recursion.patch avoiding
    unbound C recursion in conv_content_model in pyexpat.c
    (bsc#1259735, CVE-2026-4224).
  - Add CVE-2026-3644-cookies-Morsel-update-II.patch to reject
    control characters in http.cookies.Morsel.update() and
    http.cookies.BaseCookie.js_output (bsc#1259734, CVE-2026-3644).

++++ tar:

  - Fix bsc#1246399 / CVE-2025-45582.
  - Fix bsc#1246607.
  - Add patch:
    * CVE-2025-45582.patch
    * tar-fix-deletion-from-archive.patch
  - Refresh patch:
    * tar-fix-extract-unlink.patch

------------------------------------------------------------------
------------------  2026-3-22  -  Mar 22 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - bpf, test_run: Subtract size of xdp_frame from allowed metadata
    size (CVE-2026-23140 bsc#1258305).
  - commit d6a4451

++++ kernel-rt:

  - bpf, test_run: Subtract size of xdp_frame from allowed metadata
    size (CVE-2026-23140 bsc#1258305).
  - commit d6a4451

++++ openssl-3:

  - Security fix:
    * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652)
    Added patch openssl-CVE-2026-2673.patch
    Added patch openssl-crypto-mem.c-factor-out-memory-allocation-failure-reporting.patch
    Added patch openssl-Add-array-memory-allocation-routines.patch

------------------------------------------------------------------
------------------  2026-3-20  -  Mar 20 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: scsi_transport_sas: Fix the maximum channel scanning issue
    (bsc#1255687, git-fixes).
  - commit d70069d
  - scsi: hisi_sas: Fix NULL pointer exception during user_scan()
    (bsc#1255687).
  - commit 43112c2
  - bpf, btf: Enforce destructor kfunc type with CFI (bsc#1259955).
  - selftests/bpf: Use the correct destructor kfunc type
    (bsc#1259955).
  - bpf: crypto: Use the correct destructor kfunc type (bsc#1259955).
  - commit 2fdc072

++++ kernel-rt:

  - scsi: scsi_transport_sas: Fix the maximum channel scanning issue
    (bsc#1255687, git-fixes).
  - commit d70069d
  - scsi: hisi_sas: Fix NULL pointer exception during user_scan()
    (bsc#1255687).
  - commit 43112c2
  - bpf, btf: Enforce destructor kfunc type with CFI (bsc#1259955).
  - selftests/bpf: Use the correct destructor kfunc type
    (bsc#1259955).
  - bpf: crypto: Use the correct destructor kfunc type (bsc#1259955).
  - commit 2fdc072

++++ nghttp2:

  - added patches
    CVE-2026-27135: assertion failure due to missing state validation can lead to DoS (bsc#1259845)
    * nghttp2-CVE-2026-27135.patch

++++ rust-keylime:

  - Suggests only the IMA policy package, and keep it as example (bsc#1259963)
  - Add Cargo_toml.patch to re-generate TSS bindings
  - Update to version 0.2.9+8:
    * build(deps): bump thiserror from 2.0.17 to 2.0.18
    * build(deps): bump docker/login-action from 3 to 4
    * build(deps): bump docker/metadata-action from 5 to 6
    * Remove generate-bindings feature from tss-esapi
    * Use port constants instead of hardcoded values in tests
    * push-attestation: Use registrar TLS port when TLS is enabled
    * build(deps): bump docker/build-push-action from 6 to 7
    * build(deps): bump actions/upload-artifact from 6 to 7
    * dist: Make the services to conflict with each other
    * Bump version to 0.2.9
    * build(deps): bump mockoon/cli-action from 2 to 3
    * cargo: Bump tracing_subscriber to version 0.3.20
    * cargo: Bump time to version 0.3.47
    * build(deps): bump http from 1.3.1 to 1.4.0
    * Update reqwest from 0.12 to 0.13
    * build(deps): bump serde from 1.0.219 to 1.0.228
    * auth: Load CA certificate in authentication client
    * packit: Add missing e2e tests
    * registrar: Rename insecure option to disable_tls
    * push-attestation: Drop self-signed mTLS certificate generation
    * config: Add missing config options to keylime-agent.conf
    * config: Add support for "default" in registrar_api_versions option
    * config: Add support for "default" in registrar_tls_ca_cert option
    * config: Drop unused config options and constants
    * push-attestation: Drop support for mTLS to registrar
    * push-attestation: Drop mTLS support and require PoP authentication
    * build(deps): bump clap from 4.5.45 to 4.5.54
    * build(deps): bump actix-web from 4.11.0 to 4.12.1
    * auth: Reuse existing ContextInfo to avoid duplicate TPM objects
    * resilient_client: Reauthenticate if a 403 error is received

++++ selinux-policy:

  - Update to version 20250627+git355.5249ba7d5:
    * Revert "Define file equivalency for /var/opt" (bsc#1259704)
    * Make stalld stalld_var_run_t labeling rules more generic (bsc#1259438)

------------------------------------------------------------------
------------------  2026-3-19  -  Mar 19 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - kabi/severities: Clean up unused entries
    Clean up kABI severity rules that ksymvers reports as unused.
    * kabi/severities:29: WARNING: Severity rule 'MODULE drivers/block/rbd PASS' is unused
    kabi/severities:30: WARNING: Severity rule 'MODULE fs/ceph PASS' is unused
    The modules are present but don't export any symbols. Remove the entries.
    * kabi/severities:31: WARNING: Severity rule 'MODULE drivers/target/target_core_rbd PASS' is unused
    The entry refers to a non-existent module. Remove the entry.
    * kabi/severities:37: WARNING: Severity rule 'SYMBOL get_dev_data PASS' is unused
    Mainline commit fb1b6955bbf3 ("iommu/amd: Unexport get_dev_data()")
    unexported the function and commit 05a0542b456e ("iommu/amd: Store
    dev_data as device iommu private data") subsequently removed it. The
    entry is no longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:43: WARNING: Severity rule 'MODULE net/iucv/* PASS' is unused
    The entry is a module pattern but the iucv support is built into vmlinux.
    Change the pattern to match the iucv_* and __iucv_* symbols instead.
    * kabi/severities:81: WARNING: Severity rule 'MODULE drivers/cxl/core/* PASS' is unused
    The pattern is never matched because it is preceded by the superset
    pattern 'MODULE drivers/cxl/* PASS'. Remove the superfluous entry.
    * kabi/severities:82: WARNING: Severity rule 'MODULE include/linux/cxl-events.h PASS' is unused
    The pattern doesn't make sense because matching on a header file is not
    supported. Remove the entry.
    * kabi/severities:121: WARNING: Severity rule 'SYMBOL hv_init_clocksource PASS' is unused
    kabi/severities:122: WARNING: Severity rule 'SYMBOL mdio_bus_init PASS' is unused
    kabi/severities:123: WARNING: Severity rule 'SYMBOL seg6_hmac_net_init PASS' is unused
    kabi/severities:124: WARNING: Severity rule 'SYMBOL seg6_hmac_init PASS' is unused
    kabi/severities:125: WARNING: Severity rule 'SYMBOL tick_nohz_full_setup PASS' is unused
    kabi/severities:126: WARNING: Severity rule 'SYMBOL xen_xlate_map_ballooned_pages PASS' is unused
    kabi/severities:127: WARNING: Severity rule 'SYMBOL xfrm4_protocol_init PASS' is unused
    These entries were necessary because the specified symbols were
    previously marked as both exported and __init. This issue was resolved
    upstream through several commits, which were also backported to SLE,
    requiring us to mark the symbols as ignored from the kABI perspective.
    Since SL-16.0 began with all relevant fixes already present, these
    entries are no longer needed, therefore remove them.
    * kabi/severities:130: WARNING: Severity rule 'SYMBOL rt5682_headset_detect PASS' is unused
    This is a similar case. Mainline commit 4045daf0fa87 ("ASoC: rt5682: Fix
    deadlock on resume") unexported the specified symbol. To backport the
    fix, the symbol needed to be marked as ignored. The entry is no longer
    relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:160: WARNING: Severity rule 'MODULE drivers/gpu/drm/vmwgfx/* PASS' is unused
    The vmwgfx module previously had some exported symbols but mainline
    commit a309c7194e8a ("drm/vmwgfx: Remove rcu locks from user resources")
    removed the last of these symbols. Remove the now unnecessary entry.
    * kabi/severities:163: WARNING: Severity rule 'MODULE io_uring/* PASS' is unused
    This entry is a module pattern but the io_uring support is built into
    vmlinux. It doesn't appear this entry is currently needed, therefore
    remove it.
    * kabi/severities:170: WARNING: Severity rule 'SYMBOL retbleed_untrain_ret PASS' is unused
    kabi/severities:171: WARNING: Severity rule 'SYMBOL srso_untrain_ret PASS' is unused
    Mainline commit eb54be26b0d2 ("x86/srso: Unexport untraining functions")
    unexported the specified symbols. The entry is no longer relevant in
    SL-16.0 and later, therefore remove it.
    * kabi/severities:174: WARNING: Severity rule 'SYMBOL tasdevice_prmg_calibdata_load PASS' is unused
    Mainline commit b195acf5266d ("ASoC: tas2781: Fix wrong loading
    calibrated data sequence") removed the specified symbol. The entry is no
    longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:177: WARNING: Severity rule 'SYMBOL pci_create_ims_domain PASS' is unused
    Mainline commit b966b1102871 ("Revert "PCI/MSI: Provide IMS (Interrupt
    Message Store) support"") removed the specified symbol. The entry is no
    longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:178: WARNING: Severity rule 'SYMBOL pci_ims_alloc_irq PASS' is unused
    kabi/severities:179: WARNING: Severity rule 'SYMBOL pci_ims_free_irq PASS' is unused
    Mainline commit 1794808fb1b3 ("Revert "PCI/MSI: Provide
    pci_ims_alloc/free_irq()"") removed the specified symbols. The entry is
    no longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:190: WARNING: Severity rule 'SYMBOL tlbstate_untag_mask PASS' is unused
    Downstream commit 405fa97a73d8 ("config: Disable LAM on x86
    (bsc#1217845)") unset CONFIG_ADDRESS_MASKING and marked the specified
    symbol as ignored from the kABI perspective. The entry is no longer
    relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:193: WARNING: Severity rule 'SYMBOL mmio_stale_data_clear PASS' is unused
    Mainline commit d9b79111fd99 ("x86/bugs: Rename mmio_stale_data_clear to
    cpu_buf_vm_clear") renamed the specified symbol, and to backport the
    patch, the symbol was marked as ignored from the kABI perspective. The
    entry is no longer relevant in SL-16.0 and later, therefore remove it.
  - commit 177fa7d
  - x86/vmware: Fix hypercall clobbers (CVE-2026-23215 bsc#1258476).
  - commit 6fb22e1

++++ kernel-rt:

  - kabi/severities: Clean up unused entries
    Clean up kABI severity rules that ksymvers reports as unused.
    * kabi/severities:29: WARNING: Severity rule 'MODULE drivers/block/rbd PASS' is unused
    kabi/severities:30: WARNING: Severity rule 'MODULE fs/ceph PASS' is unused
    The modules are present but don't export any symbols. Remove the entries.
    * kabi/severities:31: WARNING: Severity rule 'MODULE drivers/target/target_core_rbd PASS' is unused
    The entry refers to a non-existent module. Remove the entry.
    * kabi/severities:37: WARNING: Severity rule 'SYMBOL get_dev_data PASS' is unused
    Mainline commit fb1b6955bbf3 ("iommu/amd: Unexport get_dev_data()")
    unexported the function and commit 05a0542b456e ("iommu/amd: Store
    dev_data as device iommu private data") subsequently removed it. The
    entry is no longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:43: WARNING: Severity rule 'MODULE net/iucv/* PASS' is unused
    The entry is a module pattern but the iucv support is built into vmlinux.
    Change the pattern to match the iucv_* and __iucv_* symbols instead.
    * kabi/severities:81: WARNING: Severity rule 'MODULE drivers/cxl/core/* PASS' is unused
    The pattern is never matched because it is preceded by the superset
    pattern 'MODULE drivers/cxl/* PASS'. Remove the superfluous entry.
    * kabi/severities:82: WARNING: Severity rule 'MODULE include/linux/cxl-events.h PASS' is unused
    The pattern doesn't make sense because matching on a header file is not
    supported. Remove the entry.
    * kabi/severities:121: WARNING: Severity rule 'SYMBOL hv_init_clocksource PASS' is unused
    kabi/severities:122: WARNING: Severity rule 'SYMBOL mdio_bus_init PASS' is unused
    kabi/severities:123: WARNING: Severity rule 'SYMBOL seg6_hmac_net_init PASS' is unused
    kabi/severities:124: WARNING: Severity rule 'SYMBOL seg6_hmac_init PASS' is unused
    kabi/severities:125: WARNING: Severity rule 'SYMBOL tick_nohz_full_setup PASS' is unused
    kabi/severities:126: WARNING: Severity rule 'SYMBOL xen_xlate_map_ballooned_pages PASS' is unused
    kabi/severities:127: WARNING: Severity rule 'SYMBOL xfrm4_protocol_init PASS' is unused
    These entries were necessary because the specified symbols were
    previously marked as both exported and __init. This issue was resolved
    upstream through several commits, which were also backported to SLE,
    requiring us to mark the symbols as ignored from the kABI perspective.
    Since SL-16.0 began with all relevant fixes already present, these
    entries are no longer needed, therefore remove them.
    * kabi/severities:130: WARNING: Severity rule 'SYMBOL rt5682_headset_detect PASS' is unused
    This is a similar case. Mainline commit 4045daf0fa87 ("ASoC: rt5682: Fix
    deadlock on resume") unexported the specified symbol. To backport the
    fix, the symbol needed to be marked as ignored. The entry is no longer
    relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:160: WARNING: Severity rule 'MODULE drivers/gpu/drm/vmwgfx/* PASS' is unused
    The vmwgfx module previously had some exported symbols but mainline
    commit a309c7194e8a ("drm/vmwgfx: Remove rcu locks from user resources")
    removed the last of these symbols. Remove the now unnecessary entry.
    * kabi/severities:163: WARNING: Severity rule 'MODULE io_uring/* PASS' is unused
    This entry is a module pattern but the io_uring support is built into
    vmlinux. It doesn't appear this entry is currently needed, therefore
    remove it.
    * kabi/severities:170: WARNING: Severity rule 'SYMBOL retbleed_untrain_ret PASS' is unused
    kabi/severities:171: WARNING: Severity rule 'SYMBOL srso_untrain_ret PASS' is unused
    Mainline commit eb54be26b0d2 ("x86/srso: Unexport untraining functions")
    unexported the specified symbols. The entry is no longer relevant in
    SL-16.0 and later, therefore remove it.
    * kabi/severities:174: WARNING: Severity rule 'SYMBOL tasdevice_prmg_calibdata_load PASS' is unused
    Mainline commit b195acf5266d ("ASoC: tas2781: Fix wrong loading
    calibrated data sequence") removed the specified symbol. The entry is no
    longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:177: WARNING: Severity rule 'SYMBOL pci_create_ims_domain PASS' is unused
    Mainline commit b966b1102871 ("Revert "PCI/MSI: Provide IMS (Interrupt
    Message Store) support"") removed the specified symbol. The entry is no
    longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:178: WARNING: Severity rule 'SYMBOL pci_ims_alloc_irq PASS' is unused
    kabi/severities:179: WARNING: Severity rule 'SYMBOL pci_ims_free_irq PASS' is unused
    Mainline commit 1794808fb1b3 ("Revert "PCI/MSI: Provide
    pci_ims_alloc/free_irq()"") removed the specified symbols. The entry is
    no longer relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:190: WARNING: Severity rule 'SYMBOL tlbstate_untag_mask PASS' is unused
    Downstream commit 405fa97a73d8 ("config: Disable LAM on x86
    (bsc#1217845)") unset CONFIG_ADDRESS_MASKING and marked the specified
    symbol as ignored from the kABI perspective. The entry is no longer
    relevant in SL-16.0 and later, therefore remove it.
    * kabi/severities:193: WARNING: Severity rule 'SYMBOL mmio_stale_data_clear PASS' is unused
    Mainline commit d9b79111fd99 ("x86/bugs: Rename mmio_stale_data_clear to
    cpu_buf_vm_clear") renamed the specified symbol, and to backport the
    patch, the symbol was marked as ignored from the kABI perspective. The
    entry is no longer relevant in SL-16.0 and later, therefore remove it.
  - commit 177fa7d
  - x86/vmware: Fix hypercall clobbers (CVE-2026-23215 bsc#1258476).
  - commit 6fb22e1

------------------------------------------------------------------
------------------  2026-3-18  -  Mar 18 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains (CVE-2026-23187 bsc#1258330)
  - commit 2110258
  - KVM: x86: Introduce KVM_X86_QUIRK_VMCS12_ALLOW_FREEZE_IN_SMM
    (git-fixes).
  - commit 7b41d14
  - KVM: x86: synthesize CPUID bits only if CPU capability is set
    (bsc#1257511).
  - commit 798c0f2
  - Refresh
    patches.suse/mm-page_alloc-thp-prevent-reclaim-for-__GFP_THISNODE-THP-a.patch.
  - Refresh
    patches.suse/scsi-lpfc-Rework-lpfc_sli4_fcf_rr_next_index_get.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.13.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-Speed-in-SFP-print-information.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-bsg-interface-to-support-firmware-i.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-load-flash-firmware-mailbox-support.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-support-for-64G-SFP-speed.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Allow-recovery-for-tape-devices.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Delay-module-unload-while-fabric-scan-i.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Fix-bsg_done-causing-double-free.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Free-sp-in-error-path-to-fix-system-cra.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Query-FW-again-before-proceeding-with-l.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Update-version-to-10.02.10.100-k.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Validate-MCU-signature-before-executing.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Validate-sp-before-freeing-associated-m.patch.
  - commit 4563ee6
  - nvme: fix memory leak in quirks_param_set() (bsc#1243208).
  - nvme: add support for dynamic quirk configuration via module
    parameter (bsc#1243208).
  - nvme: expose active quirks in sysfs (bsc#1243208).
    Refresh:
  - patches.suse/nvme-add-partial_nid-quirk.patch
  - commit 422f1b7

++++ kernel-rt:

  - pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains (CVE-2026-23187 bsc#1258330)
  - commit 2110258
  - KVM: x86: Introduce KVM_X86_QUIRK_VMCS12_ALLOW_FREEZE_IN_SMM
    (git-fixes).
  - commit 7b41d14
  - KVM: x86: synthesize CPUID bits only if CPU capability is set
    (bsc#1257511).
  - commit 798c0f2
  - Refresh
    patches.suse/mm-page_alloc-thp-prevent-reclaim-for-__GFP_THISNODE-THP-a.patch.
  - Refresh
    patches.suse/scsi-lpfc-Rework-lpfc_sli4_fcf_rr_next_index_get.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.13.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-Speed-in-SFP-print-information.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-bsg-interface-to-support-firmware-i.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-load-flash-firmware-mailbox-support.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Add-support-for-64G-SFP-speed.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Allow-recovery-for-tape-devices.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Delay-module-unload-while-fabric-scan-i.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Fix-bsg_done-causing-double-free.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Free-sp-in-error-path-to-fix-system-cra.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Query-FW-again-before-proceeding-with-l.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Update-version-to-10.02.10.100-k.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Validate-MCU-signature-before-executing.patch.
  - Refresh
    patches.suse/scsi-qla2xxx-Validate-sp-before-freeing-associated-m.patch.
  - commit 4563ee6
  - nvme: fix memory leak in quirks_param_set() (bsc#1243208).
  - nvme: add support for dynamic quirk configuration via module
    parameter (bsc#1243208).
  - nvme: expose active quirks in sysfs (bsc#1243208).
    Refresh:
  - patches.suse/nvme-add-partial_nid-quirk.patch
  - commit 422f1b7

++++ python313-core:

  - Fix changelog

++++ libzypp:

  - Fix preloader not caching packages from arch specific subrepos
    (bsc#1253740)
  - Deprioritize invalid mirrors (fixes openSUSE/zypper#636)
  - version 17.38.5 (35)

++++ nvidia-open-driver-G06-signed:

  - do not set ExclusiveArch in order to fix RPM description for -cuda
    variant (bsc#1259719)
  - improved RPM description for -cuda and non-cuda variant

++++ python313:

  - Fix changelog

++++ python-PyJWT:

  - Skip failing tests (gh#jpadilla/pyjwt#1153)
  - Update to 2.12.1:
  - Add missing typing_extensions dependency for Python < 3.11 in
    [#1150]
  - Update to 2.12.0:
  - Fixed
  - Annotate PyJWKSet.keys for pyright by @tamird in #1134
  - Close HTTPError response to prevent ResourceWarning on
    Python 3.14 by @veeceey in #1133
  - Do not keep algorithms dict in PyJWK instances by @akx in
    [#1143]
  - Validate the crit (Critical) Header Parameter defined in
    RFC 7515 §4.1.11. by @dmbs335 in GHSA-752w-5fwx-jx9f
    (bsc#1259616, CVE-2026-32597).
  - Use PyJWK algorithm when encoding without explicit
    algorithm in #1148
  - Added
  - Docs: Add PyJWKClient API reference and document the
    two-tier caching system (JWK Set cache and signing key LRU
    cache). v2.11.0
  - Fixed
  - Enforce ECDSA curve validation per RFC 7518 Section 3.4.
  - Fix build system warnings by @kurtmckee in #1105
  - Validate key against allowed types for Algorithm family in
    [#964]
  - Add iterator for JWKSet in #1041
  - Validate iss claim is a string during encoding and decoding
    by @pachewise in #1040
  - Improve typing/logic for options in decode, decode_complete
    by @pachewise in #1045
  - Declare float supported type for lifespan and timeout by
    @nikitagashkov in #1068
  - Fix SyntaxWarnings/DeprecationWarnings caused by invalid
    escape sequences by @kurtmckee in #1103
  - Development: Build a shared wheel once to speed up test
    suite setup times by @kurtmckee in #1114
  - Development: Test type annotations across all supported
    Python versions, increase the strictness of the type
    checking, and remove the mypy pre-commit hook by @kurtmckee
    in #1112
  - Added
  - Support Python 3.14, and test against PyPy 3.10 and 3.11 by
    @kurtmckee in #1104
  - Development: Migrate to build to test package building in
    CI by @kurtmckee in #1108
  - Development: Improve coverage config and eliminate unused
    test suite code by @kurtmckee in #1115
  - Docs: Standardize CHANGELOG links to PRs by @kurtmckee in
    [#1110]
  - Docs: Fix Read the Docs builds by @kurtmckee in #1111
  - Docs: Add example of using leeway with nbf by @djw8605 in
    [#1034]
  - Docs: Refactored docs with autodoc; added PyJWS and
    jwt.algorithms docs by @pachewise in #1045
  - Docs: Documentation improvements for "sub" and "jti" claims
    by @cleder in #1088
  - Development: Add pyupgrade as a pre-commit hook by
    @kurtmckee in #1109
  - Add minimum key length validation for HMAC and RSA keys
    (CWE-326). Warns by default via InsecureKeyLengthWarning
    when keys are below minimum recommended lengths per RFC
    7518 Section 3.2 (HMAC) and NIST SP 800-131A (RSA). Pass
    enforce_minimum_key_length=True in options to PyJWT or
    PyJWS to raise InvalidKeyError instead.
  - Refactor PyJWT to own an internal PyJWS instance instead of
    calling global api_jws functions.

------------------------------------------------------------------
------------------  2026-3-17  -  Mar 17 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
    (CVE-2026-23231 bsc#1259188).
  - commit febac42
  - s390/ctcm: Fix double-kfree (CVE-2025-40253 bsc#1255084).
  - commit a8fc62d
  - Update config files (bsc#1254307).
  - commit 3e059ac
  - s390/ipl: Clear SBP flag when bootprog is set (bsc#1258175).
  - s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP (bsc#1254306).
  - s390/cio: Update purge function to unregister the unused
    subchannels (bsc#1254214).
  - commit 9226bc5
  - l2tp: avoid one data-race in l2tp_tunnel_del_work() (CVE-2026-23120 bsc#1258280)
  - commit 6883716
  - l2tp: Fix memleak in l2tp_udp_encap_recv() (CVE-2026-23072 bsc#1257708)
  - commit 9859402
  - Use unified maintainers' email address
  - commit ab708b6
  - 9p/xen: protect xen_9pfs_front_free against concurrent calls
    (git-fixes).
  - commit bff5c7c
  - vhost: fix caching attributes of MMIO regions by setting them
    explicitly (git-fixes).
  - commit ce01fc5
  - vmw_vsock: bypass false-positive Wnonnull warning with gcc-16
    (git-fixes).
  - commit 3b72ad4
  - xenbus: Use .freeze/.thaw to handle xenbus devices (git-fixes).
  - commit e219626
  - scsi: target: target_core_configfs: Add length check to avoid
    buffer overflow (CVE-2025-39998 bsc#1252073).
  - commit a088008

++++ kernel-rt:

  - netfilter: nf_tables: fix use-after-free in nf_tables_addchain()
    (CVE-2026-23231 bsc#1259188).
  - commit febac42
  - s390/ctcm: Fix double-kfree (CVE-2025-40253 bsc#1255084).
  - commit a8fc62d
  - Update config files (bsc#1254307).
  - commit 3e059ac
  - s390/ipl: Clear SBP flag when bootprog is set (bsc#1258175).
  - s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP (bsc#1254306).
  - s390/cio: Update purge function to unregister the unused
    subchannels (bsc#1254214).
  - commit 9226bc5
  - l2tp: avoid one data-race in l2tp_tunnel_del_work() (CVE-2026-23120 bsc#1258280)
  - commit 6883716
  - l2tp: Fix memleak in l2tp_udp_encap_recv() (CVE-2026-23072 bsc#1257708)
  - commit 9859402
  - Use unified maintainers' email address
  - commit ab708b6
  - 9p/xen: protect xen_9pfs_front_free against concurrent calls
    (git-fixes).
  - commit bff5c7c
  - vhost: fix caching attributes of MMIO regions by setting them
    explicitly (git-fixes).
  - commit ce01fc5
  - vmw_vsock: bypass false-positive Wnonnull warning with gcc-16
    (git-fixes).
  - commit 3b72ad4
  - xenbus: Use .freeze/.thaw to handle xenbus devices (git-fixes).
  - commit e219626
  - scsi: target: target_core_configfs: Add length check to avoid
    buffer overflow (CVE-2025-39998 bsc#1252073).
  - commit a088008

++++ python313-core:

  - Adapt %suse_version checks to support new %suse_version design for
    16.1 and following (jsc#PED-15850)

++++ python313:

  - Adapt %suse_version checks to support new %suse_version design for
    16.1 and following (jsc#PED-15850)

++++ python-tornado6:

  - CVE-2026-31958: parsing large multipart bodies with many parts can cause a
    denial of service (bsc#1259553)
    * added CVE-2026-31958.patch
  - VUL-0: incomplete validation of cookie attributes allows for injection of
    user-controlled values in other cookie attributes (bsc#1259630)
    * added VUL-0-cookie-attribute-validation.patch

++++ ovmf:

  - Update mbedtls to 3.6.5 to fix CVE-2025-59438 (bsc#1252441)
  - Requires Mbed TLS 3.6.5 or higher to mitigate vulnerability.
  - Add backported patches to support MbedTLS 3.6.5 for ARM32
  - ovmf-CryptoPkg-EDK2-code-update-for-Mbedtls-3.6.5.patch
    c2147ed33a CryptoPkg: EDK2 code update for Mbedtls 3.6.5.
  - ovmf-CryptoPkg-MbedTls-not-support-content-data-signature.patch
    95838ecb96 CryptoPkg: MbedTls not support content data signature.
  - ovmf-CryptoPkg-Override-mbedtls_config-header.patch
    77f21b70fd CryptoPkg: Override mbedtls_config header
  - Add patch to fix ARM32 build failures
  - ovmf-CryptoPkg-Library-MbedTlsLib-Add-compiler-defines-fo.patch

------------------------------------------------------------------
------------------  2026-3-16  -  Mar 16 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: fnic: Fix missing DMA mapping error in fnic_send_frame()
    (jsc#PED-15441).
  - scsi: fnic: Turn off FDMI ACTIVE flags on link down
    (jsc#PED-15441).
  - scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times
    out (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary spinlock locking and unlocking
    (jsc#PED-15441).
  - scsi: fnic: Replace fnic->lock_flags with local flags
    (jsc#PED-15441).
  - scsi: fnic: Replace use of sizeof with standard usage
    (jsc#PED-15441).
  - scsi: fnic: Fix indentation and remove unnecessary parenthesis
    (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary debug print (jsc#PED-15441).
  - scsi: fnic: Propagate SCSI error code from fnic_scsi_drv_init()
    (jsc#PED-15441).
  - scsi: fnic: Test for memory allocation failure and return
    error code (jsc#PED-15441).
  - scsi: fnic: Return appropriate error code from failure of scsi
    drv init (jsc#PED-15441).
  - scsi: fnic: Return appropriate error code for mem alloc failure
    (jsc#PED-15441).
  - scsi: fnic: Remove always-true IS_FNIC_FCP_INITIATOR macro
    (jsc#PED-15441).
  - scsi: fnic: Fix use of uninitialized value in debug message
    (jsc#PED-15441).
  - scsi: fnic: Delete incorrect debugfs error handling
    (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary else to fix warning in FDLS FIP
    (jsc#PED-15441).
  - scsi: fnic: Remove extern definition from .c files
    (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary else and unnecessary break in
    FDLS (jsc#PED-15441).
  - scsi: fnic: Add support to handle port channel RSCN
    (jsc#PED-15441).
  - scsi: fnic: Code cleanup (jsc#PED-15441).
  - scsi: fnic: Add stats and related functionality (jsc#PED-15441).
  - scsi: fnic: Modify fnic interfaces to use FDLS (jsc#PED-15441).
  - scsi: fnic: Modify IO path to use FDLS (jsc#PED-15441).
  - scsi: fnic: Add functionality in fnic to support FDLS
    (jsc#PED-15441).
  - scsi: fnic: Add and integrate support for FIP (jsc#PED-15441).
  - scsi: fnic: Add and integrate support for FDMI (jsc#PED-15441).
  - scsi: fnic: Add Cisco hardware model names (jsc#PED-15441).
  - scsi: fnic: Add support for unsolicited requests and responses
    (jsc#PED-15441).
  - scsi: fnic: Add support for target based solicited requests
    and responses (jsc#PED-15441).
  - scsi: fnic: Add support for fabric based solicited requests
    and responses (jsc#PED-15441).
  - scsi: fnic: Add headers and definitions for FDLS
    (jsc#PED-15441).
  - scsi: fnic: Replace shost_printk() with dev_info()/dev_err()
    (jsc#PED-15441).
  - scsi: fnic: Increment driver version (jsc#PED-15441).
  - commit 975501d
  - arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix (git-fixes)
  - commit 3475d30
  - arm64: Fix sampling the "stable" virtual counter in preemptible (git-fixes)
  - commit 2a1727d
  - iomap: adjust read range correctly for non-block-aligned positions (CVE-2025-68794 bsc#1256647)
  - commit 3c90321
  - Refresh
    patches.suse/selftests-bpf-add-verifier-sign-extension-bound-comp.patch.
    Updated expected BPF verifier message to align with those output by
    SL-16.0 kernel.
  - commit 63646e4
  - net: mana: fix use-after-free in mana_hwc_destroy_channel()
    by reordering teardown (git-fixes).
  - net/mana: Null service_wq on setup error to prevent double
    destroy (git-fixes).
  - commit c784715

++++ kernel-rt:

  - scsi: fnic: Fix missing DMA mapping error in fnic_send_frame()
    (jsc#PED-15441).
  - scsi: fnic: Turn off FDMI ACTIVE flags on link down
    (jsc#PED-15441).
  - scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times
    out (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary spinlock locking and unlocking
    (jsc#PED-15441).
  - scsi: fnic: Replace fnic->lock_flags with local flags
    (jsc#PED-15441).
  - scsi: fnic: Replace use of sizeof with standard usage
    (jsc#PED-15441).
  - scsi: fnic: Fix indentation and remove unnecessary parenthesis
    (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary debug print (jsc#PED-15441).
  - scsi: fnic: Propagate SCSI error code from fnic_scsi_drv_init()
    (jsc#PED-15441).
  - scsi: fnic: Test for memory allocation failure and return
    error code (jsc#PED-15441).
  - scsi: fnic: Return appropriate error code from failure of scsi
    drv init (jsc#PED-15441).
  - scsi: fnic: Return appropriate error code for mem alloc failure
    (jsc#PED-15441).
  - scsi: fnic: Remove always-true IS_FNIC_FCP_INITIATOR macro
    (jsc#PED-15441).
  - scsi: fnic: Fix use of uninitialized value in debug message
    (jsc#PED-15441).
  - scsi: fnic: Delete incorrect debugfs error handling
    (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary else to fix warning in FDLS FIP
    (jsc#PED-15441).
  - scsi: fnic: Remove extern definition from .c files
    (jsc#PED-15441).
  - scsi: fnic: Remove unnecessary else and unnecessary break in
    FDLS (jsc#PED-15441).
  - scsi: fnic: Add support to handle port channel RSCN
    (jsc#PED-15441).
  - scsi: fnic: Code cleanup (jsc#PED-15441).
  - scsi: fnic: Add stats and related functionality (jsc#PED-15441).
  - scsi: fnic: Modify fnic interfaces to use FDLS (jsc#PED-15441).
  - scsi: fnic: Modify IO path to use FDLS (jsc#PED-15441).
  - scsi: fnic: Add functionality in fnic to support FDLS
    (jsc#PED-15441).
  - scsi: fnic: Add and integrate support for FIP (jsc#PED-15441).
  - scsi: fnic: Add and integrate support for FDMI (jsc#PED-15441).
  - scsi: fnic: Add Cisco hardware model names (jsc#PED-15441).
  - scsi: fnic: Add support for unsolicited requests and responses
    (jsc#PED-15441).
  - scsi: fnic: Add support for target based solicited requests
    and responses (jsc#PED-15441).
  - scsi: fnic: Add support for fabric based solicited requests
    and responses (jsc#PED-15441).
  - scsi: fnic: Add headers and definitions for FDLS
    (jsc#PED-15441).
  - scsi: fnic: Replace shost_printk() with dev_info()/dev_err()
    (jsc#PED-15441).
  - scsi: fnic: Increment driver version (jsc#PED-15441).
  - commit 975501d
  - arm64: mm: Add PTE_DIRTY back to PAGE_KERNEL* to fix (git-fixes)
  - commit 3475d30
  - arm64: Fix sampling the "stable" virtual counter in preemptible (git-fixes)
  - commit 2a1727d
  - iomap: adjust read range correctly for non-block-aligned positions (CVE-2025-68794 bsc#1256647)
  - commit 3c90321
  - Refresh
    patches.suse/selftests-bpf-add-verifier-sign-extension-bound-comp.patch.
    Updated expected BPF verifier message to align with those output by
    SL-16.0 kernel.
  - commit 63646e4
  - net: mana: fix use-after-free in mana_hwc_destroy_channel()
    by reordering teardown (git-fixes).
  - net/mana: Null service_wq on setup error to prevent double
    destroy (git-fixes).
  - commit c784715

++++ systemd:

  - Import commit d349fc5cd4f9ee2b7884c2610647e92806d14b28 (merge of v257.13)
    This merge includes the following fix:
    6941d92dc2 machined: reject invalid class types when registering machines (bsc#1259650 CVE-2026-4105)
    03bb697b8d udev: check for invalid chars in various fields received from the kernel (bsc#1259697)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/3c53ef3ea20bd43ef587cbdfa7107aeb1ef55654...d349fc5cd4f9ee2b7884c2610647e92806d14b28

++++ nvidia-open-driver-G06-signed:

  - add 'Provides: open-driver-non-cuda-variant = %version' for
    non-CUDA variant to be able to distinguish between both variants;
    to be used by nvidia-open-driver-G06-signed-kmp-meta for TW ...
    (boo#1259740)

++++ pcr-oracle:

  - Update to 0.6.0
    + Initial support for CI tests
    + Fix additional arguments following the PCR index
    + CI: Shutdown the swtpm instance after tests
    + Fix stop event check crash for grub-command (bsc#1258119)
    + Print PCR values during signing or sealing

------------------------------------------------------------------
------------------  2026-3-15  -  Mar 15 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - usb: roles: get usb role switch from parent only for
    usb-b-connector (git-fixes).
  - usb: typec: altmode/displayport: set displayport signaling
    rate in configure message (git-fixes).
  - usb: xhci: Fix memory leak in xhci_disable_slot() (git-fixes).
  - usb: class: cdc-wdm: fix reordering issue in read code path
    (git-fixes).
  - usb: renesas_usbhs: fix use-after-free in ISR during device
    removal (git-fixes).
  - usb: cdc-acm: Restore CAP_BRK functionnality to CH343
    (git-fixes).
  - usb: gadget: f_mass_storage: Fix potential integer overflow
    in check_command_size_in_blocks() (git-fixes).
  - USB: core: Limit the length of unkillable synchronous timeouts
    (git-fixes).
  - USB: usbtmc: Use usb_bulk_msg_killable() with user-specified
    timeouts (git-fixes).
  - USB: usbcore: Introduce usb_bulk_msg_killable() (git-fixes).
  - usb: core: don't power off roothub PHYs if phy_set_mode()
    fails (git-fixes).
  - iio: buffer: Fix wait_queue not being removed (git-fixes).
  - iio: gyro: mpu3050-core: fix pm_runtime error handling
    (git-fixes).
  - iio: gyro: mpu3050-i2c: fix pm_runtime error handling
    (git-fixes).
  - iio: chemical: sps30_serial: fix buffer size in
    sps30_serial_read_meas() (git-fixes).
  - iio: chemical: sps30_i2c: fix buffer size in
    sps30_i2c_read_meas() (git-fixes).
  - iio: proximity: hx9023s: Protect against division by zero in
    set_samp_freq (git-fixes).
  - iio: chemical: bme680: Fix measurement wait duration calculation
    (git-fixes).
  - iio: dac: ds4424: reject -128 RAW value (git-fixes).
  - iio: potentiometer: mcp4131: fix double application of wiper
    shift (git-fixes).
  - iio: imu: inv-mpu9150: fix irq ack preventing irq storms
    (git-fixes).
  - iio: frequency: adf4377: Fix duplicated soft reset mask
    (git-fixes).
  - iio: imu: inv_icm42600: fix odr switch when turning buffer off
    (git-fixes).
  - iio: imu: inv_icm42600: fix odr switch to the same value
    (git-fixes).
  - commit dd7a351

++++ kernel-rt:

  - usb: roles: get usb role switch from parent only for
    usb-b-connector (git-fixes).
  - usb: typec: altmode/displayport: set displayport signaling
    rate in configure message (git-fixes).
  - usb: xhci: Fix memory leak in xhci_disable_slot() (git-fixes).
  - usb: class: cdc-wdm: fix reordering issue in read code path
    (git-fixes).
  - usb: renesas_usbhs: fix use-after-free in ISR during device
    removal (git-fixes).
  - usb: cdc-acm: Restore CAP_BRK functionnality to CH343
    (git-fixes).
  - usb: gadget: f_mass_storage: Fix potential integer overflow
    in check_command_size_in_blocks() (git-fixes).
  - USB: core: Limit the length of unkillable synchronous timeouts
    (git-fixes).
  - USB: usbtmc: Use usb_bulk_msg_killable() with user-specified
    timeouts (git-fixes).
  - USB: usbcore: Introduce usb_bulk_msg_killable() (git-fixes).
  - usb: core: don't power off roothub PHYs if phy_set_mode()
    fails (git-fixes).
  - iio: buffer: Fix wait_queue not being removed (git-fixes).
  - iio: gyro: mpu3050-core: fix pm_runtime error handling
    (git-fixes).
  - iio: gyro: mpu3050-i2c: fix pm_runtime error handling
    (git-fixes).
  - iio: chemical: sps30_serial: fix buffer size in
    sps30_serial_read_meas() (git-fixes).
  - iio: chemical: sps30_i2c: fix buffer size in
    sps30_i2c_read_meas() (git-fixes).
  - iio: proximity: hx9023s: Protect against division by zero in
    set_samp_freq (git-fixes).
  - iio: chemical: bme680: Fix measurement wait duration calculation
    (git-fixes).
  - iio: dac: ds4424: reject -128 RAW value (git-fixes).
  - iio: potentiometer: mcp4131: fix double application of wiper
    shift (git-fixes).
  - iio: imu: inv-mpu9150: fix irq ack preventing irq storms
    (git-fixes).
  - iio: frequency: adf4377: Fix duplicated soft reset mask
    (git-fixes).
  - iio: imu: inv_icm42600: fix odr switch when turning buffer off
    (git-fixes).
  - iio: imu: inv_icm42600: fix odr switch to the same value
    (git-fixes).
  - commit dd7a351

------------------------------------------------------------------
------------------  2026-3-14  -  Mar 14 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - i2c: i801: Revert "i2c: i801: replace acpi_lock with I2C bus
    lock" (git-fixes).
  - commit b6700c3
  - drm/amdkfd: Unreserve bo if queue update failed (git-fixes).
  - drm/amdgpu: Fix kernel-doc comments for some LUT properties
    (git-fixes).
  - drm/amd/pm: add missing od setting PP_OD_FEATURE_ZERO_FAN_BIT
    for smu v14 (git-fixes).
  - drm/i915: Fix potential overflow of shmem scatterlist length
    (git-fixes).
  - drm/bridge: ti-sn65dsi83: fix CHA_DSI_CLK_RANGE rounding
    (git-fixes).
  - drm/msm/dsi: fix pclk rate calculation for bonded dsi
    (git-fixes).
  - drm/msm: Fix dma_free_attrs() buffer size (git-fixes).
  - drm/msm/dsi: fix hdisplay calculation when programming dsi
    registers (git-fixes).
  - regulator: pca9450: Correct interrupt type (git-fixes).
  - ASoC: amd: acp-mach-common: Add missing error check for clock
    acquisition (git-fixes).
  - ASoC: detect empty DMI strings (git-fixes).
  - ASoC: amd: acp3x-rt5682-max9836: Add missing error check for
    clock acquisition (git-fixes).
  - ASoC: soc-core: flush delayed work before removing DAIs and
    widgets (git-fixes).
  - ASoC: soc-core: drop delayed_work_pending() check before flush
    (git-fixes).
  - ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop
    and start (git-fixes).
  - ALSA: pcm: fix use-after-free on linked stream runtime in
    snd_pcm_drain() (git-fixes).
  - hwmon: (max6639) fix inverted polarity (git-fixes).
  - hwmon: (aht10) Fix initialization commands for AHT20
    (git-fixes).
  - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks
    missing them (stable-fixes).
  - platform/x86: dell-wmi: Add audio/mic mute key codes
    (stable-fixes).
  - ALSA: scarlett2: Fix DSP filter control array handling
    (git-fixes).
  - ALSA: hda/conexant: Fix headphone jack handling on Acer Swift
    SF314 (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Samsung Galaxy Book3 Pro 360
    (NP965QFG) (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Gigabyte G5 KF5 (2023)
    (stable-fixes).
  - usb: cdns3: fix role switching during resume (git-fixes).
  - drm/exynos: vidi: use ctx->lock to protect struct vidi_context
    member variables related to memory alloc/free (stable-fixes).
  - drm/exynos: vidi: fix to avoid directly dereferencing user
    pointer (stable-fixes).
  - ALSA: hda/conexant: Add quirk for HP ZBook Studio G4
    (stable-fixes).
  - hwmon: (aht10) Add support for dht20 (stable-fixes).
  - drm/exynos/vidi: Remove redundant error handling in
    vidi_get_modes() (stable-fixes).
  - usb: cdns3: call cdns_power_is_lost() only once in cdns_resume()
    (stable-fixes).
  - usb: cdns3: remove redundant if branch (stable-fixes).
  - ALSA: scarlett2: Fix redeclaration of loop variable
    (stable-fixes).
  - hwmon: (max6639) : Configure based on DT property
    (stable-fixes).
  - commit 6b23ebb

++++ kernel-rt:

  - i2c: i801: Revert "i2c: i801: replace acpi_lock with I2C bus
    lock" (git-fixes).
  - commit b6700c3
  - drm/amdkfd: Unreserve bo if queue update failed (git-fixes).
  - drm/amdgpu: Fix kernel-doc comments for some LUT properties
    (git-fixes).
  - drm/amd/pm: add missing od setting PP_OD_FEATURE_ZERO_FAN_BIT
    for smu v14 (git-fixes).
  - drm/i915: Fix potential overflow of shmem scatterlist length
    (git-fixes).
  - drm/bridge: ti-sn65dsi83: fix CHA_DSI_CLK_RANGE rounding
    (git-fixes).
  - drm/msm/dsi: fix pclk rate calculation for bonded dsi
    (git-fixes).
  - drm/msm: Fix dma_free_attrs() buffer size (git-fixes).
  - drm/msm/dsi: fix hdisplay calculation when programming dsi
    registers (git-fixes).
  - regulator: pca9450: Correct interrupt type (git-fixes).
  - ASoC: amd: acp-mach-common: Add missing error check for clock
    acquisition (git-fixes).
  - ASoC: detect empty DMI strings (git-fixes).
  - ASoC: amd: acp3x-rt5682-max9836: Add missing error check for
    clock acquisition (git-fixes).
  - ASoC: soc-core: flush delayed work before removing DAIs and
    widgets (git-fixes).
  - ASoC: soc-core: drop delayed_work_pending() check before flush
    (git-fixes).
  - ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop
    and start (git-fixes).
  - ALSA: pcm: fix use-after-free on linked stream runtime in
    snd_pcm_drain() (git-fixes).
  - hwmon: (max6639) fix inverted polarity (git-fixes).
  - hwmon: (aht10) Fix initialization commands for AHT20
    (git-fixes).
  - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks
    missing them (stable-fixes).
  - platform/x86: dell-wmi: Add audio/mic mute key codes
    (stable-fixes).
  - ALSA: scarlett2: Fix DSP filter control array handling
    (git-fixes).
  - ALSA: hda/conexant: Fix headphone jack handling on Acer Swift
    SF314 (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Samsung Galaxy Book3 Pro 360
    (NP965QFG) (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Gigabyte G5 KF5 (2023)
    (stable-fixes).
  - usb: cdns3: fix role switching during resume (git-fixes).
  - drm/exynos: vidi: use ctx->lock to protect struct vidi_context
    member variables related to memory alloc/free (stable-fixes).
  - drm/exynos: vidi: fix to avoid directly dereferencing user
    pointer (stable-fixes).
  - ALSA: hda/conexant: Add quirk for HP ZBook Studio G4
    (stable-fixes).
  - hwmon: (aht10) Add support for dht20 (stable-fixes).
  - drm/exynos/vidi: Remove redundant error handling in
    vidi_get_modes() (stable-fixes).
  - usb: cdns3: call cdns_power_is_lost() only once in cdns_resume()
    (stable-fixes).
  - usb: cdns3: remove redundant if branch (stable-fixes).
  - ALSA: scarlett2: Fix redeclaration of loop variable
    (stable-fixes).
  - hwmon: (max6639) : Configure based on DT property
    (stable-fixes).
  - commit 6b23ebb

------------------------------------------------------------------
------------------  2026-3-13  -  Mar 13 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - sctp: move SCTP_CMD_ASSOC_SHKEY right after SCTP_CMD_PEER_INIT
    (CVE-2026-23125 bsc#1258293).
  - commit 6fbbb68
  - KVM: x86/mmu: Drop/zap existing present SPTE even when creating
    an MMIO SPTE (bsc#1259461).
  - commit e55e509
  - ACPI: OSL: fix __iomem type on return from
    acpi_os_map_generic_address() (git-fixes).
  - can: hi311x: hi3110_open(): add check for hi3110_power_enable()
    return value (git-fixes).
  - net: usb: lan78xx: fix TX byte statistics for small packets
    (git-fixes).
  - net: usb: lan78xx: fix silent drop of packets with checksum
    errors (git-fixes).
  - qmi_wwan: allow max_mtu above hard_mtu to control rx_urb_size
    (git-fixes).
  - remoteproc: sysmon: Correct subsys_name_len type in QMI request
    (git-fixes).
  - commit 0d180fa
  - apparmor: fix race between freeing data and fs accessing it
    (bsc#1258849).
  - apparmor: fix race on rawdata dereference (bsc#1258849).
  - apparmor: fix differential encoding verification (bsc#1258849).
  - apparmor: fix unprivileged local user can do privileged policy
    management (bsc#1258849).
  - apparmor: Fix double free of ns_name in aa_replace_profiles()
    (bsc#1258849).
  - apparmor: fix missing bounds check on DEFAULT table in
    verify_dfa() (bsc#1258849).
  - apparmor: fix side-effect bug in match_char() macro usage
    (bsc#1258849).
  - apparmor: fix: limit the number of levels of policy namespaces
    (bsc#1258849).
  - apparmor: replace recursive profile removal with iterative
    approach (bsc#1258849).
  - apparmor: fix memory leak in verify_header (bsc#1258849).
  - apparmor: validate DFA start states are in bounds in unpack_pdb
    (bsc#1258849).
  - commit 4a76367

++++ kernel-rt:

  - sctp: move SCTP_CMD_ASSOC_SHKEY right after SCTP_CMD_PEER_INIT
    (CVE-2026-23125 bsc#1258293).
  - commit 6fbbb68
  - KVM: x86/mmu: Drop/zap existing present SPTE even when creating
    an MMIO SPTE (bsc#1259461).
  - commit e55e509
  - ACPI: OSL: fix __iomem type on return from
    acpi_os_map_generic_address() (git-fixes).
  - can: hi311x: hi3110_open(): add check for hi3110_power_enable()
    return value (git-fixes).
  - net: usb: lan78xx: fix TX byte statistics for small packets
    (git-fixes).
  - net: usb: lan78xx: fix silent drop of packets with checksum
    errors (git-fixes).
  - qmi_wwan: allow max_mtu above hard_mtu to control rx_urb_size
    (git-fixes).
  - remoteproc: sysmon: Correct subsys_name_len type in QMI request
    (git-fixes).
  - commit 0d180fa
  - apparmor: fix race between freeing data and fs accessing it
    (bsc#1258849).
  - apparmor: fix race on rawdata dereference (bsc#1258849).
  - apparmor: fix differential encoding verification (bsc#1258849).
  - apparmor: fix unprivileged local user can do privileged policy
    management (bsc#1258849).
  - apparmor: Fix double free of ns_name in aa_replace_profiles()
    (bsc#1258849).
  - apparmor: fix missing bounds check on DEFAULT table in
    verify_dfa() (bsc#1258849).
  - apparmor: fix side-effect bug in match_char() macro usage
    (bsc#1258849).
  - apparmor: fix: limit the number of levels of policy namespaces
    (bsc#1258849).
  - apparmor: replace recursive profile removal with iterative
    approach (bsc#1258849).
  - apparmor: fix memory leak in verify_header (bsc#1258849).
  - apparmor: validate DFA start states are in bounds in unpack_pdb
    (bsc#1258849).
  - commit 4a76367

++++ python313-core:

  - Add CVE-2026-2297-SourcelessFileLoader-io_open_code.patch
    ensuring that `SourcelessFileLoader` uses `io.open_code` when
    opening `.pyc` files (bsc#1259240, CVE-2026-2297).

++++ sqlite3:

  - Update to version 3.51.3:
    * Fix the WAL-reset database corruption bug:
    https://sqlite.org/wal.html#walresetbug
    * Other minor bug fixes.

++++ python313:

  - Add CVE-2026-2297-SourcelessFileLoader-io_open_code.patch
    ensuring that `SourcelessFileLoader` uses `io.open_code` when
    opening `.pyc` files (bsc#1259240, CVE-2026-2297).

------------------------------------------------------------------
------------------  2026-3-12  -  Mar 12 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - RDMA/rtrs-clt: For conn rejection use actual err number (git-fixes)
  - commit f0999f7

++++ kernel-rt:

  - RDMA/rtrs-clt: For conn rejection use actual err number (git-fixes)
  - commit f0999f7

++++ libsolv:

  - respect the "default" attribute in environment optionlist in
    the comps parser
  - support suse namespace deps in boolean dependencies [bsc#1258193]
  - support for the Elbrus2000 (e2k) architecture
  - support language() suse namespace rewriting
  - bump version to 0.7.36

++++ suseconnect-ng:

  - Update version to 1.21:
  - Add expanded metric collection for kernel modules and hardware
    detection (jsc#TEL-226).
  - Support new profile based metric collection
  - Fix ignored --root parameter hanbling when reading and
    writing configuration (bsc#1257667)
  - Add expanded metric collection for system vendor/manfacturer
    (jsc#TEL-260).
  - Removed backport patch: fix-libsuseconnect-and-pci.patch
  - Add missing product id to allow yast2-registration to not break (bsc#1257825)
  - Fix libsuseconnect APIError detection logic (bsc#1257825)

------------------------------------------------------------------
------------------  2026-3-11  -  Mar 11 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Refresh
    patches.suse/cpufreq-default-to-performance-governor-on-servers.patch.
    Remove call to __init function acpi_os_get_root_pointer() from non __init context.
    acpi_os_get_root_pointer() is now called in __init context, the result is stored
    in a global variable, which is later accessed by the non-__init intel_pstate_cpu_init()
    and amd_pstate_epp_cpu_init().
  - commit 49b0ab2

++++ kernel-rt:

  - Refresh
    patches.suse/cpufreq-default-to-performance-governor-on-servers.patch.
    Remove call to __init function acpi_os_get_root_pointer() from non __init context.
    acpi_os_get_root_pointer() is now called in __init context, the result is stored
    in a global variable, which is later accessed by the non-__init intel_pstate_cpu_init()
    and amd_pstate_epp_cpu_init().
  - commit 49b0ab2

++++ sssd:

  - Make sure previously rotated logs are chown-ed as well;
    (bsc#1259475); Add patch
    0009-Make-sure-previously-rotated-logs-are-chown-ed-as-we.patch

++++ vim:

    * Update Vim to version 9.2.0110 (from 9.2.0045).
    * Specifically, this fixes bsc#1259051 / CVE-2026-28417.

------------------------------------------------------------------
------------------  2026-3-10  -  Mar 10 2026  -------------------
------------------------------------------------------------------

++++ haproxy:

  - Update to version 3.2.14+git0.951507193:
    * [RELEASE] Released version 3.2.14
    * SCRIPTS: git-show-backports: add a restart-from-last option
    * SCRIPTS: git-show-backports: hide the common ancestor warning in quiet mode
    * BUG/MINOR: backend: Don't get proto to use for webscoket if there is no server
    * BUG/MINOR: ssl-sample: Fix sample_conv_sha2() by checking EVP_Digest* failures
    * BUG/MEDIUM: mux-fcgi: Use a safe loop to resume each stream eligible for sending
    * BUG/MAJOR: resolvers: Properly lowered the names found in DNS response
    * BUG/MAJOR: fcgi: Fix param decoding by properly checking its size
    * MINOR: filters: Set last_entity when a filter fails on stream_start callback
    * DEBUG: stream: Display the currently running rule in stream dump
    * BUG/MINOR: h1-htx: Be sure that H1 response version starts by "HTTP/"
    * BUG/MEDIUM: qpack: correctly deal with too large decoded numbers
    * BUG/MINOR: qpack: fix 1-byte OOB read in qpack_decode_fs_pfx()
    * BUG/MAJOR: qpack: unchecked length passed to huffman decoder
    * BUG/MEDIUM: hpack: correctly deal with too large decoded numbers
    * BUG/MEDIUM: stream: Handle TASK_WOKEN_RES as a stream event
    * BUG/MINOR: promex: fix server iteration when last server is deleted
    * BUG/MEDIUM: mux-h2: make sure to always report pending errors to the stream
    * MINOR: mux-h2: add a new setting, "tune.h2.log-errors" to tweak error logging
    * MINOR: mux-h2: also count glitches on invalid trailers
    * [RELEASE] Released version 3.2.13
    * CLEANUP: mux-h1: Remove unneeded null check
    * CI: github: disable windows.yml by default on unofficials repo
    * CI: vtest: move the vtest2 URL to vinyl-cache.org
    * MINOR: stconn: Add missing SC_FL_NO_FASTFWD flag in sc_show_flags
    * BUG/MINOR: http-ana: Stop to wait for body on client error/abort
    * CLEANUP: compression: Remove unused static buffers
    * BUG/MINOR: flt-trace: Properly compute length of the first DATA block
    * DEV: term-events: Fix hanshake events decoding
    * BUG/MEDIUM: applet: Fix test on shut flags for legacy applets (v2)
    * BUG/MEDIUM: mux-h1: Stop sending vi fast-forward for unexpected states
    * BUG/MEDIUM: mux-h2/quic: Stop sending via fast-forward if stream is closed
    * BUG/MEDIUM: h3: reject frontend CONNECT as currently not implemented
    * BUG/MAJOR: Revert "MEDIUM: mux-quic: add BUG_ON if sending on locally closed QCS"
    * BUG/MINOR: ssl: error with ssl-f-use when no "crt"
    * BUG/MINOR: ssl: clarify ssl-f-use errors in post-section parsing
    * BUG/MINOR: ssl: fix leak in ssl-f-use parser upon error
    * BUG/MINOR: ssl: double-free on error path w/ ssl-f-use parser
    * BUG/MINOR: ssl: lack crtlist_dup_ssl_conf() declaration
    * BUG/MINOR: deviceatlas: set cache_size on hot-reloaded atlas instance
    * BUG/MINOR: deviceatlas: fix deinit to only finalize when initialized
    * BUG/MINOR: deviceatlas: fix resource leak on hot-reload compile failure
    * BUG/MINOR: deviceatlas: fix double-checked locking race in checkinst
    * BUG/MINOR: deviceatlas: fix cookie vlen using wrong length after extraction
    * BUG/MINOR: deviceatlas: fix off-by-one in da_haproxy_conv()
    * BUG/MEDIUM: deviceatlas: fix resource leaks on init error paths
    * BUG/MINOR: deviceatlas: add NULL checks on strdup() results in config parsers
    * BUG/MINOR: deviceatlas: add missing return on error in config parsers
    * DOC: proxy-proto: underline the packed attribute for struct pp2_tlv_ssl
    * DOC: internals: addd mworker V3 internals

++++ sg3_utils:

  - Update to version 1.48~20221101+5.c6a1f6b8:
    * rescan-scsi-bus.sh: Fix invocation of udevadm (boo#1258664)
    * rescan_scsi_bus.sh: fix multipath issue when called with -s and
    without -u (bsc#1215720, bsc#1216355)

++++ libzypp:

  - Fix Product::referencePackage lookup (bsc#1259311)
    Use a provided autoproduct() as hint to the package name of the
    release package. It might be that not just multiple versions of
    the same release package provide the same product version, but
    also different release packages.
  - version 17.38.4 (35)

------------------------------------------------------------------
------------------  2026-3-9  -  Mar 9 2026  -------------------
------------------------------------------------------------------

++++ curl:

  - Security fixes:
    * CVE-2026-1965: Bad reuse of HTTP Negotiate connection (bsc#1259362)
    * CVE-2026-3783: Token leak with redirect and netrc (bsc#1259363)
    * CVE-2026-3784: Wrong proxy connection reuse with credentials (bsc#1259364)
    * CVE-2026-3805: Use after free in SMB connection reuse (bsc#1259365)
    * tool_operate: reset the URL --url-query between --next (510fdad)
    * Add patches:
  - curl-CVE-2026-1965.patch curl-CVE-2026-1965-disable-ntlm-fix.patch
  - curl-CVE-2026-3783.patch
  - curl-CVE-2026-3784.patch
  - curl-CVE-2026-3805.patch

++++ kernel-default:

  - dm mpath: make pg_init_delay_msecs settable (git-fixes).
  - commit b2a0fd6
  - dm: clear cloned request bio pointer when last clone bio
    completes (git-fixes).
  - commit d6eb6ea
  - dm: remove fake timeout to avoid leak request (git-fixes).
  - commit bf8f04d
  - add bugnumber to existing mana change (bsc#1252266).
  - net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes).
  - PCI: hv: remove unnecessary module_init/exit functions (git-fixes).
  - PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes).
  - RDMA/mana_ib: Add device-memory support (git-fixes).
  - RDMA/mana_ib: Take CQ type from the device type (git-fixes).
  - net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472).
  - Drivers: hv: Always do Hyper-V panic notification in hv_kmsg_dump() (git-fixes).
  - net: mana: Fix use-after-free in reset service rescan path (git-fixes).
  - net: mana: Handle hardware recovery events when probing the device (bsc#1257466).
  - net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes).
  - net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes).
  - net: mana: Add standard counter rx_missed_errors (git-fixes).
  - commit dde91c8
  - btrfs: fallback to buffered IO if the data profile has
    duplication (git-fixes).
  - commit c194c61
  - arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS (bsc#1259329)
  - commit c775b21
  - selftests/bpf: add verifier sign extension bound computation
    tests (git-fixes).
  - bpf: verifier improvement in 32bit shift sign extension pattern
    (git-fixes).
  - commit 9625613

++++ kernel-rt:

  - dm mpath: make pg_init_delay_msecs settable (git-fixes).
  - commit b2a0fd6
  - dm: clear cloned request bio pointer when last clone bio
    completes (git-fixes).
  - commit d6eb6ea
  - dm: remove fake timeout to avoid leak request (git-fixes).
  - commit bf8f04d
  - add bugnumber to existing mana change (bsc#1252266).
  - net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes).
  - PCI: hv: remove unnecessary module_init/exit functions (git-fixes).
  - PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes).
  - RDMA/mana_ib: Add device-memory support (git-fixes).
  - RDMA/mana_ib: Take CQ type from the device type (git-fixes).
  - net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472).
  - Drivers: hv: Always do Hyper-V panic notification in hv_kmsg_dump() (git-fixes).
  - net: mana: Fix use-after-free in reset service rescan path (git-fixes).
  - net: mana: Handle hardware recovery events when probing the device (bsc#1257466).
  - net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes).
  - net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes).
  - net: mana: Add standard counter rx_missed_errors (git-fixes).
  - commit dde91c8
  - btrfs: fallback to buffered IO if the data profile has
    duplication (git-fixes).
  - commit c194c61
  - arm64: contpte: fix set_access_flags() no-op check for SMMU/ATS (bsc#1259329)
  - commit c775b21
  - selftests/bpf: add verifier sign extension bound computation
    tests (git-fixes).
  - bpf: verifier improvement in 32bit shift sign extension pattern
    (git-fixes).
  - commit 9625613

++++ python-maturin:

  - CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date
    parser can lead to stack exhaustion (bsc#1257918)
    * refreshed vendor tarball to update time crate to 0.3.47

------------------------------------------------------------------
------------------  2026-3-8  -  Mar 8 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read
    (git-fixes).
  - hwmon: (it87) Check the it87_lock() return value (git-fixes).
  - commit 8d41466

++++ kernel-rt:

  - hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read
    (git-fixes).
  - hwmon: (it87) Check the it87_lock() return value (git-fixes).
  - commit 8d41466

------------------------------------------------------------------
------------------  2026-3-7  -  Mar 7 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/xe/reg_sr: Fix leak on xa_store failure (git-fixes).
  - drm/xe: Do not preempt fence signaling CS instructions
    (git-fixes).
  - nouveau/dpcd: return EBUSY for aux xfer if the device is asleep
    (git-fixes).
  - drm/sched: Fix kernel-doc warning for drm_sched_job_done()
    (git-fixes).
  - drm/solomon: Fix page start when updating rectangle in page
    addressing mode (git-fixes).
  - platform/x86: dell-wmi-sysman: Don't hex dump plaintext password
    data (git-fixes).
  - pmdomain: bcm: bcm2835-power: Fix broken reset status read
    (git-fixes).
  - ata: libata-core: Disable LPM on ST1000DM010-2EP102 (git-fixes).
  - commit a06b327

++++ kernel-rt:

  - drm/xe/reg_sr: Fix leak on xa_store failure (git-fixes).
  - drm/xe: Do not preempt fence signaling CS instructions
    (git-fixes).
  - nouveau/dpcd: return EBUSY for aux xfer if the device is asleep
    (git-fixes).
  - drm/sched: Fix kernel-doc warning for drm_sched_job_done()
    (git-fixes).
  - drm/solomon: Fix page start when updating rectangle in page
    addressing mode (git-fixes).
  - platform/x86: dell-wmi-sysman: Don't hex dump plaintext password
    data (git-fixes).
  - pmdomain: bcm: bcm2835-power: Fix broken reset status read
    (git-fixes).
  - ata: libata-core: Disable LPM on ST1000DM010-2EP102 (git-fixes).
  - commit a06b327

------------------------------------------------------------------
------------------  2026-3-6  -  Mar 6 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - tracing: Fix crash on synthetic stacktrace field usage
    (CVE-2026-23088 bsc#1257814).
  - commit 41fea09
  - tracing: Do not register unsupported perf events (CVE-2025-71125
    bsc#1256784).
  - commit 8e15740
  - tracing: Fix WARN_ON in tracing_buffers_mmap_close for split
    VMAs (CVE-2025-68329 bsc#1255490).
  - commit b6b73bb
  - ftrace: Fix softlockup in ftrace_module_enable (CVE-2025-68173
    bsc#1255311).
  - commit 2eaaeb0
  - ring-buffer: Do not warn in ring_buffer_map_get_reader()
    when reader catches up (CVE-2025-68186 bsc#1255144).
  - commit 6132115
  - nfc: rawsock: cancel tx_work before socket teardown (git-fixes).
  - nfc: nci: clear NCI_DATA_EXCHANGE before calling completion
    callback (git-fixes).
  - nfc: nci: free skb on nci_transceive early error paths
    (git-fixes).
  - net: nfc: nci: Fix zero-length proprietary notifications
    (git-fixes).
  - can: usb: f81604: correctly anchor the urb in the read bulk
    callback (git-fixes).
  - can: usb: f81604: handle bulk write errors properly (git-fixes).
  - can: usb: f81604: handle short interrupt urb messages properly
    (git-fixes).
  - can: usb: etas_es58x: correctly anchor the urb in the read
    bulk callback (git-fixes).
  - can: ucan: Fix infinite loop from zero-length messages
    (git-fixes).
  - can: ems_usb: ems_usb_read_bulk_callback(): check the proper
    length of a message (git-fixes).
  - can: mcp251x: fix deadlock in error path of mcp251x_open
    (git-fixes).
  - can: bcm: fix locking for bcm_op runtime updates (git-fixes).
  - wifi: mt76: Fix possible oob access in
    mt76_connac2_mac_write_txwi_80211() (git-fixes).
  - wifi: mt76: mt7925: Fix possible oob access in
    mt7925_mac_write_txwi_80211() (git-fixes).
  - wifi: mt76: mt7996: Fix possible oob access in
    mt7996_mac_write_txwi_80211() (git-fixes).
  - wifi: wlcore: Fix a locking bug (git-fixes).
  - wifi: cw1200: Fix locking in error paths (git-fixes).
  - wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac80211_config
    (git-fixes).
  - batman-adv: Avoid double-rtnl_lock ELP metric worker
    (git-fixes).
  - commit f8549ba

++++ kernel-rt:

  - tracing: Fix crash on synthetic stacktrace field usage
    (CVE-2026-23088 bsc#1257814).
  - commit 41fea09
  - tracing: Do not register unsupported perf events (CVE-2025-71125
    bsc#1256784).
  - commit 8e15740
  - tracing: Fix WARN_ON in tracing_buffers_mmap_close for split
    VMAs (CVE-2025-68329 bsc#1255490).
  - commit b6b73bb
  - ftrace: Fix softlockup in ftrace_module_enable (CVE-2025-68173
    bsc#1255311).
  - commit 2eaaeb0
  - ring-buffer: Do not warn in ring_buffer_map_get_reader()
    when reader catches up (CVE-2025-68186 bsc#1255144).
  - commit 6132115
  - nfc: rawsock: cancel tx_work before socket teardown (git-fixes).
  - nfc: nci: clear NCI_DATA_EXCHANGE before calling completion
    callback (git-fixes).
  - nfc: nci: free skb on nci_transceive early error paths
    (git-fixes).
  - net: nfc: nci: Fix zero-length proprietary notifications
    (git-fixes).
  - can: usb: f81604: correctly anchor the urb in the read bulk
    callback (git-fixes).
  - can: usb: f81604: handle bulk write errors properly (git-fixes).
  - can: usb: f81604: handle short interrupt urb messages properly
    (git-fixes).
  - can: usb: etas_es58x: correctly anchor the urb in the read
    bulk callback (git-fixes).
  - can: ucan: Fix infinite loop from zero-length messages
    (git-fixes).
  - can: ems_usb: ems_usb_read_bulk_callback(): check the proper
    length of a message (git-fixes).
  - can: mcp251x: fix deadlock in error path of mcp251x_open
    (git-fixes).
  - can: bcm: fix locking for bcm_op runtime updates (git-fixes).
  - wifi: mt76: Fix possible oob access in
    mt76_connac2_mac_write_txwi_80211() (git-fixes).
  - wifi: mt76: mt7925: Fix possible oob access in
    mt7925_mac_write_txwi_80211() (git-fixes).
  - wifi: mt76: mt7996: Fix possible oob access in
    mt7996_mac_write_txwi_80211() (git-fixes).
  - wifi: wlcore: Fix a locking bug (git-fixes).
  - wifi: cw1200: Fix locking in error paths (git-fixes).
  - wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac80211_config
    (git-fixes).
  - batman-adv: Avoid double-rtnl_lock ELP metric worker
    (git-fixes).
  - commit f8549ba

++++ libzypp:

  - specfile: on fedora use %{_prefix}/share as zyppconfdir if
    %{_distconfdir} is undefined (fixes #693)
    This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake.
  - Fall back to a writable location when precaching packages
    without root (bsc#1247948)
  - version 17.38.3 (35)

++++ zypper:

  - Report download progress for command line rpms (fixes #613)
  - Hint to '-vv ref' to see the mirrors used to download the
    metadata (bsc#1257882)
  - Service: Allow "zypper ls SERVICE ..." to test whether a
    service with this alias is defined (bsc#1252744)
    The command prints an abstract of all services passed on the
    command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some
    argument does not name an existing service.
  - Keep repo data when updating the service settings (bsc#1252744)
  - info: Enhance pattern content table (bsc#1158038)
    Alternatives (multiple packages providing the same requirement)
    are now listed as a single entry in the content table. The entry
    shows either the installed package which satisfies the
    requirement or the requirement itself as type 'Provides'.
    Listing all potential alternatives was miss leading, especially
    if the alternatives were mutual exclusive. It looked like an
    installed pattern had not-installed requirements and it was not
    possible to install all requirements at the same time.
  - version 1.14.95

------------------------------------------------------------------
------------------  2026-3-5  -  Mar 5 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - libceph: reset sparse-read state in osd_fault() (CVE-2026-23136 bsc#1258303).
  - commit a1cc877
  - libceph: make calc_target() set t->paused, not just clear it (CVE-2026-23047 bsc#1257682).
  - commit 3225b77
  - mm/damon/sysfs-scheme: cleanup access_pattern subdirs on scheme
    dir setup failure (CVE-2026-23142 bsc#1258289).
  - commit 217a6fd
  - mm/damon/sysfs-scheme: cleanup quotas subdirs on scheme dir
    setup failure (git-fixes).
  - commit c642652
  - mm/damon/sysfs: cleanup attrs subdirs on context dir setup
    failure (CVE-2026-23144 bsc#1258290).
  - commit c7e0495
  - crypto: ccp - Fix a case where SNP_SHUTDOWN is missed
    (git-fixes).
  - drm/xe: Defer gt->mmio initialization until after multi-tile
    setup (git-fixes).
  - commit 56b85e5
  - wifi: ath10k: fix lock protection in
    ath10k_wmi_event_peer_sta_ps_state_chg() (stable-fixes).
  - wifi: rtw89: pci: restore LDO setting after device resume
    (stable-fixes).
  - wifi: rtw89: 8922a: add digital compensation for 2GHz
    (stable-fixes).
  - wifi: rtw89: fix unable to receive probe responses under MLO
    connection (stable-fixes).
  - wifi: iwlwifi: mvm: check the validity of noa_len
    (stable-fixes).
  - wifi: ath12k: fix preferred hardware mode calculation
    (stable-fixes).
  - wifi: ath11k: Fix failure to connect to a 6 GHz AP
    (stable-fixes).
  - wifi: ath11k: add pm quirk for Thinkpad Z13/Z16 Gen1
    (stable-fixes).
  - wifi: iwlegacy: add missing mutex protection in
    il4965_store_tx_power() (stable-fixes).
  - commit 4df290e
  - rtc: zynqmp: correct frequency value (stable-fixes).
  - thermal: int340x: Fix sysfs group leak on DLVR registration
    failure (stable-fixes).
  - soundwire: dmi-quirks: add mapping for Avell B.ON (OEM rebranded
    of NUC15) (stable-fixes).
  - soundwire: intel_auxdevice: add cs42l45 codec to
    wake_capable_list (stable-fixes).
  - staging: rtl8723bs: fix memory leak on failure path
    (stable-fixes).
  - staging: rtl8723bs: fix missing status update on
    sdio_alloc_irq() failure (stable-fixes).
  - watchdog: imx7ulp_wdt: handle the nowayout option
    (stable-fixes).
  - watchdog: starfive-wdt: Fix PM reference leak in probe error
    path (git-fixes).
  - watchdog/softlockup: fix sample ring index wrap in
    need_counting_irqs() (git-fixes).
  - wifi: iwlegacy: add missing mutex protection in
    il3945_store_measurement() (stable-fixes).
  - wifi: cfg80211: allow only one NAN interface, also in multi
    radio (stable-fixes).
  - wifi: rtw89: mac: correct page number for CSI response
    (stable-fixes).
  - wifi: rtw89: wow: add reason codes for disassociation in WoWLAN
    mode (stable-fixes).
  - wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
    (stable-fixes).
  - wifi: rtw89: ser: enable error IMR after recovering from L1
    (stable-fixes).
  - wifi: rtw89: 8922a: set random mac if efuse contains zeroes
    (stable-fixes).
  - wifi: rtw88: rtw8821cu: Add ID for Mercusys MU6H (stable-fixes).
  - wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode()
    (stable-fixes).
  - wifi: rtw88: fix DTIM period handling when conf->dtim_period
    is zero (stable-fixes).
  - wifi: libertas: fix WARNING in usb_tx_block (stable-fixes).
  - power: sequencing: fix missing state_lock in pwrseq_power_on()
    error path (stable-fixes).
  - spi: geni-qcom: Fix abort sequence execution for serial engine
    errors (stable-fixes).
  - spi: stm32: fix Overrun issue at < 8bpw (stable-fixes).
  - spi-geni-qcom: initialize mode related registers to 0
    (stable-fixes).
  - spi-geni-qcom: use xfer->bits_per_word for can_dma()
    (stable-fixes).
  - tools/power cpupower: Reset errno before strtoull()
    (stable-fixes).
  - powercap: intel_rapl: Add PL4 support for Ice Lake
    (stable-fixes).
  - commit a96ba92
  - PCI: Add defines for bridge window indexing (stable-fixes).
  - Refresh
    patches.suse/PCI-ACPI-Restrict-program_hpx_type2-to-AER-bits.patch.
  - commit 41bad5b
  - pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
    (git-fixes).
  - ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access
    (stable-fixes).
  - ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut
    (stable-fixes).
  - phy: mvebu-cp110-utmi: fix dr_mode property read from dts
    (stable-fixes).
  - phy: fsl-imx8mq-usb: disable bind/unbind platform driver feature
    (stable-fixes).
  - phy: cadence-torrent: restore parent clock for refclk during
    resume (stable-fixes).
  - phy: ti: phy-j721e-wiz: restore mux selection during resume
    (stable-fixes).
  - Revert "mmc: rtsx_pci_sdmmc: increase power-on settling delay
    to 5ms" (git-fixes).
  - nfc: nxp-nci: remove interrupt trigger type (stable-fixes).
  - PCI: Add Intel Nova Lake audio Device ID (stable-fixes).
  - commit 52ffef7
  - media: dvb-net: fix OOB access in ULE extension header tables
    (git-fixes).
  - mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms
    (git-fixes).
  - misc: bcm_vk: Fix possible null-pointer dereferences in
    bcm_vk_read() (stable-fixes).
  - misc: eeprom: Fix EWEN/EWDS/ERAL commands for 93xx56 and 93xx66
    (stable-fixes).
  - mfd: intel-lpss: Add Intel Nova Lake-S PCI IDs (stable-fixes).
  - myri10ge: avoid uninitialized variable use (stable-fixes).
  - media: rkisp1: Fix filter mode register configuration
    (stable-fixes).
  - media: ipu6: Always close firmware stream (stable-fixes).
  - media: ipu6: Close firmware streams on streaming enable failure
    (stable-fixes).
  - media: ipu6: Ensure stream_mutex is acquired when dealing with
    node list (stable-fixes).
  - media: mt9m114: Return -EPROBE_DEFER if no endpoint is found
    (stable-fixes).
  - media: mt9m114: Avoid a reset low spike during probe()
    (stable-fixes).
  - media: v4l2-async: Fix error handling on steps after finding
    a match (stable-fixes).
  - media: cx25821: Fix a resource leak in cx25821_dev_setup()
    (stable-fixes).
  - media: pvrusb2: fix URB leak in pvr2_send_request_ex
    (stable-fixes).
  - media: solo6x10: Check for out of bounds chip_id (stable-fixes).
  - media: adv7180: fix frame interval in progressive mode
    (stable-fixes).
  - media: amphion: Clear last_buffer_dequeued flag for
    DEC_CMD_START (stable-fixes).
  - media: mediatek: vcodec: Don't try to decode 422/444 VP9
    (stable-fixes).
  - media: chips-media: wave5: Process ready frames when CMD_STOP
    sent to Encoder (stable-fixes).
  - media: chips-media: wave5: Fix conditional in start_streaming
    (stable-fixes).
  - media: omap3isp: isppreview: always clamp in
    preview_try_format() (stable-fixes).
  - media: omap3isp: set initial format (stable-fixes).
  - mfd: simple-mfd-i2c: Add compatible strings for Layerscape
    QIXIS FPGA (stable-fixes).
  - mfd: simple-mfd-i2c: Add MAX77705 support (stable-fixes).
  - commit 26d6095
  - iio: magnetometer: Remove IRQF_ONESHOT (stable-fixes).
  - iio: Use IRQF_NO_THREAD (stable-fixes).
  - HID: i2c-hid: Add FocalTech FT8112 (stable-fixes).
  - media: omap3isp: isp_video_mbus_to_pix/pix_to_mbus fixes
    (stable-fixes).
  - media: dvb-core: dmxdevfilter must always flush bufs
    (stable-fixes).
  - HID: elecom: Add support for ELECOM HUGE Plus M-HT1MRBK
    (stable-fixes).
  - HID: logitech-hidpp: Add support for Logitech K980
    (stable-fixes).
  - HID: multitouch: add eGalaxTouch EXC3188 support (stable-fixes).
  - HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()
    (stable-fixes).
  - hwmon: (pmbus/mpq8785) fix VOUT_MODE mismatch during
    identification (git-fixes).
  - hwmon: (f71882fg) Add F81968 support (stable-fixes).
  - hwmon: (nct6775) Add ASUS Pro WS WRX90E-SAGE SE (stable-fixes).
  - hwmon: (dell-smm) Add support for Dell OptiPlex 7080
    (stable-fixes).
  - i3c: mipi-i3c-hci: Reset RING_OPERATION1 fields during init
    (stable-fixes).
  - i3c: master: svc: Initialize 'dev' to NULL in
    svc_i3c_master_ibi_isr() (stable-fixes).
  - hwrng: core - Allow runtime disabling of the HW RNG
    (stable-fixes).
  - hwmon: pmbus: mpq8785: Add support for MPM82504 (stable-fixes).
  - hwmon: pmbus: mpq8785: Implement VOUT feedback resistor divider
    ratio configuration (stable-fixes).
  - hwmon: pmbus: mpq8785: Prepare driver for multiple device
    support (stable-fixes).
  - commit 755fe92
  - drm/xe/xe2_hpg: Fix handling of Wa_14019988906 & Wa_14019877138
    (git-fixes).
  - drm/xe/mmio: Avoid double-adjust in 64-bit reads (git-fixes).
  - drm/amdgpu: keep vga memory on MacBooks with switchable graphics
    (stable-fixes).
  - drm/amd/display: Remove conditional for shaper 3DLUT power-on
    (stable-fixes).
  - drm/amdgpu: Add HAINAN clock adjustment (stable-fixes).
  - drm/radeon: Add HAINAN clock adjustment (stable-fixes).
  - drm/amdgpu: Adjust usleep_range in fence wait (stable-fixes).
  - drm/amd/display: bypass post csc for additional color spaces
    in dal (stable-fixes).
  - drm/amd/display: Increase DCN35 SR enter/exit latency
    (stable-fixes).
  - drm/amd/display: Avoid updating surface with the same surface
    under MPO (stable-fixes).
  - drm/amd/display: Fix system resume lag issue (stable-fixes).
  - drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
    (stable-fixes).
  - drm/amd/display: Fix writeback on DCN 3.2+ (stable-fixes).
  - fpga: of-fpga-region: Fail if any bridge is missing
    (stable-fixes).
  - fix it87_wdt early reboot by reporting running timer
    (stable-fixes).
  - fbdev: ffb: fix corrupted video output on Sun FFB1
    (stable-fixes).
  - drm/amd/display: avoid dig reg access timeout on usb4 link
    training fail (stable-fixes).
  - drm/amd/display: Fix GFX12 family constant checks
    (stable-fixes).
  - drm/amd/display: Disable FEC when powering down encoders
    (stable-fixes).
  - drm/atmel-hlcdc: don't reject the commit if the src rect has
    fractional parts (stable-fixes).
  - drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after
    release (stable-fixes).
  - drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state
    callback (stable-fixes).
  - drm: Account property blob allocations to memcg (stable-fixes).
  - drm/amdkfd: Fix GART PTE for non-4K pagesize in
    svm_migrate_gart_map() (stable-fixes).
  - drm/amdkfd: Relax size checking during queue buffer get
    (stable-fixes).
  - drm/amd/display: only power down dig on phy endpoints
    (stable-fixes).
  - drm/amdgpu: Skip loading SDMA_RS64 in VF (stable-fixes).
  - drm/xe: Only toggle scheduling in TDR if GuC is running
    (stable-fixes).
  - drm/panel: Fix a possible null-pointer dereference in
    jdi_panel_dsi_remove() (stable-fixes).
  - drm/amd/display: Fix dsc eDP issue (stable-fixes).
  - drm/amd/display: Add signal type check for dcn401
    get_phyd32clk_src (stable-fixes).
  - gpu/panel-edp: add AUO panel entry for B140HAN06.4
    (stable-fixes).
  - HID: prodikeys: Check presence of pm->input_ep82 (stable-fixes).
  - HID: magicmouse: Do not crash on missing msc->input
    (stable-fixes).
  - HID: apple: Add "SONiX KN85 Keyboard" to the list of non-apple
    keyboards (stable-fixes).
  - gpio: aspeed-sgpio: Change the macro to support deferred probe
    (stable-fixes).
  - commit 2524956
  - drm/xe/ptl: Apply Wa_13011645652 (stable-fixes).
  - Refresh
    patches.suse/drm-xe-xe3lpg-Apply-Wa_14022293748-Wa_22019794406.patch.
  - commit 689b272
  - dmaengine: stm32-mdma: initialize m2m_hw_period and ccr to
    fix warnings (stable-fixes).
  - drm/amdgpu: add support for HDP IP version 6.1.1 (stable-fixes).
  - drm/amd/display: Add USB-C DP Alt Mode lane limitation in DCN32
    (stable-fixes).
  - drm/amdkfd: Handle GPU reset and drain retry fault race
    (stable-fixes).
  - drm/amdgpu: fix NULL pointer issue buffer funcs (stable-fixes).
  - drm/v3d: Set DMA segment size to avoid debug warnings
    (stable-fixes).
  - drm/i915/wakeref: clean up INTEL_WAKEREF_PUT_* flag macros
    (stable-fixes).
  - drm/display/dp_mst: Add protection against 0 vcpi
    (stable-fixes).
  - drm/xe/xe2_hpg: Add set of workarounds (stable-fixes).
  - drm/xe: Switch MMIO interface to take xe_mmio instead of xe_gt
    (stable-fixes).
  - drm/xe: Adjust mmio code to pass VF substructure to SRIOV code
    (stable-fixes).
  - drm/xe: Add xe_tile backpointer to xe_mmio (stable-fixes).
  - drm/xe: Switch mmio_ext to use 'struct xe_mmio' (stable-fixes).
  - drm/xe: Populate GT's mmio iomap from tile during init
    (stable-fixes).
  - drm/xe: Move GSI offset adjustment fields into 'struct xe_mmio'
    (stable-fixes).
  - drm/xe: Clarify size of MMIO region (stable-fixes).
  - drm/xe: Create dedicated xe_mmio structure (stable-fixes).
  - drm/xe: Move forcewake to 'gt.pm' substructure (stable-fixes).
  - docs: fix WARNING document not included in any toctree
    (stable-fixes).
  - commit 4836e0c
  - ASoC: amd: yc: Add DMI quirk for ASUS Vivobook Pro 15X M6501RR
    (stable-fixes).
  - dma: dma-axi-dmac: fix HW scatter-gather not looking at the
    queue (git-fixes).
  - dma: dma-axi-dmac: fix SW cyclic transfers (git-fixes).
  - dmaengine: sun6i: Choose appropriate burst length under maxburst
    (stable-fixes).
  - dmaengine: stm32-dma3: use module_platform_driver
    (stable-fixes).
  - crypto: ccp - Send PSP_CMD_TEE_RING_DESTROY when
    PSP_CMD_TEE_RING_INIT fails (git-fixes).
  - crypto: ccp - Factor out ring destroy handling to a helper
    (stable-fixes).
  - ata: libata: avoid long timeouts on hot-unplugged SATA DAS
    (stable-fixes).
  - Bluetooth: btusb: Add device ID for Realtek RTL8761BU
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID for RTL8852CE (stable-fixes).
  - Bluetooth: hci_conn: Set link_policy on incoming ACL connections
    (stable-fixes).
  - Bluetooth: hci_conn: use mod_delayed_work for active mode
    timeout (stable-fixes).
  - Bluetooth: btusb: Add support for MediaTek7920 0489:e158
    (stable-fixes).
  - ASoC: fsl: imx-rpmsg: use snd_soc_find_dai_with_mutex() in probe
    (stable-fixes).
  - ASoC: SOF: Intel: hda: Fix NULL pointer dereference
    (stable-fixes).
  - ASoC: codecs: max98390: Check return value of
    devm_gpiod_get_optional() in max98390_i2c_probe()
    (stable-fixes).
  - ASoC: sunxi: sun50i-dmic: Add missing check for
    devm_regmap_init_mmio (stable-fixes).
  - ASoC: soc-acpi-intel-arl-match: change rt722 amp endpoint to
    aggregated (stable-fixes).
  - ASoC: SOF: Intel: hda: Remove MODULE_SOFTDEP for
    snd-hda-codec-hdmi (stable-fixes).
  - ASoC: wm8962: Don't report a microphone if it's shorted to
    ground on plug (stable-fixes).
  - ASoC: wm8962: Add WM8962_ADC_MONOMIX to "3D Coefficients" mask
    (stable-fixes).
  - ASoC: nau8821: Cancel pending work before suspend (git-fixes).
  - ASoC: nau8821: Cancel delayed work on component remove
    (git-fixes).
  - ASoC: nau8821: Fixup nau8821_enable_jack_detect() (git-fixes).
  - ASoC: SOF: ipc4: Support for sending payload along with
    LARGE_CONFIG_GET (stable-fixes).
  - crypto: hisilicon/qm - move the barrier before writing to the
    mailbox register (stable-fixes).
  - crypto: ccp - narrow scope of snp_range_list (git-fixes).
  - APEI/GHES: ensure that won't go past CPER allocated record
    (stable-fixes).
  - ASoC: nau8821: Avoid unnecessary blocking in IRQ handler
    (stable-fixes).
  - crypto: ccp - Ensure implicit SEV/SNP init and shutdown in
    ioctls (stable-fixes).
  - commit ef48f01
  - ALSA: hda: cs35l56: Fix signedness error in
    cs35l56_hda_posture_put() (git-fixes).
  - ALSA: usb-audio: Add sanity check for OOB writes at silencing
    (stable-fixes).
  - ALSA: usb-audio: Update the number of packets properly at
    receiving (stable-fixes).
  - ACPI: x86: Force enabling of PWM2 on the Yogabook YB1-X90
    (stable-fixes).
  - ALSA: mixer: oss: Add card disconnect checkpoints
    (stable-fixes).
  - ALSA: usb-audio: Add iface reset and delay quirk for AB13X
    USB Audio (stable-fixes).
  - ALSA: hda/realtek - Enable mute LEDs on HP ENVY x360 15-es0xxx
    (stable-fixes).
  - ALSA: hda/conexant: Add headset mic fix for MECHREVO Wujie
    15X Pro (stable-fixes).
  - ALSA: hda/realtek: fix LG Gram Style 14 speakers (stable-fixes).
  - ALSA: hda/realtek: add HP Victus 16-e0xxx mute LED quirk
    (stable-fixes).
  - ALSA: pcm: Revert bufs move in snd_pcm_xfern_frames_ioctl()
    (stable-fixes).
  - ALSA: vmaster: Relax __free() variable declarations (git-fixes).
  - ALSA: pcm: Relax __free() variable declarations (git-fixes).
  - ACPI: processor: Fix NULL-pointer dereference in
    acpi_processor_errata_piix4() (stable-fixes).
  - ACPI: battery: fix incorrect charging status when current is
    zero (stable-fixes).
  - ACPI: resource: Add JWIPC JVC9100 to
    irq1_level_low_skip_override[] (stable-fixes).
  - ACPI: x86: s2idle: Invoke Microsoft _DSM Function 9 (Turn On
    Display) (stable-fixes).
  - ACPICA: Abort AML bytecode execution when executing AML_FATAL_OP
    (stable-fixes).
  - commit 119c4f9
  - net: usb: sr9700: remove code to drive nonexistent multicast
    filter (git-fixes).
  - commit 5659850
  - net: usb: r8152: fix transmit queue timeout (git-fixes).
  - commit cd570dd
  - usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
    (git-fixes).
  - commit 56a794c
  - usb: gadget: f_fs: fix DMA-BUF OUT queues (git-fixes).
  - commit 185e5e6
  - usb: gadget: f_fs: Fix ioctl error handling (git-fixes).
  - commit f20163c
  - usb: typec: ucsi: psy: Fix voltage and current max for non-Fixed
    PDOs (git-fixes).
  - commit 10c0ad8
  - firmware: arm_ffa: Unmap Rx/Tx buffers on init failure (git-fixes)
  - commit 8f51ada
  - spi: spidev: fix lock inversion between spi_lock and buf_lock (git-fixes)
  - commit b76bf6c
  - spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end (git-fixes)
  - commit c1581a2
  - spi: spi-mem: Limit octal DTR constraints to octal DTR situations (git-fixes)
  - commit 47ade1e
  - arm64: hugetlbpage: avoid unused-but-set-parameter warning (gcc-16) (git-fixes)
  - commit c2e347e
  - arm64: tegra: smaug: Add usb-role-switch support (git-fixes)
  - commit 2aec3f9
  - arm64: Disable branch profiling for all arm64 code (git-fixes)
  - commit 20e29ae
  - arm64: Add support for TSV110 Spectre-BHB mitigation (git-fixes)
  - commit 7b883f1
  - serial: 8250: 8250_omap.c: Clear DMA RX running status only
    after DMA termination is done (git-fixes).
  - serial: 8250: 8250_omap.c: Add support for handling UART error
    conditions (git-fixes).
  - serial: 8250_dw: handle clock enable errors in runtime_resume
    (git-fixes).
  - PCI: Enable ACS after configuring IOMMU for OF platforms
    (git-fixes).
  - PCI: Add ACS quirk for Qualcomm Hamoa & Glymur (git-fixes).
  - PCI: Fix pci_slot_lock () device locking (git-fixes).
  - PCI: Mark Nvidia GB10 to avoid bus reset (git-fixes).
  - PCI: Mark ASM1164 SATA controller to avoid bus reset
    (git-fixes).
  - PCI/AER: Clear stale errors on reporting agents upon probe
    (git-fixes).
  - PCI/MSI: Unmap MSI-X region on error (git-fixes).
  - char: tpm: cr50: Remove IRQF_ONESHOT (git-fixes).
  - commit 87922f3
  - mptcp: fix race in mptcp_pm_nl_flush_addrs_doit()
    (CVE-2026-23169 bsc#1258389).
  - commit ece2971
  - net: fix segmentation of forwarding fraglist GRO (CVE-2026-23154
    bsc#1258286).
  - commit f4ffe72

++++ kernel-rt:

  - libceph: reset sparse-read state in osd_fault() (CVE-2026-23136 bsc#1258303).
  - commit a1cc877
  - libceph: make calc_target() set t->paused, not just clear it (CVE-2026-23047 bsc#1257682).
  - commit 3225b77
  - mm/damon/sysfs-scheme: cleanup access_pattern subdirs on scheme
    dir setup failure (CVE-2026-23142 bsc#1258289).
  - commit 217a6fd
  - mm/damon/sysfs-scheme: cleanup quotas subdirs on scheme dir
    setup failure (git-fixes).
  - commit c642652
  - mm/damon/sysfs: cleanup attrs subdirs on context dir setup
    failure (CVE-2026-23144 bsc#1258290).
  - commit c7e0495
  - crypto: ccp - Fix a case where SNP_SHUTDOWN is missed
    (git-fixes).
  - drm/xe: Defer gt->mmio initialization until after multi-tile
    setup (git-fixes).
  - commit 56b85e5
  - wifi: ath10k: fix lock protection in
    ath10k_wmi_event_peer_sta_ps_state_chg() (stable-fixes).
  - wifi: rtw89: pci: restore LDO setting after device resume
    (stable-fixes).
  - wifi: rtw89: 8922a: add digital compensation for 2GHz
    (stable-fixes).
  - wifi: rtw89: fix unable to receive probe responses under MLO
    connection (stable-fixes).
  - wifi: iwlwifi: mvm: check the validity of noa_len
    (stable-fixes).
  - wifi: ath12k: fix preferred hardware mode calculation
    (stable-fixes).
  - wifi: ath11k: Fix failure to connect to a 6 GHz AP
    (stable-fixes).
  - wifi: ath11k: add pm quirk for Thinkpad Z13/Z16 Gen1
    (stable-fixes).
  - wifi: iwlegacy: add missing mutex protection in
    il4965_store_tx_power() (stable-fixes).
  - commit 4df290e
  - rtc: zynqmp: correct frequency value (stable-fixes).
  - thermal: int340x: Fix sysfs group leak on DLVR registration
    failure (stable-fixes).
  - soundwire: dmi-quirks: add mapping for Avell B.ON (OEM rebranded
    of NUC15) (stable-fixes).
  - soundwire: intel_auxdevice: add cs42l45 codec to
    wake_capable_list (stable-fixes).
  - staging: rtl8723bs: fix memory leak on failure path
    (stable-fixes).
  - staging: rtl8723bs: fix missing status update on
    sdio_alloc_irq() failure (stable-fixes).
  - watchdog: imx7ulp_wdt: handle the nowayout option
    (stable-fixes).
  - watchdog: starfive-wdt: Fix PM reference leak in probe error
    path (git-fixes).
  - watchdog/softlockup: fix sample ring index wrap in
    need_counting_irqs() (git-fixes).
  - wifi: iwlegacy: add missing mutex protection in
    il3945_store_measurement() (stable-fixes).
  - wifi: cfg80211: allow only one NAN interface, also in multi
    radio (stable-fixes).
  - wifi: rtw89: mac: correct page number for CSI response
    (stable-fixes).
  - wifi: rtw89: wow: add reason codes for disassociation in WoWLAN
    mode (stable-fixes).
  - wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
    (stable-fixes).
  - wifi: rtw89: ser: enable error IMR after recovering from L1
    (stable-fixes).
  - wifi: rtw89: 8922a: set random mac if efuse contains zeroes
    (stable-fixes).
  - wifi: rtw88: rtw8821cu: Add ID for Mercusys MU6H (stable-fixes).
  - wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode()
    (stable-fixes).
  - wifi: rtw88: fix DTIM period handling when conf->dtim_period
    is zero (stable-fixes).
  - wifi: libertas: fix WARNING in usb_tx_block (stable-fixes).
  - power: sequencing: fix missing state_lock in pwrseq_power_on()
    error path (stable-fixes).
  - spi: geni-qcom: Fix abort sequence execution for serial engine
    errors (stable-fixes).
  - spi: stm32: fix Overrun issue at < 8bpw (stable-fixes).
  - spi-geni-qcom: initialize mode related registers to 0
    (stable-fixes).
  - spi-geni-qcom: use xfer->bits_per_word for can_dma()
    (stable-fixes).
  - tools/power cpupower: Reset errno before strtoull()
    (stable-fixes).
  - powercap: intel_rapl: Add PL4 support for Ice Lake
    (stable-fixes).
  - commit a96ba92
  - PCI: Add defines for bridge window indexing (stable-fixes).
  - Refresh
    patches.suse/PCI-ACPI-Restrict-program_hpx_type2-to-AER-bits.patch.
  - commit 41bad5b
  - pinctrl: cirrus: cs42l43: Fix double-put in cs42l43_pin_probe()
    (git-fixes).
  - ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access
    (stable-fixes).
  - ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut
    (stable-fixes).
  - phy: mvebu-cp110-utmi: fix dr_mode property read from dts
    (stable-fixes).
  - phy: fsl-imx8mq-usb: disable bind/unbind platform driver feature
    (stable-fixes).
  - phy: cadence-torrent: restore parent clock for refclk during
    resume (stable-fixes).
  - phy: ti: phy-j721e-wiz: restore mux selection during resume
    (stable-fixes).
  - Revert "mmc: rtsx_pci_sdmmc: increase power-on settling delay
    to 5ms" (git-fixes).
  - nfc: nxp-nci: remove interrupt trigger type (stable-fixes).
  - PCI: Add Intel Nova Lake audio Device ID (stable-fixes).
  - commit 52ffef7
  - media: dvb-net: fix OOB access in ULE extension header tables
    (git-fixes).
  - mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms
    (git-fixes).
  - misc: bcm_vk: Fix possible null-pointer dereferences in
    bcm_vk_read() (stable-fixes).
  - misc: eeprom: Fix EWEN/EWDS/ERAL commands for 93xx56 and 93xx66
    (stable-fixes).
  - mfd: intel-lpss: Add Intel Nova Lake-S PCI IDs (stable-fixes).
  - myri10ge: avoid uninitialized variable use (stable-fixes).
  - media: rkisp1: Fix filter mode register configuration
    (stable-fixes).
  - media: ipu6: Always close firmware stream (stable-fixes).
  - media: ipu6: Close firmware streams on streaming enable failure
    (stable-fixes).
  - media: ipu6: Ensure stream_mutex is acquired when dealing with
    node list (stable-fixes).
  - media: mt9m114: Return -EPROBE_DEFER if no endpoint is found
    (stable-fixes).
  - media: mt9m114: Avoid a reset low spike during probe()
    (stable-fixes).
  - media: v4l2-async: Fix error handling on steps after finding
    a match (stable-fixes).
  - media: cx25821: Fix a resource leak in cx25821_dev_setup()
    (stable-fixes).
  - media: pvrusb2: fix URB leak in pvr2_send_request_ex
    (stable-fixes).
  - media: solo6x10: Check for out of bounds chip_id (stable-fixes).
  - media: adv7180: fix frame interval in progressive mode
    (stable-fixes).
  - media: amphion: Clear last_buffer_dequeued flag for
    DEC_CMD_START (stable-fixes).
  - media: mediatek: vcodec: Don't try to decode 422/444 VP9
    (stable-fixes).
  - media: chips-media: wave5: Process ready frames when CMD_STOP
    sent to Encoder (stable-fixes).
  - media: chips-media: wave5: Fix conditional in start_streaming
    (stable-fixes).
  - media: omap3isp: isppreview: always clamp in
    preview_try_format() (stable-fixes).
  - media: omap3isp: set initial format (stable-fixes).
  - mfd: simple-mfd-i2c: Add compatible strings for Layerscape
    QIXIS FPGA (stable-fixes).
  - mfd: simple-mfd-i2c: Add MAX77705 support (stable-fixes).
  - commit 26d6095
  - iio: magnetometer: Remove IRQF_ONESHOT (stable-fixes).
  - iio: Use IRQF_NO_THREAD (stable-fixes).
  - HID: i2c-hid: Add FocalTech FT8112 (stable-fixes).
  - media: omap3isp: isp_video_mbus_to_pix/pix_to_mbus fixes
    (stable-fixes).
  - media: dvb-core: dmxdevfilter must always flush bufs
    (stable-fixes).
  - HID: elecom: Add support for ELECOM HUGE Plus M-HT1MRBK
    (stable-fixes).
  - HID: logitech-hidpp: Add support for Logitech K980
    (stable-fixes).
  - HID: multitouch: add eGalaxTouch EXC3188 support (stable-fixes).
  - HID: logitech-hidpp: Check maxfield in hidpp_get_report_length()
    (stable-fixes).
  - hwmon: (pmbus/mpq8785) fix VOUT_MODE mismatch during
    identification (git-fixes).
  - hwmon: (f71882fg) Add F81968 support (stable-fixes).
  - hwmon: (nct6775) Add ASUS Pro WS WRX90E-SAGE SE (stable-fixes).
  - hwmon: (dell-smm) Add support for Dell OptiPlex 7080
    (stable-fixes).
  - i3c: mipi-i3c-hci: Reset RING_OPERATION1 fields during init
    (stable-fixes).
  - i3c: master: svc: Initialize 'dev' to NULL in
    svc_i3c_master_ibi_isr() (stable-fixes).
  - hwrng: core - Allow runtime disabling of the HW RNG
    (stable-fixes).
  - hwmon: pmbus: mpq8785: Add support for MPM82504 (stable-fixes).
  - hwmon: pmbus: mpq8785: Implement VOUT feedback resistor divider
    ratio configuration (stable-fixes).
  - hwmon: pmbus: mpq8785: Prepare driver for multiple device
    support (stable-fixes).
  - commit 755fe92
  - drm/xe/xe2_hpg: Fix handling of Wa_14019988906 & Wa_14019877138
    (git-fixes).
  - drm/xe/mmio: Avoid double-adjust in 64-bit reads (git-fixes).
  - drm/amdgpu: keep vga memory on MacBooks with switchable graphics
    (stable-fixes).
  - drm/amd/display: Remove conditional for shaper 3DLUT power-on
    (stable-fixes).
  - drm/amdgpu: Add HAINAN clock adjustment (stable-fixes).
  - drm/radeon: Add HAINAN clock adjustment (stable-fixes).
  - drm/amdgpu: Adjust usleep_range in fence wait (stable-fixes).
  - drm/amd/display: bypass post csc for additional color spaces
    in dal (stable-fixes).
  - drm/amd/display: Increase DCN35 SR enter/exit latency
    (stable-fixes).
  - drm/amd/display: Avoid updating surface with the same surface
    under MPO (stable-fixes).
  - drm/amd/display: Fix system resume lag issue (stable-fixes).
  - drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set()
    (stable-fixes).
  - drm/amd/display: Fix writeback on DCN 3.2+ (stable-fixes).
  - fpga: of-fpga-region: Fail if any bridge is missing
    (stable-fixes).
  - fix it87_wdt early reboot by reporting running timer
    (stable-fixes).
  - fbdev: ffb: fix corrupted video output on Sun FFB1
    (stable-fixes).
  - drm/amd/display: avoid dig reg access timeout on usb4 link
    training fail (stable-fixes).
  - drm/amd/display: Fix GFX12 family constant checks
    (stable-fixes).
  - drm/amd/display: Disable FEC when powering down encoders
    (stable-fixes).
  - drm/atmel-hlcdc: don't reject the commit if the src rect has
    fractional parts (stable-fixes).
  - drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after
    release (stable-fixes).
  - drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state
    callback (stable-fixes).
  - drm: Account property blob allocations to memcg (stable-fixes).
  - drm/amdkfd: Fix GART PTE for non-4K pagesize in
    svm_migrate_gart_map() (stable-fixes).
  - drm/amdkfd: Relax size checking during queue buffer get
    (stable-fixes).
  - drm/amd/display: only power down dig on phy endpoints
    (stable-fixes).
  - drm/amdgpu: Skip loading SDMA_RS64 in VF (stable-fixes).
  - drm/xe: Only toggle scheduling in TDR if GuC is running
    (stable-fixes).
  - drm/panel: Fix a possible null-pointer dereference in
    jdi_panel_dsi_remove() (stable-fixes).
  - drm/amd/display: Fix dsc eDP issue (stable-fixes).
  - drm/amd/display: Add signal type check for dcn401
    get_phyd32clk_src (stable-fixes).
  - gpu/panel-edp: add AUO panel entry for B140HAN06.4
    (stable-fixes).
  - HID: prodikeys: Check presence of pm->input_ep82 (stable-fixes).
  - HID: magicmouse: Do not crash on missing msc->input
    (stable-fixes).
  - HID: apple: Add "SONiX KN85 Keyboard" to the list of non-apple
    keyboards (stable-fixes).
  - gpio: aspeed-sgpio: Change the macro to support deferred probe
    (stable-fixes).
  - commit 2524956
  - drm/xe/ptl: Apply Wa_13011645652 (stable-fixes).
  - Refresh
    patches.suse/drm-xe-xe3lpg-Apply-Wa_14022293748-Wa_22019794406.patch.
  - commit 689b272
  - dmaengine: stm32-mdma: initialize m2m_hw_period and ccr to
    fix warnings (stable-fixes).
  - drm/amdgpu: add support for HDP IP version 6.1.1 (stable-fixes).
  - drm/amd/display: Add USB-C DP Alt Mode lane limitation in DCN32
    (stable-fixes).
  - drm/amdkfd: Handle GPU reset and drain retry fault race
    (stable-fixes).
  - drm/amdgpu: fix NULL pointer issue buffer funcs (stable-fixes).
  - drm/v3d: Set DMA segment size to avoid debug warnings
    (stable-fixes).
  - drm/i915/wakeref: clean up INTEL_WAKEREF_PUT_* flag macros
    (stable-fixes).
  - drm/display/dp_mst: Add protection against 0 vcpi
    (stable-fixes).
  - drm/xe/xe2_hpg: Add set of workarounds (stable-fixes).
  - drm/xe: Switch MMIO interface to take xe_mmio instead of xe_gt
    (stable-fixes).
  - drm/xe: Adjust mmio code to pass VF substructure to SRIOV code
    (stable-fixes).
  - drm/xe: Add xe_tile backpointer to xe_mmio (stable-fixes).
  - drm/xe: Switch mmio_ext to use 'struct xe_mmio' (stable-fixes).
  - drm/xe: Populate GT's mmio iomap from tile during init
    (stable-fixes).
  - drm/xe: Move GSI offset adjustment fields into 'struct xe_mmio'
    (stable-fixes).
  - drm/xe: Clarify size of MMIO region (stable-fixes).
  - drm/xe: Create dedicated xe_mmio structure (stable-fixes).
  - drm/xe: Move forcewake to 'gt.pm' substructure (stable-fixes).
  - docs: fix WARNING document not included in any toctree
    (stable-fixes).
  - commit 4836e0c
  - ASoC: amd: yc: Add DMI quirk for ASUS Vivobook Pro 15X M6501RR
    (stable-fixes).
  - dma: dma-axi-dmac: fix HW scatter-gather not looking at the
    queue (git-fixes).
  - dma: dma-axi-dmac: fix SW cyclic transfers (git-fixes).
  - dmaengine: sun6i: Choose appropriate burst length under maxburst
    (stable-fixes).
  - dmaengine: stm32-dma3: use module_platform_driver
    (stable-fixes).
  - crypto: ccp - Send PSP_CMD_TEE_RING_DESTROY when
    PSP_CMD_TEE_RING_INIT fails (git-fixes).
  - crypto: ccp - Factor out ring destroy handling to a helper
    (stable-fixes).
  - ata: libata: avoid long timeouts on hot-unplugged SATA DAS
    (stable-fixes).
  - Bluetooth: btusb: Add device ID for Realtek RTL8761BU
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID for RTL8852CE (stable-fixes).
  - Bluetooth: hci_conn: Set link_policy on incoming ACL connections
    (stable-fixes).
  - Bluetooth: hci_conn: use mod_delayed_work for active mode
    timeout (stable-fixes).
  - Bluetooth: btusb: Add support for MediaTek7920 0489:e158
    (stable-fixes).
  - ASoC: fsl: imx-rpmsg: use snd_soc_find_dai_with_mutex() in probe
    (stable-fixes).
  - ASoC: SOF: Intel: hda: Fix NULL pointer dereference
    (stable-fixes).
  - ASoC: codecs: max98390: Check return value of
    devm_gpiod_get_optional() in max98390_i2c_probe()
    (stable-fixes).
  - ASoC: sunxi: sun50i-dmic: Add missing check for
    devm_regmap_init_mmio (stable-fixes).
  - ASoC: soc-acpi-intel-arl-match: change rt722 amp endpoint to
    aggregated (stable-fixes).
  - ASoC: SOF: Intel: hda: Remove MODULE_SOFTDEP for
    snd-hda-codec-hdmi (stable-fixes).
  - ASoC: wm8962: Don't report a microphone if it's shorted to
    ground on plug (stable-fixes).
  - ASoC: wm8962: Add WM8962_ADC_MONOMIX to "3D Coefficients" mask
    (stable-fixes).
  - ASoC: nau8821: Cancel pending work before suspend (git-fixes).
  - ASoC: nau8821: Cancel delayed work on component remove
    (git-fixes).
  - ASoC: nau8821: Fixup nau8821_enable_jack_detect() (git-fixes).
  - ASoC: SOF: ipc4: Support for sending payload along with
    LARGE_CONFIG_GET (stable-fixes).
  - crypto: hisilicon/qm - move the barrier before writing to the
    mailbox register (stable-fixes).
  - crypto: ccp - narrow scope of snp_range_list (git-fixes).
  - APEI/GHES: ensure that won't go past CPER allocated record
    (stable-fixes).
  - ASoC: nau8821: Avoid unnecessary blocking in IRQ handler
    (stable-fixes).
  - crypto: ccp - Ensure implicit SEV/SNP init and shutdown in
    ioctls (stable-fixes).
  - commit ef48f01
  - ALSA: hda: cs35l56: Fix signedness error in
    cs35l56_hda_posture_put() (git-fixes).
  - ALSA: usb-audio: Add sanity check for OOB writes at silencing
    (stable-fixes).
  - ALSA: usb-audio: Update the number of packets properly at
    receiving (stable-fixes).
  - ACPI: x86: Force enabling of PWM2 on the Yogabook YB1-X90
    (stable-fixes).
  - ALSA: mixer: oss: Add card disconnect checkpoints
    (stable-fixes).
  - ALSA: usb-audio: Add iface reset and delay quirk for AB13X
    USB Audio (stable-fixes).
  - ALSA: hda/realtek - Enable mute LEDs on HP ENVY x360 15-es0xxx
    (stable-fixes).
  - ALSA: hda/conexant: Add headset mic fix for MECHREVO Wujie
    15X Pro (stable-fixes).
  - ALSA: hda/realtek: fix LG Gram Style 14 speakers (stable-fixes).
  - ALSA: hda/realtek: add HP Victus 16-e0xxx mute LED quirk
    (stable-fixes).
  - ALSA: pcm: Revert bufs move in snd_pcm_xfern_frames_ioctl()
    (stable-fixes).
  - ALSA: vmaster: Relax __free() variable declarations (git-fixes).
  - ALSA: pcm: Relax __free() variable declarations (git-fixes).
  - ACPI: processor: Fix NULL-pointer dereference in
    acpi_processor_errata_piix4() (stable-fixes).
  - ACPI: battery: fix incorrect charging status when current is
    zero (stable-fixes).
  - ACPI: resource: Add JWIPC JVC9100 to
    irq1_level_low_skip_override[] (stable-fixes).
  - ACPI: x86: s2idle: Invoke Microsoft _DSM Function 9 (Turn On
    Display) (stable-fixes).
  - ACPICA: Abort AML bytecode execution when executing AML_FATAL_OP
    (stable-fixes).
  - commit 119c4f9
  - net: usb: sr9700: remove code to drive nonexistent multicast
    filter (git-fixes).
  - commit 5659850
  - net: usb: r8152: fix transmit queue timeout (git-fixes).
  - commit cd570dd
  - usb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
    (git-fixes).
  - commit 56a794c
  - usb: gadget: f_fs: fix DMA-BUF OUT queues (git-fixes).
  - commit 185e5e6
  - usb: gadget: f_fs: Fix ioctl error handling (git-fixes).
  - commit f20163c
  - usb: typec: ucsi: psy: Fix voltage and current max for non-Fixed
    PDOs (git-fixes).
  - commit 10c0ad8
  - firmware: arm_ffa: Unmap Rx/Tx buffers on init failure (git-fixes)
  - commit 8f51ada
  - spi: spidev: fix lock inversion between spi_lock and buf_lock (git-fixes)
  - commit b76bf6c
  - spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end (git-fixes)
  - commit c1581a2
  - spi: spi-mem: Limit octal DTR constraints to octal DTR situations (git-fixes)
  - commit 47ade1e
  - arm64: hugetlbpage: avoid unused-but-set-parameter warning (gcc-16) (git-fixes)
  - commit c2e347e
  - arm64: tegra: smaug: Add usb-role-switch support (git-fixes)
  - commit 2aec3f9
  - arm64: Disable branch profiling for all arm64 code (git-fixes)
  - commit 20e29ae
  - arm64: Add support for TSV110 Spectre-BHB mitigation (git-fixes)
  - commit 7b883f1
  - serial: 8250: 8250_omap.c: Clear DMA RX running status only
    after DMA termination is done (git-fixes).
  - serial: 8250: 8250_omap.c: Add support for handling UART error
    conditions (git-fixes).
  - serial: 8250_dw: handle clock enable errors in runtime_resume
    (git-fixes).
  - PCI: Enable ACS after configuring IOMMU for OF platforms
    (git-fixes).
  - PCI: Add ACS quirk for Qualcomm Hamoa & Glymur (git-fixes).
  - PCI: Fix pci_slot_lock () device locking (git-fixes).
  - PCI: Mark Nvidia GB10 to avoid bus reset (git-fixes).
  - PCI: Mark ASM1164 SATA controller to avoid bus reset
    (git-fixes).
  - PCI/AER: Clear stale errors on reporting agents upon probe
    (git-fixes).
  - PCI/MSI: Unmap MSI-X region on error (git-fixes).
  - char: tpm: cr50: Remove IRQF_ONESHOT (git-fixes).
  - commit 87922f3
  - mptcp: fix race in mptcp_pm_nl_flush_addrs_doit()
    (CVE-2026-23169 bsc#1258389).
  - commit ece2971
  - net: fix segmentation of forwarding fraglist GRO (CVE-2026-23154
    bsc#1258286).
  - commit f4ffe72

++++ nvidia-open-driver-G06-signed:

  - adjusted logic for %suse_version bump with SLE16.1 Beta2 (jsc#PED-15826)

------------------------------------------------------------------
------------------  2026-3-4  -  Mar 4 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - pmdomain: imx: gpcv2: Fix the imx8mm gpu hang due to wrong
    adb400 reset (git-fixes).
  - commit 6367118
  - vsock/virtio: fix potential underflow in virtio_transport_get_credit() (bsc#1257755, CVE-2026-23069).
  - Refresh
    patches.suse/vsock-virtio-cap-TX-credit-to-local-buffer-size.patch.
  - commit c6696d4

++++ kernel-rt:

  - pmdomain: imx: gpcv2: Fix the imx8mm gpu hang due to wrong
    adb400 reset (git-fixes).
  - commit 6367118
  - vsock/virtio: fix potential underflow in virtio_transport_get_credit() (bsc#1257755, CVE-2026-23069).
  - Refresh
    patches.suse/vsock-virtio-cap-TX-credit-to-local-buffer-size.patch.
  - commit c6696d4

++++ mdadm:

  - Update to version 4.4+40.gad81df32:
    * avoid mdcheck_continue.timer and mdcheck_start.timer
    firing simultaneously (bsc#1243443, bsc#1259090)

++++ salt:

  - Make syntax in httputil_test compatible with Python 3.6
  - Fix KeyError in postgres module with PostgreSQL 17 (bsc#1254325)
  - Use internal deb classes instead of external aptsource lib
  - Speed up wheel key.finger call (bsc#1240532)
  - Backport security patches for Salt vendored tornado:
    * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903)
    * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905)
    * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904)
  - Simplify and speed up utils.find_json function (bsc#1246130)
  - Extend warn_until period to 2027
  - Added:
    * fix-tornado-s-httputil_test-syntax-for-python-3.6.patch
    * backport-add-maintain-m-privilege-to-postgres-module.patch
    * use-internal-salt.utils.pkg.deb-classes-instead-of-a.patch
    * speedup-wheel-key.finger-call-bsc-1240532-713.patch
    * fixes-for-security-issues-cve-2025-13836-cve-2025-67.patch
    * simplify-utils.json.find_json-function.patch
    * extend-fails-to-warnings-until-2027-742.patch

++++ suseconnect-ng:

  - Regressions found during QA test runs:
  - Ignore product in announce call (bsc#1257490)
  - Registration to SMT server with failed (bsc#1257625)
  - Backported by PATCH: fix-libsuseconnect-and-pci.patch

++++ vim:

    * Update Vim to version 9.2.0045 (from 9.1.1406).
    * Fix bsc#1258229 CVE-2026-26269 as 9.2.0045 is not impacted (fixed
    upstream).
    * Fix bsc#1246602 CVE-2025-53906 as 9.2.0045 is not impacted (fixed
    upstream).
    * Add wayland-client to BuildRequires and enable Wayland
    support.
    * Add Wayland include path to CFLAGS to fix clipboard compilation.
    * Package new Swedish (sv) man pages and clean up duplicate
    encodings (sv.ISO8859-1 and sv.UTF-8).
    * Add new patch:
  - reorder-exit-raw-mode.patch
    * Drop obsolete or upstreamed patches:
  - vim-7.3-filetype_spec.patch
  - vim-7.3-mktemp_tutor.patch
  - vim-7.4-filetype_apparmor.patch
  - vim-8.2.2411-globalvimrc.patch
    * Refresh the following patches:
  - vim-7.3-filetype_changes.patch
  - vim-7.3-filetype_ftl.patch
  - vim-7.3-sh_is_bash.patch
  - vim-9.1.1134-revert-putty-terminal-colors.patch

------------------------------------------------------------------
------------------  2026-3-3  -  Mar 3 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - iommu/mediatek: fix use-after-free on probe deferral
    (CVE-2025-71071 bsc#1256802).
  - commit 8109677
  - bonding: fix use-after-free due to enslave fail after slave
    array update (CVE-2026-23171 bsc#1258349).
  - commit 8dac8cc
  - gfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops (bsc#1249590
    CVE-2025-39753).
  - commit e7cde82

++++ kernel-rt:

  - iommu/mediatek: fix use-after-free on probe deferral
    (CVE-2025-71071 bsc#1256802).
  - commit 8109677
  - bonding: fix use-after-free due to enslave fail after slave
    array update (CVE-2026-23171 bsc#1258349).
  - commit 8dac8cc
  - gfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops (bsc#1249590
    CVE-2025-39753).
  - commit e7cde82

++++ linuxptp:

  - Move to DevicePolicy=closed instead of -PrivateDevices=true
    to allow access to devices (bsc#1256059)

------------------------------------------------------------------
------------------  2026-3-2  -  Mar 2 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready()
    (CVE-2026-23179 bsc#1258394).
  - commit ac77228
  - nvmet: fix race in nvmet_bio_done() leading to NULL pointer
    dereference (CVE-2026-23148 bsc#1258258).
  - commit 9bda130
  - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
    (CVE-2026-23112 bsc#1258184).
  - commit efcbeaa
  - nvme-fc: release admin tagset if init fails (git-fixes).
  - nvme-pci: disable secondary temp for Wodposit WPBSNM8
    (git-fixes).
  - nvme-fabrics: add ENOKEY to no retry criteria for authentication
    failures (git-fixes).
  - nvme-fc: don't hold rport lock when putting ctrl (git-fixes).
  - commit dd0c54b
  - pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask
    for 8mq vpu (CVE-2026-23116 bsc#1258277).
  - commit ff9d60e
  - Add bugnumber to existing mana and mana_ib changes (bsc#1251135 bsc#1251971).
  - scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT (git-fixes).
  - net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes).
  - commit 984835c
  - ceph: fix NULL pointer dereference in ceph_mds_auth_match() (CVE-2026-23189 bsc#1258308).
  - commit 51b8eb2
  - Update
    patches.suse/ALSA-ac97-fix-a-double-free-in-snd_ac97_controller_r.patch
    (git-fixes CVE-2025-71192 bsc#1257679).
  - Update
    patches.suse/ALSA-aloop-Fix-racy-access-at-PCM-trigger.patch
    (stable-fixes CVE-2026-23191 bsc#1258395).
  - Update
    patches.suse/ALSA-ctxfi-Fix-potential-OOB-access-in-audio-mixer-h.patch
    (stable-fixes CVE-2026-23076 bsc#1257788).
  - Update
    patches.suse/ALSA-scarlett2-Fix-buffer-overflow-in-config-retriev.patch
    (git-fixes CVE-2026-23078 bsc#1257789).
  - Update
    patches.suse/ALSA-usb-audio-Fix-use-after-free-in-snd_usb_mixer_f.patch
    (git-fixes CVE-2026-23089 bsc#1257790).
  - Update
    patches.suse/ASoC-amd-fix-memory-leak-in-acp3x-pdm-dma-ops.patch
    (git-fixes CVE-2026-23190 bsc#1258397).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-memory-leak-in-set_ssp_complete.patch
    (git-fixes CVE-2026-23151 bsc#1258237).
  - Update
    patches.suse/Bluetooth-hci_uart-fix-null-ptr-deref-in-hci_uart_wr.patch
    (git-fixes CVE-2026-23146 bsc#1258234).
  - Update
    patches.suse/HID-i2c-hid-fix-potential-buffer-overflow-in-i2c_hid.patch
    (stable-fixes CVE-2026-23178 bsc#1258358).
  - Update
    patches.suse/PCI-endpoint-Avoid-creating-sub-groups-asynchronousl.patch
    (git-fixes CVE-2025-71233 bsc#1258421).
  - Update
    patches.suse/arm64-Set-__nocfi-on-swsusp_arch_resume.patch
    (git-fixes CVE-2026-23128 bsc#1258298).
  - Update
    patches.suse/btrfs-always-detect-conflicting-inodes-when-logging-.patch
    (git-fixes CVE-2025-71183 bsc#1257631).
  - Update
    patches.suse/btrfs-do-not-strictly-require-dirty-metadata-thresho.patch
    (stable-fixes CVE-2026-23157 bsc#1258376).
  - Update
    patches.suse/btrfs-fix-deadlock-in-wait_current_trans-due-to-igno.patch
    (git-fixes CVE-2025-71194 bsc#1257687).
  - Update
    patches.suse/btrfs-release-path-before-initializing-extent-tree-i.patch
    (git-fixes CVE-2026-23018 bsc#1257551).
  - Update
    patches.suse/bus-fsl-mc-fix-use-after-free-in-driver_override_sho.patch
    (git-fixes CVE-2026-23221 bsc#1258660).
  - Update
    patches.suse/can-ems_usb-ems_usb_read_bulk_callback-fix-URB-memor.patch
    (git-fixes CVE-2026-23058 bsc#1257739).
  - Update
    patches.suse/can-etas_es58x-allow-partial-RX-URB-allocation-to-su.patch
    (git-fixes CVE-2026-23037 bsc#1257554).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-fix-URB-memo.patch
    (git-fixes CVE-2026-23031 bsc#1257600).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-fix-error-me.patch
    (git-fixes CVE-2026-23155 bsc#1258313).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-unanchor-URL.patch
    (git-fixes CVE-2026-23082 bsc#1257715).
  - Update
    patches.suse/can-j1939-make-j1939_session_activate-fail-if-device.patch
    (stable-fixes CVE-2025-71182 bsc#1257586).
  - Update
    patches.suse/can-kvaser_usb-kvaser_usb_read_bulk_callback-fix-URB.patch
    (git-fixes CVE-2026-23061 bsc#1257776).
  - Update
    patches.suse/can-mcba_usb-mcba_usb_read_bulk_callback-fix-URB-mem.patch
    (git-fixes CVE-2026-23080 bsc#1257714).
  - Update
    patches.suse/can-usb_8dev-usb_8dev_read_bulk_callback-fix-URB-mem.patch
    (git-fixes CVE-2026-23108 bsc#1257770).
  - Update
    patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch
    (git-fixes CVE-2026-23060 bsc#1257735).
  - Update
    patches.suse/crypto-iaa-Fix-out-of-bounds-index-in-find_empty_iaa.patch
    (git-fixes CVE-2025-71231 bsc#1258424).
  - Update
    patches.suse/crypto-omap-Allocate-OMAP_CRYPTO_FORCE_COPY-scatterl.patch
    (git-fixes CVE-2026-23222 bsc#1258484).
  - Update
    patches.suse/crypto-virtio-Add-spinlock-protection-with-virtqueue.patch
    (git-fixes CVE-2026-23229 bsc#1258429).
  - Update
    patches.suse/dmaengine-at_hdmac-fix-device-leak-on-of_dma_xlate.patch
    (git-fixes CVE-2025-71191 bsc#1257579).
  - Update
    patches.suse/dmaengine-bcm-sba-raid-fix-device-leak-on-probe.patch
    (git-fixes CVE-2025-71190 bsc#1257580).
  - Update
    patches.suse/dmaengine-dw-dmamux-fix-OF-node-leak-on-route-alloca.patch
    (git-fixes CVE-2025-71189 bsc#1257573).
  - Update
    patches.suse/dmaengine-lpc18xx-dmamux-fix-device-leak-on-route-al.patch
    (git-fixes CVE-2025-71188 bsc#1257576).
  - Update
    patches.suse/dmaengine-omap-dma-fix-dma_pool-resource-leak-in-err.patch
    (git-fixes CVE-2026-23033 bsc#1257570).
  - Update
    patches.suse/dmaengine-qcom-gpi-Fix-memory-leak-in-gpi_peripheral.patch
    (git-fixes CVE-2026-23026 bsc#1257562).
  - Update
    patches.suse/dmaengine-stm32-dmamux-fix-device-leak-on-route-allo.patch
    (git-fixes CVE-2025-71186 bsc#1257565).
  - Update
    patches.suse/dmaengine-ti-dma-crossbar-fix-device-leak-on-am335x-.patch
    (git-fixes CVE-2025-71185 bsc#1257560).
  - Update
    patches.suse/dmaengine-xilinx-xdma-Fix-regmap-max_register.patch
    (git-fixes CVE-2025-71195 bsc#1257704).
  - Update patches.suse/dpll-Prevent-duplicate-registrations.patch
    (git-fixes CVE-2026-23129 bsc#1258299).
  - Update
    patches.suse/drm-amd-pm-Disable-MMIO-access-during-SMU-Mode-1-res.patch
    (stable-fixes CVE-2026-23213 bsc#1258465).
  - Update
    patches.suse/drm-amdgpu-fix-NULL-pointer-dereference-in-amdgpu_gm.patch
    (git-fixes CVE-2026-23163 bsc#1258544).
  - Update patches.suse/drm-imx-tve-fix-probe-device-leak.patch
    (git-fixes CVE-2026-23170 bsc#1258379).
  - Update
    patches.suse/drm-panel-simple-fix-connector-type-for-DataImage-SC.patch
    (git-fixes CVE-2026-23049 bsc#1257723).
  - Update
    patches.suse/efivarfs-fix-error-propagation-in-efivar_entry_get.patch
    (git-fixes CVE-2026-23156 bsc#1258317).
  - Update
    patches.suse/ext4-fix-iloc.bh-leak-in-ext4_xattr_inode_update_ref.patch
    (git-fixes CVE-2026-23145 bsc#1258326).
  - Update
    patches.suse/gpio-virtuser-fix-UAF-in-configfs-release-path.patch
    (git-fixes CVE-2026-23158 bsc#1258323).
  - Update
    patches.suse/i2c-riic-Move-suspend-handling-to-NOIRQ-phase.patch
    (git-fixes CVE-2026-23055 bsc#1257730).
  - Update
    patches.suse/iio-adc-at91-sama5d2_adc-Fix-potential-use-after-fre.patch
    (git-fixes CVE-2025-71199 bsc#1257750).
  - Update
    patches.suse/iio-imu-st_lsm6dsx-fix-iio_chan_spec-for-sensors-wit.patch
    (git-fixes CVE-2025-71198 bsc#1257741).
  - Update
    patches.suse/intel_th-fix-device-leak-on-output-open.patch
    (git-fixes CVE-2026-23091 bsc#1257813).
  - Update
    patches.suse/interconnect-debugfs-initialize-src_node-and-dst_nod.patch
    (git-fixes CVE-2026-23123 bsc#1258276).
  - Update
    patches.suse/leds-led-class-Only-Add-LED-to-leds_list-when-it-is-.patch
    (git-fixes CVE-2026-23101 bsc#1257768).
  - Update
    patches.suse/mISDN-annotate-data-race-around-dev-work.patch
    (git-fixes CVE-2026-23121 bsc#1258309).
  - Update
    patches.suse/mm-shmem-prevent-infinite-loop-on-truncate-race.patch
    (CVE-2026-23161 bsc#1258355 CVE-2026-23177 bsc#1258324).
  - Update
    patches.suse/mmc-sdhci-of-dwcmshc-Prevent-illegal-clock-reduction.patch
    (git-fixes CVE-2025-71200 bsc#1258222).
  - Update
    patches.suse/msft-hv-3440-net-hv_netvsc-reject-RSS-hash-key-programming-withou.patch
    (bsc#1257473 CVE-2026-23054 bsc#1257732).
  - Update
    patches.suse/net-usb-pegasus-fix-memory-leak-in-update_eth_regs_a.patch
    (git-fixes CVE-2026-23021 bsc#1257557).
  - Update
    patches.suse/net-usb-r8152-fix-resume-reset-deadlock.patch
    (git-fixes CVE-2026-23188 bsc#1258331).
  - Update
    patches.suse/net-wwan-t7xx-fix-potential-skb-frags-overflow-in-RX.patch
    (git-fixes CVE-2026-23172 bsc#1258519).
  - Update
    patches.suse/nfc-llcp-Fix-memleak-in-nfc_llcp_send_ui_frame.patch
    (git-fixes CVE-2026-23150 bsc#1258354).
  - Update
    patches.suse/nfc-nci-Fix-race-between-rfkill-and-nci_unregister_d.patch
    (git-fixes CVE-2026-23167 bsc#1258374).
  - Update patches.suse/nfsd-provide-locking-for-v4_end_grace.patch
    (git-fixes CVE-2026-22980 bsc#1257222).
  - Update
    patches.suse/of-unittest-Fix-memory-leak-in-unittest_data_add.patch
    (git-fixes CVE-2026-23137 bsc#1258232).
  - Update
    patches.suse/pNFS-Fix-a-deadlock-when-returning-a-delegation-during-open.patch
    (git-fixes CVE-2026-23050 bsc#1257688).
  - Update
    patches.suse/phy-rockchip-inno-usb2-Fix-a-double-free-bug-in-rock.patch
    (git-fixes CVE-2026-23030 bsc#1257561).
  - Update
    patches.suse/phy-stm32-usphyc-Fix-off-by-one-in-probe.patch
    (git-fixes CVE-2025-71196 bsc#1257716).
  - Update
    patches.suse/platform-x86-amd-Fix-memory-leak-in-wbrf_record.patch
    (git-fixes CVE-2026-23065 bsc#1257742).
  - Update
    patches.suse/platform-x86-hp-bioscfg-Fix-kernel-panic-in-GET_INST.patch
    (git-fixes CVE-2026-23062 bsc#1257734).
  - Update
    patches.suse/platform-x86-hp-bioscfg-Fix-kobject-warnings-for-emp.patch
    (git-fixes CVE-2026-23131 bsc#1258297).
  - Update
    patches.suse/platform-x86-toshiba_haps-Fix-memory-leaks-in-add-re.patch
    (git-fixes CVE-2026-23176 bsc#1258256).
  - Update
    patches.suse/pnfs-flexfiles-Fix-memory-leak-in-nfs4_ff_alloc_deviceid_node.patch
    (git-fixes CVE-2026-23038 bsc#1257553).
  - Update
    patches.suse/regmap-Fix-race-condition-in-hwspinlock-irqsave-rout.patch
    (git-fixes CVE-2026-23071 bsc#1257706).
  - Update
    patches.suse/scsi-qla2xxx-Delay-module-unload-while-fabric-scan-i.patch
    (bsc#1256865 bsc#1256867 jsc#PED-14156 CVE-2025-71235
    bsc#1258469).
  - Update
    patches.suse/scsi-qla2xxx-Free-sp-in-error-path-to-fix-system-cra.patch
    (bsc#1256865 bsc#1256867 jsc#PED-14156 CVE-2025-71232
    bsc#1258422).
  - Update
    patches.suse/scsi-qla2xxx-Sanitize-payload-size-to-prevent-member.patch
    (git-fixes CVE-2026-23059 bsc#1257737).
  - Update
    patches.suse/scsi-qla2xxx-Validate-sp-before-freeing-associated-m.patch
    (bsc#1256865 bsc#1256867 jsc#PED-14156 CVE-2025-71236
    bsc#1258442).
  - Update
    patches.suse/slimbus-core-fix-device-reference-leak-on-report-pre.patch
    (git-fixes CVE-2026-23090 bsc#1257759).
  - Update
    patches.suse/smb-client-split-cached_fid-bitfields-to-avoid-shared-byte-RMW-rac.patch
    (bsc#1250748 bsc#1257154 CVE-2026-23230 bsc#1258430).
  - Update
    patches.suse/spi-tegra-Fix-a-memory-leak-in-tegra_slink_probe.patch
    (git-fixes CVE-2026-23182 bsc#1258259).
  - Update
    patches.suse/spi-tegra210-quad-Protect-curr_xfer-check-in-IRQ-han.patch
    (git-fixes bsc#1257952 CVE-2026-23207 bsc#1258524).
  - Update
    patches.suse/spi-tegra210-quad-Protect-curr_xfer-in-tegra_qspi_co.patch
    (git-fixes bsc#1257952 CVE-2026-23202 bsc#1258338).
  - Update
    patches.suse/uacce-ensure-safe-queue-release-with-state-managemen.patch
    (git-fixes CVE-2026-23063 bsc#1257722).
  - Update
    patches.suse/uacce-fix-cdev-handling-in-the-cleanup-path.patch
    (git-fixes CVE-2026-23096 bsc#1257809).
  - Update
    patches.suse/uacce-fix-isolate-sysfs-check-condition.patch
    (git-fixes CVE-2026-23094 bsc#1257811).
  - Update
    patches.suse/uacce-implement-mremap-in-uacce_vm_ops-to-return-EPE.patch
    (git-fixes CVE-2026-23056 bsc#1257729).
  - Update
    patches.suse/w1-therm-Fix-off-by-one-buffer-overflow-in-alarms_st.patch
    (git-fixes CVE-2025-71197 bsc#1257743).
  - Update
    patches.suse/wifi-ath10k-fix-dma_free_coherent-pointer.patch
    (git-fixes CVE-2026-23133 bsc#1258249).
  - Update
    patches.suse/wifi-ath12k-fix-dma_free_coherent-pointer.patch
    (git-fixes CVE-2026-23135 bsc#1258245).
  - Update
    patches.suse/wifi-mac80211-correctly-decode-TTLM-with-default-lin.patch
    (git-fixes CVE-2026-23152 bsc#1258252).
  - Update
    patches.suse/wifi-mac80211-ocb-skip-rx_no_sta-when-interface-is-n.patch
    (stable-fixes CVE-2025-71224 bsc#1258824).
  - Update
    patches.suse/wifi-rsi-Fix-memory-corruption-due-to-not-set-vif-dr.patch
    (git-fixes CVE-2026-23073 bsc#1257707).
  - Update
    patches.suse/wifi-rtl8xxxu-fix-slab-out-of-bounds-in-rtl8xxxu_sta.patch
    (git-fixes CVE-2025-71234 bsc#1258419).
  - Update
    patches.suse/wifi-rtw88-Fix-alignment-fault-in-rtw_core_enable_be.patch
    (git-fixes CVE-2025-71229 bsc#1258415).
  - Update
    patches.suse/wifi-wlcore-ensure-skb-headroom-before-skb_push.patch
    (stable-fixes CVE-2025-71222 bsc#1258279).
  - commit 154bcac
  - bonding: provide a net pointer to __skb_flow_dissect()
    (CVE-2026-23119 bsc#1258273).
  - commit 15d3820
  - drm/i915/display: Add quirk to skip retraining of dp link (bsc#1253129).
  - commit f730886
  - smb: client: Fix refcount leak for cifs_sb_tlink (bsc#1252924,
    CVE-2025-40103).
  - commit 176c45b
  - cifs: parse_dfs_referrals: prevent oob on malformed input
    (bsc#1252911, CVE-2025-40099).
  - commit 1544b30
  - sched/fair: Fix pelt clock sync when entering idle (bsc#1234634
    (Scheduler functional and performance backports SL-16.0)).
  - commit 24b0d4e
  - kABI fix for ipvlan: Make the addrs_lock be per port
    (CVE-2026-23103 bsc#1257773).
  - commit ee4d866
  - sched/fair: Fix pelt lost idle time detection (bsc#1234634
    (Scheduler functional and performance backports SL-16.0)).
  - sched/deadline: Stop dl_server before CPU goes offline
    (bsc#1234634 (Scheduler functional and performance backports
    SL-16.0)).
  - sched/core: Avoid direct access to hrtimer clockbase
    (bsc#1234634 (Scheduler functional and performance backports
    SL-16.0)).
  - sched/deadline: Fix race in push_dl_task() (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit b3c53c0
  - ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues
    (CVE-2026-23166 bsc#1258272).
  - net/mlx5e: TC, delete flows only for existing peers
    (CVE-2026-23173 bsc#1258520).
  - net/mlx5e: Don't gate FEC histograms on ppcnt_statistical_group
    (git-fixes).
  - commit 91bddd0

++++ kernel-rt:

  - nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready()
    (CVE-2026-23179 bsc#1258394).
  - commit ac77228
  - nvmet: fix race in nvmet_bio_done() leading to NULL pointer
    dereference (CVE-2026-23148 bsc#1258258).
  - commit 9bda130
  - nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec
    (CVE-2026-23112 bsc#1258184).
  - commit efcbeaa
  - nvme-fc: release admin tagset if init fails (git-fixes).
  - nvme-pci: disable secondary temp for Wodposit WPBSNM8
    (git-fixes).
  - nvme-fabrics: add ENOKEY to no retry criteria for authentication
    failures (git-fixes).
  - nvme-fc: don't hold rport lock when putting ctrl (git-fixes).
  - commit dd0c54b
  - pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask
    for 8mq vpu (CVE-2026-23116 bsc#1258277).
  - commit ff9d60e
  - Add bugnumber to existing mana and mana_ib changes (bsc#1251135 bsc#1251971).
  - scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT (git-fixes).
  - net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes).
  - commit 984835c
  - ceph: fix NULL pointer dereference in ceph_mds_auth_match() (CVE-2026-23189 bsc#1258308).
  - commit 51b8eb2
  - Update
    patches.suse/ALSA-ac97-fix-a-double-free-in-snd_ac97_controller_r.patch
    (git-fixes CVE-2025-71192 bsc#1257679).
  - Update
    patches.suse/ALSA-aloop-Fix-racy-access-at-PCM-trigger.patch
    (stable-fixes CVE-2026-23191 bsc#1258395).
  - Update
    patches.suse/ALSA-ctxfi-Fix-potential-OOB-access-in-audio-mixer-h.patch
    (stable-fixes CVE-2026-23076 bsc#1257788).
  - Update
    patches.suse/ALSA-scarlett2-Fix-buffer-overflow-in-config-retriev.patch
    (git-fixes CVE-2026-23078 bsc#1257789).
  - Update
    patches.suse/ALSA-usb-audio-Fix-use-after-free-in-snd_usb_mixer_f.patch
    (git-fixes CVE-2026-23089 bsc#1257790).
  - Update
    patches.suse/ASoC-amd-fix-memory-leak-in-acp3x-pdm-dma-ops.patch
    (git-fixes CVE-2026-23190 bsc#1258397).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-memory-leak-in-set_ssp_complete.patch
    (git-fixes CVE-2026-23151 bsc#1258237).
  - Update
    patches.suse/Bluetooth-hci_uart-fix-null-ptr-deref-in-hci_uart_wr.patch
    (git-fixes CVE-2026-23146 bsc#1258234).
  - Update
    patches.suse/HID-i2c-hid-fix-potential-buffer-overflow-in-i2c_hid.patch
    (stable-fixes CVE-2026-23178 bsc#1258358).
  - Update
    patches.suse/PCI-endpoint-Avoid-creating-sub-groups-asynchronousl.patch
    (git-fixes CVE-2025-71233 bsc#1258421).
  - Update
    patches.suse/arm64-Set-__nocfi-on-swsusp_arch_resume.patch
    (git-fixes CVE-2026-23128 bsc#1258298).
  - Update
    patches.suse/btrfs-always-detect-conflicting-inodes-when-logging-.patch
    (git-fixes CVE-2025-71183 bsc#1257631).
  - Update
    patches.suse/btrfs-do-not-strictly-require-dirty-metadata-thresho.patch
    (stable-fixes CVE-2026-23157 bsc#1258376).
  - Update
    patches.suse/btrfs-fix-deadlock-in-wait_current_trans-due-to-igno.patch
    (git-fixes CVE-2025-71194 bsc#1257687).
  - Update
    patches.suse/btrfs-release-path-before-initializing-extent-tree-i.patch
    (git-fixes CVE-2026-23018 bsc#1257551).
  - Update
    patches.suse/bus-fsl-mc-fix-use-after-free-in-driver_override_sho.patch
    (git-fixes CVE-2026-23221 bsc#1258660).
  - Update
    patches.suse/can-ems_usb-ems_usb_read_bulk_callback-fix-URB-memor.patch
    (git-fixes CVE-2026-23058 bsc#1257739).
  - Update
    patches.suse/can-etas_es58x-allow-partial-RX-URB-allocation-to-su.patch
    (git-fixes CVE-2026-23037 bsc#1257554).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-fix-URB-memo.patch
    (git-fixes CVE-2026-23031 bsc#1257600).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-fix-error-me.patch
    (git-fixes CVE-2026-23155 bsc#1258313).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-unanchor-URL.patch
    (git-fixes CVE-2026-23082 bsc#1257715).
  - Update
    patches.suse/can-j1939-make-j1939_session_activate-fail-if-device.patch
    (stable-fixes CVE-2025-71182 bsc#1257586).
  - Update
    patches.suse/can-kvaser_usb-kvaser_usb_read_bulk_callback-fix-URB.patch
    (git-fixes CVE-2026-23061 bsc#1257776).
  - Update
    patches.suse/can-mcba_usb-mcba_usb_read_bulk_callback-fix-URB-mem.patch
    (git-fixes CVE-2026-23080 bsc#1257714).
  - Update
    patches.suse/can-usb_8dev-usb_8dev_read_bulk_callback-fix-URB-mem.patch
    (git-fixes CVE-2026-23108 bsc#1257770).
  - Update
    patches.suse/crypto-authencesn-reject-too-short-AAD-assoclen-8-to.patch
    (git-fixes CVE-2026-23060 bsc#1257735).
  - Update
    patches.suse/crypto-iaa-Fix-out-of-bounds-index-in-find_empty_iaa.patch
    (git-fixes CVE-2025-71231 bsc#1258424).
  - Update
    patches.suse/crypto-omap-Allocate-OMAP_CRYPTO_FORCE_COPY-scatterl.patch
    (git-fixes CVE-2026-23222 bsc#1258484).
  - Update
    patches.suse/crypto-virtio-Add-spinlock-protection-with-virtqueue.patch
    (git-fixes CVE-2026-23229 bsc#1258429).
  - Update
    patches.suse/dmaengine-at_hdmac-fix-device-leak-on-of_dma_xlate.patch
    (git-fixes CVE-2025-71191 bsc#1257579).
  - Update
    patches.suse/dmaengine-bcm-sba-raid-fix-device-leak-on-probe.patch
    (git-fixes CVE-2025-71190 bsc#1257580).
  - Update
    patches.suse/dmaengine-dw-dmamux-fix-OF-node-leak-on-route-alloca.patch
    (git-fixes CVE-2025-71189 bsc#1257573).
  - Update
    patches.suse/dmaengine-lpc18xx-dmamux-fix-device-leak-on-route-al.patch
    (git-fixes CVE-2025-71188 bsc#1257576).
  - Update
    patches.suse/dmaengine-omap-dma-fix-dma_pool-resource-leak-in-err.patch
    (git-fixes CVE-2026-23033 bsc#1257570).
  - Update
    patches.suse/dmaengine-qcom-gpi-Fix-memory-leak-in-gpi_peripheral.patch
    (git-fixes CVE-2026-23026 bsc#1257562).
  - Update
    patches.suse/dmaengine-stm32-dmamux-fix-device-leak-on-route-allo.patch
    (git-fixes CVE-2025-71186 bsc#1257565).
  - Update
    patches.suse/dmaengine-ti-dma-crossbar-fix-device-leak-on-am335x-.patch
    (git-fixes CVE-2025-71185 bsc#1257560).
  - Update
    patches.suse/dmaengine-xilinx-xdma-Fix-regmap-max_register.patch
    (git-fixes CVE-2025-71195 bsc#1257704).
  - Update patches.suse/dpll-Prevent-duplicate-registrations.patch
    (git-fixes CVE-2026-23129 bsc#1258299).
  - Update
    patches.suse/drm-amd-pm-Disable-MMIO-access-during-SMU-Mode-1-res.patch
    (stable-fixes CVE-2026-23213 bsc#1258465).
  - Update
    patches.suse/drm-amdgpu-fix-NULL-pointer-dereference-in-amdgpu_gm.patch
    (git-fixes CVE-2026-23163 bsc#1258544).
  - Update patches.suse/drm-imx-tve-fix-probe-device-leak.patch
    (git-fixes CVE-2026-23170 bsc#1258379).
  - Update
    patches.suse/drm-panel-simple-fix-connector-type-for-DataImage-SC.patch
    (git-fixes CVE-2026-23049 bsc#1257723).
  - Update
    patches.suse/efivarfs-fix-error-propagation-in-efivar_entry_get.patch
    (git-fixes CVE-2026-23156 bsc#1258317).
  - Update
    patches.suse/ext4-fix-iloc.bh-leak-in-ext4_xattr_inode_update_ref.patch
    (git-fixes CVE-2026-23145 bsc#1258326).
  - Update
    patches.suse/gpio-virtuser-fix-UAF-in-configfs-release-path.patch
    (git-fixes CVE-2026-23158 bsc#1258323).
  - Update
    patches.suse/i2c-riic-Move-suspend-handling-to-NOIRQ-phase.patch
    (git-fixes CVE-2026-23055 bsc#1257730).
  - Update
    patches.suse/iio-adc-at91-sama5d2_adc-Fix-potential-use-after-fre.patch
    (git-fixes CVE-2025-71199 bsc#1257750).
  - Update
    patches.suse/iio-imu-st_lsm6dsx-fix-iio_chan_spec-for-sensors-wit.patch
    (git-fixes CVE-2025-71198 bsc#1257741).
  - Update
    patches.suse/intel_th-fix-device-leak-on-output-open.patch
    (git-fixes CVE-2026-23091 bsc#1257813).
  - Update
    patches.suse/interconnect-debugfs-initialize-src_node-and-dst_nod.patch
    (git-fixes CVE-2026-23123 bsc#1258276).
  - Update
    patches.suse/leds-led-class-Only-Add-LED-to-leds_list-when-it-is-.patch
    (git-fixes CVE-2026-23101 bsc#1257768).
  - Update
    patches.suse/mISDN-annotate-data-race-around-dev-work.patch
    (git-fixes CVE-2026-23121 bsc#1258309).
  - Update
    patches.suse/mm-shmem-prevent-infinite-loop-on-truncate-race.patch
    (CVE-2026-23161 bsc#1258355 CVE-2026-23177 bsc#1258324).
  - Update
    patches.suse/mmc-sdhci-of-dwcmshc-Prevent-illegal-clock-reduction.patch
    (git-fixes CVE-2025-71200 bsc#1258222).
  - Update
    patches.suse/msft-hv-3440-net-hv_netvsc-reject-RSS-hash-key-programming-withou.patch
    (bsc#1257473 CVE-2026-23054 bsc#1257732).
  - Update
    patches.suse/net-usb-pegasus-fix-memory-leak-in-update_eth_regs_a.patch
    (git-fixes CVE-2026-23021 bsc#1257557).
  - Update
    patches.suse/net-usb-r8152-fix-resume-reset-deadlock.patch
    (git-fixes CVE-2026-23188 bsc#1258331).
  - Update
    patches.suse/net-wwan-t7xx-fix-potential-skb-frags-overflow-in-RX.patch
    (git-fixes CVE-2026-23172 bsc#1258519).
  - Update
    patches.suse/nfc-llcp-Fix-memleak-in-nfc_llcp_send_ui_frame.patch
    (git-fixes CVE-2026-23150 bsc#1258354).
  - Update
    patches.suse/nfc-nci-Fix-race-between-rfkill-and-nci_unregister_d.patch
    (git-fixes CVE-2026-23167 bsc#1258374).
  - Update patches.suse/nfsd-provide-locking-for-v4_end_grace.patch
    (git-fixes CVE-2026-22980 bsc#1257222).
  - Update
    patches.suse/of-unittest-Fix-memory-leak-in-unittest_data_add.patch
    (git-fixes CVE-2026-23137 bsc#1258232).
  - Update
    patches.suse/pNFS-Fix-a-deadlock-when-returning-a-delegation-during-open.patch
    (git-fixes CVE-2026-23050 bsc#1257688).
  - Update
    patches.suse/phy-rockchip-inno-usb2-Fix-a-double-free-bug-in-rock.patch
    (git-fixes CVE-2026-23030 bsc#1257561).
  - Update
    patches.suse/phy-stm32-usphyc-Fix-off-by-one-in-probe.patch
    (git-fixes CVE-2025-71196 bsc#1257716).
  - Update
    patches.suse/platform-x86-amd-Fix-memory-leak-in-wbrf_record.patch
    (git-fixes CVE-2026-23065 bsc#1257742).
  - Update
    patches.suse/platform-x86-hp-bioscfg-Fix-kernel-panic-in-GET_INST.patch
    (git-fixes CVE-2026-23062 bsc#1257734).
  - Update
    patches.suse/platform-x86-hp-bioscfg-Fix-kobject-warnings-for-emp.patch
    (git-fixes CVE-2026-23131 bsc#1258297).
  - Update
    patches.suse/platform-x86-toshiba_haps-Fix-memory-leaks-in-add-re.patch
    (git-fixes CVE-2026-23176 bsc#1258256).
  - Update
    patches.suse/pnfs-flexfiles-Fix-memory-leak-in-nfs4_ff_alloc_deviceid_node.patch
    (git-fixes CVE-2026-23038 bsc#1257553).
  - Update
    patches.suse/regmap-Fix-race-condition-in-hwspinlock-irqsave-rout.patch
    (git-fixes CVE-2026-23071 bsc#1257706).
  - Update
    patches.suse/scsi-qla2xxx-Delay-module-unload-while-fabric-scan-i.patch
    (bsc#1256865 bsc#1256867 jsc#PED-14156 CVE-2025-71235
    bsc#1258469).
  - Update
    patches.suse/scsi-qla2xxx-Free-sp-in-error-path-to-fix-system-cra.patch
    (bsc#1256865 bsc#1256867 jsc#PED-14156 CVE-2025-71232
    bsc#1258422).
  - Update
    patches.suse/scsi-qla2xxx-Sanitize-payload-size-to-prevent-member.patch
    (git-fixes CVE-2026-23059 bsc#1257737).
  - Update
    patches.suse/scsi-qla2xxx-Validate-sp-before-freeing-associated-m.patch
    (bsc#1256865 bsc#1256867 jsc#PED-14156 CVE-2025-71236
    bsc#1258442).
  - Update
    patches.suse/slimbus-core-fix-device-reference-leak-on-report-pre.patch
    (git-fixes CVE-2026-23090 bsc#1257759).
  - Update
    patches.suse/smb-client-split-cached_fid-bitfields-to-avoid-shared-byte-RMW-rac.patch
    (bsc#1250748 bsc#1257154 CVE-2026-23230 bsc#1258430).
  - Update
    patches.suse/spi-tegra-Fix-a-memory-leak-in-tegra_slink_probe.patch
    (git-fixes CVE-2026-23182 bsc#1258259).
  - Update
    patches.suse/spi-tegra210-quad-Protect-curr_xfer-check-in-IRQ-han.patch
    (git-fixes bsc#1257952 CVE-2026-23207 bsc#1258524).
  - Update
    patches.suse/spi-tegra210-quad-Protect-curr_xfer-in-tegra_qspi_co.patch
    (git-fixes bsc#1257952 CVE-2026-23202 bsc#1258338).
  - Update
    patches.suse/uacce-ensure-safe-queue-release-with-state-managemen.patch
    (git-fixes CVE-2026-23063 bsc#1257722).
  - Update
    patches.suse/uacce-fix-cdev-handling-in-the-cleanup-path.patch
    (git-fixes CVE-2026-23096 bsc#1257809).
  - Update
    patches.suse/uacce-fix-isolate-sysfs-check-condition.patch
    (git-fixes CVE-2026-23094 bsc#1257811).
  - Update
    patches.suse/uacce-implement-mremap-in-uacce_vm_ops-to-return-EPE.patch
    (git-fixes CVE-2026-23056 bsc#1257729).
  - Update
    patches.suse/w1-therm-Fix-off-by-one-buffer-overflow-in-alarms_st.patch
    (git-fixes CVE-2025-71197 bsc#1257743).
  - Update
    patches.suse/wifi-ath10k-fix-dma_free_coherent-pointer.patch
    (git-fixes CVE-2026-23133 bsc#1258249).
  - Update
    patches.suse/wifi-ath12k-fix-dma_free_coherent-pointer.patch
    (git-fixes CVE-2026-23135 bsc#1258245).
  - Update
    patches.suse/wifi-mac80211-correctly-decode-TTLM-with-default-lin.patch
    (git-fixes CVE-2026-23152 bsc#1258252).
  - Update
    patches.suse/wifi-mac80211-ocb-skip-rx_no_sta-when-interface-is-n.patch
    (stable-fixes CVE-2025-71224 bsc#1258824).
  - Update
    patches.suse/wifi-rsi-Fix-memory-corruption-due-to-not-set-vif-dr.patch
    (git-fixes CVE-2026-23073 bsc#1257707).
  - Update
    patches.suse/wifi-rtl8xxxu-fix-slab-out-of-bounds-in-rtl8xxxu_sta.patch
    (git-fixes CVE-2025-71234 bsc#1258419).
  - Update
    patches.suse/wifi-rtw88-Fix-alignment-fault-in-rtw_core_enable_be.patch
    (git-fixes CVE-2025-71229 bsc#1258415).
  - Update
    patches.suse/wifi-wlcore-ensure-skb-headroom-before-skb_push.patch
    (stable-fixes CVE-2025-71222 bsc#1258279).
  - commit 154bcac
  - bonding: provide a net pointer to __skb_flow_dissect()
    (CVE-2026-23119 bsc#1258273).
  - commit 15d3820
  - drm/i915/display: Add quirk to skip retraining of dp link (bsc#1253129).
  - commit f730886
  - smb: client: Fix refcount leak for cifs_sb_tlink (bsc#1252924,
    CVE-2025-40103).
  - commit 176c45b
  - cifs: parse_dfs_referrals: prevent oob on malformed input
    (bsc#1252911, CVE-2025-40099).
  - commit 1544b30
  - sched/fair: Fix pelt clock sync when entering idle (bsc#1234634
    (Scheduler functional and performance backports SL-16.0)).
  - commit 24b0d4e
  - kABI fix for ipvlan: Make the addrs_lock be per port
    (CVE-2026-23103 bsc#1257773).
  - commit ee4d866
  - sched/fair: Fix pelt lost idle time detection (bsc#1234634
    (Scheduler functional and performance backports SL-16.0)).
  - sched/deadline: Stop dl_server before CPU goes offline
    (bsc#1234634 (Scheduler functional and performance backports
    SL-16.0)).
  - sched/core: Avoid direct access to hrtimer clockbase
    (bsc#1234634 (Scheduler functional and performance backports
    SL-16.0)).
  - sched/deadline: Fix race in push_dl_task() (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit b3c53c0
  - ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues
    (CVE-2026-23166 bsc#1258272).
  - net/mlx5e: TC, delete flows only for existing peers
    (CVE-2026-23173 bsc#1258520).
  - net/mlx5e: Don't gate FEC histograms on ppcnt_statistical_group
    (git-fixes).
  - commit 91bddd0

++++ systemd:

  - Import commit 3c53ef3ea20bd43ef587cbdfa7107aeb1ef55654 (merge of v257.11)
    This merge includes the following fix:
    54588d2ded core: validate input cgroup path more prudently (bsc#1259418 CVE-2026-29111)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/358010e6e90269570025c598b1430afa1e2ff6ca...3c53ef3ea20bd43ef587cbdfa7107aeb1ef55654

++++ openssh:

  - Add openssh-7.7p1-gssapi-new-unique.patch (bsc#1258166). This
    allows using SSSD with a non-file backend.

++++ virtiofsd:

  - Add CVE-2026-25727.patch: Avoid denial of service when parsing
    Rfc2822(bsc#1257912 CVE-2026-25727).

------------------------------------------------------------------
------------------  2026-3-1  -  Mar 1 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - device property: Allow secondary lookup in
    fwnode_get_next_child_node() (git-fixes).
  - commit 4755249

++++ kernel-rt:

  - device property: Allow secondary lookup in
    fwnode_get_next_child_node() (git-fixes).
  - commit 4755249

++++ util-linux-systemd:

  - Use full hostname for PAM to ensure correct access control for
    "login -h" (bsc#1258859, CVE-2026-3184,
    util-linux-CVE-2026-3184.patch).

++++ util-linux:

  - Use full hostname for PAM to ensure correct access control for
    "login -h" (bsc#1258859, CVE-2026-3184,
    util-linux-CVE-2026-3184.patch).

------------------------------------------------------------------
------------------  2026-2-28  -  Feb 28 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/amdgpu: Fix locking bugs in error paths (git-fixes).
  - drm/amdgpu: Replace kzalloc + copy_from_user with memdup_user
    (stable-fixes).
  - commit baf5092
  - ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB
    Audio 2.0 (stable-fixes).
  - ALSA: usb-audio: Check max frame size for implicit feedback
    mode, too (stable-fixes).
  - commit 1958ad9
  - PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value (git-fixes).
  - mmc: mmci: Fix device_node reference leak in
    of_get_dml_pipe_index() (git-fixes).
  - ALSA: usb-audio: Use correct version for UAC3 header validation
    (git-fixes).
  - ALSA: usb-audio: Use inclusive terms (git-fixes).
  - ALSA: usb-audio: Cap the packet size pre-calculations
    (git-fixes).
  - ALSA: usb-audio: Remove VALIDATE_RATES quirk for Focusrite
    devices (git-fixes).
  - drm/amd: Disable MES LR compute W/A (git-fixes).
  - drm/amdgpu: Unlock a mutex before destroying it (git-fixes).
  - drm/xe/sync: Cleanup partially initialized sync on parse failure
    (git-fixes).
  - drm/bridge: samsung-dsim: Fix memory leak in error path
    (git-fixes).
  - drm/bridge: ti-sn65dsi86: Enable HPD polling if IRQ is not used
    (git-fixes).
  - drm/logicvc: Fix device node reference leak in
    logicvc_drm_config_parse() (git-fixes).
  - drm/vmwgfx: Return the correct value in vmw_translate_ptr
    functions (git-fixes).
  - drm/vmwgfx: Fix invalid kref_put callback in
    vmw_bo_dirty_release (git-fixes).
  - commit 65e48f9

++++ kernel-rt:

  - drm/amdgpu: Fix locking bugs in error paths (git-fixes).
  - drm/amdgpu: Replace kzalloc + copy_from_user with memdup_user
    (stable-fixes).
  - commit baf5092
  - ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB
    Audio 2.0 (stable-fixes).
  - ALSA: usb-audio: Check max frame size for implicit feedback
    mode, too (stable-fixes).
  - commit 1958ad9
  - PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value (git-fixes).
  - mmc: mmci: Fix device_node reference leak in
    of_get_dml_pipe_index() (git-fixes).
  - ALSA: usb-audio: Use correct version for UAC3 header validation
    (git-fixes).
  - ALSA: usb-audio: Use inclusive terms (git-fixes).
  - ALSA: usb-audio: Cap the packet size pre-calculations
    (git-fixes).
  - ALSA: usb-audio: Remove VALIDATE_RATES quirk for Focusrite
    devices (git-fixes).
  - drm/amd: Disable MES LR compute W/A (git-fixes).
  - drm/amdgpu: Unlock a mutex before destroying it (git-fixes).
  - drm/xe/sync: Cleanup partially initialized sync on parse failure
    (git-fixes).
  - drm/bridge: samsung-dsim: Fix memory leak in error path
    (git-fixes).
  - drm/bridge: ti-sn65dsi86: Enable HPD polling if IRQ is not used
    (git-fixes).
  - drm/logicvc: Fix device node reference leak in
    logicvc_drm_config_parse() (git-fixes).
  - drm/vmwgfx: Return the correct value in vmw_translate_ptr
    functions (git-fixes).
  - drm/vmwgfx: Fix invalid kref_put callback in
    vmw_bo_dirty_release (git-fixes).
  - commit 65e48f9

------------------------------------------------------------------
------------------  2026-2-27  -  Feb 27 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ipvlan: Make the addrs_lock be per port (CVE-2026-23103
    bsc#1257773).
  - fou: Don't allow 0 for FOU_ATTR_IPPROTO (CVE-2026-23083
    bsc#1257745).
  - bonding: limit BOND_MODE_8023AD to Ethernet devices
    (CVE-2026-23099 bsc#1257816).
  - netlink: specs: fou: change local-v6/peer-v6 check
    (CVE-2026-23083 bsc#1257745).
  - tools: ynl-gen: use big-endian netlink attribute types
    (CVE-2026-23083 bsc#1257745).
  - commit 9c95bcf
  - netfilter: nf_conncount: update last_gc only when GC has been
    performed (CVE-2026-23139 bsc#1258304).
  - commit f7db582
  - netfilter: nf_tables: fix inverted genmask check in
    nft_map_catchall_activate() (CVE-2026-23111 bsc#1258181).
  - commit a2cf5ae
  - ipmi: ipmb: initialise event handler read bytes (git-fixes).
  - wifi: mac80211: fix NULL pointer dereference in
    mesh_rx_csa_frame() (git-fixes).
  - wifi: mac80211: bounds-check link_id in
    ieee80211_ml_reconfiguration (git-fixes).
  - wifi: radiotap: reject radiotap with unknown bits (git-fixes).
  - wifi: cfg80211: cancel rfkill_block work in wiphy_unregister()
    (git-fixes).
  - wifi: cfg80211: wext: fix IGTK key ID off-by-one (git-fixes).
  - net: usb: kaweth: validate USB endpoints (git-fixes).
  - net: usb: kalmia: validate USB endpoints (git-fixes).
  - nfc: pn533: properly drop the usb interface reference on
    disconnect (git-fixes).
  - Bluetooth: L2CAP: Fix missing key size check for
    L2CAP_LE_CONN_REQ (git-fixes).
  - Bluetooth: L2CAP: Fix not checking output MTU is acceptable
    on L2CAP_ECRED_CONN_REQ (git-fixes).
  - Bluetooth: L2CAP: Fix response to L2CAP_ECRED_CONN_REQ
    (git-fixes).
  - Bluetooth: hci_qca: Cleanup on all setup failures (git-fixes).
  - Bluetooth: L2CAP: Fix result of L2CAP_ECRED_CONN_RSP when MTU
    is too short (git-fixes).
  - Bluetooth: L2CAP: Fix invalid response to L2CAP_ECRED_RECONF_REQ
    (git-fixes).
  - net: usb: pegasus: enable basic endpoint checking (git-fixes).
  - net: wan: farsync: Fix use-after-free bugs caused by unfinished
    tasklets (git-fixes).
  - net: usb: lan78xx: scan all MDIO addresses on LAN7801
    (git-fixes).
  - net: usb: kaweth: remove TX queue manipulation in
    kaweth_set_rx_mode (git-fixes).
  - commit cd64e0b

++++ kernel-rt:

  - ipvlan: Make the addrs_lock be per port (CVE-2026-23103
    bsc#1257773).
  - fou: Don't allow 0 for FOU_ATTR_IPPROTO (CVE-2026-23083
    bsc#1257745).
  - bonding: limit BOND_MODE_8023AD to Ethernet devices
    (CVE-2026-23099 bsc#1257816).
  - netlink: specs: fou: change local-v6/peer-v6 check
    (CVE-2026-23083 bsc#1257745).
  - tools: ynl-gen: use big-endian netlink attribute types
    (CVE-2026-23083 bsc#1257745).
  - commit 9c95bcf
  - netfilter: nf_conncount: update last_gc only when GC has been
    performed (CVE-2026-23139 bsc#1258304).
  - commit f7db582
  - netfilter: nf_tables: fix inverted genmask check in
    nft_map_catchall_activate() (CVE-2026-23111 bsc#1258181).
  - commit a2cf5ae
  - ipmi: ipmb: initialise event handler read bytes (git-fixes).
  - wifi: mac80211: fix NULL pointer dereference in
    mesh_rx_csa_frame() (git-fixes).
  - wifi: mac80211: bounds-check link_id in
    ieee80211_ml_reconfiguration (git-fixes).
  - wifi: radiotap: reject radiotap with unknown bits (git-fixes).
  - wifi: cfg80211: cancel rfkill_block work in wiphy_unregister()
    (git-fixes).
  - wifi: cfg80211: wext: fix IGTK key ID off-by-one (git-fixes).
  - net: usb: kaweth: validate USB endpoints (git-fixes).
  - net: usb: kalmia: validate USB endpoints (git-fixes).
  - nfc: pn533: properly drop the usb interface reference on
    disconnect (git-fixes).
  - Bluetooth: L2CAP: Fix missing key size check for
    L2CAP_LE_CONN_REQ (git-fixes).
  - Bluetooth: L2CAP: Fix not checking output MTU is acceptable
    on L2CAP_ECRED_CONN_REQ (git-fixes).
  - Bluetooth: L2CAP: Fix response to L2CAP_ECRED_CONN_REQ
    (git-fixes).
  - Bluetooth: hci_qca: Cleanup on all setup failures (git-fixes).
  - Bluetooth: L2CAP: Fix result of L2CAP_ECRED_CONN_RSP when MTU
    is too short (git-fixes).
  - Bluetooth: L2CAP: Fix invalid response to L2CAP_ECRED_RECONF_REQ
    (git-fixes).
  - net: usb: pegasus: enable basic endpoint checking (git-fixes).
  - net: wan: farsync: Fix use-after-free bugs caused by unfinished
    tasklets (git-fixes).
  - net: usb: lan78xx: scan all MDIO addresses on LAN7801
    (git-fixes).
  - net: usb: kaweth: remove TX queue manipulation in
    kaweth_set_rx_mode (git-fixes).
  - commit cd64e0b

------------------------------------------------------------------
------------------  2026-2-26  -  Feb 26 2026  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Update to version 2.0.20:
    + This release adds the following features:
  - Add support for changing AMD UMA carveout size
  - Warn the user if they are using the blocked-firmware
    functionality
    + This release fixes the following bugs:
  - Disable the UEFI plugins on 32bit x86
  - Do not hang when parsing an invalid USB descriptor
  - Do not return an error if the fastboot property is not
    provided
  - Fix a CCGX DMC regression when installing on the HP G5 dock
  - Fix a harmless heap OOB read in AMD kria SOM EEPROM parser
  - Fix a potential fastboot string over-read
  - Fix a regression causing MBIM QDU updates to fail
  - Honor polkit auth for emulation tag modify device
  - Speed up calculating the cab checksum by ~21%
  - Verify the uncompressed size when decompressing CAB files
    + This release adds support for the following hardware:
  - HP Engage One G2 Advanced Hub
  - PixArt PJP274 (Framework Laptop)
  - Several new Jabra GNP devices

++++ haproxy:

  - Update to version 3.2.12+git0.6011f448e:
    * [RELEASE] Released version 3.2.12
    * BUG/MAJOR: quic: fix parsing frame type
    * BUG/MAJOR: quic: reject invalid token
    * BUG/MINOR: startup: handle a possible strdup() failure
    * BUG/MINOR: startup: fix allocation error message of progname string
    * BUG/MINOR: config: Fix setting of alt_proto
    * DOC: config: mention the limitation on server id range for consistent hash
    * BUG/MEDIUM: lb-chash: always properly initialize lb_nodes with dynamic servers
    * BUG/MINOR: cpu-topo: count cores not cpus to distinguish core types
    * CLEANUP: haproxy: fix bad line wrapping in run_poll_loop()
    * BUG/MEDIUM: threads: Atomically set TH_FL_SLEEPING and clr FL_NOTIFIED
    * DOC: internals: cleanup few typos in master-worker documentation
    * BUG/MEDIUM: applet: Fix test on shut flags for legacy applets
    * BUG/MAJOR: applet: Don't call I/O handler if the applet was shut
    * MEDIUM: ssl: don't always process pending handshakes on closed connections
    * MINOR: rawsock: introduce CO_RFL_TRY_HARDER to detect closures on complete reads
    * [RELEASE] Released version 3.2.11
    * BUG/MEDIUM: debug: only dump Lua state when panicking
    * BUG/MINOR: config: check capture pool creations for failures
    * DOC: reg-tests: update VTest upstream link in the starting guide
    * MINOR: hlua: Add support for lua 5.5
    * BUG/MEDIUM: mux-h2: synchronize all conditions to create a new backend stream
    * BUG/MINOR: mworker/cli: fix show proc pagination using reload counter
    * BUG/MINOR: mworker/cli: 'show proc' is limited by buffer size
    * CLEANUP: mworker/cli: remove useless variable
    * BUG/MINOR: ssl: fix error message of tune.ssl.certificate-compression
    * MINOR: ssl: allow to disable certificate compression
    * BUG/MEDIUM: mux-h1: Skip UNUSED htx block when formating the start line
    * BUG/MINOR: promex: Detach promex from the server on error dump its metrics dump
    * BUG/MINOR: hlua: consume error object if ignored after a failing lua_pcall()
    * BUG/MEDIUM: hlua: fix invalid lua_pcall() usage in hlua_traceback()
    * BUG/MINOR: proxy: fix deinit crash on defaults with duplicate name
    * REGTESTS: ssl: fix generate-certificates w/ LibreSSL
    * BUG/MEDIUM: mux-quic: prevent BUG_ON() on aborted uni stream close
    * BUG/MEDIUM: ssl: fix generate-certificates option when SNI greater than 64bytes
    * BUG/MEDIUM: ssl: fix error path on generate-certificates
    * BUG/MEDIUM: log: parsing log-forward options may result in segfault
    * BUG/MEDIUM: promex: server iteration may rely on stale server
    * BUG/MINOR: cfgparse: fix "default" prefix parsing
    * BUG/MINOR: proxy: free persist_rules
    * BUG/MINOR: http_act: fix deinit performed on uninitialized lf_expr in release_http_map()
    * BUG/MEDIUM: quic: fix ACK ECN frame parsing
    * BUG/MINOR: hlua_fcn: ensure Patref:add_bulk() is given a table object before using it
    * BUG/MINOR: hlua_fcn: fix broken yield for Patref:add_bulk()
    * MINOR: cfgparse: remove duplicate "force-persist" in common kw list
    * REGTESTS: ssl: Fix reg-tests curve check
    * BUG/MINOR: cli/stick-tables: argument to "show table" is optional
    * BUILD: sockpair: fix build issue on macOS related to variable-length arrays
    * BUG/MINOR: cfgparse: wrong section name upon error
    * BUILD: tools: memchr definition changed in C23
    * BUILD: ssl: strchr definition changed in C23
    * BUG/MEDIUM: mworker: can't use signals after a failed reload
    * DOC: config: fix the length attribute name for stick tables of type binary / string
    * BUG/MINOR: backend: inspect request not response buffer to check for TFO
    * BUG/MINOR: backend: fix the conn_retries check for TFO
    * BUG/MEDIUM: ssl: Don't resume session for check connections
    * MINOR: connections: Add a new CO_FL_SSL_NO_CACHED_INFO flag
    * MEDIUM: ssl/server: No longer store the SNI of cached TLS sessions
    * BUG/MEDIUM: ssl: Don't reuse TLS session if the connection's SNI differs
    * MEDIUM: tcpcheck/backend: Get the connection SNI before initializing SSL ctx
    * MINOR: connection/ssl: Store the SNI hash value in the connection itself
    * MINOR: ssl: Compare hashes instead of SNIs when a session is cached
    * MINOR: ssl: Store hash of the SNI for cached TLS sessions
    * MINOR: ssl: Add a function to hash SNIs
    * BUG/MINOR: sock-inet: ignore conntrack for transparent sockets on Linux
    * BUG/MEDIUM: stconn: Don't report abort from SC if read0 was already received
    * BUG/MEDIUM: http-ana: Properly detect client abort when forwarding response (v2)
    * [RELEASE] Released version 3.2.10
    * BUG/MEDIUM: quic: Don't try to use hystart if not implemented
    * BUG/MEDIUM: quic: handle collision on CID generation
    * MINOR: quic: split CID alloc/generation function
    * MINOR: quic: adjust CID conn tree alloc in qc_new_conn()
    * BUG/MINOR: check: only try connection reuse for http-check rulesets
    * MINOR: cfgdiag: adjust diag on servers
    * BUG/MINOR: mux-h2: send the preface along with the first request if needed
    * MINOR: mux-h2: extract the code to send preface+settings into its own function
    * MEDIUM: mux-h2: do not needlessly refrain from sending data early
    * MEDIUM: h1: Immediately try to read data for frontend
    * BUG/MINOR: cfgparse-listen: update err_code for fatal error on proxy directive
    * BUG/MEDIUM: quic: support some ciphersuites and curves related options
    * MINOR: hlua: emit a log instead of an alert for aborted actions due to unavailable yield
    * MINOR: h2/trace: emit a trace of the received RST_STREAM type
    * DOC: config: Improve spop mode documentation
    * DOC: config: Fix description of the spop mode
    * BUG/MEDIUM: http-ana: Don't close server connection on read0 in TUNNEL mode
    * BUG/MINOR: ssl: Don't allow to set NULL sni
    * MINOR: quic: Add useful debugging traces in qc_idle_timer_do_rearm()
    * BUG/MINOR: quic/ssl: crash in ClientHello callback ssl traces
    * DOC: config: reorder the cache section's keywords
    * DOC: config: mention clearer that the cache's total-max-size is mandatory
    * BUG/MEDIUM: connection: fix "bc_settings_streams_limit" typo
    * BUG/MINOR: jwt: Missing "case" in switch statement
    * BUG/MINOR: acme: fix ha_alert() call
    * BUG/MINOR: acme: warning ‘ctx’ may be used uninitialized
    * BUG/MINOR: acme: better challenge_ready processing
    * BUG/MINOR: acme: prevent creating map entries with dns-01
    * BUG/MINOR: acme: handle multiple auth with the same name
    * BUG/MEDIUM: cli: State the cli have no more data to deliver if it yields
    * BUG/MEDIUM: applet: Fix conditions to detect spinning loop with the new API
    * BUG/MINOR: http-ana: Reset analyse_exp date after 'wait-for-body' action
    * BUG/MEDIUM: h1-htx: Don't set HTX_FL_EOM flag on 1xx informational messages
    * BUG/MEDIUM: mworker/listener: ambiguous use of RX_F_INHERITED with shards
    * [RELEASE] Released version 3.2.9
    * DOC: http: document 413 response code
    * ADMIN: dump-certs: let dry-run compare certificates
    * ADMIN: dump-certs: use same error format as haproxy
    * ADMIN: dump-certs: fix lack of / in -p
    * ADMIN: dump-certs: create files in a tmpdir
    * ADMIN: dump-certs: don't update the file if it's up to date
    * ADMIN: haproxy-dump-certs: implement a certificate dumper
    * BUG/MEDIUM: proxy: do not align proxy_per_tgroup beyond allocator's capabilities
    * BUG/MEDIUM: config: Use the mux protocol ALPN by default for listeners if forced
    * MINOR: config: Do proto detection for listeners before checks about ALPN
    * MINOR: muxes: Support an optional ALPN string when defining mux protocols
    * BUG/MEDIUM: queues: Don't forget to unlock the queue before exiting
    * DOC: acme: configuring acme needs a crt file
    * DOC: acme: explain how to dump the certificates
    * DOC: acme: add details about the DNS-01 support
    * BUG/MINOR: acme: alert when the map doesn't exist at startup
    * BUG/MINOR: ssl: remove dead code in ssl_sock_from_buf()
    * BUG/MINOR: mworker: wrong signals during startup
    * BUG/MEDIUM: mworker: signals inconsistencies during startup and reload
    * BUG/MINOR: quic-be: backend SSL session reuse fix (OpenSSL 3.5)
    * BUG/MEDIUM: h1: prevent a crash on HTTP/2 upgrade
    * MINOR: h1: h1_release() should return if it destroyed the connection
    * BUG/MINOR: stick-tables: Fix return value for __stksess_kill()
    * BUG/MEDIUM: stick-tables: Always return the good stksess from stktable_set_entry
    * DOC: configuration: add missing openssl_version predicates
    * DOC: configuration: add missing ssllib_name_startswith()
    * BUG/MINOR: check: fix reuse-pool if MUX inherited from server
    * BUG/MINOR: acme: can't override the default resolver
    * BUG/MEDIUM: acme: move from mt_list to a rwlock + ebmbtree
    * BUG/MINOR: acme: more explicit error when BIO_new_file()
    * BUG/MINOR: quic: close connection on CID alloc failure
    * BUG/MEDIUM: stick-tables: Make sure updates are seen as local
    * BUG/MINOR: config: Limit "tune.maxpollevents" parameter to 1000000
    * BUG/MEDIUM: connection/ssl: also fix the ssl_sock_io_cb() regarding idle list
    * BUG/MEDIUM: connection: do not reinsert a purgeable conn in idle list
    * Revert "BUG/MEDIUM: connections: permit to permanently remove an idle conn"
    * MINOR: ssl/sample: expose ssl_*c_curve for AWS-LC
    * [RELEASE] Released version 3.2.8
    * BUG/MINOR: acme: wrong dns-01 challenge in the log
    * BUG/MEDIUM: server: close a race around ready_srv when deleting a server
    * BUG/MEDIUM: connections: permit to permanently remove an idle conn
    * BUG/MEDIUM: mux-h2: make sure not to move a dead connection to idle
    * BUG/MEDIUM: mux-h1: fix 414 / 431 status code reporting
    * SCRIPTS: build-ssl: fix rpath in AWS-LC install for openssl and bssl bin
    * OPTIM: backend: skip conn reuse for incompatible proxies
    * BUG/MINOR: resolvers: ensure fair round robin iteration
    * BUG/MINOR: ssl: returns when SSL_CTX_new failed during init
    * BUG/MINOR: resolvers: Apply dns-accept-family setting on additional records
    * BUG/MINOR: init: Do not close previously created fd in stdio_quiet
    * MINOR: http: fix 405,431,501 default errorfile
    * MINOR: ssl-sample: add ssl_fc_early_rcvd() to detect use of early data
    * DOC: config: slightly clarify the ssl_fc_has_early() behavior
    * BUG/MEDIUM: ssl: Crash because of dangling ckch_store reference in a ckch instance
    * MINOR: backend: srv_is_up converter
    * MINOR: backend: srv_queue helper
    * BUG/MEDIUM: cli: do not return ACKs one char at a time
    * MINOR: cli: create cli_raw_rcv_buf() from the generic applet_raw_rcv_buf()
    * MINOR: applet: do not put SE_FL_WANT_ROOM on rcv_buf() if the channel is empty
    * BUG/MEDIUM: mt_list: Use atomic operations to prevent compiler optims
    * BUG/MINOR: stick-tables: properly index string-type keys
    * BUG/MEDIUM: applet: Improve again spinning loops detection with the new API
    * BUG/MEDIUM: mt_lists: Avoid el->prev = el->next = el
    * [RELEASE] Released version 3.2.7
    * MINOR: acme: display the complete challenge_ready command in the logs
    * MINOR: acme: add the dns-01-record field to the sink
    * BUG/MINOR: acme: memory leak from the config parser
    * MEDIUM: acme: don't insert acme account key in ckchs_tree
    * MINOR: acme: implement "reuse-key" option
    * BUILD: acme: fix false positive null pointer dereference
    * MINOR: acme: provider-name for dpapi sink
    * CLEANUP: acme: acme_will_expire() uses acme_schedule_date()
    * MINOR: acme: check acme-vars allocation during escaping
    * MINOR: acme: acme-vars allow to pass data to the dpapi sink
    * BUG/MEDIUM: build: limit excessive and counter-productive gcc-15 vectorization
    * BUG/MAJOR: quic: use ncbmbuf for CRYPTO handling
    * MINOR: ncbmbuf: add tests as standalone mode
    * MINOR: ncbmbuf: implement advance operation
    * MINOR: ncbmbuf: implement ncbmb_data()
    * MINOR: ncbmbuf: implement iterator bitmap utilities functions
    * MINOR: ncbmbuf: implement add
    * MINOR: ncbmbuf: define new ncbmbuf type
    * MINOR: ncbuf: extract common types
    * BUG/MEDIUM: h3: properly encode response after interim one in same buf
    * BUG/MAJOR: quic: uninitialized quic_conn_closed struct members
    * BUG/MINOR: quic: SSL counters not handled
    * BUG/MEDIUM: cli: also free the trash chunk on the error path
    * BUG/MEDIUM: mt_list: Make sure not to unlock the element twice
    * BUG/MEDIUM: threads/config: drop absent threads from thread groups
    * DOC: clarify the experimental status for certain features
    * BUG/MINOR: quic: check applet_putchk() for 'show quic' first line
    * BUG/MEDIUM: stick-tables: Don't forget to dec count on failure.
    * MINOR: quic: restore QUIC_HP_SAMPLE_LEN constant
    * BUG/MINOR: quic: too short PADDING frame for too short packets
    * BUILD: ssl: can't build when using -DLISTEN_DEFAULT_CIPHERS
    * BUG/MAJOR: lb-chash: fix key calculation when using default hash-key id
    * BUG/MINOR: pools: don't report "limited to the first X entries" by default
    * BUG/MEDIUM: pools: fix crash on filtered "show pools" output
    * TESTS: quic: useless param for b_quic_dec_int()
    * BUG/MINOR: ssl: Potential NULL deref in trace macro
    * BUG/MINOR: ssl: Free key_base from global_ssl structure during deinit
    * BUG/MINOR: ssl: Free global_ssl structure contents during deinit
    * MINOR: debug: add distro name and version in postmortem
    * BUG/MINOR: sink: retry attempt for sft server may never occur
    * BUG/MEDIUM: apppet: Improve spinning loop detection with the new API
    * BUILD: makefile: disable tail calls optimizations with memory profiling
    * BUG/MINOR: ssl: leak crtlist_name in ssl-f-use
    * BUG/MINOR: ssl: leak in ssl-f-use
    * BUG/MINOR: ssl: always clear the remains of the first hello for the second one
    * BUG/MEDIUM: ssl: take care of second client hello
    * BUG/MINOr: hlua: Fix receive from HTTP applet by properly accounting data
    * BUG/MINOR: acme: avoid overflow when diff > notAfter
    * [RELEASE] Released version 3.2.6
    * BUG/MEDIUM: resolvers: break an infinite loop in resolv_get_ip_from_response()
    * BUG/MINOR: h3: forbid 'Z' as well in header field names checks
    * BUG/MINOR: h2: forbid 'Z' as well in header field names checks
    * BUG/CRITICAL: mjson: fix possible DoS when parsing numbers
    * DOC: config: clarify some known limitations of the json_query() converter
    * BUG/MEDIUM: fwlc: Handle memory allocation failures.
    * MEDIUM: fwlc: Make it so fwlc_srv_reposition works with unqueued srv
    * MEDIUM: servers: Schedule the server requeue target on creation
    * BUG/MEDIUM: stick-tables: Make sure not to free a pending entry
    * MINOR: mt_list: Implement MT_LIST_POP_LOCKED()
    * BUG/MEDIUM: ssl: ca-file directory mode must read every certificates of a file
    * BUG/MINOR: pattern: Fix pattern lookup for map with opt@ prefix
    * BUG/MINOR: acme: possible overflow in acme_will_expire()
    * BUG/MINOR: acme: possible overflow on scheduling computation
    * BUG/MINOR: pattern: Properly flag virtual maps as using samples
    * BUG/MINOR: compression: Test payload size only if content-length is specified
    * MINOR: ssl: add the ssl_bc_sni sample fetch function to retrieve backend SNI
    * BUG/MEDIUM: wdt: improve stuck task detection accuracy
    * MINOR: sched: pass the thread number to is_sched_alive()
    * MINOR: sched: let's permit to share the local ctx between threads
    * BUG/MEDIUM: acme: free() of i2d_X509_REQ() with AWS-LC
    * BUG/MEDIUM: acme: cfg_postsection_acme() don't init correctly acme sections
    * BUG/MINOR: acme: don't unlink from acme_ctx_destroy()
    * CI: github: build halog on the vtest job
    * BUILD: halog: misleading indentation in halog.c
    * BUG/MINOR: pools: Fix the dump of pools info to deal with buffers limitations
    * BUG/MEDIUM: stick-tables: Don't let table_process_entry() handle refcnt
    * BUG/MINOR: acme/cli: wrong description for "acme challenge_ready"
    * MEDIUM: resolvers: make the process_resolvers() task single-threaded
    * MEDIUM: dns: bind the nameserver sockets to the initiating thread
    * OPTIM: sink: reduce contention on sink_announce_dropped()
    * BUG/MEDIUM: resolvers: Wake resolver task up whne unlinking a stream requester
    * BUG/MEDIUM: resolvers: Accept to create resolution without hostname
    * BUG/MEDIUM: resolvers: Make resolution owns its hostname_dn value
    * BUG/MEDIUM: resolvers: Test for empty tree when getting a record from DNS answer
    * BUG/MINOR: resolvers: Restore round-robin selection on records in DNS answers
    * BUG/MEDIUM: resolvers: Properly cache do-resolv resolution
    * MINOR: tools: don't emit "+0" for symbol names which exactly match known ones
    * MINOR: activity: indicate the number of calls on "show tasks"
    * MEDIUM: peers: move process_peer_sync() to a single thread
    * MEDIUM: stick-table: move process_table_expire() to a single thread
    * MEDIUM: peers: don't even try to process updates under contention
    * MEDIUM: stick-tables: don't wait indefinitely in stktable_add_pend_updates()
    * MEDIUM: stick-tables: give up on lock contention in process_table_expire()
    * MEDIUM: stick-tables: relax stktable_trash_oldest() to only purge what is needed
    * MINOR: stick-table: permit stksess_new() to temporarily allocate more entries
    * DEBUG: peers: export functions that use locks
    * MINOR: debug: report the time since last wakeup and call
    * MINOR: debug: report the number of loops and ctxsw for each thread
    * DEBUG: stream: count the number of passes in the connect loop
    * MINOR: debug: report the process id in warnings and panics
    * BUG/MINOR: tcpcheck: Don't use sni as pool-conn-name for non-SSL connections
    * BUG/MINOR: server: Update healthcheck when server settings are changed via CLI
    * BUG/MEDIUM: server: Use sni as pool connection name for SSL server only
    * MINOR: server: Parse sni and pool-conn-name expressions in a dedicated function
    * OPTIM: stick-tables: exit expiry faster when the update lock is held
    * MINOR: stick-tables: limit the number of visited nodes during expiration
    * [RELEASE] Released version 3.2.5
    * BUG/MEDIUM: pattern: fix possible infinite loops on deletion (try 2)
    * DEBUG: stick-tables: export stktable_add_pend_updates() for better reporting
    * BUG/MEDIUM: ring: invert the length check to avoid an int overflow
    * BUG/MINOR: resolvers: always normalize FQDN from response
    * BUG/MINOR: ocsp: Crash when updating CA during ocsp updates
    * BUG/MEDIUM: http_ana: fix potential NULL deref in http_process_req_common()
    * BUG/MINOR: ocsp: prototype inconsistency
    * BUG/MINOR: ssl: Fix potential NULL deref in trace callback
    * BUG/MINOR: ssl: Potential NULL deref in trace macro
    * BUG/MEDIUM: jws: return size_t in JWS functions
    * BUG/MINOR: acme: null pointer dereference upon allocation failure
    * BUG/MAJOR: stream: Force channel analysis on successful synchronous send
    * BUG/MAJOR: stream: Remove READ/WRITE events on channels after analysers eval
    * BUG/MINOR: stick-table: make sure never to miss a process_table_expire update
    * BUG/MEDIUM: stick-tables: don't loop on non-expirable entries
    * BUG/MINOR: activity: fix reporting of task latency
    * BUG/MEDIUM: ssl: create the mux immediately on early data
    * BUG/MEDIUM: h1: Allow reception if we have early data
    * BUG/MEDIUM: checks: fix ALPN inheritance from server
    * OPTIM: check: do not delay MUX for ALPN if SSL not active
    * BUG/MEDIUM: mux-h2: Reinforce conditions to report an error to app-layer stream
    * BUG/MEDIUM: mux-h2: Report RST/error to app-layer stream during 0-copy fwding
    * BUG/MINOR: mux-h2: Remove H2_CF_DEM_DFULL flags when the demux buffer is reset
    * BUG/MEDIUM: mux-h2: Restart reading when mbuf ring is no longer full
    * BUG/MEDIUM: mux-h2; Don't block reveives in H2_CS_ERROR and H2_CS_ERROR2 states
    * BUG/MEDIUM: mux-h2: Reset MUX blocking flags when a send error is caught
    * CLEANUP: quic: fix typo in quic_tx trace
    * BUG/MINOR: cpu_topo: work around a small bug in musl's CPU_ISSET()
    * BUILD: trace: silence a bogus build warning at -Og
    * BUG/MINOR: log: fix potential memory leak upon error in add_to_logformat_list()
    * BUG/MINOR: connection: streamline conn detach from lists
    * BUG/MEDIUM: conn: fix UAF on connection after reversal on edge
    * REGTESTS: explicitly use "balance roundrobin" where RR is needed
    * BUG/MINOR: check: fix dst address when reusing a connection
    * BUG/MINOR: check: ensure check-reuse is compatible with SSL
    * BUG/MEDIUM: peers: don't fail twice to grab the update lock
    * BUG/MINOR: stick-tables: never leave used entries without expiration
    * BUG/MEDIUM: stick-tables: don't leave the expire loop with elements deleted
    * MINOR: quic: Add more information about RX packets
    * BUILD: acl: silence a possible null deref warning in parse_acl_expr()
    * BUG/MINOR: haproxy: be sure not to quit too early on soft stop
    * BUG/MINOR: quic: fix padding issue on INITIAL retransmit
    * BUG/MINOR: quic: fix room check if padding requested
    * BUG/MINOR: quic: ignore AGAIN ncbuf err when parsing CRYPTO frames
    * BUG/MINOR: tools: Add OOM check for malloc() in indent_msg()
    * BUG/MINOR: compression: Add OOM check for calloc() in parse_compression_options()
    * BUG/MINOR: cfgparse: Add OOM check for calloc() in cfg_parse_listen()
    * BUG/MINOR: acl: Add OOM check for calloc() in smp_fetch_acl_parse()
    * BUG/MINOR: log: Add OOM checks for calloc() and malloc() in logformat parser and dup_logger()
    * BUG/MINOR: halog: Add OOM checks for calloc() in filter_count_srv_status() and filter_count_url()
    * BUG/MEDIUM: server: Duplicate healthcheck's alpn inherited from default server
    * REG-TESTS: map_redirect: Don't use hdr_dom in ACLs with "-m end" matching method
    * BUG/MAJOR: mux-quic: fix crash on reload during emission
    * BUG/MEDIUM: quic: CRYPTO frame freeing without eb_delete()
    * CLEANUP: quic: remove a useless CRYPTO frame variable assignment
    * MINOR: doc: add missing statistics column
    * MINOR: doc: add missing statistics column
    * DOC: configuration: confuse "strict-mode" with "zero-warning"
    * DOC: unreliable sockpair@ on macOS
    * BUILD: mworker: fix ignoring return value of ‘read’
    * BUG/MINOR: server: decrement session idle_conns on del server
    * BUG/MINOR: connection: remove extra session_unown_conn() on reverse
    * BUG/MINOR: connection: rearrange union list members
    * BUG/MEDIUM: mworker: fix startup and reload on macOS
    * BUG/MINOR: acl: set arg_list->kw to aclkw->kw string literal if aclkw is found
    * BUG/MINOR: mux-quic: trace with non initialized qcc
    * MINOR: quic: remove ->offset qf_crypto struct field
    * DOC: configuration: clarify 'default-crt' and implicit default certificates
    * MINOR: ssl: diagnostic warning when both 'default-crt' and 'strict-sni' are used
    * BUG/MINOR: quic: reorder fragmented RX CRYPTO frames by their offsets
    * MINOR: sample: Add base2 converter
    * MINOR: sample: Add le2dec (little endian to decimal) sample fetch
    * BUG/MEDIUM: spoe: Improve error detection in SPOE applet on client abort
    * BUG/MEDIUM: http_ana: handle yield for "stats http-request" evaluation
    * BUG/MEDIUM: mux-spop: Reject connection attempts from a non-spop frontend
    * MINOR: http_ana: fix typo in http_res_get_intercept_rule
    * MINOR: quic: centralize padding for HP sampling on packet building
    * BUG/MINOR: quic: don't coalesce probing and ACK packet of same type
    * BUG/MAJOR: quic: fix INITIAL padding with probing packet only
    * BUG/MINOR: quic: do not emit probe data if CONNECTION_CLOSE requested
    * BUG/MEDIUM: quic: reset padding when building GSO datagrams
    * MINOR: dns: dns_connect_nameserver: fix fd leak at error path
    * BUG/MEDIUM: ssl: apply ssl-f-use on every "ssl" bind
    * BUG/MEDIUM: mux-h2: fix crash on idle-ping due to unwanted ABORT_NOW
    * BUG/MEDIUM: mworker: more verbose error upon loading failure
    * BUG/MEDIUM: cli: Report inbuf is no longer full when a line is consumed
    * BUG/MINOR: spoe: Properly detect and skip empty NOTIFY frames
    * MEDIUM: dns: don't call connect to dest socket for AF_INET*
    * BUG/MINOR: mux-h1: fix wrong lock label
    * BUG/MEDIUM: quic: listener connection stuck during handshakes (OpenSSL 3.5)
    * MINOR: quic: implement qc_ssl_do_hanshake()
    * BUG/MEDIUM: Remove sync sends from streams to applets
    * BUG/MEDIUM: stconn: Fix conditions to know an applet can get data from stream
    * [RELEASE] Released version 3.2.4
    * BUG/MEDIUM: http-client: Test HTX_FL_EOM flag before commiting the HTX buffer
    * BUG/MEDIUM: mux-quic: adjust wakeup behavior
    * DOC: config: recommend single quoting passwords
    * DOC: management: fix typo in commit f4f93c56
    * BUG/MINOR: init: Initialize random seed earlier in the init process
    * BUG/MEDIUM: ssl: fix build with AWS-LC
    * BUG/MEDIUM: ssl: Fix 0rtt to the server
    * MINOR: sock: update broken accept4 detection for older hardwares.
    * BUG/MINOR: stick-table: cap sticky counter idx with tune.nb_stk_ctr instead of MAX_SESS_STKCTR
    * BUILD: compat: always set _POSIX_VERSION to ease comparisons
    * BUILD: compat: provide relaxed versions of the MIN/MAX macros
    * DOC: list missing global QUIC settings
    * CLEANUP: http-client: Remove useless indentation when sending request body
    * BUG/MINOR: mux-quic: ensure close-spread-time is properly applied
    * BUG/MINOR mux-quic: apply correctly timeout on output pending data
    * BUG/MINOR: hq-interop: fix FIN transmission
    * BUG/MINOR: logs: fix log-steps extra log origins selection
    * BUG/MEDIUM: threads: Disable the workaround to load libgcc_s on macOS
    * BUG/MINOR: halog: exit with error when some output filters are set simultaneosly
    * BUG/MINOR: applet: Don't trigger BUG_ON if the tid is not on appctx init
    * MINOR: h3: remove unused outbuf in h3_resp_headers_send()
    * BUG/MINOR: quic: Wrong source address use on FreeBSD
    * BUG/MEDIUM: h3: handle interim response properly on FE side
    * MINOR: qmux: change API for snd_buf FIN transmission
    * BUG/MINOR: h3: ensure that invalid status code are not encoded (FE side)
    * BUG/MINOR: h3: properly realloc buffer after interim response encoding
    * BUG/MEDIUM: h3: do not overwrite interim with final response
    * BUG/MINOR: h1-htx: Don't forget to init flags in h1_format_htx_msg function
    * BUG/MINOR: mux-h1: Use configured error files if possible for early H1 errors
    * MINOR: h1-htx: Add function to format an HTX message in its H1 representation
    * BUG/MEDIUM: http-client: Notify applet has more data to deliver until the EOM
    * BUG/MEDIUM: http-client: Drain the request if an early response is received
    * BUG/MINOR: http-client: Reject any 101-switching-protocols response
    * BUG/MINOR: http-client: Ignore 1XX interim responses in non-HTX mode
    * BUG/MEDIUM: http-client: Ask for more room when request data cannot be xferred
    * BUG/MEDIUM: http-client: Properly inc input data when HTX blocks are xferred
    * BUG/MEDIUM: http-client: Don't wake http-client applet if nothing was xferred
    * BUG/MEDIUM: quic: Crash after QUIC server callbacks restoration (OpenSSL 3.5)
    * MINOR: quic: Prevent QUIC build with OpenSSL 3.5 new QUIC API version < 3.5.1
    * BUG/MINOR: listener: really assign distinct IDs to shards
    * MEDIUM: ssl/cli: relax crt insertion in crt-list of type directory
    * DOC: management: clarify usage of -V with -c
    * MEDIUM: acme: use lowercase for challenge names in configuration
    * BUG/MINOR: acme: possible integer underflow in acme_txt_record()
    * MINOR: acme: update the log for DNS-01
    * MEDIUM: acme: allow to wait and restart the task for DNS-01
    * MINOR: acme: emit the DNS-01 challenge details on the dpapi sink
    * MINOR: acme: emit a log for DNS-01 challenge response
    * BUG/MEDIUM: hlua_fcn: ensure systematic watcher cleanup for server list iterator
    * BUILD: acme: avoid declaring TRACE_SOURCE in acme-t.h
    * CLEANUP: ssl: Rename ssl_trace-t.h to ssl_trace.h
    * BUG/MEDIUM: mux-quic: ensure Early-data header is set
    * BUG/MINOR: hlua: take default-path into account with lua-load-per-thread
    * BUG/MEDIUM: logs: fix sess_build_logline_orig() recursion with options
    * BUG/MEDIUM: dns: Reset reconnect tempo when connection is finally established
    * BUG/MEDIUM: hlua: Report to SC when output data are blocked on a lua socket
    * BUG/MEDIUM: hlua: Report to SC when data were consumed on a lua socket
    * BUG/MINOR: hlua: Skip headers when a receive is performed on an HTTP applet
    * MINOR: acme: implement traces
    * MINOR: acme: add ACME to the haproxy -vv feature list
    * CLEANUP: acme: fix wrong spelling of "resources"
    * BUG/MINOR: acme: allow "processing" in challenge requests
    * MINOR: acme: remove acme_req_auth() and use acme_post_as_get() instead
    * BUG/MEDIUM: acme: use POST-as-GET instead of GET for resources
    * BUG/MEDIUM: ssl/clienthello: ECDSA with ssl-max-ver TLSv1.2 and no ECDSA ciphers
    * DOC: deviceatlas build clarifications
    * [RELEASE] Released version 3.2.3
    * BUILD/MEDIUM: deviceatlas: fix when installed in custom locations.
    * BUG/MINOR: http-act: Fix parsing of the expression argument for pause action
    * BUG/MINOR: ssl: crash in ssl_sock_io_cb() with SSL traces and idle connections
    * BUG/MINOR: ssl/ocsp: fix definition discrepancies with ocsp_update_init()
    * BUG/MINOR: quic: Missing TLS 1.3 QUIC cipher suites and groups inits (OpenSSL 3.5 QUIC API)
    * CI: github: update to OpenSSL 3.5.1
    * BUG/MEDIUM: quic: SSL/TCP handshake failures with OpenSSL 3.5
    * BUILD: quic: QUIC build against OpenSSL 3.5 broken
    * CI: github: update the stable CI to ubuntu-24.04
    * CI: github: add an OpenSSL 3.5.0 job
    * CI: enable USE_QUIC=1 for OpenSSL versions >= 3.5.0
    * [RELEASE] Released version 3.2.2
    * BUILD: dev/phash: remove the accidentally committed a.out file
    * BUG/MINOR: httpclient: wrongly named httpproxy flag
    * DOC: Fix 'jwt_verify' converter doc
    * BUG/MINOR: jwt: Copy input and parameters in dedicated buffers in jwt_verify converter
    * BUG/MEDIUM: mux-h2: Properly handle connection error during preface sending
    * BUG/MEDIUM: hlua: Forbid any L6/L7 sample fetche functions from lua services
    * MINOR: ssl: check TLS1.3 ciphersuites again in clienthello with recent AWS-LC
    * BUG/MINOR: tools: use my_unsetenv instead of unsetenv
    * SCRIPTS: drop the HTML generation from announce-release
    * DOC: config: crt-list clarify default cert + cert-bundle
    * MINOR: quic: Useless TX buffer size reduction in closing state
    * BUG/MINOR: quic: wrong QUIC_FT_CONNECTION_CLOSE(0x1c) frame encoding
    * DOC: configuration: add details on prefer-client-ciphers
    * BUG/MINOR: log: Be able to use %ID alias at anytime of the stream's evaluation
    * BUG/MINOR: stream: Avoid recursive evaluation for unique-id based on itself
    * BUG/MINOR: tools: only reset argument start upon new argument
    * MINOR: fwlc: Factorize code.
    * BUG/MAJOR: fwlc: Count an avoided server as unusable.
    * BUG/MINOR: mux-quic/h3: properly handle too low peer fctl initial stream
    * DOC: config: prefer-last-server: add notes for non-deterministic algorithms
    * BUG/MEDIUM: check: Set SOCKERR by default when a connection error is reported
    * MINOR: cli: handle EOS/ERROR first
    * BUG/MEDIUM: cli: Don't consume data if outbuf is full or not available
    * BUG/MINOR: quic: Fix OSSL_FUNC_SSL_QUIC_TLS_got_transport_params_fn callback (OpenSSL3.5)
    * BUG/MINOR: http-ana: Properly handle keep-query redirect option if no QS
    * BUG/MINOR: config/server: reject QUIC addresses
    * [RELEASE] Released version 3.2.1
    * BUG/MINIR: h1: Fix doc of 'accept-unsafe-...-request' about URI parsing
    * BUG/MEDIUM: fd: Use the provided tgid in fd_insert() to get tgroup_info
    * BUG/MINOR: quic: Missing SSL session object freeing
    * BUG/MINOR: config: fix arg number reported on empty arg warning
    * BUG/MINOR: config: emit warning for empty args only in discovery mode
    * BUG/MEDIUM: cli: Properly parse empty lines and avoid crashed
    * BUG/MINOR: mux-spop: Fix null-pointer deref on SPOP stream allocation failure
    * BUG/MEDIUM: check: Requeue healthchecks on I/O events to handle check timeout
    * BUG/MAJOR: leastconn: Protect tree_elt with the lbprm lock
    * DOC: config: Fix a typo in 2.7 (Name format for maps and ACLs)
    * BUILD: tools: properly define ha_dump_backtrace() to avoid a build warning
    Remove patches applied by update:
    0001-BUG-CRITICAL-mjson-fix-possible-DoS-when-parsing-num.patch
    0001-BUG-MEDIUM-applet-Fix-test-on-shut-flags-for-legacy.patch
    0001-fix-parsing-frame-type.patch
    0001-reject-invalid-token.patch

++++ kernel-default:

  - mm, shmem: prevent infinite loop on truncate race (CVE-2026-23161
    bsc#1258355).
  - commit 905c137
  - mm: prevent poison consumption when splitting THP
    (CVE-2025-40230 bsc#1254817).
  - commit 73eef46
  - ice: Fix PTP NULL pointer dereference during VSI rebuild
    (CVE-2026-23210 bsc#1258517).
  - commit ebccada
  - mm/memfd: fix information leak in hugetlb folios (CVE-2025-68292
    bsc#1255148).
  - commit ef8df4a
  - media: dvb-core: fix wrong reinitialization of ringbuffer on
    reopen (git-fixes).
  - commit 7808229

++++ kernel-rt:

  - mm, shmem: prevent infinite loop on truncate race (CVE-2026-23161
    bsc#1258355).
  - commit 905c137
  - mm: prevent poison consumption when splitting THP
    (CVE-2025-40230 bsc#1254817).
  - commit 73eef46
  - ice: Fix PTP NULL pointer dereference during VSI rebuild
    (CVE-2026-23210 bsc#1258517).
  - commit ebccada
  - mm/memfd: fix information leak in hugetlb folios (CVE-2025-68292
    bsc#1255148).
  - commit ef8df4a
  - media: dvb-core: fix wrong reinitialization of ringbuffer on
    reopen (git-fixes).
  - commit 7808229

++++ systemd:

  - Sign systemd-boot EFI binary on aarch64 (bsc#1258344)

++++ nvidia-open-driver-G06-signed:

  - updated CUDA variant to version 580.126.20
  - supersedes kernel-6.19.patch

------------------------------------------------------------------
------------------  2026-2-25  -  Feb 25 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - mm/shmem, swap: fix race of truncate and swap entry split
    (CVE-2026-23161 bsc#1258355).
  - commit d6f1384
  - NFS: Fix a deadlock involving nfs_release_folio()
    (CVE-2026-23053 bsc#1257718).
  - commit 48b00b3
  - nfsd: provide locking for v4_end_grace (git-fixes).
  - commit 86e35a2
  - rxrpc: Fix recvmsg() unconditional requeue (CVE-2026-23066
    bsc#1257726).
  - commit c17a357
  - KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing
    memslot (CVE-2025-68810 bsc#1256679).
  - commit 956c9f9
  - KVM: Don't clobber irqfd routing type when deassigning irqfd
    (CVE-2026-23198 bsc#1258321).
  - commit 6b20edc

++++ kernel-rt:

  - mm/shmem, swap: fix race of truncate and swap entry split
    (CVE-2026-23161 bsc#1258355).
  - commit d6f1384
  - NFS: Fix a deadlock involving nfs_release_folio()
    (CVE-2026-23053 bsc#1257718).
  - commit 48b00b3
  - nfsd: provide locking for v4_end_grace (git-fixes).
  - commit 86e35a2
  - rxrpc: Fix recvmsg() unconditional requeue (CVE-2026-23066
    bsc#1257726).
  - commit c17a357
  - KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing
    memslot (CVE-2025-68810 bsc#1256679).
  - commit 956c9f9
  - KVM: Don't clobber irqfd routing type when deassigning irqfd
    (CVE-2026-23198 bsc#1258321).
  - commit 6b20edc

++++ libsoup:

  - Add libsoup-CVE-2026-1539.patch: Also remove Proxy-Authorization
    header on cross origin redirect
    (bsc#1257441, CVE-2026-1539, glgo#GNOME/libsoup#489).

++++ qemu:

  - Update to version 10.0.8
    Full backport list:
    https://lore.kernel.org/qemu-devel/20260213060647.200707-1-mjt@tls.msk.ru/
    Fixes:
    bsc#1255400 (CVE-2025-14876)
    A selection of them is reported here below:
    scripts/qemugdb: timers: Fix KeyError in 'qemu timers' command
    linux-user/syscall.c: Prevent acquiring clone_lock while fork()
    virtio-gpu: fix error handling in virgl_cmd_resource_create_blob
    virtio-pmem: ignore empty queue notifications
    virtio-gpu-virgl: correct parent for blob memory region
    cryptodev-builtin: Limit the maximum size
    hw/virtio/virtio-crypto: verify asym request size
    q35: Fix migration of SMRAM state
    virtio-dmabuf: Ensure UUID persistence for hash table insertion
    vdpa: fix vhost-vdpa suspended state not be shared
    hw/i2c/aspeed_i2c: Fix DMA moving data into incorrect address
    hw/i2c/aspeed: Fix wrong I2CC_DMA_LEN when I2CM_DMA_TX/RX_ADDR set first
    hw/i2c/aspeed_i2c.c: Add a check for dma_read
    hw/adc: Fix out-of-bounds write in Aspeed ADC model
    hw/uefi: fix size negotiation
    hw/nvme: Fix bootindex suffix use-after-free
    python: fix msys64 wheel directory specification
    tests/qtest/ufs-test: Add test for mcq completion queue wraparound
    hw/ufs: Fix mcq completion queue wraparound
    hw/ufs: fix CQE endianness and UPIU length
    hw/ufs: Ensure DBC of PRDT uses only lower 18 bits
    tests/functional: migrate sbsa_ref test images
    pc-bios/optionrom: Use 32-bit linker emulation for the optionroms
    target/i386/tcg: fix a few instructions that do not support VEX.L=1
    linux-user: fixup termios2 related things on PowerPC
    linux-user: Add missing termios baud rates
    linux-user: Add termios2 support to sparc target
    linux-user: Add termios2 support to sh4 target
    linux-user: Add termios2 support to mips target
    linux-user: Add termios2 support to hppa target
    linux-user: Add termios2 support to alpha target
    linux-user: Add termios2 support
    hw/intc: avoid byte swap fiddling in gicv3 its path
    bsd-user/syscall_defs.h: define STAT_TIME_T_EXT only for 32 bits
    bsd-user: Fix __i386__ test for TARGET_HAS_STAT_TIME_T_EXT
    hw/sd/sdhci: Fix TYPE_IMX_USDHC to implement sd-spec-version 3 by default
    linux-user/aarch64/target_fcntl.h: add missing TARGET_O_LARGEFILE definition
    ...
  - Bugfix:
    * [openSUSE][RPM] spec: Tie guest-agent supplements to the kernel package (bsc#1257492)

------------------------------------------------------------------
------------------  2026-2-24  -  Feb 24 2026  -------------------
------------------------------------------------------------------

++++ gnutls:

  - Add the functionality to allow to specify the hash algorithm for
    the PSK. This fixes a bug in the current implementation where the
    binder is always calculated with SHA256.
    * (bsc#1258083, jsc#PED-15752, jsc#PED-15753)
    * lib/psk: Add gnutls_psk_allocate_{client,server}_credentials2
    * tests/psk-file: Add testing for _credentials2 functions
    * lib/psk: add null check for binder algo
    * pre_shared_key: fix memleak when retrying with different binder algo
    * pre_shared_key: add null check on pskcred
    * Add patches:
  - gnutls-PSK-hash.patch
  - gnutls-PSK-hash-tests.patch
  - gnutls-PSK-hash-NULL-check.patch
  - gnutls-PSK-hash-NULL-check-pskcred.patch
  - gnutls-PSK-hash-fix-memleak.patch

++++ grub2:

  - Support dm multipath bootlist on PowerPC (bsc#1254415)
    * 0001-ieee1275-support-dm-multipath-bootlist.patch

++++ kernel-default:

  - md: suspend array while updating raid_disks via sysfs
    (CVE-2025-71225, bsc#1258411).
  - commit 4a185e4
  - smb: client: fix memory leak in cifs_construct_tcon()
    (bsc#1255129, CVE-2025-68295).
  - commit cfb334a
  - Refresh
    patches.suse/smb-client-split-cached_fid-bitfields-to-avoid-shared-byte-RMW-rac.patch.
  - commit 3a3c827
  - Refresh and move upstreamed ath12k patch into sorted section
  - commit 6886361
  - HID: apple: Add EPOMAKER TH87 to the non-apple keyboards list
    (bsc#1258455).
  - commit 3ef2af3
  - btrfs: reject new transactions if the fs is fully read-only
    (bsc#1258464 CVE-2026-23214).
  - commit c00b6f5
  - btrfs: send: check for inline extents in
    range_is_hole_in_parent() (bsc#1258377 CVE-2026-23141).
  - commit eb3646e

++++ kernel-rt:

  - md: suspend array while updating raid_disks via sysfs
    (CVE-2025-71225, bsc#1258411).
  - commit 4a185e4
  - smb: client: fix memory leak in cifs_construct_tcon()
    (bsc#1255129, CVE-2025-68295).
  - commit cfb334a
  - Refresh
    patches.suse/smb-client-split-cached_fid-bitfields-to-avoid-shared-byte-RMW-rac.patch.
  - commit 3a3c827
  - Refresh and move upstreamed ath12k patch into sorted section
  - commit 6886361
  - HID: apple: Add EPOMAKER TH87 to the non-apple keyboards list
    (bsc#1258455).
  - commit 3ef2af3
  - btrfs: reject new transactions if the fs is fully read-only
    (bsc#1258464 CVE-2026-23214).
  - commit c00b6f5
  - btrfs: send: check for inline extents in
    range_is_hole_in_parent() (bsc#1258377 CVE-2026-23141).
  - commit eb3646e

++++ openssl-3:

  - Enable MD2 in legacy provider ( jsc#PED-15724 )

------------------------------------------------------------------
------------------  2026-2-23  -  Feb 23 2026  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Add patch for CVE-2025-47914 (bsc#1254041), CVE-2025-47913 (bsc#1253584):
    * 0001-CVE-2025-47913-CVE-2025-47914-ssh-agent-fixes.patch
  - Add patch for CVE-2025-62725 (bsc#1252752)
    * 0002-CVE-2025-62725-fix-Enforce-compose-files-from-OCI-ar.patch

++++ kernel-default:

  - ipv6: Fix use-after-free in inet6_addr_del() (CVE-2026-23010
    bsc#1257332).
  - net: fix memory leak in skb_segment_list for GRO packets
    (CVE-2026-22979 bsc#1257228).
  - commit b2654a5
  - block,bfq: fix aux stat accumulation destination (git-fixes).
  - commit 2a3051f
  - macvlan: observe an RCU grace period in macvlan_common_newlink()
    error path (CVE-2026-23209 bsc#1258518).
  - bonding: only set speed/duplex to unknown, if getting speed
    failed (bsc#1253691).
  - macvlan: fix error recovery in macvlan_common_newlink()
    (CVE-2026-23209 bsc#1258518).
  - i40e: validate ring_len parameter against hardware-specific
    values (git-fixes).
  - net/mlx5: Initialize events outside devlink lock (git-fixes).
  - commit bbb1b4f
  - btrfs: fix NULL dereference on root when tracing inode eviction
    (bsc#1257635 CVE-2025-71184).
  - commit 3fff732
  - btrfs: tracepoints: use btrfs_root_id() to get the id of a root
    (bsc#1257635 CVE-2025-71184).
  - commit 4039cd5
  - tee: optee: ffa: fix a typo of "optee_ffa_api_is_compatible" (git-fixes)
  - commit d36259f
  - tee: fix memory leak in tee_dyn_shm_alloc_helper (git-fixes)
  - commit 7a7323a
  - arm64: Force the use of CNTVCT_EL0 in __delay() (git-fixes)
  - commit 2e8d443
  - arm64: poe: fix stale POR_EL0 values for ptrace (git-fixes)
  - commit e7cd7ba
  - arm64: Fix cleared E0POE bit after cpu_suspend()/resume() (git-fixes)
  - commit ea3dd60
  - PCI: Add PCI_BRIDGE_NO_ALIAS quirk for ASPEED AST1150 (bsc#1258672)
  - commit 63015f7
  - PCI: Add ASPEED vendor ID to pci_ids.h (bsc#1258672)
  - commit c07c434
  - rtc: interface: Alarm race handling should not discard preceding
    error (git-fixes).
  - commit 142d6d3

++++ kernel-rt:

  - ipv6: Fix use-after-free in inet6_addr_del() (CVE-2026-23010
    bsc#1257332).
  - net: fix memory leak in skb_segment_list for GRO packets
    (CVE-2026-22979 bsc#1257228).
  - commit b2654a5
  - block,bfq: fix aux stat accumulation destination (git-fixes).
  - commit 2a3051f
  - macvlan: observe an RCU grace period in macvlan_common_newlink()
    error path (CVE-2026-23209 bsc#1258518).
  - bonding: only set speed/duplex to unknown, if getting speed
    failed (bsc#1253691).
  - macvlan: fix error recovery in macvlan_common_newlink()
    (CVE-2026-23209 bsc#1258518).
  - i40e: validate ring_len parameter against hardware-specific
    values (git-fixes).
  - net/mlx5: Initialize events outside devlink lock (git-fixes).
  - commit bbb1b4f
  - btrfs: fix NULL dereference on root when tracing inode eviction
    (bsc#1257635 CVE-2025-71184).
  - commit 3fff732
  - btrfs: tracepoints: use btrfs_root_id() to get the id of a root
    (bsc#1257635 CVE-2025-71184).
  - commit 4039cd5
  - tee: optee: ffa: fix a typo of "optee_ffa_api_is_compatible" (git-fixes)
  - commit d36259f
  - tee: fix memory leak in tee_dyn_shm_alloc_helper (git-fixes)
  - commit 7a7323a
  - arm64: Force the use of CNTVCT_EL0 in __delay() (git-fixes)
  - commit 2e8d443
  - arm64: poe: fix stale POR_EL0 values for ptrace (git-fixes)
  - commit e7cd7ba
  - arm64: Fix cleared E0POE bit after cpu_suspend()/resume() (git-fixes)
  - commit ea3dd60
  - PCI: Add PCI_BRIDGE_NO_ALIAS quirk for ASPEED AST1150 (bsc#1258672)
  - commit 63015f7
  - PCI: Add ASPEED vendor ID to pci_ids.h (bsc#1258672)
  - commit c07c434
  - rtc: interface: Alarm race handling should not discard preceding
    error (git-fixes).
  - commit 142d6d3

++++ mdadm:

  - Update to version 4.4+39.g1b34084f:
    * platform-intel: Deal with hot-unplugged devices (bsc#1258265)
    * imsm: Fix UEFI backward compatibility for RAID10D4 (bsc#1257009)

------------------------------------------------------------------
------------------  2026-2-22  -  Feb 22 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - NTB: ntb_transport: Fix too small buffer for debugfs_name
    (git-fixes).
  - commit 34f22c7
  - xfs: fix UAF in xchk_btree_check_block_owner (CVE-2026-23223
    bsc#1258483).
  - commit 0986f41
  - erofs: fix UAF issue for file-backed mounts w/ directio option
    (CVE-2026-23224 bsc#1258461).
  - commit 543a001

++++ kernel-rt:

  - NTB: ntb_transport: Fix too small buffer for debugfs_name
    (git-fixes).
  - commit 34f22c7
  - xfs: fix UAF in xchk_btree_check_block_owner (CVE-2026-23223
    bsc#1258483).
  - commit 0986f41
  - erofs: fix UAF issue for file-backed mounts w/ directio option
    (CVE-2026-23224 bsc#1258461).
  - commit 543a001

------------------------------------------------------------------
------------------  2026-2-21  -  Feb 21 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - spi: wpcm-fiu: Fix potential NULL pointer dereference in
    wpcm_fiu_probe() (git-fixes).
  - ASoC: rockchip: i2s-tdm: Use param rate if not provided by
    set_sysclk (git-fixes).
  - ASoC: codecs: aw88261: Fix erroneous bitmask logic in Awinic
    init (git-fixes).
  - drm/amd/display: Use same max plane scaling limits for all 64
    bpp formats (git-fixes).
  - drm/amd/display: Fix out-of-bounds stream encoder index v3
    (git-fixes).
  - drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
    (git-fixes).
  - drm/amd/display: Reject cursor plane on DCE when scaled
    differently than primary (git-fixes).
  - drm/amdkfd: Fix watch_id bounds checking in debug address
    watch v2 (git-fixes).
  - drm/i915/acpi: free _DSM package when no connectors (git-fixes).
  - drm/amd: Fix hang on amdgpu unload by using
    pci_dev_is_disconnected() (git-fixes).
  - drm/amdgpu: Fix memory leak in amdgpu_ras_init() (git-fixes).
  - drm/amdgpu: Use kvfree instead of kfree in
    amdgpu_gmc_get_nps_memranges() (git-fixes).
  - drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc()
    (git-fixes).
  - drm/amdgpu: ensure no_hw_access is visible before MMIO
    (git-fixes).
  - efi: Fix reservation of unaccepted memory table (git-fixes).
  - commit 05f5344
  - ALSA: usb-audio: Use the right limit for PCM OOB check
    (CVE-2026-23208 bsc#1258468).
  - ALSA: usb-audio: Prevent excessive number of frames
    (CVE-2026-23208 bsc#1258468).
  - commit 9c042c7

++++ kernel-rt:

  - spi: wpcm-fiu: Fix potential NULL pointer dereference in
    wpcm_fiu_probe() (git-fixes).
  - ASoC: rockchip: i2s-tdm: Use param rate if not provided by
    set_sysclk (git-fixes).
  - ASoC: codecs: aw88261: Fix erroneous bitmask logic in Awinic
    init (git-fixes).
  - drm/amd/display: Use same max plane scaling limits for all 64
    bpp formats (git-fixes).
  - drm/amd/display: Fix out-of-bounds stream encoder index v3
    (git-fixes).
  - drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
    (git-fixes).
  - drm/amd/display: Reject cursor plane on DCE when scaled
    differently than primary (git-fixes).
  - drm/amdkfd: Fix watch_id bounds checking in debug address
    watch v2 (git-fixes).
  - drm/i915/acpi: free _DSM package when no connectors (git-fixes).
  - drm/amd: Fix hang on amdgpu unload by using
    pci_dev_is_disconnected() (git-fixes).
  - drm/amdgpu: Fix memory leak in amdgpu_ras_init() (git-fixes).
  - drm/amdgpu: Use kvfree instead of kfree in
    amdgpu_gmc_get_nps_memranges() (git-fixes).
  - drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc()
    (git-fixes).
  - drm/amdgpu: ensure no_hw_access is visible before MMIO
    (git-fixes).
  - efi: Fix reservation of unaccepted memory table (git-fixes).
  - commit 05f5344
  - ALSA: usb-audio: Use the right limit for PCM OOB check
    (CVE-2026-23208 bsc#1258468).
  - ALSA: usb-audio: Prevent excessive number of frames
    (CVE-2026-23208 bsc#1258468).
  - commit 9c042c7

------------------------------------------------------------------
------------------  2026-2-20  -  Feb 20 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - mm/hugetlb: fix hugetlb_pmd_shared() (CVE-2026-23100
    bsc#1257817).
  - commit d857986
  - mm/memory-failure: teach kill_accessing_process to accept
    hugetlb tail page pfn (git-fixes).
  - commit 70b84af
  - net: nfc: nci: Fix parameter validation for packet data
    (git-fixes).
  - net: usb: catc: enable basic endpoint checking (git-fixes).
  - atm: fore200e: fix use-after-free in tasklets during device
    removal (git-fixes).
  - USB: serial: option: add Telit FN920C04 RNDIS compositions
    (stable-fixes).
  - fbdev: smscufx: properly copy ioctl memory to kernelspace
    (stable-fixes).
  - bus: fsl-mc: fix use-after-free in driver_override_show()
    (git-fixes).
  - ASoC: cs42l43: Correct handling of 3-pole jack load detection
    (stable-fixes).
  - drm/amd/display: remove assert around dpp_base replacement
    (stable-fixes).
  - drm/amd/display: extend delta clamping logic to CM3 LUT helper
    (stable-fixes).
  - platform/x86: classmate-laptop: Add missing NULL pointer checks
    (stable-fixes).
  - platform/x86/amd/pmc: Add quirk for MECHREVO Wujie 15X Pro
    (stable-fixes).
  - platform/x86: panasonic-laptop: Fix sysfs group leak in error
    path (stable-fixes).
  - gpio: sprd: Change sprd_gpio lock to raw_spin_lock
    (stable-fixes).
  - drm/tegra: hdmi: sor: Fix error: variable ‘j’ set but not
    used (stable-fixes).
  - bus: fsl-mc: Replace snprintf and sprintf with sysfs_emit in
    sysfs show functions (stable-fixes).
  - commit b8da8ac

++++ kernel-rt:

  - mm/hugetlb: fix hugetlb_pmd_shared() (CVE-2026-23100
    bsc#1257817).
  - commit d857986
  - mm/memory-failure: teach kill_accessing_process to accept
    hugetlb tail page pfn (git-fixes).
  - commit 70b84af
  - net: nfc: nci: Fix parameter validation for packet data
    (git-fixes).
  - net: usb: catc: enable basic endpoint checking (git-fixes).
  - atm: fore200e: fix use-after-free in tasklets during device
    removal (git-fixes).
  - USB: serial: option: add Telit FN920C04 RNDIS compositions
    (stable-fixes).
  - fbdev: smscufx: properly copy ioctl memory to kernelspace
    (stable-fixes).
  - bus: fsl-mc: fix use-after-free in driver_override_show()
    (git-fixes).
  - ASoC: cs42l43: Correct handling of 3-pole jack load detection
    (stable-fixes).
  - drm/amd/display: remove assert around dpp_base replacement
    (stable-fixes).
  - drm/amd/display: extend delta clamping logic to CM3 LUT helper
    (stable-fixes).
  - platform/x86: classmate-laptop: Add missing NULL pointer checks
    (stable-fixes).
  - platform/x86/amd/pmc: Add quirk for MECHREVO Wujie 15X Pro
    (stable-fixes).
  - platform/x86: panasonic-laptop: Fix sysfs group leak in error
    path (stable-fixes).
  - gpio: sprd: Change sprd_gpio lock to raw_spin_lock
    (stable-fixes).
  - drm/tegra: hdmi: sor: Fix error: variable ‘j’ set but not
    used (stable-fixes).
  - bus: fsl-mc: Replace snprintf and sprintf with sysfs_emit in
    sysfs show functions (stable-fixes).
  - commit b8da8ac

++++ mozilla-nss:

  - update to NSS 3.112.3
    * bmo#2009552 - avoid integer overflow in platform-independent ghash

++++ libgcrypt:

  - Update to 1.12.1 (jsc#PED-15059)
    * Various fixes
  - Drop libgcrypt-1.12.0-ec_regression.patch as it's upstreamed

++++ libsoup:

  - Rebase and re-enable libsoup-CVE-2026-2708.patch.
  - Update to version 3.6.6:
    + websocket: Fix out-of-bounds read in process_frame
    + Check nulls returned by soup_date_time_new_from_http_string()
    + Numerous fixes to handling of Range headers
    + server: close the connection after responsing a request
    containing Content-Length and Transfer-Encoding
    + Use CRLF as line boundary when parsing chunked enconding data
    + websocket: do not accept messages frames after closing due to
    an error
    + Sanitize filename of content disposition header values
    + Always validate the headers value when coming from untrusted
    source
    + uri-utils: do host validation when checking if a GUri is valid
    + multipart: check length of bytes read
    soup_filter_input_stream_read_until()
    + message-headers: Reject duplicate Host headers
    + server: null-check soup_date_time_to_string()
    + auth-digest: fix crash in
    soup_auth_digest_get_protection_space()
    + session: fix 'heap-use-after-free' caused by 'finishing' queue
    item twice
    + cookies: Avoid expires attribute if date is invalid
    + http1: Set EOF flag once content-length bytes have been read
    + date-utils: Add value checks for date/time parsing
    + multipart: Fix multiple boundry limits
    + Fixed multiple possible memory leaks
    + message-headers: Correct merge of ranges
    + body-input-stream: Correct chunked trailers end detection
    + server-http2: Correctly validate URIs
    + multipart: Fix read out of buffer bounds under
    soup_multipart_new_from_message()
    + headers: Ensure Request-Line comprises entire first line
    + tests: Fix MSVC build error
    + Fix possible deadlock on init from gmodule usage
    + Updated translations.
  - Drop upstream merged patches:
    + libsoup-CVE-2025-11021.patch
    + libsoup-CVE-2025-12105.patch
    + libsoup-CVE-2025-14523.patch
    + libsoup-CVE-2025-32907.patch
    + libsoup-CVE-2025-32908.patch
    + libsoup-CVE-2025-32914.patch
    + libsoup-CVE-2025-4476.patch
    + libsoup-CVE-2025-4945.patch
    + libsoup-CVE-2025-4948.patch
    + libsoup-CVE-2025-4969.patch
    + libsoup-CVE-2026-0716.patch
    + libsoup-CVE-2026-1536.patch
    + libsoup-CVE-2026-1761.patch
    + libsoup-CVE-2026-2369.patch
    + libsoup-CVE-2026-2443.patch
    + libsoup-CVE-2026-1467.patch
    + libsoup-CVE-2026-1760.patch
  - libsoup-CVE-2026-2708.patch temporarily disabled while we need to
    rebase it.
  - Add libsoup-CVE-2026-1467.patch: uri-utils: do host validation
    when checking if a GUri is valid
    (bsc#1257398, CVE-2026-1467, glgo#GNOME/libsoup#488).
  - Add libsoup-CVE-2026-1760.patch: server: close the connection
    after responsing a request containing...
    (bsc#1257597, CVE-2026-1760, glgo#GNOME/libsoup#475).

------------------------------------------------------------------
------------------  2026-2-19  -  Feb 19 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Update
    patches.suse/scsi-Revert-scsi-qla2xxx-Perform-lockless-command-co.patch
    (git-fixes CVE-2025-68818 bsc#1256675).
    Add in the CVE and bsc numbers.
  - commit 421452a
  - scsi: core: Wake up the error handler when final completions
    race against each other (CVE-2026-23110 bsc#1257761).
  - scsi: smartpqi: Fix device resources accessed after device
    removal (CVE-2025-68371 bsc#1255572).
  - commit 1b0c2b6
  - modpost: Ensure exported symbol namespaces are not quoted
    (bsc#1258489).
  - commit 9cb32ea
  - ACPI: CPPC: Fix remaining for_each_possible_cpu() to use online
    CPUs (git-fixes).
  - ACPI: PM: Add unused power resource quirk for THUNDEROBOT ZERO
    (git-fixes).
  - powercap: intel_rapl_tpmi: Remove FW_BUG from invalid version
    check (git-fixes).
  - PM: sleep: wakeirq: Update outdated documentation comments
    (git-fixes).
  - commit baec66c

++++ kernel-rt:

  - Update
    patches.suse/scsi-Revert-scsi-qla2xxx-Perform-lockless-command-co.patch
    (git-fixes CVE-2025-68818 bsc#1256675).
    Add in the CVE and bsc numbers.
  - commit 421452a
  - scsi: core: Wake up the error handler when final completions
    race against each other (CVE-2026-23110 bsc#1257761).
  - scsi: smartpqi: Fix device resources accessed after device
    removal (CVE-2025-68371 bsc#1255572).
  - commit 1b0c2b6
  - modpost: Ensure exported symbol namespaces are not quoted
    (bsc#1258489).
  - commit 9cb32ea
  - ACPI: CPPC: Fix remaining for_each_possible_cpu() to use online
    CPUs (git-fixes).
  - ACPI: PM: Add unused power resource quirk for THUNDEROBOT ZERO
    (git-fixes).
  - powercap: intel_rapl_tpmi: Remove FW_BUG from invalid version
    check (git-fixes).
  - PM: sleep: wakeirq: Update outdated documentation comments
    (git-fixes).
  - commit baec66c

++++ libsoup:

  - Add libsoup-CVE-2026-2708.patch: do not allow adding multiple
    content length values to headers (bsc#1258508 CVE-2026-2708
    glgo#GNOME/libsoup#500).

++++ makedumpfile:

  - makedumpfile-Fix-data-race-in-multi-threading-mode.patch: Fix a
    data race in multi-threading mode (--num-threads=N)
    (bsc#1245569, bsc#1256455).

++++ selinux-policy:

  - Update to version 20250627+git351.529352149:
    * Allow syslog_t access ISC dhcpd /dev/log socket (bsc#1255725)
    * privoxy: account for openSUSE chroot configuration (bsc#1237375)

------------------------------------------------------------------
------------------  2026-2-18  -  Feb 18 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - kABI: Fixup for struct mmu_gather (Git-fixes).
  - commit 343900f
  - mm/hugetlb: fix excessive IPI broadcasts when unsharing PMD
    tables using mmu_gather (Git-fixes).
  - commit 3fe2b90
  - mm/hugetlb: fix copy_hugetlb_page_range() to use
  - >pt_share_count (git-fixes).
  - commit 2c06689
  - crypto: af_alg - Fix incorrect boolean values in af_alg_ctx
    (bsc#1251966 CVE-2025-39964).
  - commit 5b3134b
  - gue: Fix skb memleak with inner IP protocol 0 (CVE-2026-23095
    bsc#1257808).
  - commit 858b063
  - crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
    (bsc#1251966 CVE-2025-39964).
  - commit 3cc4362
  - dst: fix races in rt6_uncached_list_del() and
    rt_del_uncached_list() (CVE-2026-23004 bsc#1257231).
  - commit 6d23e32
  - vsock/virtio: cap TX credit to local buffer size (CVE-2026-23086
    bsc#1257757).
  - commit 2bd0db9
  - dmaengine: fsl-edma: don't explicitly disable clocks in
    .remove() (git-fixes).
  - dmaengine: mediatek: uart-apdma: Fix above 4G addressing TX/RX
    (git-fixes).
  - phy: freescale: imx8qm-hsio: fix NULL pointer dereference
    (git-fixes).
  - phy: qcom: edp: Make the number of clocks flexible (git-fixes).
  - soundwire: intel_ace2x: add SND_HDA_CORE dependency (git-fixes).
  - usb: dwc2: fix resume failure if dr_mode is host (git-fixes).
  - usb: dwc3: gadget: Move vbus draw to workqueue context
    (git-fixes).
  - usb: gadget: tegra-xudc: Add handling for BLCG_COREPLL_PWRDN
    (git-fixes).
  - usb: bdc: fix sleep during atomic (git-fixes).
  - serial: SH_SCI: improve "DMA support" prompt (git-fixes).
  - serial: imx: change SERIAL_IMX_CONSOLE to bool (git-fixes).
  - staging: rtl8723bs: fix null dereference in find_network
    (git-fixes).
  - iio: sca3000: Fix a resource leak in sca3000_probe()
    (git-fixes).
  - iio: gyro: itg3200: Fix unchecked return value in read_raw
    (git-fixes).
  - drivers: iio: mpu3050: use dev_err_probe for regulator request
    (git-fixes).
  - iio: accel: adxl380: Avoid reading more entries than present
    in FIFO (git-fixes).
  - iio: pressure: mprls0025pa: fix pressure calculation
    (git-fixes).
  - iio: pressure: mprls0025pa: fix scan_type struct (git-fixes).
  - iio: pressure: mprls0025pa: fix interrupt flag (git-fixes).
  - iio: pressure: mprls0025pa: fix SPI CS delay violation
    (git-fixes).
  - iio: pressure: mprls0025pa: fix spi_transfer struct
    initialisation (git-fixes).
  - iio: test: drop dangling symbol in gain-time-scale helpers
    (git-fixes).
  - interconnect: mediatek: Aggregate bandwidth with saturating add
    (git-fixes).
  - interconnect: mediatek: Don't hijack parent device (git-fixes).
  - fpga: dfl: use subsys_initcall to allow built-in drivers to
    be added (git-fixes).
  - serial: caif: fix use-after-free in caif_serial ldisc_close()
    (git-fixes).
  - dmaengine: sh: setup_xref error handling (stable-fixes).
  - commit d3fb21a

++++ kernel-rt:

  - kABI: Fixup for struct mmu_gather (Git-fixes).
  - commit 343900f
  - mm/hugetlb: fix excessive IPI broadcasts when unsharing PMD
    tables using mmu_gather (Git-fixes).
  - commit 3fe2b90
  - mm/hugetlb: fix copy_hugetlb_page_range() to use
  - >pt_share_count (git-fixes).
  - commit 2c06689
  - crypto: af_alg - Fix incorrect boolean values in af_alg_ctx
    (bsc#1251966 CVE-2025-39964).
  - commit 5b3134b
  - gue: Fix skb memleak with inner IP protocol 0 (CVE-2026-23095
    bsc#1257808).
  - commit 858b063
  - crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
    (bsc#1251966 CVE-2025-39964).
  - commit 3cc4362
  - dst: fix races in rt6_uncached_list_del() and
    rt_del_uncached_list() (CVE-2026-23004 bsc#1257231).
  - commit 6d23e32
  - vsock/virtio: cap TX credit to local buffer size (CVE-2026-23086
    bsc#1257757).
  - commit 2bd0db9
  - dmaengine: fsl-edma: don't explicitly disable clocks in
    .remove() (git-fixes).
  - dmaengine: mediatek: uart-apdma: Fix above 4G addressing TX/RX
    (git-fixes).
  - phy: freescale: imx8qm-hsio: fix NULL pointer dereference
    (git-fixes).
  - phy: qcom: edp: Make the number of clocks flexible (git-fixes).
  - soundwire: intel_ace2x: add SND_HDA_CORE dependency (git-fixes).
  - usb: dwc2: fix resume failure if dr_mode is host (git-fixes).
  - usb: dwc3: gadget: Move vbus draw to workqueue context
    (git-fixes).
  - usb: gadget: tegra-xudc: Add handling for BLCG_COREPLL_PWRDN
    (git-fixes).
  - usb: bdc: fix sleep during atomic (git-fixes).
  - serial: SH_SCI: improve "DMA support" prompt (git-fixes).
  - serial: imx: change SERIAL_IMX_CONSOLE to bool (git-fixes).
  - staging: rtl8723bs: fix null dereference in find_network
    (git-fixes).
  - iio: sca3000: Fix a resource leak in sca3000_probe()
    (git-fixes).
  - iio: gyro: itg3200: Fix unchecked return value in read_raw
    (git-fixes).
  - drivers: iio: mpu3050: use dev_err_probe for regulator request
    (git-fixes).
  - iio: accel: adxl380: Avoid reading more entries than present
    in FIFO (git-fixes).
  - iio: pressure: mprls0025pa: fix pressure calculation
    (git-fixes).
  - iio: pressure: mprls0025pa: fix scan_type struct (git-fixes).
  - iio: pressure: mprls0025pa: fix interrupt flag (git-fixes).
  - iio: pressure: mprls0025pa: fix SPI CS delay violation
    (git-fixes).
  - iio: pressure: mprls0025pa: fix spi_transfer struct
    initialisation (git-fixes).
  - iio: test: drop dangling symbol in gain-time-scale helpers
    (git-fixes).
  - interconnect: mediatek: Aggregate bandwidth with saturating add
    (git-fixes).
  - interconnect: mediatek: Don't hijack parent device (git-fixes).
  - fpga: dfl: use subsys_initcall to allow built-in drivers to
    be added (git-fixes).
  - serial: caif: fix use-after-free in caif_serial ldisc_close()
    (git-fixes).
  - dmaengine: sh: setup_xref error handling (stable-fixes).
  - commit d3fb21a

++++ zlib:

  - Fix CVE-2026-27171, infinite loop via the crc32_combine64 and
    crc32_combine_gen64 functions due to missing checks for negative
    lengths (bsc#1258392)
    * CVE-2026-27171.patch
  - Fix CVE-2023-45853, integer overflow and resultant heap-based buffer
    overflow in zipOpenNewFileInZip4_6, bsc#1216378
    * CVE-2023-45853.patch

------------------------------------------------------------------
------------------  2026-2-17  -  Feb 17 2026  -------------------
------------------------------------------------------------------

++++ containerized-data-importer:

  - Update to version 1.64.0
    Release notes https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.64.0
    bsc#1235204 (CVE-2024-28180), bsc#1235365 (CVE-2024-45338),
    bsc#1239205 (CVE-2025-22868)

++++ glibc:

  - nss-missing-checks.patch: nss: Missing checks in __nss_configure_lookup,
    __nss_database_get (bsc#1258319, BZ #28940)

++++ kernel-default:

  - mm/page_alloc: make percpu_pagelist_high_fraction reads
    lock-free (git-fixes).
  - commit 2b8ec20
  - cgroup: Fix kernfs_node UAF in css_free_rwork_fn (git-fixes).
  - commit c3b7760
  - ALSA: hda: intel-dsp-config: Prefer legacy driver as fallback
    (stable-fixes).
  - commit ac8783b
  - be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list
    (CVE-2026-23084 bsc#1257830).
  - idpf: fix memory leak in idpf_vport_rel() (CVE-2026-23023
    bsc#1257556).
  - commit 63e3066
  - leds: qcom-lpg: Check the return value of regmap_bulk_write()
    (git-fixes).
  - backlight: qcom-wled: Change PM8950 WLED configurations
    (git-fixes).
  - backlight: qcom-wled: Support ovp values for PMI8994
    (git-fixes).
  - mfd: omap-usb-host: Fix OF populate on driver rebind
    (git-fixes).
  - mfd: qcom-pm8xxx: Fix OF populate on driver rebind (git-fixes).
  - mfd: arizona: Fix regulator resource leak on
    wm5102_clear_write_sequencer() failure (git-fixes).
  - mfd: core: Add locking around 'mfd_of_node_list' (git-fixes).
  - mfd: tps6105x: Fix kernel-doc warnings relating to the core
    struct and tps6105x_mode (git-fixes).
  - Revert "mfd: da9052-spi: Change read-mask to write-mask"
    (stable-fixes).
  - pinctrl: single: fix refcount leak in pcs_add_gpio_func()
    (git-fixes).
  - pinctrl: qcom: sm8250-lpass-lpi: Fix i2s2_data_groups definition
    (git-fixes).
  - pinctrl: equilibrium: Fix device node reference leak in
    pinbank_init() (git-fixes).
  - Bluetooth: btusb: Add USB ID 7392:e611 for Edimax EW-7611UXB
    (stable-fixes).
  - commit 8fe4d9c

++++ kernel-rt:

  - mm/page_alloc: make percpu_pagelist_high_fraction reads
    lock-free (git-fixes).
  - commit 2b8ec20
  - cgroup: Fix kernfs_node UAF in css_free_rwork_fn (git-fixes).
  - commit c3b7760
  - ALSA: hda: intel-dsp-config: Prefer legacy driver as fallback
    (stable-fixes).
  - commit ac8783b
  - be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list
    (CVE-2026-23084 bsc#1257830).
  - idpf: fix memory leak in idpf_vport_rel() (CVE-2026-23023
    bsc#1257556).
  - commit 63e3066
  - leds: qcom-lpg: Check the return value of regmap_bulk_write()
    (git-fixes).
  - backlight: qcom-wled: Change PM8950 WLED configurations
    (git-fixes).
  - backlight: qcom-wled: Support ovp values for PMI8994
    (git-fixes).
  - mfd: omap-usb-host: Fix OF populate on driver rebind
    (git-fixes).
  - mfd: qcom-pm8xxx: Fix OF populate on driver rebind (git-fixes).
  - mfd: arizona: Fix regulator resource leak on
    wm5102_clear_write_sequencer() failure (git-fixes).
  - mfd: core: Add locking around 'mfd_of_node_list' (git-fixes).
  - mfd: tps6105x: Fix kernel-doc warnings relating to the core
    struct and tps6105x_mode (git-fixes).
  - Revert "mfd: da9052-spi: Change read-mask to write-mask"
    (stable-fixes).
  - pinctrl: single: fix refcount leak in pcs_add_gpio_func()
    (git-fixes).
  - pinctrl: qcom: sm8250-lpass-lpi: Fix i2s2_data_groups definition
    (git-fixes).
  - pinctrl: equilibrium: Fix device node reference leak in
    pinbank_init() (git-fixes).
  - Bluetooth: btusb: Add USB ID 7392:e611 for Edimax EW-7611UXB
    (stable-fixes).
  - commit 8fe4d9c

++++ python-cryptography:

  - CVE-2026-26007: Subgroup Attack Due to Missing Subgroup
    Validation for SECT Curves (bsc#1258074)
    * added CVE-2026-26007.patch

------------------------------------------------------------------
------------------  2026-2-16  -  Feb 16 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Input: stmfts - make comments correct (git-fixes).
  - Input: stmfts - correct wording for the warning message
    (git-fixes).
  - clk: qcom: gfx3d: add parent to parent request map (git-fixes).
  - clk: qcom: dispcc-sdm845: Enable parents for pixel clocks
    (git-fixes).
  - clk: qcom: gcc-msm8917: Remove ALWAYS_ON flag from cpp_gdsc
    (git-fixes).
  - clk: qcom: gcc-msm8953: Remove ALWAYS_ON flag from cpp_gdsc
    (git-fixes).
  - clk: qcom: gcc-sm8450: Update the SDCC RCGs to use
    shared_floor_ops (git-fixes).
  - clk: qcom: rcg2: compute 2d using duty fraction directly
    (git-fixes).
  - clk: qcom: gcc-sm8550: Use floor ops for SDCC RCGs (git-fixes).
  - clk: mediatek: Fix error handling in runtime PM setup
    (git-fixes).
  - clk: meson: g12a: Limit the HDMI PLL OD to /4 (git-fixes).
  - clk: meson: gxbb: Limit the HDMI PLL OD to /4 on GXL/GXM SoCs
    (git-fixes).
  - clk: tegra: tegra124-emc: Fix potential memory leak in
    tegra124_clk_register_emc() (git-fixes).
  - clk: tegra: tegra124-emc: fix device leak on set_rate()
    (git-fixes).
  - clk: clk-apple-nco: Add "apple,t8103-nco" compatible
    (git-fixes).
  - clk: renesas: rzg2l: Select correct div round macro (git-fixes).
  - clk: renesas: rzg2l: Fix intin variable size (git-fixes).
  - fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe()
    (git-fixes).
  - fbdev: of_display_timing: Fix device node reference leak in
    of_get_display_timings() (git-fixes).
  - fbdev: of: display_timing: fix refcount leak in
    of_get_display_timings() (git-fixes).
  - fbdev: vt8500lcdfb: fix missing dma_free_coherent() (git-fixes).
  - fbcon: check return value of con2fb_acquire_newinfo()
    (git-fixes).
  - fbdev: rivafb: fix divide error in nv3_arb() (git-fixes).
  - rpmsg: core: fix race in driver_override_show() and use core
    helper (git-fixes).
  - commit 8244124
  - Update "drm/mgag200: fix mgag200_bmc_stop_scanout()" bug number (bsc#1258153)
  - commit cbe6f46

++++ kernel-rt:

  - Input: stmfts - make comments correct (git-fixes).
  - Input: stmfts - correct wording for the warning message
    (git-fixes).
  - clk: qcom: gfx3d: add parent to parent request map (git-fixes).
  - clk: qcom: dispcc-sdm845: Enable parents for pixel clocks
    (git-fixes).
  - clk: qcom: gcc-msm8917: Remove ALWAYS_ON flag from cpp_gdsc
    (git-fixes).
  - clk: qcom: gcc-msm8953: Remove ALWAYS_ON flag from cpp_gdsc
    (git-fixes).
  - clk: qcom: gcc-sm8450: Update the SDCC RCGs to use
    shared_floor_ops (git-fixes).
  - clk: qcom: rcg2: compute 2d using duty fraction directly
    (git-fixes).
  - clk: qcom: gcc-sm8550: Use floor ops for SDCC RCGs (git-fixes).
  - clk: mediatek: Fix error handling in runtime PM setup
    (git-fixes).
  - clk: meson: g12a: Limit the HDMI PLL OD to /4 (git-fixes).
  - clk: meson: gxbb: Limit the HDMI PLL OD to /4 on GXL/GXM SoCs
    (git-fixes).
  - clk: tegra: tegra124-emc: Fix potential memory leak in
    tegra124_clk_register_emc() (git-fixes).
  - clk: tegra: tegra124-emc: fix device leak on set_rate()
    (git-fixes).
  - clk: clk-apple-nco: Add "apple,t8103-nco" compatible
    (git-fixes).
  - clk: renesas: rzg2l: Select correct div round macro (git-fixes).
  - clk: renesas: rzg2l: Fix intin variable size (git-fixes).
  - fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe()
    (git-fixes).
  - fbdev: of_display_timing: Fix device node reference leak in
    of_get_display_timings() (git-fixes).
  - fbdev: of: display_timing: fix refcount leak in
    of_get_display_timings() (git-fixes).
  - fbdev: vt8500lcdfb: fix missing dma_free_coherent() (git-fixes).
  - fbcon: check return value of con2fb_acquire_newinfo()
    (git-fixes).
  - fbdev: rivafb: fix divide error in nv3_arb() (git-fixes).
  - rpmsg: core: fix race in driver_override_show() and use core
    helper (git-fixes).
  - commit 8244124
  - Update "drm/mgag200: fix mgag200_bmc_stop_scanout()" bug number (bsc#1258153)
  - commit cbe6f46

------------------------------------------------------------------
------------------  2026-2-14  -  Feb 14 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - crypto: ccp - Add an S4 restore flow (git-fixes).
  - crypto: ccp - Declare PSP dead if PSP_CMD_TEE_RING_INIT fails
    (git-fixes).
  - tools/power/x86/intel-speed-select: Fix file descriptor leak
    in isolate_cpus() (git-fixes).
  - platform/x86: ISST: Add missing write block check (git-fixes).
  - mtd: rawnand: pl353: Fix software ECC support (git-fixes).
  - mtd: spinand: Disable continuous read during probe (git-fixes).
  - mtd: spinand: Fix kernel doc (git-fixes).
  - mtd: rawnand: cadence: Fix return type of CDMA send-and-wait
    helper (git-fixes).
  - mtd: parsers: ofpart: fix OF node refcount leak in
    parse_fixed_partitions() (git-fixes).
  - mtd: parsers: Fix memory leak in
    mtd_parser_tplink_safeloader_parse() (git-fixes).
  - commit 8b24802

++++ kernel-rt:

  - crypto: ccp - Add an S4 restore flow (git-fixes).
  - crypto: ccp - Declare PSP dead if PSP_CMD_TEE_RING_INIT fails
    (git-fixes).
  - tools/power/x86/intel-speed-select: Fix file descriptor leak
    in isolate_cpus() (git-fixes).
  - platform/x86: ISST: Add missing write block check (git-fixes).
  - mtd: rawnand: pl353: Fix software ECC support (git-fixes).
  - mtd: spinand: Disable continuous read during probe (git-fixes).
  - mtd: spinand: Fix kernel doc (git-fixes).
  - mtd: rawnand: cadence: Fix return type of CDMA send-and-wait
    helper (git-fixes).
  - mtd: parsers: ofpart: fix OF node refcount leak in
    parse_fixed_partitions() (git-fixes).
  - mtd: parsers: Fix memory leak in
    mtd_parser_tplink_safeloader_parse() (git-fixes).
  - commit 8b24802

++++ libsoup:

  - Add more CVE fixes:
    + libsoup-CVE-2025-32049.patch (bsc#1240751 CVE-2025-32049
    glgo#GNOME/libsoup#390)
    + libsoup-CVE-2026-2443.patch (bsc#1258170 CVE-2026-2443
    glgo#GNOME/libsoup#487)
    + libsoup-CVE-2026-2369.patch (bsc#1258120 CVE-2026-2369
    glgo#GNOME/libsoup!508)

------------------------------------------------------------------
------------------  2026-2-13  -  Feb 13 2026  -------------------
------------------------------------------------------------------

++++ busybox:

  - Fix arbitrary file overwrite and potential code execution via
    incomplete path sanitization (CVE-2026-26157, bsc#1258163),
    fix arbitrary file modification and privilege escalation via
    unvalidated tar archive entries (CVE-2026-26158, bsc#1258167)
    * 0001-tar-strip-unsafe-hardlink-components-GNU-tar-does-th.patch
    * 0002-tar-only-strip-unsafe-components-from-hardlinks-not-.patch

++++ kernel-default:

  - rtmutex_api: provide correct extern functions (git-fixes).
  - commit 351d966
  - kabi/severities: Ignore tdx related APIs
    Changing struct tdx_vp causes various tdh_* apis to also change. In our
    kernel those are EXPORT_SYMBOL_GPL while in the upstream kernel they are
    EXPORT_SYMBOL_FOR_KVM, meaning the original intent was for those symbol
    to be consumed only by KVM.
    So let's add those symbol to severities and exclude them from ABI
    checking.
  - commit 48755cb
  - KVM: Rename kvm_slot_can_be_private() to kvm_slot_has_gmem() (git-fixes).
  - commit 6c28814
  - KVM: x86: Enable KVM_GUEST_MEMFD for all 64-bit builds (git-fixes).
  - commit 6b4e8db
  - KVM: Rename CONFIG_KVM_GENERIC_PRIVATE_MEM to CONFIG_HAVE_KVM_ARCH_GMEM_POPULATE (git-fixes).
  - commit 666f7db
  - ice: fix devlink reload call trace (CVE-2026-23104 bsc#1257763).
  - net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
    (CVE-2026-23035 bsc#1257559).
  - idpf: fix aux device unplugging when rdma is not supported by
    vport (CVE-2026-23042 bsc#1257705).
  - idpf: fix memory leak of flow steer list on rmmod
    (CVE-2026-23024 bsc#1257572).
  - idpf: fix error handling in the init_task on load
    (CVE-2026-23017 bsc#1257552).
  - idpf: fix memory leak in idpf_vc_core_deinit() (CVE-2026-23022
    bsc#1257581).
  - commit 0686561
  - KVM: Rename CONFIG_KVM_PRIVATE_MEM to CONFIG_KVM_GUEST_MEMFD (git-fixes).
  - commit 0ae9ca0
  - power: supply: qcom_battmgr: Recognize "LiP" as lithium-polymer
    (git-fixes).
  - power: supply: pm8916_lbc: Fix use-after-free for extcon in
    IRQ handler (git-fixes).
  - power: supply: wm97xx: Fix NULL pointer dereference in
    power_supply_changed() (git-fixes).
  - power: supply: bq27xxx: fix wrong errno when bus ops are
    unsupported (git-fixes).
  - power: reset: nvmem-reboot-mode: respect cell size for
    nvmem_cell_write (git-fixes).
  - power: supply: sbs-battery: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: rt9455: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: pm8916_lbc: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: pm8916_bms_vm: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: goldfish: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: cpcap-battery: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: bq25980: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: bq256xx: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: act8945a: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: ab8500: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - ata: pata_ftide010: Fix some DMA timings (git-fixes).
  - rapidio: replace rio_free_net() with kfree() in
    rio_scan_alloc_net() (git-fixes).
  - commit f9b5687

++++ kernel-rt:

  - rtmutex_api: provide correct extern functions (git-fixes).
  - commit 351d966
  - kabi/severities: Ignore tdx related APIs
    Changing struct tdx_vp causes various tdh_* apis to also change. In our
    kernel those are EXPORT_SYMBOL_GPL while in the upstream kernel they are
    EXPORT_SYMBOL_FOR_KVM, meaning the original intent was for those symbol
    to be consumed only by KVM.
    So let's add those symbol to severities and exclude them from ABI
    checking.
  - commit 48755cb
  - KVM: Rename kvm_slot_can_be_private() to kvm_slot_has_gmem() (git-fixes).
  - commit 6c28814
  - KVM: x86: Enable KVM_GUEST_MEMFD for all 64-bit builds (git-fixes).
  - commit 6b4e8db
  - KVM: Rename CONFIG_KVM_GENERIC_PRIVATE_MEM to CONFIG_HAVE_KVM_ARCH_GMEM_POPULATE (git-fixes).
  - commit 666f7db
  - ice: fix devlink reload call trace (CVE-2026-23104 bsc#1257763).
  - net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv
    (CVE-2026-23035 bsc#1257559).
  - idpf: fix aux device unplugging when rdma is not supported by
    vport (CVE-2026-23042 bsc#1257705).
  - idpf: fix memory leak of flow steer list on rmmod
    (CVE-2026-23024 bsc#1257572).
  - idpf: fix error handling in the init_task on load
    (CVE-2026-23017 bsc#1257552).
  - idpf: fix memory leak in idpf_vc_core_deinit() (CVE-2026-23022
    bsc#1257581).
  - commit 0686561
  - KVM: Rename CONFIG_KVM_PRIVATE_MEM to CONFIG_KVM_GUEST_MEMFD (git-fixes).
  - commit 0ae9ca0
  - power: supply: qcom_battmgr: Recognize "LiP" as lithium-polymer
    (git-fixes).
  - power: supply: pm8916_lbc: Fix use-after-free for extcon in
    IRQ handler (git-fixes).
  - power: supply: wm97xx: Fix NULL pointer dereference in
    power_supply_changed() (git-fixes).
  - power: supply: bq27xxx: fix wrong errno when bus ops are
    unsupported (git-fixes).
  - power: reset: nvmem-reboot-mode: respect cell size for
    nvmem_cell_write (git-fixes).
  - power: supply: sbs-battery: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: rt9455: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: pm8916_lbc: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: pm8916_bms_vm: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: goldfish: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: cpcap-battery: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: bq25980: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: bq256xx: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: act8945a: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - power: supply: ab8500: Fix use-after-free in
    power_supply_changed() (git-fixes).
  - ata: pata_ftide010: Fix some DMA timings (git-fixes).
  - rapidio: replace rio_free_net() with kfree() in
    rio_scan_alloc_net() (git-fixes).
  - commit f9b5687

++++ libxml2:

  - CVE-2026-0990: call stack overflow leading to application crash
    due to infinite recursion in `xmlCatalogXMLResolveURI` (bsc#1256807, bsc#1256811)
    * Add patch libxml2-CVE-2026-0990.patch
  - CVE-2026-0992: excessive resource consumption when processing XML
    catalogs due to exponential behavior when handling `<nextCatalog>` elements (bsc#1256808, bsc#1256809, bsc#1256812)
    * Add patch libxml2-CVE-2026-0992.patch
  - CVE-2025-8732: infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247858, bsc#1247850)
    * Add patch libxml2-CVE-2025-8732.patch

++++ libxml2-python:

  - CVE-2026-0990: call stack overflow leading to application crash
    due to infinite recursion in `xmlCatalogXMLResolveURI` (bsc#1256807, bsc#1256811)
    * Add patch libxml2-CVE-2026-0990.patch
  - CVE-2026-0992: excessive resource consumption when processing XML
    catalogs due to exponential behavior when handling `<nextCatalog>` elements (bsc#1256808, bsc#1256809, bsc#1256812)
    * Add patch libxml2-CVE-2026-0992.patch
  - CVE-2025-8732: infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247858, bsc#1247850)
    * Add patch libxml2-CVE-2025-8732.patch

------------------------------------------------------------------
------------------  2026-2-12  -  Feb 12 2026  -------------------
------------------------------------------------------------------

++++ haproxy:

  - (bsc#1257976)VUL-0: CVE-2026-26081, CVE-2026-26080: haproxy: vulnerabilities on QUIC
    Apply upstream patches:
    0001-fix-parsing-frame-type.patch
    0001-reject-invalid-token.patch

++++ kernel-default:

  - KABI: fix
    "Revert-dm-fix-a-race-condition-in-retrieve_deps.patch"
    (git-fixes).
  - commit 53fd79b
  - net/sched: act_ife: avoid possible NULL deref (CVE-2026-23064
    bsc#1257765).
  - selftests/tc-testing: Try to add teql as a child qdisc
    (CVE-2026-23105 bsc#1257775).
  - net/sched: qfq: Use cl_is_active to determine whether class
    is active in qfq_rm_from_ag (CVE-2026-23105 bsc#1257775).
  - commit 3ff4470
  - Revert "dm: fix a race condition in retrieve_deps" (git-fixes).
  - commit e64c40a
  - Refresh sorted patches.
  - commit 3b39938
  - RISC-V: KVM: use kvm_trylock_all_vcpus when locking all vCPUs (git-fixes).
  - commit 292c30b
  - KVM: arm64: use kvm_trylock_all_vcpus when locking all vCPUs (git-fixes).
  - commit 45ee0a5
  - KVM: add kvm_lock_all_vcpus and kvm_trylock_all_vcpus (git-fixes).
  - commit f8807d7
  - x86: KVM: SVM: use kvm_lock_all_vcpus instead of a custom implementation (git-fixes).
  - commit 27b7fd9
  - locking/mutex: implement mutex_lock_killable_nest_lock (git-fixes).
  - commit c11266f
  - locking/mutex: implement mutex_trylock_nested (git-fixes).
  - commit 4df10c6
  - KVM: TDX: Use struct_size to simplify tdx_get_capabilities() (git-fixes).
  - commit 1f75b03
  - KVM: TDX: Check size of user's kvm_tdx_capabilities array before allocating (git-fixes).
  - commit 319fd02
  - KVM: TDX: Fix sparse warnings from using 0 for NULL (git-fixes).
  - commit 3438716
  - KVM: TDX: Remove __user annotation from kernel pointer (git-fixes).
  - commit f5a4acb
  - KVM: TDX: Take MMU lock around tdh_vp_init() (git-fixes).
  - commit 3b6a5f3
  - KVM: TDX: Fix list_add corruption during vcpu_load() (git-fixes).
  - commit fcf6177
  - KVM: TDX: Bug the VM if extending the initial measurement fails (git-fixes).
  - commit 056ce6c
  - KVM: TDX: Guard VM state transitions with "all" the locks (git-fixes).
  - commit 6fc029e
  - KVM: TDX: Don't copy "cmd" back to userspace for KVM_TDX_CAPABILITIES (git-fixes).
  - commit a1cf957
  - KVM: TDX: Use guard() to acquire kvm->lock in tdx_vm_ioctl() (git-fixes).
  - commit 53cbd86
  - KVM: TDX: Convert INIT_MEM_REGION and INIT_VCPU to "unlocked" vCPU ioctl (git-fixes).
  - commit 33e9280
  - KVM: TDX: Add tdx_get_cmd() helper to get and validate sub-ioctl command (git-fixes).
  - commit db2e487
  - KVM: TDX: Add macro to retry SEAMCALLs when forcing vCPUs out of  guest (git-fixes).
  - commit f789249
  - KVM: TDX: Assert that mmu_lock is held for write when removing S-EPT  entries (git-fixes).
  - commit 5c9b28f
  - KVM: TDX: Derive error argument names from the local variable names (git-fixes).
  - commit e750b72
  - KVM: TDX: Combine KVM_BUG_ON + pr_tdx_error() into TDX_BUG_ON() (git-fixes).
  - commit d2a9d32
  - KVM: TDX: Fold tdx_sept_zap_private_spte() into tdx_sept_remove_private_spte() (git-fixes).
  - commit 8fa4208
  - KVM: TDX: ADD pages to the TD image while populating mirror EPT entries (git-fixes).
  - commit 05e82a8
  - KVM: TDX: Fold tdx_mem_page_record_premap_cnt() into its sole caller (git-fixes).
  - commit cc267d2
  - KVM: TDX: Use atomic64_dec_return() instead of a poor equivalent (git-fixes).
  - commit 794f48a
  - KVM: TDX: Avoid a double-KVM_BUG_ON() in tdx_sept_zap_private_spte() (git-fixes).
  - commit 8899368
  - KVM: TDX: WARN if mirror SPTE doesn't have full RWX when creating S-EPT mapping (git-fixes).
  - commit d132554
  - KVM: x86/mmu: Drop the return code from kvm_x86_ops.remove_external_spte() (git-fixes).
  - commit 2570719
  - KVM: TDX: Fold tdx_sept_drop_private_spte() into tdx_sept_remove_private_spte() (git-fixes).
  - commit 83ec6b9
  - KVM: TDX: Return -EIO, not -EINVAL, on a KVM_BUG_ON() condition (git-fixes).
  - commit ebb64f7
  - KVM: TDX: Drop superfluous page pinning in S-EPT management (git-fixes).
  - commit 5eced3b
  - KVM: x86/mmu: Rename kvm_tdp_map_page() to kvm_tdp_page_prefault() (git-fixes).
  - commit 11c9e24
  - KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (bsc#1256708, CVE-2025-71104).
  - commit 8d2aab2
  - migrate: correct lock ordering for hugetlb file folios
    (CVE-2026-23097 bsc#1257815).
  - commit 30b8633
  - vsock/virtio: Coalesce only linear skb (bsc#1257740, CVE-2026-23057).
  - commit 310c89d
  - wifi: ath10k: sdio: add missing lock protection in
    ath10k_sdio_fw_crashed_dump() (git-fixes).
  - wifi: ath9k: fix kernel-doc warnings in common-debug.h
    (git-fixes).
  - wifi: ath9k: debug.h: fix kernel-doc bad lines and struct
    ath_tx_stats (git-fixes).
  - wifi: cfg80211: stop NAN and P2P in cfg80211_leave (git-fixes).
  - wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add
    (git-fixes).
  - wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()
    (git-fixes).
  - wifi: cfg80211: Fix use_for flag update on BSS refresh
    (git-fixes).
  - PCI: mediatek: Fix IRQ domain leak when MSI allocation fails
    (git-fixes).
  - PCI: dwc: Fix msg_atu_index assignment (git-fixes).
  - Revert "PCI: qcom: Enable MSI interrupts together with Link
    up if 'Global IRQ' is supported" (stable-fixes).
  - PCI: Add ACS quirk for Pericom PI7C9X2G404 switches [12d8:b404]
    (git-fixes).
  - PCI: Fix pci_slot_trylock() error handling (git-fixes).
  - PCI: Use resource_set_range() that correctly sets ->end
    (git-fixes).
  - PCI/portdrv: Fix potential resource leak (git-fixes).
  - PCI/PM: Avoid redundant delays on D3hot->D3cold (git-fixes).
  - PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page()
    fails (git-fixes).
  - PCI/IOV: Fix race between SR-IOV enable/disable and hotplug
    (git-fixes).
  - Revert "PCI/IOV: Add PCI rescan-remove locking when
    enabling/disabling SR-IOV" (git-fixes).
  - PCI/ACPI: Restrict program_hpx_type2() to AER bits (git-fixes).
  - PCI: Initialize RCB from pci_configure_device() (git-fixes).
  - PCI: Check parent for NULL in of_pci_bus_release_domain_nr()
    (git-fixes).
  - PCI: Mark 3ware-9650SA Root Port Extended Tags as broken
    (git-fixes).
  - PCI: Do not attempt to set ExtTag for VFs (git-fixes).
  - PCI: endpoint: Fix swapped parameters in
    pci_{primary/secondary}_epc_epf_unlink() functions (git-fixes).
  - PCI: endpoint: Avoid creating sub-groups asynchronously
    (git-fixes).
  - regulator: core: move supply check earlier in
    set_machine_constraints() (git-fixes).
  - regulator: core: fix locking in regulator_resolve_supply()
    error path (git-fixes).
  - platform/chrome: cros_ec_lightbar: Fix response size
    initialization (git-fixes).
  - platform/chrome: cros_typec_switch: Don't touch struct
    fwnode_handle::dev (git-fixes).
  - soc: rockchip: grf: Support multiple grf to be handled
    (git-fixes).
  - soc: rockchip: grf: Fix wrong RK3576_IOCGRF_MISC_CON definition
    (git-fixes).
  - reset: gpio: suppress bind attributes in sysfs (git-fixes).
  - soc: mediatek: svs: Fix memory leak in svs_enable_debug_write()
    (git-fixes).
  - soc: qcom: cmd-db: Use devm_memremap() to fix memory leak in
    cmd_db_dev_probe (git-fixes).
  - soc: qcom: smem: handle ENOMEM error during probe (git-fixes).
  - soc: ti: pruss: Fix double free in pruss_clk_mux_setup()
    (git-fixes).
  - soc: ti: k3-socinfo: Fix regmap leak on probe failure
    (git-fixes).
  - spi: hisi-kunpeng: Fixed the wrong debugfs node name in hisi_spi
    debugfs initialization (stable-fixes).
  - regmap: maple: free entry on mas_store_gfp() failure
    (stable-fixes).
  - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt
    twice (stable-fixes).
  - wifi: mac80211: correctly check if CSA is active (stable-fixes).
  - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
    (stable-fixes).
  - wifi: mac80211: collect station statistics earlier when
    disconnect (stable-fixes).
  - wifi: mac80211: ocb: skip rx_no_sta when interface is not joined
    (stable-fixes).
  - wifi: wlcore: ensure skb headroom before skb_push
    (stable-fixes).
  - commit 6474bb4
  - nfc: hci: shdlc: Stop timers and work before freeing context
    (git-fixes).
  - of: unittest: fix possible null-pointer dereferences in
    of_unittest_property_copy() (git-fixes).
  - media: uvcvideo: Fix allocation for small frame sizes
    (git-fixes).
  - media: verisilicon: AV1: Fix tile info buffer size (git-fixes).
  - media: venus: vdec: restrict EOS addr quirk to IRIS2 only
    (git-fixes).
  - media: venus: vdec: fix error state assignment for zero
    bytesused (git-fixes).
  - media: i2c: ov01a10: Fix digital gain range (git-fixes).
  - media: stm32: dcmipp: bytecap: clear all interrupts upon stream
    stop (git-fixes).
  - media: ccs: Accommodate C-PHY into the calculation (git-fixes).
  - media: ipu6: Fix RPM reference leak in probe error paths
    (git-fixes).
  - media: ipu6: Fix typo and wrong constant in ipu6-mmu.c
    (git-fixes).
  - media: dw9714: Fix powerup sequence (git-fixes).
  - media: i2c: ov5647: use our own mutex for the ctrl lock
    (git-fixes).
  - media: ccs: Fix setting initial sub-device state (git-fixes).
  - media: i2c: ov5647: Fix PIXEL_RATE value for VGA mode
    (git-fixes).
  - media: i2c: ov5647: Sensor should report RAW color space
    (git-fixes).
  - media: i2c: ov5647: Correct minimum VBLANK value (git-fixes).
  - media: i2c: ov5647: Correct pixel array offset (git-fixes).
  - media: i2c: ov5647: Initialize subdev before controls
    (git-fixes).
  - media: ccs: Avoid possible division by zero (git-fixes).
  - media: qcom: camss: vfe: Fix out-of-bounds access in
    vfe_isr_reg_update() (git-fixes).
  - media: i2c: ov01a10: Fix test-pattern disabling (git-fixes).
  - media: i2c: ov01a10: Fix passing stream instead of pad to
    v4l2_subdev_state_get_format() (git-fixes).
  - media: i2c: ov01a10: Add missing v4l2_subdev_cleanup() calls
    (git-fixes).
  - media: i2c: ov01a10: Fix analogue gain range (git-fixes).
  - media: i2c: ov01a10: Fix reported pixel-rate value (git-fixes).
  - media: i2c: ov01a10: Fix the horizontal flip control
    (git-fixes).
  - media: i2c/tw9906: Fix potential memory leak in tw9906_probe()
    (git-fixes).
  - media: i2c/tw9903: Fix potential memory leak in tw9903_probe()
    (git-fixes).
  - media: cx25821: Add missing unmap in snd_cx25821_hw_params()
    (git-fixes).
  - media: cx23885: Add missing unmap in snd_cx23885_hw_params()
    (git-fixes).
  - media: cx88: Add missing unmap in snd_cx88_hw_params()
    (git-fixes).
  - media: radio-keene: fix memory leak in error path (git-fixes).
  - media: tegra-video: Fix memory leak in
    __tegra_channel_try_format() (git-fixes).
  - media: verisilicon: AV1: Set IDR flag for intra_only frame type
    (git-fixes).
  - media: rockchip: rga: Fix possible ERR_PTR dereference in
    rga_buf_init() (git-fixes).
  - media: amphion: Drop min_queued_buffers assignment (git-fixes).
  - media: verisilicon: AV1: Fix tx mode bit setting (git-fixes).
  - media: verisilicon: AV1: Fix enable cdef computation
    (git-fixes).
  - media: chips-media: wave5: Fix memory leak on codec_info
    allocation failure (git-fixes).
  - media: chips-media: wave5: Fix device cleanup order to prevent
    kernel panic (git-fixes).
  - media: chips-media: wave5: Fix kthread worker destruction in
    polling mode (git-fixes).
  - media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove()
    (git-fixes).
  - media: mtk-mdp: Fix error handling in probe function
    (git-fixes).
  - media: mediatek: encoder: Fix uninitialized scalar variable
    issue (git-fixes).
  - HID: intel-ish-hid: fix NULL-ptr-deref in
    ishtp_bus_remove_all_clients (git-fixes).
  - HID: hid-pl: handle probe errors (git-fixes).
  - HID: playstation: Add missing check for input_ff_create_memless
    (git-fixes).
  - hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler
    optimization induced race (git-fixes).
  - memory: mtk-smi: fix device leak on larb probe (git-fixes).
  - memory: mtk-smi: fix device leaks on common probe (git-fixes).
  - HID: logitech: add HID++ support for Logitech MX Anywhere 3S
    (stable-fixes).
  - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30
    (2d99:a101) (stable-fixes).
  - HID: i2c-hid: fix potential buffer overflow in
    i2c_hid_get_report() (stable-fixes).
  - HID: quirks: Add another Chicony HP 5MP Cameras to
    hid_ignore_list (stable-fixes).
  - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
    (stable-fixes).
  - net: usb: sr9700: support devices with virtual driver CD
    (stable-fixes).
  - commit 2d30005
  - scsi: qla2xxx: edif: Fix dma_free_coherent() size (git-fixes).
  - scsi: qla2xxx: Sanitize payload size to prevent member overflow
    (git-fixes).
  - scsi: qla2xxx: Enable/disable IRQD_NO_BALANCING during reset
    (git-fixes).
  - scsi: qla2xxx: target: Improve safety of cmd lookup by handle
    (git-fixes).
  - scsi: qla2xxx: target: Add back SRR support (git-fixes).
  - scsi: qla2xxx: target: Improve cmd logging (git-fixes).
  - scsi: qla2xxx: target: Add cmd->rsp_sent (git-fixes).
  - scsi: qla2xxx: target: Fix invalid memory access with big CDBs
    (git-fixes).
  - scsi: qla2xxx: Fix TMR failure handling (git-fixes).
  - scsi: qla2xxx: target: Improve checks in qlt_xmit_response()
    / qlt_rdy_to_xfer() (git-fixes).
  - scsi: qla2xxx: target: Fix races with aborting commands
    (git-fixes).
  - scsi: qla2xxx: Clear cmds after chip reset (CVE-2025-68745
    bsc#1255721 git-fixes).
  - scsi: qla2xxx: target: Fix term exchange when cmd_sent_to_fw ==
    1 (git-fixes).
  - scsi: qla2xxx: target: Improve debug output for term exchange
    (git-fixes).
  - scsi: qla2xxx: target: Remove code for unsupported hardware
    (git-fixes).
  - scsi: qla2xxx: Use reinit_completion on mbx_intr_comp
    (git-fixes).
  - scsi: qla2xxx: Fix lost interrupts with qlini_mode=disabled
    (git-fixes).
  - scsi: qla2xxx: Fix initiator mode with qlini_mode=exclusive
    (git-fixes).
  - scsi: Revert "scsi: qla2xxx: Perform lockless command completion
    in abort path" (git-fixes).
  - commit c2959d9
  - drm/xe: Unregister drm device on probe error (git-fixes).
  - drm/msm/a2xx: fix pixel shader start on A225 (git-fixes).
  - drm/msm/dpu: fix CMD panels on DPU 1.x - 3.x (git-fixes).
  - drm/msm/dpu: drop intr_start from DPU 3.x catalog files
    (git-fixes).
  - drm/msm/disp: set num_planes to 1 for interleaved YUV formats
    (git-fixes).
  - drm/msm/dpu: fix WD timer handling on DPU 8.x (git-fixes).
  - drm/msm/dpu: Set vsync source irrespective of mdp top support
    (git-fixes).
  - drm/bridge: anx7625: Fix invalid EDID size (git-fixes).
  - drm/buddy: Prevent BUG_ON by validating rounded allocation
    (git-fixes).
  - drm/tegra: dsi: fix device leak on probe (git-fixes).
  - drm/amdkfd: Fix signal_eviction_fence() bool return value
    (git-fixes).
  - drm/amd: Drop "amdgpu kernel modesetting enabled" message
    (git-fixes).
  - drm/tests: shmem: Swap names of export tests (git-fixes).
  - drm/panthor: Evict groups before VM termination (git-fixes).
  - drm/panel: sw43408: Remove manual invocation of unprepare at
    remove (git-fixes).
  - drm/panthor: Make sure we resume the tick when new jobs are
    submitted (git-fixes).
  - drm/panthor: Fix the logic that decides when to stop ticking
    (git-fixes).
  - drm/panthor: Fix immediate ticking on a disabled tick
    (git-fixes).
  - drm/panthor: Fix the group priority rotation logic (git-fixes).
  - drm/panthor: Fix the full_tick check (git-fixes).
  - drm/panthor: Recover from panthor_gpu_flush_caches() failures
    (git-fixes).
  - firmware: arm_ffa: Correct 32-bit response handling in
    NOTIFICATION_INFO_GET (git-fixes).
  - drm/xe/pm: Disable D3Cold for BMG only on specific platforms
    (git-fixes).
  - drm/amd/pm: Disable MMIO access during SMU Mode 1 reset
    (stable-fixes).
  - HID: intel-ish-hid: Reset enum_devices_done before enumeration
    (stable-fixes).
  - HID: intel-ish-hid: Update ishtp bus match to support device
    ID table (stable-fixes).
  - HID: playstation: Center initial joystick axes to prevent
    spurious events (stable-fixes).
  - gpiolib-acpi: Update file references in the Documentation and
    MAINTAINERS (git-fixes).
  - commit bfdede0
  - PCI: qcom: Remove ASPM L0s support for MSM8996 SoC (git-fixes).
  - PCI/ERR: Ensure error recoverability at all times (git-fixes).
  - commit 64dc0df
  - ALSA: hda/realtek: Add quirk for Acer Nitro AN517-55
    (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-realtek-Enable-headset-mic-for-Acer-Nitro-5.patch.
  - commit dcc35f0
  - Documentation: PCI: endpoint: Fix ntb/vntb copy & paste errors
    (git-fixes).
  - ASoC: amd: drop unused Kconfig symbols (git-fixes).
  - ASoC: pxa: drop unused Kconfig symbol (git-fixes).
  - ASoC: SOF: ipc4-control: Keep the payload size up to date
    (git-fixes).
  - ASoC: SOF: ipc4-control: Use the correct size for
    scontrol->ipc_control_data (git-fixes).
  - ASoC: SOF: ipc4-topology: Correct the allocation size for
    bytes controls (git-fixes).
  - ASoC: SOF: ipc4-control: If there is no data do not send bytes
    update (git-fixes).
  - bus: fsl-mc: fix an error handling in fsl_mc_device_add()
    (git-fixes).
  - bus: omap-ocp2scp: fix OF populate on driver rebind (git-fixes).
  - clk: qcom: Return correct error code in qcom_cc_probe_by_index()
    (git-fixes).
  - ALSA: hda/realtek: Really fix headset mic for TongFang X6AR55xU
    (git-fixes).
  - ALSA: hda/realtek: ALC269 fixup for Lenovo Yoga Book 9i 13IRU8
    audio (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic for TongFang X6AR55xU
    (stable-fixes).
  - ASoC: tlv320adcx140: Propagate error codes during probe
    (stable-fixes).
  - ASoC: amd: yc: Fix microphone on ASUS M6500RE (stable-fixes).
  - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
    (stable-fixes).
  - ASoC: simple-card-utils: Check device node before overwrite
    direction (stable-fixes).
  - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
    (stable-fixes).
  - ALSA: hda/realtek: enable woofer speakers on Medion NM14LNL
    (stable-fixes).
  - drm/xe/pm: Also avoid missing outer rpm warning on system
    suspend (stable-fixes).
  - commit 85b3e2d
  - nvme-tcp: fix NULL pointer dereferences in
    nvmet_tcp_build_pdu_iovec (CVE-2026-22998 bsc#1257209).
  - commit f6350b1
  - KVM: x86/mmu: Embed direct bits into gpa for KVM_PRE_FAULT_MEMORY (git-fixes).
  - commit 75ad287
  - Revert "KVM: x86/tdp_mmu: Add a helper function to walk down the TDP  MMU" (git-fixes).
  - commit cbd54f0
  - KVM: x86/mmu: WARN if KVM attempts to map into an invalid TDP MMU  root (git-fixes).
  - commit db82a28
  - KVM: x86/mmu: Add dedicated API to map guest_memfd pfn into TDP MMU (git-fixes).
  - commit 7bbdb3d
  - KVM: Rename kvm_arch_vcpu_async_ioctl() to kvm_arch_vcpu_unlocked_ioctl() (git-fixes).
  - commit cc287ee
  - KVM: Make support for kvm_arch_vcpu_async_ioctl() mandatory (git-fixes).
  - commit e9d19b9
  - KVM: TDX: Drop PROVE_MMU=y sanity check on to-be-populated mappings (git-fixes).
  - commit 0739547
  - KVM: TDX: Replace kmalloc + copy_from_user with memdup_user in tdx_td_init() (git-fixes).
  - commit ff33194
  - x86/virt/tdx: Use precalculated TDVPR page physical address (git-fixes).
  - commit 3fdc23e

++++ kernel-rt:

  - KABI: fix
    "Revert-dm-fix-a-race-condition-in-retrieve_deps.patch"
    (git-fixes).
  - commit 53fd79b
  - net/sched: act_ife: avoid possible NULL deref (CVE-2026-23064
    bsc#1257765).
  - selftests/tc-testing: Try to add teql as a child qdisc
    (CVE-2026-23105 bsc#1257775).
  - net/sched: qfq: Use cl_is_active to determine whether class
    is active in qfq_rm_from_ag (CVE-2026-23105 bsc#1257775).
  - commit 3ff4470
  - Revert "dm: fix a race condition in retrieve_deps" (git-fixes).
  - commit e64c40a
  - Refresh sorted patches.
  - commit 3b39938
  - RISC-V: KVM: use kvm_trylock_all_vcpus when locking all vCPUs (git-fixes).
  - commit 292c30b
  - KVM: arm64: use kvm_trylock_all_vcpus when locking all vCPUs (git-fixes).
  - commit 45ee0a5
  - KVM: add kvm_lock_all_vcpus and kvm_trylock_all_vcpus (git-fixes).
  - commit f8807d7
  - x86: KVM: SVM: use kvm_lock_all_vcpus instead of a custom implementation (git-fixes).
  - commit 27b7fd9
  - locking/mutex: implement mutex_lock_killable_nest_lock (git-fixes).
  - commit c11266f
  - locking/mutex: implement mutex_trylock_nested (git-fixes).
  - commit 4df10c6
  - KVM: TDX: Use struct_size to simplify tdx_get_capabilities() (git-fixes).
  - commit 1f75b03
  - KVM: TDX: Check size of user's kvm_tdx_capabilities array before allocating (git-fixes).
  - commit 319fd02
  - KVM: TDX: Fix sparse warnings from using 0 for NULL (git-fixes).
  - commit 3438716
  - KVM: TDX: Remove __user annotation from kernel pointer (git-fixes).
  - commit f5a4acb
  - KVM: TDX: Take MMU lock around tdh_vp_init() (git-fixes).
  - commit 3b6a5f3
  - KVM: TDX: Fix list_add corruption during vcpu_load() (git-fixes).
  - commit fcf6177
  - KVM: TDX: Bug the VM if extending the initial measurement fails (git-fixes).
  - commit 056ce6c
  - KVM: TDX: Guard VM state transitions with "all" the locks (git-fixes).
  - commit 6fc029e
  - KVM: TDX: Don't copy "cmd" back to userspace for KVM_TDX_CAPABILITIES (git-fixes).
  - commit a1cf957
  - KVM: TDX: Use guard() to acquire kvm->lock in tdx_vm_ioctl() (git-fixes).
  - commit 53cbd86
  - KVM: TDX: Convert INIT_MEM_REGION and INIT_VCPU to "unlocked" vCPU ioctl (git-fixes).
  - commit 33e9280
  - KVM: TDX: Add tdx_get_cmd() helper to get and validate sub-ioctl command (git-fixes).
  - commit db2e487
  - KVM: TDX: Add macro to retry SEAMCALLs when forcing vCPUs out of  guest (git-fixes).
  - commit f789249
  - KVM: TDX: Assert that mmu_lock is held for write when removing S-EPT  entries (git-fixes).
  - commit 5c9b28f
  - KVM: TDX: Derive error argument names from the local variable names (git-fixes).
  - commit e750b72
  - KVM: TDX: Combine KVM_BUG_ON + pr_tdx_error() into TDX_BUG_ON() (git-fixes).
  - commit d2a9d32
  - KVM: TDX: Fold tdx_sept_zap_private_spte() into tdx_sept_remove_private_spte() (git-fixes).
  - commit 8fa4208
  - KVM: TDX: ADD pages to the TD image while populating mirror EPT entries (git-fixes).
  - commit 05e82a8
  - KVM: TDX: Fold tdx_mem_page_record_premap_cnt() into its sole caller (git-fixes).
  - commit cc267d2
  - KVM: TDX: Use atomic64_dec_return() instead of a poor equivalent (git-fixes).
  - commit 794f48a
  - KVM: TDX: Avoid a double-KVM_BUG_ON() in tdx_sept_zap_private_spte() (git-fixes).
  - commit 8899368
  - KVM: TDX: WARN if mirror SPTE doesn't have full RWX when creating S-EPT mapping (git-fixes).
  - commit d132554
  - KVM: x86/mmu: Drop the return code from kvm_x86_ops.remove_external_spte() (git-fixes).
  - commit 2570719
  - KVM: TDX: Fold tdx_sept_drop_private_spte() into tdx_sept_remove_private_spte() (git-fixes).
  - commit 83ec6b9
  - KVM: TDX: Return -EIO, not -EINVAL, on a KVM_BUG_ON() condition (git-fixes).
  - commit ebb64f7
  - KVM: TDX: Drop superfluous page pinning in S-EPT management (git-fixes).
  - commit 5eced3b
  - KVM: x86/mmu: Rename kvm_tdp_map_page() to kvm_tdp_page_prefault() (git-fixes).
  - commit 11c9e24
  - KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (bsc#1256708, CVE-2025-71104).
  - commit 8d2aab2
  - migrate: correct lock ordering for hugetlb file folios
    (CVE-2026-23097 bsc#1257815).
  - commit 30b8633
  - vsock/virtio: Coalesce only linear skb (bsc#1257740, CVE-2026-23057).
  - commit 310c89d
  - wifi: ath10k: sdio: add missing lock protection in
    ath10k_sdio_fw_crashed_dump() (git-fixes).
  - wifi: ath9k: fix kernel-doc warnings in common-debug.h
    (git-fixes).
  - wifi: ath9k: debug.h: fix kernel-doc bad lines and struct
    ath_tx_stats (git-fixes).
  - wifi: cfg80211: stop NAN and P2P in cfg80211_leave (git-fixes).
  - wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add
    (git-fixes).
  - wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon()
    (git-fixes).
  - wifi: cfg80211: Fix use_for flag update on BSS refresh
    (git-fixes).
  - PCI: mediatek: Fix IRQ domain leak when MSI allocation fails
    (git-fixes).
  - PCI: dwc: Fix msg_atu_index assignment (git-fixes).
  - Revert "PCI: qcom: Enable MSI interrupts together with Link
    up if 'Global IRQ' is supported" (stable-fixes).
  - PCI: Add ACS quirk for Pericom PI7C9X2G404 switches [12d8:b404]
    (git-fixes).
  - PCI: Fix pci_slot_trylock() error handling (git-fixes).
  - PCI: Use resource_set_range() that correctly sets ->end
    (git-fixes).
  - PCI/portdrv: Fix potential resource leak (git-fixes).
  - PCI/PM: Avoid redundant delays on D3hot->D3cold (git-fixes).
  - PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page()
    fails (git-fixes).
  - PCI/IOV: Fix race between SR-IOV enable/disable and hotplug
    (git-fixes).
  - Revert "PCI/IOV: Add PCI rescan-remove locking when
    enabling/disabling SR-IOV" (git-fixes).
  - PCI/ACPI: Restrict program_hpx_type2() to AER bits (git-fixes).
  - PCI: Initialize RCB from pci_configure_device() (git-fixes).
  - PCI: Check parent for NULL in of_pci_bus_release_domain_nr()
    (git-fixes).
  - PCI: Mark 3ware-9650SA Root Port Extended Tags as broken
    (git-fixes).
  - PCI: Do not attempt to set ExtTag for VFs (git-fixes).
  - PCI: endpoint: Fix swapped parameters in
    pci_{primary/secondary}_epc_epf_unlink() functions (git-fixes).
  - PCI: endpoint: Avoid creating sub-groups asynchronously
    (git-fixes).
  - regulator: core: move supply check earlier in
    set_machine_constraints() (git-fixes).
  - regulator: core: fix locking in regulator_resolve_supply()
    error path (git-fixes).
  - platform/chrome: cros_ec_lightbar: Fix response size
    initialization (git-fixes).
  - platform/chrome: cros_typec_switch: Don't touch struct
    fwnode_handle::dev (git-fixes).
  - soc: rockchip: grf: Support multiple grf to be handled
    (git-fixes).
  - soc: rockchip: grf: Fix wrong RK3576_IOCGRF_MISC_CON definition
    (git-fixes).
  - reset: gpio: suppress bind attributes in sysfs (git-fixes).
  - soc: mediatek: svs: Fix memory leak in svs_enable_debug_write()
    (git-fixes).
  - soc: qcom: cmd-db: Use devm_memremap() to fix memory leak in
    cmd_db_dev_probe (git-fixes).
  - soc: qcom: smem: handle ENOMEM error during probe (git-fixes).
  - soc: ti: pruss: Fix double free in pruss_clk_mux_setup()
    (git-fixes).
  - soc: ti: k3-socinfo: Fix regmap leak on probe failure
    (git-fixes).
  - spi: hisi-kunpeng: Fixed the wrong debugfs node name in hisi_spi
    debugfs initialization (stable-fixes).
  - regmap: maple: free entry on mas_store_gfp() failure
    (stable-fixes).
  - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt
    twice (stable-fixes).
  - wifi: mac80211: correctly check if CSA is active (stable-fixes).
  - wifi: cfg80211: Fix bitrate calculation overflow for HE rates
    (stable-fixes).
  - wifi: mac80211: collect station statistics earlier when
    disconnect (stable-fixes).
  - wifi: mac80211: ocb: skip rx_no_sta when interface is not joined
    (stable-fixes).
  - wifi: wlcore: ensure skb headroom before skb_push
    (stable-fixes).
  - commit 6474bb4
  - nfc: hci: shdlc: Stop timers and work before freeing context
    (git-fixes).
  - of: unittest: fix possible null-pointer dereferences in
    of_unittest_property_copy() (git-fixes).
  - media: uvcvideo: Fix allocation for small frame sizes
    (git-fixes).
  - media: verisilicon: AV1: Fix tile info buffer size (git-fixes).
  - media: venus: vdec: restrict EOS addr quirk to IRIS2 only
    (git-fixes).
  - media: venus: vdec: fix error state assignment for zero
    bytesused (git-fixes).
  - media: i2c: ov01a10: Fix digital gain range (git-fixes).
  - media: stm32: dcmipp: bytecap: clear all interrupts upon stream
    stop (git-fixes).
  - media: ccs: Accommodate C-PHY into the calculation (git-fixes).
  - media: ipu6: Fix RPM reference leak in probe error paths
    (git-fixes).
  - media: ipu6: Fix typo and wrong constant in ipu6-mmu.c
    (git-fixes).
  - media: dw9714: Fix powerup sequence (git-fixes).
  - media: i2c: ov5647: use our own mutex for the ctrl lock
    (git-fixes).
  - media: ccs: Fix setting initial sub-device state (git-fixes).
  - media: i2c: ov5647: Fix PIXEL_RATE value for VGA mode
    (git-fixes).
  - media: i2c: ov5647: Sensor should report RAW color space
    (git-fixes).
  - media: i2c: ov5647: Correct minimum VBLANK value (git-fixes).
  - media: i2c: ov5647: Correct pixel array offset (git-fixes).
  - media: i2c: ov5647: Initialize subdev before controls
    (git-fixes).
  - media: ccs: Avoid possible division by zero (git-fixes).
  - media: qcom: camss: vfe: Fix out-of-bounds access in
    vfe_isr_reg_update() (git-fixes).
  - media: i2c: ov01a10: Fix test-pattern disabling (git-fixes).
  - media: i2c: ov01a10: Fix passing stream instead of pad to
    v4l2_subdev_state_get_format() (git-fixes).
  - media: i2c: ov01a10: Add missing v4l2_subdev_cleanup() calls
    (git-fixes).
  - media: i2c: ov01a10: Fix analogue gain range (git-fixes).
  - media: i2c: ov01a10: Fix reported pixel-rate value (git-fixes).
  - media: i2c: ov01a10: Fix the horizontal flip control
    (git-fixes).
  - media: i2c/tw9906: Fix potential memory leak in tw9906_probe()
    (git-fixes).
  - media: i2c/tw9903: Fix potential memory leak in tw9903_probe()
    (git-fixes).
  - media: cx25821: Add missing unmap in snd_cx25821_hw_params()
    (git-fixes).
  - media: cx23885: Add missing unmap in snd_cx23885_hw_params()
    (git-fixes).
  - media: cx88: Add missing unmap in snd_cx88_hw_params()
    (git-fixes).
  - media: radio-keene: fix memory leak in error path (git-fixes).
  - media: tegra-video: Fix memory leak in
    __tegra_channel_try_format() (git-fixes).
  - media: verisilicon: AV1: Set IDR flag for intra_only frame type
    (git-fixes).
  - media: rockchip: rga: Fix possible ERR_PTR dereference in
    rga_buf_init() (git-fixes).
  - media: amphion: Drop min_queued_buffers assignment (git-fixes).
  - media: verisilicon: AV1: Fix tx mode bit setting (git-fixes).
  - media: verisilicon: AV1: Fix enable cdef computation
    (git-fixes).
  - media: chips-media: wave5: Fix memory leak on codec_info
    allocation failure (git-fixes).
  - media: chips-media: wave5: Fix device cleanup order to prevent
    kernel panic (git-fixes).
  - media: chips-media: wave5: Fix kthread worker destruction in
    polling mode (git-fixes).
  - media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove()
    (git-fixes).
  - media: mtk-mdp: Fix error handling in probe function
    (git-fixes).
  - media: mediatek: encoder: Fix uninitialized scalar variable
    issue (git-fixes).
  - HID: intel-ish-hid: fix NULL-ptr-deref in
    ishtp_bus_remove_all_clients (git-fixes).
  - HID: hid-pl: handle probe errors (git-fixes).
  - HID: playstation: Add missing check for input_ff_create_memless
    (git-fixes).
  - hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler
    optimization induced race (git-fixes).
  - memory: mtk-smi: fix device leak on larb probe (git-fixes).
  - memory: mtk-smi: fix device leaks on common probe (git-fixes).
  - HID: logitech: add HID++ support for Logitech MX Anywhere 3S
    (stable-fixes).
  - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30
    (2d99:a101) (stable-fixes).
  - HID: i2c-hid: fix potential buffer overflow in
    i2c_hid_get_report() (stable-fixes).
  - HID: quirks: Add another Chicony HP 5MP Cameras to
    hid_ignore_list (stable-fixes).
  - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL
    (stable-fixes).
  - net: usb: sr9700: support devices with virtual driver CD
    (stable-fixes).
  - commit 2d30005
  - scsi: qla2xxx: edif: Fix dma_free_coherent() size (git-fixes).
  - scsi: qla2xxx: Sanitize payload size to prevent member overflow
    (git-fixes).
  - scsi: qla2xxx: Enable/disable IRQD_NO_BALANCING during reset
    (git-fixes).
  - scsi: qla2xxx: target: Improve safety of cmd lookup by handle
    (git-fixes).
  - scsi: qla2xxx: target: Add back SRR support (git-fixes).
  - scsi: qla2xxx: target: Improve cmd logging (git-fixes).
  - scsi: qla2xxx: target: Add cmd->rsp_sent (git-fixes).
  - scsi: qla2xxx: target: Fix invalid memory access with big CDBs
    (git-fixes).
  - scsi: qla2xxx: Fix TMR failure handling (git-fixes).
  - scsi: qla2xxx: target: Improve checks in qlt_xmit_response()
    / qlt_rdy_to_xfer() (git-fixes).
  - scsi: qla2xxx: target: Fix races with aborting commands
    (git-fixes).
  - scsi: qla2xxx: Clear cmds after chip reset (CVE-2025-68745
    bsc#1255721 git-fixes).
  - scsi: qla2xxx: target: Fix term exchange when cmd_sent_to_fw ==
    1 (git-fixes).
  - scsi: qla2xxx: target: Improve debug output for term exchange
    (git-fixes).
  - scsi: qla2xxx: target: Remove code for unsupported hardware
    (git-fixes).
  - scsi: qla2xxx: Use reinit_completion on mbx_intr_comp
    (git-fixes).
  - scsi: qla2xxx: Fix lost interrupts with qlini_mode=disabled
    (git-fixes).
  - scsi: qla2xxx: Fix initiator mode with qlini_mode=exclusive
    (git-fixes).
  - scsi: Revert "scsi: qla2xxx: Perform lockless command completion
    in abort path" (git-fixes).
  - commit c2959d9
  - drm/xe: Unregister drm device on probe error (git-fixes).
  - drm/msm/a2xx: fix pixel shader start on A225 (git-fixes).
  - drm/msm/dpu: fix CMD panels on DPU 1.x - 3.x (git-fixes).
  - drm/msm/dpu: drop intr_start from DPU 3.x catalog files
    (git-fixes).
  - drm/msm/disp: set num_planes to 1 for interleaved YUV formats
    (git-fixes).
  - drm/msm/dpu: fix WD timer handling on DPU 8.x (git-fixes).
  - drm/msm/dpu: Set vsync source irrespective of mdp top support
    (git-fixes).
  - drm/bridge: anx7625: Fix invalid EDID size (git-fixes).
  - drm/buddy: Prevent BUG_ON by validating rounded allocation
    (git-fixes).
  - drm/tegra: dsi: fix device leak on probe (git-fixes).
  - drm/amdkfd: Fix signal_eviction_fence() bool return value
    (git-fixes).
  - drm/amd: Drop "amdgpu kernel modesetting enabled" message
    (git-fixes).
  - drm/tests: shmem: Swap names of export tests (git-fixes).
  - drm/panthor: Evict groups before VM termination (git-fixes).
  - drm/panel: sw43408: Remove manual invocation of unprepare at
    remove (git-fixes).
  - drm/panthor: Make sure we resume the tick when new jobs are
    submitted (git-fixes).
  - drm/panthor: Fix the logic that decides when to stop ticking
    (git-fixes).
  - drm/panthor: Fix immediate ticking on a disabled tick
    (git-fixes).
  - drm/panthor: Fix the group priority rotation logic (git-fixes).
  - drm/panthor: Fix the full_tick check (git-fixes).
  - drm/panthor: Recover from panthor_gpu_flush_caches() failures
    (git-fixes).
  - firmware: arm_ffa: Correct 32-bit response handling in
    NOTIFICATION_INFO_GET (git-fixes).
  - drm/xe/pm: Disable D3Cold for BMG only on specific platforms
    (git-fixes).
  - drm/amd/pm: Disable MMIO access during SMU Mode 1 reset
    (stable-fixes).
  - HID: intel-ish-hid: Reset enum_devices_done before enumeration
    (stable-fixes).
  - HID: intel-ish-hid: Update ishtp bus match to support device
    ID table (stable-fixes).
  - HID: playstation: Center initial joystick axes to prevent
    spurious events (stable-fixes).
  - gpiolib-acpi: Update file references in the Documentation and
    MAINTAINERS (git-fixes).
  - commit bfdede0
  - PCI: qcom: Remove ASPM L0s support for MSM8996 SoC (git-fixes).
  - PCI/ERR: Ensure error recoverability at all times (git-fixes).
  - commit 64dc0df
  - ALSA: hda/realtek: Add quirk for Acer Nitro AN517-55
    (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-realtek-Enable-headset-mic-for-Acer-Nitro-5.patch.
  - commit dcc35f0
  - Documentation: PCI: endpoint: Fix ntb/vntb copy & paste errors
    (git-fixes).
  - ASoC: amd: drop unused Kconfig symbols (git-fixes).
  - ASoC: pxa: drop unused Kconfig symbol (git-fixes).
  - ASoC: SOF: ipc4-control: Keep the payload size up to date
    (git-fixes).
  - ASoC: SOF: ipc4-control: Use the correct size for
    scontrol->ipc_control_data (git-fixes).
  - ASoC: SOF: ipc4-topology: Correct the allocation size for
    bytes controls (git-fixes).
  - ASoC: SOF: ipc4-control: If there is no data do not send bytes
    update (git-fixes).
  - bus: fsl-mc: fix an error handling in fsl_mc_device_add()
    (git-fixes).
  - bus: omap-ocp2scp: fix OF populate on driver rebind (git-fixes).
  - clk: qcom: Return correct error code in qcom_cc_probe_by_index()
    (git-fixes).
  - ALSA: hda/realtek: Really fix headset mic for TongFang X6AR55xU
    (git-fixes).
  - ALSA: hda/realtek: ALC269 fixup for Lenovo Yoga Book 9i 13IRU8
    audio (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic for TongFang X6AR55xU
    (stable-fixes).
  - ASoC: tlv320adcx140: Propagate error codes during probe
    (stable-fixes).
  - ASoC: amd: yc: Fix microphone on ASUS M6500RE (stable-fixes).
  - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe
    (stable-fixes).
  - ASoC: simple-card-utils: Check device node before overwrite
    direction (stable-fixes).
  - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk
    (stable-fixes).
  - ALSA: hda/realtek: enable woofer speakers on Medion NM14LNL
    (stable-fixes).
  - drm/xe/pm: Also avoid missing outer rpm warning on system
    suspend (stable-fixes).
  - commit 85b3e2d
  - nvme-tcp: fix NULL pointer dereferences in
    nvmet_tcp_build_pdu_iovec (CVE-2026-22998 bsc#1257209).
  - commit f6350b1
  - KVM: x86/mmu: Embed direct bits into gpa for KVM_PRE_FAULT_MEMORY (git-fixes).
  - commit 75ad287
  - Revert "KVM: x86/tdp_mmu: Add a helper function to walk down the TDP  MMU" (git-fixes).
  - commit cbd54f0
  - KVM: x86/mmu: WARN if KVM attempts to map into an invalid TDP MMU  root (git-fixes).
  - commit db82a28
  - KVM: x86/mmu: Add dedicated API to map guest_memfd pfn into TDP MMU (git-fixes).
  - commit 7bbdb3d
  - KVM: Rename kvm_arch_vcpu_async_ioctl() to kvm_arch_vcpu_unlocked_ioctl() (git-fixes).
  - commit cc287ee
  - KVM: Make support for kvm_arch_vcpu_async_ioctl() mandatory (git-fixes).
  - commit e9d19b9
  - KVM: TDX: Drop PROVE_MMU=y sanity check on to-be-populated mappings (git-fixes).
  - commit 0739547
  - KVM: TDX: Replace kmalloc + copy_from_user with memdup_user in tdx_td_init() (git-fixes).
  - commit ff33194
  - x86/virt/tdx: Use precalculated TDVPR page physical address (git-fixes).
  - commit 3fdc23e

++++ libpng16:

  - added patches
    CVE-2026-25646: Heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020)
    * libpng16-CVE-2026-25646.patch

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to version 580.126.18 (boo#1258154)
  - updated CUDA variant to version 580.126.16

------------------------------------------------------------------
------------------  2026-2-11  -  Feb 11 2026  -------------------
------------------------------------------------------------------

++++ gpg2:

  - Fix Y2K38 FTBFS:
    * gpg2 quick-key-manipulation test FTBFS-2038 (bsc#1251214)
    * Upstream issue: dev.gnupg.org/T8096
    * Add gnupg-gpgscm-New-operator-long-time-t-to-detect-proper-tim.patch

++++ grub2:

  - Backport upstream's commit to prevent BIOS assert (bsc#1258022)
    * 0001-kern-efi-mm-Change-grub_efi_mm_add_regions-to-keep-t.patch

++++ kernel-default:

  - KVM/TDX: Explicitly do WBINVD when no more TDX SEAMCALLs (git-fixes).
  - commit b53af4c
  - mm/page_alloc: change all pageblocks migrate type on coalescing
    (CVE-2025-71134 bsc#1256732).
  - commit 3036351
  - ktls, sockmap: Fix missing uncharge operation (bsc#1252008).
  - commit 55dd0a8
  - net/sched: Enforce that teql can only be used as root qdisc
    (CVE-2026-23074 bsc#1257749).
  - commit 4a5b062
  - media: pci: mg4b: Use IRQF_NO_THREAD (git-fixes).
  - mfd: wm8350-core: Use IRQF_ONESHOT (git-fixes).
  - Bluetooth: btintel_pcie: Use IRQF_ONESHOT and default primary
    handler (git-fixes).
  - platform/x86: int0002: Remove IRQF_ONESHOT from request_irq()
    (git-fixes).
  - genirq: Set IRQF_COND_ONESHOT in devm_request_irq() (git-fixes).
  - crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists
    correctly (git-fixes).
  - crypto: starfive - Fix memory leak in
    starfive_aes_aead_do_one_req() (git-fixes).
  - crypto: caam - fix netdev memory leak in dpaa2_caam_probe
    (git-fixes).
  - crypto: hisilicon/trng - support tfms sharing the device
    (git-fixes).
  - crypto: virtio - Remove duplicated virtqueue_kick in
    virtio_crypto_skcipher_crypt_req (git-fixes).
  - crypto: virtio - Add spinlock protection with virtqueue
    notification (git-fixes).
  - crypto: hisilicon/sec2 - support skcipher/aead fallback for
    hardware queue unavailable (git-fixes).
  - crypto: hisilicon/zip - adjust the way to obtain the req in
    the callback function (git-fixes).
  - crypto: octeontx - fix dma_free_coherent() size (git-fixes).
  - crypto: cavium - fix dma_free_coherent() size (git-fixes).
  - crypto: iaa - Fix out-of-bounds index in
    find_empty_iaa_compression_mode (git-fixes).
  - crypto: octeontx - Fix length check to avoid truncation in
    ucode_load_store (git-fixes).
  - crypto: qat - fix warning on adf_pfvf_pf_proto.c (git-fixes).
  - crypto: qat - fix parameter order used in
    ICP_QAT_FW_COMN_FLAGS_BUILD (git-fixes).
  - Documentation: mailbox: mbox_chan_ops.flush() is optional
    (git-fixes).
  - platform/x86: hp-bioscfg: Skip empty attribute names
    (git-fixes).
  - commit 4559d68

++++ kernel-rt:

  - KVM/TDX: Explicitly do WBINVD when no more TDX SEAMCALLs (git-fixes).
  - commit b53af4c
  - mm/page_alloc: change all pageblocks migrate type on coalescing
    (CVE-2025-71134 bsc#1256732).
  - commit 3036351
  - ktls, sockmap: Fix missing uncharge operation (bsc#1252008).
  - commit 55dd0a8
  - net/sched: Enforce that teql can only be used as root qdisc
    (CVE-2026-23074 bsc#1257749).
  - commit 4a5b062
  - media: pci: mg4b: Use IRQF_NO_THREAD (git-fixes).
  - mfd: wm8350-core: Use IRQF_ONESHOT (git-fixes).
  - Bluetooth: btintel_pcie: Use IRQF_ONESHOT and default primary
    handler (git-fixes).
  - platform/x86: int0002: Remove IRQF_ONESHOT from request_irq()
    (git-fixes).
  - genirq: Set IRQF_COND_ONESHOT in devm_request_irq() (git-fixes).
  - crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists
    correctly (git-fixes).
  - crypto: starfive - Fix memory leak in
    starfive_aes_aead_do_one_req() (git-fixes).
  - crypto: caam - fix netdev memory leak in dpaa2_caam_probe
    (git-fixes).
  - crypto: hisilicon/trng - support tfms sharing the device
    (git-fixes).
  - crypto: virtio - Remove duplicated virtqueue_kick in
    virtio_crypto_skcipher_crypt_req (git-fixes).
  - crypto: virtio - Add spinlock protection with virtqueue
    notification (git-fixes).
  - crypto: hisilicon/sec2 - support skcipher/aead fallback for
    hardware queue unavailable (git-fixes).
  - crypto: hisilicon/zip - adjust the way to obtain the req in
    the callback function (git-fixes).
  - crypto: octeontx - fix dma_free_coherent() size (git-fixes).
  - crypto: cavium - fix dma_free_coherent() size (git-fixes).
  - crypto: iaa - Fix out-of-bounds index in
    find_empty_iaa_compression_mode (git-fixes).
  - crypto: octeontx - Fix length check to avoid truncation in
    ucode_load_store (git-fixes).
  - crypto: qat - fix warning on adf_pfvf_pf_proto.c (git-fixes).
  - crypto: qat - fix parameter order used in
    ICP_QAT_FW_COMN_FLAGS_BUILD (git-fixes).
  - Documentation: mailbox: mbox_chan_ops.flush() is optional
    (git-fixes).
  - platform/x86: hp-bioscfg: Skip empty attribute names
    (git-fixes).
  - commit 4559d68

++++ libssh:

  - Update to 0.11.4:
    * Security fixes:
  - CVE-2026-0964: SCP Protocol Path Traversal in ssh_scp_pull_request()
    (bsc#1258049)
  - CVE-2026-0965: Possible Denial of Service when parsing unexpected
    configuration files (bsc#1258045)
  - CVE-2026-0966: Buffer underflow in ssh_get_hexa() on invalid input
    (bsc#1258054)
  - CVE-2026-0967: Specially crafted patterns could cause DoS (bsc#1258081)
  - CVE-2026-0968: OOB Read in sftp_parse_longname() (bsc#1258080)
  - libssh-2026-sftp-extensions: Read buffer overrun when handling SFTP extensions
    * Other fixes:
  - Stability and compatibility improvements of ProxyJump
    * Remove patch upstream: libssh-cmake-Add-option-WITH_HERMETIC_USR.patch

++++ mdadm:

  - Update to version 4.4+37.gea219956:
  - Backport upstream fixes from 4.5 (bsc#1257009)
    * Re-enable mdadm --monitor ... for /dev/mdX
    * Allow RAID0 to be created with v0.90 metadata
    * Moves memory management into Assemble to avoid null pointer dereference
    * Support non-absolute name during monitor scan
    * Don't set badblock flag when adding a new disk
    * Fix metadata corruption when managing new imsm array

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20260210 release (bsc#1258046)
  - CVE-2024-24853: Updated fix for incorrect behavior order in transition
    between executive monitor and SMI transfer monitor (STM) in some Intel(R)
    Processor may allow a privileged user to potentially enable escalation
    of privilege via local access. (bsc#1229129)
  - CVE-2025-31648: Improper handling of values in the
    microcode flow for some Intel Processor Family may allow
    an escalation of privilege. (bsc#1258046 INTEL-SA-01396
    https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01396.html)
  - Update for various functional issues.
  - Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ADL            | C0       | 06-97-02/07 | 0000003d | 0000003e | Core Gen12
    | ADL            | H0       | 06-97-05/07 | 0000003d | 0000003e | Core Gen12
    | ADL            | L0       | 06-9a-03/80 | 0000043a | 0000043b | Core Gen12
    | ADL            | R0       | 06-9a-04/80 | 0000043a | 0000043b | Core Gen12
    | ADL-N          | N0       | 06-be-00/19 | 0000001e | 00000021 | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    | ARL-H          | A1       | 06-c5-02/82 | 0000011a | 0000011b | Core Ultra Processor (Series 2)
    | ARL-S/HX (8P)  | B0       | 06-c6-02/82 | 0000011a | 0000011b | Core Ultra Processor (Series 2)
    | ARL-U          | A0       | 06-b5-00/80 | 0000000a | 0000000d | Core Ultra Processor (Series 2)
    | AZB            | A0/R0    | 06-9a-04/40 | 0000000b | 0000000c | Atom C1100
    | EMR-SP         | A1       | 06-cf-02/87 | 210002c0 | 210002d3 | Xeon Scalable Gen5
    | GNR-AP/SP      | Bx/Hx/Lx | 06-ad-01/95 | 010003f0 | 01000405 | Xeon 6900/6700/6500 Series Processors with P-Cores
    | GNR-D          | B0/B1    | 06-ae-01/97 | 01000273 | 010002f3 | Xeon 6700P-B/6500P-B Series SoC with P-Cores
    | GNR-SP R1S     | Bx/Hx/Lx | 06-ad-01/20 | 0a000124 | 0a000133 | Xeon 6700/6500-Series Processors with P-Cores
    | ICL-D          | B0       | 06-6c-01/10 | 010002e0 | 010002f1 | Xeon D-17xx, D-27xx
    | ICL-U/Y        | D1       | 06-7e-05/80 | 000000ca | 000000cc | Core Gen10 Mobile
    | ICX-SP         | Dx/M1    | 06-6a-06/87 | 0d000410 | 0d000421 | Xeon Scalable Gen3
    | MTL            | C0       | 06-aa-04/e6 | 00000025 | 00000028 | Core Ultra Processor
    | RKL-S          | B0       | 06-a7-01/02 | 00000064 | 00000065 | Core Gen11
    | RPL-E/HX/S     | B0       | 06-b7-01/32 | 00000132 | 00000133 | Core Gen13/Gen14
    | RPL-H/P/PX 6+8 | J0       | 06-ba-02/e0 | 00006133 | 00006134 | Core Gen13
    | RPL-HX/S       | C0       | 06-bf-02/07 | 0000003d | 0000003e | Core Gen13/Gen14
    | RPL-S          | H0       | 06-bf-05/07 | 0000003d | 0000003e | Core Gen13/Gen14
    | RPL-U 2+8      | Q0       | 06-ba-03/e0 | 00006133 | 00006134 | Core Gen13
    | SPR-HBM        | Bx       | 06-8f-08/10 | 2c000410 | 2c000421 | Xeon Max
    | SPR-SP         | E4/S2    | 06-8f-07/87 | 2b000650 | 2b000661 | Xeon Scalable Gen4
    | SPR-SP         | E5/S3    | 06-8f-08/87 | 2b000650 | 2b000661 | Xeon Scalable Gen4
    | TGL            | B0/B1    | 06-8c-01/80 | 000000bc | 000000be | Core Gen11 Mobile
    | TGL-H          | R0       | 06-8d-01/c2 | 00000056 | 00000058 | Core Gen11 Mobile
    | TGL-R          | C0       | 06-8c-02/c2 | 0000003c | 0000003e | Core Gen11 Mobile
    | TWL            | N0       | 06-be-00/19 | 0000001e | 00000021 | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E

------------------------------------------------------------------
------------------  2026-2-10  -  Feb 10 2026  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20260210.ecce285:
    * For boo#1257875 get intrinsic DEFAULT_WM back
    * DIR_COLORS: add vt220 and .jxl

++++ ca-certificates-mozilla:

  - Updated to 2.84 state (bsc#1258002)
  - Removed:
  - Baltimore CyberTrust Root
  - CommScope Public Trust ECC Root-01
  - CommScope Public Trust ECC Root-02
  - CommScope Public Trust RSA Root-01
  - CommScope Public Trust RSA Root-02
  - DigiNotar Root CA
  - Added:
  - e-Szigno TLS Root CA 2023
  - OISTE Client Root ECC G1
  - OISTE Client Root RSA G1
  - OISTE Server Root ECC G1
  - OISTE Server Root RSA G1
  - SwissSign RSA SMIME Root CA 2022 - 1
  - SwissSign RSA TLS Root CA 2022 - 1
  - TrustAsia SMIME ECC Root CA
  - TrustAsia SMIME RSA Root CA
  - TrustAsia TLS ECC Root CA
  - TrustAsia TLS RSA Root CA

++++ lvm2-device-mapper:

  - L3: LVM_SUPPRESS_FD_WARNINGS is no longer effective (bsc#1257661)
    * Add upstream patch
    + bug-1257661-libdaemon-fix-suppressing-stray-fd-warnings.patch

++++ gnutls:

  - Security fix:
    * CVE-2025-14831: DoS via excessive resource consumption during
    certificate verification (bsc#1257960)
    * Add gnutls-CVE-2025-14831.patch

++++ kernel-default:

  - phy: qcom-qusb2: Fix NULL pointer dereference on early suspend (bsc#1257686 CVE-2025-71193)
  - commit 19f0093
  - Octeontx2-af: Add proper checks for fwdata (bsc#1257709 CVE-2026-23070)
  - commit dea3240
  - irqchip/gic-v3-its: Avoid truncating memory addresses (bsc#1257758 CVE-2026-23085)
  - commit be35313
  - arm64/fpsimd: signal: Allocate SSVE storage when restoring ZA (bsc#1257762 CVE-2026-23107)
  - commit 19d7755
  - arm64/fpsimd: signal: Fix restoration of SVE context (bsc#1257772 CVE-2026-23102)
  - commit 1a38c1d
  - spi: spi-sprd-adi: Fix double free in probe error path (bsc#1257805 CVE-2026-23068)
  - commit 7304352
  - blacklist.conf: CVE-2025-68789 is invalid
  - Delete
    patches.suse/hwmon-ibmpex-fix-use-after-free-in-high-low-store.patch.
  - commit f8a3a89
  - net: tunnel: make skb_vlan_inet_prepare() return drop reasons
    (bsc#1257942 bsc#1257246 CVE-2026-23003).
  - commit 1cb88e2
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-check-in-IRQ-han.patch (git-fixes bsc#1257952)
  - commit d5bce4f
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-clearing-in-tegr.patch (git-fixes bsc#1257952)
  - commit 27b982c
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-in-tegra_qspi_co.patch (git-fixes bsc#1257952)
  - commit 98fc331
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-assignment-in-te.patch (git-fixes bsc#1257952)
  - commit bd0d13d
  - Update patches.suse/spi-tegra210-quad-Move-curr_xfer-read-inside-spinloc.patch (git-fixes bsc#1257952)
  - commit 1f60101
  - Update patches.suse/spi-tegra210-quad-Return-IRQ_HANDLED-when-timeout-al.patch (git-fixes bsc#1257952)
  - commit c2f4ce0
  - thermal: intel: x86_pkg_temp_thermal: Handle invalid temperature
    (git-fixes).
  - thermal/of: Fix reference leak in thermal_of_cm_lookup()
    (git-fixes).
  - OPP: Return correct value in dev_pm_opp_get_level (git-fixes).
  - PM: sleep: wakeirq: harden dev_pm_clear_wake_irq() against races
    (git-fixes).
  - PM: wakeup: Handle empty list in wakeup_sources_walk_start()
    (git-fixes).
  - ACPICA: Fix NULL pointer dereference in
    acpi_ev_address_space_dispatch() (git-fixes).
  - tpm: st33zp24: Fix missing cleanup on get_burstcount() error
    (git-fixes).
  - tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount()
    failure (git-fixes).
  - i3c: dw: Fix memory leak in dw_i3c_master_i2c_xfers()
    (git-fixes).
  - i3c: dw: Initialize spinlock to avoid upsetting lockdep
    (git-fixes).
  - i3c: master: Update hot-join flag only on success (git-fixes).
  - i3c: Move device name assignment after i3c_bus_init (git-fixes).
  - auxdisplay: arm-charlcd: fix release_mem_region() size
    (git-fixes).
  - OPP: OF: Fix an OF node leak in _opp_add_static_v2()
    (git-fixes).
  - commit 41b898f

++++ kernel-rt:

  - phy: qcom-qusb2: Fix NULL pointer dereference on early suspend (bsc#1257686 CVE-2025-71193)
  - commit 19f0093
  - Octeontx2-af: Add proper checks for fwdata (bsc#1257709 CVE-2026-23070)
  - commit dea3240
  - irqchip/gic-v3-its: Avoid truncating memory addresses (bsc#1257758 CVE-2026-23085)
  - commit be35313
  - arm64/fpsimd: signal: Allocate SSVE storage when restoring ZA (bsc#1257762 CVE-2026-23107)
  - commit 19d7755
  - arm64/fpsimd: signal: Fix restoration of SVE context (bsc#1257772 CVE-2026-23102)
  - commit 1a38c1d
  - spi: spi-sprd-adi: Fix double free in probe error path (bsc#1257805 CVE-2026-23068)
  - commit 7304352
  - blacklist.conf: CVE-2025-68789 is invalid
  - Delete
    patches.suse/hwmon-ibmpex-fix-use-after-free-in-high-low-store.patch.
  - commit f8a3a89
  - net: tunnel: make skb_vlan_inet_prepare() return drop reasons
    (bsc#1257942 bsc#1257246 CVE-2026-23003).
  - commit 1cb88e2
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-check-in-IRQ-han.patch (git-fixes bsc#1257952)
  - commit d5bce4f
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-clearing-in-tegr.patch (git-fixes bsc#1257952)
  - commit 27b982c
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-in-tegra_qspi_co.patch (git-fixes bsc#1257952)
  - commit 98fc331
  - Update patches.suse/spi-tegra210-quad-Protect-curr_xfer-assignment-in-te.patch (git-fixes bsc#1257952)
  - commit bd0d13d
  - Update patches.suse/spi-tegra210-quad-Move-curr_xfer-read-inside-spinloc.patch (git-fixes bsc#1257952)
  - commit 1f60101
  - Update patches.suse/spi-tegra210-quad-Return-IRQ_HANDLED-when-timeout-al.patch (git-fixes bsc#1257952)
  - commit c2f4ce0
  - thermal: intel: x86_pkg_temp_thermal: Handle invalid temperature
    (git-fixes).
  - thermal/of: Fix reference leak in thermal_of_cm_lookup()
    (git-fixes).
  - OPP: Return correct value in dev_pm_opp_get_level (git-fixes).
  - PM: sleep: wakeirq: harden dev_pm_clear_wake_irq() against races
    (git-fixes).
  - PM: wakeup: Handle empty list in wakeup_sources_walk_start()
    (git-fixes).
  - ACPICA: Fix NULL pointer dereference in
    acpi_ev_address_space_dispatch() (git-fixes).
  - tpm: st33zp24: Fix missing cleanup on get_burstcount() error
    (git-fixes).
  - tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount()
    failure (git-fixes).
  - i3c: dw: Fix memory leak in dw_i3c_master_i2c_xfers()
    (git-fixes).
  - i3c: dw: Initialize spinlock to avoid upsetting lockdep
    (git-fixes).
  - i3c: master: Update hot-join flag only on success (git-fixes).
  - i3c: Move device name assignment after i3c_bus_init (git-fixes).
  - auxdisplay: arm-charlcd: fix release_mem_region() size
    (git-fixes).
  - OPP: OF: Fix an OF node leak in _opp_add_static_v2()
    (git-fixes).
  - commit 41b898f

++++ kubevirt:

  - Update to version 1.7.0
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.7.0
    bsc#1241772 (CVE-2025-22872), bsc#1253181 (CVE-2025-64432),
    bsc#1253185 (CVE-2025-64433), bsc#1253186 (CVE-2025-64434),
    bsc#1253189 (CVE-2025-64435), bsc#1253194 (CVE-2025-64437),
    bsc#1253748 (CVE-2025-64324), bsc#1257128, bsc#1257422 (CVE-2024-45310)
    Drop Update-module-golang.org-x-oauth2-to-v0.27.0-SECURITY.patch and
    Update-module-golang.org-x-net-to-v0.38.0-SECURITY.patch
  - Upstream now uses stateless firmware for CoCo VMs. Drop
    Ensure-SEV-VMs-use-stateless-OVMF-firmware.patch

++++ lvm2:

  - L3: LVM_SUPPRESS_FD_WARNINGS is no longer effective (bsc#1257661)
    * Add upstream patch
    + bug-1257661-libdaemon-fix-suppressing-stray-fd-warnings.patch

++++ nvidia-open-driver-G06-signed:

  - kernel-6.19.patch: fixes build against kernel 6.19

------------------------------------------------------------------
------------------  2026-2-9  -  Feb 9 2026  -------------------
------------------------------------------------------------------

++++ grub2:

  - Fix error "grub-core/script/lexer.c:352:out of memory" after PowerPC CAS
    Reboot (bsc#1254299)
    * 0001-Fix-PowerPC-CAS-reboot-to-evaluate-menu-context.patch

++++ rust-keylime:

  - Update vendored crates (bsc#1257908, CVE-2026-25727)
    * time 0.3.47
  - Update to version 0.2.8+116:
    * build(deps): bump bytes from 1.7.2 to 1.11.1
    * api: Modify /version endpoint output in version 2.5
    * Add API v2.5 with backward-compatible /v2.5/quotes/integrity
    * tests: add unit test for resolve_agent_id (#1182)
    * (pull-model): enable retry logic for registration
    * rpm: Update specfiles to apply on master
    * workflows: Add test to detect unused crates
    * lib: Drop unused crates
    * push-model: Drop unused crates
    * keylime-agent: Drop unused crates
    * build(deps): bump uuid from 1.18.1 to 1.19.0
    * Update reqwest-retry to 0.8, retry-policies to 0.5
    * rpm: Fix cargo_build macro usage on CentOS Stream
    * fix(push-model): resolve hash_ek uuid to actual EK hash
    * build(deps): bump thiserror from 2.0.16 to 2.0.17
    * workflows: Separate upstream test suite from e2e coverage
    * Send UEFI measured boot logs as raw bytes (#1173)
    * auth: Add unit tests for SecretToken implementation
    * packit: Enable push-attestation tests
    * resilient_client: Prevent authentication token leakage in logs

------------------------------------------------------------------
------------------  2026-2-8  -  Feb 8 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - spi: tegra114: Preserve SPI mode bits in def_command1_reg
    (git-fixes).
  - spi: tegra: Fix a memory leak in tegra_slink_probe()
    (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer check in IRQ handler
    (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer clearing in
    tegra_qspi_non_combined_seq_xfer (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer in
    tegra_qspi_combined_seq_xfer (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer assignment in
    tegra_qspi_setup_transfer_one (git-fixes).
  - spi: tegra210-quad: Move curr_xfer read inside spinlock
    (git-fixes).
  - spi: tegra210-quad: Return IRQ_HANDLED when timeout already
    processed transfer (git-fixes).
  - commit 48bc42c

++++ kernel-rt:

  - spi: tegra114: Preserve SPI mode bits in def_command1_reg
    (git-fixes).
  - spi: tegra: Fix a memory leak in tegra_slink_probe()
    (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer check in IRQ handler
    (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer clearing in
    tegra_qspi_non_combined_seq_xfer (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer in
    tegra_qspi_combined_seq_xfer (git-fixes).
  - spi: tegra210-quad: Protect curr_xfer assignment in
    tegra_qspi_setup_transfer_one (git-fixes).
  - spi: tegra210-quad: Move curr_xfer read inside spinlock
    (git-fixes).
  - spi: tegra210-quad: Return IRQ_HANDLED when timeout already
    processed transfer (git-fixes).
  - commit 48bc42c

------------------------------------------------------------------
------------------  2026-2-7  -  Feb 7 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ALSA: hda/realtek: Enable headset mic for Acer Nitro 5
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for HP 200 G2a 16 (stable-fixes).
  - ASoC: Intel: sof_es8336: Add DMI quirk for Huawei BOD-WXX9
    (stable-fixes).
  - ALSA: aloop: Fix racy access at PCM trigger (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Inspur S14-G1 (stable-fixes).
  - ALSA: hda/realtek: fix right sounds and mute/micmute LEDs for
    HP machine (stable-fixes).
  - ASoC: amd: yc: Add ASUS ExpertBook PM1503CDA to quirks list
    (stable-fixes).
  - ASoC: cs35l45: Corrects ASP_TX5 DAPM widget channel
    (stable-fixes).
  - ALSA: hda/realtek - fixed speaker no sound (stable-fixes).
  - commit 62b82cf
  - ASoC: amd: fix memory leak in acp3x pdm dma ops (git-fixes).
  - ALSA: usb-audio: fix broken logic in snd_audigy2nx_led_update()
    (git-fixes).
  - hwmon: (occ) Mark occ_init_attribute() as __printf (git-fixes).
  - drm/amd/display: fix wrong color value mapping on MCM shaper
    LUT (git-fixes).
  - Revert "drm/amd: Check if ASPM is enabled from PCIe subsystem"
    (git-fixes).
  - drm/xe/query: Fix topology query pointer advance (git-fixes).
  - drm/mgag200: fix mgag200_bmc_stop_scanout() (git-fixes).
  - Revert "drm/nouveau/disp: Set
    drm_mode_config_funcs.atomic_(check|commit)" (git-fixes).
  - efivarfs: fix error propagation in efivar_entry_get()
    (git-fixes).
  - ASoC: amd: yc: Add DMI quirk for Acer TravelMate P216-41-TCO
    (stable-fixes).
  - gpio: pca953x: mask interrupts in irq shutdown (stable-fixes).
  - drm/amdgpu/gfx12: fix wptr reset in KGQ init (stable-fixes).
  - drm/amdgpu/gfx11: fix wptr reset in KGQ init (stable-fixes).
  - drm/amdgpu/gfx10: fix wptr reset in KGQ init (stable-fixes).
  - drm/amdgpu/soc21: fix xclk for APUs (stable-fixes).
  - pinctrl: meson: mark the GPIO controller as sleeping
    (git-fixes).
  - commit 060a2c0

++++ kernel-rt:

  - ALSA: hda/realtek: Enable headset mic for Acer Nitro 5
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for HP 200 G2a 16 (stable-fixes).
  - ASoC: Intel: sof_es8336: Add DMI quirk for Huawei BOD-WXX9
    (stable-fixes).
  - ALSA: aloop: Fix racy access at PCM trigger (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Inspur S14-G1 (stable-fixes).
  - ALSA: hda/realtek: fix right sounds and mute/micmute LEDs for
    HP machine (stable-fixes).
  - ASoC: amd: yc: Add ASUS ExpertBook PM1503CDA to quirks list
    (stable-fixes).
  - ASoC: cs35l45: Corrects ASP_TX5 DAPM widget channel
    (stable-fixes).
  - ALSA: hda/realtek - fixed speaker no sound (stable-fixes).
  - commit 62b82cf
  - ASoC: amd: fix memory leak in acp3x pdm dma ops (git-fixes).
  - ALSA: usb-audio: fix broken logic in snd_audigy2nx_led_update()
    (git-fixes).
  - hwmon: (occ) Mark occ_init_attribute() as __printf (git-fixes).
  - drm/amd/display: fix wrong color value mapping on MCM shaper
    LUT (git-fixes).
  - Revert "drm/amd: Check if ASPM is enabled from PCIe subsystem"
    (git-fixes).
  - drm/xe/query: Fix topology query pointer advance (git-fixes).
  - drm/mgag200: fix mgag200_bmc_stop_scanout() (git-fixes).
  - Revert "drm/nouveau/disp: Set
    drm_mode_config_funcs.atomic_(check|commit)" (git-fixes).
  - efivarfs: fix error propagation in efivar_entry_get()
    (git-fixes).
  - ASoC: amd: yc: Add DMI quirk for Acer TravelMate P216-41-TCO
    (stable-fixes).
  - gpio: pca953x: mask interrupts in irq shutdown (stable-fixes).
  - drm/amdgpu/gfx12: fix wptr reset in KGQ init (stable-fixes).
  - drm/amdgpu/gfx11: fix wptr reset in KGQ init (stable-fixes).
  - drm/amdgpu/gfx10: fix wptr reset in KGQ init (stable-fixes).
  - drm/amdgpu/soc21: fix xclk for APUs (stable-fixes).
  - pinctrl: meson: mark the GPIO controller as sleeping
    (git-fixes).
  - commit 060a2c0

------------------------------------------------------------------
------------------  2026-2-6  -  Feb 6 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - net: openvswitch: fix middle attribute validation in push_nsh()
    action (CVE-2025-68785 bsc#1256640).
  - commit c43798b
  - clocksource: Reduce watchdog readout delay limit to prevent
    false positives (bsc#1257818).
  - commit 92245f0
  - clocksource: Print durations for sync check unconditionally
    (bsc#1257818).
  - commit 2635eb6
  - clocksource: Fix the CPUs' choice in the watchdog per CPU
    verification (bsc#1257818).
  - commit 42f5b0d
  - clocksource: Use pr_info() for "Checking clocksource
    synchronization" message (bsc#1257818).
  - Refresh
    patches.suse/clocksource-Use-migrate_disable-to-avoid-calling-get_random_u32-in-atomic-context.patch.
  - commit 3170141
  - wifi: iwlwifi: mvm: pause TCM on fast resume (git-fixes).
  - net: usb: r8152: fix resume reset deadlock (git-fixes).
  - commit 1109b27

++++ kernel-rt:

  - net: openvswitch: fix middle attribute validation in push_nsh()
    action (CVE-2025-68785 bsc#1256640).
  - commit c43798b
  - clocksource: Reduce watchdog readout delay limit to prevent
    false positives (bsc#1257818).
  - commit 92245f0
  - clocksource: Print durations for sync check unconditionally
    (bsc#1257818).
  - commit 2635eb6
  - clocksource: Fix the CPUs' choice in the watchdog per CPU
    verification (bsc#1257818).
  - commit 42f5b0d
  - clocksource: Use pr_info() for "Checking clocksource
    synchronization" message (bsc#1257818).
  - Refresh
    patches.suse/clocksource-Use-migrate_disable-to-avoid-calling-get_random_u32-in-atomic-context.patch.
  - commit 3170141
  - wifi: iwlwifi: mvm: pause TCM on fast resume (git-fixes).
  - net: usb: r8152: fix resume reset deadlock (git-fixes).
  - commit 1109b27

++++ python313-core:

  - Update to 3.13.12: Python 3.13.12 final Release date:
    2026-02-03
  - Tools/Demos
  - gh-142095: Make gdb ‘py-bt’ command use frame from thread
    local state when available. Patch by Sam Gross and Victor
    Stinner.
  - Tests
  - gh-144415: The Android testbed now distinguishes between
    stdout/stderr messages which were triggered by a newline,
    and those triggered by a manual call to flush. This fixes
    logging of progress indicators and similar content.
  - gh-65784: Add support for parametrized resource wantobjects
    in regrtests, which allows to run Tkinter tests with the
    specified value of tkinter.wantobjects, for example -u
    wantobjects=0.
  - gh-143553: Add support for parametrized resources, such as
  - u xpickle=2.7.
  - gh-142836: Accommodated Solaris in
    test_pdb.test_script_target_anonymous_pipe.
  - gh-129401: Fix a flaky test in test_repr_rlock that checks
    the representation of multiprocessing.RLock.
  - bpo-31391: Forward-port test_xpickle from Python 2 to
    Python 3 and add the resource back to test’s command line.
  - Security
  - gh-144125: BytesGenerator will now refuse to serialize
    (write) headers that are unsafely folded or delimited; see
    verify_generated_headers. (Contributed by Bas Bloemsaat and
    Petr Viktorin in gh-121650) (bsc#1257181, CVE-2026-1299).
  - gh-143935: Fixed a bug in the folding of comments when
    flattening an email message using a modern email policy.
    Comments consisting of a very long sequence of non-foldable
    characters could trigger a forced line wrap that omitted
    the required leading space on the continuation line,
    causing the remainder of the comment to be interpreted as
    a new header field. This enabled header injection with
    carefully crafted inputs (bsc#1257029, CVE-2025-11468).
  - gh-143925: Reject control characters in data: URL media
    types (bsc#1257046, CVE-2025-15282).
  - gh-143919: Reject control characters in http.cookies.Morsel
    fields and values (bsc#1257031, CVE-2026-0672).
  - gh-143916: Reject C0 control characters within
    wsgiref.headers.Headers fields, values, and parameters
    (bsc#1257042, CVE-2026-0865).
  - Library
  - gh-144380: Improve performance of io.BufferedReader line
    iteration by ~49%.
  - gh-144169: Fix three crashes when non-string keyword
    arguments are supplied to objects in the ast module.
  - gh-144100: Fixed a crash in ctypes when using a deprecated
    POINTER(str) type in argtypes. Instead of aborting, ctypes
    now raises a proper Python exception when the pointer
    target type is unresolved.
  - gh-144050: Fix stat.filemode() in the pure-Python
    implementation to avoid misclassifying invalid mode values
    as block devices.
  - gh-144023: Fixed validation of file descriptor 0 in posix
    functions when used with follow_symlinks parameter.
  - gh-143999: Fix an issue where inspect.getgeneratorstate()
    and inspect.getcoroutinestate() could fail for generators
    wrapped by types.coroutine() in the suspended state.
  - gh-143706: Fix multiprocessing forkserver so that sys.argv
    is correctly set before __main__ is preloaded. Previously,
    sys.argv was empty during main module import in forkserver
    child processes. This fixes a regression introduced in
    3.13.8 and 3.14.1. Root caused by Aaron Wieczorek, test
    provided by Thomas Watson, thanks!
  - gh-143638: Forbid reentrant calls of the pickle.Pickler and
    pickle.Unpickler methods for the C implementation.
    Previously, this could cause crash or data corruption, now
    concurrent calls of methods of the same object raise
    RuntimeError.
  - gh-78724: Raise RuntimeError’s when user attempts to call
    methods on half-initialized Struct objects, For example,
    created by Struct.__new__(Struct). Patch by Sergey
    B Kirpichev.
  - gh-143602: Fix a inconsistency issue in write() that leads
    to unexpected buffer overwrite by deduplicating the buffer
    exports.
  - gh-143547: Fix sys.unraisablehook() when the hook raises an
    exception and changes sys.unraisablehook(): hold a strong
    reference to the old hook. Patch by Victor Stinner.
  - gh-143378: Fix use-after-free crashes when a BytesIO object
    is concurrently mutated during write() or writelines().
  - gh-143346: Fix incorrect wrapping of the Base64 data in
    plistlib._PlistWriter when the indent contains a mix of
    tabs and spaces.
  - gh-143310: tkinter: fix a crash when a Python list is
    mutated during the conversion to a Tcl object (e.g., when
    setting a Tcl variable). Patch by Bénédikt Tran.
  - gh-143309: Fix a crash in os.execve() on non-Windows
    platforms when given a custom environment mapping which is
    then mutated during parsing. Patch by Bénédikt Tran.
  - gh-143308: pickle: fix use-after-free crashes when
    a PickleBuffer is concurrently mutated by a custom buffer
    callback during pickling. Patch by Bénédikt Tran and Aaron
    Wieczorek.
  - gh-143237: Fix support of named pipes in the rotating
    logging handlers.
  - gh-143249: Fix possible buffer leaks in Windows overlapped
    I/O on error handling.
  - gh-143241: zoneinfo: fix infinite loop in
    ZoneInfo.from_file when parsing a malformed TZif file.
    Patch by Fatih Celik.
  - gh-142830: sqlite3: fix use-after-free crashes when the
    connection’s callbacks are mutated during a callback
    execution. Patch by Bénédikt Tran.
  - gh-143200: xml.etree.ElementTree: fix use-after-free
    crashes in __getitem__() and __setitem__() methods of
    Element when the element is concurrently mutated. Patch by
    Bénédikt Tran.
  - gh-142195: Updated timeout evaluation logic in subprocess
    to be compatible with deterministic environments like
    Shadow where time moves exactly as requested.
  - gh-143145: Fixed a possible reference leak in ctypes when
    constructing results with multiple output parameters on
    error.
  - gh-122431: Corrected the error message in
    readline.append_history_file() to state that nelements must
    be non-negative instead of positive.
  - gh-143004: Fix a potential use-after-free in
    collections.Counter.update() when user code mutates the
    Counter during an update.
  - gh-143046: The asyncio REPL no longer prints copyright and
    version messages in the quiet mode (-q). Patch by Bartosz
    Sławecki.
  - gh-140648: The asyncio REPL now respects the -I flag
    (isolated mode). Previously, it would load and execute
    PYTHONSTARTUP even if the flag was set. Contributed by
    Bartosz Sławecki.
  - gh-142991: Fixed socket operations such as recvfrom() and
    sendto() for FreeBSD divert(4) socket.
  - gh-143010: Fixed a bug in mailbox where the precise timing
    of an external event could result in the library opening an
    existing file instead of a file it expected to create.
  - gh-142881: Fix concurrent and reentrant call of
    atexit.unregister().
  - gh-112127: Fix possible use-after-free in
    atexit.unregister() when the callback is unregistered
    during comparison.
  - gh-142783: Fix zoneinfo use-after-free with descriptor
    _weak_cache. a descriptor as _weak_cache could cause
    crashes during object creation. The fix ensures proper
    reference counting for descriptor-provided objects.
  - gh-142754: Add the ownerDocument attribute to
    xml.dom.minidom elements and attributes created by directly
    instantiating the Element or Attr class. Note that this way
    of creating nodes is not supported; creator functions like
    xml.dom.Document.documentElement() should be used instead.
  - gh-142784: The asyncio REPL now properly closes the loop
    upon the end of interactive session. Previously, it could
    cause surprising warnings. Contributed by Bartosz Sławecki.
  - gh-142555: array: fix a crash in a[i] = v when converting
    i to an index via i.__index__ or i.__float__ mutates the
    array.
  - gh-142594: Fix crash in TextIOWrapper.close() when the
    underlying buffer’s closed property calls detach().
  - gh-142451: hmac: Ensure that the HMAC.block_size attribute
    is correctly copied by HMAC.copy. Patch by Bénédikt Tran.
  - gh-142495: collections.defaultdict now prioritizes
    __setitem__() when inserting default values from
    default_factory. This prevents race conditions where
    a default value would overwrite a value set before
    default_factory returns.
  - gh-142651: unittest.mock: fix a thread safety issue where
    Mock.call_count may return inaccurate values when the mock
    is called concurrently from multiple threads.
  - gh-142595: Added type check during initialization of the
    decimal module to prevent a crash in case of broken stdlib.
    Patch by Sergey B Kirpichev.
  - gh-142517: The non-compat32 email policies now correctly
    handle refolding encoded words that contain bytes that can
    not be decoded in their specified character set. Previously
    this resulted in an encoding exception during folding.
  - gh-112527: The help text for required options in argparse
    no longer extended with “ (default: None)”.
  - gh-142315: Pdb can now run scripts from anonymous pipes
    used in process substitution. Patch by Bartosz Sławecki.
  - gh-142282: Fix winreg.QueryValueEx() to not accidentally
    read garbage buffer under race condition.
  - gh-75949: Fix argparse to preserve | separators in mutually
    exclusive groups when the usage line wraps due to length.
  - gh-68552: MisplacedEnvelopeHeaderDefect and Missing header
    name defects are now correctly passed to the handle_defect
    method of policy in FeedParser.
  - gh-142006: Fix a bug in the email.policy.default folding
    algorithm which incorrectly resulted in a doubled newline
    when a line ending at exactly max_line_length was followed
    by an unfoldable token.
  - gh-105836: Fix asyncio.run_coroutine_threadsafe() leaving
    underlying cancelled asyncio task running.
  - gh-139971: pydoc: Ensure that the link to the online
    documentation of a stdlib module is correct.
  - gh-139262: Some keystrokes can be swallowed in the new
    PyREPL on Windows, especially when used together with the
    ALT key. Fix by Chris Eibl.
  - gh-138897: Improved license/copyright/credits display in
    the REPL: now uses a pager.
  - gh-79986: Add parsing for References and In-Reply-To
    headers to the email library that parses the header content
    as lists of message id tokens. This prevents them from
    being folded incorrectly.
  - gh-109263: Starting a process from spawn context in
    multiprocessing no longer sets the start method globally.
  - gh-90871: Fixed an off by one error concerning the backlog
    parameter in create_unix_server(). Contributed by Christian
    Harries.
  - gh-133253: Fix thread-safety issues in linecache.
  - gh-132715: Skip writing objects during marshalling once
    a failure has occurred.
  - gh-127529: Correct behavior of
    asyncio.selector_events.BaseSelectorEventLoop._accept_connection()
    in handling ConnectionAbortedError in a loop. This improves
    performance on OpenBSD.
  - IDLE
  - gh-143774: Better explain the operation of Format / Format
    Paragraph.
  - Documentation
  - gh-140806: Add documentation for enum.bin().
  - Core and Builtins
  - gh-144307: Prevent a reference leak in module teardown at
    interpreter finalization.
  - gh-144194: Fix error handling in perf jitdump
    initialization on memory allocation failure.
  - gh-141805: Fix crash in set when objects with the same hash
    are concurrently added to the set after removing an element
    with the same hash while the set still contains elements
    with the same hash.
  - gh-143670: Fixes a crash in ga_repr_items_list function.
  - gh-143377: Fix a crash in _interpreters.capture_exception()
    when the exception is incorrectly formatted. Patch by
    Bénédikt Tran.
  - gh-143189: Fix crash when inserting a non-str key into
    a split table dictionary when the key matches an existing
    key in the split table but has no corresponding value in
    the dict.
  - gh-143228: Fix use-after-free in perf trampoline when
    toggling profiling while threads are running or during
    interpreter finalization with daemon threads active. The
    fix uses reference counting to ensure trampolines are not
    freed while any code object could still reference them.
    Pach by Pablo Galindo
  - gh-142664: Fix a use-after-free crash in
    memoryview.__hash__ when the __hash__ method of the
    referenced object mutates that object or the view. Patch by
    Bénédikt Tran.
  - gh-142557: Fix a use-after-free crash in bytearray.__mod__
    when the bytearray is mutated while formatting the %-style
    arguments. Patch by Bénédikt Tran.
  - gh-143195: Fix use-after-free crashes in bytearray.hex()
    and memoryview.hex() when the separator’s __len__() mutates
    the original object. Patch by Bénédikt Tran.
  - gh-143135: Set sys.flags.inspect to 1 when PYTHONINSPECT is
    0. Previously, it was set to 0 in this case.
  - gh-143003: Fix an overflow of the shared empty buffer in
    bytearray.extend() when __length_hint__() returns 0 for
    non-empty iterator.
  - gh-143006: Fix a possible assertion error when comparing
    negative non-integer float and int with the same number of
    bits in the integer part.
  - gh-142776: Fix a file descriptor leak in import.c
  - gh-142829: Fix a use-after-free crash in
    contextvars.Context comparison when a custom __eq__ method
    modifies the context via set().
  - gh-142766: Clear the frame of a generator when
    generator.close() is called.
  - gh-142737: Tracebacks will be displayed in fallback mode
    even if io.open() is lost. Previously, this would crash the
    interpreter. Patch by Bartosz Sławecki.
  - gh-142554: Fix a crash in divmod() when
    _pylong.int_divmod() does not return a tuple of length two
    exactly. Patch by Bénédikt Tran.
  - gh-142560: Fix use-after-free in bytearray search-like
    methods (find(), count(), index(), rindex(), and rfind())
    by marking the storage as exported which causes
    reallocation attempts to raise BufferError. For contains(),
    split(), and rsplit() the buffer protocol is used for this.
  - gh-142343: Fix SIGILL crash on m68k due to incorrect
    assembly constraint.
  - gh-141732: Ensure the __repr__() for ExceptionGroup and
    BaseExceptionGroup does not change when the exception
    sequence that was original passed in to its constructor is
    subsequently mutated.
  - gh-100964: Fix reference cycle in exhausted generator
    frames. Patch by Savannah Ostrowski.
  - gh-140373: Correctly emit PY_UNWIND event when generator
    object is closed. Patch by Mikhail Efimov.
  - gh-138568: Adjusted the built-in help() function so that
    empty inputs are ignored in interactive mode.
  - gh-127773: Do not use the type attribute cache for types
    with incompatible MRO.
  - C API
  - gh-142571: PyUnstable_CopyPerfMapFile() now checks that
    opening the file succeeded before flushing.
  - Build
  - gh-142454: When calculating the digest of the JIT stencils
    input, sort the hashed files by filenames before adding
    their content to the hasher. This ensures deterministic
    hash input and hence deterministic hash, independent on
    filesystem order.
  - gh-141808: When running make clean-retain-profile, keep the
    generated JIT stencils. That way, the stencils are not
    generated twice when Profile-guided optimization (PGO) is
    used. It also allows distributors to supply their own
    pre-built JIT stencils.
  - gh-138061: Ensure reproducible builds by making JIT stencil
    header generation deterministic.
  - Remove upstreamed patches:
  - CVE-2024-6923-follow-up-EOL-email-headers.patch
  - gh138131-exclude-pycache-from-digest.patch

++++ python313:

  - Update to 3.13.12: Python 3.13.12 final Release date:
    2026-02-03
  - Tools/Demos
  - gh-142095: Make gdb ‘py-bt’ command use frame from thread
    local state when available. Patch by Sam Gross and Victor
    Stinner.
  - Tests
  - gh-144415: The Android testbed now distinguishes between
    stdout/stderr messages which were triggered by a newline,
    and those triggered by a manual call to flush. This fixes
    logging of progress indicators and similar content.
  - gh-65784: Add support for parametrized resource wantobjects
    in regrtests, which allows to run Tkinter tests with the
    specified value of tkinter.wantobjects, for example -u
    wantobjects=0.
  - gh-143553: Add support for parametrized resources, such as
  - u xpickle=2.7.
  - gh-142836: Accommodated Solaris in
    test_pdb.test_script_target_anonymous_pipe.
  - gh-129401: Fix a flaky test in test_repr_rlock that checks
    the representation of multiprocessing.RLock.
  - bpo-31391: Forward-port test_xpickle from Python 2 to
    Python 3 and add the resource back to test’s command line.
  - Security
  - gh-144125: BytesGenerator will now refuse to serialize
    (write) headers that are unsafely folded or delimited; see
    verify_generated_headers. (Contributed by Bas Bloemsaat and
    Petr Viktorin in gh-121650) (bsc#1257181, CVE-2026-1299).
  - gh-143935: Fixed a bug in the folding of comments when
    flattening an email message using a modern email policy.
    Comments consisting of a very long sequence of non-foldable
    characters could trigger a forced line wrap that omitted
    the required leading space on the continuation line,
    causing the remainder of the comment to be interpreted as
    a new header field. This enabled header injection with
    carefully crafted inputs (bsc#1257029, CVE-2025-11468).
  - gh-143925: Reject control characters in data: URL media
    types (bsc#1257046, CVE-2025-15282).
  - gh-143919: Reject control characters in http.cookies.Morsel
    fields and values (bsc#1257031, CVE-2026-0672).
  - gh-143916: Reject C0 control characters within
    wsgiref.headers.Headers fields, values, and parameters
    (bsc#1257042, CVE-2026-0865).
  - Library
  - gh-144380: Improve performance of io.BufferedReader line
    iteration by ~49%.
  - gh-144169: Fix three crashes when non-string keyword
    arguments are supplied to objects in the ast module.
  - gh-144100: Fixed a crash in ctypes when using a deprecated
    POINTER(str) type in argtypes. Instead of aborting, ctypes
    now raises a proper Python exception when the pointer
    target type is unresolved.
  - gh-144050: Fix stat.filemode() in the pure-Python
    implementation to avoid misclassifying invalid mode values
    as block devices.
  - gh-144023: Fixed validation of file descriptor 0 in posix
    functions when used with follow_symlinks parameter.
  - gh-143999: Fix an issue where inspect.getgeneratorstate()
    and inspect.getcoroutinestate() could fail for generators
    wrapped by types.coroutine() in the suspended state.
  - gh-143706: Fix multiprocessing forkserver so that sys.argv
    is correctly set before __main__ is preloaded. Previously,
    sys.argv was empty during main module import in forkserver
    child processes. This fixes a regression introduced in
    3.13.8 and 3.14.1. Root caused by Aaron Wieczorek, test
    provided by Thomas Watson, thanks!
  - gh-143638: Forbid reentrant calls of the pickle.Pickler and
    pickle.Unpickler methods for the C implementation.
    Previously, this could cause crash or data corruption, now
    concurrent calls of methods of the same object raise
    RuntimeError.
  - gh-78724: Raise RuntimeError’s when user attempts to call
    methods on half-initialized Struct objects, For example,
    created by Struct.__new__(Struct). Patch by Sergey
    B Kirpichev.
  - gh-143602: Fix a inconsistency issue in write() that leads
    to unexpected buffer overwrite by deduplicating the buffer
    exports.
  - gh-143547: Fix sys.unraisablehook() when the hook raises an
    exception and changes sys.unraisablehook(): hold a strong
    reference to the old hook. Patch by Victor Stinner.
  - gh-143378: Fix use-after-free crashes when a BytesIO object
    is concurrently mutated during write() or writelines().
  - gh-143346: Fix incorrect wrapping of the Base64 data in
    plistlib._PlistWriter when the indent contains a mix of
    tabs and spaces.
  - gh-143310: tkinter: fix a crash when a Python list is
    mutated during the conversion to a Tcl object (e.g., when
    setting a Tcl variable). Patch by Bénédikt Tran.
  - gh-143309: Fix a crash in os.execve() on non-Windows
    platforms when given a custom environment mapping which is
    then mutated during parsing. Patch by Bénédikt Tran.
  - gh-143308: pickle: fix use-after-free crashes when
    a PickleBuffer is concurrently mutated by a custom buffer
    callback during pickling. Patch by Bénédikt Tran and Aaron
    Wieczorek.
  - gh-143237: Fix support of named pipes in the rotating
    logging handlers.
  - gh-143249: Fix possible buffer leaks in Windows overlapped
    I/O on error handling.
  - gh-143241: zoneinfo: fix infinite loop in
    ZoneInfo.from_file when parsing a malformed TZif file.
    Patch by Fatih Celik.
  - gh-142830: sqlite3: fix use-after-free crashes when the
    connection’s callbacks are mutated during a callback
    execution. Patch by Bénédikt Tran.
  - gh-143200: xml.etree.ElementTree: fix use-after-free
    crashes in __getitem__() and __setitem__() methods of
    Element when the element is concurrently mutated. Patch by
    Bénédikt Tran.
  - gh-142195: Updated timeout evaluation logic in subprocess
    to be compatible with deterministic environments like
    Shadow where time moves exactly as requested.
  - gh-143145: Fixed a possible reference leak in ctypes when
    constructing results with multiple output parameters on
    error.
  - gh-122431: Corrected the error message in
    readline.append_history_file() to state that nelements must
    be non-negative instead of positive.
  - gh-143004: Fix a potential use-after-free in
    collections.Counter.update() when user code mutates the
    Counter during an update.
  - gh-143046: The asyncio REPL no longer prints copyright and
    version messages in the quiet mode (-q). Patch by Bartosz
    Sławecki.
  - gh-140648: The asyncio REPL now respects the -I flag
    (isolated mode). Previously, it would load and execute
    PYTHONSTARTUP even if the flag was set. Contributed by
    Bartosz Sławecki.
  - gh-142991: Fixed socket operations such as recvfrom() and
    sendto() for FreeBSD divert(4) socket.
  - gh-143010: Fixed a bug in mailbox where the precise timing
    of an external event could result in the library opening an
    existing file instead of a file it expected to create.
  - gh-142881: Fix concurrent and reentrant call of
    atexit.unregister().
  - gh-112127: Fix possible use-after-free in
    atexit.unregister() when the callback is unregistered
    during comparison.
  - gh-142783: Fix zoneinfo use-after-free with descriptor
    _weak_cache. a descriptor as _weak_cache could cause
    crashes during object creation. The fix ensures proper
    reference counting for descriptor-provided objects.
  - gh-142754: Add the ownerDocument attribute to
    xml.dom.minidom elements and attributes created by directly
    instantiating the Element or Attr class. Note that this way
    of creating nodes is not supported; creator functions like
    xml.dom.Document.documentElement() should be used instead.
  - gh-142784: The asyncio REPL now properly closes the loop
    upon the end of interactive session. Previously, it could
    cause surprising warnings. Contributed by Bartosz Sławecki.
  - gh-142555: array: fix a crash in a[i] = v when converting
    i to an index via i.__index__ or i.__float__ mutates the
    array.
  - gh-142594: Fix crash in TextIOWrapper.close() when the
    underlying buffer’s closed property calls detach().
  - gh-142451: hmac: Ensure that the HMAC.block_size attribute
    is correctly copied by HMAC.copy. Patch by Bénédikt Tran.
  - gh-142495: collections.defaultdict now prioritizes
    __setitem__() when inserting default values from
    default_factory. This prevents race conditions where
    a default value would overwrite a value set before
    default_factory returns.
  - gh-142651: unittest.mock: fix a thread safety issue where
    Mock.call_count may return inaccurate values when the mock
    is called concurrently from multiple threads.
  - gh-142595: Added type check during initialization of the
    decimal module to prevent a crash in case of broken stdlib.
    Patch by Sergey B Kirpichev.
  - gh-142517: The non-compat32 email policies now correctly
    handle refolding encoded words that contain bytes that can
    not be decoded in their specified character set. Previously
    this resulted in an encoding exception during folding.
  - gh-112527: The help text for required options in argparse
    no longer extended with “ (default: None)”.
  - gh-142315: Pdb can now run scripts from anonymous pipes
    used in process substitution. Patch by Bartosz Sławecki.
  - gh-142282: Fix winreg.QueryValueEx() to not accidentally
    read garbage buffer under race condition.
  - gh-75949: Fix argparse to preserve | separators in mutually
    exclusive groups when the usage line wraps due to length.
  - gh-68552: MisplacedEnvelopeHeaderDefect and Missing header
    name defects are now correctly passed to the handle_defect
    method of policy in FeedParser.
  - gh-142006: Fix a bug in the email.policy.default folding
    algorithm which incorrectly resulted in a doubled newline
    when a line ending at exactly max_line_length was followed
    by an unfoldable token.
  - gh-105836: Fix asyncio.run_coroutine_threadsafe() leaving
    underlying cancelled asyncio task running.
  - gh-139971: pydoc: Ensure that the link to the online
    documentation of a stdlib module is correct.
  - gh-139262: Some keystrokes can be swallowed in the new
    PyREPL on Windows, especially when used together with the
    ALT key. Fix by Chris Eibl.
  - gh-138897: Improved license/copyright/credits display in
    the REPL: now uses a pager.
  - gh-79986: Add parsing for References and In-Reply-To
    headers to the email library that parses the header content
    as lists of message id tokens. This prevents them from
    being folded incorrectly.
  - gh-109263: Starting a process from spawn context in
    multiprocessing no longer sets the start method globally.
  - gh-90871: Fixed an off by one error concerning the backlog
    parameter in create_unix_server(). Contributed by Christian
    Harries.
  - gh-133253: Fix thread-safety issues in linecache.
  - gh-132715: Skip writing objects during marshalling once
    a failure has occurred.
  - gh-127529: Correct behavior of
    asyncio.selector_events.BaseSelectorEventLoop._accept_connection()
    in handling ConnectionAbortedError in a loop. This improves
    performance on OpenBSD.
  - IDLE
  - gh-143774: Better explain the operation of Format / Format
    Paragraph.
  - Documentation
  - gh-140806: Add documentation for enum.bin().
  - Core and Builtins
  - gh-144307: Prevent a reference leak in module teardown at
    interpreter finalization.
  - gh-144194: Fix error handling in perf jitdump
    initialization on memory allocation failure.
  - gh-141805: Fix crash in set when objects with the same hash
    are concurrently added to the set after removing an element
    with the same hash while the set still contains elements
    with the same hash.
  - gh-143670: Fixes a crash in ga_repr_items_list function.
  - gh-143377: Fix a crash in _interpreters.capture_exception()
    when the exception is incorrectly formatted. Patch by
    Bénédikt Tran.
  - gh-143189: Fix crash when inserting a non-str key into
    a split table dictionary when the key matches an existing
    key in the split table but has no corresponding value in
    the dict.
  - gh-143228: Fix use-after-free in perf trampoline when
    toggling profiling while threads are running or during
    interpreter finalization with daemon threads active. The
    fix uses reference counting to ensure trampolines are not
    freed while any code object could still reference them.
    Pach by Pablo Galindo
  - gh-142664: Fix a use-after-free crash in
    memoryview.__hash__ when the __hash__ method of the
    referenced object mutates that object or the view. Patch by
    Bénédikt Tran.
  - gh-142557: Fix a use-after-free crash in bytearray.__mod__
    when the bytearray is mutated while formatting the %-style
    arguments. Patch by Bénédikt Tran.
  - gh-143195: Fix use-after-free crashes in bytearray.hex()
    and memoryview.hex() when the separator’s __len__() mutates
    the original object. Patch by Bénédikt Tran.
  - gh-143135: Set sys.flags.inspect to 1 when PYTHONINSPECT is
    0. Previously, it was set to 0 in this case.
  - gh-143003: Fix an overflow of the shared empty buffer in
    bytearray.extend() when __length_hint__() returns 0 for
    non-empty iterator.
  - gh-143006: Fix a possible assertion error when comparing
    negative non-integer float and int with the same number of
    bits in the integer part.
  - gh-142776: Fix a file descriptor leak in import.c
  - gh-142829: Fix a use-after-free crash in
    contextvars.Context comparison when a custom __eq__ method
    modifies the context via set().
  - gh-142766: Clear the frame of a generator when
    generator.close() is called.
  - gh-142737: Tracebacks will be displayed in fallback mode
    even if io.open() is lost. Previously, this would crash the
    interpreter. Patch by Bartosz Sławecki.
  - gh-142554: Fix a crash in divmod() when
    _pylong.int_divmod() does not return a tuple of length two
    exactly. Patch by Bénédikt Tran.
  - gh-142560: Fix use-after-free in bytearray search-like
    methods (find(), count(), index(), rindex(), and rfind())
    by marking the storage as exported which causes
    reallocation attempts to raise BufferError. For contains(),
    split(), and rsplit() the buffer protocol is used for this.
  - gh-142343: Fix SIGILL crash on m68k due to incorrect
    assembly constraint.
  - gh-141732: Ensure the __repr__() for ExceptionGroup and
    BaseExceptionGroup does not change when the exception
    sequence that was original passed in to its constructor is
    subsequently mutated.
  - gh-100964: Fix reference cycle in exhausted generator
    frames. Patch by Savannah Ostrowski.
  - gh-140373: Correctly emit PY_UNWIND event when generator
    object is closed. Patch by Mikhail Efimov.
  - gh-138568: Adjusted the built-in help() function so that
    empty inputs are ignored in interactive mode.
  - gh-127773: Do not use the type attribute cache for types
    with incompatible MRO.
  - C API
  - gh-142571: PyUnstable_CopyPerfMapFile() now checks that
    opening the file succeeded before flushing.
  - Build
  - gh-142454: When calculating the digest of the JIT stencils
    input, sort the hashed files by filenames before adding
    their content to the hasher. This ensures deterministic
    hash input and hence deterministic hash, independent on
    filesystem order.
  - gh-141808: When running make clean-retain-profile, keep the
    generated JIT stencils. That way, the stencils are not
    generated twice when Profile-guided optimization (PGO) is
    used. It also allows distributors to supply their own
    pre-built JIT stencils.
  - gh-138061: Ensure reproducible builds by making JIT stencil
    header generation deterministic.
  - Remove upstreamed patches:
  - CVE-2024-6923-follow-up-EOL-email-headers.patch
  - gh138131-exclude-pycache-from-digest.patch

------------------------------------------------------------------
------------------  2026-2-5  -  Feb 5 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - dm: Fix deadlock when reloading a multipath table (bsc#1254928).
  - commit 8e55787
  - iomap: account for unaligned end offsets when truncating read
    range (git-fixes).
  - commit d3a2bf0
  - ext4: fix iloc.bh leak in ext4_xattr_inode_update_ref
    (git-fixes).
  - commit 2476b62
  - arm64: Set __nocfi on swsusp_arch_resume() (git-fixes)
  - commit 9cd22b1
  - btrfs: fix beyond-EOF write handling (git-fixes).
  - commit 4c56d83

++++ kernel-rt:

  - dm: Fix deadlock when reloading a multipath table (bsc#1254928).
  - commit 8e55787
  - iomap: account for unaligned end offsets when truncating read
    range (git-fixes).
  - commit d3a2bf0
  - ext4: fix iloc.bh leak in ext4_xattr_inode_update_ref
    (git-fixes).
  - commit 2476b62
  - arm64: Set __nocfi on swsusp_arch_resume() (git-fixes)
  - commit 9cd22b1
  - btrfs: fix beyond-EOF write handling (git-fixes).
  - commit 4c56d83

++++ gcc15:

  - Add gcc15-bsc1257463.patch to fix bogus expression simplification
    [bsc#1257463]

++++ systemd:

  - Avoid shipping (empty) directories and ghost files in /var (jsc#PED-14853)
    This was originally intended to ensure these paths had a designated package
    owner. However the existing list was neither exhaustive nor up to date. To
    better support immutable images, we are removing these entries and will now
    keep only /var/lib/systemd as owned by the systemd package. Maintaining the
    broader list provided little value due to its ongoing inconsistency anyways.

++++ read-only-root-fs:

  - Add patch to fix workaround for read-only / subvolumes (bsc#1252892):
    * 0001-Fix-workaround-for-read-only-subvolumes-by-remountin.patch

++++ regionServiceClientConfigGCE:

  - Update to version 5.2.0
    + Drop the if condition for gcemetdata requirement

------------------------------------------------------------------
------------------  2026-2-4  -  Feb 4 2026  -------------------
------------------------------------------------------------------

++++ docker:

  - Places a hard cap on the amount of mechanisms that can be specified and
    encoded in the payload. (bcs#1253904, CVE-2025-58181)
    * 0007-CVE-2025-58181-fix-vendor-crypto-ssh.patch

++++ kernel-default:

  - ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
    (CVE-2026-23003 bsc#1257246).
  - commit 574bdcd
  - Refresh patches.suse/scsi-ufs-core-Improve-ufshcd_mcq_sq_cleanup.patch.
    Align with resulting upstream code after merges.
    Avoids a format string warning.
  - commit dd8af96
  - idpf: detach and close netdevs while handling a reset
    (CVE-2026-22981 bsc#1257225).
  - commit 6e399ef
  - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR
    (failed VMRUN) (git-fixes).
  - commit ea24b4e
  - KVM: nSVM: Clear exit_code_hi in VMCB when synthesizing nested
    VM-Exits (git-fixes).
  - commit 39ff5cb
  - KVM: x86: Explicitly set new periodic hrtimer expiration in
    apic_timer_fn() (git-fixes).
  - commit e059ee8
  - KVM: x86: WARN if hrtimer callback for periodic APIC timer
    fires with period=0 (git-fixes).
  - commit 2c24d91
  - platform/x86: intel_telemetry: Fix PSS event register mask
    (git-fixes).
  - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
    (git-fixes).
  - platform/x86: toshiba_haps: Fix memory leaks in add/remove
    routines (git-fixes).
  - commit 35ce7c7
  - KVM: x86: Don't clear async #PF queue when CR0.PG is disabled
    (e.g. on #SMI) (git-fixes).
  - commit c57db6d
  - btrfs: scrub: always update btrfs_scrub_progress::last_physical
    (git-fixes).
  - commit 9d5464b

++++ kernel-rt:

  - ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv()
    (CVE-2026-23003 bsc#1257246).
  - commit 574bdcd
  - Refresh patches.suse/scsi-ufs-core-Improve-ufshcd_mcq_sq_cleanup.patch.
    Align with resulting upstream code after merges.
    Avoids a format string warning.
  - commit dd8af96
  - idpf: detach and close netdevs while handling a reset
    (CVE-2026-22981 bsc#1257225).
  - commit 6e399ef
  - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR
    (failed VMRUN) (git-fixes).
  - commit ea24b4e
  - KVM: nSVM: Clear exit_code_hi in VMCB when synthesizing nested
    VM-Exits (git-fixes).
  - commit 39ff5cb
  - KVM: x86: Explicitly set new periodic hrtimer expiration in
    apic_timer_fn() (git-fixes).
  - commit e059ee8
  - KVM: x86: WARN if hrtimer callback for periodic APIC timer
    fires with period=0 (git-fixes).
  - commit 2c24d91
  - platform/x86: intel_telemetry: Fix PSS event register mask
    (git-fixes).
  - platform/x86: intel_telemetry: Fix swapped arrays in PSS output
    (git-fixes).
  - platform/x86: toshiba_haps: Fix memory leaks in add/remove
    routines (git-fixes).
  - commit 35ce7c7
  - KVM: x86: Don't clear async #PF queue when CR0.PG is disabled
    (e.g. on #SMI) (git-fixes).
  - commit c57db6d
  - btrfs: scrub: always update btrfs_scrub_progress::last_physical
    (git-fixes).
  - commit 9d5464b

++++ libxslt:

  - CVE-2025-10911 will be fixed on libxml2 side instead [bsc#1250553]
  - deleted patches
    * libxslt-CVE-2025-10911.patch

++++ systemd:

  - Import commit fb9d92682b2469aa205d4df3ffea61e4806ed0e9
    fb9d92682b terminal-util: stop doing 0/upper bound check in tty_is_vc() (bsc#1255326)
    80ec26cee0 core/dbus-manager: propagate meaningful dbus errors from EnqueueMarkedJobs

++++ libxml2:

  - CVE-2026-1757: memory leak in the `xmllint` interactive shell (bsc#1257593, bsc#1257594, bsc#1257595)
    * Add patch libxml2-CVE-2026-1757.patch
  - CVE-2025-10911: use-after-free with key data stored cross-RVT (bsc#1250553)
    * Add patch libxml2-CVE-2025-10911.patch

++++ opensuse-migration-tool:

  - Update to version 20260204.2cf77a3:
    * Drop requires on update-bootloader as it's not available on 15.6.
    Install it in post-script on target of migration instead. boo#1255897
    * Refine post-scritps
    * Ensure update bootloader is installed in post scripts
    * don't install selinux-policy-targeted-gaming by default

++++ libxml2-python:

  - CVE-2026-1757: memory leak in the `xmllint` interactive shell (bsc#1257593, bsc#1257594, bsc#1257595)
    * Add patch libxml2-CVE-2026-1757.patch
  - CVE-2025-10911: use-after-free with key data stored cross-RVT (bsc#1250553)
    * Add patch libxml2-CVE-2025-10911.patch

------------------------------------------------------------------
------------------  2026-2-3  -  Feb 3 2026  -------------------
------------------------------------------------------------------

++++ cockpit-podman:

  - Update dependencies for bsc#1257324/CVE-2025-13465

++++ kernel-default:

  - slimbus: core: Constify slim_eaddr_equal() (jsc#PED-10906
    git-fixes).
  - commit 6c2c54b
  - bus: fsl-mc: Constify fsl_mc_device_match() (jsc#PED-10906
    git-fixes).
  - commit b3ff1a5
  - mm, page_alloc, thp: prevent reclaim for __GFP_THISNODE THP
    allocations (bsc#1254447 bsc#1253087).
  - commit 8de8481
  - arm64: Update config files. Disable DEVPORT (bsc#1256792)
  - commit 3858f73
  - KABi: fix "dm-snapshot: fix 'scheduling while atomic' on
    real-time kernels" (git-fixes).
  - commit b8ec588
  - bpf/selftests: test_select_reuseport_kern: Remove unused header
    (bsc#1257603).
  - commit 1a032d9
  - smb: client: split cached_fid bitfields to avoid shared-byte
    RMW races (bsc#1250748,bsc#1257154).
  - commit 9624e6c
  - smb: client: update cfid->last_access_time in
    open_cached_dir_by_dentry() (git-fixes).
  - commit a159cff
  - cifs: add new field to track the last access time of cfid
    (git-fixes).
  - commit 0cd09f9
  - smb: improve directory cache reuse for readdir operations
    (bsc#1252712).
  - commit 98f179c

++++ kernel-rt:

  - slimbus: core: Constify slim_eaddr_equal() (jsc#PED-10906
    git-fixes).
  - commit 6c2c54b
  - bus: fsl-mc: Constify fsl_mc_device_match() (jsc#PED-10906
    git-fixes).
  - commit b3ff1a5
  - mm, page_alloc, thp: prevent reclaim for __GFP_THISNODE THP
    allocations (bsc#1254447 bsc#1253087).
  - commit 8de8481
  - arm64: Update config files. Disable DEVPORT (bsc#1256792)
  - commit 3858f73
  - KABi: fix "dm-snapshot: fix 'scheduling while atomic' on
    real-time kernels" (git-fixes).
  - commit b8ec588
  - bpf/selftests: test_select_reuseport_kern: Remove unused header
    (bsc#1257603).
  - commit 1a032d9
  - smb: client: split cached_fid bitfields to avoid shared-byte
    RMW races (bsc#1250748,bsc#1257154).
  - commit 9624e6c
  - smb: client: update cfid->last_access_time in
    open_cached_dir_by_dentry() (git-fixes).
  - commit a159cff
  - cifs: add new field to track the last access time of cfid
    (git-fixes).
  - commit 0cd09f9
  - smb: improve directory cache reuse for readdir operations
    (bsc#1252712).
  - commit 98f179c

++++ expat:

  - security update
  - added patches
    CVE-2026-24515 [bsc#1257144], NULL dereference (CWE-476) due to function XML_ExternalEntityParserCreate() failing to copy the encoding handler data passed to XML_SetUnknownEncodingHandler() from the parent to the subparser
    * expat-CVE-2026-24515.patch
    CVE-2026-25210 [bsc#1257496], lack of buffer size check can lead to an integer overflow
    * expat-CVE-2026-25210.patch

++++ libsoup:

  - Add libsoup-CVE-2026-1536.patch: Always validate the headers
    value when coming from untrusted source
    (bsc#1257440, CVE-2026-1536, glgo#GNOME/libsoup/commit/5c1a2e9c).
  - Add libsoup-CVE-2026-1761.patch: multipart: check length of bytes
    read soup_filter_input_stream_read_until()
    (bsc#1257598, CVE-2026-1761, glgo#GNOME/libsoup!496).

++++ selinux-policy:

  - Update to version 20250627+git347.b8926451e:
    * Add support for 'mariadb@.service' (bsc#1255024).

------------------------------------------------------------------
------------------  2026-2-2  -  Feb 2 2026  -------------------
------------------------------------------------------------------

++++ cryptsetup:

  - Update to 2.8.4: (jsc#PED-15889)
    * Fix integritysetup resize (grow) of the device if integrity bitmap
    mode is used. Increasing the integrity device in bitmap mode did
    not work as integritysetup incorrectly used journal settings that
    were not applicable.
    * Fix device size status reports in cryptsetup and integritysetup.
    If the device uses a sector size larger than 512 bytes, the newly
    reported byte sizes (introduced in 2.8.0) in the status report
    were incorrectly displayed.
    * BITLK: Fix unlocking BitLocker device with recovery passphrase.
    If the recovery passphrase was present in the first keyslot, the
    device failed to unlock. This bug was introduced in 2.8.2 with
    Clear Key support.

++++ kernel-default:

  - scripts/python/git_sort/git_sort.yaml: add cifs for-next repository
  - commit 5e1a139
  - libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990 bsc#1257221).
  - commit bf45795
  - libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984 bsc#1257217).
  - commit 3af214d
  - libceph: return the handler error from mon_handle_auth_done() (CVE-2026-22992 bsc#1257218).
  - commit 2da8b55
  - libceph: make free_choose_arg_map() resilient to partial allocation (CVE-2026-22991 bsc#1257220).
  - commit 1c4a387
  - Update config files: disable CONFIG_DEVPORT for arm64 (bsc#1256792)
  - commit 89771ce
  - x86/fpu: Clear XSTATE_BV in guest XSAVE state whenever XFD[i]=1
    (CVE-2026-23005 bsc#1257245).
  - commit 0a828e9
  - Update
    patches.suse/ACPICA-Avoid-walking-the-Namespace-if-start_node-is-.patch
    (stable-fixes CVE-2025-71118 bsc#1256763).
  - Update
    patches.suse/ALSA-hda-Fix-missing-pointer-check-in-hda_component_.patch
    (git-fixes CVE-2025-40097 bsc#1252900).
  - Update
    patches.suse/ALSA-usb-mixer-us16x08-validate-meter-packet-indices.patch
    (git-fixes CVE-2025-68783 bsc#1256650).
  - Update
    patches.suse/ASoC-codecs-wcd9375-Fix-double-free-of-regulator-sup.patch
    (git-fixes CVE-2025-38423 bsc#1247292).
  - Update
    patches.suse/ASoC-codecs-wcd937x-set-the-comp-soundwire-port-corr.patch
    (git-fixes CVE-2025-40045 bsc#1252784).
  - Update
    patches.suse/ASoC-stm32-sai-fix-OF-node-leak-on-probe.patch
    (git-fixes CVE-2025-71081 bsc#1256609).
  - Update patches.suse/ASoC-tlv320adcx140-fix-null-pointer.patch
    (git-fixes CVE-2026-23006 bsc#1257208).
  - Update
    patches.suse/Bluetooth-btusb-revert-use-of-devm_kzalloc-in-btusb.patch
    (git-fixes CVE-2025-71082 bsc#1256611).
  - Update
    patches.suse/EDAC-skx_common-Fix-general-protection-fault.patch
    (git-fixes CVE-2025-38298 bsc#1253079).
  - Update
    patches.suse/HID-nintendo-avoid-bluetooth-suspend-resume-stalls.patch
    (stable-fixes CVE-2025-38507 bsc#1248188).
  - Update
    patches.suse/HID-quirks-Add-quirk-for-2-Chicony-Electronics-HP-5M.patch
    (stable-fixes CVE-2025-38540 bsc#1248208).
  - Update
    patches.suse/Input-alps-fix-use-after-free-bugs-caused-by-dev3_re.patch
    (git-fixes CVE-2025-68822 bsc#1256668).
  - Update
    patches.suse/Input-lkkbd-disable-pending-work-before-freeing-devi.patch
    (stable-fixes CVE-2025-71073 bsc#1256632).
  - Update
    patches.suse/Input-ti_am335x_tsc-fix-off-by-one-error-in-wire_ord.patch
    (git-fixes CVE-2025-68777 bsc#1256655).
  - Update
    patches.suse/KEYS-trusted-Fix-a-memory-leak-in-tpm2_load_cmd.patch
    (git-fixes CVE-2025-71147 bsc#1257158).
  - Update
    patches.suse/PM-EM-Fix-potential-division-by-zero-error-in-em_com.patch
    (git-fixes CVE-2025-38297 bsc#1253078).
  - Update
    patches.suse/arp-do-not-assume-dev_hard_header-does-not-change-skb-head.patch
    (CVE-2025-71098 bsc#1256591 CVE-2026-22988 bsc#1257282).
  - Update patches.suse/benet-fix-BUG-when-creating-VFs.patch
    (git-fixes CVE-2025-38569 bsc#1248384).
  - Update
    patches.suse/block-avoid-possible-overflow-for-chunk_sectors-check-in-b.patch
    (git-fixes CVE-2025-39795 bsc#1249609).
  - Update
    patches.suse/bpf-Do-not-let-BPF-test-infra-emit-invalid-GSO-types.patch
    (bsc#1255569 CVE-2025-68725).
  - Update
    patches.suse/btrfs-don-t-log-conflicting-inode-if-it-s-a-dir-move.patch
    (git-fixes CVE-2025-68778 bsc#1256683).
  - Update
    patches.suse/btrfs-fix-invalid-inode-pointer-dereferences-during-.patch
    (git-fixes CVE-2025-38243 bsc#1246184).
  - Update patches.suse/btrfs-fix-the-inode-leak-in-btrfs_iget.patch
    (git-fixes CVE-2025-37904 bsc#1243452).
  - Update
    patches.suse/ceph-fix-race-condition-validating-r_parent-before-applyin.patch
    (CVE-2025-39880 bsc#1250388 CVE-2025-39927 bsc#1250738).
  - Update
    patches.suse/char-applicom-fix-NULL-pointer-dereference-in-ac_ioc.patch
    (stable-fixes CVE-2025-68797 bsc#1256660).
  - Update
    patches.suse/clk-samsung-exynos-clkout-Assign-.num-before-accessi.patch
    (git-fixes CVE-2025-71143 bsc#1256749).
  - Update
    patches.suse/comedi-aio_iiro_16-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38529 bsc#1248196).
  - Update
    patches.suse/comedi-fix-divide-by-zero-in-comedi_buf_munge.patch
    (stable-fixes CVE-2025-40106 bsc#1252891).
  - Update
    patches.suse/comedi-pcl812-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38530 bsc#1248206).
  - Update
    patches.suse/cpuset-fix-warning-when-disabling-remote-partition.patch
    (bsc#1256794 CVE-2025-71142 bsc#1256748).
  - Update
    patches.suse/crypto-af_alg-zero-initialize-memory-allocated-via-s.patch
    (git-fixes CVE-2025-71113 bsc#1256716).
  - Update
    patches.suse/crypto-seqiv-Do-not-use-req-iv-after-crypto_aead_enc.patch
    (git-fixes CVE-2025-71131 bsc#1256742).
  - Update
    patches.suse/dmaengine-idxd-fix-device-leaks-on-compat-bind-and-u.patch
    (git-fixes CVE-2025-71163 bsc#1257215).
  - Update
    patches.suse/dmaengine-nbpfaxi-Fix-memory-corruption-in-probe.patch
    (git-fixes CVE-2025-38538 bsc#1248213).
  - Update
    patches.suse/dmaengine-tegra-adma-Fix-use-after-free.patch
    (git-fixes CVE-2025-71162 bsc#1257204).
  - Update
    patches.suse/drm-amdkfd-Don-t-call-mmput-from-MMU-notifier-callba.patch
    (git-fixes CVE-2025-38520 bsc#1248217).
  - Update
    patches.suse/drm-i915-gem-Zero-initialize-the-eb.vma-array-in-i91.patch
    (git-fixes CVE-2025-71130 bsc#1256741).
  - Update
    patches.suse/drm-imagination-Fix-kernel-crash-when-hard-resetting.patch
    (git-fixes CVE-2025-38521 bsc#1248232).
  - Update
    patches.suse/drm-msm-dpu-Add-missing-NULL-pointer-check-for-pingp.patch
    (git-fixes CVE-2025-71138 bsc#1256785).
  - Update
    patches.suse/drm-sched-Increment-job-count-before-swapping-tail-s.patch
    (git-fixes CVE-2025-38515 bsc#1248212).
  - Update
    patches.suse/drm-tegra-nvdec-Fix-dma_alloc_coherent-error-check.patch
    (git-fixes CVE-2025-38543 bsc#1248214).
  - Update
    patches.suse/drm-tilcdc-Fix-removal-actions-in-case-of-failed-pro.patch
    (git-fixes CVE-2025-71141 bsc#1256756).
  - Update
    patches.suse/drm-ttm-Avoid-NULL-pointer-deref-for-evicted-BOs.patch
    (git-fixes CVE-2025-71083 bsc#1256610).
  - Update
    patches.suse/drm-xe-Limit-num_syncs-to-prevent-oversized-allocati.patch
    (git-fixes CVE-2025-68802 bsc#1256661).
  - Update
    patches.suse/drm-xe-oa-Fix-potential-UAF-in-xe_oa_add_config_ioct.patch
    (git-fixes CVE-2025-71099 bsc#1256592).
  - Update
    patches.suse/drm-xe-oa-Limit-num_syncs-to-prevent-oversized-alloc.patch
    (git-fixes CVE-2025-71076 bsc#1256627).
  - Update
    patches.suse/drm-xe-pf-Clear-all-LMTT-pages-on-alloc.patch
    (git-fixes CVE-2025-38511 bsc#1248175).
  - Update
    patches.suse/efivarfs-Fix-slab-out-of-bounds-in-efivarfs_d_compar.patch
    (git-fixes CVE-2025-39817 bsc#1249998).
  - Update
    patches.suse/ftrace-Also-allocate-and-copy-hash-for-reading-of-filter-f.patch
    (bsc#1250032 CVE-2025-39813 CVE-2025-39689 bsc#1249307).
  - Update
    patches.suse/hwmon-corsair-cpro-Validate-the-size-of-the-received.patch
    (git-fixes CVE-2025-38548 bsc#1248228).
  - Update
    patches.suse/hwmon-ibmpex-fix-use-after-free-in-high-low-store.patch
    (git-fixes CVE-2025-68789 bsc#1256781).
  - Update
    patches.suse/hwmon-w83791d-Convert-macros-to-functions-to-avoid-T.patch
    (git-fixes CVE-2025-71111 bsc#1256728).
  - Update
    patches.suse/ice-fix-NULL-pointer-dereference-in-ice_unplug_aux_d.patch
    (jsc#PED-13728 CVE-2025-39814 bsc#1249895).
  - Update
    patches.suse/idpf-Fix-RSS-LUT-NULL-pointer-crash-on-early-ethtool.patch
    (CVE-2026-22993 bsc#1257180 CVE-2026-22985 bsc#1257277).
  - Update
    patches.suse/iio-adc-axp20x_adc-Add-missing-sentinel-to-AXP717-AD.patch
    (git-fixes CVE-2025-38547 bsc#1248222).
  - Update
    patches.suse/ipv6-mcast-Delay-put-pmc-idev-in-mld_del_delrec.patch
    (git-fixes CVE-2025-38550 bsc#1248227).
  - Update
    patches.suse/kasan-remove-kasan_find_vm_area-to-prevent-possible-.patch
    (git-fixes CVE-2025-38510 bsc#1248166).
  - Update
    patches.suse/lib-buildid-use-__kernel_read-for-sleepable-context.patch
    (git-fixes CVE-2026-23002 bsc#1257243).
  - Update
    patches.suse/media-adv7842-Avoid-possible-out-of-bounds-array-acc.patch
    (git-fixes CVE-2025-71136 bsc#1256759).
  - Update
    patches.suse/media-dvb-usb-dtv5100-fix-out-of-bounds-in-dtv5100_i.patch
    (git-fixes CVE-2025-68819 bsc#1256664).
  - Update
    patches.suse/media-vidtv-initialize-local-pointers-upon-transfer-.patch
    (git-fixes CVE-2025-68808 bsc#1256682).
  - Update
    patches.suse/mount-handle-NULL-values-in-mnt_ns_release.patch
    (bsc#1254308 CVE-2025-40195 bsc#1253500).
  - Update
    patches.suse/neighbour-Fix-null-ptr-deref-in-neigh_flush_dev.patch
    (git-fixes CVE-2025-38589 bsc#1248366).
  - Update
    patches.suse/net-can-j1939-j1939_xtp_rx_rts_session_active-deacti.patch
    (git-fixes CVE-2026-22997 bsc#1257202).
  - Update
    patches.suse/net-mlx5-Check-device-memory-pointer-before-usage.patch
    (git-fixes CVE-2025-38645 bsc#1248626).
  - Update
    patches.suse/net-mlx5e-Remove-skb-secpath-if-xfrm-state-is-not-fo.patch
    (git-fixes CVE-2025-38590 bsc#1248360).
  - Update
    patches.suse/net-nfc-fix-deadlock-between-nfc_unregister_device-a.patch
    (git-fixes CVE-2025-71079 bsc#1256619).
  - Update patches.suse/net-phy-Don-t-register-LEDs-for-genphy.patch
    (git-fixes CVE-2025-38537 bsc#1248229).
  - Update
    patches.suse/net-rose-fix-invalid-array-index-in-rose_kill_by_dev.patch
    (git-fixes CVE-2025-71086 bsc#1256625).
  - Update
    patches.suse/net-usb-rtl8150-fix-memory-leak-on-usb_submit_urb-fa.patch
    (git-fixes CVE-2025-71154 bsc#1257163).
  - Update
    patches.suse/netfilter-nft_set_hash-unaligned-atomic-read-on-struct-nft.patch
    (git-fixes CVE-2024-54031 bsc#1235905).
  - Update
    patches.suse/nfsd-check-that-server-is-running-in-unlock_filesystem.patch
    (git-fixes CVE-2026-22989 bsc#1257279).
  - Update
    patches.suse/phy-tegra-xusb-Fix-unbalanced-regulator-disable-in-U.patch
    (git-fixes CVE-2025-38535 bsc#1248240).
  - Update
    patches.suse/pinctrl-check-the-return-value-of-pinmux_ops-get_fun.patch
    (stable-fixes CVE-2025-40030 bsc#1252773).
  - Update
    patches.suse/pinctrl-qcom-msm-mark-certain-pins-as-invalid-for-in.patch
    (git-fixes CVE-2025-38516 bsc#1248209).
  - Update
    patches.suse/platform-chrome-cros_ec_ishtp-Fix-UAF-after-unbindin.patch
    (git-fixes CVE-2025-68804 bsc#1256617).
  - Update
    patches.suse/platform-x86-hp-bioscfg-Fix-out-of-bounds-array-acce.patch
    (git-fixes CVE-2025-71101 bsc#1256594).
  - Update
    patches.suse/pm-cpupower-bench-Prevent-NULL-dereference-on-malloc.patch
    (stable-fixes CVE-2025-37841 bsc#1242974).
  - Update
    patches.suse/powerpc-64s-slb-Fix-SLB-multihit-issue-during-SLB-preload.patch
    (bac#1236022 ltc#211187 CVE-2025-71078 bsc#1256616).
  - Update
    patches.suse/powerpc-kexec-Enable-SMT-before-waking-offline-CPUs.patch
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1253739 ltc#211493 bsc#1254244 ltc#216496 CVE-2025-71119
    bsc#1256730).
  - Update
    patches.suse/smb-client-fix-warning-when-reconnecting-channel.patch
    (git-fixes CVE-2025-38379 bsc#1247030).
  - Update
    patches.suse/spi-fsl-cpm-Check-length-parity-before-switching-to-.patch
    (git-fixes CVE-2025-68773 bsc#1256586).
  - Update
    patches.suse/tcp_bpf-Call-sk_msg_free-when-tcp_bpf_send_verdict-f.patch
    (bsc#1250705 CVE-2025-39913).
  - Update
    patches.suse/trace-fgraph-Fix-the-warning-caused-by-missing-unregister-.patch
    (bsc#1248211 CVE-2025-38539 CVE-2025-39829 bsc#1250082).
  - Update
    patches.suse/tracing-fprobe-events-Fix-possible-UAF-on-modules.patch
    (git-fixes CVE-2025-37845 bsc#1242986).
  - Update
    patches.suse/tty-serial-uartlite-register-uart-driver-in-init.patch
    (stable-fixes CVE-2025-38262 bsc#1246282).
  - Update
    patches.suse/usb-phy-isp1301-fix-non-OF-device-reference-imbalanc.patch
    (git-fixes CVE-2025-71145 bsc#1257155).
  - Update
    patches.suse/usb-typec-ucsi-Handle-incorrect-num_connectors-capab.patch
    (stable-fixes CVE-2025-71108 bsc#1256774).
  - Update
    patches.suse/via_wdt-fix-critical-boot-hang-due-to-unnamed-resour.patch
    (stable-fixes CVE-2025-71114 bsc#1256752).
  - Update
    patches.suse/virtio-net-fix-recursived-rtnl_lock-during-probe.patch
    (git-fixes CVE-2025-38551 bsc#1248234).
  - Update
    patches.suse/virtio-net-free-xsk_buffs-on-error-in-virtnet_xsk_po.patch
    (git-fixes CVE-2025-37955 bsc#1243507).
  - Update
    patches.suse/wifi-ath12k-fix-memory-leak-in-ath12k_pci_remove.patch
    (stable-fixes CVE-2025-37744 bsc#1243662).
  - Update
    patches.suse/wifi-avoid-kernel-infoleak-from-struct-iw_point.patch
    (git-fixes CVE-2026-22978 bsc#1257227).
  - Update
    patches.suse/wifi-mt76-mt7925-Fix-null-ptr-deref-in-mt7925_therma.patch
    (git-fixes CVE-2025-38541 bsc#1248216).
  - Update
    patches.suse/wifi-mwifiex-discard-erroneous-disassoc-frames-on-ST.patch
    (git-fixes CVE-2025-38505 bsc#1248185).
  - Update
    patches.suse/wifi-prevent-A-MSDU-attacks-in-mesh-networks.patch
    (stable-fixes CVE-2025-38512 bsc#1248178).
  - Update
    patches.suse/wifi-rtlwifi-8192cu-fix-tid-out-of-range-in-rtl92cu_.patch
    (git-fixes CVE-2025-71100 bsc#1256593).
  - Update
    patches.suse/wifi-zd1211rw-Fix-potential-NULL-pointer-dereference.patch
    (git-fixes CVE-2025-38513 bsc#1248179).
  - Update
    patches.suse/x86-cpu-Avoid-running-off-the-end-of-an-AMD-erratum-table.patch
    (git-fixes CVE-2025-37751 bsc#1242505).
  - commit 74167a5
  - powerpc/addnote: Fix overflow on 32-bit builds (bsc#1215199).
  - commit 651b1d4
  - net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv
    (CVE-2026-22996).
  - net/mlx5e: Fix crash on profile change rollback failure
    (CVE-2026-23000 bsc#1257234).
  - commit 395ffba
  - gpio: rockchip: Stop calling pinctrl for set_direction
    (git-fixes).
  - commit 0d36e6c

++++ kernel-rt:

  - scripts/python/git_sort/git_sort.yaml: add cifs for-next repository
  - commit 5e1a139
  - libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (CVE-2026-22990 bsc#1257221).
  - commit bf45795
  - libceph: prevent potential out-of-bounds reads in handle_auth_done() (CVE-2026-22984 bsc#1257217).
  - commit 3af214d
  - libceph: return the handler error from mon_handle_auth_done() (CVE-2026-22992 bsc#1257218).
  - commit 2da8b55
  - libceph: make free_choose_arg_map() resilient to partial allocation (CVE-2026-22991 bsc#1257220).
  - commit 1c4a387
  - Update config files: disable CONFIG_DEVPORT for arm64 (bsc#1256792)
  - commit 89771ce
  - x86/fpu: Clear XSTATE_BV in guest XSAVE state whenever XFD[i]=1
    (CVE-2026-23005 bsc#1257245).
  - commit 0a828e9
  - Update
    patches.suse/ACPICA-Avoid-walking-the-Namespace-if-start_node-is-.patch
    (stable-fixes CVE-2025-71118 bsc#1256763).
  - Update
    patches.suse/ALSA-hda-Fix-missing-pointer-check-in-hda_component_.patch
    (git-fixes CVE-2025-40097 bsc#1252900).
  - Update
    patches.suse/ALSA-usb-mixer-us16x08-validate-meter-packet-indices.patch
    (git-fixes CVE-2025-68783 bsc#1256650).
  - Update
    patches.suse/ASoC-codecs-wcd9375-Fix-double-free-of-regulator-sup.patch
    (git-fixes CVE-2025-38423 bsc#1247292).
  - Update
    patches.suse/ASoC-codecs-wcd937x-set-the-comp-soundwire-port-corr.patch
    (git-fixes CVE-2025-40045 bsc#1252784).
  - Update
    patches.suse/ASoC-stm32-sai-fix-OF-node-leak-on-probe.patch
    (git-fixes CVE-2025-71081 bsc#1256609).
  - Update patches.suse/ASoC-tlv320adcx140-fix-null-pointer.patch
    (git-fixes CVE-2026-23006 bsc#1257208).
  - Update
    patches.suse/Bluetooth-btusb-revert-use-of-devm_kzalloc-in-btusb.patch
    (git-fixes CVE-2025-71082 bsc#1256611).
  - Update
    patches.suse/EDAC-skx_common-Fix-general-protection-fault.patch
    (git-fixes CVE-2025-38298 bsc#1253079).
  - Update
    patches.suse/HID-nintendo-avoid-bluetooth-suspend-resume-stalls.patch
    (stable-fixes CVE-2025-38507 bsc#1248188).
  - Update
    patches.suse/HID-quirks-Add-quirk-for-2-Chicony-Electronics-HP-5M.patch
    (stable-fixes CVE-2025-38540 bsc#1248208).
  - Update
    patches.suse/Input-alps-fix-use-after-free-bugs-caused-by-dev3_re.patch
    (git-fixes CVE-2025-68822 bsc#1256668).
  - Update
    patches.suse/Input-lkkbd-disable-pending-work-before-freeing-devi.patch
    (stable-fixes CVE-2025-71073 bsc#1256632).
  - Update
    patches.suse/Input-ti_am335x_tsc-fix-off-by-one-error-in-wire_ord.patch
    (git-fixes CVE-2025-68777 bsc#1256655).
  - Update
    patches.suse/KEYS-trusted-Fix-a-memory-leak-in-tpm2_load_cmd.patch
    (git-fixes CVE-2025-71147 bsc#1257158).
  - Update
    patches.suse/PM-EM-Fix-potential-division-by-zero-error-in-em_com.patch
    (git-fixes CVE-2025-38297 bsc#1253078).
  - Update
    patches.suse/arp-do-not-assume-dev_hard_header-does-not-change-skb-head.patch
    (CVE-2025-71098 bsc#1256591 CVE-2026-22988 bsc#1257282).
  - Update patches.suse/benet-fix-BUG-when-creating-VFs.patch
    (git-fixes CVE-2025-38569 bsc#1248384).
  - Update
    patches.suse/block-avoid-possible-overflow-for-chunk_sectors-check-in-b.patch
    (git-fixes CVE-2025-39795 bsc#1249609).
  - Update
    patches.suse/bpf-Do-not-let-BPF-test-infra-emit-invalid-GSO-types.patch
    (bsc#1255569 CVE-2025-68725).
  - Update
    patches.suse/btrfs-don-t-log-conflicting-inode-if-it-s-a-dir-move.patch
    (git-fixes CVE-2025-68778 bsc#1256683).
  - Update
    patches.suse/btrfs-fix-invalid-inode-pointer-dereferences-during-.patch
    (git-fixes CVE-2025-38243 bsc#1246184).
  - Update patches.suse/btrfs-fix-the-inode-leak-in-btrfs_iget.patch
    (git-fixes CVE-2025-37904 bsc#1243452).
  - Update
    patches.suse/ceph-fix-race-condition-validating-r_parent-before-applyin.patch
    (CVE-2025-39880 bsc#1250388 CVE-2025-39927 bsc#1250738).
  - Update
    patches.suse/char-applicom-fix-NULL-pointer-dereference-in-ac_ioc.patch
    (stable-fixes CVE-2025-68797 bsc#1256660).
  - Update
    patches.suse/clk-samsung-exynos-clkout-Assign-.num-before-accessi.patch
    (git-fixes CVE-2025-71143 bsc#1256749).
  - Update
    patches.suse/comedi-aio_iiro_16-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38529 bsc#1248196).
  - Update
    patches.suse/comedi-fix-divide-by-zero-in-comedi_buf_munge.patch
    (stable-fixes CVE-2025-40106 bsc#1252891).
  - Update
    patches.suse/comedi-pcl812-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38530 bsc#1248206).
  - Update
    patches.suse/cpuset-fix-warning-when-disabling-remote-partition.patch
    (bsc#1256794 CVE-2025-71142 bsc#1256748).
  - Update
    patches.suse/crypto-af_alg-zero-initialize-memory-allocated-via-s.patch
    (git-fixes CVE-2025-71113 bsc#1256716).
  - Update
    patches.suse/crypto-seqiv-Do-not-use-req-iv-after-crypto_aead_enc.patch
    (git-fixes CVE-2025-71131 bsc#1256742).
  - Update
    patches.suse/dmaengine-idxd-fix-device-leaks-on-compat-bind-and-u.patch
    (git-fixes CVE-2025-71163 bsc#1257215).
  - Update
    patches.suse/dmaengine-nbpfaxi-Fix-memory-corruption-in-probe.patch
    (git-fixes CVE-2025-38538 bsc#1248213).
  - Update
    patches.suse/dmaengine-tegra-adma-Fix-use-after-free.patch
    (git-fixes CVE-2025-71162 bsc#1257204).
  - Update
    patches.suse/drm-amdkfd-Don-t-call-mmput-from-MMU-notifier-callba.patch
    (git-fixes CVE-2025-38520 bsc#1248217).
  - Update
    patches.suse/drm-i915-gem-Zero-initialize-the-eb.vma-array-in-i91.patch
    (git-fixes CVE-2025-71130 bsc#1256741).
  - Update
    patches.suse/drm-imagination-Fix-kernel-crash-when-hard-resetting.patch
    (git-fixes CVE-2025-38521 bsc#1248232).
  - Update
    patches.suse/drm-msm-dpu-Add-missing-NULL-pointer-check-for-pingp.patch
    (git-fixes CVE-2025-71138 bsc#1256785).
  - Update
    patches.suse/drm-sched-Increment-job-count-before-swapping-tail-s.patch
    (git-fixes CVE-2025-38515 bsc#1248212).
  - Update
    patches.suse/drm-tegra-nvdec-Fix-dma_alloc_coherent-error-check.patch
    (git-fixes CVE-2025-38543 bsc#1248214).
  - Update
    patches.suse/drm-tilcdc-Fix-removal-actions-in-case-of-failed-pro.patch
    (git-fixes CVE-2025-71141 bsc#1256756).
  - Update
    patches.suse/drm-ttm-Avoid-NULL-pointer-deref-for-evicted-BOs.patch
    (git-fixes CVE-2025-71083 bsc#1256610).
  - Update
    patches.suse/drm-xe-Limit-num_syncs-to-prevent-oversized-allocati.patch
    (git-fixes CVE-2025-68802 bsc#1256661).
  - Update
    patches.suse/drm-xe-oa-Fix-potential-UAF-in-xe_oa_add_config_ioct.patch
    (git-fixes CVE-2025-71099 bsc#1256592).
  - Update
    patches.suse/drm-xe-oa-Limit-num_syncs-to-prevent-oversized-alloc.patch
    (git-fixes CVE-2025-71076 bsc#1256627).
  - Update
    patches.suse/drm-xe-pf-Clear-all-LMTT-pages-on-alloc.patch
    (git-fixes CVE-2025-38511 bsc#1248175).
  - Update
    patches.suse/efivarfs-Fix-slab-out-of-bounds-in-efivarfs_d_compar.patch
    (git-fixes CVE-2025-39817 bsc#1249998).
  - Update
    patches.suse/ftrace-Also-allocate-and-copy-hash-for-reading-of-filter-f.patch
    (bsc#1250032 CVE-2025-39813 CVE-2025-39689 bsc#1249307).
  - Update
    patches.suse/hwmon-corsair-cpro-Validate-the-size-of-the-received.patch
    (git-fixes CVE-2025-38548 bsc#1248228).
  - Update
    patches.suse/hwmon-ibmpex-fix-use-after-free-in-high-low-store.patch
    (git-fixes CVE-2025-68789 bsc#1256781).
  - Update
    patches.suse/hwmon-w83791d-Convert-macros-to-functions-to-avoid-T.patch
    (git-fixes CVE-2025-71111 bsc#1256728).
  - Update
    patches.suse/ice-fix-NULL-pointer-dereference-in-ice_unplug_aux_d.patch
    (jsc#PED-13728 CVE-2025-39814 bsc#1249895).
  - Update
    patches.suse/idpf-Fix-RSS-LUT-NULL-pointer-crash-on-early-ethtool.patch
    (CVE-2026-22993 bsc#1257180 CVE-2026-22985 bsc#1257277).
  - Update
    patches.suse/iio-adc-axp20x_adc-Add-missing-sentinel-to-AXP717-AD.patch
    (git-fixes CVE-2025-38547 bsc#1248222).
  - Update
    patches.suse/ipv6-mcast-Delay-put-pmc-idev-in-mld_del_delrec.patch
    (git-fixes CVE-2025-38550 bsc#1248227).
  - Update
    patches.suse/kasan-remove-kasan_find_vm_area-to-prevent-possible-.patch
    (git-fixes CVE-2025-38510 bsc#1248166).
  - Update
    patches.suse/lib-buildid-use-__kernel_read-for-sleepable-context.patch
    (git-fixes CVE-2026-23002 bsc#1257243).
  - Update
    patches.suse/media-adv7842-Avoid-possible-out-of-bounds-array-acc.patch
    (git-fixes CVE-2025-71136 bsc#1256759).
  - Update
    patches.suse/media-dvb-usb-dtv5100-fix-out-of-bounds-in-dtv5100_i.patch
    (git-fixes CVE-2025-68819 bsc#1256664).
  - Update
    patches.suse/media-vidtv-initialize-local-pointers-upon-transfer-.patch
    (git-fixes CVE-2025-68808 bsc#1256682).
  - Update
    patches.suse/mount-handle-NULL-values-in-mnt_ns_release.patch
    (bsc#1254308 CVE-2025-40195 bsc#1253500).
  - Update
    patches.suse/neighbour-Fix-null-ptr-deref-in-neigh_flush_dev.patch
    (git-fixes CVE-2025-38589 bsc#1248366).
  - Update
    patches.suse/net-can-j1939-j1939_xtp_rx_rts_session_active-deacti.patch
    (git-fixes CVE-2026-22997 bsc#1257202).
  - Update
    patches.suse/net-mlx5-Check-device-memory-pointer-before-usage.patch
    (git-fixes CVE-2025-38645 bsc#1248626).
  - Update
    patches.suse/net-mlx5e-Remove-skb-secpath-if-xfrm-state-is-not-fo.patch
    (git-fixes CVE-2025-38590 bsc#1248360).
  - Update
    patches.suse/net-nfc-fix-deadlock-between-nfc_unregister_device-a.patch
    (git-fixes CVE-2025-71079 bsc#1256619).
  - Update patches.suse/net-phy-Don-t-register-LEDs-for-genphy.patch
    (git-fixes CVE-2025-38537 bsc#1248229).
  - Update
    patches.suse/net-rose-fix-invalid-array-index-in-rose_kill_by_dev.patch
    (git-fixes CVE-2025-71086 bsc#1256625).
  - Update
    patches.suse/net-usb-rtl8150-fix-memory-leak-on-usb_submit_urb-fa.patch
    (git-fixes CVE-2025-71154 bsc#1257163).
  - Update
    patches.suse/netfilter-nft_set_hash-unaligned-atomic-read-on-struct-nft.patch
    (git-fixes CVE-2024-54031 bsc#1235905).
  - Update
    patches.suse/nfsd-check-that-server-is-running-in-unlock_filesystem.patch
    (git-fixes CVE-2026-22989 bsc#1257279).
  - Update
    patches.suse/phy-tegra-xusb-Fix-unbalanced-regulator-disable-in-U.patch
    (git-fixes CVE-2025-38535 bsc#1248240).
  - Update
    patches.suse/pinctrl-check-the-return-value-of-pinmux_ops-get_fun.patch
    (stable-fixes CVE-2025-40030 bsc#1252773).
  - Update
    patches.suse/pinctrl-qcom-msm-mark-certain-pins-as-invalid-for-in.patch
    (git-fixes CVE-2025-38516 bsc#1248209).
  - Update
    patches.suse/platform-chrome-cros_ec_ishtp-Fix-UAF-after-unbindin.patch
    (git-fixes CVE-2025-68804 bsc#1256617).
  - Update
    patches.suse/platform-x86-hp-bioscfg-Fix-out-of-bounds-array-acce.patch
    (git-fixes CVE-2025-71101 bsc#1256594).
  - Update
    patches.suse/pm-cpupower-bench-Prevent-NULL-dereference-on-malloc.patch
    (stable-fixes CVE-2025-37841 bsc#1242974).
  - Update
    patches.suse/powerpc-64s-slb-Fix-SLB-multihit-issue-during-SLB-preload.patch
    (bac#1236022 ltc#211187 CVE-2025-71078 bsc#1256616).
  - Update
    patches.suse/powerpc-kexec-Enable-SMT-before-waking-offline-CPUs.patch
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1253739 ltc#211493 bsc#1254244 ltc#216496 CVE-2025-71119
    bsc#1256730).
  - Update
    patches.suse/smb-client-fix-warning-when-reconnecting-channel.patch
    (git-fixes CVE-2025-38379 bsc#1247030).
  - Update
    patches.suse/spi-fsl-cpm-Check-length-parity-before-switching-to-.patch
    (git-fixes CVE-2025-68773 bsc#1256586).
  - Update
    patches.suse/tcp_bpf-Call-sk_msg_free-when-tcp_bpf_send_verdict-f.patch
    (bsc#1250705 CVE-2025-39913).
  - Update
    patches.suse/trace-fgraph-Fix-the-warning-caused-by-missing-unregister-.patch
    (bsc#1248211 CVE-2025-38539 CVE-2025-39829 bsc#1250082).
  - Update
    patches.suse/tracing-fprobe-events-Fix-possible-UAF-on-modules.patch
    (git-fixes CVE-2025-37845 bsc#1242986).
  - Update
    patches.suse/tty-serial-uartlite-register-uart-driver-in-init.patch
    (stable-fixes CVE-2025-38262 bsc#1246282).
  - Update
    patches.suse/usb-phy-isp1301-fix-non-OF-device-reference-imbalanc.patch
    (git-fixes CVE-2025-71145 bsc#1257155).
  - Update
    patches.suse/usb-typec-ucsi-Handle-incorrect-num_connectors-capab.patch
    (stable-fixes CVE-2025-71108 bsc#1256774).
  - Update
    patches.suse/via_wdt-fix-critical-boot-hang-due-to-unnamed-resour.patch
    (stable-fixes CVE-2025-71114 bsc#1256752).
  - Update
    patches.suse/virtio-net-fix-recursived-rtnl_lock-during-probe.patch
    (git-fixes CVE-2025-38551 bsc#1248234).
  - Update
    patches.suse/virtio-net-free-xsk_buffs-on-error-in-virtnet_xsk_po.patch
    (git-fixes CVE-2025-37955 bsc#1243507).
  - Update
    patches.suse/wifi-ath12k-fix-memory-leak-in-ath12k_pci_remove.patch
    (stable-fixes CVE-2025-37744 bsc#1243662).
  - Update
    patches.suse/wifi-avoid-kernel-infoleak-from-struct-iw_point.patch
    (git-fixes CVE-2026-22978 bsc#1257227).
  - Update
    patches.suse/wifi-mt76-mt7925-Fix-null-ptr-deref-in-mt7925_therma.patch
    (git-fixes CVE-2025-38541 bsc#1248216).
  - Update
    patches.suse/wifi-mwifiex-discard-erroneous-disassoc-frames-on-ST.patch
    (git-fixes CVE-2025-38505 bsc#1248185).
  - Update
    patches.suse/wifi-prevent-A-MSDU-attacks-in-mesh-networks.patch
    (stable-fixes CVE-2025-38512 bsc#1248178).
  - Update
    patches.suse/wifi-rtlwifi-8192cu-fix-tid-out-of-range-in-rtl92cu_.patch
    (git-fixes CVE-2025-71100 bsc#1256593).
  - Update
    patches.suse/wifi-zd1211rw-Fix-potential-NULL-pointer-dereference.patch
    (git-fixes CVE-2025-38513 bsc#1248179).
  - Update
    patches.suse/x86-cpu-Avoid-running-off-the-end-of-an-AMD-erratum-table.patch
    (git-fixes CVE-2025-37751 bsc#1242505).
  - commit 74167a5
  - powerpc/addnote: Fix overflow on 32-bit builds (bsc#1215199).
  - commit 651b1d4
  - net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv
    (CVE-2026-22996).
  - net/mlx5e: Fix crash on profile change rollback failure
    (CVE-2026-23000 bsc#1257234).
  - commit 395ffba
  - gpio: rockchip: Stop calling pinctrl for set_direction
    (git-fixes).
  - commit 0d36e6c

++++ libgcrypt:

  - Update to 1.12.0 (jsc#PED-15059)
    * New and extended interfaces:
  - Allow access to the FIPS service indicator via the new
    GCRYCTL_FIPS_SERVICE_INDICATOR control code.
  - Make SHA-1 non-FIPS internally for the 1.12 API
  - Add Dilithium (ML-DSA) support
  - Support optional random-override and support byte string data
    * Bug fixes:
  - Use secure MPI in _gcry_mpi_assign_limb_space.
  - Use CSIDL_COMMON_APPDATA instead of /etc on Windows.
  - Apply a Kyber patch from upstream.
  - Fix an edge case in Jent initialization.
  - mceliece6688128f: Fix stack overflow crash on win64/wine
    * Performance:
  - Many performance improvements, new AVX512 implementations for modern CPUs.
  - Add RISC-V Zbb+Zbc implementation of CRC.
  - Add RISC-V vector cryptography implementation of GHASH, AES, SHA256 and SHA512
  - Add AVX2 and AVX512 code paths to improve CRC.
    For a full changelog, see:
    https://dev.gnupg.org/source/libgcrypt/history/master/;libgcrypt-1.12.0
    * Dropped libgcrypt-1.11.1-public-SLI-API.patch - applied upstream
    * Rebased libgcrypt-CVE-2024-2236.patch
    * Rebased libgcrypt-FIPS-SLI-hash-mac.patch
    * Rebased libgcrypt-FIPS-SLI-kdf-leylength.patch
    * Rebased libgcrypt-FIPS-SLI-pk.patch
    * Rebased libgcrypt-FIPS-jitter-standalone.patch
    * Rebased libgcrypt-FIPS-rndjent_poll.patch
    * Rebased libgcrypt-nobetasuffix.patch
    * Rebased libgcrypt-rol64-redefinition.patch
    * Added libgcrypt-1.12.0-ec_regression.patch
    * libgcrypt 1.12.0: gcry_mpi_ec_curve_point corrupts point

++++ libgpg-error:

  - Update to 1.58
    * New src/gpg-error.c (main): New command "fconcat".
    * Rename src/spawn-posix.c (struct gpgrt_spawn_actions): Rename the field to
    ENVP.
    * argparse: Use SYSCONFDIR for /etc.
    * Update translations for Portugese, German
    * src/estream.c (parse_mode): Fix parsing of "share". Set sysopen
    flag.
    * syscfg: Add 64-bit Android arch.

++++ sssd:

  - Use %pre scriptlet instead of %pretrans to migrate from
    sssd-common; (bsc#1257509);

++++ patch:

  - CVE-2021-45261.patch: Clear range of pointers before they are
    used/freed (boo#1194037 CVE-2021-45261).

++++ pcr-oracle:

  - Update to 0.5.9
    + Fix event skipping due to double increment
    + Add '--persistent-srk' to make SRK persistent (bsc#1248516)

------------------------------------------------------------------
------------------  2026-2-1  -  Feb 1 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - gpiolib: fix race condition for gdev->srcu (CVE-2026-22986
    bsc#1257276).
  - commit 52ce57d
  - btrfs: do not strictly require dirty metadata threshold for
    metadata  writepages (stable-fixes).
  - commit 17f45d0
  - ASoC: Intel: sof_es8336: fix headphone GPIO logic inversion
    (git-fixes).
  - ASoC: fsl: imx-card: Do not force slot width to sample width
    (git-fixes).
  - ASoC: Intel: sof_es8336: fix headphone GPIO logic inversion
    (git-fixes).
  - ASoC: fsl: imx-card: Do not force slot width to sample width
    (git-fixes).
  - commit 7c26c54

++++ kernel-rt:

  - gpiolib: fix race condition for gdev->srcu (CVE-2026-22986
    bsc#1257276).
  - commit 52ce57d
  - btrfs: do not strictly require dirty metadata threshold for
    metadata  writepages (stable-fixes).
  - commit 17f45d0
  - ASoC: Intel: sof_es8336: fix headphone GPIO logic inversion
    (git-fixes).
  - ASoC: fsl: imx-card: Do not force slot width to sample width
    (git-fixes).
  - ASoC: Intel: sof_es8336: fix headphone GPIO logic inversion
    (git-fixes).
  - ASoC: fsl: imx-card: Do not force slot width to sample width
    (git-fixes).
  - commit 7c26c54

------------------------------------------------------------------
------------------  2026-1-31  -  Jan 31 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ceph: fix crash in process_v2_sparse_read() for encrypted directories (CVE-2025-68297 bsc#1255403).
  - commit 49f747e
  - fuse: fix readahead reclaim deadlock (CVE-2025-68821 bsc#1256667).
  - commit f1828b7
  - gpio: omap: do not register driver in probe() (git-fixes).
  - gpio: virtuser: fix UAF in configfs release path (git-fixes).
  - gpio: rockchip: Stop calling pinctrl for set_direction
    (git-fixes).
  - drm/imx/tve: fix probe device leak (git-fixes).
  - drm/amdgpu: Fix cond_exec handling in amdgpu_ib_schedule()
    (git-fixes).
  - drm/amd/pm: fix race in power state check before mutex lock
    (git-fixes).
  - drm/amdgpu: fix NULL pointer dereference in
    amdgpu_gmc_filter_faults_remove (git-fixes).
  - drm/msm/a6xx: fix bogus hwcg register updates (git-fixes).
  - iio: core: add separate lockdep class for info_exist_lock
    (git-fixes).
  - Input: i8042 - add quirks for MECHREVO Wujie 15X Pro
    (stable-fixes).
  - Input: i8042 - add quirk for ASUS Zenbook UX425QA_UM425QA
    (stable-fixes).
  - ALSA: ctxfi: Fix potential OOB access in audio mixer handling
    (stable-fixes).
  - drm/amdgpu: remove frame cntl for gfx v12 (stable-fixes).
  - drm/nouveau/disp: Set
    drm_mode_config_funcs.atomic_(check|commit) (stable-fixes).
  - mISDN: annotate data-race around dev->work (git-fixes).
  - iio: core: Replace lockdep_set_class() + mutex_init() by
    combined call (stable-fixes).
  - tpm: Compare HMAC values in constant time (stable-fixes).
  - dmaengine: ti: k3-udma: Enable second resource range for BCDMA
    and PKTDMA (stable-fixes).
  - gpio: omap: do not register driver in probe() (git-fixes).
  - gpio: virtuser: fix UAF in configfs release path (git-fixes).
  - gpio: rockchip: Stop calling pinctrl for set_direction
    (git-fixes).
  - drm/imx/tve: fix probe device leak (git-fixes).
  - drm/amdgpu: Fix cond_exec handling in amdgpu_ib_schedule()
    (git-fixes).
  - drm/amd/pm: fix race in power state check before mutex lock
    (git-fixes).
  - drm/amdgpu: fix NULL pointer dereference in
    amdgpu_gmc_filter_faults_remove (git-fixes).
  - drm/msm/a6xx: fix bogus hwcg register updates (git-fixes).
  - iio: core: add separate lockdep class for info_exist_lock
    (git-fixes).
  - Input: i8042 - add quirks for MECHREVO Wujie 15X Pro
    (stable-fixes).
  - Input: i8042 - add quirk for ASUS Zenbook UX425QA_UM425QA
    (stable-fixes).
  - ALSA: ctxfi: Fix potential OOB access in audio mixer handling
    (stable-fixes).
  - drm/amdgpu: remove frame cntl for gfx v12 (stable-fixes).
  - drm/nouveau/disp: Set
    drm_mode_config_funcs.atomic_(check|commit) (stable-fixes).
  - mISDN: annotate data-race around dev->work (git-fixes).
  - iio: core: Replace lockdep_set_class() + mutex_init() by
    combined call (stable-fixes).
  - tpm: Compare HMAC values in constant time (stable-fixes).
  - dmaengine: ti: k3-udma: Enable second resource range for BCDMA
    and PKTDMA (stable-fixes).
  - commit 3e7d134

++++ kernel-rt:

  - ceph: fix crash in process_v2_sparse_read() for encrypted directories (CVE-2025-68297 bsc#1255403).
  - commit 49f747e
  - fuse: fix readahead reclaim deadlock (CVE-2025-68821 bsc#1256667).
  - commit f1828b7
  - gpio: omap: do not register driver in probe() (git-fixes).
  - gpio: virtuser: fix UAF in configfs release path (git-fixes).
  - gpio: rockchip: Stop calling pinctrl for set_direction
    (git-fixes).
  - drm/imx/tve: fix probe device leak (git-fixes).
  - drm/amdgpu: Fix cond_exec handling in amdgpu_ib_schedule()
    (git-fixes).
  - drm/amd/pm: fix race in power state check before mutex lock
    (git-fixes).
  - drm/amdgpu: fix NULL pointer dereference in
    amdgpu_gmc_filter_faults_remove (git-fixes).
  - drm/msm/a6xx: fix bogus hwcg register updates (git-fixes).
  - iio: core: add separate lockdep class for info_exist_lock
    (git-fixes).
  - Input: i8042 - add quirks for MECHREVO Wujie 15X Pro
    (stable-fixes).
  - Input: i8042 - add quirk for ASUS Zenbook UX425QA_UM425QA
    (stable-fixes).
  - ALSA: ctxfi: Fix potential OOB access in audio mixer handling
    (stable-fixes).
  - drm/amdgpu: remove frame cntl for gfx v12 (stable-fixes).
  - drm/nouveau/disp: Set
    drm_mode_config_funcs.atomic_(check|commit) (stable-fixes).
  - mISDN: annotate data-race around dev->work (git-fixes).
  - iio: core: Replace lockdep_set_class() + mutex_init() by
    combined call (stable-fixes).
  - tpm: Compare HMAC values in constant time (stable-fixes).
  - dmaengine: ti: k3-udma: Enable second resource range for BCDMA
    and PKTDMA (stable-fixes).
  - gpio: omap: do not register driver in probe() (git-fixes).
  - gpio: virtuser: fix UAF in configfs release path (git-fixes).
  - gpio: rockchip: Stop calling pinctrl for set_direction
    (git-fixes).
  - drm/imx/tve: fix probe device leak (git-fixes).
  - drm/amdgpu: Fix cond_exec handling in amdgpu_ib_schedule()
    (git-fixes).
  - drm/amd/pm: fix race in power state check before mutex lock
    (git-fixes).
  - drm/amdgpu: fix NULL pointer dereference in
    amdgpu_gmc_filter_faults_remove (git-fixes).
  - drm/msm/a6xx: fix bogus hwcg register updates (git-fixes).
  - iio: core: add separate lockdep class for info_exist_lock
    (git-fixes).
  - Input: i8042 - add quirks for MECHREVO Wujie 15X Pro
    (stable-fixes).
  - Input: i8042 - add quirk for ASUS Zenbook UX425QA_UM425QA
    (stable-fixes).
  - ALSA: ctxfi: Fix potential OOB access in audio mixer handling
    (stable-fixes).
  - drm/amdgpu: remove frame cntl for gfx v12 (stable-fixes).
  - drm/nouveau/disp: Set
    drm_mode_config_funcs.atomic_(check|commit) (stable-fixes).
  - mISDN: annotate data-race around dev->work (git-fixes).
  - iio: core: Replace lockdep_set_class() + mutex_init() by
    combined call (stable-fixes).
  - tpm: Compare HMAC values in constant time (stable-fixes).
  - dmaengine: ti: k3-udma: Enable second resource range for BCDMA
    and PKTDMA (stable-fixes).
  - commit 3e7d134

------------------------------------------------------------------
------------------  2026-1-30  -  Jan 30 2026  -------------------
------------------------------------------------------------------

++++ fde-tools:

  - Add fde-tools-bsc1248516-tpm-Support-persistent-SRK.patch to
    support persistent SRK (bsc#1248516)

++++ haproxy:

  - haproxy bad test for for legacy applets (bsc#1257521)
    BUG/MEDIUM: applet: Fix test on shut flags for legacy applets
    BUG/MAJOR: applet: Don't call I/O handler if the applet was shut
    Apply upstream patch:
    0001-BUG-MEDIUM-applet-Fix-test-on-shut-flags-for-legacy.patch

++++ kernel-default:

  - io_uring/poll: correctly handle io_poll_add() return value on
    update (CVE-2025-71149 bsc#1257164).
  - commit 0d997be
  - dm-snapshot: fix 'scheduling while atomic' on real-time kernels
    (git-fixes).
  - commit b3fc112
  - dm-bufio: align write boundary on physical block size
    (git-fixes).
  - commit e8ab2ba
  - dm-ebs: Mark full buffer dirty even on partial write
    (git-fixes).
  - commit b6359d7
  - dm-verity: disable recursive forward error correction
    (CVE-2025-71161, bsc#1257174).
  - commit 94c6d56
  - virt: tdx-guest: Transition to scoped_cond_guard for mutex operations (bsc#1257504).
  - commit a7ecc0e
  - virt: tdx-guest: Refactor and streamline TDREPORT generation (bsc#1257504).
  - commit 372915e
  - virt: tdx-guest: Expose TDX MRs as sysfs attributes (bsc#1257504).
  - commit af47cfb
  - x86/tdx: tdx_mcall_get_report0: Return -EBUSY on TDCALL_OPERAND_BUSY  error (bsc#1257504).
  - commit 2590e39
  - x86/tdx: Add tdx_mcall_extend_rtmr() interface (bsc#1257504).
  - commit 4b01fb9
  - tsm-mr: Add tsm-mr sample code (bsc#1257504).
  - commit bca5c7b
  - tsm-mr: Add TVM Measurement Register support (bsc#1257504).
  - commit a919cc1
  - macvlan: fix possible UAF in macvlan_forward_source()
    (CVE-2026-23001 bsc#1257232).
  - net: mscc: ocelot: Fix crash when adding interface under a lag
    (CVE-2026-22982 bsc#1257179).
  - net/handshake: restore destructor on submit failure
    (CVE-2025-71148 bsc#1257159).
  - commit e5558d8
  - net/sched: sch_qfq: do not free existing class in
    qfq_change_class() (CVE-2026-22999 bsc#1257236).
  - commit 79bc198
  - ipv4: ip_gre: make ipgre_header() robust (CVE-2026-23011
    bsc#1257207).
  - commit 26b5de2
  - Revert "mtd: spinand: esmt: fix id code for F50D1G41LB"
    (stable-fixes).
  - wifi: mac80211: correctly decode TTLM with default link map
    (git-fixes).
  - net: phy: micrel: fix clk warning when removing the driver
    (git-fixes).
  - nfc: nci: Fix race between rfkill and nci_unregister_device()
    (git-fixes).
  - nfc: llcp: Fix memleak in nfc_llcp_send_ui_frame() (git-fixes).
  - net: wwan: t7xx: fix potential skb->frags overflow in RX path
    (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
    (git-fixes).
  - can: at91_can: Fix memory leak in at91_can_probe() (git-fixes).
  - Bluetooth: MGMT: Fix memory leak in set_ssp_complete
    (git-fixes).
  - Bluetooth: hci_uart: fix null-ptr-deref in hci_uart_write_work
    (git-fixes).
  - tpm2-sessions: Fix tpm2_read_public range checks (git-fixes).
  - commit 46e120b

++++ kernel-rt:

  - io_uring/poll: correctly handle io_poll_add() return value on
    update (CVE-2025-71149 bsc#1257164).
  - commit 0d997be
  - dm-snapshot: fix 'scheduling while atomic' on real-time kernels
    (git-fixes).
  - commit b3fc112
  - dm-bufio: align write boundary on physical block size
    (git-fixes).
  - commit e8ab2ba
  - dm-ebs: Mark full buffer dirty even on partial write
    (git-fixes).
  - commit b6359d7
  - dm-verity: disable recursive forward error correction
    (CVE-2025-71161, bsc#1257174).
  - commit 94c6d56
  - virt: tdx-guest: Transition to scoped_cond_guard for mutex operations (bsc#1257504).
  - commit a7ecc0e
  - virt: tdx-guest: Refactor and streamline TDREPORT generation (bsc#1257504).
  - commit 372915e
  - virt: tdx-guest: Expose TDX MRs as sysfs attributes (bsc#1257504).
  - commit af47cfb
  - x86/tdx: tdx_mcall_get_report0: Return -EBUSY on TDCALL_OPERAND_BUSY  error (bsc#1257504).
  - commit 2590e39
  - x86/tdx: Add tdx_mcall_extend_rtmr() interface (bsc#1257504).
  - commit 4b01fb9
  - tsm-mr: Add tsm-mr sample code (bsc#1257504).
  - commit bca5c7b
  - tsm-mr: Add TVM Measurement Register support (bsc#1257504).
  - commit a919cc1
  - macvlan: fix possible UAF in macvlan_forward_source()
    (CVE-2026-23001 bsc#1257232).
  - net: mscc: ocelot: Fix crash when adding interface under a lag
    (CVE-2026-22982 bsc#1257179).
  - net/handshake: restore destructor on submit failure
    (CVE-2025-71148 bsc#1257159).
  - commit e5558d8
  - net/sched: sch_qfq: do not free existing class in
    qfq_change_class() (CVE-2026-22999 bsc#1257236).
  - commit 79bc198
  - ipv4: ip_gre: make ipgre_header() robust (CVE-2026-23011
    bsc#1257207).
  - commit 26b5de2
  - Revert "mtd: spinand: esmt: fix id code for F50D1G41LB"
    (stable-fixes).
  - wifi: mac80211: correctly decode TTLM with default link map
    (git-fixes).
  - net: phy: micrel: fix clk warning when removing the driver
    (git-fixes).
  - nfc: nci: Fix race between rfkill and nci_unregister_device()
    (git-fixes).
  - nfc: llcp: Fix memleak in nfc_llcp_send_ui_frame() (git-fixes).
  - net: wwan: t7xx: fix potential skb->frags overflow in RX path
    (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): fix error message
    (git-fixes).
  - can: at91_can: Fix memory leak in at91_can_probe() (git-fixes).
  - Bluetooth: MGMT: Fix memory leak in set_ssp_complete
    (git-fixes).
  - Bluetooth: hci_uart: fix null-ptr-deref in hci_uart_write_work
    (git-fixes).
  - tpm2-sessions: Fix tpm2_read_public range checks (git-fixes).
  - commit 46e120b

------------------------------------------------------------------
------------------  2026-1-29  -  Jan 29 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: storvsc: Process unsupported MODE_SENSE_10 (bsc#1257296).
  - Add bugnumber to an existing hv_netvsc change (bsc#1257473).
  - commit 6b4816a
  - Refresh patches.kabi/tpm2-sessions-kabi-workaround.patch
    Suppress compiler warnings due to missing prototypes.
  - commit e9a2f19
  - idpf: Fix RSS LUT NULL ptr issue after soft reset
    (CVE-2026-22993 bsc#1257180).
  - idpf: Fix RSS LUT NULL pointer crash on early ethtool operations
    (CVE-2026-22993 bsc#1257180).
  - gve: defer interrupt enabling until NAPI registration
    (CVE-2025-71156 bsc#1257167).
  - mlxbf_gige: emit messages during open and probe failures
    (git-fixes).
  - mlxbf_gige: return EPROBE_DEFER if PHY IRQ is not available
    (git-fixes).
  - commit 247473b
  - ipv6: BUG() in pskb_expand_head() as part of
    calipso_skbuff_setattr() (CVE-2025-71085 bsc#1256623).
  - commit 5565f0e
  - mptcp: fallback earlier on simult connection (CVE-2025-71088
    bsc#1256630).
  - commit 38b098b
  - RDMA/core: always drop device refcount in ib_del_sub_device_and_put() (CVE-2025-71157 bsc#1257168)
  - commit 7027c8b
  - =?UTF-8?q?net:=20phy:=20Introduce=20PHY=5FID=5FSIZE=20?=
    =?UTF-8?q?=E2=80=94=20minimum=20size=20for=20PHY=20ID=20string?=
    (CVE-2025-71094 bsc#1256597).
  - commit d8e9577
  - kabi: export inet_frag_rbtree_purge() function again
    (CVE-2025-68768 bsc#1256579).
  - commit e7cc137
  - inet: frags: flush pending skbs in fqdir_pre_exit()
    (CVE-2025-68768 bsc#1256579).
  - inet: frags: add inet_frag_queue_flush() (CVE-2025-68768
    bsc#1256579).
  - commit 7956a17
  - net/sched: ets: Remove drr class from the active list if it
    changes to strict (CVE-2025-68815 bsc#1256680).
  - commit ef2665d
  - net/sched: ets: Always remove class from active list before
    deleting in ets_qdisc_change (CVE-2025-71066 bsc#1256645).
  - commit 19d5700

++++ kernel-rt:

  - scsi: storvsc: Process unsupported MODE_SENSE_10 (bsc#1257296).
  - Add bugnumber to an existing hv_netvsc change (bsc#1257473).
  - commit 6b4816a
  - Refresh patches.kabi/tpm2-sessions-kabi-workaround.patch
    Suppress compiler warnings due to missing prototypes.
  - commit e9a2f19
  - idpf: Fix RSS LUT NULL ptr issue after soft reset
    (CVE-2026-22993 bsc#1257180).
  - idpf: Fix RSS LUT NULL pointer crash on early ethtool operations
    (CVE-2026-22993 bsc#1257180).
  - gve: defer interrupt enabling until NAPI registration
    (CVE-2025-71156 bsc#1257167).
  - mlxbf_gige: emit messages during open and probe failures
    (git-fixes).
  - mlxbf_gige: return EPROBE_DEFER if PHY IRQ is not available
    (git-fixes).
  - commit 247473b
  - ipv6: BUG() in pskb_expand_head() as part of
    calipso_skbuff_setattr() (CVE-2025-71085 bsc#1256623).
  - commit 5565f0e
  - mptcp: fallback earlier on simult connection (CVE-2025-71088
    bsc#1256630).
  - commit 38b098b
  - RDMA/core: always drop device refcount in ib_del_sub_device_and_put() (CVE-2025-71157 bsc#1257168)
  - commit 7027c8b
  - =?UTF-8?q?net:=20phy:=20Introduce=20PHY=5FID=5FSIZE=20?=
    =?UTF-8?q?=E2=80=94=20minimum=20size=20for=20PHY=20ID=20string?=
    (CVE-2025-71094 bsc#1256597).
  - commit d8e9577
  - kabi: export inet_frag_rbtree_purge() function again
    (CVE-2025-68768 bsc#1256579).
  - commit e7cc137
  - inet: frags: flush pending skbs in fqdir_pre_exit()
    (CVE-2025-68768 bsc#1256579).
  - inet: frags: add inet_frag_queue_flush() (CVE-2025-68768
    bsc#1256579).
  - commit 7956a17
  - net/sched: ets: Remove drr class from the active list if it
    changes to strict (CVE-2025-68815 bsc#1256680).
  - commit ef2665d
  - net/sched: ets: Always remove class from active list before
    deleting in ets_qdisc_change (CVE-2025-71066 bsc#1256645).
  - commit 19d5700

++++ libzypp:

  - Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros.
    See the ZYPP.CONF(5) man page for details.
  - Fix runtime check for broken rpm --runposttrans (bsc#1257068)
  - version 17.38.2 (35)

++++ nvidia-open-driver-G06-signed:

  - apply kernel-5.14.patch also on sle15-sp5 in order to fix build
    and adjusted it to sle15-sp5 kernel

++++ podman:

  - Add symlink to catatonit in /usr/libexec/podman (bsc#1248988)

++++ qemu:

  - Fix bsc#1257474:
    * ui/vdagent: remove migration blocker (bsc#1257474)
    * ui/vdagent: add migration support (bsc#1257474)
    * ui/vdagent: factor out clipboard peer registration (bsc#1257474)
    * ui/vdagent: keep "connected" state (bsc#1257474)
    * ui/vdagent: replace Buffer with GByteArray (bsc#1257474)
    * ui/clipboard: delay clipboard update when not running (bsc#1257474)
    * ui/clipboard: add vmstate_cbinfo (bsc#1257474)
    * ui/clipboard: split out QemuClipboardContent (bsc#1257474)
    * ui/clipboard: use int for selection field (bsc#1257474)
    * ui/gtk: warn if setting the clipboard failed (bsc#1257474)
  - Bug and spec file fixes:
    * hw/i386/kvm: fix PIRQ bounds check in xen_physdev_map_pirq() (bsc#1256484, CVE-2026-0665)
    * [openSUSE][RPM] spec: require qemu-hw-display-virtio-gpu-pci for x86 too

++++ syslinux:

  - bsc#1257495: NASM (3.00+) requires explicit size hints
    Add syslinux-4.04-size.patch

------------------------------------------------------------------
------------------  2026-1-28  -  Jan 28 2026  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update dependencies for bsc#1257324/CVE-2025-13465

++++ librsvg:

  - Update to version 2.60.2:
    + Fix the check for the cargo-cbuild version.

++++ gpg2:

  - Security fix
    * [bsc#1257396, CVE-2026-24882]
  - gpg2: stack-based buffer overflow in TPM2 PKDECRYPT for TPM-backed RSA and ECC keys
  - Added gnupg-CVE-2026-24882.patch
    * [bsc#1257395, CVE-2026-24883]
  - gpg2: denial of service due to long signature packet length causing parse_signature to return success with sig->data[] set to a NULL value
  - Added gnupg-CVE-2026-24883.patch
  - Security fix [bsc#1256389] (gpg.fail/filename)
    * Added gnupg-accepts-path-separators-literal-data.patch
    * GnuPG Accepts Path Separators and Path Traversals in Literal Data

++++ kernel-default:

  - libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116 bsc#1256744).
  - commit ec226dd
  - net/sched: sch_qfq: Fix NULL deref when deactivating inactive
    aggregate in qfq_reset (CVE-2026-22976 bsc#1257035).
  - commit 9a83c42
  - net: usb: asix: validate PHY address before use (CVE-2025-71094
    bsc#1256597).
  - commit 1c268d0
  - net: usb: asix: ax88772: Increase phy_name size (CVE-2025-71094
    bsc#1256597).
  - commit 1a25880
  - selftests/bpf: ns_current_pid_tgid: Use test_progs's ns_
    feature (bsc#1255552 CVE-2025-68363).
  - selftests/bpf: tc_links/tc_opts: Unserialize tests (bsc#1255552
    CVE-2025-68363).
  - selftests/bpf: Optionally open a dedicated namespace to run
    test in it (CVE-2025-68363 bsc#1255552).
  - selftests/bpf: ns_current_pid_tgid: Rename the test function
    (bsc#1255552 CVE-2025-68363).
  - commit deba1cc
  - perf/x86/amd: Check event before enable to avoid GPF
    (bsc#1256689 CVE-2025-68798).
  - commit 599ecfb

++++ kernel-rt:

  - libceph: make decode_pool() more resilient against corrupted osdmaps (CVE-2025-71116 bsc#1256744).
  - commit ec226dd
  - net/sched: sch_qfq: Fix NULL deref when deactivating inactive
    aggregate in qfq_reset (CVE-2026-22976 bsc#1257035).
  - commit 9a83c42
  - net: usb: asix: validate PHY address before use (CVE-2025-71094
    bsc#1256597).
  - commit 1c268d0
  - net: usb: asix: ax88772: Increase phy_name size (CVE-2025-71094
    bsc#1256597).
  - commit 1a25880
  - selftests/bpf: ns_current_pid_tgid: Use test_progs's ns_
    feature (bsc#1255552 CVE-2025-68363).
  - selftests/bpf: tc_links/tc_opts: Unserialize tests (bsc#1255552
    CVE-2025-68363).
  - selftests/bpf: Optionally open a dedicated namespace to run
    test in it (CVE-2025-68363 bsc#1255552).
  - selftests/bpf: ns_current_pid_tgid: Rename the test function
    (bsc#1255552 CVE-2025-68363).
  - commit deba1cc
  - perf/x86/amd: Check event before enable to avoid GPF
    (bsc#1256689 CVE-2025-68798).
  - commit 599ecfb

++++ libpng16:

  - security update
  - added patches
    CVE-2025-28162 [bsc#1257364], memory leaks when running `pngimage`
    CVE-2025-28164 [bsc#1257365], memory leaks when running `pngimage`
    * libpng16-CVE-2025-28162,28164.patch

++++ python-gcemetadata:

  - Update to version 1.1.0 (jsc#PCT-590, jsc#PED-8945)
    + Add licenses option in identity command.

++++ regionServiceClientConfigGCE:

  - Update to version 5.1.0 (jsc#PCT-590)
    + Add licenses info in the metdata
  - Accomodate build setup

------------------------------------------------------------------
------------------  2026-1-27  -  Jan 27 2026  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Update dependencies for bsc#1257325/CVE-2025-13465
  - Update to 346
    * 346
  - Performance improvements
  - Translation updates
    * 345
  - New virtual machines don't get SPICE graphics anymore
  - Support for network port forwarding
  - Bug fixes and translation updates

++++ glib2:

  - Add CVE fixes:
    + glib2-CVE-2026-1484.patch (bsc#1257355 CVE-2026-1484
    glgo#GNOME/glib!4979).
    + glib2-CVE-2026-1485.patch (bsc#1257354 CVE-2026-1485
    glgo#GNOME/glib!4981).
    + glib2-CVE-2026-1489.patch (bsc#1257353 CVE-2026-1489
    glgo#GNOME/glib!4984).

++++ kernel-default:

  - selftests/bpf: Optionally open a dedicated namespace to run
    test in it (CVE-2025-68363 bsc#1255552).
  - commit 72f882c
  - btrfs: use variable for end offset in extent_writepage_io()
    (git-fixes).
  - commit b0ce396
  - btrfs: truncate ordered extent when skipping writeback past
    i_size (git-fixes).
  - commit 2d28056
  - btrfs: fix deadlock in wait_current_trans() due to ignored
    transaction type (git-fixes).
  - commit 58c1893
  - blk-cgroup: fix possible deadlock while configuring policy
    (CVE-2025-68178 bsc#1255266).
  - commit 39b8d0d
  - libbpf: Fix -Wdiscarded-qualifiers under C23 (bsc#1257309).
  - commit 123e6ba
  - scripts/cve_tools/kss-dashboard: --exportpatch: Skip commits that are in base kernel
  - commit ef59f5e
  - scripts/cve_tools/kss-dashboard: Simplify --exportpatch condition
    Use the filtering logic only once. (This changes warning messages when
    patch would have been both backported and blacklisted.)
    Fix insert_sereis comand when we end up with empty patch set.
  - commit d3bd915
  - bpf: Add bpf_prog_run_data_pointers() (bsc#1255241
    CVE-2025-68200).
  - commit 738511e

++++ kernel-rt:

  - selftests/bpf: Optionally open a dedicated namespace to run
    test in it (CVE-2025-68363 bsc#1255552).
  - commit 72f882c
  - btrfs: use variable for end offset in extent_writepage_io()
    (git-fixes).
  - commit b0ce396
  - btrfs: truncate ordered extent when skipping writeback past
    i_size (git-fixes).
  - commit 2d28056
  - btrfs: fix deadlock in wait_current_trans() due to ignored
    transaction type (git-fixes).
  - commit 58c1893
  - blk-cgroup: fix possible deadlock while configuring policy
    (CVE-2025-68178 bsc#1255266).
  - commit 39b8d0d
  - libbpf: Fix -Wdiscarded-qualifiers under C23 (bsc#1257309).
  - commit 123e6ba
  - scripts/cve_tools/kss-dashboard: --exportpatch: Skip commits that are in base kernel
  - commit ef59f5e
  - scripts/cve_tools/kss-dashboard: Simplify --exportpatch condition
    Use the filtering logic only once. (This changes warning messages when
    patch would have been both backported and blacklisted.)
    Fix insert_sereis comand when we end up with empty patch set.
  - commit d3bd915
  - bpf: Add bpf_prog_run_data_pointers() (bsc#1255241
    CVE-2025-68200).
  - commit 738511e

++++ openssl-3:

  - Security fixes:
    * Missing ASN1_TYPE validation in PKCS#12 parsing
  - openssl-CVE-2026-22795.patch [bsc#1256839, CVE-2026-22795]
    * ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function
  - openssl-CVE-2026-22795.patch [bsc#1256840, CVE-2026-22796]
    * Missing ASN1_TYPE validation in TS_RESP_verify_response() function
  - openssl-CVE-2025-69420.patch [bsc#1256837, CVE-2025-69420]
    * NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function
  - openssl-CVE-2025-69421.patch [bsc#1256838, CVE-2025-69421]
    * Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion
  - openssl-CVE-2025-69419.patch [bsc#1256836, CVE-2025-69419]
    * TLS 1.3 CompressedCertificate excessive memory allocation
  - openssl-CVE-2025-66199.patch [bsc#1256833, CVE-2025-66199]
    * Heap out-of-bounds write in BIO_f_linebuffer on short writes
  - openssl-CVE-2025-68160.patch [bsc#1256834, CVE-2025-68160]
    * Unauthenticated/unencrypted trailing bytes with low-level OCB function calls
  - openssl-CVE-2025-69418.patch [bsc#1256835, CVE-2025-69418]
    * 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB
  - openssl-CVE-2025-15469.patch [bsc#1256832, CVE-2025-15469]
    * Stack buffer overflow in CMS AuthEnvelopedData parsing
  - openssl-CVE-2025-15467.patch [bsc#1256830, CVE-2025-15467]
  - openssl-CVE-2025-15467-comments.patch
  - openssl-CVE-2025-15467-test.patch
    * Improper validation of PBMAC1 parameters in PKCS#12 MAC verification
  - openssl-CVE-2025-11187.patch [bsc#1256829, CVE-2025-11187]
    * NULL dereference in SSL_CIPHER_find() function on unknown cipher ID
  - openssl-CVE-2025-15468.patch [bsc#1256831, CVE-2025-15468]
  - Enable livepatching support for ppc64le [bsc#1257274]

++++ python313-core:

  - Add CVE-2024-6923-follow-up-EOL-email-headers.patch which is
    a follow-up to the previous fix of CVE-2024-6923 further
    encoding EOL possibly hidden in email headers (bsc#1257181).

++++ open-vm-tools:

  - update to 13.0.10 based on build 25056151: (boo#1257357):
    Please refer to the Release Notes at
    https://github.com/vmware/open-vm-tools/blob/stable-13.0.10/ReleaseNotes.md.
    The granular changes that have gone into the open-vm-tools
    13.0.10 release are in the ChangeLog at
    https://github.com/vmware/open-vm-tools/blob/stable-13.0.10/open-vm-tools/ChangeLog.
    There are no new features in the open-vm-tools 13.0.10 release.
    This is primarily a maintenance release that addresses a fix.
    A minor enhancement has been made for Guest OS Customization. The
    DeployPkg plugin has been updated to handle a new cloud-init
    error code that signals a recoverable error and allow cloud-init
    to finish running.
    For a more complete description of what's new in this release,
    see the What's New and Resolved Issues sections of the Release
    Notes.

++++ python313:

  - Add CVE-2024-6923-follow-up-EOL-email-headers.patch which is
    a follow-up to the previous fix of CVE-2024-6923 further
    encoding EOL possibly hidden in email headers (bsc#1257181).

------------------------------------------------------------------
------------------  2026-1-26  -  Jan 26 2026  -------------------
------------------------------------------------------------------

++++ hwinfo:

  - merge gh#openSUSE/hwinfo#175
  - include package spec file in git repo
  - adjust spec file for immutable mode: switch to using
    systemd-tmpfiles (jsc#PED-14832)
  - update git2log script
  - 25.1

++++ kernel-default:

  - smb: client: don't try following DFS links in
    cifs_tree_connect() (git-fixes).
  - commit 3cf926a
  - kABI workaround for tpm_chip changes (CVE-2025-71077
    bsc#1256613).
  - commit b25df62
  - e1000: fix OOB in e1000_tbi_should_accept() (CVE-2025-71093
    bsc#1256777).
  - net/mlx5: fw_tracer, Validate format string parameters
    (CVE-2025-68816 bsc#1256674).
  - commit 767a8ff
  - tpm: Cap the number of PCR banks (CVE-2025-71077 bsc#1256613).
  - Refresh
    patches.suse/0003-ima-invalidate-unsupported-PCR-banks.patch.
  - commit 3fdd7fa
  - gfs2: Prevent recursive memory reclaim (bsc#1255593
    CVE-2025-68356).
  - commit 798fe56
  - keys/trusted_keys: fix handle passed to tpm_buf_append_name
    during unseal (CVE-2025-68792 bsc#1256656).
  - commit 6ebc180
  - kABI workaround for tpm2_session changes (CVE-2025-68792
    bsc#1256656).
  - commit 7af0065
  - tpm2-sessions: Fix out of range indexing in name_size
    (CVE-2025-68792 bsc#1256656).
  - commit 2805234
  - x86: make page fault handling disable interrupts properly (git-fixes).
  - commit 8ec97c6
  - selftests: net: fib-onlink-tests: Convert to use namespaces
    by default (bsc#1255346).
  - commit 9f9ee4e
  - Delete
    patches.suse/selftests-net-fib-onlink-tests-Set-high-metric-for-d.patch.
  - commit 3ae01ff
  - exfat: check return value of sb_min_blocksize in
    exfat_read_boot_sector (git-fixes).
  - commit 3d9560f
  - pnfs/blocklayout: Fix memory leak in bl_parse_scsi()
    (git-fixes).
  - commit 25884fe
  - pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node()
    (git-fixes).
  - commit def5db6
  - pNFS: Fix a deadlock when returning a delegation during open()
    (git-fixes).
  - commit 39c05eb
  - nfsd: check that server is running in unlock_filesystem
    (git-fixes).
  - commit d20f2be
  - nfsd: use correct loop termination in nfsd4_revoke_states()
    (git-fixes).
  - commit bb91457
  - NFSD: Fix permission check for read access to executable-only
    files (git-fixes).
  - commit 183186b
  - nfsd: Drop the client reference in client_states_open()
    (git-fixes).
  - commit c888f17
  - NFSD/blocklayout: Fix minlength check in proc_layoutget
    (git-fixes).
  - commit b191678
  - NFSD: use correct reservation type in nfsd4_scsi_fence_client
    (git-fixes).
  - commit 9c83e59
  - svcrdma: return 0 on success from svc_rdma_copy_inline_range
    (git-fixes).
  - commit 029a31c
  - NFSD: Clear SECLABEL in the suppattr_exclcreat bitmap
    (git-fixes).
  - commit 5253399
  - NFS: Fix up the automount fs_context to use the correct cred
    (git-fixes).
  - commit 98b121a
  - NFSv4: ensure the open stateid seqid doesn't go backwards
    (git-fixes).
  - commit 15f5d8e
  - exfat: fix remount failure in different process environments
    (git-fixes).
  - commit 2a1614d
  - exfat: zero out post-EOF page cache on file extension
    (git-fixes).
  - commit b63526d
  - Update patch metadata and sort
    patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch.
  - commit 6b28e35
  - w1: fix redundant counter decrement in w1_attach_slave_device()
    (git-fixes).
  - w1: therm: Fix off-by-one buffer overflow in alarms_store
    (git-fixes).
  - comedi: dmm32at: serialize use of paged registers (git-fixes).
  - mei: trace: treat reg parameter as string (git-fixes).
  - uacce: ensure safe queue release with state management
    (git-fixes).
  - uacce: implement mremap in uacce_vm_ops to return -EPERM
    (git-fixes).
  - uacce: fix isolate sysfs check condition (git-fixes).
  - uacce: fix cdev handling in the cleanup path (git-fixes).
  - slimbus: core: fix of_slim_get_device() kernel doc (git-fixes).
  - slimbus: core: fix device reference leak on report present
    (git-fixes).
  - slimbus: core: fix runtime PM imbalance on report present
    (git-fixes).
  - slimbus: core: fix OF node leak on registration failure
    (git-fixes).
  - intel_th: fix device leak on output open() (git-fixes).
  - comedi: Fix getting range information for subdevices 16 to 255
    (git-fixes).
  - interconnect: debugfs: initialize src_node and dst_node to
    empty strings (git-fixes).
  - iio: accel: iis328dq: fix gain values (git-fixes).
  - iio: chemical: scd4x: fix reported channel endianness
    (git-fixes).
  - iio: dac: ad5686: add AD5695R to ad5686_chip_info_tbl
    (git-fixes).
  - iio: accel: adxl380: fix handling of unavailable "INT1"
    interrupt (git-fixes).
  - iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without
    event detection (git-fixes).
  - iio: adc: pac1934: Fix clamped value in pac1934_reg_snapshot
    (git-fixes).
  - iio: adc: ad9467: fix ad9434 vref mask (git-fixes).
  - iio: adc: ad7280a: handle spi_setup() errors in probe()
    (git-fixes).
  - iio: adc: at91-sama5d2_adc: Fix potential use-after-free in
    sama5d2_adc driver (git-fixes).
  - serial: 8250_pci: Fix broken RS485 for F81504/508/512
    (git-fixes).
  - comedi: fix divide-by-zero in comedi_buf_munge() (stable-fixes).
  - commit e39a507
  - bpf: Do not let BPF test infra emit invalid GSO types to stack
    (bsc#1255569).
  - commit 7eec89f

++++ kernel-rt:

  - smb: client: don't try following DFS links in
    cifs_tree_connect() (git-fixes).
  - commit 3cf926a
  - kABI workaround for tpm_chip changes (CVE-2025-71077
    bsc#1256613).
  - commit b25df62
  - e1000: fix OOB in e1000_tbi_should_accept() (CVE-2025-71093
    bsc#1256777).
  - net/mlx5: fw_tracer, Validate format string parameters
    (CVE-2025-68816 bsc#1256674).
  - commit 767a8ff
  - tpm: Cap the number of PCR banks (CVE-2025-71077 bsc#1256613).
  - Refresh
    patches.suse/0003-ima-invalidate-unsupported-PCR-banks.patch.
  - commit 3fdd7fa
  - gfs2: Prevent recursive memory reclaim (bsc#1255593
    CVE-2025-68356).
  - commit 798fe56
  - keys/trusted_keys: fix handle passed to tpm_buf_append_name
    during unseal (CVE-2025-68792 bsc#1256656).
  - commit 6ebc180
  - kABI workaround for tpm2_session changes (CVE-2025-68792
    bsc#1256656).
  - commit 7af0065
  - tpm2-sessions: Fix out of range indexing in name_size
    (CVE-2025-68792 bsc#1256656).
  - commit 2805234
  - x86: make page fault handling disable interrupts properly (git-fixes).
  - commit 8ec97c6
  - selftests: net: fib-onlink-tests: Convert to use namespaces
    by default (bsc#1255346).
  - commit 9f9ee4e
  - Delete
    patches.suse/selftests-net-fib-onlink-tests-Set-high-metric-for-d.patch.
  - commit 3ae01ff
  - exfat: check return value of sb_min_blocksize in
    exfat_read_boot_sector (git-fixes).
  - commit 3d9560f
  - pnfs/blocklayout: Fix memory leak in bl_parse_scsi()
    (git-fixes).
  - commit 25884fe
  - pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node()
    (git-fixes).
  - commit def5db6
  - pNFS: Fix a deadlock when returning a delegation during open()
    (git-fixes).
  - commit 39c05eb
  - nfsd: check that server is running in unlock_filesystem
    (git-fixes).
  - commit d20f2be
  - nfsd: use correct loop termination in nfsd4_revoke_states()
    (git-fixes).
  - commit bb91457
  - NFSD: Fix permission check for read access to executable-only
    files (git-fixes).
  - commit 183186b
  - nfsd: Drop the client reference in client_states_open()
    (git-fixes).
  - commit c888f17
  - NFSD/blocklayout: Fix minlength check in proc_layoutget
    (git-fixes).
  - commit b191678
  - NFSD: use correct reservation type in nfsd4_scsi_fence_client
    (git-fixes).
  - commit 9c83e59
  - svcrdma: return 0 on success from svc_rdma_copy_inline_range
    (git-fixes).
  - commit 029a31c
  - NFSD: Clear SECLABEL in the suppattr_exclcreat bitmap
    (git-fixes).
  - commit 5253399
  - NFS: Fix up the automount fs_context to use the correct cred
    (git-fixes).
  - commit 98b121a
  - NFSv4: ensure the open stateid seqid doesn't go backwards
    (git-fixes).
  - commit 15f5d8e
  - exfat: fix remount failure in different process environments
    (git-fixes).
  - commit 2a1614d
  - exfat: zero out post-EOF page cache on file extension
    (git-fixes).
  - commit b63526d
  - Update patch metadata and sort
    patches.suse/sched-fair-Disable-scheduler-feature-NEXT_BUDDY.patch.
  - commit 6b28e35
  - w1: fix redundant counter decrement in w1_attach_slave_device()
    (git-fixes).
  - w1: therm: Fix off-by-one buffer overflow in alarms_store
    (git-fixes).
  - comedi: dmm32at: serialize use of paged registers (git-fixes).
  - mei: trace: treat reg parameter as string (git-fixes).
  - uacce: ensure safe queue release with state management
    (git-fixes).
  - uacce: implement mremap in uacce_vm_ops to return -EPERM
    (git-fixes).
  - uacce: fix isolate sysfs check condition (git-fixes).
  - uacce: fix cdev handling in the cleanup path (git-fixes).
  - slimbus: core: fix of_slim_get_device() kernel doc (git-fixes).
  - slimbus: core: fix device reference leak on report present
    (git-fixes).
  - slimbus: core: fix runtime PM imbalance on report present
    (git-fixes).
  - slimbus: core: fix OF node leak on registration failure
    (git-fixes).
  - intel_th: fix device leak on output open() (git-fixes).
  - comedi: Fix getting range information for subdevices 16 to 255
    (git-fixes).
  - interconnect: debugfs: initialize src_node and dst_node to
    empty strings (git-fixes).
  - iio: accel: iis328dq: fix gain values (git-fixes).
  - iio: chemical: scd4x: fix reported channel endianness
    (git-fixes).
  - iio: dac: ad5686: add AD5695R to ad5686_chip_info_tbl
    (git-fixes).
  - iio: accel: adxl380: fix handling of unavailable "INT1"
    interrupt (git-fixes).
  - iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without
    event detection (git-fixes).
  - iio: adc: pac1934: Fix clamped value in pac1934_reg_snapshot
    (git-fixes).
  - iio: adc: ad9467: fix ad9434 vref mask (git-fixes).
  - iio: adc: ad7280a: handle spi_setup() errors in probe()
    (git-fixes).
  - iio: adc: at91-sama5d2_adc: Fix potential use-after-free in
    sama5d2_adc driver (git-fixes).
  - serial: 8250_pci: Fix broken RS485 for F81504/508/512
    (git-fixes).
  - comedi: fix divide-by-zero in comedi_buf_munge() (stable-fixes).
  - commit e39a507
  - bpf: Do not let BPF test infra emit invalid GSO types to stack
    (bsc#1255569).
  - commit 7eec89f

++++ multipath-tools:

  - Update to version 0.12.2+254+suse.924a3ed8:
  - Bug fixes from 0.12.2 (bsc#1257007, see NEWS.md for details)
    * kpartx: fix segfault when operating on regular files
    (bsc#1257244, bsc#1257153)
    * multipathd: print path offline message even without a checker
    (bsc#1254094)
    * Fix `mpathpersist --report-capabilities` output.
    * Fix command descriptions in the multipathd man page.
    * Fix ISO C23 compatibility issue causing errors with new compilers.
    * Fix memory leak caused by not joining the "init unwinder" thread.
    * Fix memory leaks in kpartx.
    * Print the warning "setting scsi timeouts is unsupported for protocol" only
    once per protocol.
    * Make sure multipath-tools is compiled with the compiler flag
    `-fno-strict-aliasing`. (gh#opensvc/multipath-tools#130, bsc#1255285)
  - Features from upstream 0.12.0 (see also NEWS.md):
    * Maps that were added outside of multipathd (e.g. using the **multipath**
    command) and that couldn't be reloaded by multipathd used to be ignored
    by multipathd. multipathd will now monitor them. If some paths were
    offline while the map was created, multipathd will now add them to the
    map when they go online again.
    * multipathd retries persistent reservation commands that have failed on one
    path on another one.
  - Documentation fixes
  - Additions to the hardware table

++++ opensuse-migration-tool:

  - Add dependency on update-bootloader to fix boo#1255897
    pattern-base-selinux could be skipped if update-bootloader was missing

++++ pcr-oracle:

  - Enable build on %{arm} as it is required by sdbootutil

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#194
  - adjust spec file for immutable mode: switch to using
    systemd-tmpfiles (jsc#PED-14833)
  - 1.27

------------------------------------------------------------------
------------------  2026-1-24  -  Jan 24 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - platform/x86: hp-bioscfg: Fix automatic module loading
    (git-fixes).
  - platform/x86: hp-bioscfg: Fix kernel panic in GET_INSTANCE_ID
    macro (git-fixes).
  - platform/x86: hp-bioscfg: Fix kobject warnings for empty
    attribute names (git-fixes).
  - platform/x86/amd: Fix memory leak in wbrf_record() (git-fixes).
  - mmc: rtsx_pci_sdmmc: implement sdmmc_card_busy function
    (git-fixes).
  - mmc: sdhci-of-dwcmshc: Prevent illegal clock reduction in
    HS200/HS400 mode (git-fixes).
  - regmap: Fix race condition in hwspinlock irqsave routine
    (git-fixes).
  - gpio: cdev: Correct return code on memory allocation failure
    (git-fixes).
  - ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free()
    (git-fixes).
  - ALSA: scarlett2: Fix buffer overflow in config retrieval
    (git-fixes).
  - ALSA: usb: Increase volume range that triggers a warning
    (git-fixes).
  - drm/amd/pm: Workaround SI powertune issue on Radeon 430 (v2)
    (git-fixes).
  - drm/amd/pm: Don't clear SI SMC table when setting power limit
    (git-fixes).
  - drm/nouveau: implement missing DCB connector types; gracefully
    handle unknown connectors (git-fixes).
  - drm/nouveau: add missing DCB connector types (git-fixes).
  - drm/imagination: Wait for FW trace update command completion
    (git-fixes).
  - commit a8c0274

++++ kernel-rt:

  - platform/x86: hp-bioscfg: Fix automatic module loading
    (git-fixes).
  - platform/x86: hp-bioscfg: Fix kernel panic in GET_INSTANCE_ID
    macro (git-fixes).
  - platform/x86: hp-bioscfg: Fix kobject warnings for empty
    attribute names (git-fixes).
  - platform/x86/amd: Fix memory leak in wbrf_record() (git-fixes).
  - mmc: rtsx_pci_sdmmc: implement sdmmc_card_busy function
    (git-fixes).
  - mmc: sdhci-of-dwcmshc: Prevent illegal clock reduction in
    HS200/HS400 mode (git-fixes).
  - regmap: Fix race condition in hwspinlock irqsave routine
    (git-fixes).
  - gpio: cdev: Correct return code on memory allocation failure
    (git-fixes).
  - ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free()
    (git-fixes).
  - ALSA: scarlett2: Fix buffer overflow in config retrieval
    (git-fixes).
  - ALSA: usb: Increase volume range that triggers a warning
    (git-fixes).
  - drm/amd/pm: Workaround SI powertune issue on Radeon 430 (v2)
    (git-fixes).
  - drm/amd/pm: Don't clear SI SMC table when setting power limit
    (git-fixes).
  - drm/nouveau: implement missing DCB connector types; gracefully
    handle unknown connectors (git-fixes).
  - drm/nouveau: add missing DCB connector types (git-fixes).
  - drm/imagination: Wait for FW trace update command completion
    (git-fixes).
  - commit a8c0274

------------------------------------------------------------------
------------------  2026-1-23  -  Jan 23 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - phy: freescale: imx8m-pcie: assert phy reset during power on
    (stable-fixes).
  - phy: rockchip: inno-usb2: Fix a double free bug in
    rockchip_usb2phy_probe() (git-fixes).
  - USB: serial: ftdi_sio: add support for PICAXE AXE027 cable
    (stable-fixes).
  - USB: serial: option: add Telit LE910 MBIM composition
    (stable-fixes).
  - USB: OHCI/UHCI: Add soft dependencies on ehci_platform
    (stable-fixes).
  - usb: core: add USB_QUIRK_NO_BOS for devices that hang on BOS
    descriptor (stable-fixes).
  - usb: dwc3: Check for USB4 IP_NAME (stable-fixes).
  - drm/amd/pm: fix smu overdrive data type wrong issue on smu
    14.0.2 (git-fixes).
  - drm/amd/display: Bump the HDMI clock to 340MHz (stable-fixes).
  - drm/amd: Clean up kfd node on surprise disconnect
    (stable-fixes).
  - HID: usbhid: paper over wrong bNumDescriptor field
    (stable-fixes).
  - firmware: imx: scu-irq: Set mu_resource_id before get handle
    (stable-fixes).
  - phy: phy-rockchip-inno-usb2: Use dev_err_probe() in the probe
    path (stable-fixes).
  - commit 3f8bd8a
  - io_uring: fix filename leak in __io_openat_prep()
    (CVE-2025-68814 bsc#1256651).
  - commit 675d22e
  - octeontx2-pf: fix "UBSAN: shift-out-of-bounds error" (CVE-2025-71137 bsc#1256760)
  - commit 3d4407e
  - net: hns3: using the num_tqps in the vf driver to apply for resources (CVE-2025-71064 bsc#1256654)
  - commit 58ee56d
  - macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse (CVE-2025-68367 bsc#1255547)
  - commit ed9e7a9
  - team: fix check for port enabled in team_queue_override_port_prio_changed() (CVE-2025-71091 bsc#1256773)
  - commit c426951
  - md/raid5: fix possible null-pointer dereferences in
    raid5_store_group_thread_cnt() (CVE-2025-71135 bsc#1256761).
  - commit 1fc61fc
  - net: sock: fix hardened usercopy panic in sock_recv_errqueue
    (CVE-2026-22977 bsc#1257053).
  - commit d4fc6df
  - ipv4: Fix reference count leak when using error routes with
    nexthop objects (CVE-2025-71097 bsc#1256607).
  - net: stmmac: fix the crash issue for zero copy XDP_TX action
    (CVE-2025-71095 bsc#1256605).
  - net: hns3: add VLAN id validation before using (CVE-2025-71112
    bsc#1256726).
  - net/handshake: duplicate handshake cancellations leak socket
    (CVE-2025-68775 bsc#1256665).
  - ethtool: Avoid overflowing userspace buffer on stats query
    (CVE-2025-68795 bsc#1256688).
  - mptcp: avoid deadlock on fallback while reinjecting
    (CVE-2025-71126 bsc#1256755).
  - bnxt_en: Fix XDP_TX path (CVE-2025-68770 bsc#1256584).
  - mlxsw: spectrum_mr: Fix use-after-free when updating multicast
    route stats (CVE-2025-68800 bsc#1256646).
  - mlxsw: spectrum_router: Fix neighbour use-after-free
    (CVE-2025-68801 bsc#1256653).
  - lan966x: Fix sleeping in atomic context (CVE-2025-68320
    bsc#1255172).
  - commit 4e1af62
  - iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089
    bsc#1256612).
  - commit 2eb2757
  - dpll: Prevent duplicate registrations (git-fixes).
  - dpll: zl3073x: Fix output pin registration (git-fixes).
  - dpll: fix device-id-get and pin-id-get to return errors properly
    (git-fixes).
  - dpll: spec: add missing module-name and clock-id to pin-get
    reply (git-fixes).
  - dpll: fix clock quality level reporting (git-fixes).
  - dpll: Add an assertion to check freq_supported_num
    (stable-fixes).
  - commit 59f0fdc
  - crypto: authencesn - reject too-short AAD (assoclen<8) to
    match ESP/ESN spec (git-fixes).
  - wifi: mac80211: don't perform DA check on S1G beacon
    (git-fixes).
  - wifi: ath12k: fix dma_free_coherent() pointer (git-fixes).
  - wifi: ath10k: fix dma_free_coherent() pointer (git-fixes).
  - wifi: mwifiex: Fix a loop in mwifiex_update_ampdu_rxwinsize()
    (git-fixes).
  - wifi: rsi: Fix memory corruption due to not set vif driver
    data size (git-fixes).
  - usbnet: limit max_mtu based on device's hard_mtu (git-fixes).
  - can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory
    leak (git-fixes).
  - can: mcba_usb: mcba_usb_read_bulk_callback(): fix URB memory
    leak (git-fixes).
  - can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB
    memory leak (git-fixes).
  - can: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak
    (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on
    usb_submit_urb() error (git-fixes).
  - Revert "nfc/nci: Add the inconsistency check between the input
    data length and count" (git-fixes).
  - net: usb: dm9601: remove broken SR9700 support (git-fixes).
  - leds: led-class: Only Add LED to leds_list when it is fully
    ready (git-fixes).
  - commit d5d2445

++++ kernel-rt:

  - phy: freescale: imx8m-pcie: assert phy reset during power on
    (stable-fixes).
  - phy: rockchip: inno-usb2: Fix a double free bug in
    rockchip_usb2phy_probe() (git-fixes).
  - USB: serial: ftdi_sio: add support for PICAXE AXE027 cable
    (stable-fixes).
  - USB: serial: option: add Telit LE910 MBIM composition
    (stable-fixes).
  - USB: OHCI/UHCI: Add soft dependencies on ehci_platform
    (stable-fixes).
  - usb: core: add USB_QUIRK_NO_BOS for devices that hang on BOS
    descriptor (stable-fixes).
  - usb: dwc3: Check for USB4 IP_NAME (stable-fixes).
  - drm/amd/pm: fix smu overdrive data type wrong issue on smu
    14.0.2 (git-fixes).
  - drm/amd/display: Bump the HDMI clock to 340MHz (stable-fixes).
  - drm/amd: Clean up kfd node on surprise disconnect
    (stable-fixes).
  - HID: usbhid: paper over wrong bNumDescriptor field
    (stable-fixes).
  - firmware: imx: scu-irq: Set mu_resource_id before get handle
    (stable-fixes).
  - phy: phy-rockchip-inno-usb2: Use dev_err_probe() in the probe
    path (stable-fixes).
  - commit 3f8bd8a
  - io_uring: fix filename leak in __io_openat_prep()
    (CVE-2025-68814 bsc#1256651).
  - commit 675d22e
  - octeontx2-pf: fix "UBSAN: shift-out-of-bounds error" (CVE-2025-71137 bsc#1256760)
  - commit 3d4407e
  - net: hns3: using the num_tqps in the vf driver to apply for resources (CVE-2025-71064 bsc#1256654)
  - commit 58ee56d
  - macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse (CVE-2025-68367 bsc#1255547)
  - commit ed9e7a9
  - team: fix check for port enabled in team_queue_override_port_prio_changed() (CVE-2025-71091 bsc#1256773)
  - commit c426951
  - md/raid5: fix possible null-pointer dereferences in
    raid5_store_group_thread_cnt() (CVE-2025-71135 bsc#1256761).
  - commit 1fc61fc
  - net: sock: fix hardened usercopy panic in sock_recv_errqueue
    (CVE-2026-22977 bsc#1257053).
  - commit d4fc6df
  - ipv4: Fix reference count leak when using error routes with
    nexthop objects (CVE-2025-71097 bsc#1256607).
  - net: stmmac: fix the crash issue for zero copy XDP_TX action
    (CVE-2025-71095 bsc#1256605).
  - net: hns3: add VLAN id validation before using (CVE-2025-71112
    bsc#1256726).
  - net/handshake: duplicate handshake cancellations leak socket
    (CVE-2025-68775 bsc#1256665).
  - ethtool: Avoid overflowing userspace buffer on stats query
    (CVE-2025-68795 bsc#1256688).
  - mptcp: avoid deadlock on fallback while reinjecting
    (CVE-2025-71126 bsc#1256755).
  - bnxt_en: Fix XDP_TX path (CVE-2025-68770 bsc#1256584).
  - mlxsw: spectrum_mr: Fix use-after-free when updating multicast
    route stats (CVE-2025-68800 bsc#1256646).
  - mlxsw: spectrum_router: Fix neighbour use-after-free
    (CVE-2025-68801 bsc#1256653).
  - lan966x: Fix sleeping in atomic context (CVE-2025-68320
    bsc#1255172).
  - commit 4e1af62
  - iommu: disable SVA when CONFIG_X86 is set (CVE-2025-71089
    bsc#1256612).
  - commit 2eb2757
  - dpll: Prevent duplicate registrations (git-fixes).
  - dpll: zl3073x: Fix output pin registration (git-fixes).
  - dpll: fix device-id-get and pin-id-get to return errors properly
    (git-fixes).
  - dpll: spec: add missing module-name and clock-id to pin-get
    reply (git-fixes).
  - dpll: fix clock quality level reporting (git-fixes).
  - dpll: Add an assertion to check freq_supported_num
    (stable-fixes).
  - commit 59f0fdc
  - crypto: authencesn - reject too-short AAD (assoclen<8) to
    match ESP/ESN spec (git-fixes).
  - wifi: mac80211: don't perform DA check on S1G beacon
    (git-fixes).
  - wifi: ath12k: fix dma_free_coherent() pointer (git-fixes).
  - wifi: ath10k: fix dma_free_coherent() pointer (git-fixes).
  - wifi: mwifiex: Fix a loop in mwifiex_update_ampdu_rxwinsize()
    (git-fixes).
  - wifi: rsi: Fix memory corruption due to not set vif driver
    data size (git-fixes).
  - usbnet: limit max_mtu based on device's hard_mtu (git-fixes).
  - can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory
    leak (git-fixes).
  - can: mcba_usb: mcba_usb_read_bulk_callback(): fix URB memory
    leak (git-fixes).
  - can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB
    memory leak (git-fixes).
  - can: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak
    (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on
    usb_submit_urb() error (git-fixes).
  - Revert "nfc/nci: Add the inconsistency check between the input
    data length and count" (git-fixes).
  - net: usb: dm9601: remove broken SR9700 support (git-fixes).
  - leds: led-class: Only Add LED to leds_list when it is fully
    ready (git-fixes).
  - commit d5d2445

------------------------------------------------------------------
------------------  2026-1-22  -  Jan 22 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - mptcp: fix a race in mptcp_pm_del_add_timer() (CVE-2025-40257
    bsc#1254842).
  - commit dab52b4
  - net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop
    (CVE-2025-68325 bsc#1255417).
  - commit 1f83ea8
  - tcp: use dst_dev_rcu() in
    tcp_fastopen_active_disable_ofo_check() (CVE-2025-68188
    bsc#1255269).
  - commit 46ce97a

++++ kernel-rt:

  - mptcp: fix a race in mptcp_pm_del_add_timer() (CVE-2025-40257
    bsc#1254842).
  - commit dab52b4
  - net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop
    (CVE-2025-68325 bsc#1255417).
  - commit 1f83ea8
  - tcp: use dst_dev_rcu() in
    tcp_fastopen_active_disable_ofo_check() (CVE-2025-68188
    bsc#1255269).
  - commit 46ce97a

++++ sqlite3:

  - Update to version 3.51.2:
    * bsc#1259619, CVE-2025-70873: zipfile extension may disclose
    uninitialized heap memory during inflation.
    * Fix an obscure deadlock in the new broken-posix-lock detection
    logic.
    * Fix multiple problems in the EXISTS-to-JOIN optimization.
    * Other minor bug fixes.

++++ libxml2:

  - CVE-2026-0989: call stack exhaustion leading to application crash
    due to RelaxNG parser not limiting the recursion depth when
    resolving `<include>` directives (bsc#1256804, bsc#1256805, bsc#1256810)
    * Add patch libxml2-CVE-2026-0989.patch
    * https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374

++++ libxml2-python:

  - CVE-2026-0989: call stack exhaustion leading to application crash
    due to RelaxNG parser not limiting the recursion depth when
    resolving `<include>` directives (bsc#1256804, bsc#1256805, bsc#1256810)
    * Add patch libxml2-CVE-2026-0989.patch
    * https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374

++++ suseconnect-ng:

  - Update version to 1.20:
  - Update error message for Public Cloud instances with registercloudguest
    installed. SUSEConnect -d is disabled on PYAG and BYOS when the
    registercloudguest command is available. (bsc#1230861)
  - Enhanced SAP detected. Take TREX into account and remove empty values when
    only /usr/sap but no installation exists (bsc#1241002)
  - Fixed modules and extension link to point to version less documentation. (bsc#1239439)
  - Fixed SAP instance detection (bsc#1244550)
  - Remove link to extensions documentation (bsc#1239439)
  - Migrate to the public library

------------------------------------------------------------------
------------------  2026-1-21  -  Jan 21 2026  -------------------
------------------------------------------------------------------

++++ cups:

  - Version upgrade to 2.4.16:
    See https://github.com/openprinting/cups/releases
    The hotfix release 2.4.16 includes fix for infinite loop in GTK,
    which was caused by change of internal behavior in libcups
    on which GTK depended on, and workaround for stopping
    the scheduler if configuration includes unknown directives.
    Detailed list (from CHANGES.md):
    * 'cupsUTF8ToCharset' didn't validate 2-byte UTF-8 sequences,
    potentially reading past the end of the source string
    (Issue #1438)
    * The web interface did not support domain usernames fully
    (Issue #1441)
    * Fixed an infinite loop issue in the GTK+ print dialog
    (Issue #1439 boo#1254353)
    * Fixed stopping scheduler on unknown directive in
    configuration (Issue #1443)
    Issues are those at https://github.com/OpenPrinting/cups/issues
  - Version upgrade to 2.4.15:
    See https://github.com/openprinting/cups/releases
    The release CUPS 2.4.15 brings two CVE fixes:
    Fix various cupsd issues which cause local DoS
    (CVE-2025-61915 bsc#1253783)
    Fix unresponsive cupsd process caused by slow client
    (CVE-2025-58436 bsc#1244057)
    and several bug fixes described in CHANGES.md.
    Detailed list (from CHANGES.md):
    * Fixed potential crash in 'cups-driverd' when there are
    duplicate PPDs (Issue #1355)
    * Fixed error recovery when scanning for PPDs
    in 'cups-driverd' (Issue #1416)
    Issues are those at https://github.com/OpenPrinting/cups/issues
  - Adapted downgrade-autoconf-requirement.patch for CUPS 2.4.16
  - Fixed entry below dated "Sat Sep 30 08:52:42 UTC 2017"
    which contained needless UTF-8 Unicode characters that are
    now replaced by plain ASCII text in "... line - the ..."
    to fix a rpmlint "non-break-space" warning.
  - Adapted and enhanced 'tmpfiles.d' related things in cups.spec
    to "Fix packages for Immutable Mode - cups"
    (implementation task jsc#PED-14775 from epic jsc#PED-14688)

++++ glib2:

  - Add glib2-CVE-2026-0988.patch: fix a potential integer overflow
    in g_buffered_input_stream_peek (bsc#1257049 CVE-2026-0988
    glgo#GNOME/glib#3851).

++++ kernel-default:

  - erofs: fix file-backed mounts no longer working on EROFS
    partitions (CVE-2025-68361 bsc#1255526).
  - commit 472da07
  - erofs: don't bother with s_stack_depth increasing for now
    (CVE-2025-68361 bsc#1255526).
  - commit 39303bf
  - net: ipv6: fix field-spanning memcpy warning in AH output
    (CVE-2025-40363 bsc#1255102).
  - commit e140a1d
  - fsnotify: do not generate ACCESS/MODIFY events on child for
    special files (bsc#1256638 CVE-2025-68788).
  - commit c5ba5af
  - ext4: xattr: fix null pointer deref in ext4_raw_inode()
    (bsc#1256754 CVE-2025-68820).
  - commit 5db1006
  - ext4: fix string copying in parse_apply_sb_mount_options()
    (bsc#1256757 CVE-2025-71123).
  - commit f859099
  - ext4: add i_data_sem protection in
    ext4_destroy_inline_data_nolock() (bsc#1255164 CVE-2025-68261).
  - commit ca299fb
  - nbd: defer config put in recv_work (bsc#1255537 CVE-2025-68372).
  - commit a3661a2
  - nbd: defer config unlock in nbd_genl_connect (bsc#1255622
    CVE-2025-68366).
  - commit abe0920
  - jbd2: avoid bug_on in jbd2_journal_get_create_access() when
    file system corrupted (bsc#1255482 CVE-2025-68337).
  - commit 158d717
  - Refresh patches.suse/iavf-get-rid-of-the-crit-lock.patch.
    Fix locking issue introduced by CVE backport (bsc#1256975 bsc#1254977).
  - commit d093512
  - erofs: limit the level of fs stacking for file-backed mounts
    (CVE-2025-68361 bsc#1255526).
  - commit 4238cae
  - ipv4: route: Prevent rt_bind_exception() from rebinding stale
    fnhe (CVE-2025-68241 bsc#1255157).
  - net: netpoll: fix incorrect refcount handling causing incorrect
    cleanup (CVE-2025-68245 bsc#1255268).
  - commit b8da07f
  - nfsd: adjust WARN_ON_ONCE in revoke_delegation (bsc#1257015).
  - commit da1be71
  - of: fix reference count leak in of_alias_scan() (git-fixes).
  - of: platform: Use default match table for /firmware (git-fixes).
  - ata: libata: Add cpr_log to ata_dev_print_features() early
    return (git-fixes).
  - ata: libata-sata: Improve link_power_management_supported
    sysfs attribute (git-fixes).
  - ata: ahci: Do not read the per port area for unimplemented ports
    (git-fixes).
  - ata: libata-scsi: Fix system suspend for a security locked drive
    (git-fixes).
  - ata: libata-scsi: Fix ata_to_sense_error() status handling
    (git-fixes).
  - commit 7be8126
  - Refresh
    patches.suse/dmaengine-idxd-Fix-refcount-underflow-on-module-unlo.patch.
  - blacklist.conf:
    Fix the missing cleanup, folding the upsteram stable 6.12.y fix (commit
    d28c1b1566a1) into the backport patch itself.
  - commit 3863579

++++ kernel-rt:

  - erofs: fix file-backed mounts no longer working on EROFS
    partitions (CVE-2025-68361 bsc#1255526).
  - commit 472da07
  - erofs: don't bother with s_stack_depth increasing for now
    (CVE-2025-68361 bsc#1255526).
  - commit 39303bf
  - net: ipv6: fix field-spanning memcpy warning in AH output
    (CVE-2025-40363 bsc#1255102).
  - commit e140a1d
  - fsnotify: do not generate ACCESS/MODIFY events on child for
    special files (bsc#1256638 CVE-2025-68788).
  - commit c5ba5af
  - ext4: xattr: fix null pointer deref in ext4_raw_inode()
    (bsc#1256754 CVE-2025-68820).
  - commit 5db1006
  - ext4: fix string copying in parse_apply_sb_mount_options()
    (bsc#1256757 CVE-2025-71123).
  - commit f859099
  - ext4: add i_data_sem protection in
    ext4_destroy_inline_data_nolock() (bsc#1255164 CVE-2025-68261).
  - commit ca299fb
  - nbd: defer config put in recv_work (bsc#1255537 CVE-2025-68372).
  - commit a3661a2
  - nbd: defer config unlock in nbd_genl_connect (bsc#1255622
    CVE-2025-68366).
  - commit abe0920
  - jbd2: avoid bug_on in jbd2_journal_get_create_access() when
    file system corrupted (bsc#1255482 CVE-2025-68337).
  - commit 158d717
  - Refresh patches.suse/iavf-get-rid-of-the-crit-lock.patch.
    Fix locking issue introduced by CVE backport (bsc#1256975 bsc#1254977).
  - commit d093512
  - erofs: limit the level of fs stacking for file-backed mounts
    (CVE-2025-68361 bsc#1255526).
  - commit 4238cae
  - ipv4: route: Prevent rt_bind_exception() from rebinding stale
    fnhe (CVE-2025-68241 bsc#1255157).
  - net: netpoll: fix incorrect refcount handling causing incorrect
    cleanup (CVE-2025-68245 bsc#1255268).
  - commit b8da07f
  - nfsd: adjust WARN_ON_ONCE in revoke_delegation (bsc#1257015).
  - commit da1be71
  - of: fix reference count leak in of_alias_scan() (git-fixes).
  - of: platform: Use default match table for /firmware (git-fixes).
  - ata: libata: Add cpr_log to ata_dev_print_features() early
    return (git-fixes).
  - ata: libata-sata: Improve link_power_management_supported
    sysfs attribute (git-fixes).
  - ata: ahci: Do not read the per port area for unimplemented ports
    (git-fixes).
  - ata: libata-scsi: Fix system suspend for a security locked drive
    (git-fixes).
  - ata: libata-scsi: Fix ata_to_sense_error() status handling
    (git-fixes).
  - commit 7be8126
  - Refresh
    patches.suse/dmaengine-idxd-Fix-refcount-underflow-on-module-unlo.patch.
  - blacklist.conf:
    Fix the missing cleanup, folding the upsteram stable 6.12.y fix (commit
    d28c1b1566a1) into the backport patch itself.
  - commit 3863579

++++ samba:

  - Fix mistake in README.SUSE /var/spool/samba => /var/samba/spool
    (bsc#1254665).

------------------------------------------------------------------
------------------  2026-1-20  -  Jan 20 2026  -------------------
------------------------------------------------------------------

++++ glibc:

  - memalign-overflow-check.patch: memalign: reinstate alignment overflow
    check (CVE-2026-0861, bsc#1256766, BZ #33796)
  - nss-dns-getnetbyaddr.patch: resolv: Fix NSS DNS backend for getnetbyaddr
    (CVE-2026-0915, bsc#1256822, BZ #33802)
  - nptl-optimize-trylock.patch: nptl: Optimize trylock for high cache
    contention workloads (bsc#1256436, BZ #33704)
  - wordexp-wrde-reuse.patch: posix: Reset wordexp_t fields with WRDE_REUSE
    (CVE-2025-15281, bsc#1257005, BZ #33814)

++++ grub2:

  - Optimize PBKDF2 to reduce the decryption time (bsc#1248516)
    * 0001-lib-crypto-Introduce-new-HMAC-functions-to-reuse-buf.patch
    * 0002-lib-pbkdf2-Optimize-PBKDF2-by-reusing-HMAC-handle.patch
    * 0001-kern-misc-Implement-faster-grub_memcpy-for-aligned-b.patch

++++ kernel-default:

  - blk-throttle: fix throtl_data leak during disk release
    (git-fixes).
  - commit d28bb8b
  - NFSD: NFSv4 file creation neglects setting ACL (CVE-2025-68803
    bsc#1256770).
  - commit ac1975f
  - xfs: fix a UAF problem in xattr repair (CVE-2025-68784
    bsc#1256793).
  - commit 2b579a4
  - svcrdma: use rc_pageoff for memcpy byte offset (CVE-2025-68811
    bsc#1256677).
  - commit 5da529b
  - RDMA/irdma: avoid invalid read in irdma_net_event (CVE-2025-71133 bsc#1256733)
  - commit d92ea95
  - RDMA/cm: Fix leaking the multicast GID table reference (CVE-2025-71084 bsc#1256622)
  - commit 677f876
  - ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT
    (CVE-2025-71080 bsc#1256608).
  - smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132
    bsc#1256737).
  - commit 1c36926
  - sched/fair: Disable scheduler feature NEXT_BUDDY (bsc#1255459).
  - commit a542b6f
  - drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup (bsc#1255128 CVE-2025-68296)
  - commit 77ece13
  - Remove patches.suse/0001-drm-fbcon-vga_switcheroo-Avoid-race-condition-in-fbc.patch
    Remove this patch before remaking it in an appropriate way.
  - commit f91d20a
  - SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token
    in gss_read_proxy_verf (CVE-2025-71120 bsc#1256779).
  - commit 796b399

++++ kernel-rt:

  - blk-throttle: fix throtl_data leak during disk release
    (git-fixes).
  - commit d28bb8b
  - NFSD: NFSv4 file creation neglects setting ACL (CVE-2025-68803
    bsc#1256770).
  - commit ac1975f
  - xfs: fix a UAF problem in xattr repair (CVE-2025-68784
    bsc#1256793).
  - commit 2b579a4
  - svcrdma: use rc_pageoff for memcpy byte offset (CVE-2025-68811
    bsc#1256677).
  - commit 5da529b
  - RDMA/irdma: avoid invalid read in irdma_net_event (CVE-2025-71133 bsc#1256733)
  - commit d92ea95
  - RDMA/cm: Fix leaking the multicast GID table reference (CVE-2025-71084 bsc#1256622)
  - commit 677f876
  - ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT
    (CVE-2025-71080 bsc#1256608).
  - smc91x: fix broken irq-context in PREEMPT_RT (CVE-2025-71132
    bsc#1256737).
  - commit 1c36926
  - sched/fair: Disable scheduler feature NEXT_BUDDY (bsc#1255459).
  - commit a542b6f
  - drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup (bsc#1255128 CVE-2025-68296)
  - commit 77ece13
  - Remove patches.suse/0001-drm-fbcon-vga_switcheroo-Avoid-race-condition-in-fbc.patch
    Remove this patch before remaking it in an appropriate way.
  - commit f91d20a
  - SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token
    in gss_read_proxy_verf (CVE-2025-71120 bsc#1256779).
  - commit 796b399

++++ nvidia-open-driver-G06-signed:

  - updated CUDA variant to version 580.126.09
  - supersedes kernel-6.18.patch

++++ python-urllib3:

  - Add security patch:
    * CVE-2025-66471.patch (bsc#1254867)
    * CVE-2025-66418.patch (bsc#1254866)

------------------------------------------------------------------
------------------  2026-1-19  -  Jan 19 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: qla2xxx: Fix improper freeing of purex item
    (CVE-2025-68741 bsc#1255703).
  - scsi: sg: Do not sleep in atomic context (CVE-2025-40259
    bsc#1254845).
  - blk-throttle: fix access race during throttle policy activation
    (CVE-2025-40147 bsc#1253344).
  - commit 3a550b4
  - arp: do not assume dev_hard_header() does not change skb->head
    (CVE-2025-71098 bsc#1256591).
  - ip6_gre: make ip6gre_header() robust (CVE-2025-71098
    bsc#1256591).
  - commit 7dae7cf
  - ksm: use range-walk function to jump over holes in
    scan_get_next_rmap_item (CVE-2025-68211 bsc#1255319).
  - commit 4816124
  - btrfs: release path before iget_failed() in
    btrfs_read_locked_inode() (git-fixes).
  - commit fa0306d
  - btrfs: fix double free of qgroup record after failure to add
    delayed ref head (bsc#1255542 CVE-2025-68359).
  - commit 6ceb575
  - btrfs: track delayed ref heads in an xarray (git-fixes).
  - commit 1e30518
  - btrfs: remove pointless initialization at
    btrfs_qgroup_trace_extent() (git-fixes).
  - commit a6f074a
  - btrfs: always use delayed_refs local variable at
    btrfs_qgroup_trace_extent() (git-fixes).
  - commit fe22722
  - btrfs: remove unnecessary delayed refs locking at
    btrfs_qgroup_trace_extent() (git-fixes).
  - commit 9f1e0ee
  - btrfs: store fs_info in a local variable at
    btrfs_qgroup_trace_extent_post() (git-fixes).
  - commit 83a75de
  - btrfs: qgroups: remove bytenr field from struct
    btrfs_qgroup_extent_record (git-fixes).
  - commit 4040e94
  - btrfs: add comments regarding locking to struct
    btrfs_delayed_ref_root (git-fixes).
  - commit c3029d5
  - btrfs: assert delayed refs lock is held at
    add_delayed_ref_head() (git-fixes).
  - commit a71ad52
  - btrfs: assert delayed refs lock is held at find_first_ref_head()
    (git-fixes).
  - commit d0232bb
  - btrfs: assert delayed refs lock is held at find_ref_head()
    (git-fixes).
  - commit c64e28a
  - btrfs: pass fs_info to btrfs_delete_ref_head() (git-fixes).
  - commit 9209eb3
  - btrfs: pass fs_info to functions that search for delayed ref
    heads (git-fixes).
  - commit c8e07b0
  - btrfs: move delayed ref head unselection to delayed-ref.c
    (git-fixes).
  - commit 489dc34
  - btrfs: simplify obtaining a delayed ref head (git-fixes).
  - commit 16c3f62
  - btrfs: change return type of btrfs_delayed_ref_lock() to boolean
    (git-fixes).
  - commit 03bca3c
  - btrfs: remove num_entries atomic counter from delayed ref root
    (git-fixes).
  - commit 054bc10
  - btrfs: use helper to find first ref head at
    btrfs_destroy_delayed_refs() (git-fixes).
  - commit 4374302
  - btrfs: remove duplicated code to drop delayed ref during
    transaction abort (git-fixes).
  - commit 725dadb
  - btrfs: remove fs_info parameter from
    btrfs_cleanup_one_transaction() (git-fixes).
  - commit 1591511
  - btrfs: remove fs_info parameter from
    btrfs_destroy_delayed_refs() (git-fixes).
  - commit 9c2d1b7
  - btrfs: move btrfs_destroy_delayed_refs() to delayed-ref.c
    (git-fixes).
  - commit 3491ecf
  - btrfs: remove BUG_ON() at btrfs_destroy_delayed_refs()
    (git-fixes).
  - commit 08fe1bf
  - move GDMA_DRV_CAP_FLAG_1_DYNAMIC_IRQ_ALLOC_SUPPORT to upstream location
  - remove a bpf CVE change which is already part of the base kernel
  - net: hv_netvsc: reject RSS hash key programming without RX indirection table (git-fixes).
  - RDMA/mana_ib: check cqe length for kernel CQs (git-fixes).
  - Drivers: hv: use kmalloc_array() instead of kmalloc() (git-fixes).
  - mshv: Fix create memory region overlap check (bsc#1255708 CVE-2025-68743).
  - Drivers: hv: Use kmalloc_array() instead of kmalloc() (git-fixes).
  - Drivers: hv: Resolve ambiguity in hypervisor version log (git-fixes).
  - Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes).
  - Drivers: hv: remove stale comment (git-fixes).
  - mshv: Fix deposit memory in MSHV_ROOT_HVCALL (git-fixes).
  - mshv: Fix VpRootDispatchThreadBlocked value (git-fixes).
  - net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes).
  - commit 5f8e751
  - dmaengine: apple-admac: Add "apple,t8103-admac" compatible
    (git-fixes).
  - dmaengine: omap-dma: fix dma_pool resource leak in error paths
    (git-fixes).
  - dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()
    (git-fixes).
  - dmaengine: sh: rz-dmac: Fix rz_dmac_terminate_all() (git-fixes).
  - dmaengine: xilinx_dma: Fix uninitialized addr_width when
    "xlnx,addrwidth" property is missing (git-fixes).
  - dmaengine: tegra-adma: Fix use-after-free (git-fixes).
  - dmaengine: ti: k3-udma: fix device leak on udma lookup
    (git-fixes).
  - dmaengine: ti: dma-crossbar: fix device leak on am335x route
    allocation (git-fixes).
  - dmaengine: ti: dma-crossbar: fix device leak on dra7x route
    allocation (git-fixes).
  - dmaengine: stm32: dmamux: fix OF node leak on route allocation
    failure (git-fixes).
  - dmaengine: stm32: dmamux: fix device leak on route allocation
    (git-fixes).
  - dmaengine: lpc32xx-dmamux: fix device leak on route allocation
    (git-fixes).
  - dmaengine: lpc18xx-dmamux: fix device leak on route allocation
    (git-fixes).
  - dmaengine: idxd: fix device leaks on compat bind and unbind
    (git-fixes).
  - dmaengine: dw: dmamux: fix OF node leak on route allocation
    failure (git-fixes).
  - dmaengine: bcm-sba-raid: fix device leak on probe (git-fixes).
  - dmaengine: at_hdmac: fix device leak on of_dma_xlate()
    (git-fixes).
  - dmaengine: xilinx: xdma: Fix regmap max_register (git-fixes).
  - phy: broadcom: ns-usb3: Fix Wvoid-pointer-to-enum-cast warning
    (again) (git-fixes).
  - phy: tegra: xusb: Explicitly configure HS_DISCON_LEVEL to 0x7
    (git-fixes).
  - phy: rockchip: inno-usb2: fix communication disruption in
    gadget mode (git-fixes).
  - phy: rockchip: inno-usb2: fix disconnection in gadget mode
    (git-fixes).
  - phy: ti: gmii-sel: fix regmap leak on probe failure (git-fixes).
  - phy: ti: da8xx-usb: Handle devm_pm_runtime_enable() errors
    (git-fixes).
  - phy: stm32-usphyc: Fix off by one in probe() (git-fixes).
  - phy: fsl-imx8mq-usb: Clear the PCS_TX_SWING_FULL field before
    using it (git-fixes).
  - i2c: riic: Move suspend handling to NOIRQ phase (git-fixes).
  - commit f852916

++++ kernel-rt:

  - scsi: qla2xxx: Fix improper freeing of purex item
    (CVE-2025-68741 bsc#1255703).
  - scsi: sg: Do not sleep in atomic context (CVE-2025-40259
    bsc#1254845).
  - blk-throttle: fix access race during throttle policy activation
    (CVE-2025-40147 bsc#1253344).
  - commit 3a550b4
  - arp: do not assume dev_hard_header() does not change skb->head
    (CVE-2025-71098 bsc#1256591).
  - ip6_gre: make ip6gre_header() robust (CVE-2025-71098
    bsc#1256591).
  - commit 7dae7cf
  - ksm: use range-walk function to jump over holes in
    scan_get_next_rmap_item (CVE-2025-68211 bsc#1255319).
  - commit 4816124
  - btrfs: release path before iget_failed() in
    btrfs_read_locked_inode() (git-fixes).
  - commit fa0306d
  - btrfs: fix double free of qgroup record after failure to add
    delayed ref head (bsc#1255542 CVE-2025-68359).
  - commit 6ceb575
  - btrfs: track delayed ref heads in an xarray (git-fixes).
  - commit 1e30518
  - btrfs: remove pointless initialization at
    btrfs_qgroup_trace_extent() (git-fixes).
  - commit a6f074a
  - btrfs: always use delayed_refs local variable at
    btrfs_qgroup_trace_extent() (git-fixes).
  - commit fe22722
  - btrfs: remove unnecessary delayed refs locking at
    btrfs_qgroup_trace_extent() (git-fixes).
  - commit 9f1e0ee
  - btrfs: store fs_info in a local variable at
    btrfs_qgroup_trace_extent_post() (git-fixes).
  - commit 83a75de
  - btrfs: qgroups: remove bytenr field from struct
    btrfs_qgroup_extent_record (git-fixes).
  - commit 4040e94
  - btrfs: add comments regarding locking to struct
    btrfs_delayed_ref_root (git-fixes).
  - commit c3029d5
  - btrfs: assert delayed refs lock is held at
    add_delayed_ref_head() (git-fixes).
  - commit a71ad52
  - btrfs: assert delayed refs lock is held at find_first_ref_head()
    (git-fixes).
  - commit d0232bb
  - btrfs: assert delayed refs lock is held at find_ref_head()
    (git-fixes).
  - commit c64e28a
  - btrfs: pass fs_info to btrfs_delete_ref_head() (git-fixes).
  - commit 9209eb3
  - btrfs: pass fs_info to functions that search for delayed ref
    heads (git-fixes).
  - commit c8e07b0
  - btrfs: move delayed ref head unselection to delayed-ref.c
    (git-fixes).
  - commit 489dc34
  - btrfs: simplify obtaining a delayed ref head (git-fixes).
  - commit 16c3f62
  - btrfs: change return type of btrfs_delayed_ref_lock() to boolean
    (git-fixes).
  - commit 03bca3c
  - btrfs: remove num_entries atomic counter from delayed ref root
    (git-fixes).
  - commit 054bc10
  - btrfs: use helper to find first ref head at
    btrfs_destroy_delayed_refs() (git-fixes).
  - commit 4374302
  - btrfs: remove duplicated code to drop delayed ref during
    transaction abort (git-fixes).
  - commit 725dadb
  - btrfs: remove fs_info parameter from
    btrfs_cleanup_one_transaction() (git-fixes).
  - commit 1591511
  - btrfs: remove fs_info parameter from
    btrfs_destroy_delayed_refs() (git-fixes).
  - commit 9c2d1b7
  - btrfs: move btrfs_destroy_delayed_refs() to delayed-ref.c
    (git-fixes).
  - commit 3491ecf
  - btrfs: remove BUG_ON() at btrfs_destroy_delayed_refs()
    (git-fixes).
  - commit 08fe1bf
  - move GDMA_DRV_CAP_FLAG_1_DYNAMIC_IRQ_ALLOC_SUPPORT to upstream location
  - remove a bpf CVE change which is already part of the base kernel
  - net: hv_netvsc: reject RSS hash key programming without RX indirection table (git-fixes).
  - RDMA/mana_ib: check cqe length for kernel CQs (git-fixes).
  - Drivers: hv: use kmalloc_array() instead of kmalloc() (git-fixes).
  - mshv: Fix create memory region overlap check (bsc#1255708 CVE-2025-68743).
  - Drivers: hv: Use kmalloc_array() instead of kmalloc() (git-fixes).
  - Drivers: hv: Resolve ambiguity in hypervisor version log (git-fixes).
  - Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes).
  - Drivers: hv: remove stale comment (git-fixes).
  - mshv: Fix deposit memory in MSHV_ROOT_HVCALL (git-fixes).
  - mshv: Fix VpRootDispatchThreadBlocked value (git-fixes).
  - net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes).
  - commit 5f8e751
  - dmaengine: apple-admac: Add "apple,t8103-admac" compatible
    (git-fixes).
  - dmaengine: omap-dma: fix dma_pool resource leak in error paths
    (git-fixes).
  - dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()
    (git-fixes).
  - dmaengine: sh: rz-dmac: Fix rz_dmac_terminate_all() (git-fixes).
  - dmaengine: xilinx_dma: Fix uninitialized addr_width when
    "xlnx,addrwidth" property is missing (git-fixes).
  - dmaengine: tegra-adma: Fix use-after-free (git-fixes).
  - dmaengine: ti: k3-udma: fix device leak on udma lookup
    (git-fixes).
  - dmaengine: ti: dma-crossbar: fix device leak on am335x route
    allocation (git-fixes).
  - dmaengine: ti: dma-crossbar: fix device leak on dra7x route
    allocation (git-fixes).
  - dmaengine: stm32: dmamux: fix OF node leak on route allocation
    failure (git-fixes).
  - dmaengine: stm32: dmamux: fix device leak on route allocation
    (git-fixes).
  - dmaengine: lpc32xx-dmamux: fix device leak on route allocation
    (git-fixes).
  - dmaengine: lpc18xx-dmamux: fix device leak on route allocation
    (git-fixes).
  - dmaengine: idxd: fix device leaks on compat bind and unbind
    (git-fixes).
  - dmaengine: dw: dmamux: fix OF node leak on route allocation
    failure (git-fixes).
  - dmaengine: bcm-sba-raid: fix device leak on probe (git-fixes).
  - dmaengine: at_hdmac: fix device leak on of_dma_xlate()
    (git-fixes).
  - dmaengine: xilinx: xdma: Fix regmap max_register (git-fixes).
  - phy: broadcom: ns-usb3: Fix Wvoid-pointer-to-enum-cast warning
    (again) (git-fixes).
  - phy: tegra: xusb: Explicitly configure HS_DISCON_LEVEL to 0x7
    (git-fixes).
  - phy: rockchip: inno-usb2: fix communication disruption in
    gadget mode (git-fixes).
  - phy: rockchip: inno-usb2: fix disconnection in gadget mode
    (git-fixes).
  - phy: ti: gmii-sel: fix regmap leak on probe failure (git-fixes).
  - phy: ti: da8xx-usb: Handle devm_pm_runtime_enable() errors
    (git-fixes).
  - phy: stm32-usphyc: Fix off by one in probe() (git-fixes).
  - phy: fsl-imx8mq-usb: Clear the PCS_TX_SWING_FULL field before
    using it (git-fixes).
  - i2c: riic: Move suspend handling to NOIRQ phase (git-fixes).
  - commit f852916

++++ samba:

  - Update to 4.22.7
    * Samba 4.22 breaks Time Machine; (bso#15926).
    * Searching for numbers doesn't work with Spotlight;
    (bso#15930).
    * mdssvc doesn't support $time.iso dates before 1970;
    (bso#15947).
    * Fix winbind cache consistency; (bso#15963).
    * vfs_recycle does not update mtime; (bso#15940).
    * Assert failed: (dirfd != -1) || (smb_fname->base_name[0] ==
    '/') in vfswrap_openat; (bso#15897).
    * ctdb can crash with inconsistent cluster lock configuration;
    (bso#15950).
    * samba-bgqd: rework man page; (bso#15809).
    * samba-bgqd can't find [printers] share; (bso#15936); (bsc#1254586).
    * Winbind can hang forever in gssapi if there are network
    issues; (bso#15955).
    * libldb requires linking libreplace on Linux; (bso#15961).
    * Crash in ctdbd on failed updateip; (bso#15935).

------------------------------------------------------------------
------------------  2026-1-18  -  Jan 18 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/amdgpu: Fix query for VPE block_type and ip_count
    (stable-fixes).
  - drm/amd/display: Apply e4479aecf658 to dml (stable-fixes).
  - spi: cadence-quadspi: Prevent lost complete() call during
    indirect read (stable-fixes).
  - ata: libata-core: Disable LPM on ST2000DM008-2FR102
    (stable-fixes).
  - spi: mt65xx: Use IRQF_ONESHOT with threaded IRQ (stable-fixes).
  - drm/amdkfd: Fix improper NULL termination of queue restore
    SMI event string (stable-fixes).
  - drm/amd/display: shrink struct members (stable-fixes).
  - ASoC: rockchip: Fix Wvoid-pointer-to-enum-cast warning (again)
    (stable-fixes).
  - drm/amd/display: Respect user's CONFIG_FRAME_WARN more for
    dml files (stable-fixes).
  - commit d246be3
  - mei: me: add nova lake point S DID (stable-fixes).
  - gpio: pca953x: handle short interrupt pulses on PCAL devices
    (git-fixes).
  - drm/radeon: Remove __counted_by from ClockInfoArray.clockInfo[]
    (stable-fixes).
  - ASoC: fsl_sai: Add missing registers to cache default
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for Honor MagicBook X16 2025
    (stable-fixes).
  - ALSA: usb-audio: Update for native DSD support quirks
    (stable-fixes).
  - drm/amd/display: Fix DP no audio issue (stable-fixes).
  - powercap: fix sscanf() error return value handling
    (stable-fixes).
  - powercap: fix race condition in register_control_type()
    (stable-fixes).
  - can: j1939: make j1939_session_activate() fail if device is
    no longer registered (stable-fixes).
  - gpio: pca953x: Add support for level-triggered interrupts
    (stable-fixes).
  - commit 18eceac
  - ocfs2: fix kernel BUG in ocfs2_find_victim_chain (bsc#1256582
    CVE-2025-68771).
  - commit a066f3b

++++ kernel-rt:

  - drm/amdgpu: Fix query for VPE block_type and ip_count
    (stable-fixes).
  - drm/amd/display: Apply e4479aecf658 to dml (stable-fixes).
  - spi: cadence-quadspi: Prevent lost complete() call during
    indirect read (stable-fixes).
  - ata: libata-core: Disable LPM on ST2000DM008-2FR102
    (stable-fixes).
  - spi: mt65xx: Use IRQF_ONESHOT with threaded IRQ (stable-fixes).
  - drm/amdkfd: Fix improper NULL termination of queue restore
    SMI event string (stable-fixes).
  - drm/amd/display: shrink struct members (stable-fixes).
  - ASoC: rockchip: Fix Wvoid-pointer-to-enum-cast warning (again)
    (stable-fixes).
  - drm/amd/display: Respect user's CONFIG_FRAME_WARN more for
    dml files (stable-fixes).
  - commit d246be3
  - mei: me: add nova lake point S DID (stable-fixes).
  - gpio: pca953x: handle short interrupt pulses on PCAL devices
    (git-fixes).
  - drm/radeon: Remove __counted_by from ClockInfoArray.clockInfo[]
    (stable-fixes).
  - ASoC: fsl_sai: Add missing registers to cache default
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for Honor MagicBook X16 2025
    (stable-fixes).
  - ALSA: usb-audio: Update for native DSD support quirks
    (stable-fixes).
  - drm/amd/display: Fix DP no audio issue (stable-fixes).
  - powercap: fix sscanf() error return value handling
    (stable-fixes).
  - powercap: fix race condition in register_control_type()
    (stable-fixes).
  - can: j1939: make j1939_session_activate() fail if device is
    no longer registered (stable-fixes).
  - gpio: pca953x: Add support for level-triggered interrupts
    (stable-fixes).
  - commit 18eceac
  - ocfs2: fix kernel BUG in ocfs2_find_victim_chain (bsc#1256582
    CVE-2025-68771).
  - commit a066f3b

------------------------------------------------------------------
------------------  2026-1-17  -  Jan 17 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/nouveau/disp/nv50-: Set lock_core in curs507a_prepare
    (git-fixes).
  - drm/panel-simple: fix connector type for DataImage
    SCF0700C48GGU18 panel (git-fixes).
  - drm/vmwgfx: Fix an error return check in vmw_compat_shader_add()
    (git-fixes).
  - drm/vmwgfx: Merge vmw_bo_release and vmw_bo_free functions
    (git-fixes).
  - drm/amd/display: Initialise backlight level values from hw
    (git-fixes).
  - drm/amdkfd: fix a memory leak in device_queue_manager_init()
    (git-fixes).
  - PM: EM: Fix incorrect description of the cost field in struct
    em_perf_state (git-fixes).
  - ASoC: tlv320adcx140: fix word length (git-fixes).
  - ASoC: tlv320adcx140: fix null pointer (git-fixes).
  - ASoC: sdw_utils: cs42l43: Enable Headphone pin for LINEOUT
    jack type (git-fixes).
  - ASoC: codecs: wsa884x: fix codec initialisation (git-fixes).
  - ASoC: codecs: wsa881x: fix unnecessary initialisation
    (git-fixes).
  - ASoC: codecs: wsa883x: fix unnecessary initialisation
    (git-fixes).
  - ALSA: hda/cirrus_scodec_test: Fix test suite name (git-fixes).
  - ALSA: hda/cirrus_scodec_test: Fix incorrect setup of gpiochip
    (git-fixes).
  - commit fcd5437

++++ kernel-rt:

  - drm/nouveau/disp/nv50-: Set lock_core in curs507a_prepare
    (git-fixes).
  - drm/panel-simple: fix connector type for DataImage
    SCF0700C48GGU18 panel (git-fixes).
  - drm/vmwgfx: Fix an error return check in vmw_compat_shader_add()
    (git-fixes).
  - drm/vmwgfx: Merge vmw_bo_release and vmw_bo_free functions
    (git-fixes).
  - drm/amd/display: Initialise backlight level values from hw
    (git-fixes).
  - drm/amdkfd: fix a memory leak in device_queue_manager_init()
    (git-fixes).
  - PM: EM: Fix incorrect description of the cost field in struct
    em_perf_state (git-fixes).
  - ASoC: tlv320adcx140: fix word length (git-fixes).
  - ASoC: tlv320adcx140: fix null pointer (git-fixes).
  - ASoC: sdw_utils: cs42l43: Enable Headphone pin for LINEOUT
    jack type (git-fixes).
  - ASoC: codecs: wsa884x: fix codec initialisation (git-fixes).
  - ASoC: codecs: wsa881x: fix unnecessary initialisation
    (git-fixes).
  - ASoC: codecs: wsa883x: fix unnecessary initialisation
    (git-fixes).
  - ALSA: hda/cirrus_scodec_test: Fix test suite name (git-fixes).
  - ALSA: hda/cirrus_scodec_test: Fix incorrect setup of gpiochip
    (git-fixes).
  - commit fcd5437

------------------------------------------------------------------
------------------  2026-1-16  -  Jan 16 2026  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Drop 0010-add-onExpand-prop-to-ListingTable.patch: Has been upstreamed
  - Update to 354
    * changes since 351
  - 354
    * Convert documentation to AsciiDoc
    * Work around Firefox 146/147 bug (rhbz#2422331)
    * Bug fixes
  - 353
    * Networking: Suggest prefix length and gateway address
    * Bug fixes and translation updates
  - 352
    * Shown a warning if the last shutdown/reboot was unclean
    * Bug fixes and translation updates

++++ kernel-default:

  - caif: fix integer underflow in cffrml_receive() (CVE-2025-68799 bsc#1256643)
  - commit 1ef0d96
  - NFS: Automounted filesystems should inherit ro,noexec,nodev,sync
    flags (CVE-2025-68764 bsc#1255930).
  - commit 09d81f3
  - coresight: ETR: Fix ETR buffer use-after-free issue (CVE-2025-68376 bsc#1255529)
  - commit a4ff2c1
  - net/hsr: fix NULL pointer dereference in prp_get_untagged_frame() (CVE-2025-68776 bsc#1256659)
  - commit 49a3b6c
  - block: fix memory leak in __blkdev_issue_zero_pages (CVE-2025-68348 bsc#1255694)
  - commit 73e6c55
  - RDMA/rxe: Fix null deref on srq->rq.queue after resize failure (CVE-2025-68379 bsc#1255695)
  - commit c6b18fc
  - Fix KABI for "md: fix rcu protection in md_wakeup_thread"
    (CVE-2025-68374 bsc#1255530).
  - commit 19ea2fb
  - ice: use netif_get_num_default_rss_queues() (bsc#1247712).
  - commit 9a8d388
  - scsi: qla2xxx: Update version to 10.02.10.100-k (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Fix bsg_done() causing double free (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Query FW again before proceeding with login
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Validate sp before freeing associated memory
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Free sp in error path to fix system crash
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Delay module unload while fabric scan in progress
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Allow recovery for tape devices (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add bsg interface to support firmware img
    validation (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Validate MCU signature before executing MBC 03h
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add load flash firmware mailbox support for 28xxx
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add support for 64G SFP speed (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add Speed in SFP print information (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - commit c16cfd0
  - iavf: fix off-by-one issues in iavf_config_rss_reg()
    (CVE-2025-71087 bsc#1256628).
  - net: mana: Fix incorrect speed reported by debugfs
    (bsc#1255232).
  - net: mana: Support HW link state events (bsc#1253049).
  - veth: reduce XDP no_direct return section to fix race
    (CVE-2025-68341 bsc#1255506).
  - commit ffa2fc1
  - scsi: lpfc: Update lpfc version to 14.4.0.13 (bsc#1256864).
  - scsi: lpfc: Rework lpfc_sli4_fcf_rr_next_index_get()
    (bsc#1256864).
  - commit ff9c1e2
  - Refresh
    patches.suse/perf-hwmon_pmu-Fix-uninitialized-variable-warning.patch.
  - Refresh
    patches.suse/scsi-lpfc-Add-capability-to-register-Platform-Name-I.patch.
  - Refresh
    patches.suse/scsi-lpfc-Allow-support-for-BB-credit-recovery-in-po.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ensure-unregistration-of-rpis-for-received.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-leaked-ndlp-krefs-when-in-point-to-poi.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-reusing-an-ndlp-that-is-marked-NLP_DRO.patch.
  - Refresh
    patches.suse/scsi-lpfc-Modify-kref-handling-for-Fabric-Controller.patch.
  - Refresh
    patches.suse/scsi-lpfc-Remove-redundant-NULL-ptr-assignment-in-lp.patch.
  - Refresh
    patches.suse/scsi-lpfc-Revise-discovery-related-function-headers-.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.12.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-various-NPIV-diagnostic-log-messagi.patch.
  - commit b68a391
  - md: fix rcu protection in md_wakeup_thread (CVE-2025-68374
    bsc#1255530).
  - commit 4c1b1ef
  - NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in
    pnfs_mark_layout_stateid_invalid (CVE-2025-68349 bsc#1255544).
  - commit 6b33846
  - md: init bioset in mddev_init (CVE-2025-68368 bsc#1255527).
  - commit 4b605d4
  - ipvs: fix ipv4 null-ptr-deref in route error path
    (CVE-2025-68813 bsc#1256641).
  - commit dfa5bc8
  - drm/panthor: Prevent potential UAF in group creation
    (CVE-2025-68735 bsc#1255811).
  - commit ab86e96
  - nvme: nvme-fc: Ensure ->ioerr_work is cancelled in
    nvme_fc_delete_ctrl() (CVE-2025-40261 bsc#1254839).
  - nvme-multipath: fix lockdep WARN due to partition scan work
    (CVE-2025-68218 bsc#1255245).
  - commit ff3bc4b
  - wifi: mt76: wed: use proper wed reference in mt76 wed driver
    callabacks (CVE-2025-68360 bsc#1255536).
  - commit 5863e8a
  - Refresh
    patches.kabi/bpf-Enforce-expected_attach_type-for-tailcall-compat.patch.
    Refresh kABI workaround to use 'unsigned char' instead
    of the original 'enum bpf_attach_type' as the data type.
    It was discovered at SL-16.0 MU submission time that the kABI workaround
    currently in-place does not work on -rt flavor. The reason is that due
    to preceding spinlock_t having a different size, the hole was only 2
    bytes instead of 6 bytes, and thus too small to fit 'enum'.
    Since all the possible enum values are small enough to fit within
    'unsigned char', switch the data type of the new field to that instead.
  - commit 06ff4d9
  - drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup (bsc#1255128 CVE-2025-68296)
  - commit 1b12281
  - efi/cper: Fix cper_bits_to_str buffer handling and return value
    (git-fixes).
  - lib/buildid: use __kernel_read() for sleepable context
    (git-fixes).
  - net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate
    session upon receiving the second rts (git-fixes).
  - can: ctucanfd: fix SSP_SRC in cases when bit-rate is higher
    than 1 MBit (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak
    (git-fixes).
  - can: etas_es58x: allow partial RX URB allocation to succeed
    (git-fixes).
  - commit 6b2a65b

++++ kernel-rt:

  - caif: fix integer underflow in cffrml_receive() (CVE-2025-68799 bsc#1256643)
  - commit 1ef0d96
  - NFS: Automounted filesystems should inherit ro,noexec,nodev,sync
    flags (CVE-2025-68764 bsc#1255930).
  - commit 09d81f3
  - coresight: ETR: Fix ETR buffer use-after-free issue (CVE-2025-68376 bsc#1255529)
  - commit a4ff2c1
  - net/hsr: fix NULL pointer dereference in prp_get_untagged_frame() (CVE-2025-68776 bsc#1256659)
  - commit 49a3b6c
  - block: fix memory leak in __blkdev_issue_zero_pages (CVE-2025-68348 bsc#1255694)
  - commit 73e6c55
  - RDMA/rxe: Fix null deref on srq->rq.queue after resize failure (CVE-2025-68379 bsc#1255695)
  - commit c6b18fc
  - Fix KABI for "md: fix rcu protection in md_wakeup_thread"
    (CVE-2025-68374 bsc#1255530).
  - commit 19ea2fb
  - ice: use netif_get_num_default_rss_queues() (bsc#1247712).
  - commit 9a8d388
  - scsi: qla2xxx: Update version to 10.02.10.100-k (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Fix bsg_done() causing double free (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Query FW again before proceeding with login
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Validate sp before freeing associated memory
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Free sp in error path to fix system crash
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Delay module unload while fabric scan in progress
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Allow recovery for tape devices (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add bsg interface to support firmware img
    validation (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Validate MCU signature before executing MBC 03h
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add load flash firmware mailbox support for 28xxx
    (bsc#1256865 bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add support for 64G SFP speed (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - scsi: qla2xxx: Add Speed in SFP print information (bsc#1256865
    bsc#1256867 jsc#PED-14156).
  - commit c16cfd0
  - iavf: fix off-by-one issues in iavf_config_rss_reg()
    (CVE-2025-71087 bsc#1256628).
  - net: mana: Fix incorrect speed reported by debugfs
    (bsc#1255232).
  - net: mana: Support HW link state events (bsc#1253049).
  - veth: reduce XDP no_direct return section to fix race
    (CVE-2025-68341 bsc#1255506).
  - commit ffa2fc1
  - scsi: lpfc: Update lpfc version to 14.4.0.13 (bsc#1256864).
  - scsi: lpfc: Rework lpfc_sli4_fcf_rr_next_index_get()
    (bsc#1256864).
  - commit ff9c1e2
  - Refresh
    patches.suse/perf-hwmon_pmu-Fix-uninitialized-variable-warning.patch.
  - Refresh
    patches.suse/scsi-lpfc-Add-capability-to-register-Platform-Name-I.patch.
  - Refresh
    patches.suse/scsi-lpfc-Allow-support-for-BB-credit-recovery-in-po.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ensure-unregistration-of-rpis-for-received.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-leaked-ndlp-krefs-when-in-point-to-poi.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-reusing-an-ndlp-that-is-marked-NLP_DRO.patch.
  - Refresh
    patches.suse/scsi-lpfc-Modify-kref-handling-for-Fabric-Controller.patch.
  - Refresh
    patches.suse/scsi-lpfc-Remove-redundant-NULL-ptr-assignment-in-lp.patch.
  - Refresh
    patches.suse/scsi-lpfc-Revise-discovery-related-function-headers-.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.12.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-various-NPIV-diagnostic-log-messagi.patch.
  - commit b68a391
  - md: fix rcu protection in md_wakeup_thread (CVE-2025-68374
    bsc#1255530).
  - commit 4c1b1ef
  - NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in
    pnfs_mark_layout_stateid_invalid (CVE-2025-68349 bsc#1255544).
  - commit 6b33846
  - md: init bioset in mddev_init (CVE-2025-68368 bsc#1255527).
  - commit 4b605d4
  - ipvs: fix ipv4 null-ptr-deref in route error path
    (CVE-2025-68813 bsc#1256641).
  - commit dfa5bc8
  - drm/panthor: Prevent potential UAF in group creation
    (CVE-2025-68735 bsc#1255811).
  - commit ab86e96
  - nvme: nvme-fc: Ensure ->ioerr_work is cancelled in
    nvme_fc_delete_ctrl() (CVE-2025-40261 bsc#1254839).
  - nvme-multipath: fix lockdep WARN due to partition scan work
    (CVE-2025-68218 bsc#1255245).
  - commit ff3bc4b
  - wifi: mt76: wed: use proper wed reference in mt76 wed driver
    callabacks (CVE-2025-68360 bsc#1255536).
  - commit 5863e8a
  - Refresh
    patches.kabi/bpf-Enforce-expected_attach_type-for-tailcall-compat.patch.
    Refresh kABI workaround to use 'unsigned char' instead
    of the original 'enum bpf_attach_type' as the data type.
    It was discovered at SL-16.0 MU submission time that the kABI workaround
    currently in-place does not work on -rt flavor. The reason is that due
    to preceding spinlock_t having a different size, the hole was only 2
    bytes instead of 6 bytes, and thus too small to fit 'enum'.
    Since all the possible enum values are small enough to fit within
    'unsigned char', switch the data type of the new field to that instead.
  - commit 06ff4d9
  - drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup (bsc#1255128 CVE-2025-68296)
  - commit 1b12281
  - efi/cper: Fix cper_bits_to_str buffer handling and return value
    (git-fixes).
  - lib/buildid: use __kernel_read() for sleepable context
    (git-fixes).
  - net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate
    session upon receiving the second rts (git-fixes).
  - can: ctucanfd: fix SSP_SRC in cases when bit-rate is higher
    than 1 MBit (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): fix URB memory leak
    (git-fixes).
  - can: etas_es58x: allow partial RX URB allocation to succeed
    (git-fixes).
  - commit 6b2a65b

++++ harfbuzz:

  - Add harfbuzz-CVE-2026-22693.patch: fix a NULL pointer dereference
    (bsc#1256459 CVE-2026-22693).

------------------------------------------------------------------
------------------  2026-1-15  -  Jan 15 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285 bsc#1255401).
  - commit bfcbd27
  - landlock: Fix handling of disconnected directories
    (CVE-2025-68736 bsc#1255698).
  - landlock: Optimize file path walks and prepare for audit support
    (CVE-2025-68736 bsc#1255698).
  - commit 255f197
  - libceph: fix invalid accesses to ceph_connection_v1_info (CVE-2025-39880 bsc#1250388).
  - commit f8b4e56
  - ceph: fix race condition validating r_parent before applying state (CVE-2025-39880 bsc#1250388).
  - commit 5a88d0a
  - cpuset: fix warning when disabling remote partition
    (bsc#1256794).
  - commit ab4d052
  - RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly (CVE-2025-71096 bsc#1256606)
  - commit 6757234
  - mptcp: Fix proto fallback detection with BPF (CVE-2025-68227
    bsc#1255216).
  - commit e27edfa
  - Refresh
    patches.suse/smb-client-introduce-close_cached_dir_locked-.patch.
    Just refresh to fix:
    warning: patches.suse/smb-client-introduce-close_cached_dir_locked-.patch:
    Patch unexpectedly ends in the middle of a line.
  - commit 675e06b
  - x86/fpu: Ensure XFD state on signal delivery (CVE-2025-68171
    bsc#1255255).
  - commit 74e061b

++++ kernel-rt:

  - libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285 bsc#1255401).
  - commit bfcbd27
  - landlock: Fix handling of disconnected directories
    (CVE-2025-68736 bsc#1255698).
  - landlock: Optimize file path walks and prepare for audit support
    (CVE-2025-68736 bsc#1255698).
  - commit 255f197
  - libceph: fix invalid accesses to ceph_connection_v1_info (CVE-2025-39880 bsc#1250388).
  - commit f8b4e56
  - ceph: fix race condition validating r_parent before applying state (CVE-2025-39880 bsc#1250388).
  - commit 5a88d0a
  - cpuset: fix warning when disabling remote partition
    (bsc#1256794).
  - commit ab4d052
  - RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly (CVE-2025-71096 bsc#1256606)
  - commit 6757234
  - mptcp: Fix proto fallback detection with BPF (CVE-2025-68227
    bsc#1255216).
  - commit e27edfa
  - Refresh
    patches.suse/smb-client-introduce-close_cached_dir_locked-.patch.
    Just refresh to fix:
    warning: patches.suse/smb-client-introduce-close_cached_dir_locked-.patch:
    Patch unexpectedly ends in the middle of a line.
  - commit 675e06b
  - x86/fpu: Ensure XFD state on signal delivery (CVE-2025-68171
    bsc#1255255).
  - commit 74e061b

++++ libpng16:

  - security update
  - added patches
    * libpng16-CVE-2025-22801.patch
    CVE-2026-22695 [bsc#1256525], Heap buffer over-read in png_image_finish_read
    * libpng16-CVE-2026-22695.patch
    CVE-2026-22801 [bsc#1256526], Integer truncation causing heap buffer over-read in png_image_write_*
    * libpng16-CVE-2026-22801.patch

++++ sssd:

  - Update to release 2.10.2; (jsc#PED-12449);
    * If the ssh responder is not running, sss_ssh_knownhosts will
    not fail (but it will not return the keys).
    * SSSD is now capable of handling multiple services associated
    with the same port.
    * sssd_pam, being a privileged binary, now clears the
    environment and does not allow configuration of the
    PR_SET_DUMPABLE flag as a precaution.
  - Changes from sssd 2.10.1
    * SSSD does not create anymore missing path components of
    DIR:/FILE: ccache types while acquiring user's TGT. The
    parent directory of requested ccache directory must exist and
    the user trying to log in must have rwx access to this
    directory. This matches behavior of /usr/bin/kinit.
    * The option default_domain_suffix is deprecated.
  - Changes from sssd 2.10.0
    * The ``sssctl cache-upgrade`` command was removed. SSSD
    performs automatic upgrades at startup when needed.
    * Support of ``enumeration`` feature (i.e. ability to list all
    users/groups using ``getent passwd/group`` without argument)
    for AD/IPA providers is deprecated and might be removed in
    further releases.
    * The new tool ``sss_ssh_knownhosts`` can be used with ssh's
    ``KnownHostsCommand`` configuration option to retrieve the
    host's public keys from a remote server (FreeIPA, LDAP,
    etc.). It replaces ```sss_ssh_knownhostsproxy``.
    * The default value for ``ldap_id_use_start_tls`` changed from
    false to true for improved security.
    * https://github.com/SSSD/sssd/releases/tag/2.10.0
  - Fix socket activation of responders
  - Daemon runs now as unprivileged user 'sssd'
  - Add patch:
    * 0007-TOOL-Fix-build-parameter-name-omitted.patch

------------------------------------------------------------------
------------------  2026-1-14  -  Jan 14 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - sched: Increase sched_tick_remote timeout (bsc#1254510).
  - commit 6c6193f
  - ice: fix PTP cleanup on driver removal in error path
    (CVE-2025-68215 bsc#1255226).
  - commit eb213a2
  - KVM: VMX: Clean up and macrofy x86_ops (git-fixes).
  - Refresh
    patches.suse/KVM-x86-Drop-kvm_x86_ops.set_dr6-in-favor-of-a-new-K.patch.
  - Refresh
    patches.suse/KVM-VMX-Preserve-host-s-DEBUGCTLMSR_FREEZE_IN_SMM-wh.patch.
  - commit 03cc358
  - KVM: VMX: Define a VMX glue macro for kvm_complete_insn_gp()
    (git-fixes).
  - commit 2d0bc5c
  - KVM: VMX: Move vt_apicv_pre_state_restore() to posted_intr.c
    and tweak name (git-fixes).
  - Refresh
    patches.suse/KVM-Pass-new-routing-entries-and-irqfd-when-updating.patch.
  - commit 6b2a898
  - nvme: nvme-fc: move tagset removal to nvme_fc_delete_ctrl()
    (git-fixes).
  - commit a1c2afd
  - amd/amdkfd: enhance kfd process check in switch partition
    (CVE-2025-68174 bsc#1255327).
  - commit 7117c37
  - selftests/bpf: Test bpf_skb_check_mtu(BPF_MTU_CHK_SEGS) when
    transport_header is not set (CVE-2025-68363 bsc#1255552).
  - commit ed9cc2b
  - bpf: Check skb->transport_header is set in bpf_skb_check_mtu
    (CVE-2025-68363 bsc#1255552).
  - commit 8c412fd
  - rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer (bsc#1254408 CVE-2025-38704)
  - commit 7bdb299
  - sched_ext: Fix unsafe locking in the scx_dump_state() (bsc#1255223 CVE-2025-68202)
  - commit 22f9135

++++ kernel-rt:

  - sched: Increase sched_tick_remote timeout (bsc#1254510).
  - commit 6c6193f
  - ice: fix PTP cleanup on driver removal in error path
    (CVE-2025-68215 bsc#1255226).
  - commit eb213a2
  - KVM: VMX: Clean up and macrofy x86_ops (git-fixes).
  - Refresh
    patches.suse/KVM-x86-Drop-kvm_x86_ops.set_dr6-in-favor-of-a-new-K.patch.
  - Refresh
    patches.suse/KVM-VMX-Preserve-host-s-DEBUGCTLMSR_FREEZE_IN_SMM-wh.patch.
  - commit 03cc358
  - KVM: VMX: Define a VMX glue macro for kvm_complete_insn_gp()
    (git-fixes).
  - commit 2d0bc5c
  - KVM: VMX: Move vt_apicv_pre_state_restore() to posted_intr.c
    and tweak name (git-fixes).
  - Refresh
    patches.suse/KVM-Pass-new-routing-entries-and-irqfd-when-updating.patch.
  - commit 6b2a898
  - nvme: nvme-fc: move tagset removal to nvme_fc_delete_ctrl()
    (git-fixes).
  - commit a1c2afd
  - amd/amdkfd: enhance kfd process check in switch partition
    (CVE-2025-68174 bsc#1255327).
  - commit 7117c37
  - selftests/bpf: Test bpf_skb_check_mtu(BPF_MTU_CHK_SEGS) when
    transport_header is not set (CVE-2025-68363 bsc#1255552).
  - commit ed9cc2b
  - bpf: Check skb->transport_header is set in bpf_skb_check_mtu
    (CVE-2025-68363 bsc#1255552).
  - commit 8c412fd
  - rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer (bsc#1254408 CVE-2025-38704)
  - commit 7bdb299
  - sched_ext: Fix unsafe locking in the scx_dump_state() (bsc#1255223 CVE-2025-68202)
  - commit 22f9135

++++ libzypp:

  - Avoid libcurl-mini4 when building as it does not support ftp
    protocol.
  - Translation: updated .pot file.
  - version 17.38.1 (35)

------------------------------------------------------------------
------------------  2026-1-13  -  Jan 13 2026  -------------------
------------------------------------------------------------------

++++ avahi:

  - Add avahi-CVE-2025-68276.patch:
    Backport 0c013e2 from upstream, refuse to create wide-area record
    browsers when wide-area is off.
    (CVE-2025-68276, bsc#1256498)
  - Add avahi-CVE-2025-68471.patch:
    Backport 9c6eb53 from upstream, fix DoS bug by changing assert to
    return.
    (CVE-2025-68471, bsc#1256500)
  - Add avahi-CVE-2025-68468.patch:
    Backport f66be13 from upstream, fix DoS bug by removing incorrect
    assertion.
    (CVE-2025-68468, bsc#1256499)

++++ fwupd:

  - Add 0001-Allow-systemd-service-to-access-block-sr-cdrom-devic.patch:
    allow fwupd.service to interact with cdrom (boo#1256507)

++++ kernel-default:

  - btrfs: fix reservation leak in some error paths when inserting
    inline extent (git-fixes).
  - commit 362a620
  - btrfs: do not free data reservation in fallback from inline
    due to -ENOSPC (git-fixes).
  - commit 38b35b2
  - btrfs: fix the qgroup data free range for inline data extents
    (git-fixes).
  - commit 9d6cfa8
  - btrfs: always detect conflicting inodes when logging inode refs
    (git-fixes).
  - commit 626d828
  - btrfs: release path before initializing extent tree in
    btrfs_read_locked_inode() (git-fixes).
  - commit 78aa23f
  - ext4: use optimized mballoc scanning regardless of inode format
    (bsc#1254378).
  - commit af9447d
  - supported.conf: Mark lan 743x supported (jsc#PED-14571)
  - commit b80b147
  - Set HZ=1000 for ppc64 default configuration (jsc#PED-14344)
    Update based on upstream commit a206d2334012 ("powerpc/defconfigs: Set
    HZ=1000 on ppc64 and powernv defconfigs") and requested by jsc#PED-14344.
  - commit 031e354
  - net: vxlan: prevent NULL deref in vxlan_xmit_one (CVE-2025-68353
    bsc#1255533).
  - net/mlx5: Fix IPsec cleanup over MPV device (CVE-2025-40238
    bsc#1254871).
  - net/mlx5e: RX, Fix generating skb from non-linear xdp_buff
    for striding RQ (CVE-2025-40350 bsc#1255260).
  - commit 0edf819
  - bpf: Fix invalid prog->stats access when update_effective_progs
    fails (CVE-2025-68742 bsc#1255707).
  - commit 4f8b390

++++ kernel-rt:

  - btrfs: fix reservation leak in some error paths when inserting
    inline extent (git-fixes).
  - commit 362a620
  - btrfs: do not free data reservation in fallback from inline
    due to -ENOSPC (git-fixes).
  - commit 38b35b2
  - btrfs: fix the qgroup data free range for inline data extents
    (git-fixes).
  - commit 9d6cfa8
  - btrfs: always detect conflicting inodes when logging inode refs
    (git-fixes).
  - commit 626d828
  - btrfs: release path before initializing extent tree in
    btrfs_read_locked_inode() (git-fixes).
  - commit 78aa23f
  - ext4: use optimized mballoc scanning regardless of inode format
    (bsc#1254378).
  - commit af9447d
  - supported.conf: Mark lan 743x supported (jsc#PED-14571)
  - commit b80b147
  - Set HZ=1000 for ppc64 default configuration (jsc#PED-14344)
    Update based on upstream commit a206d2334012 ("powerpc/defconfigs: Set
    HZ=1000 on ppc64 and powernv defconfigs") and requested by jsc#PED-14344.
  - commit 031e354
  - net: vxlan: prevent NULL deref in vxlan_xmit_one (CVE-2025-68353
    bsc#1255533).
  - net/mlx5: Fix IPsec cleanup over MPV device (CVE-2025-40238
    bsc#1254871).
  - net/mlx5e: RX, Fix generating skb from non-linear xdp_buff
    for striding RQ (CVE-2025-40350 bsc#1255260).
  - commit 0edf819
  - bpf: Fix invalid prog->stats access when update_effective_progs
    fails (CVE-2025-68742 bsc#1255707).
  - commit 4f8b390

++++ systemd:

  - Name libsystemd-{shared,core} based on the major version of systemd and the
    package release number (bsc#1228081 bsc#1256427)
    This way, both the old and new versions of the shared libraries will be
    present during the update. This should prevent issues during package updates
    when incompatible changes are introduced in the new versions of the shared
    libraries.

++++ nvidia-open-driver-G06-signed:

  - kernel-5.14.patch
    * fixes build for sle15-sp4

++++ python-urllib3:

  - Add CVE-2026-21441.patch to fix excessive resource consumption
    during decompression of data in HTTP redirect responses
    (bsc#1256331, CVE-2026-21441)

------------------------------------------------------------------
------------------  2026-1-12  -  Jan 12 2026  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20260112.8f614f3:
    * add ghost entries for the removed dirs
    * Revert list directories above all normal files.

++++ kernel-default:

  - perf/x86/intel: Fix KASAN global-out-of-bounds warning
    (CVE-2025-40359 bsc#1255087).
  - commit ed1e93a
  - mlx5: Fix default values in create CQ (CVE-2025-68209
    bsc#1255230).
  - commit 02d60e0
  - x86/microcode/AMD: Use sha256() instead of init/update/final
    (bsc#1256495).
  - Refresh
    patches.suse/x86-microcode-AMD-Limit-Entrysign-signature-checking-to-kn.patch.
  - commit 6b04345
  - x86/microcode/AMD: Fix Entrysign revision check for Zen5/Strix
    Halo (bsc#1256495).
  - x86/microcode/AMD: Select which microcode patch to load
    (bsc#1256495).
  - x86/microcode/AMD: Make __verify_patch_size() return bool
    (bsc#1256495).
  - x86/microcode/AMD: Remove bogus comment from parse_container()
    (bsc#1256495).
  - commit 9f14cfe
  - crash: fix crashkernel resource shrink (CVE-2025-68198 bsc#1255243)
  - commit 7e8f708
  - bnxt_en: Fix null pointer dereference in bnxt_bs_trace_check_wrap() (CVE-2025-68197 bsc#1255242)
  - commit 766431f
  - lib/crypto: aes: Fix missing MMU protection for AES S-box
    (git-fixes).
  - virtio_console: fix order of fields cols and rows
    (stable-fixes).
  - commit d55882c
  - drm/amdgpu: Forward VMID reservation errors (git-fixes).
  - commit 2373a9d
  - supported.conf: mark ksmbd unsupported
    Based on discussion with Enzo Matsumiya it has tuned out that ksmbd
    module is unsupported but the supported.conf entry is incorrect. Fix
    that.
  - commit 143566d
  - powerpc/eeh: fix recursive pci_lock_rescan_remove locking in
    EEH event handling (bsc#1253262 ltc#216029).
  - commit 594b86e
  - Update
    patches.suse/ACPI-video-Fix-use-after-free-in-acpi_video_switch_b.patch
    (git-fixes CVE-2025-40211 bsc#1254126).
  - Update
    patches.suse/ALSA-dice-fix-buffer-overflow-in-detect_stream_forma.patch
    (git-fixes CVE-2025-68346 bsc#1255603).
  - Update
    patches.suse/ALSA-firewire-motu-add-bounds-check-in-put_user-loop.patch
    (git-fixes CVE-2025-68753 bsc#1256238).
  - Update
    patches.suse/ALSA-firewire-motu-fix-buffer-overflow-in-hwdep-read.patch
    (git-fixes CVE-2025-68347 bsc#1255706).
  - Update
    patches.suse/ALSA-hda-cs35l41-Fix-NULL-pointer-dereference-in-cs3-c34b04c.patch
    (git-fixes CVE-2025-68345 bsc#1255601).
  - Update
    patches.suse/ALSA-usb-audio-Fix-NULL-pointer-dereference-in-snd_u.patch
    (git-fixes CVE-2025-40275 bsc#1254829).
  - Update
    patches.suse/ALSA-usb-audio-Fix-potential-overflow-of-PCM-transfe.patch
    (stable-fixes CVE-2025-40269 bsc#1255035).
  - Update
    patches.suse/ALSA-wavefront-Fix-integer-overflow-in-sample-size-v.patch
    (git-fixes CVE-2025-68344 bsc#1255816).
  - Update
    patches.suse/ASoC-Intel-avs-Disable-periods-elapsed-work-when-clo.patch
    (git-fixes CVE-2025-40344 bsc#1254618).
  - Update
    patches.suse/Bluetooth-6lowpan-reset-link-local-header-on-ipv6-re.patch
    (git-fixes CVE-2025-40282 bsc#1254850).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-OOB-access-in-parse_adv_monitor_p.patch
    (git-fixes CVE-2025-40294 bsc#1255181).
  - Update
    patches.suse/Bluetooth-MGMT-cancel-mesh-send-timer-when-hdev-remo.patch
    (git-fixes CVE-2025-40284 bsc#1254860).
  - Update
    patches.suse/Bluetooth-MGMT-fix-crash-in-set_mesh_sync-and-set_me.patch
    (git-fixes CVE-2025-40213 bsc#1253674).
  - Update patches.suse/Bluetooth-SCO-Fix-UAF-on-sco_conn_free.patch
    (stable-fixes CVE-2025-40309 bsc#1255065).
  - Update
    patches.suse/Bluetooth-bcsp-receive-data-only-if-registered.patch
    (stable-fixes CVE-2025-40308 bsc#1255064).
  - Update
    patches.suse/Bluetooth-btusb-mediatek-Avoid-btusb_mtk_claim_iso_i.patch
    (git-fixes CVE-2025-68298 bsc#1255124).
  - Update
    patches.suse/Bluetooth-btusb-mediatek-Fix-kernel-crash-when-relea.patch
    (git-fixes CVE-2025-68306 bsc#1255145).
  - Update
    patches.suse/Bluetooth-btusb-reorder-cleanup-in-btusb_disconnect-.patch
    (git-fixes CVE-2025-40283 bsc#1254858).
  - Update
    patches.suse/Bluetooth-hci_event-validate-skb-length-for-unknown-.patch
    (git-fixes CVE-2025-40301 bsc#1255193).
  - Update
    patches.suse/Bluetooth-hci_sock-Prevent-race-in-socket-write-iter.patch
    (git-fixes CVE-2025-68305 bsc#1255169).
  - Update
    patches.suse/Bluetooth-hci_sync-fix-race-in-hci_cmd_sync_dequeue_.patch
    (git-fixes CVE-2025-40318 bsc#1254798).
  - Update
    patches.suse/Input-cros_ec_keyb-fix-an-invalid-memory-access.patch
    (stable-fixes CVE-2025-40263 bsc#1255077).
  - Update
    patches.suse/Input-imx_sc_key-fix-memory-corruption-on-unload.patch
    (git-fixes CVE-2025-40262 bsc#1254840).
  - Update
    patches.suse/Input-pegasus-notetaker-fix-potential-out-of-bounds-.patch
    (git-fixes CVE-2025-68217 bsc#1255221).
  - Update
    patches.suse/KVM-arm64-Check-the-untrusted-offset-in-FF-A-memory-.patch
    (git-fixes CVE-2025-40266 bsc#1255040).
  - Update
    patches.suse/NFS-Fix-LTP-test-failures-when-timestamps-are-delegated.patch
    (git-fixes CVE-2025-68242 bsc#1255186).
  - Update patches.suse/NFSD-Fix-crash-in-nfsd4_read_release.patch
    (git-fixes CVE-2025-40324 bsc#1254791).
  - Update
    patches.suse/NFSD-free-copynotify-stateid-in-nfs4_free_ol_stateid.patch
    (git-fixes CVE-2025-40273 bsc#1254828).
  - Update
    patches.suse/PCI-IOV-Add-PCI-rescan-remove-locking-when-enabling-.patch
    (git-fixes CVE-2025-40219 bsc#1254518).
  - Update
    patches.suse/PCI-cadence-Check-for-the-existence-of-cdns_pcie-ops.patch
    (stable-fixes CVE-2025-68176 bsc#1255329).
  - Update
    patches.suse/accel-habanalabs-support-mapping-cb-with-vmalloc-bac.patch
    (stable-fixes CVE-2025-40311 bsc#1255068).
  - Update
    patches.suse/accel-ivpu-Fix-race-condition-when-unbinding-BOs.patch
    (git-fixes CVE-2025-68749 bsc#1255724).
  - Update
    patches.suse/amd-amdkfd-resolve-a-race-in-amdgpu_amdkfd_device_fi.patch
    (stable-fixes CVE-2025-40310 bsc#1255041).
  - Update
    patches.suse/arm64-mte-Do-not-warn-if-the-page-is-already-tagged-in-cop.patch
    (git-fixes CVE-2025-40353 bsc#1255312).
  - Update
    patches.suse/atm-fore200e-Fix-possible-data-race-in-fore200e_open.patch
    (git-fixes CVE-2025-68339 bsc#1255505).
  - Update
    patches.suse/backlight-led-bl-Add-devlink-to-supplier-LEDs.patch
    (git-fixes CVE-2025-68758 bsc#1255944).
  - Update
    patches.suse/btrfs-directly-free-partially-initialized-fs_info-in.patch
    (git-fixes CVE-2025-40235 bsc#1254808).
  - Update
    patches.suse/btrfs-ensure-no-dirty-metadata-is-written-back-for-a.patch
    (git-fix CVE-2025-40303 bsc#1255058).
  - Update
    patches.suse/btrfs-fix-memory-leak-of-qgroup_list-in-btrfs_add_qg.patch
    (git-fixes CVE-2025-40209 bsc#1254128).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-check-actual-395d988.patch
    (git-fixes CVE-2025-68342 bsc#1255508).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-check-actual.patch
    (git-fixes CVE-2025-68343 bsc#1255509).
  - Update
    patches.suse/can-gs_usb-gs_usb_xmit_callback-fix-handling-of-fail.patch
    (git-fixes CVE-2025-68307 bsc#1255146).
  - Update
    patches.suse/can-kvaser_usb-leaf-Fix-potential-infinite-loop-in-c.patch
    (git-fixes CVE-2025-68308 bsc#1255149).
  - Update
    patches.suse/comedi-c6xdigio-Fix-invalid-PNP-driver-unregistratio.patch
    (git-fixes CVE-2025-68332 bsc#1255483).
  - Update
    patches.suse/comedi-check-device-s-attached-status-in-compat-ioct.patch
    (git-fixes CVE-2025-68257 bsc#1255167).
  - Update
    patches.suse/comedi-multiq3-sanitize-config-options-in-multiq3_at.patch
    (git-fixes CVE-2025-68258 bsc#1255182).
  - Update
    patches.suse/comedi-pcl818-fix-null-ptr-deref-in-pcl818_ai_cancel.patch
    (git-fixes CVE-2025-68335 bsc#1255480).
  - Update
    patches.suse/crypto-aspeed-fix-double-free-caused-by-devm.patch
    (git-fixes CVE-2025-68172 bsc#1255253).
  - Update
    patches.suse/crypto-asymmetric_keys-prevent-overflow-in-asymmetri.patch
    (git-fixes CVE-2025-68724 bsc#1255550).
  - Update
    patches.suse/drm-amd-display-Check-NULL-before-accessing.patch
    (stable-fixes CVE-2025-68286 bsc#1255351).
  - Update
    patches.suse/drm-amd-display-Fix-NULL-deref-in-debugfs-odm_combin.patch
    (git-fixes CVE-2025-68180 bsc#1255252).
  - Update
    patches.suse/drm-amd-display-increase-max-link-count-and-fix-link.patch
    (stable-fixes CVE-2025-40354 bsc#1255316).
  - Update
    patches.suse/drm-amdgpu-Fix-NULL-pointer-dereference-in-VRAM-logi.patch
    (stable-fixes CVE-2025-40288 bsc#1255057).
  - Update
    patches.suse/drm-amdgpu-atom-Check-kcalloc-for-WS-buffer-in-amdgp.patch
    (stable-fixes CVE-2025-68190 bsc#1255131).
  - Update
    patches.suse/drm-amdgpu-fix-gpu-page-fault-after-hibernation-on-P.patch
    (stable-fixes CVE-2025-68230 bsc#1255134).
  - Update
    patches.suse/drm-amdgpu-fix-nullptr-err-of-vm_handle_moved.patch
    (stable-fixes CVE-2025-40339 bsc#1255428).
  - Update
    patches.suse/drm-amdgpu-hide-VRAM-sysfs-attributes-on-GPUs-withou.patch
    (stable-fixes CVE-2025-40289 bsc#1255042).
  - Update patches.suse/drm-amdgpu-remove-two-invalid-BUG_ON-s.patch
    (stable-fixes CVE-2025-68201 bsc#1255136).
  - Update
    patches.suse/drm-amdkfd-Fix-mmap-write-lock-not-release.patch
    (bsc#1243112 CVE-2025-40332 bsc#1255116).
  - Update
    patches.suse/drm-i915-Avoid-lock-inversion-when-pinning-to-GGTT-o.patch
    (git-fixes CVE-2025-68244 bsc#1255190).
  - Update
    patches.suse/drm-mediatek-Disable-AFBC-support-on-Mediatek-DRM-dr.patch
    (git-fixes CVE-2025-68184 bsc#1255220).
  - Update
    patches.suse/drm-mediatek-Fix-device-use-after-free-on-unbind.patch
    (git-fixes CVE-2025-40316 bsc#1254797).
  - Update
    patches.suse/drm-panthor-Fix-UAF-on-kernel-BO-VA-nodes.patch
    (git-fixes CVE-2025-68747 bsc#1255723).
  - Update
    patches.suse/drm-panthor-Fix-UAF-race-between-device-unplug-and-F.patch
    (git-fixes CVE-2025-68748 bsc#1255813).
  - Update
    patches.suse/drm-panthor-Fix-kernel-panic-on-partial-unmap-of-a-G.patch
    (git-fixes CVE-2025-40225 bsc#1254827).
  - Update
    patches.suse/drm-radeon-Do-not-kfree-devres-managed-rdev.patch
    (git-fixes CVE-2025-68170 bsc#1255256).
  - Update patches.suse/drm-radeon-Remove-calls-to-drm_put_dev.patch
    (git-fixes CVE-2025-68181 bsc#1255247).
  - Update
    patches.suse/drm-radeon-delete-radeon_fence_process-in-is_signale.patch
    (stable-fixes CVE-2025-68223 bsc#1255357).
  - Update
    patches.suse/drm-sched-Fix-deadlock-in-drm_sched_entity_kill_jobs.patch
    (git-fixes CVE-2025-40329 bsc#1254621).
  - Update
    patches.suse/drm-sysfb-Do-not-dereference-NULL-pointer-in-plane-r.patch
    (git-fixes CVE-2025-40360 bsc#1255095).
  - Update patches.suse/drm-tegra-Add-call-to-put_pid.patch
    (git-fixes CVE-2025-68233 bsc#1255206).
  - Update
    patches.suse/drm-vgem-fence-Fix-potential-deadlock-on-release.patch
    (git-fixes CVE-2025-68757 bsc#1255943).
  - Update
    patches.suse/drm-vmwgfx-Validate-command-header-size-against-SVGA.patch
    (git-fixes CVE-2025-40277 bsc#1254894).
  - Update
    patches.suse/drm-xe-Fix-oops-in-xe_gem_fault-when-running-core_ho.patch
    (stable-fixes CVE-2025-40340 bsc#1254996).
  - Update
    patches.suse/drm-xe-guc-Synchronize-Dead-CT-worker-with-unbind.patch
    (git-fixes CVE-2025-68207 bsc#1255234).
  - Update
    patches.suse/erofs-avoid-infinite-loop-due-to-incomplete-zstd-compressed-data.patch
    (git-fixes CVE-2025-68210 bsc#1255231).
  - Update
    patches.suse/exfat-fix-improper-check-of-dentry.stream.valid_size.patch
    (git-fixes CVE-2025-40287 bsc#1255030).
  - Update patches.suse/exfat-fix-refcount-leak-in-exfat_find.patch
    (git-fixes CVE-2025-68351 bsc#1255567).
  - Update
    patches.suse/exfat-validate-cluster-allocation-bits-of-the-allocation-bitmap.patch
    (git-fixes CVE-2025-40307 bsc#1255039).
  - Update
    patches.suse/fbcon-Set-fb_display-i-mode-to-NULL-when-the-mode-is.patch
    (stable-fixes CVE-2025-40323 bsc#1255094).
  - Update
    patches.suse/fbdev-Add-bounds-checking-in-bit_putcs-to-fix-vmallo.patch
    (stable-fixes CVE-2025-40304 bsc#1255034).
  - Update
    patches.suse/fbdev-bitblit-bound-check-glyph-index-in-bit_putcs.patch
    (stable-fixes CVE-2025-40322 bsc#1255092).
  - Update
    patches.suse/firmware-arm_scmi-Account-for-failed-debug-initializ.patch
    (git-fixes CVE-2025-40226 bsc#1254821).
  - Update
    patches.suse/firmware-stratix10-svc-fix-bug-in-saving-controller-.patch
    (git-fixes CVE-2025-68328 bsc#1255489).
  - Update
    patches.suse/gpiolib-fix-invalid-pointer-access-in-debugfs.patch
    (git-fixes CVE-2025-68167 bsc#1255099).
  - Update
    patches.suse/gpu-host1x-Fix-race-in-syncpt-alloc-free.patch
    (git-fixes CVE-2025-68732 bsc#1255688).
  - Update
    patches.suse/idpf-fix-possible-vport_config-NULL-pointer-deref-in.patch
    (git-fixes CVE-2025-68213 bsc#1255228).
  - Update
    patches.suse/iio-accel-bmc150-Fix-irq-assumption-regression.patch
    (stable-fixes CVE-2025-68330 bsc#1255493).
  - Update
    patches.suse/ima-Handle-error-code-returned-by-ima_filter_rule_ma.patch
    (git-fixes CVE-2025-68740 bsc#1255812).
  - Update
    patches.suse/ima-don-t-clear-IMA_DIGSIG-flag-when-setting-or-remo.patch
    (stable-fixes CVE-2025-68183 bsc#1255251).
  - Update
    patches.suse/irqchip-mchp-eic-Fix-error-code-in-mchp_eic_domain_a.patch
    (git-fixes CVE-2025-68766 bsc#1255932).
  - Update
    patches.suse/media-imon-make-send_packet-more-robust.patch
    (stable-fixes CVE-2025-68194 bsc#1255325).
  - Update
    patches.suse/media-pci-mg4b-fix-uninitialized-iio-scan-data.patch
    (git-fixes CVE-2025-40221 bsc#1254519).
  - Update
    patches.suse/media-videobuf2-forbid-remove_bufs-when-legacy-filei.patch
    (git-fixes CVE-2025-40302 bsc#1255196).
  - Update
    patches.suse/misc-fastrpc-Fix-dma_buf-object-leak-in-fastrpc_map_.patch
    (git-fixes CVE-2025-68252 bsc#1255197).
  - Update
    patches.suse/mm-secretmem-fix-use-after-free-race-in-fault-handle.patch
    (git-fixes CVE-2025-40272 bsc#1254832).
  - Update
    patches.suse/most-usb-Fix-use-after-free-in-hdm_disconnect.patch
    (git-fixes CVE-2025-40223 bsc#1254957).
  - Update
    patches.suse/most-usb-fix-double-free-on-late-probe-failure.patch
    (git-fixes CVE-2025-68290 bsc#1255154).
  - Update
    patches.suse/most-usb-hdm_probe-Fix-calling-put_device-before-dev.patch
    (git-fixes CVE-2025-68249 bsc#1255233).
  - Update
    patches.suse/mt76-mt7615-Fix-memory-leak-in-mt7615_mcu_wtbl_sta_a.patch
    (git-fixes CVE-2025-68765 bsc#1255931).
  - Update
    patches.suse/mtd-rawnand-cadence-fix-DMA-device-NULL-pointer-dere.patch
    (git-fixes CVE-2025-68238 bsc#1255202).
  - Update
    patches.suse/mtdchar-fix-integer-overflow-in-read-write-ioctls.patch
    (git-fixes CVE-2025-68237 bsc#1255203).
  - Update
    patches.suse/net-stmmac-Correctly-handle-Rx-checksum-offload-erro.patch
    (git-fixes CVE-2025-40337 bsc#1255081).
  - Update
    patches.suse/net-usb-qmi_wwan-initialize-MAC-header-offset-in-qmi.patch
    (git-fixes CVE-2025-68192 bsc#1255246).
  - Update
    patches.suse/nfs4_setup_readdir-insufficient-locking-for-d_parent-d_inode-dereferencing.patch
    (git-fixes CVE-2025-68185 bsc#1255135).
  - Update
    patches.suse/nfsd-fix-refcount-leak-in-nfsd_set_fh_dentry.patch
    (git-fixes CVE-2025-40212 bsc#1254195).
  - Update
    patches.suse/nouveau-firmware-Add-missing-kfree-of-nvkm_falcon_fw.patch
    (git-fixes CVE-2025-68235 bsc#1255209).
  - Update
    patches.suse/nvme-fc-use-lock-accessing-port_state-and-rport-stat.patch
    (bsc#1245193 bsc#1247500 CVE-2025-40342 bsc#1255274).
  - Update
    patches.suse/nvmet-fc-avoid-scheduling-association-deletion-twice.patch
    (bsc#1245193 bsc#1247500 CVE-2025-40343 bsc#1255276).
  - Update
    patches.suse/pinctrl-s32cc-fix-uninitialized-memory-in-s32_pinctr.patch
    (git-fixes CVE-2025-68222 bsc#1255218).
  - Update
    patches.suse/platform-x86-intel-punit_ipc-fix-memory-corruption.patch
    (git-fixes CVE-2025-68303 bsc#1255122).
  - Update
    patches.suse/regmap-slimbus-fix-bus_context-pointer-in-regmap-ini.patch
    (git-fixes CVE-2025-40317 bsc#1254796).
  - Update
    patches.suse/regulator-core-Protect-regulator_supply_alias_list-w.patch
    (git-fixes CVE-2025-68354 bsc#1255553).
  - Update
    patches.suse/sctp-avoid-NULL-dereference-when-chunk-data-buffer-i.patch
    (git-fixes CVE-2025-40240 bsc#1254869).
  - Update
    patches.suse/smb-client-fix-potential-cfid-UAF-in-smb2_query_info_compound.patch
    (git-fixes CVE-2025-40320 bsc#1254793).
  - Update
    patches.suse/spi-ch341-fix-out-of-bounds-memory-access-in-ch341_t.patch
    (git-fixes CVE-2025-68352 bsc#1255541).
  - Update patches.suse/spi-tegra210-quad-Fix-timeout-handling.patch
    (bsc#1253155 CVE-2025-68746 bsc#1255722).
  - Update
    patches.suse/staging-rtl8723bs-fix-out-of-bounds-read-in-OnBeacon.patch
    (stable-fixes CVE-2025-68254 bsc#1255140).
  - Update
    patches.suse/staging-rtl8723bs-fix-out-of-bounds-read-in-rtw_get_.patch
    (stable-fixes CVE-2025-68256 bsc#1255138).
  - Update
    patches.suse/staging-rtl8723bs-fix-stack-buffer-overflow-in-OnAss.patch
    (stable-fixes CVE-2025-68255 bsc#1255395).
  - Update
    patches.suse/tty-serial-ip22zilog-Use-platform-device-for-probing.patch
    (stable-fixes CVE-2025-68311 bsc#1255161).
  - Update
    patches.suse/usb-cdns3-gadget-Use-after-free-during-failed-initia.patch
    (stable-fixes CVE-2025-40314 bsc#1255072).
  - Update
    patches.suse/usb-dwc3-Fix-race-condition-between-concurrent-dwc3_.patch
    (git-fixes CVE-2025-68287 bsc#1255152).
  - Update
    patches.suse/usb-gadget-f_eem-Fix-memory-leak-in-eem_unwrap.patch
    (git-fixes CVE-2025-68289 bsc#1255155).
  - Update
    patches.suse/usb-gadget-f_fs-Fix-epfile-null-pointer-access-after.patch
    (stable-fixes CVE-2025-40315 bsc#1255083).
  - Update
    patches.suse/usb-potential-integer-overflow-in-usbg_make_tpg.patch
    (stable-fixes CVE-2025-68750 bsc#1255814).
  - Update
    patches.suse/usb-renesas_usbhs-Fix-synchronous-external-abort-on-.patch
    (git-fixes CVE-2025-68327 bsc#1255488).
  - Update
    patches.suse/usb-storage-sddr55-Reject-out-of-bound-new_pba.patch
    (stable-fixes CVE-2025-40345 bsc#1255279).
  - Update
    patches.suse/usb-uas-fix-urb-unmapping-issue-when-the-uas-device-.patch
    (git-fixes CVE-2025-68331 bsc#1255495).
  - Update patches.suse/usbnet-Prevents-free-active-kevent.patch
    (git-fixes CVE-2025-68312 bsc#1255171).
  - Update patches.suse/wifi-ath11k-fix-peer-HE-MCS-assignment.patch
    (git-fixes CVE-2025-68380 bsc#1255580).
  - Update
    patches.suse/wifi-brcmfmac-fix-crash-while-sending-Action-Frames-.patch
    (git-fixes CVE-2025-40321 bsc#1254795).
  - Update
    patches.suse/wifi-rtl818x-Fix-potential-memory-leaks-in-rtl8180_i.patch
    (git-fixes CVE-2025-68759 bsc#1255934).
  - Update
    patches.suse/wifi-rtl818x-rtl8187-Fix-potential-buffer-underflow-.patch
    (git-fixes CVE-2025-68362 bsc#1255611).
  - Update patches.suse/x86-CPU-AMD-Add-RDSEED-fix-for-Zen5.patch
    (git-fixes CVE-2025-68313 bsc#1255415).
  - Update
    patches.suse/x86-CPU-AMD-Add-missing-terminator-for-zen5_rdseed_m.patch
    (git-fixes CVE-2025-68195 bsc#1255259).
  - Update
    patches.suse/xfrm-also-call-xfrm_state_delete_tunnel-at-destroy-time-fo.patch
    (CVE-2025-40215 bsc#1254959 CVE-2025-40256 bsc#1254851).
  - commit c0f554e

++++ kernel-rt:

  - perf/x86/intel: Fix KASAN global-out-of-bounds warning
    (CVE-2025-40359 bsc#1255087).
  - commit ed1e93a
  - mlx5: Fix default values in create CQ (CVE-2025-68209
    bsc#1255230).
  - commit 02d60e0
  - x86/microcode/AMD: Use sha256() instead of init/update/final
    (bsc#1256495).
  - Refresh
    patches.suse/x86-microcode-AMD-Limit-Entrysign-signature-checking-to-kn.patch.
  - commit 6b04345
  - x86/microcode/AMD: Fix Entrysign revision check for Zen5/Strix
    Halo (bsc#1256495).
  - x86/microcode/AMD: Select which microcode patch to load
    (bsc#1256495).
  - x86/microcode/AMD: Make __verify_patch_size() return bool
    (bsc#1256495).
  - x86/microcode/AMD: Remove bogus comment from parse_container()
    (bsc#1256495).
  - commit 9f14cfe
  - crash: fix crashkernel resource shrink (CVE-2025-68198 bsc#1255243)
  - commit 7e8f708
  - bnxt_en: Fix null pointer dereference in bnxt_bs_trace_check_wrap() (CVE-2025-68197 bsc#1255242)
  - commit 766431f
  - lib/crypto: aes: Fix missing MMU protection for AES S-box
    (git-fixes).
  - virtio_console: fix order of fields cols and rows
    (stable-fixes).
  - commit d55882c
  - drm/amdgpu: Forward VMID reservation errors (git-fixes).
  - commit 2373a9d
  - supported.conf: mark ksmbd unsupported
    Based on discussion with Enzo Matsumiya it has tuned out that ksmbd
    module is unsupported but the supported.conf entry is incorrect. Fix
    that.
  - commit 143566d
  - powerpc/eeh: fix recursive pci_lock_rescan_remove locking in
    EEH event handling (bsc#1253262 ltc#216029).
  - commit 594b86e
  - Update
    patches.suse/ACPI-video-Fix-use-after-free-in-acpi_video_switch_b.patch
    (git-fixes CVE-2025-40211 bsc#1254126).
  - Update
    patches.suse/ALSA-dice-fix-buffer-overflow-in-detect_stream_forma.patch
    (git-fixes CVE-2025-68346 bsc#1255603).
  - Update
    patches.suse/ALSA-firewire-motu-add-bounds-check-in-put_user-loop.patch
    (git-fixes CVE-2025-68753 bsc#1256238).
  - Update
    patches.suse/ALSA-firewire-motu-fix-buffer-overflow-in-hwdep-read.patch
    (git-fixes CVE-2025-68347 bsc#1255706).
  - Update
    patches.suse/ALSA-hda-cs35l41-Fix-NULL-pointer-dereference-in-cs3-c34b04c.patch
    (git-fixes CVE-2025-68345 bsc#1255601).
  - Update
    patches.suse/ALSA-usb-audio-Fix-NULL-pointer-dereference-in-snd_u.patch
    (git-fixes CVE-2025-40275 bsc#1254829).
  - Update
    patches.suse/ALSA-usb-audio-Fix-potential-overflow-of-PCM-transfe.patch
    (stable-fixes CVE-2025-40269 bsc#1255035).
  - Update
    patches.suse/ALSA-wavefront-Fix-integer-overflow-in-sample-size-v.patch
    (git-fixes CVE-2025-68344 bsc#1255816).
  - Update
    patches.suse/ASoC-Intel-avs-Disable-periods-elapsed-work-when-clo.patch
    (git-fixes CVE-2025-40344 bsc#1254618).
  - Update
    patches.suse/Bluetooth-6lowpan-reset-link-local-header-on-ipv6-re.patch
    (git-fixes CVE-2025-40282 bsc#1254850).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-OOB-access-in-parse_adv_monitor_p.patch
    (git-fixes CVE-2025-40294 bsc#1255181).
  - Update
    patches.suse/Bluetooth-MGMT-cancel-mesh-send-timer-when-hdev-remo.patch
    (git-fixes CVE-2025-40284 bsc#1254860).
  - Update
    patches.suse/Bluetooth-MGMT-fix-crash-in-set_mesh_sync-and-set_me.patch
    (git-fixes CVE-2025-40213 bsc#1253674).
  - Update patches.suse/Bluetooth-SCO-Fix-UAF-on-sco_conn_free.patch
    (stable-fixes CVE-2025-40309 bsc#1255065).
  - Update
    patches.suse/Bluetooth-bcsp-receive-data-only-if-registered.patch
    (stable-fixes CVE-2025-40308 bsc#1255064).
  - Update
    patches.suse/Bluetooth-btusb-mediatek-Avoid-btusb_mtk_claim_iso_i.patch
    (git-fixes CVE-2025-68298 bsc#1255124).
  - Update
    patches.suse/Bluetooth-btusb-mediatek-Fix-kernel-crash-when-relea.patch
    (git-fixes CVE-2025-68306 bsc#1255145).
  - Update
    patches.suse/Bluetooth-btusb-reorder-cleanup-in-btusb_disconnect-.patch
    (git-fixes CVE-2025-40283 bsc#1254858).
  - Update
    patches.suse/Bluetooth-hci_event-validate-skb-length-for-unknown-.patch
    (git-fixes CVE-2025-40301 bsc#1255193).
  - Update
    patches.suse/Bluetooth-hci_sock-Prevent-race-in-socket-write-iter.patch
    (git-fixes CVE-2025-68305 bsc#1255169).
  - Update
    patches.suse/Bluetooth-hci_sync-fix-race-in-hci_cmd_sync_dequeue_.patch
    (git-fixes CVE-2025-40318 bsc#1254798).
  - Update
    patches.suse/Input-cros_ec_keyb-fix-an-invalid-memory-access.patch
    (stable-fixes CVE-2025-40263 bsc#1255077).
  - Update
    patches.suse/Input-imx_sc_key-fix-memory-corruption-on-unload.patch
    (git-fixes CVE-2025-40262 bsc#1254840).
  - Update
    patches.suse/Input-pegasus-notetaker-fix-potential-out-of-bounds-.patch
    (git-fixes CVE-2025-68217 bsc#1255221).
  - Update
    patches.suse/KVM-arm64-Check-the-untrusted-offset-in-FF-A-memory-.patch
    (git-fixes CVE-2025-40266 bsc#1255040).
  - Update
    patches.suse/NFS-Fix-LTP-test-failures-when-timestamps-are-delegated.patch
    (git-fixes CVE-2025-68242 bsc#1255186).
  - Update patches.suse/NFSD-Fix-crash-in-nfsd4_read_release.patch
    (git-fixes CVE-2025-40324 bsc#1254791).
  - Update
    patches.suse/NFSD-free-copynotify-stateid-in-nfs4_free_ol_stateid.patch
    (git-fixes CVE-2025-40273 bsc#1254828).
  - Update
    patches.suse/PCI-IOV-Add-PCI-rescan-remove-locking-when-enabling-.patch
    (git-fixes CVE-2025-40219 bsc#1254518).
  - Update
    patches.suse/PCI-cadence-Check-for-the-existence-of-cdns_pcie-ops.patch
    (stable-fixes CVE-2025-68176 bsc#1255329).
  - Update
    patches.suse/accel-habanalabs-support-mapping-cb-with-vmalloc-bac.patch
    (stable-fixes CVE-2025-40311 bsc#1255068).
  - Update
    patches.suse/accel-ivpu-Fix-race-condition-when-unbinding-BOs.patch
    (git-fixes CVE-2025-68749 bsc#1255724).
  - Update
    patches.suse/amd-amdkfd-resolve-a-race-in-amdgpu_amdkfd_device_fi.patch
    (stable-fixes CVE-2025-40310 bsc#1255041).
  - Update
    patches.suse/arm64-mte-Do-not-warn-if-the-page-is-already-tagged-in-cop.patch
    (git-fixes CVE-2025-40353 bsc#1255312).
  - Update
    patches.suse/atm-fore200e-Fix-possible-data-race-in-fore200e_open.patch
    (git-fixes CVE-2025-68339 bsc#1255505).
  - Update
    patches.suse/backlight-led-bl-Add-devlink-to-supplier-LEDs.patch
    (git-fixes CVE-2025-68758 bsc#1255944).
  - Update
    patches.suse/btrfs-directly-free-partially-initialized-fs_info-in.patch
    (git-fixes CVE-2025-40235 bsc#1254808).
  - Update
    patches.suse/btrfs-ensure-no-dirty-metadata-is-written-back-for-a.patch
    (git-fix CVE-2025-40303 bsc#1255058).
  - Update
    patches.suse/btrfs-fix-memory-leak-of-qgroup_list-in-btrfs_add_qg.patch
    (git-fixes CVE-2025-40209 bsc#1254128).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-check-actual-395d988.patch
    (git-fixes CVE-2025-68342 bsc#1255508).
  - Update
    patches.suse/can-gs_usb-gs_usb_receive_bulk_callback-check-actual.patch
    (git-fixes CVE-2025-68343 bsc#1255509).
  - Update
    patches.suse/can-gs_usb-gs_usb_xmit_callback-fix-handling-of-fail.patch
    (git-fixes CVE-2025-68307 bsc#1255146).
  - Update
    patches.suse/can-kvaser_usb-leaf-Fix-potential-infinite-loop-in-c.patch
    (git-fixes CVE-2025-68308 bsc#1255149).
  - Update
    patches.suse/comedi-c6xdigio-Fix-invalid-PNP-driver-unregistratio.patch
    (git-fixes CVE-2025-68332 bsc#1255483).
  - Update
    patches.suse/comedi-check-device-s-attached-status-in-compat-ioct.patch
    (git-fixes CVE-2025-68257 bsc#1255167).
  - Update
    patches.suse/comedi-multiq3-sanitize-config-options-in-multiq3_at.patch
    (git-fixes CVE-2025-68258 bsc#1255182).
  - Update
    patches.suse/comedi-pcl818-fix-null-ptr-deref-in-pcl818_ai_cancel.patch
    (git-fixes CVE-2025-68335 bsc#1255480).
  - Update
    patches.suse/crypto-aspeed-fix-double-free-caused-by-devm.patch
    (git-fixes CVE-2025-68172 bsc#1255253).
  - Update
    patches.suse/crypto-asymmetric_keys-prevent-overflow-in-asymmetri.patch
    (git-fixes CVE-2025-68724 bsc#1255550).
  - Update
    patches.suse/drm-amd-display-Check-NULL-before-accessing.patch
    (stable-fixes CVE-2025-68286 bsc#1255351).
  - Update
    patches.suse/drm-amd-display-Fix-NULL-deref-in-debugfs-odm_combin.patch
    (git-fixes CVE-2025-68180 bsc#1255252).
  - Update
    patches.suse/drm-amd-display-increase-max-link-count-and-fix-link.patch
    (stable-fixes CVE-2025-40354 bsc#1255316).
  - Update
    patches.suse/drm-amdgpu-Fix-NULL-pointer-dereference-in-VRAM-logi.patch
    (stable-fixes CVE-2025-40288 bsc#1255057).
  - Update
    patches.suse/drm-amdgpu-atom-Check-kcalloc-for-WS-buffer-in-amdgp.patch
    (stable-fixes CVE-2025-68190 bsc#1255131).
  - Update
    patches.suse/drm-amdgpu-fix-gpu-page-fault-after-hibernation-on-P.patch
    (stable-fixes CVE-2025-68230 bsc#1255134).
  - Update
    patches.suse/drm-amdgpu-fix-nullptr-err-of-vm_handle_moved.patch
    (stable-fixes CVE-2025-40339 bsc#1255428).
  - Update
    patches.suse/drm-amdgpu-hide-VRAM-sysfs-attributes-on-GPUs-withou.patch
    (stable-fixes CVE-2025-40289 bsc#1255042).
  - Update patches.suse/drm-amdgpu-remove-two-invalid-BUG_ON-s.patch
    (stable-fixes CVE-2025-68201 bsc#1255136).
  - Update
    patches.suse/drm-amdkfd-Fix-mmap-write-lock-not-release.patch
    (bsc#1243112 CVE-2025-40332 bsc#1255116).
  - Update
    patches.suse/drm-i915-Avoid-lock-inversion-when-pinning-to-GGTT-o.patch
    (git-fixes CVE-2025-68244 bsc#1255190).
  - Update
    patches.suse/drm-mediatek-Disable-AFBC-support-on-Mediatek-DRM-dr.patch
    (git-fixes CVE-2025-68184 bsc#1255220).
  - Update
    patches.suse/drm-mediatek-Fix-device-use-after-free-on-unbind.patch
    (git-fixes CVE-2025-40316 bsc#1254797).
  - Update
    patches.suse/drm-panthor-Fix-UAF-on-kernel-BO-VA-nodes.patch
    (git-fixes CVE-2025-68747 bsc#1255723).
  - Update
    patches.suse/drm-panthor-Fix-UAF-race-between-device-unplug-and-F.patch
    (git-fixes CVE-2025-68748 bsc#1255813).
  - Update
    patches.suse/drm-panthor-Fix-kernel-panic-on-partial-unmap-of-a-G.patch
    (git-fixes CVE-2025-40225 bsc#1254827).
  - Update
    patches.suse/drm-radeon-Do-not-kfree-devres-managed-rdev.patch
    (git-fixes CVE-2025-68170 bsc#1255256).
  - Update patches.suse/drm-radeon-Remove-calls-to-drm_put_dev.patch
    (git-fixes CVE-2025-68181 bsc#1255247).
  - Update
    patches.suse/drm-radeon-delete-radeon_fence_process-in-is_signale.patch
    (stable-fixes CVE-2025-68223 bsc#1255357).
  - Update
    patches.suse/drm-sched-Fix-deadlock-in-drm_sched_entity_kill_jobs.patch
    (git-fixes CVE-2025-40329 bsc#1254621).
  - Update
    patches.suse/drm-sysfb-Do-not-dereference-NULL-pointer-in-plane-r.patch
    (git-fixes CVE-2025-40360 bsc#1255095).
  - Update patches.suse/drm-tegra-Add-call-to-put_pid.patch
    (git-fixes CVE-2025-68233 bsc#1255206).
  - Update
    patches.suse/drm-vgem-fence-Fix-potential-deadlock-on-release.patch
    (git-fixes CVE-2025-68757 bsc#1255943).
  - Update
    patches.suse/drm-vmwgfx-Validate-command-header-size-against-SVGA.patch
    (git-fixes CVE-2025-40277 bsc#1254894).
  - Update
    patches.suse/drm-xe-Fix-oops-in-xe_gem_fault-when-running-core_ho.patch
    (stable-fixes CVE-2025-40340 bsc#1254996).
  - Update
    patches.suse/drm-xe-guc-Synchronize-Dead-CT-worker-with-unbind.patch
    (git-fixes CVE-2025-68207 bsc#1255234).
  - Update
    patches.suse/erofs-avoid-infinite-loop-due-to-incomplete-zstd-compressed-data.patch
    (git-fixes CVE-2025-68210 bsc#1255231).
  - Update
    patches.suse/exfat-fix-improper-check-of-dentry.stream.valid_size.patch
    (git-fixes CVE-2025-40287 bsc#1255030).
  - Update patches.suse/exfat-fix-refcount-leak-in-exfat_find.patch
    (git-fixes CVE-2025-68351 bsc#1255567).
  - Update
    patches.suse/exfat-validate-cluster-allocation-bits-of-the-allocation-bitmap.patch
    (git-fixes CVE-2025-40307 bsc#1255039).
  - Update
    patches.suse/fbcon-Set-fb_display-i-mode-to-NULL-when-the-mode-is.patch
    (stable-fixes CVE-2025-40323 bsc#1255094).
  - Update
    patches.suse/fbdev-Add-bounds-checking-in-bit_putcs-to-fix-vmallo.patch
    (stable-fixes CVE-2025-40304 bsc#1255034).
  - Update
    patches.suse/fbdev-bitblit-bound-check-glyph-index-in-bit_putcs.patch
    (stable-fixes CVE-2025-40322 bsc#1255092).
  - Update
    patches.suse/firmware-arm_scmi-Account-for-failed-debug-initializ.patch
    (git-fixes CVE-2025-40226 bsc#1254821).
  - Update
    patches.suse/firmware-stratix10-svc-fix-bug-in-saving-controller-.patch
    (git-fixes CVE-2025-68328 bsc#1255489).
  - Update
    patches.suse/gpiolib-fix-invalid-pointer-access-in-debugfs.patch
    (git-fixes CVE-2025-68167 bsc#1255099).
  - Update
    patches.suse/gpu-host1x-Fix-race-in-syncpt-alloc-free.patch
    (git-fixes CVE-2025-68732 bsc#1255688).
  - Update
    patches.suse/idpf-fix-possible-vport_config-NULL-pointer-deref-in.patch
    (git-fixes CVE-2025-68213 bsc#1255228).
  - Update
    patches.suse/iio-accel-bmc150-Fix-irq-assumption-regression.patch
    (stable-fixes CVE-2025-68330 bsc#1255493).
  - Update
    patches.suse/ima-Handle-error-code-returned-by-ima_filter_rule_ma.patch
    (git-fixes CVE-2025-68740 bsc#1255812).
  - Update
    patches.suse/ima-don-t-clear-IMA_DIGSIG-flag-when-setting-or-remo.patch
    (stable-fixes CVE-2025-68183 bsc#1255251).
  - Update
    patches.suse/irqchip-mchp-eic-Fix-error-code-in-mchp_eic_domain_a.patch
    (git-fixes CVE-2025-68766 bsc#1255932).
  - Update
    patches.suse/media-imon-make-send_packet-more-robust.patch
    (stable-fixes CVE-2025-68194 bsc#1255325).
  - Update
    patches.suse/media-pci-mg4b-fix-uninitialized-iio-scan-data.patch
    (git-fixes CVE-2025-40221 bsc#1254519).
  - Update
    patches.suse/media-videobuf2-forbid-remove_bufs-when-legacy-filei.patch
    (git-fixes CVE-2025-40302 bsc#1255196).
  - Update
    patches.suse/misc-fastrpc-Fix-dma_buf-object-leak-in-fastrpc_map_.patch
    (git-fixes CVE-2025-68252 bsc#1255197).
  - Update
    patches.suse/mm-secretmem-fix-use-after-free-race-in-fault-handle.patch
    (git-fixes CVE-2025-40272 bsc#1254832).
  - Update
    patches.suse/most-usb-Fix-use-after-free-in-hdm_disconnect.patch
    (git-fixes CVE-2025-40223 bsc#1254957).
  - Update
    patches.suse/most-usb-fix-double-free-on-late-probe-failure.patch
    (git-fixes CVE-2025-68290 bsc#1255154).
  - Update
    patches.suse/most-usb-hdm_probe-Fix-calling-put_device-before-dev.patch
    (git-fixes CVE-2025-68249 bsc#1255233).
  - Update
    patches.suse/mt76-mt7615-Fix-memory-leak-in-mt7615_mcu_wtbl_sta_a.patch
    (git-fixes CVE-2025-68765 bsc#1255931).
  - Update
    patches.suse/mtd-rawnand-cadence-fix-DMA-device-NULL-pointer-dere.patch
    (git-fixes CVE-2025-68238 bsc#1255202).
  - Update
    patches.suse/mtdchar-fix-integer-overflow-in-read-write-ioctls.patch
    (git-fixes CVE-2025-68237 bsc#1255203).
  - Update
    patches.suse/net-stmmac-Correctly-handle-Rx-checksum-offload-erro.patch
    (git-fixes CVE-2025-40337 bsc#1255081).
  - Update
    patches.suse/net-usb-qmi_wwan-initialize-MAC-header-offset-in-qmi.patch
    (git-fixes CVE-2025-68192 bsc#1255246).
  - Update
    patches.suse/nfs4_setup_readdir-insufficient-locking-for-d_parent-d_inode-dereferencing.patch
    (git-fixes CVE-2025-68185 bsc#1255135).
  - Update
    patches.suse/nfsd-fix-refcount-leak-in-nfsd_set_fh_dentry.patch
    (git-fixes CVE-2025-40212 bsc#1254195).
  - Update
    patches.suse/nouveau-firmware-Add-missing-kfree-of-nvkm_falcon_fw.patch
    (git-fixes CVE-2025-68235 bsc#1255209).
  - Update
    patches.suse/nvme-fc-use-lock-accessing-port_state-and-rport-stat.patch
    (bsc#1245193 bsc#1247500 CVE-2025-40342 bsc#1255274).
  - Update
    patches.suse/nvmet-fc-avoid-scheduling-association-deletion-twice.patch
    (bsc#1245193 bsc#1247500 CVE-2025-40343 bsc#1255276).
  - Update
    patches.suse/pinctrl-s32cc-fix-uninitialized-memory-in-s32_pinctr.patch
    (git-fixes CVE-2025-68222 bsc#1255218).
  - Update
    patches.suse/platform-x86-intel-punit_ipc-fix-memory-corruption.patch
    (git-fixes CVE-2025-68303 bsc#1255122).
  - Update
    patches.suse/regmap-slimbus-fix-bus_context-pointer-in-regmap-ini.patch
    (git-fixes CVE-2025-40317 bsc#1254796).
  - Update
    patches.suse/regulator-core-Protect-regulator_supply_alias_list-w.patch
    (git-fixes CVE-2025-68354 bsc#1255553).
  - Update
    patches.suse/sctp-avoid-NULL-dereference-when-chunk-data-buffer-i.patch
    (git-fixes CVE-2025-40240 bsc#1254869).
  - Update
    patches.suse/smb-client-fix-potential-cfid-UAF-in-smb2_query_info_compound.patch
    (git-fixes CVE-2025-40320 bsc#1254793).
  - Update
    patches.suse/spi-ch341-fix-out-of-bounds-memory-access-in-ch341_t.patch
    (git-fixes CVE-2025-68352 bsc#1255541).
  - Update patches.suse/spi-tegra210-quad-Fix-timeout-handling.patch
    (bsc#1253155 CVE-2025-68746 bsc#1255722).
  - Update
    patches.suse/staging-rtl8723bs-fix-out-of-bounds-read-in-OnBeacon.patch
    (stable-fixes CVE-2025-68254 bsc#1255140).
  - Update
    patches.suse/staging-rtl8723bs-fix-out-of-bounds-read-in-rtw_get_.patch
    (stable-fixes CVE-2025-68256 bsc#1255138).
  - Update
    patches.suse/staging-rtl8723bs-fix-stack-buffer-overflow-in-OnAss.patch
    (stable-fixes CVE-2025-68255 bsc#1255395).
  - Update
    patches.suse/tty-serial-ip22zilog-Use-platform-device-for-probing.patch
    (stable-fixes CVE-2025-68311 bsc#1255161).
  - Update
    patches.suse/usb-cdns3-gadget-Use-after-free-during-failed-initia.patch
    (stable-fixes CVE-2025-40314 bsc#1255072).
  - Update
    patches.suse/usb-dwc3-Fix-race-condition-between-concurrent-dwc3_.patch
    (git-fixes CVE-2025-68287 bsc#1255152).
  - Update
    patches.suse/usb-gadget-f_eem-Fix-memory-leak-in-eem_unwrap.patch
    (git-fixes CVE-2025-68289 bsc#1255155).
  - Update
    patches.suse/usb-gadget-f_fs-Fix-epfile-null-pointer-access-after.patch
    (stable-fixes CVE-2025-40315 bsc#1255083).
  - Update
    patches.suse/usb-potential-integer-overflow-in-usbg_make_tpg.patch
    (stable-fixes CVE-2025-68750 bsc#1255814).
  - Update
    patches.suse/usb-renesas_usbhs-Fix-synchronous-external-abort-on-.patch
    (git-fixes CVE-2025-68327 bsc#1255488).
  - Update
    patches.suse/usb-storage-sddr55-Reject-out-of-bound-new_pba.patch
    (stable-fixes CVE-2025-40345 bsc#1255279).
  - Update
    patches.suse/usb-uas-fix-urb-unmapping-issue-when-the-uas-device-.patch
    (git-fixes CVE-2025-68331 bsc#1255495).
  - Update patches.suse/usbnet-Prevents-free-active-kevent.patch
    (git-fixes CVE-2025-68312 bsc#1255171).
  - Update patches.suse/wifi-ath11k-fix-peer-HE-MCS-assignment.patch
    (git-fixes CVE-2025-68380 bsc#1255580).
  - Update
    patches.suse/wifi-brcmfmac-fix-crash-while-sending-Action-Frames-.patch
    (git-fixes CVE-2025-40321 bsc#1254795).
  - Update
    patches.suse/wifi-rtl818x-Fix-potential-memory-leaks-in-rtl8180_i.patch
    (git-fixes CVE-2025-68759 bsc#1255934).
  - Update
    patches.suse/wifi-rtl818x-rtl8187-Fix-potential-buffer-underflow-.patch
    (git-fixes CVE-2025-68362 bsc#1255611).
  - Update patches.suse/x86-CPU-AMD-Add-RDSEED-fix-for-Zen5.patch
    (git-fixes CVE-2025-68313 bsc#1255415).
  - Update
    patches.suse/x86-CPU-AMD-Add-missing-terminator-for-zen5_rdseed_m.patch
    (git-fixes CVE-2025-68195 bsc#1255259).
  - Update
    patches.suse/xfrm-also-call-xfrm_state_delete_tunnel-at-destroy-time-fo.patch
    (CVE-2025-40215 bsc#1254959 CVE-2025-40256 bsc#1254851).
  - commit c0f554e

++++ net-snmp:

  - Fix snmptrapd buffer overflow (bsc#1255491, CVE-2025-68615).
    Add net-snmp-5.9.4-fix-out-of-bounds-trapOid-access.patch

++++ libsoup:

  - Add libsoup-CVE-2026-0716.patch: Fix out-of-bounds read for
    websocket (bsc#1256418, CVE-2026-0716, glgo#GNOME/libsoup!494).

------------------------------------------------------------------
------------------  2026-1-11  -  Jan 11 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - docs: ABI: sysfs-devices-soc: Fix swapped sample values
    (git-fixes).
  - commit 8c83315

++++ kernel-rt:

  - docs: ABI: sysfs-devices-soc: Fix swapped sample values
    (git-fixes).
  - commit 8c83315

++++ util-linux-systemd:

  - Fix heap buffer overread in setpwnam() when processing 256-byte
    usernames (bsc#1254666, CVE-2025-14104,
    util-linux-CVE-2025-14104-1.patch,
    util-linux-CVE-2025-14104-2.patch).

++++ util-linux:

  - Fix heap buffer overread in setpwnam() when processing 256-byte
    usernames (bsc#1254666, CVE-2025-14104,
    util-linux-CVE-2025-14104-1.patch,
    util-linux-CVE-2025-14104-2.patch).

++++ libzypp:

  - zypp.conf: follow the UAPI configuration file specification
    (PED-14658)
    In short terms it means we will no longer ship an
    /etc/zypp/zypp.conf, but store our own defaults in
    /usr/etc/zypp/zypp.conf. The systems administrator may choose to
    keep a full copy in /etc/zypp/zypp.conf ignoring our config file
    settings completely, or - the preferred way - to overwrite
    specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files.
    See the ZYPP.CONF(5) man page for details.
  - cmake: correctly detect rpm6 (fixes #689)
  - Use 'zypp.tmp' as temp directory component to ease setting up
    SELinux policies (bsc#1249435)
  - zyppng: Update Provider to current MediaCurl2 download
    approach, drop Metalink ( fixes #682 )
  - version 17.38.0 (35)

------------------------------------------------------------------
------------------  2026-1-10  -  Jan 10 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - gpio: rockchip: mark the GPIO controller as sleeping
    (git-fixes).
  - drm/pl111: Fix error handling in pl111_amba_probe (git-fixes).
  - crypto: qat - fix duplicate restarting msg during AER error
    (git-fixes).
  - commit f18c9f6

++++ kernel-rt:

  - gpio: rockchip: mark the GPIO controller as sleeping
    (git-fixes).
  - drm/pl111: Fix error handling in pl111_amba_probe (git-fixes).
  - crypto: qat - fix duplicate restarting msg during AER error
    (git-fixes).
  - commit f18c9f6

------------------------------------------------------------------
------------------  2026-1-9  -  Jan 9 2026  -------------------
------------------------------------------------------------------

++++ cryptsetup:

  - Update to 2.8.3:
    * Stable bug-fix release with minor extensions.
  - Update to 2.8.2:
    * BITLK: Fix for BitLocker metadata validation on big-endian systems.

++++ python-kiwi:

  - Fixed ramdisk sysroot generator
    Do not use a custom _dev name and stick with the UUID representation
    of the disk image in RAM after deployment. Former versions of udev
    did not create a by-uuid device representation which now seems to
    have changed. This then leads to the device name RamDisk_rootfs
    not being created the and respective .device unit times out.
    In addition the timer unit for the standard device representation
    changed to infinity. This fixes bsc#1254116

++++ kernel-default:

  - io_uring/zctx: check chained notif contexts (CVE-2025-68317
    bsc#1255354).
  - commit b895dee
  - cifs: client: fix memory leak in smb3_fs_context_parse_param
    (bsc#1255082, CVE-2025-40268).
  - commit 7120bdc
  - selftests/bpf: Add test to verify freeing the special fields
    in pcpu maps (CVE-2025-68744 bsc#1255709).
  - commit 763d99d
  - drm/amdkfd: Trap handler support for expert scheduling mode
    (stable-fixes).
  - commit 021ac24
  - PCI: brcmstb: Reuse pcie_cfg_data structure (stable-fixes).
  - Refresh
    patches.suse/PCI-brcmstb-Set-generation-limit-before-PCIe-link-up.patch.
  - commit 0f681e6
  - pinctrl: qcom: lpass-lpi: mark the GPIO controller as sleeping
    (git-fixes).
  - wifi: mac80211: restore non-chanctx injection behaviour
    (git-fixes).
  - wifi: avoid kernel-infoleak from struct iw_point (git-fixes).
  - atm: Fix dma_free_coherent() size (git-fixes).
  - net: usb: pegasus: fix memory leak in update_eth_regs_async()
    (git-fixes).
  - net: wwan: iosm: Fix memory leak in ipc_mux_deinit()
    (git-fixes).
  - HID: quirks: work around VID/PID conflict for appledisplay
    (git-fixes).
  - ASoC: sun4i-spdif: Add missing kerneldoc fields for
    sun4i_spdif_quirks (git-fixes).
  - ALSA: ac97: fix a double free in snd_ac97_controller_register()
    (git-fixes).
  - usb: usb-storage: Maintain minimal modifications to the
    bcdDevice range (git-fixes).
  - serial: xilinx_uartps: fix rs485 delay_rts_after_send
    (git-fixes).
  - Input: i8042 - add TUXEDO InfinityBook Max Gen10 AMD to i8042
    quirk table (stable-fixes).
  - Input: lkkbd - disable pending work before freeing device
    (stable-fixes).
  - drm/amd/display: Fix scratch registers offsets for DCN351
    (stable-fixes).
  - drm/amd/display: Fix scratch registers offsets for DCN35
    (stable-fixes).
  - broadcom: b44: prevent uninitialized value usage (git-fixes).
  - Revert "drm/amd/display: Fix pbn to kbps Conversion"
    (stable-fixes).
  - drm/amdkfd: bump minimum vgpr size for gfx1151 (stable-fixes).
  - drm/amdkfd: Export the cwsr_size and ctl_stack_size to userspace
    (stable-fixes).
  - drm/amd/display: Use GFP_ATOMIC in dc_create_plane_state()
    (stable-fixes).
  - i2c: designware: Disable SMBus interrupts to prevent storms
    from mis-configured firmware (stable-fixes).
  - platform/x86/intel/hid: Add Dell Pro Rugged 10/12 tablet to
    VGBS DMI quirks (stable-fixes).
  - clk: qcom: dispcc-sm7150: Fix dispcc_mdss_pclk0_clk_src
    (stable-fixes).
  - usb: usb-storage: No additional quirks need to be added to
    the EL-R12 optical drive (stable-fixes).
  - usb: xhci: limit run_graceperiod for only usb 3.0 devices
    (stable-fixes).
  - usb: typec: ucsi: Handle incorrect num_connectors capability
    (stable-fixes).
  - usbip: Fix locking bug in RT-enabled kernels (stable-fixes).
  - serial: sprd: Return -EPROBE_DEFER when uart clock is not ready
    (stable-fixes).
  - char: applicom: fix NULL pointer dereference in ac_ioctl
    (stable-fixes).
  - iio: adc: ti_am335x_adc: Limit step_avg to valid range for
    gcc complains (stable-fixes).
  - fbdev: gbefb: fix to use physical address instead of dma address
    (stable-fixes).
  - via_wdt: fix critical boot hang due to unnamed resource
    allocation (stable-fixes).
  - ipmi: Fix __scan_channels() failing to rescan channels
    (stable-fixes).
  - ipmi: Fix the race between __scan_channels() and
    deliver_response() (stable-fixes).
  - reset: fix BIT macro reference (stable-fixes).
  - ti-sysc: allow OMAP2 and OMAP4 timers to be reserved on AM33xx
    (stable-fixes).
  - firmware: imx: scu-irq: Init workqueue before request mbox
    channel (stable-fixes).
  - clk: mvebu: cp110 add CLK_IGNORE_UNUSED to pcie_x10, pcie_x11 &
    pcie_x4 (stable-fixes).
  - HID: input: map HID_GD_Z to ABS_DISTANCE for stylus/pen
    (stable-fixes).
  - mmc: sdhci-msm: Avoid early clock doubling during HS400
    transition (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25H02NWxxAM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25H01NWxxAM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25H512NWxxAM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25Q02NWxxIM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25Q01NWxxIM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25Q01NWxxIQ chips
    (stable-fixes).
  - ASoC: qcom: sdw: fix memory leak for sdw_stream_runtime
    (git-fixes).
  - drm/amdgpu/gmc12: add amdgpu_vm_handle_fault() handling
    (stable-fixes).
  - drm/amdgpu/gmc11: add amdgpu_vm_handle_fault() handling
    (stable-fixes).
  - drm/displayid: add quirk to ignore DisplayID checksum errors
    (stable-fixes).
  - drm/edid: add DRM_EDID_IDENT_INIT() to initialize struct
    drm_edid_ident (stable-fixes).
  - drm/displayid: pass iter to drm_find_displayid_extension()
    (stable-fixes).
  - media: amphion: Remove vpu_vb_is_codecconfig (git-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3533 for RTL8821CE
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0x0489/0xE12F for RTL8852BE-VT
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 2b89/6275 for RTL8761BUV
    (stable-fixes).
  - Bluetooth: btusb: MT7922: Add VID/PID 0489/e170 (stable-fixes).
  - Bluetooth: btusb: MT7920: Add VID/PID 0489/e135 (stable-fixes).
  - wifi: mt76: mt792x: fix wifi init fail by setting MCU_RUNNING
    after CLC load (stable-fixes).
  - wifi: brcmfmac: Add DMI nvram filename quirk for Acer A1 840
    tablet (stable-fixes).
  - wifi: cfg80211: stop radar detection in cfg80211_leave()
    (stable-fixes).
  - wifi: cfg80211: use cfg80211_leave() in iftype change
    (stable-fixes).
  - wifi: rtl8xxxu: Fix HT40 channel config for RTL8192CU, RTL8723AU
    (stable-fixes).
  - cpufreq: nforce2: fix reference count leak in nforce2
    (git-fixes).
  - ACPI: fan: Workaround for 64-bit firmware bug (stable-fixes).
  - ACPI: property: Use ACPI functions in
    acpi_graph_get_next_endpoint() only (stable-fixes).
  - ACPICA: Avoid walking the Namespace if start_node is NULL
    (stable-fixes).
  - media: amphion: Make some vpu_v4l2 functions static
    (stable-fixes).
  - firmware: imx: Add stub functions for SCMI MISC API (git-fixes).
  - media: amphion: Add a frame flush mode for decoder
    (stable-fixes).
  - serial: xilinx_uartps: Use helper function
    hrtimer_update_function() (stable-fixes).
  - commit 52a2394
  - net/smc: fix general protection fault in __smc_diag_dump
    (CVE-2025-40357 bsc#1255097).
  - commit ef3290b
  - KVM: SVM: Don't skip unrelated instruction if INT3/INTO is
    replaced (CVE-2025-68259 bsc#1255199).
  - commit 0428a24
  - bpf: Free special fields when update [lru_,]percpu_hash maps
    (CVE-2025-68744 bsc#1255709).
  - commit ab66ed0

++++ kernel-rt:

  - io_uring/zctx: check chained notif contexts (CVE-2025-68317
    bsc#1255354).
  - commit b895dee
  - cifs: client: fix memory leak in smb3_fs_context_parse_param
    (bsc#1255082, CVE-2025-40268).
  - commit 7120bdc
  - selftests/bpf: Add test to verify freeing the special fields
    in pcpu maps (CVE-2025-68744 bsc#1255709).
  - commit 763d99d
  - drm/amdkfd: Trap handler support for expert scheduling mode
    (stable-fixes).
  - commit 021ac24
  - PCI: brcmstb: Reuse pcie_cfg_data structure (stable-fixes).
  - Refresh
    patches.suse/PCI-brcmstb-Set-generation-limit-before-PCIe-link-up.patch.
  - commit 0f681e6
  - pinctrl: qcom: lpass-lpi: mark the GPIO controller as sleeping
    (git-fixes).
  - wifi: mac80211: restore non-chanctx injection behaviour
    (git-fixes).
  - wifi: avoid kernel-infoleak from struct iw_point (git-fixes).
  - atm: Fix dma_free_coherent() size (git-fixes).
  - net: usb: pegasus: fix memory leak in update_eth_regs_async()
    (git-fixes).
  - net: wwan: iosm: Fix memory leak in ipc_mux_deinit()
    (git-fixes).
  - HID: quirks: work around VID/PID conflict for appledisplay
    (git-fixes).
  - ASoC: sun4i-spdif: Add missing kerneldoc fields for
    sun4i_spdif_quirks (git-fixes).
  - ALSA: ac97: fix a double free in snd_ac97_controller_register()
    (git-fixes).
  - usb: usb-storage: Maintain minimal modifications to the
    bcdDevice range (git-fixes).
  - serial: xilinx_uartps: fix rs485 delay_rts_after_send
    (git-fixes).
  - Input: i8042 - add TUXEDO InfinityBook Max Gen10 AMD to i8042
    quirk table (stable-fixes).
  - Input: lkkbd - disable pending work before freeing device
    (stable-fixes).
  - drm/amd/display: Fix scratch registers offsets for DCN351
    (stable-fixes).
  - drm/amd/display: Fix scratch registers offsets for DCN35
    (stable-fixes).
  - broadcom: b44: prevent uninitialized value usage (git-fixes).
  - Revert "drm/amd/display: Fix pbn to kbps Conversion"
    (stable-fixes).
  - drm/amdkfd: bump minimum vgpr size for gfx1151 (stable-fixes).
  - drm/amdkfd: Export the cwsr_size and ctl_stack_size to userspace
    (stable-fixes).
  - drm/amd/display: Use GFP_ATOMIC in dc_create_plane_state()
    (stable-fixes).
  - i2c: designware: Disable SMBus interrupts to prevent storms
    from mis-configured firmware (stable-fixes).
  - platform/x86/intel/hid: Add Dell Pro Rugged 10/12 tablet to
    VGBS DMI quirks (stable-fixes).
  - clk: qcom: dispcc-sm7150: Fix dispcc_mdss_pclk0_clk_src
    (stable-fixes).
  - usb: usb-storage: No additional quirks need to be added to
    the EL-R12 optical drive (stable-fixes).
  - usb: xhci: limit run_graceperiod for only usb 3.0 devices
    (stable-fixes).
  - usb: typec: ucsi: Handle incorrect num_connectors capability
    (stable-fixes).
  - usbip: Fix locking bug in RT-enabled kernels (stable-fixes).
  - serial: sprd: Return -EPROBE_DEFER when uart clock is not ready
    (stable-fixes).
  - char: applicom: fix NULL pointer dereference in ac_ioctl
    (stable-fixes).
  - iio: adc: ti_am335x_adc: Limit step_avg to valid range for
    gcc complains (stable-fixes).
  - fbdev: gbefb: fix to use physical address instead of dma address
    (stable-fixes).
  - via_wdt: fix critical boot hang due to unnamed resource
    allocation (stable-fixes).
  - ipmi: Fix __scan_channels() failing to rescan channels
    (stable-fixes).
  - ipmi: Fix the race between __scan_channels() and
    deliver_response() (stable-fixes).
  - reset: fix BIT macro reference (stable-fixes).
  - ti-sysc: allow OMAP2 and OMAP4 timers to be reserved on AM33xx
    (stable-fixes).
  - firmware: imx: scu-irq: Init workqueue before request mbox
    channel (stable-fixes).
  - clk: mvebu: cp110 add CLK_IGNORE_UNUSED to pcie_x10, pcie_x11 &
    pcie_x4 (stable-fixes).
  - HID: input: map HID_GD_Z to ABS_DISTANCE for stylus/pen
    (stable-fixes).
  - mmc: sdhci-msm: Avoid early clock doubling during HS400
    transition (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25H02NWxxAM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25H01NWxxAM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25H512NWxxAM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25Q02NWxxIM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25Q01NWxxIM chips
    (stable-fixes).
  - mtd: spi-nor: winbond: Add support for W25Q01NWxxIQ chips
    (stable-fixes).
  - ASoC: qcom: sdw: fix memory leak for sdw_stream_runtime
    (git-fixes).
  - drm/amdgpu/gmc12: add amdgpu_vm_handle_fault() handling
    (stable-fixes).
  - drm/amdgpu/gmc11: add amdgpu_vm_handle_fault() handling
    (stable-fixes).
  - drm/displayid: add quirk to ignore DisplayID checksum errors
    (stable-fixes).
  - drm/edid: add DRM_EDID_IDENT_INIT() to initialize struct
    drm_edid_ident (stable-fixes).
  - drm/displayid: pass iter to drm_find_displayid_extension()
    (stable-fixes).
  - media: amphion: Remove vpu_vb_is_codecconfig (git-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3533 for RTL8821CE
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0x0489/0xE12F for RTL8852BE-VT
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 2b89/6275 for RTL8761BUV
    (stable-fixes).
  - Bluetooth: btusb: MT7922: Add VID/PID 0489/e170 (stable-fixes).
  - Bluetooth: btusb: MT7920: Add VID/PID 0489/e135 (stable-fixes).
  - wifi: mt76: mt792x: fix wifi init fail by setting MCU_RUNNING
    after CLC load (stable-fixes).
  - wifi: brcmfmac: Add DMI nvram filename quirk for Acer A1 840
    tablet (stable-fixes).
  - wifi: cfg80211: stop radar detection in cfg80211_leave()
    (stable-fixes).
  - wifi: cfg80211: use cfg80211_leave() in iftype change
    (stable-fixes).
  - wifi: rtl8xxxu: Fix HT40 channel config for RTL8192CU, RTL8723AU
    (stable-fixes).
  - cpufreq: nforce2: fix reference count leak in nforce2
    (git-fixes).
  - ACPI: fan: Workaround for 64-bit firmware bug (stable-fixes).
  - ACPI: property: Use ACPI functions in
    acpi_graph_get_next_endpoint() only (stable-fixes).
  - ACPICA: Avoid walking the Namespace if start_node is NULL
    (stable-fixes).
  - media: amphion: Make some vpu_v4l2 functions static
    (stable-fixes).
  - firmware: imx: Add stub functions for SCMI MISC API (git-fixes).
  - media: amphion: Add a frame flush mode for decoder
    (stable-fixes).
  - serial: xilinx_uartps: Use helper function
    hrtimer_update_function() (stable-fixes).
  - commit 52a2394
  - net/smc: fix general protection fault in __smc_diag_dump
    (CVE-2025-40357 bsc#1255097).
  - commit ef3290b
  - KVM: SVM: Don't skip unrelated instruction if INT3/INTO is
    replaced (CVE-2025-68259 bsc#1255199).
  - commit 0428a24
  - bpf: Free special fields when update [lru_,]percpu_hash maps
    (CVE-2025-68744 bsc#1255709).
  - commit ab66ed0

++++ openvswitch:

  - Update OVN to 25.03.2
  - Bug fixes
  - Dynamic Routing:
    * Add the option "dynamic-routing-redistribute-local-only" to Logical
    Routers and Logical Router Ports which refines the way in which
    chassis-specific Advertised_Routes (e.g., for NAT and LB IPs) are
    advertised.
    * Add the option "dynamic-routing-vrf-id" to Logical Routers which allows
    CMS to specify the Linux routing table id for a given vrf.
  - Add ovn-nbctl lsp-add-router-port which will create router port on
    specified LS.
  - Add ovn-nbctl lsp-add-localnet-port which will create localnet port on
    specified LS.

++++ libsodium:

  - Update to 1.0.21: [bsc#1256070, CVE-2025-15444, bsc#1255764, CVE-2025-69277]
    * The new crypto_ipcrypt_* functions implement mechanisms for securely
    encrypting and anonymizing IP addresses.
    * The sodium_bin2ip and sodium_ip2bin helper functions have been added to
    complement the crypto_ipcrypt_* functions and easily convert addresses
    between bytes and strings.
    * XOF: the crypto_xof_shake* and crypto_xof_turboshake* functions are
    * standard
    extendable output functions. From input of any length, they can derive
    output of any length with the same properties as hash functions. These
    primitives are required by many post-quantum mechanisms, but can also be
    used for a wide range of applications, including key derivation, session
    encryption and more.
    * Performance of AES256-GCM and AEGIS on ARM has been improved with some
    compilers
    * Security: optblockers have been introduced in critical code paths to prevent
    compilers from introducing unwanted side channels via conditional jumps. This
    was observed on RISC-V targets with specific compilers and options.
    * Security: crypto_core_ed25519_is_valid_point() now properly rejects
    small-order points that are not in the main subgroup
    * ((nonnull)) attributes have been relaxed on some crypto_stream* functions to
    allow NULL output buffers when the output length is zero
    * A cross-compilation issue with old clang versions has been fixed
    * crypto_aead_aes256gcm_is_available is exported to JavaScript
    * Security: memory fences have been added after MAC verification in AEAD to
    prevent speculative access to plaintext before authentication is complete
    * Assembly files now include .gnu.property notes for proper IBT and Shadow
    Stack support when building with CET instrumentation.
  - Add patch libsodium-Fix-compilation-with-GCC-on-aarch64.patch

++++ libsoup:

  - Add libsoup-CVE-2026-0719.patch: Fix overflow for password md4sum
    (bsc#1256399, CVE-2026-0719, glgo#GNOME/libsoup!493).

++++ systemd:

  - systemd-update-helper: clean up the flags immediately after they have been
    consumed (no functional changes).
  - systemd.spec: don't reexecute PID1 on transactional updates.
  - Drop most of the workarounds contained in the fixlets.
    These workarounds were hold to address old issues that no longer exist in
    recent versions of systemd. For systems upgrading to this version, we assume
    these issues have already been fixed by the fixlet scripts still shipped by
    the previous distribution.
    Only the logig warning users about the deprecated usage of the main
    configuration files (favoring drop-in files) is preserved.

++++ libtasn1:

  - Update to libtasn1 4.21.0: [bsc#1256341, CVE-2025-13151]
    * Undocumented asn1Decoding --debug flag removed.
    * Code coverage for src/ went from 35% to 82%.
    * Fix of ASN.1 typo in manual.
    * NEWS renamed to NEWS.md and uses markdown syntax.
    * Update gnulib files and various build/maintenance fixes.
    * Fix for vulnerability CVE-2025-13151 Stack-based buffer overflow:
  - libtasn1: stack-based buffer overflow in asn1_expend_octet_string()

++++ man:

  - Do not masked out the already existing %ghost file entry
    (Accordingly to Packaging for Immutable Mode - Best Practices)

------------------------------------------------------------------
------------------  2026-1-8  -  Jan 8 2026  -------------------
------------------------------------------------------------------

++++ gpg2:

  - Security fix: [bsc#1255715, CVE-2025-68973] (gpg.fail/memcpy)
    * gpg: Fix possible memory corruption in the armor parser [T7906]
    * Add gnupg-CVE-2025-68973.patch
  - Security fix: [bsc#1256246] (gpg.fail/sha1)
    * gpg: Avoid potential downgrade to SHA1 in 3rd party key signatures [T7904]
    * Add gnupg-gpg-Avoid-potential-downgrade-to-SHA1-in-3rd-party-keysig.patch
  - Security fix: [bsc#1256244] (gpg.fail/detached)
    * gpg: Error out on unverified output for non-detached signatures [T7903]
    * Add gnupg-gpg-Error-out-on-unverified-output-for-non-detached-signatures.patch
  - Security fix: [bsc#1256390] (gpg.fail/notdash)
    * gpg2: Cleartext Signature Forgery in the NotDashEscaped header
    implementation in GnuPG
    * Add patch gnupg-notdash-escape.patch

++++ kernel-default:

  - cifs: reset iface weights when we cannot find a candidate
    (git-fixes).
  - commit 859fca4
  - smb: client: fix warning when reconnecting channel (git-fixes).
  - commit 700befa
  - cifs: do not disable interface polling on failure (git-fixes).
  - commit 87a748d
  - cifs: deal with the channel loading lag while picking channels
    (git-fixes).
  - commit c445274
  - cifs: serialize other channels when query server interfaces
    is pending (git-fixes).
  - commit 202c543
  - cifs: dns resolution is needed only for primary channel
    (git-fixes).
  - commit 47e47ab
  - cifs: update dstaddr whenever channel iface is updated
    (git-fixes).
  - commit cd217a8
  - cifs: reset connections for all channels when reconnect
    requested (git-fixes).
  - commit a324ea9
  - smb: client: introduce close_cached_dir_locked() (git-fixes).
  - commit e15b950
  - smb: client: fix potential UAF in smb2_close_cached_fid()
    (CVE-2025-40328 bsc#1254624).
  - commit f11d74a
  - binfmt_misc: restore write access before closing files opened
    by open_exec() (bsc#1255272 CVE-2025-68239).
  - commit 2983172
  - fs/proc: fix uaf in proc_readdir_de() (bsc#1255297
    CVE-2025-40271).
  - commit 46250e7
  - ext4: refresh inline data size before write operations
    (bsc#1255380 CVE-2025-68264).
  - commit c23012b
  - fs/notify: call exportfs_encode_fid with s_umount (bsc#1254809
    CVE-2025-40237).
  - commit 70d7e44
  - ext4: guard against EA inode refcount underflow in xattr update
    (bsc#1253623 CVE-2025-40190).
  - commit 6c51c0b
  - mm/damon/vaddr: do not repeat pte_offset_map_lock() until success (CVE-2025-40218 bsc#1254964)
  - commit a3828d9
  - arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() (CVE-2025-40346 bsc#1255318)
  - commit 799eb50
  - net: sxgbe: fix potential NULL dereference in sxgbe_rx() (CVE-2025-68302 bsc#1255121)
  - commit 15ce001
  - net: sched: act_ife: initialize struct tc_ife to fix KMSAN
    kernel-infoleak (CVE-2025-40278 bsc#1254825).
  - commit a5a7e57
  - Refresh
    patches.suse/perf-hwmon_pmu-Fix-uninitialized-variable-warning.patch.
  - Refresh
    patches.suse/scsi-lpfc-Add-capability-to-register-Platform-Name-I.patch.
  - Refresh
    patches.suse/scsi-lpfc-Allow-support-for-BB-credit-recovery-in-po.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ensure-unregistration-of-rpis-for-received.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-leaked-ndlp-krefs-when-in-point-to-poi.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-reusing-an-ndlp-that-is-marked-NLP_DRO.patch.
  - Refresh
    patches.suse/scsi-lpfc-Modify-kref-handling-for-Fabric-Controller.patch.
  - Refresh
    patches.suse/scsi-lpfc-Remove-redundant-NULL-ptr-assignment-in-lp.patch.
  - Refresh
    patches.suse/scsi-lpfc-Revise-discovery-related-function-headers-.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.12.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-various-NPIV-diagnostic-log-messagi.patch.
  - commit b565804
  - mm/huge_memory: fix NULL pointer deference when splitting folio
    (CVE-2025-68293 bsc#1255150).
  - commit 1dd8abe
  - iommufd: Don't overflow during division for dirty tracking
    (CVE-2025-40293 bsc#1255179).
  - commit b6a4633

++++ kernel-rt:

  - cifs: reset iface weights when we cannot find a candidate
    (git-fixes).
  - commit 859fca4
  - smb: client: fix warning when reconnecting channel (git-fixes).
  - commit 700befa
  - cifs: do not disable interface polling on failure (git-fixes).
  - commit 87a748d
  - cifs: deal with the channel loading lag while picking channels
    (git-fixes).
  - commit c445274
  - cifs: serialize other channels when query server interfaces
    is pending (git-fixes).
  - commit 202c543
  - cifs: dns resolution is needed only for primary channel
    (git-fixes).
  - commit 47e47ab
  - cifs: update dstaddr whenever channel iface is updated
    (git-fixes).
  - commit cd217a8
  - cifs: reset connections for all channels when reconnect
    requested (git-fixes).
  - commit a324ea9
  - smb: client: introduce close_cached_dir_locked() (git-fixes).
  - commit e15b950
  - smb: client: fix potential UAF in smb2_close_cached_fid()
    (CVE-2025-40328 bsc#1254624).
  - commit f11d74a
  - binfmt_misc: restore write access before closing files opened
    by open_exec() (bsc#1255272 CVE-2025-68239).
  - commit 2983172
  - fs/proc: fix uaf in proc_readdir_de() (bsc#1255297
    CVE-2025-40271).
  - commit 46250e7
  - ext4: refresh inline data size before write operations
    (bsc#1255380 CVE-2025-68264).
  - commit c23012b
  - fs/notify: call exportfs_encode_fid with s_umount (bsc#1254809
    CVE-2025-40237).
  - commit 70d7e44
  - ext4: guard against EA inode refcount underflow in xattr update
    (bsc#1253623 CVE-2025-40190).
  - commit 6c51c0b
  - mm/damon/vaddr: do not repeat pte_offset_map_lock() until success (CVE-2025-40218 bsc#1254964)
  - commit a3828d9
  - arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() (CVE-2025-40346 bsc#1255318)
  - commit 799eb50
  - net: sxgbe: fix potential NULL dereference in sxgbe_rx() (CVE-2025-68302 bsc#1255121)
  - commit 15ce001
  - net: sched: act_ife: initialize struct tc_ife to fix KMSAN
    kernel-infoleak (CVE-2025-40278 bsc#1254825).
  - commit a5a7e57
  - Refresh
    patches.suse/perf-hwmon_pmu-Fix-uninitialized-variable-warning.patch.
  - Refresh
    patches.suse/scsi-lpfc-Add-capability-to-register-Platform-Name-I.patch.
  - Refresh
    patches.suse/scsi-lpfc-Allow-support-for-BB-credit-recovery-in-po.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ensure-unregistration-of-rpis-for-received.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-leaked-ndlp-krefs-when-in-point-to-poi.patch.
  - Refresh
    patches.suse/scsi-lpfc-Fix-reusing-an-ndlp-that-is-marked-NLP_DRO.patch.
  - Refresh
    patches.suse/scsi-lpfc-Modify-kref-handling-for-Fabric-Controller.patch.
  - Refresh
    patches.suse/scsi-lpfc-Remove-redundant-NULL-ptr-assignment-in-lp.patch.
  - Refresh
    patches.suse/scsi-lpfc-Revise-discovery-related-function-headers-.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.12.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-various-NPIV-diagnostic-log-messagi.patch.
  - commit b565804
  - mm/huge_memory: fix NULL pointer deference when splitting folio
    (CVE-2025-68293 bsc#1255150).
  - commit 1dd8abe
  - iommufd: Don't overflow during division for dirty tracking
    (CVE-2025-40293 bsc#1255179).
  - commit b6a4633

++++ libsodium:

  - Security fix: [bsc#1256070, CVE-2025-15444]
    * check Y==Z in addition to X==0
    * Add patch libsodium-CVE-2025-15444.patch

++++ libsoup:

  - Add libsoup-CVE-2025-14523.patch: Reject duplicated Host in
    headers (bsc#1254876, CVE-2025-14523, glgo#GNOME/libsoup!491).

++++ opensuse-migration-tool:

  - Update to version 20260106.d2cfd39:
    * Update scripts/20_pulse2pipewire.sh
    * Update scripts/20_ia32.sh
    * Update scripts/20_pulse2pipewire.sh
    * Consistent no-use of sudo in migration scripts
    * Update scripts/10_keepapparmor.sh
    * Update scripts/10_keepselinux.sh
    * Update scripts/10_keepapparmor.sh
    * Update scripts/10_keepapparmor.sh
    * Update opensuse-migration-tool
    * Update scripts/10_keepselinux.sh
    * Improve DRYRUN option to work well even from scripts
    * Enable migration to SElinux with proper dryrun
    * Update 10_keepselinux.sh
    * Update 10_keepapparmor.sh
    * Update 10_keepapparmor.sh

------------------------------------------------------------------
------------------  2026-1-7  -  Jan 7 2026  -------------------
------------------------------------------------------------------

++++ curl:

  - Security fix: [bsc#1256105, CVE-2025-14017]
    * call ldap_init() before setting the options
    * Add patch curl-CVE-2025-14017.patch

++++ kernel-default:

  - libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (CVE-2025-68284 bsc#1255377).
  - commit 9132138
  - libceph: replace BUG_ON with bounds check for map->max_osd (CVE-2025-68283 bsc#1255379).
  - commit 0f51ab5
  - ceph: fix multifs mds auth caps issue (CVE-2025-40362 bsc#1255103).
  - commit 9fee071
  - fuse: fix livelock in synchronous file put from fuseblk workers (CVE-2025-40220 bsc#1254520).
  - commit 9838be9
  - ASoC: codecs: wcd937x: fix OF node leaks on probe failure
    (git-fixes).
  - ASoC: Intel: soc-acpi: arl: Correct order of cs42l43 matches
    (git-fixes).
  - commit 1cc2d04

++++ kernel-rt:

  - libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (CVE-2025-68284 bsc#1255377).
  - commit 9132138
  - libceph: replace BUG_ON with bounds check for map->max_osd (CVE-2025-68283 bsc#1255379).
  - commit 0f51ab5
  - ceph: fix multifs mds auth caps issue (CVE-2025-40362 bsc#1255103).
  - commit 9fee071
  - fuse: fix livelock in synchronous file put from fuseblk workers (CVE-2025-40220 bsc#1254520).
  - commit 9838be9
  - ASoC: codecs: wcd937x: fix OF node leaks on probe failure
    (git-fixes).
  - ASoC: Intel: soc-acpi: arl: Correct order of cs42l43 matches
    (git-fixes).
  - commit 1cc2d04

++++ samba:

  - samba-ad-dc-libs packages are missing a DLZ plugin for bind 9.20;
    (bso#15790); (bsc#1249058).

++++ systemd:

  - Drop %filetriggers build flag. It was introduced to ease backport of
    Base:System to SLE distros where file-triggers were unreliable but that is no
    longer the case on the latest SLE distros.

++++ rust-keylime:

  - Use tmpfiles.d for /var directories (PED-14736)
    + tmpfiles.keylime renamed to rust-keylime.conf and extended
  - Update to version 0.2.8+96:
    * build(deps): bump wiremock from 0.6.4 to 0.6.5
    * build(deps): bump actions/checkout from 5 to 6
    * build(deps): bump chrono from 0.4.41 to 0.4.42
    * packit: Get coverage from Fedora 43 runs
    * Fix issues pointed out by clippy
    * Replace mutex unwraps with proper error handling in TPM library
    * Remove unused session request methods from StructureFiller
    * Fix config panic on missing ek_handle in push model agent
    * build(deps): bump tempfile from 3.21.0 to 3.23.0
    * build(deps): bump actions/upload-artifact from 4 to 6 (#1163)
    * Fix clippy warnings project-wide
    * Add KEYLIME_DIR support for verifier TLS certificates in push model agent
    * Thread privileged resources and use MeasurementList for IMA reading
    * Add privileged resource initialization and privilege dropping to push model agent
    * Fix privilege dropping order in run_as()
    * add documentation on FQDN hostnames
    * Remove confusing logs for push mode agent
    * Set correct default Verifier port (8891->8881) (#1159)
    * Add verifier_url to reference configuration file (#1158)
    * Add TLS support for Registrar communication (#1139)
    * Fix agent handling of 403 registration responses (#1154)
    * Add minor README.md rephrasing (#1151)
    * build(deps): bump actions/checkout from 5 to 6 (#1153)
    * ci: update spec files for packit COPR build
    * docs: improve challenge encoding and async TPM documentation
    * refactor: improve middleware and error handling
    * feat: add authentication client with middleware integration
    * docker: Include keylime_push_model_agent binary
    * Include attestation_interval configuration (#1146)
    * Persist payload keys to avoid attestation failure on restart
    * crypto: Implement the load or generate pattern for keys
    * Use simple algorithm specifiers in certification_keys object (#1140)
    * tests: Enable more tests in CI
    * Fix RSA2048 algorithm reporting in keylime agent
    * Remove disabled_signing_algorithms configuration
    * rpm: Fix metadata patches to apply to current code
    * workflows/rpm.yml: Use more strict patching
    * build(deps): bump uuid from 1.17.0 to 1.18.1
    * Fix ECC algorithm selection and reporting for keylime agent
    * Improve logging consistency and coherency
    * Implement minimal RFC compliance for Location header and URI parsing (#1125)
    * Use separate keys for payload mechanism and mTLS
    * docker: update rust to 1.81 for distroless Dockerfile
    * Ensure UEFI log capabilities are set to false
    * build(deps): bump http from 1.1.0 to 1.3.1
    * build(deps): bump log from 0.4.27 to 0.4.28
    * build(deps): bump cfg-if from 1.0.1 to 1.0.3
    * build(deps): bump actix-rt from 2.10.0 to 2.11.0
    * build(deps): bump async-trait from 0.1.88 to 0.1.89
    * build(deps): bump trybuild from 1.0.105 to 1.0.110
    * Accept evidence handling structures null entries
    * workflows: Add test to check if RPM patches still apply
    * CI: Enable test add-agent-with-malformed-ek-cert
    * config: Fix singleton tests
    * FSM: Remove needless lifetime annotations (#1105)
    * rpm: Do not remove wiremock which is now available in Fedora
    * Use latest Fedora httpdate version (1.0.3)
    * Enhance coverage with parse_retry_after test
    * Fix issues reported by CI regarding unwrap() calls
    * Reuse max retries indicated to the ResilientClient
    * Include limit of retries to 5 for Retry-After
    * Add policy to handle Retry-After response headers
    * build(deps): bump wiremock from 0.6.3 to 0.6.4
    * build(deps): bump serde_json from 1.0.140 to 1.0.143
    * build(deps): bump pest_derive from 2.8.0 to 2.8.1
    * build(deps): bump syn from 2.0.90 to 2.0.106
    * build(deps): bump tempfile from 3.20.0 to 3.21.0
    * build(deps): bump thiserror from 2.0.12 to 2.0.16
    * rpm: Fix patches to apply to current master code
    * build(deps): bump anyhow from 1.0.98 to 1.0.99
    * state_machine: Automatically clean config override during tests
    * config: Implement singleton and factory pattern
    * testing: Support overriding configuration during tests
    * feat: implement standalone challenge-response authentication module
    * structures: rename session structs for clarity and fix typos
    * tpm: refactor certify_credential_with_iak() into a more generic function
    * Add Push Model Agent Mermaid FSM chart (#1095)
    * Add state to avoid exiting on wrong attestation (#1093)
    * Add 6 alphanumeric lowercase X-Request-ID header
    * Enhance Evidence Handling response parsing
    * build(deps): bump quote from 1.0.35 to 1.0.40
    * build(deps): bump libc from 0.2.172 to 0.2.175
    * build(deps): bump glob from 0.3.2 to 0.3.3
    * build(deps): bump actix-web from 4.10.2 to 4.11.0

++++ selinux-policy:

  - Update to version 20250627+git345.3965b24b0:
    * Allow 'mysql-systemd-helper upgrade' to work correctly (bsc#1255024)

------------------------------------------------------------------
------------------  2026-1-6  -  Jan 6 2026  -------------------
------------------------------------------------------------------

++++ dpdk:

  - Update to version 24.11.4
    * LTS update with ~250 fixes, details here:
    https://doc.dpdk.org/guides-24.11/rel_notes/release_24_11.html#id10
  - Update to version 24.11.3
    * LTS release update contains ~180 fixes from main branch up to DPDK 25.07
  - Fixes CVE-2025-23259 -- an attacker on a VM in the system can cause
    information disclosure and denial of service (bsc#1254161)
    * remove included patch 0001-dts-generate-random-capture_name-per-call.patch
  - Remove obsolete build option -Denable_kmods (upstream a52d472c5)
  - dpdk-tools requires "which" and is noarch
  - Drop pesign and needssslcertforbuild because we don't build a kmp anymore
    (boo#1247389)

++++ kernel-default:

  - devlink: rate: Unset parent pointer in devl_rate_nodes_destroy
    (CVE-2025-40251 bsc#1254856).
  - commit da56dba
  - net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower()
    (bsc#1255156 CVE-2025-40255).
  - commit 57e1c6f
  - PCI/DOE: Poll DOE Busy bit for up to 1 second in
    pci_doe_send_req() (bsc#1255868).
  - commit 44c675f

++++ kernel-rt:

  - devlink: rate: Unset parent pointer in devl_rate_nodes_destroy
    (CVE-2025-40251 bsc#1254856).
  - commit da56dba
  - net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower()
    (bsc#1255156 CVE-2025-40255).
  - commit 57e1c6f
  - PCI/DOE: Poll DOE Busy bit for up to 1 second in
    pci_doe_send_req() (bsc#1255868).
  - commit 44c675f

------------------------------------------------------------------
------------------  2026-1-5  -  Jan 5 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - net: sched: act_connmark: initialize struct tc_ife to fix
    kernel leak (CVE-2025-40279 bsc#1254846).
  - commit cb9f7bb
  - btrfs: do not skip logging new dentries when logging a new name
    (git-fixes).
  - commit ec916c6
  - btrfs: don't log conflicting inode if it's a dir moved in the
    current transaction (git-fixes).
  - commit a690d41
  - btrfs: fix changeset leak on mmap write after failure to
    reserve metadata (git-fixes).
  - commit 75e4299
  - team: Move team device type change at the end of team_port_add
    (CVE-2025-68340 bsc#1255507).
  - net/mlx5: Clean up only new IRQ glue on request_irq() failure
    (CVE-2025-40250 bsc#1254854).
  - net: qlogic/qede: fix potential out-of-bounds read in
    qede_tpa_cont() and qede_tpa_end() (CVE-2025-40252 bsc#1254849).
  - net: enetc: fix the deadlock of enetc_mdio_lock (CVE-2025-40347
    bsc#1255262).
  - commit 085c913
  - ASoC: Intel: avs: Do not share the name pointer between
    components (CVE-2025-40338 bsc#1255273).
  - commit fb15ec5
  - usb: phy: isp1301: fix non-OF device reference imbalance
    (git-fixes).
  - usb: gadget: lpc32xx_udc: fix clock imbalance in error path
    (git-fixes).
  - serial: core: Fix serial device initialization (git-fixes).
  - commit 592ca99
  - wifi: mac80211: do not use old MBSSID elements (git-fixes).
  - wifi: cfg80211: sme: store capped length in
    __cfg80211_connect_result() (git-fixes).
  - wifi: rtlwifi: 8192cu: fix tid out of range in
    rtl92cu_tx_fill_desc() (git-fixes).
  - wifi: rtw88: limit indirect IO under powered off for RTL8822CS
    (git-fixes).
  - usb: ohci-nxp: fix device leak on probe failure (git-fixes).
  - usb: dwc3: of-simple: fix clock resource leak in
    dwc3_of_simple_probe (git-fixes).
  - USB: lpc32xx_udc: Fix error handling in probe (git-fixes).
  - usb: typec: altmodes/displayport: Drop the device reference
    in dp_altmode_probe() (git-fixes).
  - usb: renesas_usbhs: Fix a resource leak in usbhs_pipe_malloc()
    (git-fixes).
  - usb: dwc3: keep susphy enabled during exit to avoid controller
    faults (git-fixes).
  - usb: dwc2: fix hang during shutdown if set as peripheral
    (git-fixes).
  - wifi: ath10k: move recovery check logic into a new work
    (git-fixes).
  - wifi: ath10k: Add missing include of export.h (stable-fixes).
  - wifi: ath10k: Avoid vdev delete timeout when firmware is
    already down (stable-fixes).
  - commit 07af9a3
  - of: unittest: Fix memory leak in unittest_data_add()
    (git-fixes).
  - drm/i915/gem: Zero-initialize the eb.vma array in
    i915_gem_do_execbuffer (git-fixes).
  - drm/nouveau/dispnv50: Don't call drm_atomic_get_crtc_state()
    in prepare_fb (git-fixes).
  - platform/x86: hp-bioscfg: Fix out-of-bounds array access in
    ACPI package parsing (git-fixes).
  - platform/x86: ibm_rtl: fix EBDA signature search pointer
    arithmetic (git-fixes).
  - platform/x86: msi-laptop: add missing sysfs_remove_group()
    (git-fixes).
  - platform/mellanox: mlxbf-pmc: Remove trailing whitespaces from
    event names (git-fixes).
  - net: rose: fix invalid array index in rose_kill_by_device()
    (git-fixes).
  - net: usb: sr9700: fix incorrect command used to write single
    register (git-fixes).
  - net: nfc: fix deadlock between nfc_unregister_device and
    rfkill_fop_write (git-fixes).
  - net: usb: rtl8150: fix memory leak on usb_submit_urb() failure
    (git-fixes).
  - net: mdio: aspeed: add dummy read to avoid read-after-write
    issue (git-fixes).
  - idr: fix idr_alloc() returning an ID out of range (git-fixes).
  - genalloc.h: fix htmldocs warning (git-fixes).
  - serial: sh-sci: Check that the DMA cookie is valid (git-fixes).
  - serial: core: Restore sysfs fwnode information (git-fixes).
  - firewire: nosy: Fix dma_free_coherent() size (git-fixes).
  - Input: ti_am335x_tsc - fix off-by-one error in wire_order
    validation (git-fixes).
  - Input: alps - fix use-after-free bugs caused by
    dev3_register_work (git-fixes).
  - Input: atkbd - skip deactivate for HONOR FMB-P's internal
    keyboard (git-fixes).
  - spi: cadence-quadspi: Fix clock disable on probe failure path
    (git-fixes).
  - spi: fsl-cpm: Check length parity before switching to 16 bit
    mode (git-fixes).
  - hwmon: (ltc4282): Fix reset_history file permissions
    (git-fixes).
  - hwmon: (tmp401) fix overflow caused by default conversion rate
    value (git-fixes).
  - hwmon: (ibmpex) fix use-after-free in high/low store
    (git-fixes).
  - hwmon: (dell-smm) Limit fan multiplier to avoid overflow
    (git-fixes).
  - mmc: sdhci-esdhc-imx: add alternate ARCH_S32 dependency to
    Kconfig (git-fixes).
  - mmc: sdhci-of-arasan: Increase CD stable timeout to 2 seconds
    (git-fixes).
  - PM: runtime: Do not clear needs_force_resume with enabled
    runtime PM (git-fixes).
  - nfc: pn533: Fix error code in pn533_acr122_poweron_rdr()
    (git-fixes).
  - r8169: fix RTL8117 Wake-on-Lan in DASH mode (git-fixes).
  - net: phy: marvell-88q2xxx: Fix clamped value in
    mv88q2xxx_hwmon_write (git-fixes).
  - firmware_loader: make RUST_FW_LOADER_ABSTRACTIONS select
    FW_LOADER (git-fixes).
  - efi/cper: align ARM CPER type with UEFI 2.9A/2.10 specs
    (stable-fixes).
  - efi/cper: Add a new helper function to print bitmasks
    (stable-fixes).
  - efi/cper: Adjust infopfx size to accept an extra space
    (stable-fixes).
  - usb: dwc2: disable platform lowlevel hw resources during
    shutdown (stable-fixes).
  - resource: introduce is_type_match() helper and use it
    (stable-fixes).
  - resource: replace open coded resource_intersection()
    (stable-fixes).
  - commit 0273be1
  - accel/ivpu: Prevent runtime suspend during context abort work
    (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Trigger-device-recovery-on-engine-reset-r.patch.
  - commit 79c3327
  - drm/imagination: Disallow exporting of PM/FW protected objects
    (git-fixes).
  - Bluetooth: btusb: revert use of devm_kzalloc in btusb
    (git-fixes).
  - crypto: seqiv - Do not use req->iv after crypto_aead_encrypt
    (git-fixes).
  - drm/msm/dpu: Add missing NULL pointer check for pingpong
    interface (git-fixes).
  - ASoC: ak4458: remove the reset operation in probe and remove
    (git-fixes).
  - ASoC: fsl_sai: Constrain sample rates from audio PLLs only in
    master mode (git-fixes).
  - ALSA: usb-mixer: us16x08: validate meter packet indices
    (git-fixes).
  - ALSA: pcmcia: Fix resource leak in snd_pdacf_probe error path
    (git-fixes).
  - ALSA: vxpocket: Fix resource leak in vxpocket_probe error path
    (git-fixes).
  - drm/xe: Use usleep_range for accurate long-running workload
    timeslicing (git-fixes).
  - drm/xe: Drop preempt-fences when destroying imported dma-bufs
    (git-fixes).
  - drm/xe/oa: Disallow 0 OA property values (git-fixes).
  - drm/xe: Adjust long-running workload timeslices to reasonable
    values (git-fixes).
  - drm/xe/oa: Limit num_syncs to prevent oversized allocations
    (git-fixes).
  - drm/xe: Limit num_syncs to prevent oversized allocations
    (git-fixes).
  - drm/xe: Restore engine registers before restarting schedulers
    after GT reset (git-fixes).
  - drm/xe/bo: Don't include the CCS metadata in the dma-buf
    sg-table (git-fixes).
  - drm/me/gsc: mei interrupt top half should be in irq disabled
    context (git-fixes).
  - drm/panel: sony-td4353-jdi: Enable prepare_prev_first
    (git-fixes).
  - ACPI: PCC: Fix race condition by removing static qualifier
    (git-fixes).
  - ACPI: CPPC: Fix missing PCC check for guaranteed_perf
    (git-fixes).
  - can: j1939: make j1939_sk_bind() fail if device is no longer
    registered (git-fixes).
  - can: gs_usb: gs_can_open(): fix error handling (git-fixes).
  - ASoC: codecs: nau8325: Silence uninitialized variables warnings
    (stable-fixes).
  - ASoC: nau8325: use simple i2c probe function (stable-fixes).
  - ALSA: wavefront: Fix integer overflow in sample size validation
    (git-fixes).
  - accel/ivpu: Ensure rpm_runtime_put in case of engine
    reset/resume fail (git-fixes).
  - commit bc5d2b7
  - bpf: Fix stackmap overflow check in __bpf_get_stackid()
    (CVE-2025-68378 bsc#1255614).
  - commit 7a823bd
  - bpf: Refactor stack map trace depth calculation into helper
    function (CVE-2025-68378 bsc#1255614).
  - commit 296727b

++++ kernel-rt:

  - net: sched: act_connmark: initialize struct tc_ife to fix
    kernel leak (CVE-2025-40279 bsc#1254846).
  - commit cb9f7bb
  - btrfs: do not skip logging new dentries when logging a new name
    (git-fixes).
  - commit ec916c6
  - btrfs: don't log conflicting inode if it's a dir moved in the
    current transaction (git-fixes).
  - commit a690d41
  - btrfs: fix changeset leak on mmap write after failure to
    reserve metadata (git-fixes).
  - commit 75e4299
  - team: Move team device type change at the end of team_port_add
    (CVE-2025-68340 bsc#1255507).
  - net/mlx5: Clean up only new IRQ glue on request_irq() failure
    (CVE-2025-40250 bsc#1254854).
  - net: qlogic/qede: fix potential out-of-bounds read in
    qede_tpa_cont() and qede_tpa_end() (CVE-2025-40252 bsc#1254849).
  - net: enetc: fix the deadlock of enetc_mdio_lock (CVE-2025-40347
    bsc#1255262).
  - commit 085c913
  - ASoC: Intel: avs: Do not share the name pointer between
    components (CVE-2025-40338 bsc#1255273).
  - commit fb15ec5
  - usb: phy: isp1301: fix non-OF device reference imbalance
    (git-fixes).
  - usb: gadget: lpc32xx_udc: fix clock imbalance in error path
    (git-fixes).
  - serial: core: Fix serial device initialization (git-fixes).
  - commit 592ca99
  - wifi: mac80211: do not use old MBSSID elements (git-fixes).
  - wifi: cfg80211: sme: store capped length in
    __cfg80211_connect_result() (git-fixes).
  - wifi: rtlwifi: 8192cu: fix tid out of range in
    rtl92cu_tx_fill_desc() (git-fixes).
  - wifi: rtw88: limit indirect IO under powered off for RTL8822CS
    (git-fixes).
  - usb: ohci-nxp: fix device leak on probe failure (git-fixes).
  - usb: dwc3: of-simple: fix clock resource leak in
    dwc3_of_simple_probe (git-fixes).
  - USB: lpc32xx_udc: Fix error handling in probe (git-fixes).
  - usb: typec: altmodes/displayport: Drop the device reference
    in dp_altmode_probe() (git-fixes).
  - usb: renesas_usbhs: Fix a resource leak in usbhs_pipe_malloc()
    (git-fixes).
  - usb: dwc3: keep susphy enabled during exit to avoid controller
    faults (git-fixes).
  - usb: dwc2: fix hang during shutdown if set as peripheral
    (git-fixes).
  - wifi: ath10k: move recovery check logic into a new work
    (git-fixes).
  - wifi: ath10k: Add missing include of export.h (stable-fixes).
  - wifi: ath10k: Avoid vdev delete timeout when firmware is
    already down (stable-fixes).
  - commit 07af9a3
  - of: unittest: Fix memory leak in unittest_data_add()
    (git-fixes).
  - drm/i915/gem: Zero-initialize the eb.vma array in
    i915_gem_do_execbuffer (git-fixes).
  - drm/nouveau/dispnv50: Don't call drm_atomic_get_crtc_state()
    in prepare_fb (git-fixes).
  - platform/x86: hp-bioscfg: Fix out-of-bounds array access in
    ACPI package parsing (git-fixes).
  - platform/x86: ibm_rtl: fix EBDA signature search pointer
    arithmetic (git-fixes).
  - platform/x86: msi-laptop: add missing sysfs_remove_group()
    (git-fixes).
  - platform/mellanox: mlxbf-pmc: Remove trailing whitespaces from
    event names (git-fixes).
  - net: rose: fix invalid array index in rose_kill_by_device()
    (git-fixes).
  - net: usb: sr9700: fix incorrect command used to write single
    register (git-fixes).
  - net: nfc: fix deadlock between nfc_unregister_device and
    rfkill_fop_write (git-fixes).
  - net: usb: rtl8150: fix memory leak on usb_submit_urb() failure
    (git-fixes).
  - net: mdio: aspeed: add dummy read to avoid read-after-write
    issue (git-fixes).
  - idr: fix idr_alloc() returning an ID out of range (git-fixes).
  - genalloc.h: fix htmldocs warning (git-fixes).
  - serial: sh-sci: Check that the DMA cookie is valid (git-fixes).
  - serial: core: Restore sysfs fwnode information (git-fixes).
  - firewire: nosy: Fix dma_free_coherent() size (git-fixes).
  - Input: ti_am335x_tsc - fix off-by-one error in wire_order
    validation (git-fixes).
  - Input: alps - fix use-after-free bugs caused by
    dev3_register_work (git-fixes).
  - Input: atkbd - skip deactivate for HONOR FMB-P's internal
    keyboard (git-fixes).
  - spi: cadence-quadspi: Fix clock disable on probe failure path
    (git-fixes).
  - spi: fsl-cpm: Check length parity before switching to 16 bit
    mode (git-fixes).
  - hwmon: (ltc4282): Fix reset_history file permissions
    (git-fixes).
  - hwmon: (tmp401) fix overflow caused by default conversion rate
    value (git-fixes).
  - hwmon: (ibmpex) fix use-after-free in high/low store
    (git-fixes).
  - hwmon: (dell-smm) Limit fan multiplier to avoid overflow
    (git-fixes).
  - mmc: sdhci-esdhc-imx: add alternate ARCH_S32 dependency to
    Kconfig (git-fixes).
  - mmc: sdhci-of-arasan: Increase CD stable timeout to 2 seconds
    (git-fixes).
  - PM: runtime: Do not clear needs_force_resume with enabled
    runtime PM (git-fixes).
  - nfc: pn533: Fix error code in pn533_acr122_poweron_rdr()
    (git-fixes).
  - r8169: fix RTL8117 Wake-on-Lan in DASH mode (git-fixes).
  - net: phy: marvell-88q2xxx: Fix clamped value in
    mv88q2xxx_hwmon_write (git-fixes).
  - firmware_loader: make RUST_FW_LOADER_ABSTRACTIONS select
    FW_LOADER (git-fixes).
  - efi/cper: align ARM CPER type with UEFI 2.9A/2.10 specs
    (stable-fixes).
  - efi/cper: Add a new helper function to print bitmasks
    (stable-fixes).
  - efi/cper: Adjust infopfx size to accept an extra space
    (stable-fixes).
  - usb: dwc2: disable platform lowlevel hw resources during
    shutdown (stable-fixes).
  - resource: introduce is_type_match() helper and use it
    (stable-fixes).
  - resource: replace open coded resource_intersection()
    (stable-fixes).
  - commit 0273be1
  - accel/ivpu: Prevent runtime suspend during context abort work
    (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Trigger-device-recovery-on-engine-reset-r.patch.
  - commit 79c3327
  - drm/imagination: Disallow exporting of PM/FW protected objects
    (git-fixes).
  - Bluetooth: btusb: revert use of devm_kzalloc in btusb
    (git-fixes).
  - crypto: seqiv - Do not use req->iv after crypto_aead_encrypt
    (git-fixes).
  - drm/msm/dpu: Add missing NULL pointer check for pingpong
    interface (git-fixes).
  - ASoC: ak4458: remove the reset operation in probe and remove
    (git-fixes).
  - ASoC: fsl_sai: Constrain sample rates from audio PLLs only in
    master mode (git-fixes).
  - ALSA: usb-mixer: us16x08: validate meter packet indices
    (git-fixes).
  - ALSA: pcmcia: Fix resource leak in snd_pdacf_probe error path
    (git-fixes).
  - ALSA: vxpocket: Fix resource leak in vxpocket_probe error path
    (git-fixes).
  - drm/xe: Use usleep_range for accurate long-running workload
    timeslicing (git-fixes).
  - drm/xe: Drop preempt-fences when destroying imported dma-bufs
    (git-fixes).
  - drm/xe/oa: Disallow 0 OA property values (git-fixes).
  - drm/xe: Adjust long-running workload timeslices to reasonable
    values (git-fixes).
  - drm/xe/oa: Limit num_syncs to prevent oversized allocations
    (git-fixes).
  - drm/xe: Limit num_syncs to prevent oversized allocations
    (git-fixes).
  - drm/xe: Restore engine registers before restarting schedulers
    after GT reset (git-fixes).
  - drm/xe/bo: Don't include the CCS metadata in the dma-buf
    sg-table (git-fixes).
  - drm/me/gsc: mei interrupt top half should be in irq disabled
    context (git-fixes).
  - drm/panel: sony-td4353-jdi: Enable prepare_prev_first
    (git-fixes).
  - ACPI: PCC: Fix race condition by removing static qualifier
    (git-fixes).
  - ACPI: CPPC: Fix missing PCC check for guaranteed_perf
    (git-fixes).
  - can: j1939: make j1939_sk_bind() fail if device is no longer
    registered (git-fixes).
  - can: gs_usb: gs_can_open(): fix error handling (git-fixes).
  - ASoC: codecs: nau8325: Silence uninitialized variables warnings
    (stable-fixes).
  - ASoC: nau8325: use simple i2c probe function (stable-fixes).
  - ALSA: wavefront: Fix integer overflow in sample size validation
    (git-fixes).
  - accel/ivpu: Ensure rpm_runtime_put in case of engine
    reset/resume fail (git-fixes).
  - commit bc5d2b7
  - bpf: Fix stackmap overflow check in __bpf_get_stackid()
    (CVE-2025-68378 bsc#1255614).
  - commit 7a823bd
  - bpf: Refactor stack map trace depth calculation into helper
    function (CVE-2025-68378 bsc#1255614).
  - commit 296727b

++++ libpcap:

  - Security fix: [bsc#1255765, CVE-2025-11961]
    * Fix out-of-bound-write and out-of-bound-read in pcap_ether_aton()
    due to missing validation of provided MAC-48 address string
    * Add libpcap-CVE-2025-11961.patch

------------------------------------------------------------------
------------------  2026-1-3  -  Jan 3 2026  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Actually build and install manpages:
    * These were originally removed because including them would
    have required pulling a nasty set of ghc/pandocs build
    dependencies directly into Ring 1
    * fwupd upstream quickly reverted this change in 1.8.13, but
    the conditional to block building/installing the manpages by
    default was never removed from the specfile
    * This restores the fwupd manpages, which have been sorely
    missing in openSUSE for a couple years

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to version 580.126.09 (boo#1255858)

------------------------------------------------------------------
------------------  2026-1-2  -  Jan 2 2026  -------------------
------------------------------------------------------------------

++++ curl:

  - Security fixes:
    * [bsc#1255731, CVE-2025-14524] if redirected, require permission to use bearer
    * [bsc#1255734, CVE-2025-15224] require private key or user-agent for public key auth
    * [bsc#1255732, CVE-2025-14819] toggling CURLSSLOPT_NO_PARTIALCHAIN makes a different CA cache
    * [bsc#1255733, CVE-2025-15079] set both knownhosts options to the same file
    * Add patches:
  - curl-CVE-2025-14524.patch
  - curl-CVE-2025-15224.patch
  - curl-CVE-2025-14819.patch
  - curl-CVE-2025-15079.patch

++++ kernel-default:

  - powerpc/kexec: Enable SMT before waking offline CPUs
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1253739 ltc#211493 bsc#1254244 ltc#216496).
  - commit 2cae729
  - ftrace: bpf: Fix IPMODIFY + DIRECT in modify_ftrace_direct()
    (git-fixes).
  - commit fa39b88
  - uprobe: Do not emulate/sstep original instruction when ip is
    changed (git-fixes).
  - commit d467aca

++++ kernel-rt:

  - powerpc/kexec: Enable SMT before waking offline CPUs
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1253739 ltc#211493 bsc#1254244 ltc#216496).
  - commit 2cae729
  - ftrace: bpf: Fix IPMODIFY + DIRECT in modify_ftrace_direct()
    (git-fixes).
  - commit fa39b88
  - uprobe: Do not emulate/sstep original instruction when ip is
    changed (git-fixes).
  - commit d467aca

------------------------------------------------------------------
------------------  2026-1-1  -  Jan 1 2026  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: ufs: core: Fix PM QoS mutex initialization (git-fixes).
  - commit d4f8c1e

++++ kernel-rt:

  - scsi: ufs: core: Fix PM QoS mutex initialization (git-fixes).
  - commit d4f8c1e

++++ c-ares:

  - c-ares 1.35.6:
    * CVE-2025-62408: use-after-free in read_answers() (boo#1254738)
    * Ignore Windows IDN Search Domains until proper IDN support is
    added
    * Various bug fixes

------------------------------------------------------------------
------------------  2025-12-31  -  Dec 31 2025  -------------------
------------------------------------------------------------------

++++ fde-tools:

  - Add fde-tools.conf to create /var/log/fde with tmpfiles.d
    (jsc#PED-14754)

++++ kernel-default:

  - sysfs: check visibility before changing group attribute
    ownership (CVE-2025-40355 bsc#1255261).
  - commit 880a26c
  - kabi: fix struct ufs_hba changes (bsc#1253414 CVE-2025-40130).
  - commit fc77a12
  - tracing: Fix race condition in kprobe initialization causing
    NULL pointer dereference (CVE-2025-40042 bsc#1252861).
  - commit bdfa48f

++++ kernel-rt:

  - sysfs: check visibility before changing group attribute
    ownership (CVE-2025-40355 bsc#1255261).
  - commit 880a26c
  - kabi: fix struct ufs_hba changes (bsc#1253414 CVE-2025-40130).
  - commit fc77a12
  - tracing: Fix race condition in kprobe initialization causing
    NULL pointer dereference (CVE-2025-40042 bsc#1252861).
  - commit bdfa48f

------------------------------------------------------------------
------------------  2025-12-30  -  Dec 30 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - KVM: SEV: Drop GHCB_VERSION_DEFAULT and open code it
    (bsc#1255672).
  - Refresh
    patches.suse/KVM-SEV-Enforce-minimum-GHCB-version-requirement-for.patch.
  - Refresh
    patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch.
  - commit 24d45f1
  - scsi: ufs: core: Fix data race in CPU latency PM QoS request
    handling (CVE-2025-40130 bsc#1253414).
  - commit ebfcb5d

++++ kernel-rt:

  - KVM: SEV: Drop GHCB_VERSION_DEFAULT and open code it
    (bsc#1255672).
  - Refresh
    patches.suse/KVM-SEV-Enforce-minimum-GHCB-version-requirement-for.patch.
  - Refresh
    patches.suse/KVM-SEV-Rename-kvm_ghcb_get_sw_exit_code-to-kvm_get_.patch.
  - commit 24d45f1
  - scsi: ufs: core: Fix data race in CPU latency PM QoS request
    handling (CVE-2025-40130 bsc#1253414).
  - commit ebfcb5d

------------------------------------------------------------------
------------------  2025-12-29  -  Dec 29 2025  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.717.g75494a30:
    Fix and update testsuite (bsc#1254873):
    * test(FULL-SYSTEMD): ignore errors in systemd-vconsole-setup.service
    * test: move /failed to /run/failed as rootfs might be read-only
    * test(FULL-SYSTEMD): use poweroff to shut down test
    * test(FULL SYSTEMD): no need to include dbus to the target rootfs
    * test: make the size of all test drives 512 MB
    * fix(systemd): move installation of libkmod to udev-rules module
    * test: switch to virtio for the QEMU drive
    * test: switch to virtio for the QEMU drive
    * test: increase test VM memory from 512M to 1024M to avoid OOM killer
    * test: move more common test code to test-functions
    * test: upgrade to ext4
    Other:
    * fix(nfs): do not execute logic in nfs hooks if netroot is not nfs (bsc#1253960)

++++ kernel-default:

  - cpuidle: menu: Use residency threshold in polling state override
    decisions (bsc#1255026).
  - commit 652c9d1

++++ kernel-rt:

  - cpuidle: menu: Use residency threshold in polling state override
    decisions (bsc#1255026).
  - commit 652c9d1

------------------------------------------------------------------
------------------  2025-12-28  -  Dec 28 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20251217.34fd7bc:
    * add tmpfiles template adm-backup.conf (jsc#PED-14803)
    * Revert ec7f00fa60f11d28b427f2e224822a7b81825806
    * Fix old script to support copy mode as well
    * Support for XDG environment variables for the su,
    * adapted sugggestions
    * Patching nsswitch.conf only if it has not been generated by nsswitch-config (JIRA-#PED-13807).
    * Avoid nasty exceptions running tput

++++ kernel-default:

  - supported.conf: Update path for ufs drivers
    As part of bsc#1253414 CVE-2025-40130, which updates
    the ufs driver, it was discovered that the pathnames
    in the supported module list had the old ufs driver
    pathnames, which was drivers/scsi/ufs. But the
    ufs drivers are now in drivers/ufs.
    Also, the ti-j721e-ufs modules is now in the "host"
    subdirectory.
  - commit 0d9f529

++++ kernel-rt:

  - supported.conf: Update path for ufs drivers
    As part of bsc#1253414 CVE-2025-40130, which updates
    the ufs driver, it was discovered that the pathnames
    in the supported module list had the old ufs driver
    pathnames, which was drivers/scsi/ufs. But the
    ufs drivers are now in drivers/ufs.
    Also, the ti-j721e-ufs modules is now in the "host"
    subdirectory.
  - commit 0d9f529

------------------------------------------------------------------
------------------  2025-12-23  -  Dec 23 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - selftests/bpf: Test widen_imprecise_scalars() with different
    stack depth (CVE-2025-68208 bsc#1255227).
  - commit cbc44e7
  - bpf: account for current allocated stack depth in
    widen_imprecise_scalars() (CVE-2025-68208 bsc#1255227).
  - commit ac93c78
  - gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242
    bsc#1255075).
  - commit d162d45

++++ kernel-rt:

  - selftests/bpf: Test widen_imprecise_scalars() with different
    stack depth (CVE-2025-68208 bsc#1255227).
  - commit cbc44e7
  - bpf: account for current allocated stack depth in
    widen_imprecise_scalars() (CVE-2025-68208 bsc#1255227).
  - commit ac93c78
  - gfs2: Fix unlikely race in gdlm_put_lock (CVE-2025-40242
    bsc#1255075).
  - commit d162d45

------------------------------------------------------------------
------------------  2025-12-22  -  Dec 22 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - netfilter: nft_ct: add seqadj extension for natted connections
    (CVE-2025-68206 bsc#1255142).
  - commit c2d456f
  - sctp: Prevent TOCTOU out-of-bounds write (CVE-2025-40331
    bsc#1254615).
  - commit cd21b6d
  - net: bridge: fix use-after-free due to MST port state bypass
    (CVE-2025-40297 bsc#1255187).
  - commit 656c4a6
  - bpf: Sync pending IRQ work before freeing ring buffer
    (CVE-2025-40319 bsc#1254794).
  - commit 0031a97

++++ kernel-rt:

  - netfilter: nft_ct: add seqadj extension for natted connections
    (CVE-2025-68206 bsc#1255142).
  - commit c2d456f
  - sctp: Prevent TOCTOU out-of-bounds write (CVE-2025-40331
    bsc#1254615).
  - commit cd21b6d
  - net: bridge: fix use-after-free due to MST port state bypass
    (CVE-2025-40297 bsc#1255187).
  - commit 656c4a6
  - bpf: Sync pending IRQ work before freeing ring buffer
    (CVE-2025-40319 bsc#1254794).
  - commit 0031a97

++++ sssd:

  - Fix sssctl config-check exit code when the conf.d snippets
    directory does not exist; (bsc#1230348); Add patch
    0006-SSSCTL-config-check-do-not-return-an-error-if-snippe.patch

++++ udisks2:

  - (CVE-2025-8067) VUL-0: missing bounds check can lead to out-of-bounds
    read in udisks daemon (bsc#1248502)
    + add 0001-udiskslinuxmanager-Add-lower-bounds-check-to-fd_inde.patch
  - Fix dbus daemon requires, it's dbus-service, not dbus-1

++++ podman:

  - Add patch for CVE-2025-47914 (bsc#1253993), CVE-2025-47913 (bsc#1253542):
    * 0006-CVE-2025-47913-CVE-2025-47914-ssh-agent-fixes.patch
  - Rebase patches:
    * 0001-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch
    * 0002-Fix-Remove-appending-rw-as-the-default-mount-option.patch
    * 0003-CVE-2025-6032-machine-init-fix-tls-check.patch
    * 0004-CVE-2025-9566-kube-play-don-t-follow-volume-symlinks.patch
    * 0005-CVE-2025-52881-backport-subset-of-patch-from-runc.patch

------------------------------------------------------------------
------------------  2025-12-21  -  Dec 21 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ocfs2: clear extent cache after moving/defragmenting extents
    (CVE-2025-40233 bsc#1254813).
  - commit 852b35f
  - net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170
    bsc#1253413).
  - commit 2787f89

++++ kernel-rt:

  - ocfs2: clear extent cache after moving/defragmenting extents
    (CVE-2025-40233 bsc#1254813).
  - commit 852b35f
  - net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170
    bsc#1253413).
  - commit 2787f89

------------------------------------------------------------------
------------------  2025-12-19  -  Dec 19 2025  -------------------
------------------------------------------------------------------

++++ busybox:

  - Fix tar hidden files via escape sequence (CVE-2025-46394, bsc#1241661)
    * 0001-archival-libarchive-sanitize-filenames-on-output-pre.patch
  - Fix HTTP request header injection in wget (CVE-2025-60876, bsc#1253245)
    * wget-don-t-allow-control-characters-in-url.patch
  - Set CONFIG_FIRST_SYSTEM_ID to 201 to avoid confclict (bsc#1236670)
  - Fix unshare -mrpf sh core dump on  ppc64le (bsc#1249237)
    * 0001-nsenter-unshare-don-t-use-xvfork_parent_waits_and_ex.patch

++++ fwupd:

  - Update to version 2.0.19:
    + This release adds the following features:
  - Add two commands to fwupdtool to calculate and find CRCs
  - Allow systems to use the udev event source without using systemd
    + This release fixes the following bugs:
  - Always show the correct new firmware version in 'fwupdmgr get-history'
  - Fix an integer underflow when parsing a malicious PE file
  - Fix a regression when enumerating the dell-dock status component
  - Fix the fuzzer timeout when parsing a synaptics-rmi SBL container
  - Fix updating the Intel GPU FWDATA section
  - Respect 'fwupdmgr --force' when installing firmware
    + This release adds support for the following hardware:
  - Lenovo Sapphire Folio Keyboard

++++ kernel-default:

  - tipc: Fix use-after-free in tipc_mon_reinit_self()
    (CVE-2025-40280 bsc#1254847).
  - commit 1a4ecc3
  - cgroup: rstat: use LOCK CMPXCHG in css_rstat_updated
    (bsc#1255434).
  - bpf: Do not limit bpf_cgroup_from_id to current's namespace
    (bsc#1255433).
  - commit f9dd89c
  - virtio-net: fix received length check in big packets (bsc#1255175, CVE-2025-40292).
  - commit d9c33d8
  - af_unix: Initialise scc_index in unix_add_edge() (CVE-2025-40214
    bsc#1254961).
  - commit f4d0234
  - net: atlantic: fix fragment overflow handling in RX path
    (CVE-2025-68301 bsc#1255120).
  - net: openvswitch: remove never-working support for setting
    nsh fields (CVE-2025-40254 bsc#1254852).
  - commit ca34a4d
  - vsock: Ignore signal/timeout on connect() if already established
    (CVE-2025-40248, bsc#1254864).
  - commit 8f55c39
  - vsock: fix lock inversion in vsock_assign_transport()
    (CVE-2025-40231, bsc#1254815).
  - commit 1f7e22a
  - xen/events: Return -EEXIST for bound VIRQs (CVE-2025-40160,
    bsc#1253400).
  - commit 3883ce8
  - xen/events: Cleanup find_virq() return codes (CVE-2025-40160,
    bsc#1253400).
  - commit 8f641eb

++++ kernel-rt:

  - tipc: Fix use-after-free in tipc_mon_reinit_self()
    (CVE-2025-40280 bsc#1254847).
  - commit 1a4ecc3
  - cgroup: rstat: use LOCK CMPXCHG in css_rstat_updated
    (bsc#1255434).
  - bpf: Do not limit bpf_cgroup_from_id to current's namespace
    (bsc#1255433).
  - commit f9dd89c
  - virtio-net: fix received length check in big packets (bsc#1255175, CVE-2025-40292).
  - commit d9c33d8
  - af_unix: Initialise scc_index in unix_add_edge() (CVE-2025-40214
    bsc#1254961).
  - commit f4d0234
  - net: atlantic: fix fragment overflow handling in RX path
    (CVE-2025-68301 bsc#1255120).
  - net: openvswitch: remove never-working support for setting
    nsh fields (CVE-2025-40254 bsc#1254852).
  - commit ca34a4d
  - vsock: Ignore signal/timeout on connect() if already established
    (CVE-2025-40248, bsc#1254864).
  - commit 8f55c39
  - vsock: fix lock inversion in vsock_assign_transport()
    (CVE-2025-40231, bsc#1254815).
  - commit 1f7e22a
  - xen/events: Return -EEXIST for bound VIRQs (CVE-2025-40160,
    bsc#1253400).
  - commit 3883ce8
  - xen/events: Cleanup find_virq() return codes (CVE-2025-40160,
    bsc#1253400).
  - commit 8f641eb

++++ systemd:

  - Add 0001-Drop-or-soften-some-upstream-warnings.patch (bsc#1228728) (bsc#1251981)
    For now it just drops the 'unmerged-bin' taint flag.

------------------------------------------------------------------
------------------  2025-12-18  -  Dec 18 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - selftests: net: fib-onlink-tests: Set high metric for default
    IPv6 route (bsc#1255346).
  - selftests: net: use slowwait to make sure IPv6 setup finished
    (bsc#1255349).
  - selftests: net: use slowwait to stabilize vrf_route_leaking test
    (bsc#1255349).
  - commit 18154f6
  - kABI: xfrm: delete x->tunnel as we delete x (bsc#1254959
    CVE-2025-40215).
  - commit 23f1b71
  - be2net: pass wrb_params in case of OS2BMC (CVE-2025-40264
    bsc#1254835).
  - net: phy: micrel: always set shared->phydev for LAN8814
    (CVE-2025-40239 bsc#1254868).
  - commit 48a9709

++++ kernel-rt:

  - selftests: net: fib-onlink-tests: Set high metric for default
    IPv6 route (bsc#1255346).
  - selftests: net: use slowwait to make sure IPv6 setup finished
    (bsc#1255349).
  - selftests: net: use slowwait to stabilize vrf_route_leaking test
    (bsc#1255349).
  - commit 18154f6
  - kABI: xfrm: delete x->tunnel as we delete x (bsc#1254959
    CVE-2025-40215).
  - commit 23f1b71
  - be2net: pass wrb_params in case of OS2BMC (CVE-2025-40264
    bsc#1254835).
  - net: phy: micrel: always set shared->phydev for LAN8814
    (CVE-2025-40239 bsc#1254868).
  - commit 48a9709

++++ samba:

  - Adjust README.SUSE to reflect the new preferred location for
    '[printers]' share; (bsc#1254665).

------------------------------------------------------------------
------------------  2025-12-17  -  Dec 17 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/panthor: Flush shmem writes before mapping buffers CPU-uncached (CVE-2025-40276 bsc#1254824).
  - commit a018fa4
  - mptcp: fix race condition in mptcp_schedule_work()
    (CVE-2025-40258 bsc#1254843).
  - commit 37cfb37
  - netdevsim: print human readable IP address (bsc#1255071).
  - commit f4d9e1a
  - selftests/bpf: Skip timer cases when bpf_timer is not supported
    (git-fixes).
  - commit 52f69d8
  - bpf: Reject bpf_timer for PREEMPT_RT (git-fixes).
  - commit 772432b
  - xfs: fix out of bounds memory read error in symlink repair
    (CVE-2025-40246 bsc#1254861).
  - commit 520885a
  - xfs: Replace strncpy with memcpy (git-fixes).
  - commit d262779
  - KVM: guest_memfd: Remove bindings on memslot deletion when
    gmem is dying (CVE-2025-40274, bsc#1254830).
  - commit bf3055c
  - btrfs: handle aligned EOF truncation correctly for subpage cases
    (bsc#1253238).
  - commit abcc81c

++++ kernel-rt:

  - drm/panthor: Flush shmem writes before mapping buffers CPU-uncached (CVE-2025-40276 bsc#1254824).
  - commit a018fa4
  - mptcp: fix race condition in mptcp_schedule_work()
    (CVE-2025-40258 bsc#1254843).
  - commit 37cfb37
  - netdevsim: print human readable IP address (bsc#1255071).
  - commit f4d9e1a
  - selftests/bpf: Skip timer cases when bpf_timer is not supported
    (git-fixes).
  - commit 52f69d8
  - bpf: Reject bpf_timer for PREEMPT_RT (git-fixes).
  - commit 772432b
  - xfs: fix out of bounds memory read error in symlink repair
    (CVE-2025-40246 bsc#1254861).
  - commit 520885a
  - xfs: Replace strncpy with memcpy (git-fixes).
  - commit d262779
  - KVM: guest_memfd: Remove bindings on memslot deletion when
    gmem is dying (CVE-2025-40274, bsc#1254830).
  - commit bf3055c
  - btrfs: handle aligned EOF truncation correctly for subpage cases
    (bsc#1253238).
  - commit abcc81c

++++ samba:

  -  Fix Samba printers reporting invalid sid during print jobs;
    (bsc#1234210); (bsc#1254926); (bso#15792).

++++ man:

  - Extend tmpfiles template man-db.conf (jsc#PED-14862)
    * Create cache directories with systemd tmpfiles service

++++ selinux-policy:

  - Update to version 20250627+git343.b66ec7135:
    * Allow snapper_tu_etc_plugin_t to connect to machined varlink socket (bsc#1254889)

------------------------------------------------------------------
------------------  2025-12-16  -  Dec 16 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - tick/sched: Limit non-timekeeper CPUs calling jiffies update
    (bsc#1254477).
  - commit 5c0d7c3
  - futex: Prevent use-after-free during requeue-PI (CVE-2025-39977
    bsc#1252046).
  - commit 584a8ca
  - xfrm: also call xfrm_state_delete_tunnel at destroy time for
    states that were never added (CVE-2025-40215 bsc#1254959).
  - commit e9b2533

++++ kernel-rt:

  - tick/sched: Limit non-timekeeper CPUs calling jiffies update
    (bsc#1254477).
  - commit 5c0d7c3
  - futex: Prevent use-after-free during requeue-PI (CVE-2025-39977
    bsc#1252046).
  - commit 584a8ca
  - xfrm: also call xfrm_state_delete_tunnel at destroy time for
    states that were never added (CVE-2025-40215 bsc#1254959).
  - commit e9b2533

++++ systemd:

  - Import commit 5701fd5fb409da99b6627b86d7839553079a73ab
    5701fd5fb4 timer: rebase last_trigger timestamp if needed
    4e76e74d0d timer: rebase the next elapse timestamp only if timer didn't already run

++++ shim:

  - shim-install: Add ca_string for SL Micro to update fallback loader
    The fallback loader, /boot/efi/EFI/BOOT/bootaa64.efi or bootx64.efi,
    cannot be upgraded by shim-install on SL Micro. The issue case is
    SL Micro 6.0. It causes that system gets regression bug because it's
    fallback to a old shim. So this patch adds ca_string to SL Micro.
    (bsc#1254336)

------------------------------------------------------------------
------------------  2025-12-15  -  Dec 15 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - xfrm: delete x->tunnel as we delete x (CVE-2025-40215
    bsc#1254959).
  - commit 2fc5164
  - net: call cond_resched() less often in __release_sock()
    (git-fixes).
  - commit 38a2c24
  - bnxt_en: Shutdown FW DMA in bnxt_shutdown() (CVE-2025-40330
    bsc#1254616).
  - commit b08b65b
  - Update
    patches.kabi/devlink_hide_adding_u64_to_devlink_param_types.patch
    (jsc#PED-12745).
  - Refresh
    patches.suse/devlink-Add-support-for-u64-parameters.patch.
  - Delete
    patches.suse/devlink-avoid-param-type-value-translations.patch.
    Fix kABI breakage, caused by adding U64 type to DEVLINK_PARAM_TYPE (bsc#1254363)
  - commit 4d0e363

++++ kernel-rt:

  - xfrm: delete x->tunnel as we delete x (CVE-2025-40215
    bsc#1254959).
  - commit 2fc5164
  - net: call cond_resched() less often in __release_sock()
    (git-fixes).
  - commit 38a2c24
  - bnxt_en: Shutdown FW DMA in bnxt_shutdown() (CVE-2025-40330
    bsc#1254616).
  - commit b08b65b
  - Update
    patches.kabi/devlink_hide_adding_u64_to_devlink_param_types.patch
    (jsc#PED-12745).
  - Refresh
    patches.suse/devlink-Add-support-for-u64-parameters.patch.
  - Delete
    patches.suse/devlink-avoid-param-type-value-translations.patch.
    Fix kABI breakage, caused by adding U64 type to DEVLINK_PARAM_TYPE (bsc#1254363)
  - commit 4d0e363

++++ python-tornado6:

  - Add security patches:
    * CVE-2025-67724.patch (bsc#1254903)
    * CVE-2025-67725.patch (bsc#1254905)
    * CVE-2025-67726.patch (bsc#1254904)

++++ shim:

  - Add DER format certificate files for the pretrans script to verify
    that the necessary certificate is in the UEFI db
  - openSUSE Secure Boot CA, 2013-2035
    openSUSE_Secure_Boot_CA_2013.crt
  - SUSE Linux Enterprise Secure Boot CA, 2013-2035
    SUSE_Linux_Enterprise_Secure_Boot_CA_2013.crt
  - Microsoft Corporation UEFI CA 2011, 2011-2026
    Microsoft_Corporation_UEFI_CA_2011.crt
  - Microsoft UEFI CA 2023, 2023-2038
    Microsoft_UEFI_CA_2023.crt
  - shim.spec: Add a pretrans script to verify that the necessary certificate
    is in the UEFI db.
  - Always put SUSE Linux Enterprise Secure Boot CA to target array.
    (bsc#1254679)

++++ suse-module-tools:

  - Update to version 16.0.64:
    * udev rules: write block queue attributes only if necessary
    (bsc#1254928)

------------------------------------------------------------------
------------------  2025-12-14  -  Dec 14 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
    (git-fixes).
  - args: fix documentation to reflect the correct numbers
    (git-fixes).
  - drm/mgag200: Fix big-endian support (git-fixes).
  - drm/tilcdc: Fix removal actions in case of failed probe
    (git-fixes).
  - drm/ttm: Avoid NULL pointer deref for evicted BOs (git-fixes).
  - drm: nouveau: Replace sprintf() with sysfs_emit() (git-fixes).
  - drm/nouveau: refactor deprecated strcpy (git-fixes).
  - drm/plane: Fix IS_ERR() vs NULL check in
    drm_plane_create_hotspot_properties() (git-fixes).
  - drm/i915: Fix format string truncation warning (git-fixes).
  - drm/amdkfd: Use huge page size to check split svm range
    alignment (git-fixes).
  - rtc: gamecube: Check the return value of ioremap() (git-fixes).
  - commit 26c9258

++++ kernel-rt:

  - irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
    (git-fixes).
  - args: fix documentation to reflect the correct numbers
    (git-fixes).
  - drm/mgag200: Fix big-endian support (git-fixes).
  - drm/tilcdc: Fix removal actions in case of failed probe
    (git-fixes).
  - drm/ttm: Avoid NULL pointer deref for evicted BOs (git-fixes).
  - drm: nouveau: Replace sprintf() with sysfs_emit() (git-fixes).
  - drm/nouveau: refactor deprecated strcpy (git-fixes).
  - drm/plane: Fix IS_ERR() vs NULL check in
    drm_plane_create_hotspot_properties() (git-fixes).
  - drm/i915: Fix format string truncation warning (git-fixes).
  - drm/amdkfd: Use huge page size to check split svm range
    alignment (git-fixes).
  - rtc: gamecube: Check the return value of ioremap() (git-fixes).
  - commit 26c9258

------------------------------------------------------------------
------------------  2025-12-13  -  Dec 13 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ASoC: codecs: wcd939x: fix OF node leaks on probe failure
    (git-fixes).
  - ASoC: codecs: wcd938x: fix OF node leaks on probe failure
    (git-fixes).
  - ASoC: ak5558: Disable regulator when error happens (git-fixes).
  - ASoC: ak4458: Disable regulator when error happens (git-fixes).
  - ASoC: bcm: bcm63xx-pcm-whistler: Check return value of
    of_dma_configure() (git-fixes).
  - ALSA: firewire-motu: add bounds check in put_user loop for
    DSP events (git-fixes).
  - ALSA: uapi: Fix typo in asound.h comment (git-fixes).
  - ALSA: firewire-motu: fix buffer overflow in hwdep read for
    DSP events (git-fixes).
  - ALSA: hda: cs35l41: Fix NULL pointer dereference in
    cs35l41_hda_read_acpi() (git-fixes).
  - staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE
    parsing (stable-fixes).
  - staging: rtl8723bs: fix stack buffer overflow in OnAssocReq
    IE parsing (stable-fixes).
  - staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie()
    parser (stable-fixes).
  - USB: serial: option: move Telit 0x10c7 composition in the
    right place (stable-fixes).
  - USB: serial: option: add Telit Cinterion FE910C04 new
    compositions (stable-fixes).
  - USB: serial: option: add Foxconn T99W760 (stable-fixes).
  - USB: serial: ftdi_sio: match on interface number for jtag
    (stable-fixes).
  - serial: add support of CPCI cards (stable-fixes).
  - wifi: rtw88: Add USB ID 2001:3329 for D-Link AC13U rev. A1
    (stable-fixes).
  - wifi: rtl8xxxu: Add USB ID 2001:3328 for D-Link AN3U rev. A1
    (stable-fixes).
  - pinctrl: qcom: msm: Fix deadlock in pinmux configuration
    (stable-fixes).
  - samples: work around glibc redefining some of our defines wrong
    (stable-fixes).
  - platform/x86: acer-wmi: Ignore backlight event (stable-fixes).
  - platform/x86/amd: pmc: Add Lenovo Legion Go 2 to pmc quirk list
    (stable-fixes).
  - platform/x86/amd/pmc: Add spurious_8042 to Xbox Ally
    (stable-fixes).
  - platform/x86: huawei-wmi: add keys for HONOR models
    (stable-fixes).
  - HID: elecom: Add support for ELECOM M-XT3URBK (018F)
    (stable-fixes).
  - HID: hid-input: Extend Elan ignore battery quirk to USB
    (stable-fixes).
  - HID: apple: Add SONiX AK870 PRO to non_apple_keyboards quirk
    list (stable-fixes).
  - drm/vmwgfx: Use kref in vmw_bo_dirty (stable-fixes).
  - drm/amdkfd: Fix GPU mappings for APU after prefetch
    (stable-fixes).
  - spi: xilinx: increase number of retries before declaring stall
    (stable-fixes).
  - spi: imx: keep dma request disabled before dma transfer setup
    (stable-fixes).
  - ALSA: usb-audio: Add native DSD quirks for PureAudio DAC series
    (stable-fixes).
  - Bluetooth: btrtl: Avoid loading the config file on security
    chips (stable-fixes).
  - commit 5d984a6

++++ kernel-rt:

  - ASoC: codecs: wcd939x: fix OF node leaks on probe failure
    (git-fixes).
  - ASoC: codecs: wcd938x: fix OF node leaks on probe failure
    (git-fixes).
  - ASoC: ak5558: Disable regulator when error happens (git-fixes).
  - ASoC: ak4458: Disable regulator when error happens (git-fixes).
  - ASoC: bcm: bcm63xx-pcm-whistler: Check return value of
    of_dma_configure() (git-fixes).
  - ALSA: firewire-motu: add bounds check in put_user loop for
    DSP events (git-fixes).
  - ALSA: uapi: Fix typo in asound.h comment (git-fixes).
  - ALSA: firewire-motu: fix buffer overflow in hwdep read for
    DSP events (git-fixes).
  - ALSA: hda: cs35l41: Fix NULL pointer dereference in
    cs35l41_hda_read_acpi() (git-fixes).
  - staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE
    parsing (stable-fixes).
  - staging: rtl8723bs: fix stack buffer overflow in OnAssocReq
    IE parsing (stable-fixes).
  - staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie()
    parser (stable-fixes).
  - USB: serial: option: move Telit 0x10c7 composition in the
    right place (stable-fixes).
  - USB: serial: option: add Telit Cinterion FE910C04 new
    compositions (stable-fixes).
  - USB: serial: option: add Foxconn T99W760 (stable-fixes).
  - USB: serial: ftdi_sio: match on interface number for jtag
    (stable-fixes).
  - serial: add support of CPCI cards (stable-fixes).
  - wifi: rtw88: Add USB ID 2001:3329 for D-Link AC13U rev. A1
    (stable-fixes).
  - wifi: rtl8xxxu: Add USB ID 2001:3328 for D-Link AN3U rev. A1
    (stable-fixes).
  - pinctrl: qcom: msm: Fix deadlock in pinmux configuration
    (stable-fixes).
  - samples: work around glibc redefining some of our defines wrong
    (stable-fixes).
  - platform/x86: acer-wmi: Ignore backlight event (stable-fixes).
  - platform/x86/amd: pmc: Add Lenovo Legion Go 2 to pmc quirk list
    (stable-fixes).
  - platform/x86/amd/pmc: Add spurious_8042 to Xbox Ally
    (stable-fixes).
  - platform/x86: huawei-wmi: add keys for HONOR models
    (stable-fixes).
  - HID: elecom: Add support for ELECOM M-XT3URBK (018F)
    (stable-fixes).
  - HID: hid-input: Extend Elan ignore battery quirk to USB
    (stable-fixes).
  - HID: apple: Add SONiX AK870 PRO to non_apple_keyboards quirk
    list (stable-fixes).
  - drm/vmwgfx: Use kref in vmw_bo_dirty (stable-fixes).
  - drm/amdkfd: Fix GPU mappings for APU after prefetch
    (stable-fixes).
  - spi: xilinx: increase number of retries before declaring stall
    (stable-fixes).
  - spi: imx: keep dma request disabled before dma transfer setup
    (stable-fixes).
  - ALSA: usb-audio: Add native DSD quirks for PureAudio DAC series
    (stable-fixes).
  - Bluetooth: btrtl: Avoid loading the config file on security
    chips (stable-fixes).
  - commit 5d984a6

++++ qemu:

  - Update to version 10.0.7
    Full backport list:
    https://lore.kernel.org/qemu-devel/1765037524.347582.2700543.nullmailer@tls.msk.ru/
    Fixes:
    bsc#1253002 (CVE-2025-12464)
    bsc#1250984 (CVE-2025-11234)
    A selection of them is reported here below:
    kvm: Fix kvm_vm_ioctl() and kvm_device_ioctl() return value
    docs/devel: Update URL for make-pullreq script
    target/arm: Fix assert on BRA.
    hw/aspeed/{xdma, rtc, sdhci}: Fix endianness to DEVICE_LITTLE_ENDIAN
    hw/core/machine: Provide a description for aux-ram-share property
    hw/pci: Make msix_init take a uint32_t for nentries
    block/io_uring: avoid potentially getting stuck after resubmit at the end of ioq_submit()
    block-backend: Fix race when resuming queued requests
    ui/vnc: Fix qemu abort when query vnc info
    chardev/char-pty: Do not ignore chr_write() failures
    hw/display/exynos4210_fimd: Account for zero length in fimd_update_memory_section()
    hw/arm/armv7m: Disable reentrancy guard for v7m_sysreg_ns_ops MRs
    hw/arm/aspeed: Fix missing SPI IRQ connection causing DMA interrupt failure
    migration: Fix transition to COLO state from precopy
  - Other updates and bugfixes:
    * [openSUSE][RPM} spec: delete old specfile constructs
    * [openSUSE][RPM]: really fix *-virtio-gpu-pci dependency on ARM (bsc#1254286)
    * [openSUSE][RPM] spec: make glusterfs support conditional (bsc#1254494)

------------------------------------------------------------------
------------------  2025-12-12  -  Dec 12 2025  -------------------
------------------------------------------------------------------

++++ openldap2_6:

  - jsc#PED-13833 - Add limited support for libldap-2.4 library compatibility

++++ selinux-policy:

  - Update to version 20250627+git341.4beeb2d65:
    * Allow virtlogd_t dac_override (bsc#1253389)
    * Introduce systemd_cryptsetup_generator_var_run_t file type (bsc#1244459)
    * Allow virtqemud_t to read/write device_t (bsc#1251789)
    * update support for polkit agent helper (bsc#1251931)
    * Allow system_mail_t read apache system content conditionally
    * Allow login_userdomain read lastlog
    * Allow sshd-net read and write to sshd vsock socket
    * Update ktls policy
    * Add comprehensive SELinux policy module for bwrap thumbnail generation
    * Revert "Allow thumb_t create permission in the user namespace"
    * Allow systemd-machined read svirt process state
    * Allow sshd_auth_t getopt/setopt on tcp_socket (bsc#1252992)
    * Allow sysadm access to TPM
    * Allow tlp get the attributes of the pidfs filesystem
    * Allow kmscon to read netlink_kobject_uevent_socket
    * Allow systemd-ssh-issue read kernel sysctls
    * fix: bz2279215 Allow speech-dispatcher access to user home/cache files
    * Allow create kerberos files in postgresql db home
    * Fix files_delete_boot_symlinks() to contain delete_lnk_files_pattern
    * Allow shell comamnds in locate systemd service (bsc#1246559)
    * Introduce initrc_nnp_daemon_domain interface
    * Label /var/lib/cosmic-greeter with xdm_var_lib_t
    * Allow setroubleshoot-fixit get attributes of xattr fs
    * Allow insights-client manage /etc symlinks
    * Allow insights-client get attributes of the rpm executable
    * Allow nfsidmapd search virt lib directories
    * Allow iotop stream connect to systemd-userdbd
    * Allow snapper_sdbootutil_plugin_t manage unlabeled_t files,dirs,symlinks (bsc#1252993)
    * Allow gnome-remote-desktop read sssd public files
    * Allow thumb_t stream connect to systemd-userdbd
    * Add auth_nnp_domtrans_chkpwd()
    * Allow sshd_auth_t getopt/setopt on tcp_socket (bsc#1252992)
    * Allow bluez dbus API passing unix domain sockets
    * Allow bluez dbus api pass sockets over dbus
    * Dontaudit systemd-generator connect to sssd over a unix stream socket
    * Allow init watch/watch_reads systemd-machined user ptys
    * Introduce sap_service_transition_to_unconfined_user boolean
    * allow init to read sap symlinks
    * Allow SAP domain to relocation text in all files
  - Switch internal tracking branch to slfo-1.2, we will start
    backporting from now on

++++ shim:

  - Update to 16.1
  - RPMs
    shim-16.1-150300.4.31.1.x86_64.rpm
    shim-debuginfo-16.1-150300.4.31.1.x86_64.rpm
    shim-debugsource-16.1-150300.4.31.1.x86_64.rpm
    shim-16.1-150300.4.31.1.aarch64.rpm
    shim-debuginfo-16.1-150300.4.31.1.aarch64.rpm
    shim-debugsource-16.1-150300.4.31.1.aarch64.rpm
  - submitreq: https://build.suse.de/request/show/395247
  - repo: https://build.suse.de/package/show/SUSE:Maintenance:39913/shim.SUSE_SLE-15-SP3_Update
  - Patches (git log --oneline --reverse 16.0..16.1)
    4040ec4 shim_start_image(): fix guid/handle pairing when uninstalling protocols
    39c0aa1 str2ip6(): parsing of "uncompressed" ipv6 addresses
    3133d19 test-mock-variables: make our filter list entries safer.
    d44405e mock-variables: remove unused variable
    0e8459f Update CI to use ubuntu-24.04 instead of ubuntu-20.04
    d16a5a6 SbatLevel_Variable.txt: minor typo fix.
    32804cf Realloc() needs one more byte for sprintf()
    431d370 IPv6: Add more check to avoid multiple double colon and illegal char
    5e4d93c Loader Proto: make freeing of bprop.buffer conditional.
    33deac2 Prepare to move things from shim.c to verify.c
    030e7df Move a bunch of stuff from shim.c to verify.c
    f3ddda7 handle_image(): make verification conditional
    774f226 Cache sections of a loaded image and sub-images from them.
    eb0d20b loader-protocol: handle sub-section loading for UKIs
    2f64bb9 loader-protocol: add workaround for EDK2 2025.02 page fault on FreePages
    1abc7ca loader-protocol: NULL output variable in load_image on failure
    fb77b44 Generate Authenticode for the entire PE file
    b86b909 README: mention new loader protocol and interaction with UKIs
    8522612 ci: add mkosi configuration and CI
    9ebab84 mkosi workflow: fix the branch name for main.
    72a4c41 shim: change automatically enable MOK_POLICY_REQUIRE_NX
    a2f0dfa This is an organizational patch to move some things around in mok.c
    54b9946 Update to the shim-16.1 branch of gnu-efi to get AsciiSPrint()
    a5a6922 get_max_var_sz(): add more debugging for apple platforms
    77a2922 Add a "VariableInfo" variable to mok-variables.
    efc71c9 build: Avoid passing *FLAGS to sub-make
    7670932 Fixes for 'make TOPDIR=... clean'
    13ab598 add SbatLevel entry 2025051000 for PSA-2025-00012-1
    617aed5 Update version to 16.1~rc1
    d316ba8 format_variable_info(): fix wrong size test.
    f5fad0e _do_sha256_sum(): Fix missing error check.
    3a9734d doc: add howto for running mkosi locally
    ced5f71 mkosi: remove spurious slashes from script
    0076155 ci: update mkosi commit
    5481105 fix http boot
    121cddf loader-protocol: Handle UnloadImage after StartImage properly
    6a1d1a9 loader-protocol: Fix memory leaks
    27a5d22 gitignore: add more mkosi dirs and vscode dir
    346ed15 mkosi: disable repository key check on Fedora
    afc4955 Update version to 16.1
  - 16.1 release note https://github.com/rhboot/shim/releases
    shim_start_image(): fix guid/handle pairing when uninstalling protocols by @vathpela in #738
    Fix uncompressed ipv6 netboot by @hrvach in #742
    fix test segfaults caused by uninitialized memory by @Fabian-Gruenbichler in #739
    Update CI to use ubuntu-24.04 instead of ubuntu-20.04 by @vathpela in #749
    SbatLevel_Variable.txt: minor typo fix. by @vathpela in #751
    Realloc() needs to allocate one more byte for sprintf() by @dennis-tseng99 in #746
    IPv6: Add more check to avoid multiple double colon and illegal char by @dennis-tseng99 in #753
    Loader proto v2 by @vathpela in #748
    loader-protocol: add workaround for EDK2 2025.02 page fault on FreePages by @bluca in #750
    Generate Authenticode for the entire PE file by @esnowberg in #604
    README: mention new loader protocol and interaction with UKIs by @bluca in #755
    ci: add mkosi configuration and CI by @bluca in #764
    shim: change automatically enable MOK_POLICY_REQUIRE_NX by @vathpela in #761
    Save var info by @vathpela in #763
    build: Avoid passing *FLAGS to sub-make by @rosslagerwall in #758
    Fixes for 'make TOPDIR=... clean' by @bluca in #762
    add SbatLevel entry 2025051000 for PSA-2025-00012-1 by @Fabian-Gruenbichler in #766
    Coverity fixes 20250804 by @vathpela in #767
    ci: fixlets and docs for mkosi workflow by @bluca in #768
    fix http boot by @jsetje in #770
    Fix double free and leak in the loader protocol by @rosslagerwall in #769
    gitignore: add more mkosi dirs and vscode dir by @bluca in #771
  - Drop upstreamed patch:
    The following patches are merged to 16.1
  - shim-alloc-one-more-byte-for-sprintf.patch
  - 32804cf5d9 Realloc() needs one more byte for sprintf()    [16.1]
  - shim-change-automatically-enable-MOK_POLICY_REQUIRE_NX.patch (bsc#1205588)
  - 72a4c41877 shim: change automatically enable MOK_POLICY_REQUIRE_NX [16.1]
  - Building MokManager.efi and fallback.efi with POST_PROCESS_PE_FLAGS=-n (bsc#1205588)
  - Building with the latest version of gcc in the codebase:
  - The gcc13 can workaround dxe_get_mem_attrs() hsi_status problem
  - We prefer that building shim with the latest version of gcc in codebase.
  - Set the minimum version is gcc-13.
    (bsc#1247432)
  - SLE shim should includes vendor-dbx-sles.esl instead of
    vendor-dbx-opensuse.esl. Fixed it in shim.spec.

++++ supportutils:

  - Changes to version 3.2.12
    + Optimized lsof usage and honors OPTION_OFILES (bsc#1232351, PR#274)
    + Run in containers without errors (bsc#1245667, PR#272)
    + Removed pmap PID from memory.txt (bsc#1246011, PR#263)
    + Added missing /proc/pagetypeinfo to memory.txt (bsc#1246025, PR#264)
    + Improved database perforce with kGraft patching (bsc#1249657, PR#273)
    + Using last boot for journalctl for optimization (bsc#1250224, PR#287)
    + Fixed extraction failures (bsc#1252318, PR#275)
    + Update supportconfig.conf path in docs (bsc#1254425, PR#281)
    + drm_sub_info: Catch error when dir doesn't exist (PR#265)
    + Replace remaining `egrep` with `grep -E` (PR#261, PR#266)
    + Add process affinity to slert logs (PR#269)
    + Reintroduce cgroup statistics (and v2) (PR#270)
    + Minor changes to basic-health-check: improve information level (PR#271)
    + Collect important machine health counters (PR#276)
    + powerpc: collect hot-pluggable PCI and PHB slots (PR#278)
    + podman: collect podman disk usage (PR#279)
    + Exclude binary files in crondir (PR#282)
    + kexec/kdump: collect everything under /sys/kernel/kexec dir (PR#284)
    + Use short-iso for journalctl (PR#288)

------------------------------------------------------------------
------------------  2025-12-11  -  Dec 11 2025  -------------------
------------------------------------------------------------------

++++ glib2:

  - Add CVE fixes:
    + glib2-CVE-2025-13601-1.patch, glib2-CVE-2025-13601-2.patch
    (bsc#1254297 CVE-2025-13601 glgo#GNOME/glib#3827).
    + glib2-CVE-2025-14087-1.patch, glib2-CVE-2025-14087-2.patch,
    glib2-CVE-2025-14087-3.patch (bsc#1254662 CVE-2025-14087
    glgo#GNOME/glib#3834).
    + glib2-CVE-2025-14512.patch (bsc#1254878 CVE-2025-14512
    glgo#GNOME/glib#3845).

++++ kernel-default:

  - ext4: detect invalid INLINE_DATA + EXTENTS flag combination
    (bsc#1253458 CVE-2025-40167).
  - commit 605db4d
  - ext4: align max orphan file size with e2fsprogs limit
    (bsc#1253442 CVE-2025-40179).
  - commit 26fd0f5
  - ext4: free orphan info with kvfree (bsc#1253442 CVE-2025-40179).
  - commit 610e2f7
  - ext4: verify orphan file size is not too big (bsc#1253442
    CVE-2025-40179).
  - commit ab947ea
  - config.conf: add kernel-azure as additonal flavor
    The content is based on commit 55ebf5f2a4b and de2b7669cdd.
    This makes kernel-source-azure and kernel-syms-azure obsolete.
  - commit 8ce1bdd
  - kABI workaround for HCI_LE_ADV_0 addition (git-fixes).
  - commit 10199fc
  - regulator: fixed: Rely on the core freeing the enable GPIO
    (git-fixes).
  - commit 5011006

++++ kernel-rt:

  - ext4: detect invalid INLINE_DATA + EXTENTS flag combination
    (bsc#1253458 CVE-2025-40167).
  - commit 605db4d
  - ext4: align max orphan file size with e2fsprogs limit
    (bsc#1253442 CVE-2025-40179).
  - commit 26fd0f5
  - ext4: free orphan info with kvfree (bsc#1253442 CVE-2025-40179).
  - commit 610e2f7
  - ext4: verify orphan file size is not too big (bsc#1253442
    CVE-2025-40179).
  - commit ab947ea
  - config.conf: add kernel-azure as additonal flavor
    The content is based on commit 55ebf5f2a4b and de2b7669cdd.
    This makes kernel-source-azure and kernel-syms-azure obsolete.
  - commit 8ce1bdd
  - kABI workaround for HCI_LE_ADV_0 addition (git-fixes).
  - commit 10199fc
  - regulator: fixed: Rely on the core freeing the enable GPIO
    (git-fixes).
  - commit 5011006

++++ python313-core:

  - Update to 3.13.11:
  - gh-142145: Remove quadratic behavior in xml.minidom node ID
    cache clearing (CVE-2025-12084, bsc#1254997).
  - gh-119451: Fix a potential memory denial of service in the
    http.client module. When connecting to a malicious server,
    it could cause an arbitrary amount of memory to be
    allocated. This could have led to symptoms including
    a MemoryError, swapping, out of memory (OOM) killed
    processes or containers, or even system crashes
    (bsc#1254400, CVE-2025-13836).
  - gh-119452: Fix a potential memory denial of service in the
    http.server module. When a malicious user is connected to
    the CGI server on Windows, it could cause an arbitrary
    amount of memory to be allocated. This could have led to
    symptoms including a MemoryError, swapping, out of memory
    (OOM) killed processes or containers, or even system
    crashes.
  - Library
  - gh-140797: Revert changes to the undocumented re.Scanner
    class. Capturing groups are still allowed for backward
    compatibility, although using them can lead to incorrect
    result. They will be forbidden in future Python versions.
  - gh-142206: The resource tracker in the multiprocessing
    module now uses the original communication protocol, as in
    Python 3.14.0 and below, by default. This avoids issues
    with upgrading Python while it is running. (Note that such
    ‘in-place’ upgrades are not tested.) The tracker remains
    compatible with subprocesses that use new protocol (that
    is, subprocesses using Python 3.13.10, 3.14.1 and 3.15).
  - Core and Builtins
  - gh-142218: Fix crash when inserting into a split table
    dictionary with a non str key that matches an existing key.
  - Update to 3.13.10:
  - Tools/Demos
  - gh-141442: The iOS testbed now correctly handles test
    arguments that contain spaces.
  - Tests
  - gh-140482: Preserve and restore the state of stty echo as
    part of the test environment.
  - gh-140082: Update python -m test to set FORCE_COLOR=1 when
    being run with color enabled so that unittest which is run
    by it with redirected output will output in color.
  - gh-136442: Use exitcode 1 instead of 5 if
    unittest.TestCase.setUpClass() raises an exception
  - Security
  - gh-139700: Check consistency of the zip64 end of central
    directory record. Support records with “zip64 extensible
    data” if there are no bytes prepended to the ZIP file.
    (CVE-2025-8291, bsc#1251305)
  - gh-137836: Add support of the “plaintext” element, RAWTEXT
    elements “xmp”, “iframe”, “noembed” and “noframes”, and
    optionally RAWTEXT element “noscript” in
    html.parser.HTMLParser.
  - gh-136063: email.message: ensure linear complexity for
    legacy HTTP parameters parsing. Patch by Bénédikt Tran.
  - gh-136065: Fix quadratic complexity in
    os.path.expandvars() (CVE-2025-6075, bsc#1252974).
  - gh-119342: Fix a potential memory denial of service in the
    plistlib module. When reading a Plist file received from
    untrusted source, it could cause an arbitrary amount of
    memory to be allocated. This could have led to symptoms
    including a MemoryError, swapping, out of memory (OOM)
    killed processes or containers, or even system crashes
    (CVE-2025-13837, bsc#1254401).
  - Library
  - gh-74389: When the stdin being used by a subprocess.Popen
    instance is closed, this is now ignored in
    subprocess.Popen.communicate() instead of leaving the class
    in an inconsistent state.
  - gh-87512: Fix subprocess.Popen.communicate() timeout
    handling on Windows when writing large input. Previously,
    the timeout was ignored during stdin writing, causing the
    method to block indefinitely if the child process did not
    consume input quickly. The stdin write is now performed in
    a background thread, allowing the timeout to be properly
    enforced.
  - gh-141473: When subprocess.Popen.communicate() was called
    with input and a timeout and is called for a second time
    after a TimeoutExpired exception before the process has
    died, it should no longer hang.
  - gh-59000: Fix pdb breakpoint resolution for class methods
    when the module defining the class is not imported.
  - gh-141570: Support file-like object raising OSError from
    fileno() in color detection (_colorize.can_colorize()).
    This can occur when sys.stdout is redirected.
  - gh-141659: Fix bad file descriptor errors from
    _posixsubprocess on AIX.
  - gh-141497: ipaddress: ensure that the methods
    IPv4Network.hosts() and IPv6Network.hosts() always return
    an iterator.
  - gh-140938: The statistics.stdev() and statistics.pstdev()
    functions now raise a ValueError when the input contains an
    infinity or a NaN.
  - gh-124111: Updated Tcl threading configuration in _tkinter
    to assume that threads are always available in Tcl 9 and
    later.
  - gh-137109: The os.fork and related forking APIs will no
    longer warn in the common case where Linux or macOS
    platform APIs return the number of threads in a process and
    find the answer to be 1 even when a os.register_at_fork()
    after_in_parent= callback (re)starts a thread.
  - gh-141314: Fix assertion failure in io.TextIOWrapper.tell()
    when reading files with standalone carriage return (\r)
    line endings.
  - gh-141311: Fix assertion failure in io.BytesIO.readinto()
    and undefined behavior arising when read position is above
    capcity in io.BytesIO.
  - gh-141141: Fix a thread safety issue with
    base64.b85decode(). Contributed by Benel Tayar.
  - gh-140911: collections: Ensure that the methods
    UserString.rindex() and UserString.index() accept
    collections.UserString instances as the sub argument.
  - gh-140797: The undocumented re.Scanner class now forbids
    regular expressions containing capturing groups in its
    lexicon patterns. Patterns using capturing groups could
    previously lead to crashes with segmentation fault. Use
    non-capturing groups (?:…) instead.
  - gh-140815: faulthandler now detects if a frame or a code
    object is invalid or freed. Patch by Victor Stinner.
  - gh-100218: Correctly set errno when socket.if_nametoindex()
    or socket.if_indextoname() raise an OSError. Patch by
    Bénédikt Tran.
  - gh-140875: Fix handling of unclosed character references
    (named and numerical) followed by the end of file in
    html.parser.HTMLParser with convert_charrefs=False.
  - gh-140734: multiprocessing: fix off-by-one error when
    checking the length of a temporary socket file path. Patch
    by Bénédikt Tran.
  - gh-140874: Bump the version of pip bundled in ensurepip to
    version 25.3
  - gh-140691: In urllib.request, when opening a FTP URL fails
    because a data connection cannot be made, the control
    connection’s socket is now closed to avoid
    a ResourceWarning.
  - gh-103847: Fix hang when cancelling process created by
    asyncio.create_subprocess_exec() or
    asyncio.create_subprocess_shell(). Patch by Kumar Aditya.
  - gh-140590: Fix arguments checking for the
    functools.partial.__setstate__() that may lead to internal
    state corruption and crash. Patch by Sergey Miryanov.
  - gh-140634: Fix a reference counting bug in
    os.sched_param.__reduce__().
  - gh-140633: Ignore AttributeError when setting a module’s
    __file__ attribute when loading an extension module
    packaged as Apple Framework.
  - gh-140593: xml.parsers.expat: Fix a memory leak that could
    affect users with ElementDeclHandler() set to a custom
    element declaration handler. Patch by Sebastian Pipping.
  - gh-140607: Inside io.RawIOBase.read(), validate that the
    count of bytes returned by io.RawIOBase.readinto() is valid
    (inside the provided buffer).
  - gh-138162: Fix logging.LoggerAdapter with merge_extra=True
    and without the extra argument.
  - gh-140474: Fix memory leak in array.array when creating
    arrays from an empty str and the u type code.
  - gh-140272: Fix memory leak in the clear() method of the
    dbm.gnu database.
  - gh-140041: Fix import of ctypes on Android and Cygwin when
    ABI flags are present.
  - gh-139905: Add suggestion to error message for
    typing.Generic subclasses when cls.__parameters__ is
    missing due to a parent class failing to call
    super().__init_subclass__() in its __init_subclass__.
  - gh-139845: Fix to not print KeyboardInterrupt twice in
    default asyncio REPL.
  - gh-139783: Fix inspect.getsourcelines() for the case when
    a decorator is followed by a comment or an empty line.
  - gh-70765: http.server: fix default handling of HTTP/0.9
    requests in BaseHTTPRequestHandler. Previously,
    BaseHTTPRequestHandler.parse_request() incorrectly waited
    for headers in the request although those are not supported
    in HTTP/0.9. Patch by Bénédikt Tran.
  - gh-139391: Fix an issue when, on non-Windows platforms, it
    was not possible to gracefully exit a python -m asyncio
    process suspended by Ctrl+Z and later resumed by fg other
    than with kill.
  - gh-101828: Fix 'shift_jisx0213', 'shift_jis_2004',
    'euc_jisx0213' and 'euc_jis_2004' codecs truncating null
    chars as they were treated as part of multi-character
    sequences.
  - gh-139246: fix: paste zero-width in default repl width is
    wrong.
  - gh-90949: Add SetAllocTrackerActivationThreshold() and
    SetAllocTrackerMaximumAmplification() to xmlparser objects
    to prevent use of disproportional amounts of dynamic memory
    from within an Expat parser. Patch by Bénédikt Tran.
  - gh-139065: Fix trailing space before a wrapped long word if
    the line length is exactly width in textwrap.
  - gh-138993: Dedent credits text.
  - gh-138859: Fix generic type parameterization raising
    a TypeError when omitting a ParamSpec that has a default
    which is not a list of types.
  - gh-138775: Use of python -m with base64 has been fixed to
    detect input from a terminal so that it properly notices
    EOF.
  - gh-98896: Fix a failure in multiprocessing resource_tracker
    when SharedMemory names contain colons. Patch by Rani
    Pinchuk.
  - gh-75989: tarfile.TarFile.extractall() and
    tarfile.TarFile.extract() now overwrite symlinks when
    extracting hardlinks. (Contributed by Alexander Enrique
    Urieles Nieto in gh-75989.)
  - gh-83424: Allows creating a ctypes.CDLL without name when
    passing a handle as an argument.
  - gh-136234: Fix asyncio.WriteTransport.writelines() to be
    robust to connection failure, by using the same behavior as
    write().
  - gh-136057: Fixed the bug in pdb and bdb where next and step
    can’t go over the line if a loop exists in the line.
  - gh-135307: email: Fix exception in set_content() when
    encoding text and max_line_length is set to 0 or None
    (unlimited).
  - gh-134453: Fixed subprocess.Popen.communicate() input=
    handling of memoryview instances that were non-byte shaped
    on POSIX platforms. Those are now properly cast to a byte
    shaped view instead of truncating the input. Windows
    platforms did not have this bug.
  - gh-102431: Clarify constraints for “logical” arguments in
    methods of decimal.Context.
  - IDLE
  - gh-96491: Deduplicate version number in IDLE shell title
    bar after saving to a file.
  - Documentation
  - gh-141994: xml.sax.handler: Make Documentation of
    xml.sax.handler.feature_external_ges warn of opening up to
    external entity attacks. Patch by Sebastian Pipping.
  - gh-140578: Remove outdated sencence in the documentation
    for multiprocessing, that implied that
    concurrent.futures.ThreadPoolExecutor did not exist.
  - Core and Builtins
  - gh-142048: Fix quadratically increasing garbage collection
    delays in free-threaded build.
  - gh-141930: When importing a module, use Python’s regular
    file object to ensure that writes to .pyc files are
    complete or an appropriate error is raised.
  - gh-120158: Fix inconsistent state when enabling or
    disabling monitoring events too many times.
  - gh-141579: Fix sys.activate_stack_trampoline() to properly
    support the perf_jit backend. Patch by Pablo Galindo.
  - gh-141312: Fix the assertion failure in the __setstate__
    method of the range iterator when a non-integer argument is
    passed. Patch by Sergey Miryanov.
  - gh-140939: Fix memory leak when bytearray or bytes is
    formated with the
    %*b format with a large width that results in
    %a MemoryError.
  - gh-140530: Fix a reference leak when raise exc from cause
    fails. Patch by Bénédikt Tran.
  - gh-140576: Fixed crash in tokenize.generate_tokens() in
    case of specific incorrect input. Patch by Mikhail Efimov.
  - gh-140551: Fixed crash in dict if dict.clear() is called at
    the lookup stage. Patch by Mikhail Efimov and Inada Naoki.
  - gh-140471: Fix potential buffer overflow in ast.AST node
    initialization when encountering malformed _fields
    containing non-str.
  - gh-140406: Fix memory leak when an object’s __hash__()
    method returns an object that isn’t an int.
  - gh-140306: Fix memory leaks in cross-interpreter channel
    operations and shared namespace handling.
  - gh-140301: Fix memory leak of PyConfig in subinterpreters.
  - gh-140000: Fix potential memory leak when a reference cycle
    exists between an instance of typing.TypeAliasType,
    typing.TypeVar, typing.ParamSpec, or typing.TypeVarTuple
    and its __name__ attribute. Patch by Mikhail Efimov.
  - gh-139748: Fix reference leaks in error branches of
    functions accepting path strings or bytes such as compile()
    and os.system(). Patch by Bénédikt Tran.
  - gh-139516: Fix lambda colon erroneously start format spec
    in f-string in tokenizer.
  - gh-139640: Fix swallowing some syntax warnings in different
    modules if they accidentally have the same message and are
    emitted from the same line. Fix duplicated warnings in the
    finally block.
  - gh-137400: Fix a crash in the free threading build when
    disabling profiling or tracing across all threads with
    PyEval_SetProfileAllThreads() or
    PyEval_SetTraceAllThreads() or their Python equivalents
    threading.settrace_all_threads() and
    threading.setprofile_all_threads().
  - gh-133400: Fixed Ctrl+D (^D) behavior in _pyrepl module to
    match old pre-3.13 REPL behavior.
  - C API
  - gh-140042: Removed the sqlite3_shutdown call that could
    cause closing connections for sqlite when used with
    multiple sub interpreters.
  - gh-140487: Fix Py_RETURN_NOTIMPLEMENTED in limited C API
    3.11 and older: don’t treat Py_NotImplemented as immortal.
    Patch by Victor Stinner.
  - Remove upstreamed patches:
  - CVE-2025-13836-http-resp-cont-len.patch
  - CVE-2025-8291-consistency-zip64.patch
  - CVE-2025-6075-expandvars-perf-degrad.patch

++++ nvidia-open-driver-G06-signed:

  - readded kernel-6.18.patch still needed for cuda driver version
    580.105.08
  - update non-CUDA variant to version 580.119.02 (boo#1254801)

++++ python313:

  - Update to 3.13.11:
  - gh-142145: Remove quadratic behavior in xml.minidom node ID
    cache clearing (CVE-2025-12084, bsc#1254997).
  - gh-119451: Fix a potential memory denial of service in the
    http.client module. When connecting to a malicious server,
    it could cause an arbitrary amount of memory to be
    allocated. This could have led to symptoms including
    a MemoryError, swapping, out of memory (OOM) killed
    processes or containers, or even system crashes
    (bsc#1254400, CVE-2025-13836).
  - gh-119452: Fix a potential memory denial of service in the
    http.server module. When a malicious user is connected to
    the CGI server on Windows, it could cause an arbitrary
    amount of memory to be allocated. This could have led to
    symptoms including a MemoryError, swapping, out of memory
    (OOM) killed processes or containers, or even system
    crashes.
  - Library
  - gh-140797: Revert changes to the undocumented re.Scanner
    class. Capturing groups are still allowed for backward
    compatibility, although using them can lead to incorrect
    result. They will be forbidden in future Python versions.
  - gh-142206: The resource tracker in the multiprocessing
    module now uses the original communication protocol, as in
    Python 3.14.0 and below, by default. This avoids issues
    with upgrading Python while it is running. (Note that such
    ‘in-place’ upgrades are not tested.) The tracker remains
    compatible with subprocesses that use new protocol (that
    is, subprocesses using Python 3.13.10, 3.14.1 and 3.15).
  - Core and Builtins
  - gh-142218: Fix crash when inserting into a split table
    dictionary with a non str key that matches an existing key.
  - Update to 3.13.10:
  - Tools/Demos
  - gh-141442: The iOS testbed now correctly handles test
    arguments that contain spaces.
  - Tests
  - gh-140482: Preserve and restore the state of stty echo as
    part of the test environment.
  - gh-140082: Update python -m test to set FORCE_COLOR=1 when
    being run with color enabled so that unittest which is run
    by it with redirected output will output in color.
  - gh-136442: Use exitcode 1 instead of 5 if
    unittest.TestCase.setUpClass() raises an exception
  - Security
  - gh-139700: Check consistency of the zip64 end of central
    directory record. Support records with “zip64 extensible
    data” if there are no bytes prepended to the ZIP file.
    (CVE-2025-8291, bsc#1251305)
  - gh-137836: Add support of the “plaintext” element, RAWTEXT
    elements “xmp”, “iframe”, “noembed” and “noframes”, and
    optionally RAWTEXT element “noscript” in
    html.parser.HTMLParser.
  - gh-136063: email.message: ensure linear complexity for
    legacy HTTP parameters parsing. Patch by Bénédikt Tran.
  - gh-136065: Fix quadratic complexity in
    os.path.expandvars() (CVE-2025-6075, bsc#1252974).
  - gh-119342: Fix a potential memory denial of service in the
    plistlib module. When reading a Plist file received from
    untrusted source, it could cause an arbitrary amount of
    memory to be allocated. This could have led to symptoms
    including a MemoryError, swapping, out of memory (OOM)
    killed processes or containers, or even system crashes
    (CVE-2025-13837, bsc#1254401).
  - Library
  - gh-74389: When the stdin being used by a subprocess.Popen
    instance is closed, this is now ignored in
    subprocess.Popen.communicate() instead of leaving the class
    in an inconsistent state.
  - gh-87512: Fix subprocess.Popen.communicate() timeout
    handling on Windows when writing large input. Previously,
    the timeout was ignored during stdin writing, causing the
    method to block indefinitely if the child process did not
    consume input quickly. The stdin write is now performed in
    a background thread, allowing the timeout to be properly
    enforced.
  - gh-141473: When subprocess.Popen.communicate() was called
    with input and a timeout and is called for a second time
    after a TimeoutExpired exception before the process has
    died, it should no longer hang.
  - gh-59000: Fix pdb breakpoint resolution for class methods
    when the module defining the class is not imported.
  - gh-141570: Support file-like object raising OSError from
    fileno() in color detection (_colorize.can_colorize()).
    This can occur when sys.stdout is redirected.
  - gh-141659: Fix bad file descriptor errors from
    _posixsubprocess on AIX.
  - gh-141497: ipaddress: ensure that the methods
    IPv4Network.hosts() and IPv6Network.hosts() always return
    an iterator.
  - gh-140938: The statistics.stdev() and statistics.pstdev()
    functions now raise a ValueError when the input contains an
    infinity or a NaN.
  - gh-124111: Updated Tcl threading configuration in _tkinter
    to assume that threads are always available in Tcl 9 and
    later.
  - gh-137109: The os.fork and related forking APIs will no
    longer warn in the common case where Linux or macOS
    platform APIs return the number of threads in a process and
    find the answer to be 1 even when a os.register_at_fork()
    after_in_parent= callback (re)starts a thread.
  - gh-141314: Fix assertion failure in io.TextIOWrapper.tell()
    when reading files with standalone carriage return (\r)
    line endings.
  - gh-141311: Fix assertion failure in io.BytesIO.readinto()
    and undefined behavior arising when read position is above
    capcity in io.BytesIO.
  - gh-141141: Fix a thread safety issue with
    base64.b85decode(). Contributed by Benel Tayar.
  - gh-140911: collections: Ensure that the methods
    UserString.rindex() and UserString.index() accept
    collections.UserString instances as the sub argument.
  - gh-140797: The undocumented re.Scanner class now forbids
    regular expressions containing capturing groups in its
    lexicon patterns. Patterns using capturing groups could
    previously lead to crashes with segmentation fault. Use
    non-capturing groups (?:…) instead.
  - gh-140815: faulthandler now detects if a frame or a code
    object is invalid or freed. Patch by Victor Stinner.
  - gh-100218: Correctly set errno when socket.if_nametoindex()
    or socket.if_indextoname() raise an OSError. Patch by
    Bénédikt Tran.
  - gh-140875: Fix handling of unclosed character references
    (named and numerical) followed by the end of file in
    html.parser.HTMLParser with convert_charrefs=False.
  - gh-140734: multiprocessing: fix off-by-one error when
    checking the length of a temporary socket file path. Patch
    by Bénédikt Tran.
  - gh-140874: Bump the version of pip bundled in ensurepip to
    version 25.3
  - gh-140691: In urllib.request, when opening a FTP URL fails
    because a data connection cannot be made, the control
    connection’s socket is now closed to avoid
    a ResourceWarning.
  - gh-103847: Fix hang when cancelling process created by
    asyncio.create_subprocess_exec() or
    asyncio.create_subprocess_shell(). Patch by Kumar Aditya.
  - gh-140590: Fix arguments checking for the
    functools.partial.__setstate__() that may lead to internal
    state corruption and crash. Patch by Sergey Miryanov.
  - gh-140634: Fix a reference counting bug in
    os.sched_param.__reduce__().
  - gh-140633: Ignore AttributeError when setting a module’s
    __file__ attribute when loading an extension module
    packaged as Apple Framework.
  - gh-140593: xml.parsers.expat: Fix a memory leak that could
    affect users with ElementDeclHandler() set to a custom
    element declaration handler. Patch by Sebastian Pipping.
  - gh-140607: Inside io.RawIOBase.read(), validate that the
    count of bytes returned by io.RawIOBase.readinto() is valid
    (inside the provided buffer).
  - gh-138162: Fix logging.LoggerAdapter with merge_extra=True
    and without the extra argument.
  - gh-140474: Fix memory leak in array.array when creating
    arrays from an empty str and the u type code.
  - gh-140272: Fix memory leak in the clear() method of the
    dbm.gnu database.
  - gh-140041: Fix import of ctypes on Android and Cygwin when
    ABI flags are present.
  - gh-139905: Add suggestion to error message for
    typing.Generic subclasses when cls.__parameters__ is
    missing due to a parent class failing to call
    super().__init_subclass__() in its __init_subclass__.
  - gh-139845: Fix to not print KeyboardInterrupt twice in
    default asyncio REPL.
  - gh-139783: Fix inspect.getsourcelines() for the case when
    a decorator is followed by a comment or an empty line.
  - gh-70765: http.server: fix default handling of HTTP/0.9
    requests in BaseHTTPRequestHandler. Previously,
    BaseHTTPRequestHandler.parse_request() incorrectly waited
    for headers in the request although those are not supported
    in HTTP/0.9. Patch by Bénédikt Tran.
  - gh-139391: Fix an issue when, on non-Windows platforms, it
    was not possible to gracefully exit a python -m asyncio
    process suspended by Ctrl+Z and later resumed by fg other
    than with kill.
  - gh-101828: Fix 'shift_jisx0213', 'shift_jis_2004',
    'euc_jisx0213' and 'euc_jis_2004' codecs truncating null
    chars as they were treated as part of multi-character
    sequences.
  - gh-139246: fix: paste zero-width in default repl width is
    wrong.
  - gh-90949: Add SetAllocTrackerActivationThreshold() and
    SetAllocTrackerMaximumAmplification() to xmlparser objects
    to prevent use of disproportional amounts of dynamic memory
    from within an Expat parser. Patch by Bénédikt Tran.
  - gh-139065: Fix trailing space before a wrapped long word if
    the line length is exactly width in textwrap.
  - gh-138993: Dedent credits text.
  - gh-138859: Fix generic type parameterization raising
    a TypeError when omitting a ParamSpec that has a default
    which is not a list of types.
  - gh-138775: Use of python -m with base64 has been fixed to
    detect input from a terminal so that it properly notices
    EOF.
  - gh-98896: Fix a failure in multiprocessing resource_tracker
    when SharedMemory names contain colons. Patch by Rani
    Pinchuk.
  - gh-75989: tarfile.TarFile.extractall() and
    tarfile.TarFile.extract() now overwrite symlinks when
    extracting hardlinks. (Contributed by Alexander Enrique
    Urieles Nieto in gh-75989.)
  - gh-83424: Allows creating a ctypes.CDLL without name when
    passing a handle as an argument.
  - gh-136234: Fix asyncio.WriteTransport.writelines() to be
    robust to connection failure, by using the same behavior as
    write().
  - gh-136057: Fixed the bug in pdb and bdb where next and step
    can’t go over the line if a loop exists in the line.
  - gh-135307: email: Fix exception in set_content() when
    encoding text and max_line_length is set to 0 or None
    (unlimited).
  - gh-134453: Fixed subprocess.Popen.communicate() input=
    handling of memoryview instances that were non-byte shaped
    on POSIX platforms. Those are now properly cast to a byte
    shaped view instead of truncating the input. Windows
    platforms did not have this bug.
  - gh-102431: Clarify constraints for “logical” arguments in
    methods of decimal.Context.
  - IDLE
  - gh-96491: Deduplicate version number in IDLE shell title
    bar after saving to a file.
  - Documentation
  - gh-141994: xml.sax.handler: Make Documentation of
    xml.sax.handler.feature_external_ges warn of opening up to
    external entity attacks. Patch by Sebastian Pipping.
  - gh-140578: Remove outdated sencence in the documentation
    for multiprocessing, that implied that
    concurrent.futures.ThreadPoolExecutor did not exist.
  - Core and Builtins
  - gh-142048: Fix quadratically increasing garbage collection
    delays in free-threaded build.
  - gh-141930: When importing a module, use Python’s regular
    file object to ensure that writes to .pyc files are
    complete or an appropriate error is raised.
  - gh-120158: Fix inconsistent state when enabling or
    disabling monitoring events too many times.
  - gh-141579: Fix sys.activate_stack_trampoline() to properly
    support the perf_jit backend. Patch by Pablo Galindo.
  - gh-141312: Fix the assertion failure in the __setstate__
    method of the range iterator when a non-integer argument is
    passed. Patch by Sergey Miryanov.
  - gh-140939: Fix memory leak when bytearray or bytes is
    formated with the
    %*b format with a large width that results in
    %a MemoryError.
  - gh-140530: Fix a reference leak when raise exc from cause
    fails. Patch by Bénédikt Tran.
  - gh-140576: Fixed crash in tokenize.generate_tokens() in
    case of specific incorrect input. Patch by Mikhail Efimov.
  - gh-140551: Fixed crash in dict if dict.clear() is called at
    the lookup stage. Patch by Mikhail Efimov and Inada Naoki.
  - gh-140471: Fix potential buffer overflow in ast.AST node
    initialization when encountering malformed _fields
    containing non-str.
  - gh-140406: Fix memory leak when an object’s __hash__()
    method returns an object that isn’t an int.
  - gh-140306: Fix memory leaks in cross-interpreter channel
    operations and shared namespace handling.
  - gh-140301: Fix memory leak of PyConfig in subinterpreters.
  - gh-140000: Fix potential memory leak when a reference cycle
    exists between an instance of typing.TypeAliasType,
    typing.TypeVar, typing.ParamSpec, or typing.TypeVarTuple
    and its __name__ attribute. Patch by Mikhail Efimov.
  - gh-139748: Fix reference leaks in error branches of
    functions accepting path strings or bytes such as compile()
    and os.system(). Patch by Bénédikt Tran.
  - gh-139516: Fix lambda colon erroneously start format spec
    in f-string in tokenizer.
  - gh-139640: Fix swallowing some syntax warnings in different
    modules if they accidentally have the same message and are
    emitted from the same line. Fix duplicated warnings in the
    finally block.
  - gh-137400: Fix a crash in the free threading build when
    disabling profiling or tracing across all threads with
    PyEval_SetProfileAllThreads() or
    PyEval_SetTraceAllThreads() or their Python equivalents
    threading.settrace_all_threads() and
    threading.setprofile_all_threads().
  - gh-133400: Fixed Ctrl+D (^D) behavior in _pyrepl module to
    match old pre-3.13 REPL behavior.
  - C API
  - gh-140042: Removed the sqlite3_shutdown call that could
    cause closing connections for sqlite when used with
    multiple sub interpreters.
  - gh-140487: Fix Py_RETURN_NOTIMPLEMENTED in limited C API
    3.11 and older: don’t treat Py_NotImplemented as immortal.
    Patch by Victor Stinner.
  - Remove upstreamed patches:
  - CVE-2025-13836-http-resp-cont-len.patch
  - CVE-2025-8291-consistency-zip64.patch
  - CVE-2025-6075-expandvars-perf-degrad.patch

------------------------------------------------------------------
------------------  2025-12-10  -  Dec 10 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Add 0010-add-onExpand-prop-to-ListingTable.patch to backport a feature

++++ kernel-default:

  - exfat: fix refcount leak in exfat_find (git-fixes).
  - commit eb1ffd0
  - mm/hugetlb: unshare page tables during VMA split, not before
    (bsc#1245431 CVE-2025-38084 bsc#1245498).
  - commit ae3cd1c
  - i2c: amd-mp2: fix reference leak in MP2 PCI device (git-fixes).
  - i2c: i2c.h: fix a bad kernel-doc line (git-fixes).
  - platform/x86: asus-wmi: use brightness_set_blocking() for kbd
    led (git-fixes).
  - platform/x86:intel/pmc: Update Arrow Lake telemetry GUID
    (git-fixes).
  - commit 73f17dd

++++ kernel-rt:

  - exfat: fix refcount leak in exfat_find (git-fixes).
  - commit eb1ffd0
  - mm/hugetlb: unshare page tables during VMA split, not before
    (bsc#1245431 CVE-2025-38084 bsc#1245498).
  - commit ae3cd1c
  - i2c: amd-mp2: fix reference leak in MP2 PCI device (git-fixes).
  - i2c: i2c.h: fix a bad kernel-doc line (git-fixes).
  - platform/x86: asus-wmi: use brightness_set_blocking() for kbd
    led (git-fixes).
  - platform/x86:intel/pmc: Update Arrow Lake telemetry GUID
    (git-fixes).
  - commit 73f17dd

++++ selinux-policy:

  - Fix macros.selinux-policy to allow changing booleans when policy
    is not loaded. Previous logic was broken (bsc#1254395)

------------------------------------------------------------------
------------------  2025-12-9  -  Dec 9 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - smb3: fix for slab out of bounds on mount to ksmbd (bsc#1249256,
    CVE-2025-38728).
  - commit 0f61287
  - mount: handle NULL values in mnt_ns_release() (bsc#1254308)
  - commit 08256f9
  - smb: Log an error when close_all_cached_dirs fails (bsc#1246328,
    CVE-2025-38321).
  - commit c5a4d00
  - mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (bsc#1245431
    CVE-2025-38085 bsc#1245499).
  - commit 50d9103
  - arm64: mte: Do not warn if the page is already tagged in (git-fixes)
  - commit 52c9758
  - arm64: zynqmp: Revert usb node drive strength and slew rate for (git-fixes)
  - commit 2f61b01
  - arm64: zynqmp: Disable coresight by default (git-fixes)
  - commit 11d63c1
  - arm64: dts: broadcom: bcm2712: Add default GIC address cells (git-fixes)
  - commit 3096bdd
  - arm64: sysreg: Correct sign definitions for EIESB and DoubleLock (git-fixes)
  - commit 525b723
  - dm-verity: fix unreliable memory allocation (git-fixes).
  - commit 75249b6
  - spi: tegra210-quad: Check hardware status on timeout (bsc#1253155)
  - commit a1e793f
  - spi: tegra210-quad: Refactor error handling into helper functions (bsc#1253155)
  - commit 97a9820
  - spi: tegra210-quad: Fix timeout handling (bsc#1253155)
  - commit c86dba3
  - spi: tegra210-qspi: Remove cache operations (git-fixes)
  - commit 56b11a7
  - spi: tegra210-quad: Add support for internal DMA (git-fixes)
  - commit 908f7ec
  - spi: tegra210-quad: Update dummy sequence configuration (git-fixes)
  - commit 3b335f9
  - kABI workaround for hci_conn remote_id removal (git-fixes).
  - commit 426b083
  - kABI workaround for mgmt_cp_set_mesh struct change (git-fixes).
  - commit 53230c4
  - Bluetooth: btusb: mediatek: Fix kernel crash when releasing
    mtk iso interface (git-fixes).
  - Refresh
    patches.suse/Bluetooth-btusb-mediatek-Avoid-btusb_mtk_claim_iso_i.patch.
  - commit 94a2a40
  - Bluetooth: MGMT: fix crash in set_mesh_sync and
    set_mesh_complete (git-fixes).
  - Refresh patches.kabi/hci_dev-centralize-extra-lock.patch.
  - commit 5a62562
  - Bluetooth: HCI: Fix tracking of advertisement set/instance 0x00
    (git-fixes).
  - Refresh
    patches.suse/Bluetooth-hci_core-Fix-tracking-of-periodic-advertis.patch.
  - commit a7f0549
  - KVM: arm64: Check the untrusted offset in FF-A memory share
    (git-fixes).
  - commit eba1e78
  - mm/hugetlb: fix folio is still mapped when deleted
    (CVE-2025-40006 bsc#1252342).
  - commit 8661a60
  - EDAC/i10nm: Skip DIMM enumeration on a disabled memory
    controller (CVE-2025-40157 bsc#1253423).
  - commit bbd1520
  - docs: hwmon: fix link to g762 devicetree binding (git-fixes).
  - hwmon: (w83791d) Convert macros to functions to avoid TOCTOU
    (git-fixes).
  - pinctrl: single: Fix incorrect type for error return variable
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix PMC restore (git-fixes).
  - pinctrl: stm32: fix hwspinlock resource leak in probe function
    (git-fixes).
  - phy: rockchip: samsung-hdptx: Prevent Inter-Pair Skew from
    exceeding the limits (git-fixes).
  - phy: rockchip: samsung-hdptx: Reduce ROPLL loop bandwidth
    (git-fixes).
  - phy: freescale: Initialize priv->lock (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Fix an error handling path in
    rcar_gen3_phy_usb2_probe() (git-fixes).
  - phy: broadcom: bcm63xx-usbh: fix section mismatches (git-fixes).
  - commit 577e522
  - kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader)
    in sys_prlimit64() paths (CVE-2025-40201 bsc#1253455).
  - commit 2e63b63
  - Refresh
    patches.suse/sched-fair-Enable-scheduler-feature-NEXT_BUDDY.patch.
  - Refresh
    patches.suse/sched-fair-Have-SD_SERIALIZE-affect-newidle-balancing.patch.
  - Refresh
    patches.suse/sched-fair-Proportional-newidle-balance.patch.
  - Refresh
    patches.suse/sched-fair-Reimplement-NEXT_BUDDY-to-align-with-EEVDF-goals.patch.
  - Refresh
    patches.suse/sched-fair-Revert-max_newidle_lb_cost-bump.patch.
  - Refresh
    patches.suse/sched-fair-Skip-sched_balance_running-cmpxchg-when-balance-is-not-due.patch.
  - Refresh
    patches.suse/sched-fair-Small-cleanup-to-sched_balance_newidle.patch.
  - Refresh
    patches.suse/sched-fair-Small-cleanup-to-update_newidle_cost.patch.
    Update upstream status and move to sorted section.
  - commit 16fa696
  - mm: hugetlb: avoid soft lockup when mprotect to large memory
    area (CVE-2025-40153 bsc#1253408).
  - commit 7bc4acd
  - perf list: Add IBM z17 event descriptions (jsc#PED-13611).
  - commit f62e448

++++ kernel-rt:

  - smb3: fix for slab out of bounds on mount to ksmbd (bsc#1249256,
    CVE-2025-38728).
  - commit 0f61287
  - mount: handle NULL values in mnt_ns_release() (bsc#1254308)
  - commit 08256f9
  - smb: Log an error when close_all_cached_dirs fails (bsc#1246328,
    CVE-2025-38321).
  - commit c5a4d00
  - mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (bsc#1245431
    CVE-2025-38085 bsc#1245499).
  - commit 50d9103
  - arm64: mte: Do not warn if the page is already tagged in (git-fixes)
  - commit 52c9758
  - arm64: zynqmp: Revert usb node drive strength and slew rate for (git-fixes)
  - commit 2f61b01
  - arm64: zynqmp: Disable coresight by default (git-fixes)
  - commit 11d63c1
  - arm64: dts: broadcom: bcm2712: Add default GIC address cells (git-fixes)
  - commit 3096bdd
  - arm64: sysreg: Correct sign definitions for EIESB and DoubleLock (git-fixes)
  - commit 525b723
  - dm-verity: fix unreliable memory allocation (git-fixes).
  - commit 75249b6
  - spi: tegra210-quad: Check hardware status on timeout (bsc#1253155)
  - commit a1e793f
  - spi: tegra210-quad: Refactor error handling into helper functions (bsc#1253155)
  - commit 97a9820
  - spi: tegra210-quad: Fix timeout handling (bsc#1253155)
  - commit c86dba3
  - spi: tegra210-qspi: Remove cache operations (git-fixes)
  - commit 56b11a7
  - spi: tegra210-quad: Add support for internal DMA (git-fixes)
  - commit 908f7ec
  - spi: tegra210-quad: Update dummy sequence configuration (git-fixes)
  - commit 3b335f9
  - kABI workaround for hci_conn remote_id removal (git-fixes).
  - commit 426b083
  - kABI workaround for mgmt_cp_set_mesh struct change (git-fixes).
  - commit 53230c4
  - Bluetooth: btusb: mediatek: Fix kernel crash when releasing
    mtk iso interface (git-fixes).
  - Refresh
    patches.suse/Bluetooth-btusb-mediatek-Avoid-btusb_mtk_claim_iso_i.patch.
  - commit 94a2a40
  - Bluetooth: MGMT: fix crash in set_mesh_sync and
    set_mesh_complete (git-fixes).
  - Refresh patches.kabi/hci_dev-centralize-extra-lock.patch.
  - commit 5a62562
  - Bluetooth: HCI: Fix tracking of advertisement set/instance 0x00
    (git-fixes).
  - Refresh
    patches.suse/Bluetooth-hci_core-Fix-tracking-of-periodic-advertis.patch.
  - commit a7f0549
  - KVM: arm64: Check the untrusted offset in FF-A memory share
    (git-fixes).
  - commit eba1e78
  - mm/hugetlb: fix folio is still mapped when deleted
    (CVE-2025-40006 bsc#1252342).
  - commit 8661a60
  - EDAC/i10nm: Skip DIMM enumeration on a disabled memory
    controller (CVE-2025-40157 bsc#1253423).
  - commit bbd1520
  - docs: hwmon: fix link to g762 devicetree binding (git-fixes).
  - hwmon: (w83791d) Convert macros to functions to avoid TOCTOU
    (git-fixes).
  - pinctrl: single: Fix incorrect type for error return variable
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix PMC restore (git-fixes).
  - pinctrl: stm32: fix hwspinlock resource leak in probe function
    (git-fixes).
  - phy: rockchip: samsung-hdptx: Prevent Inter-Pair Skew from
    exceeding the limits (git-fixes).
  - phy: rockchip: samsung-hdptx: Reduce ROPLL loop bandwidth
    (git-fixes).
  - phy: freescale: Initialize priv->lock (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Fix an error handling path in
    rcar_gen3_phy_usb2_probe() (git-fixes).
  - phy: broadcom: bcm63xx-usbh: fix section mismatches (git-fixes).
  - commit 577e522
  - kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader)
    in sys_prlimit64() paths (CVE-2025-40201 bsc#1253455).
  - commit 2e63b63
  - Refresh
    patches.suse/sched-fair-Enable-scheduler-feature-NEXT_BUDDY.patch.
  - Refresh
    patches.suse/sched-fair-Have-SD_SERIALIZE-affect-newidle-balancing.patch.
  - Refresh
    patches.suse/sched-fair-Proportional-newidle-balance.patch.
  - Refresh
    patches.suse/sched-fair-Reimplement-NEXT_BUDDY-to-align-with-EEVDF-goals.patch.
  - Refresh
    patches.suse/sched-fair-Revert-max_newidle_lb_cost-bump.patch.
  - Refresh
    patches.suse/sched-fair-Skip-sched_balance_running-cmpxchg-when-balance-is-not-due.patch.
  - Refresh
    patches.suse/sched-fair-Small-cleanup-to-sched_balance_newidle.patch.
  - Refresh
    patches.suse/sched-fair-Small-cleanup-to-update_newidle_cost.patch.
    Update upstream status and move to sorted section.
  - commit 16fa696
  - mm: hugetlb: avoid soft lockup when mprotect to large memory
    area (CVE-2025-40153 bsc#1253408).
  - commit 7bc4acd
  - perf list: Add IBM z17 event descriptions (jsc#PED-13611).
  - commit f62e448

------------------------------------------------------------------
------------------  2025-12-8  -  Dec 8 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - powerpc/64s/slb: Fix SLB multihit issue during SLB preload
    (bac#1236022 ltc#211187).
  - commit 9c0821c
  - idpf: cleanup remaining SKBs in PTP flows (CVE-2025-40175
    bsc#1253426).
  - commit 659c3f9
  - Update kvmsmall config files.
    disable more NET_VENDOR, no actual change
    AMD ASIX DAVICOM ENGLEDER FUNGIBLE I825XX LITEX META PENSANDO REALTEK VERTEXCOM WANGXUN
  - commit 7e6a292
  - i3c: master: svc: Prevent incomplete IBI transaction
    (git-fixes).
  - i3c: fix refcount inconsistency in i3c_master_register
    (git-fixes).
  - clk: qcom: Mark camcc_sm7150_hws static (git-fixes).
  - clk: qcom: camcc-sm7150: Fix PLL config of PLL2 (git-fixes).
  - clk: qcom: camcc-sm6350: Fix PLL config of PLL2 (git-fixes).
  - clk: qcom: camcc-sm6350: Specify Titan GDSC power domain as
    a parent to other (git-fixes).
  - clk: qcom: camcc-sm8550: Specify Titan GDSC power domain as
    a parent to other (git-fixes).
  - clk: samsung: exynos-clkout: Assign .num before accessing .hws
    (git-fixes).
  - clk: renesas: r9a06g032: Fix memory leak in error path
    (git-fixes).
  - clk: renesas: cpg-mssr: Add missing 1ms delay into reset toggle
    callback (git-fixes).
  - commit 05a94b3

++++ kernel-rt:

  - powerpc/64s/slb: Fix SLB multihit issue during SLB preload
    (bac#1236022 ltc#211187).
  - commit 9c0821c
  - idpf: cleanup remaining SKBs in PTP flows (CVE-2025-40175
    bsc#1253426).
  - commit 659c3f9
  - Update kvmsmall config files.
    disable more NET_VENDOR, no actual change
    AMD ASIX DAVICOM ENGLEDER FUNGIBLE I825XX LITEX META PENSANDO REALTEK VERTEXCOM WANGXUN
  - commit 7e6a292
  - i3c: master: svc: Prevent incomplete IBI transaction
    (git-fixes).
  - i3c: fix refcount inconsistency in i3c_master_register
    (git-fixes).
  - clk: qcom: Mark camcc_sm7150_hws static (git-fixes).
  - clk: qcom: camcc-sm7150: Fix PLL config of PLL2 (git-fixes).
  - clk: qcom: camcc-sm6350: Fix PLL config of PLL2 (git-fixes).
  - clk: qcom: camcc-sm6350: Specify Titan GDSC power domain as
    a parent to other (git-fixes).
  - clk: qcom: camcc-sm8550: Specify Titan GDSC power domain as
    a parent to other (git-fixes).
  - clk: samsung: exynos-clkout: Assign .num before accessing .hws
    (git-fixes).
  - clk: renesas: r9a06g032: Fix memory leak in error path
    (git-fixes).
  - clk: renesas: cpg-mssr: Add missing 1ms delay into reset toggle
    callback (git-fixes).
  - commit 05a94b3

++++ mdadm:

  - Update to version 4.4+31.g541b40d3:
    * fix crash with homehost=none (bsc#1254541)

------------------------------------------------------------------
------------------  2025-12-7  -  Dec 7 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - staging: fbtft: core: fix potential memory leak in
    fbtft_probe_common() (git-fixes).
  - usb: gadget: tegra-xudc: Always reinitialize data toggle when
    clear halt (git-fixes).
  - USB: serial: kobil_sct: fix TIOCMBIS and TIOCMBIC (git-fixes).
  - USB: serial: belkin_sa: fix TIOCMBIS and TIOCMBIC (git-fixes).
  - usb: phy: Initialize struct usb_phy list_head (git-fixes).
  - usb: raw-gadget: cap raw_io transfer length to KMALLOC_MAX_SIZE
    (git-fixes).
  - usb: dwc2: fix hang during suspend if set as peripheral
    (git-fixes).
  - usb: chaoskey: fix locking for O_NONBLOCK (git-fixes).
  - usb: dwc3: dwc3_power_off_all_roothub_ports: Use ioremap_np
    when required (git-fixes).
  - USB: Fix descriptor count when handling invalid MBIM extended
    descriptor (git-fixes).
  - intel_th: Fix error handling in intel_th_output_open
    (git-fixes).
  - comedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel()
    (git-fixes).
  - comedi: multiq3: sanitize config options in multiq3_attach()
    (git-fixes).
  - comedi: check device's attached status in compat ioctls
    (git-fixes).
  - comedi: c6xdigio: Fix invalid PNP driver unregistration
    (git-fixes).
  - mei: gsc: add dependency on Xe driver (git-fixes).
  - firmware: stratix10-svc: fix make htmldocs warning for
    stratix10_svc (git-fixes).
  - interconnect: qcom: sdx75: Drop QPIC interconnect and BCM nodes
    (git-fixes).
  - interconnect: qcom: msm8996: add missing link to SLAVE_USB_HS
    (git-fixes).
  - interconnect: debugfs: Fix incorrect error handling for NULL
    path (git-fixes).
  - iio: core: Clean up device correctly on iio_device_alloc()
    failure (git-fixes).
  - iio: core: add missing mutex_destroy in iio_dev_release()
    (git-fixes).
  - iio: imu: st_lsm6dsx: Fix measurement unit for odr struct member
    (git-fixes).
  - firmware: stratix10-svc: Add mutex in stratix10 memory
    management (git-fixes).
  - uio: uio_fsl_elbc_gpcm:: Add null pointer check to
    uio_fsl_elbc_gpcm_probe (git-fixes).
  - fbdev: ssd1307fb: fix potential page leak in ssd1307fb_probe()
    (git-fixes).
  - fbdev: pxafb: Fix multiple clamped values in pxafb_adjust_timing
    (git-fixes).
  - fbdev: tcx.c fix mem_map to correct smem_start offset
    (git-fixes).
  - watchdog: starfive: Fix resource leak in probe error path
    (git-fixes).
  - watchdog: wdat_wdt: Fix ACPI table leak in probe function
    (git-fixes).
  - rpmsg: glink: fix rpmsg device leak (git-fixes).
  - iio: accel: bmc150: Fix irq assumption regression
    (stable-fixes).
  - usb: storage: sddr55: Reject out-of-bound new_pba
    (stable-fixes).
  - USB: serial: option: add support for Rolling RW101R-GL
    (stable-fixes).
  - USB: serial: ftdi_sio: add support for u-blox EVK-M101
    (stable-fixes).
  - usb: dwc3: pci: Sort out the Intel device IDs (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Nova Lake -S
    (stable-fixes).
  - thunderbolt: Add support for Intel Wildcat Lake (stable-fixes).
  - drm/amd/display: Don't change brightness for disabled connectors
    (stable-fixes).
  - drm/amd/display: Check NULL before accessing (stable-fixes).
  - drm/amd/amdgpu: reserve vm invalidation engine for uni_mes
    (stable-fixes).
  - ALSA: usb-audio: Add DSD quirk for LEAK Stereo 230
    (stable-fixes).
  - usb: udc: Add trace event for usb_gadget_set_state
    (stable-fixes).
  - drm/i915/dp: Initialize the source OUI write timestamp always
    (stable-fixes).
  - commit 2fc138c

++++ kernel-rt:

  - staging: fbtft: core: fix potential memory leak in
    fbtft_probe_common() (git-fixes).
  - usb: gadget: tegra-xudc: Always reinitialize data toggle when
    clear halt (git-fixes).
  - USB: serial: kobil_sct: fix TIOCMBIS and TIOCMBIC (git-fixes).
  - USB: serial: belkin_sa: fix TIOCMBIS and TIOCMBIC (git-fixes).
  - usb: phy: Initialize struct usb_phy list_head (git-fixes).
  - usb: raw-gadget: cap raw_io transfer length to KMALLOC_MAX_SIZE
    (git-fixes).
  - usb: dwc2: fix hang during suspend if set as peripheral
    (git-fixes).
  - usb: chaoskey: fix locking for O_NONBLOCK (git-fixes).
  - usb: dwc3: dwc3_power_off_all_roothub_ports: Use ioremap_np
    when required (git-fixes).
  - USB: Fix descriptor count when handling invalid MBIM extended
    descriptor (git-fixes).
  - intel_th: Fix error handling in intel_th_output_open
    (git-fixes).
  - comedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel()
    (git-fixes).
  - comedi: multiq3: sanitize config options in multiq3_attach()
    (git-fixes).
  - comedi: check device's attached status in compat ioctls
    (git-fixes).
  - comedi: c6xdigio: Fix invalid PNP driver unregistration
    (git-fixes).
  - mei: gsc: add dependency on Xe driver (git-fixes).
  - firmware: stratix10-svc: fix make htmldocs warning for
    stratix10_svc (git-fixes).
  - interconnect: qcom: sdx75: Drop QPIC interconnect and BCM nodes
    (git-fixes).
  - interconnect: qcom: msm8996: add missing link to SLAVE_USB_HS
    (git-fixes).
  - interconnect: debugfs: Fix incorrect error handling for NULL
    path (git-fixes).
  - iio: core: Clean up device correctly on iio_device_alloc()
    failure (git-fixes).
  - iio: core: add missing mutex_destroy in iio_dev_release()
    (git-fixes).
  - iio: imu: st_lsm6dsx: Fix measurement unit for odr struct member
    (git-fixes).
  - firmware: stratix10-svc: Add mutex in stratix10 memory
    management (git-fixes).
  - uio: uio_fsl_elbc_gpcm:: Add null pointer check to
    uio_fsl_elbc_gpcm_probe (git-fixes).
  - fbdev: ssd1307fb: fix potential page leak in ssd1307fb_probe()
    (git-fixes).
  - fbdev: pxafb: Fix multiple clamped values in pxafb_adjust_timing
    (git-fixes).
  - fbdev: tcx.c fix mem_map to correct smem_start offset
    (git-fixes).
  - watchdog: starfive: Fix resource leak in probe error path
    (git-fixes).
  - watchdog: wdat_wdt: Fix ACPI table leak in probe function
    (git-fixes).
  - rpmsg: glink: fix rpmsg device leak (git-fixes).
  - iio: accel: bmc150: Fix irq assumption regression
    (stable-fixes).
  - usb: storage: sddr55: Reject out-of-bound new_pba
    (stable-fixes).
  - USB: serial: option: add support for Rolling RW101R-GL
    (stable-fixes).
  - USB: serial: ftdi_sio: add support for u-blox EVK-M101
    (stable-fixes).
  - usb: dwc3: pci: Sort out the Intel device IDs (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Nova Lake -S
    (stable-fixes).
  - thunderbolt: Add support for Intel Wildcat Lake (stable-fixes).
  - drm/amd/display: Don't change brightness for disabled connectors
    (stable-fixes).
  - drm/amd/display: Check NULL before accessing (stable-fixes).
  - drm/amd/amdgpu: reserve vm invalidation engine for uni_mes
    (stable-fixes).
  - ALSA: usb-audio: Add DSD quirk for LEAK Stereo 230
    (stable-fixes).
  - usb: udc: Add trace event for usb_gadget_set_state
    (stable-fixes).
  - drm/i915/dp: Initialize the source OUI write timestamp always
    (stable-fixes).
  - commit 2fc138c

------------------------------------------------------------------
------------------  2025-12-6  -  Dec 6 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - soc: samsung: exynos-pmu: fix device leak on regmap lookup
    (git-fixes).
  - soc: apple: mailbox: fix device leak on lookup (git-fixes).
  - soc: amlogic: canvas: fix device leak on lookup (git-fixes).
  - soc: qcom: smem: fix hwspinlock resource leak in probe error
    paths (git-fixes).
  - soc: qcom: pbs: fix device leak on lookup (git-fixes).
  - soc: qcom: ocmem: fix device leak on lookup (git-fixes).
  - firmware: qcom: tzmem: fix qcom_tzmem_policy kernel-doc
    (git-fixes).
  - firmware: imx: scu-irq: fix OF node leak in (git-fixes).
  - soc/tegra: fuse: speedo-tegra210: Update speedo IDs (git-fixes).
  - soc/tegra: fuse: Do not register SoC device on ACPI boot
    (git-fixes).
  - sysctl: fix kernel-doc format warning (git-fixes).
  - commit f44d471

++++ kernel-rt:

  - soc: samsung: exynos-pmu: fix device leak on regmap lookup
    (git-fixes).
  - soc: apple: mailbox: fix device leak on lookup (git-fixes).
  - soc: amlogic: canvas: fix device leak on lookup (git-fixes).
  - soc: qcom: smem: fix hwspinlock resource leak in probe error
    paths (git-fixes).
  - soc: qcom: pbs: fix device leak on lookup (git-fixes).
  - soc: qcom: ocmem: fix device leak on lookup (git-fixes).
  - firmware: qcom: tzmem: fix qcom_tzmem_policy kernel-doc
    (git-fixes).
  - firmware: imx: scu-irq: fix OF node leak in (git-fixes).
  - soc/tegra: fuse: speedo-tegra210: Update speedo IDs (git-fixes).
  - soc/tegra: fuse: Do not register SoC device on ACPI boot
    (git-fixes).
  - sysctl: fix kernel-doc format warning (git-fixes).
  - commit f44d471

------------------------------------------------------------------
------------------  2025-12-5  -  Dec 5 2025  -------------------
------------------------------------------------------------------

++++ librsvg:

  - Update to version 2.60.1 -
    (CVE-2024-12224 / bsc#1243867),
    (CVE-2024-43806 / bsc#1229950)
    + This is a security release for RUSTSEC-2024-0421, RUSTSEC-2024-0404,
    and GHSA-c827-hfw6-qwvm (CVE-2024-43806 / bsc#1229376).
  - glgo#GNOME/librsvg#1193 - RUSTSEC-2024-0421 - idna accepts Punycode
    labels that do not produce any non-ASCII when decoded.
  - RUSTSEC-2024-0404 - Unsoundness in anstream.
  - GHSA-c827-hfw6-qwvm - Memory explosion in rustix.  Note that librsvg
    does not use rustix except in the test suite.

++++ kernel-default:

  - net: phy: realtek: add defines for shadowed c45 standard
    registers (jsc#PED-14353).
  - commit 9b6cda5
  - net: phy: realtek: add helper RTL822X_VND2_C22_REG
    (jsc#PED-14353).
  - commit f06f507
  - net: phy: realtek: switch from paged to MMD ops in rtl822x
    functions (jsc#PED-14353).
  - commit b4b9148
  - net: phy: move realtek PHY driver to its own subdirectory
    (jsc#PED-14353).
  - Refresh
    patches.suse/net-phy-realtek-always-clear-NBase-T-lpa.patch.
  - Refresh
    patches.suse/net-phy-realtek-clear-1000Base-T-lpa-if-link-is-down.patch.
  - Refresh
    patches.suse/net-phy-realtek-clear-master_slave_state-if-link-is-.patch.
  - commit e3f95b1
  - net: phy: realtek: always clear NBase-T lpa (git-fixes).
  - net: phy: realtek: clear master_slave_state if link is down
    (git-fixes).
  - commit 0dd31d0
  - net: phy: realtek: clear 1000Base-T lpa if link is down
    (git-fixes).
  - commit 07367d4
  - net: phy: realtek: improve mmd register access for internal
    PHY's (jsc#PED-14353).
  - net: phy: realtek: use string choices helpers (jsc#PED-14353).
  - commit 7ae9fe3
  - net: phy: realtek: clear 1000Base-T link partner advertisement
    (jsc#PED-14353).
  - net: phy: realtek: change order of calls in C22 read_status()
    (jsc#PED-14353).
  - net: phy: realtek: read duplex and gbit master from PHYSR
    register (jsc#PED-14353).
  - commit 4e4fcb4
  - r8169: enable RTL8168H/RTL8168EP/RTL8168FP ASPM support
    (jsc#PED-14353).
  - r8169: switch away from deprecated pcim_iomap_table
    (jsc#PED-14353).
  - r8169: increase max jumbo packet size on RTL8125/RTL8126
    (jsc#PED-14353).
  - r8169: add PHY c45 ops for MDIO_MMD_VENDOR2 registers
    (jsc#PED-14353).
  - r8169: add support for Intel Killer E5000 (jsc#PED-14353).
  - commit 1daed61
  - r8169: adjust version numbering for RTL8126 (jsc#PED-14353).
  - Refresh patches.suse/r8169-set-EEE-speed-down-ratio-to-1.patch.
  - commit abf8121
  - r8169: add support for RTL8125BP rev.b (jsc#PED-14353).
  - r8169: add support for RTL8125D rev.b (jsc#PED-14353).
  - r8169: remove support for chip version 11 (jsc#PED-14353).
  - r8169: remove unused flag RTL_FLAG_TASK_RESET_NO_QUEUE_WAKE
    (jsc#PED-14353).
  - r8169: use helper r8169_mod_reg8_cond to simplify
    rtl_jumbo_config (jsc#PED-14353).
  - r8169: align WAKE_PHY handling with r8125/r8126 vendor drivers
    (jsc#PED-14353).
  - r8169: improve rtl_set_d3_pll_down (jsc#PED-14353).
  - r8169: improve __rtl8169_set_wol (jsc#PED-14353).
  - r8169: remove leftover locks after reverted change
    (jsc#PED-14353).
  - r8169: improve initialization of RSS registers on
    RTL8125/RTL8126 (jsc#PED-14353).
  - r8169: align RTL8126 EEE config with vendor driver
    (jsc#PED-14353).
  - r8169: align RTL8125/RTL8126 PHY config with vendor driver
    (jsc#PED-14353).
  - r8169: align RTL8125 EEE config with vendor driver
    (jsc#PED-14353).
  - r8169: fix inconsistent indenting in rtl8169_get_eth_mac_stats
    (jsc#PED-14353).
  - r8169: enable EEE at 2.5G per default on RTL8125B
    (jsc#PED-14353).
  - r8169: remove rtl_dash_loop_wait_high/low (jsc#PED-14353).
  - r8169: avoid duplicated messages if loading firmware fails
    and switch to warn level (jsc#PED-14353).
  - r8169: replace custom flag with disable_work() et al
    (jsc#PED-14353).
  - r8169: don't take RTNL lock in rtl_task() (jsc#PED-14353).
  - r8169: implement additional ethtool stats ops (jsc#PED-14353).
  - r8169: remove original workaround for RTL8125 broken rx issue
    (jsc#PED-14353).
  - commit fd05f54
  - Revert "drm/amd: Skip power ungate during suspend for VPE"
    (git-fixes).
  - commit 33847bb
  - PCI: rcar-gen2: Drop ARM dependency from PCI_RCAR_GEN2
    (git-fixes).
  - PCI: keystone: Exit ks_pcie_probe() for invalid mode
    (git-fixes).
  - PCI: dwc: Fix wrong PORT_LOGIC_LTSSM_STATE_MASK definition
    (git-fixes).
  - PCI/PM: Reinstate clearing state_saved in legacy and !PM
    codepaths (git-fixes).
  - efi: stmm: fix kernel-doc "bad line" warnings (git-fixes).
  - power: supply: apm_power: only unset own apm_get_power_status
    (git-fixes).
  - power: supply: wm831x: Check wm831x_set_bits() return value
    (git-fixes).
  - power: supply: rt9467: Prevent using uninitialized local
    variable in rt9467_set_value_from_ranges() (git-fixes).
  - power: supply: rt9467: Return error on failure in
    rt9467_set_value_from_ranges() (git-fixes).
  - power: supply: max17040: Check iio_read_channel_processed()
    return code (git-fixes).
  - power: supply: cw2015: Check devm_delayed_work_autocancel()
    return code (git-fixes).
  - power: supply: rt5033_charger: Fix device node reference leaks
    (git-fixes).
  - Documentation: hid-alps: Fix packet format section headings
    (git-fixes).
  - HID: logitech-hidpp: Do not assume FAP in
    hidpp_send_message_sync() (git-fixes).
  - HID: logitech-dj: Add support for a new lightspeed receiver
    iteration (git-fixes).
  - HID: logitech-dj: Remove duplicate error logging (git-fixes).
  - backlight: lp855x: Fix lp855x.h kernel-doc warnings (git-fixes).
  - backlight: led-bl: Add devlink to supplier LEDs (git-fixes).
  - leds: rgb: leds-qcom-lpg: Don't enable TRILED when configuring
    PWM (git-fixes).
  - leds: netxbig: Fix GPIO descriptor leak in error paths
    (git-fixes).
  - leds: leds-lp50xx: Enable chip before any communication
    (git-fixes).
  - leds: Drop duplicate LEDS_EXPRESSWIRE config (git-fixes).
  - leds: leds-cros_ec: Skip LEDs without color components
    (git-fixes).
  - leds: leds-lp50xx: LP5009 supports 3 modules for a total of
    9 LEDs (git-fixes).
  - leds: leds-lp50xx: Allow LED 0 to be added to module bank
    (git-fixes).
  - mfd: mt6358-irq: Fix missing irq_domain_remove() in error path
    (git-fixes).
  - mfd: mt6397-irq: Fix missing irq_domain_remove() in error path
    (git-fixes).
  - mfd: max77620: Fix potential IRQ chip conflict when probing
    two devices (git-fixes).
  - mfd: da9055: Fix missing regmap_del_irq_chip() in error path
    (git-fixes).
  - mfd: altera-sysmgr: Fix device leak on sysmgr regmap lookup
    (git-fixes).
  - platform/x86: intel: chtwc_int33fe: don't dereference swnode
    args (git-fixes).
  - hwmon: (max16065) Use local variable to avoid TOCTOU
    (git-fixes).
  - hwmon: (w83l786ng) Convert macros to functions to avoid TOCTOU
    (git-fixes).
  - hwmon: (max6697) fix regmap leak on probe failure (git-fixes).
  - hwmon: sy7636a: Fix regulator_enable resource leak on error path
    (git-fixes).
  - spi: ch341: fix out-of-bounds memory access in
    ch341_transfer_one (git-fixes).
  - spi: airoha-snfi: en7523: workaround flash damaging if UART_TXD
    was short to GND (git-fixes).
  - spi: bcm63xx: drop wrong casts in probe() (git-fixes).
  - spi: tegra210-quad: Fix timeout handling (git-fixes).
  - regulator: core: Protect regulator_supply_alias_list with
    regulator_list_mutex (git-fixes).
  - regulator: core: disable supply if enabling main regulator fails
    (git-fixes).
  - mtd: rawnand: renesas: Handle devm_pm_runtime_enable() errors
    (git-fixes).
  - mtd: rawnand: lpc32xx_slc: fix GPIO descriptor leak on probe
    error and remove (git-fixes).
  - mtd: nand: relax ECC parameter validation check (git-fixes).
  - Revert "mtd: rawnand: marvell: fix layouts" (git-fixes).
  - mtd: lpddr_cmds: fix signed shifts in lpddr_cmds (git-fixes).
  - mtd: mtdpart: ignore error -ENOENT from parsers on subpartitions
    (git-fixes).
  - mtd: maps: pcmciamtd: fix potential memory leak in
    pcmciamtd_detach() (git-fixes).
  - pwm: bcm2835: Make sure the channel is enabled after
    pwm_request() (git-fixes).
  - platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver
    (git-fixes).
  - ASoC: Intel: catpt: Fix error path in hw_params() (git-fixes).
  - ASoC: codecs: wcd939x: fix regmap leak on probe failure
    (git-fixes).
  - ASoC: stm32: sai: fix OF node leak on probe (git-fixes).
  - ASoC: stm32: sai: fix clk prepare imbalance on probe failure
    (git-fixes).
  - ASoC: stm32: sai: fix device leak on probe (git-fixes).
  - ASoC: codecs: lpass-tx-macro: fix SM6115 support (git-fixes).
  - ASoC: qcom: q6asm-dai: perform correct state check before
    closing (git-fixes).
  - ASoC: qcom: qdsp6: q6asm-dai: set 10 ms period and buffer
    alignment (git-fixes).
  - ASoC: qcom: q6adm: the the copp device only during last instance
    (git-fixes).
  - ASoC: qcom: q6apm-dai: set flags to reflect correct operation
    of appl_ptr (git-fixes).
  - ALSA: dice: fix buffer overflow in detect_stream_formats()
    (git-fixes).
  - ASoC: fsl_xcvr: clear the channel status control memory
    (git-fixes).
  - ASoC: tas2781: correct the wrong period (git-fixes).
  - drm/amdgpu: add missing lock to amdgpu_ttm_access_memory_sdma
    (git-fixes).
  - drm/amd/display: Fix logical vs bitwise bug in
    get_embedded_panel_info_v2_1() (git-fixes).
  - drm/panthor: Avoid adding of kernel BOs to extobj list
    (git-fixes).
  - drm/nouveau: restrict the flush page to a 32-bit address
    (git-fixes).
  - drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl()
    (git-fixes).
  - drm/mediatek: Fix device node reference leak in
    mtk_dp_dt_parse() (git-fixes).
  - drm/mediatek: Fix CCORR mtk_ctm_s31_32_to_s1_n function issue
    (git-fixes).
  - drm/mediatek: Fix probe device leaks (git-fixes).
  - drm/mediatek: Fix probe memory leak (git-fixes).
  - drm/mediatek: Fix probe resource leaks (git-fixes).
  - drm/msm/a6xx: Improve MX rail fallback in RPMH vote init
    (git-fixes).
  - drm/msm/a6xx: Fix the gemnoc workaround (git-fixes).
  - drm/msm/a6xx: Flush LRZ cache before PT switch (git-fixes).
  - drm/msm/a6xx: Fix out of bound IO access in
    a6xx_get_gmu_registers (git-fixes).
  - drm/msm/a2xx: stop over-complaining about the legacy firmware
    (git-fixes).
  - drm/msm/dpu: drop dpu_hw_dsc_destroy() prototype (git-fixes).
  - drm/msm/dpu: Remove dead-code in
    dpu_encoder_helper_reset_mixers() (git-fixes).
  - drm/panthor: Fix potential memleak of vma structure (git-fixes).
  - drm/panthor: Fix UAF on kernel BO VA nodes (git-fixes).
  - drm/panthor: Fix race with suspend during unplug (git-fixes).
  - drm/panthor: Fix UAF race between device unplug and FW event
    processing (git-fixes).
  - drm/panthor: Fix group_free_queue() for partially initialized
    queues (git-fixes).
  - drm/panthor: Handle errors returned by drm_sched_entity_init()
    (git-fixes).
  - drm/imagination: Fix reference to
    devm_platform_get_and_ioremap_resource() (git-fixes).
  - accel/ivpu: Fix race condition when unbinding BOs (git-fixes).
  - drm: atmel-hlcdc: fix atmel_xlcdc_plane_setup_scaler()
    (git-fixes).
  - drm/vgem-fence: Fix potential deadlock on release (git-fixes).
  - accel/ivpu: Fix DCT active percent format (git-fixes).
  - drm/panel: visionox-rm69299: Don't clear all mode flags
    (git-fixes).
  - drm/gma500: Remove unused helper psb_fbdev_fb_setcolreg()
    (git-fixes).
  - gpu: host1x: Fix race in syncpt alloc/free (git-fixes).
  - media: rc: st_rc: Fix reset control resource leak (git-fixes).
  - media: videobuf2: Fix device reference leak in vb2_dc_alloc
    error path (git-fixes).
  - media: vpif_display: fix section mismatch (git-fixes).
  - media: vpif_capture: fix section mismatch (git-fixes).
  - media: samsung: exynos4-is: fix potential ABBA deadlock on init
    (git-fixes).
  - media: renesas: rcar_drif: fix device node reference leak in
    rcar_drif_bond_enabled (git-fixes).
  - media: mediatek: vcodec: Fix a reference leak in
    mtk_vcodec_fw_vpu_init() (git-fixes).
  - media: amphion: Cancel message work before releasing the VPU
    core (git-fixes).
  - media: verisilicon: Protect G2 HEVC decoder against invalid
    DPB index (git-fixes).
  - media: verisilicon: Fix CPU stalls on G2 bus error (git-fixes).
  - media: platform: mtk-mdp3: fix device leaks at probe
    (git-fixes).
  - media: v4l2-mem2mem: Fix outdated documentation (git-fixes).
  - media: cec: Fix debugfs leak on bus_register() failure
    (git-fixes).
  - media: vidtv: initialize local pointers upon transfer of memory
    ownership (git-fixes).
  - media: pvrusb2: Fix incorrect variable used in trace message
    (git-fixes).
  - media: msp3400: Avoid possible out-of-bounds array accesses
    in msp3400c_thread() (git-fixes).
  - media: adv7842: Avoid possible out-of-bounds array accesses
    in adv7842_cp_log_status() (git-fixes).
  - media: i2c: ADV7604: Remove redundant cancel_delayed_work in
    probe (git-fixes).
  - media: i2c: adv7842: Remove redundant cancel_delayed_work in
    probe (git-fixes).
  - media: TDA1997x: Remove redundant cancel_delayed_work in probe
    (git-fixes).
  - media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
    (git-fixes).
  - commit 695e096

++++ kernel-rt:

  - net: phy: realtek: add defines for shadowed c45 standard
    registers (jsc#PED-14353).
  - commit 9b6cda5
  - net: phy: realtek: add helper RTL822X_VND2_C22_REG
    (jsc#PED-14353).
  - commit f06f507
  - net: phy: realtek: switch from paged to MMD ops in rtl822x
    functions (jsc#PED-14353).
  - commit b4b9148
  - net: phy: move realtek PHY driver to its own subdirectory
    (jsc#PED-14353).
  - Refresh
    patches.suse/net-phy-realtek-always-clear-NBase-T-lpa.patch.
  - Refresh
    patches.suse/net-phy-realtek-clear-1000Base-T-lpa-if-link-is-down.patch.
  - Refresh
    patches.suse/net-phy-realtek-clear-master_slave_state-if-link-is-.patch.
  - commit e3f95b1
  - net: phy: realtek: always clear NBase-T lpa (git-fixes).
  - net: phy: realtek: clear master_slave_state if link is down
    (git-fixes).
  - commit 0dd31d0
  - net: phy: realtek: clear 1000Base-T lpa if link is down
    (git-fixes).
  - commit 07367d4
  - net: phy: realtek: improve mmd register access for internal
    PHY's (jsc#PED-14353).
  - net: phy: realtek: use string choices helpers (jsc#PED-14353).
  - commit 7ae9fe3
  - net: phy: realtek: clear 1000Base-T link partner advertisement
    (jsc#PED-14353).
  - net: phy: realtek: change order of calls in C22 read_status()
    (jsc#PED-14353).
  - net: phy: realtek: read duplex and gbit master from PHYSR
    register (jsc#PED-14353).
  - commit 4e4fcb4
  - r8169: enable RTL8168H/RTL8168EP/RTL8168FP ASPM support
    (jsc#PED-14353).
  - r8169: switch away from deprecated pcim_iomap_table
    (jsc#PED-14353).
  - r8169: increase max jumbo packet size on RTL8125/RTL8126
    (jsc#PED-14353).
  - r8169: add PHY c45 ops for MDIO_MMD_VENDOR2 registers
    (jsc#PED-14353).
  - r8169: add support for Intel Killer E5000 (jsc#PED-14353).
  - commit 1daed61
  - r8169: adjust version numbering for RTL8126 (jsc#PED-14353).
  - Refresh patches.suse/r8169-set-EEE-speed-down-ratio-to-1.patch.
  - commit abf8121
  - r8169: add support for RTL8125BP rev.b (jsc#PED-14353).
  - r8169: add support for RTL8125D rev.b (jsc#PED-14353).
  - r8169: remove support for chip version 11 (jsc#PED-14353).
  - r8169: remove unused flag RTL_FLAG_TASK_RESET_NO_QUEUE_WAKE
    (jsc#PED-14353).
  - r8169: use helper r8169_mod_reg8_cond to simplify
    rtl_jumbo_config (jsc#PED-14353).
  - r8169: align WAKE_PHY handling with r8125/r8126 vendor drivers
    (jsc#PED-14353).
  - r8169: improve rtl_set_d3_pll_down (jsc#PED-14353).
  - r8169: improve __rtl8169_set_wol (jsc#PED-14353).
  - r8169: remove leftover locks after reverted change
    (jsc#PED-14353).
  - r8169: improve initialization of RSS registers on
    RTL8125/RTL8126 (jsc#PED-14353).
  - r8169: align RTL8126 EEE config with vendor driver
    (jsc#PED-14353).
  - r8169: align RTL8125/RTL8126 PHY config with vendor driver
    (jsc#PED-14353).
  - r8169: align RTL8125 EEE config with vendor driver
    (jsc#PED-14353).
  - r8169: fix inconsistent indenting in rtl8169_get_eth_mac_stats
    (jsc#PED-14353).
  - r8169: enable EEE at 2.5G per default on RTL8125B
    (jsc#PED-14353).
  - r8169: remove rtl_dash_loop_wait_high/low (jsc#PED-14353).
  - r8169: avoid duplicated messages if loading firmware fails
    and switch to warn level (jsc#PED-14353).
  - r8169: replace custom flag with disable_work() et al
    (jsc#PED-14353).
  - r8169: don't take RTNL lock in rtl_task() (jsc#PED-14353).
  - r8169: implement additional ethtool stats ops (jsc#PED-14353).
  - r8169: remove original workaround for RTL8125 broken rx issue
    (jsc#PED-14353).
  - commit fd05f54
  - Revert "drm/amd: Skip power ungate during suspend for VPE"
    (git-fixes).
  - commit 33847bb
  - PCI: rcar-gen2: Drop ARM dependency from PCI_RCAR_GEN2
    (git-fixes).
  - PCI: keystone: Exit ks_pcie_probe() for invalid mode
    (git-fixes).
  - PCI: dwc: Fix wrong PORT_LOGIC_LTSSM_STATE_MASK definition
    (git-fixes).
  - PCI/PM: Reinstate clearing state_saved in legacy and !PM
    codepaths (git-fixes).
  - efi: stmm: fix kernel-doc "bad line" warnings (git-fixes).
  - power: supply: apm_power: only unset own apm_get_power_status
    (git-fixes).
  - power: supply: wm831x: Check wm831x_set_bits() return value
    (git-fixes).
  - power: supply: rt9467: Prevent using uninitialized local
    variable in rt9467_set_value_from_ranges() (git-fixes).
  - power: supply: rt9467: Return error on failure in
    rt9467_set_value_from_ranges() (git-fixes).
  - power: supply: max17040: Check iio_read_channel_processed()
    return code (git-fixes).
  - power: supply: cw2015: Check devm_delayed_work_autocancel()
    return code (git-fixes).
  - power: supply: rt5033_charger: Fix device node reference leaks
    (git-fixes).
  - Documentation: hid-alps: Fix packet format section headings
    (git-fixes).
  - HID: logitech-hidpp: Do not assume FAP in
    hidpp_send_message_sync() (git-fixes).
  - HID: logitech-dj: Add support for a new lightspeed receiver
    iteration (git-fixes).
  - HID: logitech-dj: Remove duplicate error logging (git-fixes).
  - backlight: lp855x: Fix lp855x.h kernel-doc warnings (git-fixes).
  - backlight: led-bl: Add devlink to supplier LEDs (git-fixes).
  - leds: rgb: leds-qcom-lpg: Don't enable TRILED when configuring
    PWM (git-fixes).
  - leds: netxbig: Fix GPIO descriptor leak in error paths
    (git-fixes).
  - leds: leds-lp50xx: Enable chip before any communication
    (git-fixes).
  - leds: Drop duplicate LEDS_EXPRESSWIRE config (git-fixes).
  - leds: leds-cros_ec: Skip LEDs without color components
    (git-fixes).
  - leds: leds-lp50xx: LP5009 supports 3 modules for a total of
    9 LEDs (git-fixes).
  - leds: leds-lp50xx: Allow LED 0 to be added to module bank
    (git-fixes).
  - mfd: mt6358-irq: Fix missing irq_domain_remove() in error path
    (git-fixes).
  - mfd: mt6397-irq: Fix missing irq_domain_remove() in error path
    (git-fixes).
  - mfd: max77620: Fix potential IRQ chip conflict when probing
    two devices (git-fixes).
  - mfd: da9055: Fix missing regmap_del_irq_chip() in error path
    (git-fixes).
  - mfd: altera-sysmgr: Fix device leak on sysmgr regmap lookup
    (git-fixes).
  - platform/x86: intel: chtwc_int33fe: don't dereference swnode
    args (git-fixes).
  - hwmon: (max16065) Use local variable to avoid TOCTOU
    (git-fixes).
  - hwmon: (w83l786ng) Convert macros to functions to avoid TOCTOU
    (git-fixes).
  - hwmon: (max6697) fix regmap leak on probe failure (git-fixes).
  - hwmon: sy7636a: Fix regulator_enable resource leak on error path
    (git-fixes).
  - spi: ch341: fix out-of-bounds memory access in
    ch341_transfer_one (git-fixes).
  - spi: airoha-snfi: en7523: workaround flash damaging if UART_TXD
    was short to GND (git-fixes).
  - spi: bcm63xx: drop wrong casts in probe() (git-fixes).
  - spi: tegra210-quad: Fix timeout handling (git-fixes).
  - regulator: core: Protect regulator_supply_alias_list with
    regulator_list_mutex (git-fixes).
  - regulator: core: disable supply if enabling main regulator fails
    (git-fixes).
  - mtd: rawnand: renesas: Handle devm_pm_runtime_enable() errors
    (git-fixes).
  - mtd: rawnand: lpc32xx_slc: fix GPIO descriptor leak on probe
    error and remove (git-fixes).
  - mtd: nand: relax ECC parameter validation check (git-fixes).
  - Revert "mtd: rawnand: marvell: fix layouts" (git-fixes).
  - mtd: lpddr_cmds: fix signed shifts in lpddr_cmds (git-fixes).
  - mtd: mtdpart: ignore error -ENOENT from parsers on subpartitions
    (git-fixes).
  - mtd: maps: pcmciamtd: fix potential memory leak in
    pcmciamtd_detach() (git-fixes).
  - pwm: bcm2835: Make sure the channel is enabled after
    pwm_request() (git-fixes).
  - platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver
    (git-fixes).
  - ASoC: Intel: catpt: Fix error path in hw_params() (git-fixes).
  - ASoC: codecs: wcd939x: fix regmap leak on probe failure
    (git-fixes).
  - ASoC: stm32: sai: fix OF node leak on probe (git-fixes).
  - ASoC: stm32: sai: fix clk prepare imbalance on probe failure
    (git-fixes).
  - ASoC: stm32: sai: fix device leak on probe (git-fixes).
  - ASoC: codecs: lpass-tx-macro: fix SM6115 support (git-fixes).
  - ASoC: qcom: q6asm-dai: perform correct state check before
    closing (git-fixes).
  - ASoC: qcom: qdsp6: q6asm-dai: set 10 ms period and buffer
    alignment (git-fixes).
  - ASoC: qcom: q6adm: the the copp device only during last instance
    (git-fixes).
  - ASoC: qcom: q6apm-dai: set flags to reflect correct operation
    of appl_ptr (git-fixes).
  - ALSA: dice: fix buffer overflow in detect_stream_formats()
    (git-fixes).
  - ASoC: fsl_xcvr: clear the channel status control memory
    (git-fixes).
  - ASoC: tas2781: correct the wrong period (git-fixes).
  - drm/amdgpu: add missing lock to amdgpu_ttm_access_memory_sdma
    (git-fixes).
  - drm/amd/display: Fix logical vs bitwise bug in
    get_embedded_panel_info_v2_1() (git-fixes).
  - drm/panthor: Avoid adding of kernel BOs to extobj list
    (git-fixes).
  - drm/nouveau: restrict the flush page to a 32-bit address
    (git-fixes).
  - drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl()
    (git-fixes).
  - drm/mediatek: Fix device node reference leak in
    mtk_dp_dt_parse() (git-fixes).
  - drm/mediatek: Fix CCORR mtk_ctm_s31_32_to_s1_n function issue
    (git-fixes).
  - drm/mediatek: Fix probe device leaks (git-fixes).
  - drm/mediatek: Fix probe memory leak (git-fixes).
  - drm/mediatek: Fix probe resource leaks (git-fixes).
  - drm/msm/a6xx: Improve MX rail fallback in RPMH vote init
    (git-fixes).
  - drm/msm/a6xx: Fix the gemnoc workaround (git-fixes).
  - drm/msm/a6xx: Flush LRZ cache before PT switch (git-fixes).
  - drm/msm/a6xx: Fix out of bound IO access in
    a6xx_get_gmu_registers (git-fixes).
  - drm/msm/a2xx: stop over-complaining about the legacy firmware
    (git-fixes).
  - drm/msm/dpu: drop dpu_hw_dsc_destroy() prototype (git-fixes).
  - drm/msm/dpu: Remove dead-code in
    dpu_encoder_helper_reset_mixers() (git-fixes).
  - drm/panthor: Fix potential memleak of vma structure (git-fixes).
  - drm/panthor: Fix UAF on kernel BO VA nodes (git-fixes).
  - drm/panthor: Fix race with suspend during unplug (git-fixes).
  - drm/panthor: Fix UAF race between device unplug and FW event
    processing (git-fixes).
  - drm/panthor: Fix group_free_queue() for partially initialized
    queues (git-fixes).
  - drm/panthor: Handle errors returned by drm_sched_entity_init()
    (git-fixes).
  - drm/imagination: Fix reference to
    devm_platform_get_and_ioremap_resource() (git-fixes).
  - accel/ivpu: Fix race condition when unbinding BOs (git-fixes).
  - drm: atmel-hlcdc: fix atmel_xlcdc_plane_setup_scaler()
    (git-fixes).
  - drm/vgem-fence: Fix potential deadlock on release (git-fixes).
  - accel/ivpu: Fix DCT active percent format (git-fixes).
  - drm/panel: visionox-rm69299: Don't clear all mode flags
    (git-fixes).
  - drm/gma500: Remove unused helper psb_fbdev_fb_setcolreg()
    (git-fixes).
  - gpu: host1x: Fix race in syncpt alloc/free (git-fixes).
  - media: rc: st_rc: Fix reset control resource leak (git-fixes).
  - media: videobuf2: Fix device reference leak in vb2_dc_alloc
    error path (git-fixes).
  - media: vpif_display: fix section mismatch (git-fixes).
  - media: vpif_capture: fix section mismatch (git-fixes).
  - media: samsung: exynos4-is: fix potential ABBA deadlock on init
    (git-fixes).
  - media: renesas: rcar_drif: fix device node reference leak in
    rcar_drif_bond_enabled (git-fixes).
  - media: mediatek: vcodec: Fix a reference leak in
    mtk_vcodec_fw_vpu_init() (git-fixes).
  - media: amphion: Cancel message work before releasing the VPU
    core (git-fixes).
  - media: verisilicon: Protect G2 HEVC decoder against invalid
    DPB index (git-fixes).
  - media: verisilicon: Fix CPU stalls on G2 bus error (git-fixes).
  - media: platform: mtk-mdp3: fix device leaks at probe
    (git-fixes).
  - media: v4l2-mem2mem: Fix outdated documentation (git-fixes).
  - media: cec: Fix debugfs leak on bus_register() failure
    (git-fixes).
  - media: vidtv: initialize local pointers upon transfer of memory
    ownership (git-fixes).
  - media: pvrusb2: Fix incorrect variable used in trace message
    (git-fixes).
  - media: msp3400: Avoid possible out-of-bounds array accesses
    in msp3400c_thread() (git-fixes).
  - media: adv7842: Avoid possible out-of-bounds array accesses
    in adv7842_cp_log_status() (git-fixes).
  - media: i2c: ADV7604: Remove redundant cancel_delayed_work in
    probe (git-fixes).
  - media: i2c: adv7842: Remove redundant cancel_delayed_work in
    probe (git-fixes).
  - media: TDA1997x: Remove redundant cancel_delayed_work in probe
    (git-fixes).
  - media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
    (git-fixes).
  - commit 695e096

++++ libpng16:

  - security update
  - added patches
    CVE-2025-66293 [bsc#1254480], LIBPNG out-of-bounds read in png_image_read_composite
    * libpng16-CVE-2025-66293.patch

------------------------------------------------------------------
------------------  2025-12-4  -  Dec 4 2025  -------------------
------------------------------------------------------------------

++++ fde-tools:

  - Build with distro flags

++++ kernel-default:

  - net: phy: aquantia: check for NVMEM deferral (git-fixes).
  - wifi: nl80211: vendor-cmd: intel: fix a blank kernel-doc line
    warning (git-fixes).
  - wifi: ieee80211: correct FILS status codes (git-fixes).
  - mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add()
    (git-fixes).
  - wifi: mt76: Fix DTS power-limits on little endian systems
    (git-fixes).
  - wifi: rtl818x: rtl8187: Fix potential buffer underflow in
    rtl8187_rx_cb() (git-fixes).
  - wifi: rtl818x: Fix potential memory leaks in
    rtl8180_init_rx_ring() (git-fixes).
  - wifi: mac80211: fix CMAC functions not handling errors
    (git-fixes).
  - net: phy: adin1100: Fix software power-down ready condition
    (git-fixes).
  - wifi: cw1200: Fix potential memory leak in cw1200_bh_rx_helper()
    (git-fixes).
  - wifi: ath12k: fix potential memory leak in
    ath12k_wow_arp_ns_offload() (git-fixes).
  - wifi: ath11k: fix peer HE MCS assignment (git-fixes).
  - wifi: ath11k: fix VHT MCS assignment (git-fixes).
  - wifi: ath11k: restore register window after global reset
    (git-fixes).
  - lib/vsprintf: Check pointer before dereferencing in
    time_and_date() (git-fixes).
  - Documentation/kernel-parameters: fix typo in retbleed= kernel
    parameter description (git-fixes).
  - Documentation: tps6594-pfsm: Fix macro cross-reference syntax
    (git-fixes).
  - Documentation: mrvl-cn10k-dpi: Fix macro cross-reference syntax
    (git-fixes).
  - Documentation: parport-lowlevel: Separate function listing
    code blocks (git-fixes).
  - docs: w1: fix w1-netlink invalid URL (git-fixes).
  - crypto: ccree - Correctly handle return of sg_nents_for_len
    (git-fixes).
  - crypto: iaa - Fix incorrect return value in save_iaa_wq()
    (git-fixes).
  - crypto: rockchip - drop redundant crypto_skcipher_ivsize()
    calls (git-fixes).
  - crypto: hisilicon/qm - restore original qos values (git-fixes).
  - crypto: asymmetric_keys - prevent overflow in
    asymmetric_key_generate_id (git-fixes).
  - crypto: authenc - Correctly pass EINPROGRESS back up to the
    caller (git-fixes).
  - crypto: af_alg - zero initialize memory allocated via
    sock_kmalloc (git-fixes).
  - crypto: caam - Add check for kcalloc() in test_len()
    (git-fixes).
  - ima: Handle error code returned by ima_filter_rule_match()
    (git-fixes).
  - KEYS: trusted: Fix a memory leak in tpm2_load_cmd (git-fixes).
  - commit 915eacb

++++ kernel-firmware-amdgpu:

  - Update to version 20251203 (git commit a0f0e52138e5):
    * Revert "amdgpu: update GC 11.5.0 firmware"

++++ kernel-rt:

  - net: phy: aquantia: check for NVMEM deferral (git-fixes).
  - wifi: nl80211: vendor-cmd: intel: fix a blank kernel-doc line
    warning (git-fixes).
  - wifi: ieee80211: correct FILS status codes (git-fixes).
  - mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add()
    (git-fixes).
  - wifi: mt76: Fix DTS power-limits on little endian systems
    (git-fixes).
  - wifi: rtl818x: rtl8187: Fix potential buffer underflow in
    rtl8187_rx_cb() (git-fixes).
  - wifi: rtl818x: Fix potential memory leaks in
    rtl8180_init_rx_ring() (git-fixes).
  - wifi: mac80211: fix CMAC functions not handling errors
    (git-fixes).
  - net: phy: adin1100: Fix software power-down ready condition
    (git-fixes).
  - wifi: cw1200: Fix potential memory leak in cw1200_bh_rx_helper()
    (git-fixes).
  - wifi: ath12k: fix potential memory leak in
    ath12k_wow_arp_ns_offload() (git-fixes).
  - wifi: ath11k: fix peer HE MCS assignment (git-fixes).
  - wifi: ath11k: fix VHT MCS assignment (git-fixes).
  - wifi: ath11k: restore register window after global reset
    (git-fixes).
  - lib/vsprintf: Check pointer before dereferencing in
    time_and_date() (git-fixes).
  - Documentation/kernel-parameters: fix typo in retbleed= kernel
    parameter description (git-fixes).
  - Documentation: tps6594-pfsm: Fix macro cross-reference syntax
    (git-fixes).
  - Documentation: mrvl-cn10k-dpi: Fix macro cross-reference syntax
    (git-fixes).
  - Documentation: parport-lowlevel: Separate function listing
    code blocks (git-fixes).
  - docs: w1: fix w1-netlink invalid URL (git-fixes).
  - crypto: ccree - Correctly handle return of sg_nents_for_len
    (git-fixes).
  - crypto: iaa - Fix incorrect return value in save_iaa_wq()
    (git-fixes).
  - crypto: rockchip - drop redundant crypto_skcipher_ivsize()
    calls (git-fixes).
  - crypto: hisilicon/qm - restore original qos values (git-fixes).
  - crypto: asymmetric_keys - prevent overflow in
    asymmetric_key_generate_id (git-fixes).
  - crypto: authenc - Correctly pass EINPROGRESS back up to the
    caller (git-fixes).
  - crypto: af_alg - zero initialize memory allocated via
    sock_kmalloc (git-fixes).
  - crypto: caam - Add check for kcalloc() in test_len()
    (git-fixes).
  - ima: Handle error code returned by ima_filter_rule_match()
    (git-fixes).
  - KEYS: trusted: Fix a memory leak in tpm2_load_cmd (git-fixes).
  - commit 915eacb

++++ ucode-amd:

  - Update to version 20251203 (git commit a0f0e52138e5):
    * linux-firmware: Update amd-ucode copyright information
    * linux-firmware: Update AMD cpu microcode

------------------------------------------------------------------
------------------  2025-12-3  -  Dec 3 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ACPI: property: Fix fwnode refcount leak in
    acpi_fwnode_graph_parse_endpoint() (git-fixes).
  - ACPI: processor_core: fix map_x2apic_id for amd-pstate on am4
    (git-fixes).
  - efi/libstub: Fix page table access in 5-level to 4-level paging
    transition (git-fixes).
  - commit 2215dd3

++++ kernel-firmware-bluetooth:

  - Update to version 20251202 (git commit 685171356137):
    * linux-firmware: Update firmware file for Intel Scorpius core
    * linux-firmware: Update firmware file for Intel BlazarIGfP core
    * linux-firmware: Update firmware file for Intel BlazarI core
    * linux-firmware: Update firmware file for Intel BlazarU-HrPGfP core
    * linux-firmware: Update firmware file for Intel BlazarU core

++++ kernel-rt:

  - ACPI: property: Fix fwnode refcount leak in
    acpi_fwnode_graph_parse_endpoint() (git-fixes).
  - ACPI: processor_core: fix map_x2apic_id for amd-pstate on am4
    (git-fixes).
  - efi/libstub: Fix page table access in 5-level to 4-level paging
    transition (git-fixes).
  - commit 2215dd3

++++ nvidia-open-driver-G06-signed:

  - kernel-6.18.patch
    * fixed build against kernel 6.18

------------------------------------------------------------------
------------------  2025-12-2  -  Dec 2 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Input: cros_ec_keyb - fix an invalid memory access
    (stable-fixes).
  - Input: goodix - add support for ACPI ID GDIX1003 (stable-fixes).
  - drm/xe: Prevent BIT() overflow when handling invalid prefetch
    region (git-fixes).
  - drm/amdgpu: Skip emit de meta data on gfx11 with rs64 enabled
    (stable-fixes).
  - drm/amd: Skip power ungate during suspend for VPE
    (stable-fixes).
  - drm/radeon: delete radeon_fence_process in is_signaled, no
    deadlock (stable-fixes).
  - drm/amd/display: Fix pbn to kbps Conversion (stable-fixes).
  - drm/amd/display: Clear the CUR_ENABLE register on DCN20 on DPP5
    (stable-fixes).
  - drm/amd/display: Increase DPCD read retries (stable-fixes).
  - drm/amd/display: Move sleep into each retry for
    retrieve_link_cap() (stable-fixes).
  - drm/amd/display: Prevent Gating DTBCLK before It Is Properly
    Latched (git-fixes).
  - drm/i915/dp_mst: Disable Panel Replay (git-fixes).
  - drm/amdgpu: fix gpu page fault after hibernation on PF
    passthrough (stable-fixes).
  - drm/amd/display: Insert dccg log for easy debug (stable-fixes).
  - drm/amd/display: disable DPP RCG before DPP CLK enable
    (stable-fixes).
  - drm/amd/display: avoid reset DTBCLK at clock init
    (stable-fixes).
  - commit c2e115d

++++ kernel-rt:

  - Input: cros_ec_keyb - fix an invalid memory access
    (stable-fixes).
  - Input: goodix - add support for ACPI ID GDIX1003 (stable-fixes).
  - drm/xe: Prevent BIT() overflow when handling invalid prefetch
    region (git-fixes).
  - drm/amdgpu: Skip emit de meta data on gfx11 with rs64 enabled
    (stable-fixes).
  - drm/amd: Skip power ungate during suspend for VPE
    (stable-fixes).
  - drm/radeon: delete radeon_fence_process in is_signaled, no
    deadlock (stable-fixes).
  - drm/amd/display: Fix pbn to kbps Conversion (stable-fixes).
  - drm/amd/display: Clear the CUR_ENABLE register on DCN20 on DPP5
    (stable-fixes).
  - drm/amd/display: Increase DPCD read retries (stable-fixes).
  - drm/amd/display: Move sleep into each retry for
    retrieve_link_cap() (stable-fixes).
  - drm/amd/display: Prevent Gating DTBCLK before It Is Properly
    Latched (git-fixes).
  - drm/i915/dp_mst: Disable Panel Replay (git-fixes).
  - drm/amdgpu: fix gpu page fault after hibernation on PF
    passthrough (stable-fixes).
  - drm/amd/display: Insert dccg log for easy debug (stable-fixes).
  - drm/amd/display: disable DPP RCG before DPP CLK enable
    (stable-fixes).
  - drm/amd/display: avoid reset DTBCLK at clock init
    (stable-fixes).
  - commit c2e115d

------------------------------------------------------------------
------------------  2025-12-1  -  Dec 1 2025  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Update to version 2.0.18:
    + This release adds the following features:
  - Add a MOTD message for devices needing reboot after staged updates
  - Create the reboot-required file when a firmware update requires reboot
  - Record the system state for each composite emulation
  - Update USI docking station firmware without requiring a manual replug
    + This release fixes the following bugs:
  - Add a MTD device problem if the Intel SPI BIOS lock is set
  - Allow changing the child name when using PARENT_NAME_PREFIX
  - Allow UpdateCapsule to work on systems that do not support SecureBoot
  - Correctly parse the EFI_CAPSULE_RESULT_VARIABLE_HEADER
  - Fall back to the SMBIOS version for BIOS MTD devices
  - Fix a crash when trying to record an i2c emulation
  - Fixed Huddly upgrade problems with major version changes
  - Fix man page compatibility with apropos and whatis
  - Fix parsing USB BOS descriptors
  - Fix up the x86_64-specific capsule flags when deploying UEFI firmware
  - Improve firmware stream searching speed by a huge amount
  - Only convert the release uint32_t to device version format for UEFI devices
  - Only handle SIGINT in fwupdtool when required
  - Refactor the hypervisor and container detection to be usable from plugins
  - Set PlatformArchitecture as the CPU architecture for RISC-V machines
  - Use a sensible timeout when doing qc-s5gen2 HID requests
    + This release adds support for the following hardware:
  - HP Portable USB-C 4K HDMI Hub
  - Lenovo Legion Go 2 (as a HID device)
  - Synaptics HapticsPad
  - Rebase fwupd-bsc1130056-change-shim-path.patch

++++ kernel-default:

  - NFS4: Fix state renewals missing after boot (git-fixes).
  - commit a5ed3d2
  - NFS: check if suid/sgid was cleared after a write as needed
    (git-fixes).
  - commit dd862cb
  - simplify nfs_atomic_open_v23() (git-fixes).
  - commit 4eb518c
  - exfat: fix improper check of dentry.stream.valid_size
    (git-fixes).
  - commit 7c2b843
  - cramfs: Verify inode mode when loading from disk (git-fixes).
  - commit 7bbff69
  - rpm/mkspec: Exclude azure from kernel-syms dependencies
    Similar to rt azure was initially a separate kernel variant, and not all
    KMPs are built for it. kernel-azure-devel should be included as explicit
    build depedency to get a KMP for this kernel flavor.
  - commit c174e9b
  - Refresh
    patches.suse/wifi-iwlwifi-Add-missing-firmware-info-for-bz-b0-mod.patch.
    Fix backport for 6.12.
    Upstream's IWL_BZ_UCODE_CORE_MAX has to be changed to 6.12's
    IWL_BZ_UCODE_API_MAX. Otherwise we get the fw strings like:
    "firmware" "=" "iwlwifi-bz-b0-fm-c0" "-" "IWL_BZ_UCODE_CORE_MAX" ".ucode";
    instead of upstream's:
    "firmware" "=" "iwlwifi-bz-b0-fm-c0" "-c" "99" ".ucode";
  - commit 0609d52

++++ kernel-firmware-amdgpu:

  - Update to version 20251201 (git commit 934bfe7e1e27):
    * Reapply "amdgpu: update SMU 14.0.3 firmware"
    * Revert "amdgpu: update SMU 14.0.3 firmware"
    * Revert "amdgpu: update GC 10.3.6 firmware"
    * Revert "amdgpu: update GC 11.5.1 firmware"

++++ kernel-rt:

  - NFS4: Fix state renewals missing after boot (git-fixes).
  - commit a5ed3d2
  - NFS: check if suid/sgid was cleared after a write as needed
    (git-fixes).
  - commit dd862cb
  - simplify nfs_atomic_open_v23() (git-fixes).
  - commit 4eb518c
  - exfat: fix improper check of dentry.stream.valid_size
    (git-fixes).
  - commit 7c2b843
  - cramfs: Verify inode mode when loading from disk (git-fixes).
  - commit 7bbff69
  - rpm/mkspec: Exclude azure from kernel-syms dependencies
    Similar to rt azure was initially a separate kernel variant, and not all
    KMPs are built for it. kernel-azure-devel should be included as explicit
    build depedency to get a KMP for this kernel flavor.
  - commit c174e9b
  - Refresh
    patches.suse/wifi-iwlwifi-Add-missing-firmware-info-for-bz-b0-mod.patch.
    Fix backport for 6.12.
    Upstream's IWL_BZ_UCODE_CORE_MAX has to be changed to 6.12's
    IWL_BZ_UCODE_API_MAX. Otherwise we get the fw strings like:
    "firmware" "=" "iwlwifi-bz-b0-fm-c0" "-" "IWL_BZ_UCODE_CORE_MAX" ".ucode";
    instead of upstream's:
    "firmware" "=" "iwlwifi-bz-b0-fm-c0" "-c" "99" ".ucode";
  - commit 0609d52

------------------------------------------------------------------
------------------  2025-11-30  -  Nov 30 2025  -------------------
------------------------------------------------------------------

++++ kernel-firmware-mediatek:

  - Update to version 20251129 (git commit 01006f5dea2d):
    * linux-firmware: update firmware for MT7925 WiFi device
    * mediatek MT7925: update bluetooth firmware to 20251124093155

------------------------------------------------------------------
------------------  2025-11-29  -  Nov 29 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - spi: nxp-fspi: Propagate fwnode in ACPI case as well
    (git-fixes).
  - spi: amlogic-spifc-a1: Handle devm_pm_runtime_enable() errors
    (git-fixes).
  - spi: bcm63xx: fix premature CS deassertion on RX-only
    transactions (git-fixes).
  - regulator: rtq2208: Correct LDO2 logic judgment bits
    (git-fixes).
  - regulator: rtq2208: Correct buck group2 phase mapping logic
    (git-fixes).
  - firmware: stratix10-svc: fix bug in saving controller data
    (git-fixes).
  - iio: st_lsm6dsx: Fixed calibrated timestamp calculation
    (git-fixes).
  - iio: humditiy: hdc3020: fix units for thresholds and hysteresis
    (git-fixes).
  - iio: humditiy: hdc3020: fix units for temperature and humidity
    measurement (git-fixes).
  - iio: imu: st_lsm6dsx: fix array size for st_lsm6dsx_settings
    fields (git-fixes).
  - iio: accel: fix ADXL355 startup race condition (git-fixes).
  - iio:common:ssp_sensors: Fix an error handling path ssp_probe()
    (git-fixes).
  - iio: adc: ad7280a: fix ad7280_store_balance_timer() (git-fixes).
  - iio: adc: stm32-dfsdm: fix st,adc-alt-channel property handling
    (git-fixes).
  - iio: adc: rtq6056: Correct the sign bit index (git-fixes).
  - most: usb: fix double free on late probe failure (git-fixes).
  - slimbus: ngd: Fix reference count leak in
    qcom_slim_ngd_notify_slaves (git-fixes).
  - serial: amba-pl011: prefer dma_mapping_error() over explicit
    address checking (git-fixes).
  - usb: gadget: renesas_usbf: Handle devm_pm_runtime_enable()
    errors (git-fixes).
  - USB: storage: Remove subclass and protocol overrides from
    Novatek quirk (git-fixes).
  - usb: uas: fix urb unmapping issue when the uas device is remove
    during ongoing data transfer (git-fixes).
  - usb: dwc3: Fix race condition between concurrent
    dwc3_remove_requests() call paths (git-fixes).
  - usb: typec: ucsi: psy: Set max current to zero when disconnected
    (git-fixes).
  - usb: gadget: f_eem: Fix memory leak in eem_unwrap (git-fixes).
  - drivers/usb/dwc3: fix PCI parent check (git-fixes).
  - usb: storage: Fix memory leak in USB bulk transport (git-fixes).
  - xhci: fix stale flag preventig URBs after link state error is
    cleared (git-fixes).
  - usb: cdns3: Fix double resource release in cdns3_pci_probe
    (git-fixes).
  - usb: renesas_usbhs: Fix synchronous external abort on unbind
    (git-fixes).
  - mailbox: mtk-cmdq: Refine DMA address handling for the command
    buffer (git-fixes).
  - mailbox: mailbox-test: Fix debugfs_create_dir error checking
    (git-fixes).
  - mmc: sdhci-of-dwcmshc: Promote the th1520 reset handling to
    ip level (git-fixes).
  - drm/xe: Fix conversion from clock ticks to milliseconds
    (git-fixes).
  - drm: sti: fix device leaks at component probe (git-fixes).
  - drm/amdgpu: fix cyan_skillfish2 gpu info fw handling
    (git-fixes).
  - Revert "drm/amd/display: Move setup_stream_attribute"
    (stable-fixes).
  - commit ded5020
  - net: dlink: handle copy_thresh allocation failure (CVE-2025-40053 bsc#1252808)
  - commit 243bc04

++++ kernel-rt:

  - spi: nxp-fspi: Propagate fwnode in ACPI case as well
    (git-fixes).
  - spi: amlogic-spifc-a1: Handle devm_pm_runtime_enable() errors
    (git-fixes).
  - spi: bcm63xx: fix premature CS deassertion on RX-only
    transactions (git-fixes).
  - regulator: rtq2208: Correct LDO2 logic judgment bits
    (git-fixes).
  - regulator: rtq2208: Correct buck group2 phase mapping logic
    (git-fixes).
  - firmware: stratix10-svc: fix bug in saving controller data
    (git-fixes).
  - iio: st_lsm6dsx: Fixed calibrated timestamp calculation
    (git-fixes).
  - iio: humditiy: hdc3020: fix units for thresholds and hysteresis
    (git-fixes).
  - iio: humditiy: hdc3020: fix units for temperature and humidity
    measurement (git-fixes).
  - iio: imu: st_lsm6dsx: fix array size for st_lsm6dsx_settings
    fields (git-fixes).
  - iio: accel: fix ADXL355 startup race condition (git-fixes).
  - iio:common:ssp_sensors: Fix an error handling path ssp_probe()
    (git-fixes).
  - iio: adc: ad7280a: fix ad7280_store_balance_timer() (git-fixes).
  - iio: adc: stm32-dfsdm: fix st,adc-alt-channel property handling
    (git-fixes).
  - iio: adc: rtq6056: Correct the sign bit index (git-fixes).
  - most: usb: fix double free on late probe failure (git-fixes).
  - slimbus: ngd: Fix reference count leak in
    qcom_slim_ngd_notify_slaves (git-fixes).
  - serial: amba-pl011: prefer dma_mapping_error() over explicit
    address checking (git-fixes).
  - usb: gadget: renesas_usbf: Handle devm_pm_runtime_enable()
    errors (git-fixes).
  - USB: storage: Remove subclass and protocol overrides from
    Novatek quirk (git-fixes).
  - usb: uas: fix urb unmapping issue when the uas device is remove
    during ongoing data transfer (git-fixes).
  - usb: dwc3: Fix race condition between concurrent
    dwc3_remove_requests() call paths (git-fixes).
  - usb: typec: ucsi: psy: Set max current to zero when disconnected
    (git-fixes).
  - usb: gadget: f_eem: Fix memory leak in eem_unwrap (git-fixes).
  - drivers/usb/dwc3: fix PCI parent check (git-fixes).
  - usb: storage: Fix memory leak in USB bulk transport (git-fixes).
  - xhci: fix stale flag preventig URBs after link state error is
    cleared (git-fixes).
  - usb: cdns3: Fix double resource release in cdns3_pci_probe
    (git-fixes).
  - usb: renesas_usbhs: Fix synchronous external abort on unbind
    (git-fixes).
  - mailbox: mtk-cmdq: Refine DMA address handling for the command
    buffer (git-fixes).
  - mailbox: mailbox-test: Fix debugfs_create_dir error checking
    (git-fixes).
  - mmc: sdhci-of-dwcmshc: Promote the th1520 reset handling to
    ip level (git-fixes).
  - drm/xe: Fix conversion from clock ticks to milliseconds
    (git-fixes).
  - drm: sti: fix device leaks at component probe (git-fixes).
  - drm/amdgpu: fix cyan_skillfish2 gpu info fw handling
    (git-fixes).
  - Revert "drm/amd/display: Move setup_stream_attribute"
    (stable-fixes).
  - commit ded5020
  - net: dlink: handle copy_thresh allocation failure (CVE-2025-40053 bsc#1252808)
  - commit 243bc04

------------------------------------------------------------------
------------------  2025-11-28  -  Nov 28 2025  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.703.g9c695861:
    * fix(kernel-modules-extra): remove stray \ before / (bsc#1253029)

++++ haproxy:

  - VUL-0: CVE-2025-11230: haproxy: issue in the mjson JSON decoder leads
    to excessive resource consumption when processing numbers with large exponents
    (bsc#1250983)  Add upstream patch:
    0001-BUG-CRITICAL-mjson-fix-possible-DoS-when-parsing-num.patch

++++ kernel-default:

  - pid: Add a judgment for ns null in pid_nr_ns (CVE-2025-40178 bsc#1253463)
  - commit 63794eb
  - wifi: mt76: mt7925: refine the txpower initialization flow
    (bsc#1254315).
  - wifi: mt76: mt7925: add pci restore for hibernate (bsc#1254315).
  - wifi: mt76: mt7925: extend MCU support for testmode
    (bsc#1254315).
  - wifi: mt76: mt7925: Fix logical vs bitwise typo (bsc#1254315).
  - wifi: mt76: mt7925: fix missing hdr_trans_tlv command for
    broadcast wtbl (bsc#1254315).
  - wifi: mt76: mt7925: update the channel usage when the regd
    domain changed (bsc#1254315).
  - wifi: mt76: mt7925: add EHT control support based on the CLC
    data (bsc#1254315).
  - commit b3a65bc
  - wifi: mt76: mt7925: Simplify HIF suspend handling to avoid
    suspend fail (bsc#1254315).
  - wifi: mt76: mt7925: Remove unnecessary if-check (bsc#1254315).
  - wifi: mt76: mt7925e: fix too long of wifi resume time
    (bsc#1254315).
  - wifi: mt76: mt7925: add handler to hif suspend/resume event
    (bsc#1254315).
  - wifi: mt76: mt7925: fix CLC command timeout when suspend/resume
    (bsc#1254315).
  - wifi: mt76: mt7925: fix the unfinished command of regd_notifier
    before suspend (bsc#1254315).
  - commit 7d10c9c
  - wifi: mt76: do not add wcid entries to sta poll list during
    MCU reset (bsc#1254315).
  - wifi: mt76: mt7925: replace zero-length array with
    flexible-array member (bsc#1254315).
  - wifi: mt76: mt7925: config the dwell time by firmware
    (bsc#1254315).
  - wifi: mt76: introduce mt792x_config_mac_addr_list routine
    (bsc#1254315).
  - commit 0881cd3
  - can: sun4i_can: sun4i_can_interrupt(): fix max irq loop handling
    (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length
    before accessing data (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length
    before accessing header (git-fixes).
  - can: gs_usb: gs_usb_xmit_callback(): fix handling of failed
    transmitted URBs (git-fixes).
  - can: sja1000: fix max irq loop handling (git-fixes).
  - can: kvaser_usb: leaf: Fix potential infinite loop in command
    parsers (git-fixes).
  - net: phy: mxl-gpy: fix link properties on USXGMII and internal
    PHYs (git-fixes).
  - atm/fore200e: Fix possible data race in fore200e_open()
    (git-fixes).
  - Bluetooth: SMP: Fix not generating mackey and ltk when repairing
    (git-fixes).
  - Bluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf()
    NULL deref (git-fixes).
  - Bluetooth: hci_sock: Prevent race in socket write iter and
    sock bind (git-fixes).
  - Bluetooth: hci_core: Fix triggering cmd_timer for HCI_OP_NOP
    (git-fixes).
  - net: phy: mxl-gpy: fix bogus error on USXGMII and integrated
    PHY (git-fixes).
  - platform/x86: intel: punit_ipc: fix memory corruption
    (git-fixes).
  - atm: idt77252: Add missing `dma_map_error()` (stable-fixes).
  - commit d903713
  - powercap: intel_rapl: Add support for Panther Lake platform
    (jsc#PED-13949).
  - commit ec5339a

++++ kernel-rt:

  - pid: Add a judgment for ns null in pid_nr_ns (CVE-2025-40178 bsc#1253463)
  - commit 63794eb
  - wifi: mt76: mt7925: refine the txpower initialization flow
    (bsc#1254315).
  - wifi: mt76: mt7925: add pci restore for hibernate (bsc#1254315).
  - wifi: mt76: mt7925: extend MCU support for testmode
    (bsc#1254315).
  - wifi: mt76: mt7925: Fix logical vs bitwise typo (bsc#1254315).
  - wifi: mt76: mt7925: fix missing hdr_trans_tlv command for
    broadcast wtbl (bsc#1254315).
  - wifi: mt76: mt7925: update the channel usage when the regd
    domain changed (bsc#1254315).
  - wifi: mt76: mt7925: add EHT control support based on the CLC
    data (bsc#1254315).
  - commit b3a65bc
  - wifi: mt76: mt7925: Simplify HIF suspend handling to avoid
    suspend fail (bsc#1254315).
  - wifi: mt76: mt7925: Remove unnecessary if-check (bsc#1254315).
  - wifi: mt76: mt7925e: fix too long of wifi resume time
    (bsc#1254315).
  - wifi: mt76: mt7925: add handler to hif suspend/resume event
    (bsc#1254315).
  - wifi: mt76: mt7925: fix CLC command timeout when suspend/resume
    (bsc#1254315).
  - wifi: mt76: mt7925: fix the unfinished command of regd_notifier
    before suspend (bsc#1254315).
  - commit 7d10c9c
  - wifi: mt76: do not add wcid entries to sta poll list during
    MCU reset (bsc#1254315).
  - wifi: mt76: mt7925: replace zero-length array with
    flexible-array member (bsc#1254315).
  - wifi: mt76: mt7925: config the dwell time by firmware
    (bsc#1254315).
  - wifi: mt76: introduce mt792x_config_mac_addr_list routine
    (bsc#1254315).
  - commit 0881cd3
  - can: sun4i_can: sun4i_can_interrupt(): fix max irq loop handling
    (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length
    before accessing data (git-fixes).
  - can: gs_usb: gs_usb_receive_bulk_callback(): check actual_length
    before accessing header (git-fixes).
  - can: gs_usb: gs_usb_xmit_callback(): fix handling of failed
    transmitted URBs (git-fixes).
  - can: sja1000: fix max irq loop handling (git-fixes).
  - can: kvaser_usb: leaf: Fix potential infinite loop in command
    parsers (git-fixes).
  - net: phy: mxl-gpy: fix link properties on USXGMII and internal
    PHYs (git-fixes).
  - atm/fore200e: Fix possible data race in fore200e_open()
    (git-fixes).
  - Bluetooth: SMP: Fix not generating mackey and ltk when repairing
    (git-fixes).
  - Bluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf()
    NULL deref (git-fixes).
  - Bluetooth: hci_sock: Prevent race in socket write iter and
    sock bind (git-fixes).
  - Bluetooth: hci_core: Fix triggering cmd_timer for HCI_OP_NOP
    (git-fixes).
  - net: phy: mxl-gpy: fix bogus error on USXGMII and integrated
    PHY (git-fixes).
  - platform/x86: intel: punit_ipc: fix memory corruption
    (git-fixes).
  - atm: idt77252: Add missing `dma_map_error()` (stable-fixes).
  - commit d903713
  - powercap: intel_rapl: Add support for Panther Lake platform
    (jsc#PED-13949).
  - commit ec5339a

++++ libpng16:

  - security update
  - added patches
    CVE-2025-64505 [bsc#1254157], heap buffer over-read in `png_do_quantize` via malformed palette index
    * libpng16-CVE-2025-64505.patch
    CVE-2025-64506 [bsc#1254158], heap buffer over-read in `png_write_image_8bit` with 8-bit input and `convert_to_8bit` enabled
    * libpng16-CVE-2025-64506.patch
    CVE-2025-64720 [bsc#1254159], buffer overflow in `png_image_read_composite` via incorrect palette premultiplication
    * libpng16-CVE-2025-64720.patch
    CVE-2025-65018 [bsc#1254160], heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`
    * libpng16-CVE-2025-65018.patch

++++ sqlite3:

  - Update to version 3.51.1:
    * Fix incorrect results from nested EXISTS queries caused by the
    optimization in item 6b in the 3.51.0 release.
    * Fix a latent bug in fts5vocab virtual table, exposed by new
    optimizations in the 3.51.0 release
  - Changes in version 3.51.0:
    * New macros in sqlite3.h:
  - SQLITE_SCM_BRANCH → the name of the branch from which the
    source code is taken.
  - SQLITE_SCM_TAGS → space-separated list of tags on the source
    code check-in.
  - SQLITE_SCM_DATETIME → ISO-8601 date and time of the source
    code check-in.
    * Two new JSON functions, jsonb_each() and jsonb_tree() work the
    same as the existing json_each() and json_tree() functions
    except that they return JSONB for the "value" column when the
    "type" is 'array' or 'object'.
    * The carray and percentile extensions are now built into the
    amalgamation, though they are disabled by default and must be
    activated at compile-time using the -DSQLITE_ENABLE_CARRAY
    and/or -DSQLITE_ENABLE_PERCENTILE options, respectively.
    * Enhancements to TCL Interface:
  - Add the -asdict flag to the eval command to have it set the
    row data as a dict instead of an array.
  - User-defined functions may now break to return an SQL NULL.
    * CLI enhancements:
  - Increase the precision of ".timer" to microseconds.
  - Enhance the "box" and "column" formatting modes to deal with
    double-wide characters.
  - The ".imposter" command provides read-only imposter tables
    that work with VACUUM and do not require the --unsafe-testing
    option.
  - Add the --ifexists option to the CLI command-line option and
    to the .open command.
  - Limit columns widths set by the ".width" command to 30,000 or
    less, as there is not good reason to have wider columns, but
    supporting wider columns provides opportunity to malefactors.
    * Performance enhancements:
  - Use fewer CPU cycles to commit a read transaction.
  - Early detection of joins that return no rows due to one or
    more of the tables containing no rows.
  - Avoid evaluation of scalar subqueries if the result of the
    subquery does not change the result of the overall expression.
  - Faster window function queries when using
    "BETWEEN :x FOLLOWING AND :y FOLLOWING" with a large :y.
    * Add the PRAGMA wal_checkpoint=NOOP; command and the
    SQLITE_CHECKPOINT_NOOP argument for sqlite3_wal_checkpoint_v2().
    * Add the sqlite3_set_errmsg() API for use by extensions.
    * Add the sqlite3_db_status64() API, which works just like the
    existing sqlite3_db_status() API except that it returns 64-bit
    results.
    * Add the SQLITE_DBSTATUS_TEMPBUF_SPILL option to the
    sqlite3_db_status() and sqlite3_db_status64() interfaces.
    * In the session extension add the sqlite3changeset_apply_v3()
    interface.
    * For the built-in printf() and the format() SQL function, omit
    the leading '-' from negative floating point numbers if the '+'
    flag is omitted and the "#" flag is present and all displayed
    digits are '0'. Use '%#f' or similar to avoid outputs like
    '-0.00' and instead show just '0.00'.
    * Improved error messages generated by FTS5.
    * Enforce STRICT typing on computed columns.
    * Improved support for VxWorks
    * JavaScript/WASM now supports 64-bit WASM. The canonical builds
    continue to be 32-bit but creating one's own 64-bit build is
    now as simple as running "make".
    * Improved resistance to database corruption caused by an
    application breaking Posix advisory locks using close().

++++ runc:

  - Update to runc v1.3.4. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.3.4>. bsc#1254362

------------------------------------------------------------------
------------------  2025-11-27  -  Nov 27 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable() (CVE-2025-40033 bsc#1252824)
  - commit 1f94f0d
  - dm: fix NULL pointer dereference in __dm_suspend() (CVE-2025-40134 bsc#1253386)
  - commit 58ac2ab
  - dm: fix queue start/stop imbalance under suspend/load/resume races (bsc#1253386)
  - commit b6bae55
  - KVM: arm64: Prevent access to vCPU events before init (CVE-2025-40102 bsc#1252919)
  - commit 4b4bc9f
  - perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (CVE-2025-40081 bsc#1252776)
  - commit 81815d3
  - Add dtb-spacemit
    SpacemiT boards include MilkV-Jupiter, Banana Pi F3 and Orange Pi RV2.
  - commit f2f396d
  - scsi: lpfc: Update lpfc version to 14.4.0.12 (bsc#1254119).
  - scsi: lpfc: Add capability to register Platform Name ID to
    fabric (bsc#1254119).
  - scsi: lpfc: Allow support for BB credit recovery in
    point-to-point topology (bsc#1254119).
  - scsi: lpfc: Fix reusing an ndlp that is marked NLP_DROPPED
    during FLOGI (bsc#1254119).
  - scsi: lpfc: Modify kref handling for Fabric Controller ndlps
    (bsc#1254119).
  - scsi: lpfc: Fix leaked ndlp krefs when in point-to-point
    topology (bsc#1254119).
  - scsi: lpfc: Ensure unregistration of rpis for received PLOGIs
    (bsc#1254119).
  - scsi: lpfc: Remove redundant NULL ptr assignment in
    lpfc_els_free_iocb() (bsc#1254119).
  - scsi: lpfc: Revise discovery related function headers and
    comments (bsc#1254119).
  - scsi: lpfc: Update various NPIV diagnostic log messaging
    (bsc#1254119).
  - commit 35bb962
  - dm error: mark as DM_TARGET_PASSES_INTEGRITY (git-fixes).
  - commit 2430a06
  - nvmet-auth: update sc_c in target host hash calculation
    (git-fixes).
  - nvmet-auth: update sc_c in host response (git-fixes
    bsc#1249397).
  - nvme: Use non zero KATO for persistent discovery connections
    (git-fixes).
  - commit 6cc3f67
  - dm-raid: don't set io_min and io_opt for raid1 (git-fixes).
  - commit 0efc26c
  - dm-integrity: limit MAX_TAG_SIZE to 255 (git-fixes).
  - commit 403c124
  - s390/mm: Fix __ptep_rdp() inline assembly (bsc#1253643).
  - commit 0584e20
  - KVM: s390: kABI backport for 'last_sleep_cpu' (bsc#1252352).
  - KVM: s390: improve interrupt cpu for wakeup (bsc#1235463).
  - commit 772f945
  - kABI workaround for bpf: Enforce expected_attach_type for
    tailcall compatibility (CVE-2025-40123 bsc#1253365).
  - commit 71b6940
  - ALSA: usb-audio: fix uac2 clock source at terminal parser
    (git-fixes).
  - commit cab7bbf
  - selftests/bpf: Add test case for different expected_attach_type
    (CVE-2025-40123 bsc#1253365).
  - bpf: Enforce expected_attach_type for tailcall compatibility
    (CVE-2025-40123 bsc#1253365).
  - commit 9fe957a
  - sched/fair: Have SD_SERIALIZE affect newidle balancing
    (bsc#1248792).
  - commit 64c9f81
  - sched/fair: Skip sched_balance_running cmpxchg when balance
    is not due (bsc#1248792).
  - commit 315148b
  - Delete
    patches.suse/sched-Skip-useless-sched_balance_running-acquisition-if-load-balance-is-not-due.patch.
    Will be replaced by final upstream version.
  - commit 0df2b8e

++++ kernel-rt:

  - remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable() (CVE-2025-40033 bsc#1252824)
  - commit 1f94f0d
  - dm: fix NULL pointer dereference in __dm_suspend() (CVE-2025-40134 bsc#1253386)
  - commit 58ac2ab
  - dm: fix queue start/stop imbalance under suspend/load/resume races (bsc#1253386)
  - commit b6bae55
  - KVM: arm64: Prevent access to vCPU events before init (CVE-2025-40102 bsc#1252919)
  - commit 4b4bc9f
  - perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (CVE-2025-40081 bsc#1252776)
  - commit 81815d3
  - Add dtb-spacemit
    SpacemiT boards include MilkV-Jupiter, Banana Pi F3 and Orange Pi RV2.
  - commit f2f396d
  - scsi: lpfc: Update lpfc version to 14.4.0.12 (bsc#1254119).
  - scsi: lpfc: Add capability to register Platform Name ID to
    fabric (bsc#1254119).
  - scsi: lpfc: Allow support for BB credit recovery in
    point-to-point topology (bsc#1254119).
  - scsi: lpfc: Fix reusing an ndlp that is marked NLP_DROPPED
    during FLOGI (bsc#1254119).
  - scsi: lpfc: Modify kref handling for Fabric Controller ndlps
    (bsc#1254119).
  - scsi: lpfc: Fix leaked ndlp krefs when in point-to-point
    topology (bsc#1254119).
  - scsi: lpfc: Ensure unregistration of rpis for received PLOGIs
    (bsc#1254119).
  - scsi: lpfc: Remove redundant NULL ptr assignment in
    lpfc_els_free_iocb() (bsc#1254119).
  - scsi: lpfc: Revise discovery related function headers and
    comments (bsc#1254119).
  - scsi: lpfc: Update various NPIV diagnostic log messaging
    (bsc#1254119).
  - commit 35bb962
  - dm error: mark as DM_TARGET_PASSES_INTEGRITY (git-fixes).
  - commit 2430a06
  - nvmet-auth: update sc_c in target host hash calculation
    (git-fixes).
  - nvmet-auth: update sc_c in host response (git-fixes
    bsc#1249397).
  - nvme: Use non zero KATO for persistent discovery connections
    (git-fixes).
  - commit 6cc3f67
  - dm-raid: don't set io_min and io_opt for raid1 (git-fixes).
  - commit 0efc26c
  - dm-integrity: limit MAX_TAG_SIZE to 255 (git-fixes).
  - commit 403c124
  - s390/mm: Fix __ptep_rdp() inline assembly (bsc#1253643).
  - commit 0584e20
  - KVM: s390: kABI backport for 'last_sleep_cpu' (bsc#1252352).
  - KVM: s390: improve interrupt cpu for wakeup (bsc#1235463).
  - commit 772f945
  - kABI workaround for bpf: Enforce expected_attach_type for
    tailcall compatibility (CVE-2025-40123 bsc#1253365).
  - commit 71b6940
  - ALSA: usb-audio: fix uac2 clock source at terminal parser
    (git-fixes).
  - commit cab7bbf
  - selftests/bpf: Add test case for different expected_attach_type
    (CVE-2025-40123 bsc#1253365).
  - bpf: Enforce expected_attach_type for tailcall compatibility
    (CVE-2025-40123 bsc#1253365).
  - commit 9fe957a
  - sched/fair: Have SD_SERIALIZE affect newidle balancing
    (bsc#1248792).
  - commit 64c9f81
  - sched/fair: Skip sched_balance_running cmpxchg when balance
    is not due (bsc#1248792).
  - commit 315148b
  - Delete
    patches.suse/sched-Skip-useless-sched_balance_running-acquisition-if-load-balance-is-not-due.patch.
    Will be replaced by final upstream version.
  - commit 0df2b8e

++++ suse-module-tools:

  - Update to version 16.0.63:
    * 80-hotplug-cpu-mem.rules: remount tmpfs on "online" uevents
    (bsc#1254264)
    * udev: use systemd service to remount tmpfs (bsc#1253679)

------------------------------------------------------------------
------------------  2025-11-26  -  Nov 26 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - vhost: Take a reference on the task in struct vhost_task (CVE-2025-40024 bsc#1252686)
  - commit b3a75c3
  - net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work (CVE-2025-40003 bsc#1252301)
  - commit 0fea05a
  - fbnic: Move phylink resume out of service_task and into open/close (CVE-2025-39831 bsc#1249977)
  - commit bfb2b64
  - ipv6: use RCU in ip6_output() (CVE-2025-40158 bsc#1253402).
  - commit e408492
  - ipv6: use RCU in ip6_xmit() (CVE-2025-40135 bsc#1253342).
  - commit 7761cf8
  - Delete
    patches.suse/sched-fair-Get-rid-of-sched_domains_curr_level-hack-for-tl-cpumask.patch.
    patches.suse/sched-topology-Refinement-to-topology_span_sane-speedup.patch.
    patches.suse/sched-topology-improve-topology_span_sane-speed.patch.
    (bsc#1246843)
  - commit cbe4772
  - tls: Use __sk_dst_get() and dst_dev_rcu() in
    get_netdev_for_sock() (CVE-2025-40149 bsc#1253355).
  - commit 952ca78
  - mptcp: Use __sk_dst_get() and dst_dev_rcu() in
    mptcp_active_enable() (CVE-2025-40133 bsc#1253328).
  - mptcp: Call dst_release() in mptcp_active_enable()
    (CVE-2025-40133 bsc#1253328).
  - commit 995c058
  - sched/fair: Get rid of sched_domains_curr_level hack for
    tl->cpumask() (bsc#1246843).
  - x86/smpboot: avoid SMT domain attach/destroy if SMT is not
    enabled (bsc#1246843).
  - x86/smpboot: moves x86_topology to static initialize and
    truncate (bsc#1246843).
  - x86/smpboot: remove redundant CONFIG_SCHED_SMT (bsc#1246843).
  - smpboot: introduce SDTL_INIT() helper to tidy sched topology
    setup (bsc#1246843).
  - commit ce47c32
  - smc: Use __sk_dst_get() and dst_dev_rcu() in
    smc_clc_prfx_match() (CVE-2025-40168 bsc#1253427).
  - commit 53c7932
  - smc: Use __sk_dst_get() and dst_dev_rcu() in in
    smc_clc_prfx_set() (CVE-2025-40139 bsc#1253409).
  - commit e1e0529
  - smc: Fix use-after-free in __pnet_find_base_ndev()
    (CVE-2025-40064 bsc#1252845).
  - commit 186d68e
  - tcp_metrics: use dst_dev_net_rcu() (CVE-2025-40075 bsc#1252795).
  - commit 771932c
  - Update
    patches.suse/ALSA-pcm-Disable-bottom-softirqs-as-part-of-spin_loc.patch
    (git-fixes CVE-2025-40142 bsc#1253348).
  - Update
    patches.suse/ASoC-Intel-bytcr_rt5640-Fix-invalid-quirk-input-mapp.patch
    (git-fixes CVE-2025-40154 bsc#1253431).
  - Update
    patches.suse/ASoC-Intel-bytcr_rt5651-Fix-invalid-quirk-input-mapp.patch
    (git-fixes CVE-2025-40121 bsc#1253367).
  - Update
    patches.suse/ASoC-Intel-sof_sdw-Prevent-jump-to-NULL-add_sidecar-.patch
    (git-fixes CVE-2025-40132 bsc#1253330).
  - Update
    patches.suse/ASoC-amd-sdw_utils-avoid-NULL-deref-when-devm_kaspri.patch
    (git-fixes CVE-2025-40162 bsc#1253422).
  - Update
    patches.suse/Bluetooth-ISO-Fix-possible-UAF-on-iso_conn_free.patch
    (git-fixes CVE-2025-40141 bsc#1253352).
  - Update
    patches.suse/PM-devfreq-mtk-cci-Fix-potential-error-pointer-deref.patch
    (git-fixes CVE-2025-40156 bsc#1253428).
  - Update
    patches.suse/Revert-ipmi-fix-msg-stack-when-IPMI-is-disconnected.patch
    (stable-fixes CVE-2025-40192 bsc#1253622).
  - Update
    patches.suse/Squashfs-reject-negative-file-sizes-in-squashfs_read_inode.patch
    (git-fixes CVE-2025-40200 bsc#1253448).
  - Update
    patches.suse/accel-qaic-Fix-bootlog-initialization-ordering.patch
    (git-fixes CVE-2025-40177 bsc#1253443).
  - Update
    patches.suse/accel-qaic-Treat-remaining-0-as-error-in-find_and_ma.patch
    (git-fixes CVE-2025-40172 bsc#1253424).
  - Update
    patches.suse/bpf-Fix-metadata_dst-leak-__bpf_redirect_neigh_v-4-6.patch
    (git-fixes CVE-2025-40183 bsc#1253441).
  - Update
    patches.suse/btrfs-avoid-potential-out-of-bounds-in-btrfs_encode_.patch
    (git-fixes CVE-2025-40205 bsc#1253456).
  - Update
    patches.suse/can-hi311x-fix-null-pointer-dereference-when-resumin.patch
    (stable-fixes CVE-2025-40107 bsc#1253018).
  - Update
    patches.suse/cpufreq-intel_pstate-Fix-object-lifecycle-issue-in-update_qos_request.patch
    (git-fixes CVE-2025-40194 bsc#1253445).
  - Update
    patches.suse/crypto-rng-Ensure-set_ent-is-always-present.patch
    (git-fixes CVE-2025-40109 bsc#1253176).
  - Update
    patches.suse/drm-vmwgfx-Fix-Use-after-free-in-validation.patch
    (git-fixes CVE-2025-40111 bsc#1253362).
  - Update
    patches.suse/drm-vmwgfx-Fix-a-null-ptr-access-in-the-cursor-snoop.patch
    (git-fixes CVE-2025-40110 bsc#1253275).
  - Update
    patches.suse/drm-xe-guc-Check-GuC-running-state-before-deregister.patch
    (git-fixes CVE-2025-40166 bsc#1253433).
  - Update
    patches.suse/ext4-avoid-potential-buffer-over-read-in-parse_apply.patch
    (git-fixes CVE-2025-40198 bsc#1253453).
  - Update
    patches.suse/fs-quota-create-dedicated-workqueue-for-quota_releas.patch
    (git-fixes CVE-2025-40196 bsc#1253624).
  - Update
    patches.suse/hwrng-ks-sa-fix-division-by-zero-in-ks_sa_rng_init.patch
    (git-fixes CVE-2025-40127 bsc#1253369).
  - Update
    patches.suse/ipmi-Rework-user-message-limit-handling.patch
    (git-fixes CVE-2025-40202 bsc#1253451).
  - Update
    patches.suse/mailbox-zynqmp-ipi-Fix-SGI-cleanup-on-unbind.patch
    (git-fixes CVE-2025-40161 bsc#1253410).
  - Update
    patches.suse/mailbox-zynqmp-ipi-Fix-out-of-bounds-access-in-mailb.patch
    (git-fixes CVE-2025-40180 bsc#1253440).
  - Update
    patches.suse/media-mc-Clear-minor-number-before-put-device.patch
    (git-fixes CVE-2025-40197 bsc#1253450).
  - Update
    patches.suse/media-nxp-imx8-isi-m2m-Fix-streaming-cleanup-on-rele.patch
    (git-fixes CVE-2025-40165 bsc#1253405).
  - Update
    patches.suse/media-v4l2-subdev-Fix-alloc-failure-check-in-v4l2_su.patch
    (git-fixes CVE-2025-40207 bsc#1253395).
  - Update
    patches.suse/net-sctp-fix-a-null-dereference-in-sctp_disposition-.patch
    (git-fixes CVE-2025-40187 bsc#1253647).
  - Update
    patches.suse/net-usb-Remove-disruptive-netif_wake_queue-in-rtl815.patch
    (git-fixes CVE-2025-40140 bsc#1253349).
  - Update
    patches.suse/net-usb-asix-hold-PM-usage-ref-to-avoid-PM-MDIO-RTNL.patch
    (git-fixes CVE-2025-40120 bsc#1253360).
  - Update
    patches.suse/nvmet-fc-move-lsop-put-work-to-nvmet_fc_ls_req_op.patch
    (bsc#1245193 bsc#1247500 CVE-2025-40171 bsc#1253412).
  - Update
    patches.suse/pwm-berlin-Fix-wrong-register-in-suspend-resume.patch
    (git-fixes CVE-2025-40188 bsc#1253449).
  - Update
    patches.suse/scsi-mpt3sas-Fix-crash-in-transport-port-remove-by-using-i.patch
    (git-fixes CVE-2025-40115 bsc#1253318).
  - Update
    patches.suse/scsi-pm80xx-Fix-array-index-out-of-of-bounds-on-rmmod.patch
    (git-fixes CVE-2025-40118 bsc#1253363).
  - Update
    patches.suse/sctp-Fix-MAC-comparison-to-be-constant-time.patch
    (git-fixes CVE-2025-40204 bsc#1253436).
  - Update
    patches.suse/sunrpc-fix-null-pointer-dereference-on-zero-length-checksum.patch
    (git-fixes CVE-2025-40129 bsc#1253472).
  - Update
    patches.suse/tcp-Don-t-call-reqsk_fastopen_remove-in-tcp_conn_request.patch
    (git-fixes CVE-2025-40186 bsc#1253438).
  - Update
    patches.suse/usb-host-max3421-hcd-Fix-error-pointer-dereference-i.patch
    (git-fixes CVE-2025-40116 bsc#1253324).
  - Update
    patches.suse/usbnet-Fix-using-smp_processor_id-in-preemptible-cod.patch
    (git-fixes CVE-2025-40164 bsc#1253407).
  - commit 6d826bc
  - iommu/amd/pgtbl: Fix possible race while increase page table
    level (bsc#1251817 CVE-2025-39961).
  - commit 1eb24e4
  - Fix "drm/xe: Don't allow evicting of BOs in same VM in array of VM binds" (bsc#1252923)
    Fix the following compiler warning:
    * no semicolon at end of struct or union in ../drivers/gpu/drm/xe/xe_vm_types.h
    In file included from ../drivers/gpu/drm/xe/xe_bb.c:16:0:
    ../drivers/gpu/drm/xe/xe_vm_types.h:393:1: warning: no semicolon at end of struct or union
  - drm/xe: Don't allow evicting of BOs in same VM in array of VM binds (bsc#1252923 CVE-2025-40086)
  - commit 89cd9fa

++++ kernel-firmware-amdgpu:

  - Update to version 20251125 (git commit 23568a4b9420):
    * Revert "amdgpu: update GC 11.0.1 firmware"

++++ kernel-firmware-bluetooth:

  - Update to version 20251125 (git commit 23568a4b9420):
    * QCA: Add Bluetooth firmware for WCN685x uart interface

++++ kernel-rt:

  - vhost: Take a reference on the task in struct vhost_task (CVE-2025-40024 bsc#1252686)
  - commit b3a75c3
  - net: mscc: ocelot: Fix use-after-free caused by cyclic delayed work (CVE-2025-40003 bsc#1252301)
  - commit 0fea05a
  - fbnic: Move phylink resume out of service_task and into open/close (CVE-2025-39831 bsc#1249977)
  - commit bfb2b64
  - ipv6: use RCU in ip6_output() (CVE-2025-40158 bsc#1253402).
  - commit e408492
  - ipv6: use RCU in ip6_xmit() (CVE-2025-40135 bsc#1253342).
  - commit 7761cf8
  - Delete
    patches.suse/sched-fair-Get-rid-of-sched_domains_curr_level-hack-for-tl-cpumask.patch.
    patches.suse/sched-topology-Refinement-to-topology_span_sane-speedup.patch.
    patches.suse/sched-topology-improve-topology_span_sane-speed.patch.
    (bsc#1246843)
  - commit cbe4772
  - tls: Use __sk_dst_get() and dst_dev_rcu() in
    get_netdev_for_sock() (CVE-2025-40149 bsc#1253355).
  - commit 952ca78
  - mptcp: Use __sk_dst_get() and dst_dev_rcu() in
    mptcp_active_enable() (CVE-2025-40133 bsc#1253328).
  - mptcp: Call dst_release() in mptcp_active_enable()
    (CVE-2025-40133 bsc#1253328).
  - commit 995c058
  - sched/fair: Get rid of sched_domains_curr_level hack for
    tl->cpumask() (bsc#1246843).
  - x86/smpboot: avoid SMT domain attach/destroy if SMT is not
    enabled (bsc#1246843).
  - x86/smpboot: moves x86_topology to static initialize and
    truncate (bsc#1246843).
  - x86/smpboot: remove redundant CONFIG_SCHED_SMT (bsc#1246843).
  - smpboot: introduce SDTL_INIT() helper to tidy sched topology
    setup (bsc#1246843).
  - commit ce47c32
  - smc: Use __sk_dst_get() and dst_dev_rcu() in
    smc_clc_prfx_match() (CVE-2025-40168 bsc#1253427).
  - commit 53c7932
  - smc: Use __sk_dst_get() and dst_dev_rcu() in in
    smc_clc_prfx_set() (CVE-2025-40139 bsc#1253409).
  - commit e1e0529
  - smc: Fix use-after-free in __pnet_find_base_ndev()
    (CVE-2025-40064 bsc#1252845).
  - commit 186d68e
  - tcp_metrics: use dst_dev_net_rcu() (CVE-2025-40075 bsc#1252795).
  - commit 771932c
  - Update
    patches.suse/ALSA-pcm-Disable-bottom-softirqs-as-part-of-spin_loc.patch
    (git-fixes CVE-2025-40142 bsc#1253348).
  - Update
    patches.suse/ASoC-Intel-bytcr_rt5640-Fix-invalid-quirk-input-mapp.patch
    (git-fixes CVE-2025-40154 bsc#1253431).
  - Update
    patches.suse/ASoC-Intel-bytcr_rt5651-Fix-invalid-quirk-input-mapp.patch
    (git-fixes CVE-2025-40121 bsc#1253367).
  - Update
    patches.suse/ASoC-Intel-sof_sdw-Prevent-jump-to-NULL-add_sidecar-.patch
    (git-fixes CVE-2025-40132 bsc#1253330).
  - Update
    patches.suse/ASoC-amd-sdw_utils-avoid-NULL-deref-when-devm_kaspri.patch
    (git-fixes CVE-2025-40162 bsc#1253422).
  - Update
    patches.suse/Bluetooth-ISO-Fix-possible-UAF-on-iso_conn_free.patch
    (git-fixes CVE-2025-40141 bsc#1253352).
  - Update
    patches.suse/PM-devfreq-mtk-cci-Fix-potential-error-pointer-deref.patch
    (git-fixes CVE-2025-40156 bsc#1253428).
  - Update
    patches.suse/Revert-ipmi-fix-msg-stack-when-IPMI-is-disconnected.patch
    (stable-fixes CVE-2025-40192 bsc#1253622).
  - Update
    patches.suse/Squashfs-reject-negative-file-sizes-in-squashfs_read_inode.patch
    (git-fixes CVE-2025-40200 bsc#1253448).
  - Update
    patches.suse/accel-qaic-Fix-bootlog-initialization-ordering.patch
    (git-fixes CVE-2025-40177 bsc#1253443).
  - Update
    patches.suse/accel-qaic-Treat-remaining-0-as-error-in-find_and_ma.patch
    (git-fixes CVE-2025-40172 bsc#1253424).
  - Update
    patches.suse/bpf-Fix-metadata_dst-leak-__bpf_redirect_neigh_v-4-6.patch
    (git-fixes CVE-2025-40183 bsc#1253441).
  - Update
    patches.suse/btrfs-avoid-potential-out-of-bounds-in-btrfs_encode_.patch
    (git-fixes CVE-2025-40205 bsc#1253456).
  - Update
    patches.suse/can-hi311x-fix-null-pointer-dereference-when-resumin.patch
    (stable-fixes CVE-2025-40107 bsc#1253018).
  - Update
    patches.suse/cpufreq-intel_pstate-Fix-object-lifecycle-issue-in-update_qos_request.patch
    (git-fixes CVE-2025-40194 bsc#1253445).
  - Update
    patches.suse/crypto-rng-Ensure-set_ent-is-always-present.patch
    (git-fixes CVE-2025-40109 bsc#1253176).
  - Update
    patches.suse/drm-vmwgfx-Fix-Use-after-free-in-validation.patch
    (git-fixes CVE-2025-40111 bsc#1253362).
  - Update
    patches.suse/drm-vmwgfx-Fix-a-null-ptr-access-in-the-cursor-snoop.patch
    (git-fixes CVE-2025-40110 bsc#1253275).
  - Update
    patches.suse/drm-xe-guc-Check-GuC-running-state-before-deregister.patch
    (git-fixes CVE-2025-40166 bsc#1253433).
  - Update
    patches.suse/ext4-avoid-potential-buffer-over-read-in-parse_apply.patch
    (git-fixes CVE-2025-40198 bsc#1253453).
  - Update
    patches.suse/fs-quota-create-dedicated-workqueue-for-quota_releas.patch
    (git-fixes CVE-2025-40196 bsc#1253624).
  - Update
    patches.suse/hwrng-ks-sa-fix-division-by-zero-in-ks_sa_rng_init.patch
    (git-fixes CVE-2025-40127 bsc#1253369).
  - Update
    patches.suse/ipmi-Rework-user-message-limit-handling.patch
    (git-fixes CVE-2025-40202 bsc#1253451).
  - Update
    patches.suse/mailbox-zynqmp-ipi-Fix-SGI-cleanup-on-unbind.patch
    (git-fixes CVE-2025-40161 bsc#1253410).
  - Update
    patches.suse/mailbox-zynqmp-ipi-Fix-out-of-bounds-access-in-mailb.patch
    (git-fixes CVE-2025-40180 bsc#1253440).
  - Update
    patches.suse/media-mc-Clear-minor-number-before-put-device.patch
    (git-fixes CVE-2025-40197 bsc#1253450).
  - Update
    patches.suse/media-nxp-imx8-isi-m2m-Fix-streaming-cleanup-on-rele.patch
    (git-fixes CVE-2025-40165 bsc#1253405).
  - Update
    patches.suse/media-v4l2-subdev-Fix-alloc-failure-check-in-v4l2_su.patch
    (git-fixes CVE-2025-40207 bsc#1253395).
  - Update
    patches.suse/net-sctp-fix-a-null-dereference-in-sctp_disposition-.patch
    (git-fixes CVE-2025-40187 bsc#1253647).
  - Update
    patches.suse/net-usb-Remove-disruptive-netif_wake_queue-in-rtl815.patch
    (git-fixes CVE-2025-40140 bsc#1253349).
  - Update
    patches.suse/net-usb-asix-hold-PM-usage-ref-to-avoid-PM-MDIO-RTNL.patch
    (git-fixes CVE-2025-40120 bsc#1253360).
  - Update
    patches.suse/nvmet-fc-move-lsop-put-work-to-nvmet_fc_ls_req_op.patch
    (bsc#1245193 bsc#1247500 CVE-2025-40171 bsc#1253412).
  - Update
    patches.suse/pwm-berlin-Fix-wrong-register-in-suspend-resume.patch
    (git-fixes CVE-2025-40188 bsc#1253449).
  - Update
    patches.suse/scsi-mpt3sas-Fix-crash-in-transport-port-remove-by-using-i.patch
    (git-fixes CVE-2025-40115 bsc#1253318).
  - Update
    patches.suse/scsi-pm80xx-Fix-array-index-out-of-of-bounds-on-rmmod.patch
    (git-fixes CVE-2025-40118 bsc#1253363).
  - Update
    patches.suse/sctp-Fix-MAC-comparison-to-be-constant-time.patch
    (git-fixes CVE-2025-40204 bsc#1253436).
  - Update
    patches.suse/sunrpc-fix-null-pointer-dereference-on-zero-length-checksum.patch
    (git-fixes CVE-2025-40129 bsc#1253472).
  - Update
    patches.suse/tcp-Don-t-call-reqsk_fastopen_remove-in-tcp_conn_request.patch
    (git-fixes CVE-2025-40186 bsc#1253438).
  - Update
    patches.suse/usb-host-max3421-hcd-Fix-error-pointer-dereference-i.patch
    (git-fixes CVE-2025-40116 bsc#1253324).
  - Update
    patches.suse/usbnet-Fix-using-smp_processor_id-in-preemptible-cod.patch
    (git-fixes CVE-2025-40164 bsc#1253407).
  - commit 6d826bc
  - iommu/amd/pgtbl: Fix possible race while increase page table
    level (bsc#1251817 CVE-2025-39961).
  - commit 1eb24e4
  - Fix "drm/xe: Don't allow evicting of BOs in same VM in array of VM binds" (bsc#1252923)
    Fix the following compiler warning:
    * no semicolon at end of struct or union in ../drivers/gpu/drm/xe/xe_vm_types.h
    In file included from ../drivers/gpu/drm/xe/xe_bb.c:16:0:
    ../drivers/gpu/drm/xe/xe_vm_types.h:393:1: warning: no semicolon at end of struct or union
  - drm/xe: Don't allow evicting of BOs in same VM in array of VM binds (bsc#1252923 CVE-2025-40086)
  - commit 89cd9fa

++++ openvswitch:

  - Update OVN to 25.03.1
    * Bug fixes
  - Update Openvswitch to 3.5.2
    * Bug fixes

++++ salt:

  - Add minimum_auth_version to enforce security (CVE-2025-62349)
  - Backport security fixes for vendored tornado
    * BDSA-2024-3438
    * BDSA-2024-3439
    * BDSA-2024-9026
  - Junos module yaml loader fix (CVE-2025-62348)
  - Added:
    * backport-3006.17-security-fixes-739.patch

++++ zypp-plugin:

  - Fix link to libzypp plugins documentation:
    https://opensuse.github.io/libzypp/zypp-plugins.html
  - version 0.6.6

------------------------------------------------------------------
------------------  2025-11-25  -  Nov 25 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ipv4: start using dst_dev_rcu() (CVE-2025-40074 bsc#1252794).
  - commit 6cfda9e
  - kabi: hide dst_entry::dev_rcu (CVE-2025-40074 bsc#1252794).
  - commit fdd7887
  - net: dst: introduce dst->dev_rcu (CVE-2025-40074 bsc#1252794).
  - commit 13867db
  - net: Add locking to protect skb->dev access in ip_output
    (CVE-2025-40074 bsc#1252794).
  - commit 2cdabe8
  - ipv6: ip6_mc_input() and ip6_mr_input() cleanups (CVE-2025-40074
    bsc#1252794).
  - commit fa3386d
  - ipv6: adopt skb_dst_dev() and skb_dst_dev_net[_rcu]() helpers
    (CVE-2025-40074 bsc#1252794).
  - commit c2db144
  - ipv6: adopt dst_dev() helper (CVE-2025-40074 bsc#1252794).
  - refresh patches.suse/net-ip6_tunnel-Prevent-perpetual-tunnel-growth.patch
  - commit c4ea44a
  - ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu]
    (CVE-2025-40074 bsc#1252794).
  - commit 84f2b83
  - net: dst: add four helpers to annotate data-races around
    dst->dev (CVE-2025-40074 bsc#1252794).
  - commit 641c10d
  - net: dst: annotate data-races around dst->output (CVE-2025-40074
    bsc#1252794).
  - commit 0a67853
  - net: dst: annotate data-races around dst->input (CVE-2025-40074
    bsc#1252794).
  - commit bc1bb03
  - net: dst: annotate data-races around dst->lastuse
    (CVE-2025-40074 bsc#1252794).
  - commit c73e633
  - net: dst: annotate data-races around dst->expires
    (CVE-2025-40074 bsc#1252794).
  - commit 036fc25
  - net: dst: annotate data-races around dst->obsolete
    (CVE-2025-40074 bsc#1252794).
  - commit e91bc82
  - net: ipv4: ipmr: ipmr_queue_xmit(): Drop local variable `dev'
    (CVE-2025-40074 bsc#1252794).
  - commit b5b015d
  - net: gro: convert four dev_net() calls (CVE-2025-40074
    bsc#1252794).
  - commit be8aee4
  - tcp: convert to dev_net_rcu() (CVE-2025-40074 bsc#1252794).
  - commit 20ab1af
  - ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
    (stable-fixes).
  - commit d8feafd
  - selftests/run_kselftest.sh: Add `--skip` argument option
    (bsc#1254221).
  - commit 8ddf4e6
  - rpm/kernel-obs-build.spec.in: Add xt_addrtype module for docker
    Needed by docker meanwhile.
  - commit 1cd2f7d
  - wifi: ath11k: Add quirk entries for Thinkpad T14s Gen3 AMD
    (bsc#1254181).
  - commit 74b4608
  - drm/amdkfd: relax checks for over allocation of save area
    (stable-fixes).
  - drm/amdgpu: disable peer-to-peer access for DCC-enabled GC12
    VRAM surfaces (stable-fixes).
  - net: phy: micrel: lan8814 fix reset of the QSGMII interface
    (git-fixes).
  - drm/xe: Do clean shutdown also when using flr (git-fixes).
  - drm/xe: Move declarations under conditional branch
    (stable-fixes).
  - wifi: mac80211: use wiphy_hrtimer_work for csa.switch_work
    (git-fixes).
  - wifi: cfg80211: add an hrtimer based delayed work item
    (stable-fixes).
  - HID: logitech-hidpp: Add HIDPP_QUIRK_RESET_HI_RES_SCROLL
    (stable-fixes).
  - HID: nintendo: Wait longer for initial probe (stable-fixes).
  - HID: quirks: Add ALWAYS_POLL quirk for VRS R295 steering wheel
    (stable-fixes).
  - HID: quirks: avoid Cooler Master MM712 dongle wakeup bug
    (stable-fixes).
  - ASoC: max98090/91: fixed max98091 ALSA widget powering up/down
    (stable-fixes).
  - ALSA: hda: Fix missing pointer check in
    hda_component_manager_init function (git-fixes).
  - drm/amdgpu: Fix NULL pointer dereference in VRAM logic for
    APU devices (stable-fixes).
  - drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM
    (stable-fixes).
  - drm/amdgpu: remove two invalid BUG_ON()s (stable-fixes).
  - drm/amd/pm: Disable MCLK switching on SI at high pixel clocks
    (stable-fixes).
  - net: phy: micrel: Fix lan8814_config_init (git-fixes).
  - net: phy: micrel: Replace hardcoded pages with defines
    (stable-fixes).
  - net: phy: micrel: Introduce lanphy_modify_page_reg
    (stable-fixes).
  - ktime: Add us_to_ktime() (stable-fixes).
  - commit bf8b937
  - selftests/bpf: Fix flaky bpf_cookie selftest (git-fixes).
  - commit 49e49bc

++++ kernel-rt:

  - ipv4: start using dst_dev_rcu() (CVE-2025-40074 bsc#1252794).
  - commit 6cfda9e
  - kabi: hide dst_entry::dev_rcu (CVE-2025-40074 bsc#1252794).
  - commit fdd7887
  - net: dst: introduce dst->dev_rcu (CVE-2025-40074 bsc#1252794).
  - commit 13867db
  - net: Add locking to protect skb->dev access in ip_output
    (CVE-2025-40074 bsc#1252794).
  - commit 2cdabe8
  - ipv6: ip6_mc_input() and ip6_mr_input() cleanups (CVE-2025-40074
    bsc#1252794).
  - commit fa3386d
  - ipv6: adopt skb_dst_dev() and skb_dst_dev_net[_rcu]() helpers
    (CVE-2025-40074 bsc#1252794).
  - commit c2db144
  - ipv6: adopt dst_dev() helper (CVE-2025-40074 bsc#1252794).
  - refresh patches.suse/net-ip6_tunnel-Prevent-perpetual-tunnel-growth.patch
  - commit c4ea44a
  - ipv4: adopt dst_dev, skb_dst_dev and skb_dst_dev_net[_rcu]
    (CVE-2025-40074 bsc#1252794).
  - commit 84f2b83
  - net: dst: add four helpers to annotate data-races around
    dst->dev (CVE-2025-40074 bsc#1252794).
  - commit 641c10d
  - net: dst: annotate data-races around dst->output (CVE-2025-40074
    bsc#1252794).
  - commit 0a67853
  - net: dst: annotate data-races around dst->input (CVE-2025-40074
    bsc#1252794).
  - commit bc1bb03
  - net: dst: annotate data-races around dst->lastuse
    (CVE-2025-40074 bsc#1252794).
  - commit c73e633
  - net: dst: annotate data-races around dst->expires
    (CVE-2025-40074 bsc#1252794).
  - commit 036fc25
  - net: dst: annotate data-races around dst->obsolete
    (CVE-2025-40074 bsc#1252794).
  - commit e91bc82
  - net: ipv4: ipmr: ipmr_queue_xmit(): Drop local variable `dev'
    (CVE-2025-40074 bsc#1252794).
  - commit b5b015d
  - net: gro: convert four dev_net() calls (CVE-2025-40074
    bsc#1252794).
  - commit be8aee4
  - tcp: convert to dev_net_rcu() (CVE-2025-40074 bsc#1252794).
  - commit 20ab1af
  - ALSA: usb-audio: Fix potential overflow of PCM transfer buffer
    (stable-fixes).
  - commit d8feafd
  - selftests/run_kselftest.sh: Add `--skip` argument option
    (bsc#1254221).
  - commit 8ddf4e6
  - rpm/kernel-obs-build.spec.in: Add xt_addrtype module for docker
    Needed by docker meanwhile.
  - commit 1cd2f7d
  - wifi: ath11k: Add quirk entries for Thinkpad T14s Gen3 AMD
    (bsc#1254181).
  - commit 74b4608
  - drm/amdkfd: relax checks for over allocation of save area
    (stable-fixes).
  - drm/amdgpu: disable peer-to-peer access for DCC-enabled GC12
    VRAM surfaces (stable-fixes).
  - net: phy: micrel: lan8814 fix reset of the QSGMII interface
    (git-fixes).
  - drm/xe: Do clean shutdown also when using flr (git-fixes).
  - drm/xe: Move declarations under conditional branch
    (stable-fixes).
  - wifi: mac80211: use wiphy_hrtimer_work for csa.switch_work
    (git-fixes).
  - wifi: cfg80211: add an hrtimer based delayed work item
    (stable-fixes).
  - HID: logitech-hidpp: Add HIDPP_QUIRK_RESET_HI_RES_SCROLL
    (stable-fixes).
  - HID: nintendo: Wait longer for initial probe (stable-fixes).
  - HID: quirks: Add ALWAYS_POLL quirk for VRS R295 steering wheel
    (stable-fixes).
  - HID: quirks: avoid Cooler Master MM712 dongle wakeup bug
    (stable-fixes).
  - ASoC: max98090/91: fixed max98091 ALSA widget powering up/down
    (stable-fixes).
  - ALSA: hda: Fix missing pointer check in
    hda_component_manager_init function (git-fixes).
  - drm/amdgpu: Fix NULL pointer dereference in VRAM logic for
    APU devices (stable-fixes).
  - drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM
    (stable-fixes).
  - drm/amdgpu: remove two invalid BUG_ON()s (stable-fixes).
  - drm/amd/pm: Disable MCLK switching on SI at high pixel clocks
    (stable-fixes).
  - net: phy: micrel: Fix lan8814_config_init (git-fixes).
  - net: phy: micrel: Replace hardcoded pages with defines
    (stable-fixes).
  - net: phy: micrel: Introduce lanphy_modify_page_reg
    (stable-fixes).
  - ktime: Add us_to_ktime() (stable-fixes).
  - commit bf8b937
  - selftests/bpf: Fix flaky bpf_cookie selftest (git-fixes).
  - commit 49e49bc

------------------------------------------------------------------
------------------  2025-11-24  -  Nov 24 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Delete workflows conflicting with upstream

++++ gnutls:

  - Security fix bsc#1254132 CVE-2025-9820
    * Fix buffer overflow in gnutls_pkcs11_token_init
    * Added gnutls-CVE-2025-9820.patch

++++ kernel-default:

  - kernel-binary: Only skip brp-strip when debuginfo is enabled
    Fixes: 4fc8f912b4f2 ("kernel-binary: Do not change debuginfo config during build")
  - commit cd9963e
  - USB: serial: option: add Telit FN920C04 ECM compositions
    (stable-fixes).
  - USB: serial: option: add Quectel RG255C (stable-fixes).
  - commit b1c03da
  - octeontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp() (CVE-2025-39944 bsc#1251120)
  - commit d80dc54
  - ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog (CVE-2025-39859 bsc#1250252)
  - commit 6972595
  - net: macb: fix unregister_netdev call order in macb_remove() (CVE-2025-39805 bsc#1249982)
  - commit 41ae930
  - listmount: don't call path_put() under namespace semaphore (CVE-2025-40203 bsc#1253457)
  - commit 47742e9
  - Disable CONFIG_CPU5_WDT
    The cpu5wdt driver doesn't implement a proper watchdog interface and
    has many code issues. It only handles obscure and obsolete hardware.
    Stop building and supporting this driver (jsc#PED-14062).
  - commit 97992f4
  - idpf: fix possible vport_config NULL pointer deref in remove
    (git-fixes).
  - ice: ice_adapter: release xa entry on adapter allocation failure
    (CVE-2025-40185 bsc#1253394).
  - Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set"
    (git-fixes).
  - net: stmmac: est: Drop frames causing HLBS error (git-fixes).
  - net/mlx5e: Don't query FEC statistics when FEC is disabled
    (git-fixes).
  - net: intel: fm10k: Fix parameter idx set but not used
    (git-fixes).
  - net: ethernet: microchip: sparx5: make it selectable for
    ARCH_LAN969X (git-fixes).
  - eth: 8139too: Make 8139TOO_PIO depend on !NO_IOPORT_MAP
    (git-fixes).
  - net: dsa: felix: support phy-mode = "10g-qxgmii" (git-fixes).
  - idpf: do not linearize big TSO packets (git-fixes).
  - bnxt_en: Add Hyper-V VF ID (git-fixes).
  - net: stmmac: Correctly handle Rx checksum offload errors
    (git-fixes).
  - Revert "net/mlx5e: Update and set Xon/Xoff upon port speed set"
    (git-fixes).
  - net: sfp: add quirk for FLYPRO copper SFP+ module (git-fixes).
  - commit a9efe5e
  - net/ip6_tunnel: Prevent perpetual tunnel growth (CVE-2025-40173
    bsc#1253421).
  - commit aef1404
  - net/smc: Remove validation of reserved bits in CLC Decline
    (bsc#1252357).
  - commit e959d95
  - kernel-binary: Support building gendwarfksyms on SLE/Leap 15
  - commit 940a186
  - btrfs: do not clear read-only when adding sprout device
    (bsc#1253238).
  - commit 33d1fad

++++ kernel-rt:

  - kernel-binary: Only skip brp-strip when debuginfo is enabled
    Fixes: 4fc8f912b4f2 ("kernel-binary: Do not change debuginfo config during build")
  - commit cd9963e
  - USB: serial: option: add Telit FN920C04 ECM compositions
    (stable-fixes).
  - USB: serial: option: add Quectel RG255C (stable-fixes).
  - commit b1c03da
  - octeontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp() (CVE-2025-39944 bsc#1251120)
  - commit d80dc54
  - ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog (CVE-2025-39859 bsc#1250252)
  - commit 6972595
  - net: macb: fix unregister_netdev call order in macb_remove() (CVE-2025-39805 bsc#1249982)
  - commit 41ae930
  - listmount: don't call path_put() under namespace semaphore (CVE-2025-40203 bsc#1253457)
  - commit 47742e9
  - Disable CONFIG_CPU5_WDT
    The cpu5wdt driver doesn't implement a proper watchdog interface and
    has many code issues. It only handles obscure and obsolete hardware.
    Stop building and supporting this driver (jsc#PED-14062).
  - commit 97992f4
  - idpf: fix possible vport_config NULL pointer deref in remove
    (git-fixes).
  - ice: ice_adapter: release xa entry on adapter allocation failure
    (CVE-2025-40185 bsc#1253394).
  - Revert "net/mlx5e: Update and set Xon/Xoff upon MTU set"
    (git-fixes).
  - net: stmmac: est: Drop frames causing HLBS error (git-fixes).
  - net/mlx5e: Don't query FEC statistics when FEC is disabled
    (git-fixes).
  - net: intel: fm10k: Fix parameter idx set but not used
    (git-fixes).
  - net: ethernet: microchip: sparx5: make it selectable for
    ARCH_LAN969X (git-fixes).
  - eth: 8139too: Make 8139TOO_PIO depend on !NO_IOPORT_MAP
    (git-fixes).
  - net: dsa: felix: support phy-mode = "10g-qxgmii" (git-fixes).
  - idpf: do not linearize big TSO packets (git-fixes).
  - bnxt_en: Add Hyper-V VF ID (git-fixes).
  - net: stmmac: Correctly handle Rx checksum offload errors
    (git-fixes).
  - Revert "net/mlx5e: Update and set Xon/Xoff upon port speed set"
    (git-fixes).
  - net: sfp: add quirk for FLYPRO copper SFP+ module (git-fixes).
  - commit a9efe5e
  - net/ip6_tunnel: Prevent perpetual tunnel growth (CVE-2025-40173
    bsc#1253421).
  - commit aef1404
  - net/smc: Remove validation of reserved bits in CLC Decline
    (bsc#1252357).
  - commit e959d95
  - kernel-binary: Support building gendwarfksyms on SLE/Leap 15
  - commit 940a186
  - btrfs: do not clear read-only when adding sprout device
    (bsc#1253238).
  - commit 33d1fad

------------------------------------------------------------------
------------------  2025-11-23  -  Nov 23 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Input: imx_sc_key - fix memory corruption on unload (git-fixes).
  - Input: pegasus-notetaker - fix potential out-of-bounds access
    (git-fixes).
  - commit ca4fb1e
  - scsi: mvsas: Fix use-after-free bugs in mvs_work_queue
    (CVE-2025-40001 bsc#1252303).
  - commit 73f1aad

++++ kernel-rt:

  - Input: imx_sc_key - fix memory corruption on unload (git-fixes).
  - Input: pegasus-notetaker - fix potential out-of-bounds access
    (git-fixes).
  - commit ca4fb1e
  - scsi: mvsas: Fix use-after-free bugs in mvs_work_queue
    (CVE-2025-40001 bsc#1252303).
  - commit 73f1aad

------------------------------------------------------------------
------------------  2025-11-22  -  Nov 22 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ata: libata-scsi: Add missing scsi_device_put() in
    ata_scsi_dev_rescan() (git-fixes).
  - pinctrl: s32cc: initialize gpio_pin_config::list after kmalloc()
    (git-fixes).
  - pinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc
    (git-fixes).
  - pinctrl: cirrus: Fix fwnode leak in cs42l43_pin_probe()
    (git-fixes).
  - pinctrl: realtek: Select REGMAP_MMIO for RTD driver (git-fixes).
  - drm/xe: Remove duplicate DRM_EXEC selection from Kconfig
    (git-fixes).
  - nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot
    (git-fixes).
  - Revert "drm/tegra: dsi: Clear enable register if powered by
    bootloader" (git-fixes).
  - drm/tegra: Add call to put_pid() (git-fixes).
  - drm/tegra: dc: Fix reference leak in tegra_dc_couple()
    (git-fixes).
  - commit 30ae56a

++++ kernel-firmware-amdgpu:

  - Update to version 20251121 (git commit ff6418d18552):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-firmware-bluetooth:

  - Update to version 20251121 (git commit ff6418d18552):
    * rtl_bt: Update RTL8852B BT USB FW to 0x42D3_4E04

++++ kernel-rt:

  - ata: libata-scsi: Add missing scsi_device_put() in
    ata_scsi_dev_rescan() (git-fixes).
  - pinctrl: s32cc: initialize gpio_pin_config::list after kmalloc()
    (git-fixes).
  - pinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc
    (git-fixes).
  - pinctrl: cirrus: Fix fwnode leak in cs42l43_pin_probe()
    (git-fixes).
  - pinctrl: realtek: Select REGMAP_MMIO for RTD driver (git-fixes).
  - drm/xe: Remove duplicate DRM_EXEC selection from Kconfig
    (git-fixes).
  - nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot
    (git-fixes).
  - Revert "drm/tegra: dsi: Clear enable register if powered by
    bootloader" (git-fixes).
  - drm/tegra: Add call to put_pid() (git-fixes).
  - drm/tegra: dc: Fix reference leak in tegra_dc_couple()
    (git-fixes).
  - commit 30ae56a

------------------------------------------------------------------
------------------  2025-11-21  -  Nov 21 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - tls: wait for pending async decryptions if tls_strp_msg_hold
    fails (CVE-2025-40176 bsc#1253425).
  - commit c156a2c
  - platform/x86/intel/speed_select_if: Convert PCIBIOS_* return
    codes to errnos (git-fixes).
  - platform/x86: msi-wmi-platform: Fix typo in WMI GUID
    (git-fixes).
  - platform/x86: msi-wmi-platform: Only load on MSI devices
    (git-fixes).
  - commit a00f5ce
  - vfs: Don't leak disconnected dentries on umount (CVE-2025-40105
    bsc#1252928).
  - commit 9ec7356
  - tee: fix register_shm_helper() (CVE-2025-40031 bsc#1252779).
  - commit b6c7c1f

++++ kernel-rt:

  - tls: wait for pending async decryptions if tls_strp_msg_hold
    fails (CVE-2025-40176 bsc#1253425).
  - commit c156a2c
  - platform/x86/intel/speed_select_if: Convert PCIBIOS_* return
    codes to errnos (git-fixes).
  - platform/x86: msi-wmi-platform: Fix typo in WMI GUID
    (git-fixes).
  - platform/x86: msi-wmi-platform: Only load on MSI devices
    (git-fixes).
  - commit a00f5ce
  - vfs: Don't leak disconnected dentries on umount (CVE-2025-40105
    bsc#1252928).
  - commit 9ec7356
  - tee: fix register_shm_helper() (CVE-2025-40031 bsc#1252779).
  - commit b6c7c1f

++++ libmicrohttpd:

  - Fix for the following bugs:
    * bsc#1253177 CVE-2025-59777
    * bsc#1253178 CVE-2025-62689
  - Add patch:
    * CVE-2025-59777.patch
    * this same patch fixes both CVEs
    * git commit ff13abc1c1d7d2b30d69d5c0bd4a237e1801c50b

------------------------------------------------------------------
------------------  2025-11-20  -  Nov 20 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - HID: uclogic: Fix potential memory leak in error path
    (git-fixes).
  - HID: playstation: Fix memory leak in
    dualshock4_get_calibration_data() (git-fixes).
  - HID: hid-ntrig: Prevent memory leak in ntrig_report_version()
    (git-fixes).
  - HID: amd_sfh: Stop sensor before starting (git-fixes).
  - HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155
    (git-fixes).
  - commit 1cc7637

++++ kernel-firmware-amdgpu:

  - Update to version 20251119 (git commit fe13aa9b9830):
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update renoir firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update GC 10.3.6 firmware
    * amdgpu: update VCN 5.0.0 firmware
    * amdgpu: update SMU 14.0.3 firmware
    * amdgpu: update PSP 14.0.3 firmware
    * amdgpu: update GC 12.0.1 firmware
    * amdgpu: update SMU 14.0.2 firmware
    * amdgpu: update PSP 14.0.2 firmware
    * amdgpu: update GC 12.0.0 firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update smu 13.0.7 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update smu 13.0.0 kicker firmware
    * amdgpu: update PSP 13.0.0 kicker firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SMU 13.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update VCN 5.0.1 firmware
    * amdgpu: update PSP 13.0.12 firmware
    * amdgpu: update GC 9.5.0 firmware
    * amdgpu: update PSP 13.0.14 firmware
    * amdgpu: update GC 9.4.4 firmware
    * amdgpu: update PSP 14.0.5 firmware
    * amdgpu: update GC 11.5.3 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.3 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add vce1 firmware

++++ kernel-firmware-mediatek:

  - Update to version 20251119 (git commit fe13aa9b9830):
    * mediatek MT7922: update bluetooth firmware to 20251118163447
    * linux-firmware: update firmware for MT7922 WiFi device

++++ kernel-rt:

  - HID: uclogic: Fix potential memory leak in error path
    (git-fixes).
  - HID: playstation: Fix memory leak in
    dualshock4_get_calibration_data() (git-fixes).
  - HID: hid-ntrig: Prevent memory leak in ntrig_report_version()
    (git-fixes).
  - HID: amd_sfh: Stop sensor before starting (git-fixes).
  - HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155
    (git-fixes).
  - commit 1cc7637

++++ mdadm:

  - Update to version 4.4+30.g9a59bf51:
    * mdcheck: work around bash 5.3 bug (bsc#1254087)

------------------------------------------------------------------
------------------  2025-11-19  -  Nov 19 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update SELinux module dir as macro to allow root path move from /var/lib/selinux
    to /etc/selinux (bsc#1221342)

++++ curl:

  - Security fix: [bsc#1253757, CVE-2025-11563]
    * curl: wcurl path traversal with percent-encoded slashes
    * Add curl-CVE-2025-11563.patch

++++ kernel-default:

  - tracing: dynevent: Add a missing lockdown check on dynevent
    (CVE-2025-40021 bsc#1252681).
  - commit fb8bc58
  - Update
    patches.suse/netfilter-nft_objref-validate-objref-and-objrefmap-e.patch
    (bsc#1250237 CVE-2025-40206).
    Updated mainline and CVE reference and insert the series.
  - commit eb9ca6a
  - KVM: SVM: Mark VMCB_LBR dirty when MSR_IA32_DEBUGCTLMSR is
    updated (git-fixes).
  - commit b9e89cd
  - KVM: VMX: Fix check for valid GVA on an EPT violation
    (git-fixes).
  - commit b29274c
  - KVM: SVM: Initialize per-CPU svm_data at the end of hardware
    setup (git-fixes).
  - commit bf2f0c2
  - KVM: x86: Don't treat ENTER and LEAVE as branches, because
    they aren't (git-fixes).
  - commit b77653d
  - KVM: SVM: Emulate PERF_CNTR_GLOBAL_STATUS_SET for PerfMonV2
    (git-fixes).
  - commit 16eb189
  - KVM: SVM: Re-load current, not host, TSC_AUX on #VMEXIT from
    SEV-ES guest (git-fixes).
  - commit 1c49256
  - KVM: x86: Add helper to retrieve current value of user return
    MSR (git-fixes).
  - commit cd171db
  - KVM: VMX: Preserve host's DEBUGCTLMSR_FREEZE_IN_SMM while
    running the guest (git-fixes).
  - commit 5727f0b
  - KVM: VMX: Wrap all accesses to IA32_DEBUGCTL with getter/setter
    APIs (git-fixes).
  - commit ee1a2d6
  - KVM: nVMX: Check vmcs12->guest_ia32_debugctl on nested VM-Enter
    (git-fixes).
  - commit d879306
  - KVM: VMX: Extract checking of guest's DEBUGCTL into helper
    (git-fixes).
  - commit a2f59ae
  - KVM: VMX: Allow guest to set DEBUGCTL.RTM_DEBUG if RTM is
    supported (git-fixes).
  - commit 2968fd0
  - KVM: x86: Drop kvm_x86_ops.set_dr6() in favor of a new KVM_RUN
    flag (git-fixes).
  - commit 39255f9
  - s390/pci: Use pci_uevent_ers() in PCI recovery (git-fixes).
  - commit 0abe806
  - bpf: Reject negative offsets for ALU ops (CVE-2025-40169
    bsc#1253416).
  - commit c692c6c

++++ kernel-rt:

  - tracing: dynevent: Add a missing lockdown check on dynevent
    (CVE-2025-40021 bsc#1252681).
  - commit fb8bc58
  - Update
    patches.suse/netfilter-nft_objref-validate-objref-and-objrefmap-e.patch
    (bsc#1250237 CVE-2025-40206).
    Updated mainline and CVE reference and insert the series.
  - commit eb9ca6a
  - KVM: SVM: Mark VMCB_LBR dirty when MSR_IA32_DEBUGCTLMSR is
    updated (git-fixes).
  - commit b9e89cd
  - KVM: VMX: Fix check for valid GVA on an EPT violation
    (git-fixes).
  - commit b29274c
  - KVM: SVM: Initialize per-CPU svm_data at the end of hardware
    setup (git-fixes).
  - commit bf2f0c2
  - KVM: x86: Don't treat ENTER and LEAVE as branches, because
    they aren't (git-fixes).
  - commit b77653d
  - KVM: SVM: Emulate PERF_CNTR_GLOBAL_STATUS_SET for PerfMonV2
    (git-fixes).
  - commit 16eb189
  - KVM: SVM: Re-load current, not host, TSC_AUX on #VMEXIT from
    SEV-ES guest (git-fixes).
  - commit 1c49256
  - KVM: x86: Add helper to retrieve current value of user return
    MSR (git-fixes).
  - commit cd171db
  - KVM: VMX: Preserve host's DEBUGCTLMSR_FREEZE_IN_SMM while
    running the guest (git-fixes).
  - commit 5727f0b
  - KVM: VMX: Wrap all accesses to IA32_DEBUGCTL with getter/setter
    APIs (git-fixes).
  - commit ee1a2d6
  - KVM: nVMX: Check vmcs12->guest_ia32_debugctl on nested VM-Enter
    (git-fixes).
  - commit d879306
  - KVM: VMX: Extract checking of guest's DEBUGCTL into helper
    (git-fixes).
  - commit a2f59ae
  - KVM: VMX: Allow guest to set DEBUGCTL.RTM_DEBUG if RTM is
    supported (git-fixes).
  - commit 2968fd0
  - KVM: x86: Drop kvm_x86_ops.set_dr6() in favor of a new KVM_RUN
    flag (git-fixes).
  - commit 39255f9
  - s390/pci: Use pci_uevent_ers() in PCI recovery (git-fixes).
  - commit 0abe806
  - bpf: Reject negative offsets for ALU ops (CVE-2025-40169
    bsc#1253416).
  - commit c692c6c

++++ python313-core:

  - Add pass-test_write_read_limited_history.patch:
    Fix readline history truncation when length is reduced
    The `readline.set_history_length()` function did not previously
    truncate the in-memory history when the new length was set to
    a value smaller than the current number of history items. This
    could lead to unexpected behavior where `get_history_length()`
    would still report the old length and writing the history to a
    file would write more entries than the new limit.
    This patch modifies `set_history_length()` to explicitly
    remove the oldest history entries using `remove_history()`
    when the length is decreased, ensuring the in-memory history
    is correctly truncated to the new limit. This brings the
    function's behavior in line with expectations and fixes
    failures in `test_write_read_limited_history`.

++++ systemd:

  - Import commit 409c6ef1ea5cd4d11214648aabd34227aa058d79 (merge of v257.10)
    This merge includes the following fix:
    08c1da70de timer: don't run service immediately after restart of a timer (bsc#1254563)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/aba474eeaac455ebe22b643ecdd856e5583094a1...409c6ef1ea5cd4d11214648aabd34227aa058d79
  - Import commit aba474eeaac455ebe22b643ecdd856e5583094a1
    aba474eeaa main: switch explicitly to tty1 on soft-reboot (bsc#1231986)
    a437bf2499 terminal-util: modernize vtnr_from_tty() a bit
    2dbe9f5809 units: don't force the loading of the loop and dm_mod modules in systemd-repart.service (bsc#1248356)

++++ libvirt:

  - CVE-2025-13193: qemu: Set umask for 'qemu-img' when creating
    external inactive snapshots
    bsc#1253703

++++ python313:

  - Add pass-test_write_read_limited_history.patch:
    Fix readline history truncation when length is reduced
    The `readline.set_history_length()` function did not previously
    truncate the in-memory history when the new length was set to
    a value smaller than the current number of history items. This
    could lead to unexpected behavior where `get_history_length()`
    would still report the old length and writing the history to a
    file would write more entries than the new limit.
    This patch modifies `set_history_length()` to explicitly
    remove the oldest history entries using `remove_history()`
    when the length is decreased, ensuring the in-memory history
    is correctly truncated to the new limit. This brings the
    function's behavior in line with expectations and fixes
    failures in `test_write_read_limited_history`.

------------------------------------------------------------------
------------------  2025-11-18  -  Nov 18 2025  -------------------
------------------------------------------------------------------

++++ drbd-utils:

  - [SELinux] nfs_drbd: "fence-peer helper broken, returned 0" and nfs WRITE hang when power off the secondary node (bsc#1252991)
    * Update and rename patch
  - bsc-1233273_drbd.ocf-update-for-OCF-1.1.patch
    + bsc-1233273-1252991_drbd.ocf-update-for-OCF-1.1.patch

++++ kernel-default:

  - kernel-binary: Require libdw in Factory
    Libdw is required for gendwarfksyms
  - commit 0d3f66b
  - drm/ast: Blank with VGACR17 sync enable, always clear VGACRB6
    sync off (git-fixes).
  - commit ec917da
  - ASoC: nau8821: Consistently clear interrupts before unmasking
    (git-fixes).
  - Refresh
    patches.suse/ASoC-nau8821-Add-DMI-quirk-to-bypass-jack-debounce-c.patch.
  - commit 26a2ff0
  - Revert "ACPI: Suppress misleading SPCR console message when
    SPCR table is absent" (stable-fixes).
  - commit d03b19b
  - thunderbolt: Increase DPRX capabilities read timeout
    (git-fixes).
  - commit 555764d
  - thermal/drivers/mediatek/lvts: Disable low offset IRQ for
    minimum threshold (git-fixes).
  - Refresh
    patches.suse/thermal-drivers-mediatek-lvts-Start-sensor-interrupt.patch.
  - commit 3c59e7d
  - tty: serial: ip22zilog: Use platform device for probing
    (stable-fixes).
  - tty: serial: uartlite: register uart driver in init
    (stable-fixes).
  - commit 31331ea
  - wifi: rtw89: avoid possible TX wait initialization race
    (git-fixes).
  - commit 1cf0319
  - PM: EM: Fix late boot with holes in CPU topology (git-fixes).
  - PM: EM: Move CPU capacity check to em_adjust_new_capacity()
    (stable-fixes).
  - PM: EM: Slightly reduce em_check_capacity_update() overhead
    (stable-fixes).
  - PM: EM: Drop unused parameter from em_adjust_new_capacity()
    (stable-fixes).
  - commit e9cac92
  - platform/x86: thinkpad_acpi: Handle KCOV __init vs inline
    mismatches (stable-fixes).
  - commit cbe0445
  - mei: me: add wildcat lake P DID (stable-fixes).
  - pinctrl: check the return value of
    pinmux_ops::get_function_name() (stable-fixes).
  - commit 1b746a1
  - media: mc: Clear minor number before put device (git-fixes).
  - media: verisilicon: Explicitly disable selection api ioctls
    for decoders (stable-fixes).
  - media: nxp: imx8-isi: m2m: Fix streaming cleanup on release
    (git-fixes).
  - commit c31f158
  - kasan: fix GCC mem-intrinsic prefix with sw tags (git-fixes).
  - commit 3652fcf
  - ipmi: Fix handling of messages with provided receive message
    pointer (git-fixes).
  - commit a67a65e
  - ipmi: Rework user message limit handling (git-fixes).
  - Revert "ipmi: fix msg stack when IPMI is disconnected"
    (stable-fixes).
  - commit 15ee836
  - Input: atmel_mxt_ts - allow reset GPIO to sleep (stable-fixes).
  - HID: simplify snto32() (stable-fixes).
  - commit 5536114
  - HID: multitouch: fix sticky fingers (git-fixes).
  - efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
    (git-fixes).
  - commit 7b1353d
  - drm/xe: Do not wake device during a GT reset (git-fixes).
  - drm/exynos: exynos7_drm_decon: remove ctx->suspended
    (git-fixes).
  - drm/msm/a6xx: Fix PDC sleep sequence (git-fixes).
  - commit 5296d1a
  - drm/amdgpu: Fix function header names in amdgpu_connectors.c
    (git-fixes).
  - drm/xe/guc: Add more GuC load error status codes (stable-fixes).
  - drm/amdgpu: Respect max pixel clock for HDMI and DVI-D (v2)
    (stable-fixes).
  - drm/amdgpu: Fix unintended error log in VCN5_0_0 (git-fixes).
  - commit 6c1d83f
  - drm/amdgpu: Check vcn sram load return value (stable-fixes).
  - commit 2a00bb4
  - ASoC: codecs: wcd937x: make stub functions inline (git-fixes).
  - ASoC: codecs: wcd937x: set the comp soundwire port correctly
    (git-fixes).
  - ASoC: rsnd: adjust convert rate limitation (stable-fixes).
  - ASoC: rsnd: don't indicate warning on
    rsnd_kctrl_accept_runtime() (stable-fixes).
  - ASoC: rsnd: indicate unsupported clock rate (stable-fixes).
  - ASoC: renesas: rz-ssi: Add a check for negative sample_space
    (git-fixes).
  - ASoC: renesas: rz-ssi: Use only the proper amount of dividers
    (git-fixes).
  - ASoC: renesas: rz-ssi: Terminate all the DMA transactions
    (git-fixes).
  - commit 8a0b029
  - ALSA: hda/realtek - Add new HP ZBook laptop with micmute led
    fixup (stable-fixes).
  - commit 97a0d09
  - ALSA: hda/realtek: Add support for HP Agusta using CS35L41 HDA
    (stable-fixes).
  - commit 2423cdd
  - ALSA: hda/realtek: Add support for various HP Laptops using
    CS35L41 HDA (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-Apply-volume-control-on-speaker-lineout-for.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-quirk-for-Asus-GU605C.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Fix-built-in-mic-on-ASUS-VivoBook-X.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Support-mute-led-function-for-HP-pl.patch.
  - commit 652c005
  - ALSA: hda/realtek: fix micmute LEDs on HP Laptops with ALC3247
    (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-Apply-volume-control-on-speaker-lineout-for.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Support-mute-led-function-for-HP-pl.patch.
  - commit 431b8c2
  - ALSA: hda/realtek: fix micmute LEDs on HP Laptops with ALC3315
    (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-Apply-volume-control-on-speaker-lineout-for.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-mute-LED-support-for-HP-Victus--ce174b4.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-quirk-for-Asus-GU605C.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Fix-built-in-mic-on-ASUS-VivoBook-X.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Support-mute-led-function-for-HP-pl.patch.
  - commit 4bc4bb8
  - Refresh
    patches.suse/sched-fair-Enable-scheduler-feature-NEXT_BUDDY.patch.
    patches.suse/sched-fair-Reimplement-NEXT_BUDDY-to-align-with-EEVDF-goals.patch.
    Replace out-of-tree patches with upstream
  - commit 05723b9
  - mtd: onenand: Pass correct pointer to IRQ handler (git-fixes).
  - mtd: rawnand: cadence: fix DMA device NULL pointer dereference
    (git-fixes).
  - mtdchar: fix integer overflow in read/write ioctls (git-fixes).
  - commit 9e717e0
  - Update config files: enable zstd module decompression (jsc#PED-14115).
    Enable in-kernel decompression for modules compressed with zstd. This
    allows kmod to load these modules using the finit_module syscall, which
    provides better detection of idempotent modules compared to init_module.
    Additionally, it enables module loading with tools that do not natively
    support zstd decompression, such as busybox.
  - commit f0effe5
  - ring-buffer: Update pages_touched to reflect persistent buffer
    content (git-fixes).
  - commit b413c4a
  - tracing: Have the error of __tracing_resize_ring_buffer()
    passed to user (git-fixes).
  - commit 780aa09
  - ring-buffer: Unlock resize on mmap error (git-fixes).
  - commit cfd3a65
  - tracing: gfp: Fix the GFP enum values shown for user space
    tracing tools (git-fixes).
  - commit 825ad23
  - uprobes: Fix race in uprobe_free_utask (git-fixes).
  - commit 8b6b5fb
  - usb: acpi: fix device link removal (git-fixes).
  - commit 1f93244
  - [PATCH] usb: hub: Fix flushing of delayed work used for post
    resume purposes (git-fixes).
  - commit 0d77330

++++ kernel-firmware-mediatek:

  - Update to version 20251118 (git commit 53dce114cc5d):
    * mt76: add firmware for MT7990
    * mt76: update firmware for MT7992
    * mt76: update firmware for MT7996

++++ kernel-rt:

  - kernel-binary: Require libdw in Factory
    Libdw is required for gendwarfksyms
  - commit 0d3f66b
  - drm/ast: Blank with VGACR17 sync enable, always clear VGACRB6
    sync off (git-fixes).
  - commit ec917da
  - ASoC: nau8821: Consistently clear interrupts before unmasking
    (git-fixes).
  - Refresh
    patches.suse/ASoC-nau8821-Add-DMI-quirk-to-bypass-jack-debounce-c.patch.
  - commit 26a2ff0
  - Revert "ACPI: Suppress misleading SPCR console message when
    SPCR table is absent" (stable-fixes).
  - commit d03b19b
  - thunderbolt: Increase DPRX capabilities read timeout
    (git-fixes).
  - commit 555764d
  - thermal/drivers/mediatek/lvts: Disable low offset IRQ for
    minimum threshold (git-fixes).
  - Refresh
    patches.suse/thermal-drivers-mediatek-lvts-Start-sensor-interrupt.patch.
  - commit 3c59e7d
  - tty: serial: ip22zilog: Use platform device for probing
    (stable-fixes).
  - tty: serial: uartlite: register uart driver in init
    (stable-fixes).
  - commit 31331ea
  - wifi: rtw89: avoid possible TX wait initialization race
    (git-fixes).
  - commit 1cf0319
  - PM: EM: Fix late boot with holes in CPU topology (git-fixes).
  - PM: EM: Move CPU capacity check to em_adjust_new_capacity()
    (stable-fixes).
  - PM: EM: Slightly reduce em_check_capacity_update() overhead
    (stable-fixes).
  - PM: EM: Drop unused parameter from em_adjust_new_capacity()
    (stable-fixes).
  - commit e9cac92
  - platform/x86: thinkpad_acpi: Handle KCOV __init vs inline
    mismatches (stable-fixes).
  - commit cbe0445
  - mei: me: add wildcat lake P DID (stable-fixes).
  - pinctrl: check the return value of
    pinmux_ops::get_function_name() (stable-fixes).
  - commit 1b746a1
  - media: mc: Clear minor number before put device (git-fixes).
  - media: verisilicon: Explicitly disable selection api ioctls
    for decoders (stable-fixes).
  - media: nxp: imx8-isi: m2m: Fix streaming cleanup on release
    (git-fixes).
  - commit c31f158
  - kasan: fix GCC mem-intrinsic prefix with sw tags (git-fixes).
  - commit 3652fcf
  - ipmi: Fix handling of messages with provided receive message
    pointer (git-fixes).
  - commit a67a65e
  - ipmi: Rework user message limit handling (git-fixes).
  - Revert "ipmi: fix msg stack when IPMI is disconnected"
    (stable-fixes).
  - commit 15ee836
  - Input: atmel_mxt_ts - allow reset GPIO to sleep (stable-fixes).
  - HID: simplify snto32() (stable-fixes).
  - commit 5536114
  - HID: multitouch: fix sticky fingers (git-fixes).
  - efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare
    (git-fixes).
  - commit 7b1353d
  - drm/xe: Do not wake device during a GT reset (git-fixes).
  - drm/exynos: exynos7_drm_decon: remove ctx->suspended
    (git-fixes).
  - drm/msm/a6xx: Fix PDC sleep sequence (git-fixes).
  - commit 5296d1a
  - drm/amdgpu: Fix function header names in amdgpu_connectors.c
    (git-fixes).
  - drm/xe/guc: Add more GuC load error status codes (stable-fixes).
  - drm/amdgpu: Respect max pixel clock for HDMI and DVI-D (v2)
    (stable-fixes).
  - drm/amdgpu: Fix unintended error log in VCN5_0_0 (git-fixes).
  - commit 6c1d83f
  - drm/amdgpu: Check vcn sram load return value (stable-fixes).
  - commit 2a00bb4
  - ASoC: codecs: wcd937x: make stub functions inline (git-fixes).
  - ASoC: codecs: wcd937x: set the comp soundwire port correctly
    (git-fixes).
  - ASoC: rsnd: adjust convert rate limitation (stable-fixes).
  - ASoC: rsnd: don't indicate warning on
    rsnd_kctrl_accept_runtime() (stable-fixes).
  - ASoC: rsnd: indicate unsupported clock rate (stable-fixes).
  - ASoC: renesas: rz-ssi: Add a check for negative sample_space
    (git-fixes).
  - ASoC: renesas: rz-ssi: Use only the proper amount of dividers
    (git-fixes).
  - ASoC: renesas: rz-ssi: Terminate all the DMA transactions
    (git-fixes).
  - commit 8a0b029
  - ALSA: hda/realtek - Add new HP ZBook laptop with micmute led
    fixup (stable-fixes).
  - commit 97a0d09
  - ALSA: hda/realtek: Add support for HP Agusta using CS35L41 HDA
    (stable-fixes).
  - commit 2423cdd
  - ALSA: hda/realtek: Add support for various HP Laptops using
    CS35L41 HDA (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-Apply-volume-control-on-speaker-lineout-for.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-quirk-for-Asus-GU605C.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Fix-built-in-mic-on-ASUS-VivoBook-X.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Support-mute-led-function-for-HP-pl.patch.
  - commit 652c005
  - ALSA: hda/realtek: fix micmute LEDs on HP Laptops with ALC3247
    (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-Apply-volume-control-on-speaker-lineout-for.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Support-mute-led-function-for-HP-pl.patch.
  - commit 431b8c2
  - ALSA: hda/realtek: fix micmute LEDs on HP Laptops with ALC3315
    (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-Apply-volume-control-on-speaker-lineout-for.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-mute-LED-support-for-HP-Victus--ce174b4.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-quirk-for-Asus-GU605C.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Fix-built-in-mic-on-ASUS-VivoBook-X.patch.
  - Refresh
    patches.suse/ALSA-hda-realtek-Support-mute-led-function-for-HP-pl.patch.
  - commit 4bc4bb8
  - Refresh
    patches.suse/sched-fair-Enable-scheduler-feature-NEXT_BUDDY.patch.
    patches.suse/sched-fair-Reimplement-NEXT_BUDDY-to-align-with-EEVDF-goals.patch.
    Replace out-of-tree patches with upstream
  - commit 05723b9
  - mtd: onenand: Pass correct pointer to IRQ handler (git-fixes).
  - mtd: rawnand: cadence: fix DMA device NULL pointer dereference
    (git-fixes).
  - mtdchar: fix integer overflow in read/write ioctls (git-fixes).
  - commit 9e717e0
  - Update config files: enable zstd module decompression (jsc#PED-14115).
    Enable in-kernel decompression for modules compressed with zstd. This
    allows kmod to load these modules using the finit_module syscall, which
    provides better detection of idempotent modules compared to init_module.
    Additionally, it enables module loading with tools that do not natively
    support zstd decompression, such as busybox.
  - commit f0effe5
  - ring-buffer: Update pages_touched to reflect persistent buffer
    content (git-fixes).
  - commit b413c4a
  - tracing: Have the error of __tracing_resize_ring_buffer()
    passed to user (git-fixes).
  - commit 780aa09
  - ring-buffer: Unlock resize on mmap error (git-fixes).
  - commit cfd3a65
  - tracing: gfp: Fix the GFP enum values shown for user space
    tracing tools (git-fixes).
  - commit 825ad23
  - uprobes: Fix race in uprobe_free_utask (git-fixes).
  - commit 8b6b5fb
  - usb: acpi: fix device link removal (git-fixes).
  - commit 1f93244
  - [PATCH] usb: hub: Fix flushing of delayed work used for post
    resume purposes (git-fixes).
  - commit 0d77330

++++ libsoup:

  - Add libsoup-CVE-2025-12105.patch: fix use after free caused by
    'finishing' queue item twice (bsc#1252555 CVE-2025-12105
    glgo#GNOME/libsoup!481).
  - Add i586 to the list of architectures where we re-run tests;
    hsts-db-test is timing out there as well.

++++ sssd:

  - Install file in krb5.conf.d to include sssd krb5 config snippets;
    (bsc#1244325);
  - Disable Kerberos localauth an2ln plugin for AD; (CVE-2025-11561);
    (bsc#1251827); Add patch
    0005-krb5-disable-Kerberos-localauth-an2ln-plugin-for-AD-.patch

------------------------------------------------------------------
------------------  2025-11-17  -  Nov 17 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fixed spec file requires
    The package requirement for binutils was set to TW (>=1650)
    only but is also required for SLES16/Leap16 which is 1600
    This commit fixes the condition to match with all required
    distributions and fixes bsc#1253637

++++ kernel-default:

  - cpuidle: Fail cpuidle device registration if there is one
    already (stable-fixes).
  - commit 774b422
  - cpufreq: intel_pstate: Check IDA only before MSR_IA32_PERF_CTL
    writes (stable-fixes).
  - commit 3040a19
  - cpufreq: ti: Add support for AM62D2 (stable-fixes).
  - commit aae5dea
  - net/sched: sch_qfq: Fix null-deref in agg_dequeue
    (CVE-2025-40083 bsc#1252912).
  - commit db525fd
  - RDMA/irdma: Remove unused struct irdma_cq fields (git-fixes)
    Refresh: patches.suse/RDMA-irdma-Set-irdma_cq-cq_num-field-during-CQ-creat.patch
  - commit 2bc40c7
  - usb: hub: Fix flushing of delayed work used for post resume
    purposes (git-fixes).
  - commit 568c0c7
  - sched/fair: Proportional newidle balance -KABI (bsc#1248792).
  - commit 2a30a31
  - mm/secretmem: fix use-after-free race in fault handler
    (git-fixes).
  - commit 80f400e
  - mm/mm_init: fix hash table order logging in
    alloc_large_system_hash() (git-fixes).
  - commit 6277246
  - mm/shmem: fix THP allocation and fallback loop (git-fixes).
  - commit 7df97a5
  - sched/fair: Proportional newidle balance (bsc#1248792).
  - sched/fair: Small cleanup to update_newidle_cost()
    (bsc#1248792).
  - sched/fair: Small cleanup to sched_balance_newidle()
    (bsc#1248792).
  - sched/fair: Revert max_newidle_lb_cost bump (bsc#1248792).
  - commit 002bf3c
  - usb: acpi: fix device link removal (git-fixes).
  - commit 7da3956
  - btrfs: fix COW handling in run_delalloc_nocow() (git-fixes).
  - commit 3658fcf
  - usb: hub: Fix flushing and scheduling of delayed work that
    tunes runtime pm (git-fixes).
  - commit 0e7a64a
  - NFS: Fix LTP test failures when timestamps are delegated
    (git-fixes).
  - commit a27c9b1
  - NFSv4: Fix an incorrect parameter when calling nfs4_call_sync()
    (git-fixes).
  - commit 88b6f1a
  - NFS: sysfs: fix leak when nfs_client kobject add fails
    (git-fixes).
  - commit ba849e7
  - pnfs: Set transport security policy to RPC_XPRTSEC_NONE unless
    using TLS (git-fixes).
  - commit 8f818b2
  - pnfs: Fix TLS logic in _nfs4_pnfs_v4_ds_connect() (git-fixes).
  - commit 3e16694
  - usb: hub: fix detection of high tier USB3 devices behind
    suspended hubs (git-fixes).
  - commit 3b2ca74
  - x86/amd_node: Fix AMD root device caching (git-fixes).
  - commit e237c08
  - Input: atmel_mxt_ts - allow reset GPIO to sleep (git-fixes).
  - commit 5b233b4
  - x86/acpi: Fix LAPIC/x2APIC parsing order (git-fixes).
  - commit a215e89
  - x86/cpu: Add CPU model number for Bartlett Lake CPUs with Raptor Cove  cores (git-fixes).
  - commit 20898eb
  - x86/dumpstack: Fix inaccurate unwinding from exception stacks due to  misplaced assignment (git-fixes).
  - commit bc02028
  - x86/e820: Fix handling of subpage regions when calculating nosave  ranges in e820__register_nosave_regions() (git-fixes).
  - commit 3176c31
  - x86/traps: Initialize DR7 by writing its architectural reset value (git-fixes).
  - commit bd0c543
  - x86/bugs: Fix reporting of LFENCE retpoline (git-fixes).
  - commit 5ec8592
  - x86/bugs: Report correct retbleed mitigation status (git-fixes).
  - commit af3db49
  - x86/fred: Remove ENDBR64 from FRED entry points (git-fixes).
  - commit 25fde52
  - x86/CPU/AMD: Add additional fixed RDSEED microcode revisions (git-fixes).
  - Refresh
    patches.suse/x86-CPU-AMD-Add-missing-terminator-for-zen5_rdseed_m.patch.
  - commit 2043e4b
  - x86/microcode/AMD: Add Zen5 model 0x44, stepping 0x1 minrev (git-fixes).
  - commit 58eb355
  - x86/microcode/AMD: Add more known models to entry sign checking (git-fixes).
  - commit c6f2391
  - x86/microcode: Fix Entrysign revision check for Zen1/Naples (git-fixes).
  - commit 0fef111
  - x86/mm: Ensure clear_page() variants always have __kcfi_typeid_ symbols (git-fixes).
  - commit 8353963
  - x86/vmscape: Add old Intel CPUs to affected list (git-fixes).
  - commit ab22902
  - bpf: Check the helper function is valid in get_helper_proto
    (CVE-2025-39990 bsc#1252054).
  - commit 84dd981
  - xsk: Harden userspace-supplied xdp_desc validation
    (CVE-2025-40159 bsc#1253403).
  - commit bdd6de1

++++ kernel-rt:

  - cpuidle: Fail cpuidle device registration if there is one
    already (stable-fixes).
  - commit 774b422
  - cpufreq: intel_pstate: Check IDA only before MSR_IA32_PERF_CTL
    writes (stable-fixes).
  - commit 3040a19
  - cpufreq: ti: Add support for AM62D2 (stable-fixes).
  - commit aae5dea
  - net/sched: sch_qfq: Fix null-deref in agg_dequeue
    (CVE-2025-40083 bsc#1252912).
  - commit db525fd
  - RDMA/irdma: Remove unused struct irdma_cq fields (git-fixes)
    Refresh: patches.suse/RDMA-irdma-Set-irdma_cq-cq_num-field-during-CQ-creat.patch
  - commit 2bc40c7
  - usb: hub: Fix flushing of delayed work used for post resume
    purposes (git-fixes).
  - commit 568c0c7
  - sched/fair: Proportional newidle balance -KABI (bsc#1248792).
  - commit 2a30a31
  - mm/secretmem: fix use-after-free race in fault handler
    (git-fixes).
  - commit 80f400e
  - mm/mm_init: fix hash table order logging in
    alloc_large_system_hash() (git-fixes).
  - commit 6277246
  - mm/shmem: fix THP allocation and fallback loop (git-fixes).
  - commit 7df97a5
  - sched/fair: Proportional newidle balance (bsc#1248792).
  - sched/fair: Small cleanup to update_newidle_cost()
    (bsc#1248792).
  - sched/fair: Small cleanup to sched_balance_newidle()
    (bsc#1248792).
  - sched/fair: Revert max_newidle_lb_cost bump (bsc#1248792).
  - commit 002bf3c
  - usb: acpi: fix device link removal (git-fixes).
  - commit 7da3956
  - btrfs: fix COW handling in run_delalloc_nocow() (git-fixes).
  - commit 3658fcf
  - usb: hub: Fix flushing and scheduling of delayed work that
    tunes runtime pm (git-fixes).
  - commit 0e7a64a
  - NFS: Fix LTP test failures when timestamps are delegated
    (git-fixes).
  - commit a27c9b1
  - NFSv4: Fix an incorrect parameter when calling nfs4_call_sync()
    (git-fixes).
  - commit 88b6f1a
  - NFS: sysfs: fix leak when nfs_client kobject add fails
    (git-fixes).
  - commit ba849e7
  - pnfs: Set transport security policy to RPC_XPRTSEC_NONE unless
    using TLS (git-fixes).
  - commit 8f818b2
  - pnfs: Fix TLS logic in _nfs4_pnfs_v4_ds_connect() (git-fixes).
  - commit 3e16694
  - usb: hub: fix detection of high tier USB3 devices behind
    suspended hubs (git-fixes).
  - commit 3b2ca74
  - x86/amd_node: Fix AMD root device caching (git-fixes).
  - commit e237c08
  - Input: atmel_mxt_ts - allow reset GPIO to sleep (git-fixes).
  - commit 5b233b4
  - x86/acpi: Fix LAPIC/x2APIC parsing order (git-fixes).
  - commit a215e89
  - x86/cpu: Add CPU model number for Bartlett Lake CPUs with Raptor Cove  cores (git-fixes).
  - commit 20898eb
  - x86/dumpstack: Fix inaccurate unwinding from exception stacks due to  misplaced assignment (git-fixes).
  - commit bc02028
  - x86/e820: Fix handling of subpage regions when calculating nosave  ranges in e820__register_nosave_regions() (git-fixes).
  - commit 3176c31
  - x86/traps: Initialize DR7 by writing its architectural reset value (git-fixes).
  - commit bd0c543
  - x86/bugs: Fix reporting of LFENCE retpoline (git-fixes).
  - commit 5ec8592
  - x86/bugs: Report correct retbleed mitigation status (git-fixes).
  - commit af3db49
  - x86/fred: Remove ENDBR64 from FRED entry points (git-fixes).
  - commit 25fde52
  - x86/CPU/AMD: Add additional fixed RDSEED microcode revisions (git-fixes).
  - Refresh
    patches.suse/x86-CPU-AMD-Add-missing-terminator-for-zen5_rdseed_m.patch.
  - commit 2043e4b
  - x86/microcode/AMD: Add Zen5 model 0x44, stepping 0x1 minrev (git-fixes).
  - commit 58eb355
  - x86/microcode/AMD: Add more known models to entry sign checking (git-fixes).
  - commit c6f2391
  - x86/microcode: Fix Entrysign revision check for Zen1/Naples (git-fixes).
  - commit 0fef111
  - x86/mm: Ensure clear_page() variants always have __kcfi_typeid_ symbols (git-fixes).
  - commit 8353963
  - x86/vmscape: Add old Intel CPUs to affected list (git-fixes).
  - commit ab22902
  - bpf: Check the helper function is valid in get_helper_proto
    (CVE-2025-39990 bsc#1252054).
  - commit 84dd981
  - xsk: Harden userspace-supplied xdp_desc validation
    (CVE-2025-40159 bsc#1253403).
  - commit bdd6de1

------------------------------------------------------------------
------------------  2025-11-15  -  Nov 15 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/vmwgfx: Validate command header size against
    SVGA_CMD_MAX_DATASIZE (git-fixes).
  - drm/amd/display: Allow VRR params change if unsynced with the
    stream (git-fixes).
  - mmc: dw_mmc-rockchip: Fix wrong internal phase calculate
    (git-fixes).
  - mmc: sdhci-of-dwcmshc: Change DLL_STRBIN_TAPNUM_DEFAULT to 0x4
    (git-fixes).
  - acpi/hmat: Fix lockdep warning for hmem_register_resource()
    (git-fixes).
  - acpi,srat: Fix incorrect device handle check for Generic
    Initiator (git-fixes).
  - spi: Try to get ACPI GPIO IRQ earlier (git-fixes).
  - regulator: fixed: fix GPIO descriptor leak on register failure
    (git-fixes).
  - ASoC: tas2781: fix getting the wrong device number (git-fixes).
  - ASoC: codecs: va-macro: fix resource leak in probe error path
    (git-fixes).
  - ASoC: cs4271: Fix regulator leak on probe failure (git-fixes).
  - ALSA: usb-audio: Fix NULL pointer dereference in
    snd_usb_mixer_controls_badd (git-fixes).
  - crypto: hisilicon/qm - Fix device reference leak in
    qm_get_qos_value (git-fixes).
  - commit f615b8d

++++ kernel-rt:

  - drm/vmwgfx: Validate command header size against
    SVGA_CMD_MAX_DATASIZE (git-fixes).
  - drm/amd/display: Allow VRR params change if unsynced with the
    stream (git-fixes).
  - mmc: dw_mmc-rockchip: Fix wrong internal phase calculate
    (git-fixes).
  - mmc: sdhci-of-dwcmshc: Change DLL_STRBIN_TAPNUM_DEFAULT to 0x4
    (git-fixes).
  - acpi/hmat: Fix lockdep warning for hmem_register_resource()
    (git-fixes).
  - acpi,srat: Fix incorrect device handle check for Generic
    Initiator (git-fixes).
  - spi: Try to get ACPI GPIO IRQ earlier (git-fixes).
  - regulator: fixed: fix GPIO descriptor leak on register failure
    (git-fixes).
  - ASoC: tas2781: fix getting the wrong device number (git-fixes).
  - ASoC: codecs: va-macro: fix resource leak in probe error path
    (git-fixes).
  - ASoC: cs4271: Fix regulator leak on probe failure (git-fixes).
  - ALSA: usb-audio: Fix NULL pointer dereference in
    snd_usb_mixer_controls_badd (git-fixes).
  - crypto: hisilicon/qm - Fix device reference leak in
    qm_get_qos_value (git-fixes).
  - commit f615b8d

++++ libvirt:

  - spec: Adjust dbus dependency
    bsc#1253642
  - CVE-2025-12748: Check ACLs before parsing the whole domain XML
    bsc#1253278

------------------------------------------------------------------
------------------  2025-11-14  -  Nov 14 2025  -------------------
------------------------------------------------------------------

++++ drbd-utils:

  - Allow domtrans from kernel_t to drbd_t (bsc#1252991)
    * add patch
  - 1252991-selinux-domtrans-from-kernel.patch

++++ kernel-default:

  - kernel-binary: Do not change debuginfo config during build
    Historically when debuginfo build was disabled in OBS kernel was
    configured to not generate the debuginfo at all saving space during
    build and making the build faster.
    More and more kernel features depend on debuginfo, and disabling it
    changes the kernel significantly disabling functionality that is
    otherwise available and causing ABI breakage.
    Recently genksyms was rewritten as gendwarfksyms to support more
    features but requires debuginfo to operate. With that kernel builds
    without deuginfo are not very useful anymore. Even if rpm eventually
    trashes the debuginfo it needs to be always generated.
  - commit 4fc8f91
  - bpf/selftests: Fix test_tcpnotify_user (bsc#1253635).
  - commit 9374c78
  - drm/amd/display: Reject modes with too high pixel clock on
    DCE6-10 (git-fixes).
  - commit 5c1955e
  - PM: hibernate: Use atomic64_t for compressed_size variable
    (git-fixes).
  - PM: hibernate: Emit an error when image writing fails
    (git-fixes).
  - wifi: mwl8k: inject DSSS Parameter Set element into beacons
    if missing (git-fixes).
  - wifi: mac80211: skip rate verification for not captured PSDUs
    (git-fixes).
  - wifi: ath11k: zero init info->status in
    wmi_process_mgmt_tx_comp() (git-fixes).
  - wifi: mac80211: reject address change while connecting
    (git-fixes).
  - strparser: Fix signed/unsigned mismatch bug (git-fixes).
  - tools: ynl: fix string attribute length to include null
    terminator (git-fixes).
  - wifi: mac80211: fix key tailroom accounting leak (git-fixes).
  - wifi: ath11k: avoid bit operation on key flags (git-fixes).
  - USB: serial: option: add UNISOC UIS7720 (stable-fixes).
  - usb/core/quirks: Add Huawei ME906S to wakeup quirk
    (stable-fixes).
  - usb: raw-gadget: do not limit transfer length (git-fixes).
  - usb: xhci-pci: Fix USB2-only root hub registration (git-fixes).
  - rtc: pcf2127: fix watchdog interrupt mask on pcf2131
    (stable-fixes).
  - rtc: pcf2127: clear minute/second interrupt (stable-fixes).
  - tools bitmap: Add missing asm-generic/bitsperlong.h include
    (stable-fixes).
  - tools: lib: thermal: don't preserve owner in install
    (stable-fixes).
  - tools: lib: thermal: use pkg-config to locate libnl3
    (stable-fixes).
  - watchdog: s3c2410_wdt: Fix max_timeout being calculated larger
    (stable-fixes).
  - PCI: cadence: Check for the existence of cdns_pcie::ops before
    using it (stable-fixes).
  - phy: rockchip: phy-rockchip-inno-csidphy: allow writes to grf
    register 0 (stable-fixes).
  - phy: cadence: cdns-dphy: Enable lower resolutions in dphy
    (stable-fixes).
  - phy: renesas: r8a779f0-ether-serdes: add new step added to
    latest datasheet (stable-fixes).
  - thunderbolt: Use is_pciehp instead of is_hotplug_bridge
    (stable-fixes).
  - usb: xhci-pci: add support for hosts with zero USB3 ports
    (stable-fixes).
  - usb: gadget: f_fs: Fix epfile null pointer access after ep
    enable (stable-fixes).
  - usb: mon: Increase BUFF_MAX to 64 MiB to support multi-MB URBs
    (stable-fixes).
  - usb: xhci: plat: Facilitate using autosuspend for xhci plat
    devices (stable-fixes).
  - usb: cdns3: gadget: Use-after-free during failed initialization
    and exit of cdnsp gadget (stable-fixes).
  - usb: gadget: f_hid: Fix zero length packet transfer
    (stable-fixes).
  - usb: gadget: f_ncm: Fix MAC assignment NCM ethernet
    (stable-fixes).
  - tty/vt: Add missing return value for VT_RESIZE in vt_ioctl()
    (stable-fixes).
  - tty: serial: Modify the use of dev_err_probe() (stable-fixes).
  - platform/x86/intel-uncore-freq: Fix warning in partitioned
    system (stable-fixes).
  - wifi: ath12k: Increase DP_REO_CMD_RING_SIZE to 256
    (stable-fixes).
  - wifi: ath10k: Fix connection after GTK rekeying (stable-fixes).
  - wifi: rtw89: renew a completion for each H2C command waiting
    C2H event (stable-fixes).
  - wifi: rtw89: obtain RX path from ppdu status IE00
    (stable-fixes).
  - wifi: rtw89: fix BSSID comparison for non-transmitted BSSID
    (stable-fixes).
  - wifi: rtw89: wow: remove notify during WoWLAN net-detect
    (stable-fixes).
  - wifi: rtw89: print just once for unknown C2H events
    (stable-fixes).
  - wifi: rtw88: sdio: use indirect IO for device registers before
    power-on (stable-fixes).
  - wifi: mac80211: Track NAN interface start/stop (stable-fixes).
  - wifi: mt76: mt7996: fix memory leak on mt7996_mcu_sta_key_tlv
    error (stable-fixes).
  - wifi: mt76: mt76_eeprom_override to int (stable-fixes).
  - wifi: mt76: mt7996: Temporarily disable EPCS (stable-fixes).
  - wifi: mt76: mt7921: Add 160MHz beamformee capability for mt7922
    device (stable-fixes).
  - r8169: set EEE speed down ratio to 1 (stable-fixes).
  - wifi: iwlwifi: fw: Add ASUS to PPAG and TAS list (stable-fixes).
  - wifi: mac80211: Fix HE capabilities element check
    (stable-fixes).
  - wifi: mac80211: Fix 6 GHz Band capabilities element
    advertisement in lower bands (stable-fixes).
  - smsc911x: add second read of EEPROM mac when possible corruption
    seen (stable-fixes).
  - soc: ti: pruss: don't use %pK through printk (stable-fixes).
  - soc/tegra: fuse: Add Tegra114 nvmem cells and fuse lookups
    (stable-fixes).
  - soc: qcom: smem: Fix endian-unaware access of num_entries
    (stable-fixes).
  - soc: aspeed: socinfo: Add AST27xx silicon IDs (stable-fixes).
  - thermal: intel: selftests: workload_hint: Mask unsupported types
    (stable-fixes).
  - thermal: gov_step_wise: Allow cooling level to be reduced
    earlier (stable-fixes).
  - tools/cpupower: Fix incorrect size in cpuidle_state_disable()
    (stable-fixes).
  - tools/cpupower: fix error return value in cpupower_write_sysfs()
    (stable-fixes).
  - tools/power x86_energy_perf_policy: Prefer driver HWP limits
    (stable-fixes).
  - tools/power x86_energy_perf_policy: Enhance HWP enable
    (stable-fixes).
  - tools/power x86_energy_perf_policy: Fix incorrect fopen mode
    usage (stable-fixes).
  - pinctrl: keembay: release allocated memory in detach path
    (stable-fixes).
  - pinctrl: single: fix bias pull up/down handling in
    pin_config_set (stable-fixes).
  - power: supply: qcom_battmgr: handle charging state change
    notifications (stable-fixes).
  - power: supply: sbs-charger: Support multiple devices
    (stable-fixes).
  - power: supply: qcom_battmgr: add OOI chemistry (stable-fixes).
  - video: backlight: lp855x_bl: Set correct EPROM start for LP8556
    (stable-fixes).
  - spi: rpc-if: Add resume support for RZ/G3E (stable-fixes).
  - spi: loopback-test: Don't use %pK through printk (stable-fixes).
  - pwm: pca9685: Use bulk write to atomicially update registers
    (stable-fixes).
  - wifi: mac80211: don't mark keys for inactive links as uploaded
    (stable-fixes).
  - wifi: ath11k: add support for MU EDCA (stable-fixes).
  - commit 0ec6ab7
  - net: wwan: t7xx: add support for HP DRMR-H01 (stable-fixes).
  - PCI: imx6: Enable the Vaux supply if available (stable-fixes).
  - PCI: dwc: Verify the single eDMA IRQ in
    dw_pcie_edma_irq_verify() (stable-fixes).
  - PCI: endpoint: pci-epf-test: Limit PCIe BAR size for fixed BARs
    (stable-fixes).
  - PCI/PM: Skip resuming to D0 if device is disconnected
    (stable-fixes).
  - PCI/P2PDMA: Fix incorrect pointer usage in devm_kfree() call
    (stable-fixes).
  - PCI: Disable MSI on RDC PCI to PCIe bridges (stable-fixes).
  - PCI/ERR: Update device error_state already after reset
    (stable-fixes).
  - net: phy: clear link parameters on admin link down
    (stable-fixes).
  - net: phy: marvell: Fix 88e1510 downshift counter errata
    (stable-fixes).
  - net: phy: fixed_phy: let fixed_phy_unregister free the
    phy_device (stable-fixes).
  - mfd: intel-lpss: Add Intel Wildcat Lake LPSS PCI IDs
    (stable-fixes).
  - mfd: core: Increment of_node's refcount before linking it to
    the platform device (stable-fixes).
  - mfd: madera: Work around false-positive -Wininitialized warning
    (stable-fixes).
  - mfd: da9063: Split chip variant reading in two bus transactions
    (stable-fixes).
  - mfd: kempld: Switch back to earlier ->init() behavior
    (stable-fixes).
  - mfd: stmpe-i2c: Add missing MODULE_LICENSE (stable-fixes).
  - mfd: stmpe: Remove IRQ domain upon removal (stable-fixes).
  - mmc: sdhci-msm: Enable tuning for SDR50 mode for SD card
    (stable-fixes).
  - mmc: host: renesas_sdhi: Fix the actual clock (stable-fixes).
  - commit a9ec390
  - kunit: test_dev_action: Correctly cast 'priv' pointer to long*
    (git-fixes).
  - ima: don't clear IMA_DIGSIG flag when setting or removing
    non-IMA xattr (stable-fixes).
  - iio: adc: imx93_adc: load calibrated values even calibration
    failed (stable-fixes).
  - iio: adc: spear_adc: mask SPEAR_ADC_STATUS channel and avg
    sample before setting register (stable-fixes).
  - media: redrat3: use int type to store negative error codes
    (stable-fixes).
  - media: ov08x40: Fix the horizontal flip control (stable-fixes).
  - media: i2c: og01a1b: Specify monochrome media bus format
    instead of Bayer (stable-fixes).
  - media: adv7180: Only validate format in querystd (stable-fixes).
  - media: adv7180: Do not write format to device in set_fmt
    (stable-fixes).
  - media: adv7180: Add missing lock in suspend callback
    (stable-fixes).
  - media: pci: mgb4: Fix timings comparison in VIDIOC_S_DV_TIMINGS
    (stable-fixes).
  - media: fix uninitialized symbol warnings (stable-fixes).
  - media: ipu6: isys: Set embedded data type correctly for metadata
    formats (stable-fixes).
  - media: imon: make send_packet() more robust (stable-fixes).
  - media: i2c: Kconfig: Ensure a dependency on HAVE_CLK for
    VIDEO_CAMERA_SENSOR (stable-fixes).
  - media: amphion: Delete v4l2_fh synchronously in .release()
    (stable-fixes).
  - i3c: mipi-i3c-hci-pci: Add support for Intel Wildcat Lake-U I3C
    (stable-fixes).
  - memstick: Add timeout to prevent indefinite waiting
    (stable-fixes).
  - hwmon: (asus-ec-sensors) increase timeout for locking ACPI mutex
    (stable-fixes).
  - commit 539916e
  - fbcon: Set fb_display[i]->mode to NULL when the mode is released
    (stable-fixes).
  - fbdev: bitblit: bound-check glyph index in bit_putcs*
    (stable-fixes).
  - fbdev: pvr2fb: Fix leftover reference to ONCHIP_NR_DMA_CHANNELS
    (stable-fixes).
  - fbdev: Add bounds checking in bit_putcs to fix
    vmalloc-out-of-bounds (stable-fixes).
  - extcon: adc-jack: Cleanup wakeup source only if it was enabled
    (git-fixes).
  - extcon: adc-jack: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - HID: pidff: PERMISSIVE_CONTROL quirk autodetection
    (stable-fixes).
  - HID: pidff: Use direction fix only for conditional effects
    (stable-fixes).
  - HID: asus: add Z13 folio to generic group for multitouch to work
    (stable-fixes).
  - Fix access to video_is_primary_device() when compiled without
    CONFIG_VIDEO (stable-fixes).
  - firmware: qcom: tzmem: disable sc7180 platform (stable-fixes).
  - firmware: qcom: scm: preserve assign_mem() error return value
    (stable-fixes).
  - firewire: ohci: move self_id_complete tracepoint after
    validating register (stable-fixes).
  - hwmon: (dell-smm) Remove Dell Precision 490 custom config data
    (stable-fixes).
  - hwmon: sy7636a: add alias (stable-fixes).
  - hwmon: (sbtsi_temp) AMD CPU extended temperature range support
    (stable-fixes).
  - hwmon: (lenovo-ec-sensors) Update P8 supprt (stable-fixes).
  - hwmon: (k10temp) Add device ID for Strix Halo (stable-fixes).
  - hwmon: (k10temp) Add thermal support for AMD Family 1Ah-based
    models (stable-fixes).
  - commit 666e545
  - drm/amd/display: Disable VRR on DCE 6 (stable-fixes).
  - commit b765989
  - drm/amdgpu/smu: Handle S0ix for vangogh (stable-fixes).
  - drm/amd/display: Fix black screen with HDMI outputs (git-fixes).
  - drm/sched: avoid killing parent entity on child SIGKILL
    (stable-fixes).
  - drm/amd/display: Fix incorrect return of vblank enable on
    unconfigured crtc (stable-fixes).
  - drm/amd: Check that VPE has reached DPM0 in idle handler
    (stable-fixes).
  - drm/amd/display: change dc stream color settings only in atomic
    commit (stable-fixes).
  - drm/amd/display: update color on atomic commit time
    (stable-fixes).
  - drm/amd/display: Fix for test crash due to power gating
    (stable-fixes).
  - drm/amd/display: Init dispclk from bootup clock for DCN314
    (stable-fixes).
  - drm/amd/display: Add AVI infoframe copy in
    copy_stream_update_to_stream (stable-fixes).
  - drm/amdgpu/atom: Check kcalloc() for WS buffer in
    amdgpu_atom_execute_table_locked() (stable-fixes).
  - drm/amdgpu: reject gang submissions under SRIOV (stable-fixes).
  - drm/amd/display/dml2: Guard
    dml21_map_dc_state_into_dml_display_cfg with DC_FP_START
    (stable-fixes).
  - drm/amd/display: Fix DVI-D/HDMI adapters (stable-fixes).
  - drm/amd/display: Add fallback path for YCBCR422 (stable-fixes).
  - drm/amd/display: Set up pixel encoding for YCBCR422
    (stable-fixes).
  - drm/amd/display: fix dml ms order of operations (stable-fixes).
  - drm/amdgpu: Use memdup_array_user in amdgpu_cs_wait_fences_ioctl
    (stable-fixes).
  - drm/xe/guc: Return an error code if the GuC load fails
    (stable-fixes).
  - drm/xe/guc: Set upper limit of H2G retries over CTB
    (stable-fixes).
  - drm/xe/guc: Increase GuC crash dump buffer size (stable-fixes).
  - drm/msm/registers: Generate _HI/LO builders for reg64
    (stable-fixes).
  - drm/msm: make sure to not queue up recovery more than once
    (stable-fixes).
  - drm/msm/dsi/phy_7nm: Fix missing initial VCO rate
    (stable-fixes).
  - drm/msm/dsi/phy: Toggle back buffer resync after preparing PLL
    (stable-fixes).
  - drm/amd/display: Fix pbn_div Calculation Error (stable-fixes).
  - drm/amdgpu: don't enable SMU on cyan skillfish (stable-fixes).
  - commit a6576e9
  - drm/amdgpu: add support for cyan skillfish gpu_info
    (stable-fixes).
  - drm/amd: add more cyan skillfish PCI ids (stable-fixes).
  - drm/amdgpu: Allow kfd CRIU with no buffer objects
    (stable-fixes).
  - drm: panel-backlight-quirks: Make EDID match optional
    (stable-fixes).
  - drm/panthor: check bo offset alignment in vm bind
    (stable-fixes).
  - drm/xe: Fix oops in xe_gem_fault when running core_hotunplug
    test (stable-fixes).
  - drm/amd/display: incorrect conditions for failing dto
    calculations (stable-fixes).
  - drm/amd/display: Increase minimum clock for TMDS 420 with pipe
    splitting (stable-fixes).
  - drm/amd/display: Support HW cursor 180 rot for any number of
    pipe splits (stable-fixes).
  - drm/amdkfd: Tie UNMAP_LATENCY to queue_preemption
    (stable-fixes).
  - drm/amdkfd: fix vram allocation failure for a special case
    (stable-fixes).
  - drm/amdgpu: Correct the counts of nr_banks and nr_errors
    (stable-fixes).
  - drm/amdkfd: Handle lack of READ permissions in SVM mapping
    (stable-fixes).
  - drm/amdgpu: fix nullptr err of vm_handle_moved (stable-fixes).
  - drm/amdkfd: return -ENOTTY for unsupported IOCTLs
    (stable-fixes).
  - drm/amd/display: Reset apply_eamless_boot_optimization when
    dpms_off (stable-fixes).
  - drm/amd/display: Wait until OTG enable state is cleared
    (stable-fixes).
  - drm/amdgpu/jpeg: Hold pg_lock before jpeg poweroff
    (stable-fixes).
  - drm/amd/pm: Use cached metrics data on arcturus (stable-fixes).
  - drm/amd/pm: Use cached metrics data on aldebaran (stable-fixes).
  - drm/amd/display: update dpp/disp clock from smu clock table
    (stable-fixes).
  - drm/amdgpu: Skip poison aca bank from UE channel (stable-fixes).
  - drm/amd/display: add more cyan skillfish devices (stable-fixes).
  - drm/amd/amdgpu: Release xcp drm memory after unplug
    (stable-fixes).
  - drm/amd/display: Increase AUX Intra-Hop Done Max Wait Duration
    (stable-fixes).
  - drm/amd/display: Move setup_stream_attribute (stable-fixes).
  - drm/amdgpu: add range check for RAS bad page address
    (stable-fixes).
  - drm/amd/display: ensure committing streams is seamless
    (stable-fixes).
  - drm/amd/display: fix condition for setting timing_adjust_pending
    (stable-fixes).
  - drm/bridge: display-connector: don't set OP_DETECT for
    DisplayPorts (stable-fixes).
  - commit 6369e4e
  - dmaengine: dw-edma: Set status for callback_result
    (stable-fixes).
  - dmaengine: mv_xor: match alloc_wc and free_wc (stable-fixes).
  - drm/panthor: Serialize GPU cache flush operations
    (stable-fixes).
  - drm/tidss: Set crtc modesetting parameters with adjusted mode
    (stable-fixes).
  - drm/bridge: cdns-dsi: Don't fail on MIPI_DSI_MODE_VIDEO_BURST
    (stable-fixes).
  - drm/bridge: cdns-dsi: Fix REG_WAKEUP_TIME value (stable-fixes).
  - drm/tidss: Use the crtc_* timings when programming the HW
    (stable-fixes).
  - drm/nouveau: replace snprintf() with scnprintf() in
    nvkm_snprintbf() (stable-fixes).
  - drm/sched: Optimise drm_sched_entity_push_job (stable-fixes).
  - commit 088581e
  - char: Use list_del_init() in misc_deregister() to reinitialize
    list pointer (stable-fixes).
  - char: misc: Does not request module for miscdevice with dynamic
    minor (stable-fixes).
  - crypto: hisilicon/qm - clear all VF configurations in the
    hardware (stable-fixes).
  - crypto: hisilicon/qm - invalidate queues in use (stable-fixes).
  - crypto: caam - double the entropy delay interval for retry
    (stable-fixes).
  - crypto: ccp - Fix incorrect payload size calculation in
    psp_poulate_hsti() (stable-fixes).
  - crypto: qat - use kcalloc() in qat_uclo_map_objs_from_mof()
    (stable-fixes).
  - commit 88c75e8
  - ACPI: CPPC: Limit perf ctrs in PCC check only to online CPUs
    (git-fixes).
  - ACPI: CPPC: Perform fast check switch only for online CPUs
    (git-fixes).
  - ACPI: CPPC: Check _CPC validity for only the online CPUs
    (git-fixes).
  - ACPI: CPPC: Detect preferred core availability on online CPUs
    (git-fixes).
  - Bluetooth: 6lowpan: add missing l2cap_chan_lock() (git-fixes).
  - Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions
    (git-fixes).
  - Bluetooth: L2CAP: export l2cap_chan_hold for modules
    (stable-fixes).
  - Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type
    confusion (git-fixes).
  - Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
    (git-fixes).
  - Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid
    UAF (git-fixes).
  - Bluetooth: MGMT: cancel mesh send timer when hdev removed
    (git-fixes).
  - ALSA: usb-audio: don't log messages meant for 1810c when
    initializing 1824c (git-fixes).
  - ACPI: fan: Use platform device for devres-related actions
    (git-fixes).
  - ACPI: fan: Use ACPI handle when retrieving _FST (stable-fixes).
  - ACPI: SPCR: Check for table version when using precise baudrate
    (git-fixes).
  - ASoC: meson: aiu-encoder-i2s: fix bit clock polarity
    (stable-fixes).
  - ACPI: property: Return present device nodes only on fwnode
    interface (stable-fixes).
  - bus: mhi: core: Improve mhi_sync_power_up handling for SYS_ERR
    state (stable-fixes).
  - char: misc: Make misc_register() reentry for miscdevice who
    wants dynamic minor (stable-fixes).
  - ACPI: scan: Update honor list for RPMI System MSI
    (stable-fixes).
  - Bluetooth: SCO: Fix UAF on sco_conn_free (stable-fixes).
  - Bluetooth: bcsp: receive data only if registered (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3633 for MT7922
    (stable-fixes).
  - Bluetooth: btusb: Check for unexpected bytes when defragmenting
    HCI frames (stable-fixes).
  - amd/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw
    (stable-fixes).
  - accel/habanalabs/gaudi2: read preboot status after recovering
    from dirty state (stable-fixes).
  - accel/habanalabs: support mapping cb with vmalloc-backed
    coherent memory (stable-fixes).
  - accel/habanalabs/gaudi2: fix BMON disable configuration
    (stable-fixes).
  - accel/habanalabs: return ENOMEM if less than requested pages
    were pinned (stable-fixes).
  - ASoC: tlv320aic3x: Fix class-D initialization for tlv320aic3007
    (stable-fixes).
  - ASoC: stm32: sai: manage context in set_sysclk callback
    (stable-fixes).
  - ALSA: usb-audio: add mono main switch to Presonus S1824c
    (stable-fixes).
  - ASoC: qcom: sc8280xp: explicitly set S16LE format in
    sc8280xp_be_hw_params_fixup() (stable-fixes).
  - ASoC: SOF: ipc4-pcm: Add fixup for channels (stable-fixes).
  - ASoC: mediatek: Use SND_JACK_AVOUT for HDMI/DP jacks
    (stable-fixes).
  - ALSA: serial-generic: remove shared static buffer
    (stable-fixes).
  - ALSA: usb-audio: apply quirk for MOONDROP Quark2 (stable-fixes).
  - ALSA: usb-audio: Add validation of UAC2/UAC3 effect units
    (stable-fixes).
  - ACPI: PRM: Skip handlers with NULL handler_address or NULL VA
    (stable-fixes).
  - ACPI: video: force native for Lenovo 82K8 (stable-fixes).
  - ACPI: SPCR: Support Precise Baud Rate field (stable-fixes).
  - ACPI: resource: Skip IRQ override on ASUS Vivobook Pro N6506CU
    (stable-fixes).
  - ACPI: sysfs: Use ACPI_FREE() for freeing an ACPI object
    (stable-fixes).
  - ACPI: scan: Add Intel CVS ACPI HIDs to acpi_ignore_dep_ids[]
    (stable-fixes).
  - ACPICA: Update dsmethod.c to get rid of unused variable warning
    (stable-fixes).
  - ACPICA: dispatcher: Use acpi_ds_clear_operands() in
    acpi_ds_call_control_method() (stable-fixes).
  - char: misc: restrict the dynamic range to exclude reserved
    minors (stable-fixes).
  - ACPI: fan: Add fan speed reporting for fans with only _FST
    (stable-fixes).
  - commit f52da15
  - erofs: avoid infinite loop due to incomplete zstd-compressed
    data (git-fixes).
  - commit 7b42d7d
  - exfat: validate cluster allocation bits of the allocation bitmap
    (git-fixes).
  - commit f4032b9
  - exfat: limit log print for IO error (git-fixes).
  - commit 1405b08
  - nfs4_setup_readdir(): insufficient locking for
  - >d_parent->d_inode dereferencing (git-fixes).
  - commit 589935f
  - NFSv4.1: fix mount hang after CREATE_SESSION failure
    (git-fixes).
  - commit 76c7f5a
  - NFSv4: handle ERR_GRACE on delegation recalls (git-fixes).
  - commit cc6039d
  - IB/ipoib: Ignore L3 master device (git-fixes)
  - commit 117d08f
  - btrfs: ensure no dirty metadata is written back for an fs with
    errors (git-fix).
  - commit 17770b9
  - io_uring/kbuf: fix signedness in this_len calculation
    (CVE-2025-39822 bsc#1250034).
  - Update patches.suse/io_uring-kbuf-always-use-READ_ONCE-to-read-ring-prov.patch
  - commit 40a2039
  - io_uring/waitid: always prune wait queue entry in
    io_waitid_wait() (CVE-2025-40047 bsc#1252790).
  - commit 17b3d49
  - io_uring/net: mark iov as dynamically allocated even for single
    segments (git-fixes).
  - commit d6cddb7

++++ kernel-rt:

  - kernel-binary: Do not change debuginfo config during build
    Historically when debuginfo build was disabled in OBS kernel was
    configured to not generate the debuginfo at all saving space during
    build and making the build faster.
    More and more kernel features depend on debuginfo, and disabling it
    changes the kernel significantly disabling functionality that is
    otherwise available and causing ABI breakage.
    Recently genksyms was rewritten as gendwarfksyms to support more
    features but requires debuginfo to operate. With that kernel builds
    without deuginfo are not very useful anymore. Even if rpm eventually
    trashes the debuginfo it needs to be always generated.
  - commit 4fc8f91
  - bpf/selftests: Fix test_tcpnotify_user (bsc#1253635).
  - commit 9374c78
  - drm/amd/display: Reject modes with too high pixel clock on
    DCE6-10 (git-fixes).
  - commit 5c1955e
  - PM: hibernate: Use atomic64_t for compressed_size variable
    (git-fixes).
  - PM: hibernate: Emit an error when image writing fails
    (git-fixes).
  - wifi: mwl8k: inject DSSS Parameter Set element into beacons
    if missing (git-fixes).
  - wifi: mac80211: skip rate verification for not captured PSDUs
    (git-fixes).
  - wifi: ath11k: zero init info->status in
    wmi_process_mgmt_tx_comp() (git-fixes).
  - wifi: mac80211: reject address change while connecting
    (git-fixes).
  - strparser: Fix signed/unsigned mismatch bug (git-fixes).
  - tools: ynl: fix string attribute length to include null
    terminator (git-fixes).
  - wifi: mac80211: fix key tailroom accounting leak (git-fixes).
  - wifi: ath11k: avoid bit operation on key flags (git-fixes).
  - USB: serial: option: add UNISOC UIS7720 (stable-fixes).
  - usb/core/quirks: Add Huawei ME906S to wakeup quirk
    (stable-fixes).
  - usb: raw-gadget: do not limit transfer length (git-fixes).
  - usb: xhci-pci: Fix USB2-only root hub registration (git-fixes).
  - rtc: pcf2127: fix watchdog interrupt mask on pcf2131
    (stable-fixes).
  - rtc: pcf2127: clear minute/second interrupt (stable-fixes).
  - tools bitmap: Add missing asm-generic/bitsperlong.h include
    (stable-fixes).
  - tools: lib: thermal: don't preserve owner in install
    (stable-fixes).
  - tools: lib: thermal: use pkg-config to locate libnl3
    (stable-fixes).
  - watchdog: s3c2410_wdt: Fix max_timeout being calculated larger
    (stable-fixes).
  - PCI: cadence: Check for the existence of cdns_pcie::ops before
    using it (stable-fixes).
  - phy: rockchip: phy-rockchip-inno-csidphy: allow writes to grf
    register 0 (stable-fixes).
  - phy: cadence: cdns-dphy: Enable lower resolutions in dphy
    (stable-fixes).
  - phy: renesas: r8a779f0-ether-serdes: add new step added to
    latest datasheet (stable-fixes).
  - thunderbolt: Use is_pciehp instead of is_hotplug_bridge
    (stable-fixes).
  - usb: xhci-pci: add support for hosts with zero USB3 ports
    (stable-fixes).
  - usb: gadget: f_fs: Fix epfile null pointer access after ep
    enable (stable-fixes).
  - usb: mon: Increase BUFF_MAX to 64 MiB to support multi-MB URBs
    (stable-fixes).
  - usb: xhci: plat: Facilitate using autosuspend for xhci plat
    devices (stable-fixes).
  - usb: cdns3: gadget: Use-after-free during failed initialization
    and exit of cdnsp gadget (stable-fixes).
  - usb: gadget: f_hid: Fix zero length packet transfer
    (stable-fixes).
  - usb: gadget: f_ncm: Fix MAC assignment NCM ethernet
    (stable-fixes).
  - tty/vt: Add missing return value for VT_RESIZE in vt_ioctl()
    (stable-fixes).
  - tty: serial: Modify the use of dev_err_probe() (stable-fixes).
  - platform/x86/intel-uncore-freq: Fix warning in partitioned
    system (stable-fixes).
  - wifi: ath12k: Increase DP_REO_CMD_RING_SIZE to 256
    (stable-fixes).
  - wifi: ath10k: Fix connection after GTK rekeying (stable-fixes).
  - wifi: rtw89: renew a completion for each H2C command waiting
    C2H event (stable-fixes).
  - wifi: rtw89: obtain RX path from ppdu status IE00
    (stable-fixes).
  - wifi: rtw89: fix BSSID comparison for non-transmitted BSSID
    (stable-fixes).
  - wifi: rtw89: wow: remove notify during WoWLAN net-detect
    (stable-fixes).
  - wifi: rtw89: print just once for unknown C2H events
    (stable-fixes).
  - wifi: rtw88: sdio: use indirect IO for device registers before
    power-on (stable-fixes).
  - wifi: mac80211: Track NAN interface start/stop (stable-fixes).
  - wifi: mt76: mt7996: fix memory leak on mt7996_mcu_sta_key_tlv
    error (stable-fixes).
  - wifi: mt76: mt76_eeprom_override to int (stable-fixes).
  - wifi: mt76: mt7996: Temporarily disable EPCS (stable-fixes).
  - wifi: mt76: mt7921: Add 160MHz beamformee capability for mt7922
    device (stable-fixes).
  - r8169: set EEE speed down ratio to 1 (stable-fixes).
  - wifi: iwlwifi: fw: Add ASUS to PPAG and TAS list (stable-fixes).
  - wifi: mac80211: Fix HE capabilities element check
    (stable-fixes).
  - wifi: mac80211: Fix 6 GHz Band capabilities element
    advertisement in lower bands (stable-fixes).
  - smsc911x: add second read of EEPROM mac when possible corruption
    seen (stable-fixes).
  - soc: ti: pruss: don't use %pK through printk (stable-fixes).
  - soc/tegra: fuse: Add Tegra114 nvmem cells and fuse lookups
    (stable-fixes).
  - soc: qcom: smem: Fix endian-unaware access of num_entries
    (stable-fixes).
  - soc: aspeed: socinfo: Add AST27xx silicon IDs (stable-fixes).
  - thermal: intel: selftests: workload_hint: Mask unsupported types
    (stable-fixes).
  - thermal: gov_step_wise: Allow cooling level to be reduced
    earlier (stable-fixes).
  - tools/cpupower: Fix incorrect size in cpuidle_state_disable()
    (stable-fixes).
  - tools/cpupower: fix error return value in cpupower_write_sysfs()
    (stable-fixes).
  - tools/power x86_energy_perf_policy: Prefer driver HWP limits
    (stable-fixes).
  - tools/power x86_energy_perf_policy: Enhance HWP enable
    (stable-fixes).
  - tools/power x86_energy_perf_policy: Fix incorrect fopen mode
    usage (stable-fixes).
  - pinctrl: keembay: release allocated memory in detach path
    (stable-fixes).
  - pinctrl: single: fix bias pull up/down handling in
    pin_config_set (stable-fixes).
  - power: supply: qcom_battmgr: handle charging state change
    notifications (stable-fixes).
  - power: supply: sbs-charger: Support multiple devices
    (stable-fixes).
  - power: supply: qcom_battmgr: add OOI chemistry (stable-fixes).
  - video: backlight: lp855x_bl: Set correct EPROM start for LP8556
    (stable-fixes).
  - spi: rpc-if: Add resume support for RZ/G3E (stable-fixes).
  - spi: loopback-test: Don't use %pK through printk (stable-fixes).
  - pwm: pca9685: Use bulk write to atomicially update registers
    (stable-fixes).
  - wifi: mac80211: don't mark keys for inactive links as uploaded
    (stable-fixes).
  - wifi: ath11k: add support for MU EDCA (stable-fixes).
  - commit 0ec6ab7
  - net: wwan: t7xx: add support for HP DRMR-H01 (stable-fixes).
  - PCI: imx6: Enable the Vaux supply if available (stable-fixes).
  - PCI: dwc: Verify the single eDMA IRQ in
    dw_pcie_edma_irq_verify() (stable-fixes).
  - PCI: endpoint: pci-epf-test: Limit PCIe BAR size for fixed BARs
    (stable-fixes).
  - PCI/PM: Skip resuming to D0 if device is disconnected
    (stable-fixes).
  - PCI/P2PDMA: Fix incorrect pointer usage in devm_kfree() call
    (stable-fixes).
  - PCI: Disable MSI on RDC PCI to PCIe bridges (stable-fixes).
  - PCI/ERR: Update device error_state already after reset
    (stable-fixes).
  - net: phy: clear link parameters on admin link down
    (stable-fixes).
  - net: phy: marvell: Fix 88e1510 downshift counter errata
    (stable-fixes).
  - net: phy: fixed_phy: let fixed_phy_unregister free the
    phy_device (stable-fixes).
  - mfd: intel-lpss: Add Intel Wildcat Lake LPSS PCI IDs
    (stable-fixes).
  - mfd: core: Increment of_node's refcount before linking it to
    the platform device (stable-fixes).
  - mfd: madera: Work around false-positive -Wininitialized warning
    (stable-fixes).
  - mfd: da9063: Split chip variant reading in two bus transactions
    (stable-fixes).
  - mfd: kempld: Switch back to earlier ->init() behavior
    (stable-fixes).
  - mfd: stmpe-i2c: Add missing MODULE_LICENSE (stable-fixes).
  - mfd: stmpe: Remove IRQ domain upon removal (stable-fixes).
  - mmc: sdhci-msm: Enable tuning for SDR50 mode for SD card
    (stable-fixes).
  - mmc: host: renesas_sdhi: Fix the actual clock (stable-fixes).
  - commit a9ec390
  - kunit: test_dev_action: Correctly cast 'priv' pointer to long*
    (git-fixes).
  - ima: don't clear IMA_DIGSIG flag when setting or removing
    non-IMA xattr (stable-fixes).
  - iio: adc: imx93_adc: load calibrated values even calibration
    failed (stable-fixes).
  - iio: adc: spear_adc: mask SPEAR_ADC_STATUS channel and avg
    sample before setting register (stable-fixes).
  - media: redrat3: use int type to store negative error codes
    (stable-fixes).
  - media: ov08x40: Fix the horizontal flip control (stable-fixes).
  - media: i2c: og01a1b: Specify monochrome media bus format
    instead of Bayer (stable-fixes).
  - media: adv7180: Only validate format in querystd (stable-fixes).
  - media: adv7180: Do not write format to device in set_fmt
    (stable-fixes).
  - media: adv7180: Add missing lock in suspend callback
    (stable-fixes).
  - media: pci: mgb4: Fix timings comparison in VIDIOC_S_DV_TIMINGS
    (stable-fixes).
  - media: fix uninitialized symbol warnings (stable-fixes).
  - media: ipu6: isys: Set embedded data type correctly for metadata
    formats (stable-fixes).
  - media: imon: make send_packet() more robust (stable-fixes).
  - media: i2c: Kconfig: Ensure a dependency on HAVE_CLK for
    VIDEO_CAMERA_SENSOR (stable-fixes).
  - media: amphion: Delete v4l2_fh synchronously in .release()
    (stable-fixes).
  - i3c: mipi-i3c-hci-pci: Add support for Intel Wildcat Lake-U I3C
    (stable-fixes).
  - memstick: Add timeout to prevent indefinite waiting
    (stable-fixes).
  - hwmon: (asus-ec-sensors) increase timeout for locking ACPI mutex
    (stable-fixes).
  - commit 539916e
  - fbcon: Set fb_display[i]->mode to NULL when the mode is released
    (stable-fixes).
  - fbdev: bitblit: bound-check glyph index in bit_putcs*
    (stable-fixes).
  - fbdev: pvr2fb: Fix leftover reference to ONCHIP_NR_DMA_CHANNELS
    (stable-fixes).
  - fbdev: Add bounds checking in bit_putcs to fix
    vmalloc-out-of-bounds (stable-fixes).
  - extcon: adc-jack: Cleanup wakeup source only if it was enabled
    (git-fixes).
  - extcon: adc-jack: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - HID: pidff: PERMISSIVE_CONTROL quirk autodetection
    (stable-fixes).
  - HID: pidff: Use direction fix only for conditional effects
    (stable-fixes).
  - HID: asus: add Z13 folio to generic group for multitouch to work
    (stable-fixes).
  - Fix access to video_is_primary_device() when compiled without
    CONFIG_VIDEO (stable-fixes).
  - firmware: qcom: tzmem: disable sc7180 platform (stable-fixes).
  - firmware: qcom: scm: preserve assign_mem() error return value
    (stable-fixes).
  - firewire: ohci: move self_id_complete tracepoint after
    validating register (stable-fixes).
  - hwmon: (dell-smm) Remove Dell Precision 490 custom config data
    (stable-fixes).
  - hwmon: sy7636a: add alias (stable-fixes).
  - hwmon: (sbtsi_temp) AMD CPU extended temperature range support
    (stable-fixes).
  - hwmon: (lenovo-ec-sensors) Update P8 supprt (stable-fixes).
  - hwmon: (k10temp) Add device ID for Strix Halo (stable-fixes).
  - hwmon: (k10temp) Add thermal support for AMD Family 1Ah-based
    models (stable-fixes).
  - commit 666e545
  - drm/amd/display: Disable VRR on DCE 6 (stable-fixes).
  - commit b765989
  - drm/amdgpu/smu: Handle S0ix for vangogh (stable-fixes).
  - drm/amd/display: Fix black screen with HDMI outputs (git-fixes).
  - drm/sched: avoid killing parent entity on child SIGKILL
    (stable-fixes).
  - drm/amd/display: Fix incorrect return of vblank enable on
    unconfigured crtc (stable-fixes).
  - drm/amd: Check that VPE has reached DPM0 in idle handler
    (stable-fixes).
  - drm/amd/display: change dc stream color settings only in atomic
    commit (stable-fixes).
  - drm/amd/display: update color on atomic commit time
    (stable-fixes).
  - drm/amd/display: Fix for test crash due to power gating
    (stable-fixes).
  - drm/amd/display: Init dispclk from bootup clock for DCN314
    (stable-fixes).
  - drm/amd/display: Add AVI infoframe copy in
    copy_stream_update_to_stream (stable-fixes).
  - drm/amdgpu/atom: Check kcalloc() for WS buffer in
    amdgpu_atom_execute_table_locked() (stable-fixes).
  - drm/amdgpu: reject gang submissions under SRIOV (stable-fixes).
  - drm/amd/display/dml2: Guard
    dml21_map_dc_state_into_dml_display_cfg with DC_FP_START
    (stable-fixes).
  - drm/amd/display: Fix DVI-D/HDMI adapters (stable-fixes).
  - drm/amd/display: Add fallback path for YCBCR422 (stable-fixes).
  - drm/amd/display: Set up pixel encoding for YCBCR422
    (stable-fixes).
  - drm/amd/display: fix dml ms order of operations (stable-fixes).
  - drm/amdgpu: Use memdup_array_user in amdgpu_cs_wait_fences_ioctl
    (stable-fixes).
  - drm/xe/guc: Return an error code if the GuC load fails
    (stable-fixes).
  - drm/xe/guc: Set upper limit of H2G retries over CTB
    (stable-fixes).
  - drm/xe/guc: Increase GuC crash dump buffer size (stable-fixes).
  - drm/msm/registers: Generate _HI/LO builders for reg64
    (stable-fixes).
  - drm/msm: make sure to not queue up recovery more than once
    (stable-fixes).
  - drm/msm/dsi/phy_7nm: Fix missing initial VCO rate
    (stable-fixes).
  - drm/msm/dsi/phy: Toggle back buffer resync after preparing PLL
    (stable-fixes).
  - drm/amd/display: Fix pbn_div Calculation Error (stable-fixes).
  - drm/amdgpu: don't enable SMU on cyan skillfish (stable-fixes).
  - commit a6576e9
  - drm/amdgpu: add support for cyan skillfish gpu_info
    (stable-fixes).
  - drm/amd: add more cyan skillfish PCI ids (stable-fixes).
  - drm/amdgpu: Allow kfd CRIU with no buffer objects
    (stable-fixes).
  - drm: panel-backlight-quirks: Make EDID match optional
    (stable-fixes).
  - drm/panthor: check bo offset alignment in vm bind
    (stable-fixes).
  - drm/xe: Fix oops in xe_gem_fault when running core_hotunplug
    test (stable-fixes).
  - drm/amd/display: incorrect conditions for failing dto
    calculations (stable-fixes).
  - drm/amd/display: Increase minimum clock for TMDS 420 with pipe
    splitting (stable-fixes).
  - drm/amd/display: Support HW cursor 180 rot for any number of
    pipe splits (stable-fixes).
  - drm/amdkfd: Tie UNMAP_LATENCY to queue_preemption
    (stable-fixes).
  - drm/amdkfd: fix vram allocation failure for a special case
    (stable-fixes).
  - drm/amdgpu: Correct the counts of nr_banks and nr_errors
    (stable-fixes).
  - drm/amdkfd: Handle lack of READ permissions in SVM mapping
    (stable-fixes).
  - drm/amdgpu: fix nullptr err of vm_handle_moved (stable-fixes).
  - drm/amdkfd: return -ENOTTY for unsupported IOCTLs
    (stable-fixes).
  - drm/amd/display: Reset apply_eamless_boot_optimization when
    dpms_off (stable-fixes).
  - drm/amd/display: Wait until OTG enable state is cleared
    (stable-fixes).
  - drm/amdgpu/jpeg: Hold pg_lock before jpeg poweroff
    (stable-fixes).
  - drm/amd/pm: Use cached metrics data on arcturus (stable-fixes).
  - drm/amd/pm: Use cached metrics data on aldebaran (stable-fixes).
  - drm/amd/display: update dpp/disp clock from smu clock table
    (stable-fixes).
  - drm/amdgpu: Skip poison aca bank from UE channel (stable-fixes).
  - drm/amd/display: add more cyan skillfish devices (stable-fixes).
  - drm/amd/amdgpu: Release xcp drm memory after unplug
    (stable-fixes).
  - drm/amd/display: Increase AUX Intra-Hop Done Max Wait Duration
    (stable-fixes).
  - drm/amd/display: Move setup_stream_attribute (stable-fixes).
  - drm/amdgpu: add range check for RAS bad page address
    (stable-fixes).
  - drm/amd/display: ensure committing streams is seamless
    (stable-fixes).
  - drm/amd/display: fix condition for setting timing_adjust_pending
    (stable-fixes).
  - drm/bridge: display-connector: don't set OP_DETECT for
    DisplayPorts (stable-fixes).
  - commit 6369e4e
  - dmaengine: dw-edma: Set status for callback_result
    (stable-fixes).
  - dmaengine: mv_xor: match alloc_wc and free_wc (stable-fixes).
  - drm/panthor: Serialize GPU cache flush operations
    (stable-fixes).
  - drm/tidss: Set crtc modesetting parameters with adjusted mode
    (stable-fixes).
  - drm/bridge: cdns-dsi: Don't fail on MIPI_DSI_MODE_VIDEO_BURST
    (stable-fixes).
  - drm/bridge: cdns-dsi: Fix REG_WAKEUP_TIME value (stable-fixes).
  - drm/tidss: Use the crtc_* timings when programming the HW
    (stable-fixes).
  - drm/nouveau: replace snprintf() with scnprintf() in
    nvkm_snprintbf() (stable-fixes).
  - drm/sched: Optimise drm_sched_entity_push_job (stable-fixes).
  - commit 088581e
  - char: Use list_del_init() in misc_deregister() to reinitialize
    list pointer (stable-fixes).
  - char: misc: Does not request module for miscdevice with dynamic
    minor (stable-fixes).
  - crypto: hisilicon/qm - clear all VF configurations in the
    hardware (stable-fixes).
  - crypto: hisilicon/qm - invalidate queues in use (stable-fixes).
  - crypto: caam - double the entropy delay interval for retry
    (stable-fixes).
  - crypto: ccp - Fix incorrect payload size calculation in
    psp_poulate_hsti() (stable-fixes).
  - crypto: qat - use kcalloc() in qat_uclo_map_objs_from_mof()
    (stable-fixes).
  - commit 88c75e8
  - ACPI: CPPC: Limit perf ctrs in PCC check only to online CPUs
    (git-fixes).
  - ACPI: CPPC: Perform fast check switch only for online CPUs
    (git-fixes).
  - ACPI: CPPC: Check _CPC validity for only the online CPUs
    (git-fixes).
  - ACPI: CPPC: Detect preferred core availability on online CPUs
    (git-fixes).
  - Bluetooth: 6lowpan: add missing l2cap_chan_lock() (git-fixes).
  - Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions
    (git-fixes).
  - Bluetooth: L2CAP: export l2cap_chan_hold for modules
    (stable-fixes).
  - Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type
    confusion (git-fixes).
  - Bluetooth: 6lowpan: reset link-local header on ipv6 recv path
    (git-fixes).
  - Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid
    UAF (git-fixes).
  - Bluetooth: MGMT: cancel mesh send timer when hdev removed
    (git-fixes).
  - ALSA: usb-audio: don't log messages meant for 1810c when
    initializing 1824c (git-fixes).
  - ACPI: fan: Use platform device for devres-related actions
    (git-fixes).
  - ACPI: fan: Use ACPI handle when retrieving _FST (stable-fixes).
  - ACPI: SPCR: Check for table version when using precise baudrate
    (git-fixes).
  - ASoC: meson: aiu-encoder-i2s: fix bit clock polarity
    (stable-fixes).
  - ACPI: property: Return present device nodes only on fwnode
    interface (stable-fixes).
  - bus: mhi: core: Improve mhi_sync_power_up handling for SYS_ERR
    state (stable-fixes).
  - char: misc: Make misc_register() reentry for miscdevice who
    wants dynamic minor (stable-fixes).
  - ACPI: scan: Update honor list for RPMI System MSI
    (stable-fixes).
  - Bluetooth: SCO: Fix UAF on sco_conn_free (stable-fixes).
  - Bluetooth: bcsp: receive data only if registered (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3633 for MT7922
    (stable-fixes).
  - Bluetooth: btusb: Check for unexpected bytes when defragmenting
    HCI frames (stable-fixes).
  - amd/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw
    (stable-fixes).
  - accel/habanalabs/gaudi2: read preboot status after recovering
    from dirty state (stable-fixes).
  - accel/habanalabs: support mapping cb with vmalloc-backed
    coherent memory (stable-fixes).
  - accel/habanalabs/gaudi2: fix BMON disable configuration
    (stable-fixes).
  - accel/habanalabs: return ENOMEM if less than requested pages
    were pinned (stable-fixes).
  - ASoC: tlv320aic3x: Fix class-D initialization for tlv320aic3007
    (stable-fixes).
  - ASoC: stm32: sai: manage context in set_sysclk callback
    (stable-fixes).
  - ALSA: usb-audio: add mono main switch to Presonus S1824c
    (stable-fixes).
  - ASoC: qcom: sc8280xp: explicitly set S16LE format in
    sc8280xp_be_hw_params_fixup() (stable-fixes).
  - ASoC: SOF: ipc4-pcm: Add fixup for channels (stable-fixes).
  - ASoC: mediatek: Use SND_JACK_AVOUT for HDMI/DP jacks
    (stable-fixes).
  - ALSA: serial-generic: remove shared static buffer
    (stable-fixes).
  - ALSA: usb-audio: apply quirk for MOONDROP Quark2 (stable-fixes).
  - ALSA: usb-audio: Add validation of UAC2/UAC3 effect units
    (stable-fixes).
  - ACPI: PRM: Skip handlers with NULL handler_address or NULL VA
    (stable-fixes).
  - ACPI: video: force native for Lenovo 82K8 (stable-fixes).
  - ACPI: SPCR: Support Precise Baud Rate field (stable-fixes).
  - ACPI: resource: Skip IRQ override on ASUS Vivobook Pro N6506CU
    (stable-fixes).
  - ACPI: sysfs: Use ACPI_FREE() for freeing an ACPI object
    (stable-fixes).
  - ACPI: scan: Add Intel CVS ACPI HIDs to acpi_ignore_dep_ids[]
    (stable-fixes).
  - ACPICA: Update dsmethod.c to get rid of unused variable warning
    (stable-fixes).
  - ACPICA: dispatcher: Use acpi_ds_clear_operands() in
    acpi_ds_call_control_method() (stable-fixes).
  - char: misc: restrict the dynamic range to exclude reserved
    minors (stable-fixes).
  - ACPI: fan: Add fan speed reporting for fans with only _FST
    (stable-fixes).
  - commit f52da15
  - erofs: avoid infinite loop due to incomplete zstd-compressed
    data (git-fixes).
  - commit 7b42d7d
  - exfat: validate cluster allocation bits of the allocation bitmap
    (git-fixes).
  - commit f4032b9
  - exfat: limit log print for IO error (git-fixes).
  - commit 1405b08
  - nfs4_setup_readdir(): insufficient locking for
  - >d_parent->d_inode dereferencing (git-fixes).
  - commit 589935f
  - NFSv4.1: fix mount hang after CREATE_SESSION failure
    (git-fixes).
  - commit 76c7f5a
  - NFSv4: handle ERR_GRACE on delegation recalls (git-fixes).
  - commit cc6039d
  - IB/ipoib: Ignore L3 master device (git-fixes)
  - commit 117d08f
  - btrfs: ensure no dirty metadata is written back for an fs with
    errors (git-fix).
  - commit 17770b9
  - io_uring/kbuf: fix signedness in this_len calculation
    (CVE-2025-39822 bsc#1250034).
  - Update patches.suse/io_uring-kbuf-always-use-READ_ONCE-to-read-ring-prov.patch
  - commit 40a2039
  - io_uring/waitid: always prune wait queue entry in
    io_waitid_wait() (CVE-2025-40047 bsc#1252790).
  - commit 17b3d49
  - io_uring/net: mark iov as dynamically allocated even for single
    segments (git-fixes).
  - commit d6cddb7

++++ ucode-amd:

  - Update to version 20251113 (git commit fb0dbcd30118):
    * linux-firmware: Update AMD cpu microcode

------------------------------------------------------------------
------------------  2025-11-13  -  Nov 13 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update to 351
    * Changes since 349
  - 351
    * Firewall ports can be deleted individually
  - 350
    * networking: fix renaming of bridges and other groups (RHEL-117883)
    * bridge: fix OpenSSH_10.2p1 host key detection

++++ cockpit-machines:

  - Update to 344
    * 344
  - Port forwarding for user session VMs
  - "Shutdown and restart" action
  - Faster startup
    * 343
  - Memory usage now shows numbers reported by the guest (RHEL-116731)

++++ cockpit-podman:

  - Update to 117
    * 117
  - Performance and stability improvements
    * 116
  - Support stopping/starting/restart quadlets

++++ kernel-default:

  - io_uring/net: fix sendzc double notif flush (git-fixes).
  - commit 39ada15
  - bpf: make sure skb->len != 0 when redirecting to a tunneling device (CVE-2022-50253 bsc#1249912)
  - commit f8c850b
  - net: xilinx: axienet: Add error handling for RX metadata pointer retrieval (CVE-2025-39897 bsc#1250746)
  - commit 7a69552
  - net: xilinx: axienet: Fix RX skb ring management in DMAengine mode (bsc#1250746)
  - commit 3b07625
  - net: xilinx: axienet: Fix Tx skb circular buffer occupancy check in dmaengine xmit (bsc#1250746)
  - commit f3dd19b
  - net: xilinx: axienet: Fix IRQ coalescing packet count overflow (bsc#1250746)
  - commit 342b7c5
  - NFSD: Never cache a COMPOUND when the SEQUENCE operation fails
    (git-fixes).
  - commit 9760aee
  - NFSD: Skip close replay processing if XDR encoding fails
    (git-fixes).
  - commit c1a2a70
  - NFSD: free copynotify stateid in nfs4_free_ol_stateid()
    (git-fixes).
  - commit 402584f
  - nfsd: add missing FATTR4_WORD2_CLONE_BLKSIZE from supported
    attributes (git-fixes).
  - commit 5236ad9
  - nfsd: fix refcount leak in nfsd_set_fh_dentry() (git-fixes).
  - commit 958cf9b

++++ kernel-rt:

  - io_uring/net: fix sendzc double notif flush (git-fixes).
  - commit 39ada15
  - bpf: make sure skb->len != 0 when redirecting to a tunneling device (CVE-2022-50253 bsc#1249912)
  - commit f8c850b
  - net: xilinx: axienet: Add error handling for RX metadata pointer retrieval (CVE-2025-39897 bsc#1250746)
  - commit 7a69552
  - net: xilinx: axienet: Fix RX skb ring management in DMAengine mode (bsc#1250746)
  - commit 3b07625
  - net: xilinx: axienet: Fix Tx skb circular buffer occupancy check in dmaengine xmit (bsc#1250746)
  - commit f3dd19b
  - net: xilinx: axienet: Fix IRQ coalescing packet count overflow (bsc#1250746)
  - commit 342b7c5
  - NFSD: Never cache a COMPOUND when the SEQUENCE operation fails
    (git-fixes).
  - commit 9760aee
  - NFSD: Skip close replay processing if XDR encoding fails
    (git-fixes).
  - commit c1a2a70
  - NFSD: free copynotify stateid in nfs4_free_ol_stateid()
    (git-fixes).
  - commit 402584f
  - nfsd: add missing FATTR4_WORD2_CLONE_BLKSIZE from supported
    attributes (git-fixes).
  - commit 5236ad9
  - nfsd: fix refcount leak in nfsd_set_fh_dentry() (git-fixes).
  - commit 958cf9b

++++ python313-core:

  - Add CVE-2025-6075-expandvars-perf-degrad.patch avoid simple
    quadratic complexity vulnerabilities of os.path.expandvars()
    (CVE-2025-6075, bsc#1252974).

++++ linux-glibc-devel:

  - Sync with SL-16.0 update kernel (6.12.0-160000.6) (bsc#1253334)

++++ nvidia-open-driver-G06-signed:

  - introduced extra %gfx_aarch64_version and appropriate
    tarball/pci_id file in the hope that build service will no
    longer complain
  - update CUDA variant to 580.105.08

++++ python313:

  - Add CVE-2025-6075-expandvars-perf-degrad.patch avoid simple
    quadratic complexity vulnerabilities of os.path.expandvars()
    (CVE-2025-6075, bsc#1252974).

++++ salt:

  - Require Python dependencies only for used Python version

------------------------------------------------------------------
------------------  2025-11-12  -  Nov 12 2025  -------------------
------------------------------------------------------------------

++++ grub2:

  - Fix CVE-2025-54771 (bsc#1252931)
    * 0001-kern-file-Call-grub_dl_unref-after-fs-fs_close.patch
  - Fix CVE-2025-54770 (bsc#1252930)
    * 0002-net-net-Unregister-net_set_vlan-command-on-unload.patch
  - Fix CVE-2025-61662 (bsc#1252933)
    * 0003-gettext-gettext-Unregister-gettext-command-on-module.patch
  - Fix CVE-2025-61663 (bsc#1252934)
  - Fix CVE-2025-61664 (bsc#1252935)
    * 0004-normal-main-Unregister-commands-on-module-unload.patch
    * 0005-tests-lib-functional_test-Unregister-commands-on-mod.patch
  - Fix CVE-2025-61661 (bsc#1252932)
    * 0006-commands-usbtest-Use-correct-string-length-field.patch
    * 0007-commands-usbtest-Ensure-string-length-is-sufficient-.patch
  - Bump upstream SBAT generation to 6

++++ kernel-default:

  - Rename kABI-fix-for-struct-devlink_port_attrs-move-new-memb.patch
    Use the name of the patch being fixed.
  - commit 6298d1e
  - btrfs: release root after error in
    data_reloc_print_warning_inode() (git-fixes).
  - commit c634c60
  - btrfs: scrub: put bio after errors in
    scrub_raid56_parity_stripe() (git-fixes).
  - commit 9ef6fe3
  - btrfs: do not update last_log_commit when logging inode due
    to a new name (git-fixes).
  - commit da7f4a2
  - Refresh patches.suse/devlink-let-driver-opt-out-of-automatic-phys_port_na.patch.
    Use the upstream patch as is. Don't drop the hunk adding no_phys_port_name
  - Refresh patches.kabi/kABI-fix-for-struct-devlink_port_attrs-move-new-memb.patch
    No need to add a new member. Use the existing bit-field
  - commit 623c177

++++ kernel-firmware-bluetooth:

  - Update to version 20251111 (git commit 6fc940781a01):
    * rtl_bt: Update RTL8922A BT USB firmware to 0x41C0_C905

++++ kernel-rt:

  - Rename kABI-fix-for-struct-devlink_port_attrs-move-new-memb.patch
    Use the name of the patch being fixed.
  - commit 6298d1e
  - btrfs: release root after error in
    data_reloc_print_warning_inode() (git-fixes).
  - commit c634c60
  - btrfs: scrub: put bio after errors in
    scrub_raid56_parity_stripe() (git-fixes).
  - commit 9ef6fe3
  - btrfs: do not update last_log_commit when logging inode due
    to a new name (git-fixes).
  - commit da7f4a2
  - Refresh patches.suse/devlink-let-driver-opt-out-of-automatic-phys_port_na.patch.
    Use the upstream patch as is. Don't drop the hunk adding no_phys_port_name
  - Refresh patches.kabi/kABI-fix-for-struct-devlink_port_attrs-move-new-memb.patch
    No need to add a new member. Use the existing bit-field
  - commit 623c177

++++ mozilla-nspr:

  - update to NSPR 4.36.2
    * Fixed a syntax error in test file parsetm.c,
    which was introduced in 4.36.1
  - update to NSPR 4.36.1
    * Incorrect time value produced by PR_ParseTimeString and
    PR_ParseTimeStringToExplodedTime if input string doesn't
    specify seconds.

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20251111 release (bsc#1253319)
  - Update for functional issues.
    New Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | GNR-D          | B0/B1    | 06-ae-01/97 |          | 01000273 | Xeon 6700P-B/6500P-B Series SoC with P-Cores
    Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ADL            | C0       | 06-97-02/07 | 0000003a | 0000003d | Core Gen12
    | ADL            | H0       | 06-97-05/07 | 0000003a | 0000003d | Core Gen12
    | ADL            | L0       | 06-9a-03/80 | 00000437 | 0000043a | Core Gen12
    | ADL            | R0       | 06-9a-04/80 | 00000437 | 0000043a | Core Gen12
    | ADL-N          | N0       | 06-be-00/19 | 0000001d | 0000001e | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    | ARL-H          | A1       | 06-c5-02/82 | 00000119 | 0000011a | Core Ultra Processor (Series 2)
    | ARL-S/HX (8P)  | B0       | 06-c6-02/82 | 00000119 | 0000011a | Core Ultra Processor (Series 2)
    | AZB            | A0/R0    | 06-9a-04/40 | 0000000a | 0000000b | Atom C1100
    | EMR-SP         | A1       | 06-cf-02/87 | 210002b3 | 210002c0 | Xeon Scalable Gen5
    | GNR-AP/SP      | Bx/Hx/Lx | 06-ad-01/95 | 010003d0 | 010003f0 | Xeon 6900-6700/6500-Series Processors with P-Cores
    | GNR-SP R1S     | Bx/Hx/Lx | 06-ad-01/20 | 0a000100 | 0a000124 | Xeon 6700/6500-Series Processors with P-Cores
    | LNL            | B0       | 06-bd-01/80 | 00000123 | 00000125 | Core Ultra 200 V Series Processor
    | RPL-E/HX/S     | B0       | 06-b7-01/32 | 0000012f | 00000132 | Core Gen13/Gen14
    | RPL-H/P/PX 6+8 | J0       | 06-ba-02/e0 | 00004129 | 00006133 | Core Gen13
    | RPL-HX/S       | C0       | 06-bf-02/07 | 0000003a | 0000003d | Core Gen13/Gen14
    | RPL-S          | H0       | 06-bf-05/07 | 0000003a | 0000003d | Core Gen13/Gen14
    | RPL-U 2+8      | Q0       | 06-ba-03/e0 | 00004129 | 00006133 | Core Gen13
    | SPR-HBM        | Bx       | 06-8f-08/10 | 2c000401 | 2c000410 | Xeon Max
    | SPR-SP         | E4/S2    | 06-8f-07/87 | 2b000643 | 2b000650 | Xeon Scalable Gen4
    | SPR-SP         | E5/S3    | 06-8f-08/87 | 2b000643 | 2b000650 | Xeon Scalable Gen4
    | SRF-AP/SP      | C0       | 06-af-03/01 | 03000362 | 03000382 | Xeon 6900/6700-Series Processors with E-Cores
    | TWL            | N0       | 06-be-00/19 | 0000001d | 0000001e | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E

------------------------------------------------------------------
------------------  2025-11-11  -  Nov 11 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20251111.509a363:
    * Avoid escape sequences on dump terminal of s390
  - Update to version 84.87+git20251111.16d9d43:
    * Set XDG environment variables consistently without trailing slash

++++ cloud-init:

  - Fix dependency replace -serial with -pyserial

++++ crypto-policies:

  - Fix the testsuite:
    * Port all the policy changes to the config files in the test suite.
    * Use the newly introduced SKIP_LINTING=1 option.
    * Rebase crypto-policies-Allow-openssl-other-policies-in-FIPS-mode.patch

++++ fwupd:

  - Do not try to load i2c_dev kernel module on s390x. S390x has no
    native i2c devices and does not have the module (bsc#1253138).

++++ kernel-default:

  - Rename to
    patches.kabi/kabi-fix-dm-fix-dm_blk_report_zones.patch.
  - commit 911b752
  - KVM: SEV: Validate XCR0 provided by guest in GHCB (git-fixes).
  - commit 7df395e
  - KVM: SEV: Read save fields from GHCB exactly once (git-fixes).
  - commit 035bf6d
  - KVM: SEV: Rename kvm_ghcb_get_sw_exit_code() to
    kvm_get_cached_sw_exit_code() (git-fixes).
  - commit fb01ff1
  - KVM: SEV: Enforce minimum GHCB version requirement for SEV-SNP
    guests (git-fixes).
  - commit 924cf52
  - KVM: TDX: Do not retry locally when the retry is caused by
    invalid memslot (git-fixes).
  - commit 1ee08a7
  - KVM: x86/mmu: Return -EAGAIN if userspace deletes/moves memslot
    during prefault (git-fixes).
  - commit ebc80d5
  - KVM: x86: Have all vendor neutral sub-configs depend on KVM_X86,
    not just KVM (git-fixes).
  - commit 77fc3c5
  - KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC
    is active (git-fixes).
  - commit b1ea66f
  - KVM: SVM: Pass through GHCB MSR if and only if VM is an SEV-ES
    guest (git-fixes).
  - commit a848ce9
  - Refresh
    patches.suse/drm-amd-display-Default-IPS-to-RCG_IN_ACTIVE_IPS2_IN.patch.
  - Refresh
    patches.suse/drm-amdgpu-discovery-fix-fw-based-ip-discovery.patch.
  - Refresh
    patches.suse/drm-i915-dp-Fix-2.7-Gbps-DP_LINK_BW-value-on-g4x.patch.
  - Refresh
    patches.suse/drm-xe-Allow-dropping-kunit-dependency-as-built-in.patch.
  - Refresh
    patches.suse/drm-xe-Carve-out-wopcm-portion-from-the-stolen-memor.patch.
  - Refresh
    patches.suse/drm-xe-Ensure-fixed_slice_mode-gets-set-after-ccs_mo.patch.
  - Refresh
    patches.suse/drm-xe-Move-page-fault-init-after-topology-init.patch.
  - Refresh patches.suse/drm-xe-bmg-Update-Wa_22019338487.patch.
  - Refresh
    patches.suse/drm-xe-gsc-do-not-flush-the-GSC-worker-from-the-rese.patch.
  - Refresh
    patches.suse/drm-xe-guc_submit-fix-race-around-pending_disable.patch.
  - commit ce19d99
  - io_uring/rsrc: don't rely on user vaddr alignment (git-fixes).
  - io_uring: make fallocate be hashed work (git-fixes).
  - commit 4b7f18b
  - io_uring: fix task leak issue in io_wq_create() (git-fixes).
  - io_uring/kbuf: don't truncate end buffer for multiple buffer
    peeks (git-fixes).
  - commit 6eac1e4
  - io_uring/kbuf: account ring io_buffer_list memory (git-fixes).
  - commit f9b2eed
  - io_uring: account drain memory to cgroup (git-fixes).
  - io_uring: fix overflow resched cqe reordering (git-fixes).
  - commit 14d2bfa
  - io_uring: ensure deferred completions are flushed for multishot
    (git-fixes).
  - commit 9ec928d
  - io_uring/fdinfo: annotate racy sq/cq head/tail reads
    (git-fixes).
  - io_uring: fix 'sync' handling of io_fallback_tw() (git-fixes).
  - commit c501028
  - io_uring: don't duplicate flushing in io_req_post_cqe
    (git-fixes).
  - io_uring/kbuf: reject zero sized provided buffers (git-fixes).
  - commit add5ee3
  - io_uring/msg: initialise msg request opcode (git-fixes).
  - commit 78239f9
  - io_uring/net: account memory for zc sendmsg (git-fixes).
  - commit 1a819c2
  - io_uring/net: fix accept multishot handling (git-fixes).
  - commit 8f56af6
  - io_uring: check for iowq alloc_workqueue failure (git-fixes).
  - commit 1158052
  - io_uring/io-wq: do not use bogus hash value (git-fixes).
  - io_uring/io-wq: cache work->flags in variable (git-fixes).
  - io_uring/io-wq: move worker lists to struct io_wq_acct
    (git-fixes).
  - io_uring/io-wq: add io_worker.acct pointer (git-fixes).
  - io_uring/io-wq: eliminate redundant io_work_get_acct() calls
    (git-fixes).
  - commit 53c8977

++++ kernel-firmware-mediatek:

  - Update to version 20251110 (git commit 15b5dddd9b2a):
    * linux-firmware: add firmware for mt7987 internal 2.5G ethernet phy
  - Update aliases

++++ kernel-rt:

  - Rename to
    patches.kabi/kabi-fix-dm-fix-dm_blk_report_zones.patch.
  - commit 911b752
  - KVM: SEV: Validate XCR0 provided by guest in GHCB (git-fixes).
  - commit 7df395e
  - KVM: SEV: Read save fields from GHCB exactly once (git-fixes).
  - commit 035bf6d
  - KVM: SEV: Rename kvm_ghcb_get_sw_exit_code() to
    kvm_get_cached_sw_exit_code() (git-fixes).
  - commit fb01ff1
  - KVM: SEV: Enforce minimum GHCB version requirement for SEV-SNP
    guests (git-fixes).
  - commit 924cf52
  - KVM: TDX: Do not retry locally when the retry is caused by
    invalid memslot (git-fixes).
  - commit 1ee08a7
  - KVM: x86/mmu: Return -EAGAIN if userspace deletes/moves memslot
    during prefault (git-fixes).
  - commit ebc80d5
  - KVM: x86: Have all vendor neutral sub-configs depend on KVM_X86,
    not just KVM (git-fixes).
  - commit 77fc3c5
  - KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC
    is active (git-fixes).
  - commit b1ea66f
  - KVM: SVM: Pass through GHCB MSR if and only if VM is an SEV-ES
    guest (git-fixes).
  - commit a848ce9
  - Refresh
    patches.suse/drm-amd-display-Default-IPS-to-RCG_IN_ACTIVE_IPS2_IN.patch.
  - Refresh
    patches.suse/drm-amdgpu-discovery-fix-fw-based-ip-discovery.patch.
  - Refresh
    patches.suse/drm-i915-dp-Fix-2.7-Gbps-DP_LINK_BW-value-on-g4x.patch.
  - Refresh
    patches.suse/drm-xe-Allow-dropping-kunit-dependency-as-built-in.patch.
  - Refresh
    patches.suse/drm-xe-Carve-out-wopcm-portion-from-the-stolen-memor.patch.
  - Refresh
    patches.suse/drm-xe-Ensure-fixed_slice_mode-gets-set-after-ccs_mo.patch.
  - Refresh
    patches.suse/drm-xe-Move-page-fault-init-after-topology-init.patch.
  - Refresh patches.suse/drm-xe-bmg-Update-Wa_22019338487.patch.
  - Refresh
    patches.suse/drm-xe-gsc-do-not-flush-the-GSC-worker-from-the-rese.patch.
  - Refresh
    patches.suse/drm-xe-guc_submit-fix-race-around-pending_disable.patch.
  - commit ce19d99
  - io_uring/rsrc: don't rely on user vaddr alignment (git-fixes).
  - io_uring: make fallocate be hashed work (git-fixes).
  - commit 4b7f18b
  - io_uring: fix task leak issue in io_wq_create() (git-fixes).
  - io_uring/kbuf: don't truncate end buffer for multiple buffer
    peeks (git-fixes).
  - commit 6eac1e4
  - io_uring/kbuf: account ring io_buffer_list memory (git-fixes).
  - commit f9b2eed
  - io_uring: account drain memory to cgroup (git-fixes).
  - io_uring: fix overflow resched cqe reordering (git-fixes).
  - commit 14d2bfa
  - io_uring: ensure deferred completions are flushed for multishot
    (git-fixes).
  - commit 9ec928d
  - io_uring/fdinfo: annotate racy sq/cq head/tail reads
    (git-fixes).
  - io_uring: fix 'sync' handling of io_fallback_tw() (git-fixes).
  - commit c501028
  - io_uring: don't duplicate flushing in io_req_post_cqe
    (git-fixes).
  - io_uring/kbuf: reject zero sized provided buffers (git-fixes).
  - commit add5ee3
  - io_uring/msg: initialise msg request opcode (git-fixes).
  - commit 78239f9
  - io_uring/net: account memory for zc sendmsg (git-fixes).
  - commit 1a819c2
  - io_uring/net: fix accept multishot handling (git-fixes).
  - commit 8f56af6
  - io_uring: check for iowq alloc_workqueue failure (git-fixes).
  - commit 1158052
  - io_uring/io-wq: do not use bogus hash value (git-fixes).
  - io_uring/io-wq: cache work->flags in variable (git-fixes).
  - io_uring/io-wq: move worker lists to struct io_wq_acct
    (git-fixes).
  - io_uring/io-wq: add io_worker.acct pointer (git-fixes).
  - io_uring/io-wq: eliminate redundant io_work_get_acct() calls
    (git-fixes).
  - commit 53c8977

++++ multipath-tools:

  - Update to version 0.11.3+184+suse.e1501732:
  - Fixes from upstream 0.11.3 (see also NEWS.md) (bsc#1253260)
    * Improved the communication with **udev** and **systemd** by triggering
    uevents when path devices are added to or removed from multipath maps,
    or when `multipathd reconfigure` is executed after changing blacklist
    directives in `multipath.conf`.
    * Failed paths should be checked every `polling_interval`. In certain cases,
    this wouldn't happen, because the check interval wasn't reset by multipathd.
    * It could happen that multipathd would accidentally release a SCSI persistent
    reservation held by another node. Fix it.
    * After manually failing some paths and then reinstating them, sometimes
    the reinstated paths were immediately failed again by multipathd. Fix it.
    * Various minor fixes reported by coverity.

++++ salt:

  - Fix TLS and x509 modules for OSes with older cryptography module
  - Require python-legacy-cgi only for Python > 3.12
  - Builds with py >=3.13 require python-legacy-cgi
  - Fix Salt for Python > 3.11 (bsc#1252285) (bsc#1252244)
    * Use external tornado on Python > 3.11
    * Make tls and x509 to use python-cryptography
    * Remove usage of spwd
  - Added:
    * fix-tls-and-x509-modules-for-older-cryptography-modu.patch
    * fix-salt-for-python-3.11.patch

++++ selinux-policy:

  - Update to version 20250627+git293.3432d4834:
    * Allow pcscd_t to search cgroup (bsc#1253098)
    * Fix syntax error in userdomain.if
    * Allow nnp_transition for OpenSMTPD (bsc#1252431)
    * Allow ras-mc-ctl get attributes of the kmod executable
    * Define file equivalency for /var/opt
    * Allow virtnodedev_t the perfmon capability
    * Allow nut_upsdrvctl_t the sys_ptrace capability
    * Label /usr/lib/systemd/user/graphical-session-pre.target with xdm_unit_file_t
    * Allow snapper sdbootutil plugin read emmc devices (bsc#1231354)
    * Allow pcrlock to delete pid entries
    * Allow systemd_pcrlock_t to manage its pid files
    * Mark snapper_sdbootutil_plugin_t as permissive
    * Drop unnamed filetrans, should be done upstream (bsc#1241964)
    * Label pcrlock pid file correctly (bsc#1241964)
    * Allow snapper sdbootutil plugin send msg to system bus (bsc#1241964)
    * snapper takes output from stdout/err, allow pcrlock to write
    * Add tpm2_getcap permissions to snapper sdbootutil (bsc#1244573)
    * Allow snapper sdbootutil plugin to read snapper data and conf
    * Allow snapper sdbootutil plugin to grep /proc/stat (bsc#1241964)
    * Replace snapper tmp file access for pcrlock (bsc#1241964)
    * Allow snapper sdbootutil read kernel module dirs (bsc#1241964)
    * Allow snapper sdbootutil plugin use bootctl (bsc#1241964)
    * Allow snapper sdbootutil plugin to list and read sysfs (bsc#1241964)
    * Allow snapper sdbootutil sys_admin (bsc#1241964)
    * Allow snapper sdbootutils plugin to findmnt (bsc#1241964)
    * Allow snapper sdbootutil plugin rw tpm (bsc#1233358)
    * Move manage dos permissions and dontaudit execmem to snapper sdbootutils plugin (bsc#1241964)
    * Move snapper domtrans to sdbootutil to plugin (bsc#1241964)
    * Revert snapper access to keys, move to sdbootutils plugin policy (bsc#1241964)
    * Add initial seperate policy for sdbootutil called by snapper (bsc#1233358)
    * Allow sort in snapper_grub_plugin_t read cpu.max (bsc#1252095)
    * systemd-sysctl: allow rw on binfm_misc_fs_t to set binfmt_misc status
    * Allow cupsd to manage cupsd_rw_etc_t lnk_files
    * Set temporary no-stub resolv.conf file from NetworkManager as net_conf_t
    * Allow spamc read aliases file
    * Mark configfs_t as mountpoint (bsc#1246080)
    * Allow systemd-machined watch cgroup files
    * Allow sshd-auth read generic proc files
    * Allow sshd-auth read and write user domain ptys
    * Allow logwatch read and write sendmail unix stream sockets
    * Allow logwatch domain transition on rpm execution
    * Allow thumb_t mounton its private tmpfs files
    * Allow thumb_t create permission in the user namespace
    * Allow corenet_unconfined_type name_bind to icmp_socket
    * Allow systemd-networkd to manage systemd_networkd_var_lib_t files
    * Allow sshd-session get attributes of sshd vsock socket

------------------------------------------------------------------
------------------  2025-11-10  -  Nov 10 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20251110.af063e6:
    * Avoid escape sequences on dump terminal of s390
    * Set erase character from kbs entry of terminfo

++++ crypto-policies:

  - Adapt the manpages to SUSE/openSUSE:
    * Add crypto-policies-SUSE-manpages.patch
    * Compress all the man pages for update-crypto-policies.8.gz,
    crypto-policies.7.gz, fips-finish-install.8.gz and
    fips-mode-setup.8.gz into man-crypto-policies.tar.xz
  - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696]
    * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert
    * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519
    * FIPS: disable MLKEM768-X25519 for openssh (no-op)
    * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl...
    * TEST-PQ: be more careful with the ordering
    * openssl: send one PQ and one classic key_share; prioritize PQ groups
    * sequoia: Generate AEAD policy
    * Do not include EdDSA in FIPS policy
    * sequoia: Add PQC algorithm
    * sequoia: Run tests against PQC capable policy-config-check
    * Revert "openssl, policies: implement group_key_share option"
    * openssl, policies: implement group_key_share option
    * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA
    * python/build-crypto-policies: output diffs on --test mismatches
    * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ...
    * policies, alg_lists, openssl: remove KYBER from allowed values
    * openssl: stricter enabling of Ciphersuites
    * openssl: make use of -CBC and -AESGCM keywords
    * openssl: add TLS 1.3 Brainpool identifiers
    * fix warning on using experimental key_exchanges
    * update-crypto-policies: don't output FIPS warning in fips mode
    * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256
    * openssh, libssh: refactor kx maps to use tuples
    * alg_lists: mark MLKEM768/SNTRUP kex experimental
    * nss: revert enabling mlkem768secp256r1
    * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber
    * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768
    * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768
    * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768
    * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256
    * LEGACY: enable 192-bit ciphers for nss pkcs12/smime
    * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384...
    * nss: be stricter with new purposes
    * python/update-crypto-policies: pacify pylint
    * fips-mode-setup: tolerate fips dracut module presence w/o FIPS
    * fips-mode-setup: small Argon2 detection fix
    * SHA1: add __openssl_block_sha1_signatures = 0
    * fips-mode-setup: block if LUKS devices using Argon2 are detected
    * update-crypto-policies: skip warning on --set=FIPS if bootc
    * fips-setup-helper: skip warning, BTW
    * fips-mode-setup: force --no-bootcfg when UKI is detected
    * fips-crypto-policy-overlay: automount FIPS policy
    * nss: rewrite backend for 3.101
    * cryptopolicies: parent scopes for dumping purposes
    * policygenerators: move scoping inside generators
    * openssh: make dss no longer enableble, support is dropped
    * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768
    * TEST-PQ: disable pure Kyber768
    * DEFAULT: switch to rh-allow-sha1-signatures = no...
    * java: drop unused javasystem backend
    * java: stop specifying jdk.tls.namedGroups in javasystem
    * ec_min_size: introduce and use in java, default to 256
    * java: use and include jdk.disabled.namedCurves
    * BSI: Update BSI policy for new 2024 minimum recommendations
    * fips-mode-setup: flashy ticking warning upon use
    * fips-mode-setup: add another scary "unsupported"
    * BSI: switch to 3072 minimum RSA key size
    * java: make hash, mac and sign more orthogonal
    * java: specify jdk.tls.namedGroups system property
    * java: respect more key size restrictions
    * java: disable anon ciphersuites, tying them to NULL...
    * java: start controlling / disable DTLSv1.0
    * nss: wire KYBER768 to XYBER768D00

++++ cyrus-sasl:

  - Python3 error log upon importing pycurl (bsc#1233529)
    Remove senceless log message.
    * add remove-senceless-log.patch

++++ kernel-default:

  - io_uring/net: don't clear REQ_F_NEED_CLEANUP unconditionally
    (git-fixes).
  - commit 4936341
  - io_uring/net: save msg_control for compat (git-fixes).
  - commit 09c50d3
  - btrfs: send: fix duplicated rmdir operations when using extrefs
    (git-fixes).
  - commit 4f3cd5c
  - btrfs: use smp_mb__after_atomic() when forcing COW in
    create_pending_snapshot() (git-fixes).
  - commit 2b2b6a8
  - btrfs: mark dirty extent range for out of bound prealloc extents
    (git-fixes).
  - commit b68eaa8
  - btrfs: set inode flag BTRFS_INODE_COPY_EVERYTHING when logging
    new name (git-fixes).
  - commit 36dafa0
  - btrfs: simplify error handling logic for btrfs_link()
    (git-fixes).
  - commit d00c25e
  - btrfs: fix inode leak on failure to add link to inode
    (git-fixes).
  - commit 722b72e
  - btrfs: abort transaction on failure to add link to inode
    (git-fixes).
  - commit b280fd3
  - btrfs: rename err to ret in btrfs_link() (git-fixes).
  - commit bccf104
  - btrfs: fix memory leak of qgroup_list in
    btrfs_add_qgroup_relation (git-fixes).
  - commit db8578f
  - x86/CPU/AMD: Add missing terminator for zen5_rdseed_microcode (git-fixes).
  - commit 3ad5c25
  - pds_core: remove write-after-free of client_id (CVE-2025-37916 bsc#1243474)
  - commit 5e9a8d2
  - coresight: Fix incorrect handling for return value of devm_kzalloc (CVE-2025-40059 bsc#1252809)
  - commit 855baa1
  - btrfs: fix memory leaks when rejecting a non SINGLE data profile without an RST (CVE-2025-40101 bsc#1252901)
  - commit 6c5e13d
  - bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt (CVE-2025-39917 bsc#1250723)
  - commit c537a65
  - ocfs2: fix double free in user_cluster_connect() (CVE-2025-40055 bsc#1252821)
  - commit 233260e
  - pps: fix warning in pps_register_cdev when register device fail
    (CVE-2025-40070 bsc#1252836).
  - commit 5d93ed8
  - ALSA: hda: cs35l41: Fix NULL pointer dereference in
    cs35l41_get_acpi_mute_state() (CVE-2025-40098 bsc#1252917).
  - commit 014dce4
  - nfsd: nfserr_jukebox in nlm_fopen should lead to a retry
    (git-fixes).
  - commit 0452526
  - rtc: rx8025: fix incorrect register reference (git-fixes).
  - drm/xe/guc: Synchronize Dead CT worker with unbind (git-fixes).
  - drm/mediatek: Add pm_runtime support for GCE power control
    (git-fixes).
  - drm/mediatek: Disable AFBC support on Mediatek DRM driver
    (git-fixes).
  - drm/amd/display: Enable mst when it's detected but yet to be
    initialized (git-fixes).
  - drm/amd: Fix suspend failure with secure display TA (git-fixes).
  - drm/amd/display: Fix NULL deref in debugfs odm_combine_segments
    (git-fixes).
  - drm/i915: Fix conversion between clock ticks and nanoseconds
    (git-fixes).
  - drm/i915: Avoid lock inversion when pinning to GGTT on
    CHV/BXT+VTD (git-fixes).
  - drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb
    (git-fixes).
  - gpiolib: fix invalid pointer access in debugfs (git-fixes).
  - gpio: swnode: don't use the swnode's name as the key for GPIO
    lookup (git-fixes).
  - Documentation: ACPI: i2c-muxes: fix I2C device references
    (git-fixes).
  - ACPI: SBS: Fix present test in acpi_battery_read() (git-fixes).
  - lib/crypto: curve25519-hacl64: Fix older clang KASAN workaround
    for GCC (git-fixes).
  - wifi: mac80211_hwsim: Limit destroy_on_close radio removal to
    netgroup (git-fixes).
  - net: usb: qmi_wwan: initialize MAC header offset in
    qmimux_rx_fixup (git-fixes).
  - Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()
    (git-fixes).
  - Bluetooth: btrtl: Fix memory leak in rtlbt_parse_firmware_v2()
    (git-fixes).
  - Bluetooth: hci_event: validate skb length for unknown CC opcode
    (git-fixes).
  - wifi: zd1211rw: fix potential memory leak in
    __zd_usb_enable_rx() (git-fixes).
  - Revert "wifi: ath10k: avoid unnecessary wait for service ready
    message" (git-fixes).
  - media: videobuf2: forbid remove_bufs when legacy fileio is
    active (git-fixes).
  - media: uvcvideo: Use heuristic to find stream entity
    (git-fixes).
  - drm/amd/display: increase max link count and fix link->enc
    NULL pointer access (stable-fixes).
  - Documentation: w1: Fix SPDX comment syntax on masters and
    slaves toctree index (git-fixes).
  - commit b161491

++++ kernel-rt:

  - io_uring/net: don't clear REQ_F_NEED_CLEANUP unconditionally
    (git-fixes).
  - commit 4936341
  - io_uring/net: save msg_control for compat (git-fixes).
  - commit 09c50d3
  - btrfs: send: fix duplicated rmdir operations when using extrefs
    (git-fixes).
  - commit 4f3cd5c
  - btrfs: use smp_mb__after_atomic() when forcing COW in
    create_pending_snapshot() (git-fixes).
  - commit 2b2b6a8
  - btrfs: mark dirty extent range for out of bound prealloc extents
    (git-fixes).
  - commit b68eaa8
  - btrfs: set inode flag BTRFS_INODE_COPY_EVERYTHING when logging
    new name (git-fixes).
  - commit 36dafa0
  - btrfs: simplify error handling logic for btrfs_link()
    (git-fixes).
  - commit d00c25e
  - btrfs: fix inode leak on failure to add link to inode
    (git-fixes).
  - commit 722b72e
  - btrfs: abort transaction on failure to add link to inode
    (git-fixes).
  - commit b280fd3
  - btrfs: rename err to ret in btrfs_link() (git-fixes).
  - commit bccf104
  - btrfs: fix memory leak of qgroup_list in
    btrfs_add_qgroup_relation (git-fixes).
  - commit db8578f
  - x86/CPU/AMD: Add missing terminator for zen5_rdseed_microcode (git-fixes).
  - commit 3ad5c25
  - pds_core: remove write-after-free of client_id (CVE-2025-37916 bsc#1243474)
  - commit 5e9a8d2
  - coresight: Fix incorrect handling for return value of devm_kzalloc (CVE-2025-40059 bsc#1252809)
  - commit 855baa1
  - btrfs: fix memory leaks when rejecting a non SINGLE data profile without an RST (CVE-2025-40101 bsc#1252901)
  - commit 6c5e13d
  - bpf: Fix out-of-bounds dynptr write in bpf_crypto_crypt (CVE-2025-39917 bsc#1250723)
  - commit c537a65
  - ocfs2: fix double free in user_cluster_connect() (CVE-2025-40055 bsc#1252821)
  - commit 233260e
  - pps: fix warning in pps_register_cdev when register device fail
    (CVE-2025-40070 bsc#1252836).
  - commit 5d93ed8
  - ALSA: hda: cs35l41: Fix NULL pointer dereference in
    cs35l41_get_acpi_mute_state() (CVE-2025-40098 bsc#1252917).
  - commit 014dce4
  - nfsd: nfserr_jukebox in nlm_fopen should lead to a retry
    (git-fixes).
  - commit 0452526
  - rtc: rx8025: fix incorrect register reference (git-fixes).
  - drm/xe/guc: Synchronize Dead CT worker with unbind (git-fixes).
  - drm/mediatek: Add pm_runtime support for GCE power control
    (git-fixes).
  - drm/mediatek: Disable AFBC support on Mediatek DRM driver
    (git-fixes).
  - drm/amd/display: Enable mst when it's detected but yet to be
    initialized (git-fixes).
  - drm/amd: Fix suspend failure with secure display TA (git-fixes).
  - drm/amd/display: Fix NULL deref in debugfs odm_combine_segments
    (git-fixes).
  - drm/i915: Fix conversion between clock ticks and nanoseconds
    (git-fixes).
  - drm/i915: Avoid lock inversion when pinning to GGTT on
    CHV/BXT+VTD (git-fixes).
  - drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb
    (git-fixes).
  - gpiolib: fix invalid pointer access in debugfs (git-fixes).
  - gpio: swnode: don't use the swnode's name as the key for GPIO
    lookup (git-fixes).
  - Documentation: ACPI: i2c-muxes: fix I2C device references
    (git-fixes).
  - ACPI: SBS: Fix present test in acpi_battery_read() (git-fixes).
  - lib/crypto: curve25519-hacl64: Fix older clang KASAN workaround
    for GCC (git-fixes).
  - wifi: mac80211_hwsim: Limit destroy_on_close radio removal to
    netgroup (git-fixes).
  - net: usb: qmi_wwan: initialize MAC header offset in
    qmimux_rx_fixup (git-fixes).
  - Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern()
    (git-fixes).
  - Bluetooth: btrtl: Fix memory leak in rtlbt_parse_firmware_v2()
    (git-fixes).
  - Bluetooth: hci_event: validate skb length for unknown CC opcode
    (git-fixes).
  - wifi: zd1211rw: fix potential memory leak in
    __zd_usb_enable_rx() (git-fixes).
  - Revert "wifi: ath10k: avoid unnecessary wait for service ready
    message" (git-fixes).
  - media: videobuf2: forbid remove_bufs when legacy fileio is
    active (git-fixes).
  - media: uvcvideo: Use heuristic to find stream entity
    (git-fixes).
  - drm/amd/display: increase max link count and fix link->enc
    NULL pointer access (stable-fixes).
  - Documentation: w1: Fix SPDX comment syntax on masters and
    slaves toctree index (git-fixes).
  - commit b161491

------------------------------------------------------------------
------------------  2025-11-8  -  Nov 8 2025  -------------------
------------------------------------------------------------------

++++ kernel-firmware-amdgpu:

  - Update to version 20251107 (git commit b918d0b3cb97):
    * amdgpu: DMCUB updates for various ASICs

------------------------------------------------------------------
------------------  2025-11-7  -  Nov 7 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - io_uring/rw: forbid multishot async reads (git-fixes).
  - commit b8ee47f
  - io-wq: backoff when retrying worker creation (git-fixes).
  - commit ed7c8cc
  - io_uring/waitid: setup async data in the prep handler
    (git-fixes).
  - commit c823259
  - io_uring/uring_cmd: remove dead req_has_async_data() check
    (git-fixes).
  - commit bbe13e2
  - KVM: SVM: Delete IRTE link from previous vCPU irrespective of
    new routing (git-fixes).
  - commit e2a2287
  - KVM: SVM: Delete IRTE link from previous vCPU before setting
    new IRTE (git-fixes).
  - commit 39eaa4c
  - KVM: SVM: Track per-vCPU IRTEs using kvm_kernel_irqfd structure
    (git-fixes).
  - commit 5da1bc9
  - KVM: Pass new routing entries and irqfd when updating IRTEs
    (git-fixes).
  - commit 613b778
  - x86/CPU/AMD: Add RDSEED fix for Zen5 (git-fixes).
  - commit 7dd7ddd
  - fs/smb: Fix inconsistent refcnt update (bsc#1250176,
    CVE-2025-39819).
  - commit 22b6cc8
  - KVM: SVM: WARN if an invalid posted interrupt IRTE entry is
    added (git-fixes).
  - commit a8ef915
  - Refresh
    patches.suse/x86-microcode-AMD-Limit-Entrysign-signature-checking-to-kn.patch.
  - commit ec68be1
  - iommu/amd: Return an error if vCPU affinity is set for non-vCPU
    IRTE (git-fixes).
  - commit e7a1195
  - net/9p: fix double req put in p9_fd_cancelled (CVE-2025-40027
    bsc#1252763).
  - commit 2c3c104
  - KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't
    valid (CVE-2025-40038 bsc#1252817).
  - commit d41e9f1
  - tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails
    to allocate psock->cork (bsc#1250705).
  - commit f8c7e99

++++ kernel-firmware-bluetooth:

  - Update to version 20251106 (git commit b055b3e24542):
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel BlazarI core

++++ kernel-rt:

  - io_uring/rw: forbid multishot async reads (git-fixes).
  - commit b8ee47f
  - io-wq: backoff when retrying worker creation (git-fixes).
  - commit ed7c8cc
  - io_uring/waitid: setup async data in the prep handler
    (git-fixes).
  - commit c823259
  - io_uring/uring_cmd: remove dead req_has_async_data() check
    (git-fixes).
  - commit bbe13e2
  - KVM: SVM: Delete IRTE link from previous vCPU irrespective of
    new routing (git-fixes).
  - commit e2a2287
  - KVM: SVM: Delete IRTE link from previous vCPU before setting
    new IRTE (git-fixes).
  - commit 39eaa4c
  - KVM: SVM: Track per-vCPU IRTEs using kvm_kernel_irqfd structure
    (git-fixes).
  - commit 5da1bc9
  - KVM: Pass new routing entries and irqfd when updating IRTEs
    (git-fixes).
  - commit 613b778
  - x86/CPU/AMD: Add RDSEED fix for Zen5 (git-fixes).
  - commit 7dd7ddd
  - fs/smb: Fix inconsistent refcnt update (bsc#1250176,
    CVE-2025-39819).
  - commit 22b6cc8
  - KVM: SVM: WARN if an invalid posted interrupt IRTE entry is
    added (git-fixes).
  - commit a8ef915
  - Refresh
    patches.suse/x86-microcode-AMD-Limit-Entrysign-signature-checking-to-kn.patch.
  - commit ec68be1
  - iommu/amd: Return an error if vCPU affinity is set for non-vCPU
    IRTE (git-fixes).
  - commit e7a1195
  - net/9p: fix double req put in p9_fd_cancelled (CVE-2025-40027
    bsc#1252763).
  - commit 2c3c104
  - KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't
    valid (CVE-2025-40038 bsc#1252817).
  - commit d41e9f1
  - tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails
    to allocate psock->cork (bsc#1250705).
  - commit f8c7e99

++++ openssh:

  - Add openssh-cve-2025-61984-username-validation.patch
    (bsc#1251198, CVE-2025-61984).
  - Add openssh-cve-2025-61985-nul-url-encode.patch
    (bsc#1251199, CVE-2025-61985).

++++ opensuse-migration-tool:

  - Drop accidentally created submodule
    * Add opensuse-migration-tool to .gitignore

++++ qemu:

  - Update to version 10.0.6
    Full backport list:
    https://lore.kernel.org/qemu-devel/1761022287.744330.6357.nullmailer@tls.msk.ru/
    A selection of them is reported below:
    linux-user/microblaze: Fix little-endianness binary
    target/hppa: correct size bit parity for fmpyadd
    target/i386: user: do not set up a valid LDT on reset
    async: access bottom half flags with qatomic_read
    target/i386: fix x86_64 pushw op
    i386/tcg/smm_helper: Properly apply DR values on SMM entry / exit
    i386/cpu: Prevent delivering SIPI during SMM in TCG mode
    i386/kvm: Expose ARCH_CAP_FB_CLEAR when invulnerable to MDS
    target/i386: Fix CR2 handling for non-canonical addresses
    block/curl.c: Use explicit long constants in curl_easy_setopt calls
    pcie_sriov: Fix broken MMIO accesses from SR-IOV VFs
    target/riscv: rvv: Fix vslide1[up|down].vx unexpected result when XLEN2 and SEWd
    target/riscv: Fix ssamoswap error handling
  - Update to version 10.0.5:
    Full backport list:
    https://lore.kernel.org/qemu-devel/1759986125.676506.643525.nullmailer@tls.msk.ru/
    A selection of them is reported below:
    tests/functional/test_aarch64_sbsaref_freebsd: Fix the URL of the ISO image
    tests/functional/test_ppc_bamboo: Replace broken link with working assets
    physmem: Destroy all CPU AddressSpaces on unrealize
    memory: New AS helper to serialize destroy+free
    include/system/memory.h: Clarify address_space_destroy() behaviour
    migration: Fix state transition in postcopy_start() error handling
    target/riscv: rvv: Modify minimum VLEN according to enabled vector extensions
    target/riscv: rvv: Replace checking V by checking Zve32x
    target/riscv: Fix endianness swap on compressed instructions
    hw/riscv/riscv-iommu: Fixup PDT Nested Walk
    ...
  - Fix bsc#1230042
  - Support for Intel TDX (jsc#PED-9266)
    A list of backported patches (so far) is:
    i386/tdx: Build TDX only for 64-bit target
    i386/tdx: Clarify the error message of mrconfigid/mrowner/mrownerconfig
    i386/tdx: Fix the typo of the comment of struct TdxGuest
    i386/cpu: Rename enable_cpuid_0x1f to force_cpuid_0x1f
    i386/tdx: Error and exit when named cpu model is requested
    i386/cpu: Warn about why CPUID_EXT_PDCM is not available
    i386/tdvf: Fix build on 32-bit host
    i386/tdx: Fix build on 32-bit host
    x86/loader: Don't update kernel header for CoCo VMs
    docs: Add TDX documentation
    i386/tdx: Validate phys_bits against host value
    i386/tdx: Make invtsc default on
    i386/tdx: Don't treat SYSCALL as unavailable
    i386/tdx: Fetch and validate CPUID of TD guest
    target/i386: Print CPUID subleaf info for unsupported feature
    i386: Remove unused parameter "uint32_t bit" in feature_word_description()
    i386/cgs: Introduce x86_confidential_guest_check_features()
    i386/tdx: Define supported KVM features for TDX
    i386/tdx: Add XFD to supported bit of TDX
    i386/tdx: Add supported CPUID bits relates to XFAM
    i386/tdx: Add supported CPUID bits related to TD Attributes
    i386/tdx: Add TDX fixed1 bits to supported CPUIDs
    i386/tdx: Implement adjust_cpuid_features() for TDX
    i386/cgs: Rename *mask_cpuid_features() to *adjust_cpuid_features()
    cpu: Don't set vcpu_dirty when guest_state_protected
    i386/apic: Skip kvm_apic_put() for TDX
    i386/tdx: Only configure MSR_IA32_UCODE_REV in kvm_init_msrs() for TDs
    i386/tdx: Don't synchronize guest tsc for TDs
    i386/tdx: Set and check kernel_irqchip mode for TDX
    i386/tdx: Disable PIC for TDX VMs
    i386/tdx: Disable SMM for TDX VMs
    i386/tdx: Set kvm_readonly_mem_enabled to false for TDX VM
    i386/tdx: Force exposing CPUID 0x1f
    i386/cpu: Introduce enable_cpuid_0x1f to force exposing CPUID 0x1f
    i386/tdx: implement tdx_cpu_instance_init()
    i386/cpu: introduce x86_confidential_guest_cpu_instance_init()
    kvm: Check KVM_CAP_MAX_VCPUS at vm level
    i386/tdx: Wire TDX_REPORT_FATAL_ERROR with GuestPanic facility
    i386/tdx: Handle KVM_SYSTEM_EVENT_TDX_FATAL
    i386/tdx: Enable user exit on KVM_HC_MAP_GPA_RANGE
    i386/tdx: Finalize TDX VM
    i386/tdx: Call KVM_TDX_INIT_VCPU to initialize TDX vcpu
    i386/tdx: Add TDVF memory via KVM_TDX_INIT_MEM_REGION
    i386/tdx: Setup the TD HOB list
    headers: Add definitions from UEFI spec for volumes, resources, etc...
    i386/tdx: Track RAM entries for TDX VM
    i386/tdx: Track mem_ptr for each firmware entry of TDVF
    i386/tdx: Don't initialize pc.rom for TDX VMs
    i386/tdx: Parse TDVF metadata for TDX VM
    i386/tdvf: Introduce function to parse TDVF metadata
    i386/tdx: load TDVF for TD guest
    i386/tdx: Implement user specified tsc frequency
    i386/tdx: Set APIC bus rate to match with what TDX module enforces
    i386/tdx: Support user configurable mrconfigid/mrowner/mrownerconfig
    i386/tdx: Validate TD attributes
    i386/tdx: Wire CPU features up with attributes of TD guest
    i386/tdx: Make sept_ve_disable set by default
    i386/tdx: Add property sept-ve-disable for tdx-guest object
    i386/tdx: Initialize TDX before creating TD vcpus
    kvm: Introduce kvm_arch_pre_create_vcpu()
    i386/tdx: Introduce is_tdx_vm() helper and cache tdx_guest object
    i386/tdx: Get tdx_capabilities via KVM_TDX_CAPABILITIES
    i386/tdx: Implement tdx_kvm_init() to initialize TDX VM context
    i386/tdx: Implement tdx_kvm_type() for TDX
    i386: Introduce tdx-guest object
    linux-headers: update from 6.15 + kvm/next
    linux-headers: Update to Linux v6.15-rc3

------------------------------------------------------------------
------------------  2025-11-6  -  Nov 6 2025  -------------------
------------------------------------------------------------------

++++ ipw-firmware:

  - mark LICENSE.ipw2x00 as %license [bsc#1252153]

++++ kernel-default:

  - nexthop: Forbid FDB status change while nexthop is in a group
    (CVE-2025-39980 bsc#1252063).
  - commit dada308
  - mm/ksm: fix flag-dropping behavior in ksm_madvise
    (CVE-2025-40040 bsc#1252780).
  - commit 095dc3d
  - serial: 8250_exar: add support for Advantech 2 port card with
    Device ID 0x0018 (git-fixes).
  - PCI: qcom: Add equalization settings for 8.0 GT/s and 32.0 GT/s
    (git-fixes).
  - kABI: PCI: qcom: Add equalization settings for 8.0 GT/s and
    32.0 GT/s (kabi git-fixes).
  - kabi/severities: add qcom_pcie_common_set_16gt_equalization()
    It's internal to dwc, noone is supposed to rely on it. Fixes:
    Export 'qcom_pcie_common_set_16gt_equalization' has been removed
  - PCI: Ensure relaxed tail alignment does not increase min_align
    (git-fixes).
  - PCI: Test for bit underflow in pcie_set_readrq() (git-fixes).
  - PCI: Add pci_resource_num() helper (git-fixes).
  - PCI: Use min_align, not unrelated add_align, for size0
    (git-fixes).
  - commit d635c02

++++ kernel-rt:

  - nexthop: Forbid FDB status change while nexthop is in a group
    (CVE-2025-39980 bsc#1252063).
  - commit dada308
  - mm/ksm: fix flag-dropping behavior in ksm_madvise
    (CVE-2025-40040 bsc#1252780).
  - commit 095dc3d
  - serial: 8250_exar: add support for Advantech 2 port card with
    Device ID 0x0018 (git-fixes).
  - PCI: qcom: Add equalization settings for 8.0 GT/s and 32.0 GT/s
    (git-fixes).
  - kABI: PCI: qcom: Add equalization settings for 8.0 GT/s and
    32.0 GT/s (kabi git-fixes).
  - kabi/severities: add qcom_pcie_common_set_16gt_equalization()
    It's internal to dwc, noone is supposed to rely on it. Fixes:
    Export 'qcom_pcie_common_set_16gt_equalization' has been removed
  - PCI: Ensure relaxed tail alignment does not increase min_align
    (git-fixes).
  - PCI: Test for bit underflow in pcie_set_readrq() (git-fixes).
  - PCI: Add pci_resource_num() helper (git-fixes).
  - PCI: Use min_align, not unrelated add_align, for size0
    (git-fixes).
  - commit d635c02

++++ mdadm:

  - Split off the Software RAID HOWTO into a -doc package
  - Update to version 4.4+29.gf8bb524b:
    * fix race between mdcheck_start.service and mdcheck_continue.service
    (bsc#1243443, bsc#1248097)
    * various fixes for mdcheck (bsc#1248097)
    * mdadm_env.sh: ignore MDADM_RAIDDEVICES if MDADM_SCAN is set
    (bsc#1229997)
  - Upstream bug fixes since 4.4 (bsc#1253060)
    * mdadm: add attribute nonstring for signature
    * super-ddf: Prevent crash when handling DDF metadata
    * platform-intel: Disable legacy option ROM scan on UEFI machines
    * mdadm: fix --grow with --add for linear
    * mdadm/raid6check: add xmalloc.h to raid6check.c
    * Coverity fixes resources leaks
    * udev: persist properties of MD devices after switch_root
  - _service: switch to tar_scm for better interoperabity with SLFO.

------------------------------------------------------------------
------------------  2025-11-5  -  Nov 5 2025  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Update to version 2.0.17:
    + This release adds the following features:
  - Add support for client-side phased update deployment
  - Add support for post-quantum signatures
  - Allow clearing the cache dirirectory
  - Allow fwupdtpmevlog to dump the raw eventlog data
  - Build a NVMe GUID derived from the serial number
  - Make fwupdtool extract work with deeply nested images
  - Parse VSS and FTW variable stores from EFI volumes
  - Reintroduce the FreeBSD CI target
  - Support very old versions of UDisks
    + This release fixes the following bugs:
  - Add 'fwupdmgr hwids' by exposing another daemon property
  - Add offline hashes for the Microsoft 20250902 dbx
  - Add the Framework-specific KEK and db hashes
  - Allow updating IFD BIOS region via parent MTD
  - Avoid showing reinstall prompts for composite devices
  - Clean up the fwupdtool lock file in all cases
  - Correctly match the correct historical composite component
  - Do not allow PK or KEK updates when system has a test key installed
  - Do not allow reinstalling when using ONLY_VERSION_UPGRADE
  - Do not require AC power to run the installed tests
  - Do not scan EFI volumes when constructing MTD BIOS devices
  - Ensure REGION is always set for MTD IFD children
  - Ensure SCSI instance IDs are valid ASCII values
  - Fix a critical warning when parsing invalid Jabra firmware
  - Fix an Ilitek parsing crash found when fuzzing
  - Fix an inotify race when refreshing metadata
  - Fix a pending-activation problem with Dell docking stations
  - Fix a potential hang when creating a chunk array with aligned sizes
  - Fix MTD emulation recording for PCI-backed devices
  - Fix the device order when the parent specifies install-parent-first
  - Fix the FLMSTR layout when reading IFD partitions
  - Fix the thunderbolt controller rushing to finalize before onlining retimers
  - Fix writing Intel GPU OptionROM data and OptionROM code
  - Flush stale events to make the Logitech Rallybar more reliable
  - Ignore all the Intel GPU MTD devices
  - Ignore errors when writing the last page of Dell dock firmware
  - Make an error message more specific
  - Modify the Dell dock needs-activation flag after updates are installed
  - Only add one devlink device for each PCI card
  - Parse the FMAP SBOM area as uSWID when required
  - Relax the USI dock DMC child device checks for new firmware
  - Revert back to the flashrom deprecated API as the new API is unusable
  - Rewrite the fwupdmgr manpage to be more useful
  - Use higher delay when update status for Logitech peripheral devices
    + This release adds support for the following hardware:
  - ASUS CX9406 (touch controller)
  - Framework Copilot keyboard
  - Genesys GL352530 and GL352360
  - Huddly C1
  - Lexar and Maxio NVMe SSDs
  - Primax Ryder mouse 2
  - Add pkgconfig(libmnl) BuildRequires: new dependency.

++++ kernel-default:

  - cpuset: Use new excpus for nocpu error check when enabling
    root partition (bsc#1241166).
  - cgroup/cpuset: Remove remote_partition_check() & make
    update_cpumasks_hier() handle remote partition (bsc#1241166).
  - commit d4c3a1b
  - cpuset: fix failure to enable isolated partition when containing
    isolcpus (bsc#1241166).
  - commit 9093c25
  - nbd: restrict sockets to TCP and UDP (bsc#1252774
    CVE-2025-40080).
  - commit 3fbbb49
  - kernel-subpackage-spec: Do not doubly-sign modules (bsc#1251930).
  - commit 0f034b6
  - RDMA/hns: Fix wrong WQE data when QP wraps around (git-fixes)
  - commit 6ea0097
  - RDMA/hns: Fix the modification of max_send_sge (git-fixes)
  - commit f143d8d
  - RDMA/hns: Fix recv CQ and QP cache affinity (git-fixes)
  - commit 61f6ae6
  - RDMA/irdma: Set irdma_cq cq_num field during CQ create (git-fixes)
  - commit be2c8f8
  - RDMA/irdma: Fix SD index calculation (git-fixes)
  - commit 0aad166
  - RDMA/bnxt_re: Fix a potential memory leak in destroy_gsi_sqp (git-fixes)
  - commit 0f46cf0

++++ kernel-rt:

  - cpuset: Use new excpus for nocpu error check when enabling
    root partition (bsc#1241166).
  - cgroup/cpuset: Remove remote_partition_check() & make
    update_cpumasks_hier() handle remote partition (bsc#1241166).
  - commit d4c3a1b
  - cpuset: fix failure to enable isolated partition when containing
    isolcpus (bsc#1241166).
  - commit 9093c25
  - nbd: restrict sockets to TCP and UDP (bsc#1252774
    CVE-2025-40080).
  - commit 3fbbb49
  - kernel-subpackage-spec: Do not doubly-sign modules (bsc#1251930).
  - commit 0f034b6
  - RDMA/hns: Fix wrong WQE data when QP wraps around (git-fixes)
  - commit 6ea0097
  - RDMA/hns: Fix the modification of max_send_sge (git-fixes)
  - commit f143d8d
  - RDMA/hns: Fix recv CQ and QP cache affinity (git-fixes)
  - commit 61f6ae6
  - RDMA/irdma: Set irdma_cq cq_num field during CQ create (git-fixes)
  - commit be2c8f8
  - RDMA/irdma: Fix SD index calculation (git-fixes)
  - commit 0aad166
  - RDMA/bnxt_re: Fix a potential memory leak in destroy_gsi_sqp (git-fixes)
  - commit 0f46cf0

++++ lz4:

  - CVE-2025-62813 was rejected [bsc#1252557]
  - deleted patches
    * lz4-CVE-2025-62813.patch

++++ podman:

  - Add patch for CVE-2025-31133,CVE-2025-52565,CVE-2025-52881 (bsc#1252376):
    * 0005-CVE-2025-52881-backport-subset-of-patch-from-runc.patch
  - Rebase patches:
    * 0001-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch
    * 0002-Fix-Remove-appending-rw-as-the-default-mount-option.patch
    * 0003-CVE-2025-6032-machine-init-fix-tls-check.patch
    * 0004-CVE-2025-9566-kube-play-don-t-follow-volume-symlinks.patch

++++ salt:

  - Fix payload signature verification on Tumbleweed (bsc#1251776)
  - Fix broken symlink on migration to Leap 16.0 (bsc#1250755)
  - Use versioned python interpreter for salt-ssh
  - Fix known_hosts error on gitfs (bsc#1250520) (bsc#1227207)
  - Add python3.11 as preferable for salt-ssh to avoid tests fails
  - Make test_pillar_timeout test more reliable
  - Modify README and other doc files for openSUSE
  - Set python-CherryPy as required for python-salt-testsuite (#115)
  - Revert require M2Crypto >= 0.44.0 for SUSE Family distros
  - This reverts commit aa40615dcf7a15325ef71bbc09a5423ce512491d.
  - Improve SL Micro 6.2 detection with grains
  - Fix functional.states.test_user for SLES 16 and Micro systems
  - Fix the tests failing on AlmaLinux 10 and other clones
  - Added:
    * do-not-break-signature-verification-on-latest-m2cryp.patch
    * use-versioned-python-interpreter-for-salt-ssh.patch
    * allow-libgit2-to-guess-sysdir-homedir-successfully-b.patch
    * add-python3.11-as-preferable-for-salt-ssh-to-avoid-t.patch
    * even-more-reliable-pillar-timeout-test.patch
    * modify-readme-for-opensuse-728.patch
    * improve-sl-micro-6.2-detection-with-grains.patch
    * fix-functional.states.test_user-for-sles-16-and-micr.patch
    * fix-the-tests-failing-on-almalinux-10-and-other-clon.patch

++++ runc:

  - Update to runc v1.3.3. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.3.3>. bsc#1252232
    * CVE-2025-31133
    * CVE-2025-52565
    * CVE-2025-52881
  - Remove upstreamed patches for bsc#1252232:
  - 2025-11-05-CVEs.patch

------------------------------------------------------------------
------------------  2025-11-4  -  Nov 4 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Revert "e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898"
    This reverts commit c8a67ee47d80a407b3a0277b35ca59f2d01f3488.
  - commit 379dc19
  - vhost: vringh: Modify the return value check (CVE-2025-40051
    bsc#1252858).
  - commit 0f5b967
  - btrfs: fix the incorrect max_bytes value for
    find_lock_delalloc_range() (git-fixes).
  - commit 6669879

++++ kernel-rt:

  - Revert "e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898"
    This reverts commit c8a67ee47d80a407b3a0277b35ca59f2d01f3488.
  - commit 379dc19
  - vhost: vringh: Modify the return value check (CVE-2025-40051
    bsc#1252858).
  - commit 0f5b967
  - btrfs: fix the incorrect max_bytes value for
    find_lock_delalloc_range() (git-fixes).
  - commit 6669879

++++ python313-core:

  - Add CVE-2025-8291-consistency-zip64.patch which checks
    consistency of the zip64 end of central directory record, and
    preventing obfuscation of the payload, i.e., you scanning for
    malicious content in a ZIP file with one ZIP parser (let's say
    a Rust one) then unpack it in production with another (e.g.,
    the Python one) and get malicious content that the other parser
    did not see (CVE-2025-8291, bsc#1251305)
  - Readjust patches while synchronizing between openSUSE and SLE trees:
  - F00251-change-user-install-location.patch
  - doc-py38-to-py36.patch
  - gh126985-mv-pyvenv.cfg2getpath.patch

++++ mdadm:

  - _service: pull from github.com/openSUSE/mdadm, patches now managed in git
    * delete 0010-mdopen-add-sbin-path-to-env-PATH-when-call-system-mo.patch
    * delete 1000-Revert-mdmonitor-Abandon-custom-configuration-files.patch
    * delete 1001-display-timeout-status.patch
    * delete 1002-OnCalendar-format-fix-of-mdcheck_start-timer.patch
    * delete 1003-mdadm-treat-the-Dell-softraid-array-as-local-array.patch
    * delete 1004-call-mdadm_env.sh-from-usr-libexec-mdadm.patch
    * delete 1005-mdadm-enable-Intel-Alderlake-RSTe-configuration.patch
    * delete 1006-imsm-Fix-RAID0-to-RAID10-migration.patch
    * delete 1007-mdadm-allow-any-valid-minor-number-in-md-device-name.patch
    * delete 1008-mdmonitor-use-MAILFROM-to-set-sendmail-envelope-send.patch
  - New versioning scheme: add tag offset and git commit from openSUSE/mdadm repo

++++ nvidia-open-driver-G06-signed:

  - back to 580.95.05 on aarch64, since userspace drivers have not
    been updated for this platform

++++ python313:

  - Add CVE-2025-8291-consistency-zip64.patch which checks
    consistency of the zip64 end of central directory record, and
    preventing obfuscation of the payload, i.e., you scanning for
    malicious content in a ZIP file with one ZIP parser (let's say
    a Rust one) then unpack it in production with another (e.g.,
    the Python one) and get malicious content that the other parser
    did not see (CVE-2025-8291, bsc#1251305)
  - Readjust patches while synchronizing between openSUSE and SLE trees:
  - F00251-change-user-install-location.patch
  - doc-py38-to-py36.patch
  - gh126985-mv-pyvenv.cfg2getpath.patch

------------------------------------------------------------------
------------------  2025-11-3  -  Nov 3 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Update
    patches.suse/ALSA-usb-audio-Fix-NULL-pointer-deference-in-try_to_.patch
    (git-fixes CVE-2025-40085 bsc#1252873).
  - Update
    patches.suse/ALSA-usb-audio-fix-race-condition-to-UAF-in-snd_usbm.patch
    (git-fixes CVE-2025-39997 bsc#1252056).
  - Update
    patches.suse/ASoC-qcom-audioreach-fix-potential-null-pointer-dere.patch
    (git-fixes CVE-2025-40013 bsc#1252348).
  - Update patches.suse/Bluetooth-MGMT-Fix-possible-UAFs.patch
    (git-fixes CVE-2025-39981 bsc#1252060).
  - Update
    patches.suse/Bluetooth-hci_event-Fix-UAF-in-hci_acl_create_conn_s.patch
    (git-fixes CVE-2025-39982 bsc#1252083).
  - Update
    patches.suse/Input-uinput-zero-initialize-uinput_ff_upload_compat.patch
    (git-fixes CVE-2025-40035 bsc#1252866).
  - Update
    patches.suse/NFSD-Define-a-proc_layoutcommit-for-the-FlexFiles-layout-type.patch
    (git-fixes CVE-2025-40087 bsc#1252909).
  - Update
    patches.suse/PCI-endpoint-pci-epf-test-Add-NULL-check-for-DMA-cha.patch
    (git-fixes CVE-2025-40032 bsc#1252841).
  - Update
    patches.suse/RDMA-rxe-Fix-race-in-do_task-when-draining.patch
    (git-fixes CVE-2025-40061 bsc#1252849).
  - Update
    patches.suse/Squashfs-fix-uninit-value-in-squashfs_get_parent.patch
    (git-fixes CVE-2025-40049 bsc#1252822).
  - Update
    patches.suse/bus-fsl-mc-Check-return-value-of-platform_get_resour.patch
    (git-fixes CVE-2025-40029 bsc#1252772).
  - Update
    patches.suse/can-etas_es58x-populate-ndo_change_mtu-to-prevent-bu.patch
    (git-fixes CVE-2025-39988 bsc#1252074).
  - Update
    patches.suse/can-hi311x-populate-ndo_change_mtu-to-prevent-buffer.patch
    (git-fixes CVE-2025-39987 bsc#1252079).
  - Update
    patches.suse/can-mcba_usb-populate-ndo_change_mtu-to-prevent-buff.patch
    (git-fixes CVE-2025-39985 bsc#1252082).
  - Update
    patches.suse/can-peak_usb-fix-shift-out-of-bounds-issue.patch
    (git-fixes CVE-2025-40020 bsc#1252679).
  - Update
    patches.suse/can-sun4i_can-populate-ndo_change_mtu-to-prevent-buf.patch
    (git-fixes CVE-2025-39986 bsc#1252078).
  - Update
    patches.suse/crypto-essiv-Check-ssize-for-decryption-and-in-place.patch
    (git-fixes CVE-2025-40019 bsc#1252678).
  - Update
    patches.suse/crypto-hisilicon-qm-set-NULL-to-qm-debug.qm_diff_reg.patch
    (git-fixes CVE-2025-40062 bsc#1252850).
  - Update
    patches.suse/drm-gma500-Fix-null-dereference-in-hdmi-teardown.patch
    (git-fixes CVE-2025-40011 bsc#1252336).
  - Update
    patches.suse/drm-sched-Fix-potential-double-free-in-drm_sched_job.patch
    (git-fixes CVE-2025-40096 bsc#1252902).
  - Update
    patches.suse/fbcon-fix-integer-overflow-in-fbcon_do_set_font.patch
    (git-fixes CVE-2025-39967 bsc#1252033).
  - Update
    patches.suse/fbdev-simplefb-Fix-use-after-free-in-simplefb_detach.patch
    (git-fixes CVE-2025-40037 bsc#1252819).
  - Update
    patches.suse/fs-proc-task_mmu-check-p-vec_buf-for-NULL.patch
    (git-fixes CVE-2025-40009 bsc#1252333).
  - Update
    patches.suse/fs-udf-fix-OOB-read-in-lengthAllocDescs-handling.patch
    (git-fixes CVE-2025-40044 bsc#1252785).
  - Update
    patches.suse/io_uring-fix-multishots-with-selected-buffers.patch
    (git-fixes CVE-2025-40364 bsc#1241637).
  - Update
    patches.suse/iommu-vt-d-Disallow-dirty-tracking-if-incoherent-pag.patch
    (git-fixes CVE-2025-40058 bsc#1252854).
  - Update
    patches.suse/ixgbe-fix-too-early-devlink_free-in-ixgbe_remove.patch
    (git-fixes CVE-2025-40091 bsc#1252915).
  - Update
    patches.suse/ixgbevf-fix-mailbox-API-compatibility-by-negotiating.patch
    (bsc#1247222 CVE-2025-40104 bsc#1252921).
  - Update
    patches.suse/media-b2c2-Fix-use-after-free-causing-by-irq_check_w.patch
    (git-fixes CVE-2025-39996 bsc#1252065).
  - Update
    patches.suse/media-i2c-tc358743-Fix-use-after-free-bugs-caused-by.patch
    (git-fixes CVE-2025-39995 bsc#1252064).
  - Update
    patches.suse/media-rc-fix-races-with-imon_disconnect.patch
    (git-fixes CVE-2025-39993 bsc#1252070).
  - Update
    patches.suse/media-tuner-xc5000-Fix-use-after-free-in-xc5000_rele.patch
    (git-fixes CVE-2025-39994 bsc#1252072).
  - Update
    patches.suse/media-uvcvideo-Mark-invalid-entities-with-id-UVC_INV.patch
    (git-fixes CVE-2025-40016 bsc#1252346).
  - Update
    patches.suse/misc-fastrpc-fix-possible-map-leak-in-fastrpc_put_ar.patch
    (git-fixes CVE-2025-40036 bsc#1252865).
  - Update
    patches.suse/msft-hv-3336-uio_hv_generic-Let-userspace-take-care-of-interrupt-.patch
    (git-fixes CVE-2025-40048 bsc#1252862).
  - Update
    patches.suse/net-nfc-nci-Add-parameter-validation-for-packet-data.patch
    (git-fixes CVE-2025-40043 bsc#1252787).
  - Update
    patches.suse/smb-client-fix-crypto-buffers-in-non-linear-memory.patch
    (bsc#1250491 boo#1239206 CVE-2025-40052 bsc#1252851).
  - Update
    patches.suse/tty-n_gsm-Don-t-block-input-queue-by-waiting-MSC.patch
    (git-fixes CVE-2025-40071 bsc#1252797).
  - Update
    patches.suse/wifi-ath11k-fix-NULL-dereference-in-ath11k_qmi_m3_lo.patch
    (git-fixes CVE-2025-39991 bsc#1252075).
  - Update
    patches.suse/xfrm-xfrm_alloc_spi-shouldn-t-use-0-as-SPI.patch
    (CVE-2025-39797 bsc#1249608 CVE-2025-39965 bsc#1251967).
  - commit 0209f26
  - coresight: trbe: Return NULL pointer for allocation failures
    (CVE-2025-40060 bsc#1252848).
  - commit f6a5f19

++++ kernel-rt:

  - Update
    patches.suse/ALSA-usb-audio-Fix-NULL-pointer-deference-in-try_to_.patch
    (git-fixes CVE-2025-40085 bsc#1252873).
  - Update
    patches.suse/ALSA-usb-audio-fix-race-condition-to-UAF-in-snd_usbm.patch
    (git-fixes CVE-2025-39997 bsc#1252056).
  - Update
    patches.suse/ASoC-qcom-audioreach-fix-potential-null-pointer-dere.patch
    (git-fixes CVE-2025-40013 bsc#1252348).
  - Update patches.suse/Bluetooth-MGMT-Fix-possible-UAFs.patch
    (git-fixes CVE-2025-39981 bsc#1252060).
  - Update
    patches.suse/Bluetooth-hci_event-Fix-UAF-in-hci_acl_create_conn_s.patch
    (git-fixes CVE-2025-39982 bsc#1252083).
  - Update
    patches.suse/Input-uinput-zero-initialize-uinput_ff_upload_compat.patch
    (git-fixes CVE-2025-40035 bsc#1252866).
  - Update
    patches.suse/NFSD-Define-a-proc_layoutcommit-for-the-FlexFiles-layout-type.patch
    (git-fixes CVE-2025-40087 bsc#1252909).
  - Update
    patches.suse/PCI-endpoint-pci-epf-test-Add-NULL-check-for-DMA-cha.patch
    (git-fixes CVE-2025-40032 bsc#1252841).
  - Update
    patches.suse/RDMA-rxe-Fix-race-in-do_task-when-draining.patch
    (git-fixes CVE-2025-40061 bsc#1252849).
  - Update
    patches.suse/Squashfs-fix-uninit-value-in-squashfs_get_parent.patch
    (git-fixes CVE-2025-40049 bsc#1252822).
  - Update
    patches.suse/bus-fsl-mc-Check-return-value-of-platform_get_resour.patch
    (git-fixes CVE-2025-40029 bsc#1252772).
  - Update
    patches.suse/can-etas_es58x-populate-ndo_change_mtu-to-prevent-bu.patch
    (git-fixes CVE-2025-39988 bsc#1252074).
  - Update
    patches.suse/can-hi311x-populate-ndo_change_mtu-to-prevent-buffer.patch
    (git-fixes CVE-2025-39987 bsc#1252079).
  - Update
    patches.suse/can-mcba_usb-populate-ndo_change_mtu-to-prevent-buff.patch
    (git-fixes CVE-2025-39985 bsc#1252082).
  - Update
    patches.suse/can-peak_usb-fix-shift-out-of-bounds-issue.patch
    (git-fixes CVE-2025-40020 bsc#1252679).
  - Update
    patches.suse/can-sun4i_can-populate-ndo_change_mtu-to-prevent-buf.patch
    (git-fixes CVE-2025-39986 bsc#1252078).
  - Update
    patches.suse/crypto-essiv-Check-ssize-for-decryption-and-in-place.patch
    (git-fixes CVE-2025-40019 bsc#1252678).
  - Update
    patches.suse/crypto-hisilicon-qm-set-NULL-to-qm-debug.qm_diff_reg.patch
    (git-fixes CVE-2025-40062 bsc#1252850).
  - Update
    patches.suse/drm-gma500-Fix-null-dereference-in-hdmi-teardown.patch
    (git-fixes CVE-2025-40011 bsc#1252336).
  - Update
    patches.suse/drm-sched-Fix-potential-double-free-in-drm_sched_job.patch
    (git-fixes CVE-2025-40096 bsc#1252902).
  - Update
    patches.suse/fbcon-fix-integer-overflow-in-fbcon_do_set_font.patch
    (git-fixes CVE-2025-39967 bsc#1252033).
  - Update
    patches.suse/fbdev-simplefb-Fix-use-after-free-in-simplefb_detach.patch
    (git-fixes CVE-2025-40037 bsc#1252819).
  - Update
    patches.suse/fs-proc-task_mmu-check-p-vec_buf-for-NULL.patch
    (git-fixes CVE-2025-40009 bsc#1252333).
  - Update
    patches.suse/fs-udf-fix-OOB-read-in-lengthAllocDescs-handling.patch
    (git-fixes CVE-2025-40044 bsc#1252785).
  - Update
    patches.suse/io_uring-fix-multishots-with-selected-buffers.patch
    (git-fixes CVE-2025-40364 bsc#1241637).
  - Update
    patches.suse/iommu-vt-d-Disallow-dirty-tracking-if-incoherent-pag.patch
    (git-fixes CVE-2025-40058 bsc#1252854).
  - Update
    patches.suse/ixgbe-fix-too-early-devlink_free-in-ixgbe_remove.patch
    (git-fixes CVE-2025-40091 bsc#1252915).
  - Update
    patches.suse/ixgbevf-fix-mailbox-API-compatibility-by-negotiating.patch
    (bsc#1247222 CVE-2025-40104 bsc#1252921).
  - Update
    patches.suse/media-b2c2-Fix-use-after-free-causing-by-irq_check_w.patch
    (git-fixes CVE-2025-39996 bsc#1252065).
  - Update
    patches.suse/media-i2c-tc358743-Fix-use-after-free-bugs-caused-by.patch
    (git-fixes CVE-2025-39995 bsc#1252064).
  - Update
    patches.suse/media-rc-fix-races-with-imon_disconnect.patch
    (git-fixes CVE-2025-39993 bsc#1252070).
  - Update
    patches.suse/media-tuner-xc5000-Fix-use-after-free-in-xc5000_rele.patch
    (git-fixes CVE-2025-39994 bsc#1252072).
  - Update
    patches.suse/media-uvcvideo-Mark-invalid-entities-with-id-UVC_INV.patch
    (git-fixes CVE-2025-40016 bsc#1252346).
  - Update
    patches.suse/misc-fastrpc-fix-possible-map-leak-in-fastrpc_put_ar.patch
    (git-fixes CVE-2025-40036 bsc#1252865).
  - Update
    patches.suse/msft-hv-3336-uio_hv_generic-Let-userspace-take-care-of-interrupt-.patch
    (git-fixes CVE-2025-40048 bsc#1252862).
  - Update
    patches.suse/net-nfc-nci-Add-parameter-validation-for-packet-data.patch
    (git-fixes CVE-2025-40043 bsc#1252787).
  - Update
    patches.suse/smb-client-fix-crypto-buffers-in-non-linear-memory.patch
    (bsc#1250491 boo#1239206 CVE-2025-40052 bsc#1252851).
  - Update
    patches.suse/tty-n_gsm-Don-t-block-input-queue-by-waiting-MSC.patch
    (git-fixes CVE-2025-40071 bsc#1252797).
  - Update
    patches.suse/wifi-ath11k-fix-NULL-dereference-in-ath11k_qmi_m3_lo.patch
    (git-fixes CVE-2025-39991 bsc#1252075).
  - Update
    patches.suse/xfrm-xfrm_alloc_spi-shouldn-t-use-0-as-SPI.patch
    (CVE-2025-39797 bsc#1249608 CVE-2025-39965 bsc#1251967).
  - commit 0209f26
  - coresight: trbe: Return NULL pointer for allocation failures
    (CVE-2025-40060 bsc#1252848).
  - commit f6a5f19

++++ suse-module-tools:

  - Update to version 16.0.62:
    * spec file: remove %udev_rules_update call (bsc#1250664)

++++ systemd-presets-branding-ALP-transactional:

  - disable cockpit.socket (to override SUSE default) (bsc#1252729)

------------------------------------------------------------------
------------------  2025-11-2  -  Nov 2 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Delete
    patches.suse/cpuidle-menu-Avoid-discarding-useful-information.patch.
  - commit 8ddc500
  - regulator: bd718x7: Fix voltages scaled by resistor divider
    (git-fixes).
  - regmap: slimbus: fix bus_context pointer in regmap init calls
    (git-fixes).
  - commit 8599172

++++ kernel-firmware-amdgpu:

  - Update to version 20251031 (git commit 04b323bb64f9):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-rt:

  - Delete
    patches.suse/cpuidle-menu-Avoid-discarding-useful-information.patch.
  - commit 8ddc500
  - regulator: bd718x7: Fix voltages scaled by resistor divider
    (git-fixes).
  - regmap: slimbus: fix bus_context pointer in regmap init calls
    (git-fixes).
  - commit 8599172

++++ ucode-amd:

  - Update to version 20251031 (git commit 04b323bb64f9):
    * linux-firmware: Update AMD cpu microcode

------------------------------------------------------------------
------------------  2025-11-1  -  Nov 1 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/ast: Clear preserved bits from register output value
    (git-fixes).
  - drm/panel: kingdisplay-kd097d04: Disable EoTp (git-fixes).
  - drm/panel: sitronix-st7789v: fix sync flags for t28cp45tn89
    (git-fixes).
  - drm/etnaviv: fix flush sequence logic (git-fixes).
  - drm/nouveau: Fix race in nouveau_sched_fini() (git-fixes).
  - drm/sysfb: Do not dereference NULL pointer in plane reset
    (git-fixes).
  - drm/msm/dpu: Require linear modifier for writeback framebuffers
    (git-fixes).
  - drm/msm/dpu: Fix pixel extension sub-sampling (git-fixes).
  - drm/msm/a6xx: Fix GMU firmware parser (git-fixes).
  - drm/amdgpu: fix SPDX header on cyan_skillfish_reg_init.c
    (git-fixes).
  - drm/amd/pm/powerplay/smumgr: Fix PCIeBootLinkLevel value on
    Iceland (git-fixes).
  - drm/amd/pm/powerplay/smumgr: Fix PCIeBootLinkLevel value on Fiji
    (git-fixes).
  - drm/amd/pm: fix smu table id bound check issue in
    smu_cmn_update_table() (git-fixes).
  - drm/radeon: Remove calls to drm_put_dev() (git-fixes).
  - drm/radeon: Do not kfree() devres managed rdev (git-fixes).
  - drm/mediatek: Fix device use-after-free on unbind (git-fixes).
  - ASoC: fsl_sai: Fix sync error in consumer mode (git-fixes).
  - ASoC: fsl_sai: fix bit order for DSD format (git-fixes).
  - ASoC: Intel: avs: Disable periods-elapsed work when closing PCM
    (git-fixes).
  - ASoC: Intel: avs: Unprepare a stream when XRUN occurs
    (git-fixes).
  - ASoC: mediatek: Fix double pm_runtime_disable in remove
    functions (git-fixes).
  - ASoC: qdsp6: q6asm: do not sleep while atomic (git-fixes).
  - ALSA: usb-audio: fix control pipe direction (git-fixes).
  - crypto: aspeed - fix double free caused by devm (git-fixes).
  - commit cd0d1a8

++++ kernel-rt:

  - drm/ast: Clear preserved bits from register output value
    (git-fixes).
  - drm/panel: kingdisplay-kd097d04: Disable EoTp (git-fixes).
  - drm/panel: sitronix-st7789v: fix sync flags for t28cp45tn89
    (git-fixes).
  - drm/etnaviv: fix flush sequence logic (git-fixes).
  - drm/nouveau: Fix race in nouveau_sched_fini() (git-fixes).
  - drm/sysfb: Do not dereference NULL pointer in plane reset
    (git-fixes).
  - drm/msm/dpu: Require linear modifier for writeback framebuffers
    (git-fixes).
  - drm/msm/dpu: Fix pixel extension sub-sampling (git-fixes).
  - drm/msm/a6xx: Fix GMU firmware parser (git-fixes).
  - drm/amdgpu: fix SPDX header on cyan_skillfish_reg_init.c
    (git-fixes).
  - drm/amd/pm/powerplay/smumgr: Fix PCIeBootLinkLevel value on
    Iceland (git-fixes).
  - drm/amd/pm/powerplay/smumgr: Fix PCIeBootLinkLevel value on Fiji
    (git-fixes).
  - drm/amd/pm: fix smu table id bound check issue in
    smu_cmn_update_table() (git-fixes).
  - drm/radeon: Remove calls to drm_put_dev() (git-fixes).
  - drm/radeon: Do not kfree() devres managed rdev (git-fixes).
  - drm/mediatek: Fix device use-after-free on unbind (git-fixes).
  - ASoC: fsl_sai: Fix sync error in consumer mode (git-fixes).
  - ASoC: fsl_sai: fix bit order for DSD format (git-fixes).
  - ASoC: Intel: avs: Disable periods-elapsed work when closing PCM
    (git-fixes).
  - ASoC: Intel: avs: Unprepare a stream when XRUN occurs
    (git-fixes).
  - ASoC: mediatek: Fix double pm_runtime_disable in remove
    functions (git-fixes).
  - ASoC: qdsp6: q6asm: do not sleep while atomic (git-fixes).
  - ALSA: usb-audio: fix control pipe direction (git-fixes).
  - crypto: aspeed - fix double free caused by devm (git-fixes).
  - commit cd0d1a8

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to version 580.105.08 (boo#1252978)

------------------------------------------------------------------
------------------  2025-10-31  -  Oct 31 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - smb: client: fix potential cfid UAF in smb2_query_info_compound
    (git-fixes).
  - commit ae8c7ce
  - vhost: vringh: Fix copy_to_iter return value check (CVE-2025-40056 bsc#1252826)
  - commit 2460f9a
  - net: tun: Update napi->skb after XDP process (CVE-2025-39984 bsc#1252081)
  - commit e3933a9
  - btrfs: don't allow adding block device of less than 1 MB
    (git-fixes).
  - commit 568a3e3
  - btrfs: directly free partially initialized fs_info in
    btrfs_check_leaked_roots() (git-fixes).
  - commit 348f92c
  - btrfs: do not assert we found block group item when creating
    free space tree (bsc#1252918 CVE-2025-40100).
  - commit ec19be1
  - btrfs: fix memory leak on duplicated memory in the qgroup
    assign ioctl (git-fixes).
  - commit 84fb697
  - btrfs: fix clearing of BTRFS_FS_RELOC_RUNNING if relocation
    already running (git-fixes).
  - commit 2ab85fb
  - btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
    (git-fixes).
  - commit 754a7d0
  - Bluetooth: hci_core: Fix tracking of periodic advertisement
    (git-fixes).
  - commit e160131
  - mm/mremap: correctly account old mapping after MREMAP_DONTUNMAP
    remap (git-fixes).
  - commit a874d3d
  - tmpfs: preserve SB_I_VERSION on remount (git-fixes).
  - commit 16a0fb3
  - mm: shmem: fix the shmem large folio allocation for the i915
    driver (git-fixes).
  - commit 3b07e73
  - mm: fix finish_fault() handling for large folios (git-fixes).
  - commit 1f5c347
  - mm: don't skip arch_sync_kernel_mappings() in error paths
    (git-fixes).
  - commit aab904b
  - coredump: Only sort VMAs when core_sort_vma sysctl is set
    (git-fixes).
  - commit 2a877a6
  - net: sctp: fix KMSAN uninit-value in sctp_inq_pop (git-fixes).
  - commit 3c3210d
  - sctp: avoid NULL dereference when chunk data buffer is missing
    (git-fixes).
  - commit de09ec4
  - net/sctp: fix a null dereference in sctp_disposition
    sctp_sf_do_5_1D_ce() (git-fixes).
  - commit 0da23a3
  - inet: ping: check sock_net() in ping_get_port() and
    ping_lookup() (git-fixes).
  - commit acb0bb7
  - sctp: Fix MAC comparison to be constant-time (git-fixes).
  - commit 2363529
  - ipv4: Fix NULL vs error pointer check in
    inet_blackhole_dev_init() (git-fixes).
  - commit 9c6ff53
  - sctp: Do not wake readers in __sctp_write_space() (git-fixes).
  - commit 9974f7a
  - ACPI: video: Fix use-after-free in
    acpi_video_switch_brightness() (git-fixes).
  - ACPI: button: Call input_free_device() on failing input device
    registration (git-fixes).
  - fbdev: atyfb: Check if pll_ops->init_pll failed (git-fixes).
  - fbdev: valkyriefb: Fix reference count leak in valkyriefb_init
    (git-fixes).
  - net: phy: dp83869: fix STRAP_OPMODE bitmask (git-fixes).
  - net: usb: asix_devices: Check return value of
    usbnet_get_endpoints (git-fixes).
  - Bluetooth: rfcomm: fix modem control handling (git-fixes).
  - Bluetooth: btintel_pcie: Fix event packet loss issue
    (git-fixes).
  - Bluetooth: ISO: Fix another instance of dst_type handling
    (git-fixes).
  - Revert "Bluetooth: L2CAP: convert timeouts to secs_to_jiffies()"
    (git-fixes).
  - Bluetooth: btmtksdio: Add pmctrl handling for BT closed state
    during reset (git-fixes).
  - Bluetooth: ISO: Fix BIS connection dst_type handling
    (git-fixes).
  - Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once
    (git-fixes).
  - usbnet: Prevents free active kevent (git-fixes).
  - wifi: brcmfmac: fix crash while sending Action Frames in
    standalone AP Mode (git-fixes).
  - wifi: ath12k: free skb during idr cleanup callback (git-fixes).
  - wifi: ath11k: Add missing platform IDs for quirk table
    (git-fixes).
  - wifi: ath10k: Fix memory leak on unsupported WMI command
    (git-fixes).
  - wifi: mac80211: reset FILS discovery and unsol probe resp
    intervals (git-fixes).
  - usbnet: Fix using smp_processor_id() in preemptible code
    warnings (git-fixes).
  - commit 02b30ff

++++ kernel-firmware-bluetooth:

  - Update to version 20251029 (git commit bfc84303530a):
    * rtl_bt: Add firmware and config files for RTL8761CUV

++++ kernel-firmware-mediatek:

  - Update to version 20251029 (git commit bfc84303530a):
    * linux-firmware: update firmware for MT7925 WiFi device
    * mediatek MT7925: update bluetooth firmware to 20251015213201

++++ kernel-rt:

  - smb: client: fix potential cfid UAF in smb2_query_info_compound
    (git-fixes).
  - commit ae8c7ce
  - vhost: vringh: Fix copy_to_iter return value check (CVE-2025-40056 bsc#1252826)
  - commit 2460f9a
  - net: tun: Update napi->skb after XDP process (CVE-2025-39984 bsc#1252081)
  - commit e3933a9
  - btrfs: don't allow adding block device of less than 1 MB
    (git-fixes).
  - commit 568a3e3
  - btrfs: directly free partially initialized fs_info in
    btrfs_check_leaked_roots() (git-fixes).
  - commit 348f92c
  - btrfs: do not assert we found block group item when creating
    free space tree (bsc#1252918 CVE-2025-40100).
  - commit ec19be1
  - btrfs: fix memory leak on duplicated memory in the qgroup
    assign ioctl (git-fixes).
  - commit 84fb697
  - btrfs: fix clearing of BTRFS_FS_RELOC_RUNNING if relocation
    already running (git-fixes).
  - commit 2ab85fb
  - btrfs: avoid potential out-of-bounds in btrfs_encode_fh()
    (git-fixes).
  - commit 754a7d0
  - Bluetooth: hci_core: Fix tracking of periodic advertisement
    (git-fixes).
  - commit e160131
  - mm/mremap: correctly account old mapping after MREMAP_DONTUNMAP
    remap (git-fixes).
  - commit a874d3d
  - tmpfs: preserve SB_I_VERSION on remount (git-fixes).
  - commit 16a0fb3
  - mm: shmem: fix the shmem large folio allocation for the i915
    driver (git-fixes).
  - commit 3b07e73
  - mm: fix finish_fault() handling for large folios (git-fixes).
  - commit 1f5c347
  - mm: don't skip arch_sync_kernel_mappings() in error paths
    (git-fixes).
  - commit aab904b
  - coredump: Only sort VMAs when core_sort_vma sysctl is set
    (git-fixes).
  - commit 2a877a6
  - net: sctp: fix KMSAN uninit-value in sctp_inq_pop (git-fixes).
  - commit 3c3210d
  - sctp: avoid NULL dereference when chunk data buffer is missing
    (git-fixes).
  - commit de09ec4
  - net/sctp: fix a null dereference in sctp_disposition
    sctp_sf_do_5_1D_ce() (git-fixes).
  - commit 0da23a3
  - inet: ping: check sock_net() in ping_get_port() and
    ping_lookup() (git-fixes).
  - commit acb0bb7
  - sctp: Fix MAC comparison to be constant-time (git-fixes).
  - commit 2363529
  - ipv4: Fix NULL vs error pointer check in
    inet_blackhole_dev_init() (git-fixes).
  - commit 9c6ff53
  - sctp: Do not wake readers in __sctp_write_space() (git-fixes).
  - commit 9974f7a
  - ACPI: video: Fix use-after-free in
    acpi_video_switch_brightness() (git-fixes).
  - ACPI: button: Call input_free_device() on failing input device
    registration (git-fixes).
  - fbdev: atyfb: Check if pll_ops->init_pll failed (git-fixes).
  - fbdev: valkyriefb: Fix reference count leak in valkyriefb_init
    (git-fixes).
  - net: phy: dp83869: fix STRAP_OPMODE bitmask (git-fixes).
  - net: usb: asix_devices: Check return value of
    usbnet_get_endpoints (git-fixes).
  - Bluetooth: rfcomm: fix modem control handling (git-fixes).
  - Bluetooth: btintel_pcie: Fix event packet loss issue
    (git-fixes).
  - Bluetooth: ISO: Fix another instance of dst_type handling
    (git-fixes).
  - Revert "Bluetooth: L2CAP: convert timeouts to secs_to_jiffies()"
    (git-fixes).
  - Bluetooth: btmtksdio: Add pmctrl handling for BT closed state
    during reset (git-fixes).
  - Bluetooth: ISO: Fix BIS connection dst_type handling
    (git-fixes).
  - Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once
    (git-fixes).
  - usbnet: Prevents free active kevent (git-fixes).
  - wifi: brcmfmac: fix crash while sending Action Frames in
    standalone AP Mode (git-fixes).
  - wifi: ath12k: free skb during idr cleanup callback (git-fixes).
  - wifi: ath11k: Add missing platform IDs for quirk table
    (git-fixes).
  - wifi: ath10k: Fix memory leak on unsupported WMI command
    (git-fixes).
  - wifi: mac80211: reset FILS discovery and unsol probe resp
    intervals (git-fixes).
  - usbnet: Fix using smp_processor_id() in preemptible code
    warnings (git-fixes).
  - commit 02b30ff

++++ samba:

  - Update [printers] location to /var/samba/spool; (bsc#1249179).

------------------------------------------------------------------
------------------  2025-10-30  -  Oct 30 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20251030.441f926:
    * Add systemd to /etc/nsswitch.conf [bsc#1250513]
    * Add group-directories-first option
    * prevent normal users from accessing dmesg (bsc#1249686)
    * Use explicit defaults for XDG environment variables

++++ kernel-default:

  - bpf: Explicitly check accesses to bpf_sock_addr (CVE-2025-40078
    bsc#1252789).
  - commit 3153aa7
  - mm: swap: check for stable address space before operating on
    the VMA (CVE-2025-39992 bsc#1252076).
  - commit cb5a00c
  - kdb: Replace deprecated strcpy() with memmove() in vkdb_printf()
    (bsc#1252939).
  - commit 2f5c813
  - Refresh patches.suse/perf-hwmon_pmu-Fix-uninitialized-variable-warning.patch.
  - commit 88b2431

++++ kernel-rt:

  - bpf: Explicitly check accesses to bpf_sock_addr (CVE-2025-40078
    bsc#1252789).
  - commit 3153aa7
  - mm: swap: check for stable address space before operating on
    the VMA (CVE-2025-39992 bsc#1252076).
  - commit cb5a00c
  - kdb: Replace deprecated strcpy() with memmove() in vkdb_printf()
    (bsc#1252939).
  - commit 2f5c813
  - Refresh patches.suse/perf-hwmon_pmu-Fix-uninitialized-variable-warning.patch.
  - commit 88b2431

------------------------------------------------------------------
------------------  2025-10-29  -  Oct 29 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ipvs: Defer ip_vs_ftp unregister during netns cleanup
    (CVE-2025-40018 bsc#1252688).
  - commit 64026d5
  - NFSD: Fix crash in nfsd4_read_release() (git-fixes).
  - commit e00ae91
  - x86/microcode/AMD: Limit Entrysign signature checking to known generations (bsc#1252725).
  - commit 8983a77

++++ kernel-rt:

  - ipvs: Defer ip_vs_ftp unregister during netns cleanup
    (CVE-2025-40018 bsc#1252688).
  - commit 64026d5
  - NFSD: Fix crash in nfsd4_read_release() (git-fixes).
  - commit e00ae91
  - x86/microcode/AMD: Limit Entrysign signature checking to known generations (bsc#1252725).
  - commit 8983a77

++++ lz4:

  - security update
  - added patches
    CVE-2025-62813 [bsc#1252557], incorrect error handling when passing
    a NULL pointer to lz4frame functions allows for application crash
    when processing untrusted LZ4 frames
    * lz4-CVE-2025-62813.patch

++++ opensuse-migration-tool:

  - Update to version 20251029.ed0d12d:
    * Update opensuse-migration-tool

++++ ucode-amd:

  - Update to version 20251028 (git commit 4f72031fc195):
    * linux-firmware: Update AMD cpu microcode

------------------------------------------------------------------
------------------  2025-10-28  -  Oct 28 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - KVM: x86: Don't load/put vCPU when unloading its MMU during
    teardown (git-fixes).
  - commit 625c23b
  - md/raid1: fix data lost for writemostly rdev (git-fixes).
  - commit 9711ae3
  - timers: Add missing READ_ONCE() in __run_timer_base()
    (git-fixes).
  - commit 01edf7f
  - x86/resctrl: Fix miscount of bandwidth event when reactivating previously unavailable RMID (bsc#1252734).
  - commit bcfb9ac
  - x86/resctrl: Refactor resctrl_arch_rmid_read() (bsc#1252734).
  - commit 47cb871
  - Update patches.suse/nvme-auth-update-bi_directional-flag.patch
    (git-fixes bsc#1249735).
  - Update
    patches.suse/nvme-tcp-send-only-permitted-commands-for-secure-con.patch
    (git-fixes bsc#1249397 bsc#1249398).
  - commit a032b7d
  - net/smc: fix warning in smc_rx_splice() when calling get_page()
    (CVE-2025-40012 bsc#1252330).
  - commit 75584c2
  - KVM: x86: move vm_destroy callback at end of kvm_arch_destroy_vm
    (git-fixes).
  - commit e564cdc
  - Update patches.suse/nvme-auth-update-bi_directional-flag.patch
    (git-fixes bsc#1249735).
  - Update
    patches.suse/nvme-tcp-send-only-permitted-commands-for-secure-con.patch
    (git-fixes bsc#1249397).
  - commit b5375ad
  - nvme/tcp: handle tls partially sent records in write_space()
    (git-fixes).
  - nvme-auth: update sc_c in host response (git-fixes bsc#1249397).
  - nvme-multipath: Skip nr_active increments in RETRY disposition
    (git-fixes).
  - nvme-pci: Add TUXEDO IBS Gen8 to Samsung sleep quirk
    (git-fixes).
  - commit 988d439
  - i40e: add max boundary check for VF filters (CVE-2025-39968
    bsc#1252047).
  - i40e: fix validation of VF state in get resources
    (CVE-2025-39969 bsc#1252044).
  - i40e: fix idx validation in i40e_validate_queue_map
    (CVE-2025-39972 bsc#1252039).
  - i40e: add validation for ring_len param (CVE-2025-39973
    bsc#1252035).
  - igc: don't fail igc_probe() on LED setup error (CVE-2025-39956
    bsc#1251809).
  - ice: fix Rx page leak on multi-buffer frames (CVE-2025-39948
    bsc#1251233).
  - qed: Don't collect too many protection override GRC elements
    (CVE-2025-39949 bsc#1251177).
  - commit fd8c4e7
  - drm/xe/guc_submit: fix race around pending_disable (git-fixes).
  - commit 4c4892e
  - drm/xe/guc: Adding steering info support for GuC register lists
    (git-fixes).
  - commit 3d70978
  - drm/xe/guc: Prepare GuC register list and update ADS size for
    error capture (stable-fixes).
  - Refresh
    patches.suse/drm-xe-Set-LRC-addresses-before-guc-load.patch.
  - commit b0f889f
  - Remove unnecessary firmware version check for gc v9_4_2
    (stable-fixes).
  - commit f08b376
  - KVM: TDX: Fix uninitialized error code for __tdx_bringup() (git-fixes).
  - commit 91d2e64
  - KVM: TDX: Remove redundant __GFP_ZERO (git-fixes).
  - commit d028109
  - x86/tdx: Skip clearing reclaimed pages unless X86_BUG_TDX_PW_MCE is present (git-fixes).
  - commit 99576da
  - x86/tdx: Tidy reset_pamt functions (git-fixes).
  - commit 39b4875
  - x86/tdx: Eliminate duplicate code in tdx_clear_page() (git-fixes).
  - commit b1d3c98
  - KVM: TDX: Move TDX hardware setup from main.c to tdx.c (git-fixes).
  - commit f5a7c5b
  - cpufreq/amd-pstate: Avoid shadowing ret in
    amd_pstate_ut_check_driver() (git-fixes).
  - commit f494d60

++++ kernel-rt:

  - KVM: x86: Don't load/put vCPU when unloading its MMU during
    teardown (git-fixes).
  - commit 625c23b
  - md/raid1: fix data lost for writemostly rdev (git-fixes).
  - commit 9711ae3
  - timers: Add missing READ_ONCE() in __run_timer_base()
    (git-fixes).
  - commit 01edf7f
  - x86/resctrl: Fix miscount of bandwidth event when reactivating previously unavailable RMID (bsc#1252734).
  - commit bcfb9ac
  - x86/resctrl: Refactor resctrl_arch_rmid_read() (bsc#1252734).
  - commit 47cb871
  - Update patches.suse/nvme-auth-update-bi_directional-flag.patch
    (git-fixes bsc#1249735).
  - Update
    patches.suse/nvme-tcp-send-only-permitted-commands-for-secure-con.patch
    (git-fixes bsc#1249397 bsc#1249398).
  - commit a032b7d
  - net/smc: fix warning in smc_rx_splice() when calling get_page()
    (CVE-2025-40012 bsc#1252330).
  - commit 75584c2
  - KVM: x86: move vm_destroy callback at end of kvm_arch_destroy_vm
    (git-fixes).
  - commit e564cdc
  - Update patches.suse/nvme-auth-update-bi_directional-flag.patch
    (git-fixes bsc#1249735).
  - Update
    patches.suse/nvme-tcp-send-only-permitted-commands-for-secure-con.patch
    (git-fixes bsc#1249397).
  - commit b5375ad
  - nvme/tcp: handle tls partially sent records in write_space()
    (git-fixes).
  - nvme-auth: update sc_c in host response (git-fixes bsc#1249397).
  - nvme-multipath: Skip nr_active increments in RETRY disposition
    (git-fixes).
  - nvme-pci: Add TUXEDO IBS Gen8 to Samsung sleep quirk
    (git-fixes).
  - commit 988d439
  - i40e: add max boundary check for VF filters (CVE-2025-39968
    bsc#1252047).
  - i40e: fix validation of VF state in get resources
    (CVE-2025-39969 bsc#1252044).
  - i40e: fix idx validation in i40e_validate_queue_map
    (CVE-2025-39972 bsc#1252039).
  - i40e: add validation for ring_len param (CVE-2025-39973
    bsc#1252035).
  - igc: don't fail igc_probe() on LED setup error (CVE-2025-39956
    bsc#1251809).
  - ice: fix Rx page leak on multi-buffer frames (CVE-2025-39948
    bsc#1251233).
  - qed: Don't collect too many protection override GRC elements
    (CVE-2025-39949 bsc#1251177).
  - commit fd8c4e7
  - drm/xe/guc_submit: fix race around pending_disable (git-fixes).
  - commit 4c4892e
  - drm/xe/guc: Adding steering info support for GuC register lists
    (git-fixes).
  - commit 3d70978
  - drm/xe/guc: Prepare GuC register list and update ADS size for
    error capture (stable-fixes).
  - Refresh
    patches.suse/drm-xe-Set-LRC-addresses-before-guc-load.patch.
  - commit b0f889f
  - Remove unnecessary firmware version check for gc v9_4_2
    (stable-fixes).
  - commit f08b376
  - KVM: TDX: Fix uninitialized error code for __tdx_bringup() (git-fixes).
  - commit 91d2e64
  - KVM: TDX: Remove redundant __GFP_ZERO (git-fixes).
  - commit d028109
  - x86/tdx: Skip clearing reclaimed pages unless X86_BUG_TDX_PW_MCE is present (git-fixes).
  - commit 99576da
  - x86/tdx: Tidy reset_pamt functions (git-fixes).
  - commit 39b4875
  - x86/tdx: Eliminate duplicate code in tdx_clear_page() (git-fixes).
  - commit b1d3c98
  - KVM: TDX: Move TDX hardware setup from main.c to tdx.c (git-fixes).
  - commit f5a7c5b
  - cpufreq/amd-pstate: Avoid shadowing ret in
    amd_pstate_ut_check_driver() (git-fixes).
  - commit f494d60

------------------------------------------------------------------
------------------  2025-10-27  -  Oct 27 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Enable SELinux in default daemon.json config (--selinux-enabled). This has no
    practical impact on non-SELinux systems. bsc#1252290

++++ kernel-default:

  - scsi: libfc: Prevent integer overflow in fc_fcp_recv_data()
    (git-fixes).
  - md: fix mssing blktrace bio split events (git-fixes).
  - commit 8af9b0e
  - scsi: storvsc: Prefer returning channel with the same CPU as on the I/O issuing CPU (bsc#1252267).
  - hyperv: Remove the spurious null directive line (git-fixes).
  - Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes).
  - Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes).
  - Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes).
  - mshv: Handle NEED_RESCHED_LAZY before transferring to guest (git-fixes).
  - x86/hyperv: Add kexec/kdump support on Azure CVMs (git-fixes).
  - Drivers: hv: util: Cosmetic changes for hv_utils_transport.c (git-fixes).
  - clocksource: hyper-v: Skip unnecessary checks for the root partition (git-fixes).
  - hyperv: Add missing field to hv_output_map_device_interrupt (git-fixes).
  - uio_hv_generic: Let userspace take care of interrupt mask (git-fixes).
  - scsi: storvsc: Remove redundant ternary operators (git-fixes).
  - net: mana: Reduce waiting time if HWC not responding (git-fixes).
  - commit dc5fea5
  - amd-pstate-ut: Reset amd-pstate driver mode after running
    selftests (bsc#1249226).
  - commit 62def1a
  - cpufreq/amd-pstate: Fix a regression leading to EPP 0 after
    hibernate (git-fixes).
  - commit 60d54b4
  - ACPI: platform-profile: Fix CFI violation when accessing sysfs
    files (git-fixes).
  - commit 6a68087
  - tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request()
    (git-fixes).
  - commit 9b6914d
  - octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()
    (CVE-2025-39978 bsc#1252069).
  - tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect()
    (CVE-2025-39955 bsc#1251804).
  - commit 63120f8
  - wifi: rtw89: fix use-after-free in
    rtw89_core_tx_kick_off_and_wait() (CVE-2025-40000 bsc#1252062).
  - commit 247f800
  - most: usb: hdm_probe: Fix calling put_device() before device
    initialization (git-fixes).
  - most: usb: Fix use-after-free in hdm_disconnect (git-fixes).
  - misc: fastrpc: Fix dma_buf object leak in fastrpc_map_lookup
    (git-fixes).
  - serial: 8250_mtk: Enable baud clock and manage in runtime PM
    (git-fixes).
  - serial: 8250_dw: handle reset control deassert error
    (git-fixes).
  - serial: sc16is7xx: remove useless enable of enhanced features
    (git-fixes).
  - xhci: dbc: enable back DbC in resume if it was enabled before
    suspend (git-fixes).
  - xhci: dbc: fix bogus 1024 byte prefix if ttyDBC read races
    with stall event (git-fixes).
  - spi: airoha: fix reading/writing of flashes with more than
    one plane per lun (git-fixes).
  - spi: airoha: add support of dual/quad wires spi modes to
    exec_op() handler (git-fixes).
  - spi: airoha: return an error for continuous mode dirmap creation
    cases (git-fixes).
  - spi: spi-nxp-fspi: add extra delay after dll locked (git-fixes).
  - net: usb: rtl8150: Fix frame padding (git-fixes).
  - net: usb: lan78xx: fix use of improperly initialized dev->chipid
    in lan78xx_reset (git-fixes).
  - r8152: add error handling in rtl8152_driver_init (git-fixes).
  - r8169: fix packet truncation after S4 resume on
    RTL8168H/RTL8111H (git-fixes).
  - rtc: interface: Ensure alarm irq is enabled when UIE is enabled
    (stable-fixes).
  - rtc: interface: Fix long-standing race when setting alarm
    (stable-fixes).
  - PCI: endpoint: pci-epf-test: Add NULL check for DMA channels
    before release (git-fixes).
  - PCI/AER: Support errors introduced by PCIe r6.0 (stable-fixes).
  - phy: cadence: cdns-dphy: Update calibration wait time for
    startup state machine (git-fixes).
  - phy: cadence: cdns-dphy: Fix PLL lock and O_CMN_READY polling
    (git-fixes).
  - phy: cdns-dphy: Store hs_clk_rate and return it (stable-fixes).
  - mtd: rawnand: fsmc: Default to autodetect buswidth
    (stable-fixes).
  - wifi: mt76: mt7921u: Add VID/PID for Netgear A7500
    (stable-fixes).
  - wifi: mt76: mt7925u: Add VID/PID for Netgear A9000
    (stable-fixes).
  - media: vivid: fix disappearing <Vendor Command With ID> messages
    (git-fixes).
  - media: nxp: imx8-isi: Drop unused argument to
    mxc_isi_channel_chain() (stable-fixes).
  - mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config
    flag (git-fixes).
  - mmc: mmc_spi: multiple block read remove read crc ack
    (stable-fixes).
  - mmc: core: SPI mode remove cmd7 (stable-fixes).
  - lib/crypto/curve25519-hacl64: Disable KASAN with clang-17 and
    older (stable-fixes).
  - PM: runtime: Add new devm functions (stable-fixes).
  - mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for
    cache_type (stable-fixes).
  - mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config
    max_register value (stable-fixes).
  - net: usb: lan78xx: Add error handling to
    lan78xx_init_mac_address (stable-fixes).
  - PCI: endpoint: Remove surplus return statement from
    pci_epf_test_clean_dma_chan() (stable-fixes).
  - commit 7cc4d1c
  - drm/panic: Fix qr_code, ensure vmargin is positive (git-fixes).
  - firmware: arm_scmi: Fix premature SCMI_XFER_FLAG_IS_RAW clearing
    in raw mode (git-fixes).
  - firmware: arm_scmi: Account for failed debug initialization
    (git-fixes).
  - hwmon: (sht3x) Fix error handling (git-fixes).
  - gpio: ljca: Fix duplicated IRQ mapping (git-fixes).
  - gpio: pci-idio-16: Define maximum valid register address offset
    (git-fixes).
  - gpio: 104-idio-16: Define maximum valid register address offset
    (git-fixes).
  - HID: multitouch: fix name of Stylus input devices (git-fixes).
  - HID: hid-input: only ignore 0 battery events for digitizers
    (git-fixes).
  - commit 07ce516
  - ASoC: SOF: ipc4-pcm: Enable delay reporting for ChainDMA streams
    (stable-fixes).
  - Refresh
    patches.suse/ASoC-SOF-ipc4-topology-Correct-the-minimum-host-DMA-.patch.
  - commit fc33a6f
  - drm/panic: Fix drawing the logo on a small narrow screen
    (git-fixes).
  - drm/panthor: Fix kernel panic on partial unmap of a GPU VA
    region (git-fixes).
  - drm/amd/display: use GFP_NOWAIT for allocation in interrupt
    handler (git-fixes).
  - can: netlink: can_changelink(): allow disabling of automatic
    restart (git-fixes).
  - can: rockchip-canfd: rkcanfd_start_xmit(): use
    can_dev_dropped_skb() instead of can_dropped_invalid_skb()
    (git-fixes).
  - can: esd: acc_start_xmit(): use can_dev_dropped_skb() instead
    of can_dropped_invalid_skb() (git-fixes).
  - can: bxcan: bxcan_start_xmit(): use can_dev_dropped_skb()
    instead of can_dropped_invalid_skb() (git-fixes).
  - ASoC: nau8821: Add DMI quirk to bypass jack debounce circuit
    (git-fixes).
  - ASoC: nau8821: Generalize helper to clear IRQ status
    (git-fixes).
  - ASoC: nau8821: Cancel jdet_work before handling jack ejection
    (git-fixes).
  - ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf()
    fails (git-fixes).
  - ASoC: codecs: Fix gain setting ranges for Renesas IDT821034
    codec (git-fixes).
  - ALSA: usb-audio: Fix NULL pointer deference in
    try_to_register_card (git-fixes).
  - ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
    (git-fixes).
  - drm/xe/guc: Check GuC running state before deregistering exec
    queue (git-fixes).
  - drm/sched: Fix potential double free in
    drm_sched_job_add_resv_dependencies (git-fixes).
  - accel/qaic: Synchronize access to DBC request queue head &
    tail pointer (git-fixes).
  - accel/qaic: Treat remaining == 0 as error in
    find_and_map_user_pages() (git-fixes).
  - accel/qaic: Fix bootlog initialization ordering (git-fixes).
  - drm/rockchip: vop2: use correct destination rectangle height
    check (git-fixes).
  - drm/bridge: lt9211: Drop check for last nibble of version
    register (git-fixes).
  - drm/panthor: Ensure MCU is disabled on suspend (git-fixes).
  - drm/amdgpu: fix gfx12 mes packet status return check
    (stable-fixes).
  - drm/amd/powerplay: Fix CIK shutdown temperature (git-fixes).
  - drm/amdgpu: use atomic functions with memory barriers for vm
    fault info (git-fixes).
  - drm/amdgpu: fix handling of harvesting for ip_discovery firmware
    (git-fixes).
  - drm/i915/guc: Skip communication warning on reset in progress
    (git-fixes).
  - can: m_can: m_can_chip_config(): bring up interface in correct
    state (git-fixes).
  - can: m_can: m_can_handle_state_errors(): fix CAN state
    transition to Error Active (git-fixes).
  - can: m_can: m_can_plat_remove(): add missing
    pm_runtime_disable() (git-fixes).
  - can: gs_usb: gs_make_candev(): populate net_device->dev_port
    (git-fixes).
  - can: gs_usb: increase max interface to U8_MAX (git-fixes).
  - ASoC: SOF: ipc4-pcm: fix start offset calculation for chain DMA
    (git-fixes).
  - ASoC: SOF: ipc4-pcm: fix delay calculation when DSP resamples
    (git-fixes).
  - clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
    (git-fixes).
  - clk: nxp: lpc18xx-cgu: convert from round_rate() to
    determine_rate() (stable-fixes).
  - drm/amdgpu: add support for cyan skillfish without IP discovery
    (stable-fixes).
  - drm/amdgpu: add ip offset support for cyan skillfish
    (stable-fixes).
  - ACPI: property: Do not pass NULL handles to acpi_attach_data()
    (git-fixes).
  - ACPI: property: Add code comments explaining what is going on
    (stable-fixes).
  - ACPI: property: Disregard references in data-only subnode lists
    (stable-fixes).
  - ACPICA: Allow to skip Global Lock initialization (stable-fixes).
  - drm/exynos: exynos7_drm_decon: properly clear channels during
    bind (stable-fixes).
  - drm/exynos: exynos7_drm_decon: fix uninitialized crtc reference
    in functions (stable-fixes).
  - commit fba5dbc
  - spi: cadence-quadspi: Implement refcount to handle unbind
    during busy (CVE-2025-40005 bsc#1252349).
  - commit 3246504

++++ kernel-firmware-amdgpu:

  - Update to version 20251024 (git commit 9b899c779b8a):
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates for various ASICs
  - Update aliases

++++ kernel-firmware-bluetooth:

  - Update to version 20251024 (git commit 9b899c779b8a):
    * QCA: Update Bluetooth WCN6856 firmware 2.1.0-00653 to 2.1.0-00659

++++ kernel-firmware-mediatek:

  - Update to version 20251024 (git commit 9b899c779b8a):
    * mediatek MT7920: update bluetooth firmware to 20251020151255
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7920 WiFi device
    * mediatek MT7922: update bluetooth firmware to 20251020143443
    * Revert "linux-firmware: update firmware for MT7922 WiFi device"

++++ kernel-rt:

  - scsi: libfc: Prevent integer overflow in fc_fcp_recv_data()
    (git-fixes).
  - md: fix mssing blktrace bio split events (git-fixes).
  - commit 8af9b0e
  - scsi: storvsc: Prefer returning channel with the same CPU as on the I/O issuing CPU (bsc#1252267).
  - hyperv: Remove the spurious null directive line (git-fixes).
  - Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes).
  - Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes).
  - Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes).
  - mshv: Handle NEED_RESCHED_LAZY before transferring to guest (git-fixes).
  - x86/hyperv: Add kexec/kdump support on Azure CVMs (git-fixes).
  - Drivers: hv: util: Cosmetic changes for hv_utils_transport.c (git-fixes).
  - clocksource: hyper-v: Skip unnecessary checks for the root partition (git-fixes).
  - hyperv: Add missing field to hv_output_map_device_interrupt (git-fixes).
  - uio_hv_generic: Let userspace take care of interrupt mask (git-fixes).
  - scsi: storvsc: Remove redundant ternary operators (git-fixes).
  - net: mana: Reduce waiting time if HWC not responding (git-fixes).
  - commit dc5fea5
  - amd-pstate-ut: Reset amd-pstate driver mode after running
    selftests (bsc#1249226).
  - commit 62def1a
  - cpufreq/amd-pstate: Fix a regression leading to EPP 0 after
    hibernate (git-fixes).
  - commit 60d54b4
  - ACPI: platform-profile: Fix CFI violation when accessing sysfs
    files (git-fixes).
  - commit 6a68087
  - tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request()
    (git-fixes).
  - commit 9b6914d
  - octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()
    (CVE-2025-39978 bsc#1252069).
  - tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect()
    (CVE-2025-39955 bsc#1251804).
  - commit 63120f8
  - wifi: rtw89: fix use-after-free in
    rtw89_core_tx_kick_off_and_wait() (CVE-2025-40000 bsc#1252062).
  - commit 247f800
  - most: usb: hdm_probe: Fix calling put_device() before device
    initialization (git-fixes).
  - most: usb: Fix use-after-free in hdm_disconnect (git-fixes).
  - misc: fastrpc: Fix dma_buf object leak in fastrpc_map_lookup
    (git-fixes).
  - serial: 8250_mtk: Enable baud clock and manage in runtime PM
    (git-fixes).
  - serial: 8250_dw: handle reset control deassert error
    (git-fixes).
  - serial: sc16is7xx: remove useless enable of enhanced features
    (git-fixes).
  - xhci: dbc: enable back DbC in resume if it was enabled before
    suspend (git-fixes).
  - xhci: dbc: fix bogus 1024 byte prefix if ttyDBC read races
    with stall event (git-fixes).
  - spi: airoha: fix reading/writing of flashes with more than
    one plane per lun (git-fixes).
  - spi: airoha: add support of dual/quad wires spi modes to
    exec_op() handler (git-fixes).
  - spi: airoha: return an error for continuous mode dirmap creation
    cases (git-fixes).
  - spi: spi-nxp-fspi: add extra delay after dll locked (git-fixes).
  - net: usb: rtl8150: Fix frame padding (git-fixes).
  - net: usb: lan78xx: fix use of improperly initialized dev->chipid
    in lan78xx_reset (git-fixes).
  - r8152: add error handling in rtl8152_driver_init (git-fixes).
  - r8169: fix packet truncation after S4 resume on
    RTL8168H/RTL8111H (git-fixes).
  - rtc: interface: Ensure alarm irq is enabled when UIE is enabled
    (stable-fixes).
  - rtc: interface: Fix long-standing race when setting alarm
    (stable-fixes).
  - PCI: endpoint: pci-epf-test: Add NULL check for DMA channels
    before release (git-fixes).
  - PCI/AER: Support errors introduced by PCIe r6.0 (stable-fixes).
  - phy: cadence: cdns-dphy: Update calibration wait time for
    startup state machine (git-fixes).
  - phy: cadence: cdns-dphy: Fix PLL lock and O_CMN_READY polling
    (git-fixes).
  - phy: cdns-dphy: Store hs_clk_rate and return it (stable-fixes).
  - mtd: rawnand: fsmc: Default to autodetect buswidth
    (stable-fixes).
  - wifi: mt76: mt7921u: Add VID/PID for Netgear A7500
    (stable-fixes).
  - wifi: mt76: mt7925u: Add VID/PID for Netgear A9000
    (stable-fixes).
  - media: vivid: fix disappearing <Vendor Command With ID> messages
    (git-fixes).
  - media: nxp: imx8-isi: Drop unused argument to
    mxc_isi_channel_chain() (stable-fixes).
  - mfd: intel_soc_pmic_chtdc_ti: Set use_single_read regmap_config
    flag (git-fixes).
  - mmc: mmc_spi: multiple block read remove read crc ack
    (stable-fixes).
  - mmc: core: SPI mode remove cmd7 (stable-fixes).
  - lib/crypto/curve25519-hacl64: Disable KASAN with clang-17 and
    older (stable-fixes).
  - PM: runtime: Add new devm functions (stable-fixes).
  - mfd: intel_soc_pmic_chtdc_ti: Drop unneeded assignment for
    cache_type (stable-fixes).
  - mfd: intel_soc_pmic_chtdc_ti: Fix invalid regmap-config
    max_register value (stable-fixes).
  - net: usb: lan78xx: Add error handling to
    lan78xx_init_mac_address (stable-fixes).
  - PCI: endpoint: Remove surplus return statement from
    pci_epf_test_clean_dma_chan() (stable-fixes).
  - commit 7cc4d1c
  - drm/panic: Fix qr_code, ensure vmargin is positive (git-fixes).
  - firmware: arm_scmi: Fix premature SCMI_XFER_FLAG_IS_RAW clearing
    in raw mode (git-fixes).
  - firmware: arm_scmi: Account for failed debug initialization
    (git-fixes).
  - hwmon: (sht3x) Fix error handling (git-fixes).
  - gpio: ljca: Fix duplicated IRQ mapping (git-fixes).
  - gpio: pci-idio-16: Define maximum valid register address offset
    (git-fixes).
  - gpio: 104-idio-16: Define maximum valid register address offset
    (git-fixes).
  - HID: multitouch: fix name of Stylus input devices (git-fixes).
  - HID: hid-input: only ignore 0 battery events for digitizers
    (git-fixes).
  - commit 07ce516
  - ASoC: SOF: ipc4-pcm: Enable delay reporting for ChainDMA streams
    (stable-fixes).
  - Refresh
    patches.suse/ASoC-SOF-ipc4-topology-Correct-the-minimum-host-DMA-.patch.
  - commit fc33a6f
  - drm/panic: Fix drawing the logo on a small narrow screen
    (git-fixes).
  - drm/panthor: Fix kernel panic on partial unmap of a GPU VA
    region (git-fixes).
  - drm/amd/display: use GFP_NOWAIT for allocation in interrupt
    handler (git-fixes).
  - can: netlink: can_changelink(): allow disabling of automatic
    restart (git-fixes).
  - can: rockchip-canfd: rkcanfd_start_xmit(): use
    can_dev_dropped_skb() instead of can_dropped_invalid_skb()
    (git-fixes).
  - can: esd: acc_start_xmit(): use can_dev_dropped_skb() instead
    of can_dropped_invalid_skb() (git-fixes).
  - can: bxcan: bxcan_start_xmit(): use can_dev_dropped_skb()
    instead of can_dropped_invalid_skb() (git-fixes).
  - ASoC: nau8821: Add DMI quirk to bypass jack debounce circuit
    (git-fixes).
  - ASoC: nau8821: Generalize helper to clear IRQ status
    (git-fixes).
  - ASoC: nau8821: Cancel jdet_work before handling jack ejection
    (git-fixes).
  - ASoC: amd/sdw_utils: avoid NULL deref when devm_kasprintf()
    fails (git-fixes).
  - ASoC: codecs: Fix gain setting ranges for Renesas IDT821034
    codec (git-fixes).
  - ALSA: usb-audio: Fix NULL pointer deference in
    try_to_register_card (git-fixes).
  - ALSA: firewire: amdtp-stream: fix enum kernel-doc warnings
    (git-fixes).
  - drm/xe/guc: Check GuC running state before deregistering exec
    queue (git-fixes).
  - drm/sched: Fix potential double free in
    drm_sched_job_add_resv_dependencies (git-fixes).
  - accel/qaic: Synchronize access to DBC request queue head &
    tail pointer (git-fixes).
  - accel/qaic: Treat remaining == 0 as error in
    find_and_map_user_pages() (git-fixes).
  - accel/qaic: Fix bootlog initialization ordering (git-fixes).
  - drm/rockchip: vop2: use correct destination rectangle height
    check (git-fixes).
  - drm/bridge: lt9211: Drop check for last nibble of version
    register (git-fixes).
  - drm/panthor: Ensure MCU is disabled on suspend (git-fixes).
  - drm/amdgpu: fix gfx12 mes packet status return check
    (stable-fixes).
  - drm/amd/powerplay: Fix CIK shutdown temperature (git-fixes).
  - drm/amdgpu: use atomic functions with memory barriers for vm
    fault info (git-fixes).
  - drm/amdgpu: fix handling of harvesting for ip_discovery firmware
    (git-fixes).
  - drm/i915/guc: Skip communication warning on reset in progress
    (git-fixes).
  - can: m_can: m_can_chip_config(): bring up interface in correct
    state (git-fixes).
  - can: m_can: m_can_handle_state_errors(): fix CAN state
    transition to Error Active (git-fixes).
  - can: m_can: m_can_plat_remove(): add missing
    pm_runtime_disable() (git-fixes).
  - can: gs_usb: gs_make_candev(): populate net_device->dev_port
    (git-fixes).
  - can: gs_usb: increase max interface to U8_MAX (git-fixes).
  - ASoC: SOF: ipc4-pcm: fix start offset calculation for chain DMA
    (git-fixes).
  - ASoC: SOF: ipc4-pcm: fix delay calculation when DSP resamples
    (git-fixes).
  - clk: nxp: Fix pll0 rate check condition in LPC18xx CGU driver
    (git-fixes).
  - clk: nxp: lpc18xx-cgu: convert from round_rate() to
    determine_rate() (stable-fixes).
  - drm/amdgpu: add support for cyan skillfish without IP discovery
    (stable-fixes).
  - drm/amdgpu: add ip offset support for cyan skillfish
    (stable-fixes).
  - ACPI: property: Do not pass NULL handles to acpi_attach_data()
    (git-fixes).
  - ACPI: property: Add code comments explaining what is going on
    (stable-fixes).
  - ACPI: property: Disregard references in data-only subnode lists
    (stable-fixes).
  - ACPICA: Allow to skip Global Lock initialization (stable-fixes).
  - drm/exynos: exynos7_drm_decon: properly clear channels during
    bind (stable-fixes).
  - drm/exynos: exynos7_drm_decon: fix uninitialized crtc reference
    in functions (stable-fixes).
  - commit fba5dbc
  - spi: cadence-quadspi: Implement refcount to handle unbind
    during busy (CVE-2025-40005 bsc#1252349).
  - commit 3246504

++++ python-PyJWT:

  - Remove not needed update-alternatives requirement.

++++ ucode-amd:

  - Update to version 20251024 (git commit 9b899c779b8a):
    * amd-ucode: Fix minimum revisions in README

------------------------------------------------------------------
------------------  2025-10-26  -  Oct 26 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - i40e: fix idx validation in config queues msg (CVE-2025-39971 bsc#1252052)
  - commit 61648b1
  - i40e: fix input validation logic for action_meta (CVE-2025-39970 bsc#1252051)
  - commit 333e729
  - scsi: mpt3sas: Fix crash in transport port remove by using
    ioc_info() (git-fixes).
  - scsi: hpsa: Fix potential memory leak in
    hpsa_big_passthru_ioctl() (git-fixes).
  - scsi: pm80xx: Fix pm8001_abort_task() for chip_8006 when using
    an expander (git-fixes).
  - scsi: pm80xx: Add helper function to get the local phy id
    (git-fixes).
  - scsi: pm80xx: Use dev_parent_is_expander() helper (git-fixes).
  - scsi: libsas: Add dev_parent_is_expander() helper (git-fixes).
  - scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
    (git-fixes).
  - scsi: core: sysfs: Correct sysfs attributes access rights
    (git-fixes).
  - scsi: Fix sas_user_scan() to handle wildcard and multi-channel
    scans (git-fixes).
  - scsi: aacraid: Stop using PCI_IRQ_AFFINITY (git-fixes).
  - commit 3570466

++++ kernel-rt:

  - i40e: fix idx validation in config queues msg (CVE-2025-39971 bsc#1252052)
  - commit 61648b1
  - i40e: fix input validation logic for action_meta (CVE-2025-39970 bsc#1252051)
  - commit 333e729
  - scsi: mpt3sas: Fix crash in transport port remove by using
    ioc_info() (git-fixes).
  - scsi: hpsa: Fix potential memory leak in
    hpsa_big_passthru_ioctl() (git-fixes).
  - scsi: pm80xx: Fix pm8001_abort_task() for chip_8006 when using
    an expander (git-fixes).
  - scsi: pm80xx: Add helper function to get the local phy id
    (git-fixes).
  - scsi: pm80xx: Use dev_parent_is_expander() helper (git-fixes).
  - scsi: libsas: Add dev_parent_is_expander() helper (git-fixes).
  - scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod
    (git-fixes).
  - scsi: core: sysfs: Correct sysfs attributes access rights
    (git-fixes).
  - scsi: Fix sas_user_scan() to handle wildcard and multi-channel
    scans (git-fixes).
  - scsi: aacraid: Stop using PCI_IRQ_AFFINITY (git-fixes).
  - commit 3570466

------------------------------------------------------------------
------------------  2025-10-25  -  Oct 25 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - arm64, mm: avoid always making PTE dirty in pte_mkwrite() (git-fixes)
  - commit da7d611
  - arm64: errata: Apply workarounds for Neoverse-V3AE (git-fixes)
  - commit 986e15f
  - arm64: cputype: Add Neoverse-V3AE definitions (git-fixes)
  - commit 47240ca

++++ kernel-rt:

  - arm64, mm: avoid always making PTE dirty in pte_mkwrite() (git-fixes)
  - commit da7d611
  - arm64: errata: Apply workarounds for Neoverse-V3AE (git-fixes)
  - commit 986e15f
  - arm64: cputype: Add Neoverse-V3AE definitions (git-fixes)
  - commit 47240ca

------------------------------------------------------------------
------------------  2025-10-24  -  Oct 24 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: mpi3mr: Drop unnecessary volatile from __iomem pointers
    (git-fixes).
  - Refresh
    patches.suse/scsi-mpi3mr-Serialize-admin-queue-BAR-writes-on-32-bit-sys.patch.
  - commit 51bb9bc
  - scsi: mpt3sas: Correctly handle ATA device errors (git-fixes).
  - scsi: mpi3mr: Correctly handle ATA device errors (git-fixes).
  - commit 38e545b
  - kABI: fix for struct hrtimer_cpu_base (CVE-2025-21816 bsc#1238472)
  - commit 0177587
  - xfs: rename the old_crc variable in xlog_recover_process
    (git-fixes).
  - commit a33e036
  - NFSD: Minor cleanup in layoutcommit processing (git-fixes).
  - commit 0111c00
  - NFSD: Rework encoding and decoding of nfsd4_deviceid
    (git-fixes).
  - commit 9c6f966
  - nfsd: Drop dprintk in blocklayout xdr functions (git-fixes).
  - commit 6cb9aff
  - nfsd: Use correct error code when decoding extents (git-fixes).
  - commit 080ee5e

++++ kernel-rt:

  - scsi: mpi3mr: Drop unnecessary volatile from __iomem pointers
    (git-fixes).
  - Refresh
    patches.suse/scsi-mpi3mr-Serialize-admin-queue-BAR-writes-on-32-bit-sys.patch.
  - commit 51bb9bc
  - scsi: mpt3sas: Correctly handle ATA device errors (git-fixes).
  - scsi: mpi3mr: Correctly handle ATA device errors (git-fixes).
  - commit 38e545b
  - kABI: fix for struct hrtimer_cpu_base (CVE-2025-21816 bsc#1238472)
  - commit 0177587
  - xfs: rename the old_crc variable in xlog_recover_process
    (git-fixes).
  - commit a33e036
  - NFSD: Minor cleanup in layoutcommit processing (git-fixes).
  - commit 0111c00
  - NFSD: Rework encoding and decoding of nfsd4_deviceid
    (git-fixes).
  - commit 9c6f966
  - nfsd: Drop dprintk in blocklayout xdr functions (git-fixes).
  - commit 6cb9aff
  - nfsd: Use correct error code when decoding extents (git-fixes).
  - commit 080ee5e

------------------------------------------------------------------
------------------  2025-10-23  -  Oct 23 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - blk-zoned: Fix a lockdep complaint about recursive locking
    (git-fixes).
  - block: fix kobject double initialization in add_disk
    (git-fixes).
  - lib/sbitmap: convert shallow_depth from one word to the whole
    sbitmap (git-fixes).
  - block: avoid possible overflow for chunk_sectors check in
    blk_stack_limits() (git-fixes).
  - commit 213ae89
  - net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (CVE-2025-39876 bsc#1250400)
  - commit 3be7e1e
  - proc: fix type confusion in pde_set_flags() (bsc#1248630)
  - commit 12ef5f2
  - proc: fix missing pde_set_flags() for net proc files (bsc#1248630)
  - commit 9aac12e
  - proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653 bsc#1248630)
  - commit 038e313
  - add bug reference to existing hv_netvsc change (bsc#1252265)
  - commit bded92b
  - fs/xattr.c: fix simple_xattr_list() (git-fixes).
  - commit 0c27ee1

++++ kernel-rt:

  - blk-zoned: Fix a lockdep complaint about recursive locking
    (git-fixes).
  - block: fix kobject double initialization in add_disk
    (git-fixes).
  - lib/sbitmap: convert shallow_depth from one word to the whole
    sbitmap (git-fixes).
  - block: avoid possible overflow for chunk_sectors check in
    blk_stack_limits() (git-fixes).
  - commit 213ae89
  - net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (CVE-2025-39876 bsc#1250400)
  - commit 3be7e1e
  - proc: fix type confusion in pde_set_flags() (bsc#1248630)
  - commit 12ef5f2
  - proc: fix missing pde_set_flags() for net proc files (bsc#1248630)
  - commit 9aac12e
  - proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (CVE-2025-38653 bsc#1248630)
  - commit 038e313
  - add bug reference to existing hv_netvsc change (bsc#1252265)
  - commit bded92b
  - fs/xattr.c: fix simple_xattr_list() (git-fixes).
  - commit 0c27ee1

++++ unbound:

  - Update to 1.24.1:
    Security Fixes:
    * Fix CVE-2025-11411 (possible domain hijacking attack)
    [bsc#1252525]
    Features:
    * Increase default to num-queries-per-thread: 2048, when unbound
    is compiled with libevent. It makes saturation of the task
    queue more resource intensive and less practical.
    * Auto-configure '-slabs' values.
    * Change default for so-sndbuf to 1m, to mitigate a cross-layer
    issue where the UDP socket send buffers are exhausted waiting
    for ARP/NDP resolution.
    * Adjusted so-sndbuf default to 4m.
    * Add extra statistic to track the number of signature validation
    operations. Adds 'num.valops' to extended statistics.
    * [FR] Disable TLSv1.2.
    * unbound-control cache_lookup prints the cached rrsets and
    messages for those.
    * unbound-control cache_lookup +t allows tld and root names. And
    subnet cache contents are printed.
    * [FR] zone status for Unbound auth-zones.
    Bug Fixes:
    * Fix assertion failure testcode/unitverify.c:202.
    * Use macros for the fr_check_changed* functions.
    * Fix for parallel build of dnstap protoc-c output.
    * Fix dnstap to use protoc.
    * Sync unbound and unbound-checkconf log output for unknown
    modules.
    * Fix forward-zone "name: ." conflicts with auth-zone "name: ."
    in 1.23.0, but worked in 1.22.0.
    * Fix unsafe usage of atoi() while parsing the configuration
    file.
    * Fix auth nsec3 code. Fixes NSEC3 code to not break on broken
    auth zones that include unsigned out of zone (above apex) data.
    Could lead to hang while trying to prove a wildcard answer.
    * Fix NULL pointer deref in az_find_nsec_cover() (latent bug) by
    adding a log_assert() to safeguard future development.
    * Fix log-destaddr fail on long ipv6 addresses.
    * Fix config of slab values when there is no config file.
    * Fix for cname chain length with qtype ANY and qname
    minimisation.
    * RST man pages. It introduces restructuredText man pages to sync
    the online and source code man page documentation. The
    templated man pages (*.in) are still part of the repo but
    generated with docutils from their .rst counterpart.
    Documentation on how to generate those (mainly for core
    developers) is in README.man.
    * Add more checks about respip in unbound-checkconf. Also fixes
    unbound-checkconf not reporting RPZ configuration error.
    * [FR] Improve fuzzing of unbound by adapting the netbound
    program.
    * Small manpage corrections for the 'disable-dnssec-lame-check'
    option.
    * Fix unbound-anchor certificate file read for line ends and end
    of file.
    * Fix comment for the dname_remove_label_limit_len function.
    * iana portlist updated.
    * Fix bitwise operators in conditional expressions with
    parentheses.
    * Fix conditional expressions with parentheses for bitwise and.
    * Fix header return value description for skip_pkt_rrs and
    parse_edns_from_query_pkt.
    * Fix to check control-interface addresses in unbound-checkconf.
    * Fix Windows 32-bit binaries download seems to be missing dll
    dependency.
    * Fix for consistent use of local zone CNAME alias for configured
    auth zones. Now it also applies to downstream configured auth
    zones.
    * Fix DNS over QUIC depends on a very outdated version of ngtcp2.
    Fixed so it works with ngtcp2 1.13.0 and OpenSSL 3.5.0.
    * edns-subnet: fix NULL_AFTER_DEREF on subnetmod.
    * Fix rrset cache create allocation failure case.
    * Fix EDE 6 is attached to insecure cached answers when client
    sends the CD bit.
    * Fix forward-first: ssl handshake failed on root nameservers.
    * Turn off fetch-policy for delegation when looking into parent
    side name servers that may not update the addresses and hit
    NXNS limits.
    * Replay test (added tcp_transport to outnet_serviced_query).
    * Generate ltmain.sh and configure again.
    * Fix is 'sock-queue-timeout' a linux only feature.
    * Implement sock-queue-timeout for FreeBSD as well.
    * Fix layout of comm_point_udp_ancil_callback.
    * Fix to improve dnstap discovery on Fedora.
    * Fix detection of SSL_CTX_set_tmp_ecdh function.
    * Fix configure cant find SSL_is_quic in OpenSSL 3.5.1.
    * Test num.valops in existing stat_values.tdir.
    * Add num.valops in the unbound-control man page.
    * Add unit tests for non-ecs aggregation.
    * Fix to not set rlimits in the unit tests.
    * iana portlist updated.
    * Redis checks for server down and throttles reconnects.
    * Fix redis cachedb module gettimeofday init failure.
    * Fix testbound test program to accurately output packets from
    hex.
    * Fix incorrectly reclaimed tcp handler can cause data corruption
    and segfault.
    * Fix to use assertions for consistency checks in reclaimed tcp
    handlers.
    * Fix edns subnet, so that the subquery without subnet is stored
    in global cache if the querier used 0.0.0.0/0 and the name and
    address do not receive subnet treatment. If the name and
    address are configured for subnet, it is stored in the subnet
    cache.
    * Fix dname_str for printout of long names.
    * Fix that edns-subnet failure to create a subquery errors as
    servfail, and not formerror.
    * Fix to whitespace in dname_str.
    * Fix that unbound-control dump_cache releases the cache locks
    every so often, so that the server stays responsive.
    * Fix to remove debug from cache_lookup.
    * Fix to unlock cache_lookup message for malformed records.
    * Fix to increase responsiveness of dump_cache.
    * Fix to decouple file descriptor activity and cache lookups in
    dump_cache.
    * Fix cache_lookup subnet printout to wipe zero part of the
    prefix.
    * Fix cache_lookup subnet print to not print messages without
    rrsets and perform in-depth check on node in the addrtree.
    * Fix to check for extraneous command arguments for
    unbound-control, when the command takes no arguments but there
    are arguments present.
    * Fix contrib/unbound.service comment path for systemd network
    configuration.
    * Fix compile warnings for DoH compile on windows.
    * Fix sha1 enable environment variable in test code on windows.
    * Fix that the zone acquired timestamp is set after the zonefile
    is read.
    * Fix unbound-control dump_cache for double unlock of lruhash
    table.
    * Fix setup_listen_sslctx warning for nettle compile.
    * Limit the number of consecutive reads on an HTTP/2 session.
    * Fix to free edns options scratch in ratelimit case.
    * Fix outdated Python2 code in unbound/pythonmod/examples/log.py.
    * Fix memory leak in 'msgparse.c' in
    'parse_edns_options_from_query(...)'.
    * Fix indentation in tcp-mss option parsing.
    * Fix make depend.
    * Update documentation for using "SET ... EX" in Redis.
    * Document max buffer sizes for Redis commands.
    * Update man pages.
    * Fix CNAME chains are sometimes not followed when RPZs add a
    local CNAME rewrite.
    * Update contrib/aaaa-filter-iterator.patch so it applies on
    1.24.0.
    * Small debug output improvement when attaching an EDE.
    * Fix to print warning for when so-sndbuf setsockopt is not
    granted.
    * Too many quotes for the EDE message debug printout.

++++ osinfo-db:

  - bsc#1252429 - virt-manager does not detect Leap 16.0 offline ISO
    add-opensuse-leap-16.0-support.patch

------------------------------------------------------------------
------------------  2025-10-22  -  Oct 22 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - net/tcp: Fix a NULL pointer dereference when using TCP-AO with
    TCP_REPAIR (CVE-2025-39950 bsc#1251176).
  - commit cf7da46
  - x86/virt/tdx: Mark memory cache state incoherent when making SEAMCALL (jsc#PED-348).
  - Delete
    patches.suse/x86-virt-tdx-Mark-memory-cache-state-incoherent-when-making-seamcall.patch.
  - commit 4525f45
  - perf hwmon_pmu: Fix uninitialized variable warning
    (perf-sle16-v6.13-userspace-update, git-fixes).
  - commit ce493c8

++++ kernel-rt:

  - net/tcp: Fix a NULL pointer dereference when using TCP-AO with
    TCP_REPAIR (CVE-2025-39950 bsc#1251176).
  - commit cf7da46
  - x86/virt/tdx: Mark memory cache state incoherent when making SEAMCALL (jsc#PED-348).
  - Delete
    patches.suse/x86-virt-tdx-Mark-memory-cache-state-incoherent-when-making-seamcall.patch.
  - commit 4525f45
  - perf hwmon_pmu: Fix uninitialized variable warning
    (perf-sle16-v6.13-userspace-update, git-fixes).
  - commit ce493c8

++++ gpgme:

  - Treat empty DISPLAY variable as unset. [bsc#1252425, bsc#1231055]
    * To avoid gpgme constructing an invalid gpg command line when
    the DISPLAY variable is empty it can be treated as unset.
    * Add gpgme-Treat-empty-DISPLAY-variable-as-unset.patch
    * Reported upstream: dev.gnupg.org/T7919

++++ pciutils:

  - pciutils.spec: Add a strict dependency to libpci. [bsc#1252338]
    Mixing different versions of pciutils and libpci could result in
    a segmentation fault due to incompatible ABI.

------------------------------------------------------------------
------------------  2025-10-21  -  Oct 21 2025  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.700.g40f7c5c4:
    Additional fixes for PXE boot with filled-in NBFT (bsc#1238848):
    * fix(74nvmf): make sure autoconnect script is run at least once
    * fix(74nvmf): only set netroot if it's yet empty

++++ kernel-default:

  - kbuild/modfinal: Link livepatches with module-common.o
    (bsc#1218644, bsc#1252270).
  - commit 6e2ca7b
  - ixgbe: fix too early devlink_free() in ixgbe_remove()
    (git-fixes).
  - ixgbe: handle IXGBE_VF_FEATURES_NEGOTIATE mbox cmd
    (bsc#1247222).
  - ixgbevf: fix mailbox API compatibility by negotiating supported
    features (bsc#1247222).
  - ixgbe: handle IXGBE_VF_GET_PF_LINK_STATE mailbox operation
    (bsc#1247222).
  - ixgbevf: fix getting link speed data for E610 devices
    (bsc#1247222).
  - commit 350b510
  - btrfs: subpage: keep TOWRITE tag until folio is cleaned
    (bsc#1249495 CVE-2025-39779).
  - commit 27527fb
  - i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (CVE-2025-39911 bsc#1250704)
  - commit 963571a
  - sched: Fix sched_numa_find_nth_cpu() if mask offline (CVE-2025-39895 bsc#1250721)
  - commit 6265695
  - sctp: initialize more fields in sctp_v6_from_sk() (CVE-2025-39812 bsc#1250202)
  - commit faea944
  - of_numa: fix uninitialized memory nodes causing kernel panic (CVE-2025-39903 bsc#1250749)
  - commit 8722073

++++ kernel-rt:

  - kbuild/modfinal: Link livepatches with module-common.o
    (bsc#1218644, bsc#1252270).
  - commit 6e2ca7b
  - ixgbe: fix too early devlink_free() in ixgbe_remove()
    (git-fixes).
  - ixgbe: handle IXGBE_VF_FEATURES_NEGOTIATE mbox cmd
    (bsc#1247222).
  - ixgbevf: fix mailbox API compatibility by negotiating supported
    features (bsc#1247222).
  - ixgbe: handle IXGBE_VF_GET_PF_LINK_STATE mailbox operation
    (bsc#1247222).
  - ixgbevf: fix getting link speed data for E610 devices
    (bsc#1247222).
  - commit 350b510
  - btrfs: subpage: keep TOWRITE tag until folio is cleaned
    (bsc#1249495 CVE-2025-39779).
  - commit 27527fb
  - i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (CVE-2025-39911 bsc#1250704)
  - commit 963571a
  - sched: Fix sched_numa_find_nth_cpu() if mask offline (CVE-2025-39895 bsc#1250721)
  - commit 6265695
  - sctp: initialize more fields in sctp_v6_from_sk() (CVE-2025-39812 bsc#1250202)
  - commit faea944
  - of_numa: fix uninitialized memory nodes causing kernel panic (CVE-2025-39903 bsc#1250749)
  - commit 8722073

++++ samba:

  - Update to 4.22.6
    * macOS Finder client DFS broken on 4.22.0; (bso#15843).
    * Samba 4.22 breaks Time Machine; (bso#15926).
    * Spotlight search restriction for shares incomplete and
    default search searches in too many attributes; (bso#15927).
    * rpcd_mdssvc may crash because name mangling is not
    initialized; (bso#15931).
    * Only increment lease epoch if a lease was granted;
    (bso#15933).
    * samba-4.21 fails to join AD when multiple DCs are returned;
    (bso#15905).
    * 'net ads group' failed to list domain groups; (bso#15900).
    * vfs_ceph_new should not use ceph_ll_nonblocking_readv_writev
    for fsync_send; (bso#15919).
    * CTDB_SOCKET can be used even when CTDB_TEST_MODE is not set;
    (bso#15921).

++++ sqlite3:

  - bsc#1252217: Add a %license file.

------------------------------------------------------------------
------------------  2025-10-20  -  Oct 20 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Update to 342
    * 342
  - Bug fixes and translation updates
    * 341
  - Improved UX for Disks and Network interface tables
  - Bug fixes and translation updates
    * 340
  - Use exclusive VNC connections with "Remote resizing"
  - Drop hostadd-allow-device-form-to-overflow-on-X-axis.patch as this has
    been upstreamed

++++ cockpit-podman:

  - Update to 115
    * 115
  - List stopped quadlets
  - Translations and dependency updates
    * 114
  - Bug fixes and translation updates
    * 113
  - Sortable Images table

++++ kernel-default:

  - ipv6: sr: Fix MAC comparison to be constant-time (CVE-2025-39702 bsc#1249317)
  - commit 01c4905
  - sctp: linearize cloned gso packets in sctp_rcv (CVE-2025-38718 bsc#1249161)
  - commit dadd6c3
  - scsi: qla4xxx: Prevent a potential error pointer dereference (CVE-2025-39676 bsc#1249302)
  - commit 7b25b2e
  - io_uring: fix incorrect io_kiocb reference in io_link_skb (CVE-2025-39963 bsc#1251819)
  - commit 69302e5
  - dpll: zl3073x: Handle missing or corrupted flash configuration
    (bsc#1252253).
  - dpll: zl3073x: Increase maximum size of flash utility
    (bsc#1252253).
  - dpll: zl3073x: Fix double free in zl3073x_devlink_flash_update()
    (bsc#1252253).
  - dpll: zl3073x: Implement devlink flash callback (bsc#1252253).
  - dpll: zl3073x: Refactor DPLL initialization (bsc#1252253).
  - dpll: zl3073x: Add firmware loading functionality (bsc#1252253).
  - dpll: zl3073x: Add low-level flash functions (bsc#1252253).
  - dpll: zl3073x: Add functions to access hardware registers
    (bsc#1252253).
  - net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979
    bsc#1252067).
  - net/mlx5e: Harden uplink netdev access against device unbind
    (CVE-2025-39947 bsc#1251232).
  - dpll: zl3073x: Add support to get fractional frequency offset
    (bsc#1252253).
  - dpll: zl3073x: Add support to get phase offset on connected
    input pin (bsc#1252253).
  - dpll: zl3073x: Add support to get/set esync on pins
    (bsc#1252253).
  - net/mlx5: fs, add API for sharing HWS action by refcount
    (CVE-2025-39979 bsc#1252067).
  - commit fe6aeff
  - powerpc/fadump: skip parameter area allocation when fadump is
    disabled (jsc#PED-9891 git-fixes).
  - commit bdb01f7
  - nfsd: refine and rename NFSD_MAY_LOCK (git-fixes).
  - commit c7caa62
  - NFSD: Replace use of NFSD_MAY_LOCK in nfsd4_lock() (git-fixes).
  - commit 3a34ceb

++++ kernel-rt:

  - ipv6: sr: Fix MAC comparison to be constant-time (CVE-2025-39702 bsc#1249317)
  - commit 01c4905
  - sctp: linearize cloned gso packets in sctp_rcv (CVE-2025-38718 bsc#1249161)
  - commit dadd6c3
  - scsi: qla4xxx: Prevent a potential error pointer dereference (CVE-2025-39676 bsc#1249302)
  - commit 7b25b2e
  - io_uring: fix incorrect io_kiocb reference in io_link_skb (CVE-2025-39963 bsc#1251819)
  - commit 69302e5
  - dpll: zl3073x: Handle missing or corrupted flash configuration
    (bsc#1252253).
  - dpll: zl3073x: Increase maximum size of flash utility
    (bsc#1252253).
  - dpll: zl3073x: Fix double free in zl3073x_devlink_flash_update()
    (bsc#1252253).
  - dpll: zl3073x: Implement devlink flash callback (bsc#1252253).
  - dpll: zl3073x: Refactor DPLL initialization (bsc#1252253).
  - dpll: zl3073x: Add firmware loading functionality (bsc#1252253).
  - dpll: zl3073x: Add low-level flash functions (bsc#1252253).
  - dpll: zl3073x: Add functions to access hardware registers
    (bsc#1252253).
  - net/mlx5: fs, fix UAF in flow counter release (CVE-2025-39979
    bsc#1252067).
  - net/mlx5e: Harden uplink netdev access against device unbind
    (CVE-2025-39947 bsc#1251232).
  - dpll: zl3073x: Add support to get fractional frequency offset
    (bsc#1252253).
  - dpll: zl3073x: Add support to get phase offset on connected
    input pin (bsc#1252253).
  - dpll: zl3073x: Add support to get/set esync on pins
    (bsc#1252253).
  - net/mlx5: fs, add API for sharing HWS action by refcount
    (CVE-2025-39979 bsc#1252067).
  - commit fe6aeff
  - powerpc/fadump: skip parameter area allocation when fadump is
    disabled (jsc#PED-9891 git-fixes).
  - commit bdb01f7
  - nfsd: refine and rename NFSD_MAY_LOCK (git-fixes).
  - commit c7caa62
  - NFSD: Replace use of NFSD_MAY_LOCK in nfsd4_lock() (git-fixes).
  - commit 3a34ceb

++++ selinux-policy:

  - Update to version 20250627+git239.fcbf2d509:
    * fail2ban: bump module version
    * fail2ban: allow fail2ban to watch all log files and dirs (bsc#1251952)
    * fail2ban: fix typos in interface descriptions
    * fail2ban: tweak file context regex for /run/fail2ban
    * fail2ban: drop file context for old rc.d file
    * Allow wicket to manage its proc directories (bsc#1235731)
    * Allow NM to manage wicked pid files (bsc#1235731)
    * Allow NM to reach systemd unit files (bsc#1235731)
    * Make wicked script backwards compatible (bsc#1251923)
    * Allow snapper grub plugin to domtrans to bootloader_t (bsc#1251862)
    * Allow salt_t transition to rpm_script_t (bsc#1250696)
    * grub snapper plugin is now named 00-grub (bsc#1251793)
    * Assign alts_exec_t exec_file attribute (bsc#1250974)
    * Add equivalency between /srv/tomcat and /var/lib/tomcat (bsc#1251227)
    * Allow sshd_session_t write to wtmpdb
    * Support /usr/libexec/ssh as well as openssh folder
    * Set xenstored_use_store_type_domain boolean true(bsc#1247875)
    * Adjust guest and xguest users policy for sshd-session
    * Allow valkey-server create and use netlink_rdma_socket
    * Allow blueman get attributes of filesystems with extended attributes
    * Update files_search_base_file_types()
    * Introduce unconfined wicked_script_t (bsc#1205770, bsc#1250661)
    * Allow geoclue get attributes of the /dev/shm filesystem
    * Allow apcupsd get attributes of the /dev/shm filesystem
    * Allow sshd-session read cockpit pid files
    * Add /opt/.snapshots to the snapper file context (bsc#1232226)
    * Allow nfs generator create and use netlink sockets
    * Conditionally allow virt guests to read certificates in user home directories
    * xenstored_t needs CAP_SYS_ADMIN for XENSTORETYPE=domain (bsc#1247875)
    * Allow nfs-generator create and use udp sockets
    * Allow kdump search kdumpctl_tmp_t directories
    * Allow init open and read user tmp files
    * Fix the systemd_logind_stream_connect() interface
    * Allow staff and sysadm execute iotop using sudo
    * Allow sudodomains connect to systemd-logind over a unix socket
    * /boot/efi is dosfs_t and kdump needs to access it (bsc#1249370)
    * Add default contexts for sshd-seesion
    * Define types for new openssh executables
    * Fix systemd_manage_unit_symlinks() interface definition
    * Support coreos installation methods
    * Add a new type for systemd-ssh-issue PID files
    * Allow gnome-remote-desktop connect to unreserved ports
    * Zypper moves files in /var/tmp to /var/cache (bsc#1249052, bsc#1249435)
    * Allow mdadm the CAP_SYS_PTRACE capability
    * Allow iptables manage its private fifo_files in /tmp
    * Allow auditd manage its private run dirs
    * Revert "Allow virt_domain write to virt_image_t files"
    * Allow gdm create /etc/.pwd.lock with a file transition
    * Allow gdm bind a socket in the /run/systemd/userdbd directory
    * Allow nsswitch_domain connect to xdm over a unix domain socket
    * Allow systemd homed getattr all tmpfs files (bsc#1240883)
    * Allow systemd (PID 1) create lastlog entries
    * Allow systemd_homework_t transition pid files to lvm_var_run_t (bsc#1240883)
    * Allow gnome-remote-desktop speak with tabrmd over dbus (bsc#1244573)
    * Allow nm-dispatcher iscsi and sendmail plugins get pidfs attributes
    * Allow systemd-oomd watch tmpfs dirs
    * Allow chronyc the setgid and setuid capabilities
    * Label /usr/lib/systemd/systemd-ssh-issue with systemd_ssh_issue_exec_t
    * Allow stalld map sysfs files
    * Allow NetworkManager-dispatcher-winbind get pidfs attributes
    * Allow openvpn create and use generic netlink socket
    * policy_capabilities: remove estimated from released versions
    * policy_capabilities: add stub for userspace_initial_context
    * add netlink_xperm policy capability and nlmsg permission definitions
    * policy_capabilities: add ioctl_skip_cloexec
    * selinux-policy: add allow rule for tuned_ppd_t
    * selinux-policy: add allow rule for switcheroo_control_t
    * Label /run/audit with auditd_var_run_t
    * Allow virtqemud start a vm which uses nbdkit
    * Add nbdkit_signal() and nbdkit_signull() interfaces
    * Fix insights_client interfaces names
    * Add insights_core and insights_client interfaces
    * Fix selinux-autorelabel-generator label after upstream changes
    * Revert "Remove the mysql module sources"
    * Revert "Allow rasdaemon write access to sysfs (bsc#1229587)"
    * Reset postfix.fc to upstream, add alias instead
    * dist/targeted/modules.conf: enable slrnpull module
    * Allow bootupd delete symlinks in the /boot directory
    * Allow systemd-coredumpd capabilities in the user namespace
    * Allow openvswitch read virtqemud process state
    * Allow systemd-networkd to create leases directory
    * Apply generator template to selinux-autorelabel generator
    * Support virtqemud handle hotplug hostdev devices
    * Allow virtstoraged create qemu /var/run files
    * Allow unconfined_domain_type cap2_userns capabilities
    * Label /usr/libexec/postfix/tlsproxy with postfix_smtp_exec_t
    * Remove the mysql module sources
    * dist/targeted/modules.conf: Enable kmscon module (bsc#1238137)
    * Update kmscon policy module to kmscon version 9 (bsc#1238137)
    * Allow login to getattr pidfs
    * Allow systemd to map files under /sys
    * systemd: drop duplicate init_nnp_daemon_domain lines
    * Fix typo
    * Allow logwatch stream connect to opensmtpd
    * Allow geoclue read NetworkManager pid files
    * Allow unconfined user a file transition for creating sudo log directory
    * Allow virtqemud read/write inherited dri devices
    * Allow xdm_t create user namespaces
    * Update policy for login_userdomain
    * Add ppd_base_profile to file transition to get tuned_rw_etc_t type
    * Update policy for bootupd
    * Allow logwatch work with opensmtpd
    * Update dovecot policy for dovecot 2.4.1
    * Allow ras-mc-ctl write to sysfs files
    * Allow anaconda-generator get attributes of all filesystems
    * Add the rhcd_rw_fifo_files() interface
    * Allow systemd-coredump the sys_chroot capability
    * Allow hostapd write to socket files in /tmp
    * Recognize /var/home as an alternate path for /home
    * Label /var/lib/lastlog with lastlog_t
    * Allow virtqemud write to sysfs files
    * Allow irqbalance search sssd lib directories
    * Allow samba-dcerpcd send sigkills to passwd
    * Allow systemd-oomd watch dbus pid sock files
    * Allow some confined users read and map generic log files
    * Allow login_userdomain watch the /run/log/journal directory
    * Allow login_userdomain dbus chat with tuned-ppd
    * Allow login_userdomain dbus chat with switcheroo-control
    * Allow userdomain to connect to systemd-oomd over a unix socket
    * Add insights_client_delete_lib_dirs() interface
    * Allow virtqemud_t use its private tmpfs files (bsc#1242998)
    * Allow virtqemud_t setattr to /dev/userfaultfd (bsc#1242998)
    * Allow virtqemud_t read and write /dev/ptmx (bsc#1242998)
    * Extend virtqemud_t tcp_socket permissions (bsc#1242998)
    * Allow virtqemud_t to read and write generic pty (bsc#1242998)
    * Allow systemd-importd create and unlink init pid socket
    * Allow virtqemud handle virt_content_t chr files
    * Allow svirt read virtqemud fifo files
    * All sblim-sfcbd the dac_read_search capability
    * Allow sblim domain read systemd session files
    * Allow sblim-sfcbd execute dnsdomainname
    * Confine nfs-server generator
    * Allow systemd-timedated start/stop timemaster services
    * Allow "hostapd_cli ping" run as a systemd service
    * Allow power-profiles-daemon get attributes of filesystems with extended attributes
    * Allow 'oomctl dump' to interact with systemd-oomd
    * Basic functionality for systemd-oomd
    * Basic enablement for systemd-oomd
    * Allow samba-bgqd send to smbd over a unix datagram socket
    * Update kernel_secretmem_use()
    * Add the file/watch_mountns permission
    * Update systemd-generators policy
    * Allow plymouthd_t read proc files of systemd_passwd_agent (bsc#1245470)
    * Allow insights-client file transition for files in /var/tmp
    * Allow tuned-ppd manage tuned log files
    * Allow systemd-coredump mount on tmpfs filesystems
    * Update sssd_dontaudit_read_public_files()
    * Allow zram-generator raw read fixed disk device
    * Add fs_write_cgroup_dirs() and fs_setattr_cgroup_dirs() interfaces

------------------------------------------------------------------
------------------  2025-10-19  -  Oct 19 2025  -------------------
------------------------------------------------------------------

++++ util-linux-systemd:

  - lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682,
    util-linux-lscpu-add-arm64-NVIDIA-Olympus.patch).

++++ util-linux:

  - lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682,
    util-linux-lscpu-add-arm64-NVIDIA-Olympus.patch).

------------------------------------------------------------------
------------------  2025-10-17  -  Oct 17 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update to 349
    * Changes since 346
  - 349
    * Package manifests: add any test
    * Bug fixes and translation updates
  - 348
    * Bug fixes and translation updates
  - 347
    * Site-specific branding support

++++ kernel-default:

  - doc/README.SUSE: Correct the character used for TAINT_NO_SUPPORT
    The character was previously 'N', but upstream used it for TAINT_TEST,
    which prompted the change of TAINT_NO_SUPPORT to 'n'. This occurred in
    commit c35dc3823d08 ("Update to 6.0-rc1") on master and in d016c04d731d
    ("Bump to 6.4 kernel (jsc#PED-4593)") for SLE15-SP6 (and onwards).
    Update the documentation to reflect this change.
  - commit f42ecf5
  - cpufreq: Make drivers using CPUFREQ_ETERNAL specify transition
    latency (stable-fixes git-fixes).
  - commit 41821ef
  - cpufreq: CPPC: Avoid using CPUFREQ_ETERNAL as transition delay
    (stable-fixes).
  - commit 4f5afab
  - cpufreq: scmi: Account for malformed DT in
    scmi_dev_used_by_cpus() (git-fixes).
  - commit e9a9ed4
  - cpufreq: armada-8k: Fix off by one in
    armada_8k_cpufreq_free_table() (stable-fixes).
  - commit 1b00366
  - cpufreq: armada-8k: make both cpu masks static (git-fixes).
  - commit 3ab6135
  - cpufreq: sun50i: prevent out-of-bounds access (git-fixes).
  - commit 815165b
  - cpufreq: intel_pstate: Fix object lifecycle issue in
    update_qos_request() (git-fixes).
  - commit 330c599
  - skmsg: Return copied bytes in sk_msg_memcopy_from_iter
    (bsc#1250650).
  - commit 6650ce1

++++ kernel-rt:

  - doc/README.SUSE: Correct the character used for TAINT_NO_SUPPORT
    The character was previously 'N', but upstream used it for TAINT_TEST,
    which prompted the change of TAINT_NO_SUPPORT to 'n'. This occurred in
    commit c35dc3823d08 ("Update to 6.0-rc1") on master and in d016c04d731d
    ("Bump to 6.4 kernel (jsc#PED-4593)") for SLE15-SP6 (and onwards).
    Update the documentation to reflect this change.
  - commit f42ecf5
  - cpufreq: Make drivers using CPUFREQ_ETERNAL specify transition
    latency (stable-fixes git-fixes).
  - commit 41821ef
  - cpufreq: CPPC: Avoid using CPUFREQ_ETERNAL as transition delay
    (stable-fixes).
  - commit 4f5afab
  - cpufreq: scmi: Account for malformed DT in
    scmi_dev_used_by_cpus() (git-fixes).
  - commit e9a9ed4
  - cpufreq: armada-8k: Fix off by one in
    armada_8k_cpufreq_free_table() (stable-fixes).
  - commit 1b00366
  - cpufreq: armada-8k: make both cpu masks static (git-fixes).
  - commit 3ab6135
  - cpufreq: sun50i: prevent out-of-bounds access (git-fixes).
  - commit 815165b
  - cpufreq: intel_pstate: Fix object lifecycle issue in
    update_qos_request() (git-fixes).
  - commit 330c599
  - skmsg: Return copied bytes in sk_msg_memcopy_from_iter
    (bsc#1250650).
  - commit 6650ce1

++++ opensuse-migration-tool:

  - Update to version 20251017.e28f94c:
    * fix: remove the check for x86-64-v3 flag xsave from the v2 check

++++ virt-manager:

  - bsc#1252105 - Unable to create an SEV-SNP enabled guest with
    virt-manager. This simplifies the code from what used to be
    required for sev while adding initial tdx support.
    virtman-add-launch-security-support.patch
  - Dropped patches rolled into above the patch.
    virtman-add-sev-memory-support.patch
    virtinst-dont-require-uefi-for-sev-snp.patch

------------------------------------------------------------------
------------------  2025-10-16  -  Oct 16 2025  -------------------
------------------------------------------------------------------

++++ gstreamer:

  - Update to version 1.26.7:
    + Highlighted bugfixes in 1.26.7:
  - cea608overlay: improve handling of non-system memory
  - cuda: Fix runtime kernel compile with CUDA 13.0
  - d3d12: Fix crop meta support in converter and passthrough
    handling in deinterlacer
  - fallbacksrc: source handling improvements; no-more-pads
    signal for streams-unaware parents
  - inter: add properties to fine tune the inner elements
  - qtdemux: surround sound channel layout handling fixes and
    performance improvements for GoPro videos
  - rtp: Add linear audio (L8, L16, L24) RTP payloaders /
    depayloaders
  - rtspsrc: Send RTSP keepalives in TCP/interleaved modes
  - rtpamrpay2: frame quality indicator flag related fixes
  - rtpbasepay2: reuse last PTS when possible, to work around
    problems with NVIDIA Jetson AV1 encoder
  - mpegtsmux, tsdemux: Opus audio handling fixes
  - threadshare: latency related improvements and many other
    fixes
  - matroskamux, tsmux, flvmux, cea608mux: Best pad determination
    fixes at EOS
  - unixfd: support buffers with a big payload
  - videorate unknown buffer duration assertion failure with
    variable framerates
  - editing services: Make GESTimeline respect
    SELECT_ELEMENT_TRACK signal discard decision; memory leak
    fixes
  - gobject-introspection annotation fixes
  - cerbero: Update meson to 1.9.0 to enable Xcode 26
    compatibility
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - controller: Fix get_all() return type annotation
  - gst-launch: Do not assume error messages have a src element
  - multiqueue: Fix object reference handling in signal callbacks
  - netclientclock: Fix memory leak in error paths

++++ gstreamer-plugins-base:

  - Update to version 1.26.7:
    + discoverer: Mark gst_discoverer_stream_info_list_free() as
    transfer full
    + riff: Add channel reorder maps for 3 and 7 channel audio
    + sdp: proper usage of gst_buffer_append
    + videorate: fix assert fail due to invalid buffer duration
    + Fix build error with glib < 2.68

++++ kernel-default:

  - scsi: mpi3mr: Update driver version to 8.15.0.5.50
    (bsc#1251186).
  - scsi: mpi3mr: Fix premature TM timeouts on virtual drives
    (bsc#1251186).
  - scsi: mpi3mr: Update MPI headers to revision 37 (bsc#1251186).
  - scsi: mpi3mr: Fix I/O failures during controller reset
    (bsc#1251186).
  - scsi: mpi3mr: Fix controller init failure on fault during
    queue creation (bsc#1251186).
  - scsi: mpi3mr: Fix device loss during enclosure reboot due to
    zero link speed (bsc#1251186).
  - scsi: mpi3mr: Event processing debug improvement (bsc#1251186).
  - commit 15f7129
  - iommu/amd: Fix alias device DTE setting (git-fixes).
  - iommu/arm-smmu-v3: Fix smmu_domain->nr_ats_masters decrement
    (git-fixes).
  - iommu/amd: Enable PASID and ATS capabilities in the correct
    order (git-fixes).
  - commit 6e3bf58
  - tls: make sure to abort the stream if headers are bogus
    (CVE-2025-39946 bsc#1251114).
  - commit 97adb08
  - selftests/bpf: Add test for unpinning htab with internal timer
    struct (git-fixes).
  - commit 54bbdc7
  - bpf: Avoid RCU context warning when unpinning htab with internal
    structs (git-fixes).
  - commit 6cf3a66
  - bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6}
    (git-fixes).
  - commit 939b57e

++++ kernel-rt:

  - scsi: mpi3mr: Update driver version to 8.15.0.5.50
    (bsc#1251186).
  - scsi: mpi3mr: Fix premature TM timeouts on virtual drives
    (bsc#1251186).
  - scsi: mpi3mr: Update MPI headers to revision 37 (bsc#1251186).
  - scsi: mpi3mr: Fix I/O failures during controller reset
    (bsc#1251186).
  - scsi: mpi3mr: Fix controller init failure on fault during
    queue creation (bsc#1251186).
  - scsi: mpi3mr: Fix device loss during enclosure reboot due to
    zero link speed (bsc#1251186).
  - scsi: mpi3mr: Event processing debug improvement (bsc#1251186).
  - commit 15f7129
  - iommu/amd: Fix alias device DTE setting (git-fixes).
  - iommu/arm-smmu-v3: Fix smmu_domain->nr_ats_masters decrement
    (git-fixes).
  - iommu/amd: Enable PASID and ATS capabilities in the correct
    order (git-fixes).
  - commit 6e3bf58
  - tls: make sure to abort the stream if headers are bogus
    (CVE-2025-39946 bsc#1251114).
  - commit 97adb08
  - selftests/bpf: Add test for unpinning htab with internal timer
    struct (git-fixes).
  - commit 54bbdc7
  - bpf: Avoid RCU context warning when unpinning htab with internal
    structs (git-fixes).
  - commit 6cf3a66
  - bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4,6}
    (git-fixes).
  - commit 939b57e

++++ libsoup:

  - Update libsoup-CVE-2025-11021.patch: Add NULL check for
    soup_date_time_to_string() (bsc#1250562, CVE-2025-11021,
    glgo#GNOME/libsoup!483).

++++ nvidia-open-driver-G06-signed:

  - renamed check to %name-check package

++++ runc:

    [ This update was only released for SLE 12 and 15. ]
  - Backport patches for three CVEs. All three vulnerabilities ultimately allow
    (through different methods) for full container breakouts by bypassing runc's
    restrictions for writing to arbitrary /proc files. bsc#1252232
    * CVE-2025-31133
    * CVE-2025-52565
    * CVE-2025-52881
    + 2025-11-05-CVEs.patch

------------------------------------------------------------------
------------------  2025-10-15  -  Oct 15 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Update
    patches.suse/ASoC-qcom-q6apm-lpass-dais-Fix-NULL-pointer-derefere.patch
    (git-fixes CVE-2025-39938 bsc#1251134).
  - Update
    patches.suse/crypto-af_alg-Set-merge-to-zero-early-in-af_alg_send.patch
    (git-fixes CVE-2025-39931 bsc#1251100).
  - Update
    patches.suse/drm-bridge-anx7625-Fix-NULL-pointer-dereference-with.patch
    (git-fixes CVE-2025-39934 bsc#1251146).
  - Update
    patches.suse/net-rfkill-gpio-Fix-crash-due-to-dereferencering-uni.patch
    (git-fixes CVE-2025-39937 bsc#1251143).
  - Update
    patches.suse/wifi-mac80211-increase-scan_ies_len-for-S1G.patch
    (stable-fixes CVE-2025-39957 bsc#1251810).
  - Update
    patches.suse/wifi-wilc1000-avoid-buffer-overflow-in-WID-string-co.patch
    (stable-fixes CVE-2025-39952 bsc#1251216).
  - commit 6d21f77
  - iommu/vt-d: Disallow dirty tracking if incoherent page walk
    (git-fixes).
  - iommu/vt-d: PRS isn't usable if PDS isn't supported (git-fixes).
  - commit 9da8433
  - wifi: iwlwifi: Add missing firmware info for bz-b0-* models
    (bsc#1252084).
  - commit 7b5c81c
  - wifi: iwlwifi: config: unify fw/pnvm MODULE_FIRMWARE
    (bsc#1252084).
  - commit 2e309d0
  - mm/page_alloc: fix race condition in unaccepted memory handling
    (CVE-2025-38008 bsc#1244939).
  - commit c480181
  - mm/slub: avoid accessing metadata when pointer is invalid in
    object_err() (CVE-2025-39902 bsc#1250702).
  - commit 507e4ea
  - NFSD: Define a proc_layoutcommit for the FlexFiles layout type
    (git-fixes).
  - commit d3322a8
  - selftests/tracing: Fix false failure of subsystem event test
    (git-fixes).
  - commit 95dc965
  - tracing: Fix filter string testing (git-fixes).
  - commit aca40c5
  - tracing: fprobe events: Fix possible UAF on modules (git-fixes).
  - commit afb00f2
  - tracing: tprobe-events: Fix leakage of module refcount
    (git-fixes).
  - commit c1d1f90
  - powerpc/ftrace: ensure ftrace record ops are always set for NOPs
    (git-fixes).
  - commit afe3ecd
  - bpf: Check link_create.flags parameter for multi_kprobe
    (git-fixes).
  - commit 0da9eff
  - bpf: Check link_create.flags parameter for multi_uprobe
    (git-fixes).
  - commit 5ee2013
  - ftrace: fix incorrect hash size in register_ftrace_direct()
    (git-fixes).
  - commit 7b2465b
  - bpf: Use preempt_count() directly in bpf_send_signal_common()
    (git-fixes).
  - commit 840bc07
  - tracing: Correct the refcount if the hist/hist_debug file
    fails to open (git-fixes).
  - commit 66499d7
  - module: Prevent silent truncation of module name in
    delete_module(2) (git-fixes).
  - commit 97db76c
  - tracing: Add down_write(trace_event_sem) when adding trace event
    (bsc#1248211 CVE-2025-38539).
  - commit 7396877
  - tracing: Limit access to parser->buffer when trace_get_user
    failed (bsc#1249286 CVE-2025-39683).
  - tracing: Remove unneeded goto out logic (bsc#1249286).
  - commit 1685cce

++++ kernel-firmware-mediatek:

  - Update aliases from 6.18-rc1

++++ kernel-rt:

  - Update
    patches.suse/ASoC-qcom-q6apm-lpass-dais-Fix-NULL-pointer-derefere.patch
    (git-fixes CVE-2025-39938 bsc#1251134).
  - Update
    patches.suse/crypto-af_alg-Set-merge-to-zero-early-in-af_alg_send.patch
    (git-fixes CVE-2025-39931 bsc#1251100).
  - Update
    patches.suse/drm-bridge-anx7625-Fix-NULL-pointer-dereference-with.patch
    (git-fixes CVE-2025-39934 bsc#1251146).
  - Update
    patches.suse/net-rfkill-gpio-Fix-crash-due-to-dereferencering-uni.patch
    (git-fixes CVE-2025-39937 bsc#1251143).
  - Update
    patches.suse/wifi-mac80211-increase-scan_ies_len-for-S1G.patch
    (stable-fixes CVE-2025-39957 bsc#1251810).
  - Update
    patches.suse/wifi-wilc1000-avoid-buffer-overflow-in-WID-string-co.patch
    (stable-fixes CVE-2025-39952 bsc#1251216).
  - commit 6d21f77
  - iommu/vt-d: Disallow dirty tracking if incoherent page walk
    (git-fixes).
  - iommu/vt-d: PRS isn't usable if PDS isn't supported (git-fixes).
  - commit 9da8433
  - wifi: iwlwifi: Add missing firmware info for bz-b0-* models
    (bsc#1252084).
  - commit 7b5c81c
  - wifi: iwlwifi: config: unify fw/pnvm MODULE_FIRMWARE
    (bsc#1252084).
  - commit 2e309d0
  - mm/page_alloc: fix race condition in unaccepted memory handling
    (CVE-2025-38008 bsc#1244939).
  - commit c480181
  - mm/slub: avoid accessing metadata when pointer is invalid in
    object_err() (CVE-2025-39902 bsc#1250702).
  - commit 507e4ea
  - NFSD: Define a proc_layoutcommit for the FlexFiles layout type
    (git-fixes).
  - commit d3322a8
  - selftests/tracing: Fix false failure of subsystem event test
    (git-fixes).
  - commit 95dc965
  - tracing: Fix filter string testing (git-fixes).
  - commit aca40c5
  - tracing: fprobe events: Fix possible UAF on modules (git-fixes).
  - commit afb00f2
  - tracing: tprobe-events: Fix leakage of module refcount
    (git-fixes).
  - commit c1d1f90
  - powerpc/ftrace: ensure ftrace record ops are always set for NOPs
    (git-fixes).
  - commit afe3ecd
  - bpf: Check link_create.flags parameter for multi_kprobe
    (git-fixes).
  - commit 0da9eff
  - bpf: Check link_create.flags parameter for multi_uprobe
    (git-fixes).
  - commit 5ee2013
  - ftrace: fix incorrect hash size in register_ftrace_direct()
    (git-fixes).
  - commit 7b2465b
  - bpf: Use preempt_count() directly in bpf_send_signal_common()
    (git-fixes).
  - commit 840bc07
  - tracing: Correct the refcount if the hist/hist_debug file
    fails to open (git-fixes).
  - commit 66499d7
  - module: Prevent silent truncation of module name in
    delete_module(2) (git-fixes).
  - commit 97db76c
  - tracing: Add down_write(trace_event_sem) when adding trace event
    (bsc#1248211 CVE-2025-38539).
  - commit 7396877
  - tracing: Limit access to parser->buffer when trace_get_user
    failed (bsc#1249286 CVE-2025-39683).
  - tracing: Remove unneeded goto out logic (bsc#1249286).
  - commit 1685cce

++++ libxslt:

  - security update
  - added patches
    CVE-2025-11731 [bsc#1251979], type confusion in exsltFuncResultCompfunction leading to denial of service
    * libxslt-CVE-2025-11731.patch

++++ samba:

  - Update to 4.22.5
    * CVE-2025-10230: Command injection via WINS server hook
    script (bso#15903); (bsc#1251280).
    * CVE-2025-9640: uninitialized memory disclosure via
    vfs_streams_xattr; (bso#15885); (bsc#1251279).

++++ python313-core:

  - Update to 3.13.9:
  - Library
  - gh-139783: Fix inspect.getsourcelines() for the case when a
    decorator is followed by a comment or an empty line.
  - Update to 3.13.8:
  - macOS
  - gh-124111: Update macOS installer to use Tcl/Tk 8.6.17.
  - gh-139573: Updated bundled version of OpenSSL to 3.0.18.
  - Windows
  - gh-139573: Updated bundled version of OpenSSL to 3.0.18.
  - gh-138896: Fix error installing C runtime on non-updated Windows
    machines
  - Tools/Demos
  - gh-139330: SBOM generation tool didn’t cross-check the version
    and checksum values against the Modules/expat/refresh.sh script,
    leading to the values becoming out-of-date during routine
    updates.
  - gh-137873: The iOS test runner has been simplified, resolving
    some issues that have been observed using the runner in GitHub
    Actions and Azure Pipelines test environments.
  - Tests
  - gh-139208: Fix regrtest --fast-ci --verbose: don’t ignore the
  - -verbose option anymore. Patch by Victor Stinner.
  - Security
  - gh-139400: xml.parsers.expat: Make sure that parent Expat
    parsers are only garbage-collected once they are no longer
    referenced by subparsers created by
    ExternalEntityParserCreate(). Patch by Sebastian Pipping.
  - gh-139283: sqlite3: correctly handle maximum number of rows to
    fetch in Cursor.fetchmany and reject negative values for
    Cursor.arraysize. Patch by Bénédikt Tran.
  - gh-135661: Fix CDATA section parsing in html.parser.HTMLParser
    according to the HTML5 standard: ] ]> and ]] > no longer end the
    CDATA section. Add private method _set_support_cdata() which can
    be used to specify how to parse <[CDATA[ — as a CDATA section in
    foreign content (SVG or MathML) or as a bogus comment in the
    HTML namespace.
  - Library
  - gh-139312: Upgrade bundled libexpat to 2.7.3
  - gh-139289: Do a real lazy-import on rlcompleter in pdb and
    restore the existing completer after importing rlcompleter.
  - gh-139210: Fix use-after-free when reporting unknown event in
    xml.etree.ElementTree.iterparse(). Patch by Ken Jin.
  - gh-138860: Lazy import rlcompleter in pdb to avoid deadlock in
    subprocess.
  - gh-112729: Fix crash when calling _interpreters.create when the
    process is out of memory.
  - gh-139076: Fix a bug in the pydoc module that was hiding
    functions in a Python module if they were implemented in an
    extension module and the module did not have __all__.
  - gh-138998: Update bundled libexpat to 2.7.2
  - gh-130567: Fix possible crash in locale.strxfrm() due to a
    platform bug on macOS.
  - gh-138779: Support device numbers larger than 2**63-1 for the
    st_rdev field of the os.stat_result structure.
  - gh-128636: Fix crash in PyREPL when os.environ is overwritten
    with an invalid value for mac
  - gh-88375: Fix normalization of the robots.txt rules and URLs in
    the urllib.robotparser module. No longer ignore trailing ?.
    Distinguish raw special characters ?, = and & from the
    percent-encoded ones.
  - gh-138515: email is added to Emscripten build.
  - gh-111788: Fix parsing errors in the urllib.robotparser module.
    Don’t fail trying to parse weird paths. Don’t fail trying to
    decode non-UTF-8 robots.txt files.
  - gh-138432: zoneinfo.reset_tzpath() will now convert any
    os.PathLike objects it receives into strings before adding them
    to TZPATH. It will raise TypeError if anything other than a
    string is found after this conversion. If given an os.PathLike
    object that represents a relative path, it will now raise
    ValueError instead of TypeError, and present a more informative
    error message.
  - gh-138008: Fix segmentation faults in the ctypes module due to
    invalid argtypes. Patch by Dung Nguyen.
  - gh-60462: Fix locale.strxfrm() on Solaris (and possibly other
    platforms).
  - gh-138204: Forbid expansion of shared anonymous memory maps on
    Linux, which caused a bus error.
  - gh-138010: Fix an issue where defining a class with a
    @warnings.deprecated-decorated base class may not invoke the
    correct __init_subclass__() method in cases involving multiple
    inheritance. Patch by Brian Schubert.
  - gh-138133: Prevent infinite traceback loop when sending CTRL^C
    to Python through strace.
  - gh-134869: Fix an issue where pressing Ctrl+C during tab
    completion in the REPL would leave the autocompletion menu in a
    corrupted state.
  - gh-137317: inspect.signature() now correctly handles classes
    that use a descriptor on a wrapped __init__() or __new__()
    method. Contributed by Yongyu Yan.
  - gh-137754: Fix import of the zoneinfo module if the C
    implementation of the datetime module is not available.
  - gh-137490: Handle ECANCELED in the same way as EINTR in
    signal.sigwaitinfo() on NetBSD.
  - gh-137477: Fix inspect.getblock(), inspect.getsourcelines() and
    inspect.getsource() for generator expressions.
  - gh-137017: Fix threading.Thread.is_alive to remain True until
    the underlying OS thread is fully cleaned up. This avoids false
    negatives in edge cases involving thread monitoring or premature
    threading.Thread.is_alive calls.
  - gh-136134: SMTP.auth_cram_md5() now raises an SMTPException
    instead of a ValueError if Python has been built without MD5
    support. In particular, SMTP clients will not attempt to use
    this method even if the remote server is assumed to support it.
    Patch by Bénédikt Tran.
  - gh-136134: IMAP4.login_cram_md5 now raises an IMAP4.error if
    CRAM-MD5 authentication is not supported. Patch by Bénédikt
    Tran.
  - gh-135386: Fix opening a dbm.sqlite3 database for reading from
    read-only file or directory.
  - gh-126631: Fix multiprocessing forkserver bug which prevented
    __main__ from being preloaded.
  - gh-123085: In a bare call to importlib.resources.files(), ensure
    the caller’s frame is properly detected when importlib.resources
    is itself available as a compiled module only (no source).
  - gh-118981: Fix potential hang in
    multiprocessing.popen_spawn_posix that can happen when the child
    proc dies early by closing the child fds right away.
  - gh-78319: UTF8 support for the IMAP APPEND command has been made
    RFC compliant.
  - bpo-38735: Fix failure when importing a module from the root
    directory on unix-like platforms with sys.pycache_prefix set.
  - bpo-41839: Allow negative priority values from
    os.sched_get_priority_min() and os.sched_get_priority_max()
    functions.
  - Core and Builtins
  - gh-134466: Don’t run PyREPL in a degraded environment where
    setting termios attributes is not allowed.
  - gh-71810: Raise OverflowError for (-1).to_bytes() for signed
    conversions when bytes count is zero. Patch by Sergey B
    Kirpichev.
  - gh-105487: Remove non-existent __copy__(), __deepcopy__(), and
    __bases__ from the __dir__() entries of types.GenericAlias.
  - gh-134163: Fix a hang when the process is out of memory inside
    an exception handler.
  - gh-138479: Fix a crash when a generic object’s __typing_subst__
    returns an object that isn’t a tuple.
  - gh-137576: Fix for incorrect source code being shown in
    tracebacks from the Basic REPL when PYTHONSTARTUP is given.
    Patch by Adam Hartz.
  - gh-132744: Certain calls now check for runaway recursion and
    respect the system recursion limit.
  - C API
  - gh-87135: Attempting to acquire the GIL after runtime
    finalization has begun in a different thread now causes the
    thread to hang rather than terminate, which avoids potential
    crashes or memory corruption caused by attempting to terminate a
    thread that is running code not specifically designed to support
    termination. In most cases this hanging is harmless since the
    process will soon exit anyway.
    While not officially marked deprecated until 3.14,
    PyThread_exit_thread is no longer called internally and remains
    solely for interface compatibility. Its behavior is inconsistent
    across platforms, and it can only be used safely in the unlikely
    case that every function in the entire call stack has been
    designed to support the platform-dependent termination
    mechanism. It is recommended that users of this function change
    their design to not require thread termination. In the unlikely
    case that thread termination is needed and can be done safely,
    users may migrate to calling platform-specific APIs such as
    pthread_exit (POSIX) or _endthreadex (Windows) directly.
  - Build
  - gh-135734: Python can correctly be configured and built with
    ./configure --enable-optimizations --disable-test-modules.
    Previously, the profile data generation step failed due to PGO
    tests where immortalization couldn’t be properly suppressed.
    Patch by Bénédikt Tran.

++++ python313:

  - Update to 3.13.9:
  - Library
  - gh-139783: Fix inspect.getsourcelines() for the case when a
    decorator is followed by a comment or an empty line.
  - Update to 3.13.8:
  - macOS
  - gh-124111: Update macOS installer to use Tcl/Tk 8.6.17.
  - gh-139573: Updated bundled version of OpenSSL to 3.0.18.
  - Windows
  - gh-139573: Updated bundled version of OpenSSL to 3.0.18.
  - gh-138896: Fix error installing C runtime on non-updated Windows
    machines
  - Tools/Demos
  - gh-139330: SBOM generation tool didn’t cross-check the version
    and checksum values against the Modules/expat/refresh.sh script,
    leading to the values becoming out-of-date during routine
    updates.
  - gh-137873: The iOS test runner has been simplified, resolving
    some issues that have been observed using the runner in GitHub
    Actions and Azure Pipelines test environments.
  - Tests
  - gh-139208: Fix regrtest --fast-ci --verbose: don’t ignore the
  - -verbose option anymore. Patch by Victor Stinner.
  - Security
  - gh-139400: xml.parsers.expat: Make sure that parent Expat
    parsers are only garbage-collected once they are no longer
    referenced by subparsers created by
    ExternalEntityParserCreate(). Patch by Sebastian Pipping.
  - gh-139283: sqlite3: correctly handle maximum number of rows to
    fetch in Cursor.fetchmany and reject negative values for
    Cursor.arraysize. Patch by Bénédikt Tran.
  - gh-135661: Fix CDATA section parsing in html.parser.HTMLParser
    according to the HTML5 standard: ] ]> and ]] > no longer end the
    CDATA section. Add private method _set_support_cdata() which can
    be used to specify how to parse <[CDATA[ — as a CDATA section in
    foreign content (SVG or MathML) or as a bogus comment in the
    HTML namespace.
  - Library
  - gh-139312: Upgrade bundled libexpat to 2.7.3
  - gh-139289: Do a real lazy-import on rlcompleter in pdb and
    restore the existing completer after importing rlcompleter.
  - gh-139210: Fix use-after-free when reporting unknown event in
    xml.etree.ElementTree.iterparse(). Patch by Ken Jin.
  - gh-138860: Lazy import rlcompleter in pdb to avoid deadlock in
    subprocess.
  - gh-112729: Fix crash when calling _interpreters.create when the
    process is out of memory.
  - gh-139076: Fix a bug in the pydoc module that was hiding
    functions in a Python module if they were implemented in an
    extension module and the module did not have __all__.
  - gh-138998: Update bundled libexpat to 2.7.2
  - gh-130567: Fix possible crash in locale.strxfrm() due to a
    platform bug on macOS.
  - gh-138779: Support device numbers larger than 2**63-1 for the
    st_rdev field of the os.stat_result structure.
  - gh-128636: Fix crash in PyREPL when os.environ is overwritten
    with an invalid value for mac
  - gh-88375: Fix normalization of the robots.txt rules and URLs in
    the urllib.robotparser module. No longer ignore trailing ?.
    Distinguish raw special characters ?, = and & from the
    percent-encoded ones.
  - gh-138515: email is added to Emscripten build.
  - gh-111788: Fix parsing errors in the urllib.robotparser module.
    Don’t fail trying to parse weird paths. Don’t fail trying to
    decode non-UTF-8 robots.txt files.
  - gh-138432: zoneinfo.reset_tzpath() will now convert any
    os.PathLike objects it receives into strings before adding them
    to TZPATH. It will raise TypeError if anything other than a
    string is found after this conversion. If given an os.PathLike
    object that represents a relative path, it will now raise
    ValueError instead of TypeError, and present a more informative
    error message.
  - gh-138008: Fix segmentation faults in the ctypes module due to
    invalid argtypes. Patch by Dung Nguyen.
  - gh-60462: Fix locale.strxfrm() on Solaris (and possibly other
    platforms).
  - gh-138204: Forbid expansion of shared anonymous memory maps on
    Linux, which caused a bus error.
  - gh-138010: Fix an issue where defining a class with a
    @warnings.deprecated-decorated base class may not invoke the
    correct __init_subclass__() method in cases involving multiple
    inheritance. Patch by Brian Schubert.
  - gh-138133: Prevent infinite traceback loop when sending CTRL^C
    to Python through strace.
  - gh-134869: Fix an issue where pressing Ctrl+C during tab
    completion in the REPL would leave the autocompletion menu in a
    corrupted state.
  - gh-137317: inspect.signature() now correctly handles classes
    that use a descriptor on a wrapped __init__() or __new__()
    method. Contributed by Yongyu Yan.
  - gh-137754: Fix import of the zoneinfo module if the C
    implementation of the datetime module is not available.
  - gh-137490: Handle ECANCELED in the same way as EINTR in
    signal.sigwaitinfo() on NetBSD.
  - gh-137477: Fix inspect.getblock(), inspect.getsourcelines() and
    inspect.getsource() for generator expressions.
  - gh-137017: Fix threading.Thread.is_alive to remain True until
    the underlying OS thread is fully cleaned up. This avoids false
    negatives in edge cases involving thread monitoring or premature
    threading.Thread.is_alive calls.
  - gh-136134: SMTP.auth_cram_md5() now raises an SMTPException
    instead of a ValueError if Python has been built without MD5
    support. In particular, SMTP clients will not attempt to use
    this method even if the remote server is assumed to support it.
    Patch by Bénédikt Tran.
  - gh-136134: IMAP4.login_cram_md5 now raises an IMAP4.error if
    CRAM-MD5 authentication is not supported. Patch by Bénédikt
    Tran.
  - gh-135386: Fix opening a dbm.sqlite3 database for reading from
    read-only file or directory.
  - gh-126631: Fix multiprocessing forkserver bug which prevented
    __main__ from being preloaded.
  - gh-123085: In a bare call to importlib.resources.files(), ensure
    the caller’s frame is properly detected when importlib.resources
    is itself available as a compiled module only (no source).
  - gh-118981: Fix potential hang in
    multiprocessing.popen_spawn_posix that can happen when the child
    proc dies early by closing the child fds right away.
  - gh-78319: UTF8 support for the IMAP APPEND command has been made
    RFC compliant.
  - bpo-38735: Fix failure when importing a module from the root
    directory on unix-like platforms with sys.pycache_prefix set.
  - bpo-41839: Allow negative priority values from
    os.sched_get_priority_min() and os.sched_get_priority_max()
    functions.
  - Core and Builtins
  - gh-134466: Don’t run PyREPL in a degraded environment where
    setting termios attributes is not allowed.
  - gh-71810: Raise OverflowError for (-1).to_bytes() for signed
    conversions when bytes count is zero. Patch by Sergey B
    Kirpichev.
  - gh-105487: Remove non-existent __copy__(), __deepcopy__(), and
    __bases__ from the __dir__() entries of types.GenericAlias.
  - gh-134163: Fix a hang when the process is out of memory inside
    an exception handler.
  - gh-138479: Fix a crash when a generic object’s __typing_subst__
    returns an object that isn’t a tuple.
  - gh-137576: Fix for incorrect source code being shown in
    tracebacks from the Basic REPL when PYTHONSTARTUP is given.
    Patch by Adam Hartz.
  - gh-132744: Certain calls now check for runaway recursion and
    respect the system recursion limit.
  - C API
  - gh-87135: Attempting to acquire the GIL after runtime
    finalization has begun in a different thread now causes the
    thread to hang rather than terminate, which avoids potential
    crashes or memory corruption caused by attempting to terminate a
    thread that is running code not specifically designed to support
    termination. In most cases this hanging is harmless since the
    process will soon exit anyway.
    While not officially marked deprecated until 3.14,
    PyThread_exit_thread is no longer called internally and remains
    solely for interface compatibility. Its behavior is inconsistent
    across platforms, and it can only be used safely in the unlikely
    case that every function in the entire call stack has been
    designed to support the platform-dependent termination
    mechanism. It is recommended that users of this function change
    their design to not require thread termination. In the unlikely
    case that thread termination is needed and can be done safely,
    users may migrate to calling platform-specific APIs such as
    pthread_exit (POSIX) or _endthreadex (Windows) directly.
  - Build
  - gh-135734: Python can correctly be configured and built with
    ./configure --enable-optimizations --disable-test-modules.
    Previously, the profile data generation step failed due to PGO
    tests where immortalization couldn’t be properly suppressed.
    Patch by Bénédikt Tran.

------------------------------------------------------------------
------------------  2025-10-14  -  Oct 14 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ftrace: Also allocate and copy hash for reading of filter files
    (bsc#1250032 CVE-2025-39813).
  - commit cef7211
  - media: i2c: tc358743: Fix use-after-free bugs caused by orphan
    timer in probe (git-fixes).
  - commit a1733f5
  - Disable CET before shutdown by tboot (bsc#1247950).
    Tboot isn't compatible with CET (yet). So use an out-of-tree patch
    provided by Intel to disable CET before jumping into tboot as part of the
    shutdown sequence.
  - commit 25a6f98
  - drm/amd/display: Enable Dynamic DTBCLK Switch (bsc#1243112).
  - drm/amdgpu: Report individual reset error (bsc#1243112).
  - drm/amd: Check whether secure display TA loaded successfully
    (bsc#1243112).
  - drm/amdkfd: Fix mmap write lock not release (bsc#1243112).
  - drm/amdgpu: Fix for GPU reset being blocked by KIQ I/O
    (bsc#1243112).
  - drm/amd: Avoid evicting resources at S5 (bsc#1243112).
  - drm/amdgpu/mes12: implement detect and reset callback
    (bsc#1243112).
  - drm/amdgpu/mes11: implement detect and reset callback
    (bsc#1243112).
  - drm/amdgpu/mes: add front end for detect and reset hung queue
    (bsc#1243112).
  - drm/amd/amdgpu: Implement MES suspend/resume gang functionality
    for v12 (bsc#1243112).
  - drm/amdgpu/vpe: cancel delayed work in hw_fini (bsc#1243112).
  - commit d1679a6
  - ftrace: Fix potential warning in trace_printk_seq during
    ftrace_dump (bsc#1250032 CVE-2025-39813).
  - commit 596515e
  - x86/bugs: Fix GDS mitigation selecting when mitigation is off (git-fixes).
  - commit 75fb73f
  - x86/bugs: Add attack vector controls for SSB (git-fixes).
  - commit ae652b4
  - drm/amd: Only restore cached manual clock settings in restore
    if OD enabled (bsc#1243112).
  - drm/amd/display: Add NULL check for stream before dereference in
    'dm_vupdate_high_irq' (bsc#1243112).
  - drm/amd/display: Fix vupdate_offload_work doc (bsc#1243112).
  - drm/amdgpu: fix link error for !PM_SLEEP (bsc#1243112).
  - commit 5e5cc07
  - drm/amd/display: more liberal vmin/vmax update for freesync
    (bsc#1243112).
  - drm/amd/display: fix dmub access race condition (bsc#1243112).
  - commit 3d8614e
  - Drop bogus AMDGPU backport patch from 6.12.y stable
    Deleted:
    patches.suse/drm-amdgpu-VCN-v5_0_1-to-prevent-FW-checking-RB-duri.patch
    The backport was a mess, and the added code wasn't actually used at all.
  - commit 4e052cc
  - drm/amdgpu: Avoid rma causes GPU duplicate reset (bsc#1243112).
  - drm/amd: Restore cached manual clock settings during resume
    (bsc#1243112).
  - PM: hibernate: Fix pm_hibernation_mode_is_suspend() build
    breakage (bsc#1243112).
  - drm/amd: Fix hybrid sleep (bsc#1243112).
  - PM: hibernate: Add pm_hibernation_mode_is_suspend()
    (bsc#1243112).
  - PM: hibernate: Add stub for pm_hibernate_is_recovering()
    (bsc#1243112).
  - drm/amdgpu: do not resume device in thaw for normal hibernation
    (bsc#1243112).
  - PM: hibernate: add new api pm_hibernate_is_recovering()
    (bsc#1243112).
  - commit f6582d3
  - mm: memory-tiering: fix PGPROMOTE_CANDIDATE counting - kabi
    (bsc#1245630).
  - commit cf64417
  - trace/fgraph: Fix error handling (git-fixes).
  - commit 96a9de8
  - trace/fgraph: Fix the warning caused by missing unregister
    notifier (bsc#1248211 CVE-2025-38539).
  - commit 0901700
  - x86/bugs: Select best SRSO mitigation (git-fixes).
  - commit b4f33d4
  - x86/bugs: Print enabled attack vectors (git-fixes).
  - commit b08aa53
  - x86/bugs: Add attack vector controls for TSA (git-fixes).
  - commit 7acc191
  - cpu: Define attack vectors (git-fixes).
  - commit c8fa133
  - x86/pti: Add attack vector controls for PTI (git-fixes).
  - commit 78147b6
  - x86/bugs: Add attack vector controls for ITS (git-fixes).
  - commit 3b568ea
  - x86/bugs: Add attack vector controls for SRSO (git-fixes).
  - commit 0e4f2f2
  - x86/bugs: Add attack vector controls for L1TF (git-fixes).
  - commit 987b389
  - x86/bugs: Add attack vector controls for spectre_v2 (git-fixes).
  - commit dd53eb3
  - x86/bugs: Add attack vector controls for BHI (git-fixes).
  - commit 5656bb2
  - x86/bugs: Add attack vector controls for spectre_v2_user (git-fixes).
  - commit 16df3c7
  - x86/bugs: Add attack vector controls for retbleed (git-fixes).
  - commit 5580d6e
  - x86/bugs: Add attack vector controls for spectre_v1 (git-fixes).
  - commit cc85e5a
  - x86/bugs: Add attack vector controls for GDS (git-fixes).
  - commit 6711126
  - x86/bugs: Add attack vector controls for SRBDS (git-fixes).
  - commit 1fea28a
  - x86/bugs: Add attack vector controls for RFDS (git-fixes).
  - commit 9771c45
  - x86/bugs: Add attack vector controls for MMIO (git-fixes).
  - commit 2753f65
  - x86/bugs: Add attack vector controls for TAA (git-fixes).
  - commit c1e124c
  - x86/bugs: Add attack vector controls for MDS (git-fixes).
  - commit 052575a
  - x86/bugs: Define attack vectors relevant for each bug (git-fixes).
  - commit 83936cf
  - x86/Kconfig: Add arch attack vector support (git-fixes).
  - commit bb7b76d
  - Documentation/x86: Document new attack vector controls (git-fixes).
  - commit 507712f
  - RDMA/mana_ib: Extend modify QP (bsc#1251135).
  - RDMA/mana_ib: Drain send wrs of GSI QP (bsc#1251135).
  - net: mana: Use page pool fragments for RX buffers instead of
    full pages to improve memory efficiency (bsc#1248754).
  - cnic: Fix use-after-free bugs in cnic_delete_task
    (CVE-2025-39945 bsc#1251230).
  - commit b1cda45

++++ kernel-rt:

  - ftrace: Also allocate and copy hash for reading of filter files
    (bsc#1250032 CVE-2025-39813).
  - commit cef7211
  - media: i2c: tc358743: Fix use-after-free bugs caused by orphan
    timer in probe (git-fixes).
  - commit a1733f5
  - Disable CET before shutdown by tboot (bsc#1247950).
    Tboot isn't compatible with CET (yet). So use an out-of-tree patch
    provided by Intel to disable CET before jumping into tboot as part of the
    shutdown sequence.
  - commit 25a6f98
  - drm/amd/display: Enable Dynamic DTBCLK Switch (bsc#1243112).
  - drm/amdgpu: Report individual reset error (bsc#1243112).
  - drm/amd: Check whether secure display TA loaded successfully
    (bsc#1243112).
  - drm/amdkfd: Fix mmap write lock not release (bsc#1243112).
  - drm/amdgpu: Fix for GPU reset being blocked by KIQ I/O
    (bsc#1243112).
  - drm/amd: Avoid evicting resources at S5 (bsc#1243112).
  - drm/amdgpu/mes12: implement detect and reset callback
    (bsc#1243112).
  - drm/amdgpu/mes11: implement detect and reset callback
    (bsc#1243112).
  - drm/amdgpu/mes: add front end for detect and reset hung queue
    (bsc#1243112).
  - drm/amd/amdgpu: Implement MES suspend/resume gang functionality
    for v12 (bsc#1243112).
  - drm/amdgpu/vpe: cancel delayed work in hw_fini (bsc#1243112).
  - commit d1679a6
  - ftrace: Fix potential warning in trace_printk_seq during
    ftrace_dump (bsc#1250032 CVE-2025-39813).
  - commit 596515e
  - x86/bugs: Fix GDS mitigation selecting when mitigation is off (git-fixes).
  - commit 75fb73f
  - x86/bugs: Add attack vector controls for SSB (git-fixes).
  - commit ae652b4
  - drm/amd: Only restore cached manual clock settings in restore
    if OD enabled (bsc#1243112).
  - drm/amd/display: Add NULL check for stream before dereference in
    'dm_vupdate_high_irq' (bsc#1243112).
  - drm/amd/display: Fix vupdate_offload_work doc (bsc#1243112).
  - drm/amdgpu: fix link error for !PM_SLEEP (bsc#1243112).
  - commit 5e5cc07
  - drm/amd/display: more liberal vmin/vmax update for freesync
    (bsc#1243112).
  - drm/amd/display: fix dmub access race condition (bsc#1243112).
  - commit 3d8614e
  - Drop bogus AMDGPU backport patch from 6.12.y stable
    Deleted:
    patches.suse/drm-amdgpu-VCN-v5_0_1-to-prevent-FW-checking-RB-duri.patch
    The backport was a mess, and the added code wasn't actually used at all.
  - commit 4e052cc
  - drm/amdgpu: Avoid rma causes GPU duplicate reset (bsc#1243112).
  - drm/amd: Restore cached manual clock settings during resume
    (bsc#1243112).
  - PM: hibernate: Fix pm_hibernation_mode_is_suspend() build
    breakage (bsc#1243112).
  - drm/amd: Fix hybrid sleep (bsc#1243112).
  - PM: hibernate: Add pm_hibernation_mode_is_suspend()
    (bsc#1243112).
  - PM: hibernate: Add stub for pm_hibernate_is_recovering()
    (bsc#1243112).
  - drm/amdgpu: do not resume device in thaw for normal hibernation
    (bsc#1243112).
  - PM: hibernate: add new api pm_hibernate_is_recovering()
    (bsc#1243112).
  - commit f6582d3
  - mm: memory-tiering: fix PGPROMOTE_CANDIDATE counting - kabi
    (bsc#1245630).
  - commit cf64417
  - trace/fgraph: Fix error handling (git-fixes).
  - commit 96a9de8
  - trace/fgraph: Fix the warning caused by missing unregister
    notifier (bsc#1248211 CVE-2025-38539).
  - commit 0901700
  - x86/bugs: Select best SRSO mitigation (git-fixes).
  - commit b4f33d4
  - x86/bugs: Print enabled attack vectors (git-fixes).
  - commit b08aa53
  - x86/bugs: Add attack vector controls for TSA (git-fixes).
  - commit 7acc191
  - cpu: Define attack vectors (git-fixes).
  - commit c8fa133
  - x86/pti: Add attack vector controls for PTI (git-fixes).
  - commit 78147b6
  - x86/bugs: Add attack vector controls for ITS (git-fixes).
  - commit 3b568ea
  - x86/bugs: Add attack vector controls for SRSO (git-fixes).
  - commit 0e4f2f2
  - x86/bugs: Add attack vector controls for L1TF (git-fixes).
  - commit 987b389
  - x86/bugs: Add attack vector controls for spectre_v2 (git-fixes).
  - commit dd53eb3
  - x86/bugs: Add attack vector controls for BHI (git-fixes).
  - commit 5656bb2
  - x86/bugs: Add attack vector controls for spectre_v2_user (git-fixes).
  - commit 16df3c7
  - x86/bugs: Add attack vector controls for retbleed (git-fixes).
  - commit 5580d6e
  - x86/bugs: Add attack vector controls for spectre_v1 (git-fixes).
  - commit cc85e5a
  - x86/bugs: Add attack vector controls for GDS (git-fixes).
  - commit 6711126
  - x86/bugs: Add attack vector controls for SRBDS (git-fixes).
  - commit 1fea28a
  - x86/bugs: Add attack vector controls for RFDS (git-fixes).
  - commit 9771c45
  - x86/bugs: Add attack vector controls for MMIO (git-fixes).
  - commit 2753f65
  - x86/bugs: Add attack vector controls for TAA (git-fixes).
  - commit c1e124c
  - x86/bugs: Add attack vector controls for MDS (git-fixes).
  - commit 052575a
  - x86/bugs: Define attack vectors relevant for each bug (git-fixes).
  - commit 83936cf
  - x86/Kconfig: Add arch attack vector support (git-fixes).
  - commit bb7b76d
  - Documentation/x86: Document new attack vector controls (git-fixes).
  - commit 507712f
  - RDMA/mana_ib: Extend modify QP (bsc#1251135).
  - RDMA/mana_ib: Drain send wrs of GSI QP (bsc#1251135).
  - net: mana: Use page pool fragments for RX buffers instead of
    full pages to improve memory efficiency (bsc#1248754).
  - cnic: Fix use-after-free bugs in cnic_delete_task
    (CVE-2025-39945 bsc#1251230).
  - commit b1cda45

++++ nvidia-open-driver-G06-signed:

  - changed Requires to
    * nvidia-modprobe = %version
    * nvidia-persitenced = %version
    it has been >= before ...

------------------------------------------------------------------
------------------  2025-10-13  -  Oct 13 2025  -------------------
------------------------------------------------------------------

++++ grub2:

  - Fix "sparse file not allowed" error after grub2-reboot (bsc#1245738)
    * grub2-grubenv-in-btrfs-header.patch
  - Fix PowerPC network boot prefix to correctly locate grub.cfg (bsc#1249385)
    * 0001-ieee1275-Use-net-config-for-boot-location-instead-of.patch

++++ kernel-default:

  - powerpc/ftrace: ensure ftrace record ops are always set for NOPs
    (jsc#PED-10909 git-fixes).
  - commit 27e3939
  - powerpc/powernv/pci: Fix underflow and leak issue (bsc#1215199).
  - powerpc/pseries/msi: Fix potential underflow and leak issue
    (bsc#1215199).
  - powerpc/kvm: Fix ifdef to remove build warning (bsc#1215199).
  - KVM: PPC: Fix misleading interrupts comment in
    kvmppc_prepare_to_enter() (bsc#1215199).
  - powerpc: floppy: Add missing checks after DMA map (bsc#1215199).
  - commit 1ed7d5a
  - powerpc64/modules: correctly iterate over stubs in
    setup_ftrace_ool_stubs (jsc#PED-10909 git-fixes).
  - commit 5325db8
  - USB: serial: option: add SIMCom 8230C compositions
    (stable-fixes).
  - Bluetooth: btusb: Add USB ID 2001:332a for D-Link AX9U rev. A1
    (stable-fixes).
  - wifi: rtl8xxxu: Don't claim USB ID 07b8:8188 (stable-fixes).
  - wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
    (stable-fixes).
  - drm/amdgpu: Enable MES lr_compute_wa by default (stable-fixes).
  - driver core/PM: Set power.no_callbacks along with power.no_pm
    (stable-fixes).
  - platform/x86/amd/pmc: Add Stellaris Slim Gen6 AMD to spurious
    8042 quirks list (stable-fixes).
  - can: rcar_canfd: Fix controller mode setting (stable-fixes).
  - can: hi311x: fix null pointer dereference when resuming from
    sleep before interface was enabled (stable-fixes).
  - ASoC: rt5682s: Adjust SAR ADC button mode to fix noise issue
    (stable-fixes).
  - ASoC: amd: acp: Adjust pdm gain value (stable-fixes).
  - platform/x86/amd/pmf: Support new ACPI ID AMDI0108
    (stable-fixes).
  - platform/x86/amd/pmc: Add MECHREVO Yilong15Pro to spurious_8042
    list (stable-fixes).
  - hid: fix I2C read buffer overflow in raw_event() for mcp2221
    (stable-fixes).
  - drm/amd/include : Update MES v12 API for fence update
    (stable-fixes).
  - drm/amd/include : MES v11 and v12 API header update
    (stable-fixes).
  - drm/amd : Update MES API header file for v11 & v12
    (stable-fixes).
  - commit 0f46bd5

++++ kernel-firmware-ath12k:

  - Add the missing Supplements (bsc#1250952)

++++ kernel-rt:

  - powerpc/ftrace: ensure ftrace record ops are always set for NOPs
    (jsc#PED-10909 git-fixes).
  - commit 27e3939
  - powerpc/powernv/pci: Fix underflow and leak issue (bsc#1215199).
  - powerpc/pseries/msi: Fix potential underflow and leak issue
    (bsc#1215199).
  - powerpc/kvm: Fix ifdef to remove build warning (bsc#1215199).
  - KVM: PPC: Fix misleading interrupts comment in
    kvmppc_prepare_to_enter() (bsc#1215199).
  - powerpc: floppy: Add missing checks after DMA map (bsc#1215199).
  - commit 1ed7d5a
  - powerpc64/modules: correctly iterate over stubs in
    setup_ftrace_ool_stubs (jsc#PED-10909 git-fixes).
  - commit 5325db8
  - USB: serial: option: add SIMCom 8230C compositions
    (stable-fixes).
  - Bluetooth: btusb: Add USB ID 2001:332a for D-Link AX9U rev. A1
    (stable-fixes).
  - wifi: rtl8xxxu: Don't claim USB ID 07b8:8188 (stable-fixes).
  - wifi: rtlwifi: rtl8192cu: Don't claim USB ID 07b8:8188
    (stable-fixes).
  - drm/amdgpu: Enable MES lr_compute_wa by default (stable-fixes).
  - driver core/PM: Set power.no_callbacks along with power.no_pm
    (stable-fixes).
  - platform/x86/amd/pmc: Add Stellaris Slim Gen6 AMD to spurious
    8042 quirks list (stable-fixes).
  - can: rcar_canfd: Fix controller mode setting (stable-fixes).
  - can: hi311x: fix null pointer dereference when resuming from
    sleep before interface was enabled (stable-fixes).
  - ASoC: rt5682s: Adjust SAR ADC button mode to fix noise issue
    (stable-fixes).
  - ASoC: amd: acp: Adjust pdm gain value (stable-fixes).
  - platform/x86/amd/pmf: Support new ACPI ID AMDI0108
    (stable-fixes).
  - platform/x86/amd/pmc: Add MECHREVO Yilong15Pro to spurious_8042
    list (stable-fixes).
  - hid: fix I2C read buffer overflow in raw_event() for mcp2221
    (stable-fixes).
  - drm/amd/include : Update MES v12 API for fence update
    (stable-fixes).
  - drm/amd/include : MES v11 and v12 API header update
    (stable-fixes).
  - drm/amd : Update MES API header file for v11 & v12
    (stable-fixes).
  - commit 0f46bd5

++++ libvirt:

  - qemu: Add support for Intel TDX
    jsc#PED-9265

------------------------------------------------------------------
------------------  2025-10-12  -  Oct 12 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - rtc: optee: fix memory leak on driver removal (git-fixes).
  - rtc: x1205: Fix Xicor X1205 vendor prefix (git-fixes).
  - commit b6c4ddb

++++ kernel-rt:

  - rtc: optee: fix memory leak on driver removal (git-fixes).
  - rtc: x1205: Fix Xicor X1205 vendor prefix (git-fixes).
  - commit b6c4ddb

------------------------------------------------------------------
------------------  2025-10-11  -  Oct 11 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/amd/display: Disable scaling on DCE6 for now (git-fixes).
  - drm/amd/display: Properly disable scaling on DCE6 (git-fixes).
  - drm/amd/display: Properly clear SCL_*_FILTER_CONTROL on DCE6
    (git-fixes).
  - drm/amd/display: Add missing DCE6 SCL_HORZ_FILTER_INIT* SRIs
    (git-fixes).
  - drm/amdgpu: Add additional DCE6 SCL registers (git-fixes).
  - drm/xe/hw_engine_group: Fix double write lock release in error
    path (git-fixes).
  - drm/xe/uapi: loosen used tracking restriction (git-fixes).
  - drm/nouveau: fix bad ret code in nouveau_bo_move_prep
    (git-fixes).
  - drm/vmwgfx: Fix copy-paste typo in validation (git-fixes).
  - drm/vmwgfx: Fix Use-after-free in validation (git-fixes).
  - drm/vmwgfx: Fix a null-ptr access in the cursor snooper
    (git-fixes).
  - of: unittest: Fix device reference count leak in
    of_unittest_pci_node_verify (git-fixes).
  - ASoC: SOF: Intel: Read the LLP via the associated Link DMA
    channel (git-fixes).
  - ASoC: SOF: Intel: hda-pcm: Place the constraint on period time
    instead of buffer time (git-fixes).
  - ASoC: SOF: ipc4-topology: Account for different ChainDMA host
    buffer size (git-fixes).
  - ASoC: SOF: ipc4-topology: Correct the minimum host DMA buffer
    size (git-fixes).
  - ASoC: SOF: ipc3-topology: Fix multi-core and static pipelines
    tear down (git-fixes).
  - fbdev: Fix logic error in "offb" name match (git-fixes).
  - fbdev: simplefb: Fix use after free in simplefb_detach_genpds()
    (git-fixes).
  - gpio: wcd934x: mark the GPIO controller as sleeping (git-fixes).
  - crypto: essiv - Check ssize for decryption and in-place
    encryption (git-fixes).
  - tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single
    (git-fixes).
  - commit 850e21e

++++ kernel-firmware-bluetooth:

  - Update to version 20251010 (git commit fef0b3bbf494):
    * linux-firmware: Update firmware file for Intel Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel BlazarI core

++++ kernel-rt:

  - drm/amd/display: Disable scaling on DCE6 for now (git-fixes).
  - drm/amd/display: Properly disable scaling on DCE6 (git-fixes).
  - drm/amd/display: Properly clear SCL_*_FILTER_CONTROL on DCE6
    (git-fixes).
  - drm/amd/display: Add missing DCE6 SCL_HORZ_FILTER_INIT* SRIs
    (git-fixes).
  - drm/amdgpu: Add additional DCE6 SCL registers (git-fixes).
  - drm/xe/hw_engine_group: Fix double write lock release in error
    path (git-fixes).
  - drm/xe/uapi: loosen used tracking restriction (git-fixes).
  - drm/nouveau: fix bad ret code in nouveau_bo_move_prep
    (git-fixes).
  - drm/vmwgfx: Fix copy-paste typo in validation (git-fixes).
  - drm/vmwgfx: Fix Use-after-free in validation (git-fixes).
  - drm/vmwgfx: Fix a null-ptr access in the cursor snooper
    (git-fixes).
  - of: unittest: Fix device reference count leak in
    of_unittest_pci_node_verify (git-fixes).
  - ASoC: SOF: Intel: Read the LLP via the associated Link DMA
    channel (git-fixes).
  - ASoC: SOF: Intel: hda-pcm: Place the constraint on period time
    instead of buffer time (git-fixes).
  - ASoC: SOF: ipc4-topology: Account for different ChainDMA host
    buffer size (git-fixes).
  - ASoC: SOF: ipc4-topology: Correct the minimum host DMA buffer
    size (git-fixes).
  - ASoC: SOF: ipc3-topology: Fix multi-core and static pipelines
    tear down (git-fixes).
  - fbdev: Fix logic error in "offb" name match (git-fixes).
  - fbdev: simplefb: Fix use after free in simplefb_detach_genpds()
    (git-fixes).
  - gpio: wcd934x: mark the GPIO controller as sleeping (git-fixes).
  - crypto: essiv - Check ssize for decryption and in-place
    encryption (git-fixes).
  - tpm_tis: Fix incorrect arguments in tpm_tis_probe_irq_single
    (git-fixes).
  - commit 850e21e

++++ libsoup:

  - Add libsoup-CVE-2025-11021.patch: Ignore invalid date when
    processing cookies to prevent out-of-bounds read (bsc#1250562,
    CVE-2025-11021, glgo#GNOME/libsoup!482).

------------------------------------------------------------------
------------------  2025-10-10  -  Oct 10 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - x86/topology: Implement topology_is_core_online() to address SMT regression (jsc#PED-13815).
  - commit 13d76d5
  - x86/smp: Fix mwait_play_dead() and acpi_processor_ffh_play_dead() noreturn behavior (jsc#PED-13815).
  - commit 24aa526
  - ACPI/processor_idle: Export acpi_processor_ffh_play_dead() (jsc#PED-13815).
  - commit 7d8dbc7
  - drm/amd/display: update sequential pg logic DCN35
    (CVE-2025-38360 bsc#1247078).
  - Refresh
    patches.suse/drm-amd-display-Add-more-checks-for-DSC-HUBP-ONO-gua.patch.
  - commit ad27636
  - drm/amd/display: add workaround flag to link to force FFE preset
    (stable-fixes).
  - commit 61c6ea5
  - Refresh patches.suse/drm-amdgpu-Fix-Circular-Locking-Dependency-in-AMDGPU.patch
    Correct the wrong bool arguments, to align with the upstream behavior
  - commit 8db2492
  - mm: memory-tiering: fix PGPROMOTE_CANDIDATE counting
    (bsc#1245630).
  - commit 0cbd971
  - Reapply "x86/smp: Eliminate mwait_play_dead_cpuid_hint()" (jsc#PED-13815).
  - commit 5f6e3a3
  - ACPI: processor: Rescan "dead" SMT siblings during initialization (jsc#PED-13815).
  - commit 6cf1b0e
  - intel_idle: Rescan "dead" SMT siblings during initialization (jsc#PED-13815).
  - commit 19451cd
  - x86/smp: PM/hibernate: Split arch_resume_nosmt() (jsc#PED-13815).
  - commit 88ac4d0
  - intel_idle: Use subsys_initcall_sync() for initialization (jsc#PED-13815).
  - commit 05a8782
  - intel_idle: Provide the default enter_dead() handler (jsc#PED-13815).
  - commit 3fe4d1d
  - ACPI/processor_idle: Add FFH state handling (jsc#PED-13815).
  - commit bbf694a
  - x86/smp: Allow calling mwait_play_dead with an arbitrary hint (jsc#PED-13815).
  - commit ce38e7e
  - net: usb: asix: hold PM usage ref to avoid PM/MDIO + RTNL
    deadlock (git-fixes).
  - commit 377678d

++++ kernel-firmware-bluetooth:

  - Update to version 20251010 (git commit 49fafa182b23):
    * qca: Update Bluetooth WCN6750 1.1.3-00091 firmware to 1.1.3-00100

++++ kernel-rt:

  - x86/topology: Implement topology_is_core_online() to address SMT regression (jsc#PED-13815).
  - commit 13d76d5
  - x86/smp: Fix mwait_play_dead() and acpi_processor_ffh_play_dead() noreturn behavior (jsc#PED-13815).
  - commit 24aa526
  - ACPI/processor_idle: Export acpi_processor_ffh_play_dead() (jsc#PED-13815).
  - commit 7d8dbc7
  - drm/amd/display: update sequential pg logic DCN35
    (CVE-2025-38360 bsc#1247078).
  - Refresh
    patches.suse/drm-amd-display-Add-more-checks-for-DSC-HUBP-ONO-gua.patch.
  - commit ad27636
  - drm/amd/display: add workaround flag to link to force FFE preset
    (stable-fixes).
  - commit 61c6ea5
  - Refresh patches.suse/drm-amdgpu-Fix-Circular-Locking-Dependency-in-AMDGPU.patch
    Correct the wrong bool arguments, to align with the upstream behavior
  - commit 8db2492
  - mm: memory-tiering: fix PGPROMOTE_CANDIDATE counting
    (bsc#1245630).
  - commit 0cbd971
  - Reapply "x86/smp: Eliminate mwait_play_dead_cpuid_hint()" (jsc#PED-13815).
  - commit 5f6e3a3
  - ACPI: processor: Rescan "dead" SMT siblings during initialization (jsc#PED-13815).
  - commit 6cf1b0e
  - intel_idle: Rescan "dead" SMT siblings during initialization (jsc#PED-13815).
  - commit 19451cd
  - x86/smp: PM/hibernate: Split arch_resume_nosmt() (jsc#PED-13815).
  - commit 88ac4d0
  - intel_idle: Use subsys_initcall_sync() for initialization (jsc#PED-13815).
  - commit 05a8782
  - intel_idle: Provide the default enter_dead() handler (jsc#PED-13815).
  - commit 3fe4d1d
  - ACPI/processor_idle: Add FFH state handling (jsc#PED-13815).
  - commit bbf694a
  - x86/smp: Allow calling mwait_play_dead with an arbitrary hint (jsc#PED-13815).
  - commit ce38e7e
  - net: usb: asix: hold PM usage ref to avoid PM/MDIO + RTNL
    deadlock (git-fixes).
  - commit 377678d

++++ runc:

    [ This update was only released for SLE 12 and 15. ]
  - Update to runc v1.2.7. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.7>.

------------------------------------------------------------------
------------------  2025-10-9  -  Oct 9 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory
    is allocated (CVE-2025-38700 bsc#1249182).
  - commit b82e3fc
  - Update
    patches.suse/scsi-lpfc-Fix-buffer-free-clear-order-in-deferred-re.patch
    (bsc#1250519 bsc#1250247/CVE-2025-39841).
    Added in new bug number and CVE number.
  - commit 778e5da
  - netfilter: nft_objref: validate objref and objrefmap expressions
    (bsc#1250237).
    No CVE available yet, please see the bugzilla ticket referenced.
  - commit d6e82ec
  - README.BRANCH: mfranc@suse.cz leaving SUSE
  - commit 29cd3a3
  - ext4: avoid potential buffer over-read in
    parse_apply_sb_mount_options() (git-fixes).
  - commit d186b30
  - ext4: fix an off-by-one issue during moving extents (git-fixes).
  - commit 176d807
  - ext4: add ext4_sb_bread_nofail() helper function for
    ext4_free_branches() (git-fixes).
  - commit 9860491
  - ext4: fix hole length calculation overflow in non-extent inodes
    (git-fixes).
  - commit b7d6d21
  - ext4: don't try to clear the orphan_present feature block
    device is r/o (git-fixes).
  - commit 3758b29
  - ext4: fix reserved gdt blocks handling in fsmap (git-fixes).
  - commit 82855aa
  - ext4: fix fsmap end of range reporting with bigalloc
    (git-fixes).
  - commit f381d1b
  - ext4: check fast symlink for ea_inode correctly (git-fixes).
  - commit 720dc5d
  - ext4: preserve SB_I_VERSION on remount (git-fixes).
  - commit 4cf6f00
  - ext4: fix largest free orders lists corruption on
    mb_optimize_scan switch (git-fixes).
  - commit 6f98372
  - ext4: fix zombie groups in average fragment size lists
    (git-fixes).
  - commit 8313998
  - ext4: Make sure BH_New bit is cleared in ->write_end handler
    (git-fixes).
  - commit 8eb04f9
  - ext4: ensure i_size is smaller than maxbytes (git-fixes).
  - commit f9c6d79
  - ext4: factor out ext4_get_maxbytes() (git-fixes).
  - commit a0eb116
  - ext4: fix calculation of credits for extent tree modification
    (git-fixes).
  - commit 3858fc4
  - ext4: reorder capability check last (git-fixes).
  - commit 05df3ba
  - jbd2: do not try to recover wiped journal (git-fixes).
  - commit 72ca0c0
  - ext4: do not convert the unwritten extents if data writeback
    fails (git-fixes).
  - commit 27c9400
  - drm/amdgpu: Fix allocating extra dwords for rings (v2)
    (git-fixes).
  - drm/amd/display: remove output_tf_change flag (git-fixes).
  - drm/amd/display: Init DCN35 clocks from pre-os HW values
    (git-fixes).
  - drm/amd/amdgpu: Declare isp firmware binary file (stable-fixes).
  - drm/amd/display: Don't warn when missing DCE encoder caps
    (stable-fixes).
  - drm/amdgpu/gfx10: fix KGQ reset sequence (git-fixes).
  - drm/amd/display: Don't check for NULL divisor in fixpt code
    (git-fixes).
  - drm/amdgpu/mes: enable compute pipes across all MEC (git-fixes).
  - drm/amdgpu/mes: optimize compute loop handling (stable-fixes).
  - drm/amdgpu/vcn: fix ref counting for ring based profile handling
    (git-fixes).
  - commit 328f37b
  - fs: writeback: fix use-after-free in __mark_inode_dirty()
    (bsc#1250455 CVE-2025-39866).
  - commit dacb491
  - kernfs: Fix UAF in polling when open file is released
    (bsc#1250379 CVE-2025-39881).
  - commit debfec6
  - fs: Prevent file descriptor table allocations exceeding INT_MAX
    (bsc#1249512 CVE-2025-39756).
  - commit e9788bc
  - fs/xattr.c: fix simple_xattr_list to always include security.*
    xattrs (git-fixes).
  - commit eabd40a
  - fs: Remove redundant errseq_set call in
    mark_buffer_write_io_error (git-fixes).
  - commit 26efe8f
  - fs: udf: fix OOB read in lengthAllocDescs handling (git-fixes).
  - commit e4638c4
  - udf: Verify partition map count (git-fixes).
  - commit 19b7cc7
  - udf: Make sure i_lenExtents is uptodate on inode eviction
    (git-fixes).
  - commit eba6a22
  - readahead: fix return value of page_cache_next_miss() when no
    hole is found (git-fixes).
  - commit 17edc41
  - fix a leak in fcntl_dirnotify() (git-fixes).
  - commit 8ed0d88
  - fs: quota: create dedicated workqueue for quota_release_work
    (git-fixes).
  - commit 13c6f86
  - isofs: Verify inode mode when loading from disk (git-fixes).
  - commit 9fe2789
  - isofs: fix Y2038 and Y2156 issues in Rock Ridge TF entry
    (git-fixes).
  - commit 6d45c5a
  - mailbox: mtk-cmdq: Remove pm_runtime APIs from
    cmdq_mbox_send_data() (git-fixes).
  - mailbox: zynqmp-ipi: Fix SGI cleanup on unbind (git-fixes).
  - mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox
    cleanup loop (git-fixes).
  - mailbox: zynqmp-ipi: Remove dev.parent check in
    zynqmp_ipi_free_mboxes (git-fixes).
  - mailbox: zynqmp-ipi: Remove redundant
    mbox_controller_unregister() call (git-fixes).
  - Input: psxpad-spi - add a check for the return value of
    spi_setup() (git-fixes).
  - Input: uinput - zero-initialize uinput_ff_upload_compat to
    avoid info leak (git-fixes).
  - crypto: rng - Ensure set_ent is always present (git-fixes).
  - commit 342754b
  - net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y
    (CVE-2025-39900 bsc#1250758).
  - commit b0580b7
  - arm64: mte: Do not flag the zero page as PG_mte_tagged (git-fixes)
  - commit a6bcfac

++++ kernel-rt:

  - scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory
    is allocated (CVE-2025-38700 bsc#1249182).
  - commit b82e3fc
  - Update
    patches.suse/scsi-lpfc-Fix-buffer-free-clear-order-in-deferred-re.patch
    (bsc#1250519 bsc#1250247/CVE-2025-39841).
    Added in new bug number and CVE number.
  - commit 778e5da
  - netfilter: nft_objref: validate objref and objrefmap expressions
    (bsc#1250237).
    No CVE available yet, please see the bugzilla ticket referenced.
  - commit d6e82ec
  - README.BRANCH: mfranc@suse.cz leaving SUSE
  - commit 29cd3a3
  - ext4: avoid potential buffer over-read in
    parse_apply_sb_mount_options() (git-fixes).
  - commit d186b30
  - ext4: fix an off-by-one issue during moving extents (git-fixes).
  - commit 176d807
  - ext4: add ext4_sb_bread_nofail() helper function for
    ext4_free_branches() (git-fixes).
  - commit 9860491
  - ext4: fix hole length calculation overflow in non-extent inodes
    (git-fixes).
  - commit b7d6d21
  - ext4: don't try to clear the orphan_present feature block
    device is r/o (git-fixes).
  - commit 3758b29
  - ext4: fix reserved gdt blocks handling in fsmap (git-fixes).
  - commit 82855aa
  - ext4: fix fsmap end of range reporting with bigalloc
    (git-fixes).
  - commit f381d1b
  - ext4: check fast symlink for ea_inode correctly (git-fixes).
  - commit 720dc5d
  - ext4: preserve SB_I_VERSION on remount (git-fixes).
  - commit 4cf6f00
  - ext4: fix largest free orders lists corruption on
    mb_optimize_scan switch (git-fixes).
  - commit 6f98372
  - ext4: fix zombie groups in average fragment size lists
    (git-fixes).
  - commit 8313998
  - ext4: Make sure BH_New bit is cleared in ->write_end handler
    (git-fixes).
  - commit 8eb04f9
  - ext4: ensure i_size is smaller than maxbytes (git-fixes).
  - commit f9c6d79
  - ext4: factor out ext4_get_maxbytes() (git-fixes).
  - commit a0eb116
  - ext4: fix calculation of credits for extent tree modification
    (git-fixes).
  - commit 3858fc4
  - ext4: reorder capability check last (git-fixes).
  - commit 05df3ba
  - jbd2: do not try to recover wiped journal (git-fixes).
  - commit 72ca0c0
  - ext4: do not convert the unwritten extents if data writeback
    fails (git-fixes).
  - commit 27c9400
  - drm/amdgpu: Fix allocating extra dwords for rings (v2)
    (git-fixes).
  - drm/amd/display: remove output_tf_change flag (git-fixes).
  - drm/amd/display: Init DCN35 clocks from pre-os HW values
    (git-fixes).
  - drm/amd/amdgpu: Declare isp firmware binary file (stable-fixes).
  - drm/amd/display: Don't warn when missing DCE encoder caps
    (stable-fixes).
  - drm/amdgpu/gfx10: fix KGQ reset sequence (git-fixes).
  - drm/amd/display: Don't check for NULL divisor in fixpt code
    (git-fixes).
  - drm/amdgpu/mes: enable compute pipes across all MEC (git-fixes).
  - drm/amdgpu/mes: optimize compute loop handling (stable-fixes).
  - drm/amdgpu/vcn: fix ref counting for ring based profile handling
    (git-fixes).
  - commit 328f37b
  - fs: writeback: fix use-after-free in __mark_inode_dirty()
    (bsc#1250455 CVE-2025-39866).
  - commit dacb491
  - kernfs: Fix UAF in polling when open file is released
    (bsc#1250379 CVE-2025-39881).
  - commit debfec6
  - fs: Prevent file descriptor table allocations exceeding INT_MAX
    (bsc#1249512 CVE-2025-39756).
  - commit e9788bc
  - fs/xattr.c: fix simple_xattr_list to always include security.*
    xattrs (git-fixes).
  - commit eabd40a
  - fs: Remove redundant errseq_set call in
    mark_buffer_write_io_error (git-fixes).
  - commit 26efe8f
  - fs: udf: fix OOB read in lengthAllocDescs handling (git-fixes).
  - commit e4638c4
  - udf: Verify partition map count (git-fixes).
  - commit 19b7cc7
  - udf: Make sure i_lenExtents is uptodate on inode eviction
    (git-fixes).
  - commit eba6a22
  - readahead: fix return value of page_cache_next_miss() when no
    hole is found (git-fixes).
  - commit 17edc41
  - fix a leak in fcntl_dirnotify() (git-fixes).
  - commit 8ed0d88
  - fs: quota: create dedicated workqueue for quota_release_work
    (git-fixes).
  - commit 13c6f86
  - isofs: Verify inode mode when loading from disk (git-fixes).
  - commit 9fe2789
  - isofs: fix Y2038 and Y2156 issues in Rock Ridge TF entry
    (git-fixes).
  - commit 6d45c5a
  - mailbox: mtk-cmdq: Remove pm_runtime APIs from
    cmdq_mbox_send_data() (git-fixes).
  - mailbox: zynqmp-ipi: Fix SGI cleanup on unbind (git-fixes).
  - mailbox: zynqmp-ipi: Fix out-of-bounds access in mailbox
    cleanup loop (git-fixes).
  - mailbox: zynqmp-ipi: Remove dev.parent check in
    zynqmp_ipi_free_mboxes (git-fixes).
  - mailbox: zynqmp-ipi: Remove redundant
    mbox_controller_unregister() call (git-fixes).
  - Input: psxpad-spi - add a check for the return value of
    spi_setup() (git-fixes).
  - Input: uinput - zero-initialize uinput_ff_upload_compat to
    avoid info leak (git-fixes).
  - crypto: rng - Ensure set_ent is always present (git-fixes).
  - commit 342754b
  - net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y
    (CVE-2025-39900 bsc#1250758).
  - commit b0580b7
  - arm64: mte: Do not flag the zero page as PG_mte_tagged (git-fixes)
  - commit a6bcfac

------------------------------------------------------------------
------------------  2025-10-8  -  Oct 8 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 28.5.1-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2851>
  - Rebased patches:
    * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
    * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch
    * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch
  - Remove upstreamed patch:
  - 0007-Add-back-vendor.sum.patch

++++ kernel-default:

  - ext4: fix checks for orphan inodes (bsc#1250119).
  - commit c65de7e
  - smc: Fix lockdep false-positive for IPPROTO_SMC (git-fixes).
  - Refresh
    patches.suse/smc-Fix-various-oops-due-to-inet_sock-type-confusion.patch.
  - commit d87b439
  - kABI: add back tx_stopped to kcm_sock struct (bsc#1249167
    CVE-2025-38717).
    The upstream commit 52565a935213 ("net: kcm: Fix race condition in
    kcm_unattach()") removed the tx_stopped field from the kcm_sock
    structure. Bring it back to preserve kABI, even though it isn't used.
  - commit dfccc64
  - net: kcm: Fix race condition in kcm_unattach() (CVE-2025-38717
    bsc#1249167).
  - commit e60fdb9
  - usb: misc: qcom_eud: Access EUD_MODE_MANAGER2 through secure
    calls (git-fixes).
  - commit edc8bfe
  - misc: fastrpc: Skip reference for DMA handles (git-fixes).
  - misc: fastrpc: fix possible map leak in fastrpc_put_args
    (git-fixes).
  - misc: fastrpc: Fix fastrpc_map_lookup operation (git-fixes).
  - misc: fastrpc: Save actual DMA size in fastrpc_map structure
    (git-fixes).
  - staging: axis-fifo: flush RX FIFO on read errors (git-fixes).
  - staging: axis-fifo: fix TX handling on copy_from_user() failure
    (git-fixes).
  - staging: axis-fifo: fix maximum TX packet length check
    (git-fixes).
  - ACPI: battery: Add synchronization between interface updates
    (git-fixes).
  - cpufreq: tegra186: Set target frequency for all cpus in policy
    (git-fixes).
  - cpufreq: mediatek: fix device leak on probe failure (git-fixes).
  - clk: at91: peripheral: fix return value (git-fixes).
  - clk: mediatek: clk-mux: Do not pass flags to
    clk_mux_determine_rate_flags() (git-fixes).
  - clk: mediatek: mt8195-infra_ao: Fix parent for infra_ao_hdmi_26m
    (git-fixes).
  - clk: qcom: tcsrcc-x1e80100: Set the bi_tcxo as parent to eDP
    refclk (git-fixes).
  - clk: qcom: common: Fix NULL vs IS_ERR() check in
    qcom_cc_icc_register() (git-fixes).
  - clk: renesas: cpg-mssr: Fix memory leak in
    cpg_mssr_reserved_init() (git-fixes).
  - clk: tegra: do not overallocate memory for bpmp clocks
    (git-fixes).
  - commit bba55ef

++++ kernel-rt:

  - ext4: fix checks for orphan inodes (bsc#1250119).
  - commit c65de7e
  - smc: Fix lockdep false-positive for IPPROTO_SMC (git-fixes).
  - Refresh
    patches.suse/smc-Fix-various-oops-due-to-inet_sock-type-confusion.patch.
  - commit d87b439
  - kABI: add back tx_stopped to kcm_sock struct (bsc#1249167
    CVE-2025-38717).
    The upstream commit 52565a935213 ("net: kcm: Fix race condition in
    kcm_unattach()") removed the tx_stopped field from the kcm_sock
    structure. Bring it back to preserve kABI, even though it isn't used.
  - commit dfccc64
  - net: kcm: Fix race condition in kcm_unattach() (CVE-2025-38717
    bsc#1249167).
  - commit e60fdb9
  - usb: misc: qcom_eud: Access EUD_MODE_MANAGER2 through secure
    calls (git-fixes).
  - commit edc8bfe
  - misc: fastrpc: Skip reference for DMA handles (git-fixes).
  - misc: fastrpc: fix possible map leak in fastrpc_put_args
    (git-fixes).
  - misc: fastrpc: Fix fastrpc_map_lookup operation (git-fixes).
  - misc: fastrpc: Save actual DMA size in fastrpc_map structure
    (git-fixes).
  - staging: axis-fifo: flush RX FIFO on read errors (git-fixes).
  - staging: axis-fifo: fix TX handling on copy_from_user() failure
    (git-fixes).
  - staging: axis-fifo: fix maximum TX packet length check
    (git-fixes).
  - ACPI: battery: Add synchronization between interface updates
    (git-fixes).
  - cpufreq: tegra186: Set target frequency for all cpus in policy
    (git-fixes).
  - cpufreq: mediatek: fix device leak on probe failure (git-fixes).
  - clk: at91: peripheral: fix return value (git-fixes).
  - clk: mediatek: clk-mux: Do not pass flags to
    clk_mux_determine_rate_flags() (git-fixes).
  - clk: mediatek: mt8195-infra_ao: Fix parent for infra_ao_hdmi_26m
    (git-fixes).
  - clk: qcom: tcsrcc-x1e80100: Set the bi_tcxo as parent to eDP
    refclk (git-fixes).
  - clk: qcom: common: Fix NULL vs IS_ERR() check in
    qcom_cc_icc_register() (git-fixes).
  - clk: renesas: cpg-mssr: Fix memory leak in
    cpg_mssr_reserved_init() (git-fixes).
  - clk: tegra: do not overallocate memory for bpmp clocks
    (git-fixes).
  - commit bba55ef

++++ nvidia-open-driver-G06-signed:

  - Check4WrongSupplements.sh
    * check for wrong Supplements in generated KMPs after build by
    misusing %post of a dummy "check" subpackage

------------------------------------------------------------------
------------------  2025-10-7  -  Oct 7 2025  -------------------
------------------------------------------------------------------

++++ glibc:

  - abort-msg-s-underallocation.patch: Fix underallocation of abort_msg_s
    struct (CVE-2025-0395, bsc#1236282, BZ #32582)

++++ kernel-default:

  - ice: fix NULL pointer dereference in ice_unplug_aux_dev()
    on reset (jsc#PED-13728).
  - commit 4569920
  - idpf: set mac type when adding and removing MAC filters
    (jsc#PED-13728).
  - idpf: fix UAF in RDMA core aux dev deinitialization
    (jsc#PED-13728).
  - idpf: remove obsolete stashing code (jsc#PED-13728).
  - idpf: stop Tx if there are insufficient buffer resources
    (jsc#PED-13728).
  - idpf: replace flow scheduling buffer ring with buffer pool
    (jsc#PED-13728).
  - idpf: simplify and fix splitq Tx packet rollback error path
    (jsc#PED-13728).
  - idpf: improve when to set RE bit logic (jsc#PED-13728).
  - idpf: add support for Tx refillqs in flow scheduling mode
    (jsc#PED-13728).
  - idpf: preserve coalescing settings across resets
    (jsc#PED-13728).
  - idpf: add cross timestamping (jsc#PED-13728).
  - idpf: add flow steering support (jsc#PED-13728).
  - virtchnl2: add flow steering support (jsc#PED-13728).
  - virtchnl2: rename enum virtchnl2_cap_rss (jsc#PED-13728).
  - idpf: implement get LAN MMIO memory regions (jsc#PED-13728
    jsc#PED-13762).
  - idpf: implement IDC vport aux driver MTU change handler
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: implement remaining IDC RDMA core callbacks and handlers
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: implement RDMA vport auxiliary dev create, init, and
    destroy (jsc#PED-13728 jsc#PED-13762).
  - idpf: implement core RDMA auxiliary dev create, init, and
    destroy (jsc#PED-13728 jsc#PED-13762).
  - idpf: use reserved RDMA vectors from control plane
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: add support for Rx timestamping (jsc#PED-13728
    jsc#PED-13762).
  - idpf: add Tx timestamp flows (jsc#PED-13728 jsc#PED-13762).
  - idpf: add Tx timestamp capabilities negotiation (jsc#PED-13728
    jsc#PED-13762).
  - idpf: add PTP clock configuration (jsc#PED-13728 jsc#PED-13762).
  - idpf: add mailbox access to read PTP clock time (jsc#PED-13728
    jsc#PED-13762).
  - idpf: negotiate PTP capabilities and get PTP clock
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: move virtchnl structures to the header file (jsc#PED-13728
    jsc#PED-13762).
  - virtchnl: add PTP virtchnl definitions (jsc#PED-13728
    jsc#PED-13762).
  - idpf: add initial PTP support (jsc#PED-13728 jsc#PED-13762).
  - idpf: change the method for mailbox workqueue allocation
    (jsc#PED-13728 jsc#PED-13762).
  - iidc/ice/irdma: Update IDC to support multiple consumers
    (jsc#PED-13728 jsc#PED-13762).
  - ice: Replace ice specific DSCP mapping num with a kernel define
    (jsc#PED-13728 jsc#PED-13762).
  - iidc/ice/irdma: Break iidc.h into two headers (jsc#PED-13728
    jsc#PED-13762).
  - iidc/ice/irdma: Rename to iidc_* convention (jsc#PED-13728
    jsc#PED-13762).
  - iidc/ice/irdma: Rename IDC header file (jsc#PED-13728
    jsc#PED-13762).
  - idpf: remove unreachable code from setting mailbox
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: assign extracted ptype to struct libeth_rqe_info field
    (jsc#PED-13728 jsc#PED-13762).
  - libeth: move idpf_rx_csum_decoded and idpf_rx_extracted
    (jsc#PED-13728 jsc#PED-13762).
  - resource: Add resource set range and size helpers (jsc#PED-13728
    jsc#PED-13762).
  - commit 7610740
  - smb: client: fix crypto buffers in non-linear memory
    (bsc#1250491, boo#1239206).
  - commit 95451c8
  - tcp_bpf: Fix copied value in tcp_bpf_sendmsg (bsc#1250650).
  - commit 458b7be
  - Revert "usb: xhci: Avoid Stop Endpoint retry loop if the
    endpoint seems Running" (git-fixes).
  - commit 888e234
  - kABI workaround for struct atmdev_ops extension (CVE-2025-39828
    bsc#1250205).
  - commit e17abcd
  - atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control()
    (CVE-2025-39828 bsc#1250205).
  - commit a33e596
  - nfsd: fix access checking for NLM under XPRTSEC policies
    (git-fixes).
  - commit 373e2d2
  - nfsd: Fix NFSD_MAY_BYPASS_GSS and NFSD_MAY_BYPASS_GSS_ON_ROOT
    (git-fixes).
  - commit 8f7d330
  - NFSD: Fix destination buffer size in nfsd4_ssc_setup_dul()
    (git-fixes).
  - commit f2f0b4c
  - sunrpc: fix null pointer dereference on zero-length checksum
    (git-fixes).
  - commit 77680ce
  - kABI fix for net: vlan: fix VLAN 0 refcount imbalance of
    toggling filtering during runtime (CVE-2025-38470 bsc#1247288).
  - commit 872debf
  - genetlink: fix genl_bind() invoking bind() after -EPERM
    (CVE-2025-39926 bsc#1250737).
  - e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898
    bsc#1250742).
  - vxlan: Fix NPD when refreshing an FDB entry with a nexthop
    object (CVE-2025-39851 bsc#1250296).
  - commit b1c6264
  - ACPI: NFIT: Fix incorrect ndr_desc being reportedin dev_err
    message (git-fixes).
  - watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling
    the watchdog (git-fixes).
  - PCI/ACPI: Fix pci_acpi_preserve_config() memory leak
    (git-fixes).
  - PCI: xilinx-nwl: Fix ECAM programming (git-fixes).
  - PCI: tegra: Convert struct tegra_msi mask_lock into raw spinlock
    (git-fixes).
  - PCI: tegra194: Fix duplicate PLL disable in
    pex_ep_event_pex_rst_assert() (git-fixes).
  - PCI: tegra: Fix devm_kcalloc() argument order for port->phys
    allocation (git-fixes).
  - PCI: rcar-host: Convert struct rcar_msi mask_lock into raw
    spinlock (git-fixes).
  - PCI: rcar-host: Drop PMSR spinlock (git-fixes).
  - PCI: rcar-gen4: Fix inverted break condition in PHY
    initialization (git-fixes).
  - PCI: rcar-gen4: Assure reset occurs before DBI access
    (git-fixes).
  - PCI: rcar-gen4: Add missing 1ms delay after PWR reset assertion
    (git-fixes).
  - PCI: rcar-gen4: Fix PHY initialization (git-fixes).
  - PCI: keystone: Use devm_request_irq() to free
    "ks-pcie-error-irq" on exit (git-fixes).
  - PCI: j721e: Fix incorrect error message in probe() (git-fixes).
  - PCI: j721e: Fix programming sequence of "strap" settings
    (git-fixes).
  - PCI: tegra194: Handle errors in BPMP response (git-fixes).
  - PCI: tegra194: Reset BARs when running in PCIe endpoint mode
    (git-fixes).
  - PCI: tegra194: Fix broken tegra_pcie_ep_raise_msi_irq()
    (git-fixes).
  - PCI/IOV: Add PCI rescan-remove locking when enabling/disabling
    SR-IOV (git-fixes).
  - PCI/pwrctrl: Fix device leak at registration (git-fixes).
  - PCI/sysfs: Ensure devices are powered for config reads
    (git-fixes).
  - PCI/AER: Fix missing uevent on recovery when a reset is
    requested (git-fixes).
  - PCI/ERR: Fix uevent on failure to recover (git-fixes).
  - dmaengine: Fix dma_async_tx_descriptor->tx_submit documentation
    (git-fixes).
  - phy: rockchip: naneng-combphy: Enable U3 OTG port for RK3568
    (git-fixes).
  - media: rc: fix races with imon_disconnect() (git-fixes).
  - commit 89c34cb
  - arm64: dts: apple: Add ethernet0 alias for J375 template (git-fixes)
  - commit bf06513
  - arm64: dts: apple: t8103-j457: Fix PCIe ethernet iommu-map (git-fixes)
  - commit d06126a
  - arm64: dts: imx95: Correct the lpuart7 and lpuart8 srcid (git-fixes)
  - commit d730190
  - arm64: dts: imx93-kontron: Fix USB port assignment (git-fixes)
  - commit 986b7b9
  - arm64: dts: imx93-kontron: Fix GPIO for panel regulator (git-fixes)
  - commit 2c413ce
  - bpf, arm64: Call bpf_jit_binary_pack_finalize() in bpf_jit_free() (git-fixes)
  - commit e47726c
  - arm64: map [_text, _stext) virtual address range (git-fixes)
  - commit 10168ba
  - arm64: dts: imx8mp: Correct thermal sensor index (git-fixes)
  - commit 7d86bf9
  - arm64: dts: marvell: cn9132-clearfog: fix multi-lane pci x2 and x4 (git-fixes)
  - commit da906fa
  - arm64: dts: marvell: cn9132-clearfog: disable eMMC high-speed modes (git-fixes)
  - commit 8fbea30
  - Refresh new ".init.text.ftrace_trampoline" kABI fix.
    First version made modules build before patch [1] fail to load.
    [1] a7ed7b9d0ebb0 "arm64: ftrace: fix unreachable PLT for ftrace_caller in init_module with CONFIG_DYNAMIC_FTRACE"
  - commit 6910b1a

++++ kernel-rt:

  - ice: fix NULL pointer dereference in ice_unplug_aux_dev()
    on reset (jsc#PED-13728).
  - commit 4569920
  - idpf: set mac type when adding and removing MAC filters
    (jsc#PED-13728).
  - idpf: fix UAF in RDMA core aux dev deinitialization
    (jsc#PED-13728).
  - idpf: remove obsolete stashing code (jsc#PED-13728).
  - idpf: stop Tx if there are insufficient buffer resources
    (jsc#PED-13728).
  - idpf: replace flow scheduling buffer ring with buffer pool
    (jsc#PED-13728).
  - idpf: simplify and fix splitq Tx packet rollback error path
    (jsc#PED-13728).
  - idpf: improve when to set RE bit logic (jsc#PED-13728).
  - idpf: add support for Tx refillqs in flow scheduling mode
    (jsc#PED-13728).
  - idpf: preserve coalescing settings across resets
    (jsc#PED-13728).
  - idpf: add cross timestamping (jsc#PED-13728).
  - idpf: add flow steering support (jsc#PED-13728).
  - virtchnl2: add flow steering support (jsc#PED-13728).
  - virtchnl2: rename enum virtchnl2_cap_rss (jsc#PED-13728).
  - idpf: implement get LAN MMIO memory regions (jsc#PED-13728
    jsc#PED-13762).
  - idpf: implement IDC vport aux driver MTU change handler
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: implement remaining IDC RDMA core callbacks and handlers
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: implement RDMA vport auxiliary dev create, init, and
    destroy (jsc#PED-13728 jsc#PED-13762).
  - idpf: implement core RDMA auxiliary dev create, init, and
    destroy (jsc#PED-13728 jsc#PED-13762).
  - idpf: use reserved RDMA vectors from control plane
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: add support for Rx timestamping (jsc#PED-13728
    jsc#PED-13762).
  - idpf: add Tx timestamp flows (jsc#PED-13728 jsc#PED-13762).
  - idpf: add Tx timestamp capabilities negotiation (jsc#PED-13728
    jsc#PED-13762).
  - idpf: add PTP clock configuration (jsc#PED-13728 jsc#PED-13762).
  - idpf: add mailbox access to read PTP clock time (jsc#PED-13728
    jsc#PED-13762).
  - idpf: negotiate PTP capabilities and get PTP clock
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: move virtchnl structures to the header file (jsc#PED-13728
    jsc#PED-13762).
  - virtchnl: add PTP virtchnl definitions (jsc#PED-13728
    jsc#PED-13762).
  - idpf: add initial PTP support (jsc#PED-13728 jsc#PED-13762).
  - idpf: change the method for mailbox workqueue allocation
    (jsc#PED-13728 jsc#PED-13762).
  - iidc/ice/irdma: Update IDC to support multiple consumers
    (jsc#PED-13728 jsc#PED-13762).
  - ice: Replace ice specific DSCP mapping num with a kernel define
    (jsc#PED-13728 jsc#PED-13762).
  - iidc/ice/irdma: Break iidc.h into two headers (jsc#PED-13728
    jsc#PED-13762).
  - iidc/ice/irdma: Rename to iidc_* convention (jsc#PED-13728
    jsc#PED-13762).
  - iidc/ice/irdma: Rename IDC header file (jsc#PED-13728
    jsc#PED-13762).
  - idpf: remove unreachable code from setting mailbox
    (jsc#PED-13728 jsc#PED-13762).
  - idpf: assign extracted ptype to struct libeth_rqe_info field
    (jsc#PED-13728 jsc#PED-13762).
  - libeth: move idpf_rx_csum_decoded and idpf_rx_extracted
    (jsc#PED-13728 jsc#PED-13762).
  - resource: Add resource set range and size helpers (jsc#PED-13728
    jsc#PED-13762).
  - commit 7610740
  - smb: client: fix crypto buffers in non-linear memory
    (bsc#1250491, boo#1239206).
  - commit 95451c8
  - tcp_bpf: Fix copied value in tcp_bpf_sendmsg (bsc#1250650).
  - commit 458b7be
  - Revert "usb: xhci: Avoid Stop Endpoint retry loop if the
    endpoint seems Running" (git-fixes).
  - commit 888e234
  - kABI workaround for struct atmdev_ops extension (CVE-2025-39828
    bsc#1250205).
  - commit e17abcd
  - atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control()
    (CVE-2025-39828 bsc#1250205).
  - commit a33e596
  - nfsd: fix access checking for NLM under XPRTSEC policies
    (git-fixes).
  - commit 373e2d2
  - nfsd: Fix NFSD_MAY_BYPASS_GSS and NFSD_MAY_BYPASS_GSS_ON_ROOT
    (git-fixes).
  - commit 8f7d330
  - NFSD: Fix destination buffer size in nfsd4_ssc_setup_dul()
    (git-fixes).
  - commit f2f0b4c
  - sunrpc: fix null pointer dereference on zero-length checksum
    (git-fixes).
  - commit 77680ce
  - kABI fix for net: vlan: fix VLAN 0 refcount imbalance of
    toggling filtering during runtime (CVE-2025-38470 bsc#1247288).
  - commit 872debf
  - genetlink: fix genl_bind() invoking bind() after -EPERM
    (CVE-2025-39926 bsc#1250737).
  - e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898
    bsc#1250742).
  - vxlan: Fix NPD when refreshing an FDB entry with a nexthop
    object (CVE-2025-39851 bsc#1250296).
  - commit b1c6264
  - ACPI: NFIT: Fix incorrect ndr_desc being reportedin dev_err
    message (git-fixes).
  - watchdog: mpc8xxx_wdt: Reload the watchdog timer when enabling
    the watchdog (git-fixes).
  - PCI/ACPI: Fix pci_acpi_preserve_config() memory leak
    (git-fixes).
  - PCI: xilinx-nwl: Fix ECAM programming (git-fixes).
  - PCI: tegra: Convert struct tegra_msi mask_lock into raw spinlock
    (git-fixes).
  - PCI: tegra194: Fix duplicate PLL disable in
    pex_ep_event_pex_rst_assert() (git-fixes).
  - PCI: tegra: Fix devm_kcalloc() argument order for port->phys
    allocation (git-fixes).
  - PCI: rcar-host: Convert struct rcar_msi mask_lock into raw
    spinlock (git-fixes).
  - PCI: rcar-host: Drop PMSR spinlock (git-fixes).
  - PCI: rcar-gen4: Fix inverted break condition in PHY
    initialization (git-fixes).
  - PCI: rcar-gen4: Assure reset occurs before DBI access
    (git-fixes).
  - PCI: rcar-gen4: Add missing 1ms delay after PWR reset assertion
    (git-fixes).
  - PCI: rcar-gen4: Fix PHY initialization (git-fixes).
  - PCI: keystone: Use devm_request_irq() to free
    "ks-pcie-error-irq" on exit (git-fixes).
  - PCI: j721e: Fix incorrect error message in probe() (git-fixes).
  - PCI: j721e: Fix programming sequence of "strap" settings
    (git-fixes).
  - PCI: tegra194: Handle errors in BPMP response (git-fixes).
  - PCI: tegra194: Reset BARs when running in PCIe endpoint mode
    (git-fixes).
  - PCI: tegra194: Fix broken tegra_pcie_ep_raise_msi_irq()
    (git-fixes).
  - PCI/IOV: Add PCI rescan-remove locking when enabling/disabling
    SR-IOV (git-fixes).
  - PCI/pwrctrl: Fix device leak at registration (git-fixes).
  - PCI/sysfs: Ensure devices are powered for config reads
    (git-fixes).
  - PCI/AER: Fix missing uevent on recovery when a reset is
    requested (git-fixes).
  - PCI/ERR: Fix uevent on failure to recover (git-fixes).
  - dmaengine: Fix dma_async_tx_descriptor->tx_submit documentation
    (git-fixes).
  - phy: rockchip: naneng-combphy: Enable U3 OTG port for RK3568
    (git-fixes).
  - media: rc: fix races with imon_disconnect() (git-fixes).
  - commit 89c34cb
  - arm64: dts: apple: Add ethernet0 alias for J375 template (git-fixes)
  - commit bf06513
  - arm64: dts: apple: t8103-j457: Fix PCIe ethernet iommu-map (git-fixes)
  - commit d06126a
  - arm64: dts: imx95: Correct the lpuart7 and lpuart8 srcid (git-fixes)
  - commit d730190
  - arm64: dts: imx93-kontron: Fix USB port assignment (git-fixes)
  - commit 986b7b9
  - arm64: dts: imx93-kontron: Fix GPIO for panel regulator (git-fixes)
  - commit 2c413ce
  - bpf, arm64: Call bpf_jit_binary_pack_finalize() in bpf_jit_free() (git-fixes)
  - commit e47726c
  - arm64: map [_text, _stext) virtual address range (git-fixes)
  - commit 10168ba
  - arm64: dts: imx8mp: Correct thermal sensor index (git-fixes)
  - commit 7d86bf9
  - arm64: dts: marvell: cn9132-clearfog: fix multi-lane pci x2 and x4 (git-fixes)
  - commit da906fa
  - arm64: dts: marvell: cn9132-clearfog: disable eMMC high-speed modes (git-fixes)
  - commit 8fbea30
  - Refresh new ".init.text.ftrace_trampoline" kABI fix.
    First version made modules build before patch [1] fail to load.
    [1] a7ed7b9d0ebb0 "arm64: ftrace: fix unreachable PLT for ftrace_caller in init_module with CONFIG_DYNAMIC_FTRACE"
  - commit 6910b1a

++++ mozilla-nss:

  - Add bmo1990242.patch to move NSS DB password hash away from SHA-1

++++ pcr-oracle:

  - Update to 0.5.8
    + Fix unsealing failure when using non default PCR bank
    + Extra checks for TPM self-test (bsc#1249079)

++++ suse-module-tools:

  - Update to version 16.0.61:
    * weak-modules2: skip livepatch dir when checking for unresolved symbols
    (bsc#1250655)

------------------------------------------------------------------
------------------  2025-10-6  -  Oct 6 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - wifi: ath12k: Add MODULE_FIRMWARE() entries (bsc#1250952).
  - commit 2e6fdfd
  - scsi: qla2xxx: Fix incorrect sign of error code in
    qla_nvme_xmt_ls_rsp() (git-fixes).
  - scsi: qla2xxx: Fix incorrect sign of error code in
    START_SP_W_RETRIES() (git-fixes).
  - scsi: qla2xxx: edif: Fix incorrect sign of error code
    (git-fixes).
  - scsi: qla2xxx: Use secs_to_jiffies() instead of
    msecs_to_jiffies() (git-fixes).
  - scsi: qla2xxx: Remove firmware URL (git-fixes).
  - scsi: qla2xxx: Avoid stack frame size warning in qla_dfs
    (git-fixes).
  - commit f40dfff
  - scsi: lpfc: Copyright updates for 14.4.0.11 patches
    (bsc#1250519).
  - scsi: lpfc: Update lpfc version to 14.4.0.11 (bsc#1250519).
  - scsi: lpfc: Convert debugfs directory counts from atomic to
    unsigned int (bsc#1250519).
  - scsi: lpfc: Clean up extraneous phba dentries (bsc#1250519).
  - scsi: lpfc: Use switch case statements in DIF debugfs handlers
    (bsc#1250519).
  - scsi: lpfc: Define size of debugfs entry for xri rebalancing
    (bsc#1250519).
  - scsi: lpfc: Ensure PLOGI_ACC is sent prior to PRLI in Point
    to Point topology (bsc#1250519).
  - scsi: lpfc: Check return status of lpfc_reset_flush_io_context
    during TGT_RESET (bsc#1250519).
  - scsi: lpfc: Decrement ndlp kref after FDISC retries exhausted
    (bsc#1250519).
  - scsi: lpfc: Remove ndlp kref decrement clause for F_Port_Ctrl
    in lpfc_cleanup (bsc#1250519).
  - scsi: lpfc: Clean up allocated queues when queue setup mbox
    commands fail (bsc#1250519).
  - scsi: lpfc: Abort outstanding ELS WQEs regardless of if rmmod
    is in progress (bsc#1250519).
  - scsi: lpfc: Remove unused member variables in struct lpfc_hba
    and lpfc_vport (bsc#1250519).
  - scsi: lpfc: Use int type to store negative error codes
    (bsc#1250519).
  - scsi: fc: Avoid -Wflex-array-member-not-at-end warnings
    (bsc#1250519).
  - scsi: lpfc: use min() to improve code (bsc#1250519).
  - scsi: lpfc: Fix buffer free/clear order in deferred receive path
    (bsc#1250519).
  - scsi: lpfc: Remove redundant assignment to avoid memory leak
    (bsc#1250519).
  - scsi: lpfc: Fix wrong function reference in a comment
    (bsc#1250519).
  - lpfc: don't use file->f_path.dentry for comparisons
    (bsc#1250519).
  - commit 833345a
  - nvme-tcp: send only permitted commands for secure concat
    (git-fixes).
  - nvme-auth: update bi_directional flag (git-fixes).
  - nvme: fix PI insert on write (git-fixes).
  - commit bfff0fa
  - nvme-fc: use lock accessing port_state and rport state
    (bsc#1245193 bsc#1247500).
  - nvmet-fcloop: call done callback even when remote port is gone
    (bsc#1245193 bsc#1247500).
  - nvmet-fc: avoid scheduling association deletion twice
    (bsc#1245193 bsc#1247500).
  - nvmet-fc: move lsop put work to nvmet_fc_ls_req_op (bsc#1245193
    bsc#1247500).
  - commit 343e69e
  - ppp: fix memory leak in pad_compress_skb (CVE-2025-39847
    bsc#1250292).
  - ixgbe: fix incorrect map used in eee linkmode (CVE-2025-39922
    bsc#1250722).
  - ice: fix NULL access of tx->in_use in ice_ll_ts_intr
    (CVE-2025-39854 bsc#1250297).
  - vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop
    objects (CVE-2025-39850 bsc#1250276).
  - commit bb7194b
  - NFSv4.1: fix backchannel max_resp_sz verification check
    (git-fixes).
  - commit 875c2e0
  - igb: Fix NULL pointer dereference in ethtool loopback test (CVE-2025-39875 bsc#1250398)
  - commit 42c851b
  - sched/deadline: Initialize dl_servers after SMP (git-fixes)
  - commit 6da3701
  - sched_ext, sched/core: Don't call scx_group_set_weight() (git-fixes)
  - commit ea277bd
  - cpufreq/sched: Explicitly synchronize limits_changed flag (git-fixes)
  - commit aa9d54c
  - cpufreq/sched: Fix the usage of CPUFREQ_NEED_UPDATE_LIMITS (git-fixes)
  - commit 74fd037
  - sched_ext: Fix invalid irq restore in scx_ops_bypass() (bsc#1235953 CVE-2024-57891)
  - commit 9fe8fce
  - Update
    patches.suse/ACPI-APEI-send-SIGBUS-to-current-task-if-synchronous.patch
    (stable-fixes CVE-2025-39763 bsc#1249615).
  - Update
    patches.suse/ACPI-pfr_update-Fix-the-driver-update-version-check.patch
    (git-fixes CVE-2025-39701 bsc#1249308).
  - Update
    patches.suse/ALSA-hda-ca0132-Fix-buffer-overflow-in-add_tuning_co.patch
    (stable-fixes CVE-2025-39751 bsc#1249538).
  - Update
    patches.suse/ALSA-timer-fix-ida_free-call-while-not-allocated.patch
    (git-fixes CVE-2025-39765 bsc#1249509).
  - Update
    patches.suse/ALSA-usb-audio-Validate-UAC3-cluster-segment-descrip.patch
    (git-fixes CVE-2025-39757 bsc#1249515).
  - Update
    patches.suse/ALSA-usb-audio-Validate-UAC3-power-domain-descriptor.patch
    (git-fixes CVE-2025-38729 bsc#1249164).
  - Update
    patches.suse/ASoC-core-Check-for-rtd-NULL-in-snd_soc_remove_pcm_r.patch
    (stable-fixes CVE-2025-38706 bsc#1249195).
  - Update
    patches.suse/Bluetooth-Fix-use-after-free-in-l2cap_sock_cleanup_l.patch
    (git-fixes CVE-2025-39860 bsc#1250247).
  - Update
    patches.suse/Bluetooth-l2cap-Check-encryption-key-size-on-incomin.patch
    (git-fixes CVE-2025-39889 bsc#1249833).
  - Update
    patches.suse/Bluetooth-vhci-Prevent-use-after-free-by-removing-de.patch
    (git-fixes CVE-2025-39861 bsc#1250249).
  - Update
    patches.suse/HID-asus-fix-UAF-via-HID_CLAIMED_INPUT-validation.patch
    (git-fixes CVE-2025-39824 bsc#1250007).
  - Update
    patches.suse/HID-hid-ntrig-fix-unable-to-handle-page-fault-in-ntr.patch
    (stable-fixes CVE-2025-39808 bsc#1250088).
  - Update
    patches.suse/HID-multitouch-fix-slab-out-of-bounds-access-in-mt_r.patch
    (git-fixes CVE-2025-39806 bsc#1249888).
  - Update
    patches.suse/NFS-Fix-a-race-when-updating-an-existing-write.patch
    (git-fixes CVE-2025-39697 bsc#1249319).
  - Update
    patches.suse/NFS-Fix-filehandle-bounds-checking-in-nfs_fh_to_dentry.patch
    (git-fixes CVE-2025-39730 bsc#1249296).
  - Update
    patches.suse/NFS-Fix-the-setting-of-capabilities-when-automounting-a-new-filesystem.patch
    (git-fixes CVE-2025-39798 bsc#1249774).
  - Update
    patches.suse/PCI-endpoint-Fix-configfs-group-list-head-handling.patch
    (git-fixes CVE-2025-39783 bsc#1249486).
  - Update
    patches.suse/RDMA-hfi1-fix-possible-divide-by-zero-in-find_hw_thr.patch
    (git-fixes CVE-2025-39742 bsc#1249479).
  - Update
    patches.suse/RDMA-rxe-Flush-delayed-SKBs-while-releasing-RXE-reso.patch
    (git-fixes CVE-2025-39695 bsc#1249306).
  - Update
    patches.suse/RDMA-siw-Fix-the-sendmsg-byte-count-in-siw_tcp_sendp.patch
    (git-fixes CVE-2025-39758 bsc#1249490).
  - Update
    patches.suse/accel-ivpu-Prevent-recovery-work-from-being-queued-d.patch
    (git-fixes CVE-2025-39896 bsc#1250716).
  - Update
    patches.suse/ax25-properly-unshare-skbs-in-ax25_kiss_rcv.patch
    (git-fixes CVE-2025-39848 bsc#1250298).
  - Update
    patches.suse/batman-adv-fix-OOB-read-write-in-network-coding-deco.patch
    (git-fixes CVE-2025-39839 bsc#1250291).
  - Update
    patches.suse/bnxt_en-Fix-memory-corruption-when-FW-resources-chan.patch
    (git-fixes CVE-2025-39810 bsc#1249975).
  - Update
    patches.suse/bpf-Forget-ranges-when-refining-tnum-after-JSET.patch
    (git-fixes CVE-2025-39748 bsc#1249587).
  - Update
    patches.suse/btrfs-abort-transaction-on-unexpected-eb-generation-.patch
    (git-fixes CVE-2025-39800 bsc#1250177).
  - Update
    patches.suse/btrfs-do-not-allow-relocation-of-partially-dropped-s.patch
    (bsc#1249540 CVE-2025-39738).
  - Update
    patches.suse/btrfs-fix-subvolume-deletion-lockup-caused-by-inodes.patch
    (git-fixes CVE-2025-39884 bsc#1250386).
  - Update
    patches.suse/btrfs-qgroup-fix-race-between-quota-disable-and-quot.patch
    (git-fixes CVE-2025-39759 bsc#1249522).
  - Update
    patches.suse/bus-mhi-host-Detect-events-pointing-to-unexpected-TR.patch
    (git-fixes CVE-2025-39790 bsc#1249548).
  - Update
    patches.suse/can-j1939-implement-NETDEV_UNREGISTER-notification-h.patch
    (git-fixes CVE-2025-39925 bsc#1250736).
  - Update
    patches.suse/can-xilinx_can-xcan_write_frame-fix-use-after-free-o.patch
    (git-fixes CVE-2025-39873 bsc#1250371).
  - Update
    patches.suse/comedi-Fix-use-of-uninitialized-memory-in-do_insn_io.patch
    (git-fixes CVE-2025-39684 bsc#1249281).
  - Update
    patches.suse/comedi-Make-insn_rw_emulate_bits-do-insn-n-samples.patch
    (git-fixes CVE-2025-39686 bsc#1249312).
  - Update
    patches.suse/comedi-fix-race-between-polling-and-detaching.patch
    (git-fixes CVE-2025-38687 bsc#1249177).
  - Update
    patches.suse/comedi-pcl726-Prevent-invalid-irq-number.patch
    (git-fixes CVE-2025-39685 bsc#1249282).
  - Update
    patches.suse/crypto-caam-Prevent-crash-on-suspend-with-iMX8QM-iMX.patch
    (git-fixes CVE-2025-39722 bsc#1249301).
  - Update
    patches.suse/crypto-qat-flush-misc-workqueue-during-device-shutdo.patch
    (git-fixes CVE-2025-39721 bsc#1249323).
  - Update
    patches.suse/dmaengine-idxd-Fix-double-free-in-idxd_setup_wqs.patch
    (git-fixes CVE-2025-39870 bsc#1250402).
  - Update
    patches.suse/dmaengine-idxd-Remove-improper-idxd_free.patch
    (git-fixes CVE-2025-39871 bsc#1250377).
  - Update
    patches.suse/dmaengine-qcom-bam_dma-Fix-DT-error-handling-for-num.patch
    (git-fixes CVE-2025-39923 bsc#1250741).
  - Update
    patches.suse/dmaengine-ti-edma-Fix-memory-allocation-size-for-que.patch
    (git-fixes CVE-2025-39869 bsc#1250406).
  - Update
    patches.suse/drm-amd-display-Add-null-pointer-check-in-mod_hdcp_h.patch
    (git-fixes CVE-2025-39675 bsc#1249263).
  - Update
    patches.suse/drm-amd-display-Avoid-a-NULL-pointer-dereference.patch
    (stable-fixes CVE-2025-39693 bsc#1249279).
  - Update
    patches.suse/drm-amd-display-fix-a-Null-pointer-dereference-vulne.patch
    (stable-fixes CVE-2025-39705 bsc#1249295).
  - Update patches.suse/drm-amd-pm-fix-null-pointer-access.patch
    (stable-fixes CVE-2025-38705 bsc#1249334).
  - Update
    patches.suse/drm-amdgpu-check-if-hubbub-is-NULL-in-debugfs-amdgpu.patch
    (stable-fixes CVE-2025-39707 bsc#1249333).
  - Update
    patches.suse/drm-amdkfd-Destroy-KFD-debugfs-after-destroy-KFD-wq.patch
    (stable-fixes CVE-2025-39706 bsc#1249413).
  - Update
    patches.suse/drm-hisilicon-hibmc-fix-the-hibmc-loaded-failed-bug.patch
    (git-fixes CVE-2025-39772 bsc#1249506).
  - Update
    patches.suse/drm-mediatek-Add-error-handling-for-old-state-CRTC-i.patch
    (git-fixes CVE-2025-39807 bsc#1249887).
  - Update
    patches.suse/drm-mediatek-fix-potential-OF-node-use-after-free.patch
    (git-fixes CVE-2025-39882 bsc#1250389).
  - Update
    patches.suse/drm-msm-Add-error-handling-for-krealloc-in-metadata-.patch
    (stable-fixes CVE-2025-39747 bsc#1249566).
  - Update
    patches.suse/drm-nouveau-nvif-Fix-potential-memory-leak-in-nvif_v.patch
    (git-fixes CVE-2025-39679 bsc#1249338).
  - Update
    patches.suse/drm-xe-Make-dma-fences-compliant-with-the-safe-acces.patch
    (stable-fixes CVE-2025-38703 bsc#1249193).
  - Update
    patches.suse/drm-xe-vm-Clear-the-scratch_pt-pointer-on-error.patch
    (git-fixes CVE-2025-39811 bsc#1249915).
  - Update
    patches.suse/efi-stmm-Fix-incorrect-buffer-allocation-method.patch
    (git-fixes CVE-2025-39836 bsc#1249904).
  - Update
    patches.suse/exfat-add-cluster-chain-loop-check-for-dir.patch
    (git-fixes CVE-2025-38692 bsc#1249221).
  - Update
    patches.suse/fbdev-Fix-vmalloc-out-of-bounds-write-in-fast_imageb.patch
    (stable-fixes CVE-2025-38685 bsc#1249220).
  - Update
    patches.suse/fbdev-fix-potential-buffer-overflow-in-do_register_f.patch
    (stable-fixes CVE-2025-38702 bsc#1249254).
  - Update patches.suse/gve-prevent-ethtool-ops-after-shutdown.patch
    (git-fixes CVE-2025-38735 bsc#1249288).
  - Update patches.suse/habanalabs-fix-UAF-in-export_dmabuf.patch
    (git-fixes CVE-2025-38722 bsc#1249163).
  - Update
    patches.suse/iio-imu-bno055-fix-OOB-access-of-hw_xlate-array.patch
    (git-fixes CVE-2025-39719 bsc#1249271).
  - Update
    patches.suse/iio-light-as73211-Ensure-buffer-holes-are-zeroed.patch
    (git-fixes CVE-2025-39687 bsc#1249316).
  - Update
    patches.suse/iommu-arm-smmu-qcom-Add-SM6115-MDSS-compatible.patch
    (git-fixes CVE-2025-39739 bsc#1249542).
  - Update
    patches.suse/mISDN-hfcpci-Fix-warning-when-deleting-uninitialized.patch
    (git-fixes CVE-2025-39833 bsc#1250028).
  - Update
    patches.suse/media-dvb-frontends-dib7090p-fix-null-ptr-deref-in-d.patch
    (stable-fixes CVE-2025-38694 bsc#1249272).
  - Update
    patches.suse/media-dvb-frontends-w7090p-fix-null-ptr-deref-in-w70.patch
    (stable-fixes CVE-2025-38693 bsc#1249190).
  - Update
    patches.suse/media-ivsc-Fix-crash-at-shutdown-due-to-missing-mei_.patch
    (git-fixes CVE-2025-39711 bsc#1249274).
  - Update
    patches.suse/media-mt9m114-Fix-deadlock-in-get_frame_interval-set.patch
    (git-fixes CVE-2025-39712 bsc#1249269).
  - Update
    patches.suse/media-rainshadow-cec-fix-TOCTOU-race-condition-in-ra.patch
    (git-fixes CVE-2025-39713 bsc#1249321).
  - Update
    patches.suse/media-usbtv-Lock-resolution-while-streaming.patch
    (git-fixes CVE-2025-39714 bsc#1249273).
  - Update
    patches.suse/media-uvcvideo-Fix-1-byte-out-of-bounds-read-in-uvc_.patch
    (git-fixes CVE-2025-38680 bsc#1249203).
  - Update
    patches.suse/media-venus-Add-a-check-for-packet-size-after-readin.patch
    (git-fixes CVE-2025-39710 bsc#1249304).
  - Update
    patches.suse/media-venus-Fix-OOB-read-due-to-missing-payload-boun.patch
    (git-fixes CVE-2025-38679 bsc#1249202).
  - Update
    patches.suse/media-venus-protect-against-spurious-interrupts-duri.patch
    (git-fixes CVE-2025-39709 bsc#1249278).
  - Update
    patches.suse/mm-damon-lru_sort-avoid-divide-by-zero-in-damon_lru_.patch
    (git-fixes CVE-2025-39909 bsc#1250711).
  - Update
    patches.suse/mm-damon-ops-common-ignore-migration-request-to-inva.patch
    (git-fixes CVE-2025-39700 bsc#1249309).
  - Update
    patches.suse/mm-damon-reclaim-avoid-divide-by-zero-in-damon_recla.patch
    (git-fixes CVE-2025-39916 bsc#1250719).
  - Update
    patches.suse/mm-damon-sysfs-fix-use-after-free-in-state_show.patch
    (git-fixes CVE-2025-39877 bsc#1250408).
  - Update
    patches.suse/mm-move-page-table-sync-declarations-to-linux-pgtabl.patch
    (git-fixes CVE-2025-39844 bsc#1250268).
  - Update
    patches.suse/mm-ptdump-take-the-memory-hotplug-lock-inside-ptdump_walk_.patch
    (git-fixes CVE-2025-38681 bsc#1249204).
  - Update
    patches.suse/mm-swap-fix-potential-buffer-overflow-in-setup_clust.patch
    (git-fixes CVE-2025-39727 bsc#1249297).
  - Update
    patches.suse/mm-userfaultfd-fix-kmap_local-LIFO-ordering-for-CONF.patch
    (git-fixes CVE-2025-39899 bsc#1250739).
  - Update
    patches.suse/msft-hv-3329-hv_netvsc-Fix-panic-during-namespace-deletion-with-V.patch
    (bsc#1248111 CVE-2025-38683 bsc#1249159).
  - Update
    patches.suse/mtd-rawnand-stm32_fmc2-avoid-overlapping-mappings-on.patch
    (git-fixes CVE-2025-39907 bsc#1250713).
  - Update
    patches.suse/net-mlx5-Fix-lockdep-assertion-on-sync-reset-unload-.patch
    (git-fixes CVE-2025-39832 bsc#1249901).
  - Update
    patches.suse/net-mlx5-HWS-Fix-memory-leak-in-hws_action_get_share.patch
    (git-fixes CVE-2025-39834 bsc#1250021).
  - Update
    patches.suse/net-rose-convert-use-field-to-refcount_t.patch
    (git-fixes CVE-2025-39826 bsc#1250203).
  - Update
    patches.suse/net-rose-include-node-references-in-rose_neigh-refco.patch
    (git-fixes CVE-2025-39827 bsc#1250204).
  - Update
    patches.suse/net-usb-asix_devices-Fix-PHY-address-mask-in-MDIO-bu.patch
    (git-fixes CVE-2025-38736 bsc#1249318).
  - Update
    patches.suse/net-usb-asix_devices-add-phy_mask-for-ax88772-mdio-b.patch
    (git-fixes CVE-2025-38725 bsc#1249170).
  - Update
    patches.suse/netfilter-ctnetlink-fix-refcount-leak-on-table-dump.patch
    (git-fixes CVE-2025-38721 bsc#1249176).
  - Update
    patches.suse/netlink-avoid-infinite-retry-looping-in-netlink_unic.patch
    (CVE-2025-38465 bsc#1247118 CVE-2025-38727 bsc#1249166).
  - Update
    patches.suse/nfsd-handle-get_client_locked-failure-in-nfsd4_setclientid_confirm.patch
    (git-fixes CVE-2025-38724 bsc#1249169).
  - Update
    patches.suse/pNFS-Fix-uninited-ptr-deref-in-block-scsi-layout.patch
    (git-fixes CVE-2025-38691 bsc#1249215).
  - Update
    patches.suse/platform-x86-amd-hsmp-Ensure-sock-metric_tbl_addr-is.patch
    (git-fixes CVE-2025-39678 bsc#1249290).
  - Update
    patches.suse/s390-ism-fix-concurrency-management-in-ism_cmd.patch
    (git-fixes bsc#1247372 CVE-2025-39726 bsc#1249266).
  - Update
    patches.suse/s390-mm-Do-not-map-lowcore-with-identity-mapping.patch
    (git-fixes bsc#1249066 CVE-2025-38733 bsc#1249313).
  - Update patches.suse/s390-sclp-Fix-SCCB-present-check.patch
    (git-fixes bsc#1249065 CVE-2025-39694 bsc#1249299).
  - Update
    patches.suse/scsi-lpfc-Check-for-hdwq-null-ptr-when-cleaning-up-l.patch
    (bsc#1245260 bsc#1243100 bsc#1246125 CVE-2025-38695
    bsc#1249285).
  - Update
    patches.suse/scsi-ufs-exynos-Fix-programming-of-HCI_UTRL_NEXUS_TYPE.patch
    (git-fixes CVE-2025-39788 bsc#1249547).
  - Update patches.suse/serial-8250-fix-panic-due-to-PSLVERR.patch
    (git-fixes CVE-2025-39724 bsc#1249265).
  - Update
    patches.suse/soc-qcom-mdt_loader-Ensure-we-don-t-read-past-the-EL.patch
    (git-fixes CVE-2025-39787 bsc#1249545).
  - Update
    patches.suse/usb-core-config-Prevent-OOB-read-in-SS-endpoint-comp.patch
    (stable-fixes CVE-2025-39760 bsc#1249598).
  - Update
    patches.suse/usb-dwc3-Remove-WARN_ON-for-device-endpoint-command-.patch
    (stable-fixes CVE-2025-39801 bsc#1250450).
  - Update
    patches.suse/vsock-virtio-Validate-length-in-packet-header-before.patch
    (git-fixes CVE-2025-39718 bsc#1249305).
  - Update
    patches.suse/wifi-ath10k-shutdown-driver-when-hardware-is-unrelia.patch
    (stable-fixes CVE-2025-39746 bsc#1249516).
  - Update
    patches.suse/wifi-ath11k-fix-sleeping-in-atomic-in-ath11k_mac_op_.patch
    (git-fixes CVE-2025-39732 bsc#1249292).
  - Update
    patches.suse/wifi-ath12k-Correct-tid-cleanup-when-tid-setup-fails.patch
    (stable-fixes CVE-2025-39750 bsc#1249523).
  - Update
    patches.suse/wifi-ath12k-Decrement-TID-on-RX-peer-frag-setup-erro.patch
    (stable-fixes CVE-2025-39761 bsc#1249554).
  - Update
    patches.suse/wifi-ath12k-fix-memory-leak-in-ath12k_service_ready_.patch
    (git-fixes CVE-2025-39890 bsc#1250334).
  - Update
    patches.suse/wifi-brcmfmac-fix-use-after-free-when-rescheduling-b.patch
    (git-fixes CVE-2025-39863 bsc#1250281).
  - Update
    patches.suse/wifi-cfg80211-fix-use-after-free-in-cmp_bss.patch
    (git-fixes CVE-2025-39864 bsc#1250242).
  - Update
    patches.suse/wifi-cfg80211-sme-cap-SSID-length-in-__cfg80211_conn.patch
    (git-fixes CVE-2025-39849 bsc#1250266).
  - Update patches.suse/wifi-mt76-fix-linked-list-corruption.patch
    (git-fixes CVE-2025-39918 bsc#1250729).
  - Update
    patches.suse/wifi-mwifiex-Initialize-the-chan_stats-array-to-zero.patch
    (git-fixes CVE-2025-39891 bsc#1250712).
  - Update
    patches.suse/x86-mm-64-define-ARCH_PAGE_TABLE_SYNC_MASK-and-arch_.patch
    (git-fixes CVE-2025-39845 bsc#1250262).
  - Update
    patches.suse/xfs-do-not-propagate-ENODATA-disk-errors-into-xattr-code.patch
    (git-fixes CVE-2025-39835 bsc#1250025).
  - commit ccb1ac6
  - i40e: Fix potential invalid access when MAC list is empty (CVE-2025-39853 bsc#1250275)
  - commit eaef03f
  - RDMA/siw: Always report immediate post SQ errors (git-fixes)
  - commit 6353dba
  - RDMA/rxe: Fix race in do_task() when draining (git-fixes)
  - commit b9fe6cd
  - IB/sa: Fix sa_local_svc_timeout_ms read race (git-fixes)
  - commit d793b3b
  - RDMA/core: Resolve MAC of next-hop device without ARP support (git-fixes)
  - commit 5f77a41
  - RDMA/cm: Rate limit destroy CM ID timeout error message (git-fixes)
  - commit 8c45dbb
  - RDMA/mlx5: Fix vport loopback forcing for MPV device (git-fixes)
  - commit d3a8859
  - RDMA/mlx5: Better estimate max_qp_wr to reflect WQE count (git-fixes)
  - commit d4e0310

++++ kernel-rt:

  - wifi: ath12k: Add MODULE_FIRMWARE() entries (bsc#1250952).
  - commit 2e6fdfd
  - scsi: qla2xxx: Fix incorrect sign of error code in
    qla_nvme_xmt_ls_rsp() (git-fixes).
  - scsi: qla2xxx: Fix incorrect sign of error code in
    START_SP_W_RETRIES() (git-fixes).
  - scsi: qla2xxx: edif: Fix incorrect sign of error code
    (git-fixes).
  - scsi: qla2xxx: Use secs_to_jiffies() instead of
    msecs_to_jiffies() (git-fixes).
  - scsi: qla2xxx: Remove firmware URL (git-fixes).
  - scsi: qla2xxx: Avoid stack frame size warning in qla_dfs
    (git-fixes).
  - commit f40dfff
  - scsi: lpfc: Copyright updates for 14.4.0.11 patches
    (bsc#1250519).
  - scsi: lpfc: Update lpfc version to 14.4.0.11 (bsc#1250519).
  - scsi: lpfc: Convert debugfs directory counts from atomic to
    unsigned int (bsc#1250519).
  - scsi: lpfc: Clean up extraneous phba dentries (bsc#1250519).
  - scsi: lpfc: Use switch case statements in DIF debugfs handlers
    (bsc#1250519).
  - scsi: lpfc: Define size of debugfs entry for xri rebalancing
    (bsc#1250519).
  - scsi: lpfc: Ensure PLOGI_ACC is sent prior to PRLI in Point
    to Point topology (bsc#1250519).
  - scsi: lpfc: Check return status of lpfc_reset_flush_io_context
    during TGT_RESET (bsc#1250519).
  - scsi: lpfc: Decrement ndlp kref after FDISC retries exhausted
    (bsc#1250519).
  - scsi: lpfc: Remove ndlp kref decrement clause for F_Port_Ctrl
    in lpfc_cleanup (bsc#1250519).
  - scsi: lpfc: Clean up allocated queues when queue setup mbox
    commands fail (bsc#1250519).
  - scsi: lpfc: Abort outstanding ELS WQEs regardless of if rmmod
    is in progress (bsc#1250519).
  - scsi: lpfc: Remove unused member variables in struct lpfc_hba
    and lpfc_vport (bsc#1250519).
  - scsi: lpfc: Use int type to store negative error codes
    (bsc#1250519).
  - scsi: fc: Avoid -Wflex-array-member-not-at-end warnings
    (bsc#1250519).
  - scsi: lpfc: use min() to improve code (bsc#1250519).
  - scsi: lpfc: Fix buffer free/clear order in deferred receive path
    (bsc#1250519).
  - scsi: lpfc: Remove redundant assignment to avoid memory leak
    (bsc#1250519).
  - scsi: lpfc: Fix wrong function reference in a comment
    (bsc#1250519).
  - lpfc: don't use file->f_path.dentry for comparisons
    (bsc#1250519).
  - commit 833345a
  - nvme-tcp: send only permitted commands for secure concat
    (git-fixes).
  - nvme-auth: update bi_directional flag (git-fixes).
  - nvme: fix PI insert on write (git-fixes).
  - commit bfff0fa
  - nvme-fc: use lock accessing port_state and rport state
    (bsc#1245193 bsc#1247500).
  - nvmet-fcloop: call done callback even when remote port is gone
    (bsc#1245193 bsc#1247500).
  - nvmet-fc: avoid scheduling association deletion twice
    (bsc#1245193 bsc#1247500).
  - nvmet-fc: move lsop put work to nvmet_fc_ls_req_op (bsc#1245193
    bsc#1247500).
  - commit 343e69e
  - ppp: fix memory leak in pad_compress_skb (CVE-2025-39847
    bsc#1250292).
  - ixgbe: fix incorrect map used in eee linkmode (CVE-2025-39922
    bsc#1250722).
  - ice: fix NULL access of tx->in_use in ice_ll_ts_intr
    (CVE-2025-39854 bsc#1250297).
  - vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop
    objects (CVE-2025-39850 bsc#1250276).
  - commit bb7194b
  - NFSv4.1: fix backchannel max_resp_sz verification check
    (git-fixes).
  - commit 875c2e0
  - igb: Fix NULL pointer dereference in ethtool loopback test (CVE-2025-39875 bsc#1250398)
  - commit 42c851b
  - sched/deadline: Initialize dl_servers after SMP (git-fixes)
  - commit 6da3701
  - sched_ext, sched/core: Don't call scx_group_set_weight() (git-fixes)
  - commit ea277bd
  - cpufreq/sched: Explicitly synchronize limits_changed flag (git-fixes)
  - commit aa9d54c
  - cpufreq/sched: Fix the usage of CPUFREQ_NEED_UPDATE_LIMITS (git-fixes)
  - commit 74fd037
  - sched_ext: Fix invalid irq restore in scx_ops_bypass() (bsc#1235953 CVE-2024-57891)
  - commit 9fe8fce
  - Update
    patches.suse/ACPI-APEI-send-SIGBUS-to-current-task-if-synchronous.patch
    (stable-fixes CVE-2025-39763 bsc#1249615).
  - Update
    patches.suse/ACPI-pfr_update-Fix-the-driver-update-version-check.patch
    (git-fixes CVE-2025-39701 bsc#1249308).
  - Update
    patches.suse/ALSA-hda-ca0132-Fix-buffer-overflow-in-add_tuning_co.patch
    (stable-fixes CVE-2025-39751 bsc#1249538).
  - Update
    patches.suse/ALSA-timer-fix-ida_free-call-while-not-allocated.patch
    (git-fixes CVE-2025-39765 bsc#1249509).
  - Update
    patches.suse/ALSA-usb-audio-Validate-UAC3-cluster-segment-descrip.patch
    (git-fixes CVE-2025-39757 bsc#1249515).
  - Update
    patches.suse/ALSA-usb-audio-Validate-UAC3-power-domain-descriptor.patch
    (git-fixes CVE-2025-38729 bsc#1249164).
  - Update
    patches.suse/ASoC-core-Check-for-rtd-NULL-in-snd_soc_remove_pcm_r.patch
    (stable-fixes CVE-2025-38706 bsc#1249195).
  - Update
    patches.suse/Bluetooth-Fix-use-after-free-in-l2cap_sock_cleanup_l.patch
    (git-fixes CVE-2025-39860 bsc#1250247).
  - Update
    patches.suse/Bluetooth-l2cap-Check-encryption-key-size-on-incomin.patch
    (git-fixes CVE-2025-39889 bsc#1249833).
  - Update
    patches.suse/Bluetooth-vhci-Prevent-use-after-free-by-removing-de.patch
    (git-fixes CVE-2025-39861 bsc#1250249).
  - Update
    patches.suse/HID-asus-fix-UAF-via-HID_CLAIMED_INPUT-validation.patch
    (git-fixes CVE-2025-39824 bsc#1250007).
  - Update
    patches.suse/HID-hid-ntrig-fix-unable-to-handle-page-fault-in-ntr.patch
    (stable-fixes CVE-2025-39808 bsc#1250088).
  - Update
    patches.suse/HID-multitouch-fix-slab-out-of-bounds-access-in-mt_r.patch
    (git-fixes CVE-2025-39806 bsc#1249888).
  - Update
    patches.suse/NFS-Fix-a-race-when-updating-an-existing-write.patch
    (git-fixes CVE-2025-39697 bsc#1249319).
  - Update
    patches.suse/NFS-Fix-filehandle-bounds-checking-in-nfs_fh_to_dentry.patch
    (git-fixes CVE-2025-39730 bsc#1249296).
  - Update
    patches.suse/NFS-Fix-the-setting-of-capabilities-when-automounting-a-new-filesystem.patch
    (git-fixes CVE-2025-39798 bsc#1249774).
  - Update
    patches.suse/PCI-endpoint-Fix-configfs-group-list-head-handling.patch
    (git-fixes CVE-2025-39783 bsc#1249486).
  - Update
    patches.suse/RDMA-hfi1-fix-possible-divide-by-zero-in-find_hw_thr.patch
    (git-fixes CVE-2025-39742 bsc#1249479).
  - Update
    patches.suse/RDMA-rxe-Flush-delayed-SKBs-while-releasing-RXE-reso.patch
    (git-fixes CVE-2025-39695 bsc#1249306).
  - Update
    patches.suse/RDMA-siw-Fix-the-sendmsg-byte-count-in-siw_tcp_sendp.patch
    (git-fixes CVE-2025-39758 bsc#1249490).
  - Update
    patches.suse/accel-ivpu-Prevent-recovery-work-from-being-queued-d.patch
    (git-fixes CVE-2025-39896 bsc#1250716).
  - Update
    patches.suse/ax25-properly-unshare-skbs-in-ax25_kiss_rcv.patch
    (git-fixes CVE-2025-39848 bsc#1250298).
  - Update
    patches.suse/batman-adv-fix-OOB-read-write-in-network-coding-deco.patch
    (git-fixes CVE-2025-39839 bsc#1250291).
  - Update
    patches.suse/bnxt_en-Fix-memory-corruption-when-FW-resources-chan.patch
    (git-fixes CVE-2025-39810 bsc#1249975).
  - Update
    patches.suse/bpf-Forget-ranges-when-refining-tnum-after-JSET.patch
    (git-fixes CVE-2025-39748 bsc#1249587).
  - Update
    patches.suse/btrfs-abort-transaction-on-unexpected-eb-generation-.patch
    (git-fixes CVE-2025-39800 bsc#1250177).
  - Update
    patches.suse/btrfs-do-not-allow-relocation-of-partially-dropped-s.patch
    (bsc#1249540 CVE-2025-39738).
  - Update
    patches.suse/btrfs-fix-subvolume-deletion-lockup-caused-by-inodes.patch
    (git-fixes CVE-2025-39884 bsc#1250386).
  - Update
    patches.suse/btrfs-qgroup-fix-race-between-quota-disable-and-quot.patch
    (git-fixes CVE-2025-39759 bsc#1249522).
  - Update
    patches.suse/bus-mhi-host-Detect-events-pointing-to-unexpected-TR.patch
    (git-fixes CVE-2025-39790 bsc#1249548).
  - Update
    patches.suse/can-j1939-implement-NETDEV_UNREGISTER-notification-h.patch
    (git-fixes CVE-2025-39925 bsc#1250736).
  - Update
    patches.suse/can-xilinx_can-xcan_write_frame-fix-use-after-free-o.patch
    (git-fixes CVE-2025-39873 bsc#1250371).
  - Update
    patches.suse/comedi-Fix-use-of-uninitialized-memory-in-do_insn_io.patch
    (git-fixes CVE-2025-39684 bsc#1249281).
  - Update
    patches.suse/comedi-Make-insn_rw_emulate_bits-do-insn-n-samples.patch
    (git-fixes CVE-2025-39686 bsc#1249312).
  - Update
    patches.suse/comedi-fix-race-between-polling-and-detaching.patch
    (git-fixes CVE-2025-38687 bsc#1249177).
  - Update
    patches.suse/comedi-pcl726-Prevent-invalid-irq-number.patch
    (git-fixes CVE-2025-39685 bsc#1249282).
  - Update
    patches.suse/crypto-caam-Prevent-crash-on-suspend-with-iMX8QM-iMX.patch
    (git-fixes CVE-2025-39722 bsc#1249301).
  - Update
    patches.suse/crypto-qat-flush-misc-workqueue-during-device-shutdo.patch
    (git-fixes CVE-2025-39721 bsc#1249323).
  - Update
    patches.suse/dmaengine-idxd-Fix-double-free-in-idxd_setup_wqs.patch
    (git-fixes CVE-2025-39870 bsc#1250402).
  - Update
    patches.suse/dmaengine-idxd-Remove-improper-idxd_free.patch
    (git-fixes CVE-2025-39871 bsc#1250377).
  - Update
    patches.suse/dmaengine-qcom-bam_dma-Fix-DT-error-handling-for-num.patch
    (git-fixes CVE-2025-39923 bsc#1250741).
  - Update
    patches.suse/dmaengine-ti-edma-Fix-memory-allocation-size-for-que.patch
    (git-fixes CVE-2025-39869 bsc#1250406).
  - Update
    patches.suse/drm-amd-display-Add-null-pointer-check-in-mod_hdcp_h.patch
    (git-fixes CVE-2025-39675 bsc#1249263).
  - Update
    patches.suse/drm-amd-display-Avoid-a-NULL-pointer-dereference.patch
    (stable-fixes CVE-2025-39693 bsc#1249279).
  - Update
    patches.suse/drm-amd-display-fix-a-Null-pointer-dereference-vulne.patch
    (stable-fixes CVE-2025-39705 bsc#1249295).
  - Update patches.suse/drm-amd-pm-fix-null-pointer-access.patch
    (stable-fixes CVE-2025-38705 bsc#1249334).
  - Update
    patches.suse/drm-amdgpu-check-if-hubbub-is-NULL-in-debugfs-amdgpu.patch
    (stable-fixes CVE-2025-39707 bsc#1249333).
  - Update
    patches.suse/drm-amdkfd-Destroy-KFD-debugfs-after-destroy-KFD-wq.patch
    (stable-fixes CVE-2025-39706 bsc#1249413).
  - Update
    patches.suse/drm-hisilicon-hibmc-fix-the-hibmc-loaded-failed-bug.patch
    (git-fixes CVE-2025-39772 bsc#1249506).
  - Update
    patches.suse/drm-mediatek-Add-error-handling-for-old-state-CRTC-i.patch
    (git-fixes CVE-2025-39807 bsc#1249887).
  - Update
    patches.suse/drm-mediatek-fix-potential-OF-node-use-after-free.patch
    (git-fixes CVE-2025-39882 bsc#1250389).
  - Update
    patches.suse/drm-msm-Add-error-handling-for-krealloc-in-metadata-.patch
    (stable-fixes CVE-2025-39747 bsc#1249566).
  - Update
    patches.suse/drm-nouveau-nvif-Fix-potential-memory-leak-in-nvif_v.patch
    (git-fixes CVE-2025-39679 bsc#1249338).
  - Update
    patches.suse/drm-xe-Make-dma-fences-compliant-with-the-safe-acces.patch
    (stable-fixes CVE-2025-38703 bsc#1249193).
  - Update
    patches.suse/drm-xe-vm-Clear-the-scratch_pt-pointer-on-error.patch
    (git-fixes CVE-2025-39811 bsc#1249915).
  - Update
    patches.suse/efi-stmm-Fix-incorrect-buffer-allocation-method.patch
    (git-fixes CVE-2025-39836 bsc#1249904).
  - Update
    patches.suse/exfat-add-cluster-chain-loop-check-for-dir.patch
    (git-fixes CVE-2025-38692 bsc#1249221).
  - Update
    patches.suse/fbdev-Fix-vmalloc-out-of-bounds-write-in-fast_imageb.patch
    (stable-fixes CVE-2025-38685 bsc#1249220).
  - Update
    patches.suse/fbdev-fix-potential-buffer-overflow-in-do_register_f.patch
    (stable-fixes CVE-2025-38702 bsc#1249254).
  - Update patches.suse/gve-prevent-ethtool-ops-after-shutdown.patch
    (git-fixes CVE-2025-38735 bsc#1249288).
  - Update patches.suse/habanalabs-fix-UAF-in-export_dmabuf.patch
    (git-fixes CVE-2025-38722 bsc#1249163).
  - Update
    patches.suse/iio-imu-bno055-fix-OOB-access-of-hw_xlate-array.patch
    (git-fixes CVE-2025-39719 bsc#1249271).
  - Update
    patches.suse/iio-light-as73211-Ensure-buffer-holes-are-zeroed.patch
    (git-fixes CVE-2025-39687 bsc#1249316).
  - Update
    patches.suse/iommu-arm-smmu-qcom-Add-SM6115-MDSS-compatible.patch
    (git-fixes CVE-2025-39739 bsc#1249542).
  - Update
    patches.suse/mISDN-hfcpci-Fix-warning-when-deleting-uninitialized.patch
    (git-fixes CVE-2025-39833 bsc#1250028).
  - Update
    patches.suse/media-dvb-frontends-dib7090p-fix-null-ptr-deref-in-d.patch
    (stable-fixes CVE-2025-38694 bsc#1249272).
  - Update
    patches.suse/media-dvb-frontends-w7090p-fix-null-ptr-deref-in-w70.patch
    (stable-fixes CVE-2025-38693 bsc#1249190).
  - Update
    patches.suse/media-ivsc-Fix-crash-at-shutdown-due-to-missing-mei_.patch
    (git-fixes CVE-2025-39711 bsc#1249274).
  - Update
    patches.suse/media-mt9m114-Fix-deadlock-in-get_frame_interval-set.patch
    (git-fixes CVE-2025-39712 bsc#1249269).
  - Update
    patches.suse/media-rainshadow-cec-fix-TOCTOU-race-condition-in-ra.patch
    (git-fixes CVE-2025-39713 bsc#1249321).
  - Update
    patches.suse/media-usbtv-Lock-resolution-while-streaming.patch
    (git-fixes CVE-2025-39714 bsc#1249273).
  - Update
    patches.suse/media-uvcvideo-Fix-1-byte-out-of-bounds-read-in-uvc_.patch
    (git-fixes CVE-2025-38680 bsc#1249203).
  - Update
    patches.suse/media-venus-Add-a-check-for-packet-size-after-readin.patch
    (git-fixes CVE-2025-39710 bsc#1249304).
  - Update
    patches.suse/media-venus-Fix-OOB-read-due-to-missing-payload-boun.patch
    (git-fixes CVE-2025-38679 bsc#1249202).
  - Update
    patches.suse/media-venus-protect-against-spurious-interrupts-duri.patch
    (git-fixes CVE-2025-39709 bsc#1249278).
  - Update
    patches.suse/mm-damon-lru_sort-avoid-divide-by-zero-in-damon_lru_.patch
    (git-fixes CVE-2025-39909 bsc#1250711).
  - Update
    patches.suse/mm-damon-ops-common-ignore-migration-request-to-inva.patch
    (git-fixes CVE-2025-39700 bsc#1249309).
  - Update
    patches.suse/mm-damon-reclaim-avoid-divide-by-zero-in-damon_recla.patch
    (git-fixes CVE-2025-39916 bsc#1250719).
  - Update
    patches.suse/mm-damon-sysfs-fix-use-after-free-in-state_show.patch
    (git-fixes CVE-2025-39877 bsc#1250408).
  - Update
    patches.suse/mm-move-page-table-sync-declarations-to-linux-pgtabl.patch
    (git-fixes CVE-2025-39844 bsc#1250268).
  - Update
    patches.suse/mm-ptdump-take-the-memory-hotplug-lock-inside-ptdump_walk_.patch
    (git-fixes CVE-2025-38681 bsc#1249204).
  - Update
    patches.suse/mm-swap-fix-potential-buffer-overflow-in-setup_clust.patch
    (git-fixes CVE-2025-39727 bsc#1249297).
  - Update
    patches.suse/mm-userfaultfd-fix-kmap_local-LIFO-ordering-for-CONF.patch
    (git-fixes CVE-2025-39899 bsc#1250739).
  - Update
    patches.suse/msft-hv-3329-hv_netvsc-Fix-panic-during-namespace-deletion-with-V.patch
    (bsc#1248111 CVE-2025-38683 bsc#1249159).
  - Update
    patches.suse/mtd-rawnand-stm32_fmc2-avoid-overlapping-mappings-on.patch
    (git-fixes CVE-2025-39907 bsc#1250713).
  - Update
    patches.suse/net-mlx5-Fix-lockdep-assertion-on-sync-reset-unload-.patch
    (git-fixes CVE-2025-39832 bsc#1249901).
  - Update
    patches.suse/net-mlx5-HWS-Fix-memory-leak-in-hws_action_get_share.patch
    (git-fixes CVE-2025-39834 bsc#1250021).
  - Update
    patches.suse/net-rose-convert-use-field-to-refcount_t.patch
    (git-fixes CVE-2025-39826 bsc#1250203).
  - Update
    patches.suse/net-rose-include-node-references-in-rose_neigh-refco.patch
    (git-fixes CVE-2025-39827 bsc#1250204).
  - Update
    patches.suse/net-usb-asix_devices-Fix-PHY-address-mask-in-MDIO-bu.patch
    (git-fixes CVE-2025-38736 bsc#1249318).
  - Update
    patches.suse/net-usb-asix_devices-add-phy_mask-for-ax88772-mdio-b.patch
    (git-fixes CVE-2025-38725 bsc#1249170).
  - Update
    patches.suse/netfilter-ctnetlink-fix-refcount-leak-on-table-dump.patch
    (git-fixes CVE-2025-38721 bsc#1249176).
  - Update
    patches.suse/netlink-avoid-infinite-retry-looping-in-netlink_unic.patch
    (CVE-2025-38465 bsc#1247118 CVE-2025-38727 bsc#1249166).
  - Update
    patches.suse/nfsd-handle-get_client_locked-failure-in-nfsd4_setclientid_confirm.patch
    (git-fixes CVE-2025-38724 bsc#1249169).
  - Update
    patches.suse/pNFS-Fix-uninited-ptr-deref-in-block-scsi-layout.patch
    (git-fixes CVE-2025-38691 bsc#1249215).
  - Update
    patches.suse/platform-x86-amd-hsmp-Ensure-sock-metric_tbl_addr-is.patch
    (git-fixes CVE-2025-39678 bsc#1249290).
  - Update
    patches.suse/s390-ism-fix-concurrency-management-in-ism_cmd.patch
    (git-fixes bsc#1247372 CVE-2025-39726 bsc#1249266).
  - Update
    patches.suse/s390-mm-Do-not-map-lowcore-with-identity-mapping.patch
    (git-fixes bsc#1249066 CVE-2025-38733 bsc#1249313).
  - Update patches.suse/s390-sclp-Fix-SCCB-present-check.patch
    (git-fixes bsc#1249065 CVE-2025-39694 bsc#1249299).
  - Update
    patches.suse/scsi-lpfc-Check-for-hdwq-null-ptr-when-cleaning-up-l.patch
    (bsc#1245260 bsc#1243100 bsc#1246125 CVE-2025-38695
    bsc#1249285).
  - Update
    patches.suse/scsi-ufs-exynos-Fix-programming-of-HCI_UTRL_NEXUS_TYPE.patch
    (git-fixes CVE-2025-39788 bsc#1249547).
  - Update patches.suse/serial-8250-fix-panic-due-to-PSLVERR.patch
    (git-fixes CVE-2025-39724 bsc#1249265).
  - Update
    patches.suse/soc-qcom-mdt_loader-Ensure-we-don-t-read-past-the-EL.patch
    (git-fixes CVE-2025-39787 bsc#1249545).
  - Update
    patches.suse/usb-core-config-Prevent-OOB-read-in-SS-endpoint-comp.patch
    (stable-fixes CVE-2025-39760 bsc#1249598).
  - Update
    patches.suse/usb-dwc3-Remove-WARN_ON-for-device-endpoint-command-.patch
    (stable-fixes CVE-2025-39801 bsc#1250450).
  - Update
    patches.suse/vsock-virtio-Validate-length-in-packet-header-before.patch
    (git-fixes CVE-2025-39718 bsc#1249305).
  - Update
    patches.suse/wifi-ath10k-shutdown-driver-when-hardware-is-unrelia.patch
    (stable-fixes CVE-2025-39746 bsc#1249516).
  - Update
    patches.suse/wifi-ath11k-fix-sleeping-in-atomic-in-ath11k_mac_op_.patch
    (git-fixes CVE-2025-39732 bsc#1249292).
  - Update
    patches.suse/wifi-ath12k-Correct-tid-cleanup-when-tid-setup-fails.patch
    (stable-fixes CVE-2025-39750 bsc#1249523).
  - Update
    patches.suse/wifi-ath12k-Decrement-TID-on-RX-peer-frag-setup-erro.patch
    (stable-fixes CVE-2025-39761 bsc#1249554).
  - Update
    patches.suse/wifi-ath12k-fix-memory-leak-in-ath12k_service_ready_.patch
    (git-fixes CVE-2025-39890 bsc#1250334).
  - Update
    patches.suse/wifi-brcmfmac-fix-use-after-free-when-rescheduling-b.patch
    (git-fixes CVE-2025-39863 bsc#1250281).
  - Update
    patches.suse/wifi-cfg80211-fix-use-after-free-in-cmp_bss.patch
    (git-fixes CVE-2025-39864 bsc#1250242).
  - Update
    patches.suse/wifi-cfg80211-sme-cap-SSID-length-in-__cfg80211_conn.patch
    (git-fixes CVE-2025-39849 bsc#1250266).
  - Update patches.suse/wifi-mt76-fix-linked-list-corruption.patch
    (git-fixes CVE-2025-39918 bsc#1250729).
  - Update
    patches.suse/wifi-mwifiex-Initialize-the-chan_stats-array-to-zero.patch
    (git-fixes CVE-2025-39891 bsc#1250712).
  - Update
    patches.suse/x86-mm-64-define-ARCH_PAGE_TABLE_SYNC_MASK-and-arch_.patch
    (git-fixes CVE-2025-39845 bsc#1250262).
  - Update
    patches.suse/xfs-do-not-propagate-ENODATA-disk-errors-into-xattr-code.patch
    (git-fixes CVE-2025-39835 bsc#1250025).
  - commit ccb1ac6
  - i40e: Fix potential invalid access when MAC list is empty (CVE-2025-39853 bsc#1250275)
  - commit eaef03f
  - RDMA/siw: Always report immediate post SQ errors (git-fixes)
  - commit 6353dba
  - RDMA/rxe: Fix race in do_task() when draining (git-fixes)
  - commit b9fe6cd
  - IB/sa: Fix sa_local_svc_timeout_ms read race (git-fixes)
  - commit d793b3b
  - RDMA/core: Resolve MAC of next-hop device without ARP support (git-fixes)
  - commit 5f77a41
  - RDMA/cm: Rate limit destroy CM ID timeout error message (git-fixes)
  - commit 8c45dbb
  - RDMA/mlx5: Fix vport loopback forcing for MPV device (git-fixes)
  - commit d3a8859
  - RDMA/mlx5: Better estimate max_qp_wr to reflect WQE count (git-fixes)
  - commit d4e0310

++++ mozilla-nss:

  - update to NSS 3.112.2
    * bmo#1970079 - Prevent leaks during pkcs12 decoding.
    * bmo#1988046 - SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates
  - Adding patch bmo1980465.patch to fix bug on s390x (bmo#1980465)
  - Adding patch bmo1956754.patch to fix possible undefined behaviour (bmo#1956754)

++++ libnvme:

  - Update to version 1.11+17.g6d55624d:
    * linux: use EVP_PKEY_CTX_add1_hkdf_info only once in compat function (bsc#1246914)
    * nvme/linux: check for empty digest in gen_tls_identity() (bsc#1246914)
    * nvme/linux: add fallback implementation for nvme_insert_tls_key_compat() (bsc#1246914)
    * linux: fix HKDF TLS key derivation back to OpenSSL 3.0.8 (bsc#1246914)
    * libnvme: TLS PSK derivation fixes (bsc#1246914)
    * linux: rename __nvme_insert_tls_key_versioned() to __nvme_insert_tls_key() (bsc#1246914)
    * linux: rename __nvme_insert_tls_key() to __nvme_import_tls_key() (bsc#1246914)
    * test/psk: add testcase for TLS identity derivation (bsc#1246914)
    * linux: set errno when nvme_generate_tls_key_identity() fails (bsc#1246914)
    * tree: do not try to strdup NULL pointer (bsc#1247225)
    * tree: always set the host key (bsc#1246560)
    * tree: add routine to fetch subsys firmware rev (bsc#1240518)
    * tree: add routine to fetch subsys model (bsc#1240518)

++++ nvidia-open-driver-G06-signed:

  - update CUDA variant to 580.95.05

++++ nvme-cli:

  - Update to version 2.11+29.g35e62868:
    * nvme: add --compat flag for 'gen-tls-key' and 'check-tls-key' (bsc#1246914)
    * netapp-ontapdev: update invalid device handling (bsc#1247017)
    * netapp-smdev: update invalid device handling (bsc#1247017)
    * nvme-print: display fw-rev in list-subsys output (bsc#1240518)
    * nvme-print: display model in list-subsys output (bsc#1240518)
    * netapp-ontapdev: add subsysname to regular output (bsc#1240518)
    * netapp-ontapdev: add subsysname to the verbose output (bsc#1240518)
    * Revert "nvme-print-json: display only verbose output"
    * nvme: check for valid output format (bsc#1237275)
    * nvme: make get-feature JSON output print everything (bsc#1237275)
    * nvme: make -v output consistent with -H output for nvme get-feature (bsc#1237275)
    * nvme: make -v output consistent with -H output for nvme get-property (bsc#1237275)
    * nvme-print-stdout: add details in list-ns verbose output (bsc#1237275)
    * nvme-print-stdout: add descriptions for nsze, ncap & nuse (bsc#1237275)
    * netapp-ontapdev: correct the basestr header (bsc#1237275)
    * netapp-smdev: update err msg for no smdevices (bsc#1237275)
    * netapp-ontapdev: update err msg for no ontapdevices (bsc#1237275)
    * netapp-smdev: update basestr header in verbose output (bsc#1237275)
    * netapp-ontapdev: update basestr headers in verbose output
    * netapp-smdev: add verbose output
    * netapp-smdev: remove redundant code
    * nvme-netapp: update err messages
    * netapp-ontapdev: fix JSON output for nsze & nuse
    * netapp-ontapdev: fix fw version handling
    * netapp-ontapdev: add verbose output

------------------------------------------------------------------
------------------  2025-10-5  -  Oct 5 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - bus: mhi: ep: Fix chained transfer handling in read path
    (git-fixes).
  - bus: mhi: host: Do not use uninitialized 'dev' pointer in
    mhi_init_irq_setup() (git-fixes).
  - iio: imu: inv_icm42600: Drop redundant pm_runtime
    reinitialization in resume (git-fixes).
  - iio: consumers: Fix offset handling in
    iio_convert_raw_to_processed() (git-fixes).
  - iio: consumers: Fix handling of negative channel scale in
    iio_convert_raw_to_processed() (git-fixes).
  - iio: dac: ad5421: use int type to store negative error codes
    (git-fixes).
  - iio: dac: ad5360: use int type to store negative error codes
    (git-fixes).
  - iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
    (git-fixes).
  - iio: frequency: adf4350: Fix prescaler usage (git-fixes).
  - iio: xilinx-ams: Fix AMS_ALARM_THR_DIRECT_MASK (git-fixes).
  - iio: xilinx-ams: Unmask interrupts after updating alarms
    (git-fixes).
  - iio/adc/pac1934: fix channel disable configuration (git-fixes).
  - misc: genwqe: Fix incorrect cmd field being reported in error
    (git-fixes).
  - uio: uio_pdrv_genirq: Remove MODULE_DEVICE_TABLE (git-fixes).
  - usb: vhci-hcd: Prevent suspending virtually attached devices
    (git-fixes).
  - thunderbolt: Compare HMAC values in constant time (git-fixes).
  - Revert "usb: xhci: Avoid Stop Endpoint retry loop if the
    endpoint seems Running" (git-fixes).
  - usb: typec: tipd: Clear interrupts first (git-fixes).
  - usb: cdns3: cdnsp-pci: remove redundant pci_disable_device()
    call (git-fixes).
  - usb: gadget: configfs: Correctly set use_os_string at bind
    (git-fixes).
  - usb: phy: twl6030: Fix incorrect type for ret (git-fixes).
  - usb: misc: qcom_eud: Access EUD_MODE_MANAGER2 through secure
    calls (git-fixes).
  - usb: host: max3421-hcd: Fix error pointer dereference in probe
    cleanup (git-fixes).
  - tty: n_gsm: Don't block input queue by waiting MSC (git-fixes).
  - serial: max310x: Add error checking in probe() (git-fixes).
  - mtd: rawnand: omap2: fix device leak on probe failure
    (git-fixes).
  - mtd: rawnand: atmel: Fix error handling path in
    atmel_nand_controller_add_nands (git-fixes).
  - HID: intel-ish-ipc: Remove redundant ready check after timeout
    function (git-fixes).
  - HID: hidraw: tighten ioctl command parsing (git-fixes).
  - KEYS: trusted_tpm1: Compare HMAC values in constant time
    (git-fixes).
  - hwrng: ks-sa - fix division by zero in ks_sa_rng_init
    (git-fixes).
  - KEYS: X.509: Fix Basic Constraints CA flag parsing (git-fixes).
  - crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs
    (git-fixes).
  - crypto: aspeed - Fix dma_unmap_sg() direction (git-fixes).
  - crypto: atmel - Fix dma_unmap_sg() direction (git-fixes).
  - crypto: rockchip - Fix dma_unmap_sg() nents value (git-fixes).
  - crypto: hisilicon/qm - check whether the input function and
    PF are on the same device (git-fixes).
  - crypto: hisilicon - re-enable address prefetch after device
    resuming (git-fixes).
  - crypto: hisilicon/zip - remove unnecessary validation for
    high-performance mode configurations (git-fixes).
  - crypto: octeontx2 - Call strscpy() with correct size argument
    (git-fixes).
  - hwrng: nomadik - add ARM_AMBA dependency (git-fixes).
  - crypto: keembay - Add missing check after sg_nents_for_len()
    (git-fixes).
  - commit 619851e

++++ kernel-rt:

  - bus: mhi: ep: Fix chained transfer handling in read path
    (git-fixes).
  - bus: mhi: host: Do not use uninitialized 'dev' pointer in
    mhi_init_irq_setup() (git-fixes).
  - iio: imu: inv_icm42600: Drop redundant pm_runtime
    reinitialization in resume (git-fixes).
  - iio: consumers: Fix offset handling in
    iio_convert_raw_to_processed() (git-fixes).
  - iio: consumers: Fix handling of negative channel scale in
    iio_convert_raw_to_processed() (git-fixes).
  - iio: dac: ad5421: use int type to store negative error codes
    (git-fixes).
  - iio: dac: ad5360: use int type to store negative error codes
    (git-fixes).
  - iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE
    (git-fixes).
  - iio: frequency: adf4350: Fix prescaler usage (git-fixes).
  - iio: xilinx-ams: Fix AMS_ALARM_THR_DIRECT_MASK (git-fixes).
  - iio: xilinx-ams: Unmask interrupts after updating alarms
    (git-fixes).
  - iio/adc/pac1934: fix channel disable configuration (git-fixes).
  - misc: genwqe: Fix incorrect cmd field being reported in error
    (git-fixes).
  - uio: uio_pdrv_genirq: Remove MODULE_DEVICE_TABLE (git-fixes).
  - usb: vhci-hcd: Prevent suspending virtually attached devices
    (git-fixes).
  - thunderbolt: Compare HMAC values in constant time (git-fixes).
  - Revert "usb: xhci: Avoid Stop Endpoint retry loop if the
    endpoint seems Running" (git-fixes).
  - usb: typec: tipd: Clear interrupts first (git-fixes).
  - usb: cdns3: cdnsp-pci: remove redundant pci_disable_device()
    call (git-fixes).
  - usb: gadget: configfs: Correctly set use_os_string at bind
    (git-fixes).
  - usb: phy: twl6030: Fix incorrect type for ret (git-fixes).
  - usb: misc: qcom_eud: Access EUD_MODE_MANAGER2 through secure
    calls (git-fixes).
  - usb: host: max3421-hcd: Fix error pointer dereference in probe
    cleanup (git-fixes).
  - tty: n_gsm: Don't block input queue by waiting MSC (git-fixes).
  - serial: max310x: Add error checking in probe() (git-fixes).
  - mtd: rawnand: omap2: fix device leak on probe failure
    (git-fixes).
  - mtd: rawnand: atmel: Fix error handling path in
    atmel_nand_controller_add_nands (git-fixes).
  - HID: intel-ish-ipc: Remove redundant ready check after timeout
    function (git-fixes).
  - HID: hidraw: tighten ioctl command parsing (git-fixes).
  - KEYS: trusted_tpm1: Compare HMAC values in constant time
    (git-fixes).
  - hwrng: ks-sa - fix division by zero in ks_sa_rng_init
    (git-fixes).
  - KEYS: X.509: Fix Basic Constraints CA flag parsing (git-fixes).
  - crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs
    (git-fixes).
  - crypto: aspeed - Fix dma_unmap_sg() direction (git-fixes).
  - crypto: atmel - Fix dma_unmap_sg() direction (git-fixes).
  - crypto: rockchip - Fix dma_unmap_sg() nents value (git-fixes).
  - crypto: hisilicon/qm - check whether the input function and
    PF are on the same device (git-fixes).
  - crypto: hisilicon - re-enable address prefetch after device
    resuming (git-fixes).
  - crypto: hisilicon/zip - remove unnecessary validation for
    high-performance mode configurations (git-fixes).
  - crypto: octeontx2 - Call strscpy() with correct size argument
    (git-fixes).
  - hwrng: nomadik - add ARM_AMBA dependency (git-fixes).
  - crypto: keembay - Add missing check after sg_nents_for_len()
    (git-fixes).
  - commit 619851e

------------------------------------------------------------------
------------------  2025-10-4  -  Oct 4 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - rpm/check-for-config-changes: ignore CONFIG_SCHED_PROXY_EXEC, too (bsc#1250946)
    CONFIG_SCHED_PROXY_EXEC is set only when the debug is off, exclusive
    to CONFIG_SCHED_CLASS_EXT.
  - commit ac06fa9
  - drivers/base/node: fix double free in register_one_node()
    (git-fixes).
  - commit 3766861
  - net: nfc: nci: Add parameter validation for packet data
    (git-fixes).
  - net: usb: Remove disruptive netif_wake_queue in
    rtl8150_set_multicast (git-fixes).
  - wifi: ath11k: HAL SRNG: don't deinitialize and re-initialize
    again (git-fixes).
  - wifi: ath10k: avoid unnecessary wait for service ready message
    (git-fixes).
  - wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load()
    (git-fixes).
  - wifi: ath12k: fix wrong logging ID used for CE (git-fixes).
  - wifi: ath12k: fix the fetching of combined rssi (git-fixes).
  - wifi: rtw89: avoid circular locking dependency in
    ser_state_run() (git-fixes).
  - wifi: mac80211: fix Rx packet handling when pubsta information
    is not available (git-fixes).
  - wifi: mt76: mt7915: fix mt7981 pre-calibration (git-fixes).
  - wifi: mt76: mt7996: Convert mt7996_wed_rro_addr to LE
    (git-fixes).
  - wifi: mt76: mt7996: Fix RX packets configuration for primary
    WED device (git-fixes).
  - wifi: mt76: fix potential memory leak in mt76_wmac_probe()
    (git-fixes).
  - wifi: iwlwifi: Remove redundant header files (git-fixes).
  - wifi: mwifiex: send world regulatory domain to driver
    (git-fixes).
  - wifi: virt_wifi: Fix page fault on connect (stable-fixes).
  - net: phy: fix phy_uses_state_machine() (git-fixes).
  - mmc: sdhci-cadence: add Mobileye eyeQ support (stable-fixes).
  - usb: core: Add 0x prefix to quirks debug output (stable-fixes).
  - commit 5a62af8
  - media: tuner: xc5000: Fix use-after-free in xc5000_release
    (git-fixes).
  - media: b2c2: Fix use-after-free causing by irq_check_work in
    flexcop_pci_remove (git-fixes).
  - media: uvcvideo: Mark invalid entities with id
    UVC_INVALID_ENTITY_ID (git-fixes).
  - media: i2c: mt9v111: fix incorrect type for ret (git-fixes).
  - media: venus: firmware: Use correct reset sequence for IRIS2
    (git-fixes).
  - media: s5p-mfc: remove an unused/uninitialized variable
    (git-fixes).
  - media: cec: extron-da-hd-4k-plus: drop external-module make
    commands (git-fixes).
  - media: pci: mg4b: fix uninitialized iio scan data (git-fixes).
  - media: pci: ivtv: Add missing check after DMA map (git-fixes).
  - media: cx18: Add missing check after DMA map (git-fixes).
  - media: st-delta: avoid excessive stack usage (git-fixes).
  - media: mc: Fix MUST_CONNECT handling for pads with no links
    (git-fixes).
  - media: ti: j721e-csi2rx: Fix source subdev link creation
    (git-fixes).
  - media: ti: j721e-csi2rx: Use devm_of_platform_populate
    (git-fixes).
  - media: v4l2-subdev: Fix alloc failure check in
    v4l2_subdev_call_state_try() (git-fixes).
  - media: rj54n1cb0c: Fix memleak in rj54n1_probe() (git-fixes).
  - media: lirc: Fix error handling in lirc_register() (git-fixes).
  - media: zoran: Remove zoran_fh structure (git-fixes).
  - commit 776580e
  - docs: admin-guide: update to current minimum pipe size default
    (git-fixes).
  - maple_tree: fix testing for 32 bit builds (git-fixes).
  - maple_tree: fix MAPLE_PARENT_RANGE32 and parent pointer docs
    (git-fixes).
  - Bluetooth: hci_sync: Fix using random address for BIG/PA
    advertisements (git-fixes).
  - Bluetooth: ISO: don't leak skb in ISO_CONT RX (git-fixes).
  - drm/amdgpu: remove the redeclaration of variable i (git-fixes).
  - drm/msm/dpu: fix incorrect type for ret (git-fixes).
  - drm/amdkfd: Fix error code sign for EINVAL in svm_ioctl()
    (git-fixes).
  - drm/amd/pm: Disable SCLK switching on Oland with high pixel
    clocks (v3) (git-fixes).
  - drm/amd/pm: Disable MCLK switching with non-DC at 120 Hz+ (v2)
    (git-fixes).
  - drm/amd/pm: Treat zero vblank time as too short in si_dpm (v3)
    (git-fixes).
  - drm/amd/pm: Adjust si_upload_smc_data register programming (v3)
    (git-fixes).
  - drm/amd/pm: Fix si_upload_smc_data (v3) (git-fixes).
  - drm/amd/pm: Disable ULV even if unsupported (v3) (git-fixes).
  - drm/amdgpu: Power up UVD 3 for FW validation (v2) (git-fixes).
  - drm/rcar-du: dsi: Fix 1/2/3 lane support (git-fixes).
  - drm/amd/display: Remove redundant semicolons (git-fixes).
  - drm/radeon/r600_cs: clean up of dead code in r600_cs
    (git-fixes).
  - drm/bridge: it6505: select REGMAP_I2C (git-fixes).
  - drm/panel: novatek-nt35560: Fix invalid return value
    (git-fixes).
  - drm/panthor: Fix memory leak in panthor_ioctl_group_create()
    (git-fixes).
  - firmware: firmware: meson-sm: fix compile-test default
    (git-fixes).
  - HID: asus: add support for missing PX series fn keys
    (stable-fixes).
  - can: rcar_can: rcar_can_resume(): fix s2ram with PSCI
    (stable-fixes).
  - i2c: designware: Add quirk for Intel Xe (stable-fixes).
  - drm/i915/backlight: Return immediately when scale() finds
    invalid parameters (stable-fixes).
  - commit 5415587
  - drivers/base/node: handle error properly in register_one_node()
    (git-fixes).
  - Bluetooth: ISO: free rx_skb if not consumed (git-fixes).
  - Bluetooth: ISO: Fix possible UAF on iso_conn_free (git-fixes).
  - Bluetooth: MGMT: Fix not exposing debug UUID on
    MGMT_OP_READ_EXP_FEATURES_INFO (git-fixes).
  - ASoC: wcd934x: fix error handling in wcd934x_codec_parse_data()
    (git-fixes).
  - ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback
    (git-fixes).
  - ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
    (git-fixes).
  - ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
    (git-fixes).
  - ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
    (git-fixes).
  - ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping
    (git-fixes).
  - ASoC: qcom: audioreach: fix potential null pointer dereference
    (git-fixes).
  - ASoC: imx-hdmi: remove cpu_pdev related code (git-fixes).
  - ALSA: pcm: Disable bottom softirqs as part of spin_lock_irq()
    on PREEMPT_RT (git-fixes).
  - ALSA: lx_core: use int type to store negative error codes
    (git-fixes).
  - ALSA: usb-audio: Add mute TLV for playback volumes on more
    devices (stable-fixes).
  - ALSA: usb-audio: move mixer_quirks' min_mute into common quirk
    (stable-fixes).
  - ALSA: usb-audio: Add DSD support for Comtrue USB Audio device
    (stable-fixes).
  - ALSA: usb-audio: Fix build with CONFIG_INPUT=n (git-fixes).
  - ALSA: hda/realtek: Add support for ASUS NUC using CS35L41 HDA
    (stable-fixes).
  - ALSA: usb-audio: Convert comma to semicolon (git-fixes).
  - ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5
    (stable-fixes).
  - ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Simplify NULL comparison in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Avoid multiple assignments in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Drop unnecessary parentheses in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Fix block comments in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Fix code alignment in mixer_quirks
    (stable-fixes).
  - commit 3e06154
  - scsi: smartpqi: Update driver version to 2.1.34-035
    (bsc#1246631).
  - scsi: smartpqi: Enhance WWID logging logic (bsc#1246631).
  - scsi: smartpqi: Take drives offline when controller is offline
    (bsc#1246631).
  - commit 64644a2

++++ kernel-firmware-amdgpu:

  - Update to version 20251004 (git commit 757854f42d83):
    * amdgpu: DMCUB updates for various ASICs
    * Update VCN for Navi1x, Green Sardine and Renoir

++++ kernel-firmware-bluetooth:

  - Update to version 20251004 (git commit 757854f42d83):
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x3BAC_ADBA

++++ kernel-rt:

  - rpm/check-for-config-changes: ignore CONFIG_SCHED_PROXY_EXEC, too (bsc#1250946)
    CONFIG_SCHED_PROXY_EXEC is set only when the debug is off, exclusive
    to CONFIG_SCHED_CLASS_EXT.
  - commit ac06fa9
  - drivers/base/node: fix double free in register_one_node()
    (git-fixes).
  - commit 3766861
  - net: nfc: nci: Add parameter validation for packet data
    (git-fixes).
  - net: usb: Remove disruptive netif_wake_queue in
    rtl8150_set_multicast (git-fixes).
  - wifi: ath11k: HAL SRNG: don't deinitialize and re-initialize
    again (git-fixes).
  - wifi: ath10k: avoid unnecessary wait for service ready message
    (git-fixes).
  - wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load()
    (git-fixes).
  - wifi: ath12k: fix wrong logging ID used for CE (git-fixes).
  - wifi: ath12k: fix the fetching of combined rssi (git-fixes).
  - wifi: rtw89: avoid circular locking dependency in
    ser_state_run() (git-fixes).
  - wifi: mac80211: fix Rx packet handling when pubsta information
    is not available (git-fixes).
  - wifi: mt76: mt7915: fix mt7981 pre-calibration (git-fixes).
  - wifi: mt76: mt7996: Convert mt7996_wed_rro_addr to LE
    (git-fixes).
  - wifi: mt76: mt7996: Fix RX packets configuration for primary
    WED device (git-fixes).
  - wifi: mt76: fix potential memory leak in mt76_wmac_probe()
    (git-fixes).
  - wifi: iwlwifi: Remove redundant header files (git-fixes).
  - wifi: mwifiex: send world regulatory domain to driver
    (git-fixes).
  - wifi: virt_wifi: Fix page fault on connect (stable-fixes).
  - net: phy: fix phy_uses_state_machine() (git-fixes).
  - mmc: sdhci-cadence: add Mobileye eyeQ support (stable-fixes).
  - usb: core: Add 0x prefix to quirks debug output (stable-fixes).
  - commit 5a62af8
  - media: tuner: xc5000: Fix use-after-free in xc5000_release
    (git-fixes).
  - media: b2c2: Fix use-after-free causing by irq_check_work in
    flexcop_pci_remove (git-fixes).
  - media: uvcvideo: Mark invalid entities with id
    UVC_INVALID_ENTITY_ID (git-fixes).
  - media: i2c: mt9v111: fix incorrect type for ret (git-fixes).
  - media: venus: firmware: Use correct reset sequence for IRIS2
    (git-fixes).
  - media: s5p-mfc: remove an unused/uninitialized variable
    (git-fixes).
  - media: cec: extron-da-hd-4k-plus: drop external-module make
    commands (git-fixes).
  - media: pci: mg4b: fix uninitialized iio scan data (git-fixes).
  - media: pci: ivtv: Add missing check after DMA map (git-fixes).
  - media: cx18: Add missing check after DMA map (git-fixes).
  - media: st-delta: avoid excessive stack usage (git-fixes).
  - media: mc: Fix MUST_CONNECT handling for pads with no links
    (git-fixes).
  - media: ti: j721e-csi2rx: Fix source subdev link creation
    (git-fixes).
  - media: ti: j721e-csi2rx: Use devm_of_platform_populate
    (git-fixes).
  - media: v4l2-subdev: Fix alloc failure check in
    v4l2_subdev_call_state_try() (git-fixes).
  - media: rj54n1cb0c: Fix memleak in rj54n1_probe() (git-fixes).
  - media: lirc: Fix error handling in lirc_register() (git-fixes).
  - media: zoran: Remove zoran_fh structure (git-fixes).
  - commit 776580e
  - docs: admin-guide: update to current minimum pipe size default
    (git-fixes).
  - maple_tree: fix testing for 32 bit builds (git-fixes).
  - maple_tree: fix MAPLE_PARENT_RANGE32 and parent pointer docs
    (git-fixes).
  - Bluetooth: hci_sync: Fix using random address for BIG/PA
    advertisements (git-fixes).
  - Bluetooth: ISO: don't leak skb in ISO_CONT RX (git-fixes).
  - drm/amdgpu: remove the redeclaration of variable i (git-fixes).
  - drm/msm/dpu: fix incorrect type for ret (git-fixes).
  - drm/amdkfd: Fix error code sign for EINVAL in svm_ioctl()
    (git-fixes).
  - drm/amd/pm: Disable SCLK switching on Oland with high pixel
    clocks (v3) (git-fixes).
  - drm/amd/pm: Disable MCLK switching with non-DC at 120 Hz+ (v2)
    (git-fixes).
  - drm/amd/pm: Treat zero vblank time as too short in si_dpm (v3)
    (git-fixes).
  - drm/amd/pm: Adjust si_upload_smc_data register programming (v3)
    (git-fixes).
  - drm/amd/pm: Fix si_upload_smc_data (v3) (git-fixes).
  - drm/amd/pm: Disable ULV even if unsupported (v3) (git-fixes).
  - drm/amdgpu: Power up UVD 3 for FW validation (v2) (git-fixes).
  - drm/rcar-du: dsi: Fix 1/2/3 lane support (git-fixes).
  - drm/amd/display: Remove redundant semicolons (git-fixes).
  - drm/radeon/r600_cs: clean up of dead code in r600_cs
    (git-fixes).
  - drm/bridge: it6505: select REGMAP_I2C (git-fixes).
  - drm/panel: novatek-nt35560: Fix invalid return value
    (git-fixes).
  - drm/panthor: Fix memory leak in panthor_ioctl_group_create()
    (git-fixes).
  - firmware: firmware: meson-sm: fix compile-test default
    (git-fixes).
  - HID: asus: add support for missing PX series fn keys
    (stable-fixes).
  - can: rcar_can: rcar_can_resume(): fix s2ram with PSCI
    (stable-fixes).
  - i2c: designware: Add quirk for Intel Xe (stable-fixes).
  - drm/i915/backlight: Return immediately when scale() finds
    invalid parameters (stable-fixes).
  - commit 5415587
  - drivers/base/node: handle error properly in register_one_node()
    (git-fixes).
  - Bluetooth: ISO: free rx_skb if not consumed (git-fixes).
  - Bluetooth: ISO: Fix possible UAF on iso_conn_free (git-fixes).
  - Bluetooth: MGMT: Fix not exposing debug UUID on
    MGMT_OP_READ_EXP_FEATURES_INFO (git-fixes).
  - ASoC: wcd934x: fix error handling in wcd934x_codec_parse_data()
    (git-fixes).
  - ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback
    (git-fixes).
  - ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free
    (git-fixes).
  - ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping
    (git-fixes).
  - ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping
    (git-fixes).
  - ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping
    (git-fixes).
  - ASoC: qcom: audioreach: fix potential null pointer dereference
    (git-fixes).
  - ASoC: imx-hdmi: remove cpu_pdev related code (git-fixes).
  - ALSA: pcm: Disable bottom softirqs as part of spin_lock_irq()
    on PREEMPT_RT (git-fixes).
  - ALSA: lx_core: use int type to store negative error codes
    (git-fixes).
  - ALSA: usb-audio: Add mute TLV for playback volumes on more
    devices (stable-fixes).
  - ALSA: usb-audio: move mixer_quirks' min_mute into common quirk
    (stable-fixes).
  - ALSA: usb-audio: Add DSD support for Comtrue USB Audio device
    (stable-fixes).
  - ALSA: usb-audio: Fix build with CONFIG_INPUT=n (git-fixes).
  - ALSA: hda/realtek: Add support for ASUS NUC using CS35L41 HDA
    (stable-fixes).
  - ALSA: usb-audio: Convert comma to semicolon (git-fixes).
  - ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5
    (stable-fixes).
  - ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Simplify NULL comparison in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Avoid multiple assignments in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Drop unnecessary parentheses in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Fix block comments in mixer_quirks
    (stable-fixes).
  - ALSA: usb-audio: Fix code alignment in mixer_quirks
    (stable-fixes).
  - commit 3e06154
  - scsi: smartpqi: Update driver version to 2.1.34-035
    (bsc#1246631).
  - scsi: smartpqi: Enhance WWID logging logic (bsc#1246631).
  - scsi: smartpqi: Take drives offline when controller is offline
    (bsc#1246631).
  - commit 64644a2

++++ runc:

  - Update to runc v1.3.2. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.3.2> bsc#1252110
  - Includes an important fix for the CPUSet translation for cgroupv2.

------------------------------------------------------------------
------------------  2025-10-3  -  Oct 3 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 28.5.0-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2850>
  - Backport <https://github.com/moby/moby/pull/51091> to re-add vendor.sum,
    fixing our builds.
    + 0007-Add-back-vendor.sum.patch
  - Rebased patches:
    * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
    * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch
    * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch

++++ kernel-default:

  - Squashfs: reject negative file sizes in squashfs_read_inode()
    (git-fixes).
  - commit 1c9018f
  - Squashfs: add additional inode sanity checking (git-fixes).
  - commit 1064852
  - Squashfs: fix uninit-value in squashfs_get_parent (git-fixes).
  - commit fa0095c
  - hrtimers: Force migrate away hrtimers queued after (bsc#1238472 CVE-2025-21816)
  - commit 9e989a9
  - kbuild/modpost: Continue processing all unresolved symbols
    when KLP_SYM_RELA is found (bsc#1218644, bsc#1250655).
  - commit 4741268

++++ kernel-rt:

  - Squashfs: reject negative file sizes in squashfs_read_inode()
    (git-fixes).
  - commit 1c9018f
  - Squashfs: add additional inode sanity checking (git-fixes).
  - commit 1064852
  - Squashfs: fix uninit-value in squashfs_get_parent (git-fixes).
  - commit fa0095c
  - hrtimers: Force migrate away hrtimers queued after (bsc#1238472 CVE-2025-21816)
  - commit 9e989a9
  - kbuild/modpost: Continue processing all unresolved symbols
    when KLP_SYM_RELA is found (bsc#1218644, bsc#1250655).
  - commit 4741268

++++ podman:

  - Add patch for CVE-2025-9566 (bsc#1249154):
    * 0004-CVE-2025-9566-kube-play-don-t-follow-volume-symlinks.patch
  - Rebase patches:
    * 0001-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch
    * 0002-Fix-Remove-appending-rw-as-the-default-mount-option.patch
    * 0003-CVE-2025-6032-machine-init-fix-tls-check.patch

------------------------------------------------------------------
------------------  2025-10-2  -  Oct 2 2025  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Fix file list

++++ kernel-default:

  - fs/proc/task_mmu: check p->vec_buf for NULL (git-fixes).
  - commit 98a15a1
  - Update
    patches.suse/HID-asus-fix-UAF-via-HID_CLAIMED_INPUT-validation.patch
    (CVE-2025-39824 bsc#1250007).
    Added CVE reference
  - commit abe8096
  - smb: client: fix race with concurrent opens in rename(2)
    (bsc#1250179, CVE-2025-39825).
  - commit 37c11fc
  - bus: fsl-mc: Check return value of platform_get_resource()
    (git-fixes).
  - memory: samsung: exynos-srom: Fix of_iomap leak in
    exynos_srom_probe (git-fixes).
  - firmware: meson_sm: fix device leak at probe (git-fixes).
  - soc: mediatek: mtk-svs: fix device leaks on mt8192 probe failure
    (git-fixes).
  - soc: mediatek: mtk-svs: fix device leaks on mt8183 probe failure
    (git-fixes).
  - firmware: arm_scmi: Mark VirtIO ready before registering
    scmi_virtio_driver (git-fixes).
  - soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS
    (git-fixes).
  - thermal/drivers/qcom/lmh: Add missing IRQ includes (git-fixes).
  - ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT
    (git-fixes).
  - ACPI: property: Fix buffer properties extraction for subnodes
    (git-fixes).
  - ACPI: processor: idle: Fix memory leak when register cpuidle
    device failed (git-fixes).
  - ACPICA: Fix largest possible resource descriptor index
    (git-fixes).
  - ACPI: debug: fix signedness issues in read/write helpers
    (git-fixes).
  - PM: sleep: core: Clear power.must_resume in noirq suspend
    error path (git-fixes).
  - PM / devfreq: rockchip-dfi: double count on RK3588 (git-fixes).
  - PM / devfreq: mtk-cci: Fix potential error pointer dereference
    in probe() (git-fixes).
  - i3c: master: svc: Recycle unused IBI slot (git-fixes).
  - i3c: master: svc: Use manual response for IBI events
    (git-fixes).
  - i3c: Fix default I2C adapter timeout value (git-fixes).
  - i2c: designware: Add disabling clocks when probe fails
    (git-fixes).
  - i2c: designware: Fix clock issue when PM is disabled
    (git-fixes).
  - i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD
    (git-fixes).
  - pinctrl: renesas: Use int type to store negative error codes
    (git-fixes).
  - pinctrl: samsung: Drop unused S3C24xx driver data (git-fixes).
  - pinctrl: renesas: rzg2l: Fix invalid unsigned return in
    rzg3s_oen_read() (git-fixes).
  - pinctrl: meson-gxl: add missing i2c_d pinmux (git-fixes).
  - pinctrl: equilibrium: Remove redundant semicolons (git-fixes).
  - power: supply: max77976_charger: fix constant current reporting
    (git-fixes).
  - power: supply: cw2015: Fix a alignment coding style issue
    (git-fixes).
  - leds: leds-lp55xx: Use correct address for memory programming
    (git-fixes).
  - leds: flash: leds-qcom-flash: Update torch current clamp setting
    (git-fixes).
  - mfd: rz-mtu3: Fix MTU5 NFCR register offset (git-fixes).
  - mmc: core: Fix variable shadowing in mmc_route_rpmb_frames()
    (git-fixes).
  - spi: fix return code when spi device has too many chipselects
    (git-fixes).
  - spi: cadence-quadspi: Fix cqspi_setup_flash() (git-fixes).
  - spi: cadence-quadspi: Flush posted register writes before DAC
    access (git-fixes).
  - spi: cadence-quadspi: Flush posted register writes before
    INDAC access (git-fixes).
  - spi: mtk-snfi: Remove redundant semicolons (git-fixes).
  - spi: bcm2835: Remove redundant semicolons (git-fixes).
  - regulator: scmi: Use int type to store negative error codes
    (git-fixes).
  - regmap: Remove superfluous check for !config in __regmap_init()
    (git-fixes).
  - mfd: vexpress-sysreg: Check the return value of
    devm_gpiochip_add_data() (git-fixes).
  - pwm: tiehrpwm: Fix corner case in clock divisor calculation
    (git-fixes).
  - pwm: tiehrpwm: Fix various off-by-one errors in duty-cycle
    calculation (git-fixes).
  - pwm: tiehrpwm: Make code comment in .free() more useful
    (git-fixes).
  - pwm: tiehrpwm: Don't drop runtime PM reference in .free()
    (git-fixes).
  - pwm: berlin: Fix wrong register in suspend/resume (git-fixes).
  - hwmon: (mlxreg-fan) Separate methods of fan setting coming
    from different subsystems (git-fixes).
  - soc: qcom: mdt_loader: Deal with zero e_shentsize (git-fixes).
  - commit faf07bc
  - Drop patches.suse/drm-amd-display-Disable-PSR-SU-on-eDP-panels.patch (bsc#1243112)
    The patch caused a regression wrt s2idle on AMD laptops
  - commit d42f41f
  - net/smc: fix UAF on smcsk after smc_listen_out() (CVE-2025-38734
    bsc#1249324).
  - commit 4a22467
  - net: gso: Forbid IPv6 TSO with extensions on devices with only
    IPV6_CSUM (CVE-2025-39770 bsc#1249508).
  - commit 6df7556
  - Update
    patches.suse/dmaengine-ti-edma-Fix-memory-allocation-size-for-que.patch
    (CVE-2025-39869 bsc#1250406).
    Added CVE reference
  - commit 464897c
  - writeback: Avoid contention on wb->list_lock when switching
    inodes (kABI fixup) (bsc#1237776).
  - commit f7f2303
  - Fix bugzilla and CVE references (CVE-2025-38552 bsc#1248230)
    Patches
    patches.suse/mptcp-plug-races-between-subflow-fail-and-subflow-cr.patch
    patches.kabi/kabi-hide-new-member-allow_subflows-in-struct-mptcp_.patch
    had wrong bugzilla and CVE references (belonging to previous CVE bug
    related to similar code). Replace them with the correct ones.
  - commit f5079d3
  - net/tcp: Fix socket memory leak in TCP-AO failure handling
    for IPv6 (CVE-2025-39852 bsc#1250258).
  - commit c9b08eb
  - Update
    patches.suse/netfilter-ctnetlink-remove-refcounting-in-expectation-dump.patch
    references (add CVE-2025-39764 bsc#1249513).
  - commit 8f60b19
  - net/sched: Make cake_enqueue return NET_XMIT_CN when past
    buffer_limit (CVE-2025-39766 bsc#1249510).
  - commit b1cb568
  - net/sched: Fix backlog accounting in qdisc_dequeue_internal
    (CVE-2025-39677 bsc#1249300).
  - commit 910f097
  - tls: handle data disappearing from under the TLS ULP
    (CVE-2025-38616 bsc#1248512).
  - commit ac9ae3e

++++ kernel-rt:

  - fs/proc/task_mmu: check p->vec_buf for NULL (git-fixes).
  - commit 98a15a1
  - Update
    patches.suse/HID-asus-fix-UAF-via-HID_CLAIMED_INPUT-validation.patch
    (CVE-2025-39824 bsc#1250007).
    Added CVE reference
  - commit abe8096
  - smb: client: fix race with concurrent opens in rename(2)
    (bsc#1250179, CVE-2025-39825).
  - commit 37c11fc
  - bus: fsl-mc: Check return value of platform_get_resource()
    (git-fixes).
  - memory: samsung: exynos-srom: Fix of_iomap leak in
    exynos_srom_probe (git-fixes).
  - firmware: meson_sm: fix device leak at probe (git-fixes).
  - soc: mediatek: mtk-svs: fix device leaks on mt8192 probe failure
    (git-fixes).
  - soc: mediatek: mtk-svs: fix device leaks on mt8183 probe failure
    (git-fixes).
  - firmware: arm_scmi: Mark VirtIO ready before registering
    scmi_virtio_driver (git-fixes).
  - soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS
    (git-fixes).
  - thermal/drivers/qcom/lmh: Add missing IRQ includes (git-fixes).
  - ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT
    (git-fixes).
  - ACPI: property: Fix buffer properties extraction for subnodes
    (git-fixes).
  - ACPI: processor: idle: Fix memory leak when register cpuidle
    device failed (git-fixes).
  - ACPICA: Fix largest possible resource descriptor index
    (git-fixes).
  - ACPI: debug: fix signedness issues in read/write helpers
    (git-fixes).
  - PM: sleep: core: Clear power.must_resume in noirq suspend
    error path (git-fixes).
  - PM / devfreq: rockchip-dfi: double count on RK3588 (git-fixes).
  - PM / devfreq: mtk-cci: Fix potential error pointer dereference
    in probe() (git-fixes).
  - i3c: master: svc: Recycle unused IBI slot (git-fixes).
  - i3c: master: svc: Use manual response for IBI events
    (git-fixes).
  - i3c: Fix default I2C adapter timeout value (git-fixes).
  - i2c: designware: Add disabling clocks when probe fails
    (git-fixes).
  - i2c: designware: Fix clock issue when PM is disabled
    (git-fixes).
  - i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD
    (git-fixes).
  - pinctrl: renesas: Use int type to store negative error codes
    (git-fixes).
  - pinctrl: samsung: Drop unused S3C24xx driver data (git-fixes).
  - pinctrl: renesas: rzg2l: Fix invalid unsigned return in
    rzg3s_oen_read() (git-fixes).
  - pinctrl: meson-gxl: add missing i2c_d pinmux (git-fixes).
  - pinctrl: equilibrium: Remove redundant semicolons (git-fixes).
  - power: supply: max77976_charger: fix constant current reporting
    (git-fixes).
  - power: supply: cw2015: Fix a alignment coding style issue
    (git-fixes).
  - leds: leds-lp55xx: Use correct address for memory programming
    (git-fixes).
  - leds: flash: leds-qcom-flash: Update torch current clamp setting
    (git-fixes).
  - mfd: rz-mtu3: Fix MTU5 NFCR register offset (git-fixes).
  - mmc: core: Fix variable shadowing in mmc_route_rpmb_frames()
    (git-fixes).
  - spi: fix return code when spi device has too many chipselects
    (git-fixes).
  - spi: cadence-quadspi: Fix cqspi_setup_flash() (git-fixes).
  - spi: cadence-quadspi: Flush posted register writes before DAC
    access (git-fixes).
  - spi: cadence-quadspi: Flush posted register writes before
    INDAC access (git-fixes).
  - spi: mtk-snfi: Remove redundant semicolons (git-fixes).
  - spi: bcm2835: Remove redundant semicolons (git-fixes).
  - regulator: scmi: Use int type to store negative error codes
    (git-fixes).
  - regmap: Remove superfluous check for !config in __regmap_init()
    (git-fixes).
  - mfd: vexpress-sysreg: Check the return value of
    devm_gpiochip_add_data() (git-fixes).
  - pwm: tiehrpwm: Fix corner case in clock divisor calculation
    (git-fixes).
  - pwm: tiehrpwm: Fix various off-by-one errors in duty-cycle
    calculation (git-fixes).
  - pwm: tiehrpwm: Make code comment in .free() more useful
    (git-fixes).
  - pwm: tiehrpwm: Don't drop runtime PM reference in .free()
    (git-fixes).
  - pwm: berlin: Fix wrong register in suspend/resume (git-fixes).
  - hwmon: (mlxreg-fan) Separate methods of fan setting coming
    from different subsystems (git-fixes).
  - soc: qcom: mdt_loader: Deal with zero e_shentsize (git-fixes).
  - commit faf07bc
  - Drop patches.suse/drm-amd-display-Disable-PSR-SU-on-eDP-panels.patch (bsc#1243112)
    The patch caused a regression wrt s2idle on AMD laptops
  - commit d42f41f
  - net/smc: fix UAF on smcsk after smc_listen_out() (CVE-2025-38734
    bsc#1249324).
  - commit 4a22467
  - net: gso: Forbid IPv6 TSO with extensions on devices with only
    IPV6_CSUM (CVE-2025-39770 bsc#1249508).
  - commit 6df7556
  - Update
    patches.suse/dmaengine-ti-edma-Fix-memory-allocation-size-for-que.patch
    (CVE-2025-39869 bsc#1250406).
    Added CVE reference
  - commit 464897c
  - writeback: Avoid contention on wb->list_lock when switching
    inodes (kABI fixup) (bsc#1237776).
  - commit f7f2303
  - Fix bugzilla and CVE references (CVE-2025-38552 bsc#1248230)
    Patches
    patches.suse/mptcp-plug-races-between-subflow-fail-and-subflow-cr.patch
    patches.kabi/kabi-hide-new-member-allow_subflows-in-struct-mptcp_.patch
    had wrong bugzilla and CVE references (belonging to previous CVE bug
    related to similar code). Replace them with the correct ones.
  - commit f5079d3
  - net/tcp: Fix socket memory leak in TCP-AO failure handling
    for IPv6 (CVE-2025-39852 bsc#1250258).
  - commit c9b08eb
  - Update
    patches.suse/netfilter-ctnetlink-remove-refcounting-in-expectation-dump.patch
    references (add CVE-2025-39764 bsc#1249513).
  - commit 8f60b19
  - net/sched: Make cake_enqueue return NET_XMIT_CN when past
    buffer_limit (CVE-2025-39766 bsc#1249510).
  - commit b1cb568
  - net/sched: Fix backlog accounting in qdisc_dequeue_internal
    (CVE-2025-39677 bsc#1249300).
  - commit 910f097
  - tls: handle data disappearing from under the TLS ULP
    (CVE-2025-38616 bsc#1248512).
  - commit ac9ae3e

++++ libxslt:

  - security update
  - added patches
    CVE-2025-10911 [bsc#1250553], use-after-free with key data stored cross-RVT
    * libxslt-CVE-2025-10911.patch

------------------------------------------------------------------
------------------  2025-10-1  -  Oct 1 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to docker-buildx v0.29.0. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.29.0>

++++ kernel-default:

  - cifs: prevent NULL pointer dereference in UTF16 conversion
    (bsc#1250365, CVE-2025-39838).
  - commit 759c64b
  - writeback: Avoid excessively long inode switching times
    (bsc#1237776).
  - commit b26feb2
  - writeback: Avoid softlockup when switching many inodes
    (bsc#1237776).
  - commit a8e4925
  - writeback: Avoid contention on wb->list_lock when switching
    inodes (bsc#1237776).
  - commit 02a1b52
  - btrfs: return any hit error from extent_writepage_io()
    (git-fixes).
  - commit b307677

++++ kernel-rt:

  - cifs: prevent NULL pointer dereference in UTF16 conversion
    (bsc#1250365, CVE-2025-39838).
  - commit 759c64b
  - writeback: Avoid excessively long inode switching times
    (bsc#1237776).
  - commit b26feb2
  - writeback: Avoid softlockup when switching many inodes
    (bsc#1237776).
  - commit a8e4925
  - writeback: Avoid contention on wb->list_lock when switching
    inodes (bsc#1237776).
  - commit 02a1b52
  - btrfs: return any hit error from extent_writepage_io()
    (git-fixes).
  - commit b307677

++++ samba:

  - Relax samba-gpupdate requirement for cepces, certmonger, and sscep
    to a recommends. They are only required if utilizing certificate
    auto enrollment (bsc#1249087).

++++ openssl-3:

  - Security fix: [bsc#1250232 CVE-2025-9230]
    * Fix out-of-bounds read & write in RFC 3211 KEK unwrap
    * Add patch openssl3-CVE-2025-9230.patch
  - Security fix: [bsc#1250233 CVE-2025-9231]
    * Fix timing side-channel in SM2 algorithm on 64 bit ARM
    * Add patch openssl3-CVE-2025-9231.patch
  - Security fix: [bsc#1250234 CVE-2025-9232]
    * Fix out-of-bounds read in HTTP client no_proxy handling
    * Add patch openssl3-CVE-2025-9232.patch

++++ open-vm-tools:

  - Update to open-vm-tools 13.0.5 based on build 24915695. (boo#1250692):
    Please refer to the Release Notes at
    https://github.com/vmware/open-vm-tools/blob/stable-13.0.5/ReleaseNotes.md.
    The granular changes that have gone into the open-vm-tools 13.0.5 release
    are in the ChangeLog at
    https://github.com/vmware/open-vm-tools/blob/stable-13.0.5/open-vm-tools/ChangeLog.
    There are no new features in the open-vm-tools 13.0.5 release. This is
    primarily a maintenance release that addresses a security issue.
    This release resolves and includes the patch for CVE-2025-41244. For more
    information on this vulnerability and its impact on Broadcom products,
    see VMSA-2025-0015.
    A patch to address CVE-2025-41244 on earlier open-vm-tools releases is
    provided to the Linux community at CVE-2025-41244.patch.
    A minor enhancement has been made for Guest OS Customization. The
    DeployPkg plugin has been updated to use "systemctl reboot", if available.
    For a more complete list of issues addressed in this release, see the
    What's New and Resolved Issues section of the Release Notes.
  - Drop patch now contained in 13.0.5:
    0001-GOSC-Update-Guest-OS-Customization-to-utilize-system.patch
    CVE-2025-41244-1240-1300-SDMP.patch

++++ nvidia-open-driver-G06-signed:

  - fixed 'osc service run download_files'

++++ opensuse-migration-tool:

  - Update to version 20251001.d4b9783:
    * Be consistently not using abbreviations in zypper
    * Refactor upgrade for not just Tumbleweed
    * Update migration matrix
    * Add support from MicroOS-Slowroll -> MicroOS
    * Enable MicroOS-Slowroll migration target
    * fix: remove the check for x86-64-v3 flag `movbe` from the v2 check
    * Update README to remove duplicate warning
    * Revise experimental usage warning in README
    * Update screenshot
    * Keep only Experimental in the title

------------------------------------------------------------------
------------------  2025-9-30  -  Sep 30 2025  -------------------
------------------------------------------------------------------

++++ cloud-init:

  - Drop unneeded test dependency on httpretty, fixed long ago
    * https://github.com/canonical/cloud-init/pull/1720

++++ kernel-default:

  - x86/microcode: Update the Intel processor flag scan check (git-fixes).
  - commit b729bda
  - x86/microcode/AMD: Handle the case of no BIOS microcode (git-fixes).
  - commit 2fbcb40
  - kabi/severities: ignore asus-wmi kABI breakage
    The recent fix for asus WMI drivers (commit 132bfcd24925 backport)
    breaks kABI.  As the symbols are used only internally for asus WMI
    drivers and the kABI workaround isn't trivial, let's just ignore
    kABI breakage.
  - commit d543a77
  - erofs: avoid reading more for fragment maps (git-fixes).
  - commit a9573c6
  - ocfs2: fix recursive semaphore deadlock in fiemap call
    (bsc#1250407 CVE-2025-39885).
  - ocfs2: prevent release journal inode after journal shutdown
    (bsc#1250267 CVE-2025-39842).
  - commit aeb8389
  - seccomp: Fix a race with WAIT_KILLABLE_RECV if the tracer
    replies too fast (git-fixes bsc#1250671).
  - commit 1ea074e
  - mm/smaps: fix race between smaps_hugetlb_range and migration
    (CVE-2025-39754 bsc#1249524).
  - commit 8df5ff7
  - tty: hvc_console: Call hvc_kick in hvc_write unconditionally
    (bsc#1230062).
  - commit 544e413

++++ kernel-rt:

  - x86/microcode: Update the Intel processor flag scan check (git-fixes).
  - commit b729bda
  - x86/microcode/AMD: Handle the case of no BIOS microcode (git-fixes).
  - commit 2fbcb40
  - kabi/severities: ignore asus-wmi kABI breakage
    The recent fix for asus WMI drivers (commit 132bfcd24925 backport)
    breaks kABI.  As the symbols are used only internally for asus WMI
    drivers and the kABI workaround isn't trivial, let's just ignore
    kABI breakage.
  - commit d543a77
  - erofs: avoid reading more for fragment maps (git-fixes).
  - commit a9573c6
  - ocfs2: fix recursive semaphore deadlock in fiemap call
    (bsc#1250407 CVE-2025-39885).
  - ocfs2: prevent release journal inode after journal shutdown
    (bsc#1250267 CVE-2025-39842).
  - commit aeb8389
  - seccomp: Fix a race with WAIT_KILLABLE_RECV if the tracer
    replies too fast (git-fixes bsc#1250671).
  - commit 1ea074e
  - mm/smaps: fix race between smaps_hugetlb_range and migration
    (CVE-2025-39754 bsc#1249524).
  - commit 8df5ff7
  - tty: hvc_console: Call hvc_kick in hvc_write unconditionally
    (bsc#1230062).
  - commit 544e413

++++ qemu:

  - Update to version 10.0.4:
    Full backport list:
    https://lore.kernel.org/qemu-devel/1748499690.323471.13081.nullmailer@localhost/
    A selection of them is reported below:
    hvf: arm: Emulate ICC_RPR_EL1 accesses properly
    target/arm: Correct encoding of Debug Communications Channel registers
    ui: fix setting client_endian field defaults
    hw/net/npcm_gmac.c: Send the right data for second packet in a row
    target/i386: do not expose ARCH_CAPABILITIES on AMD CPU
    i386/cpu: Honor maximum value for CPUID.8000001DH.EAX[25:14]
    i386/cpu: Fix overflow of cache topology fields in CPUID.04H
    i386/cpu: Fix cpu number overflow in CPUID.01H.EBX[23:16]
    ui/vnc: Do not copy z_stream
    vhost: Fix used memslot tracking when destroying a vhost device
    roms: re-remove execute bit from hppa-firmware*
    file-posix: Fix aio=threads performance regression after enablign FUA
    amd_iommu: Fix truncation of oldval in amdvi_writeq
    amd_iommu: Remove duplicated definitions
    amd_iommu: Fix the calculation for Device Table size
    amd_iommu: Fix mask to retrieve Interrupt Table Root Pointer from DTE
    amd_iommu: Fix masks for various IOMMU MMIO Registers
    amd_iommu: Update bitmasks representing DTE reserved fields
    amd_iommu: Fix Device ID decoding for INVALIDATE_IOTLB_PAGES command
    amd_iommu: Fix Miscellaneous Information Register 0 encoding
    virtio-net: Add queues for RSS during migration
    net: fix buffer overflow in af_xdp_umem_create()
    accel/kvm: Adjust the note about the minimum required kernel version
    linux-user: Use qemu_set_cloexec() to mark pidfd as FD_CLOEXEC
    migration: Don't sync volatile memory after migration completes
    linux-user: Hold the fd-trans lock across fork
    linux-user: Check for EFAULT failure in nanosleep
    linux-user: Implement fchmodat2 syscall
    hw/arm/fsl-imx8mp: Wire VIRQ and VFIQ
    target/arm: Don't enforce NSE,NS check for EL3->EL3 returns
    target/i386: fix TB exit logic in gen_movl_seg() when writing to SS
    target/arm: Fix bfdotadd_ebf vs nan selection
    target/arm: Fix f16_dotadd vs nan selection
    target/arm: Fix PSEL size operands to tcg_gen_gvec_ands
    target/arm: Fix 128-bit element ZIP, UZP, TRN
    target/arm: Fix sve_access_check for SME
    target/arm: Fix SME vs AdvSIMD exception priority
    hw/s390x/ccw-device: Fix memory leak in loadparm setter
    virtio-gpu: support context init multiple timeline
    target/arm: Correct KVM & HVF dtb_compatible value
    target/arm: Make RETA[AB] UNDEF when pauth is not implemented
    tcg: Fix constant propagation in tcg_reg_alloc_dup
    target/loongarch: fix vldi/xvldi raise wrong error
    target/loongarch: add check for fcond
    linux-user/arm: Fix return value of SYS_cacheflush
    hw/arm/mps2: Configure the AN500 CPU with 16 MPU regions
    qemu-options.hx: Fix reversed description of icount sleep behavior
    hw/arm/virt: Check bypass iommu is not set for iommu-map DT property
    hw/loongarch/virt: Fix big endian support with MCFG table
    hw/core/qdev-properties-system: Add missing return in set_drive_helper()
    iotests: fix 240
    target/i386: Remove FRED dependency on WRMSRNS
    hw/audio/asc: fix SIGSEGV in asc_realize()
    audio: fix size calculation in AUD_get_buffer_size_out()
    audio: fix SIGSEGV in AUD_get_buffer_size_out()
    hw/i386/amd_iommu: Fix xtsup when vcpus < 255
    hw/i386/amd_iommu: Fix device setup failure when PT is on.

------------------------------------------------------------------
------------------  2025-9-29  -  Sep 29 2025  -------------------
------------------------------------------------------------------

++++ afterburn:

  - Add bugzilla references to past changelog

++++ docker:

  - Remove git-core recommends also on openSUSE: the below argument
    is valid for those users too.
  - Remove git-core recommends on SLE. Most SLE systems have
    installRecommends=yes by default and thus end up installing git with Docker.
    bsc#1250508
    This feature is mostly intended for developers ("docker build git://") so
    most users already have the dependency installed, and the error when git is
    missing is fairly straightforward (so they can easily figure out what they
    need to install).

++++ kernel-default:

  - net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() (CVE-2025-39857 bsc#1250251)
  - commit a9b3df4
  - net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (CVE-2025-39830 bsc#1249974)
  - commit 163399c
  - platform/x86: asus-wmi: Re-add extra keys to ignore_key_wlan
    quirk (git-fixes).
  - platform/x86: asus-wmi: Fix ROG button mapping, tablet mode
    on ASUS ROG Z13 (stable-fixes).
  - commit 20f9cff
  - i2c: riic: Allow setting frequencies lower than 50KHz
    (git-fixes).
  - commit 43a1dc1
  - kABI workaround for amd_sfh (git-fixes).
  - commit 2e4b180
  - HID: amd_sfh: Add sync across amd sfh work functions
    (git-fixes).
  - commit ba93a25
  - selftests/cpufreq: Fix cpufreq basic read and update testcases
    (bsc#1250344).
  - commit a092a13
  - hv_netvsc: Link queues to NAPIs (git-fixes).
  - commit c52cbb3
  - KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush (bsc#1246782 CVE-2025-38351).
  - commit 28ac15f
  - net/sched: ets: use old 'nbands' while purging unused classes
    (CVE-2025-38684 bsc#1249156).
  - commit ecd1ae5
  - tee: fix NULL pointer dereference in tee_shm_put (CVE-2025-39865
    bsc#1250294).
  - commit 5275cd3
  - cpufreq: Initialize cpufreq-based invariance before subsys
    (git-fixes).
  - commit 378dc28
  - PM: cpufreq: powernv/tracing: Move powernv_throttle trace event
    (git-fixes).
    Allow kabi breakage: declaring powernv_throttle moved from global
    to local powernv only header file.
  - commit 28a4607
  - cpufreq: Add SM8650 to cpufreq-dt-platdev blocklist
    (stable-fixes).
  - commit fab468d
  - cpufreq: tegra186: Share policy per cluster (stable-fixes).
  - commit a730531
  - x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init
    helper (CVE-2025-39681 bsc#1249303).
  - commit ecf77f1

++++ kernel-rt:

  - net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() (CVE-2025-39857 bsc#1250251)
  - commit a9b3df4
  - net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (CVE-2025-39830 bsc#1249974)
  - commit 163399c
  - platform/x86: asus-wmi: Re-add extra keys to ignore_key_wlan
    quirk (git-fixes).
  - platform/x86: asus-wmi: Fix ROG button mapping, tablet mode
    on ASUS ROG Z13 (stable-fixes).
  - commit 20f9cff
  - i2c: riic: Allow setting frequencies lower than 50KHz
    (git-fixes).
  - commit 43a1dc1
  - kABI workaround for amd_sfh (git-fixes).
  - commit 2e4b180
  - HID: amd_sfh: Add sync across amd sfh work functions
    (git-fixes).
  - commit ba93a25
  - selftests/cpufreq: Fix cpufreq basic read and update testcases
    (bsc#1250344).
  - commit a092a13
  - hv_netvsc: Link queues to NAPIs (git-fixes).
  - commit c52cbb3
  - KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush (bsc#1246782 CVE-2025-38351).
  - commit 28ac15f
  - net/sched: ets: use old 'nbands' while purging unused classes
    (CVE-2025-38684 bsc#1249156).
  - commit ecd1ae5
  - tee: fix NULL pointer dereference in tee_shm_put (CVE-2025-39865
    bsc#1250294).
  - commit 5275cd3
  - cpufreq: Initialize cpufreq-based invariance before subsys
    (git-fixes).
  - commit 378dc28
  - PM: cpufreq: powernv/tracing: Move powernv_throttle trace event
    (git-fixes).
    Allow kabi breakage: declaring powernv_throttle moved from global
    to local powernv only header file.
  - commit 28a4607
  - cpufreq: Add SM8650 to cpufreq-dt-platdev blocklist
    (stable-fixes).
  - commit fab468d
  - cpufreq: tegra186: Share policy per cluster (stable-fixes).
  - commit a730531
  - x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init
    helper (CVE-2025-39681 bsc#1249303).
  - commit ecf77f1

++++ expat:

  - Fix CVE-2025-59375 / bsc#1249584.
  - Add patch file:
    * CVE-2025-59375.patch

++++ python313-core:

  - Add gh139257-Support-docutils-0.22.patch to fix build with latest
    docutils (>=0.22) gh#python/cpython#139257

++++ patterns-base:

  - Bump to 6.2
  - Micro 6.2 Thunderbolt enablement code-o-o#leap/features#242

++++ python313:

  - Add gh139257-Support-docutils-0.22.patch to fix build with latest
    docutils (>=0.22) gh#python/cpython#139257

++++ qemu:

  - Resolve a repo-has-moved service running issue:
    * .gitmodules: move u-boot mirrors to qemu-project-mirrors

------------------------------------------------------------------
------------------  2025-9-28  -  Sep 28 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Bluetooth: MGMT: Fix possible UAFs (git-fixes).
  - Refresh patches.kabi/hci_dev-centralize-extra-lock.patch.
  - commit 40462f6
  - fbcon: Fix OOB access in font allocation (git-fixes).
  - commit 3d28b38
  - platform/x86: lg-laptop: Fix WMAB call in fan_mode_store()
    (git-fixes).
  - gpiolib: Extend software-node support to support secondary
    software-nodes (git-fixes).
  - drm/panthor: Defer scheduler entitiy destruction to queue
    release (git-fixes).
  - fbcon: fix integer overflow in fbcon_do_set_font (git-fixes).
  - drm/gma500: Fix null dereference in hdmi teardown (git-fixes).
  - drm/ast: Use msleep instead of mdelay for edid read (git-fixes).
  - can: peak_usb: fix shift-out-of-bounds issue (git-fixes).
  - can: mcba_usb: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - can: sun4i_can: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - can: hi311x: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - can: etas_es58x: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync
    (git-fixes).
  - Bluetooth: hci_sync: Fix hci_resume_advertising_sync
    (git-fixes).
  - reset: eyeq: fix OF node leak (git-fixes).
  - firewire: core: fix overlooked update of subsystem ABI version
    (git-fixes).
  - ALSA: hda/realtek: Fix mute led for HP Laptop 15-dw4xx
    (stable-fixes).
  - net: rfkill: gpio: Fix crash due to dereferencering
    uninitialized pointer (git-fixes).
  - wifi: wilc1000: avoid buffer overflow in WID string
    configuration (stable-fixes).
  - wifi: mac80211: increase scan_ies_len for S1G (stable-fixes).
  - wifi: mac80211: fix incorrect type for ret (stable-fixes).
  - ALSA: firewire-motu: drop EPOLLOUT from poll return values as
    write is not supported (stable-fixes).
  - commit a203b7e

++++ kernel-rt:

  - Bluetooth: MGMT: Fix possible UAFs (git-fixes).
  - Refresh patches.kabi/hci_dev-centralize-extra-lock.patch.
  - commit 40462f6
  - fbcon: Fix OOB access in font allocation (git-fixes).
  - commit 3d28b38
  - platform/x86: lg-laptop: Fix WMAB call in fan_mode_store()
    (git-fixes).
  - gpiolib: Extend software-node support to support secondary
    software-nodes (git-fixes).
  - drm/panthor: Defer scheduler entitiy destruction to queue
    release (git-fixes).
  - fbcon: fix integer overflow in fbcon_do_set_font (git-fixes).
  - drm/gma500: Fix null dereference in hdmi teardown (git-fixes).
  - drm/ast: Use msleep instead of mdelay for edid read (git-fixes).
  - can: peak_usb: fix shift-out-of-bounds issue (git-fixes).
  - can: mcba_usb: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - can: sun4i_can: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - can: hi311x: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - can: etas_es58x: populate ndo_change_mtu() to prevent buffer
    overflow (git-fixes).
  - Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync
    (git-fixes).
  - Bluetooth: hci_sync: Fix hci_resume_advertising_sync
    (git-fixes).
  - reset: eyeq: fix OF node leak (git-fixes).
  - firewire: core: fix overlooked update of subsystem ABI version
    (git-fixes).
  - ALSA: hda/realtek: Fix mute led for HP Laptop 15-dw4xx
    (stable-fixes).
  - net: rfkill: gpio: Fix crash due to dereferencering
    uninitialized pointer (git-fixes).
  - wifi: wilc1000: avoid buffer overflow in WID string
    configuration (stable-fixes).
  - wifi: mac80211: increase scan_ies_len for S1G (stable-fixes).
  - wifi: mac80211: fix incorrect type for ret (stable-fixes).
  - ALSA: firewire-motu: drop EPOLLOUT from poll return values as
    write is not supported (stable-fixes).
  - commit a203b7e

------------------------------------------------------------------
------------------  2025-9-26  -  Sep 26 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - iommu/vt-d: Fix __domain_mapping()'s usage of
    switch_to_super_page() (git-fixes).
  - commit 1d0bd57
  - mm/mremap: fix WARN with uffd that has remap events disabled
    (CVE-2025-39775 bsc#1249500).
  - commit ec812cb
  - kabi: Restore layout of parallel_data (bsc1248343).
  - commit 3819e36
  - padata: Fix pd UAF once and for all (CVE-2025-38584 bsc1248343).
  - commit 0631965
  - x86/CPU/AMD: Add CPUID faulting support (jsc#PED-13704).
  - commit f69b3f2
  - xfrm: xfrm_alloc_spi shouldn't use 0 as SPI (CVE-2025-39797
    bsc#1249608).
  - commit 169508a
  - xfrm: Duplicate SPI Handling (CVE-2025-39797 bsc#1249608).
  - commit 05dc0f3
  - kernel-source.spec: Depend on python3-base for build
    Both kernel-binary and kernel-docs already have this dependency.
    Adding it to kernel-source makes it possible to use python in shared
    build scripts.
  - commit 72fdedd
  - kernel-source: Do not list mkspec and its inputs as sources
    (bsc#1250522).
    This excludes the files from the src.rpm. The next step is to remove
    these files in tar-up so that they do not get uploaded to OBS either.
    As there is only one version of tar-up these files need to be removed
    from all kernels.
  - commit e72b8a2

++++ kernel-firmware-amdgpu:

  - Update to version 20250926 (git commit fad361e997ee):
    * amdgpu: DMCUB updates for various ASICs
    * Revert "amdgpu: update gc 10.3.6 firmware"

++++ kernel-firmware-mediatek:

  - Update to version 20250926 (git commit fad361e997ee):
    * mediatek: mtk_wed: drop links for mt7988

++++ kernel-rt:

  - iommu/vt-d: Fix __domain_mapping()'s usage of
    switch_to_super_page() (git-fixes).
  - commit 1d0bd57
  - mm/mremap: fix WARN with uffd that has remap events disabled
    (CVE-2025-39775 bsc#1249500).
  - commit ec812cb
  - kabi: Restore layout of parallel_data (bsc1248343).
  - commit 3819e36
  - padata: Fix pd UAF once and for all (CVE-2025-38584 bsc1248343).
  - commit 0631965
  - x86/CPU/AMD: Add CPUID faulting support (jsc#PED-13704).
  - commit f69b3f2
  - xfrm: xfrm_alloc_spi shouldn't use 0 as SPI (CVE-2025-39797
    bsc#1249608).
  - commit 169508a
  - xfrm: Duplicate SPI Handling (CVE-2025-39797 bsc#1249608).
  - commit 05dc0f3
  - kernel-source.spec: Depend on python3-base for build
    Both kernel-binary and kernel-docs already have this dependency.
    Adding it to kernel-source makes it possible to use python in shared
    build scripts.
  - commit 72fdedd
  - kernel-source: Do not list mkspec and its inputs as sources
    (bsc#1250522).
    This excludes the files from the src.rpm. The next step is to remove
    these files in tar-up so that they do not get uploaded to OBS either.
    As there is only one version of tar-up these files need to be removed
    from all kernels.
  - commit e72b8a2

------------------------------------------------------------------
------------------  2025-9-25  -  Sep 25 2025  -------------------
------------------------------------------------------------------

++++ afterburn:

  - Update to version 5.9.0.git21.a73f509:
    * docs/release-notes: update for release 5.10.0
    * cargo: update dependencies
    * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat
    * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix
    * microsoft/azure: Fix SharedConfig parsing of XML attributes
    * microsoft/azure: Mock goalstate.SharedConfig output in tests
    * providers/azure: switch SSH key retrieval from certs endpoint to IMDS
    as azure stopped providing keys in the old one, fixes bsc#1250471
    * build(deps): bump the build group with 8 updates
    * build(deps): bump slab from 0.4.10 to 0.4.11
    * build(deps): bump actions/checkout from 4 to 5
    * upcloud: implement UpCloud provider
    * build(deps): bump the build group with 4 updates
    * Sync repo templates ⚙

++++ kernel-default:

  - rpm: Link arch-symbols script from scripts directory.
  - commit 90b2abb
  - mm/rmap: avoid -EBUSY from make_device_exclusive()
    (CVE-2025-22034 bsc#1241435).
  - commit 3fde912
  - cgroup: llist: avoid memory tears for llist_node (bsc#1247963).
  - commit c443f2f
  - mm/rmap: keep mapcount untouched for device-exclusive entries
    (CVE-2025-22034 bsc#1241435).
  - commit 1f6e890
  - mm/damon: handle device-exclusive entries correctly in
    damon_folio_mkold_one() (CVE-2025-22034 bsc#1241435).
  - commit 51352f5
  - mm/damon: handle device-exclusive entries correctly in
    damon_folio_young_one() (CVE-2025-22034 bsc#1241435).
  - commit ece262f
  - mm/page_idle: handle device-exclusive entries correctly in
    page_idle_clear_pte_refs_one() (CVE-2025-22034 bsc#1241435).
  - commit f9cfa84
  - mm/rmap: handle device-exclusive entries correctly in
    page_vma_mkclean_one() (CVE-2025-22034 bsc#1241435).
  - commit dfbbdbb
  - mm/rmap: handle device-exclusive entries correctly in
    try_to_migrate_one() (CVE-2025-22034 bsc#1241435).
  - commit 622f2ca
  - mm/rmap: handle device-exclusive entries correctly in
    try_to_unmap_one() (CVE-2025-22034 bsc#1241435).
  - commit 6ce6bcc
  - mm/ksm: handle device-exclusive entries correctly in
    write_protect_page() (CVE-2025-22034 bsc#1241435).
  - commit 36a9f94
  - kernel/events/uprobes: handle device-exclusive entries correctly
    in __replace_page() (CVE-2025-22034 bsc#1241435).
  - commit 2b51ee2
  - mm/page_vma_mapped: device-exclusive entries are not migration
    entries (CVE-2025-22034 bsc#1241435).
  - commit 3e96420
  - mm: use single SWP_DEVICE_EXCLUSIVE entry type (CVE-2025-22034
    bsc#1241435).
  - commit 4f438a1
  - mm/memory: detect writability in restore_exclusive_pte()
    through can_change_pte_writable() (CVE-2025-22034 bsc#1241435).
  - commit 2cf7b2d
  - mm/rmap: implement make_device_exclusive() using folio_walk
    instead of rmap walk (CVE-2025-22034 bsc#1241435).
  - commit f6443ef
  - mm/rmap: convert make_device_exclusive_range() to
    make_device_exclusive() (CVE-2025-22034 bsc#1241435).
  - commit a8eb13b
  - mm/rmap: reject hugetlb folios in folio_make_device_exclusive()
    (CVE-2025-22034 bsc#1241435).
  - commit 147fff4
  - mm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs (CVE-2025-22034
    bsc#1241435).
  - commit a005761

++++ kernel-rt:

  - rpm: Link arch-symbols script from scripts directory.
  - commit 90b2abb
  - mm/rmap: avoid -EBUSY from make_device_exclusive()
    (CVE-2025-22034 bsc#1241435).
  - commit 3fde912
  - cgroup: llist: avoid memory tears for llist_node (bsc#1247963).
  - commit c443f2f
  - mm/rmap: keep mapcount untouched for device-exclusive entries
    (CVE-2025-22034 bsc#1241435).
  - commit 1f6e890
  - mm/damon: handle device-exclusive entries correctly in
    damon_folio_mkold_one() (CVE-2025-22034 bsc#1241435).
  - commit 51352f5
  - mm/damon: handle device-exclusive entries correctly in
    damon_folio_young_one() (CVE-2025-22034 bsc#1241435).
  - commit ece262f
  - mm/page_idle: handle device-exclusive entries correctly in
    page_idle_clear_pte_refs_one() (CVE-2025-22034 bsc#1241435).
  - commit f9cfa84
  - mm/rmap: handle device-exclusive entries correctly in
    page_vma_mkclean_one() (CVE-2025-22034 bsc#1241435).
  - commit dfbbdbb
  - mm/rmap: handle device-exclusive entries correctly in
    try_to_migrate_one() (CVE-2025-22034 bsc#1241435).
  - commit 622f2ca
  - mm/rmap: handle device-exclusive entries correctly in
    try_to_unmap_one() (CVE-2025-22034 bsc#1241435).
  - commit 6ce6bcc
  - mm/ksm: handle device-exclusive entries correctly in
    write_protect_page() (CVE-2025-22034 bsc#1241435).
  - commit 36a9f94
  - kernel/events/uprobes: handle device-exclusive entries correctly
    in __replace_page() (CVE-2025-22034 bsc#1241435).
  - commit 2b51ee2
  - mm/page_vma_mapped: device-exclusive entries are not migration
    entries (CVE-2025-22034 bsc#1241435).
  - commit 3e96420
  - mm: use single SWP_DEVICE_EXCLUSIVE entry type (CVE-2025-22034
    bsc#1241435).
  - commit 4f438a1
  - mm/memory: detect writability in restore_exclusive_pte()
    through can_change_pte_writable() (CVE-2025-22034 bsc#1241435).
  - commit 2cf7b2d
  - mm/rmap: implement make_device_exclusive() using folio_walk
    instead of rmap walk (CVE-2025-22034 bsc#1241435).
  - commit f6443ef
  - mm/rmap: convert make_device_exclusive_range() to
    make_device_exclusive() (CVE-2025-22034 bsc#1241435).
  - commit a8eb13b
  - mm/rmap: reject hugetlb folios in folio_make_device_exclusive()
    (CVE-2025-22034 bsc#1241435).
  - commit 147fff4
  - mm/gup: reject FOLL_SPLIT_PMD with hugetlb VMAs (CVE-2025-22034
    bsc#1241435).
  - commit a005761

++++ samba:

  - Disable timeouts for smb.service so that possibly slow running
    ExecStartPre script 'update-samba-security-profile' doesn't
    cause service start to fail due to timeouts;(bsc#1249181).
  - Ensure semanage is pulled in as a requirement when samba in
    installed when selinux security access mechanism that is used;
    (bsc#1249180).
  - don't attempt to label paths that don't exist, also remove
    unecessary evaluation of semange & restorecon cmds;(bsc#1249179).
  - Update to 4.22.4
    * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with
    SysvolReady=0; (bso#14981).
    * getpwuid does not shift to new DC when current DC is down;
    (bso#15844).
    * Windows security hardening locks out schannel'ed netlogon dc
    calls like netr_DsRGetDCName-; (bso#15876).
    * Unresponsive second DC can cause idmapping failure when using
    idmap_ad-; (bso#15881).
    * kinit command is failing with Missing cache Error;
    (bso#15840).
    * Figuring out the DC name from IP address fails and breaks
    fork_domain_child(); (bso#15891).
    * vfs_streams_depot fstatat broken; (bso#15816).
    * Delayed leader broadcast can block ctdb forever; (bso#15892).
    * Apparently there is a conflict between shadow_copy2 module
    and virusfilter (action quarantine); (bso#15663).
    * Fix handling of empty GPO link; (bso#15877).
    * SMB ACL inheritance doesn't work for files created;
    (bso#15880).

++++ nvidia-open-driver-G06-signed:

  - update to version 580.95.05 (boo#1250536)

++++ qemu:

  - Fix bsc#1230042:
    * [openSUSE] rpm/spec: qemu-vgabios is required on ppc (bsc#1230042)

------------------------------------------------------------------
------------------  2025-9-24  -  Sep 24 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - rcu: Fix racy re-initialization of irq_work causing hangs (git-fixes)
  - commit d2a13f5
  - rcu: Fix rcu_read_unlock() deadloop due to IRQ work (bsc#1249494 CVE-2025-39744)
  - commit 765c8d9
  - rcu: Protect ->defer_qs_iw_pending from data race (bsc#1249533 CVE-2025-39749)
  - commit 5fd1692
  - use uniform permission checks for all mount propagation changes
    (git-fixes).
  - commit f53ccd0
  - rpm: Link guards script from scripts directory.
  - commit e19a893
  - Update patches.suse/netfilter-nf_reject-don-t-leak-dst-refcount-for-loopback-p.patch
    (git-fixes bsc#1249262 CVE-2025-38732).
    Update references to include bsc#1249262 and CVE-2025-38732.
  - commit 760e804
  - KVM: x86: use array_index_nospec with indices that come from
    guest (CVE-2025-39823 bsc#1250002).
  - commit 6411ad9
  - btrfs: do not allow relocation of partially dropped  subvolumes
    (bsc#1249540).
  - commit 84e3cf7
  - perf test: Fix a build error in x86 topdown test (git-fixes).
  - commit 4e90429

++++ kernel-rt:

  - rcu: Fix racy re-initialization of irq_work causing hangs (git-fixes)
  - commit d2a13f5
  - rcu: Fix rcu_read_unlock() deadloop due to IRQ work (bsc#1249494 CVE-2025-39744)
  - commit 765c8d9
  - rcu: Protect ->defer_qs_iw_pending from data race (bsc#1249533 CVE-2025-39749)
  - commit 5fd1692
  - use uniform permission checks for all mount propagation changes
    (git-fixes).
  - commit f53ccd0
  - rpm: Link guards script from scripts directory.
  - commit e19a893
  - Update patches.suse/netfilter-nf_reject-don-t-leak-dst-refcount-for-loopback-p.patch
    (git-fixes bsc#1249262 CVE-2025-38732).
    Update references to include bsc#1249262 and CVE-2025-38732.
  - commit 760e804
  - KVM: x86: use array_index_nospec with indices that come from
    guest (CVE-2025-39823 bsc#1250002).
  - commit 6411ad9
  - btrfs: do not allow relocation of partially dropped  subvolumes
    (bsc#1249540).
  - commit 84e3cf7
  - perf test: Fix a build error in x86 topdown test (git-fixes).
  - commit 4e90429

------------------------------------------------------------------
------------------  2025-9-23  -  Sep 23 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - add requirement on python3-pcp if pcp is installed bsc#1239759

++++ grub2:

  - turn off page flipping for i386-pc using VBE video backend (bsc#1245636)
    * grub2-i386-pc-no-pageflipping.patch

++++ kernel-default:

  - nfs/localio: add direct IO enablement with sync and async IO
    support (git-fixes).
  - commit 2e09183
  - fs/nfs/io: make nfs_start_io_*() killable (git-fixes).
  - commit da6c18a
  - nfs/localio: remove extra indirect nfs_to call to check
    {read,write}_iter (git-fixes).
  - commit 66b491e
  - kabi: drop kvm_x86_ops from kabi relevant symbols
    Since upstream commit dfc4e6ca04113 ("KVM: x86: Unexport kvm_x86_ops")
    v5.18-rc1~139^2~153 kvm_x86_ops is no longer exported, so it can be
    dropped from kabi checks.
  - commit 436eb7a
  - btrfs: initialize inode::file_extent_tree after i_mode has
    been set (git-fixes).
  - commit ba7d857
  - btrfs: fix the inode leak in btrfs_iget() (git-fixes).
  - commit 86df556
  - btrfs: fix invalid inode pointer after failure to create reloc
    inode (git-fixes).
  - commit 195186f
  - btrfs: make btrfs_iget_path() return a btrfs inode instead
    (git-fixes).
  - commit 5c2fa5a
  - btrfs: make btrfs_iget() return a btrfs inode instead
    (git-fixes).
  - Refresh
    patches.suse/btrfs-fix-inode-lookup-error-handling-during-log-rep.patch.
  - commit f577da7
  - btrfs: pass a btrfs_inode to fixup_inode_link_count()
    (git-fixes).
  - commit 0a542a8
  - btrfs: send: remove unnecessary inode lookup at
    send_encoded_inline_extent() (git-fixes).
  - commit 4b03a51
  - btrfs: use struct btrfs_inode inside btrfs_get_name()
    (git-fixes).
  - commit 9e54445
  - btrfs: use struct btrfs_inode inside btrfs_get_parent()
    (git-fixes).
  - commit f8234ff
  - btrfs: use struct btrfs_inode inside
    btrfs_remap_file_range_prep() (git-fixes).
  - commit 7cd3ceb
  - btrfs: use struct btrfs_inode inside btrfs_remap_file_range()
    (git-fixes).
  - commit 7bd3156
  - btrfs: pass struct btrfs_inode to btrfs_extent_same_range()
    (git-fixes).
  - commit 7f4ce8b
  - btrfs: pass struct btrfs_inode to btrfs_double_mmap_unlock()
    (git-fixes).
  - commit 6e85b98
  - btrfs: pass struct btrfs_inode to btrfs_double_mmap_lock()
    (git-fixes).
  - commit 7a41133
  - btrfs: pass struct btrfs_inode to clone_copy_inline_extent()
    (git-fixes).
  - commit c5e9fe5
  - btrfs: props: switch prop_handler::extract to struct btrfs_inode
    (git-fixes).
  - commit c7faedf
  - btrfs: props: switch prop_handler::apply to struct btrfs_inode
    (git-fixes).
  - commit a007bab
  - btrfs: pass struct btrfs_inode to btrfs_inode_inherit_props()
    (git-fixes).
  - commit da6d69a
  - btrfs: pass struct btrfs_inode to btrfs_load_inode_props()
    (git-fixes).
  - commit 0b464f7
  - btrfs: pass struct btrfs_inode to btrfs_fill_inode()
    (git-fixes).
  - commit 3bafa62
  - btrfs: pass struct btrfs_inode to fill_stack_inode_item()
    (git-fixes).
  - commit 74968ef
  - btrfs: use struct btrfs_inode inside create_pending_snapshot()
    (git-fixes).
  - commit eb860e0
  - btrfs: pass struct btrfs_inode to btrfs_defrag_file()
    (git-fixes).
  - commit 66d00cf
  - btrfs: pass struct btrfs_inode to btrfs_inode_type()
    (git-fixes).
  - commit 0cf8d55
  - btrfs: pass struct btrfs_inode to new_simple_dir() (git-fixes).
  - commit d0fd694
  - btrfs: pass struct btrfs_inode to btrfs_iget_locked()
    (git-fixes).
  - commit abfb73d
  - btrfs: pass struct btrfs_inode to btrfs_read_locked_inode()
    (git-fixes).
  - commit 7580ad2
  - btrfs: pass struct btrfs_inode to
    extent_range_clear_dirty_for_io() (git-fixes).
  - commit 5bffc21
  - btrfs: pass struct btrfs_inode to can_nocow_extent()
    (git-fixes).
  - commit 3883a42
  - btrfs: unify ordering of btrfs_key initializations (git-fixes).
  - Refresh
    patches.suse/btrfs-simplify-error-detection-flow-during-log-repla.patch.
  - commit 33fd53f
  - btrfs: add assertions and comment about path expectations to
    btrfs_cross_ref_exist() (git-fixes).
  - commit 00d3657
  - btrfs: add function comment for check_committed_ref()
    (git-fixes).
  - commit e6f6ede
  - btrfs: simplify arguments for btrfs_cross_ref_exist()
    (git-fixes).
  - commit 95ec2cf
  - btrfs: simplify return logic at check_committed_ref()
    (git-fixes).
  - commit 13f3e6d
  - btrfs: avoid redundant call to get inline ref type at
    check_committed_ref() (git-fixes).
  - commit 4676cb7
  - btrfs: remove the snapshot check from check_committed_ref()
    (git-fixes).
  - commit 8aa9a59
  - btrfs: remove no longer needed strict argument from
    can_nocow_extent() (git-fixes).
  - commit c8b943a
  - btrfs: remove conditional path allocation in
    btrfs_read_locked_inode() (git-fixes).
  - commit 653c0e7
  - btrfs: push cleanup into btrfs_read_locked_inode() (git-fixes).
  - commit 7e4da3e
  - btrfs: use filemap_get_folio() helper (git-fixes).
  - Refresh
    patches.suse/btrfs-remove-the-unused-locked_folio-parameter-from-.patch.
  - commit 28ed9e4
  - IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (git-fixes)
  - commit 8085078
  - btrfs: tree-checker: fix the incorrect inode ref size check
    (git-fixes).
  - commit 0cdf433
  - btrfs: fix corruption reading compressed range when block
    size is smaller than page size (git-fixes).
  - commit cbb42db

++++ kernel-rt:

  - nfs/localio: add direct IO enablement with sync and async IO
    support (git-fixes).
  - commit 2e09183
  - fs/nfs/io: make nfs_start_io_*() killable (git-fixes).
  - commit da6c18a
  - nfs/localio: remove extra indirect nfs_to call to check
    {read,write}_iter (git-fixes).
  - commit 66b491e
  - kabi: drop kvm_x86_ops from kabi relevant symbols
    Since upstream commit dfc4e6ca04113 ("KVM: x86: Unexport kvm_x86_ops")
    v5.18-rc1~139^2~153 kvm_x86_ops is no longer exported, so it can be
    dropped from kabi checks.
  - commit 436eb7a
  - btrfs: initialize inode::file_extent_tree after i_mode has
    been set (git-fixes).
  - commit ba7d857
  - btrfs: fix the inode leak in btrfs_iget() (git-fixes).
  - commit 86df556
  - btrfs: fix invalid inode pointer after failure to create reloc
    inode (git-fixes).
  - commit 195186f
  - btrfs: make btrfs_iget_path() return a btrfs inode instead
    (git-fixes).
  - commit 5c2fa5a
  - btrfs: make btrfs_iget() return a btrfs inode instead
    (git-fixes).
  - Refresh
    patches.suse/btrfs-fix-inode-lookup-error-handling-during-log-rep.patch.
  - commit f577da7
  - btrfs: pass a btrfs_inode to fixup_inode_link_count()
    (git-fixes).
  - commit 0a542a8
  - btrfs: send: remove unnecessary inode lookup at
    send_encoded_inline_extent() (git-fixes).
  - commit 4b03a51
  - btrfs: use struct btrfs_inode inside btrfs_get_name()
    (git-fixes).
  - commit 9e54445
  - btrfs: use struct btrfs_inode inside btrfs_get_parent()
    (git-fixes).
  - commit f8234ff
  - btrfs: use struct btrfs_inode inside
    btrfs_remap_file_range_prep() (git-fixes).
  - commit 7cd3ceb
  - btrfs: use struct btrfs_inode inside btrfs_remap_file_range()
    (git-fixes).
  - commit 7bd3156
  - btrfs: pass struct btrfs_inode to btrfs_extent_same_range()
    (git-fixes).
  - commit 7f4ce8b
  - btrfs: pass struct btrfs_inode to btrfs_double_mmap_unlock()
    (git-fixes).
  - commit 6e85b98
  - btrfs: pass struct btrfs_inode to btrfs_double_mmap_lock()
    (git-fixes).
  - commit 7a41133
  - btrfs: pass struct btrfs_inode to clone_copy_inline_extent()
    (git-fixes).
  - commit c5e9fe5
  - btrfs: props: switch prop_handler::extract to struct btrfs_inode
    (git-fixes).
  - commit c7faedf
  - btrfs: props: switch prop_handler::apply to struct btrfs_inode
    (git-fixes).
  - commit a007bab
  - btrfs: pass struct btrfs_inode to btrfs_inode_inherit_props()
    (git-fixes).
  - commit da6d69a
  - btrfs: pass struct btrfs_inode to btrfs_load_inode_props()
    (git-fixes).
  - commit 0b464f7
  - btrfs: pass struct btrfs_inode to btrfs_fill_inode()
    (git-fixes).
  - commit 3bafa62
  - btrfs: pass struct btrfs_inode to fill_stack_inode_item()
    (git-fixes).
  - commit 74968ef
  - btrfs: use struct btrfs_inode inside create_pending_snapshot()
    (git-fixes).
  - commit eb860e0
  - btrfs: pass struct btrfs_inode to btrfs_defrag_file()
    (git-fixes).
  - commit 66d00cf
  - btrfs: pass struct btrfs_inode to btrfs_inode_type()
    (git-fixes).
  - commit 0cf8d55
  - btrfs: pass struct btrfs_inode to new_simple_dir() (git-fixes).
  - commit d0fd694
  - btrfs: pass struct btrfs_inode to btrfs_iget_locked()
    (git-fixes).
  - commit abfb73d
  - btrfs: pass struct btrfs_inode to btrfs_read_locked_inode()
    (git-fixes).
  - commit 7580ad2
  - btrfs: pass struct btrfs_inode to
    extent_range_clear_dirty_for_io() (git-fixes).
  - commit 5bffc21
  - btrfs: pass struct btrfs_inode to can_nocow_extent()
    (git-fixes).
  - commit 3883a42
  - btrfs: unify ordering of btrfs_key initializations (git-fixes).
  - Refresh
    patches.suse/btrfs-simplify-error-detection-flow-during-log-repla.patch.
  - commit 33fd53f
  - btrfs: add assertions and comment about path expectations to
    btrfs_cross_ref_exist() (git-fixes).
  - commit 00d3657
  - btrfs: add function comment for check_committed_ref()
    (git-fixes).
  - commit e6f6ede
  - btrfs: simplify arguments for btrfs_cross_ref_exist()
    (git-fixes).
  - commit 95ec2cf
  - btrfs: simplify return logic at check_committed_ref()
    (git-fixes).
  - commit 13f3e6d
  - btrfs: avoid redundant call to get inline ref type at
    check_committed_ref() (git-fixes).
  - commit 4676cb7
  - btrfs: remove the snapshot check from check_committed_ref()
    (git-fixes).
  - commit 8aa9a59
  - btrfs: remove no longer needed strict argument from
    can_nocow_extent() (git-fixes).
  - commit c8b943a
  - btrfs: remove conditional path allocation in
    btrfs_read_locked_inode() (git-fixes).
  - commit 653c0e7
  - btrfs: push cleanup into btrfs_read_locked_inode() (git-fixes).
  - commit 7e4da3e
  - btrfs: use filemap_get_folio() helper (git-fixes).
  - Refresh
    patches.suse/btrfs-remove-the-unused-locked_folio-parameter-from-.patch.
  - commit 28ed9e4
  - IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (git-fixes)
  - commit 8085078
  - btrfs: tree-checker: fix the incorrect inode ref size check
    (git-fixes).
  - commit 0cdf433
  - btrfs: fix corruption reading compressed range when block
    size is smaller than page size (git-fixes).
  - commit cbb42db

++++ open-vm-tools:

  - Fix (bsc#1250373 (CVE-2025-41244) - VUL-0: contains a local privilege
    escalation vulnerability.
    + Add patch:
  - CVE-2025-41244-1240-1300-SDMP.patch

++++ nvidia-open-driver-G06-signed:

  - get rid of multiversion for the KMPs, since it only brought/brings
    us trouble and no benefit at all (jsc#PED-12049)
    * remove any ^Conflicts and ^Provides: multiversion from
    /usr/lib/rpm/kernel-module-subpackage
    * set INSTALL_MOD_DIR back to %{kernel_module_package_moddir}, i.e.
    updates/ subdir

++++ ovmf:

  - Add backported patch to enable iSCSI boot support by default (bsc#1245454)
  - ovmf-OvmfPkg-Add-NETWORK_ISCSI_DEFAULT_ENABLE-build-flag.patch
    502f0dfda4 OvmfPkg: Add NETWORK_ISCSI_DEFAULT_ENABLE build flag
  - Add build flag NETWORK_ISCSI_DEFAULT_ENABLE for x64 OVMF to enable iSCSI boot support by default

++++ zypper:

  - Fixed `bash-completion`: `zypper refresh` now ignores
    repository priority lines.
  - Changes to support building against restructured libzypp in
    stack build (bsc#1230267)
  - version 1.14.94

------------------------------------------------------------------
------------------  2025-9-22  -  Sep 22 2025  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Move dispatcher.d/pre-up.d/90-nm-cloud-setup.sh to cloud-setup
    subpackage(bsc#1250086).

++++ grub2:

  - Fix boot hangs in setting up serial console when ACPI SPCR table is present
    and redirection is disabled (bsc#1249088)
    * 0001-term-ns8250-spcr-Return-if-redirection-is-disabled.patch

++++ kernel-default:

  - io_uring/kbuf: always use READ_ONCE() to read ring provided
    buffer lengths (CVE-2025-39816 bsc#1249906).
  - commit 5f1b3b6
  - perf bpf-utils: Harden get_bpf_prog_info_linear (git-fixes).
  - perf bpf-utils: Constify bpil_array_desc (git-fixes).
  - perf bpf-event: Fix use-after-free in synthesis (git-fixes).
  - perf symbol-minimal: Fix ehdr reading in filename__read_build_id
    (git-fixes).
  - perf record: Cache build-ID of hit DSOs only (git-fixes).
  - perf tools: Remove libtraceevent in .gitignore (git-fixes).
  - perf topdown: Use attribute to see an event is a topdown metic
    or slots (git-fixes).
  - perf hwmon_pmu: Avoid shortening hwmon PMU name (git-fixes).
  - perf tests bp_account: Fix leaked file descriptor (git-fixes).
  - perf sched: Fix memory leaks in 'perf sched latency'
    (git-fixes).
  - perf sched: Use RC_CHK_EQUAL() to compare pointers (git-fixes).
  - perf sched: Fix memory leaks for evsel->priv in timehist
    (git-fixes).
  - perf sched: Fix thread leaks in 'perf sched timehist'
    (git-fixes).
  - perf sched: Fix memory leaks in 'perf sched map' (git-fixes).
  - perf sched: Free thread->priv using priv_destructor (git-fixes).
  - perf sched: Make sure it frees the usage string (git-fixes).
  - perf dso: Add missed dso__put to dso__load_kcore (git-fixes).
  - perf parse-events: Set default GH modifier properly (git-fixes).
  - perf trace: Remove --map-dump documentation (git-fixes).
  - commit ab29dec
  - kabi: restore layout of struct cgroup_rstat_cpu (bsc#1247963).
  - commit 4968d41
  - cgroup: remove per-cpu per-subsystem locks (bsc#1247963).
  - cgroup: make css_rstat_updated nmi safe (bsc#1247963).
  - cgroup: support to enable nmi-safe css_rstat_updated
    (bsc#1247963).
  - commit 8bebd47
  - KVM: arm64: vgic: fix incorrect spinlock API usage (git-fixes).
  - commit 3e87b0e
  - Refresh
    patches.suse/net-usb-qmi_wwan-add-Telit-Cinterion-LE910C4-WWX-new.patch.
    Adding alt commit ID
  - commit 620e1f8
  - Refresh
    patches.suse/net-usb-qmi_wwan-add-Telit-Cinterion-FN990A-w-audio-.patch.
    Add alt commit ID
  - commit ce1eebe
  - KVM: arm64: Mark freed S2 MMUs as invalid (git-fixes).
  - commit 7df42be

++++ kernel-rt:

  - io_uring/kbuf: always use READ_ONCE() to read ring provided
    buffer lengths (CVE-2025-39816 bsc#1249906).
  - commit 5f1b3b6
  - perf bpf-utils: Harden get_bpf_prog_info_linear (git-fixes).
  - perf bpf-utils: Constify bpil_array_desc (git-fixes).
  - perf bpf-event: Fix use-after-free in synthesis (git-fixes).
  - perf symbol-minimal: Fix ehdr reading in filename__read_build_id
    (git-fixes).
  - perf record: Cache build-ID of hit DSOs only (git-fixes).
  - perf tools: Remove libtraceevent in .gitignore (git-fixes).
  - perf topdown: Use attribute to see an event is a topdown metic
    or slots (git-fixes).
  - perf hwmon_pmu: Avoid shortening hwmon PMU name (git-fixes).
  - perf tests bp_account: Fix leaked file descriptor (git-fixes).
  - perf sched: Fix memory leaks in 'perf sched latency'
    (git-fixes).
  - perf sched: Use RC_CHK_EQUAL() to compare pointers (git-fixes).
  - perf sched: Fix memory leaks for evsel->priv in timehist
    (git-fixes).
  - perf sched: Fix thread leaks in 'perf sched timehist'
    (git-fixes).
  - perf sched: Fix memory leaks in 'perf sched map' (git-fixes).
  - perf sched: Free thread->priv using priv_destructor (git-fixes).
  - perf sched: Make sure it frees the usage string (git-fixes).
  - perf dso: Add missed dso__put to dso__load_kcore (git-fixes).
  - perf parse-events: Set default GH modifier properly (git-fixes).
  - perf trace: Remove --map-dump documentation (git-fixes).
  - commit ab29dec
  - kabi: restore layout of struct cgroup_rstat_cpu (bsc#1247963).
  - commit 4968d41
  - cgroup: remove per-cpu per-subsystem locks (bsc#1247963).
  - cgroup: make css_rstat_updated nmi safe (bsc#1247963).
  - cgroup: support to enable nmi-safe css_rstat_updated
    (bsc#1247963).
  - commit 8bebd47
  - KVM: arm64: vgic: fix incorrect spinlock API usage (git-fixes).
  - commit 3e87b0e
  - Refresh
    patches.suse/net-usb-qmi_wwan-add-Telit-Cinterion-LE910C4-WWX-new.patch.
    Adding alt commit ID
  - commit 620e1f8
  - Refresh
    patches.suse/net-usb-qmi_wwan-add-Telit-Cinterion-FN990A-w-audio-.patch.
    Add alt commit ID
  - commit ce1eebe
  - KVM: arm64: Mark freed S2 MMUs as invalid (git-fixes).
  - commit 7df42be

++++ python313-core:

  - Drop AppStream: this results in a different cycle than
    appstream-glib. As the appdata.xml is controlled by ourselves, we
    can get away with just manually validating it when changing it.

++++ libzypp:

  - runposttrans: strip root prefix from tmppath (bsc#1250343)
  - fixup! Make ld.so ignore the subarch packages during install
    (bsc#1246912)
  - version 17.37.18 (35)

++++ python313:

  - Drop AppStream: this results in a different cycle than
    appstream-glib. As the appdata.xml is controlled by ourselves, we
    can get away with just manually validating it when changing it.

++++ ucode-intel:

  - switch the supplements to use supplements + kernel to allow
    moving a installation to Intel hardware (bsc#1249138)

------------------------------------------------------------------
------------------  2025-9-20  -  Sep 20 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - NFSv4/flexfiles: Fix layout merge mirror check (git-fixes).
  - commit d3e4ea4
  - SUNRPC: call xs_sock_process_cmsg for all cmsg (git-fixes).
  - commit e20ec8c
  - Revert "SUNRPC: Don't allow waiting for exiting tasks"
    (git-fixes).
  - commit d3bd385
  - NFS: nfs_invalidate_folio() must observe the offset and size
    arguments (git-fixes).
  - commit 3067280
  - flexfiles/pNFS: fix NULL checks on result of
    ff_layout_choose_ds_for_read (git-fixes).
  - commit fba14d9
  - NFSv4: Clear the NFS_CAP_XATTR flag if not supported by the
    server (git-fixes).
  - commit 59365a8
  - NFSv4: Clear NFS_CAP_OPEN_XOR and NFS_CAP_DELEGTIME if not
    supported (git-fixes).
  - commit 1bfae45
  - NFSv4: Clear the NFS_CAP_FS_LOCATIONS flag if it is not set
    (git-fixes).
  - commit 36a8789
  - NFSv4: Don't clear capabilities that won't be reset (git-fixes).
  - commit e82d989
  - xfs: fix scrub trace with null pointer in quotacheck
    (git-fixes).
  - commit df9ef9b
  - Delete patches.suse/drm-amd-display-Optimize-cursor-position-updates.patch (git-fixes)
    reverted in the upstream
  - commit fb65ee4
  - mmc: mvsdio: Fix dma_unmap_sg() nents value (git-fixes).
  - crypto: af_alg - Set merge to zero early in af_alg_sendmsg
    (git-fixes).
  - ASoC: qcom: q6apm-lpass-dais: Fix missing set_fmt DAI op for
    I2S (git-fixes).
  - ASoC: qcom: audioreach: Fix lpaif_type configuration for the
    I2S interface (git-fixes).
  - ASoC: Intel: catpt: Expose correct bit depth to userspace
    (git-fixes).
  - ASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dereference if
    source graph failed (git-fixes).
  - ASoC: wm8974: Correct PLL rate rounding (git-fixes).
  - ASoC: wm8940: Correct typo in control name (git-fixes).
  - ASoC: wm8940: Correct PLL rate rounding (git-fixes).
  - ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in
    error message (git-fixes).
  - ALSA: hda: intel-dsp-config: Prevent SEGFAULT if ACPI_HANDLE()
    is NULL (git-fixes).
  - ALSA: hda/realtek: Add ALC295 Dell TAS2781 I2C fixup
    (git-fixes).
  - drm/amd/display: Allow RX6xxx & RX7700 to invoke
    amdgpu_irq_get/put (git-fixes).
  - drm/xe: Fix a NULL vs IS_ERR() in xe_vm_add_compute_exec_queue()
    (git-fixes).
  - drm/xe/tile: Release kobject for the failure path (git-fixes).
  - drm: bridge: cdns-mhdp8546: Fix missing mutex unlock on error
    path (git-fixes).
  - drm: bridge: anx7625: Fix NULL pointer dereference with early
    IRQ (git-fixes).
  - USB: serial: option: add Telit Cinterion LE910C4-WWX new
    compositions (stable-fixes).
  - USB: serial: option: add Telit Cinterion FN990A w/audio
    compositions (stable-fixes).
  - Input: i8042 - add TUXEDO InfinityBook Pro Gen10 AMD to i8042
    quirk table (stable-fixes).
  - Input: iqs7222 - avoid enabling unused interrupts
    (stable-fixes).
  - drm/amdgpu/vcn: Allow limiting ctx to instance 0 for AV1 at
    any time (stable-fixes).
  - drm/amdgpu/vcn4: Fix IB parsing with multiple engine info
    packages (stable-fixes).
  - compiler-clang.h: define __SANITIZE_*__ macros only when
    undefined (stable-fixes).
  - i2c: i801: Hide Intel Birch Stream SoC TCO WDT (git-fixes).
  - commit 65f2bb8

++++ kernel-firmware-amdgpu:

  - Update to version 20250919 (git commit 493de17dee99):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-firmware-ath12k:

  - Update to version 20250919 (git commit 493de17dee99):
    * ath12k: WCN7850 hw2.0: update board-2.bin

++++ kernel-rt:

  - NFSv4/flexfiles: Fix layout merge mirror check (git-fixes).
  - commit d3e4ea4
  - SUNRPC: call xs_sock_process_cmsg for all cmsg (git-fixes).
  - commit e20ec8c
  - Revert "SUNRPC: Don't allow waiting for exiting tasks"
    (git-fixes).
  - commit d3bd385
  - NFS: nfs_invalidate_folio() must observe the offset and size
    arguments (git-fixes).
  - commit 3067280
  - flexfiles/pNFS: fix NULL checks on result of
    ff_layout_choose_ds_for_read (git-fixes).
  - commit fba14d9
  - NFSv4: Clear the NFS_CAP_XATTR flag if not supported by the
    server (git-fixes).
  - commit 59365a8
  - NFSv4: Clear NFS_CAP_OPEN_XOR and NFS_CAP_DELEGTIME if not
    supported (git-fixes).
  - commit 1bfae45
  - NFSv4: Clear the NFS_CAP_FS_LOCATIONS flag if it is not set
    (git-fixes).
  - commit 36a8789
  - NFSv4: Don't clear capabilities that won't be reset (git-fixes).
  - commit e82d989
  - xfs: fix scrub trace with null pointer in quotacheck
    (git-fixes).
  - commit df9ef9b
  - Delete patches.suse/drm-amd-display-Optimize-cursor-position-updates.patch (git-fixes)
    reverted in the upstream
  - commit fb65ee4
  - mmc: mvsdio: Fix dma_unmap_sg() nents value (git-fixes).
  - crypto: af_alg - Set merge to zero early in af_alg_sendmsg
    (git-fixes).
  - ASoC: qcom: q6apm-lpass-dais: Fix missing set_fmt DAI op for
    I2S (git-fixes).
  - ASoC: qcom: audioreach: Fix lpaif_type configuration for the
    I2S interface (git-fixes).
  - ASoC: Intel: catpt: Expose correct bit depth to userspace
    (git-fixes).
  - ASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dereference if
    source graph failed (git-fixes).
  - ASoC: wm8974: Correct PLL rate rounding (git-fixes).
  - ASoC: wm8940: Correct typo in control name (git-fixes).
  - ASoC: wm8940: Correct PLL rate rounding (git-fixes).
  - ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in
    error message (git-fixes).
  - ALSA: hda: intel-dsp-config: Prevent SEGFAULT if ACPI_HANDLE()
    is NULL (git-fixes).
  - ALSA: hda/realtek: Add ALC295 Dell TAS2781 I2C fixup
    (git-fixes).
  - drm/amd/display: Allow RX6xxx & RX7700 to invoke
    amdgpu_irq_get/put (git-fixes).
  - drm/xe: Fix a NULL vs IS_ERR() in xe_vm_add_compute_exec_queue()
    (git-fixes).
  - drm/xe/tile: Release kobject for the failure path (git-fixes).
  - drm: bridge: cdns-mhdp8546: Fix missing mutex unlock on error
    path (git-fixes).
  - drm: bridge: anx7625: Fix NULL pointer dereference with early
    IRQ (git-fixes).
  - USB: serial: option: add Telit Cinterion LE910C4-WWX new
    compositions (stable-fixes).
  - USB: serial: option: add Telit Cinterion FN990A w/audio
    compositions (stable-fixes).
  - Input: i8042 - add TUXEDO InfinityBook Pro Gen10 AMD to i8042
    quirk table (stable-fixes).
  - Input: iqs7222 - avoid enabling unused interrupts
    (stable-fixes).
  - drm/amdgpu/vcn: Allow limiting ctx to instance 0 for AV1 at
    any time (stable-fixes).
  - drm/amdgpu/vcn4: Fix IB parsing with multiple engine info
    packages (stable-fixes).
  - compiler-clang.h: define __SANITIZE_*__ macros only when
    undefined (stable-fixes).
  - i2c: i801: Hide Intel Birch Stream SoC TCO WDT (git-fixes).
  - commit 65f2bb8

------------------------------------------------------------------
------------------  2025-9-19  -  Sep 19 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - btrfs: fix invalid extref key setup when replaying dentry
    (git-fixes).
  - commit d3ba0e7
  - mm/memory-failure: fix redundant updates for already poisoned pages (bsc#1250087).
  - commit 2742d4a
  - KVM: s390: Fix incorrect usage of mmu_notifier_register()
    (git-fixes bsc#1250123).
  - KVM: s390: Fix access to unavailable adapter indicator pages
    during postcopy (git-fixes bsc#1250124).
  - commit 4b89509
  - kabi: hide new member allow_subflows in struct mptcp_sock
    (CVE-2025-38491 bsc#1247280).
  - commit 0d82424
  - mptcp: plug races between subflow fail and subflow creation
    (CVE-2025-38491 bsc#1247280).
  - Refresh patches.kabi/kabi-hide-new-member-fallback_lock-in-struct-mptcp_s.patch.
  - commit 7b433f3
  - Update
    patches.kabi/kabi-hide-new-member-fallback_lock-in-struct-mptcp_s.patch.
    Original kABI workaround relied on the fact that struct mptcp has a 4-byte
    padding which the new member fallback_lock (of type spinlock_t) can fit
    into. Unfortunately this is not true in realtime builds where spinlock_t is
    32 bytes long.
    Thankfully we do not have to preserve the length of struct mptcp_sock as
    explained in the patch commit message.
  - commit 7542a84
  - gfs2: Validate i_depth for exhash directories (bsc#1249201
    CVE-2025-38710).
  - commit 1cd54df

++++ kernel-rt:

  - btrfs: fix invalid extref key setup when replaying dentry
    (git-fixes).
  - commit d3ba0e7
  - mm/memory-failure: fix redundant updates for already poisoned pages (bsc#1250087).
  - commit 2742d4a
  - KVM: s390: Fix incorrect usage of mmu_notifier_register()
    (git-fixes bsc#1250123).
  - KVM: s390: Fix access to unavailable adapter indicator pages
    during postcopy (git-fixes bsc#1250124).
  - commit 4b89509
  - kabi: hide new member allow_subflows in struct mptcp_sock
    (CVE-2025-38491 bsc#1247280).
  - commit 0d82424
  - mptcp: plug races between subflow fail and subflow creation
    (CVE-2025-38491 bsc#1247280).
  - Refresh patches.kabi/kabi-hide-new-member-fallback_lock-in-struct-mptcp_s.patch.
  - commit 7b433f3
  - Update
    patches.kabi/kabi-hide-new-member-fallback_lock-in-struct-mptcp_s.patch.
    Original kABI workaround relied on the fact that struct mptcp has a 4-byte
    padding which the new member fallback_lock (of type spinlock_t) can fit
    into. Unfortunately this is not true in realtime builds where spinlock_t is
    32 bytes long.
    Thankfully we do not have to preserve the length of struct mptcp_sock as
    explained in the patch commit message.
  - commit 7542a84
  - gfs2: Validate i_depth for exhash directories (bsc#1249201
    CVE-2025-38710).
  - commit 1cd54df

++++ read-only-root-fs:

  - Add additional check in %post to prevent generating the btrfs
    /etc subvolume during a KIWI run
    [bsc#1250133] [gh#openSUSE/read-only-root-fs#27]

------------------------------------------------------------------
------------------  2025-9-18  -  Sep 18 2025  -------------------
------------------------------------------------------------------

++++ bash-completion:

  - Add patch bug1246923.patch
    * Skip colon from device names for ethtool (bsc#1246923)

++++ cockpit:

  - Rewrite hide-pcp.patch to apply to SLFO based versions of micro

++++ kernel-default:

  - Refresh
    patches.kabi/kabi-hide-new-member-allow_subflows-in-struct-mptcp_.patch
  - Refresh
    patches.kabi/xsk-Fix-race-condition-in-AF_XDP-generic-RX-path.patch
    Automated edit
    git grep -l static_assert patches.kabi/ | xargs sed -i '/^+/s/static_assert/suse_kabi_static_assert/'
    plus modified guards in kabi-hide-new-member-allow_subflows-in-struct-mptcp_.patch.
  - commit ee20154
  - Revert "Refresh patches.kabi/xsk-Fix-race-condition-in-AF_XDP-generic-RX-path.patch"
    This reverts commit e7bb4bfabf763f6feebe9b971c01a1746b67afc6.
  - commit d1ce41e
  - Update config files. (bsc#1249186)
    Enable where we define KABI refs + rely on Kconfig deps.
  - commit 2bf74df
  - Update config files.
    Run run_oldconfig.
    Re-unset CONFIG_DRM_MSM_VALIDATE_XML, disappeared in
    9ca53363a24bc40dd0bda686354dfa6687847f48.
  - commit 269a088
  - jbd2: prevent softlockup in jbd2_log_do_checkpoint()
    (bsc#1249526 CVE-2025-39782).
  - commit 7f18cbf
  - ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
    (bsc#1249258 CVE-2025-38701).
  - commit 364a60b
  - loop: Avoid updating block size under exclusive owner
    (bsc#1249199 CVE-2025-38709).
  - commit 4262a77
  - eventpoll: Fix semi-unbounded recursion (bsc#1248392
    CVE-2025-38614).
  - commit 7646f9d
  - fs/buffer: fix use-after-free when call bh_read() helper
    (bsc#1249374 CVE-2025-39691).
  - commit 632fdc7
  - net: bridge: fix soft lockup in br_multicast_query_expired()
    (CVE-2025-39773 bsc#1249504).
  - commit 69dfa3b

++++ kernel-rt:

  - Refresh
    patches.kabi/kabi-hide-new-member-allow_subflows-in-struct-mptcp_.patch
  - Refresh
    patches.kabi/xsk-Fix-race-condition-in-AF_XDP-generic-RX-path.patch
    Automated edit
    git grep -l static_assert patches.kabi/ | xargs sed -i '/^+/s/static_assert/suse_kabi_static_assert/'
    plus modified guards in kabi-hide-new-member-allow_subflows-in-struct-mptcp_.patch.
  - commit ee20154
  - Revert "Refresh patches.kabi/xsk-Fix-race-condition-in-AF_XDP-generic-RX-path.patch"
    This reverts commit e7bb4bfabf763f6feebe9b971c01a1746b67afc6.
  - commit d1ce41e
  - Update config files. (bsc#1249186)
    Enable where we define KABI refs + rely on Kconfig deps.
  - commit 2bf74df
  - Update config files.
    Run run_oldconfig.
    Re-unset CONFIG_DRM_MSM_VALIDATE_XML, disappeared in
    9ca53363a24bc40dd0bda686354dfa6687847f48.
  - commit 269a088
  - jbd2: prevent softlockup in jbd2_log_do_checkpoint()
    (bsc#1249526 CVE-2025-39782).
  - commit 7f18cbf
  - ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr
    (bsc#1249258 CVE-2025-38701).
  - commit 364a60b
  - loop: Avoid updating block size under exclusive owner
    (bsc#1249199 CVE-2025-38709).
  - commit 4262a77
  - eventpoll: Fix semi-unbounded recursion (bsc#1248392
    CVE-2025-38614).
  - commit 7646f9d
  - fs/buffer: fix use-after-free when call bh_read() helper
    (bsc#1249374 CVE-2025-39691).
  - commit 632fdc7
  - net: bridge: fix soft lockup in br_multicast_query_expired()
    (CVE-2025-39773 bsc#1249504).
  - commit 69dfa3b

++++ python313-core:

  - Require AppStream to validate appdata file instead of deprecated
    appstream-glib.
  - Update idle3.appdata.xml to pass the more pedantic appstreamcli.

++++ tiff:

  - Update to 4.7.1:
    Software configuration changes:
    * Define HAVE_JPEGTURBO_DUAL_MODE_8_12 and LERC_STATIC in tif_config.h.
    * CMake: define WORDS_BIGENDIAN via tif_config.h
    * doc/CMakeLists.txt: remove useless cmake_minimum_required()
    * CMake: fix build with LLVM/Clang 17 (fixes issue #651)
    * CMake: set CMP0074 new policy
    * Set LINKER_LANGUAGE for C targets with C deps
    * Export tiffxx cmake target (fixes issue #674)
    * autogen.sh: Enable verbose wget.
    * configure.ac: Syntax updates for Autoconf 2.71
    * autogen.sh: Re-implement based on autoreconf. Failure to update
    config.guess/config.sub does not return error (fixes issue #672)
    * CMake: fix CMake 4.0 warning when minimum required version is < 3.10.
    * CMake: Add build option tiff-static (fixes issue #709)
    Library changes:
    * Add TIFFOpenOptionsSetWarnAboutUnknownTags() for explicit control
    about emitting warnings for unknown tags. No longer emit warnings
    about unknown tags by default
    * tif_predict.c: speed-up decompression in some cases.
    Bug fixes:
    * tif_fax3: For fax group 3 data if no EOL is detected, reading is
    retried without synchronisation for EOLs. (fixes issue #54)
    * Updating TIFFMergeFieldInfo() with read_count=write_count=0 for
    FIELD_IGNORE. Updating TIFFMergeFieldInfo() with read_count=write_count=0 for
    FIELD_IGNORE. Improving handling when field_name = NULL. (fixes issue #532)
    * tiff.h: add COMPRESSION_JXL_DNG_1_7=52546 as used for JPEGXL compression in
    the DNG 1.7 specification
    * TIFFWriteDirectorySec: Increment string length for ASCII tags for codec tags
    defined with FIELD_xxx bits, as it is done for FIELD_CUSTOM tags. (fixes issue #648)
    * Do not error out on a tag whose tag count value is zero, just issue a warning.
    Fix parsing a private tag 0x80a6 (fixes issue #647)
    * TIFFDefaultTransferFunction(): give up beyond td_bitspersample = 24
    Fixes https://github.com/OSGeo/gdal/issues/10875)
    * tif_getimage.c: Remove unnecessary calls to TIFFRGBAImageOK() (fixes issue #175)
    * Fix writing a Predictor=3 file with non-native endianness
    * _TIFFVSetField(): fix potential use of unallocated memory (out-of-bounds
    * read / nullptr dereference) in case of out-of-memory situation when dealing with
    custom tags (fixes issue #663)
    * tif_fax3.c: Error out for CCITT fax encoding if SamplesPerPixel is not equal 1 and
    PlanarConfiguration = Contiguous (fixes issue #26)
    * tif_fax3.c: error out after a number of times end-of-line or unexpected bad code
    words have been reached. (fixes issue #670)
    * Fix memory leak in TIFFSetupStrips() (fixes issue #665)
    * tif_zip.c: Provide zlib allocation functions. Otherwise for zlib built with
  - DZ_SOLO inflating will fail.
    * Fix memory leak in _TIFFSetDefaultCompressionState. (fixes issue #676)
    * tif_predict.c: Don’t overwrite input buffer of TIFFWriteScanline() if "prediction"
    is enabled. Use extra working buffer in PredictorEncodeRow(). (fixes issue #5)
    * tif_getimage.c: update some integer overflow checks (fixes issue #79)
    * tif_getimage.c: Fix buffer underflow crash for less raster rows at
    TIFFReadRGBAImageOriented() (fixes issue #704, bsc#1250413, CVE-2025-9900)
    * TIFFReadRGBAImage(): several fixes to avoid buffer overflows.
    * Correct passing arguments to TIFFCvtIEEEFloatToNative() and TIFFCvtIEEEDoubleToNative()
    if HAVE_IEEEFP is not defined. (fixes issue #699)
    * LZWDecode(): avoid nullptr dereference when trying to read again after EOI marker
    has been found with remaining output bytes (fixes issue #698)
    * TIFFSetSubDirectory(): check _TIFFCheckDirNumberAndOffset() return.
    * TIFFUnlinkDirectory() and TIFFWriteDirectorySec(): clear tif_rawcp when clearing
    tif_rawdata (fixes issue #711)
    * JPEGEncodeRaw(): error out if a previous scanline failed to be written, to avoid
    out-of-bounds access (fixes issue #714)
    * tif_jpeg: Fix bug in JPEGDecodeRaw() if JPEG_LIB_MK1_OR_12BIT is defined for 8/12bit
    dual mode, introduced in libjpeg-turbo 2.2, which was actually released as 3.0.
    Fixes issue #717
    * add assert for TIFFReadCustomDirectory infoarray check.
    * ppm2tiff: Fix bug in pack_words trailing bytes, where last two bytes of each line
    were written wrongly. (fixes issue #467)
    * fax2ps: fix regression of commit 28c38d648b64a66c3218778c4745225fe3e3a06d where
    TIFFTAG_FAXFILLFUNC is being used rather than an output buffer (fixes issue #649)
    * tiff2pdf: Check TIFFTAG_TILELENGTH and TIFFTAGTILEWIDTH (fixes issue #650)
    * tiff2pdf: check h_samp and v_samp for range 1 to 4 to avoid division by zero.
    Fixes issue #654
    * tiff2pdf: avoid null pointer dereference. (fixes issue #741)
    * Improve non-secure integer overflow check (comparison of division result with
    multiplicant) at compiler optimisation in tiffcp, rgb2ycbcr and tiff2rgba.
    Fixes issue #546
    * tiff2rgba: fix some "a partial expression can generate an overflow before it is
    assigned to a broader type" warnings. (fixes issue #682)
    * tiffdither/tiffmedian: Don't skip the first line of the input image. (fixes issue #703)
    * tiffdither: avoid out-of-bounds read identified in issue #733
    * tiffmedian: error out if TIFFReadScanline() fails (fixes issue #707)
    * tiffmedian: close input file. (fixes issue #735)
    * thumbail: avoid potential out of bounds access (fixes issue #715)
    * tiffcrop: close open TIFF files and release allocated buffers before exiting in case
    of error to avoid memory leaks. (fixes issue #716)
    * tiffcrop: fix double-free and memory leak exposed by issue #721
    * tiffcrop: avoid buffer overflow. (fixes issue #740)
    * tiffcrop: avoid nullptr dereference. (fixes issue #734)
    * tiffdump: Fix coverity scan issue CID 1373365: Passing tainted expression *datamem
    to PrintData, which uses it as a divisor or modulus.
    * tiff2ps: check return of TIFFGetFiled() for TIFFTAG_STRIPBYTECOUNTS and
    TIFFTAG_TILEBYTECOUNTS to avoid NULL pointer dereference. (fixes issue #718)
    * tiffcmp: fix memory leak when second file cannot be opened. (fixes issue #718 and issue #729)
    * tiffcp: fix setting compression level for lossless codecs. (fixes issue #730)
    * raw2tiff: close input file before exit (fixes issue #742)
    Tools changes:
    * tiffinfo: add a -W switch to warn about unknown tags.
    * tiffdither: process all pages in input TIFF file.
    Documentation:
    * TIFFRGBAImage.rst note added for incorrect saving of images with TIFF orientation
    from 5 (LeftTop) to 8 (LeftBottom) in the raster.
    * TIFFRGBAImage.rst note added about un-associated alpha handling (fixes issue #67)
    * Update "Defining New TIFF Tags" description. (fixes issue #642)
    * Fix return type of TIFFReadEncodedTile()
    * Update the documentation to reflect deprecated typedefs.
    * TIFFWriteDirectory.rst: Clarify TIFFSetWriteOffset() only sets offset for image
    data and not for IFD data.
    * Update documentation on re-entrancy and thread safety.
    * Remove dead links to no more existing Awaresystems web-site.
    * Updating BigTIFF specification and some miscelaneous editions.
    * Replace some last links and remove last todos.
    * Added hints for correct allocation of TIFFYCbCrtoRGB structure and its
    associated buffers. (fixes issue #681)
    * Added chapter to "Using the TIFF Library" with links to handling multi-page TIFF
    and custom directories. (fixes issue #43)
    * update TIFFOpen.rst with the return values of mapproc and unmapproc. (fixes issue #12)
  - Drop upstreamed patches:
    * tiff-4.7.0-test_directory.patch
    * tiff-CVE-2025-8176.patch
    * tiff-CVE-2025-8177.patch
    * tiff-4.7.0-bsc1243503.patch
    * tiff-CVE-2025-8534.patch
    * tiff-CVE-2025-9165.patch
    * tiff-CVE-2024-13978.patch
    * tiff-CVE-2025-8961.patch

++++ python313:

  - Require AppStream to validate appdata file instead of deprecated
    appstream-glib.
  - Update idle3.appdata.xml to pass the more pedantic appstreamcli.

------------------------------------------------------------------
------------------  2025-9-17  -  Sep 17 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Don't set UEFI as default firmware for ppc64le and s390x
    * Fixes bsc#1249828 and bsc#1249830

++++ cups:

  - Version upgrade to 2.4.14:
    See https://github.com/openprinting/cups/releases
    The hotfix release brings fix for installation process
    of localized templates and CUPS web UI home pages.
  - Version upgrade to 2.4.13:
    See https://github.com/openprinting/cups/releases
    The release 2.4.13 brings two CVE fixes
    fix for important CVE-2025-58060
    "Authentication bypass with AuthType Negotiate" (bsc#1249049)
    and fix for moderate CVE-2025-58364
    "Remote DoS via null dereference" (bsc#1249128)
    together with several bug fixes.
    The release includes a new feature - new attribute
    for printer and job objects - print-as-raster - which
    allows enforce rasterization of the file for
    IPP Everywhere/AirPrint printers, which supports PDF
    and raster document formats. The feature is useful for
    working around internal PDF issues in the printer firmware,
    for example missing diacritic when printing a PDF.
    Detailed list (from CHANGES.md):
    * Blocked authentication using alternate methods
    in cupsd (CVE-2025-58060)
    * Fixed extension tag handling in 'ipp_read_io()'
    in libcups (CVE-2025-58364)
    * Added 'print-as-raster' printer and job attributes
    for forcing rasterization (Issue #1282)
    * Updated documentation (Issue #1086)
    * Updated IPP backend to try a sanitized user name if the
    printer/server does not like the value (Issue #1145)
    * Updated the scheduler to send the "printer-added"
    or "printer-modified" events  whenever an IPP Everywhere PPD
    is installed (Issue #1244)
    * Updated the scheduler to send the "printer-modified" event
    whenever the system default printer is changed (Issue #1246)
    * Fixed a memory leak in 'httpClose' (Issue #1223)
    * Fixed missing commas in 'ippCreateRequestedArray'
    (Issue #1234)
    * Fixed subscription issues in the scheduler and D-Bus notifier
    (Issue #1235)
    * Fixed media-default reporting for custom sizes (Issue #1238)
    * Fixed support for IPP/PPD options with periods or underscores
    (Issue #1249)
    * Fixed parsing of real numbers in PPD compiler source files
    (Issue #1263)
    * Fixed scheduler freezing with zombie clients (Issue #1264)
    * Fixed support for the server name in the ErrorLog filename
    (Issue #1277)
    * Fixed job cleanup after daemon restart (Issue #1315)
    * Fixed handling of buggy DYMO USB printer serial numbers
    (Issue #1338)
    * Fixed unreachable block in IPP backend (Issue #1351)
    * Fixed memory leak in _cupsConvertOptions (Issue #1354)
    Issues are those at https://github.com/OpenPrinting/cups/issues
  - Adapted downgrade-autoconf-requirement.patch for CUPS 2.4.14

++++ kernel-default:

  - rpm/config.sh: SLFO 1.2 is now synced to OBS as well
  - commit a1cec7e
  - ACPI: RISC-V: Fix FFH_CPPC_CSR error handling (git-fixes).
  - commit 29541f6
  - ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path
    (stable-fixes).
  - commit 3cb3b40
  - io_uring/net: commit partial buffers on retry (CVE-2025-38730
    bsc#1249172).
  - commit 6c3c764
  - io_uring/futex: ensure io_futex_wait() cleans up properly on
    failure (bsc#1249322 CVE-2025-39698).
  - commit 6b74cde
  - userfaultfd: fix a crash in UFFDIO_MOVE when PMD is a migration
    entry (CVE-2025-38686 bsc#1249160).
  - commit a942b8d
  - kABI: netfs: handle new netfs_io_stream flag (bsc#1249314
    CVE-2025-39723).
  - commit b79d24b
  - btrfs: fix subvolume deletion lockup caused by inodes xarray
    race (git-fixes).
  - commit d8d3b1e
  - btrfs: fix squota compressed stats leak (git-fixes).
  - commit f4489c7
  - btrfs: fix wrong length parameter for
    btrfs_cleanup_ordered_extents() (git-fixes).
  - commit 73f12d4
  - netfs: Fix unbuffered write error handling (stable-fixes
    bsc#1249314 CVE-2025-39723).
  - commit de949a4
  - ppp: fix race conditions in ppp_fill_forward_path
    (CVE-2025-39673 bsc#1249320).
  - commit 835095c

++++ kernel-firmware-amdgpu:

  - Update to version 20250916 (git commit add225168d0d):
    * amdgpu: update PSP 14.0.3 kicker firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update VPE 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update GC 10.3.6 firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update VCN 5.0.0 firmware
    * amdgpu: update PSP 14.0.3 firmware
    * amdgpu: update GC 12.0.1 firmware
    * amdgpu: update SMU 14.0.2 firmware
    * amdgpu: update PSP 14.0.2 firmware
    * amdgpu: update GC 12.0.0 firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update SMU 13.0.0 kicker firmware
    * amdgpu: update PSP 13.0.0 kicker firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update SMU 13.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update VCN 5.0.1 firmware
    * amdgpu: update PSP 13.0.12 firmware
    * amdgpu: update GC 9.5.0 firmware
    * amdgpu: update PSP 13.0.14 firmware
    * amdgpu: update GC 9.4.4 firmware
    * amdgpu: update SDMA 6.1.3 firmware
    * amdgpu: update PSP 14.0.5 firmware
    * amdgpu: update GC 11.5.3 firmware
    * amdgpu: update VPE 6.1.3 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.3 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware

++++ kernel-rt:

  - rpm/config.sh: SLFO 1.2 is now synced to OBS as well
  - commit a1cec7e
  - ACPI: RISC-V: Fix FFH_CPPC_CSR error handling (git-fixes).
  - commit 29541f6
  - ACPI: APEI: GHES: add TAINT_MACHINE_CHECK on GHES panic path
    (stable-fixes).
  - commit 3cb3b40
  - io_uring/net: commit partial buffers on retry (CVE-2025-38730
    bsc#1249172).
  - commit 6c3c764
  - io_uring/futex: ensure io_futex_wait() cleans up properly on
    failure (bsc#1249322 CVE-2025-39698).
  - commit 6b74cde
  - userfaultfd: fix a crash in UFFDIO_MOVE when PMD is a migration
    entry (CVE-2025-38686 bsc#1249160).
  - commit a942b8d
  - kABI: netfs: handle new netfs_io_stream flag (bsc#1249314
    CVE-2025-39723).
  - commit b79d24b
  - btrfs: fix subvolume deletion lockup caused by inodes xarray
    race (git-fixes).
  - commit d8d3b1e
  - btrfs: fix squota compressed stats leak (git-fixes).
  - commit f4489c7
  - btrfs: fix wrong length parameter for
    btrfs_cleanup_ordered_extents() (git-fixes).
  - commit 73f12d4
  - netfs: Fix unbuffered write error handling (stable-fixes
    bsc#1249314 CVE-2025-39723).
  - commit de949a4
  - ppp: fix race conditions in ppp_fill_forward_path
    (CVE-2025-39673 bsc#1249320).
  - commit 835095c

++++ systemd:

  - systemd.spec: use %sysusers_generate_pre so that some systemd users are
    already available in %pre. This is important because D-Bus automatically
    reloads its configuration whenever new configuration files are installed,
    i.e. between %pre and %post. (bsc#1248501)
    No needs for systemd and udev packages as they are always installed during
    the initial installation.
  - Import commit c139debf2c6e9556df8ee6eca77ae18d5b98f027 (merge of v257.9)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/835af70f4e4fab4746319145d9fdb1a01e33f4c8...c139debf2c6e9556df8ee6eca77ae18d5b98f027
  - Rebase 5001-Revert-udev-update-devlink-with-the-newer-device-nod.patch
  - Import commit 835af70f4e4fab4746319145d9fdb1a01e33f4c8
    835af70f4e core/cgroup: Properly handle aborting a pending freeze operation
    1f96f9da13 detect-virt: add bare-metal support for GCE (bsc#1244449)
    c3bcfc9558 uki.conf is used by the ukify tool to create an Unified Kernel Image[...]
  - Make sure that the ordering trick used to update the udev package as close as
    as possible to the update of the systemd package also works with zypper.
    We also need to add "Suggests: udev", which serves the same purpose as
    "OrderWithRequires: udev" but is part of the repository metadata. It should
    therefore hint zypper to install systemd and udev as close together as
    possible (see bsc#1228659)

++++ nvidia-open-driver-G06-signed:

  - pesign-spec-macros: added definition for %__kernel_supplements,
    which replaced %__kmp_supplements with latest RPM used on TW now,
    in order to fix PCI HW Supplements for TW (boo#1249814)

------------------------------------------------------------------
------------------  2025-9-16  -  Sep 16 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Add a hard require on libvirt bsc#1236149
  - add hostadd-allow-device-form-to-overflow-on-X-axis.patch fixes bsc#1248250

++++ kernel-default:

  - mm/damon/sysfs: fix use-after-free in state_show() (git-fixes).
  - commit 97c6157
  - percpu: fix race on alloc failed warning limit (git-fixes).
  - commit df7089c
  - mm/damon/reclaim: avoid divide-by-zero in
    damon_reclaim_apply_parameters() (git-fixes).
  - commit 7f118fd
  - mm/damon/lru_sort: avoid divide-by-zero in
    damon_lru_sort_apply_parameters() (git-fixes).
  - commit a721c93
  - mm/damon/core: set quota->charged_from to jiffies at first
    charge window (git-fixes).
  - commit 8cc5d6c
  - mm: fault in complete folios instead of individual pages for
    tmpfs (git-fixes).
  - commit 72eb4d6
  - mm: close theoretical race where stale TLB entries could linger
    (git-fixes).
  - commit 43ddf98
  - mm/damon/core: avoid destroyed target reference from DAMOS quota
    (git-fixes).
  - commit b8f858b
  - execmem: enforce allocation size aligment to PAGE_SIZE
    (git-fixes).
  - commit ed49080
  - coredump: Fixes core_pipe_limit sysctl proc_handler (git-fixes).
  - commit dfdab4e
  - mm: khugepaged: fix call hpage_collapse_scan_file() for
    anonymous vma (git-fixes).
  - commit debc2cc
  - pptp: fix pptp_xmit() error path (git-fixes).
  - commit bf03393
  - net, hsr: reject HSR frame if skb can't hold tag (CVE-2025-39703
    bsc#1249315).
  - commit 31af9c5
  - power: supply: bq27xxx: restrict no-battery detection to bq27000
    (git-fixes).
  - power: supply: bq27xxx: fix error return in case of no bq27000
    hdq battery (git-fixes).
  - commit ca0a722
  - drm/dp: Add an EDID quirk for the DPCD register access probe
    (bsc#1248121).
  - kABI workaround for "drm/dp: Add an EDID quirk for the DPCD
    register access probe" (bsc#1248121).
  - Refresh
    patches.suse/drm-Add-kabi-placeholders-to-commonly-used-structs.patch.
  - commit 8284f72
  - kABI: arm64: ftrace: Restore struct mod_arch_specific layout (git-fixes).
  - commit cb06f32
  - arm64: ftrace: fix unreachable PLT for ftrace_caller in init_module (git-fixes)
  - commit a64c583
  - arm64: dts: rockchip: Fix Bluetooth interrupts flag on Neardi LBA3368 (git-fixes)
  - commit 78938d3
  - arm64: dts: rockchip: Fix the headphone detection on the orangepi 5 (git-fixes)
  - commit ba5fe5b
  - arm64: dts: rockchip: Add vcc-supply to SPI flash on (git-fixes)
  - commit 8dd21d2
  - arm64: dts: rockchip: use cs-gpios for spi1 on ringneck (git-fixes)
  - commit 7fdd334
  - arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi 4B (git-fixes).
  - commit bc5a89e
  - arm64: dts: rockchip: disable unrouted USB controllers and PHY on (git-fixes)
  - commit 607b715
  - arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma (git-fixes)
  - commit d20c924
  - arm64: dts: imx8mp: Fix missing microSD slot vqmmc on Data Modul (git-fixes)
  - commit f84cc30
  - arm64: dts: imx8mp: Fix missing microSD slot vqmmc on DH electronics (git-fixes)
  - commit 627de8c
  - arm64: dts: imx8mp-tqma8mpql: fix LDO5 power off (git-fixes)
  - commit e690dcc
  - arm64: Mark kernel as tainted on SAE and SError panic (git-fixes)
  - commit 5a4a449
  - arm64: stacktrace: Check kretprobe_find_ret_addr() return value (git-fixes)
  - commit f7313d0
  - arm64: Handle KCOV __init vs inline mismatches (git-fixes)
  - commit 8a132f8
  - i2c: tegra: Use internal reset when reset property is not available (bsc#1249143)
  - commit 9c0b7e3
  - cpufreq: CPPC: Mark driver with NEED_UPDATE_LIMITS flag
    (stable-fixes).
  - commit fc53d59
  - cpufreq: Exit governor when failed to start old governor
    (stable-fixes).
  - commit e935313

++++ kernel-rt:

  - mm/damon/sysfs: fix use-after-free in state_show() (git-fixes).
  - commit 97c6157
  - percpu: fix race on alloc failed warning limit (git-fixes).
  - commit df7089c
  - mm/damon/reclaim: avoid divide-by-zero in
    damon_reclaim_apply_parameters() (git-fixes).
  - commit 7f118fd
  - mm/damon/lru_sort: avoid divide-by-zero in
    damon_lru_sort_apply_parameters() (git-fixes).
  - commit a721c93
  - mm/damon/core: set quota->charged_from to jiffies at first
    charge window (git-fixes).
  - commit 8cc5d6c
  - mm: fault in complete folios instead of individual pages for
    tmpfs (git-fixes).
  - commit 72eb4d6
  - mm: close theoretical race where stale TLB entries could linger
    (git-fixes).
  - commit 43ddf98
  - mm/damon/core: avoid destroyed target reference from DAMOS quota
    (git-fixes).
  - commit b8f858b
  - execmem: enforce allocation size aligment to PAGE_SIZE
    (git-fixes).
  - commit ed49080
  - coredump: Fixes core_pipe_limit sysctl proc_handler (git-fixes).
  - commit dfdab4e
  - mm: khugepaged: fix call hpage_collapse_scan_file() for
    anonymous vma (git-fixes).
  - commit debc2cc
  - pptp: fix pptp_xmit() error path (git-fixes).
  - commit bf03393
  - net, hsr: reject HSR frame if skb can't hold tag (CVE-2025-39703
    bsc#1249315).
  - commit 31af9c5
  - power: supply: bq27xxx: restrict no-battery detection to bq27000
    (git-fixes).
  - power: supply: bq27xxx: fix error return in case of no bq27000
    hdq battery (git-fixes).
  - commit ca0a722
  - drm/dp: Add an EDID quirk for the DPCD register access probe
    (bsc#1248121).
  - kABI workaround for "drm/dp: Add an EDID quirk for the DPCD
    register access probe" (bsc#1248121).
  - Refresh
    patches.suse/drm-Add-kabi-placeholders-to-commonly-used-structs.patch.
  - commit 8284f72
  - kABI: arm64: ftrace: Restore struct mod_arch_specific layout (git-fixes).
  - commit cb06f32
  - arm64: ftrace: fix unreachable PLT for ftrace_caller in init_module (git-fixes)
  - commit a64c583
  - arm64: dts: rockchip: Fix Bluetooth interrupts flag on Neardi LBA3368 (git-fixes)
  - commit 78938d3
  - arm64: dts: rockchip: Fix the headphone detection on the orangepi 5 (git-fixes)
  - commit ba5fe5b
  - arm64: dts: rockchip: Add vcc-supply to SPI flash on (git-fixes)
  - commit 8dd21d2
  - arm64: dts: rockchip: use cs-gpios for spi1 on ringneck (git-fixes)
  - commit 7fdd334
  - arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi 4B (git-fixes).
  - commit bc5a89e
  - arm64: dts: rockchip: disable unrouted USB controllers and PHY on (git-fixes)
  - commit 607b715
  - arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma (git-fixes)
  - commit d20c924
  - arm64: dts: imx8mp: Fix missing microSD slot vqmmc on Data Modul (git-fixes)
  - commit f84cc30
  - arm64: dts: imx8mp: Fix missing microSD slot vqmmc on DH electronics (git-fixes)
  - commit 627de8c
  - arm64: dts: imx8mp-tqma8mpql: fix LDO5 power off (git-fixes)
  - commit e690dcc
  - arm64: Mark kernel as tainted on SAE and SError panic (git-fixes)
  - commit 5a4a449
  - arm64: stacktrace: Check kretprobe_find_ret_addr() return value (git-fixes)
  - commit f7313d0
  - arm64: Handle KCOV __init vs inline mismatches (git-fixes)
  - commit 8a132f8
  - i2c: tegra: Use internal reset when reset property is not available (bsc#1249143)
  - commit 9c0b7e3
  - cpufreq: CPPC: Mark driver with NEED_UPDATE_LIMITS flag
    (stable-fixes).
  - commit fc53d59
  - cpufreq: Exit governor when failed to start old governor
    (stable-fixes).
  - commit e935313

------------------------------------------------------------------
------------------  2025-9-15  -  Sep 15 2025  -------------------
------------------------------------------------------------------

++++ avahi:

  - Add avahi-CVE-2024-52615.patch:
    Backport 4e2e1ea from upstream, Resolve fixed source ports for
    wide-area DNS queries cause DNS responses be injected.
    (CVE-2024-52615, bsc#1233421)

++++ gstreamer:

  - Update to version 1.26.6:
    + Highlighted bugfixes in 1.26.6:
  - analytics GstTensorMeta handling changes (see note below)
  - closed caption combiner and transcriberbin stability fixes
  - decklinkvideosrc: fix unrecoverable state after failing to
    start streaming because device is busy
  - decodebin3 tag handling improvements
  - fallbacksrc: Fix sources only being restarted once, as well
    as some deadlocks and race conditions on shutdown
  - gtk4paintablesink: Try importing dmabufs withouth DMA_DRM
    caps
  - hlsdemux2: Fix parsing of byterange and init map directives
  - rtpmp4gdepay2: allow only constantduration with neither
    constantsize nor sizelength set
  - spotifysrc: update to librespot 0.7 to make work after recent
    Spotify changes
  - threadshare: new blocking adapter element for use in front of
    block elements such as sinks that sync to the clock
  - threadshare: various other threadshare element fixes and
    improvements
  - v4l2: Add support for WVC1 and WMV3
  - videorate: possible performance improvements when operating
    in drop-only mode
  - GstBaseParse fixes
  - Vulkan video decoder fixes
  - Fix gst-device-monitor-1.0 tool device-path regression on
    Windows
  - Monorepo development environment builds fewer plugins using
    subprojects by default, those require explicit enablement now
  - Python bindings: Handle buffer PTS, DTS, duration, offset,
    and offset-end as unsigned long long (regression fix)
  - Cerbero: Reduce recipe parallelism in various cases and dump
    cerbero and recipe versions into datadir during packaging
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + Possibly breaking behavioural changes:
  - Previously it was guaranteed that there is only ever up to
    one GstTensorMeta per buffer. This is no longer true and code
    working with GstTensorMeta must be able to handle multiple
    GstTensorMeta now.
    + gstreamer:
  - baseparse: Try harder to fixate caps based on upstream in
    default negotiation
  - gst-discoverer reports 1x1 dimensions for "valid" MP4 files
  - baseparse: don't clear most sticky events after a FLUSH_STOP
    event
  - gstreamer: Disable miniobject inline functions for
    gobject-introspection for non-subprojects too
  - gstreamer: Make sure to zero-initialize the GValue before
    G_VALUE_COLLECT_INIT
  - ptp: Fix a new Rust 1.89 compiler warning on Windows
  - ptp: Fix new compiler warning with Rust 1.89
  - Segmentation fault when compiled with
    "-ftrivial-auto-var-init=pattern". Use of unitialized GValue

++++ gstreamer-plugins-base:

  - Update to version 1.26.6:
    + decodebin3: Update stream tags
    + rtpbasedepayload: Avoid potential use-after free
    + rtspconnection: Add get_url and get_ip return value annotation
    + gst_rtsp_connection_get_url return value transfer annotation
    missing
    + videometa: Fix valgrind warning when deserializing video meta
    + videorate: don't hold the reference to the buffer in drop-only
    mode
    + gst-device-monitor-1.0: Fix device-path regression on Windows
    + gst-device-monitor-1.0: Add quoting for powershell and cmd
    + Monorepo: opengl, vorbis, plugins require explicit enablement
    now for a build using the Meson subproject fallback

++++ kernel-default:

  - cpufreq: Init policy->rwsem before it may be possibly used
    (git-fixes).
  - commit fdf9d91
  - drm/amd/display: Disable DPCD Probe Quirk (bsc#1248121).
  - commit b441892
  - tls: fix handling of zero-length records on the rx_list
    (CVE-2025-39682 bsc#1249284).
  - commit dae1b00
  - drm/dp: Change AUX DPCD probe address from LANE0_1_STATUS to
    TRAINING_PATTERN_SET (bsc#1248121).
  - commit 05496be
  - Update patches.suse/drm-dp-Change-AUX-DPCD-probe-address-from-DPCD_REV-t.patch (bsc#1248121)
    Move to the cherry-picked 6.16-rc patch, to be applied earlier
  - commit c2137da
  - drm/edid: Add support for quirks visible to DRM core and drivers
    (bsc#1248121).
  - commit 3f7be89
  - drm/edid: Define the quirks in an enum list (bsc#1248121).
  - commit f72505b
  - netfilter: nf_tables: reject duplicate device on updates
    (CVE-2025-38678 bsc#1249126).
  - commit fa3b4ce
  - ptp: fix breakage after ptp_vclock_in_use() rework (git-fixes).
  - commit c4393a1
  - iommu/amd: Avoid stack buffer overflow from kernel cmdline
    (CVE-2025-38676 bsc#1248775).
  - commit b6650d7
  - phy: ti-pipe3: fix device leak at unbind (git-fixes).
  - phy: ti: omap-usb2: fix device leak at unbind (git-fixes).
  - phy: tegra: xusb: fix device and OF node leak at probe
    (git-fixes).
  - phy: qualcomm: phy-qcom-eusb2-repeater: fix override properties
    (git-fixes).
  - dmaengine: dw: dmamux: Fix device reference leak in
    rzn1_dmamux_route_allocate (git-fixes).
  - dmaengine: ti: edma: Fix memory allocation size for
    queue_priority_map (git-fixes).
  - dmaengine: idxd: Fix double free in idxd_setup_wqs()
    (git-fixes).
  - dmaengine: idxd: Fix refcount underflow on module unload
    (git-fixes).
  - dmaengine: idxd: Remove improper idxd_free (git-fixes).
  - dmaengine: qcom: bam_dma: Fix DT error handling for
    num-channels/ees (git-fixes).
  - serial: sc16is7xx: fix bug in flow control levels init
    (git-fixes).
  - usb: gadget: midi2: Fix MIDI2 IN EP max packet size (git-fixes).
  - usb: gadget: midi2: Fix missing UMP group attributes
    initialization (git-fixes).
  - usb: typec: tcpm: properly deliver cable vdms to altmode drivers
    (git-fixes).
  - USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels
    (git-fixes).
  - xhci: fix memory leak regression when freeing xhci vdev devices
    depth first (git-fixes).
  - xhci: dbc: Fix full DbC transfer ring after several reconnects
    (git-fixes).
  - xhci: dbc: decouple endpoint allocation from initialization
    (git-fixes).
  - commit 8847945

++++ kernel-rt:

  - cpufreq: Init policy->rwsem before it may be possibly used
    (git-fixes).
  - commit fdf9d91
  - drm/amd/display: Disable DPCD Probe Quirk (bsc#1248121).
  - commit b441892
  - tls: fix handling of zero-length records on the rx_list
    (CVE-2025-39682 bsc#1249284).
  - commit dae1b00
  - drm/dp: Change AUX DPCD probe address from LANE0_1_STATUS to
    TRAINING_PATTERN_SET (bsc#1248121).
  - commit 05496be
  - Update patches.suse/drm-dp-Change-AUX-DPCD-probe-address-from-DPCD_REV-t.patch (bsc#1248121)
    Move to the cherry-picked 6.16-rc patch, to be applied earlier
  - commit c2137da
  - drm/edid: Add support for quirks visible to DRM core and drivers
    (bsc#1248121).
  - commit 3f7be89
  - drm/edid: Define the quirks in an enum list (bsc#1248121).
  - commit f72505b
  - netfilter: nf_tables: reject duplicate device on updates
    (CVE-2025-38678 bsc#1249126).
  - commit fa3b4ce
  - ptp: fix breakage after ptp_vclock_in_use() rework (git-fixes).
  - commit c4393a1
  - iommu/amd: Avoid stack buffer overflow from kernel cmdline
    (CVE-2025-38676 bsc#1248775).
  - commit b6650d7
  - phy: ti-pipe3: fix device leak at unbind (git-fixes).
  - phy: ti: omap-usb2: fix device leak at unbind (git-fixes).
  - phy: tegra: xusb: fix device and OF node leak at probe
    (git-fixes).
  - phy: qualcomm: phy-qcom-eusb2-repeater: fix override properties
    (git-fixes).
  - dmaengine: dw: dmamux: Fix device reference leak in
    rzn1_dmamux_route_allocate (git-fixes).
  - dmaengine: ti: edma: Fix memory allocation size for
    queue_priority_map (git-fixes).
  - dmaengine: idxd: Fix double free in idxd_setup_wqs()
    (git-fixes).
  - dmaengine: idxd: Fix refcount underflow on module unload
    (git-fixes).
  - dmaengine: idxd: Remove improper idxd_free (git-fixes).
  - dmaengine: qcom: bam_dma: Fix DT error handling for
    num-channels/ees (git-fixes).
  - serial: sc16is7xx: fix bug in flow control levels init
    (git-fixes).
  - usb: gadget: midi2: Fix MIDI2 IN EP max packet size (git-fixes).
  - usb: gadget: midi2: Fix missing UMP group attributes
    initialization (git-fixes).
  - usb: typec: tcpm: properly deliver cable vdms to altmode drivers
    (git-fixes).
  - USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels
    (git-fixes).
  - xhci: fix memory leak regression when freeing xhci vdev devices
    depth first (git-fixes).
  - xhci: dbc: Fix full DbC transfer ring after several reconnects
    (git-fixes).
  - xhci: dbc: decouple endpoint allocation from initialization
    (git-fixes).
  - commit 8847945

------------------------------------------------------------------
------------------  2025-9-14  -  Sep 14 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - regulator: sy7636a: fix lifecycle of power good gpio
    (git-fixes).
  - commit 3cf2f7b

++++ kernel-rt:

  - regulator: sy7636a: fix lifecycle of power good gpio
    (git-fixes).
  - commit 3cf2f7b

------------------------------------------------------------------
------------------  2025-9-13  -  Sep 13 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - struct cdc_ncm_ctx: move new member to end (git-fixes).
  - commit 0696383
  - drm/xe: Attempt to bring bos back to VRAM after eviction
    (git-fixes).
  - drm/panthor: validate group queue count (git-fixes).
  - drm/mediatek: fix potential OF node use-after-free (git-fixes).
  - drm/amd/display: use udelay rather than fsleep (git-fixes).
  - drm/amdgpu: fix a memory leak in fence cleanup when unloading
    (git-fixes).
  - drm/i915/power: fix size for for_each_set_bit() in abox
    iteration (git-fixes).
  - commit 28aeb21
  - net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new
    compositions (git-fixes).
  - commit d37f2a9
  - net: usb: cdc-ncm: check for filtering capability (git-fixes).
  - commit 024c467

++++ kernel-rt:

  - struct cdc_ncm_ctx: move new member to end (git-fixes).
  - commit 0696383
  - drm/xe: Attempt to bring bos back to VRAM after eviction
    (git-fixes).
  - drm/panthor: validate group queue count (git-fixes).
  - drm/mediatek: fix potential OF node use-after-free (git-fixes).
  - drm/amd/display: use udelay rather than fsleep (git-fixes).
  - drm/amdgpu: fix a memory leak in fence cleanup when unloading
    (git-fixes).
  - drm/i915/power: fix size for for_each_set_bit() in abox
    iteration (git-fixes).
  - commit 28aeb21
  - net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new
    compositions (git-fixes).
  - commit d37f2a9
  - net: usb: cdc-ncm: check for filtering capability (git-fixes).
  - commit 024c467

------------------------------------------------------------------
------------------  2025-9-12  -  Sep 12 2025  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Update to version 2.0.16:
    + This release adds the following features:
  - Add a 'search' feature to fwupdtool and fwupdmgr
    + This release fixes the following bugs:
  - Fix missing release locations when loading from artifact
  - Fix remaining issues to make updates on FreeBSD work

++++ kernel-default:

  - Update config files: Disable UBLK (PED-13686)
  - commit 32a5a8b
  - Refresh
    patches.suse/sched-Don-t-define-sched_clock_irqtime-as-static-key.patch.
  - commit ccab819
  - iommu/vt-d: Restore context entry setup order for aliased
    devices (CVE-2025-38216 bsc#1245963).
  - commit 9397573
  - pidfs: Fix memory leak in pidfd_info() (jsc#PED-13113).
  - pidfs: raise SB_I_NODEV and SB_I_NOEXEC (bsc#1249562).
  - commit 7f76e12
  - cgroup/cpuset: Fix a partition error with CPU hotplug
    (bsc#1241166).
  - cgroup/cpuset: Use static_branch_enable_cpuslocked() on
    cpusets_insane_config_key (bsc#1241166).
  - commit 403a981
  - sched/deadline: Don't count nr_running for dl_server proxy tasks (git-fixes, bsc#1247936).
  - sched/deadline: Fix RT task potential starvation when expiry
    time passed (git-fixes, bsc#1247936).
  - sched/deadline: Always stop dl-server before changing parameters
    (bsc#1247936).
  - sched/deadline: Fix dl_server_stopped() (bsc#1247936).
  - commit ef2b61d
  - Limit patch filenames to 100 characters (bsc#1249604).
  - commit 6aa47a1
  - cpufreq: Initialize cpufreq-based frequency-invariance later
    (git-fixes).
  - commit 4cd57b7
  - s390/cpum_cf: Deny all sampling events by counter PMU (git-fixes
    bsc#1249477).
  - s390/pai: Deny all events not handled by this PMU (git-fixes
    bsc#1249478).
  - commit 9debf1a
  - mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing
    (git-fixes).
  - mtd: rawnand: stm32_fmc2: fix ECC overwrite (git-fixes).
  - mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC
    buffer (git-fixes).
  - can: xilinx_can: xcan_write_frame(): fix use-after-free of
    transmitted SKB (git-fixes).
  - can: j1939: j1939_local_ecu_get(): undo increment when
    j1939_local_ecu_get() fails (git-fixes).
  - can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately
    when j1939_local_ecu_get() failed (git-fixes).
  - can: j1939: implement NETDEV_UNREGISTER notification handler
    (git-fixes).
  - cpufreq/amd-pstate: Fix a regression leading to EPP 0 after
    resume (git-fixes).
  - cpufreq/amd-pstate: Fix setting of CPPC.min_perf in active
    mode for performance governor (git-fixes).
  - commit f4059fc

++++ kernel-firmware-amdgpu:

  - Update to version 20250912 (git commit 46730bc6b999):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-rt:

  - Update config files: Disable UBLK (PED-13686)
  - commit 32a5a8b
  - Refresh
    patches.suse/sched-Don-t-define-sched_clock_irqtime-as-static-key.patch.
  - commit ccab819
  - iommu/vt-d: Restore context entry setup order for aliased
    devices (CVE-2025-38216 bsc#1245963).
  - commit 9397573
  - pidfs: Fix memory leak in pidfd_info() (jsc#PED-13113).
  - pidfs: raise SB_I_NODEV and SB_I_NOEXEC (bsc#1249562).
  - commit 7f76e12
  - cgroup/cpuset: Fix a partition error with CPU hotplug
    (bsc#1241166).
  - cgroup/cpuset: Use static_branch_enable_cpuslocked() on
    cpusets_insane_config_key (bsc#1241166).
  - commit 403a981
  - sched/deadline: Don't count nr_running for dl_server proxy tasks (git-fixes, bsc#1247936).
  - sched/deadline: Fix RT task potential starvation when expiry
    time passed (git-fixes, bsc#1247936).
  - sched/deadline: Always stop dl-server before changing parameters
    (bsc#1247936).
  - sched/deadline: Fix dl_server_stopped() (bsc#1247936).
  - commit ef2b61d
  - Limit patch filenames to 100 characters (bsc#1249604).
  - commit 6aa47a1
  - cpufreq: Initialize cpufreq-based frequency-invariance later
    (git-fixes).
  - commit 4cd57b7
  - s390/cpum_cf: Deny all sampling events by counter PMU (git-fixes
    bsc#1249477).
  - s390/pai: Deny all events not handled by this PMU (git-fixes
    bsc#1249478).
  - commit 9debf1a
  - mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing
    (git-fixes).
  - mtd: rawnand: stm32_fmc2: fix ECC overwrite (git-fixes).
  - mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC
    buffer (git-fixes).
  - can: xilinx_can: xcan_write_frame(): fix use-after-free of
    transmitted SKB (git-fixes).
  - can: j1939: j1939_local_ecu_get(): undo increment when
    j1939_local_ecu_get() fails (git-fixes).
  - can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately
    when j1939_local_ecu_get() failed (git-fixes).
  - can: j1939: implement NETDEV_UNREGISTER notification handler
    (git-fixes).
  - cpufreq/amd-pstate: Fix a regression leading to EPP 0 after
    resume (git-fixes).
  - cpufreq/amd-pstate: Fix setting of CPPC.min_perf in active
    mode for performance governor (git-fixes).
  - commit f4059fc

++++ opensuse-migration-tool:

  - Update to version 20250815.344dba5:
    * Keep only Experimental in the title
    * Install custom dialogrc with a green theme

------------------------------------------------------------------
------------------  2025-9-11  -  Sep 11 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Update to 339
    * 339
  - Serial consoles now keep their content and stay alive
  - No longer copies qemu.conf values into VM definitions
    * 338
  - Translation and dependency updates
  - Detachable VNC console
  - removed nic-domain-not-found.patch that is now part of upstream

++++ python-kiwi:

  - Bump version: 10.2.32 → 10.2.33

++++ kernel-default:

  - s390/mm: Fix in_atomic() handling in do_secure_storage_access()
    (git-fixes CVE-2025-38359 bsc#1247076).
  - commit ad2ef8d
  - cpufreq: intel_pstate: Add Granite Rapids support in no-HWP mode
    (stable-fixes).
  - commit 688ba83
  - cpufreq: intel_pstate: Always use HWP_DESIRED_PERF in passive
    mode (git-fixes).
  - commit 93b10c9
  - cpufreq: scmi: Skip SCMI devices that aren't used by the CPUs
    (stable-fixes).
  - commit 8228e62
  - pptp: ensure minimal skb length in pptp_xmit() (CVE-2025-38574
    bsc#1248365).
  - commit 5a47a7a
  - cpufreq: intel_pstate: Unchecked MSR aceess in legacy mode
    (git-fixes).
  - commit 8c79560
  - io_uring: expose read/write attribute capability (jsc#PED-12882 bsc#1237542).
  - io_uring/rw: don't mask in f_iocb_flags (jsc#PED-12882 bsc#1237542).
    Drop blacklisting.
  - commit c90a02f

++++ kernel-firmware-mediatek:

  - Update to version 20250909 (git commit 4573c02ca0ca):
    * mediatek MT7922: update bluetooth firmware to 20250903123504
    * linux-firmware: update firmware for MT7922 WiFi device

++++ kernel-rt:

  - s390/mm: Fix in_atomic() handling in do_secure_storage_access()
    (git-fixes CVE-2025-38359 bsc#1247076).
  - commit ad2ef8d
  - cpufreq: intel_pstate: Add Granite Rapids support in no-HWP mode
    (stable-fixes).
  - commit 688ba83
  - cpufreq: intel_pstate: Always use HWP_DESIRED_PERF in passive
    mode (git-fixes).
  - commit 93b10c9
  - cpufreq: scmi: Skip SCMI devices that aren't used by the CPUs
    (stable-fixes).
  - commit 8228e62
  - pptp: ensure minimal skb length in pptp_xmit() (CVE-2025-38574
    bsc#1248365).
  - commit 5a47a7a
  - cpufreq: intel_pstate: Unchecked MSR aceess in legacy mode
    (git-fixes).
  - commit 8c79560
  - io_uring: expose read/write attribute capability (jsc#PED-12882 bsc#1237542).
  - io_uring/rw: don't mask in f_iocb_flags (jsc#PED-12882 bsc#1237542).
    Drop blacklisting.
  - commit c90a02f

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#193
  - adjust test cases
  - 1.26
  - merge gh#openSUSE/perl-bootloader#192
  - Implement config for BLS (boo#1246013)

++++ virt-manager:

  - Fix issues with detection of openSUSE Leap 16.
    virtinst-add-sle16-detection-support.patch

------------------------------------------------------------------
------------------  2025-9-10  -  Sep 10 2025  -------------------
------------------------------------------------------------------

++++ curl:

  - tool_operate: fix return code when --retry is used but not
    triggered [bsc#1249367]
    * Add curl-tool_operate-fix-return-code-when-retry-is-used.patch

++++ python-kiwi:

  - Run grub mkconfig with os-prober disabled
    Set GRUB_DISABLE_OS_PROBER=true to the caller environment
    such that it gets consumed via /etc/grub.d/30_os-prober
    This Fixes #2883
  - Fixed typo in documentation
    Invalid XML syntax, missing end tag. This Fixes #2882

++++ fwupd:

  - Update to version 2.0.15:
    + This release adds the following features:
  - Allow child devices to use the parent name as a prefix
    + This release fixes the following bugs:
  - Add newer commands and options for Fish completion
  - Allow installing archives named as .CAB rather than .cab
  - Erase Firehose modem devices correctly
  - Fix Goodix enumeration issues
  - Fix sending firmware reports without --force
  - Fix the FreeBSD build
  - Fix version number of BnR MTD devices
  - Require additional requirements for the default PS5512 devboard
  - Require a full system shutdown for all Micron NVMe updates
  - Use a better name for Elan touchpad and Intel PCH SPI devices
    + This release adds support for the following hardware:
  - Foxconn SDX61 Modem
  - Jabra Evolve2 child devices
  - NVIDIA ConnectX-6, ConnectX-7 and ConnectX-8 NICs

++++ kernel-default:

  - smb: client: fix use-after-free in cifs_oplock_break
    (bsc#1248199, CVE-2025-38527).
  - commit a3059e7
  - Drop PCI patches that broke kdump capture boot (bsc#1246509)
    Deleted:
    patches.suse/PCI-Explicitly-put-devices-into-D0-when-initializing.patch
    patches.suse/PCI-PM-Set-up-runtime-PM-even-for-devices-without-PC.patch
    Refreshed:
    patches.suse/PCI-Support-Immediate-Readiness-on-devices-without-PM.patch
  - commit b491bf9
  - platform/x86/amd/pmc: Add TUXEDO IB Pro Gen10 AMD to spurious
    8042 quirks list (stable-fixes).
  - drm/amd/display: Clear the CUR_ENABLE register on DCN314 w/out
    DPP PG (stable-fixes).
  - drm/amdgpu: drop hw access in non-DC audio fini (stable-fixes).
  - ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4
    model (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic for TongFang X6[AF]R5xxY
    (stable-fixes).
  - ALSA: usb-audio: Add mute TLV for playback volumes on some
    devices (stable-fixes).
  - mmc: sdhci-of-arasan: Ensure CD logic stabilization before
    power-up (stable-fixes).
  - cpupower: Fix a bug where the -t option of the set subcommand
    was not working (stable-fixes).
  - cdc_ncm: Flag Intel OEM version of Fibocom L850-GL as WWAN
    (stable-fixes).
  - Bluetooth: hci_sync: Avoid adding default advertising on startup
    (stable-fixes).
  - net: usb: qmi_wwan: add Telit Cinterion FN990A w/audio
    composition (stable-fixes).
  - dmaengine: mediatek: Fix a flag reuse error in
    mtk_cqdma_tx_status() (git-fixes).
  - net: usb: qmi_wwan: fix Telit Cinterion FE990A name
    (stable-fixes).
  - net: usb: qmi_wwan: fix Telit Cinterion FN990A name
    (stable-fixes).
  - mmc: sdhci-of-arasan: Support for emmc hardware reset
    (stable-fixes).
  - commit 67865ae

++++ kernel-rt:

  - smb: client: fix use-after-free in cifs_oplock_break
    (bsc#1248199, CVE-2025-38527).
  - commit a3059e7
  - Drop PCI patches that broke kdump capture boot (bsc#1246509)
    Deleted:
    patches.suse/PCI-Explicitly-put-devices-into-D0-when-initializing.patch
    patches.suse/PCI-PM-Set-up-runtime-PM-even-for-devices-without-PC.patch
    Refreshed:
    patches.suse/PCI-Support-Immediate-Readiness-on-devices-without-PM.patch
  - commit b491bf9
  - platform/x86/amd/pmc: Add TUXEDO IB Pro Gen10 AMD to spurious
    8042 quirks list (stable-fixes).
  - drm/amd/display: Clear the CUR_ENABLE register on DCN314 w/out
    DPP PG (stable-fixes).
  - drm/amdgpu: drop hw access in non-DC audio fini (stable-fixes).
  - ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4
    model (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic for TongFang X6[AF]R5xxY
    (stable-fixes).
  - ALSA: usb-audio: Add mute TLV for playback volumes on some
    devices (stable-fixes).
  - mmc: sdhci-of-arasan: Ensure CD logic stabilization before
    power-up (stable-fixes).
  - cpupower: Fix a bug where the -t option of the set subcommand
    was not working (stable-fixes).
  - cdc_ncm: Flag Intel OEM version of Fibocom L850-GL as WWAN
    (stable-fixes).
  - Bluetooth: hci_sync: Avoid adding default advertising on startup
    (stable-fixes).
  - net: usb: qmi_wwan: add Telit Cinterion FN990A w/audio
    composition (stable-fixes).
  - dmaengine: mediatek: Fix a flag reuse error in
    mtk_cqdma_tx_status() (git-fixes).
  - net: usb: qmi_wwan: fix Telit Cinterion FE990A name
    (stable-fixes).
  - net: usb: qmi_wwan: fix Telit Cinterion FN990A name
    (stable-fixes).
  - mmc: sdhci-of-arasan: Support for emmc hardware reset
    (stable-fixes).
  - commit 67865ae

++++ osinfo-db:

  - Fix the definition of Leap 16.0 to match the current names of the
    Leap 16.0 ISOs and the Volume IDs contained within those ISOs.
    (bsc#1236401)
    add-opensuse-leap-16.0-support.patch

------------------------------------------------------------------
------------------  2025-9-9  -  Sep 9 2025  -------------------
------------------------------------------------------------------

++++ cockpit-podman:

  - Update to 113
    * Sortable Images table

++++ curl:

  - Security fixes:
    * [bsc#1249191, CVE-2025-9086] Out of bounds read for cookie path
    * [bsc#1249348, CVE-2025-10148] Predictable WebSocket mask
    * Add patches:
  - curl-CVE-2025-9086.patch
  - curl-CVE-2025-10148.patch

++++ kernel-default:

  - cpufreq: cppc: Fix invalid return value in .get() callback
    (git-fixes).
  - commit 0113318
  - cpufreq: Reference count policy in cpufreq_update_limits()
    (git-fixes).
  - commit fc0d863
  - cpufreq: governor: Fix negative 'idle_time' handling in
    dbs_update() (git-fixes).
  - commit 5082177
  - cpufreq: scpi: compare kHz instead of Hz (git-fixes).
  - commit f23b3de
  - kernel-subpackage-build: Decompress ghost file when compressed version exists (bsc#1249346)
  - commit 40606b5
  - PCI: pnv_php: Fix surprise plug detection and recovery
    (CVE-2025-38623 bsc#1248610).
  - commit a87ddcb
  - selftests/bpf: Add test cases with CONST_PTR_TO_MAP null checks
    (git-fixes).
  - selftests/bpf: Add cmp_map_pointer_with_const test (git-fixes).
  - bpf: Make reg_not_null() true for CONST_PTR_TO_MAP (git-fixes).
  - commit 07f73b3
  - supported.conf: mark hyperv_drm as external
  - net: hv_netvsc: fix loss of early receive events from host
    during channel open (git-fixes).
  - hv_netvsc: Fix panic during namespace deletion with VF
    (bsc#1248111).
  - RDMA/mana_ib: add support of multiple ports (git-fixes).
  - RDMA/mana_ib: add additional port counters (git-fixes).
  - net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes).
  - commit 27fd758
  - drm/rockchip: vop2: fail cleanly if missing a primary plane
    for a video-port (CVE-2025-38597 bsc#1248378).
  - commit 3361c8b
  - bpf: Disable migration in nf_hook_run_bpf() (bsc#1248622
    CVE-2025-38640).
  - commit ea00555
  - btrfs: codify pattern for adding block_group to bg_list
    (git-fixes).
  - commit 28d12b0

++++ kernel-rt:

  - cpufreq: cppc: Fix invalid return value in .get() callback
    (git-fixes).
  - commit 0113318
  - cpufreq: Reference count policy in cpufreq_update_limits()
    (git-fixes).
  - commit fc0d863
  - cpufreq: governor: Fix negative 'idle_time' handling in
    dbs_update() (git-fixes).
  - commit 5082177
  - cpufreq: scpi: compare kHz instead of Hz (git-fixes).
  - commit f23b3de
  - kernel-subpackage-build: Decompress ghost file when compressed version exists (bsc#1249346)
  - commit 40606b5
  - PCI: pnv_php: Fix surprise plug detection and recovery
    (CVE-2025-38623 bsc#1248610).
  - commit a87ddcb
  - selftests/bpf: Add test cases with CONST_PTR_TO_MAP null checks
    (git-fixes).
  - selftests/bpf: Add cmp_map_pointer_with_const test (git-fixes).
  - bpf: Make reg_not_null() true for CONST_PTR_TO_MAP (git-fixes).
  - commit 07f73b3
  - supported.conf: mark hyperv_drm as external
  - net: hv_netvsc: fix loss of early receive events from host
    during channel open (git-fixes).
  - hv_netvsc: Fix panic during namespace deletion with VF
    (bsc#1248111).
  - RDMA/mana_ib: add support of multiple ports (git-fixes).
  - RDMA/mana_ib: add additional port counters (git-fixes).
  - net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes).
  - commit 27fd758
  - drm/rockchip: vop2: fail cleanly if missing a primary plane
    for a video-port (CVE-2025-38597 bsc#1248378).
  - commit 3361c8b
  - bpf: Disable migration in nf_hook_run_bpf() (bsc#1248622
    CVE-2025-38640).
  - commit ea00555
  - btrfs: codify pattern for adding block_group to bg_list
    (git-fixes).
  - commit 28d12b0

++++ python313-core:

  - Add gh138131-exclude-pycache-from-digest.patch fixing reproducible
    build for python-nogil.
    (bsc#1244680, gh#python/cpython#138131)

++++ libssh:

  - Update to 0.11.3
    * Security:
    * CVE-2025-8114: Fix NULL pointer dereference after allocation failure (bsc#1246974)
    * CVE-2025-8277: Fix memory leak of ephemeral key pair during repeated wrong KEX (bsc#1249375)
    * Potential UAF when send() fails during key exchange
    * Bugfixes:
    * Fix possible timeout during KEX if client sends authentication too early
    * Cleanup OpenSSL PKCS#11 provider when loaded
    * Zeroize buffers containing private key blobs during export

++++ liburing:

  - Add upstream patch to fix test on ppc64le
    * 0001-test-recvsend_bundle-enlarge-recv-buf-ring-to-2-MiB-.patch

++++ python313:

  - Add gh138131-exclude-pycache-from-digest.patch fixing reproducible
    build for python-nogil.
    (bsc#1244680, gh#python/cpython#138131)

------------------------------------------------------------------
------------------  2025-9-8  -  Sep 8 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update to 346
    * Changes since 344
  - 346
    * Support branding Cockpit pages
    * Storage: Support for Stratis "V2" pools
  - 345
    * Translation and dependency updates
    * Shorter IPv6 addresses
    * IPv6 addresses for WireGuard

++++ kernel-default:

  - isolcpus: add missing hunk back (bsc#1236897 bsc#1249206).
    Update
    patches.suse/blk-mq-use-hk-cpus-only-when-isolcpus-managed_irq-is-enabled.patch
    (bsc#1236897 bsc#1249206).
  - commit 9d2b796
  - btrfs: fix printing of mount info messages for
    NODATACOW/NODATASUM (git-fixes).
  - commit ba5bcd7
  - btrfs: restore mount option info messages during mount
    (git-fixes).
  - commit 802999a
  - btrfs: fix incorrect log message for nobarrier mount option
    (git-fixes).
  - commit e3e34d3
  - btrfs: avoid load/store tearing races when checking if an
    inode was logged (git-fixes).
  - commit 05dbe91
  - btrfs: fix race between setting last_dir_index_offset and
    inode logging (git-fixes).
  - commit 87677ec
  - btrfs: fix race between logging inode and checking if it was
    logged before (git-fixes).
  - commit dd428a8
  - btrfs: always abort transaction on failure to add block group
    to free space tree (git-fixes).
  - btrfs: move transaction aborts to the error site in
    add_block_group_free_space() (git-fixes).
  - commit 66017bd
  - netfilter: xt_nfacct: don't assume acct name is null-terminated (CVE-2025-38639 bsc#1248674)
  - commit 6246696
  - btrfs: abort transaction on unexpected eb generation at
    btrfs_copy_root() (git-fixes).
  - commit 7a86e25
  - btrfs: qgroup: remove no longer used fs_info->qgroup_ulist
    (git-fixes).
  - btrfs: qgroup: fix race between quota disable and quota rescan
    ioctl (git-fixes).
  - commit cbd92f9
  - x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and
    arch_sync_kernel_mappings() (git-fixes).
  - commit 1ff0ea2
  - mm: introduce and use {pgd,p4d}_populate_kernel() (git-fixes).
  - commit 98f7021
  - mm: move page table sync declarations to linux/pgtable.h
    (git-fixes).
  - commit 57bad67
  - mm/damon/core: prevent unnecessary overflow in
    damos_set_effective_quota() (git-fixes).
  - commit 760f69c
  - mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE
    (git-fixes).
  - commit a1213be
  - mm/damon/ops-common: ignore migration request to invalid nodes
    (git-fixes).
  - commit 0aae268
  - mm: swap: fix potential buffer overflow in setup_clusters()
    (git-fixes).
  - commit ba72e08
  - PCI: pnv_php: Fix surprise plug detection and recovery
    (CVE-2025-38623 bsc#1248610).
  - commit 72424b3
  - kABI workaround for bluetooth discovery_state change
    (CVE-2025-38593 bsc#1248357).
  - commit 12620c5
  - Bluetooth: hci_sync: fix double free in
    'hci_discovery_filter_clear()' (CVE-2025-38593 bsc#1248357).
  - Refresh patches.kabi/bluetooth-hci_dev-kabi-workaround.patch.
  - commit 1bb3148
  - Fix OOB access in "drm/amdgpu: read back register after written for VCN v4.0.5" (bsc#1249251)
  - commit 3545bbd

++++ kernel-rt:

  - isolcpus: add missing hunk back (bsc#1236897 bsc#1249206).
    Update
    patches.suse/blk-mq-use-hk-cpus-only-when-isolcpus-managed_irq-is-enabled.patch
    (bsc#1236897 bsc#1249206).
  - commit 9d2b796
  - btrfs: fix printing of mount info messages for
    NODATACOW/NODATASUM (git-fixes).
  - commit ba5bcd7
  - btrfs: restore mount option info messages during mount
    (git-fixes).
  - commit 802999a
  - btrfs: fix incorrect log message for nobarrier mount option
    (git-fixes).
  - commit e3e34d3
  - btrfs: avoid load/store tearing races when checking if an
    inode was logged (git-fixes).
  - commit 05dbe91
  - btrfs: fix race between setting last_dir_index_offset and
    inode logging (git-fixes).
  - commit 87677ec
  - btrfs: fix race between logging inode and checking if it was
    logged before (git-fixes).
  - commit dd428a8
  - btrfs: always abort transaction on failure to add block group
    to free space tree (git-fixes).
  - btrfs: move transaction aborts to the error site in
    add_block_group_free_space() (git-fixes).
  - commit 66017bd
  - netfilter: xt_nfacct: don't assume acct name is null-terminated (CVE-2025-38639 bsc#1248674)
  - commit 6246696
  - btrfs: abort transaction on unexpected eb generation at
    btrfs_copy_root() (git-fixes).
  - commit 7a86e25
  - btrfs: qgroup: remove no longer used fs_info->qgroup_ulist
    (git-fixes).
  - btrfs: qgroup: fix race between quota disable and quota rescan
    ioctl (git-fixes).
  - commit cbd92f9
  - x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and
    arch_sync_kernel_mappings() (git-fixes).
  - commit 1ff0ea2
  - mm: introduce and use {pgd,p4d}_populate_kernel() (git-fixes).
  - commit 98f7021
  - mm: move page table sync declarations to linux/pgtable.h
    (git-fixes).
  - commit 57bad67
  - mm/damon/core: prevent unnecessary overflow in
    damos_set_effective_quota() (git-fixes).
  - commit 760f69c
  - mm/userfaultfd: fix kmap_local LIFO ordering for CONFIG_HIGHPTE
    (git-fixes).
  - commit a1213be
  - mm/damon/ops-common: ignore migration request to invalid nodes
    (git-fixes).
  - commit 0aae268
  - mm: swap: fix potential buffer overflow in setup_clusters()
    (git-fixes).
  - commit ba72e08
  - PCI: pnv_php: Fix surprise plug detection and recovery
    (CVE-2025-38623 bsc#1248610).
  - commit 72424b3
  - kABI workaround for bluetooth discovery_state change
    (CVE-2025-38593 bsc#1248357).
  - commit 12620c5
  - Bluetooth: hci_sync: fix double free in
    'hci_discovery_filter_clear()' (CVE-2025-38593 bsc#1248357).
  - Refresh patches.kabi/bluetooth-hci_dev-kabi-workaround.patch.
  - commit 1bb3148
  - Fix OOB access in "drm/amdgpu: read back register after written for VCN v4.0.5" (bsc#1249251)
  - commit 3545bbd

++++ tiff:

  - security update:
    * CVE-2025-8961 [bsc#1248117]
    Fix segmentation fault via main function of tiffcrop utility
    + tiff-CVE-2025-8961.patch

++++ net-tools:

  - Drop 0002-Do-not-warn-about-interface-socket-not-binded.patch. It
    worked around a net-tools-1.60 specific problem, that does not
    happen in net-tools-2.10. It is more harmful than useful, as it
    can hide real problems. (bsc#430864#c15,
    https://github.com/ecki/net-tools/issues/32#issuecomment-3265471116).

++++ nvidia-open-driver-G06-signed:

  - let conflict CUDA and non-CUDA -devel packages; this is needed
    if both have the same version

------------------------------------------------------------------
------------------  2025-9-7  -  Sep 7 2025  -------------------
------------------------------------------------------------------

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 580.82.07 (boo#1249235)

------------------------------------------------------------------
------------------  2025-9-6  -  Sep 6 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - spi: spi-fsl-lpspi: Clear status register after disabling the
    module (git-fixes).
  - spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer
    abort (git-fixes).
  - spi: spi-fsl-lpspi: Set correct chip-select polarity bit
    (git-fixes).
  - spi: spi-fsl-lpspi: Fix transmissions when using CONT
    (git-fixes).
  - ACPI/IORT: Fix memory leak in iort_rmr_alloc_sids() (git-fixes).
  - hwmon: mlxreg-fan: Prevent fans from getting stuck at 0 RPM
    (git-fixes).
  - platform/x86/intel: power-domains: Use
    topology_logical_package_id() for package ID (git-fixes).
  - platform/x86: asus-wmi: Remove extra keys from ignore_key_wlan
    quirk (git-fixes).
  - drm/amd/amdgpu: Fix missing error return on kzalloc failure
    (git-fixes).
  - drm/bridge: ti-sn65dsi86: fix REFCLK setting (git-fixes).
  - accel/ivpu: Prevent recovery work from being queued during
    device removal (git-fixes).
  - nouveau: fix disabling the nonstall irq due to storm code
    (git-fixes).
  - commit 10f191d

++++ kernel-rt:

  - spi: spi-fsl-lpspi: Clear status register after disabling the
    module (git-fixes).
  - spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer
    abort (git-fixes).
  - spi: spi-fsl-lpspi: Set correct chip-select polarity bit
    (git-fixes).
  - spi: spi-fsl-lpspi: Fix transmissions when using CONT
    (git-fixes).
  - ACPI/IORT: Fix memory leak in iort_rmr_alloc_sids() (git-fixes).
  - hwmon: mlxreg-fan: Prevent fans from getting stuck at 0 RPM
    (git-fixes).
  - platform/x86/intel: power-domains: Use
    topology_logical_package_id() for package ID (git-fixes).
  - platform/x86: asus-wmi: Remove extra keys from ignore_key_wlan
    quirk (git-fixes).
  - drm/amd/amdgpu: Fix missing error return on kzalloc failure
    (git-fixes).
  - drm/bridge: ti-sn65dsi86: fix REFCLK setting (git-fixes).
  - accel/ivpu: Prevent recovery work from being queued during
    device removal (git-fixes).
  - nouveau: fix disabling the nonstall irq due to storm code
    (git-fixes).
  - commit 10f191d

++++ net-tools:

  - Drop 0004-By-default-do-not-fopen-anything-in-netrom_gr.patch. It
    was net-tools-1.60 specific leak fix and breaks netrom in
    net-tools-2.10 (bnc#544339#c2).

++++ nvidia-open-driver-G06-signed:

  - update CUDA variant to 580.82.07

------------------------------------------------------------------
------------------  2025-9-5  -  Sep 5 2025  -------------------
------------------------------------------------------------------

++++ chrony:

  - Update to version 4.8:
    * Add maxunreach option to limit selection of unreachable sources
    * Add -u option to chronyc to drop root privileges (default
    chronyc user is set by configure script)
    * Fix refclock extpps option to work on Linux >= 6.15
    * Validate refclock samples for reachability updates
    * Obsoletes chrony-unix-socket.patch
    * Obsoletes chrony-remove-chmod.patch

++++ kernel-default:

  - erofs: fix atomic context detection when
    !CONFIG_DEBUG_LOCK_ALLOC (git-fixes).
  - commit 672e366
  - net: drop UFO packets in udp_rcv_segment() (CVE-2025-38622
    bsc#1248619).
  - commit 48c98b8
  - smb: client: fix use-after-free in crypt_message when using
    async crypto (bsc#1247239, CVE-2025-38488).
  - commit 09784fa
  - wifi: mt76: mt7925: fix the wrong bss cleanup for SAP
    (git-fixes).
  - commit aed2258
  - ax25: properly unshare skbs in ax25_kiss_rcv() (git-fixes).
  - wifi: ath11k: fix group data packet drops during rekey
    (git-fixes).
  - wifi: cfg80211: sme: cap SSID length in
    __cfg80211_connect_result() (git-fixes).
  - wifi: libertas: cap SSID len in lbs_associate() (git-fixes).
  - wifi: cw1200: cap SSID length in cw1200_do_join() (git-fixes).
  - batman-adv: fix OOB read/write in network-coding decode
    (git-fixes).
  - Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
    (git-fixes).
  - Bluetooth: vhci: Prevent use-after-free by removing debugfs
    files early (git-fixes).
  - microchip: lan865x: Fix LAN8651 autoloading (git-fixes).
  - microchip: lan865x: Fix module autoloading (git-fixes).
  - mISDN: Fix memory leak in dsp_hwec_enable() (git-fixes).
  - xirc2ps_cs: fix register access when enabling FullDuplex
    (git-fixes).
  - wifi: iwlwifi: uefi: check DSM item validity (git-fixes).
  - wifi: mt76: fix linked list corruption (git-fixes).
  - wifi: mt76: free pending offchannel tx frames on wcid cleanup
    (git-fixes).
  - wifi: mt76: prevent non-offchannel mgmt tx during scan/roc
    (git-fixes).
  - wifi: mt76: mt7925u: use connac3 tx aggr check in tx complete
    (git-fixes).
  - wifi: mt76: mt7925: fix locking in mt7925_change_vif_links()
    (git-fixes).
  - wifi: mt76: mt7996: Initialize hdr before passing to
    skb_put_data() (git-fixes).
  - wifi: mwifiex: Initialize the chan_stats array to zero
    (git-fixes).
  - wifi: brcmfmac: fix use-after-free when rescheduling
    brcmf_btcoex_info work (git-fixes).
  - wifi: cfg80211: fix use-after-free in cmp_bss() (git-fixes).
  - HID: quirks: add support for Legion Go dual dinput modes
    (stable-fixes).
  - HID: logitech: Add ids for G PRO 2 LIGHTSPEED (stable-fixes).
  - HID: input: report battery status changes immediately
    (git-fixes).
  - HID: input: rename hidinput_set_battery_charge_status()
    (stable-fixes).
  - HID: hid-ntrig: fix unable to handle page fault in
    ntrig_report_version() (stable-fixes).
  - HID: wacom: Add a new Art Pen 2 (stable-fixes).
  - drm/amd/amdgpu: disable hwmon power1_cap* for gfx 11.0.3 on
    vf mode (stable-fixes).
  - Revert "drm/amdgpu: fix incorrect vm flags to map bo"
    (stable-fixes).
  - net: rose: fix a typo in rose_clear_routes() (git-fixes).
  - net: rose: include node references in rose_neigh refcount
    (git-fixes).
  - net: rose: convert 'use' field to refcount_t (git-fixes).
  - net: rose: split remove and free operations in
    rose_remove_neigh() (stable-fixes).
  - mISDN: hfcpci: Fix warning when deleting uninitialized timer
    (git-fixes).
  - dma/pool: Ensure DMA_DIRECT_REMAP allocations are decrypted
    (stable-fixes).
  - ASoC: codecs: tx-macro: correct tx_macro_component_drv name
    (stable-fixes).
  - PCI: dwc: Ensure that dw_pcie_wait_for_link() waits 100 ms
    after link up (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Add mt7988 lvts commands
    (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Add lvts commands and
    their sizes to driver data (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Change lvts commands
    array to static const (stable-fixes).
  - ACPI: EC: Add device to acpi_ec_no_wakeup[] qurik list
    (stable-fixes).
  - commit 605bae8
  - Refresh
    patches.suse/selftests-bpf-Range-analysis-test-case-for-JSET.patch.
    Fix BPF selftest failure in the "verifier_bounds/dead branch on jset,
    does not result in invariants violation error" case.
  - commit 906c64e

++++ kernel-rt:

  - erofs: fix atomic context detection when
    !CONFIG_DEBUG_LOCK_ALLOC (git-fixes).
  - commit 672e366
  - net: drop UFO packets in udp_rcv_segment() (CVE-2025-38622
    bsc#1248619).
  - commit 48c98b8
  - smb: client: fix use-after-free in crypt_message when using
    async crypto (bsc#1247239, CVE-2025-38488).
  - commit 09784fa
  - wifi: mt76: mt7925: fix the wrong bss cleanup for SAP
    (git-fixes).
  - commit aed2258
  - ax25: properly unshare skbs in ax25_kiss_rcv() (git-fixes).
  - wifi: ath11k: fix group data packet drops during rekey
    (git-fixes).
  - wifi: cfg80211: sme: cap SSID length in
    __cfg80211_connect_result() (git-fixes).
  - wifi: libertas: cap SSID len in lbs_associate() (git-fixes).
  - wifi: cw1200: cap SSID length in cw1200_do_join() (git-fixes).
  - batman-adv: fix OOB read/write in network-coding decode
    (git-fixes).
  - Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
    (git-fixes).
  - Bluetooth: vhci: Prevent use-after-free by removing debugfs
    files early (git-fixes).
  - microchip: lan865x: Fix LAN8651 autoloading (git-fixes).
  - microchip: lan865x: Fix module autoloading (git-fixes).
  - mISDN: Fix memory leak in dsp_hwec_enable() (git-fixes).
  - xirc2ps_cs: fix register access when enabling FullDuplex
    (git-fixes).
  - wifi: iwlwifi: uefi: check DSM item validity (git-fixes).
  - wifi: mt76: fix linked list corruption (git-fixes).
  - wifi: mt76: free pending offchannel tx frames on wcid cleanup
    (git-fixes).
  - wifi: mt76: prevent non-offchannel mgmt tx during scan/roc
    (git-fixes).
  - wifi: mt76: mt7925u: use connac3 tx aggr check in tx complete
    (git-fixes).
  - wifi: mt76: mt7925: fix locking in mt7925_change_vif_links()
    (git-fixes).
  - wifi: mt76: mt7996: Initialize hdr before passing to
    skb_put_data() (git-fixes).
  - wifi: mwifiex: Initialize the chan_stats array to zero
    (git-fixes).
  - wifi: brcmfmac: fix use-after-free when rescheduling
    brcmf_btcoex_info work (git-fixes).
  - wifi: cfg80211: fix use-after-free in cmp_bss() (git-fixes).
  - HID: quirks: add support for Legion Go dual dinput modes
    (stable-fixes).
  - HID: logitech: Add ids for G PRO 2 LIGHTSPEED (stable-fixes).
  - HID: input: report battery status changes immediately
    (git-fixes).
  - HID: input: rename hidinput_set_battery_charge_status()
    (stable-fixes).
  - HID: hid-ntrig: fix unable to handle page fault in
    ntrig_report_version() (stable-fixes).
  - HID: wacom: Add a new Art Pen 2 (stable-fixes).
  - drm/amd/amdgpu: disable hwmon power1_cap* for gfx 11.0.3 on
    vf mode (stable-fixes).
  - Revert "drm/amdgpu: fix incorrect vm flags to map bo"
    (stable-fixes).
  - net: rose: fix a typo in rose_clear_routes() (git-fixes).
  - net: rose: include node references in rose_neigh refcount
    (git-fixes).
  - net: rose: convert 'use' field to refcount_t (git-fixes).
  - net: rose: split remove and free operations in
    rose_remove_neigh() (stable-fixes).
  - mISDN: hfcpci: Fix warning when deleting uninitialized timer
    (git-fixes).
  - dma/pool: Ensure DMA_DIRECT_REMAP allocations are decrypted
    (stable-fixes).
  - ASoC: codecs: tx-macro: correct tx_macro_component_drv name
    (stable-fixes).
  - PCI: dwc: Ensure that dw_pcie_wait_for_link() waits 100 ms
    after link up (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Add mt7988 lvts commands
    (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Add lvts commands and
    their sizes to driver data (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Change lvts commands
    array to static const (stable-fixes).
  - ACPI: EC: Add device to acpi_ec_no_wakeup[] qurik list
    (stable-fixes).
  - commit 605bae8
  - Refresh
    patches.suse/selftests-bpf-Range-analysis-test-case-for-JSET.patch.
    Fix BPF selftest failure in the "verifier_bounds/dead branch on jset,
    does not result in invariants violation error" case.
  - commit 906c64e

------------------------------------------------------------------
------------------  2025-9-4  -  Sep 4 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to docker-buildx v0.28.0. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.28.0>
  - Update to Docker 28.4.0-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2840>
    * Fixes a nil pointer panic in "docker push". bsc#1248373
  - Rebased patches:
    * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
    * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * cli-0001-openSUSE-point-users-to-docker-buildx-package.patch
    * cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch

++++ kernel-default:

  - wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac() (CVE-2025-38643 bsc#1248681)
  - commit 34311cc
  - mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices (CVE-2025-38019 bsc#1245000)
  - commit a85ff92
  - Refresh
    patches.suse/Revert-mm-page_alloc.c-don-t-show-protection-in-zone.patch.
    Update patch metadata and move to sorted section.
  - commit 625f5ae
  - [ceph] parse_longname(): strrchr() expects NUL-terminated string
    (bsc#1248634 CVE-2025-38660).
  - commit ab3a29c
  - kABI: netfilter: supress warnings for nft_set_ops (git-fixes).
  - commit 27ce688
  - tracepoint: Print the function symbol when tracepoint_debug
    is set (jsc#PED-13631).
  - commit a74d4fb
  - s390/ap: Unmask SLCF bit in card and queue ap functions sysfs
    (git-fixes bsc#1247837).
  - commit 288d9b8
  - igc: fix disabling L1.2 PCI-E link substate on I226 on init
    (git-fixes).
  - commit 8d32f7d

++++ kernel-firmware-ath12k:

  - Update to version 20250903 (git commit 577ee67ffca2):
    * ath12k: WCN7850 hw2.0@ncm865: add to WLAN.IOE_HMT.1.1-00018-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1

++++ kernel-firmware-mediatek:

  - Update to version 20250903 (git commit 577ee67ffca2):
    * linux-firmware: update firmware for MT7925 WiFi device
    * mediatek MT7925:update bluetooth firmware to 20250825220109 Update binary firmware for MT7925 BT devices.

++++ kernel-rt:

  - wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac() (CVE-2025-38643 bsc#1248681)
  - commit 34311cc
  - mlxsw: spectrum_router: Fix use-after-free when deleting GRE net devices (CVE-2025-38019 bsc#1245000)
  - commit a85ff92
  - Refresh
    patches.suse/Revert-mm-page_alloc.c-don-t-show-protection-in-zone.patch.
    Update patch metadata and move to sorted section.
  - commit 625f5ae
  - [ceph] parse_longname(): strrchr() expects NUL-terminated string
    (bsc#1248634 CVE-2025-38660).
  - commit ab3a29c
  - kABI: netfilter: supress warnings for nft_set_ops (git-fixes).
  - commit 27ce688
  - tracepoint: Print the function symbol when tracepoint_debug
    is set (jsc#PED-13631).
  - commit a74d4fb
  - s390/ap: Unmask SLCF bit in card and queue ap functions sysfs
    (git-fixes bsc#1247837).
  - commit 288d9b8
  - igc: fix disabling L1.2 PCI-E link substate on I226 on init
    (git-fixes).
  - commit 8d32f7d

++++ runc:

  - Update to runc v1.3.1. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.3.1>
  - Fix runc 1.3.x builds on SLE-12 by enabling --std=gnu11.

------------------------------------------------------------------
------------------  2025-9-3  -  Sep 3 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20250903.33e5ba4:
    * Correct fix for boo#1247495 (boo#1248158)

++++ kernel-default:

  - scsi: ufs: core: Set default runtime/system PM levels before
    ufshcd_hba_init() (git-fixes).
  - commit 6c09a41
  - net/mlx5e: Set local Xoff after FW update (git-fixes).
  - net/mlx5e: Update and set Xon/Xoff upon port speed set
    (git-fixes).
  - net/mlx5e: Update and set Xon/Xoff upon MTU set (git-fixes).
  - net/mlx5: Prevent flow steering mode changes in switchdev mode
    (git-fixes).
  - net/mlx5: Nack sync reset when SFs are present (git-fixes).
  - net/mlx5: Fix lockdep assertion on sync reset unload event
    (git-fixes).
  - net/mlx5: Reload auxiliary drivers on fw_activate (git-fixes).
  - net/mlx5: HWS, Fix pattern destruction in
    mlx5hws_pat_get_pattern error path (git-fixes).
  - net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic
    error flow (git-fixes).
  - ice: fix incorrect counter for buffer allocation failures
    (git-fixes).
  - ice: use fixed adapter index for E825C embedded devices
    (git-fixes).
  - ice: don't leave device non-functional if Tx scheduler config
    fails (git-fixes).
  - bnxt_en: Fix stats context reservation logic (git-fixes).
  - bnxt_en: Adjust TX rings if reservation is less than requested
    (git-fixes).
  - bnxt_en: Fix memory corruption when FW resources change during
    ifdown (git-fixes).
  - net/mlx5e: Preserve shared buffer capacity during headroom
    updates (git-fixes).
  - net/mlx5: Base ECVF devlink port attrs from 0 (git-fixes).
  - Octeontx2-af: Skip overlap check for SPI field (git-fixes).
  - ixgbe: xsk: resolve the negative overflow of budget in
    ixgbe_xmit_zc (git-fixes).
  - net/mlx5: CT: Use the correct counter offset (git-fixes).
  - net/mlx5: HWS, fix bad parameter in CQ creation (git-fixes).
  - gve: prevent ethtool ops after shutdown (git-fixes).
  - net: page_pool: allow enabling recycling late, fix false
    positive warning (git-fixes).
  - benet: fix BUG when creating VFs (git-fixes).
  - net/mlx5: Correctly set gso_segs when LRO is used (git-fixes).
  - vdpa: Fix IDR memory leak in VDUSE module exit (git-fixes).
  - vdpa/mlx5: Fix release of uninitialized resources on error path
    (CVE-2025-38628 bsc#1248616).
  - vdpa/mlx5: Fix needs_teardown flag calculation (git-fixes).
  - RDMA/mana_ib: Fix DSCP value in modify QP (git-fixes).
  - igb: xsk: solve negative overflow of nb_pkts in zerocopy mode
    (git-fixes).
  - neighbour: Fix null-ptr-deref in neigh_flush_dev() (git-fixes).
  - net/mlx5e: Remove skb secpath if xfrm state is not found
    (git-fixes).
  - net/mlx5e: Clear Read-Only port buffer size in PBMC before
    update (git-fixes).
  - net/mlx5: Check device memory pointer before usage (git-fixes).
  - e1000e: ignore uninitialized checksum word on tgp (git-fixes).
  - e1000e: disregard NVM checksum on tgp when valid checksum bit
    is not set (git-fixes).
  - i40e: When removing VF MAC filters, only check PF-set MAC
    (git-fixes).
  - i40e: report VF tx_dropped with tx_errors instead of tx_discards
    (git-fixes).
  - gve: Fix stuck TX queue for DQ queue format (git-fixes).
  - net/mlx5: E-Switch, Fix peer miss rules to use peer eswitch
    (git-fixes).
  - net/mlx5: Fix memory leak in cmd_exec() (git-fixes).
  - ice: check correct pointer in fwlog debugfs (git-fixes).
  - net/mlx5: Correctly set gso_size when LRO is used (git-fixes).
  - bnxt_en: Flush FW trace before copying to the coredump
    (git-fixes).
  - bnxt_en: Fix DCB ETS validation (git-fixes).
  - net/mlx5e: Add new prio for promiscuous mode (git-fixes).
  - ibmvnic: Fix hardcoded NUM_RX_STATS/NUM_TX_STATS with dynamic
    sizeof (git-fixes).
  - bnxt_en: eliminate the compile warning in bnxt_request_irq
    due to CONFIG_RFS_ACCEL (git-fixes).
  - igc: disable L1.2 PCI-E link substate to avoid performance issue
    (git-fixes).
  - bnxt_en: Update MRU and RSS table of RSS contexts on queue reset
    (git-fixes).
  - bnxt_en: Add a helper function to configure MRU and RSS
    (git-fixes).
  - ice/ptp: fix crosstimestamp reporting (git-fixes).
  - commit d4ae4ee
  - Drop ath12k patch that was reverted in the upstream (git-fixes)
  - commit 0ebe805
  - netfilter: nf_reject: don't leak dst refcount for loopback
    packets (git-fixes).
  - commit c98a78c
  - netfilter: ctnetlink: remove refcounting in expectation dumpers
    (git-fixes).
  - commit 180b1da
  - netfilter: ctnetlink: fix refcount leak on table dump
    (git-fixes).
  - commit 144df33
  - Revert "wifi: mt76: mt7925: Update mt7925_mcu_uni_[tx,rx]_ba
    for MLO" (git-fixes).
  - Refresh
    patches.suse/wifi-mt76-mt7925-load-the-appropriate-CLC-data-based.patch.
  - commit 022c9d4
  - wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event
    (git-fixes).
  - wifi: ath12k: fix wrong handling of CCMP256 and GCMP ciphers
    (git-fixes).
  - wifi: mt76: mt7925: adjust rm BSS flow to prevent next
    connection failure (git-fixes).
  - wifi: ath12k: fix memory leak in ath12k_pci_remove()
    (stable-fixes).
  - commit d6dfa86
  - netfilter: nft_set_pipapo: prefer kvmalloc for scratch maps
    (git-fixes).
  - commit 30511a6
  - netfilter: nf_tables: adjust lockdep assertions handling
    (git-fixes).
  - commit 4eac73e
  - netfilter: nf_tables: Drop dead code from fill_*_info routines
    (git-fixes).
  - commit 0985889
  - netfilter: nf_nat: also check reverse tuple to obtain clashing
    entry (git-fixes).
  - commit e8b9b42
  - netfilter: nft_tunnel: fix geneve_opt dump (git-fixes).
  - commit e8ff1b8
  - usb: dwc3: qcom: Don't leave BCR asserted (git-fixes).
  - commit d02e75f
  - netfilter: xtables: support arpt_mark and ipv6 optstrip for
    iptables-nft only builds (git-fixes).
  - commit 9973f5b
  - netfilter: nf_conncount: garbage collection is not skipped
    when jiffies wrap around (git-fixes).
  - commit 840672d
  - soundwire: amd: fix for handling slave alerts after link is down
    (git-fixes).
  - tools/power turbostat: Clustered Uncore MHz counters should
    honor show/hide options (stable-fixes).
  - commit 2b28a91
  - netfilter: nft_ct: Use __refcount_inc() for per-CPU
    nft_ct_pcpu_template (git-fixes).
  - commit d759ad6
  - selinux: change security_compute_sid to return the ssid or
    tsid on match (git-fixes).
  - selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
    (stable-fixes).
  - commit 67b27c3
  - xfrm: replay: Fix the update of replay_esn->oseq_hi for GSO
    (git-fixes).
  - commit 384833b
  - r8169: disable RTL8126 ZRX-DC timeout (stable-fixes).
  - r8169: don't scan PHY addresses > 0 (stable-fixes).
  - r8169: add support for RTL8125D (stable-fixes).
  - commit 5a5406a
  - phy: mscc: Fix timestamping for vsc8584 (git-fixes).
  - phy: mscc: Fix parsing of unicast frames (git-fixes).
  - phy: rockchip-pcie: Properly disable TEST_WRITE strobe signal
    (stable-fixes).
  - commit cef652d
  - mmc: sdhci_am654: Disable HS400 for AM62P SR1.0 and SR1.1
    (git-fixes).
  - mfd: exynos-lpass: Fix another error handling path in
    exynos_lpass_probe() (git-fixes).
  - mtd: rawnand: qcom: Fix last codeword read in
    qcom_param_page_type_exec() (git-fixes).
  - misc: pci_endpoint_test: Fix 'irq_type' to convey the correct
    type (git-fixes).
  - misc: pci_endpoint_test: Give disabled BARs a distinct error
    code (stable-fixes).
  - commit 265f979
  - media: uvcvideo: Rollback non processed entities on error
    (git-fixes).
  - commit 77fe556
  - Revert "mac80211: Dynamically set CoDel parameters per station"
    (stable-fixes).
  - commit a3f9ef1
  - iio: temperature: maxim_thermocouple: use DMA-safe buffer for
    spi_read() (git-fixes).
  - iio: adc: ad7173: fix setting ODR in probe (git-fixes).
  - commit c345d74
  - kabi/severities: ignore kABI compatibility in iio inv_icm42600 drivers
    They are used only locally
  - commit 4b6ea02
  - iio: imu: inv_icm42600: Convert to uXX and sXX integer types
    (stable-fixes).
  - Refresh
    patches.suse/iio-imu-inv_icm42600-change-invalid-data-error-to-EB.patch.
  - commit b49ad7a
  - iio: accel: fxls8962af: Fix temperature calculation (git-fixes).
  - iio: hid-sensor-prox: Fix incorrect OFFSET calculation
    (git-fixes).
  - iio: hid-sensor-prox: Restore lost scale assignments
    (git-fixes).
  - iio: imu: inv_icm42600: fix spi burst write not supported
    (git-fixes).
  - commit d725fa5
  - i3c: master: Initialize ret in i3c_i2c_notifier_call()
    (stable-fixes).
  - commit 422bc10
  - i2c: designware: Use temporary variable for struct device
    (stable-fixes).
  - Refresh
    patches.suse/i2c-designware-Fix-an-error-handling-path-in-i2c_dw_.patch.
  - commit 572df73
  - HID: magicmouse: avoid setting up battery timer when not needed
    (git-fixes).
  - HID: apple: avoid setting up battery timer for devices without
    battery (git-fixes).
  - commit 60e95b8
  - drm/i915/icl+/tc: Convert AUX powered WARN to a debug message
    (stable-fixes).
  - drm/i915/icl+/tc: Cache the max lane count value (stable-fixes).
  - drm/i915/dp: Fix 2.7 Gbps DP_LINK_BW value on g4x (git-fixes).
  - drm/xe: Move page fault init after topology init (git-fixes).
  - drm/nouveau/gsp: fix potential leak of memory used during acpi
    init (git-fixes).
  - drm/xe: Allow dropping kunit dependency as built-in (git-fixes).
  - commit e6e09dd
  - drm/amdgpu/discovery: fix fw based ip discovery (git-fixes).
  - drm/xe/bmg: Update Wa_22019338487 (git-fixes).
  - drm/amdgpu: VCN v5_0_1 to prevent FW checking RB during DPG
    pause (stable-fixes).
  - drm/amdgpu: add kicker fws loading for gfx11/smu13/psp13
    (stable-fixes).
  - drm/amdgpu/mes: add missing locking in helper functions
    (stable-fixes).
  - commit 7e9890a
  - drm/simpledrm: Do not upcast in release helpers (git-fixes).
  - drm/cirrus-qemu: Fix pitch programming (git-fixes).
  - commit b624f85
  - drm/xe/gsc: do not flush the GSC worker from the reset path
    (git-fixes).
  - drm/amd/display: Default IPS to RCG_IN_ACTIVE_IPS2_IN_OFF
    (git-fixes).
  - drm/xe: Ensure fixed_slice_mode gets set after ccs_mode change
    (git-fixes).
  - drm/xe/bmg: Add one additional PCI ID (stable-fixes).
  - commit c2190df
  - netfilter: nf_tables: fix set size with rbtree backend
    (git-fixes).
  - commit 80c4ea7
  - drm/amdgpu/discovery: optionally use fw based ip discovery
    (stable-fixes).
  - commit 4e56fa6
  - drm/amd/display: Fix mismatch type comparison (stable-fixes).
  - drm/xe/bmg: Add new PCI IDs (stable-fixes).
  - commit 8b6d86b
  - net: hsr: fix fill_frame_info() regression vs VLAN packets
    (git-fixes).
  - commit 8901b13
  - Refresh patches.suse/drm-amd-display-Request-HW-cursor-on-DCN3.2-with-Sub.patch
    The partial revert in the upstream 6.12.y is folded into the patch
  - commit 8be4958
  - ipv6: reject malicious packets in ipv6_gso_segment()
    (CVE-2025-38572 bsc#1248399).
  - net: add debug check in skb_reset_transport_header()
    (CVE-2025-38572 bsc#1248399).
  - commit 1c3093c
  - drm/msm/dp: account for widebus and yuv420 during mode
    validation (git-fixes).
  - drm/xe: Carve out wopcm portion from the stolen memory
    (git-fixes).
  - commit 4792a43
  - Drop a few Xe patches that have been reverted in 6.12.y stable
    The upstream already reverted a few patches due to regressions, and
    we also follow (and blacklist them).
    Deleted:
    patches.suse/drm-xe-devcoredump-Update-handling-of-xe_force_wake_.patch
    patches.suse/drm-xe-forcewake-Add-a-helper-xe_force_wake_ref_has_.patch
    patches.suse/drm-xe-gt-Update-handling-of-xe_force_wake_get-retur.patch
    patches.suse/drm-xe-tests-mocs-Hold-XE_FORCEWAKE_ALL-for-LNCF-reg.patch
    patches.suse/drm-xe-tests-mocs-Update-xe_force_wake_get-return-ha.patch
    Refreshed:
    patches.suse/drm-xe-Fix-GT-for-each-engine-workarounds.patch
    patches.suse/drm-xe-Move-the-coredump-registration-to-the-worker-.patch
    patches.suse/drm-xe-Take-PM-ref-in-delayed-snapshot-capture-worke.patch
    patches.suse/drm-xe-bmg-Update-Wa_16023588340.patch
    patches.suse/drm-xe-pf-Prepare-to-stop-SR-IOV-support-prior-GT-re.patch
  - commit 019c4d3
  - kABI workaround for struct mtk_base_afe changes (git-fixes).
  - commit bfb1140
  - ASoC: mediatek: use reserved memory or enable buffer
    pre-allocation (git-fixes).
  - commit 8fbb8b5
  - ASoC: codecs: wcd9375: Fix double free of regulator supplies
    (git-fixes).
  - ASoC: codecs: wcd937x: Drop unused buck_supply (git-fixes).
  - commit 428fcda
  - mctp: no longer rely on net->dev_index_head (git-fixes).
  - Refresh
    patches.suse/net-mctp-Don-t-access-ifa_index-when-missing.patch.
  - commit b5bc0f2
  - rpm: Configure KABI checkingness macro (bsc#1249186)
    The value of the config should match presence of KABI reference data. If
    it mismatches:
  - !CONFIG & reference  -> this is bug, immediate fail
  - CONFIG & no reference -> OK temporarily, must be resolved eventually
  - commit 23c1536
  - mptcp: fix spurious wake-up on under memory pressure
    (git-fixes).
  - commit c782ac7
  - Kconfig.suse: Add KABI checkiness macro (config) (bsc#1249186)
    The motivation: there are patches.kabi/ patches that restore KABI and
    they check validity of the approach with static_assert()s to prevent
    accidental KABI breakage.
    These asserts are invoked on each arch-flavor and they may signal false
    negatives -- that is KABI restoration patch could break KABI but the
    given arch-flavor defines no KABI.
    The intended use is to disable the compile time checks in patches.kabi/
    (but not to be confused with __GENKSYMS__ that affects how reference is
    calculated).
    The name is chosen so that it mimics HAVE_* macros that are not
    configured manually (but is selected by an arch). In our case it's
    (un)selected by build script depending on whether KABI reference is
    defined for given arch-flavor and whether check is really requested by
    the user. Default value is 'n' so that people building merely via
    Makefile (not RPM with KABI checking) obtain consistent config.
  - commit a317d04
  - net: 802: LLC+SNAP OID:PID lookup on start of skb data
    (git-fixes).
  - commit c23ea46
  - net: llc: reset skb->transport_header (git-fixes).
  - commit 487d90f
  - net: mctp: handle skb cleanup on sock_queue failures (git-fixes).
  - Refresh
    patches.suse/net-mctp-unshare-packets-when-reassembling.patch.
  - commit 5e65ce2
  - ipvs: Fix clamp() of ip_vs_conn_tab on small memory systems
    (git-fixes).
  - commit 3d1de0f
  - psample: adjust size if rate_as_probability is set (git-fixes).
  - commit 2508d32
  - net: dsa: restore dsa_software_vlan_untag() ability to operate
    on VLAN-untagged traffic (git-fixes).
  - commit b8cbb32
  - net/smc: check sndbuf_space again after NOSPACE flag is set
    in smc_poll (git-fixes).
  - commit e07bfa8
  - net: dsa: tag_ocelot_8021q: fix broken reception (git-fixes).
  - commit 680a61f
  - net: hsr: fix hsr_init_sk() vs network/transport headers
    (git-fixes).
  - commit 9b32d20
  - btrfs: fix data overwriting bug during buffered write when
    block size < page size (git-fixes).
  - commit 2ef27b3
  - btrfs: do not output error message if a qgroup has been  already
    cleaned up (git-fixes).
  - commit 9ca239b
  - btrfs: subpage: fix the bitmap dump of the locked flags
    (git-fixes).
  - commit 7983818
  - btrfs: handle unaligned EOF truncation correctly for subpage
    cases (bsc#1249038).
  - commit 56bc678
  - btrfs: convert ASSERT(0) with handled errors to  DEBUG_WARN()
    (bsc#1249038).
  - commit a1589a9
  - btrfs: add debug build only WARN (bsc#1249038).
  - commit 97bc3a6
  - btrfs: use verbose ASSERT() in volumes.c (bsc#1249038).
  - commit e2a342d
  - gfs2: No more self recovery (bsc#1248639 CVE-2025-38659).
  - commit f21f207
  - btrfs: enhance ASSERT() to take optional format string
    (bsc#1249038).
  - commit 038fb2a
  - ALSA: usb-audio: Allow Focusrite devices to use low samplerates
    (git-fixes).
  - commit 8cb030f

++++ kernel-firmware-bluetooth:

  - Update to version 20250903 (git commit c784990ba3d2):
    * rtl_bt: Update RTL8822C BT USB firmware to 0x2B66_D962

++++ kernel-rt:

  - scsi: ufs: core: Set default runtime/system PM levels before
    ufshcd_hba_init() (git-fixes).
  - commit 6c09a41
  - net/mlx5e: Set local Xoff after FW update (git-fixes).
  - net/mlx5e: Update and set Xon/Xoff upon port speed set
    (git-fixes).
  - net/mlx5e: Update and set Xon/Xoff upon MTU set (git-fixes).
  - net/mlx5: Prevent flow steering mode changes in switchdev mode
    (git-fixes).
  - net/mlx5: Nack sync reset when SFs are present (git-fixes).
  - net/mlx5: Fix lockdep assertion on sync reset unload event
    (git-fixes).
  - net/mlx5: Reload auxiliary drivers on fw_activate (git-fixes).
  - net/mlx5: HWS, Fix pattern destruction in
    mlx5hws_pat_get_pattern error path (git-fixes).
  - net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic
    error flow (git-fixes).
  - ice: fix incorrect counter for buffer allocation failures
    (git-fixes).
  - ice: use fixed adapter index for E825C embedded devices
    (git-fixes).
  - ice: don't leave device non-functional if Tx scheduler config
    fails (git-fixes).
  - bnxt_en: Fix stats context reservation logic (git-fixes).
  - bnxt_en: Adjust TX rings if reservation is less than requested
    (git-fixes).
  - bnxt_en: Fix memory corruption when FW resources change during
    ifdown (git-fixes).
  - net/mlx5e: Preserve shared buffer capacity during headroom
    updates (git-fixes).
  - net/mlx5: Base ECVF devlink port attrs from 0 (git-fixes).
  - Octeontx2-af: Skip overlap check for SPI field (git-fixes).
  - ixgbe: xsk: resolve the negative overflow of budget in
    ixgbe_xmit_zc (git-fixes).
  - net/mlx5: CT: Use the correct counter offset (git-fixes).
  - net/mlx5: HWS, fix bad parameter in CQ creation (git-fixes).
  - gve: prevent ethtool ops after shutdown (git-fixes).
  - net: page_pool: allow enabling recycling late, fix false
    positive warning (git-fixes).
  - benet: fix BUG when creating VFs (git-fixes).
  - net/mlx5: Correctly set gso_segs when LRO is used (git-fixes).
  - vdpa: Fix IDR memory leak in VDUSE module exit (git-fixes).
  - vdpa/mlx5: Fix release of uninitialized resources on error path
    (CVE-2025-38628 bsc#1248616).
  - vdpa/mlx5: Fix needs_teardown flag calculation (git-fixes).
  - RDMA/mana_ib: Fix DSCP value in modify QP (git-fixes).
  - igb: xsk: solve negative overflow of nb_pkts in zerocopy mode
    (git-fixes).
  - neighbour: Fix null-ptr-deref in neigh_flush_dev() (git-fixes).
  - net/mlx5e: Remove skb secpath if xfrm state is not found
    (git-fixes).
  - net/mlx5e: Clear Read-Only port buffer size in PBMC before
    update (git-fixes).
  - net/mlx5: Check device memory pointer before usage (git-fixes).
  - e1000e: ignore uninitialized checksum word on tgp (git-fixes).
  - e1000e: disregard NVM checksum on tgp when valid checksum bit
    is not set (git-fixes).
  - i40e: When removing VF MAC filters, only check PF-set MAC
    (git-fixes).
  - i40e: report VF tx_dropped with tx_errors instead of tx_discards
    (git-fixes).
  - gve: Fix stuck TX queue for DQ queue format (git-fixes).
  - net/mlx5: E-Switch, Fix peer miss rules to use peer eswitch
    (git-fixes).
  - net/mlx5: Fix memory leak in cmd_exec() (git-fixes).
  - ice: check correct pointer in fwlog debugfs (git-fixes).
  - net/mlx5: Correctly set gso_size when LRO is used (git-fixes).
  - bnxt_en: Flush FW trace before copying to the coredump
    (git-fixes).
  - bnxt_en: Fix DCB ETS validation (git-fixes).
  - net/mlx5e: Add new prio for promiscuous mode (git-fixes).
  - ibmvnic: Fix hardcoded NUM_RX_STATS/NUM_TX_STATS with dynamic
    sizeof (git-fixes).
  - bnxt_en: eliminate the compile warning in bnxt_request_irq
    due to CONFIG_RFS_ACCEL (git-fixes).
  - igc: disable L1.2 PCI-E link substate to avoid performance issue
    (git-fixes).
  - bnxt_en: Update MRU and RSS table of RSS contexts on queue reset
    (git-fixes).
  - bnxt_en: Add a helper function to configure MRU and RSS
    (git-fixes).
  - ice/ptp: fix crosstimestamp reporting (git-fixes).
  - commit d4ae4ee
  - Drop ath12k patch that was reverted in the upstream (git-fixes)
  - commit 0ebe805
  - netfilter: nf_reject: don't leak dst refcount for loopback
    packets (git-fixes).
  - commit c98a78c
  - netfilter: ctnetlink: remove refcounting in expectation dumpers
    (git-fixes).
  - commit 180b1da
  - netfilter: ctnetlink: fix refcount leak on table dump
    (git-fixes).
  - commit 144df33
  - Revert "wifi: mt76: mt7925: Update mt7925_mcu_uni_[tx,rx]_ba
    for MLO" (git-fixes).
  - Refresh
    patches.suse/wifi-mt76-mt7925-load-the-appropriate-CLC-data-based.patch.
  - commit 022c9d4
  - wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event
    (git-fixes).
  - wifi: ath12k: fix wrong handling of CCMP256 and GCMP ciphers
    (git-fixes).
  - wifi: mt76: mt7925: adjust rm BSS flow to prevent next
    connection failure (git-fixes).
  - wifi: ath12k: fix memory leak in ath12k_pci_remove()
    (stable-fixes).
  - commit d6dfa86
  - netfilter: nft_set_pipapo: prefer kvmalloc for scratch maps
    (git-fixes).
  - commit 30511a6
  - netfilter: nf_tables: adjust lockdep assertions handling
    (git-fixes).
  - commit 4eac73e
  - netfilter: nf_tables: Drop dead code from fill_*_info routines
    (git-fixes).
  - commit 0985889
  - netfilter: nf_nat: also check reverse tuple to obtain clashing
    entry (git-fixes).
  - commit e8b9b42
  - netfilter: nft_tunnel: fix geneve_opt dump (git-fixes).
  - commit e8ff1b8
  - usb: dwc3: qcom: Don't leave BCR asserted (git-fixes).
  - commit d02e75f
  - netfilter: xtables: support arpt_mark and ipv6 optstrip for
    iptables-nft only builds (git-fixes).
  - commit 9973f5b
  - netfilter: nf_conncount: garbage collection is not skipped
    when jiffies wrap around (git-fixes).
  - commit 840672d
  - soundwire: amd: fix for handling slave alerts after link is down
    (git-fixes).
  - tools/power turbostat: Clustered Uncore MHz counters should
    honor show/hide options (stable-fixes).
  - commit 2b28a91
  - netfilter: nft_ct: Use __refcount_inc() for per-CPU
    nft_ct_pcpu_template (git-fixes).
  - commit d759ad6
  - selinux: change security_compute_sid to return the ssid or
    tsid on match (git-fixes).
  - selinux: fix selinux_xfrm_alloc_user() to set correct ctx_len
    (stable-fixes).
  - commit 67b27c3
  - xfrm: replay: Fix the update of replay_esn->oseq_hi for GSO
    (git-fixes).
  - commit 384833b
  - r8169: disable RTL8126 ZRX-DC timeout (stable-fixes).
  - r8169: don't scan PHY addresses > 0 (stable-fixes).
  - r8169: add support for RTL8125D (stable-fixes).
  - commit 5a5406a
  - phy: mscc: Fix timestamping for vsc8584 (git-fixes).
  - phy: mscc: Fix parsing of unicast frames (git-fixes).
  - phy: rockchip-pcie: Properly disable TEST_WRITE strobe signal
    (stable-fixes).
  - commit cef652d
  - mmc: sdhci_am654: Disable HS400 for AM62P SR1.0 and SR1.1
    (git-fixes).
  - mfd: exynos-lpass: Fix another error handling path in
    exynos_lpass_probe() (git-fixes).
  - mtd: rawnand: qcom: Fix last codeword read in
    qcom_param_page_type_exec() (git-fixes).
  - misc: pci_endpoint_test: Fix 'irq_type' to convey the correct
    type (git-fixes).
  - misc: pci_endpoint_test: Give disabled BARs a distinct error
    code (stable-fixes).
  - commit 265f979
  - media: uvcvideo: Rollback non processed entities on error
    (git-fixes).
  - commit 77fe556
  - Revert "mac80211: Dynamically set CoDel parameters per station"
    (stable-fixes).
  - commit a3f9ef1
  - iio: temperature: maxim_thermocouple: use DMA-safe buffer for
    spi_read() (git-fixes).
  - iio: adc: ad7173: fix setting ODR in probe (git-fixes).
  - commit c345d74
  - kabi/severities: ignore kABI compatibility in iio inv_icm42600 drivers
    They are used only locally
  - commit 4b6ea02
  - iio: imu: inv_icm42600: Convert to uXX and sXX integer types
    (stable-fixes).
  - Refresh
    patches.suse/iio-imu-inv_icm42600-change-invalid-data-error-to-EB.patch.
  - commit b49ad7a
  - iio: accel: fxls8962af: Fix temperature calculation (git-fixes).
  - iio: hid-sensor-prox: Fix incorrect OFFSET calculation
    (git-fixes).
  - iio: hid-sensor-prox: Restore lost scale assignments
    (git-fixes).
  - iio: imu: inv_icm42600: fix spi burst write not supported
    (git-fixes).
  - commit d725fa5
  - i3c: master: Initialize ret in i3c_i2c_notifier_call()
    (stable-fixes).
  - commit 422bc10
  - i2c: designware: Use temporary variable for struct device
    (stable-fixes).
  - Refresh
    patches.suse/i2c-designware-Fix-an-error-handling-path-in-i2c_dw_.patch.
  - commit 572df73
  - HID: magicmouse: avoid setting up battery timer when not needed
    (git-fixes).
  - HID: apple: avoid setting up battery timer for devices without
    battery (git-fixes).
  - commit 60e95b8
  - drm/i915/icl+/tc: Convert AUX powered WARN to a debug message
    (stable-fixes).
  - drm/i915/icl+/tc: Cache the max lane count value (stable-fixes).
  - drm/i915/dp: Fix 2.7 Gbps DP_LINK_BW value on g4x (git-fixes).
  - drm/xe: Move page fault init after topology init (git-fixes).
  - drm/nouveau/gsp: fix potential leak of memory used during acpi
    init (git-fixes).
  - drm/xe: Allow dropping kunit dependency as built-in (git-fixes).
  - commit e6e09dd
  - drm/amdgpu/discovery: fix fw based ip discovery (git-fixes).
  - drm/xe/bmg: Update Wa_22019338487 (git-fixes).
  - drm/amdgpu: VCN v5_0_1 to prevent FW checking RB during DPG
    pause (stable-fixes).
  - drm/amdgpu: add kicker fws loading for gfx11/smu13/psp13
    (stable-fixes).
  - drm/amdgpu/mes: add missing locking in helper functions
    (stable-fixes).
  - commit 7e9890a
  - drm/simpledrm: Do not upcast in release helpers (git-fixes).
  - drm/cirrus-qemu: Fix pitch programming (git-fixes).
  - commit b624f85
  - drm/xe/gsc: do not flush the GSC worker from the reset path
    (git-fixes).
  - drm/amd/display: Default IPS to RCG_IN_ACTIVE_IPS2_IN_OFF
    (git-fixes).
  - drm/xe: Ensure fixed_slice_mode gets set after ccs_mode change
    (git-fixes).
  - drm/xe/bmg: Add one additional PCI ID (stable-fixes).
  - commit c2190df
  - netfilter: nf_tables: fix set size with rbtree backend
    (git-fixes).
  - commit 80c4ea7
  - drm/amdgpu/discovery: optionally use fw based ip discovery
    (stable-fixes).
  - commit 4e56fa6
  - drm/amd/display: Fix mismatch type comparison (stable-fixes).
  - drm/xe/bmg: Add new PCI IDs (stable-fixes).
  - commit 8b6d86b
  - net: hsr: fix fill_frame_info() regression vs VLAN packets
    (git-fixes).
  - commit 8901b13
  - Refresh patches.suse/drm-amd-display-Request-HW-cursor-on-DCN3.2-with-Sub.patch
    The partial revert in the upstream 6.12.y is folded into the patch
  - commit 8be4958
  - ipv6: reject malicious packets in ipv6_gso_segment()
    (CVE-2025-38572 bsc#1248399).
  - net: add debug check in skb_reset_transport_header()
    (CVE-2025-38572 bsc#1248399).
  - commit 1c3093c
  - drm/msm/dp: account for widebus and yuv420 during mode
    validation (git-fixes).
  - drm/xe: Carve out wopcm portion from the stolen memory
    (git-fixes).
  - commit 4792a43
  - Drop a few Xe patches that have been reverted in 6.12.y stable
    The upstream already reverted a few patches due to regressions, and
    we also follow (and blacklist them).
    Deleted:
    patches.suse/drm-xe-devcoredump-Update-handling-of-xe_force_wake_.patch
    patches.suse/drm-xe-forcewake-Add-a-helper-xe_force_wake_ref_has_.patch
    patches.suse/drm-xe-gt-Update-handling-of-xe_force_wake_get-retur.patch
    patches.suse/drm-xe-tests-mocs-Hold-XE_FORCEWAKE_ALL-for-LNCF-reg.patch
    patches.suse/drm-xe-tests-mocs-Update-xe_force_wake_get-return-ha.patch
    Refreshed:
    patches.suse/drm-xe-Fix-GT-for-each-engine-workarounds.patch
    patches.suse/drm-xe-Move-the-coredump-registration-to-the-worker-.patch
    patches.suse/drm-xe-Take-PM-ref-in-delayed-snapshot-capture-worke.patch
    patches.suse/drm-xe-bmg-Update-Wa_16023588340.patch
    patches.suse/drm-xe-pf-Prepare-to-stop-SR-IOV-support-prior-GT-re.patch
  - commit 019c4d3
  - kABI workaround for struct mtk_base_afe changes (git-fixes).
  - commit bfb1140
  - ASoC: mediatek: use reserved memory or enable buffer
    pre-allocation (git-fixes).
  - commit 8fbb8b5
  - ASoC: codecs: wcd9375: Fix double free of regulator supplies
    (git-fixes).
  - ASoC: codecs: wcd937x: Drop unused buck_supply (git-fixes).
  - commit 428fcda
  - mctp: no longer rely on net->dev_index_head (git-fixes).
  - Refresh
    patches.suse/net-mctp-Don-t-access-ifa_index-when-missing.patch.
  - commit b5bc0f2
  - rpm: Configure KABI checkingness macro (bsc#1249186)
    The value of the config should match presence of KABI reference data. If
    it mismatches:
  - !CONFIG & reference  -> this is bug, immediate fail
  - CONFIG & no reference -> OK temporarily, must be resolved eventually
  - commit 23c1536
  - mptcp: fix spurious wake-up on under memory pressure
    (git-fixes).
  - commit c782ac7
  - Kconfig.suse: Add KABI checkiness macro (config) (bsc#1249186)
    The motivation: there are patches.kabi/ patches that restore KABI and
    they check validity of the approach with static_assert()s to prevent
    accidental KABI breakage.
    These asserts are invoked on each arch-flavor and they may signal false
    negatives -- that is KABI restoration patch could break KABI but the
    given arch-flavor defines no KABI.
    The intended use is to disable the compile time checks in patches.kabi/
    (but not to be confused with __GENKSYMS__ that affects how reference is
    calculated).
    The name is chosen so that it mimics HAVE_* macros that are not
    configured manually (but is selected by an arch). In our case it's
    (un)selected by build script depending on whether KABI reference is
    defined for given arch-flavor and whether check is really requested by
    the user. Default value is 'n' so that people building merely via
    Makefile (not RPM with KABI checking) obtain consistent config.
  - commit a317d04
  - net: 802: LLC+SNAP OID:PID lookup on start of skb data
    (git-fixes).
  - commit c23ea46
  - net: llc: reset skb->transport_header (git-fixes).
  - commit 487d90f
  - net: mctp: handle skb cleanup on sock_queue failures (git-fixes).
  - Refresh
    patches.suse/net-mctp-unshare-packets-when-reassembling.patch.
  - commit 5e65ce2
  - ipvs: Fix clamp() of ip_vs_conn_tab on small memory systems
    (git-fixes).
  - commit 3d1de0f
  - psample: adjust size if rate_as_probability is set (git-fixes).
  - commit 2508d32
  - net: dsa: restore dsa_software_vlan_untag() ability to operate
    on VLAN-untagged traffic (git-fixes).
  - commit b8cbb32
  - net/smc: check sndbuf_space again after NOSPACE flag is set
    in smc_poll (git-fixes).
  - commit e07bfa8
  - net: dsa: tag_ocelot_8021q: fix broken reception (git-fixes).
  - commit 680a61f
  - net: hsr: fix hsr_init_sk() vs network/transport headers
    (git-fixes).
  - commit 9b32d20
  - btrfs: fix data overwriting bug during buffered write when
    block size < page size (git-fixes).
  - commit 2ef27b3
  - btrfs: do not output error message if a qgroup has been  already
    cleaned up (git-fixes).
  - commit 9ca239b
  - btrfs: subpage: fix the bitmap dump of the locked flags
    (git-fixes).
  - commit 7983818
  - btrfs: handle unaligned EOF truncation correctly for subpage
    cases (bsc#1249038).
  - commit 56bc678
  - btrfs: convert ASSERT(0) with handled errors to  DEBUG_WARN()
    (bsc#1249038).
  - commit a1589a9
  - btrfs: add debug build only WARN (bsc#1249038).
  - commit 97bc3a6
  - btrfs: use verbose ASSERT() in volumes.c (bsc#1249038).
  - commit e2a342d
  - gfs2: No more self recovery (bsc#1248639 CVE-2025-38659).
  - commit f21f207
  - btrfs: enhance ASSERT() to take optional format string
    (bsc#1249038).
  - commit 038fb2a
  - ALSA: usb-audio: Allow Focusrite devices to use low samplerates
    (git-fixes).
  - commit 8cb030f

++++ pcre2:

  - Fix bsc#1248842 / CVE-2025-58050.
  - Add patch:
    * CVE-2025-58050.patch

------------------------------------------------------------------
------------------  2025-9-2  -  Sep 2 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - References #2474 and #2475 poweroff instead of halt on oem shutdown

++++ kernel-default:

  - scsi: ufs: ufs-pci: Fix default runtime and system PM levels
    (git-fixes).
  - scsi: ufs: ufs-pci: Fix hibernate state transition for Intel
    MTL-like host controllers (git-fixes).
  - scsi: ufs: core: Use link recovery when h8 exit fails during
    runtime resume (git-fixes).
  - scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE
    (git-fixes).
  - scsi: ufs: core: Fix spelling of a sysfs attribute name
    (git-fixes).
  - scsi: ufs: core: Fix clk scaling to be conditional in reset
    and restore (git-fixes).
  - scsi: ufs: core: Don't perform UFS clkscaling during host
    async scan (git-fixes).
  - scsi: ufs: mcq: Delete ufshcd_release_scsi_cmd() in
    ufshcd_mcq_abort() (git-fixes).
  - scsi: ufs: core: Remove redundant query_complete trace
    (git-fixes).
  - scsi: ufs: Introduce quirk to extend PA_HIBERN8TIME for UFS
    devices (git-fixes).
  - scsi: ufs: exynos: gs101: Put UFS device in reset on .suspend()
    (git-fixes).
  - scsi: ufs: exynos: Move phy calls to .exit() callback
    (git-fixes).
  - scsi: ufs: exynos: Enable PRDT pre-fetching with
    UFSHCD_CAP_CRYPTO (git-fixes).
  - scsi: ufs: exynos: Ensure consistent phy reference counts
    (git-fixes).
  - scsi: ufs: exynos: Move UFS shareability value to drvdata
    (git-fixes).
  - scsi: ufs: exynos: Ensure pre_link() executes before
    exynos_ufs_phy_init() (git-fixes).
  - scsi: ufs: qcom: fix dev reference leaked through
    of_qcom_ice_get (git-fixes).
  - scsi: ufs: core: Fix ufshcd_is_ufs_dev_busy() and
    ufshcd_eh_timed_out() (git-fixes).
  - scsi: ufs: core: Fix error return with query response
    (git-fixes).
  - scsi: ufs: Fix toggling of clk_gating.state when clock gating
    is not allowed (git-fixes).
  - scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails
    (git-fixes).
  - scsi: ufs: qcom: Fix crypto key eviction (git-fixes).
  - scsi: ufs: core: Prepare to introduce a new clock_gating lock
    (git-fixes).
  - scsi: ufs: core: Introduce ufshcd_has_pending_tasks()
    (git-fixes).
  - scsi: ufs: core: Honor runtime/system PM levels if set by host
    controller drivers (git-fixes).
  - scsi: ufs: core: Update compl_time_stamp_local_clock after
    completing a cqe (git-fixes).
  - scsi: ufs: core: Add missing post notify for power mode change
    (git-fixes).
  - scsi: ufs: pltfrm: Drop PM runtime reference count after
    ufshcd_remove() (git-fixes).
  - scsi: ufs: pltfrm: Disable runtime PM during removal of glue
    drivers (git-fixes).
  - scsi: ufs: core: Add ufshcd_send_bsg_uic_cmd() for UFS BSG
    (git-fixes).
  - scsi: ufs: exynos: Fix hibern8 notify callbacks (git-fixes).
  - scsi: ufs: exynos: Add gs101_ufs_drv_init() hook and enable
    WriteBooster (git-fixes).
  - scsi: ufs: exynos: Add check inside exynos_ufs_config_smu()
    (git-fixes).
  - scsi: ufs: exynos: Remove superfluous function parameter
    (git-fixes).
  - scsi: ufs: exynos: Remove empty drv_init method (git-fixes).
  - scsi: ufs: core: Improve ufshcd_mcq_sq_cleanup() (git-fixes).
  - scsi: ufs: core: Always initialize the UIC done completion
    (git-fixes).
  - commit 80e8ae3
  - atm: atmtcp: Free invalid length skb in atmtcp_c_send() (CVE-2025-38185 bsc#1246012)
  - commit 481542d
  - s390/mm: Do not map lowcore with identity mapping (git-fixes
    bsc#1249066).
  - commit 8621600
  - s390/sclp: Fix SCCB present check (git-fixes bsc#1249065).
  - commit a696cb0
  - s390/time: Use monotonic clock in get_cycles() (git-fixes
    bsc#1249064).
  - commit d681db3
  - s390/stp: Remove udelay from stp_sync_clock() (git-fixes
    bsc#1249062).
  - commit 599898d
  - s390/early: Copy last breaking event address to pt_regs
    (git-fixes bsc#1249061).
  - commit 75fe912
  - Update config files: revive pwc driver for Leap (bsc#1249060)
  - commit 3eb97c1
  - ext4: remove writable userspace mappings before truncating
    page cache (bsc#1247223).
  - commit f42a012
  - mm: fix the inaccurate memory statistics issue for users
    (bsc#1244723).
  - commit cfde4ca
  - Refresh
    patches.suse/cpuidle-menu-Bias-selection-of-a-shallower-c-state-when-CPU-idles-for-IO.patch
    (bsc#1247935).
  - commit 1c15b68
  - nvmet: exit debugfs after discovery subsystem exits (git-fixes).
  - commit 12678fa
  - nvmet: initialize discovery subsys after debugfs is initialized
    (git-fixes).
  - nvme-pci: try function level reset on init failure (git-fixes).
  - nvme-tcp: log TLS handshake failures at error level (git-fixes).
  - commit b6c5818
  - ipv6: prevent infinite loop in rt6_nlmsg_size() (CVE-2025-38588
    bsc#1248368).
  - commit 5b48674
  - ice: Fix a null pointer dereference in ice_copy_and_init_pkg()
    (CVE-2025-38664 bsc#1248628).
  - commit c056165

++++ kernel-rt:

  - scsi: ufs: ufs-pci: Fix default runtime and system PM levels
    (git-fixes).
  - scsi: ufs: ufs-pci: Fix hibernate state transition for Intel
    MTL-like host controllers (git-fixes).
  - scsi: ufs: core: Use link recovery when h8 exit fails during
    runtime resume (git-fixes).
  - scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE
    (git-fixes).
  - scsi: ufs: core: Fix spelling of a sysfs attribute name
    (git-fixes).
  - scsi: ufs: core: Fix clk scaling to be conditional in reset
    and restore (git-fixes).
  - scsi: ufs: core: Don't perform UFS clkscaling during host
    async scan (git-fixes).
  - scsi: ufs: mcq: Delete ufshcd_release_scsi_cmd() in
    ufshcd_mcq_abort() (git-fixes).
  - scsi: ufs: core: Remove redundant query_complete trace
    (git-fixes).
  - scsi: ufs: Introduce quirk to extend PA_HIBERN8TIME for UFS
    devices (git-fixes).
  - scsi: ufs: exynos: gs101: Put UFS device in reset on .suspend()
    (git-fixes).
  - scsi: ufs: exynos: Move phy calls to .exit() callback
    (git-fixes).
  - scsi: ufs: exynos: Enable PRDT pre-fetching with
    UFSHCD_CAP_CRYPTO (git-fixes).
  - scsi: ufs: exynos: Ensure consistent phy reference counts
    (git-fixes).
  - scsi: ufs: exynos: Move UFS shareability value to drvdata
    (git-fixes).
  - scsi: ufs: exynos: Ensure pre_link() executes before
    exynos_ufs_phy_init() (git-fixes).
  - scsi: ufs: qcom: fix dev reference leaked through
    of_qcom_ice_get (git-fixes).
  - scsi: ufs: core: Fix ufshcd_is_ufs_dev_busy() and
    ufshcd_eh_timed_out() (git-fixes).
  - scsi: ufs: core: Fix error return with query response
    (git-fixes).
  - scsi: ufs: Fix toggling of clk_gating.state when clock gating
    is not allowed (git-fixes).
  - scsi: ufs: bsg: Delete bsg_dev when setting up bsg fails
    (git-fixes).
  - scsi: ufs: qcom: Fix crypto key eviction (git-fixes).
  - scsi: ufs: core: Prepare to introduce a new clock_gating lock
    (git-fixes).
  - scsi: ufs: core: Introduce ufshcd_has_pending_tasks()
    (git-fixes).
  - scsi: ufs: core: Honor runtime/system PM levels if set by host
    controller drivers (git-fixes).
  - scsi: ufs: core: Update compl_time_stamp_local_clock after
    completing a cqe (git-fixes).
  - scsi: ufs: core: Add missing post notify for power mode change
    (git-fixes).
  - scsi: ufs: pltfrm: Drop PM runtime reference count after
    ufshcd_remove() (git-fixes).
  - scsi: ufs: pltfrm: Disable runtime PM during removal of glue
    drivers (git-fixes).
  - scsi: ufs: core: Add ufshcd_send_bsg_uic_cmd() for UFS BSG
    (git-fixes).
  - scsi: ufs: exynos: Fix hibern8 notify callbacks (git-fixes).
  - scsi: ufs: exynos: Add gs101_ufs_drv_init() hook and enable
    WriteBooster (git-fixes).
  - scsi: ufs: exynos: Add check inside exynos_ufs_config_smu()
    (git-fixes).
  - scsi: ufs: exynos: Remove superfluous function parameter
    (git-fixes).
  - scsi: ufs: exynos: Remove empty drv_init method (git-fixes).
  - scsi: ufs: core: Improve ufshcd_mcq_sq_cleanup() (git-fixes).
  - scsi: ufs: core: Always initialize the UIC done completion
    (git-fixes).
  - commit 80e8ae3
  - atm: atmtcp: Free invalid length skb in atmtcp_c_send() (CVE-2025-38185 bsc#1246012)
  - commit 481542d
  - s390/mm: Do not map lowcore with identity mapping (git-fixes
    bsc#1249066).
  - commit 8621600
  - s390/sclp: Fix SCCB present check (git-fixes bsc#1249065).
  - commit a696cb0
  - s390/time: Use monotonic clock in get_cycles() (git-fixes
    bsc#1249064).
  - commit d681db3
  - s390/stp: Remove udelay from stp_sync_clock() (git-fixes
    bsc#1249062).
  - commit 599898d
  - s390/early: Copy last breaking event address to pt_regs
    (git-fixes bsc#1249061).
  - commit 75fe912
  - Update config files: revive pwc driver for Leap (bsc#1249060)
  - commit 3eb97c1
  - ext4: remove writable userspace mappings before truncating
    page cache (bsc#1247223).
  - commit f42a012
  - mm: fix the inaccurate memory statistics issue for users
    (bsc#1244723).
  - commit cfde4ca
  - Refresh
    patches.suse/cpuidle-menu-Bias-selection-of-a-shallower-c-state-when-CPU-idles-for-IO.patch
    (bsc#1247935).
  - commit 1c15b68
  - nvmet: exit debugfs after discovery subsystem exits (git-fixes).
  - commit 12678fa
  - nvmet: initialize discovery subsys after debugfs is initialized
    (git-fixes).
  - nvme-pci: try function level reset on init failure (git-fixes).
  - nvme-tcp: log TLS handshake failures at error level (git-fixes).
  - commit b6c5818
  - ipv6: prevent infinite loop in rt6_nlmsg_size() (CVE-2025-38588
    bsc#1248368).
  - commit 5b48674
  - ice: Fix a null pointer dereference in ice_copy_and_init_pkg()
    (CVE-2025-38664 bsc#1248628).
  - commit c056165

++++ python-maturin:

  - Update vendor tarball to fix CVE-2025-58160 (bsc#1249011)

------------------------------------------------------------------
------------------  2025-9-1  -  Sep 1 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update warnings and errors related to "docker buildx ..." so that they
    reference our openSUSE docker-buildx packages.
    + cli-0001-openSUSE-point-users-to-docker-buildx-package.patch
  - Enable building docker-buildx for SLE15 systems with SUSEConnect secret
    injection enabled. PED-12534 PED-8905 bsc#1247594
    As docker-buildx does not support our SUSEConnect secret injection (and some
    users depend "docker build" working transparently), patch the docker CLI so
    that "docker build" will no longer automatically call "docker buildx build",
    effectively making DOCKER_BUILDKIT=0 the default configuration. Users can
    manually use "docker buildx ..." commands or set DOCKER_BUILDKIT=1 in order
    to opt-in to using docker-buildx.
    Users can silence the "docker build" warning by setting DOCKER_BUILDKIT=0
    explicitly.
    In order to inject SCC credentials with docker-buildx, users should use
    RUN --mount=type=secret,id=SCCcredentials zypper -n ...
    in their Dockerfiles, and
    docker buildx build --secret id=SCCcredentials,src=/etc/zypp/credentials.d/SCCcredentials,type=file .
    when doing their builds.
    + cli-0002-SECRETS-SUSE-default-to-DOCKER_BUILDKIT-0-for-docker.patch

++++ python-kiwi:

  - Fix rawhide integration test
    The package shim-ia32 got dropped
  - Add test for profiled overlays
    kiwi supports overlay files per profile, but we didn't had a
    proper integration test for it. This commit adds one
  - Mount proc when needed
    Using cp -a might lookup in proc/self/.. under certain conditions.
    Make sure to mount proc for config/function that might trigger
    this condition. This Fixes #2876
  - Update test-image-custom-partitions test build
    Fix patch files to match with new dracut module dirs
  - Update dracut version compat runtime check
    Update check_dracut_module_versions_compatible_to_kiwi to match
    with new dracut module dirs which have changed due to recommended
    dracut module ordering for out-of-tree modules.
  - Fix dracut Makefile install target
    module dir names have changed due to recommended dracut
    module ordering for out-of-tree modules.
  - Update pacman spec to dract changed module dirs
    Follow up change for the fix of the recommended dracut
    module ordering for out-of-tree modules.
  - Update spec file due to dract changed module dirs
    Follow up change for the fix of the recommended dracut
    module ordering for out-of-tree modules.

++++ kernel-default:

  - ring-buffer: Do not trigger WARN_ON() due to a commit_overrun (CVE-2025-38267 bsc#1246245)
  - commit 5cf9510
  - net: drv: netdevsim: don't napi_complete() from netpoll (CVE-2025-38270 bsc#1246252)
  - commit 42d34e9
  - HID: core: Harden s32ton() against conversion to 0 bits (CVE-2025-38556 bsc#1248296)
  - commit 69d7c6e
  - rxrpc: Fix bug due to prealloc collision (CVE-2025-38544 bsc#1248225)
  - commit c9a2e2d
  - net: libwx: fix the using of Rx buffer DMA (CVE-2025-38533 bsc#1248200)
  - commit 492149c
  - ice: add NULL check in eswitch lag check (CVE-2025-38526 bsc#1248192)
  - commit b5741b4
  - rxrpc: Fix oops due to non-existence of prealloc backlog struct (CVE-2025-38514 bsc#1248202)
  - commit b9aa197
  - idpf: return 0 size for RSS key if not supported (CVE-2025-38402 bsc#1247262)
  - commit 684be88
  - remoteproc: core: Release rproc->clean_table after rproc_attach() fails (CVE-2025-38418 bsc#1247137)
  - commit fcf59c8
  - remoteproc: core: Cleanup acquired resources when rproc_handle_resources() fails in rproc_attach() (CVE-2025-38419 bsc#1247136)
  - commit 081aa19
  - genirq/irq_sim: Initialize work context pointers properly (CVE-2025-38408 bsc#1247126)
  - commit e434c9f
  - ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() (CVE-2025-38456 bsc#1247099)
  - commit 411d2f8
  - perf: arm-ni: Fix missing platform_set_drvdata() (CVE-2025-38318 bsc#1246444)
  - commit a77d803
  - nvmem: zynqmp_nvmem: unbreak driver after cleanup (CVE-2025-38301 bsc#1246351)
  - commit cd1ecf3
  - perf: arm-ni: Unregister PMUs on probe failure (CVE-2025-38168 bsc#1245763)
  - commit b4e90d7
  - bcache: fix NULL pointer in cache_set_flush() (CVE-2025-38263 bsc#1246248)
  - commit 3f952c1
  - Update reference in patches.suse/lib-group_cpus-fix-NULL-pointer-dereference-from-gro.patch (CVE-2025-38255 bsc#1246190 bsc#1236897)
  - commit a85a300
  - xfs: do not propagate ENODATA disk errors into xattr code
    (git-fixes).
  - commit 15bf037
  - sunrpc: fix handling of server side tls alerts (bsc#1248374
    CVE-2025-38566).
  - commit c831a16
  - sunrpc: fix client side handling of tls alerts (bsc#1248401
    CVE-2025-38571).
  - commit a14a1e5
  - tracing/osnoise: Fix crash in timerlat_dump_stack() (CVE-2025-38493 bsc#1247283).
  - commit 5cbec5a
  - wifi: mac80211: reject TDLS operations when station is not
    associated (CVE-2025-38644 bsc#1248748).
  - commit f32351b
  - x86/bugs: Clean up SRSO microcode handling (git-fixes).
  - commit b9aaf6a
  - x86/bugs: Use IBPB for retbleed if used by SRSO (git-fixes).
  - commit 0f67ae1
  - x86/bugs: Add SRSO_MITIGATION_NOSMT (git-fixes).
  - commit 1d54073
  - EDAC/{i10nm,skx,skx_common}: Support UV systems (bsc#1234693).
  - Refresh
    patches.suse/EDAC-skx_common-i10nm-Fix-some-missing-error-reports.patch.
  - commit fd6b8c8
  - slab: Decouple slab_debug and no_hash_pointers (bsc#1249022).
  - commit 3da3d78
  - kABI fix after KVM: x86: Convert vcpu_run()'s immediate exit
    param into a generic bitmap (git-fixes).
  - commit f1ae006
  - KVM: x86: Convert vcpu_run()'s immediate exit param into a
    generic bitmap (git-fixes).
  - commit 59df1fc
  - s390/pci: Allow automatic recovery with minimal driver support
    (bsc#1248728 git-fixes).
  - commit de86836
  - s390/hypfs: Enable limited access during lockdown (bsc#1248727
    git-fixes).
  - s390/hypfs: Avoid unnecessary ioctl registration in debugfs
    (bsc#1248727 git-fixes).
  - commit 6f1ae11
  - kABI fix after KVM: VMX: Apply MMIO Stale Data mitigation if
    KVM maps MMIO into the guest (git-fixes).
  - commit f94bea5
  - KVM: VMX: Apply MMIO Stale Data mitigation if KVM maps MMIO
    into the guest (git-fixes).
  - commit d93b5c1
  - KVM: x86/mmu: Locally cache whether a PFN is host MMIO when
    making a SPTE (git-fixes).
  - commit b70d87b
  - RAS/AMD/FMPM: Get masked address (bsc#1242034).
  - commit e9e5ffb
  - RAS/AMD/ATL: Include row bit in row retirement (bsc#1242034).
  - commit 9ccbbc5
  - vhost/net: Protect ubufs with rcu read lock in
    vhost_net_ubuf_put() (git-fixes).
  - commit 61f61a5
  - vsock/virtio: Resize receive buffers so that each SKB fits in
    a 4K page (git-fixes).
  - commit b1b2e0f
  - ixgbe: fix ixgbe_orom_civd_info struct layout (bsc#1245410).
  - commit 16234f6
  - vhost: fail early when __vhost_add_used() fails (git-fixes).
  - commit 49782c5
  - vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1248511
    CVE-2025-38618).
  - commit e04e292
  - compiler: remove __ADDRESSABLE_ASM{_STR,}() again (git-fixes).
  - commit 470eca8
  - xen/netfront: Fix TX response spurious interrupts (git-fixes).
  - commit 1a84d61
  - PCI: Extend isolated function probing to LoongArch (git-fixes).
  - commit 0d2add0
  - vhost: Fix ioctl # for VHOST_[GS]ET_FORK_FROM_OWNER (git-fixes).
  - commit 6ddd657
  - gfs2: skip if we cannot defer delete (bsc#1247220).
  - gfs2: minor evict fix (bsc#1247220).
  - commit 24ae034
  - gfs2: Prevent inode creation race (2) (bsc#1247220).
  - gfs2: Replace GIF_DEFER_DELETE with GLF_DEFER_DELETE
    (bsc#1247220).
  - gfs2: Prevent inode creation race (bsc#1247220).
  - gfs2: Only defer deletes when we have an iopen glock
    (bsc#1247220).
  - gfs2: Simplify DLM_LKF_QUECVT use (bsc#1247220).
  - gfs2: gfs2_evict_inode clarification (bsc#1247220).
  - gfs2: Randomize GLF_VERIFY_DELETE work delay (bsc#1247220).
  - gfs2: Use mod_delayed_work in gfs2_queue_try_to_evict
    (bsc#1247220).
  - gfs2: Update to the evict / remote delete documentation
    (bsc#1247220).
  - gfs2: Call gfs2_queue_verify_delete from  gfs2_evict_inode
    (bsc#1247220).
  - gfs2: Clean up delete work processing (bsc#1247220).
  - gfs2: Minor delete_work_func cleanup (bsc#1247220).
  - gfs2: Return enum evict_behavior from  gfs2_upgrade_iopen_glock
    (bsc#1247220).
  - gfs2: Rename dinode_demise to evict_behavior (bsc#1247220).
  - gfs2: Rename GIF_{DEFERRED -> DEFER}_DELETE (bsc#1247220).
  - gfs2: Faster gfs2_upgrade_iopen_glock wakeups (bsc#1247220).
  - gfs2: Initialize gl_no_formal_ino earlier (bsc#1247220).
  - commit b3f7b8c

++++ kernel-rt:

  - ring-buffer: Do not trigger WARN_ON() due to a commit_overrun (CVE-2025-38267 bsc#1246245)
  - commit 5cf9510
  - net: drv: netdevsim: don't napi_complete() from netpoll (CVE-2025-38270 bsc#1246252)
  - commit 42d34e9
  - HID: core: Harden s32ton() against conversion to 0 bits (CVE-2025-38556 bsc#1248296)
  - commit 69d7c6e
  - rxrpc: Fix bug due to prealloc collision (CVE-2025-38544 bsc#1248225)
  - commit c9a2e2d
  - net: libwx: fix the using of Rx buffer DMA (CVE-2025-38533 bsc#1248200)
  - commit 492149c
  - ice: add NULL check in eswitch lag check (CVE-2025-38526 bsc#1248192)
  - commit b5741b4
  - rxrpc: Fix oops due to non-existence of prealloc backlog struct (CVE-2025-38514 bsc#1248202)
  - commit b9aa197
  - idpf: return 0 size for RSS key if not supported (CVE-2025-38402 bsc#1247262)
  - commit 684be88
  - remoteproc: core: Release rproc->clean_table after rproc_attach() fails (CVE-2025-38418 bsc#1247137)
  - commit fcf59c8
  - remoteproc: core: Cleanup acquired resources when rproc_handle_resources() fails in rproc_attach() (CVE-2025-38419 bsc#1247136)
  - commit 081aa19
  - genirq/irq_sim: Initialize work context pointers properly (CVE-2025-38408 bsc#1247126)
  - commit e434c9f
  - ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() (CVE-2025-38456 bsc#1247099)
  - commit 411d2f8
  - perf: arm-ni: Fix missing platform_set_drvdata() (CVE-2025-38318 bsc#1246444)
  - commit a77d803
  - nvmem: zynqmp_nvmem: unbreak driver after cleanup (CVE-2025-38301 bsc#1246351)
  - commit cd1ecf3
  - perf: arm-ni: Unregister PMUs on probe failure (CVE-2025-38168 bsc#1245763)
  - commit b4e90d7
  - bcache: fix NULL pointer in cache_set_flush() (CVE-2025-38263 bsc#1246248)
  - commit 3f952c1
  - Update reference in patches.suse/lib-group_cpus-fix-NULL-pointer-dereference-from-gro.patch (CVE-2025-38255 bsc#1246190 bsc#1236897)
  - commit a85a300
  - xfs: do not propagate ENODATA disk errors into xattr code
    (git-fixes).
  - commit 15bf037
  - sunrpc: fix handling of server side tls alerts (bsc#1248374
    CVE-2025-38566).
  - commit c831a16
  - sunrpc: fix client side handling of tls alerts (bsc#1248401
    CVE-2025-38571).
  - commit a14a1e5
  - tracing/osnoise: Fix crash in timerlat_dump_stack() (CVE-2025-38493 bsc#1247283).
  - commit 5cbec5a
  - wifi: mac80211: reject TDLS operations when station is not
    associated (CVE-2025-38644 bsc#1248748).
  - commit f32351b
  - x86/bugs: Clean up SRSO microcode handling (git-fixes).
  - commit b9aaf6a
  - x86/bugs: Use IBPB for retbleed if used by SRSO (git-fixes).
  - commit 0f67ae1
  - x86/bugs: Add SRSO_MITIGATION_NOSMT (git-fixes).
  - commit 1d54073
  - EDAC/{i10nm,skx,skx_common}: Support UV systems (bsc#1234693).
  - Refresh
    patches.suse/EDAC-skx_common-i10nm-Fix-some-missing-error-reports.patch.
  - commit fd6b8c8
  - slab: Decouple slab_debug and no_hash_pointers (bsc#1249022).
  - commit 3da3d78
  - kABI fix after KVM: x86: Convert vcpu_run()'s immediate exit
    param into a generic bitmap (git-fixes).
  - commit f1ae006
  - KVM: x86: Convert vcpu_run()'s immediate exit param into a
    generic bitmap (git-fixes).
  - commit 59df1fc
  - s390/pci: Allow automatic recovery with minimal driver support
    (bsc#1248728 git-fixes).
  - commit de86836
  - s390/hypfs: Enable limited access during lockdown (bsc#1248727
    git-fixes).
  - s390/hypfs: Avoid unnecessary ioctl registration in debugfs
    (bsc#1248727 git-fixes).
  - commit 6f1ae11
  - kABI fix after KVM: VMX: Apply MMIO Stale Data mitigation if
    KVM maps MMIO into the guest (git-fixes).
  - commit f94bea5
  - KVM: VMX: Apply MMIO Stale Data mitigation if KVM maps MMIO
    into the guest (git-fixes).
  - commit d93b5c1
  - KVM: x86/mmu: Locally cache whether a PFN is host MMIO when
    making a SPTE (git-fixes).
  - commit b70d87b
  - RAS/AMD/FMPM: Get masked address (bsc#1242034).
  - commit e9e5ffb
  - RAS/AMD/ATL: Include row bit in row retirement (bsc#1242034).
  - commit 9ccbbc5
  - vhost/net: Protect ubufs with rcu read lock in
    vhost_net_ubuf_put() (git-fixes).
  - commit 61f61a5
  - vsock/virtio: Resize receive buffers so that each SKB fits in
    a 4K page (git-fixes).
  - commit b1b2e0f
  - ixgbe: fix ixgbe_orom_civd_info struct layout (bsc#1245410).
  - commit 16234f6
  - vhost: fail early when __vhost_add_used() fails (git-fixes).
  - commit 49782c5
  - vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1248511
    CVE-2025-38618).
  - commit e04e292
  - compiler: remove __ADDRESSABLE_ASM{_STR,}() again (git-fixes).
  - commit 470eca8
  - xen/netfront: Fix TX response spurious interrupts (git-fixes).
  - commit 1a84d61
  - PCI: Extend isolated function probing to LoongArch (git-fixes).
  - commit 0d2add0
  - vhost: Fix ioctl # for VHOST_[GS]ET_FORK_FROM_OWNER (git-fixes).
  - commit 6ddd657
  - gfs2: skip if we cannot defer delete (bsc#1247220).
  - gfs2: minor evict fix (bsc#1247220).
  - commit 24ae034
  - gfs2: Prevent inode creation race (2) (bsc#1247220).
  - gfs2: Replace GIF_DEFER_DELETE with GLF_DEFER_DELETE
    (bsc#1247220).
  - gfs2: Prevent inode creation race (bsc#1247220).
  - gfs2: Only defer deletes when we have an iopen glock
    (bsc#1247220).
  - gfs2: Simplify DLM_LKF_QUECVT use (bsc#1247220).
  - gfs2: gfs2_evict_inode clarification (bsc#1247220).
  - gfs2: Randomize GLF_VERIFY_DELETE work delay (bsc#1247220).
  - gfs2: Use mod_delayed_work in gfs2_queue_try_to_evict
    (bsc#1247220).
  - gfs2: Update to the evict / remote delete documentation
    (bsc#1247220).
  - gfs2: Call gfs2_queue_verify_delete from  gfs2_evict_inode
    (bsc#1247220).
  - gfs2: Clean up delete work processing (bsc#1247220).
  - gfs2: Minor delete_work_func cleanup (bsc#1247220).
  - gfs2: Return enum evict_behavior from  gfs2_upgrade_iopen_glock
    (bsc#1247220).
  - gfs2: Rename dinode_demise to evict_behavior (bsc#1247220).
  - gfs2: Rename GIF_{DEFERRED -> DEFER}_DELETE (bsc#1247220).
  - gfs2: Faster gfs2_upgrade_iopen_glock wakeups (bsc#1247220).
  - gfs2: Initialize gl_no_formal_ino earlier (bsc#1247220).
  - commit b3f7b8c

------------------------------------------------------------------
------------------  2025-8-31  -  Aug 31 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Follow the recommended dracut module ordering for out-of-tree modules
    In dracut release v108 or later the recommended ordering
    for out out of tree modules is 50-59 range. The following is a section from dracut documentation:
    > Not using the 50-59 range for out of tree dracut modules will likely
    > lead to unintended errors in the initramfs generation process as your
    > dracut module will either run too early or too late in the generation process.
    > You have been warned.

++++ kernel-default:

  - Update
    patches.suse/ASoC-mediatek-mt8365-dai-i2s-pass-correct-size-to-mt.patch
    (git-fixes CVE-2025-38662 bsc#1248635).
  - Update
    patches.suse/HID-apple-validate-feature-report-field-count-to-pre.patch
    (git-fixes CVE-2025-38557 bsc#1248304).
  - Update
    patches.suse/KVM-Allow-CPU-to-reschedule-while-setting-per-page-m.patch
    (git-fixes CVE-2025-38506 bsc#1248186).
  - Update
    patches.suse/PCI-pnv_php-Clean-up-allocated-IRQs-on-unplug.patch
    (bsc#1215199 CVE-2025-38624 bsc#1248617).
  - Update
    patches.suse/PM-devfreq-Check-governor-before-using-governor-name.patch
    (git-fixes CVE-2025-38609 bsc#1248337).
  - Update
    patches.suse/RDMA-hns-Fix-double-destruction-of-rsv_qp.patch
    (git-fixes CVE-2025-38582 bsc#1248349).
  - Update
    patches.suse/arm64-entry-Mask-DAIF-in-cpu_switch_to-call_on_irq_stack.patch
    (git-fixes CVE-2025-38670 bsc#1248655).
  - Update
    patches.suse/bpf-Reject-narrower-access-to-pointer-ctx-fields.patch
    (git-fixes CVE-2025-38591 bsc#1248363).
  - Update
    patches.suse/bpf-Reject-p-format-string-in-bprintf-like-helpers.patch
    (git-fixes CVE-2025-38528 bsc#1248198).
  - Update
    patches.suse/bpf-arm64-Fix-fp-initialization-for-exception-boundary.patch
    (git-fixes CVE-2025-38586 bsc#1248359).
  - Update
    patches.suse/btrfs-fix-assertion-when-building-free-space-tree.patch
    (git-fixes CVE-2025-38503 bsc#1248183).
  - Update
    patches.suse/can-netlink-can_changelink-fix-NULL-pointer-deref-of.patch
    (git-fixes CVE-2025-38665 bsc#1248648).
  - Update
    patches.suse/clk-davinci-Add-NULL-check-in-davinci_lpsc_clk_regis.patch
    (git-fixes CVE-2025-38635 bsc#1248573).
  - Update
    patches.suse/clk-imx95-blk-ctl-Fix-synchronous-abort.patch
    (git-fixes CVE-2025-38631 bsc#1248662).
  - Update
    patches.suse/clk-xilinx-vcu-unregister-pll_post-only-if-registere.patch
    (git-fixes CVE-2025-38583 bsc#1248350).
  - Update
    patches.suse/crypto-ccp-Fix-crash-when-rebind-ccp-device-for-ccp..patch
    (git-fixes CVE-2025-38581 bsc#1248345).
  - Update
    patches.suse/fbdev-imxfb-Check-fb_add_videomode-to-prevent-null-p.patch
    (git-fixes CVE-2025-38630 bsc#1248575).
  - Update
    patches.suse/i2c-qup-jump-out-of-the-loop-in-case-of-timeout.patch
    (git-fixes CVE-2025-38671 bsc#1248652).
  - Update
    patches.suse/iio-common-st_sensors-Fix-use-of-uninitialize-device.patch
    (stable-fixes CVE-2025-38531 bsc#1248205).
  - Update
    patches.suse/ipv6-fix-possible-infinite-loop-in-fib6_info_uses_de.patch
    (git-fixes CVE-2025-38587 bsc#1248361).
  - Update
    patches.suse/ipv6-prevent-infinite-loop-in-rt6_nlmsg_size.patch
    (git-fixes CVE-2025-38588 bsc#1248368).
  - Update
    patches.suse/ipv6-reject-malicious-packets-in-ipv6_gso_segment.patch
    (git-fixes CVE-2025-38572 bsc#1248399).
  - Update
    patches.suse/iwlwifi-Add-missing-check-for-alloc_ordered_workqueu.patch
    (git-fixes CVE-2025-38602 bsc#1248341).
  - Update
    patches.suse/md-make-rdev_addable-usable-for-rcu-mode.patch
    (git-fixes CVE-2025-38621 bsc#1248609).
  - Update
    patches.suse/media-ti-j721e-csi2rx-fix-list_del-corruption.patch
    (git-fixes CVE-2025-38619 bsc#1248664).
  - Update
    patches.suse/net-packet-fix-a-race-in-packet_set_ring-and-packet_.patch
    (git-fixes CVE-2025-38617 bsc#1248621).
  - Update
    patches.suse/net-sched-Restrict-conditions-for-adding-duplicating.patch
    (git-fixes CVE-2025-38553 bsc#1248255).
  - Update
    patches.suse/net-sched-mqprio-fix-stack-out-of-bounds-write-in-tc.patch
    (git-fixes CVE-2025-38568 bsc#1248386).
  - Update
    patches.suse/nvmet-pci-epf-Do-not-complete-commands-twice-if-nvme.patch
    (git-fixes CVE-2025-38658 bsc#1248627).
  - Update patches.suse/perf-core-Exit-early-on-perf_mmap-fail.patch
    (CVE-2025-38563 bsc#1248306 dependency CVE-2025-38565
    bsc#1248377).
  - Update
    patches.suse/perf-core-Handle-buffer-mapping-fail-correctly-in-perf_mma.patch
    (CVE-2025-38563 bsc#1248306 dependency CVE-2025-38564
    bsc#1248367).
  - Update
    patches.suse/pinmux-fix-race-causing-mux_owner-NULL-with-active-m.patch
    (git-fixes CVE-2025-38632 bsc#1248669).
  - Update
    patches.suse/power-supply-cpcap-charger-Fix-null-check-for-power_.patch
    (git-fixes CVE-2025-38634 bsc#1248666).
  - Update
    patches.suse/powercap-dtpm_cpu-Fix-NULL-pointer-dereference-in-ge.patch
    (git-fixes CVE-2025-38610 bsc#1248395).
  - Update
    patches.suse/powerpc-eeh-Make-EEH-driver-device-hotplug-safe.patch
    (bsc#1215199 CVE-2025-38576 bsc#1248354).
  - Update
    patches.suse/regulator-core-fix-NULL-dereference-on-unbind-due-to.patch
    (stable-fixes CVE-2025-38668 bsc#1248647).
  - Update
    patches.suse/spi-cs42l43-Property-entry-should-be-a-null-terminat.patch
    (bsc#1246979 CVE-2025-38573 bsc#1248396).
  - Update
    patches.suse/spi-stm32-Check-for-cfg-availability-in-stm32_spi_pr.patch
    (git-fixes CVE-2025-38648 bsc#1248624).
  - Update
    patches.suse/staging-fbtft-fix-potential-memory-leak-in-fbtft_fra.patch
    (git-fixes CVE-2025-38612 bsc#1248390).
  - Update
    patches.suse/staging-media-atomisp-Fix-stack-buffer-overflow-in-g.patch
    (git-fixes CVE-2025-38585 bsc#1248355).
  - Update
    patches.suse/sunrpc-fix-client-side-handling-of-tls-alerts.patch
    (git-fixes CVE-2025-38571 bsc#1248401).
  - Update
    patches.suse/sunrpc-fix-handling-of-server-side-tls-alerts.patch
    (git-fixes CVE-2025-38566 bsc#1248374).
  - Update
    patches.suse/usb-gadget-fix-use-after-free-in-composite_dev_clean.patch
    (git-fixes CVE-2025-38555 bsc#1248297).
  - Update
    patches.suse/wifi-ath11k-clear-initialized-flag-for-deinit-ed-srn.patch
    (git-fixes CVE-2025-38601 bsc#1248340).
  - Update
    patches.suse/wifi-ath12k-Pass-ab-pointer-directly-to-ath12k_dp_tx.patch
    (git-fixes CVE-2025-38605 bsc#1248334).
  - Update
    patches.suse/wifi-iwlwifi-Fix-error-code-in-iwl_op_mode_dvm_start.patch
    (git-fixes CVE-2025-38656 bsc#1248643).
  - Update
    patches.suse/wifi-mac80211-reject-TDLS-operations-when-station-is.patch
    (git-fixes CVE-2025-38644 bsc#1248748).
  - Update
    patches.suse/wifi-rtl818x-Kill-URBs-before-clearing-tx-status-que.patch
    (git-fixes CVE-2025-38604 bsc#1248333).
  - Update
    patches.suse/wifi-rtw89-avoid-NULL-dereference-when-RX-problemati.patch
    (git-fixes CVE-2025-38646 bsc#1248577).
  - Update patches.suse/xen-fix-UAF-in-dmabuf_exp_from_pages.patch
    (git-fixes CVE-2025-38595 bsc#1248380).
  - commit ab6edaf

++++ kernel-rt:

  - Update
    patches.suse/ASoC-mediatek-mt8365-dai-i2s-pass-correct-size-to-mt.patch
    (git-fixes CVE-2025-38662 bsc#1248635).
  - Update
    patches.suse/HID-apple-validate-feature-report-field-count-to-pre.patch
    (git-fixes CVE-2025-38557 bsc#1248304).
  - Update
    patches.suse/KVM-Allow-CPU-to-reschedule-while-setting-per-page-m.patch
    (git-fixes CVE-2025-38506 bsc#1248186).
  - Update
    patches.suse/PCI-pnv_php-Clean-up-allocated-IRQs-on-unplug.patch
    (bsc#1215199 CVE-2025-38624 bsc#1248617).
  - Update
    patches.suse/PM-devfreq-Check-governor-before-using-governor-name.patch
    (git-fixes CVE-2025-38609 bsc#1248337).
  - Update
    patches.suse/RDMA-hns-Fix-double-destruction-of-rsv_qp.patch
    (git-fixes CVE-2025-38582 bsc#1248349).
  - Update
    patches.suse/arm64-entry-Mask-DAIF-in-cpu_switch_to-call_on_irq_stack.patch
    (git-fixes CVE-2025-38670 bsc#1248655).
  - Update
    patches.suse/bpf-Reject-narrower-access-to-pointer-ctx-fields.patch
    (git-fixes CVE-2025-38591 bsc#1248363).
  - Update
    patches.suse/bpf-Reject-p-format-string-in-bprintf-like-helpers.patch
    (git-fixes CVE-2025-38528 bsc#1248198).
  - Update
    patches.suse/bpf-arm64-Fix-fp-initialization-for-exception-boundary.patch
    (git-fixes CVE-2025-38586 bsc#1248359).
  - Update
    patches.suse/btrfs-fix-assertion-when-building-free-space-tree.patch
    (git-fixes CVE-2025-38503 bsc#1248183).
  - Update
    patches.suse/can-netlink-can_changelink-fix-NULL-pointer-deref-of.patch
    (git-fixes CVE-2025-38665 bsc#1248648).
  - Update
    patches.suse/clk-davinci-Add-NULL-check-in-davinci_lpsc_clk_regis.patch
    (git-fixes CVE-2025-38635 bsc#1248573).
  - Update
    patches.suse/clk-imx95-blk-ctl-Fix-synchronous-abort.patch
    (git-fixes CVE-2025-38631 bsc#1248662).
  - Update
    patches.suse/clk-xilinx-vcu-unregister-pll_post-only-if-registere.patch
    (git-fixes CVE-2025-38583 bsc#1248350).
  - Update
    patches.suse/crypto-ccp-Fix-crash-when-rebind-ccp-device-for-ccp..patch
    (git-fixes CVE-2025-38581 bsc#1248345).
  - Update
    patches.suse/fbdev-imxfb-Check-fb_add_videomode-to-prevent-null-p.patch
    (git-fixes CVE-2025-38630 bsc#1248575).
  - Update
    patches.suse/i2c-qup-jump-out-of-the-loop-in-case-of-timeout.patch
    (git-fixes CVE-2025-38671 bsc#1248652).
  - Update
    patches.suse/iio-common-st_sensors-Fix-use-of-uninitialize-device.patch
    (stable-fixes CVE-2025-38531 bsc#1248205).
  - Update
    patches.suse/ipv6-fix-possible-infinite-loop-in-fib6_info_uses_de.patch
    (git-fixes CVE-2025-38587 bsc#1248361).
  - Update
    patches.suse/ipv6-prevent-infinite-loop-in-rt6_nlmsg_size.patch
    (git-fixes CVE-2025-38588 bsc#1248368).
  - Update
    patches.suse/ipv6-reject-malicious-packets-in-ipv6_gso_segment.patch
    (git-fixes CVE-2025-38572 bsc#1248399).
  - Update
    patches.suse/iwlwifi-Add-missing-check-for-alloc_ordered_workqueu.patch
    (git-fixes CVE-2025-38602 bsc#1248341).
  - Update
    patches.suse/md-make-rdev_addable-usable-for-rcu-mode.patch
    (git-fixes CVE-2025-38621 bsc#1248609).
  - Update
    patches.suse/media-ti-j721e-csi2rx-fix-list_del-corruption.patch
    (git-fixes CVE-2025-38619 bsc#1248664).
  - Update
    patches.suse/net-packet-fix-a-race-in-packet_set_ring-and-packet_.patch
    (git-fixes CVE-2025-38617 bsc#1248621).
  - Update
    patches.suse/net-sched-Restrict-conditions-for-adding-duplicating.patch
    (git-fixes CVE-2025-38553 bsc#1248255).
  - Update
    patches.suse/net-sched-mqprio-fix-stack-out-of-bounds-write-in-tc.patch
    (git-fixes CVE-2025-38568 bsc#1248386).
  - Update
    patches.suse/nvmet-pci-epf-Do-not-complete-commands-twice-if-nvme.patch
    (git-fixes CVE-2025-38658 bsc#1248627).
  - Update patches.suse/perf-core-Exit-early-on-perf_mmap-fail.patch
    (CVE-2025-38563 bsc#1248306 dependency CVE-2025-38565
    bsc#1248377).
  - Update
    patches.suse/perf-core-Handle-buffer-mapping-fail-correctly-in-perf_mma.patch
    (CVE-2025-38563 bsc#1248306 dependency CVE-2025-38564
    bsc#1248367).
  - Update
    patches.suse/pinmux-fix-race-causing-mux_owner-NULL-with-active-m.patch
    (git-fixes CVE-2025-38632 bsc#1248669).
  - Update
    patches.suse/power-supply-cpcap-charger-Fix-null-check-for-power_.patch
    (git-fixes CVE-2025-38634 bsc#1248666).
  - Update
    patches.suse/powercap-dtpm_cpu-Fix-NULL-pointer-dereference-in-ge.patch
    (git-fixes CVE-2025-38610 bsc#1248395).
  - Update
    patches.suse/powerpc-eeh-Make-EEH-driver-device-hotplug-safe.patch
    (bsc#1215199 CVE-2025-38576 bsc#1248354).
  - Update
    patches.suse/regulator-core-fix-NULL-dereference-on-unbind-due-to.patch
    (stable-fixes CVE-2025-38668 bsc#1248647).
  - Update
    patches.suse/spi-cs42l43-Property-entry-should-be-a-null-terminat.patch
    (bsc#1246979 CVE-2025-38573 bsc#1248396).
  - Update
    patches.suse/spi-stm32-Check-for-cfg-availability-in-stm32_spi_pr.patch
    (git-fixes CVE-2025-38648 bsc#1248624).
  - Update
    patches.suse/staging-fbtft-fix-potential-memory-leak-in-fbtft_fra.patch
    (git-fixes CVE-2025-38612 bsc#1248390).
  - Update
    patches.suse/staging-media-atomisp-Fix-stack-buffer-overflow-in-g.patch
    (git-fixes CVE-2025-38585 bsc#1248355).
  - Update
    patches.suse/sunrpc-fix-client-side-handling-of-tls-alerts.patch
    (git-fixes CVE-2025-38571 bsc#1248401).
  - Update
    patches.suse/sunrpc-fix-handling-of-server-side-tls-alerts.patch
    (git-fixes CVE-2025-38566 bsc#1248374).
  - Update
    patches.suse/usb-gadget-fix-use-after-free-in-composite_dev_clean.patch
    (git-fixes CVE-2025-38555 bsc#1248297).
  - Update
    patches.suse/wifi-ath11k-clear-initialized-flag-for-deinit-ed-srn.patch
    (git-fixes CVE-2025-38601 bsc#1248340).
  - Update
    patches.suse/wifi-ath12k-Pass-ab-pointer-directly-to-ath12k_dp_tx.patch
    (git-fixes CVE-2025-38605 bsc#1248334).
  - Update
    patches.suse/wifi-iwlwifi-Fix-error-code-in-iwl_op_mode_dvm_start.patch
    (git-fixes CVE-2025-38656 bsc#1248643).
  - Update
    patches.suse/wifi-mac80211-reject-TDLS-operations-when-station-is.patch
    (git-fixes CVE-2025-38644 bsc#1248748).
  - Update
    patches.suse/wifi-rtl818x-Kill-URBs-before-clearing-tx-status-que.patch
    (git-fixes CVE-2025-38604 bsc#1248333).
  - Update
    patches.suse/wifi-rtw89-avoid-NULL-dereference-when-RX-problemati.patch
    (git-fixes CVE-2025-38646 bsc#1248577).
  - Update patches.suse/xen-fix-UAF-in-dmabuf_exp_from_pages.patch
    (git-fixes CVE-2025-38595 bsc#1248380).
  - commit ab6edaf

------------------------------------------------------------------
------------------  2025-8-30  -  Aug 30 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - efi: stmm: Fix incorrect buffer allocation method (git-fixes).
  - HID: asus: fix UAF via HID_CLAIMED_INPUT validation (git-fixes).
  - HID: multitouch: fix slab out-of-bounds access in
    mt_report_fixup() (git-fixes).
  - drm/mediatek: Fix device/node reference count leaks in
    mtk_drm_get_all_drm_priv (git-fixes).
  - drm/mediatek: Add error handling for old state CRTC in
    atomic_disable (git-fixes).
  - drm/msm: update the high bitfield of certain DSI registers
    (git-fixes).
  - drm/msm/kms: move snapshot init earlier in KMS init (git-fixes).
  - drm/msm: Defer fd_install in SUBMIT ioctl (git-fixes).
  - drm/nouveau: remove unused memory target test (git-fixes).
  - drm/nouveau: remove unused increment in gm200_flcn_pio_imem_wr
    (git-fixes).
  - drm/nouveau: fix error path in nvkm_gsp_fwsec_v2 (git-fixes).
  - drm/nouveau/disp: Always accept linear modifier (git-fixes).
  - drm/xe: Don't trigger rebind on initial dma-buf validation
    (git-fixes).
  - drm/xe/vm: Clear the scratch_pt pointer on error (git-fixes).
  - drm/xe/xe_sync: avoid race during ufence signaling (git-fixes).
  - Bluetooth: hci_sync: fix set_local_name race condition
    (git-fixes).
  - Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is
    unbalanced (git-fixes).
  - Bluetooth: hci_event: Mark connection as closed during suspend
    disconnect (git-fixes).
  - Bluetooth: hci_event: Treat UNKNOWN_CONN_ID on disconnect as
    success (git-fixes).
  - drm/hisilicon/hibmc: fix the i2c device resource leak when
    vdac init failed (git-fixes).
  - drm/hisilicon/hibmc: refactored struct hibmc_drm_private
    (stable-fixes).
  - commit 3cc6741

++++ kernel-rt:

  - efi: stmm: Fix incorrect buffer allocation method (git-fixes).
  - HID: asus: fix UAF via HID_CLAIMED_INPUT validation (git-fixes).
  - HID: multitouch: fix slab out-of-bounds access in
    mt_report_fixup() (git-fixes).
  - drm/mediatek: Fix device/node reference count leaks in
    mtk_drm_get_all_drm_priv (git-fixes).
  - drm/mediatek: Add error handling for old state CRTC in
    atomic_disable (git-fixes).
  - drm/msm: update the high bitfield of certain DSI registers
    (git-fixes).
  - drm/msm/kms: move snapshot init earlier in KMS init (git-fixes).
  - drm/msm: Defer fd_install in SUBMIT ioctl (git-fixes).
  - drm/nouveau: remove unused memory target test (git-fixes).
  - drm/nouveau: remove unused increment in gm200_flcn_pio_imem_wr
    (git-fixes).
  - drm/nouveau: fix error path in nvkm_gsp_fwsec_v2 (git-fixes).
  - drm/nouveau/disp: Always accept linear modifier (git-fixes).
  - drm/xe: Don't trigger rebind on initial dma-buf validation
    (git-fixes).
  - drm/xe/vm: Clear the scratch_pt pointer on error (git-fixes).
  - drm/xe/xe_sync: avoid race during ufence signaling (git-fixes).
  - Bluetooth: hci_sync: fix set_local_name race condition
    (git-fixes).
  - Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is
    unbalanced (git-fixes).
  - Bluetooth: hci_event: Mark connection as closed during suspend
    disconnect (git-fixes).
  - Bluetooth: hci_event: Treat UNKNOWN_CONN_ID on disconnect as
    success (git-fixes).
  - drm/hisilicon/hibmc: fix the i2c device resource leak when
    vdac init failed (git-fixes).
  - drm/hisilicon/hibmc: refactored struct hibmc_drm_private
    (stable-fixes).
  - commit 3cc6741

++++ harfbuzz:

  - Update to version 11.4.5:
    + Bug fixes for “AAT” shaping, and other shaping micro
    optimizations.

------------------------------------------------------------------
------------------  2025-8-29  -  Aug 29 2025  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Update to version 2.0.14:
    + This release adds the following features:
  - Add support for ignoring the network connectivity requirement
  - Allow building on RHEL-9 and RHEL-10
  - Allow plugins to know the firmware version during update
  - Allow UEFI capsule devices to opt-out of Capsule-on-Disk
  - Allow unsetting HwID plugin context flags
  - Allow upgrading from a zero "empty" UEFI dbx
    + This release fixes the following bugs:
  - Add an automatic firehose counterpart to the QCDM modem device
  - Disable signature time checks when verifying firmware
  - Do not add a vendor ID of UNKNOWN when the signature has no vendor
  - Do not discover ThunderBolt retimer devices when run in single-shot mode
  - Do not use deprecated libflashrom API
  - Enhance firmware metadata generation in firmware_packager
  - Ensure Lexar NVMe drives use a proper version number
  - Fix parsing and writing UF2 extension sections
  - Fix Synaptics RMI initialization for new devices
  - Fix updating DFOTA and MBIM modem devices
  - Move some vendor name fixups to the quirk file
  - Remove CapsuleOnDisk HwID match for Dell
  - Return a sensible error when using build-cabinet wrong
  - Set the firehose loader filename in a more permissive way
  - Update the mapping for TPM vendor names
  - Verify the checksum of the serialized data in tests
  - Work around a libmbim bug when detaching
    + This release adds support for the following hardware:
  - Egis MoC devices
  - Framework QMK devices
  - ILITEK touch controllers
  - SteelSeries Arctis Nova 3P

++++ kernel-default:

  - Refresh
    patches.suse/kdump-add-crashkernel-cma-suffix.patch
    patches.suse/kdump-crashkernel-cma-update-Documentation.patch
    patches.suse/kdump-implement-reserve_crashkernel_cma.patch
    patches.suse/kdump-wait-for-dma-to-time-out-when-using-cma.patch
    patches.suse/kdump-x86-implement-crashkernel-cma-reservation.patch
    (jsc#PED-7249 implementation now upstream).
  - commit f57031a
  - clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() (CVE-2025-38160 bsc#1245780)
  - commit a306e30
  - tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer (CVE-2025-38184 bsc#1245956)
  - commit ea5f7f7
  - drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 (CVE-2025-38205 bsc#1246005)
  - commit ca56750
  - smb: client: add NULL check in automount_fullpath (CVE-2025-38208 bsc#1245815)
  - commit cb3a2bf
  - net: stmmac: make sure that ptp_rate is not 0 before configuring EST (CVE-2025-38125 bsc#1245710)
  - commit 04509ac
  - block: Make REQ_OP_ZONE_FINISH a write operation (git-fixes, bsc#1249552).
  - blacklist.conf: remove 3f66ccbaaef3
    mwilck: this commit is a necessary part of an upstream fix series.
    See comments in block-Make-REQ_OP_ZONE_FINISH-a-write-operation.patch.
  - commit 5f975b1
  - dm: split write BIOs on zone boundaries when zone append is
    not emulated (git-fixes).
  - commit 68ed6f4
  - dm: Always split write BIOs to zoned device limits (git-fixes, CVE-2025-39792, bsc#1249618).
  - commit a8b835f
  - dm: dm-crypt: Do not partially accept write BIOs with zoned
    targets (git-fixes, CVE-2025-39791, bsc#1249550).
  - commit d7f2e88
  - dm: Check for forbidden splitting of zone write operations
    (git-fixes).
  - commit f3bd28c
  - dm-stripe: limit chunk_sectors to the stripe size (git-fixes).
  - commit a008640
  - kernel-binary: Another installation ordering fix (bsc#1241353).
  - commit fe14ab5
  - dm-table: fix checking for rq stackable devices (git-fixes).
  - commit c0133c8
  - dm-mpath: don't print the "loaded" message if registering fails
    (git-fixes).
  - commit d2cfeaf
  - md: dm-zoned-target: Initialize return variable r to avoid
    uninitialized use (git-fixes).
  - commit c0e418a
  - iio: imu: inv_icm42600: change invalid data error to -EBUSY
    (git-fixes).
  - commit e4f8b35
  - drm/amdgpu: fix task hang from failed job submission during
    process kill (git-fixes).
  - commit 6f325ab
  - iio: light: as73211: Ensure buffer holes are zeroed (git-fixes).
  - usb: dwc3: Remove WARN_ON for device endpoint command timeouts
    (stable-fixes).
  - USB: storage: Ignore driver CD mode for Realtek multi-mode
    Wi-Fi dongles (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Wildcat Lake
    (stable-fixes).
  - USB: storage: Add unusual-devs entry for Novatek NTK96550-based
    camera (stable-fixes).
  - usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1
    Flash Drive (stable-fixes).
  - drm/amd/display: Fix DP audio DTO1 clock source on DCE 6
    (stable-fixes).
  - drm/amd/display: Fill display clock and vblank time in
    dce110_fill_display_configs (stable-fixes).
  - drm/amd/display: Find first CRTC and its line time in
    dce110_fill_display_configs (stable-fixes).
  - drm/amd/display: Fix Xorg desktop unresponsive on Replay panel
    (stable-fixes).
  - drm/amd/display: Avoid a NULL pointer dereference
    (stable-fixes).
  - drm/amdgpu/swm14: Update power limit logic (stable-fixes).
  - ALSA: hda/realtek: Add support for HP EliteBook x360 830 G6
    and EliteBook 830 G6 (stable-fixes).
  - drm/amdkfd: Destroy KFD debugfs after destroy KFD wq
    (stable-fixes).
  - amdgpu/amdgpu_discovery: increase timeout limit for IFWI init
    (stable-fixes).
  - drm/amd/display: fix a Null pointer dereference vulnerability
    (stable-fixes).
  - drm/amd/display: Add primary plane to commits for correct VRR
    handling (stable-fixes).
  - drm/amdgpu: update mmhub 3.0.1 client id mappings
    (stable-fixes).
  - drm/amd: Restore cached power limit during resume
    (stable-fixes).
  - drm/amdgpu: Update external revid for GC v9.5.0 (stable-fixes).
  - drm/amdgpu: update mmhub 4.1.0 client id mappings
    (stable-fixes).
  - drm/amdgpu: Avoid extra evict-restore process (stable-fixes).
  - drm/amdgpu: check if hubbub is NULL in
    debugfs/amdgpu_dm_capabilities (stable-fixes).
  - pwm: mediatek: Fix duty and period setting (git-fixes).
  - pwm: mediatek: Handle hardware enable and clock enable
    separately (stable-fixes).
  - crypto: qat - lower priority for skcipher and aead algorithms
    (stable-fixes).
  - crypto: octeontx2 - Fix address alignment on CN10KB and
    CN10KA-B0 (stable-fixes).
  - crypto: octeontx2 - Fix address alignment on CN10K A0/A1 and
    OcteonTX2 (stable-fixes).
  - crypto: octeontx2 - Fix address alignment issue on ucode loading
    (stable-fixes).
  - drm/dp: Change AUX DPCD probe address from DPCD_REV to
    LANE0_1_STATUS (stable-fixes).
  - iio: imu: inv_icm42600: use = { } instead of memset()
    (stable-fixes).
  - drm/format-helper: Add conversion from XRGB8888 to BGR888
    (stable-fixes).
  - iio: imu: inv_icm42600: switch timestamp type from int64_t
    __aligned(8) to aligned_s64 (stable-fixes).
  - iio: light: Use aligned_s64 instead of open coding alignment
    (stable-fixes).
  - commit 60c07db
  - net: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting
    for skb_shared_info (CVE-2025-38545 bsc#1248224).
  - commit af6b2ae

++++ kernel-rt:

  - Refresh
    patches.suse/kdump-add-crashkernel-cma-suffix.patch
    patches.suse/kdump-crashkernel-cma-update-Documentation.patch
    patches.suse/kdump-implement-reserve_crashkernel_cma.patch
    patches.suse/kdump-wait-for-dma-to-time-out-when-using-cma.patch
    patches.suse/kdump-x86-implement-crashkernel-cma-reservation.patch
    (jsc#PED-7249 implementation now upstream).
  - commit f57031a
  - clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() (CVE-2025-38160 bsc#1245780)
  - commit a306e30
  - tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer (CVE-2025-38184 bsc#1245956)
  - commit ea5f7f7
  - drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 (CVE-2025-38205 bsc#1246005)
  - commit ca56750
  - smb: client: add NULL check in automount_fullpath (CVE-2025-38208 bsc#1245815)
  - commit cb3a2bf
  - net: stmmac: make sure that ptp_rate is not 0 before configuring EST (CVE-2025-38125 bsc#1245710)
  - commit 04509ac
  - block: Make REQ_OP_ZONE_FINISH a write operation (git-fixes, bsc#1249552).
  - blacklist.conf: remove 3f66ccbaaef3
    mwilck: this commit is a necessary part of an upstream fix series.
    See comments in block-Make-REQ_OP_ZONE_FINISH-a-write-operation.patch.
  - commit 5f975b1
  - dm: split write BIOs on zone boundaries when zone append is
    not emulated (git-fixes).
  - commit 68ed6f4
  - dm: Always split write BIOs to zoned device limits (git-fixes, CVE-2025-39792, bsc#1249618).
  - commit a8b835f
  - dm: dm-crypt: Do not partially accept write BIOs with zoned
    targets (git-fixes, CVE-2025-39791, bsc#1249550).
  - commit d7f2e88
  - dm: Check for forbidden splitting of zone write operations
    (git-fixes).
  - commit f3bd28c
  - dm-stripe: limit chunk_sectors to the stripe size (git-fixes).
  - commit a008640
  - kernel-binary: Another installation ordering fix (bsc#1241353).
  - commit fe14ab5
  - dm-table: fix checking for rq stackable devices (git-fixes).
  - commit c0133c8
  - dm-mpath: don't print the "loaded" message if registering fails
    (git-fixes).
  - commit d2cfeaf
  - md: dm-zoned-target: Initialize return variable r to avoid
    uninitialized use (git-fixes).
  - commit c0e418a
  - iio: imu: inv_icm42600: change invalid data error to -EBUSY
    (git-fixes).
  - commit e4f8b35
  - drm/amdgpu: fix task hang from failed job submission during
    process kill (git-fixes).
  - commit 6f325ab
  - iio: light: as73211: Ensure buffer holes are zeroed (git-fixes).
  - usb: dwc3: Remove WARN_ON for device endpoint command timeouts
    (stable-fixes).
  - USB: storage: Ignore driver CD mode for Realtek multi-mode
    Wi-Fi dongles (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Wildcat Lake
    (stable-fixes).
  - USB: storage: Add unusual-devs entry for Novatek NTK96550-based
    camera (stable-fixes).
  - usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1
    Flash Drive (stable-fixes).
  - drm/amd/display: Fix DP audio DTO1 clock source on DCE 6
    (stable-fixes).
  - drm/amd/display: Fill display clock and vblank time in
    dce110_fill_display_configs (stable-fixes).
  - drm/amd/display: Find first CRTC and its line time in
    dce110_fill_display_configs (stable-fixes).
  - drm/amd/display: Fix Xorg desktop unresponsive on Replay panel
    (stable-fixes).
  - drm/amd/display: Avoid a NULL pointer dereference
    (stable-fixes).
  - drm/amdgpu/swm14: Update power limit logic (stable-fixes).
  - ALSA: hda/realtek: Add support for HP EliteBook x360 830 G6
    and EliteBook 830 G6 (stable-fixes).
  - drm/amdkfd: Destroy KFD debugfs after destroy KFD wq
    (stable-fixes).
  - amdgpu/amdgpu_discovery: increase timeout limit for IFWI init
    (stable-fixes).
  - drm/amd/display: fix a Null pointer dereference vulnerability
    (stable-fixes).
  - drm/amd/display: Add primary plane to commits for correct VRR
    handling (stable-fixes).
  - drm/amdgpu: update mmhub 3.0.1 client id mappings
    (stable-fixes).
  - drm/amd: Restore cached power limit during resume
    (stable-fixes).
  - drm/amdgpu: Update external revid for GC v9.5.0 (stable-fixes).
  - drm/amdgpu: update mmhub 4.1.0 client id mappings
    (stable-fixes).
  - drm/amdgpu: Avoid extra evict-restore process (stable-fixes).
  - drm/amdgpu: check if hubbub is NULL in
    debugfs/amdgpu_dm_capabilities (stable-fixes).
  - pwm: mediatek: Fix duty and period setting (git-fixes).
  - pwm: mediatek: Handle hardware enable and clock enable
    separately (stable-fixes).
  - crypto: qat - lower priority for skcipher and aead algorithms
    (stable-fixes).
  - crypto: octeontx2 - Fix address alignment on CN10KB and
    CN10KA-B0 (stable-fixes).
  - crypto: octeontx2 - Fix address alignment on CN10K A0/A1 and
    OcteonTX2 (stable-fixes).
  - crypto: octeontx2 - Fix address alignment issue on ucode loading
    (stable-fixes).
  - drm/dp: Change AUX DPCD probe address from DPCD_REV to
    LANE0_1_STATUS (stable-fixes).
  - iio: imu: inv_icm42600: use = { } instead of memset()
    (stable-fixes).
  - drm/format-helper: Add conversion from XRGB8888 to BGR888
    (stable-fixes).
  - iio: imu: inv_icm42600: switch timestamp type from int64_t
    __aligned(8) to aligned_s64 (stable-fixes).
  - iio: light: Use aligned_s64 instead of open coding alignment
    (stable-fixes).
  - commit 60c07db
  - net: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting
    for skb_shared_info (CVE-2025-38545 bsc#1248224).
  - commit af6b2ae

------------------------------------------------------------------
------------------  2025-8-28  -  Aug 28 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - x86/sev: Evict cache lines during SNP memory validation
    (CVE-2025-38560 bsc#1248312).
  - commit 122589e
  - x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation
    (CVE-2025-38508 bsc#1248190).
  - kABI: x86/sev: Use TSC_FACTOR for Secure TSC frequency
    calculation (git-fixes).
  - commit 9051bdb
  - hid: hide cleanup of hid_descriptor (CVE-2025-38103
    bsc#1245663).
  - commit da277ba
  - xfrm: interface: fix use-after-free after changing collect_md
    xfrm interface (CVE-2025-38500 bsc#1248088).
  - rxrpc: Fix recv-recv race of completed call (CVE-2025-38524
    bsc#1248194).
  - atm: clip: Fix memory leak of struct clip_vcc (CVE-2025-38546
    bsc#1248223).
  - commit f78c063
  - HID: usbhid: Eliminate recurrent out-of-bounds bug in
    usbhid_parse() (CVE-2025-38103 bsc#1245663).
  - blacklist.conf: removing erroneous entry
  - commit 59058fc
  - selftests/bpf: Fix build error with llvm 19 (git-fixes).
  - selftests/bpf: Add a test for arena range tree algorithm
    (git-fixes).
  - commit f2d6c5a
  - selftests/bpf: Range analysis test case for JSET (git-fixes).
  - bpf: Forget ranges when refining tnum after JSET (git-fixes).
  - commit 0deb4ac

++++ kernel-rt:

  - x86/sev: Evict cache lines during SNP memory validation
    (CVE-2025-38560 bsc#1248312).
  - commit 122589e
  - x86/sev: Use TSC_FACTOR for Secure TSC frequency calculation
    (CVE-2025-38508 bsc#1248190).
  - kABI: x86/sev: Use TSC_FACTOR for Secure TSC frequency
    calculation (git-fixes).
  - commit 9051bdb
  - hid: hide cleanup of hid_descriptor (CVE-2025-38103
    bsc#1245663).
  - commit da277ba
  - xfrm: interface: fix use-after-free after changing collect_md
    xfrm interface (CVE-2025-38500 bsc#1248088).
  - rxrpc: Fix recv-recv race of completed call (CVE-2025-38524
    bsc#1248194).
  - atm: clip: Fix memory leak of struct clip_vcc (CVE-2025-38546
    bsc#1248223).
  - commit f78c063
  - HID: usbhid: Eliminate recurrent out-of-bounds bug in
    usbhid_parse() (CVE-2025-38103 bsc#1245663).
  - blacklist.conf: removing erroneous entry
  - commit 59058fc
  - selftests/bpf: Fix build error with llvm 19 (git-fixes).
  - selftests/bpf: Add a test for arena range tree algorithm
    (git-fixes).
  - commit f2d6c5a
  - selftests/bpf: Range analysis test case for JSET (git-fixes).
  - bpf: Forget ranges when refining tnum after JSET (git-fixes).
  - commit 0deb4ac

++++ net-tools:

  - Drop old Fedora patch 0006-Allow-interface-stacking.patch. It
    provided a fix for the stack corruption (bsc#142461), later
    reported as CVE-2025-46836 (bsc#1243581) and fixed by the
    upstream in a different way. Revert interfering
    net-tools-CVE-2025-46836.patch back to the upstream version.
  - Fix stack buffer overflow in parse_hex (bsc#1248687,
    GHSA-h667-qrp8-gj58, net-tools-parse_hex-stack-overflow.patch).
  - Fix stack-based buffer overflow in proc_gen_fmt (bsc#1248687,
    GHSA-w7jq-cmw2-cq59,
    net-tools-proc_gen_fmt-buffer-overflow.patch).
  - Avoid unsafe memcpy in ifconfig (bsc#1248687,
    net-tools-ifconfig-avoid-unsafe-memcpy.patch).
  - Prevent overflow in ax25 and netrom (bsc#1248687,
    net-tools-ax25+netrom-overflow-1.patch,
    net-tools-ax25+netrom-overflow-2.patch).
  - Keep possibility to enter long interface names, even if they are
    not accepted by the kernel, because it was always possible up to
    CVE-2025-46836 fix. But issue a warning about an interface name
    concatenation (bsc#1248410,
    net-tools-ifconfig-long-name-warning.patch).

------------------------------------------------------------------
------------------  2025-8-27  -  Aug 27 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - selftests/perf_events: Add a mmap() correctness test
    (CVE-2025-38563 bsc#1248306 selftest).
  - commit dffae9d
  - perf/core: Prevent VMA split of buffer mappings (CVE-2025-38563
    bsc#1248306).
  - commit 011b3e1
  - perf/core: Handle buffer mapping fail correctly in perf_mmap()
    (CVE-2025-38563 bsc#1248306 dependency).
  - commit b1e65ce
  - perf/core: Exit early on perf_mmap() fail (CVE-2025-38563
    bsc#1248306 dependency).
  - commit f53f18d
  - perf/core: Don't leak AUX buffer refcount on allocation failure
    (CVE-2025-38563 bsc#1248306 dependency).
  - commit 00401fa
  - perf/core: Preserve AUX buffer allocation failure result
    (CVE-2025-38563 bsc#1248306 dependency).
  - commit ed80f93
  - mm: fix a UAF when vma->mm is freed after vma->vm_refcnt got
    dropped (CVE-2025-38554 bsc#1248299).
  - commit af06370

++++ kernel-rt:

  - selftests/perf_events: Add a mmap() correctness test
    (CVE-2025-38563 bsc#1248306 selftest).
  - commit dffae9d
  - perf/core: Prevent VMA split of buffer mappings (CVE-2025-38563
    bsc#1248306).
  - commit 011b3e1
  - perf/core: Handle buffer mapping fail correctly in perf_mmap()
    (CVE-2025-38563 bsc#1248306 dependency).
  - commit b1e65ce
  - perf/core: Exit early on perf_mmap() fail (CVE-2025-38563
    bsc#1248306 dependency).
  - commit f53f18d
  - perf/core: Don't leak AUX buffer refcount on allocation failure
    (CVE-2025-38563 bsc#1248306 dependency).
  - commit 00401fa
  - perf/core: Preserve AUX buffer allocation failure result
    (CVE-2025-38563 bsc#1248306 dependency).
  - commit ed80f93
  - mm: fix a UAF when vma->mm is freed after vma->vm_refcnt got
    dropped (CVE-2025-38554 bsc#1248299).
  - commit af06370

++++ regionServiceClientConfigAzure:

  - Update to version 3.0.0 (bsc#1246995)
    + SLE 16 python-requests requiers SSL v3 certificates. Update 2
    region server certs to support SLE 16 when it gets released.

++++ regionServiceClientConfigEC2:

  - Update to version 5.0.0 (bsc#1246995)
    + SLE 16 python-requests requiers SSL v3 certificates. Update 2
    region server certs to support SLE 16 when it gets released.

++++ regionServiceClientConfigGCE:

  - Update to version 5.0.0 (bsc#1246995)
    + SLE 16 python-requests requires SSL v3 certificates. Update 2
    region server certs to support SLE 16 when it gets released.

------------------------------------------------------------------
------------------  2025-8-26  -  Aug 26 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - build_bug.h: Add KABI assert (bsc#1249186).
  - commit 126f232
  - kabi/severities: ignore kabi for intel pmt drivers (CVE-2025-38559 bsc#1248302)
    They are locally used only among intel pmt drivers.
  - commit 336a1fb
  - platform/x86/intel/pmt: fix a crashlog NULL pointer access
    (CVE-2025-38559 bsc#1248302).
  - commit 21f76b6
  - usb: xhci: Fix slot_id resource race conflict (git-fixes).
  - commit ca93cfc
  - of: dynamic: Fix use after free in
    of_changeset_add_prop_helper() (git-fixes).
  - commit 864aa13
  - pinctrl: STMFX: add missing HAS_IOMEM dependency (git-fixes).
  - usb: xhci: Fix slot_id resource race conflict (git-fixes).
  - usb: typec: maxim_contaminant: re-enable cc toggle if cc is
    open and port is clean (git-fixes).
  - usb: typec: maxim_contaminant: disable low power mode when
    reading comparator values (git-fixes).
  - usb: storage: realtek_cr: Use correct byte order for
    bcs->Residue (git-fixes).
  - usb: dwc3: Ignore late xferNotReady event to prevent halt
    timeout (git-fixes).
  - usb: core: hcd: fix accessing unmapped memory in
    SINGLE_STEP_SET_FEATURE test (git-fixes).
  - usb: renesas-xhci: Fix External ROM access timeouts (git-fixes).
  - platform/x86/amd/hsmp: Ensure sock->metric_tbl_addr is non-NULL
    (git-fixes).
  - platform/x86/intel-uncore-freq: Check write blocked for ELC
    (git-fixes).
  - commit 2aeddbc
  - of: dynamic: Fix memleak when of_pci_add_properties() failed
    (git-fixes).
  - iio: pressure: bmp280: Use IS_ERR() in bmp280_common_probe()
    (git-fixes).
  - iio: proximity: isl29501: fix buffered read on big-endian
    systems (git-fixes).
  - most: core: Drop device reference after usage in get_channel()
    (git-fixes).
  - comedi: Make insn_rw_emulate_bits() do insn->n samples
    (git-fixes).
  - comedi: Fix use of uninitialized memory in do_insn_ioctl()
    and do_insnlist_ioctl() (git-fixes).
  - comedi: pcl726: Prevent invalid irq number (git-fixes).
  - cdx: Fix off-by-one error in cdx_rpmsg_probe() (git-fixes).
  - drm/hisilicon/hibmc: fix the hibmc loaded failed bug
    (git-fixes).
  - accel/habanalabs/gaudi2: Use kvfree() for memory allocated
    with kvcalloc() (git-fixes).
  - iosys-map: Fix undefined behavior in iosys_map_clear()
    (git-fixes).
  - drm/tests: Fix endian warning (git-fixes).
  - drm/nouveau: fix typos in comments (git-fixes).
  - drm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor()
    (git-fixes).
  - drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3
    (git-fixes).
  - drm/amd/display: Don't print errors for nonexistent connectors
    (git-fixes).
  - drm/amd/display: Adjust DCE 8-10 clock, don't overclock by 15%
    (git-fixes).
  - drm/amd/display: Don't overclock DCE 6 by 15% (git-fixes).
  - drm/amd/display: Add null pointer check in
    mod_hdcp_hdcp1_create_session() (git-fixes).
  - memstick: Fix deadlock by moving removing flag earlier
    (git-fixes).
  - mmc: sdhci-pci-gli: GL9763e: Mask the replay timer timeout of
    AER (git-fixes).
  - mmc: sdhci-pci-gli: GL9763e: Rename the gli_set_gl9763e()
    for consistency (git-fixes).
  - mmc: sdhci-pci-gli: Add a new function to simplify the code
    (git-fixes).
  - ALSA: usb-audio: Use correct sub-type for UAC3 feature unit
    validation (git-fixes).
  - ALSA: timer: fix ida_free call while not allocated (git-fixes).
  - ALSA: hda/realtek: Audio disappears on HP 15-fc000 after warm
    boot again (git-fixes).
  - ALSA: hda/realtek: Fix headset mic on ASUS Zenbook 14
    (git-fixes).
  - ALSA: usb-audio: Fix size validation in convert_chmap_v3()
    (git-fixes).
  - commit 3b28ac3

++++ kernel-firmware-amdgpu:

  - Update to version 20250825 (git commit f044bc789f8e):
    * amdgpu: Update ISP FW for isp v4.1.1
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-rt:

  - build_bug.h: Add KABI assert (bsc#1249186).
  - commit 126f232
  - kabi/severities: ignore kabi for intel pmt drivers (CVE-2025-38559 bsc#1248302)
    They are locally used only among intel pmt drivers.
  - commit 336a1fb
  - platform/x86/intel/pmt: fix a crashlog NULL pointer access
    (CVE-2025-38559 bsc#1248302).
  - commit 21f76b6
  - usb: xhci: Fix slot_id resource race conflict (git-fixes).
  - commit ca93cfc
  - of: dynamic: Fix use after free in
    of_changeset_add_prop_helper() (git-fixes).
  - commit 864aa13
  - pinctrl: STMFX: add missing HAS_IOMEM dependency (git-fixes).
  - usb: xhci: Fix slot_id resource race conflict (git-fixes).
  - usb: typec: maxim_contaminant: re-enable cc toggle if cc is
    open and port is clean (git-fixes).
  - usb: typec: maxim_contaminant: disable low power mode when
    reading comparator values (git-fixes).
  - usb: storage: realtek_cr: Use correct byte order for
    bcs->Residue (git-fixes).
  - usb: dwc3: Ignore late xferNotReady event to prevent halt
    timeout (git-fixes).
  - usb: core: hcd: fix accessing unmapped memory in
    SINGLE_STEP_SET_FEATURE test (git-fixes).
  - usb: renesas-xhci: Fix External ROM access timeouts (git-fixes).
  - platform/x86/amd/hsmp: Ensure sock->metric_tbl_addr is non-NULL
    (git-fixes).
  - platform/x86/intel-uncore-freq: Check write blocked for ELC
    (git-fixes).
  - commit 2aeddbc
  - of: dynamic: Fix memleak when of_pci_add_properties() failed
    (git-fixes).
  - iio: pressure: bmp280: Use IS_ERR() in bmp280_common_probe()
    (git-fixes).
  - iio: proximity: isl29501: fix buffered read on big-endian
    systems (git-fixes).
  - most: core: Drop device reference after usage in get_channel()
    (git-fixes).
  - comedi: Make insn_rw_emulate_bits() do insn->n samples
    (git-fixes).
  - comedi: Fix use of uninitialized memory in do_insn_ioctl()
    and do_insnlist_ioctl() (git-fixes).
  - comedi: pcl726: Prevent invalid irq number (git-fixes).
  - cdx: Fix off-by-one error in cdx_rpmsg_probe() (git-fixes).
  - drm/hisilicon/hibmc: fix the hibmc loaded failed bug
    (git-fixes).
  - accel/habanalabs/gaudi2: Use kvfree() for memory allocated
    with kvcalloc() (git-fixes).
  - iosys-map: Fix undefined behavior in iosys_map_clear()
    (git-fixes).
  - drm/tests: Fix endian warning (git-fixes).
  - drm/nouveau: fix typos in comments (git-fixes).
  - drm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor()
    (git-fixes).
  - drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3
    (git-fixes).
  - drm/amd/display: Don't print errors for nonexistent connectors
    (git-fixes).
  - drm/amd/display: Adjust DCE 8-10 clock, don't overclock by 15%
    (git-fixes).
  - drm/amd/display: Don't overclock DCE 6 by 15% (git-fixes).
  - drm/amd/display: Add null pointer check in
    mod_hdcp_hdcp1_create_session() (git-fixes).
  - memstick: Fix deadlock by moving removing flag earlier
    (git-fixes).
  - mmc: sdhci-pci-gli: GL9763e: Mask the replay timer timeout of
    AER (git-fixes).
  - mmc: sdhci-pci-gli: GL9763e: Rename the gli_set_gl9763e()
    for consistency (git-fixes).
  - mmc: sdhci-pci-gli: Add a new function to simplify the code
    (git-fixes).
  - ALSA: usb-audio: Use correct sub-type for UAC3 feature unit
    validation (git-fixes).
  - ALSA: timer: fix ida_free call while not allocated (git-fixes).
  - ALSA: hda/realtek: Audio disappears on HP 15-fc000 after warm
    boot again (git-fixes).
  - ALSA: hda/realtek: Fix headset mic on ASUS Zenbook 14
    (git-fixes).
  - ALSA: usb-audio: Fix size validation in convert_chmap_v3()
    (git-fixes).
  - commit 3b28ac3

++++ sqlite3:

  - bsc#1248586: Fix icu-enabled build.

------------------------------------------------------------------
------------------  2025-8-25  -  Aug 25 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - btrfs: error on missing block group when unaccounting log tree
    extent buffers (git-fixes).
  - commit ca535e9
  - atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (CVE-2025-38458 bsc#1247116)
  - commit 48dd298
  - atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister() (CVE-2025-38245 bsc#1246193)
  - commit daf962c
  - NFS: Fix a race when updating an existing write (git-fixes).
  - commit dd68c46
  - squashfs: fix memory leak in squashfs_fill_super (git-fixes).
  - commit 97b84d0
  - btrfs: fix data race when accessing the inode's disk_i_size
    at btrfs_drop_extents() (git-fixes).
  - commit 71e5dc6
  - btrfs: fix two misuses of folio_shift() (git-fixes).
  - commit 56b1b7d
  - btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper
    error handling (git-fixes).
  - commit 6429a2c
  - atm: Revert atm_account_tx() if copy_from_iter_full() fails (CVE-2025-38190 bsc#1245973)
  - commit 0dae89a
  - btrfs: correctly escape subvol in btrfs_show_options()
    (git-fixes).
  - commit a28815d
  - btrfs: exit after state split error at set_extent_bit()
    (git-fixes).
  - commit 3d66187
  - btrfs: simplify error detection flow during log replay
    (git-fixes).
  - commit 01419dc
  - btrfs: remove redundant path release when replaying a log tree
    (git-fixes).
  - commit 7716eeb
  - md/raid1: Fix stack memory use after return in raid1_reshape (CVE-2025-38445 bsc#1247229)
  - commit 9aa9477
  - btrfs: abort transaction during log replay if walk_log_tree()
    failed (git-fixes).
  - commit e991a13
  - btrfs: unfold transaction aborts when replaying log trees
    (git-fixes).
  - commit e05bcc5
  - btrfs: fix -ENOSPC mmap write failure on NOCOW files/extents
    (bsc#1247949).
  - commit 358990e
  - btrfs: use a single variable to track return value at
    btrfs_page_mkwrite() (bsc#1247949).
  - commit 7b18bc8
  - btrfs: don't return VM_FAULT_SIGBUS on failure to set delalloc
    for mmap write (bsc#1247949).
  - commit 621c50f
  - btrfs: simplify early error checking in btrfs_page_mkwrite()
    (bsc#1247949).
  - commit c73e908
  - btrfs: pass true to btrfs_delalloc_release_space() at
    btrfs_page_mkwrite() (bsc#1247949).
  - commit 3b9148d
  - btrfs: fix iteration bug in __qgroup_excl_accounting()
    (git-fixes).
  - commit ad5c1bb
  - bpf, ktls: Fix data corruption when using bpf_msg_pop_data()
    in ktls (bsc#1248338 CVE-2025-38608).
  - commit 04b4d43
  - RDMA/hns: Fix dip entries leak on devices newer than hip09 (git-fixes)
  - commit 25d5b8f
  - RDMA/bnxt_re: Fix to initialize the PBL array (git-fixes)
  - commit 8869ef6
  - RDMA/bnxt_re: Fix a possible memory leak in the driver (git-fixes)
  - commit 33fe82f
  - RDMA/bnxt_re: Fix to remove workload check in SRQ limit path (git-fixes)
  - commit 9051d83
  - RDMA/bnxt_re: Fix to do SRQ armena by default (git-fixes)
  - commit abc50d4
  - RDMA/hns: Fix querying wrong SCC context for DIP algorithm (git-fixes)
  - commit a868248
  - RDMA/erdma: Fix ignored return value of init_kernel_qp (git-fixes)
  - commit 61ee0cd
  - RDMA/rxe: Flush delayed SKBs while releasing RXE resources (git-fixes)
  - commit db9dec3

++++ kernel-rt:

  - btrfs: error on missing block group when unaccounting log tree
    extent buffers (git-fixes).
  - commit ca535e9
  - atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (CVE-2025-38458 bsc#1247116)
  - commit 48dd298
  - atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister() (CVE-2025-38245 bsc#1246193)
  - commit daf962c
  - NFS: Fix a race when updating an existing write (git-fixes).
  - commit dd68c46
  - squashfs: fix memory leak in squashfs_fill_super (git-fixes).
  - commit 97b84d0
  - btrfs: fix data race when accessing the inode's disk_i_size
    at btrfs_drop_extents() (git-fixes).
  - commit 71e5dc6
  - btrfs: fix two misuses of folio_shift() (git-fixes).
  - commit 56b1b7d
  - btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper
    error handling (git-fixes).
  - commit 6429a2c
  - atm: Revert atm_account_tx() if copy_from_iter_full() fails (CVE-2025-38190 bsc#1245973)
  - commit 0dae89a
  - btrfs: correctly escape subvol in btrfs_show_options()
    (git-fixes).
  - commit a28815d
  - btrfs: exit after state split error at set_extent_bit()
    (git-fixes).
  - commit 3d66187
  - btrfs: simplify error detection flow during log replay
    (git-fixes).
  - commit 01419dc
  - btrfs: remove redundant path release when replaying a log tree
    (git-fixes).
  - commit 7716eeb
  - md/raid1: Fix stack memory use after return in raid1_reshape (CVE-2025-38445 bsc#1247229)
  - commit 9aa9477
  - btrfs: abort transaction during log replay if walk_log_tree()
    failed (git-fixes).
  - commit e991a13
  - btrfs: unfold transaction aborts when replaying log trees
    (git-fixes).
  - commit e05bcc5
  - btrfs: fix -ENOSPC mmap write failure on NOCOW files/extents
    (bsc#1247949).
  - commit 358990e
  - btrfs: use a single variable to track return value at
    btrfs_page_mkwrite() (bsc#1247949).
  - commit 7b18bc8
  - btrfs: don't return VM_FAULT_SIGBUS on failure to set delalloc
    for mmap write (bsc#1247949).
  - commit 621c50f
  - btrfs: simplify early error checking in btrfs_page_mkwrite()
    (bsc#1247949).
  - commit c73e908
  - btrfs: pass true to btrfs_delalloc_release_space() at
    btrfs_page_mkwrite() (bsc#1247949).
  - commit 3b9148d
  - btrfs: fix iteration bug in __qgroup_excl_accounting()
    (git-fixes).
  - commit ad5c1bb
  - bpf, ktls: Fix data corruption when using bpf_msg_pop_data()
    in ktls (bsc#1248338 CVE-2025-38608).
  - commit 04b4d43
  - RDMA/hns: Fix dip entries leak on devices newer than hip09 (git-fixes)
  - commit 25d5b8f
  - RDMA/bnxt_re: Fix to initialize the PBL array (git-fixes)
  - commit 8869ef6
  - RDMA/bnxt_re: Fix a possible memory leak in the driver (git-fixes)
  - commit 33fe82f
  - RDMA/bnxt_re: Fix to remove workload check in SRQ limit path (git-fixes)
  - commit 9051d83
  - RDMA/bnxt_re: Fix to do SRQ armena by default (git-fixes)
  - commit abc50d4
  - RDMA/hns: Fix querying wrong SCC context for DIP algorithm (git-fixes)
  - commit a868248
  - RDMA/erdma: Fix ignored return value of init_kernel_qp (git-fixes)
  - commit 61ee0cd
  - RDMA/rxe: Flush delayed SKBs while releasing RXE resources (git-fixes)
  - commit db9dec3

++++ colord:

  - Update to version 1.4.8:
    + New Features:
  - Add AppStream metainfo XML with hardware provide info.
  - Add support for -Dsystemd_root_prefix to make local building
    easier.
  - Install sysusers.d config file if configured user is not
    root.
    + Bugfixes:
  - Add the source attribute for each man page.
  - Drop component type from AppStream metadata XML to avoid
    parsing error.
  - Fix a critical warning when running the self tests.
  - Fix USB scanners not working with RestrictAddressFamilies.
  - Fix writing to the database with ProtectSystem=strict.
  - Properly set the status to CD_SESSION_STATUS_RUNNING.
  - Use g_ascii_strtod instead of atof().
  - Use sqlite3_errmsg() to avoid getting a mutable error
    message.
  - Changes from version 1.4.7:
    + Bugfixes:
  - Add various hardenings to the systemd service.
  - Always close the ICC profile when loading fails.
  - Avoid destructing LCMS plugin twice with lcms 2.14.
  - Do not make state files executable in tmpfiles.d/colord.conf.
  - Fix a double free spotted by Coverity.
  - Fix an error check when parsing the DTP94 data.
  - Fix a -Wincompatible-pointer-types warning.
  - Fix potential crash when reading from broken Huey hardware.
  - Set FILE_OFFSET_BITS explicitly.
  - Use a 64-bit time_t.
  - Use thread context for Gamut Alarm codes.
  - Drop colord-CVE-2021-42523.patch and
    harden_colord.service.patch: fixed upstream.

++++ harfbuzz:

  - Update to version 11.4.4:
    + Fix a shaping regression affecting mark glyphs in certain
    fonts.
    + Fix pruning of mark filtering sets when subsetting fonts, which
    caused changes in shaping behaviour.

------------------------------------------------------------------
------------------  2025-8-23  -  Aug 23 2025  -------------------
------------------------------------------------------------------

++++ kmod:

  - kmod-testsuite
    * BuildIgnore pesign-obs-integration (new runtime requirement
    of kernel-default-devel): we don't need it for the kmod
    testsuite, and it also breaks the build as we aren't
    producting any binaries. (bsc#1248108)

++++ harfbuzz:

  - Update to version 11.4.3:
    + Make shaping fail much faster for certain malformed fonts
    (e.g., those that trigger infinite recursion).
    + Fix undefined behaviour introduced in 11.4.2.
    + Fix detection of the “Cambria Math” font when fonts are scaled,
    so the workaround for the bad MATH table constant is applied.

------------------------------------------------------------------
------------------  2025-8-22  -  Aug 22 2025  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update version to 10.5.2 (bsc#1247539)
    + When an instance fails verification server side the default credentials
    were left behind requireing manual intervantion prior to the next
    registration attempt.
    + Fix issue triggered when using instance-billing-flavor-check due to
    IP address handling as object rather than string introduced 10.5.0

++++ python-kiwi:

  - Fix agama integration test
    Disable no longer existing agama-auto.service
  - Fixed agama integration test
    nothing provides agama-auto anymore

++++ kdump:

  - upgrade to version 2.1.6
    * drop broken option KDUMP_NETCONFIG="" from manpage
    * prevent NetworkManager from overwriting resolv.conf (bsc#1247848)
    * fix KDUMP_NETCONFIG=auto for NetworkManager (bsc#1247848)
    * exclude kernel.panic_on_warn sysctl (bsc#1247355)

++++ kernel-default:

  - atm: clip: Fix infinite recursive call of clip_push() (CVE-2025-38459 bsc#1247119)
  - commit 40aa5b7
  - atm: clip: prevent NULL deref in clip_push() (CVE-2025-38251 bsc#1246181)
  - commit bcf4c6c
  - spi: spi-fsl-lpspi: Clamp too high speed_hz (git-fixes).
  - ACPI: pfr_update: Fix the driver update version check
    (git-fixes).
  - microchip: lan865x: fix missing Timer Increment config for
    Rev.B0/B1 (git-fixes).
  - microchip: lan865x: fix missing netif_start_queue() call on
    device open (git-fixes).
  - net: usb: asix_devices: Fix PHY address mask in MDIO bus
    initialization (git-fixes).
  - Bluetooth: hci_conn: do return error from
    hci_enhanced_setup_sync() (git-fixes).
  - Bluetooth: hci_event: fix MTU for BN == 0 in CIS Established
    (git-fixes).
  - Bluetooth: hci_sync: Prevent unintended PA sync when SID is 0xFF
    (git-fixes).
  - Bluetooth: hci_core: Fix using {cis,bis}_capable for current
    settings (git-fixes).
  - Bluetooth: btmtk: Fix wait_on_bit_timeout interruption during
    shutdown (git-fixes).
  - Bluetooth: hci_sync: Fix scan state after PA Sync has been
    established (git-fixes).
  - commit 71fbfbf
  - bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (CVE-2025-38439 bsc#1247155)
  - commit e4fb5aa
  - zram: permit only one post-processing operation at a time
    (git-fixes).
  - Refresh
    patches.suse/zram-fix-NULL-pointer-in-comp_algorithm_show.patch.
  - commit a8f2eb9

++++ kernel-rt:

  - atm: clip: Fix infinite recursive call of clip_push() (CVE-2025-38459 bsc#1247119)
  - commit 40aa5b7
  - atm: clip: prevent NULL deref in clip_push() (CVE-2025-38251 bsc#1246181)
  - commit bcf4c6c
  - spi: spi-fsl-lpspi: Clamp too high speed_hz (git-fixes).
  - ACPI: pfr_update: Fix the driver update version check
    (git-fixes).
  - microchip: lan865x: fix missing Timer Increment config for
    Rev.B0/B1 (git-fixes).
  - microchip: lan865x: fix missing netif_start_queue() call on
    device open (git-fixes).
  - net: usb: asix_devices: Fix PHY address mask in MDIO bus
    initialization (git-fixes).
  - Bluetooth: hci_conn: do return error from
    hci_enhanced_setup_sync() (git-fixes).
  - Bluetooth: hci_event: fix MTU for BN == 0 in CIS Established
    (git-fixes).
  - Bluetooth: hci_sync: Prevent unintended PA sync when SID is 0xFF
    (git-fixes).
  - Bluetooth: hci_core: Fix using {cis,bis}_capable for current
    settings (git-fixes).
  - Bluetooth: btmtk: Fix wait_on_bit_timeout interruption during
    shutdown (git-fixes).
  - Bluetooth: hci_sync: Fix scan state after PA Sync has been
    established (git-fixes).
  - commit 71fbfbf
  - bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (CVE-2025-38439 bsc#1247155)
  - commit e4fb5aa
  - zram: permit only one post-processing operation at a time
    (git-fixes).
  - Refresh
    patches.suse/zram-fix-NULL-pointer-in-comp_algorithm_show.patch.
  - commit a8f2eb9

++++ gcc15:

  - Update to GCC 15.2 release
    * the GCC 15.2 release contains regression fixes accumulated since
    the GCC 15.1 release

++++ mozilla-nss:

  - update to NSS 3.112.1
    * bmo#1982742 - restore support for finding certificates by decoded serial number.

++++ openldap2_6:

  - Fix the git version identifying as 2.6.X which breaks packages
    parsing the version string trying to match numbers.

++++ libtpms:

  - Allow for %is_opensuse to be unset, following up to
    https://src.suse.de/products/SLFO/pulls/204 (bsc#1248486).

------------------------------------------------------------------
------------------  2025-8-21  -  Aug 21 2025  -------------------
------------------------------------------------------------------

++++ cryptsetup:

  - Update to 2.8.1:
    * Fix status and deactivation of TCRYPT (VeraCrypt compatible) devices that use chained ciphers.
    * Fix unlocking BITLK (BitLocker compatible) devices with multibyte UTF8 characters in the passphrase.
    * Do not allow activation of the LUKS2 device if the used keyslot is not encrypted (it uses a null cipher).
  - Such a configuration cannot be created by cryptsetup, but can be crafted outside of it.
  - Null cipher is sometimes used to create an empty container for later reencryption.
  - Only an empty passphrase can activate such a container (the same as in LUKS1).
    * Do not silently decrease PBKDF parallel cost (threads) if set by an option.
  - The maximum parallel cost is limited to 4 threads.
    * Fixes to configuration and installation scripts.
  - Meson and autoconf tools now properly support --prefix option for temporary directory installation.
  - Multiple fixes and cleanups to config.h for compatibility between Meson and autoconf.
  - Fix the luks2-external-tokens-path Meson option to work the same as in autoconf.
  - Fix Meson install for tool binaries, install fvault2Open man page and include test/fuzz/meson.build in release.
    * Major update to manual pages.
  - Try to explain the PBKDF hardcoded limits.
  - Add a better explanation for automatic integrity tag recalculation.
  - Mention crypt/verity/integritytab.
  - Remove or reformulate some misleading warnings present only with old and no longer supported kernels.
  - Clarify that some commands do not wipe data and unify OPAL reset wording.
  - Clarify the --label option.
  - There are also many other grammar and stylistic fixes to unify the man-page style.
    * Fixes for false-positive and annoying (optional) warnings added in recent compilers.

++++ kernel-default:

  - serial: 8250: Touch watchdogs in write_atomic() (bsc#1246688).
  - commit 956817a
  - raid10: cleanup memleak at raid10_make_request (CVE-2025-38444 bsc#1247162)
  - commit 2551d5d
  - config.sh: SLFO 1.2 branched in IBS
  - commit 38742b4
  - md/md-bitmap: fix GPF in bitmap_get_stats() (CVE-2025-38451 bsc#1247102)
  - commit f2c7bab
  - net: openvswitch: Fix the dead loop of MPLS parse
    (CVE-2025-38146 bsc#1245767).
  - commit 9115959
  - scsi: mpi3mr: Synchronous access b/w reset and tm thread for
    reply queue (bsc#1243055,CVE-2025-37861).
  - commit a094fbc
  - ata: libata-sata: Add link_power_management_supported sysfs
    attribute (git-fixes).
  - commit e1a205b
  - watchdog: sbsa: Adjust keepalive timeout to avoid MediaTek
    WS0 race condition (stable-fixes).
  - wifi: iwlwifi: mvm: avoid outdated reorder buffer head_sn
    (stable-fixes).
  - wifi: ath12k: Correct tid cleanup when tid setup fails
    (stable-fixes).
  - wifi: ath10k: shutdown driver when hardware is unreliable
    (stable-fixes).
  - wifi: ath12k: Add memset and update default rate value in wmi
    tx completion (stable-fixes).
  - wifi: ath12k: Fix station association with MBSSID Non-TX BSS
    (stable-fixes).
  - wifi: cfg80211: reject HTC bit for management frames
    (stable-fixes).
  - wifi: rtw89: wow: Add Basic Rate IE to probe request in
    scheduled scan mode (stable-fixes).
  - wifi: rtw89: Lower the timeout in rtw89_fw_read_c2h_reg()
    for USB (stable-fixes).
  - wifi: rtw89: Fix rtw89_mac_power_switch() for USB
    (stable-fixes).
  - wifi: iwlwifi: mvm: set gtk id also in older FWs (stable-fixes).
  - wifi: iwlwifi: mvm: fix scan request validation (stable-fixes).
  - wifi: cfg80211: Fix interface type validation (stable-fixes).
  - wifi: mac80211: don't unreserve never reserved chanctx
    (stable-fixes).
  - wifi: mac80211: don't complete management TX on SAE commit
    (stable-fixes).
  - wifi: mac80211: avoid weird state in error path (stable-fixes).
  - wifi: mac80211: fix rx link assignment for non-MLO stations
    (stable-fixes).
  - wifi: mt76: mt7915: mcu: re-init MCU before loading FW patch
    (stable-fixes).
  - wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd()
    (stable-fixes).
  - wifi: iwlwifi: fw: Fix possible memory leak in
    iwl_fw_dbg_collect (stable-fixes).
  - wifi: rtlwifi: fix possible skb memory leak in
    `_rtl_pci_rx_interrupt()` (stable-fixes).
  - wifi: rtw89: scan abort when assign/unassign_vif (stable-fixes).
  - wifi: rtlwifi: fix possible skb memory leak in
    _rtl_pci_init_one_rxdesc() (stable-fixes).
  - wifi: ath12k: Enable REO queue lookup table feature on QCN9274
    hw2.0 (stable-fixes).
  - wifi: ath12k: Decrement TID on RX peer frag setup error handling
    (stable-fixes).
  - wifi: mac80211: update radar_required in channel context after
    channel switch (stable-fixes).
  - wifi: iwlegacy: Check rate_idx range after addition
    (stable-fixes).
  - commit e7f2df8
  - tools/power turbostat: Handle non-root legacy-uncore sysfs
    permissions (stable-fixes).
  - tools/power turbostat: Handle cap_get_proc() ENOSYS
    (stable-fixes).
  - tools/power turbostat: Fix build with musl (stable-fixes).
  - watchdog: dw_wdt: Fix default timeout (stable-fixes).
  - watchdog: iTCO_wdt: Report error if timeout configuration fails
    (stable-fixes).
  - soundwire: amd: cancel pending slave status handling workqueue
    during remove sequence (stable-fixes).
  - soundwire: amd: serialize amd manager resume sequence during
    pm_prepare (stable-fixes).
  - soundwire: Move handle_nested_irq outside of sdw_dev_lock
    (stable-fixes).
  - usb: xhci: print xhci->xhc_state when queue_command failed
    (stable-fixes).
  - usb: typec: ucsi: psy: Set current max to 100mA for BC 1.2
    and Default (stable-fixes).
  - usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device
    Command (stable-fixes).
  - usb: xhci: Avoid showing warnings for dying controller
    (stable-fixes).
  - usb: xhci: Avoid showing errors during surprise removal
    (stable-fixes).
  - usb: typec: tcpm/tcpci_maxim: fix irq wake usage (stable-fixes).
  - usb: core: config: Prevent OOB read in SS endpoint companion
    parsing (stable-fixes).
  - usb: typec: intel_pmc_mux: Defer probe if SCU IPC isn't present
    (stable-fixes).
  - usb: core: usb_submit_urb: downgrade type check (stable-fixes).
  - tty: serial: fix print format specifiers (stable-fixes).
  - thermal: sysfs: Return ENODATA instead of EAGAIN for reads
    (stable-fixes).
  - thermal/drivers/qcom-spmi-temp-alarm: Enable stage 2 shutdown
    when required (stable-fixes).
  - commit c8e8ef2
  - rtc: ds1307: handle oscillator stop flag (OSF) for ds1341
    (stable-fixes).
  - rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe
    (stable-fixes).
  - power: supply: qcom_battmgr: Add lithium-polymer entry
    (stable-fixes).
  - soc: qcom: rpmh-rsc: Add RSC version 4 support (stable-fixes).
  - soc: qcom: mdt_loader: Actually use the e_phoff (stable-fixes).
  - reset: brcmstb: Enable reset drivers for ARCH_BCM2835
    (stable-fixes).
  - pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in
    mperf_stop() (stable-fixes).
  - PM: runtime: Clear power.needs_force_resume in
    pm_runtime_reinit() (stable-fixes).
  - PM: sleep: console: Fix the black screen issue (stable-fixes).
  - PM / devfreq: governor: Replace sscanf() with kstrtoul()
    in set_freq_store() (stable-fixes).
  - commit 958ff77
  - net: phy: smsc: add proper reset flags for LAN8710A
    (stable-fixes).
  - pinctrl: stm32: Manage irq affinity settings (stable-fixes).
  - media: hi556: Fix reset GPIO timings (stable-fixes).
  - media: ipu-bridge: Add _HID for OV5670 (stable-fixes).
  - mfd: axp20x: Set explicit ID for AXP313 regulator
    (stable-fixes).
  - net: phy: micrel: Add ksz9131_resume() (stable-fixes).
  - net: phy: bcm54811: PHY initialization (stable-fixes).
  - net: thunderbolt: Enable end-to-end flow control also in
    transmit (stable-fixes).
  - net: thunderbolt: Fix the parameter passing of
    tb_xdomain_enable_paths()/tb_xdomain_disable_paths()
    (stable-fixes).
  - net: ieee8021q: fix insufficient table-size assertion
    (stable-fixes).
  - mmc: sdhci-msm: Ensure SD card power isn't ON when card removed
    (stable-fixes).
  - mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode()
    (stable-fixes).
  - mei: bus: Check for still connected devices in
    mei_cl_bus_dev_release() (stable-fixes).
  - platform/chrome: cros_ec_sensorhub: Retries when a sensor is
    not ready (stable-fixes).
  - platform/chrome: cros_ec_typec: Defer probe on missing EC parent
    (stable-fixes).
  - platform/x86/amd: pmc: Add Lenovo Yoga 6 13ALC6 to pmc quirk
    list (stable-fixes).
  - commit dd25a85
  - ipmi: Use dev_warn_ratelimited() for incorrect message warnings
    (stable-fixes).
  - ipmi: Fix strcpy source and destination the same (stable-fixes).
  - i2c: Force DLL0945 touchpad i2c freq to 100khz (stable-fixes).
  - i3c: add missing include to internal header (stable-fixes).
  - i3c: don't fail if GETHDRCAP is unsupported (stable-fixes).
  - hwmon: (emc2305) Set initial PWM minimum value during probe
    based on thermal state (stable-fixes).
  - media: v4l2-common: Reduce warnings about missing
    V4L2_CID_LINK_FREQ control (stable-fixes).
  - media: tc358743: Return an appropriate colorspace from
    tc358743_set_fmt (stable-fixes).
  - media: tc358743: Check I2C succeeded during probe
    (stable-fixes).
  - media: tc358743: Increase FIFO trigger level to 374
    (stable-fixes).
  - media: usb: hdpvr: disable zero-length read messages
    (stable-fixes).
  - media: dvb-frontends: dib7090p: fix null-ptr-deref in
    dib7090p_rw_on_apb() (stable-fixes).
  - media: dvb-frontends: w7090p: fix null-ptr-deref in
    w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
    (stable-fixes).
  - media: uvcvideo: Add quirk for HP Webcam HD 2300 (stable-fixes).
  - media: uvcvideo: Fix bandwidth issue for Alcor camera
    (stable-fixes).
  - leds: leds-lp50xx: Handle reg to get correct multi_index
    (stable-fixes).
  - iio: adc: ad_sigma_delta: don't overallocate scan buffer
    (stable-fixes).
  - iio: adc: ad7768-1: Ensure SYNC_IN pulse minimum timing
    requirement (stable-fixes).
  - gpio: wcd934x: check the return value of regmap_update_bits()
    (stable-fixes).
  - gpio: tps65912: check the return value of regmap_update_bits()
    (stable-fixes).
  - commit 6c360e1
  - ASoC: Intel: avs: Fix uninitialized pointer error in probe()
    (stable-fixes).
  - fbdev: Fix vmalloc out-of-bounds write in fast_imageblit
    (stable-fixes).
  - fbdev: fix potential buffer overflow in
    do_register_framebuffer() (stable-fixes).
  - dmaengine: stm32-dma: configure next sg only if there are more
    than 2 sgs (stable-fixes).
  - drm/amd/display: Allow DCN301 to clear update flags (git-fixes).
  - drm/amd/display: Only finalize atomic_obj if it was initialized
    (stable-fixes).
  - drm/amd/display: Avoid configuring PSR granularity if PSR-SU
    not supported (stable-fixes).
  - drm/amd/display: Disable dsc_power_gate for dcn314 by default
    (stable-fixes).
  - crypto: hisilicon/hpre - fix dma unmap sequence (stable-fixes).
  - crypto: jitter - fix intermediary handling (stable-fixes).
  - crypto: octeontx2 - add timeout for load_fvc completion poll
    (stable-fixes).
  - crypto: ccp - Add missing bootloader info reg for pspv6
    (stable-fixes).
  - drm/amd/pm: fix null pointer access (stable-fixes).
  - drm/amd/display: limit clear_update_flags to dcn32 and above
    (stable-fixes).
  - drm/xe/xe_query: Use separate iterator while filling GT list
    (stable-fixes).
  - drm/msm: use trylock for debugfs (stable-fixes).
  - drm/msm: Add error handling for krealloc in metadata setup
    (stable-fixes).
  - drm/amd/display: Separate set_gsl from set_gsl_source_select
    (stable-fixes).
  - drm/amd/display: Fix 'failed to blank crtc!' (stable-fixes).
  - drm/amd/display: Initialize mode_select to 0 (stable-fixes).
  - drm/amd: Allow printing VanGogh OD SCLK levels without setting
    dpm to manual (stable-fixes).
  - drm/amd/display: Update DMCUB loading sequence for DCN3.5
    (stable-fixes).
  - drm/amd/display: Avoid trying AUX transactions on disconnected
    ports (stable-fixes).
  - drm/imagination: Clear runtime PM errors while resetting the
    GPU (stable-fixes).
  - drm/xe: Make dma-fences compliant with the safe access rules
    (stable-fixes).
  - drm: renesas: rz-du: mipi_dsi: Add min check for VCLK range
    (stable-fixes).
  - drm/ttm: Should to return the evict error (stable-fixes).
  - drm/ttm: Respect the shrinker core free target (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0489/e14e for MT7925
    (stable-fixes).
  - Bluetooth: hci_sock: Reset cookie to zero in
    hci_sock_free_cookie() (stable-fixes).
  - firmware: tegra: Fix IVC dependency problems (stable-fixes).
  - firmware: arm_scmi: Convert to SYSTEM_SLEEP_PM_OPS (git-fixes).
  - firmware: arm_scmi: power_control: Ensure SCMI_SYSPOWER_IDLE
    is set early during resume (stable-fixes).
  - char: misc: Fix improper and inaccurate error code returned
    by misc_init() (stable-fixes).
  - ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level()
    was successed (stable-fixes).
  - firmware: arm_ffa: Change initcall level of ffa_init() to
    rootfs_initcall (stable-fixes).
  - ata: ahci: Disallow LPM policy control if not supported
    (stable-fixes).
  - ata: ahci: Disable DIPM if host lacks support (stable-fixes).
  - ata: libata-sata: Disallow changing LPM state if not supported
    (stable-fixes).
  - commit 81a9217
  - ALSA: hda/realtek: Fix headset mic on HONOR BRB-X
    (stable-fixes).
  - ALSA: hda/realtek: Add Framework Laptop 13 (AMD Ryzen AI 300)
    to quirks (stable-fixes).
  - ALSA: hda/realtek: add LG gram 16Z90R-A to alc269 fixup table
    (stable-fixes).
  - ACPI: Suppress misleading SPCR console message when SPCR table
    is absent (stable-fixes).
  - ACPI: Return -ENODEV from acpi_parse_spcr() when SPCR support
    is disabled (stable-fixes).
  - ASoC: hdac_hdmi: Rate limit logging on connection and
    disconnection (stable-fixes).
  - ASoC: core: Check for rtd == NULL in
    snd_soc_remove_pcm_runtime() (stable-fixes).
  - ASoC: SOF: topology: Parse the dapm_widget_tokens in case of
    DSPless mode (stable-fixes).
  - ASoC: qcom: use drvdata instead of component to keep id
    (stable-fixes).
  - ASoC: codecs: rt5640: Retry DEVICE_ID verification
    (stable-fixes).
  - ALSA: hda: Handle the jack polling always via a work
    (stable-fixes).
  - ALSA: hda: Disable jack polling at shutdown (stable-fixes).
  - ALSA: intel8x0: Fix incorrect codec index usage in mixer for
    ICH4 (stable-fixes).
  - ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control
    (stable-fixes).
  - ALSA: pcm: Rewrite recalculate_boundary() to avoid costly loop
    (stable-fixes).
  - ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros
    (stable-fixes).
  - ACPI: APEI: send SIGBUS to current task if synchronous memory
    error not recovered (stable-fixes).
  - ACPI: processor: fix acpi_object initialization (stable-fixes).
  - commit 7148b68
  - RDMA/bnxt_re: Fix size of uverbs_copy_to() in BNXT_RE_METHOD_GET_TOGGLE_MEM (git-fixes)
  - commit 295036f
  - RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (git-fixes)
  - commit 3c7e10f
  - RDMA/core: reduce stack using in nldev_stat_get_doit() (git-fixes)
  - commit 096f6b9
  - pNFS: Fix disk addr range check in block/scsi layout
    (git-fixes).
  - commit c14b06d
  - pNFS: Fix stripe mapping in block/scsi layout (git-fixes).
  - commit 2a1cc0f
  - pNFS: Handle RPC size limit for layoutcommits (git-fixes).
  - commit 14b9be8
  - pNFS: Fix uninited ptr deref in block/scsi layout (git-fixes).
  - commit 65e1a8b
  - exfat: add cluster chain loop check for dir (git-fixes).
  - commit 6a79efa
  - kabi: hide new member fallback_lock in struct mptcp_sock
    (CVE-2025-38491 bsc#1247280).
  - mptcp: make fallback action and fallback decision atomic
    (CVE-2025-38491 bsc#1247280).
  - mptcp: safety check before fallback (CVE-2025-38491
    bsc#1247280).
  - commit 41fa302
  - tipc: Fix use-after-free in tipc_conn_close() (CVE-2025-38464
    bsc#1247112).
  - commit ca43752
  - ixgbe: prevent from unwanted interface name changes (git-fixes).
  - commit b593885
  - kABI: fix for struct devlink_port_attrs: move new member to
    the end (git-fixes).
  - commit 7c0fd06
  - devlink: let driver opt out of automatic phys_port_name
    generation (git-fixes).
  - commit 28c0839

++++ kernel-firmware-bluetooth:

  - Update to version 20250820 (git commit 70dda28e5098):
    * Link rtl8723b_config.bin to rtl8723bs

++++ kernel-rt:

  - serial: 8250: Touch watchdogs in write_atomic() (bsc#1246688).
  - commit 956817a
  - raid10: cleanup memleak at raid10_make_request (CVE-2025-38444 bsc#1247162)
  - commit 2551d5d
  - config.sh: SLFO 1.2 branched in IBS
  - commit 38742b4
  - md/md-bitmap: fix GPF in bitmap_get_stats() (CVE-2025-38451 bsc#1247102)
  - commit f2c7bab
  - net: openvswitch: Fix the dead loop of MPLS parse
    (CVE-2025-38146 bsc#1245767).
  - commit 9115959
  - scsi: mpi3mr: Synchronous access b/w reset and tm thread for
    reply queue (bsc#1243055,CVE-2025-37861).
  - commit a094fbc
  - ata: libata-sata: Add link_power_management_supported sysfs
    attribute (git-fixes).
  - commit e1a205b
  - watchdog: sbsa: Adjust keepalive timeout to avoid MediaTek
    WS0 race condition (stable-fixes).
  - wifi: iwlwifi: mvm: avoid outdated reorder buffer head_sn
    (stable-fixes).
  - wifi: ath12k: Correct tid cleanup when tid setup fails
    (stable-fixes).
  - wifi: ath10k: shutdown driver when hardware is unreliable
    (stable-fixes).
  - wifi: ath12k: Add memset and update default rate value in wmi
    tx completion (stable-fixes).
  - wifi: ath12k: Fix station association with MBSSID Non-TX BSS
    (stable-fixes).
  - wifi: cfg80211: reject HTC bit for management frames
    (stable-fixes).
  - wifi: rtw89: wow: Add Basic Rate IE to probe request in
    scheduled scan mode (stable-fixes).
  - wifi: rtw89: Lower the timeout in rtw89_fw_read_c2h_reg()
    for USB (stable-fixes).
  - wifi: rtw89: Fix rtw89_mac_power_switch() for USB
    (stable-fixes).
  - wifi: iwlwifi: mvm: set gtk id also in older FWs (stable-fixes).
  - wifi: iwlwifi: mvm: fix scan request validation (stable-fixes).
  - wifi: cfg80211: Fix interface type validation (stable-fixes).
  - wifi: mac80211: don't unreserve never reserved chanctx
    (stable-fixes).
  - wifi: mac80211: don't complete management TX on SAE commit
    (stable-fixes).
  - wifi: mac80211: avoid weird state in error path (stable-fixes).
  - wifi: mac80211: fix rx link assignment for non-MLO stations
    (stable-fixes).
  - wifi: mt76: mt7915: mcu: re-init MCU before loading FW patch
    (stable-fixes).
  - wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd()
    (stable-fixes).
  - wifi: iwlwifi: fw: Fix possible memory leak in
    iwl_fw_dbg_collect (stable-fixes).
  - wifi: rtlwifi: fix possible skb memory leak in
    `_rtl_pci_rx_interrupt()` (stable-fixes).
  - wifi: rtw89: scan abort when assign/unassign_vif (stable-fixes).
  - wifi: rtlwifi: fix possible skb memory leak in
    _rtl_pci_init_one_rxdesc() (stable-fixes).
  - wifi: ath12k: Enable REO queue lookup table feature on QCN9274
    hw2.0 (stable-fixes).
  - wifi: ath12k: Decrement TID on RX peer frag setup error handling
    (stable-fixes).
  - wifi: mac80211: update radar_required in channel context after
    channel switch (stable-fixes).
  - wifi: iwlegacy: Check rate_idx range after addition
    (stable-fixes).
  - commit e7f2df8
  - tools/power turbostat: Handle non-root legacy-uncore sysfs
    permissions (stable-fixes).
  - tools/power turbostat: Handle cap_get_proc() ENOSYS
    (stable-fixes).
  - tools/power turbostat: Fix build with musl (stable-fixes).
  - watchdog: dw_wdt: Fix default timeout (stable-fixes).
  - watchdog: iTCO_wdt: Report error if timeout configuration fails
    (stable-fixes).
  - soundwire: amd: cancel pending slave status handling workqueue
    during remove sequence (stable-fixes).
  - soundwire: amd: serialize amd manager resume sequence during
    pm_prepare (stable-fixes).
  - soundwire: Move handle_nested_irq outside of sdw_dev_lock
    (stable-fixes).
  - usb: xhci: print xhci->xhc_state when queue_command failed
    (stable-fixes).
  - usb: typec: ucsi: psy: Set current max to 100mA for BC 1.2
    and Default (stable-fixes).
  - usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device
    Command (stable-fixes).
  - usb: xhci: Avoid showing warnings for dying controller
    (stable-fixes).
  - usb: xhci: Avoid showing errors during surprise removal
    (stable-fixes).
  - usb: typec: tcpm/tcpci_maxim: fix irq wake usage (stable-fixes).
  - usb: core: config: Prevent OOB read in SS endpoint companion
    parsing (stable-fixes).
  - usb: typec: intel_pmc_mux: Defer probe if SCU IPC isn't present
    (stable-fixes).
  - usb: core: usb_submit_urb: downgrade type check (stable-fixes).
  - tty: serial: fix print format specifiers (stable-fixes).
  - thermal: sysfs: Return ENODATA instead of EAGAIN for reads
    (stable-fixes).
  - thermal/drivers/qcom-spmi-temp-alarm: Enable stage 2 shutdown
    when required (stable-fixes).
  - commit c8e8ef2
  - rtc: ds1307: handle oscillator stop flag (OSF) for ds1341
    (stable-fixes).
  - rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe
    (stable-fixes).
  - power: supply: qcom_battmgr: Add lithium-polymer entry
    (stable-fixes).
  - soc: qcom: rpmh-rsc: Add RSC version 4 support (stable-fixes).
  - soc: qcom: mdt_loader: Actually use the e_phoff (stable-fixes).
  - reset: brcmstb: Enable reset drivers for ARCH_BCM2835
    (stable-fixes).
  - pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in
    mperf_stop() (stable-fixes).
  - PM: runtime: Clear power.needs_force_resume in
    pm_runtime_reinit() (stable-fixes).
  - PM: sleep: console: Fix the black screen issue (stable-fixes).
  - PM / devfreq: governor: Replace sscanf() with kstrtoul()
    in set_freq_store() (stable-fixes).
  - commit 958ff77
  - net: phy: smsc: add proper reset flags for LAN8710A
    (stable-fixes).
  - pinctrl: stm32: Manage irq affinity settings (stable-fixes).
  - media: hi556: Fix reset GPIO timings (stable-fixes).
  - media: ipu-bridge: Add _HID for OV5670 (stable-fixes).
  - mfd: axp20x: Set explicit ID for AXP313 regulator
    (stable-fixes).
  - net: phy: micrel: Add ksz9131_resume() (stable-fixes).
  - net: phy: bcm54811: PHY initialization (stable-fixes).
  - net: thunderbolt: Enable end-to-end flow control also in
    transmit (stable-fixes).
  - net: thunderbolt: Fix the parameter passing of
    tb_xdomain_enable_paths()/tb_xdomain_disable_paths()
    (stable-fixes).
  - net: ieee8021q: fix insufficient table-size assertion
    (stable-fixes).
  - mmc: sdhci-msm: Ensure SD card power isn't ON when card removed
    (stable-fixes).
  - mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode()
    (stable-fixes).
  - mei: bus: Check for still connected devices in
    mei_cl_bus_dev_release() (stable-fixes).
  - platform/chrome: cros_ec_sensorhub: Retries when a sensor is
    not ready (stable-fixes).
  - platform/chrome: cros_ec_typec: Defer probe on missing EC parent
    (stable-fixes).
  - platform/x86/amd: pmc: Add Lenovo Yoga 6 13ALC6 to pmc quirk
    list (stable-fixes).
  - commit dd25a85
  - ipmi: Use dev_warn_ratelimited() for incorrect message warnings
    (stable-fixes).
  - ipmi: Fix strcpy source and destination the same (stable-fixes).
  - i2c: Force DLL0945 touchpad i2c freq to 100khz (stable-fixes).
  - i3c: add missing include to internal header (stable-fixes).
  - i3c: don't fail if GETHDRCAP is unsupported (stable-fixes).
  - hwmon: (emc2305) Set initial PWM minimum value during probe
    based on thermal state (stable-fixes).
  - media: v4l2-common: Reduce warnings about missing
    V4L2_CID_LINK_FREQ control (stable-fixes).
  - media: tc358743: Return an appropriate colorspace from
    tc358743_set_fmt (stable-fixes).
  - media: tc358743: Check I2C succeeded during probe
    (stable-fixes).
  - media: tc358743: Increase FIFO trigger level to 374
    (stable-fixes).
  - media: usb: hdpvr: disable zero-length read messages
    (stable-fixes).
  - media: dvb-frontends: dib7090p: fix null-ptr-deref in
    dib7090p_rw_on_apb() (stable-fixes).
  - media: dvb-frontends: w7090p: fix null-ptr-deref in
    w7090p_tuner_write_serpar and w7090p_tuner_read_serpar
    (stable-fixes).
  - media: uvcvideo: Add quirk for HP Webcam HD 2300 (stable-fixes).
  - media: uvcvideo: Fix bandwidth issue for Alcor camera
    (stable-fixes).
  - leds: leds-lp50xx: Handle reg to get correct multi_index
    (stable-fixes).
  - iio: adc: ad_sigma_delta: don't overallocate scan buffer
    (stable-fixes).
  - iio: adc: ad7768-1: Ensure SYNC_IN pulse minimum timing
    requirement (stable-fixes).
  - gpio: wcd934x: check the return value of regmap_update_bits()
    (stable-fixes).
  - gpio: tps65912: check the return value of regmap_update_bits()
    (stable-fixes).
  - commit 6c360e1
  - ASoC: Intel: avs: Fix uninitialized pointer error in probe()
    (stable-fixes).
  - fbdev: Fix vmalloc out-of-bounds write in fast_imageblit
    (stable-fixes).
  - fbdev: fix potential buffer overflow in
    do_register_framebuffer() (stable-fixes).
  - dmaengine: stm32-dma: configure next sg only if there are more
    than 2 sgs (stable-fixes).
  - drm/amd/display: Allow DCN301 to clear update flags (git-fixes).
  - drm/amd/display: Only finalize atomic_obj if it was initialized
    (stable-fixes).
  - drm/amd/display: Avoid configuring PSR granularity if PSR-SU
    not supported (stable-fixes).
  - drm/amd/display: Disable dsc_power_gate for dcn314 by default
    (stable-fixes).
  - crypto: hisilicon/hpre - fix dma unmap sequence (stable-fixes).
  - crypto: jitter - fix intermediary handling (stable-fixes).
  - crypto: octeontx2 - add timeout for load_fvc completion poll
    (stable-fixes).
  - crypto: ccp - Add missing bootloader info reg for pspv6
    (stable-fixes).
  - drm/amd/pm: fix null pointer access (stable-fixes).
  - drm/amd/display: limit clear_update_flags to dcn32 and above
    (stable-fixes).
  - drm/xe/xe_query: Use separate iterator while filling GT list
    (stable-fixes).
  - drm/msm: use trylock for debugfs (stable-fixes).
  - drm/msm: Add error handling for krealloc in metadata setup
    (stable-fixes).
  - drm/amd/display: Separate set_gsl from set_gsl_source_select
    (stable-fixes).
  - drm/amd/display: Fix 'failed to blank crtc!' (stable-fixes).
  - drm/amd/display: Initialize mode_select to 0 (stable-fixes).
  - drm/amd: Allow printing VanGogh OD SCLK levels without setting
    dpm to manual (stable-fixes).
  - drm/amd/display: Update DMCUB loading sequence for DCN3.5
    (stable-fixes).
  - drm/amd/display: Avoid trying AUX transactions on disconnected
    ports (stable-fixes).
  - drm/imagination: Clear runtime PM errors while resetting the
    GPU (stable-fixes).
  - drm/xe: Make dma-fences compliant with the safe access rules
    (stable-fixes).
  - drm: renesas: rz-du: mipi_dsi: Add min check for VCLK range
    (stable-fixes).
  - drm/ttm: Should to return the evict error (stable-fixes).
  - drm/ttm: Respect the shrinker core free target (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0489/e14e for MT7925
    (stable-fixes).
  - Bluetooth: hci_sock: Reset cookie to zero in
    hci_sock_free_cookie() (stable-fixes).
  - firmware: tegra: Fix IVC dependency problems (stable-fixes).
  - firmware: arm_scmi: Convert to SYSTEM_SLEEP_PM_OPS (git-fixes).
  - firmware: arm_scmi: power_control: Ensure SCMI_SYSPOWER_IDLE
    is set early during resume (stable-fixes).
  - char: misc: Fix improper and inaccurate error code returned
    by misc_init() (stable-fixes).
  - ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level()
    was successed (stable-fixes).
  - firmware: arm_ffa: Change initcall level of ffa_init() to
    rootfs_initcall (stable-fixes).
  - ata: ahci: Disallow LPM policy control if not supported
    (stable-fixes).
  - ata: ahci: Disable DIPM if host lacks support (stable-fixes).
  - ata: libata-sata: Disallow changing LPM state if not supported
    (stable-fixes).
  - commit 81a9217
  - ALSA: hda/realtek: Fix headset mic on HONOR BRB-X
    (stable-fixes).
  - ALSA: hda/realtek: Add Framework Laptop 13 (AMD Ryzen AI 300)
    to quirks (stable-fixes).
  - ALSA: hda/realtek: add LG gram 16Z90R-A to alc269 fixup table
    (stable-fixes).
  - ACPI: Suppress misleading SPCR console message when SPCR table
    is absent (stable-fixes).
  - ACPI: Return -ENODEV from acpi_parse_spcr() when SPCR support
    is disabled (stable-fixes).
  - ASoC: hdac_hdmi: Rate limit logging on connection and
    disconnection (stable-fixes).
  - ASoC: core: Check for rtd == NULL in
    snd_soc_remove_pcm_runtime() (stable-fixes).
  - ASoC: SOF: topology: Parse the dapm_widget_tokens in case of
    DSPless mode (stable-fixes).
  - ASoC: qcom: use drvdata instead of component to keep id
    (stable-fixes).
  - ASoC: codecs: rt5640: Retry DEVICE_ID verification
    (stable-fixes).
  - ALSA: hda: Handle the jack polling always via a work
    (stable-fixes).
  - ALSA: hda: Disable jack polling at shutdown (stable-fixes).
  - ALSA: intel8x0: Fix incorrect codec index usage in mixer for
    ICH4 (stable-fixes).
  - ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control
    (stable-fixes).
  - ALSA: pcm: Rewrite recalculate_boundary() to avoid costly loop
    (stable-fixes).
  - ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros
    (stable-fixes).
  - ACPI: APEI: send SIGBUS to current task if synchronous memory
    error not recovered (stable-fixes).
  - ACPI: processor: fix acpi_object initialization (stable-fixes).
  - commit 7148b68
  - RDMA/bnxt_re: Fix size of uverbs_copy_to() in BNXT_RE_METHOD_GET_TOGGLE_MEM (git-fixes)
  - commit 295036f
  - RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (git-fixes)
  - commit 3c7e10f
  - RDMA/core: reduce stack using in nldev_stat_get_doit() (git-fixes)
  - commit 096f6b9
  - pNFS: Fix disk addr range check in block/scsi layout
    (git-fixes).
  - commit c14b06d
  - pNFS: Fix stripe mapping in block/scsi layout (git-fixes).
  - commit 2a1cc0f
  - pNFS: Handle RPC size limit for layoutcommits (git-fixes).
  - commit 14b9be8
  - pNFS: Fix uninited ptr deref in block/scsi layout (git-fixes).
  - commit 65e1a8b
  - exfat: add cluster chain loop check for dir (git-fixes).
  - commit 6a79efa
  - kabi: hide new member fallback_lock in struct mptcp_sock
    (CVE-2025-38491 bsc#1247280).
  - mptcp: make fallback action and fallback decision atomic
    (CVE-2025-38491 bsc#1247280).
  - mptcp: safety check before fallback (CVE-2025-38491
    bsc#1247280).
  - commit 41fa302
  - tipc: Fix use-after-free in tipc_conn_close() (CVE-2025-38464
    bsc#1247112).
  - commit ca43752
  - ixgbe: prevent from unwanted interface name changes (git-fixes).
  - commit b593885
  - kABI: fix for struct devlink_port_attrs: move new member to
    the end (git-fixes).
  - commit 7c0fd06
  - devlink: let driver opt out of automatic phys_port_name
    generation (git-fixes).
  - commit 28c0839

++++ harfbuzz:

  - Update to version 11.4.2:
    + Various performance and memory usage improvements.
    + The hb-shape command line tool can now be built with the
    amalgamated harfbuzz.cc source.
    + Fix regression in handling version 2 of avar table.
    + Increase various buffer length limits for better handling of
    fonts that generate huge number of glyphs per codepoint (e.g.
    Noto Sans Duployan).
    + Improvements to the harfrust shaper for more accurate testing.

++++ tiff:

  - security update:
    * CVE-2025-8534 [bsc#1247582]
    Fix null pointer dereference in function PS_Lvl2page
    + tiff-CVE-2025-8534.patch
    * CVE-2025-9165 [bsc#1248330]
    Fix local execution manipulation can lead to memory leak
    + tiff-CVE-2025-9165.patch
    * CVE-2024-13978 [bsc#1247581]
    Fix null pointer dereference in tiff2pdf
    + tiff-CVE-2024-13978.patch

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20250812 release (bsc#1248438)
  - Security updates for INTEL-SA-01249 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01249.html
  - CVE-2025-20109: Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
  - Security updates for INTEL-SA-01308 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01308.html
  - CVE-2025-22840: Sequence of processor instructions leads to unexpected behavior for some Intel Xeon 6 Scalable processors may allow an authenticated user to potentially enable escalation of privilege via local access
  - Security updates for INTEL-SA-01310 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01310.html
  - CVE-2025-22839: Insufficient granularity of access control in the OOB-MSM for some Intel Xeon 6 Scalable processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.
  - Security updates for INTEL-SA-01311 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01311.html
  - CVE-2025-22889: Improper handling of overlap between protected memory ranges for some Intel Xeon 6 processor with Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.
  - Security updates for INTEL-SA-01313 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01313.html
  - CVE-2025-20053: Improper buffer restrictions for some Intel Xeon Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access.
  - Security updates for INTEL-SA-01367 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01367.html
  - CVE-2025-26403: Out-of-bounds write in the memory subsystem for some Intel Xeon 6 processors when using Intel SGX or Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.
  - CVE-2025-32086: Improperly implemented security check for standard in the DDRIO configuration for some Intel Xeon 6 Processors when using Intel SGX or Intel TDX may allow a privileged user to potentially enable escalation of privilege via local access.
  - Update for functional issues. Refer to 13th/14th Gen Intel Core Processor Specification Update for details.
  - Update for functional issues. Refer to 3rd Gen Intel Xeon Processor Scalable Family Specification Update for details.
  - Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update for details.
  - Update for functional issues. Refer to 5th Gen Intel Xeon Scalable Processors Specification Update for details.
  - Update for functional issues. Refer to 6th Gen Intel Xeon Scalable Processors Specification Update for details.
  - Update for functional issues. Refer to Intel Core Ultra 200 V Series Processor for details.
  - Update for functional issues. Refer to Intel Core Ultra Processor for details.
  - Update for functional issues. Refer to Intel Core Ultra Processor (Series 2) for details.
  - Update for functional issues. Refer to Intel Xeon 6700-Series Processor Specification Update for details.
  - Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update for details.
  - Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ARL-H          | A1       | 06-c5-02/82 | 00000118 | 00000119 | Core Ultra Processor (Series 2)
    | ARL-S/HX (8P)  | B0       | 06-c6-02/82 | 00000118 | 00000119 | Core Ultra Processor (Series 2)
    | EMR-SP         | A1       | 06-cf-02/87 | 210002a9 | 210002b3 | Xeon Scalable Gen5
    | GNR-AP/SP      | B0       | 06-ad-01/95 | 010003a2 | 010003d0 | Xeon Scalable Gen6
    | GNR-AP/SP      | H0       | 06-ad-01/20 | 0a0000d1 | 0a000100 | Xeon Scalable Gen6
    | ICL-D          | B0       | 06-6c-01/10 | 010002d0 | 010002e0 | Xeon D-17xx, D-27xx
    | ICX-SP         | Dx/M1    | 06-6a-06/87 | 0d000404 | 0d000410 | Xeon Scalable Gen3
    | LNL            | B0       | 06-bd-01/80 | 0000011f | 00000123 | Core Ultra 200 V Series Processor
    | MTL            | C0       | 06-aa-04/e6 | 00000024 | 00000025 | Core™ Ultra Processor
    | RPL-H/P/PX 6+8 | J0       | 06-ba-02/e0 | 00004128 | 00004129 | Core Gen13
    | RPL-U 2+8      | Q0       | 06-ba-03/e0 | 00004128 | 00004129 | Core Gen13
    | SPR-HBM        | Bx       | 06-8f-08/10 | 2c0003f7 | 2c000401 | Xeon Max
    | SPR-SP         | E4/S2    | 06-8f-07/87 | 2b000639 | 2b000643 | Xeon Scalable Gen4
    | SPR-SP         | E5/S3    | 06-8f-08/87 | 2b000639 | 2b000643 | Xeon Scalable Gen4
    | SRF-SP         | C0       | 06-af-03/01 | 03000341 | 03000362 | Xeon 6700-Series Processors with E-Cores
    New Disclosures Updated in Prior Releases:
    All ADL, RPL, SPR, EMR, MTL, ARL Microcode patches previously released in May 2025.

------------------------------------------------------------------
------------------  2025-8-20  -  Aug 20 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Update to 337
    * 337
  - Bug fixes and translation updates
    * 336
  - Graphical VNC and serial consoles improvements
  - Control VNC console resizing and scaling
  - Bug fixes and translation updates
    * 335
  - Bug fixes and translation updates
    * 334
  - Bug fixes and translation updates

++++ cockpit-podman:

  - Update to 112
    * 112
  - Translation and dependency updates
    * 111
  - Bug fixes and translation updates
    * 110
  - Bug fixes and translation updates
    * 109
  - Bug fixes and translation updates
    * 108
  - Bug fixes and translation updates

++++ git:

  - Use zlib instead of zlib-ng for SLES16

++++ kernel-default:

  - md: make rdev_addable usable for rcu mode (git-fixes).
  - block: ensure discard_granularity is zero when discard is not
    supported (git-fixes).
  - scsi: sd: Make sd shutdown issue START STOP UNIT appropriately
    (git-fixes).
  - scsi: Revert "scsi: iscsi: Fix HW conn removal use after free"
    (git-fixes).
  - scsi: mpt3sas: Fix a fw_event memory leak (git-fixes).
  - scsi: isci: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: mvsas: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: elx: efct: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: core: Fix kernel doc for scsi_track_queue_full()
    (git-fixes).
  - scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: mpi3mr: Serialize admin queue BAR writes on 32-bit systems
    (git-fixes).
  - scsi: mpi3mr: Fix race between config read submit and interrupt
    completion (git-fixes).
  - scsi: mpi3mr: Fix kernel-doc issues in mpi3mr_app.c (git-fixes).
  - sunvdc: Balance device refcount in vdc_port_mpgroup_check
    (git-fixes).
  - md: allow removing faulty rdev during resync (git-fixes).
  - block: sanitize chunk_sectors for atomic write limits
    (git-fixes).
  - block: mtip32xx: Fix usage of dma_map_sg() (git-fixes).
  - ublk: use vmalloc for ublk_device's __queues (git-fixes).
  - block: Introduce bio_needs_zone_write_plugging() (git-fixes).
  - loop: use kiocb helpers to fix lockdep warning (git-fixes).
  - block: fix kobject leak in blk_unregister_queue (git-fixes).
  - md/raid1,raid10: strip REQ_NOWAIT from member bios (git-fixes).
  - ublk: sanity check add_dev input for underflow (git-fixes).
  - aoe: defer rexmit timer downdev work to workqueue (git-fixes).
  - scsi: core: ufs: Fix a hang in the error handler (CVE-2025-38119
    bsc#1245700).
  - commit d72a9d3
  - fs/fhandle.c: fix a race in call of has_locked_children() (CVE-2025-38306 bsc#1246366)
  - commit ba2c55e
  - clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (CVE-2025-38499 bsc#1247976)
  - commit e64cd3b
  - selftests/livepatch: Ignore NO_SUPPORT line in dmesg (poo#187320).
  - commit e28bde1
  - livepatch: Add stack_order sysfs attribute (poo#187320).
  - commit 9ec1cd1
  - selftests: livepatch: test if ftrace can trace a livepatched
    function (poo#187320).
  - commit 30f78a7
  - selftests: livepatch: add new ftrace helpers functions
    (poo#187320).
  - commit 2920271
  - selftest/livepatch: Only run test-kprobe with
    CONFIG_KPROBES_ON_FTRACE (poo#187320).
  - commit 6f6ceda
  - selftests: livepatch: handle PRINTK_CALLER in check_result()
    (poo#187320).
  - commit 1420668
  - selftests: livepatch: add test cases of stack_order sysfs
    interface (poo#187320).
  - commit d445e83
  - selftests/livepatch: Replace hardcoded module name with variable
    in test-callbacks.sh (poo#187320).
  - commit 35f2fcd
  - selftests: livepatch: test livepatching a kprobed function
    (poo#187320).
  - commit 9775843
  - selftests: livepatch: save and restore kprobe state
    (poo#187320).
  - commit 687700e
  - selftests: livepatch: rename KLP_SYSFS_DIR to SYSFS_KLP_DIR
    (poo#187320).
  - commit 7dc1564
  - selftests/run_kselftest.sh: Use readlink if realpath is not
    available (poo#187320).
  - commit d609bae
  - selftests/run_kselftest.sh: Fix help string for --per-test-log
    (poo#187320).
  - commit 0a13bf1
  - selftests: ncdevmem: Move ncdevmem under drivers/net/hw
    (poo#187443).
  - Refresh patches.suse/selftests-net-Add-busy_poll_test.patch.
  - commit bfa5fe6
  - hrtimers: Handle CPU state correctly on hotplug (CVE-2024-57951
    bsc#1237108).
  - commit 4d85e21
  - Revert "libfs: fix infinite directory reads for offset dir"
    (CVE-2024-57952 bsc#1237131).
  - commit a2419ea

++++ kernel-rt:

  - md: make rdev_addable usable for rcu mode (git-fixes).
  - block: ensure discard_granularity is zero when discard is not
    supported (git-fixes).
  - scsi: sd: Make sd shutdown issue START STOP UNIT appropriately
    (git-fixes).
  - scsi: Revert "scsi: iscsi: Fix HW conn removal use after free"
    (git-fixes).
  - scsi: mpt3sas: Fix a fw_event memory leak (git-fixes).
  - scsi: isci: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: mvsas: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: elx: efct: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: core: Fix kernel doc for scsi_track_queue_full()
    (git-fixes).
  - scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (git-fixes).
  - scsi: mpi3mr: Serialize admin queue BAR writes on 32-bit systems
    (git-fixes).
  - scsi: mpi3mr: Fix race between config read submit and interrupt
    completion (git-fixes).
  - scsi: mpi3mr: Fix kernel-doc issues in mpi3mr_app.c (git-fixes).
  - sunvdc: Balance device refcount in vdc_port_mpgroup_check
    (git-fixes).
  - md: allow removing faulty rdev during resync (git-fixes).
  - block: sanitize chunk_sectors for atomic write limits
    (git-fixes).
  - block: mtip32xx: Fix usage of dma_map_sg() (git-fixes).
  - ublk: use vmalloc for ublk_device's __queues (git-fixes).
  - block: Introduce bio_needs_zone_write_plugging() (git-fixes).
  - loop: use kiocb helpers to fix lockdep warning (git-fixes).
  - block: fix kobject leak in blk_unregister_queue (git-fixes).
  - md/raid1,raid10: strip REQ_NOWAIT from member bios (git-fixes).
  - ublk: sanity check add_dev input for underflow (git-fixes).
  - aoe: defer rexmit timer downdev work to workqueue (git-fixes).
  - scsi: core: ufs: Fix a hang in the error handler (CVE-2025-38119
    bsc#1245700).
  - commit d72a9d3
  - fs/fhandle.c: fix a race in call of has_locked_children() (CVE-2025-38306 bsc#1246366)
  - commit ba2c55e
  - clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (CVE-2025-38499 bsc#1247976)
  - commit e64cd3b
  - selftests/livepatch: Ignore NO_SUPPORT line in dmesg (poo#187320).
  - commit e28bde1
  - livepatch: Add stack_order sysfs attribute (poo#187320).
  - commit 9ec1cd1
  - selftests: livepatch: test if ftrace can trace a livepatched
    function (poo#187320).
  - commit 30f78a7
  - selftests: livepatch: add new ftrace helpers functions
    (poo#187320).
  - commit 2920271
  - selftest/livepatch: Only run test-kprobe with
    CONFIG_KPROBES_ON_FTRACE (poo#187320).
  - commit 6f6ceda
  - selftests: livepatch: handle PRINTK_CALLER in check_result()
    (poo#187320).
  - commit 1420668
  - selftests: livepatch: add test cases of stack_order sysfs
    interface (poo#187320).
  - commit d445e83
  - selftests/livepatch: Replace hardcoded module name with variable
    in test-callbacks.sh (poo#187320).
  - commit 35f2fcd
  - selftests: livepatch: test livepatching a kprobed function
    (poo#187320).
  - commit 9775843
  - selftests: livepatch: save and restore kprobe state
    (poo#187320).
  - commit 687700e
  - selftests: livepatch: rename KLP_SYSFS_DIR to SYSFS_KLP_DIR
    (poo#187320).
  - commit 7dc1564
  - selftests/run_kselftest.sh: Use readlink if realpath is not
    available (poo#187320).
  - commit d609bae
  - selftests/run_kselftest.sh: Fix help string for --per-test-log
    (poo#187320).
  - commit 0a13bf1
  - selftests: ncdevmem: Move ncdevmem under drivers/net/hw
    (poo#187443).
  - Refresh patches.suse/selftests-net-Add-busy_poll_test.patch.
  - commit bfa5fe6
  - hrtimers: Handle CPU state correctly on hotplug (CVE-2024-57951
    bsc#1237108).
  - commit 4d85e21
  - Revert "libfs: fix infinite directory reads for offset dir"
    (CVE-2024-57952 bsc#1237131).
  - commit a2419ea

++++ rust-keylime:

  - Update vendored crates (bsc#1248006, CVE-2025-55159)
    * slab 0.4.11
  - Add Cargo_lock.patch patch to update slab and other dependencies
  - Update to version 0.2.8+12:
    * build(deps): bump actions/checkout from 4 to 5
    * build(deps): bump cfg-if from 1.0.0 to 1.0.1
    * build(deps): bump openssl from 0.10.72 to 0.10.73
    * build(deps): bump clap from 4.5.39 to 4.5.45
    * build(deps): bump pest from 2.8.0 to 2.8.1
    * Fix clippy warnings
    * Use verifier-provided interval for continuous attestation timing
    * Add meta object with seconds_to_next_attestation to evidence response
    * Fix boot time retrieval
    * Fix IMA log format (it must be ['text/plain']) (#1073)
    * Remove unnecessary configuration fields
    * cargo: Bump retry-policies to version 0.4.0
    * Bump version to 0.2.8

------------------------------------------------------------------
------------------  2025-8-19  -  Aug 19 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Update SLFO integration test
    Make sure ps tool is installed

++++ drbd-utils:

  - drbd_passive didn't start due to drbd.rules returning error (bsc#1247534)
    * update patch
  - bsc-1247534_drbd-didnt-start-due-to-drbd_rules-returning-err.patch

++++ kernel-default:

  - efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (CVE-2025-38549 bsc#1248235).
  - commit fd82800
  - scsi: target: iscsi: Fix timeout on deleted connection (CVE-2025-38075 bsc#1244734)
  - commit 9ff5b21
  - net: mctp: Don't access ifa_index when missing (CVE-2025-38006 bsc#1244930)
  - commit d4809b9

++++ kernel-rt:

  - efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (CVE-2025-38549 bsc#1248235).
  - commit fd82800
  - scsi: target: iscsi: Fix timeout on deleted connection (CVE-2025-38075 bsc#1244734)
  - commit 9ff5b21
  - net: mctp: Don't access ifa_index when missing (CVE-2025-38006 bsc#1244930)
  - commit d4809b9

++++ pam:

  - Make sure that the buffer containing encrypted passwords get's erased,
    before free.
    [pam_modutil_get-overwrite-password-at-free.patch, bsc#1232234,
    CVE-2024-10041]

++++ pam-full-src:

  - Make sure that the buffer containing encrypted passwords get's erased,
    before free.
    [pam_modutil_get-overwrite-password-at-free.patch, bsc#1232234,
    CVE-2024-10041]

------------------------------------------------------------------
------------------  2025-8-18  -  Aug 18 2025  -------------------
------------------------------------------------------------------

++++ gdk-pixbuf:

  - Add gdk-pixbuf-jpeg-icc-data.patch: be more careful with icc data
    (bsc#1246114 CVE-2025-7345 glgo@GNOME/gdk-pixbuf!217).

++++ git:

  - Update to 2.51.0
  - UI, Workflows & Features
  - Userdiff patterns for the R language have been added.
  - Documentation for "git send-email" has been updated with a
    bit more credential helper and OAuth information.
  - "git cat-file --batch" learns to understand %(objectmode)
    atom to allow the caller to tell missing objects (due to
    repository corruption) and submodules (whose commit objects
    are OK to be missing) apart.
  - "git diff --no-index dirA dirB" can limit the comparison with
    pathspec at the end of the command line, just like normal
    "git diff".
  - "git subtree" (in contrib/) learned to grok GPG signing its
    commits.
  - "git whatchanged" that is longer to type than "git log --raw"
    which is its modern rough equivalent has outlived its
    usefulness more than 10 years ago.  Plan to deprecate and
    remove it.
  - An interchange format for stash entries is defined, and
    subcommand of "git stash" to import/export has been added.
  - "git merge/pull" has been taught the "--compact-summary"
    option to use the compact-summary format, intead of diffstat,
    when showing the summary of the incoming changes.
  - "git imap-send" has been broken for a long time, which has
    been resurrected and then taught to talk OAuth2.0 etc.
  - Some error messages from "git imap-send" has been updated.
  - When "git daemon" sees a signal while attempting to accept()
    a new client, instead of retrying, it skipped it by mistake,
    which has been corrected.
  - The reftable ref backend has matured enough; Git 3.0 will
    make it the default format in a newly created repositories by
    default.
  - "netrc" credential helper has been improved to understand
    textual service names (like smtp) in addition to the numeric
    port numbers (like 25).
  - Lift the limitation to use changed-path filter in "git log"
    so that it can be used for a pathspec with multiple literal
    paths.
  - Clean up the way how signature on commit objects are exported
    to and imported from fast-import stream.
  - Remove unsupported, unused, and unsupportable old option from
    "git log".
  - Document recently added "git imap-send --list" with an
    example.
  - "git pull" learned to pay attention to pull.autostash
    configuration variable, which overrides
    rebase/merge.autostash.
  - "git for-each-ref" learns "--start-after" option to help
    applications that want to page its output.
  - "git switch" and "git restore" are declared to be no longer
    experimental.
  - "git -c alias.foo=bar foo -h baz" reported "'foo' is aliased
    to 'bar'" and then went on to run "git foo -h baz", which was
    unexpected.  Tighten the rule so that alias expansion is
    reported only when "-h" is the sole option.
  - Performance, Internal Implementation, Development Support etc.
  - "git pack-objects" learned to find delta bases from blobs at
    the same path, using the --path-walk API.
  - CodingGuidelines update.
  - Add settings for Solaris 10 & 11.
  - Meson-based build/test framework now understands TAP output
    generated by our tests.
  - "Do not explicitly initialize to zero" rule has been
    clarified in the CodingGuidelines document.
  - A test helper "test_seq" function learned the "-f <fmt>"
    option, which allowed us to simplify a lot of test scripts.
  - A lot of stale stuff has been removed from the contrib/
    hierarchy.
  - "git push" and "git fetch" are taught to update refs in
    batches to gain performance.
  - Some code paths in "git prune" used to ignore the passed-in
    repository object and used the `the_repository` singleton
    instance instead, which has been corrected.
  - Update ".clang-format" and ".editorconfig" to match our style
    guide a bit better.
  - "make coccicheck" succeeds even when spatch made suggestions,
    which has been updated to fail in such a case.
  - Code clean-up around object access API.
  - Define .precision to more canned parse-options type to avoid
    bugs coming from using a variable with a wrong type to
    capture the parsed values.
  - Flipping the default hash function to SHA-256 at Git 3.0
    boundary is planned.
  - Declare weather-balloon we raised for "bool" type 18 months
    ago a success and officially allow using the type in our
    codebase.
  - GIT_TEST_INSTALLED was not honored in the recent topic
    related to SHA256 hashes, which has been corrected.
  - The pop_most_recent_commit() function can have quite
    expensive worst case performance characteristics, which has
    been optimized by using prio-queue data structure.
  - Move structure definition from unrelated header file to where
    it belongs.
  - To help our developers, document what C99 language features
    are being considered for adoption, in addition to what past
    experiments have already decided.
  - The reftable unit tests are now ported to the "clar" unit
    testing framework.
  - Redefine where the multi-pack-index sits in the object
    subsystem, which recently was restructured to allow multiple
    backends that support a single object source that belongs to
    one repository.  A MIDX does span multiple "object sources".
  - Reduce implicit assumption and dependence on the_repository
    in the object-file subsystem.
  - Fixes since v2.50 Unless otherwise noted, all the changes in
    2.50.X maintenance track, including security updates, are
    included in this release.
  - A memory-leak in an error code path has been plugged. (merge
    7082da85cb ly/commit-graph-graph-write-leakfix later to
    maint).
  - A memory-leak in an error code path has been plugged. (merge
    aedebdb6b9 ly/fetch-pack-leakfix later to maint).
  - Some leftover references to documentation source files that
    no longer exist, due to recent ".txt" -> ".adoc" renaming,
    have been corrected. (merge 3717a5775a
    jw/doc-txt-to-adoc-refs later to maint).
  - "git stash -p <pathspec>" improvements. (merge 468817bab2
    pw/stash-p-pathspec-fixes later to maint).
  - "git send-email" incremented its internal message counter
    when a message was edited, which made logic that treats the
    first message specially misbehave, which has been corrected.
    (merge 2cc27b3501 ag/send-email-edit-threading-fix later to
    maint).
  - "git stash" recorded a wrong branch name when submodules are
    present in the current checkout, which has been corrected.
    (merge ffb36c64f2 kj/stash-onbranch-submodule-fix later to
    maint).
  - When asking to apply mailmap to both author and committer
    field while showing a commit object, the field that appears
    later was not correctly parsed and replaced, which has been
    corrected. (merge abf94a283f sa/multi-mailmap-fix later to
    maint).
  - "git maintenance" lacked the care "git gc" had to avoid
    holding onto the repository lock for too long during packing
    refs, which has been remedied. (merge 1b5074e614
    ps/maintenance-ref-lock later to maint).
  - Avoid regexp_constraint and instead use comparison_constraint
    when listing functions to exclude from application of
    coccinelle rules, as spatch can be built with different
    regexp engine X-<. (merge f2ad545813
    jc/cocci-avoid-regexp-constraint later to maint).
  - Updating submodules from the upstream did not work well when
    submodule's HEAD is detached, which has been improved. (merge
    ca62f524c1 jk/submodule-remote-lookup-cleanup later to
    maint).
  - Remove unnecessary check from "git daemon" code. (merge
    0c856224d2 cb/daemon-fd-check-fix later to maint).
  - Use of sysctl() system call to learn the total RAM size used
    on BSDs has been corrected. (merge 781c1cf571
    cb/total-ram-bsd-fix later to maint).
  - Drop FreeBSD 4 support and declare that we support only
    FreeBSD 12 or later, which has memmem() supported. (merge
    0392f976a7 bs/config-mak-freebsd later to maint).
  - A diff-filter with negative-only specification like "git log
  - -diff-filter=d" did not trigger correctly, which has been
    fixed. (merge 375ac087c5 jk/all-negative-diff-filter-fix
    later to maint).
  - A failure to open the index file for writing due to
    conflicting access did not state what went wrong, which has
    been corrected. (merge 9455397a5c
    hy/read-cache-lock-error-fix later to maint).
  - Tempfile removal fix in the codepath to sign commits with SSH
    keys. (merge 4498127b04 re/ssh-sign-buffer-fix later to
    maint).
  - Code and test clean-up around string-list API. (merge
    6e5b26c3ff sj/string-list later to maint).
  - "git apply -N" should start from the current index and
    register only new files, but it instead started from an empty
    index, which has been corrected. (merge 2b49d97fcb
    rp/apply-intent-to-add-fix later to maint).
  - Leakfix with a new and a bit invasive test on pack-bitmap
    files. (merge bfd5522e98 ly/load-bitmap-leakfix later to
    maint).
  - "git fetch --prune" used to be O(n^2) expensive when there
    are many refs, which has been corrected. (merge 87d8d8c5d0
    ph/fetch-prune-optim later to maint).
  - When a ref creation at refs/heads/foo/bar fails, the files
    backend now removes refs/heads/foo/ if the directory is
    otherwise not used. (merge a3a7f20516
    ps/refs-files-remove-empty-parent later to maint).
  - "pack-objects" has been taught to avoid pointing into objects
    in cruft packs from midx.
  - "git remote" now detects remote names that overlap with each
    other (e.g., remote nickname "outer" and "outer/inner" are
    used at the same time), as it will lead to overlapping
    remote-tracking branches. (merge a5a727c448
    jk/remote-avoid-overlapping-names later to maint).
  - The gpg.program configuration variable, which names a
    pathname to the (custom) GPG compatible program, can now be
    spelled with ~tilde expansion. (merge 7d275cd5c0
    jb/gpg-program-variable-is-a-pathname later to maint).
  - Our <sane-ctype.h> header file relied on that the
    system-supplied <ctype.h> header is not later included, which
    would override our macro definitions, but "amazon linux"
    broke this assumption.  Fix this by preemptively including
    <ctype.h> near the beginning of <sane-ctype.h> ourselves.
    (merge 9d3b33125f ps/sane-ctype-workaround later to maint).
  - Clean-up compat/bswap.h mess. (merge f4ac32c03a
    ss/compat-bswap-revamp later to maint).
  - Meson-based build did not handle libexecdir setting
    correctly, which has been corrected. (merge 056dbe8612
    rj/meson-libexecdir-fix later to maint).
  - Document that we do not require "real" name when signing your
    patches off. (merge 1f0fed312a
    bc/contribution-under-non-real-names later to maint).
  - "git commit" that concludes a conflicted merge failed to
    notice and remove existing comment added automatically (like
    "# Conflicts:") when the core.commentstring is set to 'auto'.
    (merge 92b7c7c9f5 ac/auto-comment-char-fix later to maint).
  - "git rebase -i" with bogus rebase.instructionFormat
    configuration failed to produce the todo file after recording
    the state files, leading to confused "git status"; this has
    been corrected. (merge ade14bffd7
    ow/rebase-verify-insn-fmt-before-initializing-state later to
    maint).
  - A few file descriptors left unclosed upon program completion
    in a few test helper programs are now closed. (merge
    0f1b33815b hl/test-helper-fd-close later to maint).
  - Interactive prompt code did not correctly strip CRLF from the
    end of line on Windows. (merge 711a20827b js/prompt-crlf-fix
    later to maint).
  - The config API had a set of convenience wrapper functions
    that implicitly use the_repository instance; they have been
    removed and inlined at the calling sites.
  - "git add/etc -p" now honor the diff.context configuration
    variable, and also they learn to honor the -U<n> command-line
    option. (merge 2b3ae04011 lm/add-p-context later to maint).
  - The case where a new submodule takes a path where there used
    to be a completely different subproject is now dealt with a
    bit better than before. (merge 5ed8c5b465
    kj/renamed-submodule later to maint).
  - The deflate codepath in "git archive --format=zip" had a
    longstanding bug coming from misuse of zlib API, which has
    been corrected.
  - drop patches included in update:
    0001-git-gui-Replace-null_sha1-with-nullid.patch
    0001-gitk-Add-support-of-SHA256-repo.patch
    0002-git-gui-Add-support-of-SHA256-repo.patch
  - refreshed patches:
    CVE-2024-24577.patch
    completion-wordbreaks.diff
    git-tcsh-completion-fixes.diff
    setup-don-t-fail-if-commondir-reference-is-deleted.patch
  - contrib/workdir is dropped. remove references for it.

++++ kernel-default:

  - printk: nbcon: Allow reacquire during panic (bsc#1246688).
  - commit 941c111
  - netfilter: nft_set_pipapo: clamp maximum map bucket size to
    INT_MAX (CVE-2025-38201 bsc#1245977).
  - commit 4f77e20
  - netfilter: flowtable: account for Ethernet header in
    nf_flow_pppoe_proto() (CVE-2025-38441 bsc#1247167).
  - commit d5364ae
  - netfilter: nf_conntrack: fix crash due to removal of
    uninitialised entry (CVE-2025-38472 bsc#1247313).
  - commit 11979f4
  - netfilter: nft_set_hash: unaligned atomic read on struct
    nft_set_ext (git-fixes).
  - commit 596135b
  - powerpc/kernel: Fix ppc_save_regs inclusion in build
    (bsc#1215199).
  - powerpc: do not build ppc_save_regs.o always (bsc#1215199).
  - commit 8f66a65
  - s390/mm: Allocate page table with PAGE_SIZE granularity
    (git-fixes bsc#1247838).
  - commit bb475d8
  - x86/vmscape: Warn when STIBP is disabled with SMT (bsc#1247483 CVE-2025-40300).
  - commit 0596b58
  - x86/bugs: Move cpu_bugs_smt_update() down (bsc#1247483 CVE-2025-40300).
  - commit fcdc737
  - x86/vmscape: Enable the mitigation (bsc#1247483 CVE-2025-40300).
  - Update config files.
  - commit 0178963
  - powerpc/eeh: Make EEH driver device hotplug safe (bsc#1215199).
  - powerpc/eeh: Export eeh_unfreeze_pe() (bsc#1215199).
  - PCI: pnv_php: Work around switches with broken presence
    detection (bsc#1215199).
  - PCI: pnv_php: Clean up allocated IRQs on unplug (bsc#1215199).
  - arch/powerpc: Remove .interp section in vmlinux (bsc#1215199).
  - commit c0014cb
  - x86/vmscape: Add conditional IBPB mitigation (bsc#1247483 CVE-2025-40300).
  - commit 4212c10
  - sched/psi: Fix psi_seq initialization (bsc#1248155).
  - commit 2dd3707
  - x86/vmscape: Enumerate VMSCAPE bug (bsc#1247483 CVE-2025-40300).
  - commit 91b029d
  - Documentation/hw-vuln: Add VMSCAPE documentation (bsc#1247483 CVE-2025-40300).
  - commit c6b560b

++++ kernel-rt:

  - printk: nbcon: Allow reacquire during panic (bsc#1246688).
  - commit 941c111
  - netfilter: nft_set_pipapo: clamp maximum map bucket size to
    INT_MAX (CVE-2025-38201 bsc#1245977).
  - commit 4f77e20
  - netfilter: flowtable: account for Ethernet header in
    nf_flow_pppoe_proto() (CVE-2025-38441 bsc#1247167).
  - commit d5364ae
  - netfilter: nf_conntrack: fix crash due to removal of
    uninitialised entry (CVE-2025-38472 bsc#1247313).
  - commit 11979f4
  - netfilter: nft_set_hash: unaligned atomic read on struct
    nft_set_ext (git-fixes).
  - commit 596135b
  - powerpc/kernel: Fix ppc_save_regs inclusion in build
    (bsc#1215199).
  - powerpc: do not build ppc_save_regs.o always (bsc#1215199).
  - commit 8f66a65
  - s390/mm: Allocate page table with PAGE_SIZE granularity
    (git-fixes bsc#1247838).
  - commit bb475d8
  - x86/vmscape: Warn when STIBP is disabled with SMT (bsc#1247483 CVE-2025-40300).
  - commit 0596b58
  - x86/bugs: Move cpu_bugs_smt_update() down (bsc#1247483 CVE-2025-40300).
  - commit fcdc737
  - x86/vmscape: Enable the mitigation (bsc#1247483 CVE-2025-40300).
  - Update config files.
  - commit 0178963
  - powerpc/eeh: Make EEH driver device hotplug safe (bsc#1215199).
  - powerpc/eeh: Export eeh_unfreeze_pe() (bsc#1215199).
  - PCI: pnv_php: Work around switches with broken presence
    detection (bsc#1215199).
  - PCI: pnv_php: Clean up allocated IRQs on unplug (bsc#1215199).
  - arch/powerpc: Remove .interp section in vmlinux (bsc#1215199).
  - commit c0014cb
  - x86/vmscape: Add conditional IBPB mitigation (bsc#1247483 CVE-2025-40300).
  - commit 4212c10
  - sched/psi: Fix psi_seq initialization (bsc#1248155).
  - commit 2dd3707
  - x86/vmscape: Enumerate VMSCAPE bug (bsc#1247483 CVE-2025-40300).
  - commit 91b029d
  - Documentation/hw-vuln: Add VMSCAPE documentation (bsc#1247483 CVE-2025-40300).
  - commit c6b560b

------------------------------------------------------------------
------------------  2025-8-17  -  Aug 17 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ata: libata-scsi: Fix CDL control (git-fixes).
  - commit 0aa8bcb

++++ kernel-rt:

  - ata: libata-scsi: Fix CDL control (git-fixes).
  - commit 0aa8bcb

++++ openssl-3:

  - Move ssl configuration files to the libopenssl package [bsc#1247463]
  - Don't install unneeded NOTES

------------------------------------------------------------------
------------------  2025-8-16  -  Aug 16 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/amdgpu: fix incorrect vm flags to map bo (git-fixes).
  - drm/amdgpu: fix vram reservation issue (git-fixes).
  - drm/bridge: fix OF node leak (git-fixes).
  - ALSA: usb-audio: Validate UAC3 cluster segment descriptors
    (git-fixes).
  - ALSA: usb-audio: Validate UAC3 power domain descriptors, too
    (git-fixes).
  - ASoC: fsl_sai: replace regmap_write with regmap_update_bits
    (git-fixes).
  - gpio: mlxbf3: use platform_get_irq_optional() (git-fixes).
  - Revert "gpio: mlxbf3: only get IRQ for device instance 0"
    (git-fixes).
  - soc/tegra: pmc: Ensure power-domains are in a known state
    (git-fixes).
  - net: mdio: mdio-bcm-unimac: Correct rate fallback logic
    (git-fixes).
  - net: usbnet: Fix the wrong netif_carrier_on() call (git-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-d1xxx (MB
    8A26) (stable-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-s0xxx
    (stable-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-r1xxx
    (stable-fixes).
  - Bluetooth: btusb: Add USB ID 3625:010b for TP-LINK Archer
    TX10UB Nano (stable-fixes).
  - USB: serial: option: add Foxconn T99W709 (stable-fixes).
  - ASoC: amd: yc: Add DMI quirk for HP Laptop 17 cp-2033dx
    (stable-fixes).
  - ASoC: amd: yc: Add DMI entries to support HP 15-fb1xxx
    (stable-fixes).
  - ASoC: Intel: fix SND_SOC_SOF dependencies (stable-fixes).
  - ALSA: hda/cs35l56: Workaround bad dev-index on Lenovo Yoga
    Book 9i GenX (stable-fixes).
  - ASoC: amd: yc: add DMI quirk for ASUS M6501RM (stable-fixes).
  - drm/i915/ddi: only call shutdown hooks for valid encoders
    (stable-fixes).
  - drm/i915/display: add intel_encoder_is_hdmi() (stable-fixes).
  - drm/i915/ddi: gracefully handle errors from
    intel_ddi_init_hdmi_connector() (stable-fixes).
  - drm/i915/hdmi: add error handling in g4x_hdmi_init()
    (stable-fixes).
  - drm/i915/hdmi: propagate errors from intel_hdmi_init_connector()
    (stable-fixes).
  - drm/i915/ddi: change intel_ddi_init_{dp, hdmi}_connector()
    return type (stable-fixes).
  - accel/ivpu: Fix reset_engine debugfs file logic (stable-fixes).
  - commit 6ed913d

++++ kernel-firmware-amdgpu:

  - Update to version 20250815 (git commit 07ed893df57c):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-rt:

  - drm/amdgpu: fix incorrect vm flags to map bo (git-fixes).
  - drm/amdgpu: fix vram reservation issue (git-fixes).
  - drm/bridge: fix OF node leak (git-fixes).
  - ALSA: usb-audio: Validate UAC3 cluster segment descriptors
    (git-fixes).
  - ALSA: usb-audio: Validate UAC3 power domain descriptors, too
    (git-fixes).
  - ASoC: fsl_sai: replace regmap_write with regmap_update_bits
    (git-fixes).
  - gpio: mlxbf3: use platform_get_irq_optional() (git-fixes).
  - Revert "gpio: mlxbf3: only get IRQ for device instance 0"
    (git-fixes).
  - soc/tegra: pmc: Ensure power-domains are in a known state
    (git-fixes).
  - net: mdio: mdio-bcm-unimac: Correct rate fallback logic
    (git-fixes).
  - net: usbnet: Fix the wrong netif_carrier_on() call (git-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-d1xxx (MB
    8A26) (stable-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-s0xxx
    (stable-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-r1xxx
    (stable-fixes).
  - Bluetooth: btusb: Add USB ID 3625:010b for TP-LINK Archer
    TX10UB Nano (stable-fixes).
  - USB: serial: option: add Foxconn T99W709 (stable-fixes).
  - ASoC: amd: yc: Add DMI quirk for HP Laptop 17 cp-2033dx
    (stable-fixes).
  - ASoC: amd: yc: Add DMI entries to support HP 15-fb1xxx
    (stable-fixes).
  - ASoC: Intel: fix SND_SOC_SOF dependencies (stable-fixes).
  - ALSA: hda/cs35l56: Workaround bad dev-index on Lenovo Yoga
    Book 9i GenX (stable-fixes).
  - ASoC: amd: yc: add DMI quirk for ASUS M6501RM (stable-fixes).
  - drm/i915/ddi: only call shutdown hooks for valid encoders
    (stable-fixes).
  - drm/i915/display: add intel_encoder_is_hdmi() (stable-fixes).
  - drm/i915/ddi: gracefully handle errors from
    intel_ddi_init_hdmi_connector() (stable-fixes).
  - drm/i915/hdmi: add error handling in g4x_hdmi_init()
    (stable-fixes).
  - drm/i915/hdmi: propagate errors from intel_hdmi_init_connector()
    (stable-fixes).
  - drm/i915/ddi: change intel_ddi_init_{dp, hdmi}_connector()
    return type (stable-fixes).
  - accel/ivpu: Fix reset_engine debugfs file logic (stable-fixes).
  - commit 6ed913d

------------------------------------------------------------------
------------------  2025-8-15  -  Aug 15 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix exclude list for live image builds
    When specifying a filesystem attribute for a live image build,
    the rootfs gets build directly into this filesystem instead of
    being a squashfs wraped ext4 which is the default layout for
    compatibility reasons. In this direct filesystem mode the
    exclude list was not passed along to the filesystem creation
    and causes unwanted metadata to be part of the final image.
    This Fixes #2873

++++ drbd-utils:

  - drbd_passive didn't start due to drbd.rules returning error (bsc#1247534)
    * remove patch
  - bsc-1239437_drbd.rules-fix-missing-udev-device.patch
    * add patch
  - bsc-1247534_drbd-didnt-start-due-to-drbd_rules-returning-err.patch

++++ kernel-default:

  - ACPI: processor: perflib: Move problematic pr->performance check
    (git-fixes).
  - net: usb: asix_devices: add phy_mask for ax88772 mdio bus
    (git-fixes).
  - commit c0405fc

++++ kernel-rt:

  - ACPI: processor: perflib: Move problematic pr->performance check
    (git-fixes).
  - net: usb: asix_devices: add phy_mask for ax88772 mdio bus
    (git-fixes).
  - commit c0405fc

++++ python313-core:

  - Update to 3.13.7:
  - gh-137583: Fix a deadlock introduced in 3.13.6 when a call
    to ssl.SSLSocket.recv was blocked in one thread, and then
    another method on the object (such as ssl.SSLSocket.send) was
    subsequently called in another thread.
  - gh-137044: Return large limit values as positive integers
    instead of negative integers in resource.getrlimit().
    Accept large values and reject negative values (except
    RLIM_INFINITY) for limits in resource.setrlimit().
  - gh-136914: Fix retrieval of doctest.DocTest.lineno
    for objects decorated with functools.cache() or
    functools.cached_property.
  - gh-131788: Make ResourceTracker.send from multiprocessing
    re-entrant safe
  - gh-136155: We are now checking for fatal errors in EPUB
    builds in CI.
  - gh-137400: Fix a crash in the free threading build when
    disabling profiling or tracing across all threads with
    PyEval_SetProfileAllThreads() or PyEval_SetTraceAllThreads()
    or their Python equivalents threading.settrace_all_threads()
    and threading.setprofile_all_threads().
  - Remove upstreamed patch:
  - gh137583-only-lock-SSL-context.patch

++++ python313:

  - Update to 3.13.7:
  - gh-137583: Fix a deadlock introduced in 3.13.6 when a call
    to ssl.SSLSocket.recv was blocked in one thread, and then
    another method on the object (such as ssl.SSLSocket.send) was
    subsequently called in another thread.
  - gh-137044: Return large limit values as positive integers
    instead of negative integers in resource.getrlimit().
    Accept large values and reject negative values (except
    RLIM_INFINITY) for limits in resource.setrlimit().
  - gh-136914: Fix retrieval of doctest.DocTest.lineno
    for objects decorated with functools.cache() or
    functools.cached_property.
  - gh-131788: Make ResourceTracker.send from multiprocessing
    re-entrant safe
  - gh-136155: We are now checking for fatal errors in EPUB
    builds in CI.
  - gh-137400: Fix a crash in the free threading build when
    disabling profiling or tracing across all threads with
    PyEval_SetProfileAllThreads() or PyEval_SetTraceAllThreads()
    or their Python equivalents threading.settrace_all_threads()
    and threading.setprofile_all_threads().
  - Remove upstreamed patch:
  - gh137583-only-lock-SSL-context.patch

------------------------------------------------------------------
------------------  2025-8-14  -  Aug 14 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update to 344
    * Changes since 340
  - 344
    * Bug fixes and translation updates
  - 343
    * login: Improve error message for unsupported shells
    * cockpit: Handle file access issues with files in machines.d
    * Translation updates
  - 342
    * systemd: ensure update() is called at least once for tuned-dialog
    * Translation updates
  - 341
    * services: show link to podman page for quadlets
    * Bug fixes and translation updates
  - Remove kdump-nfs-fixes.patch as this was upstreamed
  - Fix not falling back to PRETTY_NAME in SUSE_PRETTY_NAME patches bsc#1248446

++++ kernel-default:

  - Refresh patches.kabi/xsk-Fix-race-condition-in-AF_XDP-generic-RX-path.patch
    Drop the static_assert() kABI checks temporarily until we have a proper
    solution to signal kABI verification.
  - commit e7bb4bf
  - Move pesign-obs-integration requirement from kernel-syms to kernel devel
    subpackage (bsc#1248108).
  - commit e707e41
  - PCI: dw-rockchip: Replace PERST# sleep time with proper macro
    (git-fixes).
  - commit bb054e5
  - PCI: rockchip: Set Target Link Speed to 5.0 GT/s before
    retraining (git-fixes).
  - PCI: rockchip: Use standard PCIe definitions (git-fixes).
  - PCI: imx6: Add IMX8MQ_EP third 64-bit BAR in epc_features
    (git-fixes).
  - PCI: qcom: Wait PCIE_RESET_CONFIG_WAIT_MS after link-up IRQ
    (git-fixes).
  - PCI: dw-rockchip: Wait PCIE_RESET_CONFIG_WAIT_MS after link-up
    IRQ (git-fixes).
  - PCI: Rename PCIE_RESET_CONFIG_DEVICE_WAIT_MS to
    PCIE_RESET_CONFIG_WAIT_MS (git-fixes).
  - PCI/portdrv: Use is_pciehp instead of is_hotplug_bridge
    (git-fixes).
  - PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports
    (git-fixes).
  - kABI: PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug
    Capable ports (git-fixes).
  - PCI: Support Immediate Readiness on devices without PM
    capabilities (git-fixes).
  - serial: 8250: fix panic due to PSLVERR (git-fixes).
  - PCI: imx6: Add i.MX8Q PCIe Endpoint (EP) support (git-fixes).
  - commit d9839d9
  - habanalabs: fix UAF in export_dmabuf() (git-fixes).
  - commit e4702d9
  - mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() (git-fixes)
  - commit ca79f49
  - bpf, arm64: Fix fp initialization for exception boundary (git-fixes)
  - commit 99a8d8c
  - arm64: dts: imx8mm-venice-gw7904: Increase HS400 USDHC clock speed (git-fixes)
  - commit eead6a6
  - arm64: dts: imx8mm-venice-gw7903: Increase HS400 USDHC clock speed (git-fixes)
  - commit cdabae0
  - arm64: dts: imx8mn-venice-gw7902: Increase HS400 USDHC clock speed (git-fixes)
  - commit 9c47c1b
  - arm64: dts: imx8mm-venice-gw7902: Increase HS400 USDHC clock speed (git-fixes)
  - commit eb83c61
  - arm64: dts: imx8mm-venice-gw7901: Increase HS400 USDHC clock speed (git-fixes)
  - commit 2f99788
  - arm64: dts: imx8mp-venice-gw702x: Increase HS400 USDHC clock speed (git-fixes)
  - commit bf3a9db
  - arm64: dts: imx8mm-venice-gw700x: Increase HS400 USDHC clock speed (git-fixes)
  - commit 1f06f91
  - arm64: dts: imx8mn-beacon: Fix HS400 USDHC clock speed (git-fixes)
  - commit 35f4757
  - arm64: dts: imx8mm-beacon: Fix HS400 USDHC clock speed (git-fixes)
  - commit 3b1791e
  - arm64: dts: freescale: imx93-tqma9352: Limit BUCK2 to 600mV (git-fixes)
  - commit d3b2a07
  - arm64: dts: st: fix timer used for ticks (git-fixes)
  - commit 564f85e
  - arm64: dts: rockchip: fix endpoint dtc warning for PX30 ISP (git-fixes)
  - commit f18579c
  - arm64: dts: exynos: gs101: ufs: add dma-coherent property (git-fixes)
  - commit 22fb09f
  - arm64: dts: exynos: gs101: Add 'local-timer-stop' to cpuidle nodes (git-fixes)
  - commit b3eb296
  - arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() (git-fixes)
  - commit 1656f5d
  - arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi CM5 (git-fixes)
  - commit 06668ed
  - arm64: dts: freescale: imx8mm-verdin: Keep LDO5 always on (git-fixes)
  - commit 7a17452
  - arm64: dts: imx95: Correct the DMA interrupter number of pcie0_ep (git-fixes)
  - commit d3f8c87
  - arm64: dts: add big-endian property back into watchdog node (git-fixes)
  - commit 28f0cfd
  - arm64: dts: imx8mp-venice-gw74xx: fix TPM SPI frequency (git-fixes)
  - commit 6ca14ce
  - arm64: dts: imx8mp-venice-gw73xx: fix TPM SPI frequency (git-fixes)
  - commit 35c5043
  - arm64: dts: imx8mp-venice-gw72xx: fix TPM SPI frequency (git-fixes)
  - commit f964f6e
  - arm64: dts: imx8mp-venice-gw71xx: fix TPM SPI frequency (git-fixes)
  - commit 1221df5
  - arm64/mm: Drop wrong writes into TCR2_EL1 (git-fixes)
  - commit e3d963f
  - arm64: poe: Handle spurious Overlay faults (git-fixes)
  - commit c62c76a
  - arm64: Filter out SME hwcaps when FEAT_SME isn't implemented (git-fixes)
  - commit 81f649f
  - arm64: dts: apple: t8103: Fix PCIe BCM4377 nodename (git-fixes)
  - commit 9f9e25d
  - arm64: Restrict pagetable teardown to avoid false warning (git-fixes)
  - commit dee5a62
  - arm64/mm: Close theoretical race where stale TLB entry remains valid (git-fixes)
  - commit 2b9ed9e
  - arm64: dts: rockchip: fix internal USB hub instability on RK3399 Puma (git-fixes)
  - commit e5bad02
  - arm64: dts: rockchip: Update eMMC for NanoPi R5 series (git-fixes)
  - commit 7f552e2
  - arm64: dts: imx8mn-beacon: Set SAI5 MCLK direction to output for HDMI (git-fixes)
  - commit 5876cdf
  - arm64: dts: imx8mm-beacon: Set SAI5 MCLK direction to output for HDMI (git-fixes)
  - commit a98adac
  - arm64: dts: imx8mp-beacon: Fix RTC capacitive load (git-fixes)
  - commit 51525e3
  - arm64: dts: imx8mn-beacon: Fix RTC capacitive load (git-fixes)
  - commit ad05c9f
  - arm64: dts: imx8mm-beacon: Fix RTC capacitive load (git-fixes)
  - commit dfb5eed
  - arm64: tegra: Add uartd serial alias for Jetson TX1 module (git-fixes)
  - commit e812e32
  - arm64: tegra: Drop remaining serial clock-names and reset-names (git-fixes)
  - commit e6ab9c1
  - arm64: dts: rockchip: Add vcc-supply to SPI flash on rk3566-rock3c (git-fixes)
  - commit 13e0c58
  - arm64: dts: rockchip: Move SHMEM memory to reserved memory on rk3588 (git-fixes)
  - commit 344f8c5
  - kbuild: rust: add rustc-min-version support function (git-fixes)
  - commit 573f96a
  - arm64: zynqmp: add clock-output-names property in clock nodes (git-fixes)
  - commit 82c486e
  - arm64: tegra: p2597: Fix gpio for vdd-1v8-dis regulator (git-fixes)
  - commit 6c6ebf5
  - arm64: tegra: Resize aperture for the IGX PCIe C5 slot (git-fixes)
  - commit d1d248d
  - arm64/mm: Check pmd_table() in pmd_trans_huge() (git-fixes)
  - commit 04e9ebd
  - arm64/mm: Check PUD_TYPE_TABLE in pud_bad() (git-fixes)
  - commit 68e8096
  - arm64: cputype: Add QCOM_CPU_PART_KRYO_3XX_GOLD (git-fixes)
  - commit 8062927
  - arm64/sysreg: Add register fields for HFGWTR2_EL2 (git-fixes)
  - commit c06ac5b
  - arm64/sysreg: Add register fields for HFGRTR2_EL2 (git-fixes)
  - commit ac00342
  - arm64/sysreg: Add register fields for HFGITR2_EL2 (git-fixes)
  - commit 40903bf
  - arm64/sysreg: Add register fields for HDFGWTR2_EL2 (git-fixes)
  - commit 9b26437
  - arm64/sysreg: Add register fields for HDFGRTR2_EL2 (git-fixes)
  - commit 6c6c2d1
  - arm64/sysreg: Update register fields for ID_AA64MMFR0_EL1 (git-fixes)
  - commit 1862d57
  - arm64: rust: clean Rust 1.85.0 warning using softfloat target (git-fixes)
  - commit 2c2605f
  - arm64/mm: Ensure adequate HUGE_MAX_HSTATE (git-fixes)
  - commit d144825

++++ kernel-firmware-mediatek:

  - Update to version 20250813 (git commit acb26167a103):
    * mediatek: Add MT8189 SCP firmware

++++ kernel-rt:

  - Refresh patches.kabi/xsk-Fix-race-condition-in-AF_XDP-generic-RX-path.patch
    Drop the static_assert() kABI checks temporarily until we have a proper
    solution to signal kABI verification.
  - commit e7bb4bf
  - Move pesign-obs-integration requirement from kernel-syms to kernel devel
    subpackage (bsc#1248108).
  - commit e707e41
  - PCI: dw-rockchip: Replace PERST# sleep time with proper macro
    (git-fixes).
  - commit bb054e5
  - PCI: rockchip: Set Target Link Speed to 5.0 GT/s before
    retraining (git-fixes).
  - PCI: rockchip: Use standard PCIe definitions (git-fixes).
  - PCI: imx6: Add IMX8MQ_EP third 64-bit BAR in epc_features
    (git-fixes).
  - PCI: qcom: Wait PCIE_RESET_CONFIG_WAIT_MS after link-up IRQ
    (git-fixes).
  - PCI: dw-rockchip: Wait PCIE_RESET_CONFIG_WAIT_MS after link-up
    IRQ (git-fixes).
  - PCI: Rename PCIE_RESET_CONFIG_DEVICE_WAIT_MS to
    PCIE_RESET_CONFIG_WAIT_MS (git-fixes).
  - PCI/portdrv: Use is_pciehp instead of is_hotplug_bridge
    (git-fixes).
  - PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports
    (git-fixes).
  - kABI: PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug
    Capable ports (git-fixes).
  - PCI: Support Immediate Readiness on devices without PM
    capabilities (git-fixes).
  - serial: 8250: fix panic due to PSLVERR (git-fixes).
  - PCI: imx6: Add i.MX8Q PCIe Endpoint (EP) support (git-fixes).
  - commit d9839d9
  - habanalabs: fix UAF in export_dmabuf() (git-fixes).
  - commit e4702d9
  - mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() (git-fixes)
  - commit ca79f49
  - bpf, arm64: Fix fp initialization for exception boundary (git-fixes)
  - commit 99a8d8c
  - arm64: dts: imx8mm-venice-gw7904: Increase HS400 USDHC clock speed (git-fixes)
  - commit eead6a6
  - arm64: dts: imx8mm-venice-gw7903: Increase HS400 USDHC clock speed (git-fixes)
  - commit cdabae0
  - arm64: dts: imx8mn-venice-gw7902: Increase HS400 USDHC clock speed (git-fixes)
  - commit 9c47c1b
  - arm64: dts: imx8mm-venice-gw7902: Increase HS400 USDHC clock speed (git-fixes)
  - commit eb83c61
  - arm64: dts: imx8mm-venice-gw7901: Increase HS400 USDHC clock speed (git-fixes)
  - commit 2f99788
  - arm64: dts: imx8mp-venice-gw702x: Increase HS400 USDHC clock speed (git-fixes)
  - commit bf3a9db
  - arm64: dts: imx8mm-venice-gw700x: Increase HS400 USDHC clock speed (git-fixes)
  - commit 1f06f91
  - arm64: dts: imx8mn-beacon: Fix HS400 USDHC clock speed (git-fixes)
  - commit 35f4757
  - arm64: dts: imx8mm-beacon: Fix HS400 USDHC clock speed (git-fixes)
  - commit 3b1791e
  - arm64: dts: freescale: imx93-tqma9352: Limit BUCK2 to 600mV (git-fixes)
  - commit d3b2a07
  - arm64: dts: st: fix timer used for ticks (git-fixes)
  - commit 564f85e
  - arm64: dts: rockchip: fix endpoint dtc warning for PX30 ISP (git-fixes)
  - commit f18579c
  - arm64: dts: exynos: gs101: ufs: add dma-coherent property (git-fixes)
  - commit 22fb09f
  - arm64: dts: exynos: gs101: Add 'local-timer-stop' to cpuidle nodes (git-fixes)
  - commit b3eb296
  - arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() (git-fixes)
  - commit 1656f5d
  - arm64: dts: rockchip: Add cd-gpios for sdcard detect on Cool Pi CM5 (git-fixes)
  - commit 06668ed
  - arm64: dts: freescale: imx8mm-verdin: Keep LDO5 always on (git-fixes)
  - commit 7a17452
  - arm64: dts: imx95: Correct the DMA interrupter number of pcie0_ep (git-fixes)
  - commit d3f8c87
  - arm64: dts: add big-endian property back into watchdog node (git-fixes)
  - commit 28f0cfd
  - arm64: dts: imx8mp-venice-gw74xx: fix TPM SPI frequency (git-fixes)
  - commit 6ca14ce
  - arm64: dts: imx8mp-venice-gw73xx: fix TPM SPI frequency (git-fixes)
  - commit 35c5043
  - arm64: dts: imx8mp-venice-gw72xx: fix TPM SPI frequency (git-fixes)
  - commit f964f6e
  - arm64: dts: imx8mp-venice-gw71xx: fix TPM SPI frequency (git-fixes)
  - commit 1221df5
  - arm64/mm: Drop wrong writes into TCR2_EL1 (git-fixes)
  - commit e3d963f
  - arm64: poe: Handle spurious Overlay faults (git-fixes)
  - commit c62c76a
  - arm64: Filter out SME hwcaps when FEAT_SME isn't implemented (git-fixes)
  - commit 81f649f
  - arm64: dts: apple: t8103: Fix PCIe BCM4377 nodename (git-fixes)
  - commit 9f9e25d
  - arm64: Restrict pagetable teardown to avoid false warning (git-fixes)
  - commit dee5a62
  - arm64/mm: Close theoretical race where stale TLB entry remains valid (git-fixes)
  - commit 2b9ed9e
  - arm64: dts: rockchip: fix internal USB hub instability on RK3399 Puma (git-fixes)
  - commit e5bad02
  - arm64: dts: rockchip: Update eMMC for NanoPi R5 series (git-fixes)
  - commit 7f552e2
  - arm64: dts: imx8mn-beacon: Set SAI5 MCLK direction to output for HDMI (git-fixes)
  - commit 5876cdf
  - arm64: dts: imx8mm-beacon: Set SAI5 MCLK direction to output for HDMI (git-fixes)
  - commit a98adac
  - arm64: dts: imx8mp-beacon: Fix RTC capacitive load (git-fixes)
  - commit 51525e3
  - arm64: dts: imx8mn-beacon: Fix RTC capacitive load (git-fixes)
  - commit ad05c9f
  - arm64: dts: imx8mm-beacon: Fix RTC capacitive load (git-fixes)
  - commit dfb5eed
  - arm64: tegra: Add uartd serial alias for Jetson TX1 module (git-fixes)
  - commit e812e32
  - arm64: tegra: Drop remaining serial clock-names and reset-names (git-fixes)
  - commit e6ab9c1
  - arm64: dts: rockchip: Add vcc-supply to SPI flash on rk3566-rock3c (git-fixes)
  - commit 13e0c58
  - arm64: dts: rockchip: Move SHMEM memory to reserved memory on rk3588 (git-fixes)
  - commit 344f8c5
  - kbuild: rust: add rustc-min-version support function (git-fixes)
  - commit 573f96a
  - arm64: zynqmp: add clock-output-names property in clock nodes (git-fixes)
  - commit 82c486e
  - arm64: tegra: p2597: Fix gpio for vdd-1v8-dis regulator (git-fixes)
  - commit 6c6ebf5
  - arm64: tegra: Resize aperture for the IGX PCIe C5 slot (git-fixes)
  - commit d1d248d
  - arm64/mm: Check pmd_table() in pmd_trans_huge() (git-fixes)
  - commit 04e9ebd
  - arm64/mm: Check PUD_TYPE_TABLE in pud_bad() (git-fixes)
  - commit 68e8096
  - arm64: cputype: Add QCOM_CPU_PART_KRYO_3XX_GOLD (git-fixes)
  - commit 8062927
  - arm64/sysreg: Add register fields for HFGWTR2_EL2 (git-fixes)
  - commit c06ac5b
  - arm64/sysreg: Add register fields for HFGRTR2_EL2 (git-fixes)
  - commit ac00342
  - arm64/sysreg: Add register fields for HFGITR2_EL2 (git-fixes)
  - commit 40903bf
  - arm64/sysreg: Add register fields for HDFGWTR2_EL2 (git-fixes)
  - commit 9b26437
  - arm64/sysreg: Add register fields for HDFGRTR2_EL2 (git-fixes)
  - commit 6c6c2d1
  - arm64/sysreg: Update register fields for ID_AA64MMFR0_EL1 (git-fixes)
  - commit 1862d57
  - arm64: rust: clean Rust 1.85.0 warning using softfloat target (git-fixes)
  - commit 2c2605f
  - arm64/mm: Ensure adequate HUGE_MAX_HSTATE (git-fixes)
  - commit d144825

++++ harfbuzz:

  - Update to version 11.4.1:
    + Fix clang compiler warnings.
  - Changes from version 11.4.0:
    + General shaping and subsetting speedups.
    + Fix in Graphite shaping backend when glyph advances became
    negative.
    + Subsetting improvements, pruning empty mark-attachment lookups.
    + Don't use the macro name _S, which is reserved by system
    liberaries.
    + Build fixes and speedup.
    + Add a kbts shaping backend that calls into the kb_text_shape
    single-header shaping library. This is purely for testing and
    performance evaluation and we do NOT recommend using it for any
    other purposes.

++++ openldap2_6:

  - Update to version 2.6.10+10:
    * Add export symbols related to LDAP_CONNECTIONLESS
  - Initial import of OpenLDAP 2.6

++++ mdadm:

  - Fix systemd unit file handling in spec file (boo#1207266)
    * make all units known to systemd
    * restart only timers and mdmonitor.service

++++ nvidia-open-driver-G06-signed:

  - make sure Requires to nvidia packages are not added for SLE16

------------------------------------------------------------------
------------------  2025-8-13  -  Aug 13 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses
    (bsc#1242782, CVE-2025-23141).
  - commit f303436
  - net: libwx: remove duplicate page_pool_put_full_page()
    (CVE-2025-38490 bsc#1247243).
  - commit eca8cf3
  - drm/amd/display: Add more checks for DSC / HUBP ONO guarantees (bsc#1247078 CVE-2025-38360)
  - commit 273e174

++++ kernel-rt:

  - KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses
    (bsc#1242782, CVE-2025-23141).
  - commit f303436
  - net: libwx: remove duplicate page_pool_put_full_page()
    (CVE-2025-38490 bsc#1247243).
  - commit eca8cf3
  - drm/amd/display: Add more checks for DSC / HUBP ONO guarantees (bsc#1247078 CVE-2025-38360)
  - commit 273e174

++++ podman:

  - Add patch for CVE-2025-6032 (bsc#1245320):
    * 0003-CVE-2025-6032-machine-init-fix-tls-check.patch

++++ ovmf:

  - Update firmware descriptors to remove tab whitespace (bsc#1247847)
  - Replace tab whitespace with spaces in 50-ovmf-x86_64-sev.json
  - Replace tab whitespace with spaces in 50-ovmf-x86_64-sev-snp.json

++++ virt-manager:

  - Adjust how we detect sles16 as the media layout changes.
    (bsc#1244685) (bsc#1249466)
    virtinst-add-sle16-detection-support.patch

------------------------------------------------------------------
------------------  2025-8-12  -  Aug 12 2025  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.696.g950c4798:
    * fix(dracut-util): crash if CMDLINE ends with quotation mark (bsc#1247819)
    * fix(74nvmf): set root=nvmf (bsc#1238848)

++++ gstreamer:

  - Update to version 1.26.5:
    + Highlighted bugfixes:
  - audioconvert: Fix caps negotiation regression when using a
    mix matrix
  - cea608overlay, cea708overlay: Accept GPU memory buffers if
    downstream supports the overlay composition meta
  - d3d12screencapture source element and device provider fixes
  - decodebin3: Don't error on an incoming ONVIF metadata stream
  - uridecodebin3: Fix potential crash when adding URIs to
    messages, e.g. if no decoder is available
  - v4l2: Fix memory leak for dynamic resolution change
  - VA encoder fixes
  - videorate, imagefreeze: Add support for JPEG XS
  - Vulkan integration fixes
  - wasapi2 audio device monitor improvements
  - threadshare: Many improvements and fixes to the generic
    threadshare and RTP threadshare elements
  - rtpbin2 improvements and fixes
  - gst-device-monitor-1.0 command line tool improvements
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - aggregator: add sub_latency_min to pad queue size
  - build: Disable C5287 warning on MSVC

++++ gstreamer-plugins-base:

  - Update to version 1.26.5:
    + audioconvert: mix-matrix causes caps negotiation failure
    + decodebin3: Don't error on an incoming ONVIF metadata stream
    + gloverlay: Recompute geometry when caps change, and load
    texture after stopping and starting again
    + uridecodebin3: Add missing locking and NULL checks when adding
    URIs to messages
    + uridecodebin3: segfault in update_message_with_uri() if no
    decoder available
    + videorate, imagefreeze: add support for JPEG XS
    + gst-device-monitor-1.0: Add shell quoting for launch lines
    + gst-device-monitor-1.0: Fix criticals, and also accept utf8 in
    launch lines
    + gst-device-monitor-1.0: Use gst_print instead of g_print

++++ kernel-default:

  - sunrpc: fix handling of server side tls alerts (git-fixes).
  - commit 7a563f7

++++ kernel-firmware-amdgpu:

  - Update to version 20250811 (git commit 08ee93ff8ffa):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-rt:

  - sunrpc: fix handling of server side tls alerts (git-fixes).
  - commit 7a563f7

++++ python313-core:

  - Add gh137583-only-lock-SSL-context.patch fixing the
    regression in 3.13.6 by breaking non-blocking TLS connections
    (gh#python/cpython#137583).

++++ python313:

  - Add gh137583-only-lock-SSL-context.patch fixing the
    regression in 3.13.6 by breaking non-blocking TLS connections
    (gh#python/cpython#137583).

++++ qemu:

  - Fix build issues due to Python version:
    * mkvenv: Support pip 25.2 (bsc#1247972)
  - Bug and CVE fixes:
    * tests: Avoid dependency on padding on signal messages (boo#1246830)
    * pcie_sriov: Fix configuration and state synchronization (bsc#1246992 CVE-2025-54566 CVE-2025-54567)
    * [openSUSE][RPM] linux-user: restart systemd-binfmt upon changes (bsc#1247443)

++++ ovmf:

  - Update firmware descriptors for SEV-SNP and TDX (bsc#1247847)
  - Add 50-ovmf-x86_64-sev-snp.json to support the 'amd-sev-snp' feature.
  - Remove the sev-snp feature from 50-ovmf-x86_64-sev.json.
  - Update the device in 60-ovmf-x86_64-tdx.json from 'pflash' to 'memory'.

++++ virt-manager:

  - bsc#1247865 - sles 16.0 rc3 KVM virt-manager detects windows 2025
    as 2022
    virtinst-windows-server-detection.patch

------------------------------------------------------------------
------------------  2025-8-11  -  Aug 11 2025  -------------------
------------------------------------------------------------------

++++ busybox:

  - Add patch to fix adduser inside containers on an SELinux host
    (boo#1247779):
    * 0001-update_passwd-Avoid-selinux_preserve_fcontext-if-SEL.patch
  - Don't throw debug info away during build, let RPM separate it
    afterwards

++++ python-kiwi:

  - Fix test-image-custom-partitions integration test
    Same fix as for the Tumbleweed test now also applied
    to the Leap test. Patching of the new root device did
    no longer apply
  - Fix test-image-custom-partitions integration test
    Patching of the new root device did no longer apply
  - Bump version: 10.2.31 → 10.2.32
  - fix: resize for raid device, ensure vars like kiwi_RaidDev are loaded before setting disk variable

++++ kernel-default:

  - dpll: zl3073x: ZL3073X_I2C and ZL3073X_SPI should depend on NET
    (jsc#PED-13331).
  - commit 7ae9e04
  - dpll: Make ZL3073X invisible (jsc#PED-13331).
  - Update config files.
  - commit 1c5ea3f
  - dpll: Add basic Microchip ZL3073x support (jsc#PED-13331).
  - Update config files.
  - supported.conf: Mark ZL3073X modules supported
  - commit 9ca5336
  - dpll: zl3073x: Fix build failure (jsc#PED-13331).
  - netlink: specs: devlink: replace underscores with dashes in
    names (jsc#PED-13331).
  - netlink: fix policy dump for int with validation callback
    (jsc#PED-13331).
  - commit 8ed21c1
  - dpll: zl3073x: Add support to get/set frequency on pins
    (jsc#PED-13331).
  - dpll: zl3073x: Implement input pin state setting in automatic
    mode (jsc#PED-13331).
  - dpll: zl3073x: Add support to get/set priority on input pins
    (jsc#PED-13331).
  - dpll: zl3073x: Implement input pin selection in manual mode
    (jsc#PED-13331).
  - dpll: zl3073x: Register DPLL devices and pins (jsc#PED-13331).
  - dpll: zl3073x: Read DPLL types and pin properties from system
    firmware (jsc#PED-13331).
  - dpll: zl3073x: Fetch invariants during probe (jsc#PED-13331).
  - devlink: Add support for u64 parameters (jsc#PED-13331).
  - dt-bindings: dpll: Add support for Microchip Azurite chip family
    (jsc#PED-13331).
  - dt-bindings: dpll: Add DPLL device and pin (jsc#PED-13331).
  - devlink: avoid param type value translations (jsc#PED-13331).
  - devlink: define enum for attr types of dynamic attributes
    (jsc#PED-13331).
  - devlink: introduce devlink_nl_put_u64() (jsc#PED-13331).
  - commit 635a9c4
  - ice, irdma: fix an off by one in error handling code
    (bsc#1247712).
  - irdma: free iwdev->rf after removing MSI-X (bsc#1247712).
  - ice: Fix signedness bug in ice_init_interrupt_scheme()
    (bsc#1247712).
  - ice: init flow director before RDMA (bsc#1247712).
  - ice: simplify VF MSI-X managing (bsc#1247712).
  - ice: enable_rdma devlink param (bsc#1247712).
  - ice: treat dyn_allowed only as suggestion (bsc#1247712).
  - ice, irdma: move interrupts code to irdma (bsc#1247712).
  - ice: get rid of num_lan_msix field (bsc#1247712).
  - ice: remove splitting MSI-X between features (bsc#1247712).
  - ice: devlink PF MSI-X max and min parameter (bsc#1247712).
  - ice: count combined queues using Rx/Tx count (bsc#1247712).
  - ice, irdma: fix an off by one in error handling code
    (bsc#1247712).
  - irdma: free iwdev->rf after removing MSI-X (bsc#1247712).
  - ice: Fix signedness bug in ice_init_interrupt_scheme()
    (bsc#1247712).
  - ice: init flow director before RDMA (bsc#1247712).
  - ice: simplify VF MSI-X managing (bsc#1247712).
  - ice: enable_rdma devlink param (bsc#1247712).
  - ice: treat dyn_allowed only as suggestion (bsc#1247712).
  - ice, irdma: move interrupts code to irdma (bsc#1247712).
  - ice: get rid of num_lan_msix field (bsc#1247712).
  - ice: remove splitting MSI-X between features (bsc#1247712).
  - ice: devlink PF MSI-X max and min parameter (bsc#1247712).
  - ice: count combined queues using Rx/Tx count (bsc#1247712).
  - commit 5c830c5
  - iommu/vt-d: Fix missing PASID in dev TLB flush with
    cache_tag_flush_all (git-fixes).
  - commit 3a05b85
  - iommu: Handle race with default domain setup (git-fixes).
  - commit 10fd40d
  - smb: client: fix netns refcount leak after net_passive changes
    (git-fixes).
  - commit afa7a11
  - net: mana: Fix build errors when CONFIG_NET_SHAPER is disabled
    (gix-fixes).
  - commit 9d3b307
  - RDMA/mana_ib: Add device statistics support (bsc#1246651).
  - net: mana: Handle Reset Request from MANA NIC (bsc#1245728).
  - net: mana: Set tx_packets to post gso processing packet count
    (bsc#1245731).
  - net: mana: Handle unsupported HWC commands (bsc#1245726).
  - net: mana: Add speed support in mana_get_link_ksettings
    (bsc#1245726).
  - net: mana: Add support for net_shaper_ops (bsc#1245726).
  - net: mana: Fix potential deadlocks in mana napi ops
    (bsc#1245726).
  - net: mana: Allocate MSI-X vectors dynamically (bsc#1245457).
  - net: mana: Allow irq_setup() to skip cpus for affinity
    (bsc#1245457).
  - net: mana: explain irq_setup() algorithm (bsc#1245457).
  - PCI: hv: Allow dynamic MSI-X vector allocation (bsc#1245457).
  - PCI/MSI: Export pci_msix_prepare_desc() for dynamic MSI-X
    allocations (bsc#1245457).
  - net: mana: Add handler for hardware servicing events
    (bsc#1245730).
  - net: mana: Expose additional hardware counters for drop and
    TC via ethtool (bsc#1245729).
  - commit 0742f38
  - kABI: io_uring: msg_ring ensure io_kiocb freeing is deferred
    (CVE-2025-38453 bsc#1247234).
    Conflicts:
    series.conf
  - kABI: io_uring: msg_ring ensure io_kiocb freeing is deferred
    (CVE-2025-38453 bsc#1247234).
  - commit 909d7fe
  - Revert "smb: client: fix TCP timers deadlock after rmmod"
    (bsc#1241403, CVE-2025-22077).
  - commit cadbdcb
  - smb: client: fix potential deadlock when reconnecting channels
    (bsc#1246183, CVE-2025-38244).
  - commit 1b9b63f
  - NFS: Fix the setting of capabilities when automounting a new
    filesystem (git-fixes).
  - commit 92d61de
  - sunrpc: fix client side handling of tls alerts (git-fixes).
  - commit 504fa2d
  - NFS: Fixup allocation flags for nfsiod's __GFP_NORETRY
    (git-fixes).
  - commit cdc019d
  - NFSv4.2: another fix for listxattr (git-fixes).
  - commit 20728e2
  - NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
    (git-fixes).
  - commit a126339
  - NFS: Fix wakeup of __nfs_lookup_revalidate() in
    unblock_revalidate() (git-fixes).
  - commit 47a75c4
  - pNFS/flexfiles: don't attempt pnfs on fatal DS errors
    (git-fixes).
  - commit f90ce8d
  - drm/amdgpu: Add basic validation for RAS header (bsc#1247252 CVE-2025-38426)
  - commit c5bedcf
  - netlink: avoid infinite retry looping in netlink_unicast()
    (CVE-2025-38465 bsc#1247118).
  - commit e134e60
  - Move upstreamed SPI patch into sorted section
  - commit 71eadf5
  - tools/power turbostat: Fix bogus SysWatt for forked program
    (git-fixes).
  - gpio: mlxbf2: use platform_get_irq_optional() (git-fixes).
  - ASoC: tas2781: Fix the wrong step for TLV on tas2781
    (git-fixes).
  - ASoC: SOF: amd: acp-loader: Use GFP_KERNEL for DMA allocations
    in resume context (git-fixes).
  - ALSA: hda/ca0132: Fix missing error handling in
    ca0132_alt_select_out() (git-fixes).
  - ALSA: intel_hdmi: Fix off-by-one error in
    __hdmi_lpe_audio_probe() (git-fixes).
  - commit f114c9a

++++ kernel-rt:

  - dpll: zl3073x: ZL3073X_I2C and ZL3073X_SPI should depend on NET
    (jsc#PED-13331).
  - commit 7ae9e04
  - dpll: Make ZL3073X invisible (jsc#PED-13331).
  - Update config files.
  - commit 1c5ea3f
  - dpll: Add basic Microchip ZL3073x support (jsc#PED-13331).
  - Update config files.
  - supported.conf: Mark ZL3073X modules supported
  - commit 9ca5336
  - dpll: zl3073x: Fix build failure (jsc#PED-13331).
  - netlink: specs: devlink: replace underscores with dashes in
    names (jsc#PED-13331).
  - netlink: fix policy dump for int with validation callback
    (jsc#PED-13331).
  - commit 8ed21c1
  - dpll: zl3073x: Add support to get/set frequency on pins
    (jsc#PED-13331).
  - dpll: zl3073x: Implement input pin state setting in automatic
    mode (jsc#PED-13331).
  - dpll: zl3073x: Add support to get/set priority on input pins
    (jsc#PED-13331).
  - dpll: zl3073x: Implement input pin selection in manual mode
    (jsc#PED-13331).
  - dpll: zl3073x: Register DPLL devices and pins (jsc#PED-13331).
  - dpll: zl3073x: Read DPLL types and pin properties from system
    firmware (jsc#PED-13331).
  - dpll: zl3073x: Fetch invariants during probe (jsc#PED-13331).
  - devlink: Add support for u64 parameters (jsc#PED-13331).
  - dt-bindings: dpll: Add support for Microchip Azurite chip family
    (jsc#PED-13331).
  - dt-bindings: dpll: Add DPLL device and pin (jsc#PED-13331).
  - devlink: avoid param type value translations (jsc#PED-13331).
  - devlink: define enum for attr types of dynamic attributes
    (jsc#PED-13331).
  - devlink: introduce devlink_nl_put_u64() (jsc#PED-13331).
  - commit 635a9c4
  - ice, irdma: fix an off by one in error handling code
    (bsc#1247712).
  - irdma: free iwdev->rf after removing MSI-X (bsc#1247712).
  - ice: Fix signedness bug in ice_init_interrupt_scheme()
    (bsc#1247712).
  - ice: init flow director before RDMA (bsc#1247712).
  - ice: simplify VF MSI-X managing (bsc#1247712).
  - ice: enable_rdma devlink param (bsc#1247712).
  - ice: treat dyn_allowed only as suggestion (bsc#1247712).
  - ice, irdma: move interrupts code to irdma (bsc#1247712).
  - ice: get rid of num_lan_msix field (bsc#1247712).
  - ice: remove splitting MSI-X between features (bsc#1247712).
  - ice: devlink PF MSI-X max and min parameter (bsc#1247712).
  - ice: count combined queues using Rx/Tx count (bsc#1247712).
  - ice, irdma: fix an off by one in error handling code
    (bsc#1247712).
  - irdma: free iwdev->rf after removing MSI-X (bsc#1247712).
  - ice: Fix signedness bug in ice_init_interrupt_scheme()
    (bsc#1247712).
  - ice: init flow director before RDMA (bsc#1247712).
  - ice: simplify VF MSI-X managing (bsc#1247712).
  - ice: enable_rdma devlink param (bsc#1247712).
  - ice: treat dyn_allowed only as suggestion (bsc#1247712).
  - ice, irdma: move interrupts code to irdma (bsc#1247712).
  - ice: get rid of num_lan_msix field (bsc#1247712).
  - ice: remove splitting MSI-X between features (bsc#1247712).
  - ice: devlink PF MSI-X max and min parameter (bsc#1247712).
  - ice: count combined queues using Rx/Tx count (bsc#1247712).
  - commit 5c830c5
  - iommu/vt-d: Fix missing PASID in dev TLB flush with
    cache_tag_flush_all (git-fixes).
  - commit 3a05b85
  - iommu: Handle race with default domain setup (git-fixes).
  - commit 10fd40d
  - smb: client: fix netns refcount leak after net_passive changes
    (git-fixes).
  - commit afa7a11
  - net: mana: Fix build errors when CONFIG_NET_SHAPER is disabled
    (gix-fixes).
  - commit 9d3b307
  - RDMA/mana_ib: Add device statistics support (bsc#1246651).
  - net: mana: Handle Reset Request from MANA NIC (bsc#1245728).
  - net: mana: Set tx_packets to post gso processing packet count
    (bsc#1245731).
  - net: mana: Handle unsupported HWC commands (bsc#1245726).
  - net: mana: Add speed support in mana_get_link_ksettings
    (bsc#1245726).
  - net: mana: Add support for net_shaper_ops (bsc#1245726).
  - net: mana: Fix potential deadlocks in mana napi ops
    (bsc#1245726).
  - net: mana: Allocate MSI-X vectors dynamically (bsc#1245457).
  - net: mana: Allow irq_setup() to skip cpus for affinity
    (bsc#1245457).
  - net: mana: explain irq_setup() algorithm (bsc#1245457).
  - PCI: hv: Allow dynamic MSI-X vector allocation (bsc#1245457).
  - PCI/MSI: Export pci_msix_prepare_desc() for dynamic MSI-X
    allocations (bsc#1245457).
  - net: mana: Add handler for hardware servicing events
    (bsc#1245730).
  - net: mana: Expose additional hardware counters for drop and
    TC via ethtool (bsc#1245729).
  - commit 0742f38
  - kABI: io_uring: msg_ring ensure io_kiocb freeing is deferred
    (CVE-2025-38453 bsc#1247234).
    Conflicts:
    series.conf
  - kABI: io_uring: msg_ring ensure io_kiocb freeing is deferred
    (CVE-2025-38453 bsc#1247234).
  - commit 909d7fe
  - Revert "smb: client: fix TCP timers deadlock after rmmod"
    (bsc#1241403, CVE-2025-22077).
  - commit cadbdcb
  - smb: client: fix potential deadlock when reconnecting channels
    (bsc#1246183, CVE-2025-38244).
  - commit 1b9b63f
  - NFS: Fix the setting of capabilities when automounting a new
    filesystem (git-fixes).
  - commit 92d61de
  - sunrpc: fix client side handling of tls alerts (git-fixes).
  - commit 504fa2d
  - NFS: Fixup allocation flags for nfsiod's __GFP_NORETRY
    (git-fixes).
  - commit cdc019d
  - NFSv4.2: another fix for listxattr (git-fixes).
  - commit 20728e2
  - NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()
    (git-fixes).
  - commit a126339
  - NFS: Fix wakeup of __nfs_lookup_revalidate() in
    unblock_revalidate() (git-fixes).
  - commit 47a75c4
  - pNFS/flexfiles: don't attempt pnfs on fatal DS errors
    (git-fixes).
  - commit f90ce8d
  - drm/amdgpu: Add basic validation for RAS header (bsc#1247252 CVE-2025-38426)
  - commit c5bedcf
  - netlink: avoid infinite retry looping in netlink_unicast()
    (CVE-2025-38465 bsc#1247118).
  - commit e134e60
  - Move upstreamed SPI patch into sorted section
  - commit 71eadf5
  - tools/power turbostat: Fix bogus SysWatt for forked program
    (git-fixes).
  - gpio: mlxbf2: use platform_get_irq_optional() (git-fixes).
  - ASoC: tas2781: Fix the wrong step for TLV on tas2781
    (git-fixes).
  - ASoC: SOF: amd: acp-loader: Use GFP_KERNEL for DMA allocations
    in resume context (git-fixes).
  - ALSA: hda/ca0132: Fix missing error handling in
    ca0132_alt_select_out() (git-fixes).
  - ALSA: intel_hdmi: Fix off-by-one error in
    __hdmi_lpe_audio_probe() (git-fixes).
  - commit f114c9a

++++ cairo:

  - Add b5752618.patch:
    Backport from William Bader's request 621, Fix NULL access
    in active_edges_to_traps().
    https://gitlab.freedesktop.org/cairo/cairo/-/merge_requests/621/diffs
    https://gitlab.freedesktop.org/williamb/cairo/-/commit/b5752618
    (CVE-2025-50422, bsc#1247589)

++++ sqlite3:

  - Update to version 3.50.4:
    * Fix two long-standings cases of the use of uninitialized
    variables in obscure circumstances.

++++ unbound:

  - simplify python handling. python2 support is dropped and python3
    is built by default. Conditionals for the latter are removed.
  - enable EDNS subnet handling

++++ libzypp:

  - Make ld.so ignore the subarch packages during install
    (bsc#1246912)
  - version 17.37.17 (35)

++++ net-tools:

  - Provide more readable error for interface name size checking
    introduced by net-tools-CVE-2025-46836.patch
    (bsc#1243581, net-tools-CVE-2025-46836-error-reporting.patch).

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 580.76.05 (boo#1247907)
  - get rid of rule of older KMPs not to load nvidia_drm module,
    which are still installed in parallel and therefore still
    active (boo#1247923)

------------------------------------------------------------------
------------------  2025-8-10  -  Aug 10 2025  -------------------
------------------------------------------------------------------

++++ unbound:

  - Update to 1.23.1: (boo#1246625)
    Bug Fixes:
    * Fix RebirthDay Attack CVE-2025-5994, reported by Xiang Li from
    AOSP Lab Nankai University.
  - our package was not built with EDNS subnet support up to this
    point and therefor was not affected.
  - prepare enabling quic support:
    currently fails on missing quic support in openssl. aws-lc is
    sadly not a drop in replacement for unbound.
  - enable TCP Fast Open for the server and client
  - remove unused --with-ldns option
  - enable cachedb including hiredis support on Tumbleweed
    new BuildRequires pkgconfig(libhiredis)

++++ qemu:

  - Update to stable release 10.0.3:
    Full list of backports here:
    https://lore.kernel.org/qemu-devel/1748499690.323471.13081.nullmailer@localhost/
    A selection of them is reported here too:
    hvf: arm: Emulate ICC_RPR_EL1 accesses properly
    target/arm: Correct encoding of Debug Communications Channel registers
    ui: fix setting client_endian field defaults
    hw/net/npcm_gmac.c: Send the right data for second packet in a row
    target/i386: do not expose ARCH_CAPABILITIES on AMD CPU
    i386/cpu: Honor maximum value for CPUID.8000001DH.EAX[25:14]
    i386/cpu: Fix overflow of cache topology fields in CPUID.04H
    i386/cpu: Fix cpu number overflow in CPUID.01H.EBX[23:16]
    ui/vnc: Do not copy z_stream
    vhost: Fix used memslot tracking when destroying a vhost device
    roms: re-remove execute bit from hppa-firmware*
    file-posix: Fix aio=threads performance regression after enablign FUA
    amd_iommu: Fix truncation of oldval in amdvi_writeq
    amd_iommu: Remove duplicated definitions
    amd_iommu: Fix the calculation for Device Table size
    amd_iommu: Fix mask to retrieve Interrupt Table Root Pointer from DTE
    amd_iommu: Fix masks for various IOMMU MMIO Registers
    amd_iommu: Update bitmasks representing DTE reserved fields
    amd_iommu: Fix Device ID decoding for INVALIDATE_IOTLB_PAGES command
    amd_iommu: Fix Miscellaneous Information Register 0 encoding
    virtio-net: Add queues for RSS during migration
    net: fix buffer overflow in af_xdp_umem_create()
    accel/kvm: Adjust the note about the minimum required kernel version
    ...

------------------------------------------------------------------
------------------  2025-8-9  -  Aug 9 2025  -------------------
------------------------------------------------------------------

++++ kernel-firmware-amdgpu:

  - Update to version 20250808 (git commit 8f1ce114de6c):
    * amdgpu: update renoir firmware
    * amdgpu: add SMU 14.0.3 kicker firmware
    * amdgpu: add PSP 14.0.3 firmware
    * amdgpu: add GC 12.0.1 kicker firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update SDMA 6.1.2 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 5.0.0 firmware
    * amdgpu: update SDMA 7.0.1 firmware
    * amdgpu: update PSP 14.0.3 firmware
    * amdgpu: update GC 12.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update SDMA 7.0.0 firmware
    * amdgpu: update PSP 14.0.2 firmware
    * amdgpu: update GC 12.0.0 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update GC 10.3.6 firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update PSP 13.0.0 kicker firmware
    * amdgpu: update VCN 5.0.1 firmware
    * amdgpu: update PSP 13.0.12 firmware
    * amdgpu: update GC 9.5.0 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update PSP 13.0.14 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update GC 10.3.7 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update dimgrey_cavefish firmware
    * amdgpu: update aldebaran firmware

++++ kernel-firmware-ath12k:

  - Update to version 20250808 (git commit 8f1ce114de6c):
    * ath12k: WCN7850 hw2.0: update to WLAN.HMT.1.1.c5-00302-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1.115823.3
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.5-01651-QCAHKSWPL_SILICONZ-1

++++ kernel-firmware-bluetooth:

  - Update to version 20250808 (git commit 8f1ce114de6c):
    * qca: Update Bluetooth WCN6750 1.1.3-00069 firmware to 1.1.3-00091

++++ nvidia-open-driver-G06-signed:

  - make sure these Requires right below are not added on Tumbleweed

------------------------------------------------------------------
------------------  2025-8-8  -  Aug 8 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Do not clobber initialize method
    There was a method named initialize defined and implemented
    differently in the dracut modules kiwi-lib and kiwi-repart.
    kiwi-lib is expected to be shared code across all kiwi dracut
    modules. However if one module redefines a method of the
    same name which is used in another module and expected to
    work differently there, this is evil. This commit cleans
    up the name conflict and names the kiwi library init function
    as lib_initialize. All dracut code that is expected to make
    use of this method has been adopted too.

++++ glib2:

  - Update to version 2.84.4 (bsc#1249055):
    + Bugs fixed:
  - (CVE-2025-7039) (#YWH-PGM9867-104) Buffer Under-read on GLib
    through glib/gfileutils.c via get_tmp_file()
  - GFile leak in g_local_file_set_display_name during error
    handling
  - Incorrect output parameter handling in closure helper of
    g_settings_bind_with_mapping_closures
  - gfileutils: fix computation of temporary file name
  - Fix GFile leak in  g_local_file_set_display_name()
  - gthreadpool: Catch pool_spawner creation failure
  - gio/filenamecompleter: Fix leaks
  - gfilenamecompleter: Fix g_object_unref() of undefined value

++++ kernel-default:

  - io_uring/msg_ring: ensure io_kiocb freeing is deferred for RCU
    (CVE-2025-38453 bsc#1247234).
  - commit 171360a
  - posix-cpu-timers: fix race between handle_posix_cpu_timers()
    and posix_cpu_timer_del() (bsc#1246911 CVE-2025-38352).
  - commit 0681499
  - Delete patches.suse/kasan-avoid-sleepable-page-allocation-from-atomic-co.patch
    This doesn't build properly with the current SL-16.0 kernel code
  - commit beec866
  - tls: always refresh the queue when reading sock (CVE-2025-38471
    bsc#1247450).
  - mm/damon/sysfs-schemes: free old
    damon_sysfs_scheme_filter->memcg_path on write (CVE-2025-38258
    bsc#1246185).
  - perf/x86/intel: Fix crash in icl_update_topdown_event()
    (CVE-2025-38322 bsc#1246447).
  - ext4: only dirty folios when data journaling regular files
    (CVE-2025-38220 bsc#1245966).
  - commit 2bcb640
  - smc: Fix various oops due to inet_sock type confusion
    (CVE-2025-38475 bsc#1247308).
  - kABI fix for net: vlan: fix VLAN 0 refcount imbalance of
    toggling (CVE-2025-38470 bsc#1247288).
  - net: vlan: fix VLAN 0 refcount imbalance of toggling filtering
    during runtime (CVE-2025-38470 bsc#1247288).
  - smc: Fix various oops due to inet_sock type confusion
    (CVE-2025-38475 bsc#1247308).
  - net/mlx5e: Fix race between DIM disable and net_dim()
    (CVE-2025-38440 bsc#1247290).
  - net/sched: Abort __tc_modify_qdisc if parent class does not
    exist (CVE-2025-38457 bsc#1247098).
  - atm: clip: Fix potential null-ptr-deref in to_atmarpd()
    (CVE-2025-38460 bsc#1247143).
  - idpf: convert control queue mutex to a spinlock (CVE-2025-38392
    bsc#1247169).
  - commit 05e8074
  - net/sched: mqprio: fix stack out-of-bounds write in tc entry
    parsing (git-fixes).
  - commit 38b5d6f
  - net/packet: fix a race in packet_set_ring() and
    packet_notifier() (git-fixes).
  - commit da0301d
  - net/packet: fix a race in packet_set_ring() and
    packet_notifier() (CVE-2025-38617 bsc#1248621)
    Cherry-picked from SL-16.0. CVSS is 7.0 so it should be on SL-16.0-GA
    too.
  - commit 6ca1c18
  - net/sched: taprio: enforce minimum value for picos_per_byte
    (git-fixes).
  - commit d42d899
  - ipv6: reject malicious packets in ipv6_gso_segment()
    (git-fixes).
  - commit 1820a44
  - netpoll: prevent hanging NAPI when netcons gets enabled
    (git-fixes).
  - commit 1d345b1
  - tracing: Fix using ret variable in tracing_set_tracer()
    (git-fixes).
  - commit e9dbf86
  - fgraph: Fix set_graph_notrace with setting
    TRACE_GRAPH_NOTRACE_BIT (git-fixes).
  - commit c43ec6f
  - ring-buffer: Do not allow events in NMI with generic atomic64
    cmpxchg() (git-fixes).
  - commit 720a150
  - tracing: Switch trace_events_hist.c code over to use guard()
    (git-fixes).
  - commit 7cfc3ab
  - tracing: Switch trace.c code over to use guard() (git-fixes).
  - commit d022aa4
  - drm/amd/display: Don't overwrite dce60_clk_mgr (git-fixes).
  - Revert "vgacon: Add check for vc_origin address range in
    vgacon_scroll()" (stable-fixes).
  - commit 5df2fd2

++++ kernel-rt:

  - io_uring/msg_ring: ensure io_kiocb freeing is deferred for RCU
    (CVE-2025-38453 bsc#1247234).
  - commit 171360a
  - posix-cpu-timers: fix race between handle_posix_cpu_timers()
    and posix_cpu_timer_del() (bsc#1246911 CVE-2025-38352).
  - commit 0681499
  - Delete patches.suse/kasan-avoid-sleepable-page-allocation-from-atomic-co.patch
    This doesn't build properly with the current SL-16.0 kernel code
  - commit beec866
  - tls: always refresh the queue when reading sock (CVE-2025-38471
    bsc#1247450).
  - mm/damon/sysfs-schemes: free old
    damon_sysfs_scheme_filter->memcg_path on write (CVE-2025-38258
    bsc#1246185).
  - perf/x86/intel: Fix crash in icl_update_topdown_event()
    (CVE-2025-38322 bsc#1246447).
  - ext4: only dirty folios when data journaling regular files
    (CVE-2025-38220 bsc#1245966).
  - commit 2bcb640
  - smc: Fix various oops due to inet_sock type confusion
    (CVE-2025-38475 bsc#1247308).
  - kABI fix for net: vlan: fix VLAN 0 refcount imbalance of
    toggling (CVE-2025-38470 bsc#1247288).
  - net: vlan: fix VLAN 0 refcount imbalance of toggling filtering
    during runtime (CVE-2025-38470 bsc#1247288).
  - smc: Fix various oops due to inet_sock type confusion
    (CVE-2025-38475 bsc#1247308).
  - net/mlx5e: Fix race between DIM disable and net_dim()
    (CVE-2025-38440 bsc#1247290).
  - net/sched: Abort __tc_modify_qdisc if parent class does not
    exist (CVE-2025-38457 bsc#1247098).
  - atm: clip: Fix potential null-ptr-deref in to_atmarpd()
    (CVE-2025-38460 bsc#1247143).
  - idpf: convert control queue mutex to a spinlock (CVE-2025-38392
    bsc#1247169).
  - commit 05e8074
  - net/sched: mqprio: fix stack out-of-bounds write in tc entry
    parsing (git-fixes).
  - commit 38b5d6f
  - net/packet: fix a race in packet_set_ring() and
    packet_notifier() (git-fixes).
  - commit da0301d
  - net/packet: fix a race in packet_set_ring() and
    packet_notifier() (CVE-2025-38617 bsc#1248621)
    Cherry-picked from SL-16.0. CVSS is 7.0 so it should be on SL-16.0-GA
    too.
  - commit 6ca1c18
  - net/sched: taprio: enforce minimum value for picos_per_byte
    (git-fixes).
  - commit d42d899
  - ipv6: reject malicious packets in ipv6_gso_segment()
    (git-fixes).
  - commit 1820a44
  - netpoll: prevent hanging NAPI when netcons gets enabled
    (git-fixes).
  - commit 1d345b1
  - tracing: Fix using ret variable in tracing_set_tracer()
    (git-fixes).
  - commit e9dbf86
  - fgraph: Fix set_graph_notrace with setting
    TRACE_GRAPH_NOTRACE_BIT (git-fixes).
  - commit c43ec6f
  - ring-buffer: Do not allow events in NMI with generic atomic64
    cmpxchg() (git-fixes).
  - commit 720a150
  - tracing: Switch trace_events_hist.c code over to use guard()
    (git-fixes).
  - commit 7cfc3ab
  - tracing: Switch trace.c code over to use guard() (git-fixes).
  - commit d022aa4
  - drm/amd/display: Don't overwrite dce60_clk_mgr (git-fixes).
  - Revert "vgacon: Add check for vc_origin address range in
    vgacon_scroll()" (stable-fixes).
  - commit 5df2fd2

++++ man:

  - Update to man-db 2.13.1 (2 May 2025)
    * Update various manual page translation
    * Fix various minor formatting issues in manual pages.
    * Tolerate additional spaces in preprocessor strings.
    * Fix check for generated source files in out-of-tree builds.
    * Fix building with the `musl` C library.
    * Recognize another Ukrainian translation of the `NAME` section.
    * Increase the maximum size of the `NAME` section from 8192 to 16384 bytes.
  - Port patches
    * man-db-2.6.3-listall.dif
    * man-db-2.9.4.patch

------------------------------------------------------------------
------------------  2025-8-7  -  Aug 7 2025  -------------------
------------------------------------------------------------------

++++ grub2:

  - Fix timeout when loading initrd via http after PPC CAS reboot (bsc#1245953)
    * 0001-tcp-Fix-TCP-port-number-reused-on-reboot.patch

++++ kernel-default:

  - scsi: target: Fix NULL pointer dereference in
    core_scsi3_decode_spec_i_port() (CVE-2025-38399 bsc#1247097).
  - commit b40a9d6
  - exfat: fdatasync flag should be same like generic_write_sync()
    (git-fixes).
  - commit a622d1a
  - do_change_type(): refuse to operate on unmounted/not ours mounts (CVE-2025-38498 bsc#1247374)
  - commit cb82edb
  - Enable CONFIG_CMA_SYSFS
    This is a generally useful feature for anyone using CMA or
    investigating CMA issues, with a small and simple code base and no
    runtime overhead.
  - commit 523b720
  - Update config files.
    Set CONFIG_CMA_AREAS values to their new upstream default.
  - commit bb7f630
  - ring-buffer: Make reading page consistent with the code logic
    (git-fixes).
  - commit 22871cd
  - ring-buffer: Fix buffer locking in
    ring_buffer_subbuf_order_set() (CVE-2025-38101 bsc#1245659).
  - commit 59c07ff
  - tracing/kprobes: Fix to free objects when failed to copy a
    symbol (git-fixes).
  - commit c9b00b2
  - ftrace: Fix function profiler's filtering functionality
    (git-fixes).
  - commit 594ca40
  - tracing/kprobe: Make trace_kprobe's module callback called
    after jump_label update (git-fixes).
  - commit a204d8e
  - trace/ring-buffer: Do not use TP_printk() formatting for boot
    mapped buffers (git-fixes).
  - commit 4041535
  - module: Restore the moduleparam prefix length check (git-fixes).
  - module: Remove unnecessary +1 from last_unloaded_module::name
    size (git-fixes).
  - commit a84e148
  - audit,module: restore audit logging in load failure case
    (git-fixes).
  - kABI: Fix the module::name type in audit_context (git-fixes).
  - commit 4504207
  - module: Fix memory deallocation on error path in move_module()
    (git-fixes).
  - commit 00ca9af
  - mm/vmalloc: fix data race in show_numa_info() (CVE-2025-38383
    bsc#1247250).
  - commit c043092
  - RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages (git-fixes)
  - commit 4638273

++++ kernel-rt:

  - scsi: target: Fix NULL pointer dereference in
    core_scsi3_decode_spec_i_port() (CVE-2025-38399 bsc#1247097).
  - commit b40a9d6
  - exfat: fdatasync flag should be same like generic_write_sync()
    (git-fixes).
  - commit a622d1a
  - do_change_type(): refuse to operate on unmounted/not ours mounts (CVE-2025-38498 bsc#1247374)
  - commit cb82edb
  - Enable CONFIG_CMA_SYSFS
    This is a generally useful feature for anyone using CMA or
    investigating CMA issues, with a small and simple code base and no
    runtime overhead.
  - commit 523b720
  - Update config files.
    Set CONFIG_CMA_AREAS values to their new upstream default.
  - commit bb7f630
  - ring-buffer: Make reading page consistent with the code logic
    (git-fixes).
  - commit 22871cd
  - ring-buffer: Fix buffer locking in
    ring_buffer_subbuf_order_set() (CVE-2025-38101 bsc#1245659).
  - commit 59c07ff
  - tracing/kprobes: Fix to free objects when failed to copy a
    symbol (git-fixes).
  - commit c9b00b2
  - ftrace: Fix function profiler's filtering functionality
    (git-fixes).
  - commit 594ca40
  - tracing/kprobe: Make trace_kprobe's module callback called
    after jump_label update (git-fixes).
  - commit a204d8e
  - trace/ring-buffer: Do not use TP_printk() formatting for boot
    mapped buffers (git-fixes).
  - commit 4041535
  - module: Restore the moduleparam prefix length check (git-fixes).
  - module: Remove unnecessary +1 from last_unloaded_module::name
    size (git-fixes).
  - commit a84e148
  - audit,module: restore audit logging in load failure case
    (git-fixes).
  - kABI: Fix the module::name type in audit_context (git-fixes).
  - commit 4504207
  - module: Fix memory deallocation on error path in move_module()
    (git-fixes).
  - commit 00ca9af
  - mm/vmalloc: fix data race in show_numa_info() (CVE-2025-38383
    bsc#1247250).
  - commit c043092
  - RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages (git-fixes)
  - commit 4638273

++++ python313-core:

  - Update to 3.13.6:
  - Security
  - gh-135661: Fix parsing start and end tags in
    html.parser.HTMLParser according to the HTML5 standard.
  - Whitespaces no longer accepted between </ and the tag
    name. E.g. </ script> does not end the script section.
  - Vertical tabulation (\v) and non-ASCII whitespaces no
    longer recognized as whitespaces. The only whitespaces
    are \t\n\r\f and space.
  - Null character (U+0000) no longer ends the tag name.
  - Attributes and slashes after the tag name in end tags
    are now ignored, instead of terminating after the first
    > in quoted attribute value. E.g. </script/foo=">"/>.
  - Multiple slashes and whitespaces between the last
    attribute and closing > are now ignored in both start
    and end tags. E.g. <a foo=bar/ //>.
  - Multiple = between attribute name and value are no
    longer collapsed. E.g. <a foo==bar> produces attribute
    “foo” with value “=bar”.
  - gh-102555: Fix comment parsing in html.parser.HTMLParser
    according to the HTML5 standard. --!> now ends the comment.
  - - > no longer ends the comment. Support abnormally ended
    empty comments <--> and <--->.
  - gh-135462: Fix quadratic complexity in processing specially
    crafted input in html.parser.HTMLParser. End-of-file errors
    are now handled according to the HTML5 specs – comments and
    declarations are automatically closed, tags are ignored
    (CVE-2025-6069, bsc#1244705).
  - gh-118350: Fix support of escapable raw text mode (elements
    “textarea” and “title”) in html.parser.HTMLParser.
  - Core and Builtins
  - gh-58124: Fix name of the Python encoding in Unicode errors
    of the code page codec: use “cp65000” and “cp65001” instead
    of “CP_UTF7” and “CP_UTF8” which are not valid Python code
    names. Patch by Victor Stinner.
  - gh-137314: Fixed a regression where raw f-strings
    incorrectly interpreted escape sequences in format
    specifications. Raw f-strings now properly preserve literal
    backslashes in format specs, matching the behavior from
    Python 3.11. For example, rf"{obj:\xFF}" now correctly
    produces '\\xFF' instead of 'ÿ'. Patch by Pablo Galindo.
  - gh-136541: Fix some issues with the perf trampolines
    on x86-64 and aarch64. The trampolines were not being
    generated correctly for some cases, which could lead to
    the perf integration not working correctly. Patch by Pablo
    Galindo.
  - gh-109700: Fix memory error handling in
    PyDict_SetDefault().
  - gh-78465: Fix error message for cls.__new__(cls, ...) where
    cls is not instantiable builtin or extension type (with
    tp_new set to NULL).
  - gh-135871: Non-blocking mutex lock attempts now return
    immediately when the lock is busy instead of briefly
    spinning in the free threading build.
  - gh-135607: Fix potential weakref races in an object’s
    destructor on the free threaded build.
  - gh-135496: Fix typo in the f-string conversion type error
    (“exclamanation” -> “exclamation”).
  - gh-130077: Properly raise custom syntax errors when
    incorrect syntax containing names that are prefixes of soft
    keywords is encountered. Patch by Pablo Galindo.
  - gh-135148: Fixed a bug where f-string debug expressions
    (using =) would incorrectly strip out parts of strings
    containing escaped quotes and # characters. Patch by Pablo
    Galindo.
  - gh-133136: Limit excess memory usage in the free threading
    build when a large dictionary or list is resized and
    accessed by multiple threads.
  - gh-132617: Fix dict.update() modification check that could
    incorrectly raise a “dict mutated during update” error when
    a different dictionary was modified that happens to share
    the same underlying keys object.
  - gh-91153: Fix a crash when a bytearray is concurrently
    mutated during item assignment.
  - gh-127971: Fix off-by-one read beyond the end of a string
    in string search.
  - gh-125723: Fix crash with gi_frame.f_locals when generator
    frames outlive their generator. Patch by Mikhail Efimov.
  - Library
  - gh-132710: If possible, ensure that uuid.getnode()
    returns the same result even across different processes.
    Previously, the result was constant only within the same
    process. Patch by Bénédikt Tran.
  - gh-137273: Fix debug assertion failure in
    locale.setlocale() on Windows.
  - gh-137257: Bump the version of pip bundled in ensurepip to
    version 25.2
  - gh-81325: tarfile.TarFile now accepts a path-like when
    working on a tar archive. (Contributed by Alexander Enrique
    Urieles Nieto in gh-81325.)
  - gh-130522: Fix unraisable TypeError raised during
    interpreter shutdown in the threading module.
  - gh-130577: tarfile now validates archives to ensure member
    offsets are non-negative. (Contributed by Alexander Enrique
    Urieles Nieto in gh-130577; CVE-2025-8194, bsc#1247249).
  - gh-136549: Fix signature of threading.excepthook().
  - gh-136523: Fix wave.Wave_write emitting an unraisable when
    open raises.
  - gh-52876: Add missing keepends (default True)
    parameter to codecs.StreamReaderWriter.readline() and
    codecs.StreamReaderWriter.readlines().
  - gh-85702: If zoneinfo._common.load_tzdata is given a
    package without a resource a zoneinfo.ZoneInfoNotFoundError
    is raised rather than a PermissionError. Patch by Victor
    Stinner.
  - gh-134759: Fix UnboundLocalError in
    email.message.Message.get_payload() when the payload to
    decode is a bytes object. Patch by Kliment Lamonov.
  - gh-136028: Fix parsing month names containing “İ” (U+0130,
    LATIN CAPITAL LETTER I WITH DOT ABOVE) in time.strptime().
    This affects locales az_AZ, ber_DZ, ber_MA and crh_UA.
  - gh-135995: In the palmos encoding, make byte 0x9b decode to
    › (U+203A - SINGLE RIGHT-POINTING ANGLE QUOTATION MARK).
  - gh-53203: Fix time.strptime() for %c and %x formats on
    locales byn_ER, wal_ET and lzh_TW, and for %X format on
    locales ar_SA, bg_BG and lzh_TW.
  - gh-91555: An earlier change, which was introduced in
    3.13.4, has been reverted. It disabled logging for a logger
    during handling of log messages for that logger. Since the
    reversion, the behaviour should be as it was before 3.13.4.
  - gh-135878: Fixes a crash of types.SimpleNamespace on free
    threading builds, when several threads were calling its
    __repr__() method at the same time.
  - gh-135836: Fix IndexError in
    asyncio.loop.create_connection() that could occur when
    non-OSError exception is raised during connection and
    socket’s close() raises OSError.
  - gh-135836: Fix IndexError in
    asyncio.loop.create_connection() that could occur when the
    Happy Eyeballs algorithm resulted in an empty exceptions
    list during connection attempts.
  - gh-135855: Raise TypeError instead of SystemError when
    _interpreters.set___main___attrs() is passed a non-dict
    object. Patch by Brian Schubert.
  - gh-135815: netrc: skip security checks if os.getuid() is
    missing. Patch by Bénédikt Tran.
  - gh-135640: Address bug where it was possible to call
    xml.etree.ElementTree.ElementTree.write() on an ElementTree
    object with an invalid root element. This behavior blanked
    the file passed to write if it already existed.
  - gh-135444: Fix asyncio.DatagramTransport.sendto() to
    account for datagram header size when data cannot be sent.
  - gh-135497: Fix os.getlogin() failing for longer usernames
    on BSD-based platforms.
  - gh-135487: Fix reprlib.Repr.repr_int() when given integers
    with more than sys.get_int_max_str_digits() digits. Patch
    by Bénédikt Tran.
  - gh-135335: multiprocessing: Flush stdout and stderr after
    preloading modules in the forkserver.
  - gh-135244: uuid: when the MAC address cannot be
    determined, the 48-bit node ID is now generated with a
    cryptographically-secure pseudo-random number generator
    (CSPRNG) as per RFC 9562, §6.10.3. This affects uuid1().
  - gh-135069: Fix the “Invalid error handling” exception in
    encodings.idna.IncrementalDecoder to correctly replace the
    ‘errors’ parameter.
  - gh-134698: Fix a crash when calling methods of
    ssl.SSLContext or ssl.SSLSocket across multiple threads.
  - gh-132124: On POSIX-compliant systems,
    multiprocessing.util.get_temp_dir() now ignores TMPDIR
    (and similar environment variables) if the path length of
    AF_UNIX socket files exceeds the platform-specific maximum
    length when using the forkserver start method. Patch by
    Bénédikt Tran.
  - gh-133439: Fix dot commands with trailing spaces are
    mistaken for multi-line SQL statements in the sqlite3
    command-line interface.
  - gh-132969: Prevent the ProcessPoolExecutor executor thread,
    which remains running when shutdown(wait=False), from
    attempting to adjust the pool’s worker processes after
    the object state has already been reset during shutdown.
    A combination of conditions, including a worker process
    having terminated abormally, resulted in an exception and
    a potential hang when the still-running executor thread
    attempted to replace dead workers within the pool.
  - gh-130664: Support the '_' digit separator in formatting
    of the integral part of Decimal’s. Patch by Sergey B
    Kirpichev.
  - gh-85702: If zoneinfo._common.load_tzdata is given a
    package without a resource a ZoneInfoNotFoundError is
    raised rather than a IsADirectoryError.
  - gh-130664: Handle corner-case for Fraction’s formatting:
    treat zero-padding (preceding the width field by a zero
    ('0') character) as an equivalent to a fill character of
    '0' with an alignment type of '=', just as in case of
    float’s.
  - Tools/Demos
  - gh-135968: Stubs for strip are now provided as part of an
    iOS install.
  - Tests
  - gh-135966: The iOS testbed now handles the app_packages
    folder as a site directory.
  - gh-135494: Fix regrtest to support excluding tests from
  - -pgo tests. Patch by Victor Stinner.
  - gh-135489: Show verbose output for failing tests during PGO
    profiling step with –enable-optimizations.
  - Documentation
  - gh-135171: Document that the iterator for the leftmost for
    clause in the generator expression is created immediately.
  - Build
  - gh-135497: Fix the detection of MAXLOGNAME in the
    configure.ac script.
  - Remove upstreamed patches:
  - CVE-2025-8194-tarfile-no-neg-offsets.patch
  - CVE-2025-6069-quad-complex-HTMLParser.patch

++++ libzypp:

  - Fix evaluation of libproxy results (bsc#1247690)
  - Replace URL variables inside mirrorlist/metalink files
    (fixes #667)
  - version 17.37.16 (35)

++++ python313:

  - Update to 3.13.6:
  - Security
  - gh-135661: Fix parsing start and end tags in
    html.parser.HTMLParser according to the HTML5 standard.
  - Whitespaces no longer accepted between </ and the tag
    name. E.g. </ script> does not end the script section.
  - Vertical tabulation (\v) and non-ASCII whitespaces no
    longer recognized as whitespaces. The only whitespaces
    are \t\n\r\f and space.
  - Null character (U+0000) no longer ends the tag name.
  - Attributes and slashes after the tag name in end tags
    are now ignored, instead of terminating after the first
    > in quoted attribute value. E.g. </script/foo=">"/>.
  - Multiple slashes and whitespaces between the last
    attribute and closing > are now ignored in both start
    and end tags. E.g. <a foo=bar/ //>.
  - Multiple = between attribute name and value are no
    longer collapsed. E.g. <a foo==bar> produces attribute
    “foo” with value “=bar”.
  - gh-102555: Fix comment parsing in html.parser.HTMLParser
    according to the HTML5 standard. --!> now ends the comment.
  - - > no longer ends the comment. Support abnormally ended
    empty comments <--> and <--->.
  - gh-135462: Fix quadratic complexity in processing specially
    crafted input in html.parser.HTMLParser. End-of-file errors
    are now handled according to the HTML5 specs – comments and
    declarations are automatically closed, tags are ignored
    (CVE-2025-6069, bsc#1244705).
  - gh-118350: Fix support of escapable raw text mode (elements
    “textarea” and “title”) in html.parser.HTMLParser.
  - Core and Builtins
  - gh-58124: Fix name of the Python encoding in Unicode errors
    of the code page codec: use “cp65000” and “cp65001” instead
    of “CP_UTF7” and “CP_UTF8” which are not valid Python code
    names. Patch by Victor Stinner.
  - gh-137314: Fixed a regression where raw f-strings
    incorrectly interpreted escape sequences in format
    specifications. Raw f-strings now properly preserve literal
    backslashes in format specs, matching the behavior from
    Python 3.11. For example, rf"{obj:\xFF}" now correctly
    produces '\\xFF' instead of 'ÿ'. Patch by Pablo Galindo.
  - gh-136541: Fix some issues with the perf trampolines
    on x86-64 and aarch64. The trampolines were not being
    generated correctly for some cases, which could lead to
    the perf integration not working correctly. Patch by Pablo
    Galindo.
  - gh-109700: Fix memory error handling in
    PyDict_SetDefault().
  - gh-78465: Fix error message for cls.__new__(cls, ...) where
    cls is not instantiable builtin or extension type (with
    tp_new set to NULL).
  - gh-135871: Non-blocking mutex lock attempts now return
    immediately when the lock is busy instead of briefly
    spinning in the free threading build.
  - gh-135607: Fix potential weakref races in an object’s
    destructor on the free threaded build.
  - gh-135496: Fix typo in the f-string conversion type error
    (“exclamanation” -> “exclamation”).
  - gh-130077: Properly raise custom syntax errors when
    incorrect syntax containing names that are prefixes of soft
    keywords is encountered. Patch by Pablo Galindo.
  - gh-135148: Fixed a bug where f-string debug expressions
    (using =) would incorrectly strip out parts of strings
    containing escaped quotes and # characters. Patch by Pablo
    Galindo.
  - gh-133136: Limit excess memory usage in the free threading
    build when a large dictionary or list is resized and
    accessed by multiple threads.
  - gh-132617: Fix dict.update() modification check that could
    incorrectly raise a “dict mutated during update” error when
    a different dictionary was modified that happens to share
    the same underlying keys object.
  - gh-91153: Fix a crash when a bytearray is concurrently
    mutated during item assignment.
  - gh-127971: Fix off-by-one read beyond the end of a string
    in string search.
  - gh-125723: Fix crash with gi_frame.f_locals when generator
    frames outlive their generator. Patch by Mikhail Efimov.
  - Library
  - gh-132710: If possible, ensure that uuid.getnode()
    returns the same result even across different processes.
    Previously, the result was constant only within the same
    process. Patch by Bénédikt Tran.
  - gh-137273: Fix debug assertion failure in
    locale.setlocale() on Windows.
  - gh-137257: Bump the version of pip bundled in ensurepip to
    version 25.2
  - gh-81325: tarfile.TarFile now accepts a path-like when
    working on a tar archive. (Contributed by Alexander Enrique
    Urieles Nieto in gh-81325.)
  - gh-130522: Fix unraisable TypeError raised during
    interpreter shutdown in the threading module.
  - gh-130577: tarfile now validates archives to ensure member
    offsets are non-negative. (Contributed by Alexander Enrique
    Urieles Nieto in gh-130577; CVE-2025-8194, bsc#1247249).
  - gh-136549: Fix signature of threading.excepthook().
  - gh-136523: Fix wave.Wave_write emitting an unraisable when
    open raises.
  - gh-52876: Add missing keepends (default True)
    parameter to codecs.StreamReaderWriter.readline() and
    codecs.StreamReaderWriter.readlines().
  - gh-85702: If zoneinfo._common.load_tzdata is given a
    package without a resource a zoneinfo.ZoneInfoNotFoundError
    is raised rather than a PermissionError. Patch by Victor
    Stinner.
  - gh-134759: Fix UnboundLocalError in
    email.message.Message.get_payload() when the payload to
    decode is a bytes object. Patch by Kliment Lamonov.
  - gh-136028: Fix parsing month names containing “İ” (U+0130,
    LATIN CAPITAL LETTER I WITH DOT ABOVE) in time.strptime().
    This affects locales az_AZ, ber_DZ, ber_MA and crh_UA.
  - gh-135995: In the palmos encoding, make byte 0x9b decode to
    › (U+203A - SINGLE RIGHT-POINTING ANGLE QUOTATION MARK).
  - gh-53203: Fix time.strptime() for %c and %x formats on
    locales byn_ER, wal_ET and lzh_TW, and for %X format on
    locales ar_SA, bg_BG and lzh_TW.
  - gh-91555: An earlier change, which was introduced in
    3.13.4, has been reverted. It disabled logging for a logger
    during handling of log messages for that logger. Since the
    reversion, the behaviour should be as it was before 3.13.4.
  - gh-135878: Fixes a crash of types.SimpleNamespace on free
    threading builds, when several threads were calling its
    __repr__() method at the same time.
  - gh-135836: Fix IndexError in
    asyncio.loop.create_connection() that could occur when
    non-OSError exception is raised during connection and
    socket’s close() raises OSError.
  - gh-135836: Fix IndexError in
    asyncio.loop.create_connection() that could occur when the
    Happy Eyeballs algorithm resulted in an empty exceptions
    list during connection attempts.
  - gh-135855: Raise TypeError instead of SystemError when
    _interpreters.set___main___attrs() is passed a non-dict
    object. Patch by Brian Schubert.
  - gh-135815: netrc: skip security checks if os.getuid() is
    missing. Patch by Bénédikt Tran.
  - gh-135640: Address bug where it was possible to call
    xml.etree.ElementTree.ElementTree.write() on an ElementTree
    object with an invalid root element. This behavior blanked
    the file passed to write if it already existed.
  - gh-135444: Fix asyncio.DatagramTransport.sendto() to
    account for datagram header size when data cannot be sent.
  - gh-135497: Fix os.getlogin() failing for longer usernames
    on BSD-based platforms.
  - gh-135487: Fix reprlib.Repr.repr_int() when given integers
    with more than sys.get_int_max_str_digits() digits. Patch
    by Bénédikt Tran.
  - gh-135335: multiprocessing: Flush stdout and stderr after
    preloading modules in the forkserver.
  - gh-135244: uuid: when the MAC address cannot be
    determined, the 48-bit node ID is now generated with a
    cryptographically-secure pseudo-random number generator
    (CSPRNG) as per RFC 9562, §6.10.3. This affects uuid1().
  - gh-135069: Fix the “Invalid error handling” exception in
    encodings.idna.IncrementalDecoder to correctly replace the
    ‘errors’ parameter.
  - gh-134698: Fix a crash when calling methods of
    ssl.SSLContext or ssl.SSLSocket across multiple threads.
  - gh-132124: On POSIX-compliant systems,
    multiprocessing.util.get_temp_dir() now ignores TMPDIR
    (and similar environment variables) if the path length of
    AF_UNIX socket files exceeds the platform-specific maximum
    length when using the forkserver start method. Patch by
    Bénédikt Tran.
  - gh-133439: Fix dot commands with trailing spaces are
    mistaken for multi-line SQL statements in the sqlite3
    command-line interface.
  - gh-132969: Prevent the ProcessPoolExecutor executor thread,
    which remains running when shutdown(wait=False), from
    attempting to adjust the pool’s worker processes after
    the object state has already been reset during shutdown.
    A combination of conditions, including a worker process
    having terminated abormally, resulted in an exception and
    a potential hang when the still-running executor thread
    attempted to replace dead workers within the pool.
  - gh-130664: Support the '_' digit separator in formatting
    of the integral part of Decimal’s. Patch by Sergey B
    Kirpichev.
  - gh-85702: If zoneinfo._common.load_tzdata is given a
    package without a resource a ZoneInfoNotFoundError is
    raised rather than a IsADirectoryError.
  - gh-130664: Handle corner-case for Fraction’s formatting:
    treat zero-padding (preceding the width field by a zero
    ('0') character) as an equivalent to a fill character of
    '0' with an alignment type of '=', just as in case of
    float’s.
  - Tools/Demos
  - gh-135968: Stubs for strip are now provided as part of an
    iOS install.
  - Tests
  - gh-135966: The iOS testbed now handles the app_packages
    folder as a site directory.
  - gh-135494: Fix regrtest to support excluding tests from
  - -pgo tests. Patch by Victor Stinner.
  - gh-135489: Show verbose output for failing tests during PGO
    profiling step with –enable-optimizations.
  - Documentation
  - gh-135171: Document that the iterator for the leftmost for
    clause in the generator expression is created immediately.
  - Build
  - gh-135497: Fix the detection of MAXLOGNAME in the
    configure.ac script.
  - Remove upstreamed patches:
  - CVE-2025-8194-tarfile-no-neg-offsets.patch
  - CVE-2025-6069-quad-complex-HTMLParser.patch

++++ rust-keylime:

  - Update vendored crates (bsc#1247193, CVE-2025-58266)
    * shlex 1.3.0
  - Rebase keylime-agent.conf.diff for current configuration
  - Drop Cargo_lock.patch patch, already present in Cargo.lock
  - Update to version 0.2.7+141:
    * service: Use WantedBy=multi-user.target
    * rpm: Add subpackage for push-attestation agent
    * push-model: implement continuous attestation with configurable intervals
    * Retry registration forever in the state machine
    * Add Verifier URL to configuration
    * Align exp.backoff to current configuration format
    * Increase coverage of state machine (using Context)
    * Increase coverage of struct_filler.rs
    * Groom code (remove dead code)
    * Fix exponential backoff (10secs, 4xx accepted)
    * test: Add documentation test to tests/run.sh
    * tpm: Avoid running code example during documentation tests
    * state_machine: Always start the agent from the Unregistered state
    * Add fixes for the URL construction
    * Refactor evidences collection in push attestation agent
    * push-model: refactor attestation logic into a state machine
    * Fix body sending by allowing serializing strings (#1057)
    * Log ResilientClient errors/response status codes (#1055)
    * Add AK signing scheme and hash algorithm to negotiation
    * tpm: Add method to extract signing scheme and hash algorithm from AK
    * Allow custom content-type/accept headers
    * Integrate exponential backoff to registration (#1052)
    * keylime/structures: Rename ShaValues to PcrBanks
    * Add resilient_client for exponential backoff (#1048)

------------------------------------------------------------------
------------------  2025-8-6  -  Aug 6 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - io_uring/rsrc: fix folio unpinning (bsc#1246188 CVE-2025-38256).
  - commit 95e6074
  - io_uring: fix potential page leak in io_sqe_buffer_register()
    (git-fixes).
  - commit 3fb0381
  - btrfs: fix log tree replay failure due to file with 0 links
    and extents (git-fixes).
  - commit a2d6441
  - netlink: make sure we allow at least one dump skb
    (CVE-2025-38465 bsc#1247118).
  - netlink: Fix rmem check in netlink_broadcast_deliver()
    (CVE-2025-38465 bsc#1247118).
  - netlink: Fix wraparounds of sk->sk_rmem_alloc (CVE-2025-38465
    bsc#1247118).
  - commit 51a6af8
  - netfilter: nft_flow_offload: update tcp state flags under lock
    (git-fixes).
  - commit 88664ea
  - netfilter: nf_tables: imbalance in flowtable binding
    (git-fixes).
  - commit 94ec604
  - netfilter: nft_set_hash: skip duplicated elements pending gc
    run (git-fixes).
  - commit 12841f0
  - nvme-tcp: fix selinux denied when calling sock_sendmsg
    (bsc#1247497).
  - commit 6082643
  - eth: fbnic: avoid double free when failing to DMA-map FW msg
    (CVE-2025-38341 bsc#1246260).
  - commit 5553a2c
  - selftests/bpf: adapt one more case in test_lru_map to the new
    target_free (git-fixes).
  - commit 9c60da1
  - integrity/platform_certs: Allow loading of keys in the static
    key management mode (jsc#PED-13345 jsc#PED-13343).
  - powerpc/secvar: Expose secvars relevant to the key management
    mode (jsc#PED-13345 jsc#PED-13343).
  - powerpc/pseries: Correct secvar format representation for
    static key management (jsc#PED-13345 jsc#PED-13343).
  - commit 3e4fe7b

++++ kernel-firmware-amdgpu:

  - Update to version 20250805 (git commit b6b0b15278c7):
    * amdgpu: Update GCN 4.0.5 microcode
    * amdgpu: Update SDMA 6.1.0 microcode
    * amdgpu: Update GC 11.5.0 microcode

++++ kernel-rt:

  - io_uring/rsrc: fix folio unpinning (bsc#1246188 CVE-2025-38256).
  - commit 95e6074
  - io_uring: fix potential page leak in io_sqe_buffer_register()
    (git-fixes).
  - commit 3fb0381
  - btrfs: fix log tree replay failure due to file with 0 links
    and extents (git-fixes).
  - commit a2d6441
  - netlink: make sure we allow at least one dump skb
    (CVE-2025-38465 bsc#1247118).
  - netlink: Fix rmem check in netlink_broadcast_deliver()
    (CVE-2025-38465 bsc#1247118).
  - netlink: Fix wraparounds of sk->sk_rmem_alloc (CVE-2025-38465
    bsc#1247118).
  - commit 51a6af8
  - netfilter: nft_flow_offload: update tcp state flags under lock
    (git-fixes).
  - commit 88664ea
  - netfilter: nf_tables: imbalance in flowtable binding
    (git-fixes).
  - commit 94ec604
  - netfilter: nft_set_hash: skip duplicated elements pending gc
    run (git-fixes).
  - commit 12841f0
  - nvme-tcp: fix selinux denied when calling sock_sendmsg
    (bsc#1247497).
  - commit 6082643
  - eth: fbnic: avoid double free when failing to DMA-map FW msg
    (CVE-2025-38341 bsc#1246260).
  - commit 5553a2c
  - selftests/bpf: adapt one more case in test_lru_map to the new
    target_free (git-fixes).
  - commit 9c60da1
  - integrity/platform_certs: Allow loading of keys in the static
    key management mode (jsc#PED-13345 jsc#PED-13343).
  - powerpc/secvar: Expose secvars relevant to the key management
    mode (jsc#PED-13345 jsc#PED-13343).
  - powerpc/pseries: Correct secvar format representation for
    static key management (jsc#PED-13345 jsc#PED-13343).
  - commit 3e4fe7b

++++ libvirt:

  - Set virt_hooks_unconfined boolean to true in libvirt-daemon-hooks
    %post script (see comment 13 in bsc#1242998)

++++ toolbox:

  - Update to version 2.4+git20250806.ba48bd3:
    * Add SCC credentials if available [bsc#1247491]

------------------------------------------------------------------
------------------  2025-8-5  -  Aug 5 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20250805.3069494:
    * Remove initviocons for tcsh as well and
    * Update csh.login
    * Add missing quoting and remove unneeded uses of eval

++++ python-kiwi:

  - Skip kiwi-repart module in install ISOs
    In case the kiwi-repart module is explicitly requested in a
    dracut.conf file and the image is also configured to build an
    install ISO image this leads the install ISO to contain the
    kiwi-repart module as well which is unwanted. This commit
    explicitly omits the kiwi-repart when creating the initrd
    for the install image
  - Skip repart when booting install/live iso

++++ kernel-default:

  - kABI: restore layout of struct msi_desc (CVE-2025-38062
    bsc#1245216).
  - genirq/msi: Store the IOMMU IOVA directly in msi_desc instead
    of iommu_cookie (CVE-2025-38062 bsc#1245216).
  - commit 831ff50
  - md/md-cluster: handle REMOVE message earlier (bsc#1247057).
  - commit 8e8eaf1
  - sched/eevdf: Fix se->slice being set to U64_MAX and resulting (CVE-2025-37821 bsc#1242864)
  - commit ba057af
  - sched/core: Prevent rescheduling when interrupts are disabled (bsc#1240324 CVE-2024-58090)
  - commit cc45d5b
  - sched_ext: Fix invalid irq restore in scx_ops_bypass() (CVE-2024-57891 bsc#1235953)
  - commit f68543a
  - selftests/bpf: Fix unintentional switch case fall through
    (git-fixes).
  - selftests/bpf: fix signedness bug in redir_partial()
    (git-fixes).
  - selftests/bpf: Test invalid narrower ctx load (git-fixes).
  - bpf: Reject narrower access to pointer ctx fields (git-fixes).
  - bpf, sockmap: Fix psock incorrectly pointing to sk (git-fixes).
  - selftests/bpf: Add negative test cases for snprintf (git-fixes).
  - commit 0d272a0
  - bpf: Reject %p% format string in bprintf-like helpers
    (git-fixes).
  - bpf: Adjust free target to avoid global starvation of LRU map
    (git-fixes).
  - tools/resolve_btfids: Fix build when cross compiling kernel
    with clang (git-fixes).
  - commit a8770bb
  - bpf: Fix uninitialized values in BPF_{CORE,PROBE}_READ
    (git-fixes).
  - bpf: Allow XDP dev-bound programs to perform XDP_REDIRECT into
    maps (git-fixes).
  - libbpf: Add identical pointer detection to btf_dedup_is_equiv()
    (git-fixes).
  - bpf: Use proper type to calculate bpf_raw_tp_null_args.mask
    index (git-fixes).
  - samples/bpf: Fix compilation failure for samples/bpf on
    LoongArch Fedora (git-fixes).
  - commit db60287
  - bpf: Return prog btf_id without capable check (git-fixes).
  - commit 8f212fe
  - selftests/bpf: add test for softlock when modifying hashmap
    while iterating (git-fixes).
  - bpf: fix possible endless loop in BPF map iteration (git-fixes).
  - selftests/bpf: Mitigate sockmap_ktls disconnect_after_delete
    failure (git-fixes).
  - selftests/bpf: Add selftest for attaching fexit to __noreturn
    functions (git-fixes).
  - bpf: Reject attaching fexit/fmod_ret to __noreturn functions
    (git-fixes).
  - commit 088a03b
  - bpf: Only fails the busy counter check in bpf_cgrp_storage_get
    if it creates storage (git-fixes).
  - selftests/bpf: Fix string read in strncmp benchmark (git-fixes).
  - bpf, docs: Fix broken link to renamed bpf_iter_task_vmas.c
    (git-fixes).
  - selftests/bpf: Use asm constraint "m" for LoongArch (git-fixes).
  - commit 6a67de9
  - i2c: muxes: mule: Fix an error handling path in
    mule_i2c_mux_probe() (git-fixes).
  - commit 3d7da1a
  - kABI fix after vhost: Reintroduce kthread API and add mode
    selection (git-fixes).
  - commit d3622c5

++++ kernel-firmware-mediatek:

  - Update to version 20250804 (git commit 37b63dc35d98):
    * linux-firmware: update firmware for MT7925 WiFi device
    * mediatek MT7925: update bluetooth firmware to 20250721233113

++++ kernel-rt:

  - kABI: restore layout of struct msi_desc (CVE-2025-38062
    bsc#1245216).
  - genirq/msi: Store the IOMMU IOVA directly in msi_desc instead
    of iommu_cookie (CVE-2025-38062 bsc#1245216).
  - commit 831ff50
  - md/md-cluster: handle REMOVE message earlier (bsc#1247057).
  - commit 8e8eaf1
  - sched/eevdf: Fix se->slice being set to U64_MAX and resulting (CVE-2025-37821 bsc#1242864)
  - commit ba057af
  - sched/core: Prevent rescheduling when interrupts are disabled (bsc#1240324 CVE-2024-58090)
  - commit cc45d5b
  - sched_ext: Fix invalid irq restore in scx_ops_bypass() (CVE-2024-57891 bsc#1235953)
  - commit f68543a
  - selftests/bpf: Fix unintentional switch case fall through
    (git-fixes).
  - selftests/bpf: fix signedness bug in redir_partial()
    (git-fixes).
  - selftests/bpf: Test invalid narrower ctx load (git-fixes).
  - bpf: Reject narrower access to pointer ctx fields (git-fixes).
  - bpf, sockmap: Fix psock incorrectly pointing to sk (git-fixes).
  - selftests/bpf: Add negative test cases for snprintf (git-fixes).
  - commit 0d272a0
  - bpf: Reject %p% format string in bprintf-like helpers
    (git-fixes).
  - bpf: Adjust free target to avoid global starvation of LRU map
    (git-fixes).
  - tools/resolve_btfids: Fix build when cross compiling kernel
    with clang (git-fixes).
  - commit a8770bb
  - bpf: Fix uninitialized values in BPF_{CORE,PROBE}_READ
    (git-fixes).
  - bpf: Allow XDP dev-bound programs to perform XDP_REDIRECT into
    maps (git-fixes).
  - libbpf: Add identical pointer detection to btf_dedup_is_equiv()
    (git-fixes).
  - bpf: Use proper type to calculate bpf_raw_tp_null_args.mask
    index (git-fixes).
  - samples/bpf: Fix compilation failure for samples/bpf on
    LoongArch Fedora (git-fixes).
  - commit db60287
  - bpf: Return prog btf_id without capable check (git-fixes).
  - commit 8f212fe
  - selftests/bpf: add test for softlock when modifying hashmap
    while iterating (git-fixes).
  - bpf: fix possible endless loop in BPF map iteration (git-fixes).
  - selftests/bpf: Mitigate sockmap_ktls disconnect_after_delete
    failure (git-fixes).
  - selftests/bpf: Add selftest for attaching fexit to __noreturn
    functions (git-fixes).
  - bpf: Reject attaching fexit/fmod_ret to __noreturn functions
    (git-fixes).
  - commit 088a03b
  - bpf: Only fails the busy counter check in bpf_cgrp_storage_get
    if it creates storage (git-fixes).
  - selftests/bpf: Fix string read in strncmp benchmark (git-fixes).
  - bpf, docs: Fix broken link to renamed bpf_iter_task_vmas.c
    (git-fixes).
  - selftests/bpf: Use asm constraint "m" for LoongArch (git-fixes).
  - commit 6a67de9
  - i2c: muxes: mule: Fix an error handling path in
    mule_i2c_mux_probe() (git-fixes).
  - commit 3d7da1a
  - kABI fix after vhost: Reintroduce kthread API and add mode
    selection (git-fixes).
  - commit d3622c5

++++ nvidia-open-driver-G06-signed:

  - added Requires
    * nvidia-modprobe >= %version
    * nvidia-persitenced >= %version
    * nvidia-modprobe-cuda-lt-sp6
    * nvidia-persitenced-cuda-lt-sp6
    to be provided by special versions of nvidia-modprobe and
    nvidia-persitenced built against SP4 (bsc#1237208, jsc#PED-13295)

------------------------------------------------------------------
------------------  2025-8-4  -  Aug 4 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Update leap test-image-disk integration test
    Add test for alternative volume ID in install ISO

++++ grub2:

  - Skip mount point in grub_find_device function (bsc#1246231)
    * 0001-getroot-Skip-mount-points-in-grub_find_device.patch

++++ kernel-default:

  - KVM: Conditionally reschedule when resetting the dirty ring
    (git-fixes).
  - commit 2dff58a
  - KVM: Bail from the dirty ring reset flow if a signal is pending
    (git-fixes).
  - commit eab0b89
  - KVM: Bound the number of dirty ring entries in a single reset
    at INT_MAX (git-fixes).
  - commit aac37a8
  - KVM: Allow CPU to reschedule while setting per-page memory
    attributes (git-fixes).
  - commit 5d216e9
  - KVM: arm64: Don't free hyp pages with pKVM on GICv2 (git-fixes).
  - commit c01040d
  - tcp: call tcp_measure_rcv_mss() for ooo packets (git-fixes).
  - commit 317bbda
  - net/sched: sch_qfq: Avoid triggering might_sleep in atomic
    context in qfq_delete_class (git-fixes).
  - commit 7e0d53d
  - KVM: arm64: Fix error path in init_hyp_mode() (git-fixes).
  - commit 23e29da
  - btrfs: avoid starting new transaction when cleaning qgroup
    during subvolume drop (git-fixes).
  - commit 5d6038d
  - btrfs: qgroup: fix qgroup create ioctl returning success after
    quotas disabled (git-fixes).
  - commit 6bfd9e4
  - btrfs: qgroup: set quota enabled bit if quota disable fails
    flushing reservations (git-fixes).
  - commit 7eff76f
  - KVM: arm64: Adjust range correctly during host stage-2 faults
    (git-fixes).
  - commit 3d83087
  - btrfs: clear dirty status from extent buffer on error at
    insert_new_root() (git-fixes).
  - commit feae542
  - btrfs: tests: fix chunk map leak after failure to add it to
    the tree (git-fixes).
  - commit ab9615f
  - btrfs: fix ssd_spread overallocation (git-fixes).
  - commit c5cd300
  - Rename to
    patches.suse/virtio-blk-scsi-use-block-layer-helpers-to-calculate.patch.
  - commit 4cc7f9f
  - Rename to
    patches.suse/scsi-use-block-layer-helpers-to-calculate-num-of-que.patch.
  - commit a2aa4dc
  - Rename to
    patches.suse/nvme-pci-use-block-layer-helpers-to-calculate-num-of.patch.
  - commit 1f9b36e
  - btrfs: use btrfs_record_snapshot_destroy() during rmdir
    (git-fixes).
  - commit 88c829f
  - btrfs: propagate last_unlink_trans earlier when doing a rmdir
    (git-fixes).
  - commit bbb516f
  - Refresh
    patches.suse/blk-mq-add-number-of-queue-calc-helper.patch.
  - commit e910199
  - btrfs: don't skip remaining extrefs if dir not found during
    log replay (git-fixes).
  - commit 70b2e71
  - Rename to patches.suse/lib-group_cpus-Let-group_cpu_evenly-return-the-numbe.patch. (bsc#1236897 bsc#1243774)
  - Refresh
    patches.suse/lib-group_cpus-honor-housekeeping-config-when-grouping-cpus.patch.
  - commit 446c2ea
  - btrfs: don't ignore inode missing when replaying log tree
    (git-fixes).
  - commit 23b8b0c
  - btrfs: fix inode lookup error handling during log replay
    (git-fixes).
  - commit 2365a96
  - lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly() (bsc#1236897).
  - Refresh
    patches.suse/lib-group_cpus-let-group_cpu_evenly-return-number-initialized-masks.patch.
  - commit 1ff1f6d
  - btrfs: don't silently ignore unexpected extent type when
    replaying log (git-fixes).
  - commit 45649bf
  - btrfs: fix invalid inode pointer dereferences during log replay
    (git-fixes).
  - commit b75fd3b
  - KVM: x86: Drop pending_smi vs. INIT_RECEIVED check when setting
    MP_STATE (git-fixes).
  - commit 5a81b3c
  - btrfs: return a btrfs_inode from read_one_inode() (git-fixes).
  - commit f365bc7
  - btrfs: return a btrfs_inode from btrfs_iget_logging()
    (git-fixes).
  - commit 1b7aead
  - KVM: SVM: Disable interception of SPEC_CTRL iff the MSR exists
    for the guest (git-fixes).
  - commit 32d198b
  - nvmet: pci-epf: Do not complete commands twice if
    nvmet_req_init() fails (git-fixes).
  - nvmet-tcp: fix callback lock for TLS handshake (git-fixes).
  - nvme: fix misaccounting of nvme-mpath inflight I/O (git-fixes).
  - nvme: fix endianness of command word prints in
    nvme_log_err_passthru() (git-fixes).
  - nvme: fix inconsistent RCU list manipulation in
    nvme_ns_add_to_ctrl_list() (git-fixes).
  - commit 1304ce4
  - KVM: TDX: Use kvm_arch_vcpu.host_debugctl to restore the host's
    DEBUGCTL (git-fixes).
  - commit d8f0496
  - btrfs: update superblock's device bytes_used when dropping chunk
    (git-fixes).
  - commit a87918f
  - Enable SMC_LO (a.k.a SMC-D) (jsc#PED-13256).
  - commit 9164e38
  - Fix bogus i915 patch backport (bsc#1238972)
    It's been already cherry-picked in 6.12 kernel itself.
  - commit b66de0d
  - RDMA/core: Rate limit GID cache warning messages (git-fixes)
  - commit a5e809e
  - Refresh patches.suse/s390-boot-Use-D__DISABLE_EXPORTS.patch.
  - commit bcdca9e
  - KVM: x86: Avoid calling kvm_is_mmio_pfn() when
    kvm_x86_ops.get_mt_mask is NULL (git-fixes).
  - commit cc59aef
  - Update config files.
  - commit 40dfe08
  - vsock/virtio: Validate length in packet header before skb_put()
    (git-fixes).
  - commit 3f40097
  - vhost/vsock: Avoid allocating arbitrarily-sized SKBs
    (git-fixes).
  - commit b8d0767
  - vhost: Reintroduce kthread API and add mode selection
    (git-fixes).
  - commit 4f10d1a
  - vhost-scsi: Fix log flooding with target does not exist errors
    (git-fixes).
  - commit 35e2840
  - virtio_net: Enforce minimum TX ring size for reliability
    (git-fixes).
  - commit d86e0e3
  - Refresh patches.suse/powerpc-pseries-dlpar-Search-DRC-index-from-ibm-drc-.patch.
  - commit 8a56f7b
  - virtio_ring: Fix error reporting in virtqueue_resize
    (git-fixes).
  - commit 82b060c
  - kernel-syms.spec: Drop old rpm release number hack (bsc#1247172).
  - commit b4fa2d1
  - xen/gntdev: remove struct gntdev_copy_batch from stack
    (git-fixes).
  - commit 078d2c1
  - rtc: rv3028: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: pcf8563: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: pcf85063: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: nct3018y: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: hym8563: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: ds1307: fix incorrect maximum clock rate handling
    (git-fixes).
  - ucount: fix atomic_long_inc_below() argument type (git-fixes).
  - i3c: fix module_i3c_i2c_driver() with I3C=n (git-fixes).
  - commit 24bca99
  - xen: fix UAF in dmabuf_exp_from_pages() (git-fixes).
  - commit b9557cc

++++ kernel-rt:

  - KVM: Conditionally reschedule when resetting the dirty ring
    (git-fixes).
  - commit 2dff58a
  - KVM: Bail from the dirty ring reset flow if a signal is pending
    (git-fixes).
  - commit eab0b89
  - KVM: Bound the number of dirty ring entries in a single reset
    at INT_MAX (git-fixes).
  - commit aac37a8
  - KVM: Allow CPU to reschedule while setting per-page memory
    attributes (git-fixes).
  - commit 5d216e9
  - KVM: arm64: Don't free hyp pages with pKVM on GICv2 (git-fixes).
  - commit c01040d
  - tcp: call tcp_measure_rcv_mss() for ooo packets (git-fixes).
  - commit 317bbda
  - net/sched: sch_qfq: Avoid triggering might_sleep in atomic
    context in qfq_delete_class (git-fixes).
  - commit 7e0d53d
  - KVM: arm64: Fix error path in init_hyp_mode() (git-fixes).
  - commit 23e29da
  - btrfs: avoid starting new transaction when cleaning qgroup
    during subvolume drop (git-fixes).
  - commit 5d6038d
  - btrfs: qgroup: fix qgroup create ioctl returning success after
    quotas disabled (git-fixes).
  - commit 6bfd9e4
  - btrfs: qgroup: set quota enabled bit if quota disable fails
    flushing reservations (git-fixes).
  - commit 7eff76f
  - KVM: arm64: Adjust range correctly during host stage-2 faults
    (git-fixes).
  - commit 3d83087
  - btrfs: clear dirty status from extent buffer on error at
    insert_new_root() (git-fixes).
  - commit feae542
  - btrfs: tests: fix chunk map leak after failure to add it to
    the tree (git-fixes).
  - commit ab9615f
  - btrfs: fix ssd_spread overallocation (git-fixes).
  - commit c5cd300
  - Rename to
    patches.suse/virtio-blk-scsi-use-block-layer-helpers-to-calculate.patch.
  - commit 4cc7f9f
  - Rename to
    patches.suse/scsi-use-block-layer-helpers-to-calculate-num-of-que.patch.
  - commit a2aa4dc
  - Rename to
    patches.suse/nvme-pci-use-block-layer-helpers-to-calculate-num-of.patch.
  - commit 1f9b36e
  - btrfs: use btrfs_record_snapshot_destroy() during rmdir
    (git-fixes).
  - commit 88c829f
  - btrfs: propagate last_unlink_trans earlier when doing a rmdir
    (git-fixes).
  - commit bbb516f
  - Refresh
    patches.suse/blk-mq-add-number-of-queue-calc-helper.patch.
  - commit e910199
  - btrfs: don't skip remaining extrefs if dir not found during
    log replay (git-fixes).
  - commit 70b2e71
  - Rename to patches.suse/lib-group_cpus-Let-group_cpu_evenly-return-the-numbe.patch. (bsc#1236897 bsc#1243774)
  - Refresh
    patches.suse/lib-group_cpus-honor-housekeeping-config-when-grouping-cpus.patch.
  - commit 446c2ea
  - btrfs: don't ignore inode missing when replaying log tree
    (git-fixes).
  - commit 23b8b0c
  - btrfs: fix inode lookup error handling during log replay
    (git-fixes).
  - commit 2365a96
  - lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly() (bsc#1236897).
  - Refresh
    patches.suse/lib-group_cpus-let-group_cpu_evenly-return-number-initialized-masks.patch.
  - commit 1ff1f6d
  - btrfs: don't silently ignore unexpected extent type when
    replaying log (git-fixes).
  - commit 45649bf
  - btrfs: fix invalid inode pointer dereferences during log replay
    (git-fixes).
  - commit b75fd3b
  - KVM: x86: Drop pending_smi vs. INIT_RECEIVED check when setting
    MP_STATE (git-fixes).
  - commit 5a81b3c
  - btrfs: return a btrfs_inode from read_one_inode() (git-fixes).
  - commit f365bc7
  - btrfs: return a btrfs_inode from btrfs_iget_logging()
    (git-fixes).
  - commit 1b7aead
  - KVM: SVM: Disable interception of SPEC_CTRL iff the MSR exists
    for the guest (git-fixes).
  - commit 32d198b
  - nvmet: pci-epf: Do not complete commands twice if
    nvmet_req_init() fails (git-fixes).
  - nvmet-tcp: fix callback lock for TLS handshake (git-fixes).
  - nvme: fix misaccounting of nvme-mpath inflight I/O (git-fixes).
  - nvme: fix endianness of command word prints in
    nvme_log_err_passthru() (git-fixes).
  - nvme: fix inconsistent RCU list manipulation in
    nvme_ns_add_to_ctrl_list() (git-fixes).
  - commit 1304ce4
  - KVM: TDX: Use kvm_arch_vcpu.host_debugctl to restore the host's
    DEBUGCTL (git-fixes).
  - commit d8f0496
  - btrfs: update superblock's device bytes_used when dropping chunk
    (git-fixes).
  - commit a87918f
  - Enable SMC_LO (a.k.a SMC-D) (jsc#PED-13256).
  - commit 9164e38
  - Fix bogus i915 patch backport (bsc#1238972)
    It's been already cherry-picked in 6.12 kernel itself.
  - commit b66de0d
  - RDMA/core: Rate limit GID cache warning messages (git-fixes)
  - commit a5e809e
  - Refresh patches.suse/s390-boot-Use-D__DISABLE_EXPORTS.patch.
  - commit bcdca9e
  - KVM: x86: Avoid calling kvm_is_mmio_pfn() when
    kvm_x86_ops.get_mt_mask is NULL (git-fixes).
  - commit cc59aef
  - Update config files.
  - commit 40dfe08
  - vsock/virtio: Validate length in packet header before skb_put()
    (git-fixes).
  - commit 3f40097
  - vhost/vsock: Avoid allocating arbitrarily-sized SKBs
    (git-fixes).
  - commit b8d0767
  - vhost: Reintroduce kthread API and add mode selection
    (git-fixes).
  - commit 4f10d1a
  - vhost-scsi: Fix log flooding with target does not exist errors
    (git-fixes).
  - commit 35e2840
  - virtio_net: Enforce minimum TX ring size for reliability
    (git-fixes).
  - commit d86e0e3
  - Refresh patches.suse/powerpc-pseries-dlpar-Search-DRC-index-from-ibm-drc-.patch.
  - commit 8a56f7b
  - virtio_ring: Fix error reporting in virtqueue_resize
    (git-fixes).
  - commit 82b060c
  - kernel-syms.spec: Drop old rpm release number hack (bsc#1247172).
  - commit b4fa2d1
  - xen/gntdev: remove struct gntdev_copy_batch from stack
    (git-fixes).
  - commit 078d2c1
  - rtc: rv3028: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: pcf8563: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: pcf85063: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: nct3018y: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: hym8563: fix incorrect maximum clock rate handling
    (git-fixes).
  - rtc: ds1307: fix incorrect maximum clock rate handling
    (git-fixes).
  - ucount: fix atomic_long_inc_below() argument type (git-fixes).
  - i3c: fix module_i3c_i2c_driver() with I3C=n (git-fixes).
  - commit 24bca99
  - xen: fix UAF in dmabuf_exp_from_pages() (git-fixes).
  - commit b9557cc

++++ numactl:

  - bsc#1247093 bsc#1246858
    Cleanup code by reverting 2 patches and get back to old
    has_preferred_many initialization.
    This allows to call numa_set_bind_policy early again.
    A    Cleanup-No-need-to-suppress-possible-errno-anymore.patch
    A    Cleanup-move-has_preferred_many-to-numa_init-again.patch

++++ libsolv:

  - fixed rare crash in the handling of allowuninstall in combination
    with forcebest updates
  - new pool_satisfieddep_map feature to test if a set of packages
    satisfies a dependency
  - bump version to 0.7.35

++++ tiff:

  - bsc#1243503:
    Fix TIFFMergeFieldInfo() read_count=write_count=0
    + tiff-4.7.0-bsc1243503.patch
  - security update:
    * CVE-2025-8176 [bsc#1247108]
    Fix heap use-after-free in tools/tiffmedian.c
    + tiff-CVE-2025-8176.patch
    * CVE-2025-8177 [bsc#1247106]
    Fix possible buffer overflow in tools/thumbnail.c:setrow()
    + tiff-CVE-2025-8177.patch

++++ net-tools:

  - Fix a regression in net-tools-CVE-2025-46836.patch (bsc#1246608).

------------------------------------------------------------------
------------------  2025-8-3  -  Aug 3 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - pinmux: fix race causing mux_owner NULL with active mux_usecount
    (git-fixes).
  - pinctrl: berlin: fix memory leak in berlin_pinctrl_build_state()
    (git-fixes).
  - pinctrl: sunxi: Fix memory leak on krealloc failure (git-fixes).
  - fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
    (git-fixes).
  - firewire: ohci: correct code comments about bus_reset tasklet
    (git-fixes).
  - commit 598b0ba

++++ kernel-rt:

  - pinmux: fix race causing mux_owner NULL with active mux_usecount
    (git-fixes).
  - pinctrl: berlin: fix memory leak in berlin_pinctrl_build_state()
    (git-fixes).
  - pinctrl: sunxi: Fix memory leak on krealloc failure (git-fixes).
  - fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
    (git-fixes).
  - firewire: ohci: correct code comments about bus_reset tasklet
    (git-fixes).
  - commit 598b0ba

------------------------------------------------------------------
------------------  2025-8-2  -  Aug 2 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - PCI: rockchip-host: Fix "Unexpected Completion" log message
    (git-fixes).
  - PCI: imx6: Delay link start until configfs 'start' written
    (git-fixes).
  - PCI: imx6: Remove apps_reset toggling from
    imx_pcie_{assert/deassert}_core_reset (git-fixes).
  - PCI: imx6: Add IMX8MM_EP and IMX8MP_EP fixed 256-byte BAR 4
    in epc_features (git-fixes).
  - PCI: endpoint: pci-epf-vntb: Fix the incorrect usage of __iomem
    attribute (git-fixes).
  - PCI: endpoint: pci-epf-vntb: Return -ENOENT if
    pci_epc_get_next_free_bar() fails (git-fixes).
  - PCI: endpoint: Fix configfs group removal on driver teardown
    (git-fixes).
  - PCI: endpoint: Fix configfs group list head handling
    (git-fixes).
  - watchdog: ziirave_wdt: check record length in
    ziirave_firm_verify() (git-fixes).
  - dmaengine: nbpfaxi: Add missing check after DMA map (git-fixes).
  - dmaengine: mv_xor: Fix missing check after DMA map and missing
    unmap (git-fixes).
  - dmaengine: mmp: Fix again Wvoid-pointer-to-enum-cast warning
    (git-fixes).
  - dmaengine: qcom: gpi: Drop unused gpi_write_reg_field()
    (git-fixes).
  - dmaengine: fsl-dpaa2-qdma: Drop unused mc_enc() (git-fixes).
  - dmaengine: dw-edma: Drop unused dchan2dev() and chan2dev()
    (git-fixes).
  - phy: qcom: phy-qcom-m31: Update IPQ5332 M31 USB phy
    initialization sequence (git-fixes).
  - phy: qualcomm: phy-qcom-eusb2-repeater: Don't zero-out registers
    (git-fixes).
  - selftests: ALSA: fix memory leak in utimer test (git-fixes).
  - ASoC: fsl_xcvr: get channel status data when PHY is not exists
    (git-fixes).
  - ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx()
    (git-fixes).
  - soundwire: stream: restore params when prepare ports fail
    (git-fixes).
  - drm/xe/vf: Disable CSC support on VF (git-fixes).
  - drm/amd/display: fix initial backlight brightness calculation
    (git-fixes).
  - drm/amdgpu: Initialize data to NULL in
    imu_v12_0_program_rlc_ram() (git-fixes).
  - power: supply: max14577: Handle NULL pdata when CONFIG_OF is
    not set (git-fixes).
  - power: supply: cpcap-charger: Fix null check for
    power_supply_get_by_name (git-fixes).
  - HID: apple: validate feature-report field count to prevent
    NULL pointer dereference (git-fixes).
  - kasan: use vmalloc_dump_obj() for vmalloc error reports
    (git-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Pavilion
    15-eg0xxx (stable-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Victus 15-fa0xxx
    (stable-fixes).
  - staging: vchiq_arm: Make vchiq_shutdown never fail (git-fixes).
  - regulator: core: fix NULL dereference on unbind due to stale
    coupling data (stable-fixes).
  - spi: cadence-quadspi: fix cleanup of rx_chan on failure paths
    (stable-fixes).
  - platform/x86: asus-nb-wmi: add DMI quirk for ASUS Zenbook Duo
    UX8406CA (stable-fixes).
  - usb: typec: tcpm: apply vbus before data bringup in
    tcpm_src_attach (git-fixes).
  - usb: typec: tcpm: allow switching to mode accessory to mux
    properly (stable-fixes).
  - usb: typec: tcpm: allow to use sink in accessory mode
    (stable-fixes).
  - commit 50f3301

++++ kernel-rt:

  - PCI: rockchip-host: Fix "Unexpected Completion" log message
    (git-fixes).
  - PCI: imx6: Delay link start until configfs 'start' written
    (git-fixes).
  - PCI: imx6: Remove apps_reset toggling from
    imx_pcie_{assert/deassert}_core_reset (git-fixes).
  - PCI: imx6: Add IMX8MM_EP and IMX8MP_EP fixed 256-byte BAR 4
    in epc_features (git-fixes).
  - PCI: endpoint: pci-epf-vntb: Fix the incorrect usage of __iomem
    attribute (git-fixes).
  - PCI: endpoint: pci-epf-vntb: Return -ENOENT if
    pci_epc_get_next_free_bar() fails (git-fixes).
  - PCI: endpoint: Fix configfs group removal on driver teardown
    (git-fixes).
  - PCI: endpoint: Fix configfs group list head handling
    (git-fixes).
  - watchdog: ziirave_wdt: check record length in
    ziirave_firm_verify() (git-fixes).
  - dmaengine: nbpfaxi: Add missing check after DMA map (git-fixes).
  - dmaengine: mv_xor: Fix missing check after DMA map and missing
    unmap (git-fixes).
  - dmaengine: mmp: Fix again Wvoid-pointer-to-enum-cast warning
    (git-fixes).
  - dmaengine: qcom: gpi: Drop unused gpi_write_reg_field()
    (git-fixes).
  - dmaengine: fsl-dpaa2-qdma: Drop unused mc_enc() (git-fixes).
  - dmaengine: dw-edma: Drop unused dchan2dev() and chan2dev()
    (git-fixes).
  - phy: qcom: phy-qcom-m31: Update IPQ5332 M31 USB phy
    initialization sequence (git-fixes).
  - phy: qualcomm: phy-qcom-eusb2-repeater: Don't zero-out registers
    (git-fixes).
  - selftests: ALSA: fix memory leak in utimer test (git-fixes).
  - ASoC: fsl_xcvr: get channel status data when PHY is not exists
    (git-fixes).
  - ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx()
    (git-fixes).
  - soundwire: stream: restore params when prepare ports fail
    (git-fixes).
  - drm/xe/vf: Disable CSC support on VF (git-fixes).
  - drm/amd/display: fix initial backlight brightness calculation
    (git-fixes).
  - drm/amdgpu: Initialize data to NULL in
    imu_v12_0_program_rlc_ram() (git-fixes).
  - power: supply: max14577: Handle NULL pdata when CONFIG_OF is
    not set (git-fixes).
  - power: supply: cpcap-charger: Fix null check for
    power_supply_get_by_name (git-fixes).
  - HID: apple: validate feature-report field count to prevent
    NULL pointer dereference (git-fixes).
  - kasan: use vmalloc_dump_obj() for vmalloc error reports
    (git-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Pavilion
    15-eg0xxx (stable-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Victus 15-fa0xxx
    (stable-fixes).
  - staging: vchiq_arm: Make vchiq_shutdown never fail (git-fixes).
  - regulator: core: fix NULL dereference on unbind due to stale
    coupling data (stable-fixes).
  - spi: cadence-quadspi: fix cleanup of rx_chan on failure paths
    (stable-fixes).
  - platform/x86: asus-nb-wmi: add DMI quirk for ASUS Zenbook Duo
    UX8406CA (stable-fixes).
  - usb: typec: tcpm: apply vbus before data bringup in
    tcpm_src_attach (git-fixes).
  - usb: typec: tcpm: allow switching to mode accessory to mux
    properly (stable-fixes).
  - usb: typec: tcpm: allow to use sink in accessory mode
    (stable-fixes).
  - commit 50f3301

------------------------------------------------------------------
------------------  2025-8-1  -  Aug 1 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20250801.f305627:
    * Remove sysconfig.language [bsc#1247286]
  - Update to version 84.87+git20250801.b2fa3fe:
    * Allow /etc/locale.conf to have no newline

++++ busybox:

  - revert the change to busybox.install.patch below. The logic will be
    needed only in busybox-links package when generating file lists.
  - fix mkdir path to point to /usr/bin instead of /bin

++++ chrony:

  - bsc#1246544: Fix racy socket creation
    * Add chrony-unix-socket.patch
    * Add chrony-remove-chmod.patch
  - Update clknetsim to snapshot a2eb0b25.

++++ python-kiwi:

  - Bump version: 10.2.30 → 10.2.31

++++ kernel-default:

  - iommu/arm-smmu-qcom: Add SM6115 MDSS compatible (git-fixes).
  - commit 86d87fb
  - iommu/amd: Fix geometry.aperture_end for V2 tables (git-fixes).
  - commit 9fabb61
  - cgroup: Add compatibility option for content of /proc/cgroups
    (jsc#PED-12405).
  - cgroup: Print message when /proc/cgroups is read on v2-only
    system (jsc#PED-12405).
  - commit 764f23b
  - Update
    patches.suse/ACPI-CPPC-Fix-NULL-pointer-dereference-when-nosmp-is.patch
    (git-fixes CVE-2025-38113 bsc#1245683).
  - Update
    patches.suse/ACPICA-Refuse-to-evaluate-a-method-if-arguments-are-.patch
    (stable-fixes CVE-2025-38386 bsc#1247138).
  - Update
    patches.suse/ACPICA-fix-acpi-operand-cache-leak-in-dswstate.c.patch
    (stable-fixes CVE-2025-38345 bsc#1246337).
  - Update
    patches.suse/ACPICA-fix-acpi-parse-and-parseext-cache-leaks.patch
    (stable-fixes CVE-2025-38344 bsc#1246334).
  - Update
    patches.suse/ALSA-ad1816a-Fix-potential-NULL-pointer-deref-in-snd.patch
    (git-fixes CVE-2025-38454 bsc#1247426).
  - Update
    patches.suse/ALSA-usb-audio-Fix-out-of-bounds-read-in-snd_usb_get.patch
    (git-fixes CVE-2025-38249 bsc#1246171).
  - Update
    patches.suse/ASoC-Intel-avs-Verify-content-returned-by-parse_int_.patch
    (git-fixes CVE-2025-38307 bsc#1246364).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-Use-devm_kstrdup-to-avoid-memleak.patch
    (stable-fixes CVE-2025-38438 bsc#1247157).
  - Update
    patches.suse/ASoC-codecs-wcd9335-Fix-missing-free-of-regulator-su.patch
    (git-fixes CVE-2025-38259 bsc#1246220).
  - Update
    patches.suse/ASoC-mediatek-mt8195-Set-ETDM1-2-IN-OUT-to-COMP_DUMM.patch
    (git-fixes CVE-2025-38299 bsc#1246290).
  - Update
    patches.suse/Bluetooth-Disable-SCO-support-if-READ_VOICE_SETTING-.patch
    (stable-fixes CVE-2025-38099 bsc#1245671).
  - Update
    patches.suse/Bluetooth-Fix-NULL-pointer-deference-on-eir_get_serv.patch
    (git-fixes CVE-2025-38304 bsc#1246240).
  - Update
    patches.suse/Bluetooth-Fix-null-ptr-deref-in-l2cap_sock_resume_cb.patch
    (git-fixes CVE-2025-38473 bsc#1247289).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-UAF-on-mgmt_remove_adv_monitor_co.patch
    (git-fixes CVE-2025-38118 bsc#1245670).
  - Update
    patches.suse/Bluetooth-MGMT-reject-malformed-HCI_CMD_SYNC-command.patch
    (git-fixes CVE-2025-38128 bsc#1245703).
  - Update
    patches.suse/Bluetooth-btintel-Check-dsbr-size-from-EFI-variable.patch
    (git-fixes CVE-2025-38315 bsc#1246333).
  - Update
    patches.suse/Bluetooth-eir-Fix-possible-crashes-on-eir_create_adv.patch
    (git-fixes CVE-2025-38303 bsc#1246354).
  - Update
    patches.suse/HID-core-do-not-bypass-hid_hw_raw_request.patch
    (stable-fixes CVE-2025-38494 bsc#1247349).
  - Update
    patches.suse/HID-core-ensure-the-allocated-report-buffer-can-cont.patch
    (stable-fixes CVE-2025-38495 bsc#1247348).
  - Update
    patches.suse/HID-wacom-fix-crash-in-wacom_aes_battery_handler.patch
    (git-fixes CVE-2025-38253 bsc#1246192).
  - Update
    patches.suse/IB-cm-Drop-lockdep-assert-and-WARN-when-freeing-old-.patch
    (git-fixes CVE-2025-38287 bsc#1246285).
  - Update
    patches.suse/IB-mlx5-Fix-potential-deadlock-in-MR-deregistration.patch
    (git-fixes CVE-2025-38373 bsc#1247033).
  - Update
    patches.suse/Input-cs40l50-vibra-fix-potential-NULL-dereference-i.patch
    (git-fixes CVE-2025-38381 bsc#1247027).
  - Update
    patches.suse/Input-gpio-keys-fix-a-sleep-while-atomic-with-PREEMP.patch
    (git-fixes CVE-2025-38335 bsc#1246250).
  - Update
    patches.suse/Input-ims-pcu-check-record-size-in-ims_pcu_flash_fir.patch
    (git-fixes CVE-2025-38428 bsc#1247150).
  - Update
    patches.suse/KVM-SVM-Reject-SEV-ES-intra-host-migration-if-vCPU-c.patch
    (git-fixes CVE-2025-38455 bsc#1247101).
  - Update
    patches.suse/NFC-nci-uart-Set-tty-disc_data-only-in-success-path.patch
    (git-fixes CVE-2025-38416 bsc#1247151).
  - Update
    patches.suse/NFSD-fix-race-between-nfsd-registration-and-exports_proc.patch
    (git-fixes CVE-2025-38232 bsc#1246054).
  - Update
    patches.suse/NFSv4-pNFS-Fix-a-race-to-wake-on-NFS_LAYOUT_DRAIN.patch
    (git-fixes CVE-2025-38393 bsc#1247170).
  - Update
    patches.suse/PCI-pwrctrl-Cancel-outstanding-rescan-work-when-unre.patch
    (git-fixes CVE-2025-38137 bsc#1245721).
  - Update
    patches.suse/RDMA-cma-Fix-hang-when-cma_netevent_callback-fails-t.patch
    (git-fixes CVE-2025-38151 bsc#1245745).
  - Update
    patches.suse/RDMA-iwcm-Fix-use-after-free-of-work-objects-after-c.patch
    (git-fixes CVE-2025-38211 bsc#1246008).
  - Update
    patches.suse/RDMA-mlx5-Fix-error-flow-upon-firmware-failure-for-R.patch
    (git-fixes CVE-2025-38161 bsc#1245777).
  - Update
    patches.suse/RDMA-mlx5-Fix-unsafe-xarray-access-in-implicit-ODP-h.patch
    (git-fixes CVE-2025-38372 bsc#1247020).
  - Update
    patches.suse/RDMA-mlx5-Initialize-obj_event-obj_sub_list-before-x.patch
    (git-fixes CVE-2025-38387 bsc#1247154).
  - Update
    patches.suse/Squashfs-check-return-result-of-sb_min_blocksize.patch
    (git-fixes CVE-2025-38415 bsc#1247147).
  - Update
    patches.suse/VMCI-fix-race-between-vmci_host_setup_notify-and-vmc.patch
    (git-fixes CVE-2025-38102 bsc#1245669).
  - Update
    patches.suse/aoe-clean-device-rq_list-in-aoedev_downdev.patch
    (git-fixes CVE-2025-38326 bsc#1246490).
  - Update
    patches.suse/arm64-fpsimd-Avoid-clobbering-kernel-FPSIMD-state-with-SMS.patch
    (git-fixes CVE-2025-38169 bsc#1245784).
  - Update
    patches.suse/arm64-fpsimd-Discard-stale-CPU-state-when-handling-SME-tra.patch
    (git-fixes CVE-2025-38170 bsc#1245785).
  - Update
    patches.suse/ata-pata_via-Force-PIO-for-ATAPI-devices-on-VT6415-V.patch
    (stable-fixes CVE-2025-38336 bsc#1246370).
  - Update
    patches.suse/backlight-pm8941-Add-NULL-check-in-wled_configure.patch
    (git-fixes CVE-2025-38143 bsc#1245714).
  - Update
    patches.suse/block-don-t-use-submit_bio_noacct_nocheck-in-blk_zone_wplu.patch
    (git-fixes CVE-2025-38302 bsc#1246353).
  - Update patches.suse/bnxt-properly-flush-XDP-redirect-lists.patch
    (git-fixes CVE-2025-38246 bsc#1246195).
  - Update
    patches.suse/bnxt_en-Fix-double-invocation-of-bnxt_ulp_stop-bnxt_.patch
    (git-fixes CVE-2025-38186 bsc#1245955).
  - Update
    patches.suse/bpf-sockmap-Fix-panic-when-calling-skb_linearize.patch
    (bsc#1245749 CVE-2025-38154 CVE-2025-38165 bsc#1245757).
  - Update patches.suse/bus-fsl-mc-fix-double-free-on-mc_dev.patch
    (git-fixes CVE-2025-38313 bsc#1246342).
  - Update
    patches.suse/bus-mhi-ep-Update-read-pointer-only-after-buffer-is-.patch
    (git-fixes CVE-2025-38429 bsc#1247253).
  - Update
    patches.suse/calipso-Fix-null-ptr-deref-in-calipso_req_-set-del-a.patch
    (git-fixes CVE-2025-38181 bsc#1246000).
  - Update
    patches.suse/can-kvaser_pciefd-refine-error-prone-echo_skb_max-ha.patch
    (git-fixes CVE-2025-38224 bsc#1246166).
  - Update
    patches.suse/clk-imx-Fix-an-out-of-bounds-access-in-dispmix_csr_c.patch
    (git-fixes CVE-2025-38446 bsc#1247231).
  - Update
    patches.suse/comedi-Fail-COMEDI_INSNLIST-ioctl-if-n_insns-is-too-.patch
    (git-fixes CVE-2025-38481 bsc#1247276).
  - Update
    patches.suse/comedi-Fix-initialization-of-data-for-instructions-t.patch
    (git-fixes CVE-2025-38478 bsc#1247273).
  - Update
    patches.suse/comedi-Fix-use-of-uninitialized-data-in-insn_rw_emul.patch
    (git-fixes CVE-2025-38480 bsc#1247274).
  - Update
    patches.suse/comedi-das16m1-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38483 bsc#1247278).
  - Update
    patches.suse/comedi-das6402-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38482 bsc#1247277).
  - Update
    patches.suse/crypto-marvell-cesa-Handle-zero-length-skcipher-requ.patch
    (git-fixes CVE-2025-38173 bsc#1245769).
  - Update
    patches.suse/crypto-sun8i-ce-cipher-fix-error-handling-in-sun8i_c.patch
    (git-fixes CVE-2025-38300 bsc#1246349).
  - Update patches.suse/dm-bufio-fix-sched-in-atomic-context.patch
    (git-fixes CVE-2025-38496 bsc#1247284).
  - Update patches.suse/dm-fix-dm_blk_report_zones.patch
    (CVE-2025-38140 bsc#1245717 CVE-2025-38141 bsc#1245715).
  - Update
    patches.suse/dma-buf-insert-memory-barrier-before-updating-num_fe.patch
    (git-fixes CVE-2025-38095 bsc#1245658).
  - Update
    patches.suse/dmaengine-idxd-Check-availability-of-workqueue-alloc.patch
    (stable-fixes CVE-2025-38369 bsc#1247209).
  - Update
    patches.suse/dmaengine-ti-Add-NULL-check-in-udma_probe.patch
    (git-fixes CVE-2025-38138 bsc#1245719).
  - Update
    patches.suse/drivers-rapidio-rio_cm.c-prevent-possible-heap-overw.patch
    (stable-fixes CVE-2025-38090 bsc#1245510).
  - Update
    patches.suse/drm-amd-display-Add-null-pointer-check-for-get_first.patch
    (git-fixes CVE-2025-38362 bsc#1247089).
  - Update
    patches.suse/drm-amd-display-Check-dce_hwseq-before-dereferencing.patch
    (stable-fixes CVE-2025-38361 bsc#1247079).
  - Update
    patches.suse/drm-amd-display-Don-t-treat-wb-connector-as-physical.patch
    (stable-fixes CVE-2025-38098 bsc#1245654).
  - Update
    patches.suse/drm-amd-display-check-stream-id-dml21-wrapper-to-get.patch
    (stable-fixes CVE-2025-38091 bsc#1245621).
  - Update
    patches.suse/drm-amd-pp-Fix-potential-NULL-pointer-dereference-in.patch
    (git-fixes CVE-2025-38319 bsc#1246243).
  - Update
    patches.suse/drm-exynos-exynos7_drm_decon-add-vblank-check-in-IRQ.patch
    (git-fixes CVE-2025-38467 bsc#1247146).
  - Update
    patches.suse/drm-gem-Acquire-references-on-GEM-handles-for-frameb.patch
    (stable-fixes CVE-2025-38449 bsc#1247255).
  - Update
    patches.suse/drm-i915-gt-Fix-timeline-left-held-on-VMA-alloc-erro.patch
    (git-fixes CVE-2025-38389 bsc#1247153).
  - Update
    patches.suse/drm-msm-Fix-a-fence-leak-in-submit-error-path.patch
    (stable-fixes CVE-2025-38410 bsc#1247128).
  - Update
    patches.suse/drm-msm-Fix-another-leak-in-the-submit-error-path.patch
    (stable-fixes CVE-2025-38409 bsc#1247285).
  - Update
    patches.suse/drm-msm-a7xx-Call-CP_RESET_CONTEXT_STATE.patch
    (git-fixes CVE-2025-38188 bsc#1246098).
  - Update
    patches.suse/drm-msm-gpu-Fix-crash-when-throttling-GPU-immediatel.patch
    (git-fixes CVE-2025-38354 bsc#1247061).
  - Update
    patches.suse/drm-scheduler-signal-scheduled-fence-when-kill-job.patch
    (stable-fixes CVE-2025-38436 bsc#1247227).
  - Update
    patches.suse/drm-tegra-Fix-a-possible-null-pointer-dereference.patch
    (git-fixes CVE-2025-38363 bsc#1247018).
  - Update
    patches.suse/drm-v3d-Avoid-NULL-pointer-dereference-in-v3d_job_up.patch
    (stable-fixes CVE-2025-38189 bsc#1245812).
  - Update
    patches.suse/drm-v3d-Disable-interrupts-before-resetting-the-GPU.patch
    (git-fixes CVE-2025-38371 bsc#1247178).
  - Update
    patches.suse/drm-xe-Fix-taking-invalid-lock-on-wedge.patch
    (stable-fixes CVE-2025-38353 bsc#1247265).
  - Update
    patches.suse/drm-xe-Process-deferred-GGTT-node-removals-on-device.patch
    (git-fixes CVE-2025-38355 bsc#1247062).
  - Update
    patches.suse/drm-xe-guc-Explicitly-exit-CT-safe-mode-on-unwind.patch
    (git-fixes CVE-2025-38356 bsc#1247064).
  - Update
    patches.suse/e1000-Move-cancel_work_sync-to-avoid-deadlock.patch
    (git-fixes CVE-2025-38114 bsc#1245686).
  - Update
    patches.suse/erofs-avoid-using-multiple-devices-with-different-type.patch
    (git-fixes CVE-2025-38172 bsc#1245787).
  - Update
    patches.suse/fbcon-Make-sure-modelist-not-set-on-unregistered-con.patch
    (stable-fixes CVE-2025-38198 bsc#1245952).
  - Update
    patches.suse/fbdev-Fix-do_register_framebuffer-to-prevent-null-pt.patch
    (git-fixes CVE-2025-38215 bsc#1246109).
  - Update
    patches.suse/fbdev-Fix-fb_set_var-to-prevent-null-ptr-deref-in-fb.patch
    (git-fixes CVE-2025-38214 bsc#1246042).
  - Update
    patches.suse/fbdev-core-fbcvt-avoid-division-by-0-in-fb_cvt_hperi.patch
    (git-fixes CVE-2025-38312 bsc#1246386).
  - Update
    patches.suse/firmware-arm_ffa-Fix-memory-leak-by-freeing-notifier.patch
    (git-fixes CVE-2025-38390 bsc#1247088).
  - Update
    patches.suse/fpga-fix-potential-null-pointer-deref-in-fpga_mgr_te.patch
    (git-fixes CVE-2025-38274 bsc#1246234).
  - Update
    patches.suse/fs-nfs-read-fix-double-unlock-bug-in-nfs_return_empty_folio.patch
    (git-fixes CVE-2025-38338 bsc#1246258).
  - Update
    patches.suse/gve-add-missing-NULL-check-for-gve_alloc_pending_pac.patch
    (git-fixes CVE-2025-38122 bsc#1245746).
  - Update
    patches.suse/hwmon-asus-ec-sensors-check-sensor-index-in-read_str.patch
    (git-fixes CVE-2025-38142 bsc#1245713).
  - Update
    patches.suse/hwmon-ftsteutates-Fix-TOCTOU-race-in-fts_read.patch
    (git-fixes CVE-2025-38217 bsc#1246002).
  - Update
    patches.suse/i2c-designware-Fix-an-initialization-issue.patch
    (git-fixes CVE-2025-38380 bsc#1247028).
  - Update
    patches.suse/i2c-tegra-check-msg-length-in-SMBUS-block-read.patch
    (bsc#1242086 CVE-2025-38425 bsc#1247251).
  - Update
    patches.suse/ice-fix-Tx-scheduler-error-handling-in-XDP-callback.patch
    (git-fixes CVE-2025-38127 bsc#1245705).
  - Update
    patches.suse/ice-fix-eswitch-code-memory-leak-in-reset-scenario.patch
    (git-fixes CVE-2025-38417 bsc#1247282).
  - Update
    patches.suse/iio-accel-fxls8962af-Fix-use-after-free-in-fxls8962a.patch
    (git-fixes CVE-2025-38485 bsc#1247236).
  - Update patches.suse/iio-backend-fix-out-of-bound-write.patch
    (git-fixes CVE-2025-38484 bsc#1247235).
  - Update
    patches.suse/maple_tree-fix-MA_STATE_PREALLOC-flag-in-mas_preallo.patch
    (git-fixes CVE-2025-38364 bsc#1247091).
  - Update
    patches.suse/media-cxusb-no-longer-judge-rbuf-when-the-write-fail.patch
    (git-fixes CVE-2025-38229 bsc#1246049).
  - Update
    patches.suse/media-imagination-fix-a-potential-memory-leak-in-e50.patch
    (git-fixes CVE-2025-38228 bsc#1245814).
  - Update
    patches.suse/media-imx-jpeg-Cleanup-after-an-allocation-error.patch
    (git-fixes CVE-2025-38225 bsc#1246041).
  - Update
    patches.suse/media-vidtv-Terminating-the-subsequent-process-of-in.patch
    (git-fixes CVE-2025-38227 bsc#1246031).
  - Update
    patches.suse/media-vivid-Change-the-siize-of-the-composing.patch
    (git-fixes CVE-2025-38226 bsc#1246050).
  - Update
    patches.suse/misc-tps6594-pfsm-Add-NULL-pointer-check-in-tps6594_.patch
    (stable-fixes CVE-2025-38368 bsc#1247022).
  - Update
    patches.suse/mtd-nand-ecc-mxic-Fix-use-of-uninitialized-variable-.patch
    (git-fixes CVE-2025-38277 bsc#1246246).
  - Update
    patches.suse/mtd-spinand-fix-memory-leak-of-ECC-engine-conf.patch
    (stable-fixes CVE-2025-38384 bsc#1247035).
  - Update
    patches.suse/mtk-sd-Prevent-memory-corruption-from-DMA-map-failur.patch
    (git-fixes CVE-2025-38401 bsc#1247125).
  - Update
    patches.suse/nbd-fix-uaf-in-nbd_genl_connect-error-path.patch
    (git-fixes CVE-2025-38443 bsc#1247164).
  - Update patches.suse/net-Fix-TOCTOU-issue-in-sk_is_readable.patch
    (git-fixes CVE-2025-38112 bsc#1245668).
  - Update
    patches.suse/net-fix-udp-gso-skb_segment-after-pull-from-frag_lis.patch
    (git-fixes CVE-2025-38124 bsc#1245690).
  - Update
    patches.suse/net-mdiobus-Fix-potential-out-of-bounds-clause-45-re.patch
    (git-fixes CVE-2025-38110 bsc#1245665).
  - Update
    patches.suse/net-mdiobus-Fix-potential-out-of-bounds-read-write-a.patch
    (git-fixes CVE-2025-38111 bsc#1245666).
  - Update
    patches.suse/net-mlx5-Fix-ECVF-vports-unload-on-shutdown-flow.patch
    (git-fixes CVE-2025-38109 bsc#1245684).
  - Update
    patches.suse/net-phy-clear-phydev-devlink-when-the-link-is-delete.patch
    (git-fixes CVE-2025-38149 bsc#1245737).
  - Update
    patches.suse/net-phy-mscc-Fix-memory-leak-when-using-one-step-tim.patch
    (git-fixes CVE-2025-38148 bsc#1245735).
  - Update
    patches.suse/net-sched-Return-NULL-when-htb_lookup_leaf-encounter.patch
    (git-fixes CVE-2025-38468 bsc#1247437).
  - Update
    patches.suse/net-sched-fix-use-after-free-in-taprio_dev_notifier.patch
    (git-fixes CVE-2025-38087 bsc#1245504).
  - Update
    patches.suse/net-sched-sch_qfq-Fix-race-condition-on-qfq_aggregat.patch
    (git-fixes CVE-2025-38477 bsc#1247314).
  - Update
    patches.suse/net-tipc-fix-refcount-warning-in-tipc_aead_encrypt.patch
    (CVE-2025-38052 bsc#1244749 CVE-2025-38273 bsc#1246266).
  - Update
    patches.suse/net-usb-aqc111-fix-error-handling-of-usbnet-read-cal.patch
    (git-fixes CVE-2025-38153 bsc#1245744).
  - Update
    patches.suse/net-usb-lan78xx-fix-WARN-in-__netif_napi_del_locked-.patch
    (git-fixes CVE-2025-38385 bsc#1247149).
  - Update patches.suse/net-wwan-t7xx-Fix-napi-rx-poll-issue.patch
    (git-fixes CVE-2025-38123 bsc#1245688).
  - Update
    patches.suse/net_sched-ets-fix-a-race-in-ets_qdisc_change.patch
    (git-fixes CVE-2025-38107 bsc#1245676).
  - Update
    patches.suse/net_sched-red-fix-a-race-in-__red_change.patch
    (git-fixes CVE-2025-38108 bsc#1245675).
  - Update
    patches.suse/net_sched-sch_sfq-reject-invalid-perturb-period.patch
    (git-fixes CVE-2025-38193 bsc#1245945).
  - Update
    patches.suse/netfilter-nf_set_pipapo_avx2-fix-initial-map-fill.patch
    (git-fixes CVE-2025-38120 bsc#1245711).
  - Update
    patches.suse/nfs-Clean-up-proc-net-rpc-nfs-when-nfs_fs_proc_net_init-fails.patch
    (git-fixes CVE-2025-38400 bsc#1247123).
  - Update
    patches.suse/nfsd-Initialize-ssc-before-laundromat_work-to-prevent-NULL-dereference.patch
    (git-fixes CVE-2025-38231 bsc#1246055).
  - Update
    patches.suse/nfsd-nfsd4_spo_must_allow-must-check-this-is-a-v4-compound-request.patch
    (git-fixes CVE-2025-38430 bsc#1247160).
  - Update
    patches.suse/nvme-multipath-fix-suspicious-RCU-usage-warning.patch
    (git-fixes CVE-2025-38397 bsc#1247163).
  - Update
    patches.suse/nvme-tcp-remove-tag-set-when-second-admin-queue-conf.patch
    (git-fixes CVE-2025-38209 bsc#1246022).
  - Update patches.suse/nvmet-fix-memory-leak-of-bio-integrity.patch
    (git-fixes CVE-2025-38405 bsc#1247270).
  - Update
    patches.suse/octeontx2-pf-QOS-Refactor-TC_HTB_LEAF_DEL_LAST-callb.patch
    (git-fixes CVE-2025-38278 bsc#1246255).
  - Update
    patches.suse/page_pool-Fix-use-after-free-in-page_pool_recycle_in.patch
    (git-fixes CVE-2025-38129 bsc#1245723).
  - Update patches.suse/perf-Fix-sample-vs-do_exit.patch
    (bsc#1246547 CVE-2025-38424 bsc#1247293).
  - Update
    patches.suse/perf-Revert-to-requiring-CAP_SYS_ADMIN-for-uprobes.patch
    (git-fixes CVE-2025-38466 bsc#1247442).
  - Update
    patches.suse/phy-qcom-qmp-usb-Fix-an-NULL-vs-IS_ERR-bug.patch
    (git-fixes CVE-2025-38275 bsc#1246236).
  - Update
    patches.suse/pinctrl-at91-Fix-possible-out-of-boundary-access.patch
    (git-fixes CVE-2025-38286 bsc#1246283).
  - Update
    patches.suse/platform-x86-amd-pmf-Use-device-managed-allocations.patch
    (git-fixes CVE-2025-38421 bsc#1247130).
  - Update
    patches.suse/platform-x86-dell-wmi-sysman-Fix-WMI-data-block-retr.patch
    (git-fixes CVE-2025-38412 bsc#1247132).
  - Update patches.suse/platform-x86-dell_rbu-Fix-list-usage.patch
    (git-fixes CVE-2025-38197 bsc#1246047).
  - Update
    patches.suse/powerpc-bpf-fix-JIT-code-size-calculation-of-bpf-tra.patch
    (jsc#PED-10909 git-fixes CVE-2025-38339 bsc#1246259).
  - Update
    patches.suse/powerpc-powernv-memtrace-Fix-out-of-bounds-issue-in-.patch
    (bsc#1244309 ltc#213790 CVE-2025-38088 bsc#1245506).
  - Update
    patches.suse/powerpc64-ftrace-fix-clobbered-r15-during-livepatchi.patch
    (jsc#PED-10909 git-fixes CVE-2025-38233 bsc#1246053).
  - Update
    patches.suse/ptp-remove-ptp-n_vclocks-check-logic-in-ptp_vclock_i.patch
    (git-fixes CVE-2025-38305 bsc#1246358).
  - Update
    patches.suse/regulator-gpio-Fix-the-out-of-bounds-access-to-drvda.patch
    (git-fixes CVE-2025-38395 bsc#1247171).
  - Update
    patches.suse/rose-fix-dangling-neighbour-pointers-in-rose_rt_devi.patch
    (git-fixes CVE-2025-38377 bsc#1247174).
  - Update
    patches.suse/rpl-Fix-use-after-free-in-rpl_do_srh_inline.patch
    (git-fixes CVE-2025-38476 bsc#1247317).
  - Update
    patches.suse/s390-bpf-Fix-bpf_arch_text_poke-with-new_addr-NULL-again.patch
    (git-fixes bsc#1246868 CVE-2025-38489 bsc#1247241).
  - Update
    patches.suse/s390-pkey-Prevent-overflow-in-size-calculation-for-memdup_.patch
    (git-fixes bsc#1245596 CVE-2025-38257 bsc#1246186).
  - Update
    patches.suse/sch_hfsc-make-hfsc_qlen_notify-idempotent.patch
    (CVE-2025-37798 bsc#1242414 CVE-2025-38177 bsc#1245986).
  - Update patches.suse/sched-rt-Fix-race-in-push_rt_task.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2025-38234 bsc#1246057).
  - Update
    patches.suse/scsi-lpfc-Avoid-potential-ndlp-use-after-free-in-dev.patch
    (bsc#1242995 CVE-2025-38289 bsc#1246287).
  - Update patches.suse/scsi-lpfc-Use-memcpy-for-BIOS-version.patch
    (bsc#1240966 CVE-2025-38332 bsc#1246375).
  - Update
    patches.suse/scsi-smartpqi-Fix-smp_processor_id-call-trace-for-preempti.patch
    (git-fixes CVE-2025-38288 bsc#1246286).
  - Update
    patches.suse/serial-Fix-potential-null-ptr-deref-in-mlb_usio_prob.patch
    (git-fixes CVE-2025-38135 bsc#1246023).
  - Update
    patches.suse/serial-jsm-fix-NPE-during-jsm_uart_port_init.patch
    (git-fixes CVE-2025-38265 bsc#1246244).
  - Update
    patches.suse/soc-aspeed-Add-NULL-check-in-aspeed_lpc_enable_snoop.patch
    (git-fixes CVE-2025-38145 bsc#1245765).
  - Update
    patches.suse/soc-aspeed-lpc-snoop-Don-t-disable-channels-that-are.patch
    (git-fixes CVE-2025-38487 bsc#1247238).
  - Update
    patches.suse/software-node-Correct-a-OOB-check-in-software_node_g.patch
    (stable-fixes CVE-2025-38342 bsc#1246453).
  - Update
    patches.suse/sunrpc-handle-SVC_GARBAGE-during-svc-auth-processing-as-auth-error.patch
    (git-fixes CVE-2025-38089 bsc#1245508).
  - Update
    patches.suse/thunderbolt-Do-not-double-dequeue-a-configuration-re.patch
    (stable-fixes CVE-2025-38174 bsc#1245781).
  - Update
    patches.suse/usb-acpi-Prevent-null-pointer-dereference-in-usb_acp.patch
    (git-fixes CVE-2025-38134 bsc#1245678).
  - Update
    patches.suse/usb-chipidea-udc-disconnect-reconnect-from-host-when.patch
    (git-fixes CVE-2025-38376 bsc#1247176).
  - Update
    patches.suse/usb-gadget-u_serial-Fix-race-condition-in-TTY-wakeup.patch
    (git-fixes CVE-2025-38448 bsc#1247233).
  - Update
    patches.suse/usb-net-sierra-check-for-no-status-endpoint.patch
    (git-fixes CVE-2025-38474 bsc#1247311).
  - Update
    patches.suse/usb-renesas_usbhs-Reorder-clock-handling-and-power-m.patch
    (git-fixes CVE-2025-38136 bsc#1245691).
  - Update
    patches.suse/usb-typec-altmodes-displayport-do-not-index-invalid-.patch
    (git-fixes CVE-2025-38391 bsc#1247181).
  - Update
    patches.suse/usb-typec-displayport-Fix-potential-deadlock.patch
    (git-fixes CVE-2025-38404 bsc#1247271).
  - Update
    patches.suse/usb-typec-tcpm-move-tcpm_queue_vdm_unlocked-to-async.patch
    (git-fixes CVE-2025-38268 bsc#1246385).
  - Update
    patches.suse/vgacon-Add-check-for-vc_origin-address-range-in-vgac.patch
    (git-fixes CVE-2025-38213 bsc#1246037).
  - Update
    patches.suse/video-screen_info-Update-framebuffers-behind-PCI-bri.patch
    (bsc#1240696 CVE-2025-38427 bsc#1247152).
  - Update
    patches.suse/virtio-net-ensure-the-received-length-does-not-excee.patch
    (git-fixes CVE-2025-38375 bsc#1247177).
  - Update
    patches.suse/virtio-net-xsk-rx-fix-the-frame-s-length-check.patch
    (git-fixes CVE-2025-38413 bsc#1247131).
  - Update patches.suse/vsock-Fix-transport_-TOCTOU.patch (git-fixes
    CVE-2025-38461 bsc#1247103).
  - Update patches.suse/vsock-Fix-transport_-g2h-h2g-TOCTOU.patch
    (git-fixes CVE-2025-38462 bsc#1247104).
  - Update
    patches.suse/vsock-vmci-Clear-the-vmci-transport-packet-properly-.patch
    (git-fixes CVE-2025-38403 bsc#1247141).
  - Update
    patches.suse/wifi-ath11k-fix-node-corruption-in-ar-arvifs-list.patch
    (git-fixes CVE-2025-38293 bsc#1246292).
  - Update
    patches.suse/wifi-ath12k-Fix-buffer-overflow-in-debugfs.patch
    (git-fixes CVE-2025-38317 bsc#1246443).
  - Update
    patches.suse/wifi-ath12k-Prevent-sending-WMI-commands-to-firmware.patch
    (bsc#1240998 CVE-2025-38291 bsc#1246297).
  - Update
    patches.suse/wifi-ath12k-fix-GCC_GCC_PCIE_HOT_RST-definition-for-.patch
    (git-fixes CVE-2025-38414 bsc#1247145).
  - Update
    patches.suse/wifi-ath12k-fix-invalid-access-to-memory.patch
    (git-fixes CVE-2025-38292 bsc#1246295).
  - Update
    patches.suse/wifi-ath12k-fix-node-corruption-in-ar-arvifs-list.patch
    (git-fixes CVE-2025-38290 bsc#1246293).
  - Update
    patches.suse/wifi-ath6kl-remove-WARN-on-bad-firmware-input.patch
    (stable-fixes CVE-2025-38406 bsc#1247210).
  - Update
    patches.suse/wifi-ath9k_htc-Abort-software-beacon-handling-if-dis.patch
    (git-fixes CVE-2025-38157 bsc#1245747).
  - Update
    patches.suse/wifi-carl9170-do-not-ping-device-which-has-failed-to.patch
    (git-fixes CVE-2025-38420 bsc#1247279).
  - Update
    patches.suse/wifi-iwlwifi-don-t-warn-when-if-there-is-a-FW-error.patch
    (stable-fixes CVE-2025-38096 bsc#1245657).
  - Update
    patches.suse/wifi-mt76-mt7915-Fix-null-ptr-deref-in-mt7915_mmio_w.patch
    (git-fixes CVE-2025-38155 bsc#1245748).
  - Update
    patches.suse/wifi-mt76-mt7925-prevent-NULL-pointer-dereference-in.patch
    (git-fixes CVE-2025-38450 bsc#1247376).
  - Update
    patches.suse/wifi-mt76-mt7996-Fix-null-ptr-deref-in-mt7996_mmio_w.patch
    (git-fixes CVE-2025-38156 bsc#1246034).
  - Update
    patches.suse/wifi-mt76-mt7996-drop-fragments-with-multicast-or-br.patch
    (stable-fixes CVE-2025-38343 bsc#1246438).
  - Update
    patches.suse/wifi-p54-prevent-buffer-overflow-in-p54_rx_eeprom_re.patch
    (git-fixes CVE-2025-38348 bsc#1246262).
  - Update
    patches.suse/wifi-rtw88-fix-the-para-buffer-size-to-avoid-reading.patch
    (git-fixes CVE-2025-38159 bsc#1245751).
  - commit 8064d69
  - ipv6: annotate data-races around rt->fib6_nsiblings (git-fixes).
  - commit 4b09993
  - ipv6: fix possible infinite loop in fib6_info_uses_dev()
    (git-fixes).
  - commit b0133f0
  - ipv6: prevent infinite loop in rt6_nlmsg_size() (git-fixes).
  - commit a1d8794
  - net/sched: Restrict conditions for adding duplicating netems
    to qdisc tree (git-fixes).
  - commit 21bb04b
  - spi: cs42l43: Property entry should be a null-terminated array
    (bsc#1246979).
  - commit 2043cd1
  - Move upstreamed sched, SCSI and ACPI patches into sorted section
  - commit 836e139
  - selftests/bpf: Fix selection of static vs. dynamic LLVM
    Bring git fixes for commit
    4ed92da84b67 ("selftests/bpf: Support dynamically linking LLVM if static is not available")
  - commit 7a43a26
  - media: venus: vdec: Clamp param smaller than 1fps and bigger
    than 240 (git-fixes).
  - commit 1e731e7
  - maple_tree: fix status setup on restore to active (git-fixes).
  - mtd: rawnand: atmel: set pmecc data setup time (git-fixes).
  - mtd: spinand: propagate spinand_wait() errors from
    spinand_write_page() (git-fixes).
  - mtd: rawnand: fsmc: Add missing check after DMA map (git-fixes).
  - mtd: rawnand: rockchip: Add missing check after DMA map
    (git-fixes).
  - mtd: rawnand: atmel: Fix dma_mapping_error() address
    (git-fixes).
  - mtd: rawnand: renesas: Add missing check after DMA map
    (git-fixes).
  - mtd: spi-nor: Fix spi_nor_try_unlock_all() (git-fixes).
  - mtd: spi-nor: spansion: Fixup params->set_4byte_addr_mode for
    SEMPER (git-fixes).
  - mtd: fix possible integer overflow in erase_xfer() (git-fixes).
  - clk: qcom: gcc-ipq8074: fix broken freq table for
    nss_port6_tx_clk_src (git-fixes).
  - clk: imx95-blk-ctl: Fix synchronous abort (git-fixes).
  - clk: at91: sam9x7: update pll clk ranges (git-fixes).
  - clk: thead: th1520-ap: Correctly refer the parent of osc_12m
    (git-fixes).
  - clk: sunxi-ng: v3s: Fix de clock definition (git-fixes).
  - clk: samsung: exynos850: fix a comment (git-fixes).
  - clk: samsung: gs101: fix alternate mout_hsi0_usb20_ref parent
    clock (git-fixes).
  - clk: samsung: gs101: fix CLK_DOUT_CMU_G3D_BUSD (git-fixes).
  - clk: renesas: rzv2h: Fix missing CLK_SET_RATE_PARENT flag for
    ddiv clocks (git-fixes).
  - clk: clk-axi-clkgen: fix fpfd_max frequency for zynq
    (git-fixes).
  - clk: xilinx: vcu: unregister pll_post only if registered
    correctly (git-fixes).
  - clk: davinci: Add NULL check in davinci_lpsc_clk_register()
    (git-fixes).
  - hwmon: (gsc-hwmon) fix fan pwm setpoint show functions
    (git-fixes).
  - pwm: imx-tpm: Reset counter if CMOD is 0 (git-fixes).
  - media: v4l2: Add support for NV12M tiled variants to
    v4l2_format_info() (git-fixes).
  - media: uvcvideo: Do not mark valid metadata as invalid
    (git-fixes).
  - media: ov2659: Fix memory leaks in ov2659_probe() (git-fixes).
  - media: ti: j721e-csi2rx: fix list_del corruption (git-fixes).
  - media: hi556: correct the test pattern configuration
    (git-fixes).
  - media: ipu6: isys: Use correct pads for xlate_streams()
    (git-fixes).
  - media: vivid: fix wrong pixel_array control size (git-fixes).
  - media: qcom: camss: cleanup media device allocated resource
    on error path (git-fixes).
  - media: venus: Fix MSM8998 frequency table (git-fixes).
  - media: venus: hfi: explicitly release IRQ during teardown
    (git-fixes).
  - media: venus: Fix OOB read due to missing payload bound check
    (git-fixes).
  - media: venus: Add a check for packet size after reading from
    shared memory (git-fixes).
  - media: venus: protect against spurious interrupts during probe
    (git-fixes).
  - media: venus: venc: Clamp param smaller than 1fps and bigger
    than 240 (git-fixes).
  - media: pisp_be: Fix pm_runtime underrun in probe (git-fixes).
  - media: ivsc: Fix crash at shutdown due to missing
    mei_cldev_disable() calls (git-fixes).
  - media: v4l2-ctrls: Don't reset handler's error in
    v4l2_ctrl_handler_free() (git-fixes).
  - media: mt9m114: Fix deadlock in
    get_frame_interval/set_frame_interval (git-fixes).
  - media: v4l2-ctrls: Fix H264 SEPARATE_COLOUR_PLANE check
    (git-fixes).
  - media: imx: fix a potential memory leak in
    imx_media_csc_scaler_device_init() (git-fixes).
  - media: verisilicon: Fix AV1 decoder clock frequency (git-fixes).
  - media: rainshadow-cec: fix TOCTOU race condition in
    rain_interrupt() (git-fixes).
  - media: gspca: Add bounds checking to firmware parser
    (git-fixes).
  - media: usbtv: Lock resolution while streaming (git-fixes).
  - media: uvcvideo: Fix 1-byte out-of-bounds read in
    uvc_parse_format() (git-fixes).
  - Revert "leds: trigger: netdev: Configure LED blink interval
    for HW offload" (git-fixes).
  - leds: flash: leds-qcom-flash: Fix registry access after re-bind
    (git-fixes).
  - mfd: cros_ec: Separate charge-control probing from USB-PD
    (git-fixes).
  - crypto: qat - fix seq_file position update in adf_ring_next()
    (git-fixes).
  - crypto: qat - fix DMA direction for compression on GEN2 devices
    (git-fixes).
  - crypto: qat - flush misc workqueue during device shutdown
    (git-fixes).
  - crypto: qat - disable ZUC-256 capability for QAT GEN5
    (git-fixes).
  - crypto: img-hash - Fix dma_unmap_sg() nents value (git-fixes).
  - crypto: keembay - Fix dma_unmap_sg() nents value (git-fixes).
  - hwrng: mtk - handle devm_pm_runtime_enable errors (git-fixes).
  - crypto: ccp - Fix crash when rebind ccp device for ccp.ko
    (git-fixes).
  - crypto: inside-secure - Fix `dma_unmap_sg()` nents value
    (git-fixes).
  - crypto: ccp - Fix locking on alloc failure handling (git-fixes).
  - crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP
    (git-fixes).
  - crypto: arm/aes-neonbs - work around gcc-15 warning (git-fixes).
  - crypto: qat - fix state restore for banks with exceptions
    (git-fixes).
  - crypto: qat - allow enabling VFs in the absence of IOMMU
    (git-fixes).
  - crypto: marvell/cesa - Fix engine load inaccuracy (git-fixes).
  - crypto: qat - use unmanaged allocation for dc_data (git-fixes).
  - crypto: sun8i-ce - fix nents passed to dma_unmap_sg()
    (git-fixes).
  - commit ae512ba
  - RDMA/uverbs: Add empty rdma_uattrs_has_raw_cap() declaration (git-fixes)
  - commit e78882a
  - x86/rdrand: Disable RDSEED on AMD Cyan Skillfish (git-fixes).
  - commit 3ccca36
  - x86/cacheinfo: Properly parse CPUID(0x80000006) L2/L3 associativity (git-fixes).
  - commit a5b12b1
  - RDMA/mlx5: Fix compilation warning when USER_ACCESS isn't set (git-fixes)
  - commit 5241bbd
  - x86/cacheinfo: Properly parse CPUID(0x80000005) L1d/L1i associativity (git-fixes).
  - commit 530f80b
  - x86/cpu: Sanitize CPUID(0x80000000) output (git-fixes).
  - commit 8c1593e
  - RDMA/hns: Fix -Wframe-larger-than issue (git-fixes)
  - commit 160aaf0
  - RDMA/hns: Drop GFP_NOWARN (git-fixes)
  - commit 3983b2d
  - RDMA/hns: Fix accessing uninitialized resources (git-fixes)
  - commit 020f808
  - RDMA/hns: Get message length of ack_req from FW (git-fixes)
  - commit ed23840
  - RDMA/hns: Fix HW configurations not cleared in error flow (git-fixes)
  - commit 17d9c9c
  - RDMA/hns: Fix double destruction of rsv_qp (git-fixes)
  - commit 127df58
  - Fix dma_unmap_sg() nents value (git-fixes)
  - commit 72c9bb9
  - RDMA/counter: Check CAP_NET_RAW check in user namespace for RDMA counters (git-fixes)
  - commit e32f637
  - RDMA/nldev: Check CAP_NET_RAW in user namespace for QP modify (git-fixes)
  - commit 066fc2e
  - RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (git-fixes)
  - commit 876344b
  - RDMA/uverbs: Check CAP_NET_RAW in user namespace for RAW QP create (git-fixes)
  - commit 84b0982
  - RDMA/uverbs: Check CAP_NET_RAW in user namespace for QP create (git-fixes)
  - commit 5d5e159
  - RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (git-fixes)
  - commit 1d83d68
  - RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (git-fixes)
  - commit 880cd69
  - RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (git-fixes)
  - commit 1e737a4

++++ kernel-rt:

  - iommu/arm-smmu-qcom: Add SM6115 MDSS compatible (git-fixes).
  - commit 86d87fb
  - iommu/amd: Fix geometry.aperture_end for V2 tables (git-fixes).
  - commit 9fabb61
  - cgroup: Add compatibility option for content of /proc/cgroups
    (jsc#PED-12405).
  - cgroup: Print message when /proc/cgroups is read on v2-only
    system (jsc#PED-12405).
  - commit 764f23b
  - Update
    patches.suse/ACPI-CPPC-Fix-NULL-pointer-dereference-when-nosmp-is.patch
    (git-fixes CVE-2025-38113 bsc#1245683).
  - Update
    patches.suse/ACPICA-Refuse-to-evaluate-a-method-if-arguments-are-.patch
    (stable-fixes CVE-2025-38386 bsc#1247138).
  - Update
    patches.suse/ACPICA-fix-acpi-operand-cache-leak-in-dswstate.c.patch
    (stable-fixes CVE-2025-38345 bsc#1246337).
  - Update
    patches.suse/ACPICA-fix-acpi-parse-and-parseext-cache-leaks.patch
    (stable-fixes CVE-2025-38344 bsc#1246334).
  - Update
    patches.suse/ALSA-ad1816a-Fix-potential-NULL-pointer-deref-in-snd.patch
    (git-fixes CVE-2025-38454 bsc#1247426).
  - Update
    patches.suse/ALSA-usb-audio-Fix-out-of-bounds-read-in-snd_usb_get.patch
    (git-fixes CVE-2025-38249 bsc#1246171).
  - Update
    patches.suse/ASoC-Intel-avs-Verify-content-returned-by-parse_int_.patch
    (git-fixes CVE-2025-38307 bsc#1246364).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-Use-devm_kstrdup-to-avoid-memleak.patch
    (stable-fixes CVE-2025-38438 bsc#1247157).
  - Update
    patches.suse/ASoC-codecs-wcd9335-Fix-missing-free-of-regulator-su.patch
    (git-fixes CVE-2025-38259 bsc#1246220).
  - Update
    patches.suse/ASoC-mediatek-mt8195-Set-ETDM1-2-IN-OUT-to-COMP_DUMM.patch
    (git-fixes CVE-2025-38299 bsc#1246290).
  - Update
    patches.suse/Bluetooth-Disable-SCO-support-if-READ_VOICE_SETTING-.patch
    (stable-fixes CVE-2025-38099 bsc#1245671).
  - Update
    patches.suse/Bluetooth-Fix-NULL-pointer-deference-on-eir_get_serv.patch
    (git-fixes CVE-2025-38304 bsc#1246240).
  - Update
    patches.suse/Bluetooth-Fix-null-ptr-deref-in-l2cap_sock_resume_cb.patch
    (git-fixes CVE-2025-38473 bsc#1247289).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-UAF-on-mgmt_remove_adv_monitor_co.patch
    (git-fixes CVE-2025-38118 bsc#1245670).
  - Update
    patches.suse/Bluetooth-MGMT-reject-malformed-HCI_CMD_SYNC-command.patch
    (git-fixes CVE-2025-38128 bsc#1245703).
  - Update
    patches.suse/Bluetooth-btintel-Check-dsbr-size-from-EFI-variable.patch
    (git-fixes CVE-2025-38315 bsc#1246333).
  - Update
    patches.suse/Bluetooth-eir-Fix-possible-crashes-on-eir_create_adv.patch
    (git-fixes CVE-2025-38303 bsc#1246354).
  - Update
    patches.suse/HID-core-do-not-bypass-hid_hw_raw_request.patch
    (stable-fixes CVE-2025-38494 bsc#1247349).
  - Update
    patches.suse/HID-core-ensure-the-allocated-report-buffer-can-cont.patch
    (stable-fixes CVE-2025-38495 bsc#1247348).
  - Update
    patches.suse/HID-wacom-fix-crash-in-wacom_aes_battery_handler.patch
    (git-fixes CVE-2025-38253 bsc#1246192).
  - Update
    patches.suse/IB-cm-Drop-lockdep-assert-and-WARN-when-freeing-old-.patch
    (git-fixes CVE-2025-38287 bsc#1246285).
  - Update
    patches.suse/IB-mlx5-Fix-potential-deadlock-in-MR-deregistration.patch
    (git-fixes CVE-2025-38373 bsc#1247033).
  - Update
    patches.suse/Input-cs40l50-vibra-fix-potential-NULL-dereference-i.patch
    (git-fixes CVE-2025-38381 bsc#1247027).
  - Update
    patches.suse/Input-gpio-keys-fix-a-sleep-while-atomic-with-PREEMP.patch
    (git-fixes CVE-2025-38335 bsc#1246250).
  - Update
    patches.suse/Input-ims-pcu-check-record-size-in-ims_pcu_flash_fir.patch
    (git-fixes CVE-2025-38428 bsc#1247150).
  - Update
    patches.suse/KVM-SVM-Reject-SEV-ES-intra-host-migration-if-vCPU-c.patch
    (git-fixes CVE-2025-38455 bsc#1247101).
  - Update
    patches.suse/NFC-nci-uart-Set-tty-disc_data-only-in-success-path.patch
    (git-fixes CVE-2025-38416 bsc#1247151).
  - Update
    patches.suse/NFSD-fix-race-between-nfsd-registration-and-exports_proc.patch
    (git-fixes CVE-2025-38232 bsc#1246054).
  - Update
    patches.suse/NFSv4-pNFS-Fix-a-race-to-wake-on-NFS_LAYOUT_DRAIN.patch
    (git-fixes CVE-2025-38393 bsc#1247170).
  - Update
    patches.suse/PCI-pwrctrl-Cancel-outstanding-rescan-work-when-unre.patch
    (git-fixes CVE-2025-38137 bsc#1245721).
  - Update
    patches.suse/RDMA-cma-Fix-hang-when-cma_netevent_callback-fails-t.patch
    (git-fixes CVE-2025-38151 bsc#1245745).
  - Update
    patches.suse/RDMA-iwcm-Fix-use-after-free-of-work-objects-after-c.patch
    (git-fixes CVE-2025-38211 bsc#1246008).
  - Update
    patches.suse/RDMA-mlx5-Fix-error-flow-upon-firmware-failure-for-R.patch
    (git-fixes CVE-2025-38161 bsc#1245777).
  - Update
    patches.suse/RDMA-mlx5-Fix-unsafe-xarray-access-in-implicit-ODP-h.patch
    (git-fixes CVE-2025-38372 bsc#1247020).
  - Update
    patches.suse/RDMA-mlx5-Initialize-obj_event-obj_sub_list-before-x.patch
    (git-fixes CVE-2025-38387 bsc#1247154).
  - Update
    patches.suse/Squashfs-check-return-result-of-sb_min_blocksize.patch
    (git-fixes CVE-2025-38415 bsc#1247147).
  - Update
    patches.suse/VMCI-fix-race-between-vmci_host_setup_notify-and-vmc.patch
    (git-fixes CVE-2025-38102 bsc#1245669).
  - Update
    patches.suse/aoe-clean-device-rq_list-in-aoedev_downdev.patch
    (git-fixes CVE-2025-38326 bsc#1246490).
  - Update
    patches.suse/arm64-fpsimd-Avoid-clobbering-kernel-FPSIMD-state-with-SMS.patch
    (git-fixes CVE-2025-38169 bsc#1245784).
  - Update
    patches.suse/arm64-fpsimd-Discard-stale-CPU-state-when-handling-SME-tra.patch
    (git-fixes CVE-2025-38170 bsc#1245785).
  - Update
    patches.suse/ata-pata_via-Force-PIO-for-ATAPI-devices-on-VT6415-V.patch
    (stable-fixes CVE-2025-38336 bsc#1246370).
  - Update
    patches.suse/backlight-pm8941-Add-NULL-check-in-wled_configure.patch
    (git-fixes CVE-2025-38143 bsc#1245714).
  - Update
    patches.suse/block-don-t-use-submit_bio_noacct_nocheck-in-blk_zone_wplu.patch
    (git-fixes CVE-2025-38302 bsc#1246353).
  - Update patches.suse/bnxt-properly-flush-XDP-redirect-lists.patch
    (git-fixes CVE-2025-38246 bsc#1246195).
  - Update
    patches.suse/bnxt_en-Fix-double-invocation-of-bnxt_ulp_stop-bnxt_.patch
    (git-fixes CVE-2025-38186 bsc#1245955).
  - Update
    patches.suse/bpf-sockmap-Fix-panic-when-calling-skb_linearize.patch
    (bsc#1245749 CVE-2025-38154 CVE-2025-38165 bsc#1245757).
  - Update patches.suse/bus-fsl-mc-fix-double-free-on-mc_dev.patch
    (git-fixes CVE-2025-38313 bsc#1246342).
  - Update
    patches.suse/bus-mhi-ep-Update-read-pointer-only-after-buffer-is-.patch
    (git-fixes CVE-2025-38429 bsc#1247253).
  - Update
    patches.suse/calipso-Fix-null-ptr-deref-in-calipso_req_-set-del-a.patch
    (git-fixes CVE-2025-38181 bsc#1246000).
  - Update
    patches.suse/can-kvaser_pciefd-refine-error-prone-echo_skb_max-ha.patch
    (git-fixes CVE-2025-38224 bsc#1246166).
  - Update
    patches.suse/clk-imx-Fix-an-out-of-bounds-access-in-dispmix_csr_c.patch
    (git-fixes CVE-2025-38446 bsc#1247231).
  - Update
    patches.suse/comedi-Fail-COMEDI_INSNLIST-ioctl-if-n_insns-is-too-.patch
    (git-fixes CVE-2025-38481 bsc#1247276).
  - Update
    patches.suse/comedi-Fix-initialization-of-data-for-instructions-t.patch
    (git-fixes CVE-2025-38478 bsc#1247273).
  - Update
    patches.suse/comedi-Fix-use-of-uninitialized-data-in-insn_rw_emul.patch
    (git-fixes CVE-2025-38480 bsc#1247274).
  - Update
    patches.suse/comedi-das16m1-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38483 bsc#1247278).
  - Update
    patches.suse/comedi-das6402-Fix-bit-shift-out-of-bounds.patch
    (git-fixes CVE-2025-38482 bsc#1247277).
  - Update
    patches.suse/crypto-marvell-cesa-Handle-zero-length-skcipher-requ.patch
    (git-fixes CVE-2025-38173 bsc#1245769).
  - Update
    patches.suse/crypto-sun8i-ce-cipher-fix-error-handling-in-sun8i_c.patch
    (git-fixes CVE-2025-38300 bsc#1246349).
  - Update patches.suse/dm-bufio-fix-sched-in-atomic-context.patch
    (git-fixes CVE-2025-38496 bsc#1247284).
  - Update patches.suse/dm-fix-dm_blk_report_zones.patch
    (CVE-2025-38140 bsc#1245717 CVE-2025-38141 bsc#1245715).
  - Update
    patches.suse/dma-buf-insert-memory-barrier-before-updating-num_fe.patch
    (git-fixes CVE-2025-38095 bsc#1245658).
  - Update
    patches.suse/dmaengine-idxd-Check-availability-of-workqueue-alloc.patch
    (stable-fixes CVE-2025-38369 bsc#1247209).
  - Update
    patches.suse/dmaengine-ti-Add-NULL-check-in-udma_probe.patch
    (git-fixes CVE-2025-38138 bsc#1245719).
  - Update
    patches.suse/drivers-rapidio-rio_cm.c-prevent-possible-heap-overw.patch
    (stable-fixes CVE-2025-38090 bsc#1245510).
  - Update
    patches.suse/drm-amd-display-Add-null-pointer-check-for-get_first.patch
    (git-fixes CVE-2025-38362 bsc#1247089).
  - Update
    patches.suse/drm-amd-display-Check-dce_hwseq-before-dereferencing.patch
    (stable-fixes CVE-2025-38361 bsc#1247079).
  - Update
    patches.suse/drm-amd-display-Don-t-treat-wb-connector-as-physical.patch
    (stable-fixes CVE-2025-38098 bsc#1245654).
  - Update
    patches.suse/drm-amd-display-check-stream-id-dml21-wrapper-to-get.patch
    (stable-fixes CVE-2025-38091 bsc#1245621).
  - Update
    patches.suse/drm-amd-pp-Fix-potential-NULL-pointer-dereference-in.patch
    (git-fixes CVE-2025-38319 bsc#1246243).
  - Update
    patches.suse/drm-exynos-exynos7_drm_decon-add-vblank-check-in-IRQ.patch
    (git-fixes CVE-2025-38467 bsc#1247146).
  - Update
    patches.suse/drm-gem-Acquire-references-on-GEM-handles-for-frameb.patch
    (stable-fixes CVE-2025-38449 bsc#1247255).
  - Update
    patches.suse/drm-i915-gt-Fix-timeline-left-held-on-VMA-alloc-erro.patch
    (git-fixes CVE-2025-38389 bsc#1247153).
  - Update
    patches.suse/drm-msm-Fix-a-fence-leak-in-submit-error-path.patch
    (stable-fixes CVE-2025-38410 bsc#1247128).
  - Update
    patches.suse/drm-msm-Fix-another-leak-in-the-submit-error-path.patch
    (stable-fixes CVE-2025-38409 bsc#1247285).
  - Update
    patches.suse/drm-msm-a7xx-Call-CP_RESET_CONTEXT_STATE.patch
    (git-fixes CVE-2025-38188 bsc#1246098).
  - Update
    patches.suse/drm-msm-gpu-Fix-crash-when-throttling-GPU-immediatel.patch
    (git-fixes CVE-2025-38354 bsc#1247061).
  - Update
    patches.suse/drm-scheduler-signal-scheduled-fence-when-kill-job.patch
    (stable-fixes CVE-2025-38436 bsc#1247227).
  - Update
    patches.suse/drm-tegra-Fix-a-possible-null-pointer-dereference.patch
    (git-fixes CVE-2025-38363 bsc#1247018).
  - Update
    patches.suse/drm-v3d-Avoid-NULL-pointer-dereference-in-v3d_job_up.patch
    (stable-fixes CVE-2025-38189 bsc#1245812).
  - Update
    patches.suse/drm-v3d-Disable-interrupts-before-resetting-the-GPU.patch
    (git-fixes CVE-2025-38371 bsc#1247178).
  - Update
    patches.suse/drm-xe-Fix-taking-invalid-lock-on-wedge.patch
    (stable-fixes CVE-2025-38353 bsc#1247265).
  - Update
    patches.suse/drm-xe-Process-deferred-GGTT-node-removals-on-device.patch
    (git-fixes CVE-2025-38355 bsc#1247062).
  - Update
    patches.suse/drm-xe-guc-Explicitly-exit-CT-safe-mode-on-unwind.patch
    (git-fixes CVE-2025-38356 bsc#1247064).
  - Update
    patches.suse/e1000-Move-cancel_work_sync-to-avoid-deadlock.patch
    (git-fixes CVE-2025-38114 bsc#1245686).
  - Update
    patches.suse/erofs-avoid-using-multiple-devices-with-different-type.patch
    (git-fixes CVE-2025-38172 bsc#1245787).
  - Update
    patches.suse/fbcon-Make-sure-modelist-not-set-on-unregistered-con.patch
    (stable-fixes CVE-2025-38198 bsc#1245952).
  - Update
    patches.suse/fbdev-Fix-do_register_framebuffer-to-prevent-null-pt.patch
    (git-fixes CVE-2025-38215 bsc#1246109).
  - Update
    patches.suse/fbdev-Fix-fb_set_var-to-prevent-null-ptr-deref-in-fb.patch
    (git-fixes CVE-2025-38214 bsc#1246042).
  - Update
    patches.suse/fbdev-core-fbcvt-avoid-division-by-0-in-fb_cvt_hperi.patch
    (git-fixes CVE-2025-38312 bsc#1246386).
  - Update
    patches.suse/firmware-arm_ffa-Fix-memory-leak-by-freeing-notifier.patch
    (git-fixes CVE-2025-38390 bsc#1247088).
  - Update
    patches.suse/fpga-fix-potential-null-pointer-deref-in-fpga_mgr_te.patch
    (git-fixes CVE-2025-38274 bsc#1246234).
  - Update
    patches.suse/fs-nfs-read-fix-double-unlock-bug-in-nfs_return_empty_folio.patch
    (git-fixes CVE-2025-38338 bsc#1246258).
  - Update
    patches.suse/gve-add-missing-NULL-check-for-gve_alloc_pending_pac.patch
    (git-fixes CVE-2025-38122 bsc#1245746).
  - Update
    patches.suse/hwmon-asus-ec-sensors-check-sensor-index-in-read_str.patch
    (git-fixes CVE-2025-38142 bsc#1245713).
  - Update
    patches.suse/hwmon-ftsteutates-Fix-TOCTOU-race-in-fts_read.patch
    (git-fixes CVE-2025-38217 bsc#1246002).
  - Update
    patches.suse/i2c-designware-Fix-an-initialization-issue.patch
    (git-fixes CVE-2025-38380 bsc#1247028).
  - Update
    patches.suse/i2c-tegra-check-msg-length-in-SMBUS-block-read.patch
    (bsc#1242086 CVE-2025-38425 bsc#1247251).
  - Update
    patches.suse/ice-fix-Tx-scheduler-error-handling-in-XDP-callback.patch
    (git-fixes CVE-2025-38127 bsc#1245705).
  - Update
    patches.suse/ice-fix-eswitch-code-memory-leak-in-reset-scenario.patch
    (git-fixes CVE-2025-38417 bsc#1247282).
  - Update
    patches.suse/iio-accel-fxls8962af-Fix-use-after-free-in-fxls8962a.patch
    (git-fixes CVE-2025-38485 bsc#1247236).
  - Update patches.suse/iio-backend-fix-out-of-bound-write.patch
    (git-fixes CVE-2025-38484 bsc#1247235).
  - Update
    patches.suse/maple_tree-fix-MA_STATE_PREALLOC-flag-in-mas_preallo.patch
    (git-fixes CVE-2025-38364 bsc#1247091).
  - Update
    patches.suse/media-cxusb-no-longer-judge-rbuf-when-the-write-fail.patch
    (git-fixes CVE-2025-38229 bsc#1246049).
  - Update
    patches.suse/media-imagination-fix-a-potential-memory-leak-in-e50.patch
    (git-fixes CVE-2025-38228 bsc#1245814).
  - Update
    patches.suse/media-imx-jpeg-Cleanup-after-an-allocation-error.patch
    (git-fixes CVE-2025-38225 bsc#1246041).
  - Update
    patches.suse/media-vidtv-Terminating-the-subsequent-process-of-in.patch
    (git-fixes CVE-2025-38227 bsc#1246031).
  - Update
    patches.suse/media-vivid-Change-the-siize-of-the-composing.patch
    (git-fixes CVE-2025-38226 bsc#1246050).
  - Update
    patches.suse/misc-tps6594-pfsm-Add-NULL-pointer-check-in-tps6594_.patch
    (stable-fixes CVE-2025-38368 bsc#1247022).
  - Update
    patches.suse/mtd-nand-ecc-mxic-Fix-use-of-uninitialized-variable-.patch
    (git-fixes CVE-2025-38277 bsc#1246246).
  - Update
    patches.suse/mtd-spinand-fix-memory-leak-of-ECC-engine-conf.patch
    (stable-fixes CVE-2025-38384 bsc#1247035).
  - Update
    patches.suse/mtk-sd-Prevent-memory-corruption-from-DMA-map-failur.patch
    (git-fixes CVE-2025-38401 bsc#1247125).
  - Update
    patches.suse/nbd-fix-uaf-in-nbd_genl_connect-error-path.patch
    (git-fixes CVE-2025-38443 bsc#1247164).
  - Update patches.suse/net-Fix-TOCTOU-issue-in-sk_is_readable.patch
    (git-fixes CVE-2025-38112 bsc#1245668).
  - Update
    patches.suse/net-fix-udp-gso-skb_segment-after-pull-from-frag_lis.patch
    (git-fixes CVE-2025-38124 bsc#1245690).
  - Update
    patches.suse/net-mdiobus-Fix-potential-out-of-bounds-clause-45-re.patch
    (git-fixes CVE-2025-38110 bsc#1245665).
  - Update
    patches.suse/net-mdiobus-Fix-potential-out-of-bounds-read-write-a.patch
    (git-fixes CVE-2025-38111 bsc#1245666).
  - Update
    patches.suse/net-mlx5-Fix-ECVF-vports-unload-on-shutdown-flow.patch
    (git-fixes CVE-2025-38109 bsc#1245684).
  - Update
    patches.suse/net-phy-clear-phydev-devlink-when-the-link-is-delete.patch
    (git-fixes CVE-2025-38149 bsc#1245737).
  - Update
    patches.suse/net-phy-mscc-Fix-memory-leak-when-using-one-step-tim.patch
    (git-fixes CVE-2025-38148 bsc#1245735).
  - Update
    patches.suse/net-sched-Return-NULL-when-htb_lookup_leaf-encounter.patch
    (git-fixes CVE-2025-38468 bsc#1247437).
  - Update
    patches.suse/net-sched-fix-use-after-free-in-taprio_dev_notifier.patch
    (git-fixes CVE-2025-38087 bsc#1245504).
  - Update
    patches.suse/net-sched-sch_qfq-Fix-race-condition-on-qfq_aggregat.patch
    (git-fixes CVE-2025-38477 bsc#1247314).
  - Update
    patches.suse/net-tipc-fix-refcount-warning-in-tipc_aead_encrypt.patch
    (CVE-2025-38052 bsc#1244749 CVE-2025-38273 bsc#1246266).
  - Update
    patches.suse/net-usb-aqc111-fix-error-handling-of-usbnet-read-cal.patch
    (git-fixes CVE-2025-38153 bsc#1245744).
  - Update
    patches.suse/net-usb-lan78xx-fix-WARN-in-__netif_napi_del_locked-.patch
    (git-fixes CVE-2025-38385 bsc#1247149).
  - Update patches.suse/net-wwan-t7xx-Fix-napi-rx-poll-issue.patch
    (git-fixes CVE-2025-38123 bsc#1245688).
  - Update
    patches.suse/net_sched-ets-fix-a-race-in-ets_qdisc_change.patch
    (git-fixes CVE-2025-38107 bsc#1245676).
  - Update
    patches.suse/net_sched-red-fix-a-race-in-__red_change.patch
    (git-fixes CVE-2025-38108 bsc#1245675).
  - Update
    patches.suse/net_sched-sch_sfq-reject-invalid-perturb-period.patch
    (git-fixes CVE-2025-38193 bsc#1245945).
  - Update
    patches.suse/netfilter-nf_set_pipapo_avx2-fix-initial-map-fill.patch
    (git-fixes CVE-2025-38120 bsc#1245711).
  - Update
    patches.suse/nfs-Clean-up-proc-net-rpc-nfs-when-nfs_fs_proc_net_init-fails.patch
    (git-fixes CVE-2025-38400 bsc#1247123).
  - Update
    patches.suse/nfsd-Initialize-ssc-before-laundromat_work-to-prevent-NULL-dereference.patch
    (git-fixes CVE-2025-38231 bsc#1246055).
  - Update
    patches.suse/nfsd-nfsd4_spo_must_allow-must-check-this-is-a-v4-compound-request.patch
    (git-fixes CVE-2025-38430 bsc#1247160).
  - Update
    patches.suse/nvme-multipath-fix-suspicious-RCU-usage-warning.patch
    (git-fixes CVE-2025-38397 bsc#1247163).
  - Update
    patches.suse/nvme-tcp-remove-tag-set-when-second-admin-queue-conf.patch
    (git-fixes CVE-2025-38209 bsc#1246022).
  - Update patches.suse/nvmet-fix-memory-leak-of-bio-integrity.patch
    (git-fixes CVE-2025-38405 bsc#1247270).
  - Update
    patches.suse/octeontx2-pf-QOS-Refactor-TC_HTB_LEAF_DEL_LAST-callb.patch
    (git-fixes CVE-2025-38278 bsc#1246255).
  - Update
    patches.suse/page_pool-Fix-use-after-free-in-page_pool_recycle_in.patch
    (git-fixes CVE-2025-38129 bsc#1245723).
  - Update patches.suse/perf-Fix-sample-vs-do_exit.patch
    (bsc#1246547 CVE-2025-38424 bsc#1247293).
  - Update
    patches.suse/perf-Revert-to-requiring-CAP_SYS_ADMIN-for-uprobes.patch
    (git-fixes CVE-2025-38466 bsc#1247442).
  - Update
    patches.suse/phy-qcom-qmp-usb-Fix-an-NULL-vs-IS_ERR-bug.patch
    (git-fixes CVE-2025-38275 bsc#1246236).
  - Update
    patches.suse/pinctrl-at91-Fix-possible-out-of-boundary-access.patch
    (git-fixes CVE-2025-38286 bsc#1246283).
  - Update
    patches.suse/platform-x86-amd-pmf-Use-device-managed-allocations.patch
    (git-fixes CVE-2025-38421 bsc#1247130).
  - Update
    patches.suse/platform-x86-dell-wmi-sysman-Fix-WMI-data-block-retr.patch
    (git-fixes CVE-2025-38412 bsc#1247132).
  - Update patches.suse/platform-x86-dell_rbu-Fix-list-usage.patch
    (git-fixes CVE-2025-38197 bsc#1246047).
  - Update
    patches.suse/powerpc-bpf-fix-JIT-code-size-calculation-of-bpf-tra.patch
    (jsc#PED-10909 git-fixes CVE-2025-38339 bsc#1246259).
  - Update
    patches.suse/powerpc-powernv-memtrace-Fix-out-of-bounds-issue-in-.patch
    (bsc#1244309 ltc#213790 CVE-2025-38088 bsc#1245506).
  - Update
    patches.suse/powerpc64-ftrace-fix-clobbered-r15-during-livepatchi.patch
    (jsc#PED-10909 git-fixes CVE-2025-38233 bsc#1246053).
  - Update
    patches.suse/ptp-remove-ptp-n_vclocks-check-logic-in-ptp_vclock_i.patch
    (git-fixes CVE-2025-38305 bsc#1246358).
  - Update
    patches.suse/regulator-gpio-Fix-the-out-of-bounds-access-to-drvda.patch
    (git-fixes CVE-2025-38395 bsc#1247171).
  - Update
    patches.suse/rose-fix-dangling-neighbour-pointers-in-rose_rt_devi.patch
    (git-fixes CVE-2025-38377 bsc#1247174).
  - Update
    patches.suse/rpl-Fix-use-after-free-in-rpl_do_srh_inline.patch
    (git-fixes CVE-2025-38476 bsc#1247317).
  - Update
    patches.suse/s390-bpf-Fix-bpf_arch_text_poke-with-new_addr-NULL-again.patch
    (git-fixes bsc#1246868 CVE-2025-38489 bsc#1247241).
  - Update
    patches.suse/s390-pkey-Prevent-overflow-in-size-calculation-for-memdup_.patch
    (git-fixes bsc#1245596 CVE-2025-38257 bsc#1246186).
  - Update
    patches.suse/sch_hfsc-make-hfsc_qlen_notify-idempotent.patch
    (CVE-2025-37798 bsc#1242414 CVE-2025-38177 bsc#1245986).
  - Update patches.suse/sched-rt-Fix-race-in-push_rt_task.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2025-38234 bsc#1246057).
  - Update
    patches.suse/scsi-lpfc-Avoid-potential-ndlp-use-after-free-in-dev.patch
    (bsc#1242995 CVE-2025-38289 bsc#1246287).
  - Update patches.suse/scsi-lpfc-Use-memcpy-for-BIOS-version.patch
    (bsc#1240966 CVE-2025-38332 bsc#1246375).
  - Update
    patches.suse/scsi-smartpqi-Fix-smp_processor_id-call-trace-for-preempti.patch
    (git-fixes CVE-2025-38288 bsc#1246286).
  - Update
    patches.suse/serial-Fix-potential-null-ptr-deref-in-mlb_usio_prob.patch
    (git-fixes CVE-2025-38135 bsc#1246023).
  - Update
    patches.suse/serial-jsm-fix-NPE-during-jsm_uart_port_init.patch
    (git-fixes CVE-2025-38265 bsc#1246244).
  - Update
    patches.suse/soc-aspeed-Add-NULL-check-in-aspeed_lpc_enable_snoop.patch
    (git-fixes CVE-2025-38145 bsc#1245765).
  - Update
    patches.suse/soc-aspeed-lpc-snoop-Don-t-disable-channels-that-are.patch
    (git-fixes CVE-2025-38487 bsc#1247238).
  - Update
    patches.suse/software-node-Correct-a-OOB-check-in-software_node_g.patch
    (stable-fixes CVE-2025-38342 bsc#1246453).
  - Update
    patches.suse/sunrpc-handle-SVC_GARBAGE-during-svc-auth-processing-as-auth-error.patch
    (git-fixes CVE-2025-38089 bsc#1245508).
  - Update
    patches.suse/thunderbolt-Do-not-double-dequeue-a-configuration-re.patch
    (stable-fixes CVE-2025-38174 bsc#1245781).
  - Update
    patches.suse/usb-acpi-Prevent-null-pointer-dereference-in-usb_acp.patch
    (git-fixes CVE-2025-38134 bsc#1245678).
  - Update
    patches.suse/usb-chipidea-udc-disconnect-reconnect-from-host-when.patch
    (git-fixes CVE-2025-38376 bsc#1247176).
  - Update
    patches.suse/usb-gadget-u_serial-Fix-race-condition-in-TTY-wakeup.patch
    (git-fixes CVE-2025-38448 bsc#1247233).
  - Update
    patches.suse/usb-net-sierra-check-for-no-status-endpoint.patch
    (git-fixes CVE-2025-38474 bsc#1247311).
  - Update
    patches.suse/usb-renesas_usbhs-Reorder-clock-handling-and-power-m.patch
    (git-fixes CVE-2025-38136 bsc#1245691).
  - Update
    patches.suse/usb-typec-altmodes-displayport-do-not-index-invalid-.patch
    (git-fixes CVE-2025-38391 bsc#1247181).
  - Update
    patches.suse/usb-typec-displayport-Fix-potential-deadlock.patch
    (git-fixes CVE-2025-38404 bsc#1247271).
  - Update
    patches.suse/usb-typec-tcpm-move-tcpm_queue_vdm_unlocked-to-async.patch
    (git-fixes CVE-2025-38268 bsc#1246385).
  - Update
    patches.suse/vgacon-Add-check-for-vc_origin-address-range-in-vgac.patch
    (git-fixes CVE-2025-38213 bsc#1246037).
  - Update
    patches.suse/video-screen_info-Update-framebuffers-behind-PCI-bri.patch
    (bsc#1240696 CVE-2025-38427 bsc#1247152).
  - Update
    patches.suse/virtio-net-ensure-the-received-length-does-not-excee.patch
    (git-fixes CVE-2025-38375 bsc#1247177).
  - Update
    patches.suse/virtio-net-xsk-rx-fix-the-frame-s-length-check.patch
    (git-fixes CVE-2025-38413 bsc#1247131).
  - Update patches.suse/vsock-Fix-transport_-TOCTOU.patch (git-fixes
    CVE-2025-38461 bsc#1247103).
  - Update patches.suse/vsock-Fix-transport_-g2h-h2g-TOCTOU.patch
    (git-fixes CVE-2025-38462 bsc#1247104).
  - Update
    patches.suse/vsock-vmci-Clear-the-vmci-transport-packet-properly-.patch
    (git-fixes CVE-2025-38403 bsc#1247141).
  - Update
    patches.suse/wifi-ath11k-fix-node-corruption-in-ar-arvifs-list.patch
    (git-fixes CVE-2025-38293 bsc#1246292).
  - Update
    patches.suse/wifi-ath12k-Fix-buffer-overflow-in-debugfs.patch
    (git-fixes CVE-2025-38317 bsc#1246443).
  - Update
    patches.suse/wifi-ath12k-Prevent-sending-WMI-commands-to-firmware.patch
    (bsc#1240998 CVE-2025-38291 bsc#1246297).
  - Update
    patches.suse/wifi-ath12k-fix-GCC_GCC_PCIE_HOT_RST-definition-for-.patch
    (git-fixes CVE-2025-38414 bsc#1247145).
  - Update
    patches.suse/wifi-ath12k-fix-invalid-access-to-memory.patch
    (git-fixes CVE-2025-38292 bsc#1246295).
  - Update
    patches.suse/wifi-ath12k-fix-node-corruption-in-ar-arvifs-list.patch
    (git-fixes CVE-2025-38290 bsc#1246293).
  - Update
    patches.suse/wifi-ath6kl-remove-WARN-on-bad-firmware-input.patch
    (stable-fixes CVE-2025-38406 bsc#1247210).
  - Update
    patches.suse/wifi-ath9k_htc-Abort-software-beacon-handling-if-dis.patch
    (git-fixes CVE-2025-38157 bsc#1245747).
  - Update
    patches.suse/wifi-carl9170-do-not-ping-device-which-has-failed-to.patch
    (git-fixes CVE-2025-38420 bsc#1247279).
  - Update
    patches.suse/wifi-iwlwifi-don-t-warn-when-if-there-is-a-FW-error.patch
    (stable-fixes CVE-2025-38096 bsc#1245657).
  - Update
    patches.suse/wifi-mt76-mt7915-Fix-null-ptr-deref-in-mt7915_mmio_w.patch
    (git-fixes CVE-2025-38155 bsc#1245748).
  - Update
    patches.suse/wifi-mt76-mt7925-prevent-NULL-pointer-dereference-in.patch
    (git-fixes CVE-2025-38450 bsc#1247376).
  - Update
    patches.suse/wifi-mt76-mt7996-Fix-null-ptr-deref-in-mt7996_mmio_w.patch
    (git-fixes CVE-2025-38156 bsc#1246034).
  - Update
    patches.suse/wifi-mt76-mt7996-drop-fragments-with-multicast-or-br.patch
    (stable-fixes CVE-2025-38343 bsc#1246438).
  - Update
    patches.suse/wifi-p54-prevent-buffer-overflow-in-p54_rx_eeprom_re.patch
    (git-fixes CVE-2025-38348 bsc#1246262).
  - Update
    patches.suse/wifi-rtw88-fix-the-para-buffer-size-to-avoid-reading.patch
    (git-fixes CVE-2025-38159 bsc#1245751).
  - commit 8064d69
  - ipv6: annotate data-races around rt->fib6_nsiblings (git-fixes).
  - commit 4b09993
  - ipv6: fix possible infinite loop in fib6_info_uses_dev()
    (git-fixes).
  - commit b0133f0
  - ipv6: prevent infinite loop in rt6_nlmsg_size() (git-fixes).
  - commit a1d8794
  - net/sched: Restrict conditions for adding duplicating netems
    to qdisc tree (git-fixes).
  - commit 21bb04b
  - spi: cs42l43: Property entry should be a null-terminated array
    (bsc#1246979).
  - commit 2043cd1
  - Move upstreamed sched, SCSI and ACPI patches into sorted section
  - commit 836e139
  - selftests/bpf: Fix selection of static vs. dynamic LLVM
    Bring git fixes for commit
    4ed92da84b67 ("selftests/bpf: Support dynamically linking LLVM if static is not available")
  - commit 7a43a26
  - media: venus: vdec: Clamp param smaller than 1fps and bigger
    than 240 (git-fixes).
  - commit 1e731e7
  - maple_tree: fix status setup on restore to active (git-fixes).
  - mtd: rawnand: atmel: set pmecc data setup time (git-fixes).
  - mtd: spinand: propagate spinand_wait() errors from
    spinand_write_page() (git-fixes).
  - mtd: rawnand: fsmc: Add missing check after DMA map (git-fixes).
  - mtd: rawnand: rockchip: Add missing check after DMA map
    (git-fixes).
  - mtd: rawnand: atmel: Fix dma_mapping_error() address
    (git-fixes).
  - mtd: rawnand: renesas: Add missing check after DMA map
    (git-fixes).
  - mtd: spi-nor: Fix spi_nor_try_unlock_all() (git-fixes).
  - mtd: spi-nor: spansion: Fixup params->set_4byte_addr_mode for
    SEMPER (git-fixes).
  - mtd: fix possible integer overflow in erase_xfer() (git-fixes).
  - clk: qcom: gcc-ipq8074: fix broken freq table for
    nss_port6_tx_clk_src (git-fixes).
  - clk: imx95-blk-ctl: Fix synchronous abort (git-fixes).
  - clk: at91: sam9x7: update pll clk ranges (git-fixes).
  - clk: thead: th1520-ap: Correctly refer the parent of osc_12m
    (git-fixes).
  - clk: sunxi-ng: v3s: Fix de clock definition (git-fixes).
  - clk: samsung: exynos850: fix a comment (git-fixes).
  - clk: samsung: gs101: fix alternate mout_hsi0_usb20_ref parent
    clock (git-fixes).
  - clk: samsung: gs101: fix CLK_DOUT_CMU_G3D_BUSD (git-fixes).
  - clk: renesas: rzv2h: Fix missing CLK_SET_RATE_PARENT flag for
    ddiv clocks (git-fixes).
  - clk: clk-axi-clkgen: fix fpfd_max frequency for zynq
    (git-fixes).
  - clk: xilinx: vcu: unregister pll_post only if registered
    correctly (git-fixes).
  - clk: davinci: Add NULL check in davinci_lpsc_clk_register()
    (git-fixes).
  - hwmon: (gsc-hwmon) fix fan pwm setpoint show functions
    (git-fixes).
  - pwm: imx-tpm: Reset counter if CMOD is 0 (git-fixes).
  - media: v4l2: Add support for NV12M tiled variants to
    v4l2_format_info() (git-fixes).
  - media: uvcvideo: Do not mark valid metadata as invalid
    (git-fixes).
  - media: ov2659: Fix memory leaks in ov2659_probe() (git-fixes).
  - media: ti: j721e-csi2rx: fix list_del corruption (git-fixes).
  - media: hi556: correct the test pattern configuration
    (git-fixes).
  - media: ipu6: isys: Use correct pads for xlate_streams()
    (git-fixes).
  - media: vivid: fix wrong pixel_array control size (git-fixes).
  - media: qcom: camss: cleanup media device allocated resource
    on error path (git-fixes).
  - media: venus: Fix MSM8998 frequency table (git-fixes).
  - media: venus: hfi: explicitly release IRQ during teardown
    (git-fixes).
  - media: venus: Fix OOB read due to missing payload bound check
    (git-fixes).
  - media: venus: Add a check for packet size after reading from
    shared memory (git-fixes).
  - media: venus: protect against spurious interrupts during probe
    (git-fixes).
  - media: venus: venc: Clamp param smaller than 1fps and bigger
    than 240 (git-fixes).
  - media: pisp_be: Fix pm_runtime underrun in probe (git-fixes).
  - media: ivsc: Fix crash at shutdown due to missing
    mei_cldev_disable() calls (git-fixes).
  - media: v4l2-ctrls: Don't reset handler's error in
    v4l2_ctrl_handler_free() (git-fixes).
  - media: mt9m114: Fix deadlock in
    get_frame_interval/set_frame_interval (git-fixes).
  - media: v4l2-ctrls: Fix H264 SEPARATE_COLOUR_PLANE check
    (git-fixes).
  - media: imx: fix a potential memory leak in
    imx_media_csc_scaler_device_init() (git-fixes).
  - media: verisilicon: Fix AV1 decoder clock frequency (git-fixes).
  - media: rainshadow-cec: fix TOCTOU race condition in
    rain_interrupt() (git-fixes).
  - media: gspca: Add bounds checking to firmware parser
    (git-fixes).
  - media: usbtv: Lock resolution while streaming (git-fixes).
  - media: uvcvideo: Fix 1-byte out-of-bounds read in
    uvc_parse_format() (git-fixes).
  - Revert "leds: trigger: netdev: Configure LED blink interval
    for HW offload" (git-fixes).
  - leds: flash: leds-qcom-flash: Fix registry access after re-bind
    (git-fixes).
  - mfd: cros_ec: Separate charge-control probing from USB-PD
    (git-fixes).
  - crypto: qat - fix seq_file position update in adf_ring_next()
    (git-fixes).
  - crypto: qat - fix DMA direction for compression on GEN2 devices
    (git-fixes).
  - crypto: qat - flush misc workqueue during device shutdown
    (git-fixes).
  - crypto: qat - disable ZUC-256 capability for QAT GEN5
    (git-fixes).
  - crypto: img-hash - Fix dma_unmap_sg() nents value (git-fixes).
  - crypto: keembay - Fix dma_unmap_sg() nents value (git-fixes).
  - hwrng: mtk - handle devm_pm_runtime_enable errors (git-fixes).
  - crypto: ccp - Fix crash when rebind ccp device for ccp.ko
    (git-fixes).
  - crypto: inside-secure - Fix `dma_unmap_sg()` nents value
    (git-fixes).
  - crypto: ccp - Fix locking on alloc failure handling (git-fixes).
  - crypto: caam - Prevent crash on suspend with iMX8QM / iMX8ULP
    (git-fixes).
  - crypto: arm/aes-neonbs - work around gcc-15 warning (git-fixes).
  - crypto: qat - fix state restore for banks with exceptions
    (git-fixes).
  - crypto: qat - allow enabling VFs in the absence of IOMMU
    (git-fixes).
  - crypto: marvell/cesa - Fix engine load inaccuracy (git-fixes).
  - crypto: qat - use unmanaged allocation for dc_data (git-fixes).
  - crypto: sun8i-ce - fix nents passed to dma_unmap_sg()
    (git-fixes).
  - commit ae512ba
  - RDMA/uverbs: Add empty rdma_uattrs_has_raw_cap() declaration (git-fixes)
  - commit e78882a
  - x86/rdrand: Disable RDSEED on AMD Cyan Skillfish (git-fixes).
  - commit 3ccca36
  - x86/cacheinfo: Properly parse CPUID(0x80000006) L2/L3 associativity (git-fixes).
  - commit a5b12b1
  - RDMA/mlx5: Fix compilation warning when USER_ACCESS isn't set (git-fixes)
  - commit 5241bbd
  - x86/cacheinfo: Properly parse CPUID(0x80000005) L1d/L1i associativity (git-fixes).
  - commit 530f80b
  - x86/cpu: Sanitize CPUID(0x80000000) output (git-fixes).
  - commit 8c1593e
  - RDMA/hns: Fix -Wframe-larger-than issue (git-fixes)
  - commit 160aaf0
  - RDMA/hns: Drop GFP_NOWARN (git-fixes)
  - commit 3983b2d
  - RDMA/hns: Fix accessing uninitialized resources (git-fixes)
  - commit 020f808
  - RDMA/hns: Get message length of ack_req from FW (git-fixes)
  - commit ed23840
  - RDMA/hns: Fix HW configurations not cleared in error flow (git-fixes)
  - commit 17d9c9c
  - RDMA/hns: Fix double destruction of rsv_qp (git-fixes)
  - commit 127df58
  - Fix dma_unmap_sg() nents value (git-fixes)
  - commit 72c9bb9
  - RDMA/counter: Check CAP_NET_RAW check in user namespace for RDMA counters (git-fixes)
  - commit e32f637
  - RDMA/nldev: Check CAP_NET_RAW in user namespace for QP modify (git-fixes)
  - commit 066fc2e
  - RDMA/mlx5: Check CAP_NET_RAW in user namespace for devx create (git-fixes)
  - commit 876344b
  - RDMA/uverbs: Check CAP_NET_RAW in user namespace for RAW QP create (git-fixes)
  - commit 84b0982
  - RDMA/uverbs: Check CAP_NET_RAW in user namespace for QP create (git-fixes)
  - commit 5d5e159
  - RDMA/mlx5: Check CAP_NET_RAW in user namespace for anchor create (git-fixes)
  - commit 1d83d68
  - RDMA/mlx5: Check CAP_NET_RAW in user namespace for flow create (git-fixes)
  - commit 880cd69
  - RDMA/uverbs: Check CAP_NET_RAW in user namespace for flow create (git-fixes)
  - commit 1e737a4

++++ gcc15:

  - Update to GCC 15 branch head, 15.1.1+git10189, GCC 15.2 RC

++++ python313-core:

  - Add CVE-2025-8194-tarfile-no-neg-offsets.patch which now
    validates archives to ensure member offsets are non-negative
    (gh#python/cpython#130577, CVE-2025-8194, bsc#1247249).

++++ python313:

  - Add CVE-2025-8194-tarfile-no-neg-offsets.patch which now
    validates archives to ensure member offsets are non-negative
    (gh#python/cpython#130577, CVE-2025-8194, bsc#1247249).

------------------------------------------------------------------
------------------  2025-7-31  -  Jul 31 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Consolidate device lock into its own method
    Add set_device_lock method which uses udevadm lock preferable
    but also supports an flock fallback in case there is no lock
    command provided via systemd/udev
  - Fix bug in shell condition
    The shell code test ... || warn A; warn B will always
    print the warning for B despite the test result. This lead
    to the warning message "Settings from the kiwi description will be ignored"
    to be printed always. This commit fixes it with a clean if/then
    condition

++++ kernel-default:

  - tcp: Correct signedness in skb remaining space calculation
    (CVE-2025-38463 bsc#1247113).
  - net/sched: Always pass notifications when child class becomes
    empty (CVE-2025-38350 bsc#1246781).
  - commit 3e7e03b
  - wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()
    (git-fixes).
  - wifi: iwlwifi: return ERR_PTR from opmode start()
    (stable-fixes).
  - commit f109748
  - drm/amdgpu/gfx10: fix kiq locking in KCQ reset (git-fixes).
  - drm/amdgpu/gfx9.4.3: fix kiq locking in KCQ reset (git-fixes).
  - drm/amdgpu/gfx9: fix kiq locking in KCQ reset (git-fixes).
  - drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and
    value (git-fixes).
  - drm/xe/uapi: Correct sync type definition in comments
    (git-fixes).
  - fbcon: Fix outdated registered_fb reference in comment
    (git-fixes).
  - drm/msm/dpu: Fill in min_prefill_lines for SC8180X (git-fixes).
  - drm/amdgpu: Remove nbiov7.9 replay count reporting (git-fixes).
  - drm/vmwgfx: Fix Host-Backed userspace on Guest-Backed kernel
    (git-fixes).
  - drm/panthor: Add missing explicit padding in
    drm_panthor_gpu_info (git-fixes).
  - drm/panfrost: Fix panfrost device variable name in devfreq
    (git-fixes).
  - drm/connector: hdmi: Evaluate limited range after computing
    format (git-fixes).
  - drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed
    (git-fixes).
  - can: peak_usb: fix USB FD devices potential malfunction
    (git-fixes).
  - net: phy: micrel: fix KSZ8081/KSZ8091 cable test (git-fixes).
  - net: usbnet: Avoid potential RCU stall on LINK_CHANGE event
    (git-fixes).
  - can: kvaser_usb: Assign netdev.dev_port based on device channel
    index (git-fixes).
  - can: kvaser_pciefd: Store device channel index (git-fixes).
  - Bluetooth: hci_event: Mask data status from LE ext adv reports
    (git-fixes).
  - wifi: nl80211: Set num_sub_specs before looping through
    sub_specs (git-fixes).
  - wifi: mac80211: Write cnt before copying in
    ieee80211_copy_rnr_beacon() (git-fixes).
  - wifi: ath12k: fix endianness handling while accessing wmi
    service bit (git-fixes).
  - wifi: ath11k: fix sleeping-in-atomic in
    ath11k_mac_op_set_bitrate_mask() (git-fixes).
  - wifi: ath12k: fix dest ring-buffer corruption when ring is full
    (git-fixes).
  - wifi: ath12k: fix source ring-buffer corruption (git-fixes).
  - wifi: ath12k: fix dest ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix dest ring-buffer corruption when ring is full
    (git-fixes).
  - wifi: ath11k: fix source ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix dest ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix suspend use-after-free after probe failure
    (git-fixes).
  - wifi: ath11k: clear initialized flag for deinit-ed srng lists
    (git-fixes).
  - wifi: brcmfmac: fix P2P discovery failure in P2P peer due to
    missing P2P IE (git-fixes).
  - Reapply "wifi: mac80211: Update skb's control block key in
    ieee80211_tx_dequeue()" (git-fixes).
  - wifi: mac80211: Check 802.11 encaps offloading in
    ieee80211_tx_h_select_key() (git-fixes).
  - wifi: mac80211: Don't call fq_flow_idx() for management frames
    (git-fixes).
  - wifi: mac80211: Do not schedule stopped TXQs (git-fixes).
  - wifi: plfxlc: Fix error handling in usb driver probe
    (git-fixes).
  - wifi: mac80211: reject TDLS operations when station is not
    associated (git-fixes).
  - wifi: brcmsmac: Remove const from tbl_ptr parameter in
    wlc_lcnphy_common_read_table() (git-fixes).
  - wifi: rtw88: Fix macid assigned to TDLS station (git-fixes).
  - wifi: rtl8xxxu: Fix RX skb size for aggregation disabled
    (git-fixes).
  - mwl8k: Add missing check after DMA map (git-fixes).
  - iwlwifi: Add missing check for alloc_ordered_workqueue
    (git-fixes).
  - wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (git-fixes).
  - wifi: rtl818x: Kill URBs before clearing tx status queue
    (git-fixes).
  - wifi: rtw89: avoid NULL dereference when RX problematic packet
    on unsupported 6 GHz band (git-fixes).
  - wifi: ath12k: Pass ab pointer directly to
    ath12k_dp_tx_get_encap_type() (git-fixes).
  - staging: media: atomisp: Fix stack buffer overflow in
    gmin_get_var_int() (git-fixes).
  - commit 2967d89
  - RDMA/mlx5: Fix UMR modifying of mkey page size (git-fixes)
  - commit 2bdec98

++++ kernel-rt:

  - tcp: Correct signedness in skb remaining space calculation
    (CVE-2025-38463 bsc#1247113).
  - net/sched: Always pass notifications when child class becomes
    empty (CVE-2025-38350 bsc#1246781).
  - commit 3e7e03b
  - wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()
    (git-fixes).
  - wifi: iwlwifi: return ERR_PTR from opmode start()
    (stable-fixes).
  - commit f109748
  - drm/amdgpu/gfx10: fix kiq locking in KCQ reset (git-fixes).
  - drm/amdgpu/gfx9.4.3: fix kiq locking in KCQ reset (git-fixes).
  - drm/amdgpu/gfx9: fix kiq locking in KCQ reset (git-fixes).
  - drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and
    value (git-fixes).
  - drm/xe/uapi: Correct sync type definition in comments
    (git-fixes).
  - fbcon: Fix outdated registered_fb reference in comment
    (git-fixes).
  - drm/msm/dpu: Fill in min_prefill_lines for SC8180X (git-fixes).
  - drm/amdgpu: Remove nbiov7.9 replay count reporting (git-fixes).
  - drm/vmwgfx: Fix Host-Backed userspace on Guest-Backed kernel
    (git-fixes).
  - drm/panthor: Add missing explicit padding in
    drm_panthor_gpu_info (git-fixes).
  - drm/panfrost: Fix panfrost device variable name in devfreq
    (git-fixes).
  - drm/connector: hdmi: Evaluate limited range after computing
    format (git-fixes).
  - drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed
    (git-fixes).
  - can: peak_usb: fix USB FD devices potential malfunction
    (git-fixes).
  - net: phy: micrel: fix KSZ8081/KSZ8091 cable test (git-fixes).
  - net: usbnet: Avoid potential RCU stall on LINK_CHANGE event
    (git-fixes).
  - can: kvaser_usb: Assign netdev.dev_port based on device channel
    index (git-fixes).
  - can: kvaser_pciefd: Store device channel index (git-fixes).
  - Bluetooth: hci_event: Mask data status from LE ext adv reports
    (git-fixes).
  - wifi: nl80211: Set num_sub_specs before looping through
    sub_specs (git-fixes).
  - wifi: mac80211: Write cnt before copying in
    ieee80211_copy_rnr_beacon() (git-fixes).
  - wifi: ath12k: fix endianness handling while accessing wmi
    service bit (git-fixes).
  - wifi: ath11k: fix sleeping-in-atomic in
    ath11k_mac_op_set_bitrate_mask() (git-fixes).
  - wifi: ath12k: fix dest ring-buffer corruption when ring is full
    (git-fixes).
  - wifi: ath12k: fix source ring-buffer corruption (git-fixes).
  - wifi: ath12k: fix dest ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix dest ring-buffer corruption when ring is full
    (git-fixes).
  - wifi: ath11k: fix source ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix dest ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix suspend use-after-free after probe failure
    (git-fixes).
  - wifi: ath11k: clear initialized flag for deinit-ed srng lists
    (git-fixes).
  - wifi: brcmfmac: fix P2P discovery failure in P2P peer due to
    missing P2P IE (git-fixes).
  - Reapply "wifi: mac80211: Update skb's control block key in
    ieee80211_tx_dequeue()" (git-fixes).
  - wifi: mac80211: Check 802.11 encaps offloading in
    ieee80211_tx_h_select_key() (git-fixes).
  - wifi: mac80211: Don't call fq_flow_idx() for management frames
    (git-fixes).
  - wifi: mac80211: Do not schedule stopped TXQs (git-fixes).
  - wifi: plfxlc: Fix error handling in usb driver probe
    (git-fixes).
  - wifi: mac80211: reject TDLS operations when station is not
    associated (git-fixes).
  - wifi: brcmsmac: Remove const from tbl_ptr parameter in
    wlc_lcnphy_common_read_table() (git-fixes).
  - wifi: rtw88: Fix macid assigned to TDLS station (git-fixes).
  - wifi: rtl8xxxu: Fix RX skb size for aggregation disabled
    (git-fixes).
  - mwl8k: Add missing check after DMA map (git-fixes).
  - iwlwifi: Add missing check for alloc_ordered_workqueue
    (git-fixes).
  - wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (git-fixes).
  - wifi: rtl818x: Kill URBs before clearing tx status queue
    (git-fixes).
  - wifi: rtw89: avoid NULL dereference when RX problematic packet
    on unsupported 6 GHz band (git-fixes).
  - wifi: ath12k: Pass ab pointer directly to
    ath12k_dp_tx_get_encap_type() (git-fixes).
  - staging: media: atomisp: Fix stack buffer overflow in
    gmin_get_var_int() (git-fixes).
  - commit 2967d89
  - RDMA/mlx5: Fix UMR modifying of mkey page size (git-fixes)
  - commit 2bdec98

++++ systemd:

  - Remove the script used to help migrating the language and locale settings
    located in /etc/sysconfig/language on old systems to the systemd default
    locations (bsc#1247074)
    The script was introduced more than 7 years ago and all systems running TW
    should have been migrated since then. Moreover the installer supports the
    systemd default locations since approximately SLE15.

++++ libzypp:

  - Append RepoInfo::path() to the mirror URLs in Preloader
    (bsc#1247054)
  - version 17.37.15 (35)

++++ opensuse-migration-tool:

  - Update to version 20250731.8b95d00:
    * Do not enable migration scripts by default

++++ selinux-policy:

  - Update to version 20250627+git66.15675827a:
    * Set /srv/tftpboot = /var/lib/tftpboot as equivalent file context (bsc#1247381)
    * Create unconfined type for salt-minion bsc#1228984
  - Change default of example config to enforcing mode. With
    selinux-autorelabel taking care of relabeling this should work
    nowadays

------------------------------------------------------------------
------------------  2025-7-30  -  Jul 30 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - drop duplicate %changelog macro

++++ python-kiwi:

  - Fix documentation rendering
    There was an indentation bug which caused the docs to
    render wrong. This commit fixes it

++++ kernel-default:

  - io_uring/sqpoll: don't put task_struct on tctx setup failure
    (bsc#1245664 CVE-2025-38106).
  - io_uring: consistently use rcu semantics with sqpoll thread
    (bsc#1245664 CVE-2025-38106).
  - io_uring: fix use-after-free of sq->thread in
    __io_uring_show_fdinfo() (bsc#1245664 CVE-2025-38106).
  - commit 83d2779
  - usb: gadget: configfs: Fix OOB read on empty string write
    (CVE-2025-38497 bsc#1247347).
  - commit fdc50d2
  - fs: export anon_inode_make_secure_inode() and fix secretmem
    LSM bypass (CVE-2025-38396 bsc#1247156).
    Conflicts:
    series.conf
  - fs: export anon_inode_make_secure_inode() and fix secretmem
    LSM bypass (CVE-2025-38396 bsc#1247156).
  - commit 4bbdefe
  - Enable MT7925 WiFi drivers for openSUSE Leap 16.0 (bsc#1247325)
    Enabled only for Leap 16.0 kernel-default-optional as unsupported for now
  - commit 60216d7
  - optee: ffa: fix sleep in atomic context (CVE-2025-38374
    bsc#1247024).
  - commit c40f48d
  - kabi/severities: ignore two unused/dropped symbols from MEI
  - commit f8ced2f
  - soc: qcom: mdt_loader: Fix error return values in
    mdt_header_valid() (git-fixes).
  - commit eab169b
  - Docs/ABI: Fix sysfs-kernel-address_bits path (git-fixes).
  - soc: qcom: pmic_glink: fix OF node leak (git-fixes).
  - soc: qcom: fix endianness for QMI header (git-fixes).
  - soc: qcom: QMI encoding/decoding for big endian (git-fixes).
  - soc: qcom: mdt_loader: Ensure we don't read past the ELF header
    (git-fixes).
  - memory: mtk-smi: Add ostd setting for mt8186 (git-fixes).
  - soc/tegra: cbb: Clear ERR_FORCE register with ERR_STATUS
    (git-fixes).
  - firmware: arm_scmi: Fix up turbo frequencies selection
    (git-fixes).
  - usb: musb: omap2430: fix device leak at unbind (git-fixes).
  - usb: gadget: udc: renesas_usb3: fix device leak at unbind
    (git-fixes).
  - usb: dwc3: meson-g12a: fix device leaks at unbind (git-fixes).
  - usb: dwc3: imx8mp: fix device leak at unbind (git-fixes).
  - usb: atm: cxacru: Merge cxacru_upload_firmware() into
    cxacru_heavy_init() (git-fixes).
  - thunderbolt: Fix copy+paste error in match_service_id()
    (git-fixes).
  - usb: typec: ucsi: Update power_supply on power role change
    (git-fixes).
  - usb: typec: fusb302: cache PD RX state (git-fixes).
  - usb: gadget : fix use-after-free in composite_dev_cleanup()
    (git-fixes).
  - cdc-acm: fix race between initial clearing halt and open
    (git-fixes).
  - usb: early: xhci-dbc: Fix early_ioremap leak (git-fixes).
  - USB: gadget: f_hid: Fix memory leak in hidg_bind error path
    (git-fixes).
  - usb: typec: ucsi: yoga-c630: fix error and remove paths
    (git-fixes).
  - usb: misc: apple-mfi-fastcharge: Make power supply names unique
    (git-fixes).
  - Documentation: usb: gadget: Wrap remaining usage snippets in
    literal code block (git-fixes).
  - usb: host: xhci-plat: fix incorrect type for of_match variable
    in xhci_plat_probe() (git-fixes).
  - vt: defkeymap: Map keycodes above 127 to K_HOLE (git-fixes).
  - vt: keyboard: Don't process Unicode characters in K_OFF mode
    (git-fixes).
  - staging: axis-fifo: remove sysfs interface (git-fixes).
  - staging: nvec: Fix incorrect null termination of battery
    manufacturer (git-fixes).
  - staging: fbtft: fix potential memory leak in
    fbtft_framebuffer_alloc() (git-fixes).
  - interconnect: qcom: sc8180x: specify num_nodes (git-fixes).
  - interconnect: qcom: sc8280xp: specify num_links for
    qnm_a1noc_cfg (git-fixes).
  - comedi: fix race between polling and detaching (git-fixes).
  - iio: adc: ad_sigma_delta: change to buffer predisable
    (git-fixes).
  - iio: imu: bno055: fix OOB access of hw_xlate array (git-fixes).
  - bus: mhi: host: Detect events pointing to unexpected TREs
    (git-fixes).
  - bus: mhi: host: pci_generic: Fix the modem name of Foxconn
    T99W640 (git-fixes).
  - misc: rtsx: usb: Ensure mmc child device is active when card
    is present (git-fixes).
  - vmci: Prevent the dispatching of uninitialized payloads
    (git-fixes).
  - samples: mei: Fix building on musl libc (git-fixes).
  - mei: vsc: Fix "BUG: Invalid wait context" lockdep error
    (git-fixes).
  - mei: vsc: Run event callback from a workqueue (git-fixes).
  - mei: vsc: Unset the event callback on remove and probe errors
    (git-fixes).
  - mei: vsc: Event notifier fixes (git-fixes).
  - mei: vsc: Destroy mutex after freeing the IRQ (git-fixes).
  - mei: vsc: Don't re-init VSC from mei_vsc_hw_reset() on stop
    (git-fixes).
  - mei: vsc: Drop unused vsc_tp_request_irq() and vsc_tp_free_irq()
    (stable-fixes).
  - platform/chrome: cros_ec: Unregister notifier in
    cros_ec_unregister() (git-fixes).
  - pwm: rockchip: Round period/duty down on apply, up on get
    (git-fixes).
  - spi: stm32: Check for cfg availability in stm32_spi_probe
    (git-fixes).
  - gpio: virtio: Fix config space reading (git-fixes).
  - ASoC: ops: dynamically allocate struct snd_ctl_elem_value
    (git-fixes).
  - ASoC: soc-dai: tidyup return value of
    snd_soc_xlate_tdm_slot_mask() (git-fixes).
  - Documentation: ACPI: Fix parent device references (git-fixes).
  - ACPI: LPSS: Remove AudioDSP related ID (git-fixes).
  - ACPI: processor: perflib: Fix initial _PPC limit application
    (git-fixes).
  - powercap: dtpm_cpu: Fix NULL pointer dereference in
    get_pd_power_uw() (git-fixes).
  - PM: runtime: Take active children into account in
    pm_runtime_get_if_in_use() (git-fixes).
  - PM / devfreq: Fix a index typo in trans_stat (git-fixes).
  - PM / devfreq: Check governor before using governor->name
    (git-fixes).
  - commit bb1eeb0
  - s390/ism: fix concurrency management in ism_cmd() (git-fixes
    bsc#1247372).
  - commit 9c82c2d
  - s390/mm: Remove possible false-positive warning in
    pte_free_defer() (git-fixes bsc#1247366).
  - commit 24410b3
  - x86/fpu: Delay instruction pointer fixup until after warning (git-fixes).
  - commit 065c5cd
  - x86/bugs: Allow ITS stuffing in eIBRS+retpoline mode also (git-fixes).
  - commit 5066cbd
  - x86/bugs: Remove its=stuff dependency on retbleed (git-fixes).
  - commit a74c41e
  - x86/bugs: Introduce cdt_possible() (git-fixes).
  - commit 229ca7c
  - x86/bugs: Use switch/case in its_apply_mitigation() (git-fixes).
  - commit 83a9f22
  - x86/bugs: Avoid warning when overriding return thunk (git-fixes).
  - commit 0b33009
  - x86/bugs: Simplify the retbleed=stuff checks (git-fixes).
  - commit 4381119
  - x86/bugs: Avoid AUTO after the select step in the retbleed mitigation (git-fixes).
  - commit 4ef3103
  - Refresh patches.suse/x86-entry-Add-__init-to-ia32_emulation_override_cmdline.patch.
  - commit dfed6d8

++++ kernel-rt:

  - io_uring/sqpoll: don't put task_struct on tctx setup failure
    (bsc#1245664 CVE-2025-38106).
  - io_uring: consistently use rcu semantics with sqpoll thread
    (bsc#1245664 CVE-2025-38106).
  - io_uring: fix use-after-free of sq->thread in
    __io_uring_show_fdinfo() (bsc#1245664 CVE-2025-38106).
  - commit 83d2779
  - usb: gadget: configfs: Fix OOB read on empty string write
    (CVE-2025-38497 bsc#1247347).
  - commit fdc50d2
  - fs: export anon_inode_make_secure_inode() and fix secretmem
    LSM bypass (CVE-2025-38396 bsc#1247156).
    Conflicts:
    series.conf
  - fs: export anon_inode_make_secure_inode() and fix secretmem
    LSM bypass (CVE-2025-38396 bsc#1247156).
  - commit 4bbdefe
  - Enable MT7925 WiFi drivers for openSUSE Leap 16.0 (bsc#1247325)
    Enabled only for Leap 16.0 kernel-default-optional as unsupported for now
  - commit 60216d7
  - optee: ffa: fix sleep in atomic context (CVE-2025-38374
    bsc#1247024).
  - commit c40f48d
  - kabi/severities: ignore two unused/dropped symbols from MEI
  - commit f8ced2f
  - soc: qcom: mdt_loader: Fix error return values in
    mdt_header_valid() (git-fixes).
  - commit eab169b
  - Docs/ABI: Fix sysfs-kernel-address_bits path (git-fixes).
  - soc: qcom: pmic_glink: fix OF node leak (git-fixes).
  - soc: qcom: fix endianness for QMI header (git-fixes).
  - soc: qcom: QMI encoding/decoding for big endian (git-fixes).
  - soc: qcom: mdt_loader: Ensure we don't read past the ELF header
    (git-fixes).
  - memory: mtk-smi: Add ostd setting for mt8186 (git-fixes).
  - soc/tegra: cbb: Clear ERR_FORCE register with ERR_STATUS
    (git-fixes).
  - firmware: arm_scmi: Fix up turbo frequencies selection
    (git-fixes).
  - usb: musb: omap2430: fix device leak at unbind (git-fixes).
  - usb: gadget: udc: renesas_usb3: fix device leak at unbind
    (git-fixes).
  - usb: dwc3: meson-g12a: fix device leaks at unbind (git-fixes).
  - usb: dwc3: imx8mp: fix device leak at unbind (git-fixes).
  - usb: atm: cxacru: Merge cxacru_upload_firmware() into
    cxacru_heavy_init() (git-fixes).
  - thunderbolt: Fix copy+paste error in match_service_id()
    (git-fixes).
  - usb: typec: ucsi: Update power_supply on power role change
    (git-fixes).
  - usb: typec: fusb302: cache PD RX state (git-fixes).
  - usb: gadget : fix use-after-free in composite_dev_cleanup()
    (git-fixes).
  - cdc-acm: fix race between initial clearing halt and open
    (git-fixes).
  - usb: early: xhci-dbc: Fix early_ioremap leak (git-fixes).
  - USB: gadget: f_hid: Fix memory leak in hidg_bind error path
    (git-fixes).
  - usb: typec: ucsi: yoga-c630: fix error and remove paths
    (git-fixes).
  - usb: misc: apple-mfi-fastcharge: Make power supply names unique
    (git-fixes).
  - Documentation: usb: gadget: Wrap remaining usage snippets in
    literal code block (git-fixes).
  - usb: host: xhci-plat: fix incorrect type for of_match variable
    in xhci_plat_probe() (git-fixes).
  - vt: defkeymap: Map keycodes above 127 to K_HOLE (git-fixes).
  - vt: keyboard: Don't process Unicode characters in K_OFF mode
    (git-fixes).
  - staging: axis-fifo: remove sysfs interface (git-fixes).
  - staging: nvec: Fix incorrect null termination of battery
    manufacturer (git-fixes).
  - staging: fbtft: fix potential memory leak in
    fbtft_framebuffer_alloc() (git-fixes).
  - interconnect: qcom: sc8180x: specify num_nodes (git-fixes).
  - interconnect: qcom: sc8280xp: specify num_links for
    qnm_a1noc_cfg (git-fixes).
  - comedi: fix race between polling and detaching (git-fixes).
  - iio: adc: ad_sigma_delta: change to buffer predisable
    (git-fixes).
  - iio: imu: bno055: fix OOB access of hw_xlate array (git-fixes).
  - bus: mhi: host: Detect events pointing to unexpected TREs
    (git-fixes).
  - bus: mhi: host: pci_generic: Fix the modem name of Foxconn
    T99W640 (git-fixes).
  - misc: rtsx: usb: Ensure mmc child device is active when card
    is present (git-fixes).
  - vmci: Prevent the dispatching of uninitialized payloads
    (git-fixes).
  - samples: mei: Fix building on musl libc (git-fixes).
  - mei: vsc: Fix "BUG: Invalid wait context" lockdep error
    (git-fixes).
  - mei: vsc: Run event callback from a workqueue (git-fixes).
  - mei: vsc: Unset the event callback on remove and probe errors
    (git-fixes).
  - mei: vsc: Event notifier fixes (git-fixes).
  - mei: vsc: Destroy mutex after freeing the IRQ (git-fixes).
  - mei: vsc: Don't re-init VSC from mei_vsc_hw_reset() on stop
    (git-fixes).
  - mei: vsc: Drop unused vsc_tp_request_irq() and vsc_tp_free_irq()
    (stable-fixes).
  - platform/chrome: cros_ec: Unregister notifier in
    cros_ec_unregister() (git-fixes).
  - pwm: rockchip: Round period/duty down on apply, up on get
    (git-fixes).
  - spi: stm32: Check for cfg availability in stm32_spi_probe
    (git-fixes).
  - gpio: virtio: Fix config space reading (git-fixes).
  - ASoC: ops: dynamically allocate struct snd_ctl_elem_value
    (git-fixes).
  - ASoC: soc-dai: tidyup return value of
    snd_soc_xlate_tdm_slot_mask() (git-fixes).
  - Documentation: ACPI: Fix parent device references (git-fixes).
  - ACPI: LPSS: Remove AudioDSP related ID (git-fixes).
  - ACPI: processor: perflib: Fix initial _PPC limit application
    (git-fixes).
  - powercap: dtpm_cpu: Fix NULL pointer dereference in
    get_pd_power_uw() (git-fixes).
  - PM: runtime: Take active children into account in
    pm_runtime_get_if_in_use() (git-fixes).
  - PM / devfreq: Fix a index typo in trans_stat (git-fixes).
  - PM / devfreq: Check governor before using governor->name
    (git-fixes).
  - commit bb1eeb0
  - s390/ism: fix concurrency management in ism_cmd() (git-fixes
    bsc#1247372).
  - commit 9c82c2d
  - s390/mm: Remove possible false-positive warning in
    pte_free_defer() (git-fixes bsc#1247366).
  - commit 24410b3
  - x86/fpu: Delay instruction pointer fixup until after warning (git-fixes).
  - commit 065c5cd
  - x86/bugs: Allow ITS stuffing in eIBRS+retpoline mode also (git-fixes).
  - commit 5066cbd
  - x86/bugs: Remove its=stuff dependency on retbleed (git-fixes).
  - commit a74c41e
  - x86/bugs: Introduce cdt_possible() (git-fixes).
  - commit 229ca7c
  - x86/bugs: Use switch/case in its_apply_mitigation() (git-fixes).
  - commit 83a9f22
  - x86/bugs: Avoid warning when overriding return thunk (git-fixes).
  - commit 0b33009
  - x86/bugs: Simplify the retbleed=stuff checks (git-fixes).
  - commit 4381119
  - x86/bugs: Avoid AUTO after the select step in the retbleed mitigation (git-fixes).
  - commit 4ef3103
  - Refresh patches.suse/x86-entry-Add-__init-to-ia32_emulation_override_cmdline.patch.
  - commit dfed6d8

++++ openssl-3:

  - Disable LTO for userspace livepatching [jsc#PED-13245]

++++ opensuse-migration-tool:

  - Update to version 20250731.2b96308:
    * Add 10_keepapparmor.sh 10_keepselinux.sh 20_ia32.sh migration services
    * Fancy README.md

++++ selinux-policy:

  - Unify with factory specfile, which includes:
  - Explain that disabling SELinux should not be done via the config
    file anymore (bsc#1246549)
  - Drop mls option, as we don't provide this ATM
  - Improve selinux-policy-devel dependencies and add post script to
    improve experience when debugging (bsc#1236193).
  - Move manpages to selinux-policy-doc package (bsc#1241391)
  - Add ugly workaround for semodule removal issues
    (bsc#1221342 bsc#1238062 bsc#1230643 bsc#1230938)
    Can be dropped when PED-12491 is done.
  - Use python311 tools in 15.4 and 15.5 when building selinux-policy to deprecate
    python36 tooling
  - Improve selinux-policy packaging
    * Remove bashisms to support UNIX SH syntax in scriptlets (bsc#1237517)
    * Fix non-existing $package variable in "%post minimum" scriptlet
    * Improve selinux-policy.rpmlintrc file
    * Remove duplicates with fdupes

++++ ucode-amd:

  - Update to version 20250730 (git commit 910c19074091):
    * linux-firmware: Update AMD cpu microcode

------------------------------------------------------------------
------------------  2025-7-29  -  Jul 29 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 28.3.3-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2833>
    CVE-2025-54388 bsc#1247367

++++ python-kiwi:

  - solver/repository: Handle zstd-compressed metadata files
    `_create_solvables` assumes metadata files are gzip-compressed,
    but modern Fedora ones are not, they are zstd-compressed.
    Signed-off-by: Adam Williamson <awilliam@redhat.com>
  - uri: If we fail to resolve the metalink URI, log it
    It's rather useful to know *what* the URI is when something goes
    wrong, after all.
    Signed-off-by: Adam Williamson <awilliam@redhat.com>
  - Bump version: 10.2.29 → 10.2.30
  - Fix repartitioning with parted
    parted does locking itself already. Wrapping it in udevadm lock results
    in a deadlock, breaking boot.

++++ fde-tools:

  - Add the missing /var/log/fde (bsc#1247228)

++++ kernel-default:

  - selftests/bpf: Remove test_skb_cgroup_id.sh from TEST_PROGS
    Fix the following BPF selftests build error:
    [  183s] make[1]: Entering directory '/home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/bpf'
    [  183s] rsync -a --copy-unsafe-links test_kmod.sh test_xdp_redirect.sh test_xdp_redirect_multi.sh test_xdp_meta.sh test_tunnel.sh test_lwt_seg6local.sh test_lirc_mode2.sh test_skb_cgroup_id.sh test_flow_dissector.sh test_xdp_vlan_mode_generic.sh test_xdp_vlan_mode_native.sh test_lwt_ip_encap.sh test_tcp_check_syncookie.sh test_tc_tunnel.sh test_tc_edt.sh test_xdping.sh test_bpftool_build.sh test_bpftool.sh test_bpftool_metadata.sh test_doc_build.sh test_xsk.sh test_xdp_features.sh /home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/kselftest_install/bpf/
    [  183s] rsync: [sender] link_stat "/home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/bpf/test_skb_cgroup_id.sh" failed: No such file or directory (2)
    [  183s] rsync error: some files/attrs were not transferred (see previous errors) (code 23) at main.c(1338) [sender=3.4.1]
  - commit 7aa88b9
  - selftests/bpf: Support dynamically linking LLVM if static is not available
    Fix the following BPF selftests build error:
    [  116s] make[1]: Entering directory '/home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/bpf'
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMDemangle.a
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMSupport.a
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMTargetParser.a
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMBinaryFormat.a
    (...)
  - commit 4ed92da
  - iommu/tegra241-cmdqv: Read SMMU IDR1.CMDQS instead of
    hardcoding (git-fixes).
  - commit b2958c3
  - eventpoll: don't decrement ep refcount while still holding
    the ep mutex (bsc#1246777 CVE-2025-38349).
  - commit 8cd134d
  - jbd2: fix data-race and null-ptr-deref in
    jbd2_journal_dirty_metadata() (bsc#1246253 CVE-2025-38337).
  - commit c6fbc8a
  - ext4: inline: fix len overflow in ext4_prepare_inline_data
    (bsc#1245976 CVE-2025-38222).
  - commit c641a38
  - ublk: santizize the arguments from userspace when adding a
    device (bsc#1245937 CVE-2025-38182).
  - commit 89a2a7b
  - __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under
    mount_lock (bsc#1245151 CVE-2025-38058).
  - commit e772035
  - xfs: remove unused trace event xfs_reflink_cow_enospc
    (git-fixes).
  - commit be810e3
  - xfs: remove unused trace event xfs_discard_rtrelax (git-fixes).
  - commit 97feca9
  - xfs: remove unused trace event xfs_log_cil_return (git-fixes).
  - commit f8adb59
  - xfs: change xfs_xattr_class from a TRACE_EVENT() to
    DECLARE_EVENT_CLASS() (git-fixes).
  - commit 9d236fc
  - xfs: only create event xfs_file_compat_ioctl when CONFIG_COMPAT
    is configure (git-fixes).
  - commit 9c39d8c
  - xfs: remove usused xfs_end_io_direct events (git-fixes).
  - commit 60f358f
  - xfs: remove unused event xfs_pagecache_inval (git-fixes).
  - commit a5b7032
  - xfs: remove unused event xfs_alloc_near_nominleft (git-fixes).
  - commit 78d1acd
  - xfs: remove unused event xfs_alloc_near_error (git-fixes).
  - commit 3b1caf6
  - xfs: remove unused event xfs_attr_node_removename (git-fixes).
  - commit e689919
  - xfs: remove unused xfs_attr events (git-fixes).
  - commit 950fc00
  - xfs: remove unused trace event xfs_attr_rmtval_set (git-fixes).
  - commit 096be3d
  - xfs: remove unused xfs_reflink_compare_extents events
    (git-fixes).
  - commit 4ed410c
  - xfs: remove unused event xfs_ioctl_clone (git-fixes).
  - commit 1ca6b2f
  - xfs: remove unused event xlog_iclog_want_sync (git-fixes).
  - commit c429e69
  - xfs: remove unused trace event xfs_attr_remove_iter_return
    (git-fixes).
  - commit 82f668d
  - NFSD: detect mismatch of file handle and delegation stateid
    in OPEN op (git-fixes).
  - commit 4e26ab2
  - nfsd: handle get_client_locked() failure in
    nfsd4_setclientid_confirm() (git-fixes).
  - commit 5f5b227
  - x86/fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct() (git-fixes).
  - commit 5286ce5
  - x86/fpu: Fix guest FPU state buffer allocation size (git-fixes).
  - commit fcdd18c
  - x86/fpu/xstate: Fix inconsistencies in guest FPU xfeatures (git-fixes).
  - commit 3c77f80
  - x86/headers: Replace __ASSEMBLY__ with __ASSEMBLER__ in UAPI headers (git-fixes).
  - commit d331bca
  - x86/smpboot: Fix INIT delay assignment for extended Intel Families (git-fixes).
  - commit fa3f890
  - x86/fpu: Fully optimize out WARN_ON_FPU() (git-fixes).
  - commit 44d216b
  - x86/percpu: Disable named address spaces for UBSAN_BOOL with KASAN  for GCC < 14.2 (git-fixes).
  - commit 495301f
  - x86/nmi: Add an emergency handler in nmi_desc & use it in nmi_shootdown_cpus() (git-fixes).
  - commit 62f7c35
  - x86/locking: Use ALT_OUTPUT_SP() for percpu_{,try_}cmpxchg{64,128}_op() (git-fixes).
  - commit a3223dc
  - x86/boot: Sanitize boot params before parsing command line (git-fixes).
  - commit fa10e4c
  - x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (git-fixes).
  - commit c364173
  - x86/platform/olpc: Remove unused variable 'len' in olpc_dt_compatible_match() (git-fixes).
  - commit 6fe089b
  - x86/fred/signal: Prevent immediate repeat of single step trap on return from SIGTRAP handler (git-fixes).
  - commit 8aa4767
  - x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1 (git-fixes).
  - commit 9f24ef0
  - x86/Kconfig: Always enable ARCH_SPARSEMEM_ENABLE (git-fixes).
  - commit 1378c6a
  - Refresh
    patches.suse/RISC-V-Add-defines-for-the-SBI-nested-acceleration-e.patch.
    Fix metadata for the RISC-V patch.
  - commit 7fb7430
  - Refresh patches.suse/x86-entry-Add-__init-to-ia32_emulation_override_cmdline.patch.
  - commit 7b16eb0
  - Update patches.suse/vfs-add-super_operations-get_inode_dev
    (bsc#927455 bsc#1246450).
  - commit c096336

++++ kernel-rt:

  - selftests/bpf: Remove test_skb_cgroup_id.sh from TEST_PROGS
    Fix the following BPF selftests build error:
    [  183s] make[1]: Entering directory '/home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/bpf'
    [  183s] rsync -a --copy-unsafe-links test_kmod.sh test_xdp_redirect.sh test_xdp_redirect_multi.sh test_xdp_meta.sh test_tunnel.sh test_lwt_seg6local.sh test_lirc_mode2.sh test_skb_cgroup_id.sh test_flow_dissector.sh test_xdp_vlan_mode_generic.sh test_xdp_vlan_mode_native.sh test_lwt_ip_encap.sh test_tcp_check_syncookie.sh test_tc_tunnel.sh test_tc_edt.sh test_xdping.sh test_bpftool_build.sh test_bpftool.sh test_bpftool_metadata.sh test_doc_build.sh test_xsk.sh test_xdp_features.sh /home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/kselftest_install/bpf/
    [  183s] rsync: [sender] link_stat "/home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/bpf/test_skb_cgroup_id.sh" failed: No such file or directory (2)
    [  183s] rsync error: some files/attrs were not transferred (see previous errors) (code 23) at main.c(1338) [sender=3.4.1]
  - commit 7aa88b9
  - selftests/bpf: Support dynamically linking LLVM if static is not available
    Fix the following BPF selftests build error:
    [  116s] make[1]: Entering directory '/home/abuild/rpmbuild/BUILD/kselftests-bpf-6.12.0-build/tools/testing/selftests/bpf'
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMDemangle.a
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMSupport.a
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMTargetParser.a
    [  116s] llvm-config: error: missing: /usr/lib64/libLLVMBinaryFormat.a
    (...)
  - commit 4ed92da
  - iommu/tegra241-cmdqv: Read SMMU IDR1.CMDQS instead of
    hardcoding (git-fixes).
  - commit b2958c3
  - eventpoll: don't decrement ep refcount while still holding
    the ep mutex (bsc#1246777 CVE-2025-38349).
  - commit 8cd134d
  - jbd2: fix data-race and null-ptr-deref in
    jbd2_journal_dirty_metadata() (bsc#1246253 CVE-2025-38337).
  - commit c6fbc8a
  - ext4: inline: fix len overflow in ext4_prepare_inline_data
    (bsc#1245976 CVE-2025-38222).
  - commit c641a38
  - ublk: santizize the arguments from userspace when adding a
    device (bsc#1245937 CVE-2025-38182).
  - commit 89a2a7b
  - __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under
    mount_lock (bsc#1245151 CVE-2025-38058).
  - commit e772035
  - xfs: remove unused trace event xfs_reflink_cow_enospc
    (git-fixes).
  - commit be810e3
  - xfs: remove unused trace event xfs_discard_rtrelax (git-fixes).
  - commit 97feca9
  - xfs: remove unused trace event xfs_log_cil_return (git-fixes).
  - commit f8adb59
  - xfs: change xfs_xattr_class from a TRACE_EVENT() to
    DECLARE_EVENT_CLASS() (git-fixes).
  - commit 9d236fc
  - xfs: only create event xfs_file_compat_ioctl when CONFIG_COMPAT
    is configure (git-fixes).
  - commit 9c39d8c
  - xfs: remove usused xfs_end_io_direct events (git-fixes).
  - commit 60f358f
  - xfs: remove unused event xfs_pagecache_inval (git-fixes).
  - commit a5b7032
  - xfs: remove unused event xfs_alloc_near_nominleft (git-fixes).
  - commit 78d1acd
  - xfs: remove unused event xfs_alloc_near_error (git-fixes).
  - commit 3b1caf6
  - xfs: remove unused event xfs_attr_node_removename (git-fixes).
  - commit e689919
  - xfs: remove unused xfs_attr events (git-fixes).
  - commit 950fc00
  - xfs: remove unused trace event xfs_attr_rmtval_set (git-fixes).
  - commit 096be3d
  - xfs: remove unused xfs_reflink_compare_extents events
    (git-fixes).
  - commit 4ed410c
  - xfs: remove unused event xfs_ioctl_clone (git-fixes).
  - commit 1ca6b2f
  - xfs: remove unused event xlog_iclog_want_sync (git-fixes).
  - commit c429e69
  - xfs: remove unused trace event xfs_attr_remove_iter_return
    (git-fixes).
  - commit 82f668d
  - NFSD: detect mismatch of file handle and delegation stateid
    in OPEN op (git-fixes).
  - commit 4e26ab2
  - nfsd: handle get_client_locked() failure in
    nfsd4_setclientid_confirm() (git-fixes).
  - commit 5f5b227
  - x86/fpu: Avoid copying dynamic FP state from init_task in arch_dup_task_struct() (git-fixes).
  - commit 5286ce5
  - x86/fpu: Fix guest FPU state buffer allocation size (git-fixes).
  - commit fcdd18c
  - x86/fpu/xstate: Fix inconsistencies in guest FPU xfeatures (git-fixes).
  - commit 3c77f80
  - x86/headers: Replace __ASSEMBLY__ with __ASSEMBLER__ in UAPI headers (git-fixes).
  - commit d331bca
  - x86/smpboot: Fix INIT delay assignment for extended Intel Families (git-fixes).
  - commit fa3f890
  - x86/fpu: Fully optimize out WARN_ON_FPU() (git-fixes).
  - commit 44d216b
  - x86/percpu: Disable named address spaces for UBSAN_BOOL with KASAN  for GCC < 14.2 (git-fixes).
  - commit 495301f
  - x86/nmi: Add an emergency handler in nmi_desc & use it in nmi_shootdown_cpus() (git-fixes).
  - commit 62f7c35
  - x86/locking: Use ALT_OUTPUT_SP() for percpu_{,try_}cmpxchg{64,128}_op() (git-fixes).
  - commit a3223dc
  - x86/boot: Sanitize boot params before parsing command line (git-fixes).
  - commit fa10e4c
  - x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (git-fixes).
  - commit c364173
  - x86/platform/olpc: Remove unused variable 'len' in olpc_dt_compatible_match() (git-fixes).
  - commit 6fe089b
  - x86/fred/signal: Prevent immediate repeat of single step trap on return from SIGTRAP handler (git-fixes).
  - commit 8aa4767
  - x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1 (git-fixes).
  - commit 9f24ef0
  - x86/Kconfig: Always enable ARCH_SPARSEMEM_ENABLE (git-fixes).
  - commit 1378c6a
  - Refresh
    patches.suse/RISC-V-Add-defines-for-the-SBI-nested-acceleration-e.patch.
    Fix metadata for the RISC-V patch.
  - commit 7fb7430
  - Refresh patches.suse/x86-entry-Add-__init-to-ia32_emulation_override_cmdline.patch.
  - commit 7b16eb0
  - Update patches.suse/vfs-add-super_operations-get_inode_dev
    (bsc#927455 bsc#1246450).
  - commit c096336

++++ opensuse-migration-tool:

  - Update to version 20250729.4ed6ec5:
    * Add a screen to disable 3rd party repos
    * Add post-migration script support #30
    * Drop --pre-release flag completely

------------------------------------------------------------------
------------------  2025-7-28  -  Jul 28 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Update test-image-disk-simple integration test
    Update slfo/test-image-disk-simple. Add more space for
    flake testing and add a user to test flakes for non root

++++ kernel-default:

  - Refresh patches.suse/padding-for-more-cgroup-controllers.patch.
    SUSE developers may build our kernel with customized configs. We don't
    know how many controllers they enable and this may run over the limit in
    BUILD_BUG_ON because of the added padding. Relax BUILD_BUG_ON condition
    to only look at actually used controllers (the effective boundary in our
    kernel).
  - commit 44a41b0
  - sprintf.h: mask additional include (git-fixes).
  - commit 3c155f3
  - sprintf.h requires stdarg.h (git-fixes).
  - commit 4e2dd00
  - btrfs: fix non-empty delayed iputs list on unmount due to
    async workers (git-fixes).
  - commit bd1213b
  - btrfs: record new subvolume in parent dir earlier to avoid
    dir logging races (git-fixes).
  - commit bb20dcf
  - btrfs: fix assertion when building free space tree (git-fixes).
  - commit 9c045a8
  - btrfs: fix iteration of extrefs during log replay (bsc#1247031
    CVE-2025-38382).
  - commit e093d49
  - btrfs: fix missing error handling when searching for inode
    refs during log replay (git-fixes).
  - commit fb9d68c
  - kabi: Hide adding of u64 to devlink_param_type (jsc#PED-12745).
  - commit 4d9651f

++++ kernel-rt:

  - Refresh patches.suse/padding-for-more-cgroup-controllers.patch.
    SUSE developers may build our kernel with customized configs. We don't
    know how many controllers they enable and this may run over the limit in
    BUILD_BUG_ON because of the added padding. Relax BUILD_BUG_ON condition
    to only look at actually used controllers (the effective boundary in our
    kernel).
  - commit 44a41b0
  - sprintf.h: mask additional include (git-fixes).
  - commit 3c155f3
  - sprintf.h requires stdarg.h (git-fixes).
  - commit 4e2dd00
  - btrfs: fix non-empty delayed iputs list on unmount due to
    async workers (git-fixes).
  - commit bd1213b
  - btrfs: record new subvolume in parent dir earlier to avoid
    dir logging races (git-fixes).
  - commit bb20dcf
  - btrfs: fix assertion when building free space tree (git-fixes).
  - commit 9c045a8
  - btrfs: fix iteration of extrefs during log replay (bsc#1247031
    CVE-2025-38382).
  - commit e093d49
  - btrfs: fix missing error handling when searching for inode
    refs during log replay (git-fixes).
  - commit fb9d68c
  - kabi: Hide adding of u64 to devlink_param_type (jsc#PED-12745).
  - commit 4d9651f

++++ gcc15:

  - Update to GCC 15 branch head, 15.1.1+gitt10077
  - Fixes PR120714, RISC-V: incorrect frame pointer CFA address for
    stack-clash protection loops

++++ harfbuzz:

  - Update to version 11.3.3:
    + Fix bug in vertical shaping of fonts without the vmtx table.

++++ nvidia-open-driver-G06-signed:

  - update CUDA variant to 580.65.06, which addresses various security
    issues:
    * CVE-2025-23277 (bsc#1247528)
    * CVE-2025-23278 (bsc#1247529)
    * CVE-2025-23286 (bsc#1247530)
    * CVE-2025-23283 (bsc#1247531)
    * CVE-2025-23279 (bsc#1247532)

++++ virt-manager:

  - Add support for creating TDX guests in virt-install (jsc#PED-9265)
    053-virtinst-add-support-for-creating-TDX-guests.patch

------------------------------------------------------------------
------------------  2025-7-27  -  Jul 27 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Revert "RISC-V: KVM: Allow Smnpm and Ssnpm extensions for guests"
    This reverts commit 5fc44fd9addf2ae400bcc37ae75c718d86dafcaa.
    Requires support for Smnpm and Ssnpm extensions which is not present.
  - commit 2f49da4
  - i2c: qup: jump out of the loop in case of timeout (git-fixes).
  - i2c: virtio: Avoid hang by using interruptible completion wait
    (git-fixes).
  - i2c: tegra: Fix reset error handling with ACPI (git-fixes).
  - commit d23cb51

++++ kernel-rt:

  - Revert "RISC-V: KVM: Allow Smnpm and Ssnpm extensions for guests"
    This reverts commit 5fc44fd9addf2ae400bcc37ae75c718d86dafcaa.
    Requires support for Smnpm and Ssnpm extensions which is not present.
  - commit 2f49da4
  - i2c: qup: jump out of the loop in case of timeout (git-fixes).
  - i2c: virtio: Avoid hang by using interruptible completion wait
    (git-fixes).
  - i2c: tegra: Fix reset error handling with ACPI (git-fixes).
  - commit d23cb51

------------------------------------------------------------------
------------------  2025-7-26  -  Jul 26 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - RISC-V: Add defines for the SBI nested acceleration extension
    (jsc#PED-348).
  - commit 7bb7585
  - drm/xe: Fix build without debugfs (git-fixes).
  - drm/i915/display: Fix dma_fence_wait_timeout() return value
    handling (git-fixes).
  - commit 04fc7cf

++++ kernel-rt:

  - RISC-V: Add defines for the SBI nested acceleration extension
    (jsc#PED-348).
  - commit 7bb7585
  - drm/xe: Fix build without debugfs (git-fixes).
  - drm/i915/display: Fix dma_fence_wait_timeout() return value
    handling (git-fixes).
  - commit 04fc7cf

------------------------------------------------------------------
------------------  2025-7-25  -  Jul 25 2025  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update version to 10.5.1
    + Fix issue with picking up configured server names from the
    regionsrv config file. Previously only IP addresses were collected
    + Update scriptlet for package uninstall to avoid issues in the
    build service

++++ crypto-policies:

  - Update to version 20250425.9267dee:
    * openssl: fix mistakes in integrity-only cipher definitions
    * NO-PQ, cryptopolicies: add experimental value suppression
    * nss: add mlkem768x25519 and mlkem768secp256r1
    * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY
    * TEST-PQ, openssh: add support for MLKEM768 key_exchange
    * LEGACY: drop cipher@pkcs12 = SEED-CBC
    * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes
    * nss: TLS-REQUIRE-EMS in FIPS
    * DEFAULT: disable RSA key exchange
    * LEGACY: disable sign = *-SHA1
    * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768
    * Removed patches fixed upstream:
  - crypto-policies-pylint.patch
    * Rebased patches:
  - crypto-policies-nss.patch

++++ python-kiwi:

  - Catch potential exceptions from pathlib.Path.mkdir
    Creating a directory can fail, we should catch this error
    instead of ending up in a stack trace

++++ fwupd:

  - drop unneeded gpgme build dependency. GPG support is provided
    with libjcat

++++ grub2:

  - Fix CVE-2024-56738: side-channel attack due to not constant-time
    algorithm in grub_crypto_memcmp (bsc#1234959)
    * grub2-constant-time-grub_crypto_memcmp.patch

++++ kernel-default:

  - btrfs: fix a race between renames and directory logging
    (bsc#1247023 CVE-2025-38365).
  - commit 82d2bad
  - btrfs: fix use-after-free when COWing tree bock and tracing
    is enabled (bsc#1235645 CVE-2024-56759).
  - commit bd41b6c
  - nvme-tcp: sanitize request list handling (CVE-2026-38264
    bsc#1246387).
  - commit 4fae28c
  - cpufreq: amd-pstate: Remove unnecessary driver_lock in set_boost
    (bsc#1244812 CVE-2025-38038).
  - Refresh patches.suse/cpufreq-amd-pstate-Overhaul-locking.patch.
  - commit 9e52e61
  - KVM: arm64: Tear down vGIC on failed vCPU creation
    (CVE-2025-37849 bsc#1243000).
  - commit 38855cd
  - drm/xe/pf: Prepare to stop SR-IOV support prior GT reset
    (git-fixes).
  - commit 71e9c4e
  - resource: fix false warning in __request_region() (git-fixes).
  - ASoC: mediatek: mt8365-dai-i2s: pass correct size to
    mt8365_dai_set_priv (git-fixes).
  - ALSA: hda/realtek: Fix mute LED mask on HP OMEN 16 laptop
    (git-fixes).
  - can: netlink: can_changelink(): fix NULL pointer deref of
    struct can_priv::do_set_mode (git-fixes).
  - bus: fsl-mc: Fix potential double device reference in
    fsl_mc_get_endpoint() (git-fixes).
  - i2c: omap: Fix an error handling path in omap_i2c_probe()
    (git-fixes).
  - i2c: omap: Handle omap_i2c_init() errors in omap_i2c_probe()
    (git-fixes).
  - USB: serial: option: add Telit Cinterion FE910C04 (ECM)
    composition (stable-fixes).
  - USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI
    (stable-fixes).
  - USB: serial: option: add Foxconn T99W640 (stable-fixes).
  - iio: common: st_sensors: Fix use of uninitialize device structs
    (stable-fixes).
  - iio: adc: max1363: Reorder mode_list[] entries (stable-fixes).
  - iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[]
    (stable-fixes).
  - drm/xe/mocs: Initialize MOCS index early (stable-fixes).
  - drm/amdgpu: Increase reset counter only on success
    (stable-fixes).
  - drm/amd/display: Disable CRTC degamma LUT for DCN401
    (stable-fixes).
  - drm/amd/display: Free memory allocation (stable-fixes).
  - ALSA: hda/realtek: Add quirk for ASUS ROG Strix G712LWS
    (stable-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-r0xxx
    (stable-fixes).
  - HID: core: do not bypass hid_hw_raw_request (stable-fixes).
  - HID: core: ensure the allocated report buffer can contain the
    reserved report ID (stable-fixes).
  - i2c: omap: Fix an error handling path in omap_i2c_probe()
    (git-fixes).
  - i2c: omap: fix deprecated of_property_read_bool() use
    (git-fixes).
  - i2c: omap: Add support for setting mux (stable-fixes).
  - drm/xe/pf: Move VFs reprovisioning to worker (stable-fixes).
  - drm/xe/pf: Sanitize VF scratch registers on FLR (stable-fixes).
  - commit ad41c3a
  - mm: userfaultfd: fix race of userfaultfd_move and swap cache
    (CVE-2025-38242 bsc#1246176).
  - commit 04ed915

++++ kernel-firmware-amdgpu:

  - Update to version 20250725 (git commit 4bb152fb4405):
    * amdgpu: update dmcub fw for dcn314

++++ kernel-rt:

  - btrfs: fix a race between renames and directory logging
    (bsc#1247023 CVE-2025-38365).
  - commit 82d2bad
  - btrfs: fix use-after-free when COWing tree bock and tracing
    is enabled (bsc#1235645 CVE-2024-56759).
  - commit bd41b6c
  - nvme-tcp: sanitize request list handling (CVE-2026-38264
    bsc#1246387).
  - commit 4fae28c
  - cpufreq: amd-pstate: Remove unnecessary driver_lock in set_boost
    (bsc#1244812 CVE-2025-38038).
  - Refresh patches.suse/cpufreq-amd-pstate-Overhaul-locking.patch.
  - commit 9e52e61
  - KVM: arm64: Tear down vGIC on failed vCPU creation
    (CVE-2025-37849 bsc#1243000).
  - commit 38855cd
  - drm/xe/pf: Prepare to stop SR-IOV support prior GT reset
    (git-fixes).
  - commit 71e9c4e
  - resource: fix false warning in __request_region() (git-fixes).
  - ASoC: mediatek: mt8365-dai-i2s: pass correct size to
    mt8365_dai_set_priv (git-fixes).
  - ALSA: hda/realtek: Fix mute LED mask on HP OMEN 16 laptop
    (git-fixes).
  - can: netlink: can_changelink(): fix NULL pointer deref of
    struct can_priv::do_set_mode (git-fixes).
  - bus: fsl-mc: Fix potential double device reference in
    fsl_mc_get_endpoint() (git-fixes).
  - i2c: omap: Fix an error handling path in omap_i2c_probe()
    (git-fixes).
  - i2c: omap: Handle omap_i2c_init() errors in omap_i2c_probe()
    (git-fixes).
  - USB: serial: option: add Telit Cinterion FE910C04 (ECM)
    composition (stable-fixes).
  - USB: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI
    (stable-fixes).
  - USB: serial: option: add Foxconn T99W640 (stable-fixes).
  - iio: common: st_sensors: Fix use of uninitialize device structs
    (stable-fixes).
  - iio: adc: max1363: Reorder mode_list[] entries (stable-fixes).
  - iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[]
    (stable-fixes).
  - drm/xe/mocs: Initialize MOCS index early (stable-fixes).
  - drm/amdgpu: Increase reset counter only on success
    (stable-fixes).
  - drm/amd/display: Disable CRTC degamma LUT for DCN401
    (stable-fixes).
  - drm/amd/display: Free memory allocation (stable-fixes).
  - ALSA: hda/realtek: Add quirk for ASUS ROG Strix G712LWS
    (stable-fixes).
  - ALSA: hda/realtek - Fix mute LED for HP Victus 16-r0xxx
    (stable-fixes).
  - HID: core: do not bypass hid_hw_raw_request (stable-fixes).
  - HID: core: ensure the allocated report buffer can contain the
    reserved report ID (stable-fixes).
  - i2c: omap: Fix an error handling path in omap_i2c_probe()
    (git-fixes).
  - i2c: omap: fix deprecated of_property_read_bool() use
    (git-fixes).
  - i2c: omap: Add support for setting mux (stable-fixes).
  - drm/xe/pf: Move VFs reprovisioning to worker (stable-fixes).
  - drm/xe/pf: Sanitize VF scratch registers on FLR (stable-fixes).
  - commit ad41c3a
  - mm: userfaultfd: fix race of userfaultfd_move and swap cache
    (CVE-2025-38242 bsc#1246176).
  - commit 04ed915

++++ samba:

  - adjust gpgme build dependency for future-proofing

++++ wpa_supplicant:

  - Build wpa_gui with qt6 instead of obsolete qt5
    [+ 0001-wpa_gui-Port-to-Qt6.patch]
  - Update build config:
    * Enable 802.11ax support

------------------------------------------------------------------
------------------  2025-7-24  -  Jul 24 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - U_loader_wayland-Fix-missing-timespec.h-include.patch
    * fixes build with wayland-protocols 1.45

++++ Mesa-drivers:

  - U_loader_wayland-Fix-missing-timespec.h-include.patch
    * fixes build with wayland-protocols 1.45

++++ afterburn:

  - Update to version 5.9.0:
    * cargo: Afterburn release 5.9.0
    * docs/release-notes: update for release 5.9.0
    * cargo: update dependencies
    * Add TMT test structure and basic smoke test
    * build(deps): bump openssl from 0.10.72 to 0.10.73
    * build(deps): bump reqwest from 0.12.15 to 0.12.18
    * docs/release-notes: Update changelog entry
    * dracut: Return 255 in module-setup
    * oraclecloud: add release note and move base URL to constant
    * oraclecloud: implement oraclecloud provider
    * build(deps): bump nix from 0.29.0 to 0.30.1
    * build(deps): bump zbus from 5.7.0 to 5.7.1
    * build(deps): bump serde-xml-rs from 0.6.0 to 0.8.1
    * build(deps): bump ipnetwork from 0.20.0 to 0.21.1
    * build(deps): bump clap from 4.5.38 to 4.5.39

++++ container-selinux:

  - Add workaround for rootless docker iptables AVCs (bsc#1246348)
    adding rootless-docker_iptables.patch

++++ python-kiwi:

  - Bump version: 10.2.28 → 10.2.29
  - Fix return from repart stage
    If we return from the repart stage it's important to wait
    for the root device to appear. This is because the device
    setup from udev might still be held back due to a former
    lock on the device. This means if we return fast after
    locking for example when check_repart_possible() quickly
    finds out that it's not possible, then udev has not yet
    got the time to create the device nodes.
    This Fixes #2863

++++ glibc:

  - regcomp-double-free.patch: posix: Fix double-free after allocation
    failure in regcomp (CVE-2025-8058, bsc#1246965, BZ #33185)

++++ gstreamer:

  - Update to version 1.26.4:
    + Highlighted bugfixes in 1.26.4:
  - adaptivedemux2: Fixed reverse playback
  - d3d12screencapture: Add support for monitor add/remove in
    device provider
  - rtmp2src: various fixes to make it play back AWS medialive
    streams
  - rtph265pay: add profile-id, tier-flag, and level-id to output
    rtp caps
  - vp9parse: Fix handling of spatial SVC decoding
  - vtenc: Fix negotiation failure with profile=main-422-10
  - gtk4paintablesink: Add YCbCr memory texture formats and other
    improvements
  - livekit: add room-timeout
  - mp4mux: add TAI timestamp muxing support
  - rtpbin2: fix various race conditions, plus other bug fixes
    and performance improvements
  - threadshare: add a ts-rtpdtmfsrc element, implement run-time
    input switching in ts-intersrc
  - webrtcsink: fix deadlock on error setting remote description
    and other fixes.
  - cerbero: WiX installer: fix missing props files in the MSI
    packages
  - smaller macOS/iOS package sizes
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - tracers: Fix deadlock in latency tracer
  - Fix various valgrind/test errors when GST_DEBUG is enabled
  - More valgrind and test fixes
  - Various ASAN fixes

++++ gstreamer-plugins-base:

  - Update to version 1.26.4:
    + Revert "streamsynchronizer: Consider streams having received
    stream-start as waiting"
    + alsa: free conf cache under valgrind
    + gst-device-monitor: Fix caps filter splitting
    + Fix various valgrind/test errors when GST_DEBUG is enabled
    + More valgrind and test fixes
    + Various ASAN fixes

++++ kdump:

  - upgrade to version 2.1.5
    * kdumptool calibrate: use kernel flavour from the
    kdump kernel (jsc#PED-12971)
    * order kdump-commandline.service after kdump.service
    * updated documentation (bsc#1246908)

++++ kernel-default:

  - x86/fpu: Refactor xfeature bitmask update code for sigframe XSAVE (git-fixes).
  - commit fdfb535
  - kABI workaround for drm_gem.h (git-fixes).
  - commit b3f8c43
  - x86/microcode: Consolidate the loader enablement checking (git-fixes).
  - commit a281c51
  - x86/pkeys: Simplify PKRU update in signal frame (git-fixes).
  - commit 7f493bf
  - x86/mm/pat: don't collapse pages without PSE set (git-fixes).
  - commit a309aa1
  - x86/traps: Initialize DR6 by writing its architectural reset value (git-fixes).
  - commit b9a8d7c
  - x86/mce: Don't remove sysfs if thresholding sysfs init fails (git-fixes).
  - commit 6b9b4dc
  - x86/mce: Ensure user polling settings are honored when restarting  timer (git-fixes).
  - commit dd99169
  - x86/mce/amd: Add default names for MCA banks and blocks (git-fixes).
  - commit 8cf89c0
  - drivers: base: handle module_kobject creation (git-fixes).
  - kernel: globalize lookup_or_create_module_kobject()
    (stable-fixes).
  - kernel: param: rename locate_module_kobject (stable-fixes).
  - commit 443c294
  - bus: firewall: Fix missing static inline annotations for stubs
    (git-fixes).
  - drm/gem: Internally test import_attach for imported objects
    (git-fixes).
  - commit 883c447
  - mailbox: Not protect module_put with spin_lock_irqsave
    (stable-fixes).
  - of: unittest: Unlock on error in unittest_data_add()
    (git-fixes).
  - objtool, lkdtm: Obfuscate the do_nothing() pointer
    (stable-fixes).
  - objtool, regulator: rk808: Remove potential undefined behavior
    in rk806_set_mode_dcdc() (stable-fixes).
  - objtool, ASoC: codecs: wcd934x: Remove potential undefined
    behavior in wcd934x_slim_irq_handler() (stable-fixes).
  - mailbox: pcc: Use acpi_os_ioremap() instead of ioremap()
    (stable-fixes).
  - mailbox: pcc: Always clear the platform ack interrupt first
    (stable-fixes).
  - mailbox: pcc: Fix the possible race in updation of chan_in_use
    flag (stable-fixes).
  - of: resolver: Fix device node refcount leakage in
    of_resolve_phandles() (git-fixes).
  - of: resolver: Simplify of_resolve_phandles() using __free()
    (stable-fixes).
  - commit 2842fe3
  - phy: fsl-imx8mq-usb: fix phy_tx_vboost_level_from_property()
    (git-fixes).
  - phy: rockchip: samsung-hdptx: Do no set rk_hdptx_phy->rate in
    case of errors (git-fixes).
  - phy: rockchip: samsung-hdptx: Fix clock ratio setup (git-fixes).
  - PM: EM: use kfree_rcu() to simplify the code (stable-fixes).
  - pm: cpupower: bench: Prevent NULL dereference on malloc failure
    (stable-fixes).
  - commit 0b2b7d3
  - iio: pressure: mprls0025pa: use aligned_s64 for timestamp
    (git-fixes).
  - iio: adc: ad7266: Fix potential timestamp alignment issue
    (git-fixes).
  - iio: adc: ad7768-1: Fix insufficient alignment of timestamp
    (git-fixes).
  - iio: adc: dln2: Use aligned_s64 for timestamp (git-fixes).
  - iio: accel: adxl355: Make timestamp 64-bit aligned using
    aligned_s64 (git-fixes).
  - iio: chemical: pms7003: use aligned_s64 for timestamp
    (git-fixes).
  - iio: chemical: sps30: use aligned_s64 for timestamp (git-fixes).
  - commit c3a47c4
  - drm/i915/dp_mst: Work around Thunderbolt sink disconnect after
    SINK_COUNT_ESI read (stable-fixes).
  - accel/ivpu: Correct DCT interrupt handling (git-fixes).
  - commit af2fdb4
  - accel/ivpu: Fix warning in ivpu_gem_bo_free() (git-fixes).
  - drm/gem: Test for imported GEM buffers with helper
    (stable-fixes).
  - commit bf7255f
  - rpm/kernel-subpackage-spec: Skip brp-strip-debug to avoid file truncation (bsc#1246879)
    Put the same workaround to avoid file truncation of vmlinux and co in
    kernel-default-base package, too.
  - commit 2329734
  - iommu/vt-d: Fix possible circular locking dependency
    (git-fixes).
  - commit b917ee9
  - drm/bridge: ti-sn65dsi86: Remove extra semicolon in
    ti_sn_bridge_probe() (git-fixes).
  - Revert "drm/nouveau: check ioctl command codes better"
    (git-fixes).
  - drm/sched: Remove optimization that causes hang when killing
    dependent jobs (git-fixes).
  - drm/amdgpu: Reset the clear flag in buddy during resume
    (git-fixes).
  - platform/x86: Fix initialization order for
    firmware_attributes_class (git-fixes).
  - platform/x86: ideapad-laptop: Fix kbd backlight not remembered
    among boots (git-fixes).
  - platform/x86: ideapad-laptop: Fix FnLock not remembered among
    boots (git-fixes).
  - platform/mellanox: mlxbf-pmc: Use kstrtobool() to check 0/1
    input (git-fixes).
  - platform/mellanox: mlxbf-pmc: Validate event/enable input
    (git-fixes).
  - platform/mellanox: mlxbf-pmc: Remove newline char from event
    name input (git-fixes).
  - commit e77a634

++++ kernel-rt:

  - x86/fpu: Refactor xfeature bitmask update code for sigframe XSAVE (git-fixes).
  - commit fdfb535
  - kABI workaround for drm_gem.h (git-fixes).
  - commit b3f8c43
  - x86/microcode: Consolidate the loader enablement checking (git-fixes).
  - commit a281c51
  - x86/pkeys: Simplify PKRU update in signal frame (git-fixes).
  - commit 7f493bf
  - x86/mm/pat: don't collapse pages without PSE set (git-fixes).
  - commit a309aa1
  - x86/traps: Initialize DR6 by writing its architectural reset value (git-fixes).
  - commit b9a8d7c
  - x86/mce: Don't remove sysfs if thresholding sysfs init fails (git-fixes).
  - commit 6b9b4dc
  - x86/mce: Ensure user polling settings are honored when restarting  timer (git-fixes).
  - commit dd99169
  - x86/mce/amd: Add default names for MCA banks and blocks (git-fixes).
  - commit 8cf89c0
  - drivers: base: handle module_kobject creation (git-fixes).
  - kernel: globalize lookup_or_create_module_kobject()
    (stable-fixes).
  - kernel: param: rename locate_module_kobject (stable-fixes).
  - commit 443c294
  - bus: firewall: Fix missing static inline annotations for stubs
    (git-fixes).
  - drm/gem: Internally test import_attach for imported objects
    (git-fixes).
  - commit 883c447
  - mailbox: Not protect module_put with spin_lock_irqsave
    (stable-fixes).
  - of: unittest: Unlock on error in unittest_data_add()
    (git-fixes).
  - objtool, lkdtm: Obfuscate the do_nothing() pointer
    (stable-fixes).
  - objtool, regulator: rk808: Remove potential undefined behavior
    in rk806_set_mode_dcdc() (stable-fixes).
  - objtool, ASoC: codecs: wcd934x: Remove potential undefined
    behavior in wcd934x_slim_irq_handler() (stable-fixes).
  - mailbox: pcc: Use acpi_os_ioremap() instead of ioremap()
    (stable-fixes).
  - mailbox: pcc: Always clear the platform ack interrupt first
    (stable-fixes).
  - mailbox: pcc: Fix the possible race in updation of chan_in_use
    flag (stable-fixes).
  - of: resolver: Fix device node refcount leakage in
    of_resolve_phandles() (git-fixes).
  - of: resolver: Simplify of_resolve_phandles() using __free()
    (stable-fixes).
  - commit 2842fe3
  - phy: fsl-imx8mq-usb: fix phy_tx_vboost_level_from_property()
    (git-fixes).
  - phy: rockchip: samsung-hdptx: Do no set rk_hdptx_phy->rate in
    case of errors (git-fixes).
  - phy: rockchip: samsung-hdptx: Fix clock ratio setup (git-fixes).
  - PM: EM: use kfree_rcu() to simplify the code (stable-fixes).
  - pm: cpupower: bench: Prevent NULL dereference on malloc failure
    (stable-fixes).
  - commit 0b2b7d3
  - iio: pressure: mprls0025pa: use aligned_s64 for timestamp
    (git-fixes).
  - iio: adc: ad7266: Fix potential timestamp alignment issue
    (git-fixes).
  - iio: adc: ad7768-1: Fix insufficient alignment of timestamp
    (git-fixes).
  - iio: adc: dln2: Use aligned_s64 for timestamp (git-fixes).
  - iio: accel: adxl355: Make timestamp 64-bit aligned using
    aligned_s64 (git-fixes).
  - iio: chemical: pms7003: use aligned_s64 for timestamp
    (git-fixes).
  - iio: chemical: sps30: use aligned_s64 for timestamp (git-fixes).
  - commit c3a47c4
  - drm/i915/dp_mst: Work around Thunderbolt sink disconnect after
    SINK_COUNT_ESI read (stable-fixes).
  - accel/ivpu: Correct DCT interrupt handling (git-fixes).
  - commit af2fdb4
  - accel/ivpu: Fix warning in ivpu_gem_bo_free() (git-fixes).
  - drm/gem: Test for imported GEM buffers with helper
    (stable-fixes).
  - commit bf7255f
  - rpm/kernel-subpackage-spec: Skip brp-strip-debug to avoid file truncation (bsc#1246879)
    Put the same workaround to avoid file truncation of vmlinux and co in
    kernel-default-base package, too.
  - commit 2329734
  - iommu/vt-d: Fix possible circular locking dependency
    (git-fixes).
  - commit b917ee9
  - drm/bridge: ti-sn65dsi86: Remove extra semicolon in
    ti_sn_bridge_probe() (git-fixes).
  - Revert "drm/nouveau: check ioctl command codes better"
    (git-fixes).
  - drm/sched: Remove optimization that causes hang when killing
    dependent jobs (git-fixes).
  - drm/amdgpu: Reset the clear flag in buddy during resume
    (git-fixes).
  - platform/x86: Fix initialization order for
    firmware_attributes_class (git-fixes).
  - platform/x86: ideapad-laptop: Fix kbd backlight not remembered
    among boots (git-fixes).
  - platform/x86: ideapad-laptop: Fix FnLock not remembered among
    boots (git-fixes).
  - platform/mellanox: mlxbf-pmc: Use kstrtobool() to check 0/1
    input (git-fixes).
  - platform/mellanox: mlxbf-pmc: Validate event/enable input
    (git-fixes).
  - platform/mellanox: mlxbf-pmc: Remove newline char from event
    name input (git-fixes).
  - commit e77a634

------------------------------------------------------------------
------------------  2025-7-23  -  Jul 23 2025  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update version to 10.5.0
    + Use region server IP addresses to determine Internet access rather
    than a generic address. Region server IP addresses may not be blocked
    in the network construct. (bsc#1245305)

++++ cockpit:

  - Add %postun for firewalld package to ensure the firewall state
    remains as expected

++++ docker:

  - Update to docker-buildx v0.26.1. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.26.1>

++++ transactional-update:

  - Add journalmount.patch to bind mount systemd journal only when
    available

++++ kernel-default:

  - hci_dev centralize extra lock (CVE-2025-38117 bsc#1245695).
  - commit 242b32d
  - rpm/kernel-binary.spec.in: Ignore return code from ksymtypes compare
    When using suse-kabi-tools, the RPM build invokes 'ksymvers compare' to
    compare the resulting symbol CRCs with the reference data. If the values
    differ, it then invokes 'ksymtypes compare' to provide a detailed report
    explaining why the symbols differ. The build expects the latter
    'ksymtypes compare' command to always return zero, even if the two
    compared kABI corpuses are different.
    This is currently the case for 'ksymtypes compare'. However, I plan to
    update the command to return a non-zero code when the comparison detects
    any differences. This should ensure consistent behavior with 'ksymvers
    compare'.
    Since the build uses 'ksymtypes compare' only for more detailed
    diagnostics, ignore its return code.
  - commit 5ac1381
  - net: atm: fix /proc/net/atm/lec handling (CVE-2025-38180
    bsc#1245970).
  - net: atm: add lec_mutex (CVE-2025-38323 bsc#1246473).
  - net: atm: fix /proc/net/atm/lec handling (CVE-2025-38180
    bsc#1245970).
  - net: atm: add lec_mutex (CVE-2025-38323 bsc#1246473).
  - commit 736dcb9
  - Bluetooth: MGMT: Protect mgmt_pending list with its own lock
    (CVE-2025-38117 bsc#1245695).
  - commit 089c9e2
  - arm64: config: Make tpm_tis_spi module build-in (bsc#1246896)
  - commit 9192eb0

++++ kernel-rt:

  - hci_dev centralize extra lock (CVE-2025-38117 bsc#1245695).
  - commit 242b32d
  - rpm/kernel-binary.spec.in: Ignore return code from ksymtypes compare
    When using suse-kabi-tools, the RPM build invokes 'ksymvers compare' to
    compare the resulting symbol CRCs with the reference data. If the values
    differ, it then invokes 'ksymtypes compare' to provide a detailed report
    explaining why the symbols differ. The build expects the latter
    'ksymtypes compare' command to always return zero, even if the two
    compared kABI corpuses are different.
    This is currently the case for 'ksymtypes compare'. However, I plan to
    update the command to return a non-zero code when the comparison detects
    any differences. This should ensure consistent behavior with 'ksymvers
    compare'.
    Since the build uses 'ksymtypes compare' only for more detailed
    diagnostics, ignore its return code.
  - commit 5ac1381
  - net: atm: fix /proc/net/atm/lec handling (CVE-2025-38180
    bsc#1245970).
  - net: atm: add lec_mutex (CVE-2025-38323 bsc#1246473).
  - net: atm: fix /proc/net/atm/lec handling (CVE-2025-38180
    bsc#1245970).
  - net: atm: add lec_mutex (CVE-2025-38323 bsc#1246473).
  - commit 736dcb9
  - Bluetooth: MGMT: Protect mgmt_pending list with its own lock
    (CVE-2025-38117 bsc#1245695).
  - commit 089c9e2
  - arm64: config: Make tpm_tis_spi module build-in (bsc#1246896)
  - commit 9192eb0

++++ kubevirt:

  - Replace/Supercede patch
    Update-module-golang.org-x-net-to-v0.36.0-SECURITY.patch ->
    Update-module-golang.org-x-net-to-v0.38.0-SECURITY.patch (bsc#1238704, bsc#1241772)
  - Rename patch for clarity and consistency
    chore-deps-update-module-golang.org-x-oauth2-to-v0.2.patch ->
    Update-module-golang.org-x-oauth2-to-v0.27.0-SECURITY.patch
  - Update _service file to reference v1.5.2
  - Reorder patches with respect to the newly added patch

++++ libzypp:

  - During installation indicate the backend being used (bsc#1246038)
    If some package actually needs to know, it should test for
    ZYPP_CLASSIC_RPMTRANS being set in the environment.
    Otherwise the transaction is driven by librpm.
  - version 17.37.14 (35)

++++ qemu:

  - Fix bsc#1246566:
    * [roms] seabios: include "pciinit: don't misalign large BARs" (bsc#1246566)

++++ sysuser-tools:

  - disable the buildroot virus scanning, as it needs the vscan user
    this package provides. (bsc#1246878)

------------------------------------------------------------------
------------------  2025-7-22  -  Jul 22 2025  -------------------
------------------------------------------------------------------

++++ cloud-init:

  - Update to version 25.1.3 (bsc#1245401,bsc#1245403)
    + Forward port
  - cloud-init-no-openstack-guess.patch
    + docs: provide example3 for PAM and ssh_pwauth behavior (#27)
    + fix: Make hotplug socket writable only by root (#25) (CVE-2024-11584)
    + fix: Don't attempt to identify non-x86 OpenStack instances (LP: #2069607)
    (CVE-2024-6174)
    From 25.1.2
    + fix: ensure MAAS datasource retries on failure (#6167)

++++ fde-tools:

  - Add fde-tools-bsc1246464-use-default-uefi-boot-path.patch to
    use the default EFI boot path if there is no FILE compoment in
    in the boot entry (bsc#1246464)

++++ fwupd:

  - Update to version 2.0.13:
    + This release adds the following features:
  - Add a daemon config option to ignore efivars free space
  - Add support for glob-aware version comparison requirements
  - Allow targeting specific regions in FMAP when using flashrom
  - Detect static variables and magic numbers during code review
  - Remove the unused hailuck and rts54hid plugins
    + This release fixes the following bugs:
  - Align MTD erase up to the erasesize as necessary
  - Allow parsing IGSC OptionROM when using fwupdtool
  - Allow removing private flags from UEFI capsule devices in quirks
  - Do not copy the vendor for Intel reference ME firmware
  - Do not use an interactive console if stdout is redirected
  - Fix the UEFI self-test when the capsule splash is disabled
  - Get better device information when using PCI-backed MTD devices
  - Get the Intel GPU SKU and SVN when using BMG hardware
  - Make MBIM modem devices emulatable
  - Make sure fwupdtool.exe is available in the Windows PATH
  - Only show the 'Full Disk Encryption Detected' warning when required
  - Set all QCDM modem devices to raw mode when updating
  - Show all devices for fwupdtool get-devices --show-all --force
  - Show correct dbx version if non-Microsoft entries are present
  - Show KEK device attributes in fwupdmgr
  - Use an alternate GUID when the Intel GPU is in recovery mode
  - Use the kernel netlink hotplug socket when there is no Udev
  - Various small changes to speed up startup by 60% and lower RSS by 40%
    + This release adds support for the following hardware:
  - HP USB-C 100W G6 Dock
  - Logitech Bulk Controller pheripherals
  - More MediaTek scaler devices

++++ kernel-default:

  - KVM: TDX: Don't report base TDVMCALLs (git-fixes).
  - commit 486d9e8
  - Documentation: KVM: Fix unexpected unindent warning (git-fixes).
  - commit 1046fef
  - Documentation: KVM: Fix unexpected unindent warnings
    (git-fixes).
  - commit bfc2140
  - kABI fix after Add TDX support for vSphere (jsc#PED-13302).
  - commit a4c3d79
  - s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again
    (git-fixes bsc#1246868).
  - commit 7a6a473
  - KVM: VMX: Ensure unused kvm_tdx_capabilities fields are zeroed
    out (jsc#PED-13302).
  - commit bc9f3cf
  - KVM: TDX: Report supported optional TDVMCALLs in TDX
    capabilities (jsc#PED-13302).
  - commit af1a799
  - KVM: TDX: Exit to userspace for SetupEventNotifyInterrupt
    (jsc#PED-13302).
  - commit b72fb90
  - KVM: TDX: Exit to userspace for GetTdVmCallInfo (jsc#PED-13302).
  - commit 78e8a10
  - KVM: TDX: Handle TDG.VP.VMCALL<GetQuote> (jsc#PED-13302).
  - commit 2d49648
  - KVM: TDX: Add new TDVMCALL status code for unsupported subfuncs
    (jsc#PED-13302).
  - commit 9661c0c
  - KVM: x86: Reject KVM_SET_TSC_KHZ vCPU ioctl for TSC protected
    guest (git-fixes).
  - commit 62d55cd
  - KVM: x86: avoid underflow when scaling TSC frequency
    (git-fixes).
  - commit 38e9775
  - iommu/vt-d: Fix system hang on reboot -f (git-fixes).
  - commit d8aaf21
  - KVM: x86/xen: Allow 'out of range' event channel ports in IRQ
    routing table (git-fixes).
  - commit be0174d
  - KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation
    is in-flight (git-fixes).
  - commit 95b4b81
  - kABI fix after KVM: SVM: Fix SNP AP destroy race with VMRUN
    (git-fixes).
  - commit 48db1ee
  - KVM: SVM: Fix SNP AP destroy race with VMRUN (git-fixes).
  - commit 1cd78e3

++++ kernel-firmware-sound:

  - Update to version 20250721 (git commit d89120bb80fc):
    * cirrus: cs35l41: Add Firmware for various ASUS commercial Laptops using CS35L41 HDA
    * cirrus: cs35l41: Update Firmware for Dell Oasis
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * qcom: Add Audio topology for QCS6490 RB3Gen2

++++ kernel-rt:

  - KVM: TDX: Don't report base TDVMCALLs (git-fixes).
  - commit 486d9e8
  - Documentation: KVM: Fix unexpected unindent warning (git-fixes).
  - commit 1046fef
  - Documentation: KVM: Fix unexpected unindent warnings
    (git-fixes).
  - commit bfc2140
  - kABI fix after Add TDX support for vSphere (jsc#PED-13302).
  - commit a4c3d79
  - s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again
    (git-fixes bsc#1246868).
  - commit 7a6a473
  - KVM: VMX: Ensure unused kvm_tdx_capabilities fields are zeroed
    out (jsc#PED-13302).
  - commit bc9f3cf
  - KVM: TDX: Report supported optional TDVMCALLs in TDX
    capabilities (jsc#PED-13302).
  - commit af1a799
  - KVM: TDX: Exit to userspace for SetupEventNotifyInterrupt
    (jsc#PED-13302).
  - commit b72fb90
  - KVM: TDX: Exit to userspace for GetTdVmCallInfo (jsc#PED-13302).
  - commit 78e8a10
  - KVM: TDX: Handle TDG.VP.VMCALL<GetQuote> (jsc#PED-13302).
  - commit 2d49648
  - KVM: TDX: Add new TDVMCALL status code for unsupported subfuncs
    (jsc#PED-13302).
  - commit 9661c0c
  - KVM: x86: Reject KVM_SET_TSC_KHZ vCPU ioctl for TSC protected
    guest (git-fixes).
  - commit 62d55cd
  - KVM: x86: avoid underflow when scaling TSC frequency
    (git-fixes).
  - commit 38e9775
  - iommu/vt-d: Fix system hang on reboot -f (git-fixes).
  - commit d8aaf21
  - KVM: x86/xen: Allow 'out of range' event channel ports in IRQ
    routing table (git-fixes).
  - commit be0174d
  - KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation
    is in-flight (git-fixes).
  - commit 95b4b81
  - kABI fix after KVM: SVM: Fix SNP AP destroy race with VMRUN
    (git-fixes).
  - commit 48db1ee
  - KVM: SVM: Fix SNP AP destroy race with VMRUN (git-fixes).
  - commit 1cd78e3

++++ libnvme:

  - Update to version 1.11+4.g18b9f8e5:
    * tree: free ctrl attributes when (re)configure ctrl (bsc#1243716)
    * tree: filter tree after scan has completed (bsc#1243716)
    * test/mock: pass thru unknown ioctls
    * linux: fix derive_psk_digest OpenSSL 1.1 version
  - Drop intergrated patches
    * remove 0001-linux-fix-derive_psk_digest-OpenSSL-1.1-version.patch
    * remove 0002-test-mock-pass-thru-unknown-ioctls.patch

++++ libzypp:

  - Workaround 'rpm -vv' leaving scriptlets /var/tmp (bsc#1218459)
  - Verbose log libproxy results if PX_DEBUG=1 is set.
  - BuildRequires:  cmake >= 3.17.
  - version 17.37.13 (35)

++++ nvme-cli:

  - Update to version 2.11+4.g16c450a7:
    * nvme: fix mem leak in nvme copy (bsc#1243716)
    * nvme-print: suppress output when no ctrl is present for list-subsys (bsc#1243716)
    * nvme: extend filter to match device name (bsc#1243716)
    * udev-rules-ontap: switch to queue-depth iopolicy (bsc#1246599)

------------------------------------------------------------------
------------------  2025-7-21  -  Jul 21 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Add cockpit-firewalld package for easily configuring the users
    firewall jsc#PED-13228

++++ docker:

  - Update to docker-buildx v0.26.0. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.26.0>

++++ transactional-update:

  - Version 5.0.7
  - Add sysext compatibility [bsc#1246140]
  - Fix soft-reboot with btrfs subvolume based /etc
  - Sync /etc layers also on soft-reboot
  - Bind mount /run/systemd/journal to allow log calls
    [gh#openSUSE/transactional-update#149]
  - Use rootlesskit instead of fakeroot for tests
  - Small coding style fixes
  - Temporarily disabling the testsuite because it doesn't run in
    the build environment so far

++++ kernel-default:

  - iavf: get rid of the crit lock (CVE-2025-38311 bsc#1246376).
  - iavf: sprinkle netdev_assert_locked() annotations
    (CVE-2025-38311 bsc#1246376).
  - iavf: extract iavf_watchdog_step() out of iavf_watchdog_task()
    (CVE-2025-38311 bsc#1246376).
  - iavf: simplify watchdog_task in terms of adminq task scheduling
    (CVE-2025-38311 bsc#1246376).
  - iavf: centralize watchdog requeueing itself (CVE-2025-38311
    bsc#1246376).
  - net: dsa: b53: do not enable EEE on bcm63xx (CVE-2025-38272
    bsc#1246268).
  - commit 2236e1a
  - kABI workaround for bluetooth hci_dev changes (CVE-2025-38250
    bsc#1246182).
  - commit 9363e74
  - Bluetooth: hci_core: Fix use-after-free in vhci_flush()
    (CVE-2025-38250 bsc#1246182).
  - commit 7979f02
  - tools/hv: fcopy: Fix irregularities with size of ring buffer
    (git-fixes).
  - PCI: hv: Use the correct hypercall for unmasking interrupts
    on nested (git-fixes).
  - x86/hyperv: Expose hv_map_msi_interrupt() (git-fixes).
  - Drivers: hv: Use nested hypercall for post message and signal
    event (git-fixes).
  - x86/hyperv: Clean up hv_map/unmap_interrupt() return values
    (git-fixes).
  - x86/hyperv: Fix usage of cpu_online_mask to get valid cpu
    (git-fixes).
  - PCI: hv: Don't load the driver for baremetal root partition
    (git-fixes).
  - net: mana: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - PCI: hv: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - clocksource: hyper-v: Fix warnings for missing export.h header
    inclusion (git-fixes).
  - x86/hyperv: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - Drivers: hv: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - Drivers: hv: Fix the check for HYPERVISOR_CALLBACK_VECTOR
    (git-fixes).
  - tools/hv: fcopy: Fix incorrect file path conversion (git-fixes).
  - Drivers: hv: Select CONFIG_SYSFB only if EFI is enabled
    (git-fixes).
  - hv_netvsc: Set VF priv_flags to IFF_NO_ADDRCONF before open
    to prevent IPv6 addrconf (git-fixes).
  - commit 6fce57d
  - i2c: stm32f7: unmap DMA mapped buffer (git-fixes).
  - i2c: stm32: fix the device used for the DMA map (git-fixes).
  - usb: hub: Don't try to recover devices lost during warm reset
    (git-fixes).
  - usb: dwc2: gadget: Fix enter to hibernation for UTMI+ PHY
    (git-fixes).
  - usb: musb: fix gadget state on disconnect (git-fixes).
  - thunderbolt: Fix bit masking in tb_dp_port_set_hops()
    (git-fixes).
  - thunderbolt: Fix wake on connect at runtime (git-fixes).
  - pch_uart: Fix dma_sync_sg_for_device() nents value (git-fixes).
  - serial: core: fix OF node leak (git-fixes).
  - comedi: Fix initialization of data for instructions that write
    to subdevice (git-fixes).
  - comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
    (git-fixes).
  - comedi: das6402: Fix bit shift out of bounds (git-fixes).
  - comedi: aio_iiro_16: Fix bit shift out of bounds (git-fixes).
  - comedi: pcl812: Fix bit shift out of bounds (git-fixes).
  - comedi: das16m1: Fix bit shift out of bounds (git-fixes).
  - comedi: Fix some signed shift left operations (git-fixes).
  - comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
    (git-fixes).
  - interconnect: icc-clk: destroy nodes in case of memory
    allocation failures (git-fixes).
  - interconnect: exynos: handle node name allocation failure
    (git-fixes).
  - interconnect: qcom: sc7280: Add missing num_links to xm_pcie3_1
    node (git-fixes).
  - iio: adc: ad7949: use spi_is_bpw_supported() (git-fixes).
  - iio: accel: fxls8962af: Fix use after free in
    fxls8962af_fifo_flush (git-fixes).
  - iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC
    channel maps (git-fixes).
  - iio: adc: stm32-adc: Fix race in installing chained IRQ handler
    (git-fixes).
  - iio: backend: fix out-of-bound write (git-fixes).
  - spi: Add check for 8-bit transfer with 8 IO mode support
    (git-fixes).
  - regmap: fix potential memory leak of regmap_bus (git-fixes).
  - Input: xpad - set correct controller type for Acer NGR200
    (git-fixes).
  - commit efa1e54

++++ kernel-firmware-nvidia:

  - Remove stale *.rpmmoved directories (bsc#1244458)

++++ kernel-firmware-qcom:

  - Remove stale *.rpmmoved directories (bsc#1244458)

++++ kernel-rt:

  - iavf: get rid of the crit lock (CVE-2025-38311 bsc#1246376).
  - iavf: sprinkle netdev_assert_locked() annotations
    (CVE-2025-38311 bsc#1246376).
  - iavf: extract iavf_watchdog_step() out of iavf_watchdog_task()
    (CVE-2025-38311 bsc#1246376).
  - iavf: simplify watchdog_task in terms of adminq task scheduling
    (CVE-2025-38311 bsc#1246376).
  - iavf: centralize watchdog requeueing itself (CVE-2025-38311
    bsc#1246376).
  - net: dsa: b53: do not enable EEE on bcm63xx (CVE-2025-38272
    bsc#1246268).
  - commit 2236e1a
  - kABI workaround for bluetooth hci_dev changes (CVE-2025-38250
    bsc#1246182).
  - commit 9363e74
  - Bluetooth: hci_core: Fix use-after-free in vhci_flush()
    (CVE-2025-38250 bsc#1246182).
  - commit 7979f02
  - tools/hv: fcopy: Fix irregularities with size of ring buffer
    (git-fixes).
  - PCI: hv: Use the correct hypercall for unmasking interrupts
    on nested (git-fixes).
  - x86/hyperv: Expose hv_map_msi_interrupt() (git-fixes).
  - Drivers: hv: Use nested hypercall for post message and signal
    event (git-fixes).
  - x86/hyperv: Clean up hv_map/unmap_interrupt() return values
    (git-fixes).
  - x86/hyperv: Fix usage of cpu_online_mask to get valid cpu
    (git-fixes).
  - PCI: hv: Don't load the driver for baremetal root partition
    (git-fixes).
  - net: mana: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - PCI: hv: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - clocksource: hyper-v: Fix warnings for missing export.h header
    inclusion (git-fixes).
  - x86/hyperv: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - Drivers: hv: Fix warnings for missing export.h header inclusion
    (git-fixes).
  - Drivers: hv: Fix the check for HYPERVISOR_CALLBACK_VECTOR
    (git-fixes).
  - tools/hv: fcopy: Fix incorrect file path conversion (git-fixes).
  - Drivers: hv: Select CONFIG_SYSFB only if EFI is enabled
    (git-fixes).
  - hv_netvsc: Set VF priv_flags to IFF_NO_ADDRCONF before open
    to prevent IPv6 addrconf (git-fixes).
  - commit 6fce57d
  - i2c: stm32f7: unmap DMA mapped buffer (git-fixes).
  - i2c: stm32: fix the device used for the DMA map (git-fixes).
  - usb: hub: Don't try to recover devices lost during warm reset
    (git-fixes).
  - usb: dwc2: gadget: Fix enter to hibernation for UTMI+ PHY
    (git-fixes).
  - usb: musb: fix gadget state on disconnect (git-fixes).
  - thunderbolt: Fix bit masking in tb_dp_port_set_hops()
    (git-fixes).
  - thunderbolt: Fix wake on connect at runtime (git-fixes).
  - pch_uart: Fix dma_sync_sg_for_device() nents value (git-fixes).
  - serial: core: fix OF node leak (git-fixes).
  - comedi: Fix initialization of data for instructions that write
    to subdevice (git-fixes).
  - comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
    (git-fixes).
  - comedi: das6402: Fix bit shift out of bounds (git-fixes).
  - comedi: aio_iiro_16: Fix bit shift out of bounds (git-fixes).
  - comedi: pcl812: Fix bit shift out of bounds (git-fixes).
  - comedi: das16m1: Fix bit shift out of bounds (git-fixes).
  - comedi: Fix some signed shift left operations (git-fixes).
  - comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
    (git-fixes).
  - interconnect: icc-clk: destroy nodes in case of memory
    allocation failures (git-fixes).
  - interconnect: exynos: handle node name allocation failure
    (git-fixes).
  - interconnect: qcom: sc7280: Add missing num_links to xm_pcie3_1
    node (git-fixes).
  - iio: adc: ad7949: use spi_is_bpw_supported() (git-fixes).
  - iio: accel: fxls8962af: Fix use after free in
    fxls8962af_fifo_flush (git-fixes).
  - iio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC
    channel maps (git-fixes).
  - iio: adc: stm32-adc: Fix race in installing chained IRQ handler
    (git-fixes).
  - iio: backend: fix out-of-bound write (git-fixes).
  - spi: Add check for 8-bit transfer with 8 IO mode support
    (git-fixes).
  - regmap: fix potential memory leak of regmap_bus (git-fixes).
  - Input: xpad - set correct controller type for Acer NGR200
    (git-fixes).
  - commit efa1e54

++++ kubevirt:

  - Update to version 1.5.2
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.5.2
    bsc#1234537 (CVE-2024-45337), bsc#1235303 (CVE-2024-45338), bsc#1244486
  - Drop upstream patch
    0002-chore-deps-update-module-golang.org-x-crypto-to-v0.3.patch
  - Rename patches
    0001-Ensure-SEV-VMs-use-stateless-OVMF-firmware.patch ->
    Ensure-SEV-VMs-use-stateless-OVMF-firmware.patch
    0003-chore-deps-update-module-golang.org-x-oauth2-to-v0.2.patch ->
    chore-deps-update-module-golang.org-x-oauth2-to-v0.2.patch
    0004-chore-deps-update-module-golang.org-x-net-to-v0.36.0.patch ->
    Update-module-golang.org-x-net-to-v0.36.0-SECURITY.patch

++++ libbpf:

  - update to 1.6.0:
    * add more control over BPF object lifetime with new preparation step
    (bpf_object__prepare() API)
    * libbpf will report symbolic error code (e.g., "-EINVAL") in addition to
    human-readable error description
    * bpf_prog_stream_read() API
    * BPF token support when attaching BPF trampoline-based BPF programs in
    bpf_program__set_attach_target()
    * BPF token support for BPF_BTF_GET_FD_BY_ID command
    * support multi-uprobe session (SEC("uprobe.session")) BPF programs
    * support unique_match option for multi-kprobe attachment
    * support creating and destroying qdisk with BPF_TC_QDISC flag;
    * bpf_program__attach_cgroup_opts() which enables more precise cgroup-based
    attachment ordering
    * automatically take advantage of memory-mappable kernel BTF
    (/sys/kernel/btf/vmlinux), if supported
    * emit_strings option for BTF dumper API, improving string-like data printing
    * add BPF program's func and line info accessors
    * BPF linker supports linking ELF object files coming from memory buffer and
    referenced by FD, in addition to file path-based APIs;
    * small improvements to BTF dedup to handle rare quirky corner cases produces
    by some compilers
    * add likely() and unlikely() convenience macros;
    * __arg_untrusted annotation for BPF global subprog arguments;
    * bpf_stream_printk() macro for working with BPF streams;
    * bpf_usdt_arg_size() API
  - update to 1.6.0:
    * fixing a possible crash when handling BPF arena global variable relocations
  - drop 0001-libbpf-Add-identical-pointer-detection-to-btf_dedup_.patch, which
    is now included

++++ harfbuzz:

  - Update to version 11.3.2:
    + Fix build with non-compliant C++11 compilers that don't
    recognize the "and" keyword.
  - Changes from version 11.3.1:
    + Fix crasher in the glyph_v_origin function introduced in
    11.3.0.
  - Changes from version 11.3.0:
    + Speed up handling fonts with very large number of variations.
    + Speed up getting horizontal and vertical glyph advances by up
    to 24%.
    + Significantly speed up vertical text shaping.
    + Various documentation improvements.
    + Various build improvements.
    + Various subsetting improvements.
    + Various improvements to Rust font functions (fontations
    integration) and shaper (HarfRust integration).
    + Rename harfruzz option and shaper to harfrust following
    upstream rename.
    + Implement hb_face_reference_blob() for DirectWrite font
    functions.

++++ mdadm:

  - Stop emitting %release into program binaries [boo#1246806]

------------------------------------------------------------------
------------------  2025-7-20  -  Jul 20 2025  -------------------
------------------------------------------------------------------

++++ hyper-v:

  - fcopy: Fix irregularities with size of ring buffer (a4131a50)
  - fcopy: Fix incorrect file path conversion (0d86a8d6)

++++ kernel-default:

  - hwmon: (corsair-cpro) Validate the size of the received input
    buffer (git-fixes).
  - drm/mediatek: only announce AFBC if really supported
    (git-fixes).
  - drm/mediatek: Add wait_event_timeout when disabling plane
    (git-fixes).
  - drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume
    (git-fixes).
  - drm/nouveau: check ioctl command codes better (git-fixes).
  - soundwire: amd: fix for clearing command status register
    (git-fixes).
  - dmaengine: nbpfaxi: Fix memory corruption in probe()
    (git-fixes).
  - phy: tegra: xusb: Fix unbalanced regulator disable in UTMI
    PHY mode (git-fixes).
  - memstick: core: Zero initialize id_reg in
    h_memstick_read_dev_id() (git-fixes).
  - mmc: bcm2835: Fix dma_unmap_sg() nents value (git-fixes).
  - mmc: sdhci_am654: Workaround for Errata i2312 (git-fixes).
  - mmc: sdhci-pci: Quirk for broken command queuing on Intel
    GLK-based Positivo models (git-fixes).
  - commit f4e7d99

++++ kernel-rt:

  - hwmon: (corsair-cpro) Validate the size of the received input
    buffer (git-fixes).
  - drm/mediatek: only announce AFBC if really supported
    (git-fixes).
  - drm/mediatek: Add wait_event_timeout when disabling plane
    (git-fixes).
  - drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume
    (git-fixes).
  - drm/nouveau: check ioctl command codes better (git-fixes).
  - soundwire: amd: fix for clearing command status register
    (git-fixes).
  - dmaengine: nbpfaxi: Fix memory corruption in probe()
    (git-fixes).
  - phy: tegra: xusb: Fix unbalanced regulator disable in UTMI
    PHY mode (git-fixes).
  - memstick: core: Zero initialize id_reg in
    h_memstick_read_dev_id() (git-fixes).
  - mmc: bcm2835: Fix dma_unmap_sg() nents value (git-fixes).
  - mmc: sdhci_am654: Workaround for Errata i2312 (git-fixes).
  - mmc: sdhci-pci: Quirk for broken command queuing on Intel
    GLK-based Positivo models (git-fixes).
  - commit f4e7d99

++++ unbound:

  - Remove leftover dependency on sudo (not required)
    See also: boo#1215628

------------------------------------------------------------------
------------------  2025-7-19  -  Jul 19 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - virtio-net: fix recursived rtnl_lock() during probe()
    (git-fixes).
  - commit 0bc7aff
  - vsock: Fix IOCTL_VM_SOCKETS_GET_LOCAL_CID to check also
    `transport_local` (git-fixes).
  - commit 615e0f1
  - vsock: Fix transport_* TOCTOU (git-fixes).
  - commit 704674f
  - vsock: Fix transport_{g2h,h2g} TOCTOU (git-fixes).
  - commit 3024c81

++++ kernel-firmware-amdgpu:

  - Update to version 20250718 (git commit a5fbfa20d1bd):
    * amdgpu: update dmcub fw for various DCN version

++++ kernel-firmware-intel:

  - Update to version 20250718 (git commit a5fbfa20d1bd):
    * intel_vpu: Update NPU firmware

++++ kernel-rt:

  - virtio-net: fix recursived rtnl_lock() during probe()
    (git-fixes).
  - commit 0bc7aff
  - vsock: Fix IOCTL_VM_SOCKETS_GET_LOCAL_CID to check also
    `transport_local` (git-fixes).
  - commit 615e0f1
  - vsock: Fix transport_* TOCTOU (git-fixes).
  - commit 704674f
  - vsock: Fix transport_{g2h,h2g} TOCTOU (git-fixes).
  - commit 3024c81

------------------------------------------------------------------
------------------  2025-7-18  -  Jul 18 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.27 → 10.2.28
  - Fix dracut code to be POSIX compliant
    The redirect type "< <(...)" is not POSIX complians and leads
    to a syntax error in dracut which calls bash as "sh" leading
    it to be restricted to POSIX only

++++ gdk-pixbuf:

  - Add gdk-pixbuf-fix-decoder-written-bytes-reporting.patch: Fix
    memory leak caused by wrong written bytes reported by decoder
    (CVE-2025-6199, glgo#GNOME/gdk-pixbuf#257, bsc#1245227).

++++ kdump:

  - upgrade to version 2.1.4
    * work around failing calibration on aarch64
    * support for kernel flavour-specific calibration
    * specific calibration for aarch64 -64kb kernels (jsc#PED-12971)
    * use KDUMP_NET_TIMEOUT as sftp/ftp timeout
  - update calibrate values

++++ kernel-default:

  - vsock/vmci: Clear the vmci transport packet properly when
    initializing it (git-fixes).
  - commit ec91da1
  - virtio-net: xsk: rx: fix the frame's length check (git-fixes).
  - commit d6ac97d
  - af_unix: Don't set -ECONNRESET for consumed OOB skb
    (bsc#1246093).
  - commit 6c81d26
  -  sched/psi: Optimize psi_group_change() cpu_clock() usage KABI
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 74a8f57
  - virtio-net: ensure the received length does not exceed allocated
    size (git-fixes).
  - commit 98cd35a
  - sched: Skip useless sched_balance_running acquisition if load
    balance is not due (bsc#1234634 (Scheduler functional and
    performance backports)).
  - commit 8648646
  - net/sched: Return NULL when htb_lookup_leaf encounters an
    empty rbtree (git-fixes).
  - commit ecdd7a1
  - net: fix segmentation after TCP/UDP fraglist GRO (git-fixes).
  - commit 0365d28
  - ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
    (git-fixes).
  - commit 6b2d784
  - rpl: Fix use-after-free in rpl_do_srh_inline() (git-fixes).
  - commit fa150fb
  - af_packet: fix the SO_SNDTIMEO constraint not effective on
    tpacked_snd() (git-fixes).
  - commit f0f997a
  - net/sched: sch_qfq: Fix race condition on qfq_aggregate
    (git-fixes).
  - commit e3a7f48
  - sched/deadline: Less agressive dl_server handling KABI
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit ce216e3
  - sched/fair: Workaround NO_RUN_TO_PARITY fix kabi (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit 6a6e170
  - af_unix: Don't leave consecutive consumed OOB skbs
    (CVE-2025-38236 bsc#1246093).
  - commit a443f38
  - kABI workaround for struct drm_framebuffer changes (git-fixes).
  - commit 7f15c4f
  - bridge: mcast: Fix use-after-free during router port
    configuration (CVE-2025-38248 bsc#1246173).
  - commit 78cf8a3
  - Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU
    (git-fixes).
  - Bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855
    GF variant without board ID (git-fixes).
  - Bluetooth: hci_core: add missing braces when using macro
    parameters (git-fixes).
  - Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout
    (git-fixes).
  - Bluetooth: SMP: If an unallowed command is received consider
    it a failure (git-fixes).
  - Bluetooth: btintel: Check if controller is ISO capable on
    btintel_classify_pkt_type (git-fixes).
  - Bluetooth: hci_sync: fix connectable extended advertising when
    using static random address (git-fixes).
  - Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
    (git-fixes).
  - wifi: cfg80211: remove scan request n_channels counted_by
    (git-fixes).
  - can: tcan4x5x: fix reset gpio usage during probe (git-fixes).
  - usb: net: sierra: check for no status endpoint (git-fixes).
  - net: phy: Don't register LEDs for genphy (git-fixes).
  - clk: imx: Fix an out-of-bounds access in
    dispmix_csr_clk_dev_data (git-fixes).
  - clk: scmi: Handle case where child clocks are initialized
    before their parents (git-fixes).
  - drm/gem: Fix race in drm_gem_handle_create_tail()
    (stable-fixes).
  - drm/framebuffer: Acquire internal references on GEM handles
    (git-fixes).
  - wifi: prevent A-MSDU attacks in mesh networks (stable-fixes).
  - wifi: mac80211: correctly identify S1G short beacon (git-fixes).
  - wifi: cfg80211: fix S1G beacon head validation in nl80211
    (git-fixes).
  - net: phy: qcom: qca808x: Fix WoL issue by utilizing
    at8031_set_wol() (git-fixes).
  - net: phy: qcom: move the WoL function to shared library
    (stable-fixes).
  - Revert "ACPI: battery: negate current when discharging"
    (stable-fixes).
  - drm/gem: Acquire references on GEM handles for framebuffers
    (stable-fixes).
  - vt: add missing notification when switching back to text mode
    (stable-fixes).
  - Revert "PCI/ACPI: Fix allocated memory release on error in
    pci_acpi_scan_root()" (stable-fixes).
  - ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak
    (stable-fixes).
  - ASoC: amd: yc: add quirk for Acer Nitro ANV15-41 internal mic
    (stable-fixes).
  - ALSA: hda/realtek: Add mic-mute LED setup for ASUS UM5606
    (stable-fixes).
  - HID: lenovo: Add support for ThinkPad X1 Tablet Thin Keyboard
    Gen2 (stable-fixes).
  - HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (stable-fixes).
  - HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
    (stable-fixes).
  - HID: nintendo: avoid bluetooth suspend/resume stalls
    (stable-fixes).
  - driver: bluetooth: hci_qca:fix unable to load the BT driver
    (stable-fixes).
  - net: usb: qmi_wwan: add SIMCom 8230C composition (stable-fixes).
  - wifi: cfg80211/mac80211: correctly parse S1G beacon optional
    elements (git-fixes).
  - drm/amdgpu/ip_discovery: add missing ip_discovery fw
    (stable-fixes).
  - drm/amdgpu/discovery: use specific ip_discovery.bin for legacy
    asics (stable-fixes).
  - ASoC: Intel: soc-acpi: arl: Add match entries for new cs42l43
    laptops (stable-fixes).
  - ASoC: Intel: soc-acpi: arl: Correct naming of a cs35l56 address
    struct (stable-fixes).
  - commit ead540d

++++ kernel-firmware-media:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-firmware-mellanox:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-firmware-network:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-firmware-platform:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-firmware-qlogic:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-firmware-realtek:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-firmware-serial:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-firmware-usb-network:

  - Update to version 20250717 (git commit 6fc20e018cca):
    * WHENCE: extract more license statements

++++ kernel-rt:

  - vsock/vmci: Clear the vmci transport packet properly when
    initializing it (git-fixes).
  - commit ec91da1
  - virtio-net: xsk: rx: fix the frame's length check (git-fixes).
  - commit d6ac97d
  - af_unix: Don't set -ECONNRESET for consumed OOB skb
    (bsc#1246093).
  - commit 6c81d26
  -  sched/psi: Optimize psi_group_change() cpu_clock() usage KABI
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 74a8f57
  - virtio-net: ensure the received length does not exceed allocated
    size (git-fixes).
  - commit 98cd35a
  - sched: Skip useless sched_balance_running acquisition if load
    balance is not due (bsc#1234634 (Scheduler functional and
    performance backports)).
  - commit 8648646
  - net/sched: Return NULL when htb_lookup_leaf encounters an
    empty rbtree (git-fixes).
  - commit ecdd7a1
  - net: fix segmentation after TCP/UDP fraglist GRO (git-fixes).
  - commit 0365d28
  - ipv6: mcast: Delay put pmc->idev in mld_del_delrec()
    (git-fixes).
  - commit 6b2d784
  - rpl: Fix use-after-free in rpl_do_srh_inline() (git-fixes).
  - commit fa150fb
  - af_packet: fix the SO_SNDTIMEO constraint not effective on
    tpacked_snd() (git-fixes).
  - commit f0f997a
  - net/sched: sch_qfq: Fix race condition on qfq_aggregate
    (git-fixes).
  - commit e3a7f48
  - sched/deadline: Less agressive dl_server handling KABI
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit ce216e3
  - sched/fair: Workaround NO_RUN_TO_PARITY fix kabi (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit 6a6e170
  - af_unix: Don't leave consecutive consumed OOB skbs
    (CVE-2025-38236 bsc#1246093).
  - commit a443f38
  - kABI workaround for struct drm_framebuffer changes (git-fixes).
  - commit 7f15c4f
  - bridge: mcast: Fix use-after-free during router port
    configuration (CVE-2025-38248 bsc#1246173).
  - commit 78cf8a3
  - Bluetooth: L2CAP: Fix attempting to adjust outgoing MTU
    (git-fixes).
  - Bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855
    GF variant without board ID (git-fixes).
  - Bluetooth: hci_core: add missing braces when using macro
    parameters (git-fixes).
  - Bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout
    (git-fixes).
  - Bluetooth: SMP: If an unallowed command is received consider
    it a failure (git-fixes).
  - Bluetooth: btintel: Check if controller is ISO capable on
    btintel_classify_pkt_type (git-fixes).
  - Bluetooth: hci_sync: fix connectable extended advertising when
    using static random address (git-fixes).
  - Bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb()
    (git-fixes).
  - wifi: cfg80211: remove scan request n_channels counted_by
    (git-fixes).
  - can: tcan4x5x: fix reset gpio usage during probe (git-fixes).
  - usb: net: sierra: check for no status endpoint (git-fixes).
  - net: phy: Don't register LEDs for genphy (git-fixes).
  - clk: imx: Fix an out-of-bounds access in
    dispmix_csr_clk_dev_data (git-fixes).
  - clk: scmi: Handle case where child clocks are initialized
    before their parents (git-fixes).
  - drm/gem: Fix race in drm_gem_handle_create_tail()
    (stable-fixes).
  - drm/framebuffer: Acquire internal references on GEM handles
    (git-fixes).
  - wifi: prevent A-MSDU attacks in mesh networks (stable-fixes).
  - wifi: mac80211: correctly identify S1G short beacon (git-fixes).
  - wifi: cfg80211: fix S1G beacon head validation in nl80211
    (git-fixes).
  - net: phy: qcom: qca808x: Fix WoL issue by utilizing
    at8031_set_wol() (git-fixes).
  - net: phy: qcom: move the WoL function to shared library
    (stable-fixes).
  - Revert "ACPI: battery: negate current when discharging"
    (stable-fixes).
  - drm/gem: Acquire references on GEM handles for framebuffers
    (stable-fixes).
  - vt: add missing notification when switching back to text mode
    (stable-fixes).
  - Revert "PCI/ACPI: Fix allocated memory release on error in
    pci_acpi_scan_root()" (stable-fixes).
  - ASoC: SOF: Intel: hda: Use devm_kstrdup() to avoid memleak
    (stable-fixes).
  - ASoC: amd: yc: add quirk for Acer Nitro ANV15-41 internal mic
    (stable-fixes).
  - ALSA: hda/realtek: Add mic-mute LED setup for ASUS UM5606
    (stable-fixes).
  - HID: lenovo: Add support for ThinkPad X1 Tablet Thin Keyboard
    Gen2 (stable-fixes).
  - HID: Add IGNORE quirk for SMARTLINKTECHNOLOGY (stable-fixes).
  - HID: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras
    (stable-fixes).
  - HID: nintendo: avoid bluetooth suspend/resume stalls
    (stable-fixes).
  - driver: bluetooth: hci_qca:fix unable to load the BT driver
    (stable-fixes).
  - net: usb: qmi_wwan: add SIMCom 8230C composition (stable-fixes).
  - wifi: cfg80211/mac80211: correctly parse S1G beacon optional
    elements (git-fixes).
  - drm/amdgpu/ip_discovery: add missing ip_discovery fw
    (stable-fixes).
  - drm/amdgpu/discovery: use specific ip_discovery.bin for legacy
    asics (stable-fixes).
  - ASoC: Intel: soc-acpi: arl: Add match entries for new cs42l43
    laptops (stable-fixes).
  - ASoC: Intel: soc-acpi: arl: Correct naming of a cs35l56 address
    struct (stable-fixes).
  - commit ead540d

++++ leancrypto:

  - Add baselibs.conf

++++ ceph:

  - Drop cryptopp as potential dependency [jsc#PED-13011] and use gnutls as upstream seastar.
    * Remove cryptopp and use gnutls instead.
    * Add ceph-replace-CryptoPP-calls-with-GnuTLS.patch

++++ libxml2:

  - security update
  - added patches
    CVE-2025-7425 [bsc#1246296], Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
    + libxml2-CVE-2025-7425.patch

++++ libxml2-python:

  - security update
  - added patches
    CVE-2025-7425 [bsc#1246296], Heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr
    + libxml2-CVE-2025-7425.patch

++++ zypper:

  - Fix addrepo to handle explicit --check and --no-check requests
    (bsc#1246466)
  - Accept "show" as alias for "info" (bsc#1245985)
  - version 1.14.93

------------------------------------------------------------------
------------------  2025-7-17  -  Jul 17 2025  -------------------
------------------------------------------------------------------

++++ busybox:

  - add placeholder variable and ignore applet logic to busybox.install

++++ busybox-links:

  - add filtering of ignored applets to busybox.install

++++ docker:

  - Update to Go 1.24 for builds, to match upstream.

++++ python-kiwi:

  - Extend test-image-lvm integration test
    For testing a bit more complex resize procedure, update
    the lvm integration test to run more resize actions
    with required device locking
  - Apply proper udev locking
    Several commands during repart, resize and other actions
    require a proper lock to be set for udev such that other
    events knows about the locked state of a device and do
    not mess with it until the command for which the lock
    persists has completed. This commit applies proper udev
    locks to all commands that requires it. In addition
    incorrect code that was expected to prevent such race
    conditions got dropped from the implementation.
    This is related to bsc#1242987
  - relocate GPT at the end of disk using sfdisk
    Using sfdisk for relocation and verification makes this
    part more consistent. We also want to move away from gdisk.
    This is related to #2851
  - Do not strictly require config.partids in repart
    The kiwi-repart implementation requires a metadata file
    named config.partids which holds information about
    partition ids and more stored at the time the image was
    built. Depending on the complexity of the image and the
    resize request some of the information can be rebuilt
    in case the metadata file is missing. This commit adds
    the rebuild of the minimum required information to run
    a standard resize and therefore allows the kiwi-repart
    dracut module to work also without config.partids to be
    present in the system
  - Do not drop /config.partids
    The partition id metadata file is used in the kiwi-repart
    module. If a user wants to use the kiwi repart module
    permanently, this metadata file needs to stay in the system.
    Therefore it should not be automatically deleted by the
    cleanup. A disk.sh hook script can be used to force the
    deletion of the file though. This is related #2851

++++ kernel-default:

  - sched/fair: Reimplement NEXT_BUDDY to align with EEVDF goals
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Enable scheduler feature NEXT_BUDDY (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Always trigger resched at the end of a protected
    period (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Fix entity's lag with run to parity (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Limit run to parity to the min slice of enqueued
    entities (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Remove spurious shorter slice preemption
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fix NO_RUN_TO_PARITY case (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Use protect_slice() instead of direct comparison
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Less agressive dl_server handling (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/psi: Optimize psi_group_change() cpu_clock() usage
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Bump sd->max_newidle_lb_cost when newidle balance
    fails (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/eevdf: Correct the comment in place_entity (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/deadline: Fix dl_server runtime calculation formula
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Fix migrate_swap() vs. hotplug (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Fix preemption string of preempt_dynamic_none
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/numa: fix task swap by skipping kernel threads
    (bsc#1234634 (Scheduler functional and performance backports)).
  - mm: pcp: increase pcp->free_count threshold to trigger free_high
    (bsc#1241169 (MM functional and performance backports)).
  - sched/numa: add tracepoint that tracks the skipping of numa
    balancing due to cpuset memory pinning (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/numa: skip VMA scanning on memory pinned to one NUMA
    node via cpuset.mems (bsc#1234634 (Scheduler functional and
    performance backports)).
  - mm: page_alloc: remove redundant READ_ONCE (bsc#1241169 (MM
    functional and performance backports)).
  - sched/uclamp: Align uclamp and util_est and call before freq
    update (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/util_est: Simplify condition for util_est_{en,de}queue()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fixup wake_up_sync() vs DELAYED_DEQUEUE (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/core: Tweak wait_task_inactive() to force dequeue
    sched_delayed tasks (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/fair: Adhere to place_entity() constraints (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/debug: Print the local group's asym_prefer_cpu
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/topology: Introduce sched_update_asym_prefer_cpu()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Use READ_ONCE() to read sg->asym_prefer_cpu
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/isolation: Make use of more than one housekeeping cpu
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/rt: Fix race in push_rt_task (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Allow decaying util_est when util_avg > CPU capa
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Fix trace_sched_switch(.prev_state) (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit 2289d34
  - Update
    patches.suse/scsi-megaraid_sas-Fix-invalid-node-index.patch
    (git-fixes CVE-2025-38239 bsc#1246178).
  - commit 3918567
  - soc: aspeed: lpc-snoop: Don't disable channels that aren't
    enabled (git-fixes).
  - soc: aspeed: lpc-snoop: Cleanup resources in stack-order
    (git-fixes).
  - HID: core: ensure __hid_request reserves the report ID as the
    first byte (git-fixes).
  - commit d4ff6f9
  - x86/iopl: Cure TIF_IO_BITMAP inconsistencies (CVE-2025-38100
    bsc#1245650).
  - commit 2e30d9c
  - config: x86_64: default: use run_oldconfig to refresh
  - commit e2e6c0d
  - kABI workaround for bpf: Do not include stack ptr register in
    precision backtracking bookkeeping (bsc#1246264 CVE-2025-38279).
  - commit e82df30
  - btrfs: explicitly ref count block_group on new_bgs list (bsc#1243068)
  - commit 8676cda
  - btrfs: make btrfs_discard_workfn() block_group ref explicit (bsc#1243068)
  - commit 5d891f0
  - btrfs: harden block_group::bg_list against list_del() races (CVE-2025-37856 bsc#1243068)
  - commit fe28436
  - btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref (CVE-2025-38034 bsc#1244792)
  - commit cbeb64e

++++ kernel-firmware-amdgpu:

  - Update to version 20250716 (git commit 1b1a9d871442):
    * amdgpu: Update GC 11.5.1 microcode

++++ kernel-rt:

  - sched/fair: Reimplement NEXT_BUDDY to align with EEVDF goals
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Enable scheduler feature NEXT_BUDDY (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Always trigger resched at the end of a protected
    period (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Fix entity's lag with run to parity (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Limit run to parity to the min slice of enqueued
    entities (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Remove spurious shorter slice preemption
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fix NO_RUN_TO_PARITY case (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Use protect_slice() instead of direct comparison
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Less agressive dl_server handling (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/psi: Optimize psi_group_change() cpu_clock() usage
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Bump sd->max_newidle_lb_cost when newidle balance
    fails (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/eevdf: Correct the comment in place_entity (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/deadline: Fix dl_server runtime calculation formula
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Fix migrate_swap() vs. hotplug (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Fix preemption string of preempt_dynamic_none
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/numa: fix task swap by skipping kernel threads
    (bsc#1234634 (Scheduler functional and performance backports)).
  - mm: pcp: increase pcp->free_count threshold to trigger free_high
    (bsc#1241169 (MM functional and performance backports)).
  - sched/numa: add tracepoint that tracks the skipping of numa
    balancing due to cpuset memory pinning (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/numa: skip VMA scanning on memory pinned to one NUMA
    node via cpuset.mems (bsc#1234634 (Scheduler functional and
    performance backports)).
  - mm: page_alloc: remove redundant READ_ONCE (bsc#1241169 (MM
    functional and performance backports)).
  - sched/uclamp: Align uclamp and util_est and call before freq
    update (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/util_est: Simplify condition for util_est_{en,de}queue()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fixup wake_up_sync() vs DELAYED_DEQUEUE (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/core: Tweak wait_task_inactive() to force dequeue
    sched_delayed tasks (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/fair: Adhere to place_entity() constraints (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/debug: Print the local group's asym_prefer_cpu
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/topology: Introduce sched_update_asym_prefer_cpu()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Use READ_ONCE() to read sg->asym_prefer_cpu
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/isolation: Make use of more than one housekeeping cpu
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/rt: Fix race in push_rt_task (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Allow decaying util_est when util_avg > CPU capa
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Fix trace_sched_switch(.prev_state) (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit 2289d34
  - Update
    patches.suse/scsi-megaraid_sas-Fix-invalid-node-index.patch
    (git-fixes CVE-2025-38239 bsc#1246178).
  - commit 3918567
  - soc: aspeed: lpc-snoop: Don't disable channels that aren't
    enabled (git-fixes).
  - soc: aspeed: lpc-snoop: Cleanup resources in stack-order
    (git-fixes).
  - HID: core: ensure __hid_request reserves the report ID as the
    first byte (git-fixes).
  - commit d4ff6f9
  - x86/iopl: Cure TIF_IO_BITMAP inconsistencies (CVE-2025-38100
    bsc#1245650).
  - commit 2e30d9c
  - config: x86_64: default: use run_oldconfig to refresh
  - commit e2e6c0d
  - kABI workaround for bpf: Do not include stack ptr register in
    precision backtracking bookkeeping (bsc#1246264 CVE-2025-38279).
  - commit e82df30
  - btrfs: explicitly ref count block_group on new_bgs list (bsc#1243068)
  - commit 8676cda
  - btrfs: make btrfs_discard_workfn() block_group ref explicit (bsc#1243068)
  - commit 5d891f0
  - btrfs: harden block_group::bg_list against list_del() races (CVE-2025-37856 bsc#1243068)
  - commit fe28436
  - btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref (CVE-2025-38034 bsc#1244792)
  - commit cbeb64e

++++ gcc15:

  - Fixup conflicts again.
  - Make sure to retain binary suffixes for accelerator crosses.

++++ libxslt:

  - security update
  - added patches
    CVE-2025-7424 [bsc#1246360], Type confusion in xmlNode.psvi between stylesheet and source nodes
    + libxslt-CVE-2025-7424.patch

++++ sqlite3:

  - Update to version 3.50.3:
    * Fix a possible memory error that can occur if a query is made
    against against FTS5 index that has been deliberately corrupted
    in a very specific way (CVE-2025-7709, bsc#1254670).
    * Fix the parser so that it ignored SQL comments in all places of
    a CREATE TRIGGER statement. This resolves a problem that was
    introduced by the introduction of the
    SQLITE_DBCONFIG_ENABLE_COMMENTS feature in version 3.49.0.
    * Fix an incorrect answer due to over-optimization of an AND
    operator.

++++ libzypp:

  - Allow explicit request to probe an added repo's URL
    (bsc#1246466)
  - Fix tests with -DISABLE_MEDIABACKEND_TESTS=1 (fixes #661)
  - version 17.37.12 (35)

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#191
  - avoid spurious warning messages when parsing /etc/default/grub
    (bsc#1246373, bsc#1245323)
  - 1.25

------------------------------------------------------------------
------------------  2025-7-16  -  Jul 16 2025  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.692.g6ec224d5:
    * ci(suse.conf.example): change log levels (jsc#PED-12922)

++++ python-kiwi:

  - Fix centos/test-image-live-disk-v10
    There is no package named iprutils
  - Fix centos/test-image-live-disk-v10
    Update package names
  - Added centos/test-image-live-disk-v10 build test
  - Fix tumbleweed/test-image-gce integration test
    Drop obsolete growpart
  - Followup fix to support older apt versions for bootstrap
    There are apt versions that do not create missing state files.
    Make sure the intermediate bootstrap state file is created in
    any case. This Fixes #2857
  - Fixed integration test builds
    Next round of fixes for integration tests. Missing
    or wrong service activations
  - Fix arm/tumbleweed/test-image-rpi
    Fix snapper setup for this integration test

++++ grub2:

  - Fix test -f and -s do not work properly over the network files served via
    tftp and http (bsc#1246157) (bsc#1246237)
    * 0001-test-Fix-f-test-on-files-over-network.patch
    * 0002-http-Return-HTTP-status-code-in-http_establish.patch
    * 0003-docs-Clarify-test-for-files-on-TFTP-and-HTTP.patch
    * 0004-tftp-Fix-hang-when-file-is-a-directory.patch

++++ kernel-default:

  - net: sched: fix ordering of qlen adjustment (CVE-2024-53164 bsc#1234863)
  - commit f3dbf9a
  - seg6: Fix validation of nexthop addresses (CVE-2025-38310
    bsc#1246361).
  - netfs: Fix oops in write-retry from mis-resetting the subreq
    iterator (CVE-2025-38139 bsc#1245718).
  - x86/sgx: Prevent attempts to reclaim poisoned pages
    (CVE-2025-38334 bsc#1246384).
  - commit 5e00081
  - fs/proc: Use inode_get_dev() for device numbers in procmap_query
    References: bsc#1246450
  - commit 8f812e6
  - fs/proc/kcore.c: Clear ret value in read_kcore_iter after
    successful iov_iter_zero (bsc#1246620).
  - commit ac8d8ea
  - net: stmmac: make sure that ptp_rate is not 0 before configuring
    timestamping (CVE-2025-38126 bsc#1245708).
  - bpf: fix ktls panic with sockmap (CVE-2025-38166 bsc#1245758).
  - commit f2dcced
  - objtool: Ignore end-of-section jumps for KCOV/GCOV (git-fixes).
  - commit cdba1ce
  - objtool: Silence more KCOV warnings, part 2 (git-fixes).
  - commit 4da0721
  - objtool: Add missing endian conversion to read_annotate()
    (git-fixes).
  - commit 33dacf5
  - ixgbe: add FW API version check (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - Refresh
    patches.suse/bsc1170284-ixgbe_dont_check_firmware_errors.patch.
  - commit c263240
  - ixgbe: add support for devlink reload (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - Refresh
    patches.suse/bsc1170284-ixgbe_dont_check_firmware_errors.patch.
  - commit 207db98
  - ixgbe: devlink: add devlink region support for E610
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add E610 .set_phys_id() callback implementation
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: apply different rules for setting FC on E610
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add support for ACPI WOL for E610 (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: create E610 specific ethtool_ops structure (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add support for FW rollback mode (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add E610 implementation of FW recovery mode
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add device flash update via devlink (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: extend .info_get() with stored versions (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add E610 functions getting PBA and FW ver info
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add .info_get extension specific for E610 devices
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: read the netlist version information (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: read the OROM version information (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add E610 functions for acquiring flash data
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add handler for devlink .info_get() (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add initial devlink support (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - ixgbe: wrap netdev_priv() usage (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - ixgbe: Fix unreachable retry logic in combined and byte I2C
    write functions (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add support for thermal sensor event reception
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add PTP support for E610 device (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - commit aea9558
  - objtool: Stop UNRET validation on UD2 (git-fixes).
  - commit 82f38be
  - objtool: Fix INSN_CONTEXT_SWITCH handling in validate_unret()
    (git-fixes).
  - commit af1e729
  - objtool: Properly disable uaccess validation (git-fixes).
  - commit c47d66e
  - objtool: Silence more KCOV warnings (git-fixes).
  - commit 700d945
  - wifi: mt76: mt7925: fix invalid array index in ssid assignment
    during hw scan (git-fixes).
  - commit bd0db70
  - wifi: mt76: mt7925: fix the wrong config for tx interrupt
    (git-fixes).
  - commit 1568d0d
  - wifi: rt2x00: fix remove callback type mismatch (git-fixes).
  - commit c0ae7f4
  - wifi: mwifiex: discard erroneous disassoc frames on STA
    interface (git-fixes).
  - commit decdc76
  - wifi: mac80211: fix non-transmitted BSSID profile search
    (git-fixes).
  - commit 7ee21af
  - wifi: zd1211rw: Fix potential NULL pointer dereference in
    zd_mac_tx_to_dev() (git-fixes).
  - commit c13b504
  - selftests/bpf: Add tests with stack ptr register in conditional
    jmp (bsc#1246264 CVE-2025-38279).
  - bpf: Do not include stack ptr register in precision backtracking
    bookkeeping (bsc#1246264 CVE-2025-38279).
  - commit 3a79b8b
  - selftests/bpf: Set test path for
    token/obj_priv_implicit_token_envvar (git-fixes).
  - commit 493edb3
  - perf/core: Fix the WARN_ON_ONCE is out of lock protected region
    (git-fixes).
  - commit 6223b3a
  - perf: Revert to requiring CAP_SYS_ADMIN for uprobes (git-fixes).
  - perf/aux: Fix pending disable flow when the AUX ring buffer
    overruns (git-fixes).
  - perf/core: Fix WARN in perf_cgroup_switch() (git-fixes).
  - perf: Fix dangling cgroup pointer in cpuctx (git-fixes).
  - perf: Fix cgroup state vs ERROR (git-fixes).
  - perf test: Directory file descriptor leak (git-fixes).
  - perf evsel: Missed close() when probing hybrid core PMUs
    (git-fixes).
  - perf callchain: Always populate the addr_location map when
    adding IP (git-fixes).
  - perf trace: Set errpid to false for rseq and set_robust_list
    (git-fixes).
  - perf trace: Always print return value for syscalls returning
    a pid (git-fixes).
  - perf record: Fix incorrect --user-regs comments (git-fixes).
  - perf symbol: Fix use-after-free in filename__read_build_id
    (git-fixes).
  - perf pmu: Avoid segv for missing name/alias_name in wildcarding
    (git-fixes).
  - perf tests switch-tracking: Fix timestamp comparison
    (git-fixes).
  - perf scripts python: exported-sql-viewer.py: Fix pattern
    matching with Python 3 (git-fixes).
  - perf intel-pt: Fix PEBS-via-PT data_src (git-fixes).
  - perf tests: Fix 'perf report' tests installation (git-fixes).
  - perf trace: Fix leaks of 'struct thread' in
    set_filter_loop_pids() (git-fixes).
  - perf symbol-minimal: Fix double free in filename__read_build_id
    (git-fixes).
  - perf tool_pmu: Fix aggregation on duration_time (git-fixes).
  - perf ui browser hists: Set actions->thread before calling
    do_zoom_thread() (git-fixes).
  - perf build: Warn when libdebuginfod devel files are not
    available (git-fixes).
  - tools build: Don't show libunwind build status as it is opt-in
    (git-fixes).
  - tools build: Don't set libunwind as available if test-all.c
    build succeeds (git-fixes).
  - perf/core: Fix broken throttling when max_samples_per_tick=1
    (git-fixes).
  - perf/x86/amd/uncore: Prevent UMC counters from saturating
    (git-fixes).
  - perf/x86/amd/uncore: Remove unused 'struct amd_uncore_ctx::node'
    member (git-fixes).
  - perf: Ensure bpf_perf_link path is properly serialized
    (git-fixes).
  - arch/powerpc/perf: Check the instruction type before creating
    sample with perf_mem_data_src (git-fixes).
  - perf/hw_breakpoint: Return EOPNOTSUPP for unsupported breakpoint
    type (git-fixes).
  - commit 4d40f30

++++ kernel-default-base:

  - Add modules for confidential compute (bsc#1246502)

++++ kernel-firmware-realtek:

  - Update to version 20250715 (git commit 04c379b552c7):
    * rtw89: 8852b: update fw to v0.29.128.0
    * rtw89: 8852bt: update fw to v0.29.127.0
    * rtw89: 8922a: add regd fw element with version R72-R6
    * rtw89: 8852c: add regd fw element with version R72-R57
    * rtw89: 8922a: update BB parameter V49

++++ kernel-rt:

  - net: sched: fix ordering of qlen adjustment (CVE-2024-53164 bsc#1234863)
  - commit f3dbf9a
  - seg6: Fix validation of nexthop addresses (CVE-2025-38310
    bsc#1246361).
  - netfs: Fix oops in write-retry from mis-resetting the subreq
    iterator (CVE-2025-38139 bsc#1245718).
  - x86/sgx: Prevent attempts to reclaim poisoned pages
    (CVE-2025-38334 bsc#1246384).
  - commit 5e00081
  - fs/proc: Use inode_get_dev() for device numbers in procmap_query
    References: bsc#1246450
  - commit 8f812e6
  - fs/proc/kcore.c: Clear ret value in read_kcore_iter after
    successful iov_iter_zero (bsc#1246620).
  - commit ac8d8ea
  - net: stmmac: make sure that ptp_rate is not 0 before configuring
    timestamping (CVE-2025-38126 bsc#1245708).
  - bpf: fix ktls panic with sockmap (CVE-2025-38166 bsc#1245758).
  - commit f2dcced
  - objtool: Ignore end-of-section jumps for KCOV/GCOV (git-fixes).
  - commit cdba1ce
  - objtool: Silence more KCOV warnings, part 2 (git-fixes).
  - commit 4da0721
  - objtool: Add missing endian conversion to read_annotate()
    (git-fixes).
  - commit 33dacf5
  - ixgbe: add FW API version check (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - Refresh
    patches.suse/bsc1170284-ixgbe_dont_check_firmware_errors.patch.
  - commit c263240
  - ixgbe: add support for devlink reload (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - Refresh
    patches.suse/bsc1170284-ixgbe_dont_check_firmware_errors.patch.
  - commit 207db98
  - ixgbe: devlink: add devlink region support for E610
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add E610 .set_phys_id() callback implementation
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: apply different rules for setting FC on E610
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add support for ACPI WOL for E610 (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: create E610 specific ethtool_ops structure (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add support for FW rollback mode (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add E610 implementation of FW recovery mode
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add device flash update via devlink (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: extend .info_get() with stored versions (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add E610 functions getting PBA and FW ver info
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add .info_get extension specific for E610 devices
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: read the netlist version information (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: read the OROM version information (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add E610 functions for acquiring flash data
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add handler for devlink .info_get() (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - ixgbe: add initial devlink support (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - ixgbe: wrap netdev_priv() usage (jsc#PED-12380 bsc#1245410
    bsc#1246128).
  - ixgbe: Fix unreachable retry logic in combined and byte I2C
    write functions (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add support for thermal sensor event reception
    (jsc#PED-12380 bsc#1245410 bsc#1246128).
  - ixgbe: add PTP support for E610 device (jsc#PED-12380
    bsc#1245410 bsc#1246128).
  - commit aea9558
  - objtool: Stop UNRET validation on UD2 (git-fixes).
  - commit 82f38be
  - objtool: Fix INSN_CONTEXT_SWITCH handling in validate_unret()
    (git-fixes).
  - commit af1e729
  - objtool: Properly disable uaccess validation (git-fixes).
  - commit c47d66e
  - objtool: Silence more KCOV warnings (git-fixes).
  - commit 700d945
  - wifi: mt76: mt7925: fix invalid array index in ssid assignment
    during hw scan (git-fixes).
  - commit bd0db70
  - wifi: mt76: mt7925: fix the wrong config for tx interrupt
    (git-fixes).
  - commit 1568d0d
  - wifi: rt2x00: fix remove callback type mismatch (git-fixes).
  - commit c0ae7f4
  - wifi: mwifiex: discard erroneous disassoc frames on STA
    interface (git-fixes).
  - commit decdc76
  - wifi: mac80211: fix non-transmitted BSSID profile search
    (git-fixes).
  - commit 7ee21af
  - wifi: zd1211rw: Fix potential NULL pointer dereference in
    zd_mac_tx_to_dev() (git-fixes).
  - commit c13b504
  - selftests/bpf: Add tests with stack ptr register in conditional
    jmp (bsc#1246264 CVE-2025-38279).
  - bpf: Do not include stack ptr register in precision backtracking
    bookkeeping (bsc#1246264 CVE-2025-38279).
  - commit 3a79b8b
  - selftests/bpf: Set test path for
    token/obj_priv_implicit_token_envvar (git-fixes).
  - commit 493edb3
  - perf/core: Fix the WARN_ON_ONCE is out of lock protected region
    (git-fixes).
  - commit 6223b3a
  - perf: Revert to requiring CAP_SYS_ADMIN for uprobes (git-fixes).
  - perf/aux: Fix pending disable flow when the AUX ring buffer
    overruns (git-fixes).
  - perf/core: Fix WARN in perf_cgroup_switch() (git-fixes).
  - perf: Fix dangling cgroup pointer in cpuctx (git-fixes).
  - perf: Fix cgroup state vs ERROR (git-fixes).
  - perf test: Directory file descriptor leak (git-fixes).
  - perf evsel: Missed close() when probing hybrid core PMUs
    (git-fixes).
  - perf callchain: Always populate the addr_location map when
    adding IP (git-fixes).
  - perf trace: Set errpid to false for rseq and set_robust_list
    (git-fixes).
  - perf trace: Always print return value for syscalls returning
    a pid (git-fixes).
  - perf record: Fix incorrect --user-regs comments (git-fixes).
  - perf symbol: Fix use-after-free in filename__read_build_id
    (git-fixes).
  - perf pmu: Avoid segv for missing name/alias_name in wildcarding
    (git-fixes).
  - perf tests switch-tracking: Fix timestamp comparison
    (git-fixes).
  - perf scripts python: exported-sql-viewer.py: Fix pattern
    matching with Python 3 (git-fixes).
  - perf intel-pt: Fix PEBS-via-PT data_src (git-fixes).
  - perf tests: Fix 'perf report' tests installation (git-fixes).
  - perf trace: Fix leaks of 'struct thread' in
    set_filter_loop_pids() (git-fixes).
  - perf symbol-minimal: Fix double free in filename__read_build_id
    (git-fixes).
  - perf tool_pmu: Fix aggregation on duration_time (git-fixes).
  - perf ui browser hists: Set actions->thread before calling
    do_zoom_thread() (git-fixes).
  - perf build: Warn when libdebuginfod devel files are not
    available (git-fixes).
  - tools build: Don't show libunwind build status as it is opt-in
    (git-fixes).
  - tools build: Don't set libunwind as available if test-all.c
    build succeeds (git-fixes).
  - perf/core: Fix broken throttling when max_samples_per_tick=1
    (git-fixes).
  - perf/x86/amd/uncore: Prevent UMC counters from saturating
    (git-fixes).
  - perf/x86/amd/uncore: Remove unused 'struct amd_uncore_ctx::node'
    member (git-fixes).
  - perf: Ensure bpf_perf_link path is properly serialized
    (git-fixes).
  - arch/powerpc/perf: Check the instruction type before creating
    sample with perf_mem_data_src (git-fixes).
  - perf/hw_breakpoint: Return EOPNOTSUPP for unsupported breakpoint
    type (git-fixes).
  - commit 4d40f30

++++ leancrypto:

  - Split kernel module into to a separate package as to allow leancrypto to be
    part of ring1 following replacement of liboqs in gnutls [jsc#PED-3176]
  - Update to 1.5.1:
    * add ChaCha20 Poly 1305 AEAD
    * ChaCha20: add ARMv8 NEON, ARMv7 Neon, Intel AVX2, Intel AVX512,
    RISCV RVV/ZBB implementations
    * RISC-V entropy source: make implementation consistent to spec
    * Unify stack memory allocation

++++ selinux-policy:

  - Update to version 20250627+git62.68c403828:
    * Allow virtqemud_t use its private tmpfs files (bsc#1242998)
    * Allow virtqemud_t setattr to /dev/userfaultfd (bsc#1242998)
    * Allow virtqemud_t read and write /dev/ptmx (bsc#1242998)
    * Extend virtqemud_t tcp_socket permissions (bsc#1242998)
    * Mark configfs_t as mountpoint (bsc#1246080)
    * healthchecker: add proper optional_policy() guards
    * Allow virtqemud_t to read and write generic pty (bsc#1242998)
    * Drop SUSE-specific /usr/etc = /etc equivalency
    * Allow irqbalance execute shell if irqbalance_run_unconfined is on
    * Allow openvswitch ioctl vduse devices
    * Label /dev/vduse/control and /dev/vduse/NAME devices
    * Allow virtstoraged the sys_rawio capability
    * Allow virtqemud read insights-core state files
    * Allow virtnodedev create mdevctl config dirs
    * Allow virtqemud additional permissions on scsi generic chr files
    * Allow local login execute gnome keyring daemon
    * Allow plymouthd_t read proc files of systemd_passwd_agent (bsc#1245470)
    * Allow virtqemud send a generic signal to passt
    * Allow svirt-tcg read init state
    * Allow irqbalance execute shell if irqbalance_run_unconfined is on
    * Label /run/opendkim with dkim_milter_data_t
    * Allow sa-update status systemd services
    * Introduce new cluster_service_transition_to_unconfined_user boolean (bsc#1244495)
    * Allow updpwd logging send audit messages
    * Temporary dontaudit iio-sensor-proxy sys_admin.
    * Allow iio-sensor-proxy sendto to journald over a unix datagram socket
    * Revert "Allow iio-sensor-proxy sendto to journald over a unix datagram socket"
    * virt: allow QEMU use of the qgs daemon for attestation
    * qgs: add contrib module for TDX "qgs" daemon
    * kernel: add interfaces for using SGX enclaves
    * Define file equivalency for /usr/etc
    * Allow mongod to receive pressure stall information
    * Dontaudit systemd_generator read sssd public files
    * Allow plymouthd read/write input event devices
    * Label 99-nvme-nbft-connect.sh with NetworkManager_dispatcher_nvme_script_t
    * Allow systemd-user-runtime-dir sendto to syslogd
    * Remove pcp module
    * Update irqbalance policy for using unconfined scripts
    * Allow utempter use terminal multiplexor
    * Allow virtqemud execute ovs-vsctl with a domain transition
    * Update the files_search_mnt() interface
    * Allow nmbd read network sysctls
    * Allow iio-sensor-proxy sendto to journald over a unix datagram socket
    * Allow logrotate stop all systemd services
    * systemd: rework systemd_manage_random_seed
    * Allow tuned-ppd connect to sssd over a unix stream socket
    * Drop config for /run/random-seed
    * Update file location for systemd random-seed file
    * Allow tomcat execute cracklib-check with a domain transition
    * Allow sssd watch lib dirs
    * Confine systemd-hibernate-resume
    * Allow login_userdomain create /run/tlog directory with user_tmp_t
    * Allow login_pgm read filesystem sysctls
    * Allow gconfd connect to system dbus
    * Allow NetworkManager manage NetworkManager_etc_rw_t symlinks
  - Syncing with upstream rawhide selinux-policy up to:
    * 23514206ea45e1d1d2f8a4c08288065c813fcc91
  - Update embedded container-selinux version to commit:
    * 36e8f213b7ac8a1843e5e37b37eb8ef7bdc2af9c (version 2.238.0)

------------------------------------------------------------------
------------------  2025-7-15  -  Jul 15 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - add 0001-cockpit-overview-support-SUSE_SUPPORT_PRODUCT-keys.patch
  - add 0002-cockpit-kdump-support-SLE-micro-6.2.patch
  - add 0003-branding-use-SUSE_SUPPORT_PRODUCT-and-SUSE_SUPPORT_P.patch to fix bsc#1241003

++++ python-kiwi:

  - Fixed test-image-live-disk
    Added missing openssh-server package
  - Fixed test-image-azure
    Add missing python-azure-agent-config-default package
  - Fixed debian integration test builds
    secure shell service is named ssh and not sshd there
  - Fixed integration test builds
    Second round of fixes for integration tests. Again errors
    now became visible due to the refactoring of the script code
  - Fixed integration test builds
    Errors from scripts were no longer ignored due to the last
    cleanup of the integration test script code. This commit
    fixes the now exposed build errors
  - Fix check_target_dir_on_unsupported_filesystem
    Find the first existing path in the target path and
    check the filesystem capabilities for this path.
    This Fixes #2858

++++ git:

  - update git-gui sha256 patches after the upstream review:
    0001-git-gui-Replace-null_sha1-with-nullid.patch
    0002-git-gui-Add-support-of-SHA256-repo.patch

++++ gnutls:

  - Build with leancrypto. The liboqs support for post-quantum
    cryptography (PQC) has been removed and is only provided through
    leancrypto.
  - Build with TPM 2.0 support via tpm2-0-tss.

++++ kernel-default:

  - dm-bufio: fix sched in atomic context (git-fixes).
  - commit ccc1d23
  - Update
    patches.suse/nvme-pci-fix-queue-unquiesce-check-on-slot_reset.patch
    (git-fixes bsc#1240885).
  - commit 03e1767
  - objtool: Fix error handling inconsistencies in check()
    (git-fixes).
  - commit ec79144
  - x86/traps: Make exc_double_fault() consistently noreturn
    (git-fixes).
  - commit bf4b16f
  - objtool: Fix C jump table annotations for Clang (git-fixes).
  - commit 529d2a6
  - objtool: Add bch2_trans_unlocked_error() to bcachefs noreturns
    (git-fixes).
  - commit 7e1fde5
  - perf: Fix sample vs do_exit() (bsc#1246547).
  - commit 073eb4d
  - drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() (bsc#1245951 CVE-2025-38187)
  - commit 9b6cd76
  - nvme-multipath: fix suspicious RCU usage warning (git-fixes).
  - nvme-pci: refresh visible attrs after being checked (git-fixes).
  - nvmet: fix memory leak of bio integrity (git-fixes).
  - nvme: Fix incorrect cdw15 value in passthru error logging
    (git-fixes).
  - nvme-tcp: fix I/O stalls on congested sockets (git-fixes).
  - commit 717d386
  - tools: fix atomic_set() definition to set the value correctly
    (git-fixes).
  - Refresh
    patches.suse/mm-replace-vm_lock-and-detached-flag-with-a-reference-coun.patch.
  - commit a7fcdf3
  - firewall: remove misplaced semicolon from
    stm32_firewall_get_firewall (git-fixes).
  - commit 2dc4084
  - scsi: lpfc: Copyright updates for 14.4.0.10 patches (bsc#1245260
    bsc#1243100 bsc#1246125).
  - scsi: lpfc: Update lpfc version to 14.4.0.10 (bsc#1245260
    bsc#1243100 bsc#1246125).
  - scsi: lpfc: Modify end-of-life adapters' model descriptions
    (bsc#1245260 bsc#1243100 bsc#1246125 bsc#1204142).
  - scsi: lpfc: Revise CQ_CREATE_SET mailbox bitfield definitions
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Move clearing of HBA_SETUP flag to before
    lpfc_sli4_queue_unset (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Ensure HBA_SETUP flag is used only for SLI4 in
    dev_loss_tmo_callbk (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Relocate clearing initial phba flags from link up
    to link down hdlr (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Simplify error handling for failed
    lpfc_get_sli4_parameters cmd (bsc#1245260 bsc#1243100
    bsc#1246125).
  - scsi: lpfc: Early return out of FDMI cmpl for locally rejected
    statuses (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Skip RSCN processing when FC_UNLOADING flag is set
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport
    structure (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Update debugfs trace ring initialization messages
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Revise logging format for failed CT MIB requests
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - commit db7c71a
  - sched_ext: fix application of sizeof to pointer (git-fixes).
  - commit 7226f76
  - crypto: hkdf - skip TVs with unapproved salt lengths in FIPS
    mode (bsc#1241200 bsc#1246134).
  - commit 5472af3
  - Update
    patches.suse/net-clear-the-dst-when-changing-skb-protocol.patch
    (bsc#1245954 CVE-2025-38192).
    Fix incorrect CVE reference.
  - commit 0f40511
  - bpf: Check rcu_read_lock_trace_held() in
    bpf_map_lookup_percpu_elem() (bsc#1245980 CVE-2025-38202).
  - commit ca2d088
  - bpf, sockmap: Avoid using sk_socket after free when sending
    (bsc#1245749 CVE-2025-38154).
  - selftest/bpf/benchs: Add benchmark for sockmap usage
    (bsc#1245749 CVE-2025-38154).
  - bpf, sockmap: Fix panic when calling skb_linearize (bsc#1245749
    CVE-2025-38154).
  - bpf, sockmap: fix duplicated data transmission (bsc#1245749
    CVE-2025-38154).
  - bpf, sockmap: Fix data lost during EAGAIN retries (bsc#1245749
    CVE-2025-38154).
  - commit b7122ae
  - btrfs: improve the warning and error message for
    btrfs_remove_qgroup() (bsc#1246357).
  - commit 01d925c

++++ kernel-firmware-bluetooth:

  - Update to version 20250714 (git commit ecdbd2b8af04):
    * linux-firmware: Update firmware file for Intel Solar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel BlazarI core

++++ kernel-firmware-qcom:

  - Update to version 20250714 (git commit ecdbd2b8af04):
    * qcom: Update gpu firmwares of QCS615 chipset

++++ kernel-rt:

  - dm-bufio: fix sched in atomic context (git-fixes).
  - commit ccc1d23
  - Update
    patches.suse/nvme-pci-fix-queue-unquiesce-check-on-slot_reset.patch
    (git-fixes bsc#1240885).
  - commit 03e1767
  - objtool: Fix error handling inconsistencies in check()
    (git-fixes).
  - commit ec79144
  - x86/traps: Make exc_double_fault() consistently noreturn
    (git-fixes).
  - commit bf4b16f
  - objtool: Fix C jump table annotations for Clang (git-fixes).
  - commit 529d2a6
  - objtool: Add bch2_trans_unlocked_error() to bcachefs noreturns
    (git-fixes).
  - commit 7e1fde5
  - perf: Fix sample vs do_exit() (bsc#1246547).
  - commit 073eb4d
  - drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() (bsc#1245951 CVE-2025-38187)
  - commit 9b6cd76
  - nvme-multipath: fix suspicious RCU usage warning (git-fixes).
  - nvme-pci: refresh visible attrs after being checked (git-fixes).
  - nvmet: fix memory leak of bio integrity (git-fixes).
  - nvme: Fix incorrect cdw15 value in passthru error logging
    (git-fixes).
  - nvme-tcp: fix I/O stalls on congested sockets (git-fixes).
  - commit 717d386
  - tools: fix atomic_set() definition to set the value correctly
    (git-fixes).
  - Refresh
    patches.suse/mm-replace-vm_lock-and-detached-flag-with-a-reference-coun.patch.
  - commit a7fcdf3
  - firewall: remove misplaced semicolon from
    stm32_firewall_get_firewall (git-fixes).
  - commit 2dc4084
  - scsi: lpfc: Copyright updates for 14.4.0.10 patches (bsc#1245260
    bsc#1243100 bsc#1246125).
  - scsi: lpfc: Update lpfc version to 14.4.0.10 (bsc#1245260
    bsc#1243100 bsc#1246125).
  - scsi: lpfc: Modify end-of-life adapters' model descriptions
    (bsc#1245260 bsc#1243100 bsc#1246125 bsc#1204142).
  - scsi: lpfc: Revise CQ_CREATE_SET mailbox bitfield definitions
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Move clearing of HBA_SETUP flag to before
    lpfc_sli4_queue_unset (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Ensure HBA_SETUP flag is used only for SLI4 in
    dev_loss_tmo_callbk (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Relocate clearing initial phba flags from link up
    to link down hdlr (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Simplify error handling for failed
    lpfc_get_sli4_parameters cmd (bsc#1245260 bsc#1243100
    bsc#1246125).
  - scsi: lpfc: Early return out of FDMI cmpl for locally rejected
    statuses (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Skip RSCN processing when FC_UNLOADING flag is set
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport
    structure (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Update debugfs trace ring initialization messages
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - scsi: lpfc: Revise logging format for failed CT MIB requests
    (bsc#1245260 bsc#1243100 bsc#1246125).
  - commit db7c71a
  - sched_ext: fix application of sizeof to pointer (git-fixes).
  - commit 7226f76
  - crypto: hkdf - skip TVs with unapproved salt lengths in FIPS
    mode (bsc#1241200 bsc#1246134).
  - commit 5472af3
  - Update
    patches.suse/net-clear-the-dst-when-changing-skb-protocol.patch
    (bsc#1245954 CVE-2025-38192).
    Fix incorrect CVE reference.
  - commit 0f40511
  - bpf: Check rcu_read_lock_trace_held() in
    bpf_map_lookup_percpu_elem() (bsc#1245980 CVE-2025-38202).
  - commit ca2d088
  - bpf, sockmap: Avoid using sk_socket after free when sending
    (bsc#1245749 CVE-2025-38154).
  - selftest/bpf/benchs: Add benchmark for sockmap usage
    (bsc#1245749 CVE-2025-38154).
  - bpf, sockmap: Fix panic when calling skb_linearize (bsc#1245749
    CVE-2025-38154).
  - bpf, sockmap: fix duplicated data transmission (bsc#1245749
    CVE-2025-38154).
  - bpf, sockmap: Fix data lost during EAGAIN retries (bsc#1245749
    CVE-2025-38154).
  - commit b7122ae
  - btrfs: improve the warning and error message for
    btrfs_remove_qgroup() (bsc#1246357).
  - commit 01d925c

++++ polkit:

  - CVE-2025-7519: Fixed that a XML policy file with a large number of
    nested elements may lead to out-of-bounds write (bsc#1246472)
    added 0001-Nested-.policy-files-cause-xml-parsing-overflow-lead.patch

++++ systemd:

  - systemd-update-helper: fix regression introduced when support for package
    renaming/splitting was added (bsc#1245551)
    The cleanup of the flags in /run/systemd/rpm was previously handled in the
    %pretrans/%posttrans sections of the systemd main package. However, this
    method was ineffective if systemd was not part of the transaction. The cleanup
    is now run in %transfiletriggerin instead.

++++ pam-config:

  - Update to version 2.13+git.20250715:
    * Release version 2.13
    * Place himmelblau near the top of pam stack [bsc#1243418]

++++ psmisc:

  - Add patch 0001-fuser-Fix-expandpath.patch
    * Is an upstream commit which fixes https://gitlab.com/psmisc/psmisc/-/issues/57
    as well as bug boo#1242093

------------------------------------------------------------------
------------------  2025-7-14  -  Jul 14 2025  -------------------
------------------------------------------------------------------

++++ accountsservice:

  - Update accountsservice-sysconfig.patch: Check whether sysconfig
    is used and fallback to display manager settings if sysconfig is
    not used (bsc#1246127).

++++ cockpit:

  - update check_cockpit_users to only check for systemd support in /etc/nsswitch.conf bsc#1246408

++++ curl:

  - Fix the --ftp-pasv option in curl v8.14.1 [bsc#1246197]
    * tool_getparam: fix --ftp-pasv [5f805ee]
    * Add curl-fix--ftp-pasv.patch

++++ branding-SLE:

  - Update square-hicolor.svg to adapt the GNOME light color style
    (bsc#1243104).

++++ python-kiwi:

  - Cleanup integration tests config.sh script code
    Add script code to shellcheck and fix all reported issues.
    Get rid of suseXX and baseXX methods as much as possible.
    Add set -ex for all script code. Do not allow any script
    code to fail.
  - defaults: Add patterns for shim/grub2 on riscv64
    A recent commit changed the way these are looked up and
    accidentally broke image building on riscv64, with
    KiwiBootLoaderGrubSecureBootError: Signed grub2 efi loader not found
    now being raised for kiwi recipes that worked just fine
    before that moment.
    Fixes: 197572378cf4f25103934beac2ceca4fbbcfcbc0
    Thanks: David Abdurachmanov <davidlt@rivosinc.com>
    Thanks: Marcus Schäfer <marcus.schaefer@gmail.com>
    Signed-off-by: Andrea Bolognani <abologna@redhat.com>

++++ gnutls:

  - Update to 3.8.10:
    * libgnutls: Fix NULL pointer dereference when 2nd Client Hello omits PSK
    Reported by Stefan Bühler. [GNUTLS-SA-2025-07-07-4, CVSS: medium]
    [bsc#1246299, CVE-2025-6395]
    * libgnutls: Fix heap read buffer overrun in parsing X.509 SCTS timestamps
    Spotted by oss-fuzz and reported by OpenAI Security Research Team,
    and fix developed by Andrew Hamilton. [GNUTLS-SA-2025-07-07-1,
    CVSS: medium] [bsc#1246233, CVE-2025-32989]
    * libgnutls: Fix double-free upon error when exporting otherName in SAN
    Reported by OpenAI Security Research Team. [GNUTLS-SA-2025-07-07-2,
    CVSS: low] [bsc#1246232, CVE-2025-32988]
    * certtool: Fix 1-byte write buffer overrun when parsing template
    Reported by David Aitel. [GNUTLS-SA-2025-07-07-3,
    CVSS: low] [bsc#1246267, CVE-2025-32990]
    * libgnutls: PKCS#11 modules can now be used to override the default
    cryptographic backend. Use the [provider] section in the system-wide config
    to specify path and pin to the module (see system-wide config Documentation).
    * libgnutls: Linux kernel version 6.14 brings a Kernel TLS (kTLS) key update
    support. The library running on the aforementioned version now utilizes the
    kernel’s key update mechanism when kTLS is enabled, allowing uninterrupted
    TLS session. The --enable-ktls configure option as well as the system-wide
    kTLS configuration(see GnuTLS Documentation) are still required to enable
    this feature.
    * libgnutls: liboqs support for PQC has been removed
    For maintenance purposes, support for post-quantum cryptography
    (PQC) is now only provided through leancrypto. The experimental key
    exchange algorithm, X25519Kyber768Draft00, which is based on the
    round 3 candidate of Kyber and only supported through liboqs has
    also been removed altogether.
    * libgnutls: TLS certificate compression methods can now be set with
    cert-compression-alg configuration option in the gnutls priority file.
    * libgnutls: All variants of ML-DSA private key formats are supported
    While the previous implementation of ML-DSA was based on
    draft-ietf-lamps-dilithium-certificates-04, this updates it to
    draft-ietf-lamps-dilithium-certificates-12 with support for all 3
    variants of private key formats: "seed", "expandedKey", and "both".
    * libgnutls: ML-DSA signatures can now be used in TLS
    The ML-DSA signature algorithms, ML-DSA-44, ML-DSA-65, and
    ML-DSA-87, can now be used to digitally sign TLS handshake
    messages.
    * API and ABI modifications:
  - GNUTLS_PKCS_MLDSA_SEED: New enum member of gnutls_pkcs_encrypt_flags_t
  - GNUTLS_PKCS_MLDSA_EXPANDED: New enum member of gnutls_pkcs_encrypt_flags_t
  - Add patch gnutls-3.8.10-disable-ktls_test.patch
  - Rebased patches:
    * gnutls-FIPS-140-3-references.patch
    * gnutls-FIPS-disable-mac-sha1.patch
    * gnutls-disable-flaky-test-dtls-resume.patch
    * gnutls-skip-pqx-test.patch

++++ hwinfo:

  - merge gh#openSUSE/hwinfo#170
  - Makefile: fix build for ARCH=i686
  - 25.0
  - merge gh#openSUSE/hwinfo#165
  - Fix memory leaks in block device name handling
  - merge gh#openSUSE/hwinfo#164
  - feat: capture usb alternate setting
  - feat: capture usb interface association
  - feat: use interface association descriptor first when classifying
    usb devices
  - USB improvements
  - merge gh#openSUSE/hwinfo#169
  - add nvmeof and iscsi info (jsc#PED-13261, jsc#PED-13209)

++++ texinfo:

  - Add texinfo-perl-5.42.patch: Fix syntax to be unambiguous
    if (! $str eq '') is not really clear; is it
    (!$str) eq ''
    or
    !($str eq '')
    Perl 5.42 rightly flagges this syntax with:
    Possible precedence problem between ! and string eq
    Assuming !($str eq '') was meant, we can rewrite this as
    $str ne '', which happens to also be used in multiple places
    already (sometimes just a few lines further down in the same
    files)

++++ kernel-default:

  - scsi: core: Enforce unlimited max_segment_size when
    virt_boundary_mask is set (git-fixes).
  - scsi: sd: Fix VPD page 0xb7 length check (git-fixes).
  - scsi: qla4xxx: Fix missing DMA mapping error in
    qla4xxx_alloc_pdu() (git-fixes).
  - scsi: qla2xxx: Fix DMA mapping test in
    qla24xx_get_port_database() (git-fixes).
  - scsi: megaraid_sas: Fix invalid node index (git-fixes).
  - aoe: clean device rq_list in aoedev_downdev() (git-fixes).
  - block: use plug request list tail for one-shot backmerge attempt
    (git-fixes).
  - block: don't use submit_bio_noacct_nocheck in
    blk_zone_wplug_bio_work (git-fixes).
  - block: Clear BIO_EMULATES_ZONE_APPEND flag on BIO completion
    (git-fixes).
  - md/md-bitmap: fix dm-raid max_write_behind setting (git-fixes).
  - scsi: smartpqi: Add new PCI IDs (git-fixes).
  - block: use q->elevator with ->elevator_lock held in
    elv_iosched_show() (git-fixes).
  - commit abdb18a
  - mm: fix uprobe pte be overwritten when expanding vma
    (CVE-2025-38207 bsc#1246004).
  - commit b1729e5
  - ipc: fix to protect IPCS lookups using RCU (CVE-2025-38212
    bsc#1246029).
  - commit 78df593
  - calipso: unlock rcu before returning -EAFNOSUPPORT
    (CVE-2025-38147 bsc#1245768).
  - calipso: Don't call calipso functions for AF_INET sk
    (CVE-2025-38147 bsc#1245768).
  - commit ddcefe6
  - s390x config: set CONFIG_PCI_NR_FUNCTIONS=512 (bsc#1246470 LTC#214321)
  - commit 1465ef8
  - x86/fred: Fix system hang during S4 resume with FRED enabled (bsc#1245084 CVE-2025-38047).
  - commit 622750a
  - hisi_acc_vfio_pci: bugfix live migration function without VF
    device driver (CVE-2025-38283 bsc#1246273).
  - configfs-tsm-report: Fix NULL dereference of tsm_ops
    (CVE-2025-38210 bsc#1246020).
  - commit fb63fb6

++++ kernel-rt:

  - scsi: core: Enforce unlimited max_segment_size when
    virt_boundary_mask is set (git-fixes).
  - scsi: sd: Fix VPD page 0xb7 length check (git-fixes).
  - scsi: qla4xxx: Fix missing DMA mapping error in
    qla4xxx_alloc_pdu() (git-fixes).
  - scsi: qla2xxx: Fix DMA mapping test in
    qla24xx_get_port_database() (git-fixes).
  - scsi: megaraid_sas: Fix invalid node index (git-fixes).
  - aoe: clean device rq_list in aoedev_downdev() (git-fixes).
  - block: use plug request list tail for one-shot backmerge attempt
    (git-fixes).
  - block: don't use submit_bio_noacct_nocheck in
    blk_zone_wplug_bio_work (git-fixes).
  - block: Clear BIO_EMULATES_ZONE_APPEND flag on BIO completion
    (git-fixes).
  - md/md-bitmap: fix dm-raid max_write_behind setting (git-fixes).
  - scsi: smartpqi: Add new PCI IDs (git-fixes).
  - block: use q->elevator with ->elevator_lock held in
    elv_iosched_show() (git-fixes).
  - commit abdb18a
  - mm: fix uprobe pte be overwritten when expanding vma
    (CVE-2025-38207 bsc#1246004).
  - commit b1729e5
  - ipc: fix to protect IPCS lookups using RCU (CVE-2025-38212
    bsc#1246029).
  - commit 78df593
  - calipso: unlock rcu before returning -EAFNOSUPPORT
    (CVE-2025-38147 bsc#1245768).
  - calipso: Don't call calipso functions for AF_INET sk
    (CVE-2025-38147 bsc#1245768).
  - commit ddcefe6
  - s390x config: set CONFIG_PCI_NR_FUNCTIONS=512 (bsc#1246470 LTC#214321)
  - commit 1465ef8
  - x86/fred: Fix system hang during S4 resume with FRED enabled (bsc#1245084 CVE-2025-38047).
  - commit 622750a
  - hisi_acc_vfio_pci: bugfix live migration function without VF
    device driver (CVE-2025-38283 bsc#1246273).
  - configfs-tsm-report: Fix NULL dereference of tsm_ops
    (CVE-2025-38210 bsc#1246020).
  - commit fb63fb6

++++ gcc15:

  - Update to GCC 15 branch head, 15.1.1+git9973
  - Fixes PR120995, unrecognizable insn UNSPEC_COMPARE_AND_SWAP with
    rv64gc_zabha_zacas

++++ libcontainers-common:

  - Remove subpackage libcontainers-sles-mounts and prevent auto mounting
    SUSEConnect credentials from host to container. SLE16 onwards, the idea is
    to expect users to explicitly mount secrets. (bsc#1246227)

++++ libzypp:

  - Add runtime check for a broken rpm-4.18.0 --runpostrans
    (bsc#1246149)
  - Add regression test for bsc#1245220 and some other filesize
    related tests.
  - version 17.37.11 (35)

++++ python-requests:

  - Add revert-caching-default-sslcontext.patch upstream patch to avoid
    problems with certificate caching in sslcontext.
    bsc#1246104, gh#psf/requests#6767

++++ rust-keylime:

  - Update vendored crates (bsc#1242623, CVE-2025-3416)
    * openssl 0.10.73
  - Update to version 0.2.7+117:
    * Increase coverage in evidence handling structure
    * Add Capabilities Negotiations resp. missing fields
    * Fix UEFI test to check file access in all cases
    * context_info_handler: Do not assume /var/lib/keylime exists
    * Fix clippy warnings about uninlined format arguments
    * attestation: Allow unwrap() in tests
    * Increase coverage (groom code, extend unit tests)
    * Include IMA/UEFI logs in Evidence Handling request
    * Include method to get all IMA entries as string
    * Send correct list of pcr banks and sign algorithms
    * Try to fix TPM tests related issues
    * Define attestation perform asynchronous
    * Perform attestation in push model agent binary
    * Refactor code to use new attestation.rs
    * Create attestation.rs for Attestation stuff
    * Move ContextInfo management to its own handler
    * Adjust context_info.rs after rebase
    * Add attestation function to ContextInfo structure
    * Add prohibited signing algorithms, avoid ecschnorr
    * keylime/config: Use macro to implement PushModelConfigTrait
    * Introduce keylime-macros and define_view_trait
    * config: Remove KeylimeConfig structure
    * config: Remove unnecessary options and lazy initialization
    * Fix pcr_bank function to send all possible slots
    * Send Content-Type:application/json on request (#1039)
    * Send correct 'key_algorithm' in certification_keys (#1035)
    * Push Model: Persist Attestation Key to file
    * Add Keylime push model binary to root GNUmakefile
    * Use singleton to avoid multiple Context allocation
    * tests: Do not assume `/var/lib/keylime` exists (#1030)
    * lib/cert: Fix race condition due to use of same file path
    * payloads: Fix race condition in tests
    * Add uefi_log_handler.rs to parse UEFI binary
    * Use IMA log parser to send correct entry count
    * Add IMA log parser
    * build(deps): bump once_cell from 1.19.0 to 1.21.3
    * lib/config/base.rs: Add more unit tests
    * lib/permissions: Add unit tests
    * keylime-agent: move JsonWrapper from common.rs to the library
    * lib/agent_data: Move agent_data related tests from common
    * common: Replace APIVersion with the library Version structure
    * keylime_agent: Move secure_mount.rs to the library
    * lib: Rename keylime_error.rs as error.rs
    * config: Move config to keylime library
    * config: Rename push_model_config to push_model
    * lib: Move permissions.rs from keylime-agent to the lib
    * Extract Capabilities Negotiation info from TPM (#1014)

------------------------------------------------------------------
------------------  2025-7-13  -  Jul 13 2025  -------------------
------------------------------------------------------------------

++++ gnutls:

  - enable ktls support
  - enable brotli and zstd compression support

++++ open-iscsi:

  - Update to version 2.1.11.suse+73.1723affc61eb:
    * README for rpm build directory
    * Fix issue with IPv6 adapter interfaces (#508, bsc#1240969)
    * fwparam_ppc.c: Fix the calloc-transposed-args issue (#504)
    * Makefile: fix "No rule to make target 'iscsiuio/Makefile.in" issue (#506)
    * Fix typo in initiator.c (#507)
  - Fixed some issues in this changes file
    * One date had incorrect format from 2014
    * Two separator lines were formatted incrrectly

++++ kernel-default:

  - kasan: remove kasan_find_vm_area() to prevent possible deadlock
    (git-fixes).
  - maple_tree: fix mt_destroy_walk() on root leaf node (git-fixes).
  - maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate()
    (git-fixes).
  - kasan: avoid sleepable page allocation from atomic context
    (git-fixes).
  - commit 3186bf7

++++ kernel-rt:

  - kasan: remove kasan_find_vm_area() to prevent possible deadlock
    (git-fixes).
  - maple_tree: fix mt_destroy_walk() on root leaf node (git-fixes).
  - maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate()
    (git-fixes).
  - kasan: avoid sleepable page allocation from atomic context
    (git-fixes).
  - commit 3186bf7

------------------------------------------------------------------
------------------  2025-7-12  -  Jul 12 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add SLFO test-image-disk-simple integration test
    Add simple disk test and allow for testing the new
    transparent container idea for the aws toolchain. also
    add SLFO builds to the helper script

++++ kernel-default:

  - drm/imagination: Fix kernel crash when hard resetting the GPU
    (git-fixes).
  - drm/tegra: nvdec: Fix dma_alloc_coherent error check
    (git-fixes).
  - drm/xe/pm: Correct comment of xe_pm_set_vram_threshold()
    (git-fixes).
  - drm/xe/bmg: fix compressed VRAM handling (git-fixes).
  - Revert "drm/xe/xe2: Enable Indirect Ring State support for Xe2"
    (git-fixes).
  - drm/xe: Allocate PF queue size on pow2 boundary (git-fixes).
  - drm/xe/pf: Clear all LMTT pages on alloc (git-fixes).
  - nbd: fix uaf in nbd_genl_connect() error path (git-fixes).
  - can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx
    message to debug level (git-fixes).
  - net: phy: microchip: limit 100M workaround to link-down events
    on LAN88xx (git-fixes).
  - net: phy: microchip: Use genphy_soft_reset() to purge stale
    LPA bits (git-fixes).
  - wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init()
    (git-fixes).
  - wifi: mt76: mt7921: prevent decap offload config before STA
    initialization (git-fixes).
  - wifi: mt76: mt7925: prevent NULL pointer dereference in
    mt7925_sta_set_decap_offload() (git-fixes).
  - wifi: mt76: mt7925: fix invalid array index in ssid assignment
    during hw scan (git-fixes).
  - wifi: mt76: mt7925: fix the wrong config for tx interrupt
    (git-fixes).
  - wifi: mwifiex: discard erroneous disassoc frames on STA
    interface (git-fixes).
  - wifi: mac80211: fix non-transmitted BSSID profile search
    (git-fixes).
  - wifi: zd1211rw: Fix potential NULL pointer dereference in
    zd_mac_tx_to_dev() (git-fixes).
  - commit 7d2f716

++++ kernel-rt:

  - drm/imagination: Fix kernel crash when hard resetting the GPU
    (git-fixes).
  - drm/tegra: nvdec: Fix dma_alloc_coherent error check
    (git-fixes).
  - drm/xe/pm: Correct comment of xe_pm_set_vram_threshold()
    (git-fixes).
  - drm/xe/bmg: fix compressed VRAM handling (git-fixes).
  - Revert "drm/xe/xe2: Enable Indirect Ring State support for Xe2"
    (git-fixes).
  - drm/xe: Allocate PF queue size on pow2 boundary (git-fixes).
  - drm/xe/pf: Clear all LMTT pages on alloc (git-fixes).
  - nbd: fix uaf in nbd_genl_connect() error path (git-fixes).
  - can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx
    message to debug level (git-fixes).
  - net: phy: microchip: limit 100M workaround to link-down events
    on LAN88xx (git-fixes).
  - net: phy: microchip: Use genphy_soft_reset() to purge stale
    LPA bits (git-fixes).
  - wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init()
    (git-fixes).
  - wifi: mt76: mt7921: prevent decap offload config before STA
    initialization (git-fixes).
  - wifi: mt76: mt7925: prevent NULL pointer dereference in
    mt7925_sta_set_decap_offload() (git-fixes).
  - wifi: mt76: mt7925: fix invalid array index in ssid assignment
    during hw scan (git-fixes).
  - wifi: mt76: mt7925: fix the wrong config for tx interrupt
    (git-fixes).
  - wifi: mwifiex: discard erroneous disassoc frames on STA
    interface (git-fixes).
  - wifi: mac80211: fix non-transmitted BSSID profile search
    (git-fixes).
  - wifi: zd1211rw: Fix potential NULL pointer dereference in
    zd_mac_tx_to_dev() (git-fixes).
  - commit 7d2f716

------------------------------------------------------------------
------------------  2025-7-11  -  Jul 11 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - add a requirement on /usr/sbin/kdumptool for cockpit-kdump (bsc#1227402)
  - add libzypp-plugin-appdata dependency to cockpit-packagekit as
    this will generate the swcatalog which it depends on for calculating
    various cockpit packages

++++ grub2:

  - Enable loongarch64 build (bsc#1234248)

++++ kernel-default:

  - xfs: fix off-by-one error in fsmap's end_daddr usage
    (bsc#1235837).
  - commit f532c0d
  - hisi_acc_vfio_pci: fix XQE dma address error (CVE-2025-38158
    bsc#1245750).
  - commit d6de051
  - platform/x86: think-lmi: Create ksets consecutively
    (stable-fixes).
  - Refresh
    patches.suse/platform-x86-think-lmi-Fix-kobject-cleanup.patch.
  - commit ed9e879
  - ASoC: tas2764: Extend driver to SN012776 (stable-fixes).
  - Refresh
    patches.suse/ASoC-tas2764-Reinit-cache-on-part-reset.patch.
  - commit d98ebe4
  - drm/xe/guc: Dead CT helper (stable-fixes).
  - Refresh
    patches.suse/drm-xe-Fix-early-wedge-on-GuC-load-failure.patch.
  - commit f279fcb
  - net: phy: smsc: Fix link failure in forced mode with Auto-MDIX
    (git-fixes).
  - net: phy: smsc: Force predictable MDI-X state on LAN87xx
    (git-fixes).
  - net: phy: smsc: Fix Auto-MDIX configuration when disabled by
    strap (git-fixes).
  - Bluetooth: hci_event: Fix not marking Broadcast Sink BIS as
    connected (git-fixes).
  - Bluetooth: hci_sync: Fix not disabling advertising instance
    (git-fixes).
  - platform/x86: dell-wmi-sysman: Fix class device unregistration
    (git-fixes).
  - platform/x86: think-lmi: Fix class device unregistration
    (git-fixes).
  - platform/x86: hp-bioscfg: Fix class device unregistration
    (git-fixes).
  - usb: xhci: quirk for data loss in ISOC transfers (stable-fixes).
  - Logitech C-270 even more broken (stable-fixes).
  - Input: xpad - support Acer NGR 200 Controller (stable-fixes).
  - dma-buf: fix timeout handling in dma_resv_wait_timeout v2
    (stable-fixes).
  - mmc: sdhci: Add a helper function for dump register in dynamic
    debug mode (stable-fixes).
  - drm/xe/guc: Explicitly exit CT safe mode on unwind (git-fixes).
  - drm/xe: move DPT l2 flush to a more sensible place (git-fixes).
  - drm/xe: Move DSB l2 flush to a more sensible place (git-fixes).
  - ACPICA: Refuse to evaluate a method if arguments are missing
    (stable-fixes).
  - mtd: spinand: fix memory leak of ECC engine conf (stable-fixes).
  - ASoC: amd: yc: update quirk data for HP Victus (stable-fixes).
  - ASoC: amd: yc: Add quirk for MSI Bravo 17 D7VF internal mic
    (stable-fixes).
  - ALSA: sb: Force to disable DMAs once when DMA mode is changed
    (stable-fixes).
  - ALSA: sb: Don't allow changing the DMA mode during operations
    (stable-fixes).
  - drm/msm: Fix another leak in the submit error path
    (stable-fixes).
  - drm/msm: Fix a fence leak in submit error path (stable-fixes).
  - regulator: fan53555: add enable_time support and soft-start
    times (stable-fixes).
  - wifi: ath6kl: remove WARN on bad firmware input (stable-fixes).
  - wifi: mac80211: drop invalid source address OCB frames
    (stable-fixes).
  - ata: pata_cs5536: fix build on 32-bit UML (stable-fixes).
  - platform/x86/amd/pmc: Add PCSpecialist Lafite Pro V 14M to
    8042 quirks list (stable-fixes).
  - ACPI: thermal: Execute _SCP before reading trip points
    (git-fixes).
  - crypto: zynqmp-sha - Add locking (git-fixes).
  - crypto: iaa - Do not clobber req->base.data (git-fixes).
  - crypto: iaa - Remove dst_null support (stable-fixes).
  - spinlock: extend guard with spinlock_bh variants (stable-fixes).
  - ACPI: thermal: Fix stale comment regarding trip points
    (stable-fixes).
  - platform/x86: dell-sysman: Directly use
    firmware_attributes_class (stable-fixes).
  - platform/x86: hp-bioscfg: Directly use firmware_attributes_class
    (stable-fixes).
  - platform/x86: think-lmi: Directly use firmware_attributes_class
    (stable-fixes).
  - platform/x86: firmware_attributes_class: Simplify API
    (stable-fixes).
  - platform/x86: firmware_attributes_class: Move include
    linux/device/class.h (stable-fixes).
  - drm/xe: Allow bo mapping on multiple ggtts (stable-fixes).
  - drm/xe: add interface to request physical alignment for buffer
    objects (stable-fixes).
  - drm/xe: Fix DSB buffer coherency (stable-fixes).
  - drm/xe: Replace double space with single space after comma
    (stable-fixes).
  - commit 909dad5
  - i40e: fix MMIO write access to an invalid page in i40e_clear_hw
    (CVE-2025-38200 bsc#1246045).
  - net: cadence: macb: Fix a possible deadlock in macb_halt_tx
    (CVE-2025-38094 bsc#1245649).
  - commit 13d7db9
  - x86/process: Move the buffer clearing before MONITOR (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - commit 8266745
  - x86/microcode/AMD: Add TSA microcode SHAs (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - commit b20882f
  - KVM: SVM: Advertise TSA CPUID bits to guests (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - commit eae5894
  - x86/cpu: Avoid running off the end of an AMD erratum table (git-fixes).
  - commit 1a01a37
  - x86/cpu: Move AMD erratum 1386 table over to 'x86_cpu_id' (git-fixes).
  - commit 00956a9
  - x86/cpu: Replace PEBS use of 'x86_cpu_desc' use with 'x86_cpu_id' (git-fixes).
  - commit a673ad4
  - x86/cpu: Introduce new microcode matching helper (git-fixes).
  - commit e274dab
  - x86/bugs: Add a Transient Scheduler Attacks mitigation (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - Update config files.
  - commit 8a110dc
  - kabi: fix dm-fix-dm_blk_report_zones.patch
    (CVE-2025-38140 bsc#1245717).
  - commit 701faad
  - net: clear the dst when changing skb protocol (bsc#1245954
    CVE-2024-49861).
  - commit b34915e

++++ kernel-rt:

  - xfs: fix off-by-one error in fsmap's end_daddr usage
    (bsc#1235837).
  - commit f532c0d
  - hisi_acc_vfio_pci: fix XQE dma address error (CVE-2025-38158
    bsc#1245750).
  - commit d6de051
  - platform/x86: think-lmi: Create ksets consecutively
    (stable-fixes).
  - Refresh
    patches.suse/platform-x86-think-lmi-Fix-kobject-cleanup.patch.
  - commit ed9e879
  - ASoC: tas2764: Extend driver to SN012776 (stable-fixes).
  - Refresh
    patches.suse/ASoC-tas2764-Reinit-cache-on-part-reset.patch.
  - commit d98ebe4
  - drm/xe/guc: Dead CT helper (stable-fixes).
  - Refresh
    patches.suse/drm-xe-Fix-early-wedge-on-GuC-load-failure.patch.
  - commit f279fcb
  - net: phy: smsc: Fix link failure in forced mode with Auto-MDIX
    (git-fixes).
  - net: phy: smsc: Force predictable MDI-X state on LAN87xx
    (git-fixes).
  - net: phy: smsc: Fix Auto-MDIX configuration when disabled by
    strap (git-fixes).
  - Bluetooth: hci_event: Fix not marking Broadcast Sink BIS as
    connected (git-fixes).
  - Bluetooth: hci_sync: Fix not disabling advertising instance
    (git-fixes).
  - platform/x86: dell-wmi-sysman: Fix class device unregistration
    (git-fixes).
  - platform/x86: think-lmi: Fix class device unregistration
    (git-fixes).
  - platform/x86: hp-bioscfg: Fix class device unregistration
    (git-fixes).
  - usb: xhci: quirk for data loss in ISOC transfers (stable-fixes).
  - Logitech C-270 even more broken (stable-fixes).
  - Input: xpad - support Acer NGR 200 Controller (stable-fixes).
  - dma-buf: fix timeout handling in dma_resv_wait_timeout v2
    (stable-fixes).
  - mmc: sdhci: Add a helper function for dump register in dynamic
    debug mode (stable-fixes).
  - drm/xe/guc: Explicitly exit CT safe mode on unwind (git-fixes).
  - drm/xe: move DPT l2 flush to a more sensible place (git-fixes).
  - drm/xe: Move DSB l2 flush to a more sensible place (git-fixes).
  - ACPICA: Refuse to evaluate a method if arguments are missing
    (stable-fixes).
  - mtd: spinand: fix memory leak of ECC engine conf (stable-fixes).
  - ASoC: amd: yc: update quirk data for HP Victus (stable-fixes).
  - ASoC: amd: yc: Add quirk for MSI Bravo 17 D7VF internal mic
    (stable-fixes).
  - ALSA: sb: Force to disable DMAs once when DMA mode is changed
    (stable-fixes).
  - ALSA: sb: Don't allow changing the DMA mode during operations
    (stable-fixes).
  - drm/msm: Fix another leak in the submit error path
    (stable-fixes).
  - drm/msm: Fix a fence leak in submit error path (stable-fixes).
  - regulator: fan53555: add enable_time support and soft-start
    times (stable-fixes).
  - wifi: ath6kl: remove WARN on bad firmware input (stable-fixes).
  - wifi: mac80211: drop invalid source address OCB frames
    (stable-fixes).
  - ata: pata_cs5536: fix build on 32-bit UML (stable-fixes).
  - platform/x86/amd/pmc: Add PCSpecialist Lafite Pro V 14M to
    8042 quirks list (stable-fixes).
  - ACPI: thermal: Execute _SCP before reading trip points
    (git-fixes).
  - crypto: zynqmp-sha - Add locking (git-fixes).
  - crypto: iaa - Do not clobber req->base.data (git-fixes).
  - crypto: iaa - Remove dst_null support (stable-fixes).
  - spinlock: extend guard with spinlock_bh variants (stable-fixes).
  - ACPI: thermal: Fix stale comment regarding trip points
    (stable-fixes).
  - platform/x86: dell-sysman: Directly use
    firmware_attributes_class (stable-fixes).
  - platform/x86: hp-bioscfg: Directly use firmware_attributes_class
    (stable-fixes).
  - platform/x86: think-lmi: Directly use firmware_attributes_class
    (stable-fixes).
  - platform/x86: firmware_attributes_class: Simplify API
    (stable-fixes).
  - platform/x86: firmware_attributes_class: Move include
    linux/device/class.h (stable-fixes).
  - drm/xe: Allow bo mapping on multiple ggtts (stable-fixes).
  - drm/xe: add interface to request physical alignment for buffer
    objects (stable-fixes).
  - drm/xe: Fix DSB buffer coherency (stable-fixes).
  - drm/xe: Replace double space with single space after comma
    (stable-fixes).
  - commit 909dad5
  - i40e: fix MMIO write access to an invalid page in i40e_clear_hw
    (CVE-2025-38200 bsc#1246045).
  - net: cadence: macb: Fix a possible deadlock in macb_halt_tx
    (CVE-2025-38094 bsc#1245649).
  - commit 13d7db9
  - x86/process: Move the buffer clearing before MONITOR (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - commit 8266745
  - x86/microcode/AMD: Add TSA microcode SHAs (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - commit b20882f
  - KVM: SVM: Advertise TSA CPUID bits to guests (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - commit eae5894
  - x86/cpu: Avoid running off the end of an AMD erratum table (git-fixes).
  - commit 1a01a37
  - x86/cpu: Move AMD erratum 1386 table over to 'x86_cpu_id' (git-fixes).
  - commit 00956a9
  - x86/cpu: Replace PEBS use of 'x86_cpu_desc' use with 'x86_cpu_id' (git-fixes).
  - commit a673ad4
  - x86/cpu: Introduce new microcode matching helper (git-fixes).
  - commit e274dab
  - x86/bugs: Add a Transient Scheduler Attacks mitigation (bsc#1238896 CVE-2024-36350 CVE-2024-36357 CVE-2024-36348 CVE-2024-36349).
  - Update config files.
  - commit 8a110dc
  - kabi: fix dm-fix-dm_blk_report_zones.patch
    (CVE-2025-38140 bsc#1245717).
  - commit 701faad
  - net: clear the dst when changing skb protocol (bsc#1245954
    CVE-2024-49861).
  - commit b34915e

++++ llvm19:

  - Add reproducible.patch to make libomp.so reproducible (boo#1199076)
  - Replace usage of %jobs for reproducible builds (boo#1237231)

++++ at-spi2-core:

  - Add upstream fixes:
    +  at-spi2-core-grab-memory-leak.patch
    + at-spi2-core-key-grabs.patch (glgo#GNOME/at-spi2-core!193)
    + at-spi2-core-plug-crash.patch (glgo#GNOME/at-spi2-core#198)

++++ procps:

  - Add patch procps-ng-4.0.5-bsc1246330.patch
    * Do not Fail in year 2038 (bsc#1246330)

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.172.08 (boo#1246327)
  - supersedes
    * 0003-nv-dmabuf-Inline-dma_buf_attachment_is_dynamic.patch
    * 0004-nvidia-uvm-Disable-SVA-support-for-6.16.patch
  - update pci_ids-supported

++++ perl:

  - update to 5.42.0
    * new pragma "source::encoding"
    * new ":writer" attribute on field variables
    * new "any" and "all" operators
    * lexical method declaration using "my method"
    * lexical method invocation operator "->&"
    * switch and Smart Match operator kept, behind a feature
    * unicode 16.0 supported
    * assigning logical xor "^^=" operator
    * many performance enhancements
  - drop perl-dirdup.diff (included upstream)

------------------------------------------------------------------
------------------  2025-7-10  -  Jul 10 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Show reboot nofication after updates in packagekit
    * Add 0009-packagekit-reboot-notification.patch

++++ crypto-policies:

  - Add the FIPS scripts fips-finish-install and fips-mode-setup as
    sources in the spec file as they have been removed upstream.
    * We will maintain these scripts downstream.
    * Update the man pages for update-crypto-policies.8.gz
    * Rebase crypto-policies-no-build-manpages.patch
    * Add crypto-policies-FIPS-output.patch
    * Add man pages in text file in compressed form in the file
    man-fips-scripts.tar.xz and add them to the Makefile.
  - Update to version 20250324.3714354:
    * NO-PQ: introduce
    * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA
    * _openssl_block_sha1_signatures: flip the default to 1
    * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia
    * sequoia: refactor a bit
    * openssl: specify default key size for req
    * gnutls: support P384-MLKEM1024
    * openssl: stop generating `openssl` in favour of `opensslcnf`
    * gnutls: drop kyber (switching to leancrypto took it away)
    * openssl: use both names for P384-MLKEM1024
    * Detect the presence of nss-policy-check
    * Don't use hardcoded python3 path
    * Make xsltproc settable as XSLTPROC
    * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021
    * Update the info in the README.SUSE file
    * Remove the FEDORA policies and directories
    * Remove patches:
  - crypto-policies-supported.patch
  - crypto-policies-FIPS.patch
    * Rebase patches:
  - crypto-policies-policygenerators.patch
  - crypto-policies-enable-SHA1-sigver-in-DEFAULT.patch
  - crypto-policies-Allow-sshd-in-FIPS-mode-using-DEFAULT.patch

++++ kernel-default:

  - dm: limit swapping tables for devices with zone write plugs
    (CVE-2025-38140 bsc#1245717).
  - commit 8c8d49f
  - dm: fix dm_blk_report_zones (CVE-2025-38140 bsc#1245717).
  - commit 6d395b8
  - dm-table: check BLK_FEAT_ATOMIC_WRITES inside limits_lock
    (git-fixes).
  - commit d31c434
  - coresight: prevent deactivate active config while enabling
    the config (CVE-2025-38131 bsc#1245677).
  - coresight: holding cscfg_csdev_lock while removing cscfg from
    csdev (CVE-2025-38132 bsc#1245679).
  - commit 4dcb9b9
  - ACPI: PRM: Reduce unnecessary printing to avoid user confusion
    (bsc#1246122).
  - commit 13b2592
  - ALSA: hda: Add missing NVIDIA HDA codec IDs (stable-fixes).
  - ALSA: hda/tegra: Add Tegra264 support (stable-fixes).
  - commit df0e4a0
  - ALSA: hda/realtek: Add quirk for ASUS ExpertBook B9403CVAR
    (stable-fixes).
  - ALSA: usb-audio: Improve filtering of sample rates on Focusrite
    devices (stable-fixes).
  - ALSA: hda/realtek - Enable mute LED on HP Pavilion Laptop
    15-eg100 (stable-fixes).
  - commit 3d097e2
  - ALSA: hda/realtek: Enable headset Mic on Positivo K116J
    (stable-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Victus 15-fb2xxx
    (stable-fixes).
  - ALSA: hda/realtek: Add quirks for some Clevo laptops
    (stable-fixes).
  - ALSA: hda/realtek: Enable headset Mic on Positivo P15X
    (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Asus GA605K (stable-fixes).
  - commit c130ef1
  - pinctrl: amd: Clear GPIO debounce for suspend (git-fixes).
  - pinctrl: qcom: msm: mark certain pins as invalid for interrupts
    (git-fixes).
  - commit f2d1e17

++++ kernel-firmware-amdgpu:

  - Update to version 20250708 (git commit 99d64b4f788c):
    * amdgpu: Add DCN 3.6
    * amdgpu: Add PSP 14.0.5
    * amdgpu: Add SDMA 6.1.3
    * amdgpu: Add GC 11.5.3

++++ kernel-firmware-i915:

  - Update to version 20250708 (git commit 99d64b4f788c):
    * xe: Add fan_control v203.0.0.0 for BMG

++++ kernel-firmware-mediatek:

  - Update to version 20250708 (git commit 99d64b4f788c):
    * mediatek MT7921: update bluetooth firmware to 20250625154126

++++ kernel-firmware-qcom:

  - Update to version 20250708 (git commit 99d64b4f788c):
    * qcom/adreno: move A610 and A702 ZAP files to Adreno driver section
    * qcom: Add sdx61 Foxconn vendor firmware image file

++++ kernel-rt:

  - dm: limit swapping tables for devices with zone write plugs
    (CVE-2025-38140 bsc#1245717).
  - commit 8c8d49f
  - dm: fix dm_blk_report_zones (CVE-2025-38140 bsc#1245717).
  - commit 6d395b8
  - dm-table: check BLK_FEAT_ATOMIC_WRITES inside limits_lock
    (git-fixes).
  - commit d31c434
  - coresight: prevent deactivate active config while enabling
    the config (CVE-2025-38131 bsc#1245677).
  - coresight: holding cscfg_csdev_lock while removing cscfg from
    csdev (CVE-2025-38132 bsc#1245679).
  - commit 4dcb9b9
  - ACPI: PRM: Reduce unnecessary printing to avoid user confusion
    (bsc#1246122).
  - commit 13b2592
  - ALSA: hda: Add missing NVIDIA HDA codec IDs (stable-fixes).
  - ALSA: hda/tegra: Add Tegra264 support (stable-fixes).
  - commit df0e4a0
  - ALSA: hda/realtek: Add quirk for ASUS ExpertBook B9403CVAR
    (stable-fixes).
  - ALSA: usb-audio: Improve filtering of sample rates on Focusrite
    devices (stable-fixes).
  - ALSA: hda/realtek - Enable mute LED on HP Pavilion Laptop
    15-eg100 (stable-fixes).
  - commit 3d097e2
  - ALSA: hda/realtek: Enable headset Mic on Positivo K116J
    (stable-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Victus 15-fb2xxx
    (stable-fixes).
  - ALSA: hda/realtek: Add quirks for some Clevo laptops
    (stable-fixes).
  - ALSA: hda/realtek: Enable headset Mic on Positivo P15X
    (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Asus GA605K (stable-fixes).
  - commit c130ef1
  - pinctrl: amd: Clear GPIO debounce for suspend (git-fixes).
  - pinctrl: qcom: msm: mark certain pins as invalid for interrupts
    (git-fixes).
  - commit f2d1e17

++++ python313-core:

  - Fix gil/nogil package description, bsc#1246229

++++ net-tools:

  - Perform bound checks when parsing interface labels in
    /proc/net/dev (bsc#1243581, CVE-2025-46836, GHSA-pfwf-h6m3-63wf,
    net-tools-CVE-2025-46836.patch,
    net-tools-CVE-2025-46836-regression.patch).

++++ python313:

  - Fix gil/nogil package description, bsc#1246229

++++ systemd-presets-common-SUSE:

  - Add cockpit.socket to improve user experience as it is replacing
    YaST (jsc#PED-13228)

++++ ucode-amd:

  - Update to version 20250708 (git commit 99d64b4f788c):
    * linux-firmware: Update AMD cpu microcode

------------------------------------------------------------------
------------------  2025-7-9  -  Jul 9 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Explicitly set uefi as default firmware (bsc#1245145)

++++ docker:

  - Update to Docker 28.3.2-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2832>

++++ python-kiwi:

  - Fixed check for unallocated space on disk
    So far the check for unallocated space was only working for GPT
    and there it was also not really stable. The check was based on
    verifying if the backup GPT table is really at the end of the
    disk. Depending on which tool was used to dump the image on the
    target this "mistake" often got corrected by the tools that
    dumped the image. In this case the check no longer worked.
    This commit improves the check by another test which looks
    for the real free bytes on disk compared to the current
    partition geometry.
  - Move to neutral directory for calling osc
    When calling the helper/build_status.sh script to get an
    overview about the results of the integration tests, there
    is a stupid new behavior from the osc tool that it assumes
    a package name according to the name of the directory you
    are in probably connected to the fact that the data in this
    directory is a git checkout or some other strange assumption.
    This commit moves to a neutral directory where none of the
    osc internal assumptions applies and it just does what it
    should do... showing results of the given project.
  - Bump version: 10.2.26 → 10.2.27

++++ transactional-update:

  - Version 5.0.6
  - Fix missing x-initrd.mount in fstab on migration [boo#1246139]
    When migrating overlayfs based /etc to btrfs subvolumes, then
    the attribute was not set - this may result in failures from
    services operating on /etc during initrd phase such as SELinux
    relabelling
  - Optimize execution time of tests

++++ git:

  - refreshed gitk sha256 patches:
    0001-gitk-Add-support-of-SHA256-repo.patch
    0002-git-gui-Add-support-of-SHA256-repo.patch
  - update to 2.50.1 (boo#1245938 boo#1245939 boo#1245942 boo#1245943
    boo#1245946 boo#1245947)
    Security fixes for CVE-2025-27613, CVE-2025-27614,
    CVE-2025-46334, CVE-2025-46835, CVE-2025-48384, CVE-2025-48385,
    and CVE-2025-48386
    CVE-2025-27613, Gitk:
    When a user clones an untrusted repository and runs Gitk without
    additional command arguments, any writable file can be created and
    truncated. The option "Support per-file encoding" must have been
    enabled. The operation "Show origin of this line" is affected as
    well, regardless of the option being enabled or not.
    CVE-2025-27614, Gitk:
    A Git repository can be crafted in such a way that a user who has
    cloned the repository can be tricked into running any script
    supplied by the attacker by invoking `gitk filename`, where
    `filename` has a particular structure.
    CVE-2025-46334, Git GUI (Windows only):
    A malicious repository can ship versions of sh.exe or typical
    textconv filter programs such as astextplain. On Windows, path
    lookup can find such executables in the worktree. These programs
    are invoked when the user selects "Git Bash" or "Browse Files" from
    the menu.
    CVE-2025-46835, Git GUI:
    When a user clones an untrusted repository and is tricked into
    editing a file located in a maliciously named directory in the
    repository, then Git GUI can create and overwrite any writable
    file.
    CVE-2025-48384, Git:
    When reading a config value, Git strips any trailing carriage
    return and line feed (CRLF). When writing a config entry, values
    with a trailing CR are not quoted, causing the CR to be lost when
    the config is later read.  When initializing a submodule, if the
    submodule path contains a trailing CR, the altered path is read
    resulting in the submodule being checked out to an incorrect
    location. If a symlink exists that points the altered path to the
    submodule hooks directory, and the submodule contains an executable
    post-checkout hook, the script may be unintentionally executed
    after checkout.
    CVE-2025-48385, Git:
    When cloning a repository Git knows to optionally fetch a bundle
    advertised by the remote server, which allows the server-side to
    offload parts of the clone to a CDN. The Git client does not
    perform sufficient validation of the advertised bundles, which
    allows the remote side to perform protocol injection.
    This protocol injection can cause the client to write the fetched
    bundle to a location controlled by the adversary. The fetched
    content is fully controlled by the server, which can in the worst
    case lead to arbitrary code execution.
    CVE-2025-48386, Git:
    The wincred credential helper uses a static buffer (`target`) as a
    unique key for storing and comparing against internal storage. This
    credential helper does not properly bounds check the available
    space remaining in the buffer before appending to it with
    `wcsncat()`, leading to potential buffer overflows.

++++ kdump:

  - upgrade to version 2.1.1
    * check for reserved memory on load for better error reporting
    * update man page
    * set KDUMP_CPUS to 1 on XEN (bsc#1244289)
    * load.sh clean up
    * use eval for PRESCRIPT, POSTSCRIPT and TRANSFER
    * sftp: fix key-based authentication
    * fix and improve calibrate build
  - update calibrate values

++++ kernel-default:

  - kabi: restore encap_sk in struct xfrm_state (CVE-2025-38097
    bsc#1245660).
  - espintcp: remove encap socket caching to avoid reference leak
    (CVE-2025-38097 bsc#1245660).
  - commit 063ca35
  - net: lan743x: fix potential out-of-bounds write in
    lan743x_ptp_io_event_clock_get() (CVE-2025-38183 bsc#1246006).
  - commit 39da23e
  - net_sched: sch_sfq: fix a potential crash on gso_skb handling
    (CVE-2025-38115 bsc#1245689).
  - commit 9e19da0
  - ALSA: usb-audio: Kill timer properly at removal (CVE-2025-38105
    bsc#1245682).
  - commit 79e6efd
  - rpm/mkspec: Fix missing kernel-syms-rt creation (bsc#1244337)
  - commit 630f139
  - exfat: fix double free in delayed_free (bsc#1246073
    CVE-2025-38206).
  - commit ad15d15
  - pwm: mediatek: Ensure to disable clocks in error path
    (git-fixes).
  - pwm: Fix invalid state detection (git-fixes).
  - ASoC: cs35l56: probe() should fail if the device ID is not
    recognized (git-fixes).
  - ASoC: fsl_sai: Force a software reset when starting in consumer
    mode (git-fixes).
  - ASoC: Intel: SND_SOC_INTEL_SOF_BOARD_HELPERS select
    SND_SOC_ACPI_INTEL_MATCH (git-fixes).
  - ASoC: fsl_asrc: use internal measured ratio for non-ideal
    ratio mode (git-fixes).
  - ALSA: ad1816a: Fix potential NULL pointer deref in
    snd_card_ad1816a_pnp() (git-fixes).
  - commit 04c53e4

++++ kernel-rt:

  - kabi: restore encap_sk in struct xfrm_state (CVE-2025-38097
    bsc#1245660).
  - espintcp: remove encap socket caching to avoid reference leak
    (CVE-2025-38097 bsc#1245660).
  - commit 063ca35
  - net: lan743x: fix potential out-of-bounds write in
    lan743x_ptp_io_event_clock_get() (CVE-2025-38183 bsc#1246006).
  - commit 39da23e
  - net_sched: sch_sfq: fix a potential crash on gso_skb handling
    (CVE-2025-38115 bsc#1245689).
  - commit 9e19da0
  - ALSA: usb-audio: Kill timer properly at removal (CVE-2025-38105
    bsc#1245682).
  - commit 79e6efd
  - rpm/mkspec: Fix missing kernel-syms-rt creation (bsc#1244337)
  - commit 630f139
  - exfat: fix double free in delayed_free (bsc#1246073
    CVE-2025-38206).
  - commit ad15d15
  - pwm: mediatek: Ensure to disable clocks in error path
    (git-fixes).
  - pwm: Fix invalid state detection (git-fixes).
  - ASoC: cs35l56: probe() should fail if the device ID is not
    recognized (git-fixes).
  - ASoC: fsl_sai: Force a software reset when starting in consumer
    mode (git-fixes).
  - ASoC: Intel: SND_SOC_INTEL_SOF_BOARD_HELPERS select
    SND_SOC_ACPI_INTEL_MATCH (git-fixes).
  - ASoC: fsl_asrc: use internal measured ratio for non-ideal
    ratio mode (git-fixes).
  - ALSA: ad1816a: Fix potential NULL pointer deref in
    snd_card_ad1816a_pnp() (git-fixes).
  - commit 04c53e4

++++ gcc15:

  - Prune the use of update-alternatives from openSUSE Factory and
    SLFO.
  - Adjust crosses to conflict consistently where they did not
    already and make them use unsuffixed binaries.

------------------------------------------------------------------
------------------  2025-7-8  -  Jul 8 2025  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.690.g496a1409:
    * fix(rngd): adjust license to match the license of the whole project
    * fix(dracut): kernel module name normalization in drivers lists (bsc#1241680)
    * fix(dracut-init): assign real path to srcmods (bsc#1241114)

++++ python-kiwi:

  - Fix regression in get_partition_node_name
    backwards compat for lsblk before 2.38
    if START column not supported, fall back to default sort
  - Add global option --setenv
    Allow to set environment variables in the caller environment
    via the commandline, e.g --setenv SOURCE_DATE_EPOCH=42
  - Seed filesystem UUIDs with SOURCE_DATE_EPOCH
    For reproducible builds the calculation of the filesystem UUID
    should be persistent with each rebuild of the image. To achieve
    this the UUID is calculated using the SOURCE_DATE_EPOCH from
    the environment plus a char-number representation of the filesystem
    label name as random seed. In kiwi every filesystem is created
    with a label, thus only in case there is no SOURCE_DATE_EPOCH
    available we continue to create the UUID as random data.
    This Fixes #2761
  - Add label attribute for <partition> section
    Allow to specify a filesystem label as part of a <partition>
    definition. So far the label was set by the name of the
    partition. With the new label attribute, a filesystem label
    different from the partition name can be set. This commit
    also updates/fixes the documentation in this regard.
  - Improve log message in SystemIdentifier
    Add some scope information such that we know from where
    this log information originates from.

++++ grub2:

  - Backport upstream disk password retry (bsc#1245545)
    * 0001-disk-cryptodisk-Allow-user-to-retry-failed-passphras.patch

++++ jeos-firstboot:

  - Update to version 1.5.8:
    * Update files/usr/share/jeos-firstboot/jeos-firstboot-functions
    * Use SUSE_PRETTY_NAME as product name to display if it exists (bsc#1245364)
    * Use xterm-256color on WSL based hosts boo#1237756

++++ kernel-default:

  - dm-raid: fix variable in journal device check (git-fixes).
  - commit 03404b3
  - dm-verity: fix a memory leak if some arguments are specified
    multiple times (git-fixes).
  - commit bbecd6f
  - dm-mirror: fix a tiny race condition (git-fixes).
  - commit 0d4f8fc
  - dm vdo indexer: don't read request structure after enqueuing
    (git-fixes).
  - commit 4cb65b5
  - dm-table: Set BLK_FEAT_ATOMIC_WRITES for target queue limits
    (git-fixes).
  - commit 2396437
  - dm-flakey: make corrupting read bios work (git-fixes).
  - commit b0152c6
  - dm-flakey: error all IOs when num_features is absent
    (git-fixes).
  - commit fd9c57b
  - dm: lock limits when reading them (git-fixes).
  - commit 153ee47
  - dm: handle failures in dm_table_set_restrictions (git-fixes).
  - commit 78fcb29
  - dm: free table mempools if not used in __bind (git-fixes).
  - commit 5859b3f
  - dm: don't change md if dm_table_set_restrictions() fails
    (git-fixes).
  - commit 4bd9525
  - virtgpu: don't reset on shutdown (git-fixes).
  - commit 901c686
  - kernel/fork: only call untrack_pfn_clear() on VMAs duplicated
    for fork() (git-fix for CVE-2025-22090 bsc#1241537).
  - commit 09cb3ff
  - netfilter: nft_set_pipapo: prevent overflow in lookup table
    allocation (CVE-2025-38162 bsc#1245752).
  - commit 8282c3d
  - vhost-scsi: protect vq->log_used with vq->mutex (CVE-2025-38074
    bsc#1244735).
  - commit 4cc2d93
  - crypto: ecdsa - Harden against integer overflows in
    DIV_ROUND_UP() (CVE-2025-37984 bsc#1243669).
  - commit 743073a
  - virtio: break and reset virtio devices on device_shutdown()
    (CVE-2025-38064 bsc#1245201).
  - commit dec0ac7

++++ kernel-rt:

  - dm-raid: fix variable in journal device check (git-fixes).
  - commit 03404b3
  - dm-verity: fix a memory leak if some arguments are specified
    multiple times (git-fixes).
  - commit bbecd6f
  - dm-mirror: fix a tiny race condition (git-fixes).
  - commit 0d4f8fc
  - dm vdo indexer: don't read request structure after enqueuing
    (git-fixes).
  - commit 4cb65b5
  - dm-table: Set BLK_FEAT_ATOMIC_WRITES for target queue limits
    (git-fixes).
  - commit 2396437
  - dm-flakey: make corrupting read bios work (git-fixes).
  - commit b0152c6
  - dm-flakey: error all IOs when num_features is absent
    (git-fixes).
  - commit fd9c57b
  - dm: lock limits when reading them (git-fixes).
  - commit 153ee47
  - dm: handle failures in dm_table_set_restrictions (git-fixes).
  - commit 78fcb29
  - dm: free table mempools if not used in __bind (git-fixes).
  - commit 5859b3f
  - dm: don't change md if dm_table_set_restrictions() fails
    (git-fixes).
  - commit 4bd9525
  - virtgpu: don't reset on shutdown (git-fixes).
  - commit 901c686
  - kernel/fork: only call untrack_pfn_clear() on VMAs duplicated
    for fork() (git-fix for CVE-2025-22090 bsc#1241537).
  - commit 09cb3ff
  - netfilter: nft_set_pipapo: prevent overflow in lookup table
    allocation (CVE-2025-38162 bsc#1245752).
  - commit 8282c3d
  - vhost-scsi: protect vq->log_used with vq->mutex (CVE-2025-38074
    bsc#1244735).
  - commit 4cc2d93
  - crypto: ecdsa - Harden against integer overflows in
    DIV_ROUND_UP() (CVE-2025-37984 bsc#1243669).
  - commit 743073a
  - virtio: break and reset virtio devices on device_shutdown()
    (CVE-2025-38064 bsc#1245201).
  - commit dec0ac7

++++ samba:

  - Update to 4.22.3
    * samba-tool cannot add user to group whose name is exactly 16
    characters long; (bso#15854);
    * Windows security hardening locks out schannel'ed netlogon dc
    calls like netr_DsRGetDCName; (bsc#1246431); (bso#15876);
    * Startup messages of rpc deamons fills /var/log/messages;
    (bso#15869);

++++ libvirt:

  - qemu: ARM: Change default SCSI controller model from 'lsilogic'
    to 'virtio-scsi'
    bsc#1240762

++++ ovmf:

  - Backport the patch from edk2-stable202505 (jsc#PED-13202)
  - ovmf-UefiCpuPkg-MpInitLib-Fix-SNP-AP-creation.patch
    dca5d26bc57e UefiCpuPkg/MpInitLib: Fix SNP AP creation when using known APIC IDs

++++ read-only-root-fs:

  - Update to version 1.0+git20250708.3eed5de:
    * writable-etc: Install findmnt instead of mountpoint
    * CI: Omit volatile-overlay from the initrd
    * Add basic CI
    * Only remount when [/sysroot]/etc is ro (bsc#1246021)

++++ systemd-rpm-macros:

  - Bump version to 26

------------------------------------------------------------------
------------------  2025-7-7  -  Jul 7 2025  -------------------
------------------------------------------------------------------

++++ container-selinux:

  - Update to version 2.239.0:
    * Allow containers to use hsa devices for ROCM

++++ python-kiwi:

  - Add rd.kiwi.install.devicepersistency
    Allow to specify which type of persistent device name should
    be used to build up the list of installation disk devices.
    For example rd.kiwi.install.devicepersistency=by-path would
    use the by-path representations for the available disk
    devices. The default (by-id) stays untouched. In case an
    invalid or not present device representation is selected, kiwi
    falls back to the non persistent unix node names.

++++ hwinfo:

  - merge gh#openSUSE/hwinfo#167
  - fix usb network card detection (bsc#1245950)
  - 24.1

++++ kernel-default:

  - rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu (bsc#1234810 CVE-2024-53160)
  - commit cc08ae0
  - net: dsa: clean up FDB, MDB, VLAN entries on unbind
    (CVE-2025-37864 bsc#1242965).
  - commit 9f73d53
  - NFSv4: Always set NLINK even if the server doesn't support it
    (git-fixes).
  - commit ab761d1
  - NFSv4.2: fix listxattr to return selinux security label
    (git-fixes).
  - commit b10a707
  - NFSv4.2: fix setattr caching of TIME_[MODIFY|ACCESS]_SET when
    timestamps are delegated (git-fixes).
  - commit 3f2e95e
  - NFSv4: xattr handlers should check for absent nfs filehandles
    (git-fixes).
  - commit 4564984
  - sunrpc: don't immediately retransmit on seqno miss (git-fixes).
  - commit eaac877
  - usb: typec: displayport: Fix potential deadlock (git-fixes).
  - commit bf24223
  - iio: dac: ad3552r: changes to use FIELD_PREP (stable-fixes).
  - Refresh
    patches.suse/iio-dac-ad3552r-clear-reset-status-flag.patch.
  - commit 9805aa5
  - accel/ivpu: Make command queue ID allocated on XArray
    (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Fix-locking-order-in-ivpu_job_submit.patch.
  - commit f24456f
  - accel/ivpu: Do not fail on cmdq if failed to allocate preemption
    buffers (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Use-xa_alloc_cyclic-instead-of-custom-fun.patch.
  - commit d5a180a
  - drm/bridge: ti-sn65dsi86: Add HPD for DisplayPort connector type
    (git-fixes).
  - ASoC: amd: yc: Add DMI quirk for Lenovo IdeaPad Slim 5 15
    (stable-fixes).
  - wifi: mac80211: finish link init before RCU publish (git-fixes).
  - Bluetooth: L2CAP: Fix L2CAP MTU negotiation (stable-fixes).
  - spi: spi-cadence-quadspi: Fix pm runtime unbalance (git-fixes).
  - drm/xe: Fix early wedge on GuC load failure (git-fixes).
  - drm/amdkfd: Fix race in GWS queue scheduling (stable-fixes).
  - drm/amdgpu: Fix SDMA UTC_L1 handling during start/stop sequences
    (stable-fixes).
  - drm/amd/display: Check dce_hwseq before dereferencing it
    (stable-fixes).
  - drm/amdgpu: Add kicker device detection (stable-fixes).
  - drm/amd/display: Fix RMCM programming seq errors (stable-fixes).
  - drm/amd/display: Fix mpv playback corruption on weston
    (stable-fixes).
  - drm/i915/dsi: Fix off by one in BXT_MIPI_TRANS_VTOTAL
    (stable-fixes).
  - ASoC: rt1320: fix speaker noise when volume bar is 100%
    (stable-fixes).
  - ASoC: codecs: wcd9335: Fix missing free of regulator supplies
    (git-fixes).
  - ALSA: hda: Ignore unsol events for cards being shut down
    (stable-fixes).
  - usb: dwc2: also exit clock_gating when stopping udc while
    suspended (stable-fixes).
  - usb: potential integer overflow in usbg_make_tpg()
    (stable-fixes).
  - usb: common: usb-conn-gpio: use a unique name for usb connector
    device (stable-fixes).
  - usb: Add checks for snprintf() calls in usb_alloc_dev()
    (stable-fixes).
  - usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (stable-fixes).
  - usb: gadget: f_hid: wake up readers on disable/unbind
    (stable-fixes).
  - usb: typec: displayport: Receive DP Status Update NAK request
    exit dp altmode (stable-fixes).
  - usb: typec: mux: do not return on EOPNOTSUPP in {mux,
    switch}_set (stable-fixes).
  - 8250: microchip: pci1xxxx: Add PCIe Hot reset disable support
    for Rev C0 and later devices (stable-fixes).
  - iio: pressure: zpa2326: Use aligned_s64 for the timestamp
    (stable-fixes).
  - iio: adc: ad_sigma_delta: Fix use of uninitialized status_pos
    (stable-fixes).
  - misc: tps6594-pfsm: Add NULL pointer check in
    tps6594_pfsm_probe() (stable-fixes).
  - drm/scheduler: signal scheduled fence when kill job
    (stable-fixes).
  - drm/amd/display: Correct non-OLED pre_T11_delay (stable-fixes).
  - amd/amdkfd: fix a kfd_process ref leak (stable-fixes).
  - drm/amdgpu: amdgpu_vram_mgr_new(): Clamp lpfn to total vram
    (stable-fixes).
  - drm/amdgpu: seq64 memory unmap uses uninterruptible lock
    (stable-fixes).
  - Revert "drm/i915/gem: Allow EXEC_CAPTURE on recoverable contexts
    on DG1" (stable-fixes).
  - dmaengine: idxd: Check availability of workqueue allocated by
    idxd wq driver before using (stable-fixes).
  - dmaengine: xilinx_dma: Set dma_device directions (stable-fixes).
  - PCI: imx6: Add workaround for errata ERR051624 (stable-fixes).
  - PCI: dwc: Make link training more robust by setting
    PORT_LOGIC_LINK_WIDTH to one lane (stable-fixes).
  - PCI: apple: Fix missing OF node reference in
    apple_pcie_setup_port (stable-fixes).
  - leds: multicolor: Fix intensity setting while SW blinking
    (stable-fixes).
  - mfd: max14577: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - hwmon: (pmbus/max34440) Fix support for max34451 (stable-fixes).
  - wifi: mac80211: Create separate links for VLAN interfaces
    (stable-fixes).
  - wifi: mac80211: Add link iteration macro for link data
    (stable-fixes).
  - drm/bridge: ti-sn65dsi86: make use of debugfs_init callback
    (stable-fixes).
  - drm/xe: Fix taking invalid lock on wedge (stable-fixes).
  - ASoC: codec: wcd9335: Convert to GPIO descriptors
    (stable-fixes).
  - accel/ivpu: Separate DB ID and CMDQ ID allocations from CMDQ
    allocation (stable-fixes).
  - drm/amdkfd: Fix instruction hazard in gfx12 trap handler
    (stable-fixes).
  - types: Complement the aligned types with signed 64-bit one
    (stable-fixes).
  - drm/amdkfd: remove gfx 12 trap handler page size cap
    (stable-fixes).
  - accel/ivpu: Remove copy engine support (stable-fixes).
  - net: phy: realtek: add RTL8125D-internal PHY (stable-fixes).
  - net: phy: realtek: merge the drivers for internal NBase-T PHY's
    (stable-fixes).
  - commit 3355077

++++ kernel-firmware-bluetooth:

  - Update to version 20250707 (git commit ba5e4e381494):
    * Revert "linux-firmware: Update firmware file for Intel Pulsar core"

++++ kernel-firmware-i915:

  - Update to version 20250707 (git commit ba5e4e381494):
    * xe: First HuC release for Pantherlake
    * xe: First GuC release for Pantherlake

++++ kernel-firmware-mediatek:

  - Update to version 20250707 (git commit ba5e4e381494):
    * linux-firmware: update firmware for MT7921 WiFi device

++++ kernel-firmware-qcom:

  - Update to version 20250707 (git commit ba5e4e381494):
    * qcom/adreno: sort entries in WHENCE

++++ kernel-rt:

  - rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu (bsc#1234810 CVE-2024-53160)
  - commit cc08ae0
  - net: dsa: clean up FDB, MDB, VLAN entries on unbind
    (CVE-2025-37864 bsc#1242965).
  - commit 9f73d53
  - NFSv4: Always set NLINK even if the server doesn't support it
    (git-fixes).
  - commit ab761d1
  - NFSv4.2: fix listxattr to return selinux security label
    (git-fixes).
  - commit b10a707
  - NFSv4.2: fix setattr caching of TIME_[MODIFY|ACCESS]_SET when
    timestamps are delegated (git-fixes).
  - commit 3f2e95e
  - NFSv4: xattr handlers should check for absent nfs filehandles
    (git-fixes).
  - commit 4564984
  - sunrpc: don't immediately retransmit on seqno miss (git-fixes).
  - commit eaac877
  - usb: typec: displayport: Fix potential deadlock (git-fixes).
  - commit bf24223
  - iio: dac: ad3552r: changes to use FIELD_PREP (stable-fixes).
  - Refresh
    patches.suse/iio-dac-ad3552r-clear-reset-status-flag.patch.
  - commit 9805aa5
  - accel/ivpu: Make command queue ID allocated on XArray
    (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Fix-locking-order-in-ivpu_job_submit.patch.
  - commit f24456f
  - accel/ivpu: Do not fail on cmdq if failed to allocate preemption
    buffers (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Use-xa_alloc_cyclic-instead-of-custom-fun.patch.
  - commit d5a180a
  - drm/bridge: ti-sn65dsi86: Add HPD for DisplayPort connector type
    (git-fixes).
  - ASoC: amd: yc: Add DMI quirk for Lenovo IdeaPad Slim 5 15
    (stable-fixes).
  - wifi: mac80211: finish link init before RCU publish (git-fixes).
  - Bluetooth: L2CAP: Fix L2CAP MTU negotiation (stable-fixes).
  - spi: spi-cadence-quadspi: Fix pm runtime unbalance (git-fixes).
  - drm/xe: Fix early wedge on GuC load failure (git-fixes).
  - drm/amdkfd: Fix race in GWS queue scheduling (stable-fixes).
  - drm/amdgpu: Fix SDMA UTC_L1 handling during start/stop sequences
    (stable-fixes).
  - drm/amd/display: Check dce_hwseq before dereferencing it
    (stable-fixes).
  - drm/amdgpu: Add kicker device detection (stable-fixes).
  - drm/amd/display: Fix RMCM programming seq errors (stable-fixes).
  - drm/amd/display: Fix mpv playback corruption on weston
    (stable-fixes).
  - drm/i915/dsi: Fix off by one in BXT_MIPI_TRANS_VTOTAL
    (stable-fixes).
  - ASoC: rt1320: fix speaker noise when volume bar is 100%
    (stable-fixes).
  - ASoC: codecs: wcd9335: Fix missing free of regulator supplies
    (git-fixes).
  - ALSA: hda: Ignore unsol events for cards being shut down
    (stable-fixes).
  - usb: dwc2: also exit clock_gating when stopping udc while
    suspended (stable-fixes).
  - usb: potential integer overflow in usbg_make_tpg()
    (stable-fixes).
  - usb: common: usb-conn-gpio: use a unique name for usb connector
    device (stable-fixes).
  - usb: Add checks for snprintf() calls in usb_alloc_dev()
    (stable-fixes).
  - usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (stable-fixes).
  - usb: gadget: f_hid: wake up readers on disable/unbind
    (stable-fixes).
  - usb: typec: displayport: Receive DP Status Update NAK request
    exit dp altmode (stable-fixes).
  - usb: typec: mux: do not return on EOPNOTSUPP in {mux,
    switch}_set (stable-fixes).
  - 8250: microchip: pci1xxxx: Add PCIe Hot reset disable support
    for Rev C0 and later devices (stable-fixes).
  - iio: pressure: zpa2326: Use aligned_s64 for the timestamp
    (stable-fixes).
  - iio: adc: ad_sigma_delta: Fix use of uninitialized status_pos
    (stable-fixes).
  - misc: tps6594-pfsm: Add NULL pointer check in
    tps6594_pfsm_probe() (stable-fixes).
  - drm/scheduler: signal scheduled fence when kill job
    (stable-fixes).
  - drm/amd/display: Correct non-OLED pre_T11_delay (stable-fixes).
  - amd/amdkfd: fix a kfd_process ref leak (stable-fixes).
  - drm/amdgpu: amdgpu_vram_mgr_new(): Clamp lpfn to total vram
    (stable-fixes).
  - drm/amdgpu: seq64 memory unmap uses uninterruptible lock
    (stable-fixes).
  - Revert "drm/i915/gem: Allow EXEC_CAPTURE on recoverable contexts
    on DG1" (stable-fixes).
  - dmaengine: idxd: Check availability of workqueue allocated by
    idxd wq driver before using (stable-fixes).
  - dmaengine: xilinx_dma: Set dma_device directions (stable-fixes).
  - PCI: imx6: Add workaround for errata ERR051624 (stable-fixes).
  - PCI: dwc: Make link training more robust by setting
    PORT_LOGIC_LINK_WIDTH to one lane (stable-fixes).
  - PCI: apple: Fix missing OF node reference in
    apple_pcie_setup_port (stable-fixes).
  - leds: multicolor: Fix intensity setting while SW blinking
    (stable-fixes).
  - mfd: max14577: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - hwmon: (pmbus/max34440) Fix support for max34451 (stable-fixes).
  - wifi: mac80211: Create separate links for VLAN interfaces
    (stable-fixes).
  - wifi: mac80211: Add link iteration macro for link data
    (stable-fixes).
  - drm/bridge: ti-sn65dsi86: make use of debugfs_init callback
    (stable-fixes).
  - drm/xe: Fix taking invalid lock on wedge (stable-fixes).
  - ASoC: codec: wcd9335: Convert to GPIO descriptors
    (stable-fixes).
  - accel/ivpu: Separate DB ID and CMDQ ID allocations from CMDQ
    allocation (stable-fixes).
  - drm/amdkfd: Fix instruction hazard in gfx12 trap handler
    (stable-fixes).
  - types: Complement the aligned types with signed 64-bit one
    (stable-fixes).
  - drm/amdkfd: remove gfx 12 trap handler page size cap
    (stable-fixes).
  - accel/ivpu: Remove copy engine support (stable-fixes).
  - net: phy: realtek: add RTL8125D-internal PHY (stable-fixes).
  - net: phy: realtek: merge the drivers for internal NBase-T PHY's
    (stable-fixes).
  - commit 3355077

++++ libsolv:

  - add support for product-obsoletes() provides in the product
    autopackage generation code
  - bump version to 0.7.34

++++ libzypp:

  - BuildRequires: %{libsolv_devel_package} >= 0.7.34 (bsc#1243486)
    Newer rpm versions no longer allow a ':' in rpm package names or
    obsoletes. So injecting an
    Obsoletes: product:oldproductname < oldproductversion
    into the -release package to indicate a product rename is no longer
    possible.
    Since libsolv-0.7.34 you can and should use:
    Provides: product-obsoletes(oldproductname) < oldproductversion
    in the -release package. libsolv will then inject the appropriate
    Obsoletes into the Product.
  - version 17.37.10 (35)

++++ nvidia-open-driver-G06-signed:

  - empty pci_ids-570.169; PCI ID hardware Supplements get moved to
    gfx repository to package nvidia-open-driver-G06-signed-kmp-meta
    (boo#1246010)
  - remove 60-nvidia-$flavor.conf, since driver no longer gets
    autoselected without gfx/cuda repositories present and so we no
    longer need to disable it by default (boo#1246010)

++++ systemd-rpm-macros:

  - Introduce %udev_trigger_with_reload() for packages that need to trigger events
    in theirs scriplets. The new macro automatically triggers a reload of the udev
    rule files as this step is often overlooked by packages (bsc#1237143).

------------------------------------------------------------------
------------------  2025-7-6  -  Jul 6 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - i2c/designware: Fix an initialization issue (git-fixes).
  - powercap: intel_rapl: Do not change CLAMPING bit if ENABLE
    bit cannot be changed (git-fixes).
  - firmware: arm_ffa: Fix memory leak by freeing notifier callback
    node (git-fixes).
  - regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
    (git-fixes).
  - spi: spi-fsl-dspi: Clear completion counter before initiating
    transfer (git-fixes).
  - platform/x86: think-lmi: Fix sysfs group cleanup (git-fixes).
  - platform/x86: think-lmi: Fix kobject cleanup (git-fixes).
  - platform/mellanox: mlxreg-lc: Fix logic error in power state
    check (git-fixes).
  - platform/x86: dell-wmi-sysman: Fix WMI data block retrieval
    in sysfs callbacks (git-fixes).
  - platform/mellanox: nvsw-sn2201: Fix bus number in adapter
    error message (git-fixes).
  - platform/mellanox: mlxbf-pmc: Fix duplicate event ID for
    CACHE_DATA1 (git-fixes).
  - platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment
    (git-fixes).
  - xhci: dbc: Flush queued requests before stopping dbc
    (git-fixes).
  - xhci: dbctty: disable ECHO flag by default (git-fixes).
  - xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS
    (git-fixes).
  - usb: dwc3: gadget: Fix TRB reclaim logic for short transfers
    and ZLPs (git-fixes).
  - usb: typec: altmodes/displayport: do not index invalid
    pin_assignments (git-fixes).
  - usb: cdnsp: Fix issue with CV Bad Descriptor test (git-fixes).
  - Revert "usb: xhci: Implement xhci_handshake_check_state()
    helper" (git-fixes).
  - usb: xhci: Skip xhci_reset in xhci_resume if xhci is being
    removed (git-fixes).
  - usb: gadget: u_serial: Fix race condition in TTY wakeup
    (git-fixes).
  - Revert "usb: gadget: u_serial: Add null pointer check in
    gs_start_io" (git-fixes).
  - usb: chipidea: udc: disconnect/reconnect from host when do
    suspend/resume (git-fixes).
  - usb: dwc3: Abort suspend on soft disconnect failure (git-fixes).
  - usb: cdnsp: do not disable slot for disabled slot (git-fixes).
  - Input: cs40l50-vibra - fix potential NULL dereference in
    cs40l50_upload_owt() (git-fixes).
  - Input: iqs7222 - explicitly define number of external channels
    (git-fixes).
  - Input: xpad - adjust error handling for disconnect (git-fixes).
  - drm/exynos: fimd: Guard display clock control with runtime PM
    calls (git-fixes).
  - drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
    (git-fixes).
  - drm/i915/gsc: mei interrupt top half should be in irq disabled
    context (git-fixes).
  - drm/i915/gt: Fix timeline left held on VMA alloc error
    (git-fixes).
  - drm/i915/selftests: Change mock_request() to return error
    pointers (git-fixes).
  - drm/v3d: Disable interrupts before resetting the GPU
    (git-fixes).
  - drm/sched: Increment job count before swapping tail spsc queue
    (git-fixes).
  - drm/bridge: aux-hpd-bridge: fix assignment of the of_node
    (git-fixes).
  - drm/bridge: panel: move prepare_prev_first handling to
    drm_panel_bridge_add_typed (git-fixes).
  - drm/ttm: fix error handling in ttm_buffer_object_transfer
    (git-fixes).
  - drm/amdkfd: Don't call mmput from MMU notifier callback
    (git-fixes).
  - commit 58c4f95

++++ kernel-rt:

  - i2c/designware: Fix an initialization issue (git-fixes).
  - powercap: intel_rapl: Do not change CLAMPING bit if ENABLE
    bit cannot be changed (git-fixes).
  - firmware: arm_ffa: Fix memory leak by freeing notifier callback
    node (git-fixes).
  - regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods
    (git-fixes).
  - spi: spi-fsl-dspi: Clear completion counter before initiating
    transfer (git-fixes).
  - platform/x86: think-lmi: Fix sysfs group cleanup (git-fixes).
  - platform/x86: think-lmi: Fix kobject cleanup (git-fixes).
  - platform/mellanox: mlxreg-lc: Fix logic error in power state
    check (git-fixes).
  - platform/x86: dell-wmi-sysman: Fix WMI data block retrieval
    in sysfs callbacks (git-fixes).
  - platform/mellanox: nvsw-sn2201: Fix bus number in adapter
    error message (git-fixes).
  - platform/mellanox: mlxbf-pmc: Fix duplicate event ID for
    CACHE_DATA1 (git-fixes).
  - platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment
    (git-fixes).
  - xhci: dbc: Flush queued requests before stopping dbc
    (git-fixes).
  - xhci: dbctty: disable ECHO flag by default (git-fixes).
  - xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS
    (git-fixes).
  - usb: dwc3: gadget: Fix TRB reclaim logic for short transfers
    and ZLPs (git-fixes).
  - usb: typec: altmodes/displayport: do not index invalid
    pin_assignments (git-fixes).
  - usb: cdnsp: Fix issue with CV Bad Descriptor test (git-fixes).
  - Revert "usb: xhci: Implement xhci_handshake_check_state()
    helper" (git-fixes).
  - usb: xhci: Skip xhci_reset in xhci_resume if xhci is being
    removed (git-fixes).
  - usb: gadget: u_serial: Fix race condition in TTY wakeup
    (git-fixes).
  - Revert "usb: gadget: u_serial: Add null pointer check in
    gs_start_io" (git-fixes).
  - usb: chipidea: udc: disconnect/reconnect from host when do
    suspend/resume (git-fixes).
  - usb: dwc3: Abort suspend on soft disconnect failure (git-fixes).
  - usb: cdnsp: do not disable slot for disabled slot (git-fixes).
  - Input: cs40l50-vibra - fix potential NULL dereference in
    cs40l50_upload_owt() (git-fixes).
  - Input: iqs7222 - explicitly define number of external channels
    (git-fixes).
  - Input: xpad - adjust error handling for disconnect (git-fixes).
  - drm/exynos: fimd: Guard display clock control with runtime PM
    calls (git-fixes).
  - drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling
    (git-fixes).
  - drm/i915/gsc: mei interrupt top half should be in irq disabled
    context (git-fixes).
  - drm/i915/gt: Fix timeline left held on VMA alloc error
    (git-fixes).
  - drm/i915/selftests: Change mock_request() to return error
    pointers (git-fixes).
  - drm/v3d: Disable interrupts before resetting the GPU
    (git-fixes).
  - drm/sched: Increment job count before swapping tail spsc queue
    (git-fixes).
  - drm/bridge: aux-hpd-bridge: fix assignment of the of_node
    (git-fixes).
  - drm/bridge: panel: move prepare_prev_first handling to
    drm_panel_bridge_add_typed (git-fixes).
  - drm/ttm: fix error handling in ttm_buffer_object_transfer
    (git-fixes).
  - drm/amdkfd: Don't call mmput from MMU notifier callback
    (git-fixes).
  - commit 58c4f95

++++ wayland:

  - Update to release 1.24
    * A new wl_fixes interface to add a request to destroy a
    wl_registry object.
    * A new wl_keyboard.key repeated state, to allow compositors to
    take over the responsibility of repeating keys, which is
    useful for remote desktop.
    * wl_display_dispatch_queue_timeout() and
    wl_display_dispatch_timeout(), to set a timeout when
    dispatching events.
    * wl_shm_buffer_ref() and wl_shm_buffer_unref(), to access
    wl_shm_buffer underlying storage after the protocol object
    has been destroyed (e.g. when a client is shutting down).
    * wl_proxy_get_interface() and wl_resource_get_interface(), to
    fetch the wl_interface of an object.
    * wl_resource_post_error_vargs(), as an alternative to
    wl_resource_post_error() when the compositor already has a
    va_list.

------------------------------------------------------------------
------------------  2025-7-4  -  Jul 4 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - U_0001-svga-add-svga_resource_create_with_modifiers-functio.patch
    U_0002-svga-fix-printing-64-bit-value-for-32-bit-build.patch
    * fixes Wayland session when using SP7 as vmware guest (bsc#1245034)

++++ Mesa-drivers:

  - U_0001-svga-add-svga_resource_create_with_modifiers-functio.patch
    U_0002-svga-fix-printing-64-bit-value-for-32-bit-build.patch
    * fixes Wayland session when using SP7 as vmware guest (bsc#1245034)

++++ python-kiwi:

  - Update test-image-disk
    Add NetworkManager for better remote debugging capabilities

++++ transactional-update:

  - Version 5.0.5
  - Add support for kdump 2.1.0 [bsc#1243758]
  - Integrate test to support `make check`

++++ kernel-default:

  - smb: client: Fix use-after-free in cifs_fill_dirent
    (CVE-2025-38051 bsc#1244750).
  - commit f65fc44
  - cgroup/cpuset: Extend kthread_is_per_cpu() check to all
    PF_NO_SETAFFINITY tasks (bsc#1241166).
  - commit e4048e5
  - rose: fix dangling neighbour pointers in rose_rt_device_down()
    (git-fixes).
  - Bluetooth: HCI: Set extended advertising data synchronously
    (git-fixes).
  - Bluetooth: MGMT: mesh_send: check instances prior disabling
    advertising (git-fixes).
  - Bluetooth: MGMT: set_mesh: update LE scan interval and window
    (git-fixes).
  - Bluetooth: hci_sync: revert some mesh modifications (git-fixes).
  - Bluetooth: Prevent unintended pause by checking if advertising
    is active (git-fixes).
  - net: usb: lan78xx: fix WARN in __netif_napi_del_locked on
    disconnect (git-fixes).
  - commit a505fc6
  - gfs2: Don't clear sb->s_fs_info in gfs2_sys_fs_add (bsc#1243993
    bsc#1245617).
  - writeback: fix false warning in inode_to_wb() (bsc#1243993
    bsc#1245617).
  - gfs2: replace sd_aspace with sd_inode (bsc#1243993 bsc#1245617).
  - commit 9761d03

++++ kernel-rt:

  - smb: client: Fix use-after-free in cifs_fill_dirent
    (CVE-2025-38051 bsc#1244750).
  - commit f65fc44
  - cgroup/cpuset: Extend kthread_is_per_cpu() check to all
    PF_NO_SETAFFINITY tasks (bsc#1241166).
  - commit e4048e5
  - rose: fix dangling neighbour pointers in rose_rt_device_down()
    (git-fixes).
  - Bluetooth: HCI: Set extended advertising data synchronously
    (git-fixes).
  - Bluetooth: MGMT: mesh_send: check instances prior disabling
    advertising (git-fixes).
  - Bluetooth: MGMT: set_mesh: update LE scan interval and window
    (git-fixes).
  - Bluetooth: hci_sync: revert some mesh modifications (git-fixes).
  - Bluetooth: Prevent unintended pause by checking if advertising
    is active (git-fixes).
  - net: usb: lan78xx: fix WARN in __netif_napi_del_locked on
    disconnect (git-fixes).
  - commit a505fc6
  - gfs2: Don't clear sb->s_fs_info in gfs2_sys_fs_add (bsc#1243993
    bsc#1245617).
  - writeback: fix false warning in inode_to_wb() (bsc#1243993
    bsc#1245617).
  - gfs2: replace sd_aspace with sd_inode (bsc#1243993 bsc#1245617).
  - commit 9761d03

++++ systemd:

  - triggers.systemd: skip update of hwdb, journal-catalog if executed during an
    offline update.

++++ libzypp:

  - Ignore DeltaRpm download errors (bsc#1245672)
    DeltaRpms are in fact optional resources. In case of a failure
    the full rpm is downloaded.
  - Improve fix for incorrect filesize handling (bsc#1245220)
  - version 17.37.9 (35)

++++ salt:

  - Add `minion_legacy_req_warnings` option to avoid noisy warnings
  - Require M2Crypto >= 0.44.0 for SUSE Family distros
  - Added:
    * add-minion_legacy_req_warnings-option-to-avoid-noisy.patch

++++ ovmf:

  - Revert the following change due to security concerns and potential underlying issues.
  - Enables UEFI Shell support for guests on X64 and AARCH64 platforms (bsc#1244266)
  - Build Shell.efi independently
  - Add ovmf-ShellPkg-Add-post-script-for-Shell-installation.patch
  - Install Shell.efi to EFI boot partition (/boot/efi/EFI/opensuse/ or /boot/efi/EFI/sles/)
  - Register Shell.efi as a boot entry

++++ zypper:

  - sh: Reset solver options after command (bsc#1245496)
  - Explicitly selecting DownloadAsNeeded also selects the
    classic_rpmtrans backend.
  - version 1.14.92

------------------------------------------------------------------
------------------  2025-7-3  -  Jul 3 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 28.3.1-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2831>

++++ kernel-default:

  - dma-mapping: Fix warning reported for missing prototype
    (git-fixes).
  - dma/mapping.c: dev_dbg support for dma_addressing_limited
    (git-fixes).
  - commit 0c85d2b
  - s390/pci: Fix stale function handles in error handling
    (git-fixes bsc#1245644).
  - commit 6883c36
  - s390/pci: Do not try re-enabling load/store if device is
    disabled (git-fixes bsc#1245643).
  - commit 0f86722
  - NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN (git-fixes).
  - commit d887598
  - nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init()
    fails (git-fixes).
  - commit cebbc14
  - mtk-sd: reset host->mrq on prepare_data() error (git-fixes).
  - commit 9cc3c5f
  - Revert "mmc: sdhci: Disable SD card clock before changing
    parameters" (git-fixes).
  - mtk-sd: Prevent memory corruption from DMA map failure
    (git-fixes).
  - mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data
    (git-fixes).
  - mmc: core: sd: Apply BROKEN_SD_DISCARD quirk earlier
    (git-fixes).
  - commit 34daecf
  - RDMA/mlx5: Fix vport loopback for MPV device (git-fixes)
  - commit 2e17666
  - RDMA/mlx5: Fix CC counters query for MPV (git-fixes)
  - commit 047aefd
  - RDMA/mlx5: Fix HW counters query for non-representor devices (git-fixes)
  - commit 385720a
  - IB/mlx5: Fix potential deadlock in MR deregistration (git-fixes)
  - commit e26004c
  - RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert (git-fixes)
  - commit da1aeda
  - RDMA/mlx5: Fix unsafe xarray access in implicit ODP handling (git-fixes)
  - commit 877a2f1
  - RDMA/mlx5: reduce stack usage in mlx5_ib_ufile_hw_cleanup (git-fixes)
  - commit 95b475f

++++ kernel-firmware-realtek:

  - Update to version 20250630 (git commit e2dad11e8d4b):
    * rtw89: 8922a: update fw to v0.35.80.0
    * rtw89: 8852c: update fw to v0.27.129.1
    * rtw89: 8852c: update fw to v0.27.128.0

++++ kernel-rt:

  - dma-mapping: Fix warning reported for missing prototype
    (git-fixes).
  - dma/mapping.c: dev_dbg support for dma_addressing_limited
    (git-fixes).
  - commit 0c85d2b
  - s390/pci: Fix stale function handles in error handling
    (git-fixes bsc#1245644).
  - commit 6883c36
  - s390/pci: Do not try re-enabling load/store if device is
    disabled (git-fixes bsc#1245643).
  - commit 0f86722
  - NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN (git-fixes).
  - commit d887598
  - nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init()
    fails (git-fixes).
  - commit cebbc14
  - mtk-sd: reset host->mrq on prepare_data() error (git-fixes).
  - commit 9cc3c5f
  - Revert "mmc: sdhci: Disable SD card clock before changing
    parameters" (git-fixes).
  - mtk-sd: Prevent memory corruption from DMA map failure
    (git-fixes).
  - mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data
    (git-fixes).
  - mmc: core: sd: Apply BROKEN_SD_DISCARD quirk earlier
    (git-fixes).
  - commit 34daecf
  - RDMA/mlx5: Fix vport loopback for MPV device (git-fixes)
  - commit 2e17666
  - RDMA/mlx5: Fix CC counters query for MPV (git-fixes)
  - commit 047aefd
  - RDMA/mlx5: Fix HW counters query for non-representor devices (git-fixes)
  - commit 385720a
  - IB/mlx5: Fix potential deadlock in MR deregistration (git-fixes)
  - commit e26004c
  - RDMA/mlx5: Initialize obj_event->obj_sub_list before xa_insert (git-fixes)
  - commit da1aeda
  - RDMA/mlx5: Fix unsafe xarray access in implicit ODP handling (git-fixes)
  - commit 877a2f1
  - RDMA/mlx5: reduce stack usage in mlx5_ib_ufile_hw_cleanup (git-fixes)
  - commit 95b475f

++++ leancrypto:

  - Update to 1.5.0:
    * Enable SHA3 CE 2x implementation for SLH-DSA and ML-DSA (performance increases 2 to 3 fold)
    * Fix lookup of RDRAND support in CPUID
    * Catch Y2038 issue on 32-bit systems that do not have 64 bit time_t support
    * Start Python interface
    * Add ED448 / X448 for use in hybrid PQC constructions, ED448 implementation verified with NIST ACVP
    * Add ML-KEM-X448 and ML-DSA-ED448 support
    * ASN.1: Add ML-DSA-ED448 certificate support
    * RUST: Add ML-DSA-ED448 support
    * Linux kernel: Add ML-KEM-X448 and ML-DSA-ED448 support
    * Ascon AEAD: Bug fix when calculating the tag for plaintext that is not multiples of 128 bits
    * Composite X.509 signatures: update implementation to match draft revision 5
    * Add support for the Linux kernel updated scatterwalk API in 6.15 for leancrypto_kernel_aead_ascon.ko
  - Includes changes from 1.4.0:
    * ML-DSA: add signature generation rejection test cases and enable them during self tests
    * add HQC following reference implementation (https://pqc-hqc.org/implementation.html (versions from 2025-02-19)) but derived from PQClean implementation. NOTE: HQC is not yet considered stable as the implementation currently does not exhibit the IND-CCA2 property. Moreover, the FIPS standardization of HQC is pending. Changes to the HQC algorithm until standardization will need to be expected. I.e. the versioning rules of the library do not apply to the HQC algorithm until being announced in the CHANGES.md file.
    * ARMv8: properly save/restore SIMD registers v8 through v15 for ML-DSA/ML-KEM, X25519 and SHA3-CE (reported by Alexander Sosedkin)
    * Rust: add wrapper allowing a native interaction with the leancrypto library - the API offered by the Rust wrappers is not yet defined to be stable and may change to the next version - i.e. the versioning rules of the library do not apply to the Rust API until being announced in the CHANGES.md file.
    * Add “secure_execution” compile-time option
    * Add HQC AVX2 implementation derived from https://pqc-hqc.org/
  - Remove patch fix-aarch64.patch

++++ ovmf:

  - Removed ovmf-Revert-OvmfPkg-PlatformInitLib-dynamic-mmio-window-s.patch
    because the bsc#1205978 be fixed in qemu. And re-enabling 'dynamic mmio
    window size' feature in ovmf can support big GPU passthrough to guest.
    (bsc#1245542)

------------------------------------------------------------------
------------------  2025-7-2  -  Jul 2 2025  -------------------
------------------------------------------------------------------

++++ chrony:

  - Update to version 4.7:
    * Add opencommands directive to select remote monitoring
    commands
    * Add interval option to driftfile directive
    * Add waitsynced and waitunsynced options to local directive
    * Add sanity checks for integer values in configuration
    * Add support for systemd Type=notify service
    * Add RTC refclock driver
    * Allow PHC refclock to be specified with network interface name
    * Don’t require multiple refclock samples per poll to simplify
    filter configuration
    * Keep refclock reachable when dropping samples with large delay
    * Improve quantile-based filtering to adapt faster to larger
    delay
    * Improve logging of selection failures
    * Detect clock interference from other processes
    * Try to reopen message log (-l option) on cyclelogs command
    * Fix sourcedir reloading to not multiply sources
    * Fix tracking offset after failed clock step
    * Drop support for NTS with Nettle < 3.6 and GnuTLS < 3.6.14
    * Drop support for building without POSIX threads
  - Update clknetsim to snapshot 530d1a5.

++++ kernel-default:

  - btrfs: remove the subpage related warning message (bsc#1241492).
  - commit 0e19b2b
  - x86/sev: Add the Secure TSC feature for SNP guests
    (jsc#PED-12716).
  - commit 3ab97c0
  - x86/sev: Mark the TSC in a secure TSC guest as reliable
    (jsc#PED-12716).
  - commit 643400d
  - Update config files (bsc#1245603).
    Enable rtl8139 driver on ppc64le.
  - commit 61b03fb
  - scsi: s390: zfcp: Ensure synchronous unit_add (git-fixes
    bsc#1245597).
  - commit 3235d4d
  - s390/pkey: Prevent overflow in size calculation for
    memdup_user() (git-fixes bsc#1245596).
  - commit 0eac12f
  - Update config files.
    Enabled the following config on x86_64 and arm64:
    CONFIG_IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY=y
    CONFIG_INTEGRITY_CA_MACHINE_KEYRING_MAX=y
    (bsc#1243677, PED-12554, PED-6528)
  - commit 5d04048

++++ kernel-default-base:

  - Add nvme support (bsc#1245533)

++++ kernel-rt:

  - btrfs: remove the subpage related warning message (bsc#1241492).
  - commit 0e19b2b
  - x86/sev: Add the Secure TSC feature for SNP guests
    (jsc#PED-12716).
  - commit 3ab97c0
  - x86/sev: Mark the TSC in a secure TSC guest as reliable
    (jsc#PED-12716).
  - commit 643400d
  - Update config files (bsc#1245603).
    Enable rtl8139 driver on ppc64le.
  - commit 61b03fb
  - scsi: s390: zfcp: Ensure synchronous unit_add (git-fixes
    bsc#1245597).
  - commit 3235d4d
  - s390/pkey: Prevent overflow in size calculation for
    memdup_user() (git-fixes bsc#1245596).
  - commit 0eac12f
  - Update config files.
    Enabled the following config on x86_64 and arm64:
    CONFIG_IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY=y
    CONFIG_INTEGRITY_CA_MACHINE_KEYRING_MAX=y
    (bsc#1243677, PED-12554, PED-6528)
  - commit 5d04048

++++ gcc15:

  - Tune for power10 for SLES 16.  [jsc#PED-12029]
  - Tune for z15 for SLES 16.  [jsc#PED-253]

++++ python313-core:

  - Add CVE-2025-6069-quad-complex-HTMLParser.patch to avoid worst
    case quadratic complexity when processing certain crafted
    malformed inputs with HTMLParser (CVE-2025-6069, bsc#1244705).
  - Add bsc1243155-sphinx-non-determinism.patch (bsc#1243155) to
    generate ids for audit_events using docname (reproducible
    builds).

++++ libzypp:

  - Do not trigger download data exceeded errors on HTTP non data
    responses (bsc#1245220)
    In some cases a HTTP 401 or 407 did trigger a "filesize exceeded"
    error, because the response payload size was compared against the
    expected filesize. This patch adds some checks if the response
    code is in the success range and only then takes expected
    filesize into account. Otherwise the response content-length is
    used or a fallback of 2Mb if no content-length is known.
  - version 17.37.8 (35)
  - Fix SEGV in MediaDISK handler (bsc#1245452)
  - Explicitly selecting DownloadAsNeeded also selects the
    classic_rpmtrans backend.
    DownloadAsNeeded can not be combined with the rpm singletrans
    installer backend because a rpm transaction requires all package
    headers to be available the the beginning of the transaction. So
    explicitly selecting this mode also turns on the classic_rpmtrans
    backend.
  - Fix evaluation of libproxy results (bsc#1244710)
  - version 17.37.7 (35)

++++ python313:

  - Add CVE-2025-6069-quad-complex-HTMLParser.patch to avoid worst
    case quadratic complexity when processing certain crafted
    malformed inputs with HTMLParser (CVE-2025-6069, bsc#1244705).
  - Add bsc1243155-sphinx-non-determinism.patch (bsc#1243155) to
    generate ids for audit_events using docname (reproducible
    builds).

++++ ovmf:

  - Remove 60-ovmf-x86_64-sev.json descriptor (bsc#1245497)

++++ update-alternatives:

  - Update to version 1.22.21
    The full changelog is very large. Please check it here:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.21
  - Changes from 1.22.20:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.20
  - Changes from 1.22.19:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.19
  - Release 1.22.21 includes the fix upstream for CVE-2025-6297 / bsc#1245573.

------------------------------------------------------------------
------------------  2025-7-1  -  Jul 1 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Make mbr-id deterministic
    Log the value of SDE so it is available to review,
    even if the build system does not tell about it.
    Update the tests to cover the new code-path.
    Co-Authored-By: Marcus Schäfer <marcus.schaefer@gmail.com>
  - Ensure dracut initrd is reproducible
    This helps a bit with issue #2358
    Add reproducible flag for UKI too
    Update tests accordingly
    Co-Authored-By: Marcus Schäfer <marcus.schaefer@gmail.com>

++++ gstreamer:

  - Update to version 1.26.3:
    + Highlighted bugfixes in 1.26.3:
  - Security fix for the H.266 video parser
  - Fix regression for WAV files with acid chunks
  - Fix high memory consumption caused by a text handling
    regression in uridecodebin3 and playbin3
  - Fix panic on late GOP in fragmented MP4 muxer
  - Closed caption conversion, rendering and muxing improvements
  - Decklink video sink preroll frame rendering and clock drift
    handling fixes
  - MPEG-TS demuxing and muxing fixes
  - MP4 muxer fixes for creating very large files with faststart
    support
  - New thread-sharing 1:N inter source and sink elements, and a
    ts-rtpdtmfsrc
  - New speech synthesis element around ElevenLabs API
  - RTP H.265 depayloader fixes and improvements, as well as TWCC
    and GCC congestion control fixes
  - Seeking improvements in DASH client for streams with gaps
  - WebRTC sink and source fixes and enhancements, including to
    LiveKit and WHIP signallers
  - The macOS osxvideosink now posts navigation messages
  - QtQML6GL video sink input event handling improvements
  - Overhaul detection of hardware-accelerated video codecs on
    Android
  - Video4Linux capture source fixes and support for BT.2100 PQ
    and 1:4:5:3 colorimetry
  - Vulkan buffer upload and memory handling regression fixes
  - gst-python: fix various regressions introduced in 1.26.2
  - cerbero: fix text relocation issues on 32-bit Android and fix
    broken VisualStudio VC templates
  - packages: ship pbtypes plugin and update openssl to 3.5.0 LTS
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - aggregator: Do not set event seqnum to INVALID
  - baseparse: test: Fix race on test start
  - pad: Only remove TAG events on STREAM_START if the stream-id
    actually changes
  - utils: Mark times array as static to avoid symbol conflict
    with the POSIX function
  - vecdeque: Use correct index type gst_vec_deque_drop_struct()

++++ gstreamer-plugins-base:

  - Update to version 1.26.3:
    + GstAudioAggregator: fix structure unref in peek_next_sample()
    + audioconvert: Fix setting mix-matrix when input caps changes
    + encodebasebin: Duplicate encoding profile in property setter
    + gl: simplify private
    gst_gl_gst_meta_api_type_tags_contain_only()
    + osxvideosink: Use gst_pad_push_event() and post navigation
    messages
    + playsink: Fix race condition in stream synchronizer pad cleanup
    during state changes
    + python: Fix pulling events from appsink
    + streamsynchronizer: Consider streams having received
    stream-start as waiting
    + urisourcebin: Text tracks are no longer set as sparse stream in
    urisourcebin's multiqueue

++++ kernel-default:

  - kABI workaround for xsk: Fix race condition in AF_XDP generic
    RX path (CVE-2025-37920 bsc#1243479).
  - xsk: Fix race condition in AF_XDP generic RX path
    (CVE-2025-37920 bsc#1243479).
  - commit 53ced4a
  - rpm: Drop support for kabi/arch/ignore-flavor (bsc#1249186)
    It's not used in any active branches and it cannot solve contemporary
    problems.
  - commit f86a16a
  - Update config files (jsc#PED-12554 jsc#PED-6996 bsc#1243677 ltc#213602
    bsc#1243678 ltc#213596)
    CONFIG_IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY=y
    CONFIG_INTEGRITY_CA_MACHINE_KEYRING_MAX=y
  - commit b450a63
  - net: tipc: fix refcount warning in tipc_aead_encrypt
    (CVE-2025-38052 bsc#1244749).
  - net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done
    (CVE-2025-38052 bsc#1244749).
  - commit b3f2db2
  - Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT
    (git-fixes).
  - commit 106066c
  - treewide: Convert new and leftover hrtimer_init() users
    (git-fixes).
  - commit a0cfc87
  - net: vlan: don't propagate flags on open (CVE-2025-23163 bsc#1242837).
  - commit aa9c6ef
  - ata: ahci: Use correct DMI identifier for ASUSPRO-D840SA LPM
    quirk (git-fixes).
  - commit b1c1e22
  - blacklist.conf: 2 fixes to drivers we don't build
  - Delete patches.suse/watchdog-da9052_wdt-respect-TWDMIN.patch.
  - commit 493eda5
  - rtc: pcf2127: add missing semicolon after statement (git-fixes).
  - rtc: pcf2127: fix SPI command byte for PCF2131 (git-fixes).
  - rtc: cmos: use spin_lock_irqsave in cmos_interrupt (git-fixes).
  - commit 1050c51

++++ kernel-rt:

  - kABI workaround for xsk: Fix race condition in AF_XDP generic
    RX path (CVE-2025-37920 bsc#1243479).
  - xsk: Fix race condition in AF_XDP generic RX path
    (CVE-2025-37920 bsc#1243479).
  - commit 53ced4a
  - rpm: Drop support for kabi/arch/ignore-flavor (bsc#1249186)
    It's not used in any active branches and it cannot solve contemporary
    problems.
  - commit f86a16a
  - Update config files (jsc#PED-12554 jsc#PED-6996 bsc#1243677 ltc#213602
    bsc#1243678 ltc#213596)
    CONFIG_IMA_KEYRINGS_PERMIT_SIGNED_BY_BUILTIN_OR_SECONDARY=y
    CONFIG_INTEGRITY_CA_MACHINE_KEYRING_MAX=y
  - commit b450a63
  - net: tipc: fix refcount warning in tipc_aead_encrypt
    (CVE-2025-38052 bsc#1244749).
  - net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done
    (CVE-2025-38052 bsc#1244749).
  - commit b3f2db2
  - Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT
    (git-fixes).
  - commit 106066c
  - treewide: Convert new and leftover hrtimer_init() users
    (git-fixes).
  - commit a0cfc87
  - net: vlan: don't propagate flags on open (CVE-2025-23163 bsc#1242837).
  - commit aa9c6ef
  - ata: ahci: Use correct DMI identifier for ASUSPRO-D840SA LPM
    quirk (git-fixes).
  - commit b1c1e22
  - blacklist.conf: 2 fixes to drivers we don't build
  - Delete patches.suse/watchdog-da9052_wdt-respect-TWDMIN.patch.
  - commit 493eda5
  - rtc: pcf2127: add missing semicolon after statement (git-fixes).
  - rtc: pcf2127: fix SPI command byte for PCF2131 (git-fixes).
  - rtc: cmos: use spin_lock_irqsave in cmos_interrupt (git-fixes).
  - commit 1050c51

++++ python313-core:

  - Use one core to build doc. This will make sphinx doc build
    reproducible.
    bsc#1243155

++++ ceph:

  - Enable build on riscv64

++++ sqlite3:

  - Update to 3.50.2:
    * Fix the concat_ws() SQL function so that it includes empty
    strings in the concatenation.
    * Avoid writing frames with no checksums into the wal file if a
    savepoint is rolled back after dirty pages have already been
    spilled into the wal file.
    * Fix the Bitvec object to avoid stack overflow when the
    database is within 60 pages of its maximum size.
    * Fix a problem with UPDATEs on fts5 tables that contain BLOB
    values.
    * Fix an issue with transitive IS constraints on a RIGHT JOIN.
    * CVE-2025-6965, bsc#1246597:
    Raise an error early if the number of aggregate terms in a
    query exceeds the maximum number of columns, to avoid
    downstream assertion faults.
    * Ensure that sqlite3_setlk_timeout() holds the database mutex.

++++ systemd:

  - Import commit a0dfd5de4cdc3f97ef2ad23396904f3e20769317 (merge of v257.7)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/1e42ecf5a145589954df77da05937ee69619f3e5...a0dfd5de4cdc3f97ef2ad23396904f3e20769317

++++ libvirt:

  - qemu: Use numa-preplace instead of numad for numa placement advice
    bsc#1242979, jsc#PED-12821

++++ python313:

  - Use one core to build doc. This will make sphinx doc build
    reproducible.
    bsc#1243155

++++ salt:

  - Prevent tests failures when pygit2 is not present
  - Several fixes for security issues
    (bsc#1244561, CVE-2024-38822)
    (bsc#1244564, CVE-2024-38823)
    (bsc#1244565, CVE-2024-38824)
    (bsc#1244566, CVE-2024-38825)
    (bsc#1244567, CVE-2025-22240)
    (bsc#1244568, CVE-2025-22236)
    (bsc#1244570, CVE-2025-22241)
    (bsc#1244571, CVE-2025-22237)
    (bsc#1244572, CVE-2025-22238)
    (bsc#1244574, CVE-2025-22239)
    (bsc#1244575, CVE-2025-22242)
    * Request server hardening
    * Prevent traversal in local_cache::save_minions
    * Add test and fix for file_recv cve
    * Fix traversal in gitfs find_file
    * Fix traversal in salt.utils.virt
    * Fix traversal in pub_ret
    * Reasonable failures when pillars timeout
    * Make send_req_async wait longer
    * Remove token to prevent decoding errors
    * Fix checking of non-url style git remotes
    * Allow subdirs in GitFS find_file check
  - Add subsystem filter to udev.exportdb (bsc#1236621)
  - tornado.httputil: raise errors instead of logging in
    multipart/form-data parsing (CVE-2025-47287, bsc#1243268)
  - Fix Ubuntu 24.04 edge-case test failures
  - Fix broken tests for Ubuntu 24.04
  - Fix refresh of osrelease and related grains on Python 3.10+
  - Make "salt" package to obsolete "python3-salt" package on SLE15SP7+
  - Fix issue requiring proper Python flavor for dependencies and recommended package
  - Added:
    * fix-tests-issues-in-salt-shaker-environments-721.patch
    * several-fixes-for-security-issues.patch
    * add-subsystem-filter-to-udev.exportdb-bsc-1236621-71.patch
    * fix-of-cve-2025-47287-bsc-1243268-718.patch
    * fix-ubuntu-24.04-specific-failures-716.patch
    * fix-debian-tests-715.patch
    * fix-refresh-of-osrelease-and-related-grains-on-pytho.patch

++++ supportutils:

  - Changes to version 3.2.11
    + Collect rsyslog frule files (bsc#1244003, pr#257)
    + Remove proxy passwords (bsc#1244011, pr#257)
    + Missing NetworkManager information (bsc#1241284, pr#257)
    + Include agama logs bsc#1244937, pr#256)
    + Additional NFS conf files (pr#253)
    + New fadump sysfs files (pr#252)
    + Fixed change log dates

------------------------------------------------------------------
------------------  2025-6-30  -  Jun 30 2025  -------------------
------------------------------------------------------------------

++++ crypto-policies:

  - Allow openssl to load when using the DEFAULT policy, and also
    other policies, in FIPS mode. [bsc#1243830, bsc#1242233]
    * Add crypto-policies-Allow-openssl-other-policies-in-FIPS-mode.patch

++++ curl:

  - Disable insecure NTLM authentication support [bsc#1245491, jsc#PED-12960]

++++ ignition:

  - ignition-suse-generator: Only use Ignition platform ID when
    the corresponding kernel modules are found
    [bsc#1234315] [boo#1230668] [gh#coreos/ignition#1984]

++++ kernel-default:

  - vhost-scsi: Fix vhost_scsi_send_status() (git-fixes).
  - commit 5eeec6a
  - Refresh
    patches.suse/virtio_net-ensure-netdev_tx_reset_queue-is-called-on.patch.
  - commit b3cad97
  - Update config files.
  - commit 8ef851e
  - net: mana: Record doorbell physical address in PF mode (bsc#1244229).
  - scsi: storvsc: Increase the timeouts to storvsc_timeout (bsc#1245455).
  - commit daecbe1
  - kernel/watchdog: always restore
    watchdog_softlockup(,hardlockup)_user_enabled after proc show
    (bsc#1245522).
    Refresh
    patches.suse/watchdog-fix-watchdog-may-detect-false-positive-of-s.patch
    (bsc#1245523).
  - commit 789b353
  - tools/power turbostat: Fix AMD package-energy reporting
    (git-fixes).
  - commit 053070b
  - vsock: avoid timeout during connect() if the socket is closing
    (git-fixes).
  - commit 7192292
  - vhost-scsi: Return queue full for page alloc failures during
    copy (git-fixes).
  - commit 4420b10
  - vhost-scsi: Add better resource allocation failure handling
    (git-fixes).
  - Refresh
    patches.suse/vhost-scsi-Fix-vhost_scsi_send_bad_target.patch.
  - commit 575b441
  - kABI: update kABI symbols
    kABI exceptions were allowed for a couple of branches. Update kABI
    symbols after the merge. Since kABI symbols are being updated, remove
    current kABI workaround patches before the update.
  - commit 0c9b3ad
  - kernel-obs-qa: Do not depend on srchash when qemu emulation is used
    In this case the dependency is never fulfilled
    Fixes: 485ae1da2b88 ("kernel-obs-qa: Use srchash for dependency as well")
  - commit a840f87
  - virtio_net: xsk: bind/unbind xsk for tx (git-fixes).
  - Update
    patches.suse/virtio-net-free-xsk_buffs-on-error-in-virtnet_xsk_po.patch
    (git-fixes).
  - Refresh
    patches.suse/virtio_net-ensure-netdev_tx_reset_queue-is-called-on.patch.
  - commit 0050a39
  - KVM: VMX: Flush shadow VMCS on emergency reboot (git-fixes).
  - commit dec589f
  - KVM: x86/mmu: Use kvm_x86_call() instead of manual static_call()
    (git-fixes).
  - commit bfaf83d
  - KVM: SVM: Clear current_vmcb during vCPU free for all *possible*
    CPUs (git-fixes).
  - commit e71b652
  - KVM: x86: Explicitly zero-initialize on-stack CPUID unions
    (git-fixes).
  - commit 8f58b75
  - NFSD: Implement FATTR4_CLONE_BLKSIZE attribute (git-fixes).
  - commit 4f434fe
  - overflow: Introduce __DEFINE_FLEX for having no initializer
    (git-fixes).
  - commit 99c412c
  - nfsd: nfsd4_spo_must_allow() must check this is a v4 compound
    request (git-fixes).
  - commit d974da9
  - NFSD: fix race between nfsd registration and exports_proc
    (git-fixes).
  - commit 7c3e6b5
  - netlink: specs: tc: replace underscores with dashes in names
    (git-fixes).
  - netlink: specs: dpll: replace underscores with dashes in names
    (git-fixes).
  - netlink: specs: nfsd: replace underscores with dashes in names
    (git-fixes).
  - bnxt: properly flush XDP redirect lists (git-fixes).
  - e1000e: set fixed clock frequency indication for Nahum 11 and
    Nahum 13 (git-fixes).
  - ice: fix eswitch code memory leak in reset scenario (git-fixes).
  - net: ice: Perform accurate aRFS flow match (git-fixes).
  - net: ethtool: remove duplicate defines for family info
    (git-fixes).
  - bnxt_en: Fix double invocation of
    bnxt_ulp_stop()/bnxt_ulp_start() (git-fixes).
  - net/mlx5e: Fix leak of Geneve TLV option object (git-fixes).
  - net/mlx5: HWS, make sure the uplink is the last destination
    (git-fixes).
  - net/mlx5: HWS, fix missing ip_version handling in definer
    (git-fixes).
  - net/mlx5: Fix return value when searching for existing flow
    group (git-fixes).
  - net/mlx5: Fix ECVF vports unload on shutdown flow (git-fixes).
  - net/mlx5: Ensure fw pages are always allocated on same NUMA
    (git-fixes).
  - e1000: Move cancel_work_sync to avoid deadlock (git-fixes).
  - iavf: fix reset_task for early reset event (git-fixes).
  - i40e: retry VFLR handling if there is ongoing VF reset
    (git-fixes).
  - i40e: return false from i40e_reset_vf if reset is in progress
    (git-fixes).
  - iavf: iavf_suspend(): take RTNL before netdev_lock()
    (git-fixes).
  - gve: add missing NULL check for gve_alloc_pending_packet()
    in TX DQO (git-fixes).
  - idpf: avoid mailbox timeout delays during reset (git-fixes).
  - idpf: fix a race in txq wakeup (git-fixes).
  - ice: fix rebuilding the Tx scheduler tree for large queue counts
    (git-fixes).
  - ice: create new Tx scheduler nodes for new queues only
    (git-fixes).
  - ice: fix Tx scheduler error handling in XDP callback
    (git-fixes).
  - net/mlx4_en: Prevent potential integer overflow calculating Hz
    (git-fixes).
  - gve: Fix RX_BUFFERS_POSTED stat to report per-queue fill_cnt
    (git-fixes).
  - octeontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback
    (git-fixes).
  - octeontx2-pf: QOS: Perform cache sync on send queue teardown
    (git-fixes).
  - net/mlx5: Add error handling in mlx5_query_nic_vport_node_guid()
    (git-fixes).
  - net/mlx5_core: Add error handling
    inmlx5_query_nic_vport_qkey_viol_cntr() (git-fixes).
  - net/mlx5: HWS, Fix matcher action template attach (git-fixes).
  - overflow: Fix direct struct member initialization in
    _DEFINE_FLEX() (git-fixes).
  - idpf: fix idpf_vport_splitq_napi_poll() (git-fixes).
  - idpf: fix null-ptr-deref in idpf_features_check (CVE-2025-38053
    bsc#1244746).
  - ice: Fix LACP bonds without SRIOV environment (git-fixes).
  - ice: fix vf->num_mac count with port representors (git-fixes).
  - commit af82899
  - x86/xen: disable CPU idle and frequency drivers for PVH dom0
    (git-fixes).
  - commit 1d99be7
  - xen: Change xen-acpi-processor dom0 dependency (git-fixes).
  - commit 70cda63
  - xen/pci: Do not register devices with segments >= 0x10000
    (git-fixes).
  - commit 1940a47
  - xen/mcelog: Add __nonstring annotations for unterminated strings
    (git-fixes).
  - commit 6e1a750
  - xen: Add support for XenServer 6.1 platform device (git-fixes).
  - commit 7dd2df0
  - Xen/swiotlb: mark xen_swiotlb_fixup() __init (git-fixes).
  - commit 4ff5446
  - Grab mm lock before grabbing pt lock (git-fixes).
  - commit 26a77ff
  - staging: rtl8723bs: Avoid memset() in aes_cipher() and
    aes_decipher() (git-fixes).
  - serial: imx: Restore original RXTL for console to fix data loss
    (git-fixes).
  - serial: core: restore of_node information in sysfs (git-fixes).
  - commit 3895da7
  - RDMA/hns: initialize db in update_srq_db() (git-fixes)
  - commit 980c53d

++++ kernel-firmware-amdgpu:

  - Update to version 20250627 (git commit f40eafe21683):
    * amdgpu: DMCUB updates for DCN401

++++ kernel-firmware-bnx2:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: extract license texts

++++ kernel-firmware-chelsio:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: extract license texts

++++ kernel-firmware-media:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: extract license texts
    * qcom: update firmware binary for SM8550

++++ kernel-firmware-network:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: extract license texts

++++ kernel-firmware-platform:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: expand the advansys license statement
    * WHENCE: some older AMD drivers are MIT licensed

++++ kernel-firmware-radeon:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: some older AMD drivers are MIT licensed

++++ kernel-firmware-serial:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: extract license texts

++++ kernel-firmware-sound:

  - Update to version 20250627 (git commit f40eafe21683):
    * WHENCE: extract license texts

++++ kernel-rt:

  - vhost-scsi: Fix vhost_scsi_send_status() (git-fixes).
  - commit 5eeec6a
  - Refresh
    patches.suse/virtio_net-ensure-netdev_tx_reset_queue-is-called-on.patch.
  - commit b3cad97
  - Update config files.
  - commit 8ef851e
  - net: mana: Record doorbell physical address in PF mode (bsc#1244229).
  - scsi: storvsc: Increase the timeouts to storvsc_timeout (bsc#1245455).
  - commit daecbe1
  - kernel/watchdog: always restore
    watchdog_softlockup(,hardlockup)_user_enabled after proc show
    (bsc#1245522).
    Refresh
    patches.suse/watchdog-fix-watchdog-may-detect-false-positive-of-s.patch
    (bsc#1245523).
  - commit 789b353
  - tools/power turbostat: Fix AMD package-energy reporting
    (git-fixes).
  - commit 053070b
  - vsock: avoid timeout during connect() if the socket is closing
    (git-fixes).
  - commit 7192292
  - vhost-scsi: Return queue full for page alloc failures during
    copy (git-fixes).
  - commit 4420b10
  - vhost-scsi: Add better resource allocation failure handling
    (git-fixes).
  - Refresh
    patches.suse/vhost-scsi-Fix-vhost_scsi_send_bad_target.patch.
  - commit 575b441
  - kABI: update kABI symbols
    kABI exceptions were allowed for a couple of branches. Update kABI
    symbols after the merge. Since kABI symbols are being updated, remove
    current kABI workaround patches before the update.
  - commit 0c9b3ad
  - kernel-obs-qa: Do not depend on srchash when qemu emulation is used
    In this case the dependency is never fulfilled
    Fixes: 485ae1da2b88 ("kernel-obs-qa: Use srchash for dependency as well")
  - commit a840f87
  - virtio_net: xsk: bind/unbind xsk for tx (git-fixes).
  - Update
    patches.suse/virtio-net-free-xsk_buffs-on-error-in-virtnet_xsk_po.patch
    (git-fixes).
  - Refresh
    patches.suse/virtio_net-ensure-netdev_tx_reset_queue-is-called-on.patch.
  - commit 0050a39
  - KVM: VMX: Flush shadow VMCS on emergency reboot (git-fixes).
  - commit dec589f
  - KVM: x86/mmu: Use kvm_x86_call() instead of manual static_call()
    (git-fixes).
  - commit bfaf83d
  - KVM: SVM: Clear current_vmcb during vCPU free for all *possible*
    CPUs (git-fixes).
  - commit e71b652
  - KVM: x86: Explicitly zero-initialize on-stack CPUID unions
    (git-fixes).
  - commit 8f58b75
  - NFSD: Implement FATTR4_CLONE_BLKSIZE attribute (git-fixes).
  - commit 4f434fe
  - overflow: Introduce __DEFINE_FLEX for having no initializer
    (git-fixes).
  - commit 99c412c
  - nfsd: nfsd4_spo_must_allow() must check this is a v4 compound
    request (git-fixes).
  - commit d974da9
  - NFSD: fix race between nfsd registration and exports_proc
    (git-fixes).
  - commit 7c3e6b5
  - netlink: specs: tc: replace underscores with dashes in names
    (git-fixes).
  - netlink: specs: dpll: replace underscores with dashes in names
    (git-fixes).
  - netlink: specs: nfsd: replace underscores with dashes in names
    (git-fixes).
  - bnxt: properly flush XDP redirect lists (git-fixes).
  - e1000e: set fixed clock frequency indication for Nahum 11 and
    Nahum 13 (git-fixes).
  - ice: fix eswitch code memory leak in reset scenario (git-fixes).
  - net: ice: Perform accurate aRFS flow match (git-fixes).
  - net: ethtool: remove duplicate defines for family info
    (git-fixes).
  - bnxt_en: Fix double invocation of
    bnxt_ulp_stop()/bnxt_ulp_start() (git-fixes).
  - net/mlx5e: Fix leak of Geneve TLV option object (git-fixes).
  - net/mlx5: HWS, make sure the uplink is the last destination
    (git-fixes).
  - net/mlx5: HWS, fix missing ip_version handling in definer
    (git-fixes).
  - net/mlx5: Fix return value when searching for existing flow
    group (git-fixes).
  - net/mlx5: Fix ECVF vports unload on shutdown flow (git-fixes).
  - net/mlx5: Ensure fw pages are always allocated on same NUMA
    (git-fixes).
  - e1000: Move cancel_work_sync to avoid deadlock (git-fixes).
  - iavf: fix reset_task for early reset event (git-fixes).
  - i40e: retry VFLR handling if there is ongoing VF reset
    (git-fixes).
  - i40e: return false from i40e_reset_vf if reset is in progress
    (git-fixes).
  - iavf: iavf_suspend(): take RTNL before netdev_lock()
    (git-fixes).
  - gve: add missing NULL check for gve_alloc_pending_packet()
    in TX DQO (git-fixes).
  - idpf: avoid mailbox timeout delays during reset (git-fixes).
  - idpf: fix a race in txq wakeup (git-fixes).
  - ice: fix rebuilding the Tx scheduler tree for large queue counts
    (git-fixes).
  - ice: create new Tx scheduler nodes for new queues only
    (git-fixes).
  - ice: fix Tx scheduler error handling in XDP callback
    (git-fixes).
  - net/mlx4_en: Prevent potential integer overflow calculating Hz
    (git-fixes).
  - gve: Fix RX_BUFFERS_POSTED stat to report per-queue fill_cnt
    (git-fixes).
  - octeontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback
    (git-fixes).
  - octeontx2-pf: QOS: Perform cache sync on send queue teardown
    (git-fixes).
  - net/mlx5: Add error handling in mlx5_query_nic_vport_node_guid()
    (git-fixes).
  - net/mlx5_core: Add error handling
    inmlx5_query_nic_vport_qkey_viol_cntr() (git-fixes).
  - net/mlx5: HWS, Fix matcher action template attach (git-fixes).
  - overflow: Fix direct struct member initialization in
    _DEFINE_FLEX() (git-fixes).
  - idpf: fix idpf_vport_splitq_napi_poll() (git-fixes).
  - idpf: fix null-ptr-deref in idpf_features_check (CVE-2025-38053
    bsc#1244746).
  - ice: Fix LACP bonds without SRIOV environment (git-fixes).
  - ice: fix vf->num_mac count with port representors (git-fixes).
  - commit af82899
  - x86/xen: disable CPU idle and frequency drivers for PVH dom0
    (git-fixes).
  - commit 1d99be7
  - xen: Change xen-acpi-processor dom0 dependency (git-fixes).
  - commit 70cda63
  - xen/pci: Do not register devices with segments >= 0x10000
    (git-fixes).
  - commit 1940a47
  - xen/mcelog: Add __nonstring annotations for unterminated strings
    (git-fixes).
  - commit 6e1a750
  - xen: Add support for XenServer 6.1 platform device (git-fixes).
  - commit 7dd2df0
  - Xen/swiotlb: mark xen_swiotlb_fixup() __init (git-fixes).
  - commit 4ff5446
  - Grab mm lock before grabbing pt lock (git-fixes).
  - commit 26a77ff
  - staging: rtl8723bs: Avoid memset() in aes_cipher() and
    aes_decipher() (git-fixes).
  - serial: imx: Restore original RXTL for console to fix data loss
    (git-fixes).
  - serial: core: restore of_node information in sysfs (git-fixes).
  - commit 3895da7
  - RDMA/hns: initialize db in update_srq_db() (git-fixes)
  - commit 980c53d

++++ numactl:

  - Update to version 2.0.19.14.g690a72c:
    * numastat command fails on LPAR which is not having node0
    Patch is now upstream:
    https://github.com/numactl/numactl/pull/246
    D    4abeee1aac20a7a2552870e0359b8df013ae9037.patch
    Patches are wrong or not needed anymore:
    https://github.com/numactl/numactl/pull/246
    D    0001-Fixed-segfault-when-no-node-could-be-found-in-sysfs-.patch
    D    numactl-clearcache-pie.patch

++++ sudo:

  - Update to 1.9.17p1
    * Fix a possible local privilege escalation via the --host option
    [bsc#1245274, CVE-2025-32462]
    * Fix a possible local privilege Escalation via chroot option
    [bsc#1245275, CVE-2025-32463]
  - Update to 1.9.17
    * Sudo now uses the NODEV macro consistently. Bug #1074.
    Fixed a bug where the ALL command in a sudoers rule would
    override a previous NOSETENV tag. Command tags are inherited from
    previous Cmnds in a Cmnd_Spec_List. There is a special case for
    the SETENV tag with the ALL command, where SETENV is implied if
    no explicit SETENV or NOSETENV tag is specified. This special
    case did not take into account that a NOSETENV tag that was inherited
    should override this behavior.
    * If sudo is run via ssh without a terminal and a password is required,
    it now suggest using ssh’s -t option.
    * Fixed the display of timeout values in the sudo -V output on systems
    without a C99-compliant snprintf() function.
    * Quieted a number of minor Coverity warnings.
    * Fixed a problem running sudo from a serial console on Linux when the
    command is run in a pseudo-terminal (the default).
    * Fixed a crash in sudo which could occur if there was a fatal error
    after the user was validated but before the command was actually run.
    * Fixed a number of man page style warnings. The “lint” make target in
    the docs directory will now run groff with warnings enabled if it is
    available. Bug #1075.
    * The ignore_dot sudoers setting is now on by default. There is now a
  - -disable-ignore-dot configure option to disable it. The
  - -with-ignore-dot configure option has been deprecated.
    * Fixed a problem with the pwfeedback option where an initial backspace
    would reduce the maximum length allowed for the password.
    GitHub issue #439.
    * Fixed minor grammar and spelling problems in the man pages.
    * Fixed a bug where a user could avoid entering a password for sudo -l
    command if they specified their own user or group name via the -u or
  - g options.
    * Avoid potential password guessing based on timing attacks on the
    strcmp() function on systems without PAM or a crypt() function where
    plaintext passwords are stored in the shadow password file.
    * Fixed a potential information leak where sudo -l command could be used
    to determine whether an executable exists in a directory that they do
    not have search access to.
    * Sudo uses TCSAFLUSH, not TCSADRAIN, when disabling echo once again.
    A long time ago sudo changed from using TCSAFLUSH to TCSADRAIN due
    to some systems having bugs related to TCSAFLUSH. That should no longer
    be a concern. Using TCSAFLUSH ensures that password input that has been
    received by the kernel, but not yet read by sudo, will be discarded and
    not echoed.
    * Added the SUDO_TTY environment variable if the user has a terminal.
    This can be used to find the user’s original tty device when sudo runs
    the command in its own pseudo-terminal. GitHub issue #447.
    * New Cantonese translation for sudo.

++++ toolbox:

  - Update to version 2.4+git20250630.5e08e45:
    * Forbid --user if running as root

------------------------------------------------------------------
------------------  2025-6-29  -  Jun 29 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - wifi: rtw88: usb: Upload the firmware in bigger chunks
    (stable-fixes).
  - commit 1df8f6c
  - wifi: mt76: mt7996: drop fragments with multicast or broadcast
    RA (stable-fixes).
  - wifi: mt76: mt7921: add 160 MHz AP for mt7922 device
    (stable-fixes).
  - wifi: mt76: mt7925: introduce thermal protection (stable-fixes).
  - wifi: mt76: mt76x2: Add support for LiteOn WN4516R,WN4519R
    (stable-fixes).
  - wifi: ath12k: fix macro definition HAL_RX_MSDU_PKT_LENGTH_GET
    (stable-fixes).
  - wifi: ath12k: fix a possible dead lock caused by ab->base_lock
    (stable-fixes).
  - wifi: ath11k: Fix QMI memory reuse logic (stable-fixes).
  - wifi: mac80211: validate SCAN_FLAG_AP in scan request during
    MLO (stable-fixes).
  - wifi: rtw89: leave idle mode when setting WEP encryption for
    AP mode (stable-fixes).
  - wifi: rtw89: 8922a: fix TX fail with wrong VCO setting
    (stable-fixes).
  - wifi: iwlwifi: mvm: fix beacon CCK flag (stable-fixes).
  - wireless: purelifi: plfxlc: fix memory leak in
    plfxlc_usb_wreq_asyn() (stable-fixes).
  - wifi: mac80211: do not offer a mesh path if forwarding is
    disabled (stable-fixes).
  - wifi: iwlwifi: pcie: make sure to lock rxq->read (stable-fixes).
  - wifi: mac80211_hwsim: Prevent tsf from setting if beacon is
    disabled (stable-fixes).
  - wifi: ath12k: using msdu end descriptor to check for rx
    multicast packets (stable-fixes).
  - wifi: ath12k: fix failed to set mhi state error during reboot
    with hardware grouping (stable-fixes).
  - wifi: ath12k: fix link valid field initialization in the
    monitor Rx (stable-fixes).
  - wifi: ath12k: fix incorrect CE addresses (stable-fixes).
  - commit b75f8f8
  - drivers/rapidio/rio_cm.c: prevent possible heap overwrite
    (stable-fixes).
  - PCI: Add ACS quirk for Loongson PCIe (stable-fixes).
  - watchdog: da9052_wdt: respect TWDMIN (stable-fixes).
  - watchdog: fix watchdog may detect false positive of softlockup
    (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_pmx_set_by_name() (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_gpio_get_direction() (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_pmx_gpio_set_direction() (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_gpio_get() (stable-fixes).
  - pinctrl: mcp23s08: Reset all pins to input at probe
    (stable-fixes).
  - software node: Correct a OOB check in
    software_node_get_reference_args() (stable-fixes).
  - wifi: ath12k: Pass correct values of center freq1 and center
    freq2 for 160 MHz (stable-fixes).
  - wifi: mac80211: VLAN traffic in multicast path (stable-fixes).
  - wifi: iwlwifi: Add missing MODULE_FIRMWARE for Qu-c0-jf-b0
    (stable-fixes).
  - usbnet: asix AX88772: leave the carrier control to phylink
    (stable-fixes).
  - PM: runtime: fix denying of auto suspend in
    pm_suspend_timer_fn() (stable-fixes).
  - power: supply: max17040: adjust thermal channel scaling
    (stable-fixes).
  - power: supply: bq27xxx: Retrieve again when busy (stable-fixes).
  - power: supply: collie: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - platform-msi: Add msi_remove_device_irq_domain() in
    platform_device_msi_free_irqs_all() (stable-fixes).
  - wifi: rtw89: phy: add dummy C2H event handler for report of
    TAS power (stable-fixes).
  - commit 132d8d6
  - i2c: tiny-usb: disable zero-length read messages (git-fixes).
  - i2c: robotfuzz-osif: disable zero-length read messages
    (git-fixes).
  - i2c: designware: Invoke runtime suspend on quick slave
    re-registration (stable-fixes).
  - i2c: npcm: Add clock toggle recovery (stable-fixes).
  - hid-asus: check ROG Ally MCU version and warn (stable-fixes).
  - mmc: Add quirk to disable DDR50 tuning (stable-fixes).
  - gpiolib: of: Add polarity quirk for s5m8767 (stable-fixes).
  - Make 'cc-option' work correctly for the -Wno-xyzzy pattern
    (stable-fixes).
  - Input: sparcspkr - avoid unannotated fall-through
    (stable-fixes).
  - commit 1379ece
  - drm/xe/gt: Update handling of xe_force_wake_get return
    (stable-fixes).
  - Refresh
    patches.suse/drm-xe-Fix-GT-for-each-engine-workarounds.patch.
  - commit b01435e
  - drm/xe: Process deferred GGTT node removals on device unwind
    (git-fixes).
  - drm/xe/display: Add check for alloc_ordered_workqueue()
    (git-fixes).
  - drm/i915: fix build error some more (git-fixes).
  - drm/amd: Adjust output for discovery error handling (git-fixes).
  - drm/xe/bmg: Update Wa_16023588340 (git-fixes).
  - drm/v3d: Avoid NULL pointer dereference in
    `v3d_job_update_stats()` (stable-fixes).
  - fbcon: Make sure modelist not set on unregistered console
    (stable-fixes).
  - drm/amdgpu: read back register after written for VCN v4.0.5
    (stable-fixes).
  - drm/xe: Wire up device shutdown handler (stable-fixes).
  - commit 425e83a
  - ALSA: hda/realtek: Fix built-in mic on ASUS VivoBook X507UAR
    (git-fixes).
  - ALSA: usb-audio: Fix out-of-bounds read in
    snd_usb_get_audioformat_uac3() (git-fixes).
  - ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
    (stable-fixes).
  - ALSA: usb-audio: Rename ALSA kcontrol PCM and PCM1 for the
    KTMicro sound card (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Asus GU605C (stable-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Victus 16-s1xxx
    and HP Victus 15-fa1xxx (stable-fixes).
  - ALSA: hda/intel: Add Thinkpad E15 to PM deny list
    (stable-fixes).
  - ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
    (stable-fixes).
  - bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3584 for MT7922
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3630 for MT7925
    (stable-fixes).
  - ACPI: Add missing prototype for non CONFIG_SUSPEND/CONFIG_X86
    case (stable-fixes).
  - ACPI: battery: negate current when discharging (stable-fixes).
  - ACPICA: Avoid sequence overread in call to strncmp()
    (stable-fixes).
  - ACPICA: utilities: Fix overflow check in vsnprintf()
    (stable-fixes).
  - ACPICA: Apply pack(1) to union aml_resource (stable-fixes).
  - ACPICA: fix acpi parse and parseext cache leaks (stable-fixes).
  - ACPICA: fix acpi operand cache leak in dswstate.c
    (stable-fixes).
  - ACPI: bus: Bail out if acpi_kobj registration fails
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for Lenovo Yoga Pro 7 14ASP9
    (stable-fixes).
  - ASoC: intel/sdw_utils: Assign initial value in
    asoc_sdw_rt_amp_spk_rtd_init() (stable-fixes).
  - ASoC: tegra210_ahub: Add check to of_device_get_match_data()
    (stable-fixes).
  - ASoC: tas2770: Power cycle amp on ISENSE/VSENSE change
    (stable-fixes).
  - commit 36941d3

++++ kernel-rt:

  - wifi: rtw88: usb: Upload the firmware in bigger chunks
    (stable-fixes).
  - commit 1df8f6c
  - wifi: mt76: mt7996: drop fragments with multicast or broadcast
    RA (stable-fixes).
  - wifi: mt76: mt7921: add 160 MHz AP for mt7922 device
    (stable-fixes).
  - wifi: mt76: mt7925: introduce thermal protection (stable-fixes).
  - wifi: mt76: mt76x2: Add support for LiteOn WN4516R,WN4519R
    (stable-fixes).
  - wifi: ath12k: fix macro definition HAL_RX_MSDU_PKT_LENGTH_GET
    (stable-fixes).
  - wifi: ath12k: fix a possible dead lock caused by ab->base_lock
    (stable-fixes).
  - wifi: ath11k: Fix QMI memory reuse logic (stable-fixes).
  - wifi: mac80211: validate SCAN_FLAG_AP in scan request during
    MLO (stable-fixes).
  - wifi: rtw89: leave idle mode when setting WEP encryption for
    AP mode (stable-fixes).
  - wifi: rtw89: 8922a: fix TX fail with wrong VCO setting
    (stable-fixes).
  - wifi: iwlwifi: mvm: fix beacon CCK flag (stable-fixes).
  - wireless: purelifi: plfxlc: fix memory leak in
    plfxlc_usb_wreq_asyn() (stable-fixes).
  - wifi: mac80211: do not offer a mesh path if forwarding is
    disabled (stable-fixes).
  - wifi: iwlwifi: pcie: make sure to lock rxq->read (stable-fixes).
  - wifi: mac80211_hwsim: Prevent tsf from setting if beacon is
    disabled (stable-fixes).
  - wifi: ath12k: using msdu end descriptor to check for rx
    multicast packets (stable-fixes).
  - wifi: ath12k: fix failed to set mhi state error during reboot
    with hardware grouping (stable-fixes).
  - wifi: ath12k: fix link valid field initialization in the
    monitor Rx (stable-fixes).
  - wifi: ath12k: fix incorrect CE addresses (stable-fixes).
  - commit b75f8f8
  - drivers/rapidio/rio_cm.c: prevent possible heap overwrite
    (stable-fixes).
  - PCI: Add ACS quirk for Loongson PCIe (stable-fixes).
  - watchdog: da9052_wdt: respect TWDMIN (stable-fixes).
  - watchdog: fix watchdog may detect false positive of softlockup
    (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_pmx_set_by_name() (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_gpio_get_direction() (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_pmx_gpio_set_direction() (stable-fixes).
  - pinctrl: armada-37xx: propagate error from
    armada_37xx_gpio_get() (stable-fixes).
  - pinctrl: mcp23s08: Reset all pins to input at probe
    (stable-fixes).
  - software node: Correct a OOB check in
    software_node_get_reference_args() (stable-fixes).
  - wifi: ath12k: Pass correct values of center freq1 and center
    freq2 for 160 MHz (stable-fixes).
  - wifi: mac80211: VLAN traffic in multicast path (stable-fixes).
  - wifi: iwlwifi: Add missing MODULE_FIRMWARE for Qu-c0-jf-b0
    (stable-fixes).
  - usbnet: asix AX88772: leave the carrier control to phylink
    (stable-fixes).
  - PM: runtime: fix denying of auto suspend in
    pm_suspend_timer_fn() (stable-fixes).
  - power: supply: max17040: adjust thermal channel scaling
    (stable-fixes).
  - power: supply: bq27xxx: Retrieve again when busy (stable-fixes).
  - power: supply: collie: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - platform-msi: Add msi_remove_device_irq_domain() in
    platform_device_msi_free_irqs_all() (stable-fixes).
  - wifi: rtw89: phy: add dummy C2H event handler for report of
    TAS power (stable-fixes).
  - commit 132d8d6
  - i2c: tiny-usb: disable zero-length read messages (git-fixes).
  - i2c: robotfuzz-osif: disable zero-length read messages
    (git-fixes).
  - i2c: designware: Invoke runtime suspend on quick slave
    re-registration (stable-fixes).
  - i2c: npcm: Add clock toggle recovery (stable-fixes).
  - hid-asus: check ROG Ally MCU version and warn (stable-fixes).
  - mmc: Add quirk to disable DDR50 tuning (stable-fixes).
  - gpiolib: of: Add polarity quirk for s5m8767 (stable-fixes).
  - Make 'cc-option' work correctly for the -Wno-xyzzy pattern
    (stable-fixes).
  - Input: sparcspkr - avoid unannotated fall-through
    (stable-fixes).
  - commit 1379ece
  - drm/xe/gt: Update handling of xe_force_wake_get return
    (stable-fixes).
  - Refresh
    patches.suse/drm-xe-Fix-GT-for-each-engine-workarounds.patch.
  - commit b01435e
  - drm/xe: Process deferred GGTT node removals on device unwind
    (git-fixes).
  - drm/xe/display: Add check for alloc_ordered_workqueue()
    (git-fixes).
  - drm/i915: fix build error some more (git-fixes).
  - drm/amd: Adjust output for discovery error handling (git-fixes).
  - drm/xe/bmg: Update Wa_16023588340 (git-fixes).
  - drm/v3d: Avoid NULL pointer dereference in
    `v3d_job_update_stats()` (stable-fixes).
  - fbcon: Make sure modelist not set on unregistered console
    (stable-fixes).
  - drm/amdgpu: read back register after written for VCN v4.0.5
    (stable-fixes).
  - drm/xe: Wire up device shutdown handler (stable-fixes).
  - commit 425e83a
  - ALSA: hda/realtek: Fix built-in mic on ASUS VivoBook X507UAR
    (git-fixes).
  - ALSA: usb-audio: Fix out-of-bounds read in
    snd_usb_get_audioformat_uac3() (git-fixes).
  - ALSA: hda/realtek: enable headset mic on Latitude 5420 Rugged
    (stable-fixes).
  - ALSA: usb-audio: Rename ALSA kcontrol PCM and PCM1 for the
    KTMicro sound card (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Asus GU605C (stable-fixes).
  - ALSA: hda/realtek - Add mute LED support for HP Victus 16-s1xxx
    and HP Victus 15-fa1xxx (stable-fixes).
  - ALSA: hda/intel: Add Thinkpad E15 to PM deny list
    (stable-fixes).
  - ata: pata_via: Force PIO for ATAPI devices on VT6415/VT6330
    (stable-fixes).
  - bus: fsl-mc: increase MC_CMD_COMPLETION_TIMEOUT_MS value
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3584 for MT7922
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3630 for MT7925
    (stable-fixes).
  - ACPI: Add missing prototype for non CONFIG_SUSPEND/CONFIG_X86
    case (stable-fixes).
  - ACPI: battery: negate current when discharging (stable-fixes).
  - ACPICA: Avoid sequence overread in call to strncmp()
    (stable-fixes).
  - ACPICA: utilities: Fix overflow check in vsnprintf()
    (stable-fixes).
  - ACPICA: Apply pack(1) to union aml_resource (stable-fixes).
  - ACPICA: fix acpi parse and parseext cache leaks (stable-fixes).
  - ACPICA: fix acpi operand cache leak in dswstate.c
    (stable-fixes).
  - ACPI: bus: Bail out if acpi_kobj registration fails
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for Lenovo Yoga Pro 7 14ASP9
    (stable-fixes).
  - ASoC: intel/sdw_utils: Assign initial value in
    asoc_sdw_rt_amp_spk_rtd_init() (stable-fixes).
  - ASoC: tegra210_ahub: Add check to of_device_get_match_data()
    (stable-fixes).
  - ASoC: tas2770: Power cycle amp on ISENSE/VSENSE change
    (stable-fixes).
  - commit 36941d3

++++ at-spi2-core:

  - Update to version 2.56.3:
    + DeviceEventController: update mouse coordinates before sending
    button events
    + atspi-device-legacy: Don't crash when XkbGetMap fails
    + Return localized role name for ATSPI_ROLE_EDITBAR

------------------------------------------------------------------
------------------  2025-6-28  -  Jun 28 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Revert "block/bdev: enable large folio support for large logical block"
    (bsc#1245444)
    This reverts commit 03e169f9e789f08bac7bdb238dbd9bd7cfd00142.
  - commit f46bdc5

++++ kernel-rt:

  - Revert "block/bdev: enable large folio support for large logical block"
    (bsc#1245444)
    This reverts commit 03e169f9e789f08bac7bdb238dbd9bd7cfd00142.
  - commit f46bdc5

------------------------------------------------------------------
------------------  2025-6-27  -  Jun 27 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.25 → 10.2.26
  - Add kernel parameter support for dm-verity options
    Implement rd.kiwi.verity_options= parameter to allow runtime customization of veritysetup options
    Closes #2837
  - Fix shim lookup for arm on SUSE
    Add missing search path for shim binary on arm based SUSE
    systems. Also update the tumbleweed/test-image-live-disk
    integration test for arm to build with secure boot enabled
    to actually test a secure boot enabled ISO build.
    This Fixes #2842

++++ kernel-default:

  - Update
    patches.suse/ALSA-pcm-Fix-race-of-buffer-access-at-PCM-OSS-layer.patch
    (stable-fixes CVE-2025-38078 bsc#1244737).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-Fix-UAF-when-reloading-module.patch
    (git-fixes CVE-2025-38056 bsc#1244748).
  - Update
    patches.suse/HID-bpf-abort-dispatch-if-device-destroyed.patch
    (git-fixes CVE-2025-38016 bsc#1244745).
  - Update
    patches.suse/HID-uclogic-Add-NULL-check-in-uclogic_input_configur.patch
    (git-fixes CVE-2025-38007 bsc#1244938).
  - Update
    patches.suse/KVM-arm64-Fix-uninitialized-memcache-pointer-in-user.patch
    (git-fixes CVE-2025-37996 bsc#1243828).
  - Update
    patches.suse/PCI-endpoint-pci-epf-test-Fix-double-free-that-cause.patch
    (stable-fixes CVE-2025-38069 bsc#1245246).
  - Update
    patches.suse/RDMA-core-Fix-KASAN-slab-use-after-free-Read-in-ib_r.patch
    (git-fixes CVE-2025-38022 bsc#1245003).
  - Update
    patches.suse/RDMA-rxe-Fix-slab-use-after-free-Read-in-rxe_queue_c.patch
    (git-fixes CVE-2025-38024 bsc#1245025).
  - Update
    patches.suse/block-fix-race-between-set_blocksize-and-read-paths.patch
    (git-fixes CVE-2025-38073 bsc#1244741).
  - Update
    patches.suse/btrfs-avoid-NULL-pointer-dereference-if-no-valid-csu.patch
    (bsc#1243342 CVE-2025-38059 bsc#1244759).
  - Update
    patches.suse/btrfs-avoid-NULL-pointer-dereference-if-no-valid-ext.patch
    (bsc#1236208 CVE-2025-21658).
  - Update
    patches.suse/btrfs-zoned-fix-extent-range-end-unlock-in-cow_file_.patch
    (bsc#1239514 CVE-2025-21942 bsc#1240704).
  - Update
    patches.suse/can-bcm-add-locking-for-bcm_op-runtime-updates.patch
    (git-fixes CVE-2025-38004 bsc#1244274).
  - Update
    patches.suse/can-bcm-add-missing-rcu-read-protection-for-procfs-c.patch
    (git-fixes CVE-2025-38003 bsc#1244275).
  - Update
    patches.suse/can-m_can-m_can_class_allocate_dev-initialize-spin-l.patch
    (git-fixes CVE-2025-37993 bsc#1243822).
  - Update
    patches.suse/crypto-algif_hash-fix-double-free-in-hash_accept.patch
    (git-fixes CVE-2025-38079 bsc#1245217).
  - Update
    patches.suse/crypto-lzo-Fix-compression-buffer-overrun.patch
    (stable-fixes CVE-2025-38068 bsc#1245210).
  - Update
    patches.suse/dm-cache-prevent-BUG_ON-by-blocking-retries-on-faile.patch
    (git-fixes CVE-2025-38066 bsc#1244909).
  - Update
    patches.suse/dm-fix-unconditional-IO-throttle-caused-by-REQ_PREFL.patch
    (git-fixes CVE-2025-38063 bsc#1245202).
  - Update
    patches.suse/dmaengine-idxd-Refactor-remove-call-with-idxd_cleanu.patch
    (git-fixes CVE-2025-38014 bsc#1244732).
  - Update
    patches.suse/dmaengine-idxd-fix-memory-leak-in-error-handling-pat-46a5cca.patch
    (git-fixes CVE-2025-38015 bsc#1244789).
  - Update
    patches.suse/dmaengine-ti-k3-udma-Add-missing-locking.patch
    (git-fixes CVE-2025-38005 bsc#1244727).
  - Update
    patches.suse/drm-amd-display-Fix-invalid-context-error-in-dml-hel.patch
    (git-fixes CVE-2025-37965 bsc#1244174).
  - Update
    patches.suse/drm-amd-display-Increase-block_sequence-array-size.patch
    (stable-fixes CVE-2025-38080 bsc#1244738).
  - Update
    patches.suse/drm-amdgpu-csa-unmap-use-uninterruptible-lock.patch
    (stable-fixes CVE-2025-38011 bsc#1244729).
  - Update patches.suse/espintcp-fix-skb-leaks.patch (git-fixes
    CVE-2025-38057 bsc#1244862).
  - Update
    patches.suse/ext4-avoid-journaling-sb-update-on-error-if-journal-is-des.patch
    (bsc#1241967 CVE-2025-22113 bsc#1241617).
  - Update
    patches.suse/ext4-goto-right-label-out_mmap_sem-in-ext4_setattr.patch
    (bsc#1242556 CVE-2025-22120 bsc#1241592).
  - Update
    patches.suse/firmware-arm_ffa-Set-dma_mask-for-ffa-devices.patch
    (stable-fixes CVE-2025-38043 bsc#1245081).
  - Update
    patches.suse/fs-erofs-fileio-call-erofs_onlinefolio_split-after-bio_add_folio.patch
    (git-fixes CVE-2025-37999 bsc#1243846).
  - Update
    patches.suse/gpio-virtuser-fix-potential-out-of-bound-write.patch
    (stable-fixes CVE-2025-38082 bsc#1244740).
  - Update
    patches.suse/md-fix-mddev-uaf-while-iterating-all_mddevs-list.patch
    (git-fixes CVE-20255-22126 bsc#1241597 CVE-2025-22126).
  - Update patches.suse/media-cx231xx-set-device_caps-for-417.patch
    (stable-fixes CVE-2025-38044 bsc#1245082).
  - Update
    patches.suse/net-mlx5e-Disable-MACsec-offload-for-uplink-represen.patch
    (git-fixes CVE-2025-38020 bsc#1245001).
  - Update
    patches.suse/net-pktgen-fix-access-outside-of-user-given-buffer-i.patch
    (git-fixes CVE-2025-38061 bsc#1245440).
  - Update
    patches.suse/net-tls-fix-kernel-panic-when-alloc_page-failed.patch
    (git-fixes CVE-2025-38018 bsc#1244999).
  - Update patches.suse/net_sched-prio-fix-a-race-in-prio_tune.patch
    (git-fixes CVE-2025-38083 bsc#1245183).
  - Update
    patches.suse/nfs-handle-failure-of-nfs_get_lock_context-in-unlock-path.patch
    (git-fixes CVE-2025-38023 bsc#1245004).
  - Update
    patches.suse/nvmet-tcp-don-t-restore-null-sk_state_change.patch
    (git-fixes CVE-2025-38035 bsc#1244801).
  - Update
    patches.suse/padata-do-not-leak-refcount-in-reorder_work.patch
    (git-fixes CVE-2025-38031 bsc#1245046).
  - Update
    patches.suse/perf-x86-intel-Fix-segfault-with-PEBS-via-PT-with-sample_f.patch
    (git-fixes CVE-2025-38055 bsc#1244747).
  - Update
    patches.suse/phy-tegra-xusb-Use-a-bitmask-for-UTMI-pad-power-stat.patch
    (git-fixes CVE-2025-38010 bsc#1244996).
  - Update
    patches.suse/platform-x86-dell-wmi-sysman-Avoid-buffer-overflow-i.patch
    (git-fixes CVE-2025-38077 bsc#1244736).
  - Update
    patches.suse/ptp-ocp-Limit-signal-freq-counts-in-summary-output-f.patch
    (git-fixes CVE-2025-38054 bsc#1244752).
  - Update
    patches.suse/regulator-max20086-fix-invalid-memory-access.patch
    (git-fixes CVE-2025-38027 bsc#1245042).
  - Update
    patches.suse/sched-numa-fix-memory-leak-due-to-the-overwritten-vma-numab_state.patch
    (git fixes (sched/numa) CVE-2024-56613 bsc#1244176).
  - Update
    patches.suse/serial-mctrl_gpio-split-disable_ms-into-sync-and-no_.patch
    (git-fixes CVE-2025-38040 bsc#1245078).
  - Update
    patches.suse/spi-rockchip-Fix-register-out-of-bounds-access.patch
    (stable-fixes CVE-2025-38081 bsc#1244739).
  - Update
    patches.suse/staging-bcm2835-camera-Initialise-dev-in-v4l2_dev.patch
    (git-fixes CVE-2025-37971 bsc#1244173).
  - Update
    patches.suse/tracing-Have-process_string-also-allow-arrays.patch
    (git-fixes CVE-2024-57930 bsc#1236194).
  - Update
    patches.suse/usb-typec-ucsi-displayport-Fix-NULL-pointer-access.patch
    (git-fixes CVE-2025-37994 bsc#1243823).
  - Update
    patches.suse/wifi-cfg80211-fix-out-of-bounds-access-during-multi-.patch
    (git-fixes CVE-2025-37973 bsc#1244172).
  - Update patches.suse/wifi-iwlwifi-fix-debug-actions-order.patch
    (stable-fixes CVE-2025-38045 bsc#1245083).
  - Update
    patches.suse/wifi-mac80211-Set-n_channels-after-allocating-struct.patch
    (git-fixes CVE-2025-38013 bsc#1244731).
  - Update
    patches.suse/wifi-mt76-disable-napi-on-driver-removal.patch
    (git-fixes CVE-2025-38009 bsc#1244995).
  - Update
    patches.suse/x86-microcode-AMD-Fix-__apply_microcode_amd-s-return-value.patch
    (git-fixes CVE-2025-22047 bsc#1241437).
  - commit db15093
  - cpufreq/ondemand: Set io_is_busy to 1 by default on all
    platforms (bsc#1233975).
  - commit e5c69ac
  - Delete
    patches.suse/cpufreq-amd-pstate-Default-to-powersave-governor-whe.patch (jsc#PED-13111).
  - commit e2263cb
  - HID: wacom: fix crash in wacom_aes_battery_handler()
    (git-fixes).
  - HID: lenovo: Restrict F7/9/11 mode to compact keyboards only
    (git-fixes).
  - HID: wacom: fix kobject reference count leak (git-fixes).
  - HID: wacom: fix memory leak on sysfs attribute creation failure
    (git-fixes).
  - HID: wacom: fix memory leak on kobject creation failure
    (git-fixes).
  - wifi: mac80211: fix beacon interval calculation overflow
    (git-fixes).
  - commit ea1fa22

++++ kernel-rt:

  - Update
    patches.suse/ALSA-pcm-Fix-race-of-buffer-access-at-PCM-OSS-layer.patch
    (stable-fixes CVE-2025-38078 bsc#1244737).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-Fix-UAF-when-reloading-module.patch
    (git-fixes CVE-2025-38056 bsc#1244748).
  - Update
    patches.suse/HID-bpf-abort-dispatch-if-device-destroyed.patch
    (git-fixes CVE-2025-38016 bsc#1244745).
  - Update
    patches.suse/HID-uclogic-Add-NULL-check-in-uclogic_input_configur.patch
    (git-fixes CVE-2025-38007 bsc#1244938).
  - Update
    patches.suse/KVM-arm64-Fix-uninitialized-memcache-pointer-in-user.patch
    (git-fixes CVE-2025-37996 bsc#1243828).
  - Update
    patches.suse/PCI-endpoint-pci-epf-test-Fix-double-free-that-cause.patch
    (stable-fixes CVE-2025-38069 bsc#1245246).
  - Update
    patches.suse/RDMA-core-Fix-KASAN-slab-use-after-free-Read-in-ib_r.patch
    (git-fixes CVE-2025-38022 bsc#1245003).
  - Update
    patches.suse/RDMA-rxe-Fix-slab-use-after-free-Read-in-rxe_queue_c.patch
    (git-fixes CVE-2025-38024 bsc#1245025).
  - Update
    patches.suse/block-fix-race-between-set_blocksize-and-read-paths.patch
    (git-fixes CVE-2025-38073 bsc#1244741).
  - Update
    patches.suse/btrfs-avoid-NULL-pointer-dereference-if-no-valid-csu.patch
    (bsc#1243342 CVE-2025-38059 bsc#1244759).
  - Update
    patches.suse/btrfs-avoid-NULL-pointer-dereference-if-no-valid-ext.patch
    (bsc#1236208 CVE-2025-21658).
  - Update
    patches.suse/btrfs-zoned-fix-extent-range-end-unlock-in-cow_file_.patch
    (bsc#1239514 CVE-2025-21942 bsc#1240704).
  - Update
    patches.suse/can-bcm-add-locking-for-bcm_op-runtime-updates.patch
    (git-fixes CVE-2025-38004 bsc#1244274).
  - Update
    patches.suse/can-bcm-add-missing-rcu-read-protection-for-procfs-c.patch
    (git-fixes CVE-2025-38003 bsc#1244275).
  - Update
    patches.suse/can-m_can-m_can_class_allocate_dev-initialize-spin-l.patch
    (git-fixes CVE-2025-37993 bsc#1243822).
  - Update
    patches.suse/crypto-algif_hash-fix-double-free-in-hash_accept.patch
    (git-fixes CVE-2025-38079 bsc#1245217).
  - Update
    patches.suse/crypto-lzo-Fix-compression-buffer-overrun.patch
    (stable-fixes CVE-2025-38068 bsc#1245210).
  - Update
    patches.suse/dm-cache-prevent-BUG_ON-by-blocking-retries-on-faile.patch
    (git-fixes CVE-2025-38066 bsc#1244909).
  - Update
    patches.suse/dm-fix-unconditional-IO-throttle-caused-by-REQ_PREFL.patch
    (git-fixes CVE-2025-38063 bsc#1245202).
  - Update
    patches.suse/dmaengine-idxd-Refactor-remove-call-with-idxd_cleanu.patch
    (git-fixes CVE-2025-38014 bsc#1244732).
  - Update
    patches.suse/dmaengine-idxd-fix-memory-leak-in-error-handling-pat-46a5cca.patch
    (git-fixes CVE-2025-38015 bsc#1244789).
  - Update
    patches.suse/dmaengine-ti-k3-udma-Add-missing-locking.patch
    (git-fixes CVE-2025-38005 bsc#1244727).
  - Update
    patches.suse/drm-amd-display-Fix-invalid-context-error-in-dml-hel.patch
    (git-fixes CVE-2025-37965 bsc#1244174).
  - Update
    patches.suse/drm-amd-display-Increase-block_sequence-array-size.patch
    (stable-fixes CVE-2025-38080 bsc#1244738).
  - Update
    patches.suse/drm-amdgpu-csa-unmap-use-uninterruptible-lock.patch
    (stable-fixes CVE-2025-38011 bsc#1244729).
  - Update patches.suse/espintcp-fix-skb-leaks.patch (git-fixes
    CVE-2025-38057 bsc#1244862).
  - Update
    patches.suse/ext4-avoid-journaling-sb-update-on-error-if-journal-is-des.patch
    (bsc#1241967 CVE-2025-22113 bsc#1241617).
  - Update
    patches.suse/ext4-goto-right-label-out_mmap_sem-in-ext4_setattr.patch
    (bsc#1242556 CVE-2025-22120 bsc#1241592).
  - Update
    patches.suse/firmware-arm_ffa-Set-dma_mask-for-ffa-devices.patch
    (stable-fixes CVE-2025-38043 bsc#1245081).
  - Update
    patches.suse/fs-erofs-fileio-call-erofs_onlinefolio_split-after-bio_add_folio.patch
    (git-fixes CVE-2025-37999 bsc#1243846).
  - Update
    patches.suse/gpio-virtuser-fix-potential-out-of-bound-write.patch
    (stable-fixes CVE-2025-38082 bsc#1244740).
  - Update
    patches.suse/md-fix-mddev-uaf-while-iterating-all_mddevs-list.patch
    (git-fixes CVE-20255-22126 bsc#1241597 CVE-2025-22126).
  - Update patches.suse/media-cx231xx-set-device_caps-for-417.patch
    (stable-fixes CVE-2025-38044 bsc#1245082).
  - Update
    patches.suse/net-mlx5e-Disable-MACsec-offload-for-uplink-represen.patch
    (git-fixes CVE-2025-38020 bsc#1245001).
  - Update
    patches.suse/net-pktgen-fix-access-outside-of-user-given-buffer-i.patch
    (git-fixes CVE-2025-38061 bsc#1245440).
  - Update
    patches.suse/net-tls-fix-kernel-panic-when-alloc_page-failed.patch
    (git-fixes CVE-2025-38018 bsc#1244999).
  - Update patches.suse/net_sched-prio-fix-a-race-in-prio_tune.patch
    (git-fixes CVE-2025-38083 bsc#1245183).
  - Update
    patches.suse/nfs-handle-failure-of-nfs_get_lock_context-in-unlock-path.patch
    (git-fixes CVE-2025-38023 bsc#1245004).
  - Update
    patches.suse/nvmet-tcp-don-t-restore-null-sk_state_change.patch
    (git-fixes CVE-2025-38035 bsc#1244801).
  - Update
    patches.suse/padata-do-not-leak-refcount-in-reorder_work.patch
    (git-fixes CVE-2025-38031 bsc#1245046).
  - Update
    patches.suse/perf-x86-intel-Fix-segfault-with-PEBS-via-PT-with-sample_f.patch
    (git-fixes CVE-2025-38055 bsc#1244747).
  - Update
    patches.suse/phy-tegra-xusb-Use-a-bitmask-for-UTMI-pad-power-stat.patch
    (git-fixes CVE-2025-38010 bsc#1244996).
  - Update
    patches.suse/platform-x86-dell-wmi-sysman-Avoid-buffer-overflow-i.patch
    (git-fixes CVE-2025-38077 bsc#1244736).
  - Update
    patches.suse/ptp-ocp-Limit-signal-freq-counts-in-summary-output-f.patch
    (git-fixes CVE-2025-38054 bsc#1244752).
  - Update
    patches.suse/regulator-max20086-fix-invalid-memory-access.patch
    (git-fixes CVE-2025-38027 bsc#1245042).
  - Update
    patches.suse/sched-numa-fix-memory-leak-due-to-the-overwritten-vma-numab_state.patch
    (git fixes (sched/numa) CVE-2024-56613 bsc#1244176).
  - Update
    patches.suse/serial-mctrl_gpio-split-disable_ms-into-sync-and-no_.patch
    (git-fixes CVE-2025-38040 bsc#1245078).
  - Update
    patches.suse/spi-rockchip-Fix-register-out-of-bounds-access.patch
    (stable-fixes CVE-2025-38081 bsc#1244739).
  - Update
    patches.suse/staging-bcm2835-camera-Initialise-dev-in-v4l2_dev.patch
    (git-fixes CVE-2025-37971 bsc#1244173).
  - Update
    patches.suse/tracing-Have-process_string-also-allow-arrays.patch
    (git-fixes CVE-2024-57930 bsc#1236194).
  - Update
    patches.suse/usb-typec-ucsi-displayport-Fix-NULL-pointer-access.patch
    (git-fixes CVE-2025-37994 bsc#1243823).
  - Update
    patches.suse/wifi-cfg80211-fix-out-of-bounds-access-during-multi-.patch
    (git-fixes CVE-2025-37973 bsc#1244172).
  - Update patches.suse/wifi-iwlwifi-fix-debug-actions-order.patch
    (stable-fixes CVE-2025-38045 bsc#1245083).
  - Update
    patches.suse/wifi-mac80211-Set-n_channels-after-allocating-struct.patch
    (git-fixes CVE-2025-38013 bsc#1244731).
  - Update
    patches.suse/wifi-mt76-disable-napi-on-driver-removal.patch
    (git-fixes CVE-2025-38009 bsc#1244995).
  - Update
    patches.suse/x86-microcode-AMD-Fix-__apply_microcode_amd-s-return-value.patch
    (git-fixes CVE-2025-22047 bsc#1241437).
  - commit db15093
  - cpufreq/ondemand: Set io_is_busy to 1 by default on all
    platforms (bsc#1233975).
  - commit e5c69ac
  - Delete
    patches.suse/cpufreq-amd-pstate-Default-to-powersave-governor-whe.patch (jsc#PED-13111).
  - commit e2263cb
  - HID: wacom: fix crash in wacom_aes_battery_handler()
    (git-fixes).
  - HID: lenovo: Restrict F7/9/11 mode to compact keyboards only
    (git-fixes).
  - HID: wacom: fix kobject reference count leak (git-fixes).
  - HID: wacom: fix memory leak on sysfs attribute creation failure
    (git-fixes).
  - HID: wacom: fix memory leak on kobject creation failure
    (git-fixes).
  - wifi: mac80211: fix beacon interval calculation overflow
    (git-fixes).
  - commit ea1fa22

++++ pango:

  - Update to version 1.56.4:
    + fontconfig:
  - Improve the add_font_file implementation
  - Combine font features and style variants
  - Make sure font faces stay alive
    + win32:
  - Drop some caching
  - Make sure font faces stay alive
  - Modernize and simplify the code
  - Stop synthesizing fonts
  - Implement list models
    + coretext: Support synthetic small caps
    + layout: Avoid assertions in line breaking
    + build: Require GLib 2.82

++++ libxml2:

  - security update
  - added patches
    CVE-2025-49794 [bsc#1244554], heap use after free (UAF) can lead to Denial of service (DoS)
    CVE-2025-49796 [bsc#1244557], type confusion may lead to Denial of service (DoS)
    + libxml2-CVE-2025-49794,49796.patch
    CVE-2025-49795 [bsc#1244555], null pointer dereference may lead to Denial of service (DoS)
    + libxml2-CVE-2025-49795.patch
  - security update
  - added patches
    CVE-2025-6021 [bsc#1244580], Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
    CVE-2025-6170 [bsc#1244700], stack buffer overflow may lead to a crash
    + libxml2-CVE-2025-6170,6021.patch

++++ libxml2-python:

  - security update
  - added patches
    CVE-2025-49794 [bsc#1244554], heap use after free (UAF) can lead to Denial of service (DoS)
    CVE-2025-49796 [bsc#1244557], type confusion may lead to Denial of service (DoS)
    + libxml2-CVE-2025-49794,49796.patch
    CVE-2025-49795 [bsc#1244555], null pointer dereference may lead to Denial of service (DoS)
    + libxml2-CVE-2025-49795.patch
  - security update
  - added patches
    CVE-2025-6021 [bsc#1244580], Integer Overflow in xmlBuildQName() Leads to Stack Buffer Overflow in libxml2
    CVE-2025-6170 [bsc#1244700], stack buffer overflow may lead to a crash
    + libxml2-CVE-2025-6170,6021.patch

++++ ovmf:

  - Enables UEFI Shell support for virtual machines on X64 and AARCH64 platforms (bsc#1244266)
  - Build Shell.efi and install it to /usr/share/ovmf/
  - Add ovmf-ShellPkg-Add-post-script-for-Shell-installation.patch
  - Add post-install and post-uninstall scripts in /usr/share/ovmf/
  - Install Shell.efi to the EFI boot partition
    (/boot/efi/EFI/opensuse/ or /boot/efi/EFI/sles/)
  - Register Shell.efi as a UEFI boot entry

++++ selinux-policy:

  - Update to version 20250627+git0.1805634d:
    * Set /srv/www = /var/www as equivalent file context (bsc#1239177)
    * Add a smoke test to the gitlab-ci
    * Add a default PR template
    * allow openvpn to attach to wicked owned tun interfaces (bsc#1243291)
    * allow wicked to connect to networkmanager and mange pid files for it (bsc#1243291)
    * allow wicked to transition to openvswitch domain (bsc#1243291)
    * allow wicked to start systemd services (bsc#1243291)
    * allow wicked to controll firewalld services (bsc1243291)
    * allow wicked interaction with tmpfs files and creation of sysfs files (bsc#1243291)
    * introduce fs_dontaudit_exec_tmpfs_files interface
    * Trigger the gitlab-ci tests only for merge requests to factory
    * Move 'logging_mounton_syslog_pid_socket' to end of file
    * Revert "Allow init_t create syslog files (bsc#1230134)"
    * Allow mdadm nosuid_transition
    * Label plasma user service files as xdm_unit_file_t.
    * Revert "Allow systemd-homed to start services."
    * Allow virtstoraged write qemu runtime files
    * Allow virtqemud read/write/setattr input event devices
    * Allow systemd create journal pid files
    * Allow networkmanager send a general signal to iptables
    * Allow syslogd watch syslog_conf_t directories
    * Revert downstream fix for bsc#1199630 due to regression (bsc#1243242)
    * Allow systemd-machined work with its private tmp and tmpfs files
    * Allow geoclue read virt lib files
    * Fix files_dontaudit_delete_all_files()
    * Label /run/polkit-1 with policykit_var_run_t
    * Label /dev/diag as diagnostic_device_t
    * Allow systemd-homed to start services.
    * Allow named_t to read NetworkManager's runtime files
    * Improve README* documentation
    * Add missing permissions for ftpd_anon_write to manage NFS directories
    * Add missing permissions for ftpd_anon_write to manage CIFS directories
    * Allow nut-upsmon write systemd inhibit pipes
    * Allow systemd-user-runtime-dir connect to systemd-userdbd over a unix socket
    * Remove permissive domain for systemd_vsftpd_generator_t
    * Change generator-specific rules to apply to systemd_generator
    * Define file equivalency for /var/etc
    * Allow tuned-ppd create ppd_base_profile with a file transition
    * Allow lldpd connect to systemd-homed over a unix socket
    * Allow sysadm_sudo_t signal rpm script
    * Fix the "/var/cache/systemd/home(/.*)?" regex
    * allow selinux_autorelabel_generator_t dac_read_search (bsc#1237511)
    * do not set sulogin_no_pam (bsc#1237511)
  - Replace internal slfo-main git branch with factory

------------------------------------------------------------------
------------------  2025-6-26  -  Jun 26 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Patch cockpit-machines to ignore domain not found errors
    when domain is deleted (bsc#1236383)
    * added nic-domain-not-found.patch

++++ cryptsetup:

  - Update to 2.8.0:
    * Full release notes in:
  - https://cdn.kernel.org/pub/linux/utils/cryptsetup/v2.8/v2.8.0-ReleaseNotes
    * Introduce support for inline mode (use HW sectors with additional hardware
    metadata space).
    * Finalize use of keyslot context API.
    * Make all keyslot context types fully self-contained.
    * Add --key-description and --new-key-description cryptsetup options.
    * Support more precise keyslot selection in reencryption initialization.
    * Allow reencryption to resume using token and volume keys.
    * Cryptsetup repair command now tries to check LUKS keyslot areas for corruption.
    * Opal2 SED: PSID keyfile is now expected to be 32 alphanumeric characters.
    * Opal2: Avoid the Erase method and use Secure Erase for locking range.
    * Opal2: Fix some error description (in debug only).
    * Opal2: Do not allow deferred deactivation.
    * Allow --reduce-device-size and --device-size combination for reencryption
    (encrypt) action.
    * Fix the userspace storage backend to support kernel "capi:" cipher specification format.
    * Disallow conversion from LUKS2 to LUKS1 if kernel "capi:" cipher specification is used.
    * Explicitly disallow kernel "capi:" cipher specification format for LUKS2
    keyslot encryption.
    * Do not allow conversion of LUKS2 to LUKS1 if an unbound keyslot is present.
    * cryptsetup: Adjust the XTS key size for kernel "capi:" cipher specification.
    * Remove keyslot warning about possible failure due to low memory.
    * Do not limit Argon2 KDF memory cost on systems with more than 4GB of available memory.
    * Properly report out of memory error for cryptographic backends implementing Argon2.
    * Avoid KDF2 memory cost overflow on 32-bit platforms.
    * Do not use page size as a fallback for device block size.
    * veritysetup: Check hash device size in advance.
    * Print a better error message for unsupported LUKS2 AEAD device resize.
    * Optimize LUKS2 metadata writes.
    * veritysetup: support --error-as-corruption option.
    * Report all sizes in status and dump command output in the correct units.
    * Add --integrity-key-size option to cryptsetup.
    * Support trusted & encrypted keyrings for plain devices.
    * Support plain format resize with a keyring key.
    * TCRYPT: Clear mapping of system-encrypted partitions.
    * TCRYPT: Print all information from the decrypted metadata header in
    the tcryptDump command.
    * Always lock the volume key structure in memory.
    * Do not run direct-io read check on block devices.
    * Fix a possible segfault in deferred deactivation.
    * Exclude cipher allocation time from the cryptsetup benchmark.
    * Add Mbed-TLS optional crypto backend.
    * Fix the wrong preprocessor use of #ifdef for config.h processed by Meson.
    * Reorganize license files. The license text files are now in docs/licenses.
    The COPYING file in the root directory is the default license.
    * Remove cc-by-sa-4.0.txt as already shipped now in docs/licenses
    and named as COPYING.CC-BY-SA-4.0.
    * Libcryptsetup API extensions. The libcryptsetup API is backward compatible
    with all existing symbols. Due to the self-contained memory allocation,
    these symbols have the new version:
  - crypt_keyslot_context_init_by_passphrase;
  - crypt_keyslot_context_init_by_keyfile;
  - crypt_keyslot_context_init_by_token;
  - crypt_keyslot_context_init_by_volume_key;
  - crypt_keyslot_context_init_by_signed_key;
  - crypt_keyslot_context_init_by_keyring;
  - crypt_keyslot_context_init_by_vk_in_keyring;
    * New symbols:
  - crypt_format_inline
  - crypt_get_old_volume_key_size
  - crypt_reencrypt_init_by_keyslot_context
  - crypt_safe_memcpy
    * New defines:
  - CRYPT_ACTIVATE_HIGH_PRIORITY
  - CRYPT_ACTIVATE_ERROR_AS_CORRUPTION
  - CRYPT_ACTIVATE_INLINE_MODE
  - CRYPT_REENCRYPT_CREATE_NEW_DIGEST
    * New requirement flag:
  - CRYPT_REQUIREMENT_INLINE_HW_TAGS

++++ git:

  - Fix git-gui citool SHA256 repo handling:
    refreshed 0002-git-gui-Add-support-of-SHA256-repo.patch

++++ gpg2:

  - Security fix: [bsc#1236931, bsc#1239119, CVE-2025-30258]
    * gpg: Fix another regression due to the T7547 fix.
    * The fix for CVE-2025-30258 was introduced in 2.5.5
    * Add gnupg-gpg-Fix-another-regression-due-to-the-T7547-fix.patch

++++ kernel-default:

  - mm/memory-tier: Fix abstract distance calculation overflow
    (bsc#1244051).
  - commit 3248628
  - x86/xen: Fix __xen_hypercall_setfunc() (git-fixes).
  - commit 76c9b78
  - x86: don't re-generate cpufeaturemasks.h so eagerly (git-fixes).
  - commit 1bde9b6
  - btrfs: fix wrong start offset for delalloc space release during
    mmap write (git-fixes).
  - btrfs: prepare btrfs_page_mkwrite() for large folios
    (git-fixes).
  - commit e702032
  - btrfs: fix invalid data space release when truncating block
    in NOCOW mode (git-fixes).
  - commit ecc292a
  - kabi/severities: ignore nf_flow_register_bpf() that depends on
    CONFIG_DEBUG_* (bsc#1245399)
  - commit f7994ea
  - x86/cpufeatures: Use AWK to generate {REQUIRED|DISABLED}_MASK_BIT_SET  in <asm/cpufeaturemasks.h> (git-fixes).
  - Refresh patches.suse/kabi-reserve-cpuid-leaves.patch.
  - commit c797ea7
  - x86/cpufeatures: Remove {disabled,required}-features.h (git-fixes).
  - Refresh patches.suse/kabi-reserve-cpuid-leaves.patch.
  - commit 7c1ff00
  - x86/cpufeatures: Generate the <asm/cpufeaturemasks.h> header based on  build config (git-fixes).
  - commit aa4d1af
  - x86/cpufeatures: Add {REQUIRED,DISABLED} feature configs (git-fixes).
  - commit 130db28
  - x86/cpufeatures: Rename X86_CMPXCHG64 to X86_CX8 (git-fixes).
  - commit c39c8b4
  - KVM: SVM: Add Idle HLT intercept support (jsc#PED-12577).
  - commit 9b4ced8
  - kabi: restore layout of struct cgroup_subsys (bsc#1241166).
  - commit 4553ae3
  - x86/cpufeatures: Add CPUID feature bit for Idle HLT intercept
    (jsc#PED-12577).
  - commit c78722e
  - cgroup/cpuset: Fix race between newly created partition and
    dying one (bsc#1241166).
  - cgroup/cpuset: Don't allow creation of local partition over
    a remote one (bsc#1241166).
  - commit 0392529
  - vmxnet3: correctly report gso type for UDP tunnels
    (bsc#1244626).
  - commit 1216762
  - vmxnet3: update MTU after device quiesce (bsc#1244626).
  - commit d22f709

++++ kernel-rt:

  - mm/memory-tier: Fix abstract distance calculation overflow
    (bsc#1244051).
  - commit 3248628
  - x86/xen: Fix __xen_hypercall_setfunc() (git-fixes).
  - commit 76c9b78
  - x86: don't re-generate cpufeaturemasks.h so eagerly (git-fixes).
  - commit 1bde9b6
  - btrfs: fix wrong start offset for delalloc space release during
    mmap write (git-fixes).
  - btrfs: prepare btrfs_page_mkwrite() for large folios
    (git-fixes).
  - commit e702032
  - btrfs: fix invalid data space release when truncating block
    in NOCOW mode (git-fixes).
  - commit ecc292a
  - kabi/severities: ignore nf_flow_register_bpf() that depends on
    CONFIG_DEBUG_* (bsc#1245399)
  - commit f7994ea
  - x86/cpufeatures: Use AWK to generate {REQUIRED|DISABLED}_MASK_BIT_SET  in <asm/cpufeaturemasks.h> (git-fixes).
  - Refresh patches.suse/kabi-reserve-cpuid-leaves.patch.
  - commit c797ea7
  - x86/cpufeatures: Remove {disabled,required}-features.h (git-fixes).
  - Refresh patches.suse/kabi-reserve-cpuid-leaves.patch.
  - commit 7c1ff00
  - x86/cpufeatures: Generate the <asm/cpufeaturemasks.h> header based on  build config (git-fixes).
  - commit aa4d1af
  - x86/cpufeatures: Add {REQUIRED,DISABLED} feature configs (git-fixes).
  - commit 130db28
  - x86/cpufeatures: Rename X86_CMPXCHG64 to X86_CX8 (git-fixes).
  - commit c39c8b4
  - KVM: SVM: Add Idle HLT intercept support (jsc#PED-12577).
  - commit 9b4ced8
  - kabi: restore layout of struct cgroup_subsys (bsc#1241166).
  - commit 4553ae3
  - x86/cpufeatures: Add CPUID feature bit for Idle HLT intercept
    (jsc#PED-12577).
  - commit c78722e
  - cgroup/cpuset: Fix race between newly created partition and
    dying one (bsc#1241166).
  - cgroup/cpuset: Don't allow creation of local partition over
    a remote one (bsc#1241166).
  - commit 0392529
  - vmxnet3: correctly report gso type for UDP tunnels
    (bsc#1244626).
  - commit 1216762
  - vmxnet3: update MTU after device quiesce (bsc#1244626).
  - commit d22f709

++++ kmod:

  - Fix testsuite on Leap 16.0 (bsc#1240126)
    * Revert-build-check-for-__xstat-declarations.patch

++++ gcc15:

  - Update to GCC 15 branch head, 15.1.1+git9866
  - Fix PR120827, ICE due to splitter emitting constant loads directly

++++ ovmf:

  - Add patch to make Ovmf builds reproducible in OvmfPkg and ArmVirtPkg (bsc#1244218)
  - Add ovmf-OvmfPkg-ArmVirtPkg-Keep-JSON-stack-cookie-files.patch

------------------------------------------------------------------
------------------  2025-6-25  -  Jun 25 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 28.3.0-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2830>
    bsc#1246556
  - Rebase patches:
    * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
    * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

++++ python-kiwi:

  - Add container_import template test
  - Bump version: 10.2.24 → 10.2.25
  - Fixed get_partition_node_name
    The function get_partition_node_name takes the disk device
    and the partition index as arguments to match against the
    respective device node for this partition index. The partition
    index is the position of the partition in the partition table
    according to their start offset. For the code to function
    properly it is required that the list of partitions provided
    by lsblk is ordered according to the start address of the
    partitions in the table. The way lsblk was called did not
    enforce this ordering. This commit enforces the order to
    be done against the start offset and fixes bsc#1245190

++++ kernel-default:

  - btrfs: factor out nocow ordered extent and extent map generation
    into a helper (git-fixes).
  - btrfs: fix qgroup reservation leak on failure to allocate
    ordered extent (git-fixes).
  - btrfs: move ordered extent cleanup to where they are allocated
    (git-fixes).
  - btrfs: remove the unused locked_folio parameter from
    btrfs_cleanup_ordered_extents() (git-fixes).
  - btrfs: use unsigned types for constants defined as bit shifts
    (git-fixes).
  - Refresh
    patches.suse/0005-btrfs-do-proper-folio-cleanup-when-run_delalloc_noco.patch.
  - commit a1f80d1
  - tracing: Fix compilation warning on arm32 (bsc#1243551).
  - commit 5ab4900
  - cpufreq/amd-pstate: Add support for the "Requested CPU Min
    frequency" BIOS option (jsc#PED-13164).
  - cpufreq/amd-pstate: Add offline, online and suspend callbacks
    for amd_pstate_driver (jsc#PED-13164).
  - cpufreq/amd-pstate: Move max_perf limiting in amd_pstate_update
    (jsc#PED-13164).
  - commit c625c71
  - cpufreq/amd-pstate: Enable ITMT support after initializing
    core rankings (jsc#PED-13164).
  - cpufreq/amd-pstate: Fix min_limit perf and freq updation for
    performance governor (jsc#PED-13164).
  - commit f84536f
  - cpufreq/amd-pstate: Set different default EPP policy for Epyc and Ryzen (jsc#PED-13164).
  - Refresh patches.suse/cpufreq-amd-pstate-Default-to-powersave-governor-whe.patch.
  - commit f5fec72
  - ata: ahci: Disallow LPM for Asus B550-F motherboard (git-fixes).
  - commit 50509e4
  - ata: ahci: Disallow LPM for ASUSPRO-D840SA motherboard
    (git-fixes).
  - commit 1162257
  - ata: ahci: Use correct BIOS build date for ThinkPad W541 quirk
    (git-fixes).
  - commit be1e349
  - pidfs: ensure that PIDFS_INFO_EXIT is available (jsc#PED-13113).
  - blacklist.conf: Guard against unused prerequisite
  - commit 872e385
  - exit: fix the usage of delay_group_leader->exit_code in
    do_notify_parent() and pidfs_exit() (jsc#PED-13113).
  - pidfs: improve multi-threaded exec and premature thread-group
    leader exit polling (jsc#PED-13113).
  - commit c5e2e6c
  - ata: Fix typos in the comment (git-fixes).
  - commit c056491
  - cpufreq/amd-pstate: Drop actions in amd_pstate_epp_cpu_offline()
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Stop caching EPP (jsc#PED-13164).
  - cpufreq/amd-pstate: Rework CPPC enabling (jsc#PED-13164).
  - cpufreq/amd-pstate: Drop debug statements for policy setting
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Update cppc_req_cached for shared mem EPP
    writes (jsc#PED-13164).
  - cpufreq/amd-pstate: Move all EPP tracing into *_update_perf
    and *_set_epp functions (jsc#PED-13164).
  - cpufreq/amd-pstate: Cache CPPC request in shared mem case too
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Replace all AMD_CPPC_* macros with masks
    (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Adjust variable scope (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Run on all of the correct CPUs
    (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Drop SUCCESS and FAIL enums
    (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Allow lowest nonlinear and lowest to
    be the same (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Use _free macro to free put policy
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Drop `cppc_cap1_cached` (jsc#PED-13164).
  - cpufreq/amd-pstate: Overhaul locking (jsc#PED-13164).
  - cpufreq/amd-pstate: Move perf values into a union
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Drop min and max cached frequencies
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Show a warning when a CPU fails to setup
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Invalidate cppc_req_cached during suspend
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Fix the clamping of perf values
    (jsc#PED-13164).
  - commit 0b848ba
  - bpf: abort verification if env->cur_state->loop_entry != NULL
    (CVE-2025-38060 bsc#1245155).
  - commit 3e1f9c9
  - tracing: Fix oob write in trace_seq_to_buffer() (CVE-2025-37923
    bsc#1243551).
  - commit 3a99a12
  - cpufreq/amd-pstate: Remove the unncecessary driver_lock in
    amd_pstate_update_limits (jsc#PED-13164).
  - cpufreq/amd-pstate: Use scope based cleanup for cpufreq_policy
    refs (jsc#PED-13164).
  - cpufreq/amd-pstate: Remove the unnecessary cpufreq_update_policy
    call (jsc#PED-13164).
  - cpufreq/amd-pstate: Modularize perf<->freq conversion (jsc#PED-13164).
  - Refresh patches.suse/cpufreq-amd-pstate-Add-missing-NULL-ptr-check-in-amd.patch.
  - cpufreq/amd-pstate: Convert all perf values to u8 (jsc#PED-13164).
  - Refresh patches.suse/cpufreq-amd-pstate-Add-missing-NULL-ptr-check-in-amd.patch.
  - cpufreq/amd-pstate: Pass min/max_limit_perf as min/max_perf
    to amd_pstate_update (jsc#PED-13164).
  - cpufreq/amd-pstate: Remove the redundant des_perf clamping in
    adjust_perf (jsc#PED-13164).
  - cpufreq/amd-pstate: Modify the min_perf calculation in
    adjust_perf callback (jsc#PED-13164).
  - commit 21b14f2
  - tracing: Fix use-after-free in print_graph_function_flags
    during tracer switching (CVE-2025-22035 bsc#1241544).
  - commit 49f381e
  - bpf: free verifier states when they are no longer referenced
    (CVE-2025-38060 bsc#1245155).
  - Refresh patches.suse/kABI-padding-for-bpf.patch.
  - commit 06e2482
  - bpf: fix env->peak_states computation (CVE-2025-38060
    bsc#1245155).
  - commit 53d5bd3
  - bpf: use list_head to track explored states and free list
    (CVE-2025-38060 bsc#1245155).
  - bpf: do not update state->loop_entry in get_loop_entry()
    (CVE-2025-38060 bsc#1245155).
  - bpf: make state->dfs_depth < state->loop_entry->dfs_depth an
    invariant (CVE-2025-38060 bsc#1245155).
  - bpf: detect infinite loop in get_loop_entry() (CVE-2025-38060
    bsc#1245155).
  - selftests/bpf: check states pruning for deeply nested iterator
    (CVE-2025-38060 bsc#1245155).
  - bpf: don't do clean_live_states when state->loop_entry->branches
    > 0 (CVE-2025-38060 bsc#1245155).
  - selftests/bpf: test correct loop_entry update in
    copy_verifier_state (CVE-2025-38060 bsc#1245155).
  - bpf: copy_verifier_state() should copy 'loop_entry' field
    (CVE-2025-38060 bsc#1245155).
  - commit 6388e16
  - bpf: Fix deadlock between rcu_tasks_trace and event_mutex
    (CVE-2025-37884 bsc#1243060).
  - commit 1feaa51

++++ kernel-firmware-media:

  - Update to version 20250624 (git commit b05fabcd6f2a):
    * qcom: venus-5.4: add the firmware binary for qcs615

++++ kernel-rt:

  - btrfs: factor out nocow ordered extent and extent map generation
    into a helper (git-fixes).
  - btrfs: fix qgroup reservation leak on failure to allocate
    ordered extent (git-fixes).
  - btrfs: move ordered extent cleanup to where they are allocated
    (git-fixes).
  - btrfs: remove the unused locked_folio parameter from
    btrfs_cleanup_ordered_extents() (git-fixes).
  - btrfs: use unsigned types for constants defined as bit shifts
    (git-fixes).
  - Refresh
    patches.suse/0005-btrfs-do-proper-folio-cleanup-when-run_delalloc_noco.patch.
  - commit a1f80d1
  - tracing: Fix compilation warning on arm32 (bsc#1243551).
  - commit 5ab4900
  - cpufreq/amd-pstate: Add support for the "Requested CPU Min
    frequency" BIOS option (jsc#PED-13164).
  - cpufreq/amd-pstate: Add offline, online and suspend callbacks
    for amd_pstate_driver (jsc#PED-13164).
  - cpufreq/amd-pstate: Move max_perf limiting in amd_pstate_update
    (jsc#PED-13164).
  - commit c625c71
  - cpufreq/amd-pstate: Enable ITMT support after initializing
    core rankings (jsc#PED-13164).
  - cpufreq/amd-pstate: Fix min_limit perf and freq updation for
    performance governor (jsc#PED-13164).
  - commit f84536f
  - cpufreq/amd-pstate: Set different default EPP policy for Epyc and Ryzen (jsc#PED-13164).
  - Refresh patches.suse/cpufreq-amd-pstate-Default-to-powersave-governor-whe.patch.
  - commit f5fec72
  - ata: ahci: Disallow LPM for Asus B550-F motherboard (git-fixes).
  - commit 50509e4
  - ata: ahci: Disallow LPM for ASUSPRO-D840SA motherboard
    (git-fixes).
  - commit 1162257
  - ata: ahci: Use correct BIOS build date for ThinkPad W541 quirk
    (git-fixes).
  - commit be1e349
  - pidfs: ensure that PIDFS_INFO_EXIT is available (jsc#PED-13113).
  - blacklist.conf: Guard against unused prerequisite
  - commit 872e385
  - exit: fix the usage of delay_group_leader->exit_code in
    do_notify_parent() and pidfs_exit() (jsc#PED-13113).
  - pidfs: improve multi-threaded exec and premature thread-group
    leader exit polling (jsc#PED-13113).
  - commit c5e2e6c
  - ata: Fix typos in the comment (git-fixes).
  - commit c056491
  - cpufreq/amd-pstate: Drop actions in amd_pstate_epp_cpu_offline()
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Stop caching EPP (jsc#PED-13164).
  - cpufreq/amd-pstate: Rework CPPC enabling (jsc#PED-13164).
  - cpufreq/amd-pstate: Drop debug statements for policy setting
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Update cppc_req_cached for shared mem EPP
    writes (jsc#PED-13164).
  - cpufreq/amd-pstate: Move all EPP tracing into *_update_perf
    and *_set_epp functions (jsc#PED-13164).
  - cpufreq/amd-pstate: Cache CPPC request in shared mem case too
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Replace all AMD_CPPC_* macros with masks
    (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Adjust variable scope (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Run on all of the correct CPUs
    (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Drop SUCCESS and FAIL enums
    (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Allow lowest nonlinear and lowest to
    be the same (jsc#PED-13164).
  - cpufreq/amd-pstate-ut: Use _free macro to free put policy
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Drop `cppc_cap1_cached` (jsc#PED-13164).
  - cpufreq/amd-pstate: Overhaul locking (jsc#PED-13164).
  - cpufreq/amd-pstate: Move perf values into a union
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Drop min and max cached frequencies
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Show a warning when a CPU fails to setup
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Invalidate cppc_req_cached during suspend
    (jsc#PED-13164).
  - cpufreq/amd-pstate: Fix the clamping of perf values
    (jsc#PED-13164).
  - commit 0b848ba
  - bpf: abort verification if env->cur_state->loop_entry != NULL
    (CVE-2025-38060 bsc#1245155).
  - commit 3e1f9c9
  - tracing: Fix oob write in trace_seq_to_buffer() (CVE-2025-37923
    bsc#1243551).
  - commit 3a99a12
  - cpufreq/amd-pstate: Remove the unncecessary driver_lock in
    amd_pstate_update_limits (jsc#PED-13164).
  - cpufreq/amd-pstate: Use scope based cleanup for cpufreq_policy
    refs (jsc#PED-13164).
  - cpufreq/amd-pstate: Remove the unnecessary cpufreq_update_policy
    call (jsc#PED-13164).
  - cpufreq/amd-pstate: Modularize perf<->freq conversion (jsc#PED-13164).
  - Refresh patches.suse/cpufreq-amd-pstate-Add-missing-NULL-ptr-check-in-amd.patch.
  - cpufreq/amd-pstate: Convert all perf values to u8 (jsc#PED-13164).
  - Refresh patches.suse/cpufreq-amd-pstate-Add-missing-NULL-ptr-check-in-amd.patch.
  - cpufreq/amd-pstate: Pass min/max_limit_perf as min/max_perf
    to amd_pstate_update (jsc#PED-13164).
  - cpufreq/amd-pstate: Remove the redundant des_perf clamping in
    adjust_perf (jsc#PED-13164).
  - cpufreq/amd-pstate: Modify the min_perf calculation in
    adjust_perf callback (jsc#PED-13164).
  - commit 21b14f2
  - tracing: Fix use-after-free in print_graph_function_flags
    during tracer switching (CVE-2025-22035 bsc#1241544).
  - commit 49f381e
  - bpf: free verifier states when they are no longer referenced
    (CVE-2025-38060 bsc#1245155).
  - Refresh patches.suse/kABI-padding-for-bpf.patch.
  - commit 06e2482
  - bpf: fix env->peak_states computation (CVE-2025-38060
    bsc#1245155).
  - commit 53d5bd3
  - bpf: use list_head to track explored states and free list
    (CVE-2025-38060 bsc#1245155).
  - bpf: do not update state->loop_entry in get_loop_entry()
    (CVE-2025-38060 bsc#1245155).
  - bpf: make state->dfs_depth < state->loop_entry->dfs_depth an
    invariant (CVE-2025-38060 bsc#1245155).
  - bpf: detect infinite loop in get_loop_entry() (CVE-2025-38060
    bsc#1245155).
  - selftests/bpf: check states pruning for deeply nested iterator
    (CVE-2025-38060 bsc#1245155).
  - bpf: don't do clean_live_states when state->loop_entry->branches
    > 0 (CVE-2025-38060 bsc#1245155).
  - selftests/bpf: test correct loop_entry update in
    copy_verifier_state (CVE-2025-38060 bsc#1245155).
  - bpf: copy_verifier_state() should copy 'loop_entry' field
    (CVE-2025-38060 bsc#1245155).
  - commit 6388e16
  - bpf: Fix deadlock between rcu_tasks_trace and event_mutex
    (CVE-2025-37884 bsc#1243060).
  - commit 1feaa51

++++ ldmtool:

  - Update to version 0.2.5 (jsc#PED-12706)
    * Fix crash while creating mapper for a volume which lacks of
    partitions
    * Make libldm to parse and return volume GUID
    * Change the way we sanitise LDM partition name
    * Set UUID for device mapper devices (partitions and volumes)
    * Fix potential memory leak
    * Use device mapper device UUID instead of name to find device in
    a tree
    * New API: ldm_volume_dm_get_device
    * New API: ldm_partition_dm_get_device
    * Fix bug in libldm to allow for all spanned LDM volumes to bex
    correctly identified/mounted
  - Upstream fixes post 0.2.5
    001-Add-example-systemd-unit-file.patch
    002-ldmtool-fix-NULL-pointer-dereference.patch
    003-Add-ability-to-override-device-mapper-UUID.patch
    004-src-Fix-declaration-of-ldm_new.patch
    005-Update-gtkdocize.patch
  - Drop patch contained in new tarball
    Remove-deprecated-g_type_class_add_private.patch

++++ xfsprogs:

  - update to 6.15.0
  - xfs_mdrestore: don't allow restoring onto zoned block devices
  - man: adjust description of the statx manpage
  - xfs_protofile: fix permission octet when suid/guid is set
  - xfs_repair: fix libxfs abstraction mess
  - xfs_growfs: support internal RT devices
  - xfs_mdrestore: support internal RT devices
  - xfs_scrub: support internal RT device
  - xfs_spaceman: handle internal RT devices
  - xfs_io: handle internal RT devices in fsmap output
  - xfs_io: don't re-query fs_path information in fsmap_f
  - xfs_io: correctly report RGs with internal rt dev in bmap output
  - man: document XFS_FSOP_GEOM_FLAGS_ZONED
  - xfs_mkfs: document the new zoned options in the man page
  - xfs_mkfs: reflink conflicts with zoned file systems for now
  - xfs_mkfs: default to rtinherit=1 for zoned file systems
  - xfs_mkfs: calculate zone overprovisioning when specifying size
  - xfs_mkfs: support creating file system with zoned RT devices
  - xfs_mkfs: factor out a validate_rtgroup_geometry helper
  - xfs_repair: validate rt groups vs reported hardware zones
  - xfs_repair: fix the RT device check in process_dinode_int
  - xfs_repair: support repairing zoned file systems
  - libfrog: report the zoned geometry
  - xfs_repair: phase6: scan longform entries before header check
  - xfs_repair: Bump link count if longform_dir2_rebuild yields shortform dir
  - mkfs: fix the issue of maxpct set to 0 not taking effect
  - mkfs: fix blkid probe API violations causing weird output
  - xfs_io: make statx mask parsing more generally useful
  - xfs_io: redefine what statx -m all does
  - xfs_io: catch statx fields up to 6.15
  - man: fix missing cachestat manpage

------------------------------------------------------------------
------------------  2025-6-24  -  Jun 24 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add support for container-snap as a container-image engine
    With this commit, we can now pre-load images using container-snap directly
    during the kiwi image build
  - Update test-image-MicroOS for local build
    Fix bootstrap setup such that micro-os patterns can resolve
  - Fix logging of stderr data in command calls
    The stderr data was presented as one blob without line
    breaks. Hard to read and smells like a bug. This commit
    fixes the output to become readable
  - Update test-image-MicroOS/disk.sh
    Add a findmnt for / to check if there is a proper root
    device reference

++++ kernel-default:

  - netfilter: nft_exthdr: fix offset with ipv4_find_option()
    (git-fixes).
  - commit be2a228
  - netfilter: conntrack: Bound nf_conntrack sysctl writes
    (git-fixes).
  - commit 0ac13d2
  - netfilter: nf_tables: Only use nf_skip_indirect_calls() when
    MITIGATION_RETPOLINE (git-fixes).
  - commit 114a1de
  - netfilter: nft_set_hash: GC reaps elements with conncount for
    dynamic sets only (git-fixes).
  - commit fd8be75
  - netfilter: nft_quota: match correctly when the quota just
    depleted (git-fixes).
  - commit 563b1e8
  - netfilter: nf_set_pipapo_avx2: fix initial map fill (git-fixes).
  - commit 5316618
  - netfilter: bridge: Move specific fragmented packet to slow_path
    instead of dropping it (git-fixes).
  - commit 3a5285b
  - netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result
    discrepancy (git-fixes).
  - commit 18d1e67
  - netfilter: nf_tables: nft_fib: consistent l3mdev handling
    (git-fixes).
  - commit 2b7f119
  - s390/pci: Fix s390_mmio_read/write syscall page fault handling
    (git-fixes bsc#1245291).
  - commit 2f37aef
  - s390: Fix linker error when -no-pie option is unavailable
    (git-fixes bsc#1245290).
  - commit 788b161
  - Delete patches.suse/nvdimm-disable-namespace-on-error.patch.
    We think the patch is not needed and the issue bsc#1166486 has actually
    been resolved by upstream commit c1f45d86a522. The upstream submission
    never got any reply [*], so if we decide we in the end want the patch,
    it should be resent there first.
    [*] https://lore.kernel.org/nvdimm/20211201164844.125296-1-colyli@suse.de/
  - commit ecc0f57
  - s390/vfio-ap: Fix no AP queue sharing allowed message written
    to kernel log (git-fixes bsc#1245285).
  - commit 9d4cdf8
  - scsi: elx: efct: Fix memory leak in efct_hw_parse_filter()
    (git-fixes).
  - scsi: iscsi: Fix incorrect error path labels for flashnode
    operations (git-fixes).
  - commit 1fc590c

++++ kernel-firmware-amdgpu:

  - Update to version 20250623 (git commit dbfe16e9e8ac):
    * amdgpu: update dmcub fw for dcn401

++++ kernel-firmware-brcm:

  - Update to version 20250623 (git commit dbfe16e9e8ac):
    * brcm: Fix symlinks for Khadas VIM SDIO wifi config

++++ kernel-rt:

  - netfilter: nft_exthdr: fix offset with ipv4_find_option()
    (git-fixes).
  - commit be2a228
  - netfilter: conntrack: Bound nf_conntrack sysctl writes
    (git-fixes).
  - commit 0ac13d2
  - netfilter: nf_tables: Only use nf_skip_indirect_calls() when
    MITIGATION_RETPOLINE (git-fixes).
  - commit 114a1de
  - netfilter: nft_set_hash: GC reaps elements with conncount for
    dynamic sets only (git-fixes).
  - commit fd8be75
  - netfilter: nft_quota: match correctly when the quota just
    depleted (git-fixes).
  - commit 563b1e8
  - netfilter: nf_set_pipapo_avx2: fix initial map fill (git-fixes).
  - commit 5316618
  - netfilter: bridge: Move specific fragmented packet to slow_path
    instead of dropping it (git-fixes).
  - commit 3a5285b
  - netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result
    discrepancy (git-fixes).
  - commit 18d1e67
  - netfilter: nf_tables: nft_fib: consistent l3mdev handling
    (git-fixes).
  - commit 2b7f119
  - s390/pci: Fix s390_mmio_read/write syscall page fault handling
    (git-fixes bsc#1245291).
  - commit 2f37aef
  - s390: Fix linker error when -no-pie option is unavailable
    (git-fixes bsc#1245290).
  - commit 788b161
  - Delete patches.suse/nvdimm-disable-namespace-on-error.patch.
    We think the patch is not needed and the issue bsc#1166486 has actually
    been resolved by upstream commit c1f45d86a522. The upstream submission
    never got any reply [*], so if we decide we in the end want the patch,
    it should be resent there first.
    [*] https://lore.kernel.org/nvdimm/20211201164844.125296-1-colyli@suse.de/
  - commit ecc0f57
  - s390/vfio-ap: Fix no AP queue sharing allowed message written
    to kernel log (git-fixes bsc#1245285).
  - commit 9d4cdf8
  - scsi: elx: efct: Fix memory leak in efct_hw_parse_filter()
    (git-fixes).
  - scsi: iscsi: Fix incorrect error path labels for flashnode
    operations (git-fixes).
  - commit 1fc590c

++++ util-linux-systemd:

  - Update to version 2.41.1:
    * cfdisk: fix memory leak and possible NULL dereference
    * fdisk: fix possible memory leak
    * findmnt: fix -k option parsing regression (boo#1242705,
    drop util-linux-libblkid-econf-parse.patch)
    * hardlink: fix performance regression
    * include/cctype: fix string comparison
    * libblkid:
    * Fix crash while parsing config with libeconf
    * befs fix underflow
    * avoid strcasecmp() for ASCII-only strings
    * libblkid/src/topology/dm: fix fscanf return value check to
    match expected number of parsed items
    * libmount:
    * (subdir) restrict for real mounts only
    * (subdir) remove unused code
    * avoid calling memset() unnecessarily
    * fix --no-canonicalize regression (boo#1244251,
    drop libmount-fix-no-canonicalize-regression.patch)
    * lsblk:
    * use ID_PART_ENTRY_SCHEME as fallback for PTTYPE
    * avoid strcasecmp() for ASCII-only strings
    * lscpu:
    * fix possible buffer overflow in cpuinfo parser
    * Fix loongarch op-mode output with recent kernel
    * lsfd:
    * scan the protocol field of /proc/net/packet as a hex number
    * fix the description for PACKET.PROTOCOL column
    * lsns:
    * enhance compilation without USE_NS_GET_API
    * fix undefined reference to add_namespace_for_nsfd #3483
    * more:
    * fix broken ':!command' command key
    * fix implicit previous shell_line execution #3508
    * tests: (test_mkfds::mapped-packet-socket) add a new parameter,
    protocol
    * treewide:
    * add ul_ to parse_timestamp() function name
    (drop util-linux-rename-common-symbols-4.patch)
    * add ul_ to parse_switch() function name
    (drop util-linux-rename-common-symbols-3.patch)
    * add ul_ to parse_size() function name
    (drop util-linux-rename-common-symbols-2.patch)
    * add ul_ to parse_range() function name
    (drop util-linux-rename-common-symbols-1.patch)
    * fix optional arguments usage
    * avoid strcasecmp() for ASCII-only strings
    * Wipefs: improve --all descriptions for whole-disks
    * Misc: Do not call exit() on code ending in shared libraries
    * Other fixes. For complete list see
    https://kernel.org/pub/linux/utils/util-linux/v2.41/v2.41.1-ReleaseNotes
  - Fix problem with uname26 listed twice.

++++ util-linux:

  - Update to version 2.41.1:
    * cfdisk: fix memory leak and possible NULL dereference
    * fdisk: fix possible memory leak
    * findmnt: fix -k option parsing regression (boo#1242705,
    drop util-linux-libblkid-econf-parse.patch)
    * hardlink: fix performance regression
    * include/cctype: fix string comparison
    * libblkid:
    * Fix crash while parsing config with libeconf
    * befs fix underflow
    * avoid strcasecmp() for ASCII-only strings
    * libblkid/src/topology/dm: fix fscanf return value check to
    match expected number of parsed items
    * libmount:
    * (subdir) restrict for real mounts only
    * (subdir) remove unused code
    * avoid calling memset() unnecessarily
    * fix --no-canonicalize regression (boo#1244251,
    drop libmount-fix-no-canonicalize-regression.patch)
    * lsblk:
    * use ID_PART_ENTRY_SCHEME as fallback for PTTYPE
    * avoid strcasecmp() for ASCII-only strings
    * lscpu:
    * fix possible buffer overflow in cpuinfo parser
    * Fix loongarch op-mode output with recent kernel
    * lsfd:
    * scan the protocol field of /proc/net/packet as a hex number
    * fix the description for PACKET.PROTOCOL column
    * lsns:
    * enhance compilation without USE_NS_GET_API
    * fix undefined reference to add_namespace_for_nsfd #3483
    * more:
    * fix broken ':!command' command key
    * fix implicit previous shell_line execution #3508
    * tests: (test_mkfds::mapped-packet-socket) add a new parameter,
    protocol
    * treewide:
    * add ul_ to parse_timestamp() function name
    (drop util-linux-rename-common-symbols-4.patch)
    * add ul_ to parse_switch() function name
    (drop util-linux-rename-common-symbols-3.patch)
    * add ul_ to parse_size() function name
    (drop util-linux-rename-common-symbols-2.patch)
    * add ul_ to parse_range() function name
    (drop util-linux-rename-common-symbols-1.patch)
    * fix optional arguments usage
    * avoid strcasecmp() for ASCII-only strings
    * Wipefs: improve --all descriptions for whole-disks
    * Misc: Do not call exit() on code ending in shared libraries
    * Other fixes. For complete list see
    https://kernel.org/pub/linux/utils/util-linux/v2.41/v2.41.1-ReleaseNotes
  - Fix problem with uname26 listed twice.

++++ libguestfs:

  - Update to version 1.56.1 (jsc#PED-12706)
    * lib: Enable ACPI for the libvirt backend for x86_64 and arm
  - Only build the inspect-icons RPM for Tumbleweed. Tumbleweed is
    the only place where icoutils package exists which it requires.

++++ numactl:

  - Fix Node0 does not exist (bsc#1244492)
    A 4abeee1aac20a7a2552870e0359b8df013ae9037.patch

++++ ceph:

  - Disable ceph-mgr-cephadm in ring1

++++ libssh:

  - Update to version 0.11.2
    * Security:
    * CVE-2025-4877 - Write beyond bounds in binary to base64 conversion (bsc#1245309)
    * CVE-2025-4878 - Use of uninitialized variable in privatekey_from_file() (bsc#1245310)
    * CVE-2025-5318 - Likely read beyond bounds in sftp server handle management (bsc#1245311)
    * CVE-2025-5351 - Double free in functions exporting keys (bsc#1245312)
    * CVE-2025-5372 - ssh_kdf() returns a success code on certain failures (bsc#1245314)
    * CVE-2025-5449 - Likely read beyond bounds in sftp server message decoding (bsc#1245316)
    * CVE-2025-5987 - Invalid return code for chacha20 poly1305 with OpenSSL (bsc#1245317)
    * Compatibility
    * Fixed compatibility with CPM.cmake
    * Compatibility with OpenSSH 10.0
    * Tests compatibility with new Dropbear releases
    * Removed p11-kit remoting from the pkcs11 testsuite
    * Bugfixes
    * Implement missing packet filter for DH GEX
    * Properly process the SSH2_MSG_DEBUG message
    * Allow escaping quotes in quoted arguments to ssh configuration
    * Do not fail with unknown match keywords in ssh configuration
    * Process packets before selecting signature algorithm during authentication
    * Do not fail hard when the SFTP status message is not sent by noncompliant
    servers
  - Removed libssh-CmakeLists-Fix-multiple-digit-major-version-for-OpenSSH.patch
  - Removed libssh-misc-Fix-OpenSSH-banner-parsing.patch

++++ nvidia-open-driver-G06-signed:

  - 0003-nv-dmabuf-Inline-dma_buf_attachment_is_dynamic.patch
    0004-nvidia-uvm-Disable-SVA-support-for-6.16.patch
    * buildfixes against Kernel 6.16 picked up from
    https://github.com/CachyOS/CachyOS-PKGBUILDS.git
  - -> nvidia/nvidia-utils

------------------------------------------------------------------
------------------  2025-6-23  -  Jun 23 2025  -------------------
------------------------------------------------------------------

++++ busybox:

  - enable halt, poweroff, reboot commands (bsc#1243201)

++++ busybox-links:

  - Blacklist creating links for halt, reboot, shutdown commands to avoid accidental
    use in a fully booted system (bsc#1243201)

++++ docker:

    [ This update is a no-op, only needed to work around unfortunate automated
    packaging script behaviour on SLES. ]
  - The following patches were removed in openSUSE in the Docker 28.1.1-ce
    update, but the patch names were later renamed in a SLES-only update before
    Docker 28.1.1-ce was submitted to SLES.
    This causes the SLES build scripts to refuse the update because the patches
    are not referenced in the changelog. There is no obvious place to put the
    patch removals (the 28.1.1-ce update removing the patches chronologically
    predates their renaming in SLES), so they are included here a dummy changelog
    entry to work around the issue.
  - 0007-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  - 0008-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch

++++ python-kiwi:

  - Fix mount system for root_is_snapper_snapshot
    If root is a snapper snapshot we have to tell the
    chroot a proper root mount point which can be achieved
    by a bind mount pointing to itself. This Fixes
    bsc#1244668

++++ fwupd:

  - Fix %{_modulesloaddir}/fwupd-i2c.conf packaging

++++ kernel-default:

  - fs/mpage: use blocks_per_folio instead of blocks_per_page
    (bsc#1245219).
  - commit 6f61662
  - fs/mpage: avoid negative shift for large blocksize
    (bsc#1245219).
  - commit f40b15c
  - s390/tty: Fix a potential memory leak bug (git-fixes
    bsc#1245230).
  - commit 5f783ee
  - pidfs: never refuse ppid == 0 in PIDFD_GET_INFO (jsc#PED-13113).
  - commit 4327fa2
  - iommu/amd: Fix potential buffer overflow in  parse_ivrs_acpihid
    (CVE-2025-37927 bsc#1243620).
  - commit 0e060e5
  - Move upstreamed patch "genksyms: Fix enum consts from a reference
    affecting new values" into the sorted section (git-fixes).
  - commit 7c87e2b
  - s390/boot: Use -D__DISABLE_EXPORTS (bsc#1245126).
  - commit 79382ab
  - nvme: always punt polled uring_cmd end_io work to task_work
    (git-fixes).
  - nvme-tcp: remove tag set when second admin queue config fails
    (git-fixes).
  - nvme: fix implicit bool to flags conversion (git-fixes).
  - nvme: fix command limits status code (git-fixes).
  - nvme-fc: do not reference lsrsp after failure (bsc#1245193).
  - nvmet-fcloop: don't wait for lport cleanup (bsc#1245193).
  - nvmet-fcloop: add missing fcloop_callback_host_done
    (bsc#1245193).
  - nvmet-fc: take tgtport refs for portentry (bsc#1245193).
  - nvmet-fc: free pending reqs on tgtport unregister (bsc#1245193).
  - nvmet-fcloop: drop response if targetport is gone (bsc#1245193).
  - nvmet-fcloop: allocate/free fcloop_lsreq directly (bsc#1245193).
  - nvmet-fcloop: prevent double port deletion (bsc#1245193).
  - nvmet-fcloop: access fcpreq only when holding reqlock
    (bsc#1245193).
  - nvmet-fcloop: update refs on tfcp_req (bsc#1245193).
  - nvmet-fcloop: refactor fcloop_delete_local_port (bsc#1245193).
  - nvmet-fcloop: refactor fcloop_nport_alloc and track lport
    (bsc#1245193).
  - nvmet-fcloop: remove nport from list on last user (bsc#1245193).
  - nvmet-fcloop: track ref counts for nports (bsc#1245193).
  - nvme-pci: add NVME_QUIRK_NO_DEEPEST_PS quirk for SOLIDIGM P44
    Pro (git-fixes).
  - commit 60761a1
  - btrfs: fix fsync of files with no hard links not persisting
    deletion (bsc#1245068).
  - btrfs: remove end_no_trans label from btrfs_log_inode_parent()
    (bsc#1245068).
  - btrfs: simplify condition for logging new dentries at
    btrfs_log_inode_parent() (bsc#1245068).
  - commit 188ca65
  - Remove host-memcpy-hack.h
    This might have been usefult at some point but we have more things that
    depend on specific library versions today.
  - commit 0396c23
  - Remove compress-vmlinux.sh
    /usr/lib/rpm/brp-suse.d/brp-99-compress-vmlinux was added in
    pesign-obs-integration during SLE12 RC. This workaround can be removed.
  - commit 19caac0
  - Remove try-disable-staging-driver
    The config for linux-next is autogenerated from master config, and
    defaults filled for missing options. This is unlikely to enable any
    staging driver in the first place.
  - commit a6f21ed
  - btrfs: always fallback to buffered write if the inode  requires
    checksum (bsc#1245067).
  - commit b160824
  - cpufreq: Default to performance governor on servers
    (jsc#PED-13111).
  - commit 0f4c2f8
  - sunrpc: handle SVC_GARBAGE during svc auth processing as auth
    error (git-fixes).
  - commit 753d7ae
  - nfsd: use threads array as-is in netlink interface (git-fixes).
  - commit 3a8806c
  - Refresh patches.suse/x86-entry-Add-__init-to-ia32_emulation_override_cmdline.patch.
  - commit 15f587c
  - x86/microcode/AMD: Do not return error when microcode update is not  necessary (git-fixes).
  - commit 0b0ecd8
  - x86/virt/tdx: Avoid indirect calls to TDX assembly functions (git-fixes).
  - Refresh
    patches.suse/x86-virt-tdx-Mark-memory-cache-state-incoherent-when-making-seamcall.patch.
  - commit a3e640a
  - Revert "mm/execmem: Unify early execmem_cache behaviour" (git-fixes).
  - commit 99e2ca1
  - x86/its: explicitly manage permissions for ITS pages (git-fixes).
  - commit 4d57729
  - x86/Kconfig: only enable ROX cache in execmem when STRICT_MODULE_RWX  is set (git-fixes).
  - commit d3bec4e

++++ kernel-rt:

  - fs/mpage: use blocks_per_folio instead of blocks_per_page
    (bsc#1245219).
  - commit 6f61662
  - fs/mpage: avoid negative shift for large blocksize
    (bsc#1245219).
  - commit f40b15c
  - s390/tty: Fix a potential memory leak bug (git-fixes
    bsc#1245230).
  - commit 5f783ee
  - pidfs: never refuse ppid == 0 in PIDFD_GET_INFO (jsc#PED-13113).
  - commit 4327fa2
  - iommu/amd: Fix potential buffer overflow in  parse_ivrs_acpihid
    (CVE-2025-37927 bsc#1243620).
  - commit 0e060e5
  - Move upstreamed patch "genksyms: Fix enum consts from a reference
    affecting new values" into the sorted section (git-fixes).
  - commit 7c87e2b
  - s390/boot: Use -D__DISABLE_EXPORTS (bsc#1245126).
  - commit 79382ab
  - nvme: always punt polled uring_cmd end_io work to task_work
    (git-fixes).
  - nvme-tcp: remove tag set when second admin queue config fails
    (git-fixes).
  - nvme: fix implicit bool to flags conversion (git-fixes).
  - nvme: fix command limits status code (git-fixes).
  - nvme-fc: do not reference lsrsp after failure (bsc#1245193).
  - nvmet-fcloop: don't wait for lport cleanup (bsc#1245193).
  - nvmet-fcloop: add missing fcloop_callback_host_done
    (bsc#1245193).
  - nvmet-fc: take tgtport refs for portentry (bsc#1245193).
  - nvmet-fc: free pending reqs on tgtport unregister (bsc#1245193).
  - nvmet-fcloop: drop response if targetport is gone (bsc#1245193).
  - nvmet-fcloop: allocate/free fcloop_lsreq directly (bsc#1245193).
  - nvmet-fcloop: prevent double port deletion (bsc#1245193).
  - nvmet-fcloop: access fcpreq only when holding reqlock
    (bsc#1245193).
  - nvmet-fcloop: update refs on tfcp_req (bsc#1245193).
  - nvmet-fcloop: refactor fcloop_delete_local_port (bsc#1245193).
  - nvmet-fcloop: refactor fcloop_nport_alloc and track lport
    (bsc#1245193).
  - nvmet-fcloop: remove nport from list on last user (bsc#1245193).
  - nvmet-fcloop: track ref counts for nports (bsc#1245193).
  - nvme-pci: add NVME_QUIRK_NO_DEEPEST_PS quirk for SOLIDIGM P44
    Pro (git-fixes).
  - commit 60761a1
  - btrfs: fix fsync of files with no hard links not persisting
    deletion (bsc#1245068).
  - btrfs: remove end_no_trans label from btrfs_log_inode_parent()
    (bsc#1245068).
  - btrfs: simplify condition for logging new dentries at
    btrfs_log_inode_parent() (bsc#1245068).
  - commit 188ca65
  - Remove host-memcpy-hack.h
    This might have been usefult at some point but we have more things that
    depend on specific library versions today.
  - commit 0396c23
  - Remove compress-vmlinux.sh
    /usr/lib/rpm/brp-suse.d/brp-99-compress-vmlinux was added in
    pesign-obs-integration during SLE12 RC. This workaround can be removed.
  - commit 19caac0
  - Remove try-disable-staging-driver
    The config for linux-next is autogenerated from master config, and
    defaults filled for missing options. This is unlikely to enable any
    staging driver in the first place.
  - commit a6f21ed
  - btrfs: always fallback to buffered write if the inode  requires
    checksum (bsc#1245067).
  - commit b160824
  - cpufreq: Default to performance governor on servers
    (jsc#PED-13111).
  - commit 0f4c2f8
  - sunrpc: handle SVC_GARBAGE during svc auth processing as auth
    error (git-fixes).
  - commit 753d7ae
  - nfsd: use threads array as-is in netlink interface (git-fixes).
  - commit 3a8806c
  - Refresh patches.suse/x86-entry-Add-__init-to-ia32_emulation_override_cmdline.patch.
  - commit 15f587c
  - x86/microcode/AMD: Do not return error when microcode update is not  necessary (git-fixes).
  - commit 0b0ecd8
  - x86/virt/tdx: Avoid indirect calls to TDX assembly functions (git-fixes).
  - Refresh
    patches.suse/x86-virt-tdx-Mark-memory-cache-state-incoherent-when-making-seamcall.patch.
  - commit a3e640a
  - Revert "mm/execmem: Unify early execmem_cache behaviour" (git-fixes).
  - commit 99e2ca1
  - x86/its: explicitly manage permissions for ITS pages (git-fixes).
  - commit 4d57729
  - x86/Kconfig: only enable ROX cache in execmem when STRICT_MODULE_RWX  is set (git-fixes).
  - commit d3bec4e

++++ libblockdev:

  - suppress privilege escalation during xfs fs resize (CVE-2025-6019)
    (bsc#1243285)
    * add 0001-dont-allow-suid-and-dev-set-on-fs-resize.patch

++++ python-urllib3:

  - Update to 2.5.0:
    * Security issues
    Pool managers now properly control redirects when retries is passed
    (CVE-2025-50181, GHSA-pq67-6m6q-mj2v, bsc#1244925)
    Redirects are now controlled by urllib3 in the Node.js runtime
    (CVE-2025-50182, GHSA-48p4-8xcf-vxj5, bsc#1244924)
    * Features
    Added support for the compression.zstd module that is new in Python 3.14.
    Added support for version 0.5 of hatch-vcs
    * Bugfixes
    Raised exception for HTTPResponse.shutdown on a connection already
    released to the pool.
    Fixed incorrect CONNECT statement when using an IPv6 proxy with
    connection_from_host. Previously would not be wrapped in [].

------------------------------------------------------------------
------------------  2025-6-22  -  Jun 22 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - md/raid1,raid10: don't handle IO error for REQ_RAHEAD and
    REQ_NOWAIT (git-fixes).
  - commit 0ec5b97
  - PCI/PM: Set up runtime PM even for devices without PCI PM
    (git-fixes).
  - commit 58c3f30

++++ kernel-rt:

  - md/raid1,raid10: don't handle IO error for REQ_RAHEAD and
    REQ_NOWAIT (git-fixes).
  - commit 0ec5b97
  - PCI/PM: Set up runtime PM even for devices without PCI PM
    (git-fixes).
  - commit 58c3f30

------------------------------------------------------------------
------------------  2025-6-21  -  Jun 21 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ALSA: hda/realtek: Fix built-in mic on ASUS VivoBook X513EA
    (git-fixes).
  - commit 0071891
  - ALSA: hda: Apply volume control on speaker+lineout for HP
    EliteStudio AIO (stable-fixes).
  - commit ba1a979
  - ALSA: hda/realtek - Support mute led function for HP platform
    (stable-fixes).
  - commit 74fc8d1
  - gpio: mlxbf3: only get IRQ for device instance 0 (git-fixes).
  - gpio: pca953x: fix wrong error probe return value (git-fixes).
  - drm/xe: Fix memset on iomem (git-fixes).
  - drm/etnaviv: Protect the scheduler's pending list with its lock
    (git-fixes).
  - drm/nouveau/bl: increase buffer size to avoid truncate warning
    (git-fixes).
  - drm/ssd130x: fix ssd132x_clear_screen() columns (git-fixes).
  - drm/amdgpu: switch job hw_fence to amdgpu_fence (git-fixes).
  - drm/i915/pmu: Fix build error with GCOV and AutoFDO enabled
    (git-fixes).
  - drm/msm/a7xx: Call CP_RESET_CONTEXT_STATE (git-fixes).
  - drm/msm: Fix CP_RESET_CONTEXT_STATE bitfield names (git-fixes).
  - drm/msm/dsi/dsi_phy_10nm: Fix missing initial VCO rate
    (git-fixes).
  - drm/msm/disp: Correct porch timing for SDM845 (git-fixes).
  - ALSA: hda/realtek: Add support for Acer Helios Laptops using
    CS35L41 HDA (stable-fixes).
  - commit 26d96c5

++++ kernel-firmware-amdgpu:

  - Update to version 20250620 (git commit 49c833a10ad9):
    * amdgpu: update renoir firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update sdma 7.0.1 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: add raven2 ip discovery firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update sdma 7.0.0 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: add picasso ip discovery firmware
    * amdgpu: add raven ip discovery firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update smu 13.0.7 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update gc 10.3.6 firmware
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update navi10 firmware
    * amdgpu: add smu 13.0.0 kicker firmware
    * amdgpu: add psp 13.0.0 kicker firmware
    * amdgpu: add gc 11.0.0 kicker firmware
    * amdgpu: add vcn 5.0.1 firmware
    * amdgpu: add sdma 4.4.4 firmware
    * amdgpu: add psp 13.0.12 firmware
    * amdgpu: add gc 9.5.0 firmware
    * amdgpu: add arcturus IP discovery firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update beige_goby firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update dimgrey_cavefish firmware
    * amdgpu: update aldebaran firmware

++++ kernel-firmware-iwlwifi:

  - Update aliases

++++ kernel-firmware-mediatek:

  - Update aliases

++++ kernel-firmware-network:

  - Update aliases

++++ kernel-firmware-platform:

  - Update aliases

++++ kernel-firmware-realtek:

  - Update aliases

++++ kernel-firmware-sound:

  - Update aliases

++++ kernel-rt:

  - ALSA: hda/realtek: Fix built-in mic on ASUS VivoBook X513EA
    (git-fixes).
  - commit 0071891
  - ALSA: hda: Apply volume control on speaker+lineout for HP
    EliteStudio AIO (stable-fixes).
  - commit ba1a979
  - ALSA: hda/realtek - Support mute led function for HP platform
    (stable-fixes).
  - commit 74fc8d1
  - gpio: mlxbf3: only get IRQ for device instance 0 (git-fixes).
  - gpio: pca953x: fix wrong error probe return value (git-fixes).
  - drm/xe: Fix memset on iomem (git-fixes).
  - drm/etnaviv: Protect the scheduler's pending list with its lock
    (git-fixes).
  - drm/nouveau/bl: increase buffer size to avoid truncate warning
    (git-fixes).
  - drm/ssd130x: fix ssd132x_clear_screen() columns (git-fixes).
  - drm/amdgpu: switch job hw_fence to amdgpu_fence (git-fixes).
  - drm/i915/pmu: Fix build error with GCOV and AutoFDO enabled
    (git-fixes).
  - drm/msm/a7xx: Call CP_RESET_CONTEXT_STATE (git-fixes).
  - drm/msm: Fix CP_RESET_CONTEXT_STATE bitfield names (git-fixes).
  - drm/msm/dsi/dsi_phy_10nm: Fix missing initial VCO rate
    (git-fixes).
  - drm/msm/disp: Correct porch timing for SDM845 (git-fixes).
  - ALSA: hda/realtek: Add support for Acer Helios Laptops using
    CS35L41 HDA (stable-fixes).
  - commit 26d96c5

++++ python313-core:

  - adjusted sofilename for "nogil" build correctly.

++++ python313:

  - adjusted sofilename for "nogil" build correctly.

------------------------------------------------------------------
------------------  2025-6-20  -  Jun 20 2025  -------------------
------------------------------------------------------------------

++++ transactional-update:

  - Add correct SELinux policy version dependency for SLE 16

++++ fwupd:

  - Update to version 2.0.12:
    + This release adds the following features:
  - Add a config option for enforcing immutable device enumeration
  - Add device emulation support for Thunderbolt host controllers
  - Do the efivarfs free space checks for dbx, db, KEK and PK devices
  - Ensure the i2c_dev kernel driver is always loaded if a module
  - Parse the SBOM data from fwupdx64.efi if provided
  - Support loading multiple coSWID blobs from PE files
    + This release fixes the following bugs:
  - Added HP Elitedesk G6 mini to not get dbx-updates
  - Add two more uefi dbx checksum->version entries
  - Be more useful when building modem device Instance IDs
  - Convert asus-hid and legion-hid2 to hidraw to avoid possible input blips
  - Do not create radio for Logitech RDFU-capable devices
  - Fix a modem-manager regression where a PCI device had no vendor ID
  - Fix a regression when updating DFOTA modem devices
  - Fix self tests when building with -Defi_os_dir
  - Fix self tests when the builder does not support DistroVersion
  - Fix updating Thunderbolt host controllers with some version formats
  - Handle HECI unsupported status (0x0b) for Dell hardware
  - Make tar a dependency of the uefi-capsule tests
  - Mark the KEK and db updates as affecting FDE like BitLocker
  - Properly detect the Redfish reboot request for Dell servers
  - Send the proper artifact firmware filename to the Redfish BMC
  - Set the correct RMM device version for some Dell dock devices
  - Use inhibits so that the rts54hub device is marked as non-updatable
  - Use the virtual size to avoid padding when cutting PE sections
  - Wait for the Logitech Scribe device to replug after updating
    + This release adds support for the following hardware:
  - HP Portable USB-C Hub
  - More Foxconn 5G modem products
  - More Intel Arc Battlemage products

++++ kernel-default:

  - libnvdimm/labels: Fix divide error in nd_label_data_init()
    (bsc#1244743, CVE-2025-38072).
  - commit 100db61
  - mm/hugetlb: fix kernel NULL pointer dereference when replacing
    free hugetlb folios (CVE-2025-38050 bsc#1244751).
  - commit 805754b
  - config: enable rbd and libceph (jsc#PED-13108)
  - commit 793f4d9
  - s390/purgatory: Use -D__DISABLE_EXPORTS (bsc#1245126).
  - commit 490ac3b
  - wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850
    (git-fixes).
  - commit 6b57cd2
  - wifi: carl9170: do not ping device which has failed to load
    firmware (git-fixes).
  - NFC: nci: uart: Set tty->disc_data only in success path
    (git-fixes).
  - can: tcan4x5x: fix power regulator retrieval during probe
    (git-fixes).
  - hwmon: (ltc4282) avoid repeated register write (git-fixes).
  - hwmon: (occ) fix unaligned accesses (git-fixes).
  - hwmon: (occ) Rework attribute registration for stack usage
    (git-fixes).
  - hwmon: (ftsteutates) Fix TOCTOU race in fts_read() (git-fixes).
  - wifi: ath11k: move some firmware stats related functions
    outside of debugfs (git-fixes).
  - wifi: ath11k: don't wait when there is no vdev started
    (git-fixes).
  - wifi: ath11k: don't use static variables in
    ath11k_debugfs_fw_stats_process() (git-fixes).
  - wifi: ath11k: avoid burning CPU in
    ath11k_debugfs_fw_stats_request() (git-fixes).
  - net: wwan: mhi_wwan_mbim: use correct mux_id for multiplexing
    (git-fixes).
  - pinctrl: samsung: add gs101 specific eint suspend/resume
    callbacks (git-fixes).
  - pinctrl: samsung: add dedicated SoC eint suspend/resume
    callbacks (stable-fixes).
  - pinctrl: samsung: refactor drvdata suspend & resume callbacks
    (stable-fixes).
  - Bluetooth: ISO: Fix not using SID from adv report
    (stable-fixes).
  - wifi: ath12k: refactor ath12k_hw_regs structure (stable-fixes).
  - firmware: SDEI: Allow sdei initialization without ACPI_APEI_GHES
    (git-fixes).
  - thermal/drivers/mediatek/lvts: Remove unused lvts_debugfs_exit
    (git-fixes).
  - Bluetooth: MGMT: Remove unused mgmt_pending_find_data
    (stable-fixes).
  - wifi: ath11k: convert timeouts to secs_to_jiffies()
    (stable-fixes).
  - commit 9415389
  - workqueue: Initialize wq_isolated_cpumask in
    workqueue_init_early() (bsc#1245101).
  - commit 6bd2836
  - Revert "rpm/config.sh: Use suse-kabi-tools (jsc#PED-12618)"
    This breaking build on s390x and blocking upcoming submissions:
    Failed to read symtypes from '.': arch/s390/lib/string.symtypes:3:
    Export 'strlen' is duplicate, previous occurrence found in
    'arch/s390/purgatory/string.symtypes'
    This reverts commit a0854fc92f0d8c56e48e96980cea7efe15509265.
  - commit 672894a
  - calipso: Fix null-ptr-deref in calipso_req_{set,del}attr()
    (git-fixes).
  - commit 666ce5b
  - net/sched: fix use-after-free in taprio_dev_notifier
    (git-fixes).
  - commit bd3ade1
  - net_sched: ets: fix a race in ets_qdisc_change() (git-fixes).
  - commit 035ae9a
  - net_sched: tbf: fix a race in tbf_change() (git-fixes).
  - commit 4131c83
  - net_sched: red: fix a race in __red_change() (git-fixes).
  - commit f0af35e
  - net_sched: prio: fix a race in prio_tune() (git-fixes).
  - commit 13ce5f2
  - net_sched: sch_sfq: reject invalid perturb period (git-fixes).
  - commit dc06830
  - net: Fix TOCTOU issue in sk_is_readable() (git-fixes).
  - commit 9d72614
  - KEYS: trusted: don't fail module __init if SHA1 is unavailable
    (bsc#1240423 jsc#PED-12225).
  - commit 93f363a
  - pidfs: lookup pid through rbtree (jsc#PED-13113).
  - commit eead84f

++++ kernel-firmware-amdgpu:

  - Update to version 20250619 (git commit dcd2ee2f57a7):
    * amdgpu: update dmcub fw for dcn32 and dcn401

++++ kernel-firmware-mediatek:

  - Update to version 20250619 (git commit dcd2ee2f57a7):
    * mediatek: Update mt8186 SCP firmware

++++ kernel-rt:

  - libnvdimm/labels: Fix divide error in nd_label_data_init()
    (bsc#1244743, CVE-2025-38072).
  - commit 100db61
  - mm/hugetlb: fix kernel NULL pointer dereference when replacing
    free hugetlb folios (CVE-2025-38050 bsc#1244751).
  - commit 805754b
  - config: enable rbd and libceph (jsc#PED-13108)
  - commit 793f4d9
  - s390/purgatory: Use -D__DISABLE_EXPORTS (bsc#1245126).
  - commit 490ac3b
  - wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850
    (git-fixes).
  - commit 6b57cd2
  - wifi: carl9170: do not ping device which has failed to load
    firmware (git-fixes).
  - NFC: nci: uart: Set tty->disc_data only in success path
    (git-fixes).
  - can: tcan4x5x: fix power regulator retrieval during probe
    (git-fixes).
  - hwmon: (ltc4282) avoid repeated register write (git-fixes).
  - hwmon: (occ) fix unaligned accesses (git-fixes).
  - hwmon: (occ) Rework attribute registration for stack usage
    (git-fixes).
  - hwmon: (ftsteutates) Fix TOCTOU race in fts_read() (git-fixes).
  - wifi: ath11k: move some firmware stats related functions
    outside of debugfs (git-fixes).
  - wifi: ath11k: don't wait when there is no vdev started
    (git-fixes).
  - wifi: ath11k: don't use static variables in
    ath11k_debugfs_fw_stats_process() (git-fixes).
  - wifi: ath11k: avoid burning CPU in
    ath11k_debugfs_fw_stats_request() (git-fixes).
  - net: wwan: mhi_wwan_mbim: use correct mux_id for multiplexing
    (git-fixes).
  - pinctrl: samsung: add gs101 specific eint suspend/resume
    callbacks (git-fixes).
  - pinctrl: samsung: add dedicated SoC eint suspend/resume
    callbacks (stable-fixes).
  - pinctrl: samsung: refactor drvdata suspend & resume callbacks
    (stable-fixes).
  - Bluetooth: ISO: Fix not using SID from adv report
    (stable-fixes).
  - wifi: ath12k: refactor ath12k_hw_regs structure (stable-fixes).
  - firmware: SDEI: Allow sdei initialization without ACPI_APEI_GHES
    (git-fixes).
  - thermal/drivers/mediatek/lvts: Remove unused lvts_debugfs_exit
    (git-fixes).
  - Bluetooth: MGMT: Remove unused mgmt_pending_find_data
    (stable-fixes).
  - wifi: ath11k: convert timeouts to secs_to_jiffies()
    (stable-fixes).
  - commit 9415389
  - workqueue: Initialize wq_isolated_cpumask in
    workqueue_init_early() (bsc#1245101).
  - commit 6bd2836
  - Revert "rpm/config.sh: Use suse-kabi-tools (jsc#PED-12618)"
    This breaking build on s390x and blocking upcoming submissions:
    Failed to read symtypes from '.': arch/s390/lib/string.symtypes:3:
    Export 'strlen' is duplicate, previous occurrence found in
    'arch/s390/purgatory/string.symtypes'
    This reverts commit a0854fc92f0d8c56e48e96980cea7efe15509265.
  - commit 672894a
  - calipso: Fix null-ptr-deref in calipso_req_{set,del}attr()
    (git-fixes).
  - commit 666ce5b
  - net/sched: fix use-after-free in taprio_dev_notifier
    (git-fixes).
  - commit bd3ade1
  - net_sched: ets: fix a race in ets_qdisc_change() (git-fixes).
  - commit 035ae9a
  - net_sched: tbf: fix a race in tbf_change() (git-fixes).
  - commit 4131c83
  - net_sched: red: fix a race in __red_change() (git-fixes).
  - commit f0af35e
  - net_sched: prio: fix a race in prio_tune() (git-fixes).
  - commit 13ce5f2
  - net_sched: sch_sfq: reject invalid perturb period (git-fixes).
  - commit dc06830
  - net: Fix TOCTOU issue in sk_is_readable() (git-fixes).
  - commit 9d72614
  - KEYS: trusted: don't fail module __init if SHA1 is unavailable
    (bsc#1240423 jsc#PED-12225).
  - commit 93f363a
  - pidfs: lookup pid through rbtree (jsc#PED-13113).
  - commit eead84f

++++ open-vm-tools:

  - Update to open-vm-tools 13.0.0 based on build 24696409. (boo#1245169):
    There are no new features in the open-vm-tools 13.0.0 release.  This is
    primarily a maintenance release that addresses a few issues, including:
  - The vm-support script has been updated to collect the open-vm-tools log
    files from the Linux guest and information from the systemd journal.
  - Github pull requests has been integrated and issues fixed.  Please see
    the Resolved Issues section of the Release Notes.
    For a more complete list of issues resolved in this release, see the
    Resolved Issues section of the Release Notes.
    For complete details, see:
    https://github.com/vmware/open-vm-tools/releases/tag/stable-13.0.0
    Release Notes are available at:
    https://github.com/vmware/open-vm-tools/blob/stable-13.0.0/ReleaseNotes.md
    The granular changes that have gone into the 13.0.0 release are in the
    ChangeLog at:
    https://github.com/vmware/open-vm-tools/blob/stable-13.0.0/open-vm-tools/ChangeLog
  - Add patch:
    0001-GOSC-Update-Guest-OS-Customization-to-utilize-system.patch
    Currently the "telinit 6" command is used to reboot a Linux VM
    following Guest OS Customization.  As the classic Linux init system,
    SysVinit, is deprecated in favor of a newer init system, systemd,
    the telinit command may not be available on the base Linux OS.
    This change adds support to Guest OS Customization for the systemd init
    system.  If the modern init system, systemd, is available, then a
    "systemctl reboot" command will be used to trigger reboot.  Otherwise,
    the "telinit 6" command will be used assuming the traditional init
    system, SysVinit, is still available.
  - Drop patch now contained in 13.0.0:
    open-vm-tools-12.5.0-gcc15.patch
  - Ran /usr/lib/obs/service/source_validators/helpers/fix_changelog to fix changes
    file where source validator was failing.

++++ qemu:

  - Add Live migration support for QEMU-emulated AMD IOMMU (jsc#PED-13144):
    * hw/i386/amd_iommu: Allow migration when explicitly create the AMDVI-PCI device (jsc#PED-PED-13144)
    * hw/i386/amd_iommu: Isolate AMDVI-PCI from amd-iommu device to allow full control over the PCI device creation (jsc#PED-13144)

++++ ovmf:

  - Enable TDVF firmware to boot TDX guest VM with Secure boot (jsc#PED-13070)
  - Add ovmf-x86_64-tdx-secureboot.bin
  - Add 60-ovmf-x86_64-tdx.json

------------------------------------------------------------------
------------------  2025-6-19  -  Jun 19 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Add kdump-nfs-fixes.patch to fix bsc#1241949

++++ kernel-default:

  - Update patches.suse/dlm-mask-sk_shutdown-value.patch
    (bsc#1241278).
  - Update patches.suse/dlm-use-SHUT_RDWR-for-SCTP-shutdown.patch
    (bsc#1241278).
    Original bsc number was wrong. Fix it.
  - commit 4a3a0a7
  - selftests/ftrace: Use readelf to find entry point in uprobe test
    (bsc#1242836).
  - commit c5198f9
  - selftests/ftrace: Make uprobe test more robust against binary
    name (bsc#1242836).
  - commit 97eea6a

++++ kernel-rt:

  - Update patches.suse/dlm-mask-sk_shutdown-value.patch
    (bsc#1241278).
  - Update patches.suse/dlm-use-SHUT_RDWR-for-SCTP-shutdown.patch
    (bsc#1241278).
    Original bsc number was wrong. Fix it.
  - commit 4a3a0a7
  - selftests/ftrace: Use readelf to find entry point in uprobe test
    (bsc#1242836).
  - commit c5198f9
  - selftests/ftrace: Make uprobe test more robust against binary
    name (bsc#1242836).
  - commit 97eea6a

++++ systemd:

  - Import commit 1e42ecf5a145589954df77da05937ee69619f3e5
    1e42ecf5a1 firstboot: make sure labelling is enabled
    3bdb2efbe0 tmpfiles: fix symlink creation when replacing
    61c228d2cc firstboot: use WRITE_STRING_FILE_LABEL more
    f5148acf37 env-file: port write_env_file() to label_ops_pre()
    bbff8b5523 fs-util: replace symlink_atomic_full_label() by a flag to symlinkat_atomic_full() (bsc#1244237)
    2b39393efa env-file: rework write_env_file() to make use of O_TMPFILE

------------------------------------------------------------------
------------------  2025-6-18  -  Jun 18 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to docker-buildx v0.25.0. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.25.0>

++++ python-kiwi:

  - There is no shim for aarch64 on SUSE
    Fix integration test for standard EFI (no secure boot)
    setup on arm

++++ kernel-default:

  - rpm/config.sh: Use suse-kabi-tools (jsc#PED-12618)
    Fix for bsc#1245126 was merged.
  - rpm/config.sh: Use suse-kabi-tools (jsc#PED-12618)
  - commit 90af69e
  - net_sched: hfsc: Address reentrant enqueue adding class to
    eltree twice (CVE-2025-38001 bsc#1244234).
  - commit 031f2d0
  - block: flip iter directions in blk_rq_integrity_map_user()
    (git-fixes).
  - loop: add file_start_write() and file_end_write() (git-fixes).
  - brd: fix discard end sector (git-fixes).
  - brd: fix aligned_sector from brd_do_discard() (git-fixes).
  - block: only update request sector if needed (git-fixes).
  - block: fix race between set_blocksize and read paths
    (git-fixes).
  - badblocks: Fix a nonsense WARN_ON() which checks whether a
    u64 variable < 0 (git-fixes).
  - blk-throttle: don't take carryover for prioritized processing
    of metadata (git-fixes).
  - ublk: enforce ublks_max only for unprivileged devices
    (git-fixes).
  - block: mark bounce buffering as incompatible with integrity
    (git-fixes).
  - ublk: complete command synchronously on error (git-fixes).
  - loop: check in LO_FLAGS_DIRECT_IO in loop_default_blocksize
    (git-fixes).
  - commit 9c6fb7f
  - packaging: Add support for suse-kabi-tools
    The current workflow to check kABI stability during the RPM build of SUSE
    kernels consists of the following steps:
    * The downstream script rpm/modversions unpacks the consolidated kABI
    symtypes reference data from kabi/<arch>/symtypes-<flavor> and creates
    individual symref files.
    * The build performs a regular kernel make. During this operation, genksyms
    is invoked for each source file. The tool determines type signatures of
    all exports within the file, reports any differences compared to the
    associated symref reference, calculates symbol CRCs from the signatures
    and writes new type data into a symtypes file.
    * The script rpm/modversions is invoked again, this time it packs all new
    symtypes files to a consolidated kABI file.
    * The downstream script rpm/kabi.pl checks symbol CRCs in the new build and
    compares them to a reference from kabi/<arch>/symvers-<flavor>, taking
    kabi/severities into account.
    suse-kabi-tools is a new set of tools to improve the kABI checking process.
    The suite includes two tools, ksymtypes and ksymvers, which replace the
    existing scripts rpm/modversions and rpm/kabi.pl, as well as the comparison
    functionality previously provided by genksyms. The tools have their own
    source repository and package.
    The tools provide faster operation and more detailed, unified output. In
    addition, they allow the use of the new upstream tool gendwarfksyms, which
    lacks any built-in comparison functionality.
    The updated workflow is as follows:
    * The build performs a regular kernel make. During this operation, genksyms
    (gendwarfksyms) is invoked as usual, determinining signatures and CRCs of
    all exports and writing the type data to symtypes files. However,
    genksyms no longer performs any comparison.
    * 'ksymtypes consolidate' packs all new symtypes files to a consolidated
    kABI file.
    * 'ksymvers compare' checks symbol CRCs in the new build and compares them
    to a reference from kabi/<arch>/symvers-<flavor>, taking kabi/severities
    into account. The tool writes its result in a human-readable form on
    standard output and also writes a list of all changed exports (not
    ignored by kabi/severities) to the changed-exports file.
    * 'ksymtypes compare' takes the changed-exports file, the consolidated kABI
    symtypes reference data from kabi/<arch>/symtypes-<flavor> and the new
    consolidated data. Based on this data, it produces a detailed report
    explaining why the symbols changed.
    The patch enables the use of suse-kabi-tools via rpm/config.sh, providing
    explicit control to each branch. To enable the support, set
    USE_SUSE_KABI_TOOLS=Yes in the config file.
  - commit a2c6f89
  - platform/x86: dell_rbu: Stop overwriting data buffer
    (git-fixes).
  - platform/x86: dell_rbu: Fix list usage (git-fixes).
  - platform/x86/amd: pmf: Prevent amd_pmf_tee_deinit() from
    running twice (git-fixes).
  - platform/x86/amd: pmf: Use device managed allocations
    (git-fixes).
  - platform/x86/amd: pmc: Clear metrics table at start of cycle
    (git-fixes).
  - platform/x86/intel-uncore-freq: Fail module load when plat_info
    is NULL (git-fixes).
  - platform/x86: ideapad-laptop: use usleep_range() for EC polling
    (git-fixes).
  - commit 89154c9

++++ kernel-rt:

  - rpm/config.sh: Use suse-kabi-tools (jsc#PED-12618)
    Fix for bsc#1245126 was merged.
  - rpm/config.sh: Use suse-kabi-tools (jsc#PED-12618)
  - commit 90af69e
  - net_sched: hfsc: Address reentrant enqueue adding class to
    eltree twice (CVE-2025-38001 bsc#1244234).
  - commit 031f2d0
  - block: flip iter directions in blk_rq_integrity_map_user()
    (git-fixes).
  - loop: add file_start_write() and file_end_write() (git-fixes).
  - brd: fix discard end sector (git-fixes).
  - brd: fix aligned_sector from brd_do_discard() (git-fixes).
  - block: only update request sector if needed (git-fixes).
  - block: fix race between set_blocksize and read paths
    (git-fixes).
  - badblocks: Fix a nonsense WARN_ON() which checks whether a
    u64 variable < 0 (git-fixes).
  - blk-throttle: don't take carryover for prioritized processing
    of metadata (git-fixes).
  - ublk: enforce ublks_max only for unprivileged devices
    (git-fixes).
  - block: mark bounce buffering as incompatible with integrity
    (git-fixes).
  - ublk: complete command synchronously on error (git-fixes).
  - loop: check in LO_FLAGS_DIRECT_IO in loop_default_blocksize
    (git-fixes).
  - commit 9c6fb7f
  - packaging: Add support for suse-kabi-tools
    The current workflow to check kABI stability during the RPM build of SUSE
    kernels consists of the following steps:
    * The downstream script rpm/modversions unpacks the consolidated kABI
    symtypes reference data from kabi/<arch>/symtypes-<flavor> and creates
    individual symref files.
    * The build performs a regular kernel make. During this operation, genksyms
    is invoked for each source file. The tool determines type signatures of
    all exports within the file, reports any differences compared to the
    associated symref reference, calculates symbol CRCs from the signatures
    and writes new type data into a symtypes file.
    * The script rpm/modversions is invoked again, this time it packs all new
    symtypes files to a consolidated kABI file.
    * The downstream script rpm/kabi.pl checks symbol CRCs in the new build and
    compares them to a reference from kabi/<arch>/symvers-<flavor>, taking
    kabi/severities into account.
    suse-kabi-tools is a new set of tools to improve the kABI checking process.
    The suite includes two tools, ksymtypes and ksymvers, which replace the
    existing scripts rpm/modversions and rpm/kabi.pl, as well as the comparison
    functionality previously provided by genksyms. The tools have their own
    source repository and package.
    The tools provide faster operation and more detailed, unified output. In
    addition, they allow the use of the new upstream tool gendwarfksyms, which
    lacks any built-in comparison functionality.
    The updated workflow is as follows:
    * The build performs a regular kernel make. During this operation, genksyms
    (gendwarfksyms) is invoked as usual, determinining signatures and CRCs of
    all exports and writing the type data to symtypes files. However,
    genksyms no longer performs any comparison.
    * 'ksymtypes consolidate' packs all new symtypes files to a consolidated
    kABI file.
    * 'ksymvers compare' checks symbol CRCs in the new build and compares them
    to a reference from kabi/<arch>/symvers-<flavor>, taking kabi/severities
    into account. The tool writes its result in a human-readable form on
    standard output and also writes a list of all changed exports (not
    ignored by kabi/severities) to the changed-exports file.
    * 'ksymtypes compare' takes the changed-exports file, the consolidated kABI
    symtypes reference data from kabi/<arch>/symtypes-<flavor> and the new
    consolidated data. Based on this data, it produces a detailed report
    explaining why the symbols changed.
    The patch enables the use of suse-kabi-tools via rpm/config.sh, providing
    explicit control to each branch. To enable the support, set
    USE_SUSE_KABI_TOOLS=Yes in the config file.
  - commit a2c6f89
  - platform/x86: dell_rbu: Stop overwriting data buffer
    (git-fixes).
  - platform/x86: dell_rbu: Fix list usage (git-fixes).
  - platform/x86/amd: pmf: Prevent amd_pmf_tee_deinit() from
    running twice (git-fixes).
  - platform/x86/amd: pmf: Use device managed allocations
    (git-fixes).
  - platform/x86/amd: pmc: Clear metrics table at start of cycle
    (git-fixes).
  - platform/x86/intel-uncore-freq: Fail module load when plat_info
    is NULL (git-fixes).
  - platform/x86: ideapad-laptop: use usleep_range() for EC polling
    (git-fixes).
  - commit 89154c9

++++ ceph:

  - Added cephadm-fix-get_cluster_count_when_data_dir_is_missing.patch
  - Add ceph-rocksdb-gcc15.patch

++++ libsoup:

  - Add libsoup-CVE-2025-4945.patch: add value checks for date/time
    parsing (boo#1243314 CVE-2025-4945).

++++ libzypp:

  - Enhancements regarding mirror handling during repo refresh.
    Added  means to disable the use of mirrors when downloading
    security relevant files. Requires updaing zypper to 1.14.91.
  - Fix autotestcase writer if ZYPP_FULLLOG=1 (bsc#1244042)
    If ZYPP_FULLLOG=1 a solver testcase to
    "/var/log/YaST2/autoTestcase" should be written for each solver
    run. There was no testcase written for the very first solver run.
    This is now fixed.
  - Pass $1==2 to %posttrans script if it's an update (bsc#1243279)
  - version 17.37.6 (35)

++++ pam:

  - hardcode disabling elogind, meson detection is unreliable in OBS
  - Update to version 1.7.1
  - pam_access: do not resolve ttys or display variables as hostnames.
  - pam_access: added "nodns" option to disallow resolving of tokens
    as hostnames (CVE-2024-10963).
  - pam_limits: added support for rttime (RLIMIT_RTTIME).
  - pam_namespace: fixed potential privilege escalation (CVE-2025-6020).
  - meson: added support of elogind as a logind provider.
  - Multiple minor bug fixes, build fixes, portability fixes,
    documentation improvements, and translation updates.
  - pam_access-rework-resolving-of-tokens-as-hostname.patch got obsoleted

++++ pam-config:

  - Update to version 2.12+git.20250516:
    * Don't add pam_env twice

++++ pam-full-src:

  - hardcode disabling elogind, meson detection is unreliable in OBS
  - Update to version 1.7.1
  - pam_access: do not resolve ttys or display variables as hostnames.
  - pam_access: added "nodns" option to disallow resolving of tokens
    as hostnames (CVE-2024-10963).
  - pam_limits: added support for rttime (RLIMIT_RTTIME).
  - pam_namespace: fixed potential privilege escalation (CVE-2025-6020).
  - meson: added support of elogind as a logind provider.
  - Multiple minor bug fixes, build fixes, portability fixes,
    documentation improvements, and translation updates.
  - pam_access-rework-resolving-of-tokens-as-hostname.patch got obsoleted

++++ virt-manager:

  - bsc#1244685 - Could not find an installable distribution with
    virt-install command
    virtinst-add-sle16-detection-support.patch

++++ zypper:

  - BuildRequires:  libzypp-devel >= 17.37.6.
    Enhancements regarding mirror handling during repo refresh. Adapt
    to libzypp API changes. (bsc#1230267)
  - version 1.14.91

------------------------------------------------------------------
------------------  2025-6-17  -  Jun 17 2025  -------------------
------------------------------------------------------------------

++++ afterburn:

  - Fix Requires in noarch package to not be arch specific (bsc#1244675)

++++ drbd-utils:

  - merge upstream patch to fix build error
    * add patch
    + DRBDmon-Add-missing-default_types.h-include-in-strin.patch
  - Fix SELinux equivalency rules in module (bsc#1242915)
    * add patch
    + 0001-Fix-selinux-policy-for-usr-bin-equivalency-rules.patch
    + 0002-Fix-selinux-module-for-run-lock-equivalency-rules.patch
    + 0003-Fix-selinux-module-for-run-equivalency-rules.patch

++++ git:

  - update to 2.50.0
    https://about.gitlab.com/blog/what-s-new-in-git-2-50-0/
    https://raw.githubusercontent.com/git/git/refs/tags/v2.50.0/Documentation/RelNotes/2.50.0.adoc

++++ glibc:

  - ppc64le-revert-power10-strcmp.patch: Revert optimized POWER10 strcmp,
    strncmp implementations (CVE-2025-5745, CVE-2025-5702, bsc#1244184,
    bsc#1244182, BZ #33060, BZ #33056)
  - ppc64le-revert-power10-memcmp.patch: Revert optimized POWER10 memcmp
    implementation (BZ #33059)

++++ gpg2:

  - Don't install expired sks certificate [bsc#1243069]
    * Add patch gnupg-dirmngr-Don-t-install-expired-sks-certificate.patch

++++ kernel-default:

  - loop: factor out a loop_assign_backing_file helper (git-fixes).
  - Refresh
    patches.suse/loop-Add-sanity-check-for-read-write_iter.patch.
  - commit 6b2b09e
  - platform/x86/amd/hsmp: mark hsmp_msg_desc_table as maybe_unused (git-fixes).
  - commit a5ad60f
  - iommu: Clear iommu-dma ops on cleanup (CVE-2025-37877
    bsc#1243058).
  - commit 5ecb9e1
  - kernel-source: Remove log.sh from sources
  - commit 96bd779
  - powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO
    EEH recovery (bsc#1215199).
  - commit e772925

++++ kernel-firmware-amdgpu:

  - Update to version 20250616 (git commit 1d98972a5635):
    * amdgpu: Update DMCUB fw for DCN401 & DCN315

++++ kernel-firmware-qcom:

  - Update to version 20250616 (git commit 1d98972a5635):
    * qcom: add gpu firmwares for X1P42100 chipset

++++ kernel-rt:

  - loop: factor out a loop_assign_backing_file helper (git-fixes).
  - Refresh
    patches.suse/loop-Add-sanity-check-for-read-write_iter.patch.
  - commit 6b2b09e
  - platform/x86/amd/hsmp: mark hsmp_msg_desc_table as maybe_unused (git-fixes).
  - commit a5ad60f
  - iommu: Clear iommu-dma ops on cleanup (CVE-2025-37877
    bsc#1243058).
  - commit 5ecb9e1
  - kernel-source: Remove log.sh from sources
  - commit 96bd779
  - powerpc/eeh: Fix missing PE bridge reconfiguration during VFIO
    EEH recovery (bsc#1215199).
  - commit e772925

++++ vim:

  - Fix bsc#1228776 / CVE-2024-41965.
  - Fix bsc#1239602 / CVE-2025-29768.
  - Refresh patch:
    vim-7.3-sh_is_bash.patch
  - Update to 9.1.1406:
    9.1.1406: crash when importing invalid tuple
    9.1.1405: tests: no test for mapping with special keys in session file
    9.1.1404: wrong link to Chapter 2 in new-tutor
    9.1.1403: expansion of 'tabpanelopt' value adds wrong values
    9.1.1402: multi-byte mappings not properly stored in session file
    9.1.1401: list not materialized in prop_list()
    9.1.1400: [security]: use-after-free when evaluating tuple fails
    9.1.1399: tests: test_codestyle fails for auto-generated files
    9.1.1398: completion: trunc does not follow Pmenu highlighting attributes
    9.1.1397: tabpanel not correctly updated on :tabonly
    9.1.1396: 'errorformat' is a global option
    9.1.1395: search_stat not reset when pattern differs in case
    9.1.1394: tabpanel not correctly redrawn on tabonly
    9.1.1393: missing test for switching buffers and reusing curbuf
    9.1.1392: missing patch number
    9.1.1391: Vim does not have a vertical tabpanel
    9.1.1390: style: more wrong indentation
    9.1.1389: completion: still some issue when 'isexpand' contains a space
    9.1.1388: Scrolling one line too far with 'nosmoothscroll' page scrolling
    9.1.1387: memory leak when buflist_new() fails to reuse curbuf
    9.1.1386: MS-Windows: some minor problems building on AARCH64
    9.1.1385: inefficient loop for 'nosmoothscroll' scrolling
    9.1.1384: still some problem with the new tutors filetype plugin
    9.1.1383: completion: 'isexpand' option does not handle space char correct
    9.1.1382: if_ruby: unused compiler warnings from ruby internals
    9.1.1381: completion: cannot return to original text
    9.1.1380: 'eventignorewin' only checked for current buffer
    9.1.1379: MS-Windows: error when running evim when space in path
    9.1.1378: sign without text overwrites number option
    9.1.1377: patch v9.1.1370 causes some GTK warning messages
    9.1.1376: quickfix dummy buffer may remain as dummy buffer
    9.1.1375: [security]: possible heap UAF with quickfix dummy buffer
    9.1.1374: completion: 'smartcase' not respected when filtering matches
    9.1.1373: 'completeopt' checking logic can be simplified
    9.1.1372: style: braces issues in various files
    9.1.1371: style: indentation and brace issues in insexpand.c
    9.1.1370: CI Tests favor GTK2 over GTK3
    9.1.1369: configure still using autoconf 2.71
    9.1.1368: GTK3 and GTK4 will drop numeric cursor support.
    9.1.1367: too many strlen() calls in gui.c
    9.1.1366: v9.1.1364 unintentionally changed sign.c and sound.c
    9.1.1365: MS-Windows: compile warnings and too many strlen() calls
    9.1.1364: style: more indentation issues
    9.1.1363: style: inconsistent indentation in various files
    9.1.1362: Vim9: type ignored when adding tuple to instance list var
    9.1.1361: [security]: possible use-after-free when closing a buffer
    9.1.1360: filetype: GNU Radio companion files are not recognized
    9.1.1359: filetype: GNU Radio config files are not recognized
    9.1.1358: if_lua: compile warnings with gcc15
    9.1.1357: Vim incorrectly escapes tags with "[" in a help buffer
    9.1.1356: Vim9: crash when unletting variable
    9.1.1355: The pum_redraw() function is too complex
    9.1.1354: tests: Test_terminalwinscroll_topline() fails on Windows
    9.1.1353: missing change from v9.1.1350
    9.1.1352: style: inconsistent indent in insexpand.c
    9.1.1351: Return value of getcmdline() inconsistent in CmdlineLeavePre
    9.1.1350: tests: typo in Test_CmdlineLeavePre_cabbr()
    9.1.1349: CmdlineLeavePre may trigger twice
    9.1.1348: still E315 with the terminal feature
    9.1.1347: small problems with gui_w32.c
    9.1.1346: missing out-of-memory check in textformat.c
    9.1.1345: tests: Test_xxd_color2() test failure dump diff is misleading
    9.1.1344: double free in f_complete_match() (after v9.1.1341)
    9.1.1343: filetype: IPython files are not recognized
    9.1.1342: Shebang filetype detection can be improved
    9.1.1341: cannot define completion triggers
    9.1.1340: cannot complete :filetype arguments
    9.1.1339: missing out-of-memory checks for enc_to_utf16()/utf16_to_enc()
    9.1.1338: Calling expand() interferes with cmdcomplete_info()
    9.1.1337: Undo corrupted with 'completeopt' "preinsert" when switching buffer
    9.1.1336: comment plugin does not support case-insensitive 'commentstring'
    9.1.1335: Coverity complains about Null pointer dereferences
    9.1.1334: Coverity complains about unchecked return value
    9.1.1333: Coverity: complains about unutilized variable
    9.1.1332: Vim9: segfault when using super within a lambda
    9.1.1331: Leaking memory with cmdcomplete()

------------------------------------------------------------------
------------------  2025-6-16  -  Jun 16 2025  -------------------
------------------------------------------------------------------

++++ cifs-utils:

  - Update cifs-utils to 7.4
    * mount.cifs: retry mount on -EINPROGRESS
    * cifs.upcall: correctly treat UPTARGET_UNSPECIFIED as UPTARGET_APP
    * cifs.upcall: fix memory leaks in check_service_ticket_exits()
    * cifs-utils: bump version to 7.4
    * getcifsacl, setcifsacl: use <libgen.h> for basename
    * cifscreds: use <libgen.h> for basename

++++ cockpit:

  - Update to 340
    * Detect multiple mount points when creating btrfs subvolumes
    * Disk Self-Test error warnings on the overview page
    * Prevent modifying partitions in unsupported places
    * Bug fixes and translation updates

++++ cockpit-machines:

  - Update to 333
    * Bug fixes
    * The "shareable" attribute of disks is no longer modified by Cockpit
    * Virtual network interfaces can now select source mode

++++ cockpit-podman:

  - Update to 107
    * Bug fixes
    * Translation updates

++++ python-kiwi:

  - Add driver configuration support for dracut initrd
    Add driver configuration support for dracut initrd
    Add support for specifying kernel drivers to be included or omitted
    in the dracut initrd configuration. This extends the existing dracut
    configuration capabilities like in the following example
    <initrd action="add">
    <dracut driver="erofs"/>
    </initrd>

++++ kernel-default:

  - block/bdev: enable large folio support for large logical block
    sizes (git-fixes).
  - commit 03e169f
  - x86/amd_node: Add support for debugfs access to SMN registers (jsc#PED-13094).
  - commit 718f7f2
  - x86/amd_node: Add SMN offsets to exclusive region access (jsc#PED-13094).
  - commit 8b0488f
  - x86/amd_node: Use defines for SMN register offsets (jsc#PED-13094).
  - commit fdceb0c
  - ima: Suspend PCR extends and log appends when rebooting
    (bsc#1210025 ltc#196650).
  - Refresh patches.suse/0008-ima-track-the-set-of-PCRs-ever-extended.patch.
  - commit 87b6eff
  - wifi: ath12k: Prevent sending WMI commands to firmware during
    firmware crash (bsc#1240998).
  - wifi: ath12k: Resolve multicast packet drop by populating
    key_cipher in ath12k_install_key() (bsc#1240998).
  - commit 7530032
  - wifi: ath12k: ath12k_mac_op_set_key(): fix uninitialized symbol
    'ret' (bsc#1240998).
  - commit f7be9d8
  - wifi: ath12k: Fix for out-of bound access error (bsc#1240998
    CVE-2024-58015 bsc#1238995).
  - blacklist.conf:
  - commit 3c5bf1f
  - wifi: ath12k: fix key cache handling (bsc#1240998).
  - commit dcb3d62
  - wifi: ath12k: convert tasklet to BH workqueue for CE interrupts
    (bsc#1240998).
  - wifi: ath12k: fix A-MSDU indication in monitor mode
    (bsc#1240998).
  - wifi: ath12k: use tail MSDU to get MSDU information
    (bsc#1240998).
  - wifi: ath12k: delete NSS and TX power setting for monitor vdev
    (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_mpdu_start (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_phyrx_rssi_legacy_info
    (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_ppdu_start (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_ppdu_end_user_stats
    (bsc#1240998).
  - wifi: ath12k: remove unused variable monitor_present
    (bsc#1240998).
  - commit 8ed2a0a
  - wifi: ath12k: modify link arvif creation and removal for MLO
    (bsc#1240998).
  - Refresh
    patches.suse/wifi-ath12k-fix-read-pointer-after-free-in-ath12k_ma.patch.
  - commit 66e4cb1
  - wifi: ath12k: update ath12k_mac_op_update_vif_offload() for MLO
    (bsc#1240998).
  - wifi: ath12k: update ath12k_mac_op_conf_tx() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_mac_op_set_key() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_mac_op_bss_info_changed() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_get_arvif_iter() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_mac_vif_chan() for MLO
    (bsc#1240998).
  - wifi: ath12k: prepare vif config caching for MLO (bsc#1240998).
  - wifi: ath12k: prepare sta data structure for MLO handling
    (bsc#1240998).
  - wifi: ath12k: pass ath12k_link_vif instead of vif/ahvif
    (bsc#1240998).
  - commit e2a68c7
  - wifi: ath12k: prepare vif data structure for MLO handling
    (bsc#1240998).
  - Refresh
    patches.suse/wifi-ath12k-Handle-error-cases-during-extended-skb-a.patch.
  - Refresh
    patches.suse/wifi-ath12k-fix-tx-power-max-reg-power-update-to-fir.patch.
  - commit be086ca
  - wifi: ath12k: Add firmware coredump collection support
    (bsc#1240998).
  - Update config files.
  - commit 13fc60a
  - wifi: ath12k: Support BE OFDMA Pdev Rate Stats (bsc#1240998).
  - wifi: ath12k: Support Pdev Scheduled Algorithm Stats
    (bsc#1240998).
  - wifi: ath12k: Support DMAC Reset Stats (bsc#1240998).
  - wifi: ath12k: add missing lockdep_assert_wiphy() for
    ath12k_mac_op_ functions (bsc#1240998).
  - wifi: ath12k: ath12k_mac_op_sta_state(): clean up update_wk
    cancellation (bsc#1240998).
  - wifi: ath12k: ath12k_mac_set_key(): remove exit label
    (bsc#1240998).
  - commit 4d42f04
  - wifi: ath12k: switch to using wiphy_lock() and remove
    ar->conf_mutex (bsc#1240998).
  - Refresh
    patches.suse/wifi-ath12k-fix-node-corruption-in-ar-arvifs-list.patch.
  - Refresh
    patches.suse/wifi-ath12k-fix-read-pointer-after-free-in-ath12k_ma.patch.
  - commit 728526a
  - wifi: ath12k: convert struct ath12k_sta::update_wk to use
    struct wiphy_work (bsc#1240998).
  - commit 91ddf3a
  - wifi: ath12k: Support Pdev OBSS Stats (bsc#1240998).
  - wifi: ath12k: Support pdev CCA Stats (bsc#1240998).
  - wifi: ath12k: Support pdev Transmit Multi-user stats
    (bsc#1240998).
  - wifi: ath12k: Support Ring and SFM stats (bsc#1240998).
  - wifi: ath12k: Support Self-Generated Transmit stats
    (bsc#1240998).
  - wifi: ath12k: Modify print_array_to_buf() to support arrays
    with 1-based semantics (bsc#1240998).
  - wifi: ath12k: move txbaddr/rxbaddr into struct ath12k_dp
    (bsc#1240998).
  - wifi: ath12k: make read-only array svc_id static const
    (bsc#1240998).
  - commit 3509024
  - x86/bugs: Restructure ITS mitigation (git-fixes).
  - commit 085abef
  - x86/bugs: Fix spectre_v2 mitigation default on Intel (git-fixes).
  - commit f344e75
  - KVM: SVM: Set/clear SRSO's BP_SPEC_REDUCE on 0 <=> 1 VM count transitions (git-fixes).
  - commit b648f1d
  - platform/x86/amd/hsmp: fix building with CONFIG_HWMON=m (jsc#PED-13094).
  - commit dc03ed2
  - platform/x86/amd/hsmp: acpi: Add sysfs files to display HSMP telemetry (jsc#PED-13094).
  - commit d63496c
  - platform/x86/amd/hsmp: Report power via hwmon sensors (jsc#PED-13094).
  - commit 357c2f9
  - platform/x86/amd/hsmp: Use a single DRIVER_VERSION for all usmp  modules (jsc#PED-13094).
  - commit 60b1624
  - platform/x86/amd/hsmp: Make amd_hsmp and hsmp_acpi as mutually exclusive drivers (jsc#PED-13094).
  - Refresh
    patches.suse/x86-platform-amd-Move-the-asm-amd_hsmp.h-header-to-asm-amd.patch.
  - commit 02efe4c
  - x86/platform/amd: Move the <asm/amd_hsmp.h> header to <asm/amd/hsmp.h> (jsc#PED-13094).
  - commit cd8f689
  - x86/amd_node, platform/x86/amd/hsmp: Have HSMP use SMN through AMD_NODE (jsc#PED-13094).
  - commit 84c6aed
  - x86/amd_node: Remove dependency on AMD_NB (jsc#PED-13094).
  - commit 7a96278
  - x86/amd_node: Update __amd_smn_rw() error paths (jsc#PED-13094).
  - commit 4c71e32
  - x86/amd_nb: Move SMN access code to a new amd_node driver (jsc#PED-13094).
  - commit e227b52
  - x86/amd_nb, hwmon: (k10temp): Simplify amd_pci_dev_to_node_id() (jsc#PED-13094).
  - commit 4ab060a
  - x86/amd_nb: Simplify function 3 search (jsc#PED-13094).
  - commit 995c30f
  - x86/amd_nb: Use topology info to get AMD node count (jsc#PED-13094).
  - commit 92a3127
  - x86/amd_nb: Simplify root device search (jsc#PED-13094).
  - commit 99743f8
  - x86/amd_nb: Simplify function 4 search (jsc#PED-13094).
  - commit 969836a
  - x86: Start moving AMD node functionality out of AMD_NB (jsc#PED-13094).
  - commit dedae8e
  - x86/amd_nb: Clean up early_is_amd_nb() (jsc#PED-13094).
  - commit 3e7ae58
  - x86/amd_nb: Restrict init function to AMD-based systems (jsc#PED-13094).
  - commit 4581815
  - x86/mce/amd: Remove shared threshold bank plumbing (jsc#PED-13094).
  - commit 5e367df
  - platform/x86: amd: Use *-y instead of *-objs in Makefiles (jsc#PED-13094).
  - commit 80da452
  - platform/x86/amd/hsmp: Constify 'struct bin_attribute' (jsc#PED-13094).
  - commit ed01393
  - Refresh
    patches.suse/drm-panel-simple-Update-timings-for-AUO-G101EVN010.patch.
  - Refresh
    patches.suse/drm-xe-Fix-and-re-enable-xe_print_blob_ascii85.patch.
  - commit 7527c99
  - platform/x86/amd/hsmp: Add support for HSMP protocol version 7  messages (jsc#PED-13094).
  - commit 98c4882
  - platform/x86/amd/hsmp: Change the error type (jsc#PED-13094).
  - commit a450822
  - platform/x86/amd/hsmp: Add new error code and error logs (jsc#PED-13094).
  - commit 2c1e1e0
  - platform/x86/amd/hsmp: Make hsmp_pdev static instead of global (jsc#PED-13094).
  - commit 25dfaea

++++ kernel-rt:

  - block/bdev: enable large folio support for large logical block
    sizes (git-fixes).
  - commit 03e169f
  - x86/amd_node: Add support for debugfs access to SMN registers (jsc#PED-13094).
  - commit 718f7f2
  - x86/amd_node: Add SMN offsets to exclusive region access (jsc#PED-13094).
  - commit 8b0488f
  - x86/amd_node: Use defines for SMN register offsets (jsc#PED-13094).
  - commit fdceb0c
  - ima: Suspend PCR extends and log appends when rebooting
    (bsc#1210025 ltc#196650).
  - Refresh patches.suse/0008-ima-track-the-set-of-PCRs-ever-extended.patch.
  - commit 87b6eff
  - wifi: ath12k: Prevent sending WMI commands to firmware during
    firmware crash (bsc#1240998).
  - wifi: ath12k: Resolve multicast packet drop by populating
    key_cipher in ath12k_install_key() (bsc#1240998).
  - commit 7530032
  - wifi: ath12k: ath12k_mac_op_set_key(): fix uninitialized symbol
    'ret' (bsc#1240998).
  - commit f7be9d8
  - wifi: ath12k: Fix for out-of bound access error (bsc#1240998
    CVE-2024-58015 bsc#1238995).
  - blacklist.conf:
  - commit 3c5bf1f
  - wifi: ath12k: fix key cache handling (bsc#1240998).
  - commit dcb3d62
  - wifi: ath12k: convert tasklet to BH workqueue for CE interrupts
    (bsc#1240998).
  - wifi: ath12k: fix A-MSDU indication in monitor mode
    (bsc#1240998).
  - wifi: ath12k: use tail MSDU to get MSDU information
    (bsc#1240998).
  - wifi: ath12k: delete NSS and TX power setting for monitor vdev
    (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_mpdu_start (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_phyrx_rssi_legacy_info
    (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_ppdu_start (bsc#1240998).
  - wifi: ath12k: fix struct hal_rx_ppdu_end_user_stats
    (bsc#1240998).
  - wifi: ath12k: remove unused variable monitor_present
    (bsc#1240998).
  - commit 8ed2a0a
  - wifi: ath12k: modify link arvif creation and removal for MLO
    (bsc#1240998).
  - Refresh
    patches.suse/wifi-ath12k-fix-read-pointer-after-free-in-ath12k_ma.patch.
  - commit 66e4cb1
  - wifi: ath12k: update ath12k_mac_op_update_vif_offload() for MLO
    (bsc#1240998).
  - wifi: ath12k: update ath12k_mac_op_conf_tx() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_mac_op_set_key() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_mac_op_bss_info_changed() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_get_arvif_iter() for MLO
    (bsc#1240998).
  - wifi: ath12k: modify ath12k_mac_vif_chan() for MLO
    (bsc#1240998).
  - wifi: ath12k: prepare vif config caching for MLO (bsc#1240998).
  - wifi: ath12k: prepare sta data structure for MLO handling
    (bsc#1240998).
  - wifi: ath12k: pass ath12k_link_vif instead of vif/ahvif
    (bsc#1240998).
  - commit e2a68c7
  - wifi: ath12k: prepare vif data structure for MLO handling
    (bsc#1240998).
  - Refresh
    patches.suse/wifi-ath12k-Handle-error-cases-during-extended-skb-a.patch.
  - Refresh
    patches.suse/wifi-ath12k-fix-tx-power-max-reg-power-update-to-fir.patch.
  - commit be086ca
  - wifi: ath12k: Add firmware coredump collection support
    (bsc#1240998).
  - Update config files.
  - commit 13fc60a
  - wifi: ath12k: Support BE OFDMA Pdev Rate Stats (bsc#1240998).
  - wifi: ath12k: Support Pdev Scheduled Algorithm Stats
    (bsc#1240998).
  - wifi: ath12k: Support DMAC Reset Stats (bsc#1240998).
  - wifi: ath12k: add missing lockdep_assert_wiphy() for
    ath12k_mac_op_ functions (bsc#1240998).
  - wifi: ath12k: ath12k_mac_op_sta_state(): clean up update_wk
    cancellation (bsc#1240998).
  - wifi: ath12k: ath12k_mac_set_key(): remove exit label
    (bsc#1240998).
  - commit 4d42f04
  - wifi: ath12k: switch to using wiphy_lock() and remove
    ar->conf_mutex (bsc#1240998).
  - Refresh
    patches.suse/wifi-ath12k-fix-node-corruption-in-ar-arvifs-list.patch.
  - Refresh
    patches.suse/wifi-ath12k-fix-read-pointer-after-free-in-ath12k_ma.patch.
  - commit 728526a
  - wifi: ath12k: convert struct ath12k_sta::update_wk to use
    struct wiphy_work (bsc#1240998).
  - commit 91ddf3a
  - wifi: ath12k: Support Pdev OBSS Stats (bsc#1240998).
  - wifi: ath12k: Support pdev CCA Stats (bsc#1240998).
  - wifi: ath12k: Support pdev Transmit Multi-user stats
    (bsc#1240998).
  - wifi: ath12k: Support Ring and SFM stats (bsc#1240998).
  - wifi: ath12k: Support Self-Generated Transmit stats
    (bsc#1240998).
  - wifi: ath12k: Modify print_array_to_buf() to support arrays
    with 1-based semantics (bsc#1240998).
  - wifi: ath12k: move txbaddr/rxbaddr into struct ath12k_dp
    (bsc#1240998).
  - wifi: ath12k: make read-only array svc_id static const
    (bsc#1240998).
  - commit 3509024
  - x86/bugs: Restructure ITS mitigation (git-fixes).
  - commit 085abef
  - x86/bugs: Fix spectre_v2 mitigation default on Intel (git-fixes).
  - commit f344e75
  - KVM: SVM: Set/clear SRSO's BP_SPEC_REDUCE on 0 <=> 1 VM count transitions (git-fixes).
  - commit b648f1d
  - platform/x86/amd/hsmp: fix building with CONFIG_HWMON=m (jsc#PED-13094).
  - commit dc03ed2
  - platform/x86/amd/hsmp: acpi: Add sysfs files to display HSMP telemetry (jsc#PED-13094).
  - commit d63496c
  - platform/x86/amd/hsmp: Report power via hwmon sensors (jsc#PED-13094).
  - commit 357c2f9
  - platform/x86/amd/hsmp: Use a single DRIVER_VERSION for all usmp  modules (jsc#PED-13094).
  - commit 60b1624
  - platform/x86/amd/hsmp: Make amd_hsmp and hsmp_acpi as mutually exclusive drivers (jsc#PED-13094).
  - Refresh
    patches.suse/x86-platform-amd-Move-the-asm-amd_hsmp.h-header-to-asm-amd.patch.
  - commit 02efe4c
  - x86/platform/amd: Move the <asm/amd_hsmp.h> header to <asm/amd/hsmp.h> (jsc#PED-13094).
  - commit cd8f689
  - x86/amd_node, platform/x86/amd/hsmp: Have HSMP use SMN through AMD_NODE (jsc#PED-13094).
  - commit 84c6aed
  - x86/amd_node: Remove dependency on AMD_NB (jsc#PED-13094).
  - commit 7a96278
  - x86/amd_node: Update __amd_smn_rw() error paths (jsc#PED-13094).
  - commit 4c71e32
  - x86/amd_nb: Move SMN access code to a new amd_node driver (jsc#PED-13094).
  - commit e227b52
  - x86/amd_nb, hwmon: (k10temp): Simplify amd_pci_dev_to_node_id() (jsc#PED-13094).
  - commit 4ab060a
  - x86/amd_nb: Simplify function 3 search (jsc#PED-13094).
  - commit 995c30f
  - x86/amd_nb: Use topology info to get AMD node count (jsc#PED-13094).
  - commit 92a3127
  - x86/amd_nb: Simplify root device search (jsc#PED-13094).
  - commit 99743f8
  - x86/amd_nb: Simplify function 4 search (jsc#PED-13094).
  - commit 969836a
  - x86: Start moving AMD node functionality out of AMD_NB (jsc#PED-13094).
  - commit dedae8e
  - x86/amd_nb: Clean up early_is_amd_nb() (jsc#PED-13094).
  - commit 3e7ae58
  - x86/amd_nb: Restrict init function to AMD-based systems (jsc#PED-13094).
  - commit 4581815
  - x86/mce/amd: Remove shared threshold bank plumbing (jsc#PED-13094).
  - commit 5e367df
  - platform/x86: amd: Use *-y instead of *-objs in Makefiles (jsc#PED-13094).
  - commit 80da452
  - platform/x86/amd/hsmp: Constify 'struct bin_attribute' (jsc#PED-13094).
  - commit ed01393
  - Refresh
    patches.suse/drm-panel-simple-Update-timings-for-AUO-G101EVN010.patch.
  - Refresh
    patches.suse/drm-xe-Fix-and-re-enable-xe_print_blob_ascii85.patch.
  - commit 7527c99
  - platform/x86/amd/hsmp: Add support for HSMP protocol version 7  messages (jsc#PED-13094).
  - commit 98c4882
  - platform/x86/amd/hsmp: Change the error type (jsc#PED-13094).
  - commit a450822
  - platform/x86/amd/hsmp: Add new error code and error logs (jsc#PED-13094).
  - commit 2c1e1e0
  - platform/x86/amd/hsmp: Make hsmp_pdev static instead of global (jsc#PED-13094).
  - commit 25dfaea

++++ ovmf:

  - Add the patch from edk2-stable202505 (bsc#1243199)
  - ovmf-OvmfPkg-CcExitLib-Use-the-proper-register-when-filte.patch
    856bdc8eec0f OvmfPkg/CcExitLib: Use the proper register when filtering MSRs

------------------------------------------------------------------
------------------  2025-6-15  -  Jun 15 2025  -------------------
------------------------------------------------------------------

++++ kernel-firmware-bluetooth:

  - Update to version 20250613 (git commit 12fe085fa409):
    * QCA: Update WCN785x btusb firmware to 2.0.0-00799-5

++++ kernel-firmware-mediatek:

  - Update to version 20250613 (git commit 12fe085fa409):
    * linux-firmware: update firmware for MT7986
    * linux-firmware: update firmware for MT7981
    * linux-firmware: update firmware for MT7916

++++ kernel-firmware-qcom:

  - Update to version 20250613 (git commit 12fe085fa409):
    * qcom: sc8280xp: Updated power FW for X13s

++++ kernel-firmware-realtek:

  - Update to version 20250613 (git commit 12fe085fa409):
    * rtl_nic: update firmware of RTL8153A

++++ kernel-firmware-sound:

  - Update to version 20250613 (git commit 12fe085fa409):
    * cirrus: cs35l41: Add Firmware for ASUS NUC using CS35L41

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.169 (boo#1244614)

------------------------------------------------------------------
------------------  2025-6-14  -  Jun 14 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - udmabuf: use sgtable-based scatterlist wrappers (git-fixes).
  - drm/meson: fix more rounding issues with 59.94Hz modes
    (git-fixes).
  - drm/meson: use vclk_freq instead of pixel_freq in debug print
    (git-fixes).
  - drm/meson: fix debug log statement when setting the HDMI clocks
    (git-fixes).
  - ACPI: CPPC: Fix NULL pointer dereference when nosmp is used
    (git-fixes).
  - spi: omap2-mcspi: Disable multi-mode when the previous message
    kept CS asserted (git-fixes).
  - spi: omap2-mcspi: Disable multi mode when CS should be kept
    asserted after message (git-fixes).
  - regulator: max20086: Fix refcount leak in
    max20086_parse_regulators_dt() (git-fixes).
  - commit 8d2d704
  - config: arm64: default: enable mtu3 dual-role support for MediaTek platforms (bsc#1245206)
    MediaTek MTU3 dual-role switch with USB TYPE-C support is ready for most of
    the platforms since kernel 6.14. Hence to update the following default
    settings in arm64 default config.
  - disable CONFIG_USB_MTU3_HOST
  - enable CONFIG_USB_MTU3_DUAL_ROLE
  - commit 232c82c

++++ kernel-rt:

  - udmabuf: use sgtable-based scatterlist wrappers (git-fixes).
  - drm/meson: fix more rounding issues with 59.94Hz modes
    (git-fixes).
  - drm/meson: use vclk_freq instead of pixel_freq in debug print
    (git-fixes).
  - drm/meson: fix debug log statement when setting the HDMI clocks
    (git-fixes).
  - ACPI: CPPC: Fix NULL pointer dereference when nosmp is used
    (git-fixes).
  - spi: omap2-mcspi: Disable multi-mode when the previous message
    kept CS asserted (git-fixes).
  - spi: omap2-mcspi: Disable multi mode when CS should be kept
    asserted after message (git-fixes).
  - regulator: max20086: Fix refcount leak in
    max20086_parse_regulators_dt() (git-fixes).
  - commit 8d2d704
  - config: arm64: default: enable mtu3 dual-role support for MediaTek platforms (bsc#1245206)
    MediaTek MTU3 dual-role switch with USB TYPE-C support is ready for most of
    the platforms since kernel 6.14. Hence to update the following default
    settings in arm64 default config.
  - disable CONFIG_USB_MTU3_HOST
  - enable CONFIG_USB_MTU3_DUAL_ROLE
  - commit 232c82c

------------------------------------------------------------------
------------------  2025-6-13  -  Jun 13 2025  -------------------
------------------------------------------------------------------

++++ git:

  - Refresh gitk SHA256 patch and add SHA256 support to git-gui (bsc#1239989):
    0001-gitk-Add-support-of-SHA256-repo.patch
    0002-git-gui-Add-support-of-SHA256-repo.patch
    The previous patches are dropped:
    0001-gitk-Add-a-basic-support-of-SHA256-repositories-into.patch
    0002-gitk-Add-auto-select-length-preference-for-SHA256.patch

++++ glib2:

  - Update to version 2.84.3:
    + Bug fixed: gstring: Fix overflow check when expanding the
    string (CVE-2025-6052, boo#1244596).

++++ kernel-default:

  - Revert "openvswitch: switch to per-action label counting in
    conntrack" (CVE-2025-21958 bsc#1240758).
  - commit 99845fa
  - fgraph: Still initialize idle shadow stacks when starting
    (git-fixes).
  - commit bbb8b6d
  - platform/x86/amd/hsmp: Use dev_groups in the driver structure (jsc#PED-13094).
  - commit 0d0227e
  - tracing/eprobe: Fix to release eprobe when failed to add
    dyn_event (git-fixes).
  - commit 1e81e5c
  - platform/x86/amd/hsmp: Use name space while exporting module symbols (jsc#PED-13094).
  - commit 43e9d2b
  - platform/x86/amd/hsmp: Create separate ACPI, plat and common drivers (jsc#PED-13094).
  - Update config files.
  - commit 1820255
  - mm/damon: fix order of arguments in damos_before_apply
    tracepoint (git-fixes).
  - commit 573e8fc
  - platform/x86/amd/hsmp: Change generic plat_dev name to hsmp_pdev (jsc#PED-13094).
  - commit e81369a
  - platform/x86/amd/hsmp: Move ACPI code to acpi.c (jsc#PED-13094).
  - commit 4d8807d
  - platform/x86/amd/hsmp: Move platform device specific code to plat.c (jsc#PED-13094).
  - commit a6d1274
  - platform/x86/amd/hsmp: Move structure and macros to header file (jsc#PED-13094).
  - commit 226e6d8
  - platform/x86/amd/hsmp: Convert amd_hsmp_rdwr() to a function pointer (jsc#PED-13094).
  - commit cfa6b2b
  - platform/x86/amd/hsmp: Create wrapper function init_acpi() (jsc#PED-13094).
  - commit 7b2aa8b
  - tracing: Fix cmp_entries_dup() to respect sort() comparison
    rules (git-fixes).
  - commit b955896
  - platform/x86/amd/hsmp: Create hsmp/ directory (jsc#PED-13094).
  - Refresh
    patches.suse/sysfs-treewide-constify-attribute-callback-of-bin_is.patch.
  - commit fb1429d
  - tracing: Fix function name for trampoline (git-fixes).
  - commit db0dd06
  - tracing: Use atomic64_inc_return() in trace_clock_counter()
    (git-fixes).
  - commit 58aed75
  - trace/trace_event_perf: remove duplicate samples on the first
    tracepoint event (git-fixes).
  - commit 4902f47
  - x86/bugs: Restructure SRSO mitigation (git-fixes).
  - commit b308adf
  - x86/bugs: KVM: Add support for SRSO_MSR_FIX (git-fixes).
  - commit d3911cf
  - x86/bugs: Restructure L1TF mitigation (git-fixes).
  - Refresh
    patches.suse/x86-sme-Use-percpu-boolean-to-control-wbinvd-during-kexec.patch.
  - commit 1d465a8
  - x86/bugs: Restructure SSB mitigation (git-fixes).
  - commit 4fad51e
  - x86/bugs: Restructure spectre_v2 mitigation (git-fixes).
  - commit 811ec5d
  - x86/bugs: Restructure BHI mitigation (git-fixes).
  - commit 185e70f
  - x86/bugs: Restructure spectre_v2_user mitigation (git-fixes).
  - commit 7ec3712
  - x86/bugs: Remove X86_FEATURE_USE_IBPB (git-fixes).
  - commit fa88ebe
  - KVM: nVMX: Always use IBPB to properly virtualize IBRS (git-fixes).
  - blacklist.conf: Removed the patch
  - commit 557f9fb
  - x86/bugs: Use a static branch to guard IBPB on vCPU switch (git-fixes).
  - commit e724e81
  - x86/bugs: Remove the X86_FEATURE_USE_IBPB check in ib_prctl_set() (git-fixes).
  - commit 42db235
  - x86/mm: Remove X86_FEATURE_USE_IBPB checks in cond_mitigation() (git-fixes).
  - commit 4022f33
  - x86/bugs: Move the X86_FEATURE_USE_IBPB check into callers (git-fixes).
  - Refresh
    patches.suse/x86-bugs-Fix-RSB-clearing-in-indirect_branch_prediction_ba.patch.
  - commit 68a66c6
  - x86/bugs: Use the cpu_smt_possible() helper instead of open-coded  code (git-fixes).
  - commit a3f48f2
  - x86/bugs: Restructure retbleed mitigation (git-fixes).
  - commit 57e9149
  - x86/bugs: Allow retbleed=stuff only on Intel (git-fixes).
  - commit be36749
  - x86/bugs: Restructure spectre_v1 mitigation (git-fixes).
  - commit 9d9c4f9
  - x86/bugs: Restructure GDS mitigation (git-fixes).
  - commit 07ce138
  - x86/bugs: Restructure SRBDS mitigation (git-fixes).
  - commit 985324a
  - x86/bugs: Remove md_clear_*_mitigation() (git-fixes).
  - commit 3670fb7
  - x86/bugs: Restructure RFDS mitigation (git-fixes).
  - commit 5f6d514
  - x86/bugs: Restructure MMIO mitigation (git-fixes).
  - commit fbecfda
  - x86/bugs: Rename mmio_stale_data_clear to cpu_buf_vm_clear (git-fixes).
  - commit 6562e0a
  - x86/bugs: Restructure TAA mitigation (git-fixes).
  - commit 2b3c942
  - x86/bugs: Restructure MDS mitigation (git-fixes).
  - commit d61c636
  - x86/bugs: Add AUTO mitigations for mds/taa/mmio/rfds (git-fixes).
  - commit 8f40133
  - x86/bugs: Relocate mds/taa/mmio/rfds defines (git-fixes).
  - commit dd6ad69
  - x86/bugs: Add X86_BUG_SPECTRE_V2_USER (git-fixes).
  - Refresh
    patches.suse/x86-its-Add-vmexit-option-to-skip-mitigation-on-some-CPUs.patch.
  - Refresh
    patches.suse/x86-its-Enumerate-Indirect-Target-Selection-ITS-bug.patch.
  - commit 2251acf
  - net: ibmveth: Refactored veth_pool_store for better
    maintainability (jsc#PED-3944).
  - net: ibmveth: added KUnit tests for some buffer pool functions
    (jsc#PED-3944).
  - net: ibmveth: Reset the adapter when unexpected states are
    detected (jsc#PED-3944).
  - net: ibmveth: Indented struct ibmveth_adapter correctly
    (jsc#PED-3944).
  - commit 8a53c7b
  - patches.suse/block-make-sure-nr_integrity_segments-is-cloned-in-blk_rq_.patch:
    (git-fixes, bsc#1243874).
    Patch metadata
  - commit 3065561
  - x86/mm/init: Handle the special case of device private
    pages in add_pages(), to not increase max_pfn and trigger
    dma_addressing_limited() bounce buffers (git-fixes).
  - commit 497daab
  - Bluetooth: MGMT: Fix sparse errors (git-fixes).
  - commit f4127bc
  - wifi: ath11k: validate ath11k_crypto_mode on top of
    ath11k_core_qmi_firmware_ready (git-fixes).
  - ath10k: snoc: fix unbalanced IRQ enable in crash recovery
    (git-fixes).
  - Revert "wifi: mwifiex: Fix HT40 bandwidth issue." (git-fixes).
  - Bluetooth: eir: Fix possible crashes on eir_create_adv_data
    (git-fixes).
  - Bluetooth: hci_sync: Fix broadcast/PA when using an existing
    instance (git-fixes).
  - Bluetooth: Fix NULL pointer deference on eir_get_service_data
    (git-fixes).
  - net/mdiobus: Fix potential out-of-bounds clause 45 read/write
    access (git-fixes).
  - net/mdiobus: Fix potential out-of-bounds read/write access
    (git-fixes).
  - Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete
    (git-fixes).
  - Bluetooth: btintel_pcie: Reduce driver buffer posting to
    prevent race condition (git-fixes).
  - Bluetooth: btintel_pcie: Increase the tx and rx descriptor count
    (git-fixes).
  - Bluetooth: btintel_pcie: Fix driver not posting maximum rx
    buffers (git-fixes).
  - Bluetooth: hci_core: fix list_for_each_entry_rcu usage
    (git-fixes).
  - ptp: remove ptp->n_vclocks check logic in ptp_vclock_in_use()
    (git-fixes).
  - pinctrl: st: Drop unused st_gpio_bank() function (git-fixes).
  - pinctrl: qcom: pinctrl-qcm2290: Add missing pins (git-fixes).
  - ptp: ocp: Limit signal/freq counts in summary output functions
    (git-fixes).
  - ptp: ocp: fix start time alignment in ptp_ocp_signal_set
    (git-fixes).
  - ptp: ocp: reject unsupported periodic output flags (git-fixes).
  - ptp: Properly handle compat ioctls (git-fixes).
  - commit ad94026
  - PCI/MSI: Size device MSI domain with the maximum number of
    vectors (git-fixes).
  - PCI: apple: Set only available ports up (git-fixes).
  - PCI: endpoint: Retain fixed-size BAR size as well as aligned
    size (git-fixes).
  - kABI: PCI: endpoint: Retain fixed-size BAR size as well as
    aligned size (git-fixes).
  - PCI/pwrctrl: Cancel outstanding rescan work when unregistering
    (git-fixes).
  - serial: mctrl_gpio: split disable_ms into sync and no_sync APIs
    (git-fixes).
  - kABI: serial: mctrl_gpio: split disable_ms into sync and
    no_sync APIs (git-fixes).
  - PCI: apple: Use helper function for_each_child_of_node_scoped()
    (git-fixes).
  - x86/kaslr: Reduce KASLR entropy on most x86 systems (git-fixes).
  - commit f6125e9

++++ kernel-rt:

  - Revert "openvswitch: switch to per-action label counting in
    conntrack" (CVE-2025-21958 bsc#1240758).
  - commit 99845fa
  - fgraph: Still initialize idle shadow stacks when starting
    (git-fixes).
  - commit bbb8b6d
  - platform/x86/amd/hsmp: Use dev_groups in the driver structure (jsc#PED-13094).
  - commit 0d0227e
  - tracing/eprobe: Fix to release eprobe when failed to add
    dyn_event (git-fixes).
  - commit 1e81e5c
  - platform/x86/amd/hsmp: Use name space while exporting module symbols (jsc#PED-13094).
  - commit 43e9d2b
  - platform/x86/amd/hsmp: Create separate ACPI, plat and common drivers (jsc#PED-13094).
  - Update config files.
  - commit 1820255
  - mm/damon: fix order of arguments in damos_before_apply
    tracepoint (git-fixes).
  - commit 573e8fc
  - platform/x86/amd/hsmp: Change generic plat_dev name to hsmp_pdev (jsc#PED-13094).
  - commit e81369a
  - platform/x86/amd/hsmp: Move ACPI code to acpi.c (jsc#PED-13094).
  - commit 4d8807d
  - platform/x86/amd/hsmp: Move platform device specific code to plat.c (jsc#PED-13094).
  - commit a6d1274
  - platform/x86/amd/hsmp: Move structure and macros to header file (jsc#PED-13094).
  - commit 226e6d8
  - platform/x86/amd/hsmp: Convert amd_hsmp_rdwr() to a function pointer (jsc#PED-13094).
  - commit cfa6b2b
  - platform/x86/amd/hsmp: Create wrapper function init_acpi() (jsc#PED-13094).
  - commit 7b2aa8b
  - tracing: Fix cmp_entries_dup() to respect sort() comparison
    rules (git-fixes).
  - commit b955896
  - platform/x86/amd/hsmp: Create hsmp/ directory (jsc#PED-13094).
  - Refresh
    patches.suse/sysfs-treewide-constify-attribute-callback-of-bin_is.patch.
  - commit fb1429d
  - tracing: Fix function name for trampoline (git-fixes).
  - commit db0dd06
  - tracing: Use atomic64_inc_return() in trace_clock_counter()
    (git-fixes).
  - commit 58aed75
  - trace/trace_event_perf: remove duplicate samples on the first
    tracepoint event (git-fixes).
  - commit 4902f47
  - x86/bugs: Restructure SRSO mitigation (git-fixes).
  - commit b308adf
  - x86/bugs: KVM: Add support for SRSO_MSR_FIX (git-fixes).
  - commit d3911cf
  - x86/bugs: Restructure L1TF mitigation (git-fixes).
  - Refresh
    patches.suse/x86-sme-Use-percpu-boolean-to-control-wbinvd-during-kexec.patch.
  - commit 1d465a8
  - x86/bugs: Restructure SSB mitigation (git-fixes).
  - commit 4fad51e
  - x86/bugs: Restructure spectre_v2 mitigation (git-fixes).
  - commit 811ec5d
  - x86/bugs: Restructure BHI mitigation (git-fixes).
  - commit 185e70f
  - x86/bugs: Restructure spectre_v2_user mitigation (git-fixes).
  - commit 7ec3712
  - x86/bugs: Remove X86_FEATURE_USE_IBPB (git-fixes).
  - commit fa88ebe
  - KVM: nVMX: Always use IBPB to properly virtualize IBRS (git-fixes).
  - blacklist.conf: Removed the patch
  - commit 557f9fb
  - x86/bugs: Use a static branch to guard IBPB on vCPU switch (git-fixes).
  - commit e724e81
  - x86/bugs: Remove the X86_FEATURE_USE_IBPB check in ib_prctl_set() (git-fixes).
  - commit 42db235
  - x86/mm: Remove X86_FEATURE_USE_IBPB checks in cond_mitigation() (git-fixes).
  - commit 4022f33
  - x86/bugs: Move the X86_FEATURE_USE_IBPB check into callers (git-fixes).
  - Refresh
    patches.suse/x86-bugs-Fix-RSB-clearing-in-indirect_branch_prediction_ba.patch.
  - commit 68a66c6
  - x86/bugs: Use the cpu_smt_possible() helper instead of open-coded  code (git-fixes).
  - commit a3f48f2
  - x86/bugs: Restructure retbleed mitigation (git-fixes).
  - commit 57e9149
  - x86/bugs: Allow retbleed=stuff only on Intel (git-fixes).
  - commit be36749
  - x86/bugs: Restructure spectre_v1 mitigation (git-fixes).
  - commit 9d9c4f9
  - x86/bugs: Restructure GDS mitigation (git-fixes).
  - commit 07ce138
  - x86/bugs: Restructure SRBDS mitigation (git-fixes).
  - commit 985324a
  - x86/bugs: Remove md_clear_*_mitigation() (git-fixes).
  - commit 3670fb7
  - x86/bugs: Restructure RFDS mitigation (git-fixes).
  - commit 5f6d514
  - x86/bugs: Restructure MMIO mitigation (git-fixes).
  - commit fbecfda
  - x86/bugs: Rename mmio_stale_data_clear to cpu_buf_vm_clear (git-fixes).
  - commit 6562e0a
  - x86/bugs: Restructure TAA mitigation (git-fixes).
  - commit 2b3c942
  - x86/bugs: Restructure MDS mitigation (git-fixes).
  - commit d61c636
  - x86/bugs: Add AUTO mitigations for mds/taa/mmio/rfds (git-fixes).
  - commit 8f40133
  - x86/bugs: Relocate mds/taa/mmio/rfds defines (git-fixes).
  - commit dd6ad69
  - x86/bugs: Add X86_BUG_SPECTRE_V2_USER (git-fixes).
  - Refresh
    patches.suse/x86-its-Add-vmexit-option-to-skip-mitigation-on-some-CPUs.patch.
  - Refresh
    patches.suse/x86-its-Enumerate-Indirect-Target-Selection-ITS-bug.patch.
  - commit 2251acf
  - net: ibmveth: Refactored veth_pool_store for better
    maintainability (jsc#PED-3944).
  - net: ibmveth: added KUnit tests for some buffer pool functions
    (jsc#PED-3944).
  - net: ibmveth: Reset the adapter when unexpected states are
    detected (jsc#PED-3944).
  - net: ibmveth: Indented struct ibmveth_adapter correctly
    (jsc#PED-3944).
  - commit 8a53c7b
  - patches.suse/block-make-sure-nr_integrity_segments-is-cloned-in-blk_rq_.patch:
    (git-fixes, bsc#1243874).
    Patch metadata
  - commit 3065561
  - x86/mm/init: Handle the special case of device private
    pages in add_pages(), to not increase max_pfn and trigger
    dma_addressing_limited() bounce buffers (git-fixes).
  - commit 497daab
  - Bluetooth: MGMT: Fix sparse errors (git-fixes).
  - commit f4127bc
  - wifi: ath11k: validate ath11k_crypto_mode on top of
    ath11k_core_qmi_firmware_ready (git-fixes).
  - ath10k: snoc: fix unbalanced IRQ enable in crash recovery
    (git-fixes).
  - Revert "wifi: mwifiex: Fix HT40 bandwidth issue." (git-fixes).
  - Bluetooth: eir: Fix possible crashes on eir_create_adv_data
    (git-fixes).
  - Bluetooth: hci_sync: Fix broadcast/PA when using an existing
    instance (git-fixes).
  - Bluetooth: Fix NULL pointer deference on eir_get_service_data
    (git-fixes).
  - net/mdiobus: Fix potential out-of-bounds clause 45 read/write
    access (git-fixes).
  - net/mdiobus: Fix potential out-of-bounds read/write access
    (git-fixes).
  - Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete
    (git-fixes).
  - Bluetooth: btintel_pcie: Reduce driver buffer posting to
    prevent race condition (git-fixes).
  - Bluetooth: btintel_pcie: Increase the tx and rx descriptor count
    (git-fixes).
  - Bluetooth: btintel_pcie: Fix driver not posting maximum rx
    buffers (git-fixes).
  - Bluetooth: hci_core: fix list_for_each_entry_rcu usage
    (git-fixes).
  - ptp: remove ptp->n_vclocks check logic in ptp_vclock_in_use()
    (git-fixes).
  - pinctrl: st: Drop unused st_gpio_bank() function (git-fixes).
  - pinctrl: qcom: pinctrl-qcm2290: Add missing pins (git-fixes).
  - ptp: ocp: Limit signal/freq counts in summary output functions
    (git-fixes).
  - ptp: ocp: fix start time alignment in ptp_ocp_signal_set
    (git-fixes).
  - ptp: ocp: reject unsupported periodic output flags (git-fixes).
  - ptp: Properly handle compat ioctls (git-fixes).
  - commit ad94026
  - PCI/MSI: Size device MSI domain with the maximum number of
    vectors (git-fixes).
  - PCI: apple: Set only available ports up (git-fixes).
  - PCI: endpoint: Retain fixed-size BAR size as well as aligned
    size (git-fixes).
  - kABI: PCI: endpoint: Retain fixed-size BAR size as well as
    aligned size (git-fixes).
  - PCI/pwrctrl: Cancel outstanding rescan work when unregistering
    (git-fixes).
  - serial: mctrl_gpio: split disable_ms into sync and no_sync APIs
    (git-fixes).
  - kABI: serial: mctrl_gpio: split disable_ms into sync and
    no_sync APIs (git-fixes).
  - PCI: apple: Use helper function for_each_child_of_node_scoped()
    (git-fixes).
  - x86/kaslr: Reduce KASLR entropy on most x86 systems (git-fixes).
  - commit f6125e9

++++ libguestfs:

  - Drop gzip mtime from base.tar.gz (bsc#1216986)

++++ osinfo-db:

  - Update to database version 20250606 (jsc#PED-12706)
    osinfo-db-20250606.tar.xz
  - Drop add-Windows-Server-2025.patch

------------------------------------------------------------------
------------------  2025-6-12  -  Jun 12 2025  -------------------
------------------------------------------------------------------

++++ transactional-update:

  - Version 5.0.4
  - Don't override soft-reboot with hard reboot
  - Fix stdio when returning from selfupdate [boo#1243910],
    [gh#openSUSE/transactional-update#151]

++++ jq:

  - Add patch CVE-2024-23337.patch (CVE-2024-23337, bsc#1243450)

++++ kernel-default:

  - scsi: dc395x: Remove leftover if statement in reselect()
    (git-fixes).
  - commit 6750876
  - scsi: smartpqi: Fix smp_processor_id() call trace for
    preemptible kernels (git-fixes).
  - scsi: dc395x: Remove DEBUG conditional compilation (git-fixes).
  - scsi: hisi_sas: Call I_T_nexus after soft reset for SATA disk
    (git-fixes).
  - scsi: qedf: Use designated initializer for struct
    qed_fcoe_cb_ops (git-fixes).
  - scsi: sd_zbc: block: Respect bio vector limits for REPORT
    ZONES buffer (git-fixes).
  - scsi: mpi3mr: Add level check to control event logging
    (git-fixes).
  - scsi: st: Tighten the page format heuristics with MODE SELECT
    (git-fixes).
  - scsi: st: ERASE does not change tape location (git-fixes).
  - scsi: logging: Fix scsi_logging_level bounds (git-fixes).
  - scsi: mpi3mr: Update timestamp only for supervisor IOCs
    (git-fixes).
  - scsi: scsi_debug: First fixes for tapes (git-fixes).
  - scsi: mpt3sas: Send a diag reset if target reset fails
    (git-fixes).
  - scsi: st: Restore some drive settings after reset (git-fixes).
  - commit edc8361
  - sch_hfsc: Fix qlen accounting bug when using peek in
    hfsc_enqueue() (CVE-2025-38000 bsc#1244277).
  - commit 57fc275
  - ring-buffer: Limit time with disabled interrupts in
    rb_check_pages() (git-fixes).
  - commit eb4c51a
  - bpf: Force uprobe bpf program to always return 0 (git-fixes).
  - commit 8c62ccf
  - tracing: Fix function timing profiler to initialize hashtable
    (git-fixes).
  - commit bb3c8fc
  - xfs: don't lose solo dquot update transactions (bsc#1244502).
  - commit de784a3
  - xfs: don't lose solo superblock counter update transactions
    (bsc#1244502).
  - commit d46099b
  - xfs: avoid nested calls to __xfs_trans_commit (bsc#1244502).
  - commit 0e219be
  - netfilter: ipset: fix region locking in hash types
    (CVE-2025-37997 bsc#1243832).
  - commit 7805bf7
  - Revert "sysctl: update common tuning parameters for SAP workloads"
    This reverts commit 86d9b0692912bbfa298dbe77683f16d0872aaf27.
    jsc#PED-11676 has been rejected.
  - commit 346a6d9
  - supported.conf: mark mana drivers as external
  - uio_hv_generic: Set event for all channels on the device (git-fixes).
  - Drivers: hv: Always select CONFIG_SYSFB for Hyper-V guests (git-fixes).
  - Drivers: hv: vmbus: Add comments about races with "channels" sysfs dir (git-fixes).
  - PCI: hv: Remove unnecessary flex array in struct pci_packet (git-fixes).
  - Drivers: hv: Use kzalloc for panic page allocation (git-fixes).
  - uio_hv_generic: Align ring size to system page (git-fixes).
  - uio_hv_generic: Use correct size for interrupt and monitor pages (git-fixes).
  - Drivers: hv: Allocate interrupt and monitor pages aligned to system page boundary (git-fixes).
  - x86/hyperv: Fix APIC ID and VP index confusion in hv_snp_boot_ap() (git-fixes).
  - Drivers: hv: vmbus: Introduce hv_get_vmbus_root_device() (git-fixes).
  - Drivers: hv: vmbus: Get the IRQ number from DeviceTree (git-fixes).
  - arm64, x86: hyperv: Report the VTL the system boots in (git-fixes).
  - arm64: hyperv: Initialize the Virtual Trust Level field (git-fixes).
  - Drivers: hv: Provide arch-neutral implementation of get_vtl() (git-fixes).
  - Drivers: hv: Enable VTL mode for arm64 (git-fixes).
  - tools: hv: Enable debug logs for hv_kvp_daemon (git-fixes).
  - net: mana: Add support for auxiliary device servicing events (git-fixes).
  - RDMA/mana_ib: unify mana_ib functions to support any gdma device (git-fixes).
  - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (git-fixes).
  - net: mana: Probe rdma device in mana driver (git-fixes).
  - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (git-fixes).
  - RDMA/mana_ib: support of the zero based MRs (git-fixes).
  - RDMA/mana_ib: Access remote atomic for MRs (git-fixes).
  - net: mana: Add support for Multi Vports on Bare metal (bsc#1244229).
  - commit e5bb2a2

++++ kernel-firmware-nvidia:

  - Fix zypper conflict about directory -> symlink workaround (bsc#1244458)

++++ kernel-firmware-qcom:

  - Better workaround for directory -> symlink change (bsc#1244458)

++++ kernel-rt:

  - scsi: dc395x: Remove leftover if statement in reselect()
    (git-fixes).
  - commit 6750876
  - scsi: smartpqi: Fix smp_processor_id() call trace for
    preemptible kernels (git-fixes).
  - scsi: dc395x: Remove DEBUG conditional compilation (git-fixes).
  - scsi: hisi_sas: Call I_T_nexus after soft reset for SATA disk
    (git-fixes).
  - scsi: qedf: Use designated initializer for struct
    qed_fcoe_cb_ops (git-fixes).
  - scsi: sd_zbc: block: Respect bio vector limits for REPORT
    ZONES buffer (git-fixes).
  - scsi: mpi3mr: Add level check to control event logging
    (git-fixes).
  - scsi: st: Tighten the page format heuristics with MODE SELECT
    (git-fixes).
  - scsi: st: ERASE does not change tape location (git-fixes).
  - scsi: logging: Fix scsi_logging_level bounds (git-fixes).
  - scsi: mpi3mr: Update timestamp only for supervisor IOCs
    (git-fixes).
  - scsi: scsi_debug: First fixes for tapes (git-fixes).
  - scsi: mpt3sas: Send a diag reset if target reset fails
    (git-fixes).
  - scsi: st: Restore some drive settings after reset (git-fixes).
  - commit edc8361
  - sch_hfsc: Fix qlen accounting bug when using peek in
    hfsc_enqueue() (CVE-2025-38000 bsc#1244277).
  - commit 57fc275
  - ring-buffer: Limit time with disabled interrupts in
    rb_check_pages() (git-fixes).
  - commit eb4c51a
  - bpf: Force uprobe bpf program to always return 0 (git-fixes).
  - commit 8c62ccf
  - tracing: Fix function timing profiler to initialize hashtable
    (git-fixes).
  - commit bb3c8fc
  - xfs: don't lose solo dquot update transactions (bsc#1244502).
  - commit de784a3
  - xfs: don't lose solo superblock counter update transactions
    (bsc#1244502).
  - commit d46099b
  - xfs: avoid nested calls to __xfs_trans_commit (bsc#1244502).
  - commit 0e219be
  - netfilter: ipset: fix region locking in hash types
    (CVE-2025-37997 bsc#1243832).
  - commit 7805bf7
  - Revert "sysctl: update common tuning parameters for SAP workloads"
    This reverts commit 86d9b0692912bbfa298dbe77683f16d0872aaf27.
    jsc#PED-11676 has been rejected.
  - commit 346a6d9
  - supported.conf: mark mana drivers as external
  - uio_hv_generic: Set event for all channels on the device (git-fixes).
  - Drivers: hv: Always select CONFIG_SYSFB for Hyper-V guests (git-fixes).
  - Drivers: hv: vmbus: Add comments about races with "channels" sysfs dir (git-fixes).
  - PCI: hv: Remove unnecessary flex array in struct pci_packet (git-fixes).
  - Drivers: hv: Use kzalloc for panic page allocation (git-fixes).
  - uio_hv_generic: Align ring size to system page (git-fixes).
  - uio_hv_generic: Use correct size for interrupt and monitor pages (git-fixes).
  - Drivers: hv: Allocate interrupt and monitor pages aligned to system page boundary (git-fixes).
  - x86/hyperv: Fix APIC ID and VP index confusion in hv_snp_boot_ap() (git-fixes).
  - Drivers: hv: vmbus: Introduce hv_get_vmbus_root_device() (git-fixes).
  - Drivers: hv: vmbus: Get the IRQ number from DeviceTree (git-fixes).
  - arm64, x86: hyperv: Report the VTL the system boots in (git-fixes).
  - arm64: hyperv: Initialize the Virtual Trust Level field (git-fixes).
  - Drivers: hv: Provide arch-neutral implementation of get_vtl() (git-fixes).
  - Drivers: hv: Enable VTL mode for arm64 (git-fixes).
  - tools: hv: Enable debug logs for hv_kvp_daemon (git-fixes).
  - net: mana: Add support for auxiliary device servicing events (git-fixes).
  - RDMA/mana_ib: unify mana_ib functions to support any gdma device (git-fixes).
  - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (git-fixes).
  - net: mana: Probe rdma device in mana driver (git-fixes).
  - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (git-fixes).
  - RDMA/mana_ib: support of the zero based MRs (git-fixes).
  - RDMA/mana_ib: Access remote atomic for MRs (git-fixes).
  - net: mana: Add support for Multi Vports on Bare metal (bsc#1244229).
  - commit e5bb2a2

++++ ndctl:

  - Update to version 82
    * adds libcxl enumeration of FWCTL character devices - Linux 6.15 compatibility

++++ virt-manager:

  - Upstream bug fixes (bsc#1027942)
    050-Validation-allow-spaces-disallow-slashes.patch
    051-fix-default-start_folder-to-None.patch
    052-Add-Ctrl+Alt+Shift+Esc-key-command-for-loginds-SecureAttentionKey.patch

------------------------------------------------------------------
------------------  2025-6-11  -  Jun 11 2025  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - document static ip setup on boot (bsc#1244072)
    add 0001-man-document-static-ip-setup-differences-to-dracut-n.patch

++++ fde-tools:

  - Add fde-tools-bsc1244323-firstboot-fix-lsinitrd.patch to fix the
    empty LUKS header checksum from lsinitrd (bsc#1244323)

++++ kernel-default:

  - Revert "ipv6: save dontfrag in cork (git-fixes)."
    This reverts commit f07ae24f52481201baa11e1e91aab0812e1043c6.
    See https://lore.kernel.org/all/aElivdUXqd1OqgMY@karahi.gladserv.com/
    and https://bugzilla.suse.com/show_bug.cgi?id=1244313.
  - commit a4337cd
  - Revert "kABI: ipv6: save dontfrag in cork (git-fixes)."
    This reverts commit c19b92367fe535ac505c72a32609b2b5aa190746.
    See https://lore.kernel.org/all/aElivdUXqd1OqgMY@karahi.gladserv.com/
    and https://bugzilla.suse.com/show_bug.cgi?id=1244313.
  - commit d9787d8
  - rxrpc: Fix handling of received connection abort (CVE-2024-58053
    bsc#1238982).
  - commit 6192989
  - tipc: fix memory leak in tipc_link_xmit (CVE-2025-37757 bsc#1242521)
  - commit c36615f
  - isolcpus: fix bug in returning number of allocated cpumask (bsc#1243774).
    Return the correct upper limit of the allocated cpumask.
    modified:
  - patches.suse/lib-group_cpus-honor-housekeeping-config-when-grouping-cpus.patch.
  - patches.suse/lib-group_cpus-let-group_cpu_evenly-return-number-initialized-masks.patch.
  - commit 55c520e
  - Refresh patches.suse/sd-always-retry-READ-CAPACITY-for-ALUA-state-transit.patch
    This patch has two identical hunks but there is only one site where the
    hunk can be applied.
  - commit da23587
  - arm64: dts: marvell: uDPU: define pinctrl state for alarm LEDs (git-fixes)
  - commit 5fb1a6c
  - Revert "arm64: dts: allwinner: h6: Use RSB for AXP805 PMIC (git-fixes)
  - commit 0ba4e57
  - xen/arm: call uaccess_ttbr0_enable for dm_op hypercall (git-fixes)
  - commit 1f1b63d
  - ALSA: usb-audio: Add a quirk for Lenovo Thinkpad Thunderbolt
    3 dock (stable-fixes).
  - commit ba34170
  - ALSA: usb-audio: Add implicit feedback quirk for RODE AI-1
    (stable-fixes).
  - ALSA: usb-audio: Rename Pioneer mixer channel controls
    (git-fixes).
  - ALSA: usb-audio: Add Pioneer DJ DJM-V10 support (stable-fixes).
  - ALSA: usb-audio: enable support for Presonus Studio 1824c
    within 1810c file (stable-fixes).
  - commit db6d17b
  - ALSA: hda: Add new pci id for AMD GPU display HD audio
    controller (stable-fixes).
  - ALSA: hda: hda-intel: add Wildcat Lake support (stable-fixes).
  - ALSA: hda: add HDMI codec ID for Intel WCL (stable-fixes).
  - PCI: Add Intel Wildcat Lake audio Device ID (stable-fixes).
  - ALSA: hda: cs35l41: Fix swapped l/r audio channels for Acer
    Helios laptops (stable-fixes).
  - commit b41ea81
  - accel/ivpu: Trigger device recovery on engine reset/resume
    failure (git-fixes).
  - accel/ivpu: Use firmware names from upstream repo (git-fixes).
  - commit cfcd050
  - USB: serial: pl2303: add new chip PL2303GC-Q20 and PL2303GT-2AB
    (stable-fixes).
  - usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage
    device (stable-fixes).
  - usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
    (stable-fixes).
  - thunderbolt: Do not double dequeue a configuration request
    (stable-fixes).
  - Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands
    (git-fixes).
  - rtc: Make rtc_time64_to_tm() support dates before 1970
    (stable-fixes).
  - net: lan743x: Fix memleak issue when GSO enabled (git-fixes).
  - accel/ivpu: Add handling of
    VPU_JSM_STATUS_MVNCI_CONTEXT_VIOLATION_HW (stable-fixes).
  - PCI/ASPM: Disable L1 before disabling L1 PM Substates
    (stable-fixes).
  - accel/ivpu: Update power island delays (stable-fixes).
  - accel/ivpu: Add initial Panther Lake support (stable-fixes).
  - commit 122402d

++++ kernel-rt:

  - Revert "ipv6: save dontfrag in cork (git-fixes)."
    This reverts commit f07ae24f52481201baa11e1e91aab0812e1043c6.
    See https://lore.kernel.org/all/aElivdUXqd1OqgMY@karahi.gladserv.com/
    and https://bugzilla.suse.com/show_bug.cgi?id=1244313.
  - commit a4337cd
  - Revert "kABI: ipv6: save dontfrag in cork (git-fixes)."
    This reverts commit c19b92367fe535ac505c72a32609b2b5aa190746.
    See https://lore.kernel.org/all/aElivdUXqd1OqgMY@karahi.gladserv.com/
    and https://bugzilla.suse.com/show_bug.cgi?id=1244313.
  - commit d9787d8
  - rxrpc: Fix handling of received connection abort (CVE-2024-58053
    bsc#1238982).
  - commit 6192989
  - tipc: fix memory leak in tipc_link_xmit (CVE-2025-37757 bsc#1242521)
  - commit c36615f
  - isolcpus: fix bug in returning number of allocated cpumask (bsc#1243774).
    Return the correct upper limit of the allocated cpumask.
    modified:
  - patches.suse/lib-group_cpus-honor-housekeeping-config-when-grouping-cpus.patch.
  - patches.suse/lib-group_cpus-let-group_cpu_evenly-return-number-initialized-masks.patch.
  - commit 55c520e
  - Refresh patches.suse/sd-always-retry-READ-CAPACITY-for-ALUA-state-transit.patch
    This patch has two identical hunks but there is only one site where the
    hunk can be applied.
  - commit da23587
  - arm64: dts: marvell: uDPU: define pinctrl state for alarm LEDs (git-fixes)
  - commit 5fb1a6c
  - Revert "arm64: dts: allwinner: h6: Use RSB for AXP805 PMIC (git-fixes)
  - commit 0ba4e57
  - xen/arm: call uaccess_ttbr0_enable for dm_op hypercall (git-fixes)
  - commit 1f1b63d
  - ALSA: usb-audio: Add a quirk for Lenovo Thinkpad Thunderbolt
    3 dock (stable-fixes).
  - commit ba34170
  - ALSA: usb-audio: Add implicit feedback quirk for RODE AI-1
    (stable-fixes).
  - ALSA: usb-audio: Rename Pioneer mixer channel controls
    (git-fixes).
  - ALSA: usb-audio: Add Pioneer DJ DJM-V10 support (stable-fixes).
  - ALSA: usb-audio: enable support for Presonus Studio 1824c
    within 1810c file (stable-fixes).
  - commit db6d17b
  - ALSA: hda: Add new pci id for AMD GPU display HD audio
    controller (stable-fixes).
  - ALSA: hda: hda-intel: add Wildcat Lake support (stable-fixes).
  - ALSA: hda: add HDMI codec ID for Intel WCL (stable-fixes).
  - PCI: Add Intel Wildcat Lake audio Device ID (stable-fixes).
  - ALSA: hda: cs35l41: Fix swapped l/r audio channels for Acer
    Helios laptops (stable-fixes).
  - commit b41ea81
  - accel/ivpu: Trigger device recovery on engine reset/resume
    failure (git-fixes).
  - accel/ivpu: Use firmware names from upstream repo (git-fixes).
  - commit cfcd050
  - USB: serial: pl2303: add new chip PL2303GC-Q20 and PL2303GT-2AB
    (stable-fixes).
  - usb: storage: Ignore UAS driver for SanDisk 3.2 Gen2 storage
    device (stable-fixes).
  - usb: quirks: Add NO_LPM quirk for SanDisk Extreme 55AE
    (stable-fixes).
  - thunderbolt: Do not double dequeue a configuration request
    (stable-fixes).
  - Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands
    (git-fixes).
  - rtc: Make rtc_time64_to_tm() support dates before 1970
    (stable-fixes).
  - net: lan743x: Fix memleak issue when GSO enabled (git-fixes).
  - accel/ivpu: Add handling of
    VPU_JSM_STATUS_MVNCI_CONTEXT_VIOLATION_HW (stable-fixes).
  - PCI/ASPM: Disable L1 before disabling L1 PM Substates
    (stable-fixes).
  - accel/ivpu: Update power island delays (stable-fixes).
  - accel/ivpu: Add initial Panther Lake support (stable-fixes).
  - commit 122402d

++++ libguestfs:

  - Update to version 1.56.0 (jsc#PED-12706)
    * Add support for Windows 2025 (thanks Ming Xie).
    * Add support for TencentOS (Denise Cheng).
    * Inspection of Ubuntu 22+ guests that use a split /usr
    configuration now works properly (thanks Jaroslav Spanko,
    Daniel Berrange).
    * Inspecting guests that have duplicated root mountpoints now
    works.
    * Inspection of SUSE Linux guests using btrfs snapshots now
    ignores snapshots that mirror content in the root filesystem
    (thanks Ming Xie).
    * Inspection of SUSE Linux >= 15 now returns the correct osinfo
    short name (eg. "sle15") (thanks Ming Xie).
    * New command_out and sh_out APIs which allow you to capture
    output from guest commands that generate more output than the
    protocol limit allows.
    * New btrfs_scrub_full API which runs a full Btrfs scrub,
    synchronously. It works more like fsck for other filesystems.
    * The fstrim API has been modified to work around several issues
    in upstream and RHEL 9 kernels related to XFS support (Eric
    Sandeen, Dave Chinner).
    * The existing e2fsck API has a new FORCENO option enabling use
    of the command line -n flag.
    * json-c is now required. This replaces Jansson which was
    previously used for parsing JSON input files.
    * OCaml ≥ 4.08 is now required.
    * When using ./configure --disable-daemon we no longer require
    augeas and hivex (thanks Mohamed Akram).
    * zfs-fuse support has been dropped. The project is unmaintained
    upstream (thanks Paul Bolle, Gwyn Ciesla, Timothée Ravier).
    * Fix compatibility with GNU gettext 0.25.
    * Fix dhcpcd failing on systemd-resolved stub (Thomas Wouters).
    * Add support for dhcpcd and sfdisk on Debian (Daniel Gomez).
    * Print the kernel utsname in debug output.
    * We no longer emit a false warning about BLKDISCARD when
    creating a block device.
    * If qemu-img(1) commands fail during snapshot creation, make
    sure we capture and print stderr from the qemu command (Cole
    Robinson).
    * For a complete list of changes and bug fixes see,
    https://libguestfs.org/guestfs-release-notes-1.56.1.html
  - bsc#1216986 - libguestfs: embeds /etc/hosts
    reproducible-builds.patch

++++ python313-core:

  - Update to 3.13.5:
  - Tests
  - gh-135120: Add test.support.subTests().
  - Library
  - gh-133967: Do not normalize locale name ‘C.UTF-8’ to
    ‘en_US.UTF-8’.
  - gh-135326: Restore support of integer-like objects with
    __index__() in random.getrandbits().
  - gh-135321: Raise a correct exception for values greater
    than 0x7fffffff for the BINSTRING opcode in the C
    implementation of pickle.
  - gh-135276: Backported bugfixes in zipfile.Path from
    zipp 3.23. Fixed .name, .stem and other basename-based
    properties on Windows when working with a zipfile on disk.
  - gh-134151: email: Fix TypeError in
    email.utils.decode_params() when sorting RFC 2231
    continuations that contain an unnumbered section.
  - gh-134152: email: Fix parsing of email message ID with
    invalid domain.
  - gh-127081: Fix libc thread safety issues with os by
    replacing getlogin with getlogin_r re-entrant version.
  - gh-131884: Fix formatting issues in json.dump() when both
    indent and skipkeys are used.
  - Core and Builtins
  - gh-135171: Roll back changes to generator and list
    comprehensions that went into 3.13.4 to fix gh-127682,
    but which involved semantic and bytecode changes not
    appropriate for a bugfix release.
  - C API
  - gh-134989: Fix Py_RETURN_NONE, Py_RETURN_TRUE and
    Py_RETURN_FALSE macros in the limited C API 3.11 and
    older: don’t treat Py_None, Py_True and Py_False as
    immortal. Patch by Victor Stinner.
  - gh-134989: Implement PyObject_DelAttr() and
    PyObject_DelAttrString() as macros in the limited C API
    3.12 and older. Patch by Victor Stinner.
  - Substantially rewritten doc-py38-to-py36.patch patch to be more
    flexible and covering even unexpected changes.

++++ nvidia-open-driver-G06-signed:

  - 60-nvidia-$flavor.conf
    * Don't try to load the driver if config and GSP firmware files are
    not available. Otherwise let the default install rule
    'install nvidia-drm /sbin/modprobe --ignore-install nvidia-drm' of
    50-nvidia.conf win, which comes together with config and GSP
    firmware files (package nvidia-common-G06).

++++ python313:

  - Update to 3.13.5:
  - Tests
  - gh-135120: Add test.support.subTests().
  - Library
  - gh-133967: Do not normalize locale name ‘C.UTF-8’ to
    ‘en_US.UTF-8’.
  - gh-135326: Restore support of integer-like objects with
    __index__() in random.getrandbits().
  - gh-135321: Raise a correct exception for values greater
    than 0x7fffffff for the BINSTRING opcode in the C
    implementation of pickle.
  - gh-135276: Backported bugfixes in zipfile.Path from
    zipp 3.23. Fixed .name, .stem and other basename-based
    properties on Windows when working with a zipfile on disk.
  - gh-134151: email: Fix TypeError in
    email.utils.decode_params() when sorting RFC 2231
    continuations that contain an unnumbered section.
  - gh-134152: email: Fix parsing of email message ID with
    invalid domain.
  - gh-127081: Fix libc thread safety issues with os by
    replacing getlogin with getlogin_r re-entrant version.
  - gh-131884: Fix formatting issues in json.dump() when both
    indent and skipkeys are used.
  - Core and Builtins
  - gh-135171: Roll back changes to generator and list
    comprehensions that went into 3.13.4 to fix gh-127682,
    but which involved semantic and bytecode changes not
    appropriate for a bugfix release.
  - C API
  - gh-134989: Fix Py_RETURN_NONE, Py_RETURN_TRUE and
    Py_RETURN_FALSE macros in the limited C API 3.11 and
    older: don’t treat Py_None, Py_True and Py_False as
    immortal. Patch by Victor Stinner.
  - gh-134989: Implement PyObject_DelAttr() and
    PyObject_DelAttrString() as macros in the limited C API
    3.12 and older. Patch by Victor Stinner.
  - Substantially rewritten doc-py38-to-py36.patch patch to be more
    flexible and covering even unexpected changes.

++++ python-argcomplete:

  - Remove executable bit on files installed outside of the path. (bsc#1244435)

++++ xfsprogs:

  - update to 6.14.0
  - xfs_scrub_all: localize the strings in the program
  - xfs_protofile: add messages to localization catalog
  - Makefile: inject package name/version/bugreport into pot file
  - xfs_scrub_all: rename source code to .py.in
  - xfs_protofile: rename source code to .py.in
  - xfs_repair: handling a block with bad crc, bad uuid, and bad magic number needs fixing
  - xfs_repair: fix stupid argument error in verify_inode_chunk
  - xfs_repair: fix infinite loop in longform_dir2_entry_check*
  - xfs_repair: fix crash in reset_rt_metadir_inodes
  - xfs_repair: don't recreate /quota metadir if there are no quota inodes
  - xfs_repair: fix wording of error message about leftover CoW blocks on the rt device
  - xfs_io: Add cachestat syscall support
  - xfs_io: Add RWF_DONTCACHE support to preadv2
  - xfs_io: Add RWF_DONTCACHE support to pwritev2
  - xfs_io: Add support for preadv2
  - make: remove the .extradep file in libxfs on "make clean"
  - xfs_{admin,repair},man5: tell the user to mount with nouuid for snapshots
  - xfsprogs: Fix mismatched return type of filesize()
  - xfs_io: don't fail FS_IOC_FSGETXATTR on filesystems that lack support
  - configure: additionally get icu-uc from pkg-config
  - xfs_scrub: use the display mountpoint for reporting file corruptions
  - xfs_scrub: don't warn about zero width joiner control characters
  - xfs_scrub: fix buffer overflow in string_escape
  - xfs_db: add command to copy directory trees out of filesystems
  - xfs_db: make listdir more generally useful
  - xfs_db: use an empty transaction to try to prevent livelocks in path_navigate
  - xfs_db: pass const pointers when we're not modifying them
  - mkfs: enable reflink on the realtime device
  - mkfs: validate CoW extent size hint when rtinherit is set
  - xfs_logprint: report realtime CUIs
  - xfs_repair: validate CoW extent size hint on rtinherit directories
  - xfs_repair: allow realtime files to have the reflink flag set
  - xfs_repair: rebuild the realtime refcount btree
  - xfs_repair: reject unwritten shared extents
  - xfs_repair: check existing realtime refcountbt entries against observed refcounts
  - xfs_repair: compute refcount data for the realtime groups
  - xfs_repair: find and mark the rtrefcountbt inode
  - xfs_repair: use realtime refcount btree data to check block types
  - xfs_repair: allow CoW staging extents in the realtime rmap records
  - xfs_spaceman: report health of the realtime refcount btree
  - xfs_db: add rtrefcount reservations to the rgresv command
  - xfs_db: copy the realtime refcount btree
  - xfs_db: support the realtime refcountbt
  - xfs_db: display the realtime refcount btree contents
  - man: document userspace API changes due to rt reflink
  - mkfs: create the realtime rmap inode
  - xfs_logprint: report realtime RUIs
  - xfs_repair: reserve per-AG space while rebuilding rt metadata
  - xfs_repair: rebuild the bmap btree for realtime files
  - xfs_repair: check for global free space concerns with default btree slack levels
  - xfs_repair: rebuild the realtime rmap btree
  - xfs_repair: always check realtime file mappings against incore info
  - xfs_repair: check existing realtime rmapbt entries against observed rmaps
  - xfs_repair: find and mark the rtrmapbt inodes
  - xfs_repair: refactor realtime inode check
  - xfs_repair: create a new set of incore rmap information for rt groups
  - xfs_repair: use realtime rmap btree data to check block types
  - xfs_repair: flag suspect long-format btree blocks
  - xfs_repair: tidy up rmap_diffkeys
  - xfs_spaceman: report health status of the realtime rmap btree
  - xfs_db: add an rgresv command
  - xfs_db: make fsmap query the realtime reverse mapping tree
  - xfs_db: copy the realtime rmap btree
  - xfs_db: support the realtime rmapbt
  - xfs_db: display the realtime rmap btree contents
  - xfs_db: don't abort when bmapping on a non-extents/bmbt fork
  - xfs_db: compute average btree height
  - man: document userspace API changes due to rt rmap
  - xfs_scrub: try harder to fill the bulkstat array with bulkstat()
  - xfs_scrub: ignore freed inodes when single-stepping during phase 3
  - xfs_scrub: hoist the phase3 bulkstat single stepping code
  - xfs_scrub: don't blow away new inodes in bulkstat_single_step
  - xfs_scrub: return early from bulkstat_for_inumbers if no bulkstat data
  - xfs_scrub: don't complain if bulkstat fails
  - xfs_scrub: don't
  - xfs_scrub: don't double-scan inodes during phase 3
  - xfs_scrub: actually iterate all the bulkstat records
  - xfs_scrub: selectively re-run bulkstat after re-running inumbers
  - xfs_scrub: remove flags argument from scrub_scan_all_inodes
  - xfs_scrub: call bulkstat directly if we're only scanning user files
  - xfs_scrub: don't report data loss in unlinked inodes twice
  - man: document new XFS_BULK_IREQ_METADIR flag to bulkstat
  - xfs_db: obfuscate rt superblock label when metadumping
  - mkfs,xfs_repair: don't pass a daddr as the flags argument
  - drop mkfs-fix-filesize-function-compilation-error-on-32-b.patch
  - now part of the release (merged in v6.14.0)

------------------------------------------------------------------
------------------  2025-6-10  -  Jun 10 2025  -------------------
------------------------------------------------------------------

++++ branding-SLE:

  - Merge all files from distributions-logos-SLE into
    distributions-logos-branding-SLE.

++++ python-kiwi:

  - Fixed rootfs size calculation with spare part
    In case a spare_part setup is combined with the root_clone feature,
    the size calculation for the rootfs did not take the cloning into
    account and lead to the wrong value. In addition when requesting
    the spare part to be last and no size information was given, the
    partition was not created at all. This commit fixes both defects
    and Fixes #2831

++++ iputils:

  - Security fix [bsc#1243772, CVE-2025-48964]
    * Fix  integer overflow in ping statistics via zero timestamp
    * Add iputils-CVE-2025-48964_01.patch
    * Add iputils-CVE-2025-48964_02.patch
    * Add iputils-CVE-2025-48964_03.patch
    * Add iputils-CVE-2025-48964_regression.patch

++++ kernel-default:

  - net: lan743x: Fix memleak issue when GSO enabled (CVE-2025-37909
    bsc#1243467).
  - vxlan: vnifilter: Fix unlocked deletion of default FDB entry
    (CVE-2025-37921 bsc#1243480).
  - commit 1e0ef1b
  - ucsi_debugfs_entry: restore u32 respectively s32 for int
    (git-fixes).
  - commit 94a62e7
  - tracing: Verify event formats that have "%*p.." (CVE-2025-37938
    bsc#1243544).
  - tracing: Have process_string() also allow arrays (git-fixes).
  - tracing: Check "%s" dereference via the field and not the
    TP_printk format (git-fixes).
  - tracing: Add "%s" check in test_event_printk() (git-fixes).
  - tracing: Add missing helper functions in event pointer
    dereference check (git-fixes).
  - tracing: Fix test_event_printk() to process entire print
    argument (git-fixes).
  - tracing: Add __print_dynamic_array() helper (git-fixes).
  - commit 4da5a05
  - usb: typec: ucsi: fix Clang -Wsign-conversion warning
    (git-fixes).
  - Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch.
  - commit f07681a
  - usb: acpi: Prevent null pointer dereference in
    usb_acpi_add_usb4_devlink() (git-fixes).
  - commit 31571ee
  - module: ensure that kobject_put() is safe for module type kobjects (CVE-2025-37995 bsc#1243827)
  - commit ca96390
  - ptp: ocp: Fix NULL dereference in Adva board SMA sysfs operations (CVE-2025-37910 bsc#1243468)
  - commit c0e3266
  - mkspec: Exclude rt flavor from kernel-syms dependencies (bsc#1244337).
  - commit 7c95ae0
  - powerpc/vas: Return -EINVAL if the offset is non-zero in mmap()
    (bsc#1244309 ltc#213790).
  - powerpc/powernv/memtrace: Fix out of bounds issue in memtrace
    mmap (bsc#1244309 ltc#213790).
  - commit 43c5814
  - xen/x86: fix initial memory balloon target (git-fixes).
  - commit af7a319
  - kABI: kabi fix after vsock/virtio: fix `rx_bytes` accounting
    (git-fixes).
  - commit d25e930
  - vsock/virtio: fix `rx_bytes` accounting for stream sockets
    (git-fixes).
  - commit 86c965e
  - Delete patches.suse/Restore-kABI-for-NVidia-vGPU-driver.patch.
  - commit 56249f7
  - gfs2: Don't start unnecessary transactions during log flush
    (bsc#1243993).
  - dlm: use SHUT_RDWR for SCTP shutdown (bsc#1228854).
  - dlm: mask sk_shutdown value (bsc#1228854).
  - commit 691de31
  - bpf: Search and add kfuncs in struct_ops prologue and epilogue
    (git-fixes).
  - selftests/bpf: Fix stdout race condition in traffic monitor
    (git-fixes).
  - selftests/bpf: Fix freplace_link segfault in tailcalls prog test
    (git-fixes).
  - selftests: bpf: test batch lookup on array of maps with holes
    (git-fixes).
  - bpf: skip non exist keys in generic_map_lookup_batch
    (git-fixes).
  - commit 63fb01b
  - selftests/bpf: Add distilled BTF test about marking
    BTF_IS_EMBEDDED (git-fixes).
  - libbpf: Fix incorrect traversal end type ID when marking
    BTF_IS_EMBEDDED (git-fixes).
  - libbpf: Fix return zero when elf_begin failed (git-fixes).
  - selftests/bpf: Fix btf leak on new btf alloc failure in
    btf_distill test (git-fixes).
  - libbpf: Fix segfault due to libelf functions not setting errno
    (git-fixes).
  - libbpf: Prevent compiler warnings/errors (git-fixes).
  - resolve_btfids: Fix compiler warnings (git-fixes).
  - commit f3a284f

++++ kernel-firmware-iwlwifi:

  - Update to version 20250609 (git commit 0d92efb540f4):
    * Revert "iwlwifi: add Bz/gl FW for core96-76 release"

++++ kernel-rt:

  - net: lan743x: Fix memleak issue when GSO enabled (CVE-2025-37909
    bsc#1243467).
  - vxlan: vnifilter: Fix unlocked deletion of default FDB entry
    (CVE-2025-37921 bsc#1243480).
  - commit 1e0ef1b
  - ucsi_debugfs_entry: restore u32 respectively s32 for int
    (git-fixes).
  - commit 94a62e7
  - tracing: Verify event formats that have "%*p.." (CVE-2025-37938
    bsc#1243544).
  - tracing: Have process_string() also allow arrays (git-fixes).
  - tracing: Check "%s" dereference via the field and not the
    TP_printk format (git-fixes).
  - tracing: Add "%s" check in test_event_printk() (git-fixes).
  - tracing: Add missing helper functions in event pointer
    dereference check (git-fixes).
  - tracing: Fix test_event_printk() to process entire print
    argument (git-fixes).
  - tracing: Add __print_dynamic_array() helper (git-fixes).
  - commit 4da5a05
  - usb: typec: ucsi: fix Clang -Wsign-conversion warning
    (git-fixes).
  - Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch.
  - commit f07681a
  - usb: acpi: Prevent null pointer dereference in
    usb_acpi_add_usb4_devlink() (git-fixes).
  - commit 31571ee
  - module: ensure that kobject_put() is safe for module type kobjects (CVE-2025-37995 bsc#1243827)
  - commit ca96390
  - ptp: ocp: Fix NULL dereference in Adva board SMA sysfs operations (CVE-2025-37910 bsc#1243468)
  - commit c0e3266
  - mkspec: Exclude rt flavor from kernel-syms dependencies (bsc#1244337).
  - commit 7c95ae0
  - powerpc/vas: Return -EINVAL if the offset is non-zero in mmap()
    (bsc#1244309 ltc#213790).
  - powerpc/powernv/memtrace: Fix out of bounds issue in memtrace
    mmap (bsc#1244309 ltc#213790).
  - commit 43c5814
  - xen/x86: fix initial memory balloon target (git-fixes).
  - commit af7a319
  - kABI: kabi fix after vsock/virtio: fix `rx_bytes` accounting
    (git-fixes).
  - commit d25e930
  - vsock/virtio: fix `rx_bytes` accounting for stream sockets
    (git-fixes).
  - commit 86c965e
  - Delete patches.suse/Restore-kABI-for-NVidia-vGPU-driver.patch.
  - commit 56249f7
  - gfs2: Don't start unnecessary transactions during log flush
    (bsc#1243993).
  - dlm: use SHUT_RDWR for SCTP shutdown (bsc#1228854).
  - dlm: mask sk_shutdown value (bsc#1228854).
  - commit 691de31
  - bpf: Search and add kfuncs in struct_ops prologue and epilogue
    (git-fixes).
  - selftests/bpf: Fix stdout race condition in traffic monitor
    (git-fixes).
  - selftests/bpf: Fix freplace_link segfault in tailcalls prog test
    (git-fixes).
  - selftests: bpf: test batch lookup on array of maps with holes
    (git-fixes).
  - bpf: skip non exist keys in generic_map_lookup_batch
    (git-fixes).
  - commit 63fb01b
  - selftests/bpf: Add distilled BTF test about marking
    BTF_IS_EMBEDDED (git-fixes).
  - libbpf: Fix incorrect traversal end type ID when marking
    BTF_IS_EMBEDDED (git-fixes).
  - libbpf: Fix return zero when elf_begin failed (git-fixes).
  - selftests/bpf: Fix btf leak on new btf alloc failure in
    btf_distill test (git-fixes).
  - libbpf: Fix segfault due to libelf functions not setting errno
    (git-fixes).
  - libbpf: Prevent compiler warnings/errors (git-fixes).
  - resolve_btfids: Fix compiler warnings (git-fixes).
  - commit f3a284f

++++ util-linux-systemd:

  - Fix libmount --no-canonicalize regression (boo#1244251,
    gh#util-linux/util-linux#3479,
    libmount-fix-no-canonicalize-regression.patch).

++++ gcc15:

  - Remove all %gcc_icecream mode cross-compilers and the corresponding
    icecream backend subpackages.  Instead use glibc-bootstrap only
    configs for cross-x86_64-gcc (ipxe,ovmf,qemu), cross-ppc64-gcc (qemu)
    and cross-arm-gcc (ovmf).

++++ util-linux:

  - Fix libmount --no-canonicalize regression (boo#1244251,
    gh#util-linux/util-linux#3479,
    libmount-fix-no-canonicalize-regression.patch).

++++ python-requests:

  - update to 2.32.4:
    * CVE-2024-47081 Fixed an issue where a maliciously crafted URL
    and trusted environment will retrieve credentials for the wrong
    hostname/machine from a netrc file
    * Numerous documentation improvements
    * Added support for pypy 3.11 for Linux and macOS.
    * Dropped support for pypy 3.9 following its end of support.
  - drop CVE-2024-47081.patch (merged upstream)

------------------------------------------------------------------
------------------  2025-6-9  -  Jun 9 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - s390/pci: Fix __pcilg_mio_inuser() inline assembly (git-fixes
    bsc#1244280).
  - commit d830b32
  - MyBS: Do not build kernel-obs-qa with limit_packages
    Fixes: 58e3f8c34b2b ("bs-upload-kernel: Pass limit_packages also on multibuild")
  - commit f4c6047
  - MyBS: Simplify qa_expr generation
    Start with a 0 which makes the expression valid even if there are no QA
    repositories (currently does not happen). Then separator is always
    needed.
  - commit e4c2851
  - KVM: s390: rename PROT_NONE to PROT_TYPE_DUMMY (git-fixes bsc#1244278).
  - commit fb0286b
  - uprobes/x86: Harden uretprobe syscall trampoline check
    (CVE-2025-22046 bsc#1241434).
  - commit 5cc86ac
  - MyBS: Correctly generate build flags for non-multibuild package limit
    (bsc# 1244241)
    Fixes: 0999112774fc ("MyBS: Use buildflags to set which package to build")
  - commit 27588c9
  - bs-upload-kernel: Pass limit_packages also on multibuild
    Fixes: 0999112774fc ("MyBS: Use buildflags to set which package to build")
    Fixes: 747f601d4156 ("bs-upload-kernel, MyBS, Buildresults: Support multibuild (JSC-SLE#5501, boo#1211226, bsc#1218184)")
  - commit 8ef486c
  - ftrace: Avoid potential division by zero in function_stat_show()
    (CVE-2025-21898 bsc#1240610).
  - commit 13235ba
  - x86/microcode/AMD: Fix __apply_microcode_amd()'s return value (git-fixes).
  - commit 2343c8f
  - sort series.conf
  - commit 7c822ea
  - tracing: Fix bad hist from corrupting named_triggers list
    (CVE-2025-21899 bsc#1240577).
  - commit b162509
  - ring-buffer: Validate the persistent meta data subbuf array
    (CVE-2025-21777 bsc#1238764).
  - commit b030dbe
  - x86/usercopy: Fix kernel-doc func param name in clean_cache_range()'s  description (git-fixes).
  - commit 2e19a8b
  - x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2 (git-fixes).
  - commit 895937c
  - x86/microcode/AMD: Extend the SHA check to Zen5, block loading of any  unreleased standalone Zen5 microcode patches (git-fixes).
  - commit a46ec06
  - x86/microcode/AMD: Add some forgotten models to the SHA check (git-fixes).
  - commit 5ed1d64
  - x86/microcode/AMD: Load only SHA256-checksummed patches (git-fixes).
  - commit c395380
  - x86/alternative: Remove unused header #defines (git-fixes).
  - commit 0ced93a
  - x86/idle: Remove MFENCEs for X86_BUG_CLFLUSH_MONITOR in mwait_idle_with_hints() and prefer_mwait_c1_over_halt() (git-fixes).
  - commit 1051216
  - x86/microcode/AMD: Add get_patch_level() (git-fixes).
  - commit 08a178d
  - x86/microcode/AMD: Get rid of the _load_microcode_amd() forward  declaration (git-fixes).
  - commit 563faf8
  - x86/microcode/AMD: Merge early_apply_microcode() into its single  callsite (git-fixes).
  - commit 409c545
  - x86/microcode/AMD: Remove unused save_microcode_in_initrd_amd() declarations (git-fixes).
  - commit 5d4cce2
  - x86/microcode/AMD: Remove ugly linebreak in __verify_patch_section()  signature (git-fixes).
  - commit dc8a454
  - x86/microcode/AMD: Have __apply_microcode_amd() return bool (git-fixes).
  - commit 3dd0b23
  - x86/microcode/AMD: Return bool from find_blobs_in_containers() (git-fixes).
  - commit 31a173d
  - Sort series.conf
  - commit 4948d54
  - iommu: Skip PASID validation for devices without PASID capability (bsc#1244100)
  - commit 913f1ca
  - selftests/bpf: Add selftest for may_goto (bsc#1241460
    CVE-2025-22087).
  - selftests/bpf: Introduce __load_if_JITed annotation for tests
    (bsc#1241460 CVE-2025-22087).
  - bpf: Fix array bounds error with may_goto (bsc#1241460
    CVE-2025-22087).
  - commit 4c36585
  - selftests/bpf: Check for timeout in perf_link test (git-fixes).
  - commit 73ccf26

++++ kernel-rt:

  - s390/pci: Fix __pcilg_mio_inuser() inline assembly (git-fixes
    bsc#1244280).
  - commit d830b32
  - MyBS: Do not build kernel-obs-qa with limit_packages
    Fixes: 58e3f8c34b2b ("bs-upload-kernel: Pass limit_packages also on multibuild")
  - commit f4c6047
  - MyBS: Simplify qa_expr generation
    Start with a 0 which makes the expression valid even if there are no QA
    repositories (currently does not happen). Then separator is always
    needed.
  - commit e4c2851
  - KVM: s390: rename PROT_NONE to PROT_TYPE_DUMMY (git-fixes bsc#1244278).
  - commit fb0286b
  - uprobes/x86: Harden uretprobe syscall trampoline check
    (CVE-2025-22046 bsc#1241434).
  - commit 5cc86ac
  - MyBS: Correctly generate build flags for non-multibuild package limit
    (bsc# 1244241)
    Fixes: 0999112774fc ("MyBS: Use buildflags to set which package to build")
  - commit 27588c9
  - bs-upload-kernel: Pass limit_packages also on multibuild
    Fixes: 0999112774fc ("MyBS: Use buildflags to set which package to build")
    Fixes: 747f601d4156 ("bs-upload-kernel, MyBS, Buildresults: Support multibuild (JSC-SLE#5501, boo#1211226, bsc#1218184)")
  - commit 8ef486c
  - ftrace: Avoid potential division by zero in function_stat_show()
    (CVE-2025-21898 bsc#1240610).
  - commit 13235ba
  - x86/microcode/AMD: Fix __apply_microcode_amd()'s return value (git-fixes).
  - commit 2343c8f
  - sort series.conf
  - commit 7c822ea
  - tracing: Fix bad hist from corrupting named_triggers list
    (CVE-2025-21899 bsc#1240577).
  - commit b162509
  - ring-buffer: Validate the persistent meta data subbuf array
    (CVE-2025-21777 bsc#1238764).
  - commit b030dbe
  - x86/usercopy: Fix kernel-doc func param name in clean_cache_range()'s  description (git-fixes).
  - commit 2e19a8b
  - x86/bugs: Make spectre user default depend on MITIGATION_SPECTRE_V2 (git-fixes).
  - commit 895937c
  - x86/microcode/AMD: Extend the SHA check to Zen5, block loading of any  unreleased standalone Zen5 microcode patches (git-fixes).
  - commit a46ec06
  - x86/microcode/AMD: Add some forgotten models to the SHA check (git-fixes).
  - commit 5ed1d64
  - x86/microcode/AMD: Load only SHA256-checksummed patches (git-fixes).
  - commit c395380
  - x86/alternative: Remove unused header #defines (git-fixes).
  - commit 0ced93a
  - x86/idle: Remove MFENCEs for X86_BUG_CLFLUSH_MONITOR in mwait_idle_with_hints() and prefer_mwait_c1_over_halt() (git-fixes).
  - commit 1051216
  - x86/microcode/AMD: Add get_patch_level() (git-fixes).
  - commit 08a178d
  - x86/microcode/AMD: Get rid of the _load_microcode_amd() forward  declaration (git-fixes).
  - commit 563faf8
  - x86/microcode/AMD: Merge early_apply_microcode() into its single  callsite (git-fixes).
  - commit 409c545
  - x86/microcode/AMD: Remove unused save_microcode_in_initrd_amd() declarations (git-fixes).
  - commit 5d4cce2
  - x86/microcode/AMD: Remove ugly linebreak in __verify_patch_section()  signature (git-fixes).
  - commit dc8a454
  - x86/microcode/AMD: Have __apply_microcode_amd() return bool (git-fixes).
  - commit 3dd0b23
  - x86/microcode/AMD: Return bool from find_blobs_in_containers() (git-fixes).
  - commit 31a173d
  - Sort series.conf
  - commit 4948d54
  - iommu: Skip PASID validation for devices without PASID capability (bsc#1244100)
  - commit 913f1ca
  - selftests/bpf: Add selftest for may_goto (bsc#1241460
    CVE-2025-22087).
  - selftests/bpf: Introduce __load_if_JITed annotation for tests
    (bsc#1241460 CVE-2025-22087).
  - bpf: Fix array bounds error with may_goto (bsc#1241460
    CVE-2025-22087).
  - commit 4c36585
  - selftests/bpf: Check for timeout in perf_link test (git-fixes).
  - commit 73ccf26

++++ libgcrypt:

  - Security fix [bsc#1221107, CVE-2024-2236]
    * Add --enable-marvin-workaround to spec to enable workaround
    * Fix  timing based side-channel in RSA implementation ( Marvin attack )
    * Add libgcrypt-CVE-2024-2236.patch

++++ python313-core:

  - Update to 3.13.4:
  - Security
  - gh-135034: Fixes multiple issues that allowed tarfile
    extraction filters (filter="data" and filter="tar") to be
    bypassed using crafted symlinks and hard links.
    Addresses CVE-2024-12718 (bsc#1244056), CVE-2025-4138
    (bsc#1244059), CVE-2025-4330 (bsc#1244060), and
    CVE-2025-4517 (bsc#1244032). Also addresses CVE-2025-4435
    (gh#135034, bsc#1244061).
  - gh-133767: Fix use-after-free in the “unicode-escape”
    decoder with a non-“strict” error handler (CVE-2025-4516,
    bsc#1243273).
  - gh-128840: Short-circuit the processing of long IPv6
    addresses early in ipaddress to prevent excessive memory
    consumption and a minor denial-of-service.
  - Library
  - gh-134718: ast.dump() now only omits None and [] values if
    they are default values.
  - gh-128840: Fix parsing long IPv6 addresses with embedded
    IPv4 address.
  - gh-134696: Built-in HACL* and OpenSSL implementations of
    hash function constructors now correctly accept the same
    documented named arguments. For instance, md5() could be
    previously invoked as md5(data=data) or md5(string=string)
    depending on the underlying implementation but these calls
    were not compatible. Patch by Bénédikt Tran.
  - gh-134210: curses.window.getch() now correctly handles
    signals. Patch by Bénédikt Tran.
  - gh-80334: multiprocessing.freeze_support() now checks for
    work on any “spawn” start method platform rather than only
    on Windows.
  - gh-114177: Fix asyncio to not close subprocess pipes which
    would otherwise error out when the event loop is already
    closed.
  - gh-134152: Fixed UnboundLocalError that could occur during
    email header parsing if an expected trailing delimiter is
    missing in some contexts.
  - gh-62184: Remove import of C implementation of io.FileIO
    from Python implementation which has its own implementation
  - gh-133982: Emit RuntimeWarning in the Python implementation
    of io when the file-like object is not closed explicitly in
    the presence of multiple I/O layers.
  - gh-133890: The tarfile module now handles
    UnicodeEncodeError in the same way as OSError when cannot
    extract a member.
  - gh-134097: Fix interaction of the new REPL and -X
    showrefcount command line option.
  - gh-133889: The generated directory listing page in
    http.server.SimpleHTTPRequestHandler now only shows the
    decoded path component of the requested URL, and not the
    query and fragment.
  - gh-134098: Fix handling paths that end with
    a percent-encoded slash (%2f or %2F) in
    http.server.SimpleHTTPRequestHandler.
  - gh-134062: ipaddress: fix collisions in __hash__() for
    IPv4Network and IPv6Network objects.
  - gh-133745: In 3.13.3 we accidentally changed the signature
    of the asyncio create_task() family of methods and how it
    calls a custom task factory in a backwards incompatible
    way. Since some 3rd party libraries have already made
    changes to work around the issue that might break if
    we simply reverted the changes, we’re instead changing
    things to be backwards compatible with 3.13.2 while still
    supporting those workarounds for 3.13.3. In particular, the
    special-casing of name and context is back (until 3.14) and
    consequently eager tasks may still find that their name
    hasn’t been set before they execute their first yielding
    await.
  - gh-71253: Raise ValueError in open() if opener returns a
    negative file-descriptor in the Python implementation of io
    to match the C implementation.
  - gh-77057: Fix handling of invalid markup declarations in
    html.parser.HTMLParser.
  - gh-133489: random.getrandbits() can now generate more that
    231 bits. random.randbytes() can now generate more that 256
    MiB.
  - gh-133290: Fix attribute caching issue when setting
    ctypes._Pointer._type_ in the undocumented and deprecated
    ctypes.SetPointerType() function and the undocumented
    set_type() method.
  - gh-132876: ldexp() on Windows doesn’t round subnormal
    results before Windows 11, but should. Python’s
    math.ldexp() wrapper now does round them, so results may
    change slightly, in rare cases of very small results, on
    Windows versions before 11.
  - gh-133089: Use original timeout value for
    subprocess.TimeoutExpired when the func subprocess.run()
    is called with a timeout instead of sometimes a confusing
    partial remaining time out value used internally on the
    final wait().
  - gh-133009: xml.etree.ElementTree: Fix a crash in
    Element.__deepcopy__ when the element is concurrently
    mutated. Patch by Bénédikt Tran.
  - gh-132995: Bump the version of pip bundled in ensurepip to
    version 25.1.1
  - gh-132017: Fix error when pyrepl is suspended, then resumed
    and terminated.
  - gh-132673: Fix a crash when using _align_ = 0 and _fields_
    = [] in a ctypes.Structure.
  - gh-132527: Include the valid typecode ‘w’ in the error
    message when an invalid typecode is passed to array.array.
  - gh-132439: Fix PyREPL on Windows: characters entered via
    AltGr are swallowed. Patch by Chris Eibl.
  - gh-132429: Fix support of Bluetooth sockets on NetBSD and
    DragonFly BSD.
  - gh-132106: QueueListener.start now raises a RuntimeError if
    the listener is already started.
  - gh-132417: Fix a NULL pointer dereference when a C function
    called using ctypes with restype py_object returns NULL.
  - gh-132385: Fix instance error suggestions trigger potential
    exceptions in object.__getattr__() in traceback.
  - gh-132308: A traceback.TracebackException now correctly
    renders the __context__ and __cause__ attributes from
    falsey Exception, and the exceptions attribute from falsey
    ExceptionGroup.
  - gh-132250: Fixed the SystemError in cProfile when locating
    the actual C function of a method raises an exception.
  - gh-132063: Prevent exceptions that evaluate as
    falsey (namely, when their __bool__ method returns
    False or their __len__ method returns 0) from being
    ignored by concurrent.futures.ProcessPoolExecutor and
    concurrent.futures.ThreadPoolExecutor.
  - gh-119605: Respect follow_wrapped for __init__() and
    __new__() methods when getting the class signature for a
    class with inspect.signature(). Preserve class signature
    after wrapping with warnings.deprecated(). Patch by Xuehai
    Pan.
  - gh-91555: Ignore log messages generated during handling of
    log messages, to avoid deadlock or infinite recursion.
  - gh-131434: Improve error reporting for incorrect format in
    time.strptime().
  - gh-131127: Systems using LibreSSL now successfully build.
  - gh-130999: Avoid exiting the new REPL and offer suggestions
    even if there are non-string candidates when errors occur.
  - gh-130941: Fix configparser.ConfigParser parsing empty
    interpolation with allow_no_value set to True.
  - gh-129098: Fix REPL traceback reporting when using
    compile() with an inexisting file. Patch by Bénédikt Tran.
  - gh-130631: http.cookiejar.join_header_words() is now more
    similar to the original Perl version. It now quotes the
    same set of characters and always quote values that end
    with "\n".
  - gh-129719: Fix missing socket.CAN_RAW_ERR_FILTER constant
    in the socket module on Linux systems. It was missing since
    Python 3.11.
  - gh-124096: Turn on virtual terminal mode and enable
    bracketed paste in REPL on Windows console. (If the
    terminal does not support bracketed paste, enabling it does
    nothing.)
  - gh-122559: Remove __reduce__() and __reduce_ex__() methods
    that always raise TypeError in the C implementation
    of io.FileIO, io.BufferedReader, io.BufferedWriter
    and io.BufferedRandom and replace them with default
    __getstate__() methods that raise TypeError. This restores
    fine details of behavior of Python 3.11 and older versions.
  - gh-122179: hashlib.file_digest() now raises BlockingIOError
    when no data is available during non-blocking I/O. Before,
    it added spurious null bytes to the digest.
  - gh-86155: html.parser.HTMLParser.close() no longer loses
    data when the <script> tag is not closed. Patch by Waylan
    Limberg.
  - gh-69426: Fix html.parser.HTMLParser to not unescape
    character entities in attribute values if they are followed
    by an ASCII alphanumeric or an equals sign.
  - bpo-44172: Keep a reference to original curses windows in
    subwindows so that the original window does not get deleted
    before subwindows.
  - Tests
  - gh-133744: Fix multiprocessing interrupt test. Add an event
    to synchronize the parent process with the child process:
    wait until the child process starts sleeping. Patch by
    Victor Stinner.
  - gh-133639: Fix
    TestPyReplAutoindent.test_auto_indent_default() doesn’t run
    input_code.
  - gh-133131: The iOS testbed will now select the most
    recently released “SE-class” device for testing if a device
    isn’t explicitly specified.
  - gh-109981: The test helper that counts the list of open
    file descriptors now uses the optimised /dev/fd approach on
    all Apple platforms, not just macOS. This avoids crashes
    caused by guarded file descriptors.
  - IDLE
  - gh-112936: fix IDLE: no Shell menu item in single-process
    mode.
  - Documentation
  - gh-107006: Move documentation and example code for
    threading.local from its docstring to the official docs.
  - Core and Builtins
  - gh-134908: Fix crash when iterating over lines in a text
    file on the free threaded build.
  - gh-127682: No longer call __iter__ twice in list
    comprehensions. This brings the behavior of list
    comprehensions in line with other forms of iteration
  - gh-134381: Fix RuntimeError when using a not-started
    threading.Thread after calling os.fork()
  - gh-128066: Fixes an edge case where PyREPL improperly threw
    an error when Python is invoked on a read only filesystem
    while trying to write history file entries.
  - gh-134100: Fix a use-after-free bug that occurs when an
    imported module isn’t in sys.modules after its initial
    import. Patch by Nico-Posada.
  - gh-133703: Fix hashtable in dict can be bigger than
    intended in some situations.
  - gh-132869: Fix crash in the free threading build when
    accessing an object attribute that may be concurrently
    inserted or deleted.
  - gh-132762: fromkeys() no longer loops forever when adding
    a small set of keys to a large base dict. Patch by Angela
    Liss.
  - gh-133543: Fix a possible memory leak that could occur when
    directly accessing instance dictionaries (__dict__) that
    later become part of a reference cycle.
  - gh-133516: Raise ValueError when constants True, False or
    None are used as an identifier after NFKC normalization.
  - gh-133441: Fix crash upon setting an attribute with a dict
    subclass. Patch by Victor Stinner.
  - gh-132942: Fix two races in the type lookup cache. This
    affected the free-threaded build and could cause crashes
    (apparently quite difficult to trigger).
  - gh-132713: Fix repr(list) race condition: hold a strong
    reference to the item while calling repr(item). Patch by
    Victor Stinner.
  - gh-132747: Fix a crash when calling __get__() of a method
    with a None second argument.
  - gh-132542: Update Thread.native_id after fork(2) to ensure
    accuracy. Patch by Noam Cohen.
  - gh-124476: Fix decoding from the locale encoding in the
    C.UTF-8 locale.
  - gh-131927: Compiler warnings originating from the same
    module and line number are now only emitted once, matching
    the behaviour of warnings emitted from user code. This can
    also be configured with warnings filters.
  - gh-127682: No longer call __iter__ twice when creating and
    executing a generator expression. Creating a generator
    expression from a non-interable will raise only when the
    generator expression is executed. This brings the behavior
    of generator expressions in line with other generators.
  - gh-131878: Handle uncaught exceptions in the main input
    loop for the new REPL.
  - gh-131878: Fix support of unicode characters with two or
    more codepoints on Windows in the new REPL.
  - gh-130804: Fix support of unicode characters on Windows in
    the new REPL.
  - gh-130070: Fixed an assertion error for exec() passed a
    string source and a non-None closure. Patch by Bartosz
    Sławecki.
  - gh-129958: Fix a bug that was allowing newlines
    inconsitently in format specifiers for single-quoted
    f-strings. Patch by Pablo Galindo.
  - C API
  - gh-132909: Fix an overflow when handling the K format in
    Py_BuildValue(). Patch by Bénédikt Tran.
  - Remove upstreamed patches:
  - CVE-2025-4516-DecodeError-handler.patch
  - gh-132535-rsrc-warn-test_timeout.patch

++++ sqlite3:

  - Update to 3.50 (3.50.1):
    * Improved handling and robust output of control characters
    * sqlite3_rsync no longer requires WAL mode and needs less
    bandwidth
    * Bug fixes and optimized JSON handling
    * Performance optimizations and developer visible fixes

++++ nvidia-open-driver-G06-signed:

  - Drop persistent-nvidia-id-string.patch - solved via make params instead

++++ perl:

  - Replace usage of %jobs for reproducible builds (boo#1237231)
  - Add perl-fixed-uname.patch to not store kernel version (boo#1230137)

++++ python313:

  - Update to 3.13.4:
  - Security
  - gh-135034: Fixes multiple issues that allowed tarfile
    extraction filters (filter="data" and filter="tar") to be
    bypassed using crafted symlinks and hard links.
    Addresses CVE-2024-12718 (bsc#1244056), CVE-2025-4138
    (bsc#1244059), CVE-2025-4330 (bsc#1244060), and
    CVE-2025-4517 (bsc#1244032). Also addresses CVE-2025-4435
    (gh#135034, bsc#1244061).
  - gh-133767: Fix use-after-free in the “unicode-escape”
    decoder with a non-“strict” error handler (CVE-2025-4516,
    bsc#1243273).
  - gh-128840: Short-circuit the processing of long IPv6
    addresses early in ipaddress to prevent excessive memory
    consumption and a minor denial-of-service.
  - Library
  - gh-134718: ast.dump() now only omits None and [] values if
    they are default values.
  - gh-128840: Fix parsing long IPv6 addresses with embedded
    IPv4 address.
  - gh-134696: Built-in HACL* and OpenSSL implementations of
    hash function constructors now correctly accept the same
    documented named arguments. For instance, md5() could be
    previously invoked as md5(data=data) or md5(string=string)
    depending on the underlying implementation but these calls
    were not compatible. Patch by Bénédikt Tran.
  - gh-134210: curses.window.getch() now correctly handles
    signals. Patch by Bénédikt Tran.
  - gh-80334: multiprocessing.freeze_support() now checks for
    work on any “spawn” start method platform rather than only
    on Windows.
  - gh-114177: Fix asyncio to not close subprocess pipes which
    would otherwise error out when the event loop is already
    closed.
  - gh-134152: Fixed UnboundLocalError that could occur during
    email header parsing if an expected trailing delimiter is
    missing in some contexts.
  - gh-62184: Remove import of C implementation of io.FileIO
    from Python implementation which has its own implementation
  - gh-133982: Emit RuntimeWarning in the Python implementation
    of io when the file-like object is not closed explicitly in
    the presence of multiple I/O layers.
  - gh-133890: The tarfile module now handles
    UnicodeEncodeError in the same way as OSError when cannot
    extract a member.
  - gh-134097: Fix interaction of the new REPL and -X
    showrefcount command line option.
  - gh-133889: The generated directory listing page in
    http.server.SimpleHTTPRequestHandler now only shows the
    decoded path component of the requested URL, and not the
    query and fragment.
  - gh-134098: Fix handling paths that end with
    a percent-encoded slash (%2f or %2F) in
    http.server.SimpleHTTPRequestHandler.
  - gh-134062: ipaddress: fix collisions in __hash__() for
    IPv4Network and IPv6Network objects.
  - gh-133745: In 3.13.3 we accidentally changed the signature
    of the asyncio create_task() family of methods and how it
    calls a custom task factory in a backwards incompatible
    way. Since some 3rd party libraries have already made
    changes to work around the issue that might break if
    we simply reverted the changes, we’re instead changing
    things to be backwards compatible with 3.13.2 while still
    supporting those workarounds for 3.13.3. In particular, the
    special-casing of name and context is back (until 3.14) and
    consequently eager tasks may still find that their name
    hasn’t been set before they execute their first yielding
    await.
  - gh-71253: Raise ValueError in open() if opener returns a
    negative file-descriptor in the Python implementation of io
    to match the C implementation.
  - gh-77057: Fix handling of invalid markup declarations in
    html.parser.HTMLParser.
  - gh-133489: random.getrandbits() can now generate more that
    231 bits. random.randbytes() can now generate more that 256
    MiB.
  - gh-133290: Fix attribute caching issue when setting
    ctypes._Pointer._type_ in the undocumented and deprecated
    ctypes.SetPointerType() function and the undocumented
    set_type() method.
  - gh-132876: ldexp() on Windows doesn’t round subnormal
    results before Windows 11, but should. Python’s
    math.ldexp() wrapper now does round them, so results may
    change slightly, in rare cases of very small results, on
    Windows versions before 11.
  - gh-133089: Use original timeout value for
    subprocess.TimeoutExpired when the func subprocess.run()
    is called with a timeout instead of sometimes a confusing
    partial remaining time out value used internally on the
    final wait().
  - gh-133009: xml.etree.ElementTree: Fix a crash in
    Element.__deepcopy__ when the element is concurrently
    mutated. Patch by Bénédikt Tran.
  - gh-132995: Bump the version of pip bundled in ensurepip to
    version 25.1.1
  - gh-132017: Fix error when pyrepl is suspended, then resumed
    and terminated.
  - gh-132673: Fix a crash when using _align_ = 0 and _fields_
    = [] in a ctypes.Structure.
  - gh-132527: Include the valid typecode ‘w’ in the error
    message when an invalid typecode is passed to array.array.
  - gh-132439: Fix PyREPL on Windows: characters entered via
    AltGr are swallowed. Patch by Chris Eibl.
  - gh-132429: Fix support of Bluetooth sockets on NetBSD and
    DragonFly BSD.
  - gh-132106: QueueListener.start now raises a RuntimeError if
    the listener is already started.
  - gh-132417: Fix a NULL pointer dereference when a C function
    called using ctypes with restype py_object returns NULL.
  - gh-132385: Fix instance error suggestions trigger potential
    exceptions in object.__getattr__() in traceback.
  - gh-132308: A traceback.TracebackException now correctly
    renders the __context__ and __cause__ attributes from
    falsey Exception, and the exceptions attribute from falsey
    ExceptionGroup.
  - gh-132250: Fixed the SystemError in cProfile when locating
    the actual C function of a method raises an exception.
  - gh-132063: Prevent exceptions that evaluate as
    falsey (namely, when their __bool__ method returns
    False or their __len__ method returns 0) from being
    ignored by concurrent.futures.ProcessPoolExecutor and
    concurrent.futures.ThreadPoolExecutor.
  - gh-119605: Respect follow_wrapped for __init__() and
    __new__() methods when getting the class signature for a
    class with inspect.signature(). Preserve class signature
    after wrapping with warnings.deprecated(). Patch by Xuehai
    Pan.
  - gh-91555: Ignore log messages generated during handling of
    log messages, to avoid deadlock or infinite recursion.
  - gh-131434: Improve error reporting for incorrect format in
    time.strptime().
  - gh-131127: Systems using LibreSSL now successfully build.
  - gh-130999: Avoid exiting the new REPL and offer suggestions
    even if there are non-string candidates when errors occur.
  - gh-130941: Fix configparser.ConfigParser parsing empty
    interpolation with allow_no_value set to True.
  - gh-129098: Fix REPL traceback reporting when using
    compile() with an inexisting file. Patch by Bénédikt Tran.
  - gh-130631: http.cookiejar.join_header_words() is now more
    similar to the original Perl version. It now quotes the
    same set of characters and always quote values that end
    with "\n".
  - gh-129719: Fix missing socket.CAN_RAW_ERR_FILTER constant
    in the socket module on Linux systems. It was missing since
    Python 3.11.
  - gh-124096: Turn on virtual terminal mode and enable
    bracketed paste in REPL on Windows console. (If the
    terminal does not support bracketed paste, enabling it does
    nothing.)
  - gh-122559: Remove __reduce__() and __reduce_ex__() methods
    that always raise TypeError in the C implementation
    of io.FileIO, io.BufferedReader, io.BufferedWriter
    and io.BufferedRandom and replace them with default
    __getstate__() methods that raise TypeError. This restores
    fine details of behavior of Python 3.11 and older versions.
  - gh-122179: hashlib.file_digest() now raises BlockingIOError
    when no data is available during non-blocking I/O. Before,
    it added spurious null bytes to the digest.
  - gh-86155: html.parser.HTMLParser.close() no longer loses
    data when the <script> tag is not closed. Patch by Waylan
    Limberg.
  - gh-69426: Fix html.parser.HTMLParser to not unescape
    character entities in attribute values if they are followed
    by an ASCII alphanumeric or an equals sign.
  - bpo-44172: Keep a reference to original curses windows in
    subwindows so that the original window does not get deleted
    before subwindows.
  - Tests
  - gh-133744: Fix multiprocessing interrupt test. Add an event
    to synchronize the parent process with the child process:
    wait until the child process starts sleeping. Patch by
    Victor Stinner.
  - gh-133639: Fix
    TestPyReplAutoindent.test_auto_indent_default() doesn’t run
    input_code.
  - gh-133131: The iOS testbed will now select the most
    recently released “SE-class” device for testing if a device
    isn’t explicitly specified.
  - gh-109981: The test helper that counts the list of open
    file descriptors now uses the optimised /dev/fd approach on
    all Apple platforms, not just macOS. This avoids crashes
    caused by guarded file descriptors.
  - IDLE
  - gh-112936: fix IDLE: no Shell menu item in single-process
    mode.
  - Documentation
  - gh-107006: Move documentation and example code for
    threading.local from its docstring to the official docs.
  - Core and Builtins
  - gh-134908: Fix crash when iterating over lines in a text
    file on the free threaded build.
  - gh-127682: No longer call __iter__ twice in list
    comprehensions. This brings the behavior of list
    comprehensions in line with other forms of iteration
  - gh-134381: Fix RuntimeError when using a not-started
    threading.Thread after calling os.fork()
  - gh-128066: Fixes an edge case where PyREPL improperly threw
    an error when Python is invoked on a read only filesystem
    while trying to write history file entries.
  - gh-134100: Fix a use-after-free bug that occurs when an
    imported module isn’t in sys.modules after its initial
    import. Patch by Nico-Posada.
  - gh-133703: Fix hashtable in dict can be bigger than
    intended in some situations.
  - gh-132869: Fix crash in the free threading build when
    accessing an object attribute that may be concurrently
    inserted or deleted.
  - gh-132762: fromkeys() no longer loops forever when adding
    a small set of keys to a large base dict. Patch by Angela
    Liss.
  - gh-133543: Fix a possible memory leak that could occur when
    directly accessing instance dictionaries (__dict__) that
    later become part of a reference cycle.
  - gh-133516: Raise ValueError when constants True, False or
    None are used as an identifier after NFKC normalization.
  - gh-133441: Fix crash upon setting an attribute with a dict
    subclass. Patch by Victor Stinner.
  - gh-132942: Fix two races in the type lookup cache. This
    affected the free-threaded build and could cause crashes
    (apparently quite difficult to trigger).
  - gh-132713: Fix repr(list) race condition: hold a strong
    reference to the item while calling repr(item). Patch by
    Victor Stinner.
  - gh-132747: Fix a crash when calling __get__() of a method
    with a None second argument.
  - gh-132542: Update Thread.native_id after fork(2) to ensure
    accuracy. Patch by Noam Cohen.
  - gh-124476: Fix decoding from the locale encoding in the
    C.UTF-8 locale.
  - gh-131927: Compiler warnings originating from the same
    module and line number are now only emitted once, matching
    the behaviour of warnings emitted from user code. This can
    also be configured with warnings filters.
  - gh-127682: No longer call __iter__ twice when creating and
    executing a generator expression. Creating a generator
    expression from a non-interable will raise only when the
    generator expression is executed. This brings the behavior
    of generator expressions in line with other generators.
  - gh-131878: Handle uncaught exceptions in the main input
    loop for the new REPL.
  - gh-131878: Fix support of unicode characters with two or
    more codepoints on Windows in the new REPL.
  - gh-130804: Fix support of unicode characters on Windows in
    the new REPL.
  - gh-130070: Fixed an assertion error for exec() passed a
    string source and a non-None closure. Patch by Bartosz
    Sławecki.
  - gh-129958: Fix a bug that was allowing newlines
    inconsitently in format specifiers for single-quoted
    f-strings. Patch by Pablo Galindo.
  - C API
  - gh-132909: Fix an overflow when handling the K format in
    Py_BuildValue(). Patch by Bénédikt Tran.
  - Remove upstreamed patches:
  - CVE-2025-4516-DecodeError-handler.patch
  - gh-132535-rsrc-warn-test_timeout.patch

++++ python-maturin:

  - Update to 1.8.7
    * Allow specifying compression method and level, in both `build`
    and `develop` modes
    gh#PyO3/maturin#2625

------------------------------------------------------------------
------------------  2025-6-8  -  Jun 8 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add dependency for isomd5sum for iso images and set in kiwi-settings
    This ensures that isomd5sum is pulled into the environment for ISO image
    builds, and the updated settings makes it so that kiwi boxes will use it.

++++ kernel-default:

  - ASoC: Intel: avs: Verify content returned by parse_int_array()
    (git-fixes).
  - ASoC: Intel: avs: Fix deadlock when the failing IPC is SET_D0IX
    (git-fixes).
  - ASoC: codecs: hda: Fix RPM usage count underflow (git-fixes).
  - ASoC: ti: omap-hdmi: Re-add dai_link->platform to fix card init
    (git-fixes).
  - commit 6f4de93
  - drm/xe: Rework eviction rejection of bound external bos
    (git-fixes).
  - commit ad6b6b2

++++ kernel-rt:

  - ASoC: Intel: avs: Verify content returned by parse_int_array()
    (git-fixes).
  - ASoC: Intel: avs: Fix deadlock when the failing IPC is SET_D0IX
    (git-fixes).
  - ASoC: codecs: hda: Fix RPM usage count underflow (git-fixes).
  - ASoC: ti: omap-hdmi: Re-add dai_link->platform to fix card init
    (git-fixes).
  - commit 6f4de93
  - drm/xe: Rework eviction rejection of bound external bos
    (git-fixes).
  - commit ad6b6b2

++++ linux-glibc-devel:

  - Update to SL-16.0 git branch based on 6.12 kernel (bsc#1244066)

++++ python-click:

  - Add click-8.2.1-clirunner.patch to fix clirunner breaking other
    modules' tests, cf. github.com/pallets/click/issues/2939

------------------------------------------------------------------
------------------  2025-6-7  -  Jun 7 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - usb: misc: onboard_usb_dev: fix build warning for
    CONFIG_USB_ONBOARD_DEV_USB5744=n (git-fixes).
  - drm/xe: remove unmatched xe_vm_unlock() from
    __xe_exec_queue_init() (git-fixes).
  - commit cb5e053
  - spi: bcm63xx-hsspi: fix shared reset (git-fixes).
  - spi: bcm63xx-spi: fix shared reset (git-fixes).
  - regulator: max14577: Add error check for max14577_read_reg()
    (git-fixes).
  - pwm: axi-pwmgen: fix missing separate external clock
    (git-fixes).
  - USB: typec: fix const issue in typec_match() (git-fixes).
  - USB: gadget: udc: fix const issue in gadget_match_driver()
    (git-fixes).
  - USB: serial: bus: fix const issue in usb_serial_device_match()
    (git-fixes).
  - usb: usbtmc: Fix timeout value in get_stb (git-fixes).
  - usb: usbtmc: Fix read_stb function and get_stb ioctl
    (git-fixes).
  - usb: misc: onboard_usb_dev: Fix usb5744 initialization sequence
    (git-fixes).
  - usb: cdnsp: Fix issue with detecting command completion event
    (git-fixes).
  - usb: cdnsp: Fix issue with detecting USB 3.2 speed (git-fixes).
  - usb: Flush altsetting 0 endpoints before reinitializating them
    after reset (git-fixes).
  - usb: typec: tcpm: move tcpm_queue_vdm_unlocked to asynchronous
    work (git-fixes).
  - usb: typec: tcpm/tcpci_maxim: Fix bounds check in process_rx()
    (git-fixes).
  - thunderbolt: Fix a logic error in wake on connect (git-fixes).
  - usb: acpi: Prevent null pointer dereference in
    usb_acpi_add_usb4_devlink() (git-fixes).
  - usb: renesas_usbhs: Reorder clock handling and power management
    in probe (git-fixes).
  - tty: serial: 8250_omap: fix TX with DMA for am33xx (git-fixes).
  - vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
    (git-fixes).
  - serial: jsm: fix NPE during jsm_uart_port_init (git-fixes).
  - serial: Fix potential null-ptr-deref in mlb_usio_probe()
    (git-fixes).
  - iio: adc: ti-ads1298: Kconfig: add kfifo dependency to fix
    module build (git-fixes).
  - iio: adc: mcp3911: fix device dependent mappings for conversion
    result registers (git-fixes).
  - iio: adc: PAC1934: fix typo in documentation link (git-fixes).
  - staging: iio: ad5933: Correct settling cycles encoding per
    datasheet (git-fixes).
  - iio: adc: ad7124: Fix 3dB filter frequency reading (git-fixes).
  - iio: filter: admv8818: Support frequencies >= 2^32 (git-fixes).
  - iio: filter: admv8818: fix range calculation (git-fixes).
  - iio: filter: admv8818: fix integer overflow (git-fixes).
  - iio: filter: admv8818: fix band 4, state 15 (git-fixes).
  - VMCI: fix race between vmci_host_setup_notify and
    vmci_ctx_unset_notify (git-fixes).
  - mei: vsc: Cast tx_buf to (__be32 *) when passed to
    cpu_to_be32_array() (git-fixes).
  - iio: accel: fxls8962af: Fix temperature scan element sign
    (git-fixes).
  - iio: adc: ad7944: mask high bits on direct read (git-fixes).
  - iio: imu: inv_icm42600: Fix temperature calculation (git-fixes).
  - iio: adc: ad7606_spi: fix reg write value mask (git-fixes).
  - bus: mhi: host: Fix conflict between power_up and SYSERR
    (git-fixes).
  - bus: mhi: ep: Update read pointer only after buffer is written
    (git-fixes).
  - fpga: fix potential null pointer deref in
    fpga_mgr_test_img_load_sgt() (git-fixes).
  - sysfb: Fix screen_info type check for VGA (git-fixes).
  - accel/ivpu: Use dma_resv_lock() instead of a custom mutex
    (git-fixes).
  - drm/panel-simple: fix the warnings for the Evervision VGG644804
    (git-fixes).
  - accel/ivpu: Improve buffer object logging (git-fixes).
  - dummycon: Trigger redraw when switching consoles with deferred
    takeover (git-fixes).
  - drm/xe: Create LRC BO without VM (git-fixes).
  - drm/xe/guc_submit: add back fix (git-fixes).
  - drm/xe/sched: stop re-submitting signalled jobs (git-fixes).
  - drm/xe/vm: move rebind_work init earlier (git-fixes).
  - drm/i915/guc: Handle race condition where wakeref count drops
    below 0 (git-fixes).
  - drm/i915/psr: Fix using wrong mask in REG_FIELD_PREP
    (git-fixes).
  - drm/i915/guc: Check if expecting reply before decrementing
    outstanding_submission_g2h (git-fixes).
  - drm/amd/display: Add null pointer check for
    get_first_active_display() (git-fixes).
  - drm/xe: Make xe_gt_freq part of the Documentation (git-fixes).
  - drm/i915/gem: Allow EXEC_CAPTURE on recoverable contexts on DG1
    (git-fixes).
  - PM: sleep: Fix power.is_suspended cleanup for direct-complete
    devices (git-fixes).
  - net: wwan: t7xx: Fix napi rx poll issue (git-fixes).
  - Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
    (git-fixes).
  - Bluetooth: hci_qca: move the SoC type check to the right place
    (git-fixes).
  - net: usb: aqc111: debug info before sanitation (git-fixes).
  - rtc: Fix offset calculation for .start_secs < 0 (git-fixes).
  - rtc: stm32: drop unused module alias (git-fixes).
  - rtc: s3c: drop unused module alias (git-fixes).
  - rtc: pm8xxx: drop unused module alias (git-fixes).
  - rtc: jz4740: drop unused module alias (git-fixes).
  - rtc: da9063: drop unused module alias (git-fixes).
  - rtc: cpcap: drop unused module alias (git-fixes).
  - rtc: at91rm9200: drop unused module alias (git-fixes).
  - rtc: sh: assign correct interrupts with DT (git-fixes).
  - dmaengine: ti: Add NULL check in udma_probe() (git-fixes).
  - phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug (git-fixes).
  - commit 0af74e1
  - Move upstreamed patches into sorted section
  - commit 99d25fb
  - Update video patch to the upstream version and put to sorted section
  - commit 5580ff0

++++ kernel-firmware-amdgpu:

  - Update to version 20250606 (git commit 4f0106cf1943):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-firmware-mediatek:

  - Update to version 20250606 (git commit 4f0106cf1943):
    * mediatek MT7922: update bluetooth firmware to 20250523103438
    * mediatek MT7921: update bluetooth firmware to 20250523111333
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device

++++ kernel-rt:

  - usb: misc: onboard_usb_dev: fix build warning for
    CONFIG_USB_ONBOARD_DEV_USB5744=n (git-fixes).
  - drm/xe: remove unmatched xe_vm_unlock() from
    __xe_exec_queue_init() (git-fixes).
  - commit cb5e053
  - spi: bcm63xx-hsspi: fix shared reset (git-fixes).
  - spi: bcm63xx-spi: fix shared reset (git-fixes).
  - regulator: max14577: Add error check for max14577_read_reg()
    (git-fixes).
  - pwm: axi-pwmgen: fix missing separate external clock
    (git-fixes).
  - USB: typec: fix const issue in typec_match() (git-fixes).
  - USB: gadget: udc: fix const issue in gadget_match_driver()
    (git-fixes).
  - USB: serial: bus: fix const issue in usb_serial_device_match()
    (git-fixes).
  - usb: usbtmc: Fix timeout value in get_stb (git-fixes).
  - usb: usbtmc: Fix read_stb function and get_stb ioctl
    (git-fixes).
  - usb: misc: onboard_usb_dev: Fix usb5744 initialization sequence
    (git-fixes).
  - usb: cdnsp: Fix issue with detecting command completion event
    (git-fixes).
  - usb: cdnsp: Fix issue with detecting USB 3.2 speed (git-fixes).
  - usb: Flush altsetting 0 endpoints before reinitializating them
    after reset (git-fixes).
  - usb: typec: tcpm: move tcpm_queue_vdm_unlocked to asynchronous
    work (git-fixes).
  - usb: typec: tcpm/tcpci_maxim: Fix bounds check in process_rx()
    (git-fixes).
  - thunderbolt: Fix a logic error in wake on connect (git-fixes).
  - usb: acpi: Prevent null pointer dereference in
    usb_acpi_add_usb4_devlink() (git-fixes).
  - usb: renesas_usbhs: Reorder clock handling and power management
    in probe (git-fixes).
  - tty: serial: 8250_omap: fix TX with DMA for am33xx (git-fixes).
  - vt: remove VT_RESIZE and VT_RESIZEX from vt_compat_ioctl()
    (git-fixes).
  - serial: jsm: fix NPE during jsm_uart_port_init (git-fixes).
  - serial: Fix potential null-ptr-deref in mlb_usio_probe()
    (git-fixes).
  - iio: adc: ti-ads1298: Kconfig: add kfifo dependency to fix
    module build (git-fixes).
  - iio: adc: mcp3911: fix device dependent mappings for conversion
    result registers (git-fixes).
  - iio: adc: PAC1934: fix typo in documentation link (git-fixes).
  - staging: iio: ad5933: Correct settling cycles encoding per
    datasheet (git-fixes).
  - iio: adc: ad7124: Fix 3dB filter frequency reading (git-fixes).
  - iio: filter: admv8818: Support frequencies >= 2^32 (git-fixes).
  - iio: filter: admv8818: fix range calculation (git-fixes).
  - iio: filter: admv8818: fix integer overflow (git-fixes).
  - iio: filter: admv8818: fix band 4, state 15 (git-fixes).
  - VMCI: fix race between vmci_host_setup_notify and
    vmci_ctx_unset_notify (git-fixes).
  - mei: vsc: Cast tx_buf to (__be32 *) when passed to
    cpu_to_be32_array() (git-fixes).
  - iio: accel: fxls8962af: Fix temperature scan element sign
    (git-fixes).
  - iio: adc: ad7944: mask high bits on direct read (git-fixes).
  - iio: imu: inv_icm42600: Fix temperature calculation (git-fixes).
  - iio: adc: ad7606_spi: fix reg write value mask (git-fixes).
  - bus: mhi: host: Fix conflict between power_up and SYSERR
    (git-fixes).
  - bus: mhi: ep: Update read pointer only after buffer is written
    (git-fixes).
  - fpga: fix potential null pointer deref in
    fpga_mgr_test_img_load_sgt() (git-fixes).
  - sysfb: Fix screen_info type check for VGA (git-fixes).
  - accel/ivpu: Use dma_resv_lock() instead of a custom mutex
    (git-fixes).
  - drm/panel-simple: fix the warnings for the Evervision VGG644804
    (git-fixes).
  - accel/ivpu: Improve buffer object logging (git-fixes).
  - dummycon: Trigger redraw when switching consoles with deferred
    takeover (git-fixes).
  - drm/xe: Create LRC BO without VM (git-fixes).
  - drm/xe/guc_submit: add back fix (git-fixes).
  - drm/xe/sched: stop re-submitting signalled jobs (git-fixes).
  - drm/xe/vm: move rebind_work init earlier (git-fixes).
  - drm/i915/guc: Handle race condition where wakeref count drops
    below 0 (git-fixes).
  - drm/i915/psr: Fix using wrong mask in REG_FIELD_PREP
    (git-fixes).
  - drm/i915/guc: Check if expecting reply before decrementing
    outstanding_submission_g2h (git-fixes).
  - drm/amd/display: Add null pointer check for
    get_first_active_display() (git-fixes).
  - drm/xe: Make xe_gt_freq part of the Documentation (git-fixes).
  - drm/i915/gem: Allow EXEC_CAPTURE on recoverable contexts on DG1
    (git-fixes).
  - PM: sleep: Fix power.is_suspended cleanup for direct-complete
    devices (git-fixes).
  - net: wwan: t7xx: Fix napi rx poll issue (git-fixes).
  - Bluetooth: L2CAP: Fix not responding with L2CAP_CR_LE_ENCRYPTION
    (git-fixes).
  - Bluetooth: hci_qca: move the SoC type check to the right place
    (git-fixes).
  - net: usb: aqc111: debug info before sanitation (git-fixes).
  - rtc: Fix offset calculation for .start_secs < 0 (git-fixes).
  - rtc: stm32: drop unused module alias (git-fixes).
  - rtc: s3c: drop unused module alias (git-fixes).
  - rtc: pm8xxx: drop unused module alias (git-fixes).
  - rtc: jz4740: drop unused module alias (git-fixes).
  - rtc: da9063: drop unused module alias (git-fixes).
  - rtc: cpcap: drop unused module alias (git-fixes).
  - rtc: at91rm9200: drop unused module alias (git-fixes).
  - rtc: sh: assign correct interrupts with DT (git-fixes).
  - dmaengine: ti: Add NULL check in udma_probe() (git-fixes).
  - phy: qcom-qmp-usb: Fix an NULL vs IS_ERR() bug (git-fixes).
  - commit 0af74e1
  - Move upstreamed patches into sorted section
  - commit 99d25fb
  - Update video patch to the upstream version and put to sorted section
  - commit 5580ff0

++++ wayland:

  - Skip tests in qemu emulation

++++ python-argcomplete:

  - Update to version 3.5.3
    * Use interactive shells and bind to make environment variable
    name completions work in older Bash versions (#506)

------------------------------------------------------------------
------------------  2025-6-6  -  Jun 6 2025  -------------------
------------------------------------------------------------------

++++ curl:

  - Sync spec file with SLE codestreams: [jsc#PED-13055, jsc#PED-13056]
    * Add curl-mini.rpmlintrc to avoid rpmlint shlib-policy-name-error
    when building the curl-mini package in SLE.
    * Add libssh minimum version requirements.
    * Use ldconfig_scriptlets when available.
    * Remove unused option --disable-ntlm-wb.

++++ grub2:

  - Fix bls_bumpcounter breaking FDE (bsc#1243842)
    * grub2-blsbumpcounter-menu.patch

++++ hyper-v:

  - Enable debug logs for hv_kvp_daemon (a9c0b33e) (bsc#1244154)

++++ kernel-default:

  - pidfs: allow to retrieve exit information (jsc#PED-13113).
  - pidfs: record exit code and cgroupid at exit (jsc#PED-13113).
  - pidfs: use private inode slab cache (jsc#PED-13113).
  - pidfs: move setting flags into pidfs_alloc_file() (jsc#PED-13113).
  - pidfd: rely on automatic cleanup in __pidfd_prepare()
    (jsc#PED-13113).
  - pidfs: switch to copy_struct_to_user() (jsc#PED-13113).
  - pidfd: add ioctl to retrieve pid info (jsc#PED-13113).
  - commit e6e14a5
  - Re-enable patches.suse/sd-always-retry-READ-CAPACITY-for-ALUA-state-transit.patch
  - commit d22e4a4
  - Refresh patches.suse/scsi-retry-alua-transition-in-progress.
  - commit 08dd7e8
  - Delete patches.suse/fcoe-reduce-max_sectors.
  - commit b728540
  - Delete patches.suse/scsi-do-not-put-scsi_common-in-a-separate-module.patch.
  - commit 7f0112a
  - patches.suse/scsi-do-not-print-reservation-conflict-for-TEST-UNIT.patch
  - commit be8d6ac
  - Delete patches.suse/dm-mpath-no-partitions-feature.
  - commit cfbe465
  - Refresh patches.suse/md-display-timeout-error.patch.
  - commit fab1769
  - s390/pci: Prevent self deletion in disable_slot() (LTC#213760
    bsc#1244147 git-fixes).
  - commit f657f8e
  - Move upstreamed patches into sorted section
  - commit dd92279
  - drm/amd/display: Fix default DC and AC levels (bsc#1240650).
  - drm/amd/display: Add debugging message for brightness caps
    (bsc#1240650).
  - commit d85b918
  - net: fix udp gso skb_segment after pull from frag_list
    (git-fixes).
  - commit 4e1b517
  - page_pool: Fix use-after-free in page_pool_recycle_in_ring
    (git-fixes).
  - commit 829ed89
  - net_sched: Flush gso_skb list too during ->change()
    (CVE-2025-37992 bsc#1243698).
  - ipvs: fix uninit-value for saddr in do_output_route4
    (CVE-2025-37961 bsc#1243523).
  - net: dsa: free routing table on probe failure (CVE-2025-37786
    bsc#1242725).
  - net_sched: Prevent creation of classes with TC_H_ROOT
    (CVE-2025-21971 bsc#1240799).
  - vlan: enforce underlying device type (CVE-2025-21920
    bsc#1240686).
  - xfrm: delete intermediate secpath entry in packet offload mode
    (CVE-2025-21720 bsc#1238859).
  - xfrm: state: fix out-of-bounds read during lookup
    (CVE-2024-57982 bsc#1237913).
  - commit e3d881c
  - kernel-source: Do not use multiple -r in sed parameters
    This usage is enabled in commit b18d64d
    (sed: allow multiple (non-conflicting) -E/-r parameters, 2016-07-31)
    only available since sed 4.3
    Fixes: dc2037cd8f94 ("kernel-source: Also replace bin/env"
  - commit 91ad98e
  - Drop AMDGPU patch that may cause regressions (bsc#1243782)
    Deleted:
    patches.suse/drm-amd-display-more-liberal-vmin-vmax-update-for-fr.patch
  - commit ac81323
  - wifi: ath12k: Avoid memory leak while enabling statistics
    (CVE-2025-37743 bsc#1242163).
  - Refresh
    patches.suse/wifi-ath12k-fix-the-ampdu-id-fetch-in-the-HAL_RX_MPD.patch.
  - commit 378a151
  - KVM: x86: Add infrastructure for secure TSC (jsc#PED-348).
  - commit b436268
  - KVM: x86: Push down setting vcpu.arch.user_set_tsc
    (jsc#PED-348).
  - commit 166cd1c
  - Update config files: add TDX host support
  - commit 069ff6c
  - can: kvaser_pciefd: refine error prone echo_skb_max handling
    logic (git-fixes).
  - commit a9840f5
  - x86/virt/tdx: Remove the !KEXEC_CORE dependency (jsc#PED-348).
  - commit 2f85d4e
  - x86/kexec: Disable kexec/kdump on platforms with TDX partial
    write erratum (jsc#PED-348).
  - commit 0956988
  - x86/virt/tdx: Mark memory cache state incoherent when making
    SEAMCALL (jsc#PED-348).
  - commit 3db11ae
  - x86/sme: Use percpu boolean to control wbinvd during kexec
    (jsc#PED-348).
  - commit 7c35fae

++++ kernel-rt:

  - pidfs: allow to retrieve exit information (jsc#PED-13113).
  - pidfs: record exit code and cgroupid at exit (jsc#PED-13113).
  - pidfs: use private inode slab cache (jsc#PED-13113).
  - pidfs: move setting flags into pidfs_alloc_file() (jsc#PED-13113).
  - pidfd: rely on automatic cleanup in __pidfd_prepare()
    (jsc#PED-13113).
  - pidfs: switch to copy_struct_to_user() (jsc#PED-13113).
  - pidfd: add ioctl to retrieve pid info (jsc#PED-13113).
  - commit e6e14a5
  - Re-enable patches.suse/sd-always-retry-READ-CAPACITY-for-ALUA-state-transit.patch
  - commit d22e4a4
  - Refresh patches.suse/scsi-retry-alua-transition-in-progress.
  - commit 08dd7e8
  - Delete patches.suse/fcoe-reduce-max_sectors.
  - commit b728540
  - Delete patches.suse/scsi-do-not-put-scsi_common-in-a-separate-module.patch.
  - commit 7f0112a
  - patches.suse/scsi-do-not-print-reservation-conflict-for-TEST-UNIT.patch
  - commit be8d6ac
  - Delete patches.suse/dm-mpath-no-partitions-feature.
  - commit cfbe465
  - Refresh patches.suse/md-display-timeout-error.patch.
  - commit fab1769
  - s390/pci: Prevent self deletion in disable_slot() (LTC#213760
    bsc#1244147 git-fixes).
  - commit f657f8e
  - Move upstreamed patches into sorted section
  - commit dd92279
  - drm/amd/display: Fix default DC and AC levels (bsc#1240650).
  - drm/amd/display: Add debugging message for brightness caps
    (bsc#1240650).
  - commit d85b918
  - net: fix udp gso skb_segment after pull from frag_list
    (git-fixes).
  - commit 4e1b517
  - page_pool: Fix use-after-free in page_pool_recycle_in_ring
    (git-fixes).
  - commit 829ed89
  - net_sched: Flush gso_skb list too during ->change()
    (CVE-2025-37992 bsc#1243698).
  - ipvs: fix uninit-value for saddr in do_output_route4
    (CVE-2025-37961 bsc#1243523).
  - net: dsa: free routing table on probe failure (CVE-2025-37786
    bsc#1242725).
  - net_sched: Prevent creation of classes with TC_H_ROOT
    (CVE-2025-21971 bsc#1240799).
  - vlan: enforce underlying device type (CVE-2025-21920
    bsc#1240686).
  - xfrm: delete intermediate secpath entry in packet offload mode
    (CVE-2025-21720 bsc#1238859).
  - xfrm: state: fix out-of-bounds read during lookup
    (CVE-2024-57982 bsc#1237913).
  - commit e3d881c
  - kernel-source: Do not use multiple -r in sed parameters
    This usage is enabled in commit b18d64d
    (sed: allow multiple (non-conflicting) -E/-r parameters, 2016-07-31)
    only available since sed 4.3
    Fixes: dc2037cd8f94 ("kernel-source: Also replace bin/env"
  - commit 91ad98e
  - Drop AMDGPU patch that may cause regressions (bsc#1243782)
    Deleted:
    patches.suse/drm-amd-display-more-liberal-vmin-vmax-update-for-fr.patch
  - commit ac81323
  - wifi: ath12k: Avoid memory leak while enabling statistics
    (CVE-2025-37743 bsc#1242163).
  - Refresh
    patches.suse/wifi-ath12k-fix-the-ampdu-id-fetch-in-the-HAL_RX_MPD.patch.
  - commit 378a151
  - KVM: x86: Add infrastructure for secure TSC (jsc#PED-348).
  - commit b436268
  - KVM: x86: Push down setting vcpu.arch.user_set_tsc
    (jsc#PED-348).
  - commit 166cd1c
  - Update config files: add TDX host support
  - commit 069ff6c
  - can: kvaser_pciefd: refine error prone echo_skb_max handling
    logic (git-fixes).
  - commit a9840f5
  - x86/virt/tdx: Remove the !KEXEC_CORE dependency (jsc#PED-348).
  - commit 2f85d4e
  - x86/kexec: Disable kexec/kdump on platforms with TDX partial
    write erratum (jsc#PED-348).
  - commit 0956988
  - x86/virt/tdx: Mark memory cache state incoherent when making
    SEAMCALL (jsc#PED-348).
  - commit 3db11ae
  - x86/sme: Use percpu boolean to control wbinvd during kexec
    (jsc#PED-348).
  - commit 7c35fae

++++ gcc15:

  - Revert pruning the set of cross-compilers that conflict with different
    versions from the set using update-alternatives.  This causes
    endless headache with file conflicts with older GCC releases.

++++ libguestfs:

  - Update to version 1.55.14 (jsc#PED-12706)
    * lib/create.c: Capture and raise qemu-img stderr
    * inspection: Ignore btrfs snapshots of roots
  - Drop patches contained in new tarball
    004-Add-more-debugging-to-list_filesystems.patch
    005-Pipeline-style-when-mapping-and-filtering-filesystems.patch
    007-inspection-Ignore-btrfs-snapshots-of-roots.patch

++++ samba:

  - Update to 4.22.2
    * (CVE-2025-0620) [SECURITY] CVE-2025-0620: smbd doesn't pick
    up group membership changes when re-authenticating an expired
    SMB session; (bso#15707); (bsc#1244136).
    * Profile sync fails due to Directory Leases; (bso#15861).
    * net ad join fails with "Failed to join domain: failed to
    create kerberos keytab"; (bso#15727).
    * dcerpcd not able to bind to listening port; (bso#15851).
    * vfs_ceph_snapshots fails to list snapshots for entries at any
    level beyond share root; (bso#15819).
    * CTDB does not put nodes running NFS into grace on graceful
    shutdown; (bso#15858).

++++ libvirt:

  - Update to libvirt 11.4.0
  - bsc#1241481, boo#1243740, bsc#1244488
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v11-4-0-2025-06-02
  - spec: Drop support for old distros

++++ libzypp:

  - Fix credential handling in HEAD requests (bsc#1244105)
  - version 17.37.5 (35)

++++ nvidia-open-driver-G06-signed:

  - update CUDA variant to 575.57.08
  - supersedes persistent-nvidia-id-string.patch

++++ openSUSE-repos-LeapMicro:

  - Update to version 20250606.b852490:
    * Update repo definitions for Leap Micro 6.2

++++ python-libvirt-python:

  - Update to 11.4.0
  - Add all new APIs and constants in libvirt 11.4.0

++++ qemu:

  - Update to stable release 10.0.2:
    Full list of backports here:
    https://lore.kernel.org/qemu-devel/1748499690.323471.13081.nullmailer@localhost/
    A selection of them is reported here too:
    Revert "Drop support for Python 3.8"
    Update version for 10.0.1 release
    Drop support for Python 3.8
    target/hppa: Fix FPE exceptions
    linux-user/hppa: Send proper si_code on SIGFPE exception
    target/hppa: Copy instruction code into fr1 on FPU assist fault
    migration: Allow caps to be set when preempt or multifd cap enabled
    migration/multifd: Don't send device state packets with zerocopy flag
    qapi/misc-target: Fix the doc to distinguish query-sgx and query-sgx-capabilities
    hw/pci-host: Remove unused pci_host_data_be_ops
    hw/pci-host/gt64120: Fix endianness handling
    i386/hvf: Make CPUID_HT supported
    i386/tcg: Make CPUID_HT and CPUID_EXT3_CMP_LEG supported
    target/riscv/kvm: do not read unavailable CSRs
    target/riscv/kvm: add kvm_csr_cfgs[]
    target/riscv/kvm: turn kvm_riscv_reg_id_ulong() into a macro
    target/riscv/kvm: turn u32/u64 reg functions into macros
    target/riscv/kvm: fix leak in kvm_riscv_init_multiext_cfg()
    target/riscv/kvm: minor fixes/tweaks
    target/riscv: Fix vslidedown with rvv_ta_all_1s
    target/riscv: Fix the rvv reserved encoding of unmasked instructions
    ...

++++ suseconnect-ng:

  - Version 1.14 public library release
    This version is only available on Github as a tag to release the
    new golang public library which can be consumed without the need
    to interface with SUSEConnect directly.

------------------------------------------------------------------
------------------  2025-6-5  -  Jun 5 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Do not try to inject SUSEConnect secrets when in Rootless Docker mode, as
    Docker does not have permission to access the host zypper credentials in this
    mode (and unprivileged users cannot disable the feature using
    /etc/docker/suse-secrets-enable.) bsc#1240150
    * 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  - Rebase patches:
    * 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
    * 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

++++ dpdk:

  - Fix deterministic build [bsc#1244130]
    [+ 0001-dts-generate-random-capture_name-per-call.patch]

++++ fde-tools:

  - Add fde-tools-bsc1243877-firstboot-remove-key-conf.patch to
    remove the dracut conf for the key file to avoid the error from
    dracut (bsc#1243877)

++++ gobject-introspection:

  - Add explicit python3-setuptools BuildRequires: this was already
    used in the past, but was pulled in by python3-Mako. As meson
    explicitly tests for it, it's our responsibility it's there.

++++ glibc:

  - Add support for userspace livepatching for ppc64le (jsc#PED-11850)

++++ kernel-default:

  - ASoC: SOF: Intel: hda: Fix UAF when reloading module
    (git-fixes).
  - commit 0011189
  - openvswitch: Fix unsafe attribute parsing in output_userspace() (CVE-2025-37998 bsc#1243836)
  - commit 947ad09
  - supported.conf: Add PPC KVM PMU (jsc#PED-11017)
  - commit 26c31c2
  - octeon_ep: Fix host hang issue during device reboot (CVE-2025-37933 bsc#1243628)
  - commit 0fa38bf
  - spi: spi-imx: Add check for spi_imx_setupxfer() (CVE-2025-37801 bsc#1242850)
  - commit d9cd58c
  - Update
    patches.suse/driver-core-introduce-device_set_driver-helper.patch
    (stable-fixes CVE-2025-37800 bsc#1242849).
  - commit 07a018e
  - soc: qcom: smp2p: Fix fallback to qcom,ipc parse (git-fixes).
  - commit 18bbd46
  - wifi: mt76: mt7996: fix RX buffer size of MCU event (git-fixes).
  - wifi: mt76: mt7996: set EHT max ampdu length capability
    (git-fixes).
  - commit 6de50b9
  - wifi: mt76: mt7925: ensure all MCU commands wait for response
    (git-fixes).
  - wifi: mt76: mt7925: refine the sniffer commnad (git-fixes).
  - wifi: mt76: mt7925: prevent multiple scan commands (git-fixes).
  - wifi: mt76: mt7915: Fix null-ptr-deref in mt7915_mmio_wed_init()
    (git-fixes).
  - wifi: mt76: mt7996: Fix null-ptr-deref in mt7996_mmio_wed_init()
    (git-fixes).
  - wifi: mt76: mt7925: fix host interrupt register initialization
    (git-fixes).
  - Revert "wifi: mt76: mt7996: fill txd by host driver"
    (stable-fixes).
  - wifi: ath9k_htc: Abort software beacon handling if disabled
    (git-fixes).
  - wifi: ath12k: fix ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix rx completion meta data corruption
    (git-fixes).
  - wifi: ath11k: fix ring-buffer corruption (git-fixes).
  - wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
    (git-fixes).
  - wifi: rtw89: fix firmware scan delay unit for WiFi 6 chips
    (git-fixes).
  - wifi: rtw88: fix the 'para' buffer size to avoid reading out
    of bounds (git-fixes).
  - wifi: rtw88: usb: Reduce control message timeout to 500 ms
    (git-fixes).
  - wifi: rtw89: pci: enlarge retry times of RX tag to 1000
    (git-fixes).
  - commit 063c386
  - wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID
    11ad:1723 (git-fixes).
  - wifi: rtw88: do not ignore hardware read error during DPK
    (git-fixes).
  - wifi: rtw88: sdio: call rtw_sdio_indicate_tx_status
    unconditionally (git-fixes).
  - wifi: rtw88: sdio: map mgmt frames to queue TX_DESC_QSEL_MGMT
    (git-fixes).
  - wifi: iwlfiwi: mvm: Fix the rate reporting (git-fixes).
  - wifi: ath12k: fix node corruption in ar->arvifs list
    (git-fixes).
  - wifi: ath12k: Fix the QoS control field offset to build QoS
    header (git-fixes).
  - wifi: ath12k: Add MSDU length validation for TKIP MIC error
    (git-fixes).
  - wifi: ath12k: fix invalid access to memory (git-fixes).
  - wifi: ath12k: Handle error cases during extended skb allocation
    (git-fixes).
  - wifi: ath12k: Fix buffer overflow in debugfs (git-fixes).
  - wifi: ath12k: Fix WMI tag for EHT rate in peer assoc
    (git-fixes).
  - wifi: ath12k: fix cleanup path after mhi init (git-fixes).
  - wifi: ath12k: Fix invalid memory access while forming 802.11
    header (git-fixes).
  - wifi: ath12k: Fix memory leak during vdev_id mismatch
    (git-fixes).
  - wifi: ath11k: fix node corruption in ar->arvifs list
    (git-fixes).
  - wifi: iwlwifi: add support for Killer on MTL (stable-fixes).
  - wifi: mt76: only mark tx-status-failed frames as ACKed on
    mt76x0/2 (stable-fixes).
  - commit bf4f1c9
  - wifi: mt76: mt7996: fix SER reset trigger on WED reset
    (stable-fixes).
  - wifi: mt76: mt7996: revise TXS size (stable-fixes).
  - wifi: mt76: mt7925: load the appropriate CLC data based on
    hardware type (stable-fixes).
  - wifi: mt76: mt7925: fix fails to enter low power mode in
    suspend state (stable-fixes).
  - wifi: rtw89: set force HE TB mode when connecting to 11ax AP
    (stable-fixes).
  - wifi: rtw88: Fix rtw_init_vht_cap() for RTL8814AU
    (stable-fixes).
  - wifi: rtw88: Fix rtw_init_ht_cap() for RTL8814AU (stable-fixes).
  - wifi: rtw88: Fix rtw_desc_to_mcsrate() to handle MCS16-31
    (stable-fixes).
  - wifi: rtw89: fw: propagate error code from rtw89_h2c_tx()
    (stable-fixes).
  - wifi: rtw89: fw: get sb_sel_ver via get_unaligned_le32()
    (stable-fixes).
  - wifi: rtw89: fw: add blacklist to avoid obsolete secure firmware
    (stable-fixes).
  - wifi: rtw89: 8922a: fix incorrect STA-ID in EHT MU PPDU
    (stable-fixes).
  - wifi: mwifiex: Fix HT40 bandwidth issue (stable-fixes).
  - wifi: iwlwifi: mvm: fix setting the TK when associated
    (stable-fixes).
  - wifi: iwlwifi: don't warn when if there is a FW error
    (stable-fixes).
  - wifi: iwlwifi: w/a FW SMPS mode selection (stable-fixes).
  - wifi: iwlwifi: fix debug actions order (stable-fixes).
  - wifi: iwlwifi: mark Br device not integrated (stable-fixes).
  - wifi: iwlwifi: fix the ECKV UEFI variable name (stable-fixes).
  - wifi: mac80211: fix warning on disconnect during failed ML
    reconf (stable-fixes).
  - commit 19ba18c
  - vgacon: Add check for vc_origin address range in vgacon_scroll()
    (git-fixes).
  - watchdog: exar: Shorten identity name to fit correctly
    (git-fixes).
  - thermal/drivers/mediatek/lvts: Fix debugfs unregister on failure
    (git-fixes).
  - spi: sh-msiof: Fix maximum DMA transfer size (git-fixes).
  - spi: tegra210-quad: modify chip select (CS) deactivation
    (git-fixes).
  - spi: tegra210-quad: remove redundant error handling code
    (git-fixes).
  - spi: tegra210-quad: Fix X1_X2_X4 encoding and support x4
    transfers (git-fixes).
  - spi: spi-sun4i: fix early activation (stable-fixes).
  - thunderbolt: Do not add non-active NVM if NVM upgrade is
    disabled for retimer (stable-fixes).
  - thermal/drivers/mediatek/lvts: Start sensor interrupts disabled
    (stable-fixes).
  - thermal/drivers/qoriq: Power down TMU on system suspend
    (stable-fixes).
  - watchdog: aspeed: fix 64-bit division (git-fixes).
  - watchdog: aspeed: Update bootstatus handling (stable-fixes).
  - tpm: Convert warn to dbg in tpm2_start_auth_session()
    (stable-fixes).
  - wifi: mac80211_hwsim: Fix MLD address translation
    (stable-fixes).
  - wifi: cfg80211: allow IR in 20 MHz configurations
    (stable-fixes).
  - wifi: ath12k: Report proper tx completion status to mac80211
    (stable-fixes).
  - wifi: ath12k: Improve BSS discovery with hidden SSID in 6 GHz
    band (stable-fixes).
  - wifi: ath12k: fix the ampdu id fetch in the HAL_RX_MPDU_START
    TLV (stable-fixes).
  - wifi: ath12k: Avoid napi_sync() before napi_enable()
    (stable-fixes).
  - wifi: ath12k: fix ath12k_hal_tx_cmd_ext_desc_setup() info1
    override (stable-fixes).
  - wifi: ath9k: return by of_get_mac_address (stable-fixes).
  - wifi: ath12k: Fetch regdb.bin file from board-2.bin
    (stable-fixes).
  - wifi: ath12k: Fix end offset bit definition in monitor ring
    descriptor (stable-fixes).
  - wifi: ath11k: Use dma_alloc_noncoherent for rx_tid buffer
    allocation (stable-fixes).
  - wifi: rtw88: Fix download_firmware_validate() for RTL8814AU
    (stable-fixes).
  - wifi: rtw88: Fix __rtw_download_firmware() for RTL8814AU
    (stable-fixes).
  - wifi: rtw89: coex: Assign value over than 0 to avoid firmware
    timer hang (stable-fixes).
  - wifi: rtw89: fw: validate multi-firmware header before getting
    its size (stable-fixes).
  - wifi: rtw89: fw: validate multi-firmware header before accessing
    (stable-fixes).
  - wifi: rtw89: call power_on ahead before selecting firmware
    (stable-fixes).
  - wifi: rtl8xxxu: retry firmware download on error (stable-fixes).
  - wifi: rtw88: Don't use static local variable in
    rtw8822b_set_tx_power_index_by_rate (stable-fixes).
  - wifi: rtw89: add wiphy_lock() to work that isn't held
    wiphy_lock() yet (stable-fixes).
  - wifi: rtw89: coex: Separated Wi-Fi connecting event from Wi-Fi
    scan event (stable-fixes).
  - wifi: iwlwifi: use correct IMR dump variable (stable-fixes).
  - wifi: iwlwifi: don't warn during reprobe (stable-fixes).
  - wifi: mac80211: don't unconditionally call drv_mgd_complete_tx()
    (stable-fixes).
  - wifi: mac80211: remove misplaced drv_mgd_complete_tx() call
    (stable-fixes).
  - wifi: mac80211: set ieee80211_prep_tx_info::link_id upon Auth Rx
    (stable-fixes).
  - commit 8e68f8c
  - selftests/mm: restore default nr_hugepages value during cleanup
    in hugetlb_reparenting_test.sh (git-fixes).
  - soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
    (git-fixes).
  - soc: aspeed: lpc: Fix impossible judgment condition (git-fixes).
  - soc: qcom: pmic_glink_altmode: fix spurious DP hotplug events
    (git-fixes).
  - selftests/bpf: Fix caps for __xlated/jited_unpriv (git-fixes).
  - selftests/bpf: Fix bpf_nf selftest failure (git-fixes).
  - selinux: unify OOM handling in network hashtables (git-fixes).
  - selftests/seccomp: fix negative_ENOSYS tracer tests on arm32
    (git-fixes).
  - selftests/seccomp: fix syscall_restart test for arm compat
    (git-fixes).
  - power: reset: at91-reset: Optimize at91_reset() (git-fixes).
  - regulator: max20086: Change enable gpio to optional (git-fixes).
  - regulator: max20086: Fix MAX200086 chip id (git-fixes).
  - kselftest: cpufreq: Get rid of double suspend in rtcwake case
    (git-fixes).
  - spi-rockchip: Fix register out of bounds access (stable-fixes).
  - rtc: rv3032: fix EERD location (stable-fixes).
  - rtc: ds1307: stop disabling alarms on probe (stable-fixes).
  - serial: sh-sci: Save and restore more registers (git-fixes).
  - serial: sh-sci: Update the suspend/resume support
    (stable-fixes).
  - soundwire: amd: change the soundwire wake enable/disable
    sequence (stable-fixes).
  - soundwire: cadence_master: set frame shape and divider based
    on actual clk freq (stable-fixes).
  - power: supply: axp20x_battery: Update temp sensor for AXP717
    from device tree (stable-fixes).
  - soc: ti: k3-socinfo: Do not use syscon helper to build regmap
    (stable-fixes).
  - soc: samsung: include linux/array_size.h where needed
    (stable-fixes).
  - soc: mediatek: mtk-mutex: Add DPI1 SOF/EOF to MT8188 mutex
    tables (stable-fixes).
  - selftests/net: have `gro.sh -t` return a correct exit code
    (stable-fixes).
  - spi: spi-mux: Fix coverity issue, unchecked return value
    (stable-fixes).
  - spi: zynqmp-gqspi: Always acknowledge interrupts (stable-fixes).
  - regulator: ad5398: Add device tree support (stable-fixes).
  - commit 6feee74
  - pinctrl: armada-37xx: set GPIO output value before setting
    direction (git-fixes).
  - pinctrl: armada-37xx: use correct OUTPUT_VAL register for
    GPIOs > 31 (git-fixes).
  - pinctrl: at91: Fix possible out-of-boundary access (git-fixes).
  - PM: sleep: Print PM debug messages during hibernation
    (git-fixes).
  - PM: wakeup: Delete space in the end of string shown by
    pm_show_wakelocks() (git-fixes).
  - PM: EM: Fix potential division-by-zero error in
    em_compute_costs() (git-fixes).
  - pinctrl: qcom: switch to devm_register_sys_off_handler()
    (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Assert PLL reset on PHY power off
    (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Lock around hardware registers
    and driver data (git-fixes).
  - pinctrl: meson: define the pull up/down resistor value as 60
    kOhm (stable-fixes).
  - pinctrl: tegra: Fix off by one in tegra_pinctrl_get_group()
    (git-fixes).
  - pinctrl-tegra: Restore SFSEL bit when freeing pins
    (stable-fixes).
  - pinctrl: bcm281xx: Use "unsigned int" instead of bare "unsigned"
    (stable-fixes).
  - pinctrl: renesas: rzg2l: Add suspend/resume support for pull
    up/down (stable-fixes).
  - pinctrl: sophgo: avoid to modify untouched bit when setting
    cv1800 pinconf (stable-fixes).
  - pinctrl: devicetree: do not goto err when probing hogs in
    pinctrl_dt_to_map (stable-fixes).
  - PNP: Expand length of fixup id string (stable-fixes).
  - commit 30aa389
  - PCI: rcar-gen4: set ep BAR4 fixed size (git-fixes).
  - PCI: dwc: ep: Fix errno typo (git-fixes).
  - PCI: dw-rockchip: Fix PHY function call sequence in
    rockchip_pcie_phy_deinit() (git-fixes).
  - PCI: dw-rockchip: Remove PCIE_L0S_ENTRY check from
    rockchip_pcie_link_up() (git-fixes).
  - PCI: cadence: Fix runtime atomic count underflow (git-fixes).
  - PCI: apple: Use gpiod_set_value_cansleep in probe flow
    (git-fixes).
  - PCI: cadence-ep: Correct PBA offset in .set_msix() callback
    (git-fixes).
  - PCI: dwc: ep: Correct PBA offset in .set_msix() callback
    (git-fixes).
  - PCI: Fix lock symmetry in pci_slot_unlock() (git-fixes).
  - PCI: Explicitly put devices into D0 when initializing
    (git-fixes).
  - PCI/ACPI: Fix allocated memory release on error in
    pci_acpi_scan_root() (git-fixes).
  - PCI: Print the actual delay time in
    pci_bridge_wait_for_secondary_bus() (git-fixes).
  - PCI/DPC: Log Error Source ID only when valid (git-fixes).
  - PCI/DPC: Initialize aer_err_info before using it (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Move IRQ request in probe
    (stable-fixes).
  - phy: phy-rockchip-samsung-hdptx: Fix PHY PLL output 50.25MHz
    error (stable-fixes).
  - phy: starfive: jh7110-usb: Fix USB 2.0 host occasional detection
    failure (stable-fixes).
  - phy: rockchip: usbdp: Only verify link rates/lanes/voltage
    when the corresponding set flags are set (stable-fixes).
  - phy: phy-rockchip-samsung-hdptx: Swap the definitions of
    LCPLL_REF and ROPLL_REF (stable-fixes).
  - phy: core: don't require set_mode() callback for phy_get_mode()
    to work (stable-fixes).
  - phy: exynos5-usbdrd: fix EDS distribution tuning (gs101)
    (stable-fixes).
  - PCI: dwc: ep: Ensure proper iteration over outbound map windows
    (stable-fixes).
  - PCI: dwc: Use resource start as ioremap() input in
    dw_pcie_pme_turn_off() (stable-fixes).
  - PCI: brcmstb: Expand inbound window size up to 64GB
    (stable-fixes).
  - PCI: brcmstb: Add a softdep to MIP MSI-X driver (stable-fixes).
  - PCI: epf-mhi: Update device ID for SA8775P (stable-fixes).
  - PCI: endpoint: pci-epf-test: Fix double free that causes kernel
    to oops (stable-fixes).
  - PCI: Fix old_size lower bound in calculate_iosize() too
    (stable-fixes).
  - PCI: vmd: Disable MSI remapping bypass under Xen (stable-fixes).
  - commit 697d499
  - mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
    (git-fixes).
  - mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice
    in exynos_lpass_remove() (git-fixes).
  - mfd: exynos-lpass: Fix an error handling path in
    exynos_lpass_probe() (git-fixes).
  - mtd: rawnand: brcmnand: legacy exec_op implementation
    (git-fixes).
  - mtd: rawnand: sunxi: Add randomizer configuration in
    sunxi_nfc_hw_ecc_write_chunk (git-fixes).
  - mtd: nand: sunxi: Add randomizer configuration before randomizer
    enable (git-fixes).
  - mtd: spinand: esmt: fix id code for F50D1G41LB (git-fixes).
  - mtd: rawnand: qcom: Fix read len for onfi param page
    (git-fixes).
  - mtd: nand: ecc-mxic: Fix use of uninitialized variable ret
    (git-fixes).
  - net: phy: mscc: Stop clearing the the UDPv4 checksum for L2
    frames (git-fixes).
  - net: phy: mscc: Fix memory leak when using one step timestamping
    (git-fixes).
  - net: phy: clear phydev->devlink when the link is deleted
    (git-fixes).
  - net: phy: fix up const issues in to_mdio_device() and
    to_phy_device() (git-fixes).
  - media: verisilicon: Free post processor buffers on error
    (git-fixes).
  - mei: vsc: Use struct vsc_tp_packet as vsc-tp tx_buf and rx_buf
    type (stable-fixes).
  - mfd: tps65219: Remove TPS65219_REG_TI_DEV_ID check
    (stable-fixes).
  - mfd: axp20x: AXP717: Add AXP717_TS_PIN_CFG to writeable regs
    (stable-fixes).
  - net: phy: nxp-c45-tja11xx: add match_phy_device to
    TJA1103/TJA1104 (stable-fixes).
  - commit 80f0e45
  - media: uvcvideo: Fix deferred probing error (git-fixes).
  - media: uvcvideo: Send control events for partial succeeds
    (git-fixes).
  - media: uvcvideo: Return the number of processed controls
    (git-fixes).
  - media: omap3isp: use sgtable-based scatterlist wrappers
    (git-fixes).
  - media: videobuf2: use sgtable-based scatterlist wrappers
    (git-fixes).
  - media: v4l2-dev: fix error handling in __video_register_device()
    (git-fixes).
  - media: i2c: imx335: Fix frame size enumeration (git-fixes).
  - media: ov8856: suppress probe deferral errors (git-fixes).
  - media: ov5675: suppress probe deferral errors (git-fixes).
  - media: imx335: Use correct register width for HNUM (git-fixes).
  - media: nxp: imx8-isi: better handle the m2m usage_count
    (git-fixes).
  - media: gspca: Add error handling for stv06xx_read_sensor()
    (git-fixes).
  - media: davinci: vpif: Fix memory leak in probe error path
    (git-fixes).
  - media: vivid: Change the siize of the composing (git-fixes).
  - media: cxusb: no longer judge rbuf when the write fails
    (git-fixes).
  - media: vidtv: Terminating the subsequent process of
    initialization failure (git-fixes).
  - media: intel/ipu6: Fix dma mask for non-secure mode (git-fixes).
  - media: ov2740: Move pm-runtime cleanup on probe-errors to
    proper place (git-fixes).
  - media: ccs-pll: Correct the upper limit of maximum
    op_pre_pll_clk_div (git-fixes).
  - media: ccs-pll: Check for too high VT PLL multiplier in dual
    PLL case (git-fixes).
  - media: ccs-pll: Start VT pre-PLL multiplier search from correct
    value (git-fixes).
  - media: ccs-pll: Start OP pre-PLL multiplier search from correct
    value (git-fixes).
  - media: ipu6: Remove workaround for Meteor Lake ES2 (git-fixes).
  - media: i2c: ds90ub913: Fix returned fmt from .set_fmt()
    (git-fixes).
  - media: imx-jpeg: Cleanup after an allocation error (git-fixes).
  - media: imx-jpeg: Reset slot data pointers when freed
    (git-fixes).
  - media: imx-jpeg: Move mxc_jpeg_free_slot_data() ahead
    (git-fixes).
  - media: imagination: fix a potential memory leak in e5010_probe()
    (git-fixes).
  - media: imx-jpeg: Drop the first error frames (git-fixes).
  - media: venus: Fix probe error handling (git-fixes).
  - media: mediatek: vcodec: Correct vsi_core framebuffer size
    (git-fixes).
  - media: rkvdec: Fix frame size enumeration (git-fixes).
  - media: c8sectpfe: Call of_node_put(i2c_bus) only once in
    c8sectpfe_probe() (stable-fixes).
  - media: cx231xx: set device_caps for 417 (stable-fixes).
  - media: imx335: Set vblank immediately (stable-fixes).
  - media: uvcvideo: Add sanity check to uvc_ioctl_xu_ctrl_map
    (stable-fixes).
  - media: uvcvideo: Handle uvc menu translation inside
    uvc_get_le_value (stable-fixes).
  - media: adv7180: Disable test-pattern control on adv7180
    (stable-fixes).
  - media: tc358746: improve calculation of the D-PHY timing
    registers (stable-fixes).
  - media: test-drivers: vivid: don't call schedule in loop
    (stable-fixes).
  - commit 0c12415
  - Input: ims-pcu - check record size in ims_pcu_flash_firmware()
    (git-fixes).
  - Input: gpio-keys - fix possible concurrent access in
    gpio_keys_irq_timer() (git-fixes).
  - mailbox: mtk-cmdq: Refine GCE_GCTL_VALUE setting (git-fixes).
  - mailbox: imx: Fix TXDB_V2 sending (git-fixes).
  - intel_th: avoid using deprecated page->mapping, index fields
    (stable-fixes).
  - ima: process_measurement() needlessly takes inode_lock()
    on MAY_READ (stable-fixes).
  - i3c: master: svc: Fix implicit fallthrough in
    svc_i3c_master_ibi_work() (git-fixes).
  - i3c: master: svc: Fix missing STOP for master request
    (stable-fixes).
  - i3c: master: svc: Flush FIFO before sending Dynamic Address
    Assignment(DAA) (stable-fixes).
  - i2c: qup: Vote for interconnect bandwidth to DRAM
    (stable-fixes).
  - i2c: pxa: fix call balance of i2c->clk handling routines
    (stable-fixes).
  - iio: adc: ad7944: don't use storagebits for sizing
    (stable-fixes).
  - mailbox: use error ret code of of_parse_phandle_with_args()
    (stable-fixes).
  - leds: pwm-multicolor: Add check for fwnode_property_read_u32
    (stable-fixes).
  - leds: trigger: netdev: Configure LED blink interval for HW
    offload (stable-fixes).
  - ieee802154: ca8210: Use proper setters and getters for bitwise
    types (stable-fixes).
  - media: i2c: imx219: Correct the minimum vblanking value
    (stable-fixes).
  - media: v4l: Memset argument to 0 before calling get_mbus_config
    pad op (stable-fixes).
  - media: qcom: camss: csid: Only add TPG v4l2 ctrl if TPG hardware
    is available (stable-fixes).
  - media: qcom: camss: Add default case in vfe_src_pad_code
    (stable-fixes).
  - commit 71b3876
  - hwmon: (asus-ec-sensors) check sensor index in read_string()
    (git-fixes).
  - gpiolib: Revert "Don't WARN on gpiod_put() for optional GPIO"
    (stable-fixes).
  - gpio: virtuser: fix potential out-of-bound write (stable-fixes).
  - HID: quirks: Add ADATA XPG alpha wireless mouse support
    (stable-fixes).
  - fpga: altera-cvp: Increase credit timeout (stable-fixes).
  - HID: usbkbd: Fix the bit shift number for LED_KANA
    (stable-fixes).
  - hwmon: (dell-smm) Increment the number of fans (stable-fixes).
  - hwmon: (gpio-fan) Add missing mutex locks (stable-fixes).
  - hwmon: (xgene-hwmon) use appropriate type for the latency value
    (stable-fixes).
  - commit 3023def
  - EDAC/altera: Use correct write width with the INTTEST register
    (git-fixes).
  - fbdev: Fix fb_set_var to prevent null-ptr-deref in
    fb_videomode_to_var (git-fixes).
  - fbdev: Fix do_register_framebuffer to prevent null-ptr-deref
    in fb_videomode_to_var (git-fixes).
  - fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
    (git-fixes).
  - firmware: arm_scmi: Ensure that the message-id supports
    fastchannel (git-fixes).
  - efi/libstub: Describe missing 'out' parameter in efi_load_initrd
    (git-fixes).
  - firmware: psci: Fix refcount leak in psci_dt_init (git-fixes).
  - drm/msm/a6xx: Disable rgb565_predicator on Adreno 7c3
    (git-fixes).
  - drm/msm/gpu: Fix crash when throttling GPU immediately during
    boot (git-fixes).
  - drm/msm/dpu: enable SmartDMA on SC8180X (git-fixes).
  - drm/msm/dpu: enable SmartDMA on SM8150 (git-fixes).
  - drm/mediatek: mtk_drm_drv: Unbind secondary mmsys components
    on err (git-fixes).
  - drm/mediatek: Fix kobject put for component sub-drivers
    (git-fixes).
  - drm/mediatek: mtk_drm_drv: Fix kobject put for mtk_mutex device
    ptr (git-fixes).
  - Revert "drm/amdgpu: don't allow userspace to create a doorbell
    BO" (stable-fixes).
  - drm/amd/pp: Fix potential NULL pointer dereference in
    atomctrl_initialize_mc_reg_table (git-fixes).
  - EDAC/skx_common: Fix general protection fault (git-fixes).
  - eeprom: ee1004: Check chip before probing (stable-fixes).
  - fbdev: fsl-diu-fb: add missing device_remove_file()
    (stable-fixes).
  - fbcon: Use correct erase colour for clearing in fbcon
    (stable-fixes).
  - fbdev: core: tileblit: Implement missing margin clearing for
    tileblit (stable-fixes).
  - firmware: xilinx: Dont send linux address to get fpga config
    get status (stable-fixes).
  - firmware: arm_ffa: Set dma_mask for ffa devices (stable-fixes).
  - firmware: arm_ffa: Reject higher major version as incompatible
    (stable-fixes).
  - firmware: arm_ffa: Handle the presence of host partition in
    the partition info (stable-fixes).
  - firmware: arm_scmi: Relax duplicate name constraint across
    protocol ids (stable-fixes).
  - commit 1c0c86d
  - drm/tegra: Fix a possible null pointer dereference (git-fixes).
  - drm/tegra: rgb: Fix the unbound reference count (git-fixes).
  - drm/tegra: Assign plane type before registration (git-fixes).
  - drm/vkms: Adjust vkms_state->active_planes allocation type
    (git-fixes).
  - drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
    (git-fixes).
  - drm/bridge: lt9611uxc: Fix an error handling path in
    lt9611uxc_probe() (git-fixes).
  - drm/panel: samsung-sofef00: Drop s6e3fc2x01 support (git-fixes).
  - drm/panthor: Update panthor_mmu::irq::mask when needed
    (git-fixes).
  - drm/panthor: Fix GPU_COHERENCY_ACE[_LITE] definitions
    (git-fixes).
  - drm/ast: Fix comment on modeset lock (git-fixes).
  - drm/vc4: tests: Use return instead of assert (git-fixes).
  - drm/bridge: cdns-dsi: Wait for Clk and Data Lanes to be ready
    (git-fixes).
  - drm/bridge: cdns-dsi: Check return value when getting default
    PHY config (git-fixes).
  - drm/bridge: cdns-dsi: Fix the clock variable for mode_valid()
    (git-fixes).
  - drm/bridge: cdns-dsi: Fix phy de-init and flag it so
    (git-fixes).
  - drm/bridge: cdns-dsi: Fix connecting to next bridge (git-fixes).
  - drm/panic: add missing space (git-fixes).
  - drm/udl: Unregister device before cleaning up on disconnect
    (git-fixes).
  - drm/vmwgfx: Fix dumb buffer leak (git-fixes).
  - drm/vmwgfx: Add error path for xa_store in
    vmw_bo_add_detached_resource (git-fixes).
  - commit a60f216
  - drm/amd/display: Configure DTBCLK_P with OPTC only for dcn401
    (stable-fixes).
  - Refresh
    patches.suse/drm-amd-display-prevent-hang-on-link-training-fail.patch.
  - commit 16ba726
  - docs: dt: Update overlay file extension (git-fixes).
  - drm/vmwgfx: Add seqno waiter for sync_files (git-fixes).
  - drm/xe/d3cold: Set power state to D3Cold during s2idle/s3
    (git-fixes).
  - Documentation: ACPI: Use all-string data node references
    (git-fixes).
  - docs: doc-guide: clarify latest theme usage (git-fixes).
  - Documentation/scheduler: Fix typo in sched-stats domain field
    description (git-fixes).
  - Documentation/rtla: Fix typo in common_timerlat_description.rst
    (git-fixes).
  - Documentation/rtla: Fix typo in rtla-timerlat.rst (git-fixes).
  - Documentation/rtla: Fix duplicate text about timerlat tracer
    (git-fixes).
  - crypto: api - Redo lookup on EEXIST (git-fixes).
  - crypto: marvell/cesa - Do not chain submitted requests
    (git-fixes).
  - crypto: sun8i-ce - move fallback ahash_request to the end of
    the struct (git-fixes).
  - crypto: xts - Only add ecb if it is not already there
    (git-fixes).
  - crypto: lrw - Only add ecb if it is not already there
    (git-fixes).
  - crypto: marvell/cesa - Avoid empty transfer descriptor
    (git-fixes).
  - crypto: marvell/cesa - Handle zero-length skcipher requests
    (git-fixes).
  - crypto: sun8i-ce - undo runtime PM changes during driver removal
    (git-fixes).
  - crypto: sun8i-ss - do not use sg_dma_len before calling DMA
    functions (git-fixes).
  - crypto: sun8i-ce-cipher - fix error handling in
    sun8i_ce_cipher_prepare() (git-fixes).
  - dmaengine: idxd: cdev: Fix uninitialized use of sva in
    idxd_cdev_open (stable-fixes).
  - drm/xe: Save the gt pointer in lrc and drop the tile
    (stable-fixes).
  - drm/xe/xe2hpg: Add Wa_22021007897 (stable-fixes).
  - drm/amd/display: check stream id dml21 wrapper to get plane_id
    (stable-fixes).
  - drm/amd/display: fix link_set_dpms_off multi-display MST corner
    case (stable-fixes).
  - drm/amd/display: Defer BW-optimization-blocked DRR adjustments
    (git-fixes).
  - drm/amd/display: Call FP Protect Before Mode Programming/Mode
    Support (stable-fixes).
  - drm/amdgpu: Allow P2P access through XGMI (stable-fixes).
  - drm/amdgpu/discovery: check ip_discovery fw file available
    (stable-fixes).
  - drm/amdkfd: set precise mem ops caps to disabled for gfx 11
    and 12 (stable-fixes).
  - drm/amdgpu: Skip pcie_replay_count sysfs creation for VF
    (stable-fixes).
  - drm/amdgpu: release xcp_mgr on exit (stable-fixes).
  - drm/amd/display: Guard against setting dispclk low for dcn31x
    (stable-fixes).
  - drm/amdgpu: adjust drm_firmware_drivers_only() handling
    (stable-fixes).
  - drm/amdkfd: Correct F8_MODE for gfx950 (git-fixes).
  - drm/amdgpu/gfx12: don't read registers in mqd init
    (stable-fixes).
  - drm/amdgpu/gfx11: don't read registers in mqd init
    (stable-fixes).
  - drm/amdgpu: Fix the race condition for draining retry fault
    (stable-fixes).
  - drm/amdgpu: Update SRIOV video codec caps (stable-fixes).
  - drm/amd/display: remove minimum Dispclk and apply oem panel
    timing (stable-fixes).
  - drm/amd/display: Correct timing_adjust_pending flag setting
    (stable-fixes).
  - drm/amd/display: calculate the remain segments for all pipes
    (stable-fixes).
  - drm/amd/display: not abort link train when bw is low
    (stable-fixes).
  - drm/amd/display: Do not enable replay when vtotal update is
    pending (stable-fixes).
  - drm/amd/display: Fix incorrect DPCD configs while Replay/PSR
    switch (stable-fixes).
  - drm/mediatek: mtk_dpi: Add checks for reg_h_fre_con existence
    (stable-fixes).
  - drm/xe: Nuke VM's mapping upon close (stable-fixes).
  - drm/xe: Retry BO allocation (stable-fixes).
  - drm/xe/vf: Retry sending MMIO request to GUC on timeout error
    (stable-fixes).
  - drm/xe/pf: Create a link between PF and VF devices
    (stable-fixes).
  - drm/xe: xe_gen_wa_oob: replace program_invocation_short_name
    (stable-fixes).
  - drm/amdkfd: Set per-process flags only once for gfx9/10/11/12
    (stable-fixes).
  - drm/amdkfd: Set per-process flags only once cik/vi
    (stable-fixes).
  - drm/amdgpu: Fix missing drain retry fault the last entry
    (stable-fixes).
  - drm/amdgpu: Do not program AGP BAR regs under SRIOV in
    gfxhub_v1_0.c (stable-fixes).
  - drm/amd/display: Ensure DMCUB idle before reset on DCN31/DCN35
    (stable-fixes).
  - drm/amd/display: Skip checking FRL_MODE bit for PCON BW
    determination (stable-fixes).
  - drm/amd/display: Fix DMUB reset sequence for DCN401
    (stable-fixes).
  - drm/amd/display: Fix p-state type when p-state is unsupported
    (stable-fixes).
  - drm/amd/display: Request HW cursor on DCN3.2 with SubVP
    (stable-fixes).
  - drm/amdkfd: KFD release_work possible circular locking
    (stable-fixes).
  - drm/amd/display: handle max_downscale_src_width fail check
    (stable-fixes).
  - drm/amd/display: fix dcn4x init failed (stable-fixes).
  - drm/amdgpu: remove all KFD fences from the BO on release
    (stable-fixes).
  - drm/rockchip: vop2: Add uv swap for cluster window
    (stable-fixes).
  - drm/xe/oa: Ensure that polled read returns latest data
    (stable-fixes).
  - drm/xe: Stop ignoring errors from xe_ttm_stolen_mgr_init()
    (stable-fixes).
  - drm/xe: Fix xe_tile_init_noalloc() error propagation
    (stable-fixes).
  - drm/xe/debugfs: fixed the return value of wedged_mode_set
    (stable-fixes).
  - drm/xe/debugfs: Add missing xe_pm_runtime_put in wedge_mode_set
    (stable-fixes).
  - drm/xe/relay: Don't use GFP_KERNEL for new transactions
    (stable-fixes).
  - drm/xe/pf: Reset GuC VF config when unprovisioning critical
    resource (stable-fixes).
  - drm/xe: Move suballocator init to after display init
    (stable-fixes).
  - drm/xe: Do not attempt to bootstrap VF in execlists mode
    (stable-fixes).
  - drm/xe/sa: Always call drm_suballoc_manager_fini()
    (stable-fixes).
  - drm/xe: Reject BO eviction if BO is bound to current VM
    (stable-fixes).
  - drm/amd/pm: Fetch current power limit from PMFW (stable-fixes).
  - drm/amd/display: Add support for disconnected eDP streams
    (stable-fixes).
  - drm/amd/display: Guard against setting dispclk low when active
    (stable-fixes).
  - drm/amd/display: Fix BT2020 YCbCr limited/full range input
    (stable-fixes).
  - drm/amd/display: Read LTTPR ALPM caps during link cap retrieval
    (stable-fixes).
  - drm/amd/display: Don't treat wb connector as physical in
    create_validate_stream_for_sink (stable-fixes).
  - drm/amdgpu/mes11: fix set_hw_resources_1 calculation
    (stable-fixes).
  - drm/amdkfd: fix missing L2 cache info in topology
    (stable-fixes).
  - drm/amdgpu: Set snoop bit for SDMA for MI series (stable-fixes).
  - drm/amd/display: pass calculated dram_speed_mts to dml2
    (stable-fixes).
  - drm/amd/display: Don't try AUX transactions on disconnected link
    (stable-fixes).
  - drm/amdgpu: reset psp->cmd to NULL after releasing the buffer
    (stable-fixes).
  - drm/amd/pm: Skip P2S load for SMU v13.0.12 (stable-fixes).
  - drm/amd/display: Support multiple options during psr entry
    (stable-fixes).
  - drm/amd/display: Update CR AUX RD interval interpretation
    (stable-fixes).
  - drm/amd/display: Initial psr_version with correct setting
    (stable-fixes).
  - drm/amd/display: Increase block_sequence array size
    (stable-fixes).
  - drm/amd/display: Use Nominal vBlank If Provided Instead Of
    Capping It (stable-fixes).
  - drm/amd/display: Populate register address for dentist for
    dcn401 (stable-fixes).
  - drm/amdgpu: Use active umc info from discovery (stable-fixes).
  - drm/amdgpu: enlarge the VBIOS binary size limit (stable-fixes).
  - drm/amd/display/dm: drop hw_support check in
    amdgpu_dm_i2c_xfer() (stable-fixes).
  - drm/v3d: Add clock handling (stable-fixes).
  - drm/rockchip: vop2: Improve display modes handling on RK3588
    HDMI0 (stable-fixes).
  - drm/ast: Find VBIOS mode from regular display size
    (stable-fixes).
  - drm: bridge: adv7511: fill stream capabilities (stable-fixes).
  - drm/nouveau: fix the broken marco GSP_MSG_MAX_SIZE
    (stable-fixes).
  - drm/atomic: clarify the rules around
    drm_atomic_state->allow_modeset (stable-fixes).
  - drm/buddy: fix issue that force_merge cannot free all roots
    (stable-fixes).
  - drm/panel-edp: Add Starry 116KHD024006 (stable-fixes).
  - drm: Add valid clones check (stable-fixes).
  - commit 88828d8
  - crypto: sun8i-ce-hash - fix error handling in
    sun8i_ce_hash_run() (git-fixes).
  - can: kvaser_pciefd: Continue parsing DMA buf after dropped RX
    (stable-fixes).
  - can: kvaser_pciefd: Fix echo_skb race (stable-fixes).
  - char: tpm: tpm-buf: Add sanity check fallback in read helpers
    (stable-fixes).
  - crypto: octeontx2 - suppress auth failure screaming due to
    negative tests (stable-fixes).
  - crypto: lzo - Fix compression buffer overrun (stable-fixes).
  - crypto: mxs-dcp - Only set OTP_KEY bit for OTP key
    (stable-fixes).
  - crypto: skcipher - Zap type in crypto_alloc_sync_skcipher
    (stable-fixes).
  - commit a9645bd
  - backlight: pm8941: Add NULL check in wled_configure()
    (git-fixes).
  - bus: fsl-mc: fix GET/SET_TAILDROP command ids (git-fixes).
  - bus: fsl-mc: do not add a device-link for the UAPI used DPMCP
    device (git-fixes).
  - bus: fsl-mc: fix double-free on mc_dev (git-fixes).
  - Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect
    devices first" (stable-fixes).
  - Bluetooth: btintel: Check dsbr size from EFI variable
    (git-fixes).
  - Bluetooth: MGMT: iterate over mesh commands in
    mgmt_mesh_foreach() (git-fixes).
  - ASoC: qcom: sdm845: Add error handling in
    sdm845_slim_snd_hw_params() (git-fixes).
  - ASoC: apple: mca: Constrain channels according to TDM mask
    (git-fixes).
  - ASoC: amd: sof_amd_sdw: Fix unlikely uninitialized variable
    use in create_sdw_dailinks() (git-fixes).
  - ASoC: SOF: amd: add missing acp descriptor field (git-fixes).
  - ASoC: SOF: ipc4-pcm: Adjust pipeline_list->pipelines allocation
    type (git-fixes).
  - ASoC: meson: meson-card-utils: use of_property_present()
    for DT parsing (git-fixes).
  - Bluetooth: btmtksdio: Do close if SDIO card removed without
    close (git-fixes).
  - Bluetooth: btmtksdio: Check function enabled before doing close
    (git-fixes).
  - Bluetooth: btmtksdio: Prevent enabling interrupts after IRQ
    handler removal (stable-fixes).
  - Bluetooth: Disable SCO support if READ_VOICE_SETTING is
    unsupported/broken (stable-fixes).
  - can: c_can: Use of_property_present() to test existence of DT
    property (stable-fixes).
  - commit 8fe3f19
  - ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()
    (git-fixes).
  - ASoC: tas2764: Enable main IRQs (git-fixes).
  - ASoC: tas2764: Reinit cache on part reset (git-fixes).
  - ASoC: intel/sdw_utils: Add volume limit to cs42l43 speakers
    (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Acer Aspire SW3-013
    (stable-fixes).
  - ASoC: cs42l43: Disable headphone clamps during type detection
    (stable-fixes).
  - ASoC: imx-card: Adjust over allocation of memory in
    imx_card_parse_of() (stable-fixes).
  - ASoC: codecs: wsa884x: Correct VI sense channel mask
    (stable-fixes).
  - ASoC: codecs: wsa883x: Correct VI sense channel mask
    (stable-fixes).
  - commit 86bb694
  - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14ASP10
    (stable-fixes).
  - ALSA: hda/realtek - restore auto-mute mode for Dell Chrome
    platform (stable-fixes).
  - ALSA: pcm: Fix race of buffer access at PCM OSS layer
    (stable-fixes).
  - ALSA: usb-audio: Fix duplicated name in MIDI substream names
    (stable-fixes).
  - ALSA: hda/realtek: Add quirk for HP Spectre x360 15-df1xxx
    (stable-fixes).
  - ASoC: pcm6240: Drop bogus code handling IRQ as GPIO
    (stable-fixes).
  - ASoC: mediatek: mt6359: Add stub for
    mt6359_accdet_enable_jack_detect (stable-fixes).
  - ASoC: sun4i-codec: support hp-det-gpios property (stable-fixes).
  - ASoC: qcom: sm8250: explicitly set format in
    sm8250_be_hw_params_fixup() (stable-fixes).
  - ASoC: mediatek: mt8188: Treat DMIC_GAINx_CUR as non-volatile
    (stable-fixes).
  - ASoC: mediatek: mt8188: Add reference for dmic clocks
    (stable-fixes).
  - ASoC: soc-dai: check return value at snd_soc_dai_set_tdm_slot()
    (stable-fixes).
  - ASoC: tas2764: Add reg defaults for TAS2764_INT_CLK_CFG
    (stable-fixes).
  - ASoC: tas2764: Mark SW_RESET as volatile (stable-fixes).
  - ASoC: tas2764: Power up/down amp on mute ops (stable-fixes).
  - ASoC: ops: Enforce platform maximum on initial value
    (stable-fixes).
  - ASoC: codecs: pcm3168a: Allow for 24-bit in provider mode
    (stable-fixes).
  - ASoC: rt722-sdca: Add some missing readable registers
    (stable-fixes).
  - ALSA: seq: Improve data consistency at polling (stable-fixes).
  - commit 08338b9
  - kABI workaround for hda_codec.beep_just_power_on flag
    (git-fixes).
  - commit 2932a2f
  - acpi-cpufreq: Fix nominal_freq units to KHz in
    get_max_boost_ratio() (git-fixes).
  - ACPI: resource: fix a typo for MECHREVO in
    irq1_edge_low_force_override[] (git-fixes).
  - ACPICA: Utilities: Fix spelling mistake "Incremement" ->
    "Increment" (git-fixes).
  - ACPICA: exserial: don't forget to handle FFixedHW opregions
    for reading (git-fixes).
  - ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
    (git-fixes).
  - ACPI: PNP: Add Intel OC Watchdog IDs to non-PNP device list
    (stable-fixes).
  - accel/qaic: Mask out SR-IOV PCI resources (stable-fixes).
  - ALSA: hda/realtek: Enable PC beep passthrough for HP EliteBook
    855 G7 (stable-fixes).
  - ACPI: HED: Always initialize before evged (stable-fixes).
  - commit a49c2aa
  - kabi/severities: Add more PPC KVM symbols
  - commit 72910b3
  - Update patches.suse/mm-execmem-Unify-early-execmem_cache-behaviour.patch (bsc#1244062).
  - commit d02c14c
  - accel/ivpu: Correct mutex unlock order in job submission
    (git-fixes).
  - commit 9044b56
  - net: ethernet: mtk-star-emac: fix spinlock recursion issues
    on rx/tx poll (CVE-2025-37917 bsc#1243475).
  - commit 6f4e259
  - net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
    (CVE-2025-37935 bsc#1243546).
  - commit 8eb532f
  - Delete patches.suse/procfs-add-tunable-for-fd-fdinfo-dentry-retention.patch.
  - commit c9207ce
  - platform/x86: thinkpad_acpi: Ignore battery threshold change
    event notification (git-fixes).
  - commit de4db35
  - platform/x86: fujitsu-laptop: Support Lifebook S2110 hotkeys
    (git-fixes).
  - commit aad5008
  - platform/x86: thinkpad_acpi: Support also NEC Lavie X1475JAS
    (git-fixes).
  - commit 3d5ab3a
  - accel/ivpu: Fix locking order in ivpu_job_submit (CVE-2025-37907 bsc#1243464).
  - commit 9c91371
  - accel/ivpu: Abort all jobs after command queue unregister (CVE-2025-37907 bsc#1243464).
  - commit de61fba
  - kABI: kabi fixes after tdx host patches (jsc#PED-348).
  - commit d736c22

++++ kernel-firmware-amdgpu:

  - Update to version 20250603 (git commit 3b75d677f898):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-firmware-bluetooth:

  - Update to version 20250603 (git commit 3b75d677f898):
    * linux-firmware: Update firmware file for Intel Pulsar core
    * linux-firmware: Update firmware file for Intel BlazarI core
    * linux-firmware: Update firmware file for Intel Quasar core
    * linux-firmware: Update firmware file for Intel Solar core
    * linux-firmware: Update firmware file for Intel Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core

++++ kernel-firmware-brcm:

  - Update to version 20250603 (git commit 3b75d677f898):
    * brcm: Add symlinks for Khadas VIM SDIO wifi config to AW-CM256SM.txt

++++ kernel-firmware-i915:

  - Update aliases
  - Update to version 20250603 (git commit 3b75d677f898):
    * xe: Update GUC to v70.45.2 for BMG, LNL
    * i915: Update GUC to v70.45.2 for DG2
    * xe: Update LNL GSC to v104.0.5.1429

++++ kernel-firmware-intel:

  - Update to version 20250603 (git commit 3b75d677f898):
    * Intel IPU7: Add firmware binary files

++++ kernel-firmware-iwlwifi:

  - Update to version 20250603 (git commit 3b75d677f898):
    * iwlwifi: add Bz/gl FW for core96-76 release
    * iwlwifi: update ty/So/Ma firmwares for core96-76 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core96-76 release
    * iwlwifi: update firmwares for 8000 series
    * iwlwifi: update 7265D firmware

++++ kernel-firmware-mediatek:

  - Update to version 20250603 (git commit 3b75d677f898):
    * mediatek MT7925: update bluetooth firmware to 20250526153203
    * linux-firmware: update firmware for MT7925 WiFi device

++++ kernel-firmware-network:

  - Update to version 20250603 (git commit 3b75d677f898):
    * ice: update wireless_edge package to 1.3.23.0
    * ice: update comms package to 1.3.55.0
    * ice: update package to 1.3.43.0

++++ kernel-firmware-nvidia:

  - Add workaround for directory/symlink changes (bsc#1243843)

++++ kernel-firmware-qcom:

  - Update aliases
  - Update to version 20250603 (git commit 3b75d677f898):
    * qcom: add QUPv3 firmware for QCS8300 platform
    * qcom: sc8280xp: FW blob updates for X13s

++++ kernel-rt:

  - ASoC: SOF: Intel: hda: Fix UAF when reloading module
    (git-fixes).
  - commit 0011189
  - openvswitch: Fix unsafe attribute parsing in output_userspace() (CVE-2025-37998 bsc#1243836)
  - commit 947ad09
  - supported.conf: Add PPC KVM PMU (jsc#PED-11017)
  - commit 26c31c2
  - octeon_ep: Fix host hang issue during device reboot (CVE-2025-37933 bsc#1243628)
  - commit 0fa38bf
  - spi: spi-imx: Add check for spi_imx_setupxfer() (CVE-2025-37801 bsc#1242850)
  - commit d9cd58c
  - Update
    patches.suse/driver-core-introduce-device_set_driver-helper.patch
    (stable-fixes CVE-2025-37800 bsc#1242849).
  - commit 07a018e
  - soc: qcom: smp2p: Fix fallback to qcom,ipc parse (git-fixes).
  - commit 18bbd46
  - wifi: mt76: mt7996: fix RX buffer size of MCU event (git-fixes).
  - wifi: mt76: mt7996: set EHT max ampdu length capability
    (git-fixes).
  - commit 6de50b9
  - wifi: mt76: mt7925: ensure all MCU commands wait for response
    (git-fixes).
  - wifi: mt76: mt7925: refine the sniffer commnad (git-fixes).
  - wifi: mt76: mt7925: prevent multiple scan commands (git-fixes).
  - wifi: mt76: mt7915: Fix null-ptr-deref in mt7915_mmio_wed_init()
    (git-fixes).
  - wifi: mt76: mt7996: Fix null-ptr-deref in mt7996_mmio_wed_init()
    (git-fixes).
  - wifi: mt76: mt7925: fix host interrupt register initialization
    (git-fixes).
  - Revert "wifi: mt76: mt7996: fill txd by host driver"
    (stable-fixes).
  - wifi: ath9k_htc: Abort software beacon handling if disabled
    (git-fixes).
  - wifi: ath12k: fix ring-buffer corruption (git-fixes).
  - wifi: ath11k: fix rx completion meta data corruption
    (git-fixes).
  - wifi: ath11k: fix ring-buffer corruption (git-fixes).
  - wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
    (git-fixes).
  - wifi: rtw89: fix firmware scan delay unit for WiFi 6 chips
    (git-fixes).
  - wifi: rtw88: fix the 'para' buffer size to avoid reading out
    of bounds (git-fixes).
  - wifi: rtw88: usb: Reduce control message timeout to 500 ms
    (git-fixes).
  - wifi: rtw89: pci: enlarge retry times of RX tag to 1000
    (git-fixes).
  - commit 063c386
  - wifi: rtlwifi: disable ASPM for RTL8723BE with subsystem ID
    11ad:1723 (git-fixes).
  - wifi: rtw88: do not ignore hardware read error during DPK
    (git-fixes).
  - wifi: rtw88: sdio: call rtw_sdio_indicate_tx_status
    unconditionally (git-fixes).
  - wifi: rtw88: sdio: map mgmt frames to queue TX_DESC_QSEL_MGMT
    (git-fixes).
  - wifi: iwlfiwi: mvm: Fix the rate reporting (git-fixes).
  - wifi: ath12k: fix node corruption in ar->arvifs list
    (git-fixes).
  - wifi: ath12k: Fix the QoS control field offset to build QoS
    header (git-fixes).
  - wifi: ath12k: Add MSDU length validation for TKIP MIC error
    (git-fixes).
  - wifi: ath12k: fix invalid access to memory (git-fixes).
  - wifi: ath12k: Handle error cases during extended skb allocation
    (git-fixes).
  - wifi: ath12k: Fix buffer overflow in debugfs (git-fixes).
  - wifi: ath12k: Fix WMI tag for EHT rate in peer assoc
    (git-fixes).
  - wifi: ath12k: fix cleanup path after mhi init (git-fixes).
  - wifi: ath12k: Fix invalid memory access while forming 802.11
    header (git-fixes).
  - wifi: ath12k: Fix memory leak during vdev_id mismatch
    (git-fixes).
  - wifi: ath11k: fix node corruption in ar->arvifs list
    (git-fixes).
  - wifi: iwlwifi: add support for Killer on MTL (stable-fixes).
  - wifi: mt76: only mark tx-status-failed frames as ACKed on
    mt76x0/2 (stable-fixes).
  - commit bf4f1c9
  - wifi: mt76: mt7996: fix SER reset trigger on WED reset
    (stable-fixes).
  - wifi: mt76: mt7996: revise TXS size (stable-fixes).
  - wifi: mt76: mt7925: load the appropriate CLC data based on
    hardware type (stable-fixes).
  - wifi: mt76: mt7925: fix fails to enter low power mode in
    suspend state (stable-fixes).
  - wifi: rtw89: set force HE TB mode when connecting to 11ax AP
    (stable-fixes).
  - wifi: rtw88: Fix rtw_init_vht_cap() for RTL8814AU
    (stable-fixes).
  - wifi: rtw88: Fix rtw_init_ht_cap() for RTL8814AU (stable-fixes).
  - wifi: rtw88: Fix rtw_desc_to_mcsrate() to handle MCS16-31
    (stable-fixes).
  - wifi: rtw89: fw: propagate error code from rtw89_h2c_tx()
    (stable-fixes).
  - wifi: rtw89: fw: get sb_sel_ver via get_unaligned_le32()
    (stable-fixes).
  - wifi: rtw89: fw: add blacklist to avoid obsolete secure firmware
    (stable-fixes).
  - wifi: rtw89: 8922a: fix incorrect STA-ID in EHT MU PPDU
    (stable-fixes).
  - wifi: mwifiex: Fix HT40 bandwidth issue (stable-fixes).
  - wifi: iwlwifi: mvm: fix setting the TK when associated
    (stable-fixes).
  - wifi: iwlwifi: don't warn when if there is a FW error
    (stable-fixes).
  - wifi: iwlwifi: w/a FW SMPS mode selection (stable-fixes).
  - wifi: iwlwifi: fix debug actions order (stable-fixes).
  - wifi: iwlwifi: mark Br device not integrated (stable-fixes).
  - wifi: iwlwifi: fix the ECKV UEFI variable name (stable-fixes).
  - wifi: mac80211: fix warning on disconnect during failed ML
    reconf (stable-fixes).
  - commit 19ba18c
  - vgacon: Add check for vc_origin address range in vgacon_scroll()
    (git-fixes).
  - watchdog: exar: Shorten identity name to fit correctly
    (git-fixes).
  - thermal/drivers/mediatek/lvts: Fix debugfs unregister on failure
    (git-fixes).
  - spi: sh-msiof: Fix maximum DMA transfer size (git-fixes).
  - spi: tegra210-quad: modify chip select (CS) deactivation
    (git-fixes).
  - spi: tegra210-quad: remove redundant error handling code
    (git-fixes).
  - spi: tegra210-quad: Fix X1_X2_X4 encoding and support x4
    transfers (git-fixes).
  - spi: spi-sun4i: fix early activation (stable-fixes).
  - thunderbolt: Do not add non-active NVM if NVM upgrade is
    disabled for retimer (stable-fixes).
  - thermal/drivers/mediatek/lvts: Start sensor interrupts disabled
    (stable-fixes).
  - thermal/drivers/qoriq: Power down TMU on system suspend
    (stable-fixes).
  - watchdog: aspeed: fix 64-bit division (git-fixes).
  - watchdog: aspeed: Update bootstatus handling (stable-fixes).
  - tpm: Convert warn to dbg in tpm2_start_auth_session()
    (stable-fixes).
  - wifi: mac80211_hwsim: Fix MLD address translation
    (stable-fixes).
  - wifi: cfg80211: allow IR in 20 MHz configurations
    (stable-fixes).
  - wifi: ath12k: Report proper tx completion status to mac80211
    (stable-fixes).
  - wifi: ath12k: Improve BSS discovery with hidden SSID in 6 GHz
    band (stable-fixes).
  - wifi: ath12k: fix the ampdu id fetch in the HAL_RX_MPDU_START
    TLV (stable-fixes).
  - wifi: ath12k: Avoid napi_sync() before napi_enable()
    (stable-fixes).
  - wifi: ath12k: fix ath12k_hal_tx_cmd_ext_desc_setup() info1
    override (stable-fixes).
  - wifi: ath9k: return by of_get_mac_address (stable-fixes).
  - wifi: ath12k: Fetch regdb.bin file from board-2.bin
    (stable-fixes).
  - wifi: ath12k: Fix end offset bit definition in monitor ring
    descriptor (stable-fixes).
  - wifi: ath11k: Use dma_alloc_noncoherent for rx_tid buffer
    allocation (stable-fixes).
  - wifi: rtw88: Fix download_firmware_validate() for RTL8814AU
    (stable-fixes).
  - wifi: rtw88: Fix __rtw_download_firmware() for RTL8814AU
    (stable-fixes).
  - wifi: rtw89: coex: Assign value over than 0 to avoid firmware
    timer hang (stable-fixes).
  - wifi: rtw89: fw: validate multi-firmware header before getting
    its size (stable-fixes).
  - wifi: rtw89: fw: validate multi-firmware header before accessing
    (stable-fixes).
  - wifi: rtw89: call power_on ahead before selecting firmware
    (stable-fixes).
  - wifi: rtl8xxxu: retry firmware download on error (stable-fixes).
  - wifi: rtw88: Don't use static local variable in
    rtw8822b_set_tx_power_index_by_rate (stable-fixes).
  - wifi: rtw89: add wiphy_lock() to work that isn't held
    wiphy_lock() yet (stable-fixes).
  - wifi: rtw89: coex: Separated Wi-Fi connecting event from Wi-Fi
    scan event (stable-fixes).
  - wifi: iwlwifi: use correct IMR dump variable (stable-fixes).
  - wifi: iwlwifi: don't warn during reprobe (stable-fixes).
  - wifi: mac80211: don't unconditionally call drv_mgd_complete_tx()
    (stable-fixes).
  - wifi: mac80211: remove misplaced drv_mgd_complete_tx() call
    (stable-fixes).
  - wifi: mac80211: set ieee80211_prep_tx_info::link_id upon Auth Rx
    (stable-fixes).
  - commit 8e68f8c
  - selftests/mm: restore default nr_hugepages value during cleanup
    in hugetlb_reparenting_test.sh (git-fixes).
  - soc: aspeed: Add NULL check in aspeed_lpc_enable_snoop()
    (git-fixes).
  - soc: aspeed: lpc: Fix impossible judgment condition (git-fixes).
  - soc: qcom: pmic_glink_altmode: fix spurious DP hotplug events
    (git-fixes).
  - selftests/bpf: Fix caps for __xlated/jited_unpriv (git-fixes).
  - selftests/bpf: Fix bpf_nf selftest failure (git-fixes).
  - selinux: unify OOM handling in network hashtables (git-fixes).
  - selftests/seccomp: fix negative_ENOSYS tracer tests on arm32
    (git-fixes).
  - selftests/seccomp: fix syscall_restart test for arm compat
    (git-fixes).
  - power: reset: at91-reset: Optimize at91_reset() (git-fixes).
  - regulator: max20086: Change enable gpio to optional (git-fixes).
  - regulator: max20086: Fix MAX200086 chip id (git-fixes).
  - kselftest: cpufreq: Get rid of double suspend in rtcwake case
    (git-fixes).
  - spi-rockchip: Fix register out of bounds access (stable-fixes).
  - rtc: rv3032: fix EERD location (stable-fixes).
  - rtc: ds1307: stop disabling alarms on probe (stable-fixes).
  - serial: sh-sci: Save and restore more registers (git-fixes).
  - serial: sh-sci: Update the suspend/resume support
    (stable-fixes).
  - soundwire: amd: change the soundwire wake enable/disable
    sequence (stable-fixes).
  - soundwire: cadence_master: set frame shape and divider based
    on actual clk freq (stable-fixes).
  - power: supply: axp20x_battery: Update temp sensor for AXP717
    from device tree (stable-fixes).
  - soc: ti: k3-socinfo: Do not use syscon helper to build regmap
    (stable-fixes).
  - soc: samsung: include linux/array_size.h where needed
    (stable-fixes).
  - soc: mediatek: mtk-mutex: Add DPI1 SOF/EOF to MT8188 mutex
    tables (stable-fixes).
  - selftests/net: have `gro.sh -t` return a correct exit code
    (stable-fixes).
  - spi: spi-mux: Fix coverity issue, unchecked return value
    (stable-fixes).
  - spi: zynqmp-gqspi: Always acknowledge interrupts (stable-fixes).
  - regulator: ad5398: Add device tree support (stable-fixes).
  - commit 6feee74
  - pinctrl: armada-37xx: set GPIO output value before setting
    direction (git-fixes).
  - pinctrl: armada-37xx: use correct OUTPUT_VAL register for
    GPIOs > 31 (git-fixes).
  - pinctrl: at91: Fix possible out-of-boundary access (git-fixes).
  - PM: sleep: Print PM debug messages during hibernation
    (git-fixes).
  - PM: wakeup: Delete space in the end of string shown by
    pm_show_wakelocks() (git-fixes).
  - PM: EM: Fix potential division-by-zero error in
    em_compute_costs() (git-fixes).
  - pinctrl: qcom: switch to devm_register_sys_off_handler()
    (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Assert PLL reset on PHY power off
    (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Lock around hardware registers
    and driver data (git-fixes).
  - pinctrl: meson: define the pull up/down resistor value as 60
    kOhm (stable-fixes).
  - pinctrl: tegra: Fix off by one in tegra_pinctrl_get_group()
    (git-fixes).
  - pinctrl-tegra: Restore SFSEL bit when freeing pins
    (stable-fixes).
  - pinctrl: bcm281xx: Use "unsigned int" instead of bare "unsigned"
    (stable-fixes).
  - pinctrl: renesas: rzg2l: Add suspend/resume support for pull
    up/down (stable-fixes).
  - pinctrl: sophgo: avoid to modify untouched bit when setting
    cv1800 pinconf (stable-fixes).
  - pinctrl: devicetree: do not goto err when probing hogs in
    pinctrl_dt_to_map (stable-fixes).
  - PNP: Expand length of fixup id string (stable-fixes).
  - commit 30aa389
  - PCI: rcar-gen4: set ep BAR4 fixed size (git-fixes).
  - PCI: dwc: ep: Fix errno typo (git-fixes).
  - PCI: dw-rockchip: Fix PHY function call sequence in
    rockchip_pcie_phy_deinit() (git-fixes).
  - PCI: dw-rockchip: Remove PCIE_L0S_ENTRY check from
    rockchip_pcie_link_up() (git-fixes).
  - PCI: cadence: Fix runtime atomic count underflow (git-fixes).
  - PCI: apple: Use gpiod_set_value_cansleep in probe flow
    (git-fixes).
  - PCI: cadence-ep: Correct PBA offset in .set_msix() callback
    (git-fixes).
  - PCI: dwc: ep: Correct PBA offset in .set_msix() callback
    (git-fixes).
  - PCI: Fix lock symmetry in pci_slot_unlock() (git-fixes).
  - PCI: Explicitly put devices into D0 when initializing
    (git-fixes).
  - PCI/ACPI: Fix allocated memory release on error in
    pci_acpi_scan_root() (git-fixes).
  - PCI: Print the actual delay time in
    pci_bridge_wait_for_secondary_bus() (git-fixes).
  - PCI/DPC: Log Error Source ID only when valid (git-fixes).
  - PCI/DPC: Initialize aer_err_info before using it (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Move IRQ request in probe
    (stable-fixes).
  - phy: phy-rockchip-samsung-hdptx: Fix PHY PLL output 50.25MHz
    error (stable-fixes).
  - phy: starfive: jh7110-usb: Fix USB 2.0 host occasional detection
    failure (stable-fixes).
  - phy: rockchip: usbdp: Only verify link rates/lanes/voltage
    when the corresponding set flags are set (stable-fixes).
  - phy: phy-rockchip-samsung-hdptx: Swap the definitions of
    LCPLL_REF and ROPLL_REF (stable-fixes).
  - phy: core: don't require set_mode() callback for phy_get_mode()
    to work (stable-fixes).
  - phy: exynos5-usbdrd: fix EDS distribution tuning (gs101)
    (stable-fixes).
  - PCI: dwc: ep: Ensure proper iteration over outbound map windows
    (stable-fixes).
  - PCI: dwc: Use resource start as ioremap() input in
    dw_pcie_pme_turn_off() (stable-fixes).
  - PCI: brcmstb: Expand inbound window size up to 64GB
    (stable-fixes).
  - PCI: brcmstb: Add a softdep to MIP MSI-X driver (stable-fixes).
  - PCI: epf-mhi: Update device ID for SA8775P (stable-fixes).
  - PCI: endpoint: pci-epf-test: Fix double free that causes kernel
    to oops (stable-fixes).
  - PCI: Fix old_size lower bound in calculate_iosize() too
    (stable-fixes).
  - PCI: vmd: Disable MSI remapping bypass under Xen (stable-fixes).
  - commit 697d499
  - mfd: stmpe-spi: Correct the name used in MODULE_DEVICE_TABLE
    (git-fixes).
  - mfd: exynos-lpass: Avoid calling exynos_lpass_disable() twice
    in exynos_lpass_remove() (git-fixes).
  - mfd: exynos-lpass: Fix an error handling path in
    exynos_lpass_probe() (git-fixes).
  - mtd: rawnand: brcmnand: legacy exec_op implementation
    (git-fixes).
  - mtd: rawnand: sunxi: Add randomizer configuration in
    sunxi_nfc_hw_ecc_write_chunk (git-fixes).
  - mtd: nand: sunxi: Add randomizer configuration before randomizer
    enable (git-fixes).
  - mtd: spinand: esmt: fix id code for F50D1G41LB (git-fixes).
  - mtd: rawnand: qcom: Fix read len for onfi param page
    (git-fixes).
  - mtd: nand: ecc-mxic: Fix use of uninitialized variable ret
    (git-fixes).
  - net: phy: mscc: Stop clearing the the UDPv4 checksum for L2
    frames (git-fixes).
  - net: phy: mscc: Fix memory leak when using one step timestamping
    (git-fixes).
  - net: phy: clear phydev->devlink when the link is deleted
    (git-fixes).
  - net: phy: fix up const issues in to_mdio_device() and
    to_phy_device() (git-fixes).
  - media: verisilicon: Free post processor buffers on error
    (git-fixes).
  - mei: vsc: Use struct vsc_tp_packet as vsc-tp tx_buf and rx_buf
    type (stable-fixes).
  - mfd: tps65219: Remove TPS65219_REG_TI_DEV_ID check
    (stable-fixes).
  - mfd: axp20x: AXP717: Add AXP717_TS_PIN_CFG to writeable regs
    (stable-fixes).
  - net: phy: nxp-c45-tja11xx: add match_phy_device to
    TJA1103/TJA1104 (stable-fixes).
  - commit 80f0e45
  - media: uvcvideo: Fix deferred probing error (git-fixes).
  - media: uvcvideo: Send control events for partial succeeds
    (git-fixes).
  - media: uvcvideo: Return the number of processed controls
    (git-fixes).
  - media: omap3isp: use sgtable-based scatterlist wrappers
    (git-fixes).
  - media: videobuf2: use sgtable-based scatterlist wrappers
    (git-fixes).
  - media: v4l2-dev: fix error handling in __video_register_device()
    (git-fixes).
  - media: i2c: imx335: Fix frame size enumeration (git-fixes).
  - media: ov8856: suppress probe deferral errors (git-fixes).
  - media: ov5675: suppress probe deferral errors (git-fixes).
  - media: imx335: Use correct register width for HNUM (git-fixes).
  - media: nxp: imx8-isi: better handle the m2m usage_count
    (git-fixes).
  - media: gspca: Add error handling for stv06xx_read_sensor()
    (git-fixes).
  - media: davinci: vpif: Fix memory leak in probe error path
    (git-fixes).
  - media: vivid: Change the siize of the composing (git-fixes).
  - media: cxusb: no longer judge rbuf when the write fails
    (git-fixes).
  - media: vidtv: Terminating the subsequent process of
    initialization failure (git-fixes).
  - media: intel/ipu6: Fix dma mask for non-secure mode (git-fixes).
  - media: ov2740: Move pm-runtime cleanup on probe-errors to
    proper place (git-fixes).
  - media: ccs-pll: Correct the upper limit of maximum
    op_pre_pll_clk_div (git-fixes).
  - media: ccs-pll: Check for too high VT PLL multiplier in dual
    PLL case (git-fixes).
  - media: ccs-pll: Start VT pre-PLL multiplier search from correct
    value (git-fixes).
  - media: ccs-pll: Start OP pre-PLL multiplier search from correct
    value (git-fixes).
  - media: ipu6: Remove workaround for Meteor Lake ES2 (git-fixes).
  - media: i2c: ds90ub913: Fix returned fmt from .set_fmt()
    (git-fixes).
  - media: imx-jpeg: Cleanup after an allocation error (git-fixes).
  - media: imx-jpeg: Reset slot data pointers when freed
    (git-fixes).
  - media: imx-jpeg: Move mxc_jpeg_free_slot_data() ahead
    (git-fixes).
  - media: imagination: fix a potential memory leak in e5010_probe()
    (git-fixes).
  - media: imx-jpeg: Drop the first error frames (git-fixes).
  - media: venus: Fix probe error handling (git-fixes).
  - media: mediatek: vcodec: Correct vsi_core framebuffer size
    (git-fixes).
  - media: rkvdec: Fix frame size enumeration (git-fixes).
  - media: c8sectpfe: Call of_node_put(i2c_bus) only once in
    c8sectpfe_probe() (stable-fixes).
  - media: cx231xx: set device_caps for 417 (stable-fixes).
  - media: imx335: Set vblank immediately (stable-fixes).
  - media: uvcvideo: Add sanity check to uvc_ioctl_xu_ctrl_map
    (stable-fixes).
  - media: uvcvideo: Handle uvc menu translation inside
    uvc_get_le_value (stable-fixes).
  - media: adv7180: Disable test-pattern control on adv7180
    (stable-fixes).
  - media: tc358746: improve calculation of the D-PHY timing
    registers (stable-fixes).
  - media: test-drivers: vivid: don't call schedule in loop
    (stable-fixes).
  - commit 0c12415
  - Input: ims-pcu - check record size in ims_pcu_flash_firmware()
    (git-fixes).
  - Input: gpio-keys - fix possible concurrent access in
    gpio_keys_irq_timer() (git-fixes).
  - mailbox: mtk-cmdq: Refine GCE_GCTL_VALUE setting (git-fixes).
  - mailbox: imx: Fix TXDB_V2 sending (git-fixes).
  - intel_th: avoid using deprecated page->mapping, index fields
    (stable-fixes).
  - ima: process_measurement() needlessly takes inode_lock()
    on MAY_READ (stable-fixes).
  - i3c: master: svc: Fix implicit fallthrough in
    svc_i3c_master_ibi_work() (git-fixes).
  - i3c: master: svc: Fix missing STOP for master request
    (stable-fixes).
  - i3c: master: svc: Flush FIFO before sending Dynamic Address
    Assignment(DAA) (stable-fixes).
  - i2c: qup: Vote for interconnect bandwidth to DRAM
    (stable-fixes).
  - i2c: pxa: fix call balance of i2c->clk handling routines
    (stable-fixes).
  - iio: adc: ad7944: don't use storagebits for sizing
    (stable-fixes).
  - mailbox: use error ret code of of_parse_phandle_with_args()
    (stable-fixes).
  - leds: pwm-multicolor: Add check for fwnode_property_read_u32
    (stable-fixes).
  - leds: trigger: netdev: Configure LED blink interval for HW
    offload (stable-fixes).
  - ieee802154: ca8210: Use proper setters and getters for bitwise
    types (stable-fixes).
  - media: i2c: imx219: Correct the minimum vblanking value
    (stable-fixes).
  - media: v4l: Memset argument to 0 before calling get_mbus_config
    pad op (stable-fixes).
  - media: qcom: camss: csid: Only add TPG v4l2 ctrl if TPG hardware
    is available (stable-fixes).
  - media: qcom: camss: Add default case in vfe_src_pad_code
    (stable-fixes).
  - commit 71b3876
  - hwmon: (asus-ec-sensors) check sensor index in read_string()
    (git-fixes).
  - gpiolib: Revert "Don't WARN on gpiod_put() for optional GPIO"
    (stable-fixes).
  - gpio: virtuser: fix potential out-of-bound write (stable-fixes).
  - HID: quirks: Add ADATA XPG alpha wireless mouse support
    (stable-fixes).
  - fpga: altera-cvp: Increase credit timeout (stable-fixes).
  - HID: usbkbd: Fix the bit shift number for LED_KANA
    (stable-fixes).
  - hwmon: (dell-smm) Increment the number of fans (stable-fixes).
  - hwmon: (gpio-fan) Add missing mutex locks (stable-fixes).
  - hwmon: (xgene-hwmon) use appropriate type for the latency value
    (stable-fixes).
  - commit 3023def
  - EDAC/altera: Use correct write width with the INTTEST register
    (git-fixes).
  - fbdev: Fix fb_set_var to prevent null-ptr-deref in
    fb_videomode_to_var (git-fixes).
  - fbdev: Fix do_register_framebuffer to prevent null-ptr-deref
    in fb_videomode_to_var (git-fixes).
  - fbdev: core: fbcvt: avoid division by 0 in fb_cvt_hperiod()
    (git-fixes).
  - firmware: arm_scmi: Ensure that the message-id supports
    fastchannel (git-fixes).
  - efi/libstub: Describe missing 'out' parameter in efi_load_initrd
    (git-fixes).
  - firmware: psci: Fix refcount leak in psci_dt_init (git-fixes).
  - drm/msm/a6xx: Disable rgb565_predicator on Adreno 7c3
    (git-fixes).
  - drm/msm/gpu: Fix crash when throttling GPU immediately during
    boot (git-fixes).
  - drm/msm/dpu: enable SmartDMA on SC8180X (git-fixes).
  - drm/msm/dpu: enable SmartDMA on SM8150 (git-fixes).
  - drm/mediatek: mtk_drm_drv: Unbind secondary mmsys components
    on err (git-fixes).
  - drm/mediatek: Fix kobject put for component sub-drivers
    (git-fixes).
  - drm/mediatek: mtk_drm_drv: Fix kobject put for mtk_mutex device
    ptr (git-fixes).
  - Revert "drm/amdgpu: don't allow userspace to create a doorbell
    BO" (stable-fixes).
  - drm/amd/pp: Fix potential NULL pointer dereference in
    atomctrl_initialize_mc_reg_table (git-fixes).
  - EDAC/skx_common: Fix general protection fault (git-fixes).
  - eeprom: ee1004: Check chip before probing (stable-fixes).
  - fbdev: fsl-diu-fb: add missing device_remove_file()
    (stable-fixes).
  - fbcon: Use correct erase colour for clearing in fbcon
    (stable-fixes).
  - fbdev: core: tileblit: Implement missing margin clearing for
    tileblit (stable-fixes).
  - firmware: xilinx: Dont send linux address to get fpga config
    get status (stable-fixes).
  - firmware: arm_ffa: Set dma_mask for ffa devices (stable-fixes).
  - firmware: arm_ffa: Reject higher major version as incompatible
    (stable-fixes).
  - firmware: arm_ffa: Handle the presence of host partition in
    the partition info (stable-fixes).
  - firmware: arm_scmi: Relax duplicate name constraint across
    protocol ids (stable-fixes).
  - commit 1c0c86d
  - drm/tegra: Fix a possible null pointer dereference (git-fixes).
  - drm/tegra: rgb: Fix the unbound reference count (git-fixes).
  - drm/tegra: Assign plane type before registration (git-fixes).
  - drm/vkms: Adjust vkms_state->active_planes allocation type
    (git-fixes).
  - drm: rcar-du: Fix memory leak in rcar_du_vsps_init()
    (git-fixes).
  - drm/bridge: lt9611uxc: Fix an error handling path in
    lt9611uxc_probe() (git-fixes).
  - drm/panel: samsung-sofef00: Drop s6e3fc2x01 support (git-fixes).
  - drm/panthor: Update panthor_mmu::irq::mask when needed
    (git-fixes).
  - drm/panthor: Fix GPU_COHERENCY_ACE[_LITE] definitions
    (git-fixes).
  - drm/ast: Fix comment on modeset lock (git-fixes).
  - drm/vc4: tests: Use return instead of assert (git-fixes).
  - drm/bridge: cdns-dsi: Wait for Clk and Data Lanes to be ready
    (git-fixes).
  - drm/bridge: cdns-dsi: Check return value when getting default
    PHY config (git-fixes).
  - drm/bridge: cdns-dsi: Fix the clock variable for mode_valid()
    (git-fixes).
  - drm/bridge: cdns-dsi: Fix phy de-init and flag it so
    (git-fixes).
  - drm/bridge: cdns-dsi: Fix connecting to next bridge (git-fixes).
  - drm/panic: add missing space (git-fixes).
  - drm/udl: Unregister device before cleaning up on disconnect
    (git-fixes).
  - drm/vmwgfx: Fix dumb buffer leak (git-fixes).
  - drm/vmwgfx: Add error path for xa_store in
    vmw_bo_add_detached_resource (git-fixes).
  - commit a60f216
  - drm/amd/display: Configure DTBCLK_P with OPTC only for dcn401
    (stable-fixes).
  - Refresh
    patches.suse/drm-amd-display-prevent-hang-on-link-training-fail.patch.
  - commit 16ba726
  - docs: dt: Update overlay file extension (git-fixes).
  - drm/vmwgfx: Add seqno waiter for sync_files (git-fixes).
  - drm/xe/d3cold: Set power state to D3Cold during s2idle/s3
    (git-fixes).
  - Documentation: ACPI: Use all-string data node references
    (git-fixes).
  - docs: doc-guide: clarify latest theme usage (git-fixes).
  - Documentation/scheduler: Fix typo in sched-stats domain field
    description (git-fixes).
  - Documentation/rtla: Fix typo in common_timerlat_description.rst
    (git-fixes).
  - Documentation/rtla: Fix typo in rtla-timerlat.rst (git-fixes).
  - Documentation/rtla: Fix duplicate text about timerlat tracer
    (git-fixes).
  - crypto: api - Redo lookup on EEXIST (git-fixes).
  - crypto: marvell/cesa - Do not chain submitted requests
    (git-fixes).
  - crypto: sun8i-ce - move fallback ahash_request to the end of
    the struct (git-fixes).
  - crypto: xts - Only add ecb if it is not already there
    (git-fixes).
  - crypto: lrw - Only add ecb if it is not already there
    (git-fixes).
  - crypto: marvell/cesa - Avoid empty transfer descriptor
    (git-fixes).
  - crypto: marvell/cesa - Handle zero-length skcipher requests
    (git-fixes).
  - crypto: sun8i-ce - undo runtime PM changes during driver removal
    (git-fixes).
  - crypto: sun8i-ss - do not use sg_dma_len before calling DMA
    functions (git-fixes).
  - crypto: sun8i-ce-cipher - fix error handling in
    sun8i_ce_cipher_prepare() (git-fixes).
  - dmaengine: idxd: cdev: Fix uninitialized use of sva in
    idxd_cdev_open (stable-fixes).
  - drm/xe: Save the gt pointer in lrc and drop the tile
    (stable-fixes).
  - drm/xe/xe2hpg: Add Wa_22021007897 (stable-fixes).
  - drm/amd/display: check stream id dml21 wrapper to get plane_id
    (stable-fixes).
  - drm/amd/display: fix link_set_dpms_off multi-display MST corner
    case (stable-fixes).
  - drm/amd/display: Defer BW-optimization-blocked DRR adjustments
    (git-fixes).
  - drm/amd/display: Call FP Protect Before Mode Programming/Mode
    Support (stable-fixes).
  - drm/amdgpu: Allow P2P access through XGMI (stable-fixes).
  - drm/amdgpu/discovery: check ip_discovery fw file available
    (stable-fixes).
  - drm/amdkfd: set precise mem ops caps to disabled for gfx 11
    and 12 (stable-fixes).
  - drm/amdgpu: Skip pcie_replay_count sysfs creation for VF
    (stable-fixes).
  - drm/amdgpu: release xcp_mgr on exit (stable-fixes).
  - drm/amd/display: Guard against setting dispclk low for dcn31x
    (stable-fixes).
  - drm/amdgpu: adjust drm_firmware_drivers_only() handling
    (stable-fixes).
  - drm/amdkfd: Correct F8_MODE for gfx950 (git-fixes).
  - drm/amdgpu/gfx12: don't read registers in mqd init
    (stable-fixes).
  - drm/amdgpu/gfx11: don't read registers in mqd init
    (stable-fixes).
  - drm/amdgpu: Fix the race condition for draining retry fault
    (stable-fixes).
  - drm/amdgpu: Update SRIOV video codec caps (stable-fixes).
  - drm/amd/display: remove minimum Dispclk and apply oem panel
    timing (stable-fixes).
  - drm/amd/display: Correct timing_adjust_pending flag setting
    (stable-fixes).
  - drm/amd/display: calculate the remain segments for all pipes
    (stable-fixes).
  - drm/amd/display: not abort link train when bw is low
    (stable-fixes).
  - drm/amd/display: Do not enable replay when vtotal update is
    pending (stable-fixes).
  - drm/amd/display: Fix incorrect DPCD configs while Replay/PSR
    switch (stable-fixes).
  - drm/mediatek: mtk_dpi: Add checks for reg_h_fre_con existence
    (stable-fixes).
  - drm/xe: Nuke VM's mapping upon close (stable-fixes).
  - drm/xe: Retry BO allocation (stable-fixes).
  - drm/xe/vf: Retry sending MMIO request to GUC on timeout error
    (stable-fixes).
  - drm/xe/pf: Create a link between PF and VF devices
    (stable-fixes).
  - drm/xe: xe_gen_wa_oob: replace program_invocation_short_name
    (stable-fixes).
  - drm/amdkfd: Set per-process flags only once for gfx9/10/11/12
    (stable-fixes).
  - drm/amdkfd: Set per-process flags only once cik/vi
    (stable-fixes).
  - drm/amdgpu: Fix missing drain retry fault the last entry
    (stable-fixes).
  - drm/amdgpu: Do not program AGP BAR regs under SRIOV in
    gfxhub_v1_0.c (stable-fixes).
  - drm/amd/display: Ensure DMCUB idle before reset on DCN31/DCN35
    (stable-fixes).
  - drm/amd/display: Skip checking FRL_MODE bit for PCON BW
    determination (stable-fixes).
  - drm/amd/display: Fix DMUB reset sequence for DCN401
    (stable-fixes).
  - drm/amd/display: Fix p-state type when p-state is unsupported
    (stable-fixes).
  - drm/amd/display: Request HW cursor on DCN3.2 with SubVP
    (stable-fixes).
  - drm/amdkfd: KFD release_work possible circular locking
    (stable-fixes).
  - drm/amd/display: handle max_downscale_src_width fail check
    (stable-fixes).
  - drm/amd/display: fix dcn4x init failed (stable-fixes).
  - drm/amdgpu: remove all KFD fences from the BO on release
    (stable-fixes).
  - drm/rockchip: vop2: Add uv swap for cluster window
    (stable-fixes).
  - drm/xe/oa: Ensure that polled read returns latest data
    (stable-fixes).
  - drm/xe: Stop ignoring errors from xe_ttm_stolen_mgr_init()
    (stable-fixes).
  - drm/xe: Fix xe_tile_init_noalloc() error propagation
    (stable-fixes).
  - drm/xe/debugfs: fixed the return value of wedged_mode_set
    (stable-fixes).
  - drm/xe/debugfs: Add missing xe_pm_runtime_put in wedge_mode_set
    (stable-fixes).
  - drm/xe/relay: Don't use GFP_KERNEL for new transactions
    (stable-fixes).
  - drm/xe/pf: Reset GuC VF config when unprovisioning critical
    resource (stable-fixes).
  - drm/xe: Move suballocator init to after display init
    (stable-fixes).
  - drm/xe: Do not attempt to bootstrap VF in execlists mode
    (stable-fixes).
  - drm/xe/sa: Always call drm_suballoc_manager_fini()
    (stable-fixes).
  - drm/xe: Reject BO eviction if BO is bound to current VM
    (stable-fixes).
  - drm/amd/pm: Fetch current power limit from PMFW (stable-fixes).
  - drm/amd/display: Add support for disconnected eDP streams
    (stable-fixes).
  - drm/amd/display: Guard against setting dispclk low when active
    (stable-fixes).
  - drm/amd/display: Fix BT2020 YCbCr limited/full range input
    (stable-fixes).
  - drm/amd/display: Read LTTPR ALPM caps during link cap retrieval
    (stable-fixes).
  - drm/amd/display: Don't treat wb connector as physical in
    create_validate_stream_for_sink (stable-fixes).
  - drm/amdgpu/mes11: fix set_hw_resources_1 calculation
    (stable-fixes).
  - drm/amdkfd: fix missing L2 cache info in topology
    (stable-fixes).
  - drm/amdgpu: Set snoop bit for SDMA for MI series (stable-fixes).
  - drm/amd/display: pass calculated dram_speed_mts to dml2
    (stable-fixes).
  - drm/amd/display: Don't try AUX transactions on disconnected link
    (stable-fixes).
  - drm/amdgpu: reset psp->cmd to NULL after releasing the buffer
    (stable-fixes).
  - drm/amd/pm: Skip P2S load for SMU v13.0.12 (stable-fixes).
  - drm/amd/display: Support multiple options during psr entry
    (stable-fixes).
  - drm/amd/display: Update CR AUX RD interval interpretation
    (stable-fixes).
  - drm/amd/display: Initial psr_version with correct setting
    (stable-fixes).
  - drm/amd/display: Increase block_sequence array size
    (stable-fixes).
  - drm/amd/display: Use Nominal vBlank If Provided Instead Of
    Capping It (stable-fixes).
  - drm/amd/display: Populate register address for dentist for
    dcn401 (stable-fixes).
  - drm/amdgpu: Use active umc info from discovery (stable-fixes).
  - drm/amdgpu: enlarge the VBIOS binary size limit (stable-fixes).
  - drm/amd/display/dm: drop hw_support check in
    amdgpu_dm_i2c_xfer() (stable-fixes).
  - drm/v3d: Add clock handling (stable-fixes).
  - drm/rockchip: vop2: Improve display modes handling on RK3588
    HDMI0 (stable-fixes).
  - drm/ast: Find VBIOS mode from regular display size
    (stable-fixes).
  - drm: bridge: adv7511: fill stream capabilities (stable-fixes).
  - drm/nouveau: fix the broken marco GSP_MSG_MAX_SIZE
    (stable-fixes).
  - drm/atomic: clarify the rules around
    drm_atomic_state->allow_modeset (stable-fixes).
  - drm/buddy: fix issue that force_merge cannot free all roots
    (stable-fixes).
  - drm/panel-edp: Add Starry 116KHD024006 (stable-fixes).
  - drm: Add valid clones check (stable-fixes).
  - commit 88828d8
  - crypto: sun8i-ce-hash - fix error handling in
    sun8i_ce_hash_run() (git-fixes).
  - can: kvaser_pciefd: Continue parsing DMA buf after dropped RX
    (stable-fixes).
  - can: kvaser_pciefd: Fix echo_skb race (stable-fixes).
  - char: tpm: tpm-buf: Add sanity check fallback in read helpers
    (stable-fixes).
  - crypto: octeontx2 - suppress auth failure screaming due to
    negative tests (stable-fixes).
  - crypto: lzo - Fix compression buffer overrun (stable-fixes).
  - crypto: mxs-dcp - Only set OTP_KEY bit for OTP key
    (stable-fixes).
  - crypto: skcipher - Zap type in crypto_alloc_sync_skcipher
    (stable-fixes).
  - commit a9645bd
  - backlight: pm8941: Add NULL check in wled_configure()
    (git-fixes).
  - bus: fsl-mc: fix GET/SET_TAILDROP command ids (git-fixes).
  - bus: fsl-mc: do not add a device-link for the UAPI used DPMCP
    device (git-fixes).
  - bus: fsl-mc: fix double-free on mc_dev (git-fixes).
  - Revert "bus: ti-sysc: Probe for l4_wkup and l4_cfg interconnect
    devices first" (stable-fixes).
  - Bluetooth: btintel: Check dsbr size from EFI variable
    (git-fixes).
  - Bluetooth: MGMT: iterate over mesh commands in
    mgmt_mesh_foreach() (git-fixes).
  - ASoC: qcom: sdm845: Add error handling in
    sdm845_slim_snd_hw_params() (git-fixes).
  - ASoC: apple: mca: Constrain channels according to TDM mask
    (git-fixes).
  - ASoC: amd: sof_amd_sdw: Fix unlikely uninitialized variable
    use in create_sdw_dailinks() (git-fixes).
  - ASoC: SOF: amd: add missing acp descriptor field (git-fixes).
  - ASoC: SOF: ipc4-pcm: Adjust pipeline_list->pipelines allocation
    type (git-fixes).
  - ASoC: meson: meson-card-utils: use of_property_present()
    for DT parsing (git-fixes).
  - Bluetooth: btmtksdio: Do close if SDIO card removed without
    close (git-fixes).
  - Bluetooth: btmtksdio: Check function enabled before doing close
    (git-fixes).
  - Bluetooth: btmtksdio: Prevent enabling interrupts after IRQ
    handler removal (stable-fixes).
  - Bluetooth: Disable SCO support if READ_VOICE_SETTING is
    unsupported/broken (stable-fixes).
  - can: c_can: Use of_property_present() to test existence of DT
    property (stable-fixes).
  - commit 8fe3f19
  - ASoC: mediatek: mt8195: Set ETDM1/2 IN/OUT to COMP_DUMMY()
    (git-fixes).
  - ASoC: tas2764: Enable main IRQs (git-fixes).
  - ASoC: tas2764: Reinit cache on part reset (git-fixes).
  - ASoC: intel/sdw_utils: Add volume limit to cs42l43 speakers
    (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Acer Aspire SW3-013
    (stable-fixes).
  - ASoC: cs42l43: Disable headphone clamps during type detection
    (stable-fixes).
  - ASoC: imx-card: Adjust over allocation of memory in
    imx_card_parse_of() (stable-fixes).
  - ASoC: codecs: wsa884x: Correct VI sense channel mask
    (stable-fixes).
  - ASoC: codecs: wsa883x: Correct VI sense channel mask
    (stable-fixes).
  - commit 86bb694
  - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14ASP10
    (stable-fixes).
  - ALSA: hda/realtek - restore auto-mute mode for Dell Chrome
    platform (stable-fixes).
  - ALSA: pcm: Fix race of buffer access at PCM OSS layer
    (stable-fixes).
  - ALSA: usb-audio: Fix duplicated name in MIDI substream names
    (stable-fixes).
  - ALSA: hda/realtek: Add quirk for HP Spectre x360 15-df1xxx
    (stable-fixes).
  - ASoC: pcm6240: Drop bogus code handling IRQ as GPIO
    (stable-fixes).
  - ASoC: mediatek: mt6359: Add stub for
    mt6359_accdet_enable_jack_detect (stable-fixes).
  - ASoC: sun4i-codec: support hp-det-gpios property (stable-fixes).
  - ASoC: qcom: sm8250: explicitly set format in
    sm8250_be_hw_params_fixup() (stable-fixes).
  - ASoC: mediatek: mt8188: Treat DMIC_GAINx_CUR as non-volatile
    (stable-fixes).
  - ASoC: mediatek: mt8188: Add reference for dmic clocks
    (stable-fixes).
  - ASoC: soc-dai: check return value at snd_soc_dai_set_tdm_slot()
    (stable-fixes).
  - ASoC: tas2764: Add reg defaults for TAS2764_INT_CLK_CFG
    (stable-fixes).
  - ASoC: tas2764: Mark SW_RESET as volatile (stable-fixes).
  - ASoC: tas2764: Power up/down amp on mute ops (stable-fixes).
  - ASoC: ops: Enforce platform maximum on initial value
    (stable-fixes).
  - ASoC: codecs: pcm3168a: Allow for 24-bit in provider mode
    (stable-fixes).
  - ASoC: rt722-sdca: Add some missing readable registers
    (stable-fixes).
  - ALSA: seq: Improve data consistency at polling (stable-fixes).
  - commit 08338b9
  - kABI workaround for hda_codec.beep_just_power_on flag
    (git-fixes).
  - commit 2932a2f
  - acpi-cpufreq: Fix nominal_freq units to KHz in
    get_max_boost_ratio() (git-fixes).
  - ACPI: resource: fix a typo for MECHREVO in
    irq1_edge_low_force_override[] (git-fixes).
  - ACPICA: Utilities: Fix spelling mistake "Incremement" ->
    "Increment" (git-fixes).
  - ACPICA: exserial: don't forget to handle FFixedHW opregions
    for reading (git-fixes).
  - ACPI: OSI: Stop advertising support for "3.0 _SCP Extensions"
    (git-fixes).
  - ACPI: PNP: Add Intel OC Watchdog IDs to non-PNP device list
    (stable-fixes).
  - accel/qaic: Mask out SR-IOV PCI resources (stable-fixes).
  - ALSA: hda/realtek: Enable PC beep passthrough for HP EliteBook
    855 G7 (stable-fixes).
  - ACPI: HED: Always initialize before evged (stable-fixes).
  - commit a49c2aa
  - kabi/severities: Add more PPC KVM symbols
  - commit 72910b3
  - Update patches.suse/mm-execmem-Unify-early-execmem_cache-behaviour.patch (bsc#1244062).
  - commit d02c14c
  - accel/ivpu: Correct mutex unlock order in job submission
    (git-fixes).
  - commit 9044b56
  - net: ethernet: mtk-star-emac: fix spinlock recursion issues
    on rx/tx poll (CVE-2025-37917 bsc#1243475).
  - commit 6f4e259
  - net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
    (CVE-2025-37935 bsc#1243546).
  - commit 8eb532f
  - Delete patches.suse/procfs-add-tunable-for-fd-fdinfo-dentry-retention.patch.
  - commit c9207ce
  - platform/x86: thinkpad_acpi: Ignore battery threshold change
    event notification (git-fixes).
  - commit de4db35
  - platform/x86: fujitsu-laptop: Support Lifebook S2110 hotkeys
    (git-fixes).
  - commit aad5008
  - platform/x86: thinkpad_acpi: Support also NEC Lavie X1475JAS
    (git-fixes).
  - commit 3d5ab3a
  - accel/ivpu: Fix locking order in ivpu_job_submit (CVE-2025-37907 bsc#1243464).
  - commit 9c91371
  - accel/ivpu: Abort all jobs after command queue unregister (CVE-2025-37907 bsc#1243464).
  - commit de61fba
  - kABI: kabi fixes after tdx host patches (jsc#PED-348).
  - commit d736c22

++++ libarchive:

  - update to 3.8.1:
    * libarchive: fix FILE_skip regression
    * compress: Prevent call stack overflow
    * iso9660: always check archive_string_ensure return value
    * tar: Support negative time values with pax
    * tar: Reset accumulated header state after reading macOS metadata blob
    * tar: Keep block alignment after pax error
    * tar: Handle extra bytes after sparse entries
  - includes changes from 3.8.0:
    * bsdtar: support --mtime and --clamp-mtime
    * 7-zip reader: improve self-extracting archive detection
    * xar: xmllite support for the XAR reader and writer
    * zip writer: added XZ, LZMA, ZSTD and BZIP2 support
    * zip writer: added LZMA + RISCV BCJ filter
    * rar: do not skip past EOF while reading (boo#1244159)
    * rar: fix double free with over 4 billion nodes (boo#1244160)
    * rar: fix heap-buffer-overflow (boo#1244161)
    * warc: prevent signed integer overflow (boo#1244162)
    * tar: fix overflow in build_ustar_entry (boo#1244163)
    * bsdtar: don't hardlink negative inode files together
    * gz: allow setting the original filename for gzip compressed files
    * lib: improve lseek handling
    * lib: support @-prefixed Unix epoch timestamps as date strings
    * rar: support large headers on 32 bit systems
    * tar reader: Improve LFS support on 32 bit systems
  - drop lib-suffix.patch, different implementation upstream
  - spec file clean-up, removing currently unused -static

++++ libbpf:

  - Workaround kernel module size increase due to BTF deduplication
    issue since the introduction of TYPEOF_UNQUAL (poo#183503 bsc#1244135)
    * add 0001-libbpf-Add-identical-pointer-detection-to-btf_dedup_.patch

++++ perl:

  - do not change the current directory when cloning an open
    directory handle [bnc#1244079] [CVE-2025-40909]
    new patch: perl-dirdup.diff

++++ python-requests:

  - Add CVE-2024-47081.patch upstream patch, fixes netrc credential leak
    (gh#psf/requests#6965, CVE-2024-47081, bsc#1244039)

++++ rust-keylime:

  - Update vendored crates (bsc#1243861, CVE-2024-12224)
    * idna 1.0.3
  - Add Cargo_lock.patch to adjust versions that will allow the
    compilation of mbox crate
  - Update to version 0.2.7+70:
    * build(deps): bump wiremock from 0.6.2 to 0.6.3
    * build(deps): bump uuid from 1.16.0 to 1.17.0
    * lib: Introduce AgentIdentity structure
    * gitignore: Add *.swp and *.orig to be ignored
    * build(deps): bump clap from 4.5.38 to 4.5.39
    * build(deps): bump tokio from 1.45.0 to 1.45.1
    * Unify Push Model structures time formats to UTC (#1016)
    * Add Quote related structures to Keylime library
    * Remove configuration file trailing whitespaces (#1012)
    * keylime-agent.conf: add all accepted TPM encryption algs
    * tpm: add policy auth for EK to activate crendential
    * Enable non standard key sizes and curves for EK and AK
    * config: Use next_back() instead of last() for iterators
    * Update to tss-esapi v7.6.0
    * Avoid duplicated call to ctx.create_ek
    * build(deps): bump clap from 4.5.23 to 4.5.38
    * Add registration for Push Model client
    * build(deps): bump tokio from 1.44.2 to 1.45.0
    * build(deps): bump chrono from 0.4.40 to 0.4.41
    * build(deps): bump tempfile from 3.17.1 to 3.20.0
    * Refactor code: move error, registration to lib
    * Move structure filling and URL selection code (#999)
    * build(deps): bump pest_derive from 2.7.15 to 2.8.0
    * build(deps): bump pest from 2.7.15 to 2.8.0
    * build(deps): bump libc from 0.2.169 to 0.2.172
    * Add Evidence/Authentication messages to prototype
    * build(deps): bump uuid from 1.15.1 to 1.16.0
    * build(deps): bump thiserror from 2.0.11 to 2.0.12
    * build(deps): bump signal-hook from 0.3.17 to 0.3.18
    * build(deps): bump log from 0.4.25 to 0.4.27
    * build(deps): bump assert_cmd from 2.0.16 to 2.0.17
    * build(deps): bump actix-web from 4.9.0 to 4.10.2
    * build(deps): bump reqwest from 0.12.12 to 0.12.15
    * build(deps): bump serde from 1.0.217 to 1.0.219
    * Add unit tests for sessions.rs structures
    * Add auth(sessions) structures
    * Fix minor README.md issue (#988)
    * Define EvidenceHandling structures (#971)
    * Add mockoon test scenario
    * Add client certificates to push-attestation prototype
    * Cargo: bump url crate to version 2.5.4
    * Add logging to the push attestation prototype
    * Do not use certificate on insecure mode
    * common: Move the EncryptedData structure from common to the library
    * common: Move AuthTag from common to the library
    * build(deps): bump openssl from 0.10.71 to 0.10.72
    * common: Move Symmkey to library as crypto::symmkey
    * common: Remove unused constants and static values
    * build(deps): bump tokio from 1.43.0 to 1.44.2
    * Refactor code: Include AgentIdentity structure
    * Push model prototype
    * Add support for ek certificate chain, stored in TPM NVRAM.
    * Recover key_class field and set it as "asymmetric"
    * Update push model structures to latest values
    * build(deps): bump serde_json from 1.0.138 to 1.0.140
    * packit: Add identifier for each copr_build job
    * keylime-agent.conf: only mention ecdsa and rsassa for signing
    * build(deps): bump openssl from 0.10.70 to 0.10.71
    * build(deps): bump uuid from 1.13.2 to 1.15.1
    * Add capabilities_negotiation structures
    * packit: Add compatibility/api_version_compatibility test
    * build(deps): bump uuid from 1.11.0 to 1.13.2
    * build(deps): bump serde_json from 1.0.135 to 1.0.138
    * build(deps): bump thiserror from 2.0.9 to 2.0.11
    * build(deps): bump tempfile from 3.14.0 to 3.17.1
    * Allow agent to start as non-root
    * scripts: Fix coverage information downloading script
    * build(deps): bump openssl from 0.10.68 to 0.10.70
    * build(deps): bump tokio from 1.42.0 to 1.43.0

------------------------------------------------------------------
------------------  2025-6-4  -  Jun 4 2025  -------------------
------------------------------------------------------------------

++++ curl:

  - Update to 8.14.1:
    * Security fixes:
  - [bsc#1243933, CVE-2025-5399] libcurl can possibly get
    trapped in an endless busy-loop when processing specially
    crafted packets [d1145df2]
    * Bugfixes:
  - asyn-thrdd: fix cleanup when RR fails due to OOM
  - ftp: fix teardown of DATA connection in done
  - http: fail early when rewind of input failed when following redirects
  - multi: fix add_handle resizing
  - tls BIOs: handle BIO_CTRL_EOF correctly
  - tool_getparam: make --no-anyauth not be accepted
  - wolfssl: fix sending of early data
  - ws: handle blocked sends better
  - ws: tests and fixes

++++ docker:

  - Always clear SUSEConnect suse_* secrets when starting containers regardless
    of whether the daemon was built with SUSEConnect support. Not doing this
    causes containers from SUSEConnect-enabled daemons to fail to start when
    running with SUSEConnect-disabled (i.e. upstream) daemons.
    This was a long-standing issue with our secrets support but until recently
    this would've required migrating from SLE packages to openSUSE packages
    (which wasn't supported). However, as SLE Micro 6.x and SLES 16 will move
    away from in-built SUSEConnect support, this is now a practical issue users
    will run into. bsc#1244035
    + 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
  - Rearrange patches:
  - 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    + 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  - 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    + 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  - 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    + 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  - 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    + 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  - 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    + 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    [NOTE: This update was only ever released in SLES and Leap.]
  - Always clear SUSEConnect suse_* secrets when starting containers regardless
    of whether the daemon was built with SUSEConnect support. Not doing this
    causes containers from SUSEConnect-enabled daemons to fail to start when
    running with SUSEConnect-disabled (i.e. upstream) daemons.
    This was a long-standing issue with our secrets support but until recently
    this would've required migrating from SLE packages to openSUSE packages
    (which wasn't supported). However, as SLE Micro 6.x and SLES 16 will move
    away from in-built SUSEConnect support, this is now a practical issue users
    will run into. bsc#1244035
    + 0001-SECRETS-SUSE-always-clear-our-internal-secrets.patch
  - Rearrange patches:
  - 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    + 0002-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
  - 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    + 0003-SECRETS-SUSE-implement-SUSE-container-secrets.patch
  - 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    + 0004-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
  - 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    + 0005-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
  - 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    + 0006-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  - 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
    + 0007-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  - 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch
    + 0008-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch

++++ fwupd:

  - Update to version 2.0.11:
    + This release adds the following features:
  - Add a new check-reboot-needed command for scripts to use
  - Read the SELinux state in the report failure metadata
    + This release fixes the following bugs:
  - Add some notes in the README about security-relevant build flags
  - Add support for the Dell dock ownership command
  - Add the subsystem VIDPID when provided by ModemManager
  - Allow changing the rts54hub block size from a quirk entry
  - Allow Legion HID2 downgrades without --force, and clear config on upgrades
  - Allow specifying multiple DEVICE-IDs for the get-updates command
  - Cache the stream when parsing the processed cabinet to fix the report upload
  - Do not allow DBX updates on the AiStone X5KK4NAG
  - Do not use translated low-level error messages in the failure report
  - Fall back to the activation date if the X.509 cert has no suitable subject
  - Fix newer Synaptics VMM9 devices by adding a delay after disabling RC
  - Ignore some sanity checks when parsing PK, KEK and db certificates
  - Increase timeout requested by logitech RDFU devices
  - Never include systemd.machine_id in the failure report
  - Parse the correct VendorID from the ModemManager device ID
  - Process all pending event sources when waiting for replug
  - Use the UEFI PK report attributes for the other UEFI plugins
    + This release adds support for the following hardware:
  - Lenovo Thunderbolt 5 Smart Dock

++++ kernel-default:

  - Delete
    patches.suse/scsi-target-iscsi-don-t-warn-of-R-W-when-no-data.patch.
    This patch was never accepted upstream, and it has a simple
    workaround.
  - commit f19bccd
  - Delete
    patches.suse/scsi-target-iscsi-handle-SCSI-immediate-commands.patch.
    This patch was never accepted upstream, and it has a simple
    workaround.
  - commit b76df52
  - iommu: Protect against overflow in iommu_pgsize() (git-fixes).
  - commit 447faef
  - Drop unneeded guarded patches
  - Delete
    patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch.
  - Delete
    patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch.
  - Delete
    patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch.
  - commit 109a1a7
  - ext4: ignore xattrs past end (bsc#1242846 CVE-2025-37738).
  - commit 4250787
  - KVM: VMX: use __always_inline for is_td_vcpu and is_td
    (git-fixes).
  - commit b92c31e
  - KVM: x86: Revert kvm_x86_ops.mem_enc_ioctl() back to an OPTIONAL
    hook (git-fixes).
  - commit 60d9b39
  - KVM: x86: Do not use kvm_rip_read() unconditionally for
    KVM_PROFILING (git-fixes).
  - commit 6275fc3
  - KVM: x86: Do not use kvm_rip_read() unconditionally in KVM
    tracepoints (git-fixes).
  - commit 4df0c10
  - usb: xhci: Don't change the status of stalled TDs on failed
    Stop EP (git-fixes).
  - commit c602063
  - net: usb: aqc111: fix error handling of usbnet read calls
    (git-fixes).
  - commit 161e4aa
  - r8152: add vendor/device ID pair for Dell Alienware AW1022z
    (git-fixes).
  - commit 0be40bd
  - mm/execmem: Unify early execmem_cache behaviour (git-fixes).
  - commit 2b988fd
  - iio: light: opt3001: fix deadlock due to concurrent flag access (CVE-2025-37968 bsc#1243571)
  - commit 38c1f6f
  - tc: Ensure we have enough buffer space when sending filter
    netlink notifications (git-fixes).
  - commit e91ebf9
  - net: pktgen: fix mpls maximum labels list parsing (git-fixes).
  - commit 23ee838
  - perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value (CVE-2025-37936 bsc#1243537)
  - commit 595605e
  - net: pktgen: fix access outside of user given buffer in
    pktgen_thread_write() (git-fixes).
  - commit dc28109
  - netdev: fix repeated netlink messages in queue stats
    (git-fixes).
  - commit 35d6fa6
  - net: sched: fix erspan_opt settings in cls_flower (git-fixes).
  - commit 3501db1
  - net/sched: tbf: correct backlog statistic for GSO packets
    (git-fixes).
  - commit dec223e
  - pds_core: Prevent possible adminq overflow/stuck condition (CVE-2025-37987 bsc#1243542)
  - commit 1019426
  - netfilter: fib: avoid lookup if socket is available (git-fixes).
  - commit 2ec4377
  - tcp: reorganize tcp_in_ack_event() and tcp_count_delivered()
    (git-fixes).
  - commit bb6f90b
  - net: ipv6: Init tunnel link-netns before registering dev
    (git-fixes).
  - commit 7594ce3
  - net: ipv6: fix missing dst ref drop in ila lwtunnel (git-fixes).
  - commit c1b70b1
  - net: ipv6: fix dst ref loop in ila lwtunnel (git-fixes).
  - commit 86493f5
  - net: ipv6: fix dst ref loop on input in rpl lwt (git-fixes).
  - commit 4009ad2
  - net: ipv6: fix dst ref loop on input in seg6 lwt (git-fixes).
  - commit 6e27dbd
  - powerpc/kvm-hv-pmu: Add perf-events for Hostwide counters
    (jsc#PED-11017).
  - powerpc/kvm-hv-pmu: Implement GSB message-ops for hostwide
    counters (jsc#PED-11017).
  - kvm powerpc/book3s-apiv2: Introduce kvm-hv specific PMU
    (jsc#PED-11017).
    Update config files.
  - kvm powerpc/book3s-apiv2: Add kunit tests for Hostwide GSB
    elements (jsc#PED-11017).
  - kvm powerpc/book3s-apiv2: Add support for Hostwide GSB elements
    (jsc#PED-11017).
  - powerpc: Document APIv2 KVM hcall spec for Hostwide counters
    (jsc#PED-11017).
  - commit 5094316
  - SUNRPC: Prevent hang on NFS mount with xprtsec=[m]tls
    (git-fixes).
  - commit fd7832d
  - nfs: ignore SB_RDONLY when remounting nfs (git-fixes).
  - commit da5b33e
  - nfs: clear SB_RDONLY before getting superblock (git-fixes).
  - commit 35b5d18
  - NFSv4: Don't check for OPEN feature support in v4.1 (git-fixes).
  - commit cb622d7
  - fs/nfs/read: fix double-unlock bug in nfs_return_empty_folio()
    (git-fixes).
  - commit d3f8f13
  - arm64: sysreg: Drag linux/kconfig.h to work around vdso build issue (git-fixes)
  - commit 1cc351d
  - i2c: tegra: check msg length in SMBUS block read (bsc#1242086)
  - commit d765f59
  - soc: qcom: ice: introduce devm_of_qcom_ice_get (git-fixes).
  - commit 6cb417e
  - powerpc/pseries/msi: Avoid reading PCI device registers in
    reduced power states (bsc#1215199).
  - KVM: powerpc: Enable commented out BUILD_BUG_ON() assertion
    (bsc#1215199).
  - commit 679f2a3
  - RDMA/uverbs: Propagate errors from rdma_lookup_get_uobject() (git-fixes)
  - commit cad8ec2
  - RDMA/core: Fix best page size finding when it can cross SG entries (git-fixes)
  - commit 3f842a4
  - Documentation/virt/kvm: Document on Trust Domain Extensions
    (TDX) (jsc#PED-348).
  - commit 8414857
  - KVM: TDX: Make TDX VM type supported (jsc#PED-348).
  - commit 707d68f
  - KVM: TDX: KVM: TDX: Always honor guest PAT on TDX enabled guests
    (jsc#PED-348).
  - commit 1989f3c
  - KVM: x86: remove shadow_memtype_mask (jsc#PED-348).
  - commit be496d7
  - KVM: x86: Introduce Intel specific quirk
    KVM_X86_QUIRK_IGNORE_GUEST_PAT (jsc#PED-348).
  - commit a4399ff
  - KVM: x86: Introduce supported_quirks to block disabling quirks
    (jsc#PED-348).
  - commit b2c7cdd
  - KVM: x86: Allow vendor code to disable quirks (jsc#PED-348).
  - commit e2dd0d6
  - KVM: x86: do not allow re-enabling quirks (jsc#PED-348).
  - commit e772bf3
  - KVM: TDX: Enable guest access to MTRR MSRs (jsc#PED-348).
  - commit b2b6235
  - KVM: TDX: Add a method to ignore hypercall patching
    (jsc#PED-348).
  - commit d85513a
  - KVM: TDX: Ignore setting up mce (jsc#PED-348).
  - commit 94cc52d
  - KVM: TDX: Add methods to ignore accesses to TSC (jsc#PED-348).
  - commit f3fab48
  - KVM: TDX: Add methods to ignore VMX preemption timer
    (jsc#PED-348).
  - commit 9856061
  - KVM: TDX: Add method to ignore guest instruction emulation
    (jsc#PED-348).
  - commit 1b78596
  - KVM: TDX: Add methods to ignore accesses to CPU state
    (jsc#PED-348).
  - commit 6a204e7
  - KVM: TDX: Handle TDG.VP.VMCALL<GetTdVmCallInfo> hypercall
    (jsc#PED-348).
  - commit c70683b
  - KVM: TDX: Enable guest access to LMCE related MSRs
    (jsc#PED-348).
  - commit 38a0d91
  - KVM: TDX: Handle TDX PV rdmsr/wrmsr hypercall (jsc#PED-348).
  - commit 4e4c4ee
  - KVM: TDX: Implement callbacks for MSR operations (jsc#PED-348).
  - commit c357360
  - KVM: x86: Move KVM_MAX_MCE_BANKS to header file (jsc#PED-348).
  - commit 4352152
  - KVM: TDX: Handle TDX PV HLT hypercall (jsc#PED-348).
  - commit 5047fe8
  - KVM: TDX: Handle TDX PV CPUID hypercall (jsc#PED-348).
  - commit d83ca6d
  - KVM: TDX: Kick off vCPUs when SEAMCALL is busy during TD page
    removal (jsc#PED-348).
  - commit 723b654
  - KVM: TDX: Handle EXIT_REASON_OTHER_SMI (jsc#PED-348).
  - Refresh
    patches.suse/KVM-TDX-Handle-EPT-violation-misconfig-exit.patch.
  - commit ea445d7

++++ kernel-rt:

  - Delete
    patches.suse/scsi-target-iscsi-don-t-warn-of-R-W-when-no-data.patch.
    This patch was never accepted upstream, and it has a simple
    workaround.
  - commit f19bccd
  - Delete
    patches.suse/scsi-target-iscsi-handle-SCSI-immediate-commands.patch.
    This patch was never accepted upstream, and it has a simple
    workaround.
  - commit b76df52
  - iommu: Protect against overflow in iommu_pgsize() (git-fixes).
  - commit 447faef
  - Drop unneeded guarded patches
  - Delete
    patches.suse/0001-regulator-mt6360-Add-OF-match-table.patch.
  - Delete
    patches.suse/0002-regulator-mt6358-Add-OF-match-table.patch.
  - Delete
    patches.suse/0003-regulator-mt6323-Add-OF-match-table.patch.
  - commit 109a1a7
  - ext4: ignore xattrs past end (bsc#1242846 CVE-2025-37738).
  - commit 4250787
  - KVM: VMX: use __always_inline for is_td_vcpu and is_td
    (git-fixes).
  - commit b92c31e
  - KVM: x86: Revert kvm_x86_ops.mem_enc_ioctl() back to an OPTIONAL
    hook (git-fixes).
  - commit 60d9b39
  - KVM: x86: Do not use kvm_rip_read() unconditionally for
    KVM_PROFILING (git-fixes).
  - commit 6275fc3
  - KVM: x86: Do not use kvm_rip_read() unconditionally in KVM
    tracepoints (git-fixes).
  - commit 4df0c10
  - usb: xhci: Don't change the status of stalled TDs on failed
    Stop EP (git-fixes).
  - commit c602063
  - net: usb: aqc111: fix error handling of usbnet read calls
    (git-fixes).
  - commit 161e4aa
  - r8152: add vendor/device ID pair for Dell Alienware AW1022z
    (git-fixes).
  - commit 0be40bd
  - mm/execmem: Unify early execmem_cache behaviour (git-fixes).
  - commit 2b988fd
  - iio: light: opt3001: fix deadlock due to concurrent flag access (CVE-2025-37968 bsc#1243571)
  - commit 38c1f6f
  - tc: Ensure we have enough buffer space when sending filter
    netlink notifications (git-fixes).
  - commit e91ebf9
  - net: pktgen: fix mpls maximum labels list parsing (git-fixes).
  - commit 23ee838
  - perf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value (CVE-2025-37936 bsc#1243537)
  - commit 595605e
  - net: pktgen: fix access outside of user given buffer in
    pktgen_thread_write() (git-fixes).
  - commit dc28109
  - netdev: fix repeated netlink messages in queue stats
    (git-fixes).
  - commit 35d6fa6
  - net: sched: fix erspan_opt settings in cls_flower (git-fixes).
  - commit 3501db1
  - net/sched: tbf: correct backlog statistic for GSO packets
    (git-fixes).
  - commit dec223e
  - pds_core: Prevent possible adminq overflow/stuck condition (CVE-2025-37987 bsc#1243542)
  - commit 1019426
  - netfilter: fib: avoid lookup if socket is available (git-fixes).
  - commit 2ec4377
  - tcp: reorganize tcp_in_ack_event() and tcp_count_delivered()
    (git-fixes).
  - commit bb6f90b
  - net: ipv6: Init tunnel link-netns before registering dev
    (git-fixes).
  - commit 7594ce3
  - net: ipv6: fix missing dst ref drop in ila lwtunnel (git-fixes).
  - commit c1b70b1
  - net: ipv6: fix dst ref loop in ila lwtunnel (git-fixes).
  - commit 86493f5
  - net: ipv6: fix dst ref loop on input in rpl lwt (git-fixes).
  - commit 4009ad2
  - net: ipv6: fix dst ref loop on input in seg6 lwt (git-fixes).
  - commit 6e27dbd
  - powerpc/kvm-hv-pmu: Add perf-events for Hostwide counters
    (jsc#PED-11017).
  - powerpc/kvm-hv-pmu: Implement GSB message-ops for hostwide
    counters (jsc#PED-11017).
  - kvm powerpc/book3s-apiv2: Introduce kvm-hv specific PMU
    (jsc#PED-11017).
    Update config files.
  - kvm powerpc/book3s-apiv2: Add kunit tests for Hostwide GSB
    elements (jsc#PED-11017).
  - kvm powerpc/book3s-apiv2: Add support for Hostwide GSB elements
    (jsc#PED-11017).
  - powerpc: Document APIv2 KVM hcall spec for Hostwide counters
    (jsc#PED-11017).
  - commit 5094316
  - SUNRPC: Prevent hang on NFS mount with xprtsec=[m]tls
    (git-fixes).
  - commit fd7832d
  - nfs: ignore SB_RDONLY when remounting nfs (git-fixes).
  - commit da5b33e
  - nfs: clear SB_RDONLY before getting superblock (git-fixes).
  - commit 35b5d18
  - NFSv4: Don't check for OPEN feature support in v4.1 (git-fixes).
  - commit cb622d7
  - fs/nfs/read: fix double-unlock bug in nfs_return_empty_folio()
    (git-fixes).
  - commit d3f8f13
  - arm64: sysreg: Drag linux/kconfig.h to work around vdso build issue (git-fixes)
  - commit 1cc351d
  - i2c: tegra: check msg length in SMBUS block read (bsc#1242086)
  - commit d765f59
  - soc: qcom: ice: introduce devm_of_qcom_ice_get (git-fixes).
  - commit 6cb417e
  - powerpc/pseries/msi: Avoid reading PCI device registers in
    reduced power states (bsc#1215199).
  - KVM: powerpc: Enable commented out BUILD_BUG_ON() assertion
    (bsc#1215199).
  - commit 679f2a3
  - RDMA/uverbs: Propagate errors from rdma_lookup_get_uobject() (git-fixes)
  - commit cad8ec2
  - RDMA/core: Fix best page size finding when it can cross SG entries (git-fixes)
  - commit 3f842a4
  - Documentation/virt/kvm: Document on Trust Domain Extensions
    (TDX) (jsc#PED-348).
  - commit 8414857
  - KVM: TDX: Make TDX VM type supported (jsc#PED-348).
  - commit 707d68f
  - KVM: TDX: KVM: TDX: Always honor guest PAT on TDX enabled guests
    (jsc#PED-348).
  - commit 1989f3c
  - KVM: x86: remove shadow_memtype_mask (jsc#PED-348).
  - commit be496d7
  - KVM: x86: Introduce Intel specific quirk
    KVM_X86_QUIRK_IGNORE_GUEST_PAT (jsc#PED-348).
  - commit a4399ff
  - KVM: x86: Introduce supported_quirks to block disabling quirks
    (jsc#PED-348).
  - commit b2c7cdd
  - KVM: x86: Allow vendor code to disable quirks (jsc#PED-348).
  - commit e2dd0d6
  - KVM: x86: do not allow re-enabling quirks (jsc#PED-348).
  - commit e772bf3
  - KVM: TDX: Enable guest access to MTRR MSRs (jsc#PED-348).
  - commit b2b6235
  - KVM: TDX: Add a method to ignore hypercall patching
    (jsc#PED-348).
  - commit d85513a
  - KVM: TDX: Ignore setting up mce (jsc#PED-348).
  - commit 94cc52d
  - KVM: TDX: Add methods to ignore accesses to TSC (jsc#PED-348).
  - commit f3fab48
  - KVM: TDX: Add methods to ignore VMX preemption timer
    (jsc#PED-348).
  - commit 9856061
  - KVM: TDX: Add method to ignore guest instruction emulation
    (jsc#PED-348).
  - commit 1b78596
  - KVM: TDX: Add methods to ignore accesses to CPU state
    (jsc#PED-348).
  - commit 6a204e7
  - KVM: TDX: Handle TDG.VP.VMCALL<GetTdVmCallInfo> hypercall
    (jsc#PED-348).
  - commit c70683b
  - KVM: TDX: Enable guest access to LMCE related MSRs
    (jsc#PED-348).
  - commit 38a0d91
  - KVM: TDX: Handle TDX PV rdmsr/wrmsr hypercall (jsc#PED-348).
  - commit 4e4c4ee
  - KVM: TDX: Implement callbacks for MSR operations (jsc#PED-348).
  - commit c357360
  - KVM: x86: Move KVM_MAX_MCE_BANKS to header file (jsc#PED-348).
  - commit 4352152
  - KVM: TDX: Handle TDX PV HLT hypercall (jsc#PED-348).
  - commit 5047fe8
  - KVM: TDX: Handle TDX PV CPUID hypercall (jsc#PED-348).
  - commit d83ca6d
  - KVM: TDX: Kick off vCPUs when SEAMCALL is busy during TD page
    removal (jsc#PED-348).
  - commit 723b654
  - KVM: TDX: Handle EXIT_REASON_OTHER_SMI (jsc#PED-348).
  - Refresh
    patches.suse/KVM-TDX-Handle-EPT-violation-misconfig-exit.patch.
  - commit ea445d7

++++ gcc15:

  - Exclude shared objects present for link editing in the GCC specific
    subdirectory from provides processing via __provides_exclude_from.
    [bsc#1244050][bsc#1243991]

++++ libzypp:

  - RepoInfo: use pathNameSetTrailingSlash (fixes #643)
  - Fix wrong userdata parameter type when running zypp with debug
    verbosity (bsc#1239012)
  - version 17.37.4 (35)

++++ netcat-openbsd:

  - Update netcat to upstream version 1.229.
    * Fix build failure with GCC-15.
    * In UDP mode, do not test the connection (by writing "XXX" junk)
    when ‘-z’ is unset and the standard input is not a TTY.
    * rsync: Replace ‘-v’ flag with ‘-P’.
    * udp-scan-timeout.patch: Call connection_info() and udptest()
    call when ‘-z’ flag is set. This is the upstream behavior.
    * Add support for abstract namespace sockets in the AF_UNIX family.
    * Make getnameinfo(3) errors non-fatal in report_sock():
    report_sock() is used to show the peer's address/name and port
    when the '-v' flag is set. Reverse resolution errors need not
    be fatal.
    * Fix TCP MD5 signature support. The feature now requires the
    TCP_MD5SIG_EXT socket option, available since Linux 4.13.
    * Make -q0 quit immediately also with UDP sockets.
    * Re-enable specifying client socket for UNIX-domain datagram
    sockets. Regression introduced in version 1.187.
  - Added "abstract-unix-domain-socket.patch": when using '-U' to
    connect() or bind() to a UNIX domain socket, if the address
    (path) starts with "@", it is read as an abstract namespace
    socket.
  - Added "make-getnameinfo-errors-nonfatal-in-report_sock.patch":
    report_sock() is used to show the peer's address/name and port
    when the ‘-v’ flag is set. Reverse resolution errors need not be
    fatal.
  - Renamed the misspelled "port-to-linux-with-libsd.patch" to
    "port-to-linux-with-libbsd.patch".
  - Refreshed patches:
    * broadcast-support.patch
    * build-without-TLS-support.patch
    * connect-timeout.patch
    * dccp-support.patch
    * destination-port-list.patch
    * enable-udp-ip_recverr.patch
    * get-sev-by-name.patch
    * misc-failures-and-features.patch
    * port-select-on-connect.patch
    * port-to-linux-with-libbsd.patch
    * quit-timer.patch
    * send-crlf.patch
    * serialized-handling-multiple-clients.patch
    * set-TCP-MD5SIG-correctly-for-client-connections.patch
    * udp-scan-timeout.patch
    * use-flags-to-specify-listen-address.patch

++++ qemu:

  - Continue trying to fix building with GCC15:
    * roms/edk2: continue to try fixing building with GCC15 (bsc#1241473)
    * roms/ipxe: fix building with GCC15 (bsc#1241473)

------------------------------------------------------------------
------------------  2025-6-3  -  Jun 3 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Allow /boot to be a btrfs subvolume
    In a btrfs based design, allow to put /boot as subvolume.
    This required a small fix in the mount order in a way that
    boot/efi gets mounted after the subvolume mounts are done.
    The respective integration test has been updated to test
    this functionality. This Fixes #2824

++++ kernel-default:

  - kABI workaround for adding an header (CVE-2025-21868
    bsc#1240180).
  - commit 072dad0
  - iommu/tegra241-cmdqv: Fix warnings due to  dmam_free_coherent()
    (CVE-2025-37837 bsc#1242952).
  - commit 94c2388
  - KVM: TDX: Retry locally in TDX EPT violation handler on
    RET_PF_RETRY (jsc#PED-348).
  - commit 372dc9e
  - KVM: TDX: Handle EXCEPTION_NMI and EXTERNAL_INTERRUPT
    (jsc#PED-348).
  - commit 9331c7d
  - KVM: TDX: Detect unexpected SEPT violations due to pending SPTEs
    (jsc#PED-348).
  - commit 2a1fde3
  - KVM: VMX: Add a helper for NMI handling (jsc#PED-348).
  - commit 24f802e
  - KVM: TDX: Handle EPT violation/misconfig exit (jsc#PED-348).
  - commit a0ec838
  - net: ngbe: fix memory leak in ngbe_probe() error path (CVE-2025-37874 bsc#1242940)
  - commit bafeaea
  - net: txgbe: fix memory leak in txgbe_probe() error path (CVE-2025-37872 bsc#1242950)
  - commit 185c018
  - KVM: VMX: Move emulation_required to struct vcpu_vt
    (jsc#PED-348).
  - commit 9434e32
  - net: dsa: mv88e6xxx: fix -ENOENT when deleting VLANs and MST is unsupported (CVE-2025-37865 bsc#1242954)
  - commit ee6b079
  - KVM: TDX: Add methods to ignore virtual apic related operation
    (jsc#PED-348).
  - commit bf9bca9
  - KVM: TDX: Force APICv active for TDX guest (jsc#PED-348).
  - commit d79a636
  - KVM: TDX: Enforce KVM_IRQCHIP_SPLIT for TDX guests
    (jsc#PED-348).
  - commit 9e38109
  - KVM: TDX: Always block INIT/SIPI (jsc#PED-348).
  - commit 622c0b5
  - KVM: TDX: Handle SMI request as !CONFIG_KVM_SMM (jsc#PED-348).
  - commit 1d4c6d0
  - KVM: TDX: Implement methods to inject NMI (jsc#PED-348).
  - commit 27010d8
  - KVM: TDX: Handle TDX PV MMIO hypercall (jsc#PED-348).
  - commit d3a7554
  - KVM: TDX: Wait lapic expire when timer IRQ was injected
    (jsc#PED-348).
  - commit df10413
  - generic_pm_domain_data: hide new member in hole (git-fixes).
  - commit 2492c7a
  - KVM: TDX: Handle TDX PV port I/O hypercall (jsc#PED-348).
  - commit a4d0ab3
  - KVM: x86: Assume timer IRQ was injected if APIC state is
    protected (jsc#PED-348).
  - commit d27ed33
  - KVM: TDX: Handle TDG.VP.VMCALL<ReportFatalError> (jsc#PED-348).
  - commit f0081ab
  - KVM: TDX: Implement non-NMI interrupt injection (jsc#PED-348).
  - commit 6430243
  - KVM: TDX: Handle TDG.VP.VMCALL<MapGPA> (jsc#PED-348).
  - commit 06d28ef
  - KVM: VMX: Move posted interrupt delivery code to common header
    (jsc#PED-348).
  - commit 4cdd8be
  - KVM: TDX: Handle KVM hypercall with TDG.VP.VMCALL (jsc#PED-348).
  - commit b711514
  - KVM: TDX: Disable PI wakeup for IPIv (jsc#PED-348).
  - commit 0083672
  - KVM: TDX: Add a place holder for handler of TDX hypercalls
    (TDG.VP.VMCALL) (jsc#PED-348).
  - commit bbfe1d3
  - KVM: TDX: Add support for find pending IRQ in a protected
    local APIC (jsc#PED-348).
  - commit 0ac86e2
  - KVM: x86: Add a switch_db_regs flag to handle TDX's
    auto-switched behavior (jsc#PED-348).
  - commit e59aad1
  - KVM: TDX: Add a place holder to handle TDX VM exit
    (jsc#PED-348).
  - commit f6d9d03
  - KVM: TDX: Save and restore IA32_DEBUGCTL (jsc#PED-348).
  - commit 16db600
  - KVM: x86: Move pv_unhalted check out of kvm_vcpu_has_events()
    (jsc#PED-348).
  - commit 43d4480
  - pmdomain: core: Introduce dev_pm_genpd_rpm_always_on()
    (git-fixes).
  - commit 0ef07f9
  - net: switchdev: Convert blocking notification chain to a raw
    one (CVE-2025-21986 bsc#1240810).
  - commit 85f36f1
  - KVM: TDX: Disable support for TSX and WAITPKG (jsc#PED-348).
  - commit bc35c5e
  - KVM: x86: Have ____kvm_emulate_hypercall() read the GPRs
    (jsc#PED-348).
  - commit 850ed89
  - KVM: TDX: restore user ret MSRs (jsc#PED-348).
  - commit cfdcb3d
  - KVM: x86: Allow to update cached values in kvm_user_return_msrs
    w/o wrmsr (jsc#PED-348).
  - commit 8a2fb55
  - KVM: TDX: restore host xsave state when exit from the guest TD
    (jsc#PED-348).
  - commit 611c719
  - KVM: TDX: vcpu_run: save/restore host state(host kernel gs)
    (jsc#PED-348).
  - commit 06d5ada
  - KVM: TDX: Implement TDX vcpu enter/exit path (jsc#PED-348).
  - commit 38e314c
  - KVM: VMX: Move common fields of struct vcpu_{vmx,tdx} to a
    struct (jsc#PED-348).
  - commit dd35aa6
  - KVM: TDX: Handle SEPT zap error due to page add error in premap
    (jsc#PED-348).
  - commit 046d39c
  - x86/virt/tdx: Add SEAMCALL wrapper to enter/exit TDX guest
    (jsc#PED-348).
  - commit 12e92a7
  - KVM: TDX: Skip updating CPU dirty logging request for TDs
    (jsc#PED-348).
  - commit 95e549f
  - KVM: x86: Make cpu_dirty_log_size a per-VM value (jsc#PED-348).
  - commit 94f097d
  - KVM: x86/mmu: Add parameter "kvm" to
    kvm_mmu_page_ad_need_write_protect() (jsc#PED-348).
  - commit 1e27dc3
  - KVM: Add parameter "kvm" to kvm_cpu_dirty_log_size() and its
    callers (jsc#PED-348).
  - commit 74de069
  - KVM: TDX: Handle vCPU dissociation (jsc#PED-348).
  - commit 9718bb2
  - KVM: TDX: Finalize VM initialization (jsc#PED-348).
  - commit f6520b5
  - KVM: TDX: Add an ioctl to create initial guest memory
    (jsc#PED-348).
  - commit ff60511
  - KVM: x86/mmu: Export kvm_tdp_map_page() (jsc#PED-348).
  - commit 3465834
  - KVM: x86/mmu: Bail out kvm_tdp_map_page() when VM dead
    (jsc#PED-348).
  - commit 144e592
  - KVM: TDX: Implement hook to get max mapping level of private
    pages (jsc#PED-348).
  - commit 554515d
  - KVM: TDX: Implement hooks to propagate changes of TDP MMU
    mirror page table (jsc#PED-348).
  - commit f1d4b55
  - KVM: TDX: Handle TLB tracking for TDX (jsc#PED-348).
  - commit f0faa8e
  - KVM: TDX: Set per-VM shadow_mmio_value to 0 (jsc#PED-348).
  - commit 49dae5c
  - KVM: x86/mmu: Add setter for shadow_mmio_value (jsc#PED-348).
  - commit b058430
  - KVM: TDX: Require TDP MMU, mmio caching and EPT A/D bits for
    TDX (jsc#PED-348).
  - commit 7d874e9
  - KVM: TDX: Set gfn_direct_bits to shared bit (jsc#PED-348).
  - commit ef0e482
  - KVM: TDX: Add load_mmu_pgd method for TDX (jsc#PED-348).
  - commit d5b9d6f
  - KVM: TDX: Add accessors VMX VMCS helpers (jsc#PED-348).
  - commit 1f2f6c1
  - KVM: VMX: Teach EPT violation helper about private mem
    (jsc#PED-348).
  - commit 7088974
  - KVM: VMX: Split out guts of EPT violation to common/exposed
    function (jsc#PED-348).
  - commit 72c8f3e
  - KVM: x86/mmu: Do not enable page track for TD guest
    (jsc#PED-348).
  - commit de6c038
  - KVM: x86/tdp_mmu: Add a helper function to walk down the TDP
    MMU (jsc#PED-348).
  - commit 44a0f73
  - KVM: x86/mmu: Implement memslot deletion for TDX (jsc#PED-348).
  - commit 3d2ab8b
  - x86/virt/tdx: Add SEAMCALL wrappers for TD measurement of
    initial contents (jsc#PED-348).
  - commit abf2eb5
  - net: allow small head cache usage with large MAX_SKB_FRAGS
    values (CVE-2025-21868 bsc#1240180).
  - commit 289f29e
  - KVM: TDX: Register TDX host key IDs to cgroup misc controller
    (jsc#PED-348).
  - commit b50c816
  - x86/virt/tdx: Add SEAMCALL wrappers to remove a TD private page
    (jsc#PED-348).
  - commit 466591d
  - KVM: x86/mmu: Taking guest pa into consideration when calculate
    tdp level (jsc#PED-348).
  - commit 3904d80
  - x86/virt/tdx: Add SEAMCALL wrappers to manage TDX TLB tracking
    (jsc#PED-348).
  - commit a485453
  - KVM: x86: Introduce KVM_TDX_GET_CPUID (jsc#PED-348).
  - commit fe28688
  - x86/virt/tdx: Add SEAMCALL wrappers to add TD private pages
    (jsc#PED-348).
  - commit 2498b76
  - KVM: TDX: Do TDX specific vcpu initialization (jsc#PED-348).
  - commit 165bc3a
  - x86/virt/tdx: Add SEAMCALL wrapper tdh_mem_sept_add() to add
    SEPT pages (jsc#PED-348).
  - commit 7395169
  - KVM: TDX: create/free TDX vcpu structure (jsc#PED-348).
  - commit 98bd9d9
  - KVM: TDX: Don't offline the last cpu of one package when
    there's TDX guest (jsc#PED-348).
  - commit e74a04c
  - powerpc/pseries/dlpar: Search DRC index from ibm,drc-indexes
    for IO add (bsc#1243042 ltc#212167).
  - commit 87e2def
  - KVM: TDX: Make pmu_intel.c ignore guest TD case (jsc#PED-348).
  - commit 7db5893
  - KVM: TDX: add ioctl to initialize VM with TDX specific
    parameters (jsc#PED-348).
  - commit 9a8f7c4
  - KVM: x86: expose cpuid_entry2_find for TDX (jsc#PED-348).
  - commit d6d74c0
  - KVM: TDX: Support per-VM KVM_CAP_MAX_VCPUS extension check
    (jsc#PED-348).
  - commit 99f1ef2
  - KVM: TDX: create/destroy VM structure (jsc#PED-348).
  - commit ff395b9
  - KVM: TDX: Get system-wide info about TDX module on
    initialization (jsc#PED-348).
  - commit f966b83
  - cifs: avoid NULL pointer dereference in dbg call (CVE-2025-37844 bsc#1242946)
  - commit 13ce184
  - KVM: TDX: Add place holder for TDX VM specific mem_enc_op ioctl
    (jsc#PED-348).
  - commit fb81451
  - KVM: TDX: Add helper functions to print TDX SEAMCALL error
    (jsc#PED-348).
  - commit c7850a7
  - KVM: TDX: Add TDX "architectural" error codes (jsc#PED-348).
  - commit ae6dde8
  - KVM: TDX: Define TDX architectural definitions (jsc#PED-348).
  - commit 0b39ad1
  - KVM: TDX: Add placeholders for TDX VM/vCPU structures
    (jsc#PED-348).
  - commit 4331504
  - KVM: TDX: Get TDX global information (jsc#PED-348).
  - commit 2639f49
  - KVM: VMX: Initialize TDX during KVM module load (jsc#PED-348).
  - commit e605aaf
  - KVM: VMX: Refactor VMX module init/exit functions (jsc#PED-348).
  - commit 3880b0c
  - scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer() (CVE-2025-37826 bsc#1242862)
  - commit d04f316
  - KVM: Export hardware virtualization enabling/disabling functions
    (jsc#PED-348).
  - commit dbb21b7
  - x86/virt/tdx: Add tdx_guest_keyid_alloc/free() to alloc and
    free TDX guest KeyID (jsc#PED-348).
  - commit 4dc8a98
  - x86/virt/tdx: Read essential global metadata for KVM
    (jsc#PED-348).
  - commit 8ddca0b
  - x86/virt/tdx: allocate tdx_sys_info in static memory
    (jsc#PED-348).
  - commit 6a14d13
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX flush operations
    (jsc#PED-348).
  - commit c2d6ae0
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX VM/vCPU field access
    (jsc#PED-348).
  - commit a4a8ea9
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX page cache
    management (jsc#PED-348).
  - commit f562ade
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX vCPU creation
    (jsc#PED-348).
  - commit 4596a12
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX TD creation
    (jsc#PED-348).
  - commit 67ea0be
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX KeyID management
    (jsc#PED-348).
  - commit 4535d8f
  - Update
    patches.suse/9p-net-fix-improper-handling-of-bogus-negative-read-.patch
    (git-fixes CVE-2025-37879 bsc#1243077).
  - Update
    patches.suse/ALSA-ump-Fix-buffer-overflow-at-UMP-SysEx-message-co.patch
    (bsc#1242044 CVE-2025-37891 bsc#1243589).
  - Update
    patches.suse/ASoC-Intel-avs-Fix-null-ptr-deref-in-avs_component_p.patch
    (git-fixes CVE-2025-37793 bsc#1242584).
  - Update
    patches.suse/ASoC-amd-acp-Fix-NULL-pointer-deref-in-acp_i2s_set_t.patch
    (git-fixes CVE-2025-37919 bsc#1243478).
  - Update
    patches.suse/ASoC-codecs-wcd937x-fix-a-potential-memory-leak-in-w.patch
    (git-fixes CVE-2025-37941 bsc#1243525).
  - Update
    patches.suse/ASoC-imx-card-Add-NULL-check-in-imx_card_probe.patch
    (git-fixes CVE-2025-22066 bsc#1241340).
  - Update
    patches.suse/ASoC-ops-Consistently-treat-platform_max-as-control-.patch
    (git-fixes CVE-2025-37889 bsc#1242945).
  - Update
    patches.suse/ASoC-qcom-Fix-sc7280-lpass-potential-buffer-overflow.patch
    (git-fixes CVE-2025-37979 bsc#1243545).
  - Update
    patches.suse/ASoC-simple-card-utils-Fix-pointer-check-in-graph_ut.patch
    (git-fixes CVE-2025-37934 bsc#1243548).
  - Update
    patches.suse/Bluetooth-btrtl-Prevent-potential-NULL-dereference.patch
    (git-fixes CVE-2025-37792 bsc#1242591).
  - Update
    patches.suse/Bluetooth-btusb-avoid-NULL-pointer-dereference-in-sk.patch
    (git-fixes CVE-2025-37918 bsc#1243476).
  - Update
    patches.suse/HID-pidff-Fix-null-pointer-dereference-in-pidff_find.patch
    (stable-fixes CVE-2025-37862 bsc#1242982).
  - Update
    patches.suse/HID-pidff-Make-sure-to-fetch-pool-before-checking-SI.patch
    (stable-fixes CVE-2025-37942 bsc#1243576).
  - Update
    patches.suse/HSI-ssi_protocol-Fix-use-after-free-vulnerability-in.patch
    (stable-fixes CVE-2025-37838 bsc#1241641).
  - Update
    patches.suse/Input-mtk-pmic-keys-fix-possible-null-pointer-derefe.patch
    (git-fixes CVE-2025-37972 bsc#1243573).
  - Update
    patches.suse/KVM-SVM-Forcibly-leave-SMM-mode-on-SHUTDOWN-intercep.patch
    (git-fixes CVE-2025-37957 bsc#1243513).
  - Update
    patches.suse/KVM-x86-Reset-IRTE-to-host-control-if-new-route-isn-.patch
    (git-fixes CVE-2025-37885 bsc#1242960).
  - Update
    patches.suse/PCI-Fix-reference-leak-in-pci_register_host_bridge.patch
    (git-fixes CVE-2025-37836 bsc#1242957).
  - Update
    patches.suse/PCI-brcmstb-Fix-error-path-after-a-call-to-regulator.patch
    (git-fixes CVE-2025-22095 bsc#1241519).
  - Update
    patches.suse/PCI-pciehp-Avoid-unnecessary-device-replacement-chec.patch
    (git-fixes CVE-2025-37843 bsc#1242956).
  - Update
    patches.suse/PCI-vmd-Make-vmd_dev-cfg_lock-a-raw_spinlock_t-type.patch
    (stable-fixes CVE-2025-23161 bsc#1242792).
  - Update
    patches.suse/PM-hibernate-Avoid-deadlock-in-hibernate_compressor_.patch
    (stable-fixes CVE-2025-37745 bsc#1242853).
  - Update
    patches.suse/RDMA-cma-Fix-workqueue-crash-in-cma_netevent_work_ha.patch
    (git-fixes CVE-2025-37772 bsc#1242563).
  - Update
    patches.suse/RDMA-core-Don-t-expose-hw_counters-outside-of-init-n.patch
    (git-fixes CVE-2025-22089 bsc#1241538).
  - Update
    patches.suse/RDMA-core-Silence-oversized-kvmalloc-warning.patch
    (git-fixes CVE-2025-37867 bsc#1242948).
  - Update
    patches.suse/USB-wdm-close-race-between-wdm_open-and-wdm_wwan_por.patch
    (git-fixes CVE-2025-37985 bsc#1243529).
  - Update
    patches.suse/accel-ivpu-Fix-PM-related-deadlocks-in-MS-IOCTLs.patch
    (git-fixes CVE-2025-37848 bsc#1242943).
  - Update
    patches.suse/accel-ivpu-Fix-deadlock-in-ivpu_ms_cleanup.patch
    (git-fixes CVE-2025-37847 bsc#1242947).
  - Update
    patches.suse/arm64-errata-Add-missing-sentinels-to-Spectre-BHB-MIDR-arr.patch
    (git-fixes CVE-2025-37929 bsc#1243624).
  - Update
    patches.suse/arm64-mops-Do-not-dereference-src-reg-for-a-set-operation.patch
    (git-fixes CVE-2025-37846 bsc#1242963).
  - Update
    patches.suse/ata-pata_pxa-Fix-potential-NULL-pointer-dereference-.patch
    (git-fixes CVE-2025-37758 bsc#1242514).
  - Update
    patches.suse/backlight-led_bl-Hold-led_access-lock-when-calling-l.patch
    (git-fixes CVE-2025-23144 bsc#1242568).
  - Update
    patches.suse/block-fix-resource-leak-in-blk_register_queue-error-path.patch
    (git-fixes CVE-2025-37980 bsc#1243522).
  - Update
    patches.suse/block-integrity-Do-not-call-set_page_dirty_lock.patch
    (git-fixes CVE-2025-37978 bsc#1243516).
  - Update patches.suse/block-mark-GFP_NOIO-around-sysfs-store.patch
    (jsc#PED-9651 CVE-2025-21817 bsc#1239106).
  - Update
    patches.suse/bnxt_en-Fix-error-handling-path-in-bnxt_init_chip.patch
    (git-fixes CVE-2025-37895 bsc#1243532).
  - Update
    patches.suse/bnxt_en-Fix-out-of-bound-memcpy-during-ethtool-w.patch
    (git-fixes CVE-2025-37911 bsc#1243469).
  - Update
    patches.suse/book3s64-radix-Align-section-vmemmap-start-address-t.patch
    (bsc#1238318 bsc#1243298 ltc#212689 CVE-2025-37922 bsc#1243481).
  - Update patches.suse/bpf-Scrub-packet-on-bpf_redirect_peer.patch
    (git-fixes CVE-2025-37959 bsc#1243517).
  - Update
    patches.suse/bpf-check-changes_pkt_data-property-for-extension-pr.patch
    (bsc#1241590 CVE-2024-58100 bsc#1242564).
  - Update
    patches.suse/bpf-consider-that-tail-calls-invalidate-packet-point.patch
    (git-fixes CVE-2024-58237 bsc#1242574).
  - Update
    patches.suse/bpf-track-changes_pkt_data-property-for-global-funct.patch
    (bsc#1241590 CVE-2024-58098 bsc#1242565).
  - Update
    patches.suse/btrfs-adjust-subpage-bit-start-based-on-sectorsize.patch
    (bsc#1241492 CVE-2025-37931 bsc#1243626).
  - Update
    patches.suse/bus-mhi-host-Fix-race-between-unprepare-and-queue_bu.patch
    (git-fixes CVE-2025-23151 bsc#1242512).
  - Update
    patches.suse/crypto-null-Use-spin-lock-instead-of-mutex.patch
    (stable-fixes CVE-2025-37808 bsc#1242923).
  - Update
    patches.suse/cxgb4-fix-memory-leak-in-cxgb4_init_ethtool_filters-.patch
    (git-fixes CVE-2025-37788 bsc#1242766).
  - Update
    patches.suse/dm-bufio-don-t-schedule-in-atomic-context.patch
    (git-fixes CVE-2025-37928 bsc#1243621).
  - Update
    patches.suse/dmaengine-fsl-edma-free-irq-correctly-in-remove-path.patch
    (git-fixes CVE-2025-38479 bsc#1242036).
  - Update
    patches.suse/driver-core-fix-potential-NULL-pointer-dereference-i.patch
    (stable-fixes CVE-2025-37800 bsc#1242849).
  - Update
    patches.suse/drm-amd-display-Fix-slab-use-after-free-in-hdcp.patch
    (git-fixes CVE-2025-37903 bsc#1243562).
  - Update
    patches.suse/drm-amd-display-prevent-hang-on-link-training-fail.patch
    (stable-fixes CVE-2025-37870 bsc#1243056).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-4b8c3c0.patch
    (git-fixes CVE-2025-37770 bsc#1242764).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-4e3d950.patch
    (git-fixes CVE-2025-37766 bsc#1242785).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-7c246a0.patch
    (git-fixes CVE-2025-37768 bsc#1242567).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-7d641c2.patch
    (git-fixes CVE-2025-37771 bsc#1242781).
  - Update patches.suse/drm-amd-pm-Prevent-division-by-zero.patch
    (git-fixes CVE-2025-37767 bsc#1242501).
  - Update
    patches.suse/drm-amd-pm-smu11-Prevent-division-by-zero.patch
    (git-fixes CVE-2025-37769 bsc#1242587).
  - Update
    patches.suse/drm-amdgpu-handle-amdgpu_cgs_create_device-errors-in.patch
    (stable-fixes CVE-2025-37852 bsc#1243074).
  - Update patches.suse/drm-amdkfd-Fix-mode1-reset-crash-issue.patch
    (stable-fixes CVE-2025-37854 bsc#1243082).
  - Update
    patches.suse/drm-amdkfd-debugfs-hang_hws-skip-GPU-with-MES.patch
    (stable-fixes CVE-2025-37853 bsc#1243076).
  - Update
    patches.suse/drm-i915-huc-Fix-fence-not-released-on-early-probe-e.patch
    (git-fixes CVE-2025-37754 bsc#1242524).
  - Update
    patches.suse/drm-imagination-fix-firmware-memory-leaks.patch
    (git-fixes CVE-2025-37764 bsc#1242577).
  - Update
    patches.suse/drm-imagination-take-paired-job-reference.patch
    (git-fixes CVE-2025-37763 bsc#1242508).
  - Update
    patches.suse/drm-mediatek-dp-drm_err-dev_err-in-HPD-path-to-avoid.patch
    (git-fixes CVE-2025-38240 bsc#1241457).
  - Update
    patches.suse/drm-nouveau-Fix-WARN_ON-in-nouveau_fence_context_kil.patch
    (git-fixes CVE-2025-37930 bsc#1243625).
  - Update
    patches.suse/drm-nouveau-prime-fix-ttm_bo_delayed_delete-oops.patch
    (git-fixes CVE-2025-37765 bsc#1242761).
  - Update
    patches.suse/drm-v3d-Add-job-to-pending-list-if-the-reset-was-ski.patch
    (stable-fixes CVE-2025-37951 bsc#1243659).
  - Update
    patches.suse/drm-xe-Fix-an-out-of-bounds-shift-when-invalidating-.patch
    (git-fixes CVE-2025-37761 bsc#1242724).
  - Update
    patches.suse/drm-xe-Use-local-fence-in-error-path-of-xe_migrate_c.patch
    (git-fixes CVE-2025-37869 bsc#1242967).
  - Update
    patches.suse/drm-xe-userptr-fix-notifier-vs-folio-deadlock.patch
    (git-fixes CVE-2025-37868 bsc#1242966).
  - Update
    patches.suse/drm-xe-vf-Don-t-try-to-trigger-a-full-GT-reset-if-VF.patch
    (stable-fixes CVE-2025-23162 bsc#1242834).
  - Update
    patches.suse/eth-bnxt-fix-missing-ring-index-trim-on-error-path.patch
    (git-fixes CVE-2025-37873 bsc#1242961).
  - Update
    patches.suse/ethtool-cmis_cdb-use-correct-rpl-size-in-ethtool_cmi.patch
    (git-fixes CVE-2025-37791 bsc#1242729).
  - Update patches.suse/fbdev-omapfb-Add-plane-value-check.patch
    (stable-fixes CVE-2025-37851 bsc#1242977).
  - Update
    patches.suse/firmware-arm_scmi-Balance-device-refcount-when-destr.patch
    (git-fixes CVE-2025-37905 bsc#1243456).
  - Update
    patches.suse/i2c-cros-ec-tunnel-defer-probe-if-parent-EC-is-not-p.patch
    (git-fixes CVE-2025-37781 bsc#1242575).
  - Update
    patches.suse/i3c-Add-NULL-pointer-check-in-i3c_master_queue_ibi.patch
    (git-fixes CVE-2025-23147 bsc#1242530).
  - Update
    patches.suse/ice-Check-VF-VSI-Pointer-Value-in-ice_vc_add_fdir_fl.patch
    (git-fixes CVE-2025-37912 bsc#1243470).
  - Update patches.suse/igc-fix-PTM-cycle-trigger-logic.patch
    (git-fixes CVE-2025-37875 bsc#1242959).
  - Update
    patches.suse/iio-backend-make-sure-to-NULL-terminate-stack-buffer.patch
    (git-fixes CVE-2025-22082 bsc#1241336).
  - Update
    patches.suse/iio-imu-st_lsm6dsx-fix-possible-lockup-in-st_lsm6dsx-8114ef8.patch
    (git-fixes CVE-2025-37969 bsc#1243574).
  - Update
    patches.suse/iio-imu-st_lsm6dsx-fix-possible-lockup-in-st_lsm6dsx.patch
    (git-fixes CVE-2025-37970 bsc#1243575).
  - Update
    patches.suse/iio-light-Add-check-for-array-bounds-in-veml6075_rea.patch
    (git-fixes CVE-2025-40114 bsc#1241639).
  - Update
    patches.suse/iommu-Fix-two-issues-in-iommu_copy_struct_from_user.patch
    (git-fixes CVE-2025-37900 bsc#1243560).
  - Update
    patches.suse/irqchip-gic-v2m-Prevent-use-after-free-of-gicv2m_get.patch
    (git-fixes CVE-2025-37819 bsc#1242873).
  - Update
    patches.suse/irqchip-qcom-mpm-Prevent-crash-when-trying-to-handle.patch
    (git-fixes CVE-2025-37901 bsc#1243559).
  - Update patches.suse/jbd2-remove-wrong-sb-s_sequence-check.patch
    (bsc#1242343 CVE-2025-37839 bsc#1242990).
  - Update
    patches.suse/lib-iov_iter-fix-to-increase-non-slab-folio-refcount.patch
    (bsc#1241169 (MM functional and performance backports)
    CVE-2025-37779 bsc#1242525).
  - Update
    patches.suse/md-md-bitmap-fix-wrong-bitmap_limit-for-clustermd-wh.patch
    (bsc#1238212 CVE-2025-22124 bsc#1241595).
  - Update
    patches.suse/media-mediatek-vcodec-Fix-a-resource-leak-related-to.patch
    (git-fixes CVE-2025-23160 bsc#1242507).
  - Update
    patches.suse/media-venus-hfi-add-a-check-to-handle-OOB-in-sfr-reg.patch
    (git-fixes CVE-2025-23159 bsc#1242529).
  - Update
    patches.suse/media-venus-hfi-add-check-to-handle-incorrect-queue-.patch
    (git-fixes CVE-2025-23158 bsc#1242531).
  - Update
    patches.suse/media-venus-hfi_parser-add-check-to-avoid-out-of-bou.patch
    (git-fixes CVE-2025-23157 bsc#1242532).
  - Update
    patches.suse/media-venus-hfi_parser-refactor-hfi-packet-parsing-l.patch
    (git-fixes CVE-2025-23156 bsc#1242569).
  - Update
    patches.suse/mei-vsc-Fix-fortify-panic-caused-by-invalid-counted_.patch
    (git-fixes CVE-2025-37816 bsc#1242863).
  - Update
    patches.suse/mfd-ene-kb3930-Fix-a-potential-NULL-pointer-derefere.patch
    (git-fixes CVE-2025-23146 bsc#1242559).
  - Update
    patches.suse/misc-microchip-pci1xxxx-Fix-Kernel-panic-during-IRQ-.patch
    (git-fixes CVE-2025-37815 bsc#1242871).
  - Update patches.suse/mm-slab-clean-up-slab-obj_exts-always.patch
    (git-fixes CVE-2025-37908 bsc#1243466).
  - Update
    patches.suse/mtd-inftlcore-Add-error-check-for-inftl_read_oob.patch
    (git-fixes CVE-2025-37892 bsc#1243536).
  - Update
    patches.suse/mtd-rawnand-brcmnand-fix-PM-resume-warning.patch
    (git-fixes CVE-2025-37840 bsc#1242953).
  - Update
    patches.suse/net-decrease-cached-dst-counters-in-dst_release.patch
    (git-fixes CVE-2025-22057 bsc#1241533).
  - Update
    patches.suse/net-mlx5-Fix-null-ptr-deref-in-mlx5_create_-inner_-t.patch
    (git-fixes CVE-2025-37888 bsc#1242964).
  - Update
    patches.suse/net-phy-allow-MDIO-bus-PM-ops-to-start-stop-state-ma.patch
    (git-fixes CVE-2025-37945 bsc#1243538).
  - Update patches.suse/net-phy-leds-fix-memory-leak.patch
    (git-fixes CVE-2025-37989 bsc#1243511).
  - Update patches.suse/net-tls-explicitly-disallow-disconnect.patch
    (git-fixes CVE-2025-37756 bsc#1242515).
  - Update
    patches.suse/net-use-sock_gen_put-when-sk_state-is-TCP_TIME_WAIT.patch
    (git-fixes CVE-2025-37894 bsc#1243533).
  - Update
    patches.suse/net_sched-drr-Fix-double-list-add-in-class-with-nete.patch
    (git-fixes CVE-2025-37915 bsc#1243473).
  - Update
    patches.suse/net_sched-ets-Fix-double-list-add-in-class-with-nete.patch
    (git-fixes CVE-2025-37914 bsc#1243472).
  - Update
    patches.suse/net_sched-hfsc-Fix-a-UAF-vulnerability-in-class-with.patch
    (git-fixes CVE-2025-37890 bsc#1243330).
  - Update
    patches.suse/net_sched-qfq-Fix-double-list-add-in-class-with-nete.patch
    (git-fixes CVE-2025-37913 bsc#1243471).
  - Update
    patches.suse/nfsd-allow-SC_STATUS_FREEABLE-when-searching-via-nfs4_lookup_stateid.patch
    (git-fixes CVE-2025-39688 bsc#1241652).
  - Update
    patches.suse/nfsd-decrease-sc_count-directly-if-fail-to-queue-dl_recall.patch
    (git-fixes CVE-2025-37871 bsc#1242949).
  - Update
    patches.suse/nvmet-fix-out-of-bounds-access-in-nvmet_enable_port.patch
    (jsc#PED-9651 CVE-2025-37825 bsc#1242874).
  - Update
    patches.suse/objtool-media-dib8000-Prevent-divide-by-zero-in-dib8.patch
    (git-fixes CVE-2025-37937 bsc#1243540).
  - Update
    patches.suse/objtool-nvmet-Fix-out-of-bounds-stack-access-in-nvme.patch
    (git-fixes CVE-2025-39778 bsc#1241632).
  - Update
    patches.suse/objtool-spi-amd-Fix-out-of-bounds-stack-access-in-am.patch
    (git-fixes CVE-2025-40014 bsc#1241644).
  - Update
    patches.suse/page_pool-avoid-infinite-loop-to-schedule-delayed-wo.patch
    (git-fixes CVE-2025-37859 bsc#1243051).
  - Update
    patches.suse/powerpc64-ftrace-fix-module-loading-without-patchabl.patch
    (jsc#PED-10909 git-fixes bsc#1236402 CVE-2025-37898
    bsc#1243549).
  - Update
    patches.suse/pwm-mediatek-Prevent-divide-by-zero-in-pwm_mediatek_.patch
    (git-fixes CVE-2025-37850 bsc#1242955).
  - Update patches.suse/qibfs-fix-_another_-leak.patch (git-fixes
    CVE-2025-37983 bsc#1243567).
  - Update
    patches.suse/remoteproc-core-Clear-table_sz-when-rproc_shutdown.patch
    (git-fixes CVE-2025-38152 bsc#1241627).
  - Update
    patches.suse/s390-pci-Fix-duplicate-pci_dev_put-in-disable_slot-w.patch
    (git-fixes CVE-2025-37946 bsc#1243506).
  - Update patches.suse/sch_htb-make-htb_deactivate-idempotent.patch
    (CVE-2025-37798 bsc#1242414 CVE-2025-37953 bsc#1243543).
  - Update
    patches.suse/sch_htb-make-htb_qlen_notify-idempotent.patch
    (CVE-2025-37798 bsc#1242414 CVE-2025-37932 bsc#1243627).
  - Update
    patches.suse/scsi-smartpqi-Use-is_kdump_kernel-to-check-for-kdump.patch
    (git-fixes CVE-2025-37981 bsc#1243514).
  - Update
    patches.suse/sfc-fix-NULL-dereferences-in-ef100_process_design_pa.patch
    (git-fixes CVE-2025-37860 bsc#1241452).
  - Update
    patches.suse/soc-samsung-exynos-chipid-Add-NULL-pointer-check-in-.patch
    (git-fixes CVE-2025-23148 bsc#1242578).
  - Update
    patches.suse/sound-virtio-Fix-cancel_sync-warnings-on-uninitializ.patch
    (stable-fixes CVE-2025-37805 bsc#1242930).
  - Update
    patches.suse/staging-vchiq_arm-Fix-possible-NPR-of-keep-alive-thr.patch
    (git-fixes CVE-2025-22078 bsc#1241418).
  - Update
    patches.suse/tipc-fix-NULL-pointer-dereference-in-tipc_mon_reinit.patch
    (git-fixes CVE-2025-37824 bsc#1242867).
  - Update patches.suse/tpm-do-not-start-chip-while-suspended.patch
    (git-fixes CVE-2025-23149 bsc#1242758).
  - Update
    patches.suse/tty-Require-CAP_SYS_ADMIN-for-all-usages-of-TIOCL_SE.patch
    (git-fixes CVE-2025-37814 bsc#1242865).
  - Update
    patches.suse/ublk-fix-handling-recovery-reissue-in-ublk_abort_queue.patch
    (git-fixes CVE-2025-37759 bsc#1242519).
  - Update
    patches.suse/usb-cdns3-Fix-deadlock-when-using-NCM-gadget.patch
    (git-fixes CVE-2025-37812 bsc#1242908).
  - Update
    patches.suse/usb-chipidea-ci_hdrc_imx-fix-usbmisc-handling.patch
    (git-fixes CVE-2025-37811 bsc#1242907).
  - Update
    patches.suse/usb-dwc3-gadget-check-that-event-count-does-not-exce.patch
    (git-fixes CVE-2025-37810 bsc#1242906).
  - Update
    patches.suse/usb-gadget-aspeed-Add-NULL-pointer-check-in-ast_vhub.patch
    (git-fixes CVE-2025-37881 bsc#1242973).
  - Update
    patches.suse/usb-typec-class-Fix-NULL-pointer-access.patch
    (git-fixes CVE-2025-37809 bsc#1242856).
  - Update
    patches.suse/usb-typec-class-Invalidate-USB-device-pointers-on-pa.patch
    (git-fixes CVE-2025-37986 bsc#1243515).
  - Update
    patches.suse/usb-typec-ucsi-displayport-Fix-deadlock.patch
    (git-fixes CVE-2025-37967 bsc#1243572).
  - Update
    patches.suse/usb-xhci-Don-t-skip-on-Stopped-Length-Invalid.patch
    (git-fixes CVE-2025-22023 bsc#1241298).
  - Update
    patches.suse/usb-xhci-Fix-invalid-pointer-dereference-in-Etron-wo.patch
    (git-fixes CVE-2025-37813 bsc#1242909).
  - Update
    patches.suse/usb-xhci-Fix-isochronous-Ring-Underrun-Overrun-event.patch
    (stable-fixes CVE-2025-37882 bsc#1243234).
  - Update
    patches.suse/virtio-net-free-xsk_buffs-on-error-in-virtnet_xsk_po.patch
    (git-fixes CVE-2025-37955 bsc#1243507).
  - Update
    patches.suse/wifi-at76c50x-fix-use-after-free-access-in-at76_disc.patch
    (git-fixes CVE-2025-37796 bsc#1242727).
  - Update
    patches.suse/wifi-ath12k-Fix-invalid-data-access-in-ath12k_dp_rx_.patch
    (stable-fixes CVE-2025-37943 bsc#1243509).
  - Update
    patches.suse/wifi-ath12k-Fix-invalid-entry-fetch-in-ath12k_dp_mon.patch
    (stable-fixes CVE-2025-37944 bsc#1243530).
  - Update
    patches.suse/wifi-brcm80211-fmac-Add-error-handling-for-brcmf_usb.patch
    (git-fixes CVE-2025-37990 bsc#1243528).
  - Update
    patches.suse/wifi-cfg80211-init-wiphy_work-before-allocating-rfki.patch
    (git-fixes CVE-2025-22119 bsc#1241576).
  - Update
    patches.suse/wifi-mac80211-Purge-vif-txq-in-ieee80211_do_stop.patch
    (git-fixes CVE-2025-37794 bsc#1242566).
  - Update
    patches.suse/wifi-plfxlc-Remove-erroneous-assert-in-plfxlc_mac_re.patch
    (git-fixes CVE-2025-37897 bsc#1243534).
  - Update
    patches.suse/wifi-wl1251-fix-memory-leak-in-wl1251_tx_work.patch
    (git-fixes CVE-2025-37982 bsc#1243524).
  - Update
    patches.suse/xen-netfront-handle-NULL-returned-by-xdp_convert_buf.patch
    (git-fixes CVE-2025-37820 bsc#1242866).
  - Update patches.suse/xenbus-Use-kref-to-track-req-lifetime.patch
    (git-fixes CVE-2025-37949 bsc#1243541).
  - Update
    patches.suse/xsk-fix-an-integer-overflow-in-xp_create_and_assign_.patch
    (git-fixes CVE-2025-21997 bsc#1240823).
  - commit bc63f80
  - arm64: Add override for MPAM (bsc#1242843)
  - commit eb086b5
  - printk: Check CON_SUSPEND when unblanking a console
    (bsc#1243998).
  - commit bab4aa6
  - Flush console log from kernel_power_off() (bsc#1243996).
  - commit cd77fb7
  - arm64/mm: Permit lazy_mmu_mode to be nested (git-fixes)
  - commit ed7a958
  - arm64/mm: Disable barrier batching in interrupt contexts (git-fixes)
  - commit dabd452
  - smccc: kvm_guest: Align with DISCOVER_IMPL_CPUS ABI (git-fixes)
  - commit cbe1757

++++ kernel-rt:

  - kABI workaround for adding an header (CVE-2025-21868
    bsc#1240180).
  - commit 072dad0
  - iommu/tegra241-cmdqv: Fix warnings due to  dmam_free_coherent()
    (CVE-2025-37837 bsc#1242952).
  - commit 94c2388
  - KVM: TDX: Retry locally in TDX EPT violation handler on
    RET_PF_RETRY (jsc#PED-348).
  - commit 372dc9e
  - KVM: TDX: Handle EXCEPTION_NMI and EXTERNAL_INTERRUPT
    (jsc#PED-348).
  - commit 9331c7d
  - KVM: TDX: Detect unexpected SEPT violations due to pending SPTEs
    (jsc#PED-348).
  - commit 2a1fde3
  - KVM: VMX: Add a helper for NMI handling (jsc#PED-348).
  - commit 24f802e
  - KVM: TDX: Handle EPT violation/misconfig exit (jsc#PED-348).
  - commit a0ec838
  - net: ngbe: fix memory leak in ngbe_probe() error path (CVE-2025-37874 bsc#1242940)
  - commit bafeaea
  - net: txgbe: fix memory leak in txgbe_probe() error path (CVE-2025-37872 bsc#1242950)
  - commit 185c018
  - KVM: VMX: Move emulation_required to struct vcpu_vt
    (jsc#PED-348).
  - commit 9434e32
  - net: dsa: mv88e6xxx: fix -ENOENT when deleting VLANs and MST is unsupported (CVE-2025-37865 bsc#1242954)
  - commit ee6b079
  - KVM: TDX: Add methods to ignore virtual apic related operation
    (jsc#PED-348).
  - commit bf9bca9
  - KVM: TDX: Force APICv active for TDX guest (jsc#PED-348).
  - commit d79a636
  - KVM: TDX: Enforce KVM_IRQCHIP_SPLIT for TDX guests
    (jsc#PED-348).
  - commit 9e38109
  - KVM: TDX: Always block INIT/SIPI (jsc#PED-348).
  - commit 622c0b5
  - KVM: TDX: Handle SMI request as !CONFIG_KVM_SMM (jsc#PED-348).
  - commit 1d4c6d0
  - KVM: TDX: Implement methods to inject NMI (jsc#PED-348).
  - commit 27010d8
  - KVM: TDX: Handle TDX PV MMIO hypercall (jsc#PED-348).
  - commit d3a7554
  - KVM: TDX: Wait lapic expire when timer IRQ was injected
    (jsc#PED-348).
  - commit df10413
  - generic_pm_domain_data: hide new member in hole (git-fixes).
  - commit 2492c7a
  - KVM: TDX: Handle TDX PV port I/O hypercall (jsc#PED-348).
  - commit a4d0ab3
  - KVM: x86: Assume timer IRQ was injected if APIC state is
    protected (jsc#PED-348).
  - commit d27ed33
  - KVM: TDX: Handle TDG.VP.VMCALL<ReportFatalError> (jsc#PED-348).
  - commit f0081ab
  - KVM: TDX: Implement non-NMI interrupt injection (jsc#PED-348).
  - commit 6430243
  - KVM: TDX: Handle TDG.VP.VMCALL<MapGPA> (jsc#PED-348).
  - commit 06d28ef
  - KVM: VMX: Move posted interrupt delivery code to common header
    (jsc#PED-348).
  - commit 4cdd8be
  - KVM: TDX: Handle KVM hypercall with TDG.VP.VMCALL (jsc#PED-348).
  - commit b711514
  - KVM: TDX: Disable PI wakeup for IPIv (jsc#PED-348).
  - commit 0083672
  - KVM: TDX: Add a place holder for handler of TDX hypercalls
    (TDG.VP.VMCALL) (jsc#PED-348).
  - commit bbfe1d3
  - KVM: TDX: Add support for find pending IRQ in a protected
    local APIC (jsc#PED-348).
  - commit 0ac86e2
  - KVM: x86: Add a switch_db_regs flag to handle TDX's
    auto-switched behavior (jsc#PED-348).
  - commit e59aad1
  - KVM: TDX: Add a place holder to handle TDX VM exit
    (jsc#PED-348).
  - commit f6d9d03
  - KVM: TDX: Save and restore IA32_DEBUGCTL (jsc#PED-348).
  - commit 16db600
  - KVM: x86: Move pv_unhalted check out of kvm_vcpu_has_events()
    (jsc#PED-348).
  - commit 43d4480
  - pmdomain: core: Introduce dev_pm_genpd_rpm_always_on()
    (git-fixes).
  - commit 0ef07f9
  - net: switchdev: Convert blocking notification chain to a raw
    one (CVE-2025-21986 bsc#1240810).
  - commit 85f36f1
  - KVM: TDX: Disable support for TSX and WAITPKG (jsc#PED-348).
  - commit bc35c5e
  - KVM: x86: Have ____kvm_emulate_hypercall() read the GPRs
    (jsc#PED-348).
  - commit 850ed89
  - KVM: TDX: restore user ret MSRs (jsc#PED-348).
  - commit cfdcb3d
  - KVM: x86: Allow to update cached values in kvm_user_return_msrs
    w/o wrmsr (jsc#PED-348).
  - commit 8a2fb55
  - KVM: TDX: restore host xsave state when exit from the guest TD
    (jsc#PED-348).
  - commit 611c719
  - KVM: TDX: vcpu_run: save/restore host state(host kernel gs)
    (jsc#PED-348).
  - commit 06d5ada
  - KVM: TDX: Implement TDX vcpu enter/exit path (jsc#PED-348).
  - commit 38e314c
  - KVM: VMX: Move common fields of struct vcpu_{vmx,tdx} to a
    struct (jsc#PED-348).
  - commit dd35aa6
  - KVM: TDX: Handle SEPT zap error due to page add error in premap
    (jsc#PED-348).
  - commit 046d39c
  - x86/virt/tdx: Add SEAMCALL wrapper to enter/exit TDX guest
    (jsc#PED-348).
  - commit 12e92a7
  - KVM: TDX: Skip updating CPU dirty logging request for TDs
    (jsc#PED-348).
  - commit 95e549f
  - KVM: x86: Make cpu_dirty_log_size a per-VM value (jsc#PED-348).
  - commit 94f097d
  - KVM: x86/mmu: Add parameter "kvm" to
    kvm_mmu_page_ad_need_write_protect() (jsc#PED-348).
  - commit 1e27dc3
  - KVM: Add parameter "kvm" to kvm_cpu_dirty_log_size() and its
    callers (jsc#PED-348).
  - commit 74de069
  - KVM: TDX: Handle vCPU dissociation (jsc#PED-348).
  - commit 9718bb2
  - KVM: TDX: Finalize VM initialization (jsc#PED-348).
  - commit f6520b5
  - KVM: TDX: Add an ioctl to create initial guest memory
    (jsc#PED-348).
  - commit ff60511
  - KVM: x86/mmu: Export kvm_tdp_map_page() (jsc#PED-348).
  - commit 3465834
  - KVM: x86/mmu: Bail out kvm_tdp_map_page() when VM dead
    (jsc#PED-348).
  - commit 144e592
  - KVM: TDX: Implement hook to get max mapping level of private
    pages (jsc#PED-348).
  - commit 554515d
  - KVM: TDX: Implement hooks to propagate changes of TDP MMU
    mirror page table (jsc#PED-348).
  - commit f1d4b55
  - KVM: TDX: Handle TLB tracking for TDX (jsc#PED-348).
  - commit f0faa8e
  - KVM: TDX: Set per-VM shadow_mmio_value to 0 (jsc#PED-348).
  - commit 49dae5c
  - KVM: x86/mmu: Add setter for shadow_mmio_value (jsc#PED-348).
  - commit b058430
  - KVM: TDX: Require TDP MMU, mmio caching and EPT A/D bits for
    TDX (jsc#PED-348).
  - commit 7d874e9
  - KVM: TDX: Set gfn_direct_bits to shared bit (jsc#PED-348).
  - commit ef0e482
  - KVM: TDX: Add load_mmu_pgd method for TDX (jsc#PED-348).
  - commit d5b9d6f
  - KVM: TDX: Add accessors VMX VMCS helpers (jsc#PED-348).
  - commit 1f2f6c1
  - KVM: VMX: Teach EPT violation helper about private mem
    (jsc#PED-348).
  - commit 7088974
  - KVM: VMX: Split out guts of EPT violation to common/exposed
    function (jsc#PED-348).
  - commit 72c8f3e
  - KVM: x86/mmu: Do not enable page track for TD guest
    (jsc#PED-348).
  - commit de6c038
  - KVM: x86/tdp_mmu: Add a helper function to walk down the TDP
    MMU (jsc#PED-348).
  - commit 44a0f73
  - KVM: x86/mmu: Implement memslot deletion for TDX (jsc#PED-348).
  - commit 3d2ab8b
  - x86/virt/tdx: Add SEAMCALL wrappers for TD measurement of
    initial contents (jsc#PED-348).
  - commit abf2eb5
  - net: allow small head cache usage with large MAX_SKB_FRAGS
    values (CVE-2025-21868 bsc#1240180).
  - commit 289f29e
  - KVM: TDX: Register TDX host key IDs to cgroup misc controller
    (jsc#PED-348).
  - commit b50c816
  - x86/virt/tdx: Add SEAMCALL wrappers to remove a TD private page
    (jsc#PED-348).
  - commit 466591d
  - KVM: x86/mmu: Taking guest pa into consideration when calculate
    tdp level (jsc#PED-348).
  - commit 3904d80
  - x86/virt/tdx: Add SEAMCALL wrappers to manage TDX TLB tracking
    (jsc#PED-348).
  - commit a485453
  - KVM: x86: Introduce KVM_TDX_GET_CPUID (jsc#PED-348).
  - commit fe28688
  - x86/virt/tdx: Add SEAMCALL wrappers to add TD private pages
    (jsc#PED-348).
  - commit 2498b76
  - KVM: TDX: Do TDX specific vcpu initialization (jsc#PED-348).
  - commit 165bc3a
  - x86/virt/tdx: Add SEAMCALL wrapper tdh_mem_sept_add() to add
    SEPT pages (jsc#PED-348).
  - commit 7395169
  - KVM: TDX: create/free TDX vcpu structure (jsc#PED-348).
  - commit 98bd9d9
  - KVM: TDX: Don't offline the last cpu of one package when
    there's TDX guest (jsc#PED-348).
  - commit e74a04c
  - powerpc/pseries/dlpar: Search DRC index from ibm,drc-indexes
    for IO add (bsc#1243042 ltc#212167).
  - commit 87e2def
  - KVM: TDX: Make pmu_intel.c ignore guest TD case (jsc#PED-348).
  - commit 7db5893
  - KVM: TDX: add ioctl to initialize VM with TDX specific
    parameters (jsc#PED-348).
  - commit 9a8f7c4
  - KVM: x86: expose cpuid_entry2_find for TDX (jsc#PED-348).
  - commit d6d74c0
  - KVM: TDX: Support per-VM KVM_CAP_MAX_VCPUS extension check
    (jsc#PED-348).
  - commit 99f1ef2
  - KVM: TDX: create/destroy VM structure (jsc#PED-348).
  - commit ff395b9
  - KVM: TDX: Get system-wide info about TDX module on
    initialization (jsc#PED-348).
  - commit f966b83
  - cifs: avoid NULL pointer dereference in dbg call (CVE-2025-37844 bsc#1242946)
  - commit 13ce184
  - KVM: TDX: Add place holder for TDX VM specific mem_enc_op ioctl
    (jsc#PED-348).
  - commit fb81451
  - KVM: TDX: Add helper functions to print TDX SEAMCALL error
    (jsc#PED-348).
  - commit c7850a7
  - KVM: TDX: Add TDX "architectural" error codes (jsc#PED-348).
  - commit ae6dde8
  - KVM: TDX: Define TDX architectural definitions (jsc#PED-348).
  - commit 0b39ad1
  - KVM: TDX: Add placeholders for TDX VM/vCPU structures
    (jsc#PED-348).
  - commit 4331504
  - KVM: TDX: Get TDX global information (jsc#PED-348).
  - commit 2639f49
  - KVM: VMX: Initialize TDX during KVM module load (jsc#PED-348).
  - commit e605aaf
  - KVM: VMX: Refactor VMX module init/exit functions (jsc#PED-348).
  - commit 3880b0c
  - scsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer() (CVE-2025-37826 bsc#1242862)
  - commit d04f316
  - KVM: Export hardware virtualization enabling/disabling functions
    (jsc#PED-348).
  - commit dbb21b7
  - x86/virt/tdx: Add tdx_guest_keyid_alloc/free() to alloc and
    free TDX guest KeyID (jsc#PED-348).
  - commit 4dc8a98
  - x86/virt/tdx: Read essential global metadata for KVM
    (jsc#PED-348).
  - commit 8ddca0b
  - x86/virt/tdx: allocate tdx_sys_info in static memory
    (jsc#PED-348).
  - commit 6a14d13
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX flush operations
    (jsc#PED-348).
  - commit c2d6ae0
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX VM/vCPU field access
    (jsc#PED-348).
  - commit a4a8ea9
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX page cache
    management (jsc#PED-348).
  - commit f562ade
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX vCPU creation
    (jsc#PED-348).
  - commit 4596a12
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX TD creation
    (jsc#PED-348).
  - commit 67ea0be
  - x86/virt/tdx: Add SEAMCALL wrappers for TDX KeyID management
    (jsc#PED-348).
  - commit 4535d8f
  - Update
    patches.suse/9p-net-fix-improper-handling-of-bogus-negative-read-.patch
    (git-fixes CVE-2025-37879 bsc#1243077).
  - Update
    patches.suse/ALSA-ump-Fix-buffer-overflow-at-UMP-SysEx-message-co.patch
    (bsc#1242044 CVE-2025-37891 bsc#1243589).
  - Update
    patches.suse/ASoC-Intel-avs-Fix-null-ptr-deref-in-avs_component_p.patch
    (git-fixes CVE-2025-37793 bsc#1242584).
  - Update
    patches.suse/ASoC-amd-acp-Fix-NULL-pointer-deref-in-acp_i2s_set_t.patch
    (git-fixes CVE-2025-37919 bsc#1243478).
  - Update
    patches.suse/ASoC-codecs-wcd937x-fix-a-potential-memory-leak-in-w.patch
    (git-fixes CVE-2025-37941 bsc#1243525).
  - Update
    patches.suse/ASoC-imx-card-Add-NULL-check-in-imx_card_probe.patch
    (git-fixes CVE-2025-22066 bsc#1241340).
  - Update
    patches.suse/ASoC-ops-Consistently-treat-platform_max-as-control-.patch
    (git-fixes CVE-2025-37889 bsc#1242945).
  - Update
    patches.suse/ASoC-qcom-Fix-sc7280-lpass-potential-buffer-overflow.patch
    (git-fixes CVE-2025-37979 bsc#1243545).
  - Update
    patches.suse/ASoC-simple-card-utils-Fix-pointer-check-in-graph_ut.patch
    (git-fixes CVE-2025-37934 bsc#1243548).
  - Update
    patches.suse/Bluetooth-btrtl-Prevent-potential-NULL-dereference.patch
    (git-fixes CVE-2025-37792 bsc#1242591).
  - Update
    patches.suse/Bluetooth-btusb-avoid-NULL-pointer-dereference-in-sk.patch
    (git-fixes CVE-2025-37918 bsc#1243476).
  - Update
    patches.suse/HID-pidff-Fix-null-pointer-dereference-in-pidff_find.patch
    (stable-fixes CVE-2025-37862 bsc#1242982).
  - Update
    patches.suse/HID-pidff-Make-sure-to-fetch-pool-before-checking-SI.patch
    (stable-fixes CVE-2025-37942 bsc#1243576).
  - Update
    patches.suse/HSI-ssi_protocol-Fix-use-after-free-vulnerability-in.patch
    (stable-fixes CVE-2025-37838 bsc#1241641).
  - Update
    patches.suse/Input-mtk-pmic-keys-fix-possible-null-pointer-derefe.patch
    (git-fixes CVE-2025-37972 bsc#1243573).
  - Update
    patches.suse/KVM-SVM-Forcibly-leave-SMM-mode-on-SHUTDOWN-intercep.patch
    (git-fixes CVE-2025-37957 bsc#1243513).
  - Update
    patches.suse/KVM-x86-Reset-IRTE-to-host-control-if-new-route-isn-.patch
    (git-fixes CVE-2025-37885 bsc#1242960).
  - Update
    patches.suse/PCI-Fix-reference-leak-in-pci_register_host_bridge.patch
    (git-fixes CVE-2025-37836 bsc#1242957).
  - Update
    patches.suse/PCI-brcmstb-Fix-error-path-after-a-call-to-regulator.patch
    (git-fixes CVE-2025-22095 bsc#1241519).
  - Update
    patches.suse/PCI-pciehp-Avoid-unnecessary-device-replacement-chec.patch
    (git-fixes CVE-2025-37843 bsc#1242956).
  - Update
    patches.suse/PCI-vmd-Make-vmd_dev-cfg_lock-a-raw_spinlock_t-type.patch
    (stable-fixes CVE-2025-23161 bsc#1242792).
  - Update
    patches.suse/PM-hibernate-Avoid-deadlock-in-hibernate_compressor_.patch
    (stable-fixes CVE-2025-37745 bsc#1242853).
  - Update
    patches.suse/RDMA-cma-Fix-workqueue-crash-in-cma_netevent_work_ha.patch
    (git-fixes CVE-2025-37772 bsc#1242563).
  - Update
    patches.suse/RDMA-core-Don-t-expose-hw_counters-outside-of-init-n.patch
    (git-fixes CVE-2025-22089 bsc#1241538).
  - Update
    patches.suse/RDMA-core-Silence-oversized-kvmalloc-warning.patch
    (git-fixes CVE-2025-37867 bsc#1242948).
  - Update
    patches.suse/USB-wdm-close-race-between-wdm_open-and-wdm_wwan_por.patch
    (git-fixes CVE-2025-37985 bsc#1243529).
  - Update
    patches.suse/accel-ivpu-Fix-PM-related-deadlocks-in-MS-IOCTLs.patch
    (git-fixes CVE-2025-37848 bsc#1242943).
  - Update
    patches.suse/accel-ivpu-Fix-deadlock-in-ivpu_ms_cleanup.patch
    (git-fixes CVE-2025-37847 bsc#1242947).
  - Update
    patches.suse/arm64-errata-Add-missing-sentinels-to-Spectre-BHB-MIDR-arr.patch
    (git-fixes CVE-2025-37929 bsc#1243624).
  - Update
    patches.suse/arm64-mops-Do-not-dereference-src-reg-for-a-set-operation.patch
    (git-fixes CVE-2025-37846 bsc#1242963).
  - Update
    patches.suse/ata-pata_pxa-Fix-potential-NULL-pointer-dereference-.patch
    (git-fixes CVE-2025-37758 bsc#1242514).
  - Update
    patches.suse/backlight-led_bl-Hold-led_access-lock-when-calling-l.patch
    (git-fixes CVE-2025-23144 bsc#1242568).
  - Update
    patches.suse/block-fix-resource-leak-in-blk_register_queue-error-path.patch
    (git-fixes CVE-2025-37980 bsc#1243522).
  - Update
    patches.suse/block-integrity-Do-not-call-set_page_dirty_lock.patch
    (git-fixes CVE-2025-37978 bsc#1243516).
  - Update patches.suse/block-mark-GFP_NOIO-around-sysfs-store.patch
    (jsc#PED-9651 CVE-2025-21817 bsc#1239106).
  - Update
    patches.suse/bnxt_en-Fix-error-handling-path-in-bnxt_init_chip.patch
    (git-fixes CVE-2025-37895 bsc#1243532).
  - Update
    patches.suse/bnxt_en-Fix-out-of-bound-memcpy-during-ethtool-w.patch
    (git-fixes CVE-2025-37911 bsc#1243469).
  - Update
    patches.suse/book3s64-radix-Align-section-vmemmap-start-address-t.patch
    (bsc#1238318 bsc#1243298 ltc#212689 CVE-2025-37922 bsc#1243481).
  - Update patches.suse/bpf-Scrub-packet-on-bpf_redirect_peer.patch
    (git-fixes CVE-2025-37959 bsc#1243517).
  - Update
    patches.suse/bpf-check-changes_pkt_data-property-for-extension-pr.patch
    (bsc#1241590 CVE-2024-58100 bsc#1242564).
  - Update
    patches.suse/bpf-consider-that-tail-calls-invalidate-packet-point.patch
    (git-fixes CVE-2024-58237 bsc#1242574).
  - Update
    patches.suse/bpf-track-changes_pkt_data-property-for-global-funct.patch
    (bsc#1241590 CVE-2024-58098 bsc#1242565).
  - Update
    patches.suse/btrfs-adjust-subpage-bit-start-based-on-sectorsize.patch
    (bsc#1241492 CVE-2025-37931 bsc#1243626).
  - Update
    patches.suse/bus-mhi-host-Fix-race-between-unprepare-and-queue_bu.patch
    (git-fixes CVE-2025-23151 bsc#1242512).
  - Update
    patches.suse/crypto-null-Use-spin-lock-instead-of-mutex.patch
    (stable-fixes CVE-2025-37808 bsc#1242923).
  - Update
    patches.suse/cxgb4-fix-memory-leak-in-cxgb4_init_ethtool_filters-.patch
    (git-fixes CVE-2025-37788 bsc#1242766).
  - Update
    patches.suse/dm-bufio-don-t-schedule-in-atomic-context.patch
    (git-fixes CVE-2025-37928 bsc#1243621).
  - Update
    patches.suse/dmaengine-fsl-edma-free-irq-correctly-in-remove-path.patch
    (git-fixes CVE-2025-38479 bsc#1242036).
  - Update
    patches.suse/driver-core-fix-potential-NULL-pointer-dereference-i.patch
    (stable-fixes CVE-2025-37800 bsc#1242849).
  - Update
    patches.suse/drm-amd-display-Fix-slab-use-after-free-in-hdcp.patch
    (git-fixes CVE-2025-37903 bsc#1243562).
  - Update
    patches.suse/drm-amd-display-prevent-hang-on-link-training-fail.patch
    (stable-fixes CVE-2025-37870 bsc#1243056).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-4b8c3c0.patch
    (git-fixes CVE-2025-37770 bsc#1242764).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-4e3d950.patch
    (git-fixes CVE-2025-37766 bsc#1242785).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-7c246a0.patch
    (git-fixes CVE-2025-37768 bsc#1242567).
  - Update
    patches.suse/drm-amd-pm-Prevent-division-by-zero-7d641c2.patch
    (git-fixes CVE-2025-37771 bsc#1242781).
  - Update patches.suse/drm-amd-pm-Prevent-division-by-zero.patch
    (git-fixes CVE-2025-37767 bsc#1242501).
  - Update
    patches.suse/drm-amd-pm-smu11-Prevent-division-by-zero.patch
    (git-fixes CVE-2025-37769 bsc#1242587).
  - Update
    patches.suse/drm-amdgpu-handle-amdgpu_cgs_create_device-errors-in.patch
    (stable-fixes CVE-2025-37852 bsc#1243074).
  - Update patches.suse/drm-amdkfd-Fix-mode1-reset-crash-issue.patch
    (stable-fixes CVE-2025-37854 bsc#1243082).
  - Update
    patches.suse/drm-amdkfd-debugfs-hang_hws-skip-GPU-with-MES.patch
    (stable-fixes CVE-2025-37853 bsc#1243076).
  - Update
    patches.suse/drm-i915-huc-Fix-fence-not-released-on-early-probe-e.patch
    (git-fixes CVE-2025-37754 bsc#1242524).
  - Update
    patches.suse/drm-imagination-fix-firmware-memory-leaks.patch
    (git-fixes CVE-2025-37764 bsc#1242577).
  - Update
    patches.suse/drm-imagination-take-paired-job-reference.patch
    (git-fixes CVE-2025-37763 bsc#1242508).
  - Update
    patches.suse/drm-mediatek-dp-drm_err-dev_err-in-HPD-path-to-avoid.patch
    (git-fixes CVE-2025-38240 bsc#1241457).
  - Update
    patches.suse/drm-nouveau-Fix-WARN_ON-in-nouveau_fence_context_kil.patch
    (git-fixes CVE-2025-37930 bsc#1243625).
  - Update
    patches.suse/drm-nouveau-prime-fix-ttm_bo_delayed_delete-oops.patch
    (git-fixes CVE-2025-37765 bsc#1242761).
  - Update
    patches.suse/drm-v3d-Add-job-to-pending-list-if-the-reset-was-ski.patch
    (stable-fixes CVE-2025-37951 bsc#1243659).
  - Update
    patches.suse/drm-xe-Fix-an-out-of-bounds-shift-when-invalidating-.patch
    (git-fixes CVE-2025-37761 bsc#1242724).
  - Update
    patches.suse/drm-xe-Use-local-fence-in-error-path-of-xe_migrate_c.patch
    (git-fixes CVE-2025-37869 bsc#1242967).
  - Update
    patches.suse/drm-xe-userptr-fix-notifier-vs-folio-deadlock.patch
    (git-fixes CVE-2025-37868 bsc#1242966).
  - Update
    patches.suse/drm-xe-vf-Don-t-try-to-trigger-a-full-GT-reset-if-VF.patch
    (stable-fixes CVE-2025-23162 bsc#1242834).
  - Update
    patches.suse/eth-bnxt-fix-missing-ring-index-trim-on-error-path.patch
    (git-fixes CVE-2025-37873 bsc#1242961).
  - Update
    patches.suse/ethtool-cmis_cdb-use-correct-rpl-size-in-ethtool_cmi.patch
    (git-fixes CVE-2025-37791 bsc#1242729).
  - Update patches.suse/fbdev-omapfb-Add-plane-value-check.patch
    (stable-fixes CVE-2025-37851 bsc#1242977).
  - Update
    patches.suse/firmware-arm_scmi-Balance-device-refcount-when-destr.patch
    (git-fixes CVE-2025-37905 bsc#1243456).
  - Update
    patches.suse/i2c-cros-ec-tunnel-defer-probe-if-parent-EC-is-not-p.patch
    (git-fixes CVE-2025-37781 bsc#1242575).
  - Update
    patches.suse/i3c-Add-NULL-pointer-check-in-i3c_master_queue_ibi.patch
    (git-fixes CVE-2025-23147 bsc#1242530).
  - Update
    patches.suse/ice-Check-VF-VSI-Pointer-Value-in-ice_vc_add_fdir_fl.patch
    (git-fixes CVE-2025-37912 bsc#1243470).
  - Update patches.suse/igc-fix-PTM-cycle-trigger-logic.patch
    (git-fixes CVE-2025-37875 bsc#1242959).
  - Update
    patches.suse/iio-backend-make-sure-to-NULL-terminate-stack-buffer.patch
    (git-fixes CVE-2025-22082 bsc#1241336).
  - Update
    patches.suse/iio-imu-st_lsm6dsx-fix-possible-lockup-in-st_lsm6dsx-8114ef8.patch
    (git-fixes CVE-2025-37969 bsc#1243574).
  - Update
    patches.suse/iio-imu-st_lsm6dsx-fix-possible-lockup-in-st_lsm6dsx.patch
    (git-fixes CVE-2025-37970 bsc#1243575).
  - Update
    patches.suse/iio-light-Add-check-for-array-bounds-in-veml6075_rea.patch
    (git-fixes CVE-2025-40114 bsc#1241639).
  - Update
    patches.suse/iommu-Fix-two-issues-in-iommu_copy_struct_from_user.patch
    (git-fixes CVE-2025-37900 bsc#1243560).
  - Update
    patches.suse/irqchip-gic-v2m-Prevent-use-after-free-of-gicv2m_get.patch
    (git-fixes CVE-2025-37819 bsc#1242873).
  - Update
    patches.suse/irqchip-qcom-mpm-Prevent-crash-when-trying-to-handle.patch
    (git-fixes CVE-2025-37901 bsc#1243559).
  - Update patches.suse/jbd2-remove-wrong-sb-s_sequence-check.patch
    (bsc#1242343 CVE-2025-37839 bsc#1242990).
  - Update
    patches.suse/lib-iov_iter-fix-to-increase-non-slab-folio-refcount.patch
    (bsc#1241169 (MM functional and performance backports)
    CVE-2025-37779 bsc#1242525).
  - Update
    patches.suse/md-md-bitmap-fix-wrong-bitmap_limit-for-clustermd-wh.patch
    (bsc#1238212 CVE-2025-22124 bsc#1241595).
  - Update
    patches.suse/media-mediatek-vcodec-Fix-a-resource-leak-related-to.patch
    (git-fixes CVE-2025-23160 bsc#1242507).
  - Update
    patches.suse/media-venus-hfi-add-a-check-to-handle-OOB-in-sfr-reg.patch
    (git-fixes CVE-2025-23159 bsc#1242529).
  - Update
    patches.suse/media-venus-hfi-add-check-to-handle-incorrect-queue-.patch
    (git-fixes CVE-2025-23158 bsc#1242531).
  - Update
    patches.suse/media-venus-hfi_parser-add-check-to-avoid-out-of-bou.patch
    (git-fixes CVE-2025-23157 bsc#1242532).
  - Update
    patches.suse/media-venus-hfi_parser-refactor-hfi-packet-parsing-l.patch
    (git-fixes CVE-2025-23156 bsc#1242569).
  - Update
    patches.suse/mei-vsc-Fix-fortify-panic-caused-by-invalid-counted_.patch
    (git-fixes CVE-2025-37816 bsc#1242863).
  - Update
    patches.suse/mfd-ene-kb3930-Fix-a-potential-NULL-pointer-derefere.patch
    (git-fixes CVE-2025-23146 bsc#1242559).
  - Update
    patches.suse/misc-microchip-pci1xxxx-Fix-Kernel-panic-during-IRQ-.patch
    (git-fixes CVE-2025-37815 bsc#1242871).
  - Update patches.suse/mm-slab-clean-up-slab-obj_exts-always.patch
    (git-fixes CVE-2025-37908 bsc#1243466).
  - Update
    patches.suse/mtd-inftlcore-Add-error-check-for-inftl_read_oob.patch
    (git-fixes CVE-2025-37892 bsc#1243536).
  - Update
    patches.suse/mtd-rawnand-brcmnand-fix-PM-resume-warning.patch
    (git-fixes CVE-2025-37840 bsc#1242953).
  - Update
    patches.suse/net-decrease-cached-dst-counters-in-dst_release.patch
    (git-fixes CVE-2025-22057 bsc#1241533).
  - Update
    patches.suse/net-mlx5-Fix-null-ptr-deref-in-mlx5_create_-inner_-t.patch
    (git-fixes CVE-2025-37888 bsc#1242964).
  - Update
    patches.suse/net-phy-allow-MDIO-bus-PM-ops-to-start-stop-state-ma.patch
    (git-fixes CVE-2025-37945 bsc#1243538).
  - Update patches.suse/net-phy-leds-fix-memory-leak.patch
    (git-fixes CVE-2025-37989 bsc#1243511).
  - Update patches.suse/net-tls-explicitly-disallow-disconnect.patch
    (git-fixes CVE-2025-37756 bsc#1242515).
  - Update
    patches.suse/net-use-sock_gen_put-when-sk_state-is-TCP_TIME_WAIT.patch
    (git-fixes CVE-2025-37894 bsc#1243533).
  - Update
    patches.suse/net_sched-drr-Fix-double-list-add-in-class-with-nete.patch
    (git-fixes CVE-2025-37915 bsc#1243473).
  - Update
    patches.suse/net_sched-ets-Fix-double-list-add-in-class-with-nete.patch
    (git-fixes CVE-2025-37914 bsc#1243472).
  - Update
    patches.suse/net_sched-hfsc-Fix-a-UAF-vulnerability-in-class-with.patch
    (git-fixes CVE-2025-37890 bsc#1243330).
  - Update
    patches.suse/net_sched-qfq-Fix-double-list-add-in-class-with-nete.patch
    (git-fixes CVE-2025-37913 bsc#1243471).
  - Update
    patches.suse/nfsd-allow-SC_STATUS_FREEABLE-when-searching-via-nfs4_lookup_stateid.patch
    (git-fixes CVE-2025-39688 bsc#1241652).
  - Update
    patches.suse/nfsd-decrease-sc_count-directly-if-fail-to-queue-dl_recall.patch
    (git-fixes CVE-2025-37871 bsc#1242949).
  - Update
    patches.suse/nvmet-fix-out-of-bounds-access-in-nvmet_enable_port.patch
    (jsc#PED-9651 CVE-2025-37825 bsc#1242874).
  - Update
    patches.suse/objtool-media-dib8000-Prevent-divide-by-zero-in-dib8.patch
    (git-fixes CVE-2025-37937 bsc#1243540).
  - Update
    patches.suse/objtool-nvmet-Fix-out-of-bounds-stack-access-in-nvme.patch
    (git-fixes CVE-2025-39778 bsc#1241632).
  - Update
    patches.suse/objtool-spi-amd-Fix-out-of-bounds-stack-access-in-am.patch
    (git-fixes CVE-2025-40014 bsc#1241644).
  - Update
    patches.suse/page_pool-avoid-infinite-loop-to-schedule-delayed-wo.patch
    (git-fixes CVE-2025-37859 bsc#1243051).
  - Update
    patches.suse/powerpc64-ftrace-fix-module-loading-without-patchabl.patch
    (jsc#PED-10909 git-fixes bsc#1236402 CVE-2025-37898
    bsc#1243549).
  - Update
    patches.suse/pwm-mediatek-Prevent-divide-by-zero-in-pwm_mediatek_.patch
    (git-fixes CVE-2025-37850 bsc#1242955).
  - Update patches.suse/qibfs-fix-_another_-leak.patch (git-fixes
    CVE-2025-37983 bsc#1243567).
  - Update
    patches.suse/remoteproc-core-Clear-table_sz-when-rproc_shutdown.patch
    (git-fixes CVE-2025-38152 bsc#1241627).
  - Update
    patches.suse/s390-pci-Fix-duplicate-pci_dev_put-in-disable_slot-w.patch
    (git-fixes CVE-2025-37946 bsc#1243506).
  - Update patches.suse/sch_htb-make-htb_deactivate-idempotent.patch
    (CVE-2025-37798 bsc#1242414 CVE-2025-37953 bsc#1243543).
  - Update
    patches.suse/sch_htb-make-htb_qlen_notify-idempotent.patch
    (CVE-2025-37798 bsc#1242414 CVE-2025-37932 bsc#1243627).
  - Update
    patches.suse/scsi-smartpqi-Use-is_kdump_kernel-to-check-for-kdump.patch
    (git-fixes CVE-2025-37981 bsc#1243514).
  - Update
    patches.suse/sfc-fix-NULL-dereferences-in-ef100_process_design_pa.patch
    (git-fixes CVE-2025-37860 bsc#1241452).
  - Update
    patches.suse/soc-samsung-exynos-chipid-Add-NULL-pointer-check-in-.patch
    (git-fixes CVE-2025-23148 bsc#1242578).
  - Update
    patches.suse/sound-virtio-Fix-cancel_sync-warnings-on-uninitializ.patch
    (stable-fixes CVE-2025-37805 bsc#1242930).
  - Update
    patches.suse/staging-vchiq_arm-Fix-possible-NPR-of-keep-alive-thr.patch
    (git-fixes CVE-2025-22078 bsc#1241418).
  - Update
    patches.suse/tipc-fix-NULL-pointer-dereference-in-tipc_mon_reinit.patch
    (git-fixes CVE-2025-37824 bsc#1242867).
  - Update patches.suse/tpm-do-not-start-chip-while-suspended.patch
    (git-fixes CVE-2025-23149 bsc#1242758).
  - Update
    patches.suse/tty-Require-CAP_SYS_ADMIN-for-all-usages-of-TIOCL_SE.patch
    (git-fixes CVE-2025-37814 bsc#1242865).
  - Update
    patches.suse/ublk-fix-handling-recovery-reissue-in-ublk_abort_queue.patch
    (git-fixes CVE-2025-37759 bsc#1242519).
  - Update
    patches.suse/usb-cdns3-Fix-deadlock-when-using-NCM-gadget.patch
    (git-fixes CVE-2025-37812 bsc#1242908).
  - Update
    patches.suse/usb-chipidea-ci_hdrc_imx-fix-usbmisc-handling.patch
    (git-fixes CVE-2025-37811 bsc#1242907).
  - Update
    patches.suse/usb-dwc3-gadget-check-that-event-count-does-not-exce.patch
    (git-fixes CVE-2025-37810 bsc#1242906).
  - Update
    patches.suse/usb-gadget-aspeed-Add-NULL-pointer-check-in-ast_vhub.patch
    (git-fixes CVE-2025-37881 bsc#1242973).
  - Update
    patches.suse/usb-typec-class-Fix-NULL-pointer-access.patch
    (git-fixes CVE-2025-37809 bsc#1242856).
  - Update
    patches.suse/usb-typec-class-Invalidate-USB-device-pointers-on-pa.patch
    (git-fixes CVE-2025-37986 bsc#1243515).
  - Update
    patches.suse/usb-typec-ucsi-displayport-Fix-deadlock.patch
    (git-fixes CVE-2025-37967 bsc#1243572).
  - Update
    patches.suse/usb-xhci-Don-t-skip-on-Stopped-Length-Invalid.patch
    (git-fixes CVE-2025-22023 bsc#1241298).
  - Update
    patches.suse/usb-xhci-Fix-invalid-pointer-dereference-in-Etron-wo.patch
    (git-fixes CVE-2025-37813 bsc#1242909).
  - Update
    patches.suse/usb-xhci-Fix-isochronous-Ring-Underrun-Overrun-event.patch
    (stable-fixes CVE-2025-37882 bsc#1243234).
  - Update
    patches.suse/virtio-net-free-xsk_buffs-on-error-in-virtnet_xsk_po.patch
    (git-fixes CVE-2025-37955 bsc#1243507).
  - Update
    patches.suse/wifi-at76c50x-fix-use-after-free-access-in-at76_disc.patch
    (git-fixes CVE-2025-37796 bsc#1242727).
  - Update
    patches.suse/wifi-ath12k-Fix-invalid-data-access-in-ath12k_dp_rx_.patch
    (stable-fixes CVE-2025-37943 bsc#1243509).
  - Update
    patches.suse/wifi-ath12k-Fix-invalid-entry-fetch-in-ath12k_dp_mon.patch
    (stable-fixes CVE-2025-37944 bsc#1243530).
  - Update
    patches.suse/wifi-brcm80211-fmac-Add-error-handling-for-brcmf_usb.patch
    (git-fixes CVE-2025-37990 bsc#1243528).
  - Update
    patches.suse/wifi-cfg80211-init-wiphy_work-before-allocating-rfki.patch
    (git-fixes CVE-2025-22119 bsc#1241576).
  - Update
    patches.suse/wifi-mac80211-Purge-vif-txq-in-ieee80211_do_stop.patch
    (git-fixes CVE-2025-37794 bsc#1242566).
  - Update
    patches.suse/wifi-plfxlc-Remove-erroneous-assert-in-plfxlc_mac_re.patch
    (git-fixes CVE-2025-37897 bsc#1243534).
  - Update
    patches.suse/wifi-wl1251-fix-memory-leak-in-wl1251_tx_work.patch
    (git-fixes CVE-2025-37982 bsc#1243524).
  - Update
    patches.suse/xen-netfront-handle-NULL-returned-by-xdp_convert_buf.patch
    (git-fixes CVE-2025-37820 bsc#1242866).
  - Update patches.suse/xenbus-Use-kref-to-track-req-lifetime.patch
    (git-fixes CVE-2025-37949 bsc#1243541).
  - Update
    patches.suse/xsk-fix-an-integer-overflow-in-xp_create_and_assign_.patch
    (git-fixes CVE-2025-21997 bsc#1240823).
  - commit bc63f80
  - arm64: Add override for MPAM (bsc#1242843)
  - commit eb086b5
  - printk: Check CON_SUSPEND when unblanking a console
    (bsc#1243998).
  - commit bab4aa6
  - Flush console log from kernel_power_off() (bsc#1243996).
  - commit cd77fb7
  - arm64/mm: Permit lazy_mmu_mode to be nested (git-fixes)
  - commit ed7a958
  - arm64/mm: Disable barrier batching in interrupt contexts (git-fixes)
  - commit dabd452
  - smccc: kvm_guest: Align with DISCOVER_IMPL_CPUS ABI (git-fixes)
  - commit cbe1757

++++ gcc15:

  - Make cross-*-gcc15-bootstrap package conflict with the non-bootstrap
    variant conflict with the unversioned cross-*-gcc package.

++++ ceph:

  - Add ceph-volume-fix-importlib.metadata-compat.patch
  - Added ceph-mgr-python-avoid-pyo3-errors.patch
  - Added ceph-mgr-do-not-require-NOTIFY_TYPES-in-python-modules.patch
  - Added ceph-mgr-workaround-numpy-28271.patch

++++ libsolv:

  - improve transaction ordering by allowing more uninst->uninst
    edges [bsc#1243457]
  - implement color filtering when adding update targets
  - support orderwithrequires dependencies in susedata.xml
  - bump version to 0.7.33

++++ openSUSE-repos-LeapMicro:

  - Update to version 20250604.94835c9:
    * Add gpgkey for codecs-o-o as well
    * Drop opensuse_repos.sh

------------------------------------------------------------------
------------------  2025-6-2  -  Jun 2 2025  -------------------
------------------------------------------------------------------

++++ container-selinux:

  - Update to version 2.238.0:
    * label /run/sysctl.d correctly on creation

++++ coreutils:

  - coreutils-9.6-sort-CVE-2025-5278.patch: Add upstream patch:
    sort with key character offsets of SIZE_MAX, could induce
    a read of 1 byte before an allocated heap buffer.
    (CVE-2025-5278, bsc#1243767)

++++ coreutils-systemd:

  - coreutils-9.6-sort-CVE-2025-5278.patch: Add upstream patch:
    sort with key character offsets of SIZE_MAX, could induce
    a read of 1 byte before an allocated heap buffer.
    (CVE-2025-5278, bsc#1243767)

++++ dhcpcd:

  - Update to 10.2.4
    * compat: use timingsafe_bcmp if available
    * IPv6: Sort routers by reachability correctly.
    * definitions: define ND Route Information option
    * IPv6: Clear previous address RA flags on receipt of a RA.

++++ python-kiwi:

  - Use f-strings where feasible
    This is a slightly shorter and easier to read syntax
  - Allow multiple EFI arch binaries/modules
    Allow to lookup and included EFI binaries/modules for
    multiple architectures. For testing the integration
    test in rawhide/test-image-live-disk has been adapted
    accordingly to install 32bit and 64bit EFI binaries.
    This Fixes #2822
  - Log warning message for disabled runtime checks
    Complete type hints for RuntimeConfig class and log
    a warning message for each disabled runtime check
  - Fix static type argument int vs. str
  - Move it inside the context that actually uses it
    also rename it to "supported" as that seems to closer match
    what it resembles
  - Add overlayfs as supporting xattr/ACLs as well
  - Fix disk_type validation for zipl loader
    If the targettype is set to GPT in combination with plain
    zipl as loader, the code to validate the targettype against
    the targetgeometry was not effective and zipl failed.
    This Fixes #2821

++++ glibc:

  - Filter GLIBC_PRIVATE symbols again
  - Drop ngpt provides
  - Compile functions in libc_nonshared.a as PIC

++++ kernel-default:

  - kABI: net: page_pool: avoid false positive warning if NAPI
    was never added (git-fixes).
  - commit 06adb55
  - smb: cached directories can be more than root file handle
    (git-fixes).
  - commit afb4d0b
  - smb: client: remove unnecessary checks in open_cached_dir()
    (git-fixes).
  - commit a9818f2
  - smb: client: change return value in open_cached_dir_by_dentry()
    if !cfids (git-fixes).
  - commit 3994f63
  - smb: client: Avoid race in open_cached_dir with lease breaks
    (CVE-2025-37954 bsc#1243664).
  - commit af201ef
  - KVM: arm64: Specify hypercall ABI for retrieving target (git-fixes)
  - commit 5a6faf6
  - KVM: PPC: Book3S HV: Fix IRQ map warnings with XICS on pSeries
    KVM Guest (bsc#1242205 ltc#212592).
  - commit d1b31ab
  - arm64: errata: Work around AmpereOne's erratum AC04_CPU_23 (git-fixes)
    Enable workaround for this errata and remove one slot of kABI
    preservation list.
  - commit 0a959f3
  - KVM: arm64: Force HCR_EL2.xMO to 1 at all times in VHE mode (git-fixes)
  - commit 92b45e1
  - arm64: sysreg: Add layout for ICH_HCR_EL2 (git-fixes)
  - commit 10c80f5
  - objtool, panic: Disable SMAP in __stack_chk_fail()
    (bsc#1243963).
  - commit 1d39035
  - net: stmmac: Fix accessing freed irq affinity_hint (CVE-2025-23155 bsc#1242573)
  - commit b63c5f4
  - memblock: Accept allocated memory before use in
    memblock_double_array() (CVE-2025-37960 bsc#1243519).
  - commit 754095c
  - mm/huge_memory: fix dereferencing invalid pmd migration entry
    (CVE-2025-37958 bsc#1243539).
  - commit 675ffa4
  - dm: restrict dm device size to 2^63-512 bytes (git-fixes).
  - commit ae2ce2b
  - dm cache: prevent BUG_ON by blocking retries on failed device
    resumes (git-fixes).
  - commit d254a94
  - dm: fix unconditional IO throttle caused by REQ_PREFLUSH
    (git-fixes).
  - commit fec8e9d
  - dm vdo indexer: prevent unterminated string warning (git-fixes).
  - commit 379a5f2
  - dm vdo: use a short static string for thread name prefix
    (git-fixes).
  - commit 8084a50
  - net_sched: sch_sfq: move the limit validation (CVE-2025-37752 bsc#1242504)
  - commit c353024
  - net: lwtunnel: disable BHs when required (git-fixes).
  - commit 304c8c4
  - mmc: sdhci-of-dwcmshc: add PD workaround on RK3576 (git-fixes).
  - commit 19be083
  - mmc: sdhci-msm: fix dev reference leaked through of_qcom_ice_get
    (git-fixes).
  - commit e8bf316
  - mmc: host: Wait for Vdd to settle on card power off (git-fixes).
  - commit 6799785
  - mmc: dw_mmc: add exynos7870 DW MMC support (git-fixes).
  - commit 2d642c3
  - mmc: sdhci: Disable SD card clock before changing parameters
    (git-fixes).
  - commit eab27bb
  - platform/x86/intel/pmc: Fix Arrow Lake U/H NPU PCI ID
    (git-fixes).
  - commit 2916acb
  - platform/x86: dell-wmi-sysman: Avoid buffer overflow in
    current_password_store() (git-fixes).
  - commit d257f90
  - platform/x86: ideapad-laptop: add support for some new buttons
    (git-fixes).
  - commit 1e3c868
  - platform/x86: asus-wmi: Disable OOBE state after resume from
    hibernation (git-fixes).
  - commit c9e24c6
  - platform/x86/intel: hid: Add Pantherlake support (git-fixes).
  - commit 460cc0c
  - Input: synaptics-rmi - fix crash with unsupported versions of
    F34 (git-fixes).
  - commit b62a334
  - Input: xpad - add more controllers (git-fixes).
  - commit b79f69c
  - Input: xpad - fix xpad_device sorting (git-fixes).
  - commit 46af804
  - Input: xpad - add support for several more controllers
    (git-fixes).
  - commit ab01d4f
  - arm64/sysreg: Expose MTE_frac so that it is visible to KVM (git-fixes)
  - commit 53f8737
  - arm64/cpuinfo: only show one cpu's info in c_show() (git-fixes)
  - commit c7e06a7
  - arm64/mm: Batch barriers when updating kernel mappings (git-fixes)
  - commit 133d7c0
  - arm64/cpufeature: Add missing id_aa64mmfr4 feature reg update (git-fixes)
  - commit 0d85371
  - arm64: Rework checks for broken Cavium HW in the PI code (git-fixes)
  - commit 589c17e
  - arm64: Add support for HIP09 Spectre-BHB mitigation (git-fixes)
  - commit f8ba796
  - arm64: topology: Support SMT control on ACPI based system (git-fixes)
  - commit 48b6d40
  - kABI: ipv6: save dontfrag in cork (git-fixes).
    Patch-up the kABI change with an #ifdef __GENKSYMS__. This change is
    safe (as detailed in the patch commit message) due to the struct
    having a 6-byte hole at the end we can use.
  - commit c19b923
  - ipv6: save dontfrag in cork (git-fixes).
  - commit f07ae24
  - tcp: bring back NUMA dispersion in inet_ehash_locks_alloc()
    (git-fixes).
  - commit 3096e43
  - net: page_pool: avoid false positive warning if NAPI was never
    added (git-fixes).
  - commit 13d3621
  - ipv4: ip_gre: Fix set but not used warning in ipgre_err()
    if IPv4-only (git-fixes).
  - commit e7bb54c
  - net: flush_backlog() small changes (git-fixes).
  - commit db8d6de
  - kABI: net: lwtunnel: fix recursion loops (git-fixes).
  - commit 0d4c30c
  - arm64/mm: Define PTDESC_ORDER (git-fixes)
  - commit fe6a508
  - arm64/kernel: Always use level 2 or higher for early mappings (git-fixes)
  - commit c847735
  - arm64/sysreg: Rename POE_RXW to POE_RWX (git-fixes)
  - commit 81d3162
  - arm64/sysreg: Improve PIR/POR helpers (git-fixes)
  - commit 8cac771
  - smccc/kvm_guest: Enable errata based on implementation CPUs (git-fixes)
  - commit cca968d
  - arm64: Make  _midr_in_range_list() an exported function (git-fixes)
  - commit 27f4bc5
  - arm64: Modify _midr_range() functions to read MIDR/REVIDR internally (git-fixes)
  - commit 52f11f0
  - arm64: cpufeature: Handle NV_frac as a synonym of NV2 (git-fixes)
  - commit 1c65e7c
  - nvme: avoid creating multipath sysfs group under namespace
    path devices (git-fixes).
  - nvmet: pci-epf: clear completion queue IRQ flag on delete
    (git-fixes).
  - nvme-pci: acquire cq_poll_lock in nvme_poll_irqdisable
    (git-fixes bsc#1223096).
  - nvme-pci: make nvme_pci_npages_prp() __always_inline
    (git-fixes).
  - nvmet-auth: always free derived key data (git-fixes).
  - nvmet-tcp: don't restore null sk_state_change (git-fixes).
  - nvme-pci: add quirks for WDC Blue SN550 15b7:5009 (git-fixes).
  - nvme-pci: add quirks for device 126f:1001 (git-fixes).
  - commit 4e0829c
  - Remove debug flavor (bsc#1243919).
  - commit ddb9b4c
  - rpm/check-for-config-changes: add more to IGNORED_CONFIGS_RE
    Useful when someone tries (needs) to build the kernel with clang.
  - commit 06918e3
  - Squashfs: check return result of sb_min_blocksize (git-fixes).
  - commit 2e52086
  - powerpc/pseries/iommu: Fix kmemleak in TCE table userspace view
    (jsc#PED-10539 git-fixes).
  - commit 4182148
  - RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work (git-fixes)
  - commit a0be830
  - RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (git-fixes)
  - commit 0ac05e4
  - RDMA/mlx5: Fix error flow upon firmware failure for RQ destruction (git-fixes)
  - commit f3c40d5
  - IB/cm: Drop lockdep assert and WARN when freeing old msg (git-fixes)
  - commit a7456d7
  - RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h (git-fixes)
  - commit 7f90606
  - RDMA/rxe: Fix "trying to register non-static key in rxe_qp_do_cleanup" bug (git-fixes)
  - commit a59c563
  - IB/cm: use rwlock for MAD agent lock (git-fixes)
  - commit c06f30d
  - fix a couple of races in MNT_TREE_BENEATH handling by
    do_move_mount() (bsc#1243521 CVE-2025-37988).
  - commit e9c9973

++++ kernel-rt:

  - kABI: net: page_pool: avoid false positive warning if NAPI
    was never added (git-fixes).
  - commit 06adb55
  - smb: cached directories can be more than root file handle
    (git-fixes).
  - commit afb4d0b
  - smb: client: remove unnecessary checks in open_cached_dir()
    (git-fixes).
  - commit a9818f2
  - smb: client: change return value in open_cached_dir_by_dentry()
    if !cfids (git-fixes).
  - commit 3994f63
  - smb: client: Avoid race in open_cached_dir with lease breaks
    (CVE-2025-37954 bsc#1243664).
  - commit af201ef
  - KVM: arm64: Specify hypercall ABI for retrieving target (git-fixes)
  - commit 5a6faf6
  - KVM: PPC: Book3S HV: Fix IRQ map warnings with XICS on pSeries
    KVM Guest (bsc#1242205 ltc#212592).
  - commit d1b31ab
  - arm64: errata: Work around AmpereOne's erratum AC04_CPU_23 (git-fixes)
    Enable workaround for this errata and remove one slot of kABI
    preservation list.
  - commit 0a959f3
  - KVM: arm64: Force HCR_EL2.xMO to 1 at all times in VHE mode (git-fixes)
  - commit 92b45e1
  - arm64: sysreg: Add layout for ICH_HCR_EL2 (git-fixes)
  - commit 10c80f5
  - objtool, panic: Disable SMAP in __stack_chk_fail()
    (bsc#1243963).
  - commit 1d39035
  - net: stmmac: Fix accessing freed irq affinity_hint (CVE-2025-23155 bsc#1242573)
  - commit b63c5f4
  - memblock: Accept allocated memory before use in
    memblock_double_array() (CVE-2025-37960 bsc#1243519).
  - commit 754095c
  - mm/huge_memory: fix dereferencing invalid pmd migration entry
    (CVE-2025-37958 bsc#1243539).
  - commit 675ffa4
  - dm: restrict dm device size to 2^63-512 bytes (git-fixes).
  - commit ae2ce2b
  - dm cache: prevent BUG_ON by blocking retries on failed device
    resumes (git-fixes).
  - commit d254a94
  - dm: fix unconditional IO throttle caused by REQ_PREFLUSH
    (git-fixes).
  - commit fec8e9d
  - dm vdo indexer: prevent unterminated string warning (git-fixes).
  - commit 379a5f2
  - dm vdo: use a short static string for thread name prefix
    (git-fixes).
  - commit 8084a50
  - net_sched: sch_sfq: move the limit validation (CVE-2025-37752 bsc#1242504)
  - commit c353024
  - net: lwtunnel: disable BHs when required (git-fixes).
  - commit 304c8c4
  - mmc: sdhci-of-dwcmshc: add PD workaround on RK3576 (git-fixes).
  - commit 19be083
  - mmc: sdhci-msm: fix dev reference leaked through of_qcom_ice_get
    (git-fixes).
  - commit e8bf316
  - mmc: host: Wait for Vdd to settle on card power off (git-fixes).
  - commit 6799785
  - mmc: dw_mmc: add exynos7870 DW MMC support (git-fixes).
  - commit 2d642c3
  - mmc: sdhci: Disable SD card clock before changing parameters
    (git-fixes).
  - commit eab27bb
  - platform/x86/intel/pmc: Fix Arrow Lake U/H NPU PCI ID
    (git-fixes).
  - commit 2916acb
  - platform/x86: dell-wmi-sysman: Avoid buffer overflow in
    current_password_store() (git-fixes).
  - commit d257f90
  - platform/x86: ideapad-laptop: add support for some new buttons
    (git-fixes).
  - commit 1e3c868
  - platform/x86: asus-wmi: Disable OOBE state after resume from
    hibernation (git-fixes).
  - commit c9e24c6
  - platform/x86/intel: hid: Add Pantherlake support (git-fixes).
  - commit 460cc0c
  - Input: synaptics-rmi - fix crash with unsupported versions of
    F34 (git-fixes).
  - commit b62a334
  - Input: xpad - add more controllers (git-fixes).
  - commit b79f69c
  - Input: xpad - fix xpad_device sorting (git-fixes).
  - commit 46af804
  - Input: xpad - add support for several more controllers
    (git-fixes).
  - commit ab01d4f
  - arm64/sysreg: Expose MTE_frac so that it is visible to KVM (git-fixes)
  - commit 53f8737
  - arm64/cpuinfo: only show one cpu's info in c_show() (git-fixes)
  - commit c7e06a7
  - arm64/mm: Batch barriers when updating kernel mappings (git-fixes)
  - commit 133d7c0
  - arm64/cpufeature: Add missing id_aa64mmfr4 feature reg update (git-fixes)
  - commit 0d85371
  - arm64: Rework checks for broken Cavium HW in the PI code (git-fixes)
  - commit 589c17e
  - arm64: Add support for HIP09 Spectre-BHB mitigation (git-fixes)
  - commit f8ba796
  - arm64: topology: Support SMT control on ACPI based system (git-fixes)
  - commit 48b6d40
  - kABI: ipv6: save dontfrag in cork (git-fixes).
    Patch-up the kABI change with an #ifdef __GENKSYMS__. This change is
    safe (as detailed in the patch commit message) due to the struct
    having a 6-byte hole at the end we can use.
  - commit c19b923
  - ipv6: save dontfrag in cork (git-fixes).
  - commit f07ae24
  - tcp: bring back NUMA dispersion in inet_ehash_locks_alloc()
    (git-fixes).
  - commit 3096e43
  - net: page_pool: avoid false positive warning if NAPI was never
    added (git-fixes).
  - commit 13d3621
  - ipv4: ip_gre: Fix set but not used warning in ipgre_err()
    if IPv4-only (git-fixes).
  - commit e7bb54c
  - net: flush_backlog() small changes (git-fixes).
  - commit db8d6de
  - kABI: net: lwtunnel: fix recursion loops (git-fixes).
  - commit 0d4c30c
  - arm64/mm: Define PTDESC_ORDER (git-fixes)
  - commit fe6a508
  - arm64/kernel: Always use level 2 or higher for early mappings (git-fixes)
  - commit c847735
  - arm64/sysreg: Rename POE_RXW to POE_RWX (git-fixes)
  - commit 81d3162
  - arm64/sysreg: Improve PIR/POR helpers (git-fixes)
  - commit 8cac771
  - smccc/kvm_guest: Enable errata based on implementation CPUs (git-fixes)
  - commit cca968d
  - arm64: Make  _midr_in_range_list() an exported function (git-fixes)
  - commit 27f4bc5
  - arm64: Modify _midr_range() functions to read MIDR/REVIDR internally (git-fixes)
  - commit 52f11f0
  - arm64: cpufeature: Handle NV_frac as a synonym of NV2 (git-fixes)
  - commit 1c65e7c
  - nvme: avoid creating multipath sysfs group under namespace
    path devices (git-fixes).
  - nvmet: pci-epf: clear completion queue IRQ flag on delete
    (git-fixes).
  - nvme-pci: acquire cq_poll_lock in nvme_poll_irqdisable
    (git-fixes bsc#1223096).
  - nvme-pci: make nvme_pci_npages_prp() __always_inline
    (git-fixes).
  - nvmet-auth: always free derived key data (git-fixes).
  - nvmet-tcp: don't restore null sk_state_change (git-fixes).
  - nvme-pci: add quirks for WDC Blue SN550 15b7:5009 (git-fixes).
  - nvme-pci: add quirks for device 126f:1001 (git-fixes).
  - commit 4e0829c
  - Remove debug flavor (bsc#1243919).
  - commit ddb9b4c
  - rpm/check-for-config-changes: add more to IGNORED_CONFIGS_RE
    Useful when someone tries (needs) to build the kernel with clang.
  - commit 06918e3
  - Squashfs: check return result of sb_min_blocksize (git-fixes).
  - commit 2e52086
  - powerpc/pseries/iommu: Fix kmemleak in TCE table userspace view
    (jsc#PED-10539 git-fixes).
  - commit 4182148
  - RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work (git-fixes)
  - commit a0be830
  - RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (git-fixes)
  - commit 0ac05e4
  - RDMA/mlx5: Fix error flow upon firmware failure for RQ destruction (git-fixes)
  - commit f3c40d5
  - IB/cm: Drop lockdep assert and WARN when freeing old msg (git-fixes)
  - commit a7456d7
  - RDMA/hns: Include hnae3.h in hns_roce_hw_v2.h (git-fixes)
  - commit 7f90606
  - RDMA/rxe: Fix "trying to register non-static key in rxe_qp_do_cleanup" bug (git-fixes)
  - commit a59c563
  - IB/cm: use rwlock for MAD agent lock (git-fixes)
  - commit c06f30d
  - fix a couple of races in MNT_TREE_BENEATH handling by
    do_move_mount() (bsc#1243521 CVE-2025-37988).
  - commit e9c9973

++++ ncurses:

  - Add ncurses patch 20250531
    + improve logic in misc/run_tic.in for constructing symbolic link
    when $DESTDIR is set.

++++ rpm:

  - use the pubkey modification time instead of the creation time
    as the release number, as it was with older rpm versions
    * new patch: pgpreleasemtime.diff

++++ systemd:

  - Import commit c929295b4c1fb3cd6b9963bc7588fbc3e597ab86 (merge of v257.6)
    This merge includes the following fix:
    c58a8a6ec9 coredump: use %d in kernel core pattern (bsc#1243935 CVE-2025-4598)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/8e9840a2897e36ae3f926f8d10a2b0d7e4102c67...c929295b4c1fb3cd6b9963bc7588fbc3e597ab86

++++ libzypp:

  - Do not warn about no mirrors if mirrorlist was switched on
    automatically. (bsc#1243901)
  - Relax permission of cached packages to 0644 & ~umask
    (bsc#1243887)
  - version 17.37.3 (35)

++++ tuned:

  - Fix newlines in changelog

------------------------------------------------------------------
------------------  2025-6-1  -  Jun 1 2025  -------------------
------------------------------------------------------------------

++++ gstreamer-plugins-base:

  - Update to version 1.26.2:
    + alsa: Avoid infinite loop in DSD rate detection
    + gl: Implement basetransform meta transform function
    + glshader: free shader on stop
    + glupload: Only add texture-target field to GL caps
    + gstaudioutilsprivate: Fix gcc 15 compiler error with function
    pointer
    + mikey: Avoid infinite loop while parsing MIKEY payload with
    unhandled payload types
    + properties: add G_PARAM_STATIC_STRINGS where missing
    + riff-media: fix MS and DVI ADPCM av_bps calculations
    + subtitleoverlay: Remove 0.10 hardware caps handling
    + subtitleoverlay: Missing support for DMABuf(?)
    + tests: opus: Update channel support and add to meson
    + textoverlay: fix shading for RGBx / RGBA pixel format variants
    + textoverlay background is wrong while cropping
    + uridecodebin3: Don't hold play items lock while releasing pads
    + uridecodebin3: deadlock on PLAY_ITEMS_LOCK
    + Fix new warnings on Fedora 42, various meson warnings, and
    other small meson build/wrap fixes
    + Fix Qt detection in various places

++++ ceph:

  - Update to 18.2.7 (Reef):
    + RADOS
    * FileStore is not supported in Reef.
    * RocksDB has been upgraded to version 7.9.2.
    * There have been significant improvements to RocksDB iteration overhead
    and performance.
    * The `perf dump` and `perf schema` commands have been deprecated in favor
    of the new `counter dump` and `counter schema` commands.
    * Cache tiering is now deprecated.
    * A new feature, the "read balancer", is now available, which allows users
    to balance primary PGs per pool on their clusters.
    * A POOL_APP_NOT_ENABLED health warning will now be reported if the
    application is not enabled for the pool whether the pool is in use or
    not.
    * The get_pool_is_selfmanaged_snaps_mode C++ API has been deprecated due
    to being prone to false negative results. Its safer replacement is
    pool_is_in_selfmanaged_snaps_mode.
    * A new command, `ceph osd rm-pg-upmap-primary-all`, has been added that
    allows users to clear all pg-upmap-primary mappings in the osdmap when
    desired.
    * A bug related to IPv6 support is now fixed.
    + RGW
    * Bucket resharding is now supported for multi-site configurations.
    * There have been significant improvements to the stability and
    consistency of multi-site replication.
    * Compression is now supported for objects uploaded with Server-Side
    Encryption.
    * S3 multipart uploads using Server-Side Encryption now replicate
    correctly in a multi-site deployment.
    * New tools have been added to `radosgw-admin` for identifying and
    correcting issues with versioned bucket indexes.
    + Dashboard
    * There is a new Dashboard page with improved layout. Active alerts and
    some important charts are now displayed inside cards.
    * An overview page for RGW to show the overall status of RGW components.
    * Added management support for RGW Multi-site and CephFS Subvolumes and
    groups.
    * Fixed several issues in Ceph dashboard on Rook-backed clusters, and
    improved the user experience on the Rook environment.
    + RBD
    * Support for layered client-side encryption has been added.
    * When diffing against the beginning of time (fromsnapname == NULL) in
    fast-diff mode (whole_object == true with fast-diff image feature
    enabled and valid), diff-iterate is now guaranteed to execute locally if
    exclusive lock is available. This brings a dramatic performance
    improvement for QEMU live disk synchronization and backup use cases.
    * The option --image-id has been added to `rbd children` CLI command, so
    it can be run for images in the trash.
    * The try-netlink mapping option for rbd-nbd has become the default and is
    now deprecated.
    + Telemetry
    * Users can now opt in to participate in a leaderboard in the telemetry
    public dashboards.
    + CEPHFS
    * MDS now evicts clients which are not advancing their request tids.
    + mgr
    * For clusters with multiple CephFS file systems, all the snap-schedule
    commands now expect the ‘--fs’ argument.
    * Refine the orchestrator availability check to prevent against crashes in
    the prometheus module during startup.
    + ceph-volume
    * A bug related to cryptsetup version handling has been fixed.
  - Switched to managing the spec directly with a pristine source and set of
    patches
  - Removed ceph-test
  - Removed checkin scripts
  - Added ceph-mgr-stop-using-deprecated-api-to-initialize-python.patch
  - Added ceph-mgr-set-argv-for-python.patch
  - Added ceph-mgr-add-site-packages-paths.patch
  - Added ceph-librbd-fix-atomic-shared-pointer.patch
  - Added ceph-cmake-ensure-git-exists-before-executing-it.patch
  - Added ceph-build-fix-fmt-version-check.patch
  - Added ceph-tracing-fix-c-type-errors-in-librados-tracing.patch
  - Added ceph-pybind-fix-c-type-errors-in-cython-generated-python-bindings.patch

------------------------------------------------------------------
------------------  2025-5-31  -  May 31 2025  -------------------
------------------------------------------------------------------

++++ gstreamer:

  - Update to version 1.26.2:
    + Highlighted bugfixes:
  - Various security fixes and playback fixes
  - aggregator base class fixes to not produce buffers too early
    in live mode
  - AWS translate element improvements
  - D3D12 video decoder workarounds for crashes on NVIDIA cards
    on resolution changes
  - dav1d AV1-decoder performance improvements
  - fmp4mux: tfdt and composition time offset fixes, plus AC-3 /
    EAC-3 audio support
  - GStreamer editing services fixes for sources with non-1:1
    aspect ratios
  - MIDI parser improvements for tempo changes
  - MP4 demuxer atom parsing improvements and security fixes
  - New skia-based video compositor element
  - Subtitle parser security fixes
  - Subtitle rendering and seeking fixes
  - Playbin3 and uridecodebin3 stability fixes
  - GstPlay stream selection improvements
  - WAV playback regression fix
  - GTK4 paintable sink colorimetry support and other
    improvements
  - WebRTC: allow webrtcsrc to wait for a webrtcsink producer to
    initiate the connection
  - WebRTC: new Janus Video Room WebRTC source element
  - vah264enc profile decision making logic fixes
  - Python bindings gained support for handling mini object
    writability (buffers, caps, etc.)
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - aggregator: Various state related fixes
  - element: ref-sink the correct pad template when replacing an
    existing one
  - pipeline: Store the actual latency even if no static latency
    was configured
  - structure: Add gst_structure_is_writable() API to allow
    python bindings to be able to handle writability of
    MiniObjects
  - tracerutils: Do not warn on empty string as tracername
  - tracerutils: Fix leak in gst_tracer_utils_create_tracer()
  - Ensure properties are freed before (re)setting with
    g_value_dup_object() or g_value_dup_boxed() and during
    cleanup
  - Fix new warnings on Fedora 42, various meson warnings, and
    other small meson build/wrap fixes

++++ kernel-default:

  - perf/x86/intel: Fix segfault with PEBS-via-PT with sample_freq
    (git-fixes).
  - perf/x86/intel: Only check the group flag for X86 leader
    (git-fixes).
  - perf/x86: Fix non-sampling (counting) events on certain x86
    platforms (git-fixes).
  - perf/x86/intel: Allow to update user space GPRs from PEBS
    records (git-fixes).
  - perf/x86/intel/uncore: Fix the scale of IIO free running
    counters on SPR (git-fixes).
  - perf/x86/intel/uncore: Fix the scale of IIO free running
    counters on ICX (git-fixes).
  - perf/x86/intel/uncore: Fix the scale of IIO free running
    counters on SNR (git-fixes).
  - perf tools: Remove evsel__handle_error_quirks() (git-fixes).
  - perf tools: Fix up some comments and code to properly use the
    event_source bus (git-fixes).
  - commit 2275c01

++++ kernel-rt:

  - perf/x86/intel: Fix segfault with PEBS-via-PT with sample_freq
    (git-fixes).
  - perf/x86/intel: Only check the group flag for X86 leader
    (git-fixes).
  - perf/x86: Fix non-sampling (counting) events on certain x86
    platforms (git-fixes).
  - perf/x86/intel: Allow to update user space GPRs from PEBS
    records (git-fixes).
  - perf/x86/intel/uncore: Fix the scale of IIO free running
    counters on SPR (git-fixes).
  - perf/x86/intel/uncore: Fix the scale of IIO free running
    counters on ICX (git-fixes).
  - perf/x86/intel/uncore: Fix the scale of IIO free running
    counters on SNR (git-fixes).
  - perf tools: Remove evsel__handle_error_quirks() (git-fixes).
  - perf tools: Fix up some comments and code to properly use the
    event_source bus (git-fixes).
  - commit 2275c01

------------------------------------------------------------------
------------------  2025-5-30  -  May 30 2025  -------------------
------------------------------------------------------------------

++++ avahi:

  - Add patch submitted to upstream at
    to enable building with Qt6 and add that flavor:
    0001-Enable-building-with-Qt6.patch
  - Disable building the Qt5 flavor in SLE16.

++++ docker:

  - Update to Docker 28.2.2-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2822>
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  - Update to Docker 28.2.1-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2820> bsc#1243833
    <https://github.com/moby/moby/releases/tag/v28.2.1>
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

++++ kernel-default:

  - erofs: initialize decompression early (git-fixes).
  - commit 2d8813f
  - pstore: Change kmsg_bytes storage size to u32 (git-fixes).
  - commit 6956b60
  - exfat: call bh_read in get_block only when necessary
    (git-fixes).
  - commit 7dd637f
  - NFSv4: Check for delegation validity in
    nfs_start_delegation_return_locked() (git-fixes).
  - commit 418b04a
  - NFS: Don't allow waiting for exiting tasks (git-fixes).
  - Refresh
    patches.suse/nfs-add-missing-selections-of-CONFIG_CRC32.patch.
  - commit bba0843
  - SUNRPC: Don't allow waiting for exiting tasks (git-fixes).
  - commit 66f99da
  - NFSv4: Treat ENETUNREACH errors as fatal for state recovery
    (git-fixes).
  - commit 9c48276
  - SUNRPC: rpc_clnt_set_transport() must not change the autobind
    setting (git-fixes).
  - commit 3c4ee4b
  - SUNRPC: rpcbind should never reset the port to the value '0'
    (git-fixes).
  - commit 754a098
  - pNFS/flexfiles: Report ENETDOWN as a connection error
    (git-fixes).
  - commit 3294f72
  - iommu/mediatek: Fix NULL pointer deference in
    mtk_iommu_device_group (CVE-2025-37748 bsc#1242523).
  - commit 6ffeaed
  - arm64/fpsimd: Make clone() compatible with ZA lazy saving (git-fixes)
  - commit 958752f
  - kABI: update definitions after genksyms update
    Restore arm64 kABI definitions as following patch fixed genksyms issue:
    https://lore.kernel.org/linux-kbuild/20250527142318.14175-1-petr.pavlu@suse.com/
  - commit 0244242
  - arm64/fpsimd: signal: Consistently read FPSIMD context (git-fixes)
  - commit 58794fb
  - arm64/fpsimd: signal: Simplify preserve_tpidr2_context() (git-fixes)
  - commit 6c25a15
  - hypfs_create_cpu_files(): add missing check for hypfs_mkdir()
    failure (git-fixes bsc#1243839).
  - s390/tlb: Use mm_has_pgste() instead of mm_alloc_pgste()
    (git-fixes bsc#1243840).
  - commit cd720c1
  - cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()
    (bsc#1242875 CVE-2025-37829).
  - commit 48ff1cf
  - cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate()
    (bsc#1242860 CVE-2025-37830).
  - commit c157f2a
  - arm64/fpsimd: ptrace: Gracefully handle errors (git-fixes)
  - commit 4628747
  - arm64/fpsimd: ptrace: Mandate SVE payload for streaming-mode state (git-fixes)
  - commit fc027c7
  - arm64/fpsimd: ptrace: Do not present register data for inactive mode (git-fixes)
  - commit a5f9b46
  - arm64/fpsimd: ptrace: Save task state before generating SVE header (git-fixes)
  - commit 5fbb1e4
  - arm64/fpsimd: Clear PSTATE.SM during clone() (git-fixes)
  - commit 7019526
  - arm64/fpsimd: Consistently preserve FPSIMD state during clone() (git-fixes)
  - commit 3571c11
  - arm64/fpsimd: Remove redundant task->mm check (git-fixes)
  - commit 18353bd
  - arm64/fpsimd: signal: Use SMSTOP behaviour in setup_return() (git-fixes)
  - commit 7171c52
  - arm64/fpsimd: signal: Mandate SVE payload for streaming-mode state (git-fixes)
  - commit 8081e49
  - arm64/fpsimd: signal: Clear PSTATE.SM when restoring FPSIMD frame (git-fixes)
  - commit c18043d
  - arm64/fpsimd: signal: Clear TPIDR2 when delivering signals (git-fixes)
  - commit b7319ad
  - arm64/fpsimd: signal32: Always save+flush state early (git-fixes)
  - commit 2c12b65
  - arm64/fpsimd: ptrace/prctl: Ensure VL changes leave task in a valid (git-fixes)
  - commit eee117a
  - arm64/fpsimd: ptrace/prctl: Ensure VL changes do not resurrect stale (git-fixes)
  - commit 6fdd7ce
  - arm64/fpsimd: Add task_smstop_sm() (git-fixes)
  - commit 2b4d7f8
  - arm64/fpsimd: Factor out {sve,sme}_state_size() helpers (git-fixes)
  - commit 75d2e8f
  - arm64/fpsimd: Clarify sve_sync_*() functions (git-fixes)
  - commit b1c77e1
  - arm64/fpsimd: ptrace: Consistently handle partial writes to (git-fixes)
  - commit e488352
  - arm64/fpsimd: Do not discard modified SVE state (git-fixes)
  - commit 399b562
  - arm64/fpsimd: Avoid warning when sve_to_fpsimd() is unused (git-fixes)
  - commit 970f616
  - arm64/fpsimd: Avoid unnecessary per-CPU buffers for EFI runtime calls (git-fixes)
  - commit b6b5636
  - arm64/fpsimd: signal: Always save+flush state early (git-fixes)
  - commit 03d771f
  - arm64/fpsimd: Add fpsimd_save_and_flush_current_state() (git-fixes)
  - commit 5b8e5fb
  - arm64/fpsimd: Fix merging of FPSIMD state during signal return (git-fixes)
  - commit dbab629
  - arm64/fpsimd: Reset FPMR upon exec() (git-fixes)
  - commit 8dda200
  - arm64/fpsimd: Avoid clobbering kernel FPSIMD state with SMSTOP (git-fixes)
  - commit c32fbdc
  - arm64/fpsimd: Don't corrupt FPMR when streaming mode changes (git-fixes)
  - commit 6a5279e
  - arm64/fpsimd: Discard stale CPU state when handling SME traps (git-fixes)
  - commit afd7c13
  - arm64/fpsimd: Remove opportunistic freeing of SME state (git-fixes)
  - commit 017ab7e
  - arm64/fpsimd: Remove redundant SVE trap manipulation (git-fixes)
  - commit 88e70b0
  - arm64/fpsimd: Remove unused fpsimd_force_sync_to_sve() (git-fixes)
  - commit ec25502
  - arm64/fpsimd: Avoid RES0 bits in the SME trap handler (git-fixes)
  - commit 0d0c04f

++++ kernel-rt:

  - erofs: initialize decompression early (git-fixes).
  - commit 2d8813f
  - pstore: Change kmsg_bytes storage size to u32 (git-fixes).
  - commit 6956b60
  - exfat: call bh_read in get_block only when necessary
    (git-fixes).
  - commit 7dd637f
  - NFSv4: Check for delegation validity in
    nfs_start_delegation_return_locked() (git-fixes).
  - commit 418b04a
  - NFS: Don't allow waiting for exiting tasks (git-fixes).
  - Refresh
    patches.suse/nfs-add-missing-selections-of-CONFIG_CRC32.patch.
  - commit bba0843
  - SUNRPC: Don't allow waiting for exiting tasks (git-fixes).
  - commit 66f99da
  - NFSv4: Treat ENETUNREACH errors as fatal for state recovery
    (git-fixes).
  - commit 9c48276
  - SUNRPC: rpc_clnt_set_transport() must not change the autobind
    setting (git-fixes).
  - commit 3c4ee4b
  - SUNRPC: rpcbind should never reset the port to the value '0'
    (git-fixes).
  - commit 754a098
  - pNFS/flexfiles: Report ENETDOWN as a connection error
    (git-fixes).
  - commit 3294f72
  - iommu/mediatek: Fix NULL pointer deference in
    mtk_iommu_device_group (CVE-2025-37748 bsc#1242523).
  - commit 6ffeaed
  - arm64/fpsimd: Make clone() compatible with ZA lazy saving (git-fixes)
  - commit 958752f
  - kABI: update definitions after genksyms update
    Restore arm64 kABI definitions as following patch fixed genksyms issue:
    https://lore.kernel.org/linux-kbuild/20250527142318.14175-1-petr.pavlu@suse.com/
  - commit 0244242
  - arm64/fpsimd: signal: Consistently read FPSIMD context (git-fixes)
  - commit 58794fb
  - arm64/fpsimd: signal: Simplify preserve_tpidr2_context() (git-fixes)
  - commit 6c25a15
  - hypfs_create_cpu_files(): add missing check for hypfs_mkdir()
    failure (git-fixes bsc#1243839).
  - s390/tlb: Use mm_has_pgste() instead of mm_alloc_pgste()
    (git-fixes bsc#1243840).
  - commit cd720c1
  - cpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()
    (bsc#1242875 CVE-2025-37829).
  - commit 48ff1cf
  - cpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate()
    (bsc#1242860 CVE-2025-37830).
  - commit c157f2a
  - arm64/fpsimd: ptrace: Gracefully handle errors (git-fixes)
  - commit 4628747
  - arm64/fpsimd: ptrace: Mandate SVE payload for streaming-mode state (git-fixes)
  - commit fc027c7
  - arm64/fpsimd: ptrace: Do not present register data for inactive mode (git-fixes)
  - commit a5f9b46
  - arm64/fpsimd: ptrace: Save task state before generating SVE header (git-fixes)
  - commit 5fbb1e4
  - arm64/fpsimd: Clear PSTATE.SM during clone() (git-fixes)
  - commit 7019526
  - arm64/fpsimd: Consistently preserve FPSIMD state during clone() (git-fixes)
  - commit 3571c11
  - arm64/fpsimd: Remove redundant task->mm check (git-fixes)
  - commit 18353bd
  - arm64/fpsimd: signal: Use SMSTOP behaviour in setup_return() (git-fixes)
  - commit 7171c52
  - arm64/fpsimd: signal: Mandate SVE payload for streaming-mode state (git-fixes)
  - commit 8081e49
  - arm64/fpsimd: signal: Clear PSTATE.SM when restoring FPSIMD frame (git-fixes)
  - commit c18043d
  - arm64/fpsimd: signal: Clear TPIDR2 when delivering signals (git-fixes)
  - commit b7319ad
  - arm64/fpsimd: signal32: Always save+flush state early (git-fixes)
  - commit 2c12b65
  - arm64/fpsimd: ptrace/prctl: Ensure VL changes leave task in a valid (git-fixes)
  - commit eee117a
  - arm64/fpsimd: ptrace/prctl: Ensure VL changes do not resurrect stale (git-fixes)
  - commit 6fdd7ce
  - arm64/fpsimd: Add task_smstop_sm() (git-fixes)
  - commit 2b4d7f8
  - arm64/fpsimd: Factor out {sve,sme}_state_size() helpers (git-fixes)
  - commit 75d2e8f
  - arm64/fpsimd: Clarify sve_sync_*() functions (git-fixes)
  - commit b1c77e1
  - arm64/fpsimd: ptrace: Consistently handle partial writes to (git-fixes)
  - commit e488352
  - arm64/fpsimd: Do not discard modified SVE state (git-fixes)
  - commit 399b562
  - arm64/fpsimd: Avoid warning when sve_to_fpsimd() is unused (git-fixes)
  - commit 970f616
  - arm64/fpsimd: Avoid unnecessary per-CPU buffers for EFI runtime calls (git-fixes)
  - commit b6b5636
  - arm64/fpsimd: signal: Always save+flush state early (git-fixes)
  - commit 03d771f
  - arm64/fpsimd: Add fpsimd_save_and_flush_current_state() (git-fixes)
  - commit 5b8e5fb
  - arm64/fpsimd: Fix merging of FPSIMD state during signal return (git-fixes)
  - commit dbab629
  - arm64/fpsimd: Reset FPMR upon exec() (git-fixes)
  - commit 8dda200
  - arm64/fpsimd: Avoid clobbering kernel FPSIMD state with SMSTOP (git-fixes)
  - commit c32fbdc
  - arm64/fpsimd: Don't corrupt FPMR when streaming mode changes (git-fixes)
  - commit 6a5279e
  - arm64/fpsimd: Discard stale CPU state when handling SME traps (git-fixes)
  - commit afd7c13
  - arm64/fpsimd: Remove opportunistic freeing of SME state (git-fixes)
  - commit 017ab7e
  - arm64/fpsimd: Remove redundant SVE trap manipulation (git-fixes)
  - commit 88e70b0
  - arm64/fpsimd: Remove unused fpsimd_force_sync_to_sve() (git-fixes)
  - commit ec25502
  - arm64/fpsimd: Avoid RES0 bits in the SME trap handler (git-fixes)
  - commit 0d0c04f

++++ gcc15:

  - Enable C++ for offload compilers.  [bsc#1243794]

++++ python-rich:

  - Update to 14.0.0
    * Added
  - Added env var TTY_COMPATIBLE to override auto-detection of TTY
    support (See console.rst for details). #3675
    * Changed
  - An empty NO_COLOR env var is now considered disabled. #3675
  - An empty FORCE_COLOR env var is now considered disabled. #3675
  - Rich tracebacks will now render notes on Python 3.11 onwards
    (added with Exception.add_note) #3676
  - Indentation in exceptions won't be underlined #3678
  - Rich tracebacks will now render Exception Groups #3677

++++ sevctl:

  - Update to version 0.6.2:
    * Bump version to 0.6.2
    * Update sev dependency to 6.0.0
    * build: use io::Error::other to make clippy happy
    * Fix ownership in flags loop
    * validate: change parameters, now accept a full cert chain
    * Updated Ok to include support for all current proccessors. (#204)
    * Update to 0.6.0
    * session: Use anyhow macro for error return
    * Update sev crate to 4.0.0
    * secret: Use From::from conversion

++++ wpa_supplicant:

  - Remove support for WEP authentication (jsc#PED-12955)

------------------------------------------------------------------
------------------  2025-5-29  -  May 29 2025  -------------------
------------------------------------------------------------------

++++ cryptsetup:

  - Add a dependency on device-mapper to libcryptsetup12 to install
    the required device-mapper udev rules. [bsc#1241612]

++++ grub2:

  - Use /etc/SUSE-brand to display OS label (bsc#1239169)
    * 0001-mkconfig-Determine-GRUB_DISTRIBUTOR-from-etc-SUSE-br.patch

++++ kernel-default:

  - io_uring/net: fix io_req_post_cqe abuse by send bundle
    (CVE-2025-23154 bsc#1242533).
  - commit 2870613
  - mtd: phram: Add the kernel lock down check (bsc#1232649).
  - commit 984e9a9
  - io_uring: always do atomic put from iowq (CVE-2025-37804
    bsc#1242854).
  - commit cd0bf60
  - s390/bpf: Store backchain even for leaf progs (git-fixes
    bsc#1243803).
  - commit d2e89ff
  - cpufreq: apple-soc: Fix null-ptr-deref in
    apple_soc_cpufreq_get_rate() (bsc#1242861 CVE-2025-37831).
  - commit bb8e639
  - selftests/mm: vm_util: split up /proc/self/smaps parsing
    (bsc#1243354 ltc#213242).
  - commit e8e0348
  - svcrdma: Reduce the number of rdma_rw contexts per-QP
    (git-fixes).
  - commit 978dec2
  - svcrdma: Unregister the device if svc_rdma_accept() fails
    (git-fixes).
  - commit 8ddd85f
  - nfsd: Initialize ssc before laundromat_work to prevent NULL
    dereference (git-fixes).
  - commit a2f7bec
  - NFSD: unregister filesystem in case genl_register_family()
    fails (git-fixes).
  - commit f290746
  - mm: memory-failure: enhance comments for return value of
    memory_failure() (CVE-2022-49145 bsc#1238162).
  - commit 2586946
  - mm/hwpoison: do not send SIGBUS to processes with recovered
    clean pages (CVE-2022-49145 bsc#1238162).
  - commit ac8ff11
  - x86/mce: use is_copy_from_user() to determine copy-from-user
    context (CVE-2025-39989 bsc#1241629).
  - commit 4cc844d
  - perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init
    (bsc#1243235 CVE-2025-37878).
  - commit ee25a1b

++++ kernel-rt:

  - io_uring/net: fix io_req_post_cqe abuse by send bundle
    (CVE-2025-23154 bsc#1242533).
  - commit 2870613
  - mtd: phram: Add the kernel lock down check (bsc#1232649).
  - commit 984e9a9
  - io_uring: always do atomic put from iowq (CVE-2025-37804
    bsc#1242854).
  - commit cd0bf60
  - s390/bpf: Store backchain even for leaf progs (git-fixes
    bsc#1243803).
  - commit d2e89ff
  - cpufreq: apple-soc: Fix null-ptr-deref in
    apple_soc_cpufreq_get_rate() (bsc#1242861 CVE-2025-37831).
  - commit bb8e639
  - selftests/mm: vm_util: split up /proc/self/smaps parsing
    (bsc#1243354 ltc#213242).
  - commit e8e0348
  - svcrdma: Reduce the number of rdma_rw contexts per-QP
    (git-fixes).
  - commit 978dec2
  - svcrdma: Unregister the device if svc_rdma_accept() fails
    (git-fixes).
  - commit 8ddd85f
  - nfsd: Initialize ssc before laundromat_work to prevent NULL
    dereference (git-fixes).
  - commit a2f7bec
  - NFSD: unregister filesystem in case genl_register_family()
    fails (git-fixes).
  - commit f290746
  - mm: memory-failure: enhance comments for return value of
    memory_failure() (CVE-2022-49145 bsc#1238162).
  - commit 2586946
  - mm/hwpoison: do not send SIGBUS to processes with recovered
    clean pages (CVE-2022-49145 bsc#1238162).
  - commit ac8ff11
  - x86/mce: use is_copy_from_user() to determine copy-from-user
    context (CVE-2025-39989 bsc#1241629).
  - commit 4cc844d
  - perf/core: Fix WARN_ON(!ctx) in __free_event() for partial init
    (bsc#1243235 CVE-2025-37878).
  - commit ee25a1b

++++ util-linux-systemd:

  - Add ul_ prefix to functions with common names. Fixes btrfsprogs
    build failure (gh#util-linux/util-linux#3603,
    util-linux-rename-common-symbols-1.patch,
    util-linux-rename-common-symbols-2.patch,
    util-linux-rename-common-symbols-3.patch,
    util-linux-rename-common-symbols-4.patch).

++++ util-linux:

  - Add ul_ prefix to functions with common names. Fixes btrfsprogs
    build failure (gh#util-linux/util-linux#3603,
    util-linux-rename-common-symbols-1.patch,
    util-linux-rename-common-symbols-2.patch,
    util-linux-rename-common-symbols-3.patch,
    util-linux-rename-common-symbols-4.patch).

++++ libcontainers-common:

  - Sync containers.conf & storage.conf with the current c/* versions
  - Rename storage-conf-prio-list.patch to 0002-storage-conf-prio-list.patch
  - Add patch to set SUSE defaults to containers.conf:
    * 0003-containers-conf-suse-defaults.patch

++++ gpgme:

  - Do not build the qt5 flavor in SLE16 where Qt5 won't be
    available.

++++ openssl-3:

  - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014]
    * Add openssl-Fix-P384-on-P8-targets.patch [a72f753c]

++++ libssh:

  - Fix hang in torture_session test (bsc#1243799)
    * Add patch libssh-tests-Fix-an-issue-where-torture_session-request-a-SIGTERM-too-early.patch

++++ makedumpfile:

  - Update to 1.7.7:
    * Support for kernels up to v6.14 (x86_64)
    * Fix gcc-15 compile errors
    * Improve message readability and fix typos
  - Drop upstreamed patches:
    * makedumpfile-fix-detection-of-typed-compound-pages-Linux-6.12.patch
  - Update bundled eppic to 63c2a2072464d774097a1a6cc1d2e98290f89c49.

++++ pcr-oracle:

  - Update to 0.5.7
    + Support ppc64 events
    + Fix the string comparison for the alternative event
    (bsc#1241957)
  - Add the new BuildRequires: libelf-devel and libfdisk-devel

++++ python-jsonschema:

  - update to 4.24.0:
    * Fix calculation of evaluated properties by @V02460 in #1351
    * Support for Python 3.8 has been dropped, as it is end-of-life.

++++ python-psutil:

  - update to 7.0.0:
    * 669_, [Windows]: `net_if_addrs()`_ also returns the broadcast
    address instead of None.
    * 2480_: Python 2.7 is no longer supported. Latest version
    supporting Python 2.7 is psutil 6.1.X. Install it with: pip2
    install psutil==6.1.*.
    * 2490_: removed long deprecated Process.memory_info_ex()
    method. It was deprecated in psutil 4.0.0, released 8 years
    ago. Substitute is Process.memory_full_info().
    * 2496_, [Linux]: Avoid segfault (a cPython bug) on
    Process.memory_maps() for processes that use hundreds of GBs
    of memory.
    * 2502_, [macOS]: `virtual_memory()`_ now relies on
    host_statistics64 instead of host_statistics. This is the
    same approach used by vm_stat CLI tool, and should grant more
    accurate results.
    * 2480_: Python 2.7 is no longer supported.
    * 2490_: removed long deprecated Process.memory_info_ex()
    method.

------------------------------------------------------------------
------------------  2025-5-28  -  May 28 2025  -------------------
------------------------------------------------------------------

++++ curl:

  - Update to 8.14.0:
    * Security fixes:
  - [CVE-2025-4947, bsc#1243397] QUIC certificate check skip with wolfSSL
  - [CVE-2025-5025, bsc#1243706] No QUIC certificate pinning with wolfSSL
    * Changes:
  - mqtt: send ping at upkeep interval
  - schannel: handle pkcs12 client certificates containing CA certificates
  - TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs
  - vquic: ngtcp2 + openssl support
  - wcurl: import v2025.04.20 script + docs
  - websocket: add option to disable auto-pong reply
    * Bugfixes:
  - asny-thrdd: fix detach from running thread
  - async-threaded resolver: use ref counter
  - async: DoH improvements
  - build: enable gcc-12/13+, clang-10+ picky warnings
  - build: enable gcc-15 picky warnings
  - certs: drop unused `default_bits` from `.prm` files
  - cf-https-connect: use the passed in dns struct pointer
  - cf-socket: fix FTP accept connect
  - cfilters: remove assert
  - cmake: fix nghttp3 static linking with `USE_OPENSSL_QUIC=ON`
  - cmake: prefer `COMPILE_OPTIONS` over `CMAKE_C_FLAGS` for custom C options
  - cmake: revert `CURL_LTO` behavior for multi-config generators
  - configure: fix --disable-rt
  - CONTRIBUTE: add project guidelines for AI use
  - cpool/cshutdown: force close connections under pressure
  - curl: fix memory leak when -h is used in config file
  - curl_get_line: handle lines ending on the buffer boundary
  - headers: enforce a max number of response header to accept
  - http: fix HTTP/2 handling of TE request header using "trailers"
  - lib: include files using known path
  - lib: unify conversions to/from hex
  - libssh: add NULL check for Curl_meta_get()
  - libssh: fix memory leak
  - mqtt: use conn/easy meta hash
  - multi: do transfer book keeping using mid
  - multi: init_do(): check result
  - netrc: avoid NULL deref on weird input
  - netrc: avoid strdup NULL
  - netrc: deal with null token better
  - openssl-quic: avoid potential `-Wnull-dereference`, add assert
  - openssl-quic: fix shutdown when stream not open
  - openssl: enable builds for *both* engines and providers
  - openssl: set the cipher string before doing private cert
  - progress: avoid integer overflow when gathering total transfer size
  - rand: update comment on Curl_rand_bytes weak random
  - rustls: make max size of cert and key reasonable
  - smb: avoid integer overflow on weird input date
  - urlapi: redirecting to "" is considered fine
    * Remove curl-8.13.0-CloseSocket.patch upstream
    * Rebase libcurl-ocloexec.patch

++++ python-kiwi:

  - Fixup overlay unit enablement
  - Fixup overlay mount dependencies
  - Update test-image-overlayroot integration test
    Use proper systemd mount units to setup the custom overlay.
    The handling of fstab entries by systemd is limited and
    should be better handled by self managed mount units
  - Use proper mount units for overlay setup
    Instead of manual mounting create a proper systemd mount
    unit. This allows to manage mount dependencies and the order
    of nested mounts in a clean way

++++ haproxy:

  - Update apparmor profile to allow new cpu binding handling
  - Update to version 3.2.0+git0.e134140d2:
    https://www.haproxy.com/blog/announcing-haproxy-3-2
    https://www.mail-archive.com/haproxy@formilux.org/msg45917.html
    VUL-0: CVE-2025-32464: haproxy: HAProxy 2.2 through 3.1.6, in certain
    uncommon configurations, has a sample_conv_regsub heap-based buffer
    overflow because of mishandling of the replacement of multiple short
    patterns with a longer one. (bsc#1240971)

++++ kernel-default:

  - perf/dwc_pcie: fix duplicate pci_dev devices (CVE-2025-37746 bsc#1242885)
  - commit dea67be
  - perf/dwc_pcie: Qualify RAS DES VSEC Capability by Vendor, Revision (bsc#1242885)
  - commit ffcf22b
  - isofs: Prevent the use of too small fid (CVE-2025-37780 bsc#1242786)
  - commit 5c5ba6b
  - ext4: fix off-by-one error in do_split (CVE-2025-23150 bsc#1242513)
  - commit 0080833
  - net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered (CVE-2025-37787 bsc#1242585)
  - commit 9e7d0f2
  - xfrm: Fix UDP GRO handling for some corner cases (git-fixes).
  - commit 1c0c1c5
  - espintcp: fix skb leaks (git-fixes).
  - commit 15cdb39
  - xsk: Bring back busy polling support in XDP_COPY (git-fixes).
  - commit 6c2f2b4
  - net/tls: fix kernel panic when alloc_page failed (git-fixes).
  - commit 92ec148
  - gre: Fix again IPv6 link-local address generation (git-fixes).
  - commit c3ee537
  - net: lwtunnel: fix recursion loops (git-fixes).
  - commit 9d17465
  - tcp/dccp: allow a connection when sk_max_ack_backlog is zero
    (git-fixes).
  - commit 28fd02b
  - netpoll: Use rcu_access_pointer() in __netpoll_setup
    (git-fixes).
  - commit bc4dbd6
  - net: ipv4: Cache pmtu for all packet paths if multipath enabled
    (git-fixes).
  - commit 5efb982
  - ipv4: Convert ip_route_input() to dscp_t (git-fixes).
  - commit 2191938
  - ipv4: Convert icmp_route_lookup() to dscp_t (git-fixes).
  - commit 24dfb21
  - vfio/pci: Virtualize zero INTx PIN if no pdev->irq
    (bsc#1241486).
  - commit b964ce4
  - arm64: proton-pack: Add new CPUs 'k' values for branch
    mitigation (bsc#1242778).
  - arm64: bpf: Only mitigate cBPF programs loaded by unprivileged
    users (bsc#1242778 bsc#1243660 CVE-2025-37963).
  - arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs
    (bsc#1242778 bsc#1243649 CVE-2025-37948).
  - arm64: proton-pack: Expose whether the branchy loop k value
    (bsc#1242778).
  - arm64: proton-pack: Expose whether the platform is mitigated
    by firmware (bsc#1242778).
  - arm64: insn: Add support for encoding DSB (bsc#1242778).
  - commit 994f7ea
  - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (bsc#1242778).
  - x86/bpf: Add IBHF call at end of classic BPF (bsc#1242778).
  - x86/bpf: Call branch history clearing sequence on exit
    (bsc#1242778).
  - commit 03f85af
  - net: libwx: handle page_pool_dev_alloc_pages error (CVE-2025-37755 bsc#1242506)
  - commit f2b10a7
  - virtiofs: add filesystem context source name check (CVE-2025-37773 bsc#1242502).
  - commit b34e55c
  - net_sched: skbprio: Remove overly strict queue assertions (CVE-2025-38637 bsc#1241657)
  - commit 688fda2
  - fs/9p: fix NULL pointer dereference on mkdir (CVE-2025-22070 bsc#1241305)
  - commit 77c1602
  - btrfs: zoned: fix extent range end unlock in cow_file_range()
    (bsc#1239514).
  - commit 6f500d2
  - btrfs: do proper folio cleanup when run_delalloc_nocow()
    failed (CVE-2024-57975 bsc#1239099).
  - commit 1c61c63
  - btrfs: do proper folio cleanup when cow_file_range()  failed
    (CVE-2024-57976 bsc#1239100).
  - commit a599667
  - btrfs: simplify range tracking in cow_file_range()
    (bsc#1239514).
  - commit 31063e8
  - btrfs: fix error handling of submit_uncompressed_range()
    (bsc#1243744).
  - commit 923ac9f
  - btrfs: fix double accounting race when  extent_writepage_io()
    failed (bsc#1243743).
  - commit f484c24
  - btrfs: do not assume the full page range is not dirty in
    extent_writepage_io() (bsc#1239514).
  - commit 06b104d
  - btrfs: fix double accounting race when
    btrfs_run_delalloc_range() failed (CVE-2024-58089 bsc#1239514).
  - commit b3345e8
  - btrfs: use btrfs_inode in extent_writepage() (bsc#1239514).
  - commit 06adcd7
  - btrfs: rename btrfs_folio_(set|start|end)_writer_lock()
    (bsc#1239514).
  - commit 7ce4bd6
  - btrfs: unify to use writer locks for subpage locking
    (bsc#1239514).
  - commit 9a6e0a9
  - btrfs: remove unused btrfs_folio_start_writer_lock()
    (bsc#1239514).
  - commit 9326b94
  - btrfs: mark all dirty sectors as locked inside
    writepage_delalloc() (bsc#1239514).
  - commit 760b074
  - btrfs: move the delalloc range bitmap search into  extent_io.c
    (bsc#1239514).
  - commit fd2855a
  - net: fix NULL pointer dereference in l3mdev_l3_rcv (CVE-2025-22103 bsc#1241448)
  - commit 694b073
  - udmabuf: fix a buf size overflow issue during udmabuf creation (CVE-2025-37803 bsc#1242852)
  - commit 2b275c3

++++ kernel-rt:

  - perf/dwc_pcie: fix duplicate pci_dev devices (CVE-2025-37746 bsc#1242885)
  - commit dea67be
  - perf/dwc_pcie: Qualify RAS DES VSEC Capability by Vendor, Revision (bsc#1242885)
  - commit ffcf22b
  - isofs: Prevent the use of too small fid (CVE-2025-37780 bsc#1242786)
  - commit 5c5ba6b
  - ext4: fix off-by-one error in do_split (CVE-2025-23150 bsc#1242513)
  - commit 0080833
  - net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered (CVE-2025-37787 bsc#1242585)
  - commit 9e7d0f2
  - xfrm: Fix UDP GRO handling for some corner cases (git-fixes).
  - commit 1c0c1c5
  - espintcp: fix skb leaks (git-fixes).
  - commit 15cdb39
  - xsk: Bring back busy polling support in XDP_COPY (git-fixes).
  - commit 6c2f2b4
  - net/tls: fix kernel panic when alloc_page failed (git-fixes).
  - commit 92ec148
  - gre: Fix again IPv6 link-local address generation (git-fixes).
  - commit c3ee537
  - net: lwtunnel: fix recursion loops (git-fixes).
  - commit 9d17465
  - tcp/dccp: allow a connection when sk_max_ack_backlog is zero
    (git-fixes).
  - commit 28fd02b
  - netpoll: Use rcu_access_pointer() in __netpoll_setup
    (git-fixes).
  - commit bc4dbd6
  - net: ipv4: Cache pmtu for all packet paths if multipath enabled
    (git-fixes).
  - commit 5efb982
  - ipv4: Convert ip_route_input() to dscp_t (git-fixes).
  - commit 2191938
  - ipv4: Convert icmp_route_lookup() to dscp_t (git-fixes).
  - commit 24dfb21
  - vfio/pci: Virtualize zero INTx PIN if no pdev->irq
    (bsc#1241486).
  - commit b964ce4
  - arm64: proton-pack: Add new CPUs 'k' values for branch
    mitigation (bsc#1242778).
  - arm64: bpf: Only mitigate cBPF programs loaded by unprivileged
    users (bsc#1242778 bsc#1243660 CVE-2025-37963).
  - arm64: bpf: Add BHB mitigation to the epilogue for cBPF programs
    (bsc#1242778 bsc#1243649 CVE-2025-37948).
  - arm64: proton-pack: Expose whether the branchy loop k value
    (bsc#1242778).
  - arm64: proton-pack: Expose whether the platform is mitigated
    by firmware (bsc#1242778).
  - arm64: insn: Add support for encoding DSB (bsc#1242778).
  - commit 994f7ea
  - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (bsc#1242778).
  - x86/bpf: Add IBHF call at end of classic BPF (bsc#1242778).
  - x86/bpf: Call branch history clearing sequence on exit
    (bsc#1242778).
  - commit 03f85af
  - net: libwx: handle page_pool_dev_alloc_pages error (CVE-2025-37755 bsc#1242506)
  - commit f2b10a7
  - virtiofs: add filesystem context source name check (CVE-2025-37773 bsc#1242502).
  - commit b34e55c
  - net_sched: skbprio: Remove overly strict queue assertions (CVE-2025-38637 bsc#1241657)
  - commit 688fda2
  - fs/9p: fix NULL pointer dereference on mkdir (CVE-2025-22070 bsc#1241305)
  - commit 77c1602
  - btrfs: zoned: fix extent range end unlock in cow_file_range()
    (bsc#1239514).
  - commit 6f500d2
  - btrfs: do proper folio cleanup when run_delalloc_nocow()
    failed (CVE-2024-57975 bsc#1239099).
  - commit 1c61c63
  - btrfs: do proper folio cleanup when cow_file_range()  failed
    (CVE-2024-57976 bsc#1239100).
  - commit a599667
  - btrfs: simplify range tracking in cow_file_range()
    (bsc#1239514).
  - commit 31063e8
  - btrfs: fix error handling of submit_uncompressed_range()
    (bsc#1243744).
  - commit 923ac9f
  - btrfs: fix double accounting race when  extent_writepage_io()
    failed (bsc#1243743).
  - commit f484c24
  - btrfs: do not assume the full page range is not dirty in
    extent_writepage_io() (bsc#1239514).
  - commit 06b104d
  - btrfs: fix double accounting race when
    btrfs_run_delalloc_range() failed (CVE-2024-58089 bsc#1239514).
  - commit b3345e8
  - btrfs: use btrfs_inode in extent_writepage() (bsc#1239514).
  - commit 06adcd7
  - btrfs: rename btrfs_folio_(set|start|end)_writer_lock()
    (bsc#1239514).
  - commit 7ce4bd6
  - btrfs: unify to use writer locks for subpage locking
    (bsc#1239514).
  - commit 9a6e0a9
  - btrfs: remove unused btrfs_folio_start_writer_lock()
    (bsc#1239514).
  - commit 9326b94
  - btrfs: mark all dirty sectors as locked inside
    writepage_delalloc() (bsc#1239514).
  - commit 760b074
  - btrfs: move the delalloc range bitmap search into  extent_io.c
    (bsc#1239514).
  - commit fd2855a
  - net: fix NULL pointer dereference in l3mdev_l3_rcv (CVE-2025-22103 bsc#1241448)
  - commit 694b073
  - udmabuf: fix a buf size overflow issue during udmabuf creation (CVE-2025-37803 bsc#1242852)
  - commit 2b275c3

++++ gcc15:

  - Update to GCC 15 branch head, 15.1.1+git9739
  - Do not build any loongarch64 compiler for distros where we do
    not have cross-binutils.

++++ libguestfs:

  - Upstream bug fix for BTRFS based images (SLES and openSUSE)
    004-Add-more-debugging-to-list_filesystems.patch
    005-Pipeline-style-when-mapping-and-filtering-filesystems.patch
    007-inspection-Ignore-btrfs-snapshots-of-roots.patch
  - Adjustment to use fusermount3 when fuse3 is required by distro.
    use-fuse3-for-build.patch

++++ python313-core:

  - Don't use %elif, it is supported only from rpm 4.15.0, which is
    not in SLE-15.

++++ libsoup:

  - Add libsoup-CVE-2025-4969.patch: multipart: verify array bounds
    before accesing its members (boo#1243423 CVE-2025-4969).
  - Also rerun tests for ppc64le should they fail. hsts-db-test
    appears to time out intermittently there (bsc#1243570).

++++ libvirt:

  - spec: Drop dependencies on the nwfilter driver (which requires
    iptables) for Factory and SLFO
    boo#1231798, jsc#PED-12034

++++ lsof:

  - Force skip NFS test, as it cannot complete properly in OBS but it
    can be accidentally triggered there on ppc64. (bsc#1243577,
    lsof-skip-nfs-test.patch).

++++ python313:

  - Don't use %elif, it is supported only from rpm 4.15.0, which is
    not in SLE-15.

++++ qemu:

  - Fix building opensbi with gcc-15:
    * [openSUSE] Fix bsc#1241473 (in opensbi)
  - Fixes for bsc#1241240 and bsc#1243585:
    * vfio/spapr: Fix L2 crash with PCI device passthrough and memory > 128G (bsc#1241240)
    * vfio/spapr: Enhance error handling in vfio_spapr_create_window() (bsc#1241240)
    * tests/functional: Use -no-shutdown in the hppa_seabios test (bsc#1243585)

------------------------------------------------------------------
------------------  2025-5-27  -  May 27 2025  -------------------
------------------------------------------------------------------

++++ branding-SLE:

  - Drop branding-SLE main package, its content is moved to release
    package (bsc#1239169).

++++ python-kiwi:

  - Bump version: 10.2.23 → 10.2.24

++++ kernel-default:

  - add bug reference for an existing hv_netvsc change (bsc#1243737).
  - commit c741e73
  - genksyms: Fix enum consts from a reference affecting new values.
  - commit 2ee402c
  - s390/pci: Serialize device addition and removal (git-fixes
    bsc#1243729).
  - s390/pci: Allow re-add of a reserved but not yet removed device
    (git-fixes bsc#1243727).
  - s390/pci: Remove redundant bus removal and disable from
    zpci_release_device() (git-fixes bsc#1243728).
  - commit e9987df
  - scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort()
    (CVE-2025-37828 bsc#1242869).
  - commit 8116e01
  - xfs: don't assume perags are initialised when trimming AGs
    (git-fixes).
  - commit 67a3805
  - erofs: avoid using multiple devices with different type
    (git-fixes).
  - commit 0af5a86
  - erofs: fix file handle encoding for 64-bit NIDs (git-fixes).
  - commit 740cd9e
  - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
    (CVE-2025-37823 bsc#1242924).
  - commit caed7b7
  - btrfs: zoned: return EIO on RAID1 block group write pointer mismatch (CVE-2025-37827 bsc#1242876)
  - commit c5ee090
  - team: better TEAM_OPTION_TYPE_STRING validation (CVE-2025-21787 bsc#1238774)
  - commit 857f4eb
  - scsi: ufs: bsg: Set bsg_queue to NULL after removal (CVE-2024-54458 bsc#1238992)
  - commit 3efcbdb
  - cxl: Fix warning from emitting resource_size_t as long long
    int on 32bit systems (bsc#1241258).
  - commit 536fb73

++++ kernel-rt:

  - add bug reference for an existing hv_netvsc change (bsc#1243737).
  - commit c741e73
  - genksyms: Fix enum consts from a reference affecting new values.
  - commit 2ee402c
  - s390/pci: Serialize device addition and removal (git-fixes
    bsc#1243729).
  - s390/pci: Allow re-add of a reserved but not yet removed device
    (git-fixes bsc#1243727).
  - s390/pci: Remove redundant bus removal and disable from
    zpci_release_device() (git-fixes bsc#1243728).
  - commit e9987df
  - scsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort()
    (CVE-2025-37828 bsc#1242869).
  - commit 8116e01
  - xfs: don't assume perags are initialised when trimming AGs
    (git-fixes).
  - commit 67a3805
  - erofs: avoid using multiple devices with different type
    (git-fixes).
  - commit 0af5a86
  - erofs: fix file handle encoding for 64-bit NIDs (git-fixes).
  - commit 740cd9e
  - net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too
    (CVE-2025-37823 bsc#1242924).
  - commit caed7b7
  - btrfs: zoned: return EIO on RAID1 block group write pointer mismatch (CVE-2025-37827 bsc#1242876)
  - commit c5ee090
  - team: better TEAM_OPTION_TYPE_STRING validation (CVE-2025-21787 bsc#1238774)
  - commit 857f4eb
  - scsi: ufs: bsg: Set bsg_queue to NULL after removal (CVE-2024-54458 bsc#1238992)
  - commit 3efcbdb
  - cxl: Fix warning from emitting resource_size_t as long long
    int on 32bit systems (bsc#1241258).
  - commit 536fb73

++++ libguestfs:

  - bsc#1243351 - guestfs-appliance still requires ISC dhcp
    Conditionally replace usage of dhcp-client with dhcpcd in
    libguestfs.spec

++++ libsoup:

  - Add libsoup-CVE-2025-4476.patch: fix crash in
    soup_auth_digest_get_protection_space (boo#1243422
    CVE-2025-4476 glgo#GNOME/libsoup!457).
  - Add libsoup-CVE-2025-4948.patch: verify boundary limits for
    multipart body (boo#1243332 CVE-2025-4948
    glgo#GNOME/libsoup#449).

++++ libzypp:

  - Add a note to service maintained .repo file entries (fixes #638)
  - Support using %{url} variable in a RIS service's repo section.
  - version 17.37.2 (35)

++++ mdadm:

  - monitor: Add MAILFROM address to email envelope to avoid smtp auth
    errors (bsc#1241474)
    * add 1008-mdmonitor-use-MAILFROM-to-set-sendmail-envelope-send.patch

++++ python-lxml:

  - Update to 5.4.0
    * LP#2107279: Binary wheels use libxml2 2.13.8 and libxslt 1.1.43 to resolve
    several CVEs. Issue found by Anatoly Katyushin, see
    https://bugs.launchpad.net/lxml/+bug/2107279

++++ python-urllib3:

  - Update to 2.4.0
    * Applied PEP 639 by specifying the license fields in
    pyproject.toml. (#3522)
    * Updated exceptions to save and restore more properties during the
    pickle/serialization process. (#3567)
    * Added verify_flags option to create_urllib3_context with a default
    of VERIFY_X509_PARTIAL_CHAIN and VERIFY_X509_STRICT for Python
    3.13+. (#3571)
    * Fixed a bug with partial reads of streaming data in Emscripten.
    (#3555)
    * Switched to uv for installing development dependecies. (#3550)
    * Removed the multiple.intoto.jsonl asset from GitHub releases.
    Attestation of release files since v2.3.0 can be found on PyPI.
    (#3566)
  - 2.3.0:
    * Added HTTPResponse.shutdown() to stop any ongoing or future reads
    for a specific response. It calls shutdown(SHUT_RD) on the
    underlying socket. This feature was sponsored by LaunchDarkly.
    (#2868)
    * Added support for JavaScript Promise Integration on Emscripten.
    This enables more efficient WebAssembly requests and streaming,
    and makes it possible to use in Node.js if you launch it as node
  - -experimental-wasm-stack-switching. (#3400)
    * Added the proxy_is_tunneling property to HTTPConnection and
    HTTPSConnection. (#3285)
    * Added pickling support to NewConnectionError and
    NameResolutionError. (#3480)
    * Fixed an issue in debug logs where the HTTP version was rendering
    as "HTTP/11" instead of "HTTP/1.1". (#3489)
    * Removed support for Python 3.8. (#3492)
  - Skip test_close_after_handshake flaky test, it fails sometimes in
    ppc64le and s390x architectures, bsc#1243583

------------------------------------------------------------------
------------------  2025-5-26  -  May 26 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Cleanup build metadata
    Make sure the final image rootfs does not contain unneeded
    metadata files used during build time. The respective cleanup
    call is performed after the root sync and after all initrd/boot
    processing has been done. This is because up to that point it's
    still possible that the information is required. This means
    when building images with a read-only rootfs, it might not be
    possible that the metadata can be deleted due to a chicken&egg
    situation. Furthermore the cleanup is applied to the disk
    builder only as other builders do not really suffer from
    this data and for the container builder the metadata can
    also be used for the stackbuild feature when building images
    derived from containers. This Fixes #2668

++++ fwupd:

  - Update to version 2.0.10:
    + This release adds the following features:
  - Include the AGESA version as the summary of the AMD secure processor device
  - Include the UEFI PK certificate key ID in the uploaded problem report
  - Provide a way for the client to restrict the GUID list to an emulated device
    + This release fixes the following bugs:
  - Do not allow dbx updates on the HP Elitebook 845 Gen10
  - Do not warn about BIOS bugs we can easily work around
  - Fix a regression in fwupdmgr emulation-save when recording some devices
  - Fix a regression preventing installation of KEKs
  - Fix a small memory leak when getting security attributes
  - Never write a UX capsule when using Capsule-On-Disk
  - Use the 'OnBattery' property from upower to tell if plugged in
    + This release adds support for the following hardware:
  - Lenovo Legion Touchpad
  - Logitech MX Mechanical
  - Poly Studio V72 and V12

++++ kernel-default:

  - pfifo_tail_enqueue: Drop new packet when sch->limit == 0 (CVE-2025-21702 bsc#1237312)
  - commit e108fd0
  - ptp: Ensure info->enable callback is always set (CVE-2025-21814 bsc#1238473)
  - commit 0465308
  - kABI: arm64: delete definitions
    kABI checks are currently broken for arm64 and causing most of the
    branches to fail integration tests. Remove arm64 kABI files to
    workaround till this issue is fixed.
  - commit dfeef4c
  - Revert "rndis_host: Flag RNDIS modems as WWAN devices"
    (git-fixes).
  - commit 2a0aeda
  - kernel/range: Const-ify range_contains parameters (bsc#1241258).
  - commit b9d16ed
  - cxl: core/region - ignore interleave granularity when ways=1 (bsc#1241258).
  - cxl: Add extended linear cache address alias emission for cxl events (bsc#1241258).
  - acpi/hmat / cxl: Add extended linear cache support for CXL
    (bsc#1241258).
  - acpi: numa: Add support to enumerate and store extended linear
    address mode (bsc#1241258).
  - cxl: core/region - ignore interleave granularity when ways=1 (bsc#1241258).
  - cxl: Add extended linear cache address alias emission for cxl events (bsc#1241258).
  - acpi/hmat / cxl: Add extended linear cache support for CXL
    (bsc#1241258).
  - acpi: numa: Add support to enumerate and store extended linear
    address mode (bsc#1241258).
  - commit 95333c7
  - scripts/python/git_sort/git_sort.yaml: Add 'cxl/next'
    Add 'cxl/next' tree for git sort.
  - commit 61a26cf
  - s390/pci: Fix missing check for zpci_create_device() error
    return (git-fixes CVE-2025-37974 bsc#1243547).
  - commit 8413a5a
  - s390/entry: Fix last breaking event handling in case of stack
    corruption (git-fixes bsc#1243654).
  - KVM: s390: Don't use %pK through debug printing (git-fixes
    bsc#1243652).
  - KVM: s390: Don't use %pK through tracepoints (git-fixes
    bsc#1243653).
  - commit c3b5d9b
  - kABI: arm64: drop second PIDTYPE_MAX definition
    scripts/update-symvers is adding a second PIDTYPE_MAX definition which
    is causing kbuild failures. Remove it manually as a workaround till the
    source of the issue is identified.
  - commit 467e42f

++++ kernel-firmware-ath12k:

  - Update to version 20250523 (git commit f4e75db20a11):
    * ath12k: WCN7850 hw2.0: update to WLAN.HMT.1.1.c5-00284.1-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3

++++ kernel-rt:

  - pfifo_tail_enqueue: Drop new packet when sch->limit == 0 (CVE-2025-21702 bsc#1237312)
  - commit e108fd0
  - ptp: Ensure info->enable callback is always set (CVE-2025-21814 bsc#1238473)
  - commit 0465308
  - kABI: arm64: delete definitions
    kABI checks are currently broken for arm64 and causing most of the
    branches to fail integration tests. Remove arm64 kABI files to
    workaround till this issue is fixed.
  - commit dfeef4c
  - Revert "rndis_host: Flag RNDIS modems as WWAN devices"
    (git-fixes).
  - commit 2a0aeda
  - kernel/range: Const-ify range_contains parameters (bsc#1241258).
  - commit b9d16ed
  - cxl: core/region - ignore interleave granularity when ways=1 (bsc#1241258).
  - cxl: Add extended linear cache address alias emission for cxl events (bsc#1241258).
  - acpi/hmat / cxl: Add extended linear cache support for CXL
    (bsc#1241258).
  - acpi: numa: Add support to enumerate and store extended linear
    address mode (bsc#1241258).
  - cxl: core/region - ignore interleave granularity when ways=1 (bsc#1241258).
  - cxl: Add extended linear cache address alias emission for cxl events (bsc#1241258).
  - acpi/hmat / cxl: Add extended linear cache support for CXL
    (bsc#1241258).
  - acpi: numa: Add support to enumerate and store extended linear
    address mode (bsc#1241258).
  - commit 95333c7
  - scripts/python/git_sort/git_sort.yaml: Add 'cxl/next'
    Add 'cxl/next' tree for git sort.
  - commit 61a26cf
  - s390/pci: Fix missing check for zpci_create_device() error
    return (git-fixes CVE-2025-37974 bsc#1243547).
  - commit 8413a5a
  - s390/entry: Fix last breaking event handling in case of stack
    corruption (git-fixes bsc#1243654).
  - KVM: s390: Don't use %pK through debug printing (git-fixes
    bsc#1243652).
  - KVM: s390: Don't use %pK through tracepoints (git-fixes
    bsc#1243653).
  - commit c3b5d9b
  - kABI: arm64: drop second PIDTYPE_MAX definition
    scripts/update-symvers is adding a second PIDTYPE_MAX definition which
    is causing kbuild failures. Remove it manually as a workaround till the
    source of the issue is identified.
  - commit 467e42f

++++ llvm19:

  - Use generic python3 for SLES 16 as python 3.11 is dropped there.
    [bsc#1243630]

++++ mozilla-nss:

  - update to NSS 3.112
    * bmo#1963792 - Fix alias for mac workers on try
    * bmo#1966786 - ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault
    * bmo#1931930 - ABI/API break in ssl certificate processing
    * bmo#1955971 - remove unnecessary assertion in sec_asn1d_init_state_based_on_template
    * bmo#1965754 - update taskgraph to v14.2.1
    * bmo#1964358 - Workflow for automation of the release on GitHub when pushing a tag
    * bmo#1952860 - fix faulty assertions in SEC_ASN1DecoderUpdate
    * bmo#1934877 - Renegotiations should use a fresh ECH GREASE buffer
    * bmo#1951396 - update taskgraph to v14.1.1
    * bmo#1962503 - Partial fix for ACVP build CI job
    * bmo#1961827 - Initialize find in sftk_searchDatabase
    * bmo#1963121 - Add clang-18 to extra builds
    * bmo#1963044 - Fault tolerant git fetch for fuzzing
    * bmo#1962556 - Tolerate intermittent failures in ssl_policy_pkix_ocsp
    * bmo#1962770 - fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set
    * bmo#1961835 - fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls
    * bmo#1963102 - Remove Cryptofuzz CI version check

++++ ncurses:

  - Add ncurses patch 20250524
    + correct option-name used in configure script, which resulted in size
    change for cchar_t (cf: 20250517).

++++ openssl-3:

  - Security fix: [bsc#1243564, CVE-2025-4575]
    * Fix the x509 application adding trusted use instead of rejected use
    * Add openssl-CVE-2025-4575.patch

++++ openSUSE-repos-LeapMicro:

  - Update to version 20250526.4556805:
    * Default zypp parallel downloads for 16.0 and TW
    * Enable NVIDIA repository for Leap 16.0

------------------------------------------------------------------
------------------  2025-5-25  -  May 25 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Update overlay integration test for partial write
    Update the sdboot_uki_verity_erofs profile of the
    test-image-overlayroot integration test with a custom
    fstab example to overlay only parts of the system
    for writing. This Fixes #2815
  - bootloader setup without overlay write partition
    If overlayroot_write_partition="false" is set, no system
    indicator was stored. This cause the bootloader setup to
    be skipped completely which is not required for e.g.
    systemd-boot.
  - Make sure to create overlay directories
    Create overlay directories even if rd.root.overlay.readonly
    is set. This allows individual fstab overlays mounts to be
    performed

++++ file:

  - Add file-zipdata.patch
    * Fix "Some zip files are misclassified as data"
    see https://bugs.astron.com/view.php?id=571
    based on https://github.com/file/file/commit/60b2032b96fc185b37fb0f2152e834efb2edad6e

++++ grub2:

  - Add support for LoaderEntryOneshot
    * grub2-bls-loader-entry-oneshot.patch

++++ kernel-default:

  - spi: spi-fsl-dspi: Reset SR flags before sending a new message
    (git-fixes).
  - spi: spi-fsl-dspi: Halt the module after a new message transfer
    (git-fixes).
  - spi: spi-fsl-dspi: restrict register range for regmap access
    (git-fixes).
  - spi: use container_of_cont() for to_spi_device() (git-fixes).
  - commit 96f52d2

++++ kernel-rt:

  - spi: spi-fsl-dspi: Reset SR flags before sending a new message
    (git-fixes).
  - spi: spi-fsl-dspi: Halt the module after a new message transfer
    (git-fixes).
  - spi: spi-fsl-dspi: restrict register range for regmap access
    (git-fixes).
  - spi: use container_of_cont() for to_spi_device() (git-fixes).
  - commit 96f52d2

------------------------------------------------------------------
------------------  2025-5-24  -  May 24 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - U_gbm-fix-get_back_bo-failure-with-gbm_surface-and-imp.patch
    * should fix hangup on "Started GNOME Display Manager" in a VM
    on VMware Fusion Pro (bsc#1241370)

++++ Mesa-drivers:

  - U_gbm-fix-get_back_bo-failure-with-gbm_surface-and-imp.patch
    * should fix hangup on "Started GNOME Display Manager" in a VM
    on VMware Fusion Pro (bsc#1241370)

++++ kernel-default:

  - loop: don't require ->write_iter for writable files in
    loop_configure (git-fixes).
  - commit e9b3c58
  - drm/amd: Add Suspend/Hibernate notification callback support
    (stable-fixes).
  - Refresh
    patches.suse/drm-amd-Keep-display-off-while-going-into-S4.patch.
  - commit da887b2
  - accel/ivpu: Refactor functions in ivpu_fw_log.c (stable-fixes).
  - Refresh patches.suse/accel-ivpu-Add-coredump-support.patch.
  - commit 0c5d673
  - accel/ivpu: Reset fw log on cold boot (stable-fixes).
  - Refresh patches.suse/accel-ivpu-Add-coredump-support.patch.
  - commit 836180c
  - Revert "drm/amd: Keep display off while going into S4"
    (git-fixes).
  - drm/edid: fixed the bug that hdr metadata was not reset
    (git-fixes).
  - thermal: intel: x86_pkg_temp_thermal: Fix bogus trip temperature
    (git-fixes).
  - platform/x86: think-lmi: Fix attribute name usage for
    non-compliant items (git-fixes).
  - pmdomain: core: Fix error checking in
    genpd_dev_pm_attach_by_id() (git-fixes).
  - pmdomain: renesas: rcar: Remove obsolete nullify checks
    (git-fixes).
  - can: slcan: allow reception of short error messages (git-fixes).
  - can: bcm: add missing rcu read protection for procfs content
    (git-fixes).
  - can: bcm: add locking for bcm_op runtime updates (git-fixes).
  - Bluetooth: btusb: use skb_pull to avoid unsafe access in QCA
    dump handling (git-fixes).
  - Bluetooth: L2CAP: Fix not checking l2cap_chan security level
    (git-fixes).
  - ASoc: SOF: topology: connect DAI to a single DAI link
    (git-fixes).
  - ASoC: SOF: Intel: hda-bus: Use PIO mode on ACE2+ platforms
    (git-fixes).
  - ASoC: SOF: ipc4-pcm: Delay reporting is only supported for
    playback direction (git-fixes).
  - ASoC: SOF: ipc4-control: Use SOF_CTRL_CMD_BINARY as numid for
    bytes_ext (git-fixes).
  - drm/amd/display: Avoid flooding unnecessary info messages
    (git-fixes).
  - drm/amd/display: Correct the reply value when AUX write
    incomplete (git-fixes).
  - drm/amdgpu: fix incorrect MALL size for GFX1151 (stable-fixes).
  - drm/amdgpu: csa unmap use uninterruptible lock (stable-fixes).
  - ALSA: usb-audio: Add sample rate quirk for Microdia JP001 USB
    Camera (stable-fixes).
  - HID: bpf: abort dispatch if device destroyed (git-fixes).
  - HID: uclogic: Add NULL check in uclogic_input_configured()
    (git-fixes).
  - HID: thrustmaster: fix memory leak in thrustmaster_interrupts()
    (git-fixes).
  - wifi: mt76: disable napi on driver removal (git-fixes).
  - wifi: mac80211: Set n_channels after allocating struct
    cfg80211_scan_request (git-fixes).
  - drm/amdgpu: fix pm notifier handling (git-fixes).
  - Revert "drm/amd: Stop evicting resources on APUs in suspend"
    (stable-fixes).
  - accel/ivpu: Fix fw log printing (stable-fixes).
  - accel/ivpu: Rename ivpu_log_level to fw_log_level
    (stable-fixes).
  - commit 6014984

++++ kernel-rt:

  - loop: don't require ->write_iter for writable files in
    loop_configure (git-fixes).
  - commit e9b3c58
  - drm/amd: Add Suspend/Hibernate notification callback support
    (stable-fixes).
  - Refresh
    patches.suse/drm-amd-Keep-display-off-while-going-into-S4.patch.
  - commit da887b2
  - accel/ivpu: Refactor functions in ivpu_fw_log.c (stable-fixes).
  - Refresh patches.suse/accel-ivpu-Add-coredump-support.patch.
  - commit 0c5d673
  - accel/ivpu: Reset fw log on cold boot (stable-fixes).
  - Refresh patches.suse/accel-ivpu-Add-coredump-support.patch.
  - commit 836180c
  - Revert "drm/amd: Keep display off while going into S4"
    (git-fixes).
  - drm/edid: fixed the bug that hdr metadata was not reset
    (git-fixes).
  - thermal: intel: x86_pkg_temp_thermal: Fix bogus trip temperature
    (git-fixes).
  - platform/x86: think-lmi: Fix attribute name usage for
    non-compliant items (git-fixes).
  - pmdomain: core: Fix error checking in
    genpd_dev_pm_attach_by_id() (git-fixes).
  - pmdomain: renesas: rcar: Remove obsolete nullify checks
    (git-fixes).
  - can: slcan: allow reception of short error messages (git-fixes).
  - can: bcm: add missing rcu read protection for procfs content
    (git-fixes).
  - can: bcm: add locking for bcm_op runtime updates (git-fixes).
  - Bluetooth: btusb: use skb_pull to avoid unsafe access in QCA
    dump handling (git-fixes).
  - Bluetooth: L2CAP: Fix not checking l2cap_chan security level
    (git-fixes).
  - ASoc: SOF: topology: connect DAI to a single DAI link
    (git-fixes).
  - ASoC: SOF: Intel: hda-bus: Use PIO mode on ACE2+ platforms
    (git-fixes).
  - ASoC: SOF: ipc4-pcm: Delay reporting is only supported for
    playback direction (git-fixes).
  - ASoC: SOF: ipc4-control: Use SOF_CTRL_CMD_BINARY as numid for
    bytes_ext (git-fixes).
  - drm/amd/display: Avoid flooding unnecessary info messages
    (git-fixes).
  - drm/amd/display: Correct the reply value when AUX write
    incomplete (git-fixes).
  - drm/amdgpu: fix incorrect MALL size for GFX1151 (stable-fixes).
  - drm/amdgpu: csa unmap use uninterruptible lock (stable-fixes).
  - ALSA: usb-audio: Add sample rate quirk for Microdia JP001 USB
    Camera (stable-fixes).
  - HID: bpf: abort dispatch if device destroyed (git-fixes).
  - HID: uclogic: Add NULL check in uclogic_input_configured()
    (git-fixes).
  - HID: thrustmaster: fix memory leak in thrustmaster_interrupts()
    (git-fixes).
  - wifi: mt76: disable napi on driver removal (git-fixes).
  - wifi: mac80211: Set n_channels after allocating struct
    cfg80211_scan_request (git-fixes).
  - drm/amdgpu: fix pm notifier handling (git-fixes).
  - Revert "drm/amd: Stop evicting resources on APUs in suspend"
    (stable-fixes).
  - accel/ivpu: Fix fw log printing (stable-fixes).
  - accel/ivpu: Rename ivpu_log_level to fw_log_level
    (stable-fixes).
  - commit 6014984

------------------------------------------------------------------
------------------  2025-5-23  -  May 23 2025  -------------------
------------------------------------------------------------------

++++ avahi:

  - Drop obsolete update-desktop-files BuildRequires and macro.
    Replace with desktop-file-utils BuildRequires.
  - Drop unneeded update_spec.pl source, not needed since change to
    proper multibuild.

++++ cockpit:

  - Update branding patch for micro and sle

++++ python-kiwi:

  - Fixed rd.root.overlay.readonly overlay mode
    When booting an overlayroot image with rd.root.overlay.readonly
    set, the system will boot with only the read-only root mounted.
    There was a bug in the dracut code which prevented this mount
    from succeeding when the read-only rootfs is different from
    squashfs. This commit changes the mount to be a simple bind
    mount, independent of the origin filesystem. This works because
    the read-only mount is performed in the dracut overlay code
    anyway. This is related to Issue #2815

++++ gstreamer-plugins-base:

  - Drop obsolete update-desktop-files BuildRequires.

++++ kernel-default:

  - perf vendor events: Add Clearwaterforest events (jsc#PED-10528).
  - commit fe52204
  - Update patches.suse/book3s64-radix-Align-section-vmemmap-start-address-t.patch
    (bsc#1238318 bsc#1243298 ltc#212689).
  - commit 1e96a7d
  - kABI: arm64: fix put_pid_ns definition
    arm64 -rt build is currently failing in ibs so its definition is not
    updated yet.
  - commit 576371e
  - x86/speculation: Remove the extra #ifdef around CALL_NOSPEC (bsc#1242006 CVE-2024-28956).
  - commit 92a4d4d
  - x86/speculation: Add a conditional CS prefix to CALL_NOSPEC (bsc#1242006 CVE-2024-28956).
  - commit 0e463b4
  - x86/speculation: Simplify and make CALL_NOSPEC consistent (bsc#1242006 CVE-2024-28956).
  - commit 18673e3
  - supported.conf: set einj module to unsupported (bsc#1243232)
    Finally we still build EINJ as module on SLE16 but set it to
    unsupported. (bsc#1243232)
    The original plan is removing EINJ module from SLE16 kernel because it
    should NOT be used on production system. (bsc#1023051 CVE-2016-3695)
    But then Lenovo raised that they need einj module for testing RAS
    features. We do not have a approach for shipping a module to partner
    for testing only. So we build EINJ as module on SLE16 but set it to
    unsupported. Which means that EINJ module will be included in
    kernel-default-extra package. (bsc#1243232)
    User can still grab signed EINJ module from kernel-default-extra through
    Leap repo on OBS. So we continue maintain a downstream patch to lock down
    EINJ.
  - Refresh
    patches.suse/acpi-Disable-APEI-error-injection-if-the-kernel-is-lockeddown.patch.
    (bsc#1243232 bsc#1023051 CVE-2016-3695)
  - Update config files.
    x86_64/default
    CONFIG_ACPI_APEI_EINJ=m
    [#] CONFIG_ACPI_APEI_EINJ_CXL is not set
  - commit 96a1c16

++++ kernel-rt:

  - perf vendor events: Add Clearwaterforest events (jsc#PED-10528).
  - commit fe52204
  - Update patches.suse/book3s64-radix-Align-section-vmemmap-start-address-t.patch
    (bsc#1238318 bsc#1243298 ltc#212689).
  - commit 1e96a7d
  - kABI: arm64: fix put_pid_ns definition
    arm64 -rt build is currently failing in ibs so its definition is not
    updated yet.
  - commit 576371e
  - x86/speculation: Remove the extra #ifdef around CALL_NOSPEC (bsc#1242006 CVE-2024-28956).
  - commit 92a4d4d
  - x86/speculation: Add a conditional CS prefix to CALL_NOSPEC (bsc#1242006 CVE-2024-28956).
  - commit 0e463b4
  - x86/speculation: Simplify and make CALL_NOSPEC consistent (bsc#1242006 CVE-2024-28956).
  - commit 18673e3
  - supported.conf: set einj module to unsupported (bsc#1243232)
    Finally we still build EINJ as module on SLE16 but set it to
    unsupported. (bsc#1243232)
    The original plan is removing EINJ module from SLE16 kernel because it
    should NOT be used on production system. (bsc#1023051 CVE-2016-3695)
    But then Lenovo raised that they need einj module for testing RAS
    features. We do not have a approach for shipping a module to partner
    for testing only. So we build EINJ as module on SLE16 but set it to
    unsupported. Which means that EINJ module will be included in
    kernel-default-extra package. (bsc#1243232)
    User can still grab signed EINJ module from kernel-default-extra through
    Leap repo on OBS. So we continue maintain a downstream patch to lock down
    EINJ.
  - Refresh
    patches.suse/acpi-Disable-APEI-error-injection-if-the-kernel-is-lockeddown.patch.
    (bsc#1243232 bsc#1023051 CVE-2016-3695)
  - Update config files.
    x86_64/default
    CONFIG_ACPI_APEI_EINJ=m
    [#] CONFIG_ACPI_APEI_EINJ_CXL is not set
  - commit 96a1c16

++++ gpgme:

  - update to 1.24.3:
    * cpp: Ensure that all transitions go from one state to a different
    state
    * cpp: Ensure correct expiration time on 32-bit arch with 64-bit
    time_t

++++ libzypp:

  - Use a cookie file to validate mirrorlist cache.
    This patch extends the mirrorlist code to use a cookie file to
    validate the contents of the cache against the source URL, making
    sure that we do not accidentially use a old cache when the
    mirrorlist url was changed. For example when migrating a system
    from one release to the next where the same repo alias might just
    have a different URL.
  - Let Service define and update gpgkey, mirrorlist and metalink.
  - Preserve a mirrorlist file in the raw cache during refresh.
  - version 17.37.1 (35)

------------------------------------------------------------------
------------------  2025-5-22  -  May 22 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Bug fixes
  - Update theme for patternfly 6
  - Update spec from upstream
  - Change when selinux policies are installed

++++ docker:

  - Update to docker-buildx v0.24.0. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.24.0>

++++ kdump:

  - upgrade to version 2.1.0
    * fix calibrate (no run-time changes)
    * man: update kdump(7)
    * add kdump-commandline.service (jsc#PED-12454)
    * kdumptool: introduce the commandline subcommand (jsc#PED-12454)
    * kdumptool calibrate: add per-cpu userspace requirements
    * Use FADUMP_COMMANDLINE_APPEND to detect explicit ip= configuration
    (bsc#1242134)
  - update calibrate values for SLFO (alp1600)

++++ kernel-default:

  - loop: Add sanity check for read/write_iter (git-fixes).
  - commit 6c2e9cd
  - net/niu: Niu requires MSIX ENTRY_DATA fields touch before
    entry reads (CVE-2025-37833 bsc#1242868).
  - commit 720f829
  - tpm: Add SNP SVSM vTPM driver (bsc#1241191).
  - Update config files.
  - supported.conf: Add SNP SVSM vTPM driver
  - commit 0f75d8f
  - platform/x86/intel/ifs: Add Clearwater Forest to CPU support list (jsc#PED-10558).
  - commit 718d39f

++++ kernel-rt:

  - loop: Add sanity check for read/write_iter (git-fixes).
  - commit 6c2e9cd
  - net/niu: Niu requires MSIX ENTRY_DATA fields touch before
    entry reads (CVE-2025-37833 bsc#1242868).
  - commit 720f829
  - tpm: Add SNP SVSM vTPM driver (bsc#1241191).
  - Update config files.
  - supported.conf: Add SNP SVSM vTPM driver
  - commit 0f75d8f
  - platform/x86/intel/ifs: Add Clearwater Forest to CPU support list (jsc#PED-10558).
  - commit 718d39f

++++ libzypp:

  - Code16: Enable curl2 backend and parallel package download by
    default. In Code15 it's optional.
    Environment variables ZYPP_CURL2=<0|1> and ZYPP_PCK_PRELOAD=<0|1>
    can be used to turn the features on or off.
  - Make gpgKeyUrl the default source for gpg keys.
    When refreshing zypp now primarily uses gpgKeyUrl information
    from the repo files and only falls back to a automatically
    generated key Url if a gpgKeyUrl was not specified.
  - Introduce mirrors into the Media backends (bsc#1240132)
  - Drop MediaMultiCurl backend.
  - Throttle progress updates when preloading packages (bsc#1239543)
  - Check if request is in valid state in CURL callbacks (fixes
    openSUSE/zypper#605)
  - spec/CMake: add conditional build
    '--with[out] classic_rpmtrans_as_default'.
    classic_rpmtrans is the current builtin default for SUSE,
    otherwise it's single_rpmtrans.
    The `enable_preview_single_rpmtrans_as_default_for_zypper` switch
    was removed from the spec file.  Accordingly the CMake option
    ENABLE_PREVIEW_SINGLE_RPMTRANS_AS_DEFAULT_FOR_ZYPPER was removed.
  - version 17.37.0 (35)

++++ netcfg:

  - Re-add /etc/services with a warning saying it was moved to
    /usr/etc/services [jsc#PED-12191].

++++ opensuse-migration-tool:

  - Update to version 20250521.ab8700a:
    * Drop redundant repodata from Leap url
    * Update README.md

++++ regionServiceClientConfigAzure:

  - Update dependency name for metadata package, name change in SLE 16
    (bsc#1243419)

++++ regionServiceClientConfigEC2:

  - Update dependency to accomodate metadata binary package name change
    in SLE 16 (bsc#1243419)

++++ zypper:

  - BuildRequires:  libzypp-devel >= 17.37.0.
  - Use libzypp improvements for preload and mirror handling.
  - xmlout.rnc: Update repo-element (bsc#1241463)
    Add the "metalink" attribute and reflect that the "url" elements
    list may in fact be empty, if no baseurls are defined in the
    .repo files.
  - man: update --allow-unsigned-rpm description.
    Explain how to achieve the same for packages provided by
    repositories.
  - version 1.14.90

------------------------------------------------------------------
------------------  2025-5-21  -  May 21 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - The way we build debs requires setuptools
    debbuild doesn't work when setuptools is not there
  - Drop use of setuptools
    Since we moved to poetry and no code using setuptools anymore,
    this requirement can be dropped. The commit also updates the
    plugin documentation which was still based on setup.py

++++ glib2:

  - Update to version 2.84.2:
    + Bugs fixed:
  - gclosure: fix ATOMIC_CHANGE_FIELD to read vint atomically
  - Windows: fix wrong typelib path
  - gstring: carefully handle gssize parameters
  - Update macOS job for new CI runner
  - gdate: Call tzset before localtime_r
  - Backport -Wsign-conversion fixes for g_get_locale_variants()
  - glocalfile: Disable faccessat()-based query_exists on Android

++++ kernel-default:

  - kABI: freeze it
    Generated on commit a36af99b035b ("Merge branch 'users/tiwai/SL-16.0/for-next' into SL-16.0")
  - commit 2f7ad33
  - btrfs: check folio mapping after unlock in put_file_data()
    (git-fixes).
  - commit af1da2c
  - btrfs: don't loop for nowait writes when checking for cross
    references (git-fixes).
  - commit 8661911
  - btrfs: fix improper generation check in snapshot delete
    (git-fixes).
  - commit 3532f6f
  - btrfs: fix missing snapshot drew unlock when root is dead
    during swap activation (bsc#1241204).
  - commit ee4fa40
  - btrfs: fix folio leak in submit_one_async_extent() (git-fixes).
  - commit 78685ec
  - btrfs: fix reclaimed bytes accounting after automatic block
    group reclaim (git-fixes).
  - btrfs: get used bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - btrfs: get zone unusable bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - btrfs: fix reclaimed bytes accounting after automatic block
    group reclaim (git-fixes).
  - btrfs: get used bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - btrfs: get zone unusable bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - commit 2eb9b7c
  - btrfs: fix a leaked chunk map issue in read_one_chunk()
    (git-fixes).
  - commit f35fbb4
  - btrfs: avoid monopolizing a core when activating a swap file
    (git-fixes).
  - commit 2db5c34
  - btrfs: allow swap activation to be interruptible (git-fixes).
  - commit 17cd587
  - btrfs: fix swap file activation failure due to extents that
    used to be shared (bsc#1241204).
  - commit 97cbdcc
  - btrfs: fix race with memory mapped writes when activating swap
    file (bsc#1241204).
  - commit 2943521
  - btrfs: fix stale page cache after race between readahead and
    direct IO write (git-fixes).
  - btrfs: rename __get_extent_map() and pass btrfs_inode
    (git-fixes).
  - btrfs: fix stale page cache after race between readahead and
    direct IO write (git-fixes).
  - btrfs: rename __get_extent_map() and pass btrfs_inode
    (git-fixes).
  - commit eedd048
  - iommu/arm-smmu-v3: Fix pgsize_bit for sva domains (bsc#1243341)
  - commit 95c386e
  - crypto: algif_hash - fix double free in hash_accept (git-fixes).
  - padata: do not leak refcount in reorder_work (git-fixes).
  - Bluetooth: hci_event: Fix not using key encryption size when
    its known (git-fixes).
  - Bluetooth: MGMT: Fix MGMT_OP_ADD_DEVICE invalid device flags
    (git-fixes).
  - Bluetooth: btnxpuart: Handle bootloader error during cmd5 and
    cmd7 (git-fixes).
  - Bluetooth: btnxpuart: Add correct bootloader error codes
    (git-fixes).
  - Bluetooth: btusb: Fix regression in the initialization of fake
    Bluetooth controllers (git-fixes).
  - commit 65e80ed

++++ kernel-firmware-sound:

  - Update to version 20250521 (git commit 3fbaee2775a4):
    * cirrus: cs35l41: Fix firmware links for several ASUS laptops
    * cirrus: cs35l41: Add Firmware for various HP Agusta Laptops using CS35L41 HDA
    * cirrus: cs35l41: Add Firmware for various ACER Laptops using CS35L41 HDA

++++ kernel-rt:

  - kABI: freeze it
    Generated on commit a36af99b035b ("Merge branch 'users/tiwai/SL-16.0/for-next' into SL-16.0")
  - commit 2f7ad33
  - btrfs: check folio mapping after unlock in put_file_data()
    (git-fixes).
  - commit af1da2c
  - btrfs: don't loop for nowait writes when checking for cross
    references (git-fixes).
  - commit 8661911
  - btrfs: fix improper generation check in snapshot delete
    (git-fixes).
  - commit 3532f6f
  - btrfs: fix missing snapshot drew unlock when root is dead
    during swap activation (bsc#1241204).
  - commit ee4fa40
  - btrfs: fix folio leak in submit_one_async_extent() (git-fixes).
  - commit 78685ec
  - btrfs: fix reclaimed bytes accounting after automatic block
    group reclaim (git-fixes).
  - btrfs: get used bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - btrfs: get zone unusable bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - btrfs: fix reclaimed bytes accounting after automatic block
    group reclaim (git-fixes).
  - btrfs: get used bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - btrfs: get zone unusable bytes while holding lock at
    btrfs_reclaim_bgs_work() (git-fixes).
  - commit 2eb9b7c
  - btrfs: fix a leaked chunk map issue in read_one_chunk()
    (git-fixes).
  - commit f35fbb4
  - btrfs: avoid monopolizing a core when activating a swap file
    (git-fixes).
  - commit 2db5c34
  - btrfs: allow swap activation to be interruptible (git-fixes).
  - commit 17cd587
  - btrfs: fix swap file activation failure due to extents that
    used to be shared (bsc#1241204).
  - commit 97cbdcc
  - btrfs: fix race with memory mapped writes when activating swap
    file (bsc#1241204).
  - commit 2943521
  - btrfs: fix stale page cache after race between readahead and
    direct IO write (git-fixes).
  - btrfs: rename __get_extent_map() and pass btrfs_inode
    (git-fixes).
  - btrfs: fix stale page cache after race between readahead and
    direct IO write (git-fixes).
  - btrfs: rename __get_extent_map() and pass btrfs_inode
    (git-fixes).
  - commit eedd048
  - iommu/arm-smmu-v3: Fix pgsize_bit for sva domains (bsc#1243341)
  - commit 95c386e
  - crypto: algif_hash - fix double free in hash_accept (git-fixes).
  - padata: do not leak refcount in reorder_work (git-fixes).
  - Bluetooth: hci_event: Fix not using key encryption size when
    its known (git-fixes).
  - Bluetooth: MGMT: Fix MGMT_OP_ADD_DEVICE invalid device flags
    (git-fixes).
  - Bluetooth: btnxpuart: Handle bootloader error during cmd5 and
    cmd7 (git-fixes).
  - Bluetooth: btnxpuart: Add correct bootloader error codes
    (git-fixes).
  - Bluetooth: btusb: Fix regression in the initialization of fake
    Bluetooth controllers (git-fixes).
  - commit 65e80ed

++++ mozilla-nss:

  - update to NSS 3.111
    * bmo#1930806 - FIPS changes need to be upstreamed: force ems policy
    * bmo#1957685 - Turn off Websites Trust Bit from CAs
    * bmo#1937338 - Update nssckbi version following April 2025 Batch of Changes
    * bmo#1943135 - Disable SMIME ‘trust bit’ for GoDaddy CAs
    * bmo#1874383 - Replaced deprecated sprintf function with snprintf in dbtool.c
    * bmo#1954612 - Need up update NSS for PKCS 3.1
    * bmo#1773374 - avoid leaking localCert if it is already set in ssl3_FillInCachedSID
    * bmo#1953097 - Decrease ASAN quarantine size for Cryptofuzz in CI
    * bmo#1943962 - selfserv: Add support for zlib certificate compression

++++ libguestfs:

  - Update to version 1.55.13 (jsc#PED-12706)
    * appliance: Remove zfs-fuse
    * Various updates to common submodule
    * ocaml-dep.sh.in: Remove mlgettext subdirectory
    * New API: Replace btrfs-fsck with btrfs-scrub-full
    * daemon: Implement e2fsck -n flag (as FORCENO option)

++++ rpm:

  - fix posttrans scriptlet argument in the update case [bsc#1243279]
    * updated patch: posttrans.diff
  - fix postuntrans scriptlets not being run if dump_posttrans is set

++++ openSUSE-repos-LeapMicro:

  - Fix url for Leap 16 tmp migration repo

++++ python-click:

  - Update to 8.2.1:
    * Fix flag value handling for flag options with a provided type.
    [#2894] #2897
    * Fix shell completion for nested groups. #2906
    * Flush sys.stderr at the end of CliRunner.invoke. #2682
    * Fix EOF handling for stdin input in CliRunner. #2787
  - Update URL.

------------------------------------------------------------------
------------------  2025-5-20  -  May 20 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Update live boot remote boot features
    Like the upstream module also support the root=live:http://...
    remote boot options. The kiwi-live dracut module is scheduled
    to become obsolete, but it's still in use and should support
    remote boot not only for AoE. As we got more issue reports than
    working AoE remote boot success, this commit also updates the
    documentation and switches to the capabilities of this PR.

++++ grub2:

  - Fix product name missing in snapshot list (bsc#1243162)
    * grub2-snapper-plugin.sh
  - Fix incorrect nvme disks and boot order in bootlist output (bsc#1237174)
    * 0001-ieee1275-support-added-for-multiple-nvme-bootpaths.patch

++++ guestfs-tools:

  - Update to version 1.54.0 (jsc#PED-12706)
    * bash: Replace 'cp -d' command with POSIX 'cp -P'
    * ocaml-link.sh.in: Remove redundant use of getopt
    * mltools: decouple and simplify osinfo device support checks
    * mlcustomize: disable `--inject-virtio-win osinfo`
    * mltools: Unreference various objects
    * Revert "mltools: Unreference various objects"
    * mltools: Fix memory leak in OCaml binding of libosinfo
    * mlstdutils: Implement String.implode
    * mlstdutils: Add List.make function
    * mltools: Fix spelling mistake
    * mlstdutils: Add List.same function
    * mlstdutils: Modify List.take, List.drop to match OCaml 5.3
    * mlstdutils: Rename List.dropwhile -> drop_while, takewhile -> take_while
    * mlstdutils: Add List.last function
    * mlstdutils: Move List module first
    * mlstdutils: Add String.common_prefix, longest_common_prefix
    * mlstdutils: Remove Std_utils.identity
    * mlstdutils: Remove Std_utils.protect
    * mlstdutils: Remove List.filter_map
    * mlstdutils: Fix comment that still referred to the old function names
    * mldrivers: Link to gettext-stub if ocaml-gettext is enabled
    * mlstdutils: Rename String.is_prefix -> starts_with, is_suffix -> ends_with

++++ jq:

  - Add patch CVE-2024-53427.patch (CVE-2024-53427, bsc#1238078)

++++ kernel-default:

  - perf: Fix hang while freeing sigtrap event (bsc#1242520
    CVE-2025-37747).
  - commit 6aa371b
  - btrfs: fix non-empty delayed iputs list on unmount due to
    compressed write workers (git-fixes).
  - commit 62a7e9f
  - btrfs: fix discard worker infinite loop after disabling discard
    (bsc#1242012).
  - commit 19ab462
  - btrfs: fix hole expansion when writing at an offset beyond EOF
    (bsc#1241151).
  - commit 8f434d2
  - NFSv4/pnfs: Reset the layout state after a layoutreturn
    (git-fixes).
  - commit f1c7782
  - nfs: handle failure of nfs_get_lock_context in unlock path
    (git-fixes).
  - commit c89f442
  - platform/x86/intel/pmc: Disable C1 auto-demotion during suspend
    (jsc#PED-12855).
  - commit 9c3ceb9
  - btrfs: avoid NULL pointer dereference if no valid csum tree
    (bsc#1243342).
  - commit 78306f4
  - btrfs: avoid NULL pointer dereference if no valid extent tree
    (bsc#1236208).
  - commit 2b0bc81
  - btrfs: adjust subpage bit start based on sectorsize
    (bsc#1241492).
  - commit 8f98bfc

++++ kernel-firmware-mediatek:

  - Update to version 20250520 (git commit 341b9e805613):
    * mediatek: Add mt8196 VCP firmware

++++ kernel-firmware-platform:

  - Update to version 20250520 (git commit 341b9e805613):
    * cnm: Add Chips&Media wave633c firmware for NXP i.MX9

++++ kernel-firmware-qcom:

  - Update to version 20250520 (git commit 341b9e805613):
    * Adjust QUPv3 driver name

++++ kernel-rt:

  - perf: Fix hang while freeing sigtrap event (bsc#1242520
    CVE-2025-37747).
  - commit 6aa371b
  - btrfs: fix non-empty delayed iputs list on unmount due to
    compressed write workers (git-fixes).
  - commit 62a7e9f
  - btrfs: fix discard worker infinite loop after disabling discard
    (bsc#1242012).
  - commit 19ab462
  - btrfs: fix hole expansion when writing at an offset beyond EOF
    (bsc#1241151).
  - commit 8f434d2
  - NFSv4/pnfs: Reset the layout state after a layoutreturn
    (git-fixes).
  - commit f1c7782
  - nfs: handle failure of nfs_get_lock_context in unlock path
    (git-fixes).
  - commit c89f442
  - platform/x86/intel/pmc: Disable C1 auto-demotion during suspend
    (jsc#PED-12855).
  - commit 9c3ceb9
  - btrfs: avoid NULL pointer dereference if no valid csum tree
    (bsc#1243342).
  - commit 78306f4
  - btrfs: avoid NULL pointer dereference if no valid extent tree
    (bsc#1236208).
  - commit 2b0bc81
  - btrfs: adjust subpage bit start based on sectorsize
    (bsc#1241492).
  - commit 8f98bfc

++++ util-linux-systemd:

  - Fix segfault of findmnt (boo#1242705,
    gh#util-linux/util-linux#3574,
    util-linux-libblkid-econf-parse.patch).

++++ util-linux:

  - Fix segfault of findmnt (boo#1242705,
    gh#util-linux/util-linux#3574,
    util-linux-libblkid-econf-parse.patch).

++++ libbpf:

  - update to 1.5.1:
    * Patch release with a single backported change that improves compatibility
    story of older versions of libbpf-cargo.
    https://github.com/libbpf/libbpf/commit/
    453601a65a6ebcf523b009585b49ce0ad0adeff1

++++ osinfo-db:

  - bsc#1243296 - What version of virt-manager-common supports SLES16
    ISO layout
    add-sles16-support.patch

++++ python-decorator:

  - Update to 5.2.1
    * Updated CHANGES.md
    * Update Makefile [ci skip]
    * Include tests and documentation in sdist
    * Managed functions without __name__
  - from version 5.2.0
    * Replace deprecated logging.warn with logging.warning
    * Add support for Python 3.11
    * Update download links
    * Fix codespell errors
    * Add support for decorative partial functions
    * Replace 'bytecode' by 'binary' in LICENSE.txt to align with BSD-2-Clause
    * Add support for Python 3.12
    * Stop testing EOL Python 3.5 and 3.6 due to CI unavailability
    * Requiring Python >= 3.7
    * Dropped support for Python <= 3.6
    * Use SPDX license identifier
    * Add support for Python 3.13
    * codespell: assertIn is not a typo
    * Testing only Python >= 3.8
    * Using asyncio.run
    * Replaced setup.py with pyproject
    * Updated copyright
    * Moved tests outside of src
  - Switch package to modern Python Stack on SLE-15
    * Use Python 3.11 on SLE-15 by default
    * Drop support for older Python versions
  - Switch build system from setuptools to pyproject.toml
    * Add python-pip and python-wheel to BuildRequires
    * Replace %python_build with %pyproject_wheel
    * Replace %python_install with %pyproject_install
    * Update name for dist directory in %files section

++++ python-typing_extensions:

  - Update to 4.13.2
    * Fix `TypeError` when taking the union of `typing_extensions.TypeAliasType`
    and a `typing.TypeAliasType` on Python 3.12 and 3.13.
    * Backport from CPython PR #132160) to avoid having user arguments
    shadowed in generated `__new__` by `@typing_extensions.deprecated`.
  - from version 4.13.1
    * Fix regression in 4.13.0 on Python 3.10.2 causing a `TypeError` when
    using `Concatenate`.
    * Fix `TypeError` when using `evaluate_forward_ref` on Python 3.10.1-2
    and 3.9.8-10.

------------------------------------------------------------------
------------------  2025-5-19  -  May 19 2025  -------------------
------------------------------------------------------------------

++++ afterburn:

  - Update to version 5.8.2:
    * cargo: Afterburn release 5.8.2
    * docs/release-notes: update for release 5.8.2
    * cargo: update dependencies
    * cargo: Afterburn release 5.8.1
    * cargo: Afterburn release 5.8.0
    * docs/release-notes: update for release 5.8.0
    * cargo: update dependencies
    this includes an update of the dependency idna, which
    fixes CVE-2024-12224 AKA bsc#1243850
    * packit: add initial support

++++ python-kiwi:

  - Add UKI support for the grub bootloader
    In addition to systemd_boot also add support for UKI creation
    when grub is used. This includes the creation of a UKI image
    via dracut in the same way as it's done for systemd_boot.
    In addition an earlyboot grub script chainloads the UKI and
    bypasses any written grub configuration. In Theory this should
    also allow to use the shim loader for chainloading an UKI.
    However I haven't done testing in this direction and I also
    expect security issues with this approach because loading
    any non signed data by shim is not expected to work. A new
    profile named grub_uki_verity_erofs has been added to the
    integration test that experiments with UKIs
  - Bump version: 10.2.22 → 10.2.23

++++ kernel-default:

  - Input: xpad - fix Share button on Xbox One controllers
    (stable-fixes).
  - Input: synaptics - enable InterTouch on Dell Precision M3800
    (stable-fixes).
  - Input: synaptics - enable InterTouch on TUXEDO InfinityBook
    Pro 14 v5 (stable-fixes).
  - Input: synaptics - enable InterTouch on Dynabook Portege X30L-G
    (stable-fixes).
  - Input: synaptics - enable InterTouch on Dynabook Portege X30-D
    (stable-fixes).
  - Input: synaptics - enable SMBus for HP Elitebook 850 G1
    (stable-fixes).
  - Input: xpad - add support for 8BitDo Ultimate 2 Wireless
    Controller (stable-fixes).
  - drm/xe/tests/mocs: Hold XE_FORCEWAKE_ALL for LNCF regs
    (git-fixes).
  - drm/amdgpu/vcn: using separate VCN1_AON_SOC offset
    (stable-fixes).
  - drm/amd/display: Fix the checking condition in dmub aux handling
    (stable-fixes).
  - drm/amd/display: more liberal vmin/vmax update for freesync
    (stable-fixes).
  - drm/v3d: Add job to pending list if the reset was skipped
    (stable-fixes).
  - Bluetooth: btmtk: Remove the resetting step before downloading
    the fw (stable-fixes).
  - Bluetooth: btmtk: Remove resetting mt7921 before downloading
    the fw (stable-fixes).
  - drm/xe/tests/mocs: Update xe_force_wake_get() return handling
    (stable-fixes).
  - commit c7fcf05
  - update metadata
  - Update
    patches.suse/nvme-fixup-scan-failure-for-non-ANA-multipath-contro.patch
    (jsc#PED-9651 bsc#1235149).
  - Update
    patches.suse/nvme-re-read-ANA-log-page-after-ns-scan-completes.patch
    (jsc#PED-9651 bsc#1235149).
  - commit fec09ab
  - Drivers: hv: vmbus: Remove vmbus_sendpacket_pagebuffer() (git-fixes).
  - hv_netvsc: Remove rmsg_pgcnt (git-fixes).
  - hv_netvsc: Preserve contiguous PFN grouping in the page buffer array (git-fixes).
  - hv_netvsc: Use vmbus_sendpacket_mpb_desc() to send VMBus messages (git-fixes).
  - Drivers: hv: Allow vmbus_sendpacket_mpb_desc() to create multiple ranges (git-fixes).
  - RDMA/mana_ib: Fix integer overflow during queue creation (git-fixes).
  - RDMA/mana_ib: Handle net event for pointing to the current netdev (git-fixes).
  - net: mana: Change the function signature of mana_get_primary_netdev_rcu (git-fixes).
  - RDMA/mana_ib: Use safer allocation function() (git-fixes).
  - RDMA/mana_ib: Implement DMABUF MR support (git-fixes).
  - RDMA/mana_ib: Fix error code in probe() (git-fixes).
  - RDMA/mana_ib: Add port statistics support (git-fixes).
  - RDMA/mana_ib: request error CQEs when supported (git-fixes).
  - RDMA/mana_ib: Query feature_flags bitmask from FW (git-fixes).
  - RDMA/mana_ib: indicate CM support (git-fixes).
  - RDMA/mana_ib: polling of CQs for GSI/UD (git-fixes).
  - RDMA/mana_ib: extend mana QP table (git-fixes).
  - RDMA/mana_ib: implement req_notify_cq (git-fixes).
  - RDMA/mana_ib: UD/GSI work requests (git-fixes).
  - RDMA/mana_ib: create/destroy AH (git-fixes).
  - RDMA/mana_ib: UD/GSI QP creation for kernel (git-fixes).
  - RDMA/mana_ib: Create and destroy UD/GSI QP (git-fixes).
  - RDMA/mana_ib: create kernel-level CQs (git-fixes).
  - RDMA/mana_ib: helpers to allocate kernel queues (git-fixes).
  - RDMA/mana_ib: implement get_dma_mr (git-fixes).
  - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (git-fixes).
  - commit 354638c
  - octeontx2-pf: Do not reallocate all ntuple filters (git-fixes).
  - netlink: specs: tc: all actions are indexed arrays (git-fixes).
  - netlink: specs: tc: fix a couple of attribute names (git-fixes).
  - octeontx2-pf: Fix ethtool support for SDP representors
    (git-fixes).
  - net/mlx5e: Disable MACsec offload for uplink representor profile
    (git-fixes).
  - net: qede: Initialize qede_ll_ops with designated initializer
    (git-fixes).
  - ice: use DSN instead of PCI BDF for ice_adapter index
    (git-fixes).
  - igc: fix lock order in igc_ptp_reset (git-fixes).
  - idpf: protect shutdown from reset (git-fixes).
  - idpf: fix potential memory leak on kcalloc() failure
    (git-fixes).
  - bnxt_en: fix module unload sequence (git-fixes).
  - bnxt_en: Fix ethtool -d byte order for 32-bit values
    (git-fixes).
  - bnxt_en: Fix out-of-bound memcpy() during ethtool -w
    (git-fixes).
  - bnxt_en: Fix coredump logic to free allocated buffer
    (git-fixes).
  - bnxt_en: call pci_alloc_irq_vectors() after bnxt_reserve_rings()
    (git-fixes).
  - bnxt_en: Add missing skb_mark_for_recycle() in bnxt_rx_vlan()
    (git-fixes).
  - bnxt_en: Fix ethtool selftest output in one of the failure cases
    (git-fixes).
  - bnxt_en: Fix error handling path in bnxt_init_chip()
    (git-fixes).
  - idpf: fix offloads support for encapsulated packets (git-fixes).
  - ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr()
    (git-fixes).
  - ice: fix Get Tx Topology AQ command error on E830 (git-fixes).
  - bnxt_en: improve TX timestamping FIFO configuration (git-fixes).
  - net/mlx5: E-switch, Fix error handling for enabling roce
    (git-fixes).
  - net/mlx5e: Fix lock order in
    mlx5e_tx_reporter_ptpsq_unhealthy_recover (git-fixes).
  - net/mlx5e: TC, Continue the attr process even if encap entry
    is invalid (git-fixes).
  - net/mlx5: E-Switch, Initialize MAC Address for Default GID
    (git-fixes).
  - net/mlx5e: Use custom tunnel header for vxlan gbp (git-fixes).
  - pds_core: make wait_context part of q_info (CVE-2025-37886
    bsc#1242944).
  - pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result
    (CVE-2025-37887 bsc#1242962).
  - ice: Remove unnecessary ice_is_e8xx() functions (git-fixes).
  - ice: Don't check device type when checking GNSS presence
    (git-fixes).
  - net: don't dump Tx and uninitialized NAPIs (git-fixes).
  - netdev-genl: avoid empty messages in napi get (git-fixes).
  - netdev-genl: avoid empty messages in queue dump (git-fixes).
  - netdev: fix repeated netlink messages in queue dump (git-fixes).
  - commit 18e8329
  - net: ppp: Add bound checking for skb data on ppp_sync_txmung (CVE-2025-37749 bsc#1242859)
  - commit 37d30d4
  - netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets (CVE-2025-22063 bsc#1241351)
  - commit 948ed51
  - rpm: Stop using is_kotd_qa macro
    This macro is set by bs-upload-kernel, and a conditional in each spec
    file is used to determine when to build the spec file.
    This logic should not really be in the spec file. Previously this was
    done with package links and package meta for the individula links.
    However, the use of package links is rejected for packages in git based
    release projects (nothing to do with git actually, new policy). An
    alternative to package links is multibuild. However, for multibuild
    packages package meta cannot be used to set which spec file gets built.
    Use prjcon buildflags instead, and remove this conditional. Depends on
    bs-upload-kernel adding the build flag.
  - commit 9eb8a6f
  - kernel-obs-qa: Use srchash for dependency as well
  - commit 485ae1d
  - scripts/common-functions: lower curl's connection timeout
    Set it to 2 seconds. Either it can reach the server or not...
    ftp.suse.com is currently unreachable and it takes minutes to have a
    reply from check-kernel-fixes.
  - commit f9f1100
  - Fix Patch-mainline tags.
  - Refresh
    patches.suse/RDMA-core-Fix-KASAN-slab-use-after-free-Read-in-ib_r.patch.
  - Refresh
    patches.suse/RDMA-rxe-Fix-slab-use-after-free-Read-in-rxe_queue_c.patch.
  - commit a8f3f2a
  - PCI/MSI: Handle the NOMASK flag correctly for all PCI/MSI
    backends (git-fixes).
  - Refresh
    patches.suse/PCI-MSI-Add-an-option-to-write-MSIX-ENTRY_DATA-befor.patch.
  - commit bedc18c
  - s390/pci: Fix duplicate pci_dev_put() in disable_slot() when
    PF has child VFs (git-fixes).
  - PCI/MSI: Convert pci_msi_ignore_mask to per MSI domain flag
    (git-fixes).
  - commit 55e48e2
  - ocfs2: fix the issue with discontiguous allocation in the
    global_bitmap (git-fixes).
  - commit 309b543

++++ kernel-firmware-amdgpu:

  - Update to version 20250516 (git commit 759c4acafb4a):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-firmware-bluetooth:

  - Update to version 20250516 (git commit 759c4acafb4a):
    * rtl_bt: Update RTL8822C BT USB and UART firmware to 0x7C20

++++ kernel-firmware-brcm:

  - Update to version 20250516 (git commit 759c4acafb4a):
    * brcmfmac: Add a couple of NanoPi devices

++++ kernel-firmware-nvidia:

  - Update to version 20250516 (git commit 759c4acafb4a):
    * nvidia: add GSP-RM version 570.144 firmware images

++++ kernel-firmware-platform:

  - Update to version 20250516 (git commit 759c4acafb4a):
    * powervr: add firmware for Imagination Technologies BXS-4-64 GPU
    * cnm: update chips&media wave521c firmware.

++++ kernel-firmware-realtek:

  - Update to version 20250516 (git commit 759c4acafb4a):
    * rtl_nic: add firmware rtl8127a-1

++++ kernel-rt:

  - Input: xpad - fix Share button on Xbox One controllers
    (stable-fixes).
  - Input: synaptics - enable InterTouch on Dell Precision M3800
    (stable-fixes).
  - Input: synaptics - enable InterTouch on TUXEDO InfinityBook
    Pro 14 v5 (stable-fixes).
  - Input: synaptics - enable InterTouch on Dynabook Portege X30L-G
    (stable-fixes).
  - Input: synaptics - enable InterTouch on Dynabook Portege X30-D
    (stable-fixes).
  - Input: synaptics - enable SMBus for HP Elitebook 850 G1
    (stable-fixes).
  - Input: xpad - add support for 8BitDo Ultimate 2 Wireless
    Controller (stable-fixes).
  - drm/xe/tests/mocs: Hold XE_FORCEWAKE_ALL for LNCF regs
    (git-fixes).
  - drm/amdgpu/vcn: using separate VCN1_AON_SOC offset
    (stable-fixes).
  - drm/amd/display: Fix the checking condition in dmub aux handling
    (stable-fixes).
  - drm/amd/display: more liberal vmin/vmax update for freesync
    (stable-fixes).
  - drm/v3d: Add job to pending list if the reset was skipped
    (stable-fixes).
  - Bluetooth: btmtk: Remove the resetting step before downloading
    the fw (stable-fixes).
  - Bluetooth: btmtk: Remove resetting mt7921 before downloading
    the fw (stable-fixes).
  - drm/xe/tests/mocs: Update xe_force_wake_get() return handling
    (stable-fixes).
  - commit c7fcf05
  - update metadata
  - Update
    patches.suse/nvme-fixup-scan-failure-for-non-ANA-multipath-contro.patch
    (jsc#PED-9651 bsc#1235149).
  - Update
    patches.suse/nvme-re-read-ANA-log-page-after-ns-scan-completes.patch
    (jsc#PED-9651 bsc#1235149).
  - commit fec09ab
  - Drivers: hv: vmbus: Remove vmbus_sendpacket_pagebuffer() (git-fixes).
  - hv_netvsc: Remove rmsg_pgcnt (git-fixes).
  - hv_netvsc: Preserve contiguous PFN grouping in the page buffer array (git-fixes).
  - hv_netvsc: Use vmbus_sendpacket_mpb_desc() to send VMBus messages (git-fixes).
  - Drivers: hv: Allow vmbus_sendpacket_mpb_desc() to create multiple ranges (git-fixes).
  - RDMA/mana_ib: Fix integer overflow during queue creation (git-fixes).
  - RDMA/mana_ib: Handle net event for pointing to the current netdev (git-fixes).
  - net: mana: Change the function signature of mana_get_primary_netdev_rcu (git-fixes).
  - RDMA/mana_ib: Use safer allocation function() (git-fixes).
  - RDMA/mana_ib: Implement DMABUF MR support (git-fixes).
  - RDMA/mana_ib: Fix error code in probe() (git-fixes).
  - RDMA/mana_ib: Add port statistics support (git-fixes).
  - RDMA/mana_ib: request error CQEs when supported (git-fixes).
  - RDMA/mana_ib: Query feature_flags bitmask from FW (git-fixes).
  - RDMA/mana_ib: indicate CM support (git-fixes).
  - RDMA/mana_ib: polling of CQs for GSI/UD (git-fixes).
  - RDMA/mana_ib: extend mana QP table (git-fixes).
  - RDMA/mana_ib: implement req_notify_cq (git-fixes).
  - RDMA/mana_ib: UD/GSI work requests (git-fixes).
  - RDMA/mana_ib: create/destroy AH (git-fixes).
  - RDMA/mana_ib: UD/GSI QP creation for kernel (git-fixes).
  - RDMA/mana_ib: Create and destroy UD/GSI QP (git-fixes).
  - RDMA/mana_ib: create kernel-level CQs (git-fixes).
  - RDMA/mana_ib: helpers to allocate kernel queues (git-fixes).
  - RDMA/mana_ib: implement get_dma_mr (git-fixes).
  - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (git-fixes).
  - commit 354638c
  - octeontx2-pf: Do not reallocate all ntuple filters (git-fixes).
  - netlink: specs: tc: all actions are indexed arrays (git-fixes).
  - netlink: specs: tc: fix a couple of attribute names (git-fixes).
  - octeontx2-pf: Fix ethtool support for SDP representors
    (git-fixes).
  - net/mlx5e: Disable MACsec offload for uplink representor profile
    (git-fixes).
  - net: qede: Initialize qede_ll_ops with designated initializer
    (git-fixes).
  - ice: use DSN instead of PCI BDF for ice_adapter index
    (git-fixes).
  - igc: fix lock order in igc_ptp_reset (git-fixes).
  - idpf: protect shutdown from reset (git-fixes).
  - idpf: fix potential memory leak on kcalloc() failure
    (git-fixes).
  - bnxt_en: fix module unload sequence (git-fixes).
  - bnxt_en: Fix ethtool -d byte order for 32-bit values
    (git-fixes).
  - bnxt_en: Fix out-of-bound memcpy() during ethtool -w
    (git-fixes).
  - bnxt_en: Fix coredump logic to free allocated buffer
    (git-fixes).
  - bnxt_en: call pci_alloc_irq_vectors() after bnxt_reserve_rings()
    (git-fixes).
  - bnxt_en: Add missing skb_mark_for_recycle() in bnxt_rx_vlan()
    (git-fixes).
  - bnxt_en: Fix ethtool selftest output in one of the failure cases
    (git-fixes).
  - bnxt_en: Fix error handling path in bnxt_init_chip()
    (git-fixes).
  - idpf: fix offloads support for encapsulated packets (git-fixes).
  - ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr()
    (git-fixes).
  - ice: fix Get Tx Topology AQ command error on E830 (git-fixes).
  - bnxt_en: improve TX timestamping FIFO configuration (git-fixes).
  - net/mlx5: E-switch, Fix error handling for enabling roce
    (git-fixes).
  - net/mlx5e: Fix lock order in
    mlx5e_tx_reporter_ptpsq_unhealthy_recover (git-fixes).
  - net/mlx5e: TC, Continue the attr process even if encap entry
    is invalid (git-fixes).
  - net/mlx5: E-Switch, Initialize MAC Address for Default GID
    (git-fixes).
  - net/mlx5e: Use custom tunnel header for vxlan gbp (git-fixes).
  - pds_core: make wait_context part of q_info (CVE-2025-37886
    bsc#1242944).
  - pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result
    (CVE-2025-37887 bsc#1242962).
  - ice: Remove unnecessary ice_is_e8xx() functions (git-fixes).
  - ice: Don't check device type when checking GNSS presence
    (git-fixes).
  - net: don't dump Tx and uninitialized NAPIs (git-fixes).
  - netdev-genl: avoid empty messages in napi get (git-fixes).
  - netdev-genl: avoid empty messages in queue dump (git-fixes).
  - netdev: fix repeated netlink messages in queue dump (git-fixes).
  - commit 18e8329
  - net: ppp: Add bound checking for skb data on ppp_sync_txmung (CVE-2025-37749 bsc#1242859)
  - commit 37d30d4
  - netlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets (CVE-2025-22063 bsc#1241351)
  - commit 948ed51
  - rpm: Stop using is_kotd_qa macro
    This macro is set by bs-upload-kernel, and a conditional in each spec
    file is used to determine when to build the spec file.
    This logic should not really be in the spec file. Previously this was
    done with package links and package meta for the individula links.
    However, the use of package links is rejected for packages in git based
    release projects (nothing to do with git actually, new policy). An
    alternative to package links is multibuild. However, for multibuild
    packages package meta cannot be used to set which spec file gets built.
    Use prjcon buildflags instead, and remove this conditional. Depends on
    bs-upload-kernel adding the build flag.
  - commit 9eb8a6f
  - kernel-obs-qa: Use srchash for dependency as well
  - commit 485ae1d
  - scripts/common-functions: lower curl's connection timeout
    Set it to 2 seconds. Either it can reach the server or not...
    ftp.suse.com is currently unreachable and it takes minutes to have a
    reply from check-kernel-fixes.
  - commit f9f1100
  - Fix Patch-mainline tags.
  - Refresh
    patches.suse/RDMA-core-Fix-KASAN-slab-use-after-free-Read-in-ib_r.patch.
  - Refresh
    patches.suse/RDMA-rxe-Fix-slab-use-after-free-Read-in-rxe_queue_c.patch.
  - commit a8f3f2a
  - PCI/MSI: Handle the NOMASK flag correctly for all PCI/MSI
    backends (git-fixes).
  - Refresh
    patches.suse/PCI-MSI-Add-an-option-to-write-MSIX-ENTRY_DATA-befor.patch.
  - commit bedc18c
  - s390/pci: Fix duplicate pci_dev_put() in disable_slot() when
    PF has child VFs (git-fixes).
  - PCI/MSI: Convert pci_msi_ignore_mask to per MSI domain flag
    (git-fixes).
  - commit 55e48e2
  - ocfs2: fix the issue with discontiguous allocation in the
    global_bitmap (git-fixes).
  - commit 309b543

++++ ncurses:

  - Add ncurses patch 20250517
    + initial changes for some ABI 7 features:
    + disable wgetch-events
    + add feature for extending mouse-buttons
    + add feature for extending direct-color support
    + use bracketed+paste in nsterm, rlogin-color, screen, terminology -TD
  - First steps to support ABI 7
  - Update to tack-1.11-20250503
    * 2025/04/29 Add checks for RV/rv and XR/xr

++++ pam_pkcs11:

  - Removes pam_env from auth stack for security reason [bsc#1243226]

++++ virt-manager:

  - Add detection code for SLES 16 media (bsc#1236252, bsc#1243296)
    virtinst-add-sle16-detection-support.patch

------------------------------------------------------------------
------------------  2025-5-18  -  May 18 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - dmaengine: mediatek: drop unused variable (git-fixes).
  - dmaengine: idxd: Fix ->poll() return value (git-fixes).
  - phy: tegra: xusb: remove a stray unlock (git-fixes).
  - commit 3ca33c7
  - dmaengine: fsl-edma: Fix return code for unhandled interrupts
    (git-fixes).
  - dmaengine: mediatek: Fix a possible deadlock error in
    mtk_cqdma_tx_status() (git-fixes).
  - dmaengine: idxd: Refactor remove call with idxd_cleanup()
    helper (git-fixes).
  - dmaengine: idxd: Add missing idxd cleanup to fix memory leak
    in remove call (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_pci_probe (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_alloc (git-fixes).
  - dmaengine: idxd: Add missing cleanups in cleanup internals
    (git-fixes).
  - dmaengine: idxd: Add missing cleanup for early error out in
    idxd_setup_internals (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_setup_groups (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_setup_engines (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_setup_wqs (git-fixes).
  - dmaengine: idxd: Fix allowing write() from different address
    spaces (git-fixes).
  - dmaengine: ti: k3-udma: Add missing locking (git-fixes).
  - dmaengine: ti: k3-udma: Use cap_mask directly from dma_device
    structure instead of a local copy (git-fixes).
  - dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting
    less when interrupted" (git-fixes).
  - phy: Fix error handling in tegra_xusb_port_init (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Set timing registers only once
    (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Fix role detection on unbind/bind
    (git-fixes).
  - phy: tegra: xusb: Use a bitmask for UTMI pad power state
    tracking (git-fixes).
  - soundwire: bus: Fix race on the creation of the IRQ domain
    (git-fixes).
  - i2c: designware: Fix an error handling path in
    i2c_dw_pci_probe() (git-fixes).
  - commit eac523c
  - loop: aio inherit the ioprio of original request (git-fixes).
  - Refresh
    patches.suse/loop-stop-using-vfs_iter_-read-write-for-buffered-I-O.patch.
  - commit 3ecd666

++++ kernel-rt:

  - dmaengine: mediatek: drop unused variable (git-fixes).
  - dmaengine: idxd: Fix ->poll() return value (git-fixes).
  - phy: tegra: xusb: remove a stray unlock (git-fixes).
  - commit 3ca33c7
  - dmaengine: fsl-edma: Fix return code for unhandled interrupts
    (git-fixes).
  - dmaengine: mediatek: Fix a possible deadlock error in
    mtk_cqdma_tx_status() (git-fixes).
  - dmaengine: idxd: Refactor remove call with idxd_cleanup()
    helper (git-fixes).
  - dmaengine: idxd: Add missing idxd cleanup to fix memory leak
    in remove call (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_pci_probe (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_alloc (git-fixes).
  - dmaengine: idxd: Add missing cleanups in cleanup internals
    (git-fixes).
  - dmaengine: idxd: Add missing cleanup for early error out in
    idxd_setup_internals (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_setup_groups (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_setup_engines (git-fixes).
  - dmaengine: idxd: fix memory leak in error handling path of
    idxd_setup_wqs (git-fixes).
  - dmaengine: idxd: Fix allowing write() from different address
    spaces (git-fixes).
  - dmaengine: ti: k3-udma: Add missing locking (git-fixes).
  - dmaengine: ti: k3-udma: Use cap_mask directly from dma_device
    structure instead of a local copy (git-fixes).
  - dmaengine: Revert "dmaengine: dmatest: Fix dmatest waiting
    less when interrupted" (git-fixes).
  - phy: Fix error handling in tegra_xusb_port_init (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Set timing registers only once
    (git-fixes).
  - phy: renesas: rcar-gen3-usb2: Fix role detection on unbind/bind
    (git-fixes).
  - phy: tegra: xusb: Use a bitmask for UTMI pad power state
    tracking (git-fixes).
  - soundwire: bus: Fix race on the creation of the IRQ domain
    (git-fixes).
  - i2c: designware: Fix an error handling path in
    i2c_dw_pci_probe() (git-fixes).
  - commit eac523c
  - loop: aio inherit the ioprio of original request (git-fixes).
  - Refresh
    patches.suse/loop-stop-using-vfs_iter_-read-write-for-buffered-I-O.patch.
  - commit 3ecd666

------------------------------------------------------------------
------------------  2025-5-17  -  May 17 2025  -------------------
------------------------------------------------------------------

++++ fuse-overlayfs:

  - update to 0.15:
    * main: lookup upperdir only for created directories
    * main: allow escaped colons in directory paths
    * main: use extended override xattr to support devices
    * remove unsupported option "lazytime"

++++ kernel-default:

  - block: fix conversion of GPT partition name to 7-bit
    (git-fixes).
  - block: fix 'kmem_cache of name 'bio-108' already exists'
    (git-fixes).
  - commit 3799862
  - drm/xe: Save CTX_TIMESTAMP mmio value instead of LRC value
    (git-fixes).
  - commit 239d430
  - dma-buf: insert memory barrier before updating num_fences
    (git-fixes).
  - drm/meson: Use 1000ULL when operating with mode->clock
    (git-fixes).
  - Revert "drm/amd/display: Hardware cursor changes color when
    switched to software cursor" (stable-fixes).
  - ACPI: PPTT: Fix processor subtable walk (git-fixes).
  - spi: tegra114: Use value to check for invalid delays
    (git-fixes).
  - spi: loopback-test: Do not split 1024-byte hexdumps (git-fixes).
  - regulator: max20086: fix invalid memory access (git-fixes).
  - gpio: pca953x: fix IRQ storm on system wake up (git-fixes).
  - ALSA: es1968: Add error handling for
    snd_pcm_hw_constraint_pow2() (git-fixes).
  - ALSA: sh: SND_AICA should depend on SH_DMA_API (git-fixes).
  - ALSA: usb-audio: Add sample rate quirk for Audioengine D1
    (git-fixes).
  - ALSA: ump: Fix a typo of snd_ump_stream_msg_device_info
    (git-fixes).
  - ALSA: seq: Fix delivery of UMP events to group ports
    (git-fixes).
  - commit c704699

++++ kernel-rt:

  - block: fix conversion of GPT partition name to 7-bit
    (git-fixes).
  - block: fix 'kmem_cache of name 'bio-108' already exists'
    (git-fixes).
  - commit 3799862
  - drm/xe: Save CTX_TIMESTAMP mmio value instead of LRC value
    (git-fixes).
  - commit 239d430
  - dma-buf: insert memory barrier before updating num_fences
    (git-fixes).
  - drm/meson: Use 1000ULL when operating with mode->clock
    (git-fixes).
  - Revert "drm/amd/display: Hardware cursor changes color when
    switched to software cursor" (stable-fixes).
  - ACPI: PPTT: Fix processor subtable walk (git-fixes).
  - spi: tegra114: Use value to check for invalid delays
    (git-fixes).
  - spi: loopback-test: Do not split 1024-byte hexdumps (git-fixes).
  - regulator: max20086: fix invalid memory access (git-fixes).
  - gpio: pca953x: fix IRQ storm on system wake up (git-fixes).
  - ALSA: es1968: Add error handling for
    snd_pcm_hw_constraint_pow2() (git-fixes).
  - ALSA: sh: SND_AICA should depend on SH_DMA_API (git-fixes).
  - ALSA: usb-audio: Add sample rate quirk for Audioengine D1
    (git-fixes).
  - ALSA: ump: Fix a typo of snd_ump_stream_msg_device_info
    (git-fixes).
  - ALSA: seq: Fix delivery of UMP events to group ports
    (git-fixes).
  - commit c704699

------------------------------------------------------------------
------------------  2025-5-16  -  May 16 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - aarch64: enable panfrost vulkan driver on Leap 16.0

++++ Mesa-drivers:

  - aarch64: enable panfrost vulkan driver on Leap 16.0

++++ dhcpcd:

  - Update to 10.2.3
    * Restore logic on when to open an address specific socket
    * [Fix] DHCP Failure on WAN Interface Rename (Fixes #504)
    * BSD: routes via P2P interfaces now find their out-going
    interface
    * -b --background fixed
    * resolv: Fix processing more DNSSL options than RDNSS]
    * dhcpcd: Remove option rapid_commit from dhcpcd.conf
    * privsep: Fix valgrind and hardened-malloc on Linux with SECCOMP
    * route: Don't spam route changes for lifetime

++++ python-kiwi:

  - Add support for <initrd> section as part of <type>
    Extend scope and content of the <initrd> section to be allowed
    as part of the <type> section. This allows to specify custom
    call options and modules for the dracut tool. In particular
    this commit implementes support for passing the uefi option
    to dracut to enable building an UKI EFI binary as follows:
    <initrd action="setup">
    <dracut uefi="true"/>
    </initrd>
    This Fixes #2809 and Fixes #2408
  - Fix systemd-boot loader setup
    To make sure only loader entries from /boot/efi/loader/entries
    kiwi deleted eventually existing entry files from /boot/loader.
    However that is a problem for read-only systems and should actually
    also not performed by kiwi. This Fixes #2805

++++ iputils:

  - Fix bsc#1243284 - ping on s390x prints invalid ttl
    * Add iputils-invalid-ttl-s390x.patch
    * Fix ipv4 ttl value when using SOCK_DGRAM on big endian systems
  - Enable test suite

++++ kernel-default:

  - scsi: Improve CDL control (git-fixes).
  - md/raid1: Add check for missing source disk in process_checks()
    (git-fixes).
  - scsi: pm80xx: Set phy_attached to zero when device is gone
    (git-fixes).
  - scsi: hisi_sas: Fix I/O errors caused by hardware port ID
    changes (git-fixes).
  - scsi: mpi3mr: Avoid reply queue full condition (git-fixes).
  - scsi: core: Use GFP_NOIO to avoid circular locking dependency
    (git-fixes).
  - commit 0aaea76
  - x86/sev: Register tpm-svsm platform device (bsc#1241191).
  - svsm: Add header with SVSM_VTPM_CMD helpers (bsc#1241191).
  - x86/sev: Add SVSM vTPM probe/send_command functions
    (bsc#1241191).
  - tpm: Make chip->{status,cancel,req_canceled} opt (bsc#1241191).
  - commit a35885f
  - x86/its: Fix build errors when CONFIG_MODULES=n (git-fixes).
  - commit ed63681
  - x86/ibt: Fix hibernate (git-fixes).
  - commit 8f9d1f8
  - module: don't annotate ROX memory as kmemleak_not_leak() (git-fixes).
  - commit d3cd47f
  - module: fix writing of livepatch relocations in ROX text (git-fixes).
  - Refresh
    patches.suse/module-switch-to-execmem-API-for-remapping-as-RW-and-resto.patch.
  - commit 422351f
  - x86/execmem: fix ROX cache usage in Xen PV guests (git-fixes).
  - commit f9895f4
  - scripts/common-functions: fix sha_to_patch_in_branch
    sha_to_patch_in_branch f13abc1e8e1a3b7455511c4e122750127f6bc9b0 origin/SLE15-SP6
    returns
    origin/SLE15-SP6:patches.suse/watch_queue-fix-pipe-accounting-mismatch.patch
    which is obviously incorrect. We need to trim the branch name before
    filtering.
  - commit e2cf22b
  - spi: fsl-qspi: Fix double cleanup in probe error path
    (CVE-2025-37842 bsc#1242951).
  - spi: fsl-qspi: use devm function instead of driver remove
    (CVE-2025-37842 bsc#1242951).
  - commit 60d462a
  - netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in
    insert_tree() (CVE-2025-21959 bsc#1240814).
  - commit 4b2c620
  - qibfs: fix _another_ leak (git-fixes)
  - commit 62b6060
  - mm/vma: add give_up_on_oom option on modify/merge, use in uffd
    release (CVE-2025-37760 bsc#1242726).
  - commit 5e60119
  - RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem (git-fixes)
  - commit 86e6715
  - RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug (git-fixes)
  - commit 1900b07
  - tpm: Mask TPM RC in tpm2_start_auth_session() (git-fixes).
  - commit 6d86701
  - ovl: don't allow datadir only (CVE-2025-37863 bsc#1242969).
  - commit 56c14ec

++++ kernel-rt:

  - scsi: Improve CDL control (git-fixes).
  - md/raid1: Add check for missing source disk in process_checks()
    (git-fixes).
  - scsi: pm80xx: Set phy_attached to zero when device is gone
    (git-fixes).
  - scsi: hisi_sas: Fix I/O errors caused by hardware port ID
    changes (git-fixes).
  - scsi: mpi3mr: Avoid reply queue full condition (git-fixes).
  - scsi: core: Use GFP_NOIO to avoid circular locking dependency
    (git-fixes).
  - commit 0aaea76
  - x86/sev: Register tpm-svsm platform device (bsc#1241191).
  - svsm: Add header with SVSM_VTPM_CMD helpers (bsc#1241191).
  - x86/sev: Add SVSM vTPM probe/send_command functions
    (bsc#1241191).
  - tpm: Make chip->{status,cancel,req_canceled} opt (bsc#1241191).
  - commit a35885f
  - x86/its: Fix build errors when CONFIG_MODULES=n (git-fixes).
  - commit ed63681
  - x86/ibt: Fix hibernate (git-fixes).
  - commit 8f9d1f8
  - module: don't annotate ROX memory as kmemleak_not_leak() (git-fixes).
  - commit d3cd47f
  - module: fix writing of livepatch relocations in ROX text (git-fixes).
  - Refresh
    patches.suse/module-switch-to-execmem-API-for-remapping-as-RW-and-resto.patch.
  - commit 422351f
  - x86/execmem: fix ROX cache usage in Xen PV guests (git-fixes).
  - commit f9895f4
  - scripts/common-functions: fix sha_to_patch_in_branch
    sha_to_patch_in_branch f13abc1e8e1a3b7455511c4e122750127f6bc9b0 origin/SLE15-SP6
    returns
    origin/SLE15-SP6:patches.suse/watch_queue-fix-pipe-accounting-mismatch.patch
    which is obviously incorrect. We need to trim the branch name before
    filtering.
  - commit e2cf22b
  - spi: fsl-qspi: Fix double cleanup in probe error path
    (CVE-2025-37842 bsc#1242951).
  - spi: fsl-qspi: use devm function instead of driver remove
    (CVE-2025-37842 bsc#1242951).
  - commit 60d462a
  - netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in
    insert_tree() (CVE-2025-21959 bsc#1240814).
  - commit 4b2c620
  - qibfs: fix _another_ leak (git-fixes)
  - commit 62b6060
  - mm/vma: add give_up_on_oom option on modify/merge, use in uffd
    release (CVE-2025-37760 bsc#1242726).
  - commit 5e60119
  - RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem (git-fixes)
  - commit 86e6715
  - RDMA/rxe: Fix slab-use-after-free Read in rxe_queue_cleanup bug (git-fixes)
  - commit 1900b07
  - tpm: Mask TPM RC in tpm2_start_auth_session() (git-fixes).
  - commit 6d86701
  - ovl: don't allow datadir only (CVE-2025-37863 bsc#1242969).
  - commit 56c14ec

++++ python313-core:

  - Add CVE-2025-4516-DecodeError-handler.patch fixing
    CVE-2025-4516 (bsc#1243273) blocking DecodeError handling
    vulnerability, which could lead to DoS.

++++ systemd:

  - Import commit 8e9840a2897e36ae3f926f8d10a2b0d7e4102c67 (bsc#1243280)
    8e9840a289 bless-boot: never try to rename an entry file onto itself
    5b5cde8866 bless-boot: in "status" output report bad state from prev boot as "dirty"
    49949fa9fb bless-boot: switch from last_path_component() to path_find_last_component()

++++ python313:

  - Add CVE-2025-4516-DecodeError-handler.patch fixing
    CVE-2025-4516 (bsc#1243273) blocking DecodeError handling
    vulnerability, which could lead to DoS.

++++ python-tornado6:

  - Update to 6.5.0 (CVE-2025-47287, bsc#1243268):
    * Security Improvements:
  - Previously, malformed multipart-form-data requests could log
    multiple warnings and constitute a denial-of-service attack. Now
    an exception is raised at the first error, so there is only one
    log message per request. This fixes CVE-2025-47287.
    * General Changes:
  - Python 3.14 is now supported. Older versions of Tornado will
    work on Python 3.14 but may log deprecation warnings.
  - The free-threading mode of Python 3.13 is now supported on an
    experimental basis. Prebuilt wheels are not yet available for
    this configuration, but it can be built from source.
  - The minimum supported Python version is 3.9.
    * Deprecation Notices:
  - Support for obs-fold continuation lines in HTTP headers is
    deprecated and will be removed in Tornado 7.0, as is the use of
    carriage returns without line feeds as header separators.
  - The callback argument to websocket_connect is deprecated and
    will be removed in Tornado 7.0. Note that on_message_callback is
    not deprecated.
  - The log_message and args attributes of tornado.web.HTTPError are
    deprecated. Use the new get_message method instead.

------------------------------------------------------------------
------------------  2025-5-15  -  May 15 2025  -------------------
------------------------------------------------------------------

++++ aardvark-dns:

  - spec: require cargo instead of rust+cargo; drop redundant comment

++++ cloud-init:

  - Update to version 25.1.1 (bsc#1239715,jsc#PED-8680,bsc#1228414)
    + Removed included upstream
  - pep-594-drop-pipes.patch
  - cloud-init-fix-python313.patch
  - cloud-init-dont-assume-ordering-of-ThreadPoolExecutor.patch
  - cloud-init-direxist.patch
  - cloud-init-wait-for-net.patch
  - cloud-init-usr-sudoers.patch
  - cloud-init-no-nmcfg-needed.patch
  - cloud-init-keep-flake.patch
  - cloud-init-lint-fixes.patch
  - cloud-init-pckg-reboot.patch
  - cloud-init-ds-deterministic.patch
  - cloud-init-write-routes.patch
  - cloud-init-skip-empty-conf.patch
    + Forward port
  - cloud-init-no-tempnet-oci.patch
  - cloud-init-no-openstack-guess.patch
  - cloud-init-lint-set-interpreter.patch
    + Add
  - cloud-init-ssh-usrmerge.patch (bsc#1237764)
  - cloud-init-lint-set-interpreter.patch
  - cloud-init-lint-fix.patch
  - cloud-init-no-single-process.patch
  - cloud-init-needs-action.patch
    + Drop hidesensitivedata in 16 & greater
    + test: pytestify cc_chef tests, add migration test
    + chef: migrate files in old config directories for backups and cache
    + fix: correct the path for Chef's backups (#5994)
    + fix(Azure): don't reraise FileNotFoundError during ephemeral setup (#6113)
    + fix(azure): handle unexpected exceptions during obtain_lease() (#6092)
    [Ksenija Stanojevic]
    + Allow to set mac_address for VLAN subinterface (#6081)
    [jumpojoy] (GH: 5364)
    + fix: Remove erroneous EC2 reference from 503 warning (#6077)
    + fix: NM reload and bring up individual network conns (#6073) [Ani Sinha]
    + fix: stop warning on dual-stack request failure (#6044)
    + fix: install_method: pip cannot find ansible-pull command path (#6021)
    [Hasan Aliyev] (GH: 5720)
    + fix: Fix DataSourceAliYun exception_cb signature (#6068) (GH: 6066)
    + fix: Update OauthUrlHelper to use readurl exception_cb signature
    (GH: 6065)
    + test: add OauthUrlHelper tests
    + test: Remove CiTestCase from test_url_helper.py
    + test: pytestify test_url_helper.py
    + fix: track more removed modules (#6043)
  - From 25.1
    + ci: fix post-merge packaging CI (#6038)
    + feat(azure): Fix imds-based ssh_pwauth (#6002) [Ksenija Stanojevic]
    + ci: check for sorted patches (#6036)
    + feat: aliyun datasource support crawl metadata at once (#5942)
    [jinkangkang]
    + docs: document /usr merge breaking change (#6032)
    + test: Add integration test for /var mounts (#6033)
    + test: Ensure pre-24.2 custom modules work (#6034)
    + doc: Update references to older keys (#6022) [Pedro Ribeiro]
    + fix: untyped-defs in tests/unittests/{config, net, sources} (#6023)
    [Romain]
    + fix: don't reference PR in post-merged CI (#6019)
    + chore: explicitly skip broken ansible integration tests (#5996) [a-dubs]
    + tests(oracle): fix test_install_missing_deps apt race condition (#5996)
    [a-dubs]
    + test(oracle): fix test_ubuntu_drivers_installed (#5996) [a-dubs]
    + test(oracle): fix test_frequency_override integration test (#5996)
    [a-dubs]
    + chore: add type hint to IntegrationCloud's cloud_instance field (#5996)
    [a-dubs]
    + test(oracle): fix modules/test_lxd.py::test_storage_lvm on noble (#5996)
    [a-dubs]
    + commit 9e591fff266be9d4c83f74ec02a717b74993304d [a-dubs]
    + net/sysconfig: do not remove all existing settings of
    /etc/sysconfig/network (#5991) [Ani Sinha] (GH: 5990)
    + fix: remove wrong return when checking if network necessary (#6013)
    + fix: typing for rsyslog, ubuntu_pro, power_state_change (#5985)
    [MostafaTarek124eru]
    + fix: Retry on OpenStack HTTP status codes (#5943) [weiyang] (GH: 5687)
    + fix: Ensure fqdn is treated as string in get_hostname_fqdn (#5993)
    [MKhatibzadeh] (GH: 5989)
    + feat(vmware): Convert imc network config to v2 (#5937) [PengpengSun]
    + ci: add upstream post-merge test
    + ci: check if upstream commit causes ubuntu patch conflicts
    + ci: organize cla tests together
    + test: eliminate obsolete cases, add non-error case
    + chore: remove redundant manual schema validation
    + doc: clarify subiquity docs
    + chore: cleanup `len' usage (#5956) [Shreenidhi Shedi]
    + Fix: GCE _get_data crashes if DHCP lease fails (#5998) [Bryan Fraschetti]
    + Fixes GH-5997
    + fix: correct the path for Chef's cache (#5994)
    [MostafaTarek124eru] (GH: 5090)
    + fix: Run ansible with run_user instead of root for distro install_method
    (#5986) [Amirhossein Shaerpour] (GH: 4092)
    + fix: retry AWS hotplug for async IMDS (#5995) (GH: 5373)
    + feat(integration_tests): add optional INSTANCE_TYPE setting (#5988)
    [Alec Warren]
    + feat(integration-tests): set boto3 and botocore to INFO to prevent
    log spamming [a-dubs]
    + ci: add 'tox -e integration-tests-fast' command [a-dubs]
    + chore: Add feature flag for manual network waiting (#5977)
    + Release 24.4.1
    + fix: Use /usr/lib/ rather than /lib in packaging code (#5970)
    + Use log_with_downgradable_level for user password warnings (#5927)
    [Ani Sinha]
    + doc: change to hyphenated keys (#5909) (GH: 5555)
    + fix: Wait for udev on openstack (#5947) [Robert Schweikert] (GH: 4125)
    + test: disambiguate resource cleanup from test failure (#5926)
    + fix: use program name of netcat as installed by upstream, "nc" (#5933)
    (#5933) [Andreas K. Hüttel]
    + ci: bump canonical/setup-lxd to version v0.1.2 (#5948)
    + feat(cc_chef): Allow change of Chef configuration file (#5925)
    [Sean Smith]
    + docs: fix typo in generated file in LXD tutorial (#5941) [Pavel Shpak]
    + feat: Identify Samsung Cloud Platform as OpenStack (#5924) [us0310306]
    + fix: don't deadlock when starting network service with systemctl (#5935)
    + feat: Custom keys for apt archives (#5828) [Bryan Fraschetti] (GH: 5473)
    + test: improve test initialization error path (#5920)
    + chore: improve logging when lxd detection fails (#5919)
    + fix: Add "manual" to allowed subnet types  (#5875)
    [Math Marchand] (GH: 5769)
    + fix: remove bad ssh_svcname setting for Gentoo/OpenRC (#5918)
    [Andreas K. Hüttel]
    + feat(gentoo): Add compatibility for Gentoo with systemd (#5918)
    [Andreas K. Hüttel]
    + fix(ovf): no warning should be log when rpctool found no value (#5915)
    [PengpengSun] (GH: 5914)
    + Move DS VMware to be in front of DS OVF (#5912) [PengpengSun] (GH: 4030)
    + ci: Add proper 'Breaks: ' to integration testing simple deb (#5923)
    + chore: Add akhuettel to CLA signers file (#5917) [Andreas K. Hüttel]
    + chore: eliminate calls at import time (#5889) (GH: 5344)
    + test: Add pyserial to test-requirements.txt (#5907)
    + test: Allow unknown size in growpart test (#5876)
    + doc: Update tutorials [Sally]
    + fix: bump azure key size to 3072 (#5841)
    24.4.1
    + fix: Ensure _should_wait_via_user_data() handles all user data types (#5976)
    + fix: Don't log error in wait_for_url (#5972)
    + feat(url_helper): Retry on 503 error (#5938)
    + fix: Don't break modules that use get_meta_doc() (#5953)
    + refactor: Pass deprecation log args as tuple (#5953)
    + fix: uninstall custom signal handlers before shutdown (#5913)
    24.4
    + test: Ensure unit ordering in ftp tests includes downstream units (#5892)
    + test: re-decrement expected webhook events (#5894)
    + test: allow relative path in apt-get test (#5891)
    + Fix metric setting of nmconnection for rhel (#5878) [Amy Chen]
    + chore: remove unused code(#5887)
    + feat(ephemeral): replace old has_url_connectivity() with new
    _check_connectivity_to_imds() [a-dubs]
    + feat(oracle): add true single stack ipv6 support [a-dubs]
    + feat(ephemeral): refactor ephemeralIP and add ipv6 connectivity check
    [a-dubs]
    + test: Decrement expected webhook events (#5888)
    + chore: remove `--docs` option from `cloud-init schema` (#5857) (GH: 5756)
    + test: pytestify "tests/unittests/config/test_cc_timezone.py" (#5885)
    [Mahesh Ghumare]
    + ci: bump integration tests to use plucky
    + test: add grub_dpkg to inactive modules
    + test: move default behavior tests into their own module
    + test(apt): add plucky version for hello pkg (#5883)
    + Docs: improved mermaid diagram for better visibility. Add "MaheshG11"
    as contributor (#5874) [Mahesh Ghumare] (GH: 5837)
    + fix(ntp): Fix RockyLinux OS support  (#5864) [Sid Shukla]
    + chore(jsonschema): migrate from deprecated Validator.iter_errors (#5856)
    + chore: remove deprecation warning getting jsonschema's version (#5856)
    + chore: use filter arg for tar.extractall (#5856)
    + chore: remove __init__ from pytest test class (#5856)
    + chore: do not test element's truth value directly (#5856)
    + chore: migrate from deprecated datetime.datetime.utcfromtimestamp (#5856)
    + chore: migrate from deprecated datetime.datetime.utcnow() (#5856)
    + chore: set recursive=False for ensure_dir if parent path is "/" (#5816)
    [sxt1001]
    + ci: fix broken daily dependencies (#5867)
    + ci: fix packaging tests (#5865)
    + feat(vultr): add override for network interface detection (#5847)
    [Andrew Davis]
    + feat(networkd): Support RequiredForOnline option (#5852) [Dan McGregor]
    + Prevent NM from handling DNS when network interfaces have DNS config
    (#5846) [Ani Sinha]
    + fix(smartos): Add `addrconf` IPv6 support (#5831)
    [blackhelicoptersdotnet]
    + freebsd: adjust to match the new pyyaml package name (#5844)
    [Gonéri Le Bouder]
    + fix: disable grub-dpkg by default (#5840)
    + fix(openbsd): Enable sysv init scripts in OpenBSD build script (#5790)
    [Hyacinthe Cartiaux] (LP: 4036, #1992853)
    + test: Fix duplicate judgment conditions in password generation (#5835)
    [sxt1001]
    + chore: don't render non-templated unit files (#5830)
    + chore: simplify and standardize cloud-final.service (#5830)
    + chore: simplify Conflicts=shutdown.target (#5830)
    + chore: remove redundant Before=NetworkManager.service (#5830)
    + chore: remove unnecessary systemd settings (#5830)
    + chore: eliminate redundant ordering dependencies (#5819)
    + fix: fix ordering cycle for distros with default deps (#5819) (GH: 5755)
    + test: unbreak pytest-xdist (#5829)
    + feat: Conditionally remove networkd online dependency on Ubuntu (#5772)
    + feat: Ensure random passwords contain multiple character types (#5815)
    [sxt1001] (GH: 5814)
    + docs: split example page into example library (#5645) [Sally]
    + doc: clarify workarounds required for single process changes (#5817)
    + chore: add 3.13 to PR CI runs, 3.14 to scheduled (#5825)
    + fix: Render v2 bridges correctly on network-manager with set-name
    (#5740) (GH: 5717)
    + test: add no_thinpool unit test (#5802)
    + chore: split lxd init config into separate function (#5802)
    + test: pytestify test_cc_lxd.py (#5802)
    + fix: Correctly handle missing thinpool in cc_lxd (#5802)
    + fix: Render bridges correctly for v2 on sysconfig with set-name (#5674)
    (GH: 5574)
    + tests(minimal): rsyslog not in minimal images expect warning (#5811)
    + tests(lxd): avoid failure on multiple calls to --show-log (#5811)
    + chore: update netplan import semantics and related tests (#5805)
    (GH: 5804)
    + lint: fix untyped-defs on /tests/unittest/cmd (#5800) [iru]
    + test: actually use devel release and verify_clean_boot enhancements
    (#5801)
    + feat(locale): locales install on minimal images when cfg requests (#5799)
    + feat(byobu): support byobu install on minimal images when cfg requests
    (#5799)
    + chore: Use devel release and no sbuild in integration CI (#5798)
    + test: Update integration tests from netplan backport (#5796)
    + test: add get_syslog_or_console for minimal images without syslog (#5793)
    + chore: Remove resize_root_tmp from cloud.cfg.tmpl (#5795) (GH: 5786)
    + docs: Fix field name from `contents` to `content` (#5787) [Igor Akkerman]
    + chore: bump pycloudlib to required version (#5792)
    + fix: avoid deprecation logs for calling cli stages (#5770) (GH: 5726)
    + tests: bump pycloudlib deps to include gce bug fix for id str (#5783)
    + fix(test): convert use p.gce.instance.id instead of instance_id (#5783)
    + fix(network-manager): bond properties and network schema (#5768)
    [Denis Kadyshev]
    + Fix metric setting for ifcfg network connections for rhel (#5777)
    [Ani Sinha] (GH: 5776)
    + fix(akamai): handle non-string user data in base64 decoding (#5751)
    [Jesse Alter]
    + fix(ci): do not auto stale issues (#5775)
    + Make pytest more verbose for easier debugging (#5778) [Ani Sinha]
    + ci: fix tox.ini pytest cmd to use cloudinit dir for coverage reporting
    (#5774) [Alec Warren]
    + tests: add OS_IMAGE_TYPE setting to allow for minimal tests (#5682)
    + test(hotplug): Simplify test_multi_nic_hotplug (#5763)
    + test(hotplug): increase nc timeout (#5763)
    + test: pytestify test_main.py (#5758)
    + test(ec2-dual-stack): fix int-test (#5762)
    + test: make verify_clean_boot really respect return code (#5761)
    + test: bump timeout in test_order (#5759)
    + docs: Properly document the cc_ubuntu_autoinstall module (#5757)
    + docs: fix WSL tutorial (#5752) (GH: 5746)
    + test: make verify_clean_boot respect return code by environment (#5754)
    + feat(integration_test): add CLOUD_INIT_PKG setting (#5739)
    + fix(ci): fix packaging check merge operation (#5750)
    + doc: do not document user.meta-data key (#5745)
    + test: avoid undocumented lxd key (#5748)
    + test: Refactor test_cc_set_hostname.py and test_cc_ntp.py (#5727)
    + chore: update docs URLs to cloud-init.io (#5741)
    + test: fix timer logging change expected logs (#5734)
    + fix: type annotations for several modules (#5733)
    + chore: add timer to io and string manipulation code
    + feat: add log package and performance module
    + remove newline injected for cloud-init status --wait (#5700)
    [Andrew Nelson] (GH: 5863)
    + test: webhook require_deprecation msg on 24.3 (#5731)
    + test: fix test_nocloud message typo introduced by 313390f8 (#5731)
    + test: Fix test_log_message_on_missing_version_file (#5730)
    + tests: assert info level warnings instead of require_deprecation
    + tests: fix test to ignore_warnings not require Used fallback ds
    + chore: clean up pytest warnings (#5721)
    + tests(pro): bump pycloudlib add noble release to pro tests (#5719)
    + fix(hotplugd.socket): remove basic.target as dependency (#5722)
    (LP: #2081124)
    + ci: fix integration test positional argument (#5718)
    + Create datasource for CloudCIX (#1351) [BrianKelleher]
    + ci: colorize output (#5716)
    + fix(schema): Allow for locale: false in schema add tests (#5647)
    + ci: fix packaging patch check (#5713)
    + chore: clean up old pickle workaround (#5714)
    + fix: force sftp cleanup when done with instance (#5698)
    + test(hotplug): reenable vpc test in focal (#5492)
    + chore: fix typing of userdata_raw (#5710)
    + fix(NetworkManager): Fix network activator (#5620)
    + fix: lxd do not check for thinpool kernel module (#5709)
    + docs: fix typo in docstring (#5708)
    + Scaleway: Force on-link: true for static networks (#5654)
    [Louis Bouchard] (LP: 5523, #2073869)
    + fix: Invalid "seedfrom" in NoCloud system configuration (#5701)
    + tests: pytestify test_nocloud.py (#5701)
    + test: make verify_clean_boot respect return code by series (#5695)
    + fix: use cross-distro netcat name (#5696)
    + ci: fix labeler (#5697)
    + chore(actions): add packaging label for any branches modifying debian/*
    + (#5693)
    + test: add verify_clean_boot() calls alongside verify_clean_log() (#5671)
    + test: add deprecation support to verify_clean_boot (#5671)
    + doc: remove misleading warning (#5681)
    + chore: Prefer other methods over $INSTANCE_ID (#5661)
    + ci: fix packaging test when no patches (#5680)
    + chore: fix tip-ruff and update to latest version (#5676)
    + chore: make ansible test serial (#5677)
    + feat(ec2): Bump url_max_timeout to 240s from 120s. (#5565)
    [Robert Nickel]
    + chore: fix typo in requirements.txt (#5637)
    + feat: make pyserial an optional dependency (#5637)
    + chore: bump ci dependency versions (#5660)
    + chore: drop broken optimization (#5666)
    24.3.1
    + test: add test coverage for iproute2 commands (#5651)
    + fix(netops): fix ip addr flush command (#5651) (GH: 5648)
    24.3
    + docs: Clarify v2 set-name behavior (#5639)
    + fix: properly handle blank lines in fstab (#5643)
    + fix: cc_user_groups incorrectly assumes "useradd" never locks password
    field (#5355) [dermotbradley]
    + tests: assert cloud-init user-data cert is the only root cert (#5641)
    + feat: add automation for ubuntu/* branches asserting quilt patches apply
    (#5622)
    + fix(sources/wsl): no error with empty .cloud-init dir (SC-1862) (#5633)
    + feat(azure): add PPS support for azure-proxy-agent (#5601)
    [Ksenija Stanojevic]
    + fix(tests): use instance.clean/restart instead of clean --reboot (#5636)
    + test: fix cmd/test_schema int test (#5629)
    + test: fix test_honor_cloud_dir int test (#5627)
    + docs: alphabetize dsname lookup table. update comment to create the csv
    (#5624)
    + docs: new datasources should update reference/ds_dsname_map (#5624)
    + test: fix ca_certs int test (#5626)
    + chore: update schema docs to use RST bold for config key names (#5562)
    + fix(doc): italics around deprecation prefix, description bolds key names
    (#5562)
    + feat(doc): add env vars to debug config module doc builds (#5562)
    + fix(doc): doc of nested objects under JSON schema items.oneOf (#5562)
    + fix(doc): object type check if patternProperties or properties (#5562)
    + doc(schema): schema descriptions should end with trailing stop (#5562)
    + fix(wsl): Properly assemble multipart data (#5538) [Carlos Nihelton]
    + feat: collect-logs improvements (#5619)
    + tests: fix test_ca_certs.py for gcp (#5621)
    + fix(nm): Ensure bond property name formatting matches schema definition
    (#5383) [Curt Moore]
    + Update behavior of base bond interface with NetworkManager (#5385)
    [Curt Moore]
    + ci: Drop Python 3.6 and 3.7 (#5607)
    + chore(black): Bump version (#5607)
    + chore(mypy): Fix failures on newer versions of mypy (#5607)
    + chore(tox.ini): Simplify configuration, fix minor bugs (#5607)
    + chore(mypy): Lint log module (#5607)
    + fix(systemd): Correct location of installed drop-in files(#5615)
    [Noah Meyerhans]
    + fix(btrfs): Version parsing (#5618)
    + docs: Remove unnecessary section, add feature flag page (#5617)
    + docs: Drop Python 3.6 and 3.7 support (#5617)
    + chore: explain other use of oauth (#5616)
    + chore(actions): add doc label for any doc related subdir file matches
    (#5602)
    + doc: Add misc links, improve wording (#5595)
    + doc(boot): Make first boot a dedicated page (#5595)
    + doc: Describe all stages in a single process (#5595)
    + chore: Deprecate old commands in help output (#5595)
    + chore: add comment explaining the NetworkManager may-fail setting
    (#5598) [Ani Sinha]
    + Revert "fix(vmware): Set IPv6 to dhcp when there is no IPv6 addr
    (#5471)" (#5596) [PengpengSun]
    + fix: read_optional_seed to set network-config when present (#5593)
    + feat(snap): avoid refresh on package_upgrade: true and refresh.hold
    (#5426)
    + fix: Fix tests which have outdated strings (#5585)
    + fix: Fix ftp failures (#5585)
    + doc: improve integration testing configuration instructions (#5556)
    [Alec Warren]
    + azure: check azure-proxy-agent status (#5138) [Ksenija Stanojevic]
    + refactor: refactor and fix mypy in DataSourceIBMCloud.py (#5509)
    [Alec Warren]
    + fix: Update default LXD meta-data with user meta-data (#5584)
    + chore: Fix log message in url_helper.py (#5583)
    + fix: nocloud no fail when network-config absent (#5580)
    + feat: Single process optimization (#5489)
    + chore: Add helper, refactor utilities into separate module (#5573)
    + refactor: update handle function of cc_mounts (#5498)
    + fix: Integration tests (#5576)
    + fix(NoCloudNet): Add network-config support (#5566)
    + feat: Eliminate redundant configuration reads (#5536)
    + fix(actions): correct typo in cloudinit/config/schemas/ match (#5570)
    + fix: add host template for AOSC (#5557) [Yuanhang Sun]
    + chore(debian): Remove vestigial postinst and preinst code (#5569)
    + fix(actions): doc labeler needs all clause instead of default any (#5568)
    + docs: Overhaul user data formats documentation (#5551)
    + chore: Deprecate ENI as an input configuration format (#5561)
    + doc: improve drop-in custom modules (#5548)
    + doc(NoCloud): Categorize the different configuration types (#5521)
    + doc(autoinstall): Remove incorrect statements, be more direct (#5545)
    + chore: remove unneeded doc-lint tox env config (#5547)
    + fix(doc-spelling): config spelling_word_list_filename (#5547)
    + doc(modules): add section to wrap modules' doc (#5550)
    + doc: Update docs on boothooks (#5546)
    + fix: doc auto label to consider schema json changes as doc PRs (#5543)
    + feat(schema): add chef_license schema enum (#5543)
    + doc: add diagram with boot stages (#5539)
    + docs: improve qemu command line (#5540) [Christian Ehrhardt]
    + fix: auto label doc PRs (#5542)
    + fix(wsl): Put back the "path" argument to wsl_path in ds-identify
    + (#5537) [Carlos Nihelton]
    + test: fix test_kernel_command_line_match (#5529)
    + test: fix no ds cache tests (#5529)
    + fix(azurelinux): Change default usr_lib_exec path (#5526) [Minghe Ren]
    + feat: Support URI sources in `write_files` module (#5505)
    [Lucas Ritzdorf]
    + add openeuler to distros in cc_spacewalk.py (#5530) [sxt1001]
    + feat(wsl): Special handling Landscape client config tags (#5460)
    [Carlos Nihelton]
    + chore: Deprecate partially supported system config (#5515)
    + chore: Improve detection logging for user clarity (#5515)
    + fix(ds-identify): Detect nocloud when seedfrom url exists (#5515)
    + refactor: logs.py add typing and small misc refactors (#5414)
    + refactor: logs.py pathlib changes (#5414)
    + refactor: replace verbosity with log levels in logs.py (#5414)
    + feat: Add trace-level logger (#5414)
    + chore(formatting): fix squashed commit test formatting (#5524)
    + fix: Clean cache if no datasource fallback (#5499)
    + Support setting mirrorlist in yum repository config (#5522) [Ani Sinha]
    + doc(OFV): Document how to configure cloud-init (#5519)
    + fix: Update DNS behavior for NetworkManager interfaces (#5496)
    [Curt Moore]
    + Fix configuration of DNS servers via OpenStack (#5384) [Curt Moore]
    + test: Unconditionally skip test_multi_nic_hotplug_vpc (#5503)
    + tests: revert expectation of exit 2 from cloud-init init --local (#5504)
    + fix(test): Fix ip printer for non-lxd (#5488)
    + feat(systemd): convert warning level message to deprecation (#5209)
    + test: allow verify_clean_boot to ignore all or specific tracebacks
    (#5209)
    + test: Don't fail tests which call cloud-init as a command (#5209)
    + feat(systemd): Warn user of unexpected run mode (#5209)
    + fix: add schema rules for 'baseurl' and 'metalink' in yum repo config
    (#5501) [Ani Sinha]
    + Set MTU for bond parent interface (#5495) [Curt Moore]
    + refactor: util.mounts to handle errors (#5490)
    + refactor: util.get_proc_env to work with strs (#5490)
    + typing: fix check_untyped_defs in cloudinit.util (#5490)
    + test: Add missing assert to test_status.py (#5494)
    + test: Ensure mkcert executable in ftp tests (#5493)
    + test: pytestify and cleanup test_cc_mounts.py (#5459)
    + fix(vmware): Set IPv6 to dhcp when there is no IPv6 addr (#5471)
    [PengpengSun]
    + fix(openbsd): fix mtu on newline in hostname files (#5412) [Tobias Urdin]
    + feat(aosc): Add 'AOSC OS' support (#5310) [Yuanhang Sun]
    24.2
    + test: Fix no default user in test_status.py (#5478)
    + fix: correct deprecated_version=22.2 for users.sudo
    + test: Add jsonschema guard in test_cc_ubuntu_pro.py (#5479)
    + fix(test): Fix pycloudlib types in integration tests (#5350)
    + fix(test): Fix ip printing for non-lxd instances (#5350)
    + chore(mypy): Drop unused missing import exclusions (#5350)
    + type: Add stub types for network v1/v2 config (#5350)
    + chore: Auto-format network jsonschema in ci (#5350)
    + fix(tox): Update tox.ini (#5350)
    + chore(typing): Remove type ignores and casts (#5350)
    + refactor(typing): Remove unused code paths (#5350)
    + fix(typing): Add / update type annotations (#5350)
    + fix(typing): Remove type annotation for unused variable (#5350)
    + fix(typing): Remove invalid type annotations (#5350)
    + ci(mypy): Set default follow_imports value (#5350)
    + test: Update integration tests to pass on focal (#5476)
    + tests: update ubuntu_pro test to account for info-level deprecations
    (#5475)
    + tests: update nocloud deprecation test for boundary version (#5474)
    + fix(rh_subscription): add string type to org (#5453)
    + tests: integration tests aware of features.DEPRECATION_INFO_BOUNDARY
    + tests: update keyserver PPA key fur curtin-dev (#5472)
    + test: Fix deprecation test failures (#5466)
    + chore: fix schema.py formatting (#5465)
    + fix: dont double-log deprecated INFOs (#5465)
    + fix(test): Mock version boundary (#5464)
    + fix(schema): Don't report changed keys as deprecated (#5464)
    + test: fix unit test openstack vlan mac_address (#5367)
    + fix: Ensure properties for bonded interfaces are properly translated
    (#5367) [Curt Moore]
    + fix(schema): permit deprecated hyphenated keys under users key (#5456)
    + fix: Do not add the vlan_mac_address field into the VLAN object (#5365)
    [Curt Moore]
    + doc(refactor): Convert module docs to new system (#5427) [Sally]
    + test: Add unit tests for features.DEPRECATION_INFO_BOUNDARY (#5411)
    + feat: Add deprecation boundary support to schema validator (#5411)
    + feat: Add deprecation boundary to logger (#5411)
    + fix: Gracefully handle missing files (#5397) [Curt Moore]
    + test(openstack): Test bond mac address (#5369)
    + fix(openstack): Fix bond mac_address (#5369) [Curt Moore]
    + test: Add ds-identify integration test coverage (#5394)
    + chore(cmdline): Update comments (#5458)
    + fix: Add get_connection_with_tls_context() for requests 2.32.2+ (#5435)
    [eaglegai]
    + fix(net): klibc ipconfig PROTO compatibility (#5437)
    [Alexsander de Souza] (LP: #2065787)
    + Support metalink in yum repository config (#5444) [Ani Sinha]
    + tests: hard-code curtin-dev ppa instead of canonical-kernel-team (#5450)
    + ci: PR update checklist GH- anchors to align w/ later template (#5449)
    + test: update validate error message in test_networking (#5436)
    + ci: Add PR checklist (#5446)
    + chore: fix W0105 in t/u/s/h/test_netlink.py (#5409)
    + chore(pyproject.toml): migrate to booleans (#5409)
    + typing: add check_untyped_defs (#5409)
    + fix(openstack): Append interface / scope_id for IPv6 link-local metadata
    address (#5419) [Christian Rohmann]
    + test: Update validation error in test_cli.py test (#5430)
    + test: Update schema validation error in integration test (#5429)
    + test: bump pycloudlib to get azure oracular images (#5428)
    + fix(azure): fix discrepancy for monotonic() vs time() (#5420)
    [Chris Patterson]
    + fix(pytest): Fix broken pytest gdb flag (#5415)
    + fix: Use monotonic time (#5423)
    + docs: Remove mention of resolv.conf (#5424)
    + perf(netplan): Improve network v1 -> network v2 performance (#5391)
    + perf(set_passwords): Run module in Network stage (#5395)
    + fix(test): Remove temporary directory side effect (#5416)
    + Improve schema validator warning messages (#5404) [Ani Sinha]
    + feat(sysconfig): Add DNS from interface config to resolv.conf (#5401)
    [Ani Sinha]
    + typing: add no_implicit_optional lint (#5408)
    + doc: update examples to reflect alternative ways to provide `sudo`
    option (#5418) [Ani Sinha]
    + fix(jsonschema): Add missing sudo definition (#5418)
    + chore(doc): migrate cc modules i through r to templates (#5313)
    + chore(doc): migrate grub_dpkg to tmpl add changed/deprecation (#5313)
    + chore(json): migrate cc_apt_configure and json schema indents (#5313)
    + chore(doc): migrate ca_certs/chef to template, flatten schema (#5313)
    + chore(doc): migrate cc_byobu to templates (#5313)
    + chore(doc): migrate cc_bootcmd to templates (#5313)
    + fix(apt): Enable calling apt update multiple times (#5230)
    + chore(VMware): Modify section of instance-id in the customization config
    (#5356) [PengpengSun]
    + fix(treewide): Remove dead code (#5332) [Shreenidhi Shedi]
    + doc: network-config v2 ethernets are of type object (#5381) [Malte Poll]
    + Release 24.1.7 (#5375)
    + fix(azure): url_helper: specify User-Agent when using headers_cb with
    readurl() (#5298) [Ksenija Stanojevic]
    + fix: Stop attempting to resize ZFS in cc_growpart on Linux (#5370)
    + doc: update docs adding YAML 1.1 spec and jinja template references
    + fix(final_message): do not warn on datasourcenone when single ds
    + fix(growpart): correct growpart log message to include value of mode
    + feat(hotplug): disable hotplugd.socket (#5058)
    + feat(hotlug): trigger hotplug after cloud-init.service (#5058)
    + test: add function to push and enable systemd units (#5058)
    + test(util): fix wait_until_cloud_init exit code 2 (#5058)
    + test(hotplug): fix race getting ipv6 (#5271)
    + docs: Adjust CSS to increase font weight across the docs (#5363) [Sally]
    + fix(ec2): Correctly identify netplan renderer (#5361)
    + tests: fix expect logging from growpart on devent with partition (#5360)
    + test: Add v2 test coverage to test_net.py (#5247)
    + refactor: Simplify collect_logs() in logs.py (#5268)
    + fix: Ensure no subp from logs.py import (#5268)
    + tests: fix integration tests for ubuntu pro 32.3 release (#5351)
    + tests: add oracular's hello package for pkg upgrade test (#5354)
    + growpart: Fix behaviour for ZFS datasets (#5169) [Mina Galić]
    + device_part_info: do not recurse if we did not match anything (#5169)
    [Mina Galić]
    + feat(alpine): add support for Busybox adduser/addgroup (#5176)
    [dermotbradley]
    + ci: Move lint tip and py3-dev jobs to daily (#5347)
    + fix(netplan): treat netplan warnings on stderr as debug for cloud-init
    (#5348)
    + feat(disk_setup): Add support for nvme devices (#5263)
    + fix(log): Do not warn when doing requested operation (#5263)
    + Support sudoers in the "/usr/usr merge" location (#5161)
    [Robert Schweikert]
    + doc(nocloud): Document network-config file (#5204)
    + fix(netplan): Fix predictable interface rename issue (#5339)
    + cleanup: Don't execute code on import (#5295)
    + fix(net): Make duplicate route add succeed. (#5343)
    + fix(freebsd): correct configuration of IPv6 routes (#5291) [Théo Bertin]
    + fix(azure): disable use-dns for secondary nics (#5314)
    + chore: fix lint failure (#5320)
    + Update pylint version to support python 3.12 (#5338) [Ani Sinha]
    + fix(tests): use regex to avoid focal whitespace in jinja debug test
    (#5335)
    + chore: Add docstrings and types to Version class (#5262)
    + ci(mypy): add type-jinja2 stubs (#5337)
    + tests(alpine): github trust lxc mounted source dir cloud-init-ro (#5329)
    + test: Add oracular release to integration tests (#5328)
    + Release 24.1.6 (#5326)
    + test: Fix failing test_ec2.py test (#5324)
    + fix: Check renderer for netplan-specific code (#5321)
    + docs: Removal of top-level --file breaking change (#5308)
    + fix: typo correction of delaycompress (#5317)
    + docs: Renderers/Activators have downstream overrides (#5322)
    + fix(ec2): Ensure metadata exists before configuring PBR (#5287)
    + fix(lxd): Properly handle unicode from LXD socket (#5309)
    + docs: Prefer "artifact" over "artefact" (#5311) [Arthur Le Maitre]
    + chore(doc): migrate cc_byobu to templates
    + chore(doc): migrate cc_bootcmd to templates
    + chore(doc): migrate apt_pipelining and apk_configure to templates
    + tests: in_place mount module-docs into lxd vm/container
    + feat(docs): generate rtd module schema from rtd/module-docs
    + feat: Set RH ssh key permissions when no 'ssh_keys' group (#5296)
    [Ani Sinha]
    + test: Avoid circular import in Azure tests (#5280)
    + test: Fix test_failing_userdata_modules_exit_codes (#5279)
    + chore: Remove CPY check from ruff (#5281)
    + chore: Clean up docstrings
    + chore(ruff): Bump to version 0.4.3
    + feat(systemd): Improve AlmaLinux OS and CloudLinux OS support (#5265)
    [Elkhan Mammadli]
    + feat(ca_certs): Add AlmaLinux OS and CloudLinux OS support (#5264)
    [Elkhan Mammadli]
    + docs: cc_apt_pipelining docstring typo fix (#5273) [Alex Ratner]
    + feat(azure): add request identifier to IMDS requests (#5218)
    [Ksenija Stanojevic]
    + test: Fix TestFTP integration test (#5237) [d1r3ct0r]
    + feat(ifconfig): prepare for CIDR output (#5272) [Mina Galić]
    + fix: stop manually dropping dhcp6 key in integration test (#5267)
    [Alec Warren]
    + test: Remove some CiTestCase tests (#5256)
    + fix: Warn when signal is handled (#5186)
    + fix(snapd): ubuntu do not snap refresh when snap absent (LP: #2064300)
    + feat(landscape-client): handle already registered client (#4784)
    [Fabian Lichtenegger-Lukas]
    + doc: Show how to debug external services blocking cloud-init (#5255)
    + fix(pdb): Enable running cloud-init under pdb (#5217)
    + chore: Update systemd description (#5250)
    + fix(time): Harden cloud-init to system clock changes
    + fix: Update analyze timestamp uptime
    + fix(schema): no network validation on netplan systems without API
    + fix(mount): Don't run cloud-init.service if cloud-init disabled (#5226)
    + fix(ntp): Fix AlmaLinux OS and CloudLinux OS support (#5235)
    [Elkhan Mammadli]
    + tests: force version of cloud-init from PPA regardless of version (#5251)
    + ci: Print isort diff (#5242)
    + test: Fix integration test dependencies (#5248)
    + fix(ec2): Fix broken uuid match with other-endianness (#5236)
    + fix(schema): allow networkv2 schema without top-level key (#5239)
    [Cat Red]
    + fix(cmd): Do not hardcode reboot command (#5208)
    + test: Run Alpine tests without network (#5220)
    + docs: Add base config reference from explanation (#5241)
    + docs: Remove preview from WSL tutorial (#5225)
    + chore: Remove broken maas code (#5219)
    + feat(WSL): Add support for Ubuntu Pro configs (#5116) [Ash]
    + chore: sync ChangeLog and version.py from 24.1.x (#5228)
    + bug(package_update): avoid snap refresh in images without snap command
    (LP: #2064132)
    + ci: Skip package build on tox runs (#5210)
    + chore: Fix test skip message
    + test(ec2): adopt pycloudlib public ip creation while launching instances
    + test(ec2): add ipv6 testing for multi-nic instances
    + test(ec2): adopt pycloudlib enable_ipv6 while launching instances
    + feat: tool to print diff between netplan and networkv2 schema (#5200)
    [Cat Red]
    + test: mock internet access in test_upgrade (#5212)
    + ci: Add timezone for alpine unit tests (#5216)
    + fix: Ensure dump timestamps parsed as UTC (#5214)
    + docs: Add WSL tutorial (#5206)
    + feature(schema): add networkv2 schema (#4892) [Cat Red]
    + Add alpine unittests to ci (#5121)
    + test: Fix invalid openstack datasource name (#4905)
    + test: Fix MAAS test and mark xfail (#4905)
    + chore(ds-identify): Update shellcheck ignores (#4905)
    + fix(ds-identify): Prevent various false positives and false negatives
    (#4905)
    + Use grep for faster parsing of cloud config in ds-identify (#4905)
    [Scott Moser] (LP: #2030729)
    + tests: validate netplan API YAML instead of strict content (#5195)
    + chore(templates): update ubuntu universe wording (#5199)
    + Deprecate the users ssh-authorized-keys property (#5162)
    [Anders Björklund]
    + doc(nocloud): Describe ftp and ftp over tls implementation (#5193)
    + feat(net): provide network config to netplan.State for render (#4981)
    + docs: Add breaking datasource identification changes (#5171)
    + fix(openbsd): Update build-on-openbsd python dependencies (#5172)
    [Hyacinthe Cartiaux]
    + fix: Add subnet ipv4/ipv6  to network schema (#5191)
    + docs: Add deprecated system_info to schema (#5168)
    + docs: Add DataSourceNone documentation (#5165)
    + test: Skip test if console log is None (#5188)
    + fix(dhcp): Enable interactively running cloud-init init --local (#5166)
    + test: Update message for netplan apply dbus issue
    + test: install software-properties-common if absent during PPA setup
    + test: bump pycloudlib to use latest version
    + test: Update version of hello package installed on noble
    + test: universally ignore netplan apply dbus issue (#5178)
    + chore: Remove obsolete nose workaround
    + feat: Add support for FTP and FTP over TLS (#4834)
    + feat(opennebula): Add support for posix shell
    + test: Make analyze tests not depend on GNU date
    + test: Eliminate bash dependency from subp tests
    + docs: Add breaking changes section to reference docs (#5147) [Cat Red]
    + util: add log_level kwarg for logexc() (#5125) [Chris Patterson]
    + refactor: Make device info part of distro definition (#5067)
    + refactor: Distro-specific growpart code (#5067)
    + test(ec2): fix mocking with responses==0.9.0 (focal) (#5163)
    + chore(safeyaml): Remove unicode helper for Python2 (#5142)
    + Revert "test: fix upgrade dhcp6 on ec2 (#5131)" (#5148)
    + refactor(net): Reuse netops code
    + refactor(iproute2): Make expressions multi-line for legibility
    + feat(freebsd): support freebsd find part by gptid and ufsid (#5122)
    [jinkangkang]
    + feat: Determining route metric based on NIC name (#5070) [qidong.ld]
    + test: Enable profiling in integration tests (#5130)
    + dhcp: support configuring static routes for dhclient's unknown-121
    option (#5146) [Chris Patterson]
    + feat(azure): parse ProvisionGuestProxyAgent as bool (#5126)
    [Ksenija Stanojevic]
    + fix(url_helper): fix TCP connection leak on readurl() retries (#5144)
    [Chris Patterson]
    + test: pytest-ify t/u/sources/test_ec2.py
    + Revert "ec2: Do not enable dhcp6 on EC2 (#5104)" (#5145) [Major Hayden]
    + fix: Logging sensitive data
    + test: Mock ds-identify systemd path (#5119)
    + fix(dhcpcd): Make lease parsing more robust (#5129)
    + test: fix upgrade dhcp6 on ec2 (#5131)
    + net/dhcp: raise InvalidDHCPLeaseFileError on error parsing dhcpcd lease
    (#5128) [Chris Patterson]
    + fix: Fix runtime file locations for cloud-init (#4820)
    + ci: fix linkcheck.yml invalid yaml (#5123)
    + net/dhcp: bump dhcpcd timeout to 300s (#5127) [Chris Patterson]
    + ec2: Do not enable dhcp6 on EC2 (#5104) [Major Hayden]
    + fix: Fall back to cached local ds if no valid ds found (#4997)
    [PengpengSun]
    + ci: Make linkcheck a scheduled job (#5118)
    + net: Warn when interface rename fails
    + ephemeral(dhcpcd): Set dhcpcd interface down
    + Release 24.1.3
    + chore: Handle all level 1 TiCS security violations (#5103)
    + fix: Always use single datasource if specified (#5098)
    + fix(tests): Leaked mocks (#5097)
    + fix(rhel)!: Fix network boot order in upstream cloud-init
    + fix(rhel): Fix network ordering in sysconfig
    + feat: Use NetworkManager renderer by default in RHEL family
    + fix: Allow caret at the end of apt package (#5099)
    + test: Add missing mocks to prevent bleed through (#5082)
    [Robert Schweikert]
    + fix: Ensure network config in DataSourceOracle can be unpickled (#5073)
    + docs: set the home directory using homedir, not home (#5101)
    [Olivier Gayot] (LP: #2047796)
    + fix(cacerts): Correct configuration customizations for Photon (#5077)
    [Christopher McCann]
    + fix(test): Mock systemd fs path for non-systemd distros
    + fix(tests): Leaked subp.which mock
    + fix(networkd): add GatewayOnLink flag when necessary (#4996) [王煎饼]
    + Release 24.1.2
    + test: fix `disable_sysfs_net` mock (#5065)
    + refactor: don't import subp function directly (#5065)
    + test: Remove side effects from tests (#5074)
    + refactor: Import log module rather than functions (#5074)
    + fix: Fix breaking changes in package install (#5069)
    + fix: Undeprecate 'network' in schema route definition (#5072)
    + refactor(ec2): simplify convert_ec2_metadata_network_config
    + fix(ec2): fix ipv6 policy routing
    + fix: document and add 'accept-ra' to network schema (#5060)
    + bug(maas): register the correct DatasourceMAASLocal in init-local
    (#5068) (LP: #2057763)
    + ds-identify: Improve ds-identify testing flexibility (#5047)
    + fix(ansible): Add verify_commit and inventory to ansible.pull schema
    (#5032) [Fionn Fitzmaurice]
    + doc: Explain breaking change in status code (#5049)
    + gpg: Handle temp directory containing files (#5063)
    + distro(freebsd): add_user: respect homedir (#5061) [Mina Galić]
    + doc: Install required dependencies (#5054)
    + networkd: Always respect accept-ra if set (#4928) [Phil Sphicas]
    + chore: ignore all cloud-init_*.tar.gz in .gitignore (#5059)
    + test: Don't assume ordering of ThreadPoolExecutor submissions (#5052)
    + feat: Add new distro 'azurelinux' for Microsoft Azure Linux. (#4931)
    [Dan Streetman]
    + fix(gpg): Make gpg resilient to host configuration changes (#5026)
    + Sync 24.1.1 changelog and version
    + DS VMware: Fix ipv6 addr converter from netinfo to netifaces (#5029)
    [PengpengSun]
    + packages/debian: remove dependency on isc-dhcp-client (#5041)
    [Chris Patterson]
    + test: Allow fake_filesystem to work with TemporaryDirectory (#5035)
    + tests: Don't wait for GCE instance teardown (#5037)
    + fix: Include DataSourceCloudStack attribute in unpickle test (#5039)
    + bug(vmware): initialize new DataSourceVMware attributes at unpickle
    (#5021) (LP: #2056439)
    + fix(apt): Don't warn on apt 822 source format (#5028)
    + fix(atomic_helper.py): ensure presence of parent directories (#4938)
    [Shreenidhi Shedi]
    + fix: Add "broadcast" to network v1 schema (#5034) (LP: #2056460)
    + pro: honor but warn on custom ubuntu_advantage in /etc/cloud/cloud.cfg
    (#5030)
    + net/dhcp: handle timeouts for dhcpcd (#5022) [Chris Patterson]
    + fix: Make wait_for_url respect explicit arguments
    + test: Fix scaleway retry assumptions
    + fix: Make DataSourceOracle more resilient to early network issues
    (#5025) (LP: #2056194)
    + chore(cmd-modules): fix exit code when --mode init (#5017)
    + feat: pylint: enable W0201 - attribute-defined-outside-init
    + refactor: Ensure no attributes defined outside __init__
    + chore: disable attribute-defined-outside-init check in tests
    + refactor: Use _unpickle rather than hasattr() in sources
    + chore: remove unused vendordata "_pure" variables
    + chore(cmd-modules): deprecate --mode init (#5005)
    + tests: drop CiTestCase and convert to pytest
    + bug(tests): mock reads of host's /sys/class/net via get_sys_class_path
    + fix: log correct disabled path in ds-identify (#5016)
    + tests: ec2 dont spend > 1 second retrying 19 times when 3 times will do
    + tests: openstack mock expected ipv6 IMDS
    + bug(wait_for_url): when exceptions occur url is unset, use url_exc
    (LP: #2055077)
    + feat(run-container): Run from arbitrary commitish (#5015)
    + tests: Fix wsl test (#5008)
    + feat(ds-identify): Don't run unnecessary systemd-detect-virt (#4633)
    + chore(ephemeral): add debug log when bringing up ephemeral network
    (#5010) [Alec Warren]
    + release: sync changelog and version (#5011)
    + Cleanup test_net.py (#4840)
    + refactor: remove dependency on netifaces (#4634) [Cat Red]
    + feat: make lxc binary configurable (#5000)
    + docs: update 404 page for new doc site and bug link
    + test(aws): local network connectivity on multi-nics (#4982)
    + test: Make integration test output more useful (#4984)
    From 24.1.7
    + fix(ec2): Correctly identify netplan renderer (#5361)
    From 24.1.6
    + fix(ec2): Ensure metadata exists before configuring PBR (#5287)
    + fix: Check renderer for netplan-specific code (#5321)
    + test: Fix failing test_ec2.py test (#5324)
    From 24.1.5
    + fix(package_update): avoid snap refresh in images without snap command
    (LP: #2064132)
    From 24.1.4
    + fix(dhcpcd): Make lease parsing more robust (#5129)
    + net/dhcp: raise InvalidDHCPLeaseFileError on error parsing dhcpcd lease
    + (#5128) [Chris Patterson]
    + fix: Fix runtime file locations for cloud-init (#4820)
    + net/dhcp: bump dhcpcd timeout to 300s (#5127) [Chris Patterson]
    + net: Warn when interface rename fails
    + ephemeral(dhcpcd): Set dhcpcd interface down
    + test: Remove side effects from tests (#5074)
    + refactor: Import log module rather than functions (#5074)
    From 24.1.3
    + fix: Always use single datasource if specified (#5098)
    + fix: Allow caret at the end of apt package (#5099)
    From 24.1.2
    + test: Don't assume ordering of ThreadPoolExecutor submissions (#5052)
    + refactor(ec2): simplify convert_ec2_metadata_network_config
    + tests: drop CiTestCase and convert to pytest
    + bug(tests): mock reads of host's /sys/class/net via get_sys_class_path
    + fix: Fix breaking changes in package install (#5069)
    + fix: Undeprecate 'network' in schema route definition (#5072)
    + fix(ec2): fix ipv6 policy routing
    + fix: document and add 'accept-ra' to network schema (#5060)
    + bug(maas): register the correct DatasourceMAASLocal in init-local
    (#5068) (LP: #2057763)
    From 24.1.1
    + fix: Include DataSourceCloudStack attribute in unpickle test (#5039)
    + bug(vmware): initialize new DataSourceVMware attributes at unpickle (#5021)
    + fix(apt): Don't warn on apt 822 source format (#5028)
    + fix: Add "broadcast" to network v1 schema (#5034)
    + pro: honor but warn on custom ubuntu_advantage in /etc/cloud/cloud.cfg
    (#5030)
    + net/dhcp: handle timeouts for dhcpcd (#5022)
    + fix: Make wait_for_url respect explicit arguments
    + bug(wait_for_url): when exceptions occur url is unset, use url_exc
    + test: Fix scaleway retry assumptions
    + fix: Make DataSourceOracle more resilient to early network issues (#5025)
    + tests: Fix wsl test (#5008)
    From 24.1
    + fix: Don't warn on vendor directory (#4986)
    + apt: kill spawned keyboxd after gpg cmd interaction
    + tests: upgrade tests should only validate current boot log
    + net/dhcp: fix maybe_perform_dhcp_discovery check for interface=None
    [Chris Patterson]
    + doc(network-v2): fix section nesting levels
    + fix(tests): don't check for clean log on minimal image (#4965) [Cat Red]
    + fix(cc_resize): Don't warn if zpool command not found (#4969)
    (LP: #2055219)
    + feat(subp): Make invalid command warning more user-friendly (#4972)
    + docs: Remove statement about device path matching (#4966)
    + test: Fix xfail to check the dhcp client name (#4971)
    + tests: avoid console prompts when removing gpg on Noble
    + test: fix test_get_status_systemd_failure
    + fix: Remove hardcoded /var/lib/cloud hotplug path (#4940)
    + refactor: Refactor status.py (#4864)
    + test: Use correct lxd network-config keys (#4950)
    + test: limit temp dhcp6 changes to < NOBLE (#4942)
    + test: allow downgrades when install debs (#4941)
    + tests: on noble, expect default /etc/apt/sources.list
    + tests: lxd_vm early boot status test ordered After=systemd-remount-fs
    (#4936)
    + tests: pro integration tests supply ubuntu_advantage until pro v32
    (#4935)
    + feat(hotplug): add cmd to enable hotplug (#4821)
    + test: fix test_combined_cloud_config_json (#4925)
    + test: xfail udhcpc on azure (#4924)
    + feat: Implement the WSL datasource (#4786) [Carlos Nihelton]
    + refactor(openrc):  Improve the OpenRC files (#4916) [dermotbradley]
    + tests: use apt install instead of dpkg -i to install pkg deps
    + tests: inactive module rename ubuntu_advantage to ubuntu_pro
    + test: fix tmpdir in test_cc_apk_configure (#4914)
    + test: fix jsonschema version checking in pro test (#4915)
    + feat(dhcp): Make dhcpcd the default dhcp client (#4912)
    + feat(Alpine) cc_growpart.py: fix handling of /dev/mapper devices (#4876)
    [dermotbradley]
    + test: Retry longer in test_status.py integration test (#4910)
    + test: fix kernel override test (#4913)
    + chore: Rename sysvinit/gentoo directory to sysvinit/openrc (#4906)
    [dermotbradley]
    + doc: update ubuntu_advantage references to pro
    + chore: rename cc_ubuntu_advantage to cc_ubuntu_pro (SC-1555)
    + feat(ubuntu pro): deprecate ubuntu_pro key in favor of ubuntu_advantage
    + feat(schema): support ubuntu_pro key and deprecate ubuntu_advantage
    + test: fix verify_clean_log (#4903)
    + test: limit test_no_hotplug_triggered_by_docker to stable releases
    + tests: generalize warning Open vSwitch warning from netplan apply (#4894)
    + fix(hotplug): remove literal quotes in args
    + feat(apt): skip known /etc/apt/sources.list content
    + feat(apt): use APT deb822 source format by default
    + test(ubuntu-pro): change livepatch to esm-infra
    + doc(ec2): fix metadata urls (#4880)
    + fix: unpin jsonschema and update tests (#4882)
    + distro: add eject FreeBSD code path (#4838) [Mina Galić]
    + feat(ec2): add hotplug as a default network update event (#4799)
    + feat(ec2): support instances with repeated device-number (#4799)
    + feat(cc_install_hotplug): trigger hook on known ec2 drivers (#4799)
    + feat(ec2): support multi NIC/IP setups (#4799)
    + feat(hotplug): hook-hotplug is now POSIX shell add OpenRC init script
    [dermotbradley]
    + test: harden test_dhcp.py::test_noble_and_newer_force_client
    + test: fix test_combined_cloud_config_json (#4868)
    + feat(apport): Disable hook when disabled (#4874)
    + chore: Add pyright ignore comments (#4874)
    + bug(apport): Fix invalid typing (#4874)
    + refactor: Move general apport hook to main branch (#4874)
    + feat(bootspeed)!: cloud-config.service drop After=snapd.seeded
    + chore: update CI package build to oldest supported Ubuntu release focal
    (#4871)
    + test: fix test_cli.test_valid_userdata
    + feat: handle error when log file is empty (#4859) [Hasan]
    + test: fix test_ec2_ipv6
    + fix: Address TIOBE abstract interpretation issues (#4866)
    + feat(dhcp): Make udhcpc use same client id (#4830)
    + feat(dhcp): Support InfiniBand with dhcpcd (#4830)
    + feat(azure): Add ProvisionGuestProxyAgent OVF setting (#4860)
    [Ksenija Stanojevic]
    + test: Bring back dhcp6 integration test changes (#4855)
    + tests: add status --wait blocking test from early boot
    + tests: fix retry decorator to return the func value
    + docs: add create_hostname_file to all hostname user-data examples
    (#4727) [Cat Red]
    + fix: Fix typos (#4850) [Viktor Szépe]
    + feat(dhcpcd): Read dhcp option 245 for azure wireserver (#4835)
    + tests(dhcp): Add udhcpc client to test matrix (#4839)
    + fix: Add types to network v1 schema (#4841)
    + docs(vmware): fixed indentation on example userdata yaml (#4854)
    [Alec Warren]
    + tests: Remove invalid keyword from method call
    + fix: Handle systemctl when dbus not ready (#4842) (LP: #2046483)
    + fix(schema cli): avoid netplan validation on net-config version 1
    + tests: reduce expected reports due to dropped rightscale module
    + tests(net-config): add awareness of netplan on stable Ubuntu
    [Gilbert Gilb's]
    + feat: fall back to cdrom_id eject if eject is not available (#4769)
    [Cat Red]
    + fix(packages/bddeb): restrict debhelper-compat to 12 in focal (#4831)
    + tests: Add kernel commandline test (#4833)
    + fix: Ensure NetworkManager renderer works without gateway (#4829)
    + test: Correct log parsing in schema test (#4832)
    + refactor: Remove cc_rightscale_userdata (#4813)
    + refactor: Replace load_file with load_binary_file to simplify typing
    (#4823)
    + refactor: Add load_text_file function to simplify typing (#4823)
    + refactor: Change variable name for consistent typing (#4823)
    + feat(dhcp): Add support for dhcpcd (#4746)
    + refactor: Remove unused networking code (#4810)
    + test: Add more DNS net tests
    + BREAKING CHANGE: Stop adding network v2 DNS to global DNS
    + doc: update DataSource.default_update_events doc (#4815)
    + chore: do not modify instance attribute (#4815)
    + test: fix mocking leaks (#4815)
    + Revert "ci: Pin pytest<8.0.0. (#4816)" (#4815)
    + test: Update tests for passlib (#4818)
    + fix(net-schema): no warn when skipping schema check on non-netplan
    + feat(SUSE): reboot marker file is written as /run/reboot-needed (#4788)
    [Robert Schweikert]
    + test: Cleanup unwanted logger setup calls (#4817)
    + refactor(cloudinit.util): Modernize error handling, add better warnings
    (#4812)
    + ci: Pin pytest<8.0.0. (#4816)
    + fix(tests): fixing KeyError on integrations tests (#4811) [Cat Red]
    + tests: integration for network schema on netplan systems (#4767)
    + feat(schema): use netplan API to validate network-config (#4767)
    + chore: define CLOUDINIT_NETPLAN_FILE static var (#4767)
    + fix: cli schema config-file option report network-config type (#4767)
    + refactor(azure): replace BrokenAzureDataSource with reportable errors
    (#4807) [Chris Patterson]
    + Fix Alpine and Mariner /etc/hosts templates (#4780) [dermotbradley]
    + tests: revert #4792 as noble images no longer return 2 (#4809) [Cat Red]
    + tests: use client fixture instead of class_client in cleantest (#4806)
    + tests: enable ds-idenitfy xfail test LXD-kvm-not-MAAS-1 (#4808)
    + fix(tests): failing integration tests due to missing ua token (#4802)
    [Cat Red]
    + Revert "Use grep for faster parsing of cloud config in ds-identify
    (#4327)"
    + tests: Demonstrate ds-identify yaml parsing broken
    + tests: add exit 2 on noble from cloud-init status (#4792)
    + fix: linkcheck for ci to ignore scaleway anchor URL (#4793)
    + feat: Update cacerts to support VMware Photon (#4763)
    [Christopher McCann]
    + fix: netplan rendering integrations tests (#4795) [Cat Red]
    + azure: remove cloud-init.log reporting via KVP (#4715) [Chris Patterson]
    + feat(Alpine): Modify ds-identify for Alpine support and add OpenRC
    init.d script (#4785) [dermotbradley]
    + doc: Add DatasourceScaleway documentation (#4773) [Louis Bouchard]
    + fix: packaged logrotate file lacks suffix on ubuntu (#4790)
    + feat(logrotate): config flexibility more backups (#4790)
    + fix(clean): stop warning when running clean command (#4761) [d1r3ct0r]
    + feat: network schema v1 strict on nic name length 15 (#4774)
    + logrotate config (#4721) [Fabian Lichtenegger-Lukas]
    + test: Enable coverage in integration tests (#4682)
    + test: Move unit test helpers to global test helpers (#4682)
    + test: Remove snapshot option from install_new_cloud_init (#4682)
    + docs: fix cloud-init single param docs (#4682)
    + Alpine: fix location of dhclient leases file (#4782) [dermotbradley]
    + test(jsonschema): Pin jsonschema version (#4781)
    + refactor(IscDhclient): discover DHCP leases at distro-provided location
    (#4683) [Phsm Qwerty]
    + feat: datasource check for WSL (#4730) [Carlos Nihelton]
    + test: Update hostname integration tests (#4744)
    + test: Add mantic and noble releases to integration tests (#4744)
    + refactor: Ensure internal DNS state same for v1 and v2 (#4756)
    + feat: Add v2 route mtu rendering to NetworkManager (#4748)
    + tests: stable ubuntu releases will not exit 2 on warnings (#4757)
    + doc(ds-identify): Describe ds-identify irrespective of distro (#4742)
    + fix: relax NetworkManager renderer rules (#4745)
    + fix: fix growpart race (#4618)
    + feat: apply global DNS to interfaces in network-manager  (#4723)
    [Florian Apolloner]
    + feat(apt): remove /etc/apt/sources.list when deb22 preferred (#4740)
    + chore: refactor schema data as enums and namedtuples (#4585)
    + feat(schema): improve CLI message on unprocessed data files (#4585)
    + fix(config): relocate /run to /var/run on BSD (canonical#4677)
    [Mina Galić]
    + fix(ds-identify): relocate /run on *BSD (#4677) [Mina Galić]
    + fix(sysvinit): make code a bit more consistent (#4677) [Mina Galić]
    + doc: Document how cloud-init is, not how it was (#4737)
    + tests: add expected exit 2 on noble from cloud-init status (#4738)
    + test(linkcheck): ignore github md and rst link headers (#4734)
    + test: Update webhook test due to removed cc_migrator module (#4726)
    + fix(ds-identify): Return code 2 is a valid result, use cached value
    + fix(cloudstack): Use parsed lease file for virtual router in cloudstack
    + fix(dhcp): Guard against FileNotFoundError and NameError exceptions
    + fix(apt_configure): disable sources.list if rendering deb822 (#4699)
    (LP: #2045086)
    + docs: Add link to contributing to docs (#4725) [Cat Red]
    + chore: remove commented code (#4722)
    + chore: Add log message when create_hostname_file key is false (#4724)
    [Cat Red]
    + fix: Correct v2 NetworkManager route rendering (#4637)
    + azure/imds: log http failures as warnings instead of info (#4714)
    [Chris Patterson]
    + fix(setup): Relocate libexec on OpenBSD (#4708) [Mina Galić]
    + feat(jinja): better jinja feedback and error catching (#4629)
    [Alec Warren]
    + test: Fix silent swallowing of unexpected subp error (#4702)
    + fix: Move cloud-final.service after time-sync.target (#4610)
    [Dave Jones] (LP: #1951639)
    + feat(log): Make logger name more useful for __init__.py
    + chore: Remove cc_migrator module (#4690)
    + fix(tests): make cmd/devel/tests work on non-GNU [Mina Galić]
    + chore: Remove cmdline from spelling list (#4670)
    + doc: Document boot status meaning (#4670)
    + doc: Set expectations for new datasources (#4670)
    + ci: Show linkcheck broken links in job output (#4670)
    + dmi: Add support for OpenBSD (#4654) [Mina Galić]
    + ds-identify: fake dmidecode support on OpenBSD (#4654) [Mina Galić]
    + ds-identify: add OpenBSD support in uname (#4654) [Mina Galić]
    + refactor: Ensure '_cfg' in Init class is dict (#4674)
    + refactor: Make event scope required in stages.py (#4674)
    + refactor: Remove unused argument (#4674)
    + chore: Move from lintian to a sphinx spelling plugin (#3639)
    + fix(doc): Fix spelling errors found by sphinxcontrib-spelling (#3639)
    + ci: Add Python 3.13 (#4567)
    + Add AlexSv04047 to CLA signers file (#4671) [AlexSv04047]
    + fix(openbsd): services & build tool (#4660) [CodeBleu]
    + tests/unittests: add a new unit test for network manager net activator
    (#4672) [Ani Sinha]
    + Implement DataSourceCloudStack.get_hostname() (#4433) [Phsm Qwerty]
    + net/nm: check for presence of ifcfg files when nm connection files
    are absent (#4645) [Ani Sinha]
    + doc: Overhaul debugging documentation (#4578)
    + doc: Move dangerous commands to dev docs (#4578)
    + doc: Relocate file location docs (#4578)
    + doc: Remove the debugging page (#4578)
    + fix(util): Fix boottime to work on OpenBSD (#4667) [Mina Galić]
    + net: allow dhcp6 configuration from generate_fallback_configuration()
    [Ani Sinha]
    + net/network_manager: do not set "may-fail" to False for both ipv4 and
    ipv6 dhcp [Ani Sinha]
    + feat(subp): Measure subprocess command time (#4606)
    + fix(python3.13): Fix import error for passlib on Python 3.13 (#4669)
    + style(brpm/bddeb): add black and ruff for packages build scripts (#4666)
    + copr: remove TODO.rst from spec file
    + fix(packages/brpm): correct syntax error and typo
    + style(ruff): fix tip target
    + config: Module documentation updates (#4599)
    + refactor(subp): Remove redundant parameter 'env' (#4555)
    + refactor(subp): Remove unused parameter 'target' (#4555)
    + refactor: Remove 'target' boilerplate from cc_apt_configure (#4555)
    + refactor(subp): Re-add return type to subp() (#4555)
    + refactor(subp): Add type information to args (#4555)
    + refactor(subp): Use subprocess.DEVNULL (#4555)
    + refactor(subp): Remove parameter 'combine_capture' (#4555)
    + refactor(subp): Remove unused parameter 'status_cb' (#4555)
    + fix(cli): fix parsing of argparse subcommands (#4559)
    [Calvin Mwadime] (LP: #2040325)
    + chore!: drop support for dsa ssh hostkeys in docs and schema (#4456)
    + chore!: do not generate ssh dsa host keys (#4456) [shixuantong]
    From 23.4.4
    + fix(nocloud): smbios datasource definition
    + tests: Check that smbios seed works
    + fix(source): fix argument boundaries when parsing cmdline (#4825)
    From 23.4.3
    + fix: Handle systemctl when dbus not ready (#4842)
    (LP: #2046483)
    From 23.4.2
    + fix: Handle invalid user configuration gracefully (#4797)
    (LP: #2051147)
    From 23.4.1
    + fix: Handle systemctl commands when dbus not ready (#4681)
    From 23.4
    + tests: datasourcenone use client.restart to block until done (#4635)
    + tests: increase number of retries across reboot to 90 (#4651)
    + fix: Add schema for merge types (#4648)
    + feat: Allow aliyun ds to fetch data in init-local (#4590) [qidong.ld]
    + azure: report failure to eject as error instead of debug (#4643)
    [Chris Patterson]
    + bug(schema): write network-config if instance dir present (#4635)
    + test: fix schema fuzzing test (#4639)
    + Update build-on-openbsd dependencies (#4644) [CodeBleu]
    + fix(test): Fix expected log for ipv6-only ephemeral network (#4641)
    + refactor: Remove metaclass from network_state.py (#4638)
    + schema: non-root fallback to default paths on perm errors (# 4631)
    + fix: Don't loosen the permissions of the log file (#4628)
    + Revert "logging: keep current file mode of log file if its stricter
    than the new mode (#4250)"
    + ephemeral: Handle link up failure for both ipv4 and ipv6  (#4547)
    + fix(main): Don't call logging too early (#4595)
    + fix: Remove Ubuntu-specific kernel naming convention assertion (#4617)
    + fix(log): Do not implement handleError with a self parameter (#4617)
    + fix(log): Don't try to reuse stderr logger (#4617)
    + feat: Standardize logging output to stderr (#4617)
    + chore: Sever unmaintained TODO.rst (#4625)
    + test: Skip failing tests
    + distros: Add suse
    + test: Add default hello package version (#4614)
    + fix(net): Improve DHCPv4 SUSE code, add test
    + net: Fix DHCPv4 not enabled on SUSE in some cases [bin456789]
    + fix(schema): Warn if missing dependency (#4616)
    + fix(cli): main source cloud_config for schema validation (#4562)
    + feat(schema): annotation path for invalid top-level keys (#4562)
    + feat(schema): top-level additionalProperties: false (#4562)
    + test: ensure top-level properties tests will pass (#4562)
    + fix(schema): Add missing schema definitions (#4562)
    + test: Fix snap tests (#4562)
    + azure: Check for stale pps data from IMDS (#4596) [Ksenija Stanojevic]
    + test: Undo dhcp6 integration test changes (#4612)
    + azure: update diagnostic from warning level to debug [Chris Patterson]
    + azure/imds: remove limit for connection errors if route present (#4604)
    + [Chris Patterson]
    + [enhancement]: Add shellcheck to CI (#4488) [Aviral Singh]
    + chore: add conventional commits template (#4593)
    + Revert "net: allow dhcp6 configuration from
    generate_fallback_configuration()" (#4607)
    + azure: workaround to disable reporting IMDS failures on Azure Stack
    [Chris Patterson]
    + cc_apt_pipelining: Update docs, deprecate options (#4571)
    + test: add gh workflows on push to main, update status badges (#4597)
    + util: Remove function abs_join() (#4587)
    + url_helper: Remove unused function retry_on_url_exc() (#4587)
    + cc_resizefs: Add bcachefs resize support (#4594)
    + integration_tests: Support non-Ubuntu distros (#4586)
    + fix(cmdline): fix cmdline parsing with MAC containing cc:
    + azure/errors: include http code in reason for IMDS failure
    [Chris Patterson]
    + tests: cloud-init schema --system does not return exit code 2
    + github: allow pull request to specify desired rebase and merge
    + tests: fix integration test expectations of exit 2 on schema warning
    + tests: fix schema test expected cli output Valid schema <type>
    + fix(schema cli): check raw userdata when processed cloud-config empty
    + azure: report failure to host if ephemeral DHCP secondary NIC (#4558)
    [Chris Patterson]
    + man: Document cloud-init error codes (#4500)
    + Add support for cloud-init "degraded" state (#4500)
    + status.json: Don't override detail key with error condition (#4500)
    + status: Remove duplicated data (#4500)
    + refactor: Rename exported_errors in status.json (#4500)
    + test: Remove stale status.json value (#4500)
    + tools/render-template: Make yaml loading opt-in, fix setup.py (#4564)
    + Add summit digest/trip report to docs (#4561) [Sally]
    + doc: Fix incorrect statement about `cloud-init analyze`
    + azure/imds: ensure new errors are logged immediately when retrying
    (#4468) [Chris Patterson]
    + Clarify boothook docs (#4543)
    + boothook: allow stdout/stderr to emit to cloud-init-output.log
    + summit-notes: add 2023 notes for reference in mailinglist/discourse
    + fix: added mock to stop leaking journalctl that slows down unit test
    (#4556) [Alec Warren]
    + tests: maas test for DataSourceMAASLocal get_data
    + maas tests: avoid using CiTest case and prefer pytest.tmpdir fixture
    + MAAS: Add datasource to init-local timeframe
    + Ensure all tests passed and/or are skipped
    + Support QEMU in integration tests
    + fix(read-dependencies): handle version specifiers containing [~!]
    + test: unpin pytest
    + schema: network-config optional network key. route uses oneOf (#4482)
    + schema: add cloud_init_deepest_matches for best error message (#4482)
    + network: warn invalid cfg add /run/cloud-init/network-config  (#4482)
    + schema: add network-config support to schema subcommand (#4482)
    + Update version number and merge ChangeLog from 23.3.3 into main (#4553)
    + azure: check for primary interface when performing DHCP (#4465)
    [Chris Patterson]
    + Fix hypothesis failure
    + subp: add a log when skipping a file for execution for lack of exe
    permission (#4506) [Ani Sinha]
    + azure/imds: refactor max_connection_errors definition (#4467)
    [Chris Patterson]
    + chore: fix PR template rendering (#4526)
    + fix(cc_apt_configure): avoid unneeded call to apt-install (#4519)
    + comment difference between sysconfig and NetworkManager renderer (#4517)
    [Ani Sinha]
    + Set Debian's default locale to be c.UTF-8 (#4503) (LP: #2038945)
    + Convert test_debian.py to pytest (#4503)
    + doc: fix cloudstack link
    + doc: fix development/contributing.html references
    + doc: hide duplicated links
    + Revert "ds-identify/CloudStack: $DS_MAYBE if vm running on vmware/xen
    (#4281)" (#4511) (LP: #2039453)
    + Fix the missing mcopy argument [Vladimir Pouzanov]
    + tests: Add logging fix (#4499)
    + Update upgrade test to account for dhcp6
    + Remove logging of PPID path (#4502)
    + Make Python 3.12 CI test non-experimental (#4498)
    + ds-identify: exit 2 on disabled state from marker or cmdline (#4399)
    + cloud-init-generator: Various performance optimizations (#4399)
    + systemd: Standardize cloud-init systemd enablement (#4399)
    + benchmark: benchmark cloud-init-generator independent of ds-identify
    (#4399)
    + tests/integration_tests: add cloud-init disablement coverage (#4399)
    + doc: Describe disabling cloud-init using an environment variable (#4399)
    + fix: cloud-init status --wait broken with KERNEL_CMDLINE (#4399)
    + azure/imds: retry on 429 errors for reprovisiondata (#4470)
    [Chris Patterson]
    + cmd: Don't write json status files for non-boot stages (#4478)
    + ds-identify: Allow disable service and override environment (#4485)
    [Mina Galić]
    + Update DataSourceNWCS.py (#4496) [shell-skrimp]
    + Add r00ta to CLA signers file
    + Fix override of systemd_locale_conf in rhel [Jacopo Rota]
    + ci(linkcheck): minor fixes (#4495)
    + integration test fix for deb822 URI format (#4492)
    + test: use a mantic-compatible tz in t/i/m/test_combined.py (#4494)
    + ua: shift CLI command from ua to pro for all interactions
    + pro: avoid double-dash when enabling inviddual services on CLI
    + net: allow dhcp6 configuration from generate_fallback_configuration()
    (#4474) [Ani Sinha]
    + tests: apt re.search to match alternative ordering of installed pkgs
    + apt: doc apt_pkg performance improvement over subp apt-config dump
    + Tidy up contributing docs (#4469) [Sally]
    + [enhancement]: Automatically linkcheck in CI (#4479) [Aviral Singh]
    + Revert allowing pro service warnings (#4483)
    + Export warning logs to status.json (#4455)
    + Fix regression in package installation (#4466)
    + schema: cloud-init schema in early boot or in dev environ (#4448)
    + schema: annotation of nested dicts lists in schema marks (#4448)
    + feat(apport): collect ubuntu-pro logs if ubuntu-advantage.log present
    (#4443)
    + apt_configure: add deb822 support for default sources file (#4437)
    + net: remove the word "on instance boot" from cloud-init generated config
    (#4457) [Ani Sinha]
    + style: Make cloudinit.log functions use snake case (#4449)
    + Don't recommend using cloud-init as a library (#4459)
    + vmware: Fall back to vmtoolsd if vmware-rpctool errs (#4444)
    [Andrew Kutz]
    + azure: add option to enable/disable secondary ip config (#4432)
    + [Ksenija Stanojevic]
    + Allow installing snaps via package_update_upgrade_install module (#4202)
    + docs: Add cloud-init overview/introduction (#4440) [Sally]
    + apt: install software-properties-common when absent but needed (#4441)
    + sources/Azure: Ignore system volume information folder while scanning
    for files in the ntfs resource disk (#4446) [Anh Vo]
    + refactor: Remove unnecessary __main__.py file
    + style: Drop vi format comments
    + cloudinit.log: Use more appropriate exception (#4435)
    + cloudinit.log: Don't configure NullHandler (#4435)
    + commit 6bbbfbbb030831c72b5aa2bba9cb8492f19d56f4
    + cloudinit.log: Remove unnecessary module function and variables (#4435)
    + cloudinit.log: Remove unused getLogger wrapper (#4435)
    + cloudinit.log: Standardize use of cloudinit's logging module (#4435)
    + Remove unnecessary logging wrapper in Cloud class (#4435)
    + integration test: allow pro service warnings (#4447)
    + integration tests: fix mount indentation (#4445)
    + sources/Azure: fix for conflicting reports to platform (#4434)
    [Chris Patterson]
    + docs: link the cloud-config validation service (#4442)
    + Fix pip-managed ansible on pip < 23.0.1 (#4403)
    + Install gnupg if gpg not found (#4431)
    + Add "phsm" as contributor (#4429) [Phsm Qwerty]
    + cc_ubuntu_advantage: do not rely on uaclient.messages module (#4397)
    [Grant Orndorff]
    + tools/ds-identify: match Azure datasource's ds_detect() behavior (#4430)
    [Chris Patterson]
    + Refactor test_apt_source_v1.py to use pytest (#4427)
    + sources: do not override datasource detection if None is in list (#4426)
    [Chris Patterson]
    + feat: check for create_hostname_file key before writing /etc/hostname
    (SC-1588) (#4330) [Cat Red]
    + Pytestify apt config test modules (#4424)
    + upstream gentoo patch (#4422)
    + Work around no instance ip (#4419)
    + Fix typing issues in subp module (#4401)
    + net: fix ipv6_dhcpv6_stateful/stateless/slaac configuration for rhel
    (#4395) [Ani Sinha]
    + Release 23.3.1
    + apt: kill dirmngr/gpg-agent without gpgconf dependency (LP: #2034273)
    + integration tests: fix mount indentation (#4405)
    + Use grep for faster parsing of cloud config in ds-identify (#4327)
    [Scott Moser] (LP: #2030729)
    + doc: fix instructions on how to disable cloud-init from kernel command
    line (#4406) [Ani Sinha]
    + doc/vmware: Update contents relevant to disable_vmware_customization
    [PengpengSun]
    + Bring back flake8 for python 3.6 (#4394)
    + integration tests: Fix cgroup parsing (#4402)
    + summary: Update template parameter descriptions in docs [MJ Moshiri]
    + Log PPID for better debugging (#4398)
    + integration tests: don't clean when KEEP_* flags true (#4400)
    + clean: add a new option to clean generated config files [Ani Sinha]
    + pep-594: drop deprecated pipes module import
    From 23.3.3
    + Fix pip-managed ansible on pip < 23.0.1 (#4403)
    From 23.3.2
    + Revert "ds-identify/CloudStack: $DS_MAYBE if vm running on vmware/xen"
    (#4281) (#4511) (LP: #2039453)
    From 23.3.1
    + apt: kill dirmngr/gpg-agent without gpgconf dependency (LP: #2034273)
    + integration tests: Fix cgroup parsing (#4402)

++++ branding-SLE:

  - Add distribution-logos (bsc#1243104).

++++ python-kiwi:

  - Bump version: 10.2.21 → 10.2.22
  - Apply security context on writable root only
    Make sure to perform setfiles only on a writable target. In case
    of a read-only root it is expected that the security context set
    by kiwi in an earlier stage is complete. As there is no way to
    modify data when root is read-only, there is also no way to change
    the security context of any file such that we skip setfiles
    in this case. Should there be a read-only system that has writable
    partitions such as /boot and their content changes while the rest
    of the root system is read-only it is in the responsibility of
    the author of the image description to call setfiles only on
    the affected and still writable files via a custom disk.sh
    script. Along with the fix the respective integration test was
    modified to enable selinux such that this change is actually
    integration tested. This Fixes #2805
  - Docs: fix typo in users.rst

++++ fde-tools:

  - Update to version 0.7.3
    + Detect the supported RSA key size
    + Take snapshot when signing
    + Switch to "--target-platform" when available
    + Allow RPM_MACRO_DIR to be defined during build time
    + Fix naming and disable ccid
    + tpm: fix tpm-present with the newer pcr-oracle
    + firstboot: make "Pass phrase" mandatory
    + firstboot: disable FDE/TPM2 when secure boot is off
    + Conditional helper
    + firstboot: replace the key file path in crypttab
    + firstboot: add more alias bootloader functions
    + firstboot: detect the early reencryption
  - Refresh fde-tools-firstboot-alp-snapshot.patch
  - Drop merged patches
    + fde-tools-bsc1213945-set-rsa-key-size.patch
    + fde-tools-bsc1223771-firstboot-make-Pass-phrase-mandatory.patch
    + fde-tools-bsc1223002-firstboot-disable-ccid.patch
    + fde-tools-bsc1218181-replace-crypttab-key-path.patch
    + fde-tools-bsc1220160-conditional-requires.patch
    + fde-tools-change-rpm-macro-dir.patch
    + fde-tools-bsc1243166-firstboot-disable-tpm2-when-sb-is-off.patch
    + fde-tools-bsc1222970-firstboot-replace-ALP.patch
    + fde-tools-bsc1218390-fix-tpm-present-with-the-newer-pcr-oracle.patch
    + fde-tools-bsc1238593-firstboot-more-bootloader-functions.patch
    + fde-tools-bsc1218390-Switch-to-target-platform-when-available.patch

++++ kernel-default:

  - x86/its: FineIBT-paranoid vs ITS (bsc#1242006 CVE-2024-28956).
  - commit 053af3b
  - x86/ibt: Optimize the fineibt-bhi arity 1 case (git-fixes).
  - commit 83c2d1c
  - x86/ibt: Implement FineIBT-BHI mitigation (git-fixes).
  - commit 7af7513
  - x86/bhi: Add BHI stubs (git-fixes).
  - commit 5c4d2d3
  - x86/ibt: Add paranoid FineIBT mode (git-fixes).
  - commit 58c8356
  - x86/traps: Decode LOCK Jcc.d8 as #UD (git-fixes).
  - commit c6f07d8
  - x86/ibt: Optimize the FineIBT instruction sequence (git-fixes).
  - commit 5993f66
  - x86/traps: Decode 0xEA instructions as #UD (git-fixes).
  - commit 6913267
  - x86/early_printk: Harden early_serial (git-fixes).
  - commit bf7d518
  - x86/ibt: Clean up poison_endbr() (git-fixes).
  - Refresh patches.suse/x86-ibt-Add-exact_endbr-helper.patch.
  - commit 17b408c
  - x86/traps: Cleanup and robustify decode_bug() (git-fixes).
  - commit a5c24d4
  - x86/alternative: Simplify callthunk patching (git-fixes).
  - commit 1ba25b6
  - x86/boot: Mark start_secondary() with __noendbr (git-fixes).
  - commit 22d80e7
  - objtool: Warn about unknown annotation types (git-fixes).
  - commit e893f80
  - objtool: Fix ANNOTATE_REACHABLE to be a normal annotation (git-fixes).
  - commit 52cfaf7
  - objtool: Convert {.UN}REACHABLE to ANNOTATE (git-fixes).
  - commit 223c7d6
  - objtool: Remove annotate_{,un}reachable() (git-fixes).
  - commit 2954713
  - unreachable: Unify (git-fixes).
  - commit e72eec4
  - objtool: Collect more annotations in objtool.h (git-fixes).
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-indirect-thunk.patch.
  - commit 0bcdfcd
  - objtool: Collapse annotate sequences (git-fixes).
  - commit d9cc842
  - objtool: Convert ANNOTATE_INTRA_FUNCTION_CALL to ANNOTATE (git-fixes).
  - commit c425677
  - objtool: Convert ANNOTATE_IGNORE_ALTERNATIVE to ANNOTATE (git-fixes).
  - commit 384a5a4
  - objtool: Convert VALIDATE_UNRET_BEGIN to ANNOTATE (git-fixes).
  - commit 6f86771
  - objtool: Convert instrumentation_{begin,end}() to ANNOTATE (git-fixes).
  - commit 9d3ff83
  - objtool: Convert ANNOTATE_RETPOLINE_SAFE to ANNOTATE  (git-fixes).
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-indirect-thunk.patch.
  - commit e2c7195
  - objtool: Convert ANNOTATE_NOENDBR to ANNOTATE (git-fixes).
  - commit 727a06d
  - objtool: Generic annotation infrastructure (git-fixes).
  - commit 0fba83d
  - x86/cfi: Clean up linkage (git-fixes).
  - Refresh
    patches.suse/x86-bugs-Rename-entry_ibpb-to-write_ibpb.patch.
  - Refresh
    patches.suse/x86-bugs-Use-SBPB-in-write_ibpb-if-applicable.patch.
  - Refresh
    patches.suse/x86-its-Align-RETs-in-BHB-clear-sequence-to-avoid-thunking.patch.
  - commit 6fb4977
  - x86,kcfi: Fix EXPORT_SYMBOL vs kCFI (git-fixes).
  - commit 4e0ae6a
  - x86/ibt: Clean up is_endbr() (git-fixes).
  - Refresh patches.suse/x86-ibt-Add-exact_endbr-helper.patch.
  - commit 23dc2db
  - x86/alternatives: Clean up preprocessor conditional block comments (git-fixes).
  - commit 8cb2529
  - x86/ibt: Add exact_endbr() helper (git-fixes).
  - commit 6768e40
  - x86/ibt: Handle FineIBT in handle_cfi_failure() (git-fixes).
  - commit e514559
  - x86/cfi: Add 'cfi=warn' boot option (git-fixes).
  - commit 40703d1
  - x86/its: Use dynamic thunks for indirect branches (bsc#1242006 CVE-2024-28956).
  - commit f7978bc
  - x86: re-enable EXECMEM_ROX support (git-fixes).
  - commit f4fd78c
  - module: drop unused module_writable_address() (git-fixes).
  - commit 49a69cd
  - Revert "x86/module: prepare module loading for ROX allocations of text" (git-fixes).
  - Refresh
    patches.suse/x86-ibt-Keep-IBT-disabled-during-alternative-patching.patch.
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-return-thunk.patch.
  - commit 4e57a83
  - module: switch to execmem API for remapping as RW and restoring ROX (git-fixes).
  - commit fff908c
  - execmem: add API for temporal remapping as RW and restoring ROX afterwards (git-fixes).
  - commit e928bfd
  - execmem: don't remove ROX cache from the direct map (git-fixes).
  - commit eee583e
  - x86/mm/pat: restore large ROX pages after fragmentation (git-fixes).
  - commit 5598b75
  - x86/mm/pat: drop duplicate variable in cpa_flush() (git-fixes).
  - commit f93080f
  - x86/mm/pat: cpa-test: fix length for CPA_ARRAY test (git-fixes).
  - commit adde21b
  - x86: Disable EXECMEM_ROX support (git-fixes).
  - commit de5aac5
  - x86/module: enable ROX caches for module text on 64 bit (git-fixes).
  - commit 76a51ba
  - execmem: add support for cache of large ROX pages (git-fixes).
  - commit 4295212
  - x86/module: prepare module loading for ROX allocations of text  (git-fixes).
  - Refresh
    patches.suse/x86-ibt-Keep-IBT-disabled-during-alternative-patching.patch.
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-return-thunk.patch.
  - commit ec664c3
  - arch: introduce set_direct_map_valid_noflush() (git-fixes).
  - commit dab315c
  - module: prepare to handle ROX allocations for text (git-fixes).
  - commit 68b6958
  - asm-generic: introduce text-patching.h (git-fixes).
  - commit de10e1e
  - mm: vmalloc: don't account for number of nodes for HUGE_VMAP allocations (git-fixes).
  - commit 1090fe7
  - mm: vmalloc: group declarations depending on CONFIG_MMU together (git-fixes).
  - commit 2949d85
  - Fix Patch-mainline tags.
  - Refresh
    patches.suse/vhost-scsi-Fix-vhost_scsi_send_bad_target.patch.
  - Refresh
    patches.suse/virtio-net-disable-delayed-refill-when-pausing-rx.patch.
  - Refresh
    patches.suse/virtio_console-fix-missing-byte-order-handling-for-c.patch.
  - Refresh
    patches.suse/xen-netfront-handle-NULL-returned-by-xdp_convert_buf.patch.
  - commit a02aff8
  - x86/ibt: Keep IBT disabled during alternative patching (bsc#1242006 CVE-2024-28956).
  - commit 08c6924
  - x86/its: Align RETs in BHB clear sequence to avoid thunking (bsc#1242006 CVE-2024-28956).
  - commit a549c4e
  - misc: pci_endpoint_test: Avoid issue of interrupts remaining
    after request_irq error (CVE-2025-23140 bsc#1242763).
  - commit 7abc3f5
  - x86/its: Add support for RSB stuffing mitigation (bsc#1242006 CVE-2024-28956).
  - commit daf020d
  - x86/its: Add "vmexit" option to skip mitigation on some CPUs (bsc#1242006 CVE-2024-28956).
  - commit cfbe6c2
  - x86/its: Enable Indirect Target Selection mitigation (bsc#1242006 CVE-2024-28956).
  - commit 0d65b9c
  - x86/its: Add support for ITS-safe return thunk (bsc#1242006 CVE-2024-28956).
  - commit fd877d7
  - x86/its: Add support for ITS-safe indirect thunk (bsc#1242006 CVE-2024-28956).
  - commit 30641d4
  - x86/its: Enumerate Indirect Target Selection (ITS) bug (bsc#1242006 CVE-2024-28956).
  - commit ba99e99
  - x86/cpu: Expose only stepping min/max interface (bsc#1242006 CVE-2024-28956).
  - commit 8b54e17
  - Documentation: x86/bugs/its: Add ITS documentation (bsc#1242006 CVE-2024-28956).
  - commit 9540fdb
  - Refresh patches.suse/tpm-tis-Double-the-timeout-B-to-4s.patch.
  - commit e6d0a02
  - scripts/check-kernel-fix: wait for git-fixes background run properly
    we are printing potential follow up fixes only if there is an action
    required which is an intendeded behavior. We do want to wait for the run
    to finish regardless of the final outcome though as we do not want the
    git-fixes to outlive the script runtime. Theoretically we could just kill
    git_fixes_pid but this could get more tricky if the process terminated
    and the pid got recycled.
  - commit 4d3770f
  - scripts/check-kernel-fix: print ACTION NEEDED at the end
    ACTION NEEDED has been printed as soon as it is clear there is an action
    required for a certain branch. This works well for regular run but it
    generates a confusing output for verbose mode
    Link: https://git.kernel.org/linus/f9a9f43a62a04ec3183fb0da9226c7706eed0115
    SL-16.0: nope_commit_in_base
    SLE11-SP4-LTSS: nope_unaffected
    SLE12-SP3-TD: nope_unaffected
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    fix this by printing this at the very end after all the processing is
    done.
  - commit fe72ee2
  - arm64: dts: imx8mp-var-som: Fix LDO5 shutdown causing SD card timeout (git-fixes)
  - commit e0761c4
  - arm64: dts: rockchip: Assign RT5616 MCLK rate on (git-fixes)
  - commit 85e792e
  - arm64: dts: rockchip: Add pinmuxing for eMMC on QNAP TS433 (git-fixes)
  - commit 3120557
  - arm64: dts: rockchip: Remove overdrive-mode OPPs from RK3588J SoC (git-fixes)
  - commit 9670342
  - arm64: cpufeature: Move arm64_use_ng_mappings to the .data section to (git-fixes)
  - commit 407716a
  - arm64: dts: st: Use 128kB size for aliased GIC400 register access on (git-fixes)
  - commit 12333da
  - arm64: dts: st: Adjust interrupt-controller for stm32mp25 SoCs (git-fixes)
  - commit 120fe1f
  - arm64: dts: imx8mm-verdin: Link reg_usdhc2_vqmmc to usdhc2 (git-fixes)
  - commit 16c5fbc
  - arm64: dts: imx95: Correct the range of PCIe app-reg region (git-fixes)
  - commit 2139ecb
  - arm64: errata: Add missing sentinels to Spectre-BHB MIDR arrays (git-fixes)
  - commit 4976c35

++++ kernel-rt:

  - x86/its: FineIBT-paranoid vs ITS (bsc#1242006 CVE-2024-28956).
  - commit 053af3b
  - x86/ibt: Optimize the fineibt-bhi arity 1 case (git-fixes).
  - commit 83c2d1c
  - x86/ibt: Implement FineIBT-BHI mitigation (git-fixes).
  - commit 7af7513
  - x86/bhi: Add BHI stubs (git-fixes).
  - commit 5c4d2d3
  - x86/ibt: Add paranoid FineIBT mode (git-fixes).
  - commit 58c8356
  - x86/traps: Decode LOCK Jcc.d8 as #UD (git-fixes).
  - commit c6f07d8
  - x86/ibt: Optimize the FineIBT instruction sequence (git-fixes).
  - commit 5993f66
  - x86/traps: Decode 0xEA instructions as #UD (git-fixes).
  - commit 6913267
  - x86/early_printk: Harden early_serial (git-fixes).
  - commit bf7d518
  - x86/ibt: Clean up poison_endbr() (git-fixes).
  - Refresh patches.suse/x86-ibt-Add-exact_endbr-helper.patch.
  - commit 17b408c
  - x86/traps: Cleanup and robustify decode_bug() (git-fixes).
  - commit a5c24d4
  - x86/alternative: Simplify callthunk patching (git-fixes).
  - commit 1ba25b6
  - x86/boot: Mark start_secondary() with __noendbr (git-fixes).
  - commit 22d80e7
  - objtool: Warn about unknown annotation types (git-fixes).
  - commit e893f80
  - objtool: Fix ANNOTATE_REACHABLE to be a normal annotation (git-fixes).
  - commit 52cfaf7
  - objtool: Convert {.UN}REACHABLE to ANNOTATE (git-fixes).
  - commit 223c7d6
  - objtool: Remove annotate_{,un}reachable() (git-fixes).
  - commit 2954713
  - unreachable: Unify (git-fixes).
  - commit e72eec4
  - objtool: Collect more annotations in objtool.h (git-fixes).
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-indirect-thunk.patch.
  - commit 0bcdfcd
  - objtool: Collapse annotate sequences (git-fixes).
  - commit d9cc842
  - objtool: Convert ANNOTATE_INTRA_FUNCTION_CALL to ANNOTATE (git-fixes).
  - commit c425677
  - objtool: Convert ANNOTATE_IGNORE_ALTERNATIVE to ANNOTATE (git-fixes).
  - commit 384a5a4
  - objtool: Convert VALIDATE_UNRET_BEGIN to ANNOTATE (git-fixes).
  - commit 6f86771
  - objtool: Convert instrumentation_{begin,end}() to ANNOTATE (git-fixes).
  - commit 9d3ff83
  - objtool: Convert ANNOTATE_RETPOLINE_SAFE to ANNOTATE  (git-fixes).
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-indirect-thunk.patch.
  - commit e2c7195
  - objtool: Convert ANNOTATE_NOENDBR to ANNOTATE (git-fixes).
  - commit 727a06d
  - objtool: Generic annotation infrastructure (git-fixes).
  - commit 0fba83d
  - x86/cfi: Clean up linkage (git-fixes).
  - Refresh
    patches.suse/x86-bugs-Rename-entry_ibpb-to-write_ibpb.patch.
  - Refresh
    patches.suse/x86-bugs-Use-SBPB-in-write_ibpb-if-applicable.patch.
  - Refresh
    patches.suse/x86-its-Align-RETs-in-BHB-clear-sequence-to-avoid-thunking.patch.
  - commit 6fb4977
  - x86,kcfi: Fix EXPORT_SYMBOL vs kCFI (git-fixes).
  - commit 4e0ae6a
  - x86/ibt: Clean up is_endbr() (git-fixes).
  - Refresh patches.suse/x86-ibt-Add-exact_endbr-helper.patch.
  - commit 23dc2db
  - x86/alternatives: Clean up preprocessor conditional block comments (git-fixes).
  - commit 8cb2529
  - x86/ibt: Add exact_endbr() helper (git-fixes).
  - commit 6768e40
  - x86/ibt: Handle FineIBT in handle_cfi_failure() (git-fixes).
  - commit e514559
  - x86/cfi: Add 'cfi=warn' boot option (git-fixes).
  - commit 40703d1
  - x86/its: Use dynamic thunks for indirect branches (bsc#1242006 CVE-2024-28956).
  - commit f7978bc
  - x86: re-enable EXECMEM_ROX support (git-fixes).
  - commit f4fd78c
  - module: drop unused module_writable_address() (git-fixes).
  - commit 49a69cd
  - Revert "x86/module: prepare module loading for ROX allocations of text" (git-fixes).
  - Refresh
    patches.suse/x86-ibt-Keep-IBT-disabled-during-alternative-patching.patch.
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-return-thunk.patch.
  - commit 4e57a83
  - module: switch to execmem API for remapping as RW and restoring ROX (git-fixes).
  - commit fff908c
  - execmem: add API for temporal remapping as RW and restoring ROX afterwards (git-fixes).
  - commit e928bfd
  - execmem: don't remove ROX cache from the direct map (git-fixes).
  - commit eee583e
  - x86/mm/pat: restore large ROX pages after fragmentation (git-fixes).
  - commit 5598b75
  - x86/mm/pat: drop duplicate variable in cpa_flush() (git-fixes).
  - commit f93080f
  - x86/mm/pat: cpa-test: fix length for CPA_ARRAY test (git-fixes).
  - commit adde21b
  - x86: Disable EXECMEM_ROX support (git-fixes).
  - commit de5aac5
  - x86/module: enable ROX caches for module text on 64 bit (git-fixes).
  - commit 76a51ba
  - execmem: add support for cache of large ROX pages (git-fixes).
  - commit 4295212
  - x86/module: prepare module loading for ROX allocations of text  (git-fixes).
  - Refresh
    patches.suse/x86-ibt-Keep-IBT-disabled-during-alternative-patching.patch.
  - Refresh
    patches.suse/x86-its-Add-support-for-ITS-safe-return-thunk.patch.
  - commit ec664c3
  - arch: introduce set_direct_map_valid_noflush() (git-fixes).
  - commit dab315c
  - module: prepare to handle ROX allocations for text (git-fixes).
  - commit 68b6958
  - asm-generic: introduce text-patching.h (git-fixes).
  - commit de10e1e
  - mm: vmalloc: don't account for number of nodes for HUGE_VMAP allocations (git-fixes).
  - commit 1090fe7
  - mm: vmalloc: group declarations depending on CONFIG_MMU together (git-fixes).
  - commit 2949d85
  - Fix Patch-mainline tags.
  - Refresh
    patches.suse/vhost-scsi-Fix-vhost_scsi_send_bad_target.patch.
  - Refresh
    patches.suse/virtio-net-disable-delayed-refill-when-pausing-rx.patch.
  - Refresh
    patches.suse/virtio_console-fix-missing-byte-order-handling-for-c.patch.
  - Refresh
    patches.suse/xen-netfront-handle-NULL-returned-by-xdp_convert_buf.patch.
  - commit a02aff8
  - x86/ibt: Keep IBT disabled during alternative patching (bsc#1242006 CVE-2024-28956).
  - commit 08c6924
  - x86/its: Align RETs in BHB clear sequence to avoid thunking (bsc#1242006 CVE-2024-28956).
  - commit a549c4e
  - misc: pci_endpoint_test: Avoid issue of interrupts remaining
    after request_irq error (CVE-2025-23140 bsc#1242763).
  - commit 7abc3f5
  - x86/its: Add support for RSB stuffing mitigation (bsc#1242006 CVE-2024-28956).
  - commit daf020d
  - x86/its: Add "vmexit" option to skip mitigation on some CPUs (bsc#1242006 CVE-2024-28956).
  - commit cfbe6c2
  - x86/its: Enable Indirect Target Selection mitigation (bsc#1242006 CVE-2024-28956).
  - commit 0d65b9c
  - x86/its: Add support for ITS-safe return thunk (bsc#1242006 CVE-2024-28956).
  - commit fd877d7
  - x86/its: Add support for ITS-safe indirect thunk (bsc#1242006 CVE-2024-28956).
  - commit 30641d4
  - x86/its: Enumerate Indirect Target Selection (ITS) bug (bsc#1242006 CVE-2024-28956).
  - commit ba99e99
  - x86/cpu: Expose only stepping min/max interface (bsc#1242006 CVE-2024-28956).
  - commit 8b54e17
  - Documentation: x86/bugs/its: Add ITS documentation (bsc#1242006 CVE-2024-28956).
  - commit 9540fdb
  - Refresh patches.suse/tpm-tis-Double-the-timeout-B-to-4s.patch.
  - commit e6d0a02
  - scripts/check-kernel-fix: wait for git-fixes background run properly
    we are printing potential follow up fixes only if there is an action
    required which is an intendeded behavior. We do want to wait for the run
    to finish regardless of the final outcome though as we do not want the
    git-fixes to outlive the script runtime. Theoretically we could just kill
    git_fixes_pid but this could get more tricky if the process terminated
    and the pid got recycled.
  - commit 4d3770f
  - scripts/check-kernel-fix: print ACTION NEEDED at the end
    ACTION NEEDED has been printed as soon as it is clear there is an action
    required for a certain branch. This works well for regular run but it
    generates a confusing output for verbose mode
    Link: https://git.kernel.org/linus/f9a9f43a62a04ec3183fb0da9226c7706eed0115
    SL-16.0: nope_commit_in_base
    SLE11-SP4-LTSS: nope_unaffected
    SLE12-SP3-TD: nope_unaffected
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    fix this by printing this at the very end after all the processing is
    done.
  - commit fe72ee2
  - arm64: dts: imx8mp-var-som: Fix LDO5 shutdown causing SD card timeout (git-fixes)
  - commit e0761c4
  - arm64: dts: rockchip: Assign RT5616 MCLK rate on (git-fixes)
  - commit 85e792e
  - arm64: dts: rockchip: Add pinmuxing for eMMC on QNAP TS433 (git-fixes)
  - commit 3120557
  - arm64: dts: rockchip: Remove overdrive-mode OPPs from RK3588J SoC (git-fixes)
  - commit 9670342
  - arm64: cpufeature: Move arm64_use_ng_mappings to the .data section to (git-fixes)
  - commit 407716a
  - arm64: dts: st: Use 128kB size for aliased GIC400 register access on (git-fixes)
  - commit 12333da
  - arm64: dts: st: Adjust interrupt-controller for stm32mp25 SoCs (git-fixes)
  - commit 120fe1f
  - arm64: dts: imx8mm-verdin: Link reg_usdhc2_vqmmc to usdhc2 (git-fixes)
  - commit 16c5fbc
  - arm64: dts: imx95: Correct the range of PCIe app-reg region (git-fixes)
  - commit 2139ecb
  - arm64: errata: Add missing sentinels to Spectre-BHB MIDR arrays (git-fixes)
  - commit 4976c35

++++ ncurses:

  - Avoid expanding %jobs in comment (boo#1237231)

++++ openssl-3:

  - FIPS: Fix the speed command in FIPS mode for KMAC
    * Add openssl-FIPS-Fix-openssl-speed-KMAC.patch

++++ systemd:

  - systemd-update-helper: Fix invalid use of "break" in case statement

++++ skopeo:

  - Add patch:
    * 0001-CVE-2025-27144-vendor-don-t-allow-unbounded-amounts-.patch
  - Remove patch:
    * 0001-http2-close-connections-when-receiving-too-many-head.patch
    * 0002-Switch-hashicorp-go-retryablehttp-to-the-SUSE-fork.patch
    * 0003-Don-t-allow-unbounded-amounts-of-splits-https-github.patch
  - Update to version 1.18.0:
    * Bump Skopeo to v1.18.0
    * Switch to the CNCF Code of Conduct
    * fix(deps): update module golang.org/x/term to v0.29.0
    * fix(deps): update module github.com/containers/common to v0.62.0
    * chore(deps): update dependency containers/automation_images to v20250131
    * fix(deps): update module github.com/spf13/pflag to v1.0.6
    * fix(deps): update module github.com/containers/image/v5 to v5.34.0
    * RPM: include check section to silence rpmlint
    * RPM: cleanup gobuild macro for CentOS Stream
    * fix(deps): update module github.com/containers/storage to v1.57.1
    * fix(deps): update module github.com/containers/storage to v1.57.0
    * feat: Add `--retry-delay` Option
    * fix(deps): update module github.com/containers/common to v0.61.1
    * fix(deps): update module github.com/containers/image/v5 to v5.33.1
    * fix(deps): update module github.com/containers/storage to v1.56.1
    * systemtest: update quay.io registry image
    * chore(deps): update dependency containers/automation_images to v20250107 (#2488)
    * fix(deps): update module golang.org/x/term to v0.28.0
    * chore(deps): update dependency golangci/golangci-lint to v1.63.4
    * chore(deps): update dependency golangci/golangci-lint to v1.63.3
    * chore(deps): update dependency golangci/golangci-lint to v1.63.2
    * fix(deps): update golang.org/x/exp digest to b2144cd
    * chore(deps): update module golang.org/x/net to v0.33.0 [security]
    * fix(deps): update module github.com/containers/ocicrypt to v1.2.1
    * fix(deps): update module golang.org/x/term to v0.27.0
    * Fix handling of errorShouldDisplayUsage
    * fix(deps): update golang.org/x/exp digest to 2d47ceb
    * Packit: remove rhel (epel) jobs
    * Packit: switch fedora copr targets to fedora-all
    * fix(deps): update module github.com/stretchr/testify to v1.10.0
    * chore(deps): update dependency golangci/golangci-lint to v1.62.2
    * Update an expected error message
    * fix(deps): update module github.com/masterminds/semver/v3 to v3.3.1
    * chore(deps): update dependency golangci/golangci-lint to v1.62.0
    * fix(deps): update module github.com/moby/sys/capability to v0.4.0
    * Bump to c/Skopeo v1.18.0-dev
    * Bump to c/Skopeo v1.17.0
    * Bump c/common to v0.60.0
    * fix(deps): update module github.com/containers/image/v5 to v5.33.0
    * Trigger a rebuild of the ostree-rs-ext container
    * Update contrib/cirrus/ostree_ext.dockerfile for DNF 5
    * update CI images to f41
    * cirrus: use dnf remove over erase
    * fix(deps): update golang.org/x/exp digest to f66d83c
    * fix(deps): update module github.com/containers/storage to v1.55.1
    * Fix format string inconsistency causing a build failure
    * proxy: Add various debug logging
    * chore(deps): update dependency containers/automation_images to v20241010
    * * Added option to create digest file for syncing images. * Digest file output would have docker reference of source and sha of of the mainfest sync'd with the target. This file would not be created if dry-run flag is enabled * improved the sync document to include the correct output for manifest file. * added new line for the manifest file once all images are sync'd * Ensuring we log on manifest digest if the copy operation was successful. * Check for errors if any once sync process is complete. * Ensure to capture the failure when closing the manifest file. * Ensure we are not writing manifest sha for failed copy of imagesand aborting the process in case write to file fails
    * Packit: constrain downstream koji job to fedora package
    * fix(deps): update module golang.org/x/term to v0.25.0
    * fix(deps): update module github.com/containers/common to v0.60.4
    * fix(deps): update golang.org/x/exp digest to 701f63a
    * vendor: switch to moby/sys/capability (#2428)
    * Document that zstd:chunked is downgraded to zstd when encrypting
    * fix(deps): update module github.com/containers/common to v0.60.3
    * Packit: split out ELN jobs and reuse fedora downstream targets
    * Packit: Enable sidetags for bodhi updates
    * chore(deps): update dependency golangci/golangci-lint to v1.61.0
    * fix(deps): update module golang.org/x/term to v0.24.0
    * Use a range expression
    * Update to Go 1.22
    * Restrict Packit targets to those that support Go 1.22
    * fix(deps): update golang.org/x/exp digest to 9b4947d
    * chore(deps): update dependency containers/automation_images to v20240821
    * Update skopeo-generate-sigstore-key.1.md
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.60.3
    * fix(deps): update module github.com/masterminds/semver/v3 to v3.3.0
    * fix(deps): update module github.com/containers/common to v0.60.2
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.60.2
    * fix(deps): update module github.com/containers/image/v5 to v5.32.2
    * Replace egrep with grep -E
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.60.1
    * fix(deps): update module github.com/containers/common to v0.60.1
    * fix(deps): update module github.com/containers/image/v5 to v5.32.1
    * fix(deps): update module golang.org/x/term to v0.23.0
    * The fakeroot package doesn't exist in RHEL.
    * Bump Skopeo to v1.17.0-dev
    * Bump Skopeo to v1.16.0
    * fix(deps): update module github.com/containers/common to v0.60.0
    * Drop the toolchain back to 1.21.0
    * fix(deps): update module github.com/containers/image/v5 to v5.32.0
    * fix(deps): update module github.com/containers/storage to v1.55.0
    * chore(deps): update module google.golang.org/grpc to v1.64.1 [security]
    * fix(deps): update module github.com/containers/common to v0.59.2
    * [skip-ci] RPM: spec file cleanup
    * fix(deps): update module golang.org/x/term to v0.22.0
    * fix(deps): update module github.com/containers/ocicrypt to v1.2.0
    * fix(deps): update golang.org/x/exp digest to 7f521ea
    * Bump github.com/hashicorp/go-retryablehttp from 0.7.6 to 0.7.7
    * fix(deps): update module github.com/containers/image/v5 to v5.31.1
    * fix(deps): update module github.com/spf13/cobra to v1.8.1
    * Refer to registry.k8s.io instead of k8s.gcr.io
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.59.1
    * fix(deps): update module golang.org/x/term to v0.21.0
    * fix(deps): update module github.com/containers/common to v0.59.1
    * Execute cross-build task using PW pool
    * fix(deps): update golang.org/x/exp digest to fd00a4e
    * CI: bump VMs
    * Don't offer the tarball: transport in completions
    * [skip-ci] Packit: `packages: [skopeo-fedora]` for podman-next jobs
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.59.0
    * fix(deps): update module github.com/containers/common to v0.59.0
    * Stop using the exclude_graphdriver_devicemapper build tag
    * fix(deps): update module github.com/containers/image/v5 to v5.31.0
    * Update for changed c/image error texts
    * Update c/image after https://github.com/containers/image/pull/2408
    * fix(deps): update module github.com/containers/common to v0.58.3
    * hack: Support picking cc and cpp via environment variables.
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.58.1
    * [skip-ci] RPM: bats requirement only on Fedora
    * fix(deps): update module golang.org/x/exp to v0.0.0-20240506185415-9bf2ced13842
    * [skip-ci] Packit: enable c10s downstream sync
    * [skip-ci] Packit: delete EL8 jobs
    * fix(deps): update module golang.org/x/term to v0.20.0
    * Add info on Skopeo image to README.md
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.58.0
    * fix summaries for standalone-sign and standalone-verify
    * fix(deps): update module golang.org/x/exp to v0.0.0-20240416160154-fe59bbe5cc7f
    * CI VMs: bump to new versions with tmpfs /tmp
    * chore(deps): update module golang.org/x/net to v0.23.0 [security]
    * Use "slices" from the standard library
    * Update to Go 1.21
    * chore: fix function names
    * Center logo in README.md
    * fix(deps): update module github.com/containers/common to v0.58.2
    * Hard-code the device-mapper graph driver to disabled
    * Fix issue/pr lock workflow
    * feat: add `--image-parallel-copies` flag
    * Use strings.CutSuffix
    * Use strings.CutPrefix
    * Update to Go 1.20
    * fix(deps): update module golang.org/x/term to v0.19.0
    * Freeze the fedora-minimal image reference at Fedora 38
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.2
    * fix(deps): update module github.com/containers/common to v0.58.1
    * [CI:DOCS] Add golang 1.21 update warning
    * chore(deps): update dependency containers/automation_images to v20240320
    * main: return exit code `2` when an input is not found
    * chore(deps): update module github.com/docker/docker to v25.0.5+incompatible [security]
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.1
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.0
    * [skip-ci] rpm: use macro supported vendoring
    * Bump to v1.16.0-dev

++++ suse-module-tools:

  - Update to version 16.0.60:
    * spec file: add missing util-linux requirement (bsc#1241465)
    * kernel-scriptlets: enable tracing with KERNEL_PACKAGE_SCRIPT_TRACE=1

------------------------------------------------------------------
------------------  2025-5-14  -  May 14 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Docs: minor punctuation and grammar fixes
  - Give test-image-overlayroot enough space
  - Allow ext2/ext3 as valid build target
    stat reports the value 'ext2/ext3' which is a valid target
  - Added check_target_dir_on_unsupported_filesystem
    Add runtime check to make sure the selected target directory
    for the image and/or the image rootfs lives on a filesystem
    that provides all required features like extended permissions,
    ACLs or xattrs.

++++ fde-tools:

  - Add fde-tools-bsc1243166-firstboot-disable-tpm2-when-sb-is-off.patch
    to not skip the encryption process when Secure Boot is off
    (bsc#1243166)

++++ kernel-default:

  - netfilter: conntrack: clamp maximum hashtable size to INT_MAX (CVE-2025-21648 bsc#1236142)
  - commit fd771b8
  - smb: client: fix UAF in decryption with multichannel
    (bsc#1242510, CVE-2025-37750).
  - commit 68f2d81
  - cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update (CVE-2025-23137 bsc#1241363)
  - commit 48dc7df
  - Update
    patches.suse/md-raid10-wait-barrier-before-returning-discard-request-wi.patch
    (git-fixes CVE-2025-40325 bsc#1241638).
    Update meta-data, adding CVE and bug#.
  - commit b0a6c4b
  - sch_htb: make htb_deactivate() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_ets: make est_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_qfq: make qfq_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_hfsc: make hfsc_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_drr: make drr_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_htb: make htb_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - commit c3254e9
  - Refresh sorted patches.
  - commit 327f25e
  - drivers/platform/x86/amd: pmf: Check for invalid Smart PC
    Policies (git-fixes).
  - commit 70e0f6a
  - Refresh patches.suse/powerpc-boot-Fix-build-with-gcc-15.patch
  - commit 2f5ab59
  - sctp: detect and prevent references to a freed transport in
    sendmsg (CVE-2025-23142 bsc#1242760).
  - commit 23a3fc0
  - scripts/check-kernel-fix: do a full check in verbose mode
    we are skipping evaluation of ineligible (based on CVSS scoring) branches
    to save runtime because a common case is a low score CVE that is not
    eligible to any LTSS branches. Security team would like to know whether
    as specific branch is affected even in those case so let's change the
    implementation and do the full evaluation even if a branch is not
    eligible based on the scoring.
    With the current implementation we are getting
    ./scripts/check-kernel-fix -v CVE-2022-49320
    Security fix for CVE-2022-49320 bsc#1238394 with CVSS 5.5
    = f9a9f43a62a0 ("dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type") merged v5.19-rc1~100^2~37
    Fixes: b0cc417c1637 ("dmaengine: Add Xilinx zynqmp dma engine driver support") merged v4.8-rc1~117^2~7^2~2
    Experts candidates:  tiwai@suse.com (36) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/f9a9f43a62a04ec3183fb0da9226c7706eed0115
    SL-16.0: nope_commit_in_base
    SLE11-SP4-LTSS: nope_cvss
    SLE12-SP3-TD: nope_unaffected
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    SLE15-SP6: nope_commit_in_base
    SLE15-SP7-GA: nope_cvss
    cve/linux-5.14-LTSS: ok_reference_present
    cve/linux-5.3-LTSS: nope_cvss
    SUSE-2024: nope_commit_in_base
    SLE15-SP6-RT: nope_commit_in_base
    SLE15-SP6-COCO: nope_commit_in_base
    SLE15-SP6-AZURE: nope_commit_in_base
    SLE15-SP7: nope_commit_in_base
    SLE15-SP2-LTSS: nope_cvss
    SLE15-SP3-LTSS: ok_reference_present
    SUSE-2024-RT: nope_commit_in_base
    SLE15-SP7-RT: nope_commit_in_base
    SLE15-SP7-COCO: nope_commit_in_base
    SLE15-SP7-AZURE: nope_commit_in_base
    With the updated one we are getting a more specific answer for
    all branches whether they are eligible or not.
    ./scripts/check-kernel-fix -v CVE-2022-49320
    Security fix for CVE-2022-49320 bsc#1238394 with CVSS 5.5
    = f9a9f43a62a0 ("dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type") merged v5.19-rc1~100^2~37
    Fixes: b0cc417c1637 ("dmaengine: Add Xilinx zynqmp dma engine driver support") merged v4.8-rc1~117^2~7^2~2
    Experts candidates:  tiwai@suse.com (36) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/f9a9f43a62a04ec3183fb0da9226c7706eed0115
    SL-16.0: nope_commit_in_base
    SLE11-SP4-LTSS: nope_unaffected
    SLE12-SP3-TD: nope_unaffected
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    SLE15-SP6: nope_commit_in_base
    SLE15-SP7-GA: nope_commit_in_base
    cve/linux-5.14-LTSS: ok_reference_present
    cve/linux-5.3-LTSS: missing_commit_nope_cvss
    SLE12-SP5-RT: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    WW CONFIG_XILINX_ZYNQMP_DMA not enabled.
    SUSE-2024: nope_commit_in_base
    SLE15-SP6-RT: nope_commit_in_base
    SLE15-SP6-COCO: nope_commit_in_base
    SLE15-SP6-AZURE: nope_commit_in_base
    SLE15-SP7: nope_commit_in_base
    SLE15-SP4-LTSS: ok_reference_present
    SLE15-SP5-LTSS: ok_reference_present
    SLE15-SP2-LTSS: missing_commit_nope_cvss
    SLE15-SP3-LTSS: ok_reference_present
    SUSE-2024-RT: nope_commit_in_base
    SLE15-SP7-RT: nope_commit_in_base
    SLE15-SP7-COCO: nope_commit_in_base
    SLE15-SP7-AZURE: nope_commit_in_base
    SLE15-SP4-RT-LTSS: ok_reference_present
    SLE15-SP5-RT-LTSS: ok_reference_present
    SLE15-SP3-RT-LTSS: ok_reference_present
  - commit 2022652

++++ kernel-rt:

  - netfilter: conntrack: clamp maximum hashtable size to INT_MAX (CVE-2025-21648 bsc#1236142)
  - commit fd771b8
  - smb: client: fix UAF in decryption with multichannel
    (bsc#1242510, CVE-2025-37750).
  - commit 68f2d81
  - cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update (CVE-2025-23137 bsc#1241363)
  - commit 48dc7df
  - Update
    patches.suse/md-raid10-wait-barrier-before-returning-discard-request-wi.patch
    (git-fixes CVE-2025-40325 bsc#1241638).
    Update meta-data, adding CVE and bug#.
  - commit b0a6c4b
  - sch_htb: make htb_deactivate() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_ets: make est_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_qfq: make qfq_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_hfsc: make hfsc_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_drr: make drr_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - sch_htb: make htb_qlen_notify() idempotent (CVE-2025-37798
    bsc#1242414).
  - commit c3254e9
  - Refresh sorted patches.
  - commit 327f25e
  - drivers/platform/x86/amd: pmf: Check for invalid Smart PC
    Policies (git-fixes).
  - commit 70e0f6a
  - Refresh patches.suse/powerpc-boot-Fix-build-with-gcc-15.patch
  - commit 2f5ab59
  - sctp: detect and prevent references to a freed transport in
    sendmsg (CVE-2025-23142 bsc#1242760).
  - commit 23a3fc0
  - scripts/check-kernel-fix: do a full check in verbose mode
    we are skipping evaluation of ineligible (based on CVSS scoring) branches
    to save runtime because a common case is a low score CVE that is not
    eligible to any LTSS branches. Security team would like to know whether
    as specific branch is affected even in those case so let's change the
    implementation and do the full evaluation even if a branch is not
    eligible based on the scoring.
    With the current implementation we are getting
    ./scripts/check-kernel-fix -v CVE-2022-49320
    Security fix for CVE-2022-49320 bsc#1238394 with CVSS 5.5
    = f9a9f43a62a0 ("dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type") merged v5.19-rc1~100^2~37
    Fixes: b0cc417c1637 ("dmaengine: Add Xilinx zynqmp dma engine driver support") merged v4.8-rc1~117^2~7^2~2
    Experts candidates:  tiwai@suse.com (36) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/f9a9f43a62a04ec3183fb0da9226c7706eed0115
    SL-16.0: nope_commit_in_base
    SLE11-SP4-LTSS: nope_cvss
    SLE12-SP3-TD: nope_unaffected
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    SLE15-SP6: nope_commit_in_base
    SLE15-SP7-GA: nope_cvss
    cve/linux-5.14-LTSS: ok_reference_present
    cve/linux-5.3-LTSS: nope_cvss
    SUSE-2024: nope_commit_in_base
    SLE15-SP6-RT: nope_commit_in_base
    SLE15-SP6-COCO: nope_commit_in_base
    SLE15-SP6-AZURE: nope_commit_in_base
    SLE15-SP7: nope_commit_in_base
    SLE15-SP2-LTSS: nope_cvss
    SLE15-SP3-LTSS: ok_reference_present
    SUSE-2024-RT: nope_commit_in_base
    SLE15-SP7-RT: nope_commit_in_base
    SLE15-SP7-COCO: nope_commit_in_base
    SLE15-SP7-AZURE: nope_commit_in_base
    With the updated one we are getting a more specific answer for
    all branches whether they are eligible or not.
    ./scripts/check-kernel-fix -v CVE-2022-49320
    Security fix for CVE-2022-49320 bsc#1238394 with CVSS 5.5
    = f9a9f43a62a0 ("dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type") merged v5.19-rc1~100^2~37
    Fixes: b0cc417c1637 ("dmaengine: Add Xilinx zynqmp dma engine driver support") merged v4.8-rc1~117^2~7^2~2
    Experts candidates:  tiwai@suse.com (36) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/f9a9f43a62a04ec3183fb0da9226c7706eed0115
    SL-16.0: nope_commit_in_base
    SLE11-SP4-LTSS: nope_unaffected
    SLE12-SP3-TD: nope_unaffected
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    SLE15-SP6: nope_commit_in_base
    SLE15-SP7-GA: nope_commit_in_base
    cve/linux-5.14-LTSS: ok_reference_present
    cve/linux-5.3-LTSS: missing_commit_nope_cvss
    SLE12-SP5-RT: MANUAL: backport f9a9f43a62a04ec3183fb0da9226c7706eed0115 (Fixes v4.12)
    WW CONFIG_XILINX_ZYNQMP_DMA not enabled.
    SUSE-2024: nope_commit_in_base
    SLE15-SP6-RT: nope_commit_in_base
    SLE15-SP6-COCO: nope_commit_in_base
    SLE15-SP6-AZURE: nope_commit_in_base
    SLE15-SP7: nope_commit_in_base
    SLE15-SP4-LTSS: ok_reference_present
    SLE15-SP5-LTSS: ok_reference_present
    SLE15-SP2-LTSS: missing_commit_nope_cvss
    SLE15-SP3-LTSS: ok_reference_present
    SUSE-2024-RT: nope_commit_in_base
    SLE15-SP7-RT: nope_commit_in_base
    SLE15-SP7-COCO: nope_commit_in_base
    SLE15-SP7-AZURE: nope_commit_in_base
    SLE15-SP4-RT-LTSS: ok_reference_present
    SLE15-SP5-RT-LTSS: ok_reference_present
    SLE15-SP3-RT-LTSS: ok_reference_present
  - commit 2022652

++++ mozilla-nss:

  - update to NSS 3.110
    * bmo#1930806 - FIPS changes need to be upstreamed: force ems policy
    * bmo#1954724 - Prevent excess allocations in sslBuffer_Grow
    * bmo#1953429 - Remove Crl templates from ASN1 fuzz target
    * bmo#1953429 - Remove CERT_CrlTemplate from ASN1 fuzz target
    * bmo#1952855 - Fix memory leak in NSS_CMSMessage_IsSigned
    * bmo#1930807 - NSS policy updates
    * bmo#1951161 - Improve locking in nssPKIObject_GetInstances
    * bmo#1951394 - Fix race in sdb_GetMetaData
    * bmo#1951800 - Fix member access within null pointer
    * bmo#1950077 - Increase smime fuzzer memory limit
    * bmo#1949677 - Enable resumption when using custom extensions
    * bmo#1952568 - change CN of server12 test certificate
    * bmo#1949118 - Part 2: Add missing check in
    NSS_CMSDigestContext_FinishSingle
    * bmo#1949118 - Part 1: Fix smime UBSan errors
    * bmo#1930806 - FIPS changes need to be upstreamed: updated key checks
    * bmo#1951491 - Don't build libpkix in static builds
    * bmo#1951395 - handle `-p all` in try syntax
    * bmo#1951346 - fix opt-make builds to actually be opt
    * bmo#1951346 - fix opt-static builds to actually be opt
    * bmo#1916439 - Remove extraneous assert
  - Removed upstreamed nss-fips-stricter-dh.patch
  - Removed upstreamed nss-reproducible-chksums.patch
  - Added bmo1962556.patch to fix test failures
  - Rebased nss-fips-approved-crypto-non-ec.patch nss-fips-combined-hash-sign-dsa-ecdsa.patch
  - update to NSS 3.109
    * bmo#1939512 - Call BL_Init before RNG_RNGInit() so that special
    SHA instructions can be used if available
    * bmo#1930807 - NSS policy updates - fix inaccurate key policy issues
    * bmo#1945883 - SMIME fuzz target
    * bmo#1914256 - ASN1 decoder fuzz target
    * bmo#1936001 - Part 2: Revert “Extract testcases from ssl gtests
    for fuzzing”
    * bmo#1915155 - Add fuzz/README.md
    * bmo#1936001 - Part 4: Fix tstclnt arguments script
    * bmo#1944545 - Extend pkcs7 fuzz target
    * bmo#1912320 - Extend certDN fuzz target
    * bmo#1944300 - revert changes to HACL* files from bug 1866841
    * bmo#1936001 - Part 3: Package frida corpus script
  - update to NSS 3.108
    * bmo#1923285 - libclang-16 -> libclang-19
    * bmo#1939086 - Turn off Secure Email Trust Bit for Security
    Communication ECC RootCA1
    * bmo#1937332 - Turn off Secure Email Trust Bit for BJCA Global Root
    CA1 and BJCA Global Root CA2
    * bmo#1915902 - Remove SwissSign Silver CA – G2
    * bmo#1938245 - Add D-Trust 2023 TLS Roots to NSS
    * bmo#1942301 - fix fips test failure on windows
    * bmo#1935925 - change default sensitivity of KEM keys
    * bmo#1936001 - Part 1: Introduce frida hooks and script
    * bmo#1942350 - add missing arm_neon.h include to gcm.c
    * bmo#1831552 - ci: update windows workers to win2022
    * bmo#1831552 - strip trailing carriage returns in tools tests
    * bmo#1880256 - work around unix/windows path translation issues
    in cert test script
    * bmo#1831552 - ci: let the windows setup script work without $m
    * bmo#1880255 - detect msys
    * bmo#1936680 - add a specialized CTR_Update variant for AES-GCM
    * bmo#1930807 - NSS policy updates
    * bmo#1930806 - FIPS changes need to be upstreamed: FIPS 140-3 RNG
    * bmo#1930806 - FIPS changes need to be upstreamed: Add SafeZero
    * bmo#1930806 - FIPS changes need to be upstreamed - updated POST
    * bmo#1933031 - Segmentation fault in SECITEM_Hash during pkcs12 processing
    * bmo#1929922 - Extending NSS with LoadModuleFromFunction functionality
    * bmo#1935984 - Ensure zero-initialization of collectArgs.cert
    * bmo#1934526 - pkcs7 fuzz target use CERT_DestroyCertificate
    * bmo#1915898 - Fix actual underlying ODR violations issue
    * bmo#1184059 - mozilla::pkix: allow reference ID labels to begin
    and/or end with hyphens
    * bmo#1927953 - don't look for secmod.db in nssutil_ReadSecmodDB if
    NSS_DISABLE_DBM is set
    * bmo#1934526 - Fix memory leak in pkcs7 fuzz target
    * bmo#1934529 - Set -O2 for ASan builds in CI
    * bmo#1934543 - Change branch of tlsfuzzer dependency
    * bmo#1915898 - Run tests in CI for ASan builds with detect_odr_violation=1
    * bmo#1934241 - Fix coverage failure in CI
    * bmo#1934213 - Add fuzzing for delegated credentials, DTLS short
    header and Tls13BackendEch
    * bmo#1927142 - Add fuzzing for SSL_EnableTls13GreaseEch and
    SSL_SetDtls13VersionWorkaround
    * bmo#1913677 - Part 3: Restructure fuzz/
    * bmo#1931925 - Extract testcases from ssl gtests for fuzzing
    * bmo#1923037 - Force Cryptofuzz to use NSS in CI
    * bmo#1923037 - Fix Cryptofuzz on 32 bit in CI
    * bmo#1933154 - Update Cryptofuzz repository link
    * bmo#1926256 - fix build error from 9505f79d
    * bmo#1926256 - simplify error handling in get_token_objects_for_cache
    * bmo#1931973 - nss doc: fix a warning
    * bmo#1930797 - pkcs12 fixes from RHEL need to be picked up
  - remove obsolete patches
    * nss-fips-safe-memset.patch
    * nss-bmo1930797.patch
  - update to NSS 3.107
    * bmo#1923038 - Remove MPI fuzz targets.
    * bmo#1925512 - Remove globals `lockStatus` and `locksEverDisabled`.
    * bmo#1919015 - Enable PKCS8 fuzz target.
    * bmo#1923037 - Integrate Cryptofuzz in CI.
    * bmo#1913677 - Part 2: Set tls server target socket options in config class
    * bmo#1913677 - Part 1: Set tls client target socket options in config class
    * bmo#1913680 - Support building with thread sanitizer.
    * bmo#1922392 - set nssckbi version number to 2.72.
    * bmo#1919913 - remove Websites Trust Bit from Entrust Root
    Certification Authority - G4.
    * bmo#1920641 - remove Security Communication RootCA3 root cert.
    * bmo#1918559 - remove SecureSign RootCA11 root cert.
    * bmo#1922387 - Add distrust-after for TLS to Entrust Roots.
    * bmo#1927096 - update expected error code in pk12util pbmac1 tests.
    * bmo#1929041 - Use random tstclnt args with handshake collection script
    * bmo#1920466 - Remove extraneous assert in ssl3gthr.c.
    * bmo#1928402 - Adding missing release notes for NSS_3_105.
    * bmo#1874451 - Enable the disabled mlkem tests for dtls.
    * bmo#1874451 - NSS gtests filter cleans up the constucted buffer
    before the use.
    * bmo#1925505 - Make ssl_SetDefaultsFromEnvironment thread-safe.
    * bmo#1925503 - Remove short circuit test from ssl_Init.
  - fix build on loongarch64 (setting it as 64bit arch)
  - Remove upstreamed bmo-1400603.patch
  - Added nss-bmo1930797.patch to fix failing tests in testsuite
  - update to NSS 3.106
    * bmo#1925975 - NSS 3.106 should be distributed with NSPR 4.36.
    * bmo#1923767 - pk12util: improve error handling in p12U_ReadPKCS12File.
    * bmo#1899402 - Correctly destroy bulkkey in error scenario.
    * bmo#1919997 - PKCS7 fuzz target, r=djackson,nss-reviewers.
    * bmo#1923002 - Extract certificates with handshake collection script.
    * bmo#1923006 - Specify len_control for fuzz targets.
    * bmo#1923280 - Fix memory leak in dumpCertificatePEM.
    * bmo#1102981 - Fix UBSan errors for SECU_PrintCertificate and
    SECU_PrintCertificateBasicInfo.
    * bmo#1921528 - add new error codes to mozilla::pkix for Firefox to use.
    * bmo#1921768 - allow null phKey in NSC_DeriveKey.
    * bmo#1921801 - Only create seed corpus zip from existing corpus.
    * bmo#1826035 - Use explicit allowlist for for KDF PRFS.
    * bmo#1920138 - Increase optimization level for fuzz builds.
    * bmo#1920470 - Remove incorrect assert.
    * bmo#1914870 - Use libFuzzer options from fuzz/options/\*.options in CI.
    * bmo#1920945 - Polish corpus collection for automation.
    * bmo#1917572 - Detect new and unfuzzed SSL options.
    * bmo#1804646 - PKCS12 fuzzing target.
  - requires NSPR 4.36
  - update to NSS 3.105
    * bmo#1915792 - Allow importing PKCS#8 private EC keys missing public key
    * bmo#1909768 - UBSAN fix: applying zero offset to null pointer in sslsnce.c
    * bmo#1919577 - set KRML_MUSTINLINE=inline in makefile builds
    * bmo#1918965 - Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys
    * bmo#1918767 - override default definition of KRML_MUSTINLINE
    * bmo#1916525 - libssl support for mlkem768x25519
    * bmo#1916524 - support for ML-KEM-768 in softoken and pk11wrap
    * bmo#1866841 - Add Libcrux implementation of ML-KEM 768 to FreeBL
    * bmo#1911912 - Avoid misuse of ctype(3) functions
    * bmo#1917311 - part 2: run clang-format
    * bmo#1917311 - part 1: upgrade to clang-format 13
    * bmo#1916953 - clang-format fuzz
    * bmo#1910370 - DTLS client message buffer may not empty be on retransmit
    * bmo#1916413 - Optionally print config for TLS client and server
    fuzz target
    * bmo#1916059 - Fix some simple documentation issues in NSS.
    * bmo#1915439 - improve performance of NSC_FindObjectsInit when
    template has CKA_TOKEN attr
    * bmo#1912828 - define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN
  - Fix build error under Leap by rebasing nss-fips-safe-memset.patch.
  - update to NSS 3.104
    * bmo#1910071 - Copy original corpus to heap-allocated buffer
    * bmo#1910079 - Fix min ssl version for DTLS client fuzzer
    * bmo#1908990 - Remove OS2 support just like we did on NSPR
    * bmo#1910605 - clang-format NSS improvements
    * bmo#1902078 - Adding basicutil.h to use HexString2SECItem function
    * bmo#1908990 - removing dirent.c from build
    * bmo#1902078 - Allow handing in keymaterial to shlibsign to make
    the output reproducible
    * bmo#1908990 - remove nec4.3, sunos4, riscos and SNI references
    * bmo#1908990 - remove other old OS (BSDI, old HP UX, NCR,
    openunix, sco, unixware or reliantUnix
    * bmo#1908990 - remove mentions of WIN95
    * bmo#1908990 - remove mentions of WIN16
    * bmo#1913750 - More explicit directory naming
    * bmo#1913755 - Add more options to TLS server fuzz target
    * bmo#1913675 - Add more options to TLS client fuzz target
    * bmo#1835240 - Use OSS-Fuzz corpus in NSS CI
    * bmo#1908012 - set nssckbi version number to 2.70.
    * bmo#1914499 - Remove Email Trust bit from ACCVRAIZ1 root cert.
    * bmo#1908009 - Remove Email Trust bit from certSIGN ROOT CA.
    * bmo#1908006 - Add Cybertrust Japan Roots to NSS.
    * bmo#1908004 - Add Taiwan CA Roots to NSS.
    * bmo#1911354 - remove search by decoded serial in
    nssToken_FindCertificateByIssuerAndSerialNumber
    * bmo#1913132 - Fix tstclnt CI build failure
    * bmo#1913047 - vfyserv: ensure peer cert chain is in db for
    CERT_VerifyCertificateNow
    * bmo#1912427 - Enable all supported protocol versions for UDP
    * bmo#1910361 - Actually use random PSK hash type
    * bmo#1911576 - Initialize NSS DB once
    * bmo#1910361 - Additional ECH cipher suites and PSK hash types
    * bmo#1903604 - Automate corpus file generation for TLS client Fuzzer
    * bmo#1910364 - Fix crash with UNSAFE_FUZZER_MODE
    * bmo#1910605 - clang-format shlibsign.c
  - remove obsolete nss-reproducible-builds.patch
  - update to NSS 3.103
    * bmo#1908623 - move list size check after lock acquisition in sftk_PutObjectToList.
    * bmo#1899542 - Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH,
    * bmo#1909638 - Follow-up to fix test for presence of file nspr.patch.
    * bmo#1903783 - Adjust libFuzzer size limits
    * bmo#1899542 - Add fuzzing support for SSL_SetCertificateCompressionAlgorithm,
    SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk
    * bmo#1899542 - Add fuzzing support for SSL_ENABLE_GREASE and
    SSL_ENABLE_CH_EXTENSION_PERMUTATION
  - Add nss-reproducible-builds.patch to make the rpms reproducible,
    by using a hardcoded, static key to generate the checksums (*.chk-files)
  - Updated nss-fips-approved-crypto-non-ec.patch to enforce
    approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113).
  - update to NSS 3.102.1
    * bmo#1905691 - ChaChaXor to return after the function
  - update to NSS 3.102
    * bmo#1880351 - Add Valgrind annotations to freebl Chacha20-Poly1305.
    * bmo#1901932 - missing sqlite header.
    * bmo#1901080 - GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.
    * bmo#1615298 - improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling.
    * bmo#1660676 - correct length of raw SPKI data before printing in pp utility.

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.153.02 (boo#1243192)

++++ python-Pygments:

  - Redownload source file to have the same version released in pypi.

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20250512 release (bsc#1243123)
  - Security updates for [INTEL-SA-01153](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01153.html)
  - CVE-2024-28956: Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel Processors may allow an authenticated user to potentially enable information disclosure via local access.
  - Security updates for [INTEL-SA-01244](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01244.html)
  - CVE-2025-20103: Insufficient resource pool in the core management mechanism for some Intel Processors may allow an authenticated user to potentially enable denial of service via local access.
  - CVE-2025-20054: Uncaught exception in the core management mechanism for some Intel Processors may allow an authenticated user to potentially enable denial of service via local access.
  - Security updates for [INTEL-SA-01247](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html)
  - CVE-2024-43420: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Atom processors may allow an authenticated user to potentially enable information disclosure via local access.
  - CVE-2025-20623: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel Core processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access.
  - CVE-2024-45332: Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel Processors may allow an authenticated user to potentially enable information disclosure via local access.
  - Security updates for [INTEL-SA-01322](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01322.html)
  - CVE-2025-24495:  Incorrect initialization of resource in the branch prediction unit for some Intel Core Ultra Processors may allow an authenticated user to potentially enable information disclosure via local access.
  - CVE-2025-20012: Incorrect behavior order for some Intel Core Ultra Processors may allow an unauthenticated user to potentially enable information disclosure via physical access.
  - Update for functional issues. Refer to [Intel Core Ultra 200 V Series Processor (Series2)](https://cdrdv2.intel.com/v1/dl/getContent/834774) for details.
  - Update for functional issues. Refer to [Intel Core Ultra 200 V Series Processor](https://cdrdv2.intel.com/v1/dl/getContent/827538) for details.
  - Update for functional issues. Refer to [Intel Core Ultra Processor](https://cdrdv2.intel.com/v1/dl/getContent/792254) for details.
  - Update for functional issues. Refer to [14th/13th Generation Intel Core Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
  - Update for functional issues. Refer to [12th Generation Intel Core Processor Family](https://cdrdv2.intel.com/v1/dl/getContent/682436) for details.
  - Update for functional issues. Refer to [11th Gen Intel Core Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/631123) for details.
  - Update for functional issues. Refer to [10th Gen Intel Core Processor Families Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/341079) for details.
  - Update for functional issues. Refer to [10th Gen Intel Core Processor Families Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/615213) for details.
  - Update for functional issues. Refer to [8th and 9th Generation Intel Core Processor Family Spec Update](https://cdrdv2.intel.com/v1/dl/getContent/337346) for details.
  - Update for functional issues. Refer to [6th Gen Intel Xeon Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/835486) for details.
  - Update for functional issues. Refer to [5th Gen Intel Xeon Processor Scalable Family](https://cdrdv2.intel.com/v1/dl/getContent/793902) for details.
  - Update for functional issues. Refer to [4th Gen Intel Xeon Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/772415) for details.
  - Update for functional issues. Refer to [3rd Generation Intel Xeon Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/634897) for details.
  - Update for functional issues. Refer to [3rd Generation Intel Xeon Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/637780) for details.
  - Update for functional issues. Refer to [2nd Generation Intel Xeon Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/338848) for details.
  - Update for functional issues. Refer to [Intel Xeon 6700-Series Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/820922) for details.
  - Update for functional issues. Refer to [Intel Xeon E-2300 Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/709192) for details.
  - Update for functional issues. Refer to [Intel Xeon D-2700 Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/714071) for details.
  - Update for functional issues. Refer to [Intel Processors and Intel Core i3 N-Series](https://cdrdv2.intel.com/v1/dl/getContent/764616) for details.
  - Update for functional issues. Refer to [Intel Pentium Silver and Intel Celeron Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/336562) for details.
    [#]## New Platforms
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ARL-U          | A1       | 06-b5-00/80 |          | 0000000a | Core Ultra Processor (Series2)
    | ARL-S/HX (8P)  | B0       | 06-c6-02/82 |          | 00000118 | Core Ultra Processor (Series2)
    | ARL-H          | A1       | 06-c5-02/82 |          | 00000118 | Core Ultra Processor (Series2)
    | GNR-AP/SP      | B0       | 06-ad-01/95 |          | 010003a2 | Xeon Scalable Gen6
    | GNR-AP/SP      | H0       | 06-ad-01/20 |          | 0a0000d1 | Xeon Scalable Gen6
    | LNL            | B0       | 06-bd-01/80 |          | 0000011f | Core Ultra 200 V Series Processor
    [#]## Updated Platforms
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ADL            | C0       | 06-97-02/07 | 00000038 | 0000003a | Core Gen12
    | ADL            | H0       | 06-97-05/07 | 00000038 | 0000003a | Core Gen12
    | ADL            | L0       | 06-9a-03/80 | 00000436 | 00000437 | Core Gen12
    | ADL            | R0       | 06-9a-04/80 | 00000436 | 00000437 | Core Gen12
    | ADL-N          | N0       | 06-be-00/19 | 0000001c | 0000001d | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    | AML-Y42        | V0       | 06-8e-0c/94 | 000000fc | 00000100 | Core Gen10 Mobile
    | AZB            | A0/R0    | 06-9a-04/40 | 00000009 | 0000000a | Intel(R) Atom(R) C1100
    | CFL-H          | R0       | 06-9e-0d/22 | 00000102 | 00000104 | Core Gen9 Mobile
    | CLX-SP         | B1       | 06-55-07/bf | 05003707 | 05003901 | Xeon Scalable Gen2
    | CML-H          | R1       | 06-a5-02/20 | 000000fc | 00000100 | Core Gen10 Mobile
    | CML-S102       | Q0       | 06-a5-05/22 | 000000fc | 00000100 | Core Gen10
    | CML-S62        | G1       | 06-a5-03/22 | 000000fc | 00000100 | Core Gen10
    | CML-U42        | V0       | 06-8e-0c/94 | 000000fc | 00000100 | Core Gen10 Mobile
    | CML-U62 V1     | A0       | 06-a6-00/80 | 000000fe | 00000102 | Core Gen10 Mobile
    | CML-U62 V2     | K1       | 06-a6-01/80 | 000000fc | 00000100 | Core Gen10 Mobile
    | CML-Y42        | V0       | 06-8e-0c/94 | 000000fc | 00000100 | Core Gen10 Mobile
    | CPX-SP         | A1       | 06-55-0b/bf | 07002904 | 07002b01 | Xeon Scalable Gen3
    | EMR-SP         | A1       | 06-cf-02/87 | 21000291 | 210002a9 | Xeon Scalable Gen5
    | GLK-R          | R0       | 06-7a-08/01 | 00000024 | 00000026 | Pentium J5040/N5030, Celeron J4125/J4025/N4020/N4120
    | ICL-D          | B0       | 06-6c-01/10 | 010002c0 | 010002d0 | Xeon D-17xx, D-27xx
    | ICL-U/Y        | D1       | 06-7e-05/80 | 000000c6 | 000000ca | Core Gen10 Mobile
    | ICX-SP         | Dx/M1    | 06-6a-06/87 | 0d0003f5 | 0d000404 | Xeon Scalable Gen3
    | MTL            | C0       | 06-aa-04/e6 | 00000020 | 00000024 | Core Ultra Processor
    | RKL-S          | B0       | 06-a7-01/02 | 00000063 | 00000064 | Core Gen11
    | RPL-E/HX/S     | B0       | 06-b7-01/32 | 0000012c | 0000012f | Core Gen13/Gen14
    | RPL-H/P/PX 6+8 | J0       | 06-ba-02/e0 | 00004124 | 00004128 | Core Gen13
    | RPL-HX/S       | C0       | 06-bf-02/07 | 00000038 | 0000003a | Core Gen13/Gen14
    | RPL-S          | H0       | 06-bf-05/07 | 00000038 | 0000003a | Core Gen13/Gen14
    | RPL-U 2+8      | Q0       | 06-ba-03/e0 | 00004124 | 00004128 | Core Gen13
    | SPR-HBM        | Bx       | 06-8f-08/10 | 2c0003e0 | 2c0003f7 | Xeon Max
    | SPR-SP         | E4/S2    | 06-8f-07/87 | 2b000620 | 2b000639 | Xeon Scalable Gen4
    | SPR-SP         | E5/S3    | 06-8f-08/87 | 2b000620 | 2b000639 | Xeon Scalable Gen4
    | SRF-SP         | C0       | 06-af-03/01 | 03000330 | 03000341 | Xeon 6700-Series Processors with E-Cores
    | TGL            | B0/B1    | 06-8c-01/80 | 000000b8 | 000000bc | Core Gen11 Mobile
    | TGL-H          | R0       | 06-8d-01/c2 | 00000052 | 00000056 | Core Gen11 Mobile
    | TGL-R          | C0       | 06-8c-02/c2 | 00000038 | 0000003c | Core Gen11 Mobile
    | TWL            | N0       | 06-be-00/19 | 0000001c | 0000001d | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    | WHL-U          | V0       | 06-8e-0c/94 | 000000fc | 00000100 | Core Gen8 Mobile

------------------------------------------------------------------
------------------  2025-5-13  -  May 13 2025  -------------------
------------------------------------------------------------------

++++ cockpit-tukit:

  - Update to version 0.1.4~git0.6eacfc1:
    * Display message for user if they aren't superuser (bsc#1242139)
    * UI Fixes
    * FEAT: Patternfly 6 support
    * BUMP deps to patternfly-6 and update COCKPIT_REPO_COMMIT
    * fix: Properly handle superuser.allowed
    * Bump @typescript-eslint/eslint-plugin in the types group
    * Bump qunit from 2.19.4 to 2.24.1
    * Bump the stylelint group across 1 directory with 2 updates
    * Bump ts-loader from 9.4.4 to 9.5.2
    * Bump glob from 11.0.1 to 11.0.2
    * Bump the stylelint group with 2 updates
    * Bump @typescript-eslint/eslint-plugin in the types group
    * Bump @babel/preset-typescript from 7.22.5 to 7.27.1
    * Chore: With dependabot now enabled, lets update insecure npm packages
    * Bump the react group with 2 updates
    * Bump esbuild from 0.25.2 to 0.25.4 in the esbuild group
    * ci: Add in dependabot and automated updates to cockpit-lib
    * Translated using Weblate (German)
    * Translated using Weblate (German)
    * Translated using Weblate (Japanese)
    * Translated using Weblate (Japanese)
    * Translated using Weblate (Spanish)
    * Translated using Weblate (Czech)
    * Translated using Weblate (Italian)
    * Translated using Weblate (Portuguese)
    * Translated using Weblate (Portuguese)
    * Translated using Weblate (Swedish)
    * Translated using Weblate (Swedish)
    * Translated using Weblate (Georgian)
    * Translated using Weblate (Georgian)
    * Translated using Weblate (Chinese (Traditional Han script))
    * Translated using Weblate (Chinese (China) (zh_CN))
    * Translated using Weblate (Chinese (China) (zh_CN))
    * Translated using Weblate (French)
    * Translated using Weblate (Polish)
    * Translated using Weblate (Polish)
    * Translated using Weblate (German)
    * Translated using Weblate (German)
    * Translated using Weblate (Chinese (China) (zh_CN))
    * Translated using Weblate (Chinese (China) (zh_CN))
    * Translated using Weblate (Italian)
    * Translated using Weblate (Swedish)
    * Translated using Weblate (Swedish)
    * Translated using Weblate (Czech)
    * Translated using Weblate (Chinese (Traditional Han script))
    * Translated using Weblate (French)
    * Translated using Weblate (Japanese)
    * Translated using Weblate (Japanese)
    * Translated using Weblate (Polish)
    * Translated using Weblate (Polish)
    * Translated using Weblate (Georgian)
    * Translated using Weblate (Georgian)
    * Translated using Weblate (Portuguese)
    * Translated using Weblate (Portuguese)
    * Translated using Weblate (Spanish)
    * Update tukit.pot
    * Added translation using Weblate (Italian)
    * Added translation using Weblate (French)
    * Added translation using Weblate (Spanish)
    * Translated using Weblate (German)
    * Added translation using Weblate (Chinese (Traditional Han script))

++++ python-kiwi:

  - Fix rd.kiwi.oem.luks.reencrypt_randompass workflow
    When requesting a new random key prior reencryption, make
    sure that this new key is referenced in the current in
    memory initrd crypttab such that all subsequent
    tasks e.g. luks resize have permissions to complete while
    inside of this initrd instance

++++ iputils:

  - Security fix [bsc#1242300, CVE-2025-47268]
    * integer overflow in RTT calculation can lead to undefined behavior
    * Add iputils-CVE-2025-47268.patch

++++ kernel-default:

  - Update
    patches.suse/md-fix-mddev-uaf-while-iterating-all_mddevs-list.patch
    (git-fixes CVE-20255-22126 bsc#1241597).
    Update metadata, adding CVE and bug references
  - commit f526dd7
  - Update patches.suse/md-raid1-raid10-don-t-ignore-IO-flags.patch
    (git-fixes CVE-2025-22125 bsc#1241596).
    Update meta-data: add CVE and bug reference
  - commit e4da8bd
  - Delete
    patches.suse/Revert-kallsyms-unexport-kallsyms_lookup_name-and-kallsyms_on_each_symbol.patch.
  - commit a0dbeff
  - net: openvswitch: fix nested key length validation in the set()
    action (CVE-2025-37789 bsc#1242762).
  - commit f1c1667
  - platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
    (git-fixes).
  - commit d054e55
  - platform/x86/amd/pmc: Declare quirk_spurious_8042 for MECHREVO
    Wujie 14XA (GX4HRXL) (git-fixes).
  - commit 6ed7e5e
  - drivers/platform/x86/amd: pmf: Check for invalid sideloaded
    Smart PC Policies (git-fixes).
  - commit 9f77444
  - s390/cpumf: Update CPU Measurement facility extended counter
    set support (bsc#1243118).
  - s390: Add z17 elf platform (bsc#1243119).
  - commit 342b428
  - nvme-pci: add quirk for Samsung PM173x/PM173xa disk
    (bsc#1241148).
  - nvme: Add warning when a partiually unique NID is detected
    (bsc#1241148).
  - nvme: Add 'partial_nid' quirk (bsc#1241148).
  - commit 1ee5e84
  - netfilter: nft_tunnel: fix geneve_opt type confusion addition
    (CVE-2025-22056 bsc#1241525).
  - commit c55bcc7
  - net: export a helper for adding up queue stats (git-fixes).
  - commit 60dc7bb
  - virtio-net: fix total qstat values (git-fixes).
  - commit 8780e19
  - mm, slab: clean up slab->obj_exts always (git-fixes).
  - commit 82e1c69
  - slab: ensure slab->obj_exts is clear in a newly allocated slab
    page (CVE-2025-37774 bsc#1242783).
  - commit bf2c798
  - alloc_tag: uninline code gated by mem_alloc_profiling_key in
    slab allocator (git-fixes dependency).
  - commit fdcf54b
  - virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable()
    (git-fixes).
  - commit 70be972
  - mm: zswap: fix crypto_free_acomp() deadlock in
    zswap_cpu_comp_dead() (CVE-2025-22030 bsc#1241376).
  - commit b15b5e1
  - virtio-net: don't re-enable refill work too early when NAPI
    is disabled (git-fixes).
  - commit 36d0adc
  - scripts/check-kernel-fix: recognized reserved but not published yet CVEs
    We have seen a large pile of CVEs that are not released yet.
    c-k-f currently says
    $ ./scripts/check-kernel-fix CVE-2025-37846
    Can't find sha in upstream: CVE-2025-37846.
    Let's check whether the said CVE is reserved and say so to make the fact
    $ ./scripts/check-kernel-fix CVE-2025-37846
    CVE-2025-37846 is reserved but not fully published
  - commit 97893d4
  - virtio-net: disable delayed refill when pausing rx (git-fixes).
  - commit 896d338
  - vhost-scsi: Fix vhost_scsi_send_bad_target() (git-fixes).
  - commit bc9266a
  - platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
    (git-fixes).
  - platform/x86/amd/pmc: Declare quirk_spurious_8042 for MECHREVO
    Wujie 14XA (GX4HRXL) (git-fixes).
  - drivers/platform/x86/amd: pmf: Check for invalid sideloaded
    Smart PC Policies (git-fixes).
  - commit 44333aa
  - virtio_console: fix missing byte order handling for cols and
    rows (git-fixes).
  - commit 6700379

++++ kernel-firmware-intel:

  - Update to version 20250512 (git commit 9f8e520fd736):
    * intel_vpu: Update NPU firmware

++++ kernel-firmware-sound:

  - Update to version 20250512 (git commit 9f8e520fd736):
    * intel: avs: Update topology file for Digital Microphone Array
    (bsc#1243030)

++++ kernel-rt:

  - Update
    patches.suse/md-fix-mddev-uaf-while-iterating-all_mddevs-list.patch
    (git-fixes CVE-20255-22126 bsc#1241597).
    Update metadata, adding CVE and bug references
  - commit f526dd7
  - Update patches.suse/md-raid1-raid10-don-t-ignore-IO-flags.patch
    (git-fixes CVE-2025-22125 bsc#1241596).
    Update meta-data: add CVE and bug reference
  - commit e4da8bd
  - Delete
    patches.suse/Revert-kallsyms-unexport-kallsyms_lookup_name-and-kallsyms_on_each_symbol.patch.
  - commit a0dbeff
  - net: openvswitch: fix nested key length validation in the set()
    action (CVE-2025-37789 bsc#1242762).
  - commit f1c1667
  - platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
    (git-fixes).
  - commit d054e55
  - platform/x86/amd/pmc: Declare quirk_spurious_8042 for MECHREVO
    Wujie 14XA (GX4HRXL) (git-fixes).
  - commit 6ed7e5e
  - drivers/platform/x86/amd: pmf: Check for invalid sideloaded
    Smart PC Policies (git-fixes).
  - commit 9f77444
  - s390/cpumf: Update CPU Measurement facility extended counter
    set support (bsc#1243118).
  - s390: Add z17 elf platform (bsc#1243119).
  - commit 342b428
  - nvme-pci: add quirk for Samsung PM173x/PM173xa disk
    (bsc#1241148).
  - nvme: Add warning when a partiually unique NID is detected
    (bsc#1241148).
  - nvme: Add 'partial_nid' quirk (bsc#1241148).
  - commit 1ee5e84
  - netfilter: nft_tunnel: fix geneve_opt type confusion addition
    (CVE-2025-22056 bsc#1241525).
  - commit c55bcc7
  - net: export a helper for adding up queue stats (git-fixes).
  - commit 60dc7bb
  - virtio-net: fix total qstat values (git-fixes).
  - commit 8780e19
  - mm, slab: clean up slab->obj_exts always (git-fixes).
  - commit 82e1c69
  - slab: ensure slab->obj_exts is clear in a newly allocated slab
    page (CVE-2025-37774 bsc#1242783).
  - commit bf2c798
  - alloc_tag: uninline code gated by mem_alloc_profiling_key in
    slab allocator (git-fixes dependency).
  - commit fdcf54b
  - virtio-net: free xsk_buffs on error in virtnet_xsk_pool_enable()
    (git-fixes).
  - commit 70be972
  - mm: zswap: fix crypto_free_acomp() deadlock in
    zswap_cpu_comp_dead() (CVE-2025-22030 bsc#1241376).
  - commit b15b5e1
  - virtio-net: don't re-enable refill work too early when NAPI
    is disabled (git-fixes).
  - commit 36d0adc
  - scripts/check-kernel-fix: recognized reserved but not published yet CVEs
    We have seen a large pile of CVEs that are not released yet.
    c-k-f currently says
    $ ./scripts/check-kernel-fix CVE-2025-37846
    Can't find sha in upstream: CVE-2025-37846.
    Let's check whether the said CVE is reserved and say so to make the fact
    $ ./scripts/check-kernel-fix CVE-2025-37846
    CVE-2025-37846 is reserved but not fully published
  - commit 97893d4
  - virtio-net: disable delayed refill when pausing rx (git-fixes).
  - commit 896d338
  - vhost-scsi: Fix vhost_scsi_send_bad_target() (git-fixes).
  - commit bc9266a
  - platform/x86: asus-wmi: Fix wlan_ctrl_by_user detection
    (git-fixes).
  - platform/x86/amd/pmc: Declare quirk_spurious_8042 for MECHREVO
    Wujie 14XA (GX4HRXL) (git-fixes).
  - drivers/platform/x86/amd: pmf: Check for invalid sideloaded
    Smart PC Policies (git-fixes).
  - commit 44333aa
  - virtio_console: fix missing byte order handling for cols and
    rows (git-fixes).
  - commit 6700379

++++ llvm19:

  - Enable build of libc++ for ppc64le

++++ gcc15:

  - Prune set of cross-compilers that conflict with different
    versions from the set using update-alternatives.

++++ libguestfs:

  - Update to version 1.55.11 (jsc#PED-12706)
    * daemon/fstrim.c: Run the fstrim command twice
    * lib/create.c: Fix check after BLKDISCARD
    * daemon: inspect: Remove duplicate root mountpoints in /etc/fstab

++++ mpdecimal:

  - Fix LDXXFLAGS (thank you Stefan Krah for providing the patch)

++++ open-vm-tools:

  - update to 12.5.2 (bsc#1243106):
    https://github.com/vmware/open-vm-tools/blob/stable-12.5.2/ReleaseNotes.md
    https://github.com/vmware/open-vm-tools/blob/stable-12.5.2/open-vm-tools/ChangeLog
    This release resolves CVE-2025-22247. For more information on this
    vulnerability and its impact on Broadcom products, see
    VMSA-2025-0007
    https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25683

++++ pcr-oracle:

  - Update to 0.5.6
    + rsa: adopt OpenSSL 3.0 API to generate RSA key
    + Drop the code for openSSL < 3.0.0
    + Look for signing authority in alternative database
    (bsc#1241957)
  - Bump the requirement of libopenssl-devel to 3.0.0

++++ python-maturin:

  - Update to 1.8.6
    * Print a message when overriding platform tag from
    `_PYTHON_HOST_PLATFORM`
    gh#PyO3/maturin#2594
    * Use the current python interpreter's version when the abi3
    feature is set with no explicit version
    gh#PyO3/maturin#2597

++++ python-packaging:

  - skip primary build only for Tumbleweed (adjust version)

++++ python-setuptools:

  - update to 78.1.1:
    * More fully sanitized the filename in PackageIndex._download.
  - switch build-exclusion to be tumbleweed only

------------------------------------------------------------------
------------------  2025-5-12  -  May 12 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add support for new tarball-based WSL format
    With the new image="wsl" type one can build a WSL container
    image that uses the new tarball format. This Fixes #2678
  - Update SL-Micro build test
    For details see: https://build.opensuse.org/request/show/1272418
  - Required read-only-root-fs for SL-Micro test build
    Changes from the SL-Micro team requires adaptions to the
    integration test description
  - Delete fstab.script from SL-Micro test build
    This was only needed when /var was an extra partition, but
    it's a volume with copy-on-write disabled for some time
  - Add systemd-resolved to TW integration tests
    For some reason it's not longer part of the systemd standard
    installation

++++ kernel-default:

  - KVM: x86/mmu: Prevent installing hugepages when mem attributes
    are changing (git-fixes).
  - commit 0174a2a
  - KVM: SVM: Update dump_ghcb() to use the GHCB snapshot fields
    (git-fixes).
  - commit 891290f
  - KVM: x86/mmu: Check and free obsolete roots in kvm_mmu_reload()
    (git-fixes).
  - commit 774db33
  - nvme: unblock ctrl state transition for firmware update
    (git-fixes).
  - nvmet-tcp: select CONFIG_TLS from CONFIG_NVME_TARGET_TCP_TLS
    (git-fixes).
  - nvme-tcp: select CONFIG_TLS from CONFIG_NVME_TCP_TLS
    (git-fixes).
  - nvme-tcp: fix premature queue removal and I/O failover
    (git-fixes).
  - nvme-pci: fix queue unquiesce check on slot_reset (git-fixes).
  - commit a2b4b26
  - KVM: x86: Check that the high 32bits are clear in
    kvm_arch_vcpu_ioctl_run() (git-fixes).
  - commit fe32097
  - KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
    (git-fixes).
  - commit c609983
  - KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass
    producer (git-fixes).
  - commit 60e8b26
  - KVM: x86: Explicitly treat routing entry type changes as changes
    (git-fixes).
  - commit 00025dc
  - scsi: qla2xxx: Remove duplicate struct crb_addr_pair
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused module parameters (bsc#1243090).
  - scsi: qla2xxx: Remove unused qla2x00_gpsc() (bsc#1243090).
  - scsi: qla2xxx: Remove unused ql_log_qp (bsc#1243090).
  - scsi: qla2xxx: Remove unused qla82xx_wait_for_state_change()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qla82xx_pci_region_offset()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qlt_83xx_iospace_config()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qlt_fc_port_deleted()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qlt_free_qfull_cmds()
    (bsc#1243090).
  - scsi: qla2xxx: Fix typos in a comment (bsc#1243090).
  - scsi: qla2xxx: Mark device strings as nonstring (bsc#1243090).
  - commit 3480857
  - KVM: x86: Reset IRTE to host control if *new* route isn't
    postable (git-fixes).
  - commit 9592682
  - KVM: SVM: Allocate IR data using atomic allocation (git-fixes).
  - commit 853028b
  - KVM: arm64: Fix memory check in host_stage2_set_owner_locked()
    (git-fixes).
  - commit f1fda19
  - KVM: arm64: Fix uninitialized memcache pointer in
    user_mem_abort() (git-fixes).
  - commit 090f76d
  - xenbus: Allow PVH dom0 a non-local xenstore (git-fixes).
  - commit eeaa5aa
  - xenbus: Use kref to track req lifetime (git-fixes).
  - commit 49fbb67
  - Refresh
    patches.suse/io_uring-sqpoll-Increase-task_work-submission-batch-.patch.
    Patch was accepted upstream.  Update the version and add final headers.
  - commit 52da9d4
  - xen: swiotlb: Use swiotlb bouncing if kmalloc allocation
    demands it (git-fixes).
  - commit bef02e3
  - xen-netfront: handle NULL returned by
    xdp_convert_buff_to_frame() (git-fixes).
  - commit fba38b4
  - scsi: lpfc: Copyright updates for 14.4.0.9 patches
    (bsc#1242995).
  - scsi: lpfc: Update lpfc version to 14.4.0.9 (bsc#1242995).
  - scsi: lpfc: Create lpfc_vmid_info sysfs entry (bsc#1242995).
  - scsi: lpfc: Avoid potential ndlp use-after-free in
    dev_loss_tmo_callbk (bsc#1242995).
  - scsi: lpfc: Prevent failure to reregister with NVMe transport
    after PRLI retry (bsc#1242995).
  - scsi: lpfc: Restart eratt_poll timer if HBA_SETUP flag still
    unset (bsc#1242995).
  - scsi: lpfc: Notify FC transport of rport disappearance during
    PCI fcn reset (bsc#1242995).
  - scsi: lpfc: Fix lpfc_check_sli_ndlp() handling for GEN_REQUEST64
    commands (bsc#1242995).
  - scsi: lpfc: Fix spelling mistake 'Toplogy' -> 'Topology'
    (bsc#1242995).
  - scsi: lpfc: Convert timeouts to secs_to_jiffies() (bsc#1242995).
  - scsi: lpfc: convert timeouts to secs_to_jiffies() (bsc#1242995).
  - commit 45811f8
  - scsi: lpfc: Use memcpy() for BIOS version (bsc#1240965).
  - commit 53e46c0
  - Update patches.suse/powerpc-pseries-iommu-create-DDW-for-devices-with-DM.patch
    (bsc#1239691 bsc#1243044 ltc#212555).
  - commit ebbb0e6
  - usb: typec: tcpm: delay SNK_TRY_WAIT_DEBOUNCE to SRC_TRYWAIT
    transition (git-fixes).
  - commit 8f8f222
  - USB: usbtmc: use interruptible sleep in usbtmc_read (git-fixes).
  - commit b7a1a0c
  - usb: typec: ucsi: displayport: Fix NULL pointer access
    (git-fixes).
  - commit 0670aa5
  - usb: typec: ucsi: displayport: Fix deadlock (git-fixes).
  - commit b6bdc79
  - dm-integrity: fix a warning on invalid table line (git-fixes).
  - commit a020eab
  - usb: gadget: tegra-xudc: ACK ST_RC after clearing CTRL_RUN
    (git-fixes).
  - commit e100777
  - bpf: Scrub packet on bpf_redirect_peer (git-fixes).
  - commit 652efa2
  - check-for-config-changes: Fix flag name typo
  - commit 1046b16
  - netfilter: socket: Lookup orig tuple for IPv6 SNAT
    (CVE-2025-22021 bsc#1241282).
  - commit 19d5805
  - Drivers: hv: Make the sysfs node size for the ring buffer
    dynamic (git-fixes).
  - uio_hv_generic: Fix sysfs creation path for ring buffer
    (git-fixes).
  - commit 5be80b8
  - Move upstreamed sound patch into sorted section
  - commit bb3dd19
  - Input: xpad - fix two controller table values (git-fixes).
  - Input: mtk-pmic-keys - fix possible null pointer dereference
    (git-fixes).
  - Input: cyttsp5 - fix power control issue on wakeup (git-fixes).
  - Input: cyttsp5 - ensure minimum reset pulse width (git-fixes).
  - commit bc65477

++++ kernel-rt:

  - KVM: x86/mmu: Prevent installing hugepages when mem attributes
    are changing (git-fixes).
  - commit 0174a2a
  - KVM: SVM: Update dump_ghcb() to use the GHCB snapshot fields
    (git-fixes).
  - commit 891290f
  - KVM: x86/mmu: Check and free obsolete roots in kvm_mmu_reload()
    (git-fixes).
  - commit 774db33
  - nvme: unblock ctrl state transition for firmware update
    (git-fixes).
  - nvmet-tcp: select CONFIG_TLS from CONFIG_NVME_TARGET_TCP_TLS
    (git-fixes).
  - nvme-tcp: select CONFIG_TLS from CONFIG_NVME_TCP_TLS
    (git-fixes).
  - nvme-tcp: fix premature queue removal and I/O failover
    (git-fixes).
  - nvme-pci: fix queue unquiesce check on slot_reset (git-fixes).
  - commit a2b4b26
  - KVM: x86: Check that the high 32bits are clear in
    kvm_arch_vcpu_ioctl_run() (git-fixes).
  - commit fe32097
  - KVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
    (git-fixes).
  - commit c609983
  - KVM: x86: Take irqfds.lock when adding/deleting IRQ bypass
    producer (git-fixes).
  - commit 60e8b26
  - KVM: x86: Explicitly treat routing entry type changes as changes
    (git-fixes).
  - commit 00025dc
  - scsi: qla2xxx: Remove duplicate struct crb_addr_pair
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused module parameters (bsc#1243090).
  - scsi: qla2xxx: Remove unused qla2x00_gpsc() (bsc#1243090).
  - scsi: qla2xxx: Remove unused ql_log_qp (bsc#1243090).
  - scsi: qla2xxx: Remove unused qla82xx_wait_for_state_change()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qla82xx_pci_region_offset()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qlt_83xx_iospace_config()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qlt_fc_port_deleted()
    (bsc#1243090).
  - scsi: qla2xxx: Remove unused qlt_free_qfull_cmds()
    (bsc#1243090).
  - scsi: qla2xxx: Fix typos in a comment (bsc#1243090).
  - scsi: qla2xxx: Mark device strings as nonstring (bsc#1243090).
  - commit 3480857
  - KVM: x86: Reset IRTE to host control if *new* route isn't
    postable (git-fixes).
  - commit 9592682
  - KVM: SVM: Allocate IR data using atomic allocation (git-fixes).
  - commit 853028b
  - KVM: arm64: Fix memory check in host_stage2_set_owner_locked()
    (git-fixes).
  - commit f1fda19
  - KVM: arm64: Fix uninitialized memcache pointer in
    user_mem_abort() (git-fixes).
  - commit 090f76d
  - xenbus: Allow PVH dom0 a non-local xenstore (git-fixes).
  - commit eeaa5aa
  - xenbus: Use kref to track req lifetime (git-fixes).
  - commit 49fbb67
  - Refresh
    patches.suse/io_uring-sqpoll-Increase-task_work-submission-batch-.patch.
    Patch was accepted upstream.  Update the version and add final headers.
  - commit 52da9d4
  - xen: swiotlb: Use swiotlb bouncing if kmalloc allocation
    demands it (git-fixes).
  - commit bef02e3
  - xen-netfront: handle NULL returned by
    xdp_convert_buff_to_frame() (git-fixes).
  - commit fba38b4
  - scsi: lpfc: Copyright updates for 14.4.0.9 patches
    (bsc#1242995).
  - scsi: lpfc: Update lpfc version to 14.4.0.9 (bsc#1242995).
  - scsi: lpfc: Create lpfc_vmid_info sysfs entry (bsc#1242995).
  - scsi: lpfc: Avoid potential ndlp use-after-free in
    dev_loss_tmo_callbk (bsc#1242995).
  - scsi: lpfc: Prevent failure to reregister with NVMe transport
    after PRLI retry (bsc#1242995).
  - scsi: lpfc: Restart eratt_poll timer if HBA_SETUP flag still
    unset (bsc#1242995).
  - scsi: lpfc: Notify FC transport of rport disappearance during
    PCI fcn reset (bsc#1242995).
  - scsi: lpfc: Fix lpfc_check_sli_ndlp() handling for GEN_REQUEST64
    commands (bsc#1242995).
  - scsi: lpfc: Fix spelling mistake 'Toplogy' -> 'Topology'
    (bsc#1242995).
  - scsi: lpfc: Convert timeouts to secs_to_jiffies() (bsc#1242995).
  - scsi: lpfc: convert timeouts to secs_to_jiffies() (bsc#1242995).
  - commit 45811f8
  - scsi: lpfc: Use memcpy() for BIOS version (bsc#1240965).
  - commit 53e46c0
  - Update patches.suse/powerpc-pseries-iommu-create-DDW-for-devices-with-DM.patch
    (bsc#1239691 bsc#1243044 ltc#212555).
  - commit ebbb0e6
  - usb: typec: tcpm: delay SNK_TRY_WAIT_DEBOUNCE to SRC_TRYWAIT
    transition (git-fixes).
  - commit 8f8f222
  - USB: usbtmc: use interruptible sleep in usbtmc_read (git-fixes).
  - commit b7a1a0c
  - usb: typec: ucsi: displayport: Fix NULL pointer access
    (git-fixes).
  - commit 0670aa5
  - usb: typec: ucsi: displayport: Fix deadlock (git-fixes).
  - commit b6bdc79
  - dm-integrity: fix a warning on invalid table line (git-fixes).
  - commit a020eab
  - usb: gadget: tegra-xudc: ACK ST_RC after clearing CTRL_RUN
    (git-fixes).
  - commit e100777
  - bpf: Scrub packet on bpf_redirect_peer (git-fixes).
  - commit 652efa2
  - check-for-config-changes: Fix flag name typo
  - commit 1046b16
  - netfilter: socket: Lookup orig tuple for IPv6 SNAT
    (CVE-2025-22021 bsc#1241282).
  - commit 19d5805
  - Drivers: hv: Make the sysfs node size for the ring buffer
    dynamic (git-fixes).
  - uio_hv_generic: Fix sysfs creation path for ring buffer
    (git-fixes).
  - commit 5be80b8
  - Move upstreamed sound patch into sorted section
  - commit bb3dd19
  - Input: xpad - fix two controller table values (git-fixes).
  - Input: mtk-pmic-keys - fix possible null pointer dereference
    (git-fixes).
  - Input: cyttsp5 - fix power control issue on wakeup (git-fixes).
  - Input: cyttsp5 - ensure minimum reset pulse width (git-fixes).
  - commit bc65477

++++ libguestfs:

  - Use FUSE3 starting with suse_version 1600 (aka CODE16): Release
    CODE16 from the beginning without relying on FUSE 2.
  - Do not add the patch conditionally to the .src.rpm, but only
    apply the patch conditionally: allows to reuse src.rpm across
    codestreams.

++++ harfbuzz:

  - Update to version 11.2.1:
    + Various build improvements.
    + Fix build with HB_NO_DRAW and HB_NO_PAINT.
    + Add an optional harfruzz shaper that uses HarfRuzz; an ongoing
    Rust port of HarfBuzz shaping. This shaper is mainly used for
    testing the output of the Rust implementation.
    + Fix regression that caused applying unsafe_to_break() to the
    whole buffer to be ignored.
    + Update USE data files.
    + Fix getting advances of out-of-rage glyph indices in
    DirectWrite font functions.
  - Changes from version 11.2.0:
    + Painting of COLRv1 fonts without clip boxes is now about 10
    times faster.
    + Synthetic bold/slant of a sub font is now respected, instead of
    using the parent’s.
    + Glyph extents for fonts synthetic bold/slant are now accurately
    calculated.
    + Various build fixes.

++++ ncurses:

  - Add ncurses patch 20250510
    + add rv/xr codes for domterm, mintty, mlterm -TD
    + add xr code for putty -TD
    + update teraterm to 5.0 -TD
    + add rlogin-color -TD

++++ openssl-3:

  - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and
    the functionality to allow/deny via crypto-policies. [jsc#PED-12224]
    * Remove openssl-rh-allow-sha1-signatures.patch
    * Add patches:
  - openssl-Allow-disabling-of-SHA1-signatures.patch
  - openssl-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch
  - openssl-FIPS-Allow-SHA1-in-seclevel-2-if-rh-allow-sha1-signatures.patch

++++ podman:

  - Add patch for bsc#1242132:
    * 0002-Fix-Remove-appending-rw-as-the-default-mount-option.patch
  - Rebase patches:
    * 0001-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch
  - Removed patches:
    * 0001-vendor-bump-buildah-to-1.37.6-CVE-2024-11218.patch
    * 0002-CVE-2025-27144-vendor-don-t-allow-unbounded-amounts-.patch
    * 0003-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch
  - Drop iptables support in favor of nftables (required by netavark)
  - Fix conditional Requires (remove deprecated sle_version macro)
  - Update to version 5.4.2:
    * Bump to v5.4.2
    * Add release notes for v5.4.2
    * Fix a potential deadlock during `podman cp`
    * Improve the file format documentation of podman-import.
    * Revert "podman-import only supports gz and tar"
    * Bump buildah to v1.39.4
    * libpod: do not cover idmapped mountpoint
    * test: Fix runc error message
    * oci: report empty exec path as ENOENT
    * test: adapt tests new crun error messages
    * test: remove duplicate test
    * cirrus: test only on f41/rawhide
    * CI: use z1d instance for windows machine testing
    * New images 2025-03-24
    * test/e2e: use go net.Dial() ov nc
    * test: use ncat over nc
    * New images 2025-03-12
    * RPM: Add riscv64 to ExclusiveArch-es
    * Fix HealthCheck log destination, count, and size defaults
    * Win installer test: hardcode latest GH release ID
    * Packit: Fix action script for fetching upstream commit
    * Bump to v5.4.2-dev
    * Bump to v5.4.1
    * update gvproxy version to 0.8.4
    * Update Buildah to v1.39.2
    * Update release notes for v5.4.1
    * Fix reporting summed image size for compat endpoint
    * podman-import only supports gz and tar
    * quadlet kube: correctly mark unit as failed
    * pkg/domain/infra/abi/play.go: fix two nilness issues
    * kube play: don't print start errors twice
    * libpod: race in WaitForConditionWithInterval()
    * libpod: race in WaitForExit() with autoremove
    * Don't try to resolve host path if copying to container from stdin.
    * Use svg for pkginstaller banner
    * Create quota before _data dir for volumes
    * Packit: clarify secondary status in CI
    * Packit/RPM: Display upstream commit SHA in all rpm builds
    * podman run: fix --pids-limit -1 wrt runc
    * vendor: update github.com/go-jose/go-jose/v3 to v3.0.4
    * chore(deps): update module github.com/go-jose/go-jose/v4 to v4.0.5 [security]
    * wire up --retry-delay for artifact pull
    * Revert "silence false positve from golangci-lint"
    * update golangci-lint to v1.64.4
    * update golangci-lint to v1.64.2
    * silence false positve from golangci-lint
    * cmd/podman: refactor Context handling
    * fix new usetesting lint issue
    * Packit/Copr: Fix `podman version` in rpm
    * Remove persist directory when cleaning up Conmon files
    * Bump to v5.4.1-dev
    * Bump to v5.4.0
    * Update release notes for v5.4.0 final
    * In SQLite state, use defaults for empty-string checks
    * Bump FreeBSD version to 13.4
    * docs: add v5.4 to API reference
    * Update rpm/podman.spec
    * RPM: set buildOrigin in LDFLAG
    * RPM: cleanup macro defs
    * Makefile: escape BUILD_ORIGIN properly
    * rootless: fix hang on s390x
    * Set Cirrus DEST_BRANCH appropriately to fix CI
    * Bump to v5.4.0-dev
    * Bump to v5.4.0-rc3
    * Update release notes for v5.4.0-rc3
    * Add BuildOrigin field to podman info
    * artifact: only allow single manifest
    * test/e2e: improve write/removeConf()
    * Add --noheading to artifact ls
    * Add --no-trunc to artifact ls
    * Add type and annotations to artifact add
    * pkg/api: honor cdi devices from the hostconfig
    * util: replace Walk with WalkDir
    * fix(pkg/rootless): avoid memleak during init() contructor.
    * Add `machine init --playbook`
    * RPM: include empty check to silence rpmlint
    * RPM: adjust qemu dependencies
    * Force use of iptables on Windows WSL
    * rpm: add attr as dependency for podman-tests
    * update gvproxy version
    * [v5.4] Bump Buildah to v1.39.0
    * podman exec: correctly support detaching
    * libpod: remove unused ExecStartAndAttach()
    * [v5.4] Bump c/storage to v1.57.1, c/image v5.34.0, c/common v0.62.0
    * Move detection of libkrun and intel
    * Prevent two podman machines running on darwin
    * Remove unnecessary error handling
    * Remove usused Kind() function
    * Bump to v5.4.0-dev
    * Bump to v5.4.0-rc2
    * Update release notes for v5.4.0-rc2
    * Safer use of `filepath.EvalSymlinks()` on Windows
    * error with libkrun on intel-based machines
    * chore(deps): update dependency pytest to v8.3.4
    * test/buildah-bud: skip two new problematic tests on remote
    * Fix podman-restart.service when there are no containers
    * Avoid upgrading from v5.3.1 on Windows
    * Clean up after unexpectedly terminated build
    * system-tests: switch ls with getfattr for selinux tests
    * vendor latest c/{buildah,common,image,storage}
    * Makefile: Add validatepr description for 'make help' output
    * docs: Enhance podman build --secret documentation and add examples
    * docs: mount.md - idmapped mounts only work for root user
    * Define, and use, PodmanExitCleanlyWithOptions
    * Eliminate PodmanSystemdScope
    * Fix image ID query
    * Revert "Use the config digest to compare images loaded/pulled using different methods"
    * Update c/image after https://github.com/containers/image/pull/2613
    * Update expected errors when pulling encrypted images
    * Eliminate PodmanExtraFiles
    * Introduce PodmanTestIntegration.PodmanWithOptions
    * Restructure use of options
    * Inline PodmanBase into callers
    * Pass all of PodmanExecOptions to various [mM]akeOptions functions
    * Turn PodmanAsUserBase into PodmanExecBaseWithOptions
    * Avoid indirect links through quadlet(5)
    * do not set the CreateCommand for API users
    * Add podman manifest rm --ignore
    * Bump to v5.4.0-dev
    * Bump to v5.4.0-rc1
    * fix(deps): update module github.com/containers/gvisor-tap-vsock to v0.8.2
    * podman artifact
    * vendor latest c/{common,image,storage}
    * fix(deps): update module github.com/rootless-containers/rootlesskit/v2 to v2.3.2
    * cirrus: bump macos machine test timeout
    * pkg/machine/e2e: improve podman.exe match
    * pkg/machine/e2e: improve "list machine from all providers"
    * Remove JSON tag from UseImageHosts in ContainerConfig
    * Set network ID if available during container inspect
    * Stop creating a patch for v5.3.1 upgrades on windows
    * compose docs: fix typo
    * Document kube-play CDI support
    * docs: Add quadlet debug method systemd-analyze
    * Replace instances of PodmanExitCleanly in play_kube_test.go
    * docs: add 'initialized' state to status filters
    * fix(deps): update module google.golang.org/protobuf to v1.36.3
    * Switch all calls of assert.Nil to assert.NoError
    * Add --no-hostname option
    * Fix unescaping octal escape sequence in values of Quadlet unit files
    * Remove `.exe` suffix if any
    * Add kube play support for CDI resource allocation
    * add support to `;` for comments in unit files as per systemd documentation
    * Use PodmanExitCleanly in attach_test.go
    * Introduce PodmanTestIntegration.PodmanExitCleanly
    * chore(deps): update dependency setuptools to ~=75.8.0
    * Add newer c/i to support artifacts
    * fix(deps): update module golang.org/x/tools to v0.29.0
    * fix(deps): update module golang.org/x/net to v0.34.0
    * specgenutil: Fix parsing of mount option ptmxmode
    * namespaces: allow configuring keep-id userns size
    * Update description for completion
    * Quadlet - make sure the /etc/containers/systemd/users is traversed in rootless
    * Document .build for Image .container option
    * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.9.1
    * New VM Images
    * update golangci/golangci-lint to v1.63.4
    * fix(deps): update module google.golang.org/protobuf to v1.36.2
    * chore(deps): update dependency setuptools to ~=75.7.0
    * Fixing ~/.ssh/identity handling
    * vendor latest c/common from main
    * fix(deps): update module github.com/shirou/gopsutil/v4 to v4.24.12
    * fix(deps): update module github.com/opencontainers/runc to v1.2.4
    * specgen: fix comment
    * Add hint to restart Podman machine to really accept new certificates
    * fix(deps): update module github.com/onsi/gomega to v1.36.2
    * fix(deps): update module github.com/moby/term to v0.5.2
    * Pass container hostname to netavark
    * Fix slirp4netns typo in podman-network.1.md
    * Add support to ShmSize in Pods with Quadlet
    * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.22.1
    * chore(deps): update module golang.org/x/crypto to v0.31.0 [security]
    * fix(deps): update module golang.org/x/net to v0.33.0 [security]
    * Kube volumes can not container _
    * fix(deps): update module github.com/docker/docker to v27.4.1+incompatible
    * test/system: fix "podman play --build private registry" error
    * test/system: CopyDirectory() do not chown files
    * test/system: remove system dial-stdio test
    * shell completion: respect CONTAINERS_REGISTRIES_CONF
    * fix(deps): update module github.com/cpuguy83/go-md2man/v2 to v2.0.6
    * When generating host volumes for k8s, force to lowercase
    * test: enable newly added test
    * vfkit: Use 0.6.0 binary
    * gvproxy: Use 0.8.1 binary
    * systemd: simplify parser and fix infinite loop
    * Revert "win-installer test: revert to v5.3.0"
    * Avoid rebooting twice when installing WSL
    * Avoid rebooting on Windows when upgrading and WSL isn't installed
    * Add win installer patch
    * Bump WiX toolset version to 5.0.2
    * test/e2e: SkipOnOSVersion() add reason field
    * test/e2e: remove outdated SkipOnOSVersion() calls
    * Update VM images
    * fix(deps): update module golang.org/x/crypto to v0.31.0 [security]
    * fix(deps): update module github.com/crc-org/crc/v2 to v2.45.0
    * fix(deps): update module github.com/opencontainers/runc to v1.2.3
    * quadlet: fix inter-dependency of containers in `Network=`
    * Add man pages to Mac installer
    * fix(deps): update module github.com/onsi/gomega to v1.36.1
    * fix(deps): update module github.com/docker/docker to v27.4.0+incompatible
    * Fix device limitations in podman-remote update on remote systems
    * Use latest version of VS BuildTools
    * bin/docker: fix broken escaping and variable substitution
    * manifest annotate: connect IndexAnnotations
    * Fix panic in `manifest annotate --index`
    * fix(deps): update module github.com/cyphar/filepath-securejoin to v0.3.5
    * fix(deps): update module golang.org/x/net to v0.32.0
    * fix(deps): update module golang.org/x/tools to v0.28.0
    * fix(deps): update module golang.org/x/crypto to v0.30.0
    * fix(deps): update module golang.org/x/sys to v0.28.0
    * Fix overwriting of LinuxResources structure in the database
    * api: replace inspectID with name
    * fix(deps): update github.com/opencontainers/runtime-tools digest to f7e3563
    * Replace ExclusiveArch with ifarch
    * fix(deps): update module github.com/containers/gvisor-tap-vsock to v0.8.1
    * Improve platform specific URL handling in `podman compose` for machines
    * Fix `podman info` with multiple imagestores
    * Switch to fixed common
    * refact: use uptime.minutes instead of uptime.seconds
    * fix(deps): update module github.com/shirou/gopsutil/v4 to v4.24.11
    * fix(deps): update golang.org/x/exp digest to 2d47ceb
    * fix(deps): update github.com/godbus/dbus/v5 digest to c266b19
    * Cover Unix socket in inpect test on Windows platform
    * Add a test for forcing compression and v2s2 format
    * fix(deps): update module github.com/crc-org/vfkit to v0.6.0
    * Package podman-machine on supported architectures only.
    * Fixes missing binary in systemd.
    * stats: ignore errors from containers without cgroups
    * api: Error checking before NULL dereference
    * [skip-ci] Packit/copr: switch to fedora-all
    * make remotesystem: fail early if serial tests fail
    * spec: clamp rlimits without CAP_SYS_RESOURCE
    * Clarify the reason for skip_if_remote
    * Sanity-check that the test is really using partial pulls
    * Fix apparent typos in zstd:chunked tests
    * Fix compilation issues in QEMU machine files (Windows platform)
    * Mount volumes before copying into a container
    * Revert "libpod: remove shutdown.Unregister()"
    * docs: improve documentation for internal networks
    * docs: document bridge mode option
    * [skip-ci] Packit: remove epel and re-enable c9s
    * chore(deps): update dependency golangci/golangci-lint to v1.62.2
    * vendor: update containers/common
    * OWNERS: remove edsantiago
    * fix(deps): update module github.com/onsi/gomega to v1.36.0
    * fix(deps): update github.com/containers/common digest to ceceb40
    * refact: EventerType and improve consistency
    * Add --hosts-file flag to container and pod commands
    * Add nohosts option to /build and /libpod/build
    * fix(deps): update module github.com/stretchr/testify to v1.10.0
    * Quadlet - Use = sign when setting the pull arg for build
    * win-installer test: revert to v5.3.0
    * fix(deps): update module github.com/crc-org/crc/v2 to v2.44.0
    * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.22.0
    * chore(deps): update dependency setuptools to ~=75.6.0
    * Update windows installer tests
    * Windows: don't install WSL/HyperV on update
    * Switch to non-installing WSL by default
    * fix(deps): update github.com/containers/buildah digest to 52437ef
    * Configure HealthCheck with `podman update`
    * CI: --image-volume test: robustify
    * docs: add 5.3 as Reference version
    * Bump CI VMs
    * libpod: pass down NoPivotRoot to Buildah
    * vendor: bump containers/buildah
    * fix(deps): update module github.com/opencontainers/runc to v1.2.2
    * Overlay mounts supersede image volumes & volumes-from
    * libpod: addHosts() prevent nil deref
    * only read ssh_config for non machine connections
    * ssh_config: allow IdentityFile file with tilde
    * ssh_config: do not overwrite values from config file
    * connection: ignore errors when parsing ssh_config
    * Bump bundled krunkit to 0.1.4
    * fix(deps): update module google.golang.org/protobuf to v1.35.2
    * add support for driver-specific options during container creation
    * doc: fix words repetitions
    * Update release notes on main for v5.3.0
    * chore(deps): update dependency setuptools to ~=75.5.0
    * CI: system tests: parallelize 010
    * fix podman machine init --ignition-path
    * vendor: update containers/common
    * spec: clamp rlimits in a userns
    * Add subpath support to volumes in `--mount` option
    * refactor: simplify LinuxNS type definition and String method
    * test/e2e: remove FIPS test
    * vendor containers projects to tagged versions
    * fix(deps): update module github.com/moby/sys/capability to v0.4.0
    * chore(deps): update dependency setuptools to ~=75.4.0
    * system tests: safer install_kube_template()
    * Buildah treadmill tweaks
    * update golangci-lint to v1.62.0
    * fix(deps): update module golang.org/x/net to v0.31.0
    * fix(deps): update module golang.org/x/tools to v0.27.0
    * Revert "Reapply "CI: test nftables driver on fedora""
    * Yet another bump, f41 with fixed kernel
    * test: add zstd:chunked system tests
    * pkg/machine/e2e: remove dead code
    * fix(deps): update module golang.org/x/crypto to v0.29.0
    * kube SIGINT system test: fix race in timeout handling
    * New `system connection add` tests
    * Update codespell to v2.3.0
    * Avoid printing PR text to stdout in system test
    * Exclude symlink from pre-commit end-of-file-fixer
    * api: Add error check
    * [CI:ALL] Bump main to v5.4.0-dev
    * test/buildah-bud: build new inet helper
    * test/system: add regression test for TZDIR local issue
    * vendor latest c/{buildah,common,image,storage}
    * Reapply "CI: test nftables driver on fedora"
    * Revert "cirrus: test only on f40/rawhide"
    * test f41 VMs
    * AdditionalSupport for SubPath volume mounts
    * wsl-e2e: Add a test to ensure port 2222 is free with usermode networking
    * winmake.ps1: Fix the syntax of the function call Win-SSHProxy
    * volume ls: fix race that caused it to fail
    * gvproxy: Disable port-forwarding on WSL
    * build: update gvisor-tap-vsock to 0.8.0
    * podman: update roadmap
    * Log network creation and removal events in Podman
    * libpod: journald do not lock thread
    * Add key to control if a container can get started by its pod
    * Honor users requests in quadlet files
    * CI: systests: workaround for parallel podman-stop flake
    * Fix inconsistent line ending in win-installer project
    * fix(deps): update module github.com/opencontainers/runc to v1.2.1
    * Quadlet - support image file based mount in container file
    * API: container logs flush status code
    * rework event code to improve API errors
    * events: remove memory eventer
    * libpod: log file use Wait() over event API
    * Makefile: vendor target should always remove toolchain
    * cirrus: check consitent vendoring in test/tools
    * test/tools/go.mod: remove toolchain
    * fix(deps): update module github.com/shirou/gopsutil/v4 to v4.24.10
    * fix(deps): update module github.com/onsi/gomega to v1.35.1
    * doc: explain --interactive in more detail
    * fix(deps): update golang.org/x/exp digest to f66d83c
    * fix(deps): update github.com/opencontainers/runtime-tools digest to 6c9570a
    * fix(deps): update github.com/linuxkit/virtsock digest to cb6a20c
    * add default polling interval to Container.Wait
    * Instrument cleanup tracer to log weird volume removal flake
    * make podman-clean-transient.service work as user
    * Add default remote socket path if empty
    * Use current user if no user specified
    * Add support for ssh_config for connection
    * libpod: use pasta Setup() over Setup2()
    * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.21.0
    * fix(deps): update module github.com/onsi/gomega to v1.35.0
    * logformatter: add cleanup tracer log link
    * docs: fix broken example
    * docs: add missing swagger links for the stable branches
    * readthedocs: build extra formats
    * pkg/machine/e2e: remove debug
    * fix(docs): Integrate pasta in rootless tutorial
    * chore(deps): update dependency setuptools to ~=75.3.0
    * libpod: report cgroups deleted during Stat() call
    * chore: fix some function names in comment
    * CI: parallelize 450-interactive system tests
    * CI: parallelize 520-checkpoint tests
    * CI: make 070-build.bats use safe image names
    * test/system: add podman network reload test to distro gating
    * System tests: clean up unit file leaks
    * healthcheck: do not leak service on failed stop
    * healthcheck: do not leak statup service
    * fix(deps): update module github.com/containers/gvisor-tap-vsock to v0.8.0
    * Add Startup HealthCheck configuration to the podman inspect
    * buildah version display: use progress()
    * new showrun() for displaying and running shell commands
    * Buildah treadmill: redo the .cirrus.yml tweaks
    * Buildah treadmill: more allow-empty options
    * Buildah treadmill: improve test-failure instructions
    * Buildah treadmill: improve wording in test-fail instructions
    * doc: Remove whitespace before comma
    * fix(deps): update module github.com/checkpoint-restore/checkpointctl to v1.3.0
    * ps: fix display of exposed ports
    * ps: do not loop over port protocol
    * readme: Add reference to pasta in the readme
    * test/system: Fix spurious "duplicate tests" failures in pasta tests
    * Improve "podman load - from URL"
    * Try to repair c/storage after removing an additional image store
    * Use the config digest to compare images loaded/pulled using different methods
    * Simplify the additional store test
    * Fix the store choice in "podman pull image with additional store"
    * Bump to v5.3.0-dev
    * Bump to v5.3.0-rc1
    * Set quota on volume root directory, not _data
    * fix(deps): update module github.com/opencontainers/runc to v1.2.0
    * test: set soft ulimit
    * Vagrantfile: Delete
    * Enable pod restore with crun
    * vendor: update c/{buildah,common,image,storage}
    * Fix 330-corrupt-images.bats in composefs test runs
    * quadlet: add default network dependencies to all units
    * quadlet: ensure user units wait for the network
    * add new podman-user-wait-network-online.service
    * contrib/systemd: switch user symlink for file symlinks
    * Makefile: remove some duplication from install.systemd
    * contrib/systemd: move podman-auto-update units
    * quadlet: do not reject RemapUsers=keep-id as root
    * test/e2e: test quadlet with and without --user
    * CI: e2e: fix checkpoint flake
    * APIv2 test fix: image history
    * pasta udp tests: new bytecheck helper
    * Document packaging process
    * [skip-ci] RPM: remove dup Provides
    * Update dependency setuptools to ~=75.2.0
    * System tests: safer pause-image creation
    * Update module github.com/opencontainers/selinux to v1.11.1
    * Added escaping to invoked powershell command for hyperv stubber.
    * use slices.Clone instead of assignment
    * libpod API: only return exit code without conditions
    * Housekeeping: remove duplicates from success_task
    * Thorough overhaul of CONTRIBUTING doc.
    * api: Replace close function in condition body
    * test/e2e: fix default signal exit code test
    * Test new VM build
    * CI: fix changing-rootFsSize flake
    * scp: add option types
    * Unlock mutex before returning from function
    * Note in the README that we are moving to timed releases
    * cirrus: let tar extract figure out the compression
    * Make error messages more descriptive
    * Mention containers.conf settings for podman machine commands
    * [skip-ci] Packit: re-enable CentOS Stream 10/Fedora ELN teasks"
    * cmd: use logrus to print error
    * podman: do not set rlimits to the default value
    * spec: always specify default rlimits
    * vendor: update containers/common
    * Note in the README that we are moving to timed releases
    * Revert "CI: test nftables driver on fedora"
    * cirrus: use zstd over bzip2 for repo archive
    * cirrus: use shared repo_prep/repo_artifacts scripts
    * cirrus: speed up postbuild
    * cirrus: change alt arch task to only compile binaries
    * cirrus: run make with parallel jobs where useful
    * Makefile: allow man-page-check to be run in parallel
    * cirrus: use fastvm for builds
    * test/e2e: skip some Containerized checkpoint tests
    * test: update timezone checks
    * cirrus: update CI images
    * test/e2e: try debug potential pasta issue
    * CI: quadlet system tests: use airgapped testimage
    * Allow removing implicit quadlet systemd dependencies
    * fix(deps): update module github.com/cyphar/filepath-securejoin to v0.3.4
    * libpod API: make wait endpoint better against rm races
    * podman-remote run: improve how we get the exit code
    * [skip-ci] Packit: constrain koji and bodhi jobs to fedora package to avoid dupes
    * 055-rm test: clean up a test, and document
    * CI: remove skips for libkrun
    * Bump bundled krunkit to 0.1.3
    * fix(deps): update module google.golang.org/protobuf to v1.35.0
    * fix(deps): update module golang.org/x/net to v0.30.0
    * server: fix url parsing in info
    * fix(deps): update module golang.org/x/tools to v0.26.0
    * Makefile: fix ginkgo FOCUS option
    * fix(deps): update module golang.org/x/crypto to v0.28.0
    * podman-systemd.unit.5: adjust example options
    * docs: prefer --network to --net
    * fix(deps): update module golang.org/x/term to v0.25.0
    * fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.24
    * fix(deps): update module golang.org/x/sys to v0.26.0
    * OWNERS file audit and update
    * Exposed ports are only included when not --net=host
    * libpod: hasCurrentUserMapped checks for gid too
    * [CI:DOCS] Document TESTFLAGS in test README file
    * Validate the bind-propagation option to `--mount`
    * Fix typo in secret inspect examples
    * Mention `no_hosts` and `base_hosts_file` configs in CLI option docs
    * Fixes for vendoring Buildah
    * vendor: update buildah to latest
    * Makefile - silence skipped tests when focusing on a file
    * vendor: update to latest c/common
    * Quadlet - prefer "param val" over "param=val" to allow env expansion
    * System tests: sdnotify: wait for socket file creation
    * Switch to moby/sys/capability
    * platformInspectContainerHostConfig: rm dead code
    * CI: require and test CI_DESIRED_NETWORK on RHEL
    * Add ExposedPorts to Inspect's ContainerConfig
    * fix(deps): update golang.org/x/exp digest to 701f63a
    * quadlet: allow variables in PublishPort
    * fix(deps): update module github.com/shirou/gopsutil/v4 to v4.24.9
    * fix(deps): update github.com/godbus/dbus/v5 digest to a817f3c
    * Document that zstd:chunked is downgraded to zstd when encrypting
    * fix(deps): update module github.com/cyphar/filepath-securejoin to v0.3.3
    * chore(deps): update dependency ubuntu to v24
    * rpm: do not load iptables modules on f41+
    * adding docs for network-cmd-path
    * Include exposed ports in inspect output when net=host
    * feat(libpod): support kube play tar content-type (#24015)
    * podman mount: some better error wrapping
    * podman mount: ignore ErrLayerUnknown
    * Quadlet - make sure the order of the UnitsDir is deterministic
    * packit: disable Centos Stream/fedora ELN teasks
    * libpod: remove shutdown.Unregister()
    * libpod: rework shutdown handler flow
    * libpod: ensure we are not killed during netns creation
    * Update module github.com/moby/sys/capability to v0.3.0
    * Update documentation of `--no-hosts`, `--hostname`, and `--name` CLI options
    * Update documentation of `--add-host` CLI option
    * System tests: set a default XDG_RUNTIME_DIR
    * Modify machine "Remove machine" test
    * CORS system test: clean up
    * Add --health-max-log-count, --health-max-log-size, --health-log-destination flags
    * troubleshooting: adjust home path in tip 44
    * test/system: For pasta port forwarding tests don't bind socat server
    * Update connection on removal
    * Simplify `RemoveConnections`
    * Move `DefaultMachineName` to `pkg/machine/define`
    * vendor: update containers/image
    * vendor: update containers/storage
    * CI: skip the flaking quadlet test
    * CI: make systemd tests parallel-safe (*)
    * CI: run and collect cleanup tracer logs
    * add epbf program to trace podman cleanup errors
    * CI: parallelize logs test as much as possible
    * CI: format test: use local registry if available
    * CI: make 700-play parallel-safe
    * docs: Fix missing negation
    * bin/docker support warning message suppression from user config dir
    * Update module github.com/docker/docker to v27.3.1+incompatible
    * Quadlet - add full support for Symlinks
    * libpod: setupNetNS() correctly mount netns
    * vendor latest c/common
    * docs: remove usage of deprecated `--storage`
    * Update module github.com/docker/docker to v27.3.0+incompatible
    * CI: Quadlet rootfs test: use container image as rootfs
    * CI: system test registry: use --net=host
    * CI: rm system test: bump grace period
    * CI: system tests: minor documentation on parallel
    * fix typo in error message Fixes: containers/podman#24001
    * CI: system tests: always create pause image
    * CI: quadlet system test: be more forgiving
    * vendor latest c/common
    * CI: make 200-pod parallel-safe
    * allow exposed sctp ports
    * test/e2e: add netns leak check
    * test/system: netns leak check for rootless as well
    * test/system: Improve TODO comments on IPv6 pasta custom DNS forward test
    * test/system: Clarify "Local forwarder" pasta tests
    * test/system: Simplify testing for nameserver connectivity
    * test/system: Consolidate "External resolver" pasta tests
    * test/system: Move test for default forwarder into its own case
    * CI: make 090-events parallel-safe
    * Misc minor test fixes
    * Add network namespace leak check
    * Add workaround for buildah parallel bug
    * registry: lock start attempts
    * Update system test template and README
    * bats log: differentiate parallel tests from sequential
    * ci: bump system tests to fastvm
    * clean_setup: create pause image
    * CI: make 012-manifest parallel-safe
    * podman-manifest-remove: update docs and help output
    * test/system: remove wait workaround
    * wait: fix handling of multiple conditions with exited
    * Match output of Compat Top API to Docker
    * system test parallelization: enable two-pass approach
    * New VMs: test crun 1.17
    * libpod: hides env secrets from container inspect
    * CI: e2e: workaround for events out-of-sequence flake
    * update golangci-lint to 1.61.0
    * libpod: convert owner IDs only with :idmap
    * Podman CLI --add-host with multiple host for a single IP
    * Quadlet - Split getUnitDirs to small functions
    * fix(deps): update module github.com/cpuguy83/go-md2man/v2 to v2.0.5
    * chore(deps): update dependency setuptools to ~=75.1.0
    * Fxi typo in cache-ttl.md
    * Get WSL disk as an OCI artifact
    * CI: make 260-sdnotify parallel-safe
    * quadlet: do not log ENOENT errors
    * pkg/specgen: allow pasta when running inside userns
    * troubleshooting: add tip about the user containers
    * chore(deps): update dependency setuptools to v75
    * Convert windows paths in volume arg of the build command
    * Improve error when starting multiple machines
    * fix(deps): update module github.com/cyphar/filepath-securejoin to v0.3.2
    * Minor typo noticed when reading podman man page
    * Remove `RemoveFilesAndConnections`
    * Add `GetAllMachinesAndRootfulness`
    * rewrite typo osascript
    * typo
    * fix(deps): update module github.com/docker/docker to v27.2.1+incompatible
    * Add radio buttons to select WSL or Hyper-V in windows setup.exe
    * [skip-ci] Packit: split out ELN jobs and reuse fedora downstream targets
    * [skip-ci] Packit: Enable sidetags for bodhi updates
    * vendor: update c/common
    * CI: make 710-kube parallel-safe
    * CI: mark 320-system-df *NOT* parallel safe
    * Add kube play support for image volume source
    * refactor: add sshClient function
    * fix(deps): update module golang.org/x/tools to v0.25.0
    * CI: make 505-pasta parallel safe
    * CI: make 020-tag parallel-safe
    * CI: make 410-selinux parallel-safe
    * Bump VMs. ShellCheck is now built-in
    * troubleshooting: add tip about auto, keep-id, nomap
    * libpod: make use of new pasta option from c/common
    * vendor latest c/common
    * podman images: sort repository with tags
    * Remove containers/common/pkg/config from pkg/util
    * fix(deps): update module golang.org/x/net to v0.29.0
    * fix(deps): update module github.com/mattn/go-sqlite3 to v1.14.23
    * fix(deps): update module golang.org/x/crypto to v0.27.0
    * Fix CI
    * Detect and fix typos using codespell
    * Fix typo: replace buildin with built-in
    * Add codespell config, pre-commit definition, and move options from Makefile
    * prune: support clearing build cache using CleanCacheMount
    * test/e2e: fix network prune flake
    * Add support for Job to kube generate & play
    * Add podman-rootless.7 man page
    * Add DNS, DNSOption and DNSSearch to quadlet pod
    * podman.1.md: improve policy.json section
    * e2e: flake fix: SIGPIPE in hook test
    * libpod: fix rootless cgroup path with --cgroup-parent
    * vendor: update c/storage
    * CI: make 055-rm parallel-safe
    * CI: make 130-kill parallel-safe
    * CI: make 125-import parallel-safe
    * CI: make 110-history parallel-safe
    * CI: system tests: parallelize low-hanging fruit
    * Add disclaimer to `podman machine info` manpage.
    * man pages: refactor two more options
    * update github.com/opencontainers/runc to v1.2.0-rc.3
    * update go.etcd.io/bbolt to v1.3.11
    * update github.com/onsi/{ginkgo,gomega}
    * Update module github.com/shirou/gopsutil to v4
    * packit: update fedora and epel targets
    * bump go to 1.22
    * cirrus: test only on f40/rawhide
    * cirrus: remove CI_DESIRED_NETWORK reference
    * cirrus: prebuild use f40 for extra tests
    * chore(deps): update dependency setuptools to ~=74.1.0
    * libpod: fix HostConfig.Devices output from 'podman inspect' on FreeBSD
    * fix(deps): update golang.org/x/exp digest to 9b4947d
    * Implement publishing API UNIX socket on Windows platforms
    * Vendor c/common:8483ef6022b4
    * quadlet: support container network reusing
    * docs: update read the docs changes
    * CI: parallel-safe network system test
    * Quadlet - Support multiple image tags in .build files
    * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.8.3
    * cirrus: remove _bail_if_test_can_be_skipped
    * cirrus: move renovate check into validate
    * cirrus: remove 3rd party connectivity check
    * cirrus: remove cross jobs for aarch64 and x86_64
    * cirrus: do not upload alt arch cross artifacts
    * cirrus: remove ginkgo-e2e.json artifact
    * cirrus: fix default timeouts
    * github: remove fcos-podman-next-build-prepush
    * Clarify podman machine volume mounting behavior under WSL
    * machine: Add -all-providers flag to machine list
    * Create a podman-troubleshooting man page
    * chore(deps): update dependency setuptools to v74
    * fix(deps): update module github.com/docker/docker to v27.2.0+incompatible
    * Fix an improperly ignored error in SQLite
    * CI: flake workaround: ignore socat waitpid warnings
    * fix(deps): update module github.com/rootless-containers/rootlesskit/v2 to v2.3.1
    * Stop skipping machine volume test on Hyper-V
    * cleanup: add new --stopped-only option
    * fix races in the HTTP attach API
    * cirrus: skip windows/macos machine task on RHEL branches
    * Update module github.com/containers/gvisor-tap-vsock to v0.7.5
    * run: fix detach passthrough and --rmi
    * podman run: ignore image rm error
    * Add support for AddHost in quadlet .pod and .container
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.60.3
    * update github.com/vishvananda/netlink to v1.3.0
    * build: Update gvisor-tap-vsock to 0.7.5
    * Quote systemd DefaultEnvironment Proxy values, as documented in systemd.conf man page:
    * fix typo in podman-network-create.1.md
    * Use HTTP path prefix of TCP connections to match Docker context behavior
    * Makefile: remotesystem: use real podman server, no --url
    * Update module github.com/openshift/imagebuilder to v1.2.15
    * CI: parallel-safe userns test
    * Update module github.com/onsi/ginkgo/v2 to v2.20.1
    * Add support for IP in quadlet .pod files
    * Specify format to use for referencing fixed bugs.
    * CI: parallel-safe run system test
    * Revert "test/e2e: work around for pasta issue"
    * CI: On vX.Y-rhel branches, ensure that some downstream Jira issue is linked
    * quadlet: support user mapping in pod unit
    * Update Release Process
    * Test new VM build
    * command is not optional to podman exec
    * CI: parallel-safe namespaces system test
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.60.2
    * quadlet: add key CgroupsMode
    * Fix `podman stop` and `podman run --rmi`
    * quadlet: set infra name to %s-infra
    * chore(deps): update dependency setuptools to v73
    * [skip-ci] Packit: update targets for propose-downstream
    * Do not segfault on hard stop
    * Fix description of :Z to talk about pods
    * CI: disable ginkgo flake retries
    * vendor: update go-criu to latest
    * golangci-lint: make darwin linting happy
    * golangci-lint: make windows linting happy
    * test/e2e: remove kernel version check
    * golangci-lint: remove most skip dirs
    * set !remote build tags where needed
    * update golangci-lint to 1.60.1
    * test/e2e: rm systemd start test
    * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.8.1
    * podman wait: allow waiting for removal of containers
    * libpod: remove UpdateContainerStatus()
    * podman mount: fix storage/libpod ctr race
    * CI: quadlet tests: make parallel-safe
    * CI: system tests: make random_free_port() parallel-safe
    * remove trailing comma in example
    * CI: format test: make parallel-safe
    * Fix podman-docker.sh under -eu shells (fixes #23628)
    * docs: update podman-wait man page
    * libpod: remove duplicated HasVolume() check
    * podman volume rm --force: fix ABBA deadlock
    * test/system: fix network cleanup restart test
    * libpod: do not stop pod on init ctr exit
    * libpod: simplify WaitForExit()
    * CI: remove build-time quay check
    * Fix known_hosts file clogging and remote host id
    * Update docker.io/library/golang Docker tag to v1.23
    * Update dependency setuptools to ~=72.2.0
    * Update module github.com/docker/docker to v27.1.2+incompatible
    * healthcheck system check: reduce raciness
    * CI: healthcheck system test: make parallel-safe
    * Validate renovate config in every PR
    * pkg/machine: Read stderr from ssh-keygen correctly
    * Fix renovate config syntax error
    * CI: 080-pause.bats: make parallel-safe
    * CI: 050-stop.bats: make parallel-safe
    * Additional potential race condition on os.Readdir
    * pkg/bindings/containers: handle ignore for stop
    * remote: fix invalid --cidfile + --ignore
    * Update/simplify renovate config header comment
    * Migrate renovate config to latest schema
    * Fix race condition when listing /dev
    * docs/podman-systemd: Try to clarify `Exec=` more
    * libpod: reset state error on init
    * test/system: pasta_test_do add explicit port check
    * test/e2e: work around new push warning
    * vendor: update c/common to latest
    * stopIfOnlyInfraRemains: log all errors
    * libpod: do not save expected stop errors in ctr state
    * libpod: fix broken saveContainerError()
    * Quadlet: fix filters failure when the search paths are symlinks
    * readme: replace GPG with PGP
    * Drop APIv2 CNI configuration
    * De-duplicate docker-py testing
    * chore(podmansnoop): explain why crun comm is 3
    * libpod: cleanupNetwork() return error
    * fix(deps): update module golang.org/x/sys to v0.24.0
    * Reduce python APIv2 test net dependency
    * Fix not testing registry.conf updates
    * test/e2e: improve command timeout handling
    * Update module github.com/onsi/ginkgo/v2 to v2.20.0
    * Update module github.com/moby/sys/user to v0.3.0
    * Add passwd validate and generate steps
    * podman container cleanup: ignore common errors
    * Quadlet - Allow the user to override the default service name
    * CI: e2e: serialize root containerPort tests
    * Should not force conversion of manifest type to DockerV2ListMediaType
    * fix(deps): update module golang.org/x/tools to v0.24.0
    * fix(deps): update github.com/containers/common digest to 05b2e1f
    * CI: mount system test: parallelize
    * Update module golang.org/x/net to v0.28.0
    * Ignore ERROR_SHARING_VIOLATION error on windows
    * CI: manifest system tests: make parallel-safe
    * Create volume path before state initialization
    * vendor: update c/storage
    * CI: fix broken libkrun test
    * test/e2e: work around for pasta issue
    * test/e2e: fix missing exit code checks
    * Test new CI images
    * Remove another race condition when mounting containers or images
    * fix(deps): update github.com/containers/common digest to c0cc6b7
    * Change Windows installer MajorUpgrade Schedule
    * Ignore missing containers when calling GetExternalContainerLists
    * Remove runc edit to lock to specific version
    * fix(deps): update module golang.org/x/sys to v0.23.0
    * CI: podman-machine: do not use cache registry
    * CI: completion system test: use safename
    * Temporarly disable failing Windows Installer CI test
    * libpod: fix volume copyup with idmap
    * libpod: avoid hang on errors
    * Temp. disable PM basic Volume ops test
    * Add libkrun Mac task
    * Never skip checkout step in release workflow
    * System tests: leak_test: readable output
    * fix(deps): update github.com/docker/go-plugins-helpers digest to 45e2431
    * vendor: bump c/common
    * Version: bump to v5.3.0-dev
    * libpod: inhibit SIGTERM during cleanup()
    * Tweak versions in register_images.go
    * fix network cleanup flake in play kube
    * WIP: Fixes for vendoring Buildah
    * Add --compat-volumes option to build and farm build
    * Bump to Buildah v1.37.0
    * Quadlet test - Split between success, warning and error cases
    * libpod: bind ports before network setup
    * Disable compose-warning-logs if PODMAN_COMPOSE_WARNING_LOGS=false
    * Use new syntax for selinux options in quadlet
    * fix(deps): update module github.com/onsi/gomega to v1.34.1
    * CI: kube test: fix broken external-storage test
    * Update dependency setuptools to v72
    * Convert additional build context paths on Windows
    * pkg/api: do not leak config pointers into specgen
    * Quadlet - Allow the user to set the service name for .pod files
    * Quadlet tests - allow overriding the expected service name
    * fix(deps): update module github.com/moby/sys/user to v0.2.0
    * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.7.5
    * CI: enable root user namespaces
    * libpod: force rootfs for OCI path with idmap
    * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.19.1
    * Add test steps for automount with multi images
    * CI: cp tests: use safename
    * [skip-ci] RPM: podman-iptables.conf only on Fedora
    * CI: 700-play: fix a leaked non-safename
    * test: check that kube generate/play restores the userns
    * test: disable artifacts cache with composefs
    * test: fix podman pull tests
    * vendor: bump c/storage
    * Update module github.com/cyphar/filepath-securejoin to v0.3.1
    * Add /run/containers/systemd, ${XDG_RUNTIME_DIR}/containers/systemd quadlet dirs
    * build: Update gvisor-tap-vsock to 0.7.4
    * test/system: fix borken pasta interface name checks
    * test/system: fix bridge host.containers.internal test
    * api: honor the userns for the infra container
    * play: handle 'private' as 'auto'
    * kube: record infra user namespace
    * infra: user ns annotation higher precedence
    * specgenutil: record the pod userns in the annotations
    * kube: invert branches
    * CI: system log test: use safe names
    * Update encryption tests to avoid a warning if zstd:chunked is the default
    * Fix "podman pull and decrypt"/"from local registry"
    * Use unique image names for the encrypted test images
    * CI: system tests: instrument to allow failure analysis
    * Fix outdated comment for the build step win-gvproxy
    * Add utility to convert VMFile to URL for UNIX sockets
    * Run codespell on source
    * fix(deps): update module github.com/docker/docker to v27.1.0+incompatible
    * chore(deps): update dependency setuptools to ~=71.1.0
    * logformatter: tweaks to pass html tidy
    * More information for podman --remote build and running out of space.
    * Fix windows installer deleting machine provider config file
    * Use uploaded .zip for Windows action
    * pr-should-include-tests: no more CI:DOCS override

++++ rebootmgr:

  - Update to version 3.3+git20250512.b6e4e84:
    * Release version 3.3
    * Fix handling of temporarily disabled reboots

++++ selinux-policy:

  - Update to version 20241031+git652.e1d5a07e:
    * healthchecker: allow capability sys_admin (bsc#1240138)
    * Enable mysql_run_under_different_user for (open)SUSE (bsc#1240949)
    * Introduce mysql_run_under_different_user boolean (bsc#1240949)
    * Revert "Set mysqld_t permissive until we have tested it thorougly (bsc#1240949)"
    * slapd needs dac_override for ldapi socket (bsc#1242252)
    * Allow slapd_t nnp_transition for NoNewPrivileges (bsc#1242252)
    * Allow snapper_tu_etc_plugin_t fowner (bsc#1242768)
    * Allow snapper_tu_etc_plugin_t dac_override (bsc#1242768)
    * Revert "add dev_watch_sysfs_dirs interface"
    * Revert "Allow journalctl read messages from /var/lib/machines (bsc#1235829)"
    * Revert "Allow xenstored_t manage xend_var_lib_t files (bsc#1228540)"
    * label start script for pcp logger properly (bsc#1241611)
    * Allow collectd accept and listen to tcp sockets
    * healthchecker: fix findmnt with encrypted disks (bsc#1238606)
    * Allow cluster_t use NoNewPrivileges systemd hardening (bsc#1241921)
    * dontaudit sys_resource for NetworkManager_dispatcher types (bsc#1241888)
    * Allow init_t nnp domain transition to redis_t
    * Allow tlshd read network sysctls
    * Allow NetworkManager create and use icmp_socket
    * Allow varnishd execute the prlimit64() syscall
    * Allow rhsmcertd connect to systemd-machined
    * Allow virt_domain write to virt_image_t files
    * Allow system-dbusd list systemd-machined directories
    * Allow asterisk read network sysctls
    * Allow virtstoraged fsetid capability
    * Allow xdm watch a mnt_t directory
    * Allow collectd bind TCP sockets to the collectd port
    * Allow virtqemud relabel from tmpfs lnk files
    * Allow gnome-remote-desktop additional sockets permissions
    * Update insights-core policy
    * Update systemd-homed policy
    * Allow xenstored_t manage xend_var_lib_t files (bsc#1228540)
    * Allow init and login_pgm connect to systemd-logind over a unix socket
    * Allow login_userdomain read pressure stall information
    * Allow systemd-journald create and use vsock socket
    * Update systemd-pcrextend policy
    * Allow systemd watch/watch_reads usb ttys
    * Update coreos-installer-generator policy
    * Update systemd-homed policy
    * Allow systemd-user-runtime-dir get/set tmpfs quotas
    * Allow systemd-rfkill read nsfs files
    * Dontaudit bootc-systemd-generator search sssd lib directories
    * Allow systemd-user-runtime-dir delete gnome homedir content
    * allows gssd_t to read nfs symlinks (bsc#1241042)
    * Allow tuned-ppd read sssd public files
    * Allow tuned-ppd watch_reads sysfs directories
    * Confine /usr/lib/systemd/systemd-user-runtime-dir
    * Revert "Dontaudit systemd-logind remove all files"
    * Make bootupd use bootupd_tmp_t as its private type for files in /tmp
    * Label SetroubleshootPrivileged.py with setroubleshootd_exec_t
    * Allow power-profiles-daemon watch sysfs directories
    * systemd: allow reading /dev/cpu/0/msr
    * Update the pcmsensor policy
    * Allow chronyd-restricted sendto to chronyc
    * Allow system_dbusd_t r/w unix stream sockets of unconfined_service_t
    * Allow dovecot-deliver read mail aliases
    * Confine systemd-factory-reset system generator
    * Allow systemd debug generator read tmpfs files
    * Allow gnome-shell get attributes of systemd inhibit pipes
    * Allow tuned-ppd watch sysfs directories
    * Fix the storage_rw_inherited_removable_device() interface
    * Allow sadc read global pressure stall information
    * Allow virtqemud read sblim-gatherd process state
  - Update embedded container-selinux version to commit:
    * d7e420a1166c8bd237a7877f76fa9a0e484a7c68 (version 2.237.0)

++++ tuned:

  - Add hardened profile (PED-12781)
    A 0001-hardened-Introduce-hardened-profile.patch

------------------------------------------------------------------
------------------  2025-5-11  -  May 11 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - xhci: dbc: Avoid event polling busyloop if pending rx transfers
    are inactive (git-fixes).
  - usb: usbtmc: Fix erroneous generic_read ioctl return
    (git-fixes).
  - usb: usbtmc: Fix erroneous wait_srq ioctl return (git-fixes).
  - usb: usbtmc: Fix erroneous get_stb ioctl error returns
    (git-fixes).
  - usb: typec: tcpm: delay SNK_TRY_WAIT_DEBOUNCE to SRC_TRYWAIT
    transition (git-fixes).
  - USB: usbtmc: use interruptible sleep in usbtmc_read (git-fixes).
  - usb: cdnsp: fix L1 resume issue for RTL_REVISION_NEW_LPM version
    (git-fixes).
  - usb: typec: ucsi: displayport: Fix NULL pointer access
    (git-fixes).
  - usb: typec: ucsi: displayport: Fix deadlock (git-fixes).
  - usb: misc: onboard_usb_dev: fix support for Cypress HX3 hubs
    (git-fixes).
  - usb: uhci-platform: Make the clock really optional (git-fixes).
  - usb: dwc3: gadget: Make gadget_wakeup asynchronous (git-fixes).
  - usb: gadget: Use get_status callback to set remote wakeup
    capability (git-fixes).
  - usb: gadget: f_ecm: Add get_status callback (git-fixes).
  - usb: host: tegra: Prevent host controller crash when OTG port
    is used (git-fixes).
  - usb: cdnsp: Fix issue with resuming from L1 (git-fixes).
  - usb: gadget: tegra-xudc: ACK ST_RC after clearing CTRL_RUN
    (git-fixes).
  - staging: axis-fifo: Remove hardware resets for user errors
    (git-fixes).
  - staging: axis-fifo: Correct handling of tx_fifo_depth for size
    validation (git-fixes).
  - staging: bcm2835-camera: Initialise dev in v4l2_dev (git-fixes).
  - iio: adis16201: Correct inclinometer channel resolution
    (git-fixes).
  - iio: adc: ad7606: fix serial register access (git-fixes).
  - staging: iio: adc: ad7816: Correct conditional logic for store
    mode (git-fixes).
  - iio: temp: maxim-thermocouple: Fix potential lack of DMA safe
    buffer (git-fixes).
  - iio: imu: inv_mpu6050: align buffer for timestamp (git-fixes).
  - iio: adc: rockchip: Fix clock initialization sequence
    (git-fixes).
  - iio: imu: st_lsm6dsx: fix possible lockup in
    st_lsm6dsx_read_tagged_fifo (git-fixes).
  - iio: imu: st_lsm6dsx: fix possible lockup in
    st_lsm6dsx_read_fifo (git-fixes).
  - iio: accel: adxl367: fix setting odr for activity time update
    (git-fixes).
  - drm/xe: Add page queue multiplier (git-fixes).
  - drm/amdgpu/hdp7: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp6: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp5.2: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp5: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp4: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amd/display: Fix wrong handling for AUX_DEFER case
    (git-fixes).
  - drm/amd/display: Copy AUX read reply data whenever length >
    0 (git-fixes).
  - drm/amd/display: Remove incorrect checking in dmub aux handler
    (git-fixes).
  - drm/amd/display: Shift DMUB AUX reply command if necessary
    (git-fixes).
  - drm/amd/display: Fix invalid context error in dml helper
    (git-fixes).
  - drm/panel: simple: Update timings for AUO G101EVN010
    (git-fixes).
  - accel/ivpu: Increase state dump msg timeout (git-fixes).
  - wifi: mac80211: fix the type of status_code for negotiated
    TID to Link Mapping (git-fixes).
  - wifi: cfg80211: fix out-of-bounds access during multi-link
    element defragmentation (git-fixes).
  - can: gw: fix RCU/BH usage in cgw_create_job() (git-fixes).
  - can: mcan: m_can_class_unregister(): fix order of unregistration
    calls (git-fixes).
  - can: rockchip_canfd: rkcanfd_remove(): fix order of
    unregistration calls (git-fixes).
  - can: mcp251xfd: mcp251xfd_remove(): fix order of unregistration
    calls (git-fixes).
  - can: mcp251xfd: fix TDC setting for low data bit rates
    (git-fixes).
  - can: m_can: m_can_class_allocate_dev(): initialize spin lock
    on device probe (git-fixes).
  - EDAC/altera: Set DDR and SDMMC interrupt mask before
    registration (git-fixes).
  - EDAC/altera: Test the correct error reg offset (git-fixes).
  - ALSA: usb-audio: Add second USB ID for Jabra Evolve 65 headset
    (stable-fixes).
  - ALSA: usb-audio: Add retry on -EPROTO from usb_set_interface()
    (stable-fixes).
  - drm/amdgpu: Fix offset for HDP remap in nbio v7.11
    (stable-fixes).
  - drm/amd/display: Fix slab-use-after-free in hdcp (git-fixes).
  - platform/x86/amd: pmc: Require at least 2.5 seconds between
    HW sleep cycles (stable-fixes).
  - drm/amd/display: Add scoped mutexes for amdgpu_dm_dhcp
    (stable-fixes).
  - Bluetooth: btusb: Add 13 USB device IDs for Qualcomm WCN785x
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID for WCN785x (stable-fixes).
  - ASoC: soc-core: Stop using of_property_read_bool() for
    non-boolean properties (stable-fixes).
  - EDAC/{skx_common,i10nm}: Fix some missing error reports on
    Emerald Rapids (git-fixes).
  - Bluetooth: btusb: Add ID 0x2c7c:0x0130 for Qualcomm WCN785x
    (stable-fixes).
  - accel/ivpu: Use xa_alloc_cyclic() instead of custom function
    (stable-fixes).
  - accel/ivpu: Make DB_ID and JOB_ID allocations incremental
    (stable-fixes).
  - accel/ivpu: Update VPU FW API headers (stable-fixes).
  - accel/ivpu: Fix a typo (stable-fixes).
  - commit f4b367d

++++ kernel-firmware-amdgpu:

  - Update to version 20250509 (git commit a1d732703915):
    * amdgpu: updates for dcn 3.20 and dcn 4.01 firmware to 0.1.10.0

++++ kernel-rt:

  - xhci: dbc: Avoid event polling busyloop if pending rx transfers
    are inactive (git-fixes).
  - usb: usbtmc: Fix erroneous generic_read ioctl return
    (git-fixes).
  - usb: usbtmc: Fix erroneous wait_srq ioctl return (git-fixes).
  - usb: usbtmc: Fix erroneous get_stb ioctl error returns
    (git-fixes).
  - usb: typec: tcpm: delay SNK_TRY_WAIT_DEBOUNCE to SRC_TRYWAIT
    transition (git-fixes).
  - USB: usbtmc: use interruptible sleep in usbtmc_read (git-fixes).
  - usb: cdnsp: fix L1 resume issue for RTL_REVISION_NEW_LPM version
    (git-fixes).
  - usb: typec: ucsi: displayport: Fix NULL pointer access
    (git-fixes).
  - usb: typec: ucsi: displayport: Fix deadlock (git-fixes).
  - usb: misc: onboard_usb_dev: fix support for Cypress HX3 hubs
    (git-fixes).
  - usb: uhci-platform: Make the clock really optional (git-fixes).
  - usb: dwc3: gadget: Make gadget_wakeup asynchronous (git-fixes).
  - usb: gadget: Use get_status callback to set remote wakeup
    capability (git-fixes).
  - usb: gadget: f_ecm: Add get_status callback (git-fixes).
  - usb: host: tegra: Prevent host controller crash when OTG port
    is used (git-fixes).
  - usb: cdnsp: Fix issue with resuming from L1 (git-fixes).
  - usb: gadget: tegra-xudc: ACK ST_RC after clearing CTRL_RUN
    (git-fixes).
  - staging: axis-fifo: Remove hardware resets for user errors
    (git-fixes).
  - staging: axis-fifo: Correct handling of tx_fifo_depth for size
    validation (git-fixes).
  - staging: bcm2835-camera: Initialise dev in v4l2_dev (git-fixes).
  - iio: adis16201: Correct inclinometer channel resolution
    (git-fixes).
  - iio: adc: ad7606: fix serial register access (git-fixes).
  - staging: iio: adc: ad7816: Correct conditional logic for store
    mode (git-fixes).
  - iio: temp: maxim-thermocouple: Fix potential lack of DMA safe
    buffer (git-fixes).
  - iio: imu: inv_mpu6050: align buffer for timestamp (git-fixes).
  - iio: adc: rockchip: Fix clock initialization sequence
    (git-fixes).
  - iio: imu: st_lsm6dsx: fix possible lockup in
    st_lsm6dsx_read_tagged_fifo (git-fixes).
  - iio: imu: st_lsm6dsx: fix possible lockup in
    st_lsm6dsx_read_fifo (git-fixes).
  - iio: accel: adxl367: fix setting odr for activity time update
    (git-fixes).
  - drm/xe: Add page queue multiplier (git-fixes).
  - drm/amdgpu/hdp7: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp6: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp5.2: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp5: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amdgpu/hdp4: use memcfg register to post the write for
    HDP flush (git-fixes).
  - drm/amd/display: Fix wrong handling for AUX_DEFER case
    (git-fixes).
  - drm/amd/display: Copy AUX read reply data whenever length >
    0 (git-fixes).
  - drm/amd/display: Remove incorrect checking in dmub aux handler
    (git-fixes).
  - drm/amd/display: Shift DMUB AUX reply command if necessary
    (git-fixes).
  - drm/amd/display: Fix invalid context error in dml helper
    (git-fixes).
  - drm/panel: simple: Update timings for AUO G101EVN010
    (git-fixes).
  - accel/ivpu: Increase state dump msg timeout (git-fixes).
  - wifi: mac80211: fix the type of status_code for negotiated
    TID to Link Mapping (git-fixes).
  - wifi: cfg80211: fix out-of-bounds access during multi-link
    element defragmentation (git-fixes).
  - can: gw: fix RCU/BH usage in cgw_create_job() (git-fixes).
  - can: mcan: m_can_class_unregister(): fix order of unregistration
    calls (git-fixes).
  - can: rockchip_canfd: rkcanfd_remove(): fix order of
    unregistration calls (git-fixes).
  - can: mcp251xfd: mcp251xfd_remove(): fix order of unregistration
    calls (git-fixes).
  - can: mcp251xfd: fix TDC setting for low data bit rates
    (git-fixes).
  - can: m_can: m_can_class_allocate_dev(): initialize spin lock
    on device probe (git-fixes).
  - EDAC/altera: Set DDR and SDMMC interrupt mask before
    registration (git-fixes).
  - EDAC/altera: Test the correct error reg offset (git-fixes).
  - ALSA: usb-audio: Add second USB ID for Jabra Evolve 65 headset
    (stable-fixes).
  - ALSA: usb-audio: Add retry on -EPROTO from usb_set_interface()
    (stable-fixes).
  - drm/amdgpu: Fix offset for HDP remap in nbio v7.11
    (stable-fixes).
  - drm/amd/display: Fix slab-use-after-free in hdcp (git-fixes).
  - platform/x86/amd: pmc: Require at least 2.5 seconds between
    HW sleep cycles (stable-fixes).
  - drm/amd/display: Add scoped mutexes for amdgpu_dm_dhcp
    (stable-fixes).
  - Bluetooth: btusb: Add 13 USB device IDs for Qualcomm WCN785x
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID for WCN785x (stable-fixes).
  - ASoC: soc-core: Stop using of_property_read_bool() for
    non-boolean properties (stable-fixes).
  - EDAC/{skx_common,i10nm}: Fix some missing error reports on
    Emerald Rapids (git-fixes).
  - Bluetooth: btusb: Add ID 0x2c7c:0x0130 for Qualcomm WCN785x
    (stable-fixes).
  - accel/ivpu: Use xa_alloc_cyclic() instead of custom function
    (stable-fixes).
  - accel/ivpu: Make DB_ID and JOB_ID allocations incremental
    (stable-fixes).
  - accel/ivpu: Update VPU FW API headers (stable-fixes).
  - accel/ivpu: Fix a typo (stable-fixes).
  - commit f4b367d

++++ python-click:

  - Update to version 8.2.0:
    * Drop support for Python 3.7, 3.8, and 3.9. #2588 #2893
    * Use modern packaging metadata with pyproject.toml instead of setup.cfg.
    [#2438]
    * Use flit_core instead of setuptools as build backend. #2543
    * Deprecate the __version__ attribute. Use feature detection, or
    importlib.metadata.version("click"), instead. #2598
    * BaseCommand is deprecated. Command is the base class for all
    commands. #2589
    * MultiCommand is deprecated. Group is the base class for all group
    commands. #2590
    * The current parser and related classes and methods, are deprecated.
    [#2205]
  - OptionParser and the parser module, which is a modified copy of
    optparse in the standard library.
  - Context.protected_args is unneeded. Context.args contains any
    remaining arguments while parsing.
  - Parameter.add_to_parser (on both Argument and Option) is
    unneeded. Parsing works directly without building a separate parser.
  - split_arg_string is moved from parser to shell_completion.
    * Enable deferred evaluation of annotations with
    from __future__ import annotations. #2270
    * When generating a command's name from a decorated function's name, the
    suffixes _command, _cmd, _group, and _grp are removed.
    [#2322]
    * Show the types.ParamType.name for types.Choice options within
  - -help message if show_choices=False is specified.
    [#2356]
    * Do not display default values in prompts when Option.show_default is
    False. #2509
    * Add get_help_extra method on Option to fetch the generated extra
    items used in get_help_record to render help text. #2516
    [#2517]
    * Keep stdout and stderr streams independent in CliRunner. Always
    collect stderr output and never raise an exception. Add a new
    output stream to simulate what the user sees in its terminal. Removes
    the mix_stderr parameter in CliRunner. #2522 #2523
    * Option.show_envvar now also shows environment variable in error messages.
    [#2695] #2696
    * Context.close will be called on exit. This results in all
    Context.call_on_close callbacks and context managers added via
    Context.with_resource to be closed on exit as well. #2680
    * Add ProgressBar(hidden: bool) to allow hiding the progressbar. #2609
    * A UserWarning will be shown when multiple parameters attempt to use the
    same name. #2396
    * When using Option.envvar with Option.flag_value, the flag_value
    will always be used instead of the value of the environment variable.
    [#2746] #2788
    * Add Choice.get_invalid_choice_message method for customizing the
    invalid choice message. #2621 #2622
    * If help is shown because no_args_is_help is enabled (defaults to True
    for groups, False for commands), the exit code is 2 instead of 0.
    [#1489] #1489
    * Contexts created during shell completion are closed properly, fixing
    a ResourceWarning when using click.File. #2644 #2800
    [#2767]
    * click.edit(filename) now supports passing an iterable of filenames in
    case the editor supports editing multiple files at once. Its return type
    is now also typed: AnyStr if text is passed, otherwise None.
    [#2067] #2068
    * Specialized typing of progressbar(length=...) as ProgressBar[int].
    [#2630]
    * Improve echo_via_pager behaviour in face of errors.
    [#2674]
  - Terminate the pager in case a generator passed to echo_via_pager
    raises an exception.
  - Ensure to always close the pipe to the pager process and wait for it
    to terminate.
  - echo_via_pager will not ignore KeyboardInterrupt anymore. This
    allows the user to search for future output of the generator when
    using less and then aborting the program using ctrl-c.
    * deprecated: bool | str can now be used on options and arguments. This
    previously was only available for Command. The message can now also be
    customised by using a str instead of a bool. #2263 #2271
  - Command.deprecated formatting in --help changed from
    (Deprecated) help to help (DEPRECATED).
  - Parameters cannot be required nor prompted or an error is raised.
  - A warning will be printed when something deprecated is used.
    * Add a catch_exceptions parameter to CliRunner. If
    catch_exceptions is not passed to CliRunner.invoke, the value
    from CliRunner is used. #2817 #2818
    * Option.flag_value will no longer have a default value set based on
    Option.default if Option.is_flag is False. This results in
    Option.default not needing to implement __bool__. #2829
    * Incorrect click.edit typing has been corrected. #2804
    * Choice is now generic and supports any iterable value.
    This allows you to use enums and other non-str values. #2796
    [#605]
    * Fix setup of help option's defaults when using a custom class on its
    decorator. Removes HelpOption. #2832 #2840

------------------------------------------------------------------
------------------  2025-5-10  -  May 10 2025  -------------------
------------------------------------------------------------------

++++ python313-core:

  - Remove python-3.3.0b1-test-posix_fadvise.patch (not needed
    since kernel 3.6-rc1)

++++ python313:

  - Remove python-3.3.0b1-test-posix_fadvise.patch (not needed
    since kernel 3.6-rc1)

------------------------------------------------------------------
------------------  2025-5-9  -  May 9 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.20 → 10.2.21

++++ kernel-default:

  - dm: fix copying after src array boundaries (git-fixes).
  - commit d245386
  - dm: add missing unlock on in dm_keyslot_evict() (git-fixes).
  - commit 7c774eb
  - dm-ebs: fix prefetch-vs-suspend race (git-fixes).
  - commit ca47a3a
  - dm-verity: fix prefetch-vs-suspend race (git-fixes).
  - commit 08de9d9
  - dm-integrity: fix non-constant-time tag verification
    (git-fixes).
  - commit 08671cf
  - dm-integrity: set ti->error on memory allocation failure
    (git-fixes).
  - commit a523edf
  - net: mctp: Set SOCK_RCU_FREE (CVE-2025-37790 bsc#1242509).
  - commit b2b89d2
  - net_sched: hfsc: Fix a UAF vulnerability in class handling
    (CVE-2025-37797 bsc#1242417).
  - commit 5054069
  - powerpc/pseries/iommu: create DDW for devices with DMA mask
    less than 64-bits (bsc#1239691).
  - commit 73b27f8
  - codel: remove sch->q.qlen check before
    qdisc_tree_reduce_backlog() (CVE-2025-37798 bsc#1242414).
  - commit 1c8963f
  - Update
    patches.suse/mptcp-fix-NULL-pointer-in-can_accept_new_subflow.patch
    references (add CVE-2025-23145 bsc#1242596).
  - commit 86cf0bb
  - supported.conf: Make imx93-adc driver supported (jsc#PED-12016)
  - commit 0844125

++++ kernel-firmware-platform:

  - Update to version 20250508 (git commit 788aadc8f73d):
    * linux-firmware: Amphion: Update vpu firmware

++++ kernel-rt:

  - dm: fix copying after src array boundaries (git-fixes).
  - commit d245386
  - dm: add missing unlock on in dm_keyslot_evict() (git-fixes).
  - commit 7c774eb
  - dm-ebs: fix prefetch-vs-suspend race (git-fixes).
  - commit ca47a3a
  - dm-verity: fix prefetch-vs-suspend race (git-fixes).
  - commit 08de9d9
  - dm-integrity: fix non-constant-time tag verification
    (git-fixes).
  - commit 08671cf
  - dm-integrity: set ti->error on memory allocation failure
    (git-fixes).
  - commit a523edf
  - net: mctp: Set SOCK_RCU_FREE (CVE-2025-37790 bsc#1242509).
  - commit b2b89d2
  - net_sched: hfsc: Fix a UAF vulnerability in class handling
    (CVE-2025-37797 bsc#1242417).
  - commit 5054069
  - powerpc/pseries/iommu: create DDW for devices with DMA mask
    less than 64-bits (bsc#1239691).
  - commit 73b27f8
  - codel: remove sch->q.qlen check before
    qdisc_tree_reduce_backlog() (CVE-2025-37798 bsc#1242414).
  - commit 1c8963f
  - Update
    patches.suse/mptcp-fix-NULL-pointer-in-can_accept_new_subflow.patch
    references (add CVE-2025-23145 bsc#1242596).
  - commit 86cf0bb
  - supported.conf: Make imx93-adc driver supported (jsc#PED-12016)
  - commit 0844125

++++ samba:

  - Update and rename update-apparmor-samba-profile script to
    update-samba-security-profile. It additionally now caters
    for selinux (if selinux is used); (bsc#1241391);

++++ systemd:

  - Add 1002-udev-persistent-net-rules-support.patch (bsc#1241190)
    This re-adds back the support for persistent net name rule. This is needed to
    support upgrades from older systems relying on persistent net rules.
  - systemd-update-helper: do not stop or disable services when they are migrated
    to other packages. This can occur during package renaming or splitting.
  - Add 1001-journal-again-create-user-journals-for-users-with-hi.patch (bsc#1242938)
    Don't write messages sent from users with UID falling into the container UID
    range to the system journal. Daemons in the container don't talk to the
    outside journald as they talk to the inner one directly, which does its
    journal splitting based on shifted uids.

++++ wtmpdb:

  - Update to version 0.74.0+git20250509.272b109:
    * libwtmpdb: enhance/unify error messages

++++ microos-tools:

  - Update to version 4.0+git16:
    * man-online: fetch product specific manual pages
    * Add import-pubring: create gpg file from rpmdb

++++ python-maturin:

  - Update to 1.8.4
    * Install a Rust toolchain into a temporary directory when building maturin
    itself or a package and a Rust toolchain is missing. Set
    MATURIN_NO_INSTALL_RUST to disable this behavior. #2421
    * Fix broken maturin develop with latest uv in #2584
    * Add PYO3_PYTHON env var support in #2534
    * Sort RECORD file in wheel archives to make them deterministic in #2550
    * Publish wheel for loongarch64 in #2548
    * Add --compression-level option to build command in #2572

------------------------------------------------------------------
------------------  2025-5-8  -  May 8 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - update to 338:
    Upstream Changes:
  - Translation updates
  - Bug fixes
  - Add check_cockpit_users and add_preexec_cockpit.patch to ensure manually created
    users and groups are removed. Also check systemd support is in nsswitch

++++ python-kiwi:

  - Add dkms to test-image-embedded integration test
  - Fixed access issue to etc/kernel for sdboot
    In case of an overlayroot setup we have to make sure
    that etc/kernel is writable. This is done by a bind
    mount of the ESP
  - Update test-image-overlayroot
    Add another build using grub instead of systemd-boot and use
    btrfs as write partition instead of xfs. Please note this test
    requires a boot partition because grub cannot read from erofs
    and unlike systemd-boot grub does not read all boot data from
    the ESP.
  - Fixed get_volume_management
    If a volume capable filesystem like btrfs is requested, there
    must also be a volume definition available to report that
    the volume management is actively used. Just the request of
    the filesystem can also mean it's being used without volumes
    like it could be the case for an overlayroot setup that
    requests btrfs as write partition.
  - Update test-image-overlayroot
    Move to systemd-boot as bootloader, activate secure boot
    and drop the extra boot partition. Use XFS for the write
    space
  - Allow initrd updates on read-only devices
    Move initrd to ESP for boot loaders that reads data
    from there
  - Fix ordering issue for device assignment
    wrong assignment of a boot partition in overlayroot setup
    without boot partition

++++ fwupd:

  - Update to version 2.0.9:
    + This release adds the following features:
  - Add some documentation about updating the KEK and db
  - Allow installing multiple db certificate updates at the same time
  - Show what certificate signed the EFI authenticated variable
  - Use readline to look up inputs from user, and make it optional
    + This release fixes the following bugs:
  - Add several devices with broken firmware to the UEFI dbx blocklist
  - Constructing the authenticated URI properly when using FirmwareBaseURI
  - Do not enumerate non-updatable OptionROM devices
  - Do not export Redfish backup partitions as devices
  - Fix a crash when installing some Wacom firmware types
  - Fix a crash when parsing uevents that are not KEY=VALUE
  - Fix parsing the DFU descriptor when not using libusb
  - Fix PK and KEK enumeration failure on some systems
  - Fix SMBIOS parsing for ROM size >= 16MiB
  - Include a resolution for more of the HSI failures
  - Include more output when using fwupdtool get-devices --json
  - Never allow updating updatable-hidden devices with fwupdtool
  - Properly handle redfish location redirect when installing firmware
  - Recognize a very old dbx hash to allow upgrades
  - Require a reboot after updating Intel CVS devices
  - Rework the MEI code so that a device can use more than one interface
  - Rewrite the ModemManger plugin to be simpler and more supportable
  - Simplify parsing USB descriptors
    + This release adds support for the following hardware:
  - Intel Arc Battlemage GPUs
  - Add explicit pkgconfig(libusb-1.0) B?uildREquires: pulled in by
    gusb already, but having it explicit allows to add specific
    version constrains.
  - Add pkgconfig(readline) BuildRequires: new dependency.

++++ kernel-default:

  - perf: arm_cspmu: nvidia: monitor all ports by default (bsc#1242172)
  - commit bf39dd6
  - perf: arm_cspmu: nvidia: enable NVLINK-C2C port filtering (bsc#1242172)
  - commit db95d42
  - perf: arm_cspmu: nvidia: fix sysfs path in the kernel doc (bsc#1242172)
  - commit 61a8aee
  - perf: arm_cspmu: nvidia: remove unsupported SCF events (bsc#1242172)
  - commit 1b5aa51
  - cifs: Fix integer overflow while processing actimeo mount option
    (git-fixes).
  - commit cc7bbc9
  - cifs: Fix integer overflow while processing closetimeo mount
    option (CVE-2025-21962 bsc#1240655).
  - commit 365c443
  - cifs: Fix integer overflow while processing acdirmax mount
    option (CVE-2025-21963 bsc#1240717).
  - commit 19fafdd
  - cifs: Fix integer overflow while processing acregmax mount
    option (CVE-2025-21964 bsc#1240740).
  - commit 4cde60f
  - watch_queue: fix pipe accounting mismatch (CVE-2025-23138 bsc#1241648).
  - commit 7f670bc
  - wifi: nl80211: store chandef on the correct link when starting
    CAC (git-fixes).
  - commit c3b2b6d
  - wifi: nl80211: remove redundant null pointer check in coalescing
    (git-fixes).
  - commit da447dd
  - Remove simpledrm workarounds for Nvidia (bsc#1242886)
    These workarounds were required for fbdev-based console support
    with old Nvidia drivers before release 570. These are not supported
    on SLE16. Recent Nvidia drivers provide a DRM-based console.
  - commit 7b5dbb9
  - wifi: mac80211, cfg80211: miscellaneous spelling fixes
    (git-fixes).
  - commit 26269ed
  - platform/x86/amd/pmf: fix cleanup in amd_pmf_init_smart_pc()
    (git-fixes).
  - commit 22af071
  - platform/x86/amd/pmf: Switch to platform_get_resource() and
    devm_ioremap_resource() (git-fixes).
  - commit 6ee242c
  - media: i2c: imx214: Add vblank and hblank controls (git-fixes).
  - commit d20bc08
  - media: i2c: imx214: Drop IMX214_REG_EXPOSURE from mode reg
    arrays (git-fixes).
  - commit 8641706
  - media: ipu6: move the l2_unmap() up before l2_map() (git-fixes).
  - commit 15eadf0
  - media: intel/ipu6: remove buttress ish structure (git-fixes).
  - commit b671d23
  - vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp
    (CVE-2025-37799 bsc#1242283).
  - commit 4b5767a
  - erofs: ensure the extra temporary copy is valid for shortened
    bvecs (git-fixes).
  - commit 30165a9
  - fs/erofs/fileio: call erofs_onlinefolio_split() after
    bio_add_folio() (git-fixes).
  - commit 287888e

++++ kernel-rt:

  - perf: arm_cspmu: nvidia: monitor all ports by default (bsc#1242172)
  - commit bf39dd6
  - perf: arm_cspmu: nvidia: enable NVLINK-C2C port filtering (bsc#1242172)
  - commit db95d42
  - perf: arm_cspmu: nvidia: fix sysfs path in the kernel doc (bsc#1242172)
  - commit 61a8aee
  - perf: arm_cspmu: nvidia: remove unsupported SCF events (bsc#1242172)
  - commit 1b5aa51
  - cifs: Fix integer overflow while processing actimeo mount option
    (git-fixes).
  - commit cc7bbc9
  - cifs: Fix integer overflow while processing closetimeo mount
    option (CVE-2025-21962 bsc#1240655).
  - commit 365c443
  - cifs: Fix integer overflow while processing acdirmax mount
    option (CVE-2025-21963 bsc#1240717).
  - commit 19fafdd
  - cifs: Fix integer overflow while processing acregmax mount
    option (CVE-2025-21964 bsc#1240740).
  - commit 4cde60f
  - watch_queue: fix pipe accounting mismatch (CVE-2025-23138 bsc#1241648).
  - commit 7f670bc
  - wifi: nl80211: store chandef on the correct link when starting
    CAC (git-fixes).
  - commit c3b2b6d
  - wifi: nl80211: remove redundant null pointer check in coalescing
    (git-fixes).
  - commit da447dd
  - Remove simpledrm workarounds for Nvidia (bsc#1242886)
    These workarounds were required for fbdev-based console support
    with old Nvidia drivers before release 570. These are not supported
    on SLE16. Recent Nvidia drivers provide a DRM-based console.
  - commit 7b5dbb9
  - wifi: mac80211, cfg80211: miscellaneous spelling fixes
    (git-fixes).
  - commit 26269ed
  - platform/x86/amd/pmf: fix cleanup in amd_pmf_init_smart_pc()
    (git-fixes).
  - commit 22af071
  - platform/x86/amd/pmf: Switch to platform_get_resource() and
    devm_ioremap_resource() (git-fixes).
  - commit 6ee242c
  - media: i2c: imx214: Add vblank and hblank controls (git-fixes).
  - commit d20bc08
  - media: i2c: imx214: Drop IMX214_REG_EXPOSURE from mode reg
    arrays (git-fixes).
  - commit 8641706
  - media: ipu6: move the l2_unmap() up before l2_map() (git-fixes).
  - commit 15eadf0
  - media: intel/ipu6: remove buttress ish structure (git-fixes).
  - commit b671d23
  - vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp
    (CVE-2025-37799 bsc#1242283).
  - commit 4b5767a
  - erofs: ensure the extra temporary copy is valid for shortened
    bvecs (git-fixes).
  - commit 30165a9
  - fs/erofs/fileio: call erofs_onlinefolio_split() after
    bio_add_folio() (git-fixes).
  - commit 287888e

++++ gcc15:

  - Update to GCC 15 branch head, 15.1.1+git9642
    * includes fix for libgfortran.so.5 ABI regression [gcc#120152]
  - Add libgcobol and libquadmath-devel dependence to the cobol frontend
    package.

++++ libeconf:

  - Update to version 0.7.9:
    * Comments can include comment character tag multiple time.
    * Fixed static library declaration in meason
    * Fixed versioning in cmake

++++ libgcrypt:

  - Update to 1.11.1: [jsc#PED-12227]
    * Bug fixes:
  - Fix Kyber secret-dependent branch introduced by recent versions of Clang. [rCf765778e82]
  - Fix build regression due to the use of AVX512 in Blake. [T7184]
  - Do not build i386 asm on amd64 and vice versa. [T7220]
  - Fix build regression on armhf with gcc-14. [T7226]
  - Return the proper error code on malloc failure in hex2buffer. [rCc51151f5b0]
  - Fix long standing bug for PRIME % 2 == 0. [rC639b0fca15]
    * Performance:
  - Add AES Vector Permute intrinsics implementation for AArch64. [rC94a63aedbb]
  - Add GHASH AArch64/SIMD intrinsics implementation. [rCfec871fd18]
  - Add RISC-V vector permute AES. [rCb24ebd6163]
  - Add GHASH RISC-V Zbb+Zbc implementation. [rC0f1fec12b0]
  - Add ChaCha20 RISC-V vector intrinsics implementation. [rC8dbee93ac2]
  - Add SHA3 acceleration for RISC-V Zbb extension. [rC1a660068ba]
    * Other:
  - Add CET support for i386 and amd64 assembly. [T7220]
  - Add PAC/BTI support for AArch64 asm. [T7220]
  - Apply changes to Kyber from upstream for final FIPS 203. [rCcc95c36e7f]
  - Introduce an internal API for a revampled FIPS service indicator. [T7340]
  - Several improvements for constant time operation by the introduction of
    Least Leak Intended (LLI) variants of internal functions. [T7519,T7490]
    * Add libgcrypt-1.11.1-public-SLI-API.patch
    * Rebase patches:
  - libgcrypt-FIPS-SLI-hash-mac.patch
  - libgcrypt-FIPS-SLI-pk.patch
  - libgcrypt-FIPS-jitter-standalone.patch
    * Remove patches:
  - libgcrypt-fips-Introduce-an-internal-API-for-FIPS-service-indicator.patch
  - libgcrypt-fips-Introduce-GCRYCTL_FIPS_SERVICE_INDICATOR-and-the-macro.patch
  - libgcrypt-fips-kdf-Implement-new-FIPS-service-indicator-for-gcry_kdf_derive.patch
  - libgcrypt-fips-md-Implement-new-FIPS-service-indicator-for-gcry_md_hash_.patch
  - libgcrypt-fips-tests-Add-t-digest.patch
  - libgcrypt-fips-Change-the-internal-API-for-new-FIPS-service-indicator.patch
  - libgcrypt-fips-md-Implement-new-FIPS-service-indicator-for-gcry_md_open-API.patch
  - libgcrypt-fips-tests-Add-tests-for-md_open-write-read-close-for-t-digest.patch
  - libgcrypt-fips-mac-Implement-new-FIPS-service-indicator-for-gcry_mac_open.patch
  - libgcrypt-fips-cipher-Implement-new-FIPS-service-indicator-for-cipher_open.patch
  - libgcrypt-tests-fips-Add-gcry_mac_open-tests.patch
  - libgcrypt-tests-fips-Rename-t-fips-service-ind.patch
  - libgcrypt-tests-fips-Move-KDF-tests-to-t-fips-service-ind.patch
  - libgcrypt-tests-fips-Add-gcry_cipher_open-tests.patch
  - libgcrypt-fips-md-gcry_md_copy-should-care-about-FIPS-service-indicator.patch
  - libgcrypt-fips-cipher-Implement-FIPS-service-indicator-for-gcry_pk_hash_-API.patch
  - libgcrypt-fips-Introduce-GCRYCTL_FIPS_REJECT_NON_FIPS.patch
  - libgcrypt-Fix-the-previous-change.patch
  - libgcrypt-fips-Rejection-by-GCRYCTL_FIPS_REJECT_NON_FIPS-not-by-open-flags.patch
  - libgcrypt-fips-cipher-Add-behavior-not-to-reject-but-mark-non-compliant.patch
  - libgcrypt-fips-ecc-Add-rejecting-or-marking-for-gcry_pk_get_curve.patch
  - libgcrypt-tests-Add-more-tests-to-tests-t-fips-service-ind.patch
  - libgcrypt-fips-ecc-Check-DATA-in-gcry_pk_sign-verify-in-FIPS-mode.patch
  - libgcrypt-fips-cipher-Fix-memory-leak-for-gcry_pk_hash_sign.patch
  - libgcrypt-build-Improve-__thread-specifier-check.patch
  - libgcrypt-cipher-Check-and-mark-non-compliant-cipher-modes-in-the-SLI.patch
  - libgcrypt-cipher-Rename-_gcry_cipher_is_mode_fips_compliant.patch
  - libgcrypt-cipher-Don-t-differentiate-GCRY_CIPHER_MODE_CMAC-in-FIPS-mode.patch
  - libgcrypt-cipher-rsa-Mark-reject-SHA1-unknown-with-RSA-signature-generation.patch
  - libgcrypt-md-Fix-gcry_md_algo_info-to-mark-reject-under-FIPS-mode.patch
  - libgcrypt-md-Use-check_digest_algo_spec-in-_gcry_md_selftest.patch
  - libgcrypt-tests-Update-t-fips-service-ind-using-GCRY_MD_SHA256-for-KDF-tests.patch
  - libgcrypt-fips-cipher-Do-the-computation-when-marking-non-compliant.patch
  - libgcrypt-tests-Allow-tests-with-USE_RSA.patch
  - libgcrypt-cipher-Add-KAT-for-non-rfc6979-ECDSA-with-fixed-k.patch
  - libgcrypt-cipher-Differentiate-use-of-label-K-in-the-SLI.patch
  - libgcrypt-cipher-Differentiate-igninvflag-in-the-SLI.patch
  - libgcrypt-cipher-Differentiate-no-blinding-flag-in-the-SLI.patch
  - libgcrypt-fips-cipher-Add-GCRY_FIPS_FLAG_REJECT_PK_FLAGS.patch
  - libgcrypt-cipher-ecc-Fix-for-supplied-K.patch
  - libgcrypt-cipher-visibility-Differentiate-use-of-random-override-in-the-SLI.patch
  - libgcrypt-cipher-fips-Fix-for-random-override.patch
  - libgcrypt-md-Make-SHA-1-non-FIPS-internally-for-1.12-API.patch
  - libgcrypt-fips-Fix-GCRY_FIPS_FLAG_REJECT_MD.patch
  - libgcrypt-doc-Add-about-GCRYCTL_FIPS_SERVICE_INDICATOR.patch
  - libgcrypt-doc-Fix-syntax-error.patch
  - libgcrypt-Disable-SHA3-s390x-acceleration-for-CSHAKE.patch

++++ qemu:

  - Update to latest stable release (10.0.0)
    Full changelog here:
    https://wiki.qemu.org/ChangeLog/10.0
    Highlights include:
    * block: virtio-scsi multiqueue support for using different I/O threads
    to process requests for each queue (similar to the virtio-blk multiqueue
    support that was added in QEMU 9.2)
    * VFIO: improved support for IGD passthrough on all Intel Gen 11/12
    devices
    * Documentation: significant improvement/overhaul of documentation for
    QEMU Machine Protocol to make it clearer and more organized, including
    all commands/events/types now being cross-reference-able via click-able
    links in generated documentation
    * ARM: emulation support for EL2 physical and virtual timers
    * ARM: emulation support for FEAT_AFP, FEAT_RPRES, and FEAT_XS
    architecture features
    * ARM: new board models for NPCM8445 Evaluation and i.MX 8M Plus EVK
    boards
    * HPPA: new SeaBIOS-hppa version 18 with lots of fixes and enhancements
    * HPPA: translation speed and virtual CPU reset improvements
    * HPPA: emulation support for Diva GSP BMC boards
    * LoongArch: support for CPU hotplug, paravirtual IPIs, KVM steal time
    accounting, and virtual 'extioi' interrupt routing.
    * RISC-V: ISA/extension support for riscv-iommu-sys devices, 'svukte',
    'ssstateen', 'smrnmi', 'smdbltrp'/'ssdbltrp', 'supm'/'sspm', and
    IOMMU translation tags
    * RISC-V: emulation support for Ascalon and RV64 Xiangshan Nanhu CPUs,
    and Microblaze V boards.
    * s390x: add CPU model support for the generation 17 mainframe CPU
    * s930x: add support for virtio-mem and for bypassing IOMMU to improve
    PCI device performance
    * x86: CPU model support for Clearwater Forest and Sierra Forest v2
    * x86: faster emulation of string instructions
    * and lots more...
    Have a look at the list of deprecated features too, especially if you're
    still interested in using 32bits systems as hosts:
    * https://qemu-project.gitlab.io/qemu/about/deprecated.html
  - Post-update improvements and fixes:
    * [openSUSE]: fix SLOF not building with gcc15 (bsc#1241473)
    * [openSUSE][RPM]: *.spec: improve the %check phases
    * docs: Don't define duplicate label in qemu-block-drivers.rst.inc
    * [openSUSE] tests: workaround expected failures of func-x86_64-mem_addr_space
    * [openSUSE]: tests/functional increase the timeout of func_hppa_seabios
    * [openSUSE] tests/unit increase the timeouts for tlssession tests

------------------------------------------------------------------
------------------  2025-5-7  -  May 7 2025  -------------------
------------------------------------------------------------------

++++ afterburn:

  - Use autosetup for patches, refresh them and rename
    * fix-authorized-keys-location.patch to 0001-Fix-authorized-keys-location-for-OpenSUSE.patch
    * set-default-user.patch to 0002-Set-the-default-user-to-suse.patch
    * no-network-args.patch to 0003-On-OpenSUSE-do-not-add-to-kernel-command-line.patch
  - Update to version 5.7.0.git103.bae893c:
    * Sync repo templates ⚙
    * build(deps): bump crossbeam-channel from 0.5.13 to 0.5.15
    * build(deps): bump tokio from 1.40.0 to 1.44.2
    * build(deps): bump openssl from 0.10.71 to 0.10.72
    fixes RUSTSEC-2025-0022 AKA CVE-2025-3416 AKA bsc#1242665
    * build(deps): bump zbus from 4.4.0 to 5.5.0
    * mod.rs: Fix clippy lint errors
    * release-notes.md: add release notes for rust version update
    * Cargo.toml: bump MSRV to 1.84.1
    * Fix clippy lint issues
    * Sync repo templates ⚙
    * build(deps): bump mockito from 1.6.1 to 1.7.0
    * build(deps): bump serde_json from 1.0.139 to 1.0.140
    * build(deps): bump tempfile from 3.17.1 to 3.19.1
    * build(deps): bump clap from 4.5.31 to 4.5.35
    * build(deps): bump reqwest from 0.12.12 to 0.12.15
    * Update release notes.
    * proxmoxve: Add more context to log messages.
    * proxmoxve: Remove unneeded fields
    * proxmoxve: Add tests for static network configuration from cloud-init.
    * proxmoxve: Add support for static network configuration from cloud-init.
    * build(deps): bump mailparse from 0.15.0 to 0.16.1
    * Sync repo templates ⚙
    * build(deps): bump ring from 0.17.8 to 0.17.13
    * build(deps): bump anyhow from 1.0.95 to 1.0.96
    * release notes: add notes for tempfile bump from 3.16.0 to 3.17.1
    * build(deps): bump serde from 1.0.217 to 1.0.218
    * build(deps): bump openssl from 0.10.70 to 0.10.71
    * build(deps): bump tempfile from 3.16.0 to 3.17.1
    * build(deps): bump serde_json from 1.0.138 to 1.0.139
    * build(deps): bump clap from 4.5.27 to 4.5.31
    * add makefile targets for fmt,lint and test
    * providers/openstack: ignore ec2 metadata if not present
    * build(deps): bump openssl from 0.10.66 to 0.10.70
    * build(deps): bump serde_json from 1.0.137 to 1.0.138
    * build(deps): bump tempfile from 3.14.0 to 3.16.0
    * build(deps): bump openssl from 0.10.66 to 0.10.69
    * build(deps): bump ipnetwork from 0.20.0 to 0.21.1
    * build(deps): bump serde from 1.0.215 to 1.0.217
    * build(deps): bump serde_json from 1.0.133 to 1.0.137
    * build(deps): bump anyhow from 1.0.93 to 1.0.95
    * build(deps): bump clap from 4.5.21 to 4.5.27
    * build(deps): bump reqwest from 0.12.7 to 0.12.12
    * Sync repo templates ⚙
    * Sync repo templates ⚙
    * build(deps): bump mockito from 1.5.0 to 1.6.1
    * build(deps): bump serde_json from 1.0.128 to 1.0.133
    * Sync repo templates ⚙
    * build(deps): bump clap from 4.5.17 to 4.5.21
    * build(deps): bump tempfile from 3.12.0 to 3.14.0
    * build(deps): bump anyhow from 1.0.89 to 1.0.93
    * build(deps): bump serde from 1.0.210 to 1.0.215
    * Sync repo templates ⚙
    * Sync repo templates ⚙
    * docs: add changelog entry
    * proxmox: use noop provider if no configdrive
    * add noop provider
    * release-notes: remove "upcoming"
  - Update to version 5.7.0:
    * cargo: Afterburn release 5.7.0
    * docs/release-notes: update for release 5.7.0
    * cargo: update dependencies
    * dhcp: replace dbus_proxy with proxy, and zbus traits
    * build(deps): bump zbus from 3.15.2 to 4.4.0
    * build(deps): bump tempfile from 3.10.1 to 3.12.0
    * build(deps): bump serde from 1.0.205 to 1.0.210
    * build(deps): bump serde_json from 1.0.121 to 1.0.127
    * build(deps): bump reqwest from 0.12.5 to 0.12.7
    * build(deps): bump uzers from 0.12.0 to 0.12.1
    * build(deps): bump clap from 4.5.13 to 4.5.16
    * build(deps): bump serde from 1.0.203 to 1.0.205
    * build(deps): bump serde_json from 1.0.119 to 1.0.121
    * build(deps): bump mockito from 1.4.0 to 1.5.0
    * build(deps): bump openssh-keys from 0.6.3 to 0.6.4
    * build(deps): bump clap from 4.5.8 to 4.5.13
    * build(deps): bump openssl from 0.10.64 to 0.10.66
    * providers/hetzner: private ipv4 addresses in attributes
    * openstack: Document the two platforms
    * build(deps): bump zerovec-derive from 0.10.2 to 0.10.3
    * build(deps): bump zerovec from 0.10.2 to 0.10.4
    * build(deps): bump nix from 0.27.1 to 0.29.0
    * build(deps): bump clap from 4.5.7 to 4.5.8
    * build(deps): bump serde_json from 1.0.117 to 1.0.119
    * microsoft/azure: allow empty certificate chain in PKCS12 file
    * proxmoxve: implement proxmoxve provider
    * providers/hetzner: fix duplicate attribute prefix
    * build(deps): bump pnet_base from 0.34.0 to 0.35.0
    * cargo: Afterburn release 5.6.0
    * docs/release-notes: update for release 5.6.0
    * cargo: update dependencies
    * build(deps): bump libflate from 1.4.0 to 2.1.0
    * build(deps): bump base64 from 0.21.7 to 0.22.1
    * build(deps): bump uzers from 0.11.3 to 0.12.0
    * build(deps): bump pnet_datalink from 0.34.0 to 0.35.0
    * build(deps): bump nix from 0.28.0 to 0.29.0
    * lint: silence deadcode warnings
    * lint: address latest lint's from msrv update
    * workflows/rust: directly update toolchain to 1.75.0
    * cargo: update msrv to 1.75
    * Sync repo templates ⚙
    * build(deps): bump reqwest from 0.12.2 to 0.12.4
    * build(deps): bump serde from 1.0.197 to 1.0.200
    * build(deps): bump anyhow from 1.0.81 to 1.0.82
    * build(deps): bump mailparse from 0.14.1 to 0.15.0
    * build(deps): bump serde_json from 1.0.115 to 1.0.116
    * Sync repo templates ⚙
    * providers: Add "akamai" provider
    * build(deps): bump h2 from 0.3.24 to 0.3.26
    * build(deps): bump anyhow from 1.0.79 to 1.0.81
    * build(deps): bump serde_json from 1.0.113 to 1.0.115
    * build(deps): bump reqwest from 0.11.24 to 0.12.2
    * build(deps): bump serde_yaml from 0.9.32 to 0.9.34+deprecated
    * build(deps): bump mio from 0.8.10 to 0.8.11
    * build(deps): bump mailparse from 0.14.0 to 0.14.1
    * build(deps): bump openssl from 0.10.62 to 0.10.64
    * build(deps): bump nix from 0.27.1 to 0.28.0
    * build(deps): bump mockito from 1.2.0 to 1.4.0
    * build(deps): bump tempfile from 3.9.0 to 3.10.1
    * build(deps): bump serde_yaml from 0.9.31 to 0.9.32
    * build(deps): bump serde from 1.0.195 to 1.0.197
    * build(deps): bump h2 from 0.3.23 to 0.3.24
    * build(deps): bump slog-term from 2.9.0 to 2.9.1
    * build(deps): bump serde_yaml from 0.9.30 to 0.9.31
    * build(deps): bump serde_json from 1.0.111 to 1.0.113
    * build(deps): bump clap from 4.4.16 to 4.4.18
    * build(deps): bump reqwest from 0.11.23 to 0.11.24
    * Sync repo templates ⚙
    * cargo: Afterburn release 5.5.1
    * docs/release-notes: update for release 5.5.1
    * cargo: update dependencies
    * build(deps): bump anyhow from 1.0.75 to 1.0.78
    * build(deps): bump serde_yaml from 0.9.27 to 0.9.29
    * build(deps): bump reqwest from 0.11.22 to 0.11.23
    * build(deps): bump serde_json from 1.0.108 to 1.0.109
    * build(deps): bump openssl from 0.10.60 to 0.10.62
    * build(deps): bump tempfile from 3.8.1 to 3.9.0
    * build(deps): bump clap from 4.4.10 to 4.4.12
    * build(deps): bump unsafe-libyaml from 0.2.9 to 0.2.10
    * providers/vmware: add missing public functions for non-amd64
    * build(deps): bump clap from 4.4.8 to 4.4.10
    * cargo: Afterburn release 5.5.0
    * build(deps): bump openssl from 0.10.59 to 0.10.60
    * Sync repo templates ⚙
    * docs/release-notes: update for release 5.5.0
    * cargo: update dependencies
    * ci: cancel previous build on PR update
    * build(deps): allow building with libsystemd 0.7.0
    * providers/vmware: Process guestinfo.metadata netplan configuration
    * kubevirt: Run afterburn-hostname service
    * build(deps): bump reqwest from 0.11.20 to 0.11.22
    * build(deps): bump tempfile from 3.8.0 to 3.8.1
    * build(deps): bump clap from 4.4.6 to 4.4.7
    * build(deps): bump serde_json from 1.0.107 to 1.0.108
    * build(deps): bump serde_yaml from 0.9.25 to 0.9.27
    * build(deps): bump rustix from 0.37.19 to 0.37.25
    * build(deps): bump clap from 4.4.2 to 4.4.6
    * build(deps): bump serde_json from 1.0.105 to 1.0.107
    * build(deps): bump mockito from 1.1.0 to 1.2.0
    * providers: add support for scaleway
    * Move away from deprecated `users` to `uzers`
    though not vulnerable as unused but lib had CVE-2025-5791 AKA bsc#1244199
    * Sync repo templates ⚙
    * providers/hetzner: add support for Hetzner Cloud
    * build(deps): bump clap from 4.4.1 to 4.4.2
    * cargo: update MSRV to 1.71
    * build(deps): bump clap from 4.3.19 to 4.4.1
    * chore: Get rid of Clippy warnings
    * cargo: specify required features for nix dependency
    * build(deps): bump nix from 0.26.2 to 0.27.1
    * build(deps): bump slog-async from 2.7.0 to 2.8.0
    * build(deps): bump openssl from 0.10.56 to 0.10.57
    * build(deps): bump reqwest from 0.11.18 to 0.11.20
    * build(deps): bump serde from 1.0.185 to 1.0.188
    * Sync repo templates ⚙
    * build(deps): bump tempfile from 3.7.1 to 3.8.0
    * build(deps): bump serde from 1.0.183 to 1.0.185
    * build(deps): bump anyhow from 1.0.72 to 1.0.75
    * build(deps): bump serde_json from 1.0.104 to 1.0.105
    * build(deps): bump openssl from 0.10.55 to 0.10.56
    * build(deps): bump tempfile from 3.7.0 to 3.7.1
    * build(deps): bump serde from 1.0.180 to 1.0.183
    * Sync repo templates ⚙
    * build(deps): bump serde from 1.0.179 to 1.0.180
    * build(deps): bump serde_json from 1.0.103 to 1.0.104
    * build(deps): bump serde from 1.0.175 to 1.0.179
    * build(deps): bump pnet_datalink from 0.33.0 to 0.34.0
    * build(deps): bump serde from 1.0.171 to 1.0.175
    * build(deps): bump clap from 4.3.14 to 4.3.19
    * build(deps): bump pnet_base from 0.33.0 to 0.34.0
    * build(deps): bump serde_yaml from 0.9.23 to 0.9.25
    * build(deps): bump tempfile from 3.6.0 to 3.7.0
    * build(deps): bump clap from 4.3.11 to 4.3.14
    * build(deps): bump serde_yaml from 0.9.22 to 0.9.23
    * build(deps): bump anyhow from 1.0.71 to 1.0.72
    * build(deps): bump serde_json from 1.0.100 to 1.0.103
    * Sync repo templates ⚙
    * build(deps): bump clap from 4.3.10 to 4.3.11
    * build(deps): bump serde_json from 1.0.99 to 1.0.100
    * build(deps): bump openssh-keys from 0.6.1 to 0.6.2
    * build(deps): bump zbus from 3.13.1 to 3.14.1
    * build(deps): bump clap from 4.3.8 to 4.3.10
    * build(deps): bump serde from 1.0.164 to 1.0.165
    * build(deps): bump serde_json from 1.0.96 to 1.0.99
    * build(deps): bump clap from 4.3.3 to 4.3.8
    * build(deps): bump serde_yaml from 0.9.21 to 0.9.22
    * build(deps): bump openssl from 0.10.54 to 0.10.55
    * build(deps): bump mockito from 1.0.2 to 1.1.0
    * Sync repo templates ⚙
    * Sync repo templates ⚙
    * openstack: Add attribute OPENSTACK_INSTANCE_UUID
    * build(deps): bump serde from 1.0.163 to 1.0.164
    * build(deps): bump clap from 4.3.2 to 4.3.3
    * build(deps): bump tempfile from 3.5.0 to 3.6.0
    * cargo: Afterburn release 5.4.3
    * docs/release-notes: update for release 5.4.3
    * cargo: update dependencies
    * cargo: allow openssl 0.10.46
    * build(deps): bump openssl from 0.10.52 to 0.10.54
    * build(deps): bump openssh-keys from 0.6.0 to 0.6.1
    * build(deps): bump vmw_backdoor from 0.2.3 to 0.2.4
    * ci: strip debug symbols
    * Sync repo templates ⚙
    * build-sys: Use new tier = 2 for cargo-vendor-filterer
    * Sync repo templates ⚙
    * Sync repo templates ⚙
    * build(deps): bump reqwest from 0.11.17 to 0.11.18
    * cargo: Afterburn release 5.4.2
    * docs/release-notes: update for release
    * docs/release-notes: note Azure SSH regression fix with new openssl
    * cargo: fix minimum version of openssl crate
    * build(deps): bump serde from 1.0.162 to 1.0.163
    * build(deps): bump zbus from 3.12.0 to 3.13.1
    * build(deps): bump serde from 1.0.160 to 1.0.162
    * build(deps): bump anyhow from 1.0.70 to 1.0.71
    * build(deps): bump openssl from 0.10.51 to 0.10.52
    * build(deps): bump reqwest from 0.11.16 to 0.11.17
    * build(deps): bump openssl from 0.10.50 to 0.10.51
    * build(deps): bump enumflags2 from 0.7.5 to 0.7.7
    * build(deps): bump openssl from 0.10.48 to 0.10.50
    * build(deps): bump zbus from 3.11.1 to 3.12.0
    * build(deps): bump serde_json from 1.0.95 to 1.0.96
    * build(deps): bump h2 from 0.3.15 to 0.3.17
    * build(deps): bump openssl from 0.10.47 to 0.10.48
    * microsoft/crypto/mod: replace deprecated function `parse` with `parse2`
    * build(deps): bump serde from 1.0.159 to 1.0.160
    * build(deps): bump serde_yaml from 0.9.19 to 0.9.21
    * build(deps): bump tempfile from 3.4.0 to 3.5.0
    * build(deps): bump serde from 1.0.158 to 1.0.159
    * build(deps): bump mockito from 1.0.1 to 1.0.2
    * Update mockito to 1.0.1
    * build(deps): bump reqwest from 0.11.15 to 0.11.16
    * build(deps): bump serde_json from 1.0.94 to 1.0.95
    * cli: switch to clap derive
    * cli: add descriptive value names for option arguments in --help
    * build(deps): bump zbus from 3.11.0 to 3.11.1
    * build(deps): bump openssl from 0.10.45 to 0.10.47
    * build(deps): bump reqwest from 0.11.14 to 0.11.15
    * build(deps): bump serde from 1.0.155 to 1.0.158
    * build(deps): bump anyhow from 1.0.69 to 1.0.70
    * cli: have clap require exactly one of --cmdline/--provider
    * providers/*: move endpoint mocking into retry::Client
    * retry/client: move URL parsing into helper function
    * providers/microsoft: import crate::retry
    * providers/microsoft: use stored client for all fetches
    * providers/packet: use stored client for boot checkin
    * build(deps): bump zbus from 3.10.0 to 3.11.0
    * build(deps): bump serde from 1.0.152 to 1.0.155
    * Sync repo templates ⚙
    * docs: Use upstream theme & update to 0.4.1
    * build(deps): bump serde_json from 1.0.93 to 1.0.94
    * build(deps): bump serde_yaml from 0.9.17 to 0.9.19
    * build(deps): bump mockito from 0.32.3 to 0.32.4
    * build(deps): bump tempfile from 3.3.0 to 3.4.0
    * initrd: remember to write trailing newline to network kargs file
    * util: drop obsolete "OEM" terminology
    * Update to clap 4
    * build(deps): bump mockito from 0.31.1 to 0.32.3
    * workflows: update clippy to 1.67
    * Fix clippy lints
    * Inline variables into format strings
    * build(deps): bump zbus from 3.9.0 to 3.10.0
    * build(deps): bump serde_json from 1.0.92 to 1.0.93

++++ python-kiwi:

  - Add kiwi-settings package for TW
    de-blacklist erofs to allow building integration tests
    with this filesystem
  - Switch to dracut-kiwi-verity
    So far no luck with the systemd verity generator. This
    commit adds the parsing of /etc/veritytab in the existing
    kiwi-verity dracut module and uses it in the overlayroot
    integration test.
  - Update test-image-overlayroot integration test
    Switch to erofs for overlay testing. Additionally split the build
    into two profiles. The first one just builds a simple overlayroot
    oem disk based on erofs. The second one adds a veritysetup layer
    and configures the systemd-veritysetup-generator for use in dracut.
    This Fixes #2799
  - Add documentation for new attribute
    Add details how to use the new overlayroot_readonly_filesystem attribute
  - Add support for selecting the overlay read-only fs
    Add new overlayroot_readonly_filesystem attribute which allows
    to select for either squashfs or erofs as the read-only filesystem
    in an OEM overlay disk setup.
  - Fixed root setup for verity overlay disk
    When building an image with overlayroot set to true and
    activated verity data, the root= parameter must be
    set to root=overlay:MAPPER=verityroot instead of the standard
    overlay:PARTUUID mapping.
  - Make sure the verity record has a superblock
  - Drop distro specific runtime check
    The check_efi_mode_for_disk_overlay_correctly_setup exists because
    shim-install does not work on read-only devices. However, shim-install
    is a SUSE only tool that runs a SUSE specific secure boot setup.
    For other secure boot processes this runtime check is not useful.
    As runtime checks aims to be generally useful, this one gets
    dropped.

++++ kernel-default:

  - platform/x86/amd/pmf: Update PMF Driver for Compatibility with
    new PMF-TA (git-fixes).
  - commit cc3df34
  - dmaengine: idxd: Enable Function Level Reset (FLR) for halt
    (jsc#PED-10722).
  - dmaengine: idxd: Refactor halt handler (jsc#PED-10722).
  - dmaengine: idxd: Add idxd_device_config_save() and
    idxd_device_config_restore() helpers (jsc#PED-10722).
  - dmaengine: idxd: Binding and unbinding IDXD device and driver
    (jsc#PED-10722).
  - dmaengine: idxd: Add idxd_pci_probe_alloc() helper
    (jsc#PED-10722).
  - dmaengine: idxd: Remove unused idxd_(un)register_bus_type
    (git-fixes).
  - commit c5788f1
  - Review various patches for kABI changes
    Several patches require a refresh. No functional changes.
  - commit c1ac5ba
  - Update references for rtas patches (jsc#PED-12801).
  - commit 4634c37
  - net: ipv6: ioam6: fix lwtunnel_output() loop (git-fixes).
  - commit c113f7e
  - net: ipv6: fix dst refleaks in rpl, seg6 and ioam6 lwtunnels
    (git-fixes).
  - commit 96d8aa2
  - net: ipv6: ioam6_iptunnel: mitigate 2-realloc issue (git-fixes).
  - commit 2d48008
  - x86/cpu/amd: Fix workaround for erratum 1054 (git-fixes).
  - commit d81a358

++++ kernel-firmware-platform:

  - Update to version 20250507 (git commit 94e4d273ad22):
    * amd_pmf: Update AMD PMF TA Firmware to v3.1

++++ kernel-rt:

  - platform/x86/amd/pmf: Update PMF Driver for Compatibility with
    new PMF-TA (git-fixes).
  - commit cc3df34
  - dmaengine: idxd: Enable Function Level Reset (FLR) for halt
    (jsc#PED-10722).
  - dmaengine: idxd: Refactor halt handler (jsc#PED-10722).
  - dmaengine: idxd: Add idxd_device_config_save() and
    idxd_device_config_restore() helpers (jsc#PED-10722).
  - dmaengine: idxd: Binding and unbinding IDXD device and driver
    (jsc#PED-10722).
  - dmaengine: idxd: Add idxd_pci_probe_alloc() helper
    (jsc#PED-10722).
  - dmaengine: idxd: Remove unused idxd_(un)register_bus_type
    (git-fixes).
  - commit c5788f1
  - Review various patches for kABI changes
    Several patches require a refresh. No functional changes.
  - commit c1ac5ba
  - Update references for rtas patches (jsc#PED-12801).
  - commit 4634c37
  - net: ipv6: ioam6: fix lwtunnel_output() loop (git-fixes).
  - commit c113f7e
  - net: ipv6: fix dst refleaks in rpl, seg6 and ioam6 lwtunnels
    (git-fixes).
  - commit 96d8aa2
  - net: ipv6: ioam6_iptunnel: mitigate 2-realloc issue (git-fixes).
  - commit 2d48008
  - x86/cpu/amd: Fix workaround for erratum 1054 (git-fixes).
  - commit d81a358

++++ mpdecimal:

  - Update to 4.0.1 (bsc#1242704):
  - Add Cygwin support.
  - Update config.guess and config.sub to the latest versions.
  - Fix pkg-config files for custom paths.
  - Set LD/LDXX unconditionally to CC/CXX, since LDFLAGS/LDXXFLAGS from ./configure rely on it.
  - Update to 4.0.0:
  - sync soversion and major_version
  - The added number formatting feature requires an ABI change,
    hence the increase to SOVERSION=4.
  - Packagers outside of the Linux distributions sometimes use
    the major version number as the equivalent of SOVERSION on
    their platforms and have an incorrect SOVERSION for 2.5.1,
    which requires SOVERSION=3.
  - While SOVERSION is not required to match the major
    version number (example: glibc), mpdecimal will from
    now on take the path of least resistance and always use
    SOVERSION=MPD_MAJOR_VERSION.
  - The jump to 4.0.0 should also remind users that a C++ library
    is available.
  - Support for out-of-tree build.
  - Support for pkg-config.
  - Unix: support for Loongson.
  - Unix: support for CheriBSD.
  - Compilers: support for icx, icpx, ibm-clang_r, ibm-clang++_r,
    CompCert, clang-cl and emscripten.
  - Windows: support for MSYS2/MinGW.
  - MSVC: the build now uses /O2 /DNDEBUG.
  - MSVC: new arm64/arm32 cross build scripts.
  - AIX: the shared libraries are now installed as versioned
    objects, e.g., shr4.o, shr4_64.o.
  - New ./configure switches:
  - --enable-static: enable/disable the build of the static
    libraries (default: enabled).
  - --enable-pc: enable/disable the install of the pkgconfig
    files (default: enabled).
  - --enable-doc: enable/disable the install of the documentation
    (default: enabled).
  - New man pages direct users to the mpdecimal-doc package or
    the online HTML documentation.
  - The prebuilt HTML documentation is now in the separate
    mpdecimal-doc package, which gives distributions that reject
    prebuilt documentation the option to disregard it and use the
    new man pages.
  - libmpdec:
  - Add the “z” format specifier (coerce negative zeros to
    positive).
  - In extremely rare cases the transcendental functions (exp,
    ln, log10) did not set the Subnormal/Underflow flags. The
    reason is that in the case of an exponent boundary the Ziv
    correction loop for correct rounding requires very few
    iterations to arrive at the correctly rounded result, but
    may need many more iterations to arrive at the correct
    flags.
  - In these cases, Subnormal/Underflow is not very
    informative, so the status quo was to skip the extra
    iterations.
  - Version 4.0.0 now specializes exponent boundary cases
    and uses up to five additional iterations to set
    Subnormal/Underflow. The refactored code has no speed
    penalty on average; in fact, in the deccheck tests (random
    tests with a bias towards corner cases) it is slightly
    faster.
  - No cases have been found where more than two additional
    iterations are required, but they may exist.
  - eability fixes
  - mpd_qset_string_exact(), mpd_qset_i64_exact() and
    mpd_qset_u64_exact() can now be called with a nonzero
    status. Previously, the functions could return
    NaN/Invalid_operation in that case.
  - This is listed under “reliability fixes” since there is
    no possible scenario under which these functions would
    legitimately be called with a nonzero status.
  - libmpdec++
  - Add input validation for Decimal.shiftl(), Decimal.shiftr()
    and Decimal::ln10().

++++ sqlite3:

  - Update to release 3.49.2:
    * Fix a bug in the NOT NULL optimization of version 3.40.0 that
    can lead to a memory error if abused.
    * Fix the count-of-view optimization so that it does not give an
    incorrect answer for a DISTINCT query.
    * Fix a possible incorrect answer that can result if a UNIQUE
    constraint of a table contains the PRIMARY KEY column and that
    UNIQUE constraint is used by an IN operator.
    * Fix obscure problems with the generate_series() extension
    function.
    * Incremental improvements to the configure/make.

++++ wtmpdb:

  - Fix summary of libwtmpdb subpackage

++++ mdadm:

  - Allow any valid minor name in md device name (bsc#1240789)
    * add 1007-mdadm-allow-any-valid-minor-number-in-md-device-name.patch

++++ python-cryptography:

  - Update to 44.0.3
    * Fixed compilation when using LibreSSL 4.1.0.

++++ ovmf:

  - Add patchset to enable SVSM vTPM support in OVMF (jsc#PED-12743, jsc#PED-12767)
  - 9bceb1600005 ovmf-Maintainers.txt-Add-reviewer-for-SVSM-vTPM-related-m.patch
  - 87d4cdd09e4d ovmf-UefiCpuPkg-AmdSvsmLib-Stub-the-SVSM-vTPM-protocol-fo.patch
  - 40b4e190d37d ovmf-OvmfPkg-AmdSvsmLib-Add-the-SVSM-vTPM-protocol.patch
  - 06b2f9dc4385 ovmf-OvmfPkg-Use-Tpm2Device-lib-with-SVSM-vTPM-support.patch
  - 458198aa49c3 ovmf-OvmfPkg-AmdSvmLib-Use-named-protocol-and-call-consta.patch
  - fa74200c9269 ovmf-MdePkg-AmdSev-Add-SVSM-protocol-call-numbers.patch
  - 70f806ec23fb ovmf-MdePkg-AmdSev-Add-SVSM-protocol-vTPM-call-numbers.patch
  - edf5e365c104 ovmf-SecurityPkg-Tpm2DeviceLibDTpm-Add-header-file-for-Tp.patch
  - e868ece3c7d1 ovmf-SecurityPkg-Tpm2DeviceLibDTpm-Add-TPM2-lib-supportin.patch
  - 87f454532a61 ovmf-SecurityPkg-Tpm2DeviceLibDTpm-Improve-spelling-gramm.patch
  - c2d8e9236787 ovmf-SecurityPkg-Tpm2DeviceLibDTpm-Check-SNP-enabled-prio.patch
  - Remove non-unified SEV/TDX images due to potential security risks. (bsc#1232762)
  - ovmf-x86_64-sev-code.bin
  - ovmf-x86_64-sev-vars.bin
  - ovmf-x86_64-tdx-code.bin
  - ovmf-x86_64-tdx-vars.bin

++++ regionServiceClientConfigGCE:

  - Update conditional to handle name change of metadata package
    in SLE 16 (bsc#1242063)

------------------------------------------------------------------
------------------  2025-5-6  -  May 6 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix root clone size setup
    If the root_clone attribute is specified without providing a
    fixed size for the system, kiwi estimates the size needed for
    the root part and assigns the rest to the clone. This leads to
    different partition sizes for the root clones. As per definition
    of a clone the expectation is that the size is the same, this
    commit changes the behavior such that the calculated size for
    the system is applied to the origin root and all its clones.
    As a consequence this can leave unpartitioned space free in
    the image. This Fixes #2463

++++ kernel-default:

  - usb: xhci: Fix Short Packet handling rework ignoring errors
    (git-fixes).
  - media: i2c: imx214: Fix uninitialized variable in
    imx214_set_ctrl() (git-fixes).
  - media: i2c: imx214: Fix link frequency validation (git-fixes).
  - commit 9465e52
  - xhci: Handle spurious events on Etron host isoc enpoints
    (stable-fixes).
  - Refresh patches.suse/padding-XHCI-additional-padding.patch.
  - commit 292fe8c
  - firmware: arm_ffa: Skip Rx buffer ownership release if not
    acquired (git-fixes).
  - firmware: arm_scmi: Fix timeout checks on polling path
    (git-fixes).
  - firmware: arm_scmi: Balance device refcount when destroying
    devices (git-fixes).
  - irqchip/qcom-mpm: Prevent crash when trying to handle non-wake
    GPIOs (git-fixes).
  - i2c: imx-lpi2c: Fix clock count when probe defers (git-fixes).
  - spi: tegra114: Don't fail set_cs_timing when delays are zero
    (git-fixes).
  - drm/i915/pxp: fix undefined reference to
    `intel_pxp_gsccs_is_ready_for_sessions' (git-fixes).
  - drm/mipi-dbi: Fix blanking for non-16 bit formats (git-fixes).
  - drm/tests: shmem: Fix memleak (git-fixes).
  - drm: Select DRM_KMS_HELPER from DRM_DEBUG_DP_MST_TOPOLOGY_REFS
    (git-fixes).
  - drm/fdinfo: Protect against driver unbind (git-fixes).
  - drm/nouveau: Fix WARN_ON in nouveau_fence_context_kill()
    (git-fixes).
  - pinctrl: imx: Return NULL if no group is matched and found
    (git-fixes).
  - drm/amd/display: Force full update in gpu reset (stable-fixes).
  - USB: OHCI: Add quirk for LS7A OHCI controller (rev 0x02)
    (stable-fixes).
  - xhci: Limit time spent with xHC interrupts disabled during
    bus resume (stable-fixes).
  - mei: me: add panther lake H DID (stable-fixes).
  - driver core: fix potential NULL pointer dereference in
    dev_uevent() (stable-fixes).
  - driver core: introduce device_set_driver() helper
    (stable-fixes).
  - drm/amdgpu: Use the right function for hdp flush (stable-fixes).
  - drm/amdgpu: use a dummy owner for sysfs triggered cleaner
    shaders v4 (stable-fixes).
  - spi: tegra210-quad: add rate limiting and simplify timeout
    error message (stable-fixes).
  - spi: tegra210-quad: use WARN_ON_ONCE instead of WARN_ON for
    timeouts (stable-fixes).
  - drm/xe/xe3lpg: Apply Wa_14022293748, Wa_22019794406
    (stable-fixes).
  - drm/amdgpu: Increase KIQ invalidate_tlbs timeout (stable-fixes).
  - gpiolib: of: Move Atmel HSMCI quirk up out of the regulator
    comment (stable-fixes).
  - ntb_hw_amd: Add NTB PCI ID for new gen CPU (stable-fixes).
  - ntb: reduce stack usage in idt_scan_mws (stable-fixes).
  - rtc: pcf85063: do a SW reset if POR failed (stable-fixes).
  - usb: host: xhci-plat: mvebu: use ->quirks instead of
  - >init_quirk() func (stable-fixes).
  - usb: xhci: Avoid Stop Endpoint retry loop if the endpoint
    seems Running (stable-fixes).
  - usb: xhci: Fix isochronous Ring Underrun/Overrun event handling
    (stable-fixes).
  - usb: xhci: Complete 'error mid TD' transfers when handling
    Missed Service (stable-fixes).
  - sound/virtio: Fix cancel_sync warnings on uninitialized
    work_structs (stable-fixes).
  - i3c: master: svc: Add support for Nuvoton npcm845 i3c
    (stable-fixes).
  - phy: rockchip: usbdp: Avoid call hpd_event_trigger in
    dp_phy_init (stable-fixes).
  - iio: adc: ad7768-1: Fix conversion result sign (git-fixes).
  - iio: adc: ad7768-1: Move setting of val a bit later to avoid
    unnecessary return value check (stable-fixes).
  - pinctrl: renesas: rza2: Fix potential NULL pointer dereference
    (stable-fixes).
  - pinctrl: mcp23s08: Get rid of spurious level interrupts
    (stable-fixes).
  - media: i2c: imx214: Check number of lanes from device tree
    (stable-fixes).
  - media: i2c: imx214: Replace register addresses with macros
    (stable-fixes).
  - media: i2c: imx214: Convert to CCI register access helpers
    (stable-fixes).
  - media: i2c: imx214: Simplify with dev_err_probe()
    (stable-fixes).
  - media: i2c: imx214: Use subdev active state (stable-fixes).
  - media: ov08x40: Add missing ov08x40_identify_module() call on
    stream-start (git-fixes).
  - media: ov08x40: Move ov08x40_identify_module() function up
    (stable-fixes).
  - commit 783db07
  - ASoC: simple-card-utils: Fix pointer check in
    graph_util_parse_link_direction (git-fixes).
  - ASoC: amd: acp: Fix NULL pointer deref in acp_i2s_set_tdm_slot
    (git-fixes).
  - ASoC: Intel: sof_sdw: Add NULL check in
    asoc_sdw_rt_dmic_rtd_init() (git-fixes).
  - ata: libata-scsi: Improve CDL control (git-fixes).
  - ata: libata-scsi: Fix ata_msense_control_ata_feature()
    (git-fixes).
  - ata: libata-scsi: Fix ata_mselect_control_ata_feature() return
    type (git-fixes).
  - dmaengine: dmatest: Fix dmatest waiting less when interrupted
    (stable-fixes).
  - crypto: null - Use spin lock instead of mutex (stable-fixes).
  - crypto: ccp - Add support for PCI device 0x1134 (stable-fixes).
  - commit 957df2c
  - ASoC: cs-amp-lib-test: Don't select SND_SOC_CS_AMP_LIB
    (git-fixes).
  - ASoC: soc-pcm: Fix hw_params() and DAPM widget sequence
    (git-fixes).
  - ALSA: hda/realtek: Fix built-mic regression on other ASUS models
    (git-fixes).
  - ALSA: hda/realtek - Enable speaker for HP platform (git-fixes).
  - accel/ivpu: Fix the NPU's DPU frequency calculation (git-fixes).
  - ASoC: fsl_asrc_dma: get codec or cpu dai from backend
    (stable-fixes).
  - ACPI: EC: Set ec_no_wakeup for Lenovo Go S (stable-fixes).
  - ACPI PPTT: Fix coding mistakes in a couple of sizeof() calls
    (stable-fixes).
  - accel/ivpu: Add auto selection logic for job scheduler
    (stable-fixes).
  - commit 1ad8ed8
  - sched/topology: Refinement to topology_span_sane speedup
    (bsc#1242119).
  - sched/topology: improve topology_span_sane speed (bsc#1242119).
  - commit 2cbf7fc
  - include/{topology,cpuset}: Move dl_rebuild_rd_accounting to
    cpuset.h (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/topology: Stop exposing partition_sched_domains_locked
    (bsc#1234634 (Scheduler functional and performance backports)).
  - cgroup/cpuset: Remove partition_and_rebuild_sched_domains
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/topology: Remove redundant dl_clear_root_domain call
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Rebuild root domain accounting after every
    update (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/deadline: Generalize unique visiting of root domains
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/topology: Wrappers for sched_domains_mutex (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/deadline: Ignore special tasks when rebuilding domains
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Use online cpus for validating runtime
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit b339599
  - config: enable INTEGRITY_CA_MACHINE_KEYRING and IMA_BLACKLIST_KEYRING (jsc#PED-12554)
  - commit f6725b4
  - xfrm: Add error handling when nla_put_u32() returns an error
    (git-fixes).
  - commit a36fe76
  - ipv6: add exception routes to GC list in rt6_insert_exception
    (git-fixes).
  - commit a48e9e6
  - net: Handle napi_schedule() calls from non-interrupt
    (git-fixes).
  - commit a752323
  - thunderbolt: Scan retimers after device router has been
    enumerated (git-fixes).
  - commit 0362b7d
  - USB: serial: simple: add OWON HDS200 series oscilloscope support
    (git-fixes).
  - USB: serial: ftdi_sio: add support for Abacus Electrics Optical
    Probe (git-fixes).
  - commit 6c8ea90
  - ext4: goto right label 'out_mmap_sem' in ext4_setattr()
    (bsc#1242556).
  - commit 5bcf26f
  - mm/hugetlb: fix hugepage allocation for interleaved memory nodes
    (bsc#1242263).
  - commit 72a27cc
  - USB: serial: option: add Sierra Wireless EM9291 (git-fixes).
  - usb: quirks: Add delay init quirk for SanDisk 3.2Gen1 Flash
    Drive (git-fixes).
  - commit d78f11a
  - USB: VLI disk crashes if LPM is used (git-fixes).
  - commit 13ff8cb
  - xfs: lock dquot buffer before detaching dquot from b_li_list
    (git-fixes).
  - commit b938ffb
  - Update patches.suse/ax25-Remove-broken-autobind.patch references
    (add CVE-2025-22109 bsc#1241573).
  - commit 6b3aedd
  - xfs: release the dquot buf outside of qli_lock (git-fixes).
  - commit 487de6b
  - nfs: Add missing release on error in
    nfs_lock_and_join_requests() (git-fixes).
  - commit fb1389e
  - NFS: Shut down the nfs_client only after all the superblocks
    (git-fixes).
  - commit 6e7562f
  - NFS: fix open_owner_id_maxsz and related fields (git-fixes).
  - commit 8562675
  - Update patches.suse/udp-Fix-memory-accounting-leak.patch
    references (add CVE-2025-22058 bsc#1241332).
  - commit 4f32ba3
  - NFSv4: Avoid unnecessary scans of filesystems for delayed
    delegations (git-fixes).
  - commit f3951e3
  - NFSv4: Avoid unnecessary scans of filesystems for expired
    delegations (git-fixes).
  - commit 4cb5ad5
  - NFSv4: Avoid unnecessary scans of filesystems for returning
    delegations (git-fixes).
  - commit af0cb65
  - NFSv4: Don't trigger uneccessary scans for return-on-close
    delegations (git-fixes).
  - commit 7f34852
  - tipc: fix NULL pointer dereference in tipc_mon_reinit_self()
    (git-fixes).
  - commit c34766d
  - net_sched: sch_sfq: use a temporary work area for validating
    configuration (git-fixes).
  - commit 39b7b36
  - 9p/trans_fd: mark concurrent read and writes to p9_conn->err
    (git-fixes).
  - commit 0dddd74
  - 9p/net: fix improper handling of bogus negative read/write
    replies (git-fixes).
  - commit 045504b
  - page_pool: avoid infinite loop to schedule delayed worker
    (git-fixes).
  - commit 610f372
  - net: page_pool: don't cast mp param to devmem (git-fixes).
  - commit 7466806
  - net: devmem: do not WARN conditionally after
    netdev_rx_queue_restart() (git-fixes).
  - commit 76cc252
  - sctp: Fix undefined behavior in left shift operation
    (git-fixes).
  - commit 27c992e
  - NFS: Adjust delegated timestamps for O_DIRECT reads and writes
    (git-fixes).
  - commit ffa994c
  - NFS: O_DIRECT writes must check and adjust the file length
    (git-fixes).
  - commit 9122df8
  - xfs: convert quotacheck to attach dquot buffers (git-fixes).
  - commit 938df21
  - xfs: fix superfluous clearing of info->low in
    __xfs_getfsmap_datadev (git-fixes).
  - commit e17f851
  - xfs: remove the unused pag_active_wq field in struct xfs_perag
    (git-fixes).
  - commit 2df6330
  - xfs: remove the unused pagb_count field in struct xfs_perag
    (git-fixes).
  - commit 02c5f7f
  - xfs: attach dquot buffer to dquot log item buffer (git-fixes).
  - commit 6c7c9e4
  - xfs: don't over-report free space or inodes in statvfs
    (git-fixes).
  - commit 11521f9
  - xfs: unmapped buffer item size straddling mismatch (git-fixes).
  - commit c49d035
  - erofs: set error to bio if file-backed IO fails (git-fixes).
  - commit a6727e0
  - erofs: fix potential return value overflow of
    z_erofs_shrink_scan() (git-fixes).
  - commit 17881c6
  - erofs: sunset `struct erofs_workgroup` (git-fixes).
  - commit a08db22
  - erofs: move erofs_workgroup operations into zdata.c (git-fixes).
  - commit 2057765
  - erofs: get rid of erofs_{find,insert}_workgroup (git-fixes).
  - commit 3d3733d
  - USB: storage: quirk for ADATA Portable HDD CH94 (git-fixes).
  - commit 11e9a18
  - xfs: rename xfs_iomap_swapfile_activate to xfs_vm_swap_activate
    (git-fixes).
  - commit 2dad561
  - usb: quirks: add DELAY_INIT quirk for Silicon Motion Flash Drive
    (git-fixes).
  - commit ebb282b
  - xfs: do not check NEEDSREPAIR if ro,norecovery mount
    (git-fixes).
  - commit cca9581
  - xfs: clean up log item accesses in xfs_qm_dqflush{,_done}
    (git-fixes).
  - commit 350d255
  - xfs: separate dquot buffer reads from xfs_dqflush (git-fixes).
  - commit 192f33e
  - NFSD: Encode COMPOUND operation status on page boundaries
    (git-fixes).
  - commit fecafc3
  - usb: gadget: aspeed: Add NULL pointer check in
    ast_vhub_init_dev() (git-fixes).
  - commit 0168bff
  - usb: dwc3: gadget: Avoid using reserved endpoints on Intel
    Merrifield (git-fixes).
  - commit c302821
  - usb: dwc3: gadget: Refactor loop to avoid NULL endpoints
    (git-fixes).
  - commit d64f040
  - usb: host: max3421-hcd: Add missing spi_device_id table
    (git-fixes).
  - commit f198730
  - net: ipv6: rpl_iptunnel: mitigate 2-realloc issue (git-fixes).
  - commit d054524
  - net: ipv6: seg6_iptunnel: mitigate 2-realloc issue (git-fixes).
  - commit ca9fbb2
  - include: net: add static inline dst_dev_overhead() to dst.h
    (git-fixes).
  - commit 22ecdb9
  - xfrm: Add support for per cpu xfrm state handling (git-fixes).
  - commit e9b8e0a
  - mptcp: fix possible integer overflow in mptcp_reset_tout_timer
    (git-fixes).
  - commit 980364e
  - mptcp: annotate data-races around subflow->fully_established
    (git-fixes).
  - commit 76ae7cb
  - net/sched: cbs: Fix integer overflow in cbs_set_port_rate()
    (git-fixes).
  - commit 616b7a0
  - net_sched: sch_sfq: handle bigger packets (git-fixes).
  - commit d218638
  - drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to (bsc#1241635 CVE-2025-38104)
  - commit 6887f04
  - selftests/bpf: Add strparser test for bpf (bsc#1242438).
  - selftests/bpf: Fix invalid flag of recv() (bsc#1242438).
  - bpf: Fix wrong copied_seq calculation (bsc#1242438).
  - strparser: Add read_sock callback (bsc#1242438).
  - selftests/bpf: Add some tests with sockmap SK_PASS
    (bsc#1242438).
  - commit 01d874a
  - selftests/bpf: Select NUMA_NO_NODE to create map (git-fixes).
  - selftests/bpf: Define SYS_PREFIX for powerpc (git-fixes).
  - selftests/bpf: Avoid generating untracked files when running
    bpf selftests (git-fixes).
  - bpf: Use refcount_t instead of atomic_t for mmap_count
    (git-fixes).
  - selftests/bpf: Fix fill_link_info selftest on powerpc
    (git-fixes).
  - tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for
    server bind (git-fixes).
  - selftests/bpf: Actuate tx_metadata_len in xdp_hw_metadata
    (git-fixes).
  - selftests/bpf: Fix compilation error in get_uprobe_offset()
    (git-fixes).
  - commit 9c7f218
  - md/md-bitmap: fix stats collection for external bitmaps
    (git-fixes).
  - md/raid10: fix missing discard IO accounting (git-fixes).
  - md/raid10: wait barrier before returning discard request with
    REQ_NOWAIT (git-fixes).
  - md/raid1,raid10: don't ignore IO flags (git-fixes).
  - md: fix mddev uaf while iterating all_mddevs list (git-fixes).
  - md/raid1: fix memory leak in raid1_run() if no active rdev
    (git-fixes).
  - md: ensure resync is prioritized over recovery (git-fixes).
  - commit d9fa75e

++++ kernel-rt:

  - usb: xhci: Fix Short Packet handling rework ignoring errors
    (git-fixes).
  - media: i2c: imx214: Fix uninitialized variable in
    imx214_set_ctrl() (git-fixes).
  - media: i2c: imx214: Fix link frequency validation (git-fixes).
  - commit 9465e52
  - xhci: Handle spurious events on Etron host isoc enpoints
    (stable-fixes).
  - Refresh patches.suse/padding-XHCI-additional-padding.patch.
  - commit 292fe8c
  - firmware: arm_ffa: Skip Rx buffer ownership release if not
    acquired (git-fixes).
  - firmware: arm_scmi: Fix timeout checks on polling path
    (git-fixes).
  - firmware: arm_scmi: Balance device refcount when destroying
    devices (git-fixes).
  - irqchip/qcom-mpm: Prevent crash when trying to handle non-wake
    GPIOs (git-fixes).
  - i2c: imx-lpi2c: Fix clock count when probe defers (git-fixes).
  - spi: tegra114: Don't fail set_cs_timing when delays are zero
    (git-fixes).
  - drm/i915/pxp: fix undefined reference to
    `intel_pxp_gsccs_is_ready_for_sessions' (git-fixes).
  - drm/mipi-dbi: Fix blanking for non-16 bit formats (git-fixes).
  - drm/tests: shmem: Fix memleak (git-fixes).
  - drm: Select DRM_KMS_HELPER from DRM_DEBUG_DP_MST_TOPOLOGY_REFS
    (git-fixes).
  - drm/fdinfo: Protect against driver unbind (git-fixes).
  - drm/nouveau: Fix WARN_ON in nouveau_fence_context_kill()
    (git-fixes).
  - pinctrl: imx: Return NULL if no group is matched and found
    (git-fixes).
  - drm/amd/display: Force full update in gpu reset (stable-fixes).
  - USB: OHCI: Add quirk for LS7A OHCI controller (rev 0x02)
    (stable-fixes).
  - xhci: Limit time spent with xHC interrupts disabled during
    bus resume (stable-fixes).
  - mei: me: add panther lake H DID (stable-fixes).
  - driver core: fix potential NULL pointer dereference in
    dev_uevent() (stable-fixes).
  - driver core: introduce device_set_driver() helper
    (stable-fixes).
  - drm/amdgpu: Use the right function for hdp flush (stable-fixes).
  - drm/amdgpu: use a dummy owner for sysfs triggered cleaner
    shaders v4 (stable-fixes).
  - spi: tegra210-quad: add rate limiting and simplify timeout
    error message (stable-fixes).
  - spi: tegra210-quad: use WARN_ON_ONCE instead of WARN_ON for
    timeouts (stable-fixes).
  - drm/xe/xe3lpg: Apply Wa_14022293748, Wa_22019794406
    (stable-fixes).
  - drm/amdgpu: Increase KIQ invalidate_tlbs timeout (stable-fixes).
  - gpiolib: of: Move Atmel HSMCI quirk up out of the regulator
    comment (stable-fixes).
  - ntb_hw_amd: Add NTB PCI ID for new gen CPU (stable-fixes).
  - ntb: reduce stack usage in idt_scan_mws (stable-fixes).
  - rtc: pcf85063: do a SW reset if POR failed (stable-fixes).
  - usb: host: xhci-plat: mvebu: use ->quirks instead of
  - >init_quirk() func (stable-fixes).
  - usb: xhci: Avoid Stop Endpoint retry loop if the endpoint
    seems Running (stable-fixes).
  - usb: xhci: Fix isochronous Ring Underrun/Overrun event handling
    (stable-fixes).
  - usb: xhci: Complete 'error mid TD' transfers when handling
    Missed Service (stable-fixes).
  - sound/virtio: Fix cancel_sync warnings on uninitialized
    work_structs (stable-fixes).
  - i3c: master: svc: Add support for Nuvoton npcm845 i3c
    (stable-fixes).
  - phy: rockchip: usbdp: Avoid call hpd_event_trigger in
    dp_phy_init (stable-fixes).
  - iio: adc: ad7768-1: Fix conversion result sign (git-fixes).
  - iio: adc: ad7768-1: Move setting of val a bit later to avoid
    unnecessary return value check (stable-fixes).
  - pinctrl: renesas: rza2: Fix potential NULL pointer dereference
    (stable-fixes).
  - pinctrl: mcp23s08: Get rid of spurious level interrupts
    (stable-fixes).
  - media: i2c: imx214: Check number of lanes from device tree
    (stable-fixes).
  - media: i2c: imx214: Replace register addresses with macros
    (stable-fixes).
  - media: i2c: imx214: Convert to CCI register access helpers
    (stable-fixes).
  - media: i2c: imx214: Simplify with dev_err_probe()
    (stable-fixes).
  - media: i2c: imx214: Use subdev active state (stable-fixes).
  - media: ov08x40: Add missing ov08x40_identify_module() call on
    stream-start (git-fixes).
  - media: ov08x40: Move ov08x40_identify_module() function up
    (stable-fixes).
  - commit 783db07
  - ASoC: simple-card-utils: Fix pointer check in
    graph_util_parse_link_direction (git-fixes).
  - ASoC: amd: acp: Fix NULL pointer deref in acp_i2s_set_tdm_slot
    (git-fixes).
  - ASoC: Intel: sof_sdw: Add NULL check in
    asoc_sdw_rt_dmic_rtd_init() (git-fixes).
  - ata: libata-scsi: Improve CDL control (git-fixes).
  - ata: libata-scsi: Fix ata_msense_control_ata_feature()
    (git-fixes).
  - ata: libata-scsi: Fix ata_mselect_control_ata_feature() return
    type (git-fixes).
  - dmaengine: dmatest: Fix dmatest waiting less when interrupted
    (stable-fixes).
  - crypto: null - Use spin lock instead of mutex (stable-fixes).
  - crypto: ccp - Add support for PCI device 0x1134 (stable-fixes).
  - commit 957df2c
  - ASoC: cs-amp-lib-test: Don't select SND_SOC_CS_AMP_LIB
    (git-fixes).
  - ASoC: soc-pcm: Fix hw_params() and DAPM widget sequence
    (git-fixes).
  - ALSA: hda/realtek: Fix built-mic regression on other ASUS models
    (git-fixes).
  - ALSA: hda/realtek - Enable speaker for HP platform (git-fixes).
  - accel/ivpu: Fix the NPU's DPU frequency calculation (git-fixes).
  - ASoC: fsl_asrc_dma: get codec or cpu dai from backend
    (stable-fixes).
  - ACPI: EC: Set ec_no_wakeup for Lenovo Go S (stable-fixes).
  - ACPI PPTT: Fix coding mistakes in a couple of sizeof() calls
    (stable-fixes).
  - accel/ivpu: Add auto selection logic for job scheduler
    (stable-fixes).
  - commit 1ad8ed8
  - sched/topology: Refinement to topology_span_sane speedup
    (bsc#1242119).
  - sched/topology: improve topology_span_sane speed (bsc#1242119).
  - commit 2cbf7fc
  - include/{topology,cpuset}: Move dl_rebuild_rd_accounting to
    cpuset.h (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/topology: Stop exposing partition_sched_domains_locked
    (bsc#1234634 (Scheduler functional and performance backports)).
  - cgroup/cpuset: Remove partition_and_rebuild_sched_domains
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/topology: Remove redundant dl_clear_root_domain call
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Rebuild root domain accounting after every
    update (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/deadline: Generalize unique visiting of root domains
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/topology: Wrappers for sched_domains_mutex (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/deadline: Ignore special tasks when rebuilding domains
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Use online cpus for validating runtime
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit b339599
  - config: enable INTEGRITY_CA_MACHINE_KEYRING and IMA_BLACKLIST_KEYRING (jsc#PED-12554)
  - commit f6725b4
  - xfrm: Add error handling when nla_put_u32() returns an error
    (git-fixes).
  - commit a36fe76
  - ipv6: add exception routes to GC list in rt6_insert_exception
    (git-fixes).
  - commit a48e9e6
  - net: Handle napi_schedule() calls from non-interrupt
    (git-fixes).
  - commit a752323
  - thunderbolt: Scan retimers after device router has been
    enumerated (git-fixes).
  - commit 0362b7d
  - USB: serial: simple: add OWON HDS200 series oscilloscope support
    (git-fixes).
  - USB: serial: ftdi_sio: add support for Abacus Electrics Optical
    Probe (git-fixes).
  - commit 6c8ea90
  - ext4: goto right label 'out_mmap_sem' in ext4_setattr()
    (bsc#1242556).
  - commit 5bcf26f
  - mm/hugetlb: fix hugepage allocation for interleaved memory nodes
    (bsc#1242263).
  - commit 72a27cc
  - USB: serial: option: add Sierra Wireless EM9291 (git-fixes).
  - usb: quirks: Add delay init quirk for SanDisk 3.2Gen1 Flash
    Drive (git-fixes).
  - commit d78f11a
  - USB: VLI disk crashes if LPM is used (git-fixes).
  - commit 13ff8cb
  - xfs: lock dquot buffer before detaching dquot from b_li_list
    (git-fixes).
  - commit b938ffb
  - Update patches.suse/ax25-Remove-broken-autobind.patch references
    (add CVE-2025-22109 bsc#1241573).
  - commit 6b3aedd
  - xfs: release the dquot buf outside of qli_lock (git-fixes).
  - commit 487de6b
  - nfs: Add missing release on error in
    nfs_lock_and_join_requests() (git-fixes).
  - commit fb1389e
  - NFS: Shut down the nfs_client only after all the superblocks
    (git-fixes).
  - commit 6e7562f
  - NFS: fix open_owner_id_maxsz and related fields (git-fixes).
  - commit 8562675
  - Update patches.suse/udp-Fix-memory-accounting-leak.patch
    references (add CVE-2025-22058 bsc#1241332).
  - commit 4f32ba3
  - NFSv4: Avoid unnecessary scans of filesystems for delayed
    delegations (git-fixes).
  - commit f3951e3
  - NFSv4: Avoid unnecessary scans of filesystems for expired
    delegations (git-fixes).
  - commit 4cb5ad5
  - NFSv4: Avoid unnecessary scans of filesystems for returning
    delegations (git-fixes).
  - commit af0cb65
  - NFSv4: Don't trigger uneccessary scans for return-on-close
    delegations (git-fixes).
  - commit 7f34852
  - tipc: fix NULL pointer dereference in tipc_mon_reinit_self()
    (git-fixes).
  - commit c34766d
  - net_sched: sch_sfq: use a temporary work area for validating
    configuration (git-fixes).
  - commit 39b7b36
  - 9p/trans_fd: mark concurrent read and writes to p9_conn->err
    (git-fixes).
  - commit 0dddd74
  - 9p/net: fix improper handling of bogus negative read/write
    replies (git-fixes).
  - commit 045504b
  - page_pool: avoid infinite loop to schedule delayed worker
    (git-fixes).
  - commit 610f372
  - net: page_pool: don't cast mp param to devmem (git-fixes).
  - commit 7466806
  - net: devmem: do not WARN conditionally after
    netdev_rx_queue_restart() (git-fixes).
  - commit 76cc252
  - sctp: Fix undefined behavior in left shift operation
    (git-fixes).
  - commit 27c992e
  - NFS: Adjust delegated timestamps for O_DIRECT reads and writes
    (git-fixes).
  - commit ffa994c
  - NFS: O_DIRECT writes must check and adjust the file length
    (git-fixes).
  - commit 9122df8
  - xfs: convert quotacheck to attach dquot buffers (git-fixes).
  - commit 938df21
  - xfs: fix superfluous clearing of info->low in
    __xfs_getfsmap_datadev (git-fixes).
  - commit e17f851
  - xfs: remove the unused pag_active_wq field in struct xfs_perag
    (git-fixes).
  - commit 2df6330
  - xfs: remove the unused pagb_count field in struct xfs_perag
    (git-fixes).
  - commit 02c5f7f
  - xfs: attach dquot buffer to dquot log item buffer (git-fixes).
  - commit 6c7c9e4
  - xfs: don't over-report free space or inodes in statvfs
    (git-fixes).
  - commit 11521f9
  - xfs: unmapped buffer item size straddling mismatch (git-fixes).
  - commit c49d035
  - erofs: set error to bio if file-backed IO fails (git-fixes).
  - commit a6727e0
  - erofs: fix potential return value overflow of
    z_erofs_shrink_scan() (git-fixes).
  - commit 17881c6
  - erofs: sunset `struct erofs_workgroup` (git-fixes).
  - commit a08db22
  - erofs: move erofs_workgroup operations into zdata.c (git-fixes).
  - commit 2057765
  - erofs: get rid of erofs_{find,insert}_workgroup (git-fixes).
  - commit 3d3733d
  - USB: storage: quirk for ADATA Portable HDD CH94 (git-fixes).
  - commit 11e9a18
  - xfs: rename xfs_iomap_swapfile_activate to xfs_vm_swap_activate
    (git-fixes).
  - commit 2dad561
  - usb: quirks: add DELAY_INIT quirk for Silicon Motion Flash Drive
    (git-fixes).
  - commit ebb282b
  - xfs: do not check NEEDSREPAIR if ro,norecovery mount
    (git-fixes).
  - commit cca9581
  - xfs: clean up log item accesses in xfs_qm_dqflush{,_done}
    (git-fixes).
  - commit 350d255
  - xfs: separate dquot buffer reads from xfs_dqflush (git-fixes).
  - commit 192f33e
  - NFSD: Encode COMPOUND operation status on page boundaries
    (git-fixes).
  - commit fecafc3
  - usb: gadget: aspeed: Add NULL pointer check in
    ast_vhub_init_dev() (git-fixes).
  - commit 0168bff
  - usb: dwc3: gadget: Avoid using reserved endpoints on Intel
    Merrifield (git-fixes).
  - commit c302821
  - usb: dwc3: gadget: Refactor loop to avoid NULL endpoints
    (git-fixes).
  - commit d64f040
  - usb: host: max3421-hcd: Add missing spi_device_id table
    (git-fixes).
  - commit f198730
  - net: ipv6: rpl_iptunnel: mitigate 2-realloc issue (git-fixes).
  - commit d054524
  - net: ipv6: seg6_iptunnel: mitigate 2-realloc issue (git-fixes).
  - commit ca9fbb2
  - include: net: add static inline dst_dev_overhead() to dst.h
    (git-fixes).
  - commit 22ecdb9
  - xfrm: Add support for per cpu xfrm state handling (git-fixes).
  - commit e9b8e0a
  - mptcp: fix possible integer overflow in mptcp_reset_tout_timer
    (git-fixes).
  - commit 980364e
  - mptcp: annotate data-races around subflow->fully_established
    (git-fixes).
  - commit 76ae7cb
  - net/sched: cbs: Fix integer overflow in cbs_set_port_rate()
    (git-fixes).
  - commit 616b7a0
  - net_sched: sch_sfq: handle bigger packets (git-fixes).
  - commit d218638
  - drm/amdgpu: Replace Mutex with Spinlock for RLCG register access to (bsc#1241635 CVE-2025-38104)
  - commit 6887f04
  - selftests/bpf: Add strparser test for bpf (bsc#1242438).
  - selftests/bpf: Fix invalid flag of recv() (bsc#1242438).
  - bpf: Fix wrong copied_seq calculation (bsc#1242438).
  - strparser: Add read_sock callback (bsc#1242438).
  - selftests/bpf: Add some tests with sockmap SK_PASS
    (bsc#1242438).
  - commit 01d874a
  - selftests/bpf: Select NUMA_NO_NODE to create map (git-fixes).
  - selftests/bpf: Define SYS_PREFIX for powerpc (git-fixes).
  - selftests/bpf: Avoid generating untracked files when running
    bpf selftests (git-fixes).
  - bpf: Use refcount_t instead of atomic_t for mmap_count
    (git-fixes).
  - selftests/bpf: Fix fill_link_info selftest on powerpc
    (git-fixes).
  - tools/testing/selftests/bpf/test_tc_tunnel.sh: Fix wait for
    server bind (git-fixes).
  - selftests/bpf: Actuate tx_metadata_len in xdp_hw_metadata
    (git-fixes).
  - selftests/bpf: Fix compilation error in get_uprobe_offset()
    (git-fixes).
  - commit 9c7f218
  - md/md-bitmap: fix stats collection for external bitmaps
    (git-fixes).
  - md/raid10: fix missing discard IO accounting (git-fixes).
  - md/raid10: wait barrier before returning discard request with
    REQ_NOWAIT (git-fixes).
  - md/raid1,raid10: don't ignore IO flags (git-fixes).
  - md: fix mddev uaf while iterating all_mddevs list (git-fixes).
  - md/raid1: fix memory leak in raid1_run() if no active rdev
    (git-fixes).
  - md: ensure resync is prioritized over recovery (git-fixes).
  - commit d9fa75e

++++ libgcrypt:

  - CSHAKE basic regression test failure in s390x [bsc#1242419]
    * Disable SHA3 s390x acceleration for CSHAKE [rC2486d9b5ae01]
    * Add libgcrypt-Disable-SHA3-s390x-acceleration-for-CSHAKE.patch

++++ mdadm:

  - Add dependency on suse-module-tools for SLE15 (bsc#1242696)

++++ microos-tools:

  - Update to version 4.0+git14:
    * test: Test with Minimal-VM as well
    * test: Add some missing SYSTEMD_IGNORE_CHROOT=1 to poweroff calls
    * selinux-autorelabel: Fix check for relabelling only specific filesystems

------------------------------------------------------------------
------------------  2025-5-5  -  May 5 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.19 → 10.2.20

++++ grub2:

  - Fix CVE-2025-4382: TPM auto-decryption data exposure (bsc#1242971)
    * 0001-kern-rescue_reader-Block-the-rescue-mode-until-the-C.patch
    * 0002-commands-search-Introduce-the-cryptodisk-only-argume.patch
    * 0003-disk-diskfilter-Introduce-the-cryptocheck-command.patch
    * 0004-commands-search-Add-the-diskfilter-support.patch
    * 0005-docs-Document-available-crypto-disks-checks.patch
    * 0006-disk-cryptodisk-Add-the-erase-secrets-function.patch
    * 0007-disk-cryptodisk-Wipe-the-passphrase-from-memory.patch
    * 0008-cryptocheck-Add-quiet-option.patch
  - patch rebased
    * 0001-Improve-TPM-key-protection-on-boot-interruptions.patch
    * 0004-Key-revocation-on-out-of-bound-file-access.patch
  - patch refrehed
    * 0001-Fix-PowerPC-CAS-reboot-to-evaluate-menu-context.patch
    * 0002-Requiring-authentication-after-tpm-unlock-for-CLI-ac.patch

++++ kernel-default:

  - Update
    patches.suse/ALSA-timer-Don-t-take-register_mutex-with-copy_from-.patch
    (git-fixes CVE-2025-23134 bsc#1241628).
  - Update
    patches.suse/Bluetooth-btnxpuart-Fix-kernel-panic-during-FW-relea.patch
    (git-fixes CVE-2025-22102 bsc#1241456).
  - Update
    patches.suse/HID-ignore-non-functional-sensor-in-HP-5MP-Camera.patch
    (stable-fixes CVE-2025-21992 bsc#1240796).
  - Update
    patches.suse/PCI-ASPM-Fix-link-state-exit-during-switch-upstream-.patch
    (git-fixes CVE-2024-58093 bsc#1241347).
  - Update
    patches.suse/RDMA-core-Fix-use-after-free-when-rename-device-name.patch
    (git-fixes CVE-2025-22085 bsc#1241419).
  - Update
    patches.suse/RDMA-erdma-Prevent-use-after-free-in-erdma_accept_ne.patch
    (git-fixes CVE-2025-22088 bsc#1241528).
  - Update
    patches.suse/RDMA-mlx5-Fix-mlx5_poll_one-cur_qp-update-flow.patch
    (git-fixes CVE-2025-22086 bsc#1241458).
  - Update
    patches.suse/RDMA-mlx5-Fix-page_size-variable-overflow.patch
    (git-fixes CVE-2025-22091 bsc#1241535).
  - Update
    patches.suse/acpi-nfit-fix-narrowing-conversion-in-acpi_nfit_ctl.patch
    (git-fixes CVE-2025-22044 bsc#1241424).
  - Update
    patches.suse/arm64-Don-t-call-NULL-in-do_compat_alignment_fixup.patch
    (git-fixes CVE-2025-22033 bsc#1241436).
  - Update patches.suse/block-fix-adding-folio-to-bio.patch
    (git-fixes CVE-2025-22122 bsc#1241594).
  - Update
    patches.suse/block-fix-queue-freeze-vs-limits-lock-order-in-sysfs.patch
    (jsc#PED-9651 CVE-2025-21807 bsc#1238756).
  - Update
    patches.suse/bnxt_en-Mask-the-bd_cnt-field-in-the-TX-BD-properly.patch
    (git-fixes CVE-2025-22108 bsc#1241574).
  - Update
    patches.suse/bpf-Fix-bpf_sk_select_reuseport-memory-leak.patch
    (git-fixes CVE-2025-21683 bsc#1236704).
  - Update
    patches.suse/bpf-avoid-holding-freeze_mutex-during-mmap-operation.patch
    (git-fixes CVE-2025-21853 bsc#1239476).
  - Update
    patches.suse/dlm-prevent-NPD-when-writing-a-positive-value-to-event_done.patch
    (git-fixes CVE-2025-23131 bsc#1241601).
  - Update
    patches.suse/drm-amd-display-avoid-NPD-when-ASIC-does-not-support.patch
    (git-fixes CVE-2025-22093 bsc#1241545).
  - Update
    patches.suse/drm-vkms-Fix-use-after-free-and-double-free-on-init-.patch
    (git-fixes CVE-2025-22097 bsc#1241541).
  - Update
    patches.suse/efi-Don-t-map-the-entire-mokvar-table-to-determine-i.patch
    (stable-fixes CVE-2025-21872 bsc#1240323).
  - Update
    patches.suse/eth-bnxt-fix-out-of-range-access-of-vnic_info-array.patch
    (jsc#PED-11923 CVE-2025-22112 bsc#1241581).
  - Update patches.suse/exfat-fix-missing-shutdown-check.patch
    (git-fixes CVE-2025-22076 bsc#1241417).
  - Update
    patches.suse/exfat-fix-random-stack-corruption-after-get_block.patch
    (git-fixes CVE-2025-22036 bsc#1241426).
  - Update
    patches.suse/idpf-check-error-for-register_netdev-on-init.patch
    (git-fixes CVE-2025-22116 bsc#1241459).
  - Update
    patches.suse/idpf-fix-adapter-NULL-pointer-dereference-on-reboot.patch
    (git-fixes CVE-2025-22065 bsc#1241333).
  - Update
    patches.suse/ipv6-mcast-add-RCU-protection-to-mld_newpack.patch
    (git-fixes CVE-2025-21758 bsc#1238737).
  - Update
    patches.suse/media-streamzap-fix-race-between-device-disconnectio.patch
    (git-fixes CVE-2025-22027 bsc#1241369).
  - Update
    patches.suse/media-vimc-skip-.s_stream-for-stopped-entities.patch
    (git-fixes CVE-2025-22028 bsc#1241362).
  - Update
    patches.suse/mm-clear-uffd-wp-PTE-PMD-state-on-mremap.patch
    (bsc#1236648 CVE-2025-21696 bsc#1237111).
  - Update
    patches.suse/mptcp-fix-scheduling-while-atomic-in-mptcp_pm_nl_app.patch
    (git-fixes CVE-2025-21938 bsc#1240723).
  - Update
    patches.suse/msft-hv-3167-fbdev-hyperv_fb-Allow-graceful-removal-of-framebuffe.patch
    (git-fixes CVE-2025-21976 bsc#1241145).
  - Update
    patches.suse/net-9p-usbg-fix-handling-of-the-failed-kzalloc-memor.patch
    (git-fixes CVE-2024-56730 bsc#1235610).
  - Update
    patches.suse/net-Remove-RTNL-dance-for-SIOCBRADDIF-and-SIOCBRDELI.patch
    (git-fixes CVE-2025-22111 bsc#1241572).
  - Update
    patches.suse/net-ethtool-netlink-Allow-NULL-nlattrs-when-getting-.patch
    (git-fixes CVE-2025-21921 bsc#1240637).
  - Update patches.suse/net-rose-lock-the-socket-in-rose_bind.patch
    (git-fixes CVE-2025-21749 bsc#1238904).
  - Update
    patches.suse/netfilter-ipset-add-missing-range-check-in-bitmap_ip.patch
    (git-fixes CVE-2024-53141 bsc#1234381).
  - Update
    patches.suse/netfilter-nft_socket-remove-WARN_ON_ONCE-on-maximum-.patch
    (git-fixes CVE-2024-56783 bsc#1235625).
  - Update
    patches.suse/nfsd-fix-legacy-client-tracking-initialization.patch
    (git-fixes CVE-2024-58092 bsc#1241285).
  - Update
    patches.suse/nfsd-fix-management-of-listener-transports.patch
    (git-fixes CVE-2025-22024 bsc#1241348).
  - Update
    patches.suse/nfsd-put-dl_stid-if-fail-to-queue-dl_recall.patch
    (git-fixes CVE-2025-22025 bsc#1241361).
  - Update
    patches.suse/ntb_hw_switchtec-Fix-shift-out-of-bounds-in-switchte.patch
    (git-fixes CVE-2023-53034 bsc#1241341).
  - Update
    patches.suse/ocfs2-handle-a-symlink-read-error-correctly.patch
    (git-fixes CVE-2024-58001 bsc#1239079).
  - Update
    patches.suse/ovl-support-encoding-fid-from-inode-with-no-alias.patch
    (bsc#1238448 CVE-2025-21654 bsc#1236162).
  - Update
    patches.suse/powerpc-perf-Fix-ref-counting-on-the-PMU-vpa_pmu.patch
    (git-fixes CVE-2025-22094 bsc#1241512).
  - Update
    patches.suse/riscv-kvm-Fix-out-of-bounds-array-access.patch
    (jsc#PED-348 CVE-2024-53228 bsc#1235094).
  - Update
    patches.suse/rtnetlink-Allocate-vfinfo-size-for-VF-GUIDs-when-sup.patch
    (bsc#1224013 CVE-2025-22075 bsc#1241402).
  - Update
    patches.suse/sctp-add-mutual-exclusion-in-proc_sctp_do_udp_port.patch
    (git-fixes CVE-2025-22062 bsc#1241412).
  - Update
    patches.suse/thermal-int340x-Add-NULL-check-for-adev.patch
    (git-fixes CVE-2025-23136 bsc#1241357).
  - Update
    patches.suse/ublk-make-sure-ubq-canceling-is-set-when-queue-is-frozen.patch
    (git-fixes CVE-2025-22068 bsc#1241411).
  - Update patches.suse/udp-Fix-memory-accounting-leak.patch
    (git-fixes CVE-2025-22058 bsc#1241332).
  - Update
    patches.suse/usb-xhci-Apply-the-link-chain-quirk-on-NEC-isoc-endp.patch
    (git-fixes CVE-2025-22022 bsc#1241292).
  - Update patches.suse/usbnet-fix-NPE-during-rx_complete.patch
    (git-fixes CVE-2025-22050 bsc#1241441).
  - Update
    patches.suse/vhost-scsi-Fix-handling-of-multiple-calls-to-vhost_s.patch
    (git-fixes CVE-2025-22083 bsc#1241414).
  - Update
    patches.suse/w1-fix-NULL-pointer-dereference-in-probe.patch
    (git-fixes CVE-2025-22084 bsc#1241338).
  - Update
    patches.suse/wifi-ath11k-Clear-affinity-hint-before-calling-ath11.patch
    (git-fixes CVE-2025-23129 bsc#1241599).
  - Update
    patches.suse/wifi-ath11k-add-srng-lock-for-ath11k_hal_srng_-in-mo.patch
    (git-fixes CVE-2024-58096 bsc#1241344).
  - Update
    patches.suse/wifi-ath11k-fix-RCU-stall-while-reaping-monitor-dest.patch
    (git-fixes CVE-2024-58097 bsc#1241343).
  - Update
    patches.suse/wifi-ath11k-update-channel-list-in-reg-notifier-inst.patch
    (git-fixes CVE-2025-23133 bsc#1241451).
  - Update
    patches.suse/wifi-ath12k-Clear-affinity-hint-before-calling-ath12.patch
    (git-fixes CVE-2025-22128 bsc#1241598).
  - Update
    patches.suse/wifi-mt76-mt7921-fix-kernel-panic-due-to-null-pointe.patch
    (git-fixes CVE-2025-22032 bsc#1241425).
  - commit a5369e9
  - ext4: add more ext4_emergency_state() checks around sb_rdonly()
    (bsc#1242340).
  - commit e34367c
  - ext4: add ext4_emergency_state() helper function (bsc#1242340).
  - commit 2802292
  - ext4: add EXT4_FLAGS_EMERGENCY_RO bit (bsc#1242340).
  - commit 726006a
  - ext4: convert EXT4_FLAGS_* defines to enum (bsc#1242340).
  - commit a75e7cb
  - ext4: make block validity check resistent to sb bh corruption
    (bsc#1242348).
  - commit 7d22394
  - ext4: don't treat fhandle lookup of ea_inode as FS corruption
    (bsc#1242347).
  - commit ba6203b
  - jbd2: add a missing data flush during file and fs
    synchronization (bsc#1242346).
  - commit fa4ed15
  - iommu: Fix two issues in iommu_copy_struct_from_user()
    (git-fixes).
  - commit 86e4261
  - ext4: don't over-report free space or inodes in statvfs
    (bsc#1242345).
  - commit 8be4480
  - jbd2: fix off-by-one while erasing journal (bsc#1242344).
  - commit 123caf6
  - jbd2: remove wrong sb->s_sequence check (bsc#1242343).
  - commit f026605
  - ext4: add missing brelse() for bh2 in ext4_dx_add_entry()
    (bsc#1242342).
  - commit 383a1e1
  - ext4: show 'emergency_ro' when EXT4_FLAGS_EMERGENCY_RO is set
    (bsc#1242340).
  - commit d5057af
  - ext4: correct behavior under errors=remount-ro mode
    (bsc#1242337).
  - blacklist.conf: Blacklist 57e7239ce0ed
  - commit a79e7b9
  - ext4: partial zero eof block on unaligned inode size extension
    (bsc#1242336).
  - commit cacba0b
  - ext4: protect ext4_release_dquot against freezing (bsc#1242335).
  - commit 457d212
  - ext4: introduce linear search for dentries (bsc#1242334).
  - commit 58bf0d9
  - jbd2: flush filesystem device before updating tail sequence
    (bsc#1242333).
  - commit 3798ec5
  - jbd2: increase IO priority for writing revoke records
    (bsc#1242332).
  - commit a382b37
  - ext4: fix race in buffer_head read fault injection
    (bsc#1242331).
  - commit 994f6d0
  - splice: remove duplicate noinline from pipe_clear_nowait
    (bsc#1242328).
  - commit 62a8d5e
  - mm: fix filemap_get_folios_contig returning batches of identical
    folios (bsc#1242327).
  - commit 7222583
  - mm: fix error handling in __filemap_get_folio() with FGP_NOWAIT
    (bsc#1242326).
  - commit 4a38c7a
  - mm/readahead: fix large folio support in async readahead
    (bsc#1242321).
  - commit e2de4df
  - mm/filemap: don't call folio_test_locked() without a reference
    in next_uptodate_folio() (bsc#1242318).
  - commit 2a71dc7
  - mm: don't set readahead flag on a folio when lookahead_size >
    nr_to_read (bsc#1242317).
  - commit 06b8a5d
  - mm/truncate: reset xa_has_values flag on each iteration
    (bsc#1242316).
  - commit 33fa0e9
  - udf: Skip parent dir link count update if corrupted
    (bsc#1242315).
  - commit 8928a78
  - udf: Verify inode link counts before performing rename
    (bsc#1242314).
  - commit d1d387f
  - udf: Fix inode_getblk() return value (bsc#1242313).
  - commit 9d52630
  - fsnotify: fix sending inotify event with unexpected filename
    (bsc#1234198).
  - commit 4e33fd9
  - block: never reduce ra_pages in blk_apply_bdi_limits
    (bsc#1242308).
  - commit 9418247
  - isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
    (bsc#1242307).
  - commit 051b9f7
  - ext4: avoid journaling sb update on error if journal is destroying (bsc#1241967).
  - commit 4c6dcbd
  - ext4: define ext4_journal_destroy wrapper (bsc#1241967).
  - commit b1ba8b2
  - mptcp: consolidate suboption status (CVE-2025-21707
    bsc#1238862).
  - commit 83b24f9
  - reenable TN3270 so that conmode=3270 keep working (bsc#1242296)
  - commit 41f697e
  - drm/mgag200: Added support for the new device G200eH5 (bsc#1242129 jsc#PED-10427)
  - commit ed5dd29
  - Documentation: Fix description format for powerpc RTAS ioctls
    (jsc#PED-4486).
  - powerpc/pseries: Include linux/types.h in papr-platform-dump.h
    (jsc#PED-4486).
  - commit 0825081
  - make use of anon_inode_getfile_fmode() (jsc#PED-4486).
  - Refresh patches.suse/powerpc-pseries-Add-a-char-driver-for-physical-attes.patch.
  - Refresh patches.suse/powerpc-pseries-Add-ibm-get-dynamic-sensor-state-RTA.patch.
  - Refresh patches.suse/powerpc-pseries-Add-ibm-set-dynamic-indicator-RTAS-c.patch.
  - Refresh patches.suse/powerpc-pseries-Add-papr-indices-char-driver-for-ibm.patch.
  - Refresh patches.suse/powerpc-pseries-Add-papr-platform-dump-character-dri.patch.
  - Refresh patches.suse/powerpc-pseries-Define-common-functions-for-RTAS-seq.patch.
  - Refresh patches.suse/powerpc-pseries-Define-papr_indices_io_block-for-pap.patch.
  - commit e8f7e0c
  - powerpc/bpf: fix JIT code size calculation of bpf trampoline
    (jsc#PED-10909 git-fixes).
  - commit e7da6dd
  - powerpc: Don't use --- in kernel logs (git-fixes).
  - commit ecb31d5
  - powerpc64/ftrace: fix clobbered r15 during livepatching
    (jsc#PED-10909 git-fixes).
  - commit a971e4a
  - mptcp: only inc MPJoinAckHMacFailure for HMAC failures
    (git-fixes).
  - commit d5bbe65
  - mptcp: fix NULL pointer in can_accept_new_subflow (git-fixes).
  - commit e4b6b25
  - mptcp: sockopt: fix getting freebind & transparent (git-fixes).
  - commit 3a57f0a
  - mptcp: sockopt: fix getting IPV6_V6ONLY (git-fixes).
  - commit 3a8bd3c
  - mptcp: Fix data stream corruption in the address announcement
    (git-fixes).
  - commit 9194c38
  - mptcp: fix 'scheduling while atomic' in
    mptcp_pm_nl_append_new_local_addr (git-fixes).
  - commit 8aeaf4b
  - mptcp: reset when MPTCP opts are dropped after join (git-fixes).
  - commit 71d9d00
  - mptcp: blackhole only if 1st SYN retrans w/o MPC is accepted
    (git-fixes).
  - commit 32e4230
  - netdev: avoid CFI problems with sock priv helpers (git-fixes).
  - commit 9750c47
  - mptcp: be sure to send ack when mptcp-level window re-opens
    (git-fixes).
  - commit 3f7ccb9
  - mptcp: sysctl: avail sched: remove write access (git-fixes).
  - commit d8519fb
  - mptcp: prevent excessive coalescing on receive (git-fixes).
  - commit 261188f
  - mptcp: don't always assume copied data in mptcp_cleanup_rbuf()
    (git-fixes).
  - commit 7d46f2f
  - Drivers: hv: Fix bad ref to hv_synic_eventring_tail when CPU
    goes offline (git-fixes).
  - tools/hv: update route parsing in kvp daemon (git-fixes).
  - Drivers: hv: Fix bad pointer dereference in hv_get_partition_id
    (git-fixes).
  - commit 72ebc30

++++ kernel-firmware-amdgpu:

  - Update to version 20250505 (git commit 2b8dfb5e11a8):
    * amdgpu: update dcn 4.01 firmware to 0.1.8.0

++++ kernel-rt:

  - Update
    patches.suse/ALSA-timer-Don-t-take-register_mutex-with-copy_from-.patch
    (git-fixes CVE-2025-23134 bsc#1241628).
  - Update
    patches.suse/Bluetooth-btnxpuart-Fix-kernel-panic-during-FW-relea.patch
    (git-fixes CVE-2025-22102 bsc#1241456).
  - Update
    patches.suse/HID-ignore-non-functional-sensor-in-HP-5MP-Camera.patch
    (stable-fixes CVE-2025-21992 bsc#1240796).
  - Update
    patches.suse/PCI-ASPM-Fix-link-state-exit-during-switch-upstream-.patch
    (git-fixes CVE-2024-58093 bsc#1241347).
  - Update
    patches.suse/RDMA-core-Fix-use-after-free-when-rename-device-name.patch
    (git-fixes CVE-2025-22085 bsc#1241419).
  - Update
    patches.suse/RDMA-erdma-Prevent-use-after-free-in-erdma_accept_ne.patch
    (git-fixes CVE-2025-22088 bsc#1241528).
  - Update
    patches.suse/RDMA-mlx5-Fix-mlx5_poll_one-cur_qp-update-flow.patch
    (git-fixes CVE-2025-22086 bsc#1241458).
  - Update
    patches.suse/RDMA-mlx5-Fix-page_size-variable-overflow.patch
    (git-fixes CVE-2025-22091 bsc#1241535).
  - Update
    patches.suse/acpi-nfit-fix-narrowing-conversion-in-acpi_nfit_ctl.patch
    (git-fixes CVE-2025-22044 bsc#1241424).
  - Update
    patches.suse/arm64-Don-t-call-NULL-in-do_compat_alignment_fixup.patch
    (git-fixes CVE-2025-22033 bsc#1241436).
  - Update patches.suse/block-fix-adding-folio-to-bio.patch
    (git-fixes CVE-2025-22122 bsc#1241594).
  - Update
    patches.suse/block-fix-queue-freeze-vs-limits-lock-order-in-sysfs.patch
    (jsc#PED-9651 CVE-2025-21807 bsc#1238756).
  - Update
    patches.suse/bnxt_en-Mask-the-bd_cnt-field-in-the-TX-BD-properly.patch
    (git-fixes CVE-2025-22108 bsc#1241574).
  - Update
    patches.suse/bpf-Fix-bpf_sk_select_reuseport-memory-leak.patch
    (git-fixes CVE-2025-21683 bsc#1236704).
  - Update
    patches.suse/bpf-avoid-holding-freeze_mutex-during-mmap-operation.patch
    (git-fixes CVE-2025-21853 bsc#1239476).
  - Update
    patches.suse/dlm-prevent-NPD-when-writing-a-positive-value-to-event_done.patch
    (git-fixes CVE-2025-23131 bsc#1241601).
  - Update
    patches.suse/drm-amd-display-avoid-NPD-when-ASIC-does-not-support.patch
    (git-fixes CVE-2025-22093 bsc#1241545).
  - Update
    patches.suse/drm-vkms-Fix-use-after-free-and-double-free-on-init-.patch
    (git-fixes CVE-2025-22097 bsc#1241541).
  - Update
    patches.suse/efi-Don-t-map-the-entire-mokvar-table-to-determine-i.patch
    (stable-fixes CVE-2025-21872 bsc#1240323).
  - Update
    patches.suse/eth-bnxt-fix-out-of-range-access-of-vnic_info-array.patch
    (jsc#PED-11923 CVE-2025-22112 bsc#1241581).
  - Update patches.suse/exfat-fix-missing-shutdown-check.patch
    (git-fixes CVE-2025-22076 bsc#1241417).
  - Update
    patches.suse/exfat-fix-random-stack-corruption-after-get_block.patch
    (git-fixes CVE-2025-22036 bsc#1241426).
  - Update
    patches.suse/idpf-check-error-for-register_netdev-on-init.patch
    (git-fixes CVE-2025-22116 bsc#1241459).
  - Update
    patches.suse/idpf-fix-adapter-NULL-pointer-dereference-on-reboot.patch
    (git-fixes CVE-2025-22065 bsc#1241333).
  - Update
    patches.suse/ipv6-mcast-add-RCU-protection-to-mld_newpack.patch
    (git-fixes CVE-2025-21758 bsc#1238737).
  - Update
    patches.suse/media-streamzap-fix-race-between-device-disconnectio.patch
    (git-fixes CVE-2025-22027 bsc#1241369).
  - Update
    patches.suse/media-vimc-skip-.s_stream-for-stopped-entities.patch
    (git-fixes CVE-2025-22028 bsc#1241362).
  - Update
    patches.suse/mm-clear-uffd-wp-PTE-PMD-state-on-mremap.patch
    (bsc#1236648 CVE-2025-21696 bsc#1237111).
  - Update
    patches.suse/mptcp-fix-scheduling-while-atomic-in-mptcp_pm_nl_app.patch
    (git-fixes CVE-2025-21938 bsc#1240723).
  - Update
    patches.suse/msft-hv-3167-fbdev-hyperv_fb-Allow-graceful-removal-of-framebuffe.patch
    (git-fixes CVE-2025-21976 bsc#1241145).
  - Update
    patches.suse/net-9p-usbg-fix-handling-of-the-failed-kzalloc-memor.patch
    (git-fixes CVE-2024-56730 bsc#1235610).
  - Update
    patches.suse/net-Remove-RTNL-dance-for-SIOCBRADDIF-and-SIOCBRDELI.patch
    (git-fixes CVE-2025-22111 bsc#1241572).
  - Update
    patches.suse/net-ethtool-netlink-Allow-NULL-nlattrs-when-getting-.patch
    (git-fixes CVE-2025-21921 bsc#1240637).
  - Update patches.suse/net-rose-lock-the-socket-in-rose_bind.patch
    (git-fixes CVE-2025-21749 bsc#1238904).
  - Update
    patches.suse/netfilter-ipset-add-missing-range-check-in-bitmap_ip.patch
    (git-fixes CVE-2024-53141 bsc#1234381).
  - Update
    patches.suse/netfilter-nft_socket-remove-WARN_ON_ONCE-on-maximum-.patch
    (git-fixes CVE-2024-56783 bsc#1235625).
  - Update
    patches.suse/nfsd-fix-legacy-client-tracking-initialization.patch
    (git-fixes CVE-2024-58092 bsc#1241285).
  - Update
    patches.suse/nfsd-fix-management-of-listener-transports.patch
    (git-fixes CVE-2025-22024 bsc#1241348).
  - Update
    patches.suse/nfsd-put-dl_stid-if-fail-to-queue-dl_recall.patch
    (git-fixes CVE-2025-22025 bsc#1241361).
  - Update
    patches.suse/ntb_hw_switchtec-Fix-shift-out-of-bounds-in-switchte.patch
    (git-fixes CVE-2023-53034 bsc#1241341).
  - Update
    patches.suse/ocfs2-handle-a-symlink-read-error-correctly.patch
    (git-fixes CVE-2024-58001 bsc#1239079).
  - Update
    patches.suse/ovl-support-encoding-fid-from-inode-with-no-alias.patch
    (bsc#1238448 CVE-2025-21654 bsc#1236162).
  - Update
    patches.suse/powerpc-perf-Fix-ref-counting-on-the-PMU-vpa_pmu.patch
    (git-fixes CVE-2025-22094 bsc#1241512).
  - Update
    patches.suse/riscv-kvm-Fix-out-of-bounds-array-access.patch
    (jsc#PED-348 CVE-2024-53228 bsc#1235094).
  - Update
    patches.suse/rtnetlink-Allocate-vfinfo-size-for-VF-GUIDs-when-sup.patch
    (bsc#1224013 CVE-2025-22075 bsc#1241402).
  - Update
    patches.suse/sctp-add-mutual-exclusion-in-proc_sctp_do_udp_port.patch
    (git-fixes CVE-2025-22062 bsc#1241412).
  - Update
    patches.suse/thermal-int340x-Add-NULL-check-for-adev.patch
    (git-fixes CVE-2025-23136 bsc#1241357).
  - Update
    patches.suse/ublk-make-sure-ubq-canceling-is-set-when-queue-is-frozen.patch
    (git-fixes CVE-2025-22068 bsc#1241411).
  - Update patches.suse/udp-Fix-memory-accounting-leak.patch
    (git-fixes CVE-2025-22058 bsc#1241332).
  - Update
    patches.suse/usb-xhci-Apply-the-link-chain-quirk-on-NEC-isoc-endp.patch
    (git-fixes CVE-2025-22022 bsc#1241292).
  - Update patches.suse/usbnet-fix-NPE-during-rx_complete.patch
    (git-fixes CVE-2025-22050 bsc#1241441).
  - Update
    patches.suse/vhost-scsi-Fix-handling-of-multiple-calls-to-vhost_s.patch
    (git-fixes CVE-2025-22083 bsc#1241414).
  - Update
    patches.suse/w1-fix-NULL-pointer-dereference-in-probe.patch
    (git-fixes CVE-2025-22084 bsc#1241338).
  - Update
    patches.suse/wifi-ath11k-Clear-affinity-hint-before-calling-ath11.patch
    (git-fixes CVE-2025-23129 bsc#1241599).
  - Update
    patches.suse/wifi-ath11k-add-srng-lock-for-ath11k_hal_srng_-in-mo.patch
    (git-fixes CVE-2024-58096 bsc#1241344).
  - Update
    patches.suse/wifi-ath11k-fix-RCU-stall-while-reaping-monitor-dest.patch
    (git-fixes CVE-2024-58097 bsc#1241343).
  - Update
    patches.suse/wifi-ath11k-update-channel-list-in-reg-notifier-inst.patch
    (git-fixes CVE-2025-23133 bsc#1241451).
  - Update
    patches.suse/wifi-ath12k-Clear-affinity-hint-before-calling-ath12.patch
    (git-fixes CVE-2025-22128 bsc#1241598).
  - Update
    patches.suse/wifi-mt76-mt7921-fix-kernel-panic-due-to-null-pointe.patch
    (git-fixes CVE-2025-22032 bsc#1241425).
  - commit a5369e9
  - ext4: add more ext4_emergency_state() checks around sb_rdonly()
    (bsc#1242340).
  - commit e34367c
  - ext4: add ext4_emergency_state() helper function (bsc#1242340).
  - commit 2802292
  - ext4: add EXT4_FLAGS_EMERGENCY_RO bit (bsc#1242340).
  - commit 726006a
  - ext4: convert EXT4_FLAGS_* defines to enum (bsc#1242340).
  - commit a75e7cb
  - ext4: make block validity check resistent to sb bh corruption
    (bsc#1242348).
  - commit 7d22394
  - ext4: don't treat fhandle lookup of ea_inode as FS corruption
    (bsc#1242347).
  - commit ba6203b
  - jbd2: add a missing data flush during file and fs
    synchronization (bsc#1242346).
  - commit fa4ed15
  - iommu: Fix two issues in iommu_copy_struct_from_user()
    (git-fixes).
  - commit 86e4261
  - ext4: don't over-report free space or inodes in statvfs
    (bsc#1242345).
  - commit 8be4480
  - jbd2: fix off-by-one while erasing journal (bsc#1242344).
  - commit 123caf6
  - jbd2: remove wrong sb->s_sequence check (bsc#1242343).
  - commit f026605
  - ext4: add missing brelse() for bh2 in ext4_dx_add_entry()
    (bsc#1242342).
  - commit 383a1e1
  - ext4: show 'emergency_ro' when EXT4_FLAGS_EMERGENCY_RO is set
    (bsc#1242340).
  - commit d5057af
  - ext4: correct behavior under errors=remount-ro mode
    (bsc#1242337).
  - blacklist.conf: Blacklist 57e7239ce0ed
  - commit a79e7b9
  - ext4: partial zero eof block on unaligned inode size extension
    (bsc#1242336).
  - commit cacba0b
  - ext4: protect ext4_release_dquot against freezing (bsc#1242335).
  - commit 457d212
  - ext4: introduce linear search for dentries (bsc#1242334).
  - commit 58bf0d9
  - jbd2: flush filesystem device before updating tail sequence
    (bsc#1242333).
  - commit 3798ec5
  - jbd2: increase IO priority for writing revoke records
    (bsc#1242332).
  - commit a382b37
  - ext4: fix race in buffer_head read fault injection
    (bsc#1242331).
  - commit 994f6d0
  - splice: remove duplicate noinline from pipe_clear_nowait
    (bsc#1242328).
  - commit 62a8d5e
  - mm: fix filemap_get_folios_contig returning batches of identical
    folios (bsc#1242327).
  - commit 7222583
  - mm: fix error handling in __filemap_get_folio() with FGP_NOWAIT
    (bsc#1242326).
  - commit 4a38c7a
  - mm/readahead: fix large folio support in async readahead
    (bsc#1242321).
  - commit e2de4df
  - mm/filemap: don't call folio_test_locked() without a reference
    in next_uptodate_folio() (bsc#1242318).
  - commit 2a71dc7
  - mm: don't set readahead flag on a folio when lookahead_size >
    nr_to_read (bsc#1242317).
  - commit 06b8a5d
  - mm/truncate: reset xa_has_values flag on each iteration
    (bsc#1242316).
  - commit 33fa0e9
  - udf: Skip parent dir link count update if corrupted
    (bsc#1242315).
  - commit 8928a78
  - udf: Verify inode link counts before performing rename
    (bsc#1242314).
  - commit d1d387f
  - udf: Fix inode_getblk() return value (bsc#1242313).
  - commit 9d52630
  - fsnotify: fix sending inotify event with unexpected filename
    (bsc#1234198).
  - commit 4e33fd9
  - block: never reduce ra_pages in blk_apply_bdi_limits
    (bsc#1242308).
  - commit 9418247
  - isofs: fix KMSAN uninit-value bug in do_isofs_readdir()
    (bsc#1242307).
  - commit 051b9f7
  - ext4: avoid journaling sb update on error if journal is destroying (bsc#1241967).
  - commit 4c6dcbd
  - ext4: define ext4_journal_destroy wrapper (bsc#1241967).
  - commit b1ba8b2
  - mptcp: consolidate suboption status (CVE-2025-21707
    bsc#1238862).
  - commit 83b24f9
  - reenable TN3270 so that conmode=3270 keep working (bsc#1242296)
  - commit 41f697e
  - drm/mgag200: Added support for the new device G200eH5 (bsc#1242129 jsc#PED-10427)
  - commit ed5dd29
  - Documentation: Fix description format for powerpc RTAS ioctls
    (jsc#PED-4486).
  - powerpc/pseries: Include linux/types.h in papr-platform-dump.h
    (jsc#PED-4486).
  - commit 0825081
  - make use of anon_inode_getfile_fmode() (jsc#PED-4486).
  - Refresh patches.suse/powerpc-pseries-Add-a-char-driver-for-physical-attes.patch.
  - Refresh patches.suse/powerpc-pseries-Add-ibm-get-dynamic-sensor-state-RTA.patch.
  - Refresh patches.suse/powerpc-pseries-Add-ibm-set-dynamic-indicator-RTAS-c.patch.
  - Refresh patches.suse/powerpc-pseries-Add-papr-indices-char-driver-for-ibm.patch.
  - Refresh patches.suse/powerpc-pseries-Add-papr-platform-dump-character-dri.patch.
  - Refresh patches.suse/powerpc-pseries-Define-common-functions-for-RTAS-seq.patch.
  - Refresh patches.suse/powerpc-pseries-Define-papr_indices_io_block-for-pap.patch.
  - commit e8f7e0c
  - powerpc/bpf: fix JIT code size calculation of bpf trampoline
    (jsc#PED-10909 git-fixes).
  - commit e7da6dd
  - powerpc: Don't use --- in kernel logs (git-fixes).
  - commit ecb31d5
  - powerpc64/ftrace: fix clobbered r15 during livepatching
    (jsc#PED-10909 git-fixes).
  - commit a971e4a
  - mptcp: only inc MPJoinAckHMacFailure for HMAC failures
    (git-fixes).
  - commit d5bbe65
  - mptcp: fix NULL pointer in can_accept_new_subflow (git-fixes).
  - commit e4b6b25
  - mptcp: sockopt: fix getting freebind & transparent (git-fixes).
  - commit 3a57f0a
  - mptcp: sockopt: fix getting IPV6_V6ONLY (git-fixes).
  - commit 3a8bd3c
  - mptcp: Fix data stream corruption in the address announcement
    (git-fixes).
  - commit 9194c38
  - mptcp: fix 'scheduling while atomic' in
    mptcp_pm_nl_append_new_local_addr (git-fixes).
  - commit 8aeaf4b
  - mptcp: reset when MPTCP opts are dropped after join (git-fixes).
  - commit 71d9d00
  - mptcp: blackhole only if 1st SYN retrans w/o MPC is accepted
    (git-fixes).
  - commit 32e4230
  - netdev: avoid CFI problems with sock priv helpers (git-fixes).
  - commit 9750c47
  - mptcp: be sure to send ack when mptcp-level window re-opens
    (git-fixes).
  - commit 3f7ccb9
  - mptcp: sysctl: avail sched: remove write access (git-fixes).
  - commit d8519fb
  - mptcp: prevent excessive coalescing on receive (git-fixes).
  - commit 261188f
  - mptcp: don't always assume copied data in mptcp_cleanup_rbuf()
    (git-fixes).
  - commit 7d46f2f
  - Drivers: hv: Fix bad ref to hv_synic_eventring_tail when CPU
    goes offline (git-fixes).
  - tools/hv: update route parsing in kvp daemon (git-fixes).
  - Drivers: hv: Fix bad pointer dereference in hv_get_partition_id
    (git-fixes).
  - commit 72ebc30

++++ ncurses:

  - Add ncurses patch 20250503
    + update/correct some of the rv/xr strings, checked with tack -TD
    + use ansi+rca in sclp -TD
    + use vt220+pcedit in sclp (Werner Fink)
    + move some building blocks from illumos to sun-color, based on
    illumos source-history -TD
    + improve use-clauses: ansi+cup, ansi+idl1, ansi+rca, ansi+rca2,
    ansi+sgrso, ansi+sgrul -TD
    + add ecma+standout, ecma+underline -TD
    + add rv code for alacritty -TD
    + add rv/xr codes for contour, ghostty, iterm2, kitty, konsole,
    vscode, vte, wezterm -TD
  - Modify patch ncurses-5.9-ibm327x.dif
    * Reflect upstream added changes
  - Port patch ncurses-6.4.dif

++++ libvirt:

  - Update to libvirt 11.3.0
  - bsc#1241952
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v11-3-0-2025-05-02
  - spec: Build with fuse3
    boo#1242081

++++ python-charset-normalizer:

  - Update to 3.4.2
    * Addressed the DeprecationWarning in our CLI regarding `argparse.FileType`
    by backporting the target class into the package. (#591)
    * Improved the overall reliability of the detector with CJK Ideographs.
    (#605) (#587)
    * Optional mypyc compilation upgraded to version 1.15 for Python >= 3.8

++++ python-libvirt-python:

  - Update to 11.3.0
  - Add all new APIs and constants in libvirt 11.3.0

++++ toolbox:

  - Update to version 2.4+git20250429.b335d1b:
    * Support addition podman arguments

------------------------------------------------------------------
------------------  2025-5-4  -  May 4 2025  -------------------
------------------------------------------------------------------

++++ syslinux:

  - Add syslinux-4.04-gpxe-gcc15.patch to fix gcc-15 compile time
    errors during (re-)build of gpxelinux.0

------------------------------------------------------------------
------------------  2025-5-3  -  May 3 2025  -------------------
------------------------------------------------------------------

++++ kernel-firmware-mediatek:

  - Update to version 20250502 (git commit 43dfb5fb64bb):
    * linux-firmware: update firmware for MT7925 WiFi device
    * mediatek MT7925: update bluetooth firmware to 20250425073330

++++ kernel-firmware-qcom:

  - Update to version 20250502 (git commit 43dfb5fb64bb):
    * qcom: Add link for SM8350 GPU firmware

++++ kernel-firmware-realtek:

  - Update to version 20250502 (git commit 43dfb5fb64bb):
    * rtw89: 8852c: add tables for dynamic antenna TXPWR
    * rtw89: 8922a: update fw to v0.35.71.0

++++ kernel-firmware-sound:

  - Update to version 20250502 (git commit 43dfb5fb64bb):
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some Lenovo laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some ASUS laptops
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some Lenovo laptops
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some Dell laptops

++++ open-vm-tools:

  - Add open-vm-tools-12.5.0-gcc15.patch from upstream to fix
    gcc15 compile time error (boo#1241938)

------------------------------------------------------------------
------------------  2025-5-2  -  May 2 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - update to 330
    * Upgraded to Patternfly 6
  - changes from 329
    * Fix launching remote viewer
    * Translation updates

++++ cockpit-podman:

  - New version 104, updates since 102:
    * drop correct-container-search.patch: upstreamed
    * Upgraded to Patternfly 6
    * Link service containers to service pages
    * Connect to other accounts
    * Translation updates
    * Bug fixes

++++ python-kiwi:

  - Fix reencryption master key passphrase
    Make sure to use the correct passphrase for the master
    key such that it can be decrypted with the same credentials
    as before. The credentials reset is a subsequent task
    after reencryption.

++++ kernel-default:

  - scsi: megaraid_sas: Driver version update to 07.734.00.00-rc1
    (jsc#PED-11259).
  - commit c5e6340
  - scsi: megaraid_sas: Block zero-length ATA VPD inquiry
    (jsc#PED-11259).
  - commit 5d51b2e
  - scsi: megaraid_sas: Make most module parameters static
    (jsc#PED-11259).
  - commit 3864bb1
  - scsi: usb: Rename the RESERVE and RELEASE constants
    (jsc#PED-11259).
  - commit d4d26d7
  - scsi: Constify struct pci_device_id (jsc#PED-11259).
  - commit 29e45b8
  - scsi: Eliminate scsi_register() and scsi_unregister() usage &
    docs (jsc#PED-11259).
  - commit 4ca2668
  - scsi: hpsa: Replace deprecated strncpy() with strscpy_pad()
    (jsc#PED-11374).
  - commit 4f60ab0
  - scsi: hpsa: Remove deprecated and unnecessary strncpy()
    (jsc#PED-11374).
  - commit 5f4ce17
  - net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() (CVE-2025-22107 bsc#1241575)
  - commit dc509e5
  - ibmvnic: Use kernel helpers for hex dumps (CVE-2025-22104 bsc#1241550)
  - commit 850c60b
  - dm: always update the array size in realloc_argv on success
    (git-fixes).
  - commit 87e3281
  - dm-bufio: don't schedule in atomic context (git-fixes).
  - commit c14d078
  - net: use sock_gen_put() when sk_state is TCP_TIME_WAIT
    (git-fixes).
  - commit 76d8aa5
  - net: ipv6: fix UDPv6 GSO segmentation with NAT (git-fixes).
  - commit 92c5da0
  - net_sched: qfq: Fix double list add in class with netem as
    child qdisc (git-fixes).
  - commit 0d2103f
  - net_sched: ets: Fix double list add in class with netem as
    child qdisc (git-fixes).
  - commit 9b56c28
  - net_sched: hfsc: Fix a UAF vulnerability in class with netem
    as child qdisc (git-fixes).
  - commit 42d57cb
  - net_sched: drr: Fix double list add in class with netem as
    child qdisc (git-fixes).
  - commit 0f8e965
  - Bluetooth: L2CAP: copy RX timestamp to new fragments
    (git-fixes).
  - Bluetooth: btintel_pcie: Add additional to checks to clear
    TX/RX paths (git-fixes).
  - Bluetooth: btusb: avoid NULL pointer dereference in
    skb_dequeue() (git-fixes).
  - Bluetooth: btintel_pcie: Avoid redundant buffer allocation
    (git-fixes).
  - Bluetooth: hci_conn: Fix not setting timeout for BIG Create Sync
    (git-fixes).
  - Bluetooth: hci_conn: Fix not setting conn_timeout for Broadcast
    Receiver (git-fixes).
  - wifi: brcm80211: fmac: Add error handling for
    brcmf_usb_dl_writeimage() (git-fixes).
  - wifi: plfxlc: Remove erroneous assert in plfxlc_mac_release
    (git-fixes).
  - wifi: iwlwifi: fix the check for the SCRATCH register upon
    resume (git-fixes).
  - wifi: iwlwifi: don't warn if the NIC is gone in resume
    (git-fixes).
  - commit bc2d5f4

++++ kernel-rt:

  - scsi: megaraid_sas: Driver version update to 07.734.00.00-rc1
    (jsc#PED-11259).
  - commit c5e6340
  - scsi: megaraid_sas: Block zero-length ATA VPD inquiry
    (jsc#PED-11259).
  - commit 5d51b2e
  - scsi: megaraid_sas: Make most module parameters static
    (jsc#PED-11259).
  - commit 3864bb1
  - scsi: usb: Rename the RESERVE and RELEASE constants
    (jsc#PED-11259).
  - commit d4d26d7
  - scsi: Constify struct pci_device_id (jsc#PED-11259).
  - commit 29e45b8
  - scsi: Eliminate scsi_register() and scsi_unregister() usage &
    docs (jsc#PED-11259).
  - commit 4ca2668
  - scsi: hpsa: Replace deprecated strncpy() with strscpy_pad()
    (jsc#PED-11374).
  - commit 4f60ab0
  - scsi: hpsa: Remove deprecated and unnecessary strncpy()
    (jsc#PED-11374).
  - commit 5f4ce17
  - net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry() (CVE-2025-22107 bsc#1241575)
  - commit dc509e5
  - ibmvnic: Use kernel helpers for hex dumps (CVE-2025-22104 bsc#1241550)
  - commit 850c60b
  - dm: always update the array size in realloc_argv on success
    (git-fixes).
  - commit 87e3281
  - dm-bufio: don't schedule in atomic context (git-fixes).
  - commit c14d078
  - net: use sock_gen_put() when sk_state is TCP_TIME_WAIT
    (git-fixes).
  - commit 76d8aa5
  - net: ipv6: fix UDPv6 GSO segmentation with NAT (git-fixes).
  - commit 92c5da0
  - net_sched: qfq: Fix double list add in class with netem as
    child qdisc (git-fixes).
  - commit 0d2103f
  - net_sched: ets: Fix double list add in class with netem as
    child qdisc (git-fixes).
  - commit 9b56c28
  - net_sched: hfsc: Fix a UAF vulnerability in class with netem
    as child qdisc (git-fixes).
  - commit 42d57cb
  - net_sched: drr: Fix double list add in class with netem as
    child qdisc (git-fixes).
  - commit 0f8e965
  - Bluetooth: L2CAP: copy RX timestamp to new fragments
    (git-fixes).
  - Bluetooth: btintel_pcie: Add additional to checks to clear
    TX/RX paths (git-fixes).
  - Bluetooth: btusb: avoid NULL pointer dereference in
    skb_dequeue() (git-fixes).
  - Bluetooth: btintel_pcie: Avoid redundant buffer allocation
    (git-fixes).
  - Bluetooth: hci_conn: Fix not setting timeout for BIG Create Sync
    (git-fixes).
  - Bluetooth: hci_conn: Fix not setting conn_timeout for Broadcast
    Receiver (git-fixes).
  - wifi: brcm80211: fmac: Add error handling for
    brcmf_usb_dl_writeimage() (git-fixes).
  - wifi: plfxlc: Remove erroneous assert in plfxlc_mac_release
    (git-fixes).
  - wifi: iwlwifi: fix the check for the SCRATCH register upon
    resume (git-fixes).
  - wifi: iwlwifi: don't warn if the NIC is gone in resume
    (git-fixes).
  - commit bc2d5f4

++++ nvidia-open-driver-G06-signed:

  - disabled unsupported -rt flavor (bsc#1242054)

------------------------------------------------------------------
------------------  2025-5-1  -  May 1 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 28.1.1-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/28/#2811> bsc#1242114
    Includes upstream fixes:
  - CVE-2025-22872 bsc#1241830
  - Remove long-outdated build handling for deprecated and unsupported
    devicemapper and AUFS storage drivers. AUFS was removed in v24, and
    devicemapper was removed in v25.
    <https://docs.docker.com/engine/deprecated/#aufs-storage-driver>
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  - Remove upstreamed patches:
  - 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  - 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch
  - cli-0001-docs-include-required-tools-in-source-tree.patch

++++ python-kiwi:

  - Bump version: 10.2.18 → 10.2.19

------------------------------------------------------------------
------------------  2025-4-30  -  Apr 30 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fixed targettype setup in zipl.conf
    The special targettype set to GPT still indicates SCSI for
    the zipl.conf but tells kiwi to create a GPT disk layout
  - Fixed s390 integration test
    targettype attribute in wrong section
  - Add support for GPT targettype on s390
    Allow to build s390 images using GPT instead of the old DOS
    partition table. zipl has added support to read from GPT.
    This Fixes #2694
  - Add --no-compress option to bundler
    Allow to skip the compression for bundle files marked
    to become compressed. This Fixes #2736
  - Rawhide (F43) has removed basesystem package
    The basesystem package was retired with rawhide (F43).
    https://src.fedoraproject.org/rpms/filesystem/pull-request/20
  - rawhide install shadow-utils for usermod
    Using `kiwi-ng` version 10.2.18 (EL9)
    Currently with:
    ```
    sudo kiwi-ng system build \
  - -description kiwi/build-tests/x86/fedora/test-image-docker
  - -set-repo http://ftp.fau.de/fedora/linux/development/rawhide/Everything/x86_64/os/ \
  - -target-dir /tmp/myimage1
    ```
    This fails with:
    ```
    [ INFO    ]: 09:46:38 | Setting up user root
    [ INFO    ]: 09:46:38 | --> Modifying user: root
    [ INFO    ]: 09:46:38 | --> Primary group for user root: root
    [ ERROR   ]: 09:46:38 | KiwiCommandError: chroot: stderr: /sbin/chroot: failed to run command ‘usermod’: No such file or directory
    ```
    Install the package `shadow-utils` to provide `usermod`.
  - Fixed default bls value setup
    Fixed get_build_type_bootloader_bls behavior in case the bls
    attribute is not set. In this case get_bls() returns a None value
    which was returned. However in this case the attribute value
    should not be taken into account and the method defined default
    value for bls should be returned. This Fixes #2542

++++ gstreamer:

  - Update to version 1.26.1:
    + Highlighted bugfixes:
  - awstranslate and speechmatics plugin improvements
  - decodebin3 fixes and urisourcebin/playbin3 stability
    improvements
  - Closed captions: CEA-708 generation and muxing fixes, and
    H.264/H.265 caption extractor fixes
  - dav1d AV1 decoder: RGB support, plus colorimetry,
    renegotiation and buffer pool handling fixes
  - Fix regression when rendering VP9 with alpha
  - H.265 decoder base class and caption inserter SPS/PPS
    handling fixes
  - hlssink3 and hlsmultivariantsink feature enhancements
  - Matroska v4 support in muxer, seeking fixes in demuxer
  - macOS: framerate guessing for cameras or capture devices
    where the OS reports silly framerates
  - MP4 demuxer uncompressed video handling improvements and
    sample table handling fixes
  - oggdemux: seeking improvements in streaming mode
  - unixfdsrc: fix gst_memory_resize warnings
  - Plugin loader fixes, especially for Windows
  - QML6 GL source renegotiation fixes
  - RTP and RTSP stability fixes
  - Thread-safety improvements for the Media Source Extension
    (MSE) library
  - v4l2videodec: fix A/V sync issues after decoding errors
  - Various improvements and fixes for the fragmented and
    non-fragmented MP4 muxers
  - Video encoder base class segment and buffer timestamp
    handling fixes
  - Video time code support for 119.88 fps and
    drop-frames-related conversion fixes
  - WebRTC: Retransmission entry creation fixes and better audio
    level header extension compatibility
  - YUV4MPEG encoder improvments
  - dots-viewer: make work locally without network access
  - gst-python: fix compatibility with PyGObject >= 3.52.0
  - Cerbero: recipe updates, compatibility fixes for Python <
    3.10; Windows Android cross-build improvements
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - Correctly handle whitespace paths when executing
    gst-plugin-scanner
  - Ensure properties are freed before (re)setting with
    g_value_dup_string() and during cleanup
  - cmake: Fix PKG_CONFIG_PATH formatting for Windows
    cross-builds
  - macos: Move macos function documentation to the .h so the
    introspection has the information
  - meson.build: test for and link against libatomic if it exists
  - pluginloader-win32: Fix helper executable path under devenv
  - pluginloader: fix pending_plugins Glist use-after-free issue
  - unixfdsrc: Complains about resize of memory area
  - tracers: dots: fix debug log

++++ gstreamer-plugins-base:

  - Update to version 1.26.1:
    + Ensure properties are freed before (re)setting with
    g_value_dup_string() and during cleanup
    + alsadeviceprovider: Fix leak of Alsa longname
    + audioaggregator: fix error added in !8416 when chaining up
    + audiobasesink: Fix custom slaving driftsamples calculation and
    add custom audio clock slaving callback example
    + decodebin3:
  - Don't avoid parsebin even if we have a matching decoder
  - Doesn't plug parsebin for AAC from tsdemux
    + gl: eglimage: warn the reason of export failure
    + glcolorconvert:
  - Fix YUVA<->RGBA conversions
  - Regression when rendering alpha vp9
    + gldownload: Unref glcontext after usage
    + meson.build: test for and link against libatomic if it exists
    + oggdemux: Don't push new packets if there is a pending seek
    + urisourcebin:
  - Make parsebin activation more reliable
  - Deadlock between parsebin and typefind
    + videoencoder: Use the correct segment and buffer timestamp in
    the chain function
    + videotimecode: Fix conversion of timecode to datetime with
    drop-frame timecodes and handle 119.88 fps correctly in all
    places

++++ jitterentropy:

  - Update to 3.6.3: [bsc#1242050]
    * Correct time stamp processing on AIX
    * Use high-resolution time stamp on Apple Silicon
    * GCD power-up test: consider OSR
    * Remove patches fixed in the update:
  - jitterentropy-fix-a-stack-corruption-on-s390x.patch
    * Rebase patches:
  - jitterentropy-split-internal-header.patch
  - jitterentropy-with-debug.patch
  - Update to 3.6.2:
    * Fix RCT re-initialization in jent_read_entropy_safe
    * simplify test code
    * improve keyword portability
  - Update to 3.6.1:
    * Add more test code
    * Add support for SunPRO compiler
    * Fix compilation on OpenBSD by replacing sed with tr
    * internal timer: Add support for Apple
    * Various small fixes to compilation to imporve portability
  - Update to 3.6.0:
    * Remove bi-modal behavior of conditioning function
    * Make jent_read_entropy_safe safer by retrying the health test
    * Move the version information to make them available at compile time
  - Update to 3.5.0:
    * add distinction between intermittent and permanent health failure
    * add compile time option to allow configuring a mask to reduce the
    size of the time stamp used for the APT

++++ kernel-default:

  - net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
    (CVE-2025-21768 bsc#1238714).
  - commit 9b3a0ce
  - Reassign patches.suse/md-display-timeout-error.patch
  - commit 800a738
  - devtmpfs: don't use vfs_getattr_nosec to query i_mode
    (git-fixes).
  - commit 8b172cd
  - Delete patches.suse/NFS-never-reuse-a-NFSv4-0-lock-owner.patch.
    This patch was upstreamed in commit d98f72272500 ("nfs: simplify and guarantee
    owner uniqueness.") in v6.12-rc1, and as such is already part of the SL-16.0
    base.
  - commit cd65cf6
  - Refresh patches.suse/nfs-serialize-opens.patch.
  - commit ed1030a
  - Refresh
    patches.suse/NFS-Handle-missing-attributes-in-OPEN-reply.patch.
  - commit 54cd6de
  - Refresh patches.suse/nfs-access-cache-no-negative.patch.
  - commit a7a5059
  - Delete patches.suse/nfsd-dont-revoke-v4-0-states.patch.
    This patch was upstreamed in commit d688d8585e6b ("nfsd: allow admin-revoked
    NFSv4.0 state to be freed.") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit 4a72771
  - Delete
    patches.suse/nfsd-allow-delegation-state-ids-to-be-revoked-and-th.patch.
    This patch was upstreamed in commit 06efa66750a6 ("nfsd: allow delegation state
    ids to be revoked and then freed") in v6.9-rc1, and as such is already part of
    the SL-16.0 base.
  - commit eafba28
  - Delete
    patches.suse/nfsd-allow-lock-state-ids-to-be-revoked-and-then-fre.patch.
    This patch was upstreamed in commit 1c13bf9f2e3c ("nfsd: allow lock state ids
    to be revoked and then freed") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit 629688d
  - Delete
    patches.suse/nfsd-allow-open-state-ids-to-be-revoked-and-then-fre.patch.
    This patch was upstreamed in commit 39657c740644 ("nfsd: allow open state ids
    to be revoked and then freed") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit c5ad100
  - Delete
    patches.suse/nfsd-prepare-for-supporting-admin-revocation-of-stat.patch.
    This patch was upstreamed in commit 1ac3629bf012 ("nfsd: prepare for supporting
    admin-revocation of state") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit 1e7e247
  - Delete
    patches.suse/NFS-only-invalidate-dentrys-that-are-clearly-invalid.patch.
    This patch was upstreamed in commit 0c8c7c559740 ("nfs: don't invalidate
    dentries on transient errors") in v6.10-rc4, and as such is already part of the
    SL-16.0 base.
  - commit 2b97bc1
  - Refresh patches.suse/nfs-set-acl-perm.patch.
  - commit 212c3c6
  - Refresh patches.suse/mvfs-workaround.patch.
  - commit 96b23c0
  - Refresh patches.suse/NFS-flush-dirty-data-on-fput-fix.patch.
  - commit 4cff336
  - Update
    patches.suse/batman-adv-Drop-unmanaged-ELP-metric-worker.patch
    (CVE-2025-21823 bsc#1238475).
  - commit ccc0061
  - Refresh
    patches.suse/0001-NFS-flush-out-dirty-data-on-file-fput.patch.
  - commit 003497d
  - Delete
    patches.suse/NFSv3-only-use-NFS-timeout-for-MOUNT-when-protocols-.patch.
    This patch was upstreamed in commit 6e2a10343ecb ("NFSv3: only use NFS
    timeout for MOUNT when protocols are compatible") in v6.12-rc7, and as
    such is already part of the SL-16.0 base.
  - commit 9433e96
  - Update
    patches.suse/memstick-rtsx_usb_ms-Fix-slab-use-after-free-in-rtsx.patch
    (bsc#1241280 CVE-2025-22020).
    Added CVE to reference
  - commit a22621c
  - Delete
    patches.suse/kabi-placeholders-for-coco-host-support.patch.
  - commit fb7d9fc
  - btrfs: fix block group refcount race in
    btrfs_create_pending_block_groups() (bsc#1241578
    CVE-2025-22115).
  - commit 8326b59
  - Update patches.suse/KVM-PPC-Enable-CAP_SPAPR_TCE_VFIO-on-pSeries-KVM-gue.patch
    (jsc#PED-10539 git-fixes bsc#1240419 ltc#212279).
  - commit 28f1cb3
  - netfilter: nf_tables: don't unregister hook when table is
    dormant (CVE-2025-22064 bsc#1241413).
  - commit 3c1fc05
  - net: libwx: fix Tx L4 checksum (CVE-2025-22101 bsc#1241555).
  - commit ca8ce70
  - Delete
    patches.suse/bpf-selftests-adapt-bpf_iter_task_vma-to-got_inode_dev.patch.
    I no longer use openSUSE/SLES VM to run BPF selftests, and instead uses
    upstream's BPF CI to run it. Since the rootfs use is not BTRFS, this
    patch isn't needed.
  - commit b4b1b2f
  - Update references for patches.suse/atm-Fix-NULL-pointer-dereference.patch (CVE-2025-22018 bsc#1241266 git-fixes)
  - commit 6abef3a
  - bpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT (CVE-2024-58070 bsc#1238983)
  - commit 99a99f3
  - Update references for patches.suse/udp-Fix-multiple-wraparounds-of-sk-sk_rmem_alloc.patch (CVE-2025-22059 bsc#1241385 git-fixes)
  - commit 43e95fb
  - iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE (CVE-2025-21833, bsc#1239108).
  - commit 4e09108
  - Fixup unused label in patches.suse/ext4-fix-out-of-bound-read-in-ext4_xattr_inode_dec_r.patch
  - commit e7a7af8
  - arm64: allow PREEMPT_LAZY, but keep disabled (bsc#1234370).
  - commit 4aea89c
  - net: mvpp2: Prevent parser TCAM memory corruption
    (CVE-2025-22060 bsc#1241526).
  - bonding: check xdp prog when set bond mode (CVE-2025-22105
    bsc#1241548).
  - bonding: return detailed error when loading native XDP fails
    (CVE-2025-22105 bsc#1241548).
  - commit 6dae3fd
  - ALSA: ump: Fix buffer overflow at UMP SysEx message conversion
    (bsc#1242044).
  - commit a46f1d9
  - mmc: renesas_sdhi: Fix error handling in renesas_sdhi_probe
    (git-fixes).
  - platform/x86/intel-uncore-freq: Fix missing uncore sysfs during
    CPU hotplug (git-fixes).
  - commit 858bc92
  - scsi: core: Clear flags for scsi_cmnd that did not complete
    (git-fixes).
  - scsi: mpi3mr: Fix pending I/O counter (git-fixes).
  - fs: move the bdex_statx call to vfs_getattr_nosec (git-fixes).
  - block: integrity: Do not call set_page_dirty_lock() (git-fixes).
  - loop: stop using vfs_iter_{read,write} for buffered I/O
    (git-fixes).
  - loop: LOOP_SET_FD: send uevents for partitions (git-fixes).
  - loop: properly send KOBJ_CHANGED uevent for disk device
    (git-fixes).
  - block: fix resource leak in blk_register_queue() error path
    (git-fixes).
  - ublk: fix handling recovery & reissue in ublk_abort_queue()
    (git-fixes).
  - ublk: make sure ubq->canceling is set when queue is frozen
    (git-fixes).
  - block: fix adding folio to bio (git-fixes).
  - block: make sure ->nr_integrity_segments is cloned in
    blk_rq_prep_clone (git-fixes).
  - badblocks: fix missing bad blocks on retry in _badblocks_check()
    (git-fixes).
  - badblocks: fix merge issue when new badblocks align with pre+1
    (git-fixes).
  - badblocks: fix the using of MAX_BADBLOCKS (git-fixes).
  - badblocks: return error if any badblock set fails (git-fixes).
  - badblocks: return error directly when setting badblocks exceeds
    512 (git-fixes).
  - badblocks: attempt to merge adjacent badblocks during
    ack_all_badblocks (git-fixes).
  - badblocks: factor out a helper try_adjacent_combine (git-fixes).
  - badblocks: Fix error shitf ops (git-fixes).
  - block: Correctly initialize BLK_INTEGRITY_NOGENERATE and
    BLK_INTEGRITY_NOVERIFY (git-fixes).
  - block: ensure correct integrity capability propagation in
    stacked devices (git-fixes).
  - blk-throttle: fix lower bps rate by throtl_trim_slice()
    (git-fixes).
  - block: change blk_mq_add_to_batch() third argument type to bool
    (git-fixes).
  - ublk: set_params: properly check if parameters can be applied
    (git-fixes).
  - commit c655911

++++ kernel-rt:

  - net: ipv6: fix dst ref loops in rpl, seg6 and ioam6 lwtunnels
    (CVE-2025-21768 bsc#1238714).
  - commit 9b3a0ce
  - Reassign patches.suse/md-display-timeout-error.patch
  - commit 800a738
  - devtmpfs: don't use vfs_getattr_nosec to query i_mode
    (git-fixes).
  - commit 8b172cd
  - Delete patches.suse/NFS-never-reuse-a-NFSv4-0-lock-owner.patch.
    This patch was upstreamed in commit d98f72272500 ("nfs: simplify and guarantee
    owner uniqueness.") in v6.12-rc1, and as such is already part of the SL-16.0
    base.
  - commit cd65cf6
  - Refresh patches.suse/nfs-serialize-opens.patch.
  - commit ed1030a
  - Refresh
    patches.suse/NFS-Handle-missing-attributes-in-OPEN-reply.patch.
  - commit 54cd6de
  - Refresh patches.suse/nfs-access-cache-no-negative.patch.
  - commit a7a5059
  - Delete patches.suse/nfsd-dont-revoke-v4-0-states.patch.
    This patch was upstreamed in commit d688d8585e6b ("nfsd: allow admin-revoked
    NFSv4.0 state to be freed.") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit 4a72771
  - Delete
    patches.suse/nfsd-allow-delegation-state-ids-to-be-revoked-and-th.patch.
    This patch was upstreamed in commit 06efa66750a6 ("nfsd: allow delegation state
    ids to be revoked and then freed") in v6.9-rc1, and as such is already part of
    the SL-16.0 base.
  - commit eafba28
  - Delete
    patches.suse/nfsd-allow-lock-state-ids-to-be-revoked-and-then-fre.patch.
    This patch was upstreamed in commit 1c13bf9f2e3c ("nfsd: allow lock state ids
    to be revoked and then freed") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit 629688d
  - Delete
    patches.suse/nfsd-allow-open-state-ids-to-be-revoked-and-then-fre.patch.
    This patch was upstreamed in commit 39657c740644 ("nfsd: allow open state ids
    to be revoked and then freed") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit c5ad100
  - Delete
    patches.suse/nfsd-prepare-for-supporting-admin-revocation-of-stat.patch.
    This patch was upstreamed in commit 1ac3629bf012 ("nfsd: prepare for supporting
    admin-revocation of state") in v6.9-rc1, and as such is already part of the
    SL-16.0 base.
  - commit 1e7e247
  - Delete
    patches.suse/NFS-only-invalidate-dentrys-that-are-clearly-invalid.patch.
    This patch was upstreamed in commit 0c8c7c559740 ("nfs: don't invalidate
    dentries on transient errors") in v6.10-rc4, and as such is already part of the
    SL-16.0 base.
  - commit 2b97bc1
  - Refresh patches.suse/nfs-set-acl-perm.patch.
  - commit 212c3c6
  - Refresh patches.suse/mvfs-workaround.patch.
  - commit 96b23c0
  - Refresh patches.suse/NFS-flush-dirty-data-on-fput-fix.patch.
  - commit 4cff336
  - Update
    patches.suse/batman-adv-Drop-unmanaged-ELP-metric-worker.patch
    (CVE-2025-21823 bsc#1238475).
  - commit ccc0061
  - Refresh
    patches.suse/0001-NFS-flush-out-dirty-data-on-file-fput.patch.
  - commit 003497d
  - Delete
    patches.suse/NFSv3-only-use-NFS-timeout-for-MOUNT-when-protocols-.patch.
    This patch was upstreamed in commit 6e2a10343ecb ("NFSv3: only use NFS
    timeout for MOUNT when protocols are compatible") in v6.12-rc7, and as
    such is already part of the SL-16.0 base.
  - commit 9433e96
  - Update
    patches.suse/memstick-rtsx_usb_ms-Fix-slab-use-after-free-in-rtsx.patch
    (bsc#1241280 CVE-2025-22020).
    Added CVE to reference
  - commit a22621c
  - Delete
    patches.suse/kabi-placeholders-for-coco-host-support.patch.
  - commit fb7d9fc
  - btrfs: fix block group refcount race in
    btrfs_create_pending_block_groups() (bsc#1241578
    CVE-2025-22115).
  - commit 8326b59
  - Update patches.suse/KVM-PPC-Enable-CAP_SPAPR_TCE_VFIO-on-pSeries-KVM-gue.patch
    (jsc#PED-10539 git-fixes bsc#1240419 ltc#212279).
  - commit 28f1cb3
  - netfilter: nf_tables: don't unregister hook when table is
    dormant (CVE-2025-22064 bsc#1241413).
  - commit 3c1fc05
  - net: libwx: fix Tx L4 checksum (CVE-2025-22101 bsc#1241555).
  - commit ca8ce70
  - Delete
    patches.suse/bpf-selftests-adapt-bpf_iter_task_vma-to-got_inode_dev.patch.
    I no longer use openSUSE/SLES VM to run BPF selftests, and instead uses
    upstream's BPF CI to run it. Since the rootfs use is not BTRFS, this
    patch isn't needed.
  - commit b4b1b2f
  - Update references for patches.suse/atm-Fix-NULL-pointer-dereference.patch (CVE-2025-22018 bsc#1241266 git-fixes)
  - commit 6abef3a
  - bpf: bpf_local_storage: Always use bpf_mem_alloc in PREEMPT_RT (CVE-2024-58070 bsc#1238983)
  - commit 99a99f3
  - Update references for patches.suse/udp-Fix-multiple-wraparounds-of-sk-sk_rmem_alloc.patch (CVE-2025-22059 bsc#1241385 git-fixes)
  - commit 43e95fb
  - iommu/vt-d: Avoid use of NULL after WARN_ON_ONCE (CVE-2025-21833, bsc#1239108).
  - commit 4e09108
  - Fixup unused label in patches.suse/ext4-fix-out-of-bound-read-in-ext4_xattr_inode_dec_r.patch
  - commit e7a7af8
  - arm64: allow PREEMPT_LAZY, but keep disabled (bsc#1234370).
  - commit 4aea89c
  - net: mvpp2: Prevent parser TCAM memory corruption
    (CVE-2025-22060 bsc#1241526).
  - bonding: check xdp prog when set bond mode (CVE-2025-22105
    bsc#1241548).
  - bonding: return detailed error when loading native XDP fails
    (CVE-2025-22105 bsc#1241548).
  - commit 6dae3fd
  - ALSA: ump: Fix buffer overflow at UMP SysEx message conversion
    (bsc#1242044).
  - commit a46f1d9
  - mmc: renesas_sdhi: Fix error handling in renesas_sdhi_probe
    (git-fixes).
  - platform/x86/intel-uncore-freq: Fix missing uncore sysfs during
    CPU hotplug (git-fixes).
  - commit 858bc92
  - scsi: core: Clear flags for scsi_cmnd that did not complete
    (git-fixes).
  - scsi: mpi3mr: Fix pending I/O counter (git-fixes).
  - fs: move the bdex_statx call to vfs_getattr_nosec (git-fixes).
  - block: integrity: Do not call set_page_dirty_lock() (git-fixes).
  - loop: stop using vfs_iter_{read,write} for buffered I/O
    (git-fixes).
  - loop: LOOP_SET_FD: send uevents for partitions (git-fixes).
  - loop: properly send KOBJ_CHANGED uevent for disk device
    (git-fixes).
  - block: fix resource leak in blk_register_queue() error path
    (git-fixes).
  - ublk: fix handling recovery & reissue in ublk_abort_queue()
    (git-fixes).
  - ublk: make sure ubq->canceling is set when queue is frozen
    (git-fixes).
  - block: fix adding folio to bio (git-fixes).
  - block: make sure ->nr_integrity_segments is cloned in
    blk_rq_prep_clone (git-fixes).
  - badblocks: fix missing bad blocks on retry in _badblocks_check()
    (git-fixes).
  - badblocks: fix merge issue when new badblocks align with pre+1
    (git-fixes).
  - badblocks: fix the using of MAX_BADBLOCKS (git-fixes).
  - badblocks: return error if any badblock set fails (git-fixes).
  - badblocks: return error directly when setting badblocks exceeds
    512 (git-fixes).
  - badblocks: attempt to merge adjacent badblocks during
    ack_all_badblocks (git-fixes).
  - badblocks: factor out a helper try_adjacent_combine (git-fixes).
  - badblocks: Fix error shitf ops (git-fixes).
  - block: Correctly initialize BLK_INTEGRITY_NOGENERATE and
    BLK_INTEGRITY_NOVERIFY (git-fixes).
  - block: ensure correct integrity capability propagation in
    stacked devices (git-fixes).
  - blk-throttle: fix lower bps rate by throtl_trim_slice()
    (git-fixes).
  - block: change blk_mq_add_to_batch() third argument type to bool
    (git-fixes).
  - ublk: set_params: properly check if parameters can be applied
    (git-fixes).
  - commit c655911

++++ libguestfs:

  - bsc#1242082 - libguestfs: migration to fuse 3 and deprecation of
    fuse (1)
    use-fuse3-for-build.patch
  - Update to version 1.55.10 (jsc#PED-8910)
    * mltools: decouple and simplify osinfo device support checks
    * mlcustomize: disable `--inject-virtio-win osinfo`
    * mltools: Fix de-oUnit-ized tests
    * mltools: Unreference various objects
    * Revert "mltools: Unreference various objects"
    * generator: Implement struct FDevice type
    * mltools: Fix memory leak in OCaml binding of libosinfo
    * mlstdutils: Implement String.implode
    * daemon: Rewrite {pvs,vgs,lvs}-full APIs in OCaml
    * daemon: inspect: Resolve Ubuntu 22+ /dev/disk/by-id/dm-uuid-LVM-... in fstab
    * Various build improvements
    * daemon/fstrim.c: Issue sync_disks after fstri

++++ samba:

  - Update smb.conf to enable SMB3 unix extensions

++++ ncurses:

  - Modify patch ncurses-5.9-ibm327x.dif
    * sclp term: use ASCII Console key mapping and support home
    * ibm327x term: can do color and drawings but no cursor

++++ pcp:

  - Add missing dependencies for selinux-policy-targeted in
    %post for pcp-selinux (bsc#1242052)

++++ libzypp:

  - fixed build with boost 1.88.
  - XmlReader: Fix detection of bad input streams (fixes #635)
    libxml2 2.14 potentially reads the complete stream, so it may
    have the 'eof' bit set. Which is not 'good' but also not 'bad'.
  - rpm: Fix detection of %triggerscript starts (bsc#1222044)
  - RepoindexFileReader: add more <repo> related attributes a
    service may set.
    Add optional attributes gpgcheck, repo_gpgcheck, pkg_gpgcheck,
    keeppackages, gpgkey, mirrorlist, and metalink with the same
    semantic as in a .repo file.
  - version 17.36.7 (35)

++++ python-MarkupSafe:

  - Update to 3.0.2
    * Fix compatibility when __str__ returns a str subclass. #472
    * Build requires setuptools >= 70.1. #475
  - Update to 3.0.1
    * Address compiler warnings that became errors in GCC 14. #466
    * Fix compatibility with proxy objects. #467
  - Update to 3.0.0
    * Support Python 3.13 and its experimental free-threaded build. #461
    * Drop support for Python 3.7 and 3.8.
    * Use modern packaging metadata with pyproject.toml instead
    of setup.cfg. #348
    * Change distutils imports to setuptools. #399
    * Use deferred evaluation of annotations. #400
    * Update signatures for Markup methods to match str signatures.
    Use positional-only arguments. #400
    * Some str methods on Markup no longer escape their argument: strip,
    lstrip, rstrip, removeprefix, removesuffix, partition, and
    rpartition; replace only escapes its new argument. These methods
    are conceptually linked to search methods such as in, find, and
    index, which already do not escape their argument. #401
    * The __version__ attribute is deprecated. Use feature detection,
    or importlib.metadata.version("markupsafe"), instead. #402
    * Speed up escaping plain strings by 40%. #434
    * Simplify speedups implementation. #437

++++ zypper:

  - Updated translations (bsc#1230267)
  - version 1.14.89

------------------------------------------------------------------
------------------  2025-4-29  -  Apr 29 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20250429.1cad3bc:
    * Remove alias "you" (boo#1242011)

++++ busybox:

  - fix regression in hexdump that broke kernel build:
    * busybox-1.37.0-fix-regression-n2.patch
  - fix build/tests and hexdump on big endian systems (S390):
    * busybox-1.37.0-hexdump-fix-regression-for-uint16-on-big-endian-syst.patch
    * busybox-1.37.0-od-make-B-test-little-endian-only-add-variant-for-bi.patch
    * busybox-1.37.0-hexdump-add-tests-for-x-handle-little-big-endian-pro.patch

++++ cloud-regionsrv-client:

  - Update version to 10.4.0
    + Remove repositories when the package is being removed
    We do not want to leave repositories behind refering to the plugin that
    is being removed when the package gets removed (bsc#1240310, bsc#1240311)
    + Turn docker into an optional setup (jsc#PCT-560)
    Change the Requires into a Recommends and adapt the code accordingly
    + Support flexible licenses in GCE (jsc#PCT-531)
    + Drop the azure-addon package it is geting replaced by the
    license-watcher package which has a generic implementation of the
    same functionality.
    + Handle cache inconsistencies (bsc#1218345)
    + Properly handle the zypper root target argument (bsc#1240997)

++++ cockpit:

  - Update cockpit to 337
    Upstream Changes:
    337:
  - Upgraded to Patternfly 6
  - Support dnf needs-restarting
    336.2:
  - storage: Revert "Use mdraid metadata version 1.0 when in Anaconda mode"
  - Translation updates
    336.1:
  - storage: Fix passphrase remembering with "Reuse encryption"
  - Translation updates
    336:
  - storage: Implement deletion of multi-device btrfs
  - storage: Use mdraid metadata version 1.0 when in Anaconda mode
  - Add a channel capabilities system
    335:
    storage: SMART support
  - update various patches to apply on 337

++++ container-selinux:

  - Update to version 2.237.0:
    * bootc/install_t: allow transition to container_runtime_t
    * Allow containers to mask parts of their /proc

++++ hwdata:

  - Update to version 0.394:
    * Update pci and vendor ids

++++ kernel-default:

  - Delete patches.suse/scsi_probe_lun-retry-after-timeout.patch.
    Obsoleted by 987d7d3db0b9 ("scsi: core: Retry INQUIRY after timeout")
  - commit ec64964
  - ublk: refactor recovery configuration flag helpers (git-fixes).
  - Refresh
    patches.suse/ublk-fix-ublk_ch_mmap-for-64K-page-size.patch.
  - commit 0fb5300
  - Fix an incorrect Jira reference in the following patches (the correct reference
    is jsc#PED-12756):
    patches.suse/perf-amd-ibs-Add-PMU-specific-minimum-period.patch
    patches.suse/perf-amd-ibs-Add-check_period-callback.patch
    patches.suse/perf-amd-ibs-Add-support-for-OP-Load-Latency-Filtering.patch
    patches.suse/perf-amd-ibs-Ceil-sample_period-to-min_period.patch
    patches.suse/perf-amd-ibs-Don-t-allow-freq-mode-event-creation-through-config-interface.patch
    patches.suse/perf-amd-ibs-Fix-config-to-sample-period-calculation-for-OP-PMU.patch
    patches.suse/perf-amd-ibs-Fix-perf_ibs_op.cnt_mask-for-CurCnt.patch
    patches.suse/perf-amd-ibs-Prevent-leaking-sensitive-data-to-userspace.patch
    patches.suse/perf-amd-ibs-Remove-IBS_-FETCH-OP-_CONFIG_MASK-macros.patch
    patches.suse/perf-amd-ibs-Remove-pointless-sample-period-check.patch
    patches.suse/perf-amd-ibs-Update-DTLB-PageSize-decode-logic.patch
    patches.suse/perf-core-Check-sample_type-in-perf_sample_save_callchain.patch
    patches.suse/perf-core-Export-perf_exclude_event.patch
    patches.suse/perf-x86-Check-data-address-for-IBS-software-filter.patch
    patches.suse/perf-x86-Relax-privilege-filter-restriction-on-AMD-IBS.patch
  - commit 57248d9
  - Require zstd in kernel-default-devel when module compression is zstd
    To use ksym-provides tool modules need to be uncompressed.
    Without zstd at least kernel-default-base does not have provides.
    Link: https://github.com/openSUSE/rpm-config-SUSE/pull/82
  - commit a3262dd
  - net: ibmveth: make veth_pool_store stop hanging (CVE-2025-22053
    bsc#1241373).
  - commit b891bbf
  - Enable patches.suse/dm_blk_ioctl-implement-path-failover-for-SG_IO.patch (jsc#PED-12763)
    also patches.suse/dm-multipath-dont-attempt-SG_IO-on-non-SCSI-disks-.patch
    These are downstream patches for T-systems.
  - commit 51e8c0f
  - SUSE add padding for USB reset (jsc#PED-10906).
  - commit 2638f23
  - usb: ulpi: Remove unused otg_ulpi_create (jsc#PED-10906).
  - commit a3ee783
  - usb: Add base USB MCTP definitions (jsc#PED-10906).
  - commit 41d5579
  - Refreshed: clocksource: disable watchdog checks on TSC when TSC is watchdog
    (bsc#1215885).
  - commit 58f80d7
  - Reenable patches.suse/netfilter-nf_tables-fix-64-bit-load-issue-in-nft_byt.patch
    The upstream solution was supposed to be disabling multivalue access but it
    never actually happened so that we still need this fix.
  - commit e2924ba
  - Reenable and refresh
    patches.suse/net-allow-retransmitting-a-TCP-packet-if-original-is.patch.
    Unfortunately we still cannot be sure this hack is no longer needed.
  - commit 742158c
  - Delete
    patches.suse/lan78xx-Enable-LEDs-and-auto-negotiation.patch.
    An old "not yet" patch that was likely never actually submitted to upstream
    and noone seems to miss it.
  - commit d6ed239
  - usb: typec: ucsi: return CCI and message from sync_control
    callback (jsc#PED-10906).
  - commit d935e14
  - Update config files (bsc#1241057 ltc#211774).
    CONFIG_PCI_DYNAMIC_OF_NODES=n
  - commit 33d2b82
  - powerpc/boot: Fix dash warning (bsc#1215199).
  - commit c77a110
  - exec: fix the racy usage of fs_struct->in_exec (CVE-2025-22029
    bsc#1241378).
  - commit 151287d
  - x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
    (CVE-2025-22045 bsc#1241433).
  - commit 77541f2
  - book3s64/radix : Align section vmemmap start address to
    PAGE_SIZE (bsc#1238318).
  - commit 0843767
  - powerpc/boot: Check for ld-option support (bsc#1215199).
  - commit 8087188
  - typeC: kABI padding for new altmode operations (bsc#1220369).
  - commit 283e965
  - i3c: adding kABI padding (bsc#1220369).
  - commit 2d462b3
  - i2c: adding kABI paddings (bsc#1220369).
  - commit 010bc3d
  - scripts/common-functions: drop is_upstream_sha
    is_upstream_sha is a misnomer because it only guarantees that the given
    commit is in the referenced repository. It doesn't really check whether
    it is reachable from a particular remote or branch. This is not a
    problem for its only existing user because Fixes tags are referring to
    upstream commits but the naming is misleading and more importantly we do
    have a proper function for the purpose so use sha_in_upstream instead.
  - commit 5f15f6f
  - Add perf events kabi padding (kabi).
  - commit b808f4b
  - tools headers: Update the uapi/linux/perf_event.h copy with
    the kernel sources (git-fixes).
  - commit 1eecb3d
  - perf/core: Export perf_exclude_event() (jsc#PED-12549).
  - commit 30abc8e

++++ kernel-firmware-brcm:

  - Update to version 20250428 (git commit 0d104598cd5b):
    * brcm: Add NVRAM file for Radxa Rock Pi X mini PC

++++ kernel-rt:

  - Delete patches.suse/scsi_probe_lun-retry-after-timeout.patch.
    Obsoleted by 987d7d3db0b9 ("scsi: core: Retry INQUIRY after timeout")
  - commit ec64964
  - ublk: refactor recovery configuration flag helpers (git-fixes).
  - Refresh
    patches.suse/ublk-fix-ublk_ch_mmap-for-64K-page-size.patch.
  - commit 0fb5300
  - Fix an incorrect Jira reference in the following patches (the correct reference
    is jsc#PED-12756):
    patches.suse/perf-amd-ibs-Add-PMU-specific-minimum-period.patch
    patches.suse/perf-amd-ibs-Add-check_period-callback.patch
    patches.suse/perf-amd-ibs-Add-support-for-OP-Load-Latency-Filtering.patch
    patches.suse/perf-amd-ibs-Ceil-sample_period-to-min_period.patch
    patches.suse/perf-amd-ibs-Don-t-allow-freq-mode-event-creation-through-config-interface.patch
    patches.suse/perf-amd-ibs-Fix-config-to-sample-period-calculation-for-OP-PMU.patch
    patches.suse/perf-amd-ibs-Fix-perf_ibs_op.cnt_mask-for-CurCnt.patch
    patches.suse/perf-amd-ibs-Prevent-leaking-sensitive-data-to-userspace.patch
    patches.suse/perf-amd-ibs-Remove-IBS_-FETCH-OP-_CONFIG_MASK-macros.patch
    patches.suse/perf-amd-ibs-Remove-pointless-sample-period-check.patch
    patches.suse/perf-amd-ibs-Update-DTLB-PageSize-decode-logic.patch
    patches.suse/perf-core-Check-sample_type-in-perf_sample_save_callchain.patch
    patches.suse/perf-core-Export-perf_exclude_event.patch
    patches.suse/perf-x86-Check-data-address-for-IBS-software-filter.patch
    patches.suse/perf-x86-Relax-privilege-filter-restriction-on-AMD-IBS.patch
  - commit 57248d9
  - Require zstd in kernel-default-devel when module compression is zstd
    To use ksym-provides tool modules need to be uncompressed.
    Without zstd at least kernel-default-base does not have provides.
    Link: https://github.com/openSUSE/rpm-config-SUSE/pull/82
  - commit a3262dd
  - net: ibmveth: make veth_pool_store stop hanging (CVE-2025-22053
    bsc#1241373).
  - commit b891bbf
  - Enable patches.suse/dm_blk_ioctl-implement-path-failover-for-SG_IO.patch (jsc#PED-12763)
    also patches.suse/dm-multipath-dont-attempt-SG_IO-on-non-SCSI-disks-.patch
    These are downstream patches for T-systems.
  - commit 51e8c0f
  - SUSE add padding for USB reset (jsc#PED-10906).
  - commit 2638f23
  - usb: ulpi: Remove unused otg_ulpi_create (jsc#PED-10906).
  - commit a3ee783
  - usb: Add base USB MCTP definitions (jsc#PED-10906).
  - commit 41d5579
  - Refreshed: clocksource: disable watchdog checks on TSC when TSC is watchdog
    (bsc#1215885).
  - commit 58f80d7
  - Reenable patches.suse/netfilter-nf_tables-fix-64-bit-load-issue-in-nft_byt.patch
    The upstream solution was supposed to be disabling multivalue access but it
    never actually happened so that we still need this fix.
  - commit e2924ba
  - Reenable and refresh
    patches.suse/net-allow-retransmitting-a-TCP-packet-if-original-is.patch.
    Unfortunately we still cannot be sure this hack is no longer needed.
  - commit 742158c
  - Delete
    patches.suse/lan78xx-Enable-LEDs-and-auto-negotiation.patch.
    An old "not yet" patch that was likely never actually submitted to upstream
    and noone seems to miss it.
  - commit d6ed239
  - usb: typec: ucsi: return CCI and message from sync_control
    callback (jsc#PED-10906).
  - commit d935e14
  - Update config files (bsc#1241057 ltc#211774).
    CONFIG_PCI_DYNAMIC_OF_NODES=n
  - commit 33d2b82
  - powerpc/boot: Fix dash warning (bsc#1215199).
  - commit c77a110
  - exec: fix the racy usage of fs_struct->in_exec (CVE-2025-22029
    bsc#1241378).
  - commit 151287d
  - x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
    (CVE-2025-22045 bsc#1241433).
  - commit 77541f2
  - book3s64/radix : Align section vmemmap start address to
    PAGE_SIZE (bsc#1238318).
  - commit 0843767
  - powerpc/boot: Check for ld-option support (bsc#1215199).
  - commit 8087188
  - typeC: kABI padding for new altmode operations (bsc#1220369).
  - commit 283e965
  - i3c: adding kABI padding (bsc#1220369).
  - commit 2d462b3
  - i2c: adding kABI paddings (bsc#1220369).
  - commit 010bc3d
  - scripts/common-functions: drop is_upstream_sha
    is_upstream_sha is a misnomer because it only guarantees that the given
    commit is in the referenced repository. It doesn't really check whether
    it is reachable from a particular remote or branch. This is not a
    problem for its only existing user because Fixes tags are referring to
    upstream commits but the naming is misleading and more importantly we do
    have a proper function for the purpose so use sha_in_upstream instead.
  - commit 5f15f6f
  - Add perf events kabi padding (kabi).
  - commit b808f4b
  - tools headers: Update the uapi/linux/perf_event.h copy with
    the kernel sources (git-fixes).
  - commit 1eecb3d
  - perf/core: Export perf_exclude_event() (jsc#PED-12549).
  - commit 30abc8e

++++ libsoup:

  - Add libsoup-CVE-2025-32907.patch: correct merge of ranges
    (boo#1241222 CVE-2025-32907 glgo#GNOME/libsoup!452).

++++ runc:

  - Update to runc v1.3.0. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.3.0>

++++ selinux-policy:

  - Update to version 20241031+git575.74e21c8b:
    * Allow cluster_t use NoNewPrivileges systemd hardening (bsc#1241921)

------------------------------------------------------------------
------------------  2025-4-28  -  Apr 28 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Update to version 2.35
    * Make s390 3215 console work that is use EPOLLOUT|EPOLLONESHOT
    to control if we can write to ttyS0 in nonblocking mode and if
    not reenable EPOLLOUT|EPOLLONESHOT.
    * At boot set for ttyS0 via vmcp API nonblocking MORE mode with
    `0 0'.  It beeps but boots.
  - Remove patches now upstream
    * blog-3215.patch
    * blog-install.patch

++++ cockpit:

  - Update 0007-Remove-DynamicUser-setting-as-these-conflict-with-re.patch
    Update the patch to set ProtectHome and PrivateTmp to yes as it is implied
    when DynamicUser is enabled. The patch is also now only applied on leap 15
    where it is relevant

++++ docker:

  - Update to docker-buildx v0.23.0. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.23.0>

++++ python-kiwi:

  - Bump version: 10.2.17 → 10.2.18
  - Fix setup of use_disk_password for random secret
    When using luks="random" in combination with use_disk_password="true"
    the resulting cryptomount call in grub is wrong. This commit fixes it

++++ gnutls:

  - Fix FIPS mode running on Tumbleweed [bsc#1237101]
    * When nettle or libhogweed are installed with glbic-hwcaps for x86_64-v3,
    some paths differ and we are unable to match the hmac file for the lib.
    * Add gnutls-FIPS-HMAC-x86_64-v3-opt.patch

++++ iptables:

  - Provide ebtables for SLES16

++++ kernel-default:

  - perf/amd/ibs: Update DTLB/PageSize decode logic (jsc#PED-12549).
  - perf/amd/ibs: Add support for OP Load Latency Filtering
    (jsc#PED-12549).
  - perf/amd/ibs: Ceil sample_period to min_period (jsc#PED-12549).
  - perf/amd/ibs: Add ->check_period() callback (jsc#PED-12549).
  - perf/amd/ibs: Add PMU specific minimum period (jsc#PED-12549).
  - perf/amd/ibs: Don't allow freq mode event creation through
  - >config interface (jsc#PED-12549).
  - perf/amd/ibs: Fix perf_ibs_op.cnt_mask for CurCnt
    (jsc#PED-12549).
  - perf/amd/ibs: Fix ->config to sample period calculation for
    OP PMU (jsc#PED-12549).
  - perf/amd/ibs: Remove pointless sample period check
    (jsc#PED-12549).
  - perf/amd/ibs: Remove IBS_{FETCH|OP}_CONFIG_MASK macros
    (jsc#PED-12549).
  - perf/amd/ibs: Prevent leaking sensitive data to userspace
    (jsc#PED-12549).
  - perf/x86: Check data address for IBS software filter
    (jsc#PED-12549).
  - perf/x86: Relax privilege filter restriction on AMD IBS
    (jsc#PED-12549).
  - perf/core: Check sample_type in perf_sample_save_callchain
    (jsc#PED-12549).
  - commit 02c932c
  - Delete patches.suse/perf-local-check-alloc-histogram-return.patch.
    Patch was inherited from SP6 where it required a local fix which
    is no longer needed.
  - commit 0c4313d
  - scripts/check-kernel-fix: warn about all invalid shas for CVE
    There might be stable tree specific CVEs (e.g. CVE-2025-40364) which are
    referring to non-upstream (i.e. stable tree) commits. If we encounter
    such a CVE we simply bail out because we do not expect that a CVE would
    be mixing stable specific and upstream commits. If we ever have a case
    like that it would be good to learn about the fact and find out more
    about the reasoning. Therefore turn the hard failure into a warning and
    examine all commit associated with the CVE.
  - commit b0969e1
  - kabi/severities: exclude CXL (jsc#PED-12211)
  - commit 963a5c7
  - nvmet: pci-epf: Always configure BAR0 as 64-bit (jsc#PED-9651).
  - commit 1bd69f0
  - supported.conf: Mark HiSilicon I2C and GPIO modules as supported (jsc#PED-12808)
    Those two modules are needed for HiSilicon Kunpeng SoC.
  - commit acc31d6
  - supported.conf: Mark HiSilicon crypto ZIP, HPRE and SEC as supported (jsc#PED-12808)
  - commit a59b2d2
  - supported.conf: Mark HiSi PMU drivers as supported (jsc#PED-12808)
  - supported.conf:
  - drivers/perf/hisilicon/hisi_pcie_pmu
  - drivers/perf/hisilicon/hns3_pmu
    Those two will be handled by drivers/perf/hisilicon/*
  - commit c220da8
  - supported.conf: Mark HiSi DMA controller as supported (jsc#PED-12808)
  - supported.conf:
    + drivers/dma/hisi_dma
  - commit ab21278
  - supported.conf: Mark HiSi TRNG v2 as supported (jsc#PED-12808)
  - supported.conf:
  - drivers/char/hw_random/hisi-trng-v2
    + drivers/crypto/hisilicon/trng/hisi-trng-v2
  - commit 02dc142
  - scripts/check-kernel-fix: make branch_file local
  - scripts/common-functions: make branch_file local
    it doesn't have a global scope
  - commit 57f575c
  - supported.conf: Enable HiSi accel VFIO PCI (jsc#PED-12808)
  - supported.conf:
    + drivers/vfio/pci/hisilicon/hisi_acc_vfio_pci
  - commit f5abe63
  - supported.conf: Enable SPI DW mmio driver (jsc#PED-12808)
  - supported.conf
    + drivers/spi/spi-dw
    + drivers/spi/spi-dw-mmio
  - commit 11a0f85
  - nvmet: fix out-of-bounds access in nvmet_enable_port
    (jsc#PED-9651).
  - nvmet: pci-epf: cleanup link state management (jsc#PED-9651).
  - commit 6121ef2
  - nvmet: pci-epf: clear CC and CSTS when disabling the controller
    (jsc#PED-9651).
  - nvmet: pci-epf: always fully initialize completion entries
    (jsc#PED-9651).
  - nvmet: auth: use NULL to clear a pointer in nvmet_auth_sq_free()
    (jsc#PED-9651).
  - nvme-multipath: sysfs links may not be created for devices
    (jsc#PED-9651).
  - nvme: fixup scan failure for non-ANA multipath controllers
    (jsc#PED-9651).
  - commit 57152f2
  - nvmet-fc: put ref when assoc->del_work is already scheduled
    (jsc#PED-9651).
  - nvmet-fc: take tgtport reference only once (jsc#PED-9651).
  - nvmet-fc: update tgtport ref per assoc (jsc#PED-9651).
  - nvmet-fc: inline nvmet_fc_free_hostport (jsc#PED-9651).
  - nvmet-fc: inline nvmet_fc_delete_assoc (jsc#PED-9651).
  - nvmet-fcloop: add ref counting to lport (jsc#PED-9651).
  - commit ebd7542
  - nvmet-fcloop: replace kref with refcount (jsc#PED-9651).
  - nvme-tcp: fix use-after-free of netns by kernel TCP socket
    (jsc#PED-9651).
  - nvme: multipath: fix return value of nvme_available_path
    (jsc#PED-9651).
  - nvme: re-read ANA log page after ns scan completes
    (jsc#PED-9651).
  - nvme: requeue namespace scan on missed AENs (jsc#PED-9651).
  - commit 9484ecd
  - nvme-multipath: change the NVME_MULTIPATH config option
    (jsc#PED-9651).
  - nvme: update the multipath warning in nvme_init_ns_head
    (jsc#PED-9651).
  - nvme/ioctl: move fixed buffer lookup to nvme_uring_cmd_io()
    (jsc#PED-9651).
  - nvme/ioctl: move blk_mq_free_request() out of
    nvme_map_user_request() (jsc#PED-9651).
  - nvmet: pci-epf: Keep completion queues mapped (jsc#PED-9651).
  - nvme: convert timeouts to secs_to_jiffies() (jsc#PED-9651).
  - commit b857496
  - nvme-multipath: Add visibility for queue-depth io-policy
    (jsc#PED-9651).
  - nvme-multipath: Add visibility for numa io-policy
    (jsc#PED-9651).
  - nvme-multipath: Add visibility for round-robin io-policy
    (jsc#PED-9651).
  - nvmet: add tls_concat and tls_key debugfs entries
    (jsc#PED-9651).
  - nvmet-tcp: support secure channel concatenation (jsc#PED-9651).
  - commit 9372a5d
  - nvmet: Add 'sq' argument to alloc_ctrl_args (jsc#PED-9651).
  - nvme-fabrics: reset admin connection for secure concatenation
    (jsc#PED-9651).
  - nvme-tcp: request secure channel concatenation (jsc#PED-9651).
  - Refresh patches.suse/nvme-tcp-add-recovery_delay-to-sysfs.patch.
  - nvme-keyring: add nvme_tls_psk_refresh() (jsc#PED-9651).
  - nvme: add nvme_auth_derive_tls_psk() (jsc#PED-9651).
  - commit 0753eb8
  - nvme: add nvme_auth_generate_digest() (jsc#PED-9651).
  - nvme: add nvme_auth_generate_psk() (jsc#PED-9651).
  - crypto,fs: Separate out hkdf_extract() and hkdf_expand()
    (jsc#PED-9651).
  - block: remove unused parameter 'q' parameter in
    __blk_rq_map_sg() (jsc#PED-9651).
  - nvmet: pci-epf: Do not add an IRQ vector if not needed
    (jsc#PED-9651).
  - commit 1de7609
  - nvmet: pci-epf: Set NVMET_PCI_EPF_Q_LIVE when a queue is fully
    created (jsc#PED-9651).
  - nvme-pci: fix stuck reset on concurrent DPC and HP
    (jsc#PED-9651).
  - block: change blk_mq_add_to_batch() third argument type to bool
    (jsc#PED-9651).
  - nvme-pci: skip CMB blocks incompatible with PCI P2P DMA
    (jsc#PED-9651).
  - nvme-pci: clean up CMBMSC when registering CMB fails
    (jsc#PED-9651).
  - commit 7bcdfba
  - nvme-tcp: fix possible UAF in nvme_tcp_poll (jsc#PED-9651).
  - nvmet: Use enum definitions instead of hardcoded values
    (jsc#PED-9651).
  - nvme: Cleanup the definition of the controller config
    (jsc#PED-9651).
  - nvmet: pci-epf: Avoid RCU stalls under heavy workload
    (jsc#PED-9651).
  - nvmet: pci-epf: Do not uselessly write the CSTS register
    (jsc#PED-9651).
  - nvmet: pci-epf: Correctly initialize CSTS when enabling the
    controller (jsc#PED-9651).
  - commit 2ee3668
  - nvmet: add a missing endianess conversion in
    nvmet_execute_admin_connect (jsc#PED-9651).
  - nvmet: the result field in nvmet_alloc_ctrl_args is little
    endian (jsc#PED-9651).
  - nvmet: fix a memory leak in controller identify (jsc#PED-9651).
  - nvme-pci: remove redundant dma frees in hmb (jsc#PED-9651).
  - nvmet: fix rw control endian access (jsc#PED-9651).
  - commit b37065f
  - nvme-pci: use correct size to free the hmb buffer
    (jsc#PED-9651).
  - nvme-pci: fix comment typo (jsc#PED-9651).
  - nvmet: New NVMe PCI endpoint function target driver
    (jsc#PED-9651).
  - Update config files.
  - nvmet: Implement arbitration feature support (jsc#PED-9651).
  - nvmet: Implement interrupt config feature support
    (jsc#PED-9651).
  - commit 355e9de
  - nvmet: Implement interrupt coalescing feature support
    (jsc#PED-9651).
  - nvmet: Implement host identifier set feature support
    (jsc#PED-9651).
  - nvmet: Introduce get/set_feature controller operations
    (jsc#PED-9651).
  - nvmet: Do not require SGL for PCI target controller commands
    (jsc#PED-9651).
  - nvmet: Add support for I/O queue management admin commands
    (jsc#PED-9651).
  - nvmet: Introduce nvmet_sq_create() and nvmet_cq_create()
    (jsc#PED-9651).
  - commit 3aebe42
  - nvmet: Introduce nvmet_req_transfer_len() (jsc#PED-9651).
  - nvmet: Improve nvmet_alloc_ctrl() interface and implementation
    (jsc#PED-9651).
  - nvme: Add PCI transport type (jsc#PED-9651).
  - nvmet: Add drvdata field to struct nvmet_ctrl (jsc#PED-9651).
  - nvmet: Introduce nvmet_get_cmd_effects_admin() (jsc#PED-9651).
  - commit 7f723e1
  - nvmet: Export nvmet_update_cc() and nvmet_cc_xxx() helpers
    (jsc#PED-9651).
  - nvmet: Add vendor_id and subsys_vendor_id subsystem attributes
    (jsc#PED-9651).
  - nvme: Move opcode string helper functions declarations
    (jsc#PED-9651).
  - nvme: change return type of nvme_poll_cq() to bool
    (jsc#PED-9651).
  - nvmet: handle rw's limited retry flag (jsc#PED-9651).
  - commit 6e3ff3c
  - nvme-tcp: remove nvme_tcp_destroy_io_queues() (jsc#PED-9651).
  - nvme: use blk_validate_block_size() for max LBA check
    (jsc#PED-9651).
  - nvme-tcp: simplify nvme_tcp_teardown_io_queues() (jsc#PED-9651).
  - nvme-tcp: no need to quiesce admin_q in
    nvme_tcp_teardown_io_queues() (jsc#PED-9651).
  - nvme-pci: don't use dma_alloc_noncontiguous with 0 merge
    boundary (jsc#PED-9651).
  - commit bc8ad33
  - nvmet: replace kmalloc + memset with kzalloc for data allocation
    (jsc#PED-9651).
  - nvme-pci: remove two deallocate zeroes quirks (jsc#PED-9651).
  - nvmet: use kzalloc instead of ZERO_PAGE in
    nvme_execute_identify_ns_nvm() (jsc#PED-9651).
  - nvme: tuning pr code by using defined structs and macros
    (jsc#PED-9651).
  - nvme: introduce change ptpl and iekey definition (jsc#PED-9651).
  - nvme: define the remaining used sgls constants (jsc#PED-9651).
  - commit cc50dac
  - nvmet: add tracing of reservation commands (jsc#PED-9651).
  - nvme: parse reservation commands's action and rtype to string
    (jsc#PED-9651).
  - nvmet: report ns's vwc not present (jsc#PED-9651).
  - nvme: check ns's volatile write cache not present
    (jsc#PED-9651).
  - nvme: add rotational support (jsc#PED-9651).
  - commit 6d72f74
  - nvme: use command set independent id ns if available
    (jsc#PED-9651).
  - nvmet: support for csi identify ns (jsc#PED-9651).
  - nvmet: implement rotational media information log
    (jsc#PED-9651).
  - nvmet: implement endurance groups (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - nvmet: declare 2.1 version compliance (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - nvmet: implement crto property (jsc#PED-9651).
  - commit a9d87e8
  - nvmet: implement supported features log (jsc#PED-9651).
  - nvmet: implement supported log pages (jsc#PED-9651).
  - nvmet: implement active command set ns list (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - nvmet: implement id ns for nvm command set (jsc#PED-9651).
  - nvmet: support reservation feature (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-Fix-crash-when-a-namespace-is-disabled.patch.
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - commit 88ed9df
  - nvme: add reservation command's defines (jsc#PED-9651).
  - nvme-core: remove repeated wq flags (jsc#PED-9651).
  - commit 1ad47bf
  - nvmet: make nvmet_wq visible in sysfs (jsc#PED-9651).
  - commit 6767401
  - nvme-pci: use dma_alloc_noncontigous if possible (jsc#PED-9651).
  - Refresh
    patches.suse/nvme-pci-add-support-for-sgl-metadata.patch.
  - commit 26b5396
  - nvme-multipath: don't bother clearing max_hw_zone_append_sectors
    (jsc#PED-9651).
  - commit bbefc23
  - iommu/amd: Fix header file (jsc#PED-12548).
  - iommu/amd: Preserve default DTE fields when updating Host Page
    Table Root (jsc#PED-12548).
  - commit e9648a6
  - net/mlx5: Move ttc allocation after switch case to prevent leaks
    (git-fixes).
  - net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
    (git-fixes).
  - netlink: specs: rt-link: adjust mctp attribute naming
    (git-fixes).
  - netlink: specs: rtnetlink: attribute naming corrections
    (git-fixes).
  - netlink: specs: rt-link: add an attr layer around alt-ifname
    (git-fixes).
  - cxgb4: fix memory leak in cxgb4_init_ethtool_filters() error
    path (git-fixes).
  - eth: bnxt: fix missing ring index trim on error path
    (git-fixes).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors (git-fixes).
  - igc: add lock preventing multiple simultaneous PTM transactions
    (git-fixes).
  - igc: cleanup PTP module if probe fails (git-fixes).
  - igc: handle the IGC_PTP_ENABLED flag correctly (git-fixes).
  - igc: move ktime snapshot into PTM retry loop (git-fixes).
  - igc: increase wait time before retrying PTM (git-fixes).
  - igc: fix PTM cycle trigger logic (git-fixes).
  - netlink: specs: ovs_vport: align with C codegen capabilities
    (git-fixes).
  - octeontx2-pf: qos: fix VF root node parent queue index
    (git-fixes).
  - idpf: fix adapter NULL pointer dereference on reboot
    (git-fixes).
  - ixgbe: fix media type detection for E610 device (git-fixes).
  - e1000e: change k1 configuration on MTP and later platforms
    (git-fixes).
  - igc: Fix XSK queue NAPI ID mapping (git-fixes).
  - sfc: fix NULL dereferences in ef100_process_design_param()
    (git-fixes).
  - gve: handle overflow when reporting TX consumed descriptors
    (git-fixes).
  - net/mlx5e: SHAMPO, Make reserved size independent of page size
    (git-fixes).
  - vdpa/mlx5: Fix oversized null mkey longer than 32bit
    (git-fixes).
  - idpf: check error for register_netdev() on init (git-fixes).
  - ice: fix using untrusted value of pkt_len in
    ice_vc_fdir_parse_raw() (CVE-2025-22117 bsc#1241633).
  - ice: fix input validation for virtchnl BW (git-fixes).
  - ice: validate queue quanta parameters to prevent OOB access
    (CVE-2025-22118 bsc#1241562).
  - ice: stop truncating queue ids when checking (git-fixes).
  - virtchnl: make proto and filter action count unsigned
    (git-fixes).
  - ice: fix reservation of resources for RDMA when disabled
    (git-fixes).
  - ice: ensure periodic output start time is in the future
    (git-fixes).
  - net/mlx5: Start health poll after enable hca (git-fixes).
  - net/mlx5: LAG, reload representors on LAG creation failure
    (git-fixes).
  - bnxt_en: Linearize TX SKB if the fragments exceed the max
    (git-fixes).
  - bnxt_en: Mask the bd_cnt field in the TX BD properly
    (git-fixes).
  - net/mlx5e: Fix ethtool -N flow-type ip4 to RSS context
    (git-fixes).
  - gve: unlink old napi only if page pool exists (git-fixes).
  - igb: reject invalid external timestamp requests for 82580-based
    HW (git-fixes).
  - bonding: fix incorrect MAC address setting to receive NS
    messages (git-fixes).
  - net/mlx5: Fill out devlink dev info only for PFs (git-fixes).
  - cxgb4: Avoid removal of uninserted tid (git-fixes).
  - Revert "rtnetlink: add guard for RTNL" (git-fixes).
  - commit 1c6076b
  - ext4: avoid remount errors with 'abort' mount option
    (bsc#1241673).
  - commit 7e45d00
  - ext4: fix OOB read when checking dotdot dir (bsc#1241640
    CVE-2025-37785).
  - commit 1f644d1
  - ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()
    (bsc#1241593 CVE-2025-22121).
  - commit 31cdb6e
  - proc: fix UAF in proc_get_inode() (bsc#1240802 CVE-2025-21999).
  - commit 17ecba0
  - fs: relax assertions on failure to encode file handles
    (bsc#1236086 CVE-2024-57924).
  - commit 7fa3943
  - Revert "readahead: properly shorten readahead when falling
    back to do_page_cache_ra()" (bsc#1235799 CVE-2024-57839).
  - commit 6921c3b
  - isofs: avoid memory leak in iocharset (bsc#1234965
    CVE-2024-56534).
  - commit 2bb1019
  - quota: flush quota_release_work upon quota writeback
    (bsc#1235650 CVE-2024-56780).
  - commit 9807ea9
  - fsnotify: Fix ordering of iput() and watched_objects decrement
    (bsc#1234316 CVE-2024-53143).
  - commit 80f01f0
  - dm-integrity: Do not emit journal configuration in DM table
    fro Inline mode (jsc#PED-9651).
  - dm-crypt: don't initialize cc_sector again (jsc#PED-9651).
  - dm-crypt: use bi_sector in bio when initialize integrity seed
    (jsc#PED-9651).
  - dm-crypt: fully initialize clone->bi_iter in
    crypt_alloc_buffer() (jsc#PED-9651).
  - dm-crypt: set atomic as false when calling crypt_convert()
    in kworker (jsc#PED-9651).
  - dm-mirror: Support atomic writes (jsc#PED-9651).
  - dm-io: Warn on creating multiple atomic write bios for a region
    (jsc#PED-9651).
  - dm-stripe: Enable atomic writes (jsc#PED-9651).
  - dm-linear: Enable atomic writes (jsc#PED-9651).
  - dm: Ensure cloned bio is same length for atomic write
    (jsc#PED-9651).
  - dm-table: atomic writes support (jsc#PED-9651).
  - dm-transaction-manager: use red-black trees instead of linear
    lists (jsc#PED-9651).
  - dm: disable REQ_NOWAIT for flushes (jsc#PED-9651).
  - dm: remove useless test in alloc_multiple_bios (jsc#PED-9651).
  - dm: change kzalloc to kcalloc (jsc#PED-9651).
  - dm raid: fix spelling errors in raid_ctr() (jsc#PED-9651).
  - dm-verity FEC: Avoid copying RS parity bytes twice
    (jsc#PED-9651).
  - dm-verity: remove the unused "data_start" variable
    (jsc#PED-9651).
  - dm-bufio: use kmalloc to allocate power-of-two sized buffers
    (jsc#PED-9651).
  - dm: add support for get_unique_id (jsc#PED-9651).
  - dm vdo: fix function doc comment formatting (jsc#PED-9651).
  - dm vdo int-map: remove unused parameters (jsc#PED-9651).
  - dm-vdo: reset bi_ioprio to the default value when the bio is
    reset (jsc#PED-9651).
  - dm-vdo murmurhash: remove u64 alignment requirement
    (jsc#PED-9651).
  - dm ioctl: rate limit a couple of ioctl based error messages
    (jsc#PED-9651).
  - dm vdo: Remove unused uds_compute_index_size (jsc#PED-9651).
  - dm vdo: Remove unused functions (jsc#PED-9651).
  - dm: zoned: Remove unused functions (jsc#PED-9651).
  - dm: Remove unused dm_table_bio_based (jsc#PED-9651).
  - dm: Remove unused dm_set_md_type (jsc#PED-9651).
  - dm cache: Remove unused functions in bio-prison-v1
    (jsc#PED-9651).
  - dm cache: Remove unused dm_cache_size (jsc#PED-9651).
  - dm cache: Remove unused dm_cache_dump (jsc#PED-9651).
  - dm cache: Remove unused btracker_nr_writebacks_queued
    (jsc#PED-9651).
  - commit abbc785
  - iommu/amd: Enable support for up to 2K interrupts per function
    (jsc#PED-12548).
  - iommu/amd: Rename DTE_INTTABLEN* and MAX_IRQS_PER_TABLE macro
    (jsc#PED-12548).
  - iommu/amd: Replace slab cache allocator with page allocator
    (jsc#PED-12548).
  - iommu/amd: Introduce generic function to set multibit feature
    value (jsc#PED-12548).
  - iommu/amd: Remove amd_iommu_apply_erratum_63() (jsc#PED-12548).
  - iommu/amd: Lock DTE before updating the entry with WRITE_ONCE()
    (jsc#PED-12548).
  - iommu/amd: Modify clear_dte_entry() to avoid in-place update
    (jsc#PED-12548).
  - iommu/amd: Introduce helper function get_dte256()
    (jsc#PED-12548).
  - iommu/amd: Modify set_dte_entry() to use 256-bit DTE helpers
    (jsc#PED-12548).
  - iommu/amd: Introduce helper function to update 256-bit DTE
    (jsc#PED-12548).
  - iommu/amd: Introduce struct ivhd_dte_flags to store persistent
    DTE flags (jsc#PED-12548).
  - iommu/amd: Disable AMD IOMMU if CMPXCHG16B feature is not
    supported (jsc#PED-12548).
  - iommu/amd: Misc ACPI IVRS debug info clean up (jsc#PED-12548).
  - commit cea8105
  - Update patches.suse/powerpc64-ftrace-fix-module-loading-without-patchabl.patch
    (jsc#PED-10909 git-fixes bsc#1236402).
  - commit 851952d
  - Delete patches.suse/dm-mpath-leastpending-path-update.
  - commit 2fdb1ca
  - Delete
    patches.suse/nvme_core-scan-namespaces-asynchronously.patch.
  - commit b9417d4
  - Delete
    patches.suse/nvme-multipath-suppress-partition-scan-until-the-dis.patch.
  - commit e258b74
  - Delete
    patches.suse/nvme-keyring-restrict-match-length-for-version-1-ide.patch.
  - commit 9af6fe5

++++ kernel-firmware-bluetooth:

  - Update to version 20250425 (git commit 8d82acd29b5c):
    * rtl_bt: Update RTL8852B BT USB FW to 0x098B_154B

++++ kernel-firmware-i915:

  - Update to version 20250425 (git commit 8d82acd29b5c):
    * i915: Update Xe3LPD DMC to v2.23

++++ kernel-rt:

  - perf/amd/ibs: Update DTLB/PageSize decode logic (jsc#PED-12549).
  - perf/amd/ibs: Add support for OP Load Latency Filtering
    (jsc#PED-12549).
  - perf/amd/ibs: Ceil sample_period to min_period (jsc#PED-12549).
  - perf/amd/ibs: Add ->check_period() callback (jsc#PED-12549).
  - perf/amd/ibs: Add PMU specific minimum period (jsc#PED-12549).
  - perf/amd/ibs: Don't allow freq mode event creation through
  - >config interface (jsc#PED-12549).
  - perf/amd/ibs: Fix perf_ibs_op.cnt_mask for CurCnt
    (jsc#PED-12549).
  - perf/amd/ibs: Fix ->config to sample period calculation for
    OP PMU (jsc#PED-12549).
  - perf/amd/ibs: Remove pointless sample period check
    (jsc#PED-12549).
  - perf/amd/ibs: Remove IBS_{FETCH|OP}_CONFIG_MASK macros
    (jsc#PED-12549).
  - perf/amd/ibs: Prevent leaking sensitive data to userspace
    (jsc#PED-12549).
  - perf/x86: Check data address for IBS software filter
    (jsc#PED-12549).
  - perf/x86: Relax privilege filter restriction on AMD IBS
    (jsc#PED-12549).
  - perf/core: Check sample_type in perf_sample_save_callchain
    (jsc#PED-12549).
  - commit 02c932c
  - Delete patches.suse/perf-local-check-alloc-histogram-return.patch.
    Patch was inherited from SP6 where it required a local fix which
    is no longer needed.
  - commit 0c4313d
  - scripts/check-kernel-fix: warn about all invalid shas for CVE
    There might be stable tree specific CVEs (e.g. CVE-2025-40364) which are
    referring to non-upstream (i.e. stable tree) commits. If we encounter
    such a CVE we simply bail out because we do not expect that a CVE would
    be mixing stable specific and upstream commits. If we ever have a case
    like that it would be good to learn about the fact and find out more
    about the reasoning. Therefore turn the hard failure into a warning and
    examine all commit associated with the CVE.
  - commit b0969e1
  - kabi/severities: exclude CXL (jsc#PED-12211)
  - commit 963a5c7
  - nvmet: pci-epf: Always configure BAR0 as 64-bit (jsc#PED-9651).
  - commit 1bd69f0
  - supported.conf: Mark HiSilicon I2C and GPIO modules as supported (jsc#PED-12808)
    Those two modules are needed for HiSilicon Kunpeng SoC.
  - commit acc31d6
  - supported.conf: Mark HiSilicon crypto ZIP, HPRE and SEC as supported (jsc#PED-12808)
  - commit a59b2d2
  - supported.conf: Mark HiSi PMU drivers as supported (jsc#PED-12808)
  - supported.conf:
  - drivers/perf/hisilicon/hisi_pcie_pmu
  - drivers/perf/hisilicon/hns3_pmu
    Those two will be handled by drivers/perf/hisilicon/*
  - commit c220da8
  - supported.conf: Mark HiSi DMA controller as supported (jsc#PED-12808)
  - supported.conf:
    + drivers/dma/hisi_dma
  - commit ab21278
  - supported.conf: Mark HiSi TRNG v2 as supported (jsc#PED-12808)
  - supported.conf:
  - drivers/char/hw_random/hisi-trng-v2
    + drivers/crypto/hisilicon/trng/hisi-trng-v2
  - commit 02dc142
  - scripts/check-kernel-fix: make branch_file local
  - scripts/common-functions: make branch_file local
    it doesn't have a global scope
  - commit 57f575c
  - supported.conf: Enable HiSi accel VFIO PCI (jsc#PED-12808)
  - supported.conf:
    + drivers/vfio/pci/hisilicon/hisi_acc_vfio_pci
  - commit f5abe63
  - supported.conf: Enable SPI DW mmio driver (jsc#PED-12808)
  - supported.conf
    + drivers/spi/spi-dw
    + drivers/spi/spi-dw-mmio
  - commit 11a0f85
  - nvmet: fix out-of-bounds access in nvmet_enable_port
    (jsc#PED-9651).
  - nvmet: pci-epf: cleanup link state management (jsc#PED-9651).
  - commit 6121ef2
  - nvmet: pci-epf: clear CC and CSTS when disabling the controller
    (jsc#PED-9651).
  - nvmet: pci-epf: always fully initialize completion entries
    (jsc#PED-9651).
  - nvmet: auth: use NULL to clear a pointer in nvmet_auth_sq_free()
    (jsc#PED-9651).
  - nvme-multipath: sysfs links may not be created for devices
    (jsc#PED-9651).
  - nvme: fixup scan failure for non-ANA multipath controllers
    (jsc#PED-9651).
  - commit 57152f2
  - nvmet-fc: put ref when assoc->del_work is already scheduled
    (jsc#PED-9651).
  - nvmet-fc: take tgtport reference only once (jsc#PED-9651).
  - nvmet-fc: update tgtport ref per assoc (jsc#PED-9651).
  - nvmet-fc: inline nvmet_fc_free_hostport (jsc#PED-9651).
  - nvmet-fc: inline nvmet_fc_delete_assoc (jsc#PED-9651).
  - nvmet-fcloop: add ref counting to lport (jsc#PED-9651).
  - commit ebd7542
  - nvmet-fcloop: replace kref with refcount (jsc#PED-9651).
  - nvme-tcp: fix use-after-free of netns by kernel TCP socket
    (jsc#PED-9651).
  - nvme: multipath: fix return value of nvme_available_path
    (jsc#PED-9651).
  - nvme: re-read ANA log page after ns scan completes
    (jsc#PED-9651).
  - nvme: requeue namespace scan on missed AENs (jsc#PED-9651).
  - commit 9484ecd
  - nvme-multipath: change the NVME_MULTIPATH config option
    (jsc#PED-9651).
  - nvme: update the multipath warning in nvme_init_ns_head
    (jsc#PED-9651).
  - nvme/ioctl: move fixed buffer lookup to nvme_uring_cmd_io()
    (jsc#PED-9651).
  - nvme/ioctl: move blk_mq_free_request() out of
    nvme_map_user_request() (jsc#PED-9651).
  - nvmet: pci-epf: Keep completion queues mapped (jsc#PED-9651).
  - nvme: convert timeouts to secs_to_jiffies() (jsc#PED-9651).
  - commit b857496
  - nvme-multipath: Add visibility for queue-depth io-policy
    (jsc#PED-9651).
  - nvme-multipath: Add visibility for numa io-policy
    (jsc#PED-9651).
  - nvme-multipath: Add visibility for round-robin io-policy
    (jsc#PED-9651).
  - nvmet: add tls_concat and tls_key debugfs entries
    (jsc#PED-9651).
  - nvmet-tcp: support secure channel concatenation (jsc#PED-9651).
  - commit 9372a5d
  - nvmet: Add 'sq' argument to alloc_ctrl_args (jsc#PED-9651).
  - nvme-fabrics: reset admin connection for secure concatenation
    (jsc#PED-9651).
  - nvme-tcp: request secure channel concatenation (jsc#PED-9651).
  - Refresh patches.suse/nvme-tcp-add-recovery_delay-to-sysfs.patch.
  - nvme-keyring: add nvme_tls_psk_refresh() (jsc#PED-9651).
  - nvme: add nvme_auth_derive_tls_psk() (jsc#PED-9651).
  - commit 0753eb8
  - nvme: add nvme_auth_generate_digest() (jsc#PED-9651).
  - nvme: add nvme_auth_generate_psk() (jsc#PED-9651).
  - crypto,fs: Separate out hkdf_extract() and hkdf_expand()
    (jsc#PED-9651).
  - block: remove unused parameter 'q' parameter in
    __blk_rq_map_sg() (jsc#PED-9651).
  - nvmet: pci-epf: Do not add an IRQ vector if not needed
    (jsc#PED-9651).
  - commit 1de7609
  - nvmet: pci-epf: Set NVMET_PCI_EPF_Q_LIVE when a queue is fully
    created (jsc#PED-9651).
  - nvme-pci: fix stuck reset on concurrent DPC and HP
    (jsc#PED-9651).
  - block: change blk_mq_add_to_batch() third argument type to bool
    (jsc#PED-9651).
  - nvme-pci: skip CMB blocks incompatible with PCI P2P DMA
    (jsc#PED-9651).
  - nvme-pci: clean up CMBMSC when registering CMB fails
    (jsc#PED-9651).
  - commit 7bcdfba
  - nvme-tcp: fix possible UAF in nvme_tcp_poll (jsc#PED-9651).
  - nvmet: Use enum definitions instead of hardcoded values
    (jsc#PED-9651).
  - nvme: Cleanup the definition of the controller config
    (jsc#PED-9651).
  - nvmet: pci-epf: Avoid RCU stalls under heavy workload
    (jsc#PED-9651).
  - nvmet: pci-epf: Do not uselessly write the CSTS register
    (jsc#PED-9651).
  - nvmet: pci-epf: Correctly initialize CSTS when enabling the
    controller (jsc#PED-9651).
  - commit 2ee3668
  - nvmet: add a missing endianess conversion in
    nvmet_execute_admin_connect (jsc#PED-9651).
  - nvmet: the result field in nvmet_alloc_ctrl_args is little
    endian (jsc#PED-9651).
  - nvmet: fix a memory leak in controller identify (jsc#PED-9651).
  - nvme-pci: remove redundant dma frees in hmb (jsc#PED-9651).
  - nvmet: fix rw control endian access (jsc#PED-9651).
  - commit b37065f
  - nvme-pci: use correct size to free the hmb buffer
    (jsc#PED-9651).
  - nvme-pci: fix comment typo (jsc#PED-9651).
  - nvmet: New NVMe PCI endpoint function target driver
    (jsc#PED-9651).
  - Update config files.
  - nvmet: Implement arbitration feature support (jsc#PED-9651).
  - nvmet: Implement interrupt config feature support
    (jsc#PED-9651).
  - commit 355e9de
  - nvmet: Implement interrupt coalescing feature support
    (jsc#PED-9651).
  - nvmet: Implement host identifier set feature support
    (jsc#PED-9651).
  - nvmet: Introduce get/set_feature controller operations
    (jsc#PED-9651).
  - nvmet: Do not require SGL for PCI target controller commands
    (jsc#PED-9651).
  - nvmet: Add support for I/O queue management admin commands
    (jsc#PED-9651).
  - nvmet: Introduce nvmet_sq_create() and nvmet_cq_create()
    (jsc#PED-9651).
  - commit 3aebe42
  - nvmet: Introduce nvmet_req_transfer_len() (jsc#PED-9651).
  - nvmet: Improve nvmet_alloc_ctrl() interface and implementation
    (jsc#PED-9651).
  - nvme: Add PCI transport type (jsc#PED-9651).
  - nvmet: Add drvdata field to struct nvmet_ctrl (jsc#PED-9651).
  - nvmet: Introduce nvmet_get_cmd_effects_admin() (jsc#PED-9651).
  - commit 7f723e1
  - nvmet: Export nvmet_update_cc() and nvmet_cc_xxx() helpers
    (jsc#PED-9651).
  - nvmet: Add vendor_id and subsys_vendor_id subsystem attributes
    (jsc#PED-9651).
  - nvme: Move opcode string helper functions declarations
    (jsc#PED-9651).
  - nvme: change return type of nvme_poll_cq() to bool
    (jsc#PED-9651).
  - nvmet: handle rw's limited retry flag (jsc#PED-9651).
  - commit 6e3ff3c
  - nvme-tcp: remove nvme_tcp_destroy_io_queues() (jsc#PED-9651).
  - nvme: use blk_validate_block_size() for max LBA check
    (jsc#PED-9651).
  - nvme-tcp: simplify nvme_tcp_teardown_io_queues() (jsc#PED-9651).
  - nvme-tcp: no need to quiesce admin_q in
    nvme_tcp_teardown_io_queues() (jsc#PED-9651).
  - nvme-pci: don't use dma_alloc_noncontiguous with 0 merge
    boundary (jsc#PED-9651).
  - commit bc8ad33
  - nvmet: replace kmalloc + memset with kzalloc for data allocation
    (jsc#PED-9651).
  - nvme-pci: remove two deallocate zeroes quirks (jsc#PED-9651).
  - nvmet: use kzalloc instead of ZERO_PAGE in
    nvme_execute_identify_ns_nvm() (jsc#PED-9651).
  - nvme: tuning pr code by using defined structs and macros
    (jsc#PED-9651).
  - nvme: introduce change ptpl and iekey definition (jsc#PED-9651).
  - nvme: define the remaining used sgls constants (jsc#PED-9651).
  - commit cc50dac
  - nvmet: add tracing of reservation commands (jsc#PED-9651).
  - nvme: parse reservation commands's action and rtype to string
    (jsc#PED-9651).
  - nvmet: report ns's vwc not present (jsc#PED-9651).
  - nvme: check ns's volatile write cache not present
    (jsc#PED-9651).
  - nvme: add rotational support (jsc#PED-9651).
  - commit 6d72f74
  - nvme: use command set independent id ns if available
    (jsc#PED-9651).
  - nvmet: support for csi identify ns (jsc#PED-9651).
  - nvmet: implement rotational media information log
    (jsc#PED-9651).
  - nvmet: implement endurance groups (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - nvmet: declare 2.1 version compliance (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - nvmet: implement crto property (jsc#PED-9651).
  - commit a9d87e8
  - nvmet: implement supported features log (jsc#PED-9651).
  - nvmet: implement supported log pages (jsc#PED-9651).
  - nvmet: implement active command set ns list (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - nvmet: implement id ns for nvm command set (jsc#PED-9651).
  - nvmet: support reservation feature (jsc#PED-9651).
  - Refresh
    patches.suse/nvmet-Fix-crash-when-a-namespace-is-disabled.patch.
  - Refresh
    patches.suse/nvmet-loop-avoid-using-mutex-in-IO-hotpath.patch.
  - commit 88ed9df
  - nvme: add reservation command's defines (jsc#PED-9651).
  - nvme-core: remove repeated wq flags (jsc#PED-9651).
  - commit 1ad47bf
  - nvmet: make nvmet_wq visible in sysfs (jsc#PED-9651).
  - commit 6767401
  - nvme-pci: use dma_alloc_noncontigous if possible (jsc#PED-9651).
  - Refresh
    patches.suse/nvme-pci-add-support-for-sgl-metadata.patch.
  - commit 26b5396
  - nvme-multipath: don't bother clearing max_hw_zone_append_sectors
    (jsc#PED-9651).
  - commit bbefc23
  - iommu/amd: Fix header file (jsc#PED-12548).
  - iommu/amd: Preserve default DTE fields when updating Host Page
    Table Root (jsc#PED-12548).
  - commit e9648a6
  - net/mlx5: Move ttc allocation after switch case to prevent leaks
    (git-fixes).
  - net/mlx5: Fix null-ptr-deref in mlx5_create_{inner_,}ttc_table()
    (git-fixes).
  - netlink: specs: rt-link: adjust mctp attribute naming
    (git-fixes).
  - netlink: specs: rtnetlink: attribute naming corrections
    (git-fixes).
  - netlink: specs: rt-link: add an attr layer around alt-ifname
    (git-fixes).
  - cxgb4: fix memory leak in cxgb4_init_ethtool_filters() error
    path (git-fixes).
  - eth: bnxt: fix missing ring index trim on error path
    (git-fixes).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors (git-fixes).
  - igc: add lock preventing multiple simultaneous PTM transactions
    (git-fixes).
  - igc: cleanup PTP module if probe fails (git-fixes).
  - igc: handle the IGC_PTP_ENABLED flag correctly (git-fixes).
  - igc: move ktime snapshot into PTM retry loop (git-fixes).
  - igc: increase wait time before retrying PTM (git-fixes).
  - igc: fix PTM cycle trigger logic (git-fixes).
  - netlink: specs: ovs_vport: align with C codegen capabilities
    (git-fixes).
  - octeontx2-pf: qos: fix VF root node parent queue index
    (git-fixes).
  - idpf: fix adapter NULL pointer dereference on reboot
    (git-fixes).
  - ixgbe: fix media type detection for E610 device (git-fixes).
  - e1000e: change k1 configuration on MTP and later platforms
    (git-fixes).
  - igc: Fix XSK queue NAPI ID mapping (git-fixes).
  - sfc: fix NULL dereferences in ef100_process_design_param()
    (git-fixes).
  - gve: handle overflow when reporting TX consumed descriptors
    (git-fixes).
  - net/mlx5e: SHAMPO, Make reserved size independent of page size
    (git-fixes).
  - vdpa/mlx5: Fix oversized null mkey longer than 32bit
    (git-fixes).
  - idpf: check error for register_netdev() on init (git-fixes).
  - ice: fix using untrusted value of pkt_len in
    ice_vc_fdir_parse_raw() (CVE-2025-22117 bsc#1241633).
  - ice: fix input validation for virtchnl BW (git-fixes).
  - ice: validate queue quanta parameters to prevent OOB access
    (CVE-2025-22118 bsc#1241562).
  - ice: stop truncating queue ids when checking (git-fixes).
  - virtchnl: make proto and filter action count unsigned
    (git-fixes).
  - ice: fix reservation of resources for RDMA when disabled
    (git-fixes).
  - ice: ensure periodic output start time is in the future
    (git-fixes).
  - net/mlx5: Start health poll after enable hca (git-fixes).
  - net/mlx5: LAG, reload representors on LAG creation failure
    (git-fixes).
  - bnxt_en: Linearize TX SKB if the fragments exceed the max
    (git-fixes).
  - bnxt_en: Mask the bd_cnt field in the TX BD properly
    (git-fixes).
  - net/mlx5e: Fix ethtool -N flow-type ip4 to RSS context
    (git-fixes).
  - gve: unlink old napi only if page pool exists (git-fixes).
  - igb: reject invalid external timestamp requests for 82580-based
    HW (git-fixes).
  - bonding: fix incorrect MAC address setting to receive NS
    messages (git-fixes).
  - net/mlx5: Fill out devlink dev info only for PFs (git-fixes).
  - cxgb4: Avoid removal of uninserted tid (git-fixes).
  - Revert "rtnetlink: add guard for RTNL" (git-fixes).
  - commit 1c6076b
  - ext4: avoid remount errors with 'abort' mount option
    (bsc#1241673).
  - commit 7e45d00
  - ext4: fix OOB read when checking dotdot dir (bsc#1241640
    CVE-2025-37785).
  - commit 1f644d1
  - ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()
    (bsc#1241593 CVE-2025-22121).
  - commit 31cdb6e
  - proc: fix UAF in proc_get_inode() (bsc#1240802 CVE-2025-21999).
  - commit 17ecba0
  - fs: relax assertions on failure to encode file handles
    (bsc#1236086 CVE-2024-57924).
  - commit 7fa3943
  - Revert "readahead: properly shorten readahead when falling
    back to do_page_cache_ra()" (bsc#1235799 CVE-2024-57839).
  - commit 6921c3b
  - isofs: avoid memory leak in iocharset (bsc#1234965
    CVE-2024-56534).
  - commit 2bb1019
  - quota: flush quota_release_work upon quota writeback
    (bsc#1235650 CVE-2024-56780).
  - commit 9807ea9
  - fsnotify: Fix ordering of iput() and watched_objects decrement
    (bsc#1234316 CVE-2024-53143).
  - commit 80f01f0
  - dm-integrity: Do not emit journal configuration in DM table
    fro Inline mode (jsc#PED-9651).
  - dm-crypt: don't initialize cc_sector again (jsc#PED-9651).
  - dm-crypt: use bi_sector in bio when initialize integrity seed
    (jsc#PED-9651).
  - dm-crypt: fully initialize clone->bi_iter in
    crypt_alloc_buffer() (jsc#PED-9651).
  - dm-crypt: set atomic as false when calling crypt_convert()
    in kworker (jsc#PED-9651).
  - dm-mirror: Support atomic writes (jsc#PED-9651).
  - dm-io: Warn on creating multiple atomic write bios for a region
    (jsc#PED-9651).
  - dm-stripe: Enable atomic writes (jsc#PED-9651).
  - dm-linear: Enable atomic writes (jsc#PED-9651).
  - dm: Ensure cloned bio is same length for atomic write
    (jsc#PED-9651).
  - dm-table: atomic writes support (jsc#PED-9651).
  - dm-transaction-manager: use red-black trees instead of linear
    lists (jsc#PED-9651).
  - dm: disable REQ_NOWAIT for flushes (jsc#PED-9651).
  - dm: remove useless test in alloc_multiple_bios (jsc#PED-9651).
  - dm: change kzalloc to kcalloc (jsc#PED-9651).
  - dm raid: fix spelling errors in raid_ctr() (jsc#PED-9651).
  - dm-verity FEC: Avoid copying RS parity bytes twice
    (jsc#PED-9651).
  - dm-verity: remove the unused "data_start" variable
    (jsc#PED-9651).
  - dm-bufio: use kmalloc to allocate power-of-two sized buffers
    (jsc#PED-9651).
  - dm: add support for get_unique_id (jsc#PED-9651).
  - dm vdo: fix function doc comment formatting (jsc#PED-9651).
  - dm vdo int-map: remove unused parameters (jsc#PED-9651).
  - dm-vdo: reset bi_ioprio to the default value when the bio is
    reset (jsc#PED-9651).
  - dm-vdo murmurhash: remove u64 alignment requirement
    (jsc#PED-9651).
  - dm ioctl: rate limit a couple of ioctl based error messages
    (jsc#PED-9651).
  - dm vdo: Remove unused uds_compute_index_size (jsc#PED-9651).
  - dm vdo: Remove unused functions (jsc#PED-9651).
  - dm: zoned: Remove unused functions (jsc#PED-9651).
  - dm: Remove unused dm_table_bio_based (jsc#PED-9651).
  - dm: Remove unused dm_set_md_type (jsc#PED-9651).
  - dm cache: Remove unused functions in bio-prison-v1
    (jsc#PED-9651).
  - dm cache: Remove unused dm_cache_size (jsc#PED-9651).
  - dm cache: Remove unused dm_cache_dump (jsc#PED-9651).
  - dm cache: Remove unused btracker_nr_writebacks_queued
    (jsc#PED-9651).
  - commit abbc785
  - iommu/amd: Enable support for up to 2K interrupts per function
    (jsc#PED-12548).
  - iommu/amd: Rename DTE_INTTABLEN* and MAX_IRQS_PER_TABLE macro
    (jsc#PED-12548).
  - iommu/amd: Replace slab cache allocator with page allocator
    (jsc#PED-12548).
  - iommu/amd: Introduce generic function to set multibit feature
    value (jsc#PED-12548).
  - iommu/amd: Remove amd_iommu_apply_erratum_63() (jsc#PED-12548).
  - iommu/amd: Lock DTE before updating the entry with WRITE_ONCE()
    (jsc#PED-12548).
  - iommu/amd: Modify clear_dte_entry() to avoid in-place update
    (jsc#PED-12548).
  - iommu/amd: Introduce helper function get_dte256()
    (jsc#PED-12548).
  - iommu/amd: Modify set_dte_entry() to use 256-bit DTE helpers
    (jsc#PED-12548).
  - iommu/amd: Introduce helper function to update 256-bit DTE
    (jsc#PED-12548).
  - iommu/amd: Introduce struct ivhd_dte_flags to store persistent
    DTE flags (jsc#PED-12548).
  - iommu/amd: Disable AMD IOMMU if CMPXCHG16B feature is not
    supported (jsc#PED-12548).
  - iommu/amd: Misc ACPI IVRS debug info clean up (jsc#PED-12548).
  - commit cea8105
  - Update patches.suse/powerpc64-ftrace-fix-module-loading-without-patchabl.patch
    (jsc#PED-10909 git-fixes bsc#1236402).
  - commit 851952d
  - Delete patches.suse/dm-mpath-leastpending-path-update.
  - commit 2fdb1ca
  - Delete
    patches.suse/nvme_core-scan-namespaces-asynchronously.patch.
  - commit b9417d4
  - Delete
    patches.suse/nvme-multipath-suppress-partition-scan-until-the-dis.patch.
  - commit e258b74
  - Delete
    patches.suse/nvme-keyring-restrict-match-length-for-version-1-ide.patch.
  - commit 9af6fe5

++++ at-spi2-core:

  - Update to version 2.56.2:
    + Fix the build with glib < 2.76.
    + a11y-manager-device: Fix unmap_keysym_modifier.

++++ gcc15:

  - Update to GCC 15 branch head, 15.1.1+git9595
    * includes GCC 15.1 release
  - Enable gfx9-generic, gfx10-3-generic and gfx11-generic multilibs
    for the AMD GCN offload compiler when llvm is new enough.
  - Build the COBOL frontend also for risc-v

++++ ncurses:

  - Add ncurses patch 20250426
    + expand note on extensions in curs_addch.3x
    + add illumos, sun-16color, sun-256color, sun-direct -TD
    + add wyse+cvis -TD
  - Add ncurses patch 20250419
    + add note on scrolling and lower-right corner to waddch and wadd_wch
    manual pages.
  - Modify patch ncurses-5.9-ibm327x.dif
    * sclp term: more missed features like home/end/pageup/pagedown keys

++++ libnftnl:

  - Update signing key to 0x8C5F7146A1757A65E2422A94D70D1A666ACF2B21,
    which is currently used to sign the latest tarballs including
    version 1.2.9.

++++ wtmpdb:

  - Update to version 0.74.0+git20250424.2e93e77:
    * Release version 0.74.0
    * Fix varlink interface name (rebootmgr vs wtmpdb)
    * import: match login by tty if non-zero pid does not match

++++ ovmf:

  - Add TDX flavor OVMF using Config-B (OvmfPkg/IntelTdx/IntelTdxX64.dsc).
    Full TDX functionality has been supported with Config-B.
  - Config-A (OvmfPkg/OvmfPkgX64.dsc) will be proposed for switching
    from Config-B once TDX upstream support becomes more complete and integration is
    more mature.
  - Below is the difference between Config-A and Config-B.
  - Config-A:
  - Merge the basic TDVF feature to existing OvmfPkgX64.dsc. (Align with existing SEV)
  - Threat model: VMM is NOT out of TCB. (We don't make things worse)
  - The OvmfPkgX64.dsc includes SEV/TDX/normal OVMF basic boot capability. The final binary can run on SEV/TDX/normal OVMF.
  - No changes to existing OvmfPkgX64 image layout.
  - No need to remove features if they exist today.
  - PEI phase is NOT skipped in either TD or Non-TD.
  - RTMR based measurement (CC_MEASUREMENT) is supported as an optional requirement.
  - External inputs from Host VMM are measured, such as TdHob, CFV.
  - Other external inputs are measured, such as FW_CFG data, os loader, initrd, etc.
  - Config-B:
  - Add a standalone IntelTdxX64.dsc to a TDX specific directory (OvmfPkg/IntelTdx) for a full feature TDVF.(Align with existing SEV)
  - Threat model: VMM is out of TCB. (We need necessary change to prevent attack from VMM)
  - IntelTdxX64.dsc includes TDX/normal OVMF basic boot capability. The final binary can run on TDX/normal OVMF.
  - It might eventually merge with AmdSev.dsc, but NOT at this point of time. And we don't know when it will happen. We need sync with AMD in the community after both of us think the solutions are mature to merge.
  - RTMR based measurement (CC_MEASUREMENT) is supported as a mandatory requirement.
  - External inputs from Host VMM are measured, such as TdHob, CFV.
  - Other external inputs are measured, such as FW_CFG data, os loader, initrd, etc.
  - PEI phase is skipped to remove unnecessary attack surface.
  - DXE FV is split into 2 FVs (DXEFV & NCCFV) to remove the unnecessary attack surface in a TD guest..
  - When launching a TD guest, only drivers in DXEFV are loaded.
  - When launching a Non-TD guest, dirvers in both DXEFV and NCCFV are loaded.

++++ systemd-presets-common-SUSE:

  - Create devel subpackage:
    * Add RPM macros file
    * Package to be used to develop preset packages
    (distro, display manager etc.)
  - Move specfile scriptlets to the ones in macros.systemd-preset

------------------------------------------------------------------
------------------  2025-4-27  -  Apr 27 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Drop copying GRUB2 modules to /boot with Secure Boot UEFI images
    Copying the modules creates a situation where future updates
    applied to a running system can cause GRUB to crash due to mixed
    modules and GRUB EFI binaries.
    It is not needed anyway since GRUB EFI binaries for Secure Boot have
    all modules compiled into the binaries.
    Fixes: https://github.com/OSInside/kiwi/issues/2790
  - Make sure editbootinstall runs offline
    editbootinstall expects the system to be umounted
  - Make sure post sync actions are in scope
  - Follow up fix for overlayroot builds for EFI path
    Only perform the boot overlay if there is an extra boot partition
  - Only remove entries from exclude list if present
  - Fix overlayroot builds for EFI path
    make sure to keep boot/efi mountpoint directories
    in the read-only area as they can't be created later
  - doc: overview: Add list of supported Linux distributions
    These are the Linux distributions that are developed and actively
    tested for with the latest kiwi releases.
    This should offer greater clarity about what we're able to support
    as an upstream project.
  - Fixed mount of image system for volume managers
    The ImageSystem.mount() method implemented its own handling
    for mounting the volumes of a volume manager based system.
    First and foremost this duplicates code that already exists
    in the respective VolumeManager implementation and second
    the code behaved wrong in case of btrfs when there is no
    default subvolume configured
  - Handle grub fix functions less strict
    If called on full read-only systems, log the information
    that the files can't be modified but do not fail. On
    such systems the expectation is that no fix code must
    be applied and as such the fix function can be considered
    an optional step.

++++ kernel-default:

  - Delete
    patches.suse/sched-fair-Increase-wakeup_gran-if-current-task-has-not-executed-the-minimum-granularity.patch.
    Conceptually incompatible with EEVDF.
  - commit e1d8356
  - Delete
  - patches.suse/cpuidle-Poll-for-a-minimum-of-30ns-and-poll-for-a-tick-if-lower-c-states-are-disabled.patch.
  - patches.suse/sched-nohz-Avoid-disabling-the-tick-for-very-short-durations.patch.
    Neither patch has been found for be beneficial recently except as a
    debugging aid.
  - commit 2ffcdfb
  - Delete
    patches.suse/sched-fair-Revert-update_pick_idlest-Select-group-with-lowest-group_util-when-idle_cpus-are-equal.patch.
  - commit c749b06
  - Delete
    patches.suse/sched-Temporarily-restore-deprecated-scheduler-sysctls-with-a-warning.patch.
    Deprecated sysctls can no longer be restored.
  - commit 92b7eb8
  - Update
    patches.suse/cpufreq-ondemand-Set-default-up_threshold-to-30-on-multi-core-systems.patch
    (bsc#464461,bsc#981838,bsc#1064414,bsc#1144943,bsc#1193200,bsc#1193088,bsc#1217546,bsc#1241613).
  - commit 4052251
  - Refresh patches.suse/iommu-Allow-attaching-static-domains-in-iommu_attach.patch (bsc#1241193)
    Refreshed to v3 patch
  - commit 2d5f06a
  - irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
    (git-fixes).
  - drm/amd/display: Enable urgent latency adjustment on DCN35
    (stable-fixes).
  - drm/amd/display: Fix gpu reset in multidisplay config
    (git-fixes).
  - drm: panel: jd9365da: fix reset signal polarity in unprepare
    (git-fixes).
  - drm/meson: use unsigned long long / Hz for frequency types
    (git-fixes).
  - Revert "drm/meson: vclk: fix calculation of 59.94 fractional
    rates" (git-fixes).
  - commit 6c8c3c2

++++ kernel-rt:

  - Delete
    patches.suse/sched-fair-Increase-wakeup_gran-if-current-task-has-not-executed-the-minimum-granularity.patch.
    Conceptually incompatible with EEVDF.
  - commit e1d8356
  - Delete
  - patches.suse/cpuidle-Poll-for-a-minimum-of-30ns-and-poll-for-a-tick-if-lower-c-states-are-disabled.patch.
  - patches.suse/sched-nohz-Avoid-disabling-the-tick-for-very-short-durations.patch.
    Neither patch has been found for be beneficial recently except as a
    debugging aid.
  - commit 2ffcdfb
  - Delete
    patches.suse/sched-fair-Revert-update_pick_idlest-Select-group-with-lowest-group_util-when-idle_cpus-are-equal.patch.
  - commit c749b06
  - Delete
    patches.suse/sched-Temporarily-restore-deprecated-scheduler-sysctls-with-a-warning.patch.
    Deprecated sysctls can no longer be restored.
  - commit 92b7eb8
  - Update
    patches.suse/cpufreq-ondemand-Set-default-up_threshold-to-30-on-multi-core-systems.patch
    (bsc#464461,bsc#981838,bsc#1064414,bsc#1144943,bsc#1193200,bsc#1193088,bsc#1217546,bsc#1241613).
  - commit 4052251
  - Refresh patches.suse/iommu-Allow-attaching-static-domains-in-iommu_attach.patch (bsc#1241193)
    Refreshed to v3 patch
  - commit 2d5f06a
  - irqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()
    (git-fixes).
  - drm/amd/display: Enable urgent latency adjustment on DCN35
    (stable-fixes).
  - drm/amd/display: Fix gpu reset in multidisplay config
    (git-fixes).
  - drm: panel: jd9365da: fix reset signal polarity in unprepare
    (git-fixes).
  - drm/meson: use unsigned long long / Hz for frequency types
    (git-fixes).
  - Revert "drm/meson: vclk: fix calculation of 59.94 fractional
    rates" (git-fixes).
  - commit 6c8c3c2

------------------------------------------------------------------
------------------  2025-4-26  -  Apr 26 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - usb: typec: class: Unlocked on error in typec_register_partner()
    (git-fixes).
  - crypto: tegra - Fix format specifier in tegra_sha_prep_cmd()
    (git-fixes).
  - commit db6edbe
  - crypto: tegra - Transfer HASH init function to crypto engine
    (git-fixes).
  - Refresh
    patches.suse/crypto-tegra-Use-HMAC-fallback-when-keyslots-are-ful.patch.
  - commit 21485d2
  - crypto: tegra - Do not use fixed size buffers (git-fixes).
  - Refresh
    patches.suse/crypto-tegra-Fix-CMAC-intermediate-result-handling.patch.
  - commit e3d6cdb
  - cxl/core/regs.c: Skip Memory Space Enable check for RCD and
    RCH Ports (git-fixes).
  - USB: wdm: add annotation (git-fixes).
  - USB: wdm: wdm_wwan_port_tx_complete mutex in atomic context
    (git-fixes).
  - USB: wdm: close race between wdm_open and wdm_wwan_port_stop
    (git-fixes).
  - USB: wdm: handle IO errors in wdm_wwan_port_start (git-fixes).
  - usb: dwc3: gadget: check that event count does not exceed
    event buffer length (git-fixes).
  - usb: dwc3: xilinx: Prevent spike in reset signal (git-fixes).
  - usb: cdns3: Fix deadlock when using NCM gadget (git-fixes).
  - usb: chipidea: ci_hdrc_imx: implement usb_phy_init() error
    handling (git-fixes).
  - usb: chipidea: ci_hdrc_imx: fix call balance of regulator
    routines (git-fixes).
  - usb: chipidea: ci_hdrc_imx: fix usbmisc handling (git-fixes).
  - usb: typec: class: Invalidate USB device pointers on partner
    unregistration (git-fixes).
  - usb: typec: class: Fix NULL pointer access (git-fixes).
  - usb: xhci: Fix invalid pointer dereference in Etron workaround
    (git-fixes).
  - serial: sifive: lock port in startup()/shutdown() callbacks
    (git-fixes).
  - tty: Require CAP_SYS_ADMIN for all usages of
    TIOCL_SELMOUSEREPORT (git-fixes).
  - serial: msm: Configure correct working mode before starting
    earlycon (git-fixes).
  - firmware: stratix10-svc: Add of_platform_default_populate()
    (git-fixes).
  - mei: vsc: Fix fortify-panic caused by invalid counted_by()
    use (git-fixes).
  - misc: microchip: pci1xxxx: Fix incorrect IRQ status handling
    during ack (git-fixes).
  - misc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler
    registration (git-fixes).
  - char: misc: register chrdev region with all possible minors
    (git-fixes).
  - Revert "drivers: core: synchronize really_probe() and
    dev_uevent()" (stable-fixes).
  - dma/contiguous: avoid warning about unused size_bytes
    (git-fixes).
  - Bluetooth: l2cap: Process valid commands in too long frame
    (stable-fixes).
  - Revert "wifi: mac80211: Update skb's control block key in
    ieee80211_tx_dequeue()" (git-fixes).
  - wifi: mac80211: Update skb's control block key in
    ieee80211_tx_dequeue() (git-fixes).
  - platform/x86: msi-wmi-platform: Workaround a ACPI firmware bug
    (git-fixes).
  - platform/x86: msi-wmi-platform: Rename "data" variable
    (stable-fixes).
  - crypto: tegra - Fix IV usage for AES ECB (git-fixes).
  - drm/amd/display: Add HP Elitebook 645 to the quirk list for
    eDP on DP1 (stable-fixes).
  - drm/amd/display: Add HP Probook 445 and 465 to the quirk list
    for eDP on DP1 (stable-fixes).
  - drm/i915/gvt: fix unterminated-string-initialization warning
    (stable-fixes).
  - drm/amd/display: prevent hang on link training fail
    (stable-fixes).
  - drm/amd: Handle being compiled without SI or CIK support better
    (stable-fixes).
  - clk: samsung: Fix UBSAN panic in samsung_clk_init()
    (CVE-2025-39728 bsc#1241626).
  - crypto: tegra - Reserve keyslots to allocate dynamically
    (git-fixes).
  - crypto: tegra - Fix HASH intermediate result handling
    (git-fixes).
  - crypto: tegra - finalize crypto req on error (git-fixes).
  - drm/amd/display: Temporarily disable hostvm on DCN31
    (stable-fixes).
  - crypto: tegra - remove redundant error check on ret
    (stable-fixes).
  - commit 01594c5

++++ kernel-rt:

  - usb: typec: class: Unlocked on error in typec_register_partner()
    (git-fixes).
  - crypto: tegra - Fix format specifier in tegra_sha_prep_cmd()
    (git-fixes).
  - commit db6edbe
  - crypto: tegra - Transfer HASH init function to crypto engine
    (git-fixes).
  - Refresh
    patches.suse/crypto-tegra-Use-HMAC-fallback-when-keyslots-are-ful.patch.
  - commit 21485d2
  - crypto: tegra - Do not use fixed size buffers (git-fixes).
  - Refresh
    patches.suse/crypto-tegra-Fix-CMAC-intermediate-result-handling.patch.
  - commit e3d6cdb
  - cxl/core/regs.c: Skip Memory Space Enable check for RCD and
    RCH Ports (git-fixes).
  - USB: wdm: add annotation (git-fixes).
  - USB: wdm: wdm_wwan_port_tx_complete mutex in atomic context
    (git-fixes).
  - USB: wdm: close race between wdm_open and wdm_wwan_port_stop
    (git-fixes).
  - USB: wdm: handle IO errors in wdm_wwan_port_start (git-fixes).
  - usb: dwc3: gadget: check that event count does not exceed
    event buffer length (git-fixes).
  - usb: dwc3: xilinx: Prevent spike in reset signal (git-fixes).
  - usb: cdns3: Fix deadlock when using NCM gadget (git-fixes).
  - usb: chipidea: ci_hdrc_imx: implement usb_phy_init() error
    handling (git-fixes).
  - usb: chipidea: ci_hdrc_imx: fix call balance of regulator
    routines (git-fixes).
  - usb: chipidea: ci_hdrc_imx: fix usbmisc handling (git-fixes).
  - usb: typec: class: Invalidate USB device pointers on partner
    unregistration (git-fixes).
  - usb: typec: class: Fix NULL pointer access (git-fixes).
  - usb: xhci: Fix invalid pointer dereference in Etron workaround
    (git-fixes).
  - serial: sifive: lock port in startup()/shutdown() callbacks
    (git-fixes).
  - tty: Require CAP_SYS_ADMIN for all usages of
    TIOCL_SELMOUSEREPORT (git-fixes).
  - serial: msm: Configure correct working mode before starting
    earlycon (git-fixes).
  - firmware: stratix10-svc: Add of_platform_default_populate()
    (git-fixes).
  - mei: vsc: Fix fortify-panic caused by invalid counted_by()
    use (git-fixes).
  - misc: microchip: pci1xxxx: Fix incorrect IRQ status handling
    during ack (git-fixes).
  - misc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler
    registration (git-fixes).
  - char: misc: register chrdev region with all possible minors
    (git-fixes).
  - Revert "drivers: core: synchronize really_probe() and
    dev_uevent()" (stable-fixes).
  - dma/contiguous: avoid warning about unused size_bytes
    (git-fixes).
  - Bluetooth: l2cap: Process valid commands in too long frame
    (stable-fixes).
  - Revert "wifi: mac80211: Update skb's control block key in
    ieee80211_tx_dequeue()" (git-fixes).
  - wifi: mac80211: Update skb's control block key in
    ieee80211_tx_dequeue() (git-fixes).
  - platform/x86: msi-wmi-platform: Workaround a ACPI firmware bug
    (git-fixes).
  - platform/x86: msi-wmi-platform: Rename "data" variable
    (stable-fixes).
  - crypto: tegra - Fix IV usage for AES ECB (git-fixes).
  - drm/amd/display: Add HP Elitebook 645 to the quirk list for
    eDP on DP1 (stable-fixes).
  - drm/amd/display: Add HP Probook 445 and 465 to the quirk list
    for eDP on DP1 (stable-fixes).
  - drm/i915/gvt: fix unterminated-string-initialization warning
    (stable-fixes).
  - drm/amd/display: prevent hang on link training fail
    (stable-fixes).
  - drm/amd: Handle being compiled without SI or CIK support better
    (stable-fixes).
  - clk: samsung: Fix UBSAN panic in samsung_clk_init()
    (CVE-2025-39728 bsc#1241626).
  - crypto: tegra - Reserve keyslots to allocate dynamically
    (git-fixes).
  - crypto: tegra - Fix HASH intermediate result handling
    (git-fixes).
  - crypto: tegra - finalize crypto req on error (git-fixes).
  - drm/amd/display: Temporarily disable hostvm on DCN31
    (stable-fixes).
  - crypto: tegra - remove redundant error check on ret
    (stable-fixes).
  - commit 01594c5

------------------------------------------------------------------
------------------  2025-4-25  -  Apr 25 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - U_egl-never-select-swrast-for-vmwgfx.patch
    * fixes crash in libgallium on virtualbox (bsc#1241701)

++++ Mesa-drivers:

  - U_egl-never-select-swrast-for-vmwgfx.patch
    * fixes crash in libgallium on virtualbox (bsc#1241701)

++++ aaa_base:

  - Update to version 84.87+git20250425.1664836:
    * Fix bug boo#1241205 by adding missed endif
    * alias.bash: future-proof egrep/fgrep color aliases

++++ python-kiwi:

  - Fixed root setup for encrypted overlay disk
    When building an image with overlayroot set to true and
    activated luks encryption, the root= parameter must be
    set to root=overlay:MAPPER=luks instead of the standard
    overlay:PARTUUID mapping. This Fixes #2776
  - Change suffix for package manager config files
    Use .config instead of .conf for the temporary package
    manager config files. Reason for this change is a bug in
    dracut which reads and executes all /*.conf files from
    the system. This Fixes #2780
  - Set security context after root sync
    On selinux enabled image builds we call setfiles initially
    after the root tree is complete and after each script invocation
    that might change the system. However the security context
    also applies to mount points e.g volumes which only exists
    at the time when the root tree gets synced to the actual image
    binary. Thus this commit also calls setfiles on the mounted
    root tree after data sync. This Fixes rh#2333743
  - Fix broken doc link
    Rephrase chapter pointing to a documentation side at VMware.
    They are constantly changing their documentation URLs that
    I'm tired of fixing this. This Fixes #2782

++++ grub2:

  - grub2-common: use fuse3

++++ kernel-default:

  - vmxnet3: unregister xdp rxq info in the reset path (bsc#1241394
    CVE-2025-22106 bsc#1241547).
  - commit 98a3203
  - mm: (un)track_pfn_copy() fix + doc improvements (CVE-2025-22090
    bsc#1241537).
  - commit fdf32a4
  - x86/mm/pat: Fix VM_PAT handling when fork() fails in
    copy_page_range() (CVE-2025-22090 bsc#1241537).
  - commit 72666c0
  - fs/ntfs3: Prevent integer overflow in hdr_first_de()
    (bsc#1241416 CVE-2025-22080).
  - commit 715db43
  - Refresh
    patches.suse/add-product-identifying-information-to-vmcoreinfo.patch.
  - commit 1b23642
  - Refresh patches.suse/kabi-padding-for-vmstat-items.patch.
  - fix up and re-enable the kabi padding for vmstat items
  - commit cd9d69f
  - Refresh patches.suse/crasher.patch and reenable it.
  - Update config files.
  - commit 7a517c9
  - padding: add placeholders to device controllers structures (git-fixes)
  - commit bf484b5
  - Re-enable b43 patch for missing firmware notification
    The patch is still valid and applied to Tumbleweed as well
  - commit 5a8e854
  - Add kABI placeholders for sound core
  - Add kABI placeholders for regmap
  - commit 864c7f1
  - net: phy: leds: fix memory leak (git-fixes).
  - net: phy: microchip: force IRQ polling mode for lan88xx
    (git-fixes).
  - crypto: atmel-sha204a - Set hwrng quality to lowest possible
    (git-fixes).
  - commit 89bf1f8
  - bpf: Fix softlockup in arena_map_free on 64k page kernel (CVE-2025-21851 bsc#1239480)
  - commit 125c4ff
  - netfs: Call `invalidate_cache` only if implemented (CVE-2025-22002 bsc#1240875)
  - commit 5ef8097
  - Refresh patches.suse/drm-Add-kabi-placeholders-to-commonly-used-structs.patch.
    Use same drm kabi padding as in SLE15-SP7
  - commit 27dd19d

++++ kernel-firmware-amdgpu:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-ath10k:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-ath11k:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.
  - Update to version 20250424 (git commit c8af472e05cb):
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01300-QCAHKSWPL_SILICONZ-1

++++ kernel-firmware-ath12k:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.
  - Update to version 20250424 (git commit c8af472e05cb):
    * ath12k: WCN7850 hw2.0: update to WLAN.HMT.1.1.c5-00284-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3
    * ath12k: QCN9274 hw2.0: update board-2.bin

++++ kernel-firmware-atheros:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-bluetooth:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-bnx2:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-brcm:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-chelsio:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-dpaa2:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-i915:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-intel:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-iwlwifi:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-liquidio:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-marvell:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-media:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.
  - Update to version 20250424 (git commit c8af472e05cb):
    * qcom: vpu: update video firmware binary for SA8775p

++++ kernel-firmware-mediatek:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-mellanox:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-mwifiex:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-network:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-nfp:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-nvidia:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-platform:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-prestera:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-qcom:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-qlogic:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-radeon:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-realtek:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-serial:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-sound:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-ti:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-ueagle:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-firmware-usb-network:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

++++ kernel-rt:

  - vmxnet3: unregister xdp rxq info in the reset path (bsc#1241394
    CVE-2025-22106 bsc#1241547).
  - commit 98a3203
  - mm: (un)track_pfn_copy() fix + doc improvements (CVE-2025-22090
    bsc#1241537).
  - commit fdf32a4
  - x86/mm/pat: Fix VM_PAT handling when fork() fails in
    copy_page_range() (CVE-2025-22090 bsc#1241537).
  - commit 72666c0
  - fs/ntfs3: Prevent integer overflow in hdr_first_de()
    (bsc#1241416 CVE-2025-22080).
  - commit 715db43
  - Refresh
    patches.suse/add-product-identifying-information-to-vmcoreinfo.patch.
  - commit 1b23642
  - Refresh patches.suse/kabi-padding-for-vmstat-items.patch.
  - fix up and re-enable the kabi padding for vmstat items
  - commit cd9d69f
  - Refresh patches.suse/crasher.patch and reenable it.
  - Update config files.
  - commit 7a517c9
  - padding: add placeholders to device controllers structures (git-fixes)
  - commit bf484b5
  - Re-enable b43 patch for missing firmware notification
    The patch is still valid and applied to Tumbleweed as well
  - commit 5a8e854
  - Add kABI placeholders for sound core
  - Add kABI placeholders for regmap
  - commit 864c7f1
  - net: phy: leds: fix memory leak (git-fixes).
  - net: phy: microchip: force IRQ polling mode for lan88xx
    (git-fixes).
  - crypto: atmel-sha204a - Set hwrng quality to lowest possible
    (git-fixes).
  - commit 89bf1f8
  - bpf: Fix softlockup in arena_map_free on 64k page kernel (CVE-2025-21851 bsc#1239480)
  - commit 125c4ff
  - netfs: Call `invalidate_cache` only if implemented (CVE-2025-22002 bsc#1240875)
  - commit 5ef8097
  - Refresh patches.suse/drm-Add-kabi-placeholders-to-commonly-used-structs.patch.
    Use same drm kabi padding as in SLE15-SP7
  - commit 27dd19d

++++ libeconf:

  - Update to version 0.7.8:
    * Fix memory access if there are a comment character inside a comment.

++++ rpm:

  - print scriptlet messages in --runposttrans
    * needed to fix leaking tmp files [bsc#1218459]
    * updated patch: posttrans.diff
  - backport architecture check fix from upstream
    * new patch: archcheck.diff
  - backport empty password fix from upstream
    * new patch: emptypw.diff
  - backport buildsys specific prep fix from upstream
    * new patch: buildsysprep.diff
  - fix memory leak in str2locale [bsc#1241052]
    * updated patch: localetag.diff

++++ python-h11:

  - Update 0.16.0:
    * Security fix (CVE-2025-43859, bsc#1241872)
    Reject certain malformed Transfer-Encoding: chunked bodies that
    were previously accepted. These could have enabled
    request-smuggling attacks when an h11-based HTTP server was placed
    behind a load balancer with a matching bug in its chunked
    handling.
    Advisory with more details:
    https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj
  - 0.15.0:
    * Reject Content-Lengths >= 1 zettabyte (1 billion terabytes) early,
    without attempting to parse the integer (#181)
  - Update to 1.0.9
    * Resolve https://github.com/advisories/GHSA-vqfr-h8mv-ghfj with h11
    dependency update. (#1008)

++++ ucode-amd:

  - Change conflicts filesystem < 84 to conflicts filesystem without
    may-perform-usrmerge. Version 84 is specific to Tumbleweed; CODE
    16 uses Version 16; yet we need to ensure we get an up-to-date
    version of filesystem. Relying on the recently introduced provides
    instructing zypp about the usrmerge is perfect for this use case.

------------------------------------------------------------------
------------------  2025-4-24  -  Apr 24 2025  -------------------
------------------------------------------------------------------

++++ transactional-update:

  - Version 5.0.3
  - When continuing a transaction that was based on the running
    system, sync new changes from /etc into the new snapshot.
    This way it behaves as-if the snapshot was booted into
    before continuing the transaction, which matches the
    behaviour of versions < 5.0.
  - Fix syncing of file times and ownership
  - Do not sync /etc/etc.syncpoint/ into the running system
    (or parent snapshot) when using --discard

++++ kernel-default:

  - scripts/check-kernel-fix: check for non upstream sha coming from VULN_GIT
    CVE-2025-40364 is refering to a stable specific vulnerability. We
    currently choke on that
    $ ./scripts/check-kernel-fix CVE-2025-40364
    Security fix for CVE-2025-40364 bsc#1241637 with CVSS 6.1
    fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    = fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    merged Could not get object for a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3. Skipping.
    No Fixes tag. Requires manual review for affected branches.
    Experts candidates:  subsystem/role=
    Link: https://git.kernel.org/linus/a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    Be more defensive and bail out on non upstream commits before prossing
    each sha for the CVE
    $ ./scripts/check-kernel-fix CVE-2025-40364
    Security fix for CVE-2025-40364 bsc#1241637 with CVSS 6.1
    a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3 is not an upstream commit
  - commit e3ed589
  - scripts/common-functions: sha_get_upstream_git_fixes be more careful about vulnerable files
    CVE.vulnerable file is not really designed for multi sha CVEs as it is
    not really easy to tell which fix they correspond to. E.g.
    $ cat CVE-2024-56705.vulnerable
    a49d25364dfb9f8a64037488a39ab1f56c5fa419
    ad85094b293e40e7a2f831b0311a389d952ebd5e
    $ cat CVE-2024-56705.sha1
    ed61c59139509f76d3592683c90dc3fdc6e23cd6
    51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    Our current implementation will print
    = ed61c5913950 ("media: atomisp: Add check for rgby_data memory allocation failure") merged v6.13-rc1~149^2~15
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    = 51b8dc5163d2 ("media: staging: atomisp: Remove driver") merged v4.18-rc1~107^2~112
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    Fixes: ad85094b293e ("Revert "media: staging: atomisp: Remove driver"") merged v5.8-rc1~162^2~125
    The output for ed61c5913950 is correct because the patch itself has
    Fixes tag. For 51b8dc5163d2 there is none so we fallback to .vulnerable
    file and it is quite clear that ad85094b293e cannot be breaker as it has
    been merged much later. The whole situation is quite confused and
    described in https://lore.kernel.org/all/2024122837-CVE-2024-56705-049b@gregkh/T/#m85050dadf9eef7608c25fe0108bee9dde056d557
    Reduce the confusion and only use .vulnerable entries which are
    ancestors of the sha so they are related from the development POV.
  - commit 1988895
  - scripts/check-kernel-fix: implement multi sha CVEs handling
    CVE-2024-56705 has two upstream commits referenced in
    VULNS_GIT/cve/published/2024/CVE-2024-56705.sha1
    Reasons for that are arguably dubious (see
    https://lore.kernel.org/all/2024122837-CVE-2024-56705-049b@gregkh/T/#m85050dadf9eef7608c25fe0108bee9dde056d557)
    but we need to be able to handle CVEs associated with several upstream
    commits anyway.
    Preparatory patches have made this quite easy. The general logic is
    that we process and report each commit on its own. The final conclusion
    is printed after all of them are processed
    $ ./scripts/check-kernel-fix CVE-2024-56705
    Security fix for CVE-2024-56705 bsc#1235568 with CVSS 4.7
    = ed61c5913950 ("media: atomisp: Add check for rgby_data memory allocation failure") merged v6.13-rc1~149^2~15
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    Experts candidates:  tiwai@suse.com (33) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/ed61c59139509f76d3592683c90dc3fdc6e23cd6
    = 51b8dc5163d2 ("media: staging: atomisp: Remove driver") merged v4.18-rc1~107^2~112
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    Fixes: ad85094b293e ("Revert "media: staging: atomisp: Remove driver"") merged v5.8-rc1~162^2~125
    Experts candidates:  tiwai@suse.com (33) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654 (Fixes v4.12)
    WW CONFIG_INTEL_ATOMISP not enabled.
    WW CONFIG_VIDEO_ATOMISP not enabled.
    All eligible branches have warnings. If they are correct then there is NO ACTION NEEDED for 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    Potential git-fixes for ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    ad85094b293e Revert "media: staging: atomisp: Remove driver"
  - commit 998742a
  - scripts/check-kernel-fix: simplify no fixes case
    If there is no fixes tag then we cannot make an authoritative call for
    affected branches. We are still trying to capture situation that no
    branches might be actually affected e.g. because the code is not
    compiled in. E.g.
    36cef585e2a3 ("media: vimc: skip .s_stream() for stopped entities") merged v6.15-rc1~174^2~26
    Fixes: adc589d2a208 ("media: vimc: Add vimc-streamer for stream control") merged v5.1-rc1~88^2~133
    Security fix for CVE-2025-22028 bsc#1241362 with CVSS 5.5
    Experts candidates:  tiwai@suse.com (33) subsystem/role="MEDIA DRIVERS"
    Link: https://git.kernel.org/linus/36cef585e2a31e4ddf33a004b0584a7a572246de
    ACTION NEEDED!
    SLE15-SP6: MANUAL: backport 36cef585e2a31e4ddf33a004b0584a7a572246de (Fixes v6.4)
    WW CONFIG_VIDEO_VIMC not enabled.
    All eligible branches have warnings. If they are correct then there is NO ACTION NEEDED
    Potential git-fixes for 36cef585e2a31e4ddf33a004b0584a7a572246de
    Nothing found
    This works properly with the current code but it makes it harder to
    add a support for multi sha cves because the number of eligible branches
    tracking and gets more involved if we have a mixed bag of shas with and
    without known breakers.
    Therefore drop the heuristic and make multi sha tracking easier. That
    means to track all shas without breakers in no_fixes_shas file.
    Existence of the file triggers print_no_fixes_warning. Also collect
    per sha "all eligible branches have warning" hint into a global warning
    file.
  - commit 0b7b897
  - scripts/common-functions: make cve2sha multi sha aware
  - scripts/cve_tools/cve2metadata.sh: support multi sha CVEs
    cve2sha relied on the VULN_GIT/scripts/cve_search but that is harder to
    post process for multi sha CVEs so find and read the $CVE.sha1 file
    directly.
    make scipts/cve2metadata multi sha CVEs aware
    $ scripts/cve_tools/cve2metadata.sh CVE-2024-56705
    ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654  score:4.7 CVE-2024-56705 bsc#1235568
    $ scripts/cve_tools/cve2metadata.sh ed61c59139509f76d3592683c90dc3fdc6e23cd6
    ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654  score:4.7 CVE-2024-56705 bsc#1235568
    $ scripts/cve_tools/cve2metadata.sh 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654  score:4.7 CVE-2024-56705 bsc#1235568
  - commit aae56b3
  - scripts/check-kernel-fix: make the whole state handling sha specific
    rename those functions to make the review easier. No function change is
    intended here.
  - commit 752b100
  - Revert "net: do not leave a dangling sk pointer, when socket
    creation fails" (git-fixes).
  - commit 4fa271e
  - net: warn, if pf->create does not clear sock->sk on error
    (git-fixes).
  - commit 5c25b73
  - Delete
    patches.suse/memcg-deprecate-memory.force_empty-knob.patch.
    we do not enable CONFIG_MEMCG_V1 anymore
  - commit 38e2616
  - re-enable patches.suse/mm-inform-about-enabling-mirrored-memory.patch
    reasons for having the patch are still true
  - commit fe7580c
  - Delete
    patches.suse/mm-Warn-users-of-node-memory-hot-remove-if-the-memory-ratio-is-a-high-risk.patch.
    We haven't received any warning report so it seems this is not a real
    life problem. Drop the patch to minimize the divergence from upstream
  - commit f02479f
  - Refresh patches.suse/kabi-reserve-cpuid-leaves.patch.
  - commit e69c277
  - ethtool: cmis_cdb: use correct rpl size in
    ethtool_cmis_module_poll() (git-fixes).
  - net: ethtool: Don't call .cleanup_data when prepare_data fails
    (git-fixes).
  - net: ethtool: fix ethtool_ringparam_get_cfg() returns a
    hds_thresh value always as 0 (git-fixes).
  - net: ethtool: tsinfo: Fix dump command (git-fixes).
  - net: ethtool: netlink: Allow NULL nlattrs when getting a
    phy_device (git-fixes).
  - ethtool: ntuple: fix rss + ring_cookie check (git-fixes).
  - ethtool: rss: fix hiding unsupported fields in dumps
    (git-fixes).
  - ethtool: Fix set RXNFC command with symmetric RSS hash
    (git-fixes).
  - ethtool: Fix wrong mod state in case of verbose and no_mask
    bitset (git-fixes).
  - commit 2ee5bc4
  - Test the correct macro to detect RT kernel build
    Fixes: 470cd1a41502 ("kernel-binary: Support livepatch_rt with merged RT branch")
  - commit 50e863e
  - Update config files.
  - commit f1cfbf4

++++ kernel-firmware-iwlwifi:

  - Update to version 20250423 (git commit c67433231cbd):
    * iwlwifi: add Bz/gl FW for core95-82 release
    * iwlwifi: update ty/So/Ma firmwares for core95-82 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core95-82 release

++++ kernel-rt:

  - scripts/check-kernel-fix: check for non upstream sha coming from VULN_GIT
    CVE-2025-40364 is refering to a stable specific vulnerability. We
    currently choke on that
    $ ./scripts/check-kernel-fix CVE-2025-40364
    Security fix for CVE-2025-40364 bsc#1241637 with CVSS 6.1
    fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    = fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    merged Could not get object for a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3. Skipping.
    No Fixes tag. Requires manual review for affected branches.
    Experts candidates:  subsystem/role=
    Link: https://git.kernel.org/linus/a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    fatal: bad object a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3
    Be more defensive and bail out on non upstream commits before prossing
    each sha for the CVE
    $ ./scripts/check-kernel-fix CVE-2025-40364
    Security fix for CVE-2025-40364 bsc#1241637 with CVSS 6.1
    a94592ec30ff67dc36c424327f1e0a9ceeeb9bd3 is not an upstream commit
  - commit e3ed589
  - scripts/common-functions: sha_get_upstream_git_fixes be more careful about vulnerable files
    CVE.vulnerable file is not really designed for multi sha CVEs as it is
    not really easy to tell which fix they correspond to. E.g.
    $ cat CVE-2024-56705.vulnerable
    a49d25364dfb9f8a64037488a39ab1f56c5fa419
    ad85094b293e40e7a2f831b0311a389d952ebd5e
    $ cat CVE-2024-56705.sha1
    ed61c59139509f76d3592683c90dc3fdc6e23cd6
    51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    Our current implementation will print
    = ed61c5913950 ("media: atomisp: Add check for rgby_data memory allocation failure") merged v6.13-rc1~149^2~15
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    = 51b8dc5163d2 ("media: staging: atomisp: Remove driver") merged v4.18-rc1~107^2~112
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    Fixes: ad85094b293e ("Revert "media: staging: atomisp: Remove driver"") merged v5.8-rc1~162^2~125
    The output for ed61c5913950 is correct because the patch itself has
    Fixes tag. For 51b8dc5163d2 there is none so we fallback to .vulnerable
    file and it is quite clear that ad85094b293e cannot be breaker as it has
    been merged much later. The whole situation is quite confused and
    described in https://lore.kernel.org/all/2024122837-CVE-2024-56705-049b@gregkh/T/#m85050dadf9eef7608c25fe0108bee9dde056d557
    Reduce the confusion and only use .vulnerable entries which are
    ancestors of the sha so they are related from the development POV.
  - commit 1988895
  - scripts/check-kernel-fix: implement multi sha CVEs handling
    CVE-2024-56705 has two upstream commits referenced in
    VULNS_GIT/cve/published/2024/CVE-2024-56705.sha1
    Reasons for that are arguably dubious (see
    https://lore.kernel.org/all/2024122837-CVE-2024-56705-049b@gregkh/T/#m85050dadf9eef7608c25fe0108bee9dde056d557)
    but we need to be able to handle CVEs associated with several upstream
    commits anyway.
    Preparatory patches have made this quite easy. The general logic is
    that we process and report each commit on its own. The final conclusion
    is printed after all of them are processed
    $ ./scripts/check-kernel-fix CVE-2024-56705
    Security fix for CVE-2024-56705 bsc#1235568 with CVSS 4.7
    = ed61c5913950 ("media: atomisp: Add check for rgby_data memory allocation failure") merged v6.13-rc1~149^2~15
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    Experts candidates:  tiwai@suse.com (33) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/ed61c59139509f76d3592683c90dc3fdc6e23cd6
    = 51b8dc5163d2 ("media: staging: atomisp: Remove driver") merged v4.18-rc1~107^2~112
    Fixes: a49d25364dfb ("staging/atomisp: Add support for the Intel IPU v2") merged v4.12-rc1~84^2~796
    Fixes: ad85094b293e ("Revert "media: staging: atomisp: Remove driver"") merged v5.8-rc1~162^2~125
    Experts candidates:  tiwai@suse.com (33) subsystem/role="DRIVERS"
    Link: https://git.kernel.org/linus/51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    ACTION NEEDED!
    SLE12-SP5: MANUAL: backport 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654 (Fixes v4.12)
    WW CONFIG_INTEL_ATOMISP not enabled.
    WW CONFIG_VIDEO_ATOMISP not enabled.
    All eligible branches have warnings. If they are correct then there is NO ACTION NEEDED for 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    Potential git-fixes for ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    ad85094b293e Revert "media: staging: atomisp: Remove driver"
  - commit 998742a
  - scripts/check-kernel-fix: simplify no fixes case
    If there is no fixes tag then we cannot make an authoritative call for
    affected branches. We are still trying to capture situation that no
    branches might be actually affected e.g. because the code is not
    compiled in. E.g.
    36cef585e2a3 ("media: vimc: skip .s_stream() for stopped entities") merged v6.15-rc1~174^2~26
    Fixes: adc589d2a208 ("media: vimc: Add vimc-streamer for stream control") merged v5.1-rc1~88^2~133
    Security fix for CVE-2025-22028 bsc#1241362 with CVSS 5.5
    Experts candidates:  tiwai@suse.com (33) subsystem/role="MEDIA DRIVERS"
    Link: https://git.kernel.org/linus/36cef585e2a31e4ddf33a004b0584a7a572246de
    ACTION NEEDED!
    SLE15-SP6: MANUAL: backport 36cef585e2a31e4ddf33a004b0584a7a572246de (Fixes v6.4)
    WW CONFIG_VIDEO_VIMC not enabled.
    All eligible branches have warnings. If they are correct then there is NO ACTION NEEDED
    Potential git-fixes for 36cef585e2a31e4ddf33a004b0584a7a572246de
    Nothing found
    This works properly with the current code but it makes it harder to
    add a support for multi sha cves because the number of eligible branches
    tracking and gets more involved if we have a mixed bag of shas with and
    without known breakers.
    Therefore drop the heuristic and make multi sha tracking easier. That
    means to track all shas without breakers in no_fixes_shas file.
    Existence of the file triggers print_no_fixes_warning. Also collect
    per sha "all eligible branches have warning" hint into a global warning
    file.
  - commit 0b7b897
  - scripts/common-functions: make cve2sha multi sha aware
  - scripts/cve_tools/cve2metadata.sh: support multi sha CVEs
    cve2sha relied on the VULN_GIT/scripts/cve_search but that is harder to
    post process for multi sha CVEs so find and read the $CVE.sha1 file
    directly.
    make scipts/cve2metadata multi sha CVEs aware
    $ scripts/cve_tools/cve2metadata.sh CVE-2024-56705
    ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654  score:4.7 CVE-2024-56705 bsc#1235568
    $ scripts/cve_tools/cve2metadata.sh ed61c59139509f76d3592683c90dc3fdc6e23cd6
    ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654  score:4.7 CVE-2024-56705 bsc#1235568
    $ scripts/cve_tools/cve2metadata.sh 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654
    ed61c59139509f76d3592683c90dc3fdc6e23cd6 51b8dc5163d2ff2bf04019f8bf7e3bd0e75bb654  score:4.7 CVE-2024-56705 bsc#1235568
  - commit aae56b3
  - scripts/check-kernel-fix: make the whole state handling sha specific
    rename those functions to make the review easier. No function change is
    intended here.
  - commit 752b100
  - Revert "net: do not leave a dangling sk pointer, when socket
    creation fails" (git-fixes).
  - commit 4fa271e
  - net: warn, if pf->create does not clear sock->sk on error
    (git-fixes).
  - commit 5c25b73
  - Delete
    patches.suse/memcg-deprecate-memory.force_empty-knob.patch.
    we do not enable CONFIG_MEMCG_V1 anymore
  - commit 38e2616
  - re-enable patches.suse/mm-inform-about-enabling-mirrored-memory.patch
    reasons for having the patch are still true
  - commit fe7580c
  - Delete
    patches.suse/mm-Warn-users-of-node-memory-hot-remove-if-the-memory-ratio-is-a-high-risk.patch.
    We haven't received any warning report so it seems this is not a real
    life problem. Drop the patch to minimize the divergence from upstream
  - commit f02479f
  - Refresh patches.suse/kabi-reserve-cpuid-leaves.patch.
  - commit e69c277
  - ethtool: cmis_cdb: use correct rpl size in
    ethtool_cmis_module_poll() (git-fixes).
  - net: ethtool: Don't call .cleanup_data when prepare_data fails
    (git-fixes).
  - net: ethtool: fix ethtool_ringparam_get_cfg() returns a
    hds_thresh value always as 0 (git-fixes).
  - net: ethtool: tsinfo: Fix dump command (git-fixes).
  - net: ethtool: netlink: Allow NULL nlattrs when getting a
    phy_device (git-fixes).
  - ethtool: ntuple: fix rss + ring_cookie check (git-fixes).
  - ethtool: rss: fix hiding unsupported fields in dumps
    (git-fixes).
  - ethtool: Fix set RXNFC command with symmetric RSS hash
    (git-fixes).
  - ethtool: Fix wrong mod state in case of verbose and no_mask
    bitset (git-fixes).
  - commit 2ee5bc4
  - Test the correct macro to detect RT kernel build
    Fixes: 470cd1a41502 ("kernel-binary: Support livepatch_rt with merged RT branch")
  - commit 50e863e
  - Update config files.
  - commit f1cfbf4

++++ unbound:

  - Update to 1.23.0:
    Features:
    * Increase the default of max-global-quota to 200 from 128 after
    operational feedback. Still keeping the possible amplification
    factor (CAMP related issues) in the hundreds.
    * Fix #1175: serve-expired does not adhere to secure-by-default
    principle. The default value of serve-expired-client-timeout
    is set to 1800 as suggested by RFC8767.
    * For #1175, the default value of serve-expired-ttl is set to 86400
    (1 day) as suggested by RFC8767.
    * For #1207: [FR] Support for RESINFO RRType 261 (RFC9606), add
    LDNS_RR_TYPE_RESINFO similar to LDNS_RR_TYPE_TXT.
    * Add resolver.arpa and service.arpa to the default locally served
    zones.
    * Merge #1042: Fast Reload. The unbound-control fast_reload is added.
    It reads changed config in a thread, then only briefly pauses the
    service threads, that keep running. DNS service is only interrupted
    briefly, less than a second.
    * Merge #1019: Redis read-only replica support.
    Introduces new 'redis-replica-*' options for the Redis cache backend.
    * Merge #902: DNS Error Reporting (RFC 9567). Introduces new
    configuration option 'dns-error-reporting' and new statistics for
    'num.dns_error_reports'.
    Bug Fixes:
    * Fix #1154: Tag Incorrectly Applying for Other Interfaces
    Using the Same IP. This fix is not for 1.22.0.
    * Fix #1163: Typos in unbound.conf documentation.
    * Merge #1159: Stats for discard-timeout and wait-limit.
    * Add test case for #1159.
    * Some clean up for stat_values.test.
    * Merge #1170 from Melroy van den Berg, Fix chroot manpage
    description.
    * Merge #1157 from Liang Zhu, Fix heap corruption when calling
    ub_ctx_delete in Windows.
    * Fix redis that during a reload it does not fail if the redis
    server does not connect or does not respond. It still logs the
    errors and if the server is up checks expiration features.
    * Merge #1167: Makefile.in: fix occasional parallel build failures
    around bison rule.
    * Fix SETEX check during Redis (re)initialization.
    * Fix for the serve expired DNSSEC information fix, it would not allow
    current delegation information be updated in cache. The fix allows
    current delegation and validation recursion information to be
    updated, but as a consequence no longer has certain expired
    information around for later dnssec valid expired responses.
    * Fix to log redis timeout error string on failure.
    * More descriptive text for 'harden-algo-downgrade'.
    * Complete fix for max-global-quota to 200.
    * Fix #1183: the data being used is released in method
    nsec3_hash_test_entry.
    * Fix for #1183: release nsec3 hashes per test file.
    * Merge #1169 from Sergey Kacheev, fix: lock-free counters for
    auth_zone up/down queries.
    * Fix comparison to help static analyzer.
    * For #1175, update serve-expired tests.
    * Merge #1189: Fix the dname_str method to cause conversion errors
    when the domain name length is 255.
    * Merge #1197: dname_str() fixes.
    * Merge #1198: Fix log-servfail with serve expired and no useful cache
    contents.
    * Safeguard alias loop while looking in the cache for expired answers.
    * Merge #1187: Create the SSL_CTX for QUIC before chroot and privilege
    drop.
    * Fix typo in log_servfail.tdir test.
    * Merge #1204: ci: set persist-credentials: false for actions/checkout
    per zizmor suggestion.
    * Merge #1174: Serve expired cache update fixes. Fixes a regression bug
    with serve-expired that appeared in 1.22.0 and would not allow the
    iterator to update the cache with not-yet-validated entries resulting
    in increased outgoing traffic.
    * Merge #1214: Use TCP_NODELAY on TLS sockets to speed up the TLS
    handshake.
    * Fix #1213: Misleading error message on default access control causing
    refuse.
    * Merge #1221: Consider auth zones when checking for forwarders.
    * Merge #1222: Unique DoT and DoH SSL contexts to allow for different
    ALPN.
    * Create the quic SSL listening context only when needed.
    * Fix compile of interface check code when dnscrypt or quic is
    disabled.
    * Fix encoding of RR type ATMA.
    * Fix to check length in ATMA string to wire.
    * Merge #1229: check before use daemon->shm_info.
    * Use the same interface listening port discovery code for all needed
    protocols.
    * Port to string only when needed before getaddrinfo().
    * Do not open unencrypted channels next to encrypted ones on the same
    port.
    * Merge #1224 from Theo Buehler: Do not use DSA API unless USE_DSA is
    set.
    * Merge #1220 from Petr Menšík, Add unbound members group access to
    control key.
    * Make the default value of module-config "validator iterator"
    regardless of compilation options. --enable-subnet would implicitly
    change the value to enable the subnetcache module by default in the
    past.
    * Fix #986: Resolving sas.com with dnssec-validation fails though
    signed delegations seem to be (mostly) correct.
    Consider reconfigurations when calculating the still_useful_timeout
    for servers in the infrastructure cache.
    * Fix static analysis report about unhandled EOF on error conditions
    when reading anchor key files.
    * Merge #1241: Fix infra-keep-probing for low infra-cache-max-rtt
    values.
    * Fix hash calculation for cachedb to ignore case. Previously, cached
    records there were only relevant for same case queries (if not
    already in Unbound's internal cache).
    * Merge #1243: Do not shadow tm on line 236.
    * Merge #1238: Prefer SOURCE_DATE_EPOCH over actual time.
    Add --help output description for the SOURCE_DATE_EPOCH variable.
    * Fix 'unbound-control flush_negative' when reporting removed data;
    reported by David 'eqvinox' Lamparter.
    * Fix representation of types GPOS and RESINFO, add rdf type for
    unquoted str.
    * Fix #1251: WSAPoll first argument cannot be NULL.
    * Fix for windows compile create ssl contexts.
    * Fix print of RR type NSAP-PTR, it is an unquoted string.
    * Fix #1253: Cache entries fail to be removed from Redis cachedb
    backend with unbound-control flush* +c.
    * Fix for #1253: Fix for redis cachedb backend to expect an integer
    reply for the EXPIRE command.
    * Fix #1254: send failed: Socket is not connected and
    remote address is 0.0.0.0 port 53.
    * Fix #1255: Multiple pinnings to vulnerable copies of libexpat.
    * For #1255, for ios use an older expat version that does not require
    C++11 language features.
    * For #1255, for ios disable building tests that require C++11.
    * For #1255, for ios try the latest expat version again.
    * Fix unit test dname log printout typecast.
    * Fix for ci test, expat is installed on the osx image.
    * iana portlist update.
    * Skip the unit tests for auth_tls.tdir and auth_tls_failcert.tdir.
    * Fix escape more characters when printing an RR type with an unquoted
    string.
    * Enable the auth_tls.tdir and auth_tls_failcert.tdir tests.
    * Fix unbound-control test so it counts the new flush_negative output,
    also answers the _ta probe from testns and prints command output
    and skip a thread specific test when no threads are available.
    * Fix that ub_event has the facility to deal with callbacks for
    fast reload, doq, windows-stop and dnstap.
    * Fix fast reload test to check if pid exists before acting on it.
    * Merge #1262 from markyang92, fix build with
    'gcc-15 -Wbuiltin-declaration-mismatch' error in compat/malloc.c.
    * For #1262, ifdef is no longer needed.
    * Fix #1263: Exempt loopback addresses from wait-limit.
    * Fix wait-limit-netblock and wait-limit-cookie-netblock config parse
    to allow two arguments.
    * Fix ub_event and include dnstap and win_svc headers.
    * Fix test for stat_values for wait limit defaults for localhost.
    * Fix parameter unused warning in net_help.c.
    * Fix mesh_copy_client_info to omit null contents from copy.
    * Fix comment name in the rpz nsdname test.
    * Fix nettle compile for warnings and ticket keys.
    * Fix redis_replica test for unused option defaults and log printout.
    * Fix test to speed up common.sh script kill_pid.
    * Fix to update common.sh for speed of kill_pid.
    * Update to the manpage for the fast_reload part.
    * Fix fast_reload to print chroot with config file name.
    * Fix to detect if atomic_store links in configure.
    * Fix #1264: unbound 1.22.0 leaks memory when doing DoH.
    * Fix for print of connection type in log-replies for dot and doh.
    * Merge #1265: Fix WSAPoll.

------------------------------------------------------------------
------------------  2025-4-23  -  Apr 23 2025  -------------------
------------------------------------------------------------------

++++ augeas:

  - Add patch, fix for bsc#1239909 / CVE-2025-2588:
    * CVE-2025-2588.patch

++++ branding-SLE:

  - Do not build main package as noarch, as we're actually looking at the
    build architecture in the spec file itself to control which
    subpackages to build. Required after rpm 4.20 update.

++++ grub2:

  - Add support for boot assessment, needed by health-checker
    * grub2-bls-boot-counting.patch
    * grub2-bls-boot-assessment.patch
    * grub2-bls-boot-show-snapshot.patch
    * grub2-blscfg-fix-hang.patch
    * grub2-blscfg-set-efivars.patch
  - Fix reading bls fragments in file-system dependent order that is not
    predictable (bsc#1241046)
    * 0001-blscfg-read-fragments-in-order.patch
  - Fix PPC CAS reboot failure work when initiated via submenu (bsc#1241132)
    * 0001-Fix-PowerPC-CAS-reboot-to-evaluate-menu-context.patch

++++ kernel-default:

  - scsi: smartpqi: Use is_kdump_kernel() to check for kdump
    (git-fixes).
  - Refresh
    patches.suse/scsi-use-block-layer-helpers-to-calculate-num-of-queues.patch.
  - commit fc8ffe9
  - scsi: iscsi: Fix missing scsi_host_put() in error path
    (git-fixes).
  - scsi: hisi_sas: Enable force phy when SATA disk directly
    connected (git-fixes).
  - scsi: lpfc: Restore clearing of NLP_UNREG_INP in ndlp->nlp_flag
    (git-fixes).
  - scsi: hisi_sas: Fixed failure to issue vendor specific commands
    (git-fixes).
  - scsi: scsi_debug: Remove a reference to in_use_bm (git-fixes).
  - scsi: mpt3sas: Fix a locking bug in an error path (git-fixes).
  - scsi: mpi3mr: Fix locking in an error path (git-fixes).
  - scsi: mpt3sas: Reduce log level of ignore_delay_remove message
    to KERN_INFO (git-fixes).
  - commit c213b0d
  - kernel-source: Also update the search to match bin/env
    Fixes: dc2037cd8f94 ("kernel-source: Also replace bin/env"
  - commit bae6b69
  - xen: fix multicall debug feature (git-fixes).
  - commit 22440da
  - x86/xen: fix balloon target initialization for PVH dom0
    (git-fixes).
  - commit 3ec180c
  - xenfs/xensyms: respect hypervisor's "next" indication
    (git-fixes).
  - commit 25e2e64
  - s390/virtio_ccw: Don't allocate/assign airqs for non-existing
    queues (git-fixes).
  - commit 39793ac
  - vhost-scsi: Fix handling of multiple calls to
    vhost_scsi_set_endpoint (git-fixes).
  - commit 3b90d10
  - tools: virtio/linux/module.h add MODULE_DESCRIPTION() define
    (git-fixes).
  - commit bb13108
  - virtio_net: Allocate rss_hdr with devres (git-fixes).
  - commit b12f322
  - rpm/check-for-config-changes: Add GCC_ASM_FLAG_OUTPUT_BROKEN
    Both spellings are actually used
  - rpm/check-for-config-changes: Add GCC_ASM_FLAG_OUTPUT_BROKEN
  - commit d9e0b30
  - virtio_net: Fix endian with virtio_net_ctrl_rss (git-fixes).
  - commit ce0974f
  - KVM: x86: block KVM_CAP_SYNC_REGS if guest state is protected
    (git-fixes).
  - commit 81808c0
  - KVM: x86: Set PVCLOCK_GUEST_STOPPED only for kvmclock, not
    for Xen PV clock (git-fixes).
  - commit 0786f06
  - KVM: x86: Don't bleed PVCLOCK_GUEST_STOPPED across PV clocks
    (git-fixes).
  - commit 29423ad
  - KVM: x86: Process "guest stopped request" once per guest time
    update (git-fixes).
  - commit 036561e
  - KVM: x86: Drop local pvclock_flags variable in
    kvm_guest_time_update() (git-fixes).
  - commit 992c7b0
  - KVM: x86/xen: Use guest's copy of pvclock when starting timer
    (git-fixes).
  - commit 3737391
  - KVM: x86: Don't take kvm->lock when iterating over vCPUs in
    suspend notifier (git-fixes).
  - commit 6a2158b
  - KVM: SVM: Don't change target vCPU state on AP Creation VMGEXIT
    error (git-fixes).
  - commit fb05255
  - KVM: SVM: Refuse to attempt VRMUN if an SEV-ES+ guest has an
    invalid VMSA (git-fixes).
  - commit f1a16f5
  - KVM: SVM: Inject #GP if memory operand for INVPCID is
    non-canonical (git-fixes).
  - commit c2abbd2
  - KVM: VMX: Don't modify guest XFD_ERR if CR0.TS=1 (git-fixes).
  - commit 3071379
  - KVM: x86: Remove the unreachable case for 0x80000022 leaf in
    __do_cpuid_func() (git-fixes).
  - commit faa824f
  - KVM: x86: Don't inject PV async #PF if SEND_ALWAYS=0 and guest
    state is protected (git-fixes).
  - commit 8f330f9
  - KVM: nVMX: Allow emulating RDPID on behalf of L2 (git-fixes).
  - commit ec3ab2c
  - KVM: nSVM: Pass next RIP, not current RIP, for nested VM-Exit
    on emulation (git-fixes).
  - commit 42350b0
  - KVM: nVMX: Check PAUSE_EXITING, not BUS_LOCK_DETECTION, on
    PAUSE emulation (git-fixes).
  - commit cda8eef
  - KVM: x86: Clear pv_unhalted on all transitions to
    KVM_MP_STATE_RUNNABLE (git-fixes).
  - commit 7a65819
  - KVM: x86: Introduce kvm_set_mp_state() (git-fixes).
  - commit 04a2570
  - scripts/check-kernel-fix: prepare for per sha runs
    isolate sha and per CVE actions. Everything sha specific should live
    in handle_single_sha now.
  - commit 17c1590
  - KVM: x86: Wake vCPU for PIC interrupt injection iff a valid
    IRQ was found (git-fixes).
  - commit c642d0c
  - bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags
    (git-fixes).
  - commit e6dede3
  - atm: Fix NULL pointer dereference (git-fixes).
  - commit 8fb9132
  - net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF
    (git-fixes).
  - commit 7729588
  - Update
    patches.suse/net-fix-geneve_opt-length-integer-overflow.patch
    references (add CVE-2025-22055 bsc#1241371).
  - commit ba1e8a4
  - KVM: arm64: Use acquire/release to communicate FF-A version
    negotiation (git-fixes).
  - commit 50cc346
  - xsk: fix an integer overflow in xp_create_and_assign_umem()
    (git-fixes).
  - commit 7c4fb15
  - net: ipv6: fix TCP GSO segmentation with NAT (git-fixes).
  - commit 1c017db
  - net-timestamp: support TCP GSO case for a few missing flags
    (git-fixes).
  - commit c208f95
  - KVM: Allow building irqbypass.ko as as module when kvm.ko is
    a module (git-fixes).
  - commit 9b20684
  - net: Clear old fragment checksum value in napi_reuse_skb
    (git-fixes).
  - commit 2ce58e9
  - net: set the minimum for net_hotdata.netdev_budget_usecs
    (git-fixes).
  - commit 5ddd8ac
  - bpf: Disable non stream socket for strparser (git-fixes).
  - commit 7c4cfd5
  - bpf: Remove unnecessary BTF lookups in
    bpf_sk_storage_tracing_allowed (git-fixes).
  - commit 25b1d5d
  - KVM: arm64: PMU: Fix SET_ONE_REG for vPMC regs (git-fixes).
  - commit 2ecc7b5
  - net: fib_rules: annotate data-races around rule->ifindex
    (git-fixes).
  - commit cdcb902
  - udp: gso: do not drop small packets when PMTU reduces
    (git-fixes).
  - commit ab8803f
  - KVM: arm64: PMU: Set raw values from user to
    PM{C,I}NTEN{SET,CLR}, PMOVS{SET,CLR} (git-fixes).
  - commit a2da974
  - KVM: arm64: Copy guest CTR_EL0 into hyp VM (git-fixes).
  - commit d73af3d
  - bpf: Fix bpf_sk_select_reuseport() memory leak (git-fixes).
  - commit 7a6f651
  - bpf: Check negative offsets in __bpf_skb_min_len() (git-fixes).
  - commit e2c022f
  - tcp_bpf: Add sk_rmem_alloc related logic for tcp_bpf ingress
    redirection (git-fixes).
  - commit 4150633
  - tcp_bpf: Charge receive socket buffer in bpf_tcp_ingress()
    (git-fixes).
  - commit b09f3a4
  - bpf, sockmap: Fix update element with same (git-fixes).
  - commit 00fcef8
  - xsk: always clear DMA mapping information when unmapping the
    pool (git-fixes).
  - commit 839ef64
  - KVM: arm64: Set HCR_EL2.TID1 unconditionally (git-fixes).
  - commit 2a6d624
  - 9p/xen: fix init sequence (git-fixes).
  - commit 557d098
  - net/9p/usbg: fix handling of the failed kzalloc() memory
    allocation (git-fixes).
  - commit 27d9f0d
  - rxrpc: Improve setsockopt() handling of malformed user input
    (git-fixes).
  - commit d2d2373
  - llc: Improve setsockopt() handling of malformed user input
    (git-fixes).
  - commit cd07bbc
  - KVM: arm64: vgic-v4: Fall back to software irqbypass if LPI
    not found (git-fixes).
  - commit fa659dd
  - bpf, sockmap: Fix sk_msg_reset_curr (git-fixes).
  - commit c954950
  - KVM: arm64: vgic-v4: Only attempt vLPI mapping for actual MSIs
    (git-fixes).
  - commit 1fc4218
  - bpf, sockmap: Several fixes to bpf_msg_push_data (git-fixes).
  - commit 6a7ee1c
  - scripts/check-kernel-fix: move all the single sha processing into handle_single_sha
    No functional change intended.
  - commit d024b31
  - mm: memory-failure: update ttu flag inside unmap_poisoned_folio
    (CVE-2025-21907 bsc#1240588).
    Refreshed:
    patches.suse/0001-hwpoison-memory_hotplug-lock-folio-before-unmap-hwpo.patch
  - commit d0121cb
  - mm/migrate: fix shmem xarray update during migration
    (CVE-2025-22015 bsc#1240944).
  - commit fe6b387
  - scripts/check-kernel-fix: prepare for multi sha CVEs
    c-k-f supports reverse mapping to a CVE when given a sha
    ./scripts/check-kernel-fix 5701875f9609
    Security fix for CVE-2025-22121 bsc#1241593 with CVSS 5.5
    5701875f9609 ("ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()") merged v6.15-rc1~145^2~16
    Fixes: e50e5129f384 ("ext4: xattr-in-inode support") merged v4.13-rc1~85^2~45
    [...]
    unify both CVE and sha paths to store CVE shas to cve_shas so that
    we are not mixing up sha used all over the place. In the next step
    we will iterate over multiple shas if they are associated with a CVE.
  - commit 0aa8f42
  - scripts/check-kernel-fix: print CVE info before sha
    this is a preparatory work to allow a single CVE to refer to multiple
    commits.
  - commit d1012d6
  - hwpoison, memory_hotplug: lock folio before unmap hwpoisoned
    folio (CVE-2025-21931 bsc#1240709).
  - commit bac57bd
  - PCI/MSI: Add an option to write MSIX ENTRY_DATA before any reads
    (git-fixes).
  - irqchip/davinci: Remove leftover header (git-fixes).
  - tty: serial: lpuart: only disable CTS instead of overwriting
    the whole UARTMODIR register (git-fixes).
  - commit 766c734
  - Update config files (set re-set CONFIG_DRM_MSM_VALIDATE_XML=n).
    This disappeared during merges:
    acf9414cc3c603ab6c14e333e7815bffda62c250
    f94b1c184933d28d9f3a47941de5779c4a52f56b
  - commit 7d8dbec
  - Revert "tty/serial: Add kgdb_nmi driver" (git-fixes).
  - Update config files.
  - serial: kgdb_nmi: Remove unused knock code (git-fixes).
  - commit b9aff0c
  - iommu: Allow attaching static domains in
    iommu_attach_device_pasid() (bsc#1241193).
  - Delete
    patches.suse/iommu-vt-d-Assign-owner-to-the-static-identity-domai.patch.
  - commit f738282
  - selftests/bpf: extend changes_pkt_data with cases w/o
    subprograms (bsc#1241590).
  - bpf: fix null dereference when computing changes_pkt_data of
    prog w/o subprogs (bsc#1241590).
  - selftests/bpf: freplace tests for tracking of
    changes_packet_data (bsc#1241590).
  - commit 45d15f6
  - bpf: check changes_pkt_data property for extension programs
    (bsc#1241590).
  - selftests/bpf: test for changing packet data from global
    functions (bsc#1241590).
  - Refresh patches.suse/selftests-bpf-validate-that-tail-call-invalidates-pa.patch
  - bpf: track changes_pkt_data property for global functions
    (bsc#1241590).
  - bpf: add find_containing_subprog() utility function
    (bsc#1241590).
  - commit 11de59b

++++ kernel-firmware-iwlwifi:

  - Update to version 20250422 (git commit 32f3227b67c0):
    * iwlwifi: add Bz-hr FW for core93-123 release

++++ kernel-rt:

  - scsi: smartpqi: Use is_kdump_kernel() to check for kdump
    (git-fixes).
  - Refresh
    patches.suse/scsi-use-block-layer-helpers-to-calculate-num-of-queues.patch.
  - commit fc8ffe9
  - scsi: iscsi: Fix missing scsi_host_put() in error path
    (git-fixes).
  - scsi: hisi_sas: Enable force phy when SATA disk directly
    connected (git-fixes).
  - scsi: lpfc: Restore clearing of NLP_UNREG_INP in ndlp->nlp_flag
    (git-fixes).
  - scsi: hisi_sas: Fixed failure to issue vendor specific commands
    (git-fixes).
  - scsi: scsi_debug: Remove a reference to in_use_bm (git-fixes).
  - scsi: mpt3sas: Fix a locking bug in an error path (git-fixes).
  - scsi: mpi3mr: Fix locking in an error path (git-fixes).
  - scsi: mpt3sas: Reduce log level of ignore_delay_remove message
    to KERN_INFO (git-fixes).
  - commit c213b0d
  - kernel-source: Also update the search to match bin/env
    Fixes: dc2037cd8f94 ("kernel-source: Also replace bin/env"
  - commit bae6b69
  - xen: fix multicall debug feature (git-fixes).
  - commit 22440da
  - x86/xen: fix balloon target initialization for PVH dom0
    (git-fixes).
  - commit 3ec180c
  - xenfs/xensyms: respect hypervisor's "next" indication
    (git-fixes).
  - commit 25e2e64
  - s390/virtio_ccw: Don't allocate/assign airqs for non-existing
    queues (git-fixes).
  - commit 39793ac
  - vhost-scsi: Fix handling of multiple calls to
    vhost_scsi_set_endpoint (git-fixes).
  - commit 3b90d10
  - tools: virtio/linux/module.h add MODULE_DESCRIPTION() define
    (git-fixes).
  - commit bb13108
  - virtio_net: Allocate rss_hdr with devres (git-fixes).
  - commit b12f322
  - rpm/check-for-config-changes: Add GCC_ASM_FLAG_OUTPUT_BROKEN
    Both spellings are actually used
  - rpm/check-for-config-changes: Add GCC_ASM_FLAG_OUTPUT_BROKEN
  - commit d9e0b30
  - virtio_net: Fix endian with virtio_net_ctrl_rss (git-fixes).
  - commit ce0974f
  - KVM: x86: block KVM_CAP_SYNC_REGS if guest state is protected
    (git-fixes).
  - commit 81808c0
  - KVM: x86: Set PVCLOCK_GUEST_STOPPED only for kvmclock, not
    for Xen PV clock (git-fixes).
  - commit 0786f06
  - KVM: x86: Don't bleed PVCLOCK_GUEST_STOPPED across PV clocks
    (git-fixes).
  - commit 29423ad
  - KVM: x86: Process "guest stopped request" once per guest time
    update (git-fixes).
  - commit 036561e
  - KVM: x86: Drop local pvclock_flags variable in
    kvm_guest_time_update() (git-fixes).
  - commit 992c7b0
  - KVM: x86/xen: Use guest's copy of pvclock when starting timer
    (git-fixes).
  - commit 3737391
  - KVM: x86: Don't take kvm->lock when iterating over vCPUs in
    suspend notifier (git-fixes).
  - commit 6a2158b
  - KVM: SVM: Don't change target vCPU state on AP Creation VMGEXIT
    error (git-fixes).
  - commit fb05255
  - KVM: SVM: Refuse to attempt VRMUN if an SEV-ES+ guest has an
    invalid VMSA (git-fixes).
  - commit f1a16f5
  - KVM: SVM: Inject #GP if memory operand for INVPCID is
    non-canonical (git-fixes).
  - commit c2abbd2
  - KVM: VMX: Don't modify guest XFD_ERR if CR0.TS=1 (git-fixes).
  - commit 3071379
  - KVM: x86: Remove the unreachable case for 0x80000022 leaf in
    __do_cpuid_func() (git-fixes).
  - commit faa824f
  - KVM: x86: Don't inject PV async #PF if SEND_ALWAYS=0 and guest
    state is protected (git-fixes).
  - commit 8f330f9
  - KVM: nVMX: Allow emulating RDPID on behalf of L2 (git-fixes).
  - commit ec3ab2c
  - KVM: nSVM: Pass next RIP, not current RIP, for nested VM-Exit
    on emulation (git-fixes).
  - commit 42350b0
  - KVM: nVMX: Check PAUSE_EXITING, not BUS_LOCK_DETECTION, on
    PAUSE emulation (git-fixes).
  - commit cda8eef
  - KVM: x86: Clear pv_unhalted on all transitions to
    KVM_MP_STATE_RUNNABLE (git-fixes).
  - commit 7a65819
  - KVM: x86: Introduce kvm_set_mp_state() (git-fixes).
  - commit 04a2570
  - scripts/check-kernel-fix: prepare for per sha runs
    isolate sha and per CVE actions. Everything sha specific should live
    in handle_single_sha now.
  - commit 17c1590
  - KVM: x86: Wake vCPU for PIC interrupt injection iff a valid
    IRQ was found (git-fixes).
  - commit c642d0c
  - bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags
    (git-fixes).
  - commit e6dede3
  - atm: Fix NULL pointer dereference (git-fixes).
  - commit 8fb9132
  - net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF
    (git-fixes).
  - commit 7729588
  - Update
    patches.suse/net-fix-geneve_opt-length-integer-overflow.patch
    references (add CVE-2025-22055 bsc#1241371).
  - commit ba1e8a4
  - KVM: arm64: Use acquire/release to communicate FF-A version
    negotiation (git-fixes).
  - commit 50cc346
  - xsk: fix an integer overflow in xp_create_and_assign_umem()
    (git-fixes).
  - commit 7c4fb15
  - net: ipv6: fix TCP GSO segmentation with NAT (git-fixes).
  - commit 1c017db
  - net-timestamp: support TCP GSO case for a few missing flags
    (git-fixes).
  - commit c208f95
  - KVM: Allow building irqbypass.ko as as module when kvm.ko is
    a module (git-fixes).
  - commit 9b20684
  - net: Clear old fragment checksum value in napi_reuse_skb
    (git-fixes).
  - commit 2ce58e9
  - net: set the minimum for net_hotdata.netdev_budget_usecs
    (git-fixes).
  - commit 5ddd8ac
  - bpf: Disable non stream socket for strparser (git-fixes).
  - commit 7c4cfd5
  - bpf: Remove unnecessary BTF lookups in
    bpf_sk_storage_tracing_allowed (git-fixes).
  - commit 25b1d5d
  - KVM: arm64: PMU: Fix SET_ONE_REG for vPMC regs (git-fixes).
  - commit 2ecc7b5
  - net: fib_rules: annotate data-races around rule->ifindex
    (git-fixes).
  - commit cdcb902
  - udp: gso: do not drop small packets when PMTU reduces
    (git-fixes).
  - commit ab8803f
  - KVM: arm64: PMU: Set raw values from user to
    PM{C,I}NTEN{SET,CLR}, PMOVS{SET,CLR} (git-fixes).
  - commit a2da974
  - KVM: arm64: Copy guest CTR_EL0 into hyp VM (git-fixes).
  - commit d73af3d
  - bpf: Fix bpf_sk_select_reuseport() memory leak (git-fixes).
  - commit 7a6f651
  - bpf: Check negative offsets in __bpf_skb_min_len() (git-fixes).
  - commit e2c022f
  - tcp_bpf: Add sk_rmem_alloc related logic for tcp_bpf ingress
    redirection (git-fixes).
  - commit 4150633
  - tcp_bpf: Charge receive socket buffer in bpf_tcp_ingress()
    (git-fixes).
  - commit b09f3a4
  - bpf, sockmap: Fix update element with same (git-fixes).
  - commit 00fcef8
  - xsk: always clear DMA mapping information when unmapping the
    pool (git-fixes).
  - commit 839ef64
  - KVM: arm64: Set HCR_EL2.TID1 unconditionally (git-fixes).
  - commit 2a6d624
  - 9p/xen: fix init sequence (git-fixes).
  - commit 557d098
  - net/9p/usbg: fix handling of the failed kzalloc() memory
    allocation (git-fixes).
  - commit 27d9f0d
  - rxrpc: Improve setsockopt() handling of malformed user input
    (git-fixes).
  - commit d2d2373
  - llc: Improve setsockopt() handling of malformed user input
    (git-fixes).
  - commit cd07bbc
  - KVM: arm64: vgic-v4: Fall back to software irqbypass if LPI
    not found (git-fixes).
  - commit fa659dd
  - bpf, sockmap: Fix sk_msg_reset_curr (git-fixes).
  - commit c954950
  - KVM: arm64: vgic-v4: Only attempt vLPI mapping for actual MSIs
    (git-fixes).
  - commit 1fc4218
  - bpf, sockmap: Several fixes to bpf_msg_push_data (git-fixes).
  - commit 6a7ee1c
  - scripts/check-kernel-fix: move all the single sha processing into handle_single_sha
    No functional change intended.
  - commit d024b31
  - mm: memory-failure: update ttu flag inside unmap_poisoned_folio
    (CVE-2025-21907 bsc#1240588).
    Refreshed:
    patches.suse/0001-hwpoison-memory_hotplug-lock-folio-before-unmap-hwpo.patch
  - commit d0121cb
  - mm/migrate: fix shmem xarray update during migration
    (CVE-2025-22015 bsc#1240944).
  - commit fe6b387
  - scripts/check-kernel-fix: prepare for multi sha CVEs
    c-k-f supports reverse mapping to a CVE when given a sha
    ./scripts/check-kernel-fix 5701875f9609
    Security fix for CVE-2025-22121 bsc#1241593 with CVSS 5.5
    5701875f9609 ("ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()") merged v6.15-rc1~145^2~16
    Fixes: e50e5129f384 ("ext4: xattr-in-inode support") merged v4.13-rc1~85^2~45
    [...]
    unify both CVE and sha paths to store CVE shas to cve_shas so that
    we are not mixing up sha used all over the place. In the next step
    we will iterate over multiple shas if they are associated with a CVE.
  - commit 0aa8f42
  - scripts/check-kernel-fix: print CVE info before sha
    this is a preparatory work to allow a single CVE to refer to multiple
    commits.
  - commit d1012d6
  - hwpoison, memory_hotplug: lock folio before unmap hwpoisoned
    folio (CVE-2025-21931 bsc#1240709).
  - commit bac57bd
  - PCI/MSI: Add an option to write MSIX ENTRY_DATA before any reads
    (git-fixes).
  - irqchip/davinci: Remove leftover header (git-fixes).
  - tty: serial: lpuart: only disable CTS instead of overwriting
    the whole UARTMODIR register (git-fixes).
  - commit 766c734
  - Update config files (set re-set CONFIG_DRM_MSM_VALIDATE_XML=n).
    This disappeared during merges:
    acf9414cc3c603ab6c14e333e7815bffda62c250
    f94b1c184933d28d9f3a47941de5779c4a52f56b
  - commit 7d8dbec
  - Revert "tty/serial: Add kgdb_nmi driver" (git-fixes).
  - Update config files.
  - serial: kgdb_nmi: Remove unused knock code (git-fixes).
  - commit b9aff0c
  - iommu: Allow attaching static domains in
    iommu_attach_device_pasid() (bsc#1241193).
  - Delete
    patches.suse/iommu-vt-d-Assign-owner-to-the-static-identity-domai.patch.
  - commit f738282
  - selftests/bpf: extend changes_pkt_data with cases w/o
    subprograms (bsc#1241590).
  - bpf: fix null dereference when computing changes_pkt_data of
    prog w/o subprogs (bsc#1241590).
  - selftests/bpf: freplace tests for tracking of
    changes_packet_data (bsc#1241590).
  - commit 45d15f6
  - bpf: check changes_pkt_data property for extension programs
    (bsc#1241590).
  - selftests/bpf: test for changing packet data from global
    functions (bsc#1241590).
  - Refresh patches.suse/selftests-bpf-validate-that-tail-call-invalidates-pa.patch
  - bpf: track changes_pkt_data property for global functions
    (bsc#1241590).
  - bpf: add find_containing_subprog() utility function
    (bsc#1241590).
  - commit 11de59b

++++ kubevirt:

  - Remove custom SELinux policy from virt-launcher container

++++ ledmon:

  - Add a patch to fix string2ibpi function (bsc#1241207):
    * 260.patch

++++ lua54:

  - Fix license: it is MIT, not GPL-3.0-or-later.

++++ libssh:

  - Fix build and tests with OpenSSH >= 10.0
    * Use %make_build instead of naked make
    * Add patches:
  - libssh-CmakeLists-Fix-multiple-digit-major-version-for-OpenSSH.patch
  - libssh-misc-Fix-OpenSSH-banner-parsing.patch

++++ python-M2Crypto:

  - Update to 0.45.1:
  - ci: switch from using sha1 to sha256.
  - ci(keys): regenerate rsa*.pem keys as well
  - fix: make the package compatible with OpenSSL >= 3.4 (don’t
    rely on LEGACY crypto-policies)
  - chore: package also system_shadowing directory to make builds more reliable

------------------------------------------------------------------
------------------  2025-4-22  -  Apr 22 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.16 → 10.2.17
  - Fix key slot selection for luks reencrypt
    Depending on the type setup for a luks encrypted image, there
    might be one or two key slots available. When kiwi is requested
    to perform the reencryption process at least one key-slot and
    the proper keyfile/passphrase must be provided. This commit
    stores the information about the key-slot number for which
    a decryption information exists in the initrd. In addition to
    the code change also the corresponding integration test image
    was updated.
  - Fixed test-image-gce integration test
    python3-gcemetadata was renamed to python-gcemetadata

++++ kernel-default:

  - lib/iov_iter: fix to increase non slab folio refcount
    (bsc#1241169 (MM functional and performance backports)).
  - commit 27fbba6
  - mm: decline to manipulate the refcount on a slab page
    (bsc#1241169 (MM functional and performance backports)).
  - commit 953ff5e
  - mm: page_frag: fix a compile error when kernel is not compiled
    (bsc#1241169 (MM functional and performance backports)).
  - commit 1cfdca8
  - drm/amd/display/dml2: use vzalloc rather than kzalloc
    (bsc#1241568).
  - commit c6c7df4
  - nfsd: decrease sc_count directly if fail to queue dl_recall
    (git-fixes).
  - commit dfbd8a7
  - nfs: add missing selections of CONFIG_CRC32 (git-fixes).
  - commit 2f2f40e
  - iommu/vt-d: Assign owner to the static identity domain
    (bsc#1241193).
  - commit 4c9babf
  - nvmet-fcloop: swap list_add_tail arguments (git-fixes).
  - nvme-pci: skip nvme_write_sq_db on empty rqlist (git-fixes).
  - nvme/ioctl: don't warn on vectorized uring_cmd with fixed buffer
    (git-fixes).
  - objtool, nvmet: Fix out-of-bounds stack access in
    nvmet_ctrl_state_show() (git-fixes).
  - commit 551ee35
  - mm/page_isolation: don't pass gfp flags to
    start_isolate_page_range() (bsc#1241169 (MM functional and
    performance backports)).
  - commit 2482206
  - mm/page_isolation: don't pass gfp flags to
    isolate_single_pageblock() (bsc#1241169 (MM functional and
    performance backports)).
  - commit 3532ecf
  - mm: page_alloc: tighten up find_suitable_fallback() (bsc#1241169
    (MM functional and performance backports)).
  - mm: vmscan: fix kswapd exit condition in defrag_mode
    (bsc#1241169 (MM functional and performance backports)).
  - mm: vmscan: restore high-cpu watermark safety in kswapd
    (bsc#1241169 (MM functional and performance backports)).
  - mm: page_alloc: speed up fallbacks in rmqueue_bulk()
    (bsc#1241169 (MM functional and performance backports)).
  - mm/page_alloc: replace flag check with PageHWPoison() in check_new_page_bad().
  - mm: page_alloc: fix defrag_mode's retry & OOM path.
  - mm/page_alloc: remove unnecessary __maybe_unused in.
  - mm: page_alloc: defrag_mode kswapd/kcompactd watermarks.
  - mm: page_alloc: defrag_mode kswapd/kcompactd assistance.
  - mm: page_alloc: defrag_mode.
  - mm: page_alloc: trace type pollution from compaction.
  - mm: compaction: push watermark into compaction_suitable().
  - mm: lock PGDAT_RECLAIM_LOCKED with acquire memory ordering.
  - mm: add missing release barrier on PGDAT_RECLAIM_LOCKED.
  - mm/page_alloc: clarify should_claim_block() commentary.
  - mm/page_alloc: clarify terminology in migratetype fallback.
  - mm/page_alloc: warn on nr_reserved_highatomic underflow.
  - mm: page_alloc: group fallback functions together.
  - mm: page_alloc: remove remnants of unlocked migratetype.
  - mm: page_alloc: don't steal single pages from biggest buddy.
  - vmscan, cleanup: add for_each_managed_zone_pgdat macro.
  - mm/page_alloc: fix memory accept before watermarks gets.
  - mm/page_alloc: fix uninitialized variable.
  - mm: compaction: use the proper flag to determine watermarks.
  - mm/vmscan: fix hard LOCKUP in function isolate_lru_folios.
  - mm/page_alloc: remove the incorrect and misleading comment.
  - mm: alloc_pages_bulk_noprof: drop page_list argument.
  - mm: replace free hugepage folios after migration.
  - mm/memory_hotplug: don't use __GFP_HARDWALL when migrating.
  - mm/page_alloc: don't use __GFP_HARDWALL when migrating pages.
  - powernv/memtrace: use __GFP_ZERO with alloc_contig_pages().
  - mm/page_alloc: forward the gfp flags from.
  - mm/page_alloc: sort out the alloc_contig_range() gfp flags.
  - mm/page_alloc: make __alloc_contig_migrate_range() static.
  - commit 6d27651
  - mm/memory_hotplug: move debug_pagealloc_map_pages() into.
  - mm/page_alloc: add some detailed comments in.
  - slab: allocate frozen pages.
  - mm/mempolicy: add alloc_frozen_pages().
  - mm/page_alloc: add __alloc_frozen_pages().
  - mm/page_alloc: move set_page_refcounted() to end of
    __alloc_pages() (bsc#1241169 (MM functional and performance
    backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_slowpath() (bsc#1241169 (MM functional and
    performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_direct_reclaim() (bsc#1241169 (MM functional
    and performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_direct_compact() (bsc#1241169 (MM functional
    and performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_may_oom() (bsc#1241169 (MM functional and
    performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_cpuset_fallback() (bsc#1241169 (MM functional
    and performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    get_page_from_freelist() (bsc#1241169 (MM functional and
    performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    prep_new_page() (bsc#1241169 (MM functional and performance
    backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    post_alloc_hook() (bsc#1241169 (MM functional and performance
    backports)).
  - mm/page_alloc: export free_frozen_pages() instead of
    free_unref_page() (bsc#1241169 (MM functional and performance
    backports)).
  - mm: make alloc_pages_mpol() static.
  - mm/page_alloc: cache page_zone() result in free_unref_page().
  - mm: Create/affine kswapd to its preferred node.
  - mm: Create/affine kcompactd to its preferred node.
  - mm: page_alloc: fix missed updates of lowmem_reserve in.
  - mm/mempolicy: count MPOL_WEIGHTED_INTERLEAVE to.
  - mm/vmscan: wake up flushers conditionally to avoid cgroup OOM.
  - mm/page_alloc: use str_off_on() helper in.
  - mm/mempolicy: fix comments for better documentation.
  - mm: fix shrink nr.unqueued_dirty counter issue.
  - mm: move the page fragment allocator from page_alloc into its.
  - mm: page_frag: add a test module for page_frag.
  - commit bae8357
  - selftests: mincore: fix tmpfs mincore test failure
    (jsc#PED-12649).
  - commit fc35e0e
  - docs: tmpfs: drop 'fadvise()' from the documentation
    (jsc#PED-12649).
  - commit 65a3636
  - docs: tmpfs: update the large folios policy for tmpfs and shmem
    (jsc#PED-12649).
  - commit 30d861d
  - mm: shmem: add a kernel command line to change the default
    huge policy for tmpfs (jsc#PED-12649).
  - commit 39f6ebb
  - mm: shmem: add large folio support for tmpfs (jsc#PED-12649).
  - commit 1cd7838
  - mm: shmem: change shmem_huge_global_enabled() to return huge
    order bitmap (jsc#PED-12649).
  - commit 1f8c8c5
  - mm: shmem: fix incorrect index alignment for within_size policy
    (jsc#PED-12649).
  - commit 21b0427
  - mm: shmem: remove __shmem_huge_global_enabled() (jsc#PED-12649).
  - Refresh
    patches.suse/mm-shmem-control-THP-support-through-the-kernel-command-li.patch.
  - commit 983ef62
  - mm: huge_memory: move file_thp_enabled() into huge_memory.c
    (jsc#PED-12649).
  - commit 7974c27
  - tmpfs: don't enable large folios if not supported
    (jsc#PED-12649).
  - commit 81e34da
  - mm: factor out the order calculation into a new helper
    (jsc#PED-12649).
  - commit e3e8297
  - mm: shmem: fix khugepaged activation policy for shmem
    (jsc#PED-12649).
  - commit c54323a
  - mm: allocate THP on hugezeropage wp-fault (jsc#PED-12649).
  - commit 8313bfa
  - mm: abstract THP allocation (jsc#PED-12649).
  - commit 928388d
  - mm: huge_memory: use strscpy() instead of strcpy()
    (jsc#PED-12649).
  - commit dcfbb69
  - mm: shmem: override mTHP shmem default with a kernel parameter
    (jsc#PED-12649).
  - commit 5989f8b
  - mm: move ``get_order_from_str()`` to internal.h (jsc#PED-12649).
  - commit 1451f9c
  - powerpc64/ftrace: fix module loading without patchable function
    entries (jsc#PED-10909 git-fixes).
  - commit 38a673f
  - mm: shmem: control THP support through the kernel command line
    (jsc#PED-12649).
  - commit f26d9e9
  - video: screen_info: Update framebuffers behind PCI bridges
    (bsc#1240696).
  - commit 073be6a
  - Refresh
    patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch.
    scripts/gen-suse_version_h.sh requires bash, yet in Makefile
    CONFIG_SHELL is defined to 'sh'. In openSUSE and SUSE products 'sh' is a
    symbolic link to 'bash', hence this isn't a problem. However
    distributions like Debian and Ubuntu 'sh' is symbolically linked to
    'dash' instead, and gen-suse_version_h.sh will fail to run with
    ./scripts/gen-suse_version_h.sh: 3: Syntax error: "(" unexpected
    make[1]: *** [/home/runner/work/libbpf/libbpf/.kernel/Makefile:1135: include/generated/uapi/linux/suse_version.h] Error 2
    make: *** [Makefile:224: __sub-make] Error 2
    Explicitly use bash to run scripts/gen-suse_version_h.sh to make sure
    it will always work.
  - commit ed7450d
  - Refresh
    patches.suse/lockdown-fix-kernel-lockdown-enforcement-issue-when-secure.patch.
    Fix build failure due to undefined reference to
    'lockdown_hooks_secure_boot'. This only happens when
    CONFIG_SECURITY_LOCKDOWN_LSM is disabled, which is never the case for a
    SUSE-supported SL-16.0 kernel, and only needed for custom bare-minimal
    kernel used to run BPF selftests.
  - commit c8ec8b3

++++ kernel-firmware-bluetooth:

  - Update to version 20250422 (git commit 944acaa23457):
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x1881_BA06

++++ kernel-firmware-media:

  - Update to version 20250422 (git commit 944acaa23457):
    * qcom: vpu: add video firmware binary for qcm6490

++++ kernel-firmware-platform:

  - Update to version 20250422 (git commit 944acaa23457):
    * bmi260: Add BMI260 IMU initial configuration data file

++++ kernel-firmware-qcom:

  - Update to version 20250422 (git commit 944acaa23457):
    * qcom: add QUPv3 firmware for QCS9100 platform

++++ kernel-firmware-realtek:

  - Update to version 20250422 (git commit 944acaa23457):
    * rtw89: 8922a: update element RF TXPWR to R40
    * rtw89: 8852c: update element RF TXPWR to R78
    * rtw89: 8852c: add fw v0.27.125.0 with format version 2
    * Revert "rtw89: 8852c: update fw to v0.27.125.0"

++++ kernel-firmware-sound:

  - Update to version 20250422 (git commit 944acaa23457):
    * ASoC: tas2781: Swap channel for SPI projects.

++++ kernel-rt:

  - lib/iov_iter: fix to increase non slab folio refcount
    (bsc#1241169 (MM functional and performance backports)).
  - commit 27fbba6
  - mm: decline to manipulate the refcount on a slab page
    (bsc#1241169 (MM functional and performance backports)).
  - commit 953ff5e
  - mm: page_frag: fix a compile error when kernel is not compiled
    (bsc#1241169 (MM functional and performance backports)).
  - commit 1cfdca8
  - drm/amd/display/dml2: use vzalloc rather than kzalloc
    (bsc#1241568).
  - commit c6c7df4
  - nfsd: decrease sc_count directly if fail to queue dl_recall
    (git-fixes).
  - commit dfbd8a7
  - nfs: add missing selections of CONFIG_CRC32 (git-fixes).
  - commit 2f2f40e
  - iommu/vt-d: Assign owner to the static identity domain
    (bsc#1241193).
  - commit 4c9babf
  - nvmet-fcloop: swap list_add_tail arguments (git-fixes).
  - nvme-pci: skip nvme_write_sq_db on empty rqlist (git-fixes).
  - nvme/ioctl: don't warn on vectorized uring_cmd with fixed buffer
    (git-fixes).
  - objtool, nvmet: Fix out-of-bounds stack access in
    nvmet_ctrl_state_show() (git-fixes).
  - commit 551ee35
  - mm/page_isolation: don't pass gfp flags to
    start_isolate_page_range() (bsc#1241169 (MM functional and
    performance backports)).
  - commit 2482206
  - mm/page_isolation: don't pass gfp flags to
    isolate_single_pageblock() (bsc#1241169 (MM functional and
    performance backports)).
  - commit 3532ecf
  - mm: page_alloc: tighten up find_suitable_fallback() (bsc#1241169
    (MM functional and performance backports)).
  - mm: vmscan: fix kswapd exit condition in defrag_mode
    (bsc#1241169 (MM functional and performance backports)).
  - mm: vmscan: restore high-cpu watermark safety in kswapd
    (bsc#1241169 (MM functional and performance backports)).
  - mm: page_alloc: speed up fallbacks in rmqueue_bulk()
    (bsc#1241169 (MM functional and performance backports)).
  - mm/page_alloc: replace flag check with PageHWPoison() in check_new_page_bad().
  - mm: page_alloc: fix defrag_mode's retry & OOM path.
  - mm/page_alloc: remove unnecessary __maybe_unused in.
  - mm: page_alloc: defrag_mode kswapd/kcompactd watermarks.
  - mm: page_alloc: defrag_mode kswapd/kcompactd assistance.
  - mm: page_alloc: defrag_mode.
  - mm: page_alloc: trace type pollution from compaction.
  - mm: compaction: push watermark into compaction_suitable().
  - mm: lock PGDAT_RECLAIM_LOCKED with acquire memory ordering.
  - mm: add missing release barrier on PGDAT_RECLAIM_LOCKED.
  - mm/page_alloc: clarify should_claim_block() commentary.
  - mm/page_alloc: clarify terminology in migratetype fallback.
  - mm/page_alloc: warn on nr_reserved_highatomic underflow.
  - mm: page_alloc: group fallback functions together.
  - mm: page_alloc: remove remnants of unlocked migratetype.
  - mm: page_alloc: don't steal single pages from biggest buddy.
  - vmscan, cleanup: add for_each_managed_zone_pgdat macro.
  - mm/page_alloc: fix memory accept before watermarks gets.
  - mm/page_alloc: fix uninitialized variable.
  - mm: compaction: use the proper flag to determine watermarks.
  - mm/vmscan: fix hard LOCKUP in function isolate_lru_folios.
  - mm/page_alloc: remove the incorrect and misleading comment.
  - mm: alloc_pages_bulk_noprof: drop page_list argument.
  - mm: replace free hugepage folios after migration.
  - mm/memory_hotplug: don't use __GFP_HARDWALL when migrating.
  - mm/page_alloc: don't use __GFP_HARDWALL when migrating pages.
  - powernv/memtrace: use __GFP_ZERO with alloc_contig_pages().
  - mm/page_alloc: forward the gfp flags from.
  - mm/page_alloc: sort out the alloc_contig_range() gfp flags.
  - mm/page_alloc: make __alloc_contig_migrate_range() static.
  - commit 6d27651
  - mm/memory_hotplug: move debug_pagealloc_map_pages() into.
  - mm/page_alloc: add some detailed comments in.
  - slab: allocate frozen pages.
  - mm/mempolicy: add alloc_frozen_pages().
  - mm/page_alloc: add __alloc_frozen_pages().
  - mm/page_alloc: move set_page_refcounted() to end of
    __alloc_pages() (bsc#1241169 (MM functional and performance
    backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_slowpath() (bsc#1241169 (MM functional and
    performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_direct_reclaim() (bsc#1241169 (MM functional
    and performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_direct_compact() (bsc#1241169 (MM functional
    and performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_may_oom() (bsc#1241169 (MM functional and
    performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    __alloc_pages_cpuset_fallback() (bsc#1241169 (MM functional
    and performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    get_page_from_freelist() (bsc#1241169 (MM functional and
    performance backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    prep_new_page() (bsc#1241169 (MM functional and performance
    backports)).
  - mm/page_alloc: move set_page_refcounted() to callers of
    post_alloc_hook() (bsc#1241169 (MM functional and performance
    backports)).
  - mm/page_alloc: export free_frozen_pages() instead of
    free_unref_page() (bsc#1241169 (MM functional and performance
    backports)).
  - mm: make alloc_pages_mpol() static.
  - mm/page_alloc: cache page_zone() result in free_unref_page().
  - mm: Create/affine kswapd to its preferred node.
  - mm: Create/affine kcompactd to its preferred node.
  - mm: page_alloc: fix missed updates of lowmem_reserve in.
  - mm/mempolicy: count MPOL_WEIGHTED_INTERLEAVE to.
  - mm/vmscan: wake up flushers conditionally to avoid cgroup OOM.
  - mm/page_alloc: use str_off_on() helper in.
  - mm/mempolicy: fix comments for better documentation.
  - mm: fix shrink nr.unqueued_dirty counter issue.
  - mm: move the page fragment allocator from page_alloc into its.
  - mm: page_frag: add a test module for page_frag.
  - commit bae8357
  - selftests: mincore: fix tmpfs mincore test failure
    (jsc#PED-12649).
  - commit fc35e0e
  - docs: tmpfs: drop 'fadvise()' from the documentation
    (jsc#PED-12649).
  - commit 65a3636
  - docs: tmpfs: update the large folios policy for tmpfs and shmem
    (jsc#PED-12649).
  - commit 30d861d
  - mm: shmem: add a kernel command line to change the default
    huge policy for tmpfs (jsc#PED-12649).
  - commit 39f6ebb
  - mm: shmem: add large folio support for tmpfs (jsc#PED-12649).
  - commit 1cd7838
  - mm: shmem: change shmem_huge_global_enabled() to return huge
    order bitmap (jsc#PED-12649).
  - commit 1f8c8c5
  - mm: shmem: fix incorrect index alignment for within_size policy
    (jsc#PED-12649).
  - commit 21b0427
  - mm: shmem: remove __shmem_huge_global_enabled() (jsc#PED-12649).
  - Refresh
    patches.suse/mm-shmem-control-THP-support-through-the-kernel-command-li.patch.
  - commit 983ef62
  - mm: huge_memory: move file_thp_enabled() into huge_memory.c
    (jsc#PED-12649).
  - commit 7974c27
  - tmpfs: don't enable large folios if not supported
    (jsc#PED-12649).
  - commit 81e34da
  - mm: factor out the order calculation into a new helper
    (jsc#PED-12649).
  - commit e3e8297
  - mm: shmem: fix khugepaged activation policy for shmem
    (jsc#PED-12649).
  - commit c54323a
  - mm: allocate THP on hugezeropage wp-fault (jsc#PED-12649).
  - commit 8313bfa
  - mm: abstract THP allocation (jsc#PED-12649).
  - commit 928388d
  - mm: huge_memory: use strscpy() instead of strcpy()
    (jsc#PED-12649).
  - commit dcfbb69
  - mm: shmem: override mTHP shmem default with a kernel parameter
    (jsc#PED-12649).
  - commit 5989f8b
  - mm: move ``get_order_from_str()`` to internal.h (jsc#PED-12649).
  - commit 1451f9c
  - powerpc64/ftrace: fix module loading without patchable function
    entries (jsc#PED-10909 git-fixes).
  - commit 38a673f
  - mm: shmem: control THP support through the kernel command line
    (jsc#PED-12649).
  - commit f26d9e9
  - video: screen_info: Update framebuffers behind PCI bridges
    (bsc#1240696).
  - commit 073be6a
  - Refresh
    patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch.
    scripts/gen-suse_version_h.sh requires bash, yet in Makefile
    CONFIG_SHELL is defined to 'sh'. In openSUSE and SUSE products 'sh' is a
    symbolic link to 'bash', hence this isn't a problem. However
    distributions like Debian and Ubuntu 'sh' is symbolically linked to
    'dash' instead, and gen-suse_version_h.sh will fail to run with
    ./scripts/gen-suse_version_h.sh: 3: Syntax error: "(" unexpected
    make[1]: *** [/home/runner/work/libbpf/libbpf/.kernel/Makefile:1135: include/generated/uapi/linux/suse_version.h] Error 2
    make: *** [Makefile:224: __sub-make] Error 2
    Explicitly use bash to run scripts/gen-suse_version_h.sh to make sure
    it will always work.
  - commit ed7450d
  - Refresh
    patches.suse/lockdown-fix-kernel-lockdown-enforcement-issue-when-secure.patch.
    Fix build failure due to undefined reference to
    'lockdown_hooks_secure_boot'. This only happens when
    CONFIG_SECURITY_LOCKDOWN_LSM is disabled, which is never the case for a
    SUSE-supported SL-16.0 kernel, and only needed for custom bare-minimal
    kernel used to run BPF selftests.
  - commit c8ec8b3

++++ kubevirt:

  - Update to version 1.5.0
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.5.0
  - Drop patches
    0001-feat-pass-timeout-from-virt-monitor-to-virt-tail.patch
  - Add patches
    0002-chore-deps-update-module-golang.org-x-crypto-to-v0.3.patch (bsc#1239328)
    0003-chore-deps-update-module-golang.org-x-oauth2-to-v0.2.patch (bsc#1239190)
    0004-chore-deps-update-module-golang.org-x-net-to-v0.36.0.patch (bsc#1238704)
  - Rename patch
    0002-Ensure-SEV-VMs-use-stateless-OVMF-firmware.patch
    0001-Ensure-SEV-VMs-use-stateless-OVMF-firmware.patch

++++ samba:

  - Update to 4.22.1
    * Running "gpo manage motd set" twice fails with backtrace;
    (bso#15774).
    * samba-tool gpo backup creates entity backups it can't read;
    (bso#15829).
    * gp_cert_auto_enroll_ext.py has problem unpacking GUIDs with
    prepended 0's; (bso#15839).
    * Deadlock between two smbd processes; (bso#15767).
    * Subnet based interfaces definition not listening on all
    covered IP addresses; (bso#15823).
    * PANIC: assert failed at source3/smbd/smb2_oplock.c(156):
    sconn->oplocks.exclusive_open>=0; (bso#15836).
    * net ad join fails with "Failed to join domain: failed to
    create kerberos keytab"; (bso#15727).
    * Enable support for cephfs case insensitive behavior;
    (bso#15822).
    * Remove of file or directory not possible with vfs_acl_tdb;
    (bso#15791).
    * Wide link issue in samba 4.22; (bso#15841).
    * NT_STATUS_INVALID_PARAMETER: Can't create folders on share of
    an exfat file system; (bso#15845).
    * Lease code is not endian-safe; (bso#15849).
    * vfs_ceph_new module does not work with other modules for
    snapshot management; (bso#15818).
    * vfs_ceph_new: Add path based fallback for SMB_VFS_FCHOWN,
    SMB_VFS_FCHMOD and SMB_VFS_FNTIMES; (bso#15834).
    * Add async io API from libcephfs to ceph_new VFS module;
    (bso#15810).

++++ nftables:

  - Update to release 1.1.3
    * Fix incorrect bytecode for vlan pcp mangling from netdev family
    chains such as ingress/egress: `... vlan pcp set 6 counter`
    * Fix bogus element in large concatenated set ranges, leading to:
    ``16777216 . 00:11:22:33:44:55 . 10.1.2.3 comment "123"``
    instead of:
    ``"lo" . 00:11:22:33:44:55 . 10.1.2.3 comment "123"``
    * Restore set auto-merge feature with timeouts, disabled in the
    previous v1.1.2 release.

++++ openssh:

  - Add openssh-send-extra-term-env.patch, which appends a few
    environment variables useful for terminal identification to the
    default send and accept lists.

++++ python-rich:

  - Add test dependency on attrs

++++ read-only-root-fs:

  - Update to version 1.0+git20250422.3e17744:
    * Remount /sysroot/etc between sysroot-etc.mount and initrd-fs.target

++++ shim:

  - Undefine %_enable_debug_packages to fix building with rpm-4.20
    (backport of the fix from Factory in SR#1232808)
  - Fix build with rpm 4.20 by copying the extracted directories
    explicitly

------------------------------------------------------------------
------------------  2025-4-21  -  Apr 21 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fixed integration test builds for TW
    Request dracut explicitly when needed

++++ kernel-default:

  - kABI: restore tpm_pcr_extend()'s current upstream signature
    (jsc#PED-12225).
  - commit 01d2be9
  - ima: invalidate unsupported PCR banks only once (jsc#PED-12225).
  - commit 0dd99c8
  - ima: track the set of PCRs ever extended (jsc#PED-12225).
  - commit 6e9d017
  - tpm: enable bank selection for PCR extend (jsc#PED-12225).
  - commit 6bfe5f8
  - ima: move INVALID_PCR() to ima.h (jsc#PED-12225).
  - commit 971e961
  - ima: select CRYPTO_SHA256 from Kconfig (jsc#PED-12225).
  - commit 3f70f02
  - ima: make SHA1 non-mandatory (jsc#PED-12225).
  - commit fc1fa39
  - ima: invalidate unsupported PCR banks (jsc#PED-12225).
  - commit 1e32a1d
  - ima: always create runtime_measurements sysfs file for ima_hash
    (jsc#PED-12225).
  - commit 280f136
  - ima: don't expose runtime_measurements for unsupported hashes
    (jsc#PED-12225).
  - commit 9d38add
  - netfilter: nf_tables: must hold rcu read lock while iterating
    object type list (git-fixes).
  - commit b390560
  - ipv6: Align behavior across nexthops during path selection
    (git-fixes).
  - commit 57b36ca
  - net: tls: explicitly disallow disconnect (git-fixes).
  - commit 2ba499d
  - ipv6: Do not consider link down nexthops in path selection
    (git-fixes).
  - commit 59d4d47
  - ipv6: Start path selection from the first nexthop (git-fixes).
  - commit 9eafb13
  - net: fix geneve_opt length integer overflow (git-fixes).
  - commit e87d20f
  - ipv6: fix omitted netlink attributes when using
    RTEXT_FILTER_SKIP_STATS (git-fixes).
  - commit d20db35
  - net: decrease cached dst counters in dst_release (git-fixes).
  - commit db1c23e
  - udp: Fix memory accounting leak (git-fixes).
  - commit a3ec081
  - udp: Fix multiple wraparounds of sk->sk_rmem_alloc (git-fixes).
  - commit b0fc2d4
  - sctp: add mutual exclusion in proc_sctp_do_udp_port()
    (git-fixes).
  - commit f8d22f9
  - ipv6: Set errno after ip_fib_metrics_init() in
    ip6_route_info_create() (git-fixes).
  - commit 32ff0b7
  - netpoll: hold rcu read lock in __netpoll_send_skb() (git-fixes).
  - commit 5fa9ec5
  - net: Add non-RCU dev_getbyhwaddr() helper (git-fixes).
  - commit 77512cd
  - arp: switch to dev_getbyhwaddr() in arp_req_set_public()
    (git-fixes).
  - commit 0696317
  - ipv6: mcast: add RCU protection to mld_newpack() (git-fixes).
  - commit a965980
  - bpf: tcp: Mark bpf_load_hdr_opt() arg2 as read-write
    (git-fixes).
  - commit e052c7d
  - tcp_cubic: fix incorrect HyStart round start detection
    (git-fixes).
  - commit 54c97fa
  - dev: Acquire netdev_rename_lock before restoring dev->name in
    dev_change_name() (git-fixes).
  - commit 1407d36
  - inet: ipmr: fix data-races (git-fixes).
  - commit 6ab03cc
  - xsk: Bring back busy polling support (git-fixes).
  - commit 2f4d213
  - tls: Fix tls_sw_sendmsg error handling (git-fixes).
  - commit 99fffb7
  - netfilter: ipset: Fix for recursive locking warning (git-fixes).
  - commit 2894b98
  - netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup
    level (git-fixes).
  - commit e88b4d8
  - Revert "udp: avoid calling sock_def_readable() if possible"
    (git-fixes).
  - commit 94ab068
  - ipmr: fix tables suspicious RCU usage (git-fixes).
  - commit 135ece8
  - ip6mr: fix tables suspicious RCU usage (git-fixes).
  - commit 0af4c97
  - net/ipv6: delete temporary address if mngtmpaddr is removed
    or unmanaged (git-fixes).
  - commit d9ac2cf
  - netfilter: ipset: add missing range check in bitmap_ip_uadt
    (git-fixes).
  - commit f75ac14
  - netdev-genl: Hold rcu_read_lock in napi_get (git-fixes).
  - commit ff70928
  - netfilter: nf_tables: must hold rcu read lock while iterating
    expression type list (git-fixes).
  - commit 652d26e
  - netfilter: nf_tables: avoid false-positive lockdep splat on
    rule deletion (git-fixes).
  - commit 0bd3b16
  - x86/mm: Convert unreachable() to BUG() (git-fixes).
  - commit 069c530
  - PCI: Check BAR index for validity (stable-fixes).
  - commit 55d043c
  - net: phy: allow MDIO bus PM ops to start/stop state machine
    for phylink-controlled PHY (git-fixes).
  - net: phy: move phy_link_change() prior to
    mdio_bus_phy_may_suspend() (stable-fixes).
  - PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type
    (stable-fixes).
  - PCI: Add Rockchip Vendor ID (stable-fixes).
  - misc: pci_endpoint_test: Fix displaying 'irq_type' after
    'request_irq' error (git-fixes).
  - PCI: Enable Configuration RRS SV early (stable-fixes).
  - tpm: End any active auth session before shutdown (stable-fixes).
  - wifi: mt76: mt76x2u: add TP-Link TL-WDN6200 ID to device table
    (stable-fixes).
  - wifi: ath12k: Fix invalid data access in
    ath12k_dp_rx_h_undecap_nwifi (stable-fixes).
  - wifi: ath12k: Fix invalid entry fetch in
    ath12k_dp_mon_srng_process (stable-fixes).
  - wifi: ath11k: Fix DMA buffer allocation to resolve SWIOTLB
    issues (stable-fixes).
  - wifi: mac80211: ensure sdata->work is canceled before
    initialized (stable-fixes).
  - wifi: mac80211: add strict mode disabling workarounds
    (stable-fixes).
  - net: usb: asix_devices: add FiberGecko DeviceID (stable-fixes).
  - platform/x86: x86-android-tablets: Add select POWER_SUPPLY to
    Kconfig (stable-fixes).
  - platform/chrome: cros_ec_lpc: Match on Framework ACPI device
    (stable-fixes).
  - mmc: dw_mmc: add a quirk for accessing 64-bit FIFOs in two
    halves (stable-fixes).
  - PM: hibernate: Avoid deadlock in
    hibernate_compressor_param_set() (stable-fixes).
  - zstd: Increase DYNAMIC_BMI2 GCC version cutoff from 4.8 to
    11.0 to work around compiler segfault (stable-fixes).
  - commit add9125
  - kbuild: exclude .rodata.(cst|str)* when building ranges
    (git-fixes).
  - HSI: ssi_protocol: Fix use after free vulnerability in
    ssi_protocol Driver Due to Race Condition (stable-fixes).
  - ima: limit the number of ToMToU integrity violations
    (stable-fixes).
  - ima: limit the number of open-writers integrity violations
    (stable-fixes).
  - ktest: Fix Test Failures Due to Missing LOG_FILE Directories
    (stable-fixes).
  - HID: pidff: Fix set_device_control() (stable-fixes).
  - HID: pidff: Fix 90 degrees direction name North -> East
    (stable-fixes).
  - HID: pidff: Compute INFINITE value instead of using hardcoded
    0xffff (stable-fixes).
  - HID: pidff: Clamp effect playback LOOP_COUNT value
    (stable-fixes).
  - HID: pidff: Rename two functions to align them with naming
    convention (stable-fixes).
  - HID: pidff: Remove redundant call to pidff_find_special_keys
    (stable-fixes).
  - HID: pidff: Support device error response from PID_BLOCK_LOAD
    (stable-fixes).
  - HID: pidff: Comment and code style update (stable-fixes).
  - HID: hid-universal-pidff: Add Asetek wheelbases support
    (stable-fixes).
  - HID: pidff: Make sure to fetch pool before checking
    SIMULTANEOUS_MAX (stable-fixes).
  - HID: pidff: Factor out pool report fetch and remove excess
    declaration (stable-fixes).
  - HID: pidff: Use macros instead of hardcoded min/max values
    for shorts (stable-fixes).
  - HID: pidff: Simplify pidff_rescale_signed (stable-fixes).
  - HID: pidff: Move all hid-pidff definitions to a dedicated header
    (stable-fixes).
  - HID: pidff: Fix null pointer dereference in pidff_find_fields
    (stable-fixes).
  - HID: pidff: Factor out code for setting gain (stable-fixes).
  - HID: pidff: Rescale time values to match field units
    (stable-fixes).
  - HID: pidff: Define values used in pidff_find_special_fields
    (stable-fixes).
  - HID: pidff: Simplify pidff_upload_effect function
    (stable-fixes).
  - HID: pidff: Completely rework and fix pidff_reset function
    (stable-fixes).
  - HID: pidff: Add PERIODIC_SINE_ONLY quirk (stable-fixes).
  - media: s5p-mfc: Corrected NV12M/NV21M plane-sizes
    (stable-fixes).
  - media: uvcvideo: Add quirk for Actions UVC05 (stable-fixes).
  - media: mediatek: vcodec: mark vdec_vp9_slice_map_counts_eob_coef
    noinline (stable-fixes).
  - commit 9b73679
  - Update config files: CONFIG_HID_UNIVERSAL_PIDFF=m
  - supported.conf:add hid-universal-pidff
  - commit e9a63ce
  - gpio: zynq: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - HID: Add hid-universal-pidff driver and supported device ids
    (stable-fixes).
  - HID: pidff: Stop all effects before enabling actuators
    (stable-fixes).
  - HID: pidff: Add FIX_WHEEL_DIRECTION quirk (stable-fixes).
  - HID: pidff: Add hid_pidff_init_with_quirks and export as GPL
    symbol (stable-fixes).
  - HID: pidff: Add PERMISSIVE_CONTROL quirk (stable-fixes).
  - HID: pidff: Add MISSING_PBO quirk and its detection
    (stable-fixes).
  - HID: pidff: Add MISSING_DELAY quirk and its detection
    (stable-fixes).
  - HID: pidff: Clamp PERIODIC effect period to device's logical
    range (stable-fixes).
  - HID: pidff: Do not send effect envelope if it's empty
    (stable-fixes).
  - HID: pidff: Convert infinite length from Linux API to PID
    standard (stable-fixes).
  - commit a51995f
  - drm/tests: helpers: Create kunit helper to destroy a
    drm_display_mode (stable-fixes).
  - drm/amdgpu: grab an additional reference on the gang fence v2
    (stable-fixes).
  - drm/mediatek: mtk_dpi: Explicitly manage TVD clock in power
    on/off (stable-fixes).
  - drm/mediatek: mtk_dpi: Move the input_2p_en bit to platform data
    (stable-fixes).
  - drm/xe/xelp: Move Wa_16011163337 from tunings to workarounds
    (stable-fixes).
  - drm/amdgpu: handle amdgpu_cgs_create_device() errors in
    amd_powerplay_create() (stable-fixes).
  - drm/amdkfd: debugfs hang_hws skip GPU with MES (stable-fixes).
  - drm/amdkfd: Fix pqm_destroy_queue race with GPU reset
    (stable-fixes).
  - drm/amdkfd: Fix mode1 reset crash issue (stable-fixes).
  - drm/amdkfd: clamp queue size to minimum (stable-fixes).
  - drm/amd/display: stop DML2 from removing pipes based on planes
    (stable-fixes).
  - drm/xe/vf: Don't try to trigger a full GT reset if VF
    (stable-fixes).
  - drm/amdgpu: Unlocked unmap only clear page table leaves
    (stable-fixes).
  - drm/amd/display: Update Cursor request mode to the beginning
    prefetch always (stable-fixes).
  - drm/bridge: panel: forbid initializing a panel with unknown
    connector type (stable-fixes).
  - drm/debugfs: fix printk format for bridge index (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for OneXPlayer Mini
    (Intel) (stable-fixes).
  - drm: panel-orientation-quirks: Add new quirk for GPD Win 2
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO Slide
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirks for AYA NEO Flip DS
    and KB (stable-fixes).
  - drm: panel-orientation-quirks: Add support for AYANEO 2S
    (stable-fixes).
  - drm: allow encoder mode_set even when connectors change for crtc
    (stable-fixes).
  - fbdev: omapfb: Add 'plane' value check (stable-fixes).
  - Bluetooth: Add quirk for broken READ_PAGE_SCAN_TYPE
    (stable-fixes).
  - Bluetooth: Add quirk for broken READ_VOICE_SETTING
    (stable-fixes).
  - Bluetooth: qca: simplify WCN399x NVM loading (stable-fixes).
  - cdc_ether|r8152: ThinkPad Hybrid USB-C/A Dock quirk
    (stable-fixes).
  - can: flexcan: add NXP S32G2/S32G3 SoC support (stable-fixes).
  - can: flexcan: Add quirk to handle separate interrupt lines
    for mailboxes (stable-fixes).
  - commit 3b991e8
  - drivers: base: devres: Allow to release group on device release
    (stable-fixes).
  - Bluetooth: hci_qca: use the power sequencer for wcn6750
    (stable-fixes).
  - Bluetooth: btusb: Add 2 HWIDs for MT7922 (stable-fixes).
  - Bluetooth: hci_uart: Fix another race during initialization
    (git-fixes).
  - Bluetooth: hci_uart: fix race during initialization
    (stable-fixes).
  - Bluetooth: btintel_pcie: Add device id of Whale Peak
    (stable-fixes).
  - ahci: Marvell 88SE9215 controllers prefer DMA for ATAPI
    (stable-fixes).
  - ahci: add PCI ID for Marvell 88SE9215 SATA Controller
    (stable-fixes).
  - ata: libata-eh: Do not use ATAPI DMA for a device limited to
    PIO mode (stable-fixes).
  - ata: libata-core: Add 'external' to the libata.force kernel
    parameter (stable-fixes).
  - ASoC: amd: yc: update quirk data for new Lenovo model
    (stable-fixes).
  - ASoC: Intel: adl: add 2xrt1316 audio configuration
    (stable-fixes).
  - ASoC: fsl_audmix: register card device depends on 'dais'
    property (stable-fixes).
  - ASoC: amd: ps: use macro for ACP6.3 pci revision id
    (stable-fixes).
  - ASoC: SOF: topology: Use krealloc_array() to replace krealloc()
    (stable-fixes).
  - ASoC: amd: Add DMI quirk for ACP6X mic support (stable-fixes).
  - ALSA: usb-audio: Fix CME quirk for UF series keyboards
    (stable-fixes).
  - ALSA: hda: intel: Add Lenovo IdeaPad Z570 to probe denylist
    (stable-fixes).
  - ALSA: hda: intel: Fix Optimus when GPU has no sound
    (stable-fixes).
  - commit f8cceaa
  - Update config files.
  - commit ea75203

++++ kernel-rt:

  - kABI: restore tpm_pcr_extend()'s current upstream signature
    (jsc#PED-12225).
  - commit 01d2be9
  - ima: invalidate unsupported PCR banks only once (jsc#PED-12225).
  - commit 0dd99c8
  - ima: track the set of PCRs ever extended (jsc#PED-12225).
  - commit 6e9d017
  - tpm: enable bank selection for PCR extend (jsc#PED-12225).
  - commit 6bfe5f8
  - ima: move INVALID_PCR() to ima.h (jsc#PED-12225).
  - commit 971e961
  - ima: select CRYPTO_SHA256 from Kconfig (jsc#PED-12225).
  - commit 3f70f02
  - ima: make SHA1 non-mandatory (jsc#PED-12225).
  - commit fc1fa39
  - ima: invalidate unsupported PCR banks (jsc#PED-12225).
  - commit 1e32a1d
  - ima: always create runtime_measurements sysfs file for ima_hash
    (jsc#PED-12225).
  - commit 280f136
  - ima: don't expose runtime_measurements for unsupported hashes
    (jsc#PED-12225).
  - commit 9d38add
  - netfilter: nf_tables: must hold rcu read lock while iterating
    object type list (git-fixes).
  - commit b390560
  - ipv6: Align behavior across nexthops during path selection
    (git-fixes).
  - commit 57b36ca
  - net: tls: explicitly disallow disconnect (git-fixes).
  - commit 2ba499d
  - ipv6: Do not consider link down nexthops in path selection
    (git-fixes).
  - commit 59d4d47
  - ipv6: Start path selection from the first nexthop (git-fixes).
  - commit 9eafb13
  - net: fix geneve_opt length integer overflow (git-fixes).
  - commit e87d20f
  - ipv6: fix omitted netlink attributes when using
    RTEXT_FILTER_SKIP_STATS (git-fixes).
  - commit d20db35
  - net: decrease cached dst counters in dst_release (git-fixes).
  - commit db1c23e
  - udp: Fix memory accounting leak (git-fixes).
  - commit a3ec081
  - udp: Fix multiple wraparounds of sk->sk_rmem_alloc (git-fixes).
  - commit b0fc2d4
  - sctp: add mutual exclusion in proc_sctp_do_udp_port()
    (git-fixes).
  - commit f8d22f9
  - ipv6: Set errno after ip_fib_metrics_init() in
    ip6_route_info_create() (git-fixes).
  - commit 32ff0b7
  - netpoll: hold rcu read lock in __netpoll_send_skb() (git-fixes).
  - commit 5fa9ec5
  - net: Add non-RCU dev_getbyhwaddr() helper (git-fixes).
  - commit 77512cd
  - arp: switch to dev_getbyhwaddr() in arp_req_set_public()
    (git-fixes).
  - commit 0696317
  - ipv6: mcast: add RCU protection to mld_newpack() (git-fixes).
  - commit a965980
  - bpf: tcp: Mark bpf_load_hdr_opt() arg2 as read-write
    (git-fixes).
  - commit e052c7d
  - tcp_cubic: fix incorrect HyStart round start detection
    (git-fixes).
  - commit 54c97fa
  - dev: Acquire netdev_rename_lock before restoring dev->name in
    dev_change_name() (git-fixes).
  - commit 1407d36
  - inet: ipmr: fix data-races (git-fixes).
  - commit 6ab03cc
  - xsk: Bring back busy polling support (git-fixes).
  - commit 2f4d213
  - tls: Fix tls_sw_sendmsg error handling (git-fixes).
  - commit 99fffb7
  - netfilter: ipset: Fix for recursive locking warning (git-fixes).
  - commit 2894b98
  - netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup
    level (git-fixes).
  - commit e88b4d8
  - Revert "udp: avoid calling sock_def_readable() if possible"
    (git-fixes).
  - commit 94ab068
  - ipmr: fix tables suspicious RCU usage (git-fixes).
  - commit 135ece8
  - ip6mr: fix tables suspicious RCU usage (git-fixes).
  - commit 0af4c97
  - net/ipv6: delete temporary address if mngtmpaddr is removed
    or unmanaged (git-fixes).
  - commit d9ac2cf
  - netfilter: ipset: add missing range check in bitmap_ip_uadt
    (git-fixes).
  - commit f75ac14
  - netdev-genl: Hold rcu_read_lock in napi_get (git-fixes).
  - commit ff70928
  - netfilter: nf_tables: must hold rcu read lock while iterating
    expression type list (git-fixes).
  - commit 652d26e
  - netfilter: nf_tables: avoid false-positive lockdep splat on
    rule deletion (git-fixes).
  - commit 0bd3b16
  - x86/mm: Convert unreachable() to BUG() (git-fixes).
  - commit 069c530
  - PCI: Check BAR index for validity (stable-fixes).
  - commit 55d043c
  - net: phy: allow MDIO bus PM ops to start/stop state machine
    for phylink-controlled PHY (git-fixes).
  - net: phy: move phy_link_change() prior to
    mdio_bus_phy_may_suspend() (stable-fixes).
  - PCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type
    (stable-fixes).
  - PCI: Add Rockchip Vendor ID (stable-fixes).
  - misc: pci_endpoint_test: Fix displaying 'irq_type' after
    'request_irq' error (git-fixes).
  - PCI: Enable Configuration RRS SV early (stable-fixes).
  - tpm: End any active auth session before shutdown (stable-fixes).
  - wifi: mt76: mt76x2u: add TP-Link TL-WDN6200 ID to device table
    (stable-fixes).
  - wifi: ath12k: Fix invalid data access in
    ath12k_dp_rx_h_undecap_nwifi (stable-fixes).
  - wifi: ath12k: Fix invalid entry fetch in
    ath12k_dp_mon_srng_process (stable-fixes).
  - wifi: ath11k: Fix DMA buffer allocation to resolve SWIOTLB
    issues (stable-fixes).
  - wifi: mac80211: ensure sdata->work is canceled before
    initialized (stable-fixes).
  - wifi: mac80211: add strict mode disabling workarounds
    (stable-fixes).
  - net: usb: asix_devices: add FiberGecko DeviceID (stable-fixes).
  - platform/x86: x86-android-tablets: Add select POWER_SUPPLY to
    Kconfig (stable-fixes).
  - platform/chrome: cros_ec_lpc: Match on Framework ACPI device
    (stable-fixes).
  - mmc: dw_mmc: add a quirk for accessing 64-bit FIFOs in two
    halves (stable-fixes).
  - PM: hibernate: Avoid deadlock in
    hibernate_compressor_param_set() (stable-fixes).
  - zstd: Increase DYNAMIC_BMI2 GCC version cutoff from 4.8 to
    11.0 to work around compiler segfault (stable-fixes).
  - commit add9125
  - kbuild: exclude .rodata.(cst|str)* when building ranges
    (git-fixes).
  - HSI: ssi_protocol: Fix use after free vulnerability in
    ssi_protocol Driver Due to Race Condition (stable-fixes).
  - ima: limit the number of ToMToU integrity violations
    (stable-fixes).
  - ima: limit the number of open-writers integrity violations
    (stable-fixes).
  - ktest: Fix Test Failures Due to Missing LOG_FILE Directories
    (stable-fixes).
  - HID: pidff: Fix set_device_control() (stable-fixes).
  - HID: pidff: Fix 90 degrees direction name North -> East
    (stable-fixes).
  - HID: pidff: Compute INFINITE value instead of using hardcoded
    0xffff (stable-fixes).
  - HID: pidff: Clamp effect playback LOOP_COUNT value
    (stable-fixes).
  - HID: pidff: Rename two functions to align them with naming
    convention (stable-fixes).
  - HID: pidff: Remove redundant call to pidff_find_special_keys
    (stable-fixes).
  - HID: pidff: Support device error response from PID_BLOCK_LOAD
    (stable-fixes).
  - HID: pidff: Comment and code style update (stable-fixes).
  - HID: hid-universal-pidff: Add Asetek wheelbases support
    (stable-fixes).
  - HID: pidff: Make sure to fetch pool before checking
    SIMULTANEOUS_MAX (stable-fixes).
  - HID: pidff: Factor out pool report fetch and remove excess
    declaration (stable-fixes).
  - HID: pidff: Use macros instead of hardcoded min/max values
    for shorts (stable-fixes).
  - HID: pidff: Simplify pidff_rescale_signed (stable-fixes).
  - HID: pidff: Move all hid-pidff definitions to a dedicated header
    (stable-fixes).
  - HID: pidff: Fix null pointer dereference in pidff_find_fields
    (stable-fixes).
  - HID: pidff: Factor out code for setting gain (stable-fixes).
  - HID: pidff: Rescale time values to match field units
    (stable-fixes).
  - HID: pidff: Define values used in pidff_find_special_fields
    (stable-fixes).
  - HID: pidff: Simplify pidff_upload_effect function
    (stable-fixes).
  - HID: pidff: Completely rework and fix pidff_reset function
    (stable-fixes).
  - HID: pidff: Add PERIODIC_SINE_ONLY quirk (stable-fixes).
  - media: s5p-mfc: Corrected NV12M/NV21M plane-sizes
    (stable-fixes).
  - media: uvcvideo: Add quirk for Actions UVC05 (stable-fixes).
  - media: mediatek: vcodec: mark vdec_vp9_slice_map_counts_eob_coef
    noinline (stable-fixes).
  - commit 9b73679
  - Update config files: CONFIG_HID_UNIVERSAL_PIDFF=m
  - supported.conf:add hid-universal-pidff
  - commit e9a63ce
  - gpio: zynq: Fix wakeup source leaks on device unbind
    (stable-fixes).
  - HID: Add hid-universal-pidff driver and supported device ids
    (stable-fixes).
  - HID: pidff: Stop all effects before enabling actuators
    (stable-fixes).
  - HID: pidff: Add FIX_WHEEL_DIRECTION quirk (stable-fixes).
  - HID: pidff: Add hid_pidff_init_with_quirks and export as GPL
    symbol (stable-fixes).
  - HID: pidff: Add PERMISSIVE_CONTROL quirk (stable-fixes).
  - HID: pidff: Add MISSING_PBO quirk and its detection
    (stable-fixes).
  - HID: pidff: Add MISSING_DELAY quirk and its detection
    (stable-fixes).
  - HID: pidff: Clamp PERIODIC effect period to device's logical
    range (stable-fixes).
  - HID: pidff: Do not send effect envelope if it's empty
    (stable-fixes).
  - HID: pidff: Convert infinite length from Linux API to PID
    standard (stable-fixes).
  - commit a51995f
  - drm/tests: helpers: Create kunit helper to destroy a
    drm_display_mode (stable-fixes).
  - drm/amdgpu: grab an additional reference on the gang fence v2
    (stable-fixes).
  - drm/mediatek: mtk_dpi: Explicitly manage TVD clock in power
    on/off (stable-fixes).
  - drm/mediatek: mtk_dpi: Move the input_2p_en bit to platform data
    (stable-fixes).
  - drm/xe/xelp: Move Wa_16011163337 from tunings to workarounds
    (stable-fixes).
  - drm/amdgpu: handle amdgpu_cgs_create_device() errors in
    amd_powerplay_create() (stable-fixes).
  - drm/amdkfd: debugfs hang_hws skip GPU with MES (stable-fixes).
  - drm/amdkfd: Fix pqm_destroy_queue race with GPU reset
    (stable-fixes).
  - drm/amdkfd: Fix mode1 reset crash issue (stable-fixes).
  - drm/amdkfd: clamp queue size to minimum (stable-fixes).
  - drm/amd/display: stop DML2 from removing pipes based on planes
    (stable-fixes).
  - drm/xe/vf: Don't try to trigger a full GT reset if VF
    (stable-fixes).
  - drm/amdgpu: Unlocked unmap only clear page table leaves
    (stable-fixes).
  - drm/amd/display: Update Cursor request mode to the beginning
    prefetch always (stable-fixes).
  - drm/bridge: panel: forbid initializing a panel with unknown
    connector type (stable-fixes).
  - drm/debugfs: fix printk format for bridge index (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for OneXPlayer Mini
    (Intel) (stable-fixes).
  - drm: panel-orientation-quirks: Add new quirk for GPD Win 2
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO Slide
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirks for AYA NEO Flip DS
    and KB (stable-fixes).
  - drm: panel-orientation-quirks: Add support for AYANEO 2S
    (stable-fixes).
  - drm: allow encoder mode_set even when connectors change for crtc
    (stable-fixes).
  - fbdev: omapfb: Add 'plane' value check (stable-fixes).
  - Bluetooth: Add quirk for broken READ_PAGE_SCAN_TYPE
    (stable-fixes).
  - Bluetooth: Add quirk for broken READ_VOICE_SETTING
    (stable-fixes).
  - Bluetooth: qca: simplify WCN399x NVM loading (stable-fixes).
  - cdc_ether|r8152: ThinkPad Hybrid USB-C/A Dock quirk
    (stable-fixes).
  - can: flexcan: add NXP S32G2/S32G3 SoC support (stable-fixes).
  - can: flexcan: Add quirk to handle separate interrupt lines
    for mailboxes (stable-fixes).
  - commit 3b991e8
  - drivers: base: devres: Allow to release group on device release
    (stable-fixes).
  - Bluetooth: hci_qca: use the power sequencer for wcn6750
    (stable-fixes).
  - Bluetooth: btusb: Add 2 HWIDs for MT7922 (stable-fixes).
  - Bluetooth: hci_uart: Fix another race during initialization
    (git-fixes).
  - Bluetooth: hci_uart: fix race during initialization
    (stable-fixes).
  - Bluetooth: btintel_pcie: Add device id of Whale Peak
    (stable-fixes).
  - ahci: Marvell 88SE9215 controllers prefer DMA for ATAPI
    (stable-fixes).
  - ahci: add PCI ID for Marvell 88SE9215 SATA Controller
    (stable-fixes).
  - ata: libata-eh: Do not use ATAPI DMA for a device limited to
    PIO mode (stable-fixes).
  - ata: libata-core: Add 'external' to the libata.force kernel
    parameter (stable-fixes).
  - ASoC: amd: yc: update quirk data for new Lenovo model
    (stable-fixes).
  - ASoC: Intel: adl: add 2xrt1316 audio configuration
    (stable-fixes).
  - ASoC: fsl_audmix: register card device depends on 'dais'
    property (stable-fixes).
  - ASoC: amd: ps: use macro for ACP6.3 pci revision id
    (stable-fixes).
  - ASoC: SOF: topology: Use krealloc_array() to replace krealloc()
    (stable-fixes).
  - ASoC: amd: Add DMI quirk for ACP6X mic support (stable-fixes).
  - ALSA: usb-audio: Fix CME quirk for UF series keyboards
    (stable-fixes).
  - ALSA: hda: intel: Add Lenovo IdeaPad Z570 to probe denylist
    (stable-fixes).
  - ALSA: hda: intel: Fix Optimus when GPU has no sound
    (stable-fixes).
  - commit f8cceaa
  - Update config files.
  - commit ea75203

++++ libgpg-error:

  - Update to 1.54:
    * Fix a regression in 1.52 which did not allow to open UNC
    specified files on Windows. [rE28ae4ee194]
    * Ignore log file specification from the Registry in the gpg-error
    tool.

++++ libsoup:

  - Add CVE fixes:
    + libsoup-CVE-2025-32914.patch (boo#1241164 CVE-2025-32914)
    + libsoup-CVE-2025-32908.patch (boo#1241223 CVE-2025-32908)

++++ vim:

  - update to 9.1.1330:
    * patch 9.1.1330: may receive E315 in terminal
    * patch 9.1.1329: cannot get information about command line completion
    * patch 9.1.1328: too many strlen() calls in indent.c
    * patch 9.1.1327: filetype: nroff detection can be improved
    * runtime(doc): cross-link :| meaning :p and explain E749
    * runtime(doc): style: clarify to prefer 2 spaces after a sentence
    * runtime(pov): deprecate `#render` and `#statistics` in syntax script
    * patch 9.1.1326: invalid cursor position after 'tagfunc'
    * runtime(keymaps): update Brazilian keymaps
    * patch 9.1.1325: tests: not checking error numbers properly
    * runtime(doc): clarify 'includeexpr' is not used for <cfile>
    * runtime(filetype): improve *.h filetype detection
    * runtime(indent-tests): Raise timeouts for "search*()"es
    * runtime(indent-tests): Annotate timed "search*()"es for tracing
    * runtime(indent-tests): Instrument timed "search*()" calls
    * patch 9.1.1324: undefined behaviour if X11 connection dies
    * patch 9.1.1323: b:undo_ftplugin not executed when re-using buffer
    * runtime(nix): set iskeyword and b:match_words in ftplugin
    * runtime(doc): clarify "nearest" value for 'completeopt'
    * runtime(doc): Tweak documentation style a bit
    * patch 9.1.1322: small delete register cannot paste multi-line correctly
    * patch 9.1.1321: filetype: MS ixx and mpp files are not recognized
    * patch 9.1.1320: filetype: alsoft config files are not recognized
    * patch 9.1.1319: Various typos in the code, issue with test_inst_complete.vim
    * patch 9.1.1318: tests: test_format fails
    * runtime(jjdescription): Don't require a space to start comments
    * patch 9.1.1317: noisy error when restoring folds from session fails
    * patch 9.1.1316: missing memory allocation failure in os_mswin.c
    * patch 9.1.1315: completion: issue with fuzzy completion and 'completefuzzycollect'
    * patch 9.1.1314: max allowed string width too small
    * patch 9.1.1313: compile warning about uninitialized value
    * patch 9.1.1312: tests: Test_backupskip() fails when HOME is defined
    * patch 9.1.1311: completion: not possible to limit number of matches
    * patch 9.1.1310: completion: redundant check for preinsert effect
    * runtime(gleam): Update ftplugin, use recommended_style config variable
    * patch 9.1.1309: tests: no test for 'pummaxwidth' with non-truncated "kind"
    * runtime: set 'cpoptions' for line-continuation in various runtime files
    * runtime(tar): remove dependency on netrw#WinPath, include mapping doc
    * runtime(netrw): remove deprecated functions
    * patch 9.1.1308: completion: cannot order matches by distance to cursor
    * patch 9.1.1307: make syntax does not reliably detect different flavors
    * patch 9.1.1306: completion menu rendering can be improved
    * patch 9.1.1305: completion menu active after switching windows/tabs
    * patch 9.1.1304: filetype: some man files are not recognized
    * runtime(netrw): upstream snapshot of v180
    * patch 9.1.1303: missing out-of-memory check in linematch.c
    * patch 9.1.1302: Coverity warns about using uninitialized value
    * patch 9.1.1301: completion: cannot configure completion functions with 'complete'
    * patch 9.1.1300: wrong detection of -inf
    * runtime(doc): update enum helptext
    * patch 9.1.1299: filetype: mbsyncrc files are not recognized
    * runtime(doc): update options.txt and clarify 'wildmode' further
    * runtime(gleam): update Maintainer and filetype options
    * patch 9.1.1298: define_function() is too long
    * patch 9.1.1297: Ctrl-D scrolling can get stuck
    * runtime(new-tutor): update tutor and correct comandline completion
    * patch 9.1.1296: completion: incorrect truncation logic
    * patch 9.1.1295: clientserver: does not handle :stopinsert correctly
    * runtime(doc): disable last-position-jump in diff mode
    * runtime(doc): Improve 'wildmode' setting desciption
    * patch 9.1.1294: gui tabline menu does not use confirm when closing tabs
    * runtime(doc): correct backslash escaping comma example
    * patch 9.1.1293: comment plugin does not handle 'exclusive' selection for comment object
    * patch 9.1.1292: statusline not correctly evaluated
    * runtime(sh): Do not look up a "sh" utility in $PATH for "sh_13.sh"
    * runtime(filetype): make shell filetype detection more robust
    * patch 9.1.1291: too many strlen() calls in buffer.c
    * runtime(keymaps): include 2 Brazilian Keymaps
    * runtime(vim): Update-base-syntax, match full :*grep, :make, :sort and :filter commands
    * patch 9.1.1290: tests: missing cleanup in test_filetype.vim
    * patch 9.1.1289: tests: no test for matchparen plugin with WinScrolled event
    * runtime(remind): include remind.vim ftplugin
    * runtime(vim): Update base-syntax, improve :command highlighting
    * runtime(help): add omni completion and 'iskeyword' to filetype plugin
    * runtime(lf): improve syntax script, add filetype plugin
    * patch 9.1.1288: Using wrong window in ll_resize_stack()
    * runtime(doc): rename wrong option to 'pummaxwidth'
    * patch 9.1.1287: quickfix code can be further improved
    * patch 9.1.1286: filetype: help files not detected when 'iskeyword' includes ":"
    * patch 9.1.1285: Vim9: no error message for missing method after "super."
    * patch 9.1.1284: not possible to configure pum truncation char
    * runtime(lua): fix whitespace style issues in lua ftplugin
    * runtime(lua): improve foldexpr, add vim9 script version
    * runtime(doc): Fix minor typo in options.txt
    * runtime(fstab): set formatoptions-=t in filetype plugin
    * runtime(svelte): add matchit support to svelte filetype plugin
    * patch 9.1.1283: quickfix stack is limited to 10 items
    * patch 9.1.1282: Build and test failure without job feature
    * patch 9.1.1281: extra newline output when editing stdin
    * patch 9.1.1280: trailing additional semicolon in get_matches_in_str()
    * patch 9.1.1279: Vim9: null_object and null_class are no reserved names
    * patch 9.1.1278: Vim9: too long functions in vim9type.c
    * runtime(vim): Update base-syntax, match full :redir command
    * patch 9.1.1277: tests: trailing comment char in test_popupwin
    * patch 9.1.1276: inline word diff treats multibyte chars as word char
    * runtime(doc): update WinScrolled documentation
    * runtime(vim): Update base-syntax, improve :set backslash handling
    * patch 9.1.1275: MS-Windows: Not possible to pass additional flags to Make_mvc
    * patch 9.1.1274: Vim9: no support for object<type> as variable type
    * patch 9.1.1273: Coverity warns about using uninitialized value
    * patch 9.1.1272: completion: in keyword completion Ctrl_P cannot go back after Ctrl_N
    * runtime(sh): Update syntax file, command substitution opening paren at EOL
    * patch 9.1.1271: filetype: Power Query files are not recognized
    * translation(ru): fix and updated messages translation
    * runtime(doc): clarify the use of change marks when writing a buffer
    * runtime(zip): add *.whl to the list of zip extensions
    * patch 9.1.1270: missing out-of-memory checks in buffer.c
    * runtime(doc): update pi_zip.txt with current list of zip file extensions
    * patch 9.1.1269: completion: compl_shown_match is updated when starting keyword completion
    * patch 9.1.1268: filetype: dax files are not recognized
    * runtime(openPlugin): fix E480 when opening URLs with wildcards on Windows
    * patch 9.1.1267: Vim9: no support for type list/dict<object<any>>
    * patch 9.1.1266: MS-Windows: type conversion warnings
    * translation(ru): Updated messages translation
    * patch 9.1.1265: tests: no tests for typing normal char during completion
    * runtime(rust): set formatprg to rustfmt
    * patch 9.1.1264: Vim9: error when comparing objects
    * runtime(doc): update last change date for diff.txt
    * runtime(doc): Update the tuple help text
    * patch 9.1.1263: string length wrong in get_last_inserted_save()
    * patch 9.1.1262: heap-buffer-overflow with narrow 'pummaxwidth' value
    * patch 9.1.1261: No test for 'pummaxwidth' non-truncated items
    * runtime(debversions): Add release name for Debian 15 - duke
    * patch 9.1.1260: Hang when filtering buffer with NUL bytes
    * runtime(odin): add new keywords to syntax script
    * patch 9.1.1259: some issues with comment package and tailing spaces
    * runtime(java): Make changes for JDK 24 in syntax script

------------------------------------------------------------------
------------------  2025-4-20  -  Apr 20 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - i2c: cros-ec-tunnel: defer probe if parent EC is not present
    (git-fixes).
  - i2c: atr: Fix wrong include (git-fixes).
  - drm/msm/a6xx+: Don't let IB_SIZE overflow (git-fixes).
  - drm/xe/dma_buf: stop relying on placement in unmap (git-fixes).
  - drm/xe/userptr: fix notifier vs folio deadlock (git-fixes).
  - drm/xe: Set LRC addresses before guc load (git-fixes).
  - drm/mgag200: Fix value in <VBLKSTR> register (git-fixes).
  - dma-buf/sw_sync: Decrement refcount on error in
    sw_sync_ioctl_get_deadline() (git-fixes).
  - drm/v3d: Fix Indirect Dispatch configuration for V3D 7.1.6
    and later (git-fixes).
  - drm/amdgpu: Add back JPEG to video caps for carrizo and newer
    (git-fixes).
  - drm/amdgpu: fix warning of drm_mm_clean (git-fixes).
  - string: Add load_unaligned_zeropad() code path to
    sized_strscpy() (git-fixes).
  - Documentation: PM: runtime: Fix a reference to
    pm_runtime_autosuspend() (git-fixes).
  - kunit: qemu_configs: SH: Respect kunit cmdline (git-fixes).
  - commit 2ff002e

++++ kernel-firmware-amdgpu:

  - Update to version 20250419 (git commit 5aa42075d00c):
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update smu 13.0.7 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update picasso firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: update dcn 4.01 frmware to 0.1.6.0

++++ kernel-firmware-intel:

  - Update to version 20250419 (git commit 5aa42075d00c):
    * intel: ish: Update license file for ISH

++++ kernel-rt:

  - i2c: cros-ec-tunnel: defer probe if parent EC is not present
    (git-fixes).
  - i2c: atr: Fix wrong include (git-fixes).
  - drm/msm/a6xx+: Don't let IB_SIZE overflow (git-fixes).
  - drm/xe/dma_buf: stop relying on placement in unmap (git-fixes).
  - drm/xe/userptr: fix notifier vs folio deadlock (git-fixes).
  - drm/xe: Set LRC addresses before guc load (git-fixes).
  - drm/mgag200: Fix value in <VBLKSTR> register (git-fixes).
  - dma-buf/sw_sync: Decrement refcount on error in
    sw_sync_ioctl_get_deadline() (git-fixes).
  - drm/v3d: Fix Indirect Dispatch configuration for V3D 7.1.6
    and later (git-fixes).
  - drm/amdgpu: Add back JPEG to video caps for carrizo and newer
    (git-fixes).
  - drm/amdgpu: fix warning of drm_mm_clean (git-fixes).
  - string: Add load_unaligned_zeropad() code path to
    sized_strscpy() (git-fixes).
  - Documentation: PM: runtime: Fix a reference to
    pm_runtime_autosuspend() (git-fixes).
  - kunit: qemu_configs: SH: Respect kunit cmdline (git-fixes).
  - commit 2ff002e

------------------------------------------------------------------
------------------  2025-4-19  -  Apr 19 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - KVM: x86: Explicitly zero EAX and EBX when PERFMON_V2 isn't
    supported by KVM (jsc#PED-348).
  - commit 6ea52a5
  - KVM: SVM: Don't rely on DebugSwap to restore host DR0..DR3
    (jsc#PED-348).
  - commit 444f443
  - KVM: SVM: Save host DR masks on CPUs with DebugSwap
    (jsc#PED-348).
  - commit 5ed001c
  - kvm: retry nx_huge_page_recovery_thread creation (jsc#PED-348).
  - commit 37391d6
  - vhost: return task creation error instead of NULL (jsc#PED-348).
  - commit ab9278d
  - KVM: x86: Snapshot the host's DEBUGCTL after disabling IRQs
    (jsc#PED-348).
  - commit dfe2ab4
  - KVM: SVM: Manually context switch DEBUGCTL if LBR virtualization
    is disabled (jsc#PED-348).
  - commit dd7305d
  - KVM: x86: Snapshot the host's DEBUGCTL in common x86
    (jsc#PED-348).
  - commit cce9ec5
  - KVM: SVM: Suppress DEBUGCTL.BTF on AMD (jsc#PED-348).
  - commit 6c4742c
  - KVM: SVM: Drop DEBUGCTL[5:2] from guest's effective value
    (jsc#PED-348).
  - commit 8ff18f3
  - KVM: SVM: Set RFLAGS.IF=1 in C code, to get VMRUN out of the
    STI shadow (jsc#PED-348).
  - commit a9f8b51
  - KVM: nVMX: Process events on nested VM-Exit if injectable IRQ
    or NMI is pending (jsc#PED-348).
  - commit 4ed5eed
  - KVM: x86: Free vCPUs before freeing VM state (jsc#PED-348).
  - commit df99449
  - KVM: arm64: Ensure a VMID is allocated before programming
    VTTBR_EL2 (jsc#PED-348).
  - commit b95233d
  - KVM: arm64: Fix tcr_el2 initialisation in hVHE mode
    (jsc#PED-348).
  - commit 611c563
  - x86/sev: Fix broken SNP support with KVM module built-in
    (jsc#PED-348).
  - commit 7022d3a
  - x86/virt/tdx: Require the module to assert it has the NO_RBP_MOD
    mitigation (jsc#PED-348).
  - commit e353bec
  - x86/virt/tdx: Switch to use auto-generated global metadata
    reading code (jsc#PED-348).
  - commit 166cc82
  - x86/virt/tdx: Use dedicated struct members for PAMT entry sizes
    (jsc#PED-348).
  - commit 71b25ee
  - x86/virt/tdx: Use auto-generated code to read global metadata
    (jsc#PED-348).
  - commit ee1f1c1
  - x86/virt/tdx: Start to track all global metadata in one
    structure (jsc#PED-348).
  - commit 2ebc496
  - x86/virt/tdx: Rename 'struct tdx_tdmr_sysinfo' to reflect the
    spec better (jsc#PED-348).
  - commit 7ed2a91
  - x86/sev: Add full support for a segmented RMP table
    (jsc#PED-348).
  - commit be63ba4
  - x86/sev: Treat the contiguous RMP table as a single RMP segment
    (jsc#PED-348).
  - commit d7caf03
  - x86/sev: Map only the RMP table entries instead of the full
    RMP range (jsc#PED-348).
  - commit 8f23caf
  - x86/sev: Move the SNP probe routine out of the way
    (jsc#PED-348).
  - commit a6edabd
  - x86/sev: Add support for the RMPREAD instruction (jsc#PED-348).
  - commit 3f98d95

++++ kernel-rt:

  - KVM: x86: Explicitly zero EAX and EBX when PERFMON_V2 isn't
    supported by KVM (jsc#PED-348).
  - commit 6ea52a5
  - KVM: SVM: Don't rely on DebugSwap to restore host DR0..DR3
    (jsc#PED-348).
  - commit 444f443
  - KVM: SVM: Save host DR masks on CPUs with DebugSwap
    (jsc#PED-348).
  - commit 5ed001c
  - kvm: retry nx_huge_page_recovery_thread creation (jsc#PED-348).
  - commit 37391d6
  - vhost: return task creation error instead of NULL (jsc#PED-348).
  - commit ab9278d
  - KVM: x86: Snapshot the host's DEBUGCTL after disabling IRQs
    (jsc#PED-348).
  - commit dfe2ab4
  - KVM: SVM: Manually context switch DEBUGCTL if LBR virtualization
    is disabled (jsc#PED-348).
  - commit dd7305d
  - KVM: x86: Snapshot the host's DEBUGCTL in common x86
    (jsc#PED-348).
  - commit cce9ec5
  - KVM: SVM: Suppress DEBUGCTL.BTF on AMD (jsc#PED-348).
  - commit 6c4742c
  - KVM: SVM: Drop DEBUGCTL[5:2] from guest's effective value
    (jsc#PED-348).
  - commit 8ff18f3
  - KVM: SVM: Set RFLAGS.IF=1 in C code, to get VMRUN out of the
    STI shadow (jsc#PED-348).
  - commit a9f8b51
  - KVM: nVMX: Process events on nested VM-Exit if injectable IRQ
    or NMI is pending (jsc#PED-348).
  - commit 4ed5eed
  - KVM: x86: Free vCPUs before freeing VM state (jsc#PED-348).
  - commit df99449
  - KVM: arm64: Ensure a VMID is allocated before programming
    VTTBR_EL2 (jsc#PED-348).
  - commit b95233d
  - KVM: arm64: Fix tcr_el2 initialisation in hVHE mode
    (jsc#PED-348).
  - commit 611c563
  - x86/sev: Fix broken SNP support with KVM module built-in
    (jsc#PED-348).
  - commit 7022d3a
  - x86/virt/tdx: Require the module to assert it has the NO_RBP_MOD
    mitigation (jsc#PED-348).
  - commit e353bec
  - x86/virt/tdx: Switch to use auto-generated global metadata
    reading code (jsc#PED-348).
  - commit 166cc82
  - x86/virt/tdx: Use dedicated struct members for PAMT entry sizes
    (jsc#PED-348).
  - commit 71b25ee
  - x86/virt/tdx: Use auto-generated code to read global metadata
    (jsc#PED-348).
  - commit ee1f1c1
  - x86/virt/tdx: Start to track all global metadata in one
    structure (jsc#PED-348).
  - commit 2ebc496
  - x86/virt/tdx: Rename 'struct tdx_tdmr_sysinfo' to reflect the
    spec better (jsc#PED-348).
  - commit 7ed2a91
  - x86/sev: Add full support for a segmented RMP table
    (jsc#PED-348).
  - commit be63ba4
  - x86/sev: Treat the contiguous RMP table as a single RMP segment
    (jsc#PED-348).
  - commit d7caf03
  - x86/sev: Map only the RMP table entries instead of the full
    RMP range (jsc#PED-348).
  - commit 8f23caf
  - x86/sev: Move the SNP probe routine out of the way
    (jsc#PED-348).
  - commit a6edabd
  - x86/sev: Add support for the RMPREAD instruction (jsc#PED-348).
  - commit 3f98d95

++++ vim:

  - Update apparmor.vim to latest version (from AppArmor 4.1.0)
  - add more units for rlimit rules

------------------------------------------------------------------
------------------  2025-4-18  -  Apr 18 2025  -------------------
------------------------------------------------------------------

++++ haproxy:

  - Update to version 3.1.7+git0.c3f408945:
    * [RELEASE] Released version 3.1.7
    * BUG/MINOR: rhttp: ensure GOAWAY can be emitted after reversal
    * BUG/MINOR: rhttp: fix reconnect if timeout connect unset
    * BUG/MINOR: mux-h2: prevent past scheduling with idle connections
    * MINOR: compiler: rely on builtin detection for __builtin_unreachable()
    * MINOR: debug: make ha_stuck_warning() print the whole message at once
    * MINOR: debug: make ha_stuck_warning() only work for the current thread
    * MEDIUM: wdt: always make the faulty thread report its own warnings
    * MINOR: pass a valid buffer pointer to ha_thread_dump_one()
    * MINOR: debug: remove unused case of thr!=tid in ha_thread_dump_one()
    * MINOR: debug: always reset the dump pointer when done
    * MINOR: tinfo: keep a copy of the pointer to the thread dump buffer
    * MINOR: debug: protect ha_dump_backtrace() against risks of re-entrance
    * MINOR: tools: protect dladdr() against reentrant calls from the debug handler
    * MINOR: tools: also protect the library name resolution against concurrent accesses
    * BUG/MINOR: debug: detect and prevent re-entrance in ha_thread_dump_fill()
    * BUG/MINOR: wdt/debug: avoid signal re-entrance between debugger and watchdog
    * BUG/MINOR debug: fix !USE_THREAD_DUMP in ha_thread_dump_fill()
    * BUG/MINOR: threads: set threads_idle and threads_harmless even with no threads
    * BUILD: makefile: enable backtrace by default on musl
    * MINOR: compiler: add ASSUME_NONNULL() to tell the compiler a pointer is valid
    * MINOR: compiler: also enable __builtin_assume() for ASSUME()
    * MINOR: compiler: add a new "ASSUME" macro to help the compiler
    * MINOR: compiler: add a __has_builtin() macro to detect features more easily
    * BUG/MEDIUM: hlua: fix hlua_applet_{http,tcp}_fct() yield regression (lost data)
    * BUG/MINOR: h3: reject request URI with invalid characters
    * BUG/MINOR: h3: reject invalid :path in request
    * BUG/MINOR: h3: filter upgrade connection header
    * BUG/MEDIUM: h3: trim whitespaces in header value prior to QPACK encoding
    * BUG/MEDIUM: h3: trim whitespaces when parsing headers value
    * MINOR: debug: detect call instructions and show the branch target in backtraces
    * MINOR: debug: in call traces, dump the 8 bytes before the return address, not after
    * MINOR: tools: let dump_addr_and_bytes() support dumping before the offset
    * BUILD: quic: fix overflow in global tune
    * MINOR: quic: define quic_tune
    * MINOR: quic: transform pacing settings into a global option
    * MINOR: quic: allow BBR testing without pacing
    * MINOR: quic: remove references to burst in quic-cc-algo parsing
    * BUG/MEDIUM: http-ana: Report 502 from req analyzer only during rsp forwarding
    * BUG/MINOR: http-ana: Properly detect client abort when forwarding the response
    * DOC: config: add the missing "force-cfg-parser-pause" to the global kw index
    * DOC: config: add the missing "profiling.memory" to the global kw index
    * BUG/MINOR: debug: remove the trailing \n from BUG_ON() statements
    * BUG/MINOR: hlua: fix invalid errmsg use in hlua_init()
    * BUG/MINOR: backend: do not use the source port when hashing clientip
    * BUG/MEDIUM: sample: fix risk of overflow when replacing multiple regex back-refs
    * BUG/MINOR: log: fix CBOR encoding with LOG_VARTEXT_START() + lf_encode_chunk()
    * CLEANUP: log: adjust _lf_cbor_encode_byte() comment
    * BUG/MINOR: hlua_fcn: fix potential UAF with Queue:pop_wait()
    * MINOR: task: add thread safe notification_new and notification_wake variants
    * TESTS: Fix build for filltab25.c
    * BUG/MEDIUM: stream: Fix a possible freeze during a forced shut on a stream
    * DOC: update INSTALL to reflect the minimum compiler version
    * BUILD: quic_sock: address a strict-aliasing build warning with gcc 5 and 6
    * BUG/MEDIUM: backend: fix reuse with set-dst/set-dst-port
    * BUG/MINOR: backend: do not overwrite srv dst address on reuse
    * BUG/MINOR: rhttp: fix incorrect dst/dst_port values
    * BUILD: compiler: undefine the CONCAT() macro if already defined
    * DOC: config: fix two missing "content" in "tcp-request" examples
    * BUG/MINOR: config: silence .notice/.warning/.alert in discovery mode
    * BUG/MINOR: log: fix gcc warn about truncating NUL terminator while init char arrays
    * BUG/MINOR: mux-quic: remove extra BUG_ON() in _qcc_send_stream()
    * BUG/MEDIUM: mux-quic: fix crash on RS/SS emission if already close local
    * BUG/MEDIUM: peers: prevent learning expiration too far in futur from unsync node
    * BUG/MINOR: peers: fix expire learned from a peer not converted from ms to ticks
    * MINOR: log: support "raw" logformat node typecast

++++ kernel-default:

  - x86/sev: Prepare for using the RMPREAD instruction to access
    the RMP (jsc#PED-348).
  - commit 7285465
  - x86/virt: Provide "nosnp" boot option for sev kernel command
    line (jsc#PED-348).
  - commit 9aba991
  - KVM: SVM: Ensure PSP module is initialized if KVM module is
    built-in (jsc#PED-348).
  - commit 833f5aa
  - crypto: ccp: Add external API interface for PSP module
    initialization (jsc#PED-348).
  - commit a5d6aaa
  - KVM: arm64: vgic: Hoist SGI/PPI alloc from vgic_init() to
    kvm_create_vgic() (jsc#PED-348).
  - commit 10c96b3
  - KVM: arm64: timer: Drop warning on failed interrupt signalling
    (jsc#PED-348).
  - commit 51183b7
  - KVM: arm64: Convert timer offset VA when accessed in HYP code
    (jsc#PED-348).
  - commit 268c80f
  - KVM: arm64: Simplify warning in kvm_arch_vcpu_load_fp()
    (jsc#PED-348).
  - commit 1bc1f92
  - KVM: arm64: Eagerly switch ZCR_EL{1,2} (jsc#PED-348).
  - commit 7a22e64
  - KVM: arm64: Mark some header functions as inline (jsc#PED-348).
  - commit 1cfd25c
  - KVM: arm64: Refactor exit handlers (jsc#PED-348).
  - commit e5402fd
  - KVM: arm64: Refactor CPTR trap deactivation (jsc#PED-348).
  - commit 83cdb48
  - KVM: arm64: Remove VHE host restore of CPACR_EL1.SMEN
    (jsc#PED-348).
  - commit 8be93a3
  - KVM: arm64: Remove VHE host restore of CPACR_EL1.ZEN
    (jsc#PED-348).
  - commit d88a1d3
  - KVM: arm64: Remove host FPSIMD saving for non-protected KVM
    (jsc#PED-348).
  - commit 5181b6b
  - KVM: arm64: Fix __pkvm_host_mkyoung_guest() return value
    (jsc#PED-348).
  - commit faf9635
  - KVM: arm64: Simplify np-guest hypercalls (jsc#PED-348).
  - commit b546f47
  - KVM: arm64: Improve error handling from
    check_host_shared_guest() (jsc#PED-348).
  - commit 2f08e8b
  - KVM: x86/mmu: Ensure NX huge page recovery thread is alive
    before waking (jsc#PED-348).
  - commit 05116bb
  - KVM: remove kvm_arch_post_init_vm (jsc#PED-348).
  - commit 773d5f0
  - KVM: arm64: timer: Don't adjust the EL2 virtual timer offset
    (jsc#PED-348).
  - commit 92a7c8b
  - KVM: arm64: timer: Correctly handle EL1 timer emulation when
    !FEAT_ECV (jsc#PED-348).
  - commit a65b9fa
  - KVM: arm64: timer: Always evaluate the need for a soft timer
    (jsc#PED-348).
  - commit a0fcc9f
  - KVM: arm64: Fail protected mode init if no vgic hardware is
    present (jsc#PED-348).
  - commit 8888838
  - KVM: arm64: Flush/sync debug state in protected mode
    (jsc#PED-348).
  - commit 14c9899
  - KVM: s390: fake memslot for ucontrol VMs (jsc#PED-348).
  - commit 8e19c9f
  - KVM: s390: wrapper for KVM_BUG (jsc#PED-348).
  - commit 54b5f7a
  - KVM: Do not restrict the size of KVM-internal memory regions
    (jsc#PED-348).
  - commit 8fd4c93
  - KVM: s390: vsie: stop using "struct page" for vsie page
    (jsc#PED-348).
  - commit efa5690
  - KVM: s390: vsie: stop messing with page refcount (jsc#PED-348).
  - commit 7a84437
  - KVM: s390: vsie: stop using page->index (jsc#PED-348).
  - commit 6ed9ce8
  - x86/sev: Disable jump tables in SEV startup code (jsc#PED-348).
  - commit 6c45685
  - kvm: defer huge page recovery vhost task to later (jsc#PED-348).
  - blacklist.conf:
  - commit 3499024
  - KVM: x86/mmu: Return RET_PF* instead of 1 in
    kvm_mmu_page_fault() (jsc#PED-348).
  - commit 067a012
  - KVM: Disallow all flags for KVM-internal memslots (jsc#PED-348).
  - commit 12a97a6
  - KVM: x86: Drop double-underscores from __kvm_set_memory_region()
    (jsc#PED-348).
  - commit 5ce4734
  - KVM: Add a dedicated API for setting KVM-internal memslots
    (jsc#PED-348).
  - commit a323072
  - KVM: Assert slots_lock is held when setting memory regions
    (jsc#PED-348).
  - commit fb6ddb3
  - KVM: Open code kvm_set_memory_region() into its sole caller
    (ioctl() API) (jsc#PED-348).
  - commit 256fe59
  - x86/sev: Disable ftrace branch profiling in SEV startup code
    (jsc#PED-348).
  - commit b52c766
  - KVM: arm64: nv: Apply RESx settings to sysreg reset values
    (jsc#PED-348).
  - commit 45b8348
  - Revert "PCI: Avoid reset when disabled via sysfs" (git-fixes).
  - Bluetooth: vhci: Avoid needless snprintf() calls (git-fixes).
  - can: rockchip_canfd: fix broken quirks checks (git-fixes).
  - wifi: wl1251: fix memory leak in wl1251_tx_work (git-fixes).
  - wifi: mac80211: Purge vif txq in ieee80211_do_stop()
    (git-fixes).
  - wifi: at76c50x: fix use after free access in at76_disconnect
    (git-fixes).
  - Bluetooth: l2cap: Check encryption key size on incoming
    connection (git-fixes).
  - Bluetooth: btrtl: Prevent potential NULL dereference
    (git-fixes).
  - Bluetooth: hci_event: Fix sending MGMT_EV_DEVICE_FOUND for
    invalid address (git-fixes).
  - ASoC: fsl: fsl_qmc_audio: Reset audio data pointers on
    TRIGGER_START event (git-fixes).
  - ASoC: cs42l43: Reset clamp override on jack removal (git-fixes).
  - ASoC: codecs:lpass-wsa-macro: Fix logic of enabling vi channels
    (git-fixes).
  - ASoC: codecs:lpass-wsa-macro: Fix vi feedback rate (git-fixes).
  - ASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()
    (git-fixes).
  - ASoC: qcom: Fix sc7280 lpass potential buffer overflow
    (git-fixes).
  - ASoC: dwc: always enable/disable i2s irqs (git-fixes).
  - ASoC: Intel: sof_sdw: Add quirk for Asus Zenbook S16
    (git-fixes).
  - ALSA: hda/realtek - Fixed ASUS platform headset Mic issue
    (git-fixes).
  - ALSA: hda/cirrus_scodec_test: Don't select dependencies
    (git-fixes).
  - platform/x86: amd: pmf: Fix STT limits (git-fixes).
  - asus-laptop: Fix an uninitialized variable (git-fixes).
  - ata: libata-sata: Save all fields from sense data descriptor
    (git-fixes).
  - commit dc52581

++++ kernel-rt:

  - x86/sev: Prepare for using the RMPREAD instruction to access
    the RMP (jsc#PED-348).
  - commit 7285465
  - x86/virt: Provide "nosnp" boot option for sev kernel command
    line (jsc#PED-348).
  - commit 9aba991
  - KVM: SVM: Ensure PSP module is initialized if KVM module is
    built-in (jsc#PED-348).
  - commit 833f5aa
  - crypto: ccp: Add external API interface for PSP module
    initialization (jsc#PED-348).
  - commit a5d6aaa
  - KVM: arm64: vgic: Hoist SGI/PPI alloc from vgic_init() to
    kvm_create_vgic() (jsc#PED-348).
  - commit 10c96b3
  - KVM: arm64: timer: Drop warning on failed interrupt signalling
    (jsc#PED-348).
  - commit 51183b7
  - KVM: arm64: Convert timer offset VA when accessed in HYP code
    (jsc#PED-348).
  - commit 268c80f
  - KVM: arm64: Simplify warning in kvm_arch_vcpu_load_fp()
    (jsc#PED-348).
  - commit 1bc1f92
  - KVM: arm64: Eagerly switch ZCR_EL{1,2} (jsc#PED-348).
  - commit 7a22e64
  - KVM: arm64: Mark some header functions as inline (jsc#PED-348).
  - commit 1cfd25c
  - KVM: arm64: Refactor exit handlers (jsc#PED-348).
  - commit e5402fd
  - KVM: arm64: Refactor CPTR trap deactivation (jsc#PED-348).
  - commit 83cdb48
  - KVM: arm64: Remove VHE host restore of CPACR_EL1.SMEN
    (jsc#PED-348).
  - commit 8be93a3
  - KVM: arm64: Remove VHE host restore of CPACR_EL1.ZEN
    (jsc#PED-348).
  - commit d88a1d3
  - KVM: arm64: Remove host FPSIMD saving for non-protected KVM
    (jsc#PED-348).
  - commit 5181b6b
  - KVM: arm64: Fix __pkvm_host_mkyoung_guest() return value
    (jsc#PED-348).
  - commit faf9635
  - KVM: arm64: Simplify np-guest hypercalls (jsc#PED-348).
  - commit b546f47
  - KVM: arm64: Improve error handling from
    check_host_shared_guest() (jsc#PED-348).
  - commit 2f08e8b
  - KVM: x86/mmu: Ensure NX huge page recovery thread is alive
    before waking (jsc#PED-348).
  - commit 05116bb
  - KVM: remove kvm_arch_post_init_vm (jsc#PED-348).
  - commit 773d5f0
  - KVM: arm64: timer: Don't adjust the EL2 virtual timer offset
    (jsc#PED-348).
  - commit 92a7c8b
  - KVM: arm64: timer: Correctly handle EL1 timer emulation when
    !FEAT_ECV (jsc#PED-348).
  - commit a65b9fa
  - KVM: arm64: timer: Always evaluate the need for a soft timer
    (jsc#PED-348).
  - commit a0fcc9f
  - KVM: arm64: Fail protected mode init if no vgic hardware is
    present (jsc#PED-348).
  - commit 8888838
  - KVM: arm64: Flush/sync debug state in protected mode
    (jsc#PED-348).
  - commit 14c9899
  - KVM: s390: fake memslot for ucontrol VMs (jsc#PED-348).
  - commit 8e19c9f
  - KVM: s390: wrapper for KVM_BUG (jsc#PED-348).
  - commit 54b5f7a
  - KVM: Do not restrict the size of KVM-internal memory regions
    (jsc#PED-348).
  - commit 8fd4c93
  - KVM: s390: vsie: stop using "struct page" for vsie page
    (jsc#PED-348).
  - commit efa5690
  - KVM: s390: vsie: stop messing with page refcount (jsc#PED-348).
  - commit 7a84437
  - KVM: s390: vsie: stop using page->index (jsc#PED-348).
  - commit 6ed9ce8
  - x86/sev: Disable jump tables in SEV startup code (jsc#PED-348).
  - commit 6c45685
  - kvm: defer huge page recovery vhost task to later (jsc#PED-348).
  - blacklist.conf:
  - commit 3499024
  - KVM: x86/mmu: Return RET_PF* instead of 1 in
    kvm_mmu_page_fault() (jsc#PED-348).
  - commit 067a012
  - KVM: Disallow all flags for KVM-internal memslots (jsc#PED-348).
  - commit 12a97a6
  - KVM: x86: Drop double-underscores from __kvm_set_memory_region()
    (jsc#PED-348).
  - commit 5ce4734
  - KVM: Add a dedicated API for setting KVM-internal memslots
    (jsc#PED-348).
  - commit a323072
  - KVM: Assert slots_lock is held when setting memory regions
    (jsc#PED-348).
  - commit fb6ddb3
  - KVM: Open code kvm_set_memory_region() into its sole caller
    (ioctl() API) (jsc#PED-348).
  - commit 256fe59
  - x86/sev: Disable ftrace branch profiling in SEV startup code
    (jsc#PED-348).
  - commit b52c766
  - KVM: arm64: nv: Apply RESx settings to sysreg reset values
    (jsc#PED-348).
  - commit 45b8348
  - Revert "PCI: Avoid reset when disabled via sysfs" (git-fixes).
  - Bluetooth: vhci: Avoid needless snprintf() calls (git-fixes).
  - can: rockchip_canfd: fix broken quirks checks (git-fixes).
  - wifi: wl1251: fix memory leak in wl1251_tx_work (git-fixes).
  - wifi: mac80211: Purge vif txq in ieee80211_do_stop()
    (git-fixes).
  - wifi: at76c50x: fix use after free access in at76_disconnect
    (git-fixes).
  - Bluetooth: l2cap: Check encryption key size on incoming
    connection (git-fixes).
  - Bluetooth: btrtl: Prevent potential NULL dereference
    (git-fixes).
  - Bluetooth: hci_event: Fix sending MGMT_EV_DEVICE_FOUND for
    invalid address (git-fixes).
  - ASoC: fsl: fsl_qmc_audio: Reset audio data pointers on
    TRIGGER_START event (git-fixes).
  - ASoC: cs42l43: Reset clamp override on jack removal (git-fixes).
  - ASoC: codecs:lpass-wsa-macro: Fix logic of enabling vi channels
    (git-fixes).
  - ASoC: codecs:lpass-wsa-macro: Fix vi feedback rate (git-fixes).
  - ASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()
    (git-fixes).
  - ASoC: qcom: Fix sc7280 lpass potential buffer overflow
    (git-fixes).
  - ASoC: dwc: always enable/disable i2s irqs (git-fixes).
  - ASoC: Intel: sof_sdw: Add quirk for Asus Zenbook S16
    (git-fixes).
  - ALSA: hda/realtek - Fixed ASUS platform headset Mic issue
    (git-fixes).
  - ALSA: hda/cirrus_scodec_test: Don't select dependencies
    (git-fixes).
  - platform/x86: amd: pmf: Fix STT limits (git-fixes).
  - asus-laptop: Fix an uninitialized variable (git-fixes).
  - ata: libata-sata: Save all fields from sense data descriptor
    (git-fixes).
  - commit dc52581

++++ nvidia-open-driver-G06-signed:

  - update CUDA variant to 570.133.20

------------------------------------------------------------------
------------------  2025-4-17  -  Apr 17 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Add patch blog-3215.patch
    * Try to avoid blocking mode of 3215 console on s390x as holding
    the output at `MORE' stops blogd, that is that it can not see
    any messages over its socket like switch of the root file system.
  - Add patch blog-install.patch
    * Fixes install problems
    * Use module-setup.sh to install in BUILDROOT

++++ transactional-update:

  - Version 5.0.2
  - Fix continuing from an already booted snapshot
  - Fix check for overlayfs when using tukit open with --discard

++++ iptables:

  - Remove legacy backend from SLES16

++++ kernel-default:

  - Update -rt config files.
  - commit eb8f856
  - config/arm64/rt*: Use delta configs for rt and rt_debug
  - commit 50e0baa
  - config/x86_64/rt*: Use delta configs for rt and rt_debug
  - commit 91bfd3c
  - KVM: arm64: nv: Always evaluate HCR_EL2 using sanitising
    accessors (jsc#PED-348).
  - commit 00f9d3e
  - KVM: arm64: Support trace filtering for guests (jsc#PED-348).
  - commit 4c7c76f
  - KVM: arm64: coresight: Give TRBE enabled state to KVM
    (jsc#PED-348).
  - commit 11d152f
  - KVM: arm64: Drop pkvm_mem_transition for host/hyp donations
    (jsc#PED-348).
  - commit f924906
  - KVM: arm64: Drop pkvm_mem_transition for host/hyp sharing
    (jsc#PED-348).
  - commit 046b34b
  - KVM: arm64: Drop pkvm_mem_transition for FF-A (jsc#PED-348).
  - commit 5b52a59
  - KVM: arm64: Explicitly handle BRBE traps as UNDEFINED
    (jsc#PED-348).
  - commit ed370c6
  - KVM: arm64: vgic: Use str_enabled_disabled() in vgic_v3_probe()
    (jsc#PED-348).
  - commit 3bb6ff9
  - KVM: SVM: Use str_enabled_disabled() helper in
    svm_hardware_setup() (jsc#PED-348).
  - commit 6f41c4e
  - KVM: VMX: read the PML log in the same order as it was written
    (jsc#PED-348).
  - commit bccbcae
  - KVM: VMX: refactor PML terminology (jsc#PED-348).
  - commit b544ed3
  - KVM: VMX: Reinstate __exit attribute for vmx_exit()
    (jsc#PED-348).
  - commit 14a4dce
  - KVM: SVM: Use str_enabled_disabled() helper in
    sev_hardware_setup() (jsc#PED-348).
  - commit 2552094
  - KVM: x86: Use LVT_TIMER instead of an open coded literal
    (jsc#PED-348).
  - commit c79d364
  - x86/tsc: Init the TSC for Secure TSC guests (jsc#PED-348).
  - commit e1bf1ec
  - arm64: rsi: Add automatic arm-cca-guest module loading
    (jsc#PED-348).
  - commit ba7ca3a
  - arm64/sysreg: Update ID_AA64ISAR3_EL1 to DDI0601 2024-09
    (jsc#PED-348).
  - commit 418c6dd
  - KVM: arm64: Allow control of dpISA extensions in
    ID_AA64ISAR3_EL1 (jsc#PED-348).
  - Refresh
    patches.suse/KVM-arm64-Work-around-x1e-s-CNTVOFF_EL2-bogosity.patch.
  - commit 17e5fed
  - arm64: kvm: Introduce nvhe stack size constants (jsc#PED-348).
  - commit 3346c3a
  - KVM: arm64: Fix nVHE stacktrace VA bits mask (jsc#PED-348).
  - commit fba9974
  - x86/sev: Prevent RDTSC/RDTSCP interception for Secure TSC
    enabled guests (jsc#PED-348).
  - commit 91e1f0f
  - x86/sev: Prevent GUEST_TSC_FREQ MSR interception for Secure
    TSC enabled guests (jsc#PED-348).
  - commit 1619aae
  - x86/sev: Change TSC MSR behavior for Secure TSC enabled guests
    (jsc#PED-348).
  - commit 11fb1e6
  - virt: sev-guest: Move SNP Guest Request data pages handling
    under snp_cmd_mutex (jsc#PED-348).
  - blacklist.conf:
  - commit 733c44d
  - x86/sev: Add Secure TSC support for SNP guests (jsc#PED-348).
  - Refresh
    patches.suse/x86-sev-Don-t-hang-but-terminate-on-failure-to-remap.patch.
  - commit b533cc5
  - x86/sev: Don't hang but terminate on failure to remap SVSM CA
    (jsc#PED-348).
  - commit 8116c53
  - x86/sev: Relocate SNP guest messaging routines to common code
    (jsc#PED-348).
  - commit 552d0ba
  - x86/sev: Carve out and export SNP guest messaging init routines
    (jsc#PED-348).
  - commit 2443d39
  - virt: sev-guest: Replace GFP_KERNEL_ACCOUNT with GFP_KERNEL
    (jsc#PED-348).
  - commit 90d0384
  - virt: sev-guest: Remove is_vmpck_empty() helper (jsc#PED-348).
  - commit 1f8e8db
  - KVM: arm64: Work around x1e's CNTVOFF_EL2 bogosity
    (jsc#PED-348).
  - commit f93e623
  - KVM: arm64: nv: Sanitise CNTHCTL_EL2 (jsc#PED-348).
  - commit 203632a
  - KVM: arm64: nv: Propagate CNTHCTL_EL2.EL1NV{P,V}CT bits
    (jsc#PED-348).
  - commit 60a8ea7
  - KVM: arm64: nv: Add trap routing for
    CNTHCTL_EL2.EL1{NVPCT,NVVCT,TVT,TVCT} (jsc#PED-348).
  - commit d9c7361
  - KVM: arm64: Handle counter access early in non-HYP context
    (jsc#PED-348).
  - commit ffbbbd0
  - KVM: arm64: nv: Accelerate EL0 counter accesses from hypervisor
    context (jsc#PED-348).
  - commit 1753972
  - KVM: arm64: nv: Accelerate EL0 timer read accesses when FEAT_ECV
    in use (jsc#PED-348).
  - commit b3d1aef
  - KVM: arm64: nv: Use FEAT_ECV to trap access to EL0 timers
    (jsc#PED-348).
  - commit e031801
  - KVM: arm64: nv: Publish emulated timer interrupt state in the
    in-memory state (jsc#PED-348).
  - commit 0a26877
  - KVM: arm64: nv: Sync nested timer state with FEAT_NV2
    (jsc#PED-348).
  - commit 1650047
  - KVM: arm64: nv: Add handling of EL2-specific timer registers
    (jsc#PED-348).
  - commit 207d743
  - x86/sev: Disable UBSAN on SEV code that may execute very early
    (jsc#PED-348).
  - commit 876b85f
  - RISC-V: KVM: Add SBI system suspend support (jsc#PED-348).
  - commit f08bd14
  - KVM: x86/mmu: Prevent aliased memslot GFNs (jsc#PED-348).
  - commit a6d398c
  - KVM: x86/tdp_mmu: Don't zap valid mirror roots in
    kvm_tdp_mmu_zap_all() (jsc#PED-348).
  - commit 54a655a
  - KVM: x86/tdp_mmu: Take root types for
    kvm_tdp_mmu_invalidate_all_roots() (jsc#PED-348).
  - commit a57e36b
  - KVM: x86/tdp_mmu: Propagate tearing down mirror page tables
    (jsc#PED-348).
  - commit 1a40f72
  - KVM: x86/tdp_mmu: Propagate building mirror page tables
    (jsc#PED-348).
  - commit 3cccd94
  - KVM: x86/tdp_mmu: Propagate attr_filter to MMU notifier
    callbacks (jsc#PED-348).
  - commit b7f9b9b
  - KVM: x86/tdp_mmu: Support mirror root for TDP MMU (jsc#PED-348).
  - commit 517d32a
  - KVM: x86/tdp_mmu: Take root in tdp_mmu_for_each_pte()
    (jsc#PED-348).
  - commit d476e94
  - KVM: x86/tdp_mmu: Introduce KVM MMU root types to specify page
    table type (jsc#PED-348).
  - commit 0ed70b6
  - KVM: x86/tdp_mmu: Extract root invalid check from
    tdx_mmu_next_root() (jsc#PED-348).
  - commit dd22ac6
  - KVM: x86/mmu: Support GFN direct bits (jsc#PED-348).
  - commit d7ff58c
  - KVM: x86/tdp_mmu: Take struct kvm in iter loops (jsc#PED-348).
  - commit f86a705
  - KVM: x86/mmu: Make kvm_tdp_mmu_alloc_root() return void
    (jsc#PED-348).
  - commit a83e9e3
  - enabled CONFIG_DAMON (jsc#PED-12520)
  - commit 0674446
  - KVM: x86/mmu: Add an is_mirror member for union
    kvm_mmu_page_role (jsc#PED-348).
  - commit c30eeae
  - KVM: x86: Add a VM type define for TDX (jsc#PED-348).
  - commit ee9ed63
  - KVM: x86/mmu: Add an external pointer to struct kvm_mmu_page
    (jsc#PED-348).
  - commit e95d7d7
  - KVM: Add member to struct kvm_gfn_range to indicate
    private/shared (jsc#PED-348).
  - commit 1c2ff6d
  - KVM: x86/mmu: Zap invalid roots with mmu_lock holding for
    write at uninit (jsc#PED-348).
  - commit 13bf1e1
  - KVM: guest_memfd: Remove RCU-protected attribute from
    slot->gmem.file (jsc#PED-348).
  - commit 4d8e2b2
  - KVM: x86: Refactor __kvm_emulate_hypercall() into a macro
    (jsc#PED-348).
  - commit fe456a9
  - KVM: x86: Always complete hypercall via function callback
    (jsc#PED-348).
  - commit 6308fc3
  - KVM: x86: Bump hypercall stat prior to fully completing
    hypercall (jsc#PED-348).
  - commit e5b686b
  - KVM: x86: Move "emulate hypercall" function declarations to
    x86.h (jsc#PED-348).
  - commit 823ce3c
  - KVM: x86: Add a helper to check for user interception of KVM
    hypercalls (jsc#PED-348).
  - commit 18023dd
  - KVM: x86: clear vcpu->run->hypercall.ret before exiting for
    KVM_EXIT_HYPERCALL (jsc#PED-348).
  - commit 5595e7d
  - KVM: arm64: nv: Advertise the lack of AArch32 EL0 support
    (jsc#PED-348).
  - commit 2506605
  - KVM: arm64: Use kvm_vcpu_has_feature() directly for struct kvm
    (jsc#PED-348).
  - commit 0cabcd6
  - KVM: arm64: Fix FEAT_MTE in pKVM (jsc#PED-348).
  - blacklist.conf:
  - commit afe065b
  - KVM: arm64: Convert the SVE guest vcpu flag to a vm flag
    (jsc#PED-348).
  - commit 57f384a
  - KVM: arm64: Remove PtrAuth guest vcpu flag (jsc#PED-348).
  - commit 1727949
  - KVM: arm64: Fix the value of the CPTR_EL2 RES1 bitmask for nVHE
    (jsc#PED-348).
  - commit b2aa45c
  - KVM: arm64: Refactor kvm_reset_cptr_el2() (jsc#PED-348).
  - commit a627719
  - KVM: arm64: Calculate cptr_el2 traps on activating traps
    (jsc#PED-348).
  - commit ee465fa
  - KVM: arm64: Remove redundant setting of HCR_EL2 trap bit
    (jsc#PED-348).
  - commit 28bdeb3
  - KVM: arm64: Remove fixed_config.h header (jsc#PED-348).
  - commit 5791ec1
  - KVM: arm64: Rework specifying restricted features for protected
    VMs (jsc#PED-348).
  - commit 2f8220d
  - KVM: arm64: Set protected VM traps based on its view of feature
    registers (jsc#PED-348).
  - commit f831267
  - KVM: arm64: Fix RAS trapping in pKVM for protected VMs
    (jsc#PED-348).
  - commit 6cee1f3
  - KVM: arm64: Initialize feature id registers for protected VMs
    (jsc#PED-348).
  - commit 1ac9df5
  - KVM: arm64: Use KVM extension checks for allowed protected VM
    capabilities (jsc#PED-348).
  - commit 13df3e5
  - KVM: arm64: Remove KVM_ARM_VCPU_POWER_OFF from protected VMs
    allowed features in pKVM (jsc#PED-348).
  - commit 5b3a7f3
  - KVM: arm64: Move checking protected vcpu features to a separate
    function (jsc#PED-348).
  - commit c2816cc
  - KVM: arm64: Group setting traps for protected VMs by control
    register (jsc#PED-348).
  - commit 16f522d
  - KVM: arm64: Consolidate allowed and restricted VM feature checks
    (jsc#PED-348).
  - commit 077b10b
  - KVM: arm64: Plumb the pKVM MMU in KVM (jsc#PED-348).
  - commit 06d9e82
  - KVM: arm64: Introduce the EL1 pKVM MMU (jsc#PED-348).
  - commit 77ef574
  - KVM: arm64: Introduce __pkvm_tlb_flush_vmid() (jsc#PED-348).
  - commit f67a1b6
  - rpm/kernel-binary.spec.in: Also order against update-bootloader
    (boo#1228659, boo#1240785, boo#1241038).
  - commit fe0a8c9
  - KVM: arm64: Introduce __pkvm_host_mkyoung_guest() (jsc#PED-348).
  - commit 4b5f88b
  - KVM: arm64: Introduce __pkvm_host_test_clear_young_guest()
    (jsc#PED-348).
  - commit 35723b2
  - KVM: arm64: Introduce __pkvm_host_wrprotect_guest()
    (jsc#PED-348).
  - commit 245cc05
  - KVM: arm64: Introduce __pkvm_host_relax_guest_perms()
    (jsc#PED-348).
  - commit c7cc89c
  - KVM: arm64: Introduce __pkvm_host_unshare_guest() (jsc#PED-348).
  - commit d7cae74
  - KVM: arm64: Introduce __pkvm_host_share_guest() (jsc#PED-348).
  - commit e6080ad
  - KVM: arm64: Introduce __pkvm_vcpu_{load,put}() (jsc#PED-348).
  - commit 6802451
  - KVM: arm64: Add {get,put}_pkvm_hyp_vm() helpers (jsc#PED-348).
  - commit 9121741
  - KVM: arm64: Make kvm_pgtable_stage2_init() a static inline
    function (jsc#PED-348).
  - commit c15dc2c
  - KVM: arm64: Pass walk flags to kvm_pgtable_stage2_relax_perms
    (jsc#PED-348).
  - commit 06b61af
  - KVM: arm64: Pass walk flags to kvm_pgtable_stage2_mkyoung
    (jsc#PED-348).
  - commit 93eac59
  - KVM: arm64: Move host page ownership tracking to the hyp vmemmap
    (jsc#PED-348).
  - commit 5ea671f
  - KVM: arm64: Make hyp_page::order a u8 (jsc#PED-348).
  - commit 7081de3
  - KVM: arm64: Move enum pkvm_page_state to memory.h (jsc#PED-348).
  - commit 7e99c55
  - KVM: arm64: Change the layout of enum pkvm_page_state
    (jsc#PED-348).
  - commit 38fe175
  - KVM: arm64: Promote guest ownership for DBGxVR/DBGxCR reads
    (jsc#PED-348).
  - commit a24d033
  - KVM: arm64: Fold DBGxVR/DBGxCR accessors into common set
    (jsc#PED-348).
  - commit a959b03
  - KVM: arm64: Avoid reading ID_AA64DFR0_EL1 for debug save/restore
    (jsc#PED-348).
  - commit 42d7f35
  - KVM: arm64: nv: Honor MDCR_EL2.TDE routing for debug exceptions
    (jsc#PED-348).
  - commit a690913
  - KVM: arm64: Manage software step state at load/put
    (jsc#PED-348).
  - commit 318d8db
  - KVM: arm64: Don't hijack guest context MDSCR_EL1 (jsc#PED-348).
  - commit c57ed08
  - KVM: arm64: Compute MDCR_EL2 at vcpu_load() (jsc#PED-348).
  - commit 8b69d67
  - KVM: arm64: Reload vCPU for accesses to OSLAR_EL1 (jsc#PED-348).
  - commit f901dd3
  - KVM: arm64: Use debug_owner to track if debug regs need
    save/restore (jsc#PED-348).
  - commit 0d72241
  - KVM: arm64: Remove vestiges of debug_ptr (jsc#PED-348).
  - commit 55a0c51
  - KVM: arm64: Remove debug tracepoints (jsc#PED-348).
  - commit 072a66f
  - KVM: arm64: Select debug state to save/restore based on debug
    owner (jsc#PED-348).
  - commit 5d875f7
  - KVM: arm64: Clean up KVM_SET_GUEST_DEBUG handler (jsc#PED-348).
  - commit 23c64df
  - KVM: arm64: Evaluate debug owner at vcpu_load() (jsc#PED-348).
  - commit bf4bfe0
  - KVM: arm64: Write MDCR_EL2 directly from
    kvm_arm_setup_mdcr_el2() (jsc#PED-348).
  - commit e06e0a3
  - KVM: arm64: Move host SME/SVE tracking flags to host data
    (jsc#PED-348).
  - Refresh
    patches.suse/KVM-arm64-Unconditionally-save-flush-host-FPSIMD-SVE-SME-state.patch.
  - commit 96b52e1
  - KVM: arm64: Track presence of SPE/TRBE in kvm_host_data instead
    of vCPU (jsc#PED-348).
  - commit 02bb671
  - KVM: arm64: Get rid of __kvm_get_mdcr_el2() and related warts
    (jsc#PED-348).
  - commit 360d175
  - KVM: arm64: Drop MDSCR_EL1_DEBUG_MASK (jsc#PED-348).
  - commit 654a038
  - arm64/sysreg: Get rid of CPACR_ELx SysregFields (jsc#PED-348).
  - commit 4f6a67e
  - arm64/sysreg: Convert *_EL12 accessors to Mapping (jsc#PED-348).
  - commit ab8171a
  - arm64/sysreg: Get rid of the TCR2_EL1x SysregFields
    (jsc#PED-348).
  - commit ac99b49
  - arm64: setup: name 'tcr2' register (jsc#PED-348).
  - commit 083cc0a
  - arm64/sysreg: Allow a 'Mapping' descriptor for system registers
    (jsc#PED-348).
  - commit e10ff75
  - arm64/kvm: Avoid invalid physical addresses to signal owner
    updates (jsc#PED-348).
  - commit 5332312
  - arm64/kvm: Configure HYP TCR.PS/DS based on host stage1
    (jsc#PED-348).
  - commit 3fa17e8
  - KVM: x86: Remove hwapic_irr_update() from kvm_x86_ops
    (jsc#PED-348).
  - commit ec44993
  - KVM: nVMX: Honor event priority when emulating PI delivery
    during VM-Enter (jsc#PED-348).
  - commit 8b35f41
  - KVM: nVMX: Use vmcs01's controls shadow to check for IRQ/NMI
    windows at VM-Enter (jsc#PED-348).
  - commit 227df19
  - KVM: nVMX: Drop manual vmcs01.GUEST_INTERRUPT_STATUS.RVI check
    at VM-Enter (jsc#PED-348).
  - commit 2678d06
  - KVM: nVMX: Check for pending INIT/SIPI after entering non-root
    mode (jsc#PED-348).
  - commit 5281aec
  - KVM: nVMX: Explicitly update vPPR on successful nested VM-Enter
    (jsc#PED-348).
  - commit d094324
  - KVM: x86: Add information about pending requests to kvm_exit
    tracepoint (jsc#PED-348).
  - commit 62af53f
  - KVM: x86: Add interrupt injection information to the kvm_entry
    tracepoint (jsc#PED-348).
  - commit 19c8851
  - KVM: SVM: Handle event vectoring error in
    check_emulate_instruction() (jsc#PED-348).
  - commit 9866a06
  - KVM: VMX: Handle event vectoring error in
    check_emulate_instruction() (jsc#PED-348).
  - commit 3f9c1bc
  - KVM: x86: Try to unprotect and retry on unhandleable emulation
    failure (jsc#PED-348).
  - commit 23860d1
  - KVM: x86: Add emulation status for unhandleable exception
    vectoring (jsc#PED-348).
  - commit 9d2063a
  - KVM: x86: Add function for vectoring error generation
    (jsc#PED-348).
  - commit b30b581
  - KVM: x86: Use only local variables (no bitmask) to init
    kvm_cpu_caps (jsc#PED-348).
  - commit 7fe2c13
  - KVM: x86: Explicitly track feature flags that are enabled at
    runtime (jsc#PED-348).
  - commit ee49c88
  - KVM: x86: Explicitly track feature flags that require vendor
    enabling (jsc#PED-348).
  - commit 50a4cc7
  - KVM: x86: Rename "SF" macro to "SCATTERED_F" (jsc#PED-348).
  - commit fc020fe
  - KVM: x86: Pull CPUID capabilities from boot_cpu_data only as
    needed (jsc#PED-348).
  - commit dad6907
  - KVM: x86: Add a macro for features that are synthesized into
    boot_cpu_data (jsc#PED-348).
  - commit 90f17ed
  - KVM: x86: Drop superfluous host XSAVE check when adjusting
    guest XSAVES caps (jsc#PED-348).
  - commit eeb8bd7
  - KVM: x86: Replace (almost) all guest CPUID feature queries
    with cpu_caps (jsc#PED-348).
  - commit bafc961
  - KVM: x86: Shuffle code to prepare for dropping guest_cpuid_has()
    (jsc#PED-348).
  - commit ae3d20d
  - KVM: x86: Update guest cpu_caps at runtime for dynamic
    CPUID-based features (jsc#PED-348).
  - commit 088e022
  - KVM: x86: Update OS{XSAVE,PKE} bits in guest CPUID irrespective
    of host support (jsc#PED-348).
  - commit e29333b
  - KVM: x86: Drop unnecessary check that cpuid_entry2_find()
    returns right leaf (jsc#PED-348).
  - commit 3744528
  - KVM: x86: Avoid double CPUID lookup when updating MWAIT at
    runtime (jsc#PED-348).
  - commit b1910e2
  - KVM: x86: Initialize guest cpu_caps based on KVM support
    (jsc#PED-348).
  - commit 9ca94f2
  - KVM: x86: Treat MONTIOR/MWAIT as a "partially emulated" feature
    (jsc#PED-348).
  - commit 12694d7
  - KVM: x86: Extract code for generating per-entry emulated CPUID
    information (jsc#PED-348).
  - commit 6b47ba9
  - KVM: x86: Initialize guest cpu_caps based on guest CPUID
    (jsc#PED-348).
  - commit c4ec6d7
  - KVM: x86: Replace guts of "governed" features with comprehensive
    cpu_caps (jsc#PED-348).
  - commit 744133e
  - radix-tree: add missing cleanup.h (git-fixes).
  - crypto: caam/qi - Fix drv_ctx refcount bug (git-fixes).
  - commit 3c5ba83
  - KVM: x86: Rename "governed features" helpers to use
    "guest_cpu_cap" (jsc#PED-348).
  - commit 0fff997
  - KVM: x86: Advertise HYPERVISOR in KVM_GET_SUPPORTED_CPUID
    (jsc#PED-348).
  - commit 3203ab7
  - KVM: x86: Advertise TSC_DEADLINE_TIMER in
    KVM_GET_SUPPORTED_CPUID (jsc#PED-348).
  - commit a3e58fe
  - KVM: x86: Remove all direct usage of cpuid_entry2_find()
    (jsc#PED-348).
  - commit bf23d0c
  - KVM: x86: Move kvm_find_cpuid_entry{,_index}() up near
    cpuid_entry2_find() (jsc#PED-348).
  - commit 2a644e6
  - KVM: x86: Always operate on kvm_vcpu data in cpuid_entry2_find()
    (jsc#PED-348).
  - commit 843079b
  - KVM: x86: Remove unnecessary caching of KVM's PV CPUID base
    (jsc#PED-348).
  - commit cdb8730
  - KVM: x86: Clear PV_UNHALT for !HLT-exiting only when userspace
    sets CPUID (jsc#PED-348).
  - commit 74aaac1
  - KVM: x86: Swap incoming guest CPUID into vCPU before massaging
    in KVM_SET_CPUID2 (jsc#PED-348).
  - commit 9defaee
  - KVM: x86: Add a macro to init CPUID features that KVM emulates
    in software (jsc#PED-348).
  - commit eb8f359

++++ kernel-rt:

  - Update -rt config files.
  - commit eb8f856
  - config/arm64/rt*: Use delta configs for rt and rt_debug
  - commit 50e0baa
  - config/x86_64/rt*: Use delta configs for rt and rt_debug
  - commit 91bfd3c
  - KVM: arm64: nv: Always evaluate HCR_EL2 using sanitising
    accessors (jsc#PED-348).
  - commit 00f9d3e
  - KVM: arm64: Support trace filtering for guests (jsc#PED-348).
  - commit 4c7c76f
  - KVM: arm64: coresight: Give TRBE enabled state to KVM
    (jsc#PED-348).
  - commit 11d152f
  - KVM: arm64: Drop pkvm_mem_transition for host/hyp donations
    (jsc#PED-348).
  - commit f924906
  - KVM: arm64: Drop pkvm_mem_transition for host/hyp sharing
    (jsc#PED-348).
  - commit 046b34b
  - KVM: arm64: Drop pkvm_mem_transition for FF-A (jsc#PED-348).
  - commit 5b52a59
  - KVM: arm64: Explicitly handle BRBE traps as UNDEFINED
    (jsc#PED-348).
  - commit ed370c6
  - KVM: arm64: vgic: Use str_enabled_disabled() in vgic_v3_probe()
    (jsc#PED-348).
  - commit 3bb6ff9
  - KVM: SVM: Use str_enabled_disabled() helper in
    svm_hardware_setup() (jsc#PED-348).
  - commit 6f41c4e
  - KVM: VMX: read the PML log in the same order as it was written
    (jsc#PED-348).
  - commit bccbcae
  - KVM: VMX: refactor PML terminology (jsc#PED-348).
  - commit b544ed3
  - KVM: VMX: Reinstate __exit attribute for vmx_exit()
    (jsc#PED-348).
  - commit 14a4dce
  - KVM: SVM: Use str_enabled_disabled() helper in
    sev_hardware_setup() (jsc#PED-348).
  - commit 2552094
  - KVM: x86: Use LVT_TIMER instead of an open coded literal
    (jsc#PED-348).
  - commit c79d364
  - x86/tsc: Init the TSC for Secure TSC guests (jsc#PED-348).
  - commit e1bf1ec
  - arm64: rsi: Add automatic arm-cca-guest module loading
    (jsc#PED-348).
  - commit ba7ca3a
  - arm64/sysreg: Update ID_AA64ISAR3_EL1 to DDI0601 2024-09
    (jsc#PED-348).
  - commit 418c6dd
  - KVM: arm64: Allow control of dpISA extensions in
    ID_AA64ISAR3_EL1 (jsc#PED-348).
  - Refresh
    patches.suse/KVM-arm64-Work-around-x1e-s-CNTVOFF_EL2-bogosity.patch.
  - commit 17e5fed
  - arm64: kvm: Introduce nvhe stack size constants (jsc#PED-348).
  - commit 3346c3a
  - KVM: arm64: Fix nVHE stacktrace VA bits mask (jsc#PED-348).
  - commit fba9974
  - x86/sev: Prevent RDTSC/RDTSCP interception for Secure TSC
    enabled guests (jsc#PED-348).
  - commit 91e1f0f
  - x86/sev: Prevent GUEST_TSC_FREQ MSR interception for Secure
    TSC enabled guests (jsc#PED-348).
  - commit 1619aae
  - x86/sev: Change TSC MSR behavior for Secure TSC enabled guests
    (jsc#PED-348).
  - commit 11fb1e6
  - virt: sev-guest: Move SNP Guest Request data pages handling
    under snp_cmd_mutex (jsc#PED-348).
  - blacklist.conf:
  - commit 733c44d
  - x86/sev: Add Secure TSC support for SNP guests (jsc#PED-348).
  - Refresh
    patches.suse/x86-sev-Don-t-hang-but-terminate-on-failure-to-remap.patch.
  - commit b533cc5
  - x86/sev: Don't hang but terminate on failure to remap SVSM CA
    (jsc#PED-348).
  - commit 8116c53
  - x86/sev: Relocate SNP guest messaging routines to common code
    (jsc#PED-348).
  - commit 552d0ba
  - x86/sev: Carve out and export SNP guest messaging init routines
    (jsc#PED-348).
  - commit 2443d39
  - virt: sev-guest: Replace GFP_KERNEL_ACCOUNT with GFP_KERNEL
    (jsc#PED-348).
  - commit 90d0384
  - virt: sev-guest: Remove is_vmpck_empty() helper (jsc#PED-348).
  - commit 1f8e8db
  - KVM: arm64: Work around x1e's CNTVOFF_EL2 bogosity
    (jsc#PED-348).
  - commit f93e623
  - KVM: arm64: nv: Sanitise CNTHCTL_EL2 (jsc#PED-348).
  - commit 203632a
  - KVM: arm64: nv: Propagate CNTHCTL_EL2.EL1NV{P,V}CT bits
    (jsc#PED-348).
  - commit 60a8ea7
  - KVM: arm64: nv: Add trap routing for
    CNTHCTL_EL2.EL1{NVPCT,NVVCT,TVT,TVCT} (jsc#PED-348).
  - commit d9c7361
  - KVM: arm64: Handle counter access early in non-HYP context
    (jsc#PED-348).
  - commit ffbbbd0
  - KVM: arm64: nv: Accelerate EL0 counter accesses from hypervisor
    context (jsc#PED-348).
  - commit 1753972
  - KVM: arm64: nv: Accelerate EL0 timer read accesses when FEAT_ECV
    in use (jsc#PED-348).
  - commit b3d1aef
  - KVM: arm64: nv: Use FEAT_ECV to trap access to EL0 timers
    (jsc#PED-348).
  - commit e031801
  - KVM: arm64: nv: Publish emulated timer interrupt state in the
    in-memory state (jsc#PED-348).
  - commit 0a26877
  - KVM: arm64: nv: Sync nested timer state with FEAT_NV2
    (jsc#PED-348).
  - commit 1650047
  - KVM: arm64: nv: Add handling of EL2-specific timer registers
    (jsc#PED-348).
  - commit 207d743
  - x86/sev: Disable UBSAN on SEV code that may execute very early
    (jsc#PED-348).
  - commit 876b85f
  - RISC-V: KVM: Add SBI system suspend support (jsc#PED-348).
  - commit f08bd14
  - KVM: x86/mmu: Prevent aliased memslot GFNs (jsc#PED-348).
  - commit a6d398c
  - KVM: x86/tdp_mmu: Don't zap valid mirror roots in
    kvm_tdp_mmu_zap_all() (jsc#PED-348).
  - commit 54a655a
  - KVM: x86/tdp_mmu: Take root types for
    kvm_tdp_mmu_invalidate_all_roots() (jsc#PED-348).
  - commit a57e36b
  - KVM: x86/tdp_mmu: Propagate tearing down mirror page tables
    (jsc#PED-348).
  - commit 1a40f72
  - KVM: x86/tdp_mmu: Propagate building mirror page tables
    (jsc#PED-348).
  - commit 3cccd94
  - KVM: x86/tdp_mmu: Propagate attr_filter to MMU notifier
    callbacks (jsc#PED-348).
  - commit b7f9b9b
  - KVM: x86/tdp_mmu: Support mirror root for TDP MMU (jsc#PED-348).
  - commit 517d32a
  - KVM: x86/tdp_mmu: Take root in tdp_mmu_for_each_pte()
    (jsc#PED-348).
  - commit d476e94
  - KVM: x86/tdp_mmu: Introduce KVM MMU root types to specify page
    table type (jsc#PED-348).
  - commit 0ed70b6
  - KVM: x86/tdp_mmu: Extract root invalid check from
    tdx_mmu_next_root() (jsc#PED-348).
  - commit dd22ac6
  - KVM: x86/mmu: Support GFN direct bits (jsc#PED-348).
  - commit d7ff58c
  - KVM: x86/tdp_mmu: Take struct kvm in iter loops (jsc#PED-348).
  - commit f86a705
  - KVM: x86/mmu: Make kvm_tdp_mmu_alloc_root() return void
    (jsc#PED-348).
  - commit a83e9e3
  - enabled CONFIG_DAMON (jsc#PED-12520)
  - commit 0674446
  - KVM: x86/mmu: Add an is_mirror member for union
    kvm_mmu_page_role (jsc#PED-348).
  - commit c30eeae
  - KVM: x86: Add a VM type define for TDX (jsc#PED-348).
  - commit ee9ed63
  - KVM: x86/mmu: Add an external pointer to struct kvm_mmu_page
    (jsc#PED-348).
  - commit e95d7d7
  - KVM: Add member to struct kvm_gfn_range to indicate
    private/shared (jsc#PED-348).
  - commit 1c2ff6d
  - KVM: x86/mmu: Zap invalid roots with mmu_lock holding for
    write at uninit (jsc#PED-348).
  - commit 13bf1e1
  - KVM: guest_memfd: Remove RCU-protected attribute from
    slot->gmem.file (jsc#PED-348).
  - commit 4d8e2b2
  - KVM: x86: Refactor __kvm_emulate_hypercall() into a macro
    (jsc#PED-348).
  - commit fe456a9
  - KVM: x86: Always complete hypercall via function callback
    (jsc#PED-348).
  - commit 6308fc3
  - KVM: x86: Bump hypercall stat prior to fully completing
    hypercall (jsc#PED-348).
  - commit e5b686b
  - KVM: x86: Move "emulate hypercall" function declarations to
    x86.h (jsc#PED-348).
  - commit 823ce3c
  - KVM: x86: Add a helper to check for user interception of KVM
    hypercalls (jsc#PED-348).
  - commit 18023dd
  - KVM: x86: clear vcpu->run->hypercall.ret before exiting for
    KVM_EXIT_HYPERCALL (jsc#PED-348).
  - commit 5595e7d
  - KVM: arm64: nv: Advertise the lack of AArch32 EL0 support
    (jsc#PED-348).
  - commit 2506605
  - KVM: arm64: Use kvm_vcpu_has_feature() directly for struct kvm
    (jsc#PED-348).
  - commit 0cabcd6
  - KVM: arm64: Fix FEAT_MTE in pKVM (jsc#PED-348).
  - blacklist.conf:
  - commit afe065b
  - KVM: arm64: Convert the SVE guest vcpu flag to a vm flag
    (jsc#PED-348).
  - commit 57f384a
  - KVM: arm64: Remove PtrAuth guest vcpu flag (jsc#PED-348).
  - commit 1727949
  - KVM: arm64: Fix the value of the CPTR_EL2 RES1 bitmask for nVHE
    (jsc#PED-348).
  - commit b2aa45c
  - KVM: arm64: Refactor kvm_reset_cptr_el2() (jsc#PED-348).
  - commit a627719
  - KVM: arm64: Calculate cptr_el2 traps on activating traps
    (jsc#PED-348).
  - commit ee465fa
  - KVM: arm64: Remove redundant setting of HCR_EL2 trap bit
    (jsc#PED-348).
  - commit 28bdeb3
  - KVM: arm64: Remove fixed_config.h header (jsc#PED-348).
  - commit 5791ec1
  - KVM: arm64: Rework specifying restricted features for protected
    VMs (jsc#PED-348).
  - commit 2f8220d
  - KVM: arm64: Set protected VM traps based on its view of feature
    registers (jsc#PED-348).
  - commit f831267
  - KVM: arm64: Fix RAS trapping in pKVM for protected VMs
    (jsc#PED-348).
  - commit 6cee1f3
  - KVM: arm64: Initialize feature id registers for protected VMs
    (jsc#PED-348).
  - commit 1ac9df5
  - KVM: arm64: Use KVM extension checks for allowed protected VM
    capabilities (jsc#PED-348).
  - commit 13df3e5
  - KVM: arm64: Remove KVM_ARM_VCPU_POWER_OFF from protected VMs
    allowed features in pKVM (jsc#PED-348).
  - commit 5b3a7f3
  - KVM: arm64: Move checking protected vcpu features to a separate
    function (jsc#PED-348).
  - commit c2816cc
  - KVM: arm64: Group setting traps for protected VMs by control
    register (jsc#PED-348).
  - commit 16f522d
  - KVM: arm64: Consolidate allowed and restricted VM feature checks
    (jsc#PED-348).
  - commit 077b10b
  - KVM: arm64: Plumb the pKVM MMU in KVM (jsc#PED-348).
  - commit 06d9e82
  - KVM: arm64: Introduce the EL1 pKVM MMU (jsc#PED-348).
  - commit 77ef574
  - KVM: arm64: Introduce __pkvm_tlb_flush_vmid() (jsc#PED-348).
  - commit f67a1b6
  - rpm/kernel-binary.spec.in: Also order against update-bootloader
    (boo#1228659, boo#1240785, boo#1241038).
  - commit fe0a8c9
  - KVM: arm64: Introduce __pkvm_host_mkyoung_guest() (jsc#PED-348).
  - commit 4b5f88b
  - KVM: arm64: Introduce __pkvm_host_test_clear_young_guest()
    (jsc#PED-348).
  - commit 35723b2
  - KVM: arm64: Introduce __pkvm_host_wrprotect_guest()
    (jsc#PED-348).
  - commit 245cc05
  - KVM: arm64: Introduce __pkvm_host_relax_guest_perms()
    (jsc#PED-348).
  - commit c7cc89c
  - KVM: arm64: Introduce __pkvm_host_unshare_guest() (jsc#PED-348).
  - commit d7cae74
  - KVM: arm64: Introduce __pkvm_host_share_guest() (jsc#PED-348).
  - commit e6080ad
  - KVM: arm64: Introduce __pkvm_vcpu_{load,put}() (jsc#PED-348).
  - commit 6802451
  - KVM: arm64: Add {get,put}_pkvm_hyp_vm() helpers (jsc#PED-348).
  - commit 9121741
  - KVM: arm64: Make kvm_pgtable_stage2_init() a static inline
    function (jsc#PED-348).
  - commit c15dc2c
  - KVM: arm64: Pass walk flags to kvm_pgtable_stage2_relax_perms
    (jsc#PED-348).
  - commit 06b61af
  - KVM: arm64: Pass walk flags to kvm_pgtable_stage2_mkyoung
    (jsc#PED-348).
  - commit 93eac59
  - KVM: arm64: Move host page ownership tracking to the hyp vmemmap
    (jsc#PED-348).
  - commit 5ea671f
  - KVM: arm64: Make hyp_page::order a u8 (jsc#PED-348).
  - commit 7081de3
  - KVM: arm64: Move enum pkvm_page_state to memory.h (jsc#PED-348).
  - commit 7e99c55
  - KVM: arm64: Change the layout of enum pkvm_page_state
    (jsc#PED-348).
  - commit 38fe175
  - KVM: arm64: Promote guest ownership for DBGxVR/DBGxCR reads
    (jsc#PED-348).
  - commit a24d033
  - KVM: arm64: Fold DBGxVR/DBGxCR accessors into common set
    (jsc#PED-348).
  - commit a959b03
  - KVM: arm64: Avoid reading ID_AA64DFR0_EL1 for debug save/restore
    (jsc#PED-348).
  - commit 42d7f35
  - KVM: arm64: nv: Honor MDCR_EL2.TDE routing for debug exceptions
    (jsc#PED-348).
  - commit a690913
  - KVM: arm64: Manage software step state at load/put
    (jsc#PED-348).
  - commit 318d8db
  - KVM: arm64: Don't hijack guest context MDSCR_EL1 (jsc#PED-348).
  - commit c57ed08
  - KVM: arm64: Compute MDCR_EL2 at vcpu_load() (jsc#PED-348).
  - commit 8b69d67
  - KVM: arm64: Reload vCPU for accesses to OSLAR_EL1 (jsc#PED-348).
  - commit f901dd3
  - KVM: arm64: Use debug_owner to track if debug regs need
    save/restore (jsc#PED-348).
  - commit 0d72241
  - KVM: arm64: Remove vestiges of debug_ptr (jsc#PED-348).
  - commit 55a0c51
  - KVM: arm64: Remove debug tracepoints (jsc#PED-348).
  - commit 072a66f
  - KVM: arm64: Select debug state to save/restore based on debug
    owner (jsc#PED-348).
  - commit 5d875f7
  - KVM: arm64: Clean up KVM_SET_GUEST_DEBUG handler (jsc#PED-348).
  - commit 23c64df
  - KVM: arm64: Evaluate debug owner at vcpu_load() (jsc#PED-348).
  - commit bf4bfe0
  - KVM: arm64: Write MDCR_EL2 directly from
    kvm_arm_setup_mdcr_el2() (jsc#PED-348).
  - commit e06e0a3
  - KVM: arm64: Move host SME/SVE tracking flags to host data
    (jsc#PED-348).
  - Refresh
    patches.suse/KVM-arm64-Unconditionally-save-flush-host-FPSIMD-SVE-SME-state.patch.
  - commit 96b52e1
  - KVM: arm64: Track presence of SPE/TRBE in kvm_host_data instead
    of vCPU (jsc#PED-348).
  - commit 02bb671
  - KVM: arm64: Get rid of __kvm_get_mdcr_el2() and related warts
    (jsc#PED-348).
  - commit 360d175
  - KVM: arm64: Drop MDSCR_EL1_DEBUG_MASK (jsc#PED-348).
  - commit 654a038
  - arm64/sysreg: Get rid of CPACR_ELx SysregFields (jsc#PED-348).
  - commit 4f6a67e
  - arm64/sysreg: Convert *_EL12 accessors to Mapping (jsc#PED-348).
  - commit ab8171a
  - arm64/sysreg: Get rid of the TCR2_EL1x SysregFields
    (jsc#PED-348).
  - commit ac99b49
  - arm64: setup: name 'tcr2' register (jsc#PED-348).
  - commit 083cc0a
  - arm64/sysreg: Allow a 'Mapping' descriptor for system registers
    (jsc#PED-348).
  - commit e10ff75
  - arm64/kvm: Avoid invalid physical addresses to signal owner
    updates (jsc#PED-348).
  - commit 5332312
  - arm64/kvm: Configure HYP TCR.PS/DS based on host stage1
    (jsc#PED-348).
  - commit 3fa17e8
  - KVM: x86: Remove hwapic_irr_update() from kvm_x86_ops
    (jsc#PED-348).
  - commit ec44993
  - KVM: nVMX: Honor event priority when emulating PI delivery
    during VM-Enter (jsc#PED-348).
  - commit 8b35f41
  - KVM: nVMX: Use vmcs01's controls shadow to check for IRQ/NMI
    windows at VM-Enter (jsc#PED-348).
  - commit 227df19
  - KVM: nVMX: Drop manual vmcs01.GUEST_INTERRUPT_STATUS.RVI check
    at VM-Enter (jsc#PED-348).
  - commit 2678d06
  - KVM: nVMX: Check for pending INIT/SIPI after entering non-root
    mode (jsc#PED-348).
  - commit 5281aec
  - KVM: nVMX: Explicitly update vPPR on successful nested VM-Enter
    (jsc#PED-348).
  - commit d094324
  - KVM: x86: Add information about pending requests to kvm_exit
    tracepoint (jsc#PED-348).
  - commit 62af53f
  - KVM: x86: Add interrupt injection information to the kvm_entry
    tracepoint (jsc#PED-348).
  - commit 19c8851
  - KVM: SVM: Handle event vectoring error in
    check_emulate_instruction() (jsc#PED-348).
  - commit 9866a06
  - KVM: VMX: Handle event vectoring error in
    check_emulate_instruction() (jsc#PED-348).
  - commit 3f9c1bc
  - KVM: x86: Try to unprotect and retry on unhandleable emulation
    failure (jsc#PED-348).
  - commit 23860d1
  - KVM: x86: Add emulation status for unhandleable exception
    vectoring (jsc#PED-348).
  - commit 9d2063a
  - KVM: x86: Add function for vectoring error generation
    (jsc#PED-348).
  - commit b30b581
  - KVM: x86: Use only local variables (no bitmask) to init
    kvm_cpu_caps (jsc#PED-348).
  - commit 7fe2c13
  - KVM: x86: Explicitly track feature flags that are enabled at
    runtime (jsc#PED-348).
  - commit ee49c88
  - KVM: x86: Explicitly track feature flags that require vendor
    enabling (jsc#PED-348).
  - commit 50a4cc7
  - KVM: x86: Rename "SF" macro to "SCATTERED_F" (jsc#PED-348).
  - commit fc020fe
  - KVM: x86: Pull CPUID capabilities from boot_cpu_data only as
    needed (jsc#PED-348).
  - commit dad6907
  - KVM: x86: Add a macro for features that are synthesized into
    boot_cpu_data (jsc#PED-348).
  - commit 90f17ed
  - KVM: x86: Drop superfluous host XSAVE check when adjusting
    guest XSAVES caps (jsc#PED-348).
  - commit eeb8bd7
  - KVM: x86: Replace (almost) all guest CPUID feature queries
    with cpu_caps (jsc#PED-348).
  - commit bafc961
  - KVM: x86: Shuffle code to prepare for dropping guest_cpuid_has()
    (jsc#PED-348).
  - commit ae3d20d
  - KVM: x86: Update guest cpu_caps at runtime for dynamic
    CPUID-based features (jsc#PED-348).
  - commit 088e022
  - KVM: x86: Update OS{XSAVE,PKE} bits in guest CPUID irrespective
    of host support (jsc#PED-348).
  - commit e29333b
  - KVM: x86: Drop unnecessary check that cpuid_entry2_find()
    returns right leaf (jsc#PED-348).
  - commit 3744528
  - KVM: x86: Avoid double CPUID lookup when updating MWAIT at
    runtime (jsc#PED-348).
  - commit b1910e2
  - KVM: x86: Initialize guest cpu_caps based on KVM support
    (jsc#PED-348).
  - commit 9ca94f2
  - KVM: x86: Treat MONTIOR/MWAIT as a "partially emulated" feature
    (jsc#PED-348).
  - commit 12694d7
  - KVM: x86: Extract code for generating per-entry emulated CPUID
    information (jsc#PED-348).
  - commit 6b47ba9
  - KVM: x86: Initialize guest cpu_caps based on guest CPUID
    (jsc#PED-348).
  - commit c4ec6d7
  - KVM: x86: Replace guts of "governed" features with comprehensive
    cpu_caps (jsc#PED-348).
  - commit 744133e
  - radix-tree: add missing cleanup.h (git-fixes).
  - crypto: caam/qi - Fix drv_ctx refcount bug (git-fixes).
  - commit 3c5ba83
  - KVM: x86: Rename "governed features" helpers to use
    "guest_cpu_cap" (jsc#PED-348).
  - commit 0fff997
  - KVM: x86: Advertise HYPERVISOR in KVM_GET_SUPPORTED_CPUID
    (jsc#PED-348).
  - commit 3203ab7
  - KVM: x86: Advertise TSC_DEADLINE_TIMER in
    KVM_GET_SUPPORTED_CPUID (jsc#PED-348).
  - commit a3e58fe
  - KVM: x86: Remove all direct usage of cpuid_entry2_find()
    (jsc#PED-348).
  - commit bf23d0c
  - KVM: x86: Move kvm_find_cpuid_entry{,_index}() up near
    cpuid_entry2_find() (jsc#PED-348).
  - commit 2a644e6
  - KVM: x86: Always operate on kvm_vcpu data in cpuid_entry2_find()
    (jsc#PED-348).
  - commit 843079b
  - KVM: x86: Remove unnecessary caching of KVM's PV CPUID base
    (jsc#PED-348).
  - commit cdb8730
  - KVM: x86: Clear PV_UNHALT for !HLT-exiting only when userspace
    sets CPUID (jsc#PED-348).
  - commit 74aaac1
  - KVM: x86: Swap incoming guest CPUID into vCPU before massaging
    in KVM_SET_CPUID2 (jsc#PED-348).
  - commit 9defaee
  - KVM: x86: Add a macro to init CPUID features that KVM emulates
    in software (jsc#PED-348).
  - commit eb8f359

++++ util-linux-systemd:

  - Enable mountfd support again (jsc#PED-9752).
    BREAKING CHANGE
    Mountfd is nearly completely compatible with the old mount. There
    is a special case that cannot be handled by mountfd, and it needs
    to be handled by applications:
    Mountfd discriminates between physical mount layer and virtual
    mount layer. Once the physical mount layer is read-only,
    read-write mount on the virtual layer is not possible.
    If the first mount is read only, then the physical filesystem is
    mounted read-only, and later mount of the same file system as
    read-write is not possible. To solve this problem, the first
    mount needs to be read-only only on the virtual layer, keeping
    the physical layer read-write.
    The user space fix is simple:
    Instead of
    mount -oro
    use
    mount -oro=vfs
    This will keep the physical layer read-write, but the virtual
    file system layer (and the user space access) will be read-only.

++++ util-linux:

  - Enable mountfd support again (jsc#PED-9752).
    BREAKING CHANGE
    Mountfd is nearly completely compatible with the old mount. There
    is a special case that cannot be handled by mountfd, and it needs
    to be handled by applications:
    Mountfd discriminates between physical mount layer and virtual
    mount layer. Once the physical mount layer is read-only,
    read-write mount on the virtual layer is not possible.
    If the first mount is read only, then the physical filesystem is
    mounted read-only, and later mount of the same file system as
    read-write is not possible. To solve this problem, the first
    mount needs to be read-only only on the virtual layer, keeping
    the physical layer read-write.
    The user space fix is simple:
    Instead of
    mount -oro
    use
    mount -oro=vfs
    This will keep the physical layer read-write, but the virtual
    file system layer (and the user space access) will be read-only.

++++ harfbuzz:

  - Update to version 11.1.0:
    + Include bidi mirroring variants of the requested codepoints
    when subsetting. The new HB_SUBSET_FLAGS_NO_BIDI_CLOSURE can be
    used to disable this behaviour.
    + Various bug fixes.
    + Various build fixes and improvements.
    + Various test suite improvements.

++++ sqlite3:

  - Add subpackage for the lemon parser generator.
  - Add patches:
    * sqlite-3.49.0-fix-lemon-missing-cflags.patch
    * sqlite-3.6.23-lemon-system-template.patch

++++ libxml2:

  - Update to version 2.13.8:
    + Security:
  - [CVE-2025-32415] schemas: Fix heap buffer overflow in
    xmlSchemaIDCFillNodeTables.
  - [CVE-2025-32414] python: Read at most len/4 characters.
  - bug references: [bsc#1241453], [bsc#1241551]

++++ python-azuremetadata:

  - Update build setup
    + Switch source tarball name to be consistent with other tools of
    similar nature
    + Set the modules directory properly

++++ python-M2Crypto:

  - Update to 0.45.0:
  - chore: preparing 0.45.0 release
  - fix(lib,ssl): rewrite ssl_accept, ssl_{read,write}_nbio for better error handling
  - fix: replace m2_PyBuffer_Release with native PyBuffer_Release
  - chore: build Windows builds with Python 3.13 as well
  - fix: remove support for Engine
  - chore: use actual license of the project
  - ci(Debian): make M2Crypto buildable on Debian (bsc#1240965)
  - swig: Workaround for reading sys/select.h ending with wrong types.
  - ci: bump required setuptools version because of change in naming strategy
  - fix: add fix for build with older GCC
  - fix: remove AnyStr and Any types

++++ python-PyYAML:

  - dont use suse version for the dist info handling as people can
    build with newer setuptools on older distros

++++ libxml2-python:

  - Update to version 2.13.8:
    + Security:
  - [CVE-2025-32415] schemas: Fix heap buffer overflow in
    xmlSchemaIDCFillNodeTables.
  - [CVE-2025-32414] python: Read at most len/4 characters.
  - bug references: [bsc#1241453], [bsc#1241551]

------------------------------------------------------------------
------------------  2025-4-16  -  Apr 16 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Update to version 2.34
    * Make it work on s390x (still no 3215 console)
    This is a bug fix release.  But still no support in conmode
    3215 as there is a race triggered by using conmode 3215.
    The order of the systemd units seems to change with this
    console mode.

++++ cockpit:

  - Add extra requirements for selinux policies to cockpit-selinux-policies
    so it can't be installed before selinux or policycoreutils

++++ dracut:

  - Update to version 059+suse.684.g4c6c5a89:
    * fix(dracut.spec): require jq for nvmf (bsc#1239603)
  - Update to version 059+suse.683.g38e017da:
    * fix(crypt): always install s390 crypto modules (jsc#IBM-1444)
    * fix(crypt): install dm_crypt module in non-hostonly mode as well
    * fix(dmsquash-live): do not check ISO md5 if image filesystem (bsc#1240919)
    * fix(dmsquash-live): use load_fstype to load driver for filesystems
    * fix(nfs): set correct ownership of rpc.statd state directories (bsc#1217885)
    * perf(nfs): remove references to old rpcbind state dir
    * fix(nfs): libnfsidmap plugins not added in some distributions

++++ python-kiwi:

  - Add support for filtering out files from the ESP image for GRUB
    Prior to this change, KIWI blindly synced the ESP directory into the
    embedded ESP image. Depending on the distribution and packages included
    for the created image, this can have undesirable side-effects.
    For image builds that need some more fine-grained control over the
    creation of the embedded ESP image (particularly for ISO images),
    this change introduces the ability to inject an exclusion list
    similar to what is used to filter out files for the root filesystem.
    Fixes: https://github.com/OSInside/kiwi/issues/2008
    Fixes: https://github.com/OSInside/kiwi/issues/2777

++++ ethtool:

  - fix AppStream metainfo XML file
    * misc-fix-AppStream-metainfo-XML.patch
  - update to upstream release 6.14 (jsc#PED-11353)
    Normally we want the ethtool package version to match kernel
    version but upstream skipped 6.12 and 6.13 versions so that
    version 6.14 is going to be used instead. For list of features
    and fixes between versions 6.10 and 6.14 see the NEWS file in the
    package.
  - adapt package to git based patch tracking

++++ hwinfo:

  - merge gh#openSUSE/hwinfo#161
  - fix aarch64 cpu detection (bsc#1241295)
  - 24.0
  - merge gh#openSUSE/hwinfo#160
  - add touchpad class (bsc#1241295)
  - merge gh#openSUSE/hwinfo#159
  - update pci, usb, and sdio data  (bsc#1241295)
  - merge gh#openSUSE/hwinfo#158
  - capture more x86 fields from /proc/cpuinfo (bsc#1241295)

++++ iproute2:

  - add post-6.12 upstream fixes (bsc#1241316)
    * ip-fix-memory-leak-in-do_show.patch
    * devlink-do-dry-parse-for-extended-handle-with-select.patch
    * devlink-use-the-correct-handle-flag-for-port-param-s.patch
  - update to upstream version 6.12 (jsc#PED-11361)
    * for detailed list of changes between 6.3 and 6.12 see Factory
    package changelog
    * replace upstream tarball and signature
    * update specfile with changes from Factory package
    * refresh non-upstream patches
  - adjust-installation-directories-for-openSUSE-SLE.patch
  - use-sysconf-_SC_CLK_TCK-if-HZ-undefined.patch
  - add-explicit-typecast-to-avoid-gcc-warning.patch
  - split-link-and-compile-steps-for-binaries.patch
  - adapt the package for git based patch tracking
    * move patches into patches.tar.xz
    * add helper scripts apply-patches and guards
    * add series.conf file listing patches
    * update iproute2.spec to apply patches from patches.tar.xz

++++ open-iscsi:

  - Update to version 2.1.11.suse+66.13c070123738:
    * Fix iscsid.conf NOP configuration (bsc#1240541)

++++ kernel-default:

  - KVM: x86: Add a macro to init CPUID features that ignore host
    kernel support (jsc#PED-348).
  - commit 08b20bc
  - KVM: x86: Harden CPU capabilities processing against
    out-of-scope features (jsc#PED-348).
  - commit 510b6f1
  - KVM: x86: #undef SPEC_CTRL_SSBD in cpuid.c to avoid macro
    collisions (jsc#PED-348).
  - commit 21d3e95
  - KVM: x86: Handle kernel- and KVM-defined CPUID words in a
    single helper (jsc#PED-348).
  - commit 276a84b
  - KVM: x86: Add a macro to precisely handle aliased 0x1.EDX
    CPUID features (jsc#PED-348).
  - commit 634ca32
  - KVM: x86: Add a macro to init CPUID features that are 64-bit
    only (jsc#PED-348).
  - commit ad2d27f
  - KVM: x86: Rename kvm_cpu_cap_mask() to kvm_cpu_cap_init()
    (jsc#PED-348).
  - commit 07cb013
  - KVM: x86: Unpack F() CPUID feature flag macros to one flag
    per line of code (jsc#PED-348).
  - commit 94d8a41
  - KVM: x86: Account for max supported CPUID leaf when getting
    raw host CPUID (jsc#PED-348).
  - commit e01ea13
  - KVM: x86: Do reverse CPUID sanity checks in __feature_leaf()
    (jsc#PED-348).
  - commit 386c0e7
  - KVM: x86: Don't update PV features caches when enabling
    enforcement capability (jsc#PED-348).
  - commit e32cc5c
  - KVM: x86: Disallow KVM_CAP_X86_DISABLE_EXITS after vCPU creation
    (jsc#PED-348).
  - Refresh
    patches.suse/KVM-x86-Reject-disabling-of-MWAIT-HLT-interception-w.patch.
  - commit 7ab259a
  - KVM: x86: Drop now-redundant MAXPHYADDR and GPA rsvd bits from
    vCPU creation (jsc#PED-348).
  - commit 24d1858
  - KVM: x86/pmu: Drop now-redundant refresh() during init()
    (jsc#PED-348).
  - commit bdd0c1f
  - KVM: x86: Move __kvm_is_valid_cr4() definition to x86.h
    (jsc#PED-348).
  - commit 43b554e
  - KVM: x86: Explicitly do runtime CPUID updates "after" initial
    setup (jsc#PED-348).
  - commit e180b3c
  - KVM: x86: Do all post-set CPUID processing during vCPU creation
    (jsc#PED-348).
  - commit d8bccfa
  - KVM: x86: Limit use of F() and SF() to
    kvm_cpu_cap_{mask,init_kvm_defined}() (jsc#PED-348).
  - commit 988beee
  - KVM: x86: Use feature_bit() to clear CONSTANT_TSC when emulating
    CPUID (jsc#PED-348).
  - commit edd2809
  - KVM: SVM: Remove redundant TLB flush on guest CR4.PGE change
    (jsc#PED-348).
  - commit a1d30ca
  - KVM: SVM: Macrofy SEV=n versions of sev_xxx_guest()
    (jsc#PED-348).
  - commit 2eb6ad5
  - KVM/x86: add comment to kvm_mmu_do_page_fault() (jsc#PED-348).
  - commit f8b9220
  - KVM: Drop hack that "manually" informs lockdep of kvm->lock
    vs. vcpu->mutex (jsc#PED-348).
  - commit 8bb2bd9
  - KVM: Don't BUG() the kernel if xa_insert() fails with -EBUSY
    (jsc#PED-348).
  - commit 49c66f6
  - Revert "KVM: Fix vcpu_array[0] races" (jsc#PED-348).
  - commit 413becc
  - KVM: Grab vcpu->mutex across installing the vCPU's fd and
    bumping online_vcpus (jsc#PED-348).
  - commit 7f30aeb
  - x86/tdx: Dump attributes and TD_CTLS on boot (jsc#PED-348).
  - commit 74acffc
  - x86/boot: Disable UBSAN in early boot code (jsc#PED-348).
  - commit 3c2b2d2
  - x86/sev: Avoid WARN()s and panic()s in early boot code
    (jsc#PED-348).
  - commit 4125835
  - x86/tdx: Disable unnecessary virtualization exceptions
    (jsc#PED-348).
  - commit abda8db
  - x86/mtrr: Rename mtrr_overwrite_state() to
    guest_force_mtrr_state() (jsc#PED-348).
  - commit 8430eb6
  - x86: Convert unreachable() to BUG() (jsc#PED-348).
  - commit e4cd586
  - Documentation: KVM: fix malformed table (jsc#PED-348).
  - commit 12a0164
  - mm/vmscan: accumulate nr_demoted for accurate demotion
    statistics (bsc#1241017).
  - commit dee521e
  - mm: vmscan : pgdemote vmstat is not getting updated when MGLRU
    is enabled (bsc#1241017).
  - commit c383344
  - x86/tdx: Emit warning if IRQs are enabled during HLT #VE handling (git-fixes).
  - commit 821f908
  - x86/tdx: Fix arch_safe_halt() execution for TDX VMs (git-fixes).
  - commit fba743c
  - x86/paravirt: Move halt paravirt calls under CONFIG_PARAVIRT (git-fixes).
  - commit 18b7232
  - x86/coco: Replace 'static const cc_mask' with the newly introduced  cc_get_mask() function (git-fixes).
  - commit 297d234
  - x86/entry: Add __init to ia32_emulation_override_cmdline() (git-fixes).
  - commit 8ea5b5f
  - x86/uaccess: Improve performance by aligning writes to 8 bytes in  copy_user_generic(), on non-FSRM/ERMS CPUs (git-fixes).
  - commit 7e6aaa6
  - Update config files.
  - commit 2b9e98a
  - KVM: e500: perform hugepage check after looking up the PFN
    (jsc#PED-348).
  - commit 3d3cc93
  - KVM: e500: map readonly host pages for read (jsc#PED-348).
  - commit bf95e9e
  - KVM: e500: track host-writability of pages (jsc#PED-348).
  - commit 0c38772
  - KVM: e500: use shadow TLB entry as witness for writability
    (jsc#PED-348).
  - commit b72acdd
  - KVM: e500: always restore irqs (jsc#PED-348).
  - commit 25407ab
  - KVM: x86: let it be known that ignore_msrs is a bad idea
    (jsc#PED-348).
  - commit 667c8d0
  - KVM: VMX: don't include '<linux/find.h>' directly (jsc#PED-348).
  - commit a37309e
  - KVM: x86/mmu: Treat TDP MMU faults as spurious if access is
    already allowed (jsc#PED-348).
  - commit 4aa85bd
  - KVM: SVM: Disable AVIC on SNP-enabled system without
    HvInUseWrAllowed feature (jsc#PED-348).
  - commit cce39fd
  - KVM: arm64: Only apply PMCR_EL0.P to the guest range of counters
    (jsc#PED-348).
  - commit 8343d6d
  - KVM: arm64: nv: Reload PMU events upon MDCR_EL2.HPME change
    (jsc#PED-348).
  - commit 760f548
  - KVM: arm64: Use KVM_REQ_RELOAD_PMU to handle PMCR_EL0.E change
    (jsc#PED-348).
  - commit 3439829
  - KVM: arm64: Add unified helper for reprogramming counters by
    mask (jsc#PED-348).
  - commit 7b982cc
  - KVM: arm64: Always check the state from hyp_ack_unshare()
    (jsc#PED-348).
  - commit 4d50406
  - x86/bugs: Add RSB mitigation document (git-fixes).
  - commit 256a12f
  - x86/bugs: Don't fill RSB on context switch with eIBRS (git-fixes).
  - commit aed0c44
  - KVM: x86: Cache CPUID.0xD XSTATE offsets+sizes during module
    init (jsc#PED-348).
  - commit 9ce0023
  - RISC-V: KVM: Fix csr_write -> csr_set for HVIEN PMU overflow
    bit (jsc#PED-348).
  - commit ee3ee05
  - coco: virt: arm64: Do not enable cca guest driver by default
    (jsc#PED-348).
  - commit a4bf6c7
  - drivers/virt: pkvm: Don't fail ioremap() call if MMIO_GUARD
    fails (jsc#PED-348).
  - commit 64169e7
  - x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline (git-fixes).
  - commit 54d8017
  - x86/bugs: Fix RSB clearing in indirect_branch_prediction_barrier() (git-fixes).
  - commit 677de47
  - LoongArch: KVM: Protect kvm_io_bus_{read,write}() with SRCU
    (jsc#PED-348).
  - commit 56dbbd7
  - LoongArch: KVM: Protect kvm_check_requests() with SRCU
    (jsc#PED-348).
  - commit 0a3d0d9
  - KVM: s390: Increase size of union sca_utility to four bytes
    (jsc#PED-348).
  - commit 64d89b3
  - KVM: s390: Remove one byte cmpxchg() usage (jsc#PED-348).
  - commit 59db533
  - s390/asm: Helper macros for flag output operand handling
    (jsc#PED-348).
  - commit f370957
  - x86/bugs: Use SBPB in write_ibpb() if applicable (git-fixes).
  - commit b35b815
  - s390/cmpxchg: Provide arch_try_cmpxchg() (jsc#PED-348).
  - commit 7cfc4f9
  - KVM: s390: Use try_cmpxchg() instead of cmpxchg() loops
    (jsc#PED-348).
  - commit 7cac529
  - x86/bugs: Rename entry_ibpb() to write_ibpb() (git-fixes).
  - commit 7709e9f
  - arm64: Fix usage of new shifted MDCR_EL2 values (jsc#PED-348).
  - commit 92356bc
  - KVM: arm64: Use MDCR_EL2.HPME to evaluate overflow of hyp
    counters (jsc#PED-348).
  - commit 162887d
  - KVM: arm64: Mark set_sysreg_masks() as inline to avoid build
    failure (jsc#PED-348).
  - commit 268b927
  - KVM: arm64: vgic-its: Add stronger type-checking to the ITS
    entry sizes (jsc#PED-348).
  - commit 4cd8d38
  - KVM: arm64: vgic: Kill VGIC_MAX_PRIVATE definition
    (jsc#PED-348).
  - commit 0b6d63c
  - KVM: arm64: vgic: Make vgic_get_irq() more robust (jsc#PED-348).
  - commit 201dd08
  - KVM: x86: switch hugepage recovery thread to vhost_task
    (jsc#PED-348).
  - Refresh
    patches.suse/msft-hv-3141-hyperv-Clean-up-unnecessary-includes.patch.
  - commit 45a316b
  - KVM: x86: expose MSR_PLATFORM_INFO as a feature MSR
    (jsc#PED-348).
  - commit 35b6eee
  - x86: KVM: Advertise CPUIDs for new instructions in Clearwater
    Forest (jsc#PED-348).
  - commit c3aa0c5
  - s390/kvm: Convert to use flag output macros (jsc#PED-348).
  - Refresh
    patches.suse/KVM-s390-add-concurrent-function-facility-to-cpu-model.patch.
  - commit e5c65be
  - LoongArch: KVM: Add irqfd support (jsc#PED-348).
  - commit b40a03d
  - LoongArch: KVM: Add PCHPIC user mode read and write functions
    (jsc#PED-348).
  - commit 68a054f
  - LoongArch: KVM: Add PCHPIC read and write functions
    (jsc#PED-348).
  - commit 3c665e0
  - LoongArch: KVM: Add PCHPIC device support (jsc#PED-348).
  - commit f815008
  - LoongArch: KVM: Add EIOINTC user mode read and write functions
    (jsc#PED-348).
  - commit eb0dbd3
  - LoongArch: KVM: Add EIOINTC read and write functions
    (jsc#PED-348).
  - commit 8dc3259
  - LoongArch: KVM: Add EIOINTC device support (jsc#PED-348).
  - commit edb0a3f
  - LoongArch: KVM: Add IPI user mode read and write function
    (jsc#PED-348).
  - commit 36d79fb
  - LoongArch: KVM: Add IPI read and write function (jsc#PED-348).
  - commit 0131900
  - LoongArch: KVM: Add IPI device support (jsc#PED-348).
  - commit 854022c
  - LoongArch: KVM: Add iocsr and mmio bus simulation in kernel
    (jsc#PED-348).
  - commit 7b8524b
  - KVM: arm64: Pass on SVE mapping failures (jsc#PED-348).
  - commit aa7cc11
  - KVM: arm64: vgic-its: Clear ITE when DISCARD frees an ITE
    (jsc#PED-348).
  - commit dcc7422
  - KVM: arm64: vgic-its: Clear DTE when MAPD unmaps a device
    (jsc#PED-348).
  - commit 35b98e1
  - selftests/bpf: Adjust data size to have ETH_HLEN (bsc#1240181
    CVE-2025-21867).
  - bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: check program redirect in xdp_cpumap_attach
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: make xdp_cpumap_attach keep redirect prog
    attached (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: fix bpf_map_redirect call for cpu map test
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: Adjust data size to have ETH_HLEN (bsc#1240181
    CVE-2025-21867).
  - bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: check program redirect in xdp_cpumap_attach
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: make xdp_cpumap_attach keep redirect prog
    attached (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: fix bpf_map_redirect call for cpu map test
    (bsc#1240181 CVE-2025-21867).
  - commit a4cc2a4
  - KVM: arm64: vgic-its: Add a data length check in vgic_its_save_*
    (jsc#PED-348).
  - commit d51cc10
  - KVM: arm64: Make L1Ip feature in CTR_EL0 writable from userspace
    (jsc#PED-348).
  - commit 03af8fa
  - KVM: powerpc: remove remaining traces of KVM_CAP_PPC_RMA
    (jsc#PED-348).
  - commit dfc6040
  - x86/tdx: Enable CPU topology enumeration (jsc#PED-348).
  - commit add304a
  - x86/sev: Cleanup vc_handle_msr() (jsc#PED-348).
  - commit 58e7dcc
  - s390/kvm: Mask extra bits from program interrupt code
    (jsc#PED-348).
  - commit ae18f46
  - KVM: x86/xen: Initialize hrtimer in kvm_xen_init_vcpu()
    (jsc#PED-348).
  - commit a62436a
  - riscv: kvm: Fix out-of-bounds array access (jsc#PED-348).
  - commit 889deb8
  - RISC-V: KVM: Fix APLIC in_clrip and clripnum write emulation
    (jsc#PED-348).
  - commit 68b09dc
  - KVM: x86: Short-circuit all of kvm_apic_set_base() if MSR
    value is unchanged (jsc#PED-348).
  - commit 3509130
  - KVM: x86: Unpack msr_data structure prior to calling
    kvm_apic_set_base() (jsc#PED-348).
  - Refresh
    patches.suse/KVM-nVMX-Defer-SVI-update-to-vmcs01-on-EOI-when-L2-i-04bc93cf49d1.patch.
  - commit 2e2dd13
  - KVM: x86: Make kvm_recalculate_apic_map() local to lapic.c
    (jsc#PED-348).
  - commit f2d4992
  - KVM: x86: Rename APIC base setters to better capture their
    relationship (jsc#PED-348).
  - Refresh
    patches.suse/KVM-nVMX-Defer-SVI-update-to-vmcs01-on-EOI-when-L2-i-04bc93cf49d1.patch.
  - commit 01cbb78
  - KVM: x86: Move kvm_set_apic_base() implementation to lapic.c
    (from x86.c) (jsc#PED-348).
  - commit d4905e6
  - KVM: x86: Inline kvm_get_apic_mode() in lapic.h (jsc#PED-348).
  - Refresh
    patches.suse/KVM-nVMX-Defer-SVI-update-to-vmcs01-on-EOI-when-L2-i-04bc93cf49d1.patch.
  - commit 9a4a16c
  - KVM: x86: Get vcpu->arch.apic_base directly and drop
    kvm_get_apic_base() (jsc#PED-348).
  - commit 0360cf7
  - KVM: x86: Drop superfluous kvm_lapic_set_base() call when
    setting APIC state (jsc#PED-348).
  - commit 29aec95
  - KVM: x86: Short-circuit all kvm_lapic_set_base() if MSR value
    isn't changing (jsc#PED-348).
  - commit 5459e02
  - KVM: x86/mmu: Drop per-VM zapped_obsolete_pages list
    (jsc#PED-348).
  - commit c7a188a
  - KVM: x86/mmu: Remove KVM's MMU shrinker (jsc#PED-348).
  - commit bfb6ee0
  - KVM: x86/mmu: WARN if huge page recovery triggered during
    dirty logging (jsc#PED-348).
  - commit 753cf9e
  - KVM: x86/mmu: Rename make_huge_page_split_spte() to
    make_small_spte() (jsc#PED-348).
  - commit ac83548
  - KVM: x86/mmu: Recover TDP MMU huge page mappings in-place
    instead of zapping (jsc#PED-348).
  - commit 004050f
  - KVM: x86/mmu: Refactor TDP MMU iter need resched check
    (jsc#PED-348).
  - commit a6df396
  - KVM: x86/mmu: Demote the WARN on yielded in xxx_cond_resched()
    to KVM_MMU_WARN_ON (jsc#PED-348).
  - commit f4b05f2
  - KVM: x86/mmu: Check yielded_gfn for forward progress iff
    resched is needed (jsc#PED-348).
  - commit bdd5722
  - assorted variants of irqfd setup: convert to CLASS(fd)
    (jsc#PED-348).
  - commit f721c33
  - fdget(), more trivial conversions (jsc#PED-348).
  - commit 30e47bb
  - fdget(), trivial conversions (jsc#PED-348).
  - commit 2f28bfd
  - KVM: x86: Remove ordering check b/w MSR_PLATFORM_INFO and
    MISC_FEATURES_ENABLES (jsc#PED-348).
  - commit 988d494
  - KVM: x86: Reject userspace attempts to access ARCH_CAPABILITIES
    w/o support (jsc#PED-348).
  - commit 06e97ce
  - KVM: VMX: Remove restriction that PMU version > 0 for
    PERF_CAPABILITIES (jsc#PED-348).
  - commit dfd8959
  - KVM: x86: Reject userspace attempts to access PERF_CAPABILITIES
    w/o PDCM (jsc#PED-348).
  - commit 06280a1
  - KVM: x86: Quirk initialization of feature MSRs to KVM's max
    configuration (jsc#PED-348).
  - commit 995d691
  - KVM: x86: Disallow changing MSR_PLATFORM_INFO after vCPU has
    run (jsc#PED-348).
  - commit 91f2e05
  - KVM: x86: Co-locate initialization of feature MSRs in
    kvm_arch_vcpu_create() (jsc#PED-348).
  - commit 1844716
  - KVM: nVMX: fix canonical check of vmcs12 HOST_RIP (jsc#PED-348).
  - commit ff28b79
  - KVM: x86: model canonical checks more precisely (jsc#PED-348).
  - commit cad7c10
  - KVM: x86: Add X86EMUL_F_MSR and X86EMUL_F_DT_LOAD to aid
    canonical checks (jsc#PED-348).
  - commit 89eefbe
  - KVM: x86: Route non-canonical checks in emulator through
    emulate_ops (jsc#PED-348).
  - commit 32514ac
  - KVM: x86: drop x86.h include from cpuid.h (jsc#PED-348).
  - commit 92ed878
  - KVM: x86: Use '0' for guest RIP if PMI encounters protected
    guest state (jsc#PED-348).
  - commit 233268f
  - fs/proc/task_mmu: add guard region bit to pagemap
    (jsc#PED-11997).
  - commit 1dbd453
  - KVM: x86: Add lockdep-guarded asserts on register cache usage
    (jsc#PED-348).
  - commit 220a6e4
  - mm: allow guard regions in file-backed and read-only mappings
    (jsc#PED-11997).
  - commit 6e3700c
  - KVM: x86: Advertise AMD_IBPB_RET to userspace (jsc#PED-348).
  - commit 36ee592
  - KVM: x86: Ensure vcpu->mode is loaded from memory in
    kvm_vcpu_exit_request() (jsc#PED-348).
  - commit 8c2b6da
  - KVM: x86: Fix a comment inside kvm_vcpu_update_apicv()
    (jsc#PED-348).
  - commit 71218c5
  - KVM: arm64: nv: Reprogram PMU events affected by nested
    transition (jsc#PED-348).
  - commit b92fc52
  - KVM: arm64: nv: Apply EL2 event filtering when in hyp context
    (jsc#PED-348).
  - commit 100a2fa
  - KVM: arm64: nv: Honor MDCR_EL2.HLP (jsc#PED-348).
  - commit 8baeb0f
  - KVM: arm64: nv: Honor MDCR_EL2.HPME (jsc#PED-348).
  - commit 8f5ac10
  - KVM: arm64: Add helpers to determine if PMC counts at a given EL
    (jsc#PED-348).
  - commit 3723d87
  - KVM: arm64: nv: Adjust range of accessible PMCs according to
    HPMN (jsc#PED-348).
  - commit 0746fdf
  - KVM: arm64: Rename kvm_pmu_valid_counter_mask() (jsc#PED-348).
  - commit 175c7bc
  - KVM: arm64: nv: Advertise support for FEAT_HPMN0 (jsc#PED-348).
  - commit 51c1cf8
  - KVM: arm64: nv: Describe trap behaviour of MDCR_EL2.HPMN
    (jsc#PED-348).
  - commit a7132a5
  - KVM: arm64: nv: Honor MDCR_EL2.{TPM, TPMCR} in Host EL0
    (jsc#PED-348).
  - commit 3284e56
  - KVM: arm64: nv: Reinject traps that take effect in Host EL0
    (jsc#PED-348).
  - commit 8342c68
  - accel/ivpu: Increase DMA address range (jsc#PED-12366).
  - commit 40c638e
  - KVM: arm64: nv: Rename BEHAVE_FORWARD_ANY (jsc#PED-348).
  - commit 2f590ae
  - KVM: arm64: nv: Allow coarse-grained trap combos to use complex
    traps (jsc#PED-348).
  - commit 33415da
  - arm64: sysreg: Add new definitions for ID_AA64DFR0_EL1
    (jsc#PED-348).
  - commit d84a3cb
  - arm64: sysreg: Describe ID_AA64DFR2_EL1 fields (jsc#PED-348).
  - commit e2d4281
  - KVM: arm64: Describe RES0/RES1 bits of MDCR_EL2 (jsc#PED-348).
  - commit 2ae3f33
  - arm64: sysreg: Migrate MDCR_EL2 definition to table
    (jsc#PED-348).
  - commit 3384192
  - KVM: arm64: Initialize trap register values in hyp in pKVM
    (jsc#PED-348).
  - commit f99fff0
  - KVM: arm64: Initialize the hypervisor's VM state at EL2
    (jsc#PED-348).
  - commit 95114e0
  - KVM: arm64: Refactor kvm_vcpu_enable_ptrauth() for hyp use
    (jsc#PED-348).
  - commit 7187aea
  - KVM: arm64: Move pkvm_vcpu_init_traps() to init_pkvm_hyp_vcpu()
    (jsc#PED-348).
  - Refresh
    patches.suse/KVM-arm64-Get-rid-of-userspace_irqchip_in_use.patch.
  - commit 2076e77
  - rpm/package-descriptions: Add rt and rt_debug descriptions
  - commit 09573c0

++++ kernel-rt:

  - KVM: x86: Add a macro to init CPUID features that ignore host
    kernel support (jsc#PED-348).
  - commit 08b20bc
  - KVM: x86: Harden CPU capabilities processing against
    out-of-scope features (jsc#PED-348).
  - commit 510b6f1
  - KVM: x86: #undef SPEC_CTRL_SSBD in cpuid.c to avoid macro
    collisions (jsc#PED-348).
  - commit 21d3e95
  - KVM: x86: Handle kernel- and KVM-defined CPUID words in a
    single helper (jsc#PED-348).
  - commit 276a84b
  - KVM: x86: Add a macro to precisely handle aliased 0x1.EDX
    CPUID features (jsc#PED-348).
  - commit 634ca32
  - KVM: x86: Add a macro to init CPUID features that are 64-bit
    only (jsc#PED-348).
  - commit ad2d27f
  - KVM: x86: Rename kvm_cpu_cap_mask() to kvm_cpu_cap_init()
    (jsc#PED-348).
  - commit 07cb013
  - KVM: x86: Unpack F() CPUID feature flag macros to one flag
    per line of code (jsc#PED-348).
  - commit 94d8a41
  - KVM: x86: Account for max supported CPUID leaf when getting
    raw host CPUID (jsc#PED-348).
  - commit e01ea13
  - KVM: x86: Do reverse CPUID sanity checks in __feature_leaf()
    (jsc#PED-348).
  - commit 386c0e7
  - KVM: x86: Don't update PV features caches when enabling
    enforcement capability (jsc#PED-348).
  - commit e32cc5c
  - KVM: x86: Disallow KVM_CAP_X86_DISABLE_EXITS after vCPU creation
    (jsc#PED-348).
  - Refresh
    patches.suse/KVM-x86-Reject-disabling-of-MWAIT-HLT-interception-w.patch.
  - commit 7ab259a
  - KVM: x86: Drop now-redundant MAXPHYADDR and GPA rsvd bits from
    vCPU creation (jsc#PED-348).
  - commit 24d1858
  - KVM: x86/pmu: Drop now-redundant refresh() during init()
    (jsc#PED-348).
  - commit bdd0c1f
  - KVM: x86: Move __kvm_is_valid_cr4() definition to x86.h
    (jsc#PED-348).
  - commit 43b554e
  - KVM: x86: Explicitly do runtime CPUID updates "after" initial
    setup (jsc#PED-348).
  - commit e180b3c
  - KVM: x86: Do all post-set CPUID processing during vCPU creation
    (jsc#PED-348).
  - commit d8bccfa
  - KVM: x86: Limit use of F() and SF() to
    kvm_cpu_cap_{mask,init_kvm_defined}() (jsc#PED-348).
  - commit 988beee
  - KVM: x86: Use feature_bit() to clear CONSTANT_TSC when emulating
    CPUID (jsc#PED-348).
  - commit edd2809
  - KVM: SVM: Remove redundant TLB flush on guest CR4.PGE change
    (jsc#PED-348).
  - commit a1d30ca
  - KVM: SVM: Macrofy SEV=n versions of sev_xxx_guest()
    (jsc#PED-348).
  - commit 2eb6ad5
  - KVM/x86: add comment to kvm_mmu_do_page_fault() (jsc#PED-348).
  - commit f8b9220
  - KVM: Drop hack that "manually" informs lockdep of kvm->lock
    vs. vcpu->mutex (jsc#PED-348).
  - commit 8bb2bd9
  - KVM: Don't BUG() the kernel if xa_insert() fails with -EBUSY
    (jsc#PED-348).
  - commit 49c66f6
  - Revert "KVM: Fix vcpu_array[0] races" (jsc#PED-348).
  - commit 413becc
  - KVM: Grab vcpu->mutex across installing the vCPU's fd and
    bumping online_vcpus (jsc#PED-348).
  - commit 7f30aeb
  - x86/tdx: Dump attributes and TD_CTLS on boot (jsc#PED-348).
  - commit 74acffc
  - x86/boot: Disable UBSAN in early boot code (jsc#PED-348).
  - commit 3c2b2d2
  - x86/sev: Avoid WARN()s and panic()s in early boot code
    (jsc#PED-348).
  - commit 4125835
  - x86/tdx: Disable unnecessary virtualization exceptions
    (jsc#PED-348).
  - commit abda8db
  - x86/mtrr: Rename mtrr_overwrite_state() to
    guest_force_mtrr_state() (jsc#PED-348).
  - commit 8430eb6
  - x86: Convert unreachable() to BUG() (jsc#PED-348).
  - commit e4cd586
  - Documentation: KVM: fix malformed table (jsc#PED-348).
  - commit 12a0164
  - mm/vmscan: accumulate nr_demoted for accurate demotion
    statistics (bsc#1241017).
  - commit dee521e
  - mm: vmscan : pgdemote vmstat is not getting updated when MGLRU
    is enabled (bsc#1241017).
  - commit c383344
  - x86/tdx: Emit warning if IRQs are enabled during HLT #VE handling (git-fixes).
  - commit 821f908
  - x86/tdx: Fix arch_safe_halt() execution for TDX VMs (git-fixes).
  - commit fba743c
  - x86/paravirt: Move halt paravirt calls under CONFIG_PARAVIRT (git-fixes).
  - commit 18b7232
  - x86/coco: Replace 'static const cc_mask' with the newly introduced  cc_get_mask() function (git-fixes).
  - commit 297d234
  - x86/entry: Add __init to ia32_emulation_override_cmdline() (git-fixes).
  - commit 8ea5b5f
  - x86/uaccess: Improve performance by aligning writes to 8 bytes in  copy_user_generic(), on non-FSRM/ERMS CPUs (git-fixes).
  - commit 7e6aaa6
  - Update config files.
  - commit 2b9e98a
  - KVM: e500: perform hugepage check after looking up the PFN
    (jsc#PED-348).
  - commit 3d3cc93
  - KVM: e500: map readonly host pages for read (jsc#PED-348).
  - commit bf95e9e
  - KVM: e500: track host-writability of pages (jsc#PED-348).
  - commit 0c38772
  - KVM: e500: use shadow TLB entry as witness for writability
    (jsc#PED-348).
  - commit b72acdd
  - KVM: e500: always restore irqs (jsc#PED-348).
  - commit 25407ab
  - KVM: x86: let it be known that ignore_msrs is a bad idea
    (jsc#PED-348).
  - commit 667c8d0
  - KVM: VMX: don't include '<linux/find.h>' directly (jsc#PED-348).
  - commit a37309e
  - KVM: x86/mmu: Treat TDP MMU faults as spurious if access is
    already allowed (jsc#PED-348).
  - commit 4aa85bd
  - KVM: SVM: Disable AVIC on SNP-enabled system without
    HvInUseWrAllowed feature (jsc#PED-348).
  - commit cce39fd
  - KVM: arm64: Only apply PMCR_EL0.P to the guest range of counters
    (jsc#PED-348).
  - commit 8343d6d
  - KVM: arm64: nv: Reload PMU events upon MDCR_EL2.HPME change
    (jsc#PED-348).
  - commit 760f548
  - KVM: arm64: Use KVM_REQ_RELOAD_PMU to handle PMCR_EL0.E change
    (jsc#PED-348).
  - commit 3439829
  - KVM: arm64: Add unified helper for reprogramming counters by
    mask (jsc#PED-348).
  - commit 7b982cc
  - KVM: arm64: Always check the state from hyp_ack_unshare()
    (jsc#PED-348).
  - commit 4d50406
  - x86/bugs: Add RSB mitigation document (git-fixes).
  - commit 256a12f
  - x86/bugs: Don't fill RSB on context switch with eIBRS (git-fixes).
  - commit aed0c44
  - KVM: x86: Cache CPUID.0xD XSTATE offsets+sizes during module
    init (jsc#PED-348).
  - commit 9ce0023
  - RISC-V: KVM: Fix csr_write -> csr_set for HVIEN PMU overflow
    bit (jsc#PED-348).
  - commit ee3ee05
  - coco: virt: arm64: Do not enable cca guest driver by default
    (jsc#PED-348).
  - commit a4bf6c7
  - drivers/virt: pkvm: Don't fail ioremap() call if MMIO_GUARD
    fails (jsc#PED-348).
  - commit 64169e7
  - x86/bugs: Don't fill RSB on VMEXIT with eIBRS+retpoline (git-fixes).
  - commit 54d8017
  - x86/bugs: Fix RSB clearing in indirect_branch_prediction_barrier() (git-fixes).
  - commit 677de47
  - LoongArch: KVM: Protect kvm_io_bus_{read,write}() with SRCU
    (jsc#PED-348).
  - commit 56dbbd7
  - LoongArch: KVM: Protect kvm_check_requests() with SRCU
    (jsc#PED-348).
  - commit 0a3d0d9
  - KVM: s390: Increase size of union sca_utility to four bytes
    (jsc#PED-348).
  - commit 64d89b3
  - KVM: s390: Remove one byte cmpxchg() usage (jsc#PED-348).
  - commit 59db533
  - s390/asm: Helper macros for flag output operand handling
    (jsc#PED-348).
  - commit f370957
  - x86/bugs: Use SBPB in write_ibpb() if applicable (git-fixes).
  - commit b35b815
  - s390/cmpxchg: Provide arch_try_cmpxchg() (jsc#PED-348).
  - commit 7cfc4f9
  - KVM: s390: Use try_cmpxchg() instead of cmpxchg() loops
    (jsc#PED-348).
  - commit 7cac529
  - x86/bugs: Rename entry_ibpb() to write_ibpb() (git-fixes).
  - commit 7709e9f
  - arm64: Fix usage of new shifted MDCR_EL2 values (jsc#PED-348).
  - commit 92356bc
  - KVM: arm64: Use MDCR_EL2.HPME to evaluate overflow of hyp
    counters (jsc#PED-348).
  - commit 162887d
  - KVM: arm64: Mark set_sysreg_masks() as inline to avoid build
    failure (jsc#PED-348).
  - commit 268b927
  - KVM: arm64: vgic-its: Add stronger type-checking to the ITS
    entry sizes (jsc#PED-348).
  - commit 4cd8d38
  - KVM: arm64: vgic: Kill VGIC_MAX_PRIVATE definition
    (jsc#PED-348).
  - commit 0b6d63c
  - KVM: arm64: vgic: Make vgic_get_irq() more robust (jsc#PED-348).
  - commit 201dd08
  - KVM: x86: switch hugepage recovery thread to vhost_task
    (jsc#PED-348).
  - Refresh
    patches.suse/msft-hv-3141-hyperv-Clean-up-unnecessary-includes.patch.
  - commit 45a316b
  - KVM: x86: expose MSR_PLATFORM_INFO as a feature MSR
    (jsc#PED-348).
  - commit 35b6eee
  - x86: KVM: Advertise CPUIDs for new instructions in Clearwater
    Forest (jsc#PED-348).
  - commit c3aa0c5
  - s390/kvm: Convert to use flag output macros (jsc#PED-348).
  - Refresh
    patches.suse/KVM-s390-add-concurrent-function-facility-to-cpu-model.patch.
  - commit e5c65be
  - LoongArch: KVM: Add irqfd support (jsc#PED-348).
  - commit b40a03d
  - LoongArch: KVM: Add PCHPIC user mode read and write functions
    (jsc#PED-348).
  - commit 68a054f
  - LoongArch: KVM: Add PCHPIC read and write functions
    (jsc#PED-348).
  - commit 3c665e0
  - LoongArch: KVM: Add PCHPIC device support (jsc#PED-348).
  - commit f815008
  - LoongArch: KVM: Add EIOINTC user mode read and write functions
    (jsc#PED-348).
  - commit eb0dbd3
  - LoongArch: KVM: Add EIOINTC read and write functions
    (jsc#PED-348).
  - commit 8dc3259
  - LoongArch: KVM: Add EIOINTC device support (jsc#PED-348).
  - commit edb0a3f
  - LoongArch: KVM: Add IPI user mode read and write function
    (jsc#PED-348).
  - commit 36d79fb
  - LoongArch: KVM: Add IPI read and write function (jsc#PED-348).
  - commit 0131900
  - LoongArch: KVM: Add IPI device support (jsc#PED-348).
  - commit 854022c
  - LoongArch: KVM: Add iocsr and mmio bus simulation in kernel
    (jsc#PED-348).
  - commit 7b8524b
  - KVM: arm64: Pass on SVE mapping failures (jsc#PED-348).
  - commit aa7cc11
  - KVM: arm64: vgic-its: Clear ITE when DISCARD frees an ITE
    (jsc#PED-348).
  - commit dcc7422
  - KVM: arm64: vgic-its: Clear DTE when MAPD unmaps a device
    (jsc#PED-348).
  - commit 35b98e1
  - selftests/bpf: Adjust data size to have ETH_HLEN (bsc#1240181
    CVE-2025-21867).
  - bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: check program redirect in xdp_cpumap_attach
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: make xdp_cpumap_attach keep redirect prog
    attached (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: fix bpf_map_redirect call for cpu map test
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: Adjust data size to have ETH_HLEN (bsc#1240181
    CVE-2025-21867).
  - bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: check program redirect in xdp_cpumap_attach
    (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: make xdp_cpumap_attach keep redirect prog
    attached (bsc#1240181 CVE-2025-21867).
  - selftests/bpf: fix bpf_map_redirect call for cpu map test
    (bsc#1240181 CVE-2025-21867).
  - commit a4cc2a4
  - KVM: arm64: vgic-its: Add a data length check in vgic_its_save_*
    (jsc#PED-348).
  - commit d51cc10
  - KVM: arm64: Make L1Ip feature in CTR_EL0 writable from userspace
    (jsc#PED-348).
  - commit 03af8fa
  - KVM: powerpc: remove remaining traces of KVM_CAP_PPC_RMA
    (jsc#PED-348).
  - commit dfc6040
  - x86/tdx: Enable CPU topology enumeration (jsc#PED-348).
  - commit add304a
  - x86/sev: Cleanup vc_handle_msr() (jsc#PED-348).
  - commit 58e7dcc
  - s390/kvm: Mask extra bits from program interrupt code
    (jsc#PED-348).
  - commit ae18f46
  - KVM: x86/xen: Initialize hrtimer in kvm_xen_init_vcpu()
    (jsc#PED-348).
  - commit a62436a
  - riscv: kvm: Fix out-of-bounds array access (jsc#PED-348).
  - commit 889deb8
  - RISC-V: KVM: Fix APLIC in_clrip and clripnum write emulation
    (jsc#PED-348).
  - commit 68b09dc
  - KVM: x86: Short-circuit all of kvm_apic_set_base() if MSR
    value is unchanged (jsc#PED-348).
  - commit 3509130
  - KVM: x86: Unpack msr_data structure prior to calling
    kvm_apic_set_base() (jsc#PED-348).
  - Refresh
    patches.suse/KVM-nVMX-Defer-SVI-update-to-vmcs01-on-EOI-when-L2-i-04bc93cf49d1.patch.
  - commit 2e2dd13
  - KVM: x86: Make kvm_recalculate_apic_map() local to lapic.c
    (jsc#PED-348).
  - commit f2d4992
  - KVM: x86: Rename APIC base setters to better capture their
    relationship (jsc#PED-348).
  - Refresh
    patches.suse/KVM-nVMX-Defer-SVI-update-to-vmcs01-on-EOI-when-L2-i-04bc93cf49d1.patch.
  - commit 01cbb78
  - KVM: x86: Move kvm_set_apic_base() implementation to lapic.c
    (from x86.c) (jsc#PED-348).
  - commit d4905e6
  - KVM: x86: Inline kvm_get_apic_mode() in lapic.h (jsc#PED-348).
  - Refresh
    patches.suse/KVM-nVMX-Defer-SVI-update-to-vmcs01-on-EOI-when-L2-i-04bc93cf49d1.patch.
  - commit 9a4a16c
  - KVM: x86: Get vcpu->arch.apic_base directly and drop
    kvm_get_apic_base() (jsc#PED-348).
  - commit 0360cf7
  - KVM: x86: Drop superfluous kvm_lapic_set_base() call when
    setting APIC state (jsc#PED-348).
  - commit 29aec95
  - KVM: x86: Short-circuit all kvm_lapic_set_base() if MSR value
    isn't changing (jsc#PED-348).
  - commit 5459e02
  - KVM: x86/mmu: Drop per-VM zapped_obsolete_pages list
    (jsc#PED-348).
  - commit c7a188a
  - KVM: x86/mmu: Remove KVM's MMU shrinker (jsc#PED-348).
  - commit bfb6ee0
  - KVM: x86/mmu: WARN if huge page recovery triggered during
    dirty logging (jsc#PED-348).
  - commit 753cf9e
  - KVM: x86/mmu: Rename make_huge_page_split_spte() to
    make_small_spte() (jsc#PED-348).
  - commit ac83548
  - KVM: x86/mmu: Recover TDP MMU huge page mappings in-place
    instead of zapping (jsc#PED-348).
  - commit 004050f
  - KVM: x86/mmu: Refactor TDP MMU iter need resched check
    (jsc#PED-348).
  - commit a6df396
  - KVM: x86/mmu: Demote the WARN on yielded in xxx_cond_resched()
    to KVM_MMU_WARN_ON (jsc#PED-348).
  - commit f4b05f2
  - KVM: x86/mmu: Check yielded_gfn for forward progress iff
    resched is needed (jsc#PED-348).
  - commit bdd5722
  - assorted variants of irqfd setup: convert to CLASS(fd)
    (jsc#PED-348).
  - commit f721c33
  - fdget(), more trivial conversions (jsc#PED-348).
  - commit 30e47bb
  - fdget(), trivial conversions (jsc#PED-348).
  - commit 2f28bfd
  - KVM: x86: Remove ordering check b/w MSR_PLATFORM_INFO and
    MISC_FEATURES_ENABLES (jsc#PED-348).
  - commit 988d494
  - KVM: x86: Reject userspace attempts to access ARCH_CAPABILITIES
    w/o support (jsc#PED-348).
  - commit 06e97ce
  - KVM: VMX: Remove restriction that PMU version > 0 for
    PERF_CAPABILITIES (jsc#PED-348).
  - commit dfd8959
  - KVM: x86: Reject userspace attempts to access PERF_CAPABILITIES
    w/o PDCM (jsc#PED-348).
  - commit 06280a1
  - KVM: x86: Quirk initialization of feature MSRs to KVM's max
    configuration (jsc#PED-348).
  - commit 995d691
  - KVM: x86: Disallow changing MSR_PLATFORM_INFO after vCPU has
    run (jsc#PED-348).
  - commit 91f2e05
  - KVM: x86: Co-locate initialization of feature MSRs in
    kvm_arch_vcpu_create() (jsc#PED-348).
  - commit 1844716
  - KVM: nVMX: fix canonical check of vmcs12 HOST_RIP (jsc#PED-348).
  - commit ff28b79
  - KVM: x86: model canonical checks more precisely (jsc#PED-348).
  - commit cad7c10
  - KVM: x86: Add X86EMUL_F_MSR and X86EMUL_F_DT_LOAD to aid
    canonical checks (jsc#PED-348).
  - commit 89eefbe
  - KVM: x86: Route non-canonical checks in emulator through
    emulate_ops (jsc#PED-348).
  - commit 32514ac
  - KVM: x86: drop x86.h include from cpuid.h (jsc#PED-348).
  - commit 92ed878
  - KVM: x86: Use '0' for guest RIP if PMI encounters protected
    guest state (jsc#PED-348).
  - commit 233268f
  - fs/proc/task_mmu: add guard region bit to pagemap
    (jsc#PED-11997).
  - commit 1dbd453
  - KVM: x86: Add lockdep-guarded asserts on register cache usage
    (jsc#PED-348).
  - commit 220a6e4
  - mm: allow guard regions in file-backed and read-only mappings
    (jsc#PED-11997).
  - commit 6e3700c
  - KVM: x86: Advertise AMD_IBPB_RET to userspace (jsc#PED-348).
  - commit 36ee592
  - KVM: x86: Ensure vcpu->mode is loaded from memory in
    kvm_vcpu_exit_request() (jsc#PED-348).
  - commit 8c2b6da
  - KVM: x86: Fix a comment inside kvm_vcpu_update_apicv()
    (jsc#PED-348).
  - commit 71218c5
  - KVM: arm64: nv: Reprogram PMU events affected by nested
    transition (jsc#PED-348).
  - commit b92fc52
  - KVM: arm64: nv: Apply EL2 event filtering when in hyp context
    (jsc#PED-348).
  - commit 100a2fa
  - KVM: arm64: nv: Honor MDCR_EL2.HLP (jsc#PED-348).
  - commit 8baeb0f
  - KVM: arm64: nv: Honor MDCR_EL2.HPME (jsc#PED-348).
  - commit 8f5ac10
  - KVM: arm64: Add helpers to determine if PMC counts at a given EL
    (jsc#PED-348).
  - commit 3723d87
  - KVM: arm64: nv: Adjust range of accessible PMCs according to
    HPMN (jsc#PED-348).
  - commit 0746fdf
  - KVM: arm64: Rename kvm_pmu_valid_counter_mask() (jsc#PED-348).
  - commit 175c7bc
  - KVM: arm64: nv: Advertise support for FEAT_HPMN0 (jsc#PED-348).
  - commit 51c1cf8
  - KVM: arm64: nv: Describe trap behaviour of MDCR_EL2.HPMN
    (jsc#PED-348).
  - commit a7132a5
  - KVM: arm64: nv: Honor MDCR_EL2.{TPM, TPMCR} in Host EL0
    (jsc#PED-348).
  - commit 3284e56
  - KVM: arm64: nv: Reinject traps that take effect in Host EL0
    (jsc#PED-348).
  - commit 8342c68
  - accel/ivpu: Increase DMA address range (jsc#PED-12366).
  - commit 40c638e
  - KVM: arm64: nv: Rename BEHAVE_FORWARD_ANY (jsc#PED-348).
  - commit 2f590ae
  - KVM: arm64: nv: Allow coarse-grained trap combos to use complex
    traps (jsc#PED-348).
  - commit 33415da
  - arm64: sysreg: Add new definitions for ID_AA64DFR0_EL1
    (jsc#PED-348).
  - commit d84a3cb
  - arm64: sysreg: Describe ID_AA64DFR2_EL1 fields (jsc#PED-348).
  - commit e2d4281
  - KVM: arm64: Describe RES0/RES1 bits of MDCR_EL2 (jsc#PED-348).
  - commit 2ae3f33
  - arm64: sysreg: Migrate MDCR_EL2 definition to table
    (jsc#PED-348).
  - commit 3384192
  - KVM: arm64: Initialize trap register values in hyp in pKVM
    (jsc#PED-348).
  - commit f99fff0
  - KVM: arm64: Initialize the hypervisor's VM state at EL2
    (jsc#PED-348).
  - commit 95114e0
  - KVM: arm64: Refactor kvm_vcpu_enable_ptrauth() for hyp use
    (jsc#PED-348).
  - commit 7187aea
  - KVM: arm64: Move pkvm_vcpu_init_traps() to init_pkvm_hyp_vcpu()
    (jsc#PED-348).
  - Refresh
    patches.suse/KVM-arm64-Get-rid-of-userspace_irqchip_in_use.patch.
  - commit 2076e77
  - rpm/package-descriptions: Add rt and rt_debug descriptions
  - commit 09573c0

++++ ceph:

  - Update to 16.2.15-84-gb9c09b69575:
    + ceph.spec.in: Fix cephfs-{top,shell} shebangs with setuptools >= 76

++++ systemd:

  - Split systemd-network into two new sub-packages: systemd-networkd and
    systemd-resolved (bsc#1224386 jsc#PED-12669)

++++ open-vm-tools:

  - (bsc#1237147): Newer version of containerd do not have the directory
    /usr/share/go/1.x/contrib/src/github.com/containerd/containerd/api.
    Update detect-suse-location.patch to point to the directory
    /usr/share/go/1.x/contrib/src/github.com/containerd/containerd/vendor/github.com/containerd/containerd/api
    to find the needed files and update the tasks.proto file to import from
    github.com/containerd/containerd/vendor/github.com/containerd/containerd/api

++++ passt:

  - Update to version 20250415.2340bbf:
    * udp: Propagate errors on listening and brand new sockets
    * udp: Minor re-organisation of udp_sock_recverr()
    * udp: Add udp_pktinfo() helper
    * udp: Deal with errors as we go in udp_sock_fwd()
    * udp: Pass socket & flow information direction to error handling functions
    * udp: Be quieter about errors on UDP receive
    * udp: Fix breakage of UDP error handling by PKTINFO support
    * conf: Honour --dns-forward for local resolver even with --no-map-gw
    * conf: Split add_dns_resolv() into separate IPv4 and IPv6 versions
    * udp, udp_flow: Track our specific address on socket interfaces
    * inany: Improve ASSERT message for bad socket family
    * udp: Use PKTINFO cmsgs to get destination address for received datagrams
    * tcp_splice: Don't clobber errno before checking for EAGAIN
    * tcp_splice: Don't double count bytes read on EINTR
    * conf: Add missing return in conf_nat(), fix --map-guest-addr none
    * udp_flow: Save 8 bytes in struct udp_flow on 64-bit architectures
    * udp_flow: Don't discard packets that arrive between bind() and connect()
    * udp: Fold udp_splice_prepare and udp_splice_send into udp_sock_to_sock
    * udp: Rework udp_listen_sock_data() into udp_sock_fwd()
    * udp_flow: Take pif and port as explicit parameters to udp_flow_from_sock()
    * udp: Move UDP_MAX_FRAMES to udp.c
    * udp: Merge vhost-user and "buf" listening socket paths
    * udp: Split spliced forwarding path from udp_buf_reply_sock_data()
    * udp: Parameterize number of datagrams handled by udp_*_reply_sock_data()
    * udp: Don't bother to batch datagrams from "listening" socket
    * udp: Polish udp_vu_sock_info() and remove from vu specific code
    * udp: Make udp_sock_recv() take max number of frames as a parameter
    * udp: Use connect()ed sockets for initiating side
    * udp: support traceroute in direction tap-socket
    * passt-repair: Ensure that read buffer is NULL-terminated
    * udp: Correct some seccomp filter annotations
    * udp: Simplify updates to UDP flow timestamp
    * udp: Remove redundant udp_at_sidx() call in udp_tap_handler()
    * passt-repair: Correct off-by-one error verifying name
    * migrate, tcp: bind() migrated sockets in repair mode
    * platform requirements: Add test for address conflicts with TCP_REPAIR
    * platform requirements: Add attributes to die() function
    * platform requirements: Fix clang-tidy warning
    * udp: Improve name of UDP related ICMP sending functions
    * udp: Don't attempt to forward ICMP socket errors to other sockets
    * pasta, passt-repair: Support multiple events per read() in inotify handlers
    * udp: correct source address for ICMP messages
    * build: normalize arm targets
    * udp: Add helper function for creating connected UDP socket
    * udp: Always hash socket facing flowsides
    * udp: Better handling of failure to forward from reply socket
    * udp: Share more logic between vu and non-vu reply socket paths
    * udp_vu: Factor things out of udp_vu_reply_sock_data() loop
    * udp: Simplify checking of epoll event bits
    * udp: Common invocation of udp_sock_errs() for vhost-user and "buf" paths
    * packet: Upgrade severity of most packet errors
    * packet: ASSERT on signs of pool corruption
    * util: Add abort_with_msg() and ASSERT_WITH_MSG() helpers
    * packet: Rework packet_get() versus packet_get_try()
    * packet: Move checks against PACKET_MAX_LEN to packet_check_range()
    * packet: Avoid integer overflows in packet_get_do()
    * packet: Correct type of PACKET_MAX_LEN
    * tap: Clarify calculation of TAP_MSGS
    * tap: Make size of pool_tap[46] purely a tuning parameter
    * packet: More cautious checks to avoid pointer arithmetic UB
    * vu_common: Tighten vu_packet_check_range()

++++ python-httpcore:

  - Update to 1.0.8
    * Fix AttributeError when importing on Python 3.14. (#1005)

++++ selinux-policy:

  - Update to version 20241031+git573.66b1ba94:
    * allows gssd_t to read nfs symlinks (bsc#1241042)
    * Label tpm2-measure.log with systemd_pcrlock_var_lib_t (bsc#1240887)
    * Introduce unconfined mysqld_systemd_helper_t (bsc#1240949)
    * Set mysqld_t permissive until we have tested it thorougly (bsc#1240949)
    * Fix label of mysqld (bsc#1240949)
    * Allow login to podman container from tty (1238709)
    * Initial policy for snapper 50-etc plugin (bsc#1236671)
    * Add an rpmbuild test to the gitlab-ci
    * Allow hyper-v's fcopy_uio_daemon to run as unconfined_service_t (bsc#1239593)
    * Allow switcheroo-control dbus chat with xdm
    * Fix typo in calling unconfined_dbus_chat for switcheroo-control
    * Allow sysadm_t to write to /dev/kmsg
    * Allow init_t nnp domain transition to pcscd_t
    * Fix the genfscon statement for pidfs filesystem
    * Allow tuned-ppd dbus chat with xdm
    * Update INSTALL to describe necessary steps to build it
    * Rename the default policy to fedora-selinux
    * Update COPYING to the latest version of GPLv2
    * Allow traceroute_t bind rawip sockets to unreserved ports
    * Revert "Allow traceroute_t bind rawip sockets to unreserved ports"
    * Change the bootc system generator name to bootc-systemd-generator
    * Correct path for SAP HDB binary
    * additional path for SAP binaries
    * Allow xenstored_t manage xend_var_lib_t files (bsc#1228540)
    * dontaudit access to /etc/passwd for power-profiles-daemon (bsc#1237534)
    * allow power-profiles-daemon to watch sysfs directories (bsc#1237534)
    * add dev_watch_sysfs_dirs interface
    * Allow mpd use the io_uring API
    * Confine tuned-ppd
    * Add the switcheroo module
    * Label wine's windows libraries as textrel_shlib_t
    * Allow systemd domains write global pressure stall information
    * Add label and interfaces for kernel PSI files
    * Update bootupd policy
    * Update ktls policy
    * Add policy for systemd-bootc-generator
    * Allow blueman the kill capability
    * Add context for plymouth debug log files
    * Allow rlimit inheritance for domains transitioning to local_login_t
    * Update insights-core policy
    * Allow insights-core map all non-security files
    * Allow insights-core map audit config and log files
    * Allow insights-client manage insights_client_var_log_t files
  - Update embedded container-selinux version to commit:
    * 4244f856ea34d20edb903a6ff28667400a4b6c18 (version 2.236.0)

++++ sudo:

  - Update to 1.9.16p2:
    * Sudo now passes the terminal device number to the policy plugin
    even if it cannot resolve it to a path name. This allows sudo to
    run without warnings in a chroot jail when the terminal device
    files are not present. GitHub issue #421.
    * On Linux systems, sudo will now attempt to use the symbolic links
    in /proc/self/fd/{0,1,2} when resolving the terminal device number.
    This can allow sudo to map a terminal device to its path name even
    when /dev/pts is not mounted in a chroot jail.
    * Fixed compilation errors with gcc and clang in C23 mode. C23 no
    longer supports functions with unspecified arguments. GitHub issue
    [#420].
    * Fixed the test for cross-compiling when checking for C99 snprintf().
    The changes made to the test in sudo 1.9.16 resulted in a different
    problem. GitHub issue #386.
    * Fixed the date used by the exit record in sudo-format log files.
    This was a regression introduced in sudo 1.9.16 and only affected
    file-based logs, not syslog. GitHub issue #405.
    * Fixed the root cause of the “unable to find terminal name for device”
    message when running sudo on AIX when no terminal is present. In
    sudo 1.9.16 this was turned from a debug message into a warning.
    GitHub issue #408.
    * When a duplicate alias is found in the sudoers file, the warning
    message now includes the file and line number of the previous
    definition.
    * Added support for the --with-secure-path-value=no configure option
    to allow packagers to ship the default sudoers file with the secure
    path line commented out.
    * Sudo no longer sends mail when a user runs sudo -nv or sudo -nl,
    even if mail_badpass or mail_always are set. Sudo already avoids
    logging to a file or syslog in this case. Bug #1072.
    * Added the cmddenial_message sudoers option to provide additional
    information to the user when a command is denied by the sudoers
    policy. The default message is still displayed.
    * The time stamp used for file-based logs is now more consistent
    with the time stamp produced by syslog. GitHub issue #327.
    * Sudo will now warn the user if it can detect the user’s terminal but
    cannot determine the path to the terminal device. The sudoers time
    stamp file will now use the terminal device number directly.
    GitHub issue #329.
    * The embedded copy of zlib has been updated to version 1.3.1.
    * Improved error handling if generating the list of signals and signal
    names fails at build time.
    * Fixed a compilation issue on Linux systems without process_vm_readv().
    * Fixed cross-compilation with WolfSSL.
    * Added a json_compact value for the sudoers log_format option which can
    be used when logging to a file. The existing json value has been aliased
    to json_pretty. In a future release, json will be an alias for
    json_compact. GitHub issue #357.
    * A new pam_silent sudoers option has been added which may be negated to
    avoid suppressing output from PAM authentication modules. GitHub issue #216.
    * Fixed several cvtsudoers JSON output problems. GitHub issues #369, #370,
    [#371], #373, #381.
    * When sudo runs a command in a pseudo-terminal and the user’s terminal is
    revoked, the pseudo-terminal’s foreground process group will now receive
    SIGHUP before the terminal is revoked. This emulates the behavior of the
    session leader exiting and is consistent with what happens when,
    for example, an ssh session is closed. GitHub issue #367.
    * Fixed make test with Python 3.12. GitHub issue #374.
    * In schema.ActiveDirectory, fixed the quoting in the example command.
    GitHub issue #376.
    * Paths specified via a Chdir_Spec or Chroot_Spec in sudoers may now
    be double-quoted.
    * Sudo insults are now included by default, but disabled unless the
  - -with-insults configure option is specified or the insults sudoers
    option is enabled.
    * The default sudoers file now enables the secure_path option by
    default and preserves the EDITOR, VISUAL, and SUDO_EDITOR environment
    variables when running visudo. The new --with-secure-path-value
    configure option can be used to set the value of secure_path in
    the default sudoers file. GitHub issue #387.
    * A sudoers schema for IBM Directory Server (aka IBM Tivoli Directory
    Server, IBM Security Directory Server, and IBM Security Verify
    Directory) is now included.
    * When cross-compiling sudo, the configure script now assumes that
    the snprintf() function is C99-compliant if the C compiler
    supports the C99 standard. Previously, configure would use sudo’s
    own snprintf() when cross-compiling. GitHub issue #386.

------------------------------------------------------------------
------------------  2025-4-15  -  Apr 15 2025  -------------------
------------------------------------------------------------------

++++ cockpit-tukit:

  - Update to version 0.1.3~git0.41f9fbc:
    * FEAT: add ci
    * FEAT: drop rome and use styelint and eslint
    * FIX: update makefile to support updated translation utils
    * FEAT: explicitly specify cockpit-tukit is only supported on transacional systems
    * use typescript types provided by upstream
    * drop 38.patch

++++ lvm2-device-mapper:

  - LVM filter behaves unexpectedly for MPIO devices in SLES15SP5 (bsc#1216938)
    * set lvm.conf devices.multipath_wwids_file=""

++++ firewalld:

  - Require python3-PyQt6 in firewall-applet, since that's preferred
    over PyQt5.

++++ hwinfo:

  - Add support for installing to prefixes other than /usr with
    INSTALL_PREFIX (bsc#1241295)
  - merge gh#openSUSE/hwinfo#102
  - Closes #61: refactors redundant condition (bsc#1241295)
  - merge gh#openSUSE/hwinfo#110
  - remove malloc.h headers usage (bsc#1241295)
  - merge gh#openSUSE/hwinfo#147
  - Don't create unused /sbin on install (bsc#1241295)
  - merge gh#openSUSE/hwinfo#157
  - Free additional memory fields to prevent hd leaks (bsc#1241295)

++++ jeos-firstboot:

  - Update to version 1.5.5:
    * user: Add field to add the user to specified groups (bsc#1241215)
    * Add title and description to remaining modules
  - Remove changesauthor from _service

++++ kdump:

  - upgrade to version 2.0.18
    * set KDUMP_CPUs to 32 by default (bsc#1240769, jsc#PED-9894,
    bsc#1237754, bsc#1239999)

++++ kernel-default:

  - tools/power turbostat: Increase CPU_SUBSET_MAXCPUS to 8192
    (bsc#1241175).
  - commit 0ef38a2
  - KVM: arm64: Disable MPAM visibility by default and ignore VMM
    writes (jsc#PED-348).
  - commit e3beeb3
  - KVM: arm64: Add a macro for creating filtered sys_reg_descs
    entries (jsc#PED-348).
  - commit 84c72db
  - KVM: arm64: Fix missing traps of guest accesses to the MPAM
    registers (jsc#PED-348).
  - commit e04fac3
  - arm64/sysreg: Convert existing MPAM sysregs and add the
    remaining entries (jsc#PED-348).
  - commit fc877ac
  - arm64: cpufeature: discover CPU support for MPAM (jsc#PED-348).
  - Refresh
    patches.suse/arm64-sme-Move-storage-of-reg_smidr-to-__cpuinfo_store_cpu.patch.
  - commit 4273e38
  - s390/kvm: Initialize uninitialized flags variable (jsc#PED-348).
  - commit bd0573c
  - KVM: arm64: Handle WXN attribute (jsc#PED-348).
  - commit 9517663
  - KVM: arm64: Handle stage-1 permission overlays (jsc#PED-348).
  - commit f65766f
  - KVM: arm64: Make PAN conditions part of the S1 walk context
    (jsc#PED-348).
  - commit c70d3fb
  - KVM: arm64: Disable hierarchical permissions when POE is enabled
    (jsc#PED-348).
  - commit dcfbd15
  - KVM: arm64: Add POE save/restore for AT emulation fast-path
    (jsc#PED-348).
  - commit 89f6f7b
  - KVM: arm64: Add save/restore support for POR_EL2 (jsc#PED-348).
  - commit 4e2e599
  - KVM: arm64: Add basic support for POR_EL2 (jsc#PED-348).
  - commit 54dfec0
  - arm64: Add encoding for POR_EL2 (jsc#PED-348).
  - commit 9267b41
  - mm: fix kernel BUG when userfaultfd_move encounters swapcache
    (CVE-2025-21984 bsc#1240793).
  - commit 8567e65
  - KVM: arm64: Add kvm_has_s1poe() helper (jsc#PED-348).
  - commit da6756a
  - KVM: arm64: Subject S1PIE/S1POE registers to HCR_EL2.{TVM,TRVM}
    (jsc#PED-348).
  - commit 1d7e9b8
  - KVM: arm64: Drop bogus CPTR_EL2.E0POE trap routing
    (jsc#PED-348).
  - commit 9eac74b
  - KVM: arm64: Rely on visibility to let PIR*_ELx/TCR2_ELx UNDEF
    (jsc#PED-348).
  - commit 694ef1d
  - KVM: arm64: Hide S1PIE registers from userspace when disabled
    for guests (jsc#PED-348).
  - commit 2dec159
  - KVM: arm64: Hide TCR2_EL1 from userspace when disabled for
    guests (jsc#PED-348).
  - commit f97c2f8
  - KVM: arm64: Define helper for EL2 registers with custom
    visibility (jsc#PED-348).
  - commit 3d235f5
  - KVM: arm64: Add a composite EL2 visibility helper (jsc#PED-348).
  - commit f47be3b
  - KVM: arm64: Implement AT S1PIE support (jsc#PED-348).
  - commit 820b016
  - KVM: arm64: Disable hierarchical permissions when S1PIE is
    enabled (jsc#PED-348).
  - commit e14aa8f
  - KVM: arm64: Split S1 permission evaluation into direct and
    hierarchical parts (jsc#PED-348).
  - commit f4fb624
  - KVM: arm64: Add AT fast-path support for S1PIE (jsc#PED-348).
  - commit 1a3afec
  - KVM: arm64: Handle PIR{,E0}_EL2 traps (jsc#PED-348).
  - commit e7ff115
  - arm64: Add encoding for PIRE0_EL2 (jsc#PED-348).
  - commit 83735b4
  - KVM: arm64: Add save/restore for PIR{,E0}_EL2 (jsc#PED-348).
  - commit 20ffc77
  - KVM: arm64: Add PIR{,E0}_EL2 to the sysreg arrays (jsc#PED-348).
  - commit 88c8532
  - KVM: arm64: Add save/restore for TCR2_EL2 (jsc#PED-348).
  - commit ff41ff0
  - KVM: arm64: Sanitise TCR2_EL2 (jsc#PED-348).
  - commit f3d1cd4
  - usb: core: Don't use %pK through printk (jsc#PED-10906).
  - commit 451ccc3
  - arm64/sysreg: Update ID_AA64MMFR1_EL1 register (jsc#PED-348).
  - commit 9e3de0a
  - usb: core: replace usb_sndaddr0pipe macro with usb_sndctrlpipe
    (jsc#PED-10906).
  - commit d5e9e32
  - USB: core: Add eUSB2 descriptor and parsing in USB core
    (jsc#PED-10906).
  - commit 9bca1b9
  - KVM: arm64: nv: Save/Restore vEL2 sysregs (jsc#PED-348).
  - commit f6a4e31
  - KVM: arm64: Add TCR2_EL2 to the sysreg arrays (jsc#PED-348).
  - commit 451336d
  - KVM: arm64: Extend masking facility to arbitrary registers
    (jsc#PED-348).
  - commit b513a82
  - usb: hcd: Bump local buffer size in rh_string() (jsc#PED-10906).
  - commit 68d4f73
  - KVM: arm64: nv: Handle CNTHCTL_EL2 specially (jsc#PED-348).
  - commit 6e65067
  - KVM: arm64: nv: Add missing EL2->EL1 mappings in
    get_el2_to_el1_mapping() (jsc#PED-348).
  - commit 12505d9
  - net: atm: fix use after free in lec_send() (CVE-2025-22004
    bsc#1240835).
  - commit adce8b1
  - KVM: arm64: Drop useless struct s2_mmu in __kvm_at_s1e2()
    (jsc#PED-348).
  - commit fc823e4
  - KVM: x86/mmu: Batch TLB flushes when zapping collapsible TDP
    MMU SPTEs (jsc#PED-348).
  - commit de109d1
  - KVM: x86/mmu: Drop @max_level from kvm_mmu_max_mapping_level()
    (jsc#PED-348).
  - commit dd47125
  - KVM: x86: Don't emit TLB flushes when aging SPTEs for
    mmu_notifiers (jsc#PED-348).
  - Refresh
    patches.suse/KVM-x86-Break-CONFIG_KVM_X86-s-direct-dependency-on-.patch.
  - Refresh
    patches.suse/KVM-x86-add-back-X86_LOCAL_APIC-dependency.patch.
  - commit ae06851
  - KVM: Allow arch code to elide TLB flushes when aging a young
    page (jsc#PED-348).
  - commit 7716eab
  - KVM: x86/mmu: Set Dirty bit for new SPTEs, even if _hardware_
    A/D bits are disabled (jsc#PED-348).
  - commit e1874d2
  - usb: typec: tcpm: Switch to use hrtimer_setup() (jsc#PED-10906).
  - commit 6f682e4
  - KVM: x86/mmu: Dedup logic for detecting TLB flushes on leaf
    SPTE changes (jsc#PED-348).
  - commit e07246c
  - KVM: x86/mmu: Stop processing TDP MMU roots for test_age if
    young SPTE found (jsc#PED-348).
  - commit 27f92c8
  - usb: typec: ucsi: Enable UCSI commands in debugfs
    (jsc#PED-10906).
  - commit c833f26
  - KVM: x86/mmu: Process only valid TDP MMU roots when aging a
    gfn range (jsc#PED-348).
  - commit 943dc36
  - usb: typec: ucsi: Rename SET_UOM UCSI command to SET_CCOM
    (jsc#PED-10906).
  - commit ab708c6
  - KVM: x86/mmu: Use Accessed bit even when _hardware_ A/D bits
    are disabled (jsc#PED-348).
  - commit cfcfab1
  - usb: typec: ucsi: Add a macro definition for UCSI v1.0
    (jsc#PED-10906).
  - commit 39299cc
  - KVM: x86/mmu: Set shadow_dirty_mask for EPT even if A/D bits
    disabled (jsc#PED-348).
  - commit b2bf96d
  - KVM: x86/mmu: Set shadow_accessed_mask for EPT even if A/D
    bits disabled (jsc#PED-348).
  - commit 566d28e
  - USB: typec: Use str_enable_disable-like helpers (jsc#PED-10906).
  - commit 120ce5f
  - KVM: x86/mmu: Add a dedicated flag to track if A/D bits are
    globally enabled (jsc#PED-348).
  - commit 3d2e74a
  - KVM: x86/mmu: WARN and flush if resolving a TDP MMU fault
    clears MMU-writable (jsc#PED-348).
  - commit 48ca2b6
  - KVM: x86/mmu: Fold mmu_spte_update_no_track() into
    mmu_spte_update() (jsc#PED-348).
  - commit 75b98ac
  - KVM: x86/mmu: Drop ignored return value from
    kvm_tdp_mmu_clear_dirty_slot() (jsc#PED-348).
  - commit a673add
  - KVM: x86/mmu: Don't flush TLBs when clearing Dirty bit in
    shadow MMU (jsc#PED-348).
  - commit 5534036
  - KVM: x86/mmu: Don't force flush if SPTE update clears Accessed
    bit (jsc#PED-348).
  - commit b286e77
  - KVM: x86/mmu: Fold all of make_spte()'s writable handling into
    one if-else (jsc#PED-348).
  - commit af747d2
  - KVM: x86/mmu: Always set SPTE's dirty bit if it's created as
    writable (jsc#PED-348).
  - commit c950df4
  - KVM: x86/mmu: Flush remote TLBs iff MMU-writable flag is
    cleared from RO SPTE (jsc#PED-348).
  - commit d8a996f
  - KVM: Protect vCPU's "last run PID" with rwlock, not RCU
    (jsc#PED-348).
  - commit 33d08b8
  - KVM: Return '0' directly when there's no task to yield to
    (jsc#PED-348).
  - commit 61738c0
  - KVM: Rework core loop of kvm_vcpu_on_spin() to use a single
    for-loop (jsc#PED-348).
  - commit f053a79
  - kvm/vfio: Constify struct kvm_device_ops (jsc#PED-348).
  - commit d80fea1
  - KVM: VMX: Remove the unused variable "gpa" in __invept()
    (jsc#PED-348).
  - commit 7ec63c5
  - s390/kvm: Stop using gmap_{en,dis}able() (jsc#PED-348).
  - commit ad5699e
  - s390/mm/fault: Handle guest-related program interrupts in KVM
    (jsc#PED-348).
  - commit 6f895c5
  - usb: typec: ucsi: make yoga_c630_ucsi_ops be static (git-fixes).
  - Refresh
    patches.suse/acpi-typec-ucsi-Introduce-a-poll_cci-method.patch.
  - commit 1fd8834
  - s390/entry: Remove __GMAP_ASCE and use _PIF_GUEST_FAULT again
    (jsc#PED-348).
  - commit 9fb399c
  - ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw()
    (CVE-2025-22005 bsc#1240866).
  - commit 55ba3fc
  - sched: address a potential NULL pointer dereference in the
    GRED scheduler (CVE-2025-21980 bsc#1240809).
  - commit 6b4ede1
  - llc: do not use skb_get() before dev_queue_xmit()
    (CVE-2025-21925 bsc#1240713).
  - commit bda383b
  - net: gso: fix ownership in __udp_gso_segment (CVE-2025-21926
    bsc#1240712).
  - commit b665cba
  - s390/kvm: Remove kvm_arch_fault_in_page() (jsc#PED-348).
  - commit 3095779
  - x86/sev: Convert shared memory back to private on kexec
    (jsc#PED-348).
  - commit 0647d96
  - x86/mm: Refactor __set_clr_pte_enc() (jsc#PED-348).
  - commit ea457a5
  - RISC-V: KVM: Use NACL HFENCEs for KVM request based HFENCEs
    (jsc#PED-348).
  - commit d360325
  - RISC-V: KVM: Save trap CSRs in kvm_riscv_vcpu_enter_exit()
    (jsc#PED-348).
  - commit e8697fa
  - RISC-V: KVM: Use SBI sync SRET call when available
    (jsc#PED-348).
  - commit 3da5307
  - RISC-V: KVM: Use nacl_csr_xyz() for accessing AIA CSRs
    (jsc#PED-348).
  - commit 82bdae7
  - RISC-V: KVM: Use nacl_csr_xyz() for accessing H-extension CSRs
    (jsc#PED-348).
  - commit 6970419
  - RISC-V: KVM: Add common nested acceleration support
    (jsc#PED-348).
  - commit d82db7c
  - RISC-V: KVM: Don't setup SGEI for zero guest external interrupts
    (jsc#PED-348).
  - commit b1f1f2e
  - RISC-V: KVM: Replace aia_set_hvictl() with aia_hvictl_value()
    (jsc#PED-348).
  - commit 7003072
  - RISC-V: KVM: Break down the __kvm_riscv_switch_to() into macros
    (jsc#PED-348).
  - commit b08f02a
  - RISC-V: KVM: Save/restore SCOUNTEREN in C source (jsc#PED-348).
  - commit fe6d178
  - RISC-V: KVM: Save/restore HSTATUS in C source (jsc#PED-348).
  - commit c7799a4
  - RISC-V: KVM: Order the object files alphabetically
    (jsc#PED-348).
  - commit 559c6a4
  - riscv: KVM: add basic support for host vs guest profiling
    (jsc#PED-348).
  - commit 6ab0369
  - KVM: Don't grab reference on VM_MIXEDMAP pfns that have a
    "struct page" (jsc#PED-348).
  - commit 35de075
  - KVM: Drop APIs that manipulate "struct page" via pfns
    (jsc#PED-348).
  - commit 609bbfb
  - KVM: arm64: Don't mark "struct page" accessed when making SPTE
    young (jsc#PED-348).
  - commit 9484013
  - KVM: x86/mmu: Don't mark "struct page" accessed when zapping
    SPTEs (jsc#PED-348).
  - commit cc2a92b
  - KVM: Make kvm_follow_pfn.refcounted_page a required field
    (jsc#PED-348).
  - commit 169d6a4
  - KVM: s390: Use kvm_release_page_dirty() to unpin "struct page"
    memory (jsc#PED-348).
  - commit 18e2728
  - KVM: Drop gfn_to_pfn() APIs now that all users are gone
    (jsc#PED-348).
  - commit 5338a4f
  - KVM: PPC: Explicitly require struct page memory for Ultravisor
    sharing (jsc#PED-348).
  - commit 21ddf5e
  - KVM: arm64: Use __gfn_to_page() when copying MTE tags to/from
    userspace (jsc#PED-348).
  - commit 3eaa98c
  - KVM: Add support for read-only usage of gfn_to_page()
    (jsc#PED-348).
  - commit 9d01822
  - KVM: Convert gfn_to_page() to use kvm_follow_pfn()
    (jsc#PED-348).
  - commit 9029bc7
  - KVM: PPC: Use kvm_vcpu_map() to map guest memory to patch dcbz
    instructions (jsc#PED-348).
  - commit bd2622b
  - KVM: PPC: Remove extra get_page() to fix page refcount leak
    (jsc#PED-348).
  - commit 8e1492f
  - KVM: MIPS: Use kvm_faultin_pfn() to map pfns into the guest
    (jsc#PED-348).
  - commit 518e429
  - KVM: MIPS: Mark "struct page" pfns accessed prior to dropping
    mmu_lock (jsc#PED-348).
  - commit ddd3591
  - KVM: MIPS: Mark "struct page" pfns accessed only in "slow"
    page fault path (jsc#PED-348).
  - commit 297d0d2
  - KVM: MIPS: Mark "struct page" pfns dirty only in "slow" page
    fault path (jsc#PED-348).
  - commit c07fb69
  - KVM: LoongArch: Use kvm_faultin_pfn() to map pfns into the guest
    (jsc#PED-348).
  - commit b0ce30a
  - KVM: LoongArch: Mark "struct page" pfn accessed before dropping
    mmu_lock (jsc#PED-348).
  - commit 19db987
  - KVM: LoongArch: Mark "struct page" pfns accessed only in "slow"
    page fault path (jsc#PED-348).
  - commit f4eecd8
  - KVM: LoongArch: Mark "struct page" pfns dirty only in "slow"
    page fault path (jsc#PED-348).
  - commit e66b533
  - KVM: PPC: Use kvm_faultin_pfn() to handle page faults on Book3s
    PR (jsc#PED-348).
  - commit 7939351
  - KVM: PPC: Book3S: Mark "struct page" pfns dirty/accessed after
    installing PTE (jsc#PED-348).
  - commit aa1dde6
  - KVM: PPC: Drop unused @kvm_ro param from
    kvmppc_book3s_instantiate_page() (jsc#PED-348).
  - commit cc34550
  - KVM: PPC: Use __kvm_faultin_pfn() to handle page faults on
    Book3s Radix (jsc#PED-348).
  - commit 0e15d53
  - KVM: PPC: Use __kvm_faultin_pfn() to handle page faults on
    Book3s HV (jsc#PED-348).
  - commit f67a3b8
  - KVM: RISC-V: Use kvm_faultin_pfn() when mapping pfns into the
    guest (jsc#PED-348).
  - commit 9d03d10
  - KVM: RISC-V: Mark "struct page" pfns accessed before dropping
    mmu_lock (jsc#PED-348).
  - commit 7c80cea
  - KVM: RISC-V: Mark "struct page" pfns dirty iff a stage-2 PTE
    is installed (jsc#PED-348).
  - commit 9552f6c
  - KVM: arm64: Use __kvm_faultin_pfn() to handle memory aborts
    (jsc#PED-348).
  - commit fa597ff
  - KVM: arm64: Mark "struct page" pfns accessed/dirty before
    dropping mmu_lock (jsc#PED-348).
  - commit a4270e1
  - KVM: PPC: e500: Use __kvm_faultin_pfn() to handle page faults
    (jsc#PED-348).
  - commit 6be6f59
  - KVM: PPC: e500: Mark "struct page" pfn accessed before dropping
    mmu_lock (jsc#PED-348).
  - commit 5546e1c
  - KVM: PPC: e500: Mark "struct page" dirty in
    kvmppc_e500_shadow_map() (jsc#PED-348).
  - commit 160e7cb
  - KVM: VMX: Use __kvm_faultin_page() to get APIC access page/pfn
    (jsc#PED-348).
  - commit 61408ef
  - KVM: VMX: Hold mmu_lock until page is released when updating
    APIC access page (jsc#PED-348).
  - Refresh
    patches.suse/KVM-x86-Plumb-in-the-vCPU-to-kvm_x86_ops.hwapic_isr_.patch.
  - commit e97d169
  - KVM: Move x86's API to release a faultin page to common KVM
    (jsc#PED-348).
  - commit 035d4ba
  - KVM: x86/mmu: Don't mark unused faultin pages as accessed
    (jsc#PED-348).
  - commit e82b47f
  - KVM: x86/mmu: Put refcounted pages instead of blindly releasing
    pfns (jsc#PED-348).
  - commit 6c6ce8a
  - KVM: guest_memfd: Provide "struct page" as output from
    kvm_gmem_get_pfn() (jsc#PED-348).
  - commit feb8cad
  - KVM: guest_memfd: Pass index, not gfn, to __kvm_gmem_get_pfn()
    (jsc#PED-348).
  - commit bd6cf4e
  - KVM: x86/mmu: Convert page fault paths to kvm_faultin_pfn()
    (jsc#PED-348).
  - commit 6ea159b
  - KVM: Add kvm_faultin_pfn() to specifically service guest page
    faults (jsc#PED-348).
  - commit 6ea3a1f
  - KVM: Move declarations of memslot accessors up in kvm_host.h
    (jsc#PED-348).
  - commit 346a8cc
  - KVM: x86/mmu: Mark pages/folios dirty at the origin of
    make_spte() (jsc#PED-348).
  - commit b50aad2
  - KVM: x86/mmu: Add helper to "finish" handling a guest page fault
    (jsc#PED-348).
  - commit 25e2704
  - usb: typec: Only use SVID for matching altmodes (jsc#PED-10906).
  - commit 61e9ea2
  - KVM: x86/mmu: Add common helper to handle prefetching SPTEs
    (jsc#PED-348).
  - commit cf1410f
  - KVM: x86/mmu: Put direct prefetched pages via
    kvm_release_page_clean() (jsc#PED-348).
  - commit 7ec071e
  - KVM: x86/mmu: Add "mmu" prefix fault-in helpers to free up
    generic names (jsc#PED-348).
  - commit 2a00967
  - KVM: x86: Don't fault-in APIC access page during initial
    allocation (jsc#PED-348).
  - commit 78f29d5
  - KVM: Disallow direct access (w/o mmu_notifier) to unpinned
    pfn by default (jsc#PED-348).
  - commit f85530d
  - KVM: Get writable mapping for __kvm_vcpu_map() only when
    necessary (jsc#PED-348).
  - commit f777357
  - KVM: Pass in write/dirty to kvm_vcpu_map(), not kvm_vcpu_unmap()
    (jsc#PED-348).
  - commit 883428f
  - modpost: rename variables in handle_moddevtable()
    (jsc#PED-10906).
  - commit aba5386
  - KVM: nVMX: Mark vmcs12's APIC access page dirty when unmapping
    (jsc#PED-348).
  - commit 6e89a6c
  - KVM: Pin (as in FOLL_PIN) pages during kvm_vcpu_map()
    (jsc#PED-348).
  - commit 16f3b31
  - modpost: move strstarts() to modpost.h (jsc#PED-10906).
  - Refresh patches.suse/kbuild-modpost-integrate-klp-convert.patch.
  - commit a756d33
  - KVM: Migrate kvm_vcpu_map() to kvm_follow_pfn() (jsc#PED-348).
  - commit d7f465b
  - modpost: convert do_usb_table() to a generic handler
    (git-fixes).
  - commit ecc46de
  - KVM: pfncache: Precisely track refcounted pages (jsc#PED-348).
  - commit 0aff3f5
  - modpost: convert do_of_table() to a generic handler
    (jsc#PED-10906).
  - commit d8f945d
  - KVM: Add kvm_release_page_unused() API to put pages that KVM
    never consumes (jsc#PED-348).
  - commit f3f2577
  - modpost: convert do_pnp_device_entry() to a generic handler
    (jsc#PED-10906).
  - commit af13ab1
  - modpost: convert do_pnp_card_entries() to a generic handler
    (jsc#PED-10906).
  - commit f180a34
  - modpost: call module_alias_printf() from all do_*_entry()
    functions (jsc#PED-10906).
  - commit e34cda7
  - modpost: pass (struct module *) to do_*_entry() functions
    (jsc#PED-10906).
  - commit cc012bd
  - KVM: Move kvm_{set,release}_page_{clean,dirty}() helpers up
    in kvm_main.c (jsc#PED-348).
  - commit 83af984
  - modpost: remove DEF_FIELD_ADDR_VAR() macro (jsc#PED-10906).
  - commit 90a6f96
  - KVM: Provide refcounted page as output field in struct
    kvm_follow_pfn (jsc#PED-348).
  - commit 20e080e
  - modpost: deduplicate MODULE_ALIAS() for all drivers
    (jsc#PED-10906).
  - commit 76f77e7
  - KVM: Use plain "struct page" pointer instead of single-entry
    array (jsc#PED-348).
  - commit 9282fe8
  - KVM: nVMX: Add helper to put (unmap) vmcs12 pages (jsc#PED-348).
  - commit b7b598e
  - modpost: introduce module_alias_printf() helper (jsc#PED-10906).
  - Refresh patches.suse/add-suse-supported-flag.patch.
  - Refresh
    patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch.
  - commit 272330b
  - KVM: nVMX: Drop pointless msr_bitmap_map field from struct
    nested_vmx (jsc#PED-348).
  - commit d39c536
  - modpost: remove unnecessary check in do_acpi_entry()
    (jsc#PED-10906).
  - commit a88bac3
  - KVM: nVMX: Rely on kvm_vcpu_unmap() to track validity of eVMCS
    mapping (jsc#PED-348).
  - commit 4f03277
  - KVM: Use NULL for struct page pointer to indicate mremapped
    memory (jsc#PED-348).
  - commit 8ec4686
  - KVM: Explicitly initialize all fields at the start of
    kvm_vcpu_map() (jsc#PED-348).
  - commit 0ee9c47
  - KVM: Remove pointless sanity check on @map param to
    kvm_vcpu_(un)map() (jsc#PED-348).
  - commit c5f3ebd
  - KVM: Introduce kvm_follow_pfn() to eventually replace
    "gfn_to_pfn" APIs (jsc#PED-348).
  - commit f0c102d
  - KVM: Drop unused "hva" pointer from __gfn_to_pfn_memslot()
    (jsc#PED-348).
  - commit fc13047
  - KVM: x86/mmu: Drop kvm_page_fault.hva, i.e. don't track
    intermediate hva (jsc#PED-348).
  - commit a75fb71
  - KVM: Replace "async" pointer in gfn=>pfn with "no_wait" and
    error code (jsc#PED-348).
  - commit 267c432
  - KVM: Drop extra GUP (via check_user_page_hwpoison()) to detect
    poisoned page (jsc#PED-348).
  - commit 17f0d93
  - KVM: Return ERR_SIGPENDING from hva_to_pfn() if GUP returns
  - EGAIN (jsc#PED-348).
  - commit 3b658f3
  - KVM: Annotate that all paths in hva_to_pfn() might sleep
    (jsc#PED-348).
  - commit edfdc02
  - KVM: Drop @atomic param from gfn=>pfn and hva=>pfn APIs
    (jsc#PED-348).
  - commit 8f753c1
  - KVM: Rename gfn_to_page_many_atomic() to kvm_prefetch_pages()
    (jsc#PED-348).
  - commit da09c4e
  - KVM: x86/mmu: Use gfn_to_page_many_atomic() when prefetching
    indirect PTEs (jsc#PED-348).
  - commit a2ea2a7
  - KVM: x86/mmu: Mark page/folio accessed only when zapping leaf
    SPTEs (jsc#PED-348).
  - commit 7d8ddfe
  - KVM: x86/mmu: Mark folio dirty when creating SPTE, not when
    zapping/modifying (jsc#PED-348).
  - commit 93e9c16
  - KVM: x86/mmu: Mark new SPTE as Accessed when synchronizing
    existing SPTE (jsc#PED-348).
  - commit 0710a89
  - KVM: x86/mmu: Invert @can_unsync and renamed to @synchronizing
    (jsc#PED-348).
  - commit 2af317d
  - KVM: x86/mmu: Don't overwrite shadow-present MMU SPTEs when
    prefaulting (jsc#PED-348).
  - commit cf029e8
  - KVM: x86/mmu: Skip the "try unsync" path iff the old SPTE was
    a leaf SPTE (jsc#PED-348).
  - commit 8176a7a
  - KVM: Allow calling kvm_release_page_{clean,dirty}() on a NULL
    page pointer (jsc#PED-348).
  - commit dae8f22
  - KVM: Drop KVM_ERR_PTR_BAD_PAGE and instead return NULL to
    indicate an error (jsc#PED-348).
  - commit 7c4b876
  - KVM: arm64: nvhe: Pass through PSCI v1.3 SYSTEM_OFF2 call
    (jsc#PED-348).
  - commit 932dd19
  - KVM: arm64: Add support for PSCI v1.2 and v1.3 (jsc#PED-348).
  - commit f451559
  - KVM: arm64: Add PSCI v1.3 SYSTEM_OFF2 function for hibernation
    (jsc#PED-348).
  - commit 6c5d08c
  - firmware/psci: Add definitions for PSCI v1.3 specification
    (jsc#PED-348).
  - commit d3ca0ff
  - RDMA/bnxt_re: Remove unusable nq variable (git-fixes)
  - commit 047a720
  - KVM: arm64: Don't map 'kvm_vgic_global_state' at EL2 with pKVM
    (jsc#PED-348).
  - commit b6ff591
  - KVM: arm64: Just advertise SEIS as 0 when emulating ICC_CTLR_EL1
    (jsc#PED-348).
  - commit fa5285c
  - selftest/bpf: Add vsock test for sockmap rejecting unconnected
    (bsc#1239470 CVE-2025-21854).
  - commit 6e36f6b
  - selftest/bpf: Adapt vsock_delete_on_close to sockmap rejecting
    unconnected (bsc#1239470 CVE-2025-21854).
  - sockmap, vsock: For connectible sockets allow only connected
    (bsc#1239470 CVE-2025-21854).
  - selftest/bpf: Add test for vsock removal from sockmap on close()
    (bsc#1239470 CVE-2025-21854).
  - selftest/bpf: Add test for af_vsock poll() (bsc#1239470
    CVE-2025-21854).
  - commit 750fb4b
  - RDMA/core: Silence oversized kvmalloc() warning (git-fixes)
  - commit b40a0b3
  - RDMA/cma: Fix workqueue crash in cma_netevent_work_handler (git-fixes)
  - commit 1195add
  - RDMA/hns: Fix wrong maximum DMA segment size (git-fixes)
  - commit 10442e4
  - RDMA/usnic: Fix passing zero to PTR_ERR in usnic_ib_pci_probe() (git-fixes)
  - commit a0ae514
  - RDMA/bnxt_re: Fix budget handling of notification queue (git-fixes)
  - commit 4f16ca1
  - selftests/net: Add test for loading devbound XDP program in
    generic mode (bsc#1238742 CVE-2025-21808).
  - net: xdp: Disallow attaching device-bound programs in generic
    mode (bsc#1238742 CVE-2025-21808).
  - commit 461e3db
  - Update
    patches.suse/md-md-bitmap-fix-wrong-bitmap_limit-for-clustermd-wh.patch
    (bsc#1238212).
  - commit 43028e5

++++ kernel-firmware-sound:

  - Update to version 20250415 (git commit 2f411c10e457):
    * intel: avs: Update topology file for I2S Analog Devices 4567
    * intel: avs: Update topology file for I2S Realtek 5663
    * intel: avs: Update topology file for I2S Realtek 5640
    * intel: avs: Update topology file for I2S Realtek 5514
    * intel: avs: Update topology file for I2S Realtek 298
    * intel: avs: Update topology file for I2S Realtek 286
    * intel: avs: Update topology file for I2S Realtek 274
    * intel: avs: Update topology file for I2S Nuvoton 8825
    * intel: avs: Update topology file for I2S Maxim 98927
    * intel: avs: Update topology file for I2S Maxim 98373
    * intel: avs: Update topology file for I2S Maxim 98357a
    * intel: avs: Update topology file for HDAudio codecs
    * intel: avs: Update topology file for HDMI codecs
    * intel: avs: Update topology file for Digital Microphone Array
    * intel: avs: Update topology file for I2S Dialog 7219

++++ kernel-rt:

  - tools/power turbostat: Increase CPU_SUBSET_MAXCPUS to 8192
    (bsc#1241175).
  - commit 0ef38a2
  - KVM: arm64: Disable MPAM visibility by default and ignore VMM
    writes (jsc#PED-348).
  - commit e3beeb3
  - KVM: arm64: Add a macro for creating filtered sys_reg_descs
    entries (jsc#PED-348).
  - commit 84c72db
  - KVM: arm64: Fix missing traps of guest accesses to the MPAM
    registers (jsc#PED-348).
  - commit e04fac3
  - arm64/sysreg: Convert existing MPAM sysregs and add the
    remaining entries (jsc#PED-348).
  - commit fc877ac
  - arm64: cpufeature: discover CPU support for MPAM (jsc#PED-348).
  - Refresh
    patches.suse/arm64-sme-Move-storage-of-reg_smidr-to-__cpuinfo_store_cpu.patch.
  - commit 4273e38
  - s390/kvm: Initialize uninitialized flags variable (jsc#PED-348).
  - commit bd0573c
  - KVM: arm64: Handle WXN attribute (jsc#PED-348).
  - commit 9517663
  - KVM: arm64: Handle stage-1 permission overlays (jsc#PED-348).
  - commit f65766f
  - KVM: arm64: Make PAN conditions part of the S1 walk context
    (jsc#PED-348).
  - commit c70d3fb
  - KVM: arm64: Disable hierarchical permissions when POE is enabled
    (jsc#PED-348).
  - commit dcfbd15
  - KVM: arm64: Add POE save/restore for AT emulation fast-path
    (jsc#PED-348).
  - commit 89f6f7b
  - KVM: arm64: Add save/restore support for POR_EL2 (jsc#PED-348).
  - commit 4e2e599
  - KVM: arm64: Add basic support for POR_EL2 (jsc#PED-348).
  - commit 54dfec0
  - arm64: Add encoding for POR_EL2 (jsc#PED-348).
  - commit 9267b41
  - mm: fix kernel BUG when userfaultfd_move encounters swapcache
    (CVE-2025-21984 bsc#1240793).
  - commit 8567e65
  - KVM: arm64: Add kvm_has_s1poe() helper (jsc#PED-348).
  - commit da6756a
  - KVM: arm64: Subject S1PIE/S1POE registers to HCR_EL2.{TVM,TRVM}
    (jsc#PED-348).
  - commit 1d7e9b8
  - KVM: arm64: Drop bogus CPTR_EL2.E0POE trap routing
    (jsc#PED-348).
  - commit 9eac74b
  - KVM: arm64: Rely on visibility to let PIR*_ELx/TCR2_ELx UNDEF
    (jsc#PED-348).
  - commit 694ef1d
  - KVM: arm64: Hide S1PIE registers from userspace when disabled
    for guests (jsc#PED-348).
  - commit 2dec159
  - KVM: arm64: Hide TCR2_EL1 from userspace when disabled for
    guests (jsc#PED-348).
  - commit f97c2f8
  - KVM: arm64: Define helper for EL2 registers with custom
    visibility (jsc#PED-348).
  - commit 3d235f5
  - KVM: arm64: Add a composite EL2 visibility helper (jsc#PED-348).
  - commit f47be3b
  - KVM: arm64: Implement AT S1PIE support (jsc#PED-348).
  - commit 820b016
  - KVM: arm64: Disable hierarchical permissions when S1PIE is
    enabled (jsc#PED-348).
  - commit e14aa8f
  - KVM: arm64: Split S1 permission evaluation into direct and
    hierarchical parts (jsc#PED-348).
  - commit f4fb624
  - KVM: arm64: Add AT fast-path support for S1PIE (jsc#PED-348).
  - commit 1a3afec
  - KVM: arm64: Handle PIR{,E0}_EL2 traps (jsc#PED-348).
  - commit e7ff115
  - arm64: Add encoding for PIRE0_EL2 (jsc#PED-348).
  - commit 83735b4
  - KVM: arm64: Add save/restore for PIR{,E0}_EL2 (jsc#PED-348).
  - commit 20ffc77
  - KVM: arm64: Add PIR{,E0}_EL2 to the sysreg arrays (jsc#PED-348).
  - commit 88c8532
  - KVM: arm64: Add save/restore for TCR2_EL2 (jsc#PED-348).
  - commit ff41ff0
  - KVM: arm64: Sanitise TCR2_EL2 (jsc#PED-348).
  - commit f3d1cd4
  - usb: core: Don't use %pK through printk (jsc#PED-10906).
  - commit 451ccc3
  - arm64/sysreg: Update ID_AA64MMFR1_EL1 register (jsc#PED-348).
  - commit 9e3de0a
  - usb: core: replace usb_sndaddr0pipe macro with usb_sndctrlpipe
    (jsc#PED-10906).
  - commit d5e9e32
  - USB: core: Add eUSB2 descriptor and parsing in USB core
    (jsc#PED-10906).
  - commit 9bca1b9
  - KVM: arm64: nv: Save/Restore vEL2 sysregs (jsc#PED-348).
  - commit f6a4e31
  - KVM: arm64: Add TCR2_EL2 to the sysreg arrays (jsc#PED-348).
  - commit 451336d
  - KVM: arm64: Extend masking facility to arbitrary registers
    (jsc#PED-348).
  - commit b513a82
  - usb: hcd: Bump local buffer size in rh_string() (jsc#PED-10906).
  - commit 68d4f73
  - KVM: arm64: nv: Handle CNTHCTL_EL2 specially (jsc#PED-348).
  - commit 6e65067
  - KVM: arm64: nv: Add missing EL2->EL1 mappings in
    get_el2_to_el1_mapping() (jsc#PED-348).
  - commit 12505d9
  - net: atm: fix use after free in lec_send() (CVE-2025-22004
    bsc#1240835).
  - commit adce8b1
  - KVM: arm64: Drop useless struct s2_mmu in __kvm_at_s1e2()
    (jsc#PED-348).
  - commit fc823e4
  - KVM: x86/mmu: Batch TLB flushes when zapping collapsible TDP
    MMU SPTEs (jsc#PED-348).
  - commit de109d1
  - KVM: x86/mmu: Drop @max_level from kvm_mmu_max_mapping_level()
    (jsc#PED-348).
  - commit dd47125
  - KVM: x86: Don't emit TLB flushes when aging SPTEs for
    mmu_notifiers (jsc#PED-348).
  - Refresh
    patches.suse/KVM-x86-Break-CONFIG_KVM_X86-s-direct-dependency-on-.patch.
  - Refresh
    patches.suse/KVM-x86-add-back-X86_LOCAL_APIC-dependency.patch.
  - commit ae06851
  - KVM: Allow arch code to elide TLB flushes when aging a young
    page (jsc#PED-348).
  - commit 7716eab
  - KVM: x86/mmu: Set Dirty bit for new SPTEs, even if _hardware_
    A/D bits are disabled (jsc#PED-348).
  - commit e1874d2
  - usb: typec: tcpm: Switch to use hrtimer_setup() (jsc#PED-10906).
  - commit 6f682e4
  - KVM: x86/mmu: Dedup logic for detecting TLB flushes on leaf
    SPTE changes (jsc#PED-348).
  - commit e07246c
  - KVM: x86/mmu: Stop processing TDP MMU roots for test_age if
    young SPTE found (jsc#PED-348).
  - commit 27f92c8
  - usb: typec: ucsi: Enable UCSI commands in debugfs
    (jsc#PED-10906).
  - commit c833f26
  - KVM: x86/mmu: Process only valid TDP MMU roots when aging a
    gfn range (jsc#PED-348).
  - commit 943dc36
  - usb: typec: ucsi: Rename SET_UOM UCSI command to SET_CCOM
    (jsc#PED-10906).
  - commit ab708c6
  - KVM: x86/mmu: Use Accessed bit even when _hardware_ A/D bits
    are disabled (jsc#PED-348).
  - commit cfcfab1
  - usb: typec: ucsi: Add a macro definition for UCSI v1.0
    (jsc#PED-10906).
  - commit 39299cc
  - KVM: x86/mmu: Set shadow_dirty_mask for EPT even if A/D bits
    disabled (jsc#PED-348).
  - commit b2bf96d
  - KVM: x86/mmu: Set shadow_accessed_mask for EPT even if A/D
    bits disabled (jsc#PED-348).
  - commit 566d28e
  - USB: typec: Use str_enable_disable-like helpers (jsc#PED-10906).
  - commit 120ce5f
  - KVM: x86/mmu: Add a dedicated flag to track if A/D bits are
    globally enabled (jsc#PED-348).
  - commit 3d2e74a
  - KVM: x86/mmu: WARN and flush if resolving a TDP MMU fault
    clears MMU-writable (jsc#PED-348).
  - commit 48ca2b6
  - KVM: x86/mmu: Fold mmu_spte_update_no_track() into
    mmu_spte_update() (jsc#PED-348).
  - commit 75b98ac
  - KVM: x86/mmu: Drop ignored return value from
    kvm_tdp_mmu_clear_dirty_slot() (jsc#PED-348).
  - commit a673add
  - KVM: x86/mmu: Don't flush TLBs when clearing Dirty bit in
    shadow MMU (jsc#PED-348).
  - commit 5534036
  - KVM: x86/mmu: Don't force flush if SPTE update clears Accessed
    bit (jsc#PED-348).
  - commit b286e77
  - KVM: x86/mmu: Fold all of make_spte()'s writable handling into
    one if-else (jsc#PED-348).
  - commit af747d2
  - KVM: x86/mmu: Always set SPTE's dirty bit if it's created as
    writable (jsc#PED-348).
  - commit c950df4
  - KVM: x86/mmu: Flush remote TLBs iff MMU-writable flag is
    cleared from RO SPTE (jsc#PED-348).
  - commit d8a996f
  - KVM: Protect vCPU's "last run PID" with rwlock, not RCU
    (jsc#PED-348).
  - commit 33d08b8
  - KVM: Return '0' directly when there's no task to yield to
    (jsc#PED-348).
  - commit 61738c0
  - KVM: Rework core loop of kvm_vcpu_on_spin() to use a single
    for-loop (jsc#PED-348).
  - commit f053a79
  - kvm/vfio: Constify struct kvm_device_ops (jsc#PED-348).
  - commit d80fea1
  - KVM: VMX: Remove the unused variable "gpa" in __invept()
    (jsc#PED-348).
  - commit 7ec63c5
  - s390/kvm: Stop using gmap_{en,dis}able() (jsc#PED-348).
  - commit ad5699e
  - s390/mm/fault: Handle guest-related program interrupts in KVM
    (jsc#PED-348).
  - commit 6f895c5
  - usb: typec: ucsi: make yoga_c630_ucsi_ops be static (git-fixes).
  - Refresh
    patches.suse/acpi-typec-ucsi-Introduce-a-poll_cci-method.patch.
  - commit 1fd8834
  - s390/entry: Remove __GMAP_ASCE and use _PIF_GUEST_FAULT again
    (jsc#PED-348).
  - commit 9fb399c
  - ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw()
    (CVE-2025-22005 bsc#1240866).
  - commit 55ba3fc
  - sched: address a potential NULL pointer dereference in the
    GRED scheduler (CVE-2025-21980 bsc#1240809).
  - commit 6b4ede1
  - llc: do not use skb_get() before dev_queue_xmit()
    (CVE-2025-21925 bsc#1240713).
  - commit bda383b
  - net: gso: fix ownership in __udp_gso_segment (CVE-2025-21926
    bsc#1240712).
  - commit b665cba
  - s390/kvm: Remove kvm_arch_fault_in_page() (jsc#PED-348).
  - commit 3095779
  - x86/sev: Convert shared memory back to private on kexec
    (jsc#PED-348).
  - commit 0647d96
  - x86/mm: Refactor __set_clr_pte_enc() (jsc#PED-348).
  - commit ea457a5
  - RISC-V: KVM: Use NACL HFENCEs for KVM request based HFENCEs
    (jsc#PED-348).
  - commit d360325
  - RISC-V: KVM: Save trap CSRs in kvm_riscv_vcpu_enter_exit()
    (jsc#PED-348).
  - commit e8697fa
  - RISC-V: KVM: Use SBI sync SRET call when available
    (jsc#PED-348).
  - commit 3da5307
  - RISC-V: KVM: Use nacl_csr_xyz() for accessing AIA CSRs
    (jsc#PED-348).
  - commit 82bdae7
  - RISC-V: KVM: Use nacl_csr_xyz() for accessing H-extension CSRs
    (jsc#PED-348).
  - commit 6970419
  - RISC-V: KVM: Add common nested acceleration support
    (jsc#PED-348).
  - commit d82db7c
  - RISC-V: KVM: Don't setup SGEI for zero guest external interrupts
    (jsc#PED-348).
  - commit b1f1f2e
  - RISC-V: KVM: Replace aia_set_hvictl() with aia_hvictl_value()
    (jsc#PED-348).
  - commit 7003072
  - RISC-V: KVM: Break down the __kvm_riscv_switch_to() into macros
    (jsc#PED-348).
  - commit b08f02a
  - RISC-V: KVM: Save/restore SCOUNTEREN in C source (jsc#PED-348).
  - commit fe6d178
  - RISC-V: KVM: Save/restore HSTATUS in C source (jsc#PED-348).
  - commit c7799a4
  - RISC-V: KVM: Order the object files alphabetically
    (jsc#PED-348).
  - commit 559c6a4
  - riscv: KVM: add basic support for host vs guest profiling
    (jsc#PED-348).
  - commit 6ab0369
  - KVM: Don't grab reference on VM_MIXEDMAP pfns that have a
    "struct page" (jsc#PED-348).
  - commit 35de075
  - KVM: Drop APIs that manipulate "struct page" via pfns
    (jsc#PED-348).
  - commit 609bbfb
  - KVM: arm64: Don't mark "struct page" accessed when making SPTE
    young (jsc#PED-348).
  - commit 9484013
  - KVM: x86/mmu: Don't mark "struct page" accessed when zapping
    SPTEs (jsc#PED-348).
  - commit cc2a92b
  - KVM: Make kvm_follow_pfn.refcounted_page a required field
    (jsc#PED-348).
  - commit 169d6a4
  - KVM: s390: Use kvm_release_page_dirty() to unpin "struct page"
    memory (jsc#PED-348).
  - commit 18e2728
  - KVM: Drop gfn_to_pfn() APIs now that all users are gone
    (jsc#PED-348).
  - commit 5338a4f
  - KVM: PPC: Explicitly require struct page memory for Ultravisor
    sharing (jsc#PED-348).
  - commit 21ddf5e
  - KVM: arm64: Use __gfn_to_page() when copying MTE tags to/from
    userspace (jsc#PED-348).
  - commit 3eaa98c
  - KVM: Add support for read-only usage of gfn_to_page()
    (jsc#PED-348).
  - commit 9d01822
  - KVM: Convert gfn_to_page() to use kvm_follow_pfn()
    (jsc#PED-348).
  - commit 9029bc7
  - KVM: PPC: Use kvm_vcpu_map() to map guest memory to patch dcbz
    instructions (jsc#PED-348).
  - commit bd2622b
  - KVM: PPC: Remove extra get_page() to fix page refcount leak
    (jsc#PED-348).
  - commit 8e1492f
  - KVM: MIPS: Use kvm_faultin_pfn() to map pfns into the guest
    (jsc#PED-348).
  - commit 518e429
  - KVM: MIPS: Mark "struct page" pfns accessed prior to dropping
    mmu_lock (jsc#PED-348).
  - commit ddd3591
  - KVM: MIPS: Mark "struct page" pfns accessed only in "slow"
    page fault path (jsc#PED-348).
  - commit 297d0d2
  - KVM: MIPS: Mark "struct page" pfns dirty only in "slow" page
    fault path (jsc#PED-348).
  - commit c07fb69
  - KVM: LoongArch: Use kvm_faultin_pfn() to map pfns into the guest
    (jsc#PED-348).
  - commit b0ce30a
  - KVM: LoongArch: Mark "struct page" pfn accessed before dropping
    mmu_lock (jsc#PED-348).
  - commit 19db987
  - KVM: LoongArch: Mark "struct page" pfns accessed only in "slow"
    page fault path (jsc#PED-348).
  - commit f4eecd8
  - KVM: LoongArch: Mark "struct page" pfns dirty only in "slow"
    page fault path (jsc#PED-348).
  - commit e66b533
  - KVM: PPC: Use kvm_faultin_pfn() to handle page faults on Book3s
    PR (jsc#PED-348).
  - commit 7939351
  - KVM: PPC: Book3S: Mark "struct page" pfns dirty/accessed after
    installing PTE (jsc#PED-348).
  - commit aa1dde6
  - KVM: PPC: Drop unused @kvm_ro param from
    kvmppc_book3s_instantiate_page() (jsc#PED-348).
  - commit cc34550
  - KVM: PPC: Use __kvm_faultin_pfn() to handle page faults on
    Book3s Radix (jsc#PED-348).
  - commit 0e15d53
  - KVM: PPC: Use __kvm_faultin_pfn() to handle page faults on
    Book3s HV (jsc#PED-348).
  - commit f67a3b8
  - KVM: RISC-V: Use kvm_faultin_pfn() when mapping pfns into the
    guest (jsc#PED-348).
  - commit 9d03d10
  - KVM: RISC-V: Mark "struct page" pfns accessed before dropping
    mmu_lock (jsc#PED-348).
  - commit 7c80cea
  - KVM: RISC-V: Mark "struct page" pfns dirty iff a stage-2 PTE
    is installed (jsc#PED-348).
  - commit 9552f6c
  - KVM: arm64: Use __kvm_faultin_pfn() to handle memory aborts
    (jsc#PED-348).
  - commit fa597ff
  - KVM: arm64: Mark "struct page" pfns accessed/dirty before
    dropping mmu_lock (jsc#PED-348).
  - commit a4270e1
  - KVM: PPC: e500: Use __kvm_faultin_pfn() to handle page faults
    (jsc#PED-348).
  - commit 6be6f59
  - KVM: PPC: e500: Mark "struct page" pfn accessed before dropping
    mmu_lock (jsc#PED-348).
  - commit 5546e1c
  - KVM: PPC: e500: Mark "struct page" dirty in
    kvmppc_e500_shadow_map() (jsc#PED-348).
  - commit 160e7cb
  - KVM: VMX: Use __kvm_faultin_page() to get APIC access page/pfn
    (jsc#PED-348).
  - commit 61408ef
  - KVM: VMX: Hold mmu_lock until page is released when updating
    APIC access page (jsc#PED-348).
  - Refresh
    patches.suse/KVM-x86-Plumb-in-the-vCPU-to-kvm_x86_ops.hwapic_isr_.patch.
  - commit e97d169
  - KVM: Move x86's API to release a faultin page to common KVM
    (jsc#PED-348).
  - commit 035d4ba
  - KVM: x86/mmu: Don't mark unused faultin pages as accessed
    (jsc#PED-348).
  - commit e82b47f
  - KVM: x86/mmu: Put refcounted pages instead of blindly releasing
    pfns (jsc#PED-348).
  - commit 6c6ce8a
  - KVM: guest_memfd: Provide "struct page" as output from
    kvm_gmem_get_pfn() (jsc#PED-348).
  - commit feb8cad
  - KVM: guest_memfd: Pass index, not gfn, to __kvm_gmem_get_pfn()
    (jsc#PED-348).
  - commit bd6cf4e
  - KVM: x86/mmu: Convert page fault paths to kvm_faultin_pfn()
    (jsc#PED-348).
  - commit 6ea159b
  - KVM: Add kvm_faultin_pfn() to specifically service guest page
    faults (jsc#PED-348).
  - commit 6ea3a1f
  - KVM: Move declarations of memslot accessors up in kvm_host.h
    (jsc#PED-348).
  - commit 346a8cc
  - KVM: x86/mmu: Mark pages/folios dirty at the origin of
    make_spte() (jsc#PED-348).
  - commit b50aad2
  - KVM: x86/mmu: Add helper to "finish" handling a guest page fault
    (jsc#PED-348).
  - commit 25e2704
  - usb: typec: Only use SVID for matching altmodes (jsc#PED-10906).
  - commit 61e9ea2
  - KVM: x86/mmu: Add common helper to handle prefetching SPTEs
    (jsc#PED-348).
  - commit cf1410f
  - KVM: x86/mmu: Put direct prefetched pages via
    kvm_release_page_clean() (jsc#PED-348).
  - commit 7ec071e
  - KVM: x86/mmu: Add "mmu" prefix fault-in helpers to free up
    generic names (jsc#PED-348).
  - commit 2a00967
  - KVM: x86: Don't fault-in APIC access page during initial
    allocation (jsc#PED-348).
  - commit 78f29d5
  - KVM: Disallow direct access (w/o mmu_notifier) to unpinned
    pfn by default (jsc#PED-348).
  - commit f85530d
  - KVM: Get writable mapping for __kvm_vcpu_map() only when
    necessary (jsc#PED-348).
  - commit f777357
  - KVM: Pass in write/dirty to kvm_vcpu_map(), not kvm_vcpu_unmap()
    (jsc#PED-348).
  - commit 883428f
  - modpost: rename variables in handle_moddevtable()
    (jsc#PED-10906).
  - commit aba5386
  - KVM: nVMX: Mark vmcs12's APIC access page dirty when unmapping
    (jsc#PED-348).
  - commit 6e89a6c
  - KVM: Pin (as in FOLL_PIN) pages during kvm_vcpu_map()
    (jsc#PED-348).
  - commit 16f3b31
  - modpost: move strstarts() to modpost.h (jsc#PED-10906).
  - Refresh patches.suse/kbuild-modpost-integrate-klp-convert.patch.
  - commit a756d33
  - KVM: Migrate kvm_vcpu_map() to kvm_follow_pfn() (jsc#PED-348).
  - commit d7f465b
  - modpost: convert do_usb_table() to a generic handler
    (git-fixes).
  - commit ecc46de
  - KVM: pfncache: Precisely track refcounted pages (jsc#PED-348).
  - commit 0aff3f5
  - modpost: convert do_of_table() to a generic handler
    (jsc#PED-10906).
  - commit d8f945d
  - KVM: Add kvm_release_page_unused() API to put pages that KVM
    never consumes (jsc#PED-348).
  - commit f3f2577
  - modpost: convert do_pnp_device_entry() to a generic handler
    (jsc#PED-10906).
  - commit af13ab1
  - modpost: convert do_pnp_card_entries() to a generic handler
    (jsc#PED-10906).
  - commit f180a34
  - modpost: call module_alias_printf() from all do_*_entry()
    functions (jsc#PED-10906).
  - commit e34cda7
  - modpost: pass (struct module *) to do_*_entry() functions
    (jsc#PED-10906).
  - commit cc012bd
  - KVM: Move kvm_{set,release}_page_{clean,dirty}() helpers up
    in kvm_main.c (jsc#PED-348).
  - commit 83af984
  - modpost: remove DEF_FIELD_ADDR_VAR() macro (jsc#PED-10906).
  - commit 90a6f96
  - KVM: Provide refcounted page as output field in struct
    kvm_follow_pfn (jsc#PED-348).
  - commit 20e080e
  - modpost: deduplicate MODULE_ALIAS() for all drivers
    (jsc#PED-10906).
  - commit 76f77e7
  - KVM: Use plain "struct page" pointer instead of single-entry
    array (jsc#PED-348).
  - commit 9282fe8
  - KVM: nVMX: Add helper to put (unmap) vmcs12 pages (jsc#PED-348).
  - commit b7b598e
  - modpost: introduce module_alias_printf() helper (jsc#PED-10906).
  - Refresh patches.suse/add-suse-supported-flag.patch.
  - Refresh
    patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch.
  - commit 272330b
  - KVM: nVMX: Drop pointless msr_bitmap_map field from struct
    nested_vmx (jsc#PED-348).
  - commit d39c536
  - modpost: remove unnecessary check in do_acpi_entry()
    (jsc#PED-10906).
  - commit a88bac3
  - KVM: nVMX: Rely on kvm_vcpu_unmap() to track validity of eVMCS
    mapping (jsc#PED-348).
  - commit 4f03277
  - KVM: Use NULL for struct page pointer to indicate mremapped
    memory (jsc#PED-348).
  - commit 8ec4686
  - KVM: Explicitly initialize all fields at the start of
    kvm_vcpu_map() (jsc#PED-348).
  - commit 0ee9c47
  - KVM: Remove pointless sanity check on @map param to
    kvm_vcpu_(un)map() (jsc#PED-348).
  - commit c5f3ebd
  - KVM: Introduce kvm_follow_pfn() to eventually replace
    "gfn_to_pfn" APIs (jsc#PED-348).
  - commit f0c102d
  - KVM: Drop unused "hva" pointer from __gfn_to_pfn_memslot()
    (jsc#PED-348).
  - commit fc13047
  - KVM: x86/mmu: Drop kvm_page_fault.hva, i.e. don't track
    intermediate hva (jsc#PED-348).
  - commit a75fb71
  - KVM: Replace "async" pointer in gfn=>pfn with "no_wait" and
    error code (jsc#PED-348).
  - commit 267c432
  - KVM: Drop extra GUP (via check_user_page_hwpoison()) to detect
    poisoned page (jsc#PED-348).
  - commit 17f0d93
  - KVM: Return ERR_SIGPENDING from hva_to_pfn() if GUP returns
  - EGAIN (jsc#PED-348).
  - commit 3b658f3
  - KVM: Annotate that all paths in hva_to_pfn() might sleep
    (jsc#PED-348).
  - commit edfdc02
  - KVM: Drop @atomic param from gfn=>pfn and hva=>pfn APIs
    (jsc#PED-348).
  - commit 8f753c1
  - KVM: Rename gfn_to_page_many_atomic() to kvm_prefetch_pages()
    (jsc#PED-348).
  - commit da09c4e
  - KVM: x86/mmu: Use gfn_to_page_many_atomic() when prefetching
    indirect PTEs (jsc#PED-348).
  - commit a2ea2a7
  - KVM: x86/mmu: Mark page/folio accessed only when zapping leaf
    SPTEs (jsc#PED-348).
  - commit 7d8ddfe
  - KVM: x86/mmu: Mark folio dirty when creating SPTE, not when
    zapping/modifying (jsc#PED-348).
  - commit 93e9c16
  - KVM: x86/mmu: Mark new SPTE as Accessed when synchronizing
    existing SPTE (jsc#PED-348).
  - commit 0710a89
  - KVM: x86/mmu: Invert @can_unsync and renamed to @synchronizing
    (jsc#PED-348).
  - commit 2af317d
  - KVM: x86/mmu: Don't overwrite shadow-present MMU SPTEs when
    prefaulting (jsc#PED-348).
  - commit cf029e8
  - KVM: x86/mmu: Skip the "try unsync" path iff the old SPTE was
    a leaf SPTE (jsc#PED-348).
  - commit 8176a7a
  - KVM: Allow calling kvm_release_page_{clean,dirty}() on a NULL
    page pointer (jsc#PED-348).
  - commit dae8f22
  - KVM: Drop KVM_ERR_PTR_BAD_PAGE and instead return NULL to
    indicate an error (jsc#PED-348).
  - commit 7c4b876
  - KVM: arm64: nvhe: Pass through PSCI v1.3 SYSTEM_OFF2 call
    (jsc#PED-348).
  - commit 932dd19
  - KVM: arm64: Add support for PSCI v1.2 and v1.3 (jsc#PED-348).
  - commit f451559
  - KVM: arm64: Add PSCI v1.3 SYSTEM_OFF2 function for hibernation
    (jsc#PED-348).
  - commit 6c5d08c
  - firmware/psci: Add definitions for PSCI v1.3 specification
    (jsc#PED-348).
  - commit d3ca0ff
  - RDMA/bnxt_re: Remove unusable nq variable (git-fixes)
  - commit 047a720
  - KVM: arm64: Don't map 'kvm_vgic_global_state' at EL2 with pKVM
    (jsc#PED-348).
  - commit b6ff591
  - KVM: arm64: Just advertise SEIS as 0 when emulating ICC_CTLR_EL1
    (jsc#PED-348).
  - commit fa5285c
  - selftest/bpf: Add vsock test for sockmap rejecting unconnected
    (bsc#1239470 CVE-2025-21854).
  - commit 6e36f6b
  - selftest/bpf: Adapt vsock_delete_on_close to sockmap rejecting
    unconnected (bsc#1239470 CVE-2025-21854).
  - sockmap, vsock: For connectible sockets allow only connected
    (bsc#1239470 CVE-2025-21854).
  - selftest/bpf: Add test for vsock removal from sockmap on close()
    (bsc#1239470 CVE-2025-21854).
  - selftest/bpf: Add test for af_vsock poll() (bsc#1239470
    CVE-2025-21854).
  - commit 750fb4b
  - RDMA/core: Silence oversized kvmalloc() warning (git-fixes)
  - commit b40a0b3
  - RDMA/cma: Fix workqueue crash in cma_netevent_work_handler (git-fixes)
  - commit 1195add
  - RDMA/hns: Fix wrong maximum DMA segment size (git-fixes)
  - commit 10442e4
  - RDMA/usnic: Fix passing zero to PTR_ERR in usnic_ib_pci_probe() (git-fixes)
  - commit a0ae514
  - RDMA/bnxt_re: Fix budget handling of notification queue (git-fixes)
  - commit 4f16ca1
  - selftests/net: Add test for loading devbound XDP program in
    generic mode (bsc#1238742 CVE-2025-21808).
  - net: xdp: Disallow attaching device-bound programs in generic
    mode (bsc#1238742 CVE-2025-21808).
  - commit 461e3db
  - Update
    patches.suse/md-md-bitmap-fix-wrong-bitmap_limit-for-clustermd-wh.patch
    (bsc#1238212).
  - commit 43028e5

++++ alsa:

  - Update to alsa-lib 1.2.14:
    * Disable and delete alsalisp code
    * include: prefer alsa/asoundlib.h for apps, dependency cleanups
    * seq: Define new events for UMP EP/FB change notifications
    * control: remap improvements
    * pcm: tstamp mode fixes
    * rawmidi: ump fixes and tied device flag extensions
    * seq: fix UMP handling and other minot fixes
    * ucm: add sys-card substitution, etc
    * test/playmidi1: fix compilation caused by conflict between midifile.h and ump_msg.h
    For details, see:
    https://www.alsa-project.org/wiki/Changes_v1.2.13_v1.2.14#alsa-lib
  - Drop obsoleted patches:
    0001-src-Versions.in.in-Update-_tempo_base-name.patch
    0002-configure-Make-sequencer-dependent-on-rawmidi.patch
    0003-seq-include-UMP-headers.patch

++++ leancrypto:

  - added keyring, https://leancrypto.org/about/smuellerDD-2024.asc
  - adjust license to BSD-3-clause

++++ lvm2:

  - LVM filter behaves unexpectedly for MPIO devices in SLES15SP5 (bsc#1216938)
    * set lvm.conf devices.multipath_wwids_file=""

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.144 (boo#1241231)

++++ read-only-root-fs:

  - Update to version 1.0+git20250415.7e7aea4:
    * Add missing dependency on mountpoint
  - Add missing dependencies for %post

------------------------------------------------------------------
------------------  2025-4-14  -  Apr 14 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - bpf: Fix deadlock when freeing cgroup storage (CVE-2024-58088 bsc#1239510)
  - commit 16371d9
  - dpll: fix xa_alloc_cyclic() error handling (CVE-2025-22016 bsc#1240934)
  - commit cc084a2
  - devlink: fix xa_alloc_cyclic() error handling (CVE-2025-22017 bsc#1240936)
  - commit 768ef0a
  - caif_virtio: fix wrong pointer check in cfv_probe()
    (CVE-2025-21904 bsc#1240576).
  - commit 3c0bb89
  - tools/power turbostat: report CoreThr per measurement interval
    (git-fixes).
  - commit f32d7c3
  - cgroup/cpuset: Fix error handling in remote_partition_disable()
    (bsc#1241166).
  - cgroup/cpuset: Fix incorrect isolated_cpus update in
    update_parent_effective_cpumask() (bsc#1241166).
  - cgroup/cpuset: Fix spelling errors in file
    kernel/cgroup/cpuset.c (bsc#1241166).
  - commit 9c766ef
  - Update config files.
  - Disabled CONFIG_SYSFS_SYSCALL (jsc#PED-12651)
  - Had to enable CONFIG_EXPERT for config/s390x/zfcpdump to expose
    CONFIG_SYSFS_SYSCALL. The rest of new options exposed by CONFIG_EXPERT
    were set to match the other configs.
  - commit 7bd5ed3
  - arm64: realm: Use aliased addresses for device DMA to shared
    buffers (jsc#PED-11786).
  - commit e3877ff
  - dma: Introduce generic dma_addr_*crypted helpers
    (jsc#PED-11786).
  - commit 5d1c551
  - dma: Fix encryption bit clearing for dma_to_phys
    (jsc#PED-11786).
  - commit dd8af28
  - virt: sev-guest: Allocate request data dynamically
    (jsc#PED-348).
  - commit e63518a
  - Update config files.
  - supported.conf: add drivers/virt/coco/arm-cca-guest/arm-cca-guest
  - commit 758e23b
  - patches.suse/arm64-Document-Arm-Confidential-Compute.patch:
    (jsc#PED-11786).
  - commit 4c3c801
  - Update config files.
  - supported.conf: add lib/crypto/libaesgcm (needed for SEV guests)
  - commit 989f69b
  - supported.conf: Mark Intel ivpu accel driver as supported (jsc#PED-10529 jsc#PED-10738)
  - commit d6a0ec5
  - RDMA/mana_ib: Ensure variable err is initialized (git-fixes).
  - commit c0a5353
  - wifi: ath11k: update channel list in worker when wait flag is
    set (bsc#1241134).
  - commit 7612236

++++ kernel-rt:

  - bpf: Fix deadlock when freeing cgroup storage (CVE-2024-58088 bsc#1239510)
  - commit 16371d9
  - dpll: fix xa_alloc_cyclic() error handling (CVE-2025-22016 bsc#1240934)
  - commit cc084a2
  - devlink: fix xa_alloc_cyclic() error handling (CVE-2025-22017 bsc#1240936)
  - commit 768ef0a
  - caif_virtio: fix wrong pointer check in cfv_probe()
    (CVE-2025-21904 bsc#1240576).
  - commit 3c0bb89
  - tools/power turbostat: report CoreThr per measurement interval
    (git-fixes).
  - commit f32d7c3
  - cgroup/cpuset: Fix error handling in remote_partition_disable()
    (bsc#1241166).
  - cgroup/cpuset: Fix incorrect isolated_cpus update in
    update_parent_effective_cpumask() (bsc#1241166).
  - cgroup/cpuset: Fix spelling errors in file
    kernel/cgroup/cpuset.c (bsc#1241166).
  - commit 9c766ef
  - Update config files.
  - Disabled CONFIG_SYSFS_SYSCALL (jsc#PED-12651)
  - Had to enable CONFIG_EXPERT for config/s390x/zfcpdump to expose
    CONFIG_SYSFS_SYSCALL. The rest of new options exposed by CONFIG_EXPERT
    were set to match the other configs.
  - commit 7bd5ed3
  - arm64: realm: Use aliased addresses for device DMA to shared
    buffers (jsc#PED-11786).
  - commit e3877ff
  - dma: Introduce generic dma_addr_*crypted helpers
    (jsc#PED-11786).
  - commit 5d1c551
  - dma: Fix encryption bit clearing for dma_to_phys
    (jsc#PED-11786).
  - commit dd8af28
  - virt: sev-guest: Allocate request data dynamically
    (jsc#PED-348).
  - commit e63518a
  - Update config files.
  - supported.conf: add drivers/virt/coco/arm-cca-guest/arm-cca-guest
  - commit 758e23b
  - patches.suse/arm64-Document-Arm-Confidential-Compute.patch:
    (jsc#PED-11786).
  - commit 4c3c801
  - Update config files.
  - supported.conf: add lib/crypto/libaesgcm (needed for SEV guests)
  - commit 989f69b
  - supported.conf: Mark Intel ivpu accel driver as supported (jsc#PED-10529 jsc#PED-10738)
  - commit d6a0ec5
  - RDMA/mana_ib: Ensure variable err is initialized (git-fixes).
  - commit c0a5353
  - wifi: ath11k: update channel list in worker when wait flag is
    set (bsc#1241134).
  - commit 7612236

++++ ncurses:

  - Add ncurses patch 20250412
    + add pangoterm -TD
    + add kf1 to kf5 to sclp (report by Werner Fink)
    + add vt100+pf1-pf4 -TD
  - Modify patch ncurses-5.9-ibm327x.dif
    * Skip the further entry as now aprt of the common `sclp' entry
    * Add ansi.sys entry to ibm327x for coloring support

++++ nftables:

  - Update to release 1.1.2
    * Allow for expressing protocol dependency on sets.
    * Support for more advanced bitwise operations with statements.
    * Set element auto-merge now skips elements with
    timeout/expiration.
    * Memory footprint reduction for set elements.
    * Updated `nft monitor` to report flowtable events.
    * Support for merging bitmask matching in set/map with
  - o/--optimize.
    * Improved MPTCP support with symbol table for subtypes.

++++ libnftnl:

  - Update to release 1.2.9
    * Added support for kernel space AND, OR and XOR operations (for
    Linux kernel >= 6.13)
    * Fix ct id being printed as "unknown" key

++++ perl:

  - update to 5.40.2
    * fix heap buffer overflow with tr// [bsc#1241083] [CVE-2024-56406]

++++ python-lxml:

  - update to 5.3.2 (bsc#1237370, CVE-2025-24928):
    * This release resolves CVE-2025-24928 as described in
    * https://gitlab.gnome.org/GNOME/libxml2/-/issues/847
    * GH#440: Some tests were adapted for libxml2 2.14.0.
    * LP#2097175: ``DTD(external_id="…")`` erroneously required a
    byte string as ID value.
    * GH#450: ``iterparse()`` internally triggered the
    `DeprecationWarning`` added in lxml 5.3.0 when parsing HTML.

++++ read-only-root-fs:

  - Update to version 1.0+git20250414.6ef7163:
    * Add a note why we need to keep 10-read-only-root-fs.conf around
    * Migrate from /etc overlays to subvolumes
  - Switch _service to use mode="manual"

++++ update-alternatives:

  - Update to version 1.22.18.
    The full changelog is very large. Please check it here:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.18
  - Changes from 1.22.17:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.17
  - Changes from 1.22.16:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.16
  - Changes from 1.22.15:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.15
  - Changes from 1.22.14:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.14
  - Changes from 1.22.13:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.13
  - Changes from 1.22.12:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.12
  - Refresh patch:
    * openssl.patch

++++ virt-manager:

  - Spec file changes for including the correct dependencies
    depending on the distro. (bsc#1241082 and bsc#1241119)

------------------------------------------------------------------
------------------  2025-4-13  -  Apr 13 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix bundle extension for container types
    When building result files that use container types like oci or docker,
    kiwi creates them as archive tarballs with an extension prefix to
    indicate the special nature of the archive. However, the bundler
    code does not retain the prefix, which results in the wrong file
    extension for these archives.
    This change adds exceptions for these types and refactors the
    exception handling to unify it with the Vagrant image filename
    handling, which operates similarly.
    Fixes: https://github.com/OSInside/kiwi/issues/2628

++++ grub2:

  - add grub2-string-initializer.patch, part of upstream gnulib
    patch, to fix gcc15 compile time error (bsc#1239884)

++++ kernel-default:

  - pwm: fsl-ftm: Handle clk_get_rate() returning 0 (git-fixes).
  - pwm: rcar: Improve register calculation (git-fixes).
  - pwm: mediatek: Prevent divide-by-zero in pwm_mediatek_config()
    (git-fixes).
  - commit ef3f359

++++ kernel-rt:

  - pwm: fsl-ftm: Handle clk_get_rate() returning 0 (git-fixes).
  - pwm: rcar: Improve register calculation (git-fixes).
  - pwm: mediatek: Prevent divide-by-zero in pwm_mediatek_config()
    (git-fixes).
  - commit ef3f359

++++ libgcrypt:

  - Differentiate use of SHA1 in the service level indicator [jsc#PED-12227]
    * Include upstream SLI revamp and fips certification fixes
    * Add patches:
  - libgcrypt-fips-Introduce-an-internal-API-for-FIPS-service-indicator.patch
  - libgcrypt-fips-Introduce-GCRYCTL_FIPS_SERVICE_INDICATOR-and-the-macro.patch
  - libgcrypt-fips-kdf-Implement-new-FIPS-service-indicator-for-gcry_kdf_derive.patch
  - libgcrypt-fips-md-Implement-new-FIPS-service-indicator-for-gcry_md_hash_.patch
  - libgcrypt-fips-tests-Add-t-digest.patch
  - libgcrypt-fips-Change-the-internal-API-for-new-FIPS-service-indicator.patch
  - libgcrypt-fips-md-Implement-new-FIPS-service-indicator-for-gcry_md_open-API.patch
  - libgcrypt-fips-tests-Add-tests-for-md_open-write-read-close-for-t-digest.patch
  - libgcrypt-fips-mac-Implement-new-FIPS-service-indicator-for-gcry_mac_open.patch
  - libgcrypt-fips-cipher-Implement-new-FIPS-service-indicator-for-cipher_open.patch
  - libgcrypt-tests-fips-Add-gcry_mac_open-tests.patch
  - libgcrypt-tests-fips-Rename-t-fips-service-ind.patch
  - libgcrypt-tests-fips-Move-KDF-tests-to-t-fips-service-ind.patch
  - libgcrypt-tests-fips-Add-gcry_cipher_open-tests.patch
  - libgcrypt-fips-md-gcry_md_copy-should-care-about-FIPS-service-indicator.patch
  - libgcrypt-fips-cipher-Implement-FIPS-service-indicator-for-gcry_pk_hash_-API.patch
  - libgcrypt-fips-Introduce-GCRYCTL_FIPS_REJECT_NON_FIPS.patch
  - libgcrypt-Fix-the-previous-change.patch
  - libgcrypt-fips-Rejection-by-GCRYCTL_FIPS_REJECT_NON_FIPS-not-by-open-flags.patch
  - libgcrypt-fips-cipher-Add-behavior-not-to-reject-but-mark-non-compliant.patch
  - libgcrypt-fips-ecc-Add-rejecting-or-marking-for-gcry_pk_get_curve.patch
  - libgcrypt-tests-Add-more-tests-to-tests-t-fips-service-ind.patch
  - libgcrypt-fips-ecc-Check-DATA-in-gcry_pk_sign-verify-in-FIPS-mode.patch
  - libgcrypt-fips-cipher-Fix-memory-leak-for-gcry_pk_hash_sign.patch
  - libgcrypt-build-Improve-__thread-specifier-check.patch
  - libgcrypt-cipher-Check-and-mark-non-compliant-cipher-modes-in-the-SLI.patch
  - libgcrypt-cipher-Rename-_gcry_cipher_is_mode_fips_compliant.patch
  - libgcrypt-cipher-Don-t-differentiate-GCRY_CIPHER_MODE_CMAC-in-FIPS-mode.patch
  - libgcrypt-cipher-rsa-Mark-reject-SHA1-unknown-with-RSA-signature-generation.patch
  - libgcrypt-md-Fix-gcry_md_algo_info-to-mark-reject-under-FIPS-mode.patch
  - libgcrypt-md-Use-check_digest_algo_spec-in-_gcry_md_selftest.patch
  - libgcrypt-tests-Update-t-fips-service-ind-using-GCRY_MD_SHA256-for-KDF-tests.patch
  - libgcrypt-fips-cipher-Do-the-computation-when-marking-non-compliant.patch
  - libgcrypt-tests-Allow-tests-with-USE_RSA.patch
  - libgcrypt-cipher-Add-KAT-for-non-rfc6979-ECDSA-with-fixed-k.patch
  - libgcrypt-cipher-Differentiate-use-of-label-K-in-the-SLI.patch
  - libgcrypt-cipher-Differentiate-igninvflag-in-the-SLI.patch
  - libgcrypt-cipher-Differentiate-no-blinding-flag-in-the-SLI.patch
  - libgcrypt-fips-cipher-Add-GCRY_FIPS_FLAG_REJECT_PK_FLAGS.patch
  - libgcrypt-cipher-ecc-Fix-for-supplied-K.patch
  - libgcrypt-cipher-visibility-Differentiate-use-of-random-override-in-the-SLI.patch
  - libgcrypt-cipher-fips-Fix-for-random-override.patch
  - libgcrypt-md-Make-SHA-1-non-FIPS-internally-for-1.12-API.patch
  - libgcrypt-fips-Fix-GCRY_FIPS_FLAG_REJECT_MD.patch
  - libgcrypt-doc-Add-about-GCRYCTL_FIPS_SERVICE_INDICATOR.patch
  - libgcrypt-doc-Fix-syntax-error.patch
    * Rebase patches:
  - libgcrypt-FIPS-SLI-kdf-leylength.patch

------------------------------------------------------------------
------------------  2025-4-12  -  Apr 12 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Fix error in "probe libc's inet_pton & backtrace" perf test
    perf test record+probe_libc_inet_pton: Make test resilient
    (git-fixes).
  - commit ad50bb0
  - perf bpf-filter: Fix a parsing error with comma (git-fixes).
  - perf tools: Fix is_compat_mode build break in ppc64 (git-fixes).
  - perf vendor events arm64 AmpereOneX: Fix frontend_bound
    calculation (git-fixes).
  - perf pmu: Handle memory failure in tool_pmu__new() (git-fixes).
  - perf: intel-tpebs: Fix incorrect usage of zfree() (git-fixes).
  - perf dso: fix dso__is_kallsyms() check (git-fixes).
  - perf python: Check if there is space to copy all the event
    (git-fixes).
  - perf python: Don't keep a raw_data pointer to consumed ring
    buffer space (git-fixes).
  - perf python: Decrement the refcount of just created event on
    failure (git-fixes).
  - perf python: Fixup description of sample.id event member
    (git-fixes).
  - perf test stat_all_pmu.sh: Correctly check 'perf stat' result
    (git-fixes).
  - perf units: Fix insufficient array space (git-fixes).
  - perf x86/topdown: Fix topdown leader sampling test error on
    hybrid (git-fixes).
  - perf evlist: Add success path to evlist__create_syswide_maps
    (git-fixes).
  - perf debug: Avoid stack overflow in recursive error message
    (git-fixes).
  - perf tests: Fix data symbol test with LTO builds (git-fixes).
  - perf bench: Fix perf bench syscall loop count (git-fixes).
  - perf test: Add timeout to datasym workload (git-fixes).
  - perf arm-spe: Fix load-store operation checking (git-fixes).
  - perf build: Fix in-tree build due to symbolic link (git-fixes).
  - perf pmu: Don't double count common sysfs and json events
    (git-fixes).
  - perf pmu: Dynamically allocate tool PMU (git-fixes).
  - perf report: Fix input reload/switch with symbol sort key
    (git-fixes).
  - perf report: Switch data file correctly in TUI (git-fixes).
  - perf tests: Fix Tool PMU test segfault (git-fixes).
  - perf tools: Add skip check in tool_pmu__event_to_str()
    (git-fixes).
  - perf stat: Don't merge counters purely on name (git-fixes).
  - perf pmu: Rename name matching for no suffix or wildcard
    variants (git-fixes).
  - perf pmus: Restructure pmu_read_sysfs to scan fewer PMUs
    (git-fixes).
  - perf test: Fix Hwmon PMU test endianess issue (git-fixes).
  - perf: Always feature test reallocarray (git-fixes).
  - perf stat: Fix find_stat for mixed legacy/non-legacy events
    (git-fixes).
  - tools: Unify top-level quiet infrastructure (git-fixes).
  - perf test: Skip syscall enum test if no landlock syscall
    (git-fixes).
  - perf trace: Fix runtime error of index out of bounds
    (git-fixes).
  - perf trace: Fix BPF loading failure (-E2BIG) (git-fixes).
  - perf bench: Fix undefined behavior in cmpworker() (git-fixes).
  - perf lock: Add percpu-rwsem for type filter (git-fixes).
  - perf lock: Fix parse_lock_type which only retrieve one lock flag
    (git-fixes).
  - perf tools: Expose quiet/verbose variables in Makefile.perf
    (git-fixes).
  - perf inject: Fix use without initialization of local variables
    (git-fixes).
  - perf report: Fix misleading help message about --demangle
    (git-fixes).
  - perf MANIFEST: Add arch/*/include/uapi/asm/bpf_perf_event.h
    to the perf tarball (git-fixes).
  - perf namespaces: Fixup the nsinfo__in_pidns() return type,
    its bool (git-fixes).
  - perf namespaces: Introduce nsinfo__set_in_pidns() (git-fixes).
  - perf machine: Don't ignore _etext when not a text symbol
    (git-fixes).
  - perf maps: Fix display of kernel symbols (git-fixes).
  - perf top: Don't complain about lack of vmlinux when not
    resolving some kernel samples (git-fixes).
  - perf intel-pt: Add a test for pause / resume (jsc#PED-10651).
  - perf intel-pt: Add documentation for pause / resume
    (jsc#PED-10651).
  - perf intel-pt: Improve man page format (jsc#PED-10651).
  - perf tools: Add missing_features for aux_start_paused,
    aux_pause, aux_resume (jsc#PED-10651).
  - perf tools: Parse aux-action (jsc#PED-10651).
  - perf tools: Add aux-action config term (jsc#PED-10651).
  - perf tools: Add aux_start_paused, aux_pause and aux_resume
    (jsc#PED-10651).
  - perf expr: Initialize is_test value in expr__ctx_new()
    (git-fixes).
  - perf bpf: Fix two memory leakages when calling
    perf_env__insert_bpf_prog_info() (git-fixes).
  - perf header: Fix one memory leakage in process_bpf_prog_info()
    (git-fixes).
  - perf header: Fix one memory leakage in process_bpf_btf()
    (git-fixes).
  - perf arm-spe: Prepare for adding data source packet
    implementations for other cores (git-fixes).
  - tools headers: Sync uapi/linux/perf_event.h with the kernel
    sources (jsc#PED-10651).
  - commit 16d8625
  - ata: sata_sx4: Add error handling in pdc20621_i2c_read()
    (git-fixes).
  - ata: pata_pxa: Fix potential NULL pointer dereference in
    pxa_ata_probe() (git-fixes).
  - APEI: GHES: Have GHES honor the panic= setting (stable-fixes).
  - commit 2c30291

++++ kernel-rt:

  - Fix error in "probe libc's inet_pton & backtrace" perf test
    perf test record+probe_libc_inet_pton: Make test resilient
    (git-fixes).
  - commit ad50bb0
  - perf bpf-filter: Fix a parsing error with comma (git-fixes).
  - perf tools: Fix is_compat_mode build break in ppc64 (git-fixes).
  - perf vendor events arm64 AmpereOneX: Fix frontend_bound
    calculation (git-fixes).
  - perf pmu: Handle memory failure in tool_pmu__new() (git-fixes).
  - perf: intel-tpebs: Fix incorrect usage of zfree() (git-fixes).
  - perf dso: fix dso__is_kallsyms() check (git-fixes).
  - perf python: Check if there is space to copy all the event
    (git-fixes).
  - perf python: Don't keep a raw_data pointer to consumed ring
    buffer space (git-fixes).
  - perf python: Decrement the refcount of just created event on
    failure (git-fixes).
  - perf python: Fixup description of sample.id event member
    (git-fixes).
  - perf test stat_all_pmu.sh: Correctly check 'perf stat' result
    (git-fixes).
  - perf units: Fix insufficient array space (git-fixes).
  - perf x86/topdown: Fix topdown leader sampling test error on
    hybrid (git-fixes).
  - perf evlist: Add success path to evlist__create_syswide_maps
    (git-fixes).
  - perf debug: Avoid stack overflow in recursive error message
    (git-fixes).
  - perf tests: Fix data symbol test with LTO builds (git-fixes).
  - perf bench: Fix perf bench syscall loop count (git-fixes).
  - perf test: Add timeout to datasym workload (git-fixes).
  - perf arm-spe: Fix load-store operation checking (git-fixes).
  - perf build: Fix in-tree build due to symbolic link (git-fixes).
  - perf pmu: Don't double count common sysfs and json events
    (git-fixes).
  - perf pmu: Dynamically allocate tool PMU (git-fixes).
  - perf report: Fix input reload/switch with symbol sort key
    (git-fixes).
  - perf report: Switch data file correctly in TUI (git-fixes).
  - perf tests: Fix Tool PMU test segfault (git-fixes).
  - perf tools: Add skip check in tool_pmu__event_to_str()
    (git-fixes).
  - perf stat: Don't merge counters purely on name (git-fixes).
  - perf pmu: Rename name matching for no suffix or wildcard
    variants (git-fixes).
  - perf pmus: Restructure pmu_read_sysfs to scan fewer PMUs
    (git-fixes).
  - perf test: Fix Hwmon PMU test endianess issue (git-fixes).
  - perf: Always feature test reallocarray (git-fixes).
  - perf stat: Fix find_stat for mixed legacy/non-legacy events
    (git-fixes).
  - tools: Unify top-level quiet infrastructure (git-fixes).
  - perf test: Skip syscall enum test if no landlock syscall
    (git-fixes).
  - perf trace: Fix runtime error of index out of bounds
    (git-fixes).
  - perf trace: Fix BPF loading failure (-E2BIG) (git-fixes).
  - perf bench: Fix undefined behavior in cmpworker() (git-fixes).
  - perf lock: Add percpu-rwsem for type filter (git-fixes).
  - perf lock: Fix parse_lock_type which only retrieve one lock flag
    (git-fixes).
  - perf tools: Expose quiet/verbose variables in Makefile.perf
    (git-fixes).
  - perf inject: Fix use without initialization of local variables
    (git-fixes).
  - perf report: Fix misleading help message about --demangle
    (git-fixes).
  - perf MANIFEST: Add arch/*/include/uapi/asm/bpf_perf_event.h
    to the perf tarball (git-fixes).
  - perf namespaces: Fixup the nsinfo__in_pidns() return type,
    its bool (git-fixes).
  - perf namespaces: Introduce nsinfo__set_in_pidns() (git-fixes).
  - perf machine: Don't ignore _etext when not a text symbol
    (git-fixes).
  - perf maps: Fix display of kernel symbols (git-fixes).
  - perf top: Don't complain about lack of vmlinux when not
    resolving some kernel samples (git-fixes).
  - perf intel-pt: Add a test for pause / resume (jsc#PED-10651).
  - perf intel-pt: Add documentation for pause / resume
    (jsc#PED-10651).
  - perf intel-pt: Improve man page format (jsc#PED-10651).
  - perf tools: Add missing_features for aux_start_paused,
    aux_pause, aux_resume (jsc#PED-10651).
  - perf tools: Parse aux-action (jsc#PED-10651).
  - perf tools: Add aux-action config term (jsc#PED-10651).
  - perf tools: Add aux_start_paused, aux_pause and aux_resume
    (jsc#PED-10651).
  - perf expr: Initialize is_test value in expr__ctx_new()
    (git-fixes).
  - perf bpf: Fix two memory leakages when calling
    perf_env__insert_bpf_prog_info() (git-fixes).
  - perf header: Fix one memory leakage in process_bpf_prog_info()
    (git-fixes).
  - perf header: Fix one memory leakage in process_bpf_btf()
    (git-fixes).
  - perf arm-spe: Prepare for adding data source packet
    implementations for other cores (git-fixes).
  - tools headers: Sync uapi/linux/perf_event.h with the kernel
    sources (jsc#PED-10651).
  - commit 16d8625
  - ata: sata_sx4: Add error handling in pdc20621_i2c_read()
    (git-fixes).
  - ata: pata_pxa: Fix potential NULL pointer dereference in
    pxa_ata_probe() (git-fixes).
  - APEI: GHES: Have GHES honor the panic= setting (stable-fixes).
  - commit 2c30291

++++ gcc15:

  - Add loongarch64 to quadmath_arch

------------------------------------------------------------------
------------------  2025-4-11  -  Apr 11 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Use rpm-config-SUSE instead of suse-module-tools for suse version
    above 1550 and add code for the missing macros for older
    distributions like leap 15.6

++++ ca-certificates-mozilla:

  - reenable the distrusted certs again. the distrust is only for certs
    issued after the distrust date, not for all certs of a CA.
    remove: remove-distrusted.patch

++++ cockpit:

  - Add a requires for either sudo or polkit for assuming admin rights
    (bsc#1240569)

++++ curl:

  - fix Leap build add curl-8.13.0-CloseSocket.patch

++++ diffutils:

  - diffutils 3.12:
    * diff -r no longer merely summarizes when comparing an empty
    regular file to a nonempty regular file.
    * diff -y no longer crashes when given nontrivial differences
  - drop diff-fix-allocation-typo-leading-to-crashes.patch

++++ python-kiwi:

  - Update LOADER_TYPE setup for grub
    If the bootloader attribute: bls is set to true, make sure
    the LOADER_TYPE changes to grub2-bls. This is related to
    Issue #2773

++++ fwupd:

  - Update to version 2.0.8:
    + This release adds the following features:
  - Add the updated UEFI db as a new HSI attribute
  - Add two new plugins that can update the UEFI Signature Database and KEK
    + This release fixes the following bugs:
  - Add /sys/firmware/efi/efivars to ReadWritePaths
  - Avoid any DPAUX IO if the BnR DPCD does not match
  - Be more careful falling back to older emulation versions
  - Detect the Firehose protocol features if not automatically sent
  - Do not match SMC Redfish method on non-Supermicro hardware
  - Do not show prompts or messages in --json mode
  - Fix a critical warning when enumerating DTH135K0C
  - Make the EFI LOADOPT either a path or ShimHive when setting metadata
  - Match lowercase directory names when checking for ESP
  - Only allow UEFI capsule updates on UEFI-capable architectures
  - Set the version format when using fwupdtool install offline
  - Support segment value 0 in the ccgx-dmc image parser

++++ grub2:

  - Measure the envblk used by pre_loadenv
    * 0001-prep_loadenv-Measure-the-environment-block-into-PCR-.patch
  - Enable PowerPC 64 support for tss2 and tpm2_key_protector
    * 0001-tpm2_key_protector-Add-grub-emu-support.patch
    * 0001-tss2-Adjust-bit-fields-for-big-endian-targets.patch
    * 0002-term-ieee1275-serial-Cast-0-to-proper-type.patch
    * 0003-ieee1275-Consolidate-repeated-definitions-of-IEEE127.patch
    * 0004-ieee1275-ibmvpm-Move-TPM-initialization-functions-to.patch
    * 0005-ieee1275-tcg2-Refactor-grub_ieee1275_tpm_init.patch
    * 0006-ieee1275-tcg2-Add-TCG2-driver-for-ieee1275-PowerPC-f.patch
    * 0007-tpm2_key_protector-Enable-build-for-powerpc_ieee1275.patch
  - Dump PCRs when TPM unsealing fails
    * 0001-tpm2_key_protector-Dump-PCRs-on-policy-fail.patch
    * 0002-tpm2_key_protector-Add-tpm2_dump_pcr-command.patch
  - Add 'NV index' handle support to tpm2_key_protector
    * 0003-tss2-Fix-the-missing-authCommand.patch
    * 0004-tss2-Add-TPM-2.0-NV-index-commands.patch
    * 0005-tpm2_key_protector-Unseal-key-from-a-buffer.patch
    * 0006-tpm2_key_protector-Support-NV-index-handles.patch
    * 0007-util-grub-protect-Support-NV-index-mode.patch

++++ kernel-default:

  - config: Disable CONFIG_LATENCYTOP (jsc#PED-12529)
  - commit c5b32c4
  - s390/cpumf: Fix double free on error in cpumf_pmu_event_init()
    (git-fixes).
  - commit b32df18
  - Update config files: CONFIG_LAN966X_OIC and co are dropped
  - commit 32dd855
  - virt: arm-cca-guest: TSM_REPORT support for realms
    (jsc#PED-11786).
  - commit c5ab2be
  - arm64: Enable memory encrypt for Realms (jsc#PED-11786).
  - commit 3213422
  - arm64: mm: Avoid TLBI when marking pages as valid
    (jsc#PED-11786).
  - commit eecca06
  - arm64: Enforce bounce buffers for realm DMA (jsc#PED-11786).
  - commit b10d721
  - efi: arm64: Map Device with Prot Shared (jsc#PED-11786).
  - commit aefd90e
  - arm64: rsi: Map unprotected MMIO as decrypted (jsc#PED-11786).
  - commit ce08db2
  - arm64: rsi: Add support for checking whether an MMIO is
    protected (jsc#PED-11786).
  - commit 442a9ae
  - arm64: realm: Query IPA size from the RMM (jsc#PED-11786).
  - commit 9a064e4
  - arm64: Detect if in a realm and set RIPAS RAM (jsc#PED-11786).
  - commit e4b4ff0
  - arm64: rsi: Add RSI definitions (jsc#PED-11786).
  - commit 9e7e749
  - s390: Fix various typos (jsc#PED-348).
  - commit ae11616
  - RISC-V: KVM: Allow Smnpm and Ssnpm extensions for guests
    (jsc#PED-348).
  - commit 5fc44fd
  - virt: sev-guest: Carve out SNP message context structure
    (jsc#PED-348).
  - commit 9276b20
  - virt: sev-guest: Reduce the scope of SNP command mutex
    (jsc#PED-348).
  - commit 72f46bd
  - virt: sev-guest: Consolidate SNP guest messaging parameters
    to a struct (jsc#PED-348).
  - commit e467c7c
  - x86/sev: Cache the secrets page address (jsc#PED-348).
  - commit d373d20
  - Update
    patches.suse/Bluetooth-Add-check-for-mgmt_alloc_skb-in-mgmt_devic.patch
    (git-fixes CVE-2025-21936 bsc#1240716).
  - Update
    patches.suse/Bluetooth-Add-check-for-mgmt_alloc_skb-in-mgmt_remot.patch
    (git-fixes CVE-2025-21937 bsc#1240643).
  - Update
    patches.suse/Bluetooth-Fix-error-code-in-chan_alloc_skb_cb.patch
    (git-fixes CVE-2025-22007 bsc#1240829).
  - Update
    patches.suse/HID-appleir-Fix-potential-NULL-dereference-at-raw-ev.patch
    (git-fixes CVE-2025-21948 bsc#1240703).
  - Update
    patches.suse/HID-hid-steam-Fix-use-after-free-when-detaching-devi.patch
    (git-fixes CVE-2025-21923 bsc#1240691).
  - Update
    patches.suse/HID-intel-ish-hid-Fix-use-after-free-issue-in-hid_is.patch
    (git-fixes CVE-2025-21929 bsc#1240711).
  - Update
    patches.suse/HID-intel-ish-hid-Fix-use-after-free-issue-in-ishtp_.patch
    (git-fixes CVE-2025-21928 bsc#1240722).
  - Update
    patches.suse/KVM-arm64-Unconditionally-save-flush-host-FPSIMD-SVE-SME-state.patch
    (git-fixes CVE-2025-22013 bsc#1240938).
  - Update
    patches.suse/NFSv4-Fix-a-deadlock-when-recovering-state-on-a-sillyrenamed-file.patch
    (git-fixes CVE-2025-21900 bsc#1240578).
  - Update
    patches.suse/RDMA-bnxt_re-Add-sanity-checks-on-rdev-validity.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21901 bsc#1240579).
  - Update
    patches.suse/RDMA-hns-Fix-soft-lockup-during-bt-pages-loop.patch
    (git-fixes CVE-2025-22010 bsc#1240943).
  - Update
    patches.suse/accel-qaic-Fix-integer-overflow-in-qaic_validate_req.patch
    (git-fixes CVE-2025-22001 bsc#1240873).
  - Update
    patches.suse/acpi-typec-ucsi-Introduce-a-poll_cci-method.patch
    (git-fixes CVE-2025-21902 bsc#1240599).
  - Update
    patches.suse/bus-mhi-host-pci_generic-Use-pci_try_reset_function-.patch
    (git-fixes CVE-2025-21951 bsc#1240718).
  - Update
    patches.suse/can-ucan-fix-out-of-bound-read-in-strscpy-source.patch
    (git-fixes CVE-2025-22003 bsc#1240825).
  - Update
    patches.suse/cdx-Fix-possible-UAF-error-in-driver_override_show.patch
    (git-fixes CVE-2025-21915 bsc#1240594).
  - Update
    patches.suse/dm-flakey-Fix-memory-corruption-in-optional-corrupt_.patch
    (git-fixes CVE-2025-21966 bsc#1240779).
  - Update
    patches.suse/drivers-virt-acrn-hsm-Use-kzalloc-to-avoid-info-leak.patch
    (git-fixes CVE-2025-21950 bsc#1240719).
  - Update
    patches.suse/drm-amd-display-Assign-normalized_pix_clk-when-color.patch
    (stable-fixes CVE-2025-21956 bsc#1240739).
  - Update
    patches.suse/drm-amd-display-Fix-null-check-for-pipe_ctx-plane_st-374c9fa.patch
    (git-fixes CVE-2025-21941 bsc#1240701).
  - Update
    patches.suse/drm-amd-display-Fix-out-of-bound-accesses.patch
    (stable-fixes CVE-2025-21985 bsc#1240811).
  - Update
    patches.suse/drm-amd-display-Fix-slab-use-after-free-on-hdcp_work.patch
    (git-fixes CVE-2025-21968 bsc#1240783).
  - Update
    patches.suse/drm-amd-display-fix-missing-.is_two_pixels_per_conta.patch
    (git-fixes CVE-2025-21989 bsc#1240805).
  - Update
    patches.suse/drm-amdgpu-NULL-check-BO-s-backing-store-when-determ.patch
    (git-fixes CVE-2025-21990 bsc#1240804).
  - Update
    patches.suse/drm-amdgpu-init-return-value-in-amdgpu_ttm_clear_buf.patch
    (git-fixes CVE-2025-21987 bsc#1240798).
  - Update
    patches.suse/drm-amdkfd-Fix-NULL-Pointer-Dereference-in-KFD-queue.patch
    (git-fixes CVE-2025-21940 bsc#1240702).
  - Update
    patches.suse/drm-hyperv-Fix-address-space-leak-when-Hyper-V-DRM-d.patch
    (git-fixes CVE-2025-21978 bsc#1240806).
  - Update
    patches.suse/drm-imagination-avoid-deadlock-on-fence-release.patch
    (git-fixes CVE-2025-21911 bsc#1240589).
  - Update
    patches.suse/drm-radeon-fix-uninitialized-size-issue-in-radeon_vc.patch
    (git-fixes CVE-2025-21996 bsc#1240801).
  - Update
    patches.suse/drm-sched-Fix-fence-reference-count-leak.patch
    (git-fixes CVE-2025-21995 bsc#1240821).
  - Update
    patches.suse/drm-xe-hmm-Don-t-dereference-struct-page-pointers-wi.patch
    (git-fixes CVE-2025-21939 bsc#1240710).
  - Update
    patches.suse/eth-bnxt-do-not-update-checksum-in-bnxt_xdp_build_sk.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21960 bsc#1240815).
  - Update
    patches.suse/eth-bnxt-fix-kernel-panic-in-the-bnxt_get_queue_stat.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21973 bsc#1240803).
  - Update
    patches.suse/eth-bnxt-fix-truesize-for-mb-xdp-pass-case.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21961 bsc#1240816).
  - Update
    patches.suse/eth-bnxt-return-fail-if-interface-is-down-in-bnxt_qu.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21974 bsc#1240800).
  - Update
    patches.suse/firmware-qcom-uefisecapp-fix-efivars-registration-ra.patch
    (git-fixes CVE-2025-21998 bsc#1240865).
  - Update
    patches.suse/gpio-aggregator-protect-driver-attr-handlers-against.patch
    (git-fixes CVE-2025-21943 bsc#1240647).
  - Update patches.suse/keys-Fix-UAF-in-key_put.patch (git-fixes
    CVE-2025-21893 bsc#1240427).
  - Update
    patches.suse/msft-hv-3165-fbdev-hyperv_fb-Fix-hang-in-kdump-kernel-when-on-Hyp.patch
    (git-fixes CVE-2025-21977 bsc#1240876).
  - Update
    patches.suse/msft-hv-3170-net-mana-cleanup-mana-struct-after-debugfs_remove.patch
    (git-fixes CVE-2025-21953 bsc#1240727).
  - Update
    patches.suse/net-mlx5-Bridge-fix-the-crash-caused-by-LAG-state-ch.patch
    (jsc#PED-11331 CVE-2025-21970 bsc#1240819).
  - Update
    patches.suse/net-mlx5-handle-errors-in-mlx5_chains_create_table.patch
    (jsc#PED-11331 CVE-2025-21975 bsc#1240812).
  - Update
    patches.suse/nvme-tcp-fix-potential-memory-corruption-in-nvme_tcp.patch
    (git-fixes CVE-2025-21927 bsc#1240714).
  - Update
    patches.suse/pinctrl-nuvoton-npcm8xx-Add-NULL-check-in-npcm8xx_gp.patch
    (git-fixes CVE-2025-21982 bsc#1240807).
  - Update
    patches.suse/rapidio-add-check-for-rio_add_net-in-rio_scan_alloc_.patch
    (git-fixes CVE-2025-21935 bsc#1240700).
  - Update
    patches.suse/rapidio-fix-an-API-misues-when-rio_add_net-fails.patch
    (git-fixes CVE-2025-21934 bsc#1240708).
  - Update
    patches.suse/regulator-dummy-force-synchronous-probing.patch
    (git-fixes CVE-2025-22009 bsc#1240940).
  - Update
    patches.suse/sched-fair-Fix-potential-memory-corruption-in-child_cfs_rq_on_list.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2025-21919 bsc#1240593).
  - Update
    patches.suse/slimbus-messaging-Free-transaction-ID-in-delayed-int.patch
    (git-fixes CVE-2025-21914 bsc#1240595).
  - Update
    patches.suse/soc-qcom-pdr-Fix-the-potential-deadlock.patch
    (git-fixes CVE-2025-22014 bsc#1240937).
  - Update
    patches.suse/usb-atm-cxacru-fix-a-flaw-in-existing-endpoint-check.patch
    (git-fixes CVE-2025-21916 bsc#1240582).
  - Update
    patches.suse/usb-renesas_usbhs-Flush-the-notify_hotplug_work.patch
    (git-fixes CVE-2025-21917 bsc#1240596).
  - Update patches.suse/usb-typec-ucsi-Fix-NULL-pointer-access.patch
    (git-fixes CVE-2025-21918 bsc#1240592).
  - Update
    patches.suse/wifi-cfg80211-cancel-wiphy_work-before-freeing-wiphy.patch
    (git-fixes CVE-2025-21979 bsc#1240808).
  - Update
    patches.suse/wifi-cfg80211-regulatory-improve-invalid-hints-check.patch
    (git-fixes CVE-2025-21910 bsc#1240583).
  - Update
    patches.suse/wifi-iwlwifi-limit-printed-string-from-FW-file.patch
    (git-fixes CVE-2025-21905 bsc#1240575).
  - Update
    patches.suse/wifi-iwlwifi-mvm-clean-up-ROC-on-failure.patch
    (git-fixes CVE-2025-21906 bsc#1240587).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-try-to-talk-to-a-dead-firmwar.patch
    (git-fixes CVE-2025-21930 bsc#1240715).
  - Update
    patches.suse/wifi-nl80211-reject-cooked-mode-if-it-is-set-along-w.patch
    (git-fixes CVE-2025-21909 bsc#1240590).
  - commit 759681a
  - virt: sev-guest: Use AES GCM crypto library (jsc#PED-348).
  - commit ffa1eb0
  - exfat: add a check for invalid data size (git-fixes).
  - commit 9baf5c3
  - nfsd: put dl_stid if fail to queue dl_recall (git-fixes).
  - commit 8a68217
  - KVM: PPC: replace call_rcu by kfree_rcu for simple
    kmem_cache_free callback (jsc#PED-348).
  - commit 5ad92ec
  - x86/virt: Move SEV-specific parsing into arch/x86/virt/svm
    (jsc#PED-348).
  - commit 7237a96
  - drm/amd: Keep display off while going into S4 (stable-fixes).
  - Refresh
    patches.suse/drm-amd-display-Restore-correct-backlight-brightness.patch.
  - commit 015cb7c
  - drm/xe/hw_engine: define sysfs_ops on all directories
    (git-fixes).
  - drm/xe: Use local fence in error path of xe_migrate_clear
    (git-fixes).
  - drm/xe: Fix an out-of-bounds shift when invalidating TLB
    (git-fixes).
  - drm/tests: probe-helper: Fix drm_display_mode memory leak
    (git-fixes).
  - drm/tests: modes: Fix drm_display_mode memory leak (git-fixes).
  - drm/tests: cmdline: Fix drm_display_mode memory leak
    (git-fixes).
  - drm/tests: modeset: Fix drm_display_mode memory leak
    (git-fixes).
  - drm/sti: remove duplicate object names (git-fixes).
  - accel/ivpu: Fix PM related deadlocks in MS IOCTLs (git-fixes).
  - accel/ivpu: Fix deadlock in ivpu_ms_cleanup() (git-fixes).
  - accel/ivpu: Fix warning in ivpu_ipc_send_receive_internal()
    (git-fixes).
  - drm/nouveau: prime: fix ttm_bo_delayed_delete oops (git-fixes).
  - drm/imagination: fix firmware memory leaks (git-fixes).
  - drm/imagination: take paired job reference (git-fixes).
  - drm/amdgpu/mes12: optimize MES pipe FW version fetching
    (git-fixes).
  - drm/amd/pm/smu11: Prevent division by zero (git-fixes).
  - drm/amd/display: Protect FPU in dml2_validate()/dml21_validate()
    (git-fixes).
  - drm/amd/display: Protect FPU in dml2_init()/dml21_init()
    (git-fixes).
  - drm/amd/display: Protect FPU in dml21_copy() (git-fixes).
  - drm/amd/display: Do not enable Replay and PSR while VRR is on
    in amdgpu_dm_commit_planes() (git-fixes).
  - drm/amdgpu/dma_buf: fix page_link check (git-fixes).
  - drm/amdgpu: immediately use GTT for new allocations (git-fixes).
  - drm/amdgpu/mes11: optimize MES pipe FW version fetching
    (git-fixes).
  - drm/i915/huc: Fix fence not released on early probe errors
    (git-fixes).
  - drm/i915/vrr: Add vrr.vsync_{start, end} in vrr_params_changed
    (git-fixes).
  - drm/i915: Disable RPG during live selftest (git-fixes).
  - gpiolib: of: Fix the choice for Ingenic NAND quirk (git-fixes).
  - gpio: tegra186: fix resource handling in ACPI probe path
    (git-fixes).
  - mtd: rawnand: Add status chack in r852_ready() (git-fixes).
  - mtd: inftlcore: Add error check for inftl_read_oob()
    (git-fixes).
  - ntb: use 64-bit arithmetic for the MSI doorbell mask
    (git-fixes).
  - ntb_perf: Delete duplicate dmaengine_unmap_put() call in
    perf_copy_chunk() (git-fixes).
  - ntb: intel: Fix using link status DB's (git-fixes).
  - ntb_hw_switchtec: Fix shift-out-of-bounds in
    switchtec_ntb_mw_set_trans (git-fixes).
  - tty: serial: fsl_lpuart: Use u32 and u8 for register variables
    (stable-fixes).
  - tty: n_tty: use uint for space returned by tty_write_room()
    (stable-fixes).
  - staging: vchiq_arm: Fix possible NPR of keep-alive thread
    (git-fixes).
  - staging: vchiq_arm: Register debugfs after cdev (git-fixes).
  - ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
    (stable-fixes).
  - mmc: sdhci-pxav3: set NEED_RSP_BUSY capability (stable-fixes).
  - selinux: Chain up tool resolving errors in install_policy.sh
    (git-fixes).
  - selinux: always check the file label in
    selinux_kernel_read_file() (git-fixes).
  - can: statistics: use atomic access in hot path (stable-fixes).
  - hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
    (stable-fixes).
  - memory: omap-gpmc: drop no compatible check (stable-fixes).
  - ASoC: rt1320: set wake_capable = 0 explicitly (stable-fixes).
  - ASoC: codecs: wsa884x: report temps to hwmon in millidegree
    of Celsius (stable-fixes).
  - selftests: netfilter: skip br_netfilter queue tests if kernel
    is tainted (stable-fixes).
  - wifi: mac80211: fix SA Query processing in MLO (stable-fixes).
  - wifi: mac80211: flush the station before moving it to
    UN-AUTHORIZED state (stable-fixes).
  - platform/x86/amd/pmf: Propagate PMF-TA return codes
    (stable-fixes).
  - platform/x86/intel/vsec: Add Diamond Rapids support
    (stable-fixes).
  - platform/x86: intel-hid: fix volume buttons on Microsoft
    Surface Go 4 tablet (stable-fixes).
  - wifi: brcmfmac: keep power during suspend if board requires it
    (stable-fixes).
  - wifi: mac80211: Fix sparse warning for monitor_sdata
    (git-fixes).
  - wifi: iwlwifi: mvm: use the right version of the rate API
    (stable-fixes).
  - wifi: iwlwifi: fw: allocate chained SG tables for dump
    (stable-fixes).
  - wifi: mac80211: remove debugfs dir for virtual monitor
    (stable-fixes).
  - wifi: mac80211: Cleanup sta TXQs on flush (stable-fixes).
  - HID: i2c-hid: improve i2c_hid_get_report error message
    (stable-fixes).
  - commit 0295513
  - perf/core: Fix child_total_time_enabled accounting bug at task
    exit (git-fixes).
  - powerpc/perf: Fix ref-counting on the PMU 'vpa_pmu' (git-fixes).
  - perf: Clean up pmu specific data (git-fixes).
  - perf/x86: Remove swap_task_ctx() (git-fixes).
  - perf/x86/lbr: Fix shorter LBRs call stacks for the system-wide
    mode (git-fixes).
  - perf: Supply task information to sched_task() (git-fixes).
  - perf: attach/detach PMU specific data (git-fixes).
  - locking/percpu-rwsem: Add guard support (git-fixes).
  - perf: Save PMU specific data in task_struct (git-fixes).
  - perf: Extend per event callchain limit to branch stack
    (git-fixes).
  - perf/ring_buffer: Allow the EPOLLRDNORM flag for poll
    (git-fixes).
  - perf/core: Clean up perf_try_init_event() (git-fixes).
  - perf/core: Fix perf_mmap() failure path (git-fixes).
  - perf/core: Detach 'struct perf_cpu_pmu_context' and 'struct pmu'
    lifetimes (git-fixes).
  - perf/core: Lift event->mmap_mutex in perf_mmap() (git-fixes).
  - perf/core: Remove retry loop from perf_mmap() (git-fixes).
  - perf/core: Further simplify perf_mmap() (git-fixes).
  - perf/core: Simplify the perf_mmap() control flow (git-fixes).
  - perf/bpf: Robustify perf_event_free_bpf_prog() (git-fixes).
  - perf/core: Introduce perf_free_addr_filters() (git-fixes).
  - perf/core: Add this_cpc() helper (git-fixes).
  - perf/core: Merge struct pmu::pmu_disable_count into struct
    perf_cpu_pmu_context::pmu_disable_count (git-fixes).
  - perf/core: Simplify perf_event_alloc() (git-fixes).
  - perf/core: Simplify perf_init_event() (git-fixes).
  - perf/core: Simplify perf_pmu_register() (git-fixes).
  - perf/core: Simplify the perf_pmu_register() error path
    (git-fixes).
  - perf/core: Simplify the perf_event_alloc() error path
    (git-fixes).
  - perf: Avoid the read if the count is already updated
    (git-fixes).
  - perf/x86/intel: Avoid disable PMU if !cpuc->enabled in sample
    read (git-fixes).
  - perf/x86/intel: Apply static call for drain_pebs (git-fixes).
  - lockdep/mm: Fix might_fault() lockdep check of
    current->mm->mmap_lock (git-fixes).
  - perf/x86/rapl: Fix error handling in init_rapl_pmus()
    (git-fixes).
  - perf/core: Fix perf_pmu_register() vs. perf_init_event()
    (git-fixes).
  - perf/core: Fix pmus_lock vs. pmus_srcu ordering (git-fixes).
  - perf/x86/rapl: Add support for Intel Arrow Lake U (git-fixes).
  - perf/x86/intel: Use better start period for frequency mode
    (git-fixes).
  - perf/core: Fix low freq setting via IOC_PERIOD (git-fixes).
  - perf/x86: Fix low freqency setting issue (git-fixes).
  - perf/x86/intel: Fix event constraints for LNC (git-fixes).
  - perf/x86/intel: Ensure LBRs are disabled when a CPU is starting
    (git-fixes).
  - perf/x86/intel: Fix ARCH_PERFMON_NUM_COUNTER_LEAF (git-fixes).
  - perf/x86/intel: Clean up PEBS-via-PT on hybrid (git-fixes).
  - perf/x86/rapl: Fix the error checking order (git-fixes).
  - perf: map pages in advance (git-fixes).
  - perf/core: Save raw sample data conditionally based on sample
    type (git-fixes).
  - perf/x86/intel: Fix bitmask of OCR and FRONTEND events for LNC
    (git-fixes).
  - perf/x86/intel/ds: Add PEBS format 6 (git-fixes).
  - perf/x86/intel/ds: Unconditionally drain PEBS DS when changing
    PEBS_DATA_CFG (git-fixes).
  - perf/x86/intel: Do not enable large PEBS for events with aux
    actions or aux sampling (jsc#PED-10651).
  - perf/x86/intel/pt: Add support for pause / resume
    (jsc#PED-10651).
  - perf/core: Add aux_pause, aux_resume, aux_start_paused
    (jsc#PED-10651).
  - perf/x86/intel/pt: Fix buffer full but size is 0 case
    (git-fixes).
  - perf/x86/amd: Warn only on new bits set (git-fixes).
  - commit 6f059e0

++++ kernel-firmware-i915:

  - Update to version 20250410 (git commit 6a006cef10ce):
    * xe: Update GUC to v70.44.1 for BMG and LNL
    * i915: Update GUC to v70.44.1 for i915 platforms

++++ kernel-rt:

  - config: Disable CONFIG_LATENCYTOP (jsc#PED-12529)
  - commit c5b32c4
  - s390/cpumf: Fix double free on error in cpumf_pmu_event_init()
    (git-fixes).
  - commit b32df18
  - Update config files: CONFIG_LAN966X_OIC and co are dropped
  - commit 32dd855
  - virt: arm-cca-guest: TSM_REPORT support for realms
    (jsc#PED-11786).
  - commit c5ab2be
  - arm64: Enable memory encrypt for Realms (jsc#PED-11786).
  - commit 3213422
  - arm64: mm: Avoid TLBI when marking pages as valid
    (jsc#PED-11786).
  - commit eecca06
  - arm64: Enforce bounce buffers for realm DMA (jsc#PED-11786).
  - commit b10d721
  - efi: arm64: Map Device with Prot Shared (jsc#PED-11786).
  - commit aefd90e
  - arm64: rsi: Map unprotected MMIO as decrypted (jsc#PED-11786).
  - commit ce08db2
  - arm64: rsi: Add support for checking whether an MMIO is
    protected (jsc#PED-11786).
  - commit 442a9ae
  - arm64: realm: Query IPA size from the RMM (jsc#PED-11786).
  - commit 9a064e4
  - arm64: Detect if in a realm and set RIPAS RAM (jsc#PED-11786).
  - commit e4b4ff0
  - arm64: rsi: Add RSI definitions (jsc#PED-11786).
  - commit 9e7e749
  - s390: Fix various typos (jsc#PED-348).
  - commit ae11616
  - RISC-V: KVM: Allow Smnpm and Ssnpm extensions for guests
    (jsc#PED-348).
  - commit 5fc44fd
  - virt: sev-guest: Carve out SNP message context structure
    (jsc#PED-348).
  - commit 9276b20
  - virt: sev-guest: Reduce the scope of SNP command mutex
    (jsc#PED-348).
  - commit 72f46bd
  - virt: sev-guest: Consolidate SNP guest messaging parameters
    to a struct (jsc#PED-348).
  - commit e467c7c
  - x86/sev: Cache the secrets page address (jsc#PED-348).
  - commit d373d20
  - Update
    patches.suse/Bluetooth-Add-check-for-mgmt_alloc_skb-in-mgmt_devic.patch
    (git-fixes CVE-2025-21936 bsc#1240716).
  - Update
    patches.suse/Bluetooth-Add-check-for-mgmt_alloc_skb-in-mgmt_remot.patch
    (git-fixes CVE-2025-21937 bsc#1240643).
  - Update
    patches.suse/Bluetooth-Fix-error-code-in-chan_alloc_skb_cb.patch
    (git-fixes CVE-2025-22007 bsc#1240829).
  - Update
    patches.suse/HID-appleir-Fix-potential-NULL-dereference-at-raw-ev.patch
    (git-fixes CVE-2025-21948 bsc#1240703).
  - Update
    patches.suse/HID-hid-steam-Fix-use-after-free-when-detaching-devi.patch
    (git-fixes CVE-2025-21923 bsc#1240691).
  - Update
    patches.suse/HID-intel-ish-hid-Fix-use-after-free-issue-in-hid_is.patch
    (git-fixes CVE-2025-21929 bsc#1240711).
  - Update
    patches.suse/HID-intel-ish-hid-Fix-use-after-free-issue-in-ishtp_.patch
    (git-fixes CVE-2025-21928 bsc#1240722).
  - Update
    patches.suse/KVM-arm64-Unconditionally-save-flush-host-FPSIMD-SVE-SME-state.patch
    (git-fixes CVE-2025-22013 bsc#1240938).
  - Update
    patches.suse/NFSv4-Fix-a-deadlock-when-recovering-state-on-a-sillyrenamed-file.patch
    (git-fixes CVE-2025-21900 bsc#1240578).
  - Update
    patches.suse/RDMA-bnxt_re-Add-sanity-checks-on-rdev-validity.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21901 bsc#1240579).
  - Update
    patches.suse/RDMA-hns-Fix-soft-lockup-during-bt-pages-loop.patch
    (git-fixes CVE-2025-22010 bsc#1240943).
  - Update
    patches.suse/accel-qaic-Fix-integer-overflow-in-qaic_validate_req.patch
    (git-fixes CVE-2025-22001 bsc#1240873).
  - Update
    patches.suse/acpi-typec-ucsi-Introduce-a-poll_cci-method.patch
    (git-fixes CVE-2025-21902 bsc#1240599).
  - Update
    patches.suse/bus-mhi-host-pci_generic-Use-pci_try_reset_function-.patch
    (git-fixes CVE-2025-21951 bsc#1240718).
  - Update
    patches.suse/can-ucan-fix-out-of-bound-read-in-strscpy-source.patch
    (git-fixes CVE-2025-22003 bsc#1240825).
  - Update
    patches.suse/cdx-Fix-possible-UAF-error-in-driver_override_show.patch
    (git-fixes CVE-2025-21915 bsc#1240594).
  - Update
    patches.suse/dm-flakey-Fix-memory-corruption-in-optional-corrupt_.patch
    (git-fixes CVE-2025-21966 bsc#1240779).
  - Update
    patches.suse/drivers-virt-acrn-hsm-Use-kzalloc-to-avoid-info-leak.patch
    (git-fixes CVE-2025-21950 bsc#1240719).
  - Update
    patches.suse/drm-amd-display-Assign-normalized_pix_clk-when-color.patch
    (stable-fixes CVE-2025-21956 bsc#1240739).
  - Update
    patches.suse/drm-amd-display-Fix-null-check-for-pipe_ctx-plane_st-374c9fa.patch
    (git-fixes CVE-2025-21941 bsc#1240701).
  - Update
    patches.suse/drm-amd-display-Fix-out-of-bound-accesses.patch
    (stable-fixes CVE-2025-21985 bsc#1240811).
  - Update
    patches.suse/drm-amd-display-Fix-slab-use-after-free-on-hdcp_work.patch
    (git-fixes CVE-2025-21968 bsc#1240783).
  - Update
    patches.suse/drm-amd-display-fix-missing-.is_two_pixels_per_conta.patch
    (git-fixes CVE-2025-21989 bsc#1240805).
  - Update
    patches.suse/drm-amdgpu-NULL-check-BO-s-backing-store-when-determ.patch
    (git-fixes CVE-2025-21990 bsc#1240804).
  - Update
    patches.suse/drm-amdgpu-init-return-value-in-amdgpu_ttm_clear_buf.patch
    (git-fixes CVE-2025-21987 bsc#1240798).
  - Update
    patches.suse/drm-amdkfd-Fix-NULL-Pointer-Dereference-in-KFD-queue.patch
    (git-fixes CVE-2025-21940 bsc#1240702).
  - Update
    patches.suse/drm-hyperv-Fix-address-space-leak-when-Hyper-V-DRM-d.patch
    (git-fixes CVE-2025-21978 bsc#1240806).
  - Update
    patches.suse/drm-imagination-avoid-deadlock-on-fence-release.patch
    (git-fixes CVE-2025-21911 bsc#1240589).
  - Update
    patches.suse/drm-radeon-fix-uninitialized-size-issue-in-radeon_vc.patch
    (git-fixes CVE-2025-21996 bsc#1240801).
  - Update
    patches.suse/drm-sched-Fix-fence-reference-count-leak.patch
    (git-fixes CVE-2025-21995 bsc#1240821).
  - Update
    patches.suse/drm-xe-hmm-Don-t-dereference-struct-page-pointers-wi.patch
    (git-fixes CVE-2025-21939 bsc#1240710).
  - Update
    patches.suse/eth-bnxt-do-not-update-checksum-in-bnxt_xdp_build_sk.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21960 bsc#1240815).
  - Update
    patches.suse/eth-bnxt-fix-kernel-panic-in-the-bnxt_get_queue_stat.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21973 bsc#1240803).
  - Update
    patches.suse/eth-bnxt-fix-truesize-for-mb-xdp-pass-case.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21961 bsc#1240816).
  - Update
    patches.suse/eth-bnxt-return-fail-if-interface-is-down-in-bnxt_qu.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21974 bsc#1240800).
  - Update
    patches.suse/firmware-qcom-uefisecapp-fix-efivars-registration-ra.patch
    (git-fixes CVE-2025-21998 bsc#1240865).
  - Update
    patches.suse/gpio-aggregator-protect-driver-attr-handlers-against.patch
    (git-fixes CVE-2025-21943 bsc#1240647).
  - Update patches.suse/keys-Fix-UAF-in-key_put.patch (git-fixes
    CVE-2025-21893 bsc#1240427).
  - Update
    patches.suse/msft-hv-3165-fbdev-hyperv_fb-Fix-hang-in-kdump-kernel-when-on-Hyp.patch
    (git-fixes CVE-2025-21977 bsc#1240876).
  - Update
    patches.suse/msft-hv-3170-net-mana-cleanup-mana-struct-after-debugfs_remove.patch
    (git-fixes CVE-2025-21953 bsc#1240727).
  - Update
    patches.suse/net-mlx5-Bridge-fix-the-crash-caused-by-LAG-state-ch.patch
    (jsc#PED-11331 CVE-2025-21970 bsc#1240819).
  - Update
    patches.suse/net-mlx5-handle-errors-in-mlx5_chains_create_table.patch
    (jsc#PED-11331 CVE-2025-21975 bsc#1240812).
  - Update
    patches.suse/nvme-tcp-fix-potential-memory-corruption-in-nvme_tcp.patch
    (git-fixes CVE-2025-21927 bsc#1240714).
  - Update
    patches.suse/pinctrl-nuvoton-npcm8xx-Add-NULL-check-in-npcm8xx_gp.patch
    (git-fixes CVE-2025-21982 bsc#1240807).
  - Update
    patches.suse/rapidio-add-check-for-rio_add_net-in-rio_scan_alloc_.patch
    (git-fixes CVE-2025-21935 bsc#1240700).
  - Update
    patches.suse/rapidio-fix-an-API-misues-when-rio_add_net-fails.patch
    (git-fixes CVE-2025-21934 bsc#1240708).
  - Update
    patches.suse/regulator-dummy-force-synchronous-probing.patch
    (git-fixes CVE-2025-22009 bsc#1240940).
  - Update
    patches.suse/sched-fair-Fix-potential-memory-corruption-in-child_cfs_rq_on_list.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2025-21919 bsc#1240593).
  - Update
    patches.suse/slimbus-messaging-Free-transaction-ID-in-delayed-int.patch
    (git-fixes CVE-2025-21914 bsc#1240595).
  - Update
    patches.suse/soc-qcom-pdr-Fix-the-potential-deadlock.patch
    (git-fixes CVE-2025-22014 bsc#1240937).
  - Update
    patches.suse/usb-atm-cxacru-fix-a-flaw-in-existing-endpoint-check.patch
    (git-fixes CVE-2025-21916 bsc#1240582).
  - Update
    patches.suse/usb-renesas_usbhs-Flush-the-notify_hotplug_work.patch
    (git-fixes CVE-2025-21917 bsc#1240596).
  - Update patches.suse/usb-typec-ucsi-Fix-NULL-pointer-access.patch
    (git-fixes CVE-2025-21918 bsc#1240592).
  - Update
    patches.suse/wifi-cfg80211-cancel-wiphy_work-before-freeing-wiphy.patch
    (git-fixes CVE-2025-21979 bsc#1240808).
  - Update
    patches.suse/wifi-cfg80211-regulatory-improve-invalid-hints-check.patch
    (git-fixes CVE-2025-21910 bsc#1240583).
  - Update
    patches.suse/wifi-iwlwifi-limit-printed-string-from-FW-file.patch
    (git-fixes CVE-2025-21905 bsc#1240575).
  - Update
    patches.suse/wifi-iwlwifi-mvm-clean-up-ROC-on-failure.patch
    (git-fixes CVE-2025-21906 bsc#1240587).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-try-to-talk-to-a-dead-firmwar.patch
    (git-fixes CVE-2025-21930 bsc#1240715).
  - Update
    patches.suse/wifi-nl80211-reject-cooked-mode-if-it-is-set-along-w.patch
    (git-fixes CVE-2025-21909 bsc#1240590).
  - commit 759681a
  - virt: sev-guest: Use AES GCM crypto library (jsc#PED-348).
  - commit ffa1eb0
  - exfat: add a check for invalid data size (git-fixes).
  - commit 9baf5c3
  - nfsd: put dl_stid if fail to queue dl_recall (git-fixes).
  - commit 8a68217
  - KVM: PPC: replace call_rcu by kfree_rcu for simple
    kmem_cache_free callback (jsc#PED-348).
  - commit 5ad92ec
  - x86/virt: Move SEV-specific parsing into arch/x86/virt/svm
    (jsc#PED-348).
  - commit 7237a96
  - drm/amd: Keep display off while going into S4 (stable-fixes).
  - Refresh
    patches.suse/drm-amd-display-Restore-correct-backlight-brightness.patch.
  - commit 015cb7c
  - drm/xe/hw_engine: define sysfs_ops on all directories
    (git-fixes).
  - drm/xe: Use local fence in error path of xe_migrate_clear
    (git-fixes).
  - drm/xe: Fix an out-of-bounds shift when invalidating TLB
    (git-fixes).
  - drm/tests: probe-helper: Fix drm_display_mode memory leak
    (git-fixes).
  - drm/tests: modes: Fix drm_display_mode memory leak (git-fixes).
  - drm/tests: cmdline: Fix drm_display_mode memory leak
    (git-fixes).
  - drm/tests: modeset: Fix drm_display_mode memory leak
    (git-fixes).
  - drm/sti: remove duplicate object names (git-fixes).
  - accel/ivpu: Fix PM related deadlocks in MS IOCTLs (git-fixes).
  - accel/ivpu: Fix deadlock in ivpu_ms_cleanup() (git-fixes).
  - accel/ivpu: Fix warning in ivpu_ipc_send_receive_internal()
    (git-fixes).
  - drm/nouveau: prime: fix ttm_bo_delayed_delete oops (git-fixes).
  - drm/imagination: fix firmware memory leaks (git-fixes).
  - drm/imagination: take paired job reference (git-fixes).
  - drm/amdgpu/mes12: optimize MES pipe FW version fetching
    (git-fixes).
  - drm/amd/pm/smu11: Prevent division by zero (git-fixes).
  - drm/amd/display: Protect FPU in dml2_validate()/dml21_validate()
    (git-fixes).
  - drm/amd/display: Protect FPU in dml2_init()/dml21_init()
    (git-fixes).
  - drm/amd/display: Protect FPU in dml21_copy() (git-fixes).
  - drm/amd/display: Do not enable Replay and PSR while VRR is on
    in amdgpu_dm_commit_planes() (git-fixes).
  - drm/amdgpu/dma_buf: fix page_link check (git-fixes).
  - drm/amdgpu: immediately use GTT for new allocations (git-fixes).
  - drm/amdgpu/mes11: optimize MES pipe FW version fetching
    (git-fixes).
  - drm/i915/huc: Fix fence not released on early probe errors
    (git-fixes).
  - drm/i915/vrr: Add vrr.vsync_{start, end} in vrr_params_changed
    (git-fixes).
  - drm/i915: Disable RPG during live selftest (git-fixes).
  - gpiolib: of: Fix the choice for Ingenic NAND quirk (git-fixes).
  - gpio: tegra186: fix resource handling in ACPI probe path
    (git-fixes).
  - mtd: rawnand: Add status chack in r852_ready() (git-fixes).
  - mtd: inftlcore: Add error check for inftl_read_oob()
    (git-fixes).
  - ntb: use 64-bit arithmetic for the MSI doorbell mask
    (git-fixes).
  - ntb_perf: Delete duplicate dmaengine_unmap_put() call in
    perf_copy_chunk() (git-fixes).
  - ntb: intel: Fix using link status DB's (git-fixes).
  - ntb_hw_switchtec: Fix shift-out-of-bounds in
    switchtec_ntb_mw_set_trans (git-fixes).
  - tty: serial: fsl_lpuart: Use u32 and u8 for register variables
    (stable-fixes).
  - tty: n_tty: use uint for space returned by tty_write_room()
    (stable-fixes).
  - staging: vchiq_arm: Fix possible NPR of keep-alive thread
    (git-fixes).
  - staging: vchiq_arm: Register debugfs after cdev (git-fixes).
  - ACPI: resource: Skip IRQ override on ASUS Vivobook 14 X1404VAP
    (stable-fixes).
  - mmc: sdhci-pxav3: set NEED_RSP_BUSY capability (stable-fixes).
  - selinux: Chain up tool resolving errors in install_policy.sh
    (git-fixes).
  - selinux: always check the file label in
    selinux_kernel_read_file() (git-fixes).
  - can: statistics: use atomic access in hot path (stable-fixes).
  - hwmon: (nct6775-core) Fix out of bounds access for NCT679{8,9}
    (stable-fixes).
  - memory: omap-gpmc: drop no compatible check (stable-fixes).
  - ASoC: rt1320: set wake_capable = 0 explicitly (stable-fixes).
  - ASoC: codecs: wsa884x: report temps to hwmon in millidegree
    of Celsius (stable-fixes).
  - selftests: netfilter: skip br_netfilter queue tests if kernel
    is tainted (stable-fixes).
  - wifi: mac80211: fix SA Query processing in MLO (stable-fixes).
  - wifi: mac80211: flush the station before moving it to
    UN-AUTHORIZED state (stable-fixes).
  - platform/x86/amd/pmf: Propagate PMF-TA return codes
    (stable-fixes).
  - platform/x86/intel/vsec: Add Diamond Rapids support
    (stable-fixes).
  - platform/x86: intel-hid: fix volume buttons on Microsoft
    Surface Go 4 tablet (stable-fixes).
  - wifi: brcmfmac: keep power during suspend if board requires it
    (stable-fixes).
  - wifi: mac80211: Fix sparse warning for monitor_sdata
    (git-fixes).
  - wifi: iwlwifi: mvm: use the right version of the rate API
    (stable-fixes).
  - wifi: iwlwifi: fw: allocate chained SG tables for dump
    (stable-fixes).
  - wifi: mac80211: remove debugfs dir for virtual monitor
    (stable-fixes).
  - wifi: mac80211: Cleanup sta TXQs on flush (stable-fixes).
  - HID: i2c-hid: improve i2c_hid_get_report error message
    (stable-fixes).
  - commit 0295513
  - perf/core: Fix child_total_time_enabled accounting bug at task
    exit (git-fixes).
  - powerpc/perf: Fix ref-counting on the PMU 'vpa_pmu' (git-fixes).
  - perf: Clean up pmu specific data (git-fixes).
  - perf/x86: Remove swap_task_ctx() (git-fixes).
  - perf/x86/lbr: Fix shorter LBRs call stacks for the system-wide
    mode (git-fixes).
  - perf: Supply task information to sched_task() (git-fixes).
  - perf: attach/detach PMU specific data (git-fixes).
  - locking/percpu-rwsem: Add guard support (git-fixes).
  - perf: Save PMU specific data in task_struct (git-fixes).
  - perf: Extend per event callchain limit to branch stack
    (git-fixes).
  - perf/ring_buffer: Allow the EPOLLRDNORM flag for poll
    (git-fixes).
  - perf/core: Clean up perf_try_init_event() (git-fixes).
  - perf/core: Fix perf_mmap() failure path (git-fixes).
  - perf/core: Detach 'struct perf_cpu_pmu_context' and 'struct pmu'
    lifetimes (git-fixes).
  - perf/core: Lift event->mmap_mutex in perf_mmap() (git-fixes).
  - perf/core: Remove retry loop from perf_mmap() (git-fixes).
  - perf/core: Further simplify perf_mmap() (git-fixes).
  - perf/core: Simplify the perf_mmap() control flow (git-fixes).
  - perf/bpf: Robustify perf_event_free_bpf_prog() (git-fixes).
  - perf/core: Introduce perf_free_addr_filters() (git-fixes).
  - perf/core: Add this_cpc() helper (git-fixes).
  - perf/core: Merge struct pmu::pmu_disable_count into struct
    perf_cpu_pmu_context::pmu_disable_count (git-fixes).
  - perf/core: Simplify perf_event_alloc() (git-fixes).
  - perf/core: Simplify perf_init_event() (git-fixes).
  - perf/core: Simplify perf_pmu_register() (git-fixes).
  - perf/core: Simplify the perf_pmu_register() error path
    (git-fixes).
  - perf/core: Simplify the perf_event_alloc() error path
    (git-fixes).
  - perf: Avoid the read if the count is already updated
    (git-fixes).
  - perf/x86/intel: Avoid disable PMU if !cpuc->enabled in sample
    read (git-fixes).
  - perf/x86/intel: Apply static call for drain_pebs (git-fixes).
  - lockdep/mm: Fix might_fault() lockdep check of
    current->mm->mmap_lock (git-fixes).
  - perf/x86/rapl: Fix error handling in init_rapl_pmus()
    (git-fixes).
  - perf/core: Fix perf_pmu_register() vs. perf_init_event()
    (git-fixes).
  - perf/core: Fix pmus_lock vs. pmus_srcu ordering (git-fixes).
  - perf/x86/rapl: Add support for Intel Arrow Lake U (git-fixes).
  - perf/x86/intel: Use better start period for frequency mode
    (git-fixes).
  - perf/core: Fix low freq setting via IOC_PERIOD (git-fixes).
  - perf/x86: Fix low freqency setting issue (git-fixes).
  - perf/x86/intel: Fix event constraints for LNC (git-fixes).
  - perf/x86/intel: Ensure LBRs are disabled when a CPU is starting
    (git-fixes).
  - perf/x86/intel: Fix ARCH_PERFMON_NUM_COUNTER_LEAF (git-fixes).
  - perf/x86/intel: Clean up PEBS-via-PT on hybrid (git-fixes).
  - perf/x86/rapl: Fix the error checking order (git-fixes).
  - perf: map pages in advance (git-fixes).
  - perf/core: Save raw sample data conditionally based on sample
    type (git-fixes).
  - perf/x86/intel: Fix bitmask of OCR and FRONTEND events for LNC
    (git-fixes).
  - perf/x86/intel/ds: Add PEBS format 6 (git-fixes).
  - perf/x86/intel/ds: Unconditionally drain PEBS DS when changing
    PEBS_DATA_CFG (git-fixes).
  - perf/x86/intel: Do not enable large PEBS for events with aux
    actions or aux sampling (jsc#PED-10651).
  - perf/x86/intel/pt: Add support for pause / resume
    (jsc#PED-10651).
  - perf/core: Add aux_pause, aux_resume, aux_start_paused
    (jsc#PED-10651).
  - perf/x86/intel/pt: Fix buffer full but size is 0 case
    (git-fixes).
  - perf/x86/amd: Warn only on new bits set (git-fixes).
  - commit 6f059e0

++++ libmicrohttpd:

  - fix build with curl 8.13.0 (boo#1241036)
    add libmicrohttpd-1.0.1-curl-8.13.0.patch

++++ numactl:

  - Update to version 2.0.19.13.g63e0223:
    * libnuma.c: Introduce numa_preferred_err()
    * numactl: Add --show option support for MPOL_WEIGHTED_INTERLEAVE
    * Add numa_get_weighted_interleave_mask() API
    * libnuma: Add APIs for weighted-interleaved allocations
    * libnuma.c: Fix memleak in numa_has_home_node()
    * Replace fgrep with grep -F to fix warning
    * Make numa_available respect EPERM

++++ python313-core:

  - Update to 3.13.3:
  - Tools/Demos
  - gh-131852: msgfmt no longer adds the POT-Creation-Date to
    generated .mo files for consistency with GNU msgfmt.
  - gh-85012: Correctly reset msgctxt when compiling messages
    in msgfmt.
  - gh-130025: The iOS testbed now correctly handles symlinks
    used as Python framework references.
  - Tests
  - gh-131050: test_ssl.test_dh_params is skipped if the
    underlying TLS library does not support finite-field
    ephemeral Diffie-Hellman.
  - gh-129200: Multiple iOS testbed runners can now be started
    at the same time without introducing an ambiguity over
    simulator ownership.
  - gh-130292: The iOS testbed will now run successfully on a
    machine that has not previously run Xcode tests (such as CI
    configurations).
  - gh-130293: The tests of terminal colorization are no longer
    sensitive to the value of the TERM variable in the testing
    environment.
  - gh-126332: Add unit tests for pyrepl.
  - Security
  - gh-131809: Update bundled libexpat to 2.7.1
  - gh-131261: Upgrade to libexpat 2.7.0
  - gh-127371: Avoid unbounded buffering for
    tempfile.SpooledTemporaryFile.writelines(). Previously,
    disk spillover was only checked after the lines iterator
    had been exhausted. This is now done after each line is
    written.
  - gh-121284: Fix bug in the folding of rfc2047 encoded-words
    when flattening an email message using a modern email
    policy. Previously when an encoded-word was too long for
    a line, it would be decoded, split across lines, and
    re-encoded. But commas and other special characters in the
    original text could be left unencoded and unquoted. This
    could theoretically be used to spoof header lines using
    a carefully constructed encoded-word if the resulting
    rendered email was transmitted or re-parsed.
  - Library
  - gh-132174: Fix function name in error message of
    _interpreters.run_string.
  - gh-132171: Fix crash of _interpreters.run_string on string
    subclasses.
  - gh-129204: Introduce new _PYTHON_SUBPROCESS_USE_POSIX_SPAWN
    environment variable knob in subprocess to control the use
    of os.posix_spawn().
  - gh-132159: Do not shadow user arguments in generated
    __new__() by decorator warnings.deprecated. Patch by Xuehai
    Pan.
  - gh-132075: Fix possible use of socket address structures
    with uninitialized members. Now all structure members are
    initialized with zeroes by default.
  - gh-132002: Fix crash when deallocating
    contextvars.ContextVar with weird unahashable string names.
  - gh-131668: socket: Fix code parsing AF_BLUETOOTH socket
    addresses.
  - gh-131492: Fix a resource leak when constructing a
    gzip.GzipFile with a filename fails, for example when
    passing an invalid compresslevel.
  - gh-131325: Fix sendfile fallback implementation to drain
    data after writing to transport in asyncio.
  - gh-129843: Fix incorrect argument passing in
    warnings.warn_explicit().
  - gh-131204: Use monospace font from System Font Stack for
    cross-platform support in difflib.HtmlDiff.
  - gh-130940: The PyConfig.use_system_logger attribute,
    introduced in Python 3.13.2, has been removed. The
    introduction of this attribute inadvertently introduced an
    ABI breakage on macOS and iOS. The use of the system logger
    is now enabled by default on iOS, and disabled by default
    on macOS.
  - gh-131045: Fix issue with __contains__, values, and
    pseudo-members for enum.Flag.
  - gh-130959: Fix pure-Python implementation of
    datetime.time.fromisoformat() to reject times with spaces
    in fractional part (for example, 12:34:56.400 +02:00),
    matching the C implementation. Patch by Michał Gorny.
  - gh-130637: Add validation for numeric response data in
    poplib.POP3.stat() method
  - gh-130461: Remove .. index:: directives from the uuid
    module documentation. These directives previously created
    entries in the general index for getnode() as well as
    the uuid1(), uuid3(), uuid4(), and uuid5() constructor
    functions.
  - gh-130379: The zipapp module now calculates the list of
    files to be added to the archive before creating the
    archive. This avoids accidentally including the target when
    it is being created in the source directory.
  - gh-130285: Fix corner case for random.sample() allowing the
    counts parameter to specify an empty population. So now,
    sample([], 0, counts=[]) and sample('abc', k=0, counts=[0,
    0, 0]) both give the same result as sample([], 0).
  - gh-130250: Fix regression in traceback.print_last().
  - gh-130230: Fix crash in pow() with only Decimal third
    argument.
  - gh-118761: Reverts a change in the previous release
    attempting to make some stdlib imports used within the
    subprocess module lazy as this was causing errors during
    __del__ finalizers calling methods such as terminate, or
    kill, or send_signal.
  - gh-130164: Fixed failure to raise TypeError in
    inspect.Signature.bind() for positional-only arguments
    provided by keyword when a variadic keyword argument (e.g.
  - -kwargs) is present.
  - gh-130151: Fix reference leaks in _hashlib.hmac_new() and
    _hashlib.hmac_digest(). Patch by Bénédikt Tran.
  - gh-130145: Fix asyncio.AbstractEventloop.run_forever() when
    another loop is already running.
  - gh-129726: Fix gzip.GzipFile raising an unraisable
    exception during garbage collection when referring to
    a temporary object by breaking the reference loop with
    weakref.
  - gh-127750: Remove broken functools.singledispatchmethod()
    caching introduced in gh-85160.
  - gh-129583: Update bundled pip to 25.0.1
  - gh-97850: Update the deprecation warning of
    importlib.abc.Loader.load_module().
  - gh-129646: Update the locale alias mapping in the locale
    module to match the latest X Org locale alias mapping and
    support new locales in Glibc 2.41.
  - gh-129603: Fix bugs where sqlite3.Row objects could
    segfault if their inherited description was set to
    None. Patch by Erlend Aasland.
  - gh-128231: Execution of multiple statements in the new
    REPL now stops immediately upon the first exception
    encountered. Patch by Bartosz Sławecki.
  - gh-117779: Fix reading duplicated entries in zipfile by
    name. Reading duplicated entries (except the last one)
    by ZipInfo now emits a warning instead of raising an
    exception.
  - gh-128772: Fix pydoc for methods with the __module__
    attribute equal to None.
  - gh-92897: Scheduled the deprecation of the check_home
    argument of sysconfig.is_python_build() to Python 3.15.
  - gh-128657: Fix possible extra reference when using objects
    returned by hashlib.sha256() under free threading.
  - gh-128703: Fix mimetypes.guess_type() to use default
    mapping for empty Content-Type in registry.
  - gh-128308: Support the name keyword argument
    for eager tasks in asyncio.loop.create_task(),
    asyncio.create_task() and asyncio.TaskGroup.create_task(),
    by passing on all kwargs to the task factory set by
    asyncio.loop.set_task_factory().
  - gh-128388: Fix PyREPL on Windows to support more
    keybindings, like the Control-← and Control-→ word-skipping
    keybindings and those with meta (i.e. Alt), e.g. Alt-d to
    kill-word or Alt-Backspace backward-kill-word.
  - gh-126037: xml.etree.ElementTree: Fix a crash in
    Element.find, Element.findtext and Element.findall when
    the tag to find implements an __eq__() method mutating the
    element being queried. Patch by Bénédikt Tran.
  - gh-127712: Fix handling of the secure argument of
    logging.handlers.SMTPHandler.
  - gh-126033: xml.etree.ElementTree: Fix a crash in
    Element.remove when the element is concurrently
    mutated. Patch by Bénédikt Tran.
  - gh-118201: Fixed intermittent failures of os.confstr,
    os.pathconf and os.sysconf on iOS and Android.
  - gh-124927: Non-printing characters are now properly handled
    in the new REPL.
  - IDLE
  - gh-129873: Simplify displaying the IDLE doc by only copying
    the text section of idle.html to idlelib/help.html. Patch
    by Stan Ulbrych.
  - Documentation
  - gh-131417: Mention asyncio.Future and asyncio.Task in
    generic classes list.
  - gh-125722: Require Sphinx 8.2.0 or later to build the
    Python documentation. Patch by Adam Turner.
  - gh-129712: The wheel tags supported by each macOS universal
    SDK option are now documented.
  - gh-46236: C API: Document PyUnicode_RSplit(),
    PyUnicode_Partition() and PyUnicode_RPartition().
  - Core and Builtins
  - gh-132011: Fix crash when calling list.append() as an
    unbound method.
  - gh-131998: Fix a crash when using an unbound method
    descriptor object in a function where a bound method
    descriptor was used.
  - gh-131988: Fix a performance regression that caused scaling
    bottlenecks in the free threaded build in 3.13.1 and
    3.13.2.
  - gh-131719: Fix missing NULL check in _PyMem_FreeDelayed in
    free-threaded build.
  - gh-131670: Fix anext() failing on sync __anext__() raising
    an exception.
  - gh-131141: Fix data race in sys.monitoring instrumentation
    while registering callback.
  - gh-130932: Fix incorrect exception handling in
    _PyModule_IsPossiblyShadowing
  - gh-130851: Fix a crash in the free threading build when
    constructing a code object with co_consts that contains
    instances of types that are not otherwise generated by the
    bytecode compiler.
  - gh-130794: Fix memory leak in the free threaded build
    when resizing a shared list or dictionary from multiple
    short-lived threads.
  - gh-130775: Do not crash on negative column and end_column
    in ast locations.
  - gh-130382: Fix PyRefTracer_DESTROY not being sent from
    Python/ceval.c Py_DECREF().
  - gh-130618: Fix a bug that was causing UnicodeDecodeError or
    SystemError to be raised when using f-strings with lambda
    expressions with non-ASCII characters. Patch by Pablo
    Galindo
  - gh-130163: Fix possible crashes related to concurrent
    change and use of the sys module attributes.
  - gh-88887: Fixing multiprocessing Resource Tracker process
    leaking, usually observed when running Python as PID 1.
  - gh-130115: Fix an issue with thread identifiers being
    sign-extended on some platforms.
  - gh-128396: Fix a crash that occurs when calling locals()
    inside an inline comprehension that uses the same local
    variable as the outer frame scope where the variable is a
    free or cell var.
  - gh-116042: Fix location for SyntaxErrors of invalid escapes
    in the tokenizer. Patch by Pablo Galindo
  - gh-129983: Fix data race in compile_template in sre.c.
  - gh-129967: Fix a race condition in the free threading build
    when repr(set) is called concurrently with set.clear().
  - gh-129900: Fix return codes inside SystemExit not getting
    returned by the REPL.
  - gh-129732: Fixed a race in _Py_qsbr_reserve in the free
    threading build.
  - gh-129643: Fix thread safety of PyList_Insert() in
    free-threading builds.
  - gh-129668: Fix race condition when raising MemoryError in
    the free threaded build.
  - gh-129643: Fix thread safety of PyList_SetItem() in
    free-threading builds. Patch by Kumar Aditya.
  - gh-128714: Fix the potential races in get/set dunder
    methods __annotations__, __annotate__ and __type_params__
    for function object, and add related tests.
  - gh-128632: Disallow __classdict__ as the name of a type
    parameter. Using this name would previously crash the
    interpreter in some circumstances.
  - gh-127953: The time to handle a LINE event in
    sys.monitoring (and sys.settrace) is now independent of the
    number of lines in the code object.
  - gh-125331: from __future__ import barry_as_FLUFL now works
    in more contexts, including when it is used in files,
    with the -c flag, and in the REPL when there are multiple
    statements on the same line. Previously, it worked only
    on subsequent lines in the REPL, and when the appropriate
    flags were passed directly to compile(). Patch by Pablo
    Galindo.
  - C API
  - gh-131740: Update PyUnstable_GC_VisitObjects to traverse
    perm gen.
  - gh-129533: Update PyGC_Enable(), PyGC_Disable(),
    PyGC_IsEnabled() to use atomic operation for thread-safety
    at free-threading build. Patch by Donghee Na.
  - Build
  - gh-131865: The DTrace build now properly passes the CC
    and CFLAGS variables to the dtrace command when utilizing
    SystemTap on Linux.
  - gh-131675: Fix mimalloc library builds for 32-bit ARM
    targets.
  - gh-130673: Fix potential KeyError when handling object
    sections during JIT building process.
  - gh-130740: Ensure that Python.h is included before
    stdbool.h unless pyconfig.h is included before or in some
    platform-specific contexts.
  - gh-129838: Don’t redefine _Py_NO_SANITIZE_UNDEFINED when
    compiling with a recent GCC version and undefined sanitizer
    enabled.
  - gh-129660: Drop test_embed from PGO training, whose
    contribution in recent versions is considered to be
    ignorable.
  - Add gh126985-mv-pyvenv.cfg2getpath.patch to remove failing
    tests in test_sysconfig.
  - Add gh-132535-rsrc-warn-test_timeout.patch to fix
    failing tests in the build system without network access
    (gh#python/cpython#132535).

++++ ceph:

  - Update to 16.2.15-83-g635361e68c0:
    + Fix FTBFS on GCC 15 (bsc#1239885)

++++ mcelog:

  - Update to version 204:
    * Enable offline retries by default
    * Add ability to retry failed page offlines with an exponential backoff
    * Fix misspelling in variable name

++++ pam-config:

  - Update to version 2.12+git.20250411:
    * Release version 2.12
    * Call ecryptfs/fscrypt before pam_unix (#30)
    * Don't exit with error if admin disabled pam-config

++++ python313:

  - Update to 3.13.3:
  - Tools/Demos
  - gh-131852: msgfmt no longer adds the POT-Creation-Date to
    generated .mo files for consistency with GNU msgfmt.
  - gh-85012: Correctly reset msgctxt when compiling messages
    in msgfmt.
  - gh-130025: The iOS testbed now correctly handles symlinks
    used as Python framework references.
  - Tests
  - gh-131050: test_ssl.test_dh_params is skipped if the
    underlying TLS library does not support finite-field
    ephemeral Diffie-Hellman.
  - gh-129200: Multiple iOS testbed runners can now be started
    at the same time without introducing an ambiguity over
    simulator ownership.
  - gh-130292: The iOS testbed will now run successfully on a
    machine that has not previously run Xcode tests (such as CI
    configurations).
  - gh-130293: The tests of terminal colorization are no longer
    sensitive to the value of the TERM variable in the testing
    environment.
  - gh-126332: Add unit tests for pyrepl.
  - Security
  - gh-131809: Update bundled libexpat to 2.7.1
  - gh-131261: Upgrade to libexpat 2.7.0
  - gh-127371: Avoid unbounded buffering for
    tempfile.SpooledTemporaryFile.writelines(). Previously,
    disk spillover was only checked after the lines iterator
    had been exhausted. This is now done after each line is
    written.
  - gh-121284: Fix bug in the folding of rfc2047 encoded-words
    when flattening an email message using a modern email
    policy. Previously when an encoded-word was too long for
    a line, it would be decoded, split across lines, and
    re-encoded. But commas and other special characters in the
    original text could be left unencoded and unquoted. This
    could theoretically be used to spoof header lines using
    a carefully constructed encoded-word if the resulting
    rendered email was transmitted or re-parsed.
  - Library
  - gh-132174: Fix function name in error message of
    _interpreters.run_string.
  - gh-132171: Fix crash of _interpreters.run_string on string
    subclasses.
  - gh-129204: Introduce new _PYTHON_SUBPROCESS_USE_POSIX_SPAWN
    environment variable knob in subprocess to control the use
    of os.posix_spawn().
  - gh-132159: Do not shadow user arguments in generated
    __new__() by decorator warnings.deprecated. Patch by Xuehai
    Pan.
  - gh-132075: Fix possible use of socket address structures
    with uninitialized members. Now all structure members are
    initialized with zeroes by default.
  - gh-132002: Fix crash when deallocating
    contextvars.ContextVar with weird unahashable string names.
  - gh-131668: socket: Fix code parsing AF_BLUETOOTH socket
    addresses.
  - gh-131492: Fix a resource leak when constructing a
    gzip.GzipFile with a filename fails, for example when
    passing an invalid compresslevel.
  - gh-131325: Fix sendfile fallback implementation to drain
    data after writing to transport in asyncio.
  - gh-129843: Fix incorrect argument passing in
    warnings.warn_explicit().
  - gh-131204: Use monospace font from System Font Stack for
    cross-platform support in difflib.HtmlDiff.
  - gh-130940: The PyConfig.use_system_logger attribute,
    introduced in Python 3.13.2, has been removed. The
    introduction of this attribute inadvertently introduced an
    ABI breakage on macOS and iOS. The use of the system logger
    is now enabled by default on iOS, and disabled by default
    on macOS.
  - gh-131045: Fix issue with __contains__, values, and
    pseudo-members for enum.Flag.
  - gh-130959: Fix pure-Python implementation of
    datetime.time.fromisoformat() to reject times with spaces
    in fractional part (for example, 12:34:56.400 +02:00),
    matching the C implementation. Patch by Michał Gorny.
  - gh-130637: Add validation for numeric response data in
    poplib.POP3.stat() method
  - gh-130461: Remove .. index:: directives from the uuid
    module documentation. These directives previously created
    entries in the general index for getnode() as well as
    the uuid1(), uuid3(), uuid4(), and uuid5() constructor
    functions.
  - gh-130379: The zipapp module now calculates the list of
    files to be added to the archive before creating the
    archive. This avoids accidentally including the target when
    it is being created in the source directory.
  - gh-130285: Fix corner case for random.sample() allowing the
    counts parameter to specify an empty population. So now,
    sample([], 0, counts=[]) and sample('abc', k=0, counts=[0,
    0, 0]) both give the same result as sample([], 0).
  - gh-130250: Fix regression in traceback.print_last().
  - gh-130230: Fix crash in pow() with only Decimal third
    argument.
  - gh-118761: Reverts a change in the previous release
    attempting to make some stdlib imports used within the
    subprocess module lazy as this was causing errors during
    __del__ finalizers calling methods such as terminate, or
    kill, or send_signal.
  - gh-130164: Fixed failure to raise TypeError in
    inspect.Signature.bind() for positional-only arguments
    provided by keyword when a variadic keyword argument (e.g.
  - -kwargs) is present.
  - gh-130151: Fix reference leaks in _hashlib.hmac_new() and
    _hashlib.hmac_digest(). Patch by Bénédikt Tran.
  - gh-130145: Fix asyncio.AbstractEventloop.run_forever() when
    another loop is already running.
  - gh-129726: Fix gzip.GzipFile raising an unraisable
    exception during garbage collection when referring to
    a temporary object by breaking the reference loop with
    weakref.
  - gh-127750: Remove broken functools.singledispatchmethod()
    caching introduced in gh-85160.
  - gh-129583: Update bundled pip to 25.0.1
  - gh-97850: Update the deprecation warning of
    importlib.abc.Loader.load_module().
  - gh-129646: Update the locale alias mapping in the locale
    module to match the latest X Org locale alias mapping and
    support new locales in Glibc 2.41.
  - gh-129603: Fix bugs where sqlite3.Row objects could
    segfault if their inherited description was set to
    None. Patch by Erlend Aasland.
  - gh-128231: Execution of multiple statements in the new
    REPL now stops immediately upon the first exception
    encountered. Patch by Bartosz Sławecki.
  - gh-117779: Fix reading duplicated entries in zipfile by
    name. Reading duplicated entries (except the last one)
    by ZipInfo now emits a warning instead of raising an
    exception.
  - gh-128772: Fix pydoc for methods with the __module__
    attribute equal to None.
  - gh-92897: Scheduled the deprecation of the check_home
    argument of sysconfig.is_python_build() to Python 3.15.
  - gh-128657: Fix possible extra reference when using objects
    returned by hashlib.sha256() under free threading.
  - gh-128703: Fix mimetypes.guess_type() to use default
    mapping for empty Content-Type in registry.
  - gh-128308: Support the name keyword argument
    for eager tasks in asyncio.loop.create_task(),
    asyncio.create_task() and asyncio.TaskGroup.create_task(),
    by passing on all kwargs to the task factory set by
    asyncio.loop.set_task_factory().
  - gh-128388: Fix PyREPL on Windows to support more
    keybindings, like the Control-← and Control-→ word-skipping
    keybindings and those with meta (i.e. Alt), e.g. Alt-d to
    kill-word or Alt-Backspace backward-kill-word.
  - gh-126037: xml.etree.ElementTree: Fix a crash in
    Element.find, Element.findtext and Element.findall when
    the tag to find implements an __eq__() method mutating the
    element being queried. Patch by Bénédikt Tran.
  - gh-127712: Fix handling of the secure argument of
    logging.handlers.SMTPHandler.
  - gh-126033: xml.etree.ElementTree: Fix a crash in
    Element.remove when the element is concurrently
    mutated. Patch by Bénédikt Tran.
  - gh-118201: Fixed intermittent failures of os.confstr,
    os.pathconf and os.sysconf on iOS and Android.
  - gh-124927: Non-printing characters are now properly handled
    in the new REPL.
  - IDLE
  - gh-129873: Simplify displaying the IDLE doc by only copying
    the text section of idle.html to idlelib/help.html. Patch
    by Stan Ulbrych.
  - Documentation
  - gh-131417: Mention asyncio.Future and asyncio.Task in
    generic classes list.
  - gh-125722: Require Sphinx 8.2.0 or later to build the
    Python documentation. Patch by Adam Turner.
  - gh-129712: The wheel tags supported by each macOS universal
    SDK option are now documented.
  - gh-46236: C API: Document PyUnicode_RSplit(),
    PyUnicode_Partition() and PyUnicode_RPartition().
  - Core and Builtins
  - gh-132011: Fix crash when calling list.append() as an
    unbound method.
  - gh-131998: Fix a crash when using an unbound method
    descriptor object in a function where a bound method
    descriptor was used.
  - gh-131988: Fix a performance regression that caused scaling
    bottlenecks in the free threaded build in 3.13.1 and
    3.13.2.
  - gh-131719: Fix missing NULL check in _PyMem_FreeDelayed in
    free-threaded build.
  - gh-131670: Fix anext() failing on sync __anext__() raising
    an exception.
  - gh-131141: Fix data race in sys.monitoring instrumentation
    while registering callback.
  - gh-130932: Fix incorrect exception handling in
    _PyModule_IsPossiblyShadowing
  - gh-130851: Fix a crash in the free threading build when
    constructing a code object with co_consts that contains
    instances of types that are not otherwise generated by the
    bytecode compiler.
  - gh-130794: Fix memory leak in the free threaded build
    when resizing a shared list or dictionary from multiple
    short-lived threads.
  - gh-130775: Do not crash on negative column and end_column
    in ast locations.
  - gh-130382: Fix PyRefTracer_DESTROY not being sent from
    Python/ceval.c Py_DECREF().
  - gh-130618: Fix a bug that was causing UnicodeDecodeError or
    SystemError to be raised when using f-strings with lambda
    expressions with non-ASCII characters. Patch by Pablo
    Galindo
  - gh-130163: Fix possible crashes related to concurrent
    change and use of the sys module attributes.
  - gh-88887: Fixing multiprocessing Resource Tracker process
    leaking, usually observed when running Python as PID 1.
  - gh-130115: Fix an issue with thread identifiers being
    sign-extended on some platforms.
  - gh-128396: Fix a crash that occurs when calling locals()
    inside an inline comprehension that uses the same local
    variable as the outer frame scope where the variable is a
    free or cell var.
  - gh-116042: Fix location for SyntaxErrors of invalid escapes
    in the tokenizer. Patch by Pablo Galindo
  - gh-129983: Fix data race in compile_template in sre.c.
  - gh-129967: Fix a race condition in the free threading build
    when repr(set) is called concurrently with set.clear().
  - gh-129900: Fix return codes inside SystemExit not getting
    returned by the REPL.
  - gh-129732: Fixed a race in _Py_qsbr_reserve in the free
    threading build.
  - gh-129643: Fix thread safety of PyList_Insert() in
    free-threading builds.
  - gh-129668: Fix race condition when raising MemoryError in
    the free threaded build.
  - gh-129643: Fix thread safety of PyList_SetItem() in
    free-threading builds. Patch by Kumar Aditya.
  - gh-128714: Fix the potential races in get/set dunder
    methods __annotations__, __annotate__ and __type_params__
    for function object, and add related tests.
  - gh-128632: Disallow __classdict__ as the name of a type
    parameter. Using this name would previously crash the
    interpreter in some circumstances.
  - gh-127953: The time to handle a LINE event in
    sys.monitoring (and sys.settrace) is now independent of the
    number of lines in the code object.
  - gh-125331: from __future__ import barry_as_FLUFL now works
    in more contexts, including when it is used in files,
    with the -c flag, and in the REPL when there are multiple
    statements on the same line. Previously, it worked only
    on subsequent lines in the REPL, and when the appropriate
    flags were passed directly to compile(). Patch by Pablo
    Galindo.
  - C API
  - gh-131740: Update PyUnstable_GC_VisitObjects to traverse
    perm gen.
  - gh-129533: Update PyGC_Enable(), PyGC_Disable(),
    PyGC_IsEnabled() to use atomic operation for thread-safety
    at free-threading build. Patch by Donghee Na.
  - Build
  - gh-131865: The DTrace build now properly passes the CC
    and CFLAGS variables to the dtrace command when utilizing
    SystemTap on Linux.
  - gh-131675: Fix mimalloc library builds for 32-bit ARM
    targets.
  - gh-130673: Fix potential KeyError when handling object
    sections during JIT building process.
  - gh-130740: Ensure that Python.h is included before
    stdbool.h unless pyconfig.h is included before or in some
    platform-specific contexts.
  - gh-129838: Don’t redefine _Py_NO_SANITIZE_UNDEFINED when
    compiling with a recent GCC version and undefined sanitizer
    enabled.
  - gh-129660: Drop test_embed from PGO training, whose
    contribution in recent versions is considered to be
    ignorable.
  - Add gh126985-mv-pyvenv.cfg2getpath.patch to remove failing
    tests in test_sysconfig.
  - Add gh-132535-rsrc-warn-test_timeout.patch to fix
    failing tests in the build system without network access
    (gh#python/cpython#132535).

++++ qemu:

  - all glib2 versions are recent enough to use pcre2:
    * qemu-linux-user: drop pcre (by Andreas Stieger)
  - Correct wrong bug mentioned in changelog (bsc#1236329)

++++ virt-manager:

  - Upstream features and bug fixes (bsc#1027942) (jsc#PED-8910)
    040-virtinst-add-pstore-backend-support.patch
    041-tests-add-pstore-test.patch
    042-man-virt-install-Document-pstore-device.patch
    043-tests-Increase-virtio-mem-block-size.patch
    044-tests-test_urls-fix-dead-URL.patch
    045-urlfetcher-add-riscv64-architecture-for-Debian.patch
    046-virt-manager-list-virtual-networks-when-creating-new-QEMU-Session-VM.patch
    047-virt-install-add-support-for-vDPA-network-device.patch
    048-virt-manager-add-support-for-vDPA-network-device.patch
    049-virt-install-detect-wayland-in-order-to-start-virt-viewer.patch
  - bsc#1241082 - [Build 20250410] virt_install fails to launch:
    missing dependencies.
    Spec file modifications

------------------------------------------------------------------
------------------  2025-4-10  -  Apr 10 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20250410.71df276:
    * Modern s390x uses TERM=linux for ttysclp<X>

++++ blog:

  - The suse-module-tools are required at build otherwise blog
    is not in the initrd

++++ cups:

  - Version upgrade to 2.4.12:
    See https://github.com/openprinting/cups/releases
    The last planned release of CUPS 2.4.x series
    (the next will be 2.5.x series) contains several enhancements
    among set of bug fixes, such following cryptographic policies
    when using GnuTLS crypto provider and possibility to opt-out
    from this behavior, logging job debugging history if print
    queue backends fails, or raising alerts for certificate issues
    in IPPS backend.
    Detailed list (from CHANGES.md):
    * GnuTLS follows system crypto policies now (Issue #1105)
    * Added `NoSystem` SSLOptions value (Issue #1130)
    * Now we raise alert for certificate issues (Issue #1194)
    * Added Kyocera USB quirk (Issue #1198)
    * The scheduler now logs a job's debugging history
    if the backend fails (Issue #1205)
    * Fixed a potential timing issue with `cupsEnumDests`
    (Issue #1084)
    * Fixed a potential "lost PPD" condition in the scheduler
    (Issue #1109)
    * Fixed a compressed file error handling bug (Issue #1070)
    * Fixed a bug in the make-and-model whitespace trimming
    code (Issue #1096)
    * Fixed a removal of IPP Everywhere permanent queue
    if installation failed (Issue #1102)
    * Fixed `ServerToken None` in scheduler (Issue #1111)
    * Fixed invalid IPP keyword values created from PPD
    option names (Issue #1118)
    * Fixed handling of "media" and "PageSize" in the same
    print request (Issue #1125)
    * Fixed client raster printing from macOS (Issue #1143)
    * Fixed the default User-Agent string.
    * Fixed a recursion issue in `ippReadIO`.
    * Fixed handling incorrect radix in `scan_ps()` (Issue #1188)
    * Fixed validation of dateTime values with time zones
    more than UTC+11 (Issue #1201)
    * Fixed attributes returned by the Create-Xxx-Subscriptions
    requests (Issue #1204)
    * Fixed `ippDateToTime` when using a non GMT/UTC timezone
    (Issue #1208)
    * Fixed `job-completed` event notifications for jobs that are
    cancelled before started (Issue #1209)
    * Fixed DNS-SD discovery with `ippfind` (Issue #1211)
    Issues are those at https://github.com/OpenPrinting/cups/issues
  - Adapted downgrade-autoconf-requirement.patch for CUPS 2.4.12

++++ docker:

  - Update to docker-buildx v0.22.0. Upstream changelog:
    <https://github.com/docker/buildx/releases/tag/v0.22.0>
    * Includes fixes for CVE-2025-0495. bsc#1239765
  - Disable transparent SUSEConnect support for SLE-16. PED-12534
    When this patchset was first added in 2013 (and rewritten over the years),
    there was no upstream way to easily provide SLE customers with a way to build
    container images based on SLE using the host subscription. However, with
    docker-buildx you can now define secrets for builds (this is not entirely
    transparent, but we can easily document this new requirement for SLE-16).
    Users should use
    RUN --mount=type=secret,id=SCCcredentials zypper -n ...
    in their Dockerfiles, and
    docker buildx build --secret id=SCCcredentials,src=/etc/zypp/credentials.d/SCCcredentials,type=file .
    when doing their builds.
  - Now that the only blocker for docker-buildx support was removed for SLE-16,
    enable docker-buildx for SLE-16 as well. PED-8905

++++ python-kiwi:

  - Fix Agama PXE build
    A bootloader setup is needed to create config.bootoptions
    Even though a ramdisk deployment does not require a bootloader
    setup we need it because part of the setup is the root device
    reference which is still needed to pivot root into the
    system
  - Fix firmware setting for Agama PXE image
  - Added obs BUILD_FLAVOR for agama
    Required for multibuild (multiple profiles) build
  - Update Agama integration test
    Split the build into two profiles ISO and PXE to differentiate
    the build results into a small Agama for remote installations
    and a standard Agama for iso based installations

++++ kernel-default:

  - Revert "kheaders: Ignore silly-rename files" (stable-fixes).
  - rust: kbuild: add -fzero-init-padding-bits to
    bindgen_skip_cflags (git-fixes).
  - docs: rust: remove spurious item in `expect` list (git-fixes).
  - commit 2d49340
  - USB: serial: ftdi_sio: add support for Altera USB Blaster 3
    (stable-fixes).
  - USB: serial: option: fix Telit Cinterion FE990A name
    (stable-fixes).
  - USB: serial: option: add Telit Cinterion FE990B compositions
    (stable-fixes).
  - USB: serial: option: match on interface class for Telit FN990B
    (stable-fixes).
  - thermal: gov_power_allocator: Update total_weight on bind and
    cdev updates (git-fixes).
  - vmlinux.lds: Ensure that const vars with relocations are mapped
    R/O (stable-fixes).
  - usb: phy: generic: Use proper helper for property detection
    (stable-fixes).
  - commit cf7a1fa
  - selftests/mm: run_vmtests.sh: fix half_ufd_size_MB calculation
    (git-fixes).
  - net: phy: nxp-c45-tja11xx: add TJA112XB SGMII PCS restart errata
    (git-fixes).
  - net: phy: nxp-c45-tja11xx: add TJA112X PHY configuration errata
    (git-fixes).
  - kbuild: userprogs: use correct lld when linking through clang
    (git-fixes).
  - thermal/of: Fix cdev lookup in thermal_of_should_bind()
    (git-fixes).
  - selftests/landlock: Test that MPTCP actions are not restricted
    (stable-fixes).
  - selftests/landlock: Test TCP accesses with protocol=IPPROTO_TCP
    (stable-fixes).
  - irqchip/jcore-aic, clocksource/drivers/jcore: Fix jcore-pit
    interrupt request (git-fixes).
  - net: wwan: mhi_wwan_mbim: Silence sequence number glitch errors
    (stable-fixes).
  - objtool: Ignore dangling jump table entries (stable-fixes).
  - selftests/cgroup: use bash in test_cpuset_v1_hp.sh
    (stable-fixes).
  - kbuild: Move -Wenum-enum-conversion to W=2 (git-fixes).
  - powercap: call put_device() on an error path in
    powercap_register_control_type() (stable-fixes).
  - selftests: always check mask returned by statmount(2)
    (stable-fixes).
  - net: rose: lock the socket in rose_bind() (git-fixes).
  - irqchip/apple-aic: Only handle PMC interrupt as FIQ when
    configured so (git-fixes).
  - irqchip/irq-mvebu-icu: Fix access to msi_data from
    irq_domain::host_data (git-fixes).
  - irqchip/lan966x-oic: Make CONFIG_LAN966X_OIC depend on
    CONFIG_MCHP_LAN966X_PCI (git-fixes).
  - kbuild: Use -fzero-init-padding-bits=all (stable-fixes).
  - kbuild: suppress stdout from merge_config for silent builds
    (stable-fixes).
  - selftests: gpio: gpio-sim: Fix missing chip disablements
    (stable-fixes).
  - kunit: platform: Resolve 'struct completion' warning
    (stable-fixes).
  - mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id
    (stable-fixes).
  - spi: atmel-qspi: Memory barriers after memory-mapped I/O
    (git-fixes).
  - selftests/net/ipsec: Fix Null pointer dereference in
    rtattr_pack() (stable-fixes).
  - net: wwan: iosm: Fix hibernation by re-binding the driver
    around it (stable-fixes).
  - irqchip: Plug a OF node reference leak in
    platform_irqchip_probe() (git-fixes).
  - selftests: tc-testing: reduce rshift value (stable-fixes).
  - kheaders: Ignore silly-rename files (stable-fixes).
  - kbuild: pacman-pkg: provide versioned linux-api-headers package
    (git-fixes).
  - net: wwan: iosm: Properly check for valid exec stage in
    ipc_mmio_init() (git-fixes).
  - sky2: Add device ID 11ab:4373 for Marvell 88E8075
    (stable-fixes).
  - selftests/alsa: Fix circular dependency involving global-timer
    (stable-fixes).
  - kbuild: switch from lz4c to lz4 for compression (stable-fixes).
  - selftests: rtnetlink: update netdevsim ipsec output format
    (stable-fixes).
  - libsubcmd: Silence compiler warning (stable-fixes).
  - commit 875f3e3
  - efi/libstub: Avoid physical address 0x0 when doing random
    allocation (stable-fixes).
  - efi: Don't map the entire mokvar table to determine its size
    (stable-fixes).
  - ima: Reset IMA_NONACTION_RULE_FLAGS after post_setattr
    (git-fixes).
  - gpio: vf610: add locking to gpio direction functions
    (git-fixes).
  - efi: Avoid cold plugged memory for placing the kernel
    (stable-fixes).
  - Input: allocate keycode for phone linking (stable-fixes).
  - i2c: designware: Actually make use of the I2C_DW_COMMON and
    I2C_DW symbol namespaces (git-fixes).
  - hwmon: (nct6775): Actually make use of the HWMON_NCT6775 symbol
    namespace (git-fixes).
  - Input: serio - define serio_pause_rx guard to pause and resume
    serio ports (stable-fixes).
  - commit dc90670
  - clk: samsung: update PLL locktime for PLL142XX used on FSD
    platform (git-fixes).
  - clk: samsung: gs101: fix synchronous external abort in
    samsung_clk_save() (git-fixes).
  - cpufreq: s3c64xx: Fix compilation warning (stable-fixes).
  - clk: sunxi-ng: a64: drop redundant CLK_PLL_VIDEO0_2X and
    CLK_PLL_MIPI (git-fixes).
  - Documentation: rust: discuss `#[expect(...)]` in the guidelines
    (stable-fixes).
  - Documentation: rust: add coding guidelines on lints
    (stable-fixes).
  - commit 6114330
  - ata: libata-core: Add ATA_QUIRK_NO_LPM_ON_ATI for certain
    Samsung SSDs (git-fixes).
  - ASoC: dapm-graph: set fill colour of turned on nodes
    (stable-fixes).
  - batman-adv: Drop unmanaged ELP metric worker (git-fixes).
  - batman-adv: Ignore neighbor throughput metrics in error case
    (stable-fixes).
  - accel/ivpu: Fix error handling in recovery/reset (git-fixes).
  - ACPI: resource: IRQ override for Eluktronics MECH-17
    (stable-fixes).
  - ACPI: x86: Add skip i2c clients quirk for Vexia EDU ATLA 10
    tablet 5V (stable-fixes).
  - apparmor: allocate xmatch for nullpdb inside aa_alloc_null
    (stable-fixes).
  - commit bbf19e0
  - HID: apple: disable Fn key handling on the Omoton KB066
    (git-fixes).
  - gpio: sim: lock hog configfs items if present (git-fixes).
  - ASoC: samsung: Add missing depends on I2C (git-fixes).
  - thermal: gov_power_allocator: Add missing NULL pointer check
    (git-fixes).
  - commit b2840e7
  - media: i2c: ds90ub953: Add error handling for i2c reads/writes
    (stable-fixes).
  - media: i2c: ds90ub913: Add error handling to ub913_hw_init()
    (stable-fixes).
  - media: cxd2841er: fix 64-bit division on gcc-9 (stable-fixes).
  - commit 5d82128
  - mmc: sdhci-msm: Correctly set the load for the regulator
    (stable-fixes).
  - mmc: sdhci-esdhc-imx: enable 'SDHCI_QUIRK_NO_LED' quirk for S32G
    (stable-fixes).
  - mmc: core: Respect quirk_max_rate for non-UHS SDIO card
    (stable-fixes).
  - commit c3e39a3
  - platform/x86: thinkpad_acpi: disable ACPI fan access for T495*
    and E560 (git-fixes).
  - platform/x86: thinkpad_acpi: Add battery quirk for ThinkPad
    X131e (stable-fixes).
  - platform/x86: int3472: Call "reset" GPIO "enable" for INT347E
    (stable-fixes).
  - platform/x86: int3472: Use correct type for "polarity", call
    it gpio_flags (stable-fixes).
  - platform/x86: thinkpad_acpi: Support for V9 DYTC platform
    profiles (stable-fixes).
  - platform/x86: thinkpad_acpi: Fix invalid fan speed on ThinkPad
    X120e (stable-fixes).
  - platform/x86/intel: pmc: fix ltr decode in pmc_core_ltr_show()
    (stable-fixes).
  - commit 85fd67b
  - platform/x86: acer-wmi: Ignore AC events (stable-fixes).
  - platform/x86: acer-wmi: add support for Acer Nitro AN515-58
    (stable-fixes).
  - platform/x86: acer-wmi: Add support for Acer Predator PH16-72
    (stable-fixes).
  - platform/x86: acer-wmi: Add support for Acer PH14-51
    (stable-fixes).
  - platform/x86: ISST: Add Clearwater Forest to support list
    (stable-fixes).
  - platform/x86/intel: power-domains: Add Clearwater Forest support
    (stable-fixes).
  - platform/x86: thinkpad-acpi: Add support for hotkey 0x1401
    (stable-fixes).
  - platform/x86: hp-wmi: mark 8A15 board for timed OMEN thermal
    profile (stable-fixes).
  - commit f16312f
  - ASoC: SOF: Intel: don't check number of sdw links when set
    dmic_fixup (stable-fixes).
  - ASoC: tas2764: Set the SDOUT polarity correctly (stable-fixes).
  - ASoC: tas2764: Fix power control mask (stable-fixes).
  - ASoC: tas2770: Fix volume scale (stable-fixes).
  - ASoC: SOF: amd: Handle IPC replies before FW_BOOT_COMPLETE
    (stable-fixes).
  - ASoC: SOF: amd: Add post_fw_run_delay ACP quirk (stable-fixes).
  - ASoC: Intel: sof_sdw: Add quirk for Asus Zenbook S14
    (stable-fixes).
  - commit a03c313
  - ASoC: Intel: sof_sdw: Add lookup of quirk using PCI subsystem ID
    (stable-fixes).
  - ASoC: SOF: Intel: hda: add softdep pre to snd-hda-codec-hdmi
    module (stable-fixes).
  - ASoC: arizona/madera: use fsleep() in up/down DAPM event delays
    (stable-fixes).
  - ASoC: simple-card-utils.c: add missing dlc->of_node
    (stable-fixes).
  - ASoC: Intel: soc-acpi-intel-mtl-match: declare adr as ull
    (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla
    10 tablet 5V (stable-fixes).
  - ASoC: amd: Add ACPI dependency to fix build error
    (stable-fixes).
  - commit 8395ba3
  - ALSA: hda: cs35l56: Remove calls to
    cs35l56_force_sync_asp1_registers_from_cache() (stable-fixes).
  - Refresh
    patches.suse/ASoC-cs35l56-Prevent-races-when-soft-resetting-using.patch.
  - commit e8d62b1
  - ASoC: Intel: sof_sdw: Correct quirk for Lenovo Yoga Slim 7
    (stable-fixes).
  - ASoC: cs42l43: Add codec force suspend/resume ops
    (stable-fixes).
  - ASoC: samsung: Add missing selects for MFD_WM8994
    (stable-fixes).
  - ASoC: codecs: es8316: Fix HW rate calculation for 48Mhz MCLK
    (stable-fixes).
  - ASoC: wm8994: Add depends on MFD core (stable-fixes).
  - ASoC: mediatek: disable buffer pre-allocation (stable-fixes).
  - ASoC: rt722: add delay time to wait for the calibration
    procedure (stable-fixes).
  - ASoC: audio-graph-card: Call of_node_put() on correct node
    (stable-fixes).
  - ALSA: hda/ca0132: Use standard HD-audio quirk matching helpers
    (stable-fixes).
  - commit d94e804
  - Input: i8042 - swap old quirk combination with new quirk for
    more devices (stable-fixes).
  - Input: i8042 - swap old quirk combination with new quirk for
    several devices (stable-fixes).
  - Input: i8042 - add required quirks for missing old boardnames
    (stable-fixes).
  - Input: i8042 - swap old quirk combination with new quirk for
    NHxxRZQ (stable-fixes).
  - Input: xpad - rename QH controller to Legion Go S
    (stable-fixes).
  - Input: xpad - add support for TECNO Pocket Go (stable-fixes).
  - Input: xpad - add support for ZOTAC Gaming Zone (stable-fixes).
  - Input: xpad - add multiple supported devices (stable-fixes).
  - Input: xpad - add 8BitDo SN30 Pro, Hyperkin X91 and Gamesir
    G7 SE controllers (stable-fixes).
  - commit c0214ef
  - tty: serial: 8250: Add Brainboxes XC devices (stable-fixes).
  - tty: serial: 8250: Add some more device IDs (stable-fixes).
  - HID: hid-plantronics: Add mic mute mapping and generalize quirks
    (stable-fixes).
  - commit 27219be
  - intel_th: pci: Add Panther Lake-P/U support (stable-fixes).
  - intel_th: pci: Add Panther Lake-H support (stable-fixes).
  - intel_th: pci: Add Arrow Lake support (stable-fixes).
  - mei: me: add panther lake P DID (stable-fixes).
  - gpio: rcar: Use raw_spinlock to protect register access
    (stable-fixes).
  - phy: ti: gmii-sel: Do not use syscon helper to build regmap
    (stable-fixes).
  - irqchip/gic-v3: Fix rk3399 workaround when secure interrupts
    are enabled (git-fixes).
  - gpiolib: protect gpio_chip with SRCU in array_info paths in
    multi get/set (stable-fixes).
  - commit a763c51
  - gpiolib: acpi: Add a quirk for Acer Nitro ANV14 (stable-fixes).
  - thermal/cpufreq_cooling: Remove structure member documentation
    (stable-fixes).
  - HID: apple: fix up the F6 key on the Omoton KB066 keyboard
    (stable-fixes).
  - HID: hid-apple: Apple Magic Keyboard a3203 USB-C support
    (stable-fixes).
  - HID: topre: Fix n-key rollover on Realforce R3S TKL boards
    (stable-fixes).
  - HID: intel-ish-hid: ipc: Add Panther Lake PCI device IDs
    (stable-fixes).
  - HID: hid-steam: Fix issues with disabling both gamepad mode
    and lizard mode (stable-fixes).
  - HID: ignore non-functional sensor in HP 5MP Camera
    (stable-fixes).
  - HID: intel-ish-hid: Send clock sync message immediately after
    reset (stable-fixes).
  - HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in
    doorbell (stable-fixes).
  - serial: 8250_pci: Share WCH IDs with parport_serial driver
    (stable-fixes).
  - commit 2b5b959
  - Update config files: config files: CONFIG_MIPI_I3C_HCI_PCI=m
  - supported.con
  - commit 52bee05
  - HID: hid-steam: Make sure rumble work is canceled on removal
    (stable-fixes).
  - Refresh
    patches.suse/HID-hid-steam-Fix-use-after-free-when-detaching-devi.patch.
  - Refresh
    patches.suse/HID-hid-steam-Move-hidraw-input-un-registering-to-wo.patch.
  - commit 051b5d1
  - i3c: mipi-i3c-hci: Add support for MIPI I3C HCI on PCI bus
    (stable-fixes).
  - i3c: mipi-i3c-hci: Add Intel specific quirk to ring resuming
    (stable-fixes).
  - soc/tegra: fuse: Update Tegra234 nvmem keepout list
    (stable-fixes).
  - HID: Wacom: Add PCI Wacom device support (stable-fixes).
  - HID: hid-asus: Disable OOBE mode on the ProArt P16
    (stable-fixes).
  - HID: multitouch: Add quirk for Hantick 5288 touchpad
    (stable-fixes).
  - commit cee8b14
  - i2c: Force ELAN06FA touchpad I2C bus freq to 100KHz
    (stable-fixes).
  - spi: atmel-quadspi: Create `atmel_qspi_ops` to support newer
    SoC families (stable-fixes).
  - irqchip/sunxi-nmi: Add missing SKIP_WAKE flag (stable-fixes).
  - of/unittest: Add test that of_address_to_resource() fails on
    non-translatable address (stable-fixes).
  - hwmon: (drivetemp) Set scsi command timeout to 10s
    (stable-fixes).
  - gpio: sim: lock up configfs that an instantiated device depends
    on (stable-fixes).
  - gpio: virtuser: lock up configfs that an instantiated device
    depends on (stable-fixes).
  - irqchip/gic: Correct declaration of *percpu_base pointer in
    union gic_base (stable-fixes).
  - spi: spi-cadence-qspi: Disable STIG mode for Altera SoCFPGA
    (stable-fixes).
  - thermal: of: Simplify thermal_of_should_bind with scoped for
    each OF child (stable-fixes).
  - commit 3bac618
  - accel/ivpu: Add FW state dump on TDR (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Prevent-recovery-invocation-during-probe-.patch.
  - commit e154818
  - accel/ivpu: Add coredump support (stable-fixes).
  - accel/ivpu: Limit FW version string length (stable-fixes).
  - thermal: core: Move lists of thermal instances to trip
    descriptors (stable-fixes).
  - commit 1b6fd5f
  - Bluetooth: qca: Fix poor RF performance for WCN6855 (git-fixes).
  - commit 8f8d064
  - Bluetooth: qca: Update firmware-name to support board specific
    nvm (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3628 for MT7925
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3610 for MT7922
    (stable-fixes).
  - commit ff34f1d
  - Input: xpad - rename QH controller to Legion Go S (git-fixes).
  - commit aba26a6
  - Input: xpad - add support for TECNO Pocket Go (git-fixes).
  - Input: xpad - add support for ZOTAC Gaming Zone (git-fixes).
  - commit d081c97
  - Input: xpad - add multiple supported devices (git-fixes).
  - commit 8c43ca9
  - Input: xpad - add 8BitDo SN30 Pro, Hyperkin X91 and Gamesir
    G7 SE controllers (git-fixes).
  - commit a67b5a7
  - regulator: check that dummy regulator has been probed before
    using it (CVE-2025-22008 bsc#1240942).
  - commit eab7c21
  - io_uring/uring_cmd: unconditionally copy SQEs at prep time
    (CVE-2025-21837 bsc#1239064).
  - io_uring/uring_cmd: switch sqe to async_data on EAGAIN
    (CVE-2025-21837 bsc#1239064).
  - commit f44e166

++++ kernel-rt:

  - Revert "kheaders: Ignore silly-rename files" (stable-fixes).
  - rust: kbuild: add -fzero-init-padding-bits to
    bindgen_skip_cflags (git-fixes).
  - docs: rust: remove spurious item in `expect` list (git-fixes).
  - commit 2d49340
  - USB: serial: ftdi_sio: add support for Altera USB Blaster 3
    (stable-fixes).
  - USB: serial: option: fix Telit Cinterion FE990A name
    (stable-fixes).
  - USB: serial: option: add Telit Cinterion FE990B compositions
    (stable-fixes).
  - USB: serial: option: match on interface class for Telit FN990B
    (stable-fixes).
  - thermal: gov_power_allocator: Update total_weight on bind and
    cdev updates (git-fixes).
  - vmlinux.lds: Ensure that const vars with relocations are mapped
    R/O (stable-fixes).
  - usb: phy: generic: Use proper helper for property detection
    (stable-fixes).
  - commit cf7a1fa
  - selftests/mm: run_vmtests.sh: fix half_ufd_size_MB calculation
    (git-fixes).
  - net: phy: nxp-c45-tja11xx: add TJA112XB SGMII PCS restart errata
    (git-fixes).
  - net: phy: nxp-c45-tja11xx: add TJA112X PHY configuration errata
    (git-fixes).
  - kbuild: userprogs: use correct lld when linking through clang
    (git-fixes).
  - thermal/of: Fix cdev lookup in thermal_of_should_bind()
    (git-fixes).
  - selftests/landlock: Test that MPTCP actions are not restricted
    (stable-fixes).
  - selftests/landlock: Test TCP accesses with protocol=IPPROTO_TCP
    (stable-fixes).
  - irqchip/jcore-aic, clocksource/drivers/jcore: Fix jcore-pit
    interrupt request (git-fixes).
  - net: wwan: mhi_wwan_mbim: Silence sequence number glitch errors
    (stable-fixes).
  - objtool: Ignore dangling jump table entries (stable-fixes).
  - selftests/cgroup: use bash in test_cpuset_v1_hp.sh
    (stable-fixes).
  - kbuild: Move -Wenum-enum-conversion to W=2 (git-fixes).
  - powercap: call put_device() on an error path in
    powercap_register_control_type() (stable-fixes).
  - selftests: always check mask returned by statmount(2)
    (stable-fixes).
  - net: rose: lock the socket in rose_bind() (git-fixes).
  - irqchip/apple-aic: Only handle PMC interrupt as FIQ when
    configured so (git-fixes).
  - irqchip/irq-mvebu-icu: Fix access to msi_data from
    irq_domain::host_data (git-fixes).
  - irqchip/lan966x-oic: Make CONFIG_LAN966X_OIC depend on
    CONFIG_MCHP_LAN966X_PCI (git-fixes).
  - kbuild: Use -fzero-init-padding-bits=all (stable-fixes).
  - kbuild: suppress stdout from merge_config for silent builds
    (stable-fixes).
  - selftests: gpio: gpio-sim: Fix missing chip disablements
    (stable-fixes).
  - kunit: platform: Resolve 'struct completion' warning
    (stable-fixes).
  - mfd: lpc_ich: Add another Gemini Lake ISA bridge PCI device-id
    (stable-fixes).
  - spi: atmel-qspi: Memory barriers after memory-mapped I/O
    (git-fixes).
  - selftests/net/ipsec: Fix Null pointer dereference in
    rtattr_pack() (stable-fixes).
  - net: wwan: iosm: Fix hibernation by re-binding the driver
    around it (stable-fixes).
  - irqchip: Plug a OF node reference leak in
    platform_irqchip_probe() (git-fixes).
  - selftests: tc-testing: reduce rshift value (stable-fixes).
  - kheaders: Ignore silly-rename files (stable-fixes).
  - kbuild: pacman-pkg: provide versioned linux-api-headers package
    (git-fixes).
  - net: wwan: iosm: Properly check for valid exec stage in
    ipc_mmio_init() (git-fixes).
  - sky2: Add device ID 11ab:4373 for Marvell 88E8075
    (stable-fixes).
  - selftests/alsa: Fix circular dependency involving global-timer
    (stable-fixes).
  - kbuild: switch from lz4c to lz4 for compression (stable-fixes).
  - selftests: rtnetlink: update netdevsim ipsec output format
    (stable-fixes).
  - libsubcmd: Silence compiler warning (stable-fixes).
  - commit 875f3e3
  - efi/libstub: Avoid physical address 0x0 when doing random
    allocation (stable-fixes).
  - efi: Don't map the entire mokvar table to determine its size
    (stable-fixes).
  - ima: Reset IMA_NONACTION_RULE_FLAGS after post_setattr
    (git-fixes).
  - gpio: vf610: add locking to gpio direction functions
    (git-fixes).
  - efi: Avoid cold plugged memory for placing the kernel
    (stable-fixes).
  - Input: allocate keycode for phone linking (stable-fixes).
  - i2c: designware: Actually make use of the I2C_DW_COMMON and
    I2C_DW symbol namespaces (git-fixes).
  - hwmon: (nct6775): Actually make use of the HWMON_NCT6775 symbol
    namespace (git-fixes).
  - Input: serio - define serio_pause_rx guard to pause and resume
    serio ports (stable-fixes).
  - commit dc90670
  - clk: samsung: update PLL locktime for PLL142XX used on FSD
    platform (git-fixes).
  - clk: samsung: gs101: fix synchronous external abort in
    samsung_clk_save() (git-fixes).
  - cpufreq: s3c64xx: Fix compilation warning (stable-fixes).
  - clk: sunxi-ng: a64: drop redundant CLK_PLL_VIDEO0_2X and
    CLK_PLL_MIPI (git-fixes).
  - Documentation: rust: discuss `#[expect(...)]` in the guidelines
    (stable-fixes).
  - Documentation: rust: add coding guidelines on lints
    (stable-fixes).
  - commit 6114330
  - ata: libata-core: Add ATA_QUIRK_NO_LPM_ON_ATI for certain
    Samsung SSDs (git-fixes).
  - ASoC: dapm-graph: set fill colour of turned on nodes
    (stable-fixes).
  - batman-adv: Drop unmanaged ELP metric worker (git-fixes).
  - batman-adv: Ignore neighbor throughput metrics in error case
    (stable-fixes).
  - accel/ivpu: Fix error handling in recovery/reset (git-fixes).
  - ACPI: resource: IRQ override for Eluktronics MECH-17
    (stable-fixes).
  - ACPI: x86: Add skip i2c clients quirk for Vexia EDU ATLA 10
    tablet 5V (stable-fixes).
  - apparmor: allocate xmatch for nullpdb inside aa_alloc_null
    (stable-fixes).
  - commit bbf19e0
  - HID: apple: disable Fn key handling on the Omoton KB066
    (git-fixes).
  - gpio: sim: lock hog configfs items if present (git-fixes).
  - ASoC: samsung: Add missing depends on I2C (git-fixes).
  - thermal: gov_power_allocator: Add missing NULL pointer check
    (git-fixes).
  - commit b2840e7
  - media: i2c: ds90ub953: Add error handling for i2c reads/writes
    (stable-fixes).
  - media: i2c: ds90ub913: Add error handling to ub913_hw_init()
    (stable-fixes).
  - media: cxd2841er: fix 64-bit division on gcc-9 (stable-fixes).
  - commit 5d82128
  - mmc: sdhci-msm: Correctly set the load for the regulator
    (stable-fixes).
  - mmc: sdhci-esdhc-imx: enable 'SDHCI_QUIRK_NO_LED' quirk for S32G
    (stable-fixes).
  - mmc: core: Respect quirk_max_rate for non-UHS SDIO card
    (stable-fixes).
  - commit c3e39a3
  - platform/x86: thinkpad_acpi: disable ACPI fan access for T495*
    and E560 (git-fixes).
  - platform/x86: thinkpad_acpi: Add battery quirk for ThinkPad
    X131e (stable-fixes).
  - platform/x86: int3472: Call "reset" GPIO "enable" for INT347E
    (stable-fixes).
  - platform/x86: int3472: Use correct type for "polarity", call
    it gpio_flags (stable-fixes).
  - platform/x86: thinkpad_acpi: Support for V9 DYTC platform
    profiles (stable-fixes).
  - platform/x86: thinkpad_acpi: Fix invalid fan speed on ThinkPad
    X120e (stable-fixes).
  - platform/x86/intel: pmc: fix ltr decode in pmc_core_ltr_show()
    (stable-fixes).
  - commit 85fd67b
  - platform/x86: acer-wmi: Ignore AC events (stable-fixes).
  - platform/x86: acer-wmi: add support for Acer Nitro AN515-58
    (stable-fixes).
  - platform/x86: acer-wmi: Add support for Acer Predator PH16-72
    (stable-fixes).
  - platform/x86: acer-wmi: Add support for Acer PH14-51
    (stable-fixes).
  - platform/x86: ISST: Add Clearwater Forest to support list
    (stable-fixes).
  - platform/x86/intel: power-domains: Add Clearwater Forest support
    (stable-fixes).
  - platform/x86: thinkpad-acpi: Add support for hotkey 0x1401
    (stable-fixes).
  - platform/x86: hp-wmi: mark 8A15 board for timed OMEN thermal
    profile (stable-fixes).
  - commit f16312f
  - ASoC: SOF: Intel: don't check number of sdw links when set
    dmic_fixup (stable-fixes).
  - ASoC: tas2764: Set the SDOUT polarity correctly (stable-fixes).
  - ASoC: tas2764: Fix power control mask (stable-fixes).
  - ASoC: tas2770: Fix volume scale (stable-fixes).
  - ASoC: SOF: amd: Handle IPC replies before FW_BOOT_COMPLETE
    (stable-fixes).
  - ASoC: SOF: amd: Add post_fw_run_delay ACP quirk (stable-fixes).
  - ASoC: Intel: sof_sdw: Add quirk for Asus Zenbook S14
    (stable-fixes).
  - commit a03c313
  - ASoC: Intel: sof_sdw: Add lookup of quirk using PCI subsystem ID
    (stable-fixes).
  - ASoC: SOF: Intel: hda: add softdep pre to snd-hda-codec-hdmi
    module (stable-fixes).
  - ASoC: arizona/madera: use fsleep() in up/down DAPM event delays
    (stable-fixes).
  - ASoC: simple-card-utils.c: add missing dlc->of_node
    (stable-fixes).
  - ASoC: Intel: soc-acpi-intel-mtl-match: declare adr as ull
    (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla
    10 tablet 5V (stable-fixes).
  - ASoC: amd: Add ACPI dependency to fix build error
    (stable-fixes).
  - commit 8395ba3
  - ALSA: hda: cs35l56: Remove calls to
    cs35l56_force_sync_asp1_registers_from_cache() (stable-fixes).
  - Refresh
    patches.suse/ASoC-cs35l56-Prevent-races-when-soft-resetting-using.patch.
  - commit e8d62b1
  - ASoC: Intel: sof_sdw: Correct quirk for Lenovo Yoga Slim 7
    (stable-fixes).
  - ASoC: cs42l43: Add codec force suspend/resume ops
    (stable-fixes).
  - ASoC: samsung: Add missing selects for MFD_WM8994
    (stable-fixes).
  - ASoC: codecs: es8316: Fix HW rate calculation for 48Mhz MCLK
    (stable-fixes).
  - ASoC: wm8994: Add depends on MFD core (stable-fixes).
  - ASoC: mediatek: disable buffer pre-allocation (stable-fixes).
  - ASoC: rt722: add delay time to wait for the calibration
    procedure (stable-fixes).
  - ASoC: audio-graph-card: Call of_node_put() on correct node
    (stable-fixes).
  - ALSA: hda/ca0132: Use standard HD-audio quirk matching helpers
    (stable-fixes).
  - commit d94e804
  - Input: i8042 - swap old quirk combination with new quirk for
    more devices (stable-fixes).
  - Input: i8042 - swap old quirk combination with new quirk for
    several devices (stable-fixes).
  - Input: i8042 - add required quirks for missing old boardnames
    (stable-fixes).
  - Input: i8042 - swap old quirk combination with new quirk for
    NHxxRZQ (stable-fixes).
  - Input: xpad - rename QH controller to Legion Go S
    (stable-fixes).
  - Input: xpad - add support for TECNO Pocket Go (stable-fixes).
  - Input: xpad - add support for ZOTAC Gaming Zone (stable-fixes).
  - Input: xpad - add multiple supported devices (stable-fixes).
  - Input: xpad - add 8BitDo SN30 Pro, Hyperkin X91 and Gamesir
    G7 SE controllers (stable-fixes).
  - commit c0214ef
  - tty: serial: 8250: Add Brainboxes XC devices (stable-fixes).
  - tty: serial: 8250: Add some more device IDs (stable-fixes).
  - HID: hid-plantronics: Add mic mute mapping and generalize quirks
    (stable-fixes).
  - commit 27219be
  - intel_th: pci: Add Panther Lake-P/U support (stable-fixes).
  - intel_th: pci: Add Panther Lake-H support (stable-fixes).
  - intel_th: pci: Add Arrow Lake support (stable-fixes).
  - mei: me: add panther lake P DID (stable-fixes).
  - gpio: rcar: Use raw_spinlock to protect register access
    (stable-fixes).
  - phy: ti: gmii-sel: Do not use syscon helper to build regmap
    (stable-fixes).
  - irqchip/gic-v3: Fix rk3399 workaround when secure interrupts
    are enabled (git-fixes).
  - gpiolib: protect gpio_chip with SRCU in array_info paths in
    multi get/set (stable-fixes).
  - commit a763c51
  - gpiolib: acpi: Add a quirk for Acer Nitro ANV14 (stable-fixes).
  - thermal/cpufreq_cooling: Remove structure member documentation
    (stable-fixes).
  - HID: apple: fix up the F6 key on the Omoton KB066 keyboard
    (stable-fixes).
  - HID: hid-apple: Apple Magic Keyboard a3203 USB-C support
    (stable-fixes).
  - HID: topre: Fix n-key rollover on Realforce R3S TKL boards
    (stable-fixes).
  - HID: intel-ish-hid: ipc: Add Panther Lake PCI device IDs
    (stable-fixes).
  - HID: hid-steam: Fix issues with disabling both gamepad mode
    and lizard mode (stable-fixes).
  - HID: ignore non-functional sensor in HP 5MP Camera
    (stable-fixes).
  - HID: intel-ish-hid: Send clock sync message immediately after
    reset (stable-fixes).
  - HID: intel-ish-hid: fix the length of MNG_SYNC_FW_CLOCK in
    doorbell (stable-fixes).
  - serial: 8250_pci: Share WCH IDs with parport_serial driver
    (stable-fixes).
  - commit 2b5b959
  - Update config files: config files: CONFIG_MIPI_I3C_HCI_PCI=m
  - supported.con
  - commit 52bee05
  - HID: hid-steam: Make sure rumble work is canceled on removal
    (stable-fixes).
  - Refresh
    patches.suse/HID-hid-steam-Fix-use-after-free-when-detaching-devi.patch.
  - Refresh
    patches.suse/HID-hid-steam-Move-hidraw-input-un-registering-to-wo.patch.
  - commit 051b5d1
  - i3c: mipi-i3c-hci: Add support for MIPI I3C HCI on PCI bus
    (stable-fixes).
  - i3c: mipi-i3c-hci: Add Intel specific quirk to ring resuming
    (stable-fixes).
  - soc/tegra: fuse: Update Tegra234 nvmem keepout list
    (stable-fixes).
  - HID: Wacom: Add PCI Wacom device support (stable-fixes).
  - HID: hid-asus: Disable OOBE mode on the ProArt P16
    (stable-fixes).
  - HID: multitouch: Add quirk for Hantick 5288 touchpad
    (stable-fixes).
  - commit cee8b14
  - i2c: Force ELAN06FA touchpad I2C bus freq to 100KHz
    (stable-fixes).
  - spi: atmel-quadspi: Create `atmel_qspi_ops` to support newer
    SoC families (stable-fixes).
  - irqchip/sunxi-nmi: Add missing SKIP_WAKE flag (stable-fixes).
  - of/unittest: Add test that of_address_to_resource() fails on
    non-translatable address (stable-fixes).
  - hwmon: (drivetemp) Set scsi command timeout to 10s
    (stable-fixes).
  - gpio: sim: lock up configfs that an instantiated device depends
    on (stable-fixes).
  - gpio: virtuser: lock up configfs that an instantiated device
    depends on (stable-fixes).
  - irqchip/gic: Correct declaration of *percpu_base pointer in
    union gic_base (stable-fixes).
  - spi: spi-cadence-qspi: Disable STIG mode for Altera SoCFPGA
    (stable-fixes).
  - thermal: of: Simplify thermal_of_should_bind with scoped for
    each OF child (stable-fixes).
  - commit 3bac618
  - accel/ivpu: Add FW state dump on TDR (stable-fixes).
  - Refresh
    patches.suse/accel-ivpu-Prevent-recovery-invocation-during-probe-.patch.
  - commit e154818
  - accel/ivpu: Add coredump support (stable-fixes).
  - accel/ivpu: Limit FW version string length (stable-fixes).
  - thermal: core: Move lists of thermal instances to trip
    descriptors (stable-fixes).
  - commit 1b6fd5f
  - Bluetooth: qca: Fix poor RF performance for WCN6855 (git-fixes).
  - commit 8f8d064
  - Bluetooth: qca: Update firmware-name to support board specific
    nvm (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3628 for MT7925
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 13d3/3610 for MT7922
    (stable-fixes).
  - commit ff34f1d
  - Input: xpad - rename QH controller to Legion Go S (git-fixes).
  - commit aba26a6
  - Input: xpad - add support for TECNO Pocket Go (git-fixes).
  - Input: xpad - add support for ZOTAC Gaming Zone (git-fixes).
  - commit d081c97
  - Input: xpad - add multiple supported devices (git-fixes).
  - commit 8c43ca9
  - Input: xpad - add 8BitDo SN30 Pro, Hyperkin X91 and Gamesir
    G7 SE controllers (git-fixes).
  - commit a67b5a7
  - regulator: check that dummy regulator has been probed before
    using it (CVE-2025-22008 bsc#1240942).
  - commit eab7c21
  - io_uring/uring_cmd: unconditionally copy SQEs at prep time
    (CVE-2025-21837 bsc#1239064).
  - io_uring/uring_cmd: switch sqe to async_data on EAGAIN
    (CVE-2025-21837 bsc#1239064).
  - commit f44e166

++++ gcc15:

  - Update to GCC trunk head, 15.0.1+git9352
  - Make sure link editing is done against our own shared library
    copy rather than the installed system runtime.  [bsc#1240788]
  - Add newlib-gcn-libm-fix.patch to fix newlib libm miscompilation
    for GCN offloading.

++++ leancrypto:

  - updated to 1.3.0
    * Allow CPU entropy sources to be used as seed sources with meson option "seedsource=cpu"
    * Ensure full clean run on vintage system without AVX2 (thanks to "David C. Rankin" <drankinatty@gmail.com>)
    * EFI: compilation support on AARCH64
    * Meson: reduce number of object files to speed up compilation process
    * Intel assembler: add endbr[64|32] to every function and ensure IBT is enabled
    * ARMv8 assembler / ELF: add BTI and PAC support
    * *Full FIPS 140 compliance*: Invoke PCT, add integrity test for ELF compilations, enable FIPS compilation by default
    * ML-DSA: add external-mu support; new API: lc_dilithium_ctx_external_mu
    * Add optional Jitter RNG entropy source
    * Add SLH-DSA-Ascon-128[s|f]  (by default they are disabled, enable with meson configuration options `slh_dsa_ascon_128s` and `slh_dsa_ascon_128f`)
    * ML-KEM: use common poly_tobytes / poly_compress including fix for kyberslash for ARMv8 (thus all ML-KEM implementations have proper protections against it)
    * ML-KEM: reduce code duplication
    * Big-Endian: fixes on X.509 key usage processing, ML-KEM modulus tester
  - Changes 1.2.0
    * Locking für seeded_rng added to avoid requiring the caller providing a lock
    * Addition of ASN.1 decoder, X.509 parser, PKCS#7 / CMS parser
    * Addition of ASN.1 encoder, X.509 generator, PKCS#7 / CMS generator for ML-DSA, SLH-DSA, ML-DSA-ED25519
    * ML-DSA-ED25519: Hybrid implementation changed to match definition https://www.ietf.org/archive/id/draft-ietf-lamps-pq-composite-sigs-03.html
    * RISCV64: Keccak - add assembler and ZBB implementation
    * RISCV64: ML-KEM - add assembler implementation
    * RISCV64: ML-DSA - add assembler implementation
    * Add FIPS 140 mode (as of now, it does not yet implement full FIPS 140 compliance)
    * Ascon AEAD, Hash, XOF, Ascon-Keccak: Update to comply with SP800-232
    * Dilithium AVX2: Add side channel analysis
    * leancrypto passes X.509 IETF-Hackathon tests: https://ietf-hackathon.github.io/pqc-certificates/pqc_hackathon_results_certs_r4_automated_tests.html
    * Add compilation support for (U)EFI environment
    * RISCV64 RVV: ML-KEM, ML-DSA - add assembler implementation using RVV support
    * Seeded DRNG: Require a reseed after 2**14 bytes to comply with AIS20/31 3.0 DRG.4 and the discussed upcoming changes to SP800-90A.
    * SHA-512 / 384 / 256: Addition of AVX2, SHA_NI, SHA_NI-512, ARMv8 Neon, ARMv8 CE, RISCV ASM, RISCV ZBB acceleration
    * Add lc_init API
    * Intel non-AVX2 systems: remove all SIGILL causes by ensuring no AVX2 code is executed
    * Linux kernel: support version 6.13 kernel crypto signature API
    * Allow switching the central leancrypto seeded RNG instance with a caller-provided RNG
    * ML-KEM: fix poly_frombytes to perform the loading operation modulo 3329 (instead of modulo 4096) - thanks to Daiki Ueno for reporting it
  - Changes 1.1.0
    * ML-KEM remove modulus check of decapsulation key (not required by FIPS 203)
    * ML-KEM: add key pair PCT API - leancrypto cannot invoke it itself as it does not know when both keys are provided from outside
    * ML-DSA: add consistency with FIPS 204 - the signature changes as the input data handling is added (if you want to apply the old signature, use the new lc_dilithium_[sign|verify]_ctx API with ctx->ml_dsa_internal = 1)
    * ML-DSA: add API to allow caller to provide a user context as allowed by FIPS 204, to invoke ML-DSA.Sign_internal, ML-DSA.Verify_internal and HashML-DSA
    * ML-KEM: rename source code directory to ml-kem
    * ML-DSA: rename source code directory to ml-dsa
    * BIKE: Add NIST round 4 KEM candiate
    * ML-DSA: Add support to retain the expanded key to increase the performance of signature operations by 15 to 20%
    * ML-DSA: add key pair PCT API - leancrypto will not invoke it, but provides it for FIPS 140 support
    * SLH-DSA: Add SLH-DSA-SHAKE-256s, SLH-DSA-SHAKE-256f, SLH-DSA-SHAKE-192s, SLH-DSA-SHAKE-192f, SLH-DSA-SHAKE-128s, SLH-DSA-SHAKE-128f
    * ML-DSA, ML-KEM, SLH-DSA, BIKE, Hash, AEAD, RNG, HMAC, HKDF, symmetric: move API implementation from H to C file - this implies that no RUST wrappers are needed
    * Linux kernel: ML-DSA / SLH-DSA sigver input changed to be compliant to existing kernel structures: req->src SGL contains signature || msg, req->dst SGL is not processed
  - Changes 1.0.1
    * fix: Kyber keygen - add LC_KYBER_K to initial hash (change is only relevant when storing keys as seed and for interoperability)
    * fix: Dilithium keygen - add dimensions K and L (change is only relevant when storing keys as seed and for interoperability)
    * small performance improvements for hasher apps
  - Changes 1.0.0
    * enhancement: add Doxygen support - it is automatically compiled if Doxygen is present
    * enhancement: add Dilithium-ED25519 stream mode operation (i.e. init/update/final)
    * due to the Dilithium-ED25519 stream mode support, the Dilithium-ED25519 now used ED25519ph signature algorithm mode
    * Dilithium API change: the stream mode uses struct lc_dilithium_ctx instead of lc_hash_ctx to reflect the newly added Dilithium-ED25519 API - the lc_dilithium_ctx can be allocated on the stack or heap using LC_DILITHIUM_CTX_ON_STACK or lc_dilithium_ctx_alloc
    * enhancement: add Dilithium-ED25519 as Linux kernel akcipher algorithm
    * enhancement: make Kyber-X25519 as Linux kernel kpp algorithm consistent with the standalone Kyber kpp implementation and add a tester
    * seeded_rng: when using the ESDM as entropy source, use DRBG without prediction resistance. When having heavy respawning of applications, using the PR DRBG will strain the entropy source significantly.
    * Dilithium: add edge case tests as referenced by https://github.com/usnistgov/ACVP/pull/1525.patch and https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/G8Zf0hC-uu0/m/Kb3qNJb0AwAJ
  - Changes 0.11.0
    * security fix: fix possible leak of message in Kyber
    * Kyber: reduce memory footprint, use common lc_memcmp_secure API
    * Ascon-Keccak: include the tag length into the IV and thus implicitly authenticate the tag length (thanks to Markku-Juhani Saarinen to suggest this)
    * Kyber: change standard API such that caller can select Kyber type
    * Dilithium: change standard API such that caller can select Dilithium type
    * security: addition of Timecop and instrumentation of tests to find side-channels
    * enhancement: add Linux kernel crypto API support for Ascon / Ascon-Keccak
    * fix: performance of seeded RNG by setting reseed threshold to 1MB
    * fix: Linux kernel warning on return thunk
    * enhancement: add ASM ARMv7 and ARMv8 implementation for X25519
    * enhancement: add Ascon support for XDRBG
    * enhancement: performance increase for XDRBG256
    * enhancement: add ED25519ph to support Dilithium hybrid init/update/final handling
  - Changes 0.10.1
    * enhancement: Linux kernel - Kyber: allow parallel compilation of all Kyber types including all optimizations
    * enhancement: Linux kernel - Dilithium: allow parallel compilation of all Dilithium types including all optimizations
    * add additional hardening compiler flags stipulated by openssf.org
  - Changes 0.10.0
    * enhancement: add Sponge APIs
    * enhancement: add Ascon Keccak 512 and 256
    * update AEAD: add lc_aead_enc|dec_init and change all AEAD algo's tag calculation to now perform MAC(AAD || ciphertext) instead of MAC(ciphertext || AAD) - this brings it in line with all AEAD algorithms
    * enhancement: add Ascon AEAD 128 and 128b
    * rename API lc_shake to lc_xof
    * enhancement: add Ascon Hash 128 and 128a
    * enhancement: add Ascon XOF and XOFa
    * enhancement: add Ascon 128/128a hasher apps
    * large data tests can now execute on small systems by using smaller memory sizes
    * remove riscv64 hash assembler directory: it is a duplicate of the riscv32 assembler code
    * Kyber 768: Add AVX2, ARMv8, ARMv7 support
    * Dilithium 65: Add AVX2, ARMv8, ARMv7 support
    * Enable compilation of Kyber 1024, Kyber-768 and Kyber-512 at the same time (APIs starting with lc_kyber_768/lc_kex_768 refer to Kyber-768, APIs starting with lc_kyber_512/lc_kex_512 refer to Kyber-512, all others refer to Kyber-1024)
    * Enable compilation of Dilithium 87, Dilithium-65 and Dilithium-44 at the same time (APIs starting with lc_dilithium_65 refer to Dilithium-768, APIs starting with lc_dilithium_44 refer to Dilithium-44, all others refer to Dilithium-87)
    * enhancement: Windows is now supported as target platform using the MINGW compiler with full acceleration support
    * Dilithium: update SampleInBall implementation following https://groups.google.com/a/list.nist.gov/g/pqc-forum/c/y8ul-ZcVWI4 - implementation is fully checked against NIST ACVP Demo server
  - Changes 0.9.2
    * fix: update "reduce memory footprint of Keccak state" to handle big-endian systems
    * enhancement: Seed the lc_seeded_rng with (random.c || Jitter RNG)
  - Changes 0.9.1
    * fix: move XOR-256 memory definitions to lc_memory_support.h as otherwise compilation of external applications and libraries fail due to missing xor256.h
  - Changes 0.9.0
    * enhancement: X/ED25519: enable 128 bit mode on Intel for both, kernel and user
    space
    * add Rust binding support
    * enhancement: reduce memory footprint of Keccak state
    * enhancement: add cSHAKE re-init support
    * fix: KMAC-AEAD / cSHAKE-AEAD - ensure proper re-initialization
    * enhancement: add RISC-V 64 bit Keccak - currently disabled due to a bug
    * enhancement: compile Dilithium ARMv8 support in Linux kernel (excluding the SIMD Keccak operation)
    * fix: fix ARM-CE detection logic
    * fix: potential Kyber side channel
    * fix: KMAC min MAC size is 32 bits
    * enhancement: use accelerated XOR for KMAC/cSHAKE AEAD
    * fix: enable poly_compress_avx for Linux kernel compilation when GCC >= 13 is present
    * enhancement: add interface code to register leancrypto with Linux kernel crypto API
  - Changes 0.8.0:
    * enhancement: add applications
    * enhancement: add Dilithium ARMv8 support (including SHAKE 2x ARMv8 support)
    * enhancement: add Dilithium ARMv7 support
    * enhancement: add Kyber ARMv7 support
    * reduce memory footprint of Dilithium and Kyber
    * enhancement: Add Kyber-X25519 KEM, KEX, and IES
    * enhancement: Add Dilithium-ED25519
    * hardening: use -fzero-call-used-regs=used-gpr if available to counter ROP
    attacks
    * fix: Add fork-detection for seeded_rng
    * update XDRBG256 implementation based on latest draft
  - Changes 0.7.0:
    * enhancement: add XDRBG256 - the SHAKE256-based DRNG discussed for SP800-90A
    inclusion (almost idential to cSHAKE/KMAC DRNG specified with leancrypto)
    * enhancement: add SymKMAC AEAD algorithm - it uses 100 bytes less context than
    SymHMAC (it is less than 1024 bytes now), uses accelerated Keccak for KDF and
    authentication but is otherwise identical to SymHMAC
    * Kyber: switch responder and initiator definitions
    * enhancement: add ESDM seed source to seed lc_seeded_rng
    * editorial: reformat code using clang-format and provided configuration file
    * Dilithium: Update implementation to match FIPS 204 (draft from Aug 24, 2023)
    * Kyber: Update implementation to match FIPS 203 (draft from Aug 24, 2023)
    * enhancement: Dilithium and Kyber security strengths are selectable via Meson options
    * Kyber KEM: Update shared secret KDF (as the KDF is now removed from FIPS 203,
    it can be adjusted to be more performant and consistent with SP800-108)
    * Kyber KEX: Updated shared secret KDF to use SP800-108 compliant KMAC KDF
    * enhancement: Add input parameter validatino to Kyber as specified in FIPS 203
    * enhancement: consolidate all testing requiring an RNG to use selftest_rng
  - Changes 0.6.0:
    * enhancement: Linux - add memfd_secret(2) support for secure memory allocation
    * fix: documentation of lc_kyber_keypair
    * enhancement: remove the rng_ctx parameter in all Kyber APIs except the key
    generation - internally lc_seeded_rng is used instead
    * enhancement: use -Wmissing-prototypes and fix reported issues
    * enhancement: provide standalone CBC, CTR, KW implementation
    * enhancement: provide AESNI implementation
    * enhancement: provide AES ARM CE implementation
    * enhancement: provide AES RISC-V 64 assembler implementation
    * enhancement: provide Linux kernel configuration option to enable startup
    health tests
    * fix: apply fixes such that all self tests and regression tests pass when compiled for Linux kernel
    * fix: properly zeroize memory when using the workspace memory
  - Changes 0.5.3:
    * convert to safe min/max implementations
    * enhancement: allow kernel modules to be compiled directly from installed user space headers
    * enhancement: make ARMv8 code compile on macOS

++++ systemd:

  - Import commit c10a66fb4dd34b86d42fa92501bd88db63df479a (merge of v257.5)
    This merge includes the following fix:
    9b52c10986 test-network: replace symlink to 99-default.link with a copy
    d7577221b8 man/pstore.conf: pstore.conf template is not always installed in /etc
    62071a984d man: coredump.conf template is not always installed in /etc (bsc#1237496)
    18dde3dd2a umount: do not move busy network mounts (bsc#1236177)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/f133e5974e69708d7491d4823780690c913f7bda...c10a66fb4dd34b86d42fa92501bd88db63df479a

++++ libvirt:

  - cpu_map: Install Ampere-1 ARM CPU models
    bsc#1240922

++++ man:

  - Avoid latest gettextize as it breaks build now

++++ mdadm:

  - IMSM RAID0 2 disks to RAID10 4 disks migration fix
    add 1006-imsm-Fix-RAID0-to-RAID10-migration.patch (bsc#1241001)

++++ openssh:

  - "Update" to openssh 10.0p2:
  - There was an issue during the packaging of 10.0p1 which made it
    identify itself as 10.0p2 so 10.0p1 is now considered identical
    to 10.0p2 and upstream won't release a separate 10.0p2 package.

++++ python313-pyparsing:

  - update to 3.2.3:
    * Fixed bug released in 3.2.2 in which `nested_expr` could
    overwrite parse actions for defined content, and could truncate
    list of items within a nested list.
    * Released `cvt_pyparsing_pep8_names.py` conversion utility to
    upgrade pyparsing-based programs and libraries that use legacy
    camelCase names to use the new PEP8-compliant
    snake_case method names.
    * Fixed bug in `nested_expr` where nested contents were
    stripped of whitespace when the default whitespace characters
    were cleared
    * Fixed bug in `rest_of_line` and the underlying `Regex` class,
    in which matching a pattern that could match an empty string
    (such as `".*"` or `"[A-Z]*"` would not raise
    a `ParseException` at or beyond the end of the input
    string. This could cause an
    infinite parsing loop when parsing `rest_of_line` at the
    end of the input string.
    * Fixed syntax warning raised in `bigquery_view_parser.py`,
    invalid escape sequence "\s".
    * Added support for Python 3.14.

++++ runc:

  - Update to runc v1.2.6. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.6>.

++++ supermin:

  - Update Copyright year
  - Exclude the Requires on sysconfig-netconfig for SLES16 and newer

------------------------------------------------------------------
------------------  2025-4-9  -  Apr 9 2025  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Remove '-Dhostname_persist=suse' compile option, as it's not
    needed anymore. The behaviours of this option are mainly:
    1. stores hostname in /etc/HOSTNAME instead of /etc/hostname.
    2. checks DHCLIENT_SET_HOSTNAME value in /etc/sysconfig/netowrk/dhcp
    to know whether the hostname is valid.
    These are not desired haviours anymore.

++++ containerd:

  - Update to containerd v1.7.27. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.27>
    bsc#1239749 CVE-2024-40635
  - Rebase patches:
    * 0001-BUILD-SLE12-revert-btrfs-depend-on-kernel-UAPI-inste.patch

++++ crypto-policies:

  - Update crypto-policies-enable-SHA1-sigver-in-DEFAULT.patch

++++ curl:

  - Update to 8.13.0:
    * Changes:
  - curl: add write-out variable 'tls_earlydata'
  - curl: make --url support a file with URLs
  - gnutls: set priority via --ciphers
  - IMAP: add CURLOPT_UPLOAD_FLAGS and --upload-flags
  - lib: add CURLFOLLOW_OBEYCODE and CURLFOLLOW_FIRSTONLY
  - OpenSSL/quictls: add support for TLSv1.3 early data
  - rustls: add support for CERTINFO
  - rustls: add support for SSLKEYLOGFILE
  - rustls: support ECH w/ DoH lookup for config
  - rustls: support native platform verifier
  - var: add a '64dec' function that can base64 decode a string
    * Bugfixes:
  - conn: fix connection reuse when SSL is optional
  - hash: use single linked list for entries
  - http2: detect session being closed on ingress handling
  - http2: reset stream on response header error
  - http: remove a HTTP method size restriction
  - http: version negotiation
  - httpsrr: fix port detection
  - libssh: fix freeing of resources in disconnect
  - libssh: fix scp large file upload for 32-bit size_t systems
  - openssl-quic: do not iterate over multi handles
  - openssl: check return value of X509_get0_pubkey
  - openssl: drop support for old OpenSSL/LibreSSL versions
  - openssl: fix crash on missing cert password
  - openssl: fix pkcs11 URI checking for key files.
  - openssl: remove bad `goto`s into other scope
  - setopt: illegal CURLOPT_SOCKS5_AUTH should return error
  - setopt: setting PROXYUSERPWD after PROXYUSERNAME/PASSWORD is fine
  - sshserver.pl: adjust `AuthorizedKeysFile2` cutoff version
  - sshserver: fix excluding obsolete client config lines
  - SSLCERTS: list support for SSL_CERT_FILE and SSL_CERT_DIR
  - tftpd: prefix TFTP protocol error `E*` constants with `TFTP_`
  - tool_operate: fail SSH transfers without server auth
  - url: call protocol handler's disconnect in Curl_conn_free
  - urlapi: remove percent encoded dot sequences from the URL path
  - urldata: remove 'hostname' from struct Curl_async
    * Rebase patches:
  - libcurl-ocloexec.patch
  - curl-secure-getenv.patch

++++ python-kiwi:

  - Prevent loading unused data in oem deployment
    In case rd.kiwi.ramdisk is used as part of a remote deployment
    setup, it's not needed to load the system kernel and initrd
    because it's not used as kexec is not called with the system
    deployed into memory. For ramdisk deployments the system is
    booted using the currently active kernel and initrd and as
    such we can avoid loading an extra kernel and initrd for
    booting the system via kexec.
  - Update Agama integration test
    Make use of <oem-ramdisk-size> in the Agama integration test
  - Added <oem-ramdisk-size> element
    So far it was only possible to specify the size of the ramdisk
    via the kernel commandline option: ramdisk_size. In a remote
    deployment it was therefore required to carry this size as a
    mandatory information to the deployment server. With this commit
    we allow to specify the size for the ramdisk to be configured as
    part of the image configuration which makes this information
    also available inside of the initrd. If provided the ramdisk_size
    kernel commandline option still takes precedence over the
    <oem-ramdisk-size> setting to avoid any behavior change and to
    still allow dynamic overrides of the ramdisk size.

++++ kernel-default:

  - io_uring/kbuf: reallocate buf lists on upgrade (CVE-2025-21836
    bsc#1239066).
  - commit e7bf444
  - io_uring: prevent opcode speculation (CVE-2025-21863
    bsc#1239475).
  - commit a129dda
  - net: mctp: unshare packets when reassembling (CVE-2025-21972
    bsc#1240813).
  - commit 7e7e668
  - gpio: rcar: Use raw_spinlock to protect register access
    (CVE-2025-21912 bsc#1240584).
  - commit ef2385e
  - s390: Remove ioremap_wt() and pgprot_writethrough() (git-fixes
    bsc#1240977).
  - commit 8037d34
  - s390/entry: Fix setting _CIF_MCCK_GUEST with lowcore relocation
    (git-fixes bsc#1240976).
  - commit 4b51b40
  - s390/pci: Fix zpci_bus_is_isolated_vf() for non-VFs (git-fixes, bsc#1240975).
  - commit f780310
  - wifi: ath11k: fix memory leak in ath11k_xxx_remove()
    (git-fixes).
  - Refresh
    patches.suse/wifi-ath11k-choose-default-PM-policy-for-hibernation.patch.
  - Refresh
    patches.suse/wifi-ath11k-support-non-WoWLAN-mode-suspend-as-well.patch.
  - commit f0a348c
  - Update upstream status for ath11k patches
  - commit 4a45d06
  - configs: update using run_oldconfig.sh
  - commit d3805c5
  - rpm/check-for-config-changes: add LD_CAN_ to IGNORED_CONFIGS_RE
    We now have LD_CAN_USE_KEEP_IN_OVERLAY since commit:
    e7607f7d6d81 ARM: 9443/1: Require linker to support KEEP within OVERLAY for DCE
  - commit 7b55ff2
  - perf tools: annotate asm_pure_loop.S (bsc#1239906).
  - commit 9969be2

++++ kernel-firmware-bluetooth:

  - Update to version 20250408 (git commit c1a774f36657):
    * QCA: Add 8 bluetooth nvm files for WCN785x btusb
    * QCA: Update WCN785x btusb firmware to 2.0.0-00790-3

++++ kernel-firmware-i915:

  - Update aliases from 6.15-rc1

++++ kernel-firmware-media:

  - Update to version 20250408 (git commit c1a774f36657):
    * qcom: update firmware binary for SM8250

++++ kernel-firmware-mediatek:

  - Update aliases from 6.15-rc1

++++ kernel-firmware-mellanox:

  - Update to version 20250408 (git commit c1a774f36657):
    * Mellanox: Add new mlxsw_spectrum firmware xx.2014.4012

++++ kernel-firmware-network:

  - Update to version 20250408 (git commit c1a774f36657):
    * linux-firmware: add firmware for Aeonsemi AS21x1x 1G/2.5G/5G/10G Ethernet Phy

++++ kernel-firmware-platform:

  - Update aliases from 6.15-rc1

++++ kernel-firmware-qcom:

  - Update aliases from 6.15-rc1
  - Update to version 20250408 (git commit c1a774f36657):
    * qcom:x1e80100: Iris Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo Yoga Slim 7 Snapdragon platform

++++ kernel-firmware-realtek:

  - Update aliases from 6.15-rc1

++++ kernel-firmware-sound:

  - Update to version 20250408 (git commit c1a774f36657):
    * mediatek: Add new mt8195 SOF firmware
    * mediatek: Add new mt8188 SOF firmware

++++ kernel-rt:

  - io_uring/kbuf: reallocate buf lists on upgrade (CVE-2025-21836
    bsc#1239066).
  - commit e7bf444
  - io_uring: prevent opcode speculation (CVE-2025-21863
    bsc#1239475).
  - commit a129dda
  - net: mctp: unshare packets when reassembling (CVE-2025-21972
    bsc#1240813).
  - commit 7e7e668
  - gpio: rcar: Use raw_spinlock to protect register access
    (CVE-2025-21912 bsc#1240584).
  - commit ef2385e
  - s390: Remove ioremap_wt() and pgprot_writethrough() (git-fixes
    bsc#1240977).
  - commit 8037d34
  - s390/entry: Fix setting _CIF_MCCK_GUEST with lowcore relocation
    (git-fixes bsc#1240976).
  - commit 4b51b40
  - s390/pci: Fix zpci_bus_is_isolated_vf() for non-VFs (git-fixes, bsc#1240975).
  - commit f780310
  - wifi: ath11k: fix memory leak in ath11k_xxx_remove()
    (git-fixes).
  - Refresh
    patches.suse/wifi-ath11k-choose-default-PM-policy-for-hibernation.patch.
  - Refresh
    patches.suse/wifi-ath11k-support-non-WoWLAN-mode-suspend-as-well.patch.
  - commit f0a348c
  - Update upstream status for ath11k patches
  - commit 4a45d06
  - configs: update using run_oldconfig.sh
  - commit d3805c5
  - rpm/check-for-config-changes: add LD_CAN_ to IGNORED_CONFIGS_RE
    We now have LD_CAN_USE_KEEP_IN_OVERLAY since commit:
    e7607f7d6d81 ARM: 9443/1: Require linker to support KEEP within OVERLAY for DCE
  - commit 7b55ff2
  - perf tools: annotate asm_pure_loop.S (bsc#1239906).
  - commit 9969be2

++++ libcontainers-common:

  - containers.conf default configuration modifications:
    * set runc as the default OCI runtime (bsc#1239088)
    * set nftables as the default firewall driver for netavark
  - New release 20250409
    * bump bundled c/common to 0.59.1
    * bump bundled c/image to 5.31.0
    * bump bundled c/storage to 1.54.0

++++ libgpg-error:

  - Update to 1.53:
    * Fix regression in 1.52.
    * Rebase libgpg-error-nobetasuffix.patch
  - Update to 1.52:
    * The KEY_WOW64_xxKEY flags can now be passed to the Registry read
    functions. [rE652328c786]
    * In the spawn functions care about closefrom/close call is
    interrupted. [T7478]
    * New simple string list API. [rE47097806f1]
    * New API for name value files. [rE7ec1f27b60]
    * Interface changes relative to the 1.51 release:
  - gpgrt_w32_reg_query_string          NEW (Windows only).
  - gpgrt_strlist_t                     NEW type.
  - gpgrt_strlist_free                  NEW.
  - gpgrt_strlist_add                   NEW.
  - gpgrt_strlist_tokenize              NEW.
  - gpgrt_strlist_copy                  NEW.
  - gpgrt_strlist_rev                   NEW.
  - gpgrt_strlist_prev                  NEW.
  - gpgrt_strlist_last                  NEW.
  - gpgrt_strlist_pop                   NEW.
  - gpgrt_strlist_find                  NEW.
  - GPGRT_STRLIST_APPEND                NEW const.
  - GPGRT_STRLIST_WIPE                  NEW const.
  - gpgrt_nvc_t                         NEW type.
  - gpgrt_nve_t                         NEW type.
  - gpgrt_nvc_new                       NEW.
  - gpgrt_nvc_release                   NEW.
  - gpgrt_nvc_get_flag                  NEW.
  - gpgrt_nvc_add                       NEW.
  - gpgrt_nvc_set                       NEW.
  - gpgrt_nve_set                       NEW.
  - gpgrt_nvc_delete                    NEW.
  - gpgrt_nvc_lookup                    NEW.
  - gpgrt_nvc_parse                     NEW.
  - gpgrt_nvc_write                     NEW.
  - gpgrt_nve_next                      NEW.
  - gpgrt_nve_name                      NEW.
  - gpgrt_nve_value                     NEW.
  - gpgrt_nvc_get_string                NEW.
  - gpgrt_nvc_get_bool                  NEW.
  - GPGRT_NVC_WIPE                      NEW const.
  - GPGRT_NVC_PRIVKEY                   NEW const.
  - GPGRT_NVC_SECTION                   NEW const.
  - GPGRT_NVC_MODIFIED                  NEW const.

++++ ncurses:

  - Modify patch ncurses-5.9-ibm327x.dif
    * Add a further sclp entry for qemu s390 based systems

++++ shadow:

  - shadow-util-linux.patch: util-linux-2.41 introduced new variable:
    LOGIN_ENV_SAFELIST. Recognize it and update dependencies. The
    patch includes gh/shadow-maint/shadow/pull#1248.
  - shadow-login_defs-check-login_defs.lst: Make the util-linux.spec
    multibuild file compatible with quilt. Make it working with new
    quilt.

++++ openssh:

  - Update to openssh 10.0p1:
    = Potentially-incompatible changes
    * This release removes support for the weak DSA signature
    algorithm, completing the deprecation process that began in
    2015 (when DSA was disabled by default) and repeatedly warned
    over the last 12 months.
    * scp(1), sftp(1): pass "ControlMaster no" to ssh when invoked by
    scp & sftp. This disables implicit session creation by these
    tools when ControlMaster was set to yes/auto by configuration,
    which some users found surprising. This change will not prevent
    scp/sftp from using an existing multiplexing session if one had
    already been created. GHPR557
    * This release has the version number 10.0 and announces itself
    as "SSH-2.0-OpenSSH_10.0". Software that naively matches
    versions using patterns like "OpenSSH_1*" may be confused by
    this.
    * sshd(8): this release removes the code responsible for the
    user authentication phase of the protocol from the per-
    connection sshd-session binary to a new sshd-auth binary.
    Splitting this code into a separate binary ensures that the
    crucial pre-authentication attack surface has an entirely
    disjoint address space from the code used for the rest of the
    connection. It also yields a small runtime memory saving as the
    authentication code will be unloaded after the authentication
    phase completes. This change should be largely invisible to
    users, though some log messages may now come from "sshd-auth"
    instead of "sshd-session". Downstream distributors of OpenSSH
    will need to package the sshd-auth binary.
    * sshd(8): this release disables finite field (a.k.a modp)
    Diffie-Hellman key exchange in sshd by default. Specifically,
    this removes the "diffie-hellman-group*" and
    "diffie-hellman-group-exchange-*" methods from the default
    KEXAlgorithms list. The client is unchanged and continues to
    support these methods by default. Finite field Diffie Hellman
    is slow and computationally expensive for the same security
    level as Elliptic Curve DH or PQ key agreement while offering
    no redeeming advantages. ECDH has been specified for the SSH
    protocol for 15 years and some form of ECDH has been the
    default key exchange in OpenSSH for the last 14 years.
    * sshd(8): this release removes the implicit fallback to
    compiled-in groups for Diffie-Hellman Group Exchange KEX when
    the moduli file exists but does not contain moduli within the
    client-requested range.  The fallback behaviour remains for the
    case where the moduli file does not exist at all. This allows
    administrators more explicit control over which DH groups will
    be selected, but can lead to connection failures if the moduli
    file is edited incorrectly. bz#2793
    = Security
    * sshd(8): fix the DisableForwarding directive, which was failing
    to disable X11 forwarding and agent forwarding as documented.
    X11 forwarding is disabled by default in the server and agent
    forwarding is off by default in the client.
    = New features
    * ssh(1): the hybrid post-quantum algorithm mlkem768x25519-sha256
    is now used by default for key agreement. This algorithm is
    considered to be safe against attack by quantum computers,
    is guaranteed to be no less strong than the popular
    curve25519-sha256 algorithm, has been standardised by NIST
    and is considerably faster than the previous default.
    * ssh(1): prefer AES-GCM to AES-CTR mode when selecting a cipher
    for the connection. The default cipher preference list is now
    Chacha20/Poly1305, AES-GCM (128/256) followed by AES-CTR
    (128/192/256).
    * ssh(1): add %-token and environment variable expansion to the
    ssh_config SetEnv directive.
    * ssh(1): allow %-token and environment variable expansion in
    the ssh_config User directive, with the exception of %r and %C
    which would be self-referential. bz#3477
    * ssh(1), sshd(8): add "Match version" support to ssh_config and
    sshd_config. Allows matching on the local version of OpenSSH,
    e.g. "Match version OpenSSH_10.*".
    * ssh(1): add support for "Match sessiontype" to ssh_config.
    Allows matching on the type of session initially requested,
    either "shell" for interactive sessions, "exec" for command
    execution sessions, "subsystem" for subsystem requests, such as
    sftp, or "none" for transport/forwarding-only sessions.
    * ssh(1): add support for "Match command ..." support to
    ssh_config, allowing matching on the remote command as
    specified on the command-line.
    * ssh(1): allow 'Match tagged ""' and 'Match command ""' to match
    empty tag and command values respectively.
    * sshd(8): allow glob(3) patterns to be used in sshd_config
    AuthorizedKeysFile and AuthorizedPrincipalsFile directives.
    bz2755
    * sshd(1): support the VersionAddendum in the client, mirroring
    the option of the same name in the server; bz2745
    * ssh-agent(1): the agent will now delete all loaded keys when
    signaled with SIGUSR1. This allows deletion of keys without
    having access to $SSH_AUTH_SOCK.
    * Portable OpenSSH, ssh-agent(1): support systemd-style socket
    activation in ssh-agent using the LISTEN_PID/LISTEN_FDS
    mechanism. Activated when these environment variables are set,
    the agent is started with the -d or -D option and no socket
    path is set. GHPR502
    * ssh-keygen(1): support FIDO tokens that return no attestation
    data, e.g. recent WinHello. GHPR542
    * ssh-agent(1): add a "-Owebsafe-allow=..." option to allow the
    default FIDO application ID allow-list to be overridden.
    * Add a work-in-progress tool to verify FIDO attestation blobs
    that ssh-keygen can optionally write when enrolling FIDO keys.
    This tool is available under
    regress/misc/ssh-verify-attestation for experimentation but is
    not installed by "make install".
    * ssh-keygen(1): allow "-" as output file for moduli screening.
    GHPR393
    = Bugfixes
    * sshd(8): remove assumption that the sshd_config and any configs
    it includes can fit in a (possibly enlarged) socket buffer.
    Previously it was possible to create a sufficiently large
    configuration that could cause sshd to fail to accept any
    connection. sshd(8) will now actively manage sending its config
    to the sshd-session sub-process.
    * ssh(1): don't start the ObscureKeystrokeTiming mitigations if
    there has been traffic on a X11 forwarding channel recently.
    Should fix X11 forwarding performance problems when this
    setting is enabled. bz3655
    * ssh(1): prohibit the comma character in hostnames accepted, but
    allow an underscore as the first character in a hostname.
    * sftp(1): set high-water when resuming a "put". Prevents bogus
    "server reordered acks" debug message.
    * ssh(1), sshd(8): fix regression in openssh-9.8, which would
    fail to accept "Match criteria=argument" as well as the
    documented "Match criteria argument" syntax in ssh_config and
    sshd_config. bz3739
    * sftp(1), ssh(1): fix a number possible NULL dereference bugs,
    including Coverity CIDs 405019 and 477813.
    * sshd(8): fix PerSourcePenalty incorrectly using "crash" penalty
    when LoginGraceTime was exceeded. bz3797
    * sshd(8): fix "Match invalid-user" from incorrectly being
    activated in initial configuration pass when no other
    predicates were present on the match line
    * sshd(8): fix debug logging of user specific delay. GHPR#552
    * sshd(8): improve debug logging across sub-process boundaries.
    Previously some log messages were lost early in the sshd-auth
    and sshd-session processes' life.
    * ssh(1): require control-escape character sequences passed via
    the '-e ^x' command-line to be exactly two characters long.
    Avoids one byte out-of-bounds read if ssh is invoked as
    "ssh -e^ ..." GHPR368
    * ssh(1), sshd(8): prevent integer overflow in x11 port handling.
    These are theoretically possible if the admin misconfigured
    X11DisplayOffset or the user misconfigures their own $DISPLAY,
    but don't happen in normal operation. bz#3730
    * ssh-keygen(1): don't mess up ssh-keygen -l output when the file
    contains CR characters; GHPR236 bz3385.
    * sshd(8): add rate limits to logging of connections dropped by
    PerSourcePenalties. Previously these could be noisy in logs.
    * ssh(1): fix argument of "Compression" directive in ssh -G
    config dump, which regressed in openssh-9.8.
    * sshd(8): fix a corner-case triggered by UpdateHostKeys when
    sshd refuses to accept the signature returned by an agent
    holding host keys during the hostkey rotation sub-protocol.
    This situation could occur in situations where a PKCS#11
    smartcard that lacked support for particular signature
    algorithms was used to store host keys.
    * ssh-keygen(1): when using RSA keys to sign messages with
    "ssh-keygen -Y", select the signature algorithm based on the
    requested hash algorithm ("-Ohashalg=xxx"). This allows using
    something other than the default of rsa-sha2-512, which may not
    be supported on all signing backends, e.g. some smartcards only
    support SHA256.
    * ssh(1), sshd(8), ssh-keyscan(1): fix ML-KEM768x25519 KEX on
    big-endian systems.
    * Many regression and interop test improvements.
    = Portability
    * All: add support for AWS-LC (AWS libcrypto). bz3784
    * sshd(8): add wtmpdb support as a Y2038 safe wtmp replacement.
    * sshd(8): add support for locking sshd into memory, enabled with
    the --with-linux-memlock-onfault configure flag.
    * Add support for building a standalone sk-libfido2 library,
    enabled by --with-security-key-standalone
    * ssh(1), sshd(8), ssh-keyscan(1): include __builtin_popcount
    replacement function. for compilers that lack it.
    * All: Check for and replace le32toh, le64toh, htole64
    separately. It appears that at least some versions of endian.h
    in glibc do not have the latter two. bz#3794
    * Remove ancient RHL 6.x config in RPM spec.
  - Rebase patches:
    * openssh-7.7p1-fips.patch
    * openssh-7.7p1-cavstest-ctr.patch
    * openssh-7.7p1-cavstest-kdf.patch
    * openssh-7.7p1-fips_checks.patch
    * openssh-8.0p1-gssapi-keyex.patch
    * openssh-8.1p1-audit.patch
    * openssh-7.7p1-ldap.patch
    * openssh-reenable-dh-group14-sha1-default.patch
    * openssh-8.4p1-vendordir.patch
    * logind_set_tty.patch
    * openssh-mitigate-lingering-secrets.patch
    * openssh-7.8p1-role-mls.patch
    * openssh-6.6p1-privsep-selinux.patch
    * openssh-6.6.1p1-selinux-contexts.patch
    * openssh-9.6p1-crypto-policies-man.patch
    * openssh-7.6p1-cleanup-selinux.patch
  - Drop patches now included upstream:
    * wtmpdb.patch
    * fix-x11-regression-bsc1229449.patch
    * fix-nopie-flag.patch
  - Drop patch since SHA-1 isn't considered secure and the default
    kex list comes from crypto-policies anyway:
    * openssh-reenable-dh-group14-sha1-default.patch

------------------------------------------------------------------
------------------  2025-4-8  -  Apr 8 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - reinstall bootstrap packs in image phase for apt
    Due to the special bootstrap process, the packages unpacked
    during bootstrap are not properly listed in the apt index.
    Therefore the bootstrap packages are added to the install
    phase which causes an install of this packages again to
    fix the apt index and provide a consistent system from
    an apt perspective. This Fixes #2768

++++ transactional-update:

  - Version 5.0.1
  - Fix path to rebootmgrctl [bsc#1236908]

++++ kernel-default:

  - perf/core: Order the PMU list to fix warning about unordered
    pmu_ctx_list (bsc#1240585 CVE-2025-21895).
  - commit 820ecfc
  - ext4: fix FS_IOC_GETFSMAP handling (bsc#1240557).
  - commit 3d92358
  - gpio: idio-16: Actually make use of the GPIO_IDIO_16 symbol
    namespace (git-fixes).
  - commit f08563d
  - module: Convert default symbol namespace to string literal
    (git-fixes).
  - commit fd4c957
  - gpio: vf610: use generic device_get_match_data() (git-fixes).
  - commit 7d5c89d
  - rpm/kernel-binary.spec.in: Use OrderWithRequires (boo#1228659 boo#1241038).
    OrderWithRequires was introduced in rpm 4.9 (ie. SLE12+) to allow
    a package to inform the order of installation of other package without
    hard requiring that package. This means our kernel-binary packages no
    longer need to hard require perl-Bootloader or dracut, resolving the
    long-commented issue there. This is also needed for udev & systemd-boot
    to ensure those packages are installed before being called by dracut
    (boo#1228659)
  - commit 634be2c
  - s390/sclp: Initialize sclp subsystem via arch_cpu_finalize_init()
    (git-fixes, bsc#1237055).
  - Refresh
    patches.suse/s390-lock-down-kernel-in-secure-boot-mode.patch.
  - commit daf9150
  - ovl: support encoding fid from inode with no alias (bsc#1238448).
  - commit 258d9fd
  - ovl: pass realinode to ovl_encode_real_fh() instead of realdentry (git-fixes).
  - commit 28b34c8
  - ovl: properly handle large files in ovl_security_fileattr (git-fixes).
  - commit 2f1a01a
  - tools/power turbostat: Restore GFX sysfs fflush() call
    (git-fixes).
  - commit e034d9b
  - tools/power turbostat: Allow Zero return value for some RAPL
    registers (git-fixes).
  - commit 39d1fd1
  - net: usb: qmi_wwan: add Telit Cinterion FE990B composition
    (git-fixes).
  - commit b2dd890
  - net: usb: qmi_wwan: add Telit Cinterion FN990B composition
    (git-fixes).
  - commit a3fe22b
  - usb: xhci: Apply the link chain quirk on NEC isoc endpoints
    (git-fixes).
  - commit bec8bdb
  - bpf: avoid holding freeze_mutex during mmap operation
    (git-fixes).
  - bpf: unify VM_WRITE vs VM_MAYWRITE use in BPF map mmaping logic
    (git-fixes).
  - selftests/bpf: Add test for narrow ctx load for pointer args
    (git-fixes).
  - bpf: Check size for BTF-based ctx access of pointer members
    (git-fixes).
  - bpf: Fix theoretical prog_array UAF in __uprobe_perf_func()
    (git-fixes).
  - bpf: fix potential error return (git-fixes).
  - bpf: handle implicit declaration of function gettid in
    bpf_iter.c (git-fixes).
  - Refresh patches.suse/selftests-bpf-Clean-up-open-coded-gettid-syscall-inv.patch
  - selftests/bpf: Fix uprobe consumer test (git-fixes).
  - commit 2087211
  - drm/amd/display: Don't write DP_MSTM_CTRL after LT
    (stable-fixes).
  - commit fa64fbb
  - libperf cpumap: Grow array of read CPUs in smaller increments
    (bsc#1234698 jsc#PED-12309).
  - libperf cpumap: Remove use of perf_cpu_map__read() (bsc#1234698
    jsc#PED-12309).
  - perf pmu: Remove use of perf_cpu_map__read() (bsc#1234698
    jsc#PED-12309).
  - libperf cpumap: Be tolerant of newline at the end of a cpumask
    (bsc#1234698 jsc#PED-12309).
  - libperf cpumap: Hide/reduce scope of MAX_NR_CPUS (bsc#1234698
    jsc#PED-12309).
  - perf cpumap: Reduce transitive dependencies on libperf
    MAX_NR_CPUS (bsc#1234698 jsc#PED-12309).
  - perf: Increase MAX_NR_CPUS to 4096 (bsc#1234698 jsc#PED-12309).
  - commit 016f27b

++++ kernel-rt:

  - perf/core: Order the PMU list to fix warning about unordered
    pmu_ctx_list (bsc#1240585 CVE-2025-21895).
  - commit 820ecfc
  - ext4: fix FS_IOC_GETFSMAP handling (bsc#1240557).
  - commit 3d92358
  - gpio: idio-16: Actually make use of the GPIO_IDIO_16 symbol
    namespace (git-fixes).
  - commit f08563d
  - module: Convert default symbol namespace to string literal
    (git-fixes).
  - commit fd4c957
  - gpio: vf610: use generic device_get_match_data() (git-fixes).
  - commit 7d5c89d
  - rpm/kernel-binary.spec.in: Use OrderWithRequires (boo#1228659 boo#1241038).
    OrderWithRequires was introduced in rpm 4.9 (ie. SLE12+) to allow
    a package to inform the order of installation of other package without
    hard requiring that package. This means our kernel-binary packages no
    longer need to hard require perl-Bootloader or dracut, resolving the
    long-commented issue there. This is also needed for udev & systemd-boot
    to ensure those packages are installed before being called by dracut
    (boo#1228659)
  - commit 634be2c
  - s390/sclp: Initialize sclp subsystem via arch_cpu_finalize_init()
    (git-fixes, bsc#1237055).
  - Refresh
    patches.suse/s390-lock-down-kernel-in-secure-boot-mode.patch.
  - commit daf9150
  - ovl: support encoding fid from inode with no alias (bsc#1238448).
  - commit 258d9fd
  - ovl: pass realinode to ovl_encode_real_fh() instead of realdentry (git-fixes).
  - commit 28b34c8
  - ovl: properly handle large files in ovl_security_fileattr (git-fixes).
  - commit 2f1a01a
  - tools/power turbostat: Restore GFX sysfs fflush() call
    (git-fixes).
  - commit e034d9b
  - tools/power turbostat: Allow Zero return value for some RAPL
    registers (git-fixes).
  - commit 39d1fd1
  - net: usb: qmi_wwan: add Telit Cinterion FE990B composition
    (git-fixes).
  - commit b2dd890
  - net: usb: qmi_wwan: add Telit Cinterion FN990B composition
    (git-fixes).
  - commit a3fe22b
  - usb: xhci: Apply the link chain quirk on NEC isoc endpoints
    (git-fixes).
  - commit bec8bdb
  - bpf: avoid holding freeze_mutex during mmap operation
    (git-fixes).
  - bpf: unify VM_WRITE vs VM_MAYWRITE use in BPF map mmaping logic
    (git-fixes).
  - selftests/bpf: Add test for narrow ctx load for pointer args
    (git-fixes).
  - bpf: Check size for BTF-based ctx access of pointer members
    (git-fixes).
  - bpf: Fix theoretical prog_array UAF in __uprobe_perf_func()
    (git-fixes).
  - bpf: fix potential error return (git-fixes).
  - bpf: handle implicit declaration of function gettid in
    bpf_iter.c (git-fixes).
  - Refresh patches.suse/selftests-bpf-Clean-up-open-coded-gettid-syscall-inv.patch
  - selftests/bpf: Fix uprobe consumer test (git-fixes).
  - commit 2087211
  - drm/amd/display: Don't write DP_MSTM_CTRL after LT
    (stable-fixes).
  - commit fa64fbb
  - libperf cpumap: Grow array of read CPUs in smaller increments
    (bsc#1234698 jsc#PED-12309).
  - libperf cpumap: Remove use of perf_cpu_map__read() (bsc#1234698
    jsc#PED-12309).
  - perf pmu: Remove use of perf_cpu_map__read() (bsc#1234698
    jsc#PED-12309).
  - libperf cpumap: Be tolerant of newline at the end of a cpumask
    (bsc#1234698 jsc#PED-12309).
  - libperf cpumap: Hide/reduce scope of MAX_NR_CPUS (bsc#1234698
    jsc#PED-12309).
  - perf cpumap: Reduce transitive dependencies on libperf
    MAX_NR_CPUS (bsc#1234698 jsc#PED-12309).
  - perf: Increase MAX_NR_CPUS to 4096 (bsc#1234698 jsc#PED-12309).
  - commit 016f27b

++++ c-ares:

  - c-ares version 1.34.5
    * CVE-2025-31498. A use-after-free bug has been uncovered in read_answers() that
    was introduced in v1.32.3 (bsc#1240955)
  - a531524a3d085fcd9a5e25d5f6cbdb953082c2b9.patch: upstreamed, removed

++++ wtmpdb:

  - Update to version 0.73.0+git20250408.edb8638:
    * Release version 0.73.0
    * expand accepted time format options
    * use documented -t short option for last --until
    * hurd: avoid PATH_MAX
    * hurd: compat for lack of CLOCK_BOOTTIME

++++ netcat-openbsd:

  - add -std=gnu99 to CFLAGS to fix gcc15 compile time errors

++++ python-gcemetadata:

  - Switch the SLE 15 build setup to also use a macro instead of referencing
    the Python 3.11 interpreter directly.

++++ python-certifi:

  - Update to 2025.1.31
    * Added certs
  - Subject: CN=D-TRUST BR Root CA 2 2023 O=D-Trust GmbH
  - Subject: CN=D-TRUST EV Root CA 2 2023 O=D-Trust GmbH
    * Removed certs
  - Subject: CN=SwissSign Silver CA - G2 O=SwissSign AG
  - from version 2024.12.14
    * Upload attestations to PyPI
    * Added 3.13 classifier (#322)
    * Test against 3.13 final
    * Added certs
  - Subject: CN=GLOBALTRUST 2020 O=e-commerce monitoring GmbH
    * Removed certs
  - Subject: CN=SecureSign RootCA11 O=Japan Certification Services, Inc.
  - Subject: CN=Entrust Root Certification Authority - G4 O=Entrust, Inc.
    OU=See www.entrust.net/legal-terms/(c) 2015 Entrust, Inc. - for
    authorized use only
  - Subject: CN=Security Communication RootCA3 O=SECOM Trust Systems CO.,LTD.

++++ virt-manager:

  - bsc#1239837 - [SLFO] virt-manager still has unresolved
    dependencies in beta2
    Remove dependencies on spice and other Gtk sources as these
    packages don't exist in SLES16. Cleanup other dependencies.
    virt-manager.spec

------------------------------------------------------------------
------------------  2025-4-7  -  Apr 7 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Ensure cockpit-selinux-policies always installs the selinux policy
    regardless of selinuxenabled status (bsc#1240787 and bsc#1240421)

++++ python-kiwi:

  - Fixed restore of keyfile after reencryption
    When kiwi runs the reencryption it also restores an eventual
    existing keyfile. However if the option rd.kiwi.oem.luks.reencrypt_randompass
    is specified no former keyfile should be restored. The purpose
    of reencrypt_randompass is to make sure only this in memory
    passphrase can access the luks pool such that tooling at boot
    time gets the opportunity to work with the luks pool for e.g.
    setting up a TPM key or set a passphrase only known to the user.

++++ hwinfo:

  - merge gh#openSUSE/hwinfo#155
  - fix network card detection on aarch64 (bsc#1240648)
  - 23.5

++++ open-iscsi:

  - Change SPEC file so that open-iscsi lock files always go
    in /run/lock/iscsi (bsc#1239107)
  - Update to version 2.1.11.suse+65.65365e1cdedb:
    * doc: fixup iscsiadm man page option for -r (#501)
    * Modify log function to print session id (#498)
    * Fix minor typo ("authenticaton") (#500)
    * Preparing for version 2.1.11 (#499)
    * iscsid: Rate limit session reopen log messages (#492)
    * IPv6 support for iBFT iSCSI boot (#493)
    * Improve iscsiadm command line parsing messages (#494)
    * More testing cleanup, and fix dprint test usage (#491)
    * Fix a typo in test/README (#486)
    * iscsid: Fix hang during login with scan=manual (#485)
    * fix 4 issues which are finded when building with clang 17 (#478)

++++ kernel-default:

  - netmem: prevent TX of unreadable skbs (CVE-2025-21954 bsc#1240734)
  - commit a1c5aa6
  - io_uring/sqpoll: Increase task_work submission batch size
    (bsc#1237349).
  - commit 1fd5694
  - OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized (CVE-2024-58068 bsc#1238961)
  - commit becf7cb
  - net: let net.core.dev_weight always be non-zero (CVE-2025-21806 bsc#1238746)
  - commit 77296a7
  - fs/netfs/read_collect: add to next->prev_donated (CVE-2025-21988 bsc#1240794).
  - commit 266358d
  - cachefiles: Fix missing pos updates in cachefiles_ondemand_fd_write_iter() (git-fixes).
  - Refresh
    patches.suse/cachefiles-Fix-NULL-pointer-dereference-in-object-file.patch.
  - commit a239da8
  - cachefiles: Fix incorrect length return value in cachefiles_ondemand_fd_write_iter()
    (git-fixes).
  - Refresh
    patches.suse/cachefiles-Fix-NULL-pointer-dereference-in-object-file.patch.
  - commit f7aa4b2
  - OPP: add index check to assert to avoid buffer overflow in _read_freq() (CVE-2024-57998 bsc#1238527)
  - commit ba92a26
  - mm/mremap: do not set vrm->vma NULL immediately prior to
    checking it (bsc#1236648).
  - commit c9bedf5
  - mm/mremap: thread state through move page table operation
    (bsc#1236648).
  - commit 587499d
  - mm/mremap: refactor move_page_tables(), abstracting state
    (bsc#1236648).
  - commit 3e4a075
  - mm/mremap: complete refactor of move_vma() (bsc#1236648).
  - commit d2e4046
  - mm/mremap: initial refactor of move_vma() (bsc#1236648).
  - commit 10aa9c0
  - mm/mremap: introduce and use vma_remap_struct threaded state
    (bsc#1236648).
  - commit d7aa505
  - mm/mremap: refactor mremap() system call implementation
    (bsc#1236648).
  - commit 3260e42
  - mm: clear uffd-wp PTE/PMD state on mremap() (bsc#1236648).
  - Refresh
    patches.suse/mm-hugetlb-Add-huge-page-size-param-to-huge_ptep_get_and_clear.patch.
  - commit 3eabb30
  - mm/mremap: remove goto from mremap_to() (bsc#1236648).
  - commit b290f99
  - mm/mremap: cleanup vma_to_resize() (bsc#1236648).
  - commit 5eeb6b7
  - mm/mremap: correctly handle partial mremap() of VMA starting
    at 0 (bsc#1236648).
  - commit 0158c20
  - mm: make vma cache SLAB_TYPESAFE_BY_RCU (bsc#1236648).
  - commit 6632f8f
  - mm: prepare lock_vma_under_rcu() for vma reuse possibility
    (bsc#1236648).
  - commit 182064f
  - mm: remove extra vma_numab_state_init() call (bsc#1236648).
  - commit 4fa76bd
  - mm/debug: print vm_refcnt state when dumping the vma
    (bsc#1236648).
  - commit b0336b4
  - mm: move lesser used vma_area_struct members into the last
    cacheline (bsc#1236648).
  - Refresh
    patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch.
  - commit 3621034
  - mm: replace vm_lock and detached flag with a reference count
    (bsc#1236648).
  - Refresh
    patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch.
  - commit 20a4f53
  - refcount: introduce
    __refcount_{add|inc}_not_zero_limited_acquire (bsc#1236648).
  - commit 7cae058
  - refcount: provide ops for cases when object's memory can be
    reused (bsc#1236648).
  - commit 65378f2
  - mm: uninline the main body of vma_start_write() (bsc#1236648).
  - commit 07fd6a8
  - mm: move mmap_init_lock() out of the header file (bsc#1236648).
  - commit fef8887
  - mm: allow vma_start_read_locked/vma_start_read_locked_nested
    to fail (bsc#1236648).
  - commit 8ccc607
  - types: move struct rcuwait into types.h (bsc#1236648).
  - commit aafad00
  - mm: mark vmas detached upon exit (bsc#1236648).
  - commit f8b68a1
  - mm: introduce vma_iter_store_attached() to use with attached
    vmas (bsc#1236648).
  - commit 466e36f
  - mm: move per-vma lock into vm_area_struct (bsc#1236648).
  - Refresh
    patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch.
  - commit 95e3916
  - mm: mark vma as detached until it's added into vma tree
    (bsc#1236648).
  - commit 73de5d7
  - usbnet:fix NPE during rx_complete (git-fixes).
  - commit 0174b0c
  - Refresh patches.suse/btrfs-fix-use-after-free-waiting-for-encoded-read-en.patch (bsc#1240559).
    There was a trivial typo in commit 0406131af095 ("btrfs: fix use-after-free
    waiting for encoded read endios (bsc#1235128)") while backporting d29662695ed7c.
    This refresh fixes the typo.
  - commit 7d8f5ea
  - mm/slab/kvfree_rcu: Switch to WQ_MEM_RECLAIM wq (CVE-2025-21983
    bsc#1240792).
  - commit 5558350
  - mm/huge_memory: drop beyond-EOF folios with the right number
    of refs (CVE-2025-22000 bsc#1240834).
  - commit 71ff73e
  - mm: abort vma_modify() on merge out of memory failure
    (CVE-2025-21932 bsc#1240707).
  - commit b1120f6
  - net: mana: Switch to page pool for jumbo frames (git-fixes).
  - net/mana: fix warning in the writer of client oob (git-fixes).
  - PCI: hv: Correct a comment (git-fixes).
  - net: mana: Add metadata support for xdp mode (git-fixes).
  - net: mana: Add debug logs in MANA network driver (git-fixes).
  - hv_netvsc: Use VF's tso_max_size value when data path is VF (git-fixes).
  - net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (git-fixes).
  - scsi: storvsc: Don't report the host packet status as the hv status (git-fixes).
  - x86/hyperv: fix an indentation issue in mshyperv.h (git-fixes).
  - x86/hyperv: Add comments about hv_vpset and var size hypercall input args (git-fixes).
  - Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs (git-fixes).
  - hyperv: Add definitions for root partition driver to hv headers (git-fixes).
  - x86: hyperv: Add mshv_handler() irq handler and setup function (git-fixes).
  - Drivers: hv: Introduce per-cpu event ring tail (git-fixes).
  - Drivers: hv: Export some functions for use by root partition module (git-fixes).
  - acpi: numa: Export node_to_pxm() (git-fixes).
  - hyperv: Introduce hv_recommend_using_aeoi() (git-fixes).
  - arm64/hyperv: Add some missing functions to arm64 (git-fixes).
  - x86/mshyperv: Add support for extended Hyper-V features (git-fixes).
  - hyperv: Log hypercall status codes as strings (git-fixes).
  - x86/hyperv: Fix check of return value from snp_set_vmsa() (git-fixes).
  - x86/hyperv: Add VTL mode callback for restarting the system (git-fixes).
  - x86/hyperv: Add VTL mode emergency restart callback (git-fixes).
  - hyperv: Remove unused union and structs (git-fixes).
  - hyperv: Add CONFIG_MSHV_ROOT to gate root partition support (git-fixes).
  - hyperv: Change hv_root_partition into a function (git-fixes).
  - hyperv: Convert hypercall statuses to linux error codes (git-fixes).
  - drivers/hv: add CPU offlining support (git-fixes).
  - drivers/hv: introduce vmbus_channel_set_cpu() (git-fixes).
  - cpu: export lockdep_assert_cpus_held() (git-fixes).
  - hyperv: Move arch/x86/hyperv/hv_proc.c to drivers/hv (git-fixes).
  - hyperv: Move hv_current_partition_id to arch-generic code (git-fixes).
  - x86/hyperv: Use named operands in inline asm (git-fixes).
  - commit 3716372
  - ACPI/HMAT: Move HMAT messages to pr_debug() (bsc#1240653)
  - commit c3391ab
  - x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less
    NUMA nodes (CVE-2025-21991 bsc#1240795).
  - x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
    (CVE-2025-21913 bsc#1240591).
  - commit 222a34e
  - NFS: fix nfs_release_folio() to not deadlock via kcompactd
    writeback (CVE-2025-21908 bsc#1240600).
  - commit bfa8b42

++++ kernel-rt:

  - netmem: prevent TX of unreadable skbs (CVE-2025-21954 bsc#1240734)
  - commit a1c5aa6
  - io_uring/sqpoll: Increase task_work submission batch size
    (bsc#1237349).
  - commit 1fd5694
  - OPP: fix dev_pm_opp_find_bw_*() when bandwidth table not initialized (CVE-2024-58068 bsc#1238961)
  - commit becf7cb
  - net: let net.core.dev_weight always be non-zero (CVE-2025-21806 bsc#1238746)
  - commit 77296a7
  - fs/netfs/read_collect: add to next->prev_donated (CVE-2025-21988 bsc#1240794).
  - commit 266358d
  - cachefiles: Fix missing pos updates in cachefiles_ondemand_fd_write_iter() (git-fixes).
  - Refresh
    patches.suse/cachefiles-Fix-NULL-pointer-dereference-in-object-file.patch.
  - commit a239da8
  - cachefiles: Fix incorrect length return value in cachefiles_ondemand_fd_write_iter()
    (git-fixes).
  - Refresh
    patches.suse/cachefiles-Fix-NULL-pointer-dereference-in-object-file.patch.
  - commit f7aa4b2
  - OPP: add index check to assert to avoid buffer overflow in _read_freq() (CVE-2024-57998 bsc#1238527)
  - commit ba92a26
  - mm/mremap: do not set vrm->vma NULL immediately prior to
    checking it (bsc#1236648).
  - commit c9bedf5
  - mm/mremap: thread state through move page table operation
    (bsc#1236648).
  - commit 587499d
  - mm/mremap: refactor move_page_tables(), abstracting state
    (bsc#1236648).
  - commit 3e4a075
  - mm/mremap: complete refactor of move_vma() (bsc#1236648).
  - commit d2e4046
  - mm/mremap: initial refactor of move_vma() (bsc#1236648).
  - commit 10aa9c0
  - mm/mremap: introduce and use vma_remap_struct threaded state
    (bsc#1236648).
  - commit d7aa505
  - mm/mremap: refactor mremap() system call implementation
    (bsc#1236648).
  - commit 3260e42
  - mm: clear uffd-wp PTE/PMD state on mremap() (bsc#1236648).
  - Refresh
    patches.suse/mm-hugetlb-Add-huge-page-size-param-to-huge_ptep_get_and_clear.patch.
  - commit 3eabb30
  - mm/mremap: remove goto from mremap_to() (bsc#1236648).
  - commit b290f99
  - mm/mremap: cleanup vma_to_resize() (bsc#1236648).
  - commit 5eeb6b7
  - mm/mremap: correctly handle partial mremap() of VMA starting
    at 0 (bsc#1236648).
  - commit 0158c20
  - mm: make vma cache SLAB_TYPESAFE_BY_RCU (bsc#1236648).
  - commit 6632f8f
  - mm: prepare lock_vma_under_rcu() for vma reuse possibility
    (bsc#1236648).
  - commit 182064f
  - mm: remove extra vma_numab_state_init() call (bsc#1236648).
  - commit 4fa76bd
  - mm/debug: print vm_refcnt state when dumping the vma
    (bsc#1236648).
  - commit b0336b4
  - mm: move lesser used vma_area_struct members into the last
    cacheline (bsc#1236648).
  - Refresh
    patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch.
  - commit 3621034
  - mm: replace vm_lock and detached flag with a reference count
    (bsc#1236648).
  - Refresh
    patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch.
  - commit 20a4f53
  - refcount: introduce
    __refcount_{add|inc}_not_zero_limited_acquire (bsc#1236648).
  - commit 7cae058
  - refcount: provide ops for cases when object's memory can be
    reused (bsc#1236648).
  - commit 65378f2
  - mm: uninline the main body of vma_start_write() (bsc#1236648).
  - commit 07fd6a8
  - mm: move mmap_init_lock() out of the header file (bsc#1236648).
  - commit fef8887
  - mm: allow vma_start_read_locked/vma_start_read_locked_nested
    to fail (bsc#1236648).
  - commit 8ccc607
  - types: move struct rcuwait into types.h (bsc#1236648).
  - commit aafad00
  - mm: mark vmas detached upon exit (bsc#1236648).
  - commit f8b68a1
  - mm: introduce vma_iter_store_attached() to use with attached
    vmas (bsc#1236648).
  - commit 466e36f
  - mm: move per-vma lock into vm_area_struct (bsc#1236648).
  - Refresh
    patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch.
  - commit 95e3916
  - mm: mark vma as detached until it's added into vma tree
    (bsc#1236648).
  - commit 73de5d7
  - usbnet:fix NPE during rx_complete (git-fixes).
  - commit 0174b0c
  - Refresh patches.suse/btrfs-fix-use-after-free-waiting-for-encoded-read-en.patch (bsc#1240559).
    There was a trivial typo in commit 0406131af095 ("btrfs: fix use-after-free
    waiting for encoded read endios (bsc#1235128)") while backporting d29662695ed7c.
    This refresh fixes the typo.
  - commit 7d8f5ea
  - mm/slab/kvfree_rcu: Switch to WQ_MEM_RECLAIM wq (CVE-2025-21983
    bsc#1240792).
  - commit 5558350
  - mm/huge_memory: drop beyond-EOF folios with the right number
    of refs (CVE-2025-22000 bsc#1240834).
  - commit 71ff73e
  - mm: abort vma_modify() on merge out of memory failure
    (CVE-2025-21932 bsc#1240707).
  - commit b1120f6
  - net: mana: Switch to page pool for jumbo frames (git-fixes).
  - net/mana: fix warning in the writer of client oob (git-fixes).
  - PCI: hv: Correct a comment (git-fixes).
  - net: mana: Add metadata support for xdp mode (git-fixes).
  - net: mana: Add debug logs in MANA network driver (git-fixes).
  - hv_netvsc: Use VF's tso_max_size value when data path is VF (git-fixes).
  - net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (git-fixes).
  - scsi: storvsc: Don't report the host packet status as the hv status (git-fixes).
  - x86/hyperv: fix an indentation issue in mshyperv.h (git-fixes).
  - x86/hyperv: Add comments about hv_vpset and var size hypercall input args (git-fixes).
  - Drivers: hv: Introduce mshv_root module to expose /dev/mshv to VMMs (git-fixes).
  - hyperv: Add definitions for root partition driver to hv headers (git-fixes).
  - x86: hyperv: Add mshv_handler() irq handler and setup function (git-fixes).
  - Drivers: hv: Introduce per-cpu event ring tail (git-fixes).
  - Drivers: hv: Export some functions for use by root partition module (git-fixes).
  - acpi: numa: Export node_to_pxm() (git-fixes).
  - hyperv: Introduce hv_recommend_using_aeoi() (git-fixes).
  - arm64/hyperv: Add some missing functions to arm64 (git-fixes).
  - x86/mshyperv: Add support for extended Hyper-V features (git-fixes).
  - hyperv: Log hypercall status codes as strings (git-fixes).
  - x86/hyperv: Fix check of return value from snp_set_vmsa() (git-fixes).
  - x86/hyperv: Add VTL mode callback for restarting the system (git-fixes).
  - x86/hyperv: Add VTL mode emergency restart callback (git-fixes).
  - hyperv: Remove unused union and structs (git-fixes).
  - hyperv: Add CONFIG_MSHV_ROOT to gate root partition support (git-fixes).
  - hyperv: Change hv_root_partition into a function (git-fixes).
  - hyperv: Convert hypercall statuses to linux error codes (git-fixes).
  - drivers/hv: add CPU offlining support (git-fixes).
  - drivers/hv: introduce vmbus_channel_set_cpu() (git-fixes).
  - cpu: export lockdep_assert_cpus_held() (git-fixes).
  - hyperv: Move arch/x86/hyperv/hv_proc.c to drivers/hv (git-fixes).
  - hyperv: Move hv_current_partition_id to arch-generic code (git-fixes).
  - x86/hyperv: Use named operands in inline asm (git-fixes).
  - commit 3716372
  - ACPI/HMAT: Move HMAT messages to pr_debug() (bsc#1240653)
  - commit c3391ab
  - x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less
    NUMA nodes (CVE-2025-21991 bsc#1240795).
  - x86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()
    (CVE-2025-21913 bsc#1240591).
  - commit 222a34e
  - NFS: fix nfs_release_folio() to not deadlock via kcompactd
    writeback (CVE-2025-21908 bsc#1240600).
  - commit bfa8b42

++++ util-linux-systemd:

  - Update to version 2.41:
    * agetty: Fixed an issue where issue files were not being printed
    from additional locations, such as /run or /usr/lib. This
    change now allows for the use of local information from /etc,
    in addition to generated files from /run and
    distribution-specific files from /usr/lib.
    * cfdisk and sfdisk: Added support for the --sector-size command
    line option.
    * sfdisk: Added a new option, --discard-free.
    * fdisk: Added a new command, 'T', to discard sectors.
    * chrt: The --sched-runtime now supports SCHED_{OTHER,BATCH}
    policies.
    * column: Can now handle ANSI SGR colors inside OSC 8 hyperlink
    escape codes and sequences.
    * enosys: Can now dump defined filters.
    * libmount:
    * Added experimental support for statmount() and listmount()
    syscalls.
    * This new functionality can be accessed using "findmnt
  - -kernel=listmount".
    * Added a new mount option,
    X-mount.nocanonicalize[=source|target].
    * Added new mount extensions to the "ro" flag (ro[=vfs,fs]).
    * Added a new option, X-mount.noloop, to disable automatic loop
    device creation.
    * Now supports bind symlinks over symlinks.
    * Reads all kernel info/warning/error messages from new API
    syscalls (and mount(8) prints them).
    * libuuid: Now supports RFC9562 UUIDs.
    * findmnt, lsblk, and lsfd: Added a new --hyperlink command line
    option to print paths as terminal hyperlinks.
    * findmnt: Can now address filesystems using --id and --uniq-id
    (requires listmount() kernel support).
    * flock: Added support for the --fcntl command line option.
    * hardlink: Can now prioritize specified trees on the command
    line using --prioritize-trees.
    * Can exclude sub-trees using --exclude-subtree or keep them in
    the current mount using --mount.
    * Duplicates can now be printed using --list-duplicates.
    * hwclock: Added a new --param-index option to address position
    for RTC_PARAM_{GET,SET} ioctls.
    * kill: Can now decode signal masks (e.g. as used in /proc) to
    signal names.
    * libblkid: Made many changes to improve detection, including
    exfat, GPT, LUKS2, bitlocker, etc.
    * login: Added support for LOGIN_ENV_SAFELIST in /etc/login.def.
    * lsfd: Now supports pidfs and AF_VSOCK sockets.
    * lsipc, ipcmk, ipcrm: Now supports POSIX ipc.
    * lslogins: Now supports lastlog2.
    * lsns: Added support for the --filter option.
    * build by meson: Now supports translated man pages and has fixed
    many bugs.
    * mkswap: The option --file should now be usable on btrfs.
    * nsenter: Improved support for pidfd and can now join target
    process's socket net namespace.
    * scriptlive: Added a new option, --echo <never|always|auto>.
    * zramctl: Now supports COMP-RATIO and --algorithm-params.
    * Many other new features and fixes. For complete list see
    https://kernel.org/pub/linux/utils/util-linux/v2.41/v2.41-ReleaseNotes
  - Update util-linux-login_defs-check.sh:
    * Make instructions up to date.
    * Update checksum reflecting the shadow update.
  - Refresh libmount-print-a-blacklist-hint-for-unknown-filesyst.patch.

++++ util-linux:

  - Update to version 2.41:
    * agetty: Fixed an issue where issue files were not being printed
    from additional locations, such as /run or /usr/lib. This
    change now allows for the use of local information from /etc,
    in addition to generated files from /run and
    distribution-specific files from /usr/lib.
    * cfdisk and sfdisk: Added support for the --sector-size command
    line option.
    * sfdisk: Added a new option, --discard-free.
    * fdisk: Added a new command, 'T', to discard sectors.
    * chrt: The --sched-runtime now supports SCHED_{OTHER,BATCH}
    policies.
    * column: Can now handle ANSI SGR colors inside OSC 8 hyperlink
    escape codes and sequences.
    * enosys: Can now dump defined filters.
    * libmount:
    * Added experimental support for statmount() and listmount()
    syscalls.
    * This new functionality can be accessed using "findmnt
  - -kernel=listmount".
    * Added a new mount option,
    X-mount.nocanonicalize[=source|target].
    * Added new mount extensions to the "ro" flag (ro[=vfs,fs]).
    * Added a new option, X-mount.noloop, to disable automatic loop
    device creation.
    * Now supports bind symlinks over symlinks.
    * Reads all kernel info/warning/error messages from new API
    syscalls (and mount(8) prints them).
    * libuuid: Now supports RFC9562 UUIDs.
    * findmnt, lsblk, and lsfd: Added a new --hyperlink command line
    option to print paths as terminal hyperlinks.
    * findmnt: Can now address filesystems using --id and --uniq-id
    (requires listmount() kernel support).
    * flock: Added support for the --fcntl command line option.
    * hardlink: Can now prioritize specified trees on the command
    line using --prioritize-trees.
    * Can exclude sub-trees using --exclude-subtree or keep them in
    the current mount using --mount.
    * Duplicates can now be printed using --list-duplicates.
    * hwclock: Added a new --param-index option to address position
    for RTC_PARAM_{GET,SET} ioctls.
    * kill: Can now decode signal masks (e.g. as used in /proc) to
    signal names.
    * libblkid: Made many changes to improve detection, including
    exfat, GPT, LUKS2, bitlocker, etc.
    * login: Added support for LOGIN_ENV_SAFELIST in /etc/login.def.
    * lsfd: Now supports pidfs and AF_VSOCK sockets.
    * lsipc, ipcmk, ipcrm: Now supports POSIX ipc.
    * lslogins: Now supports lastlog2.
    * lsns: Added support for the --filter option.
    * build by meson: Now supports translated man pages and has fixed
    many bugs.
    * mkswap: The option --file should now be usable on btrfs.
    * nsenter: Improved support for pidfd and can now join target
    process's socket net namespace.
    * scriptlive: Added a new option, --echo <never|always|auto>.
    * zramctl: Now supports COMP-RATIO and --algorithm-params.
    * Many other new features and fixes. For complete list see
    https://kernel.org/pub/linux/utils/util-linux/v2.41/v2.41-ReleaseNotes
  - Update util-linux-login_defs-check.sh:
    * Make instructions up to date.
    * Update checksum reflecting the shadow update.
  - Refresh libmount-print-a-blacklist-hint-for-unknown-filesyst.patch.

++++ ncurses:

  - Add ncurses patch 20250405
    + improve formatting/style of manpages (patches by Branden Robinson).
    + improve infocmp -E/-e fallback feature (report by Ville Rissanen):
    + prefix names with "ti_" if they begin with a digit, e.g., 9term
    + escape backslashes and double-quotes in description fields
    + modify infocmp -E/-e fallback feature to reduce stricter compiler
    warnings for the extended capability data.
    + add sclp -TD
    + add op to vt525 -TD
    + update contour -TD
  - The new sclp terminfo description entry if for s390 sclp terminal lines
  - Correct offsets of patches
    * ncurses-6.4.dif
    * ncurses-6.5-ghostty.dif
  - Modify patch ncurses-5.9-ibm327x.dif
    * Make use of dumb

++++ slang:

  - Drop pcre module, it hasn't been ported to pcre2 yet.

++++ man:

  - Modify patch man-db-2.6.3-listall.dif
    * If a section is specified do not show the list (boo#1240874)
    * Wait 15 seconds instead of 7 instead for a choice
    * Explicit mention `export' instead of `set' for MAN_POSIXLY_CORRECT

++++ openssh:

  - Do not try to create /etc/ssh in sshd-gen-keys-start
    (bsc#1238191). sshd-gen-keys-start transitions to a SELinux
    domain that doesn't have the necessary permissions. Based on
    a SR by Johannes Segitz <jsegitz@suse.com>.

++++ python-ec2metadata:

  - Switch the build to s apecific Python interpreter. This avoids
    chasing Python binary names in our image build setup.

++++ python-gcemetadata:

  - Switch to a defined Python interpreter. Use the primary interpreter
    in SLE 16 and later distributions and Python 3.11 for SLE 15 SP4 and
    later.

++++ wpa_supplicant:

  - CVE-2025-24912: hostapd fails to process crafted RADIUS packets
    properly (bsc#1239461)
    [+ CVE-2025-24912.patch]
  - Drop rcFOO symlinks for CODE16 (PED-266).
  - Revert "Mark authorization completed on driver indication
    during 4-way HS offload" because of WPA2-PSK/WPA-SAE connection
    problems with brcmfmac wifi hardware. (bsc#1230797, bsc#1240791)
    [+ Revert-Mark-authorization-completed-on-driver-indica.patch]

------------------------------------------------------------------
------------------  2025-4-6  -  Apr 6 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Bluetooth: L2CAP: Fix corrupted list in hci_chan_del
    (CVE-2025-21969 bsc#1240784).
  - commit d0f474f
  - Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
    (CVE-2025-21969 bsc#1240784).
  - iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in
    ibft_attr_show_nic() (CVE-2025-21993 bsc#1240797).
  - commit 10fbb41
  - drm/amdgpu/gfx12: fix num_mec (git-fixes).
  - drm/amdgpu/gfx11: fix num_mec (git-fixes).
  - drm/amdgpu: Prefer shadow rom when available (git-fixes).
  - drm/amd/display: Actually do immediate vblank disable
    (git-fixes).
  - drm/amd/display: Increase vblank offdelay for PSR panels
    (git-fixes).
  - drm/amd/pm: Prevent division by zero (git-fixes).
  - Input: pm8941-pwrkey - fix dev_dbg() output in
    pm8941_pwrkey_irq() (git-fixes).
  - Input: synaptics - hide unused smbus_pnp_ids[] array
    (git-fixes).
  - commit 33c0e80

++++ kernel-rt:

  - Bluetooth: L2CAP: Fix corrupted list in hci_chan_del
    (CVE-2025-21969 bsc#1240784).
  - commit d0f474f
  - Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
    (CVE-2025-21969 bsc#1240784).
  - iscsi_ibft: Fix UBSAN shift-out-of-bounds warning in
    ibft_attr_show_nic() (CVE-2025-21993 bsc#1240797).
  - commit 10fbb41
  - drm/amdgpu/gfx12: fix num_mec (git-fixes).
  - drm/amdgpu/gfx11: fix num_mec (git-fixes).
  - drm/amdgpu: Prefer shadow rom when available (git-fixes).
  - drm/amd/display: Actually do immediate vblank disable
    (git-fixes).
  - drm/amd/display: Increase vblank offdelay for PSR panels
    (git-fixes).
  - drm/amd/pm: Prevent division by zero (git-fixes).
  - Input: pm8941-pwrkey - fix dev_dbg() output in
    pm8941_pwrkey_irq() (git-fixes).
  - Input: synaptics - hide unused smbus_pnp_ids[] array
    (git-fixes).
  - commit 33c0e80

++++ libsoup:

  - Rerun tests once for s390x should they fail, tests for this arch
    is very flaky.

------------------------------------------------------------------
------------------  2025-4-5  -  Apr 5 2025  -------------------
------------------------------------------------------------------

++++ diffutils:

  - Fix failure (noticed in sdiff as fatal "realloc(): invalid next size")
    Original upstream report: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=77265
    New patch: diff-fix-allocation-typo-leading-to-crashes.patch

++++ kernel-default:

  - ALSA: hda/realtek: Enable Mute LED on HP OMEN 16 Laptop xd000xx
    (stable-fixes).
  - ALSA: usb-audio: Add quirk for Plantronics headsets to fix
    control names (stable-fixes).
  - ALSA: hda/realtek: Bass speaker fixup for ASUS UM5606KA
    (stable-fixes).
  - ALSA: hda/realtek: Support mute LED on HP Laptop 15s-du3xxx
    (stable-fixes).
  - commit 1c28dfb
  - usbnet:fix NPE during rx_complete (git-fixes).
  - spi: bcm2835: Restore native CS probing when pinctrl-bcm2835
    is absent (git-fixes).
  - spi: bcm2835: Do not call gpiod_put() on invalid descriptor
    (git-fixes).
  - spi: cadence: Fix out-of-bounds array access in
    cdns_mrvl_xspi_setup_clock() (git-fixes).
  - platform/x86: ISST: Correct command storage data length
    (git-fixes).
  - ASoC: imx-card: Add NULL check in imx_card_probe() (git-fixes).
  - ASoC: q6apm-dai: make use of q6apm_get_hw_pointer (git-fixes).
  - ASoC: qdsp6: q6apm-dai: fix capture pipeline overruns
    (git-fixes).
  - ASoC: qdsp6: q6apm-dai: set 10 ms period and buffer alignment
    (git-fixes).
  - ASoC: q6apm: add q6apm_get_hw_pointer helper (git-fixes).
  - ASoC: q6apm-dai: schedule all available frames to avoid dsp
    under-runs (git-fixes).
  - ASoC: codecs: rt5665: Fix some error handling paths in
    rt5665_probe() (git-fixes).
  - ASoC: qdsp6: q6asm-dai: fix q6asm_dai_compr_set_params error
    path (git-fixes).
  - firmware: cs_dsp: Ensure cs_dsp_load[_coeff]() returns 0 on
    success (git-fixes).
  - ALSA: hda/realtek: Fix built-in mic on another ASUS VivoBook
    model (git-fixes).
  - ALSA: hda/realtek: Fix built-in mic breakage on ASUS VivoBook
    X515JA (git-fixes).
  - commit eb0afe3

++++ kernel-rt:

  - ALSA: hda/realtek: Enable Mute LED on HP OMEN 16 Laptop xd000xx
    (stable-fixes).
  - ALSA: usb-audio: Add quirk for Plantronics headsets to fix
    control names (stable-fixes).
  - ALSA: hda/realtek: Bass speaker fixup for ASUS UM5606KA
    (stable-fixes).
  - ALSA: hda/realtek: Support mute LED on HP Laptop 15s-du3xxx
    (stable-fixes).
  - commit 1c28dfb
  - usbnet:fix NPE during rx_complete (git-fixes).
  - spi: bcm2835: Restore native CS probing when pinctrl-bcm2835
    is absent (git-fixes).
  - spi: bcm2835: Do not call gpiod_put() on invalid descriptor
    (git-fixes).
  - spi: cadence: Fix out-of-bounds array access in
    cdns_mrvl_xspi_setup_clock() (git-fixes).
  - platform/x86: ISST: Correct command storage data length
    (git-fixes).
  - ASoC: imx-card: Add NULL check in imx_card_probe() (git-fixes).
  - ASoC: q6apm-dai: make use of q6apm_get_hw_pointer (git-fixes).
  - ASoC: qdsp6: q6apm-dai: fix capture pipeline overruns
    (git-fixes).
  - ASoC: qdsp6: q6apm-dai: set 10 ms period and buffer alignment
    (git-fixes).
  - ASoC: q6apm: add q6apm_get_hw_pointer helper (git-fixes).
  - ASoC: q6apm-dai: schedule all available frames to avoid dsp
    under-runs (git-fixes).
  - ASoC: codecs: rt5665: Fix some error handling paths in
    rt5665_probe() (git-fixes).
  - ASoC: qdsp6: q6asm-dai: fix q6asm_dai_compr_set_params error
    path (git-fixes).
  - firmware: cs_dsp: Ensure cs_dsp_load[_coeff]() returns 0 on
    success (git-fixes).
  - ALSA: hda/realtek: Fix built-in mic on another ASUS VivoBook
    model (git-fixes).
  - ALSA: hda/realtek: Fix built-in mic breakage on ASUS VivoBook
    X515JA (git-fixes).
  - commit eb0afe3

++++ libarchive:

  - Update to 3.7.9:
    * fix regression regarding GNU sparse entries

++++ harfbuzz:

  - Update to version 11.0.1:
    + The change in version 10.3.0 to apply “trak” table tracking
    values to glyph advances directly has been reverted as it
    required every font functions implementation to handle it,
    which breaks existing custom font functions. Tracking is
    instead back to being applied during shaping.
    + When directwrite integration is enabled, we now link to
    dwrite.dll instead of dynamically loading it.
    + A new experimental APIs for getting raw “CFF” and “CFF2”
    CharStrings.
    + We now provide manpages for the various command line utilities.
    Building manpages requires “help2man” and will be skipped if it
    is not present.
    + The command line utilities now set different return value for
    different kinds of failures. Details are provided in the
    manpages.
    + Various fixes and improvements to fontations font functions.
    + All shaping operations using the ot shaper have become memory
    allocation-free.
    + Glyph extents returned by hb-ot and hb-ft font functions are
    now rounded in stead of flooring/ceiling them, which also
    matches what other font libraries do.
    + Fix “AAT” deleted glyph marks interfering with fallback mark
    positioning.
    + Glyph outlines emboldening have been moved out of hb-ot and
    hb-ft font functions to the HarfBuzz font layer, so that it
    works with any font functions implementation.
    + Fix our fallback C++11 atomics integration, which seems to not
    be widely used.
    + Various testing fixes and improvements.
    + Various subsetting fixes and improvements.
    + Various other fixes and improvements.

------------------------------------------------------------------
------------------  2025-4-4  -  Apr 4 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Update dracut kiwi-lib module setup
    Make sure all tools used in code are requested for inclusion

++++ gawk:

  - GNU awk 5.3.2:
    * pretty printer now produces fewer spurious newlines
    * -no-pie linker flag is no longer required
    * fix more subtle issues related to uninitialized array elements
    * Associative arrays should now not grow quite as fast as they
    used to
    * documentation updates

++++ texinfo:

  - add -std=gnu17 to CFLAGS to fix gcc15 compile time error
    (flag can be dropped w/ release 7.2)

++++ kernel-default:

  - Delete patches.suse/tpm-send_data-Wait-longer-for-the-TPM-to-become-read.patch.
    To be replaced with upstream fix.
  - commit 05e2046
  - rpm/config.sh: Enable LIVEPATCH_RT
    This will be needed with merged RT branch
  - commit 3491368
  - tools: add VM_WARN_ON_VMG definition (bsc#1236648).
  - commit b9bc574
  - seqlock: add missing parameter documentation for
    raw_seqcount_try_begin() (bsc#1236648).
  - commit 1a97d75
  - mm: introduce mmap_lock_speculate_{try_begin|retry}
    (bsc#1236648).
  - commit d7eec4e
  - mm: convert mm_lock_seq to a proper seqcount (bsc#1236648).
  - commit 5975193
  - mm/gup: Use raw_seqcount_try_begin() (bsc#1236648).
  - commit 8a17d47
  - seqlock: add raw_seqcount_try_begin (bsc#1236648).
  - commit 0c393c8
  - rtnetlink: Allocate vfinfo size for VF GUIDs when supported
    (bsc#1224013).
  - commit 93c2a65
  - mm: introduce vma_start_read_locked{_nested} helpers
    (bsc#1236648).
  - commit e4c793a
  - mm: completely abstract unnecessary adj_start calculation
    (bsc#1236648).
  - commit 3a293a4
  - mm: make vmg->target consistent and further simplify
    commit_merge() (bsc#1236648).
  - commit ce2f380
  - mm: eliminate adj_start parameter from commit_merge()
    (bsc#1236648).
  - commit 558534f
  - mm: further refactor commit_merge() (bsc#1236648).
  - commit 093c32c
  - mm: simplify vma merge structure and expand comments
    (bsc#1236648).
  - commit bd25498
  - mm/debug: prefer VM_WARN_ON_VMG() to report VMG debug warnings
    (bsc#1236648).
  - commit cd94aee
  - cpuidle: menu: Update documentation after get_typical_interval()
    changes (bsc#1234634 (Scheduler functional and performance
    backports)).
  - commit 930e090
  - cpuidle: menu: Update documentation after previous changes
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 65fe202
  - mm: make mmap_region() internal (bsc#1236648).
  - commit d96d66d
  - mm/debug: introduce VM_WARN_ON_VMG() to dump VMA merge state
    (bsc#1236648).
  - commit 595e9aa
  - mm: remove unnecessary calls to lru_add_drain (bsc#1236648).
  - commit 4e1322b
  - mm: add comments to do_mmap(), mmap_region() and vm_mmap()
    (bsc#1236648).
  - commit f63b0a5
  - mm: assert mmap write lock held on do_mmap(), mmap_region()
    (bsc#1236648).
  - commit 9aa4cb9
  - mm: perform all memfd seal checks in a single place
    (bsc#1236648).
  - commit 5547229
  - mm: enforce __must_check on VMA merge and split (bsc#1236648).
  - commit 68d1342
  - kernel-binary: Support livepatch_rt with merged RT branch
  - commit 470cd1a
  - Update and enable
    patches.suse/cpuidle-menu-Bias-selection-of-a-shallower-c-state-when-CPU-idles-for-IO.patch
    (bsc#1193353,bsc#1237425).
  - commit 0d14d31
  - cpuidle: menu: Avoid discarding useful information (bsc#1234634
    (Scheduler functional and performance backports)).
  - cpuidle: menu: Eliminate outliers on both ends of the sample set
    (bsc#1234634 (Scheduler functional and performance backports)).
  - cpuidle: menu: Tweak threshold use in get_typical_interval()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - cpuidle: menu: Use one loop for average and variance
    computations (bsc#1234634 (Scheduler functional and performance
    backports)).
  - cpuidle: menu: Drop a redundant local variable (bsc#1234634
    (Scheduler functional and performance backports)).
  - cpuidle: menu: Remove iowait influence (bsc#1234634 (Scheduler
    functional and performance backports)).
  - commit 49ef926
  - mm/vma: move __vm_munmap() to mm/vma.c (bsc#1236648).
  - commit 206f77d
  - mm/vma: move stack expansion logic to mm/vma.c (bsc#1236648).
  - commit eceb38c
  - mm: abstract get_arg_page() stack expansion and mmap read lock
    (bsc#1236648).
  - commit e7be015
  - mm/vma: move unmapped_area() internals to mm/vma.c
    (bsc#1236648).
  - commit ae04c39
  - mm/vma: move brk() internals to mm/vma.c (bsc#1236648).
  - commit 71942ff
  - arm64: Don't call NULL in do_compat_alignment_fixup() (git-fixes)
  - commit 7dce8aa
  - arm64: mm: Drop dead code for pud special bit handling (git-fixes)
  - commit 1f7e15c
  - arm64: mops: Do not dereference src reg for a set operation (git-fixes)
  - commit 41a6490
  - arm64: mm: Correct the update of max_pfn (git-fixes)
  - commit 67d6463
  - arm64: Utilize for_each_cpu_wrap for reference lookup (bsc#1238052)
  - commit e541ce3
  - arch_topology: init capacity_freq_ref to 0 (bsc#1238052)
  - commit 8ce966e
  - cpufreq: Introduce an optional cpuinfo_avg_freq sysfs entry (bsc#1238052)
    Keep the feature disabled by default on x86_64
  - commit 5f4c4bc
  - cpufreq: Allow arch_freq_get_on_cpu to return an error (bsc#1238052)
  - commit 8850fea
  - arm64: Update AMU-based freq scale factor on entering idle (bsc#1238052)
  - commit 50698c9
  - arm64: Provide an AMU-based version of arch_freq_get_on_cpu (bsc#1238052)
  - commit 6a96c9a
  - arm64: amu: Delay allocating cpumask for AMU FIE support (bsc#1238052)
  - commit dd18237
  - tpm: tis: Double the timeout B to 4s (bsc#1235870).
  - commit 1ff9564
  - tpm, tpm_tis: Workaround failed command reception on Infineon
    devices (bsc#1235870).
  - commit 76159f7
  - Update
    patches.suse/ice-fix-memory-leak-in-aRFS-after-reset.patch
    (jsc#PED-10419 CVE-2025-21981 bsc#1240612).
    Added CVE reference.
  - commit a80c7dd
  - mctp i3c: handle NULL header address (CVE-2025-21903
    bsc#1240580).
  - ppp: Fix KMSAN uninit-value warning with bpf (CVE-2025-21922
    bsc#1240639).
  - net: hns3: make sure ptp clock is unregister and freed
    if hclge_ptp_get_cycle returns an error (CVE-2025-21924
    bsc#1240720).
  - net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC
    (CVE-2025-21894 bsc#1240581).
  - commit 4e4dcb0
  - lib: scatterlist: fix sg_split_phys to preserve original
    scatterlist offsets (git-fixes).
  - acpi: nfit: fix narrowing conversion in acpi_nfit_ctl
    (git-fixes).
  - commit 298ac86

++++ kernel-rt:

  - Delete patches.suse/tpm-send_data-Wait-longer-for-the-TPM-to-become-read.patch.
    To be replaced with upstream fix.
  - commit 05e2046
  - rpm/config.sh: Enable LIVEPATCH_RT
    This will be needed with merged RT branch
  - commit 3491368
  - tools: add VM_WARN_ON_VMG definition (bsc#1236648).
  - commit b9bc574
  - seqlock: add missing parameter documentation for
    raw_seqcount_try_begin() (bsc#1236648).
  - commit 1a97d75
  - mm: introduce mmap_lock_speculate_{try_begin|retry}
    (bsc#1236648).
  - commit d7eec4e
  - mm: convert mm_lock_seq to a proper seqcount (bsc#1236648).
  - commit 5975193
  - mm/gup: Use raw_seqcount_try_begin() (bsc#1236648).
  - commit 8a17d47
  - seqlock: add raw_seqcount_try_begin (bsc#1236648).
  - commit 0c393c8
  - rtnetlink: Allocate vfinfo size for VF GUIDs when supported
    (bsc#1224013).
  - commit 93c2a65
  - mm: introduce vma_start_read_locked{_nested} helpers
    (bsc#1236648).
  - commit e4c793a
  - mm: completely abstract unnecessary adj_start calculation
    (bsc#1236648).
  - commit 3a293a4
  - mm: make vmg->target consistent and further simplify
    commit_merge() (bsc#1236648).
  - commit ce2f380
  - mm: eliminate adj_start parameter from commit_merge()
    (bsc#1236648).
  - commit 558534f
  - mm: further refactor commit_merge() (bsc#1236648).
  - commit 093c32c
  - mm: simplify vma merge structure and expand comments
    (bsc#1236648).
  - commit bd25498
  - mm/debug: prefer VM_WARN_ON_VMG() to report VMG debug warnings
    (bsc#1236648).
  - commit cd94aee
  - cpuidle: menu: Update documentation after get_typical_interval()
    changes (bsc#1234634 (Scheduler functional and performance
    backports)).
  - commit 930e090
  - cpuidle: menu: Update documentation after previous changes
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 65fe202
  - mm: make mmap_region() internal (bsc#1236648).
  - commit d96d66d
  - mm/debug: introduce VM_WARN_ON_VMG() to dump VMA merge state
    (bsc#1236648).
  - commit 595e9aa
  - mm: remove unnecessary calls to lru_add_drain (bsc#1236648).
  - commit 4e1322b
  - mm: add comments to do_mmap(), mmap_region() and vm_mmap()
    (bsc#1236648).
  - commit f63b0a5
  - mm: assert mmap write lock held on do_mmap(), mmap_region()
    (bsc#1236648).
  - commit 9aa4cb9
  - mm: perform all memfd seal checks in a single place
    (bsc#1236648).
  - commit 5547229
  - mm: enforce __must_check on VMA merge and split (bsc#1236648).
  - commit 68d1342
  - kernel-binary: Support livepatch_rt with merged RT branch
  - commit 470cd1a
  - Update and enable
    patches.suse/cpuidle-menu-Bias-selection-of-a-shallower-c-state-when-CPU-idles-for-IO.patch
    (bsc#1193353,bsc#1237425).
  - commit 0d14d31
  - cpuidle: menu: Avoid discarding useful information (bsc#1234634
    (Scheduler functional and performance backports)).
  - cpuidle: menu: Eliminate outliers on both ends of the sample set
    (bsc#1234634 (Scheduler functional and performance backports)).
  - cpuidle: menu: Tweak threshold use in get_typical_interval()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - cpuidle: menu: Use one loop for average and variance
    computations (bsc#1234634 (Scheduler functional and performance
    backports)).
  - cpuidle: menu: Drop a redundant local variable (bsc#1234634
    (Scheduler functional and performance backports)).
  - cpuidle: menu: Remove iowait influence (bsc#1234634 (Scheduler
    functional and performance backports)).
  - commit 49ef926
  - mm/vma: move __vm_munmap() to mm/vma.c (bsc#1236648).
  - commit 206f77d
  - mm/vma: move stack expansion logic to mm/vma.c (bsc#1236648).
  - commit eceb38c
  - mm: abstract get_arg_page() stack expansion and mmap read lock
    (bsc#1236648).
  - commit e7be015
  - mm/vma: move unmapped_area() internals to mm/vma.c
    (bsc#1236648).
  - commit ae04c39
  - mm/vma: move brk() internals to mm/vma.c (bsc#1236648).
  - commit 71942ff
  - arm64: Don't call NULL in do_compat_alignment_fixup() (git-fixes)
  - commit 7dce8aa
  - arm64: mm: Drop dead code for pud special bit handling (git-fixes)
  - commit 1f7e15c
  - arm64: mops: Do not dereference src reg for a set operation (git-fixes)
  - commit 41a6490
  - arm64: mm: Correct the update of max_pfn (git-fixes)
  - commit 67d6463
  - arm64: Utilize for_each_cpu_wrap for reference lookup (bsc#1238052)
  - commit e541ce3
  - arch_topology: init capacity_freq_ref to 0 (bsc#1238052)
  - commit 8ce966e
  - cpufreq: Introduce an optional cpuinfo_avg_freq sysfs entry (bsc#1238052)
    Keep the feature disabled by default on x86_64
  - commit 5f4c4bc
  - cpufreq: Allow arch_freq_get_on_cpu to return an error (bsc#1238052)
  - commit 8850fea
  - arm64: Update AMU-based freq scale factor on entering idle (bsc#1238052)
  - commit 50698c9
  - arm64: Provide an AMU-based version of arch_freq_get_on_cpu (bsc#1238052)
  - commit 6a96c9a
  - arm64: amu: Delay allocating cpumask for AMU FIE support (bsc#1238052)
  - commit dd18237
  - tpm: tis: Double the timeout B to 4s (bsc#1235870).
  - commit 1ff9564
  - tpm, tpm_tis: Workaround failed command reception on Infineon
    devices (bsc#1235870).
  - commit 76159f7
  - Update
    patches.suse/ice-fix-memory-leak-in-aRFS-after-reset.patch
    (jsc#PED-10419 CVE-2025-21981 bsc#1240612).
    Added CVE reference.
  - commit a80c7dd
  - mctp i3c: handle NULL header address (CVE-2025-21903
    bsc#1240580).
  - ppp: Fix KMSAN uninit-value warning with bpf (CVE-2025-21922
    bsc#1240639).
  - net: hns3: make sure ptp clock is unregister and freed
    if hclge_ptp_get_cycle returns an error (CVE-2025-21924
    bsc#1240720).
  - net: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC
    (CVE-2025-21894 bsc#1240581).
  - commit 4e4dcb0
  - lib: scatterlist: fix sg_split_phys to preserve original
    scatterlist offsets (git-fixes).
  - acpi: nfit: fix narrowing conversion in acpi_nfit_ctl
    (git-fixes).
  - commit 298ac86

++++ openssl-3:

  - Update to 3.5.0:
    * Security fixes:
  - [bsc#1243459, CVE-2025-27587] Minerva side channel vulnerability in P-384
    * Changes:
  - Default encryption cipher for the req, cms, and smime applications
    changed from des-ede3-cbc to aes-256-cbc.
  - The default TLS supported groups list has been changed to include
    and prefer hybrid PQC KEM groups. Some practically unused groups
    were removed from the default list.
  - The default TLS keyshares have been changed to offer X25519MLKEM768
    and and X25519.
  - All BIO_meth_get_*() functions were deprecated.
    * New features:
  - Support for server side QUIC (RFC 9000)
  - Support for 3rd party QUIC stacks including 0-RTT support
  - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA)
  - A new configuration option no-tls-deprecated-ec to disable support
    for TLS groups deprecated in RFC8422
  - A new configuration option enable-fips-jitter to make the FIPS
    provider to use the JITTER seed source
  - Support for central key generation in CMP
  - Support added for opaque symmetric key objects (EVP_SKEY)
  - Support for multiple TLS keyshares and improved TLS key establishment
    group configurability
  - API support for pipelining in provided cipher algorithms
    * Remove patches:
  - openssl-3-disable-hmac-hw-acceleration-with-engine-digest.patch
  - openssl-3-support-CPACF-sha3-shake-perf-improvement.patch
  - openssl-3-add-defines-CPACF-funcs.patch
  - openssl-3-fix-memleak-s390x_HMAC_CTX_copy.patch
  - openssl-3-add-xof-state-handling-s3_absorb.patch
  - openssl-3-fix-state-handling-sha3_absorb_s390x.patch
  - openssl-3-fix-s390x_shake_squeeze.patch
  - openssl-3-hw-acceleration-aes-xts-s390x.patch
  - openssl-3-support-EVP_DigestSqueeze-in-digest-prov-s390x.patch
  - openssl-3-fix-state-handling-keccak_final_s390x.patch
  - openssl-3-add-hw-acceleration-hmac.patch
  - openssl-3-fix-state-handling-sha3_final_s390x.patch
  - openssl-3-fix-hmac-digest-detection-s390x.patch
  - openssl-3-support-multiple-sha3_squeeze_s390x.patch
  - openssl-3-fix-sha3-squeeze-ppc64.patch
  - openssl-3-fix-s390x_sha3_absorb.patch
  - openssl-3-fix-state-handling-shake_final_s390x.patch
  - openssl-3-add_EVP_DigestSqueeze_api.patch
  - openssl-FIPS-enforce-security-checks-during-initialization.patch
  - openssl-FIPS-140-3-zeroization.patch
  - openssl-FIPS-Add-explicit-indicator-for-key-length.patch
  - openssl-FIPS-Mark-SHA1-as-nonapproved.patch
  - openssl-Remove-EC-curves.patch
  - openssl-FIPS-services-minimize.patch
  - openssl-Revert-Improve-FIPS-RSA-keygen-performance.patch
  - openssl-3-FIPS-GCM-Implement-explicit-indicator-for-IV-gen.patch
  - openssl-3-fix-quic_multistream_test.patch
  - openssl-3-jitterentropy-3.4.0.patch
  - openssl-Add-FIPS-indicator-parameter-to-HKDF.patch
  - openssl-FIPS-140-3-DRBG.patch
  - openssl-FIPS-Use-FFDHE2048-in-self-test.patch
  - openssl-FIPS-Use-digest_sign-digest_verify-in-self-test.patch
  - openssl-FIPS-signature-Add-indicator-for-PSS-salt-length.patch
  - openssl-pbkdf2-Set-indicator-if-pkcs5-param-disabled-checks.patch
  - openssl-FIPS-enforce-EMS-support.patch
  - openssl-Allow-disabling-of-SHA1-signatures.patch
  - openssl-3-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch
    * Rebased patches:
  - openssl-pkgconfig.patch
  - openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch
  - openssl-Add-Kernel-FIPS-mode-flag-support.patch
  - openssl-Force-FIPS.patch
  - openssl-disable-fipsinstall.patch
  - openssl-FIPS-embed-hmac.patch
  - openssl-Add-changes-to-ectest-and-eccurve.patch
  - openssl-Disable-explicit-ec.patch
  - openssl-skipped-tests-EC-curves.patch
  - openssl-FIPS-140-3-keychecks.patch
  - openssl-FIPS-early-KATS.patch
  - openssl-FIPS-limit-rsa-encrypt.patch
  - openssl-FIPS-Expose-a-FIPS-indicator.patch
  - openssl-FIPS-Use-OAEP-in-KATs-support-fixed-OAEP-seed.patch
  - openssl-rand-Forbid-truncated-hashes-SHA-3-in-FIPS-prov.patch
  - openssl-pbkdf2-Set-minimum-password-length-of-8-bytes.patch
  - openssl-FIPS-RSA-disable-shake.patch
  - openssl-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch
  - openssl-FIPS-Enforce-error-state.patch
  - openssl-FIPS-Remove-X9.31-padding-from-FIPS-prov.patch
  - openssl-FIPS-enforce-EMS-support.patch
  - openssl-TESTS-Disable-default-provider-crypto-policies.patch
  - openssl-skip-quic-pairwise.patch
    * Add patches:
  - openssl-FIPS-Fix-encoder-decoder-negative-test.patch
  - openssl-FIPS-SUSE-FIPS-module-version.patch
  - openssl-FIPS-EC-disable-weak-curves.patch
  - openssl-FIPS-NO-DES-support.patch
  - openssl-FIPS-NO-DSA-Support.patch
  - openssl-FIPS-NO-Kmac.patch
  - openssl-FIPS-NO-PQ-ML-SLH-DSA.patch
  - openssl-shared-jitterentropy.patch
  - openssl-rh-allow-sha1-signatures.patch
  - openssl-disable-75-test_quicapi-test.patch
  - Changes between 3.3.0 and 3.4.0:
    * Changes:
  - Deprecation of TS_VERIFY_CTX_set_* functions and addition of
    replacement TS_VERIFY_CTX_set0_* functions with improved semantics
  - The X25519 and X448 key exchange implementation in the FIPS provider
    is unapproved and has fips=no property.
  - SHAKE-128 and SHAKE-256 implementations have no default digest length
    anymore. That means these algorithms cannot be used with
    EVP_DigestFinal/_ex() unless the xoflen param is set before.
  - Setting config_diagnostics=1 in the config file will cause errors to
    be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an
    error in the ssl module configuration.
  - An empty renegotiate extension will be used in TLS client hellos
    instead of the empty renegotiation SCSV, for all connections with a
    minimum TLS version > 1.0.
  - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and
    SSL_CTX_flush_sessions() functions in favor of their respective _ex
    functions which are Y2038-safe on platforms with Y2038-safe time_t
    * New features:
  - Support for directly fetched composite signature algorithms such as
    RSA-SHA2-256 including new API functions
  - FIPS indicators support in the FIPS provider and various updates of
    the FIPS provider required for future FIPS 140-3 validations
  - Implementation of RFC 9579 (PBMAC1) in PKCS#12
  - An optional additional random seed source RNG JITTER using a statically
    linked jitterentropy library
  - New options -not_before and -not_after for explicit setting start and
    end dates of certificates created with the req and x509 apps
  - Support for integrity-only cipher suites TLS_SHA256_SHA256 and
    TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150
  - Support for retrieving certificate request templates and CRLs in CMP
  - Support for additional X.509v3 extensions related to Attribute Certificates
  - Initial Attribute Certificate (RFC 5755) support
  - Possibility to customize ECC groups initialization to use precomputed
    values to save CPU time and use of this feature by the P-256 implementation
  - Changes between 3.2.0 and 3.3.0:
    * Changes:
  - Optimized AES-CTR for ARM Neoverse V1 and V2
  - Various optimizations for cryptographic routines using RISC-V vector
    crypto extensions
  - Added assembly implementation for md5 on loongarch64
  - Accept longer context for TLS 1.2 exporters
  - The activate and soft_load configuration settings for providers in
    openssl.cnf have been updated to require a value of [1|yes|true|on]
    (in lower or UPPER case) to enable the setting. Conversely a value of
    [0|no|false|off] will disable the setting.
  - In openssl speed, changed the default hash function used with hmac from
    md5 to sha256.
  - The -verify option to the openssl crl and openssl req will make the
    program exit with 1 on failure.
  - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(),
    and related functions have been augmented to check for a minimum length
    of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8.
  - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1
    if called with a NULL stack argument.
  - New limit on HTTP response headers is introduced to HTTP client.
    The default limit is set to 256 header lines.
    * Bug fixes and mitigations:
  - The BIO_get_new_index() function can only be called 127 times before
    it reaches its upper bound of BIO_TYPE_MASK and will now return -1
    once its exhausted.
    * new features:
  - Support for qlog for tracing QUIC connections has been added
  - Added APIs to allow configuring the negotiated idle timeout for QUIC
    connections, and to allow determining the number of additional streams
    that can currently be created for a QUIC connection.
  - Added APIs to allow disabling implicit QUIC event processing for QUIC
    SSL objects
  - Added APIs to allow querying the size and utilisation of a QUIC
    stream's write buffer
  - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN)
    condition in an optimised way when using QUIC.
  - Limited support for polling of QUIC connection and stream objects in a
    non-blocking manner.
  - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple
    times with different output sizes.
  - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable
    output length.
  - The EVP_PKEY_fromdata function has been augmented to allow for the
    derivation of CRT (Chinese Remainder Theorem) parameters when requested
  - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex()
    using time_t which is Y2038 safe on 32 bit systems when 64 bit time
    is enabled.
  - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms
    config
    options and the respective calls to SSL[_CTX]_set1_sigalgs() and
    SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored
    and the configuration will still be used.
  - Added -set_issuer and -set_subject options to openssl x509 to override
    the Issuer and Subject when creating a certificate. The -subj option
    now is an alias for -set_subject.
  - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483
  - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3
    server to prefer session resumption using PSK-only key exchange over
    PSK with DHE, if both are available.
  - New atexit configuration switch, which controls whether the OPENSSL_cleanup
    is registered when libcrypto is unloaded.
  - Added X509_STORE_get1_objects to avoid issues with the existing
    X509_STORE_get0_objects API in multi-threaded applications.
  - Support for using certificate profiles and extened delayed delivery in CMP

++++ openssl:

  - Update to 3.5.0

++++ python-azuremetadata:

  - Version 5.1.6
    + Handle queries of attributes that return an empty list properly
    + Switch the package build to a specific Python interpreter set
    by the project configuration in the Build Service

++++ setroubleshoot-plugins:

  - Update to 3.3.15
    * restorecon.py: exclude more paths
    * Improve disable_ipv6 plugin then_text
    * Update generated configuration files
    * Update translations
  - patch 9e54f6a661330070ad25a0e86f197b3530bfc5c7.patch removed since
    it is not needeed anymore

++++ setroubleshoot:

  - bumb version to 3.35 for SL Micro 6.2 which fixes bsc#1240428

------------------------------------------------------------------
------------------  2025-4-3  -  Apr 3 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Update to version 2.32
    * Better 3270 console support, use uevent below /sys file system

++++ btrfsprogs:

  - update to 6.14
    * mkfs:
    * allow --sectorsize to be 2K for testing purposes of subpage mode (needs
    the same block size supported by kernel)
    * fix false error when no compression is requested and lzo is not compiled in
    * convert: support 2K block size in the source filesystem
    * defrag: new parameter -L/--level to specify compression levels (kernel 6.15),
    also supports the realtime levels
    * subvol delete: show names of recursively deleted child subvolumes
    * qgroup show: use sysfs to detect up to date consistency status
    * zoned mode: support zone capacity tracking
    * other:
    * CI new and updated workflows
    * documentation updates
  - spec file:
  - update subpackage descriptions
  - drop conditional build of documentation, always use source
  - drop pre-systemd udev workarounds (version 190)

++++ python-kiwi:

  - keep /usr/bin/sha256sum
    dropping md5sum was okay, but now we need
    the current tool to verify the checksum
  - Restrict keyfile permissions
    For reencrypt in combination with rd.kiwi.oem.luks.reencrypt_randompass
    make sure that the temporary random pass keyfile has 0400 root
    owned access permissions set

++++ glib2:

  - Update to version 2.84.1:
    + Fix test failure when building against gobject-introspection
    ≥1.83.4
    + Bugs fixed:
  - 2.84.0 build failure on Linux:
    ../gio/gnetworkmonitornetlink.c:47:10: fatal error:
    netlink/netlink_route.h: No such file or directory
  - test failure with gobject-introspection 1.83.4: warning:
    element doc:format from state 3 is unknown, ignoring
  - gio/trash does not handle special characters well
  - `g_cancellable_connect()` documentation incorrect
  - g_cancellable_connect(): is it safe to unref cancellable from
    callback?
  - Crash with some registry key values in GWin32AppInfo
  - Memory sanitizer fixes
  - gobject: Be consistent in using atomic logic to handle the
    GParamSpecPool
  - gsettings: Port docs to gi-docgen format, add missing
    annotations and make various improvements
  - tests: Don't install runner scripts without installed_tests
  - docs: Document GSignalFlags members added after 2.0
  - tests: Add a test for g_object_freeze_notify() being called
    too often
  - gfileinfo: Slightly expand docs for
    g_file_info_get_attribute_as_string()
  - gi: Dynamically set doc-format
  - tests: Various fixes to create temporary files in /tmp rather
    than the build directory
  - gdbusnameowning: Convert docs to gi-docgen linking syntax
  - giounix-private: Fix macro for checking for epoll_create1()
  - Fix LGPL in header
  - gutils: make documentation of g_set_prgname() clearer
  - docs: Add some detail
  - gspawn-win32: Fix potential integer overflows in argv
    handling
  - gvarianttype: Improve docs on type validation
    + Updated translations.

++++ glibc:

  - pthread-wakeup.patch: pthreads NPTL: lost wakeup fix 2 (bsc#1234128, BZ
    [#25847])

++++ gnutls:

  - Disable liboqs on armv6

++++ guestfs-tools:

  - Update to version 1.53.9 (jsc#PED-8910)
    * Various build improvements
    * mlcustomize: ignore sriov vioprot.* files too
    * mlcustomize: don't inject .pdb files
    * mlcustomize: Only use osinfo id for virtio-win path matching
    * mlcustomize: virtio-win: clarify virtio-1.0 support
    * mlcustomize: make windows q35 check independent of virtio drivers
    * mlcustomize: virtio-win: stop checking osinfo for virtio drivers
    * mltools: Strip out all libosinfo driver plumbing
    * mlutils: Remove need for OCaml OUnit2
    * mltools: Remove need for OCaml OUnit2
    * mlstdutils: Remove need for OCaml OUnit2
    * mltools: Fix de-oUnit-ized tests

++++ kernel-default:

  - nfsd: allow SC_STATUS_FREEABLE when searching via
    nfs4_lookup_stateid() (git-fixes).
  - commit f2e6ba2
  - svcrdma: do not unregister device for listeners (git-fixes).
  - commit 0694dd5
  - NFSD: Never return NFS4ERR_FILE_OPEN when removing a directory
    (git-fixes).
  - commit 1db7344
  - NFSD: nfsd_unlink() clobbers non-zero status returned from
    fh_fill_pre_attrs() (git-fixes).
  - commit d6e06f3
  - NFSD: Skip sending CB_RECALL_ANY when the backchannel isn't up
    (git-fixes).
  - commit 1f12db0
  - nfsd: fix management of listener transports (git-fixes).
  - commit 57c3828
  - exfat: fix potential wrong error return from get_block
    (git-fixes).
  - commit f7ac77d
  - exfat: fix missing shutdown check (git-fixes).
  - commit bddb6cb
  - exfat: fix the infinite loop in exfat_find_last_cluster()
    (git-fixes).
  - commit 132ac47
  - exfat: fix random stack corruption after get_block (git-fixes).
  - commit 00c87f9
  - rpm/check-for-config-changes: ignore DRM_MSM_VALIDATE_XML
    This option is dynamically enabled to build-test different configurations.
    This makes run_oldconfig.sh complain sporadically for arm64.
  - commit 8fbe8b1
  - drm/fbdev-dma: Add shadow buffering for deferred I/O (bsc#1240174 CVE-2024-58091)
    Fix patch to make use of drm_fbdev_dma_helper_fb_probe()
  - commit 777c5a6
  - Update config files (jsc#PED-11779).
  - commit b834b27
  - serial: stm32: do not deassert RS485 RTS GPIO prematurely
    (git-fixes).
  - serial: 8250_dma: terminate correct DMA in tx_dma_flush()
    (git-fixes).
  - tty: serial: fsl_lpuart: disable transmitter before changing
    RS485 related registers (git-fixes).
  - staging: rtl8723bs: select CONFIG_CRYPTO_LIB_AES (git-fixes).
  - counter: microchip-tcb-capture: Fix undefined counter channel
    state on probe (git-fixes).
  - counter: stm32-lptimer-cnt: fix error handling when enabling
    (git-fixes).
  - ACPI: x86: Extend Lenovo Yoga Tab 3 quirk with skip GPIO
    event-handlers (git-fixes).
  - objtool: Fix verbose disassembly if CROSS_COMPILE isn't set
    (git-fixes).
  - objtool: Fix segfault in ignore_unreachable_insn() (git-fixes).
  - objtool, media: dib8000: Prevent divide-by-zero in
    dib8000_set_dds() (git-fixes).
  - objtool, spi: amd: Fix out-of-bounds stack access in
    amd_set_spi_freq() (git-fixes).
  - serial: stm32: do not deassert RS485 RTS GPIO prematurely
    (git-fixes).
  - serial: 8250_dma: terminate correct DMA in tx_dma_flush()
    (git-fixes).
  - tty: serial: fsl_lpuart: disable transmitter before changing
    RS485 related registers (git-fixes).
  - staging: rtl8723bs: select CONFIG_CRYPTO_LIB_AES (git-fixes).
  - counter: microchip-tcb-capture: Fix undefined counter channel
    state on probe (git-fixes).
  - counter: stm32-lptimer-cnt: fix error handling when enabling
    (git-fixes).
  - ACPI: x86: Extend Lenovo Yoga Tab 3 quirk with skip GPIO
    event-handlers (git-fixes).
  - objtool: Fix verbose disassembly if CROSS_COMPILE isn't set
    (git-fixes).
  - objtool: Fix segfault in ignore_unreachable_insn() (git-fixes).
  - objtool, media: dib8000: Prevent divide-by-zero in
    dib8000_set_dds() (git-fixes).
  - objtool, spi: amd: Fix out-of-bounds stack access in
    amd_set_spi_freq() (git-fixes).
  - commit 72b8c37
  - Move upstreamed ACPI patch into sorted section
  - commit 8422d4a
  - usb: xhci: correct debug message page size calculation
    (git-fixes).
  - commit 762b059
  - usb: xhci: Don't skip on Stopped - Length Invalid (git-fixes).
  - commit fa33a12
  - ucsi_ccg: Don't show failed to get FW build information error
    (git-fixes).
  - commit b624e76
  - usb: typec: thunderbolt: Remove IS_ERR check for plug
    (git-fixes).
  - commit 8424de6
  - usb: typec: thunderbolt: Fix loops that iterate TYPEC_PLUG_SOP_P
    and TYPEC_PLUG_SOP_PP (git-fixes).
  - commit 3a55100
  - btrfs: fix mount failure due to remount races (bsc#1240564).
  - commit 2f2a4ad
  - config: drop CONFIG_INITRAMFS_PRESERVE_MTIME (bsc#1240389)
  - commit afb8ef9
  - net: better track kernel sockets lifetime (CVE-2025-21884
    bsc#1240171).
  - net: Add net_passive_inc() and net_passive_dec() (CVE-2025-21884
    bsc#1240171).
  - commit 0a2a220

++++ kernel-rt:

  - nfsd: allow SC_STATUS_FREEABLE when searching via
    nfs4_lookup_stateid() (git-fixes).
  - commit f2e6ba2
  - svcrdma: do not unregister device for listeners (git-fixes).
  - commit 0694dd5
  - NFSD: Never return NFS4ERR_FILE_OPEN when removing a directory
    (git-fixes).
  - commit 1db7344
  - NFSD: nfsd_unlink() clobbers non-zero status returned from
    fh_fill_pre_attrs() (git-fixes).
  - commit d6e06f3
  - NFSD: Skip sending CB_RECALL_ANY when the backchannel isn't up
    (git-fixes).
  - commit 1f12db0
  - nfsd: fix management of listener transports (git-fixes).
  - commit 57c3828
  - exfat: fix potential wrong error return from get_block
    (git-fixes).
  - commit f7ac77d
  - exfat: fix missing shutdown check (git-fixes).
  - commit bddb6cb
  - exfat: fix the infinite loop in exfat_find_last_cluster()
    (git-fixes).
  - commit 132ac47
  - exfat: fix random stack corruption after get_block (git-fixes).
  - commit 00c87f9
  - rpm/check-for-config-changes: ignore DRM_MSM_VALIDATE_XML
    This option is dynamically enabled to build-test different configurations.
    This makes run_oldconfig.sh complain sporadically for arm64.
  - commit 8fbe8b1
  - drm/fbdev-dma: Add shadow buffering for deferred I/O (bsc#1240174 CVE-2024-58091)
    Fix patch to make use of drm_fbdev_dma_helper_fb_probe()
  - commit 777c5a6
  - Update config files (jsc#PED-11779).
  - commit b834b27
  - serial: stm32: do not deassert RS485 RTS GPIO prematurely
    (git-fixes).
  - serial: 8250_dma: terminate correct DMA in tx_dma_flush()
    (git-fixes).
  - tty: serial: fsl_lpuart: disable transmitter before changing
    RS485 related registers (git-fixes).
  - staging: rtl8723bs: select CONFIG_CRYPTO_LIB_AES (git-fixes).
  - counter: microchip-tcb-capture: Fix undefined counter channel
    state on probe (git-fixes).
  - counter: stm32-lptimer-cnt: fix error handling when enabling
    (git-fixes).
  - ACPI: x86: Extend Lenovo Yoga Tab 3 quirk with skip GPIO
    event-handlers (git-fixes).
  - objtool: Fix verbose disassembly if CROSS_COMPILE isn't set
    (git-fixes).
  - objtool: Fix segfault in ignore_unreachable_insn() (git-fixes).
  - objtool, media: dib8000: Prevent divide-by-zero in
    dib8000_set_dds() (git-fixes).
  - objtool, spi: amd: Fix out-of-bounds stack access in
    amd_set_spi_freq() (git-fixes).
  - serial: stm32: do not deassert RS485 RTS GPIO prematurely
    (git-fixes).
  - serial: 8250_dma: terminate correct DMA in tx_dma_flush()
    (git-fixes).
  - tty: serial: fsl_lpuart: disable transmitter before changing
    RS485 related registers (git-fixes).
  - staging: rtl8723bs: select CONFIG_CRYPTO_LIB_AES (git-fixes).
  - counter: microchip-tcb-capture: Fix undefined counter channel
    state on probe (git-fixes).
  - counter: stm32-lptimer-cnt: fix error handling when enabling
    (git-fixes).
  - ACPI: x86: Extend Lenovo Yoga Tab 3 quirk with skip GPIO
    event-handlers (git-fixes).
  - objtool: Fix verbose disassembly if CROSS_COMPILE isn't set
    (git-fixes).
  - objtool: Fix segfault in ignore_unreachable_insn() (git-fixes).
  - objtool, media: dib8000: Prevent divide-by-zero in
    dib8000_set_dds() (git-fixes).
  - objtool, spi: amd: Fix out-of-bounds stack access in
    amd_set_spi_freq() (git-fixes).
  - commit 72b8c37
  - Move upstreamed ACPI patch into sorted section
  - commit 8422d4a
  - usb: xhci: correct debug message page size calculation
    (git-fixes).
  - commit 762b059
  - usb: xhci: Don't skip on Stopped - Length Invalid (git-fixes).
  - commit fa33a12
  - ucsi_ccg: Don't show failed to get FW build information error
    (git-fixes).
  - commit b624e76
  - usb: typec: thunderbolt: Remove IS_ERR check for plug
    (git-fixes).
  - commit 8424de6
  - usb: typec: thunderbolt: Fix loops that iterate TYPEC_PLUG_SOP_P
    and TYPEC_PLUG_SOP_PP (git-fixes).
  - commit 3a55100
  - btrfs: fix mount failure due to remount races (bsc#1240564).
  - commit 2f2a4ad
  - config: drop CONFIG_INITRAMFS_PRESERVE_MTIME (bsc#1240389)
  - commit afb8ef9
  - net: better track kernel sockets lifetime (CVE-2025-21884
    bsc#1240171).
  - net: Add net_passive_inc() and net_passive_dec() (CVE-2025-21884
    bsc#1240171).
  - commit 0a2a220

++++ rdma-core:

  - Update to rdma-core v56.1 (jsc#PED-11289, jsc#PED-11323)
  - Bug fixes for all providers

++++ libguestfs:

  - Update to version 1.55.8 (jsc#PED-8910)
    * Various build improvements
    * Updated translations for several languages
    * lib/launch-libvirt.c: Remove fallback <emulator> for Arm

++++ xz:

  - Update to 5.8.1:
    * Multithreaded .xz decoder (lzma_stream_decoder_mt()):
  - Fix a bug that could at least result in a crash with
    invalid input. (bsc#1240414, CVE-2025-31115)
  - Fix a performance bug: Only one thread was used if the whole
    input file was provided at once to lzma_code(), the output
    buffer was big enough, timeout was disabled, and LZMA_FINISH
    was used. There are no bug reports about this, thus it's
    possible that no real-world application was affected.
    * Avoid <stdalign.h> even with C11/C17 compilers. This fixes the
    build with Oracle Developer Studio 12.6 on Solaris 10 when the
    compiler is in C11 mode (the header doesn't exist).
    * Autotools: Restore compatibility with GNU make versions older
    than 4.0 by creating the package using GNU gettext 0.23.1
    infrastructure instead of 0.24.
    * Update Croatian translation.
  - 5.8.0 changelog:
    * liblzma on 32/64-bit x86: When possible, use SSE2 intrinsics
    instead of memcpy() in the LZMA/LZMA2 decoder. In typical cases,
    this may reduce decompression time by 0-5 %. However, when built
    against musl libc, over 15 % time reduction was observed with
    highly compressed files.
    * CMake: Make the feature test macros match the Autotools-based
    build on NetBSD, Darwin, and mingw-w64.
    * Update the Croatian, Italian, Portuguese, and Romanian
    translations.
    * Update the German, Italian, Korean, Romanian, Serbian, and
    Ukrainian man page translations.
  - Summary of changes in the 5.7.x development releases:
    * Mark the following LZMA Utils script aliases as deprecated:
    lzcmp, lzdiff, lzless, lzmore, lzgrep, lzegrep, and lzfgrep.
    * liblzma:
  - Improve LZMA/LZMA2 encoder speed on 64-bit PowerPC (both
    endiannesses) and those 64-bit RISC-V processors that
    support fast unaligned access.
  - Add low-level APIs for RISC-V, ARM64, and x86 BCJ filters
    to lzma/bcj.h. These are primarily for erofs-utils.
  - x86/x86-64/E2K CLMUL CRC code was rewritten.
  - Use the CRC32 instructions on LoongArch.
    * xz:
  - Synchronize the output file and its directory using fsync()
    before deleting the input file. No syncing is done when xz
    isn't going to delete the input file.
  - Add --no-sync to disable the sync-before-delete behavior.
  - Make --single-stream imply --keep.
    * xz, xzdec, lzmainfo: When printing messages, replace
    non-printable characters with question marks.
    * xz and xzdec on Linux: Support Landlock ABI versions 5 and 6.
    * CMake: Revise the configuration variables and some of their
    options, and document them in the file INSTALL. CMake support
    is no longer experimental. (It was already not experimental
    when building for native Windows.)
    * Add build-aux/license-check.sh.

++++ ncurses:

  - Do not provides ncurses for *new* C++ library subpackages

++++ libsolv:

  - build both static and dynamic libraries on new suse distros
  - support the apk package and repository format (both v2 and v3)
  - new dataiterator_final_{repo,solvable} functions
  - bump version to 0.7.32

++++ libzypp:

  - Drop workaround for broken rpm-4.18 in Code16 (bsc#1237172)
  - BuildRequires:  %{libsolv_devel_package} >= 0.7.32.
    Code16 moved static libs to libsolv-devel-static.
  - Drop usage of SHA1 hash algorithm because it will become
    unavailable in FIPS mode (bsc#1240529)
  - Fix zypp.conf dupAllowVendorChange to reflect the correct
    default (false).
    The default was true in Code12 (libzypp-16.x) and changed to
    false with Code15 (libzypp-17.x). Unfortunately this was done by
    shipping a modified zypp.conf file rather than fixing the code.
  - zypp.conf: Add `lock_timeout` ($ZYPP_LOCK_TIMEOUT) (bsc#1239809)
  - version 17.36.6 (35)

++++ python-PyJWT:

  - Just use a wildcard for the dist-info metadata to make it
    properly work on all setuptools versions.

++++ ovmf:

  - Using old ovmf-Revert-Add-Stack-Cookie-Support-to-MSVC-and-GCC.patch
    to replace ovmf-Remove-unsupported-GCC-flag-mstack-protector-guard.patch
    because the new patch causes that smm ovmf can not boot success.
    (bsc#1240300)
  - guest OS: openSUSE Tumbleweed, Windows 11
  - Added ovmf-UefiCpuPkg-Disable-EFI-memory-attributes-protocol.patch
    to disable EFI memory attributes protocol at this moment. It causes
    old shim 15.8 boot fail on SLE12-SP5. (bsc#1240771)

------------------------------------------------------------------
------------------  2025-4-2  -  Apr 2 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Update to version 2.31
    * Handel BS on password prompt as well
    * Drop spining code as systemd uses clear to end of line
    escape sequence (hard coded!) for its cylon lines.
  - blog: again suggest blog-plymouth

++++ cifs-utils:

  - Update cifs-utils to 7.3
    * Fix regression in mount.cifs with guest mount option
    * resolve_host.c: Initialize site_name
    * cldap_ping: Fix socket fd leak
    * getcifsacl: fix return code check for getting full ACL
    * cifs-utils: add documentation for upcall_target
    * cifs-utils: avoid using mktemp when updating mtab
    * cldap_ping.c: add missing <sys/types.h> include
    * configure.ac: libtalloc is now mandatory
    * cifscreds: allow user to set the key's timeout
    * cifscreds: use continue instead of break when matching commands
    * Do not pass passwords with sec=none and sec=krb5
    * docs: add esize description
    * docs: add max_cached_dirs description
    * docs: update actimeo description
    * Fix compiler warnings in mount.cifs
    * CIFS.upcall to accomodate new namespace mount opt
    * cifs-utils: Skip TGT check if valid service ticket is already available
    * use enums to check password or password2 in set_password, get_password_from_file and minor documentation additions
    * cifs-utils: support and document password2 mount option
    * smbinfo: add bash completion support for filestreaminfo, keys, gettconinfo

++++ python-kiwi:

  - package: Add kiwi-image:oci Provides to -systemdeps-containers
    This allows the Open Build Service to correctly resolve dependencies
    when building OCI images.
  - Better logging which kiwi file is read
    Improve the log message that tells about reading the
    kiwi config file to actually show the file path that
    is read in. This is especially an issue if more than
    one kiwi file is read in during the build process.
  - also keep the ts binary, might be needed to provide timestamped logfiles

++++ kernel-default:

  - smb: During unmount, ensure all cached dir instances drop
    their dentry (bsc#1234894, CVE-2024-53176).
  - commit 1197dc4
  - smb: prevent use-after-free due to open_cached_dir error paths
    (bsc#1234896, CVE-2024-53177).
  - commit 418a7db
  - smb: Don't leak cfid when reconnect races with open_cached_dir
    (bsc#1234895, CVE-2024-53178).
  - commit 1515dee
  - net: usb: usbnet: restore usb%d name exception for local mac
    addresses (bsc#1234480).
  - commit d54d858
  - PCI: Allow relaxed bridge window tail sizing for optional
    resources (git-fixes).
  - PCI: Simplify size1 assignment logic (git-fixes).
  - PCI: mediatek-gen3: Rely on msleep() in
    mtk_pcie_en7581_power_up() (git-fixes).
  - Refresh
    patches.suse/PCI-mediatek-gen3-Configure-PBUS_CSR-registers-for-E.patch.
  - commit ae9c470
  - EDAC/ie31200: Switch Raptor Lake-S to interrupt mode (jsc#PED-10928).
  - commit c9941a8
  - EDAC/ie31200: Add Intel Raptor Lake-S SoCs support (jsc#PED-10928).
  - commit f51c2b8
  - EDAC/ie31200: Break up ie31200_probe1() (jsc#PED-10928).
  - commit 62ea605
  - EDAC/ie31200: Fold the two channel loops into one loop (jsc#PED-10928).
  - commit 6e2b5ee
  - EDAC/ie31200: Make struct dimm_data contain decoded information (jsc#PED-10928).
  - commit 325dfcf
  - EDAC/ie31200: Make the memory controller resources configurable (jsc#PED-7619).
  - commit eae70e1
  - EDAC/ie31200: work around false positive build warning (jsc#PED-7619).
  - commit 7dc9d30
  - EDAC/ie31200: Simplify the pci_device_id table (jsc#PED-10928).
  - commit 48616aa
  - EDAC/ie31200: Fix the 3rd parameter name of *populate_dimm_info() (jsc#PED-10928).
  - commit 5eb75d7
  - EDAC/ie31200: Fix the error path order of ie31200_init() (jsc#PED-10928).
  - commit b6e74b6
  - EDAC/ie31200: Fix the DIMM size mask for several SoCs (jsc#PED-10928).
  - commit 362d87f
  - EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer (jsc#PED-10928).
  - commit 081264d
  - Delete patches.suse/RAS-AMD-FMPM-Fix-build-when-debugfs-is-not-enabled.patch.
    It's not needed as the kernel includes the upstream fix from
    a6b227d70d2a ("RAS: Avoid build errors when CONFIG_DEBUG_FS=n")
  - commit 5f22656
  - selftests: mptcp: close fd_in before returning in main_loop
    (git-fixes).
  - selftests: mptcp: fix incorrect fd checks in main_loop
    (git-fixes).
  - net: phy: broadcom: Correct BCM5221 PHY model detection
    (git-fixes).
  - rndis_host: Flag RNDIS modems as WWAN devices (git-fixes).
  - thermal/drivers/mediatek/lvts: Disable Stage 3 thermal threshold
    (git-fixes).
  - thermal/drivers/mediatek/lvts: Disable monitor mode during
    suspend (git-fixes).
  - thermal: core: Remove duplicate struct declaration (git-fixes).
  - thermal/drivers/rockchip: Add missing rk3328 mapping entry
    (git-fixes).
  - i3c: Add NULL pointer check in i3c_master_queue_ibi()
    (git-fixes).
  - i3c: master: svc: Use readsb helper for reading MDB (git-fixes).
  - i3c: master: svc: Fix missing the IBI rules (git-fixes).
  - dmaengine: fsl-edma: free irq correctly in remove path
    (git-fixes).
  - dmaengine: fsl-edma: cleanup chan after
    dma_async_device_unregister (git-fixes).
  - phy: freescale: imx8m-pcie: assert phy reset and perst in
    power off (git-fixes).
  - phy: phy-rockchip-samsung-hdptx: Don't use dt aliases to
    determine phy-id (git-fixes).
  - soundwire: slave: fix an OF node reference leak in soundwire
    slave device (git-fixes).
  - w1: fix NULL pointer dereference in probe (git-fixes).
  - bus: mhi: host: Fix race between unprepare and queue_buf
    (git-fixes).
  - iio: light: Add check for array bounds in
    veml6075_read_int_time_ms (git-fixes).
  - iio: adc: ad7768-1: set MOSI idle state to prevent accidental
    reset (git-fixes).
  - iio: adc: ad7173: Fix comparison of channel configs (git-fixes).
  - iio: adc: ad7124: Fix comparison of channel configs (git-fixes).
  - iio: adc: ad4130: Fix comparison of channel setups (git-fixes).
  - iio: backend: make sure to NULL terminate stack buffer
    (git-fixes).
  - iio: accel: msa311: Fix failure to release runtime pm if direct
    mode claim fails (git-fixes).
  - iio: accel: mma8452: Ensure error return on failure to matching
    oversampling ratio (git-fixes).
  - driver core: Remove needless return in void API
    device_remove_group() (git-fixes).
  - docs: thermal: sync hardware protection doc with code
    (git-fixes).
  - selftests/mm/cow: fix the incorrect error handling (git-fixes).
  - maple_tree: remove a BUG_ON() in mas_alloc_nodes() (git-fixes).
  - selftests/mm: fix thuge-gen test name uniqueness (git-fixes).
  - commit e915f3b
  - disable erdma driver (jsc#PED-12235)
  - commit b893010
  - mark SIW and RXE as not supported (jsc#PED-12026)
  - commit 7ca3899

++++ kernel-firmware-bluetooth:

  - Update to version 20250401 (git commit d864697fd38a):
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x17E9_16ED
    * Revert "rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x0471_70A6"

++++ kernel-rt:

  - smb: During unmount, ensure all cached dir instances drop
    their dentry (bsc#1234894, CVE-2024-53176).
  - commit 1197dc4
  - smb: prevent use-after-free due to open_cached_dir error paths
    (bsc#1234896, CVE-2024-53177).
  - commit 418a7db
  - smb: Don't leak cfid when reconnect races with open_cached_dir
    (bsc#1234895, CVE-2024-53178).
  - commit 1515dee
  - net: usb: usbnet: restore usb%d name exception for local mac
    addresses (bsc#1234480).
  - commit d54d858
  - PCI: Allow relaxed bridge window tail sizing for optional
    resources (git-fixes).
  - PCI: Simplify size1 assignment logic (git-fixes).
  - PCI: mediatek-gen3: Rely on msleep() in
    mtk_pcie_en7581_power_up() (git-fixes).
  - Refresh
    patches.suse/PCI-mediatek-gen3-Configure-PBUS_CSR-registers-for-E.patch.
  - commit ae9c470
  - EDAC/ie31200: Switch Raptor Lake-S to interrupt mode (jsc#PED-10928).
  - commit c9941a8
  - EDAC/ie31200: Add Intel Raptor Lake-S SoCs support (jsc#PED-10928).
  - commit f51c2b8
  - EDAC/ie31200: Break up ie31200_probe1() (jsc#PED-10928).
  - commit 62ea605
  - EDAC/ie31200: Fold the two channel loops into one loop (jsc#PED-10928).
  - commit 6e2b5ee
  - EDAC/ie31200: Make struct dimm_data contain decoded information (jsc#PED-10928).
  - commit 325dfcf
  - EDAC/ie31200: Make the memory controller resources configurable (jsc#PED-7619).
  - commit eae70e1
  - EDAC/ie31200: work around false positive build warning (jsc#PED-7619).
  - commit 7dc9d30
  - EDAC/ie31200: Simplify the pci_device_id table (jsc#PED-10928).
  - commit 48616aa
  - EDAC/ie31200: Fix the 3rd parameter name of *populate_dimm_info() (jsc#PED-10928).
  - commit 5eb75d7
  - EDAC/ie31200: Fix the error path order of ie31200_init() (jsc#PED-10928).
  - commit b6e74b6
  - EDAC/ie31200: Fix the DIMM size mask for several SoCs (jsc#PED-10928).
  - commit 362d87f
  - EDAC/ie31200: Fix the size of EDAC_MC_LAYER_CHIP_SELECT layer (jsc#PED-10928).
  - commit 081264d
  - Delete patches.suse/RAS-AMD-FMPM-Fix-build-when-debugfs-is-not-enabled.patch.
    It's not needed as the kernel includes the upstream fix from
    a6b227d70d2a ("RAS: Avoid build errors when CONFIG_DEBUG_FS=n")
  - commit 5f22656
  - selftests: mptcp: close fd_in before returning in main_loop
    (git-fixes).
  - selftests: mptcp: fix incorrect fd checks in main_loop
    (git-fixes).
  - net: phy: broadcom: Correct BCM5221 PHY model detection
    (git-fixes).
  - rndis_host: Flag RNDIS modems as WWAN devices (git-fixes).
  - thermal/drivers/mediatek/lvts: Disable Stage 3 thermal threshold
    (git-fixes).
  - thermal/drivers/mediatek/lvts: Disable monitor mode during
    suspend (git-fixes).
  - thermal: core: Remove duplicate struct declaration (git-fixes).
  - thermal/drivers/rockchip: Add missing rk3328 mapping entry
    (git-fixes).
  - i3c: Add NULL pointer check in i3c_master_queue_ibi()
    (git-fixes).
  - i3c: master: svc: Use readsb helper for reading MDB (git-fixes).
  - i3c: master: svc: Fix missing the IBI rules (git-fixes).
  - dmaengine: fsl-edma: free irq correctly in remove path
    (git-fixes).
  - dmaengine: fsl-edma: cleanup chan after
    dma_async_device_unregister (git-fixes).
  - phy: freescale: imx8m-pcie: assert phy reset and perst in
    power off (git-fixes).
  - phy: phy-rockchip-samsung-hdptx: Don't use dt aliases to
    determine phy-id (git-fixes).
  - soundwire: slave: fix an OF node reference leak in soundwire
    slave device (git-fixes).
  - w1: fix NULL pointer dereference in probe (git-fixes).
  - bus: mhi: host: Fix race between unprepare and queue_buf
    (git-fixes).
  - iio: light: Add check for array bounds in
    veml6075_read_int_time_ms (git-fixes).
  - iio: adc: ad7768-1: set MOSI idle state to prevent accidental
    reset (git-fixes).
  - iio: adc: ad7173: Fix comparison of channel configs (git-fixes).
  - iio: adc: ad7124: Fix comparison of channel configs (git-fixes).
  - iio: adc: ad4130: Fix comparison of channel setups (git-fixes).
  - iio: backend: make sure to NULL terminate stack buffer
    (git-fixes).
  - iio: accel: msa311: Fix failure to release runtime pm if direct
    mode claim fails (git-fixes).
  - iio: accel: mma8452: Ensure error return on failure to matching
    oversampling ratio (git-fixes).
  - driver core: Remove needless return in void API
    device_remove_group() (git-fixes).
  - docs: thermal: sync hardware protection doc with code
    (git-fixes).
  - selftests/mm/cow: fix the incorrect error handling (git-fixes).
  - maple_tree: remove a BUG_ON() in mas_alloc_nodes() (git-fixes).
  - selftests/mm: fix thuge-gen test name uniqueness (git-fixes).
  - commit e915f3b
  - disable erdma driver (jsc#PED-12235)
  - commit b893010
  - mark SIW and RXE as not supported (jsc#PED-12026)
  - commit 7ca3899

++++ openssh:

  - Add patch to fix parsing of CFLAGS with duplicated -pie flags,
    which break 'make tests'. Submitted to upstream in
    https://bugzilla.mindrot.org/show_bug.cgi?id=3806 .
    * fix-nopie-flag.patch

++++ python-M2Crypto:

  - Allow for ambiguity in first letter of directories in
    %{python_sitearch}.

++++ qemu:

  - Update to latest stable release (9.2.3)
    Full backport list here:
    https://lore.kernel.org/qemu-devel/44124379-3349-45cf-9238-8a847d8b2770@tls.msk.ru/
    Fixes: bsc#1236329
    Highlights include:
    * hw/intc/aspeed: Fix IRQ handler mask check
    * hw/misc/aspeed_hace: Fix buffer overflow in has_padding function
    * target/riscv: fix handling of nop for vstart >= vl in some vector instruction
    * target/riscv: refactor VSTART_CHECK_EARLY_EXIT() to accept vl as a parameter
    * Makefile: "make dist" generates a .xz, not .bz2
    * target/ppc: Fix e200 duplicate SPRs
    * target/ppc: Fix facility interrupt checks for VSX
    * ppc/spapr: fix default cpu for pre-9.0 machines.
    * host/include/loongarch64: Fix inline assembly compatibility with Clang
    * linux-user/riscv: Fix handling of cpu mask in riscv_hwprobe syscall
    * target/riscv: fixes a bug against `ssamoswap` behavior in M-mode
    * target/riscv: fix access permission checks for CSR_SSP
    * docs/about/emulation: Fix broken link
    * vdpa: Allow vDPA to work on big-endian machine
    * vdpa: Fix endian bugs in shadow virtqueue
    * target/loongarch: Fix vldi inst
    * target/arm: Simplify pstate_sm check in sve_access_check
    * target/arm: Make DisasContext.{fp, sve}_access_checked tristate
    * util/cacheflush: Make first DSB unconditional on aarch64
    * docs: Rename default-configs to configs
    * block: Zero block driver state before reopening
    * hw/xen/hvm: Fix Aarch64 typo
    * hw/net/smc91c111: Don't allow data register access to overrun buffer
    * hw/net/smc91c111: Sanitize packet length on tx
    * hw/net/smc91c111: Sanitize packet numbers
    * ppc/pnv/occ: Fix common area sensor offsets
    * xen: No need to flush the mapcache for grants (bsc#1236329)
    * net: move backend cleanup to NIC cleanup
    * net: parameterize the removing client from nc list
    * util/qemu-timer.c: Don't warp timer from timerlist_rearm()
    * target/arm: Correct STRD atomicity
    * target/arm: Correct LDRD atomicity and fault behaviour
    * hw/arm: enable secure EL2 timers for sbsa machine
    * hw/arm: enable secure EL2 timers for virt machine
    * target/arm: Implement SEL2 physical and virtual timers
    * ...
  - Fix bsc#1240157:
    * [openSUSE][RPM] spec: Require ipxe and virtio-gpu packages for more arch-es

------------------------------------------------------------------
------------------  2025-4-1  -  Apr 1 2025  -------------------
------------------------------------------------------------------

++++ dpdk:

  - Change 0001-always_inline-fix.patch by replacing the function
    rte_trace_feature_is_enabled with a preprocessor substitution,
    this also work with older gcc7 where -mgeneral-regs-only isn't
    available.

++++ python-kiwi:

  - Update documentation
    Add information about new apk (Alpine) support

++++ grub2:

  - Add grub2-provide-edid.patch: Grub2 already retrieves the EDID
    from video adapters. Copy the raw data into the Linux kernel boot
    parameters, so that Linux can use this information. The necessary
    fields have been present in the boot parameters since at least
    commit f8eeaaf41803 ("[PATCH] Make the bzImage format
    self-terminating"), but never used. Within the kernel, the EDID
    data will be propagated to graphics drivers and finally to user
    space. (bsc#1240624)

++++ ignition:

  - Update to version 2.21.0:
    * Features
    * Add Azure blob support for fetching ignition configs
    * Add a check for ignition config in vendor-data (proxmoxve)
    * Bug fixes
    * Add pkey_cca kernel module to detect CEX domain for LUKS encryption
  - Add support for nested /etc subvolume (t-u 5.0.0)

++++ kernel-default:

  - uprobes: Reject the shared zeropage in uprobe_write_opcode() (CVE-2025-21881 bsc#1240185)
  - commit 7d7f5f2
  - scsi: ufs: core: bsg: Fix crash when arpmb command fails (CVE-2025-21873 bsc#1240184)
  - commit 8a3801b
  - supported.conf: Mark habanalabs drivers as supported (jsc#PED-10735)
  - commit 83e7063
  - rpm/release-projects: Update the ALP projects again (bsc#1231293).
  - commit a2f9145
  - platform/x86/intel/pmc: Add Arrow Lake U/H support to
    intel_pmc_core driver (jsc#PED-10628).
  - commit 507d3c4
  - platform/x86/intel/pmc: Remove simple init functions
    (jsc#PED-10628).
  - commit 8c62b6b
  - platform/x86:intel/pmc: Create generic_core_init() for all
    platforms (jsc#PED-10628).
  - commit ea95203
  - platform/x86/intel/pmc: Remove duplicate enum (jsc#PED-10628).
  - commit e3e65be
  - platform/x86:intel/pmc: Make tgl_core_generic_init() static
    (jsc#PED-10628).
  - commit c7ac508
  - Refresh patches.suse/kABI-padding-for-bpf.patch.
  - Refresh and renable kABI padding for BPF
  - Add padding for 'struct bpf_verifier_state'
  - commit ae782d1
  - Delete
    patches.suse/selftests-bpf-user_ringbuf-define-c_ringbuf_size.patch.
    SUSE-2025 uses GCC 13, so this workaround is no longer required.
  - commit 3707020
  - Delete
    patches.suse/selftests-bpf-lsm_cgroup-define-sockaddr_ll.patch.
    Switching to using kernel config found in tools/testing/selftests/bpf/
    instead, so this definition is no longer needed.
  - commit 6df9702
  - bpf: Add tracepoints with null-able arguments (bsc#1235501
    CVE-2024-56702).
  - commit c49f936

++++ kernel-firmware-bluetooth:

  - Update to version 20250331 (git commit 0f7fe1e739bf):
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x0471_70A6

++++ kernel-firmware-intel:

  - Update to version 20250331 (git commit 0f7fe1e739bf):
    * intel_vpu: Update NPU firmware

++++ kernel-firmware-sound:

  - Update to version 20250331 (git commit 0f7fe1e739bf):
    * cirrus: cs35l56: Correct filenames of SSID 103c8e1b and 103c8e1c

++++ kernel-rt:

  - uprobes: Reject the shared zeropage in uprobe_write_opcode() (CVE-2025-21881 bsc#1240185)
  - commit 7d7f5f2
  - scsi: ufs: core: bsg: Fix crash when arpmb command fails (CVE-2025-21873 bsc#1240184)
  - commit 8a3801b
  - supported.conf: Mark habanalabs drivers as supported (jsc#PED-10735)
  - commit 83e7063
  - rpm/release-projects: Update the ALP projects again (bsc#1231293).
  - commit a2f9145
  - platform/x86/intel/pmc: Add Arrow Lake U/H support to
    intel_pmc_core driver (jsc#PED-10628).
  - commit 507d3c4
  - platform/x86/intel/pmc: Remove simple init functions
    (jsc#PED-10628).
  - commit 8c62b6b
  - platform/x86:intel/pmc: Create generic_core_init() for all
    platforms (jsc#PED-10628).
  - commit ea95203
  - platform/x86/intel/pmc: Remove duplicate enum (jsc#PED-10628).
  - commit e3e65be
  - platform/x86:intel/pmc: Make tgl_core_generic_init() static
    (jsc#PED-10628).
  - commit c7ac508
  - Refresh patches.suse/kABI-padding-for-bpf.patch.
  - Refresh and renable kABI padding for BPF
  - Add padding for 'struct bpf_verifier_state'
  - commit ae782d1
  - Delete
    patches.suse/selftests-bpf-user_ringbuf-define-c_ringbuf_size.patch.
    SUSE-2025 uses GCC 13, so this workaround is no longer required.
  - commit 3707020
  - Delete
    patches.suse/selftests-bpf-lsm_cgroup-define-sockaddr_ll.patch.
    Switching to using kernel config found in tools/testing/selftests/bpf/
    instead, so this definition is no longer needed.
  - commit 6df9702
  - bpf: Add tracepoints with null-able arguments (bsc#1235501
    CVE-2024-56702).
  - commit c49f936

++++ libvirt:

  - Update to libvirt 11.2.0
  - jsc#PED-6556, jsc#PED-11466
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v11-2-0-2025-04-01

++++ pcr-oracle:

  - Update to 0.5.5
    + Merge of pending patches into the project
    + No new feature since last release
  - Change source to the openSUSE project
  - Remove patches (merged)
    + fix-bsc1230316-make-pcr4-hard-requirement.patch
    + fix-bsc1230316-predict-sbatlevelrt.patch
    + fix-bsc1230316-predict-sbatlevelrt-sb-off.patch
    + fix_efi_measure_and_shim.patch
    + fix-event-reshash-for-cryptouuid.patch
    + fix_grub_bls_cmdline.patch
    + fix_grub_bls_entry.patch
    + fix_loader_conf.patch
    + fix-testcase-empty-efi-variables.patch
    + support-ecc-srk.patch

++++ python-MarkupSafe:

  - Make the dist-info name case-insensitive

++++ python-PyJWT:

  - Wrap the metadata directory name in a distro-based conditional

++++ python-PyYAML:

  - Wrap the metadata directory name in a distro-based conditional

++++ python-gobject:

  - Re-add BuildRequires pkgconfig(gobject-introspection-1.0) to
    fix "cannot import name GLib, introspection typelib not found"
    error (boo#1240549)

++++ python-libvirt-python:

  - Update to 11.2.0
  - Add all new APIs and constants in libvirt 11.2.0

++++ vim:

  - add -std=gnu11 to CFLAGS to fix gcc15 compile time error, and to
    still allow build on Leap 15.6

------------------------------------------------------------------
------------------  2025-3-31  -  Mar 31 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Update to version 2.30
    * The asking variable is not shared
    * Allow password asking prompt to be repeated if empty.
    * Make spinner support UTF-8 multibyte conform.
    * Spinner lines of system still not handled.

++++ btrfsprogs:

  - update to 6.13
    * mkfs:
    * allow --sectorsize to be 2K for testing purposes of subpage mode (needs
    the same block size supported by kernel)
    * fix false error when no compression is requested and lzo is not compiled in
    * convert: support 2K block size in the source filesystem
    * defrag: new parameter -L/--level to specify compression levels (kernel 6.15),
    also supports the realtime levels
    * subvol delete: show names of recursively deleted child subvolumes
    * qgroup show: use sysfs to detect up to date consistency status
    * zoned mode: support zone capacity tracking
    * other:
    * CI new and updated workflows
    * documentation updates
  - spec: package btrfs-find-root unconditionally (bsc#1239992)
  - Refresh patches: mkfs-default-features.patch (context)

++++ ca-certificates-mozilla:

  - explit remove distruted certs, as the distrust does not get exported
    correctly and the SSL certs are still trusted. (bsc#1240343)
  - Entrust.net Premium 2048 Secure Server CA
  - Entrust Root Certification Authority
  - AffirmTrust Commercial
  - AffirmTrust Networking
  - AffirmTrust Premium
  - AffirmTrust Premium ECC
  - Entrust Root Certification Authority - G2
  - Entrust Root Certification Authority - EC1
  - GlobalSign Root E46
  - GLOBALTRUST 2020
  - remove-distrusted.patch: apply to certdata.txt

++++ container-selinux:

  - Update to version 2.236.0:
    * Allow super privileged containers to use RealtimeKit for scheduling
    * Add container_ro_file_t to the podman artifact store

++++ dpdk:

  - Add 0001-always_inline-fix.patch to fix issue with always_inline
    and rte_trace_feature_is_enabled which should use -mgeneral-regs-only
    to inter-operate with other ISA flags.  Remove GCC 14 build requirement
    for SLE15/16 again.

++++ python-kiwi:

  - Add support for Alpine
    Add apk repository and package manager support and provide
    an integration test build for the Alpine distribution
  - Fix F824 flake check for global assignments
  - Use metalink repos for local test builds

++++ gtk3:

  - Update to version 3.24.49+14:
    + widget: Explicitly annotate visible's getter.

++++ kernel-default:

  - ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up (CVE-2025-21887 bsc#1240176)
  - commit aefb37c
  - mptcp: always handle address removal under msk socket lock (CVE-2025-21875 bsc#1240168)
  - commit 30269f0
  - perf/core: Add RCU read lock protection to perf_iterate_ctx() (CVE-2025-21889 bsc#1240167)
  - commit 68c5afe
  - Update references for patches.suse/nvkm-correctly-calculate-the-available-space-of-the-.patch (CVE-2024-58018 bsc#1238990 stable-fixes)
  - commit 5d4613b
  - team: prevent adding a device which is already a team device lower (CVE-2024-58071 bsc#1238970)
  - commit e1c6462
  - nvme-tcp: Fix a C2HTermReq error message (git-fixes).
  - commit 1aeab84
  - nvmet-fc: Remove unused functions (git-fixes).
  - nvme-pci: remove stale comment (git-fixes).
  - nvme: move error logging from nvme_end_req() to __nvme_end_req()
    (git-fixes).
  - nvme-tcp: fix signedness bug in nvme_tcp_init_connection()
    (git-fixes).
  - nvmet-tcp: Fix a possible sporadic response drops in weakly
    ordered arch (git-fixes).
  - nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
    (git-fixes).
  - nvmet: remove old function prototype (git-fixes).
  - nvme-ioctl: fix leaked requests on mapping error (git-fixes).
  - nvme: only allow entering LIVE from CONNECTING state (git-fixes
    bsc#1222649).
  - nvme-fc: rely on state transitions to handle connectivity loss
    (git-fixes bsc#1222649).
  - nvmet-rdma: recheck queue state is LIVE in state lock in recv
    done (git-fixes).
  - nvme-tcp: add basic support for the C2HTermReq PDU (git-fixes).
  - nvme-pci: quirk Acer FA100 for non-uniqueue identifiers
    (git-fixes).
  - nvme-fc: do not ignore connectivity loss during connecting
    (git-fixes bsc#1222649).
  - nvme-fc: go straight to connecting state when initializing
    (git-fixes bsc#1222649).
  - nvme-pci: use sgls for all user requests if possible
    (git-fixes).
  - nvme-pci: add support for sgl metadata (git-fixes).
  - commit af2f0ab
  - series: update metadata
  - Refresh
    patches.suse/ARM-module-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/Documentation-powerpc-fadump-add-additional-paramete.patch.
  - Refresh
    patches.suse/arm-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/arm64-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/arm64-module-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/bpf-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/bug-Use-RCU-instead-RCU-sched-to-protect-module_bug_list.patch.
  - Refresh
    patches.suse/cfi-Use-RCU-while-invoking-__module_address.patch.
  - Refresh
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_address.patch.
  - Refresh
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/kprobes-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh patches.suse/lib-dump_stack-Use-preempt_model_str.patch.
  - Refresh
    patches.suse/module-Allow-__module_address-to-be-called-from-RCU-section.patch.
  - Refresh
    patches.suse/module-Begin-to-move-from-RCU-sched-to-RCU.patch.
  - Refresh
    patches.suse/module-Remove-module_assert_mutex_or_preempt-from-try_add_tainted_module.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-__find_kallsyms_symbol_value.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-__is_module_percpu_address.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-all-users-of-__module_address.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-find_kallsyms_symbol.patch.
  - Refresh patches.suse/module-Use-RCU-in-find_module_all.patch.
  - Refresh patches.suse/module-Use-RCU-in-find_symbol.patch.
  - Refresh patches.suse/module-Use-RCU-in-module_get_kallsym.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-module_kallsyms_on_each_symbol.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-search_module_extables.patch.
  - Refresh
    patches.suse/module-Use-proper-RCU-assignment-in-add_kallsyms.patch.
  - Refresh
    patches.suse/powerpc-Document-details-on-H_HTM-hcall.patch.
  - Refresh
    patches.suse/powerpc-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh patches.suse/powerpc-export-MIN-RMA-size.patch.
  - Refresh
    patches.suse/powerpc-fadump-fix-additional-param-memory-reservati.patch.
  - Refresh
    patches.suse/powerpc-increase-MIN-RMA-size-for-CAS-negotiation.patch.
  - Refresh
    patches.suse/powerpc-pseries-Export-hardware-trace-macro-dump-via.patch.
  - Refresh
    patches.suse/powerpc-pseries-Macros-and-wrapper-functions-for-H_H.patch.
  - Refresh
    patches.suse/powerpc-pseries-iommu-memory-notifier-incorrectly-ad.patch.
  - Refresh
    patches.suse/s390-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/sched-Add-a-generic-function-to-return-the-preemption-string.patch.
  - Refresh
    patches.suse/sched-Add-unlikey-branch-hints-to-several-system-calls.patch.
  - Refresh
    patches.suse/sched-Cancel-the-slice-protection-of-the-idle-entity.patch.
  - Refresh
    patches.suse/sched-Don-t-define-sched_clock_irqtime-as-static-key.patch.
  - Refresh
    patches.suse/sched-Reduce-the-default-slice-to-avoid-tasks-getting-an-extra-tick.patch.
  - Refresh
    patches.suse/sched-core-Remove-duplicate-included-header-file-stats.h.patch.
  - Refresh
    patches.suse/sched-eevdf-Force-propagating-min_slice-of-cfs_rq-when-en-de-queue-tasks.patch.
  - Refresh
    patches.suse/sched-fair-Refactor-can_migrate_task-to-elimate-looping.patch.
  - Refresh
    patches.suse/sched-membarrier-Fix-redundant-load-of-membarrier_st.patch.
  - Refresh
    patches.suse/static_call-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh patches.suse/tracing-Use-preempt_model_str.patch.
  - Refresh
    patches.suse/x86-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/x86-Use-RCU-in-all-users-of-__module_address.patch.
  - Refresh
    patches.suse/x86-tsc-Always-save-restore-TSC-sched_clock-on-suspend-resume.patch.
  - Refresh
    patches.suse/xtensa-Rely-on-generic-printing-of-preemption-model.patch.
  - commit 50abd21
  - arm64: cputype: Add MIDR_CORTEX_A76AE (git-fixes)
  - commit 12c538d
  - drm/fbdev-dma: Add shadow buffering for deferred I/O (bsc#1240174 CVE-2024-58091)
  - commit 81b755a
  - arm64: dts: rockchip: Fix PWM pinctrl names (git-fixes)
  - commit e826378
  - arm64: dts: rockchip: Remove bluetooth node from rock-3a (git-fixes)
  - commit 1354fe4
  - arm64: dts: imx8mp: change AUDIO_AXI_CLK_ROOT freq. to 800MHz (git-fixes)
  - commit 9607ffc
  - arm64: dts: imx8mp: add AUDIO_AXI_CLK_ROOT to AUDIOMIX block (git-fixes)
  - commit 79b8eb1
  - arm64: dts: imx8mp-skov: operate CPU at 850 mV by default (git-fixes)
  - commit 54699e8
  - arm64: dts: imx8mp-skov: correct PMIC board limits (git-fixes)
  - commit 864f35b
  - arm64: dts: exynos: gs101: disable pinctrl_gsacore node (git-fixes)
  - commit ea03073
  - arm64: tegra: Remove the Orin NX/Nano suspend key (git-fixes)
  - commit 5f41ffa
  - arm64/boot: Enable EL2 requirements for FEAT_PMUv3p9 (git-fixes)
  - commit b053f6d
  - arm64: errata: Add newer ARM cores to the spectre_bhb_loop_affected() (git-fixes)
  - commit 581e653
  - arm64: errata: Add KRYO 2XX/3XX/4XX silver cores to Spectre BHB safe (git-fixes)
  - commit 4a0576a
  - arm64: errata: Assume that unknown CPUs _are_ vulnerable to Spectre (git-fixes)
  - commit a914636
  - arm64: errata: Add QCOM_KRYO_4XX_GOLD to the spectre_bhb_k24_list (git-fixes)
  - commit 318ba4c
  - bitmap: Align documentation between bitmap_gather() and
    bitmap_scatter() (git-fixes).
  - commit 5ae3c5e
  - ipvlan: ensure network headers are in skb linear part
    (CVE-2025-21891 bsc#1240186).
  - commit be4e602
  - Update config files: Enable CONFIG_FRAMEBUFFER_CONSOLE_DEFERRED_TAKEOVER (bsc#1237220)
  - commit c79d4b3
  - Update
    patches.suse/ASoC-SOF-ipc4-topology-Harden-loops-for-looking-up-A.patch
    (git-fixes CVE-2025-21870 bsc#1240191).
  - Update
    patches.suse/RDMA-bnxt_re-Fix-the-page-details-for-the-srq-create.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21885 bsc#1240169).
  - Update
    patches.suse/RDMA-mlx5-Fix-a-WARN-during-dereg_mr-for-DM-type.patch
    (git-fixes CVE-2025-21888 bsc#1240177).
  - Update
    patches.suse/RDMA-mlx5-Fix-implicit-ODP-hang-on-parent-deregistra.patch
    (git-fixes CVE-2025-21886 bsc#1240188).
  - Update
    patches.suse/RDMA-mlx5-Fix-the-recovery-flow-of-the-UMR-QP.patch
    (git-fixes CVE-2025-21892 bsc#1240175).
  - Update
    patches.suse/ata-libata-sff-Ensure-that-we-cannot-write-outside-t.patch
    (git-fixes CVE-2025-21738 bsc#1238917).
  - Update
    patches.suse/cpufreq-amd-pstate-Fix-cpufreq_policy-ref-counting.patch
    (git-fixes CVE-2025-21841 bsc#1239062).
  - Update
    patches.suse/dm-integrity-Avoid-divide-by-zero-in-table-status-in.patch
    (git-fixes CVE-2025-21874 bsc#1240190).
  - Update patches.suse/drm-xe-userptr-fix-EFAULT-handling.patch
    (git-fixes CVE-2025-21880 bsc#1240170).
  - Update
    patches.suse/i2c-npcm-disable-interrupt-enable-bit-before-devm_re.patch
    (git-fixes CVE-2025-21878 bsc#1240192).
  - Update
    patches.suse/ice-Fix-deinitializing-VF-in-error-path.patch
    (jsc#PED-10419 CVE-2025-21883 bsc#1240189).
  - Update patches.suse/idpf-fix-checksums-set-in-idpf_rx_rsc.patch
    (jsc#PED-10581 CVE-2025-21890 bsc#1240173).
  - Update patches.suse/iommu-vt-d-Fix-suspicious-RCU-usage.patch
    (git-fixes CVE-2025-21876 bsc#1240179).
  - Update
    patches.suse/net-mlx5-Fix-vport-QoS-cleanup-on-error.patch
    (jsc#PED-11331 CVE-2025-21882 bsc#1240187).
  - Update
    patches.suse/powerpc-code-patching-Disable-KASAN-report-during-pa.patch
    (bsc#1215199 CVE-2025-21869 bsc#1240182).
  - Update
    patches.suse/usbnet-gl620a-fix-endpoint-checking-in-genelink_bind.patch
    (git-fixes CVE-2025-21877 bsc#1240172).
  - commit 608a30b
  - Update
    patches.suse/media-vidtv-Fix-a-null-ptr-deref-in-vidtv_mux_stop_t.patch
    (git-fixes CVE-2024-57834 bsc#1238993).
  - Update
    patches.suse/nvkm-correctly-calculate-the-available-space-of-the-.patch
    (stable-fixes CVE-2024-58018 bsc#1238990).
  - commit 60408e9
  - IB/mad: Check available slots before posting receive WRs (git-fixes)
  - commit 89aff72
  - RDMA/mlx5: Fix calculation of total invalidated pages (git-fixes)
  - commit d8fa607
  - RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow (git-fixes)
  - commit 7a3d709
  - RDMA/mlx5: Fix page_size variable overflow (git-fixes)
  - commit d686296
  - RDMA/mlx5: Fix cache entry update on dereg error (git-fixes)
  - commit 5b61d30
  - RDMA/mlx5: Fix MR cache initialization error flow (git-fixes)
  - commit 977d207
  - RDMA/core: Fix use-after-free when rename device name (git-fixes)
  - commit e693f34
  - RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() (git-fixes)
  - commit a2f7db1
  - RDMA/core: Don't expose hw_counters outside of init net namespace (git-fixes)
  - commit ac060af

++++ kernel-rt:

  - ovl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up (CVE-2025-21887 bsc#1240176)
  - commit aefb37c
  - mptcp: always handle address removal under msk socket lock (CVE-2025-21875 bsc#1240168)
  - commit 30269f0
  - perf/core: Add RCU read lock protection to perf_iterate_ctx() (CVE-2025-21889 bsc#1240167)
  - commit 68c5afe
  - Update references for patches.suse/nvkm-correctly-calculate-the-available-space-of-the-.patch (CVE-2024-58018 bsc#1238990 stable-fixes)
  - commit 5d4613b
  - team: prevent adding a device which is already a team device lower (CVE-2024-58071 bsc#1238970)
  - commit e1c6462
  - nvme-tcp: Fix a C2HTermReq error message (git-fixes).
  - commit 1aeab84
  - nvmet-fc: Remove unused functions (git-fixes).
  - nvme-pci: remove stale comment (git-fixes).
  - nvme: move error logging from nvme_end_req() to __nvme_end_req()
    (git-fixes).
  - nvme-tcp: fix signedness bug in nvme_tcp_init_connection()
    (git-fixes).
  - nvmet-tcp: Fix a possible sporadic response drops in weakly
    ordered arch (git-fixes).
  - nvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
    (git-fixes).
  - nvmet: remove old function prototype (git-fixes).
  - nvme-ioctl: fix leaked requests on mapping error (git-fixes).
  - nvme: only allow entering LIVE from CONNECTING state (git-fixes
    bsc#1222649).
  - nvme-fc: rely on state transitions to handle connectivity loss
    (git-fixes bsc#1222649).
  - nvmet-rdma: recheck queue state is LIVE in state lock in recv
    done (git-fixes).
  - nvme-tcp: add basic support for the C2HTermReq PDU (git-fixes).
  - nvme-pci: quirk Acer FA100 for non-uniqueue identifiers
    (git-fixes).
  - nvme-fc: do not ignore connectivity loss during connecting
    (git-fixes bsc#1222649).
  - nvme-fc: go straight to connecting state when initializing
    (git-fixes bsc#1222649).
  - nvme-pci: use sgls for all user requests if possible
    (git-fixes).
  - nvme-pci: add support for sgl metadata (git-fixes).
  - commit af2f0ab
  - series: update metadata
  - Refresh
    patches.suse/ARM-module-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/Documentation-powerpc-fadump-add-additional-paramete.patch.
  - Refresh
    patches.suse/arm-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/arm64-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/arm64-module-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/bpf-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/bug-Use-RCU-instead-RCU-sched-to-protect-module_bug_list.patch.
  - Refresh
    patches.suse/cfi-Use-RCU-while-invoking-__module_address.patch.
  - Refresh
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_address.patch.
  - Refresh
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/kprobes-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh patches.suse/lib-dump_stack-Use-preempt_model_str.patch.
  - Refresh
    patches.suse/module-Allow-__module_address-to-be-called-from-RCU-section.patch.
  - Refresh
    patches.suse/module-Begin-to-move-from-RCU-sched-to-RCU.patch.
  - Refresh
    patches.suse/module-Remove-module_assert_mutex_or_preempt-from-try_add_tainted_module.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-__find_kallsyms_symbol_value.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-__is_module_percpu_address.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-all-users-of-__module_address.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-find_kallsyms_symbol.patch.
  - Refresh patches.suse/module-Use-RCU-in-find_module_all.patch.
  - Refresh patches.suse/module-Use-RCU-in-find_symbol.patch.
  - Refresh patches.suse/module-Use-RCU-in-module_get_kallsym.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-module_kallsyms_on_each_symbol.patch.
  - Refresh
    patches.suse/module-Use-RCU-in-search_module_extables.patch.
  - Refresh
    patches.suse/module-Use-proper-RCU-assignment-in-add_kallsyms.patch.
  - Refresh
    patches.suse/powerpc-Document-details-on-H_HTM-hcall.patch.
  - Refresh
    patches.suse/powerpc-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh patches.suse/powerpc-export-MIN-RMA-size.patch.
  - Refresh
    patches.suse/powerpc-fadump-fix-additional-param-memory-reservati.patch.
  - Refresh
    patches.suse/powerpc-increase-MIN-RMA-size-for-CAS-negotiation.patch.
  - Refresh
    patches.suse/powerpc-pseries-Export-hardware-trace-macro-dump-via.patch.
  - Refresh
    patches.suse/powerpc-pseries-Macros-and-wrapper-functions-for-H_H.patch.
  - Refresh
    patches.suse/powerpc-pseries-iommu-memory-notifier-incorrectly-ad.patch.
  - Refresh
    patches.suse/s390-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/sched-Add-a-generic-function-to-return-the-preemption-string.patch.
  - Refresh
    patches.suse/sched-Add-unlikey-branch-hints-to-several-system-calls.patch.
  - Refresh
    patches.suse/sched-Cancel-the-slice-protection-of-the-idle-entity.patch.
  - Refresh
    patches.suse/sched-Don-t-define-sched_clock_irqtime-as-static-key.patch.
  - Refresh
    patches.suse/sched-Reduce-the-default-slice-to-avoid-tasks-getting-an-extra-tick.patch.
  - Refresh
    patches.suse/sched-core-Remove-duplicate-included-header-file-stats.h.patch.
  - Refresh
    patches.suse/sched-eevdf-Force-propagating-min_slice-of-cfs_rq-when-en-de-queue-tasks.patch.
  - Refresh
    patches.suse/sched-fair-Refactor-can_migrate_task-to-elimate-looping.patch.
  - Refresh
    patches.suse/sched-membarrier-Fix-redundant-load-of-membarrier_st.patch.
  - Refresh
    patches.suse/static_call-Use-RCU-in-all-users-of-__module_text_address.patch.
  - Refresh patches.suse/tracing-Use-preempt_model_str.patch.
  - Refresh
    patches.suse/x86-Rely-on-generic-printing-of-preemption-model.patch.
  - Refresh
    patches.suse/x86-Use-RCU-in-all-users-of-__module_address.patch.
  - Refresh
    patches.suse/x86-tsc-Always-save-restore-TSC-sched_clock-on-suspend-resume.patch.
  - Refresh
    patches.suse/xtensa-Rely-on-generic-printing-of-preemption-model.patch.
  - commit 50abd21
  - arm64: cputype: Add MIDR_CORTEX_A76AE (git-fixes)
  - commit 12c538d
  - drm/fbdev-dma: Add shadow buffering for deferred I/O (bsc#1240174 CVE-2024-58091)
  - commit 81b755a
  - arm64: dts: rockchip: Fix PWM pinctrl names (git-fixes)
  - commit e826378
  - arm64: dts: rockchip: Remove bluetooth node from rock-3a (git-fixes)
  - commit 1354fe4
  - arm64: dts: imx8mp: change AUDIO_AXI_CLK_ROOT freq. to 800MHz (git-fixes)
  - commit 9607ffc
  - arm64: dts: imx8mp: add AUDIO_AXI_CLK_ROOT to AUDIOMIX block (git-fixes)
  - commit 79b8eb1
  - arm64: dts: imx8mp-skov: operate CPU at 850 mV by default (git-fixes)
  - commit 54699e8
  - arm64: dts: imx8mp-skov: correct PMIC board limits (git-fixes)
  - commit 864f35b
  - arm64: dts: exynos: gs101: disable pinctrl_gsacore node (git-fixes)
  - commit ea03073
  - arm64: tegra: Remove the Orin NX/Nano suspend key (git-fixes)
  - commit 5f41ffa
  - arm64/boot: Enable EL2 requirements for FEAT_PMUv3p9 (git-fixes)
  - commit b053f6d
  - arm64: errata: Add newer ARM cores to the spectre_bhb_loop_affected() (git-fixes)
  - commit 581e653
  - arm64: errata: Add KRYO 2XX/3XX/4XX silver cores to Spectre BHB safe (git-fixes)
  - commit 4a0576a
  - arm64: errata: Assume that unknown CPUs _are_ vulnerable to Spectre (git-fixes)
  - commit a914636
  - arm64: errata: Add QCOM_KRYO_4XX_GOLD to the spectre_bhb_k24_list (git-fixes)
  - commit 318ba4c
  - bitmap: Align documentation between bitmap_gather() and
    bitmap_scatter() (git-fixes).
  - commit 5ae3c5e
  - ipvlan: ensure network headers are in skb linear part
    (CVE-2025-21891 bsc#1240186).
  - commit be4e602
  - Update config files: Enable CONFIG_FRAMEBUFFER_CONSOLE_DEFERRED_TAKEOVER (bsc#1237220)
  - commit c79d4b3
  - Update
    patches.suse/ASoC-SOF-ipc4-topology-Harden-loops-for-looking-up-A.patch
    (git-fixes CVE-2025-21870 bsc#1240191).
  - Update
    patches.suse/RDMA-bnxt_re-Fix-the-page-details-for-the-srq-create.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21885 bsc#1240169).
  - Update
    patches.suse/RDMA-mlx5-Fix-a-WARN-during-dereg_mr-for-DM-type.patch
    (git-fixes CVE-2025-21888 bsc#1240177).
  - Update
    patches.suse/RDMA-mlx5-Fix-implicit-ODP-hang-on-parent-deregistra.patch
    (git-fixes CVE-2025-21886 bsc#1240188).
  - Update
    patches.suse/RDMA-mlx5-Fix-the-recovery-flow-of-the-UMR-QP.patch
    (git-fixes CVE-2025-21892 bsc#1240175).
  - Update
    patches.suse/ata-libata-sff-Ensure-that-we-cannot-write-outside-t.patch
    (git-fixes CVE-2025-21738 bsc#1238917).
  - Update
    patches.suse/cpufreq-amd-pstate-Fix-cpufreq_policy-ref-counting.patch
    (git-fixes CVE-2025-21841 bsc#1239062).
  - Update
    patches.suse/dm-integrity-Avoid-divide-by-zero-in-table-status-in.patch
    (git-fixes CVE-2025-21874 bsc#1240190).
  - Update patches.suse/drm-xe-userptr-fix-EFAULT-handling.patch
    (git-fixes CVE-2025-21880 bsc#1240170).
  - Update
    patches.suse/i2c-npcm-disable-interrupt-enable-bit-before-devm_re.patch
    (git-fixes CVE-2025-21878 bsc#1240192).
  - Update
    patches.suse/ice-Fix-deinitializing-VF-in-error-path.patch
    (jsc#PED-10419 CVE-2025-21883 bsc#1240189).
  - Update patches.suse/idpf-fix-checksums-set-in-idpf_rx_rsc.patch
    (jsc#PED-10581 CVE-2025-21890 bsc#1240173).
  - Update patches.suse/iommu-vt-d-Fix-suspicious-RCU-usage.patch
    (git-fixes CVE-2025-21876 bsc#1240179).
  - Update
    patches.suse/net-mlx5-Fix-vport-QoS-cleanup-on-error.patch
    (jsc#PED-11331 CVE-2025-21882 bsc#1240187).
  - Update
    patches.suse/powerpc-code-patching-Disable-KASAN-report-during-pa.patch
    (bsc#1215199 CVE-2025-21869 bsc#1240182).
  - Update
    patches.suse/usbnet-gl620a-fix-endpoint-checking-in-genelink_bind.patch
    (git-fixes CVE-2025-21877 bsc#1240172).
  - commit 608a30b
  - Update
    patches.suse/media-vidtv-Fix-a-null-ptr-deref-in-vidtv_mux_stop_t.patch
    (git-fixes CVE-2024-57834 bsc#1238993).
  - Update
    patches.suse/nvkm-correctly-calculate-the-available-space-of-the-.patch
    (stable-fixes CVE-2024-58018 bsc#1238990).
  - commit 60408e9
  - IB/mad: Check available slots before posting receive WRs (git-fixes)
  - commit 89aff72
  - RDMA/mlx5: Fix calculation of total invalidated pages (git-fixes)
  - commit d8fa607
  - RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow (git-fixes)
  - commit 7a3d709
  - RDMA/mlx5: Fix page_size variable overflow (git-fixes)
  - commit d686296
  - RDMA/mlx5: Fix cache entry update on dereg error (git-fixes)
  - commit 5b61d30
  - RDMA/mlx5: Fix MR cache initialization error flow (git-fixes)
  - commit 977d207
  - RDMA/core: Fix use-after-free when rename device name (git-fixes)
  - commit e693f34
  - RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() (git-fixes)
  - commit a2f7db1
  - RDMA/core: Don't expose hw_counters outside of init net namespace (git-fixes)
  - commit ac060af

++++ ncurses:

  - Add ncurses patch 20250329
    + add XM/xm to ms-terminal, to enable mouse with experimental Windows
    driver -TD
    + add -x option to infocmp in MKfallback.sh
    + improve experimental Windows driver by restoring the scroll buffer
    and console mode, e.g., when reset_prog_mode or endwin is called
    (patch by Daniel Starke).
    + add a buffer-limit check in postprocess_termcap (report/testcase by
    Yifan Zhang).

++++ ndctl:

  - Update to version 81
    * ndctl/namespace: avoid integer overflow in namespace validation
    * ndctl/dimm: do not increment a ULLONG_MAX slot value
    * ndctl/namespace: protect against overflow handling param.offset
    * ndctl/namespace: protect against under|over-flow w bad param.align
    * ndctl/list: display region caps for any of BTT, PFN, DAX
    * cxl/region: report max size for region creation
    * daxctl: output more information if memblock is unremovable
    * cxl/json: remove prefix from tracefs.h #include
  - Remove upstreamed cxl-json-Fix-tracefs-include.patch

++++ nvidia-open-driver-G06-signed:

  - limit build of -azure flavor to SP6

------------------------------------------------------------------
------------------  2025-3-30  -  Mar 30 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Move upstreamed patches into sorted section
  - commit aabb1e8
  - crypto: qat - add shutdown handler to qat_c3xxx (bsc#1239934).
  - crypto: qat - remove redundant prototypes in qat_c3xxx
    (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_c62x (bsc#1239934).
  - crypto: qat - remove redundant prototypes in qat_c62x
    (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_dh895xcc
    (bsc#1239934).
  - crypto: qat - remove redundant prototypes in qat_dh895xcc
    (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_420xx (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_4xxx (bsc#1239934).
  - commit 94c5984
  - mailbox: tegra-hsp: Define dimensioning masks in SoC data
    (git-fixes).
  - power: supply: max77693: Fix wrong conversion of charge input
    threshold value (git-fixes).
  - power: supply: bq27xxx_battery: do not update cached flags
    prematurely (git-fixes).
  - remoteproc: qcom_q6v5_pas: Make single-PD handling more robust
    (git-fixes).
  - remoteproc: qcom_q6v5_pas: Use resource with CX PD for MSM8226
    (git-fixes).
  - remoteproc: core: Clear table_sz when rproc_shutdown
    (git-fixes).
  - remoteproc: qcom: pas: add minidump_id to SC7280 WPSS
    (git-fixes).
  - remoteproc: qcom_q6v5_mss: Handle platforms with one power
    domain (git-fixes).
  - pinctrl: npcm8xx: Fix incorrect struct npcm8xx_pincfg assignment
    (git-fixes).
  - pinctrl: samsung: add support for eint_fltcon_offset
    (git-fixes).
  - pinctrl: qcom: Clear latched interrupt status when changing
    IRQ type (git-fixes).
  - pinctrl: tegra: Set SFIO mode to Mux Register (git-fixes).
  - pinctrl: intel: Fix wrong bypass assignment in
    intel_pinctrl_probe_pwm() (git-fixes).
  - pinctrl: renesas: rza2: Fix missing of_node_put() call
    (git-fixes).
  - pinctrl: renesas: rzv2m: Fix missing of_node_put() call
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix missing of_node_put() call
    (git-fixes).
  - pinctrl: renesas: rzg2l: Suppress binding attributes
    (git-fixes).
  - pinctrl: nuvoton: npcm8xx: Fix error handling in
    npcm8xx_gpio_fw() (git-fixes).
  - leds: rgb: leds-qcom-lpg: Fix calculation of best period Hi-Res
    PWMs (git-fixes).
  - mfd: ene-kb3930: Fix a potential NULL pointer dereference
    (git-fixes).
  - mfd: sm501: Switch to BIT() to mitigate integer overflows
    (git-fixes).
  - of: property: Increase NR_FWNODE_REFERENCE_ARGS (git-fixes).
  - of/irq: Fix device node refcount leakages in of_irq_init()
    (git-fixes).
  - of/irq: Fix device node refcount leakage in API
    irq_of_parse_and_map() (git-fixes).
  - of/irq: Fix device node refcount leakages in of_irq_count()
    (git-fixes).
  - of/irq: Fix device node refcount leakage in API
    of_irq_parse_raw() (git-fixes).
  - of/irq: Fix device node refcount leakage in API
    of_irq_parse_one() (git-fixes).
  - lib: 842: Improve error handling in sw842_compress()
    (git-fixes).
  - commit f260551
  - backlight: led_bl: Hold led_access lock when calling
    led_sysfs_disable() (git-fixes).
  - leds: rgb: leds-qcom-lpg: Fix pwm resolution max for Hi-Res PWMs
    (git-fixes).
  - leds: Fix LED_OFF brightness race (git-fixes).
  - Revert "leds-pca955x: Remove the unused function
    pca95xx_num_led_regs()" (stable-fixes).
  - crypto: nx - Fix uninitialised hv_nxc on error (git-fixes).
  - crypto: qat - remove access to parity register for QAT GEN4
    (git-fixes).
  - crypto: qat - set parity error mask for qat_420xx (git-fixes).
  - crypto: ccp - Fix uAPI definitions of PSP errors (git-fixes).
  - crypto: iaa - Test the correct request flag (git-fixes).
  - crypto: tegra - Use HMAC fallback when keyslots are full
    (git-fixes).
  - crypto: tegra - Set IV to NULL explicitly for AES ECB
    (git-fixes).
  - crypto: tegra - Fix CMAC intermediate result handling
    (git-fixes).
  - crypto: tegra - check return value for hash do_one_req
    (git-fixes).
  - crypto: tegra - Use separate buffer for setkey (git-fixes).
  - crypto: bpf - Add MODULE_DESCRIPTION for skcipher (git-fixes).
  - crypto: api - Fix larval relookup type and mask (git-fixes).
  - crypto: hisilicon/sec2 - fix for sec spec check (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead authsize alignment
    (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead auth key length
    (git-fixes).
  - commit aa5d485

++++ kernel-rt:

  - Move upstreamed patches into sorted section
  - commit aabb1e8
  - crypto: qat - add shutdown handler to qat_c3xxx (bsc#1239934).
  - crypto: qat - remove redundant prototypes in qat_c3xxx
    (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_c62x (bsc#1239934).
  - crypto: qat - remove redundant prototypes in qat_c62x
    (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_dh895xcc
    (bsc#1239934).
  - crypto: qat - remove redundant prototypes in qat_dh895xcc
    (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_420xx (bsc#1239934).
  - crypto: qat - add shutdown handler to qat_4xxx (bsc#1239934).
  - commit 94c5984
  - mailbox: tegra-hsp: Define dimensioning masks in SoC data
    (git-fixes).
  - power: supply: max77693: Fix wrong conversion of charge input
    threshold value (git-fixes).
  - power: supply: bq27xxx_battery: do not update cached flags
    prematurely (git-fixes).
  - remoteproc: qcom_q6v5_pas: Make single-PD handling more robust
    (git-fixes).
  - remoteproc: qcom_q6v5_pas: Use resource with CX PD for MSM8226
    (git-fixes).
  - remoteproc: core: Clear table_sz when rproc_shutdown
    (git-fixes).
  - remoteproc: qcom: pas: add minidump_id to SC7280 WPSS
    (git-fixes).
  - remoteproc: qcom_q6v5_mss: Handle platforms with one power
    domain (git-fixes).
  - pinctrl: npcm8xx: Fix incorrect struct npcm8xx_pincfg assignment
    (git-fixes).
  - pinctrl: samsung: add support for eint_fltcon_offset
    (git-fixes).
  - pinctrl: qcom: Clear latched interrupt status when changing
    IRQ type (git-fixes).
  - pinctrl: tegra: Set SFIO mode to Mux Register (git-fixes).
  - pinctrl: intel: Fix wrong bypass assignment in
    intel_pinctrl_probe_pwm() (git-fixes).
  - pinctrl: renesas: rza2: Fix missing of_node_put() call
    (git-fixes).
  - pinctrl: renesas: rzv2m: Fix missing of_node_put() call
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix missing of_node_put() call
    (git-fixes).
  - pinctrl: renesas: rzg2l: Suppress binding attributes
    (git-fixes).
  - pinctrl: nuvoton: npcm8xx: Fix error handling in
    npcm8xx_gpio_fw() (git-fixes).
  - leds: rgb: leds-qcom-lpg: Fix calculation of best period Hi-Res
    PWMs (git-fixes).
  - mfd: ene-kb3930: Fix a potential NULL pointer dereference
    (git-fixes).
  - mfd: sm501: Switch to BIT() to mitigate integer overflows
    (git-fixes).
  - of: property: Increase NR_FWNODE_REFERENCE_ARGS (git-fixes).
  - of/irq: Fix device node refcount leakages in of_irq_init()
    (git-fixes).
  - of/irq: Fix device node refcount leakage in API
    irq_of_parse_and_map() (git-fixes).
  - of/irq: Fix device node refcount leakages in of_irq_count()
    (git-fixes).
  - of/irq: Fix device node refcount leakage in API
    of_irq_parse_raw() (git-fixes).
  - of/irq: Fix device node refcount leakage in API
    of_irq_parse_one() (git-fixes).
  - lib: 842: Improve error handling in sw842_compress()
    (git-fixes).
  - commit f260551
  - backlight: led_bl: Hold led_access lock when calling
    led_sysfs_disable() (git-fixes).
  - leds: rgb: leds-qcom-lpg: Fix pwm resolution max for Hi-Res PWMs
    (git-fixes).
  - leds: Fix LED_OFF brightness race (git-fixes).
  - Revert "leds-pca955x: Remove the unused function
    pca95xx_num_led_regs()" (stable-fixes).
  - crypto: nx - Fix uninitialised hv_nxc on error (git-fixes).
  - crypto: qat - remove access to parity register for QAT GEN4
    (git-fixes).
  - crypto: qat - set parity error mask for qat_420xx (git-fixes).
  - crypto: ccp - Fix uAPI definitions of PSP errors (git-fixes).
  - crypto: iaa - Test the correct request flag (git-fixes).
  - crypto: tegra - Use HMAC fallback when keyslots are full
    (git-fixes).
  - crypto: tegra - Set IV to NULL explicitly for AES ECB
    (git-fixes).
  - crypto: tegra - Fix CMAC intermediate result handling
    (git-fixes).
  - crypto: tegra - check return value for hash do_one_req
    (git-fixes).
  - crypto: tegra - Use separate buffer for setkey (git-fixes).
  - crypto: bpf - Add MODULE_DESCRIPTION for skcipher (git-fixes).
  - crypto: api - Fix larval relookup type and mask (git-fixes).
  - crypto: hisilicon/sec2 - fix for sec spec check (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead authsize alignment
    (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead auth key length
    (git-fixes).
  - commit aa5d485

++++ pcre2:

  - Update to 10.45:
    * New upstream maintainers (and signing key)
    * Update Unicode support to UCD 16
    * Case-insensitive matching of Unicode properties Ll, Lt, and Lu
    has been changed to match Perl
    * Case-insensitive matching of backreferences now respects the
    PCRE2_EXTRA_CASELESS_RESTRICT option
    * Parsing of the \x escape is stricter, and is no longer parsed
    as an escape for the NUL character if not followed by '{' or
    a hexadecimal digit. Use \x00 instead.
    * Add a new feature called scan substring. This is a type of
    assertion which matches the content of a capturing block to a
    sub-pattern.
    * Add support for UTS#18 compatible character classes
    * Add support for Perl-style extended character classes
    * JIT compilation now fails with the new error code
    PCRE2_ERROR_JIT_UNSUPPORTED for patterns which use features not
    supported by the JIT compiler.
    * New options PCRE2_EXTRA_NO_BS0 (disallow \0 as an escape for
    the NUL character); PCRE2_EXTRA_PYTHON_OCTAL (use Python
    disambiguation rules for deciding whether \12 is a
    backreference or an octal escape); PCRE2_EXTRA_NEVER_CALLOUT
    (disable callout syntax entirely); PCRE2_EXTRA_TURKISH_CASING
    (use Turkish rules for case-insensitive matching).
    * Add new API function pcre2_set_optimize() for
    controlling which optimizations are enabled.
    * A variety of extensions have been made to pcre2_substitute()
    and its syntax for replacement strings. These now support:
    \123 octal escapes; titlecasing \u\L; \1 backreferences; \g<1>
    and $<NAME> backreferences; $& $` $' and $_; new function
    pcre2_set_substitute_case_callout() to allow locale-aware case
    transformation.
  - drop pcre2-10.44-github-issue-415.patch, included upstream
  - update license to BSD-3-Clause WITH PCRE2-exception and cascade
    to subpackages and parts (boo#1240358)

++++ python-setuptools:

  - update to 78.1.0:
    * Restore access to _get_vc_env with a warning.

------------------------------------------------------------------
------------------  2025-3-29  -  Mar 29 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - schema: Allow C as a valid locale
    It should be permitted to set the "C.UTF-8" locale for minimal images
    that are not preloaded with locales. The "C.UTF-8" locale has been
    supported in Linux distributions for many years.

++++ kbd:

  - Add kbd-2.7.1-reproducible-gzip.patch (bsc#1240348)

++++ kernel-default:

  - landlock: Add erratum for TCP fix (git-fixes).
  - commit 0d484c7
  - ocfs2: fix incorrect CPU endianness conversion causing mount
    failure (git-fixes).
  - commit 8fd90d0
  - ocfs2: mark dquot as inactive if failed to start trans while
    releasing dquot (git-fixes).
  - commit cc37a55
  - ocfs2: handle a symlink read error correctly (git-fixes).
  - commit 444eb1b
  - ocfs2: check dir i_size in ocfs2_find_entry (git-fixes).
  - commit c0e37b2
  - ocfs2: fix the space leak in LA when releasing LA (git-fixes).
  - commit 1a397ea
  - ocfs2: update seq_file index in ocfs2_dlm_seq_next (git-fixes).
  - commit 036dd0b
  - selftests/landlock: Add a new test for setuid() (git-fixes).
  - commit 01c306d
  - selftests/landlock: Split signal_scoping_threads tests
    (git-fixes).
  - commit 523b194
  - landlock: Always allow signals between threads of the same
    process (git-fixes).
  - commit 1745380
  - landlock: Prepare to add second errata (git-fixes).
  - commit 7565437
  - landlock: Add the errata interface (git-fixes).
  - commit ab61616
  - landlock: Move code to ease future backports (git-fixes).
  - commit 8bc7b59
  - landlock: Fix non-TCP sockets restriction (git-fixes).
  - commit 10f3a13
  - dlm: fix error if active rsb is not hashed (git-fixes).
  - commit dde3f38
  - dlm: fix error if inactive rsb is not hashed (git-fixes).
  - commit 2a17834
  - dlm: prevent NPD when writing a positive value to event_done
    (git-fixes).
  - commit 312be0b
  - Move upstreamed nfsd and sunrpc patches into sorted section
  - commit 34f7d67
  - Move upstreamed PCI, initramfs and dlm patches into sorted section
  - commit c907f08
  - drm/amd/display: Exit idle optimizations before accessing PHY
    (git-fixes).
  - commit 56b98fb
  - PCI: xilinx-cpm: Fix IRQ domain leak in error path of probe
    (git-fixes).
  - PCI: qcom-ep: Mark BAR0/BAR2 as 64bit BARs and BAR1/BAR3 as
    RESERVED (git-fixes).
  - PCI: mediatek-gen3: Configure PBUS_CSR registers for EN7581 SoC
    (git-fixes).
  - PCI: j721e: Fix the value of .linkdown_irq_regfield for J784S4
    (git-fixes).
  - PCI: histb: Fix an error handling path in histb_pcie_probe()
    (git-fixes).
  - PCI: dwc: ep: Return -ENOMEM for allocation failures
    (git-fixes).
  - PCI: cadence-ep: Fix the driver to send MSG TLP for INTx
    without data payload (git-fixes).
  - PCI: brcmstb: Fix potential premature regulator disabling
    (git-fixes).
  - PCI: brcmstb: Fix error path after a call to
    regulator_bulk_get() (git-fixes).
  - PCI: brcmstb: Use internal register to change link capability
    (git-fixes).
  - PCI: brcmstb: Set generation limit before PCIe link up
    (git-fixes).
  - PCI: brcmstb: Fix missing of_node_put() in brcm_pcie_probe()
    (git-fixes).
  - PCI: Fix BAR resizing when VF BARs are assigned (git-fixes).
  - PCI: Remove add_align overwrite unrelated to size0 (git-fixes).
  - PCI: Avoid reset when disabled via sysfs (git-fixes).
  - PCI: pciehp: Don't enable HPIE when resuming in poll mode
    (git-fixes).
  - PCI: pciehp: Avoid unnecessary device replacement check
    (git-fixes).
  - PCI/portdrv: Only disable pciehp interrupts early when needed
    (git-fixes).
  - PCI: Remove stray put_device() in pci_register_host_bridge()
    (git-fixes).
  - PCI: Fix reference leak in pci_alloc_child_bus() (git-fixes).
  - PCI: Fix reference leak in pci_register_host_bridge()
    (git-fixes).
  - PCI: Fix wrong length of devres array (git-fixes).
  - PCI/ASPM: Fix link state exit during switch upstream function
    removal (git-fixes).
  - tpm, tpm_tis: Fix timeout handling when waiting for TPM status
    (git-fixes).
  - tpm: do not start chip while suspended (git-fixes).
  - commit 9fad6ad
  - PCI/ACS: Fix 'pci=config_acs=' parameter (git-fixes).
  - drm/amd/display: avoid NPD when ASIC does not support DMUB
    (git-fixes).
  - drm/mediatek: dsi: fix error codes in mtk_dsi_host_transfer()
    (git-fixes).
  - drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL
    ptr (git-fixes).
  - drm/mediatek: Fix config_updating flag never false when no
    mbox channel (git-fixes).
  - drm/mediatek: mtk_hdmi: Fix typo for aud_sampe_size member
    (git-fixes).
  - drm/mediatek: mtk_hdmi: Unregister audio platform device on
    failure (git-fixes).
  - drm/msm/a6xx: Fix a6xx indexed-regs in devcoreduump (git-fixes).
  - drm/msm/a6xx: Fix stale rpmh votes from GPU (git-fixes).
  - drm/msm/dsi: Add check for devm_kstrdup() (git-fixes).
  - drm/msm/dsi: Set PHY usescase (and mode) before registering
    DSI host (git-fixes).
  - drm/msm/dsi: Use existing per-interface slice count in DSC
    timing (git-fixes).
  - drm/msm/dsi/phy: Program clock inverters in correct register
    (git-fixes).
  - drm/msm/dpu: don't use active in atomic_check() (git-fixes).
  - drm/amd/display: fix type mismatch in
    CalculateDynamicMetadataParameters() (git-fixes).
  - drm/amdkfd: Fix Circular Locking Dependency in
    'svm_range_cpu_invalidate_pagetables' (git-fixes).
  - drm/amd/display: fix an indent issue in DML21 (git-fixes).
  - drm/panthor: Update CS_STATUS_ defines to correct values
    (git-fixes).
  - drm/bridge: Fix spelling mistake "gettin" -> "getting"
    (git-fixes).
  - drm/repaper: fix integer overflows in repeat functions
    (git-fixes).
  - drm/panel: ilitek-ili9882t: fix GPIO name in error message
    (git-fixes).
  - drm/amdgpu/umsch: fix ucode check (git-fixes).
  - drm/amdgpu/umsch: declare umsch firmware (git-fixes).
  - drm/amdgpu: refine smu send msg debug log format (git-fixes).
  - gpu: cdns-mhdp8546: fix call balance of mhdp->clk handling
    routines (git-fixes).
  - fbdev: sm501fb: Add some geometry checks (git-fixes).
  - mdacon: rework dependency list (git-fixes).
  - dummycon: fix default rows/cols (git-fixes).
  - fbdev: au1100fb: Move a variable assignment behind a null
    pointer check (git-fixes).
  - commit ec5fccf
  - Revert "drm/amd/display: Exit idle optimizations before attempt
    to access PHY" (stable-fixes).
  - drm/radeon/ci_dpm: Remove needless NULL checks of dpm tables
    (git-fixes).
  - drm/vkms: Fix use after free and double free on init error
    (git-fixes).
  - drm: xlnx: zynqmp: Fix max dma segment size (git-fixes).
  - drm/bridge: it6505: fix HDCP V match check is not performed
    correctly (git-fixes).
  - drm/ast: Fix ast_dp connection status (git-fixes).
  - drm/dp_mst: Fix drm RAD print (git-fixes).
  - drm/ssd130x: ensure ssd132x pitch is correct (git-fixes).
  - drm/ssd130x: fix ssd132x encoding (git-fixes).
  - drm/ssd130x: Set SPI .id_table to prevent an SPI core warning
    (git-fixes).
  - drm/bridge: ti-sn65dsi86: Fix multiple instances (git-fixes).
  - drm/amdgpu/pm: Handle SCLK offset correctly in overdrive for
    smu 14.0.2 (stable-fixes).
  - drm/amd/display: Fix message for support_edp0_on_dp1
    (git-fixes).
  - drm/amdgpu: Restore uncached behaviour on GFX12 (stable-fixes).
  - drm/amdgpu/pm: wire up hwmon fan speed for smu 14.0.2
    (stable-fixes).
  - drm/amd/pm: add unique_id for gfx12 (stable-fixes).
  - drm/amdgpu: Remove JPEG from vega and carrizo video caps
    (stable-fixes).
  - drm/amdgpu: Fix JPEG video caps max size for navi1x and raven
    (stable-fixes).
  - drm/amdgpu: Fix MPEG2, MPEG4 and VC1 video caps max size
    (stable-fixes).
  - commit 86197b9

++++ kernel-firmware-amdgpu:

  - Update to version 20250328 (git commit 4bfa7c6351ab):
    * amdgpu: update dcn 3.5 and dcn 3.5.1 firmware to 9.0.27.0
    * amdgpu: update dcn 3.1.4 firmware to 8.0.78.0

++++ kernel-rt:

  - landlock: Add erratum for TCP fix (git-fixes).
  - commit 0d484c7
  - ocfs2: fix incorrect CPU endianness conversion causing mount
    failure (git-fixes).
  - commit 8fd90d0
  - ocfs2: mark dquot as inactive if failed to start trans while
    releasing dquot (git-fixes).
  - commit cc37a55
  - ocfs2: handle a symlink read error correctly (git-fixes).
  - commit 444eb1b
  - ocfs2: check dir i_size in ocfs2_find_entry (git-fixes).
  - commit c0e37b2
  - ocfs2: fix the space leak in LA when releasing LA (git-fixes).
  - commit 1a397ea
  - ocfs2: update seq_file index in ocfs2_dlm_seq_next (git-fixes).
  - commit 036dd0b
  - selftests/landlock: Add a new test for setuid() (git-fixes).
  - commit 01c306d
  - selftests/landlock: Split signal_scoping_threads tests
    (git-fixes).
  - commit 523b194
  - landlock: Always allow signals between threads of the same
    process (git-fixes).
  - commit 1745380
  - landlock: Prepare to add second errata (git-fixes).
  - commit 7565437
  - landlock: Add the errata interface (git-fixes).
  - commit ab61616
  - landlock: Move code to ease future backports (git-fixes).
  - commit 8bc7b59
  - landlock: Fix non-TCP sockets restriction (git-fixes).
  - commit 10f3a13
  - dlm: fix error if active rsb is not hashed (git-fixes).
  - commit dde3f38
  - dlm: fix error if inactive rsb is not hashed (git-fixes).
  - commit 2a17834
  - dlm: prevent NPD when writing a positive value to event_done
    (git-fixes).
  - commit 312be0b
  - Move upstreamed nfsd and sunrpc patches into sorted section
  - commit 34f7d67
  - Move upstreamed PCI, initramfs and dlm patches into sorted section
  - commit c907f08
  - drm/amd/display: Exit idle optimizations before accessing PHY
    (git-fixes).
  - commit 56b98fb
  - PCI: xilinx-cpm: Fix IRQ domain leak in error path of probe
    (git-fixes).
  - PCI: qcom-ep: Mark BAR0/BAR2 as 64bit BARs and BAR1/BAR3 as
    RESERVED (git-fixes).
  - PCI: mediatek-gen3: Configure PBUS_CSR registers for EN7581 SoC
    (git-fixes).
  - PCI: j721e: Fix the value of .linkdown_irq_regfield for J784S4
    (git-fixes).
  - PCI: histb: Fix an error handling path in histb_pcie_probe()
    (git-fixes).
  - PCI: dwc: ep: Return -ENOMEM for allocation failures
    (git-fixes).
  - PCI: cadence-ep: Fix the driver to send MSG TLP for INTx
    without data payload (git-fixes).
  - PCI: brcmstb: Fix potential premature regulator disabling
    (git-fixes).
  - PCI: brcmstb: Fix error path after a call to
    regulator_bulk_get() (git-fixes).
  - PCI: brcmstb: Use internal register to change link capability
    (git-fixes).
  - PCI: brcmstb: Set generation limit before PCIe link up
    (git-fixes).
  - PCI: brcmstb: Fix missing of_node_put() in brcm_pcie_probe()
    (git-fixes).
  - PCI: Fix BAR resizing when VF BARs are assigned (git-fixes).
  - PCI: Remove add_align overwrite unrelated to size0 (git-fixes).
  - PCI: Avoid reset when disabled via sysfs (git-fixes).
  - PCI: pciehp: Don't enable HPIE when resuming in poll mode
    (git-fixes).
  - PCI: pciehp: Avoid unnecessary device replacement check
    (git-fixes).
  - PCI/portdrv: Only disable pciehp interrupts early when needed
    (git-fixes).
  - PCI: Remove stray put_device() in pci_register_host_bridge()
    (git-fixes).
  - PCI: Fix reference leak in pci_alloc_child_bus() (git-fixes).
  - PCI: Fix reference leak in pci_register_host_bridge()
    (git-fixes).
  - PCI: Fix wrong length of devres array (git-fixes).
  - PCI/ASPM: Fix link state exit during switch upstream function
    removal (git-fixes).
  - tpm, tpm_tis: Fix timeout handling when waiting for TPM status
    (git-fixes).
  - tpm: do not start chip while suspended (git-fixes).
  - commit 9fad6ad
  - PCI/ACS: Fix 'pci=config_acs=' parameter (git-fixes).
  - drm/amd/display: avoid NPD when ASIC does not support DMUB
    (git-fixes).
  - drm/mediatek: dsi: fix error codes in mtk_dsi_host_transfer()
    (git-fixes).
  - drm/mediatek: dp: drm_err => dev_err in HPD path to avoid NULL
    ptr (git-fixes).
  - drm/mediatek: Fix config_updating flag never false when no
    mbox channel (git-fixes).
  - drm/mediatek: mtk_hdmi: Fix typo for aud_sampe_size member
    (git-fixes).
  - drm/mediatek: mtk_hdmi: Unregister audio platform device on
    failure (git-fixes).
  - drm/msm/a6xx: Fix a6xx indexed-regs in devcoreduump (git-fixes).
  - drm/msm/a6xx: Fix stale rpmh votes from GPU (git-fixes).
  - drm/msm/dsi: Add check for devm_kstrdup() (git-fixes).
  - drm/msm/dsi: Set PHY usescase (and mode) before registering
    DSI host (git-fixes).
  - drm/msm/dsi: Use existing per-interface slice count in DSC
    timing (git-fixes).
  - drm/msm/dsi/phy: Program clock inverters in correct register
    (git-fixes).
  - drm/msm/dpu: don't use active in atomic_check() (git-fixes).
  - drm/amd/display: fix type mismatch in
    CalculateDynamicMetadataParameters() (git-fixes).
  - drm/amdkfd: Fix Circular Locking Dependency in
    'svm_range_cpu_invalidate_pagetables' (git-fixes).
  - drm/amd/display: fix an indent issue in DML21 (git-fixes).
  - drm/panthor: Update CS_STATUS_ defines to correct values
    (git-fixes).
  - drm/bridge: Fix spelling mistake "gettin" -> "getting"
    (git-fixes).
  - drm/repaper: fix integer overflows in repeat functions
    (git-fixes).
  - drm/panel: ilitek-ili9882t: fix GPIO name in error message
    (git-fixes).
  - drm/amdgpu/umsch: fix ucode check (git-fixes).
  - drm/amdgpu/umsch: declare umsch firmware (git-fixes).
  - drm/amdgpu: refine smu send msg debug log format (git-fixes).
  - gpu: cdns-mhdp8546: fix call balance of mhdp->clk handling
    routines (git-fixes).
  - fbdev: sm501fb: Add some geometry checks (git-fixes).
  - mdacon: rework dependency list (git-fixes).
  - dummycon: fix default rows/cols (git-fixes).
  - fbdev: au1100fb: Move a variable assignment behind a null
    pointer check (git-fixes).
  - commit ec5fccf
  - Revert "drm/amd/display: Exit idle optimizations before attempt
    to access PHY" (stable-fixes).
  - drm/radeon/ci_dpm: Remove needless NULL checks of dpm tables
    (git-fixes).
  - drm/vkms: Fix use after free and double free on init error
    (git-fixes).
  - drm: xlnx: zynqmp: Fix max dma segment size (git-fixes).
  - drm/bridge: it6505: fix HDCP V match check is not performed
    correctly (git-fixes).
  - drm/ast: Fix ast_dp connection status (git-fixes).
  - drm/dp_mst: Fix drm RAD print (git-fixes).
  - drm/ssd130x: ensure ssd132x pitch is correct (git-fixes).
  - drm/ssd130x: fix ssd132x encoding (git-fixes).
  - drm/ssd130x: Set SPI .id_table to prevent an SPI core warning
    (git-fixes).
  - drm/bridge: ti-sn65dsi86: Fix multiple instances (git-fixes).
  - drm/amdgpu/pm: Handle SCLK offset correctly in overdrive for
    smu 14.0.2 (stable-fixes).
  - drm/amd/display: Fix message for support_edp0_on_dp1
    (git-fixes).
  - drm/amdgpu: Restore uncached behaviour on GFX12 (stable-fixes).
  - drm/amdgpu/pm: wire up hwmon fan speed for smu 14.0.2
    (stable-fixes).
  - drm/amd/pm: add unique_id for gfx12 (stable-fixes).
  - drm/amdgpu: Remove JPEG from vega and carrizo video caps
    (stable-fixes).
  - drm/amdgpu: Fix JPEG video caps max size for navi1x and raven
    (stable-fixes).
  - drm/amdgpu: Fix MPEG2, MPEG4 and VC1 video caps max size
    (stable-fixes).
  - commit 86197b9

++++ at-spi2-core:

  - Update to version 2.56.1:
    + device-a11y-manager:
  - Fix crash on dispose
  - Check properly for the DBus backend presence

++++ python-typing_extensions:

  - update to 4.13.0:
    * Add `typing_extensions.TypeForm` from PEP 747.
    * Add `typing_extensions.get_annotations`, a backport of
    * `inspect.get_annotations` that adds features specified
    * by PEP 649.
    * Backport `evaluate_forward_ref` from CPython
    * Update PEP 728 implementation to a newer version of the PEP.
    * Copy the coroutine status of functions and methods wrapped
    with `@typing_extensions.deprecated`.
    * Fix bug where `TypeAliasType` instances could be subscripted
    even where they were not generic.
    * Fix bug where a subscripted `TypeAliasType` instance did not
    have all attributes of the original `TypeAliasType` instance
    on older Python versions.
    * Fix bug where subscripted `TypeAliasType` instances (and some
    other subscripted objects) had wrong parameters if they were
    directly subscripted with an `Unpack` object.

++++ vim:

  - Update to version 9.1.1258:
    * patch 9.1.1258: regexp: max \U and \%U value is limited by
    INT_MAX
    * patch 9.1.1257:
  - Mixing vim_strsize() with mb_ptr2cells() in pum_redraw()
  - runtime(lf): add lf r34 keywords to syntax script
    * patch 9.1.1256:
  - if_python: duplicate tuple data entries
  - runtime(vim): Update base-syntax, match tuples
    * patch 9.1.1255: missing test condition for 'pummaxwidth'
    setting
    * patch 9.1.1254: need more tests for the comment plugin
    * patch 9.1.1253:
  - abort when closing window with attached quickfix data
  - runtime(doc): non-portable sed regex in Makefile for
    pi_netrw.txt rule
    * patch 9.1.1252: typos in code and docs related to 'diffopt'
    "inline:"
    * patch 9.1.1251: if_python: build error with tuples and dynamic
    python
    * patch 9.1.1250: cannot set the maximum popup menu width
    * patch 9.1.1249:
  - tests: no test that 'listchars' "eol" doesn't affect "gM"
  - runtime(doc): group python interface related items in
    todo.txt
    * patch 9.1.1248: compile error when building without
    FEAT_QUICKFIX
    * patch 9.1.1247: fragile setup to get (preferred) keys from
    key_name_entry
    * patch 9.1.1246: coverity complains about some changes in
    v9.1.1243
    * patch 9.1.1245: need some more tests for curly braces
    evaluation

++++ wireless-regdb:

  - Update to version 20250220 (boo#1240356):
    * Update regulatory info for Oman (OM)
    * Update regulatory rules for Iran (IR) on both 2.4 and 5Ghz for 2021
    * Update regulatory info for Cayman Islands (KY) for 2024
    * Update regulatory rules for Austria (AT)
    * Permit 320 MHz bandwidth in 6 GHz band in ETSI/CEPT
    * Update regulatory rules for Armenia (AM) on 2.4 and 5 GHz
    * Update regulatory info for Azerbaijan (AZ) on 6GHz for 2024

------------------------------------------------------------------
------------------  2025-3-28  -  Mar 28 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Update to version 2.29
    * Make sure that password prompt is seen Latest
    Use a temporary buffer to be silent during asking passwords.
    And stop system console output during password questions
    only if temporary buffer becomes short. As well as do coloring
    on /dev/ttysclp0 for S390.
  - Drop patch.patch as now upstream
  - Modify temporary patch patch.patch
    * Use a temporary buffer to be silent during asking passwords
    * Stop system console output during password questions only
    if temporary buffer becomes short

++++ dmidecode:

  - Use %autosetup to work with rpm-4.20 (bsc#1240154)

++++ kernel-default:

  - mptcp: pm: only set fullmesh for subflow endp (CVE-2025-21706 bsc#1238528)
  - commit 3791cc6
  - memcg: drain obj stock on cpu hotplug teardown (bsc#1240336).
  - commit 1dd26e6
  - cgroup/rstat: Fix forceidle time in cpu.stat (bsc#1240335).
  - cgroup/rstat: Tracking cgroup-level niced CPU time
    (bsc#1240335).
  - commit cb11201
  - splice: do not checksum AF_UNIX sockets (bsc#1240333).
  - commit ffdef6b
  - cxl/core/regs: Refactor out functions to count regblocks of
    given type (jsc#PED-10013).
  - cxl/events: Update Memory Module Event Record to CXL spec rev
    3.1 (jsc#PED-10013).
  - cxl/events: Update DRAM Event Record to CXL spec rev 3.1
    (jsc#PED-10013).
  - cxl/events: Update General Media Event Record to CXL spec rev
    3.1 (jsc#PED-10013).
  - cxl/events: Add Component Identifier formatting for CXL spec
    rev 3.1 (jsc#PED-10013).
  - cxl/events: Update Common Event Record to CXL spec rev 3.1
    (jsc#PED-10013).
  - cxl/pci: Add CXL Type 1/2 support to cxl_dvsec_rr_decode()
    (jsc#PED-10013).
  - cxl/pmem: Remove is_cxl_nvdimm_bridge() (jsc#PED-10013).
  - cxl/pmem: Replace match_nvdimm_bridge() with API
    device_match_type() (jsc#PED-10013).
  - commit 0d44ee1
  - cxl/pci: Check dport->regs.rcd_pcie_cap availability before
    accessing (jsc#PED-10013).
  - cxl/region: Refactor common create region code (jsc#PED-10013).
  - cxl/hdm: Use guard() in cxl_dpa_set_mode() (jsc#PED-10013).
  - cxl/pci: Delay event buffer allocation (jsc#PED-10013).
  - cxl/cdat: Use %pra for dpa range outputs (jsc#PED-10013).
  - cxl: downgrade a warning message to debug level in
    cxl_probe_component_regs() (jsc#PED-10013).
  - cxl/pci: Add sysfs attribute for CXL 1.1 device link status
    (jsc#PED-10013).
  - cxl/core/regs: Add rcd_pcie_cap initialization (jsc#PED-10013).
  - commit 4e61860
  - drivers/block/sunvdc.c: update the correct AIP call
    (jsc#PED-9651).
  - loop: don't clear LO_FLAGS_PARTSCAN on LOOP_SET_STATUS{,64}
    (jsc#PED-9651).
  - commit f6c9b2f
  - Reapply "wifi: ath11k: restore country code during resume"
    (bsc#1207948).
  - wifi: ath11k: choose default PM policy for hibernation
    (bsc#1207948).
  - wifi: ath11k: support non-WoWLAN mode suspend as well
    (bsc#1207948).
  - wifi: ath11k: refactor ath11k_core_suspend/_resume()
    (bsc#1207948).
  - wifi: ath11k: introduce ath11k_core_continue_suspend_resume()
    (bsc#1207948).
  - wifi: ath11k: determine PM policy based on machine model
    (bsc#1207948).
  - commit 2b18011
  - tee: optee: Fix supplicant wait loop (CVE-2025-21871
    bsc#1240183).
  - commit e277e7f
  - wifi: mt76: mt7925: fix the wrong link_idx when a p2p_device
    is present (git-fixes).
  - commit c80ad3f
  - soc: samsung: exynos-chipid: Add NULL pointer check in
    exynos_chipid_probe() (git-fixes).
  - soc: mediatek: mt8365-mmsys: Fix routing table masks and values
    (git-fixes).
  - soc: mediatek: mt8167-mmsys: Fix missing regval in all entries
    (git-fixes).
  - soc: mediatek: mtk-mmsys: Fix MT8188 VDO1 DPI1 output selection
    (git-fixes).
  - wifi: mt76: mt7925: remove unused acpi function for clc
    (git-fixes).
  - wifi: mt76: mt7925: fix the wrong simultaneous cap for MLO
    (git-fixes).
  - wifi: mt76: mt7921: fix kernel panic due to null pointer
    dereference (git-fixes).
  - wifi: mt76: Add check for devm_kstrdup() (git-fixes).
  - wifi: mt76: mt7925: fix country count limitation for CLC
    (git-fixes).
  - wifi: mt76: mt7925: ensure wow pattern command align fw format
    (git-fixes).
  - wifi: mt76: mt7915: fix possible integer overflows in
    mt7915_muru_stats_show() (git-fixes).
  - wifi: rtw89: pci: correct ISR RDU bit for 8922AE (git-fixes).
  - wifi: rtw89: fw: correct debug message format in
    rtw89_build_txpwr_trk_tbl_from_elm() (git-fixes).
  - wifi: rtw89: rtw8852b{t}: fix TSSI debug timestamps (git-fixes).
  - wifi: mwifiex: Fix RF calibration data download from file
    (git-fixes).
  - wifi: mwifiex: Fix premature release of RF calibration data
    (git-fixes).
  - wifi: cfg80211: init wiphy_work before allocating rfkill fails
    (git-fixes).
  - wifi: mac80211: check basic rates validity in
    sta_link_apply_parameters (git-fixes).
  - wifi: ath12k: Clear affinity hint before calling
    ath12k_pci_free_irq() in error path (git-fixes).
  - wifi: ath11k: Clear affinity hint before calling
    ath11k_pcic_free_irq() in error path (git-fixes).
  - wifi: ath12k: Add missing htt_metadata flag in ath12k_dp_tx()
    (git-fixes).
  - wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor
    mode (git-fixes).
  - wifi: ath11k: fix RCU stall while reaping monitor destination
    ring (git-fixes).
  - wifi: ath11k: update channel list in reg notifier instead reg
    worker (git-fixes).
  - wifi: ath11k: fix wrong overriding for VHT Beamformee STS
    Capability (git-fixes).
  - wifi: ath9k: do not submit zero bytes to the entropy pool
    (git-fixes).
  - wifi: ath12k: encode max Tx power in scan channel list command
    (git-fixes).
  - wifi: ath12k: fix skb_ext_desc leak in ath12k_dp_tx() error path
    (git-fixes).
  - wifi: mac80211: fix integer overflow in hwmp_route_info_get()
    (git-fixes).
  - wifi: rtw89: Correct immediate cfg_len calculation for
    scan_offload_be (git-fixes).
  - commit 413a548
  - kunit: qemu_configs: sparc: use Zilog console (git-fixes).
  - bus: qcom-ssc-block-bus: Fix the error handling path of
    qcom_ssc_block_bus_probe() (git-fixes).
  - bus: qcom-ssc-block-bus: Remove some duplicated iounmap()
    calls (git-fixes).
  - memory: mtk-smi: Add ostd setting for mt8192 (git-fixes).
  - firmware: arm_scmi: use ioread64() instead of ioread64_hi_lo()
    (git-fixes).
  - firmware: arm_ffa: Skip the first/partition ID when parsing
    vCPU list (git-fixes).
  - firmware: arm_ffa: Explicitly cast return value from
    NOTIFICATION_INFO_GET (git-fixes).
  - firmware: arm_ffa: Explicitly cast return value from FFA_VERSION
    before comparison (git-fixes).
  - ax25: Remove broken autobind (git-fixes).
  - Bluetooth: btnxpuart: Fix kernel panic during FW release
    (git-fixes).
  - Bluetooth: HCI: Add definition of hci_rp_remote_name_req_cancel
    (git-fixes).
  - Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO
    (git-fixes).
  - broadcom: fix supported flag check in periodic output function
    (git-fixes).
  - can: rockchip_canfd: rkcanfd_chip_fifo_setup(): remove
    duplicated setup of RX FIFO (git-fixes).
  - ata: libata: Fix NCQ Non-Data log not supported print
    (git-fixes).
  - clocksource/drivers/stm32-lptimer: Use wakeup capable instead
    of init wakeup (git-fixes).
  - mtd: nand: Fix a kdoc comment (git-fixes).
  - mtd: rawnand: brcmnand: fix PM resume warning (git-fixes).
  - mtd: Add check for devm_kcalloc() (git-fixes).
  - mtd: Replace kcalloc() with devm_kcalloc() (git-fixes).
  - HID: Enable playstation driver independently of sony driver
    (git-fixes).
  - HID: remove superfluous (and wrong) Makefile entry for
    CONFIG_INTEL_ISH_FIRMWARE_DOWNLOADER (git-fixes).
  - platform/x86: dell-ddv: Fix temperature calculation (git-fixes).
  - platform/x86: dell-uart-backlight: Make
    dell_uart_bl_serdev_driver static (git-fixes).
  - platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: Make
    symbol static (git-fixes).
  - commit ff0de4a
  - ALSA: hda/realtek: Fix built-in mic assignment on ASUS VivoBook
    X515UA (git-fixes).
  - ASoC: codecs: wcd937x: fix a potential memory leak in
    wcd937x_soc_codec_probe() (git-fixes).
  - ASoC: amd: acp: Fix for enabling DMIC on acp platforms via
    _DSD entry (git-fixes).
  - ASoC: cs35l41: check the return value from spi_setup()
    (git-fixes).
  - ALSA: timer: Don't take register_mutex with copy_from/to_user()
    (git-fixes).
  - ASoC: ti: j721e-evm: Fix clock configuration for
    ti,j7200-cpb-audio compatible (git-fixes).
  - ALSA: usb-audio: separate DJM-A9 cap lvl options (git-fixes).
  - ALSA: hda/realtek: Always honor no_shutup_pins (git-fixes).
  - ALSA: pcm: Drop superfluous NULL check in
    snd_pcm_format_set_silence() (git-fixes).
  - commit 4fd931a
  - btrfs: zoned: calculate max_extent_size properly on non-zoned
    setup (jsc#PED-9651).
  - arm64: patching: avoid early page_to_phys() (jsc#PED-9651).
  - block: make struct rq_list available for !CONFIG_BLOCK
    (jsc#PED-9651).
  - btrfs: validate queue limits (jsc#PED-9651).
  - commit 587ec60
  - series.conf: move patches to sorted section (jsc#PED-9561)
  - commit eb6beb7
  - KVM: PPC: Enable CAP_SPAPR_TCE_VFIO on pSeries KVM guests
    (jsc#PED-10539 git-fixes).
  - commit f5abb5d
  - block: add support for partition table defined in OF
    (jsc#PED-9651).
  - Update config files.
  - commit 842f5a7

++++ kernel-rt:

  - mptcp: pm: only set fullmesh for subflow endp (CVE-2025-21706 bsc#1238528)
  - commit 3791cc6
  - memcg: drain obj stock on cpu hotplug teardown (bsc#1240336).
  - commit 1dd26e6
  - cgroup/rstat: Fix forceidle time in cpu.stat (bsc#1240335).
  - cgroup/rstat: Tracking cgroup-level niced CPU time
    (bsc#1240335).
  - commit cb11201
  - splice: do not checksum AF_UNIX sockets (bsc#1240333).
  - commit ffdef6b
  - cxl/core/regs: Refactor out functions to count regblocks of
    given type (jsc#PED-10013).
  - cxl/events: Update Memory Module Event Record to CXL spec rev
    3.1 (jsc#PED-10013).
  - cxl/events: Update DRAM Event Record to CXL spec rev 3.1
    (jsc#PED-10013).
  - cxl/events: Update General Media Event Record to CXL spec rev
    3.1 (jsc#PED-10013).
  - cxl/events: Add Component Identifier formatting for CXL spec
    rev 3.1 (jsc#PED-10013).
  - cxl/events: Update Common Event Record to CXL spec rev 3.1
    (jsc#PED-10013).
  - cxl/pci: Add CXL Type 1/2 support to cxl_dvsec_rr_decode()
    (jsc#PED-10013).
  - cxl/pmem: Remove is_cxl_nvdimm_bridge() (jsc#PED-10013).
  - cxl/pmem: Replace match_nvdimm_bridge() with API
    device_match_type() (jsc#PED-10013).
  - commit 0d44ee1
  - cxl/pci: Check dport->regs.rcd_pcie_cap availability before
    accessing (jsc#PED-10013).
  - cxl/region: Refactor common create region code (jsc#PED-10013).
  - cxl/hdm: Use guard() in cxl_dpa_set_mode() (jsc#PED-10013).
  - cxl/pci: Delay event buffer allocation (jsc#PED-10013).
  - cxl/cdat: Use %pra for dpa range outputs (jsc#PED-10013).
  - cxl: downgrade a warning message to debug level in
    cxl_probe_component_regs() (jsc#PED-10013).
  - cxl/pci: Add sysfs attribute for CXL 1.1 device link status
    (jsc#PED-10013).
  - cxl/core/regs: Add rcd_pcie_cap initialization (jsc#PED-10013).
  - commit 4e61860
  - drivers/block/sunvdc.c: update the correct AIP call
    (jsc#PED-9651).
  - loop: don't clear LO_FLAGS_PARTSCAN on LOOP_SET_STATUS{,64}
    (jsc#PED-9651).
  - commit f6c9b2f
  - Reapply "wifi: ath11k: restore country code during resume"
    (bsc#1207948).
  - wifi: ath11k: choose default PM policy for hibernation
    (bsc#1207948).
  - wifi: ath11k: support non-WoWLAN mode suspend as well
    (bsc#1207948).
  - wifi: ath11k: refactor ath11k_core_suspend/_resume()
    (bsc#1207948).
  - wifi: ath11k: introduce ath11k_core_continue_suspend_resume()
    (bsc#1207948).
  - wifi: ath11k: determine PM policy based on machine model
    (bsc#1207948).
  - commit 2b18011
  - tee: optee: Fix supplicant wait loop (CVE-2025-21871
    bsc#1240183).
  - commit e277e7f
  - wifi: mt76: mt7925: fix the wrong link_idx when a p2p_device
    is present (git-fixes).
  - commit c80ad3f
  - soc: samsung: exynos-chipid: Add NULL pointer check in
    exynos_chipid_probe() (git-fixes).
  - soc: mediatek: mt8365-mmsys: Fix routing table masks and values
    (git-fixes).
  - soc: mediatek: mt8167-mmsys: Fix missing regval in all entries
    (git-fixes).
  - soc: mediatek: mtk-mmsys: Fix MT8188 VDO1 DPI1 output selection
    (git-fixes).
  - wifi: mt76: mt7925: remove unused acpi function for clc
    (git-fixes).
  - wifi: mt76: mt7925: fix the wrong simultaneous cap for MLO
    (git-fixes).
  - wifi: mt76: mt7921: fix kernel panic due to null pointer
    dereference (git-fixes).
  - wifi: mt76: Add check for devm_kstrdup() (git-fixes).
  - wifi: mt76: mt7925: fix country count limitation for CLC
    (git-fixes).
  - wifi: mt76: mt7925: ensure wow pattern command align fw format
    (git-fixes).
  - wifi: mt76: mt7915: fix possible integer overflows in
    mt7915_muru_stats_show() (git-fixes).
  - wifi: rtw89: pci: correct ISR RDU bit for 8922AE (git-fixes).
  - wifi: rtw89: fw: correct debug message format in
    rtw89_build_txpwr_trk_tbl_from_elm() (git-fixes).
  - wifi: rtw89: rtw8852b{t}: fix TSSI debug timestamps (git-fixes).
  - wifi: mwifiex: Fix RF calibration data download from file
    (git-fixes).
  - wifi: mwifiex: Fix premature release of RF calibration data
    (git-fixes).
  - wifi: cfg80211: init wiphy_work before allocating rfkill fails
    (git-fixes).
  - wifi: mac80211: check basic rates validity in
    sta_link_apply_parameters (git-fixes).
  - wifi: ath12k: Clear affinity hint before calling
    ath12k_pci_free_irq() in error path (git-fixes).
  - wifi: ath11k: Clear affinity hint before calling
    ath11k_pcic_free_irq() in error path (git-fixes).
  - wifi: ath12k: Add missing htt_metadata flag in ath12k_dp_tx()
    (git-fixes).
  - wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor
    mode (git-fixes).
  - wifi: ath11k: fix RCU stall while reaping monitor destination
    ring (git-fixes).
  - wifi: ath11k: update channel list in reg notifier instead reg
    worker (git-fixes).
  - wifi: ath11k: fix wrong overriding for VHT Beamformee STS
    Capability (git-fixes).
  - wifi: ath9k: do not submit zero bytes to the entropy pool
    (git-fixes).
  - wifi: ath12k: encode max Tx power in scan channel list command
    (git-fixes).
  - wifi: ath12k: fix skb_ext_desc leak in ath12k_dp_tx() error path
    (git-fixes).
  - wifi: mac80211: fix integer overflow in hwmp_route_info_get()
    (git-fixes).
  - wifi: rtw89: Correct immediate cfg_len calculation for
    scan_offload_be (git-fixes).
  - commit 413a548
  - kunit: qemu_configs: sparc: use Zilog console (git-fixes).
  - bus: qcom-ssc-block-bus: Fix the error handling path of
    qcom_ssc_block_bus_probe() (git-fixes).
  - bus: qcom-ssc-block-bus: Remove some duplicated iounmap()
    calls (git-fixes).
  - memory: mtk-smi: Add ostd setting for mt8192 (git-fixes).
  - firmware: arm_scmi: use ioread64() instead of ioread64_hi_lo()
    (git-fixes).
  - firmware: arm_ffa: Skip the first/partition ID when parsing
    vCPU list (git-fixes).
  - firmware: arm_ffa: Explicitly cast return value from
    NOTIFICATION_INFO_GET (git-fixes).
  - firmware: arm_ffa: Explicitly cast return value from FFA_VERSION
    before comparison (git-fixes).
  - ax25: Remove broken autobind (git-fixes).
  - Bluetooth: btnxpuart: Fix kernel panic during FW release
    (git-fixes).
  - Bluetooth: HCI: Add definition of hci_rp_remote_name_req_cancel
    (git-fixes).
  - Bluetooth: hci_core: Enable buffer flow control for SCO/eSCO
    (git-fixes).
  - broadcom: fix supported flag check in periodic output function
    (git-fixes).
  - can: rockchip_canfd: rkcanfd_chip_fifo_setup(): remove
    duplicated setup of RX FIFO (git-fixes).
  - ata: libata: Fix NCQ Non-Data log not supported print
    (git-fixes).
  - clocksource/drivers/stm32-lptimer: Use wakeup capable instead
    of init wakeup (git-fixes).
  - mtd: nand: Fix a kdoc comment (git-fixes).
  - mtd: rawnand: brcmnand: fix PM resume warning (git-fixes).
  - mtd: Add check for devm_kcalloc() (git-fixes).
  - mtd: Replace kcalloc() with devm_kcalloc() (git-fixes).
  - HID: Enable playstation driver independently of sony driver
    (git-fixes).
  - HID: remove superfluous (and wrong) Makefile entry for
    CONFIG_INTEL_ISH_FIRMWARE_DOWNLOADER (git-fixes).
  - platform/x86: dell-ddv: Fix temperature calculation (git-fixes).
  - platform/x86: dell-uart-backlight: Make
    dell_uart_bl_serdev_driver static (git-fixes).
  - platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: Make
    symbol static (git-fixes).
  - commit ff0de4a
  - ALSA: hda/realtek: Fix built-in mic assignment on ASUS VivoBook
    X515UA (git-fixes).
  - ASoC: codecs: wcd937x: fix a potential memory leak in
    wcd937x_soc_codec_probe() (git-fixes).
  - ASoC: amd: acp: Fix for enabling DMIC on acp platforms via
    _DSD entry (git-fixes).
  - ASoC: cs35l41: check the return value from spi_setup()
    (git-fixes).
  - ALSA: timer: Don't take register_mutex with copy_from/to_user()
    (git-fixes).
  - ASoC: ti: j721e-evm: Fix clock configuration for
    ti,j7200-cpb-audio compatible (git-fixes).
  - ALSA: usb-audio: separate DJM-A9 cap lvl options (git-fixes).
  - ALSA: hda/realtek: Always honor no_shutup_pins (git-fixes).
  - ALSA: pcm: Drop superfluous NULL check in
    snd_pcm_format_set_silence() (git-fixes).
  - commit 4fd931a
  - btrfs: zoned: calculate max_extent_size properly on non-zoned
    setup (jsc#PED-9651).
  - arm64: patching: avoid early page_to_phys() (jsc#PED-9651).
  - block: make struct rq_list available for !CONFIG_BLOCK
    (jsc#PED-9651).
  - btrfs: validate queue limits (jsc#PED-9651).
  - commit 587ec60
  - series.conf: move patches to sorted section (jsc#PED-9561)
  - commit eb6beb7
  - KVM: PPC: Enable CAP_SPAPR_TCE_VFIO on pSeries KVM guests
    (jsc#PED-10539 git-fixes).
  - commit f5abb5d
  - block: add support for partition table defined in OF
    (jsc#PED-9651).
  - Update config files.
  - commit 842f5a7

++++ kmod:

  - Update to release 34.2
    * libkmod: fix buffer-overflow in weakdep_to_char
  - Delete unused 0001-build-resolve-build-failure-due-to-missing-include.patch

++++ gcc15:

  - Update to GCC trunk head, 15.0.1+git9001
    * includes -msplit-patch-nops required for user-space livepatching
    on powerpc
    * includes fix for Ada build with --enable-host-pie
  - Adjust for removed avx10_2roundingintrin.h intrinsic header.
  - Build GCC executables PIE on SLE.  [bsc#1239938]

++++ expat:

  - version update to 2.7.1
    Bug fixes:
    [#980] #989  Restore event pointer behavior from Expat 2.6.4
    (that the fix to CVE-2024-8176 changed in 2.7.0);
    affected API functions are:
  - XML_GetCurrentByteCount
  - XML_GetCurrentByteIndex
  - XML_GetCurrentColumnNumber
  - XML_GetCurrentLineNumber
  - XML_GetInputContext
    Other changes:
    [#976] #977  Autotools: Integrate files "fuzz/xml_lpm_fuzzer.{cpp,proto}"
    with Automake that were missing from 2.7.0 release tarballs
    [#983] #984  Fix printf format specifiers for 32bit Emscripten
    [#992]  docs: Promote OpenSSF Best Practices self-certification
    [#978]  tests/benchmark: Resolve mistaken double close
    [#986]  Address compiler warnings
    [#990] #993  Version info bumped from 11:1:10 (libexpat*.so.1.10.1)
    to 11:2:10 (libexpat*.so.1.10.2); see https://verbump.de/
    for what these numbers do
    Infrastructure:
    [#982]  CI: Start running Perl XML::Parser integration tests
    [#987]  CI: Enforce Clang Static Analyzer clean code
    [#991]  CI: Re-enable warning clang-analyzer-valist.Uninitialized
    for clang-tidy
    [#981]  CI: Cover compilation with musl
    [#983] #984  CI: Cover compilation with 32bit Emscripten
    [#976] #977  CI: Protect against fuzzer files missing from future
    release archives

++++ libxml2:

  - Update to version 2.13.7:
    + Regressions:
  - tree: Fix xmlTextMerge with NULL args
  - io: Fix `compressed` flag for uncompressed stdin
  - parser: Fix parsing of DTD content

++++ zlib:

  - Use %autopatch to work with rpm-4.20 (bsc#1240154)

++++ linux-glibc-devel:

  - Use %patch -P N instead of deprecated %patchN. (bsc#1240154)

++++ osinfo-db:

  - bsc#1240121 - [SLEMicro6.2] osinfo-db: Add support for slem6.2 to
    the database
    add-slem6.2-support.patch
  - bsc#1240338 - virt-manager: Windows Server 2025 is not
    automatically detected and missing from manual selection
    add-Windows-Server-2025.patch

++++ libxml2-python:

  - Update to version 2.13.7:
    + Regressions:
  - tree: Fix xmlTextMerge with NULL args
  - io: Fix `compressed` flag for uncompressed stdin
  - parser: Fix parsing of DTD content

++++ rpm-config-SUSE:

  - Update to version 20250328:
    * Revert "Define %jobs as variable (boo#1237231)"
    * Create the directory for rpm macros installation in install

++++ rsync:

  - Add rsync341-gcc15-bool.patch to fix gcc15 compile time error

------------------------------------------------------------------
------------------  2025-3-27  -  Mar 27 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - Add temporary patch named patch.patch
    * Stop system console output during password questions
    * Do coloring on /dev/ttysclp0

++++ crypto-policies:

  - Relax the nss version requirement since the mlkem768secp256r1
    enablement has been reverted.

++++ dialog:

  - Use %autosetup to work with rpm-4.20 (bsc#1240154)

++++ grub2:

  - Fix grub-bls has broken builtin theme for SLE (bsc#1240090)

++++ kernel-default:

  - ipv6: mcast: extend RCU protection in igmp6_send()
    (CVE-2025-21759 bsc#1238738).
  - commit d7804c2
  - ndisc: extend RCU protection in ndisc_send_skb() (CVE-2025-21760
    bsc#1238763).
  - commit 42e3dd1
  - vrf: use RCU protection in l3mdev_l3_out() (CVE-2025-21791
    bsc#1238512).
  - commit e9d9d17
  - openvswitch: use RCU protection in ovs_vport_cmd_fill_info()
    (CVE-2025-21761 bsc#1238775).
  - commit 78199de
  - arp: use RCU protection in arp_xmit() (CVE-2025-21762
    bsc#1238780).
  - commit 61a327a
  - ndisc: use RCU protection in ndisc_alloc_skb() (CVE-2025-21764
    bsc#1237885).
  - commit 71b670d
  - ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu()
    (bsc#1239994).
  - commit eb3adeb
  - ipv6: Use RCU in ip6_input() (bsc#1239994).
  - commit c9a38e6
  - ipv6: icmp: convert to dev_net_rcu() (bsc#1239994).
  - commit 68b80e3
  - ipv6: use RCU protection in ip6_default_advmss() (CVE-2025-21765
    bsc#1237906).
  - commit 67b2d6d
  - flow_dissector: use RCU protection to fetch dev_net()
    (bsc#1239994).
  - commit bacdd89
  - ipv4: icmp: convert to dev_net_rcu() (bsc#1239994).
  - commit 7b71f37
  - ipv4: use RCU protection in __ip_rt_update_pmtu()
    (CVE-2025-21766 bsc#1238754).
  - commit 370b0fb
  - ipv4: use RCU protection in inet_select_addr() (bsc#1239994).
  - commit cb28364
  - ipv4: use RCU protection in rt_is_expired() (bsc#1239994).
  - commit 113e926
  - ipv4: use RCU protection in ipv4_default_advmss() (bsc#1239994).
  - commit e699546
  - ipv4: use RCU protection in ip_dst_mtu_maybe_forward()
    (bsc#1239994).
  - commit 60c5596
  - ipv4: add RCU protection to ip4_dst_hoplimit() (bsc#1239994).
  - commit c9e4bc0
  - udp: Deal with race between UDP socket address change and rehash
    (CVE-2024-57974 bsc#1238532).
  - commit 4eccbe0
  - Patches moving to mainline causing merge conflicts.
  - Refresh
    patches.suse/scsi-lpfc-Copyright-updates-for-14.4.0.8-patches.patch.
  - Refresh
    patches.suse/scsi-lpfc-Free-phba-irq-in-lpfc_sli4_enable_msi-when.patch.
  - Refresh
    patches.suse/scsi-lpfc-Handle-duplicate-D_IDs-in-ndlp-search-by-D.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ignore-ndlp-rport-mismatch-in-dev_loss_tmo.patch.
  - Refresh
    patches.suse/scsi-lpfc-Reduce-log-message-generation-during-ELS-r.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.8.patch.
  - commit 7e994f0
  - Bluetooth: L2CAP: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: SMP: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: MGMT: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: hci_vhci: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: SCO: fix sco_conn refcounting on sco_conn_ready
    (jsc#PED-12286).
  - bluetooth: mgmt: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: SCO: remove the redundant sco_conn_put
    (jsc#PED-12286).
  - Bluetooth: MGMT: Add initial implementation of
    MGMT_OP_HCI_CMD_SYNC (jsc#PED-12286).
  - commit 352ae09
  - Bluetooth: hci_bcm: Use the devm_clk_get_optional() helper
    (jsc#PED-12286).
  - Bluetooth: hci_conn: Remove alloc from critical section
    (jsc#PED-12286).
  - Bluetooth: SCO: Use kref to track lifetime of sco_conn
    (jsc#PED-12286).
  - Bluetooth: HCI: Add IPC(11) bus type (jsc#PED-12286).
  - Bluetooth: ISO: Update hci_conn_hash_lookup_big for Broadcast
    slave (jsc#PED-12286).
  - Bluetooth: ISO: Fix matching parent socket for BIS slave
    (jsc#PED-12286).
  - Bluetooth: btrtl: Decrease HCI_OP_RESET timeout from 10 s to
    2 s (jsc#PED-12286).
  - Bluetooth: btintel_pcie: Replace deprecated PCI functions
    (jsc#PED-12286).
  - Bluetooth: btintel_pcie: remove redundant assignment to variable
    ret (jsc#PED-12286).
  - Bluetooth: btintel_pcie: Remove deadcode (jsc#PED-12286).
  - Bluetooth: hci_qca: use
    devm_clk_get_optional_enabled_with_rate() (jsc#PED-12286).
  - Bluetooth: btintel: Add DSBR support for BlazarIW, BlazarU
    and GaP (jsc#PED-12286).
  - Bluetooth: btmtksdio: Lookup device node only as fallback
    (jsc#PED-12286).
  - Bluetooth: btintel_pcie: Add recovery mechanism (jsc#PED-12286).
  - Bluetooth: hci_core: Fix not checking skb length on
    hci_scodata_packet (jsc#PED-12286).
  - Bluetooth: btnxpuart: Add GPIO support to power save feature
    (jsc#PED-12286).
  - bluetooth: Fix typos in the comments (jsc#PED-12286).
  - Bluetooth: btnxpuart: Rename IW615 to IW610 (jsc#PED-12286).
  - Bluetooth: btnxpuart: Drop _v0 suffix from FW names
    (jsc#PED-12286).
  - Bluetooth: btusb: Add one more ID 0x13d3:0x3623 for Qualcomm
    WCN785x (jsc#PED-12286).
  - Bluetooth: btusb: Add one more ID 0x0489:0xe0f3 for Qualcomm
    WCN785x (jsc#PED-12286).
  - Bluetooth: btusb: add Foxconn 0xe0fc for Qualcomm WCN785x
    (jsc#PED-12286).
  - Bluetooth: add HAS_IOPORT dependencies (jsc#PED-12286).
  - commit 638ded7
  - eth: bnxt: fix out-of-range access of vnic_info array
    (jsc#PED-11923).
  - bnxt_en: Add TPH support in BNXT driver (jsc#PED-11923).
  - bnxt_en: Extend queue stop/start for TX rings (jsc#PED-11923).
  - bnxt_en: Refactor TX ring free logic (jsc#PED-11923).
  - bnxt_en: Reallocate RX completion ring for TPH support
    (jsc#PED-11923).
  - bnxt_en: Pass NQ ID to the FW when allocating RX/RX AGG rings
    (jsc#PED-11923).
  - bnxt_en: Refactor RX/RX AGG ring parameters setup for P5_PLUS
    (jsc#PED-11923).
  - bnxt_en: Refactor bnxt_free_tx_rings() to free per TX ring
    (jsc#PED-11923).
  - bnxt_en: Refactor completion ring free routine (jsc#PED-11923).
  - bnxt_en: Refactor TX ring allocation logic (jsc#PED-11923).
  - bnxt_en: Refactor completion ring allocation logic for P5_PLUS
    chips (jsc#PED-11923).
  - bnxt_en: Set NPAR 1.2 support when registering with firmware
    (jsc#PED-11923).
  - netdev: define NETDEV_INTERNAL (jsc#PED-11923).
  - commit 5d77362
  - ice: health.c: fix compilation on gcc 7.5 (jsc#PED-10419).
  - commit 7e632c2

++++ kernel-firmware-qcom:

  - Update aliases

++++ kernel-rt:

  - ipv6: mcast: extend RCU protection in igmp6_send()
    (CVE-2025-21759 bsc#1238738).
  - commit d7804c2
  - ndisc: extend RCU protection in ndisc_send_skb() (CVE-2025-21760
    bsc#1238763).
  - commit 42e3dd1
  - vrf: use RCU protection in l3mdev_l3_out() (CVE-2025-21791
    bsc#1238512).
  - commit e9d9d17
  - openvswitch: use RCU protection in ovs_vport_cmd_fill_info()
    (CVE-2025-21761 bsc#1238775).
  - commit 78199de
  - arp: use RCU protection in arp_xmit() (CVE-2025-21762
    bsc#1238780).
  - commit 61a327a
  - ndisc: use RCU protection in ndisc_alloc_skb() (CVE-2025-21764
    bsc#1237885).
  - commit 71b670d
  - ndisc: ndisc_send_redirect() must use dev_get_by_index_rcu()
    (bsc#1239994).
  - commit eb3adeb
  - ipv6: Use RCU in ip6_input() (bsc#1239994).
  - commit c9a38e6
  - ipv6: icmp: convert to dev_net_rcu() (bsc#1239994).
  - commit 68b80e3
  - ipv6: use RCU protection in ip6_default_advmss() (CVE-2025-21765
    bsc#1237906).
  - commit 67b2d6d
  - flow_dissector: use RCU protection to fetch dev_net()
    (bsc#1239994).
  - commit bacdd89
  - ipv4: icmp: convert to dev_net_rcu() (bsc#1239994).
  - commit 7b71f37
  - ipv4: use RCU protection in __ip_rt_update_pmtu()
    (CVE-2025-21766 bsc#1238754).
  - commit 370b0fb
  - ipv4: use RCU protection in inet_select_addr() (bsc#1239994).
  - commit cb28364
  - ipv4: use RCU protection in rt_is_expired() (bsc#1239994).
  - commit 113e926
  - ipv4: use RCU protection in ipv4_default_advmss() (bsc#1239994).
  - commit e699546
  - ipv4: use RCU protection in ip_dst_mtu_maybe_forward()
    (bsc#1239994).
  - commit 60c5596
  - ipv4: add RCU protection to ip4_dst_hoplimit() (bsc#1239994).
  - commit c9e4bc0
  - udp: Deal with race between UDP socket address change and rehash
    (CVE-2024-57974 bsc#1238532).
  - commit 4eccbe0
  - Patches moving to mainline causing merge conflicts.
  - Refresh
    patches.suse/scsi-lpfc-Copyright-updates-for-14.4.0.8-patches.patch.
  - Refresh
    patches.suse/scsi-lpfc-Free-phba-irq-in-lpfc_sli4_enable_msi-when.patch.
  - Refresh
    patches.suse/scsi-lpfc-Handle-duplicate-D_IDs-in-ndlp-search-by-D.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ignore-ndlp-rport-mismatch-in-dev_loss_tmo.patch.
  - Refresh
    patches.suse/scsi-lpfc-Reduce-log-message-generation-during-ELS-r.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.8.patch.
  - commit 7e994f0
  - Bluetooth: L2CAP: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: SMP: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: MGMT: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: hci_vhci: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: SCO: fix sco_conn refcounting on sco_conn_ready
    (jsc#PED-12286).
  - bluetooth: mgmt: convert timeouts to secs_to_jiffies()
    (jsc#PED-12286).
  - Bluetooth: SCO: remove the redundant sco_conn_put
    (jsc#PED-12286).
  - Bluetooth: MGMT: Add initial implementation of
    MGMT_OP_HCI_CMD_SYNC (jsc#PED-12286).
  - commit 352ae09
  - Bluetooth: hci_bcm: Use the devm_clk_get_optional() helper
    (jsc#PED-12286).
  - Bluetooth: hci_conn: Remove alloc from critical section
    (jsc#PED-12286).
  - Bluetooth: SCO: Use kref to track lifetime of sco_conn
    (jsc#PED-12286).
  - Bluetooth: HCI: Add IPC(11) bus type (jsc#PED-12286).
  - Bluetooth: ISO: Update hci_conn_hash_lookup_big for Broadcast
    slave (jsc#PED-12286).
  - Bluetooth: ISO: Fix matching parent socket for BIS slave
    (jsc#PED-12286).
  - Bluetooth: btrtl: Decrease HCI_OP_RESET timeout from 10 s to
    2 s (jsc#PED-12286).
  - Bluetooth: btintel_pcie: Replace deprecated PCI functions
    (jsc#PED-12286).
  - Bluetooth: btintel_pcie: remove redundant assignment to variable
    ret (jsc#PED-12286).
  - Bluetooth: btintel_pcie: Remove deadcode (jsc#PED-12286).
  - Bluetooth: hci_qca: use
    devm_clk_get_optional_enabled_with_rate() (jsc#PED-12286).
  - Bluetooth: btintel: Add DSBR support for BlazarIW, BlazarU
    and GaP (jsc#PED-12286).
  - Bluetooth: btmtksdio: Lookup device node only as fallback
    (jsc#PED-12286).
  - Bluetooth: btintel_pcie: Add recovery mechanism (jsc#PED-12286).
  - Bluetooth: hci_core: Fix not checking skb length on
    hci_scodata_packet (jsc#PED-12286).
  - Bluetooth: btnxpuart: Add GPIO support to power save feature
    (jsc#PED-12286).
  - bluetooth: Fix typos in the comments (jsc#PED-12286).
  - Bluetooth: btnxpuart: Rename IW615 to IW610 (jsc#PED-12286).
  - Bluetooth: btnxpuart: Drop _v0 suffix from FW names
    (jsc#PED-12286).
  - Bluetooth: btusb: Add one more ID 0x13d3:0x3623 for Qualcomm
    WCN785x (jsc#PED-12286).
  - Bluetooth: btusb: Add one more ID 0x0489:0xe0f3 for Qualcomm
    WCN785x (jsc#PED-12286).
  - Bluetooth: btusb: add Foxconn 0xe0fc for Qualcomm WCN785x
    (jsc#PED-12286).
  - Bluetooth: add HAS_IOPORT dependencies (jsc#PED-12286).
  - commit 638ded7
  - eth: bnxt: fix out-of-range access of vnic_info array
    (jsc#PED-11923).
  - bnxt_en: Add TPH support in BNXT driver (jsc#PED-11923).
  - bnxt_en: Extend queue stop/start for TX rings (jsc#PED-11923).
  - bnxt_en: Refactor TX ring free logic (jsc#PED-11923).
  - bnxt_en: Reallocate RX completion ring for TPH support
    (jsc#PED-11923).
  - bnxt_en: Pass NQ ID to the FW when allocating RX/RX AGG rings
    (jsc#PED-11923).
  - bnxt_en: Refactor RX/RX AGG ring parameters setup for P5_PLUS
    (jsc#PED-11923).
  - bnxt_en: Refactor bnxt_free_tx_rings() to free per TX ring
    (jsc#PED-11923).
  - bnxt_en: Refactor completion ring free routine (jsc#PED-11923).
  - bnxt_en: Refactor TX ring allocation logic (jsc#PED-11923).
  - bnxt_en: Refactor completion ring allocation logic for P5_PLUS
    chips (jsc#PED-11923).
  - bnxt_en: Set NPAR 1.2 support when registering with firmware
    (jsc#PED-11923).
  - netdev: define NETDEV_INTERNAL (jsc#PED-11923).
  - commit 5d77362
  - ice: health.c: fix compilation on gcc 7.5 (jsc#PED-10419).
  - commit 7e632c2

++++ open-vm-tools:

  - (bsc#1237180): Ensure vmtoolsd.service and vgauthd.service
    are set to enabled by default. Do this by removing vmblock-fuse.service
    from the %pre section in the spec file.  vmblock-fuse.service still
    remains in the %pre desktop section.

++++ podman:

  - Depend on runc unconditionally, not only on SLE 15 (bsc#1239088)

++++ vim:

  - Update to version 9.1.1244:
    * patch 9.1.1244:
  - part of patch v9.1.1242 was wrong
  - runtime(omnimark): update and rewrite syntax script in Vim9
    script
    * patch 9.1.1243: diff mode is lacking for changes within lines
    * patch 9.1.1242: Crash when evaluating variable name
    * patch 9.1.1241: wrong preprocessort indentation in term.c
    * patch 9.1.1240:
  - Regression with ic/ac text objects and comment plugin
  - runtime(hyprlang): save and restore cpo setting in syntax
    script
  - runtime(solidity): update syntax script with error
    definitions
  - runtime(doc): add back help tag "pi_netrw.txt"
    * patch 9.1.1239:
  - if_python: no tuple data type support
  - runtime(doc): Add missing garbagecollect() hypertext link
  - Improve contributing guide by adding a section on signing
    off commits
    * patch 9.1.1238: wrong cursor column with 'set
    splitkeep=screen'
    * patch 9.1.1237: Compile error with C89 compiler in term.c
    * patch 9.1.1236: tests: test_comments leaves swapfiles around
    * patch 9.1.1235: cproto files are outdated
    * patch 9.1.1234: Compile error when SIZE_MAX is not defined
    * patch 9.1.1233:
  - Coverity warns about NULL pointer when triggering WinResized
  - runtime(doc): Fix an omission in the documentation.
    * patch 9.1.1232:
  - Vim script is missing the tuple data type
  - runtime(vim): Update base-syntax, match protected
    constructors
  - runtime(syntax-tests): Do not ignore failed screendumps
    * patch 9.1.1231:
  - filetype: SPA JSON files are not recognized
  - runtime(doc): update and correct str2blob() and blob2str()
    examples
  - runtime(hlyank): update the hlyank package
  - runtime(syntax-tests): Add non-Latin-1 character filters for
    C syntax tests

------------------------------------------------------------------
------------------  2025-3-26  -  Mar 26 2025  -------------------
------------------------------------------------------------------

++++ docker:

  - Don't use the new container-selinux conditional requires on SLE-12, as the
    RPM version there doesn't support it. Arguably the change itself is a bit
    suspect but we can fix that later. bsc#1237367

++++ file:

  - baselibs.conf: drop it

++++ kernel-default:

  - Refresh patches.suse/tpm-send_data-Wait-longer-for-the-TPM-to-become-read.patch.
    Also extend the remaining tpm_tis_send_data timeout (bsc#1235870).
  - commit 382e790
  - af_packet: fix vlan_get_tci() vs MSG_PEEK (CVE-2024-57902
    bsc#1235950).
  - commit fd3162f
  - net: fix memory leak in tcp_conn_request() (CVE-2024-57841
    bsc#1235944).
  - commit cf965e6
  - nvme: core: switch to non_owner variant of start_freeze/unfreeze
    queue (jsc#PED-9651).
  - commit c314272
  - net/smc: check smcd_v2_ext_offset when receiving proposal msg
    (CVE-2024-47408 bsc#1235711).
  - commit 24369ad
  - Delete
    patches.suse/s390-Fix-mlx5-RoCE-throuput-degradtion.patch.
    With commit 1d5024f88dad ("net/mlx5e: Default to Striding RQ when
    not conflicting with CQE compression") added to v5.18-rc5 this
    patch is no longer needed.
  - commit 7f247c8
  - asm-generic: add an optional pfn_valid check to page_to_phys
    (jsc#PED-9651).
  - asm-generic: provide generic page_to_phys and phys_to_page
    (jsc#PED-9651).
  - commit 8762cfe
  - block: use page_to_phys in bvec_phys (jsc#PED-9651).
  - commit 6850cb9
  - block: fix NULL pointer dereferenced within __blk_rq_map_sg
    (jsc#PED-9651).
  - block/merge: remove unnecessary min() with UINT_MAX
    (jsc#PED-9651).
  - commit 41708a1
  - block: force noio scope in blk_mq_freeze_queue (jsc#PED-9651).
  - nbd: fix partial sending (jsc#PED-9651).
  - loop: remove the use_dio field in struct loop_device
    (jsc#PED-9651).
  - loop: don't freeze the queue in loop_update_dio (jsc#PED-9651).
  - loop: allow loop_set_status to re-enable direct I/O
    (jsc#PED-9651).
  - commit 6d37915
  - loop: open code the direct I/O flag update in loop_set_dio
    (jsc#PED-9651).
  - loop: only write back pagecache when starting to to use direct
    I/O (jsc#PED-9651).
  - loop: create a lo_can_use_dio helper (jsc#PED-9651).
  - loop: update commands in loop_set_status still referring to
    transfers (jsc#PED-9651).
  - loop: move updating lo_flags out of loop_set_status_from_info
    (jsc#PED-9651).
  - loop: fix queue freeze vs limits lock order (jsc#PED-9651).
  - loop: refactor queue limits updates (jsc#PED-9651).
  - loop: Fix ABBA locking race (jsc#PED-9651).
  - nvme: use helpers to access io_uring cmd space (jsc#PED-9651).
  - rbd: unfreeze queue after marking disk as dead (jsc#PED-9651).
  - loop: Simplify discard granularity calc (jsc#PED-9651).
  - loop: Use bdev limit helpers for configuring discard
    (jsc#PED-9651).
  - commit a5f9b6f
  - netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()
    (git-fixes CVE-2025-21703 bsc#1237313).
  - commit f9fdeb8
  - net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving
    proposal msg (CVE-2024-49568 bsc#1235728).
  - net/smc: protect link down work from execute after lgr freed
    (CVE-2024-56718 bsc#1235589).
  - net/smc: fix LGR and link use-after-free issue (CVE-2024-56640
    bsc#1235436).
  - drop_monitor: fix incorrect initialization order (CVE-2025-21862
    bsc#1239474).
  - net/sched: cls_api: fix error handling causing NULL dereference
    (CVE-2025-21857 bsc#1239478).
  - netfilter: nf_tables: reject mismatching sum of field_len with
    set key length (CVE-2025-21826 bsc#1238968).
  - rxrpc, afs: Fix peer hash locking vs RCU callback
    (CVE-2025-21809 bsc#1238733).
  - rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
    (CVE-2025-21635 bsc#1236111).
  - netfilter: nf_tables: do not defer rule destruction via call_rcu
    (CVE-2024-56655 bsc#1235446).
  - netfilter: IDLETIMER: Fix for possible ABBA deadlock
    (CVE-2024-54683 bsc#1235729).
  - net/sched: netem: account for backlog updates from child qdisc
    (CVE-2024-56770 bsc#1235637).
  - netlink: fix false positive warning in extack during dumps
    (CVE-2024-53212 bsc#1234972).
  - ipv6: Fix soft lockups in fib6_select_path under high next
    hop churn (CVE-2024-56703 bsc#1235455).
  - ipv6: release nexthop on device removal (CVE-2024-56751
    bsc#1234936).
  - commit fc26e30
  - gpio: 74x164: Remove unneeded dependency to OF_GPIO (git-fixes).
  - Update config files.
  - commit 9b9af75
  - media: vim2m: print device name after registering device
    (git-fixes).
  - media: platform: stm32: Add check for clk_enable() (git-fixes).
  - media: siano: Fix error handling in smsdvb_module_init()
    (git-fixes).
  - media: v4l2-dv-timings: prevent possible overflow in
    v4l2_detect_gtf() (git-fixes).
  - media: rockchip: rga: fix rga offset lookup (git-fixes).
  - media: vimc: skip .s_stream() for stopped entities (git-fixes).
  - media: omap3isp: Handle ARM dma_iommu_mapping (git-fixes).
  - media: intel/ipu6: set the dev_parent of video device to pdev
    (git-fixes).
  - media: venus: hfi: add a check to handle OOB in sfr region
    (git-fixes).
  - media: venus: hfi: add check to handle incorrect queue size
    (git-fixes).
  - media: venus: hfi_parser: refactor hfi packet parsing logic
    (git-fixes).
  - media: venus: hfi_parser: add check to avoid out of bound access
    (git-fixes).
  - media: visl: Fix ERANGE error when setting enum controls
    (git-fixes).
  - media: nuvoton: Fix reference handling of ece_pdev (git-fixes).
  - media: nuvoton: Fix reference handling of ece_node (git-fixes).
  - media: mgb4: Fix switched CMT frequency range "magic values"
    sets (git-fixes).
  - media: mgb4: Fix CMT registers update logic (git-fixes).
  - media: platform: allgro-dvt: unregister v4l2_device on the
    error path (git-fixes).
  - media: verisilicon: HEVC: Initialize start_bit field
    (git-fixes).
  - media: i2c: adv748x: Fix test pattern selection mask
    (git-fixes).
  - media: mediatek: vcodec: Fix a resource leak related to the
    scp device in FW initialization (git-fixes).
  - media: uapi: rkisp1-config: Fix typo in extensible params
    example (git-fixes).
  - media: mtk-vcodec: venc: avoid -Wenum-compare-conditional
    warning (git-fixes).
  - media: imx219: Adjust PLL settings based on the number of MIPI
    lanes (git-fixes).
  - media: i2c: ov7251: Introduce 1 ms delay between regulators
    and en GPIO (git-fixes).
  - media: i2c: ov7251: Set enable GPIO low in probe (git-fixes).
  - media: i2c: imx319: Rectify runtime PM handling probe and remove
    (git-fixes).
  - media: i2c: imx219: Rectify runtime PM handling in probe and
    remove (git-fixes).
  - media: i2c: ccs: Set the device's runtime PM status correctly
    in probe (git-fixes).
  - media: i2c: ccs: Set the device's runtime PM status correctly
    in remove (git-fixes).
  - media: i2c: imx214: Rectify probe error handling related to
    runtime PM (git-fixes).
  - Revert "media: imx214: Fix the error handling in imx214_probe()"
    (git-fixes).
  - media: hi556: Fix memory leak (on error) in hi556_check_hwcfg()
    (git-fixes).
  - media: chips-media: wave5: Fix timeout while testing 10bit
    hevc fluster (git-fixes).
  - media: chips-media: wave5: Fix a hang after seeking (git-fixes).
  - media: chips-media: wave5: Avoid race condition in the interrupt
    handler (git-fixes).
  - media: chips-media: wave5: Fix gray color on screen (git-fixes).
  - media: streamzap: prevent processing IR data on URB failure
    (git-fixes).
  - media: streamzap: fix race between device disconnection and
    urb callback (git-fixes).
  - auxdisplay: panel: Fix an API misuse in panel.c (git-fixes).
  - auxdisplay: hd44780: Fix an API misuse in hd44780.c (git-fixes).
  - auxdisplay: MAX6959 should select BITREVERSE (git-fixes).
  - mmc: omap: Fix memory leak in mmc_omap_new_slot (git-fixes).
  - memstick: rtsx_usb_ms: Fix slab-use-after-free in
    rtsx_usb_ms_drv_remove (git-fixes).
  - mmc: sdhci-omap: Disable MMC_CAP_AGGRESSIVE_PM for eMMC/SD
    (git-fixes).
  - spi: cadence-qspi: Fix probe on AM62A LP SK (git-fixes).
  - regulator: pca9450: Fix enable register for LDO5 (git-fixes).
  - thermal: int340x: Add NULL check for adev (git-fixes).
  - PM: sleep: Fix handling devices with direct_complete set on
    errors (git-fixes).
  - PM: sleep: Adjust check before setting power.must_resume
    (git-fixes).
  - selftests/x86/syscall: Fix coccinelle WARNING recommending
    the use of ARRAY_SIZE() (git-fixes).
  - commit 5906346
  - dlm: make tcp still work in multi-link env (jsc#PED-11932).
  - dlm: increase max number of links for corosync3/knet
    (jsc#PED-11932).
  - commit 973d3b7

++++ kernel-rt:

  - Refresh patches.suse/tpm-send_data-Wait-longer-for-the-TPM-to-become-read.patch.
    Also extend the remaining tpm_tis_send_data timeout (bsc#1235870).
  - commit 382e790
  - af_packet: fix vlan_get_tci() vs MSG_PEEK (CVE-2024-57902
    bsc#1235950).
  - commit fd3162f
  - net: fix memory leak in tcp_conn_request() (CVE-2024-57841
    bsc#1235944).
  - commit cf965e6
  - nvme: core: switch to non_owner variant of start_freeze/unfreeze
    queue (jsc#PED-9651).
  - commit c314272
  - net/smc: check smcd_v2_ext_offset when receiving proposal msg
    (CVE-2024-47408 bsc#1235711).
  - commit 24369ad
  - Delete
    patches.suse/s390-Fix-mlx5-RoCE-throuput-degradtion.patch.
    With commit 1d5024f88dad ("net/mlx5e: Default to Striding RQ when
    not conflicting with CQE compression") added to v5.18-rc5 this
    patch is no longer needed.
  - commit 7f247c8
  - asm-generic: add an optional pfn_valid check to page_to_phys
    (jsc#PED-9651).
  - asm-generic: provide generic page_to_phys and phys_to_page
    (jsc#PED-9651).
  - commit 8762cfe
  - block: use page_to_phys in bvec_phys (jsc#PED-9651).
  - commit 6850cb9
  - block: fix NULL pointer dereferenced within __blk_rq_map_sg
    (jsc#PED-9651).
  - block/merge: remove unnecessary min() with UINT_MAX
    (jsc#PED-9651).
  - commit 41708a1
  - block: force noio scope in blk_mq_freeze_queue (jsc#PED-9651).
  - nbd: fix partial sending (jsc#PED-9651).
  - loop: remove the use_dio field in struct loop_device
    (jsc#PED-9651).
  - loop: don't freeze the queue in loop_update_dio (jsc#PED-9651).
  - loop: allow loop_set_status to re-enable direct I/O
    (jsc#PED-9651).
  - commit 6d37915
  - loop: open code the direct I/O flag update in loop_set_dio
    (jsc#PED-9651).
  - loop: only write back pagecache when starting to to use direct
    I/O (jsc#PED-9651).
  - loop: create a lo_can_use_dio helper (jsc#PED-9651).
  - loop: update commands in loop_set_status still referring to
    transfers (jsc#PED-9651).
  - loop: move updating lo_flags out of loop_set_status_from_info
    (jsc#PED-9651).
  - loop: fix queue freeze vs limits lock order (jsc#PED-9651).
  - loop: refactor queue limits updates (jsc#PED-9651).
  - loop: Fix ABBA locking race (jsc#PED-9651).
  - nvme: use helpers to access io_uring cmd space (jsc#PED-9651).
  - rbd: unfreeze queue after marking disk as dead (jsc#PED-9651).
  - loop: Simplify discard granularity calc (jsc#PED-9651).
  - loop: Use bdev limit helpers for configuring discard
    (jsc#PED-9651).
  - commit a5f9b6f
  - netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()
    (git-fixes CVE-2025-21703 bsc#1237313).
  - commit f9fdeb8
  - net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving
    proposal msg (CVE-2024-49568 bsc#1235728).
  - net/smc: protect link down work from execute after lgr freed
    (CVE-2024-56718 bsc#1235589).
  - net/smc: fix LGR and link use-after-free issue (CVE-2024-56640
    bsc#1235436).
  - drop_monitor: fix incorrect initialization order (CVE-2025-21862
    bsc#1239474).
  - net/sched: cls_api: fix error handling causing NULL dereference
    (CVE-2025-21857 bsc#1239478).
  - netfilter: nf_tables: reject mismatching sum of field_len with
    set key length (CVE-2025-21826 bsc#1238968).
  - rxrpc, afs: Fix peer hash locking vs RCU callback
    (CVE-2025-21809 bsc#1238733).
  - rds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
    (CVE-2025-21635 bsc#1236111).
  - netfilter: nf_tables: do not defer rule destruction via call_rcu
    (CVE-2024-56655 bsc#1235446).
  - netfilter: IDLETIMER: Fix for possible ABBA deadlock
    (CVE-2024-54683 bsc#1235729).
  - net/sched: netem: account for backlog updates from child qdisc
    (CVE-2024-56770 bsc#1235637).
  - netlink: fix false positive warning in extack during dumps
    (CVE-2024-53212 bsc#1234972).
  - ipv6: Fix soft lockups in fib6_select_path under high next
    hop churn (CVE-2024-56703 bsc#1235455).
  - ipv6: release nexthop on device removal (CVE-2024-56751
    bsc#1234936).
  - commit fc26e30
  - gpio: 74x164: Remove unneeded dependency to OF_GPIO (git-fixes).
  - Update config files.
  - commit 9b9af75
  - media: vim2m: print device name after registering device
    (git-fixes).
  - media: platform: stm32: Add check for clk_enable() (git-fixes).
  - media: siano: Fix error handling in smsdvb_module_init()
    (git-fixes).
  - media: v4l2-dv-timings: prevent possible overflow in
    v4l2_detect_gtf() (git-fixes).
  - media: rockchip: rga: fix rga offset lookup (git-fixes).
  - media: vimc: skip .s_stream() for stopped entities (git-fixes).
  - media: omap3isp: Handle ARM dma_iommu_mapping (git-fixes).
  - media: intel/ipu6: set the dev_parent of video device to pdev
    (git-fixes).
  - media: venus: hfi: add a check to handle OOB in sfr region
    (git-fixes).
  - media: venus: hfi: add check to handle incorrect queue size
    (git-fixes).
  - media: venus: hfi_parser: refactor hfi packet parsing logic
    (git-fixes).
  - media: venus: hfi_parser: add check to avoid out of bound access
    (git-fixes).
  - media: visl: Fix ERANGE error when setting enum controls
    (git-fixes).
  - media: nuvoton: Fix reference handling of ece_pdev (git-fixes).
  - media: nuvoton: Fix reference handling of ece_node (git-fixes).
  - media: mgb4: Fix switched CMT frequency range "magic values"
    sets (git-fixes).
  - media: mgb4: Fix CMT registers update logic (git-fixes).
  - media: platform: allgro-dvt: unregister v4l2_device on the
    error path (git-fixes).
  - media: verisilicon: HEVC: Initialize start_bit field
    (git-fixes).
  - media: i2c: adv748x: Fix test pattern selection mask
    (git-fixes).
  - media: mediatek: vcodec: Fix a resource leak related to the
    scp device in FW initialization (git-fixes).
  - media: uapi: rkisp1-config: Fix typo in extensible params
    example (git-fixes).
  - media: mtk-vcodec: venc: avoid -Wenum-compare-conditional
    warning (git-fixes).
  - media: imx219: Adjust PLL settings based on the number of MIPI
    lanes (git-fixes).
  - media: i2c: ov7251: Introduce 1 ms delay between regulators
    and en GPIO (git-fixes).
  - media: i2c: ov7251: Set enable GPIO low in probe (git-fixes).
  - media: i2c: imx319: Rectify runtime PM handling probe and remove
    (git-fixes).
  - media: i2c: imx219: Rectify runtime PM handling in probe and
    remove (git-fixes).
  - media: i2c: ccs: Set the device's runtime PM status correctly
    in probe (git-fixes).
  - media: i2c: ccs: Set the device's runtime PM status correctly
    in remove (git-fixes).
  - media: i2c: imx214: Rectify probe error handling related to
    runtime PM (git-fixes).
  - Revert "media: imx214: Fix the error handling in imx214_probe()"
    (git-fixes).
  - media: hi556: Fix memory leak (on error) in hi556_check_hwcfg()
    (git-fixes).
  - media: chips-media: wave5: Fix timeout while testing 10bit
    hevc fluster (git-fixes).
  - media: chips-media: wave5: Fix a hang after seeking (git-fixes).
  - media: chips-media: wave5: Avoid race condition in the interrupt
    handler (git-fixes).
  - media: chips-media: wave5: Fix gray color on screen (git-fixes).
  - media: streamzap: prevent processing IR data on URB failure
    (git-fixes).
  - media: streamzap: fix race between device disconnection and
    urb callback (git-fixes).
  - auxdisplay: panel: Fix an API misuse in panel.c (git-fixes).
  - auxdisplay: hd44780: Fix an API misuse in hd44780.c (git-fixes).
  - auxdisplay: MAX6959 should select BITREVERSE (git-fixes).
  - mmc: omap: Fix memory leak in mmc_omap_new_slot (git-fixes).
  - memstick: rtsx_usb_ms: Fix slab-use-after-free in
    rtsx_usb_ms_drv_remove (git-fixes).
  - mmc: sdhci-omap: Disable MMC_CAP_AGGRESSIVE_PM for eMMC/SD
    (git-fixes).
  - spi: cadence-qspi: Fix probe on AM62A LP SK (git-fixes).
  - regulator: pca9450: Fix enable register for LDO5 (git-fixes).
  - thermal: int340x: Add NULL check for adev (git-fixes).
  - PM: sleep: Fix handling devices with direct_complete set on
    errors (git-fixes).
  - PM: sleep: Adjust check before setting power.must_resume
    (git-fixes).
  - selftests/x86/syscall: Fix coccinelle WARNING recommending
    the use of ARRAY_SIZE() (git-fixes).
  - commit 5906346
  - dlm: make tcp still work in multi-link env (jsc#PED-11932).
  - dlm: increase max number of links for corosync3/knet
    (jsc#PED-11932).
  - commit 973d3b7

++++ rpm:

  - Backport check_c_compiler_flag cmake tests fix from upstream
    The old code would pick up -fhardened by accident
    * new patch: cmake_fhardened.diff

++++ tpm2.0-abrmd:

  - also enable SELinux features for SLE-16 (bsc#1240070). On SLE-16 abrmd does
    not work, because the SELinux configuration is missing and thus its
    operations are denied. Include SLE-16 to fix this.

++++ tuned:

  - Add BuildRequires:
    * gobject-introspection-devel for test in check section to succeed
    * pyinotify in ppd

------------------------------------------------------------------
------------------  2025-3-25  -  Mar 25 2025  -------------------
------------------------------------------------------------------

++++ ca-certificates-mozilla:

  - Fix awk to compare (missing a =) and give the following output:
    [#] NSS_BUILTINS_LIBRARY_VERSION "2.74"
  - pass file argument to awk (bsc#1240009)

++++ docker:

  - Add backport for golang.org/x/oauth2 CVE-2025-22868 fix. bsc#1239185
    + 0006-CVE-2025-22868-vendor-jws-split-token-into-fixed-num.patch
  - Add backport for golang.org/x/crypto CVE-2025-22869 fix. bsc#1239322
    + 0007-CVE-2025-22869-vendor-ssh-limit-the-size-of-the-inte.patch
  - Refresh patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch

++++ python-kiwi:

  - Bump version: 10.2.15 → 10.2.16
  - Support sourcetype setting on the commandline
    Allow to specifiy the sourcetype(metalink|baseurl|mirrorlist)
    also on the commandline via --set-repo/--add-repo options. So
    far this was only possible as part of the kiwi description file
  - Bump version: 10.2.14 → 10.2.15
  - Fix gh-pages deployment
    poetry install was not called, thus sphinx was not present
  - Bump version: 10.2.13 → 10.2.14

++++ fwupd:

  - Update to version 2.0.7:
    + This release adds the following features:
  - Allow calling 'fwupdtool security' with a fwupd version parameter
  - A new plugin to update B&R DisplayPort receivers
  - A new plugin to update Intel CVS cameras
  - A new plugin to verify UEFI memory protection attributes
  - A new quirk to signify that no additional ESP space is required
  - Build additional Redfish instance IDs for Dell server hardware
  - Implement the HPE proprietary Redfish firmware push method
  - Support cabinet archives greater in size than 2GB
  - Support for showing the SBOM release URL
  - Support for UEFI capsule installation in the bootloader
    + This release fixes the following bugs:
  - Always close USB file descriptors after starting the daemon
  - Do not add a Redfish release date if set to 00:00:00Z
  - Fix a critical warning when rescanning a device with no GUIDs
  - Fix a small memory leak when emumerating Logitech Rallysystem devices
  - Fix a tiny Redfish memory leak when writing firmware
  - Fix building against pygobject 3.52
  - Fix Logitech BulkController setup for new device firmware versions
  - Fix scaler-only Wacom USB update deployment
  - Fix updating the RMM component in the dell-kestrel dock
  - Fix writing new EFI variables to workaround a kernel regression
  - Make PCI NAME and SSVID_SSPID based modem-manager IDs visible
  - Parse firmware before putting the device into bootloader mode
  - Prepend the capsule header when using Capsule-on-Disk
  - Put a memory limit on decoding LZMA streams when parsing firmware
  - Retry claiming the fastboot interface for up to 2500ms
  - Trigger dpaux rescan on drm changes correctly
  - Use the metadata version format to set the version_lowest when required
    + This release adds support for the following hardware:
  - Another HP wireless dongle
  - Lenovo ThinkPad Thunderbolt 4 Smart Dock Gen2
  - Lenovo USB-C Dual Display Travel Dock
  - More EDL 5G modem devices
  - Drop 8583.patch and 8588.patch: fixed upsrtream.
  - Align meson call with current upstream supported parameters.

++++ haproxy:

  - Build with QUIC on Tumbleweed

++++ kernel-default:

  - smb: client: Add check for next_buffer in receive_encrypted_standard() (CVE-2025-21844 bsc#1239512)
  - commit 26d78d1
  - EDAC/i10nm: Add Intel Clearwater Forest server support (jsc#PED-10632).
  - commit 74f0879
  - block: fix nr_hw_queue update racing with disk addition/removal
    (jsc#PED-9651).
  - commit 1ad06cb
  - blk: Re-add symbols (jsc#PED-9651).
  - commit b75f36f
  - block: get rid of request queue ->sysfs_dir_lock (jsc#PED-9651).
  - commit 427cb3f
  - block: make bio_integrity_map_user() static inline
    (jsc#PED-9651).
  - block: add support to pass user meta buffer (jsc#PED-9651).
  - scsi: add support for user-meta interface (jsc#PED-9651).
  - nvme: add support for passing on the application tag
    (jsc#PED-9651).
  - block: introduce BIP_CHECK_GUARD/REFTAG/APPTAG bip_flags
    (jsc#PED-9651).
  - io_uring: introduce attributes for read/write and PI support
    (jsc#PED-9651).
  - fs: introduce IOCB_HAS_METADATA for metadata (jsc#PED-9651).
  - fs, iov_iter: define meta io descriptor (jsc#PED-9651).
  - block: modify bio_integrity_map_user to accept iov_iter as
    (jsc#PED-9651).
  - commit 1783ba5
  - block: define set of integrity flags to be inherited by
    (jsc#PED-9651).
  - block: Don't trim an atomic write (jsc#PED-9651).
  - commit d4c21f0
  - block: Add common atomic writes enable flag (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit b34e56a
  - md: Replace deprecated kmap_atomic() with kmap_local_page()
    (jsc#PED-9651).
  - commit 55de4aa
  - md/raid10: Atomic write support (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit 3025a42
  - md/raid1: Atomic write support (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit cddb7c9
  - md/raid0: Atomic write support (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit aa8067d
  - lockdep: Don't disable interrupts on RT in
    disable_irq_nosync_lockdep.*() (git-fixes).
  - kbuild: hdrcheck: fix cross build with clang (git-fixes).
  - commit acb9e30
  - md/raid5: Increase r5conf.cache_name size (jsc#PED-9651).
  - commit 0cb15e6
  - md/raid10: Handle bio_split() errors (jsc#PED-9651).
  - md/raid1: Handle bio_split() errors (jsc#PED-9651).
  - md/raid0: Handle bio_split() errors (jsc#PED-9651).
  - commit 3e727d4
  - md/raid5: don't set Faulty rdev for blocked_rdev (jsc#PED-9651).
  - md/raid10: don't wait for Faulty rdev in wait_blocked_rdev()
    (jsc#PED-9651).
  - md/raid1: don't wait for Faulty rdev in wait_blocked_rdev()
    (jsc#PED-9651).
  - commit a5e2aa8
  - md/raid1: factor out helper to handle blocked rdev from
    raid1_write_request() (jsc#PED-9651).
  - Refresh
    patches.suse/md-md-bitmap-remove-the-last-parameter-for-bimtap_ops-endwrite.patch.
  - commit 6d35bb1
  - md: don't record new badblocks for faulty rdev (jsc#PED-9651).
  - md: don't wait faulty rdev in md_wait_for_blocked_rdev()
    (jsc#PED-9651).
  - md: add a new helper rdev_blocked() (jsc#PED-9651).
  - md/raid5-ppl: Use atomic64_inc_return() in ppl_new_iounit()
    (jsc#PED-9651).
  - commit f925245

++++ kernel-firmware-amdgpu:

  - Fix a typo in download URL

++++ kernel-firmware-ath10k:

  - Fix a typo in download URL

++++ kernel-firmware-bluetooth:

  - Fix a typo in download URL

++++ kernel-firmware-media:

  - Fix a typo in download URL

++++ kernel-firmware-mediatek:

  - Fix a typo in download URL

++++ kernel-firmware-nvidia:

  - Fix a typo in download URL

++++ kernel-firmware-platform:

  - Fix a typo in download URL

++++ kernel-firmware-qcom:

  - Fix a typo in download URL

++++ kernel-firmware-sound:

  - Fix a typo in download URL

++++ kernel-rt:

  - smb: client: Add check for next_buffer in receive_encrypted_standard() (CVE-2025-21844 bsc#1239512)
  - commit 26d78d1
  - EDAC/i10nm: Add Intel Clearwater Forest server support (jsc#PED-10632).
  - commit 74f0879
  - block: fix nr_hw_queue update racing with disk addition/removal
    (jsc#PED-9651).
  - commit 1ad06cb
  - blk: Re-add symbols (jsc#PED-9651).
  - commit b75f36f
  - block: get rid of request queue ->sysfs_dir_lock (jsc#PED-9651).
  - commit 427cb3f
  - block: make bio_integrity_map_user() static inline
    (jsc#PED-9651).
  - block: add support to pass user meta buffer (jsc#PED-9651).
  - scsi: add support for user-meta interface (jsc#PED-9651).
  - nvme: add support for passing on the application tag
    (jsc#PED-9651).
  - block: introduce BIP_CHECK_GUARD/REFTAG/APPTAG bip_flags
    (jsc#PED-9651).
  - io_uring: introduce attributes for read/write and PI support
    (jsc#PED-9651).
  - fs: introduce IOCB_HAS_METADATA for metadata (jsc#PED-9651).
  - fs, iov_iter: define meta io descriptor (jsc#PED-9651).
  - block: modify bio_integrity_map_user to accept iov_iter as
    (jsc#PED-9651).
  - commit 1783ba5
  - block: define set of integrity flags to be inherited by
    (jsc#PED-9651).
  - block: Don't trim an atomic write (jsc#PED-9651).
  - commit d4c21f0
  - block: Add common atomic writes enable flag (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit b34e56a
  - md: Replace deprecated kmap_atomic() with kmap_local_page()
    (jsc#PED-9651).
  - commit 55de4aa
  - md/raid10: Atomic write support (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit 3025a42
  - md/raid1: Atomic write support (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit cddb7c9
  - md/raid0: Atomic write support (jsc#PED-9651).
  - Refresh
    patches.suse/md-raid-Fix-the-set_queue_limits-implementations.patch.
  - commit aa8067d
  - lockdep: Don't disable interrupts on RT in
    disable_irq_nosync_lockdep.*() (git-fixes).
  - kbuild: hdrcheck: fix cross build with clang (git-fixes).
  - commit acb9e30
  - md/raid5: Increase r5conf.cache_name size (jsc#PED-9651).
  - commit 0cb15e6
  - md/raid10: Handle bio_split() errors (jsc#PED-9651).
  - md/raid1: Handle bio_split() errors (jsc#PED-9651).
  - md/raid0: Handle bio_split() errors (jsc#PED-9651).
  - commit 3e727d4
  - md/raid5: don't set Faulty rdev for blocked_rdev (jsc#PED-9651).
  - md/raid10: don't wait for Faulty rdev in wait_blocked_rdev()
    (jsc#PED-9651).
  - md/raid1: don't wait for Faulty rdev in wait_blocked_rdev()
    (jsc#PED-9651).
  - commit a5e2aa8
  - md/raid1: factor out helper to handle blocked rdev from
    raid1_write_request() (jsc#PED-9651).
  - Refresh
    patches.suse/md-md-bitmap-remove-the-last-parameter-for-bimtap_ops-endwrite.patch.
  - commit 6d35bb1
  - md: don't record new badblocks for faulty rdev (jsc#PED-9651).
  - md: don't wait faulty rdev in md_wait_for_blocked_rdev()
    (jsc#PED-9651).
  - md: add a new helper rdev_blocked() (jsc#PED-9651).
  - md/raid5-ppl: Use atomic64_inc_return() in ppl_new_iounit()
    (jsc#PED-9651).
  - commit f925245

++++ pcp:

  - Enable custom pcp-selinux module (bsc#1237260)

++++ sssd:

  - Add python3-setuptools build dependency
  - Drop nscd build dependency

++++ microos-tools:

  - Update to version 4.0+git11:
    * Only parse section with at minimum two arguments (#42)

++++ python-MarkupSafe:

  - Lowercase metadata directory name.

++++ python-PyJWT:

  - Lowercase metadata directory name.

++++ python-PyYAML:

  - Lowercase metadata directory name.

++++ strace:

  - Update to strace 6.14
    * Added -e namespace=new option for printing the namespaces entered
    by the tracee.
    * Implemented decoding of FRA_FLOWLABEL and FRA_FLOWLABEL_MASK netlink
    attributes of RTM_{NEW,DEL,GET}RULE NETLINK_ROUTE messages.
    * Implemented decoding of RTM_{NEW,DEL}MULTICAST and RTM_{NEW,DEL}ANYCAST
    NETLINK_ROUTE messages.
    * Updated decoding of statx syscall.
    * Updated lists of AT_*, AUDIT_*, ETHTOOL_*, FAN_*, IORING_*, IPPROTO_*,
    KEY_*, NL80211_*, RWF_*, and SECBIT_* constants.
    * Updated lists of ioctl commands from Linux 6.14.

++++ systemd-presets-common-SUSE:

  - Change display-manager.service to display-manager-legacy.service
    (rename for future systemd control of display manager choice)

------------------------------------------------------------------
------------------  2025-3-24  -  Mar 24 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Drop use of travis-sphinx
    According to the documentation of peaceiris/actions-gh-pages
    the sphinx-build output can be directly consumed to publish
    to github pages
  - Allow stderr data in CommandProcess
    Enhance poll_show_progress() method to allow polling on
    stderr data too. The new parameter with_stderr is used
    together with the dnf5 package manager. dnf5 has changed
    in a way that a lot of useful information during the
    install of packages is printed to stderr. From my perspective
    a clear regression to former behavior but we can fix this
    in kiwi to poll on both channels. This Fixes #2748
  - Support arch attribute for <users> section
    Allow to setup users per arch. This Fixes #2737
  - Add Debian_12_update repo for testing with typer
    Even though we will add support for the typer Cli with kiwi-11
    I want our integration test images to be able to build with the
    open PR #2751. Debian 12 is the only target in the support matrix
    which uses a too old veryion of typer. Therefore to be able to
    test this target I built a newer version of typer in an update
    repo for Debian 12 and added it to the integration test
    description

++++ git:

  - Add support of SHA256 git repo for gitk (bsc#1239989):
    0001-gitk-Add-a-basic-support-of-SHA256-repositories-into.patch
    0002-gitk-Add-auto-select-length-preference-for-SHA256.patch

++++ glibc:

  - Mark functions in libc_nonshared.a as hidden (bsc#1239883)

++++ gnutls:

  - FIPS: Mark SHA-1 as non-approved in the SLI for all operations. [jsc#PED-12224]
    * Add gnutls-FIPS-disable-mac-sha1.patch

++++ kernel-default:

  - block: limit disk max sectors to (LLONG_MAX >> 9)
    (jsc#PED-9651).
  - block: Change blk_stack_atomic_writes_limits() unit_min check
    (jsc#PED-9651).
  - block: Ensure start sector is aligned for stacking atomic writes
    (jsc#PED-9651).
  - blk-mq: Move more error handling into blk_mq_submit_bio()
    (jsc#PED-9651).
  - block: Reorder the request allocation code in
    blk_mq_submit_bio() (jsc#PED-9651).
  - commit ff53e6b
  - blk-cgroup: rwstat: fix kernel-doc warnings in header file
    (jsc#PED-9651).
  - blacklist.conf:
  - blk-cgroup: fix kernel-doc warnings in header file
    (jsc#PED-9651).
  - block: mark GFP_NOIO around sysfs ->store() (jsc#PED-9651).
  - usb-storage: fix queue freeze vs limits lock order
    (jsc#PED-9651).
  - nbd: fix queue freeze vs limits lock order (jsc#PED-9651).
  - nvme: fix queue freeze vs limits lock order (jsc#PED-9651).
  - block: fix queue freeze vs limits lock order in sysfs store
    (jsc#PED-9651).
  - block: add a store_limit operations for sysfs entries
    (jsc#PED-9651).
  - commit db47806
  - block: add a queue_limits_commit_update_frozen helper
    (jsc#PED-9651).
  - block: fix docs for freezing of queue limits updates
    (jsc#PED-9651).
  - block: simplify tag allocation policy selection (jsc#PED-9651).
  - block: remove BLK_MQ_F_NO_SCHED (jsc#PED-9651).
  - block: remove blk_mq_init_bitmaps (jsc#PED-9651).
  - block: better split mq vs non-mq code in add_disk_fwnode
    (jsc#PED-9651).
  - block: add a dma mapping iterator (jsc#PED-9651).
  - block: remove blk_rq_bio_prep (jsc#PED-9651).
  - block: remove bio_add_pc_page (jsc#PED-9651).
  - kyber: constify sysfs attributes (jsc#PED-9651).
  - block, bfq: constify sysfs attributes (jsc#PED-9651).
  - block: mq-deadline: Constify sysfs attributes (jsc#PED-9651).
  - elevator: Enable const sysfs attributes (jsc#PED-9651).
  - blk-zoned: Split queue_zone_wplugs_show() (jsc#PED-9651).
  - blk-zoned: Improve the queue reference count strategy
    documentation (jsc#PED-9651).
  - blk-zoned: Document locking assumptions (jsc#PED-9651).
  - blk-zoned: Minimize #include directives (jsc#PED-9651).
  - block: remove BLK_MQ_F_SHOULD_MERGE (jsc#PED-9651).
  - commit aaae71e
  - blktrace: remove redundant return at end of function
    (jsc#PED-9651).
  - block: Delete bio_set_prio() (jsc#PED-9651).
  - block: Delete bio_prio() (jsc#PED-9651).
  - commit c246365
  - blktrace: move copy_[to|from]_user() out of ->debugfs_lock
    (jsc#PED-9651).
  - blktrace: don't centralize grabbing q->debugfs_mutex in
    blk_trace_ioctl (jsc#PED-9651).
  - null_blk: Add rotational feature support (jsc#PED-9651).
  - block: track queue dying state automatically for modeling
    queue freeze lockdep (jsc#PED-9651).
  - block: don't verify queue freeze manually in elevator_init_mq()
    (jsc#PED-9651).
  - block: track disk DEAD state automatically for modeling queue
    freeze lockdep (jsc#PED-9651).
  - block: remove unnecessary check in blk_unfreeze_check_owner()
    (jsc#PED-9651).
  - commit fc5adc6
  - block: Revert "block: Fix potential deadlock while freezing
    queue and acquiring sysfs_lock (jsc#PED-9651).
  - block/bdev: use helper for max block size check (jsc#PED-9651).
  - block: Fix potential deadlock while freezing queue and acquiring
    sysfs_lock (jsc#PED-9651).
  - block: Fix queue_iostats_passthrough_show() (jsc#PED-9651).
  - blk-mq: Clean up blk_mq_requeue_work() (jsc#PED-9651).
  - mq-deadline: Remove a local variable (jsc#PED-9651).
  - block: Make bio_iov_bvec_set() accept pointer to const iov_iter
    (jsc#PED-9651).
  - commit f6d6aff
  - mq-deadline: don't call req_get_ioprio from the I/O completion
    handler (jsc#PED-9651).
  - block: Remove extra part pointer NULLify in blk_rq_init()
    (jsc#PED-9651).
  - commit bd669e8
  - sched/fair: Fix potential memory corruption in
    child_cfs_rq_on_list (bsc#1234634 (Scheduler functional and
    performance backports)).
  - cpuidle, sched: Use smp_mb__after_atomic() in
    current_clr_polling() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - commit 3fdb94f
  - block: return bool from get_disk_ro and bdev_read_only
    (jsc#PED-9651).
  - block: remove a duplicate definition for bdev_read_only
    (jsc#PED-9651).
  - block: return bool from blk_rq_aligned (jsc#PED-9651).
  - block: return unsigned int from blk_lim_dma_alignment_and_pad
    (jsc#PED-9651).
  - block: return unsigned int from bdev_io_opt (jsc#PED-9651).
  - block: req->bio is always set in the merge code (jsc#PED-9651).
  - block: don't bother checking the data direction for merges
    (jsc#PED-9651).
  - block: blk-mq: fix uninit-value in blk_rq_prep_clone and
    refactor (jsc#PED-9651).
  - block: Support atomic writes limits for stacked devices
    (jsc#PED-9651).
  - block: Add extra checks in blk_validate_atomic_write_limits()
    (jsc#PED-9651).
  - block: Drop granularity check in queue_limit_discard_alignment()
    (jsc#PED-9651).
  - commit 60a3d57
  - block/genhd: use seq_put_decimal_ull for diskstats decimal
    values (jsc#PED-9651).
  - block: don't reorder requests in blk_mq_add_to_batch
    (jsc#PED-9651).
  - block: don't reorder requests in blk_add_rq_to_plug
    (jsc#PED-9651).
  - block: add a rq_list type (jsc#PED-9651).
  - block: remove rq_list_move (jsc#PED-9651).
  - commit ee68c48
  - net: mana: Support holes in device list reply msg (git-fixes).
  - net: mana: cleanup mana struct after debugfs_remove()
    (git-fixes).
  - Drivers: hv: vmbus: Don't release fb_mmio resource in
    vmbus_free_mmio() (git-fixes).
  - x86/hyperv: Fix output argument to hypercall that changes page
    visibility (git-fixes).
  - fbdev: hyperv_fb: Allow graceful removal of framebuffer
    (git-fixes).
  - fbdev: hyperv_fb: Simplify hvfb_putmem (git-fixes).
  - fbdev: hyperv_fb: Fix hang in kdump kernel when on Hyper-V
    Gen 2 VMs (git-fixes).
  - fbdev: hyperv_fb: iounmap() the correct memory when removing
    a device (git-fixes).
  - x86/hyperv/vtl: Stop kernel from probing VTL0 low memory
    (git-fixes).
  - commit 6ca88b5
  - kprobes: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - kprobes: Reduce preempt disable scope
    in check_kprobe_access_safe() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - commit 8d86dd1
  - block: export blk_validate_limits (jsc#PED-9651).
  - block: remove the ioprio field from struct request
    (jsc#PED-9651).
  - block: remove the write_hint field from struct request
    (jsc#PED-9651).
  - commit 4da93a9
  - Refresh
    patches.suse/block-pre-calculate-max_zone_append_sectors.patch.
  - Delete
    patches.suse/Revert-block-pre-calculate-max_zone_append_sectors.patch.
  - commit 176765a
  - net/mlx5e: Prevent bridge link show failure for
    non-eswitch-allowed devices (jsc#PED-11331).
  - net/mlx5: Bridge, fix the crash caused by LAG state check
    (jsc#PED-11331).
  - net/mlx5: Lag, Check shared fdb before creating MultiPort
    E-Switch (jsc#PED-11331).
  - net/mlx5: Fix incorrect IRQ pool usage when releasing IRQs
    (jsc#PED-11331).
  - net/mlx5: HWS, Rightsize bwc matcher priority (jsc#PED-11331).
  - net/mlx5: DR, use the right action structs for STEv3
    (jsc#PED-11331).
  - eth: bnxt: fix memory leak in queue reset (jsc#PED-10684
    jsc#PED-11230).
  - eth: bnxt: fix kernel panic in the bnxt_get_queue_stats{rx |
    tx} (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: do not update checksum in bnxt_xdp_build_skb()
    (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: do not use BNXT_VNIC_NTUPLE unconditionally in
    queue restart logic (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: return fail if interface is down in
    bnxt_queue_mem_alloc() (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: fix truesize for mb-xdp-pass case (jsc#PED-10684
    jsc#PED-11230).
  - net/mlx5: handle errors in mlx5_chains_create_table()
    (jsc#PED-11331).
  - ice: register devlink prior to creating health reporters
    (jsc#PED-10419).
  - ice: Fix switchdev slow-path in LAG (jsc#PED-10419).
  - ice: fix memory leak in aRFS after reset (jsc#PED-10419).
  - ice: do not configure destination override for switchdev
    (jsc#PED-10419).
  - be2net: fix sleeping while atomic bugs in be_ndo_bridge_getlink
    (jsc#PED-8900 jsc#PED-11248).
  - commit cffd61f
  - block: Handle bio_split() errors in bio_submit_split()
    (jsc#PED-9651).
  - block: Error an attempt to split an atomic write in bio_split()
    (jsc#PED-9651).
  - block: Rework bio_split() return value (jsc#PED-9651).
  - commit cc36652
  - block: remove blk_freeze_queue() (jsc#PED-9651).
  - Refresh
    patches.suse/block-always-verify-unfreeze-lock-on-the-owner-task.patch.
  - commit c10f921
  - block: Replace sprintf() with sysfs_emit() (jsc#PED-9651).
  - commit e18c441
  - block: Add a public bdev_zone_is_seq() helper (jsc#PED-9651).
  - block: return unsigned int from queue_dma_alignment
    (jsc#PED-9651).
  - Refresh
    patches.suse/block-Prevent-potential-deadlocks-in-zone-write-plug-error-recovery.patch.
  - Refresh
    patches.suse/dm-Fix-dm-zoned-reclaim-zone-write-pointer-alignment.patch.
  - commit 9f0b2a7
  - series: update metadata
    The lpfc driver update moved forward to the next stage on the way
    to mainline. Update the metadata to avoid breaking the kernel patch
    maintainance tooling.
  - Refresh
    patches.suse/scsi-lpfc-Copyright-updates-for-14.4.0.8-patches.patch.
  - Refresh
    patches.suse/scsi-lpfc-Free-phba-irq-in-lpfc_sli4_enable_msi-when.patch.
  - Refresh
    patches.suse/scsi-lpfc-Handle-duplicate-D_IDs-in-ndlp-search-by-D.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ignore-ndlp-rport-mismatch-in-dev_loss_tmo.patch.
  - Refresh
    patches.suse/scsi-lpfc-Reduce-log-message-generation-during-ELS-r.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.8.patch.
  - commit 61224c0
  - Revert "block: pre-calculate max_zone_append_sectors"
    (jsc#PED-9651).
  - commit 72c7300
  - config: update using run_oldconfig.sh
  - commit 71298c4
  - block: pre-calculate max_zone_append_sectors (jsc#PED-9651).
  - commit 630582a
  - block: remove the max_zone_append_sectors check in
    blk_revalidate_disk_zones (jsc#PED-9651).
  - block: update blk_stack_limits documentation (jsc#PED-9651).
  - block: remove bio_add_zone_append_page (jsc#PED-9651).
  - block: remove zone append special casing from the direct I/O
    path (jsc#PED-9651).
  - blk-integrity: remove seed for user mapped buffers
    (jsc#PED-9651).
  - block: add a bdev_limits helper (jsc#PED-9651).
  - blk-mq: Unexport blk_mq_flush_busy_ctxs() (jsc#PED-9651).
  - block: remove redundant explicit memory barrier from rq_qos
    waiter and waker (jsc#PED-9651).
  - block: flush all throttled bios when deleting the cgroup
    (jsc#PED-9651).
  - commit f26135d
  - block: sed-opal: add ioctl IOC_OPAL_SET_SID_PW (jsc#PED-9651
  - commit 4f40e80
  - block: replace call_rcu by kfree_rcu for simple kmem_cache_free
    callback (jsc#PED-9651).
  - block: enable passthrough command statistics (jsc#PED-9651).
  - block: return void from the queue_sysfs_entry load_module method
    (jsc#PED-9651).
  - block: add partition uuid into uevent as "PARTUUID"
    (jsc#PED-9651).
  - block: move issue side time stamping to blk_account_io_start()
    (jsc#PED-9651).
  - block: set issue time stamp based on queue state (jsc#PED-9651).
  - block: introduce add_disk_fwnode() (jsc#PED-9651).
  - block: add support for defining read-only partitions
    (jsc#PED-9651).
  - block: kill blk_do_io_stat() helper (jsc#PED-9651).
  - block: remove 'req->part' check for stats accounting
    (jsc#PED-9651).
  - block: remove redundant passthrough check in
    blk_mq_need_time_stamp() (jsc#PED-9651).
  - block: move iostat check into blk_acount_io_start()
    (jsc#PED-9651).
  - commit 7ebf536
  - rpm/kernel-binary.spec.in: Fix missing 20-kernel-default-extra.conf (bsc#1239986)
    sle_version was obsoleted for SLE16.  It has to be combined with
    suse_version check.
  - commit cbd5de3
  - turbostat: rename patches using ./scripts/renamepatches
    Prepare to merge turbostat forklift backport
  - commit c56074a
  - s390/cio: Fix CHPID "configure" attribute caching (git-fixes
    bsc#1239979).
  - commit 8905a0c

++++ kernel-rt:

  - block: limit disk max sectors to (LLONG_MAX >> 9)
    (jsc#PED-9651).
  - block: Change blk_stack_atomic_writes_limits() unit_min check
    (jsc#PED-9651).
  - block: Ensure start sector is aligned for stacking atomic writes
    (jsc#PED-9651).
  - blk-mq: Move more error handling into blk_mq_submit_bio()
    (jsc#PED-9651).
  - block: Reorder the request allocation code in
    blk_mq_submit_bio() (jsc#PED-9651).
  - commit ff53e6b
  - blk-cgroup: rwstat: fix kernel-doc warnings in header file
    (jsc#PED-9651).
  - blacklist.conf:
  - blk-cgroup: fix kernel-doc warnings in header file
    (jsc#PED-9651).
  - block: mark GFP_NOIO around sysfs ->store() (jsc#PED-9651).
  - usb-storage: fix queue freeze vs limits lock order
    (jsc#PED-9651).
  - nbd: fix queue freeze vs limits lock order (jsc#PED-9651).
  - nvme: fix queue freeze vs limits lock order (jsc#PED-9651).
  - block: fix queue freeze vs limits lock order in sysfs store
    (jsc#PED-9651).
  - block: add a store_limit operations for sysfs entries
    (jsc#PED-9651).
  - commit db47806
  - block: add a queue_limits_commit_update_frozen helper
    (jsc#PED-9651).
  - block: fix docs for freezing of queue limits updates
    (jsc#PED-9651).
  - block: simplify tag allocation policy selection (jsc#PED-9651).
  - block: remove BLK_MQ_F_NO_SCHED (jsc#PED-9651).
  - block: remove blk_mq_init_bitmaps (jsc#PED-9651).
  - block: better split mq vs non-mq code in add_disk_fwnode
    (jsc#PED-9651).
  - block: add a dma mapping iterator (jsc#PED-9651).
  - block: remove blk_rq_bio_prep (jsc#PED-9651).
  - block: remove bio_add_pc_page (jsc#PED-9651).
  - kyber: constify sysfs attributes (jsc#PED-9651).
  - block, bfq: constify sysfs attributes (jsc#PED-9651).
  - block: mq-deadline: Constify sysfs attributes (jsc#PED-9651).
  - elevator: Enable const sysfs attributes (jsc#PED-9651).
  - blk-zoned: Split queue_zone_wplugs_show() (jsc#PED-9651).
  - blk-zoned: Improve the queue reference count strategy
    documentation (jsc#PED-9651).
  - blk-zoned: Document locking assumptions (jsc#PED-9651).
  - blk-zoned: Minimize #include directives (jsc#PED-9651).
  - block: remove BLK_MQ_F_SHOULD_MERGE (jsc#PED-9651).
  - commit aaae71e
  - blktrace: remove redundant return at end of function
    (jsc#PED-9651).
  - block: Delete bio_set_prio() (jsc#PED-9651).
  - block: Delete bio_prio() (jsc#PED-9651).
  - commit c246365
  - blktrace: move copy_[to|from]_user() out of ->debugfs_lock
    (jsc#PED-9651).
  - blktrace: don't centralize grabbing q->debugfs_mutex in
    blk_trace_ioctl (jsc#PED-9651).
  - null_blk: Add rotational feature support (jsc#PED-9651).
  - block: track queue dying state automatically for modeling
    queue freeze lockdep (jsc#PED-9651).
  - block: don't verify queue freeze manually in elevator_init_mq()
    (jsc#PED-9651).
  - block: track disk DEAD state automatically for modeling queue
    freeze lockdep (jsc#PED-9651).
  - block: remove unnecessary check in blk_unfreeze_check_owner()
    (jsc#PED-9651).
  - commit fc5adc6
  - block: Revert "block: Fix potential deadlock while freezing
    queue and acquiring sysfs_lock (jsc#PED-9651).
  - block/bdev: use helper for max block size check (jsc#PED-9651).
  - block: Fix potential deadlock while freezing queue and acquiring
    sysfs_lock (jsc#PED-9651).
  - block: Fix queue_iostats_passthrough_show() (jsc#PED-9651).
  - blk-mq: Clean up blk_mq_requeue_work() (jsc#PED-9651).
  - mq-deadline: Remove a local variable (jsc#PED-9651).
  - block: Make bio_iov_bvec_set() accept pointer to const iov_iter
    (jsc#PED-9651).
  - commit f6d6aff
  - mq-deadline: don't call req_get_ioprio from the I/O completion
    handler (jsc#PED-9651).
  - block: Remove extra part pointer NULLify in blk_rq_init()
    (jsc#PED-9651).
  - commit bd669e8
  - sched/fair: Fix potential memory corruption in
    child_cfs_rq_on_list (bsc#1234634 (Scheduler functional and
    performance backports)).
  - cpuidle, sched: Use smp_mb__after_atomic() in
    current_clr_polling() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - commit 3fdb94f
  - block: return bool from get_disk_ro and bdev_read_only
    (jsc#PED-9651).
  - block: remove a duplicate definition for bdev_read_only
    (jsc#PED-9651).
  - block: return bool from blk_rq_aligned (jsc#PED-9651).
  - block: return unsigned int from blk_lim_dma_alignment_and_pad
    (jsc#PED-9651).
  - block: return unsigned int from bdev_io_opt (jsc#PED-9651).
  - block: req->bio is always set in the merge code (jsc#PED-9651).
  - block: don't bother checking the data direction for merges
    (jsc#PED-9651).
  - block: blk-mq: fix uninit-value in blk_rq_prep_clone and
    refactor (jsc#PED-9651).
  - block: Support atomic writes limits for stacked devices
    (jsc#PED-9651).
  - block: Add extra checks in blk_validate_atomic_write_limits()
    (jsc#PED-9651).
  - block: Drop granularity check in queue_limit_discard_alignment()
    (jsc#PED-9651).
  - commit 60a3d57
  - block/genhd: use seq_put_decimal_ull for diskstats decimal
    values (jsc#PED-9651).
  - block: don't reorder requests in blk_mq_add_to_batch
    (jsc#PED-9651).
  - block: don't reorder requests in blk_add_rq_to_plug
    (jsc#PED-9651).
  - block: add a rq_list type (jsc#PED-9651).
  - block: remove rq_list_move (jsc#PED-9651).
  - commit ee68c48
  - net: mana: Support holes in device list reply msg (git-fixes).
  - net: mana: cleanup mana struct after debugfs_remove()
    (git-fixes).
  - Drivers: hv: vmbus: Don't release fb_mmio resource in
    vmbus_free_mmio() (git-fixes).
  - x86/hyperv: Fix output argument to hypercall that changes page
    visibility (git-fixes).
  - fbdev: hyperv_fb: Allow graceful removal of framebuffer
    (git-fixes).
  - fbdev: hyperv_fb: Simplify hvfb_putmem (git-fixes).
  - fbdev: hyperv_fb: Fix hang in kdump kernel when on Hyper-V
    Gen 2 VMs (git-fixes).
  - fbdev: hyperv_fb: iounmap() the correct memory when removing
    a device (git-fixes).
  - x86/hyperv/vtl: Stop kernel from probing VTL0 low memory
    (git-fixes).
  - commit 6ca88b5
  - kprobes: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - kprobes: Reduce preempt disable scope
    in check_kprobe_access_safe() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - commit 8d86dd1
  - block: export blk_validate_limits (jsc#PED-9651).
  - block: remove the ioprio field from struct request
    (jsc#PED-9651).
  - block: remove the write_hint field from struct request
    (jsc#PED-9651).
  - commit 4da93a9
  - Refresh
    patches.suse/block-pre-calculate-max_zone_append_sectors.patch.
  - Delete
    patches.suse/Revert-block-pre-calculate-max_zone_append_sectors.patch.
  - commit 176765a
  - net/mlx5e: Prevent bridge link show failure for
    non-eswitch-allowed devices (jsc#PED-11331).
  - net/mlx5: Bridge, fix the crash caused by LAG state check
    (jsc#PED-11331).
  - net/mlx5: Lag, Check shared fdb before creating MultiPort
    E-Switch (jsc#PED-11331).
  - net/mlx5: Fix incorrect IRQ pool usage when releasing IRQs
    (jsc#PED-11331).
  - net/mlx5: HWS, Rightsize bwc matcher priority (jsc#PED-11331).
  - net/mlx5: DR, use the right action structs for STEv3
    (jsc#PED-11331).
  - eth: bnxt: fix memory leak in queue reset (jsc#PED-10684
    jsc#PED-11230).
  - eth: bnxt: fix kernel panic in the bnxt_get_queue_stats{rx |
    tx} (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: do not update checksum in bnxt_xdp_build_skb()
    (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: do not use BNXT_VNIC_NTUPLE unconditionally in
    queue restart logic (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: return fail if interface is down in
    bnxt_queue_mem_alloc() (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: fix truesize for mb-xdp-pass case (jsc#PED-10684
    jsc#PED-11230).
  - net/mlx5: handle errors in mlx5_chains_create_table()
    (jsc#PED-11331).
  - ice: register devlink prior to creating health reporters
    (jsc#PED-10419).
  - ice: Fix switchdev slow-path in LAG (jsc#PED-10419).
  - ice: fix memory leak in aRFS after reset (jsc#PED-10419).
  - ice: do not configure destination override for switchdev
    (jsc#PED-10419).
  - be2net: fix sleeping while atomic bugs in be_ndo_bridge_getlink
    (jsc#PED-8900 jsc#PED-11248).
  - commit cffd61f
  - block: Handle bio_split() errors in bio_submit_split()
    (jsc#PED-9651).
  - block: Error an attempt to split an atomic write in bio_split()
    (jsc#PED-9651).
  - block: Rework bio_split() return value (jsc#PED-9651).
  - commit cc36652
  - block: remove blk_freeze_queue() (jsc#PED-9651).
  - Refresh
    patches.suse/block-always-verify-unfreeze-lock-on-the-owner-task.patch.
  - commit c10f921
  - block: Replace sprintf() with sysfs_emit() (jsc#PED-9651).
  - commit e18c441
  - block: Add a public bdev_zone_is_seq() helper (jsc#PED-9651).
  - block: return unsigned int from queue_dma_alignment
    (jsc#PED-9651).
  - Refresh
    patches.suse/block-Prevent-potential-deadlocks-in-zone-write-plug-error-recovery.patch.
  - Refresh
    patches.suse/dm-Fix-dm-zoned-reclaim-zone-write-pointer-alignment.patch.
  - commit 9f0b2a7
  - series: update metadata
    The lpfc driver update moved forward to the next stage on the way
    to mainline. Update the metadata to avoid breaking the kernel patch
    maintainance tooling.
  - Refresh
    patches.suse/scsi-lpfc-Copyright-updates-for-14.4.0.8-patches.patch.
  - Refresh
    patches.suse/scsi-lpfc-Free-phba-irq-in-lpfc_sli4_enable_msi-when.patch.
  - Refresh
    patches.suse/scsi-lpfc-Handle-duplicate-D_IDs-in-ndlp-search-by-D.patch.
  - Refresh
    patches.suse/scsi-lpfc-Ignore-ndlp-rport-mismatch-in-dev_loss_tmo.patch.
  - Refresh
    patches.suse/scsi-lpfc-Reduce-log-message-generation-during-ELS-r.patch.
  - Refresh
    patches.suse/scsi-lpfc-Update-lpfc-version-to-14.4.0.8.patch.
  - commit 61224c0
  - Revert "block: pre-calculate max_zone_append_sectors"
    (jsc#PED-9651).
  - commit 72c7300
  - config: update using run_oldconfig.sh
  - commit 71298c4
  - block: pre-calculate max_zone_append_sectors (jsc#PED-9651).
  - commit 630582a
  - block: remove the max_zone_append_sectors check in
    blk_revalidate_disk_zones (jsc#PED-9651).
  - block: update blk_stack_limits documentation (jsc#PED-9651).
  - block: remove bio_add_zone_append_page (jsc#PED-9651).
  - block: remove zone append special casing from the direct I/O
    path (jsc#PED-9651).
  - blk-integrity: remove seed for user mapped buffers
    (jsc#PED-9651).
  - block: add a bdev_limits helper (jsc#PED-9651).
  - blk-mq: Unexport blk_mq_flush_busy_ctxs() (jsc#PED-9651).
  - block: remove redundant explicit memory barrier from rq_qos
    waiter and waker (jsc#PED-9651).
  - block: flush all throttled bios when deleting the cgroup
    (jsc#PED-9651).
  - commit f26135d
  - block: sed-opal: add ioctl IOC_OPAL_SET_SID_PW (jsc#PED-9651
  - commit 4f40e80
  - block: replace call_rcu by kfree_rcu for simple kmem_cache_free
    callback (jsc#PED-9651).
  - block: enable passthrough command statistics (jsc#PED-9651).
  - block: return void from the queue_sysfs_entry load_module method
    (jsc#PED-9651).
  - block: add partition uuid into uevent as "PARTUUID"
    (jsc#PED-9651).
  - block: move issue side time stamping to blk_account_io_start()
    (jsc#PED-9651).
  - block: set issue time stamp based on queue state (jsc#PED-9651).
  - block: introduce add_disk_fwnode() (jsc#PED-9651).
  - block: add support for defining read-only partitions
    (jsc#PED-9651).
  - block: kill blk_do_io_stat() helper (jsc#PED-9651).
  - block: remove 'req->part' check for stats accounting
    (jsc#PED-9651).
  - block: remove redundant passthrough check in
    blk_mq_need_time_stamp() (jsc#PED-9651).
  - block: move iostat check into blk_acount_io_start()
    (jsc#PED-9651).
  - commit 7ebf536
  - rpm/kernel-binary.spec.in: Fix missing 20-kernel-default-extra.conf (bsc#1239986)
    sle_version was obsoleted for SLE16.  It has to be combined with
    suse_version check.
  - commit cbd5de3
  - turbostat: rename patches using ./scripts/renamepatches
    Prepare to merge turbostat forklift backport
  - commit c56074a
  - s390/cio: Fix CHPID "configure" attribute caching (git-fixes
    bsc#1239979).
  - commit 8905a0c

++++ gcc15:

  - Disable build of glibc cross to loongarch64 and hppa in SLFO.

++++ libguestfs:

  - libguestfs-appliance: drop incorrect requireson libpcre1,
    package was converted to pcre2 by 1.44.2

++++ harfbuzz:

  - Update to version 11.0.0:
    + There are three new font-functions implementations
    (integrations) in this release:
  - hb-coretext has gained one, calling into the CoreText
    library.
  - hb-directwrite has gained one, calling into the DirectWrite
    library.
  - hb-fontations has gained one, calling into the Skrifa Rust
    library.
  - All three are mostly useful for performance and correctness
    testing, but some clients might find them useful.
    + An API is added to use them from a single API by providing a
    backend name string: hb_font_set_funcs_using()
    + Several new APIs are added, to load a font-face using different
    "face-loaders", and a single entry point to them all using a
    loader name string:
  - hb_ft_face_create_from_file_or_fail() and
    hb_ft_face_create_from_blob_or_fail().
  - hb_coretext_face_create_from_file_or_fail() and
    hb_coretext_face_create_from_blob_or_fail().
  - hb_directwrite_face_create_from_file_or_fail() and
    hb_directwrite_face_create_from_blob_or_fail().
  - hb_face_create_from_file_or_fail_using()
    + All drawing and painting operations using the default, hb-ot
    functions have become memory allocation-free.
    + Several performance optimizations have been implemented.
    + Application of the trak table during shaping has been improved.
    + The directwrite shaper now supports font variations, and
    correctly applies user features.
    + The hb-directwrite API and shaper has graduated from
    experimental.
    + Various bug fixes and other improvements.

++++ ncurses:

  - Add ncurses patch 20250322
    + add a null pointer check in mouse-initialization, for the
    experimental Windows driver (patch by Daniel Starke).
    + improve makefile dependency in Ada95/src
    + add note in user_caps.5 addressing a quibble about dates.

++++ openSUSE-repos-LeapMicro:

  - Update to version 20250324.7d1bc96:
    * Add non-oss / non-oss-debug repos for Leap 16.0 (#80)

++++ pam:

  - Remove unix2_chkpwd, no consumer left

++++ pam-full-src:

  - Remove unix2_chkpwd, no consumer left

++++ pcsc-tools:

  - Update to version 1.7.3
    * A number of new ATRs.
    * build system and portability changes.

++++ python-setuptools:

  - update to 78.0.2
    * Reverted distutils changes that broke the monkey patching of command
    classes.
    * Temporarily remove requests from integration tests.

++++ rpm-config-SUSE:

  - Update to version 20250324:
    * Define %jobs as variable (boo#1237231)
    * %requires_eq|ge(): Fix multiline output
    * Split the SUSE distribution version macros to a separate file

------------------------------------------------------------------
------------------  2025-3-23  -  Mar 23 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - i2c: amd-mp2: drop free_irq() of devm_request_irq() allocated
    irq (git-fixes).
  - keys: Fix UAF in key_put() (git-fixes).
  - drm/i915/cdclk: Do cdclk post plane programming later
    (stable-fixes).
  - drm/atomic: Filter out redundant DPMS calls (stable-fixes).
  - drm/amd/amdkfd: Evict all queues even HWS remove queue failed
    (stable-fixes).
  - drm/amd/display: Assign normalized_pix_clk when color depth =
    14 (stable-fixes).
  - drm/amd/display: Restore correct backlight brightness after
    a GPU reset (stable-fixes).
  - drm/amd/display: Disable unneeded hpd interrupts during dm_init
    (stable-fixes).
  - drm/amdgpu/display: Allow DCC for video formats on GFX12
    (stable-fixes).
  - drm/hyperv: Fix address space leak when Hyper-V DRM device is
    removed (git-fixes).
  - drm/nouveau: Do not override forced connector status
    (stable-fixes).
  - drm/vkms: Round fixp2int conversion in lerp_u16 (stable-fixes).
  - drm/tests: hdmi: Remove redundant assignments (stable-fixes).
  - drm/amd/display: Fix out-of-bound accesses (stable-fixes).
  - commit f9bc5aa

++++ kernel-firmware-amdgpu:

  - Update to version 20250322 (git commit 710a336b3198):
    * amdgpu: update dcn 4.01 firmware to 0.1.3.0
    * amdgpu: update dcn 3.5 firmware to 0.1.0.0
  - Update kernel-firmware-tools scripts to be downloadable

++++ kernel-rt:

  - i2c: amd-mp2: drop free_irq() of devm_request_irq() allocated
    irq (git-fixes).
  - keys: Fix UAF in key_put() (git-fixes).
  - drm/i915/cdclk: Do cdclk post plane programming later
    (stable-fixes).
  - drm/atomic: Filter out redundant DPMS calls (stable-fixes).
  - drm/amd/amdkfd: Evict all queues even HWS remove queue failed
    (stable-fixes).
  - drm/amd/display: Assign normalized_pix_clk when color depth =
    14 (stable-fixes).
  - drm/amd/display: Restore correct backlight brightness after
    a GPU reset (stable-fixes).
  - drm/amd/display: Disable unneeded hpd interrupts during dm_init
    (stable-fixes).
  - drm/amdgpu/display: Allow DCC for video formats on GFX12
    (stable-fixes).
  - drm/hyperv: Fix address space leak when Hyper-V DRM device is
    removed (git-fixes).
  - drm/nouveau: Do not override forced connector status
    (stable-fixes).
  - drm/vkms: Round fixp2int conversion in lerp_u16 (stable-fixes).
  - drm/tests: hdmi: Remove redundant assignments (stable-fixes).
  - drm/amd/display: Fix out-of-bound accesses (stable-fixes).
  - commit f9bc5aa

++++ libarchive:

  - Update to 3.7.8:
    * 7zip reader: add SPARC and POWERPC filter support for non-LZMA compressors
    * tar reader: Ignore ustar size when pax size is present
    * tar writer: Fix bug when -s/a/b/ used more than once with b flag
    * libarchive: Handle ARCHIVE_FILTER_LZOP in archive_read_append_filter
    * libarchive: Adding missing seeker function to archive_read_open_FILE()
  - inludes the previously patched security fixes, dropping:
    CVE-2025-1632.patch, CVE-2025-25724.patch, CVE-2024-57970.patch

++++ python-cryptography:

  - update to 44.0.2:
    * We now build wheels for PyPy 3.11.

++++ timezone:

  - Update to 2025b:
    * New zone for Aysén Region in Chile (America/Coyhaique) which
    moves from -04/-03 to -03

------------------------------------------------------------------
------------------  2025-3-22  -  Mar 22 2025  -------------------
------------------------------------------------------------------

++++ hwdata:

  - Update to version 0.393:
    * Update pci, usb and vendor ids
    * Fix usb.ids encoding and a couple of typos
    * Fix configure to honor --prefix

++++ kernel-default:

  - Delete patches.suse/sysfs-Add-sys-kernel-realtime-entry.patch.
    No upstrem consensus on whether this is necessary. It's possible the same
    benefit could be achieved within udev with the risk that dynamic preempt
    may cause complications if preemption level changes during udev rule
    resolution.
  - commit f984751
  - Delete
    patches.suse/preempt-Add-a-generic-function-to-return-the-preemption-string.patch.
    Will be replaced by upstream equivalent via SUSE-2025.
  - commit 0d463f4
  - spi: Fix reference count leak in slave_show() (git-fixes).
  - regulator: rtq2208: Fix the LDO DVS capability (git-fixes).
  - regulator: rtq2208: Fix incorrect buck converter phase mapping
    (git-fixes).
  - regulator: dummy: force synchronous probing (git-fixes).
  - regulator: core: Fix deadlock in create_regulator() (git-fixes).
  - spi: microchip-core: prevent RX overflows when transmit size >
    FIFO size (git-fixes).
  - spi: omap2-mcspi: Correctly handle devm_clk_get_optional()
    errors (git-fixes).
  - commit e7c032b

++++ kernel-firmware-ath10k:

  - Correct aliases with comma (bsc#1239877)
  - Update spec to make kernel-firmware-tools downloadable

++++ kernel-firmware-bluetooth:

  - Correct aliases with comma (bsc#1239877)
  - Update spec to make kernel-firmware-tools downloadable

++++ kernel-firmware-media:

  - Correct aliases with comma (bsc#1239877)
  - Update spec to make kernel-firmware-tools downloadable

++++ kernel-firmware-mediatek:

  - Correct aliases with comma (bsc#1239877)
  - Update spec to make kernel-firmware-tools downloadable

++++ kernel-firmware-nvidia:

  - Correct aliases with comma (bsc#1239877)
  - Update spec to make kernel-firmware-tools downloadable

++++ kernel-firmware-platform:

  - Correct aliases with comma (bsc#1239877)
  - Update spec to make kernel-firmware-tools downloadable

++++ kernel-firmware-qcom:

  - Correct aliases with comma (bsc#1239877)
  - Update spec to make kernel-firmware-tools downloadable

++++ kernel-firmware-sound:

  - Correct aliases with comma (bsc#1239877)
  - Update to version 20250321 (git commit e61b8981aeef):
    * cirrus: cs35l41: Add Firmware for various HP Laptops using CS35L41 HDA

++++ kernel-rt:

  - Delete patches.suse/sysfs-Add-sys-kernel-realtime-entry.patch.
    No upstrem consensus on whether this is necessary. It's possible the same
    benefit could be achieved within udev with the risk that dynamic preempt
    may cause complications if preemption level changes during udev rule
    resolution.
  - commit f984751
  - Delete
    patches.suse/preempt-Add-a-generic-function-to-return-the-preemption-string.patch.
    Will be replaced by upstream equivalent via SUSE-2025.
  - commit 0d463f4
  - spi: Fix reference count leak in slave_show() (git-fixes).
  - regulator: rtq2208: Fix the LDO DVS capability (git-fixes).
  - regulator: rtq2208: Fix incorrect buck converter phase mapping
    (git-fixes).
  - regulator: dummy: force synchronous probing (git-fixes).
  - regulator: core: Fix deadlock in create_regulator() (git-fixes).
  - spi: microchip-core: prevent RX overflows when transmit size >
    FIFO size (git-fixes).
  - spi: omap2-mcspi: Correctly handle devm_clk_get_optional()
    errors (git-fixes).
  - commit e7c032b

++++ tiff:

  - Add -DCMAKE_POLICY_VERSION_MINIMUM=3.5 to fix FTBFS with cmake4
  - Add %check section
  - Remove Group: declarations, no longer used

++++ python-cssselect:

  - Remove superfluous %python_module definition

++++ python-setuptools:

  - update to 77.0.3:
    * Temporarily convert error for license glob patterns containing
    ../ into a deprecation warning to allow an accomodation period
    * Better error messages for packaging.
    * Avoided eagerly raising an exception when license-files is
    defined simultaneously inside and outside of pyproject.toml.
    * Added initial support for license expression (PEP 639)
    * Store License-Files in .dist-info/licenses subfolder and
    added support for recursive globs for license_files (PEP 639)
    * Bump core metadata version to 2.4.
    * Updated vendored copy of wheel to v0.45.1

++++ vim:

  - update to 9.1.1230
  - refresh vim-7.3-sh_is_bash.patch
    * patch 9.1.1230: inconsistent CTRL-C behaviour for popup windows
    * patch 9.1.1229: the comment plugin can be improved
    * runtime(sh): consider sh as POSIX shell by default
    * patch 9.1.1228: completion: current position column wrong after got a match
    * runtime(hlyank): add the hlyank package
    * patch 9.1.1227: no tests for the comment package
    * patch 9.1.1226: "shellcmdline" completion doesn't work with input()
    * patch 9.1.1225: extra NULL check in VIM_CLEAR()
    * runtime(sh): remove invalid commented out line in syntax script
    * runtime(sh): update sh indent script
    * patch 9.1.1224: cannot :put while keeping indent
    * runtime(go): use :term for keywordprg for nvim/gvim
    * patch 9.1.1223: wrong translation used for encoding failures
    * patch 9.1.1222: using wrong length for last inserted string
    * patch 9.1.1221: Wrong cursor pos when leaving Insert mode just after 'autoindent'
    * patch 9.1.1220: filetype: uv.lock file not recognized
    * patch 9.1.1219: Strange error with wrong type for matchfuzzy() "camelcase"
    * patch 9.1.1218: missing out-of-memory check in filepath.c
    * patch 9.1.1217: tests: typos in test_matchfuzzy.vim
    * patch 9.1.1216: Pasting the '.' register multiple times may not work
    * runtime(keymap) Add forward slash (/) to russian-jcukenwin keymap
    * runtime(vim): Update base-syntax, match multiline return types
    * patch 9.1.1215: Patch 9.1.1213 has some issues
    * patch 9.1.1214: matchfuzzy() can be improved for camel case matches
    * patch 9.1.1213: cannot :put while keeping indent
    * runtime(syntax-tests): Support "wait-free" test failure
    * patch 9.1.1212: too many strlen() calls in edit.c
    * patch 9.1.1212: filetype: logrotate'd pacmanlogs are not recognized
    * runtime(prql): include prql syntax script
    * patch 9.1.1211: TabClosedPre is triggered just before the tab is being freed
    * patch 9.1.1210: translation(ru): missing Russian translation for the new tutor
    * patch 9.1.1209: colorcolumn not drawn after virtual text lines
    * patch 9.1.1208: MS-Windows: not correctly restoring alternate screen on Win 10
    * patch 9.1.1207: MS-Windows: build warning in filepath.c
    * translation(ru): include Russian translation for chapter two of the tutorial
    * runtime(matchparen): line continuation causes failure in CI
    * patch 9.1.1206: tests: test_filetype fails when a file is a directory
    * runtime(doc): symlinking netrw.txt causes problems during install on Windows
    * patch 9.1.1205: completion: preinserted text not removed when closing pum
    * runtime(tutor): updated Russian translation for tutor chapter 1
    * runtime(cs): Update C# runtime files
    * patch 9.1.1203: matchparen keeps cursor on case label in sh filetype
    * runtime(doc): fix a typo in gitrebase filetype
    * runtime(doc): Tweak documentation style a bit
    * runtime(vim): Sync syntax generator base file with output file.
    * runtime(doc): update a few minor omissions from 5876016 and 4d2c4b9
    * patch 9.1.1202: Missing TabClosedPre autocommand
    * patch 9.1.1201: 'completefuzzycollect' does not handle dictionary correctly
    * runtime(doc): make :h 'completefuzzycollect' a bit clearer
    * runtime(doc): document gitrebase filetype
    * translation(it): update menu_it
    * translation(sr): Add chapter two of the new tutor
    * patch 9.1.1200: cmdline pum not cleared for input() completion
    * patch 9.1.1199: gvim uses hardcoded xpm icon file
    * runtime(indent-tests): GitHub Actions doesn't show why indent tests failed
    * patch 9.1.1198: [security]: potential data loss with zip.vim
    * patch 9.1.1197: process_next_cpt_value() uses wrong condition
    * patch 9.1.1196: filetype: config files for container tools are not recognized
    * runtime(doc): remove unnecessary "an"
    * patch 9.1.1195: inside try-block: fn body executed with default arg undefined
    * runtime(doc): Update doc 52.6
    * runtime(compiler): allow customizing exe and args for tsc
    * runtime(compiler): add comment for Dispatch
    * runtime(tera): remove unwanted code and fix issues in syntax script
    * runtime(doc): clarify that a umask is applied to mkdir()
    * patch 9.1.1194: filetype: false positive help filetype detection
    * runtime(man): improve :Man completion for man-db
    * patch 9.1.1193: Unnecessary use of STRCAT() in au_event_disable()
    * translation(sr): Update Serbian messages translation
    * runtime(doc): document vim syntax switches
    * runtime(vim): Update base-syntax, improve :syntax highlighting
    * patch 9.1.1192: Vim crashes with term response debug logging enabled
    * runtime(vim): Update base-syntax and generator, only match valid predefined variables
    * runtime(plsql): move fold option from syntax to filetype plugin
    * patch 9.1.1191: tests: test for patch 9.1.1186 doesn't fail without the patch
    * patch 9.1.1190: C indentation does not detect multibyte labels
    * runtime(sh): set b:match_skip to ignore matches for matchit
    * patch 9.1.1189: if_python: build error due to incompatible pointer types
    * patch 9.1.1188: runtime(tera): tera support can be improved
    * patch 9.1.1187: matchparen plugin wrong highlights shell case statement
    * runtime(doc): use GNOME instead of Gnome
    * patch 9.1.1186: filetype: help files in git repos are not detected
    * runtime(nohlsearch): fix CursorHold loop
    * runtime(doc): warn users about potentially risky hotkey
    * runtime(syntax-tests): Improve parts of "runtest.vim"
    * patch 9.1.1185: endless loop with completefuzzycollect and no match found
    * runtime(doc): CmdUndefined and FuncUndefined can always be nested
    * patch 9.1.1184: Unnecessary use of vim_tolower() in vim_strnicmp_asc()
    * patch 9.1.1083: "above" virtual text breaks cursorlineopt=number
    * runtime(go): add 'keywordprg' and 'formatprg' to ftplugin
    * runtime(syntax-tests): Re-introduce support for "phoney" languages
    * patch 9.1.1182: No cmdline completion for 'completefuzzycollect'
    * patch 9.1.1181: Unnecessary STRLEN() calls in insexpand.c
    * patch 9.1.1180: short-description
    * runtime(vim): Update base-syntax, bug fixes
    * patch 9.1.1179: too many strlen() calls in misc2.c
    * patch 9.1.1178: not possible to generate completion candidates using fuzzy matching
    * editorconfig: set editing style for comment and hlsearch package
    * patch 9.1.1177: filetype: tera files not detected
    * runtime(doc): revert modeline change in vim9.txt
    * runtime(new-tutor): add chapter two to the interactive tutorial
    * patch 9.1.1176: wrong indent when expanding multiple lines
    * test(runtime/syntax): improve syntax tests
    * editorconfig: set indent config for *.vim files
    * runtime(doc): mention alternative check for vim9script
    * patch 9.1.1175: inconsistent behaviour with exclusive selection and motion commands
    * runtime(man): don't add jumps when loading a manpage
    * runtime(vim): recognize <...> strings (and keys) for 'keywordprg'
    * patch 9.1.1174: tests: Test_complete_cmdline() may fail
    * runtime(doc): mention bzip3 in gzip plugin documentation

------------------------------------------------------------------
------------------  2025-3-21  -  Mar 21 2025  -------------------
------------------------------------------------------------------

++++ combustion:

  - Update to version 1.5:
    * Add support for nested /etc subvolumes
    * Log combustion-prepare.service to journal+console
    * CI: Verify combustion runs only on the first boot
    * CI: Add some missing SYSTEMD_IGNORE_CHROOT=1 to poweroff calls
    * CI: Add a test with Minimal-VM
    * Silence stderr of grep in /proc/*/mountinfo

++++ dracut:

  - Update to version 059+suse.672.g25f25f98:
    * fix(dracut.spec): move znet to the main package (bsc#1239632)
    * feat(lsinitrd.sh): print stored dracut cmdline
    * feat(lsinitrd.sh): enable unpacking files from squash-root.img

++++ python-kiwi:

  - Fixed python3_sitelib for debbuild in OBS
  - Fixed test-image-agama
    Service setup-systemd-proxy-env.path no longer exists

++++ grub2:

  - Filter out the non-subvolume btrfs mount points when creating the
    relative path (bsc#1239674)
    * grub2-btrfs-filter-non-subvol-mount.patch

++++ haproxy:

  - Update to version 3.1.6+git0.d929ca290:
    * [RELEASE] Released version 3.1.6
    * BUILD: tools: avoid a build warning on gcc-4.8 in resolve_sym_name()
    * MINOR: tools: teach resolve_sym_name() a few more common symbols
    * MINOR: tools: ease the declaration of known symbols in resolve_sym_name()
    * MINOR: tools: improve symbol resolution without dl_addr
    * MINOR: cli: export cli_io_handler() to ease symbol resolution
    * BUG/MEDIUM: stream: don't use localtime in dumps from a signal handler
    * MINOR: tinfo: split the signal handler report flags into 3
    * IMPORT: plock: use cpu_relax() for a shorter time in EBO
    * IMPORT: plock: lower the slope of the exponential back-off
    * IMPORT: plock: give higher precedence to W than S
    * BUG/MINOR: mux-h2: Reset streams with NO_ERROR code if full response was already sent
    * BUG/MEDIUM: hlua/cli: fix cli applet UAF in hlua_applet_wakeup()
    * BUG/MINOR: limits: compute_ideal_maxconn: don't cap remain if fd_hard_limit=0
    * BUILD: tools: silence a build warning when USE_THREAD=0
    * MINOR: tools: use only opportunistic symbols resolution
    * BUG/MINOR: stats: fix capabilities and hide settings for some generic metrics
    * DOC: management: rename some last occurences from domain "dns" to "resolvers"
    * MINOR: compiler: add a new __decl_thread_var() macro to declare local variables
    * MINOR: compiler: add a simple macro to concatenate resolved strings
    * BUG/MEDIUM: thread: use pthread_self() not ha_pthread[tid] in set_affinity
    * MINOR: startup: adjust alert messages, when capabilities are missed
    * BUG/MINOR: cfgparse-tcp: relax namespace bind check
    * MINOR: stream/cli: make "show sess" support filtering on front/back/server
    * MINOR: stream/cli: rework "show sess" to better consider optional arguments
    * BUG/MINOR: stream: fix age calculation in "show sess" output
    * MINOR: cfgparse/peers: provide more info when ignoring invalid "peer" or "server" lines
    * BUG/MINOR: server: dont return immediately from parse_server() when skipping checks
    * BUG/MINOR: cfgparse/peers: properly handle ignored local peer case
    * BUG/MINOR: cfgparse/peers: fix inconsistent check for missing peer server
    * BUG/MEIDUM: startup: return to initial cwd only after check_config_validity()
    * BUG/MINOR: log: set proper smp size for balance log-hash
    * CLEANUP: log: removing "log-balance" references
    * CI: github: fix h2spec.config proxy names
    * TESTS: ist: fix wrong array size
    * BUG/MINOR: server: check for either proxy-protocol v1 or v2 to send hedaer
    * BUG/MEDIUM: mux-fcgi: Try to fully fill demux buffer on receive if not empty
    * CLEANUP: h3: fix documentation of h3_rcv_buf()
    * BUG/MINOR: h3: do not report transfer as aborted on preemptive response
    * BUG/MINOR: server: fix the "server-template" prefix memory leak
    * BUG/MEDIUM: server: properly initialize PROXY v2 TLVs
    * BUG/MINOR: h2: always trim leading and trailing LWS in header values
    * BUG/MEDIUM: stream: use non-blocking freq_ctr calls from the stream dumper
    * MINOR: freq_ctr: provide non-blocking read functions
    * BUG/MEDIUM: stream: never allocate connection addresses from signal handler
    * MINOR: tinfo: add a new thread flag to indicate a call from a sig handler
    * BUG/MINOR: mux-h1: always make sure h1s->sd exists in h1_dump_h1s_info()
    * BUG/MINOR: stream: do not call co_data() from __strm_dump_to_buffer()
    * MINOR: clock: always use atomic ops for global_now_ms
    * BUG/MINOR: sink: add tempo between 2 connection attempts for sft servers
    * BUG/MINOR: log: fix outgoing abns address family
    * BUG/MEDIUM: uxst: fix outgoing abns address family in connect()
    * BUG/MINOR: cfgparse: fix NULL ptr dereference in cfg_parse_peers

++++ kernel-default:

  - firmware: qcom: scm: smc: Handle missing SCM device
    (CVE-2024-57852 bsc#1239006).
  - commit a7a0e2d
  - KVM: Explicitly verify target vCPU is online in  kvm_get_vcpu()
    (CVE-2024-58083 bsc#1239036).
  - commit ea92b0c
  - ACPI: processor: idle: Return an error if both P_LVL{2,3}
    idle states are invalid (bsc#1237530).
  - commit c93b04f
  - nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() (CVE-2025-21848
    bsc#1239479).
  - commit 594a7b5
  - lockdown: fix kernel lockdown enforcement issue when secure
    boot is enabled (bsc#1237521).
  - commit f8669a3
  - Delete
    patches.suse/0001-Lock-down-x86_64-kernel-in-secure-boot-mode-in-subsy.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot
    is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
    Refresh
    patches.suse/0001-initcall_blacklist-Does-not-allow-kernel_lockdown-be.patch.
  - commit 5500cb2
  - Delete
    patches.suse/0002-security-Add-a-kernel-lockdown-flag-for-early-boot-s.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot
    is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
    Refresh
    patches.suse/0001-security-create-hidden-area-to-keep-sensitive-data.patch.
  - commit 331aba7
  - Delete
    patches.suse/0003-efi-Set-early-kernel-lock-down-flag-if-booted-in-sec.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot
    is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
  - commit 586858d
  - Delete
    patches.suse/0004-ACPI-Check-early-kernel-lockdown-flag-before-overlay.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure
    boot is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
  - commit 347398a
  - Delete
    patches.suse/0005-kgdb-Check-early-kernel-lockdown-flag-before-using-k.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
  - commit 0872595
  - dma-mapping: fix missing clear bdr in check_ram_in_range_map()
    (git-fixes).
  - commit 3994034
  - tracing: Use preempt_model_str() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - xtensa: Rely on generic printing of preemption model
    (bsc#1234634 (Scheduler functional and performance backports)).
  - x86: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - s390: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - powerpc: Rely on generic printing of preemption model
    (bsc#1234634 (Scheduler functional and performance backports)).
  - arm64: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - arm: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - lib/dump_stack: Use preempt_model_str() (bsc#1234634 (Scheduler
    functional and performance backports)).
    Refresh
  - patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch
  - patches.suse/kernel-add-release-status-to-kernel-build.patch
  - sched: Add a generic function to return the preemption string
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Add unlikey branch hints to several system calls
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Remove duplicate included header file stats.h
    (bsc#1234634 (Scheduler functional and performance backports)).
  - x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/rt: Update limit of sched_rt sysctl in documentation
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 0efe548
  - gve: unlink old napi when stopping a queue using queue API
    (jsc#PED-12442).
  - gve: set xdp redirect target only when it is available
    (jsc#PED-12442).
  - gve: Convert timeouts to secs_to_jiffies() (jsc#PED-12442).
  - net: ena: Fix incorrect indentation (jsc#PED-12441).
  - gve: Remove unused gve_adminq_set_mtu (jsc#PED-12442).
  - eth: gve: use appropriate helper to set xdp_features
    (jsc#PED-12442).
  - gve: trigger RX NAPI instead of TX NAPI in gve_xsk_wakeup
    (jsc#PED-12442).
  - gve: fix XDP allocation path in edge cases (jsc#PED-12442).
  - gve: process XSK TX descriptors as part of RX NAPI
    (jsc#PED-12442).
  - gve: clean XDP queues in gve_tx_stop_ring_gqi (jsc#PED-12442).
  - gve: Flow steering trigger reset only for timeout error
    (jsc#PED-12442).
  - net: ena: remove devm from ethtool (jsc#PED-12441).
  - net: ena: Remove deadcode (jsc#PED-12441).
  - net: ena: Remove autopolling mode (jsc#PED-12441).
  - gve: change to use page_pool_put_full_page when recycling pages
    (jsc#PED-12442).
  - gve: add support for basic queue stats (jsc#PED-12442).
  - gve: adopt page pool for DQ RDA mode (jsc#PED-12442).
  - gve: move DQO rx buffer management related code to a new file
    (jsc#PED-12442).
  - gve: Map NAPI instances to queues (jsc#PED-12442).
  - gve: Map IRQs to NAPI instances (jsc#PED-12442).
  - ena: Link queues to NAPIs (jsc#PED-12441).
  - ena: Link IRQs to NAPI instances (jsc#PED-12441).
  - commit 7e86f33
  - config: drop CONFIG_RTS5208 (jsc#PED-12436)
  - commit aa48231
  - drm/amd/display: Use HW lock mgr for PSR1 when only one eDP
    (git-fixes).
  - drm/amdkfd: Fix user queue validation on Gfx7/8 (git-fixes).
  - drm/amdgpu/gfx12: correct cleanup of 'me' field with
    gfx_v12_0_me_fini() (git-fixes).
  - drm/radeon: fix uninitialized size issue in
    radeon_vce_cs_parse() (git-fixes).
  - drm/xe: Fix exporting xe buffers multiple times (git-fixes).
  - gpu: host1x: Do not assume that a NULL domain means no DMA IOMMU
    (git-fixes).
  - accel/qaic: Fix integer overflow in qaic_validate_req()
    (git-fixes).
  - accel/qaic: Fix possible data corruption in BOs > 2G
    (git-fixes).
  - drm/v3d: Don't run jobs that have errors flagged in its fence
    (git-fixes).
  - drm/sched: Fix fence reference count leak (git-fixes).
  - batman-adv: Ignore own maximum aggregation size during RX
    (git-fixes).
  - Bluetooth: hci_event: Fix connection regression between LE
    and non-LE adapters (git-fixes).
  - Bluetooth: Fix error code in chan_alloc_skb_cb() (git-fixes).
  - phy: fix xa_alloc_cyclic() error handling (git-fixes).
  - can: flexcan: disable transceiver during system PM (git-fixes).
  - can: flexcan: only change CAN state when link up in system PM
    (git-fixes).
  - can: rcar_canfd: Fix page entries in the AFL list (git-fixes).
  - can: ucan: fix out of bound read in strscpy() source
    (git-fixes).
  - mmc: sdhci-brcmstb: add cqhci suspend/resume to PM ops
    (git-fixes).
  - mmc: atmel-mci: Add missing clk_disable_unprepare() (git-fixes).
  - commit b41c1ad
  - RDMA/hns: Fix wrong value of max_sge_rd (git-fixes)
  - commit 27c0c16
  - RDMA/hns: Fix missing xa_destroy() (git-fixes)
  - commit eb7233d
  - RDMA/hns: Fix a missing rollback in error path of hns_roce_create_qp_common() (git-fixes)
  - commit 8cab2f7
  - RDMA/hns: Fix invalid sq params not being blocked (git-fixes)
  - commit 78e84f5
  - RDMA/hns: Fix unmatched condition in error path of alloc_user_qp_db() (git-fixes)
  - commit d091e88
  - RDMA/hns: Fix soft lockup during bt pages loop (git-fixes)
  - commit f21c5dc
  - RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path (git-fixes)
  - commit 0cf903d
  - RDMA/mlx5: Handle errors returned from mlx5r_ib_rate() (git-fixes)
  - commit 6773008
  - RDMA/bnxt_re: Fix reporting maximum SRQs on P7 chips (git-fixes)
  - commit d02de7f
  - RDMA/bnxt_re: Add missing paranthesis in map_qp_id_to_tbl_indx (git-fixes)
  - commit d2797fc
  - RDMA/bnxt_re: Fix allocation of QP table (git-fixes)
  - commit 2120053
  - RDMA/rxe: Fix the failure of ibv_query_device() and ibv_query_device_ex() tests (git-fixes)
  - commit 6ee5467

++++ kernel-firmware-sound:

  - Update to version 20250320 (git commit a60087f7c925):
    * cirrus: Add cs35l56 firmware symlinks for Asus UM5606KA
  - Update kernel-firmware-tools scripts to be downloadable

++++ kernel-rt:

  - firmware: qcom: scm: smc: Handle missing SCM device
    (CVE-2024-57852 bsc#1239006).
  - commit a7a0e2d
  - KVM: Explicitly verify target vCPU is online in  kvm_get_vcpu()
    (CVE-2024-58083 bsc#1239036).
  - commit ea92b0c
  - ACPI: processor: idle: Return an error if both P_LVL{2,3}
    idle states are invalid (bsc#1237530).
  - commit c93b04f
  - nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() (CVE-2025-21848
    bsc#1239479).
  - commit 594a7b5
  - lockdown: fix kernel lockdown enforcement issue when secure
    boot is enabled (bsc#1237521).
  - commit f8669a3
  - Delete
    patches.suse/0001-Lock-down-x86_64-kernel-in-secure-boot-mode-in-subsy.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot
    is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
    Refresh
    patches.suse/0001-initcall_blacklist-Does-not-allow-kernel_lockdown-be.patch.
  - commit 5500cb2
  - Delete
    patches.suse/0002-security-Add-a-kernel-lockdown-flag-for-early-boot-s.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot
    is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
    Refresh
    patches.suse/0001-security-create-hidden-area-to-keep-sensitive-data.patch.
  - commit 331aba7
  - Delete
    patches.suse/0003-efi-Set-early-kernel-lock-down-flag-if-booted-in-sec.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot
    is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
  - commit 586858d
  - Delete
    patches.suse/0004-ACPI-Check-early-kernel-lockdown-flag-before-overlay.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure
    boot is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
  - commit 347398a
  - Delete
    patches.suse/0005-kgdb-Check-early-kernel-lockdown-flag-before-using-k.patch.
    Removed this patch because we will apply
    [PATCH] lockdown: fix kernel lockdown enforcement issue when secure boot is enabled
    from Srish Srinivasan <ssrish@linux.ibm.com>. (bsc#1237521)
  - commit 0872595
  - dma-mapping: fix missing clear bdr in check_ram_in_range_map()
    (git-fixes).
  - commit 3994034
  - tracing: Use preempt_model_str() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - xtensa: Rely on generic printing of preemption model
    (bsc#1234634 (Scheduler functional and performance backports)).
  - x86: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - s390: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - powerpc: Rely on generic printing of preemption model
    (bsc#1234634 (Scheduler functional and performance backports)).
  - arm64: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - arm: Rely on generic printing of preemption model (bsc#1234634
    (Scheduler functional and performance backports)).
  - lib/dump_stack: Use preempt_model_str() (bsc#1234634 (Scheduler
    functional and performance backports)).
    Refresh
  - patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch
  - patches.suse/kernel-add-release-status-to-kernel-build.patch
  - sched: Add a generic function to return the preemption string
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Add unlikey branch hints to several system calls
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Remove duplicate included header file stats.h
    (bsc#1234634 (Scheduler functional and performance backports)).
  - x86/tsc: Always save/restore TSC sched_clock() on suspend/resume
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/rt: Update limit of sched_rt sysctl in documentation
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 0efe548
  - gve: unlink old napi when stopping a queue using queue API
    (jsc#PED-12442).
  - gve: set xdp redirect target only when it is available
    (jsc#PED-12442).
  - gve: Convert timeouts to secs_to_jiffies() (jsc#PED-12442).
  - net: ena: Fix incorrect indentation (jsc#PED-12441).
  - gve: Remove unused gve_adminq_set_mtu (jsc#PED-12442).
  - eth: gve: use appropriate helper to set xdp_features
    (jsc#PED-12442).
  - gve: trigger RX NAPI instead of TX NAPI in gve_xsk_wakeup
    (jsc#PED-12442).
  - gve: fix XDP allocation path in edge cases (jsc#PED-12442).
  - gve: process XSK TX descriptors as part of RX NAPI
    (jsc#PED-12442).
  - gve: clean XDP queues in gve_tx_stop_ring_gqi (jsc#PED-12442).
  - gve: Flow steering trigger reset only for timeout error
    (jsc#PED-12442).
  - net: ena: remove devm from ethtool (jsc#PED-12441).
  - net: ena: Remove deadcode (jsc#PED-12441).
  - net: ena: Remove autopolling mode (jsc#PED-12441).
  - gve: change to use page_pool_put_full_page when recycling pages
    (jsc#PED-12442).
  - gve: add support for basic queue stats (jsc#PED-12442).
  - gve: adopt page pool for DQ RDA mode (jsc#PED-12442).
  - gve: move DQO rx buffer management related code to a new file
    (jsc#PED-12442).
  - gve: Map NAPI instances to queues (jsc#PED-12442).
  - gve: Map IRQs to NAPI instances (jsc#PED-12442).
  - ena: Link queues to NAPIs (jsc#PED-12441).
  - ena: Link IRQs to NAPI instances (jsc#PED-12441).
  - commit 7e86f33
  - config: drop CONFIG_RTS5208 (jsc#PED-12436)
  - commit aa48231
  - drm/amd/display: Use HW lock mgr for PSR1 when only one eDP
    (git-fixes).
  - drm/amdkfd: Fix user queue validation on Gfx7/8 (git-fixes).
  - drm/amdgpu/gfx12: correct cleanup of 'me' field with
    gfx_v12_0_me_fini() (git-fixes).
  - drm/radeon: fix uninitialized size issue in
    radeon_vce_cs_parse() (git-fixes).
  - drm/xe: Fix exporting xe buffers multiple times (git-fixes).
  - gpu: host1x: Do not assume that a NULL domain means no DMA IOMMU
    (git-fixes).
  - accel/qaic: Fix integer overflow in qaic_validate_req()
    (git-fixes).
  - accel/qaic: Fix possible data corruption in BOs > 2G
    (git-fixes).
  - drm/v3d: Don't run jobs that have errors flagged in its fence
    (git-fixes).
  - drm/sched: Fix fence reference count leak (git-fixes).
  - batman-adv: Ignore own maximum aggregation size during RX
    (git-fixes).
  - Bluetooth: hci_event: Fix connection regression between LE
    and non-LE adapters (git-fixes).
  - Bluetooth: Fix error code in chan_alloc_skb_cb() (git-fixes).
  - phy: fix xa_alloc_cyclic() error handling (git-fixes).
  - can: flexcan: disable transceiver during system PM (git-fixes).
  - can: flexcan: only change CAN state when link up in system PM
    (git-fixes).
  - can: rcar_canfd: Fix page entries in the AFL list (git-fixes).
  - can: ucan: fix out of bound read in strscpy() source
    (git-fixes).
  - mmc: sdhci-brcmstb: add cqhci suspend/resume to PM ops
    (git-fixes).
  - mmc: atmel-mci: Add missing clk_disable_unprepare() (git-fixes).
  - commit b41c1ad
  - RDMA/hns: Fix wrong value of max_sge_rd (git-fixes)
  - commit 27c0c16
  - RDMA/hns: Fix missing xa_destroy() (git-fixes)
  - commit eb7233d
  - RDMA/hns: Fix a missing rollback in error path of hns_roce_create_qp_common() (git-fixes)
  - commit 8cab2f7
  - RDMA/hns: Fix invalid sq params not being blocked (git-fixes)
  - commit 78e84f5
  - RDMA/hns: Fix unmatched condition in error path of alloc_user_qp_db() (git-fixes)
  - commit d091e88
  - RDMA/hns: Fix soft lockup during bt pages loop (git-fixes)
  - commit f21c5dc
  - RDMA/bnxt_re: Avoid clearing VLAN_ID mask in modify qp path (git-fixes)
  - commit 0cf903d
  - RDMA/mlx5: Handle errors returned from mlx5r_ib_rate() (git-fixes)
  - commit 6773008
  - RDMA/bnxt_re: Fix reporting maximum SRQs on P7 chips (git-fixes)
  - commit d02de7f
  - RDMA/bnxt_re: Add missing paranthesis in map_qp_id_to_tbl_indx (git-fixes)
  - commit d2797fc
  - RDMA/bnxt_re: Fix allocation of QP table (git-fixes)
  - commit 2120053
  - RDMA/rxe: Fix the failure of ibv_query_device() and ibv_query_device_ex() tests (git-fixes)
  - commit 6ee5467

++++ openssl-3:

  - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224]
    * Add openssl-FIPS-Mark-SHA1-as-nonapproved.patch

++++ openvswitch:

  - Update OVN to 25.03.0 for a list of changes, check
    https://github.com/ovn-org/ovn/blob/v25.03.0/NEWS (jsc#PED-11228)
  - Update openvswitch to 3.5.0 for a list of changes, check
    https://www.openvswitch.org/releases/NEWS-3.5.0.txt (jsc#PED-11228)
  - Rename "python3-ovs" to "python3-openvswitch" for distro consistency
  - Update patch file 0001-Use-strongswan-for-openvswitch-ipsec-service.patch

++++ libsoup:

  - Update to version 3.6.5 (boo#1241263):
    + session: Strip authentication credentials on cross-origin
    redirects
    + build: Use pkg-config instead of krb5-config for the gssapi
    dependency
    + http1: When using chunked encoding report an error in case of
    unexpected stream end
    + http2:
  - When a message has no content still respect its Content-Type
  - Revert manual window size management temporarily, as it could
    stall
    + sniffer: Fix potential overflows
    + hsts: Fix minor leak
    + headers: Fix a few parsing edge cases that could be an out of
    bound read
    + connection: Avoid ever calling disconnect twice
    + auth-digest: Fix handling when a nonce isn't present
    + cookies:
  - Limit max size of max-age, path, and domain attributes to
    1024 bytes
  - Limit max size of name and value to 4096 bytes
    + docs: Remove references to old libsoup domain
    + Reintroduce some thread-safety to SoupSession (see
    https://libsoup.gnome.org/libsoup-3.0/client-thread-safety.html)
    Numerous API have been changed which is documented on
    https://libsoup.gnome.org
  - Replace pkgconfig(krb5) with pkgconfig(krb5-gssapi)
    BuildRequires: Following upstream changes, and stop passing
    krb5_config="$(which krb5-config)" to meson setup, no longer
    needed nor recognized.

++++ libvirt:

  - spec: Disable rbd storage driver for SLFO
    bsc#1239836

++++ wayland:

  - Disable test on loongarch.

++++ python-bcrypt:

  - Update 4.3.0
    * Bump proc-macro2 from 1.0.89 to 1.0.90 in /src/_bcrypt (#916)
    * Bump unicode-ident from 1.0.13 to 1.0.14 in /src/_bcrypt (#915)
    * fixes #917 -- correctly handle a salt that's too short (#918)
    * Bump cpufeatures from 0.2.15 to 0.2.16 in /src/_bcrypt (#919)
    * Bump proc-macro2 from 1.0.90 to 1.0.92 in /src/_bcrypt (#920)
    * Bump syn from 2.0.87 to 2.0.89 in /src/_bcrypt (#921)
    * Fix new ruff warning (#923)
    * Build manylinux 2.34 images (#922)
    * Bump portable-atomic from 1.9.0 to 1.10.0 in /src/_bcrypt (#924)
    * drop py37 (#926)
    * Bump pyo3 from 0.23.1 to 0.23.2 in /src/_bcrypt (#927)
    * Bump libc from 0.2.164 to 0.2.165 in /src/_bcrypt (#928)
    * Bump libc from 0.2.165 to 0.2.166 in /src/_bcrypt (#929)
    * Bump dawidd6/action-download-artifact from 6 to 7 (#932)
    * Bump syn from 2.0.89 to 2.0.90 in /src/_bcrypt (#931)
    * Bump libc from 0.2.166 to 0.2.167 in /src/_bcrypt (#930)
    * Bump pyo3 from 0.23.2 to 0.23.3 in /src/_bcrypt (#933)
    * Bump actions/cache from 4.1.2 to 4.2.0 (#934)
    * Bump libc from 0.2.167 to 0.2.168 in /src/_bcrypt (#935)
    * Bump pypa/gh-action-pypi-publish from 1.12.2 to 1.12.3 (#936)
    * Bump dtolnay/rust-toolchain (#937)
    * Bump actions/upload-artifact from 4.4.3 to 4.5.0 (#938)
    * Bump libc from 0.2.168 to 0.2.169 in /src/_bcrypt (#939)
    * Bump syn from 2.0.90 to 2.0.91 in /src/_bcrypt (#940)
    * Bump quote from 1.0.37 to 1.0.38 in /src/_bcrypt (#942)
    * Bump syn from 2.0.91 to 2.0.92 in /src/_bcrypt (#941)
    * Bump syn from 2.0.92 to 2.0.93 in /src/_bcrypt (#943)
    * Bump syn from 2.0.93 to 2.0.94 in /src/_bcrypt (#944)
    * Bump syn from 2.0.94 to 2.0.95 in /src/_bcrypt (#945)
    * Bump syn from 2.0.95 to 2.0.96 in /src/_bcrypt (#948)
    * Bump actions/upload-artifact from 4.5.0 to 4.6.0 (#947)
    * Bump proc-macro2 from 1.0.92 to 1.0.93 in /src/_bcrypt (#949)
    * Bump pyo3 from 0.23.3 to 0.23.4 in /src/_bcrypt (#950)
    * Support free-threaded Python 3.13 (#925)
    * Switch to nox (#954)
    * use github hosted arm runners in wheel builder (#952)
    * use github hosted arm runners in ci (#951)
    * Bump dawidd6/action-download-artifact from 7 to 8 (#956)
    * Bump pypa/gh-action-pypi-publish from 1.12.3 to 1.12.4 (#957)
    * Bump unicode-ident from 1.0.14 to 1.0.15 in /src/_bcrypt (#958)
    * include matrix.PYTHON.VERSION in CI cache keys (#964)
    * Bump cpufeatures from 0.2.16 to 0.2.17 in /src/_bcrypt (#960)
    * Bump unicode-ident from 1.0.15 to 1.0.16 in /src/_bcrypt (#962)
    * Bump actions/setup-python from 5.3.0 to 5.4.0 (#963)
    * Update getrandom and bcrypt (#966)
    * Bump syn from 2.0.96 to 2.0.98 in /src/_bcrypt (#967)
    * Bump quansight-labs/setup-python from 5.3.1 to 5.4.0 (#968)
    * add support for free-threaded wheels (#955)
    * Bump once_cell from 1.20.2 to 1.20.3 in /src/_bcrypt (#970)
    * Bump unicode-ident from 1.0.16 to 1.0.17 in /src/_bcrypt (#972)
    * Bump typenum from 1.17.0 to 1.18.0 in /src/_bcrypt (#973)
    * Bump actions/cache from 4.2.0 to 4.2.1 (#974)
    * Bump actions/upload-artifact from 4.6.0 to 4.6.1 (#975)
    * Bump libc from 0.2.169 to 0.2.170 in /src/_bcrypt (#976)
    * Bump inout from 0.1.3 to 0.1.4 in /src/_bcrypt (#977)
    * Bump portable-atomic from 1.10.0 to 1.11.0 in /src/_bcrypt (#978)
    * Update PyO3 to 0.23.5 (#980)
    * Bump actions/download-artifact from 4.1.8 to 4.1.9 (#982)
    * Add PyPy 3.11 and armv7l to matrix runner (#983)
    * PyPy 3.11 and armv7l wheels (#984)

++++ velociraptor-client:

  - Update to version 0.7.0.4.git152.fb24dfd:
    * audit: fix watch rules in artifacts
    * audit: update go-libaudit dependency for pcc64le arch filter fix
    * Use execsnoop plugin in artifacts when possible
    * Add execsnoop plugin to capture execve system calls
    * github-actions: update ubuntu runners to 22.04
    * Fix failing tls unit test on new go versions

------------------------------------------------------------------
------------------  2025-3-20  -  Mar 20 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - fixed build on SLE16

++++ Mesa-drivers:

  - fixed build on SLE16

++++ docker:

  - Make container-selinux requirement conditional on selinux-policy
    (bsc#1237367)

++++ kernel-default:

  - Update MIN RMA patch metadata.
  - commit 397880c
  - scsi: core: Update API documentation (jsc#PED-11374).
  - commit afbed9f
  - scsi: core: Remove the .slave_configure() method
    (jsc#PED-11374).
  - commit e23ac39
  - scsi: Convert SCSI drivers to .sdev_configure() (jsc#PED-11374).
  - commit f727f99
  - scsi: Rename .device_configure() into .sdev_configure()
    (jsc#PED-11374).
  - commit da24907
  - scsi: Rename .slave_alloc() and .slave_destroy()
    (jsc#PED-11374).
  - commit 15bec2e
  - powerpc/pseries: Add a char driver for physical-attestation RTAS
    (jsc#PED-4486).
  - powerpc/pseries: Add papr-platform-dump character driver for
    dump retrieval (jsc#PED-4486).
  - powerpc/pseries: Add ibm,get-dynamic-sensor-state RTAS call
    support (jsc#PED-4486).
  - powerpc/pseries: Add ibm,set-dynamic-indicator RTAS call support
    (jsc#PED-4486).
  - powerpc/pseries: Add papr-indices char driver for
    ibm,get-indices (jsc#PED-4486).
  - powerpc/pseries: Define papr_indices_io_block for papr-indices
    ioctls (jsc#PED-4486).
  - powerpc/pseries: Define common functions for RTAS sequence calls
    (jsc#PED-4486).
  - commit c1d4c4f
  - ata: libata-sff: Ensure that we cannot write outside the
    allocated buffer (git-fixes).
  - commit 3d8b30d
  - tools/power turbostat: version 2025.02.02 (jsc#PED-10489).
  - commit 7bf3da6
  - tools/power turbostat: Add CPU%c1e BIC for CWF (jsc#PED-10489).
  - commit 8256a23
  - tools/power turbostat: Harden one-shot mode against cpu offline
    (jsc#PED-10489).
  - commit 366d8e0
  - tools/power turbostat: Fix forked child affinity regression
    (jsc#PED-10489).
  - commit 6366db1
  - tools/power turbostat: Add tcore clock PMT type (jsc#PED-10489).
  - commit afcffd8
  - tools/power turbostat: version 2025.01.14 (jsc#PED-10489).
  - commit ca12a02
  - tools/power turbostat: Allow adding PMT counters directly by
    sysfs path (jsc#PED-10489).
  - commit 37b1df6
  - tools/power turbostat: Allow mapping multiple PMT files with
    the same GUID (jsc#PED-10489).
  - commit 8a90e6f
  - tools/power turbostat: Add PMT directory iterator helper
    (jsc#PED-10489).
  - commit 75d1b39
  - tools/power turbostat: Extend PMT identification with a sequence
    number (jsc#PED-10489).
  - commit 0290a7e
  - tools/power turbostat: Return default value for unmapped PMT
    domains (jsc#PED-10489).
  - commit 9817bf4
  - tools/power turbostat: Check for non-zero value when MSR probing
    (jsc#PED-10489).
  - commit a43d1f2
  - tools/power turbostat: Enhance turbostat self-performance
    visibility (jsc#PED-10489).
  - commit 6c19cae
  - tools/power turbostat: Add fixed RAPL PSYS divisor for SPR
    (jsc#PED-10489).
  - commit bf6f8ef
  - tools/power turbostat: Fix PMT mmaped file size rounding
    (jsc#PED-10489).
  - commit cf7c965
  - tools/power turbostat: Remove SysWatt from DISABLED_BY_DEFAULT
    (jsc#PED-10489).
  - commit af2594a
  - tools/power turbostat: Add an NMI column (jsc#PED-10489).
  - commit 5470be6
  - tools/power turbostat: add Busy% to "show idle" (jsc#PED-10489).
  - commit 3646652
  - tools/power turbostat: Introduce --force parameter
    (jsc#PED-10489).
  - commit 23ebcd1
  - tools/power turbostat: Improve --help output (jsc#PED-10489).
  - commit b1c1e48
  - tools/power turbostat: Exit on unsupported Vendors
    (jsc#PED-10489).
  - commit 9955156
  - tools/power turbostat: Exit on unsupported Intel models
    (jsc#PED-10489).
  - commit ac6ed96
  - tools/power turbostat: update turbostat(8) (jsc#PED-10489).
  - commit 4189edc
  - tools/power turbostat: Add initial support for ClearwaterForest
    (jsc#PED-10489).
  - commit 00868a5
  - tools/power turbostat: Add initial support for PantherLake
    (jsc#PED-10489).
  - commit 6c786e0
  - tools/power turbostat: 2024.11.30 (jsc#PED-10489).
  - commit befcb16
  - tools/power turbostat: Add RAPL psys as a built-in counter
    (jsc#PED-10489).
  - commit 461da30
  - tools/power turbostat: Force --no-perf in --dump mode
    (jsc#PED-10489).
  - commit c44095e
  - tools/power turbostat: Add support for /sys/class/drm/card1
    (jsc#PED-10489).
  - commit 58cfa1c
  - tools/power turbostat: Cache graphics sysfs file descriptors
    during probe (jsc#PED-10489).
  - commit 1bd8b6e
  - tools/power turbostat: Consolidate graphics sysfs access
    (jsc#PED-10489).
  - commit 0f0ae6c
  - tools/power turbostat: Remove unnecessary fflush() call
    (jsc#PED-10489).
  - commit 044a10d
  - tools/power turbostat: Enhance platform divergence description
    (jsc#PED-10489).
  - commit 5a915ac
  - tools/power turbostat: Remove PC3 support on Lunarlake
    (jsc#PED-10489).
  - commit 5cdff5e
  - tools/power turbostat: Rename arl_features to lnl_features
    (jsc#PED-10489).
  - commit 71430ca
  - tools/power turbostat: Add back PC8 support on Arrowlake
    (jsc#PED-10489).
  - commit 1469155
  - tools/power turbostat: Remove PC7/PC9 support on MTL
    (jsc#PED-10489).
  - commit adf5534
  - tools/power turbostat: Honor --show CPU, even when even when
    num_cpus=1 (jsc#PED-10489).
  - commit dffe523
  - tools/power turbostat: Allow using cpu device in perf counters
    on hybrid platforms (jsc#PED-10489).
  - commit adc2554
  - tools/power turbostat: Fix column printing for PMT xtal_time
    counters (jsc#PED-10489).
  - commit 5fa62f1
  - tools/power turbostat: fix GCC9 build regression
    (jsc#PED-10489).
  - commit 50f1052
  - config: s390x: update using run_oldconfig.sh
  - commit fc516b9
  - arm64: dts: rockchip: Add missing PCIe supplies to RockPro64 board (git-fixes)
  - commit e3ff48c
  - arm64: dts: rockchip: Add avdd HDMI supplies to RockPro64 board dtsi (git-fixes)
  - commit 5516b5a
  - arm64: dts: rockchip: Remove undocumented sdmmc property from (git-fixes)
  - commit 638d95e
  - arm64: dts: rockchip: fix pinmux of UART5 for PX30 Ringneck on Haikou (git-fixes)
  - commit 80f0a4f
  - arm64: dts: rockchip: fix pinmux of UART0 for PX30 Ringneck on Haikou (git-fixes)
  - commit fedab81
  - arm64: dts: rockchip: remove supports-cqe from rk3588 tiger (git-fixes)
  - commit 178b294
  - arm64: dts: rockchip: remove supports-cqe from rk3588 jaguar (git-fixes)
  - commit 3a1de74
  - arm64: dts: freescale: imx8mm-verdin-dahlia: add Microphone Jack to (git-fixes)
  - commit d13da10
  - arm64: dts: freescale: imx8mp-verdin-dahlia: add Microphone Jack to (git-fixes)
  - commit f19dbca
  - arm64: dts: freescale: tqma8mpql: Fix vqmmc-supply (git-fixes)
  - commit 5d6cf39
  - arm64: dts: bcm2712: PL011 UARTs are actually r1p5 (git-fixes)
  - commit 965834f
  - arm64: mm: Populate vmemmap at the page level if not section aligned (git-fixes)
  - commit 11d7647

++++ kernel-firmware-mediatek:

  - Update to version 20250319 (git commit b8828772e413):
    * mediatek: Add MT8188 SCP firmware

++++ kernel-firmware-qcom:

  - Update to version 20250319 (git commit b8828772e413):
    * qcom: Add DSP firmware for QCS8300 platform

++++ kernel-rt:

  - Update MIN RMA patch metadata.
  - commit 397880c
  - scsi: core: Update API documentation (jsc#PED-11374).
  - commit afbed9f
  - scsi: core: Remove the .slave_configure() method
    (jsc#PED-11374).
  - commit e23ac39
  - scsi: Convert SCSI drivers to .sdev_configure() (jsc#PED-11374).
  - commit f727f99
  - scsi: Rename .device_configure() into .sdev_configure()
    (jsc#PED-11374).
  - commit da24907
  - scsi: Rename .slave_alloc() and .slave_destroy()
    (jsc#PED-11374).
  - commit 15bec2e
  - powerpc/pseries: Add a char driver for physical-attestation RTAS
    (jsc#PED-4486).
  - powerpc/pseries: Add papr-platform-dump character driver for
    dump retrieval (jsc#PED-4486).
  - powerpc/pseries: Add ibm,get-dynamic-sensor-state RTAS call
    support (jsc#PED-4486).
  - powerpc/pseries: Add ibm,set-dynamic-indicator RTAS call support
    (jsc#PED-4486).
  - powerpc/pseries: Add papr-indices char driver for
    ibm,get-indices (jsc#PED-4486).
  - powerpc/pseries: Define papr_indices_io_block for papr-indices
    ioctls (jsc#PED-4486).
  - powerpc/pseries: Define common functions for RTAS sequence calls
    (jsc#PED-4486).
  - commit c1d4c4f
  - ata: libata-sff: Ensure that we cannot write outside the
    allocated buffer (git-fixes).
  - commit 3d8b30d
  - tools/power turbostat: version 2025.02.02 (jsc#PED-10489).
  - commit 7bf3da6
  - tools/power turbostat: Add CPU%c1e BIC for CWF (jsc#PED-10489).
  - commit 8256a23
  - tools/power turbostat: Harden one-shot mode against cpu offline
    (jsc#PED-10489).
  - commit 366d8e0
  - tools/power turbostat: Fix forked child affinity regression
    (jsc#PED-10489).
  - commit 6366db1
  - tools/power turbostat: Add tcore clock PMT type (jsc#PED-10489).
  - commit afcffd8
  - tools/power turbostat: version 2025.01.14 (jsc#PED-10489).
  - commit ca12a02
  - tools/power turbostat: Allow adding PMT counters directly by
    sysfs path (jsc#PED-10489).
  - commit 37b1df6
  - tools/power turbostat: Allow mapping multiple PMT files with
    the same GUID (jsc#PED-10489).
  - commit 8a90e6f
  - tools/power turbostat: Add PMT directory iterator helper
    (jsc#PED-10489).
  - commit 75d1b39
  - tools/power turbostat: Extend PMT identification with a sequence
    number (jsc#PED-10489).
  - commit 0290a7e
  - tools/power turbostat: Return default value for unmapped PMT
    domains (jsc#PED-10489).
  - commit 9817bf4
  - tools/power turbostat: Check for non-zero value when MSR probing
    (jsc#PED-10489).
  - commit a43d1f2
  - tools/power turbostat: Enhance turbostat self-performance
    visibility (jsc#PED-10489).
  - commit 6c19cae
  - tools/power turbostat: Add fixed RAPL PSYS divisor for SPR
    (jsc#PED-10489).
  - commit bf6f8ef
  - tools/power turbostat: Fix PMT mmaped file size rounding
    (jsc#PED-10489).
  - commit cf7c965
  - tools/power turbostat: Remove SysWatt from DISABLED_BY_DEFAULT
    (jsc#PED-10489).
  - commit af2594a
  - tools/power turbostat: Add an NMI column (jsc#PED-10489).
  - commit 5470be6
  - tools/power turbostat: add Busy% to "show idle" (jsc#PED-10489).
  - commit 3646652
  - tools/power turbostat: Introduce --force parameter
    (jsc#PED-10489).
  - commit 23ebcd1
  - tools/power turbostat: Improve --help output (jsc#PED-10489).
  - commit b1c1e48
  - tools/power turbostat: Exit on unsupported Vendors
    (jsc#PED-10489).
  - commit 9955156
  - tools/power turbostat: Exit on unsupported Intel models
    (jsc#PED-10489).
  - commit ac6ed96
  - tools/power turbostat: update turbostat(8) (jsc#PED-10489).
  - commit 4189edc
  - tools/power turbostat: Add initial support for ClearwaterForest
    (jsc#PED-10489).
  - commit 00868a5
  - tools/power turbostat: Add initial support for PantherLake
    (jsc#PED-10489).
  - commit 6c786e0
  - tools/power turbostat: 2024.11.30 (jsc#PED-10489).
  - commit befcb16
  - tools/power turbostat: Add RAPL psys as a built-in counter
    (jsc#PED-10489).
  - commit 461da30
  - tools/power turbostat: Force --no-perf in --dump mode
    (jsc#PED-10489).
  - commit c44095e
  - tools/power turbostat: Add support for /sys/class/drm/card1
    (jsc#PED-10489).
  - commit 58cfa1c
  - tools/power turbostat: Cache graphics sysfs file descriptors
    during probe (jsc#PED-10489).
  - commit 1bd8b6e
  - tools/power turbostat: Consolidate graphics sysfs access
    (jsc#PED-10489).
  - commit 0f0ae6c
  - tools/power turbostat: Remove unnecessary fflush() call
    (jsc#PED-10489).
  - commit 044a10d
  - tools/power turbostat: Enhance platform divergence description
    (jsc#PED-10489).
  - commit 5a915ac
  - tools/power turbostat: Remove PC3 support on Lunarlake
    (jsc#PED-10489).
  - commit 5cdff5e
  - tools/power turbostat: Rename arl_features to lnl_features
    (jsc#PED-10489).
  - commit 71430ca
  - tools/power turbostat: Add back PC8 support on Arrowlake
    (jsc#PED-10489).
  - commit 1469155
  - tools/power turbostat: Remove PC7/PC9 support on MTL
    (jsc#PED-10489).
  - commit adf5534
  - tools/power turbostat: Honor --show CPU, even when even when
    num_cpus=1 (jsc#PED-10489).
  - commit dffe523
  - tools/power turbostat: Allow using cpu device in perf counters
    on hybrid platforms (jsc#PED-10489).
  - commit adc2554
  - tools/power turbostat: Fix column printing for PMT xtal_time
    counters (jsc#PED-10489).
  - commit 5fa62f1
  - tools/power turbostat: fix GCC9 build regression
    (jsc#PED-10489).
  - commit 50f1052
  - config: s390x: update using run_oldconfig.sh
  - commit fc516b9
  - arm64: dts: rockchip: Add missing PCIe supplies to RockPro64 board (git-fixes)
  - commit e3ff48c
  - arm64: dts: rockchip: Add avdd HDMI supplies to RockPro64 board dtsi (git-fixes)
  - commit 5516b5a
  - arm64: dts: rockchip: Remove undocumented sdmmc property from (git-fixes)
  - commit 638d95e
  - arm64: dts: rockchip: fix pinmux of UART5 for PX30 Ringneck on Haikou (git-fixes)
  - commit 80f0a4f
  - arm64: dts: rockchip: fix pinmux of UART0 for PX30 Ringneck on Haikou (git-fixes)
  - commit fedab81
  - arm64: dts: rockchip: remove supports-cqe from rk3588 tiger (git-fixes)
  - commit 178b294
  - arm64: dts: rockchip: remove supports-cqe from rk3588 jaguar (git-fixes)
  - commit 3a1de74
  - arm64: dts: freescale: imx8mm-verdin-dahlia: add Microphone Jack to (git-fixes)
  - commit d13da10
  - arm64: dts: freescale: imx8mp-verdin-dahlia: add Microphone Jack to (git-fixes)
  - commit f19dbca
  - arm64: dts: freescale: tqma8mpql: Fix vqmmc-supply (git-fixes)
  - commit 5d6cf39
  - arm64: dts: bcm2712: PL011 UARTs are actually r1p5 (git-fixes)
  - commit 965834f
  - arm64: mm: Populate vmemmap at the page level if not section aligned (git-fixes)
  - commit 11d7647

++++ libusb-1_0:

  - Update to version 1.0.28
    * New libusb_get_ssplus_usb_device_capability_descriptor API
    for query of SuperSpeed+ Capability Descriptors
    * API support for reporting USB 3.2 Gen2x2 speeds
    * macOS: Fix Zero-Length Packet for multiple packets per frame
    * Windows: Base HID device descriptor on OS-cached values
    * Build fixes for Haiku and SunOS
    * Many code correctness fixes

++++ open-vm-tools:

  - remove unused pcre build dependency

++++ mailx:

  - drop unneeded pcre build dependency

++++ passt:

  - Update to version 20250320.32f6212:
    * Makefile: Enable -Wformat-security
    * conf: Include libgen.h for basename(), fix build against musl
    * tcp: Flush socket before checking for more data in active close state
    * migrate: Bump migration version number
    * migrate, tcp: Migrate RFC 7323 timestamp
    * migrate, tcp: More careful marshalling of mss parameter during migration
    * passt-repair: Fix build with -Werror=format-security
    * tcp, flow: Better use flow specific logging heleprs
    * conf: Unify several paths in conf_ports()
    * test/perf: Simplify iperf3 server lifetime management
    * conf: Limit maximum MTU based on backend frame size
    * pcap: Correctly set snaplen based on tap backend type
    * Simplify sizing of pkt_buf
    * tap: Use explicit defines for maximum length of L2 frame
    * packet: Remove redundant TAP_BUF_BYTES define
    * packet: Give explicit name to maximum packet size
    * conf: Detect vhost-user mode earlier
    * conf: Move mode detection into helper function
    * conf: Use the same optstring for passt and pasta modes
    * flow, repair: Wait for a short while for passt-repair to connect
    * passt-repair: Add directory watch
    * cppcheck: Add suppressions for "logically" exported functions
    * vhost_user: Don't export several functions
    * tcp: Don't export tcp_update_csum()
    * checksum: Don't export various functions
    * log: Don't export passt_vsyslog()
    * treewide: Mark assorted functions static
    * udp: create and send ICMPv6 to local peer when applicable
    * tap: break out building of udp header from tap_udp6_send function
    * udp: create and send ICMPv4 to local peer when applicable
    * tap: break out building of udp header from tap_udp4_send function
    * conf: Be more precise about minimum MTUs
    * tcp: Send RST in response to guest packets that match no connection
    * tap: Consider IPv6 flow label when building packet sequences
    * ip: Helpers to access IPv6 flow label
    * migrate, tcp: Don't flow_alloc_cancel() during incoming migration
    * tcp: Unconditionally move to CLOSED state on tcp_rst()
    * tcp: Correct error code handling from tcp_flow_repair_socket()
    * migrate, flow: Don't attempt to migrate TCP flows without passt-repair
    * migrate, flow: Trivially succeed if migrating with no flows
    * selinux: Fixes/workarounds for passt and passt-repair, mostly for libvirt usage
    * seccomp.sh: Silence stty errors
    * tap: always set the no_frag flag in IPv4 headers
    * contrib/fedora: Actually install passt-repair SELinux policy file
    * dhcp: Add option code byte in calculation for OPT_MAX boundary check
    * Makefile: Use mmap2() as alternative for mmap() in valgrind extra syscalls
    * conf: Use 0 instead of -1 as "unassigned" mtu value
    * conf: More thorough error checking when parsing --mtu option
    * flow: Clean up and generalise flow traversal macros
    * flow: Remove unneeded bound parameter from flow traversal macros
    * flow: Remove unneeded index from foreach_* macros
    * flow: Add flow_perror() helper
    * tcp: Don't pass both flow pointer and flow index
    * tcp: Remove spurious prototype for tcp_flow_migrate_shrink_window
    * tcp: More type safety for tcp_flow_migrate_target_ext()
    * tcp_vu: head_cnt need not be global
    * tap: Remove unused ETH_HDR_INIT() macro
    * packet: Don't pass start and offset separately to packet_check_range()
    * packet: Use flexible array member in struct pool
    * dhcp: Remove option 255 length byte

++++ perl:

  - Drop BerkeleyDB support from core perl [jsc#PED-12413]

++++ python-cssselect:

  - Update to 1.3.0
    * Dropped support for Python 3.7-3.8, added support for
    Python 3.12-3.13 and PyPy 3.10.
    * Removed ``_unicode_safe_getattr()``, deprecated in 1.2.0.
    * Added ``pre-commit`` and formatted the code with ``ruff``.
    * Many CI additions and improvements.
  - Limit Python files matched in %files section
  - Switch build system from setuptools to pyproject.toml
    * Add python-pip and python-wheel to BuildRequires
    * Replace %python_build with %pyproject_wheel
    * Replace %python_install with %pyproject_install

++++ selinux-policy:

  - Update to version 20241031+git516.1a75276b:
    * rebootmgr: Handle config under /etc/rebootmgr (bsc#1239720)
    * health-checker-plugin: Move from dbus to varlink for rebootmgr communication (bsc#1237273)
    * Introduce rebootmgr_var_run_t for files under run (bsc#1237273)
    * Adjust to correct new binary path (bsc#1237273)
    * health-checker: allow snapshot rollback (bsc#1235860)
    * snapper: add interface to select the next boot snapshot
    * Label wine's windows libraries as textrel_shlib_t (bsc#1239317)
    * Allow auth_use_pam to create /var/lib/wtmpdb (bsc#1237513)
    * initial labeling for Hana systems
    * allow ping to bind generic UDP nodes
    * allow systemd_pcrlock_t to manage dos directories (bsc#1233358)
    * Allow snapper to manage dos files and dontaudit execmem (bsc#1233358)
    * enabled filed name transitions for systemd_pcrlock (bsc#1233358)
    * Update kmscon policy module to kmscon version 9 (bsc#1238137)
    * Revert "Allow systemd-networkd to rw memfd objects in tmpfs (bsc#1237515)"
    * Label /var/log/php-fpm.log httpd_log_t (bsc#1238403)
    * Allow systemd-networkd to rw memfd objects in tmpfs (bsc#1237515)
    * Add a gitlab-ci build test
    * allow ssh-keygen to connect to the ssh daemon via vsockets (bsc#1238191)
    * Add context for plymouth debug log files (bsc#1237440)
    * Remove duplicate dev_rw_dma_dev(xdm_t)
    * Allow thumbnailer read and write the dma device
    * Allow named_filetrans_domain filetrans raid/mdadm named content
    * Allow afterburn to mount and read config drives
    * dist/targeted/modules.conf: Enable kmscon module (bsc#1238137)
    * Allow mptcpd the net_admin capability
    * label apache2 binaries correctly (bsc#1237596)
    * Label /run/systemd/pcrlock.json systemd_pcrlock_var_lib_t
    * systemd_pcrlock_t needs to filetrans when recreating /var/lib/pcrlock.d
    * Allow snapper access to keys
    * Add rules for pcrlock (bsc#1233358)
    * allow snapper to call pcrlock and manage its files
    * allow unconfined_t to execute pcrlock
    * label rules for default systemd_pcrlock_var_lib_t locations
    * new interfaces: systemd_domtrans_pcrlock and systemd_pcrlock_exec
    * introduce systemd_pcrlock_var_lib_t and systemd_manage_pcrlock_files
    * Introduce interfaces snapper_manage_tmp_files and snapper_manage_tmp_dirs
    * Allow named_filetrans_domain filetrans raid/mdadm named content (bsc#1236807)
    * Grant privoxy_t the sys_chroot capability (bsc#1237375)
    * Allow init_t nnp_transition to tor_t (bsc#1237375)
    * Allow systemd-networkd the sys_admin capability
    * Update systemd-networkd policy in systemd v257
    * Separate insights-core from insights-client
    * Removed unused insights_client interfaces calls from other modules
    * Update policy for insights_client wrt new rules for insights_core_t
    * Add policy for insights-core
    * Allow systemd-networkd use its private tmpfs files
    * Allow boothd connect to systemd-machined over a unix socket
    * Update init_explicit_domain() interface
    * Allow tlp to read/write nmi_watchdog state information
    * Allow power-profiles-daemon the bpf capability
    * Allow svirt_t to connect to nbdkit over a unix stream socket
    * Update ktlshd policy to read /proc/keys and domain keyrings
    * Allow virt_domain read hardware state information unconditionally
    * Allow init mounton crypto sysctl files
    * Rename winbind_rpcd_* types to samba_dcerpcd_*
    * Support peer-to-peer migration of vms using ssh
    * Allow virtqemud use hostdev usb devices conditionally
    * Allow virtqemud map svirt_image_t plain files
    * Allow virtqemud work with nvdimm devices
    * Support saving and restoring a VM to/from a block device
    * Allow virtnwfilterd dbus chat with firewalld
  - Update embedded container-selinux version to commit:
    * c9b3eca0e1a878a1fe79408cb6c2e89b38b10829

++++ supportutils:

  - Changes to version 3.2.10
    + network.txt collect all firewalld zones (pr#233)
    + Collects gfs2 info (PED-11853, pr#235, pr#236)
    + Ignore tasks/threads to prevent collecting duplicate fd data in open_files (bsc#1230371, pr#237)
    + Added openldap2_5 support for SLES (pr#238)
    + Collects additional hawk details (pr#239)
    + Optimized filtering D/Z processes (pr#241)
    + Collect firewalld permanent configuration (pr#243)
    + ldap_info: support for multiple DBs and sanitize olcRootPW (bsc#1231838, pr#247)
    + Added dbus_info for dbus.txt (bsc#1222650, pr#248)

------------------------------------------------------------------
------------------  2025-3-19  -  Mar 19 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Patch python bridge to handle dbus message endianness correctly
  - added 0008-pybridge-endian-flag.patch
    (bsc#1220477)

++++ file:

  - Change patch file-seccomp.patch
    * Remove the dumb prctl allow rule as for glibc malloc the prctl
    PR_SET_VMA with flag PR_SET_VMA_ANON_NAME is already allowed
  - Require at build zlib-devel to enable direct uncompresion of
    zip'ed files as well

++++ gawk:

  - Mark profiling as non-deterministic (boo#1040589, jsc#PED-12137)

++++ librsvg:

  - Update to version 2.60.0:
    + The minimum supported Rust version (MSRV) is 1.77.2.
    + Many build fixes for various platforms.
    + Basic support for the dominant-baseline property.
    + Parse the white-space property. It is not processed yet; this
    is part of the work to support SVG2 text layout.
    + Report errors correctly from the parsers for attribute values.
    + Portability fixes to the C header files.

++++ hwinfo:

  - merge gh#openSUSE/hwinfo#150
  - do not overdo usb device de-duplication (bsc#1239663)
  - 23.4

++++ kernel-default:

  - iommu/vt-d: Remove device comparison in
    context_setup_pass_through_cb (git-fixes).
  - commit 6f00978
  - iommu/vt-d: Fix suspicious RCU usage (git-fixes).
  - commit 5ad5ea1
  - Revert "drm/i915: Depend on !PREEMPT_RT." (bsc#1234370).
  - drm/i915/guc: Consider also RCU depth in busy loop
    (bsc#1234370).
  - drm/i915: Drop the irqs_disabled() check (bsc#1234370).
  - drm/i915/gt: Use spin_lock_irq() instead of local_irq_disable()
    + spin_lock() (bsc#1234370).
  - drm/i915: Disable tracing points on PREEMPT_RT (bsc#1234370).
  - drm/i915: Don't check for atomic context on PREEMPT_RT
    (bsc#1234370).
  - commit 88585fa
  - drm/i915: Don't disable interrupts on PREEMPT_RT during atomic
    updates (bsc#1234370).
  - commit cdca27f
  - drm/i915: Use preempt_disable/enable_rt() where recommended
    (bsc#1234370).
  - commit 63dfe9f
  - serial: 8250: Revert "drop lockdep annotation from
    serial8250_clear_IER()" (bsc#1234370 (PREEMPT_RT prerequisite
    backports)).
  - blacklist.conf: Refresh
  - serial: 8250: Switch to nbcon console (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - serial: 8250: Provide flag for IER toggling for RS485
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Use high-level writing function for FIFO
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Use frame time to determine timeout (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Explain the role of @read_status_mask (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Never adjust UART_LSR_DR in @read_status_mask
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Do not set UART_LSR_THRE in @read_status_mask
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Use @ier bits to determine if Rx is stopped
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250_port: Assign UPIO_UNKNOWN instead of its direct
    value (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - tty: serial: Work around warning backtrace in
    serial8250_set_defaults (bsc#1234370 (PREEMPT_RT prerequisite
    backports)).
  - tty: serial: export serial_8250_warn_need_ioport (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - tty: serial: handle HAS_IOPORT dependencies (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - commit 031ec61
  - md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb (bsc#1238212)
  - commit e36aa4c
  - initramfs: fix hardlink hash leak without TRAILER (bsc#1232848).
  - initramfs: allocate heap buffers together (bsc#1232848).
  - init: add initramfs_internal.h (bsc#1232848).
  - commit 9d3eb63
  - x86/efi: skip memattr table on kexec boot (jsc#PED-12274).
  - efi/esrt: remove esre_attribute::store() (jsc#PED-12274).
  - efi/zboot: Limit compression options to GZIP and ZSTD
    (jsc#PED-12274).
  - efi: Fix memory leak in efivar_ssdt_load (jsc#PED-12274).
  - efi/libstub: Take command line overrides into account for
    loaded files (jsc#PED-12274).
  - efi/libstub: Fix command line fallback handling when loading
    files (jsc#PED-12274).
  - efi/libstub: Parse builtin command line after bootloader
    provided one (jsc#PED-12274).
  - x86/efi: Apply EFI Memory Attributes after kexec
    (jsc#PED-12274).
  - x86/efi: Drop support for the EFI_PROPERTIES_TABLE
    (jsc#PED-12274).
    Refresh
    patches.suse/0002-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-boot-mode.patch.
  - efi/memattr: Ignore table if the size is clearly bogus
    (jsc#PED-12274).
  - efi/zboot: Fix outdated comment about using LoadImage/StartImage
    (jsc#PED-12274).
  - libstub,tpm: do not ignore failure case when reading final
    event log (jsc#PED-12274).
  - tpm: fix unsigned/signed mismatch errors related to
    __calc_tpm2_event_size (jsc#PED-12274).
  - tpm: do not ignore memblock_reserve return value
    (jsc#PED-12274).
  - efi/libstub: measure initrd to PCR9 independent of source
    (jsc#PED-12274).
  - efi/libstub: remove unnecessary cmd_line_len from
    efi_convert_cmdline() (jsc#PED-12274).
  - x86/cpu: Fix FAM5_QUARK_X1000 to use X86_MATCH_VFM()
    (jsc#PED-12274).
  - commit b9ae6eb
  - efi/libstub: Bump up EFI_MMAP_NR_SLACK_SLOTS to 32
    (bsc#1239349).
  - commit f7e4da8

++++ kernel-rt:

  - iommu/vt-d: Remove device comparison in
    context_setup_pass_through_cb (git-fixes).
  - commit 6f00978
  - iommu/vt-d: Fix suspicious RCU usage (git-fixes).
  - commit 5ad5ea1
  - Revert "drm/i915: Depend on !PREEMPT_RT." (bsc#1234370).
  - drm/i915/guc: Consider also RCU depth in busy loop
    (bsc#1234370).
  - drm/i915: Drop the irqs_disabled() check (bsc#1234370).
  - drm/i915/gt: Use spin_lock_irq() instead of local_irq_disable()
    + spin_lock() (bsc#1234370).
  - drm/i915: Disable tracing points on PREEMPT_RT (bsc#1234370).
  - drm/i915: Don't check for atomic context on PREEMPT_RT
    (bsc#1234370).
  - commit 88585fa
  - drm/i915: Don't disable interrupts on PREEMPT_RT during atomic
    updates (bsc#1234370).
  - commit cdca27f
  - drm/i915: Use preempt_disable/enable_rt() where recommended
    (bsc#1234370).
  - commit 63dfe9f
  - serial: 8250: Revert "drop lockdep annotation from
    serial8250_clear_IER()" (bsc#1234370 (PREEMPT_RT prerequisite
    backports)).
  - blacklist.conf: Refresh
  - serial: 8250: Switch to nbcon console (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - serial: 8250: Provide flag for IER toggling for RS485
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Use high-level writing function for FIFO
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Use frame time to determine timeout (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Explain the role of @read_status_mask (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Never adjust UART_LSR_DR in @read_status_mask
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Do not set UART_LSR_THRE in @read_status_mask
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250: Use @ier bits to determine if Rx is stopped
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - serial: 8250_port: Assign UPIO_UNKNOWN instead of its direct
    value (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - tty: serial: Work around warning backtrace in
    serial8250_set_defaults (bsc#1234370 (PREEMPT_RT prerequisite
    backports)).
  - tty: serial: export serial_8250_warn_need_ioport (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - tty: serial: handle HAS_IOPORT dependencies (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - commit 031ec61
  - md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb (bsc#1238212)
  - commit e36aa4c
  - initramfs: fix hardlink hash leak without TRAILER (bsc#1232848).
  - initramfs: allocate heap buffers together (bsc#1232848).
  - init: add initramfs_internal.h (bsc#1232848).
  - commit 9d3eb63
  - x86/efi: skip memattr table on kexec boot (jsc#PED-12274).
  - efi/esrt: remove esre_attribute::store() (jsc#PED-12274).
  - efi/zboot: Limit compression options to GZIP and ZSTD
    (jsc#PED-12274).
  - efi: Fix memory leak in efivar_ssdt_load (jsc#PED-12274).
  - efi/libstub: Take command line overrides into account for
    loaded files (jsc#PED-12274).
  - efi/libstub: Fix command line fallback handling when loading
    files (jsc#PED-12274).
  - efi/libstub: Parse builtin command line after bootloader
    provided one (jsc#PED-12274).
  - x86/efi: Apply EFI Memory Attributes after kexec
    (jsc#PED-12274).
  - x86/efi: Drop support for the EFI_PROPERTIES_TABLE
    (jsc#PED-12274).
    Refresh
    patches.suse/0002-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-boot-mode.patch.
  - efi/memattr: Ignore table if the size is clearly bogus
    (jsc#PED-12274).
  - efi/zboot: Fix outdated comment about using LoadImage/StartImage
    (jsc#PED-12274).
  - libstub,tpm: do not ignore failure case when reading final
    event log (jsc#PED-12274).
  - tpm: fix unsigned/signed mismatch errors related to
    __calc_tpm2_event_size (jsc#PED-12274).
  - tpm: do not ignore memblock_reserve return value
    (jsc#PED-12274).
  - efi/libstub: measure initrd to PCR9 independent of source
    (jsc#PED-12274).
  - efi/libstub: remove unnecessary cmd_line_len from
    efi_convert_cmdline() (jsc#PED-12274).
  - x86/cpu: Fix FAM5_QUARK_X1000 to use X86_MATCH_VFM()
    (jsc#PED-12274).
  - commit b9ae6eb
  - efi/libstub: Bump up EFI_MMAP_NR_SLACK_SLOTS to 32
    (bsc#1239349).
  - commit f7e4da8

++++ cairo:

  - Switch back to using source service.

++++ netavark:

  - Update to version 1.14.1:
    * Release v1.14.1
    * Release notes for v1.14.0
    * Fix detect of Firewalld's StrictForwardPorts property
    * test/001-basic: Make commit test optional
    * cirrus: do not build debug bins
    * Makefile: do not rebuild if nothing changed
    * Makefile: uninstall netavark-firewalld-reload.service
    * docs/Makefile: several fixes
    * Makefile: build docs by default
    * Makefile: do not build twice

++++ salt:

  - Fix aptpkg 'NoneType object has no attribute split' error
  - Detect openEuler as RedHat family OS
  - Ensure the correct crypt module is loaded
  - Implement multiple inventory for ansible.targets
  - Make x509 module compatible with M2Crypto 0.44.0
  - Remove deprecated code from x509.certificate_managed test mode
  - Move logrotate config to /usr/etc/logrotate.d where possible
  - Add DEB822 apt repository format support
  - Make Salt-SSH work with all SSH passwords (bsc#1215484)
  - Fix issue of using update-alternatives with alts (#105)
  - Fix virt_query outputter and add support for block devices
  - Make _auth calls visible with master stats
  - Repair mount.fstab_present always returning pending changes
  - Set virtual grain in Podman systemd container
  - Fix crash due wrong client reference on `SaltMakoTemplateLookup`
  - Enhace batch async and fix some detected issues
  - Enhacement of Salt packaging
    * Use update-alternatives for all salt scripts
    * Use flexible dependencies for the subpackages
    * Make salt-minion to require flavored zypp-plugin
    * Make zyppnotify to use update-alternatives
    * Drop unused yumnotify plugin
    * Add dependency to python3-dnf-plugins-core for RHEL based
  - Fix tests failures after "repo.saltproject.io" deprecation
  - Fix error to stat '/root/.gitconfig' on gitfs
    (bsc#1230944) (bsc#1234881) (bsc#1220905)
  - Adapt to removal of hex attribute in pygit2 v1.15.0 (bsc#1230642)
  - Enhance smart JSON parsing when garbage is present (bsc#1231605)
  - Fix virtual grains for VMs running on Nutanix AHV (bsc#1234022)
  - Fix issues running on Python 3.12 and 3.13
  - Revert setting SELinux context for minion service (bsc#1233667)
  - Remove System V init support
    * Make systemd the only supported init system by removing System V init
    and insserv references
    * Ensure package builds with no init system dependencies if built
    without systemd (for example for use in containers)
    * Apply some spec-cleaner suggestions (update copyright year, sort
    requirements, adjust spacing)
  - Fix the condition of alternatives for Tumbleweed and Leap 16
  - Use update-alternatives for salt-call and fix builing on EL8
  - Build all python bindings for all flavors
  - Make minion reconnecting on changing master IP (bsc#1228182)
  - Handle logger exception when flushing already closed file
  - Include passlib as a recommended dependency
  - Make Salt Bundle more tolerant to long running jobs (bsc#1228690)
  - Fix additional x509 tests and test_suse tests for SLE12
  - Added:
    * fix-deb822-nonetype-object-has-no-attribute-split-71.patch
    * detect-openeuler-as-redhat-family-os.patch
    * ensure-the-correct-crypt-module-is-loaded.patch
    * implement-multiple-inventory-for-ansible.targets.patch
    * make-x509-module-compatible-with-m2crypto-0.44.0.patch
    * remove-deprecated-code-from-x509.certificate_managed.patch
    * add-deb822-apt-source-format-support-692.patch
    * remove-password-from-shell-after-functional-text-mat.patch
    * repair-virt_query-outputter-655.patch
    * make-_auth-calls-visible-with-master-stats-696.patch
    * repair-fstab_present-test-mode-702.patch
    * set-virtual-grain-in-podman-systemd-container-703.patch
    * fixed-file-client-private-attribute-reference-on-sal.patch
    * backport-batch-async-fixes-and-improvements-701.patch
    * fix-tests-failures-after-repo.saltproject.io-depreca.patch
    * fix-failed-to-stat-root-.gitconfig-issue-on-gitfs-bs.patch
    * update-for-deprecation-of-hex-in-pygit2-1.15.0-and-a.patch
    * enhance-find_json-garbage-filtering-bsc-1231605-688.patch
    * fix-virtual-grains-for-vms-running-on-nutanix-ahv-bs.patch
    * fix-issues-that-break-salt-in-python-3.12-and-3.13-6.patch
    * revert-setting-selinux-context-for-minion-service-bs.patch
    * make-minion-reconnecting-on-changing-master-ip-bsc-1.patch
    * handle-logger-flushing-already-closed-file-686.patch
    * enhance-cleanup-mechanism-after-salt-bundle-upgrade-.patch
    * fix-x509-private-key-tests-and-test_suse-on-sle12-68.patch

------------------------------------------------------------------
------------------  2025-3-18  -  Mar 18 2025  -------------------
------------------------------------------------------------------

++++ cpupower:

  - Show the first 2 lines of kernel-source sources we build against
    in the package description.
    Also show the latest git hash commit ID there to be able to track
    the exact sources the package has been built against.

++++ crypto-policies:

  - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370]
    * Add crypto-policies-Allow-sshd-in-FIPS-mode-using-DEFAULT.patch

++++ file:

  - Add patch file-seccomp-ppc.patch
    * Minimal patch to work around of wrong provide of used TCGETS

++++ gnutls:

  - bsc#1237101, FIPS selfcheck fails on tumbleweed
    * Match dependent library names ( nettle, gmp, hogweed ) even when they include full verison in soname
    * Add gnutls-fips-sonames-check.patch

++++ kernel-default:

  - Update config files: set CONFIG_DRM_CLIENT_SELECTION and CONFIG_DRM_CLIENT_SETUP
  - commit 97c1612
  - EDAC/qcom: Correct interrupt enable register configuration
    (git-fixes).
  - commit cf86879
  - module: Don't fail module loading when setting ro_after_init
    section RO failed (git-fixes).
  - mtd: hyperbus: hbmc-am654: fix an OF node reference leak
    (git-fixes).
  - commit db53e48
  - rseq/selftests: Fix riscv rseq_offset_deref_addv inline asm
    (git-fixes).
  - rseq: Fix rseq registration with CONFIG_DEBUG_RSEQ (git-fixes).
  - commit d572a1b
  - samples/landlock: Fix possible NULL dereference in parse_path()
    (git-fixes).
  - commit 9a41c2d
  - scripts: generate_rust_analyzer: add missing macros deps
    (git-fixes).
  - scripts/Makefile.extrawarn: Do not show clang's non-kprintf
    warnings at W=1 (git-fixes).
  - scripts/mksysmap: Fix escape chars '$' (git-fixes).
  - scripts/sorttable: fix orc_sort_cmp() to maintain symmetry
    and transitivity (git-fixes).
  - commit 8b3ebf9
  - selftests: bonding: fix incorrect mac address (git-fixes).
  - selftests/damon/damon_nr_regions: sort collected regiosn before
    checking with min/max boundaries (git-fixes).
  - selftests/damon/damon_nr_regions: set ops update for merge
    results check to 100ms (git-fixes).
  - selftests/damon/damos_quota: make real expectation of quota
    exceeds (git-fixes).
  - selftests/damon/damos_quota_goal: handle minimum quota that
    cannot be further reduced (git-fixes).
  - Revert "selftests/mm: remove local __NR_* definitions"
    (git-fixes).
  - commit f916b2c
  - tools/power turbostat: Fix forked child affinity regression
    (git-fixes).
  - tools/power turbostat: Fix PMT mmaped file size rounding
    (git-fixes).
  - commit 00c6f9a
  - usb: typec: ucsi: Set orientation as none when connector is
    unplugged (git-fixes).
  - commit 5e217bd
  - HID: hid-steam: Fix use-after-free when detaching device
    (git-fixes).
  - commit 23d7480
  - wifi: rtw89: pci: disable PCIE wake bit when PCIE deinit
    (stable-fixes).
  - commit a65f71f
  - wifi: rtw89: tweak setting of channel and TX power for MLO
    (stable-fixes).
  - Refresh
    patches.suse/wifi-rtw89-fix-proceeding-MCC-with-wrong-scanning-st.patch.
  - commit 77488c0
  - wifi: mac80211: Support parsing EPCS ML element (stable-fixes).
  - Refresh
    patches.suse/wifi-mac80211-fix-MLE-non-inheritance-parsing.patch.
  - Refresh
    patches.suse/wifi-mac80211-fix-vendor-specific-inheritance.patch.
  - commit 1421c5d
  - drm/nouveau: select FW caching (git-fixes).
  - nvkm: correctly calculate the available space of the GSP cmdq
    buffer (stable-fixes).
  - nvkm/gsp: correctly advance the read pointer of GSP message
    queue (stable-fixes).
  - drm/nouveau: Run DRM default client setup (stable-fixes).
  - drm/fbdev-ttm: Support struct drm_driver.fbdev_probe
    (stable-fixes).
  - drm: Add client-agnostic setup helper (stable-fixes).
  - drm/fbdev: Add memory-agnostic fbdev client (stable-fixes).
  - drm/fbdev-helper: Move color-mode lookup into 4CC format helper
    (stable-fixes).
  - commit 7808594
  - dm-flakey: Fix memory corruption in optional corrupt_bio_byte
    feature (git-fixes).
  - commit 5ee65a9
  - soc: qcom: pdr: Fix the potential deadlock (git-fixes).
  - firmware: qcom: uefisecapp: fix efivars registration race
    (git-fixes).
  - firmware: qcom: scm: Fix error code in probe() (git-fixes).
  - soc: imx8m: Unregister cpufreq and soc dev in cleanup path
    (git-fixes).
  - firmware: imx-scu: fix OF node leak in .probe() (git-fixes).
  - ubi: Add a check for ubi_num (git-fixes).
  - commit 65fa628

++++ kernel-firmware-amdgpu:

  - Update to version 20250318 (git commit 588505068c48):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-firmware-bluetooth:

  - Update to version 20250318 (git commit 588505068c48):
    * linux-firmware: Update firmware file for Intel BlazarI core

++++ kernel-firmware-sound:

  - Update to version 20250318 (git commit 588505068c48):
    * qcom: Add Audio firmware for Lenovo Slim 7x
    * qcom: Add Audio firmware for Lenovo T14s

++++ kernel-rt:

  - Update config files: set CONFIG_DRM_CLIENT_SELECTION and CONFIG_DRM_CLIENT_SETUP
  - commit 97c1612
  - EDAC/qcom: Correct interrupt enable register configuration
    (git-fixes).
  - commit cf86879
  - module: Don't fail module loading when setting ro_after_init
    section RO failed (git-fixes).
  - mtd: hyperbus: hbmc-am654: fix an OF node reference leak
    (git-fixes).
  - commit db53e48
  - rseq/selftests: Fix riscv rseq_offset_deref_addv inline asm
    (git-fixes).
  - rseq: Fix rseq registration with CONFIG_DEBUG_RSEQ (git-fixes).
  - commit d572a1b
  - samples/landlock: Fix possible NULL dereference in parse_path()
    (git-fixes).
  - commit 9a41c2d
  - scripts: generate_rust_analyzer: add missing macros deps
    (git-fixes).
  - scripts/Makefile.extrawarn: Do not show clang's non-kprintf
    warnings at W=1 (git-fixes).
  - scripts/mksysmap: Fix escape chars '$' (git-fixes).
  - scripts/sorttable: fix orc_sort_cmp() to maintain symmetry
    and transitivity (git-fixes).
  - commit 8b3ebf9
  - selftests: bonding: fix incorrect mac address (git-fixes).
  - selftests/damon/damon_nr_regions: sort collected regiosn before
    checking with min/max boundaries (git-fixes).
  - selftests/damon/damon_nr_regions: set ops update for merge
    results check to 100ms (git-fixes).
  - selftests/damon/damos_quota: make real expectation of quota
    exceeds (git-fixes).
  - selftests/damon/damos_quota_goal: handle minimum quota that
    cannot be further reduced (git-fixes).
  - Revert "selftests/mm: remove local __NR_* definitions"
    (git-fixes).
  - commit f916b2c
  - tools/power turbostat: Fix forked child affinity regression
    (git-fixes).
  - tools/power turbostat: Fix PMT mmaped file size rounding
    (git-fixes).
  - commit 00c6f9a
  - usb: typec: ucsi: Set orientation as none when connector is
    unplugged (git-fixes).
  - commit 5e217bd
  - HID: hid-steam: Fix use-after-free when detaching device
    (git-fixes).
  - commit 23d7480
  - wifi: rtw89: pci: disable PCIE wake bit when PCIE deinit
    (stable-fixes).
  - commit a65f71f
  - wifi: rtw89: tweak setting of channel and TX power for MLO
    (stable-fixes).
  - Refresh
    patches.suse/wifi-rtw89-fix-proceeding-MCC-with-wrong-scanning-st.patch.
  - commit 77488c0
  - wifi: mac80211: Support parsing EPCS ML element (stable-fixes).
  - Refresh
    patches.suse/wifi-mac80211-fix-MLE-non-inheritance-parsing.patch.
  - Refresh
    patches.suse/wifi-mac80211-fix-vendor-specific-inheritance.patch.
  - commit 1421c5d
  - drm/nouveau: select FW caching (git-fixes).
  - nvkm: correctly calculate the available space of the GSP cmdq
    buffer (stable-fixes).
  - nvkm/gsp: correctly advance the read pointer of GSP message
    queue (stable-fixes).
  - drm/nouveau: Run DRM default client setup (stable-fixes).
  - drm/fbdev-ttm: Support struct drm_driver.fbdev_probe
    (stable-fixes).
  - drm: Add client-agnostic setup helper (stable-fixes).
  - drm/fbdev: Add memory-agnostic fbdev client (stable-fixes).
  - drm/fbdev-helper: Move color-mode lookup into 4CC format helper
    (stable-fixes).
  - commit 7808594
  - dm-flakey: Fix memory corruption in optional corrupt_bio_byte
    feature (git-fixes).
  - commit 5ee65a9
  - soc: qcom: pdr: Fix the potential deadlock (git-fixes).
  - firmware: qcom: uefisecapp: fix efivars registration race
    (git-fixes).
  - firmware: qcom: scm: Fix error code in probe() (git-fixes).
  - soc: imx8m: Unregister cpufreq and soc dev in cleanup path
    (git-fixes).
  - firmware: imx-scu: fix OF node leak in .probe() (git-fixes).
  - ubi: Add a check for ubi_num (git-fixes).
  - commit 65fa628

++++ llvm19:

  - Enable build of libc++ and openmp for riscv64

++++ openssh:

  - Disable seccomp_filter and rlimitsandbox sandbox for loongarch.
    seccomp_filter and rlimitsandbox not supported on loongarch64 yet.

++++ podman:

  - Add patch for CVE-2025-22869 (bsc#1239330):
    * 0003-CVE-2025-22869-ssh-limit-the-size-of-the-internal-pa.patch
  - Rebase patches:
    * 0001-vendor-bump-buildah-to-1.37.6-CVE-2024-11218.patch
    * 0002-CVE-2025-27144-vendor-don-t-allow-unbounded-amounts-.patch

------------------------------------------------------------------
------------------  2025-3-17  -  Mar 17 2025  -------------------
------------------------------------------------------------------

++++ drbd-utils:

  - Default SELinux Profile prevents configuration of drbd_passive resources in cluster (bsc#1239436)
    * update spec file to create a new package drbd-selinux
    * update patch bsc-1233273_drbd.ocf-update-for-OCF-1.1.patch
  - fix the commit log mistake and typo, no code change

++++ fwupd:

  - Add 8588.patch: Fix compile when using Pango >= 1.56.2.

++++ grub2:

  - Refresh PPC NVMEoF ofpath related patches to newer revision
    * 0002-ieee1275-ofpath-enable-NVMeoF-logical-device-transla.patch
  - Patch refreshed
    * 0001-ieee1275-support-added-for-multiple-nvme-bootpaths.patch
  - Patch obseleted
    * 0004-ofpath-controller-name-update.patch
    * 0001-squash-ieee1275-ofpath-enable-NVMeoF-logical-device-.patch
  - Fix segmentation fault error in grub2-probe with target=hints_string
    (bsc#1235971) (bsc#1235958) (bsc#1239651)
    * 0001-ofpath-Add-error-check-in-NVMEoF-device-translation.patch

++++ gsettings-desktop-schemas:

  - Update to version 48.0:
    + Updated translations.

++++ kernel-default:

  - scsi: ufs: core: Fix use-after free in init error and remove
    paths (CVE-2025-21739 bsc#1238506).
  - commit df21342
  - cpufreq/amd-pstate: Fix cpufreq_policy ref counting (git-fixes
    CVE-2025-21841).
  - commit be4b6ae
  - cpufreq/amd-pstate: Fix max_perf updation with schedutil
    (git-fixes).
  - cpufreq/amd-pstate: Remove the goto label in
    amd_pstate_update_limits (git-fixes).
  - commit 89584e6
  - cpufreq/amd-pstate: Fix per-policy boost flag incorrect when
    fail (git-fixes).
  - commit 3905635
  - cpufreq/amd-pstate: Refactor max frequency calculation
    (bsc#1233975).
  - commit 2243400
  - cpufreq/amd-pstate: Drop boost_state variable (bsc#1233975).
  - commit 8becee9
  - cpufreq/amd-pstate: Drop ret variable from
    amd_pstate_set_energy_pref_index() (bsc#1233975).
  - cpufreq/amd-pstate: Always write EPP value when updating perf
    (bsc#1233975).
  - cpufreq/amd-pstate: Cache EPP value and use that everywhere
    (bsc#1233975).
  - cpufreq/amd-pstate: Move limit updating code (bsc#1233975).
  - cpufreq/amd-pstate: Change amd_pstate_update_perf() to return
    an int (bsc#1233975).
  - cpufreq/amd-pstate: store all values in cpudata struct in khz
    (bsc#1233975).
  - cpufreq/amd-pstate: Only update the cached value in
    msr_set_epp() on success (bsc#1233975).
  - cpufreq/amd-pstate: Use FIELD_PREP and FIELD_GET macros
    (bsc#1233975).
  - cpufreq/amd-pstate: Drop cached epp_policy variable
    (bsc#1233975).
  - commit 72b6cbd
  - cpufreq/amd-pstate: convert mutex use to guard() (stable-fixes).
  - commit fff7e25
  - cpufreq/amd-pstate: Add trace event for EPP perf updates
    (bsc#1233975).
  - commit ff4fc8b
  - cpufreq/amd-pstate: Merge amd_pstate_epp_cpu_offline() and
    amd_pstate_epp_offline() (stable-fixes).
  - cpufreq/amd-pstate: Remove the cppc_state check in
    offline/online functions (stable-fixes).
  - cpufreq/amd-pstate: Refactor amd_pstate_epp_reenable() and
    amd_pstate_epp_offline() (stable-fixes).
  - commit 96308d8
  - cpufreq/amd-pstate: Move the invocation of
    amd_pstate_update_perf() (bsc#1233975).
  - cpufreq/amd-pstate: Convert the amd_pstate_get/set_epp()
    to static calls (bsc#1233975).
  - commit d070175
  - media: vidtv: Fix a null-ptr-deref in vidtv_mux_stop_thread
    (git-fixes).
  - commit 97cb127
  - cpufreq/amd-pstate-ut: Add fix for min freq unit test
    (bsc#1233975).
  - commit 9e7a47c
  - cpufreq/amd-pstate: Drop needless EPP initialization
    (bsc#1233975).
  - cpufreq/amd-pstate: Use amd_pstate_update_min_max_limit()
    for EPP limits (bsc#1233975).
  - commit 441355e
  - media: uvcvideo: Add Kurokesu C1 PRO camera (git-fixes).
  - commit ea77e6f
  - media: uvcvideo: Add new quirk definition for the Sonix
    Technology Co. 292a camera (git-fixes).
  - commit 36000c4
  - media: uvcvideo: Implement dual stream quirk to fix loss of
    usb packets (git-fixes).
  - commit 26eff04
  - media: bcm2835-unicam: Disable trigger mode operation
    (git-fixes).
  - commit aed8a4d
  - usbnet: ipheth: document scope of NCM implementation
    (git-fixes).
  - commit 59787c7
  - usb: quirks: Add DELAY_INIT and NO_LPM for Prolific Mass
    Storage Card Reader (git-fixes).
  - commit 80d32a6
  - usb: xhci: Enable the TRB overfetch quirk on VIA VL805
    (git-fixes).
  - commit 6690424
  - USB: pci-quirks: Fix HCCPARAMS register error for LS7A EHCI
    (git-fixes).
  - commit a1670ac
  - usb: typec: ucsi: Set orientation as none when connector is
    unplugged (git-fixes).
  - commit 5ce8719
  - Fix mmu notifiers for range-based invalidates (bsc#1239601)
  - commit 2dfd96f
  - supported.conf:
    Mark intel_plr_tpmi and intel_tpmi_power_domains as supported
    jsc#PED-10664
  - commit 474b66f
  - Update
    patches.suse/ASoC-SOF-stream-ipc-Check-for-cstream-nullity-in-sof.patch
    (git-fixes CVE-2025-21847 bsc#1239471).
  - Update
    patches.suse/HID-multitouch-Add-NULL-check-in-mt_input_configured.patch
    (git-fixes CVE-2024-58020 bsc#1239346).
  - Update
    patches.suse/USB-gadget-f_midi-f_midi_complete-to-call-queue_work.patch
    (git-fixes CVE-2025-21859 bsc#1239467).
  - Update patches.suse/acct-perform-last-write-from-workqueue.patch
    (git-fixes CVE-2025-21846 bsc#1239508).
  - Update
    patches.suse/bpf-Reject-struct_ops-registration-that-uses-module-.patch
    (git-fixes CVE-2024-58060 bsc#1238967).
  - Update
    patches.suse/drm-i915-gt-Use-spin_lock_irqsave-in-interruptible-c.patch
    (git-fixes CVE-2025-21849 bsc#1239485).
  - Update
    patches.suse/fbdev-omap-use-threaded-IRQ-for-LCD-DMA.patch
    (stable-fixes CVE-2025-21821 bsc#1239174).
  - Update
    patches.suse/ibmvnic-Don-t-reference-skb-after-sending-to-VIOS.patch
    (jsc#PED_10911 jsc#PED-3606 CVE-2025-21855 bsc#1239484).
  - Update patches.suse/mtd-spi-nor-sst-Fix-SST-write-failure.patch
    (git-fixes CVE-2025-21845 bsc#1239511).
  - Update
    patches.suse/net-Add-rx_skb-of-kfree_skb-to-raw_tp_null_args.patch
    (git-fixes CVE-2025-21852 bsc#1239487).
  - Update
    patches.suse/nvmet-Fix-crash-when-a-namespace-is-disabled.patch
    (git-fixes CVE-2025-21850 bsc#1239477).
  - Update
    patches.suse/powerpc-code-patching-Fix-KASAN-hit-by-not-flagging-.patch
    (bsc#1215199 CVE-2025-21866 bsc#1239473).
  - Update
    patches.suse/s390-ism-add-release-function-for-struct-device.patch
    (git-fixes bsc#1237494 CVE-2025-21856 bsc#1239486).
  - commit f5a5d00
  - Update "nvkm/gsp: correctly advance the read pointer of GSP message queue" (bsc#1238997 CVE-2024-58019)
  - commit 31b49bf
  - drm/i915: Grab intel_display from the encoder to avoid potential (bsc#1238972 CVE-2024-58074)
  - commit 04e6c21
  - i2c: sis630: Fix an error handling path in sis630_probe()
    (git-fixes).
  - i2c: ali15x3: Fix an error handling path in ali15x3_probe()
    (git-fixes).
  - i2c: ali1535: Fix an error handling path in ali1535_probe()
    (git-fixes).
  - i2c: omap: fix IRQ storms (git-fixes).
  - commit 4d52526
  - ACPI: GTDT: Relax sanity checking on Platform Timers array count
    (jsc#PED-12273).
  - ACPI: video: Fix random crashes due to bad kfree()
    (jsc#PED-12273).
  - ACPI: resource: acpi_dev_irq_override(): Check DMI match last
    (jsc#PED-12273).
  - ACPI: resource: Add TongFang GM5HG0A to
    irq1_edge_low_force_override (jsc#PED-12273).
  - ACPI: resource: Add Asus Vivobook X1504VAP to
    irq1_level_low_skip_override (jsc#PED-12273).
  - ACPI: introduce acpi_arch_init() (jsc#PED-12273).
  - ACPI/CDAT: Add CDAT/DSMAS shared and read only flag values
    (jsc#PED-12273).
  - ACPI/IORT: Support CANWBS memory access flag (jsc#PED-12273).
  - ACPICA: IORT: Update for revision E.f (jsc#PED-12273).
  - ACPI: Switch back to struct platform_driver::remove()
    (jsc#PED-12273).
  - ACPI: scan: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: SBSHC: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: SBS: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: power: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: pci_root: Use strscpy() instead of strcpy()
    (jsc#PED-12273).
  - ACPI: pci_link: Use strscpy() instead of strcpy()
    (jsc#PED-12273).
  - ACPI: event: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: EC: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: APD: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: thermal: Use strscpy() instead of strcpy()
    (jsc#PED-12273).
  - ACPI: processor_perflib: extend X86 dependency (jsc#PED-12273).
  - ACPI: allow building without CONFIG_HAS_IOPORT (jsc#PED-12273).
  - ACPI: pfr_telemetry: remove redundant error check on ret
    (jsc#PED-12273).
  - ACPI: EC: make EC support compile-time conditional
    (jsc#PED-12273).
    Update config files.
    CONFIG_ACPI_EC=y on x86_64
    CONFIG_ACPI_EC is not set on arm64
    blacklist.conf: add 0674188f2f4d Enable EC support on LoongArch by default
    Add '0674188f2f4d ACPI: EC: Enable EC support on LoongArch by default'
    because we do not support LoongArch.
  - ACPI: battery: Check for error code from devm_mutex_init()
    call (jsc#PED-12273).
  - ACPI: battery: use DEFINE_SIMPLE_DEV_PM_OPS (jsc#PED-12273).
  - ACPI: battery: initialize mutexes through devm_ APIs
    (jsc#PED-12273).
  - ACPI: battery: allocate driver data through devm_ APIs
    (jsc#PED-12273).
  - ACPI: battery: check result of register_pm_notifier()
    (jsc#PED-12273).
  - acpi/arm64: remove unnecessary cast (jsc#PED-12273).
  - ACPI: GTDT: Tighten the check for the array of platform timer
    structures (jsc#PED-12273).
  - commit 08aefe9
  - series.conf: Move kprobe patches to sorted section
  - commit 50044e2

++++ kernel-rt:

  - scsi: ufs: core: Fix use-after free in init error and remove
    paths (CVE-2025-21739 bsc#1238506).
  - commit df21342
  - cpufreq/amd-pstate: Fix cpufreq_policy ref counting (git-fixes
    CVE-2025-21841).
  - commit be4b6ae
  - cpufreq/amd-pstate: Fix max_perf updation with schedutil
    (git-fixes).
  - cpufreq/amd-pstate: Remove the goto label in
    amd_pstate_update_limits (git-fixes).
  - commit 89584e6
  - cpufreq/amd-pstate: Fix per-policy boost flag incorrect when
    fail (git-fixes).
  - commit 3905635
  - cpufreq/amd-pstate: Refactor max frequency calculation
    (bsc#1233975).
  - commit 2243400
  - cpufreq/amd-pstate: Drop boost_state variable (bsc#1233975).
  - commit 8becee9
  - cpufreq/amd-pstate: Drop ret variable from
    amd_pstate_set_energy_pref_index() (bsc#1233975).
  - cpufreq/amd-pstate: Always write EPP value when updating perf
    (bsc#1233975).
  - cpufreq/amd-pstate: Cache EPP value and use that everywhere
    (bsc#1233975).
  - cpufreq/amd-pstate: Move limit updating code (bsc#1233975).
  - cpufreq/amd-pstate: Change amd_pstate_update_perf() to return
    an int (bsc#1233975).
  - cpufreq/amd-pstate: store all values in cpudata struct in khz
    (bsc#1233975).
  - cpufreq/amd-pstate: Only update the cached value in
    msr_set_epp() on success (bsc#1233975).
  - cpufreq/amd-pstate: Use FIELD_PREP and FIELD_GET macros
    (bsc#1233975).
  - cpufreq/amd-pstate: Drop cached epp_policy variable
    (bsc#1233975).
  - commit 72b6cbd
  - cpufreq/amd-pstate: convert mutex use to guard() (stable-fixes).
  - commit fff7e25
  - cpufreq/amd-pstate: Add trace event for EPP perf updates
    (bsc#1233975).
  - commit ff4fc8b
  - cpufreq/amd-pstate: Merge amd_pstate_epp_cpu_offline() and
    amd_pstate_epp_offline() (stable-fixes).
  - cpufreq/amd-pstate: Remove the cppc_state check in
    offline/online functions (stable-fixes).
  - cpufreq/amd-pstate: Refactor amd_pstate_epp_reenable() and
    amd_pstate_epp_offline() (stable-fixes).
  - commit 96308d8
  - cpufreq/amd-pstate: Move the invocation of
    amd_pstate_update_perf() (bsc#1233975).
  - cpufreq/amd-pstate: Convert the amd_pstate_get/set_epp()
    to static calls (bsc#1233975).
  - commit d070175
  - media: vidtv: Fix a null-ptr-deref in vidtv_mux_stop_thread
    (git-fixes).
  - commit 97cb127
  - cpufreq/amd-pstate-ut: Add fix for min freq unit test
    (bsc#1233975).
  - commit 9e7a47c
  - cpufreq/amd-pstate: Drop needless EPP initialization
    (bsc#1233975).
  - cpufreq/amd-pstate: Use amd_pstate_update_min_max_limit()
    for EPP limits (bsc#1233975).
  - commit 441355e
  - media: uvcvideo: Add Kurokesu C1 PRO camera (git-fixes).
  - commit ea77e6f
  - media: uvcvideo: Add new quirk definition for the Sonix
    Technology Co. 292a camera (git-fixes).
  - commit 36000c4
  - media: uvcvideo: Implement dual stream quirk to fix loss of
    usb packets (git-fixes).
  - commit 26eff04
  - media: bcm2835-unicam: Disable trigger mode operation
    (git-fixes).
  - commit aed8a4d
  - usbnet: ipheth: document scope of NCM implementation
    (git-fixes).
  - commit 59787c7
  - usb: quirks: Add DELAY_INIT and NO_LPM for Prolific Mass
    Storage Card Reader (git-fixes).
  - commit 80d32a6
  - usb: xhci: Enable the TRB overfetch quirk on VIA VL805
    (git-fixes).
  - commit 6690424
  - USB: pci-quirks: Fix HCCPARAMS register error for LS7A EHCI
    (git-fixes).
  - commit a1670ac
  - usb: typec: ucsi: Set orientation as none when connector is
    unplugged (git-fixes).
  - commit 5ce8719
  - Fix mmu notifiers for range-based invalidates (bsc#1239601)
  - commit 2dfd96f
  - supported.conf:
    Mark intel_plr_tpmi and intel_tpmi_power_domains as supported
    jsc#PED-10664
  - commit 474b66f
  - Update
    patches.suse/ASoC-SOF-stream-ipc-Check-for-cstream-nullity-in-sof.patch
    (git-fixes CVE-2025-21847 bsc#1239471).
  - Update
    patches.suse/HID-multitouch-Add-NULL-check-in-mt_input_configured.patch
    (git-fixes CVE-2024-58020 bsc#1239346).
  - Update
    patches.suse/USB-gadget-f_midi-f_midi_complete-to-call-queue_work.patch
    (git-fixes CVE-2025-21859 bsc#1239467).
  - Update patches.suse/acct-perform-last-write-from-workqueue.patch
    (git-fixes CVE-2025-21846 bsc#1239508).
  - Update
    patches.suse/bpf-Reject-struct_ops-registration-that-uses-module-.patch
    (git-fixes CVE-2024-58060 bsc#1238967).
  - Update
    patches.suse/drm-i915-gt-Use-spin_lock_irqsave-in-interruptible-c.patch
    (git-fixes CVE-2025-21849 bsc#1239485).
  - Update
    patches.suse/fbdev-omap-use-threaded-IRQ-for-LCD-DMA.patch
    (stable-fixes CVE-2025-21821 bsc#1239174).
  - Update
    patches.suse/ibmvnic-Don-t-reference-skb-after-sending-to-VIOS.patch
    (jsc#PED_10911 jsc#PED-3606 CVE-2025-21855 bsc#1239484).
  - Update patches.suse/mtd-spi-nor-sst-Fix-SST-write-failure.patch
    (git-fixes CVE-2025-21845 bsc#1239511).
  - Update
    patches.suse/net-Add-rx_skb-of-kfree_skb-to-raw_tp_null_args.patch
    (git-fixes CVE-2025-21852 bsc#1239487).
  - Update
    patches.suse/nvmet-Fix-crash-when-a-namespace-is-disabled.patch
    (git-fixes CVE-2025-21850 bsc#1239477).
  - Update
    patches.suse/powerpc-code-patching-Fix-KASAN-hit-by-not-flagging-.patch
    (bsc#1215199 CVE-2025-21866 bsc#1239473).
  - Update
    patches.suse/s390-ism-add-release-function-for-struct-device.patch
    (git-fixes bsc#1237494 CVE-2025-21856 bsc#1239486).
  - commit f5a5d00
  - Update "nvkm/gsp: correctly advance the read pointer of GSP message queue" (bsc#1238997 CVE-2024-58019)
  - commit 31b49bf
  - drm/i915: Grab intel_display from the encoder to avoid potential (bsc#1238972 CVE-2024-58074)
  - commit 04e6c21
  - i2c: sis630: Fix an error handling path in sis630_probe()
    (git-fixes).
  - i2c: ali15x3: Fix an error handling path in ali15x3_probe()
    (git-fixes).
  - i2c: ali1535: Fix an error handling path in ali1535_probe()
    (git-fixes).
  - i2c: omap: fix IRQ storms (git-fixes).
  - commit 4d52526
  - ACPI: GTDT: Relax sanity checking on Platform Timers array count
    (jsc#PED-12273).
  - ACPI: video: Fix random crashes due to bad kfree()
    (jsc#PED-12273).
  - ACPI: resource: acpi_dev_irq_override(): Check DMI match last
    (jsc#PED-12273).
  - ACPI: resource: Add TongFang GM5HG0A to
    irq1_edge_low_force_override (jsc#PED-12273).
  - ACPI: resource: Add Asus Vivobook X1504VAP to
    irq1_level_low_skip_override (jsc#PED-12273).
  - ACPI: introduce acpi_arch_init() (jsc#PED-12273).
  - ACPI/CDAT: Add CDAT/DSMAS shared and read only flag values
    (jsc#PED-12273).
  - ACPI/IORT: Support CANWBS memory access flag (jsc#PED-12273).
  - ACPICA: IORT: Update for revision E.f (jsc#PED-12273).
  - ACPI: Switch back to struct platform_driver::remove()
    (jsc#PED-12273).
  - ACPI: scan: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: SBSHC: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: SBS: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: power: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: pci_root: Use strscpy() instead of strcpy()
    (jsc#PED-12273).
  - ACPI: pci_link: Use strscpy() instead of strcpy()
    (jsc#PED-12273).
  - ACPI: event: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: EC: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: APD: Use strscpy() instead of strcpy() (jsc#PED-12273).
  - ACPI: thermal: Use strscpy() instead of strcpy()
    (jsc#PED-12273).
  - ACPI: processor_perflib: extend X86 dependency (jsc#PED-12273).
  - ACPI: allow building without CONFIG_HAS_IOPORT (jsc#PED-12273).
  - ACPI: pfr_telemetry: remove redundant error check on ret
    (jsc#PED-12273).
  - ACPI: EC: make EC support compile-time conditional
    (jsc#PED-12273).
    Update config files.
    CONFIG_ACPI_EC=y on x86_64
    CONFIG_ACPI_EC is not set on arm64
    blacklist.conf: add 0674188f2f4d Enable EC support on LoongArch by default
    Add '0674188f2f4d ACPI: EC: Enable EC support on LoongArch by default'
    because we do not support LoongArch.
  - ACPI: battery: Check for error code from devm_mutex_init()
    call (jsc#PED-12273).
  - ACPI: battery: use DEFINE_SIMPLE_DEV_PM_OPS (jsc#PED-12273).
  - ACPI: battery: initialize mutexes through devm_ APIs
    (jsc#PED-12273).
  - ACPI: battery: allocate driver data through devm_ APIs
    (jsc#PED-12273).
  - ACPI: battery: check result of register_pm_notifier()
    (jsc#PED-12273).
  - acpi/arm64: remove unnecessary cast (jsc#PED-12273).
  - ACPI: GTDT: Tighten the check for the array of platform timer
    structures (jsc#PED-12273).
  - commit 08aefe9
  - series.conf: Move kprobe patches to sorted section
  - commit 50044e2

++++ gcc15:

  - Update to GCC trunk head, 15.0.1+git8082
  - Includes change to also record -D_FORTIFY_SOURCE=2 in the DWARF
    debug info DW_AT_producer string.  [bsc#1239566]
  - Package GCC COBOL compiler for openSUSE Factory for supported
    targets which are x86_64, aarch64 and ppc64le.

++++ cairo:

  - Update to version 1.18.4:
    + The dependency on LZO has been made optional through a build
    time configuration toggle.
    + You can build Cairo against a Freetype installation that does
    not have the FT_Color type.
    + Cairo tests now build on Solaris 11.4 with GCC 14.
    + The DirectWrite backend now builds on MINGW 11.
    + The DirectWrite backend now supports font variations and proper
    glyph coverage.
    + Support for Windows 98 has been removed. The minimum
    requirement for Windows is now Vista.
  - Use tarball in lieu of source service due to freedesktop gitlab
    migration, will switch back at next release at the latest.
  - Drop b9eed915f9a67380e7ef9d8746656455c43f67e2.patch: Fixed
    upstream.
  - Add pkgconfig(lzo2) BuildRequires: New optional dependency, build
    lzo2 support feature.

++++ ncurses:

  - Add ncurses patch 20250315
    + improve formatting/style of manpages (patches by Branden Robinson).

++++ systemd:

  - Maintain the network device naming scheme used on SLE15 (jsc#PED-12317)

++++ libzypp:

  - Fix computation of RepStatus if Repo URLs change.
  - Fix lost double slash when appending to an absolute FTP url
    (bsc#1238315)
    Ftp actually differs between absolute and relative URL paths.
    Absolute path names begin with a double slash encoded as '/%2F'.
    This must be preserved when manipulating the path.
  - version 17.36.5 (35)

++++ python-Jinja2:

  - Skip test_elif_deep on s390x arch

++++ rebootmgr:

  - Update to version 3.2+git20250317.27192cc:
    * Set c_std to gnu17

------------------------------------------------------------------
------------------  2025-3-16  -  Mar 16 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - bug: Use RCU instead RCU-sched to protect module_bug_list
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - static_call: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - bpf: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - jump_label: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - jump_label: Use RCU in all users of __module_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - x86: Use RCU in all users of __module_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - cfi: Use RCU while invoking __module_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - arm64: module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - ARM: module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in all users of __module_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in search_module_extables() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Allow __module_address() to be called from RCU section
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in __is_module_percpu_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in find_symbol() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - module: Remove module_assert_mutex_or_preempt() from
    try_add_tainted_module() (bsc#1234370 (PREEMPT_RT prerequisite
    backports)).
  - module: Use RCU in module_kallsyms_on_each_symbol() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in __find_kallsyms_symbol_value() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in find_module_all() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - module: Use RCU in module_get_kallsym() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - module: Use RCU in find_kallsyms_symbol() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use proper RCU assignment in add_kallsyms() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Begin to move from RCU-sched to RCU (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Extend the preempt disabled section in
    dereference_symbol_descriptor() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - commit a01f490
  - Input: iqs7222 - preserve system status register (git-fixes).
  - Input: goodix-berlin - fix vddio regulator references
    (git-fixes).
  - Input: goodix-berlin - fix comment referencing wrong regulator
    (git-fixes).
  - Input: ads7846 - fix gpiod allocation (git-fixes).
  - commit 7b707af

++++ kernel-rt:

  - bug: Use RCU instead RCU-sched to protect module_bug_list
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - static_call: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - bpf: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - jump_label: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - jump_label: Use RCU in all users of __module_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - x86: Use RCU in all users of __module_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - cfi: Use RCU while invoking __module_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - arm64: module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - ARM: module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in all users of __module_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in search_module_extables() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Allow __module_address() to be called from RCU section
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in __is_module_percpu_address() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in find_symbol() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - module: Remove module_assert_mutex_or_preempt() from
    try_add_tainted_module() (bsc#1234370 (PREEMPT_RT prerequisite
    backports)).
  - module: Use RCU in module_kallsyms_on_each_symbol() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in __find_kallsyms_symbol_value() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use RCU in find_module_all() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - module: Use RCU in module_get_kallsym() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - module: Use RCU in find_kallsyms_symbol() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Use proper RCU assignment in add_kallsyms() (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Begin to move from RCU-sched to RCU (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - module: Extend the preempt disabled section in
    dereference_symbol_descriptor() (bsc#1234370 (PREEMPT_RT
    prerequisite backports)).
  - commit a01f490
  - Input: iqs7222 - preserve system status register (git-fixes).
  - Input: goodix-berlin - fix vddio regulator references
    (git-fixes).
  - Input: goodix-berlin - fix comment referencing wrong regulator
    (git-fixes).
  - Input: ads7846 - fix gpiod allocation (git-fixes).
  - commit 7b707af

++++ at-spi2-core:

  - Update to version 2.56.0:
    + Updated translations.

++++ pango:

  - Update to version 1.56.3:
    + Improve font description serialization
    + fontconfig: Avoid FcFontSetSort when possible
    + coverage: Extend coverage by Unicode decomposition
    + win32: Speed up coverage creation
    + Deprecate pango_font_descriptions_free

++++ python-gobject:

  - Update to version 3.52.3:
    + Remove invalid error check for gi_constant_info_get_value.

++++ python-maturin:

  - Update to 1.8.3
    * Fix cargo run uniffi-bindgen when cross compiling
    gh#PyO3/maturin#2476
    * Add rnet python library to examples
    gh#PyO3/maturin#2480
    * bump the attest-build-provenance version in the generated ci file
    gh#PyO3/maturin#2484
    * Auto detect PyPy 3.11
    gh#PyO3/maturin#2487
    * Update manylinux/musllinux policies to the latest main
    gh#PyO3/maturin#2491
    * Update generate-ci options in user guide
    gh#PyO3/maturin#2501
    * chore: Update cbindgen to 0.28.0
    gh#PyO3/maturin#2498
    * Don't install dependencies when running maturin develop --skip-install
    gh#PyO3/maturin#2504
    * Upgrade pyo3 to 0.24.0
    gh#PyO3/maturin#2511
    * Update the TP docs to use pypi as the GH Env name
    gh#PyO3/maturin#2512
    * fix auditwheel .so relocation for namespace modules
    gh#PyO3/maturin#2513
    * Updates Rng legacy methods in tutorial
    gh#PyO3/maturin#2514

------------------------------------------------------------------
------------------  2025-3-15  -  Mar 15 2025  -------------------
------------------------------------------------------------------

++++ gobject-introspection:

  - Update to version 1.84.0:
    + No changes, stable version bump only.

++++ kernel-default:

  - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion x360
    14-dy1xxx (stable-fixes).
  - commit 7b3f84c
  - ASoC: amd: yc: Support mic on another Lenovo ThinkPad E16 Gen
    2 model (stable-fixes).
  - commit dfd3c28
  - ASoC: codecs: wm0010: Fix error handling path in
    wm0010_spi_probe() (git-fixes).
  - ASoC: rt722-sdca: add missing readable registers (git-fixes).
  - ASoC: cs42l43: Fix maximum ADC Volume (git-fixes).
  - ASoC: ops: Consistently treat platform_max as control value
    (git-fixes).
  - ASoC: Intel: sof_sdw: Fix unlikely uninitialized variable use
    in create_sdw_dailinks() (git-fixes).
  - drm/xe: remove redundant check in xe_vm_create_ioctl()
    (git-fixes).
  - drm/xe/pm: Temporarily disable D3Cold on BMG (git-fixes).
  - drm/xe/userptr: Fix an incorrect assert (git-fixes).
  - drm/xe: Release guc ids before cancelling work (git-fixes).
  - drm/i915: Increase I915_PARAM_MMAP_GTT_VERSION version to
    indicate support for partial mmaps (git-fixes).
  - drm/dp_mst: Fix locking when skipping CSN before topology
    probing (git-fixes).
  - drm/panic: fix overindented list items in documentation
    (git-fixes).
  - drm/panic: use `div_ceil` to clean Clippy warning (git-fixes).
  - drm/gma500: Add NULL check for pci_gfx_root in
    mid_get_vbt_data() (git-fixes).
  - drm/amdgpu: NULL-check BO's backing store when determining
    GFX12 PTE flags (git-fixes).
  - drm/amd/display: Fix slab-use-after-free on hdcp_work
    (git-fixes).
  - drm/amd/display: fix default brightness (git-fixes).
  - drm/amd/display: fix missing .is_two_pixels_per_container
    (git-fixes).
  - commit a0a574a

++++ kernel-rt:

  - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion x360
    14-dy1xxx (stable-fixes).
  - commit 7b3f84c
  - ASoC: amd: yc: Support mic on another Lenovo ThinkPad E16 Gen
    2 model (stable-fixes).
  - commit dfd3c28
  - ASoC: codecs: wm0010: Fix error handling path in
    wm0010_spi_probe() (git-fixes).
  - ASoC: rt722-sdca: add missing readable registers (git-fixes).
  - ASoC: cs42l43: Fix maximum ADC Volume (git-fixes).
  - ASoC: ops: Consistently treat platform_max as control value
    (git-fixes).
  - ASoC: Intel: sof_sdw: Fix unlikely uninitialized variable use
    in create_sdw_dailinks() (git-fixes).
  - drm/xe: remove redundant check in xe_vm_create_ioctl()
    (git-fixes).
  - drm/xe/pm: Temporarily disable D3Cold on BMG (git-fixes).
  - drm/xe/userptr: Fix an incorrect assert (git-fixes).
  - drm/xe: Release guc ids before cancelling work (git-fixes).
  - drm/i915: Increase I915_PARAM_MMAP_GTT_VERSION version to
    indicate support for partial mmaps (git-fixes).
  - drm/dp_mst: Fix locking when skipping CSN before topology
    probing (git-fixes).
  - drm/panic: fix overindented list items in documentation
    (git-fixes).
  - drm/panic: use `div_ceil` to clean Clippy warning (git-fixes).
  - drm/gma500: Add NULL check for pci_gfx_root in
    mid_get_vbt_data() (git-fixes).
  - drm/amdgpu: NULL-check BO's backing store when determining
    GFX12 PTE flags (git-fixes).
  - drm/amd/display: Fix slab-use-after-free on hdcp_work
    (git-fixes).
  - drm/amd/display: fix default brightness (git-fixes).
  - drm/amd/display: fix missing .is_two_pixels_per_container
    (git-fixes).
  - commit a0a574a

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.133.07 (bsc#1239653)

------------------------------------------------------------------
------------------  2025-3-14  -  Mar 14 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Patch cockpit-machines to use UEFI as default firmware
    * added uefi-default-firmware.patch

++++ cryptsetup:

  - Set pbkdf2 as the default PBKDF algorithm in LUKS2 format.
    [bsc#1236375, bsc#1236164]
    * The default PBKDF algorithm in the LUKS2 format is now Argon2id
    but its not FIPS compliant. A system would be unbootable if using
    Argon2id or Argon2i for disk encryption and then switching to
    kernel FIPS mode. This can be avoided by setting pbkdf2 as default.
    * Build using the configure option --with-luks2-pbkdf=pbkdf2.
    * Remove the dependency on libargon2 as is now provided by openssl.

++++ dpdk:

  - Remove the 'thunderx' multibuild flavor; it was identical to aarch64.
    It also makes 'Provides: dpdk-any' obsolete. [bsc#1237385]

++++ git:

  - update to 2.49.0
    https://about.gitlab.com/blog/2025/03/14/whats-new-in-git-2-49-0/
    https://raw.githubusercontent.com/git/git/refs/tags/v2.49.0/Documentation/RelNotes/2.49.0.adoc
  - switch to zlib-ng for code 16
  - docs switched to asciidoc

++++ kernel-default:

  - tty: serial: export serial_8250_warn_need_ioport (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - commit 48458ed
  - Update patches to mainline versions (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Add
    kprobes: Reduce preempt disable scope in check_kprobe_access_safe()
  - Update
    patches.suse/kprobes-Use-RCU-in-all-users-of-__module_text_address.patch
  - commit d74e94a
  - intel_idle: add Clearwater Forest SoC support (jsc#10590).
  - commit 2854d6d
  - mm/migrate_device: don't add folio to be freed to LRU in
    migrate_device_finalize() (CVE-2025-21861 bsc#1239483).
  - commit fdddb9f
  - dm vdo: add missing spin_lock_init (git-fixes).
  - commit b792a24
  - dm-integrity: Avoid divide by zero in table status in Inline
    mode (git-fixes).
  - commit e905656
  - dm-crypt: track tag_offset in convert_context (git-fixes).
  - commit 915d69f
  - dm-crypt: don't update io->sector after
    kcryptd_crypt_write_io_submit() (git-fixes).
  - commit 8f09e8c
  - dm-ebs: don't set the flag DM_TARGET_PASSES_INTEGRITY
    (git-fixes).
  - commit 0a56a91
  - dm-verity FEC: Fix RS FEC repair for roots unaligned to block
    size (take 2) (git-fixes).
  - commit 54105ae
  - dm array: fix cursor index when skipping across block boundaries
    (git-fixes).
  - commit 326fa75
  - dm array: fix unreleased btree blocks on closing a faulty
    array cursor (git-fixes).
  - commit c753f51
  - dm thin: Add missing destroy_work_on_stack() (git-fixes).
  - commit 9070649
  - dm: Fix typo in error message (git-fixes).
  - commit e99a4d1
  - geneve: Suppress list corruption splat in
    geneve_destroy_tunnels() (CVE-2025-21858 bsc#1239468).
  - gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl()
    (CVE-2025-21865 bsc#1239481).
  - geneve: Fix use-after-free in geneve_find_dev() (CVE-2025-21858
    bsc#1239468).
  - geneve: Suppress list corruption splat in
    geneve_destroy_tunnels() (CVE-2025-21858 bsc#1239468).
  - gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl()
    (CVE-2025-21865 bsc#1239481).
  - geneve: Fix use-after-free in geneve_find_dev() (CVE-2025-21858
    bsc#1239468).
  - commit 3208c63
  - rt: Add clarification comments to series.conf
  - commit dab06d0
  - Update 8250 closer to mainline implementation
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Add
    serial: 8250: Do not set UART_LSR_THRE in @read_status_mask
    serial: 8250: Explain the role of @read_status_mask
    serial: 8250: Never adjust UART_LSR_DR in @read_status_mask
    serial: 8250: Provide flag for IER toggling for RS485
    serial: 8250: Use frame time to determine timeout (bsc#1234370
    serial: 8250: Use high-level writing function for FIFO
    serial: 8250: Use @ier bits to determine if Rx is stopped
    serial: 8250_port: Assign UPIO_UNKNOWN instead of its direct value
    tty: serial: Work around warning backtrace in serial8250_set_defaults
    tty: serial: handle HAS_IOPORT dependencies
  - Refresh
    patches.suse/serial-8250-Revert-drop-lockdep-annotation-from-serial8250_clear_IER.patch
    patches.suse/serial-8250-Switch-to-nbcon-console.patch
  - blacklist.conf: Ignore reverts
  - commit 156c7e3
  - wifi: cfg80211: cancel wiphy_work before freeing wiphy
    (git-fixes).
  - wifi: mac80211: don't queue sdata::work for a non-running sdata
    (git-fixes).
  - wifi: iwlwifi: mvm: fix PNVM timeout for non-MSI-X platforms
    (git-fixes).
  - wifi: iwlwifi: pcie: Fix TSO preparation (git-fixes).
  - Bluetooth: hci_event: Fix enabling passive scanning (git-fixes).
  - drm/amd/pm: always allow ih interrupt from fw (stable-fixes).
  - drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress
    200M (stable-fixes).
  - drm/xe: Fix GT "for each engine" workarounds (stable-fixes).
  - drm/xe: Remove double pageflip (git-fixes).
  - HID: appleir: Fix potential NULL dereference at raw event handle
    (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    ishtp_hid_remove() (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    hid_ishtp_cl_remove() (git-fixes).
  - HID: google: fix unused variable warning under !CONFIG_ACPI
    (git-fixes).
  - drm/i915/dsi: Use TRANS_DDI_FUNC_CTL's own port width macro
    (git-fixes).
  - drm/i915/dsi: convert to struct intel_display (stable-fixes).
  - drm/i915: Plumb 'dsb' all way to the plane hooks (stable-fixes).
  - drm/i915/color: Extract intel_color_modeset() (stable-fixes).
  - wifi: cfg80211: cancel wiphy_work before freeing wiphy
    (git-fixes).
  - wifi: mac80211: don't queue sdata::work for a non-running sdata
    (git-fixes).
  - wifi: iwlwifi: mvm: fix PNVM timeout for non-MSI-X platforms
    (git-fixes).
  - wifi: iwlwifi: pcie: Fix TSO preparation (git-fixes).
  - Bluetooth: hci_event: Fix enabling passive scanning (git-fixes).
  - drm/amd/pm: always allow ih interrupt from fw (stable-fixes).
  - drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress
    200M (stable-fixes).
  - drm/xe: Fix GT "for each engine" workarounds (stable-fixes).
  - drm/xe: Remove double pageflip (git-fixes).
  - HID: appleir: Fix potential NULL dereference at raw event handle
    (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    ishtp_hid_remove() (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    hid_ishtp_cl_remove() (git-fixes).
  - HID: google: fix unused variable warning under !CONFIG_ACPI
    (git-fixes).
  - drm/i915/dsi: Use TRANS_DDI_FUNC_CTL's own port width macro
    (git-fixes).
  - drm/i915/dsi: convert to struct intel_display (stable-fixes).
  - drm/i915: Plumb 'dsb' all way to the plane hooks (stable-fixes).
  - drm/i915/color: Extract intel_color_modeset() (stable-fixes).
  - commit a981d96
  - crypto/testmgr: disallow sha1 in FIPS mode (jsc#PED-12225).
  - commit 8e93183
  - ipv6: sr: continue initialization at ENOENT HMAC instantiation
    failures (jsc#PED-12225).
  - commit 27c4e79
  - ipv6: sr: factor seg6_hmac_init_algo()'s per-algo code into
    separate function (jsc#PED-12225).
  - commit 4e9bfd8
  - ipv6: sr: factor seg6_hmac_exit()'s per-algo code into separate
    function (jsc#PED-12225).
  - commit f60189c
  - ipv6: sr: reject unsupported SR HMAC algos with -ENOENT
    (jsc#PED-12225).
  - commit 6f2bd16
  - Refresh patches.suse/drm-xe-Move-the-coredump-registration-to-the-worker-.patch.
  - Refresh patches.suse/drm-xe-Take-PM-ref-in-delayed-snapshot-capture-worke.patch.
  - Refresh patches.suse/xe-oa-Fix-query-mode-of-operation-for-OAR-OAC.patch.
    Alt-commits
  - commit 3371d69

++++ kernel-firmware-realtek:

  - Update to version 20250313 (git commit 1d4c88ee96ec):
    * rtw88: Add firmware v33.6.0 for RTL8814AE/RTL8814AU
    * rtw89: 8922a: update fw to v0.35.64.0
    * rtw89: 8922a: update fw to v0.35.63.0
    * rtw89: 8852c: update fw to v0.27.125.0

++++ kernel-rt:

  - tty: serial: export serial_8250_warn_need_ioport (bsc#1234370
    (PREEMPT_RT prerequisite backports)).
  - commit 48458ed
  - Update patches to mainline versions (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Add
    kprobes: Reduce preempt disable scope in check_kprobe_access_safe()
  - Update
    patches.suse/kprobes-Use-RCU-in-all-users-of-__module_text_address.patch
  - commit d74e94a
  - intel_idle: add Clearwater Forest SoC support (jsc#10590).
  - commit 2854d6d
  - mm/migrate_device: don't add folio to be freed to LRU in
    migrate_device_finalize() (CVE-2025-21861 bsc#1239483).
  - commit fdddb9f
  - dm vdo: add missing spin_lock_init (git-fixes).
  - commit b792a24
  - dm-integrity: Avoid divide by zero in table status in Inline
    mode (git-fixes).
  - commit e905656
  - dm-crypt: track tag_offset in convert_context (git-fixes).
  - commit 915d69f
  - dm-crypt: don't update io->sector after
    kcryptd_crypt_write_io_submit() (git-fixes).
  - commit 8f09e8c
  - dm-ebs: don't set the flag DM_TARGET_PASSES_INTEGRITY
    (git-fixes).
  - commit 0a56a91
  - dm-verity FEC: Fix RS FEC repair for roots unaligned to block
    size (take 2) (git-fixes).
  - commit 54105ae
  - dm array: fix cursor index when skipping across block boundaries
    (git-fixes).
  - commit 326fa75
  - dm array: fix unreleased btree blocks on closing a faulty
    array cursor (git-fixes).
  - commit c753f51
  - dm thin: Add missing destroy_work_on_stack() (git-fixes).
  - commit 9070649
  - dm: Fix typo in error message (git-fixes).
  - commit e99a4d1
  - geneve: Suppress list corruption splat in
    geneve_destroy_tunnels() (CVE-2025-21858 bsc#1239468).
  - gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl()
    (CVE-2025-21865 bsc#1239481).
  - geneve: Fix use-after-free in geneve_find_dev() (CVE-2025-21858
    bsc#1239468).
  - geneve: Suppress list corruption splat in
    geneve_destroy_tunnels() (CVE-2025-21858 bsc#1239468).
  - gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl()
    (CVE-2025-21865 bsc#1239481).
  - geneve: Fix use-after-free in geneve_find_dev() (CVE-2025-21858
    bsc#1239468).
  - commit 3208c63
  - rt: Add clarification comments to series.conf
  - commit dab06d0
  - Update 8250 closer to mainline implementation
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Add
    serial: 8250: Do not set UART_LSR_THRE in @read_status_mask
    serial: 8250: Explain the role of @read_status_mask
    serial: 8250: Never adjust UART_LSR_DR in @read_status_mask
    serial: 8250: Provide flag for IER toggling for RS485
    serial: 8250: Use frame time to determine timeout (bsc#1234370
    serial: 8250: Use high-level writing function for FIFO
    serial: 8250: Use @ier bits to determine if Rx is stopped
    serial: 8250_port: Assign UPIO_UNKNOWN instead of its direct value
    tty: serial: Work around warning backtrace in serial8250_set_defaults
    tty: serial: handle HAS_IOPORT dependencies
  - Refresh
    patches.suse/serial-8250-Revert-drop-lockdep-annotation-from-serial8250_clear_IER.patch
    patches.suse/serial-8250-Switch-to-nbcon-console.patch
  - blacklist.conf: Ignore reverts
  - commit 156c7e3
  - wifi: cfg80211: cancel wiphy_work before freeing wiphy
    (git-fixes).
  - wifi: mac80211: don't queue sdata::work for a non-running sdata
    (git-fixes).
  - wifi: iwlwifi: mvm: fix PNVM timeout for non-MSI-X platforms
    (git-fixes).
  - wifi: iwlwifi: pcie: Fix TSO preparation (git-fixes).
  - Bluetooth: hci_event: Fix enabling passive scanning (git-fixes).
  - drm/amd/pm: always allow ih interrupt from fw (stable-fixes).
  - drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress
    200M (stable-fixes).
  - drm/xe: Fix GT "for each engine" workarounds (stable-fixes).
  - drm/xe: Remove double pageflip (git-fixes).
  - HID: appleir: Fix potential NULL dereference at raw event handle
    (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    ishtp_hid_remove() (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    hid_ishtp_cl_remove() (git-fixes).
  - HID: google: fix unused variable warning under !CONFIG_ACPI
    (git-fixes).
  - drm/i915/dsi: Use TRANS_DDI_FUNC_CTL's own port width macro
    (git-fixes).
  - drm/i915/dsi: convert to struct intel_display (stable-fixes).
  - drm/i915: Plumb 'dsb' all way to the plane hooks (stable-fixes).
  - drm/i915/color: Extract intel_color_modeset() (stable-fixes).
  - wifi: cfg80211: cancel wiphy_work before freeing wiphy
    (git-fixes).
  - wifi: mac80211: don't queue sdata::work for a non-running sdata
    (git-fixes).
  - wifi: iwlwifi: mvm: fix PNVM timeout for non-MSI-X platforms
    (git-fixes).
  - wifi: iwlwifi: pcie: Fix TSO preparation (git-fixes).
  - Bluetooth: hci_event: Fix enabling passive scanning (git-fixes).
  - drm/amd/pm: always allow ih interrupt from fw (stable-fixes).
  - drm/radeon: Fix rs400_gpu_init for ATI mobility radeon Xpress
    200M (stable-fixes).
  - drm/xe: Fix GT "for each engine" workarounds (stable-fixes).
  - drm/xe: Remove double pageflip (git-fixes).
  - HID: appleir: Fix potential NULL dereference at raw event handle
    (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    ishtp_hid_remove() (git-fixes).
  - HID: intel-ish-hid: Fix use-after-free issue in
    hid_ishtp_cl_remove() (git-fixes).
  - HID: google: fix unused variable warning under !CONFIG_ACPI
    (git-fixes).
  - drm/i915/dsi: Use TRANS_DDI_FUNC_CTL's own port width macro
    (git-fixes).
  - drm/i915/dsi: convert to struct intel_display (stable-fixes).
  - drm/i915: Plumb 'dsb' all way to the plane hooks (stable-fixes).
  - drm/i915/color: Extract intel_color_modeset() (stable-fixes).
  - commit a981d96
  - crypto/testmgr: disallow sha1 in FIPS mode (jsc#PED-12225).
  - commit 8e93183
  - ipv6: sr: continue initialization at ENOENT HMAC instantiation
    failures (jsc#PED-12225).
  - commit 27c4e79
  - ipv6: sr: factor seg6_hmac_init_algo()'s per-algo code into
    separate function (jsc#PED-12225).
  - commit 4e9bfd8
  - ipv6: sr: factor seg6_hmac_exit()'s per-algo code into separate
    function (jsc#PED-12225).
  - commit f60189c
  - ipv6: sr: reject unsupported SR HMAC algos with -ENOENT
    (jsc#PED-12225).
  - commit 6f2bd16
  - Refresh patches.suse/drm-xe-Move-the-coredump-registration-to-the-worker-.patch.
  - Refresh patches.suse/drm-xe-Take-PM-ref-in-delayed-snapshot-capture-worke.patch.
  - Refresh patches.suse/xe-oa-Fix-query-mode-of-operation-for-OAR-OAC.patch.
    Alt-commits
  - commit 3371d69

++++ expat:

  - version update to 2.7.0 (CVE-2024-8176 [bsc#1239618])
    * Security fixes:
    [#893] #973  CVE-2024-8176 -- Fix crash from chaining a large number
    of entities caused by stack overflow by resolving use of
    recursion, for all three uses of entities:
  - general entities in character data ("<e>&g1;</e>")
  - general entities in attribute values ("<e k1='&g1;'/>")
  - parameter entities ("%p1;")
    Known impact is (reliable and easy) denial of service:
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:O/RC:C
    (Base Score: 7.5, Temporal Score: 7.2)
    Please note that a layer of compression around XML can
    significantly reduce the minimum attack payload size.
    * Other changes:
    [#935] #937  Autotools: Make generated CMake files look for
    libexpat.@SO_MAJOR@.dylib on macOS
    [#925]  Autotools: Sync CMake templates with CMake 3.29
    [#945] #962 #966  CMake: Drop support for CMake <3.13
    [#942]  CMake: Small fuzzing related improvements
    [#921]  docs: Add missing documentation of error code
    XML_ERROR_NOT_STARTED that was introduced with 2.6.4
    [#941]  docs: Document need for C++11 compiler for use from C++
    [#959]  tests/benchmark: Fix a (harmless) TOCTTOU
    [#944]  Windows: Fix installer target location of file xmlwf.xml
    for CMake
    [#953]  Windows: Address warning -Wunknown-warning-option
    about -Wno-pedantic-ms-format from LLVM MinGW
    [#971]  Address Cppcheck warnings
    [#969] #970  Mass-migrate links from http:// to https://
    [#947] #958 ..
    [#974] #975  Document changes since the previous release
    [#974] #975  Version info bumped from 11:0:10 (libexpat*.so.1.10.0)
    to 11:1:10 (libexpat*.so.1.10.1); see https://verbump.de/
    for what these numbers do

++++ libxslt:

  - Update to 1.1.43:
    * Major changes:
  - The non-standard EXSLT crypto extensions and support for dynamically
    loaded plugins are now disabled by default. These features can be
    enabled by passing --with-crypto or --with-plugins to configure.
    In a future release, these features will be removed.
  - Debug output and the debugger are disabled by default and can be
    enabled by passing --with-debug or --with-debugger.
    * Security:
  - [bsc#1239625, CVE-2025-24855] Fix use-after-free of XPath context node
  - [bsc#1239637, CVE-2024-55549] Fix UAF related to excluded namespaces
    * Bug fixes:
  - variables: Fix non-deterministic generated IDs
    * libxml2 related cleanup:
  - python: Don't use removed libxml2 macro
  - tests: Skip test_bad.xsl with libxml2 before 2.13
  - python: Don't include nanoftp.h and nanohttp.h
  - tests: Avoid namespace warning on Windows
  - numbers: Stop using libxml2 XPath axis API
  - numbers: Use private copy of xmlCopyCharMultiByte
  - documents: Use xmlCtxtParseDocument if available
  - tests: Make runtest compile with older libxml2 versions
  - utils: Account for libxml2 change
  - tests: Make bug-219.xsl compatible with older libxml2
  - extensions: always include stdlib.h (Hugo Beauzée-Luyssen)
  - extensions: Don't use libxml2's "modules" feature
    * Code cleanup:
  - numbers: Make static variables const
  - variables: Remove debug code
    * Portability:
  - python: Declare init func with PyMODINIT_FUNC
  - exslt: Use C99 NAN macro
    * Build:
  - cmake: Always build Python module as shared library
  - cmake: Fix compatibility in package version file
  - configure.ac: Find libgcrypt via pkg-config (Alessandro Astone)
    * Remove patches fixed in the update:
  - libxslt-reproducible.patch
  - libxslt-test-compile-with-older-libxml2-versions.patch

++++ microos-tools:

  - Update to version 4.0+git10:
    * Remove setup-systemd-proxy, now part of aaa_base
    * Drop wtmpdb SELinux AVC workaround in test suite
    * test: Wait for sshd.service before checking labels in /etc

++++ tuned:

  - tuned-ppd: add missing requirement on `asyncore` python library

------------------------------------------------------------------
------------------  2025-3-13  -  Mar 13 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20250313.4dd1cfd:
    * DIR_COLORS: add backup and temporary file extensions
    * DIR_COLORS: sort audio formats
    * DIR_COLORS: use cyan for audio formats instead of green
    * DIR_COLORS: add 'avif' to image formats
    * DIR_COLORS: add updated and sorted list of archive formats
    * DIR_COLORS: don't colour DOS/Windows executables
    * DIR_COLORS: update existing colours and add missing ones
    * DIR_COLORS: add COLORTERM and 'st' terminal
    * DIR_COLORS: update file description
    * DIR_COLORS: sort TERM entries
    * DIR_COLORS: remove COLOR, OPTIONS and EIGHTBIT
  - Update to version 84.87+git20250313.e71c2f4:
    * Respect PROFILEREAD/CSHRCREAD at shell switch
    * Modernize specfile
    * Add safety quotes and proper escaping
    * Avoid bashisms in build recipe
    * Add setup-systemd-proxy-env
    * profile.{sh,csh}: Drop useless proxy variables cleanup

++++ drbd-utils:

  - drbd_passive resource times out after 10 minutes and drbd device doesn't exist (bsc#1239437)
    * add patch
    + bsc-1239437_drbd.rules-fix-missing-udev-device.patch
    * update drbd.spec
    + remove '--without-83support' from configure, which is not needed anymore

++++ grub2:

  - Update the patch to fix "SRK not matched" errors when unsealing
    the key (bsc#1232411) (bsc#1247242)
    * 0001-tpm2-Add-extra-RSA-SRK-types.patch

++++ haproxy:

  - Update to version 3.1.5+git0.076df0292:
    * [RELEASE] Released version 3.1.5
    * BUG/MEDIUM: spoe/mux-spop: Introduce an NOOP action to deal with empty ACK
    * BUG/MEDIUM: applet: Don't handle EOI/EOS/ERROR is applet is waiting for room
    * [RELEASE] Released version 3.1.4
    * DOC: option redispatch should mention persist options
    * BUG/MINOR: stats-json: Define JSON_INT_MAX as a signed integer
    * BUG/MINOR: flt-trace: Support only one name option
    * BUG/MINOR: auth: Fix a leak on error path when parsing user's groups
    * BUG/MINOR: config/userlist: Support one 'users' option for 'group' directive
    * BUG/MINOR: cli: Fix a possible infinite loop in _getsocks()
    * BUG/MINOR: cli: Fix memory leak on error for _getsocks command
    * BUG/MINOR: cli: Don't set SE flags from the cli applet
    * MINOR: mux-spop: Set SPOP_CF_ERROR flag on connection error only
    * MINOR: mux-spop: Report EOI on the SE when a ACK is received for a stream
    * MINOR: flt-spoe: Report end of input immediately after applet init
    * BUG/MEDIUM: flt-spoe: Properly handle end of stream from the SPOE applet
    * BUG/MEDIUM: applet: Don't pretend to have more data to handle EOI/EOS/ERROR
    * BUG/MEDIUM: flt-spoe: Set/test applet flags instead of SE flags from I/O handler
    * BUG/MINOR: http-check: Don't pretend a C-L heeader is set before adding it
    * BUG/MINOR: tcp-rules: Don't forward close during tcp-response content rules eval
    * BUG/MEDIUM: mux-fcgi: Properly handle read0 on partial records
    * DOC: htx: clarify <mark> parameter for htx_xfer_blks()
    * BUG/MEDIUM: htx: wrong count computation in htx_xfer_blks()
    * MEDIUM: epoll: skip reports of stale file descriptors
    * DEBUG: epoll: store and compare the FD's generation count with reported event
    * MINOR: fd: add a generation number to file descriptors
    * DEBUG: fd: add a counter of takeovers of an FD since it was last opened
    * BUG/MEDIUM: chunk: make sure to flush the trash pool before resizing
    * MINOR: epoll: permit to mask certain specific events
    * MINOR: quic: adapt credit based pacing to BBR
    * MINOR: quic: remove unused pacing burst in bind_conf/quic_cc_path
    * MEDIUM: quic: use dynamic credit for pacing
    * MEDIUM: mux-quic: reduce pacing CPU usage with passive wait
    * MEDIUM: quic: implement credit based pacing
    * MINOR: mux-quic: increment pacing retry counter on expired
    * MINOR: quic: rename pacing_rate cb to pacing_inter
    * BUG/MINOR: stktable: invalid use of stkctr_set_entry() with mixed table types
    * BUG/MINOR: mux-h2: Properly handle full or truncated HTX messages on shut
    * REGTESTS: Fix truncated.vtc to send 0-CRLF
    * BUG/MINOR: mux-quic: prevent crash after MUX init failure
    * BUG/MINOR: quic: prevent crash on conn access after MUX init failure
    * BUG/MINOR: fcgi: Don't set the status to 302 if it is already set
    * BUG/MEDIUM: filters: Handle filters registered on data with no payload callback
    * BUG/MINOR: cli: Wait for the last ACK when FDs are xferred from the old worker
    * BUG/MEDIUM: cli: Be sure to drop all input data in END state
    * BUG/MINOR: ssl/cli: "show ssl crt-list" lacks sigals
    * BUG/MINOR: ssl/cli: "show ssl crt-list" lacks client-sigals
    * BUG/MEDIUM: fd: mark FD transferred to another process as FD_CLONED
    * BUG/MINOR: mworker: post_section_parser for the last section in discovery
    * BUG/MINOR: mworker: section ignored in discovery after a post_section_parser
    * BUG/MINOR: quic: fix CRYPTO payload size calcul for encoding
    * BUG/MINOR: quic: reserve length field for long header encoding
    * BUG/MEDIUM: debug: close a possible race between thread dump and panic()
    * BUG/MEDIUM: ssl: chosing correct certificate using RSA-PSS with TLSv1.3
  - apparmor: fix debug output when running in a vm (/sys paths
    differ from hardware)

++++ kernel-default:

  - Refresh
    patches.suse/serial-8250-Revert-drop-lockdep-annotation-from-serial8250_clear_IER.patch.
  - blacklist.conf: Remove blacklisted dependency
  - commit c753de3
  - Refresh patches.suse/serial-8250-Switch-to-nbcon-console.patch.
  - commit 82ef2ab
  - tcp: Defer ts_recent changes until req is owned (git-fixes).
  - tcp: devmem: don't write truncated dmabuf CMSGs to userspace
    (git-fixes).
  - tcp: adjust rcvq_space after updating scaling ratio (git-fixes).
  - tcp: Annotate data-race around sk->sk_mark in tcp_v4_send_reset
    (git-fixes).
  - tcp: check space before adding MPTCP SYN options (git-fixes).
  - net/tcp: Add missing lockdep annotations for TCP-AO hlist
    traversals (git-fixes).
  - commit ac8e01e
  - tcp: drop secpath at the same time as we currently drop dst
    (CVE-2025-21864 bsc#1239482).
  - commit 847360a
  - net/smc: check iparea_offset and ipv6_prefixes_cnt when
    receiving proposal msg (CVE-2024-49571 bsc#1235733).
  - commit 3e094ad
  - Refresh
    patches.suse/0011-PM-hibernate-require-hibernate-snapshot-image-to-be-.patch.
    Improve the secret key invalid message.(bsc#1238797)
  - commit 401f424

++++ kernel-firmware-iwlwifi:

  - Update to version 20250312 (git commit 89ba9b7ce05c):
    * iwlwifi: add Bz/gl FW for core94-91 release
    * iwlwifi: update ty/So/Ma firmwares for core94-91 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core94-91 release

++++ kernel-rt:

  - Refresh
    patches.suse/serial-8250-Revert-drop-lockdep-annotation-from-serial8250_clear_IER.patch.
  - blacklist.conf: Remove blacklisted dependency
  - commit c753de3
  - Refresh patches.suse/serial-8250-Switch-to-nbcon-console.patch.
  - commit 82ef2ab
  - tcp: Defer ts_recent changes until req is owned (git-fixes).
  - tcp: devmem: don't write truncated dmabuf CMSGs to userspace
    (git-fixes).
  - tcp: adjust rcvq_space after updating scaling ratio (git-fixes).
  - tcp: Annotate data-race around sk->sk_mark in tcp_v4_send_reset
    (git-fixes).
  - tcp: check space before adding MPTCP SYN options (git-fixes).
  - net/tcp: Add missing lockdep annotations for TCP-AO hlist
    traversals (git-fixes).
  - commit ac8e01e
  - tcp: drop secpath at the same time as we currently drop dst
    (CVE-2025-21864 bsc#1239482).
  - commit 847360a
  - net/smc: check iparea_offset and ipv6_prefixes_cnt when
    receiving proposal msg (CVE-2024-49571 bsc#1235733).
  - commit 3e094ad
  - Refresh
    patches.suse/0011-PM-hibernate-require-hibernate-snapshot-image-to-be-.patch.
    Improve the secret key invalid message.(bsc#1238797)
  - commit 401f424

++++ spirv-tools:

  - Bump BuildRequires to match spirv-headers

++++ ncurses:

  - Add _c++ library subpackages to libncurses5, libncurses6 & libncurses6-compat
    This removes libstdc++ from the ncurses dependency chain unless a binary or
    librarly explicitly depends on libncurses++ or libncurses++w

++++ pciutils:

  - Synchronize SLE-12 and openSUSE:Factory [jsc#PED-4587].
    The following patches are now obsolete in version 3.13.0:
    * add-decoding-of-vendor-specific-vpd-fields.patch
    * pciutils-3.1.7-fix-memory-leak-in-get_cache_name.patch
    * pciutils-3.2.0_update-dist.patch
    * pciutils-3.5.1-add-support-for-32-bit-pci-domains.patch
    * pciutils-lspci-Correct-Root-Capabilities-CRS-Software-Visibil.patch
    * show-gen4-speed-properly.patch

++++ systemd:

  - triggers.systemd: more posix.fork() conversion (bsc#1238566)

++++ vulkan-loader:

  - Update to tag SDK-1.4.309.0
    * Make Xrandr not implicitly required when x11 is used
    * Make emulate_VK_EXT_surface_maintenance1 comply better with
    Vulkan spec
    * Support VK_GOOGLE_surfaceless_query

++++ psmisc:

  - fix build with gcc15
  - added patches
    + psmisc-gcc15.patch

++++ suse-module-tools:

  - Update to version 16.0.59:
    * inkmp-script: fix "bad array subscript" error (bsc#1239550)
  - Update to version 16.0.58:
    * mkosi-initrd: build initrds directly to /boot
    (gh#openSUSE/suse-module-tools#115)

++++ zypper:

  - Do not double encode URL strings passed on the commandline
    (bsc#1237587)
    URLs passed on the commandline must have their special chars
    encoded already. We just want to check and encode forgotten
    unsafe chars like a blank. A '%' however must not be encoded
    again.
  - version 1.14.88

------------------------------------------------------------------
------------------  2025-3-12  -  Mar 12 2025  -------------------
------------------------------------------------------------------

++++ blog:

  - blog: recommend blog-plymouth instead of only suggesting
    * More house advertising to make plymouth support of blogd
    more familiar and known by the users

++++ cockpit:

  - move selinux policies to cockpit-selinux-policies bsc#1236057

++++ python-kiwi:

  - Explicitly request shadow-utils
    Make sure shadow-utils gets installed for rawhide
    integration tests
  - Drop test-image-suse-on-dnf test
    This was just a "can this work" test but has no real
    relevance for users since nobody would use dnf to build
    a suse image, there is also no help when it does not
    work. So let's drop this test build

++++ glibc:

  - Do not build libnsl1 (bsc#1239459)

++++ gstreamer:

  - Update to version 1.26.0:
    + Highlights
  - H.266 Versatile Video Coding (VVC) codec support
  - Low Complexity Enhancement Video Coding (LCEVC) support
  - Closed captions: H.264/H.265 extractor/inserter,
    cea708overlay, cea708mux, tttocea708 and more
  - New hlscmafsink, hlssink3, and hlsmultivariantsink; HLS/DASH
    client and dashsink improvements
  - New AWS and Speechmatics transcription, translation and TTS
    services elements, plus translationbin
  - Splitmux lazy loading and dynamic fragment addition support
  - Matroska: H.266 video and rotation tag support, defined
    latency muxing
  - MPEG-TS: support for H.266, JPEG XS, AV1, VP9 codecs and
    SMPTE ST-2038 and ID3 meta; mpegtslivesrc
  - ISO MP4: support for H.266, Hap, Lagarith lossless codecs;
    raw video support; rotation tags
  - SMPTE 2038 ancillary data streams support
  - JPEG XS image codec support
  - Analytics: New TensorMeta; N-to-N relationships; Mtd to carry
    segmentation masks
  - ONVIF metadata extractor and conversion to/from relation
    metas
  - New originalbuffer element that can restore buffers again
    after transformation steps for analytics
  - Improved Python bindings for analytics API
  - Lots of Vulkan integration and Vulkan Video decoder/encoder
    improvements
  - OpenGL integration improvements, esp. in glcolorconvert,
    gldownload, glupload
  - Qt5/Qt6 QML GL sinks now support direct DMABuf import from
    hardware decoders
  - CUDA: New compositor, Jetson NVMM memory support,
    stream-ordered allocator
  - NVCODEC AV1 video encoder element, and nvdsdewarp
  - New Direct3D12 integration support library
  - New d3d12swapchainsink and d3d12deinterlace elements and
    D3D12 sink/source for zero-copy IPC
  - Decklink HDR support (PQ + HLG) and frame scheduling
    enhancements
  - AJA capture source clock handling and signal loss recovery
    improvements
  - RTP and RTSP: New rtpbin sync modes, client-side MIKEY
    support in rtspsrc
  - New Rust rtpbin2, rtprecv, rtpsend, and many new Rust RTP
    payloaders and depayloaders
  - webrtcbin support for basic rollbacks and other improvements
  - webrtcsink: support for more encoders, SDP munging, and a
    built-in web/signalling server
  - webrtcsrc/sink: support for uncompressed audio/video and NTP
    & PTP clock signalling and synchronization
  - rtmp2: server authentication improvements incl. Limelight
    CDN (llnw) authentication
  - New Microsoft WebView2 based web browser source element
  - The GTK3 plugin has gained support for OpenGL/WGL on Windows
  - Many GTK4 paintable sink improvements
  - GstPlay: id-based stream selection and message API
    improvements
  - Real-time pipeline visualization in a browser using a new
    dots tracer and viewer
  - New tracers for tracking memory usage, pad push timings, and
    buffer flow as pcap files
  - VA hardware-acclerated H.266/VVC decoder, VP8 and JPEG
    encoders, VP9/VP8 alpha decodebins
  - Video4Linux2 elements support DMA_DRM caps negotiation now
  - V4L2 stateless decoders implement inter-frame resolution
    changes for AV1 and VP9
  - Editing services: support for reverse playback and audio
    channel reordering
  - New QUIC-based elements for working with raw QUIC streams,
    RTP-over-QUIC (RoQ) and WebTransport
  - Apple AAC audio encoder and multi-channel support for the
    Apple audio decoders
  - cerbero: Python bindings and introspection support; improved
    Windows installer based on WiX5
  - Lots of new plugins, features, performance improvements and
    bug fixes
    + Possibly Breaking Changes
  - qroverlay: the "pixel-size" property has been removed in
    favour of a new "size" property with slightly different
    semantics, where the size of the square is expressed in
    percent of the smallest of width and height.
  - svtav1enc: The SVT-AV1 3.0.0 API exposes a different
    mechanism to configure the level of parallelism when
    encoding, which has been exposed as a new
    "level-of-parallelism" property. The old "logical-processors"
    property is no longer functional if the plugin has been
    compiled against the new API, which might affect encoder
    performance if application code setting it is not updated.
  - udpsrc: now disables allocated port reuse for unicast to
    avoid unexpected side-effects of SO_REUSEADDR where the
    kernel allocates the same listening port for multiple udpsrc.
  - uridecodebin3 remove non-functional "source" property that
    doesn't make sense and always returned NULL anyway.
    + Known Issues
  - GstBuffer now uses C11 atomics for 64 bit atomic operations
    if available, which may require linking to libatomic on some
    systems, but this is not done automatically yet, see issue
    glfo#gstreamer/gstreamer#4177.
    + For more detailed information on this update, please see
    https://gstreamer.freedesktop.org/releases/1.26/

++++ gstreamer-plugins-base:

  - Update to version 1.26.0:
    + Highlights
  - H.266 Versatile Video Coding (VVC) codec support
  - Low Complexity Enhancement Video Coding (LCEVC) support
  - Closed captions: H.264/H.265 extractor/inserter,
    cea708overlay, cea708mux, tttocea708 and more
  - New hlscmafsink, hlssink3, and hlsmultivariantsink; HLS/DASH
    client and dashsink improvements
  - New AWS and Speechmatics transcription, translation and TTS
    services elements, plus translationbin
  - Splitmux lazy loading and dynamic fragment addition support
  - Matroska: H.266 video and rotation tag support, defined
    latency muxing
  - MPEG-TS: support for H.266, JPEG XS, AV1, VP9 codecs and
    SMPTE ST-2038 and ID3 meta; mpegtslivesrc
  - ISO MP4: support for H.266, Hap, Lagarith lossless codecs;
    raw video support; rotation tags
  - SMPTE 2038 ancillary data streams support
  - JPEG XS image codec support
  - Analytics: New TensorMeta; N-to-N relationships; Mtd to carry
    segmentation masks
  - ONVIF metadata extractor and conversion to/from relation
    metas
  - New originalbuffer element that can restore buffers again
    after transformation steps for analytics
  - Improved Python bindings for analytics API
  - Lots of Vulkan integration and Vulkan Video decoder/encoder
    improvements
  - OpenGL integration improvements, esp. in glcolorconvert,
    gldownload, glupload
  - Qt5/Qt6 QML GL sinks now support direct DMABuf import from
    hardware decoders
  - CUDA: New compositor, Jetson NVMM memory support,
    stream-ordered allocator
  - NVCODEC AV1 video encoder element, and nvdsdewarp
  - New Direct3D12 integration support library
  - New d3d12swapchainsink and d3d12deinterlace elements and
    D3D12 sink/source for zero-copy IPC
  - Decklink HDR support (PQ + HLG) and frame scheduling
    enhancements
  - AJA capture source clock handling and signal loss recovery
    improvements
  - RTP and RTSP: New rtpbin sync modes, client-side MIKEY
    support in rtspsrc
  - New Rust rtpbin2, rtprecv, rtpsend, and many new Rust RTP
    payloaders and depayloaders
  - webrtcbin support for basic rollbacks and other improvements
  - webrtcsink: support for more encoders, SDP munging, and a
    built-in web/signalling server
  - webrtcsrc/sink: support for uncompressed audio/video and NTP
    & PTP clock signalling and synchronization
  - rtmp2: server authentication improvements incl. Limelight
    CDN (llnw) authentication
  - New Microsoft WebView2 based web browser source element
  - The GTK3 plugin has gained support for OpenGL/WGL on Windows
  - Many GTK4 paintable sink improvements
  - GstPlay: id-based stream selection and message API
    improvements
  - Real-time pipeline visualization in a browser using a new
    dots tracer and viewer
  - New tracers for tracking memory usage, pad push timings, and
    buffer flow as pcap files
  - VA hardware-acclerated H.266/VVC decoder, VP8 and JPEG
    encoders, VP9/VP8 alpha decodebins
  - Video4Linux2 elements support DMA_DRM caps negotiation now
  - V4L2 stateless decoders implement inter-frame resolution
    changes for AV1 and VP9
  - Editing services: support for reverse playback and audio
    channel reordering
  - New QUIC-based elements for working with raw QUIC streams,
    RTP-over-QUIC (RoQ) and WebTransport
  - Apple AAC audio encoder and multi-channel support for the
    Apple audio decoders
  - cerbero: Python bindings and introspection support; improved
    Windows installer based on WiX5
  - Lots of new plugins, features, performance improvements and
    bug fixes
    + Some other changes include:
  - New AV1 caps utility functions for AV1 Codec Configuration
    Record codec_data handling
  - The GstEncodingProfile (de)serialization functions are now
    public
  - GstEncodingProfile gained a way to specify a factory-name
    when specifying caps. In some cases you want to ensure that
    a specific element factory is used while requiring some
    specific caps, but this was not possible so far. You can now
    do e.g. qtmux:video/x-prores,variant=standard|factory-name=avenc_prores_ks
    to ensure that the avenc_prores_ks factory is used to produce
    the variant of prores video stream.
    + For more detailed information on this update, please see
    https://gstreamer.freedesktop.org/releases/1.26/

++++ guestfs-tools:

  - Update to version 1.53.8 (jsc#PED-8910)
    * mlstdutils: Reimplement String.find, add String.find_from
    * mlstdutils: Reimplement String.nsplit tail recursively
    * mldrivers: Handle large output from 'rpm -ql' command
    * drivers: Handle large output from 'rpm -ql' command
    This requires the new guestfs_sh_out API from libguestfs 1.55.6
    * Add a 'git-publish' profile
    * builder: Link to the actually existing virt-builder templates dir
    * mlcustomize: Drop old virtio-win dir name scraping
    * mlcustomize: Remove dnf --verbose option

++++ kernel-default:

  - series.conf: Move modules patches to sorted section
  - commit 3d9f4dd
  - scripts/python/git_sort/git_sort.yaml: update modules location
    Update the modules-next location jeyu/modules-next does not appear to have
    been used since 2021.
    See also ced75a2f5da7 ("MAINTAINERS: Add Luis Chamberlain as modules maintainer")
  - commit 7c7198e
  - series.conf: Move patch to sorted section
  - commit 3d9810e
  - ARM: module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/arm64-module-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/bpf-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/bug-Use-RCU-instead-RCU-sched-to-protect-module_bug_list.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/cfi-Use-RCU-while-invoking-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Allow-__module_address-to-be-called-from-RCU-section.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Begin-to-move-from-RCU-sched-to-RCU.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Extend-the-preempt-disabled-section-in-dereference_symbol_descriptor.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Remove-module_assert_mutex_or_preempt-from-try_add_tainted_module.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-__find_kallsyms_symbol_value.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-__is_module_percpu_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-all-users-of-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-find_kallsyms_symbol.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-find_module_all.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-find_symbol.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-module_get_kallsym.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-module_kallsyms_on_each_symbol.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-search_module_extables.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-proper-RCU-assignment-in-add_kallsyms.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/static_call-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/x86-Use-RCU-in-all-users-of-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - commit bb9ab70
  - series.conf: Move RT-specific patches pending for mainline to top of RT section
  - commit bc2a85a
  - config: Disable CONFIG_CGROUP_FREEZER (jsc#PED-12329)
    We already have (by default):
    [#] CONFIG_MEMCG_V1 is not set
    [#] CONFIG_CPUSETS_V1 is not set
    that disable memory and cpuset v1 controllers respectively.
    Natural extension is disabling freezer v1 controller (as gradually going
    away from v1 controllers).
    This keeps the global freezer functionality (for suspend) and there is
    independent group freezing in cgroup v2.
  - commit 46442b5
  - config: Disable CONFIG_CGROUP_DEVICE (jsc#PED-12328)
    We already have (by default):
    [#] CONFIG_MEMCG_V1 is not set
    [#] CONFIG_CPUSETS_V1 is not set
    that disable memory and cpuset v1 controllers respectively.
    The replacement are BPF device-control programs attached to cgroups.
    openSUSE Tumbleweed switched to (such) v2 setup in 2021-03. Today is
    time for config cleanup.
  - commit f845e63
  - config: Disable CONFIG_CGROUP_CPUACCT (jsc#PED-12327)
    We already have (by default):
    [#] CONFIG_MEMCG_V1 is not set
    [#] CONFIG_CPUSETS_V1 is not set
    that disable memory and cpuset v1 controllers respectively.
    cpuacct is v1-only controller whose functionality was taken over with
    cgroup v2 core. It even adds slight overhead since it doubly-accounts
    CPU time in root cgroup even on v2-only runtimes.
    openSUSE Tumbleweed switched to v2 setup in 2021-03. Today (if not
    earlier) is time for config cleanup.
  - commit fb4110d
  - net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases
    (CVE-2025-21788 bsc#1238761).
  - net: ravb: Fix missing rtnl lock in suspend/resume path
    (CVE-2025-21801 bsc#1238758).
  - net: hns3: fix oops when unload drivers paralleling
    (CVE-2025-21802 bsc#1238751).
  - commit 3709944
  - pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fw
    (git-fixes).
  - pinctrl: bcm281xx: Fix incorrect regmap max_registers value
    (git-fixes).
  - commit 53a34e8
  - Bluetooth: MGMT: Fix slab-use-after-free Read in
    mgmt_remove_adv_monitor_sync (bsc#1239095 CVE-2024-58013).
  - commit 828d19c
  - Update
    patches.suse/Bluetooth-btusb-mediatek-Add-locks-for-usb_driver_cl.patch
    (git-fixes CVE-2025-21827 bsc#1238974).
  - Update
    patches.suse/HID-hid-thrustmaster-fix-stack-out-of-bounds-read-in.patch
    (git-fixes CVE-2025-21794 bsc#1238502).
  - Update
    patches.suse/Input-synaptics-fix-crash-when-enabling-pass-through.patch
    (bsc#1219522 CVE-2025-21746 bsc#1238498).
  - Update
    patches.suse/KVM-x86-Load-DR6-with-guest-value-only-before-enteri.patch
    (git-fixes CVE-2025-21839 bsc#1239061).
  - Update
    patches.suse/LoongArch-Fix-warnings-during-S3-suspend.patch
    (git-fixes CVE-2025-21803 bsc#1238744).
  - Update
    patches.suse/NFC-nci-Add-bounds-checking-in-nci_hci_create_pipe.patch
    (git-fixes CVE-2025-21735 bsc#1238497).
  - Update
    patches.suse/PCI-Avoid-putting-some-root-ports-into-D3-on-TUXEDO-.patch
    (git-fixes CVE-2025-21831 bsc#1239039).
  - Update
    patches.suse/PCI-rcar-ep-Fix-incorrect-variable-used-when-calling.patch
    (git-fixes CVE-2025-21804 bsc#1238736).
  - Update
    patches.suse/RDMA-mlx5-Fix-a-race-for-an-ODP-MR-which-leads-to-CQ.patch
    (git-fixes CVE-2025-21732 bsc#1237877).
  - Update
    patches.suse/RDMA-mlx5-Fix-implicit-ODP-use-after-free.patch
    (git-fixes CVE-2025-21714 bsc#1237890).
  - Update patches.suse/RDMA-rtrs-Add-missing-deinit-call.patch
    (git-fixes CVE-2025-21805 bsc#1238741).
  - Update
    patches.suse/RDMA-rxe-Fix-the-warning-__rxe_cleanup-0x12c-0x170-r.patch
    (git-fixes CVE-2025-21829 bsc#1239030).
  - Update
    patches.suse/Revert-drm-amd-display-Use-HW-lock-mgr-for-PSR1.patch
    (stable-fixes CVE-2025-21819 bsc#1238994).
  - Update
    patches.suse/amdkfd-properly-free-gang_ctx_bo-when-failed-to-init.patch
    (git-fixes CVE-2025-21842 bsc#1239063).
  - Update
    patches.suse/arm64-cacheinfo-Avoid-out-of-bounds-write-to-cacheinfo-array.patch
    (git-fixes CVE-2025-21785 bsc#1238747).
  - Update
    patches.suse/ax25-Fix-refcount-leak-caused-by-setting-SO_BINDTODE.patch
    (git-fixes CVE-2025-21792 bsc#1238745).
  - Update patches.suse/ax25-rcu-protect-dev-ax25_ptr.patch
    (git-fixes CVE-2025-21812 bsc#1238471).
  - Update
    patches.suse/batman-adv-fix-panic-during-interface-removal.patch
    (git-fixes CVE-2025-21781 bsc#1238735).
  - Update
    patches.suse/blk-cgroup-Fix-class-block_class-s-subsystem-refcount-leakage.patch
    (bsc#1237558 CVE-2025-21745 bsc#1238785).
  - Update
    patches.suse/block-bfq-fix-waker_bfqq-UAF-after-bfq_split_bfqq.patch
    (git-fixes CVE-2025-21631 bsc#1236099).
  - Update
    patches.suse/block-don-t-revert-iter-for-EIOCBQUEUED.patch
    (git-fixes CVE-2025-21832 bsc#1239105).
  - Update
    patches.suse/can-ctucanfd-handle-skb-allocation-failure.patch
    (git-fixes CVE-2025-21775 bsc#1238501).
  - Update
    patches.suse/can-etas_es58x-fix-potential-NULL-pointer-dereferenc.patch
    (git-fixes CVE-2025-21773 bsc#1238762).
  - Update
    patches.suse/can-rockchip-rkcanfd_handle_rx_fifo_overflow_int-bai.patch
    (git-fixes CVE-2025-21774 bsc#1238770).
  - Update
    patches.suse/driver-core-class-Fix-wild-pointer-dereferences-in-A.patch
    (git-fixes CVE-2025-21810 bsc#1238757).
  - Update
    patches.suse/drm-amdgpu-avoid-buffer-overflow-attach-in-smu_sys_s.patch
    (stable-fixes CVE-2025-21780 bsc#1239115).
  - Update
    patches.suse/drm-amdgpu-bail-out-when-failed-to-load-fw-in-psp_in.patch
    (git-fixes CVE-2025-21784 bsc#1238510).
  - Update
    patches.suse/firewire-test-Fix-potential-null-dereference-in-fire.patch
    (git-fixes CVE-2025-21798 bsc#1238776).
  - Update
    patches.suse/gpiolib-Fix-crash-on-error-in-gpiochip_get_ngpios.patch
    (git-fixes CVE-2025-21783 bsc#1238530).
  - Update
    patches.suse/gpu-host1x-Fix-a-use-of-uninitialized-mutex.patch
    (git-fixes CVE-2025-21824 bsc#1238478).
  - Update
    patches.suse/iommu-Fix-potential-memory-leak-in-iopf_queue_remove.patch
    (git-fixes CVE-2025-21770 bsc#1238495).
  - Update patches.suse/landlock-Handle-weird-files.patch (git-fixes
    CVE-2025-21830 bsc#1239033).
  - Update
    patches.suse/md-md-bitmap-Synchronize-bitmap_get_stats-with-bitmap-lifetime.patch
    (git-fixes CVE-2025-21712 bsc#1237886).
  - Update patches.suse/misc-fastrpc-Fix-copy-buffer-page-size.patch
    (git-fixes CVE-2025-21734 bsc#1238734).
  - Update
    patches.suse/mm-compaction-fix-UBSAN-shift-out-of-bounds-warning.patch
    (git fixes (mm/compaction) CVE-2025-21815 bsc#1238474).
  - Update
    patches.suse/msft-hv-3160-KVM-x86-Reject-Hyper-V-s-SEND_IPI-hypercalls-if-loca.patch
    (git-fixes CVE-2025-21779 bsc#1238768).
  - Update
    patches.suse/nbd-don-t-allow-reconnect-after-disconnect.patch
    (git-fixes CVE-2025-21731 bsc#1237881).
  - Update
    patches.suse/neighbour-use-RCU-protection-in-__neigh_notify.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21763 bsc#1237897).
  - Update
    patches.suse/net-avoid-race-between-device-unregistration-and-eth.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21701 bsc#1237164).
  - Update
    patches.suse/net-mlx5-HWS-change-error-flow-on-matcher-disconnect.patch
    (jsc#PED-11331 CVE-2025-21751 bsc#1238907).
  - Update
    patches.suse/net-mlx5-HWS-fix-definer-s-HWS_SET32-macro-for-negat.patch
    (jsc#PED-11331 CVE-2025-21800 bsc#1238743).
  - Update
    patches.suse/net-mlx5e-add-missing-cpu_to_node-to-kvzalloc_node-i.patch
    (jsc#PED-11331 CVE-2025-21717 bsc#1238866).
  - Update
    patches.suse/net-rose-fix-timer-races-against-user-threads.patch
    (git-fixes CVE-2025-21718 bsc#1239073).
  - Update
    patches.suse/net-rose-prevent-integer-overflows-in-rose_setsockop.patch
    (git-fixes CVE-2025-21711 bsc#1239114).
  - Update
    patches.suse/net-usb-rtl8150-enable-basic-endpoint-checking.patch
    (git-fixes CVE-2025-21708 bsc#1239087).
  - Update
    patches.suse/netdev-prevent-accessing-NAPI-instances-from-another.patch
    (jsc#PED-12085 CVE-2025-21659 bsc#1236206).
  - Update
    patches.suse/nfsd-clear-acl_access-acl_default-after-releasing-them.patch
    (git-fixes CVE-2025-21796 bsc#1238716).
  - Update patches.suse/padata-avoid-UAF-for-reorder_work.patch
    (git-fixes CVE-2025-21726 bsc#1238865).
  - Update patches.suse/padata-fix-UAF-in-padata_reorder.patch
    (git-fixes CVE-2025-21727 bsc#1237876).
  - Update
    patches.suse/partitions-mac-fix-handling-of-bogus-partition-table.patch
    (git-fixes CVE-2025-21772 bsc#1238911).
  - Update
    patches.suse/powerpc-pseries-iommu-Don-t-unset-window-if-it-was-n.patch
    (jsc#PED-10539 git-fixes CVE-2025-21713 bsc#1237887).
  - Update
    patches.suse/sched_ext-Fix-incorrect-autogroup-migration-detection.patch
    (git fixes (sched) CVE-2025-21771 bsc#1238752).
  - Update
    patches.suse/scsi-mpi3mr-Fix-possible-crash-when-setting-up-bsg-fails.patch
    (git-fixes CVE-2025-21723 bsc#1238864).
  - Update
    patches.suse/seccomp-passthrough-uretprobe-systemcall-without-fil.patch
    (git-fixes CVE-2025-21834 bsc#1239026).
  - Update patches.suse/spi-sn-f-ospi-Fix-division-by-zero.patch
    (git-fixes CVE-2025-21793 bsc#1238500).
  - Update patches.suse/tty-xilinx_uartps-split-sysrq-handling.patch
    (git-fixes CVE-2025-21820 bsc#1238479).
  - Update
    patches.suse/usb-cdc-acm-Check-control-transfer-buffer-size-befor.patch
    (git-fixes CVE-2025-21704 bsc#1237571).
  - Update
    patches.suse/usb-gadget-core-flush-gadget-workqueue-after-device-.patch
    (git-fixes CVE-2025-21838 bsc#1239065).
  - Update
    patches.suse/usb-gadget-f_midi-fix-MIDI-Streaming-descriptor-leng.patch
    (git-fixes CVE-2025-21835 bsc#1239068).
  - Update patches.suse/usbnet-ipheth-fix-DPE-OoB-read.patch
    (git-fixes CVE-2025-21741 bsc#1238767).
  - Update
    patches.suse/usbnet-ipheth-fix-possible-overflow-in-DPE-length-ch.patch
    (git-fixes CVE-2025-21743 bsc#1238781).
  - Update
    patches.suse/usbnet-ipheth-use-static-NDP16-location-in-URB.patch
    (git-fixes CVE-2025-21742 bsc#1238771).
  - Update
    patches.suse/vsock-Keep-the-binding-until-socket-destruction.patch
    (git-fixes CVE-2025-21756 bsc#1238876).
  - Update
    patches.suse/vsock-Orphan-socket-after-transport-release.patch
    (jsc#PED-11028 CVE-2025-21755 bsc#1237882).
  - Update
    patches.suse/wifi-brcmfmac-Check-the-return-value-of-of_property_.patch
    (stable-fixes CVE-2025-21750 bsc#1238905).
  - Update
    patches.suse/wifi-mac80211-don-t-flush-non-uploaded-STAs.patch
    (git-fixes CVE-2025-21828 bsc#1238958).
  - Update
    patches.suse/wifi-rtw89-avoid-to-init-mgnt_entry-list-twice-when-.patch
    (git-fixes CVE-2025-21730 bsc#1237878).
  - Update
    patches.suse/wifi-rtw89-fix-race-between-cancel_hw_scan-and-hw_sc.patch
    (git-fixes CVE-2025-21729 bsc#1237874).
  - Update
    patches.suse/workqueue-Put-the-pwq-after-detaching-the-rescuer-from-the-pool.patch
    (bsc#1237866 CVE-2025-21786 bsc#1238505).
  - Update patches.suse/zram-fix-potential-UAF-of-zram-table.patch
    (git-fixes CVE-2025-21671 bsc#1236692).
  - commit af45f0e
  - Update
    patches.suse/ALSA-6fire-Release-resources-at-card-release.patch
    (git-fixes CVE-2024-53239 bsc#1235054 bsc#1234853).
  - Update
    patches.suse/ASoC-soc-pcm-don-t-use-soc_pcm_ret-on-.prepare-callb.patch
    (stable-fixes CVE-2024-58077 bsc#1239090).
  - Update
    patches.suse/Bluetooth-L2CAP-do-not-leave-dangling-sk-pointer-on-.patch
    (stable-fixes CVE-2024-56605 bsc#1235061 bsc#1234853).
  - Update
    patches.suse/Bluetooth-L2CAP-handle-NULL-sock-pointer-in-l2cap_so.patch
    (git-fixes CVE-2024-58009 bsc#1238760).
  - Update
    patches.suse/Bluetooth-btbcm-Fix-NULL-deref-in-btbcm_get_board_na.patch
    (git-fixes CVE-2024-57988 bsc#1237910).
  - Update
    patches.suse/Bluetooth-btrtl-check-for-NULL-in-btrtl_setup_realte.patch
    (git-fixes CVE-2024-57987 bsc#1237905).
  - Update
    patches.suse/HID-core-Fix-assumption-that-Resolution-Multipliers-.patch
    (git-fixes CVE-2024-57986 bsc#1237907).
  - Update
    patches.suse/HID-hid-thrustmaster-Fix-warning-in-thrustmaster_pro.patch
    (git-fixes CVE-2024-57993 bsc#1237894).
  - Update
    patches.suse/HID-winwing-Add-NULL-check-in-winwing_init_led.patch
    (git-fixes CVE-2024-58021 bsc#1238778).
  - Update
    patches.suse/KEYS-trusted-dcp-fix-improper-sg-use-with-CONFIG_VMA.patch
    (git-fixes CVE-2024-58008 bsc#1238749).
  - Update
    patches.suse/NFSv4.0-Fix-a-use-after-free-problem-in-the-asynchronous-open.patch
    (git-fixes CVE-2024-53173 bsc#1234891 bsc#1234853).
  - Update
    patches.suse/PCI-dwc-ep-Prevent-changing-BAR-size-flags-in-pci_ep.patch
    (git-fixes CVE-2024-58006 bsc#1238772).
  - Update
    patches.suse/block-Prevent-potential-deadlocks-in-zone-write-plug-error-recovery.patch
    (git-fixes CVE-2024-55642 bsc#1235744).
  - Update
    patches.suse/block-avoid-to-reuse-hctx-not-removed-from-cpuhp-callback-list.patch
    (git-fixes CVE-2024-41149 bsc#1235698).
  - Update
    patches.suse/bpf-Mark-raw_tp-arguments-with-PTR_MAYBE_NULL.patch
    (git-fixes CVE-2024-56702 bsc#1235501).
  - Update
    patches.suse/clk-mmp2-call-pm_genpd_init-only-after-genpd.name-is.patch
    (git-fixes CVE-2024-58081 bsc#1239032).
  - Update
    patches.suse/clk-qcom-dispcc-sm6350-Add-missing-parent_map-for-a-.patch
    (git-fixes CVE-2024-58080 bsc#1239027).
  - Update
    patches.suse/clk-qcom-gcc-sm6350-Add-missing-parent_map-for-two-c.patch
    (git-fixes CVE-2024-58076 bsc#1239037).
  - Update
    patches.suse/crypto-tegra-do-not-transfer-req-when-tegra-init-fai.patch
    (git-fixes CVE-2024-58075 bsc#1238976).
  - Update
    patches.suse/drm-amdgpu-Fix-potential-NULL-pointer-dereference-in.patch
    (git-fixes CVE-2024-58052 bsc#1238986).
  - Update
    patches.suse/drm-msm-gem-prevent-integer-overflow-in-msm_ioctl_ge.patch
    (git-fixes CVE-2024-52559 bsc#1238507).
  - Update
    patches.suse/drm-v3d-Stop-active-perfmon-if-it-is-being-destroyed.patch
    (git-fixes CVE-2024-58086 bsc#1239038).
  - Update
    patches.suse/drm-xe-tracing-Fix-a-potential-TP_printk-UAF.patch
    (git-fixes CVE-2024-49570 bsc#1238782).
  - Update
    patches.suse/firmware-qcom-scm-Cleanup-global-__scm-on-probe-fail.patch
    (git-fixes CVE-2024-57985 bsc#1237914).
  - Update
    patches.suse/firmware-qcom-scm-Fix-missing-read-barrier-in-qcom_s-b628510.patch
    (git-fixes CVE-2024-58084 bsc#1239028).
  - Update
    patches.suse/i3c-dw-Fix-use-after-free-in-dw_i3c_master-driver-du.patch
    (git-fixes CVE-2024-57984 bsc#1237909).
  - Update patches.suse/idpf-convert-workqueues-to-unbound.patch
    (jsc#PED-10581 CVE-2024-58057 bsc#1238969).
  - Update
    patches.suse/ipmi-ipmb-Add-check-devm_kasprintf-returned-value.patch
    (git-fixes CVE-2024-58051 bsc#1238963).
  - Update
    patches.suse/media-i2c-ds90ub9x3-Fix-extra-fwnode_handle_put.patch
    (git-fixes CVE-2024-58003 bsc#1238766).
  - Update
    patches.suse/media-imx-jpeg-Fix-potential-error-pointer-dereferen.patch
    (git-fixes CVE-2024-57978 bsc#1238523).
  - Update
    patches.suse/media-intel-ipu6-remove-cpu-latency-qos-request-on-e.patch
    (git-fixes CVE-2024-58004 bsc#1238508).
  - Update
    patches.suse/media-nuvoton-Fix-an-error-check-in-npcm_video_ece_i.patch
    (git-fixes CVE-2024-58082 bsc#1239031).
  - Update
    patches.suse/media-uvcvideo-Fix-crash-during-unbind-if-gpio-unit-.patch
    (git-fixes CVE-2024-58079 bsc#1239029).
  - Update
    patches.suse/media-uvcvideo-Fix-deadlock-during-uvc_probe.patch
    (git-fixes CVE-2024-58059 bsc#1238960).
  - Update
    patches.suse/media-uvcvideo-Fix-double-free-in-error-path.patch
    (git-fixes CVE-2024-57980 bsc#1237911).
  - Update
    patches.suse/media-uvcvideo-Remove-dangling-pointers.patch
    (git-fixes CVE-2024-58002 bsc#1238503).
  - Update
    patches.suse/memory-tegra20-emc-fix-an-OF-node-reference-bug-in-t.patch
    (git-fixes CVE-2024-58034 bsc#1238773).
  - Update
    patches.suse/misc-misc_minor_alloc-to-use-ida-for-all-dynamic-mis.patch
    (git-fixes CVE-2024-58078 bsc#1239034).
  - Update
    patches.suse/powerpc-pseries-iommu-IOMMU-incorrectly-marks-MMIO-r.patch
    (bsc#1218470 ltc#204531 CVE-2024-57999 bsc#1238526).
  - Update patches.suse/pps-Fix-a-use-after-free.patch (git-fixes
    CVE-2024-57979 bsc#1238521).
  - Update
    patches.suse/printk-Fix-signed-integer-overflow-when-defining-LOG_BUF_LEN_MAX.patch
    (bsc#1237950 CVE-2024-58017 bsc#1239112).
  - Update
    patches.suse/rdma-cxgb4-Prevent-potential-integer-overflow-on-32b.patch
    (git-fixes CVE-2024-57973 bsc#1238531).
  - Update
    patches.suse/remoteproc-core-Fix-ida_free-call-while-not-allocate.patch
    (git-fixes CVE-2024-58056 bsc#1238981).
  - Update
    patches.suse/rhashtable-Fix-potential-deadlock-by-moving-schedule.patch
    (git-fixes CVE-2024-58042 bsc#1238769).
  - Update
    patches.suse/rtc-pcf85063-fix-potential-OOB-write-in-PCF85063-NVM.patch
    (git-fixes CVE-2024-58069 bsc#1238978).
  - Update
    patches.suse/rtc-tps6594-Fix-integer-overflow-on-32bit-systems.patch
    (git-fixes CVE-2024-57953 bsc#1238524).
  - Update
    patches.suse/soc-qcom-socinfo-Avoid-out-of-bounds-read-of-serial-.patch
    (git-fixes CVE-2024-58007 bsc#1238511).
  - Update
    patches.suse/staging-media-max96712-fix-kernel-oops-when-removing.patch
    (git-fixes CVE-2024-58054 bsc#1238975).
  - Update
    patches.suse/tpm-Change-to-kvalloc-in-eventlog-acpi.c.patch
    (bsc#1233260 bsc#1233259 bsc#1232421 CVE-2024-58005
    bsc#1237873).
  - Update
    patches.suse/ubi-fastmap-Fix-duplicate-slab-cache-names-while-att.patch
    (git-fixes CVE-2024-53172 bsc#1234898).
  - Update
    patches.suse/usb-gadget-f_tcm-Don-t-free-command-immediately.patch
    (git-fixes CVE-2024-58055 bsc#1238959).
  - Update
    patches.suse/usb-xhci-Fix-NULL-pointer-dereference-on-certain-com.patch
    (git-fixes CVE-2024-57981 bsc#1237912).
  - Update
    patches.suse/wifi-ath12k-fix-read-pointer-after-free-in-ath12k_ma.patch
    (git-fixes CVE-2024-57995 bsc#1237895).
  - Update
    patches.suse/wifi-brcmsmac-add-gain-range-check-to-wlc_phy_iqcal_.patch
    (stable-fixes CVE-2024-58014 bsc#1239109).
  - Update
    patches.suse/wifi-cfg80211-tests-Fix-potential-NULL-dereference-i.patch
    (git-fixes CVE-2024-58064 bsc#1238977).
  - Update
    patches.suse/wifi-iwlwifi-mvm-avoid-NULL-pointer-dereference.patch
    (git-fixes CVE-2024-58062 bsc#1238965).
  - Update
    patches.suse/wifi-mac80211-prohibit-deactivating-all-links.patch
    (git-fixes CVE-2024-58061 bsc#1238973).
  - Update
    patches.suse/wifi-mt76-mt7925-fix-NULL-deref-check-in-mt7925_chan.patch
    (git-fixes CVE-2024-57989 bsc#1237899).
  - Update
    patches.suse/wifi-mt76-mt7925-fix-off-by-one-in-mt7925_load_clc.patch
    (git-fixes CVE-2024-57990 bsc#1237900).
  - Update
    patches.suse/wifi-mwifiex-Fix-memcpy-field-spanning-write-warning.patch
    (git-fixes CVE-2024-56539 bsc#1234963 bsc#1234853).
  - Update
    patches.suse/wifi-rtlwifi-fix-memory-leaks-and-invalid-access-at-.patch
    (git-fixes CVE-2024-58063 bsc#1238984).
  - Update
    patches.suse/wifi-rtlwifi-remove-unused-check_buddy_priv.patch
    (git-fixes CVE-2024-58072 bsc#1238964).
  - Update
    patches.suse/wifi-rtw89-chan-fix-soft-lockup-in-rtw89_entity_reca.patch
    (git-fixes CVE-2024-57991 bsc#1237896).
  - Update
    patches.suse/wifi-wcn36xx-fix-channel-survey-memory-allocation-si.patch
    (git-fixes CVE-2024-57997 bsc#1238529).
  - commit 214e3e7
  - io_uring/waitid: don't abuse io_tw_state (git-fixes).
  - io_uring/net: don't retry connect operation on EPOLLERR
    (git-fixes).
  - commit 4470192
  - io_uring: fix multishots with selected buffers (git-fixes).
  - io_uring/uring_cmd: use cached cmd_op in io_uring_cmd_sock()
    (git-fixes).
  - io_uring/timeout: fix multishot updates (git-fixes).
  - io_uring/kbuf: use pre-committed buffer address for non-pollable
    file (git-fixes).
  - io_uring/net: always initialize kmsg->msg.msg_inq upfront
    (git-fixes).
  - io_uring/rw: fix downgraded mshot read (git-fixes).
  - io_uring/sqpoll: fix sqpoll error handling races (git-fixes).
  - commit 1987e55

++++ kernel-firmware-amdgpu:

  - Update to version 20250311 (git commit b69d4b74c986):
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update sdma 7.0.1 firmware
    * amdgpu: update gc 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update gc 10.3.6 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update picasso firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update gc 10.3.7 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update aldebaran firmware

++++ kernel-firmware-intel:

  - Update to version 20250311 (git commit b69d4b74c986):
    * linux-firmware: add firmware for qat_420xx devices

++++ kernel-firmware-qcom:

  - Update to version 20250311 (git commit b69d4b74c986):
    * qcom: Update gpu firmwares for qcs8300 chipset

++++ kernel-rt:

  - series.conf: Move modules patches to sorted section
  - commit 3d9f4dd
  - scripts/python/git_sort/git_sort.yaml: update modules location
    Update the modules-next location jeyu/modules-next does not appear to have
    been used since 2021.
    See also ced75a2f5da7 ("MAINTAINERS: Add Luis Chamberlain as modules maintainer")
  - commit 7c7198e
  - series.conf: Move patch to sorted section
  - commit 3d9810e
  - ARM: module: Use RCU in all users of __module_text_address()
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/arm64-module-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/bpf-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/bug-Use-RCU-instead-RCU-sched-to-protect-module_bug_list.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/cfi-Use-RCU-while-invoking-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/jump_label-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Allow-__module_address-to-be-called-from-RCU-section.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Begin-to-move-from-RCU-sched-to-RCU.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Extend-the-preempt-disabled-section-in-dereference_symbol_descriptor.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Remove-module_assert_mutex_or_preempt-from-try_add_tainted_module.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-__find_kallsyms_symbol_value.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-__is_module_percpu_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-all-users-of-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-find_kallsyms_symbol.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-find_module_all.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-find_symbol.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update patches.suse/module-Use-RCU-in-module_get_kallsym.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-module_kallsyms_on_each_symbol.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-RCU-in-search_module_extables.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/module-Use-proper-RCU-assignment-in-add_kallsyms.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/static_call-Use-RCU-in-all-users-of-__module_text_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - Update
    patches.suse/x86-Use-RCU-in-all-users-of-__module_address.patch
    (bsc#1234370 (PREEMPT_RT prerequisite backports)).
  - commit bb9ab70
  - series.conf: Move RT-specific patches pending for mainline to top of RT section
  - commit bc2a85a
  - config: Disable CONFIG_CGROUP_FREEZER (jsc#PED-12329)
    We already have (by default):
    [#] CONFIG_MEMCG_V1 is not set
    [#] CONFIG_CPUSETS_V1 is not set
    that disable memory and cpuset v1 controllers respectively.
    Natural extension is disabling freezer v1 controller (as gradually going
    away from v1 controllers).
    This keeps the global freezer functionality (for suspend) and there is
    independent group freezing in cgroup v2.
  - commit 46442b5
  - config: Disable CONFIG_CGROUP_DEVICE (jsc#PED-12328)
    We already have (by default):
    [#] CONFIG_MEMCG_V1 is not set
    [#] CONFIG_CPUSETS_V1 is not set
    that disable memory and cpuset v1 controllers respectively.
    The replacement are BPF device-control programs attached to cgroups.
    openSUSE Tumbleweed switched to (such) v2 setup in 2021-03. Today is
    time for config cleanup.
  - commit f845e63
  - config: Disable CONFIG_CGROUP_CPUACCT (jsc#PED-12327)
    We already have (by default):
    [#] CONFIG_MEMCG_V1 is not set
    [#] CONFIG_CPUSETS_V1 is not set
    that disable memory and cpuset v1 controllers respectively.
    cpuacct is v1-only controller whose functionality was taken over with
    cgroup v2 core. It even adds slight overhead since it doubly-accounts
    CPU time in root cgroup even on v2-only runtimes.
    openSUSE Tumbleweed switched to v2 setup in 2021-03. Today (if not
    earlier) is time for config cleanup.
  - commit fb4110d
  - net: ethernet: ti: am65-cpsw: fix memleak in certain XDP cases
    (CVE-2025-21788 bsc#1238761).
  - net: ravb: Fix missing rtnl lock in suspend/resume path
    (CVE-2025-21801 bsc#1238758).
  - net: hns3: fix oops when unload drivers paralleling
    (CVE-2025-21802 bsc#1238751).
  - commit 3709944
  - pinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fw
    (git-fixes).
  - pinctrl: bcm281xx: Fix incorrect regmap max_registers value
    (git-fixes).
  - commit 53a34e8
  - Bluetooth: MGMT: Fix slab-use-after-free Read in
    mgmt_remove_adv_monitor_sync (bsc#1239095 CVE-2024-58013).
  - commit 828d19c
  - Update
    patches.suse/Bluetooth-btusb-mediatek-Add-locks-for-usb_driver_cl.patch
    (git-fixes CVE-2025-21827 bsc#1238974).
  - Update
    patches.suse/HID-hid-thrustmaster-fix-stack-out-of-bounds-read-in.patch
    (git-fixes CVE-2025-21794 bsc#1238502).
  - Update
    patches.suse/Input-synaptics-fix-crash-when-enabling-pass-through.patch
    (bsc#1219522 CVE-2025-21746 bsc#1238498).
  - Update
    patches.suse/KVM-x86-Load-DR6-with-guest-value-only-before-enteri.patch
    (git-fixes CVE-2025-21839 bsc#1239061).
  - Update
    patches.suse/LoongArch-Fix-warnings-during-S3-suspend.patch
    (git-fixes CVE-2025-21803 bsc#1238744).
  - Update
    patches.suse/NFC-nci-Add-bounds-checking-in-nci_hci_create_pipe.patch
    (git-fixes CVE-2025-21735 bsc#1238497).
  - Update
    patches.suse/PCI-Avoid-putting-some-root-ports-into-D3-on-TUXEDO-.patch
    (git-fixes CVE-2025-21831 bsc#1239039).
  - Update
    patches.suse/PCI-rcar-ep-Fix-incorrect-variable-used-when-calling.patch
    (git-fixes CVE-2025-21804 bsc#1238736).
  - Update
    patches.suse/RDMA-mlx5-Fix-a-race-for-an-ODP-MR-which-leads-to-CQ.patch
    (git-fixes CVE-2025-21732 bsc#1237877).
  - Update
    patches.suse/RDMA-mlx5-Fix-implicit-ODP-use-after-free.patch
    (git-fixes CVE-2025-21714 bsc#1237890).
  - Update patches.suse/RDMA-rtrs-Add-missing-deinit-call.patch
    (git-fixes CVE-2025-21805 bsc#1238741).
  - Update
    patches.suse/RDMA-rxe-Fix-the-warning-__rxe_cleanup-0x12c-0x170-r.patch
    (git-fixes CVE-2025-21829 bsc#1239030).
  - Update
    patches.suse/Revert-drm-amd-display-Use-HW-lock-mgr-for-PSR1.patch
    (stable-fixes CVE-2025-21819 bsc#1238994).
  - Update
    patches.suse/amdkfd-properly-free-gang_ctx_bo-when-failed-to-init.patch
    (git-fixes CVE-2025-21842 bsc#1239063).
  - Update
    patches.suse/arm64-cacheinfo-Avoid-out-of-bounds-write-to-cacheinfo-array.patch
    (git-fixes CVE-2025-21785 bsc#1238747).
  - Update
    patches.suse/ax25-Fix-refcount-leak-caused-by-setting-SO_BINDTODE.patch
    (git-fixes CVE-2025-21792 bsc#1238745).
  - Update patches.suse/ax25-rcu-protect-dev-ax25_ptr.patch
    (git-fixes CVE-2025-21812 bsc#1238471).
  - Update
    patches.suse/batman-adv-fix-panic-during-interface-removal.patch
    (git-fixes CVE-2025-21781 bsc#1238735).
  - Update
    patches.suse/blk-cgroup-Fix-class-block_class-s-subsystem-refcount-leakage.patch
    (bsc#1237558 CVE-2025-21745 bsc#1238785).
  - Update
    patches.suse/block-bfq-fix-waker_bfqq-UAF-after-bfq_split_bfqq.patch
    (git-fixes CVE-2025-21631 bsc#1236099).
  - Update
    patches.suse/block-don-t-revert-iter-for-EIOCBQUEUED.patch
    (git-fixes CVE-2025-21832 bsc#1239105).
  - Update
    patches.suse/can-ctucanfd-handle-skb-allocation-failure.patch
    (git-fixes CVE-2025-21775 bsc#1238501).
  - Update
    patches.suse/can-etas_es58x-fix-potential-NULL-pointer-dereferenc.patch
    (git-fixes CVE-2025-21773 bsc#1238762).
  - Update
    patches.suse/can-rockchip-rkcanfd_handle_rx_fifo_overflow_int-bai.patch
    (git-fixes CVE-2025-21774 bsc#1238770).
  - Update
    patches.suse/driver-core-class-Fix-wild-pointer-dereferences-in-A.patch
    (git-fixes CVE-2025-21810 bsc#1238757).
  - Update
    patches.suse/drm-amdgpu-avoid-buffer-overflow-attach-in-smu_sys_s.patch
    (stable-fixes CVE-2025-21780 bsc#1239115).
  - Update
    patches.suse/drm-amdgpu-bail-out-when-failed-to-load-fw-in-psp_in.patch
    (git-fixes CVE-2025-21784 bsc#1238510).
  - Update
    patches.suse/firewire-test-Fix-potential-null-dereference-in-fire.patch
    (git-fixes CVE-2025-21798 bsc#1238776).
  - Update
    patches.suse/gpiolib-Fix-crash-on-error-in-gpiochip_get_ngpios.patch
    (git-fixes CVE-2025-21783 bsc#1238530).
  - Update
    patches.suse/gpu-host1x-Fix-a-use-of-uninitialized-mutex.patch
    (git-fixes CVE-2025-21824 bsc#1238478).
  - Update
    patches.suse/iommu-Fix-potential-memory-leak-in-iopf_queue_remove.patch
    (git-fixes CVE-2025-21770 bsc#1238495).
  - Update patches.suse/landlock-Handle-weird-files.patch (git-fixes
    CVE-2025-21830 bsc#1239033).
  - Update
    patches.suse/md-md-bitmap-Synchronize-bitmap_get_stats-with-bitmap-lifetime.patch
    (git-fixes CVE-2025-21712 bsc#1237886).
  - Update patches.suse/misc-fastrpc-Fix-copy-buffer-page-size.patch
    (git-fixes CVE-2025-21734 bsc#1238734).
  - Update
    patches.suse/mm-compaction-fix-UBSAN-shift-out-of-bounds-warning.patch
    (git fixes (mm/compaction) CVE-2025-21815 bsc#1238474).
  - Update
    patches.suse/msft-hv-3160-KVM-x86-Reject-Hyper-V-s-SEND_IPI-hypercalls-if-loca.patch
    (git-fixes CVE-2025-21779 bsc#1238768).
  - Update
    patches.suse/nbd-don-t-allow-reconnect-after-disconnect.patch
    (git-fixes CVE-2025-21731 bsc#1237881).
  - Update
    patches.suse/neighbour-use-RCU-protection-in-__neigh_notify.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21763 bsc#1237897).
  - Update
    patches.suse/net-avoid-race-between-device-unregistration-and-eth.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2025-21701 bsc#1237164).
  - Update
    patches.suse/net-mlx5-HWS-change-error-flow-on-matcher-disconnect.patch
    (jsc#PED-11331 CVE-2025-21751 bsc#1238907).
  - Update
    patches.suse/net-mlx5-HWS-fix-definer-s-HWS_SET32-macro-for-negat.patch
    (jsc#PED-11331 CVE-2025-21800 bsc#1238743).
  - Update
    patches.suse/net-mlx5e-add-missing-cpu_to_node-to-kvzalloc_node-i.patch
    (jsc#PED-11331 CVE-2025-21717 bsc#1238866).
  - Update
    patches.suse/net-rose-fix-timer-races-against-user-threads.patch
    (git-fixes CVE-2025-21718 bsc#1239073).
  - Update
    patches.suse/net-rose-prevent-integer-overflows-in-rose_setsockop.patch
    (git-fixes CVE-2025-21711 bsc#1239114).
  - Update
    patches.suse/net-usb-rtl8150-enable-basic-endpoint-checking.patch
    (git-fixes CVE-2025-21708 bsc#1239087).
  - Update
    patches.suse/netdev-prevent-accessing-NAPI-instances-from-another.patch
    (jsc#PED-12085 CVE-2025-21659 bsc#1236206).
  - Update
    patches.suse/nfsd-clear-acl_access-acl_default-after-releasing-them.patch
    (git-fixes CVE-2025-21796 bsc#1238716).
  - Update patches.suse/padata-avoid-UAF-for-reorder_work.patch
    (git-fixes CVE-2025-21726 bsc#1238865).
  - Update patches.suse/padata-fix-UAF-in-padata_reorder.patch
    (git-fixes CVE-2025-21727 bsc#1237876).
  - Update
    patches.suse/partitions-mac-fix-handling-of-bogus-partition-table.patch
    (git-fixes CVE-2025-21772 bsc#1238911).
  - Update
    patches.suse/powerpc-pseries-iommu-Don-t-unset-window-if-it-was-n.patch
    (jsc#PED-10539 git-fixes CVE-2025-21713 bsc#1237887).
  - Update
    patches.suse/sched_ext-Fix-incorrect-autogroup-migration-detection.patch
    (git fixes (sched) CVE-2025-21771 bsc#1238752).
  - Update
    patches.suse/scsi-mpi3mr-Fix-possible-crash-when-setting-up-bsg-fails.patch
    (git-fixes CVE-2025-21723 bsc#1238864).
  - Update
    patches.suse/seccomp-passthrough-uretprobe-systemcall-without-fil.patch
    (git-fixes CVE-2025-21834 bsc#1239026).
  - Update patches.suse/spi-sn-f-ospi-Fix-division-by-zero.patch
    (git-fixes CVE-2025-21793 bsc#1238500).
  - Update patches.suse/tty-xilinx_uartps-split-sysrq-handling.patch
    (git-fixes CVE-2025-21820 bsc#1238479).
  - Update
    patches.suse/usb-cdc-acm-Check-control-transfer-buffer-size-befor.patch
    (git-fixes CVE-2025-21704 bsc#1237571).
  - Update
    patches.suse/usb-gadget-core-flush-gadget-workqueue-after-device-.patch
    (git-fixes CVE-2025-21838 bsc#1239065).
  - Update
    patches.suse/usb-gadget-f_midi-fix-MIDI-Streaming-descriptor-leng.patch
    (git-fixes CVE-2025-21835 bsc#1239068).
  - Update patches.suse/usbnet-ipheth-fix-DPE-OoB-read.patch
    (git-fixes CVE-2025-21741 bsc#1238767).
  - Update
    patches.suse/usbnet-ipheth-fix-possible-overflow-in-DPE-length-ch.patch
    (git-fixes CVE-2025-21743 bsc#1238781).
  - Update
    patches.suse/usbnet-ipheth-use-static-NDP16-location-in-URB.patch
    (git-fixes CVE-2025-21742 bsc#1238771).
  - Update
    patches.suse/vsock-Keep-the-binding-until-socket-destruction.patch
    (git-fixes CVE-2025-21756 bsc#1238876).
  - Update
    patches.suse/vsock-Orphan-socket-after-transport-release.patch
    (jsc#PED-11028 CVE-2025-21755 bsc#1237882).
  - Update
    patches.suse/wifi-brcmfmac-Check-the-return-value-of-of_property_.patch
    (stable-fixes CVE-2025-21750 bsc#1238905).
  - Update
    patches.suse/wifi-mac80211-don-t-flush-non-uploaded-STAs.patch
    (git-fixes CVE-2025-21828 bsc#1238958).
  - Update
    patches.suse/wifi-rtw89-avoid-to-init-mgnt_entry-list-twice-when-.patch
    (git-fixes CVE-2025-21730 bsc#1237878).
  - Update
    patches.suse/wifi-rtw89-fix-race-between-cancel_hw_scan-and-hw_sc.patch
    (git-fixes CVE-2025-21729 bsc#1237874).
  - Update
    patches.suse/workqueue-Put-the-pwq-after-detaching-the-rescuer-from-the-pool.patch
    (bsc#1237866 CVE-2025-21786 bsc#1238505).
  - Update patches.suse/zram-fix-potential-UAF-of-zram-table.patch
    (git-fixes CVE-2025-21671 bsc#1236692).
  - commit af45f0e
  - Update
    patches.suse/ALSA-6fire-Release-resources-at-card-release.patch
    (git-fixes CVE-2024-53239 bsc#1235054 bsc#1234853).
  - Update
    patches.suse/ASoC-soc-pcm-don-t-use-soc_pcm_ret-on-.prepare-callb.patch
    (stable-fixes CVE-2024-58077 bsc#1239090).
  - Update
    patches.suse/Bluetooth-L2CAP-do-not-leave-dangling-sk-pointer-on-.patch
    (stable-fixes CVE-2024-56605 bsc#1235061 bsc#1234853).
  - Update
    patches.suse/Bluetooth-L2CAP-handle-NULL-sock-pointer-in-l2cap_so.patch
    (git-fixes CVE-2024-58009 bsc#1238760).
  - Update
    patches.suse/Bluetooth-btbcm-Fix-NULL-deref-in-btbcm_get_board_na.patch
    (git-fixes CVE-2024-57988 bsc#1237910).
  - Update
    patches.suse/Bluetooth-btrtl-check-for-NULL-in-btrtl_setup_realte.patch
    (git-fixes CVE-2024-57987 bsc#1237905).
  - Update
    patches.suse/HID-core-Fix-assumption-that-Resolution-Multipliers-.patch
    (git-fixes CVE-2024-57986 bsc#1237907).
  - Update
    patches.suse/HID-hid-thrustmaster-Fix-warning-in-thrustmaster_pro.patch
    (git-fixes CVE-2024-57993 bsc#1237894).
  - Update
    patches.suse/HID-winwing-Add-NULL-check-in-winwing_init_led.patch
    (git-fixes CVE-2024-58021 bsc#1238778).
  - Update
    patches.suse/KEYS-trusted-dcp-fix-improper-sg-use-with-CONFIG_VMA.patch
    (git-fixes CVE-2024-58008 bsc#1238749).
  - Update
    patches.suse/NFSv4.0-Fix-a-use-after-free-problem-in-the-asynchronous-open.patch
    (git-fixes CVE-2024-53173 bsc#1234891 bsc#1234853).
  - Update
    patches.suse/PCI-dwc-ep-Prevent-changing-BAR-size-flags-in-pci_ep.patch
    (git-fixes CVE-2024-58006 bsc#1238772).
  - Update
    patches.suse/block-Prevent-potential-deadlocks-in-zone-write-plug-error-recovery.patch
    (git-fixes CVE-2024-55642 bsc#1235744).
  - Update
    patches.suse/block-avoid-to-reuse-hctx-not-removed-from-cpuhp-callback-list.patch
    (git-fixes CVE-2024-41149 bsc#1235698).
  - Update
    patches.suse/bpf-Mark-raw_tp-arguments-with-PTR_MAYBE_NULL.patch
    (git-fixes CVE-2024-56702 bsc#1235501).
  - Update
    patches.suse/clk-mmp2-call-pm_genpd_init-only-after-genpd.name-is.patch
    (git-fixes CVE-2024-58081 bsc#1239032).
  - Update
    patches.suse/clk-qcom-dispcc-sm6350-Add-missing-parent_map-for-a-.patch
    (git-fixes CVE-2024-58080 bsc#1239027).
  - Update
    patches.suse/clk-qcom-gcc-sm6350-Add-missing-parent_map-for-two-c.patch
    (git-fixes CVE-2024-58076 bsc#1239037).
  - Update
    patches.suse/crypto-tegra-do-not-transfer-req-when-tegra-init-fai.patch
    (git-fixes CVE-2024-58075 bsc#1238976).
  - Update
    patches.suse/drm-amdgpu-Fix-potential-NULL-pointer-dereference-in.patch
    (git-fixes CVE-2024-58052 bsc#1238986).
  - Update
    patches.suse/drm-msm-gem-prevent-integer-overflow-in-msm_ioctl_ge.patch
    (git-fixes CVE-2024-52559 bsc#1238507).
  - Update
    patches.suse/drm-v3d-Stop-active-perfmon-if-it-is-being-destroyed.patch
    (git-fixes CVE-2024-58086 bsc#1239038).
  - Update
    patches.suse/drm-xe-tracing-Fix-a-potential-TP_printk-UAF.patch
    (git-fixes CVE-2024-49570 bsc#1238782).
  - Update
    patches.suse/firmware-qcom-scm-Cleanup-global-__scm-on-probe-fail.patch
    (git-fixes CVE-2024-57985 bsc#1237914).
  - Update
    patches.suse/firmware-qcom-scm-Fix-missing-read-barrier-in-qcom_s-b628510.patch
    (git-fixes CVE-2024-58084 bsc#1239028).
  - Update
    patches.suse/i3c-dw-Fix-use-after-free-in-dw_i3c_master-driver-du.patch
    (git-fixes CVE-2024-57984 bsc#1237909).
  - Update patches.suse/idpf-convert-workqueues-to-unbound.patch
    (jsc#PED-10581 CVE-2024-58057 bsc#1238969).
  - Update
    patches.suse/ipmi-ipmb-Add-check-devm_kasprintf-returned-value.patch
    (git-fixes CVE-2024-58051 bsc#1238963).
  - Update
    patches.suse/media-i2c-ds90ub9x3-Fix-extra-fwnode_handle_put.patch
    (git-fixes CVE-2024-58003 bsc#1238766).
  - Update
    patches.suse/media-imx-jpeg-Fix-potential-error-pointer-dereferen.patch
    (git-fixes CVE-2024-57978 bsc#1238523).
  - Update
    patches.suse/media-intel-ipu6-remove-cpu-latency-qos-request-on-e.patch
    (git-fixes CVE-2024-58004 bsc#1238508).
  - Update
    patches.suse/media-nuvoton-Fix-an-error-check-in-npcm_video_ece_i.patch
    (git-fixes CVE-2024-58082 bsc#1239031).
  - Update
    patches.suse/media-uvcvideo-Fix-crash-during-unbind-if-gpio-unit-.patch
    (git-fixes CVE-2024-58079 bsc#1239029).
  - Update
    patches.suse/media-uvcvideo-Fix-deadlock-during-uvc_probe.patch
    (git-fixes CVE-2024-58059 bsc#1238960).
  - Update
    patches.suse/media-uvcvideo-Fix-double-free-in-error-path.patch
    (git-fixes CVE-2024-57980 bsc#1237911).
  - Update
    patches.suse/media-uvcvideo-Remove-dangling-pointers.patch
    (git-fixes CVE-2024-58002 bsc#1238503).
  - Update
    patches.suse/memory-tegra20-emc-fix-an-OF-node-reference-bug-in-t.patch
    (git-fixes CVE-2024-58034 bsc#1238773).
  - Update
    patches.suse/misc-misc_minor_alloc-to-use-ida-for-all-dynamic-mis.patch
    (git-fixes CVE-2024-58078 bsc#1239034).
  - Update
    patches.suse/powerpc-pseries-iommu-IOMMU-incorrectly-marks-MMIO-r.patch
    (bsc#1218470 ltc#204531 CVE-2024-57999 bsc#1238526).
  - Update patches.suse/pps-Fix-a-use-after-free.patch (git-fixes
    CVE-2024-57979 bsc#1238521).
  - Update
    patches.suse/printk-Fix-signed-integer-overflow-when-defining-LOG_BUF_LEN_MAX.patch
    (bsc#1237950 CVE-2024-58017 bsc#1239112).
  - Update
    patches.suse/rdma-cxgb4-Prevent-potential-integer-overflow-on-32b.patch
    (git-fixes CVE-2024-57973 bsc#1238531).
  - Update
    patches.suse/remoteproc-core-Fix-ida_free-call-while-not-allocate.patch
    (git-fixes CVE-2024-58056 bsc#1238981).
  - Update
    patches.suse/rhashtable-Fix-potential-deadlock-by-moving-schedule.patch
    (git-fixes CVE-2024-58042 bsc#1238769).
  - Update
    patches.suse/rtc-pcf85063-fix-potential-OOB-write-in-PCF85063-NVM.patch
    (git-fixes CVE-2024-58069 bsc#1238978).
  - Update
    patches.suse/rtc-tps6594-Fix-integer-overflow-on-32bit-systems.patch
    (git-fixes CVE-2024-57953 bsc#1238524).
  - Update
    patches.suse/soc-qcom-socinfo-Avoid-out-of-bounds-read-of-serial-.patch
    (git-fixes CVE-2024-58007 bsc#1238511).
  - Update
    patches.suse/staging-media-max96712-fix-kernel-oops-when-removing.patch
    (git-fixes CVE-2024-58054 bsc#1238975).
  - Update
    patches.suse/tpm-Change-to-kvalloc-in-eventlog-acpi.c.patch
    (bsc#1233260 bsc#1233259 bsc#1232421 CVE-2024-58005
    bsc#1237873).
  - Update
    patches.suse/ubi-fastmap-Fix-duplicate-slab-cache-names-while-att.patch
    (git-fixes CVE-2024-53172 bsc#1234898).
  - Update
    patches.suse/usb-gadget-f_tcm-Don-t-free-command-immediately.patch
    (git-fixes CVE-2024-58055 bsc#1238959).
  - Update
    patches.suse/usb-xhci-Fix-NULL-pointer-dereference-on-certain-com.patch
    (git-fixes CVE-2024-57981 bsc#1237912).
  - Update
    patches.suse/wifi-ath12k-fix-read-pointer-after-free-in-ath12k_ma.patch
    (git-fixes CVE-2024-57995 bsc#1237895).
  - Update
    patches.suse/wifi-brcmsmac-add-gain-range-check-to-wlc_phy_iqcal_.patch
    (stable-fixes CVE-2024-58014 bsc#1239109).
  - Update
    patches.suse/wifi-cfg80211-tests-Fix-potential-NULL-dereference-i.patch
    (git-fixes CVE-2024-58064 bsc#1238977).
  - Update
    patches.suse/wifi-iwlwifi-mvm-avoid-NULL-pointer-dereference.patch
    (git-fixes CVE-2024-58062 bsc#1238965).
  - Update
    patches.suse/wifi-mac80211-prohibit-deactivating-all-links.patch
    (git-fixes CVE-2024-58061 bsc#1238973).
  - Update
    patches.suse/wifi-mt76-mt7925-fix-NULL-deref-check-in-mt7925_chan.patch
    (git-fixes CVE-2024-57989 bsc#1237899).
  - Update
    patches.suse/wifi-mt76-mt7925-fix-off-by-one-in-mt7925_load_clc.patch
    (git-fixes CVE-2024-57990 bsc#1237900).
  - Update
    patches.suse/wifi-mwifiex-Fix-memcpy-field-spanning-write-warning.patch
    (git-fixes CVE-2024-56539 bsc#1234963 bsc#1234853).
  - Update
    patches.suse/wifi-rtlwifi-fix-memory-leaks-and-invalid-access-at-.patch
    (git-fixes CVE-2024-58063 bsc#1238984).
  - Update
    patches.suse/wifi-rtlwifi-remove-unused-check_buddy_priv.patch
    (git-fixes CVE-2024-58072 bsc#1238964).
  - Update
    patches.suse/wifi-rtw89-chan-fix-soft-lockup-in-rtw89_entity_reca.patch
    (git-fixes CVE-2024-57991 bsc#1237896).
  - Update
    patches.suse/wifi-wcn36xx-fix-channel-survey-memory-allocation-si.patch
    (git-fixes CVE-2024-57997 bsc#1238529).
  - commit 214e3e7
  - io_uring/waitid: don't abuse io_tw_state (git-fixes).
  - io_uring/net: don't retry connect operation on EPOLLERR
    (git-fixes).
  - commit 4470192
  - io_uring: fix multishots with selected buffers (git-fixes).
  - io_uring/uring_cmd: use cached cmd_op in io_uring_cmd_sock()
    (git-fixes).
  - io_uring/timeout: fix multishot updates (git-fixes).
  - io_uring/kbuf: use pre-committed buffer address for non-pollable
    file (git-fixes).
  - io_uring/net: always initialize kmsg->msg.msg_inq upfront
    (git-fixes).
  - io_uring/rw: fix downgraded mshot read (git-fixes).
  - io_uring/sqpoll: fix sqpoll error handling races (git-fixes).
  - commit 1987e55

++++ kmod:

  - tests: drop ppc64 workaround, print failed test results if any

++++ spirv-tools:

  - Update to release 2025.1~rc1
    * Added OpImageSampleFootprintNV to IsAllowedSampledImageOperand
    * spirv-val: Validate zero product workgroup size
    * Added EXT_mesh_shader validation support
    * Added support for SPV_INTEL_subgroup_matrix_multiply_accumulate
    * Added SPV_AMDX_shader_enqueue version 2 support
    * Now validates SPV_NV_cooperative_vector
    * Added validation for SPV_NV_cluster_acceleration_structure,
    SPV_NV_linear_swept_spheres

++++ libguestfs:

  - Update to version 1.55.7 (jsc#PED-8910)
    * libguestfs: Rust binding build error and warning fixes
    * support TencentOS
    * lib: Print kernel utsname in debug output
    * daemon: Fix loongarch64 detection on RHEL 9

++++ samba:

  - Update to 4.22.0
    * SMB3 Directory Leases are supported. By default, SMB3 Directory
    Leases are enabled on non-clustered Samba and disabled on
    clustered Samba, based on the "clustering" option.
    * Netlogon Ping over LDAP and LDAPS
    * Experimental Himmelblaud Authentication in Samba
    * The "nmbd proxy logon" feature was removed.
    * fruit:posix_rename option of the vfs_fruit VFS module that
    could be used to enable POSIX directory rename behaviour for
    OS X clients has been removed as it could result in severe
    problems for Windows clients.

++++ pango:

  - Update to version 1.56.2:
    + Annotation fixes
    + fontconfig:
  - Set optical size for fonts with an opsz axis
  - Make panog_font_map_reload_font scale linearly
    + win32: Improve the pango_font_map_reload_font implementation

++++ systemd:

  - Import commit f133e5974e69708d7491d4823780690c913f7bda (merge of v257.4)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/e03ffd74c4a30c1c75e05874ce18d31e503437b7...f133e5974e69708d7491d4823780690c913f7bda

++++ tdb:

  - Update to 1.4.13
    * Add LGPLv3 LICENSE file

++++ openSUSE-repos-LeapMicro:

  - Update to version 20250312.dd33dd1:
    * Add openh264 repo for Leap 16.0 (#76)

++++ python-gobject:

  - Update to version 3.52.2:
    + Revert to legacy license definition in pyproject.toml.
  - Drop pygobject-license.patch: variant of this has been merged
    upstream.

++++ system-users:

  - system-group-hardware: add group clock for systemd 258
    (udev: set clock group for PTP and RTC devices)

++++ virt-manager:

  - Upstream bug fix (bsc#1027942)
    010-virtManager-domain-fix-indentation.patch
  - Upstream features from Lin Ma and others (jsc#PED-8910)
    021-cli-Add-memdev-target.dynamicMemslots-support-for-virtio-mem.patch
    022-cli-add-target.memReserve-for-pci-bridge-and-pcie-root-port-controllers.patch
    023-cli-Add-disk-driver.queue_size-support.patch
    024-cli-Add-poll-settings-for-iothread.patch
    025-test_cli-Fix-a-pycodestyle-E261-issue.patch
    026-gitignore-Ignore-coverage.xml.patch
    027-cli-Add-tpm-backend.profile.source-removeDisabled-support.patch
    028-cli-Add-nvram.templateFormat-to-indicate-template-format.patch
    029-cli-Add-features-hyperv.xmm_input.state-on-off.patch
    030-cli-Add-features-hyperv.emsr_bitmap.state-on-off.patch
    031-cli-Add-features-hyperv.tlbflush.direct.state-on-off.patch
    032-cli-Add-features-hyperv.tlbflush.extended.state-on-off.patch
    033-createvm-prioritize-riscv64.patch
    034-tests-uitests-handle-linux2020-going-EOL.patch

++++ yast2:

  - Checking if a TPM2 device is available (has_tpm2). (jsc#PED-10703)
  - 5.0.13

------------------------------------------------------------------
------------------  2025-3-11  -  Mar 11 2025  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Add 2069.patch: Fix build against girepository-2.0 (pygobject
    3.52).

++++ crypto-policies:

  - Enable SHA1 sigver in the DEFAULT policy.
    * Add crypto-policies-enable-SHA1-sigver-in-DEFAULT.patch

++++ fde-tools:

  - Add fde-tools-bsc1238593-firstboot-more-bootloader-functions.patch
    to define non-expanded functions for the firstboot script
    (bsc#1238593)

++++ fwupd:

  - Add explicit pkgconfig(pango) BuildRequires: used to be pulled in
    by python-gobject, but that's no longer the case with 3.52.
  - Add 8583.patch: Fix build againts pygobject 3.52.

++++ grub2:

  - Update patches for Power guest secure boot with key management (jsc#PED-3520)
    (jsc#PED-9892)
    * 0001-ieee1275-adding-failure-check-condition-on-ibm-secur.patch
    * 0002-ieee1275-Platform-Keystore-PKS-Support.patch
    * 0003-ieee1275-Read-the-DB-and-DBX-secure-boot-variables.patch
    * 0004-appendedsig-The-creation-of-trusted-and-distrusted-l.patch
    * 0005-appendedsig-While-verifying-the-kernel-use-trusted-a.patch
    * 0006-powerpc_ieee1275-set-use_static_keys-flag.patch
    * 0007-appendedsig-Reads-the-default-DB-keys-from-ELF-Note.patch
    * 0008-appendedsig-The-grub-command-s-trusted-and-distruste.patch
    * 0009-appendedsig-documentation.patch
  - Remove patches
    * 0001-ieee1275-Platform-Keystore-PKS-Support.patch
    * 0002-ieee1275-Read-the-DB-and-DBX-secure-boot-variables.patch
    * 0003-appendedsig-The-creation-of-trusted-and-distrusted-l.patch
    * 0004-appendedsig-While-verifying-the-kernel-use-trusted-a.patch
    * 0005-appendedsig-The-grub-command-s-trusted-and-distruste.patch
    * 0006-appendedsig-documentation.patch

++++ kernel-default:

  - r8169: don't apply UDP padding quirk on RTL8126A (stable-fixes).
  - commit 68384e2
  - drm/xe: Fix and re-enable xe_print_blob_ascii85() (git-fixes).
  - commit 3db422a
  - sched/membarrier: Fix redundant load of membarrier_state
    (bsc#1232743).
  - commit bf44b2b
  - bpf: Reject struct_ops registration that uses module ptr and
    the module btf_id is missing (git-fixes).
  - commit 3b9c73b
  - selftests/bpf: Add test case for the freeing of bpf_timer
    (bsc#1238971 CVE-2025-21825).
  - bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
    (bsc#1238971 CVE-2025-21825).
  - bpf: Free element after unlock in
    __htab_map_lookup_and_delete_elem() (bsc#1238971
    CVE-2025-21825).
  - bpf: Bail out early in __htab_map_lookup_and_delete_elem()
    (bsc#1238971 CVE-2025-21825).
  - bpf: Free special fields after unlock in
    htab_lru_map_delete_node() (bsc#1238971 CVE-2025-21825).
  - commit 1cd4c2e

++++ kernel-firmware-amdgpu:

  - Update to version 20250310 (git commit 11c4e60f9573):
    * amdgpu: DMCUB updates for various ASICs

++++ kernel-firmware-bluetooth:

  - Update to version 20250310 (git commit 11c4e60f9573):
    * QCA: Add Bluetooth firmwares for QCA2066 with USB transport
    * QCA: Add two bluetooth firmware nvm files for QCA2066
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00653
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00653
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel BlazarI core

++++ kernel-firmware-i915:

  - Update to version 20250310 (git commit 11c4e60f9573):
    * i915: Update Xe3LPD DMC to v2.20

++++ kernel-firmware-mediatek:

  - Update to version 20250310 (git commit 11c4e60f9573):
    * linux-firmware: update firmware for MT7925 WiFi device
    * mediatek MT7925: update bluetooth firmware to 20250305133215
    * mediatek MT7920: update bluetooth firmware to 20250210151502

++++ kernel-rt:

  - r8169: don't apply UDP padding quirk on RTL8126A (stable-fixes).
  - commit 68384e2
  - drm/xe: Fix and re-enable xe_print_blob_ascii85() (git-fixes).
  - commit 3db422a
  - sched/membarrier: Fix redundant load of membarrier_state
    (bsc#1232743).
  - commit bf44b2b
  - bpf: Reject struct_ops registration that uses module ptr and
    the module btf_id is missing (git-fixes).
  - commit 3b9c73b
  - selftests/bpf: Add test case for the freeing of bpf_timer
    (bsc#1238971 CVE-2025-21825).
  - bpf: Cancel the running bpf_timer through kworker for PREEMPT_RT
    (bsc#1238971 CVE-2025-21825).
  - bpf: Free element after unlock in
    __htab_map_lookup_and_delete_elem() (bsc#1238971
    CVE-2025-21825).
  - bpf: Bail out early in __htab_map_lookup_and_delete_elem()
    (bsc#1238971 CVE-2025-21825).
  - bpf: Free special fields after unlock in
    htab_lru_map_delete_node() (bsc#1238971 CVE-2025-21825).
  - commit 1cd4c2e

++++ libarchive:

  - Fix CVE-2025-1632, null pointer dereference in bsdunzip.c
    (CVE-2025-1632, bsc#1237606)
    * CVE-2025-1632.patch
  - Fix CVE-2025-25724, Buffer Overflow vulnerability in libarchive
    (CVE-2025-25724, bsc#1238610)
    * CVE-2025-25724.patch

++++ ncurses:

  - Move manual pages of examples from section 6 to subsection 6n

++++ sqlite3:

  - Mark build recipe as POSIX-sh-incompatible
  - Run mkdir/rm with verbose mode for the build log

++++ tevent:

  - Update to version 0.16.2
    * Documentation fixes
    * Add LGPLv3 LICENSE file

------------------------------------------------------------------
------------------  2025-3-10  -  Mar 10 2025  -------------------
------------------------------------------------------------------

++++ bash:

  - Skip PGO with %want_reproducible_builds (boo#1040589)

++++ busybox:

  - add busybox-1.37.0-make-ping-work-without-root-privileges.patch
    (bsc#1239176)

++++ cockpit:

  - Update to 334.1
  - Various bug fixes and improvements
  - Translation updates
  - npm modules updated, since new version

++++ cockpit-machines:

  - Update to 328
    * Translation updates
  - Remove qemu-spice from SLFO_16 (bsc#1238723)

++++ cockpit-podman:

  - Update to version 102
    * Translation updates
    * Bug fixes

++++ dpdk:

  - Update to version 24.11.1
    * Contains DPDK 24.11 plus the fix for CVE-2024-11614,
    remove patch dpdk-CVE-2024-11614.patch
  - Move docs from %{_docdir}/dpdk/dpdk to %{docdir}/dpdk

++++ kernel-default:

  - Input: atkbd - map F23 key to support default copilot shortcut
    (git-fixes).
  - commit bfe2bb7
  - Input: xpad - add unofficial Xbox 360 wireless receiver clone
    (git-fixes).
  - Input: xpad - add support for wooting two he (arm) (git-fixes).
  - Input: xpad - improve name of 8BitDo controller 2dc8:3106
    (git-fixes).
  - Input: xpad - add QH Electronics VID/PID (git-fixes).
  - Input: xpad - add support for Nacon Evol-X Xbox One Controller
    (git-fixes).
  - commit 4710207
  - Input: xpad - add support for Nacon Pro Compact (git-fixes).
  - commit 3a2bb67
  - KVM: arm64: Initialize SCTLR_EL1 in __kvm_hyp_init_cpu() (git-fixes)
  - commit 2805274
  - KVM: arm64: Initialize HCR_EL2.E2H early (git-fixes)
  - commit 0ff07a9
  - USB: hub: Ignore non-compliant devices with too many configs
    or interfaces (bsc#1238909 CVE-2025-21776).
  - commit 1601393
  - powerpc/pseries/iommu: memory notifier incorrectly adds TCEs
    for pmemory (bsc#1239167 ltc#211055).
  - commit 5ee1b4c
  - s390/traps: Fix test_monitor_call() inline assembly (git-fixes
    bsc#1239160).
  - commit 1a519e2
  - platform/x86: int3472: Check for adev == NULL (CVE-2024-58011
    bsc#1239080).
  - commit 58ea3d9
  - net_sched: sch_sfq: don't allow 1 packet limit (CVE-2024-57996
    bsc#1239076).
  - commit 6b3567e
  - ASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during
    params (CVE-2024-58012 bsc#1239104).
  - commit 642aedc
  - wifi: brcmfmac: fix NULL pointer dereference in
    brcmf_txfinalize() (CVE-2025-21744 bsc#1238903).
  - commit 062e9bf
  - usb: gadget: Check bmAttributes only if configuration is valid
    (git-fixes).
  - usb: gadget: Fix setting self-powered state on suspend
    (git-fixes).
  - commit fb64cab
  - usb: typec: ucsi: Fix NULL pointer access (git-fixes).
  - usb: xhci: Fix host controllers "dying" after suspend and resume
    (git-fixes).
  - usb: dwc3: Set SUSPENDENABLE soon after phy init (git-fixes).
  - usb: hub: lack of clearing xHC resources (git-fixes).
  - usb: renesas_usbhs: Flush the notify_hotplug_work (git-fixes).
  - usb: renesas_usbhs: Use devm_usb_get_phy() (git-fixes).
  - usb: renesas_usbhs: Call clk_put() (git-fixes).
  - usb: dwc3: gadget: Prevent irq storm when TH re-executes
    (git-fixes).
  - xhci: Restrict USB4 tunnel detection for USB3 devices to Intel
    hosts (git-fixes).
  - usb: typec: ucsi: increase timeout for PPM reset operations
    (git-fixes).
  - acpi: typec: ucsi: Introduce a ->poll_cci method (git-fixes).
  - usb: typec: tcpci_rt1711h: Unmask alert interrupts to fix
    functionality (git-fixes).
  - usb: gadget: Set self-powered based on MaxPower and bmAttributes
    (git-fixes).
  - usb: gadget: u_ether: Set is_suspend flag if remote wakeup fails
    (git-fixes).
  - usb: atm: cxacru: fix a flaw in existing endpoint checks
    (git-fixes).
  - drivers: core: fix device leak in __fw_devlink_relax_cycles()
    (git-fixes).
  - Revert "drivers/card_reader/rtsx_usb: Restore interrupt based
    detection" (git-fixes).
  - bus: simple-pm-bus: fix forced runtime PM use (git-fixes).
  - char: misc: deallocate static minor in error path (git-fixes).
  - eeprom: digsy_mtc: Make GPIO lookup table match the device
    (git-fixes).
  - drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in
    pmcmd_ioctl (git-fixes).
  - slimbus: messaging: Free transaction ID in delayed interrupt
    scenario (git-fixes).
  - cdx: Fix possible UAF error in driver_override_show()
    (git-fixes).
  - bus: mhi: host: pci_generic: Use pci_try_reset_function()
    to avoid deadlock (git-fixes).
  - mei: vsc: Use "wakeuphostint" when getting the host wakeup GPIO
    (git-fixes).
  - iio: filter: admv8818: Force initialization of SDO (git-fixes).
  - iio: dac: ad3552r: clear reset status flag (git-fixes).
  - iio: adc: ad7192: fix channel select (git-fixes).
  - iio: adc: at91-sama5d2_adc: fix sama7g5 realbits value
    (git-fixes).
  - iio: light: apds9306: fix max_scale_nano values (git-fixes).
  - commit 2fb3d9c

++++ kernel-rt:

  - Input: atkbd - map F23 key to support default copilot shortcut
    (git-fixes).
  - commit bfe2bb7
  - Input: xpad - add unofficial Xbox 360 wireless receiver clone
    (git-fixes).
  - Input: xpad - add support for wooting two he (arm) (git-fixes).
  - Input: xpad - improve name of 8BitDo controller 2dc8:3106
    (git-fixes).
  - Input: xpad - add QH Electronics VID/PID (git-fixes).
  - Input: xpad - add support for Nacon Evol-X Xbox One Controller
    (git-fixes).
  - commit 4710207
  - Input: xpad - add support for Nacon Pro Compact (git-fixes).
  - commit 3a2bb67
  - KVM: arm64: Initialize SCTLR_EL1 in __kvm_hyp_init_cpu() (git-fixes)
  - commit 2805274
  - KVM: arm64: Initialize HCR_EL2.E2H early (git-fixes)
  - commit 0ff07a9
  - USB: hub: Ignore non-compliant devices with too many configs
    or interfaces (bsc#1238909 CVE-2025-21776).
  - commit 1601393
  - powerpc/pseries/iommu: memory notifier incorrectly adds TCEs
    for pmemory (bsc#1239167 ltc#211055).
  - commit 5ee1b4c
  - s390/traps: Fix test_monitor_call() inline assembly (git-fixes
    bsc#1239160).
  - commit 1a519e2
  - platform/x86: int3472: Check for adev == NULL (CVE-2024-58011
    bsc#1239080).
  - commit 58ea3d9
  - net_sched: sch_sfq: don't allow 1 packet limit (CVE-2024-57996
    bsc#1239076).
  - commit 6b3567e
  - ASoC: SOF: Intel: hda-dai: Ensure DAI widget is valid during
    params (CVE-2024-58012 bsc#1239104).
  - commit 642aedc
  - wifi: brcmfmac: fix NULL pointer dereference in
    brcmf_txfinalize() (CVE-2025-21744 bsc#1238903).
  - commit 062e9bf
  - usb: gadget: Check bmAttributes only if configuration is valid
    (git-fixes).
  - usb: gadget: Fix setting self-powered state on suspend
    (git-fixes).
  - commit fb64cab
  - usb: typec: ucsi: Fix NULL pointer access (git-fixes).
  - usb: xhci: Fix host controllers "dying" after suspend and resume
    (git-fixes).
  - usb: dwc3: Set SUSPENDENABLE soon after phy init (git-fixes).
  - usb: hub: lack of clearing xHC resources (git-fixes).
  - usb: renesas_usbhs: Flush the notify_hotplug_work (git-fixes).
  - usb: renesas_usbhs: Use devm_usb_get_phy() (git-fixes).
  - usb: renesas_usbhs: Call clk_put() (git-fixes).
  - usb: dwc3: gadget: Prevent irq storm when TH re-executes
    (git-fixes).
  - xhci: Restrict USB4 tunnel detection for USB3 devices to Intel
    hosts (git-fixes).
  - usb: typec: ucsi: increase timeout for PPM reset operations
    (git-fixes).
  - acpi: typec: ucsi: Introduce a ->poll_cci method (git-fixes).
  - usb: typec: tcpci_rt1711h: Unmask alert interrupts to fix
    functionality (git-fixes).
  - usb: gadget: Set self-powered based on MaxPower and bmAttributes
    (git-fixes).
  - usb: gadget: u_ether: Set is_suspend flag if remote wakeup fails
    (git-fixes).
  - usb: atm: cxacru: fix a flaw in existing endpoint checks
    (git-fixes).
  - drivers: core: fix device leak in __fw_devlink_relax_cycles()
    (git-fixes).
  - Revert "drivers/card_reader/rtsx_usb: Restore interrupt based
    detection" (git-fixes).
  - bus: simple-pm-bus: fix forced runtime PM use (git-fixes).
  - char: misc: deallocate static minor in error path (git-fixes).
  - eeprom: digsy_mtc: Make GPIO lookup table match the device
    (git-fixes).
  - drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in
    pmcmd_ioctl (git-fixes).
  - slimbus: messaging: Free transaction ID in delayed interrupt
    scenario (git-fixes).
  - cdx: Fix possible UAF error in driver_override_show()
    (git-fixes).
  - bus: mhi: host: pci_generic: Use pci_try_reset_function()
    to avoid deadlock (git-fixes).
  - mei: vsc: Use "wakeuphostint" when getting the host wakeup GPIO
    (git-fixes).
  - iio: filter: admv8818: Force initialization of SDO (git-fixes).
  - iio: dac: ad3552r: clear reset status flag (git-fixes).
  - iio: adc: ad7192: fix channel select (git-fixes).
  - iio: adc: at91-sama5d2_adc: fix sama7g5 realbits value
    (git-fixes).
  - iio: light: apds9306: fix max_scale_nano values (git-fixes).
  - commit 2fb3d9c

++++ gcc15:

  - Disable profiling during build when %want_reproducible_builds is set
    [bsc#1238491]

++++ mozilla-nss:

  - Add nss-reproducible-chksums.patch to make NSS-build reproducible
    Use key from openssl (bsc#1081723)

++++ ncurses:

  - Add ncurses patch 20250308
    + remove test in wgetch which applied notimeout to the initial read
    of a character (patch by Branden Robinson).
    + improve formatting/style of manpages (patches by Branden Robinson).
    + fix a few compiler-warnings in MinGW port.

++++ python313-core:

  - Skip PGO with %want_reproducible_builds (bsc#1239210).

++++ talloc:

  - Update to 2.4.3
    * Testsuite and documenation fixes
    * Add LGPLv3 LICENSE file

++++ python313:

  - Skip PGO with %want_reproducible_builds (bsc#1239210).

++++ python-Jinja2:

  - Update to 3.1.6
    * The ``|attr`` filter does not bypass the environment's attribute lookup,
    allowing the sandbox to apply its checks.

++++ python-Pygments:

  - Remove files from testsamples that licensedigger flagged as high risks.
    Also created an issue upstream for potential licensing issues. See
    https://github.com/pygments/pygments/issues/2872
  - Disable tests which depended on those files

++++ python-gobject:

  - Update to version 3.52.1
    + Use `girepository` 2.0 for GIR mappings.
    + Use Python's vectorcall protocol internally.
    + Improved API for asyncio.
    + Deprecation: The pygtkcompat module now throws an exception
    when imported.
    + Method signatures are exposed from PyGObject now.
    + Use gobject-introspection-tests for testing.
    + Convenience API for Gdk.RGBA got GDK 4, similar to GDK 3.
    + Added a [pre-commit](https://pre-commit.com/) configuration.
    + Use standard `enum` module for enums and flags in PyGObject.
    + Added an option to skip automatic initialization of GTK and
    GDK.
    + PyGObject is no longer automatically tested on i386
    architecture.
    + Fixed iterator protocol implementation for properties.
    + Various code and documentation improvements.
  - Add pythoncapi-compat as subproject.
  - Pass -Dtests=false to meson: disable tests for now, as we do not
    have the submodule for that.
  - Pass -Dwheel=false to meson, as we use our own python
    single-spec mechanism to install the python bindings.
  - Add pygobject-license.patch: Fix build by not relying on PE-639
    yet.
  - Replace pkgconfig(gobject-introspection-1.0) BuildRequires with
    pkgconfig(girepository-2.0): follow upstreams changes.
  - Drop pkgconfig(gmodule-2.0) BuildRequires: no longer needed.

------------------------------------------------------------------
------------------  2025-3-9  -  Mar 9 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ALSA: hda: intel: Add Dell ALC3271 to power_save denylist
    (stable-fixes).
  - ALSA: seq: Avoid module auto-load handling at event delivery
    (stable-fixes).
  - commit 5548289
  - ALSA: hda/realtek: Add support for ASUS B5405 and B5605 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS ROG Strix GA603 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS ROG Strix G814 Laptop
    using CS35L41 HDA (stable-fixes).
  - commit 5f7974b
  - ALSA: hda/realtek: Add support for ASUS Zenbook UM3406KA
    Laptops using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS B3405 and B3605 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for various ASUS Laptops using
    CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS ROG Strix G614 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: update ALC222 depop optimize (stable-fixes).
  - ALSA: hda: realtek: fix incorrect IS_REACHABLE() usage
    (git-fixes).
  - ALSA: hda/realtek - add supported Mic Mute LED for Lenovo
    platform (stable-fixes).
  - ALSA: hda: Fix speakers on ASUS EXPERTBOOK P5405CSA 1.0
    (stable-fixes).
  - ALSA: hda/realtek: Fix Asus Z13 2025 audio (stable-fixes).
  - commit c78c8b9
  - drm/xe/oa: Signal output fences (stable-fixes).
  - Refresh
    patches.suse/xe-oa-Fix-query-mode-of-operation-for-OAR-OAC.patch.
  - commit 9868b15
  - rapidio: add check for rio_add_net() in rio_scan_alloc_net()
    (git-fixes).
  - rapidio: fix an API misues when rio_add_net() fails (git-fixes).
  - dma: kmsan: export kmsan_handle_dma() for modules (git-fixes).
  - hwmon: fix a NULL vs IS_ERR_OR_NULL() check in
    xgene_hwmon_probe() (git-fixes).
  - hwmon: (ad7314) Validate leading zero bits and return error
    (git-fixes).
  - hwmon: (ntc_thermistor) Fix the ncpXXxh103 sensor table
    (git-fixes).
  - hwmon: (pmbus) Initialise page count in pmbus_identify()
    (git-fixes).
  - hwmon: (peci/dimmtemp) Do not provide fake thresholds data
    (git-fixes).
  - gpio: rcar: Fix missing of_node_put() call (git-fixes).
  - gpio: aggregator: protect driver attr handlers against module
    unload (git-fixes).
  - ALSA: usx2y: validate nrpacks module parameter on probe
    (git-fixes).
  - ALSA: hda/realtek: Remove (revert) duplicate Ally X config
    (git-fixes).
  - drm/xe/oa: Allow oa_exponent value of 0 (git-fixes).
  - drm/amd/display: Fix HPD after gpu reset (stable-fixes).
  - drm/amd/display: add a quirk to enable eDP0 on DP1
    (stable-fixes).
  - drm/amd/display: Disable PSR-SU on eDP panels (stable-fixes).
  - drm/amdkfd: Preserve cp_hqd_pq_control on update_mqd
    (stable-fixes).
  - drm/xe/oa: Allow only certain property changes from config
    (stable-fixes).
  - drm/xe/oa: Add syncs support to OA config ioctl (stable-fixes).
  - drm/xe/oa: Move functions up so they can be reused for config
    ioctl (stable-fixes).
  - commit d3f758a
  - sunrpc: suppress warnings for unused procfs functions
    (git-fixes).
  - commit c61a5ed
  - SUNRPC: Handle -ETIMEDOUT return from tlshd (git-fixes).
  - commit 5ae6ead
  - NFSv4: Fix a deadlock when recovering state on a sillyrenamed
    file (git-fixes).
  - commit 68a98ff
  - SUNRPC: Prevent looping due to rpc_signal_task() races
    (git-fixes).
  - commit efcf93f
  - NFSD: Fix CB_GETATTR status fix (git-fixes).
  - commit bfb8cfa
  - nfsd: validate the nfsd_serv pointer before calling svc_wake_up
    (git-fixes).
  - commit 2e52d43
  - nfsd: clear acl_access/acl_default after releasing them
    (git-fixes).
  - commit 27010fb
  - pnfs/flexfiles: retry getting layout segment for reads
    (git-fixes).
  - commit b6de6d7
  - nfs: Make NFS_FSCACHE select NETFS_SUPPORT instead of depending
    on it (git-fixes).
  - commit 7c2ea4b
  - KMSAN: uninit-value in inode_go_dump (5) (git-fixes).
  - commit 33eb119
  - gfs2: Fix unlinked inode cleanup (git-fixes).
  - commit 34e8c14
  - gfs2: Allow immediate GLF_VERIFY_DELETE work (git-fixes).
  - commit 85fd98d
  - gfs2: Rename GLF_VERIFY_EVICT to GLF_VERIFY_DELETE (git-fixes).
  - commit 7b42f25
  - xfs: flush inodegc before swapon (git-fixes).
  - commit 5c0ff3f
  - xfs: fix online repair probing when CONFIG_XFS_ONLINE_REPAIR=n
    (git-fixes).
  - commit 188fef0
  - xfs: report realtime block quota limits on realtime directories
    (git-fixes).
  - commit fe8bc40
  - exfat: short-circuit zero-byte writes in exfat_file_write_iter
    (git-fixes).
  - commit e7632e9
  - exfat: fix soft lockup in exfat_clear_bitmap (git-fixes).
  - commit 72aa500
  - exfat: fix just enough dentries but allocate a new cluster to
    dir (git-fixes).
  - commit 9bf8f0b
  - NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client()
    (bsc#1239113 CVE-2024-54456).
  - commit a3a35d5

++++ kernel-firmware-intel:

  - Update to version 20250307 (git commit bd3d8a8b1bb7):
    * intel_vpu: Add firmware for 37xx and 40xx NPUs
  - Update aliases

++++ kernel-rt:

  - ALSA: hda: intel: Add Dell ALC3271 to power_save denylist
    (stable-fixes).
  - ALSA: seq: Avoid module auto-load handling at event delivery
    (stable-fixes).
  - commit 5548289
  - ALSA: hda/realtek: Add support for ASUS B5405 and B5605 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS ROG Strix GA603 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS ROG Strix G814 Laptop
    using CS35L41 HDA (stable-fixes).
  - commit 5f7974b
  - ALSA: hda/realtek: Add support for ASUS Zenbook UM3406KA
    Laptops using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS B3405 and B3605 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for various ASUS Laptops using
    CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS ROG Strix G614 Laptops
    using CS35L41 HDA (stable-fixes).
  - ALSA: hda/realtek: update ALC222 depop optimize (stable-fixes).
  - ALSA: hda: realtek: fix incorrect IS_REACHABLE() usage
    (git-fixes).
  - ALSA: hda/realtek - add supported Mic Mute LED for Lenovo
    platform (stable-fixes).
  - ALSA: hda: Fix speakers on ASUS EXPERTBOOK P5405CSA 1.0
    (stable-fixes).
  - ALSA: hda/realtek: Fix Asus Z13 2025 audio (stable-fixes).
  - commit c78c8b9
  - drm/xe/oa: Signal output fences (stable-fixes).
  - Refresh
    patches.suse/xe-oa-Fix-query-mode-of-operation-for-OAR-OAC.patch.
  - commit 9868b15
  - rapidio: add check for rio_add_net() in rio_scan_alloc_net()
    (git-fixes).
  - rapidio: fix an API misues when rio_add_net() fails (git-fixes).
  - dma: kmsan: export kmsan_handle_dma() for modules (git-fixes).
  - hwmon: fix a NULL vs IS_ERR_OR_NULL() check in
    xgene_hwmon_probe() (git-fixes).
  - hwmon: (ad7314) Validate leading zero bits and return error
    (git-fixes).
  - hwmon: (ntc_thermistor) Fix the ncpXXxh103 sensor table
    (git-fixes).
  - hwmon: (pmbus) Initialise page count in pmbus_identify()
    (git-fixes).
  - hwmon: (peci/dimmtemp) Do not provide fake thresholds data
    (git-fixes).
  - gpio: rcar: Fix missing of_node_put() call (git-fixes).
  - gpio: aggregator: protect driver attr handlers against module
    unload (git-fixes).
  - ALSA: usx2y: validate nrpacks module parameter on probe
    (git-fixes).
  - ALSA: hda/realtek: Remove (revert) duplicate Ally X config
    (git-fixes).
  - drm/xe/oa: Allow oa_exponent value of 0 (git-fixes).
  - drm/amd/display: Fix HPD after gpu reset (stable-fixes).
  - drm/amd/display: add a quirk to enable eDP0 on DP1
    (stable-fixes).
  - drm/amd/display: Disable PSR-SU on eDP panels (stable-fixes).
  - drm/amdkfd: Preserve cp_hqd_pq_control on update_mqd
    (stable-fixes).
  - drm/xe/oa: Allow only certain property changes from config
    (stable-fixes).
  - drm/xe/oa: Add syncs support to OA config ioctl (stable-fixes).
  - drm/xe/oa: Move functions up so they can be reused for config
    ioctl (stable-fixes).
  - commit d3f758a
  - sunrpc: suppress warnings for unused procfs functions
    (git-fixes).
  - commit c61a5ed
  - SUNRPC: Handle -ETIMEDOUT return from tlshd (git-fixes).
  - commit 5ae6ead
  - NFSv4: Fix a deadlock when recovering state on a sillyrenamed
    file (git-fixes).
  - commit 68a98ff
  - SUNRPC: Prevent looping due to rpc_signal_task() races
    (git-fixes).
  - commit efcf93f
  - NFSD: Fix CB_GETATTR status fix (git-fixes).
  - commit bfb8cfa
  - nfsd: validate the nfsd_serv pointer before calling svc_wake_up
    (git-fixes).
  - commit 2e52d43
  - nfsd: clear acl_access/acl_default after releasing them
    (git-fixes).
  - commit 27010fb
  - pnfs/flexfiles: retry getting layout segment for reads
    (git-fixes).
  - commit b6de6d7
  - nfs: Make NFS_FSCACHE select NETFS_SUPPORT instead of depending
    on it (git-fixes).
  - commit 7c2ea4b
  - KMSAN: uninit-value in inode_go_dump (5) (git-fixes).
  - commit 33eb119
  - gfs2: Fix unlinked inode cleanup (git-fixes).
  - commit 34e8c14
  - gfs2: Allow immediate GLF_VERIFY_DELETE work (git-fixes).
  - commit 85fd98d
  - gfs2: Rename GLF_VERIFY_EVICT to GLF_VERIFY_DELETE (git-fixes).
  - commit 7b42f25
  - xfs: flush inodegc before swapon (git-fixes).
  - commit 5c0ff3f
  - xfs: fix online repair probing when CONFIG_XFS_ONLINE_REPAIR=n
    (git-fixes).
  - commit 188fef0
  - xfs: report realtime block quota limits on realtime directories
    (git-fixes).
  - commit fe8bc40
  - exfat: short-circuit zero-byte writes in exfat_file_write_iter
    (git-fixes).
  - commit e7632e9
  - exfat: fix soft lockup in exfat_clear_bitmap (git-fixes).
  - commit 72aa500
  - exfat: fix just enough dentries but allocate a new cluster to
    dir (git-fixes).
  - commit 9bf8f0b
  - NFS: Fix potential buffer overflowin nfs_sysfs_link_rpc_client()
    (bsc#1239113 CVE-2024-54456).
  - commit a3a35d5

++++ libidn2:

  - update to 2.3.8:
    * Unicode 15.1.0 table updates
    * Now U+19DA is DISALLOWED again
    * The idn2 tool now binds the "gnulib" domain for translations

++++ vim:

  - Introduce patch to fix bsc#1235751 (regression).
    * vim-9.1.1134-revert-putty-terminal-colors.patch
  - Update to 9.1.1176. Changes:
    * 9.1.1176: wrong indent when expanding multiple lines
    * 9.1.1175: inconsistent behaviour with exclusive selection and motion commands
    * 9.1.1174: tests: Test_complete_cmdline() may fail
    * 9.1.1173: filetype: ABNF files are not detected
    * 9.1.1172: [security]: overflow with 'nostartofline' and Ex command in tag file
    * 9.1.1171: tests: wrong arguments passed to assert_equal()
    * 9.1.1170: wildmenu highlighting in popup can be improved
    * 9.1.1169: using global variable for get_insert()/get_lambda_name()
    * 9.1.1168: wrong flags passed down to nextwild()
    * 9.1.1167: mark '] wrong after copying text object
    * 9.1.1166: command-line auto-completion hard with wildmenu
    * 9.1.1165: diff: regression with multi-file diff blocks
    * 9.1.1164: [security]: code execution with tar.vim and special crafted tar files
    * 9.1.1163: $MYVIMDIR is set too late
    * 9.1.1162: completion popup not cleared in cmdline
    * 9.1.1161: preinsert requires bot "menu" and "menuone" to be set
    * 9.1.1160: Ctrl-Y does not work well with "preinsert" when completing items
    * 9.1.1159: $MYVIMDIR may not always be set
    * 9.1.1158: :verbose set has wrong file name with :compiler!
    * 9.1.1157: command completion wrong for input()
    * 9.1.1156: tests: No test for what patch 9.1.1152 fixes
    * 9.1.1155: Mode message not cleared after :silent message
    * 9.1.1154: Vim9: not able to use autoload class accross scripts
    * 9.1.1153: build error on Haiku
    * 9.1.1152: Patch v9.1.1151 causes problems
    * 9.1.1151: too many strlen() calls in getchar.c
    * 9.1.1150: :hi completion may complete to wrong value
    * 9.1.1149: Unix Makefile does not support Brazilian lang for the installer
    * 9.1.1148: Vim9: finding imported scripts can be further improved
    * 9.1.1147: preview-window does not scroll correctly
    * 9.1.1146: Vim9: wrong context being used when evaluating class member
    * 9.1.1145: multi-line completion has wrong indentation for last line
    * 9.1.1144: no way to create raw strings from a blob
    * 9.1.1143: illegal memory access when putting a register
    * 9.1.1142: tests: test_startup fails if $HOME/$XDG_CONFIG_HOME is defined
    * 9.1.1141: Misplaced comment in readfile()
    * 9.1.1140: filetype: m17ndb files are not detected
    * 9.1.1139: [fifo] is not displayed when editing a fifo
    * 9.1.1138: cmdline completion for :hi is too simplistic
    * 9.1.1137: ins_str() is inefficient by calling STRLEN()
    * 9.1.1136: Match highlighting marks a buffer region as changed
    * 9.1.1135: 'suffixesadd' doesn't work with multiple items
    * 9.1.1134: filetype: Guile init file not recognized
    * 9.1.1133: filetype: xkb files not recognized everywhere
    * 9.1.1132: Mark positions wrong after triggering multiline completion
    * 9.1.1131: potential out-of-memory issue in search.c
    * 9.1.1130: 'listchars' "precedes" is not drawn on Tabs.
    * 9.1.1129: missing out-of-memory test in buf_write()
    * 9.1.1128: patch 9.1.1119 caused a regression with imports
    * 9.1.1127: preinsert text is not cleaned up correctly
    * 9.1.1126: patch 9.1.1121 used a wrong way to handle enter
    * 9.1.1125: cannot loop through pum menu with multiline items
    * 9.1.1124: No test for 'listchars' "precedes" with double-width char
    * 9.1.1123: popup hi groups not falling back to defaults
    * 9.1.1122: too many strlen() calls in findfile.c
    * 9.1.1121: Enter does not insert newline with "noselect"
    * 9.1.1120: tests: Test_registers fails
    * 9.1.1119: Vim9: Not able to use an autoloaded class from another autoloaded script
    * 9.1.1118: tests: test_termcodes fails
    * 9.1.1117: there are a few minor style issues
    * 9.1.1116: Vim9: super not supported in lambda expressions
    * 9.1.1115: [security]: use-after-free in str_to_reg()
    * 9.1.1114: enabling termguicolors automatically confuses users
    * 9.1.1113: tests: Test_terminal_builtin_without_gui waits 2 seconds
    * 9.1.1112: Inconsistencies in get_next_or_prev_match()
    * 9.1.1111: Vim9: variable not found in transitive import
    * 9.1.1110: Vim tests are slow and flaky
    * 9.1.1109: cmdexpand.c hard to read
    * 9.1.1108: 'smoothscroll' gets stuck with 'listchars' "eol"
    * 9.1.1107: cannot loop through completion menu with fuzzy
    * 9.1.1106: tests: Test_log_nonexistent() causes asan failure
    * 9.1.1105: Vim9: no support for protected new() method
    * 9.1.1104: CI: using Ubuntu 22.04 Github runners
    * 9.1.1103: if_perl: still some compile errors with Perl 5.38
    * 9.1.1102: tests: Test_WinScrolled_Resized_eiw() uses wrong filename

------------------------------------------------------------------
------------------  2025-3-8  -  Mar 8 2025  -------------------
------------------------------------------------------------------

++++ gobject-introspection:

  - Update to version 1.83.4:
    + Revert support for "static" virtual functions.

++++ nftables:

  - Update 0001-tools-add-a-systemd-unit-for-static-rulesets.patch
    from new submission.

++++ nvidia-open-driver-G06-signed:

  - removed obsolete kernel-firmware-nvidia-gspx-G06-cuda; firmware
    has moved to nvidia-common-G06 and
    kernel-firmware-nvidia-gspx-G06 is no longer available either
    (boo#1239139)

------------------------------------------------------------------
------------------  2025-3-7  -  Mar 7 2025  -------------------
------------------------------------------------------------------

++++ checkpolicy:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * no source change

++++ lvm2-device-mapper:

  - Fixes the lvm2-testsuite case fsadm-btrfs.sh (bsc#1238857)
    * Update SUSE special patch
    + fate-31841-03_tests-new-test-suite-of-fsadm-for-btrfs.patch

++++ dracut:

  - Update to version 059+suse.667.gf0265ebe:
    * fix(iscsi): make sure services are shut down when switching root (bsc#1237695)
    * fix(iscsi): don't require network setup for qedi
    * fix(90kernel-modules): explicitly include xhci-pci-renesas (bsc#1238258)
    * fix(network-legacy): do not require pgrep when using wicked (bsc#1236982)

++++ gpg2:

  - Update to 2.5.5: [bsc#1236931, bsc#1239119]
    * gpg: Fix a verification DoS due to a malicious subkey in the
    keyring.  [T7527]
    * dirmngr: Fix possible hangs due to blocking connection requests.
    [T6606, T7434]
    Release-info: https://dev.gnupg.org/T7530

++++ grub2:

  - Pass through PAES cipher as AES on s390x-emu (jsc#PED-10950)
    * 0001-s390x-emu-Pass-through-PAES-cipher-as-AES.patch
  - Fix zfs.mo not found message when booting on legacy BIOS (bsc#1237865)
    * 0001-autofs-Ignore-zfs-not-found.patch

++++ kernel-default:

  - block: Remove zone write plugs when handling native zone append
    writes (git-fixes).
  - md/raid*: Fix the set_queue_limits implementations (git-fixes).
  - partitions: mac: fix handling of bogus partition table
    (git-fixes).
  - block: cleanup and fix batch completion adding conditions
    (git-fixes).
  - block: don't revert iter for -EIOCBQUEUED (git-fixes).
  - commit 9fb2f84
  - packaging: Patch Makefile to pre-select gcc version (jsc#PED-12251).
    When compiler different from the one which was used to configure the
    kernel is used to build modules a warning is issued and the build
    continues. This could be turned into an error but that would be too
    restrictive.
    The generated kernel-devel makefile could set the compiler but then the
    main Makefile as to be patched to assign CC with ?=
    This causes run_oldconfig failure on SUSE-2024 and kbuild config check
    failure on SUSE-2025.
    This cannot be hardcoded to one version in a regular patch because the
    value is expected to be configurable at mkspec time. Patch the Makefile
    after aplyin patches in rpm prep step instead. A check is added to
    verify that the sed command did indeed apply the change.
  - commit 6031391
  - tracing/osnoise: Fix resetting of tracepoints (CVE-2025-21733
    bsc#1238494).
  - commit 2bff62d
  - btrfs: fix assertion failure when splitting ordered extent
    after transaction abort (CVE-2025-21754 bsc#1238496).
  - commit 57147c4
  - tcp: correct handling of extreme memory squeeze (CVE-2025-21710
    bsc#1237888).
  - commit 101929d
  - x86/boot: Use '-std=gnu11' to fix build with GCC 15
    (jsc#PED-12251).
  - commit bb8a87d
  - drm/amdkfd: Fix NULL Pointer Dereference in KFD queue
    (git-fixes).
  - drm/amd/display: Fix null check for pipe_ctx->plane_state in
    resource_build_scaling_params (git-fixes).
  - drm/xe/userptr: Unmap userptrs in the mmu notifier (git-fixes).
  - drm/xe/hmm: Don't dereference struct page pointers without
    notifier lock (git-fixes).
  - drm/xe/hmm: Style- and include fixes (git-fixes).
  - drm/xe: Add staging tree for VM binds (git-fixes).
  - drm/xe: Fix fault mode invalidation with unbind (git-fixes).
  - drm/xe/vm: Fix a misplaced #endif (git-fixes).
  - drm/xe/vm: Validate userptr during gpu vma prefetching
    (git-fixes).
  - drm/xe/userptr: properly setup pfn_flags_mask (git-fixes).
  - drm/sched: Fix preprocessor guard (git-fixes).
  - drm/imagination: Fix timestamps in firmware traces (git-fixes).
  - drm/imagination: only init job done fences once (git-fixes).
  - drm/imagination: Hold drm_gem_gpuva lock for unmap (git-fixes).
  - drm/imagination: avoid deadlock on fence release (git-fixes).
  - wifi: cfg80211: regulatory: improve invalid hints checking
    (git-fixes).
  - wifi: mac80211: fix vendor-specific inheritance (git-fixes).
  - wifi: mac80211: fix MLE non-inheritance parsing (git-fixes).
  - wifi: iwlwifi: Fix A-MSDU TSO preparation (git-fixes).
  - wifi: iwlwifi: Free pages allocated when failing to build A-MSDU
    (git-fixes).
  - wifi: iwlwifi: limit printed string from FW file (git-fixes).
  - wifi: iwlwifi: mvm: don't try to talk to a dead firmware
    (git-fixes).
  - wifi: iwlwifi: mvm: clean up ROC on failure (git-fixes).
  - wifi: nl80211: reject cooked mode if it is set along with
    other flags (git-fixes).
  - Bluetooth: Add check for mgmt_alloc_skb() in
    mgmt_device_connected() (git-fixes).
  - Bluetooth: Add check for mgmt_alloc_skb() in mgmt_remote_name()
    (git-fixes).
  - bluetooth: btusb: Initialize .owner field of
    force_poll_sync_fops (git-fixes).
  - commit bceb443
  - initcall_blacklist: Does not allow kernel_lockdown be
    blacklisted (bsc#1237521).
  - commit 4ab5f98

++++ kernel-rt:

  - block: Remove zone write plugs when handling native zone append
    writes (git-fixes).
  - md/raid*: Fix the set_queue_limits implementations (git-fixes).
  - partitions: mac: fix handling of bogus partition table
    (git-fixes).
  - block: cleanup and fix batch completion adding conditions
    (git-fixes).
  - block: don't revert iter for -EIOCBQUEUED (git-fixes).
  - commit 9fb2f84
  - packaging: Patch Makefile to pre-select gcc version (jsc#PED-12251).
    When compiler different from the one which was used to configure the
    kernel is used to build modules a warning is issued and the build
    continues. This could be turned into an error but that would be too
    restrictive.
    The generated kernel-devel makefile could set the compiler but then the
    main Makefile as to be patched to assign CC with ?=
    This causes run_oldconfig failure on SUSE-2024 and kbuild config check
    failure on SUSE-2025.
    This cannot be hardcoded to one version in a regular patch because the
    value is expected to be configurable at mkspec time. Patch the Makefile
    after aplyin patches in rpm prep step instead. A check is added to
    verify that the sed command did indeed apply the change.
  - commit 6031391
  - tracing/osnoise: Fix resetting of tracepoints (CVE-2025-21733
    bsc#1238494).
  - commit 2bff62d
  - btrfs: fix assertion failure when splitting ordered extent
    after transaction abort (CVE-2025-21754 bsc#1238496).
  - commit 57147c4
  - tcp: correct handling of extreme memory squeeze (CVE-2025-21710
    bsc#1237888).
  - commit 101929d
  - x86/boot: Use '-std=gnu11' to fix build with GCC 15
    (jsc#PED-12251).
  - commit bb8a87d
  - drm/amdkfd: Fix NULL Pointer Dereference in KFD queue
    (git-fixes).
  - drm/amd/display: Fix null check for pipe_ctx->plane_state in
    resource_build_scaling_params (git-fixes).
  - drm/xe/userptr: Unmap userptrs in the mmu notifier (git-fixes).
  - drm/xe/hmm: Don't dereference struct page pointers without
    notifier lock (git-fixes).
  - drm/xe/hmm: Style- and include fixes (git-fixes).
  - drm/xe: Add staging tree for VM binds (git-fixes).
  - drm/xe: Fix fault mode invalidation with unbind (git-fixes).
  - drm/xe/vm: Fix a misplaced #endif (git-fixes).
  - drm/xe/vm: Validate userptr during gpu vma prefetching
    (git-fixes).
  - drm/xe/userptr: properly setup pfn_flags_mask (git-fixes).
  - drm/sched: Fix preprocessor guard (git-fixes).
  - drm/imagination: Fix timestamps in firmware traces (git-fixes).
  - drm/imagination: only init job done fences once (git-fixes).
  - drm/imagination: Hold drm_gem_gpuva lock for unmap (git-fixes).
  - drm/imagination: avoid deadlock on fence release (git-fixes).
  - wifi: cfg80211: regulatory: improve invalid hints checking
    (git-fixes).
  - wifi: mac80211: fix vendor-specific inheritance (git-fixes).
  - wifi: mac80211: fix MLE non-inheritance parsing (git-fixes).
  - wifi: iwlwifi: Fix A-MSDU TSO preparation (git-fixes).
  - wifi: iwlwifi: Free pages allocated when failing to build A-MSDU
    (git-fixes).
  - wifi: iwlwifi: limit printed string from FW file (git-fixes).
  - wifi: iwlwifi: mvm: don't try to talk to a dead firmware
    (git-fixes).
  - wifi: iwlwifi: mvm: clean up ROC on failure (git-fixes).
  - wifi: nl80211: reject cooked mode if it is set along with
    other flags (git-fixes).
  - Bluetooth: Add check for mgmt_alloc_skb() in
    mgmt_device_connected() (git-fixes).
  - Bluetooth: Add check for mgmt_alloc_skb() in mgmt_remote_name()
    (git-fixes).
  - bluetooth: btusb: Initialize .owner field of
    force_poll_sync_fops (git-fixes).
  - commit bceb443
  - initcall_blacklist: Does not allow kernel_lockdown be
    blacklisted (bsc#1237521).
  - commit 4ab5f98

++++ lvm2:

  - Fixes the lvm2-testsuite case fsadm-btrfs.sh (bsc#1238857)
    * Update SUSE special patch
    + fate-31841-03_tests-new-test-suite-of-fsadm-for-btrfs.patch

++++ rpm:

  - update to rpm-4.20.1
    * add support for fully locked user accounts in sysusers.d
    * fix unmodified %config files being removed in case of an
    unpack failure
    * fix lua deprecation warnings being shown packages built with
    old rpm versions
    * ignore all files in macro directories that do not end with an
    alphanumeric character
  - refreshed patches:
    * rpmqpack.diff
    * unshare.diff
    * rpm2archive.diff
  - dropped patches:
    * debugpackage.diff
    * nextfiles.diff
    * buildsys.diff

++++ libselinux:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * no source change

++++ libsemanage:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * libsemanage: improved performance of semanage store rebuild

++++ libsepol:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * no source change

++++ pcr-oracle:

  - Add fix-bsc1230316-predict-sbatlevelrt-sb-off.patch to fix the
    prediction of SbatLevelRT when Secure Boot is disabled
    (bsc#1230316)
  - Add fix-bsc1230316-make-pcr4-hard-requirement.patch to make PCR4
    a hard requirement for SbatLevelRT prediction (bsc#1230316)

++++ perl:

  - update to 5.40.1
    * fix strftime sometimes crashing if a non-string was used as argument
    * some functions in the builtin:: package would crash when used after
    a tail call
    * fix utf8n_to_uvchr sometimes failing to correctly identify certain
    invalid UTF-8 sequences as invalid.

++++ policycoreutils:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * no source change

++++ python-rpm:

  - update to rpm-4.20.1

++++ libselinux-bindings:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * no source change

++++ python-semanage:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * libsemanage: improved performance of semanage store rebuild

++++ restorecond:

  - Update to version 3.8.1
    https://github.com/SELinuxProject/selinux/releases/tag/3.8.1
    * no source change

++++ setroubleshoot-plugins:

  - Fix license tag, it's GPL-3.0-or-later.

------------------------------------------------------------------
------------------  2025-3-6  -  Mar 6 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Build with GCC 13 on Leap/SLES 15 (bsc#1238713)
  - reverted previous change; n_remove-llvm17-wa-option.patch didn't
    help at all ...

++++ Mesa-drivers:

  - Build with GCC 13 on Leap/SLES 15 (bsc#1238713)
  - reverted previous change; n_remove-llvm17-wa-option.patch didn't
    help at all ...

++++ cpupower:

  - Not also adopt the kernel version, but also the exact build release
    By that it is finally possible to find out on which exact (kernel)
    sources the cpupower tools are based on.
    D amd_do_not_show_amount_of_boost_states_if_zero.patch
  -> This was only needed for an old Dell test env, will not go mainline
    and can vanish now.

++++ python-kiwi:

  - distutils sysconfig is deprecated
    Move to sysconfig module

++++ librsvg:

  - Update to version 2.59.91 (Unstable):
    + Fix linkage on Illumos.
    + Fix the build of the static library on MinGW.
    + Fix versioning of library name.
    + Enable cross-compilation of the gdk-pixbuf loader if meson/qemu
    can handle it.

++++ glib2:

  - Update to version 2.84.0:
    + Bugs fixed:
  - tests: Minor fixes to reference and stream-rw_all tests
  - gdebugcontrollerdbus: Fix a minor typo in a code example in
    the docs
    + Updated translations.

++++ gtk3:

  - Update to version 3.24.49:
    + Fix a crash in GtkIMContext
    + Fix crashes in DND with GtkPlug/GtkSocket
    + Wayland:
  - Fix erroneous crossing events, causing menus to malfunction
  - Support the cursor-shape protocol
    + X11: Enforce size limits on windows, preventing lockups
    + Updated translations.

++++ kernel-default:

  - powerpc: boot: Fix build with gcc 15 (jsc#PED-12251).
  - commit 177c148
  - efi: libstub: Use '-std=gnu11' to fix build with GCC 15
    (jsc#PED-12251).
  - commit 3a88c96
  - NFSD: fix hang in nfsd4_shutdown_callback (CVE-2025-21795
    bsc#1238759).
  - commit 839b02b
  - vxlan: check vxlan_vnigroup_init() return value (CVE-2025-21790
    bsc#1238753).
  - commit 45e6d1b
  - clocksource: Use migrate_disable() to avoid calling
    get_random_u32() in atomic context (CVE-2025-21767 bsc#1238509).
  - commit 1d52af5
  - vxlan: Fix uninit-value in vxlan_vnifilter_dump()
    (CVE-2025-21716 bsc#1237891).
  - commit e46863c
  - mptcp: handle fastopen disconnect correctly (CVE-2025-21705
    bsc#1238525).
  - commit 320aaa6
  - smb: client: fix oops due to unset link speed (CVE-2025-21725
    bsc#1238877).
  - commit 675f8ca
  - ipmr: do not call mr_mfc_uses_dev() for unres entries
    (CVE-2025-21719 bsc#1238860).
  - commit 32e5d0c
  - net: davicom: fix UAF in dm9000_drv_remove (CVE-2025-21715
    bsc#1237889).
  - commit a8a4ff6
  - iommufd/iova_bitmap: Fix shift-out-of-bounds in
    iova_bitmap_offset_to_index() (CVE-2025-21724 bsc#1238863).
  - commit 707e0f9
  - net: ethernet: ti: am65-cpsw: fix freeing IRQ in
    am65_cpsw_nuss_remove_tx_chns() (CVE-2025-21799 bsc#1238739).
  - commit 922ef51
  - powerpc/ftrace: Fix ftrace bug with KASAN=y (jsc#PED-10909).
  - powerpc64/bpf: Add support for bpf trampolines (jsc#PED-10909).
  - samples/ftrace: Add support for ftrace direct samples on powerpc
    (jsc#PED-10909).
  - Update config files
  - powerpc/ftrace: Add support for DYNAMIC_FTRACE_WITH_DIRECT_CALLS
    (jsc#PED-10909).
  - Update config files
  - powerpc/ftrace: Add support for DYNAMIC_FTRACE_WITH_CALL_OPS
    (jsc#PED-10909).
  - Update config files
  - powerpc64/ftrace: Support .text larger than 32MB with
    out-of-line stubs (jsc#PED-10909).
  - Update config files
  - powerpc64/ftrace: Move ftrace sequence out of line
    (jsc#PED-10909).
  - Update config files
  - kbuild: Add generic hook for architectures to use before the
    final vmlinux link (jsc#PED-10909).
  - powerpc/ftrace: Add a postlink script to validate function
    tracer (jsc#PED-10909).
  - powerpc64/bpf: Fold bpf_jit_emit_func_call_hlp() into
    bpf_jit_emit_func_call_rel() (jsc#PED-10909).
  - powerpc/ftrace: Move ftrace stub used for init text before
    _einittext (jsc#PED-10909).
  - powerpc/ftrace: Skip instruction patching if the instructions
    are the same (jsc#PED-10909).
  - powerpc/ftrace: Remove pointer to struct module from
    dyn_arch_ftrace (jsc#PED-10909).
  - powerpc/module_64: Convert #ifdef to IS_ENABLED()
    (jsc#PED-10909).
  - powerpc32/ftrace: Unify 32-bit and 64-bit ftrace entry code
    (jsc#PED-10909).
  - powerpc64/ftrace: Nop out additional 'std' instruction emitted
    by gcc v5.x (jsc#PED-10909).
  - powerpc/kprobes: Use ftrace to determine if a probe is at
    function entry (jsc#PED-10909).
  - commit 52bb9ce
  - supported.conf: correct dependencies for optional (bsc#1238570)
    Also move some fortoggen cros modules into optional, too
  - commit 1502e47
  - rpm/split-modules: Fix optional splitting with usrmerge (bsc#1238570)
  - commit 8be63c4
  - ipvs: fix UB due to uninitialized stack access in
    ip_vs_protocol_init() (CVE-2024-53680 bsc#1235715).
  - commit 1f83147

++++ kernel-firmware-i915:

  - Update to version 20250306 (git commit 44740031a34e):
    * xe: Update GUC to v70.40.2 for BMG, LNL

++++ kernel-firmware-sound:

  - Update to version 20250306 (git commit 44740031a34e):
    * cirrus: cs35l41: Add firmware and tuning for ASUS Consumer laptops
    * cirrus: cs35l41: Add Firmware for various ASUS Commercial laptops
    * ASoC: tas2781: Update dsp firmware for Gemtree project

++++ kernel-rt:

  - powerpc: boot: Fix build with gcc 15 (jsc#PED-12251).
  - commit 177c148
  - efi: libstub: Use '-std=gnu11' to fix build with GCC 15
    (jsc#PED-12251).
  - commit 3a88c96
  - NFSD: fix hang in nfsd4_shutdown_callback (CVE-2025-21795
    bsc#1238759).
  - commit 839b02b
  - vxlan: check vxlan_vnigroup_init() return value (CVE-2025-21790
    bsc#1238753).
  - commit 45e6d1b
  - clocksource: Use migrate_disable() to avoid calling
    get_random_u32() in atomic context (CVE-2025-21767 bsc#1238509).
  - commit 1d52af5
  - vxlan: Fix uninit-value in vxlan_vnifilter_dump()
    (CVE-2025-21716 bsc#1237891).
  - commit e46863c
  - mptcp: handle fastopen disconnect correctly (CVE-2025-21705
    bsc#1238525).
  - commit 320aaa6
  - smb: client: fix oops due to unset link speed (CVE-2025-21725
    bsc#1238877).
  - commit 675f8ca
  - ipmr: do not call mr_mfc_uses_dev() for unres entries
    (CVE-2025-21719 bsc#1238860).
  - commit 32e5d0c
  - net: davicom: fix UAF in dm9000_drv_remove (CVE-2025-21715
    bsc#1237889).
  - commit a8a4ff6
  - iommufd/iova_bitmap: Fix shift-out-of-bounds in
    iova_bitmap_offset_to_index() (CVE-2025-21724 bsc#1238863).
  - commit 707e0f9
  - net: ethernet: ti: am65-cpsw: fix freeing IRQ in
    am65_cpsw_nuss_remove_tx_chns() (CVE-2025-21799 bsc#1238739).
  - commit 922ef51
  - powerpc/ftrace: Fix ftrace bug with KASAN=y (jsc#PED-10909).
  - powerpc64/bpf: Add support for bpf trampolines (jsc#PED-10909).
  - samples/ftrace: Add support for ftrace direct samples on powerpc
    (jsc#PED-10909).
  - Update config files
  - powerpc/ftrace: Add support for DYNAMIC_FTRACE_WITH_DIRECT_CALLS
    (jsc#PED-10909).
  - Update config files
  - powerpc/ftrace: Add support for DYNAMIC_FTRACE_WITH_CALL_OPS
    (jsc#PED-10909).
  - Update config files
  - powerpc64/ftrace: Support .text larger than 32MB with
    out-of-line stubs (jsc#PED-10909).
  - Update config files
  - powerpc64/ftrace: Move ftrace sequence out of line
    (jsc#PED-10909).
  - Update config files
  - kbuild: Add generic hook for architectures to use before the
    final vmlinux link (jsc#PED-10909).
  - powerpc/ftrace: Add a postlink script to validate function
    tracer (jsc#PED-10909).
  - powerpc64/bpf: Fold bpf_jit_emit_func_call_hlp() into
    bpf_jit_emit_func_call_rel() (jsc#PED-10909).
  - powerpc/ftrace: Move ftrace stub used for init text before
    _einittext (jsc#PED-10909).
  - powerpc/ftrace: Skip instruction patching if the instructions
    are the same (jsc#PED-10909).
  - powerpc/ftrace: Remove pointer to struct module from
    dyn_arch_ftrace (jsc#PED-10909).
  - powerpc/module_64: Convert #ifdef to IS_ENABLED()
    (jsc#PED-10909).
  - powerpc32/ftrace: Unify 32-bit and 64-bit ftrace entry code
    (jsc#PED-10909).
  - powerpc64/ftrace: Nop out additional 'std' instruction emitted
    by gcc v5.x (jsc#PED-10909).
  - powerpc/kprobes: Use ftrace to determine if a probe is at
    function entry (jsc#PED-10909).
  - commit 52bb9ce
  - supported.conf: correct dependencies for optional (bsc#1238570)
    Also move some fortoggen cros modules into optional, too
  - commit 1502e47
  - rpm/split-modules: Fix optional splitting with usrmerge (bsc#1238570)
  - commit 8be63c4
  - ipvs: fix UB due to uninitialized stack access in
    ip_vs_protocol_init() (CVE-2024-53680 bsc#1235715).
  - commit 1f83147

++++ kmod:

  - Update to release 34.1
    * Build fixes only

++++ spirv-tools:

  - Build with GCC 13 on Leap/SLES 15 in the hope to fix Mesa build
    (bsc#1238713)

++++ passt:

  - Introduce apparmor subpackage, fixes bsc#1238597

++++ setroubleshoot:

  - Fix in spec file (correct sysemctl command to reload auditd on
    install/uninstall) (bsc#1237388)
  - Update to version 3.35
    * Mon Mar 03 2025 Petr Lautrbach <lautrbach@redhat.com> - 3.3.35-4
  - Update tmpfiles.d config (bz#2346971)
    * Tue Feb 11 2025 Zbigniew Jędrzejewski-Szmek <zbyszek@in.waw.pl> - 3.3.35-3
  - Drop call to %sysusers_create_compat
    * Tue Nov 26 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.3.35-1
  - Do not hardcode /var/lib/selinux as store_root
    * Fri Nov 15 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.3.34-2
  - Do not hardcode /var/lib/selinux as store_root
  - Fix icon file name (bz#2300369)
    * Mon Nov 04 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.3.34-1
  - data: update app icon
  - Disable bug reporting, if libreport is not available
  - Enable Georgian and Arabic (ar) languages in configure.ac
  - Update translations
    * Wed Aug 21 2024 Michal Srb <michal@redhat.com> - 3.3.33-6
  - Disable bug reporting, if libreport is not available
  - Resolves: RHEL-52902
    * Mon Jun 03 2024 Petr Lautrbach <lautrbach@redhat.com> - 3.3.33-2
  - Ship with contemporary app icon
    * Wed Jan 31 2024 Vit Mojzis <vmojzis@redhat.com> - 3.3.33-1
  - Check that SELinux is enabled before running (rhbz#2178950)
  - Improve limiting RAM utilization
    * Tue Jul 25 2023 Petr Lautrbach <lautrbach@redhat.com> - 3.3.32-7
  - Always reset pending alarms when alarm(0) (rhbz#2112573)
    * Tue Jul 25 2023 Petr Lautrbach <lautrbach@redhat.com> - 3.3.32-6
  - 'imp' module is deprecated in favor of 'importlib' (rhbz#2224393)
    * Fri May 26 2023 Miro Hrončok <mhroncok@redhat.com> - 3.3.32-3
  - Fix build with pip 23.1.2+
  - Fixes: rhbz#2209022

++++ vim:

  - Introduce patch to fix bsc#1235751 (regression).
    * vim-9.1.1134-revert-putty-terminal-colors.patch
  - Update to 9.1.1176.
    * 9.1.1176: wrong indent when expanding multiple lines
    test(runtime/syntax): improve syntax tests
    editorconfig: set indent config for *.vim files
    runtime(doc): mention alternative check for vim9script
    * 9.1.1175: inconsistent behaviour with exclusive selection and motion commands
    runtime(man): don't add jumps when loading a manpage
    runtime(vim): recognize <...> strings (and keys) for 'keywordprg'
    * 9.1.1174: tests: Test_complete_cmdline() may fail
    runtime(doc): mention bzip3 in gzip plugin documentation
    * 9.1.1173: filetype: ABNF files are not detected
    * 9.1.1172: [security]: overflow with 'nostartofline' and Ex command in tag file
    * 9.1.1171: tests: wrong arguments passed to assert_equal()
    * 9.1.1170: wildmenu highlighting in popup can be improved
    runtime(netrw): upstream snapshot of v179
    runtime(doc): fix typo "bet" in :h 'completeopt'
    * 9.1.1169: using global variable for get_insert()/get_lambda_name()
    * 9.1.1168: wrong flags passed down to nextwild()
    * 9.1.1167: mark '] wrong after copying text object
    runtime(doc): update how to get Vim
    * 9.1.1166: command-line auto-completion hard with wildmenu
    runtime(tar): use readblob() instead of shelling out to file(1)
    * 9.1.1165: diff: regression with multi-file diff blocks
    * 9.1.1164: [security]: code execution with tar.vim and special crafted tar files
    translation(it): Update Italian translation
    runtime(tar): fix syntax error in tar.vim
    * 9.1.1163: $MYVIMDIR is set too late
    runtime(syntax-tests): Apply stronger synchronisation between buffers
    * 9.1.1162: completion popup not cleared in cmdline
    * 9.1.1161: preinsert requires bot "menu" and "menuone" to be set
    runtime(misc): add support for bzip3 to tar, vimball and gzip plugins
    * 9.1.1160: Ctrl-Y does not work well with "preinsert" when completing items
    * 9.1.1159: $MYVIMDIR may not always be set
    * 9.1.1158: :verbose set has wrong file name with :compiler!
    runtime(netrw): correctly handle shellslash variable
    * 9.1.1157: command completion wrong for input()
    runtime(doc): fix confusing docs for 'completeitemalign'
    * 9.1.1156: tests: No test for what patch 9.1.1152 fixes
    * 9.1.1155: Mode message not cleared after :silent message
    runtime(lua): Improve 'include' and make '*expr' functions script-local
    runtime(vim): Update base-syntax, match Vim9 function calls after "|"
    * 9.1.1154: Vim9: not able to use autoload class accross scripts
    runtime(compiler): improve svelte-check
    * 9.1.1153: build error on Haiku
    * 9.1.1152: Patch v9.1.1151 causes problems
    runtime(new-tutor): update examples from Neovim to Vim
    nsis: add Portuguese Brazilian translation to nsis installer
    * 9.1.1151: too many strlen() calls in getchar.c
    runtime(vim): make VimKeywordPrg even smarter for regexes
    * 9.1.1150: :hi completion may complete to wrong value
    * 9.1.1149: Unix Makefile does not support Brazilian lang for the installer
    * 9.1.1148: Vim9: finding imported scripts can be further improved
    runtime(lua): Update lua ftplugin and documentation
    * 9.1.1147: preview-window does not scroll correctly
    nsis: added support for pt-BR to installer and update README.txt
    translation(tr): Update Turkish translations
    * 9.1.1146: Vim9: wrong context being used when evaluating class member
    * 9.1.1145: multi-line completion has wrong indentation for last line
    runtime(netrw): runtime(netrw): upstream snapshot of v178
    * 9.1.1144: no way to create raw strings from a blob
    * 9.1.1143: illegal memory access when putting a register
    * 9.1.1142: tests: test_startup fails if $HOME/$XDG_CONFIG_HOME is defined
    runtime(vim): improve &keywordprg in ftplugin
    runtime(vim): Update base-syntax, match :CompilerSet and :SynMenu commands
    * 9.1.1141: Misplaced comment in readfile()
    * 9.1.1140: filetype: m17ndb files are not detected
    * 9.1.1139: [fifo] is not displayed when editing a fifo
    * 9.1.1138: cmdline completion for :hi is too simplistic
    * 9.1.1137: ins_str() is inefficient by calling STRLEN()
    CI: Install netbeans on windows to make sure to run test_netbeans.vim
    runtime(dockerfile): set comments in filetype plugin
    runtime(compiler): include svelte-check compiler
    runtime(doc): get rid of the titlestring hack for terminal-api
    * 9.1.1136: Match highlighting marks a buffer region as changed
    * 9.1.1135: 'suffixesadd' doesn't work with multiple items
    runtime(filetype): move filetype detection into filetypedetect augroup
    CI: add Makefile target to verify default highlighting groups are present

++++ virt-manager:

  - bsc#1239013 - Unable to install an SEV-SNP guest with virt-install
    virtinst-dont-require-uefi-for-sev-snp.patch

------------------------------------------------------------------
------------------  2025-3-5  -  Mar 5 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - n_remove-llvm17-wa-option.patch
    * no longer use --llvm17-wa option when running intel_clc;
    hopefully this fixes again Mesa's build after we updated
    llvm 19.1.5 to 19.1.7 and building it now with gcc13 instead of
    gcc7 (bsc#1238713)

++++ Mesa-drivers:

  - n_remove-llvm17-wa-option.patch
    * no longer use --llvm17-wa option when running intel_clc;
    hopefully this fixes again Mesa's build after we updated
    llvm 19.1.5 to 19.1.7 and building it now with gcc13 instead of
    gcc7 (bsc#1238713)

++++ container-selinux:

  - Update to version 2.235.0:
    * Bump to v2.235.0
    * OWNERS: add wrabcak and zpytela
    * OWNERS: initial commit
    * container_log{reader,writer}_t: allow watch file
    * RPM: Update gating config
    * Enable aarch64 testing
    * TMT: simplify podman tests
    * feat: support /var/lib/crio

++++ kernel-default:

  - udmabuf: fix vmap_udmabuf error page set (git-fixes).
  - Update config files.
  - commit e2e943e
  - acct: block access to kernel internal filesystems (git-fixes).
  - acct: perform last write from workqueue (git-fixes).
  - wifi: mt76: mt7921u: Add VID/PID for TP-Link TXE50UH
    (stable-fixes).
  - wifi: rtw88: sdio: Fix disconnection after beacon loss
    (stable-fixes).
  - wifi: rtw88: add __packed attribute to efuse layout struct
    (stable-fixes).
  - wifi: iwlwifi: avoid memory leak (stable-fixes).
  - wifi: brcmfmac: Check the return value of
    of_property_read_string_index() (stable-fixes).
  - wifi: rtw89: add crystal_cap check to avoid setting as overflow
    value (stable-fixes).
  - wifi: brcmsmac: add gain range check to
    wlc_phy_iqcal_gainparams_nphy() (stable-fixes).
  - xe/oa: Fix query mode of operation for OAR/OAC (git-fixes).
  - drm/amdgpu: Fix Circular Locking Dependency in AMDGPU GFX
    Isolation (git-fixes).
  - drm/amd/display: Reduce accessing remote DPCD overhead
    (git-fixes).
  - alloc_tag: fix set_codetag_empty() when
    !CONFIG_MEM_ALLOC_PROFILING_DEBUG (git-fixes).
  - udmabuf: also check for F_SEAL_FUTURE_WRITE (git-fixes).
  - EDAC/amd64: Simplify ECC check on unified memory controllers
    (git-fixes).
  - ptp: kvm: x86: Return EOPNOTSUPP instead of ENODEV from
    kvm_arch_ptp_init() (git-fixes).
  - ptp: Add error handling for adjfine callback in
    ptp_clock_adjtime (git-fixes).
  - ubi: fastmap: Fix duplicate slab cache names while attaching
    (git-fixes).
  - ubi: fastmap: wl: Schedule fm_work if wear-leveling pool is
    empty (git-fixes).
  - ubi: wl: Put source PEB into correct list if trying locking
    LEB failed (git-fixes).
  - verification/dot2: Improve dot parser robustness (stable-fixes).
  - EDAC/{skx_common,i10nm}: Fix incorrect far-memory error source
    indicator (git-fixes).
  - EDAC/skx_common: Differentiate memory error sources (git-fixes).
  - commit dcf43d4
  - Revert "of: reserved-memory: Fix using wrong number of cells
    to get property 'alignment'" (stable-fixes).
  - commit dfbe690
  - net: Add rx_skb of kfree_skb to raw_tp_null_args (git-fixes).
  - commit 449c6f3
  - selftests/bpf: Add tests for raw_tp NULL args (git-fixes).
  - bpf: Augment raw_tp arguments with PTR_MAYBE_NULL (git-fixes).
  - bpf: Revert "bpf: Mark raw_tp arguments with PTR_MAYBE_NULL"
    (git-fixes).
  - selftests/bpf: Add more test cases for LPM trie (git-fixes).
  - selftests/bpf: Move test_lpm_map.c to map_tests (git-fixes).
  - bpf: Use raw_spinlock_t for LPM trie (git-fixes).
  - bpf: Switch to bpf mem allocator for LPM trie (git-fixes).
  - bpf: Fix exact match conditions in trie_get_next_key()
    (git-fixes).
  - bpf: Handle in-place update for full LPM trie correctly
    (git-fixes).
  - bpf: Handle BPF_EXIST and BPF_NOEXIST for LPM trie (git-fixes).
  - bpf: Remove unnecessary check when updating LPM trie
    (git-fixes).
  - selftests/bpf: Add test for narrow spill into 64-bit spilled
    scalar (git-fixes).
  - selftests/bpf: Add test for reading from STACK_INVALID slots
    (git-fixes).
  - selftests/bpf: Introduce __caps_unpriv annotation for tests
    (git-fixes).
  - bpf: Fix narrow scalar spill onto 64-bit spilled scalar slots
    (git-fixes).
  - bpf: Don't mark STACK_INVALID as STACK_MISC in
    mark_stack_slot_misc (git-fixes).
  - selftests/bpf: Add tests for raw_tp null handling (git-fixes).
  - bpf: Mark raw_tp arguments with PTR_MAYBE_NULL (git-fixes).
  - commit 33a0c52

++++ kernel-rt:

  - udmabuf: fix vmap_udmabuf error page set (git-fixes).
  - Update config files.
  - commit e2e943e
  - acct: block access to kernel internal filesystems (git-fixes).
  - acct: perform last write from workqueue (git-fixes).
  - wifi: mt76: mt7921u: Add VID/PID for TP-Link TXE50UH
    (stable-fixes).
  - wifi: rtw88: sdio: Fix disconnection after beacon loss
    (stable-fixes).
  - wifi: rtw88: add __packed attribute to efuse layout struct
    (stable-fixes).
  - wifi: iwlwifi: avoid memory leak (stable-fixes).
  - wifi: brcmfmac: Check the return value of
    of_property_read_string_index() (stable-fixes).
  - wifi: rtw89: add crystal_cap check to avoid setting as overflow
    value (stable-fixes).
  - wifi: brcmsmac: add gain range check to
    wlc_phy_iqcal_gainparams_nphy() (stable-fixes).
  - xe/oa: Fix query mode of operation for OAR/OAC (git-fixes).
  - drm/amdgpu: Fix Circular Locking Dependency in AMDGPU GFX
    Isolation (git-fixes).
  - drm/amd/display: Reduce accessing remote DPCD overhead
    (git-fixes).
  - alloc_tag: fix set_codetag_empty() when
    !CONFIG_MEM_ALLOC_PROFILING_DEBUG (git-fixes).
  - udmabuf: also check for F_SEAL_FUTURE_WRITE (git-fixes).
  - EDAC/amd64: Simplify ECC check on unified memory controllers
    (git-fixes).
  - ptp: kvm: x86: Return EOPNOTSUPP instead of ENODEV from
    kvm_arch_ptp_init() (git-fixes).
  - ptp: Add error handling for adjfine callback in
    ptp_clock_adjtime (git-fixes).
  - ubi: fastmap: Fix duplicate slab cache names while attaching
    (git-fixes).
  - ubi: fastmap: wl: Schedule fm_work if wear-leveling pool is
    empty (git-fixes).
  - ubi: wl: Put source PEB into correct list if trying locking
    LEB failed (git-fixes).
  - verification/dot2: Improve dot parser robustness (stable-fixes).
  - EDAC/{skx_common,i10nm}: Fix incorrect far-memory error source
    indicator (git-fixes).
  - EDAC/skx_common: Differentiate memory error sources (git-fixes).
  - commit dcf43d4
  - Revert "of: reserved-memory: Fix using wrong number of cells
    to get property 'alignment'" (stable-fixes).
  - commit dfbe690
  - net: Add rx_skb of kfree_skb to raw_tp_null_args (git-fixes).
  - commit 449c6f3
  - selftests/bpf: Add tests for raw_tp NULL args (git-fixes).
  - bpf: Augment raw_tp arguments with PTR_MAYBE_NULL (git-fixes).
  - bpf: Revert "bpf: Mark raw_tp arguments with PTR_MAYBE_NULL"
    (git-fixes).
  - selftests/bpf: Add more test cases for LPM trie (git-fixes).
  - selftests/bpf: Move test_lpm_map.c to map_tests (git-fixes).
  - bpf: Use raw_spinlock_t for LPM trie (git-fixes).
  - bpf: Switch to bpf mem allocator for LPM trie (git-fixes).
  - bpf: Fix exact match conditions in trie_get_next_key()
    (git-fixes).
  - bpf: Handle in-place update for full LPM trie correctly
    (git-fixes).
  - bpf: Handle BPF_EXIST and BPF_NOEXIST for LPM trie (git-fixes).
  - bpf: Remove unnecessary check when updating LPM trie
    (git-fixes).
  - selftests/bpf: Add test for narrow spill into 64-bit spilled
    scalar (git-fixes).
  - selftests/bpf: Add test for reading from STACK_INVALID slots
    (git-fixes).
  - selftests/bpf: Introduce __caps_unpriv annotation for tests
    (git-fixes).
  - bpf: Fix narrow scalar spill onto 64-bit spilled scalar slots
    (git-fixes).
  - bpf: Don't mark STACK_INVALID as STACK_MISC in
    mark_stack_slot_misc (git-fixes).
  - selftests/bpf: Add tests for raw_tp null handling (git-fixes).
  - bpf: Mark raw_tp arguments with PTR_MAYBE_NULL (git-fixes).
  - commit 33a0c52

++++ multipath-tools:

  - Update to version 0.11.0+183+suse.3973293:
    * multipathd: fix hang during shutdown with queuing maps
    (bsc#1238484).
    This adds multipathd-queueing.service.
    * multipath-tools: make multipathd listen on a pathname socket
    (/run/multipathd.socket) besides listening on an abstract socket.
    This allows connecting to multipathd from a containerized application
    (gh#opensvc/multipath-tools#111). In client mode, applications
    linked against libmpathcmd will attempt to connect to the pathname
    socket first, and to the abstract socket if this fails.
    The MULTIPATH_SOCKET_NAME environment variable can be used to
    override the socket name.
    * multipathd: trigger uevents for blacklisted paths in reconfigure
    (bsc#1236321)
    * libmultipath: remove buggy reinstate_paths function

++++ gcc15:

  - Update to GCC trunk head, 15.0.1+git7827
  - Includes fix for emacs JIT use
  - Bumps libgo SONAME to libgo24 which should fix go1.9 build

++++ openssl-3:

  - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are
    also built using -flto=* which significantly increases build times, this
    option disables lto which improve iteration times when developing.

++++ wtmpdb:

  - Update to version 0.72.0+git20250305.10803fd:
    * Release version 0.72.0
    * i386: fix integer format length errors
    * Add utmp format importer
    * Fix wtmp database path in documentation
    * test: schedule test logins on correct day
    * rotate: don't throw away microseconds calculating threshold

++++ ovmf:

  - Update to edk2-stable202502
  - New Features & Bug Fixes (https://github.com/tianocore/edk2/releases):
  - DynamicTablesPkg: Adds X64 support to SRAT table generator
  - DynamicTablesPkg: Generates X64 MADT and CPU SSDT Topology Table
  - Add RNG PPI
  - Update to openssl-3.4.x
  - Update CI to VS2022
  - Produce EFI memory attribute protocol
  - UefiCpuPkg: Add TdxMeasurementLib
  - DxeRngLib: GetRandomNumber spurious success
  - SecurityPkg: Update libspdm
  - OvmfPkg: Use the OvmfPkg version of CcProbeLib
  - ShellPkg: Fix bug #3080, OOB, minor UefiShellLib fixes
  - MdePkg: Fix overflow issue in PeCoffLoaderRelocateImageForRuntime
  - Add Dynamic Stack Cookie Support to IA32/X64/AARCH64
  - Patches (git log --oneline --date-order edk2-stable202411..edk2-stable202502):
    fbe0805b20 MdeModulePkg/HiiDatabaseDxe: Remove buffer error for string default.
    0192f2d7cb MdeModulePkg/UsbBusPei: Improve PEI USB enumeration
    bc664d1830 Revert "FatPkg: Validate Reserved FAT Entries on Volume Open"
    523dbb6d59 ArmPkg: ArmFfaStandaloneMmLib: Fix non-FFA path
    96cf70951f MdePkg/DynamicStackCookieEntryPointLib: Drop execute-in-place versions
    5c3dcef94c MdePkg/DynamicStackCookieEntryPointLib: Remove unused files
    23007f7ae2 UefiPayloadPkg: Add StackCheckLib to fix FIT build issue
    7308568dd6 StandaloneMmPkg StandaloneMmCoreMemoryAllocationLib: Rename gMmst
    0d61f52fe3 Add MockVariablePolicyHelperLib
    2b3ea9334f DynamicTablesPkg: Adds X64 support to SRAT table generator
    1f1182c396 ArmVirtPkg: ArmVirtQemu: Add Custom Stack Cookies
    861b91d975 ArmVirtPkg: Add RNDR Support to QEMU
    30547859f2 OvmfPkg: OvmfIA32X64: Add Custom Stack Cookie Checking
    6d741357c2 OvmfPkg: Add RDRAND Support To QEMU
    e6b6aa90d4 MdePkg: Add Dynamic Stack Cookie Support
    efbf5ed08c MdePkg: Move StackCheckLibStaticInit to StackCheckLib
    db03bf1d9d StandaloneMmPkg: Consume X64 StandaloneMmCoreEntryPoint From MdePkg
    885bcca649 MdePkg: Add StandaloneMmCoreEntryPoint for X64
    e63cdeebb8 MdePkg: Add StackCheckLib Library Class
    d9715c133f MdePkg: Centralize RNDR Register Definition
    5c02a64823 Maintainers.txt: adding Ard and Michael to stewards team
    1cb349e4bb IntelFsp2WrapperPkg: Remove inactive maintainer email
    edf1450f3e SecurityPkg: Add RngPei
    bcab6996a0 MdePkg: Add PeiRngLib
    de5c1198c1 MdePkg: Add Random Number Generator (RNG) PPI
    7518b93f77 MdePkg: Split RNG protocol definitions
    15e225d06a Maintainers.txt: add myself as PrmPkg maintainer
    258f2d1563 ReadMe.rst: reflect bugzilla migration
    f7cf6ce299 License-History.txt: Reflect bugzilla migration
    fe5c2df49e SignedCapsulePkg: make Doxygen interpret ASCII art as verbatim text
    259e1f04c6 BaseTools: Add @verbatim as allowed Doxygen tag
    0664c4e3b9 UefiPayloadPkg: Revert 4KB alignment of CLANGDWARF build
    cd87106d26 BaseTools: Add /DRIVER to CLANGPDB link flags
    074f61e4c6 MdePkg/IndustryStandard: add definitions for CXL CEDT
    62b0698309 BaseTools/AutoGen: GenMake response file quotes strings
    15a7d311a8 BaseTools/tools_def: Remove no-warn-rwx-segments linker options
    f2b42c83dd BaseTools/Scripts/GccBase.lds: Use separate R-W and RW- ELF segments
    e5d95c786b BaseTools/Scripts: Merge GCC and Clang ELF linker scripts
    f5d585b46b BaseTools/Scripts/ClangBase.lds: Move .entry into .text section
    7fd3c89ff4 UefiPayloadPkg: Update Elf segment/section syncup process
    d844a7eab5 BaseTools/tools_def: Use no-warn-rwx-segments only for GCC5
    09d4e6f7c7 MdePkg: Add Hot pluggable resource attribute
    4ec3539e34 MdePkg: Add UEFI 2.11 specification macro
    2e6359a088 MdePkg: Add Confidential Computing Extension for RISC-V AP-TEE
    12ceee664a MdePkg: Add HotPlug Memory Attribute
    62cd7d338b ArmPkg: Retire ArmDisassemblerLib
    fbe19844e0 Revert "ArmVirtPkg/ArmVirtQemu: Reduce MMIO region mapped by default"
    4dd8b9e0f7 ArmVirtPkg: turn off debug logging for VirtioSerialDxe
    c1ab2d6397 Maintainers: update my email address
    e063f8b8a5 BaseTools/Pccts: set C standard
    c0796335d3 MdePkg/BaseFdtLib: fix build with gcc 15
    7742247d1c MdePkg: Add SM3 crypto algorithm GUID definition
    d949ed05d4 Devcontainer: Use latest Fedora 40 image
    31abbed237 .github/codeql.yml: Drop ArmPkg IA32 and X64 from build matrix
    87f14322da ArmVirtPkg: Drop reference to ArmDisassemblerLib
    ef80dd8fad ArmPkg: Stop using ArmDisassemblerLib
    74376f0b72 ArmPkg,ArmPkg/ArmExceptionLib: drop vector relocation variant/support
    43233ff9f8 ArmVirtPkg/ArmVirtQemu: Reduce MMIO region mapped by default
    c558a3b18b ArmPkg/ArmGicDxe: Map GIC MMIO regions before use
    3c4c7a0fc9 ArmPkg/ArmGicDxe: Remove pointless passing around of MMIO addresses
    e68e784649 ArmPkg/ArmGicDxe: Avoid pointless repeated iteration over GIC frames
    387fcf4fa1 ArmPkg/ArmGicDxe: Replace CpuArch registration event with DEPEX
    fb7497cbf9 ArmPkg/CpuDxe: Replace DEPEX on h/w protocol with event notification
    0422dd0669 ArmPkg/CpuDxe: Remove rudimentary vector handoff logic
    e5b56d6ef9 ArmPkg/CpuDxe: Use STATIC linkage where possible
    afdae789cd ArmPkg/CpuDxe: Fix error handling in driver initialization
    b64f735867 Maintainers.txt: Update EmulatorPkg maintainers
    2cb8bf6c69 UnitTestFrameworkPkg: Fix false positives from address sanitizer
    3600675368 MdePkg/BasePeCoffLib: Remove DEBUG() statements from runtime code
    254937f0bc ShellPkg: fix warnings about uninitialized variable
    755d4b9397 OvmfPkg: fix warning about uninitialized variable
    ceb87029c5 SecurityPkg/RngDxe: fix warning about uninitialized variable
    c58501aa1a MdeModulePkg: NvmExpressDxe: fix warning about uninitialized variable
    0f12a5f722 MdeModulePkg: fix warning about uninitialized variable
    a5cb67fb8d MdeModulePkg: PeiMain: fix warning about uninitialized variable
    bba72ffbe1 OvmfPkg/QemuKernelLoaderFsDxe: use SIZE_OF_EFI_FILE_INFO
    df84bb5eda Resolved Coverity Issues in Http Dxe
    428cd8a46f MdePkg: Fix Clang Build Error
    18984b68fe OvmfPkg: make legacy direct kernel loader code nx clean
    6d2143f685 BaseTools: Fix NoneType parent reference in FMMT operations
    8c1e786e50 OvmfPkg/XenPvBlkDxe: Update disk size calculation
    3cf7a644eb OvmfPkg/IndustryStandard/Xen: Update io/blkif.h
    7c5ec51175 MdeModulePkg PeiMain: Remove return for PeiCoreBuildHobHandoffInfoTable()
    d35899b6d2 UnitTestFrameworkPkg: Add SafeIntLib to Common Includes
    6278bbb898 MdePkg: Use SafeIntLib to handle overflow
    aedcaa3df8 MdePkg: Fix overflow issue in PeCoffLoaderRelocateImageForRuntime
    b3bfb8f22d UefiPayloadPkg: Add 4KB align to CLANGDWARF build.
    e356b0f6fd EmulatorPkg PlatformBm: Fix duplicate BootManagerMenuApp boot option issue
    0df3729ad6 ShellPkg Http.c: Remove extra `\n` when using `-m` param
    1f19c3d6ee OvmfPkg/GenericQemuLoadImageLib: fix cmdline + initrd handling
    b873e8b8e3 OvmfPkg/QemuKernelLoaderFsDxe: root directory name should be ""
    9f28d48d2f Maintainers.txt: Add Star as UefiCpuPkg reviewer
    38c17825ad UefiCpuPkg LocalApicLib: Correct typo LINT0 to LINT1
    99cbb63652 OvmfPkg/OvmfXen: use PeiPcdLib for PEI_CORE
    33309733e4 command drvcfg ASSERT REF: https://github.com/tianocore/edk2/issues/10626
    eda58c143c DynamicTablesPkg: Adds X64 FACS generator library
    feb8d49834 OvmfPkg/RiscVVirtQemu.dsc: enable VGA support
    a36fb60053 Maintainers.txt: Remove myself from some reviewer role
    81802056c8 EmulatorPkg: Move magic page to first allocation
    54c1460dd0 RedfishPkg/RedfishHttpDxe: report failure via status code
    3ba6f7d966 Maintainers.txt: add myself as UefiPayloadPkg maintainer
    14cb48b0a0 BaseTools: Break Build on Linker Warnings
    4613eb6abc EmulatorPkg: Fix IA32 MSVC Linker Warnings
    81ba76f7df PrmPkg: Clarify Architecture Support
    336e7e06eb UefiCpuPkg/CpuMpPei: Add LoongArch64 support
    7bc51fc68e UefiCpuPkg/CpuMpPei: Split CpuMpPei.c to two files
    f6afd87663 UefiCpuPkg/PiSmmCpuDxeSmm: SmmWaitForApArrival first sync check
    cbfae3e8a9 EmulatorPkg: Fix Source Level Debug on Windows
    58766a4729 FatPkg: Validate Reserved FAT Entries on Volume Open
    35232f165c OvmfPkg: document opt/org.tianocore/EnableLegacyLoader option
    1549bf11cc OvmfPkg/X86QemuLoadImageLib: make legacy loader configurable.
    4b507b4966 OvmfPkg/GenericQemuLoadImageLib: support booting via shim
    3da39f2cb6 OvmfPkg/X86QemuLoadImageLib: support booting via shim
    c45051450e OvmfPkg/QemuKernelLoaderFsDxe: don't quit when named blobs are present
    46ae4e4b95 OvmfPkg/QemuKernelLoaderFsDxe: accept absolute paths
    1111e9fe70 OvmfPkg/QemuKernelLoaderFsDxe: drop bogus assert
    adf385ecab OvmfPkg/QemuKernelLoaderFsDxe: allow longer file names
    20df7c42bd OvmfPkg/QemuKernelLoaderFsDxe: add support for named blobs
    459f5ffa24 OvmfPkg/QemuKernelLoaderFsDxe: rework direct kernel boot filesystem
    139cbb266b BaseTools/Plugin/HostBasedUnitTestRunner: Set ASAN env vars
    e78fb8a366 UnitTestFrameworkPkg/MemoryAllocationLibPosix: Add allocate below address
    5f97d5391e UnitTestFrameworkPkg/UnitTestLib: Reduce sanitizer false positive
    1c73f0e71d UnitTestFrameworkPkg: Add failing unit tests cases for sanitizer
    de06288019 UnitTestFrameworkPkg: Use /MTd and enable Address Sanitizers
    8d0e23d998 BaseTools/Conf: Simplify VS20xx HOST_APPLICATION builds
    ca4e19ccc2 UnitTestFraworkPkg: Enable DEBUG_CLEAR_MEMORY in host tests
    30b10dcdd0 UnitTestFrameworkPkg/UnitTestLib: Implement Free*() services
    182dbe79a0 UnitTestFrameworkPkg/MemoryAllocationLibPosix: Add DEBUG_CLEAR_MEMORY()
    f9a0e54953 OvmfPkg/OvmfDisplayPcds.dsc.inc: set SetupConOut too
    df35307196 OvmfPkg/OvmfDisplayPcds.dsc.inc: set SetupVideoResolution too
    fde034447f OvmfPkg/PlatformDxe: set SetupVideoResolution too
    b4536e36c4 OvmfPkg/VirtioGpuDxe: set SetupVideoResolution too
    1d2558af76 OvmfPkg/QemuVideoDxe: set SetupVideoResolution too
    2f5db44fdd ArmVirtPkg/ArmVirtQemu.dsc: use OvmfDisplayPcds.dsc.inc
    2b72a70cd1 OvmfPkg/RiscVVirtQemu.dsc: use OvmfDisplayPcds.dsc.inc
    787450af9c OvmfPkg/OvmfXen.dsc: use OvmfDisplayPcds.dsc.inc
    c3427ae439 OvmfPkg: move display pcds to OvmfDisplayPcds.dsc.inc include file
    2091e449f1 StandaloneMmPkg: Introduce a PCD to disable shadow boot FV
    2d2642f483 ArmPkg/ArmGicDxe: Use EOImode 0x0 on GICv3
    81e2cd329e ArmPkg/ArmGic: Rename directory to ArmGicDxe
    9d1a9b426e ArmPkg/ArmGic: Implement GICv3+ version of GIC driver
    86119ff79e ArmPkg/ArmGic: Implement GICv2-only version of GIC driver
    0bb40c79be ArmPkg: Retire ArmGicLib implementations
    c9e38d1afb ArmPkg/ArmGic: Incorporate v3 code from ArmGicLib
    eaa60a6b10 ArmPkg/ArmGic: Retire ArmGicArchLib
    34ab9197a5 DynamicTablesPkg/SsdtSerialPortFixupLib: Switch to ArmGicLib.h
    9bf20991b4 ArmPkg/ArmGic: Move some GIC defines into ArmGicLib.h
    e663b79f74 ArmVirtPkg: Convert ArmVirtGicArchLib to NULL class library
    8edd5fd6d3 ArmPkg/ArmGic: Move GICv3 sysreg check into ArmGicDxe
    84eed1ef2a ArmPkg/ArmGic: Move GICv2 specific EOI/ACK routines into v2 driver
    337a99af10 ArmPkg/ArmGic: Move remaining shared code into ArmGicDxe
    298d8c436a ArmPkg/ArmGic: Drop declarations for non-existent functions
    2ab362f313 ArmPkg/ArmGic: Disentangle ArmGicEnableDistributor () versions
    4e874fcf09 ArmPkg/ArmGic: Disentangle v2 and v3 versions of IRQ en/disable APIs
    a4928a0cfc ArmPkg/ArmGic: Remove ArmGicEndOfInterrupt () API
    aad4dd9aac ArmPkg/ArmGic: Remove ArmGicSendSgiTo () API
    ec5bb8f953 ArmPkg/ArmGic: drop ArmGicEnableInterruptInterface from ArmGicLib
    555bbc6643 ArmPkg/ArmGic: Drop GICv2 legacy support
    ea2f6c68ee MdePkg/Base: Don't error out on missing compiler CPP macros
    f0c87b9ef4 StandaloneMmPkg: move core entry point lib and cpu driver to ArmPkg
    b370eab898 StandaloneMmPkg: introduce StandaloneMmExtractGuidedSectionLib
    6dd5375820 StandaloneMmPkg: remove per-cpu feature on StandaloneMm
    6c62f40df3 StandaloneMmPkg: Move sanity check for comm buffer to entrypoint
    7340a4b63a StandaloneMmPkg: Apply embedded stack in StandaloneMmEntryPoint
    6975494655 ArmPkg: Add StandaloneMm stack size Pcd
    6016c522c6 StandaloneMmCore: Change log level when mCommunicationBuffer is NULL
    1bebc97b81 ArmPkg/MmCommunication: add helper function converting smc return
    8f3c157e04 AmrPkg/MmCommunication: move Mmcommunicate.h to common include
    73b2831879 ArmPkg/MmCommunicationPei: Mmcommunication via FF-A
    9f9a3de9e4 ArmPkg/MmCommunicationDxe: Mmcommunication via FF-A
    1c963008e8 StandaloneMm/Library: Apply FF-A v1.2 in StandaloneMm
    4ca452cf91 ArmPkg/Library: Update StandaloneMmuLib with FF-A v1.2 with page granulirty
    401699c326 ArmPkg: Add ArmFfaLib used in StandaloneMm
    166c3b2eb7 ArmPkg: Add ArmFfaLib used in PEIM
    5d1b38dd07 ArmPkg: Add ArmFfaLib used in Dxe driver
    18948c4a6a ArmPkg: Add ArmFfaLib.h
    30ecebe015 ArmPkg: Remove PcdFfaEnabled
    843f4fd60d ArmPkg: Add FF-A related dynamic Pcd and Guid
    79875fdde0 ArmPkg: Add FF-A partition information header
    d1d690f363 ArmPkg/IndustryStandard: Introduce ArmFfaBootInfo.h
    173af697dd ArmPkg/IndustryStandard: Update ArmFfaSvc.h
    a5212d3db7 StandaloneMm/Library: Apply transfer list boot protocol in StandaloneMm
    54e394b4a2 ArmPkg/StandaloneMmMmuLib: Introduce a SPM_MM status helper fucntion
    c56856f068 ArmPkg/IndustryStandard: Change naming convention in ArmMmSvc.h
    31fcaf1fc0 StandaloneMm/Library: Remove Hob creation on Arm CoreHob Library
    fbeab84945 ArmPkg/Library: Introduce ArmTransferListLib
    6087382c62 StandaloneMmPkg: Introduce PI_MM_CPU_DRIVER_EP protocol.
    62127dfbc7 StandaloneMmPkg: Simplify returning event complete values
    1301e0b47e MdePkg: Add manageability status code defined in PI 1.9 Spec.
    89d413731d NetworkPkg/SnpDxe: Shutdown SnpDxe on BeforeExitBootServices Event.
    c1548908c9 NetworkPkg: UefiPxeBcDxe: Fix error packet detection
    cb672a8eb1 ArmVirtPkg: Use OvmfPkg/Include/*/Shell*.inc
    076ef39ba2 OvmfPkg: Use OvmfPkg/Include/*/Shell*.inc throughout
    7d958e55a4 ArmVirtPkg/CI: Copy shell to virtual drive
    e8de471660 ArmVirtPkg: Include no network components with -D NETWORK_ENABLE=0
    9a21320361 OvmfPkg: Include no network components with -D NETWORK_ENABLE=0
    b24ad97e53 Add VS Code GitHub issues notebook
    f07b03ea90 IntelFsp2Pkg/IntelFsp2Pkg.dec: add a GUID defined in FSP EAS
    8b2256fbf2 MdePkg/Include: Use _Static_assert for clang and GNUC
    aae044a130 EmbeddedPkg: CodeQL Fixes.
    d6f828b384 OvmfPkg/MicroVM: use PeiPcdLib for PEI_CORE
    ac9a6eed02 BaseTools: build_rule.template generate a different dll for wholearchive.
    f35d3a5bd3 MdeModulePkg: Make noisy log DEBUG_VERBOSE
    f2a8bb9dfb CloudHv: Disable PcdFirstTimeWakeUpAPsBySipi
    cbe8a09dba MdeModulePkg/HiiDatabaseDxe: Add string question load default support.
    7c1562f03c CryptoPkg: Add HMAC algorithms for signature/keymgmt
    8b87eb9dfb OvmfPkg: Use the OvmfPkg version of CcProbeLib
    d51baa02a6 OvmfPkg: Update with TdxMeasurementLib
    6f73428d06 OvmfPkg: Implement TdxMeasurementLib
    d97f530413 UefiCpuPkg: Add NULL TdxMeasurementLib instance
    94bfc6f0cb UefiCpuPkg: Add TdxMeasurementLib.h
    8c180acf1d StandaloneMmPkg/MmIpl: Correct FV HOB check founction
    3c8f47bf21 EmulatorPkg/Win/Host: Use safe function _vsnprintf_s()
    4218026bd6 CryptoPkg/BaseCryptLib: Fix mktime() coding style issue
    96390bb8a5 UefiCpuPkg: Update return status to follow spec
    efaa102d00 UefiCpuPkg: Produce EFI memory attributes protocol
    aaf0846fa2 ArmPkg: remove ArmGicAcknowledgeInterrupt function.
    11cffd9c3f CryptoPkg/BaseCryptLibMbedTls : Add strncpy() support to SecCryptLib
    c0533b7e22 OvmfPkg/SmmCpuPlatformHookLibQemu: Define IsCpuSyncAlwaysNeeded
    a8363bce36 Add SmmCpuPlatformHookLib IsCpuSyncAlwaysNeeded interface
    21cbba1bb3 StandaloneMmPkg: Call PeCoffLoaderUnloadImage When Unloading Image
    9bb11cad9d EmbeddedPkg: Remove misleading error message in FindNextMemoryNodeReg
    107981f3f0 StandaloneMmPkg: Assert if dispatcher fails memory allocation
    3ac092cf72 BaseTools: Clean up os.path.normcase and os.path.normpath usage
    8593eca048 ShellPkg: AcpiView: TPM2 parser for Arm FF-A
    14f5e9b098 ShellPkg: AcpiView: TPM2 Parser
    7216013b36 MdePkg: Tpm2Acpi.h: Add defines for TPM2 ACPI table revision 5
    1a23fe7472 MdeModulePkg: Update AtaPassThru to UEFI 2.10A
    114b54e3fb MdePkg: Update AtaPassThru header to UEFI 2.10A
    bb129c6a82 SignedCapsulePkg: Clarify return status of Fmp Protocol GetImage()
    768adcd9c1 FmpDevicePkg: Clarify return status of FMP Protocol GetImage()
    e4d74bb592 MdePkg: Add UEFI Specification macros
    a872cc18e0 MdePkg: Clarify return status of FMP Protocol GetImage()
    9144bb940a MdePkg: Update Default IP TTL
    42a141800c BaseTools: Skip directories with code extensions in the name
    7e03c40659 MdePkg: Update BASE_CR macro in Base.h for a Coverity error
    f6e19abd97 OvmfPkg/VirtioSerialDxe: respond CONSOLE_PORT with PORT_OPEN
    dca265a8ca RedfishPkg/RedfishPlatformConfigDxe: check attribute max. and min. value
    a7cc0014d2 FatPkg: CI: Add PrEval entry
    62de957185 CryptoPkg: Add sleep() function to BaseCryptLibMbedTls
    070eadb550 NetworkPkg/UefiPxeBcDxe: Bugfix for pxe driver
    a2263cb201 UefiPayloadpkg Add Missing part back
    105a62d3ac UefiPayloadPkg ：Update RetrieveMultiSegmentInfoFromHob
    fc140c5eae OvmfPkg: Enable virtio keyboard driver for Ia32x64 OVMF platform
    ce4317b4c8 OvmfPkg: Enable virtio keyboard driver for X64 OVMF platform
    573057cb1d ArmVirtPkg: Enable virtio keyboard driver for ARM OVMF platform
    8bc9f5a2bc OvmfPkg: Virtio based keyboard driver implementation
    0eea7b9c02 OvmfPkg: Add virtio keyboard device hooks
    0986082d7e Redfish/HiiUtilityLib Fix incorrect type assignment
    9e6537469d MdePkg: UefiDevicePathLib: Add Display Only format for Hard Drive.
    f39b121066 UefiPayloadPkg: Align base address for ACPI region
    da6504e5cc IntelFsp2WrapperPkg: Save FspHobListPtr right after FspMemoryInit exits
    1cc78814cd Remove dependancy on re.T
    e8c7b14da0 UefiPayloadPkg: Set PixelsPerScanLine property in GraphicInfo HOB
    c52dddf1eb ArmPkg: Update Generic Watchdog PCD Type
    4971459ab2 OvmfPkg: add new shell runtime config option to documentation.
    597342b212 OvmfPkg/PlatformBootManagerLib: Optimize PlatformRegisterFvBootOption
    abbd05992d OvmfPkg/PlatformBootManagerLib: Introduce FileIsInFv function.
    103aed83a7 OvmfPkg/PlatformBootManagerLib: Introduce support for fw_cfg for UEFI Shell
    07bb226542 OvmfPkg: Add a runtime switch for PlatformRegisterFvBootOption
    b8f3199595 OvmfPkg/LoongArch: Enabling some base libraries
    2ece0790f7 UefiCpuPkg: Add dump interrupt type on LoongArch64
    0fdffb71df UefiCpuPkg: Adjust the exception handler logic on LoongArch64
    fbbf4206c1 MdeModulePkg/XhciDxe: Non-zero start/stop values in XhcGetElapsedTicks
    896930edc9 .github: Add issue automation workflows
    3c8016b302 BaseTools: Support custom library build for base tools on Linux ARM
    74bf7f55c1 BaseTools: Adding cross compilation of BaseTool for Windows ARM/ARM64
    4b2f964749 BaseTools: Adding support of building BaseTool on Windows ARM/ARM64
    79a64e73f7 StandaloneMmPkg/Core: Support to dispatch multiple standalone MM FVs
    40df344b54 .github: Add GitHub issue templates
    124ed0f6d8 IntelFsp2Pkg : Add FSP-I arch config PPI
    1d1e0474d7 IntelFsp2WrapperPkg/FspiWrapperPeim : Support FSP-I measurement
    df1726a65e IntelFsp2WrapperPkg/FspiWrapperPeim : Support API mode
    4ffa8810af IntelFsp2Pkg : Add fsp status code for fspsmm init
    e374edc180 IntelFsp2WrapperPkg/FspiWrapperPeim : Support dispatch mode
    6fd8533b62 IntelFsp2WrapperPkg/FspiWrapperPeim : FSP-I wrapper PEIM entrypoint
    816a02cb3b StandaloneMmPkg/MmIpl : Add MM core fv location PPI support
    47cb080ca4 StandaloneMmPkg : Add MM core fv location PPI
    8279e49aae StandaloneMmPkg/MmIpl : Check if  MM FV HOB was built
    e8ce6c5189 UefiPkg/PiSmmCpuDxeSmm: Set SmmProfile Variable only for DXE SMM
    4af5849556 UefiPayloadPkg: Fix the issue detected by Uncrustify
    c5811ef1b3 UefiPayloadPkg: Enhance universal payload build
    72b65146bf UefiPayloadPkg: Enhance Universal payload serial port node
    7e7492fa12 .pytool/EccCheck: Open files in utf-8
    260d36484d .pytool/LicenseCheck: Open files in utf-8
    b8602d8fee NetworkPkg/WifiConnectionManagerDxe: Keep Setup page on no Wi-Fi module
    d1fccbf494 EmulatorPkg: spurious failure in WriteBlocks on X64
    30c8a73850 SecurityPkg/SecureBootConfigDxe: Enhance help in Delete Signature page
    2c07ab6256 Maintainers.txt: Add myself as ShellPkg reviewer
    9ef348350a OvmfPkg: document runtime config options
    924780f2cc UefiCpuPkg: x86 CpuDxe: Allocate AP Exception Stack Below 4GB
    cef65b2e93 MdePkg BootManagerPolicy.h: Define GUID for connecting storage devices.
    b38180effe ShellPkg/AcpiView: RAS2 Parser - check validity of PCC Count
    35216819b5 SourceLevelDebugPkg DxeDebugAgent: Handle additional initialize cases.
    17e67d26d9 MdeModulePkg DxeMain: Add late initialization for Debug Agent.
    e99d532fd7 ShellPkg/UefiShellLib: Accept "0 " as valid numeric string
    d63d5884d7 ShellPkg/UefiShellLib: Only write value if successful conversion
    f34a945a80 ShellPkg/UefiShellLib: Simplify check for empty string
    e11a912aa3 ShellPkg/UefiShellLib: Correct check for empty string
    ef3a1ef397 ShellPkg/UefiShellLib: Prevent out-of-bounds access
    7936ffa1e6 MdePkg/Ufs.h: Update to UFS 4.0
    59cfc13139 MdeModulePkg/Bus/Ufs: Use IndustryStandard headers
    29ebe5ee5a MdePkg/IndustryStandard: Add UFS definitions
    89b527df17 CryptoPkg: revert BUFSIZ macro definition from commit 456dd8b99f00
    1a440d9638 Retrieve the USB class specific data from the configuration descriptor
    c7354e9c84 OvmfPkg: Add minimum Python version for CI badge
    4274bcf146 EmulatorPkg: Add minimum Python version for CI badge
    ff003faabe ReadMe.rst: Add minimum Python version badge
    c1eb477e06 OvmfPkg/TdxDxe: Clear GPR Mask for RBX
    3022bab164 OvmfPkg: Remove macro MAX_LOONGARCH_EXCEPTION
    9537f8ce67 UefiCpuPkg: Remove macro MAX_LOONGARCH_EXCEPTION
    3c8e10c8b3 MdePkg: Synchronize UEFI2.11 LoongArch64 DebugSupportLib definition
    03783393e1 MdePkg: Allows loading X64 and ARM64 OPROM images on LoongArch64
    25ce25ecce ArmPkg: DefaultExceptionHandlerLib: Update function input bitwidth
    e8b7d7a238 ArmPkg: ArmExceptionLib: Fixing exception vector and type casting
    b689c387e2 ArmPkg: ArmLib: Update function to match header file
    6539b693d1 MdePkg: ArmLib: Return UINT32 for ArmCacheWritebackGranule
    9d0f3dd35d ArmPkg: ArmArchTimerLib: Update operations to be 64 bit wide
    77d32b1796 ArmPkg: TimerDxe: Use 64bit operation for timer ticks
    957fcbe7a3 ArmPkg: ArmGic: Cast CpuTarget to UINT32 for legacy GIC
    95972f966e DynamicTablesPkg: Correct parser for X64 architecture objects
    cf8241facc MdePkg: Add Google Mock Library for SafeIntLib
    232003ce5a MdePkg: Update StatusCodeDataTypeId.h
    e02c7848af MdeModulePkg SmbiosMeasurementDxe: Release TableAddress after use
    58c7517228 MdeModulePkg DriverHealthManagerDxe: Display HealthStatus as TextTwo
    f8f29a4a6a BaseTools: fix spelling error
    74ac8cc0e8 BaseTools: Typo fixes
    aca75d3c08 BaseTools: Update alignment for entry seg for Clang
    1bb10a479f MdeModulePkg/BrotliCustomDecompressLib: Make the library buildable
    1c5c951ec3 Update CI to VS2022
    bcbb709959 BaseTools: Add VS2022 XIPFLAGS
    f1e014a5ca BaseTools: Add /WHOLEARCHIVE for VS2022 Builds
    4c7c90254f Maintainers.txt: Add VS Code PR Dashboard maintainer
    2941f4b57f PullRequests.github-issues: Add PR notebook
    d55d4e22f4 OvmfPkg: Update PlatformPei.inf with TdxHelperLib
    1f55e175f4 OvmfPkg: Update OvmfPkgX64.dsc to support TdTcg2Pei
    9f9657e7da OvmfPkg: Update OvmfTpmLibs.dsc.inc to add PeiTpmMeasurementLib.inf
    7689c0d9fa OvmfPkg/TdTcg2Pei: Add TdTcg2Pei to install gEdkiiCcPpi
    bdf3c917e3 OvmfPkg/TdTcg2Dxe: Update with TdxHelperLib
    b6b1fdb073 OvmfPkg/TdxHelperLib: Refactor for new APIs
    cc0ec8ebae OvmfPkgX64: Add BaseCryptLib definition in PEIM
    b2df9a89ba SecurityPkg/PeiTpmMeasurementLib: Support CC Measurement
    3b07a2fb52 SecurityPkg/Ppi: Add gEdkiiCcPpi for CC Measurement in PEI phase
    481c43308b MdePkg: Add new PCDs for IPMI Serial
    5b760ca087 MdePkg/IndustryStandard: Add definitions for IPMI Serial
    e53cf2412a ShellPkg/UefiShellLevel2CommandsLib: Add helper for reset -fwui option
    694cc9f100 UefiPayloadPkg: Update ReadUnaligned64 in ACPI parsing
    ddb4ea681b UefiPayloadPkg: Update FDT parser logic for unaligned data access
    2d6d03056a UefiPayloadPkg: Add AARCH64 support on FdtParserLib
    f0424ec80e OvmfPkg: disable iscsi by default
    645988d9b3 OvmfPkg: add PcdEntryPointOverrideDefaultValue
    9ca29831f6 OvmfPkg: add fw_cfg option for usb storage
    f9335bcb7c OvmfPkg: add fw_cfg option for iscsi support
    b9cb18206a OvmfPkg: add fw_cfg option for virtio-net support
    5be587067a OvmfPkg: move USB drivers to new UsbComponents.dsc.inc
    b3b3cfab7e OvmfPkg: move VirtioNet to NetworkComponents.dsc.inc
    35706d43c5 NetworkPkg: PXE boot option build flag
    087a47688c OvmfPkg: PXE boot option build flag
    9e0c46efb0 ArmVirtPkg: PXE boot option build flag
    f6422011e5 MdeModulePkg/PlatformDriOverrideDxe: fix HiiOpCodeHandle leak
    1b283cf437 MdeModulePkg/UiApp: fix HiiOpCodeHandle leak
    e8cfc7beba NetworkPkg/IScsiDxe: fix HiiOpCodeHandle leak
    b1cdfc556f SecurityPkg/OpalPassword: fix HiiOpCodeHandle leak on error path
    fd9501f582 DxeRngLib: GetRandomNumber spurious success
    bbcdc0b7d9 MdePkg: Improve comments on DebugLib PCDs
    5b2d55533b BaseTools: Improve error messages from UefiCapsuleHeader.py
    e508c6c08a MdeModulePkg/DxeIplPeim: Free scratch buffer after FV extraction
    73570d8ab6 openssl: disable visual studio warning #4189
    99e18f2327 CryptoPkg: CI: update OpensslGen file list
    8c5dcecd24 CryptoPkg: gcc needs 4k section alignment too
    9895fe25ac CryptoPkg/BaseCryptLib: add next parameter to SHA3_squeeze
    a801363249 CryptoPkg: add openssl/providers/fips/include to includes
    005f4c6b5e openssl: add more stubs for openssl 3.2.x
    53cea8efd1 openssl: adapt stubs to openssl 3.2.x
    8f6c2ccc45 openssl: update generated files
    e584e865f8 openssl: update submodule to 3.4.0
    333e9638ad MdeModulePkg/Bus/Pci: Fix Descriptor Misalignment in USB Config Handling
    e8668d2dee MdeModulePkg/DxeCore: Call BeforeExitBootServices event group only once
    47e28a6d44 ArmVirtPkg/ArmPlatformLibQemu: Enable early ID map on EL2+VHE
    793f4d2662 Maintainers.txt: Add a new R for LoongArch64
    47ef197873 BaseTools: Coverage: Detect lcov version
    2940708eb2 NetworkPkg/DxeNetLib: drop GLOBAL_REMOVE_IF_UNREFERENCED
    d31fd8bcb7 MdePkg/DxeRngLib: drop GLOBAL_REMOVE_IF_UNREFERENCED
    061bccff3a DynamicTablesPkg: Update link to iASL in Readme.md
    210a76e917 Remove Ray from maintainer list of FatPkg
    775d6cd7ed OvmfPkg/QemuFwCfgDxeLib: use PcdConfidentialComputingGuestAttr
    194cdc1700 SecurityPkg: remove unused `EfiSig` variable in SecureBootFetchData
    dfab971e91 SecurityPkg: Improve formatting of msg when GetVariable fails
    61c714285f BaseTools: Coverage: make lcov v2.0 work
    29859cbc28 CI: Use latest Fedora 40 image for Linux jobs
    0f9dbb4abf Maintainers.txt: Add myself as FatPkg Maintainer
    745cab5aad DynamicTablesPkg: Fix BDF format for PCI initiators
    bff50932c1 OvmfPkg: Update links to Intel & MS ACPI compilers in README
    da1084ccf4 MdePkg/Include/IndustryStandard: Address C++ keyword collisions
    e6a886fdfc SecurityPkg/Library/TpmCommandLib: Change xor to xor_
    05ac9a58f5 MdePkg/Include/IndustryStandard: Add operator_ and xor_ field names
    1e079360cd PrmPkg: Update link to ACPICA in Readme.md
    9112fb0ecc MdeModulePkg/HiiDatabase: Return default value for BIT VarStore as UNIT32
    9a9bcacbe0 UefiCpuPkg/CpuMmuLib: Adjust default memory attributes on LoongArch
    9098efdf0d EmulatorPkg: BlockIo2 APIs do not signal event
    5158b598f7 DynamicTablesPkg: Adds X64 support for CPU SSDT generator
    e89ff68110 DynamicTablesPkg: Add X64 MADT table generator
    24d835a131 OvmfPkg/Library/HardwareInfoLib: Fix memory allocation for a root bridge
    4928851899 ArmVirtPkg: Report an error if NETWORK_TLS_ENABLE is TRUE on ARM
    3781ad107d OvmfPkg/QemuVideoDxe: Clean up Non-Used PCDs
    9c4542a064 OvmfPkg: Rerun dispatcher after initializing virtio-rng
    3ee2ceb6fa FatPkg/EnhancedFatDxe: Add comments around StrSize() checks
    bf32c2d61f ArmPkg/SemihostFs: StrSize() cannot return 0
    d90bf1f973 EmbeddedPkg: reduce "Found ACPI table" messages from ERROR to INFO
    b78b4da1fb ArmPlatformPkg: Allow up to 5 Secure Boot DB certs
    ae8ab7190c ArmVirtPkg/ArmVirtKvmTool: Use PSCI/SMCCC conduit from FDT
    f9f4164af9 ArmVirtPkg: Rename ArmVirtQemuMonitorLib to ArmVirtMonitorLib
    91171b6b94 ArmVirtPkg/PrePi: Don't clear HCR_EL2 fields when setting TGE
    f60a839480 ArmPkg/ArmMmuLib: Add support for EL2&0 translation regime
    e80b17d21a ArmPkg/ArmMmuLib: Ignore EL3 in RELEASE code
    31ff325228 ArmPkg/ArmLib: Use VHE alternatives for timer system registers
    c2827283a8 MdePkg/AArch64: Add some missing MMU related constants
    a25eb7557f SignedCapsulePkg: Drop ARM support
    6f0e977165 Drop git submodule for Berkeley softfloat library
    31ea376b58 ArmPkg: Remove ArmSoftFloatLib implementation
    e54794bcc6 Remove all ArmSoftFloatLib library class resolutions
    98f4d35aae RedfishPkg: Drop ARM support
    f73f7b2318 CryptoPkg/OpensslLib: Drop dependency on ArmSoftFloatLib
    a4c50dd3e8 .github: Handle deleted GitHub accounts
    7eff71fe69 SecurityPkg: Update libspdm
    c15bd99342 SecurityPkg/Tcg2Config: Set TPM2.0 for default of Attempt TPM Device
    468b3d9589 UefiCpuPkg/PiSmmCpuDxeSmm:Check resource HOB range before mapping
    065df32de3 CryptoPkg: Apply gettimeofday() solution to BaseCryptLibMbedTls
    8c8e05db24 OvmfPkg/PlatformInitLib: enable x2apic mode if needed
    800205678f ShellPkg: Fix check on OldArgv in UpdateArgcArgv()
    6142f0a8a5 OvmfPkg/EmuVariableFvbRuntimeDxe: Issue NV vars initializitation message
    d502cc7702 OvmfPkg/PlatformInitLib: Retry NV vars FV check as shared
    52fa7e78d2 OvmfPkg/PlatformPei: Move NV vars init to after SEV-SNP memory acceptance
    f0d2bc3ab2 OvmfPkg/QemuFlashFvbServicesRuntimeDxe: Do not use flash with SEV-SNP
    a6f1433e95 DynamicTablesPkg/ArmGicCParser: Parse VGIC interrupt for all CPUs
    0d129450c2 NetworkPkg: Restore TPL Before Return
    f3bc6013d2 MdeModulePkg HobPrintLib: Add Guid to Guids section.
    edb312d5d0 MdePkg/BaseRngLib: Remove global variable for RDRAND state update
    4d3cf37ff0 MdePkg/SmmPciExpressLib: Ensure gBS variable for the constructor
  - Remove berkeley-softfloat-3-b64af41c3276f.tar.xz because of commit "31ea376b58 ArmPkg: Remove ArmSoftFloatLib implementation"
  - Remove ovmf-Revert-Add-Stack-Cookie-Support-to-MSVC-and-GCC.patch (modified as ovmf-Remove-unsupported-GCC-flag-mstack-protector-guard.patch to minimize impact)
  - Add ovmf-Remove-unsupported-GCC-flag-mstack-protector-guard.patch
  - Add ovmf-Increase-FVMAIN-Size-for-Compatibility-with-2MB-Size.patch
  - Update openssl library to 3.4

------------------------------------------------------------------
------------------  2025-3-4  -  Mar 4 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Make integration tests to build outside of OBS
    Update and extend all integration tests such that they also
    build outside of the Open Build Service. Along with the changes
    on the descriptions a simple build-tests.sh script was added
    to drive the build process. The build is based on the kiwi
    boxbuild plugin in container mode to build the tests
    from a given build-tests directory. A new chapter to document
    how to Build the Build Tests is also provided and referenced
    on the github main page.

++++ kernel-default:

  - config: Set gcc version (jsc#PED-12251).
  - packaging: Turn gcc version into config.sh variable
    Fixes: 51dacec21eb1 ("Use gcc-13 for build on SLE16 (jsc#PED-10028).")
  - commit 2bf5321
  - powerpc: Document details on H_HTM hcall (jsc#PED-10944).
  - powerpc/pseries: Export hardware trace macro dump via debugfs
    (jsc#PED-10944).
  - Update config files.
  - powerpc/pseries: Macros and wrapper functions for H_HTM call
    (jsc#PED-10944).
  - commit 5460fb0
  - rpm/config.sh: Update Bugzillla product
    There is now proper product for SLE16 which is the preferred target for
    automated bug reports.
  - commit 1b3f821
  - btrfs: check folio mapping after unlock in relocate_one_folio() (CVE-2024-56758 bsc#1235621)
  - commit ba0cfe2
  - arm64: hugetlb: Fix flush_hugetlb_tlb_range() invalidation level (git-fixes)
  - commit 8f89035
  - arm64: hugetlb: Fix huge_ptep_get_and_clear() for non-present ptes (git-fixes)
  - commit f4826cb
  - mm: hugetlb: Add huge page size param to huge_ptep_get_and_clear() (git-fixes)
  - commit 1fac258
  - arm64/mm: Fix Boot panic on Ampere Altra (git-fixes)
  - commit a6faf3e
  - arm64: dts: rockchip: adjust SMMU interrupt type on rk3588 (git-fixes)
  - commit 638ed0e
  - arm64: dts: rockchip: Fix lcdpwr_en pin for Cool Pi GenBook (git-fixes)
  - commit dcbc592
  - USB: serial: option: fix Telit Cinterion FN990A name
    (git-fixes).
  - commit c850a7b
  - USB: serial: option: add Telit Cinterion FN990B compositions
    (git-fixes).
  - commit 1f5ca02
  - USB: serial: option: drop MeiG Smart defines (git-fixes).
  - commit f6098ca
  - USB: serial: option: add MeiG Smart SLM828 (git-fixes).
  - commit e39974a
  - USB: quirks: add USB_QUIRK_NO_LPM quirk for Teclast dist
    (git-fixes).
  - commit c8ad9c4
  - USB: Add USB_QUIRK_NO_LPM quirk for sony xperia xz1 smartphone
    (git-fixes).
  - commit 1cd3bfd
  - usb: typec: tcpm: PSSourceOffTimer timeout in PR_Swap enters
    ERROR_RECOVERY (git-fixes).
  - commit d3d2cdf
  - RDMA/mana_ib: Allocate PAGE aligned doorbell index (git-fixes).
  - KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC
    isn't in-kernel (git-fixes).
  - commit ac8f9f3
  - arm64: dts: rockchip: Fix broken tsadc pinctrl names for rk3588 (git-fixes)
  - commit 730f333
  - rpm/kernel-docs.spec.in: Workaround for reproducible builds (bsc#1238303)
  - commit 1f1e842
  - Refresh patches.suse/0001-idpf-extend-tx-watchdog-timeout.patch.
  - Refresh
    patches.suse/s390-Fix-mlx5-RoCE-throuput-degradtion.patch.
    Re-enabled needed patches.
  - commit 553c7bc
  - ila: serialize calls to nf_register_net_hooks() (CVE-2024-57900
    bsc#1235973).
  - commit 4159884
  - net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets
    (CVE-2025-21629 bsc#1235968).
  - commit f3eb8e0

++++ kernel-rt:

  - config: Set gcc version (jsc#PED-12251).
  - packaging: Turn gcc version into config.sh variable
    Fixes: 51dacec21eb1 ("Use gcc-13 for build on SLE16 (jsc#PED-10028).")
  - commit 2bf5321
  - powerpc: Document details on H_HTM hcall (jsc#PED-10944).
  - powerpc/pseries: Export hardware trace macro dump via debugfs
    (jsc#PED-10944).
  - Update config files.
  - powerpc/pseries: Macros and wrapper functions for H_HTM call
    (jsc#PED-10944).
  - commit 5460fb0
  - rpm/config.sh: Update Bugzillla product
    There is now proper product for SLE16 which is the preferred target for
    automated bug reports.
  - commit 1b3f821
  - btrfs: check folio mapping after unlock in relocate_one_folio() (CVE-2024-56758 bsc#1235621)
  - commit ba0cfe2
  - arm64: hugetlb: Fix flush_hugetlb_tlb_range() invalidation level (git-fixes)
  - commit 8f89035
  - arm64: hugetlb: Fix huge_ptep_get_and_clear() for non-present ptes (git-fixes)
  - commit f4826cb
  - mm: hugetlb: Add huge page size param to huge_ptep_get_and_clear() (git-fixes)
  - commit 1fac258
  - arm64/mm: Fix Boot panic on Ampere Altra (git-fixes)
  - commit a6faf3e
  - arm64: dts: rockchip: adjust SMMU interrupt type on rk3588 (git-fixes)
  - commit 638ed0e
  - arm64: dts: rockchip: Fix lcdpwr_en pin for Cool Pi GenBook (git-fixes)
  - commit dcbc592
  - USB: serial: option: fix Telit Cinterion FN990A name
    (git-fixes).
  - commit c850a7b
  - USB: serial: option: add Telit Cinterion FN990B compositions
    (git-fixes).
  - commit 1f5ca02
  - USB: serial: option: drop MeiG Smart defines (git-fixes).
  - commit f6098ca
  - USB: serial: option: add MeiG Smart SLM828 (git-fixes).
  - commit e39974a
  - USB: quirks: add USB_QUIRK_NO_LPM quirk for Teclast dist
    (git-fixes).
  - commit c8ad9c4
  - USB: Add USB_QUIRK_NO_LPM quirk for sony xperia xz1 smartphone
    (git-fixes).
  - commit 1cd3bfd
  - usb: typec: tcpm: PSSourceOffTimer timeout in PR_Swap enters
    ERROR_RECOVERY (git-fixes).
  - commit d3d2cdf
  - RDMA/mana_ib: Allocate PAGE aligned doorbell index (git-fixes).
  - KVM: x86: Reject Hyper-V's SEND_IPI hypercalls if local APIC
    isn't in-kernel (git-fixes).
  - commit ac8f9f3
  - arm64: dts: rockchip: Fix broken tsadc pinctrl names for rk3588 (git-fixes)
  - commit 730f333
  - rpm/kernel-docs.spec.in: Workaround for reproducible builds (bsc#1238303)
  - commit 1f1e842
  - Refresh patches.suse/0001-idpf-extend-tx-watchdog-timeout.patch.
  - Refresh
    patches.suse/s390-Fix-mlx5-RoCE-throuput-degradtion.patch.
    Re-enabled needed patches.
  - commit 553c7bc
  - ila: serialize calls to nf_register_net_hooks() (CVE-2024-57900
    bsc#1235973).
  - commit 4159884
  - net: reenable NETIF_F_IPV6_CSUM offload for BIG TCP packets
    (CVE-2025-21629 bsc#1235968).
  - commit f3eb8e0

++++ nftables:

  - Add 0001-tools-add-a-systemd-unit-for-static-rulesets.patch
    [boo#1237277]

++++ npth:

  - specfile: update license to LGPL-2.1-or-later

++++ python313-core:

  - Do not build with experimental_jit when primary_python

++++ lsof:

  - Update to version 4.99.4:
    * In lsof manpage: mention /etc/services for -P option
    * Fix typos in docs
    * Linux 6.9 changed the pidfs appearence in procfs. Try to
    maintain original output in lsof (bsc#1224285)
    * closefrom_shim: Add optimized fallback for platforms without
    closefrom or close_range
    * fix build against -std=c23 (`void (*)()`) changed the meaning)
  - Drop obsolete lsof-4.99.3-fix-version-in-configure-ac.patch,
    0001-tests-eliminate-use-of-fgrep.patch and
    0002-linux-Maintain-original-output-for-pidfd-in-linux-6..patch.

++++ mdadm:

  - cleanup 1005-mdadm-enable-Intel-Alderlake-RSTe-configuration.patch
    (remove a redundant macro definition)

++++ nvidia-open-driver-G06-signed:

  - update CUDA variant to 570.124.06

++++ python313:

  - Do not build with experimental_jit when primary_python

++++ python-libvirt-python:

  - Update to 11.1.0
  - Add all new APIs and constants in libvirt 11.1.0

------------------------------------------------------------------
------------------  2025-3-3  -  Mar 3 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add rd.kiwi.oem.luks.reencrypt_randompass
    For OEM LUKS2 encrypted disk images in combination
    with rd.kiwi.oem.luks.reencrypt. Reset insecure built time
    passphrase with a random onetime passphrase
  - Bump version: 10.2.12 → 10.2.13

++++ grub2:

  - Cherry-pick upstream XFS fixes
    * 0001-fs-xfs-Add-new-superblock-features-added-in-Linux-6..patch
    * 0002-fs-xfs-Fix-grub_xfs_iterate_dir-return-value-in-case.patch
  - Fix "attempt to read of write outside of partition" error message (bsc#1237844)
    * 0003-fs-xfs-fix-large-extent-counters-incompat-feature-su.patch

++++ kernel-default:

  - tracing: Do not allow mmap() of persistent ring buffer
    (git-fixes bsc#1237898 CVE-2025-21778).
  - commit 7bd7207
  - Delete
    patches.suse/staging-qlge-devlink-use-retained-error-fmsg-API.patch.
    Dropped patch for no longer present driver.
  - commit d78cf53
  - bpf: Send signals asynchronously if !preemptible (git-fixes
    bsc#1237879 CVE-2025-21728).
  - commit bf6a524
  - scsi: lpfc: Copyright updates for 14.4.0.8 patches
    (bsc#1238349).
  - scsi: lpfc: Update lpfc version to 14.4.0.8 (bsc#1238349).
  - scsi: lpfc: Handle duplicate D_IDs in ndlp search-by D_ID
    routine (bsc#1238349).
  - scsi: lpfc: Ignore ndlp rport mismatch in dev_loss_tmo callbk
    (bsc#1238349).
  - scsi: lpfc: Free phba irq in lpfc_sli4_enable_msi() when
    pci_irq_vector() fails (bsc#1238349).
  - scsi: lpfc: Reduce log message generation during ELS ring
    clean up (bsc#1238349).
  - commit 9c9e63e
  - net: ethtool: Use hwprov under rcu_read_lock (git-fixes).
  - commit 9b0a090
  - idpf: fix checksums set in idpf_rx_rsc() (jsc#PED-10581).
  - net/mlx5: IRQ, Fix null string in debug print (jsc#PED-11331).
  - net/mlx5: Restore missing trace event when enabling vport QoS
    (jsc#PED-11331).
  - net/mlx5: Fix vport QoS cleanup on error (jsc#PED-11331).
  - ixgbe: fix media cage present detection for E610 device
    (jsc#PED-9647).
  - iavf: fix circular lock dependency with netdev_lock
    (jsc#PED-10423).
  - ice: Avoid setting default Rx VSI twice in switchdev setup
    (jsc#PED-10419).
  - ice: Fix deinitializing VF in error path (jsc#PED-10419).
  - net: ethtool: fix ioctl confusing drivers about desired HDS
    user config (git-fixes).
  - RDMA/bnxt_re: Fix the page details for the srq created by
    kernel consumers (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Fix the statistics for Gen P7 VF (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Fix issue in the unload path (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Add sanity checks on rdev validity (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Fix an issue in bnxt_re_async_notifier
    (jsc#PED-10684 jsc#PED-11230).
  - vsock/bpf: Warn on socket without transport (jsc#PED-11028).
  - ibmvnic: Don't reference skb after sending to VIOS
    (jsc#PED_10911 jsc#PED-3606).
  - s390/qeth: move netif_napi_add_tx() and napi_enable() from
    under BH (git-fixes).
  - vsock: Orphan socket after transport release (jsc#PED-11028).
  - igc: Set buffer type for empty frames in igc_init_empty_frame
    (jsc#PED-10417).
  - igc: Fix HW RX timestamp when passed by ZC XDP (jsc#PED-10417).
  - ixgbe: Fix possible skb NULL pointer dereference (jsc#PED-9647).
  - idpf: record rx queue in skb for RSC packets (jsc#PED-10581).
  - idpf: fix handling rsc packet with a single segment
    (jsc#PED-10581).
  - iavf: Fix a locking bug in an error path (jsc#PED-10423).
  - neighbour: use RCU protection in __neigh_notify() (jsc#PED-10684
    jsc#PED-11230).
  - net: ethtool: tsconfig: Fix netlink type of hwtstamp flags
    (git-fixes).
  - net: add dev_net_rcu() helper (jsc#PED-10684 jsc#PED-11230).
  - net: atlantic: fix warning during hot unplug (jsc#PED-11287).
  - ice: stop storing XDP verdict within ice_rx_buf (jsc#PED-10419).
  - ice: gather page_count()'s of each frag right before XDP prog
    call (jsc#PED-10419).
  - ice: put Rx buffers after being done with current frame
    (jsc#PED-10419).
  - tg3: Disable tg3 PCIe AER on system reboot (jsc#PED-3526
    jsc#PED-11226).
  - vmxnet3: Fix tx queue race condition with XDP (jsc#PED-11024).
  - ice: Add check for devm_kzalloc() (jsc#PED-10419).
  - vsock: Allow retrying on connect() failure (jsc#PED-11028).
  - iavf: allow changing VLAN state without calling PF
    (jsc#PED-10423).
  - ice: remove invalid parameter of equalizer (jsc#PED-10419).
  - ice: fix ice_parser_rt::bst_key array size (jsc#PED-10419).
  - idpf: add more info during virtchnl transaction timeout/salt
    mismatch (jsc#PED-10581).
  - idpf: convert workqueues to unbound (jsc#PED-10581).
  - idpf: Acquire the lock before accessing the xn->salt
    (jsc#PED-10581).
  - idpf: fix transaction timeouts on reset (jsc#PED-10581).
  - idpf: add read memory barrier when checking descriptor done bit
    (jsc#PED-10581).
  - net: page_pool: don't try to stash the napi id (jsc#PED-10423).
  - netdevsim: don't assume core pre-populates HDS params on GET
    (jsc#PED-10684 jsc#PED-11230).
  - wifi: mt76: move napi_enable() from under BH (git-fixes).
  - eth: via-rhine: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: niu: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: 8139too: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: forcedeth: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: forcedeth: remove local wrappers for napi enable/disable
    (git-fixes).
  - eth: tg3: fix calling napi_enable() in atomic context
    (jsc#PED-3526 jsc#PED-11226).
  - net/mlx5e: add missing cpu_to_node to kvzalloc_node in
    mlx5e_open_xdpredirect_sq (jsc#PED-11331).
  - net: mvneta: fix locking in mvneta_cpu_online() (git-fixes).
  - octeontx2: don't mess with ->d_parent or ->d_parent->d_name
    (jsc#PED-11317).
  - sysfs: constify bin_attribute argument of
    sysfs_bin_attr_simple_read() (jsc#PED-10421 jsc#PED-8564).
  - sysfs: constify macro BIN_ATTRIBUTE_GROUPS() (jsc#PED-10421
    jsc#PED-8564).
  - VMCI: remove unused ioctl definitions (jsc#PED-11026).
  - RDMA/hfi1: Constify 'struct bin_attribute' (jsc#PED-10421
    jsc#PED-8564).
  - RDMA/bnxt_re: Allocate dev_attr information dynamically
    (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Pass the context for ulp_irq_stop (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Add support to handle DCB_CONFIG_CHANGE event
    (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Query firmware defaults of CC params during probe
    (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Add Async event handling support (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Add ULP call to notify async events (jsc#PED-10684
    jsc#PED-11230).
  - net: avoid race between device unregistration and ethnl ops
    (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: update header sizing defaults (jsc#PED-10684
    jsc#PED-11230).
  - eth: bnxt: allocate enough buffer space to meet HDS threshold
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: populate the default HDS params in the core
    (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: apply hds_thrs settings correctly (jsc#PED-10684
    jsc#PED-11230).
  - net: provide pending ring configuration in net_device
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: store netdev in a temp variable in
    ethnl_default_set_doit() (jsc#PED-10684 jsc#PED-11230).
  - net: move HDS config from ethtool state (jsc#PED-10684
    jsc#PED-11230).
  - net: destroy dev->lock later in free_netdev() (git-fixes).
  - eth: bnxt: fix string truncation warning in FW version
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: ts: add separate counter for unconfirmed one-step
    TX timestamps (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: fix unintentional sign extension on shift of
    dest_attr->vport.vhca_id (jsc#PED-11331).
  - ice: support FW Recovery Mode (jsc#PED-10419).
  - devlink: add devl guard (jsc#PED-10419).
  - pldmfw: enable selected component update (jsc#PED-10419).
  - net/mlx5e: CT: Offload connections with hardware steering rules
    (jsc#PED-11331).
  - net/mlx5e: CT: Make mlx5_ct_fs_smfs_ct_validate_flow_rule
    reusable (jsc#PED-11331).
  - net/mlx5e: CT: Add initial support for Hardware Steering
    (jsc#PED-11331).
  - net/mlx5: HWS, rework the check if matcher size can be increased
    (jsc#PED-11331).
  - net: protect napi->irq with netdev_lock() (jsc#PED-3526
    jsc#PED-11226).
  - net: protect NAPI enablement with netdev_lock() (jsc#PED-10423).
  - net: protect netdev->napi_list with netdev_lock()
    (jsc#PED-10423).
  - net: add netdev->up protected by netdev_lock() (jsc#PED-10423).
  - net: make netdev_lock() protect netdev->reg_state
    (jsc#PED-10423).
  - net: add netdev_lock() / netdev_unlock() helpers
    (jsc#PED-10423).
  - ice: Add in/out PTP pin delays (jsc#PED-10419).
  - ice: implement low latency PHY timer updates (jsc#PED-10419).
  - ice: check low latency PHY timer update firmware capability
    (jsc#PED-10419).
  - ice: add lock to protect low latency interface (jsc#PED-10419).
  - ice: rename TS_LL_READ* macros to REG_LL_PROXY_H_*
    (jsc#PED-10419).
  - ice: use read_poll_timeout_atomic in ice_read_phy_tstamp_ll_e810
    (jsc#PED-10419).
  - ice: use string choice helpers (jsc#PED-10419).
  - ice: add fw and port health reporters (jsc#PED-10419).
  - ice: add recipe priority check in search (jsc#PED-10419).
  - ice: ice_probe: init ice_adapter after HW init (jsc#PED-10419).
  - ice: minor: rename goto labels from err to unroll
    (jsc#PED-10419).
  - ice: split ice_init_hw() out from ice_init_dev()
    (jsc#PED-10419).
  - ice: c827: move wait for FW to ice_init_hw() (jsc#PED-10419).
  - netdevsim: add HDS feature (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: add support for hds-thresh ethtool command
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: add support for tcp-data-split ethtool command
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: add support for rx-copybreak ethtool command
    (jsc#PED-10684 jsc#PED-11230).
  - net: disallow setup single buffer XDP when tcp-data-split is
    enabled (jsc#PED-10684 jsc#PED-11230).
  - net: devmem: add ring parameter filtering (jsc#PED-10684
    jsc#PED-11230).
  - net: ethtool: add support for configuring hds-thresh
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: add hds_config member in ethtool_netdev_state
    (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: Add nic_cap_reg and vhca_icm_ctrl registers
    (jsc#PED-11331).
  - net/mlx5: SHAMPO: Introduce new SHAMPO specific HCA caps
    (jsc#PED-11331).
  - net/mlx5: Add support for MRTCQ register (jsc#PED-11331).
  - net/mlx5: Update mlx5_ifc to support FEC for 200G per lane
    link modes (jsc#PED-11331).
  - net: ethtool: add support for structured PHY statistics
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: plumb PHY stats to PHY drivers (jsc#PED-10684
    jsc#PED-11230).
  - ethtool: linkstate: migrate linkstate functions to support
    multi-PHY setups (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: HWS, update flow - support through bigger action RTC
    (jsc#PED-11331).
  - net/mlx5: HWS, update flow - remove the use of dual RTCs
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS to steering mode options (jsc#PED-11331).
  - net/mlx5: fs, add HWS get capabilities (jsc#PED-11331).
  - net/mlx5: fs, set create match definer to not supported by HWS
    (jsc#PED-11331).
  - net/mlx5: fs, add support for dest vport HWS action
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS fte API functions (jsc#PED-11331).
  - net/mlx5: fs, add dest table cache (jsc#PED-11331).
  - net/mlx5: fs, manage flow counters HWS action sharing by
    refcount (jsc#PED-11331).
  - net/mlx5: fs, add HWS modify header API function
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS packet reformat API function
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS actions pool (jsc#PED-11331).
  - net/mlx5: fs, add HWS flow group API functions (jsc#PED-11331).
  - net/mlx5: fs, add HWS flow table API functions (jsc#PED-11331).
  - net/mlx5: fs, add HWS root namespace functions (jsc#PED-11331).
  - eth: iavf: extend the netdev_lock usage (jsc#PED-10423).
  - net/mlx5e: Update TX ESN context for IPSec hardware offload
    (jsc#PED-11331).
  - xfrm: Support ESN context update to hardware for TX
    (jsc#PED-11331).
  - net/mlx5: use do_aux_work for PHC overflow checks
    (jsc#PED-11331).
  - igc: Link queues to NAPI instances (jsc#PED-10417).
  - igc: Link IRQs to NAPI instances (jsc#PED-10417).
  - i40e: add ability to reset VF for Tx and Rx MDD events
    (jsc#PED-10428).
  - ixgbevf: Fix passing 0 to ERR_PTR in ixgbevf_run_xdp()
    (jsc#PED-9647).
  - ixgbe: Fix passing 0 to ERR_PTR in ixgbe_run_xdp()
    (jsc#PED-9647).
  - igb: Fix passing 0 to ERR_PTR in igb_run_xdp() (jsc#PED-10426).
  - igc: Fix passing 0 to ERR_PTR in igc_xdp_run_prog()
    (jsc#PED-10417).
  - igc: Allow hot-swapping XDP program (jsc#PED-10417).
  - igb: Add AF_XDP zero-copy Tx support (jsc#PED-10426).
  - igb: Add AF_XDP zero-copy Rx support (jsc#PED-10426).
  - igb: Add XDP finalize and stats update functions
    (jsc#PED-10426).
  - igb: Introduce XSK data structures and helpers (jsc#PED-10426).
  - igb: Introduce igb_xdp_is_enabled() (jsc#PED-10426).
  - igb: Remove static qualifiers (jsc#PED-10426).
  - ixgbevf: Remove unused ixgbevf_hv_mbx_ops (jsc#PED-9647).
  - octeontx2-pf: mcs: Remove dead code and semi-colon from
    rsrc_name() (jsc#PED-11317).
  - net/mlx5: HWS, set timeout on polling for completion
    (jsc#PED-11331).
  - net/mlx5: HWS, support flow sampler destination (jsc#PED-11331).
  - net/mlx5: HWS, use the right size when writing arg data
    (jsc#PED-11331).
  - net/mlx5: HWS, handle returned error value in pool alloc
    (jsc#PED-11331).
  - net/mlx5: HWS, fix definer's HWS_SET32 macro for negative offset
    (jsc#PED-11331).
  - net/mlx5: HWS, separate SQ that HWS uses from the usual traffic
    SQs (jsc#PED-11331).
  - net/mlx5: HWS, num_of_rules counter on matcher should be atomic
    (jsc#PED-11331).
  - net/mlx5: HWS, reduce memory consumption of a matcher struct
    (jsc#PED-11331).
  - net/mlx5: HWS, remove wrong deletion of the miss table list
    (jsc#PED-11331).
  - net/mlx5: HWS, change error flow on matcher disconnect
    (jsc#PED-11331).
  - net/mlx5: HWS, add error message on failure to move rules
    (jsc#PED-11331).
  - net/mlx5: HWS, simplify allocations as we support only FDB
    (jsc#PED-11331).
  - net/mlx5: HWS, denote how refcounts are protected
    (jsc#PED-11331).
  - net/mlx5: HWS, remove implementation of unused FW commands
    (jsc#PED-11331).
  - net/mlx5: HWS, remove the use of duplicated structs
    (jsc#PED-11331).
  - igc: Remove unused igc_read/write_pcie_cap_reg (jsc#PED-10417).
  - igc: Remove unused igc_read/write_pci_cfg wrappers
    (jsc#PED-10417).
  - igc: Remove unused igc_acquire/release_nvm (jsc#PED-10417).
  - i40e: Remove unused i40e_dcb_hw_get_num_tc (jsc#PED-10428).
  - i40e: Remove unused i40e_asq_send_command_v2 (jsc#PED-10428).
  - i40e: Remove unused i40e_commit_partition_bw_setting
    (jsc#PED-10428).
  - i40e: Remove unused i40e_del_filter (jsc#PED-10428).
  - i40e: Remove unused i40e_get_cur_guaranteed_fd_count
    (jsc#PED-10428).
  - i40e: Deadcode profile code (jsc#PED-10428).
  - i40e: Remove unused i40e_(read|write)_phy_register
    (jsc#PED-10428).
  - i40e: Remove unused i40e_blink_phy_link_led (jsc#PED-10428).
  - i40e: Deadcode i40e_aq_* (jsc#PED-10428).
  - devlink: Improve the port attributes description
    (jsc#PED-10419).
  - ixgbevf: Add support for Intel(R) E610 device (jsc#PED-9647).
  - PCI: Add PCI_VDEVICE_SUB helper macro (jsc#PED-9647).
  - ixgbe: Enable link management in E610 device (jsc#PED-9647).
  - ixgbe: Clean up the E610 link management related code
    (jsc#PED-9647).
  - ixgbe: Add ixgbe_x540 multiple header inclusion protection
    (jsc#PED-9647).
  - ixgbe: Add support for EEPROM dump in E610 device
    (jsc#PED-9647).
  - ixgbe: Add support for NVM handling in E610 device
    (jsc#PED-9647).
  - ixgbe: Add link management support for E610 device
    (jsc#PED-9647).
  - ixgbe: Add support for E610 device capabilities detection
    (jsc#PED-9647).
  - ixgbe: Add support for E610 FW Admin Command Interface
    (jsc#PED-9647).
  - net: ethtool: Fix suspicious rcu_dereference usage (git-fixes).
  - net/mlx5: fs, Add support for RDMA RX steering over IB link
    layer (jsc#PED-11331).
  - net/mlx5: Remove PTM support log message (jsc#PED-11331).
  - net/mlx5: DR, add support for ConnectX-8 steering
    (jsc#PED-11331).
  - net/mlx5: DR, expand SWS STE callbacks and consolidate common
    structs (jsc#PED-11331).
  - net/mlx5: HWS, do not initialize native API queues
    (jsc#PED-11331).
  - net/mlx5: HWS, no need to expose mlx5hws_send_queues_open/close
    (jsc#PED-11331).
  - net/mlx5: fs, retry insertion to hash table on EBUSY
    (jsc#PED-11331).
  - net/mlx5: fs, add mlx5_fs_pool API (jsc#PED-11331).
  - net/mlx5: fs, add counter object to flow destination
    (jsc#PED-11331).
  - net/mlx5: LAG, Support LAG over Multi-Host NICs (jsc#PED-11331).
  - net/mlx5: LAG, Refactor lag logic (jsc#PED-11331).
  - sfc: Use netdev refcount tracking in struct
    efx_async_filter_insertion (jsc#PED-11366).
  - xsk: add generic XSk &xdp_buff -> skb conversion
    (jsc#PED-10428).
  - xsk: make xsk_buff_add_frag() really add the frag via
    __xdp_buff_add_frag() (jsc#PED-10428).
  - xdp: add generic xdp_build_skb_from_buff() (jsc#PED-10428).
  - xdp: add generic xdp_buff_add_frag() (jsc#PED-10428).
  - page_pool: add page_pool_dev_alloc_netmem() (jsc#PED-10428).
  - sfc: remove efx_writed_page_locked (jsc#PED-11366).
  - bnxt_en: Skip reading PXP registers during ethtool -d if
    unsupported (bsc#1238145).
  - bnxt_en: Skip MAC loopback selftest if it is unsupported by FW
    (bsc#1238145).
  - bnxt_en: Skip PHY loopback ethtool selftest if unsupported by FW
    (bsc#1238145).
  - bnxt_en: Do not allow ethtool -m on an untrusted VF
    (bsc#1238145).
  - bnxt_en: Use FW defined resource limits for RoCE (bsc#1238145).
  - ice: Add MDD logging via devlink health (jsc#PED-10419).
  - ice: add Tx hang devlink health reporter (jsc#PED-10419).
  - ice: rename devlink_port. to port.[ch] (jsc#PED-10419).
  - devlink: add devlink_fmsg_dump_skb() function (jsc#PED-10419).
  - devlink: add devlink_fmsg_put() macro (jsc#PED-10419).
  - net/mlx5e: Report rx_discards_phy via rx_dropped
    (jsc#PED-11331).
  - net: page_pool: rename page_pool_is_last_ref() (jsc#PED-10428).
  - net/mlx5: Add device cap abs_native_port_num (jsc#PED-11331).
  - net/mlx5: qos: Add ifc support for cross-esw scheduling
    (jsc#PED-11331).
  - net/mlx5: Add support for new scheduling elements
    (jsc#PED-11331).
  - net/mlx5: Add ConnectX-8 device to ifc (jsc#PED-11331).
  - net/mlx5: ifc: Reorganize mlx5_ifc_flow_table_context_bits
    (jsc#PED-11331).
  - net: ethtool: Add support for tsconfig command to get/set
    hwtstamp config (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp
    by net topology (jsc#PED-10684 jsc#PED-11230).
  - net: Add the possibility to support a selected hwtstamp in
    netdevice (jsc#PED-10684 jsc#PED-11230).
  - net: Make net_hwtstamp_validate accessible (jsc#PED-10684
    jsc#PED-11230).
  - net: Make dev_get_hwtstamp_phylib accessible (jsc#PED-10684
    jsc#PED-11230).
  - octeontx2-af: fix build regression without CONFIG_DCB
    (jsc#PED-11317).
  - ionic: remove the unused nb_work (jsc#PED-11378).
  - page_pool: disable sync for cpu for dmabuf memory provider
    (jsc#PED-10428).
  - page_pool: Set `dma_sync` to false for devmem memory provider
    (jsc#PED-10428).
  - net: page_pool: create page_pool_alloc_netmem (jsc#PED-10428).
  - net: page_pool: rename page_pool_alloc_netmem to *_netmems
    (jsc#PED-10423).
  - xdp: make __xdp_return() MP-agnostic (jsc#PED-10428).
  - xdp: get rid of xdp_frame::mem.id (jsc#PED-10428).
  - page_pool: allow mixing PPs within one bulk (jsc#PED-10428).
  - ionic: add support for QSFP_PLUS_CMIS (jsc#PED-11378).
  - ionic: add speed defines for 200G and 400G (jsc#PED-11378).
  - ionic: Translate IONIC_RC_ENOSUPP to EOPNOTSUPP (jsc#PED-11378).
  - ionic: Use VLAN_ETH_HLEN when possible (jsc#PED-11378).
  - ionic: add asic codes to firmware interface file
    (jsc#PED-11378).
  - ice: cleanup Rx queue context programming functions
    (jsc#PED-10419).
  - ice: move prefetch enable to ice_setup_rx_ctx (jsc#PED-10419).
  - ice: reduce size of queue context fields (jsc#PED-10419).
  - ice: use <linux/packing.h> for Tx and Rx queue context data
    (jsc#PED-10419).
  - ice: use structures to keep track of queue context size
    (jsc#PED-10419).
  - ice: remove int_q_state from ice_tlan_ctx (jsc#PED-10419).
  - lib: packing: add pack_fields() and unpack_fields()
    (jsc#PED-10419).
  - lib: packing: demote truncation error in pack() to a warning
    in __pack() (jsc#PED-10419).
  - lib: packing: create __pack() and __unpack() variants without
    error checking (jsc#PED-10419).
  - cn10k-ipsec: Fix compilation error when CONFIG_XFRM_OFFLOAD
    disabled (jsc#PED-11317).
  - cn10k-ipsec: Enable outbound ipsec crypto offload
    (jsc#PED-11317).
  - cn10k-ipsec: Allow ipsec crypto offload for skb with SA
    (jsc#PED-11317).
  - cn10k-ipsec: Process outbound ipsec crypto offload
    (jsc#PED-11317).
  - cn10k-ipsec: Add SA add/del support for outb ipsec crypto
    offload (jsc#PED-11317).
  - cn10k-ipsec: Init hardware for outbound ipsec crypto offload
    (jsc#PED-11317).
  - octeontx2-af: Disable backpressure between CPT and NIX
    (jsc#PED-11317).
  - octeontx2-pf: Move skb fragment map/unmap to common code
    (jsc#PED-11317).
  - octeontx2-pf: map skb data as device writeable (jsc#PED-11317).
  - page_pool: make page_pool_put_page_bulk() handle array of
    netmems (jsc#PED-10428).
  - netmem: add a couple of page helper wrappers (jsc#PED-10428).
  - xdp: register system page pool as an XDP memory model
    (jsc#PED-10428).
  - xsk: allow attaching XSk pool via xdp_rxq_info_reg_mem_model()
    (jsc#PED-10428).
  - xdp: allow attaching already registered memory model to
    xdp_rxq_info (jsc#PED-10428).
  - xdp, xsk: constify read-only arguments of some static inline
    helpers (jsc#PED-10428).
  - ethtool: regenerate uapi header from the spec (jsc#PED-10684
    jsc#PED-11230).
  - ethtool: remove the comments that are not gonna be generated
    (jsc#PED-10684 jsc#PED-11230).
  - ethtool: separate definitions that are gonna be generated
    (jsc#PED-10684 jsc#PED-11230).
  - ynl: add missing pieces to ethtool spec to better match uapi
    header (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5e: Always start IPsec sequence number from 1
    (jsc#PED-11331).
  - net/mlx5e: Rely on reqid in IPsec tunnel mode (jsc#PED-11331).
  - net/mlx5: SF, Fix add port error handling (jsc#PED-11331).
  - net/mlx5: Fix a lockdep warning as part of the write combining
    test (jsc#PED-11331).
  - net/mlx5: Fix RDMA TX steering prio (jsc#PED-11331).
  - net: make page_pool_ref_netmem work with net iovs
    (jsc#PED-10428).
  - ice: Add correct PHY lane assignment (jsc#PED-10419).
  - ice: Fix ETH56G FC-FEC Rx offset value (jsc#PED-10419).
  - ice: Fix quad registers read on E825 (jsc#PED-10419).
  - ice: Fix E825 initialization (jsc#PED-10419).
  - igc: return early when failing to read EECD register
    (jsc#PED-10417).
  - ice: fix incorrect PHY settings for 100 GB/s (jsc#PED-10419).
  - ice: fix max values for dpll pin phase adjust (jsc#PED-10419).
  - bnxt_en: Fix DIM shutdown (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Fix possible memory leak when hwrm_req_replace fails
    (jsc#PED-10684 jsc#PED-11230).
  - sysfs: attribute_group: allow registration of const
    bin_attribute (jsc#PED-10421 jsc#PED-8564).
  - cdx: Fix cdx_mmap_resource() after constifying attr in ->mmap()
    (git-fixes).
  - sysfs: bin_attribute: add const read/write callback variants
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: implement all BIN_ATTR_* macros in terms of __BIN_ATTR()
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: treewide: constify attribute callback of
    bin_attribute::llseek() (jsc#PED-10421 jsc#PED-8564).
  - sysfs: treewide: constify attribute callback of
    bin_attribute::mmap() (jsc#PED-10421 jsc#PED-8564).
  - sysfs: treewide: constify attribute callback of bin_is_visible()
    (jsc#PED-10421 jsc#PED-8564).
  - nvmem: core: calculate bin_attribute size through bin_size()
    (jsc#PED-10421 jsc#PED-8564).
  - PCI/sysfs: Calculate bin_attribute size through bin_size()
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: introduce callback attribute_group::bin_size
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: explicitly pass size to sysfs_add_bin_file_mode_ns()
    (jsc#PED-10421 jsc#PED-8564).
  - tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
    (jsc#PED-3526 jsc#PED-11226).
  - net/neighbor: clear error in case strict check is not set
    (jsc#PED-10684 jsc#PED-11230).
  - neighbour: Create netdev->neighbour association (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Remove bare neighbour::next pointer (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Convert iteration to use hlist+macro (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Convert seq_file functions to use hlist
    (jsc#PED-10684 jsc#PED-11230).
  - neighbour: Define neigh_for_each_in_bucket (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Add hlist_node to struct neighbour (jsc#PED-10684
    jsc#PED-11230).
  - Documentation: networking: Add missing PHY_GET command in the
    message list (jsc#PED-10684 jsc#PED-11230).
  - neighbour: use kvzalloc()/kvfree() (jsc#PED-10684
    jsc#PED-11230).
  - netlink: specs: Add missing phy-ntf command to ethtool spec
    (jsc#PED-10684 jsc#PED-11230).
  - netlink: specs: Add missing bitset attrs to ethtool spec
    (jsc#PED-10684 jsc#PED-11230).
  - ethtool: rss: prevent rss ctx deletion when in use (git-fixes).
  - neighbour: Use rtnl_register_many() (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Remove NEIGH_DN_TABLE (jsc#PED-10684 jsc#PED-11230).
  - xsk: s/free_list_node/list_node/ (jsc#PED-10428).
  - xsk: Get rid of xdp_buff_xsk::xskb_list_node (jsc#PED-10428).
  - lib: packing: catch kunit_kzalloc() failure in the pack() test
    (jsc#PED-10419).
  - lib: packing: use GENMASK() for box_mask (jsc#PED-10419).
  - lib: packing: use BITS_PER_BYTE instead of 8 (jsc#PED-10419).
  - lib: packing: fix QUIRK_MSB_ON_THE_RIGHT behavior
    (jsc#PED-10419).
  - lib: packing: add additional KUnit tests (jsc#PED-10419).
  - lib: packing: add KUnit tests adapted from selftests
    (jsc#PED-10419).
  - lib: packing: duplicate pack() and unpack() implementations
    (jsc#PED-10419).
  - lib: packing: add pack() and unpack() wrappers over packing()
    (jsc#PED-10419).
  - lib: packing: remove kernel-doc from header file
    (jsc#PED-10419).
  - lib: packing: adjust definitions and implementation for
    arbitrary buffer lengths (jsc#PED-10419).
  - lib: packing: refuse operating on bit indices which exceed
    size of buffer (jsc#PED-10419).
  - commit 6cae1c1
  - nvme/ioctl: add missing space in err message (git-fixes).
  - nvme-tcp: fix connect failure on receiving partial ICResp PDU
    (git-fixes).
  - nvme: tcp: Fix compilation warning with W=1 (git-fixes).
  - nvmet: Fix crash when a namespace is disabled (git-fixes).
  - nvme-fc: use ctrl state getter (git-fixes).
  - nvme: make nvme_tls_attrs_group static (git-fixes).
  - nvme: handle connectivity loss in nvme_set_queue_count
    (git-fixes).
  - nvme-pci: Add TUXEDO IBP Gen9 to Samsung sleep quirk
    (git-fixes).
  - nvme-pci: Add TUXEDO InfinityFlex to Samsung sleep quirk
    (git-fixes).
  - commit 1f4a76c
  - docs/zh_TW+zh_CN: Make rst references unique (bsc#1238303).
  - commit cc79623
  - sched: Compact RSEQ concurrency IDs with reduced threads and
    affinity (git fixes (sched)).
  - sched_ext: Fix incorrect autogroup migration detection (git
    fixes (sched)).
  - commit ff0b264
  - powerpc/vdso: Flag VDSO64 entry points as functions
    (bsc#1238318).
  - commit 8f0f0a0
  - btrfs: fix use-after-free when attempting to join an aborted transaction (CVE-2025-21753 bsc#1237875)
  - commit 03161f9
  - 8250: microchip: pci1xxxx: Add workaround for RTS bit toggle
    (git-fixes).
  - serial: 8250_pci: Resolve WCH vendor ID ambiguity (git-fixes).
  - PCI: switchtec: Add Microchip PCI100X device IDs (git-fixes).
  - PCI/DPC: Quirk PIO log size for Intel Raptor Lake-P (git-fixes).
  - commit 55d8dfe
  - phy: tegra: xusb: reset VBUS & ID OVERRIDE (git-fixes).
  - phy: exynos5-usbdrd: gs101: ensure power is gated to SS phy
    in phy_exit() (git-fixes).
  - phy: exynos5-usbdrd: fix MPLL_MULTIPLIER and SSC_REFCLKSEL
    masks in refclk (git-fixes).
  - phy: rockchip: naneng-combphy: compatible reset with old DT
    (git-fixes).
  - phy: rockchip: fix Kconfig dependency more (git-fixes).
  - commit d9bc035

++++ kernel-firmware-amdgpu:

  - Update to version 20250302 (git commit 76e258534a5d):
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DCUB update for DCN401 and DCN315

++++ kernel-firmware-sound:

  - Update to version 20250302 (git commit 76e258534a5d):
    * cirrus: cs35l41: Add firmware and tunings for CS35L41 driver for Steam Deck

++++ kernel-rt:

  - tracing: Do not allow mmap() of persistent ring buffer
    (git-fixes bsc#1237898 CVE-2025-21778).
  - commit 7bd7207
  - Delete
    patches.suse/staging-qlge-devlink-use-retained-error-fmsg-API.patch.
    Dropped patch for no longer present driver.
  - commit d78cf53
  - bpf: Send signals asynchronously if !preemptible (git-fixes
    bsc#1237879 CVE-2025-21728).
  - commit bf6a524
  - scsi: lpfc: Copyright updates for 14.4.0.8 patches
    (bsc#1238349).
  - scsi: lpfc: Update lpfc version to 14.4.0.8 (bsc#1238349).
  - scsi: lpfc: Handle duplicate D_IDs in ndlp search-by D_ID
    routine (bsc#1238349).
  - scsi: lpfc: Ignore ndlp rport mismatch in dev_loss_tmo callbk
    (bsc#1238349).
  - scsi: lpfc: Free phba irq in lpfc_sli4_enable_msi() when
    pci_irq_vector() fails (bsc#1238349).
  - scsi: lpfc: Reduce log message generation during ELS ring
    clean up (bsc#1238349).
  - commit 9c9e63e
  - net: ethtool: Use hwprov under rcu_read_lock (git-fixes).
  - commit 9b0a090
  - idpf: fix checksums set in idpf_rx_rsc() (jsc#PED-10581).
  - net/mlx5: IRQ, Fix null string in debug print (jsc#PED-11331).
  - net/mlx5: Restore missing trace event when enabling vport QoS
    (jsc#PED-11331).
  - net/mlx5: Fix vport QoS cleanup on error (jsc#PED-11331).
  - ixgbe: fix media cage present detection for E610 device
    (jsc#PED-9647).
  - iavf: fix circular lock dependency with netdev_lock
    (jsc#PED-10423).
  - ice: Avoid setting default Rx VSI twice in switchdev setup
    (jsc#PED-10419).
  - ice: Fix deinitializing VF in error path (jsc#PED-10419).
  - net: ethtool: fix ioctl confusing drivers about desired HDS
    user config (git-fixes).
  - RDMA/bnxt_re: Fix the page details for the srq created by
    kernel consumers (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Fix the statistics for Gen P7 VF (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Fix issue in the unload path (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Add sanity checks on rdev validity (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Fix an issue in bnxt_re_async_notifier
    (jsc#PED-10684 jsc#PED-11230).
  - vsock/bpf: Warn on socket without transport (jsc#PED-11028).
  - ibmvnic: Don't reference skb after sending to VIOS
    (jsc#PED_10911 jsc#PED-3606).
  - s390/qeth: move netif_napi_add_tx() and napi_enable() from
    under BH (git-fixes).
  - vsock: Orphan socket after transport release (jsc#PED-11028).
  - igc: Set buffer type for empty frames in igc_init_empty_frame
    (jsc#PED-10417).
  - igc: Fix HW RX timestamp when passed by ZC XDP (jsc#PED-10417).
  - ixgbe: Fix possible skb NULL pointer dereference (jsc#PED-9647).
  - idpf: record rx queue in skb for RSC packets (jsc#PED-10581).
  - idpf: fix handling rsc packet with a single segment
    (jsc#PED-10581).
  - iavf: Fix a locking bug in an error path (jsc#PED-10423).
  - neighbour: use RCU protection in __neigh_notify() (jsc#PED-10684
    jsc#PED-11230).
  - net: ethtool: tsconfig: Fix netlink type of hwtstamp flags
    (git-fixes).
  - net: add dev_net_rcu() helper (jsc#PED-10684 jsc#PED-11230).
  - net: atlantic: fix warning during hot unplug (jsc#PED-11287).
  - ice: stop storing XDP verdict within ice_rx_buf (jsc#PED-10419).
  - ice: gather page_count()'s of each frag right before XDP prog
    call (jsc#PED-10419).
  - ice: put Rx buffers after being done with current frame
    (jsc#PED-10419).
  - tg3: Disable tg3 PCIe AER on system reboot (jsc#PED-3526
    jsc#PED-11226).
  - vmxnet3: Fix tx queue race condition with XDP (jsc#PED-11024).
  - ice: Add check for devm_kzalloc() (jsc#PED-10419).
  - vsock: Allow retrying on connect() failure (jsc#PED-11028).
  - iavf: allow changing VLAN state without calling PF
    (jsc#PED-10423).
  - ice: remove invalid parameter of equalizer (jsc#PED-10419).
  - ice: fix ice_parser_rt::bst_key array size (jsc#PED-10419).
  - idpf: add more info during virtchnl transaction timeout/salt
    mismatch (jsc#PED-10581).
  - idpf: convert workqueues to unbound (jsc#PED-10581).
  - idpf: Acquire the lock before accessing the xn->salt
    (jsc#PED-10581).
  - idpf: fix transaction timeouts on reset (jsc#PED-10581).
  - idpf: add read memory barrier when checking descriptor done bit
    (jsc#PED-10581).
  - net: page_pool: don't try to stash the napi id (jsc#PED-10423).
  - netdevsim: don't assume core pre-populates HDS params on GET
    (jsc#PED-10684 jsc#PED-11230).
  - wifi: mt76: move napi_enable() from under BH (git-fixes).
  - eth: via-rhine: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: niu: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: 8139too: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: forcedeth: fix calling napi_enable() in atomic context
    (git-fixes).
  - eth: forcedeth: remove local wrappers for napi enable/disable
    (git-fixes).
  - eth: tg3: fix calling napi_enable() in atomic context
    (jsc#PED-3526 jsc#PED-11226).
  - net/mlx5e: add missing cpu_to_node to kvzalloc_node in
    mlx5e_open_xdpredirect_sq (jsc#PED-11331).
  - net: mvneta: fix locking in mvneta_cpu_online() (git-fixes).
  - octeontx2: don't mess with ->d_parent or ->d_parent->d_name
    (jsc#PED-11317).
  - sysfs: constify bin_attribute argument of
    sysfs_bin_attr_simple_read() (jsc#PED-10421 jsc#PED-8564).
  - sysfs: constify macro BIN_ATTRIBUTE_GROUPS() (jsc#PED-10421
    jsc#PED-8564).
  - VMCI: remove unused ioctl definitions (jsc#PED-11026).
  - RDMA/hfi1: Constify 'struct bin_attribute' (jsc#PED-10421
    jsc#PED-8564).
  - RDMA/bnxt_re: Allocate dev_attr information dynamically
    (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Pass the context for ulp_irq_stop (jsc#PED-10684
    jsc#PED-11230).
  - RDMA/bnxt_re: Add support to handle DCB_CONFIG_CHANGE event
    (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Query firmware defaults of CC params during probe
    (jsc#PED-10684 jsc#PED-11230).
  - RDMA/bnxt_re: Add Async event handling support (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Add ULP call to notify async events (jsc#PED-10684
    jsc#PED-11230).
  - net: avoid race between device unregistration and ethnl ops
    (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: update header sizing defaults (jsc#PED-10684
    jsc#PED-11230).
  - eth: bnxt: allocate enough buffer space to meet HDS threshold
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: populate the default HDS params in the core
    (jsc#PED-10684 jsc#PED-11230).
  - eth: bnxt: apply hds_thrs settings correctly (jsc#PED-10684
    jsc#PED-11230).
  - net: provide pending ring configuration in net_device
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: store netdev in a temp variable in
    ethnl_default_set_doit() (jsc#PED-10684 jsc#PED-11230).
  - net: move HDS config from ethtool state (jsc#PED-10684
    jsc#PED-11230).
  - net: destroy dev->lock later in free_netdev() (git-fixes).
  - eth: bnxt: fix string truncation warning in FW version
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: ts: add separate counter for unconfirmed one-step
    TX timestamps (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: fix unintentional sign extension on shift of
    dest_attr->vport.vhca_id (jsc#PED-11331).
  - ice: support FW Recovery Mode (jsc#PED-10419).
  - devlink: add devl guard (jsc#PED-10419).
  - pldmfw: enable selected component update (jsc#PED-10419).
  - net/mlx5e: CT: Offload connections with hardware steering rules
    (jsc#PED-11331).
  - net/mlx5e: CT: Make mlx5_ct_fs_smfs_ct_validate_flow_rule
    reusable (jsc#PED-11331).
  - net/mlx5e: CT: Add initial support for Hardware Steering
    (jsc#PED-11331).
  - net/mlx5: HWS, rework the check if matcher size can be increased
    (jsc#PED-11331).
  - net: protect napi->irq with netdev_lock() (jsc#PED-3526
    jsc#PED-11226).
  - net: protect NAPI enablement with netdev_lock() (jsc#PED-10423).
  - net: protect netdev->napi_list with netdev_lock()
    (jsc#PED-10423).
  - net: add netdev->up protected by netdev_lock() (jsc#PED-10423).
  - net: make netdev_lock() protect netdev->reg_state
    (jsc#PED-10423).
  - net: add netdev_lock() / netdev_unlock() helpers
    (jsc#PED-10423).
  - ice: Add in/out PTP pin delays (jsc#PED-10419).
  - ice: implement low latency PHY timer updates (jsc#PED-10419).
  - ice: check low latency PHY timer update firmware capability
    (jsc#PED-10419).
  - ice: add lock to protect low latency interface (jsc#PED-10419).
  - ice: rename TS_LL_READ* macros to REG_LL_PROXY_H_*
    (jsc#PED-10419).
  - ice: use read_poll_timeout_atomic in ice_read_phy_tstamp_ll_e810
    (jsc#PED-10419).
  - ice: use string choice helpers (jsc#PED-10419).
  - ice: add fw and port health reporters (jsc#PED-10419).
  - ice: add recipe priority check in search (jsc#PED-10419).
  - ice: ice_probe: init ice_adapter after HW init (jsc#PED-10419).
  - ice: minor: rename goto labels from err to unroll
    (jsc#PED-10419).
  - ice: split ice_init_hw() out from ice_init_dev()
    (jsc#PED-10419).
  - ice: c827: move wait for FW to ice_init_hw() (jsc#PED-10419).
  - netdevsim: add HDS feature (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: add support for hds-thresh ethtool command
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: add support for tcp-data-split ethtool command
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: add support for rx-copybreak ethtool command
    (jsc#PED-10684 jsc#PED-11230).
  - net: disallow setup single buffer XDP when tcp-data-split is
    enabled (jsc#PED-10684 jsc#PED-11230).
  - net: devmem: add ring parameter filtering (jsc#PED-10684
    jsc#PED-11230).
  - net: ethtool: add support for configuring hds-thresh
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: add hds_config member in ethtool_netdev_state
    (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: Add nic_cap_reg and vhca_icm_ctrl registers
    (jsc#PED-11331).
  - net/mlx5: SHAMPO: Introduce new SHAMPO specific HCA caps
    (jsc#PED-11331).
  - net/mlx5: Add support for MRTCQ register (jsc#PED-11331).
  - net/mlx5: Update mlx5_ifc to support FEC for 200G per lane
    link modes (jsc#PED-11331).
  - net: ethtool: add support for structured PHY statistics
    (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: plumb PHY stats to PHY drivers (jsc#PED-10684
    jsc#PED-11230).
  - ethtool: linkstate: migrate linkstate functions to support
    multi-PHY setups (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: HWS, update flow - support through bigger action RTC
    (jsc#PED-11331).
  - net/mlx5: HWS, update flow - remove the use of dual RTCs
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS to steering mode options (jsc#PED-11331).
  - net/mlx5: fs, add HWS get capabilities (jsc#PED-11331).
  - net/mlx5: fs, set create match definer to not supported by HWS
    (jsc#PED-11331).
  - net/mlx5: fs, add support for dest vport HWS action
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS fte API functions (jsc#PED-11331).
  - net/mlx5: fs, add dest table cache (jsc#PED-11331).
  - net/mlx5: fs, manage flow counters HWS action sharing by
    refcount (jsc#PED-11331).
  - net/mlx5: fs, add HWS modify header API function
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS packet reformat API function
    (jsc#PED-11331).
  - net/mlx5: fs, add HWS actions pool (jsc#PED-11331).
  - net/mlx5: fs, add HWS flow group API functions (jsc#PED-11331).
  - net/mlx5: fs, add HWS flow table API functions (jsc#PED-11331).
  - net/mlx5: fs, add HWS root namespace functions (jsc#PED-11331).
  - eth: iavf: extend the netdev_lock usage (jsc#PED-10423).
  - net/mlx5e: Update TX ESN context for IPSec hardware offload
    (jsc#PED-11331).
  - xfrm: Support ESN context update to hardware for TX
    (jsc#PED-11331).
  - net/mlx5: use do_aux_work for PHC overflow checks
    (jsc#PED-11331).
  - igc: Link queues to NAPI instances (jsc#PED-10417).
  - igc: Link IRQs to NAPI instances (jsc#PED-10417).
  - i40e: add ability to reset VF for Tx and Rx MDD events
    (jsc#PED-10428).
  - ixgbevf: Fix passing 0 to ERR_PTR in ixgbevf_run_xdp()
    (jsc#PED-9647).
  - ixgbe: Fix passing 0 to ERR_PTR in ixgbe_run_xdp()
    (jsc#PED-9647).
  - igb: Fix passing 0 to ERR_PTR in igb_run_xdp() (jsc#PED-10426).
  - igc: Fix passing 0 to ERR_PTR in igc_xdp_run_prog()
    (jsc#PED-10417).
  - igc: Allow hot-swapping XDP program (jsc#PED-10417).
  - igb: Add AF_XDP zero-copy Tx support (jsc#PED-10426).
  - igb: Add AF_XDP zero-copy Rx support (jsc#PED-10426).
  - igb: Add XDP finalize and stats update functions
    (jsc#PED-10426).
  - igb: Introduce XSK data structures and helpers (jsc#PED-10426).
  - igb: Introduce igb_xdp_is_enabled() (jsc#PED-10426).
  - igb: Remove static qualifiers (jsc#PED-10426).
  - ixgbevf: Remove unused ixgbevf_hv_mbx_ops (jsc#PED-9647).
  - octeontx2-pf: mcs: Remove dead code and semi-colon from
    rsrc_name() (jsc#PED-11317).
  - net/mlx5: HWS, set timeout on polling for completion
    (jsc#PED-11331).
  - net/mlx5: HWS, support flow sampler destination (jsc#PED-11331).
  - net/mlx5: HWS, use the right size when writing arg data
    (jsc#PED-11331).
  - net/mlx5: HWS, handle returned error value in pool alloc
    (jsc#PED-11331).
  - net/mlx5: HWS, fix definer's HWS_SET32 macro for negative offset
    (jsc#PED-11331).
  - net/mlx5: HWS, separate SQ that HWS uses from the usual traffic
    SQs (jsc#PED-11331).
  - net/mlx5: HWS, num_of_rules counter on matcher should be atomic
    (jsc#PED-11331).
  - net/mlx5: HWS, reduce memory consumption of a matcher struct
    (jsc#PED-11331).
  - net/mlx5: HWS, remove wrong deletion of the miss table list
    (jsc#PED-11331).
  - net/mlx5: HWS, change error flow on matcher disconnect
    (jsc#PED-11331).
  - net/mlx5: HWS, add error message on failure to move rules
    (jsc#PED-11331).
  - net/mlx5: HWS, simplify allocations as we support only FDB
    (jsc#PED-11331).
  - net/mlx5: HWS, denote how refcounts are protected
    (jsc#PED-11331).
  - net/mlx5: HWS, remove implementation of unused FW commands
    (jsc#PED-11331).
  - net/mlx5: HWS, remove the use of duplicated structs
    (jsc#PED-11331).
  - igc: Remove unused igc_read/write_pcie_cap_reg (jsc#PED-10417).
  - igc: Remove unused igc_read/write_pci_cfg wrappers
    (jsc#PED-10417).
  - igc: Remove unused igc_acquire/release_nvm (jsc#PED-10417).
  - i40e: Remove unused i40e_dcb_hw_get_num_tc (jsc#PED-10428).
  - i40e: Remove unused i40e_asq_send_command_v2 (jsc#PED-10428).
  - i40e: Remove unused i40e_commit_partition_bw_setting
    (jsc#PED-10428).
  - i40e: Remove unused i40e_del_filter (jsc#PED-10428).
  - i40e: Remove unused i40e_get_cur_guaranteed_fd_count
    (jsc#PED-10428).
  - i40e: Deadcode profile code (jsc#PED-10428).
  - i40e: Remove unused i40e_(read|write)_phy_register
    (jsc#PED-10428).
  - i40e: Remove unused i40e_blink_phy_link_led (jsc#PED-10428).
  - i40e: Deadcode i40e_aq_* (jsc#PED-10428).
  - devlink: Improve the port attributes description
    (jsc#PED-10419).
  - ixgbevf: Add support for Intel(R) E610 device (jsc#PED-9647).
  - PCI: Add PCI_VDEVICE_SUB helper macro (jsc#PED-9647).
  - ixgbe: Enable link management in E610 device (jsc#PED-9647).
  - ixgbe: Clean up the E610 link management related code
    (jsc#PED-9647).
  - ixgbe: Add ixgbe_x540 multiple header inclusion protection
    (jsc#PED-9647).
  - ixgbe: Add support for EEPROM dump in E610 device
    (jsc#PED-9647).
  - ixgbe: Add support for NVM handling in E610 device
    (jsc#PED-9647).
  - ixgbe: Add link management support for E610 device
    (jsc#PED-9647).
  - ixgbe: Add support for E610 device capabilities detection
    (jsc#PED-9647).
  - ixgbe: Add support for E610 FW Admin Command Interface
    (jsc#PED-9647).
  - net: ethtool: Fix suspicious rcu_dereference usage (git-fixes).
  - net/mlx5: fs, Add support for RDMA RX steering over IB link
    layer (jsc#PED-11331).
  - net/mlx5: Remove PTM support log message (jsc#PED-11331).
  - net/mlx5: DR, add support for ConnectX-8 steering
    (jsc#PED-11331).
  - net/mlx5: DR, expand SWS STE callbacks and consolidate common
    structs (jsc#PED-11331).
  - net/mlx5: HWS, do not initialize native API queues
    (jsc#PED-11331).
  - net/mlx5: HWS, no need to expose mlx5hws_send_queues_open/close
    (jsc#PED-11331).
  - net/mlx5: fs, retry insertion to hash table on EBUSY
    (jsc#PED-11331).
  - net/mlx5: fs, add mlx5_fs_pool API (jsc#PED-11331).
  - net/mlx5: fs, add counter object to flow destination
    (jsc#PED-11331).
  - net/mlx5: LAG, Support LAG over Multi-Host NICs (jsc#PED-11331).
  - net/mlx5: LAG, Refactor lag logic (jsc#PED-11331).
  - sfc: Use netdev refcount tracking in struct
    efx_async_filter_insertion (jsc#PED-11366).
  - xsk: add generic XSk &xdp_buff -> skb conversion
    (jsc#PED-10428).
  - xsk: make xsk_buff_add_frag() really add the frag via
    __xdp_buff_add_frag() (jsc#PED-10428).
  - xdp: add generic xdp_build_skb_from_buff() (jsc#PED-10428).
  - xdp: add generic xdp_buff_add_frag() (jsc#PED-10428).
  - page_pool: add page_pool_dev_alloc_netmem() (jsc#PED-10428).
  - sfc: remove efx_writed_page_locked (jsc#PED-11366).
  - bnxt_en: Skip reading PXP registers during ethtool -d if
    unsupported (bsc#1238145).
  - bnxt_en: Skip MAC loopback selftest if it is unsupported by FW
    (bsc#1238145).
  - bnxt_en: Skip PHY loopback ethtool selftest if unsupported by FW
    (bsc#1238145).
  - bnxt_en: Do not allow ethtool -m on an untrusted VF
    (bsc#1238145).
  - bnxt_en: Use FW defined resource limits for RoCE (bsc#1238145).
  - ice: Add MDD logging via devlink health (jsc#PED-10419).
  - ice: add Tx hang devlink health reporter (jsc#PED-10419).
  - ice: rename devlink_port. to port.[ch] (jsc#PED-10419).
  - devlink: add devlink_fmsg_dump_skb() function (jsc#PED-10419).
  - devlink: add devlink_fmsg_put() macro (jsc#PED-10419).
  - net/mlx5e: Report rx_discards_phy via rx_dropped
    (jsc#PED-11331).
  - net: page_pool: rename page_pool_is_last_ref() (jsc#PED-10428).
  - net/mlx5: Add device cap abs_native_port_num (jsc#PED-11331).
  - net/mlx5: qos: Add ifc support for cross-esw scheduling
    (jsc#PED-11331).
  - net/mlx5: Add support for new scheduling elements
    (jsc#PED-11331).
  - net/mlx5: Add ConnectX-8 device to ifc (jsc#PED-11331).
  - net/mlx5: ifc: Reorganize mlx5_ifc_flow_table_context_bits
    (jsc#PED-11331).
  - net: ethtool: Add support for tsconfig command to get/set
    hwtstamp config (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: tsinfo: Enhance tsinfo to support several hwtstamp
    by net topology (jsc#PED-10684 jsc#PED-11230).
  - net: Add the possibility to support a selected hwtstamp in
    netdevice (jsc#PED-10684 jsc#PED-11230).
  - net: Make net_hwtstamp_validate accessible (jsc#PED-10684
    jsc#PED-11230).
  - net: Make dev_get_hwtstamp_phylib accessible (jsc#PED-10684
    jsc#PED-11230).
  - octeontx2-af: fix build regression without CONFIG_DCB
    (jsc#PED-11317).
  - ionic: remove the unused nb_work (jsc#PED-11378).
  - page_pool: disable sync for cpu for dmabuf memory provider
    (jsc#PED-10428).
  - page_pool: Set `dma_sync` to false for devmem memory provider
    (jsc#PED-10428).
  - net: page_pool: create page_pool_alloc_netmem (jsc#PED-10428).
  - net: page_pool: rename page_pool_alloc_netmem to *_netmems
    (jsc#PED-10423).
  - xdp: make __xdp_return() MP-agnostic (jsc#PED-10428).
  - xdp: get rid of xdp_frame::mem.id (jsc#PED-10428).
  - page_pool: allow mixing PPs within one bulk (jsc#PED-10428).
  - ionic: add support for QSFP_PLUS_CMIS (jsc#PED-11378).
  - ionic: add speed defines for 200G and 400G (jsc#PED-11378).
  - ionic: Translate IONIC_RC_ENOSUPP to EOPNOTSUPP (jsc#PED-11378).
  - ionic: Use VLAN_ETH_HLEN when possible (jsc#PED-11378).
  - ionic: add asic codes to firmware interface file
    (jsc#PED-11378).
  - ice: cleanup Rx queue context programming functions
    (jsc#PED-10419).
  - ice: move prefetch enable to ice_setup_rx_ctx (jsc#PED-10419).
  - ice: reduce size of queue context fields (jsc#PED-10419).
  - ice: use <linux/packing.h> for Tx and Rx queue context data
    (jsc#PED-10419).
  - ice: use structures to keep track of queue context size
    (jsc#PED-10419).
  - ice: remove int_q_state from ice_tlan_ctx (jsc#PED-10419).
  - lib: packing: add pack_fields() and unpack_fields()
    (jsc#PED-10419).
  - lib: packing: demote truncation error in pack() to a warning
    in __pack() (jsc#PED-10419).
  - lib: packing: create __pack() and __unpack() variants without
    error checking (jsc#PED-10419).
  - cn10k-ipsec: Fix compilation error when CONFIG_XFRM_OFFLOAD
    disabled (jsc#PED-11317).
  - cn10k-ipsec: Enable outbound ipsec crypto offload
    (jsc#PED-11317).
  - cn10k-ipsec: Allow ipsec crypto offload for skb with SA
    (jsc#PED-11317).
  - cn10k-ipsec: Process outbound ipsec crypto offload
    (jsc#PED-11317).
  - cn10k-ipsec: Add SA add/del support for outb ipsec crypto
    offload (jsc#PED-11317).
  - cn10k-ipsec: Init hardware for outbound ipsec crypto offload
    (jsc#PED-11317).
  - octeontx2-af: Disable backpressure between CPT and NIX
    (jsc#PED-11317).
  - octeontx2-pf: Move skb fragment map/unmap to common code
    (jsc#PED-11317).
  - octeontx2-pf: map skb data as device writeable (jsc#PED-11317).
  - page_pool: make page_pool_put_page_bulk() handle array of
    netmems (jsc#PED-10428).
  - netmem: add a couple of page helper wrappers (jsc#PED-10428).
  - xdp: register system page pool as an XDP memory model
    (jsc#PED-10428).
  - xsk: allow attaching XSk pool via xdp_rxq_info_reg_mem_model()
    (jsc#PED-10428).
  - xdp: allow attaching already registered memory model to
    xdp_rxq_info (jsc#PED-10428).
  - xdp, xsk: constify read-only arguments of some static inline
    helpers (jsc#PED-10428).
  - ethtool: regenerate uapi header from the spec (jsc#PED-10684
    jsc#PED-11230).
  - ethtool: remove the comments that are not gonna be generated
    (jsc#PED-10684 jsc#PED-11230).
  - ethtool: separate definitions that are gonna be generated
    (jsc#PED-10684 jsc#PED-11230).
  - ynl: add missing pieces to ethtool spec to better match uapi
    header (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5e: Always start IPsec sequence number from 1
    (jsc#PED-11331).
  - net/mlx5e: Rely on reqid in IPsec tunnel mode (jsc#PED-11331).
  - net/mlx5: SF, Fix add port error handling (jsc#PED-11331).
  - net/mlx5: Fix a lockdep warning as part of the write combining
    test (jsc#PED-11331).
  - net/mlx5: Fix RDMA TX steering prio (jsc#PED-11331).
  - net: make page_pool_ref_netmem work with net iovs
    (jsc#PED-10428).
  - ice: Add correct PHY lane assignment (jsc#PED-10419).
  - ice: Fix ETH56G FC-FEC Rx offset value (jsc#PED-10419).
  - ice: Fix quad registers read on E825 (jsc#PED-10419).
  - ice: Fix E825 initialization (jsc#PED-10419).
  - igc: return early when failing to read EECD register
    (jsc#PED-10417).
  - ice: fix incorrect PHY settings for 100 GB/s (jsc#PED-10419).
  - ice: fix max values for dpll pin phase adjust (jsc#PED-10419).
  - bnxt_en: Fix DIM shutdown (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Fix possible memory leak when hwrm_req_replace fails
    (jsc#PED-10684 jsc#PED-11230).
  - sysfs: attribute_group: allow registration of const
    bin_attribute (jsc#PED-10421 jsc#PED-8564).
  - cdx: Fix cdx_mmap_resource() after constifying attr in ->mmap()
    (git-fixes).
  - sysfs: bin_attribute: add const read/write callback variants
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: implement all BIN_ATTR_* macros in terms of __BIN_ATTR()
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: treewide: constify attribute callback of
    bin_attribute::llseek() (jsc#PED-10421 jsc#PED-8564).
  - sysfs: treewide: constify attribute callback of
    bin_attribute::mmap() (jsc#PED-10421 jsc#PED-8564).
  - sysfs: treewide: constify attribute callback of bin_is_visible()
    (jsc#PED-10421 jsc#PED-8564).
  - nvmem: core: calculate bin_attribute size through bin_size()
    (jsc#PED-10421 jsc#PED-8564).
  - PCI/sysfs: Calculate bin_attribute size through bin_size()
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: introduce callback attribute_group::bin_size
    (jsc#PED-10421 jsc#PED-8564).
  - sysfs: explicitly pass size to sysfs_add_bin_file_mode_ns()
    (jsc#PED-10421 jsc#PED-8564).
  - tg3: Set coherent DMA mask bits to 31 for BCM57766 chipsets
    (jsc#PED-3526 jsc#PED-11226).
  - net/neighbor: clear error in case strict check is not set
    (jsc#PED-10684 jsc#PED-11230).
  - neighbour: Create netdev->neighbour association (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Remove bare neighbour::next pointer (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Convert iteration to use hlist+macro (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Convert seq_file functions to use hlist
    (jsc#PED-10684 jsc#PED-11230).
  - neighbour: Define neigh_for_each_in_bucket (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Add hlist_node to struct neighbour (jsc#PED-10684
    jsc#PED-11230).
  - Documentation: networking: Add missing PHY_GET command in the
    message list (jsc#PED-10684 jsc#PED-11230).
  - neighbour: use kvzalloc()/kvfree() (jsc#PED-10684
    jsc#PED-11230).
  - netlink: specs: Add missing phy-ntf command to ethtool spec
    (jsc#PED-10684 jsc#PED-11230).
  - netlink: specs: Add missing bitset attrs to ethtool spec
    (jsc#PED-10684 jsc#PED-11230).
  - ethtool: rss: prevent rss ctx deletion when in use (git-fixes).
  - neighbour: Use rtnl_register_many() (jsc#PED-10684
    jsc#PED-11230).
  - neighbour: Remove NEIGH_DN_TABLE (jsc#PED-10684 jsc#PED-11230).
  - xsk: s/free_list_node/list_node/ (jsc#PED-10428).
  - xsk: Get rid of xdp_buff_xsk::xskb_list_node (jsc#PED-10428).
  - lib: packing: catch kunit_kzalloc() failure in the pack() test
    (jsc#PED-10419).
  - lib: packing: use GENMASK() for box_mask (jsc#PED-10419).
  - lib: packing: use BITS_PER_BYTE instead of 8 (jsc#PED-10419).
  - lib: packing: fix QUIRK_MSB_ON_THE_RIGHT behavior
    (jsc#PED-10419).
  - lib: packing: add additional KUnit tests (jsc#PED-10419).
  - lib: packing: add KUnit tests adapted from selftests
    (jsc#PED-10419).
  - lib: packing: duplicate pack() and unpack() implementations
    (jsc#PED-10419).
  - lib: packing: add pack() and unpack() wrappers over packing()
    (jsc#PED-10419).
  - lib: packing: remove kernel-doc from header file
    (jsc#PED-10419).
  - lib: packing: adjust definitions and implementation for
    arbitrary buffer lengths (jsc#PED-10419).
  - lib: packing: refuse operating on bit indices which exceed
    size of buffer (jsc#PED-10419).
  - commit 6cae1c1
  - nvme/ioctl: add missing space in err message (git-fixes).
  - nvme-tcp: fix connect failure on receiving partial ICResp PDU
    (git-fixes).
  - nvme: tcp: Fix compilation warning with W=1 (git-fixes).
  - nvmet: Fix crash when a namespace is disabled (git-fixes).
  - nvme-fc: use ctrl state getter (git-fixes).
  - nvme: make nvme_tls_attrs_group static (git-fixes).
  - nvme: handle connectivity loss in nvme_set_queue_count
    (git-fixes).
  - nvme-pci: Add TUXEDO IBP Gen9 to Samsung sleep quirk
    (git-fixes).
  - nvme-pci: Add TUXEDO InfinityFlex to Samsung sleep quirk
    (git-fixes).
  - commit 1f4a76c
  - docs/zh_TW+zh_CN: Make rst references unique (bsc#1238303).
  - commit cc79623
  - sched: Compact RSEQ concurrency IDs with reduced threads and
    affinity (git fixes (sched)).
  - sched_ext: Fix incorrect autogroup migration detection (git
    fixes (sched)).
  - commit ff0b264
  - powerpc/vdso: Flag VDSO64 entry points as functions
    (bsc#1238318).
  - commit 8f0f0a0
  - btrfs: fix use-after-free when attempting to join an aborted transaction (CVE-2025-21753 bsc#1237875)
  - commit 03161f9
  - 8250: microchip: pci1xxxx: Add workaround for RTS bit toggle
    (git-fixes).
  - serial: 8250_pci: Resolve WCH vendor ID ambiguity (git-fixes).
  - PCI: switchtec: Add Microchip PCI100X device IDs (git-fixes).
  - PCI/DPC: Quirk PIO log size for Intel Raptor Lake-P (git-fixes).
  - commit 55d8dfe
  - phy: tegra: xusb: reset VBUS & ID OVERRIDE (git-fixes).
  - phy: exynos5-usbdrd: gs101: ensure power is gated to SS phy
    in phy_exit() (git-fixes).
  - phy: exynos5-usbdrd: fix MPLL_MULTIPLIER and SSC_REFCLKSEL
    masks in refclk (git-fixes).
  - phy: rockchip: naneng-combphy: compatible reset with old DT
    (git-fixes).
  - phy: rockchip: fix Kconfig dependency more (git-fixes).
  - commit d9bc035

++++ ncurses:

  - Add ncurses patch 20250301
    + add color to vt525 (Branden Robinson)
    + add vt520-w and vt525-w (Branden Robinson)
    + improve formatting/style of manpages (patches by Branden Robinson).
    + improve configurability of alloca() as used in Windows ports.
    + fix some typos in manpages.
    + modify configure script checks for stdbool.h to fix build with older
    gcc version.
  - Correct offsets of patches
    * ncurses-5.9-ibm327x.dif
    * ncurses-6.4.dif
    * ncurses-6.5-ghostty.dif

++++ orc:

  - Removing patches after update
  - 0001-Use-vasprintf-if-available-for-error-messages-and.patch
  - orc-check-return-value-of-vasprintf.patch

++++ ceph:

  - Update to 16.2.15-82-gc12b9a96bd8:
    + ceph.spec.in: remove "Obsoletes: libcephfs1" (boo#1237420)
    + Suport Python 3.13

++++ libvirt:

  - Update to libvirt 11.1.0
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v11-1-0-2025-03-03

++++ openSUSE-repos-LeapMicro:

  - Update to version 20250303.f74564e:
    * Enable experimental parallel downloads for Leap and TW (#79)
    * Fix $arch -> $basearch for Leap 16.0
    * Add /etc/profile.d/opensuse_repos.sh

++++ podman:

  - Add patch for CVE-2025-27144 (bsc#1237641):
    * 0002-CVE-2025-27144-vendor-don-t-allow-unbounded-amounts-.patch
  - Rebase patches:
    * 0001-vendor-bump-buildah-to-1.37.6-CVE-2024-11218.patch

------------------------------------------------------------------
------------------  2025-3-2  -  Mar 2 2025  -------------------
------------------------------------------------------------------

++++ gsettings-desktop-schemas:

  - Update to version 48.rc:
    + Switch to JPEG for background image.
    + Updated translations.

++++ kernel-default:

  - i2c: ls2x: Fix frequency division register access (git-fixes).
  - i2c: npcm: disable interrupt enable bit before devm_request_irq
    (git-fixes).
  - Revert "ata: libata-core: Add ATA_QUIRK_NOLPM for Samsung SSD
    870 QVO drives" (git-fixes).
  - commit 33aa03b

++++ kernel-rt:

  - i2c: ls2x: Fix frequency division register access (git-fixes).
  - i2c: npcm: disable interrupt enable bit before devm_request_irq
    (git-fixes).
  - Revert "ata: libata-core: Add ATA_QUIRK_NOLPM for Samsung SSD
    870 QVO drives" (git-fixes).
  - commit 33aa03b

------------------------------------------------------------------
------------------  2025-3-1  -  Mar 1 2025  -------------------
------------------------------------------------------------------

++++ gobject-introspection:

  - Update to version 1.83.2:
    + Improve GType inspection helper
    + Parse C11's _Alignas
    + Respect custom Python binary
    + Fix build on the latest Windows SDK
    + Small performance improvement when looking up a signal
    information
    + Use standard imports in the JavaScript templates for
    g-ir-doctool
    + Ensure that enumeration members can be marked as deprecated
    + Add more test coverage for structured union types
    + Add an option to skip tests when building
    + Fix various MSVC compatibility issues
    + Add support for "static" virtual functions
    + Allow specifying the format of the documentation inside doc
    blocks
    + Handle C99's _Complex
    + Consider UCRT64 and CLANG64 as mingw32 compilers
    + Handle static NSString syntax
    + Add instance parameter checks to strict validation
    + Documentation improvements
    + Add documentation to the RelaxNG schema
    + tests: Fix compatibility with Python 3.5
    + gir: Include C header in cairo gir file
    + tests: Add functions using flat struct arrays

++++ kernel-default:

  - thermal: gov_power_allocator: Fix incorrect calculation in
    divvy_up_power() (git-fixes).
  - drm/xe: cancel pending job timer before freeing scheduler
    (git-fixes).
  - drm/xe/regs: remove a duplicate definition for
    RING_CTL_SIZE(size) (git-fixes).
  - drm/xe/userptr: fix EFAULT handling (git-fixes).
  - drm/xe/userptr: restore invalidation list on error (git-fixes).
  - drm/amdgpu: init return value in amdgpu_ttm_clear_buffer
    (git-fixes).
  - drm/amdgpu: disable BAR resize on Dell G5 SE (git-fixes).
  - amdgpu/pm/legacy: fix suspend/resume issues (git-fixes).
  - commit 4f76ef0
  - scsi: core: Clear driver private data when retrying request
    (git-fixes).
  - commit adaa7f6

++++ kernel-rt:

  - thermal: gov_power_allocator: Fix incorrect calculation in
    divvy_up_power() (git-fixes).
  - drm/xe: cancel pending job timer before freeing scheduler
    (git-fixes).
  - drm/xe/regs: remove a duplicate definition for
    RING_CTL_SIZE(size) (git-fixes).
  - drm/xe/userptr: fix EFAULT handling (git-fixes).
  - drm/xe/userptr: restore invalidation list on error (git-fixes).
  - drm/amdgpu: init return value in amdgpu_ttm_clear_buffer
    (git-fixes).
  - drm/amdgpu: disable BAR resize on Dell G5 SE (git-fixes).
  - amdgpu/pm/legacy: fix suspend/resume issues (git-fixes).
  - commit 4f76ef0
  - scsi: core: Clear driver private data when retrying request
    (git-fixes).
  - commit adaa7f6

++++ mozilla-nss:

  - Updated nss-fips-approved-crypto-non-ec.patch to exclude the
    SHA-1 hash from SLI approval.

++++ harfbuzz:

  - Update to version 10.4.0:
    + Drawing glyphs using hb-draw API now avoids any “malloc” calls,
    which improves drawing performance by 10+%.
    + Add support new “GVAR” table fonts with more than 65535 glyphs.
    Support is currently behind a compilation flag and is disabled
    by default.
    + Some hb-directwrite and hb-ft APIs got renamed with more clear
    names and the old names are deprecated.
    + Various build and fuzzing fixes.
    + New API:
  - +hb_directwrite_face_get_dw_font_face()
  - +hb_ft_font_get_ft_face()
    + Deprecated API:
  - +hb_directwrite_face_get_font_face()
  - +hb_ft_font_get_face()

------------------------------------------------------------------
------------------  2025-2-28  -  Feb 28 2025  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Update to version 1.52.0:
    + Store interactive history in `$XDG_CACHE_HOME/nmcli-history`
    instead of `~/.nmcli-history`
    + Add new ipv4.link-local=fallback to set an IPv4 link-local
    address when no other IPv4 is set.
    + Remove support for building with Autotools
    + Add IPVLAN interface support
    + Allow to manually configure the authentication of LTE's initial
    EPS Bearer.
    + Add support for the "IPv6-only preferred" DHCPv4 option (RFC
    8925), used to indicate that a host supports an IPv6-only mode
    and is willing to forgo obtaining an IPv4 address if the
    network provides IPv6 connectivity.
    + Support automatically adding routes to DNS servers via the
    ipv4.routed-dns and ipv6.routed-dns properties; when enabled,
    each name server is reached only via the device that specifies
    it.
    + Support OCI in nm-cloud-setup
    + Added support for ethtool FEC mode
    + Add new ipv4.shared-dhcp-range and ipv4.shared-dhcp-lease-time,
    which allows you to customize the DHCP range and lease time
    offered by DHCP server in `shared` connection method.
    + DNS servers can now be specified with a URI-like syntax which
    supports DNS over TLS name servers.
    + The initrd-generator understands the "rd.net.dns" option to
    configure global name servers.
    + Drop support for the "dhcpcanon" DHCP client.
    + global-dns configuration section now has 2 additional keys:
    "resolve-mode" and "certification-authority".
    + Dnsconfd plugin can now be used for configuration of
    system-wide DNS caching resolver. If dnsconfd plugin is enabled
    and ipvX.routed-dns is set to -1 then adding routes is by
    default enabled.
    + Add "shared" method to the IPv6 configuration options in nmtui.
    + Fix a bug that prevented the activation of bond and bridge's
    ports in some cases.
    + Fix a bug that prevented the activation of OVS interfaces in
    some cases.
    + Fix MTPCP endpoint creation for IPv4 with DAD and IPv6
    tentative addresses.
    + Fix some VPN routes not being added to the table specified in
    ipv4/6.routing-table. This fix allow to use policy routing to
    mitigate Tunnelvision attacks.
  - Stop passing dhcpcanon=no to meson setup, no longer recognized,
    nor needed.
  - Update to version 1.50.3:
    + Wait configuring MPTCP endpoints until DAD has completed.
    + Properly autoconnect OVS ports at boot.
    + Allow configuring "shared" IPv6 method in nmtui.
  - Changes from version 1.50.2:
    + Fix potential crash when the property "ipv4.dhcp-send-release"
    is enabled.
    + Support routing rules for VPN connections.
    + Place the route to the VPN gateway into the table defined by
    the "ipv{4,6}.route-table" properties-
    + Fix error handling rp_filter when kernel don't support MPTCP.
    + Fix configuration of VLAN QoS mappings.
  - Changes from version 1.50.1:
    + nmcli: fix handling of connection.down-on-poweroff property
    + sriov: only validate sriov capacity when enabled
    + wwan: fix crash with IPv4 and method=auto
    + dns: fix deleting internal global DNS configuration
    + wifi: fix list corruption when scanning with explicit SSID
    + bonding: steer IGMP queries to the active bond balance-slb
    primary port
    + Remove routes added by NM on reapply
    + Never retry ACD on NOARP interfaces
    + Support IPv6 EUI64 link-local address for ipv6 tunnels

++++ containerd:

  - Update to containerd v1.7.26. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.26>
  - Rebase patches:
    * 0001-BUILD-SLE12-revert-btrfs-depend-on-kernel-UAPI-inste.patch

++++ crypto-policies:

  - Fix fips-mode-setup in EFI or Secure Boot mode. [bsc#1227637]
    * Rebase crypto-policies-FIPS.patch

++++ python-kiwi:

  - Lookup CHRP loader instead of using a static name
    On ppc the CHRP loader name can vary between distributions.
    This commit adds a search method to lookup different ELF
    loader names. In addition an integration test image for
    Fedora was added. This Fixes #2741

++++ glib2:

  - Update to version 2.83.5 (Unstable):
    + A few improvements for when GLib is used as a subproject
    + Fix out-of-order parameters in a marshaller generated by
    `gdbus-codegen`
    + Various bugs fixed.
    + Updated translations.

++++ kdump:

  - upgrade to version 2.0.17
    * fix bonding options (bsc#1235933)
    * don't use wicked to read bond and bridge config
    * prevent KDUMP_NET_TIMEOUT busy loop when DNS fails
    * limit dump file permissions (bsc#1237497, bsc#1237529)

++++ kernel-default:

  - Revert "mm/page_alloc.c: don't show protection in zone's
  - >lowmem_reserve[] for empty zone" (bsc#1237124).
  - commit 50e61e8
  - KVM: nVMX: Defer SVI update to vmcs01 on EOI when L2 is active
    w/o VID (git-fixes).
  - commit 0abcd2f
  - KVM: x86: Plumb in the vCPU to kvm_x86_ops.hwapic_isr_update()
    (git-fixes).
  - commit 24722f8
  - KVM: x86: Reject disabling of MWAIT/HLT interception when not
    allowed (git-fixes).
  - commit a3d8ac2
  - KVM: x86: Break CONFIG_KVM_X86's direct dependency on KVM_INTEL
    || KVM_AMD (git-fixes).
  - commit 0ad14bf
  - KVM: x86: add back X86_LOCAL_APIC dependency (git-fixes).
  - commit 32787b9
  - kernel: be more careful about dup_mmap() failures and uprobe
    registering (CVE-2025-21709 bsc#1237884).
  - commit 1a9b90a
  - vsock/virtio: fix variables initialization during resuming
    (git-fixes).
  - commit 2798352
  - virtio_net: ensure netdev_tx_reset_queue is called on tx ring
    resize (git-fixes).
  - commit 28a402c
  - ASoC: SOF: Intel: pci-ptl: Add support for PTL-H (stable-fixes).
  - ALSA: hda/realtek: Fix volume adjustment issue on Lenovo
    ThinkBook 16P Gen5 (stable-fixes).
  - ALSA: hda/realtek: fixup ASUS H7606W (stable-fixes).
  - ALSA: hda/realtek: fixup ASUS GA605W (stable-fixes).
  - ALSA: hda/realtek: Add new alc2xx-fixup-headset-mic model
    (stable-fixes).
  - commit 7116445
  - ALSA: hda/cirrus: Reduce codec resume time (stable-fixes).
  - ALSA: hda: hda-intel: add Panther Lake-H support (stable-fixes).
  - ALSA: hda: intel-dsp-config: Add PTL-H support (stable-fixes).
  - PCI: pci_ids: add INTEL_HDA_PTL_H (stable-fixes).
  - ALSA: hda/realtek: Limit mic boost on Positivo ARN50
    (stable-fixes).
  - ALSA: hda: Support for Ideapad hotkey mute LEDs (stable-fixes).
  - ALSA: hda: Add AZX_DCAPS_NO_TCSEL flag for Loongson HDA devices
    (stable-fixes).
  - ALSA: hda/realtek: Add support for Ayaneo System using CS35L41
    HDA (stable-fixes).
  - ALSA: hda/realtek - Add support for ASUS Zen AIO 27
    Z272SD_A272SD audio (stable-fixes).
  - commit 4e48fbb
  - sound: usb: format: don't warn that raw DSD is unsupported
    (stable-fixes).
  - sound: usb: enable DSD output for ddHiFi TC44C (stable-fixes).
  - commit da2e3f4
  - selftests/mm: fix check for running THP tests (git-fixes).
  - selftests: net/{lib,openvswitch}: extend CFLAGS to keep options
    from environment (git-fixes).
  - selftests: mptcp: extend CFLAGS to keep options from environment
    (git-fixes).
  - commit ab48ae5
  - ALSA: usb-audio: Re-add sample rate quirk for Pioneer
    DJM-900NXS2 (stable-fixes).
  - commit 7a3eb62
  - selftests: drv-net: Check if combined-count exists (git-fixes).
  - usbnet: gl620a: fix endpoint checking in genelink_bind()
    (git-fixes).
  - Bluetooth: L2CAP: Fix L2CAP_ECRED_CONN_RSP response (git-fixes).
  - net: phy: qcom: qca807x fix condition for DAC_DSP_BIAS_CURRENT
    (git-fixes).
  - ASoC: cs35l56: Prevent races when soft-resetting using SPI
    control (git-fixes).
  - firmware: cs_dsp: Remove async regmap writes (git-fixes).
  - ASoC: fsl: Rename stream name of SAI DAI driver (git-fixes).
  - ASoC: es8328: fix route from DAC to output (git-fixes).
  - ALSA: hda/realtek: Fix microphone regression on ASUS N705UD
    (git-fixes).
  - ALSA: hda/realtek: Fix wrong mic setup for ASUS VivoBook 15
    (git-fixes).
  - ALSA: usb-audio: Avoid dropping MIDI events at closing multiple
    ports (git-fixes).
  - drm/i915/dp: Fix error handling during 128b/132b link training
    (stable-fixes).
  - drm/i915: Make sure all planes in use by the joiner have their
    crtc included (stable-fixes).
  - drm/amdkfd: Ensure consistent barrier state saved in gfx12
    trap handler (stable-fixes).
  - drm/amdgpu: bump version for RV/PCO compute fix (stable-fixes).
  - drm/amdgpu/gfx9: manually control gfxoff for CS on RV
    (stable-fixes).
  - drm/amd/display: Correct register address in dcn35
    (stable-fixes).
  - drm/amdkfd: Move gfx12 trap handler to separate file
    (stable-fixes).
  - drm/amd/display: update dcn351 used clock offset (stable-fixes).
  - drm/amd/display: Refactoring if and endif statements to enable
    DC_LOGGER (stable-fixes).
  - drm/xe/oa: Add input fence dependencies (stable-fixes).
  - drm/xe/oa/uapi: Define and parse OA sync properties
    (stable-fixes).
  - drm/xe/oa: Separate batch submission from waiting for completion
    (stable-fixes).
  - commit dbc984f
  - virtio_ring: add a func argument 'recycle_done' to
    virtqueue_resize() (git-fixes).
  - commit 9d5dc5a

++++ kernel-firmware-ath10k:

  - Don't install superfluous info texts to firmware directory
  - Update license entry

++++ kernel-firmware-ath11k:

  - Update to version 20250227 (git commit 30f36b8b9053):
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02175-QCAHKSWPL_SILICONZ-2
    * ath11k: QCA6698AQ hw2.1: update to WLAN.HSP.1.1-04604-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: update board-2.bin
  - Don't install superfluous info files to firmware directory

++++ kernel-rt:

  - Revert "mm/page_alloc.c: don't show protection in zone's
  - >lowmem_reserve[] for empty zone" (bsc#1237124).
  - commit 50e61e8
  - KVM: nVMX: Defer SVI update to vmcs01 on EOI when L2 is active
    w/o VID (git-fixes).
  - commit 0abcd2f
  - KVM: x86: Plumb in the vCPU to kvm_x86_ops.hwapic_isr_update()
    (git-fixes).
  - commit 24722f8
  - KVM: x86: Reject disabling of MWAIT/HLT interception when not
    allowed (git-fixes).
  - commit a3d8ac2
  - KVM: x86: Break CONFIG_KVM_X86's direct dependency on KVM_INTEL
    || KVM_AMD (git-fixes).
  - commit 0ad14bf
  - KVM: x86: add back X86_LOCAL_APIC dependency (git-fixes).
  - commit 32787b9
  - kernel: be more careful about dup_mmap() failures and uprobe
    registering (CVE-2025-21709 bsc#1237884).
  - commit 1a9b90a
  - vsock/virtio: fix variables initialization during resuming
    (git-fixes).
  - commit 2798352
  - virtio_net: ensure netdev_tx_reset_queue is called on tx ring
    resize (git-fixes).
  - commit 28a402c
  - ASoC: SOF: Intel: pci-ptl: Add support for PTL-H (stable-fixes).
  - ALSA: hda/realtek: Fix volume adjustment issue on Lenovo
    ThinkBook 16P Gen5 (stable-fixes).
  - ALSA: hda/realtek: fixup ASUS H7606W (stable-fixes).
  - ALSA: hda/realtek: fixup ASUS GA605W (stable-fixes).
  - ALSA: hda/realtek: Add new alc2xx-fixup-headset-mic model
    (stable-fixes).
  - commit 7116445
  - ALSA: hda/cirrus: Reduce codec resume time (stable-fixes).
  - ALSA: hda: hda-intel: add Panther Lake-H support (stable-fixes).
  - ALSA: hda: intel-dsp-config: Add PTL-H support (stable-fixes).
  - PCI: pci_ids: add INTEL_HDA_PTL_H (stable-fixes).
  - ALSA: hda/realtek: Limit mic boost on Positivo ARN50
    (stable-fixes).
  - ALSA: hda: Support for Ideapad hotkey mute LEDs (stable-fixes).
  - ALSA: hda: Add AZX_DCAPS_NO_TCSEL flag for Loongson HDA devices
    (stable-fixes).
  - ALSA: hda/realtek: Add support for Ayaneo System using CS35L41
    HDA (stable-fixes).
  - ALSA: hda/realtek - Add support for ASUS Zen AIO 27
    Z272SD_A272SD audio (stable-fixes).
  - commit 4e48fbb
  - sound: usb: format: don't warn that raw DSD is unsupported
    (stable-fixes).
  - sound: usb: enable DSD output for ddHiFi TC44C (stable-fixes).
  - commit da2e3f4
  - selftests/mm: fix check for running THP tests (git-fixes).
  - selftests: net/{lib,openvswitch}: extend CFLAGS to keep options
    from environment (git-fixes).
  - selftests: mptcp: extend CFLAGS to keep options from environment
    (git-fixes).
  - commit ab48ae5
  - ALSA: usb-audio: Re-add sample rate quirk for Pioneer
    DJM-900NXS2 (stable-fixes).
  - commit 7a3eb62
  - selftests: drv-net: Check if combined-count exists (git-fixes).
  - usbnet: gl620a: fix endpoint checking in genelink_bind()
    (git-fixes).
  - Bluetooth: L2CAP: Fix L2CAP_ECRED_CONN_RSP response (git-fixes).
  - net: phy: qcom: qca807x fix condition for DAC_DSP_BIAS_CURRENT
    (git-fixes).
  - ASoC: cs35l56: Prevent races when soft-resetting using SPI
    control (git-fixes).
  - firmware: cs_dsp: Remove async regmap writes (git-fixes).
  - ASoC: fsl: Rename stream name of SAI DAI driver (git-fixes).
  - ASoC: es8328: fix route from DAC to output (git-fixes).
  - ALSA: hda/realtek: Fix microphone regression on ASUS N705UD
    (git-fixes).
  - ALSA: hda/realtek: Fix wrong mic setup for ASUS VivoBook 15
    (git-fixes).
  - ALSA: usb-audio: Avoid dropping MIDI events at closing multiple
    ports (git-fixes).
  - drm/i915/dp: Fix error handling during 128b/132b link training
    (stable-fixes).
  - drm/i915: Make sure all planes in use by the joiner have their
    crtc included (stable-fixes).
  - drm/amdkfd: Ensure consistent barrier state saved in gfx12
    trap handler (stable-fixes).
  - drm/amdgpu: bump version for RV/PCO compute fix (stable-fixes).
  - drm/amdgpu/gfx9: manually control gfxoff for CS on RV
    (stable-fixes).
  - drm/amd/display: Correct register address in dcn35
    (stable-fixes).
  - drm/amdkfd: Move gfx12 trap handler to separate file
    (stable-fixes).
  - drm/amd/display: update dcn351 used clock offset (stable-fixes).
  - drm/amd/display: Refactoring if and endif statements to enable
    DC_LOGGER (stable-fixes).
  - drm/xe/oa: Add input fence dependencies (stable-fixes).
  - drm/xe/oa/uapi: Define and parse OA sync properties
    (stable-fixes).
  - drm/xe/oa: Separate batch submission from waiting for completion
    (stable-fixes).
  - commit dbc984f
  - virtio_ring: add a func argument 'recycle_done' to
    virtqueue_resize() (git-fixes).
  - commit 9d5dc5a

++++ at-spi2-core:

  - Update to version 2.55.90 (Unstable):
    + Support grabbing keyboard shortcuts through the new
    org.freedesktop.a11y.KeyboardMonitor interface. This allows key
    grabs to be supported under Wayland with the latest mutter.

++++ libzypp:

  - Add a transaction package preloader (fixes openSUSE/zypper#104)
    This patch adds a preloader that concurrently downloads files
    during a transaction commit. It's not yet enabled per default.
    To enable the preview set ZYPP_CURL2=1 and ZYPP_PCK_PRELOAD=1
    in the environment.
  - RpmPkgSigCheck_test: Exchange the test package signingkey
    (fixes #622)
  - Exclude MediaCurl tests if DISABLE_MEDIABACKEND_TESTS (fixes #626)
  - Strip a mediahandler tag from baseUrl querystrings.
  - version 17.36.4 (35)

++++ mdadm:

  - mdopen: add sbin path to env PATH when call system("modprobe md_mod")
    (bsc#1233265)
    add 0010-mdopen-add-sbin-path-to-env-PATH-when-call-system-mo.patch

++++ qemu:

  - Update to latest upstream release, 9.2.2:
    The full list of changes are available at:
    https://lore.kernel.org/qemu-devel/3e847ae0-8dfc-440e-92f7-6eaa89818837@tls.msk.ru/
    Highlights include:
    * net/slirp: libslirp 4.9.0 compatibility
    * target/sparc: Fix gdbstub incorrectly handling registers f32-f62
    * target/sparc: Fix register selection for all F*TOx and FxTO* instructions
    * elfload: Fix alignment when unmapping excess reservation
    * hw/net/smc91c111: Ignore attempt to pop from empty RX fifo
    * make-release: don't rely on $CWD when excluding subproject directories
    * ui/sdl2: reenable the SDL2 Windows keyboard hook procedure
    * vfio/iommufd: Fix SIGSEV in iommufd_cdev_attach()
    * gitlab-ci.d/cirrus: Update the FreeBSD job to v14.2
    * qmp: update vhost-user protocol feature maps
    * linux-user: Do not define struct sched_attr if libc headers do
    * block-backend: Fix argument order when calling 'qapi_event_send_block_io_error()'
    * block: Fix leak in send_qmp_error_event
    * rust: add --rust-target option for bindgen
    * ...
  - Fix bsc#1237603:
    * linux-user: Do not define struct sched_attr if libc headers do

++++ skopeo:

  - Add patch for CVE-2025-27144 (bsc#1237613)
    Add patch:
    * 0003-Don-t-allow-unbounded-amounts-of-splits-https-github.patch
    Rebase patches:
    * 0001-http2-close-connections-when-receiving-too-many-head.patch
    * 0002-Switch-hashicorp-go-retryablehttp-to-the-SUSE-fork.patch

++++ zypper:

  - Package preloader that concurrently downloads files. It's not yet
    enabled per default. To enable the preview set ZYPP_CURL2=1 and
    ZYPP_PCK_PRELOAD=1 in the environment. (#104)
  - BuildRequires:  libzypp-devel >= 17.36.4.
  - version 1.14.87

------------------------------------------------------------------
------------------  2025-2-27  -  Feb 27 2025  -------------------
------------------------------------------------------------------

++++ lvm2-device-mapper:

  - fixing HA16.0 Product building issues for packages: lvm2-lockd, cluster-md, dlm, drbd (bsc#1237701)
    * update lvm2.spec

++++ kernel-default:

  - netfilter: nft_inner: incorrect percpu area handling under
    softirq (CVE-2024-56638 bsc#1235524).
  - commit c4eaec2
  - ptr_ring: do not block hard interrupts in
    ptr_ring_resize_multiple() (CVE-2024-57994 bsc#1237901).
  - commit eb91bfe
  - printk: Fix signed integer overflow when defining
    LOG_BUF_LEN_MAX (bsc#1237950).
  - commit 2864e46
  - add nf_tables for iptables non-legacy network handling
    This is needed for example by docker on the Alpine Linux distribution,
    but can also be used on openSUSE.
  - commit f9b0903
  - tcp: Fix use-after-free of nreq in reqsk_timer_handler()
    (CVE-2024-53206 bsc#1234960).
  - commit 1d4fc49
  - workqueue: Put the pwq after detaching the rescuer from the pool
    (bsc#1237866).
  - commit 7f68bba

++++ kernel-rt:

  - netfilter: nft_inner: incorrect percpu area handling under
    softirq (CVE-2024-56638 bsc#1235524).
  - commit c4eaec2
  - ptr_ring: do not block hard interrupts in
    ptr_ring_resize_multiple() (CVE-2024-57994 bsc#1237901).
  - commit eb91bfe
  - printk: Fix signed integer overflow when defining
    LOG_BUF_LEN_MAX (bsc#1237950).
  - commit 2864e46
  - add nf_tables for iptables non-legacy network handling
    This is needed for example by docker on the Alpine Linux distribution,
    but can also be used on openSUSE.
  - commit f9b0903
  - tcp: Fix use-after-free of nreq in reqsk_timer_handler()
    (CVE-2024-53206 bsc#1234960).
  - commit 1d4fc49
  - workqueue: Put the pwq after detaching the rescuer from the pool
    (bsc#1237866).
  - commit 7f68bba

++++ gmp:

  - Manually select the z13/z14 architecture level specific assembly routines
    for s390x and SLFO since GMP lacks fat binary support there and also lacks
    a way to auto-detect the architecture level used at compile-time.
    [jsc#PED-3270]

++++ lvm2:

  - fixing HA16.0 Product building issues for packages: lvm2-lockd, cluster-md, dlm, drbd (bsc#1237701)
    * update lvm2.spec

++++ zchunk:

  - Update to 1.5.1:
    * Stop storing last error when missing zchunk context
    * More statistics in zchunk_delta_info
    * Various memory leak fixes
    * Better support for OpenSSL 3.x
    * Various bug fixes
  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang_path macro, [bsc#1212476]
  - update to 1.5.7:
    * zstd now employs multiple threads by default
    * Fix a rare bug in 32-bit mode
    * Enhanced Compression Speed for Small Data Blocks
    * Substantial --patch-from performance improvements
  - Drop pzstd.1.patch - not upstream, but also not needed
  - Changes between 1.5.5 and 1.5.6:
    * Introduce a new stable parameter ZSTD_c_targetCBlockSize,
    enabling the division of blocks into smaller segments to
    enhance initial byte delivery speed for congested networks
    * library allows allow ganular binary size selection

++++ libzypp:

  - Disable zypp.conf:download.use_deltarpm by default (fixes #620)
    Measurements show that you don't benefit from using deltarpms
    unless your network connection is very slow. That's why most
    distributions even stop offering deltarpms. The default remains
    unchanged on SUSE-15.6 and older.
  - Make sure repo variables are evaluated in the right context
    (bsc#1237044)
  - Introducing MediaCurl2 a alternative HTTP backend.
    This patch adds MediaCurl2 as a testbed for experimenting with a
    more simple way to download files. Set ZYPP_CURL2=1 in the
    environment to use it.
  - version 17.36.3 (35)

++++ makedumpfile:

  - Update to 1.7.5:
    * Support for kernels up to v6.11 (x86_64)
  - Drop upstreamed patches:
    * 0001-PATCH-Fix-failure-of-hugetlb-pages-exclusion-on-Linu.patch
    * 0002-PATCH-Fix-wrong-exclusion-of-Slab-pages-on-Linux-6.1.patch
    * make-reserve_diskspace-do-nothing-for-flattened-form.patch
  - makedumpfile-fix-detection-of-typed-compound-pages-Linux-6.12.patch:
    Reflect mm changes in kernel v6.12 (bsc#1237269).

++++ mdadm:

  - Update to version 4.4 (jsc#PED-10220)
    Features:
    * Remove custom bitmap file support from Yu Kuai.
    * Custom device policies implementation from Mariusz Tkaczyk.
    * Self encrypted drives (**SED**) support for IMSM metadata from Blazej Kucman.
    * Support more than 4 disks for **IMSM** RAID10 from Mateusz Kusiak.
    * Read **IMSM** license information from ACPI tables from Blazej Kucman.
    * Support devnode in **--Incremental --remove** from Mariusz Tkaczyk.
    * Printing **IMSM** license type in **--detail-platform** from Blazej Kucman.
    * README.md from Mariusz Tkaczyk and Anna Sztukowska.
    Fixes:
    * Tests improvements from Xiao Ni and Kinga Stefaniuk.
    * Mdmon's Checkpointing improvements from Mateusz Kusiak.
    * Pass mdadm environment flags to systemd-env to enable tests from Mateusz Kusiak.
    * Superblock 1.0 uuid printing fixes from Mariusz Tkaczyk.
    * Find VMD bus manually if link is not available from Mariusz Tkaczyk.
    * Unconditional devices count printing in --detail from Anna Sztukowska.
    * Improve SIGTERM handling during reshape, from Mateusz Kusiak.
    * **Monitor.c** renamed to **Mdmonitor.c** from Kinga Stefaniuk.
    * Mdmonitor service documentation update from Mariusz Tkaczyk.
    * Rework around writing to sysfs files from Mariusz Tkaczyk.
    * Drop of HOT_REMOVE_DISK ioctl in Manage in favour of sysfs from Mariusz Tkaczyk.
    * Delegate disk removal to managemon from Mariusz Tkaczyk.
    * Some clean-ups of legacy code and functionalities like **--auto=md** from Mariusz Tkaczyk.
    * Manual clean-up, references to old kernels removed from Mariusz Tkaczyk.
    * Various static code analysis fixes.
  - Add 1000-Revert-mdmonitor-Abandon-custom-configuration-files.patch
    (reverts upstream change to ignore /etc/sysconfig/mdadm)
  - Drop obsolete patches (included upstream):
    * Del 0001-Remove-hardcoded-checkpoint-interval-checking.patch
    * Del 0002-monitor-refactor-checkpoint-update.patch
    * Del 0003-Super-intel-Fix-first-checkpoint-restart.patch
    * Del 0004-Grow-Move-update_tail-assign-to-Grow_reshape.patch
    * Del 0005-Add-understanding-output-section-in-man.patch
    * Del 0006-util.c-change-devnm-to-const-in-mdmon-functions.patch
    * Del 0007-Wait-for-mdmon-when-it-is-stared-via-systemd.patch
    * Del 0008-Detail-remove-duplicated-code.patch
    * Del 0009-mdadm-Fix-native-detail-export.patch
  - Use obs_scm for code maintenance

++++ microos-tools:

  - Update to version 4.0+git7:
    * Only autorelabel local filesystems with SELinux support (boo#1237202)

++++ osinfo-db:

  - Modify SLES and Leap 16 database entries to define new volume id
    of Agama 12 ISOs (bsc#1236401)
    add-sles16-support.patch
    add-opensuse-leap-16.0-support.patch

++++ virt-manager:

  - Remove unneeded Requires on python3-ipaddr.

++++ zypper:

  - refresh: add --include-all-archs (fixes #598)
    Future multi-arch repos may allow to download only those metadata
    which refer to packages actually compatible with the systems
    architecture. Some tools however want zypp to provide the full
    metadata of a repository without filtering incompatible
    architectures.
  - info,search: add option to search and list Enhances
    (bsc#1237949)
  - version 1.14.86
  - Annonunce --root in commands not launching a Target
    (bsc#1237044)
  - BuildRequires:  libzypp-devel >= 17.36.3.
  - version 1.14.85

------------------------------------------------------------------
------------------  2025-2-26  -  Feb 26 2025  -------------------
------------------------------------------------------------------

++++ conmon:

  - New upstream release 2.1.13
    [#]## Bug fixes
    * Make timestamp generation never fail.
    * Change permissions of logs from 0600 to 0640
    * Avoid bogus journal filling errors
    * Fix typos and clarify man page.
    * conmon: do not create oom file under cwd
    * logging: remove unuseful fsync

++++ dhcpcd:

  - Update to 10.2.2
    * DHCP6: Fix dhcpcd vendor class option
    * options: Allow interface block to be pattern matching

++++ python-kiwi:

  - Bump version: 10.2.11 → 10.2.12
  - Fix profile env variable name regression
    In the effort of adapting to the latest snapper in Issue #2697
    we overlooked the after effect of a different variable name
    in the profile environment with regards to $kiwi_btrfs_root_is_snapshot
    and $kiwi_btrfs_root_is_snapper_snapshot. Image builds that
    references the former variable name would be broken by the change.
    This commit makes sure no regression is introduced by providing
    both variants. This Fixes bsc#1237772

++++ gettext-runtime:

  - Fix crash while handling po files with malformed header and
    process them properly
    (0003-Fix-malformed-header-processing.patch, boo#1227316).

++++ glibc:

  - Bump minimal kernel version to 4.3 to enable use of direct socketcalls
    on x86-32 and s390x (bsc#1234713)

++++ gpg2:

  - Fixing gpg-agent integration by changing --supervised to
  - -deprecated-supervised in service files.

++++ kernel-default:

  - kernel-source: Also replace bin/env
  - commit dc2037c
  - RDMA/mlx5: Fix bind QP error cleanup flow (git-fixes)
  - commit 789f3e9
  - RDMA/mlx5: Fix AH static rate parsing (git-fixes)
  - commit 9b914e2
  - RDMA/mlx5: Fix implicit ODP hang on parent deregistration (git-fixes)
  - commit 094971b
  - RDMA/hns: Fix mbox timing out by adding retry mechanism (git-fixes)
  - commit d95c6ee
  - RDMA/mlx5: Fix a WARN during dereg_mr for DM type (git-fixes)
  - commit f0da614
  - RDMA/mlx5: Fix a race for DMABUF MR which can lead to CQE with error (git-fixes)
  - commit a39ffd1
  - IB/mlx5: Set and get correct qp_num for a DCT QP (git-fixes)
  - commit d33e08b
  - RDMA/mlx5: Fix the recovery flow of the UMR QP (git-fixes)
  - commit 868f8b2
  - RDMA/efa: Reset device on probe failure (git-fixes)
  - commit 6c8b3e4
  - media: uvcvideo: Fix deadlock during uvc_probe (git-fixes).
  - commit c3f3457
  - md: Fix linear_set_limits() (git-fixes).
  - md/md-linear: Fix a NULL vs IS_ERR() bug in linear_add()
    (git-fixes).
  - commit 7025de8

++++ kernel-rt:

  - kernel-source: Also replace bin/env
  - commit dc2037c
  - RDMA/mlx5: Fix bind QP error cleanup flow (git-fixes)
  - commit 789f3e9
  - RDMA/mlx5: Fix AH static rate parsing (git-fixes)
  - commit 9b914e2
  - RDMA/mlx5: Fix implicit ODP hang on parent deregistration (git-fixes)
  - commit 094971b
  - RDMA/hns: Fix mbox timing out by adding retry mechanism (git-fixes)
  - commit d95c6ee
  - RDMA/mlx5: Fix a WARN during dereg_mr for DM type (git-fixes)
  - commit f0da614
  - RDMA/mlx5: Fix a race for DMABUF MR which can lead to CQE with error (git-fixes)
  - commit a39ffd1
  - IB/mlx5: Set and get correct qp_num for a DCT QP (git-fixes)
  - commit d33e08b
  - RDMA/mlx5: Fix the recovery flow of the UMR QP (git-fixes)
  - commit 868f8b2
  - RDMA/efa: Reset device on probe failure (git-fixes)
  - commit 6c8b3e4
  - media: uvcvideo: Fix deadlock during uvc_probe (git-fixes).
  - commit c3f3457
  - md: Fix linear_set_limits() (git-fixes).
  - md/md-linear: Fix a NULL vs IS_ERR() bug in linear_add()
    (git-fixes).
  - commit 7025de8

++++ pcr-oracle:

  - Add fix-bsc1230316-predict-sbatlevelrt.patch to predict
    SbatLevelRT for the next boot (bsc#1230316)

++++ python-cryptography:

  - update to 44.0.1:
    * Updated Windows, macOS, and Linux wheels to be compiled with
    OpenSSL 3.4.1.
    * We now build armv7l manylinux wheels and publish them to
    PyPI.
    * We now build manylinux_2_34 wheels and publish them to PyPI.

------------------------------------------------------------------
------------------  2025-2-25  -  Feb 25 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix grub mkimage call for the ppc platform
    The list of modules used to create a grub platform image for
    ppc was the same list as used for the x86 bios platform.
    This commit fixes this and also cleans up the inconsistency
    and misleading names used for creating platform specific
    output. This Fixes #2738

++++ grub2:

  - Make SLFO/SLE-16 and openSUSE have identical package structures
  - Provide grub2-<CPUARCH>-efi-bls for SLFO/SLE-16

++++ kernel-default:

  - Refresh
    patches.suse/btrfs-provide-super_operations-get_inode_dev.
  - Refresh patches.suse/vfs-add-super_operations-get_inode_dev.
    We want to keep these two patches. See bsc#1237035.
  - commit b446678
  - media: videobuf2-core: update vb2_thread if wait_finish/prepare
    are NULL (jsc#PED-10929).
  - commit 10a1fa2
  - media: platform: video-mux: Fix mutex locking (jsc#PED-10929
    jsc#PED-10931).
  - commit dadd533
  - media: ipu6: fix the wrong type casting and 64-bit division
    (jsc#PED-10931).
  - commit 2627941
  - v4l2-subdev: Return -EOPNOTSUPP for unsupported pad type in
    call_get_frame_desc() (jsc#PED-10929).
  - commit 030d5b9
  - media: uapi: Add meta formats for PiSP FE config and stats
    (jsc#PED-10929).
  - commit 802cc52
  - crypto: ccp - Fix check for the primary ASP device
    (bsc#1237400).
  - commit 96d9d45
  - supported.conf: Mark Intel Xe DRM driver as supported (jsc#PED-10927)
  - commit e99dd3a
  - media: tda18271: add missing result checking of
    tda18271_lookup_map() (git-fixes).
  - commit 8360f5e
  - media: video-i2c: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 76ce583
  - media: rcar_drif.c: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 6c43c80
  - media: airspy: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit d204d85
  - media: hackrf: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 0cf29c8
  - media: msi2500: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 78a851d
  - media: pwc: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 88e95f0
  - media: v4l2-core: add v4l2_debugfs_root() (jsc#PED-10929).
  - commit cae4a2c
  - media: uvcvideo: Avoid race condition during unregister
    (git-fixes).
  - commit f90251c
  - media: uvcvideo: Refactor the status irq API (git-fixes).
  - commit fbb3682
  - config: update with run_oldconfig.sh
  - commit 6dd51d0
  - Revert "stackleak: disable stack erasing by default (jsc#PED-11837)."
    References: bsc#1236639
    This reverts commit 25d95db331f571abeffc51daf9daa6219b4e2925.
  - commit 84b2605
  - Revert "config: enable CONFIG_GCC_PLUGIN_STACKLEAK"
    References: bsc#1236639
    This reverts commit 8cf8a171b158d71a7c9aed37d0a2ddc905d92ad3.
  - commit f7b80f9
  - media: uvcvideo: Add support for the D3DFMT_R5G6B5 pixmap type
    (jsc#PED-10929).
  - commit a17e732
  - media: uvcvideo: Add luma 16-bit interlaced pixel format
    (jsc#PED-10929).
  - commit 1f638e3
  - seqlock: annotate spinning as unlikely() in
    __read_seqcount_begin (bsc#1234634 (Scheduler functional and
    performance backports)).
  - commit a946846
  - usb: storage: fix wrong comments for struct bulk_cb_wrap
    (git-fixes).
  - fs_parser: update mount_api doc to match function signature
    (git-fixes).
  - media: v4l: Add luma 16-bit interlaced pixel format
    (jsc#PED-10929).
  - commit 33206f5
  - sysctl: remove kernel.stack_erase
    References: bsc#1236639
    Commit 25d95db331f5 ("stackleak: disable stack erasing by default (jsc#PED-11837)")
    changed the default state of kernel.stack_erase to 0. There is no need
    to do the same in the sysctl/defaults.
  - commit 5dfd8de
  - usb: dwc3: st: Switch from CONFIG_PM_SLEEP guards to
    pm_sleep_ptr() (jsc#PED-10596).
  - commit a7ea25c
  - usb: dwc3: gadget: Reinitiate stream for all host NoStream
    behavior (jsc#PED-10596).
  - commit df9c212
  - supported.conf: typec_thunderbolt: fix syntax
    Remove '+' from the start of the line as it causes kbuild failures
  - commit 7b2bf44

++++ kernel-default-base:

  - Add 9p with support for virtio and xen

++++ kernel-firmware-realtek:

  - Update to version 20250224 (git commit 1a1470d90de2):
    * rtw89: 8852bt: update fw to v0.29.122.0 and BB parameter to 07

++++ kernel-rt:

  - Refresh
    patches.suse/btrfs-provide-super_operations-get_inode_dev.
  - Refresh patches.suse/vfs-add-super_operations-get_inode_dev.
    We want to keep these two patches. See bsc#1237035.
  - commit b446678
  - media: videobuf2-core: update vb2_thread if wait_finish/prepare
    are NULL (jsc#PED-10929).
  - commit 10a1fa2
  - media: platform: video-mux: Fix mutex locking (jsc#PED-10929
    jsc#PED-10931).
  - commit dadd533
  - media: ipu6: fix the wrong type casting and 64-bit division
    (jsc#PED-10931).
  - commit 2627941
  - v4l2-subdev: Return -EOPNOTSUPP for unsupported pad type in
    call_get_frame_desc() (jsc#PED-10929).
  - commit 030d5b9
  - media: uapi: Add meta formats for PiSP FE config and stats
    (jsc#PED-10929).
  - commit 802cc52
  - crypto: ccp - Fix check for the primary ASP device
    (bsc#1237400).
  - commit 96d9d45
  - supported.conf: Mark Intel Xe DRM driver as supported (jsc#PED-10927)
  - commit e99dd3a
  - media: tda18271: add missing result checking of
    tda18271_lookup_map() (git-fixes).
  - commit 8360f5e
  - media: video-i2c: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 76ce583
  - media: rcar_drif.c: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 6c43c80
  - media: airspy: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit d204d85
  - media: hackrf: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 0cf29c8
  - media: msi2500: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 78a851d
  - media: pwc: set lock before calling vb2_queue_init()
    (jsc#PED-10929).
  - commit 88e95f0
  - media: v4l2-core: add v4l2_debugfs_root() (jsc#PED-10929).
  - commit cae4a2c
  - media: uvcvideo: Avoid race condition during unregister
    (git-fixes).
  - commit f90251c
  - media: uvcvideo: Refactor the status irq API (git-fixes).
  - commit fbb3682
  - config: update with run_oldconfig.sh
  - commit 6dd51d0
  - Revert "stackleak: disable stack erasing by default (jsc#PED-11837)."
    References: bsc#1236639
    This reverts commit 25d95db331f571abeffc51daf9daa6219b4e2925.
  - commit 84b2605
  - Revert "config: enable CONFIG_GCC_PLUGIN_STACKLEAK"
    References: bsc#1236639
    This reverts commit 8cf8a171b158d71a7c9aed37d0a2ddc905d92ad3.
  - commit f7b80f9
  - media: uvcvideo: Add support for the D3DFMT_R5G6B5 pixmap type
    (jsc#PED-10929).
  - commit a17e732
  - media: uvcvideo: Add luma 16-bit interlaced pixel format
    (jsc#PED-10929).
  - commit 1f638e3
  - seqlock: annotate spinning as unlikely() in
    __read_seqcount_begin (bsc#1234634 (Scheduler functional and
    performance backports)).
  - commit a946846
  - usb: storage: fix wrong comments for struct bulk_cb_wrap
    (git-fixes).
  - fs_parser: update mount_api doc to match function signature
    (git-fixes).
  - media: v4l: Add luma 16-bit interlaced pixel format
    (jsc#PED-10929).
  - commit 33206f5
  - sysctl: remove kernel.stack_erase
    References: bsc#1236639
    Commit 25d95db331f5 ("stackleak: disable stack erasing by default (jsc#PED-11837)")
    changed the default state of kernel.stack_erase to 0. There is no need
    to do the same in the sysctl/defaults.
  - commit 5dfd8de
  - usb: dwc3: st: Switch from CONFIG_PM_SLEEP guards to
    pm_sleep_ptr() (jsc#PED-10596).
  - commit a7ea25c
  - usb: dwc3: gadget: Reinitiate stream for all host NoStream
    behavior (jsc#PED-10596).
  - commit df9c212
  - supported.conf: typec_thunderbolt: fix syntax
    Remove '+' from the start of the line as it causes kbuild failures
  - commit 7b2bf44

++++ libarchive:

  - Fix CVE-2024-57970, heap-based buffer over-read in header_gnu_longlink
    because it mishandles truncation (CVE-2024-57970, bsc#1237233)
    * CVE-2024-57970.patch

++++ freetype2:

  - update to 2.13.3:
    * Some  fields in the `FT_Outline` structure have been changed
    from signed to unsigned type, which better reflects the actual
    usage. It is also an additional means to protect against
    malformed input.
    * Rare double-free crashes in the cache subsystem have been fixed.
    * Excessive stack allocation in the autohinter has been fixed.
    * The B/W  rasterizer has received a major upkeep that results in
    large performance improvements.  The rendering speed has
    increased and even doubled for very complex glyphs.

++++ ncurses:

  - Add ncurses patch 20250222
    + modify treatment of "n" parameter for waddnstr, waddnwstr, and
    wins_nwstr to return OK when "n" is zero, for consistency with other
    implementations (report by Benjamin Barenblat, cf: 20231118).
    + formatting improvements for terminfo.5 (Debian #1096164).

++++ open-vm-tools:

  - Revert previous change (Thu Feb 20 23:08:43 UTC 2025).  The proposed
    solutions was non-standard.

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.124.04 (boo#1237585)

++++ python-setuptools:

  - update to 75.8.0:
    * Implemented Dynamic field for core metadata (as introduced in
    PEP 643). The existing implementation is currently
    experimental and the exact approach may change in future
    releases.
    * Synced with pypa/distutils@c97a3db2f including better support
    for free threaded Python on Windows (pypa/distutils#310),
    improved typing support, and linter accommodations.
    * Synced with pypa/distutils@ff11eed0c including bugfix for
    duplicate CFLAGS and adaption to support Python 3.13 is_abs
    in the C compiler (#4669).

++++ selinux-policy:

  - Update to version 20240604+git813.a995c5c8:
    * Label /run/systemd/pcrlock.json systemd_pcrlock_var_lib_t
    * systemd_pcrlock_t needs to filetrans when recreating /var/lib/pcrlock.d
    * Allow snapper access to keys
    * Add rules for pcrlock (bsc#1233358)
    * allow snapper to call pcrlock and manage its files
    * allow unconfined_t to execute pcrlock
    * label rules for default systemd_pcrlock_var_lib_t locations
    * new interfaces: systemd_domtrans_pcrlock and systemd_pcrlock_exec
    * introduce systemd_pcrlock_var_lib_t and systemd_manage_pcrlock_files
    * Introduce interfaces snapper_manage_tmp_files and snapper_manage_tmp_dirs

------------------------------------------------------------------
------------------  2025-2-24  -  Feb 24 2025  -------------------
------------------------------------------------------------------

++++ bash:

  - Explicitly specify that the build recipe needs bash

++++ bash-completion:

  - Drop completions for kmod; kmod>=34 provides its own now.

++++ cockpit:

  - fix build with latest local-npm-registry

++++ dhcpcd:

  - Update to 10.2.1
    * Fix building with different options
    * Only drop IPv4 LL addresses if configured to handle them

++++ gnutls:

  - Update to 3.8.9:
  - libgnutls: leancrypto was added as an interim option for PQC
    The library can now be built with leancrypto instead of liboqs for
    post-quantum cryptography (PQC), when configured with
  - -with-leancrypto option instead of --with-liboqs.
  - libgnutls: Experimental support for ML-DSA signature algorithm
    The library and certtool now support ML-DSA signature algorithm as
    defined in FIPS 204 and based on
    draft-ietf-lamps-dilithium-certificates-04. This feature is
    currently marked as experimental and can only be enabled when
    compiled with --with-leancrypto or --with-liboqs.
    Contributed by David Dudas.
  - libgnutls: Support for ML-KEM-1024 key encapsulation mechanism
    The support for ML-KEM post-quantum key encapsulation mechanisms
    has been extended to cover ML-KEM-1024, in addition to ML-KEM-768.
    MLKEM1024 is only offered as SecP384r1MLKEM1024 hybrid as per
    draft-kwiatkowski-tls-ecdhe-mlkem-03.
  - libgnutls: Fix potential DoS in handling certificates with numerous name
    constraints, as a follow-up of CVE-2024-12133 in libtasn1. The
    bundled copy of libtasn1 has also been updated to the latest 4.20.0
    release to complete the fix.  Reported by Bing Shi (#1553).
    [GNUTLS-SA-2025-02-07, CVSS: medium] [bsc#1236974, CVE-2024-12243
  - Licensing information moved to REAMDE.md, COPYING, COPYING.LESSERv2
    * Rebased gnutls-FIPS-140-3-references.patch
    * Rebased gnutls-FIPS-TLS_KDF_selftest.patch
    * Rebased gnutls-FIPS-jitterentropy.patch
    * Rebased gnutls-disable-flaky-test-dtls-resume.patch
    * Rebased gnutls-srp-test-SIGPIPE.patch
    * Rebased gnutls-3.5.11-skip-trust-store-tests.patch
    * Add gnutls-set-cligen-python-interp.patch
    * Add gnutls-skip-pqx-test.patch

++++ kernel-default:

  - md/md-bitmap: Synchronize bitmap_get_stats() with bitmap
    lifetime (git-fixes).
  - md/md-bitmap: move bitmap_{start, end}write to md upper layer
    (git-fixes).
  - md/raid5: implement pers->bitmap_sector() (git-fixes).
  - md: add a new callback pers->bitmap_sector() (git-fixes).
  - md/md-bitmap: remove the last parameter for
    bimtap_ops->endwrite() (git-fixes).
  - md/md-bitmap: factor behind write counters out from
    bitmap_{start/end}write() (git-fixes).
  - commit 4ada1e0
  - md: reintroduce md-linear (git-fixes).
  - Update config files.
  - commit f99cccf
  - usb: dwc3: gadget: Fix incorrect UDC state after manual
    deconfiguration (git-fixes).
  - commit befc60a
  - usb: dwc3: core: Disable USB2 retry for DWC_usb31 1.80a and
    prior (jsc#PED-10596).
  - commit 8b10560
  - usb: dwc3: remove unused sg struct member (jsc#PED-10596).
  - commit 7e4c228
  - usb: dwc3: gadget: Remove dwc3_request->needs_extra_trb
    (jsc#PED-10596).
  - commit afb0887
  - usb: dwc3: gadget: Cleanup SG handling (jsc#PED-10596).
  - commit c49703b
  - usb: dwc3: core: Set force_gen1 bit for all applicable
    SuperSpeed ports (jsc#PED-10596).
  - commit 288dd0b
  - usb: dwc3: gadget: Refine the logic for resizing Tx FIFOs
    (jsc#PED-10596).
  - Refresh
    patches.suse/usb-dwc3-gadget-Add-missing-check-for-single-port-RA.patch.
  - commit 7ccfe71
  - Update
    patches.suse/usb-Switch-back-to-struct-platform_driver-remove.patch
    (jsc#PED-10906 jsc#PED-10596).
  - commit 467bf03
  - s390/boot: Fix ESSA detection (git-fixes bsc#1237566).
  - commit 1f84598
  - thunderbolt: debugfs: Implement Gen 4 margining eye selection
    (jsc#PED-10603).
  - commit 759b7a2
  - thunderbolt: debugfs: Add USB4 Gen 4 margining capabilities
    (jsc#PED-10603).
  - commit 29dbb78
  - thunderbolt: Don't hardcode margining capabilities size
    (jsc#PED-10603).
  - commit 945d1a2
  - cgroup: Remove steal time from usage_usec (bsc#1237560).
  - cgroup: fix race between fork and cgroup.kill (bsc#1237559).
  - blk-cgroup: Fix class @block_class's subsystem refcount leakage
    (bsc#1237558).
  - commit 17c1245
  - series: enabled downstream patches for storage again
  - Refresh
    patches.suse/blk-kabi-add-suse_kabi_padding-to-blk-layer-structs.patch.
  - Refresh
    patches.suse/nvme-tcp-do-not-terminate-commands-when-in-resetting.patch.
  - Refresh
    patches.suse/scsi-kabi-add-suse_kabi_padding-to-scsi-template-structs.patch.
  - commit 152726d
  - x86/cpu/kvm: SRSO: Fix possible missing IBPB on VM-Exit (git-fixes).
  - commit 37d1575

++++ kernel-rt:

  - md/md-bitmap: Synchronize bitmap_get_stats() with bitmap
    lifetime (git-fixes).
  - md/md-bitmap: move bitmap_{start, end}write to md upper layer
    (git-fixes).
  - md/raid5: implement pers->bitmap_sector() (git-fixes).
  - md: add a new callback pers->bitmap_sector() (git-fixes).
  - md/md-bitmap: remove the last parameter for
    bimtap_ops->endwrite() (git-fixes).
  - md/md-bitmap: factor behind write counters out from
    bitmap_{start/end}write() (git-fixes).
  - commit 4ada1e0
  - md: reintroduce md-linear (git-fixes).
  - Update config files.
  - commit f99cccf
  - usb: dwc3: gadget: Fix incorrect UDC state after manual
    deconfiguration (git-fixes).
  - commit befc60a
  - usb: dwc3: core: Disable USB2 retry for DWC_usb31 1.80a and
    prior (jsc#PED-10596).
  - commit 8b10560
  - usb: dwc3: remove unused sg struct member (jsc#PED-10596).
  - commit 7e4c228
  - usb: dwc3: gadget: Remove dwc3_request->needs_extra_trb
    (jsc#PED-10596).
  - commit afb0887
  - usb: dwc3: gadget: Cleanup SG handling (jsc#PED-10596).
  - commit c49703b
  - usb: dwc3: core: Set force_gen1 bit for all applicable
    SuperSpeed ports (jsc#PED-10596).
  - commit 288dd0b
  - usb: dwc3: gadget: Refine the logic for resizing Tx FIFOs
    (jsc#PED-10596).
  - Refresh
    patches.suse/usb-dwc3-gadget-Add-missing-check-for-single-port-RA.patch.
  - commit 7ccfe71
  - Update
    patches.suse/usb-Switch-back-to-struct-platform_driver-remove.patch
    (jsc#PED-10906 jsc#PED-10596).
  - commit 467bf03
  - s390/boot: Fix ESSA detection (git-fixes bsc#1237566).
  - commit 1f84598
  - thunderbolt: debugfs: Implement Gen 4 margining eye selection
    (jsc#PED-10603).
  - commit 759b7a2
  - thunderbolt: debugfs: Add USB4 Gen 4 margining capabilities
    (jsc#PED-10603).
  - commit 29dbb78
  - thunderbolt: Don't hardcode margining capabilities size
    (jsc#PED-10603).
  - commit 945d1a2
  - cgroup: Remove steal time from usage_usec (bsc#1237560).
  - cgroup: fix race between fork and cgroup.kill (bsc#1237559).
  - blk-cgroup: Fix class @block_class's subsystem refcount leakage
    (bsc#1237558).
  - commit 17c1245
  - series: enabled downstream patches for storage again
  - Refresh
    patches.suse/blk-kabi-add-suse_kabi_padding-to-blk-layer-structs.patch.
  - Refresh
    patches.suse/nvme-tcp-do-not-terminate-commands-when-in-resetting.patch.
  - Refresh
    patches.suse/scsi-kabi-add-suse_kabi_padding-to-scsi-template-structs.patch.
  - commit 152726d
  - x86/cpu/kvm: SRSO: Fix possible missing IBPB on VM-Exit (git-fixes).
  - commit 37d1575

++++ util-linux-systemd:

  - Delete /usr/sbin/rc* symlinks
  - Drop bashisms from build recipe

++++ util-linux:

  - Delete /usr/sbin/rc* symlinks
  - Drop bashisms from build recipe

++++ tiff:

  - Use python3-Sphinx instead of  %{primary_python}-Sphinx
    based on recommendation from python maintainers.
    * Fixes build issue of man flavor on 15.6

++++ libvirt:

  - Adjust downstream patch 'Add virt-create-rootfs utility' to only
    install virt-create-rootfs when building the LXC driver

++++ libx86emu:

  - merge gh#wfeldt/libx86emu#47
  - fix building on non-x86 architectures
  - 3.7
  - merge gh#wfeldt/libx86emu#46
  - fix a buffer overflow in x86emu_log (bsc#1237557)
  - 3.6
  - merge gh#wfeldt/libx86emu#44
  - prim_ops: fix some indentation
  - merge gh#wfeldt/libx86emu#42
  - Fix a bug in R/M 01 decoding
  - merge gh#wfeldt/libx86emu#41
  - fix NEG remark typos

++++ libxmlb:

  - Update to 0.3.21
    * Check for corrupt XbSiloNode values in a smarter way
    Changes in 0.3.20:
    * Do not always strip literal text
    * Do not assume .txt files are application/xml
    * Fix a crash when loading a corrupt XMLb store

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.124.02 (boo#1237585)

------------------------------------------------------------------
------------------  2025-2-23  -  Feb 23 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - md/raid5: Wait sync io to finish before changing group cnt
    (git-fixes).
  - md/md-bitmap: Add missing destroy_work_on_stack() (git-fixes).
  - commit fd1221e

++++ kernel-rt:

  - md/raid5: Wait sync io to finish before changing group cnt
    (git-fixes).
  - md/md-bitmap: Add missing destroy_work_on_stack() (git-fixes).
  - commit fd1221e

++++ nvidia-open-driver-G06-signed:

  - explicitly enable KMP for kernel-longterm: this will be needed
    for the transition period, until all KMPs are enabled

------------------------------------------------------------------
------------------  2025-2-22  -  Feb 22 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - mtd: rawnand: cadence: fix unchecked dereference (git-fixes).
  - commit f57c089
  - soc: loongson: loongson2_guts: Add check for devm_kstrdup()
    (git-fixes).
  - firmware: arm_scmi: imx: Correct tx size of
    scmi_imx_misc_ctrl_set (git-fixes).
  - platform: cznic: CZNIC_PLATFORMS should depend on ARCH_MVEBU
    (git-fixes).
  - drm/msm/dsi/phy: Do not overwite PHY_CMN_CLK_CFG1 when choosing
    bitclk source (git-fixes).
  - drm/msm/dsi/phy: Protect PHY_CMN_CLK_CFG1 against clock driver
    (git-fixes).
  - drm/msm/dsi/phy: Protect PHY_CMN_CLK_CFG0 updated from driver
    side (git-fixes).
  - drm/msm/dpu: Don't leak bits_per_component into random DSC_ENC
    fields (git-fixes).
  - drm/msm/dpu: Disable dither in phys encoder cleanup (git-fixes).
  - drm/msm/dpu: enable DPU_WB_INPUT_CTRL for DPU 5.x (git-fixes).
  - drm/msm/dpu: skip watchdog timer programming through TOP on >=
    SM8450 (git-fixes).
  - drm/msm: Avoid rounding up to one jiffy (git-fixes).
  - drm/i915/ddi: Fix HDMI port width programming in DDI_BUF_CTL
    (git-fixes).
  - drm/i915/gt: Use spin_lock_irqsave() in interruptible context
    (git-fixes).
  - drm/nouveau/pmu: Fix gp10b firmware guard (git-fixes).
  - nouveau/svm: fix missing folio unlock + put after
    make_device_exclusive_range() (git-fixes).
  - drm: panel: jd9365da-h3: fix reset signal polarity (git-fixes).
  - mtd: spi-nor: sst: Fix SST write failure (git-fixes).
  - mtd: rawnand: cadence: fix incorrect device in dma_unmap_single
    (git-fixes).
  - mtd: rawnand: cadence: use dma_map_resource for sdma address
    (git-fixes).
  - mtd: rawnand: cadence: fix error code in cadence_nand_init()
    (git-fixes).
  - drm/amdgpu: avoid buffer overflow attach in
    smu_sys_set_pp_table() (stable-fixes).
  - fbdev: omap: use threaded IRQ for LCD DMA (stable-fixes).
  - commit b47b393

++++ kernel-rt:

  - mtd: rawnand: cadence: fix unchecked dereference (git-fixes).
  - commit f57c089
  - soc: loongson: loongson2_guts: Add check for devm_kstrdup()
    (git-fixes).
  - firmware: arm_scmi: imx: Correct tx size of
    scmi_imx_misc_ctrl_set (git-fixes).
  - platform: cznic: CZNIC_PLATFORMS should depend on ARCH_MVEBU
    (git-fixes).
  - drm/msm/dsi/phy: Do not overwite PHY_CMN_CLK_CFG1 when choosing
    bitclk source (git-fixes).
  - drm/msm/dsi/phy: Protect PHY_CMN_CLK_CFG1 against clock driver
    (git-fixes).
  - drm/msm/dsi/phy: Protect PHY_CMN_CLK_CFG0 updated from driver
    side (git-fixes).
  - drm/msm/dpu: Don't leak bits_per_component into random DSC_ENC
    fields (git-fixes).
  - drm/msm/dpu: Disable dither in phys encoder cleanup (git-fixes).
  - drm/msm/dpu: enable DPU_WB_INPUT_CTRL for DPU 5.x (git-fixes).
  - drm/msm/dpu: skip watchdog timer programming through TOP on >=
    SM8450 (git-fixes).
  - drm/msm: Avoid rounding up to one jiffy (git-fixes).
  - drm/i915/ddi: Fix HDMI port width programming in DDI_BUF_CTL
    (git-fixes).
  - drm/i915/gt: Use spin_lock_irqsave() in interruptible context
    (git-fixes).
  - drm/nouveau/pmu: Fix gp10b firmware guard (git-fixes).
  - nouveau/svm: fix missing folio unlock + put after
    make_device_exclusive_range() (git-fixes).
  - drm: panel: jd9365da-h3: fix reset signal polarity (git-fixes).
  - mtd: spi-nor: sst: Fix SST write failure (git-fixes).
  - mtd: rawnand: cadence: fix incorrect device in dma_unmap_single
    (git-fixes).
  - mtd: rawnand: cadence: use dma_map_resource for sdma address
    (git-fixes).
  - mtd: rawnand: cadence: fix error code in cadence_nand_init()
    (git-fixes).
  - drm/amdgpu: avoid buffer overflow attach in
    smu_sys_set_pp_table() (stable-fixes).
  - fbdev: omap: use threaded IRQ for LCD DMA (stable-fixes).
  - commit b47b393

++++ libX11:

  - U_CVE-2025-26597-0001-xkb-Fix-buffer-overflow-in-XkbChangeTypesOfKey.patch
    * Buffer overflow in XkbChangeTypesOfKey()
    (CVE-2025-26597, bsc#1237431)

------------------------------------------------------------------
------------------  2025-2-21  -  Feb 21 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Always apply 0007-Remove-DynamicUser-setting-as-these-conflict-with-re.patch
    for every build system. Fixes bsc#1237451

++++ docker-compose:

  - Update to version 2.33.1:
    * Improvements
  - Add support for gw_priority, enable_ipv4 (requires docker
    v28.0) by @thaJeztah in #12570
    * Fixes
  - Run watch standalone if menu fails to start by @ndeloof in
    [#12536]
  - Report error using non-file secret|config with read-only
    service by @ndeloof in #12531
  - Don't display bake suggestion when using --progress with
    quiet or json option by @glours in #12561
  - Fix pull --parallel and --no-parallel deprecation warnings
    missing by @maxproske in #12555
  - Fix error message when detach is implied by wait by @ndeloof
    in #12566
    * Dependencies
  - build(deps): bump github.com/spf13/cobra from 1.8.1 to 1.9.1
    by @dependabot in #12556
  - build(deps): bump google.golang.org/grpc from 1.68.1 to
    1.70.0 by @dependabot in #12494
  - go.mod: update to docker v28.0.0 by @thaJeztah in #12545

++++ file:

  - Add patch boo1237209.patch temporary
    * Fix stack overrun (boo#1237209)

++++ kernel-default:

  - Move upstreamed sound patch into sorted section
  - commit 9c8581a
  - s390/ism: add release function for struct device (git-fixes
    bsc#1237494).
  - commit 040e6ac
  - supported.conf: Make pca9450 and btnxpuart drivers supported (jsc#PED-12016)
  - commit 4bd4eef
  - power: supply: axp20x_battery: Fix fault handling for AXP717
    (git-fixes).
  - power: supply: da9150-fg: fix potential overflow (git-fixes).
  - commit 9a75ead

++++ kernel-firmware-mediatek:

  - Update to version 20250220 (git commit 6cf959daab2a):
    * linux-firmware: update firmware for MT7920 WiFi device

++++ kernel-firmware-platform:

  - Update to version 20250220 (git commit 6cf959daab2a):
    * linux-firmware: Update AMD SEV firmware

++++ kernel-rt:

  - Move upstreamed sound patch into sorted section
  - commit 9c8581a
  - s390/ism: add release function for struct device (git-fixes
    bsc#1237494).
  - commit 040e6ac
  - supported.conf: Make pca9450 and btnxpuart drivers supported (jsc#PED-12016)
  - commit 4bd4eef
  - power: supply: axp20x_battery: Fix fault handling for AXP717
    (git-fixes).
  - power: supply: da9150-fg: fix potential overflow (git-fixes).
  - commit 9a75ead

++++ kmod:

  - Update to release 34
    * modinfo now dlopens compression libraries, and only if needed.
    (insmod/modprobe exercises the kernel's built-in decompression
    anyway, so is unaffected).
    * depmod: add -m option for overriding the module directory at
    runtime.
    * depmod: deleted deprecated options --unresolved-error, --quiet,
  - root and --map.
    * rmmod: deleted deprecated option -w.
    * insmod: deleted deprecated options -p, -s.
  - Delete 0001-testsuite-fix-path-for-test-user.patch (obsolete)

++++ llvm19:

  - Build with GCC 13 on Leap/SLES 15 (bsc#1235697)

++++ harfbuzz:

  - Update to version 10.3.0:
    + Vastly improved “AAT” shaping performance. LucidaGrande
    benchmark-shape before: 14.6ms after: 5.9ms.
    + Improved OpenType shaping performance (kerning / ligature), at
    the expense of ~1kb per face allocated cache memory.
    Roboto-Regular benchmark-shape before: 10.3ms after: 9.4ms.
    + Improved “COLRv1” benchmark-font paint performance. Before:
    7.85ms after 4.85ms.
    + Don’t apply glyph substitutions in “morx” table of a font with
    known broken “morx” table (AALMAGHRIBI.ttf font).
    + Update IANA and OT language registries.
    + Various documentation updates.
    + Various build improvements, and test speed-ups.
    + The “hb_face_reference_blob()” API now works for faces created
    with “hb_face_create_for_tables()” if the face sets
    “get_table_tags” callback. This constructs a new face blob from
    individual table blobs.
    + Various fixes to how “trak” table is handled to bring it closer
    to Core Text behaviour. Particularly, the tracking values for
    sizes not explicitly set in the table are now properly
    interpolated, and the tracking is applied to glyph advances
    when they are returned by ot-font functions, instead of
    applying them during shaping. The “trak” pseudo OpenType
    feature that could be used to disable “trak” table application
    have been dropped.
    + Core Text font functions now support non-BMP code points.
    + The drawing algorithm used by hb-draw for “glyf” table now
    match the algorithm used by FreeType and Core Text.
    + The “hb_coretext_font_create()” API now copy font variations
    from Core Text font to the created HarfBuzz font.
    + Add an API to get the feature tags enabled on a given
    shape-plan after executing it, which can be used to
    applications to show in the UI what features are applied by
    default (which can vary based on the font, the script, the
    language, and the direction set on the buffer).
    + Add APIs to created HarfBuzz font from DirectWrite font, and
    copy the font variations.
    + New API:
    hb_directwrite_font_create()
    hb_directwrite_font_get_dw_font()
    hb_ot_shape_plan_get_feature_tags()

++++ libzypp:

  - Filesystem usrmerge must not be done in singletrans mode
    (bsc#1236481, bsc#1189788)
    Commit will amend the backend in case the transaction would
    perform a filesystem usrmerge.
  - Workaround bsc#1216091 on Code16.
  - version 17.36.2 (35)

++++ osinfo-db:

  - Add for SLES 16 / Leap 16, <firmware arch="x86_64" type="efi"/>
    add-sles16-support.patch
    add-opensuse-leap-16.0-support.patch

++++ pcr-oracle:

  - Update the License tag to GPL-2.0-or-later to match the license
    declaration in the source files

++++ selinux-policy:

  - Update to version 20240604+git802.bedfc504:
    * Allow named_filetrans_domain filetrans raid/mdadm named content (bsc#1236807)

++++ vim:

  - Version bump to fix bsc#1237359 (fixed as of 9.1.1115).
  - Update to 9.1.1134.
    * 9.1.1134: filetype: Guile init file not recognized
    * 9.1.1133: filetype: xkb files not recognized everywhere
    * 9.1.1132: Mark positions wrong after triggering multiline completion
    * 9.1.1131: potential out-of-memory issue in search.c
    * remove resolved complete item from todo list
    * 9.1.1130: 'listchars' "precedes" is not drawn on Tabs.
    * set fileformat=dos in filetype plugin
    * 9.1.1129: missing out-of-memory test in buf_write()
    * add commentstring '> %s' to ftplugin
    * 9.1.1128: 9.1.1119 caused a regression with imports
    * include simple filetype plugin
    * 9.1.1127: preinsert text is not cleaned up correctly
    * 9.1.1126: 9.1.1121 used a wrong way to handle enter
    * 9.1.1125: cannot loop through pum menu with multiline items
    * 9.1.1124: No test for 'listchars' "precedes" with double-width char
    * 9.1.1123: popup hi groups not falling back to defaults
    * Add support for # comments to ftplugin
    * 9.1.1122: too many strlen() calls in findfile.c
    * 9.1.1121: Enter does not insert newline with "noselect"
    * fix s:NetrwHome() regression
    * 9.1.1120: tests: Test_registers fails
    * add reference to extendnew() at extend()
    * 9.1.1119: Vim9: Not able to use an autoloaded class from another
    * autoloaded script
    * 9.1.1118: tests: test_termcodes fails
    * Update base-syntax, improve performance
    * 9.1.1117: there are a few minor style issues
    * 9.1.1116: Vim9: super not supported in lambda expressions
    * Update the 'specifies' keyword documentation, slightly
    * reformat
    * 9.1.1115: [security]: use-after-free in str_to_reg()
    * 9.1.1114: enabling termguicolors automatically confuses users
    * Add ukrainian-enhanced keymap
    * 9.1.1113: tests: Test_terminal_builtin_without_gui waits 2 seconds
    * 9.1.1112: Inconsistencies in get_next_or_prev_match()
    * document ComplMatchIns highlight for insert-completion
    * upstream snapshot of v177
    * 9.1.1111: Vim9: variable not found in transitive import
    * 9.1.1110: Vim tests are slow and flaky
    * 9.1.1109: cmdexpand.c hard to read
    * include simple filetype plugin
    * include simple filetype plugin
    * 9.1.1108: 'smoothscroll' gets stuck with 'listchars' "eol"
    * 9.1.1107: cannot loop through completion menu with fuzzy
    * Update base-syntax, always match continuation comments to EOL
    * set define option & add matchit config in ftplugin
    * Update base-syntax, match Vim9 boolean and null literals in
    * parens
    * 9.1.1106: tests: Test_log_nonexistent() causes asan failure
    * 9.1.1105: Vim9: no support for protected new() method
    * 9.1.1104: CI: using Ubuntu 22.04 Github runners
    * ci: syntax tests spam output
    * 9.1.1103: if_perl: still some compile errors with Perl 5.38
    * 9.1.1102: tests: Test_WinScrolled_Resized_eiw() uses wrong filename

------------------------------------------------------------------
------------------  2025-2-20  -  Feb 20 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Add functionality to cockpit-packagekit that allows selecting what updates
    should be applied
  - Added packagekit-single-install.patch file that adds this functionality

++++ lvm2-device-mapper:

  - system with LVM on iSCSI hangs on shutdown because blk-availability.service is not enabled (bsc#1236788)
    * update lvm2.spec
  - remove blk-availability.service from %postun
  - add new Provides 'dont_stop_blk_availability_service'

++++ glib2:

  - Update to version 2.83.4 (Unstable):
    + Fix Python shebang paths so they work on Windows again
    + Fix refcounting semantics of
    `g_dbus_connection_register_object_with_closures()` by adding a
    replacement API
    + Support static vfuncs in GIRepository
    + Add support for QNX8.0
    + Add a soft dependency on C11 — if your toolchain doesn’t
    support C11, you have six months to tell us before this becomes
    a hard dependency
    + Port from `net.hadess.PowerProfiles` to
    `org.freedesktop.UPower.PowerProfiles` for
    `GPowerProfileMonitorDBus`
    + Various bugs fixed.
    + Updated translations.
    + gdatetime: Fix integer overflow when parsing very long ISO8601 inputs.
    (CVE-2025-3360, bsc#1240897)
  - Rebase patches with quilt.
  - Update to version 2.83.3 (Unstable):
    + Fix build-time paths appearing in generated `Gio-2.0.gir` and
    `GioUnix-2.0.gir` files
    + Fix crash on macOS when opening links
    + Bugs fixed:
  - Recent `(inout)` changes caused unintended side-effects with
    `GWeakRef`
  - Missing nullable annotation on parameter user_data and on the
    return value of GVfsFileLookupFunc callback
  - GBytes semantics of handling empty strings are inconsistent
    and confusing
  - Bad anchor link in g_signal_connect() documentation
  - build-time paths to gio/gunixmounts.h, etc. end up in
    Gio-2.0.gir, GioUnix-2.0.gir
  - Links crash application on MacOS due to lack of machine-id
    file
  - Requirement of GUnixMountMonitor for a Valid Timestamp from
    unix_mount_at is not Suffeciently Documented
  - gmacros:  _G_BOOLEAN_EXPR_IMPL is incompatible with c++
    functions marked constexpr
  - [th/gdataset-index] add a lookup index (GHashTable) to
    `GData`
  - GWin32: Add g_win32_com_clear()
  - docs: Add --generate-md to the gdbus-codegen documentation
  - docs: Fix some backslash escaping issues in doc comments
  - gio, gobject: Improve reproducibility of enumtypes headers
  - gstrfuncs: Drop a redundant paragraph
  - Don't define test setups unless we're testing
  - build: Make the introspection feature yield
  - Fix pointer-to-paramref syntax in docs
  - gio: Fix a link to a specifications document
  - Add several assertions to help static analysis and fix some
    GIR annotations
  - Fix GCC version detection for GUINT*_SWAP_LE_BE
  - gioenums: Add deprecation for FLAGS_NONE
  - docs: Use gi-docgen syntax in main-loop.md
  - docs: Document more extension points
  - docs: Clarify that g_array_unref() works like
    g_ptr_array_unref()
  - Update to version 2.83.2:
    + This release has the same code as 2.83.1, but contains a fix
    for release archive generation which means that 2.83.1 does not
    have a release archive
    + Bugs fixed: ci: Enable -Dintrospection for dist builds.
  - Changes from version 2.83.1:
    + Heap buffer overflow read in utf8_verify_ascii().
    + Build failure “'ifunc' is not supported on this target” with
    muslc.
    + 2.82.3 regression: lollypop crashes on startup.
    + Replace procfs linuxism with kinfo freebsdism.
  - Update to version 2.83.0:
    + Update to Unicode 16.0.0; there may be bugs in linebreaking
    support.
    + Optimise UTF-8 validation of strings, including use of ifuncs
    to prevent spurious warnings from sanitizers and valgrind.
    + Change the default value of -Dglib_debug from `auto` to
    `enabled` for developers — distributions will almost certainly
    want to override it to `-Dglib_debug=disabled` for package
    release builds though.
    + Revert per-instance locking changes in `GCancellable` as they
    introduced new races.
    + Bump Meson dependency to 1.4.0.
    + Rename multiple `g_unix_mount_*()` APIs to
    `g_unix_mount_entry_*()` (#3492.
    + Add a new `GFileMonitor` backend for macOS and BSD.
    + Add APIs for sync, async and finish function annotations to
    libgirepository.
    + Updated translations.
  - Update to version 2.82.5:
    + Bugs fixed:
  - gosxappinfo: Correctly launch list of files
  - Don't mark test setups as default in subprojects
  - gdatetime: Fix integer overflow when parsing very long
    ISO8601 inputs

++++ gptfdisk:

  - Update to release 1.0.10
    * Fix failure & crash of sgdisk when compiled with latest popt
    * Fix NULL dereference when duplicating string argument
    * Allow partition dynamically allocated by --largest-new to be
    referenced by other options
    * Truncate decimal inputs (e.g. "9.5G" becomes "9G")
    * New partition type codes from the Discoverable Partitions
    Specification
  - Delete 0001-Fix-failure-crash-of-sgdisk-when-compiled-with-lates.patch
    gptfdisk-1.0.9-libuuid.patch,
    gptfdisk-fix-null-pointer-dereference.patch (merged)

++++ kernel-default:

  - iommu/amd: Fix corruption when mapping large pages from 0
    (stable-fixes).
  - iommu/tegra241-cmdqv: Fix unused variable warning
    (stable-fixes).
  - iommu/io-pgtable-arm: Fix stage-2 map/unmap for concatenated
    tables (stable-fixes).
  - commit dc2d748
  - sched/fair: Refactor can_migrate_task() to elimate looping
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/eevdf: Force propagating min_slice of cfs_rq when
    {en,de}queue tasks (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: Don't define sched_clock_irqtime as static key
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Reduce the default slice to avoid tasks getting an
    extra tick (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Cancel the slice protection of the idle entity
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Clarify wake_up_q()'s write to task->wake_q.next
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 4c4449a
  - net: qcom/emac: Find sgmii_ops by device_for_each_child()
    (jsc#PED-10906).
  - commit a0954d0
  - libnvdimm: Replace namespace_match() with
    device_find_child_by_name() (jsc#PED-10906).
  - commit 9effb4f
  - driver core: Constify API device_find_child() and adapt for
    various usages (jsc#PED-10906).
  - commit ce62ef8
  - PCI: Use downstream bridges for distributing resources
    (bsc#1237325).
  - commit ac1a584
  - drm/i915: Drop 64bpp YUV formats from ICL+ SDR planes
    (stable-fixes).
  - Revert "drm/amd/display: Use HW lock mgr for PSR1"
    (stable-fixes).
  - drm/amdkfd: only flush the validate MES contex (stable-fixes).
  - drm/amd/pm: Mark MM activity as unsupported (stable-fixes).
  - drm/modeset: Handle tiled displays in pan_display_atomic
    (stable-fixes).
  - drm/amd/display: Fix Mode Cutoff in DSC Passthrough to DP2.1
    Monitor (stable-fixes).
  - drm/bridge: it6505: fix HDCP CTS KSV list wait timer
    (stable-fixes).
  - drm/bridge: it6505: fix HDCP CTS compare V matching
    (stable-fixes).
  - drm/bridge: it6505: fix HDCP encryption when R0 ready
    (stable-fixes).
  - drm/bridge: it6505: fix HDCP Bstatus check (stable-fixes).
  - drm/bridge: it6505: Change definition MAX_HDCP_DOWN_STREAM_COUNT
    (stable-fixes).
  - drm/virtio: New fence for every plane update (stable-fixes).
  - commit 615893a
  - Fix conditional for selecting gcc-13
    Fixes: 51dacec21eb1 ("Use gcc-13 for build on SLE16 (jsc#PED-10028).")
  - commit 07542ae
  - kasan: don't call find_vm_area() in a PREEMPT_RT kernel
    (git-fixes).
  - lib/iov_iter: fix import_iovec_ubuf iovec management
    (git-fixes).
  - kasan: make kasan_record_aux_stack_noalloc() the default
    behaviour (git-fixes).
  - commit 0d9c641
  - dt-bindings: clock: sunxi: Export PLL_VIDEO_2X and PLL_MIPI (git-fixes)
  - commit 0a7858b
  - arm64: dts: allwinner: a64: explicitly assign clock parent for TCON0 (git-fixes)
  - commit 9135ee4
  - KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state (git-fixes)
  - commit faef568
  - arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (git-fixes)
  - commit 10a9960
  - arm64: Handle .ARM.attributes section in linker scripts (git-fixes)
  - commit f30d30c
  - arm64: dts: imx93: Use IMX93_CLK_SPDIF_IPG as SPDIF IPG clock (git-fixes)
  - commit 45bf054

++++ kernel-firmware-amdgpu:

  - Update to version 20250219 (git commit 5faab136de1a):
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-bluetooth:

  - Update to version 20250219 (git commit 5faab136de1a):
    * qca: update WCN3988 firmware

++++ kernel-firmware-network:

  - Update to version 20250219 (git commit 5faab136de1a):
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy

++++ kernel-firmware-qcom:

  - Update to version 20250219 (git commit 5faab136de1a):
    * qcom: add firmware for Adreno A225

++++ kernel-firmware-sound:

  - Update to version 20250219 (git commit 5faab136de1a):
    * cirrus: cs35l56: Add and update firmware for Cirrus CS35L56 for two HP laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some ASUS laptops
    * cirrus: cs35l56: Add and update firmware for Cirrus CS35L56 for various Lenovo laptops
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some Dell laptops

++++ kernel-rt:

  - iommu/amd: Fix corruption when mapping large pages from 0
    (stable-fixes).
  - iommu/tegra241-cmdqv: Fix unused variable warning
    (stable-fixes).
  - iommu/io-pgtable-arm: Fix stage-2 map/unmap for concatenated
    tables (stable-fixes).
  - commit dc2d748
  - sched/fair: Refactor can_migrate_task() to elimate looping
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/eevdf: Force propagating min_slice of cfs_rq when
    {en,de}queue tasks (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: Don't define sched_clock_irqtime as static key
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Reduce the default slice to avoid tasks getting an
    extra tick (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Cancel the slice protection of the idle entity
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Clarify wake_up_q()'s write to task->wake_q.next
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 4c4449a
  - net: qcom/emac: Find sgmii_ops by device_for_each_child()
    (jsc#PED-10906).
  - commit a0954d0
  - libnvdimm: Replace namespace_match() with
    device_find_child_by_name() (jsc#PED-10906).
  - commit 9effb4f
  - driver core: Constify API device_find_child() and adapt for
    various usages (jsc#PED-10906).
  - commit ce62ef8
  - PCI: Use downstream bridges for distributing resources
    (bsc#1237325).
  - commit ac1a584
  - drm/i915: Drop 64bpp YUV formats from ICL+ SDR planes
    (stable-fixes).
  - Revert "drm/amd/display: Use HW lock mgr for PSR1"
    (stable-fixes).
  - drm/amdkfd: only flush the validate MES contex (stable-fixes).
  - drm/amd/pm: Mark MM activity as unsupported (stable-fixes).
  - drm/modeset: Handle tiled displays in pan_display_atomic
    (stable-fixes).
  - drm/amd/display: Fix Mode Cutoff in DSC Passthrough to DP2.1
    Monitor (stable-fixes).
  - drm/bridge: it6505: fix HDCP CTS KSV list wait timer
    (stable-fixes).
  - drm/bridge: it6505: fix HDCP CTS compare V matching
    (stable-fixes).
  - drm/bridge: it6505: fix HDCP encryption when R0 ready
    (stable-fixes).
  - drm/bridge: it6505: fix HDCP Bstatus check (stable-fixes).
  - drm/bridge: it6505: Change definition MAX_HDCP_DOWN_STREAM_COUNT
    (stable-fixes).
  - drm/virtio: New fence for every plane update (stable-fixes).
  - commit 615893a
  - Fix conditional for selecting gcc-13
    Fixes: 51dacec21eb1 ("Use gcc-13 for build on SLE16 (jsc#PED-10028).")
  - commit 07542ae
  - kasan: don't call find_vm_area() in a PREEMPT_RT kernel
    (git-fixes).
  - lib/iov_iter: fix import_iovec_ubuf iovec management
    (git-fixes).
  - kasan: make kasan_record_aux_stack_noalloc() the default
    behaviour (git-fixes).
  - commit 0d9c641
  - dt-bindings: clock: sunxi: Export PLL_VIDEO_2X and PLL_MIPI (git-fixes)
  - commit 0a7858b
  - arm64: dts: allwinner: a64: explicitly assign clock parent for TCON0 (git-fixes)
  - commit 9135ee4
  - KVM: arm64: Unconditionally save+flush host FPSIMD/SVE/SME state (git-fixes)
  - commit faef568
  - arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (git-fixes)
  - commit 10a9960
  - arm64: Handle .ARM.attributes section in linker scripts (git-fixes)
  - commit f30d30c
  - arm64: dts: imx93: Use IMX93_CLK_SPDIF_IPG as SPDIF IPG clock (git-fixes)
  - commit 45bf054

++++ gpgme:

  - Don't own content of all common-lisp directories, just own the
    directories themselves (adding %dir in front of them). Prevents
    duplicate ownership of the Common Lisp files.

++++ lvm2:

  - system with LVM on iSCSI hangs on shutdown because blk-availability.service is not enabled (bsc#1236788)
    * update lvm2.spec
  - remove blk-availability.service from %postun
  - add new Provides 'dont_stop_blk_availability_service'

++++ open-vm-tools:

  - (bsc#1237180): Ensure vmtoolsd.service, vgauthd.service, and
    vmblock-fuse.service are set to enabled by default.

++++ openSUSE-repos-LeapMicro:

  - Update to version 20250220.13a9986:
    * Use arch specific repodata on Leap 16.0 (#77)

++++ python-MarkupSafe:

  - split test dependencies into a multibuild to break cycle
    with pytest

++++ yast2:

  - respect kernel parameter filtering from agama if found
    (bsc#1237390,bsc#1234678)
  - 5.0.12

------------------------------------------------------------------
------------------  2025-2-19  -  Feb 19 2025  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Update to 327:
    * Translation updates
  - Changes from 326:
    * Download and install unsupported and older operating systems
  - Changes from 325:
    * Improve rendering of VM descriptions
    * Translation updates

++++ docker:

  - Update to Docker 27.5.1-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/27/#2741> bsc#1237335
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * cli-0001-docs-include-required-tools-in-source-tree.patch
  - Update to docker-buildx 0.20.1. See upstream changelog online at
    <https://github.com/docker/buildx/releases/tag/v0.20.1>

++++ dracut:

  - Update to version 059+suse.658.ge9a17609:
    Fixes for booting from iSCSI offload with bnx2i (bsc#1228086):
    * fix(iscsi): attempt iSCSI login before all interfaces are up
    * fix(iscsi): don't require network setup for bnx2i
    Other:
    * feat(livenet): get live image size from TFTP servers

++++ gpg2:

  - Update to 2.5.4:
    * gpg: New option --disable-pqc-encryption. [rG00c31f8b04]
    * gpg: Fix --quick-add-key for Weierstrass ECC with usage given. [T7506]
    * gpg: Fix handling with no CRC armor. [T7071]
    * gpg: New private Kyber keys are now cross-referenced using a new
    Link attribute. [T6638]
    * gpg: Fix an import problem with keys having another primary key as
    a subkey. [T7527]
    * gpgsm: Allow unattended PKCS#12 export without passphrase. [rG159e801043]
    * gpgsm: Allow CSR generation with an unprotected key. [rG89055f24f4]
    * agent: New option --change-std-env-name. [T7522]
    * agent: Fix ssh-agent's request_identities for skipped Brainpool
    keys. [rG2469dc5aae]
    * Do not package zlib and bzip2 object files in a speedo release build. [T7442]
    * Rebase patches:
  - gnupg-add_legacy_FIPS_mode_option.patch
  - gnupg-allow-import-of-previously-known-keys-even-without-UIDs.patch
  - gnupg-revert-rfc4880bis.patch

++++ grub2:

  - Fix grub-bls does not rollback via setting new default (bsc#1237198)
    * 0001-bls-Accept-.conf-suffix-in-setting-default-entry.patch

++++ kernel-default:

  - idpf: call set_real_num_queues in idpf_open (bsc#1236661
    bsc#1237316).
  - commit 038664b
  - driver core: Introduce an device matching API
    device_match_type() (jsc#PED-10906).
  - commit 9f68205
  - driver core: Put device attribute @wakeup_last_time_ms and
    its show() together (jsc#PED-10906).
  - commit 0ab8f11
  - cacheinfo: Don't opencode per_cpu_cacheinfo() (jsc#PED-10906).
  - commit e469790
  - drivers/base: Remove unused auxiliary_find_device
    (jsc#PED-10906).
  - commit e7ed3d1
  - driver core: Add device probe log helper dev_warn_probe()
    (jsc#PED-10906).
  - commit e646f4e
  - regmap-irq: Consistently use memset32() in regmap_irq_thread()
    (jsc#PED-10906).
  - commit e64a63b
  - usb: typec: class: Remove both cable_match() and partner_match()
    (jsc#PED-10906).
  - commit e1bfd88
  - sysctl: update common tuning parameters for SAP workloads
    References: jsc#PED-11670
  - commit 86d9b06
  - config: set selinux as defautl lsm
    References: jsc#PED-12021
    Clear CONFIG_DEFAULT_SECURITY_APPARMOR=y
  - commit ad8cf6a
  - config: update configs using run_oldconfig.sh
    Mainly cleanup of TOMOYO configs after following commit:
    08c6cff34064 Update config files: disable tomoyo lsm (jsc#PED-12020)
  - commit 6d8067f
  - supported.conf: Add more iMX93 modules to supported list (jsc#PED-12016)
  - supported.conf: Make few iMX93 modules supported (jsc#PED-12016)
  - commit 8472ab7
  - i2c: imx-lpi2c: select CONFIG_I2C_SLAVE (git-fixes)
  - commit 9775c66
  - Update
    patches.suse/cachestat-fix-page-cache-statistics-permission-check.patch
    (CVE-2025-21691 bsc#1237026).
  - commit 77a27c3
  - usb: typec: Print err when displayport fails to enter
    (jsc#PED-10603).
  - commit ca6631e
  - usb: typec: Make active on port altmode writable
    (jsc#PED-10603).
  - commit eeb0401
  - usb: typec: Add driver for Thunderbolt 3 Alternate Mode
    (jsc#PED-10603).
  - commit 4279597
  - KVM: arm64: Fix alignment of kvm_hyp_memcache allocations
    (git-fixes).
  - commit cd5d95b
  - KVM: arm64: Fix nested S2 MMU structures reallocation
    (git-fixes).
  - commit b5739e1
  - usb: typec: tcpm: Add new AMS for Get_Revision response
    (jsc#PED-10906).
  - commit 0dc07bd
  - PCI: microchip: Add support for using either Root Port 1 or 2
    (git-fixes).
  - Refresh
    patches.suse/PCI-microchip-Set-inbound-address-translation-for-co.patch.
  - commit a34fcbd
  - KVM: arm64: Flush hyp bss section after initialization of
    variables in bss (git-fixes).
  - commit aaf5efb
  - usb: typec: tcpm: Add support for parsing pd-revision DT
    property (jsc#PED-10906).
  - commit 3e2e05e
  - usb: typec: tcpm: Add support for sink-bc12-completion-time-ms
    DT property (jsc#PED-10906).
  - commit fc6e26e
  - KVM: arm64: vgic-its: Add error handling in
    vgic_its_cache_translation (git-fixes).
  - commit c94c6dc
  - KVM: arm64: Do not allow ID_AA64MMFR0_EL1.ASIDbits to be
    overridden (git-fixes).
  - commit 452d1e3
  - usb: typec: tcpm: Add support for parsing time dt properties
    (jsc#PED-10906).
  - commit 4bcea43
  - KVM: arm64: Fix S1/S2 combination when FWB==1 and S2 has Device
    memory type (git-fixes).
  - commit b033aa6
  - usb: typec: stusb160x: Make use of i2c_get_match_data()
    (jsc#PED-10906).
  - commit bd20d7d
  - usb: typec: Fix typo in comment (jsc#PED-10906).
  - commit 3f9d1f1
  - KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow
    status (git-fixes).
  - commit dcc3c1a
  - KVM: arm64: vgic-v3: Sanitise guest writes to GICR_INVLPIR
    (git-fixes).
  - commit 817c4c3
  - usb: phy: Remove API devm_usb_put_phy() (jsc#PED-10906).
  - commit a4eae2b
  - usb: quirks: Add NO_LPM quirk for TOSHIBA TransMemory-Mx device
    (git-fixes).
  - commit eef2b55
  - KVM: arm64: Correctly access TCR2_EL1, PIR_EL1, PIRE0_EL1 with
    VHE (git-fixes).
  - commit ec41dc1
  - KVM: x86: Load DR6 with guest value only before entering
    .vcpu_run() loop (git-fixes).
  - commit 4a7679b
  - KVM: nSVM: Enter guest mode before initializing nested NPT MMU
    (git-fixes).
  - commit a57f140
  - KVM: x86: Avoid double RDPKRU when loading host/guest PKRU
    (git-fixes).
  - commit 9f1de37
  - KVM: x86: Zero out PV features cache when the CPUID leaf is
    not present (git-fixes).
  - commit e7655b9
  - USB: Replace own str_plural with common one (jsc#PED-10906).
  - commit 78aa90a
  - KVM: x86: Account for KVM-reserved CR4 bits when passing
    through CR4 on VMX (git-fixes).
  - commit 72969c6
  - ALSA: hda/conexant: Add quirk for HP ProBook 450 G4 mute LED
    (stable-fixes).
  - commit 70602b0
  - ALSA: seq: Drop UMP events when no UMP-conversion is set
    (git-fixes).
  - ALSA: hda/cirrus: Correct the full scale volume set logic
    (git-fixes).
  - ALSA: hda: Add error check for snd_ctl_rename_id() in
    snd_hda_create_dig_out_ctls() (git-fixes).
  - ASoC: imx-audmix: remove cpu_mclk which is from cpu dai device
    (git-fixes).
  - ASoC: SOF: pcm: Clear the susbstream pointer to NULL on close
    (git-fixes).
  - ASoC: SOF: stream-ipc: Check for cstream nullity in
    sof_ipc_msg_data() (git-fixes).
  - ASoC: SOF: ipc4-topology: Harden loops for looking up ALH
    copiers (git-fixes).
  - ASoC: rockchip: i2s-tdm: fix shift config for
    SND_SOC_DAIFMT_DSP_[AB] (git-fixes).
  - ASoC: fsl_micfil: Enable default case in micfil_set_quality()
    (git-fixes).
  - ALSA: hda/realtek: Fixup ALC225 depop procedure (git-fixes).
  - commit 5049122
  - KVM: VMX: Fix comment of handle_vmx_instruction() (git-fixes).
  - commit 34e0912
  - KVM: VMX: Allow toggling bits in MSR_IA32_RTIT_CTL when enable
    bit is cleared (git-fixes).
  - commit 8556a9f
  - Revert "KVM: VMX: Move LOAD_IA32_PERF_GLOBAL_CTRL errata
    handling out of setup_vmcs_config()" (git-fixes).
  - commit 92c9049
  - KVM: x86: Bypass register cache when querying CPL from
    kvm_sched_out() (git-fixes).
  - commit 3f985bf
  - KVM: x86: AMD's IBPB is not equivalent to Intel's IBPB
    (git-fixes).
  - commit 7344d06
  - KVM: x86: Fix a comment inside
    __kvm_set_or_clear_apicv_inhibit() (git-fixes).
  - commit c404f67

++++ kernel-rt:

  - idpf: call set_real_num_queues in idpf_open (bsc#1236661
    bsc#1237316).
  - commit 038664b
  - driver core: Introduce an device matching API
    device_match_type() (jsc#PED-10906).
  - commit 9f68205
  - driver core: Put device attribute @wakeup_last_time_ms and
    its show() together (jsc#PED-10906).
  - commit 0ab8f11
  - cacheinfo: Don't opencode per_cpu_cacheinfo() (jsc#PED-10906).
  - commit e469790
  - drivers/base: Remove unused auxiliary_find_device
    (jsc#PED-10906).
  - commit e7ed3d1
  - driver core: Add device probe log helper dev_warn_probe()
    (jsc#PED-10906).
  - commit e646f4e
  - regmap-irq: Consistently use memset32() in regmap_irq_thread()
    (jsc#PED-10906).
  - commit e64a63b
  - usb: typec: class: Remove both cable_match() and partner_match()
    (jsc#PED-10906).
  - commit e1bfd88
  - sysctl: update common tuning parameters for SAP workloads
    References: jsc#PED-11670
  - commit 86d9b06
  - config: set selinux as defautl lsm
    References: jsc#PED-12021
    Clear CONFIG_DEFAULT_SECURITY_APPARMOR=y
  - commit ad8cf6a
  - config: update configs using run_oldconfig.sh
    Mainly cleanup of TOMOYO configs after following commit:
    08c6cff34064 Update config files: disable tomoyo lsm (jsc#PED-12020)
  - commit 6d8067f
  - supported.conf: Add more iMX93 modules to supported list (jsc#PED-12016)
  - supported.conf: Make few iMX93 modules supported (jsc#PED-12016)
  - commit 8472ab7
  - i2c: imx-lpi2c: select CONFIG_I2C_SLAVE (git-fixes)
  - commit 9775c66
  - Update
    patches.suse/cachestat-fix-page-cache-statistics-permission-check.patch
    (CVE-2025-21691 bsc#1237026).
  - commit 77a27c3
  - usb: typec: Print err when displayport fails to enter
    (jsc#PED-10603).
  - commit ca6631e
  - usb: typec: Make active on port altmode writable
    (jsc#PED-10603).
  - commit eeb0401
  - usb: typec: Add driver for Thunderbolt 3 Alternate Mode
    (jsc#PED-10603).
  - commit 4279597
  - KVM: arm64: Fix alignment of kvm_hyp_memcache allocations
    (git-fixes).
  - commit cd5d95b
  - KVM: arm64: Fix nested S2 MMU structures reallocation
    (git-fixes).
  - commit b5739e1
  - usb: typec: tcpm: Add new AMS for Get_Revision response
    (jsc#PED-10906).
  - commit 0dc07bd
  - PCI: microchip: Add support for using either Root Port 1 or 2
    (git-fixes).
  - Refresh
    patches.suse/PCI-microchip-Set-inbound-address-translation-for-co.patch.
  - commit a34fcbd
  - KVM: arm64: Flush hyp bss section after initialization of
    variables in bss (git-fixes).
  - commit aaf5efb
  - usb: typec: tcpm: Add support for parsing pd-revision DT
    property (jsc#PED-10906).
  - commit 3e2e05e
  - usb: typec: tcpm: Add support for sink-bc12-completion-time-ms
    DT property (jsc#PED-10906).
  - commit fc6e26e
  - KVM: arm64: vgic-its: Add error handling in
    vgic_its_cache_translation (git-fixes).
  - commit c94c6dc
  - KVM: arm64: Do not allow ID_AA64MMFR0_EL1.ASIDbits to be
    overridden (git-fixes).
  - commit 452d1e3
  - usb: typec: tcpm: Add support for parsing time dt properties
    (jsc#PED-10906).
  - commit 4bcea43
  - KVM: arm64: Fix S1/S2 combination when FWB==1 and S2 has Device
    memory type (git-fixes).
  - commit b033aa6
  - usb: typec: stusb160x: Make use of i2c_get_match_data()
    (jsc#PED-10906).
  - commit bd20d7d
  - usb: typec: Fix typo in comment (jsc#PED-10906).
  - commit 3f9d1f1
  - KVM: arm64: Ignore PMCNTENSET_EL0 while checking for overflow
    status (git-fixes).
  - commit dcc3c1a
  - KVM: arm64: vgic-v3: Sanitise guest writes to GICR_INVLPIR
    (git-fixes).
  - commit 817c4c3
  - usb: phy: Remove API devm_usb_put_phy() (jsc#PED-10906).
  - commit a4eae2b
  - usb: quirks: Add NO_LPM quirk for TOSHIBA TransMemory-Mx device
    (git-fixes).
  - commit eef2b55
  - KVM: arm64: Correctly access TCR2_EL1, PIR_EL1, PIRE0_EL1 with
    VHE (git-fixes).
  - commit ec41dc1
  - KVM: x86: Load DR6 with guest value only before entering
    .vcpu_run() loop (git-fixes).
  - commit 4a7679b
  - KVM: nSVM: Enter guest mode before initializing nested NPT MMU
    (git-fixes).
  - commit a57f140
  - KVM: x86: Avoid double RDPKRU when loading host/guest PKRU
    (git-fixes).
  - commit 9f1de37
  - KVM: x86: Zero out PV features cache when the CPUID leaf is
    not present (git-fixes).
  - commit e7655b9
  - USB: Replace own str_plural with common one (jsc#PED-10906).
  - commit 78aa90a
  - KVM: x86: Account for KVM-reserved CR4 bits when passing
    through CR4 on VMX (git-fixes).
  - commit 72969c6
  - ALSA: hda/conexant: Add quirk for HP ProBook 450 G4 mute LED
    (stable-fixes).
  - commit 70602b0
  - ALSA: seq: Drop UMP events when no UMP-conversion is set
    (git-fixes).
  - ALSA: hda/cirrus: Correct the full scale volume set logic
    (git-fixes).
  - ALSA: hda: Add error check for snd_ctl_rename_id() in
    snd_hda_create_dig_out_ctls() (git-fixes).
  - ASoC: imx-audmix: remove cpu_mclk which is from cpu dai device
    (git-fixes).
  - ASoC: SOF: pcm: Clear the susbstream pointer to NULL on close
    (git-fixes).
  - ASoC: SOF: stream-ipc: Check for cstream nullity in
    sof_ipc_msg_data() (git-fixes).
  - ASoC: SOF: ipc4-topology: Harden loops for looking up ALH
    copiers (git-fixes).
  - ASoC: rockchip: i2s-tdm: fix shift config for
    SND_SOC_DAIFMT_DSP_[AB] (git-fixes).
  - ASoC: fsl_micfil: Enable default case in micfil_set_quality()
    (git-fixes).
  - ALSA: hda/realtek: Fixup ALC225 depop procedure (git-fixes).
  - commit 5049122
  - KVM: VMX: Fix comment of handle_vmx_instruction() (git-fixes).
  - commit 34e0912
  - KVM: VMX: Allow toggling bits in MSR_IA32_RTIT_CTL when enable
    bit is cleared (git-fixes).
  - commit 8556a9f
  - Revert "KVM: VMX: Move LOAD_IA32_PERF_GLOBAL_CTRL errata
    handling out of setup_vmcs_config()" (git-fixes).
  - commit 92c9049
  - KVM: x86: Bypass register cache when querying CPL from
    kvm_sched_out() (git-fixes).
  - commit 3f985bf
  - KVM: x86: AMD's IBPB is not equivalent to Intel's IBPB
    (git-fixes).
  - commit 7344d06
  - KVM: x86: Fix a comment inside
    __kvm_set_or_clear_apicv_inhibit() (git-fixes).
  - commit c404f67

++++ libassuan:

  - Update to 3.0.2:
    * Fix for FreeBSD to set the pid of assuan_peercred_t. [rAdfa5e6532d]
    * Use socklen_t for the length of socket address. [T5924]
    * Fix errno setting on Windows for assuan_sock_bind failure. [T7456]
    * New assuan_sock_get_flag "w32_error" to get the actual Windows
    error after a system call and not just the mapped errno. [T7456]

++++ rdma-core:

  - Update to rdma-core v56.0 (jsc#PED11323)
  - No release notes available

++++ libguestfs:

  - Update to version 1.55.6 (jsc#PED-8910)
    * appliance: add dhcpcd support on Debian
    * appliance: add support for sfdisk on Debian
    * mlcustomize, mltools: Replace $TEST_FUNCTIONS
    * ruby: Make sure all object files are cleaned up
    * daemon: New command_out and sh_out APIs

++++ samba:

  - Remove nscd build dependency and usage in RPM scriptlets;
    (bsc#1237296);
  - Update to 4.21.4
    * Increasing slowness of sharesec performance with high number
    of registry shares; (bso#15780).
    * winbindd shows memleak in kerberos_decode_pac; (bso#15782).
    * Creation of GPOs applicable to more than one group is
    impossible with Samba 4.20.0 and later; (bso#15738).
    * Replace `crypt` module in
    python/samba/netcmd/user/readpasswords/common.py;
    (bso#15756).
    * vfs_gpfs silently garbles timestamps > year 2106;
    (bso#15151).
    * Spotlight search results don't show file size and creation
    date; (bso#15796).
    * General improvements for vfs_ceph_new module; (bso#15703).
    * net offlinejoin not working correctly; (bso#15777).
    * net ads create/join/winbind producing unix dysfunctional
    keytabs; (bso#15759).
    * Windows Explorer crashes on S-1-22-* Unix-SIDs when accessing
    security tab; (bso#14213).
    * The values from hresult_errstr_const and hresult_errstr are
    reversed in 4.20 and 4.21; (bso#15769).
    * Kerberos referral tickets are generated for principals in our
    domain if we have a trust to a top level domain; (bso#15778).
    * NETLOGON_NTLMV2_ENABLED is missing in the SamLogon*
    user_flags field; (bso#15783).
    * Regression: stack-use-after-return in crypt_as_best_we_can();
    (bso#15784).
    * libreplace:readline: gcc 15 complains about incompatible
    pointer types; (bso#15788).

++++ openssh:

  - merge openssh-fips into the main openssh package (bsc#1185116)

++++ perl-Error:

  - Normalize CPAN version
    See https://github.com/openSUSE/cpanspec/issues/47 for details.
    I found no reverse dependencies in devel:languages:perl depending
    on a certain version higher than the normalized.

++++ ppp:

  - Update to version 2.5.2:
    * Some old and probably unused code has been removed, notably
    the pppgetpass program and the passprompt plugin, and some of
    the files in the sample and scripts directories.
    * If a remote number has been set, it is available to scripts in
    the REMOTENUMBER environment variable.
    * Various other bug fixes and minor enhancements.
  - Obsoleted patches:
    * ppp-fix-bashisms.patch

++++ python-M2Crypto:

  - Change macro to %{?sle15allpythons} so we build both Python 3.6
    and Python 3.11 on SLE-15.

++++ selinux-policy:

  - Update to version 20240604+git800.2adbf625:
    * Enable postfix_local_write_mail_spool boolean by default for targeted only
    * Revert "Enable postfix_local_write_mail_spool boolean by default"
    * Support openSUSE-specific krb5kdc paths (bsc#1237064)
    * Allow rlimit inheritance for domains transitioning to local_login_t
    * Enable postfix_local_write_mail_spool boolean by default
    * kanidm_unixd.fc: follow default style for aliased paths
    * Dontaudit systemd-logind remove all files
    * Add the files_dontaudit_read_all_dirs() interface
    * Add the files_dontaudit_delete_all_files() interface
    * Allow rhsmcertd notify virt-who
    * Allow irqbalance to run unconfined scripts conditionally
    * Allow snapperd execute systemctl in the caller domain
    * Allow svirt_tcg_t to connect to nbdkit over a unix stream socket
    * Allow iio-sensor-proxy read iio devices
    * Label /dev/iio:device[0-9]+ devices
    * Allow systemd-coredump the sys_admin capability
    * Allow apcupsd's apccontrol to send messages using wall
    * contrib/thumb: also allow per-user thumbnailers
    * contrib/thumb: fix thunar thumbnailer (rhbz#2315893)
    * Allow virt_domain to use pulseaudio - conditional
    * Allow pcmsensor read nmi_watchdog state information
    * Allow init_t nnp domain transition to gssproxy_t
    * Allow quota_t load its kernel module (bsc#1235805)
    * Allow apcupsd's apccontrol to send messages using wall (bsc#1235688)
    * Allow systemd-generator connect to syslog over a unix stream socket
    * Allow virtqemud manage fixed disk device nodes
    * Allow iio-sensor-proxy connect to syslog over a unix stream socket
    * Allow virtstoraged write to sysfs files
    * Allow power-profiles-daemon write sysfs files
    * Update iiosensorproxy policy
    * Allow pcmsensor write nmi_watchdog state information
    * Label /proc/sys/kernel/nmi_watchdog with sysctl_nmi_watchdog_t
    * Allow virtnodedev create /etc/mdevctl.d/scripts.d with bin_t type
    * Add the gpg_read_user_secrets() interface
    * Dontaudit xdm_t wanting to create /root/.cache dir (bsc#1235669)
    * Allow journalctl read messages from /var/lib/machines (bsc#1235829)
    * Allow gnome-remote-desktop read resolv.conf
    * Update switcheroo policy
    * Allow nfsidmap connect to systemd-homed over a unix socket
    * wtmpdbd systemd service uses NoNewPrivileges (bsc#1235660)
    * Transition samba-dcerpcd pid file from smbd_var_run_t to winbind_var_run_t (bsc#1235801)
    * /run/samba/samba-dcerpcd.pid needs fc type winbind_rpcd_var_run_t (bsc#1235801)
    * Adjust rpcd_lsad, samba-bgqd, samba-dcerpcd to SUSE-specific part (bsc#1235801)
    * Transition nmbd pid file from smbd_var_run_t to nmbd_var_run_t (bsc#1235801)
    * Add the auth_write_motd_var_run_files() interface
    * Add the bind_exec_named_checkconf() interface
    * Add the virt_exec_virsh() interface
    * Allow database rotation for wtmpdbd_t
    * Allow wtmpdbd to send messages notifications
    * Introduce policy for wtmpdbd (bsc#1235660)
    * Label xrdp scripts in /etc as bin_t (bsc#1233738)
    * introduce unconfined_service_transition_to_unconfined_user boolean (bsc#1233738)
    * Allow virtqemud domain transition to nbdkit
    * Add nbdkit interfaces defined conditionally
    * Allow samba-bgqd connect to cupsd over an unix domain stream socket
    * Confine the switcheroo-control service
    * Allow svirt_t read sysfs files
    * Allow init to manage DOS files (bsc#1232527)
    * Add rhsmcertd interfaces
    * Add the ssh_exec_sshd() interface
    * Add the gpg_domtrans_agent() interface
    * Label /usr/bin/dnf5 with rpm_exec_t
    * Label /dev/pmem[0-9]+ with fixed_disk_device_t
    * allow kdm to create /root/.kde/ with correct label
    * Change /usr/sbin entries to use /usr/bin or remove them
    * Allow systemd-homed get filesystem quotas
    * Allow login_userdomain getattr nsfs files
    * Allow virtqemud send a generic signal to the ssh client domain
    * Dontaudit request-key read /etc/passwd
    * Update virtqemud policy regarding the svirt_tcg_t domain
    * Allow virtqemud domain transition on numad execution
    * Support virt live migration using ssh
    * Allow virtqemud permissions needed for live migration
    * Allow virtqemud the getpgid process permission
    * Allow virtqemud manage nfs dirs when virt_use_nfs boolean is on
    * Allow virtqemud relabelfrom virt_log_t files
    * Allow virtqemud relabel tun_socket
    * Add policy for systemd-import-generator
    * Confine vsftpd systemd system generator
    * Allow virtqemud read and write sgx_vepc devices
    * Allow systemd-networkd list cgroup directories
    * Allow xdm dbus chat with power-profiles-daemon
    * Allow ssh_t read systemd config files
    * Add Valkey rules to Redis module
    * Update ktlsh policy
    * Allow request-key to read /etc/passwd
    * Allow request-key to manage all domains' keys
    * Add support for the KVM guest memfd anon inodes

++++ vim:

  - 9.1.1101 is a fix for:
    bsc#1229685 (CVE-2024-43790)
    bsc#1229822 (CVE-2024-43802)
    bsc#1230078 (CVE-2024-45306)
    bsc#1235695 (CVE-2025-22134)
    bsc#1236151 (CVE-2025-24014)
    bsc#1237137 (CVE-2025-1215)
  - Remove obsoleted patch:
    * vim-7.3-mktemp_tutor.patch
  - update to 9.1.1101
    * insexpand.c hard to read
    * tests: Test_log_nonexistent only works on Linux
    * Update base-syntax, improve variable matching
    * Vim9: import with extends may crash
    * leaking memory with completing multi lines
    * --log with non-existent path causes a crash
    * if_perl: Perl 5.38 adds new symbols causing link failure
    * tests: matchparen plugin test wrongly named
    * Vim9: problem finding implemented method in type hierarchy
    * runtime(qf): Update syntax file, match second delimiter
    * tests: output of test ...win32_ctrl_z depends on python version
    * tests: fix expected return code for python 3.13 on Windows
    * tests: timeout might be a bit too small
    * tests: test_terminwscroll_topline2 unreliable
    * tests: No check when tests are run under Github actions
    * tests: plugin tests are named inconsistently
    * Vim9: import with extends may crash
    * completion doesn't work with multi lines
    * filetype: cmmt files are not recognized
    * Unable to persistently ignore events in a window and its buffers
    * improve syntax highlighting
    * setreg() doesn't correctly handle mbyte chars in blockwise mode
    * unexpected DCS responses may cause out of bounds reads
    * has('bsd') is true for GNU/Hurd
    * filetype: Mill files are not recognized
    * GUI late startup leads to uninitialized scrollbars
    * Add support for lz4 to tar & gzip plugin
    * Terminal ansi colors off by one after tgc reset
    * included syntax items do not understand contains=TOP
    * vim_strnchr() is strange and unnecessary
    * Vim9: len variable not used in compile_load()
    * runtime(vim): Update base-syntax, match :debuggreedy count prefix
    * Strange error when heredoc marker starts with "trim"
    * tests: test_compiler fails on Windows without Maven
    * 'diffopt' "linematch" cannot be used with {n} less than 10
    * args missing after failing to redefine a function
    * Cannot control cursor positioning of getchar()
    * preinsert text completions not deleted with <C-W>/<C-U>
    * getchar() can't distinguish between C-I and Tab
    * tests: Test_termwinscroll_topline2 fails on MacOS
    * heap-use-after-free and stack-use-after-scope with :14verbose
    * no digraph for "Approaches the limit"
    * not possible to use plural forms with gettext()
    * too many strlen() calls in userfunc.c
    * terminal: E315 when dragging the terminal with the mouse
    * runtime(openPlugin): fix unclosed parenthesis in GetWordUnderCursor()
    * runtime(doc): Tweak documentation style a bit
    * tests: test_glvs fails when unarchiver not available
    * Vim always enables 'termguicolors' in a terminal
    * completion: input text deleted with preinsert when adding leader
    * translation(sr): Missing Serbian translation for the tutor
    * Superfluous cleanup steps in test_ins_complete.vim
    * runtime(netrw): correct wrong version check
    * Vim doesn't highlight to be inserted text when completing
    * runtime(netrw): upstream snapshot of v176
    * runtime(dist/vim9): fix regressions in dist#vim9#Open
    * runtime(hyprlang): fix string recognition
    * make install fails because of a missing dependency
    * runtime(asm): add byte directives to syntax script
    * Vim doesn't work well with TERM=xterm-direct
    * runtime(filetype): commit 99181205c5f8284a3 breaks V lang detection
    * runtime: decouple Open and Launch commands and gx mapping from netrw
    * "nosort" enables fuzzy filtering even if "fuzzy" isn't in 'completeopt'
    * runtime(just): fix typo in syntax file
    * runtime(filetype): Improve Verilog detection by checking for modules definition
    * tests: off-by-one error in CheckCWD in test_debugger.vim
    * tests: no support for env variables when running Vim in terminal
    * too many strlen() calls in os_unix.c
    * insert-completed items are always sorted
    * crash after scrolling and pasting in silent Ex mode
    * Makefiles uses non-portable syntax
    * fuzzymatching doesn't prefer matching camelcase
    * filetype: N-Tripels and TriG files are not recognized
    * Vim9: Patch 9.1.1014 causes regressions
    * translation(sr): Update Serbian messages translation
  - updade to 9.1.1043
    * [security]: segfault in win_line()
    * update helptags
    * filetype: just files are not recognized
    * Update base-syntax, match ternary and falsy operators
    * Vim9: out-of-bound access when echoing an enum
    * Vim9: imported type cannot be used as func return type
    * runtime(kconfig): updated ftplugin and syntax script
    * runtime(doc): rename last t_BG reference to t_RB
    * Vim9: comments are outdated
    * tests: test_channel.py fails with IPv6
    * runtime(vim): Update base-syntax, fix is/isnot operator matching
    * Vim9: confusing error when using abstract method via super
    * make install fails when using shadowdir
    * Vim9: memory leak with blob2str()
    * runtime(tex): add texEmphStyle to texMatchGroup in syntax script
    * runtime(netrw): upstream snapshot of v175
    * Vim9: compiling abstract method fails without return
    * runtime(c): add new constexpr keyword to syntax file (C23)
    * tests: shaderslang was removed from test_filetype erroneously
    * link error when FEAT_SPELL not defined
    * Coverity complains about insecure data handling
    * runtime(sh): update syntax script
    * runtime(c): Add missing syntax test files
    * filetype: setting bash filetype is backwards incompatible
    * runtime(c): Update syntax and ftplugin files
    * the installer can be improved
    * too many strlen() calls in screen.c
    * no sanitize check when running linematch
    * filetype: swc configuration files are not recognized
    * runtime(netrw): change netrw maintainer
    * wrong return type of blob2str()
    * blob2str/str2blob() do not support list of strings
    * runtime(doc): fix typo in usr_02.txt
    * Coverity complains about dereferencing NULL pointer
    * linematch option value not completed
    * string might be used without a trailing NUL
    * no way to get current selected item in a async context
    * filetype: fd ignore files are not recognized
    * v9.1.0743 causes regression with diff mode
    * runtime(doc): fix base64 encode/decode examples
    * Vim9: Patch 9.1.1013 causes a few problems
    * Not possible to convert string2blob and blob2string
    * Coverity complains about dereferencing NULL value
    * Vim9: variable not found in transitive import
    * runtime(colors): Update colorschemes, include new unokai colorscheme
    * Vim9: Regression caused by patch v9.1.0646
    * runtime(lyrics): support milliseconds in syntax script
    * runtime(vim): Split Vim legacy and Vim9 script indent tests
    * Vim9: class interface inheritance not correctly working
    * popupmenu internal error with some abbr in completion item
    * filetype: VisualCode setting file not recognized
    * diff feature can be improved
    * tests: test for patch 9.1.1006 doesn't fail without the patch
    * filetype: various ignore are not recognized
    * tests: Load screendump files with "git vimdumps"
    * PmenuMatch completion highlight can be combined
    * completion text is highlighted even with no pattern found
    * tests: a few termdebug tests are flaky
    * [security]: heap-buffer-overflow with visual mode
    * runtime(doc): add package-<name> helptags for included packages
    * Vim9: unknown func error with interface declaring func var
    * runtime(filetype): don't detect string interpolation as angular
    * ComplMatchIns highlight hard to read on light background
    * runtime(vim): Update base-syntax, highlight literal string quote escape
    * runtime(editorconfig): set omnifunc to syntaxcomplete func
    * tests: ruby tests fail with Ruby 3.4
    * Vim9: leaking finished exception
    * runtime(tiasm):  use correct syntax name tiasm in syntax script
    * filetype: TI assembly files are not recognized
    * too many strlen() calls in drawscreen.c
    * runtime(xf86conf): add section name OutputClass to syntax script
    * ComplMatchIns may highlight wrong text
    * runtime(vim): Update base-syntax, improve ex-bang matching
    * runtime(doc): clarify buffer deletion on popup_close()
    * filetype: shaderslang files are not detected
    * Vim9: not able to use comment after opening curly brace
  - update to 9.1.0993
    * 9.1.0993: New 'cmdheight' behavior may be surprising
    * runtime(sh): fix typo in Last Change header
    * 9.1.0992: Vim9: double-free after v9.1.0988
    * 9.1.0991: v:stacktrace has wrong type in Vim9 script
    * runtime(sh): add PS0 to bashSpecialVariables in syntax script
    * runtime(vim): Remove trailing comma from match_words
    * runtime(zsh): sync syntax script with upstream repo
    * runtime(doc): Capitalise the mnemonic "Zero" for the 'z' flag of search()
    * 9.1.0990: Inconsistent behavior when changing cmdheight
    * 9.1.0989: Vim9: Whitespace after the final enum value causes a syntax error
    * runtime(java): Quietly opt out for unsupported markdown.vim versions
    * runtime(vim): fix failing vim syntax test
    * 9.1.0988: Vim9: no error when using uninitialized var in new()
    * runtime(doc): update index.txt
    * 9.1.0987: filetype: cake files are not recognized
    * 9.1.0986: filetype: 'jj' filetype is a bit imprecise
    * runtime(jj): Support diffs in jj syntax
    * runtime(vim): Update matchit pattern, no Vim9 short names
    * 9.1.0985: Vim9: some ex commands can be shortened
    * 9.1.0984: exception handling can be improved
    * runtime(doc): update doc for :horizontal
    * runtime(doc): update index.txt, windows.txt and version9.txt
    * runtime(doc): Tweak documentation about base64 function
    * runtime(chordpro): update syntax script
    * 9.1.0983: not able to get the displayed items in complete_info()
    * runtime(doc): use standard SGR format at :h xterm-true-color
    * 9.1.0982: TI linker files are not recognized
    * runtime(vim): update vim generator syntax script
    * 9.1.0981: tests: typo in test_filetype.vim
    * 9.1.0980: no support for base64 en-/decoding functions in Vim Script
    * syntax(sh): Improve the recognition of bracket expressions
    * runtime(doc): mention how NUL bytes are handled
    * 9.1.0979: VMS: type warning with $XDG_VIMRC_FILE
    * 9.1.0978: GUI tests sometimes fail when setting 'scroll' options
    * 9.1.0977: filetype: msbuild filetypes are not recognized
    * 9.1.0976: Vim9: missing return statement with throw
    * 9.1.0975: Vim9: interpolated string expr not working in object methods
    * 9.1.0974: typo in change of commit v9.1.0873
    * 9.1.0973: too many strlen() calls in fileio.c
    * runtime(sh): set shellcheck as the compiler for supported shells
    * runtime(doc): Fix enum example syntax
    * 9.1.0972: filetype: TI linker map files are not recognized
    * runtime(vim): Improve syntax script generator for Vim Script
    * 9.1.0971: filetype: SLNX files are not recognized
    * 9.1.0970: VMS: build errors on VMS architecture
    * runtime(doc): Fix documentation typos
    * runtime(doc): update for new keyprotocol option value (after v9.1.0969)
    * 9.1.0969: ghostty not using kitty protocol by default
    * 9.1.0968: tests: GetFileNameChecks() isn't fully sorted by filetype name
    * runtime(doc): update version9.txt for bash filetype
    * runtime(netrw): update last change header for #16265
    * runtime(doc): fix doc error in :r behaviour
    * 9.1.0967: SpotBugs compiler setup can be further improved
    * 9.1.0966: Vim9: :enum command can be shortened
    * runtime(compiler): include a basic bash syntax checker compiler
    * 9.1.0965: filetype: sh filetype set when detecting the use of bash
    * runtime(doc): clarify ARCH value for 32-bit in INSTALLpc.txt
    * 9.1.0963: fuzzy-matching does not prefer full match
    * 9.1.0962: filetype: bun.lock file is not recognized
    * runtime(vim): update indentation plugin for Vim script
    * runtime(doc): tweak documentation style in helphelp.txt
    * runtime(vim): Update base-syntax, allow parens in default arguments
    * runtime(doc): mention auto-format using clang-format for sound.c/sign.c
    * runtime(help): fix typo s/additional/arbitrary/
    * runtime(help): Add better support for language annotation highlighting
    * 9.1.0961: filetype: TI gel files are not recognized
    * 9.1.0960: filetype: hy history files are not recognized
    * translation(fi): Fix typoes in Finish menu translation
    * 9.1.0959: Coverity complains about type conversion
    * runtime(vim): Use supported syntax in indent tests
    * 9.1.0958: filetype: supertux2 config files detected as lisp
    * 9.1.0956: completion may crash, completion highlight wrong with preview window
    * 9.1.0955: Vim9: vim9compile.c can be further improved
    * runtime(doc): move help tag E1182
    * runtime(graphql): contribute vim-graphql to Vim core
    * 9.1.0954: popupmenu.c can be improved
    * 9.1.0953: filetype: APKBUILD files not correctly detected
    * 9.1.0952: Vim9: missing type checking for any type assignment
    * 9.1.0951: filetype: jshell files are not recognized
    * runtime(dockerfile): do not set commentstring in syntax script
    * 9.1.0950: filetype: fennelrc files are not recognized
    * runtime(netrw): do not double escape Vim special characters
    * git: ignore reformatting change of netrw plugin
    * runtime(netrw): more reformating #16248
    * runtime(doc): Add a note about handling symbolic links in starting.txt
    * 9.1.0949: popups inconsistently shifted to the left
    * git: ignore reformatting change of netrw plugin
    * runtime(netrw): change indent size from 1 to 2
    * 9.1.0948: Missing cmdline completion for :pbuffer
    * runtime(tutor): Reformat tutor1
    * 9.1.0947: short-description
    * 9.1.0946: cross-compiling fails on osx-arm64
    * 9.1.0945: ComplMatchIns highlight doesn't end after inserted text
    * translation(sv): re-include the change from #16240
    * 9.1.0944: tests: test_registers fails when not run under X11
    * 9.1.0943: Vim9: vim9compile.c can be further improved
    * runtime(doc): Update README and mention make check to verify
    * translation(sv): partly revert commit 98874dca6d0b60ccd6fc3a140b3ec
    * runtime(vim): update base-syntax after v9.1.0936
    * 9.1.0942: a few typos were found
    * 9.1.0941: ComplMatchIns doesn't work after multibyte chars
    * runtime(doc): Fix style in fold.txt
    * translation(sv): Fix typo in Swedish translation
    * 9.1.0940: Wrong cursor shape with "gq" and 'indentexpr' executes :normal
    * runtime(doc): fix some small errors
    * 9.1.0939: make installtutor fails
    * 9.1.0938: exclusive selection not respected when re-selecting block mode
    * 9.1.0937: test_undolist() is flaky
    * 9.1.0936: cannot highlight completed text
    * 9.1.0935: SpotBugs compiler can be improved
    * 9.1.0934: hard to view an existing buffer in the preview window
    * runtime(doc): document how to minimize fold computation costs
    * 9.1.0933: Vim9: vim9compile.c can be further improved
    * 9.1.0932: new Italian tutor not installed
    * runtime(doc): fix a few minor errors from the last doc updates
    * translation(it): add Italian translation for the interactive tutor
    * runtime(doc): update the change.txt help file
    * runtime(help): Add Vim lang annotation support for codeblocks
    * 9.1.0931: ml_get error in terminal buffer
    * 9.1.0930: tests: test_terminal2 may hang in GUI mode
    * 9.1.0929: filetype: lalrpop files are not recognized
    * 9.1.0928: tests: test_popupwin fails because the filter command fails
    * editorconfig: set trim_trailing_whitespace = false for src/testdir/test*.vim
    * 9.1.0927: style issues in insexpand.c
    * 9.1.0926: filetype: Pixi lock files are not recognized
    * runtime(doc): Add a reference to |++opt| and |+cmd| at `:h :pedit`
    * runtime(doc): add a note about inclusive motions and exclusive selection
    * 9.1.0925: Vim9: expression compiled when not necessary
    * 9.1.0924: patch 9.1.0923 causes issues
    * 9.1.0923: too many strlen() calls in filepath.c
    * 9.1.0923: wrong MIN macro in popupmenu.c
    * 9.1.0921: popupmenu logic is a bit convoluted
    * 9.1.0920: Vim9: compile_assignment() too long
    * 9.1.0919: filetype: some assembler files are not recognized
    * runtime(netrw): do not pollute search history with symlinks
    * 9.1.0918: tiny Vim crashes with fuzzy buffer completion
    * 9.1.0917: various vartabstop and shiftround bugs when shifting lines
    * runtime(typst): add definition lists to formatlistpat, update maintainer
    * 9.1.0916: messages.c is exceeding 80 columns
    * runtime(proto): include filetype plugin for protobuf
    * 9.1.0915: GVim: default font size a bit too small
    * 9.1.0914: Vim9: compile_assignment() is too long
    * 9.1.0913: no error check for neg values for 'messagesopt'
    * runtime(netrw): only check first arg of netrw_browsex_viewer for being executable
    * 9.1.0912: xxd: integer overflow with sparse files and -autoskip
    * 9.1.0911: Variable name for 'messagesopt' doesn't match short name
    * 9.1.0910: 'messagesopt' does not check max wait time
    * runtime(doc): update wrong Vietnamese localization tag
    * 9.1.0909: Vim9: crash when calling instance method
  - update to 9.1.0908
    * refresh vim-7.3-mktemp_tutor.patch
    * 9.1.0908: not possible to configure :messages
    * 9.1.0907: printoptions:portrait does not change postscript Orientation
    * runtime(doc): Add vietnamese.txt to helps main TOC
    * 9.1.0906: filetype: Nvidia PTX files are not recognized
    * runtime(doc): updated version9.txt with changes from v9.1.0905
    * 9.1.0905: Missing information in CompleteDone event
    * 9.1.0904: Vim9: copy-paste error in class_defining_member()
    * 9.1.0903: potential overflow in spell_soundfold_wsal()
    * runtime(netrw): do not detach when launching external programs in gvim
    * runtime(doc): make tag alignment more consistent in filetype.txt
    * runtime(doc): fix wrong syntax and style of vietnamese.txt
    * translation(it): update Italian manpage for vimtutor
    * runtime(lua): add optional lua function folding
    * Filelist: include translations for Chapter 2 tutor
    * translation(vi): Update Vietnamese translation
    * runtime(doc): include vietnamese.txt
    * runtime(tutor): fix another typo in tutor2
    * runtime(doc): fix typo in vimtutor manpage
    * translation(it): update Italian manpage for vimtutor
    * translation(it): include Italian version of tutor chapter 2
    * runtime(tutor): regenerated some translated tutor1 files
    * runtime(tutor): fix typo in Chapter 2
    * 9.1.0902: filetype: Conda configuration files are not recognized
    * runtime(doc): Tweak documentation style a bit
    * runtime(tutor): update the tutor files and re-number the chapters
    * runtime(tutor): Update the makefiles for tutor1 and tutor2 files
    * 9.1.0901: MS-Windows: vimtutor batch script can be improved
    * runtime(doc): remove buffer-local completeopt todo item
    * 9.1.0900: Vim9: digraph_getlist() does not accept bool arg
    * runtime(typst): provide a formatlistpat in ftplugin
    * runtime(doc): Update documentation for "noselect" in 'completeopt'
    * 9.1.0899: default for 'backspace' can be set in C code
    * runtime(helptoc): reload cached g:helptoc.shell_prompt when starting toc
    * translation(ru): Updated messages translation
    * 9.1.0898: runtime(compiler): pytest compiler not included
    * 9.1.0897: filetype: pyrex files are not detected
    * runtime(compiler): update eslint compiler
    * 9.1.0896: completion list wrong after v9.1.0891
    * runtime(doc): document changed default value for 'history'
    * 9.1.0895: default history value is too small
    * 9.1.0894: No test for what the spotbug compiler parses
    * 9.1.0893: No test that undofile format does not regress
    * translation(de): update German manpages
    * runtime(compiler): include spotbugs Java linter
    * 9.1.0892: the max value of 'tabheight' is limited by other tabpages
    * runtime(po): remove poDiffOld/New, add po-format flags to syntax file
    * 9.1.0891: building the completion list array is inefficient
    * patch 9.1.0890: %! item not allowed for 'rulerformat'
    * runtime(gzip): load undofile if there exists one
    * 9.1.0889: Possible unnecessary redraw after adding/deleting lines
    * 9.1.0888: leftcol property not available in getwininfo()
    * 9.1.0887: Wrong expression in sign.c
    * 9.1.0886: filetype: debian control file not detected
    * runtime(c3): include c3 filetype plugin
    * 9.1.0885: style of sign.c can be improved
    * 9.1.0884: gcc warns about uninitialized variable
    * runtime(apache): Update syntax directives for apache server 2.4.62
    * translation(ru): updated vimtutor translation, update MAINTAINERS file
    * 9.1.0883: message history cleanup is missing some tests
    * runtime(doc): Expand docs on :! vs. :term
    * runtime(netrw): Fixing powershell execution issues on Windows
    * 9.1.0882: too many strlen() calls in insexpand.c
    * 9.1.0881: GUI: message dialog may not get focus
    * runtime(netrw): update netrw's decompress logic
    * runtime(apache): Update syntax keyword definition
    * runtime(misc): add Italian LICENSE and (top-level) README file
    * 9.1.0880: filetype: C3 files are not recognized
    * runtime(doc): add helptag for :HelpToc command
    * 9.1.0879: source is not consistently formatted
    * Add clang-format config file
    * runtime(compiler): fix escaping of arguments passed to :CompilerSet
    * 9.1.0878: termdebug: cannot enable DEBUG mode
    * 9.1.0877: tests: missing test for termdebug + decimal signs
    * 9.1.0876: filetype: openCL files are not recognized
    * 9.1.0875: filetype: hyprlang detection can be improved
    * 9.1.0874: filetype: karel files are not detected
    * 9.1.0873: filetype: Vivado files are not recognized
    * 9.1.0872: No test for W23 message
    * 9.1.0871: getcellpixels() can be further improved
    * 9.1.0870: too many strlen() calls in eval.c
    * 9.1.0869: Problem: curswant not set on gm in folded line
    * 9.1.0868: the warning about missing clipboard can be improved
    * runtime(doc): Makefile does not clean up all temporary files
    * 9.1.0867: ins_compl_add() has too many args
    * editorconfig: don't trim trailing whitespaces in runtime/doc
    * translation(am): Remove duplicate keys in desktop files
    * runtime(doc): update helptags
    * runtime(filetype): remove duplicated *.org file pattern
    * runtime(cfg): only consider leading // as starting a comment
    * 9.1.0866: filetype: LLVM IR files are not recognized
    * 9.1.0865: filetype: org files are not recognized
    * 9.1.0864: message history is fixed to 200
    * 9.1.0863: getcellpixels() can be further improved
    * runtime(sh): better function support for bash/zsh in indent script
    * runtime(netrw): small fixes to netrw#BrowseX
    * 9.1.0862: 'wildmenu' not enabled by default in nocp mode
    * runtime(doc): update how to report issues for mac Vim
    * runtime(doc): mention option-backslash at :h CompilerSet
    * runtime(compiler): include a Java Maven compiler plugin
    * runtime(racket): update Racket runtime files
    * runtime(doc): improve indentation in examples for netrw-handler
    * runtime(doc): improve examples for netrw-handler functions
    * runtime(idris2): include filetype,indent+syntax plugins for (L)Idris2 + ipkg
    * runtime(doc): clarify the use of filters and external commands
    * 9.1.0861: Vim9: no runtime check for object member access of any var
    * runtime(compiler): update pylint linter
    * 9.1.0860: tests: mouse_shape tests use hard code sleep value
    * 9.1.0859: several problems with the GLVS plugin
    * 9.1.0858: Coverity complains about dead code
    * runtime(tar): Update tar.vim to support permissions
    * 9.1.0857: xxd: --- is incorrectly recognized as end-of-options
    * 9.1.0851: too many strlen() calls in getchar.c
    * 9.1.0850: Vim9: cannot access nested object inside objects
    * runtime(tex): extra Number highlighting causes issues
    * runtime(vim): Fix indent after :silent! function
    * 9.1.0849: there are a few typos in the source
    * runtime(netrw): directory symlink not resolved in tree view
    * runtime(doc): add a table of supported Operating Systems
    * runtime(tex): update Last Change header in syntax script
    * runtime(doc): fix typo in g:termdebug_config
    * runtime(vim): Update base-syntax, improve :normal highlighting
    * runtime(tex): add Number highlighting to syntax file
    * runtime(doc): Tweak documentation style a bit
    * 9.1.0848: if_lua: v:false/v:true are not evaluated to boolean
    * runtime(dune): use :setl instead of :set in ftplugin
    * runtime(termdebug): allow to use decimal signs
    * translation(it): Updated Italian vimtutor
    * runtime(compiler): improve cppcheck
    * git: git-blame-ignore-revs shown as an error on Github
    * 9.1.0847: tests: test_popupwin fails because of updated help file
    * 9.1.0846: debug symbols for xxd are not cleaned in Makefile
    * runtime(structurizr): Update structurizr syntax
    * runtime(8th): updated 8th syntax
    * runtime(doc): Add pi_tutor.txt to help TOC
    * runtime(compiler): add mypy and ruff compiler; update pylint linter
    * runtime(netrw): fix several bugs in netrw tree listing
    * runtime(netrw): prevent polluting the search history
    * 9.1.0845: vimtutor shell script can be improved
    * 9.1.0844: if_python: no way to pass local vars to python
    * 9.1.0843: too many strlen() calls in undo.c
    * runtime(doc): update default value for fillchars option
    * runtime(compiler): fix typo in cppcheck compiler plugin
    * runtime(doc): simplify vimtutor manpage a bit more
    * runtime(matchparen): Add matchparen_disable_cursor_hl config option
    * 9.1.0842: not checking for the sync() systemcall
    * 9.1.0841: tests: still preferring python2 over python3
    * 9.1.0840: filetype: idris2 files are not recognized
    * 9.1.0839: filetype: leo files are not recognized
    * runtime(cook): include cook filetype plugin
    * runtime(debversions): Update Debian versions
    * patch 9.1.0838: vimtutor is bash-specific
    * runtime(doc): add help specific modeline to pi_tutor.txt
    * Filelist: vimtutor chapter 2 is missing in Filelist
    * 9.1.0837: cross-compiling has some issues
    * runtime(vimtutor): Add a second chapter

------------------------------------------------------------------
------------------  2025-2-18  -  Feb 18 2025  -------------------
------------------------------------------------------------------

++++ canutils:

  - Add 0001-build-give-libisobusfs-a-version.patch

++++ guestfs-tools:

  - Update to version 1.53.7 (jsc#PED-8910)
    * mlcustomize, mltools: Replace $TEST_FUNCTIONS
    * mldrivers/linux_bootloaders.ml: Don't overwrite EFI grub2 wrapper
    * resize: Use stderr consistently for debug messages
    * resize/test-virt-resize.pl: Various fixes and adjustments

++++ hwdata:

  - Update to version 0.392:
    * Update pci and vendor ids

++++ kernel-default:

  - vhost/net: Set num_buffers for virtio 1.0 (git-fixes).
  - commit 3d87f0e
  - s390/virtio_ccw: Fix dma_parm pointer not set up (git-fixes).
  - commit 15ec5ee
  - virtio_blk: reverse request order in virtio_queue_rqs
    (git-fixes).
  - commit a91d779
  - zram: fix potential UAF of zram table (git-fixes).
  - block: avoid to reuse `hctx` not removed from cpuhp callback
    list (git-fixes).
  - block: don't verify IO lock for freeze/unfreeze in
    elevator_init_mq() (git-fixes).
  - block: always verify unfreeze lock on the owner task
    (git-fixes).
  - commit 16febb0
  - iommu/amd: Expicitly enable CNTRL.EPHEn bit in resume path
    (git-fixes).
  - commit b2a42ed
  - iommu: Fix potential memory leak in  iopf_queue_remove_device()
    (git-fixes).
  - commit 074adf0
  - s390/stackleak: Use exrl instead of ex in __stackleak_poison()
    (git-fixes bsc#1237317).
  - commit 4950e44
  - x86/xen: allow larger contiguous memory regions in PV guests
    (git-fixes).
  - commit 959d5ed
  - xen/swiotlb: relax alignment requirements (git-fixes).
  - commit 02c1859
  - x86/xen: add FRAME_END to xen_hypercall_hvm() (git-fixes).
  - commit f61b030
  - x86/xen: fix xen_hypercall_hvm() to not clobber %rbx
    (git-fixes).
  - commit f11a452
  - Update
    patches.suse/RDMA-hns-Fix-NULL-pointer-derefernce-in-hns_roce_map.patch (CVE-2024-53226 bsc#1236576)
  - Update
    patches.suse/USB-serial-quatech2-fix-null-ptr-deref-in-qt2_proces.patch (CVE-2025-21689 bsc#1237017)
  - Update
    patches.suse/bpf-Call-free_htab_elem-after-htab_unlock_bucket.patch (CVE-2024-56592 bsc#1235244)
  - Update
    patches.suse/bpf-Prevent-tailcall-infinite-loop-caused-by-freplac.patch (CVE-2024-47794 bsc#1235712)
  - Update
    patches.suse/bpf-put-bpf_link-s-program-when-link-is-safe-to-be-d.patch (CVE-2024-56786 bsc#1235644)
  - Update
    patches.suse/cachestat-fix-page-cache-statistics-permission-check.patch (CVE-2025-21691 bsc#1237026)
  - Update
    patches.suse/cgroup-cpuset-remove-kernfs-active-break.patch (CVE-2025-21634 bsc#1236110)
  - Update
    patches.suse/drm-amd-display-Initialize-denominator-defaults-to-1.patch (CVE-2024-57950 bsc#1237032)
  - Update
    patches.suse/drm-v3d-Assign-job-pointer-to-NULL-before-signaling-.patch (CVE-2025-21688 bsc#1237007)
  - Update
    patches.suse/drm-v3d-Ensure-job-pointer-is-set-to-NULL-after-job-.patch (CVE-2025-21697 bsc#1237132)
  - Update
    patches.suse/gfs2-Truncate-address-space-when-flipping-GFS2_DIF_JDATA-flag.patch (CVE-2025-21699 bsc#1237139)
  - Update
    patches.suse/gpio-xilinx-Convert-gpio_lock-to-raw-spinlock.patch (CVE-2025-21684 bsc#1236952)
  - Update
    patches.suse/iomap-avoid-avoid-truncating-64-bit-offset-to-32-bits.patch (CVE-2025-21667 bsc#1236681)
  - Update
    patches.suse/media-amphion-Set-video-drvdata-before-register-vide.patch (CVE-2024-56579 bsc#1236575)
  - Update
    patches.suse/msft-hv-3155-scsi-storvsc-Ratelimit-warning-logs-to-prevent-VM-de.patch (CVE-2025-21690 bsc#1237025)
  - Update
    patches.suse/pinctrl-mcp23s08-Fix-sleeping-in-atomic-context-due-.patch (CVE-2024-57889 bsc#1236573)
  - Update
    patches.suse/platform-x86-dell-uart-backlight-fix-serdev-race.patch (CVE-2025-21695 bsc#1237110)
  - Update
    patches.suse/platform-x86-lenovo-yoga-tab2-pro-1380-fastcharger-f.patch (CVE-2025-21685 bsc#1236953)
  - Update
    patches.suse/pmdomain-imx8mp-blk-ctrl-add-missing-loop-break-cond.patch (CVE-2025-21668 bsc#1236682)
  - commit 3462ac1
  - bpf, sockmap: Several fixes to bpf_msg_pop_data (CVE-2024-56720
    bsc#1235592).
  - commit 0185843
  - net: Fix icmp host relookup triggering ip_rt_bug (CVE-2024-56647
    bsc#1235435).
  - commit 49b2b74
  - USB: Fix the issue of task recovery failure caused by USB
    status when S4 wakes up (git-fixes).
  - commit 0e001cb
  - ipv6: avoid possible NULL deref in modify_prefix_route()
    (CVE-2024-56646 bsc#1235131).
  - commit 5a68a13
  - USB: make to_usb_device_driver() use container_of_const()
    (jsc#PED-10906).
  - commit 1cd52ca
  - drm/amd/display: Fix seamless boot sequence (stable-fixes).
  - drm/amdgpu: add a BO metadata flag to disable write compression
    for Vulkan (stable-fixes).
  - drm/amd/amdgpu: change the config of cgcg on gfx12
    (stable-fixes).
  - drm/amdkfd: Block per-queue reset when halt_if_hws_hang=1
    (stable-fixes).
  - drm/amd/display: Optimize cursor position updates
    (stable-fixes).
  - drm/client: Handle tiled displays better (stable-fixes).
  - ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback
    (stable-fixes).
  - clk: qcom: Make GCC_8150 depend on QCOM_GDSC (stable-fixes).
  - wifi: iwlwifi: pcie: Add support for new device ids
    (stable-fixes).
  - drm/amd/display: Limit Scaling Ratio on DCN3.01 (stable-fixes).
  - drm/amd/display: Increase sanitizer frame larger than limit
    when compile testing with clang (stable-fixes).
  - drm/amdkfd: Queue interrupt work to different CPU
    (stable-fixes).
  - drm/amdgpu: Don't enable sdma 4.4.5 CTXEMPTY interrupt
    (stable-fixes).
  - drm/amd/display: Overwriting dualDPP UBF values before usage
    (stable-fixes).
  - drm/amd/display: Populate chroma prefetch parameters, DET
    buffer fix (stable-fixes).
  - drm/vc4: hdmi: use eld_mutex to protect access to connector->eld
    (stable-fixes).
  - drm/sti: hdmi: use eld_mutex to protect access to connector->eld
    (stable-fixes).
  - drm/radeon: use eld_mutex to protect access to connector->eld
    (stable-fixes).
  - drm/exynos: hdmi: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/amd/display: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/bridge: ite-it66121: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/bridge: anx7625: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/connector: add mutex to protect ELD from concurrent access
    (stable-fixes).
  - drm/tests: hdmi: return meaningful value from
    set_connector_edid() (stable-fixes).
  - drm/tests: hdmi: handle empty modes in find_preferred_mode()
    (stable-fixes).
  - drm: panel-backlight-quirks: Add Framework 13 glossy and 2.8k
    panels (stable-fixes).
  - drm: panel-backlight-quirks: Add Framework 13 matte panel
    (stable-fixes).
  - drm: Add panel backlight quirks (stable-fixes).
  - commit 88df338
  - USB: make to_usb_driver() use container_of_const()
    (jsc#PED-10906).
  - commit 3096d5c
  - USB: properly lock dynamic id list when showing an id
    (jsc#PED-10906).
  - commit a65f0a3
  - USB: core: remove dead code in do_proc_bulk() (jsc#PED-10906).
  - commit f209e17
  - usb: core: use sysfs_emit() instead of sprintf()
    (jsc#PED-10906).
  - commit 4b40393
  - usb: require FMODE_WRITE for usbdev_mmap() (jsc#PED-10906).
  - commit 552bff1
  - powerpc/code-patching: Fix KASAN hit by not flagging text
    patching area as VM_ALLOC (bsc#1215199).
  - powerpc/64s: Rewrite __real_pte() and __rpte_to_hidx() as
    static inline (bsc#1215199).
  - powerpc/code-patching: Disable KASAN report during patching
    via temporary mm (bsc#1215199).
  - commit f5c0b81

++++ kernel-firmware-i915:

  - Update to version 20250217 (git commit 487f2f2421ae):
    * i915: Update Xe3LPD DMC to v2.17
  - Drop duplicated aliases

++++ kernel-firmware-sound:

  - Update to version 20250217 (git commit 487f2f2421ae):
    * ASoC: tas2781: Change regbin firmwares for single device
  - Drop duplicated aliases

++++ kernel-rt:

  - vhost/net: Set num_buffers for virtio 1.0 (git-fixes).
  - commit 3d87f0e
  - s390/virtio_ccw: Fix dma_parm pointer not set up (git-fixes).
  - commit 15ec5ee
  - virtio_blk: reverse request order in virtio_queue_rqs
    (git-fixes).
  - commit a91d779
  - zram: fix potential UAF of zram table (git-fixes).
  - block: avoid to reuse `hctx` not removed from cpuhp callback
    list (git-fixes).
  - block: don't verify IO lock for freeze/unfreeze in
    elevator_init_mq() (git-fixes).
  - block: always verify unfreeze lock on the owner task
    (git-fixes).
  - commit 16febb0
  - iommu/amd: Expicitly enable CNTRL.EPHEn bit in resume path
    (git-fixes).
  - commit b2a42ed
  - iommu: Fix potential memory leak in  iopf_queue_remove_device()
    (git-fixes).
  - commit 074adf0
  - s390/stackleak: Use exrl instead of ex in __stackleak_poison()
    (git-fixes bsc#1237317).
  - commit 4950e44
  - x86/xen: allow larger contiguous memory regions in PV guests
    (git-fixes).
  - commit 959d5ed
  - xen/swiotlb: relax alignment requirements (git-fixes).
  - commit 02c1859
  - x86/xen: add FRAME_END to xen_hypercall_hvm() (git-fixes).
  - commit f61b030
  - x86/xen: fix xen_hypercall_hvm() to not clobber %rbx
    (git-fixes).
  - commit f11a452
  - Update
    patches.suse/RDMA-hns-Fix-NULL-pointer-derefernce-in-hns_roce_map.patch (CVE-2024-53226 bsc#1236576)
  - Update
    patches.suse/USB-serial-quatech2-fix-null-ptr-deref-in-qt2_proces.patch (CVE-2025-21689 bsc#1237017)
  - Update
    patches.suse/bpf-Call-free_htab_elem-after-htab_unlock_bucket.patch (CVE-2024-56592 bsc#1235244)
  - Update
    patches.suse/bpf-Prevent-tailcall-infinite-loop-caused-by-freplac.patch (CVE-2024-47794 bsc#1235712)
  - Update
    patches.suse/bpf-put-bpf_link-s-program-when-link-is-safe-to-be-d.patch (CVE-2024-56786 bsc#1235644)
  - Update
    patches.suse/cachestat-fix-page-cache-statistics-permission-check.patch (CVE-2025-21691 bsc#1237026)
  - Update
    patches.suse/cgroup-cpuset-remove-kernfs-active-break.patch (CVE-2025-21634 bsc#1236110)
  - Update
    patches.suse/drm-amd-display-Initialize-denominator-defaults-to-1.patch (CVE-2024-57950 bsc#1237032)
  - Update
    patches.suse/drm-v3d-Assign-job-pointer-to-NULL-before-signaling-.patch (CVE-2025-21688 bsc#1237007)
  - Update
    patches.suse/drm-v3d-Ensure-job-pointer-is-set-to-NULL-after-job-.patch (CVE-2025-21697 bsc#1237132)
  - Update
    patches.suse/gfs2-Truncate-address-space-when-flipping-GFS2_DIF_JDATA-flag.patch (CVE-2025-21699 bsc#1237139)
  - Update
    patches.suse/gpio-xilinx-Convert-gpio_lock-to-raw-spinlock.patch (CVE-2025-21684 bsc#1236952)
  - Update
    patches.suse/iomap-avoid-avoid-truncating-64-bit-offset-to-32-bits.patch (CVE-2025-21667 bsc#1236681)
  - Update
    patches.suse/media-amphion-Set-video-drvdata-before-register-vide.patch (CVE-2024-56579 bsc#1236575)
  - Update
    patches.suse/msft-hv-3155-scsi-storvsc-Ratelimit-warning-logs-to-prevent-VM-de.patch (CVE-2025-21690 bsc#1237025)
  - Update
    patches.suse/pinctrl-mcp23s08-Fix-sleeping-in-atomic-context-due-.patch (CVE-2024-57889 bsc#1236573)
  - Update
    patches.suse/platform-x86-dell-uart-backlight-fix-serdev-race.patch (CVE-2025-21695 bsc#1237110)
  - Update
    patches.suse/platform-x86-lenovo-yoga-tab2-pro-1380-fastcharger-f.patch (CVE-2025-21685 bsc#1236953)
  - Update
    patches.suse/pmdomain-imx8mp-blk-ctrl-add-missing-loop-break-cond.patch (CVE-2025-21668 bsc#1236682)
  - commit 3462ac1
  - bpf, sockmap: Several fixes to bpf_msg_pop_data (CVE-2024-56720
    bsc#1235592).
  - commit 0185843
  - net: Fix icmp host relookup triggering ip_rt_bug (CVE-2024-56647
    bsc#1235435).
  - commit 49b2b74
  - USB: Fix the issue of task recovery failure caused by USB
    status when S4 wakes up (git-fixes).
  - commit 0e001cb
  - ipv6: avoid possible NULL deref in modify_prefix_route()
    (CVE-2024-56646 bsc#1235131).
  - commit 5a68a13
  - USB: make to_usb_device_driver() use container_of_const()
    (jsc#PED-10906).
  - commit 1cd52ca
  - drm/amd/display: Fix seamless boot sequence (stable-fixes).
  - drm/amdgpu: add a BO metadata flag to disable write compression
    for Vulkan (stable-fixes).
  - drm/amd/amdgpu: change the config of cgcg on gfx12
    (stable-fixes).
  - drm/amdkfd: Block per-queue reset when halt_if_hws_hang=1
    (stable-fixes).
  - drm/amd/display: Optimize cursor position updates
    (stable-fixes).
  - drm/client: Handle tiled displays better (stable-fixes).
  - ASoC: soc-pcm: don't use soc_pcm_ret() on .prepare callback
    (stable-fixes).
  - clk: qcom: Make GCC_8150 depend on QCOM_GDSC (stable-fixes).
  - wifi: iwlwifi: pcie: Add support for new device ids
    (stable-fixes).
  - drm/amd/display: Limit Scaling Ratio on DCN3.01 (stable-fixes).
  - drm/amd/display: Increase sanitizer frame larger than limit
    when compile testing with clang (stable-fixes).
  - drm/amdkfd: Queue interrupt work to different CPU
    (stable-fixes).
  - drm/amdgpu: Don't enable sdma 4.4.5 CTXEMPTY interrupt
    (stable-fixes).
  - drm/amd/display: Overwriting dualDPP UBF values before usage
    (stable-fixes).
  - drm/amd/display: Populate chroma prefetch parameters, DET
    buffer fix (stable-fixes).
  - drm/vc4: hdmi: use eld_mutex to protect access to connector->eld
    (stable-fixes).
  - drm/sti: hdmi: use eld_mutex to protect access to connector->eld
    (stable-fixes).
  - drm/radeon: use eld_mutex to protect access to connector->eld
    (stable-fixes).
  - drm/exynos: hdmi: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/amd/display: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/bridge: ite-it66121: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/bridge: anx7625: use eld_mutex to protect access to
    connector->eld (stable-fixes).
  - drm/connector: add mutex to protect ELD from concurrent access
    (stable-fixes).
  - drm/tests: hdmi: return meaningful value from
    set_connector_edid() (stable-fixes).
  - drm/tests: hdmi: handle empty modes in find_preferred_mode()
    (stable-fixes).
  - drm: panel-backlight-quirks: Add Framework 13 glossy and 2.8k
    panels (stable-fixes).
  - drm: panel-backlight-quirks: Add Framework 13 matte panel
    (stable-fixes).
  - drm: Add panel backlight quirks (stable-fixes).
  - commit 88df338
  - USB: make to_usb_driver() use container_of_const()
    (jsc#PED-10906).
  - commit 3096d5c
  - USB: properly lock dynamic id list when showing an id
    (jsc#PED-10906).
  - commit a65f0a3
  - USB: core: remove dead code in do_proc_bulk() (jsc#PED-10906).
  - commit f209e17
  - usb: core: use sysfs_emit() instead of sprintf()
    (jsc#PED-10906).
  - commit 4b40393
  - usb: require FMODE_WRITE for usbdev_mmap() (jsc#PED-10906).
  - commit 552bff1
  - powerpc/code-patching: Fix KASAN hit by not flagging text
    patching area as VM_ALLOC (bsc#1215199).
  - powerpc/64s: Rewrite __real_pte() and __rpte_to_hidx() as
    static inline (bsc#1215199).
  - powerpc/code-patching: Disable KASAN report during patching
    via temporary mm (bsc#1215199).
  - commit f5c0b81

++++ gcc15:

  - Enable cross compilers on loongarch64

++++ orc:

  - Update to version 0.4.41:
    + orccodemem: Don't modify the process umask, which caused race
    conditions with other threads
    + x86: various SSE and MMX fixes
    + avx: Fix sqrtps encoding causing an illegal instruction crash
    + Hide internal symbols from ABI and do not install internal
    headers
    + Rename backend to target, including `orc-backend` meson option
    and `ORC_BACKEND` environment variable
    + Testsuite, tools: Disambiguate OrcProgram naming conventions
    + Build: Fix `_clear_cache` call for Clang and error out on
    implicit function declarations
    + opcodes: Use MIN instead of CLAMP for known unsigned values to
    fix compiler warnings
    + Spelling fix in debug log message

++++ sqlite3:

  - Update to release 3.49.1:
    * Improve portability of makefiles and configure scripts.
    * CVE-2025-29087, CVE-2025-3277, bsc#1241020:
    Fix a bug in the concat_ws() function, introduced in version
    3.44.0, that could lead to a memory error if the separator
    string is very large (hundreds of megabytes).
    * CVE-2025-29088, bsc#1241078: Enhanced the
    SQLITE_DBCONFIG_LOOKASIDE interface to make it  more robust
    against misuse.

++++ libssh:

  - Move global config dir to /usr/etc/libssh (bsc#1222716)
    * Add patch libssh-cmake-Add-option-WITH_HERMETIC_USR.patch

++++ libvirt:

  - spec: Add note about packages with no files
    bsc#1237228

++++ libxml2:

  - Update to version 2.13.6 ([bsc#1237363], [bsc#1237370], [bsc#1237418]):
    + Security:
  - [CVE-2025-24928] Fix stack-buffer-overflow in
    xmlSnprintfElements
  - [CVE-2024-56171] Fix use-after-free after
    xmlSchemaItemListAdd
  - pattern: Fix compilation of explicit child axis
    + Regressions:
  - xmllint: Support compressed input from stdin
  - uri: Fix handling of Windows drive letters
  - reader: Fix return value of xmlTextReaderReadString again
  - SAX2: Fix xmlSAX2ResolveEntity if systemId is NULL
    + Portability:
  - dict: Handle ENOSYS from getentropy gracefully
  - Fix compilation with uclibc (Dario Binacchi)
  - python: Declare init func with PyMODINIT_FUNC
  - tests: Fix sanitizer version check on old Apple clang
  - cmake: Work around broken sys/random.h in old macOS SDKs
    + Build:
  - autotools: Set AC_CONFIG_AUX_DIR
  - cmake: Always build Python module as shared library
  - cmake: add missing `Bcrypt` link on Windows
  - cmake: Fix compatibility in package version file
  - xmlIO: Fix reading from non-regular files like pipes
  - xmlreader: Fix return value of xmlTextReaderReadString
  - parser: Fix loading of parameter entities in external DTDs
  - parser: Fix downstream code that swaps DTDs
  - parser: Fix detection of duplicate attributes
  - string: Fix va_copy fallback
  - xpath: Fix parsing of non-ASCII names
  - Drop libxml2-support-compressed-input-from-stdin.patch: Fixed
    upstream.
  - Also CVE-2025-27113 was assigned to this release.

++++ nvidia-open-driver-G06-signed:

  - In the module install path revert the order of the 'updates'
    subdirectory and the package name & version. This satisfies
    the kmp dependency checker (boo#1237308).

++++ openssh:

  - Update to openssh 9.9p2:
    = Security
    * Fix CVE-2025-26465 - ssh(1) in OpenSSH versions 6.8p1 to 9.9p1
    (inclusive) contained a logic error that allowed an on-path
    attacker (a.k.a MITM) to impersonate any server when the
    VerifyHostKeyDNS option is enabled. This option is off by
    default.
    * Fix CVE-2025-26466 - sshd(8) in OpenSSH versions 9.5p1 to 9.9p1
    (inclusive) is vulnerable to a memory/CPU denial-of-service
    related to the handling of SSH2_MSG_PING packets. This
    condition may be mitigated using the existing
    PerSourcePenalties feature.
    Both vulnerabilities were discovered and demonstrated to be
    exploitable by the Qualys Security Advisory team. The openSSH
    team thanks them for their detailed review of OpenSSH.
    = Bugfixes
    * ssh(1), sshd(8): fix regression in Match directive that caused
    failures when predicates and their arguments were separated by
    '=' characters instead of whitespace (bz3739).
    * sshd(8): fix the "Match invalid-user" predicate, which was
    matching incorrectly in the initial pass of config evaluation.
    * ssh(1), sshd(8), ssh-keyscan(1): fix mlkem768x25519-sha256 key
    exchange on big-endian systems.
    * Fix a number of build problems on particular operating systems
    and configurations.
  - Remove patches that are already included in 9.9p2:
    * 0001-fix-utmpx-ifdef.patch
    * 0002-upstream-fix-regression-introduced-when-I-switched-the-Match.patch
    * 0003-upstream-fix-previous-change-to-ssh_config-Match_-which-broken-on.patch
    * 0004-upstream-fix-ML-KEM768x25519-KEX-on-big-endian-systems-spotted-by.patch
    * fix-CVE-2025-26465-and-CVE-2025-26466.patch

++++ perl-Error:

  - updated to 0.17030
    see /usr/share/doc/packages/perl-Error/ChangeLog

++++ psmisc:

  - Looks like Factory and TW includes glibc-gconv-modules-extra at build time

++++ python-M2Crypto:

  - Fix spelling of BSD-2-Clause license.
  - Add rpmlintrc … overflow of ignorable rpmlint warnings caused
    me not to see the previous problem.

++++ python-distro:

  - Build package for multiple Python flavors on the SLE15 family

++++ libxml2-python:

  - Update to version 2.13.6 ([bsc#1237363], [bsc#1237370], [bsc#1237418]):
    + Security:
  - [CVE-2025-24928] Fix stack-buffer-overflow in
    xmlSnprintfElements
  - [CVE-2024-56171] Fix use-after-free after
    xmlSchemaItemListAdd
  - pattern: Fix compilation of explicit child axis
    + Regressions:
  - xmllint: Support compressed input from stdin
  - uri: Fix handling of Windows drive letters
  - reader: Fix return value of xmlTextReaderReadString again
  - SAX2: Fix xmlSAX2ResolveEntity if systemId is NULL
    + Portability:
  - dict: Handle ENOSYS from getentropy gracefully
  - Fix compilation with uclibc (Dario Binacchi)
  - python: Declare init func with PyMODINIT_FUNC
  - tests: Fix sanitizer version check on old Apple clang
  - cmake: Work around broken sys/random.h in old macOS SDKs
    + Build:
  - autotools: Set AC_CONFIG_AUX_DIR
  - cmake: Always build Python module as shared library
  - cmake: add missing `Bcrypt` link on Windows
  - cmake: Fix compatibility in package version file
  - xmlIO: Fix reading from non-regular files like pipes
  - xmlreader: Fix return value of xmlTextReaderReadString
  - parser: Fix loading of parameter entities in external DTDs
  - parser: Fix downstream code that swaps DTDs
  - parser: Fix detection of duplicate attributes
  - string: Fix va_copy fallback
  - xpath: Fix parsing of non-ASCII names
  - Drop libxml2-support-compressed-input-from-stdin.patch: Fixed
    upstream.
  - Also CVE-2025-27113 was assigned to this release.

++++ zypp-plugin:

  - version 0.6.5

++++ thin-provisioning-tools:

  - Enable internal testsuite
  - Refresh vendored dependencies

++++ xfsprogs:

  - mkfs: fix filesize function compilation error on 32-bit archs
  - add mkfs-fix-filesize-function-compilation-error-on-32-b.patch

------------------------------------------------------------------
------------------  2025-2-17  -  Feb 17 2025  -------------------
------------------------------------------------------------------

++++ dpdk:

  - Update to LTS version 24.11
    * Changelog: https://doc.dpdk.org/guides/rel_notes/release_24_11.html
    * This update fix build with glibc 2.41
  - Use gcc14 on x86_64 SLE15/16 to avoid the inline error

++++ fontconfig:

  - update to 2.16.0:
    * Fix misleading-indentation warning
    * Deal with glob string properly
    * Allow comma as a delimiter in postscriptname and ignore it on matching
    * Refactor exclusive language logic into separate file
    * Use proper postscriptname for named instance if any
    * Remove redundant leaf assignment in fcfreetype.c
    * Ensure lock/unlock symmetry
    * Ensure config is locked during retry in FcConfigReference
    * Unlock on allocation failure in FcCacheInsert
    * Fix FcSerialize undefined behavior with null pointer usage
    * Fix undefined behavior issue on qsort call
    * Add cop.orth for Coptic language
    * Add got.orth for Gothic language
    * Fix a memory leak in fc-list/fc-query/fc-scan
    * mark _FcPatternIter as may_alias
    * Accept integer for pixelsize
    * Improve hinting detection for fonthashint object
    * Add FcConfigSetFontSetFilter
    * Fix some code found by SAST
    * Set FcTypeVoid if no valid types to convert
    * Fix a memory leak in _get_real_paths_from_prefix
    * Fix double slashes in path
    * More information when no writable cache directories
    * Fix test case for reproducible builds
    * Fix invalid escape character \s
    * Sort out bitmap related config files
    * Clean up .uuid files with fc-cache -f too
  - add fontconfig-autoconf269.patch to start leap build

++++ glibc:

  - Remove nis from nsswitch.conf (bsc#1237210)

++++ kernel-default:

  - rseq: Fix rseq unregistration regression (bsc#1234634 (Scheduler
    functional and performance backports)).
  - commit d16e10a
  - locking/ww_mutex: Fix ww_mutex dummy lockdep map selftest
    warnings (bsc#1234634 (Scheduler functional and performance
    backports)).
  - commit 7357fd9
  - debugfs: Fix the missing initializations in __debugfs_file_get()
    (jsc#PED-10906).
  - commit a5a225f
  - net: sched: Disallow replacing of child qdisc from one parent
    to another (CVE-2025-21700 bsc#1237159).
  - commit 45e9f84
  - usb: common: expand documentation for USB functions
    (jsc#PED-10906).
  - commit 5dc8ea1
  - USB: make single lock for all usb dynamic id lists
    (jsc#PED-10906).
  - commit ca6a4cf
  - pktgen: Avoid out-of-bounds access in get_imix_entries
    (CVE-2025-21680 bsc#1236700).
  - commit a7a7f74
  - sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy (CVE-2025-21640 bsc#1236123)
  - commit a4016e3
  - sctp: sysctl: rto_min/max: avoid using current->nsproxy (CVE-2025-21639 bsc#1236122)
  - commit 3a3fa72
  - sctp: sysctl: auth_enable: avoid using current->nsproxy (CVE-2025-21638 bsc#1236115)
  - commit 923596b
  - sctp: sysctl: udp_port: avoid using current->nsproxy (CVE-2025-21637 bsc#1236114)
  - commit 8abdd74
  - sctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxy (CVE-2025-21636 bsc#1236113)
  - commit 19d97ab
  - usb: host: xhci-plat: add support compatible ID PNP0D15
    (jsc#PED-10906).
  - commit e39bb0b
  - USB: host: Use str_enable_disable-like helpers (jsc#PED-10906).
  - commit 2c7456c
  - xhci: don't mess with ->d_iname (jsc#PED-10906).
  - commit 739b405
  - debugfs: allow to store an additional opaque pointer at file
    creation (jsc#PED-10906).
  - commit 2324ce1
  - debugfs: don't mess with bits in ->d_fsdata (jsc#PED-10906).
  - commit ef5509c
  - debugfs: get rid of dynamically allocation proxy_ops
    (jsc#PED-10906).
  - commit 2205145
  - debugfs: move ->automount into debugfs_inode_info
    (jsc#PED-10906).
  - commit 1597940
  - debugfs: separate cache for debugfs inodes (jsc#PED-10906).
  - commit dcce65c
  - fs: debugfs: fix open proxy for unsafe files (jsc#PED-10906).
  - commit 9dffd44
  - debugfs: fix missing mutex_destroy() in short_fops case
    (jsc#PED-10906).
  - commit efab813
  - fs: debugfs: differentiate short fops with proxy ops
    (jsc#PED-10906).
  - commit dae3000
  - debugfs: add small file operations for most files
    (jsc#PED-10906).
  - commit c4f473c
  - xhci: Add missing capability definition bits (jsc#PED-10906).
  - commit 7f85c83
  - xhci: Add command completion parameter support (jsc#PED-10906).
  - commit 946ecb2
  - xhci: dbgtty: Improve performance by handling received data
    immediately (jsc#PED-10906).
  - commit 61c0ac1
  - xhci: dbc: Improve performance by removing delay in transfer
    event polling (jsc#PED-10906).
  - commit 6fb9745
  - usb: cdns3: Synchronise PCI IDs via common data base
    (jsc#PED-10906).
  - commit d047513
  - usb: xhci: remove irrelevant comment (jsc#PED-10906).
  - commit 3e95364
  - usb: xhci: add help function xhci_dequeue_td() (jsc#PED-10906).
  - commit b370f56
  - s390/pci: Fix handling of isolated VFs (git-fixes bsc#1237252).
  - commit 09fc7a2
  - s390/pci: Pull search for parent PF out of
    zpci_iov_setup_virtfn() (git-fixes bsc#1237251).
  - commit 54c32f5
  - Use gcc-13 for build on SLE16 (jsc#PED-10028).
  - commit 51dacec
  - usb: xhci: Restore xhci_pci support for Renesas HCs (git-fixes).
  - commit c96fec0
  - kbuild: userprogs: fix bitsize and target detection on clang
    (git-fixes).
  - tools: fix annoying "mkdir -p ..." logs when building tools
    in parallel (git-fixes).
  - serial: 8250: Fix fifo underflow on flush (git-fixes).
  - serial: port: Always update ->iotype in __uart_read_properties()
    (git-fixes).
  - serial: port: Assign ->iotype correctly when ->iobase is set
    (git-fixes).
  - usb: roles: set switch registered flag early on (git-fixes).
  - usb: gadget: core: flush gadget workqueue after device removal
    (git-fixes).
  - USB: gadget: f_midi: f_midi_complete to call queue_work
    (git-fixes).
  - usb: core: fix pipe creation for get_bMaxPacketSize0
    (git-fixes).
  - usb: dwc3: Fix timeout issue during controller enter/exit from
    halt state (git-fixes).
  - USB: cdc-acm: Fill in Renesas R-Car D3 USB Download mode quirk
    (git-fixes).
  - usb: cdc-acm: Fix handling of oversized fragments (git-fixes).
  - usb: cdc-acm: Check control transfer buffer size before access
    (git-fixes).
  - usb: gadget: f_midi: fix MIDI Streaming descriptor lengths
    (git-fixes).
  - usb: dwc2: gadget: remove of_node reference upon udc_stop
    (git-fixes).
  - usb: gadget: udc: renesas_usb3: Fix compiler warning
    (git-fixes).
  - usb: gadget: f_midi: Fixing wMaxPacketSize exceeded issue
    during MIDI bind retries (git-fixes).
  - commit 3893a99

++++ kernel-rt:

  - rseq: Fix rseq unregistration regression (bsc#1234634 (Scheduler
    functional and performance backports)).
  - commit d16e10a
  - locking/ww_mutex: Fix ww_mutex dummy lockdep map selftest
    warnings (bsc#1234634 (Scheduler functional and performance
    backports)).
  - commit 7357fd9
  - debugfs: Fix the missing initializations in __debugfs_file_get()
    (jsc#PED-10906).
  - commit a5a225f
  - net: sched: Disallow replacing of child qdisc from one parent
    to another (CVE-2025-21700 bsc#1237159).
  - commit 45e9f84
  - usb: common: expand documentation for USB functions
    (jsc#PED-10906).
  - commit 5dc8ea1
  - USB: make single lock for all usb dynamic id lists
    (jsc#PED-10906).
  - commit ca6a4cf
  - pktgen: Avoid out-of-bounds access in get_imix_entries
    (CVE-2025-21680 bsc#1236700).
  - commit a7a7f74
  - sctp: sysctl: cookie_hmac_alg: avoid using current->nsproxy (CVE-2025-21640 bsc#1236123)
  - commit a4016e3
  - sctp: sysctl: rto_min/max: avoid using current->nsproxy (CVE-2025-21639 bsc#1236122)
  - commit 3a3fa72
  - sctp: sysctl: auth_enable: avoid using current->nsproxy (CVE-2025-21638 bsc#1236115)
  - commit 923596b
  - sctp: sysctl: udp_port: avoid using current->nsproxy (CVE-2025-21637 bsc#1236114)
  - commit 8abdd74
  - sctp: sysctl: plpmtud_probe_interval: avoid using current->nsproxy (CVE-2025-21636 bsc#1236113)
  - commit 19d97ab
  - usb: host: xhci-plat: add support compatible ID PNP0D15
    (jsc#PED-10906).
  - commit e39bb0b
  - USB: host: Use str_enable_disable-like helpers (jsc#PED-10906).
  - commit 2c7456c
  - xhci: don't mess with ->d_iname (jsc#PED-10906).
  - commit 739b405
  - debugfs: allow to store an additional opaque pointer at file
    creation (jsc#PED-10906).
  - commit 2324ce1
  - debugfs: don't mess with bits in ->d_fsdata (jsc#PED-10906).
  - commit ef5509c
  - debugfs: get rid of dynamically allocation proxy_ops
    (jsc#PED-10906).
  - commit 2205145
  - debugfs: move ->automount into debugfs_inode_info
    (jsc#PED-10906).
  - commit 1597940
  - debugfs: separate cache for debugfs inodes (jsc#PED-10906).
  - commit dcce65c
  - fs: debugfs: fix open proxy for unsafe files (jsc#PED-10906).
  - commit 9dffd44
  - debugfs: fix missing mutex_destroy() in short_fops case
    (jsc#PED-10906).
  - commit efab813
  - fs: debugfs: differentiate short fops with proxy ops
    (jsc#PED-10906).
  - commit dae3000
  - debugfs: add small file operations for most files
    (jsc#PED-10906).
  - commit c4f473c
  - xhci: Add missing capability definition bits (jsc#PED-10906).
  - commit 7f85c83
  - xhci: Add command completion parameter support (jsc#PED-10906).
  - commit 946ecb2
  - xhci: dbgtty: Improve performance by handling received data
    immediately (jsc#PED-10906).
  - commit 61c0ac1
  - xhci: dbc: Improve performance by removing delay in transfer
    event polling (jsc#PED-10906).
  - commit 6fb9745
  - usb: cdns3: Synchronise PCI IDs via common data base
    (jsc#PED-10906).
  - commit d047513
  - usb: xhci: remove irrelevant comment (jsc#PED-10906).
  - commit 3e95364
  - usb: xhci: add help function xhci_dequeue_td() (jsc#PED-10906).
  - commit b370f56
  - s390/pci: Fix handling of isolated VFs (git-fixes bsc#1237252).
  - commit 09fc7a2
  - s390/pci: Pull search for parent PF out of
    zpci_iov_setup_virtfn() (git-fixes bsc#1237251).
  - commit 54c32f5
  - Use gcc-13 for build on SLE16 (jsc#PED-10028).
  - commit 51dacec
  - usb: xhci: Restore xhci_pci support for Renesas HCs (git-fixes).
  - commit c96fec0
  - kbuild: userprogs: fix bitsize and target detection on clang
    (git-fixes).
  - tools: fix annoying "mkdir -p ..." logs when building tools
    in parallel (git-fixes).
  - serial: 8250: Fix fifo underflow on flush (git-fixes).
  - serial: port: Always update ->iotype in __uart_read_properties()
    (git-fixes).
  - serial: port: Assign ->iotype correctly when ->iobase is set
    (git-fixes).
  - usb: roles: set switch registered flag early on (git-fixes).
  - usb: gadget: core: flush gadget workqueue after device removal
    (git-fixes).
  - USB: gadget: f_midi: f_midi_complete to call queue_work
    (git-fixes).
  - usb: core: fix pipe creation for get_bMaxPacketSize0
    (git-fixes).
  - usb: dwc3: Fix timeout issue during controller enter/exit from
    halt state (git-fixes).
  - USB: cdc-acm: Fill in Renesas R-Car D3 USB Download mode quirk
    (git-fixes).
  - usb: cdc-acm: Fix handling of oversized fragments (git-fixes).
  - usb: cdc-acm: Check control transfer buffer size before access
    (git-fixes).
  - usb: gadget: f_midi: fix MIDI Streaming descriptor lengths
    (git-fixes).
  - usb: dwc2: gadget: remove of_node reference upon udc_stop
    (git-fixes).
  - usb: gadget: udc: renesas_usb3: Fix compiler warning
    (git-fixes).
  - usb: gadget: f_midi: Fixing wMaxPacketSize exceeded issue
    during MIDI bind retries (git-fixes).
  - commit 3893a99

++++ bluez:

  - Add supplements bluedevil6 for bluez-obexd
    * In Plasma 6 bluedevil5 got renamed to bluedevil6.
    While bluedevil6 provides bluedevil5 on Tumbleweed it's a good
    idea to add it for future proofing.

++++ ncurses:

  - Add ncurses patch 20250216
    + add limit-checks in alloc_entry.c and alloc_ttype.c to avoid indexing
    errors when using infocmp to compare all capabilities when processing
    a malformed terminfo binary which has a valid header (testcase by
    "Ekkosun").
  - Add ncurses patch 20250215
    + add gzip option for suppressing filename/timestamp information to an
    overlooked case (cf: 20240330).
    + correct spelling errors found with codespell.
    + fix some typos in manpages (report by Sven Joachim)
    + amend change to lib_set_term.c to work with thread configuration
    (report by Rajeev Pillai, cf: 20250208).

++++ libtirpc:

  - update to 1.3.6:
    * configure.ac: Using autoupdate updated to the latest autoconf macros
    * svc_fd_create: skip getsockname on a non-network socket
    * detect whether linker supports --version-script
    * check for gss_pname_to_uid or hardcode an early return if we can't use aname to localname
    * test for IPV6_PKTINFO and potentially define __APPLE_USE_RFC_3542 to expose
    * macos uses the same mutex primitives as linux and so can use these defines
    * check for struct rpcent in netdb.h before redefining
    * include string.h when we need a memset prototype for
    * attempt to use machine/endian.h if endian.h does not exist
    * updated macOS support for tirpc [2/7] SOL_IP vs IPPROTO_IP
    * check for getpeereid
    * rpcb_prot.x: Update _PATH_RPCBINDSOCK
    * Move rpcbind.sock to /run
  - update to 1.3.5:
    * Try using a new abstract address when connecting to rpcbind
    * Change local_rpcb() to take a targaddr pointer.
    * Allow working with abstract AF_UNIX addresses.
    * rpcb_clnt.c: memory leak in destroy_addr
    * _rpc_dtablesize: Decrease the value of size.
    * netconfig: remove tcp6, udp6 on --disable-ipv6
    * gssapi: fix rpc_gss_seccreate passed in cred
    * Revert commit f5b6e6fdb1e6 "gss-api: expose gss major/minor
    error in authgss_refresh()".

++++ passt:

  - Update to version 20250217.a1e48a0:
    * test: Add migration tests
    * migrate: Migrate TCP flows
    * repair, passt-repair: Build and warning fixes for musl
    * tcp_splice: A typo three years ago and SO_RCVLOWAT is gone
    * tcp_splice: Don't wake up on input data if we can't write it anywhere
    * vhost_user: Clear ring address on GET_VRING_BASE
    * tcp, tcp_splice: Don't set SO_SNDBUF and SO_RCVBUF to maximum values
    * tcp: Keep updating window and checking for socket data after FIN from guest
    * contrib/selinux: Enable mapping guest memory for libvirt guests
    * selinux: Add rules needed to run tests
    * rampstream: Add utility to test for corruption of data streams
    * tcp: Get bound address for connected inbound sockets too
    * vhost_user: Make source quit after reporting migration state
    * Add interfaces and configuration bits for passt-repair
    * migrate: Migrate guest observed addresses
    * migrate: Skeleton of live migration logic
    * passt-repair: Fix off-by-one in check for number of file descriptors
    * tcp_vu: Fix off-by one in header count array adjustment
    * tcp: Implement conservative zero-window probe on ACK timeout
    * tcp: Don't discard window information on keep-alive segments
    * dhcp, dhcpv6: Add hostname and client fqdn ops
    * conf: Don't map DNS traffic to host, if host gateway is a resolver
    * passt-repair: Send one confirmation *per command*, not *per socket*
    * dhcp: Don't re-use request message for reply
    * passt-repair: Dodge "structurally unreachable code" warning from Coverity
    * passt-repair: Fix calculation of payload length from cmsg_len
    * passt-repair: Don't use perror(), accept ECONNRESET as termination
    * conf, passt.1: Un-deprecate --host-lo-to-ns-lo
    * debug: Add tcpdump to mbuto.img
    * apparmor: Workaround for unconfined libvirtd when triggered by unprivileged user
    * passt-repair.1: Fix indication of TCP_REPAIR constants
    * passt-repair: Build fixes for musl
    * passt-repair: use _exit() over return
    * treewide: use _exit() over exit()
    * tcp: Simplify handling of getsockname()
    * migrate: Fix several errors with passt-repair
    * doc: Add mock of migration source and target
    * tcp: Get socket port and address using getsockname() when connecting from guest
    * Introduce passt-repair
    * vhost_user: Turn some vhost-user message reports to trace()
    * util: Add read_remainder() and read_all_buf()
    * tcp_splice, udp_flow: fcntl64() support on PPC64 depends on glibc version
    * vhost_user: On 32-bit ARM, mmap() is not available, mmap2() is used instead
    * tcp: Don't reset outbound connection on SYN retries
    * pasta.te: fix demo.sh and remove one duplicate rule
    * tcp: Add HOSTSIDE(x), HOSTFLOW(x) macros
    * util: Rename and make global vu_remove_watch()
    * tcp: Always pass NULL event with EPOLL_CTL_DEL
    * vhost-user: Implement an empty VHOST_USER_SEND_RARP command
    * netlink: Skip loopback interface while looking for a template

++++ podman:

  - Add patch for CVE-2024-11218 (bsc#1236270):
    * 0001-vendor-bump-buildah-to-1.37.6-CVE-2024-11218.patch
  - Removed patches (merged upstream):
    * 0001-pkg-subscriptions-use-securejoin-for-the-container-p.patch
    * 0002-CVE-2024-9407-validate-bind-propagation-flag-setting.patch
    * 0003-Properly-validate-cache-IDs-and-sources.patch
    * 0004-Use-securejoin.SecureJoin-when-forming-userns-paths.patch
  - Add missing podman-clean-transient unit
  - Update to version 5.2.5:
    * Bump to v5.2.5 (bsc#1236507)
    * Update release notes for 5.2.5
    * Bump c/storage to v1.55.1 and Buildah to v1.37.5
    * RPM: remove dup Provides
    * Packit: constrain koji and bodhi jobs to fedora package to avoid dupes
    * Bump to v5.2.5-dev
    * Bump to v5.2.4
    * Update release notes for v5.2.4
    * Validate the bind-propagation option to `--mount`
    * Bump Buildah to v1.37.4
    * vendor: update c/common to v0.60.4
    * Bump to v5.2.4-dev
    * Bump to v5.2.3
    * Update release notes for v5.2.3
    * [v5.2] Bump Buildah to v1.37.3
    * pkg/specgen: allow pasta when running inside userns
    * libpod: convert owner IDs only with :idmap
    * docs: update read the docs changes
    * allow exposed sctp ports
    * libpod: setupNetNS() correctly mount netns
    * vendor: update c/common to v0.60.3
    * [skip-ci] Packit: split out ELN jobs and reuse fedora downstream targets
    * [skip-ci] Packit: Enable sidetags for bodhi updates
    * build: Update gvisor-tap-vsock to 0.7.5
    * CI: podman-machine: do not use cache registry
    * [CI:DOCS] Add v5.2.2 lib updates to RELEASE_NOTES.md
    * Bump to v5.2.3-dev
    * Bump to v5.2.2
    * Update RELEASE_NOTES for v5.2.2
    * [v5.2] Bump Buildah to v1.37.2, c/common v0.60.2, c/image v5.32.2
    * [v5.2] golangci-lint: make darwin linting happy
    * [v5.2] golangci-lint: make windows linting happy
    * [v5.2] test/e2e: remove kernel version check
    * [v5.2] golangci-lint: remove most skip dirs
    * [v5.2] set !remote build tags where needed
    * [v5.2] update golangci-lint to 1.60.1
    * Packit: update targets for propose-downstream
    * Create volume path before state initialization
    * Update Cirrus DEST_BRANCH
    * Bump to v5.2.2-dev
    * Bump to v5.2.1
    * Update release notes for v5.2.1
    * [v5.2] Add zstd:chunked test fix
    * [v5.2] Bump Buildah to v1.37.1, c/common v0.60.1, c/image v5.32.1
    * libpod: reset state error on init
    * libpod: do not save expected stop errors in ctr state
    * libpod: fix broken saveContainerError()
    * Bump to v5.2.1-dev
    * Bump to v5.2.0
    * Never skip checkout step in release workflow
    * Bump to v5.2.0-dev
    * Bump to v5.2.0-rc3
    * Update release notes for v5.2.0-rc3
    * Tweak versions in register_images.go
    * fix network cleanup flake in play kube
    * WIP: Fixes for vendoring Buildah
    * Add --compat-volumes option to build and farm build
    * Bump Buildah, c/storage, c/image, c/common
    * libpod: bind ports before network setup
    * pkg/api: do not leak config pointers into specgen
    * build: Update gvisor-tap-vsock to 0.7.4
    * test/system: fix borken pasta interface name checks
    * test/system: fix bridge host.containers.internal test
    * CI: system tests: instrument to allow failure analysis
    * Use uploaded .zip for Windows action
    * RPM: podman-iptables.conf only on Fedora
    * Bump to v5.2.0-dev
    * Bump to v5.2.0-rc2
    * Update release notes for v5.2.0-rc2
    * test/e2e: fix ncat tests
    * libpod: add hidden env to set sqlite timeout
    * Add support for StopSignal in quadlet .container files
    * podman pod stats: fix race when ctr process exits
    * Update module github.com/vbauerster/mpb/v8 to v8.7.4
    * libpod: correctly capture healthcheck output
    * Bump bundled krunkit to 0.1.2
    * podman stats: fix race when ctr process exists
    * nc -p considered harmful
    * podman pod stats: fix pod rm race
    * podman ps: fix racy pod name query
    * system connection remove: use Args function to validate
    * pkg/machine/compression: skip decompress bar for empty file
    * nc -p considered harmful
    * podman system df: fix fix ErrNoSuchCtr/Volume race
    * podman auto-update: fix ErrNoSuchCtr race
    * Fix name for builder in farm connection
    * 700-play.bats: use unique pod/container/image/volume names
    * safename: consistent within same test, and, dashes
    * 700-kube.bats: refactor $PODMAN_TMPDIR/test.yaml
    * 700-play.bats: eliminate $testYaml
    * 700-play.bats: refactor clumsy yamlfile creation
    * 700-play.bats: move _write_test_yaml up near top
    * chore(deps): update dependency setuptools to v71
    * Expand drop-in search paths * top-level (pod.d) * truncated (unit-.container.d)
    * Remove references and checks for --gpus
    * Do not crash on invalid filters
    * fix(deps): update module github.com/rootless-containers/rootlesskit/v2 to v2.2.0
    * Bump to v5.2.0-dev
    * Bump to v5.2.0-rc1
    * Keep the volume-driver flag deprecated
    * Vendor in latest containers(common, storage,image, buildah)
    * System tests: safe container/image/volume/etc names
    * Implement disable default mounts via command line
    * test: drop unmount for overlay
    * test: gracefully terminate server
    * libpod: shutdown Stop waits for handlers completion
    * libpod: cleanup store at shutdown
    * Add NetworkAlias= support to quadlet
    * cmd: call shutdown handler stop function
    * fix race conditions in start/attach logic
    * swagger: exlude new docker network types
    * vendor: bump c/storage
    * update to docker 27
    * contrib: use a distinct --pull-option= for each flag
    * Update warning message when using external compose provider
    * Update module github.com/cyphar/filepath-securejoin to v0.3.0
    * Ignore result of EvalSymlinks on ENOENT
    * test/upgrade: fix tests when netavark uses nftables
    * test/system: fix network reload test with nftables
    * test/e2e: rework some --expose tests
    * test: remove publish tests from e2e
    * CI: test nftables driver on fedora
    * CI: use local registry, part 3 of 3: for developers
    * CI: use local registry, part 2 of 3: fix tests
    * CI: use local registry, part 1 of 3: setup
    * CI: test composefs on rawhide
    * chore(deps): update module google.golang.org/grpc to v1.64.1 [security]
    * chore(deps): update dependency setuptools to ~=70.3.0
    * Improve container filenname ambiguity.
    * containers/attach: Note bug around goroutine leak
    * Drop minikube CI test
    * add libkrun test docs
    * fix(deps): update module tags.cncf.io/container-device-interface to v0.8.0
    * cirrus: check for header files in source code check
    * pkg/machine/e2e: run debug command only for macos
    * create runtime's worker queue before queuing any job
    * test/system: fix pasta host.containers.internal test
    * Visual Studio BuildTools as a MinGW alternative
    * SetupRootless(): only reexec when needed
    * pkg/rootless: simplify reexec for container code
    * cirrus: add missing test/tools to danger files
    * fix(deps): update module golang.org/x/tools to v0.23.0
    * Windows Installer: switch to wix5
    * fix(deps): update module golang.org/x/net to v0.27.0
    * pkg/machine/e2e: print tests timings at the end
    * pkg/machine/e2e: run debug commands after init
    * pkg/machine/e2e: improve timeout handling
    * libpod: first delete container then cidfile
    * fix(deps): update module golang.org/x/term to v0.22.0
    * System test fixes
    * cirrus.yml: automatic skips based on source
    * fix(deps): update module github.com/containers/ocicrypt to v1.2.0
    * podman events: fix error race
    * chore(deps): update dependency setuptools to ~=70.2.0
    * fix(deps): update module github.com/gorilla/schema to v1.4.1 [security]
    * Update CI VM images
    * pkg/machine/e2e: fix broken cleanup
    * pkg/machine/e2e: use tmp file for connections
    * test/system: fix podman --image-volume to allow tmpfs storage
    * CI: mount tmpfs for container storage
    * docs: --network remove missing leading sentence
    * specgen: parse devices even with privileged set
    * vendor: update c/storage
    * Remove the unused machine volume-driver
    * feat(quadlet): log option handling
    * Error when machine memory exceeds system memory
    * machine: Always use --log-file with gvproxy
    * CI: Build-Each-Commit test: run only on PRs
    * Small fixes for testing libkrun
    * Podman machine resets all providers
    * Clearly indicate names w/ URLencoded duplicates
    * [skip-ci] Packit: split rhel and centos-stream jobs
    * apple virtiofs: fix racy mount setup
    * cirrus: fix broken macos artifacts URL
    * libpod/container_top_linux.c: fix missing header
    * refactor(build): improve err when file specified by -f does not exist
    * Minor: Remove unhelpful comment
    * Update module github.com/openshift/imagebuilder to v1.2.11
    * Minor: Rename the OSX Cross task
    * [skip-ci] Remove conditionals from changelog
    * podman top: join the container userns
    * Run linting in parallel with building
    * Fix missing Makefile target dependency
    * build API: accept platform comma separated
    * [skip-ci] RPM: create podman-machine subpackage
    * ExitWithError() - more upgrades from Exit()
    * test/e2e: remove podman system service tests
    * cirrus: reduce int tests timeout
    * cirrus: remove redundant skip logic
    * pkg/machine/apple: machine stop timeout
    * CI: logformatter: link to correct PR base
    * Update module github.com/crc-org/crc/v2 to v2.38.0
    * ExitWithError(): continued
    * test/system: Add test steps for journald log check in quadlet
    * restore: fix missing network setup
    * podman run use pod userns even with --pod-id-file
    * macos-installer: bundle krunkit
    * remote API: fix pod top error reporting
    * libpod API: return proper error status code for pod start
    * fix #22233
    * added check for `registry.IsRemote()`. and correct error message.
    * fix #20686
    * pkg/machine/e2e: Remove unnecessary copy of machine image.
    * libpod: intermediate mount if UID not mapped into the userns
    * libpod: avoid chowning the rundir to root in the userns
    * libpod: do not chmod bind mounts
    * libpod: unlock the thread if possible
    * CI Cleanup: Remove cgroups v1 support
    * ExitWithError() - more upgrades from Exit()
    * remote: fix incorrect CONTAINER_CONNECTION parsing
    * container: pass KillSignal and StopTimeout to the systemd scope
    * libpod: fix comment
    * e2e: test container restore in pod by name
    * docs: Adds all PushImage supported paramters to openapi docs.
    * systests: kube: bump up a timeout
    * cirrus.yml: add CI:ALL mode to force all tests
    * cirrus.yml: implement skips based on source changes
    * CI VMs: bump
    * restore: fix container restore into pod
    * sqlite_state: Fix RewriteVolumeConfig
    * chore(deps): update dependency setuptools to ~=70.1.0
    * Quadlet - use specifier for unescaped values for templated container name
    * cirrus: check for system test leaks in nightly
    * test/system: check for leaks in teardown suite
    * test/system: speed up basic_{setup,teardown}()
    * test/system: fix up many tests that do not cleanup
    * test/system: fix podman --authfile=nonexistent-path
    * Update module github.com/containernetworking/plugins to v1.5.1
    * Update module github.com/checkpoint-restore/checkpointctl to v1.2.1
    * Update module github.com/spf13/cobra to v1.8.1
    * Update module github.com/gorilla/schema to v1.4.0
    * pkg/machine/wsl: force terminate wsl instance
    * pkg/machine/wsl: wrap command errors
    * [CI:DOCS] Quadlet - add note about relative path resolution
    * CI: do not install python packages at runtime
    * Release workflow: Include candidate descriptor
    * Minor: Fix indentation in GHA release workflow
    * GHA: Send release notification mail
    * GHA: Validate release version number
    * Remove references to --pull=true and --pull=false
    * ExitWithError, continued
    * podman: add new hidden flag --pull-option
    * [CI:DOCS] Fix typos in podman-build
    * infra: mark storageSet when imagestore is changed
    * [CI:DOCS] Add jnovy as reviewer and approver
    * fix(deps): update module google.golang.org/protobuf to v1.34.2
    * refactor(machine,wsl): improve operations of Windows API
    * --squash --layers=false should be allowed
    * fix(deps): update module github.com/checkpoint-restore/checkpointctl to v1.2.0
    * update golangci-lint to v1.59.1
    * Rename master to main in CONTRIBUTING.md
    * podman 5, pasta and inter-container networking
    * libpod: do not resuse networking on start
    * machine/linux: Switch to virtiofs by default
    * machine/linux: Support virtiofs mounts (retain 9p default)
    * machine/linux: Use memory-backend-memfd by default
    * ExitWithError() - continued
    * Enable libkrun provider to open a debug console
    * Add new targets on Windows makefile (winmake.ps1)
    * fix(deps): update module github.com/docker/docker to v26.1.4+incompatible
    * fix(deps): update module github.com/crc-org/crc/v2 to v2.37.1
    * fix(deps): update module golang.org/x/tools to v0.22.0
    * fix(deps): update module golang.org/x/net to v0.26.0
    * libpod: fix 'podman kube generate' on FreeBSD
    * fix(deps): update module golang.org/x/sys to v0.21.0
    * libpod: do not leak systemd hc startup unit timer
    * vendor latest c/common
    * pkg/rootless: set _CONTAINERS_USERNS_CONFIGURED correctly
    * run bats -T, to profile timing hogs
    * test/system: speed up podman ps --external
    * test/system: speed up podman network connect/disconnect
    * test/system: speed up podman network reload
    * test/system: speed up quadlet - pod simple
    * test/system: speed up podman parallel build should not race
    * test/system: speed up podman cp dir from host to container
    * test/system: speed up podman build - workdir, cmd, env, label
    * test/system: speed up podman --log-level recognizes log levels
    * test/system: remove obsolete debug in net connect/disconnect test
    * test/system: speed up quadlet - basic
    * test/system: speed up user namespace preserved root ownership
    * System tests: add `podman system check` tests
    * Add `podman system check` for checking storage consistency
    * fix(deps): update module github.com/crc-org/crc/v2 to v2.37.0
    * fix(libpod): add newline character to the end of container's hostname file
    * fix(deps): update module github.com/openshift/imagebuilder to v1.2.10
    * fix(deps): update github.com/containers/image/v5 digest to aa93504
    * Fix 5.1 release note re: runlabel
    * test/e2e: use local skopeo not image
    * fix(deps): update golang.org/x/exp digest to fd00a4e
    * [CI:DOCS] Add contrib/podmanimage/stable path back in repo
    * chore(deps): update dependency requests to ~=2.32.3
    * fix(deps): update github.com/containers/image/v5 digest to 2343e81
    * libpod: do not move podman with --cgroups=disabled
    * Update release notes on Main to v5.1.0
    * test: look at the file base name
    * tests: simplify expected output
    * Sigh, new VMs again
    * Fail earlier when no containers exist in stats
    * Add Hyper-V option in windows installer
    * libpod: cleanup default cache on system reset
    * vendor: update c/image
    * test/system: speed up kube generate tmpfs on /tmp
    * test/system: speed up podman kube play tests
    * test/system: speed up podman shell completion test
    * test/system: simplify test signal handling in containers
    * test/system: speed up podman container rm ...
    * test/system: speed up podman ps - basic tests
    * test/system: speed up read-only from containers.conf
    * test/system: speed up podman logs - multi ...
    * test/system: speed up podman run --name
    * Debian: switch to crun
    * test/system: speed up podman generate systemd - envar
    * test/system: speed up podman-kube@.service template
    * test/system: speed up kube play healthcheck initialDelaySeconds
    * test/system: speed up exit-code propagation test
    * test/system: speed up "podman run --timeout"
    * test/system: fix slow kube play --wait with siginterrupt
    * undo auto-formatting
    * test/system: speed up podman events tests
    * Quadlet: Add support for .build files
    * test/system: speed up "podman auto-update using systemd"
    * test/system: remove podman wait test
    * tests: disable tests affected by a race condition
    * update golangci-lint to v1.59.0
    * kubernetes_support.md: Mark volumeMounts.subPath as supported
    * working name of pod on start and stop
    * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.19.0
    * Bump Buildah to v1.36.0
    * fix(deps): update module github.com/burntsushi/toml to v1.4.0
    * fix typo in Tutorials.rst
    * Mac PM test: Require pre-installed rosetta
    * test/e2e: fix new error message
    * Add configuration for podmansh
    * Update containers/common to latest main
    * Only stop chowning volumes once they're not empty
    * podman: fix --sdnotify=healthy with --rm
    * libpod: wait another interval for healthcheck
    * quadlet: Add a network requirement on .image units
    * test, pasta: Ignore deprecated addresses in tests
    * [CI:DOCS] performance: update network docs
    * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.18.0
    * CI: disable minikube task
    * [CI:DOCS] Fix windows action trigger
    * chore(deps): update dependency setuptools to v70
    * Check AppleHypervisor before accessing it
    * fix(deps): update module github.com/containernetworking/plugins to v1.5.0
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.58.2
    * add podman-clean-transient.service service to rootless
    * [CI:DOCS] Update podman network docs
    * fix incorrect host.containers.internal entry for rootless bridge mode
    * vendor latest c/common main
    * Add Rosetta support for Apple Silicon mac
    * bump main to 5.2.0-dev
    * Use a defined constant instead of a hard-coded magic value
    * cirrus: use faster VM's for integration tests
    * fix(deps): update github.com/containers/gvisor-tap-vsock digest to 01a1a0c
    * [CI:DOCS] Fix Mac pkg link
    * test: remove test_podman* scripts
    * test/system: fix documentation
    * Return StatusNotFound when multiple volumes matching occurs
    * container_api: do not wait for healtchecks if stopped
    * libpod: wait for healthy on main thread
    * `podman events`: check for an error after we finish reading events
    * remote API: restore v4 payload in container inspect
    * Fix updating connection when SSH port conflict happens
    * rootless: fix reexec to use /proc/self/exe
    * ExitWithError() - enforce required exit status & stderr
    * ExitWithError() - a few that I missed
    * [skip-ci] Packit: use only one value for `packages` key for `trigger: commit` copr builds
    * Revert "Temporarily disable rootless debian e2e testing"
    * CI tests: enforce TMPDIR on tmpfs
    * use new CI images with tmpfs /tmp
    * run e2e test on tmpfs
    * Update module github.com/crc-org/crc/v2 to v2.36.0
    * Address CVE-2024-3727
    * [CI:DOCS] Use checkout@v4 in GH Actions
    * ExitWithError() - rmi_test
    * ExitWithError() - more r files
    * ExitWithError() - s files
    * ExitWithError() - more run_xxx tests
    * Fix podman-remote support for `podman farm build`
    * [CI:DOCS] Trigger windows installer action properly
    * Revert "container stop: kill conmon"
    * Ensure that containers do not get stuck in stopping
    * [CI:DOCS] Improvements to make validatepr
    * ExitWithError() - rest of the p files
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.58.1
    * Graceful shutdown during podman kube down
    * Remove duplicate  call
    * test/system: fix broken "podman volume globs" test
    * Quadlet/Container: Add GroupAdd option
    * Don't panic if a runtime was configured without paths
    * update c/{buildah,common,image,storage} to latest main
    * update golangci-lint to 1.58
    * machine: Add LibKrun provider detection
    * ExitWithError() - continue tightening
    * fix(deps): update module google.golang.org/protobuf to v1.34.1
    * test: improve test for powercap presence
    * fix(deps): update module github.com/onsi/ginkgo/v2 to v2.17.3
    * fix(deps): update module go.etcd.io/bbolt to v1.3.10
    * fix(deps): update module golang.org/x/tools to v0.21.0
    * [skip-ci] RPM: `bats` required only on Fedora
    * fix(deps): update module golang.org/x/exp to v0.0.0-20240506185415-9bf2ced13842
    * gpdate and remove parameter settings in `.golangci.yml`
    * ExitWithError() - play_kube_test.go
    * Temporarily disable rootless debian e2e testing
    * fix(deps): update module golang.org/x/crypto to v0.23.0
    * CI Docs: Clarify passthrough_envars() comments
    * Skip machine tests if they don't need to be run
    * Update CI VMs to F40, F39, D13
    * ExitWithError() - v files
    * Update module golang.org/x/term to v0.20.0
    * machine: Add provider detection API
    * util: specify a not empty pause dir for root too
    * Add missing option 'healthy' to output of `podman run --help`
    * [CI:DOCS] Add info on the quay.io images to the README.md
    * Add a random suffix to healthcheck unit names
    * test/e2e: remove toolbox image
    * Also substitute $HOME in runlabel with user's homedir
    * Update module github.com/cyphar/filepath-securejoin to v0.2.5
    * Change tmpDir for macOS
    * ExitWithError() - pod_xxx tests
    * ExitWithError() -- run_test.go
    * Update module golang.org/x/exp to v0.0.0-20240416160154-fe59bbe5cc7f
    * Update module github.com/shirou/gopsutil/v3 to v3.24.4
    * Update module github.com/docker/docker to v26.1.1+incompatible
    * GHA: Attempt fix exceeded a secondary rate limit
    * vendor ginkgo 2.17.2 into test/tools
    * Fix machine volumes with long path and paths with dashes
    * Update module google.golang.org/protobuf to v1.34.0
    * Update module github.com/crc-org/crc/v2 to v2.35.0
    * Update module github.com/onsi/gomega to v1.33.1
    * test/e2e: podman unshare image mount fix tmpdir leak
    * test/e2e: do not leak /tmp/private_file
    * test/e2e: "persistentVolumeClaim with source" do not leak file
    * e2e tests: use /var/tmp, not $TMPDIR, as workdirs
    * Update dependency pytest to v8.1.2
    * Remove unncessary lines at the end of specfile summary
    * Clean machine pull cache
    * Add krun support to podman machine
    * Use custom image for make validatepr
    * test/e2e: force systemd cgroup manager
    * e2e and bindings tests: fix $PATH setup
    * Makefile: remove useless HACK variable in e2e test
    * test/e2e: fix volumes and suid/dev/exec options
    * test/e2e: volumes and suid/dev/exec options works remote
    * test/e2e: fix limits test
    * Update module github.com/rootless-containers/rootlesskit/v2 to v2.1.0
    * Correct option name `ip` -> `ip6`
    * Add the ability to automount images as volumes via play
    * Add support for image volume subpaths
    * Bump Buildah to latest main
    * Update Makefile to Go 1.22 for in-container
    * ExitWithError() - yet more low-hanging fruit
    * ExitWithError() - more low-hanging fruit
    * ExitWithError() - low-hanging fruit
    * chore: fix function names in comment
    * Remove redundant Prerequisite before build section
    * Remove PKG_CONFIG_PATH
    * Add installation instructions for openSUSE
    * Replace golang.org/x/exp/slices with slices from std
    * Update to go 1.21
    * fix(deps): update module github.com/docker/docker to v26.1.0+incompatible
    * [CI:DOCS] Fix artifact action
    * [skip-ci] Packit/rpm: remove el8 jobs and spec conditionals
    * e2e tests: stop littering
    * [CI:DOCS] format podman-pull example as code
    * [CI:DOCS] Build & upload release artifacts with GitHub Actions
    * libpod: getHealthCheckLog() remove unessesary check
    * add containers.conf healthcheck_events support
    * vendor latest c/common
    * libpod: make healthcheck events more efficient
    * libpod: wrap store setup error message
    * [skip-ci] Packit: enable CentOS 10 Stream build jobs
    * pkg/systemd: use fileutils.(Le|E)xists
    * pkg/bindings: use fileutils.(Le|E)xists
    * pkg/util: use fileutils.(Le|E)xists
    * pkg/trust: use fileutils.(Le|E)xists
    * pkg/specgen: use fileutils.(Le|E)xists
    * pkg/rootless: use fileutils.(Le|E)xists
    * pkg/machine: use fileutils.(Le|E)xists
    * pkg/domain: use fileutils.(Le|E)xists
    * pkg/api: use fileutils.(Le|E)xists
    * libpod: use fileutils.(Le|E)xists
    * cmd: use fileutils.(Le|E)xists
    * vendor: update containers/{buildah,common,image,storage}
    * fix(deps): update module github.com/docker/docker to v26.0.2+incompatible [security]
    * fix podman-pod-restart.1.md typo
    * [skip-ci] Packit: switch to EPEL instead of centos-stream+epel-next
    * fix(deps): update module github.com/onsi/gomega to v1.33.0
    * Add more annnotation information to podman kupe play man page
    * test/compose: remove compose v1 code
    * CI: remove compose v1 tests
    * fix: close resource file
    * [CI:DOCS] Fix windows installer action
    * fix(deps): update module tags.cncf.io/container-device-interface to v0.7.2
    * add `list` as an alias to list networks
    * Add support for updating restart policy
    * Add Compat API for Update
    * Make `podman update` changes persistent
    * Emergency fix (well, skip) for failing bud tests
    * fix swagger doc for manifest create
    * [CI:DOCS] options/network: fix markdown lists
    * Makefile: do not hardcode `GOOS` in `podman-remote-static` target
    * chore(deps): update module golang.org/x/crypto to v0.17.0 [security]
    * chore(deps): update dependency setuptools to ~=69.5.0
    * Fix some comments
    * swagger fix infinitive recursion on some types
    * install swagger from source
    * Revert "Swap out javascript engine"
    * podman exec CID without command should exit 125
    * (minor) prefetch systemd image before use
    * Update go-swagger version
    * Swap out javascript engine
    * fix(deps): update module github.com/docker/docker to v26.0.1+incompatible
    * Add os, arch, and ismanifest to libpod image list
    * [CI:DOCS]Initial PR validation
    * fix(deps): update github.com/containers/gvisor-tap-vsock digest to d744d71
    * vendor ginkgo 2.17.1 into test/tools
    * fix "concurrent map writes" in network ls compat endpoint
    * chore(deps): update dependency pytest to v8
    * e2e: redefine ExitWithError() to require exit code
    * docs: fix missleading run/create --expose description
    * podman ps: show exposed ports under PORTS as well
    * rootless: drop function ReadMappingsProc
    * fix(deps): update module github.com/vbauerster/mpb/v8 to v8.7.3
    * New CI VMs, to give us pasta 2024-04-05
    * Add big warning to GHA workflow
    * GHA: Fix intermittent workflow error
    * fix(deps): update module golang.org/x/tools to v0.20.0
    * e2e tests: remove requirement for fuse-overlayfs
    * docs: update Quadlet volume Options desc
    * fix(deps): update module golang.org/x/sync to v0.7.0
    * Fix relabeling failures with Z/z volumes on Mac
    * fix(deps): update module golang.org/x/net to v0.24.0
    * Makefile: fix annoying errors in docs generation
    * chore: fix function names in comment
    * Bump tags.cncf.io/container-device-interface to v0.7.1
    * fix(deps): update module golang.org/x/crypto to v0.22.0
    * Detect unhandled reboots and require user intervention
    * podman --runroot: remove 50 char length restriction
    * update github.com/rootless-containers/rootlesskit to v2
    * Update module github.com/gorilla/schema to v1.3.0
    * Update dependency requests-mock to ~=1.12.1
    * Update module github.com/crc-org/crc/v2 to v2.34.1
    * rm --force work for more than one arg
    * [CI:DOCS] Update kube docs
    * fix(deps): update module github.com/shirou/gopsutil/v3 to v3.24.3
    * [CI:DOCS] Add GitHub action to update version on Podman.io
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.2
    * Windows: clean up temporary perl install
    * pkg/util: FindDeviceNodes() ignore ENOENT errors
    * [CI:DOCS] build deps: make-validate needs docs
    * test/system: add rootless-netns test for setup errors
    * vendor latest c/common main
    * container: do not chown to dest target with U
    * [CI:DOCS] golangci-lint: update deprecated flags
    * systests: conditionalize slirp4netns tests
    * CI: systests: instrument flaky tests
    * s3fs docs
    * test: do not skip tests under rootless
    * Add note about host networking to Kube PublishPort option
    * Inject additional build tags from the environment
    * libpod: use original IDs if idmap is provided
    * Switch back to checking out the same branch the action script runs in
    * docs/podman-login: Give an example of writing the persistent path
    * CI: Bump VMs to 2024-03-28
    * [skip-ci] Update dawidd6/action-send-mail action to v3.12.0
    * fix(deps): update module github.com/openshift/imagebuilder to v1.2.7
    * Fix reference to deprecated types.Info
    * Use logformatter for podman_machine_windows_task
    * applehv: Print vfkit logs in --log-level debug
    * [CI:DOCS]Add Mario to reviewers list
    * [CI:DOCS] Document CI-maintenance job addition
    * Add golang 1.21 update warning
    * Add rootless network command to `podman info`
    * libpod: don't warn about cgroupsv1 on FreeBSD
    * hyperv: error if not admin
    * Properly parse stderr when updating container status
    * [skip-ci] Packit: specify fedora-latest in propose-downstream
    * Use built-in ssh impl for all non-pty operations
    * Add support for annotations
    * hyperv: fix machine rm -r
    * [skip-ci] Packit: Enable CentOS Stream 10 update job
    * 5.0 release note fix typo in cgroupv1 env var
    * fix remote build isolation on client side
    * chore: remove repetitive words
    * Dont save remote context in temp file but stream and extract
    * fix remote build isolation when server runs as root
    * util: use private propagation with bind
    * util: add some tests for ProcessOptions
    * util: refactor ProcessOptions into an internal function
    * util: rename files to snake case
    * Add LoongArch support for libpod
    * fix(deps): update github.com/containers/common digest to bc5f97c
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.1
    * fix(deps): update module github.com/docker/docker to v25.0.5+incompatible [security]
    * fix(deps): update module github.com/onsi/gomega to v1.32.0
    * [CI:DOCS] Update dependency golangci/golangci-lint to v1.57.0
    * Update module github.com/cpuguy83/go-md2man/v2 to v2.0.4
    * Fix type-o
    * Use correct extension in suite
    * minikube: instrument tests, to allow debugging failures
    * libpod: restart always reconfigure the netns
    * use new c/common pasta2 setup logic to fix dns
    * utils: drop conversion float->string->float
    * utils: do not generate duplicate range
    * logformatter: handle Windows logs
    * utils: add test for the new function
    * utils: move rootless code to a new function
    * CVE-2024-1753 fix for main
    * xref-helpmsgs-manpages: cross-check Commands.rst
    * test/system: Add support for multipath routes in pasta networking tests
    * [skip-ci] rpm: use macro supported vendoring
    * Adjust to the standard location of gvforwarder used in new images
    * Makefile: add target `podman-remote-static`
    * Switch to 5.x WSL machine os stream using new automation
    * Cleanup build scratch dir if remote end disconnects while passing the context
    * bump main to 5.1.0-dev
    * Use faster gzip for compression for 3x speedup for sending large contexts to remote
    * pkg/machine: make checkExclusiveActiveVM race free
    * pkg/machine/wsl: remove unused CheckExclusiveActiveVM()
    * pkg/machine: CheckExclusiveActiveVM should also check for starting
    * pkg/machine: refresh config after we hold lock
    * Update dependency setuptools to ~=69.2.0
    * [skip-ci] rpm: update containers-common dep on f40+
    * fix invalid HTTP header values when hijacking a connection
    * Add doc to build podman on windows without MSYS
    * Removing CRI-O related annotations
    * fix(deps): update module github.com/containers/ocicrypt to v1.1.10
    * Pass the restart policy to the individual containers
    * kube play: always pull when both imagePullPolicy and tag are missing

++++ python-M2Crypto:

  - Update to 0.44.0:
  - fix(rsa): introduce internal cache for rsa.check_key()
    (bsc#1236664, srht#mcepl/m2crypto#369)
  - fix[authcookie]: modernize the module
  - fix(_lib): add missing #include for windows
  - ci: relax fedora crypto policy to legacy.
  - enhance setup.py for macos compatibility
  - prefer packaging.version over distutils.version
  - fix segfault with openssl 3.4.0
  - fix[ec]: raise ioerror instead when load_key_bio() cannot read
    the file.
  - doc: update installation instructions for windows.
  - fix setting x509.verify_* variables
  - fix building against openssl in non-standard location
  - test_x509: use only x509_version_1 (0) as version for csr.

++++ zypp-plugin:

  - Build package for multiple Python flavors on the SLE15 family
    (fixes #4)

++++ rpcbind:

  - Require system-user-nobody for as the rpc user relies on `nobody`
    from this package
  - Update to rpcbind 1.2.7
    * rpcinfo: try connecting using abstract address
    * Listen on an AF_UNIX abstract address if supported
    * autotools/systemd: call rpcbind with -w only on enabled warm starts
    * rpcbind: fix double free in init_transport
  - Refresh and rename patches (while turning them into git patches)
    * 0001-systemd-unit-files.patch -> 0001-systemd-rpcbind.service-Fix-ordering-add-etc-sysconf.patch
    * harden_rpcbind.service.patch -> 0001-systemd-rpcbind.service-Add-hardening-bsc-1181400.patch

++++ velociraptor-client:

  - Use the latest llvm/clang on tumbleweed

++++ xfsprogs:

  - update to 6.13.0
  - xfs_protofile: fix device number encoding
  - xfs_protofile: fix mode formatting error
  - mkfs: fix file size setting when interpreting a protofile
  - xfs_repair: require zeroed quota/rt inodes in metadir superblocks
  - mkfs: use a default sector size that is also suitable for the rtdev
  - xfs_scrub_all.timer: don't run if /var/lib/xfsprogs is readonly
  - xfs_logprint: Fix super block buffer interpretation issue
  - mkfs: allow sizing realtime allocation groups for concurrency
  - build: initialize stack variables to zero by default
  - m4: fix statx override selection if /usr/include doesn't define it
  - mkfs: fix parsing of value-less -d/-l concurrency cli option
  - xfs_db: improve error message when unknown btree type given to btheight
  - xfs_repair: don't obliterate return codes
  - xfs_db: fix multiple dblock commands
  - xfs: don't return an error from xfs_update_last_rtgroup_size for !XFS_RT
  - xfs_io: add extsize command support
  - xfs_io: allow foreign FSes to show FS_IOC_FSGETXATTR details
  - mkfs: enable rt quota options
  - xfs_quota: report warning limits for realtime space quotas
  - mkfs: add quota flags when setting up filesystem
  - xfs_repair: try not to trash qflags on metadir filesystems
  - xfs_repair: support quota inodes in the metadata directory
  - xfs_db: support metadir quotas
  - libfrog: scrub quota file metapaths
  - mkfs: format realtime groups
  - mkfs: add headers to realtime bitmap blocks
  - xfs_scrub: use histograms to speed up phase 8 on the realtime volume
  - xfs_scrub: trim realtime volumes too
  - xfs_scrub: call GETFSMAP for each rt group in parallel
  - xfs_scrub: cleanup fsmap keys initialization
  - xfs_scrub: check rtgroup metadata directory connections
  - xfs_scrub: scrub realtime allocation group metadata
  - xfs_spaceman: report on realtime group health
  - xfs_mdrestore: restore rt group superblocks to realtime device
  - xfs_io: display rt group in verbose fsmap output
  - xfs_io: display rt group in verbose bmap output
  - xfs_io: add a command to display realtime group information
  - xfs_io: add a command to display allocation group information
  - xfs_io: support scrubbing rtgroup metadata paths
  - xfs_io: support scrubbing rtgroup metadata
  - xfs_db: report rt group and block number in the bmap command
  - xfs_db: dump rt summary blocks
  - xfs_db: dump rt bitmap blocks
  - xfs_db: metadump realtime devices
  - xfs_db: metadump metadir rt bitmap and summary files
  - xfs_db: enable conversion of rt space units
  - xfs_db: support changing the label and uuid of rt superblocks
  - xfs_db: support dumping realtime group data and superblocks
  - xfs_db: listify the definition of enum typnm
  - xfs_db: enable rtconvert to handle segmented rtblocks
  - xfs_db: enable the rtblock and rtextent commands for segmented rt block numbers
  - xfs_repair: repair rtbitmap and rtsummary block headers
  - xfs_repair: support realtime superblocks
  - xfs_repair: find and clobber rtgroup bitmap and summary files
  - xfs_repair: support realtime groups
  - xfs_repair: add a real per-AG bitmap abstraction
  - xfs_repair: simplify rt_lock handling
  - xfs_repair: improve rtbitmap discrepancy reporting
  - xfs_repair: refactor offsetof+sizeof to offsetofend
  - xfs_repair: refactor phase4
  - xfs_repair: adjust rtbitmap/rtsummary word updates to handle big endian values
  - xfs_logprint: report realtime EFIs
  - libfrog: add bitmap_clear
  - libfrog: report rt groups in output
  - libfrog: support scrubbing rtgroup metadata paths
  - man: document rgextents geom field
  - man: document the rt group geometry ioctl
  - mkfs: add a utility to generate protofiles
  - mkfs: support copying in xattrs
  - mkfs: support copying in large or sparse files
  - mkfs.xfs: enable metadata directories
  - xfs_repair: do not count metadata directory files when doing quotacheck
  - xfs_repair: truncate and unmark orphaned metadata inodes
  - xfs_repair: drop all the metadata directory files during pass 4
  - xfs_repair: metadata dirs are never plausible root dirs
  - xfs_repair: mark space used by metadata files
  - xfs_repair: update incore metadata state whenever we create new files
  - xfs_repair: don't let metadata and regular files mix
  - xfs_repair: rebuild the metadata directory
  - xfs_repair: check metadata inode flag
  - xfs_repair: dont check metadata directory dirent inumbers
  - xfs_repair: handle sb_metadirino correctly when zeroing supers
  - xfs_scrub: re-run metafile scrubbers during phase 5
  - xfs_scrub: scan metadata directories during phase 3
  - xfs_scrub: tread zero-length read verify as an IO error
  - xfs_spaceman: report health of metadir inodes too
  - xfs_io: support scrubbing metadata directory paths
  - xfs_io: support flag for limited bulkstat of the metadata directory
  - xfs_db: drop the metadata checking code from blockget
  - xfs_db: display di_metatype
  - xfs_db: show the metadata root directory when dumping superblocks
  - xfs_db: support metadata directories in the path command
  - xfs_db: don't obfuscate metadata directories and attributes
  - xfs_db: report metadir support for version command
  - xfs_db: disable xfs_check when metadir is enabled
  - xfs_io: support scrubbing metadata directory paths
  - libfrog: report metadata directories in the geometry report
  - man: update scrub ioctl documentation for metadir
  - man2: document metadata directory flag in fsgeom ioctl
  - man: document the -n parent mkfs option
  - man: fix ioctl_xfs_commit_range man page install
  - xfs_repair: fix maximum file offset comparison
  - update to 6.12.0
  - xfs_io: add support for atomic write statx fields
  - xfs_repair: fix crasher in pf_queuing_worker
  - xfs: Reduce unnecessary searches when searching for the best extents
  - xfs_spaceman: add dependency on libhandle target
  - mkfs: add a config file for 6.12 LTS kernels
  - xfs_scrub_all: wait for services to start activating
  - xfs_repair: checking rt free space metadata must happen during phase 4
  - xfs_db: allow setting current address to log blocks
  - xfs_db: convert rtsummary geometry
  - xfs_db: convert rtbitmap geometry
  - xfs_db: enable conversion of rt space units
  - xfs_db: access arbitrary realtime blocks and extents
  - xfs_db: access realtime file blocks
  - xfs_db: make the daddr command target the realtime device
  - xfs_db: report the realtime device when associated with each io cursor
  - xfs_db: support passing the realtime device to the debugger
  - xfs_io: add atomic file update commands to exercise file commit range
  - xfs_io: add a commitrange option to the exchangerange command
  - xfs_fsr: port to new file exchange library function
  - ------------------------------------------------------------------

------------------------------------------------------------------
------------------  2025-2-16  -  Feb 16 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.10 → 10.2.11
  - Update box plugin documentation
    Add chapter about new container build feature. The
    box plugin can now also run the build in containers

++++ kernel-default:

  - block: copy back bounce buffer to user-space correctly in case
    of split (git-fixes).
  - partitions: ldm: remove the initial kernel-doc notation
    (git-fixes).
  - block, bfq: fix waker_bfqq UAF after bfq_split_bfqq()
    (git-fixes).
  - zram: fix uninitialized ZRAM not releasing backing device
    (git-fixes).
  - zram: refuse to use zero sized block device as backing device
    (git-fixes).
  - blk-iocost: Avoid using clamp() on inuse in
    __propagate_weights() (git-fixes).
  - block: get wp_offset by bdev_offset_from_zone_start (git-fixes).
  - block: Prevent potential deadlocks in zone write plug error
    recovery (git-fixes).
  - commit 4b28019
  - objtool/rust: add one more `noreturn` Rust function (git-fixes).
  - gpiolib: Fix crash on error in gpiochip_get_ngpios()
    (git-fixes).
  - gpio: stmpe: Check return value of stmpe_reg_read in
    stmpe_gpio_irq_sync_unlock (git-fixes).
  - gpio: bcm-kona: Add missing newline to dev_err format string
    (git-fixes).
  - gpio: bcm-kona: Make sure GPIO bits are unlocked when requesting
    IRQ (git-fixes).
  - gpio: bcm-kona: Fix GPIO lock/unlock for banks above bank 0
    (git-fixes).
  - commit 218f1c3

++++ kernel-rt:

  - block: copy back bounce buffer to user-space correctly in case
    of split (git-fixes).
  - partitions: ldm: remove the initial kernel-doc notation
    (git-fixes).
  - block, bfq: fix waker_bfqq UAF after bfq_split_bfqq()
    (git-fixes).
  - zram: fix uninitialized ZRAM not releasing backing device
    (git-fixes).
  - zram: refuse to use zero sized block device as backing device
    (git-fixes).
  - blk-iocost: Avoid using clamp() on inuse in
    __propagate_weights() (git-fixes).
  - block: get wp_offset by bdev_offset_from_zone_start (git-fixes).
  - block: Prevent potential deadlocks in zone write plug error
    recovery (git-fixes).
  - commit 4b28019
  - objtool/rust: add one more `noreturn` Rust function (git-fixes).
  - gpiolib: Fix crash on error in gpiochip_get_ngpios()
    (git-fixes).
  - gpio: stmpe: Check return value of stmpe_reg_read in
    stmpe_gpio_irq_sync_unlock (git-fixes).
  - gpio: bcm-kona: Add missing newline to dev_err format string
    (git-fixes).
  - gpio: bcm-kona: Make sure GPIO bits are unlocked when requesting
    IRQ (git-fixes).
  - gpio: bcm-kona: Fix GPIO lock/unlock for banks above bank 0
    (git-fixes).
  - commit 218f1c3

------------------------------------------------------------------
------------------  2025-2-15  -  Feb 15 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - block: don't update BLK_FEAT_POLL in
    __blk_mq_update_nr_hw_queues (git-fixes).
  - block: check BLK_FEAT_POLL under q_usage_count (git-fixes).
  - nbd: don't allow reconnect after disconnect (git-fixes).
  - ps3disk: Do not use dev->bounce_size before it is set
    (git-fixes).
  - block: retry call probe after request_module in
    blk_request_module (git-fixes).
  - dm: Fix dm-zoned-reclaim zone write pointer alignment
    (git-fixes).
  - commit 7d6f0ed
  - PCI: Avoid FLR for Mediatek MT7922 WiFi (git-fixes).
  - mmc: mtk-sd: Fix register settings for hs400(es) mode
    (git-fixes).
  - commit 7643768
  - block: Ignore REQ_NOWAIT for zone reset and zone finish
    operations (git-fixes).
  - block: Use a zone write plug BIO work for REQ_NOWAIT BIOs
    (git-fixes).
  - blk-mq: move cpuhp callback registering out of q->sysfs_lock
    (git-fixes).
  - blk-mq: register cpuhp callback after hctx is added to xarray
    table (git-fixes).
  - brd: decrease the number of allocated pages which discarded
    (git-fixes).
  - block: Don't allow an atomic write be truncated in
    blkdev_write_iter() (git-fixes).
  - block: Prevent potential deadlock in blk_revalidate_disk_zones()
    (git-fixes).
  - ublk: fix error code for unsupported command (git-fixes).
  - block: return unsigned int from bdev_io_min (git-fixes).
  - blk-settings: round down io_opt to physical_block_size
    (git-fixes).
  - zram: ZRAM_DEF_COMP should depend on ZRAM (git-fixes).
  - zram: clear IDLE flag in mark_idle() (git-fixes).
  - zram: clear IDLE flag after recompression (git-fixes).
  - zram: do not mark idle slots that cannot be idle (git-fixes).
  - block: lift bio_is_zone_append to bio.h (git-fixes).
  - block: fix bio_split_rw_at to take zone_write_granularity into
    account (git-fixes).
  - block: take chunk_sectors into account in bio_split_write_zeroes
    (git-fixes).
  - ublk: fix ublk_ch_mmap() for 64K page size (git-fixes).
  - loop: fix type of block size (git-fixes).
  - block: Switch to using refcount_t for zone write plugs
    (git-fixes).
  - commit df002cc

++++ kernel-rt:

  - block: don't update BLK_FEAT_POLL in
    __blk_mq_update_nr_hw_queues (git-fixes).
  - block: check BLK_FEAT_POLL under q_usage_count (git-fixes).
  - nbd: don't allow reconnect after disconnect (git-fixes).
  - ps3disk: Do not use dev->bounce_size before it is set
    (git-fixes).
  - block: retry call probe after request_module in
    blk_request_module (git-fixes).
  - dm: Fix dm-zoned-reclaim zone write pointer alignment
    (git-fixes).
  - commit 7d6f0ed
  - PCI: Avoid FLR for Mediatek MT7922 WiFi (git-fixes).
  - mmc: mtk-sd: Fix register settings for hs400(es) mode
    (git-fixes).
  - commit 7643768
  - block: Ignore REQ_NOWAIT for zone reset and zone finish
    operations (git-fixes).
  - block: Use a zone write plug BIO work for REQ_NOWAIT BIOs
    (git-fixes).
  - blk-mq: move cpuhp callback registering out of q->sysfs_lock
    (git-fixes).
  - blk-mq: register cpuhp callback after hctx is added to xarray
    table (git-fixes).
  - brd: decrease the number of allocated pages which discarded
    (git-fixes).
  - block: Don't allow an atomic write be truncated in
    blkdev_write_iter() (git-fixes).
  - block: Prevent potential deadlock in blk_revalidate_disk_zones()
    (git-fixes).
  - ublk: fix error code for unsupported command (git-fixes).
  - block: return unsigned int from bdev_io_min (git-fixes).
  - blk-settings: round down io_opt to physical_block_size
    (git-fixes).
  - zram: ZRAM_DEF_COMP should depend on ZRAM (git-fixes).
  - zram: clear IDLE flag in mark_idle() (git-fixes).
  - zram: clear IDLE flag after recompression (git-fixes).
  - zram: do not mark idle slots that cannot be idle (git-fixes).
  - block: lift bio_is_zone_append to bio.h (git-fixes).
  - block: fix bio_split_rw_at to take zone_write_granularity into
    account (git-fixes).
  - block: take chunk_sectors into account in bio_split_write_zeroes
    (git-fixes).
  - ublk: fix ublk_ch_mmap() for 64K page size (git-fixes).
  - loop: fix type of block size (git-fixes).
  - block: Switch to using refcount_t for zone write plugs
    (git-fixes).
  - commit df002cc

------------------------------------------------------------------
------------------  2025-2-14  -  Feb 14 2025  -------------------
------------------------------------------------------------------

++++ cockpit-podman:

  - Update to version 100
    * dropped: correct-container-search.patch as this behaviour is
    fixed upstream

++++ fwupd:

  - Update to version 2.0.6:
    + This release adds the following features:
  - Add 'fwupdtool efiboot-hive' to allow setting the nmbl cmdline
  - Allow setting the inhibit reason from fwupdmgr
  - Allow USB-provided hidraw devices to use DS-20 descriptors
    + This release fixes the following bugs:
  - Correctly deploy the dbx on MSI hardware
  - Correctly extract the milestone from Lenovo version numbers
  - Do not add invalid CoSWID entities to fix a fuzzing hang
  - Fix Logitech HID++ child device detection
  - Get the correct internal network VID and PID from Redfish
  - Include the payload length in the Wacom scaler update start command
  - Only use emulated devices when using device-emulate
  - Reload the thunderbolt retimer version after the payload is deployed
  - Speed up startup by ~1% by limiting the precision of percentage updates
  - Support new version formats for future Huddly devices
  - Updating the Logitech Rallybar in a more reliable way
    + This release adds support for the following hardware:
  - HPE Gen10/Gen10+ devices using Redfish

++++ grub2:

  - Security fixes for 2024
    * 0001-misc-Implement-grub_strlcpy.patch
  - Fix CVE-2024-45781 (bsc#1233617)
    * 0002-fs-ufs-Fix-a-heap-OOB-write.patch
  - Fix CVE-2024-56737 (bsc#1234958)
  - Fix CVE-2024-45782 (bsc#1233615)
    * 0003-fs-hfs-Fix-stack-OOB-write-with-grub_strcpy.patch
  - Fix CVE-2024-45780 (bsc#1233614)
    * 0004-fs-tar-Integer-overflow-leads-to-heap-OOB-write.patch
  - Fix CVE-2024-45783 (bsc#1233616)
    * 0005-fs-hfsplus-Set-a-grub_errno-if-mount-fails.patch
    * 0006-kern-file-Ensure-file-data-is-set.patch
    * 0007-kern-file-Implement-filesystem-reference-counting.patch
  - Fix CVE-2025-0624 (bsc#1236316)
    * 0008-net-Fix-OOB-write-in-grub_net_search_config_file.patch
  - Fix CVE-2024-45774 (bsc#1233609)
    * 0009-video-readers-jpeg-Do-not-permit-duplicate-SOF0-mark.patch
  - Fix CVE-2024-45775 (bsc#1233610)
    * 0010-commands-extcmd-Missing-check-for-failed-allocation.patch
  - Fix CVE-2025-0622 (bsc#1236317)
    * 0011-commands-pgp-Unregister-the-check_signatures-hooks-o.patch
  - Fix CVE-2025-0622 (bsc#1236317)
    * 0012-normal-Remove-variables-hooks-on-module-unload.patch
  - Fix CVE-2025-0622 (bsc#1236317)
    * 0013-gettext-Remove-variables-hooks-on-module-unload.patch
  - Fix CVE-2024-45776 (bsc#1233612)
    * 0014-gettext-Integer-overflow-leads-to-heap-OOB-write-or-.patch
  - Fix CVE-2024-45777 (bsc#1233613)
    * 0015-gettext-Integer-overflow-leads-to-heap-OOB-write.patch
  - Fix CVE-2025-0690 (bsc#1237012)
    * 0016-commands-read-Fix-an-integer-overflow-when-supplying.patch
  - Fix CVE-2025-1118 (bsc#1237013)
    * 0017-commands-minicmd-Block-the-dump-command-in-lockdown-.patch
  - Fix CVE-2024-45778 (bsc#1233606)
  - Fix CVE-2024-45779 (bsc#1233608)
    * 0018-fs-bfs-Disable-under-lockdown.patch
  - Fix CVE-2025-0677 (bsc#1237002)
  - Fix CVE-2025-0684 (bsc#1237008)
  - Fix CVE-2025-0685 (bsc#1237009)
  - Fix CVE-2025-0686 (bsc#1237010)
  - Fix CVE-2025-0689 (bsc#1237011)
    * 0019-fs-Disable-many-filesystems-under-lockdown.patch
  - Fix CVE-2025-1125 (bsc#1237014)
  - Fix CVE-2025-0678 (bsc#1237006)
    * 0020-fs-Prevent-overflows-when-allocating-memory-for-arra.patch
  - Updated to upstream version
    * 0002-Requiring-authentication-after-tpm-unlock-for-CLI-ac.patch
  - Bump upstream SBAT generation to 5

++++ kernel-default:

  - block: model freeze & enter queue as lock for supporting lockdep
    (git-fixes).
  - Refresh
    patches.suse/block-fix-uaf-for-flush-rq-while-iterating-tags.patch.
  - commit da1d6bf
  - blk-mq: add non_owner variant of start_freeze/unfreeze queue
    APIs (git-fixes).
  - Refresh
    patches.suse/blk-mq-add-number-of-queue-calc-helper.patch.
  - Refresh
    patches.suse/blk-mq-introduce-blk_mq_map_hw_queues.patch.
  - commit 1793948
  - blk-mq: Make blk_mq_quiesce_tagset() hold the tag list mutex
    less long (git-fixes).
  - block: fix ordering between checking BLK_MQ_S_STOPPED request
    adding (git-fixes).
  - block: fix ordering between checking QUEUE_FLAG_QUIESCED
    request adding (git-fixes).
  - block: fix missing dispatching request when queue is started
    or unquiesced (git-fixes).
  - Revert "blk-throttle: Fix IO hang for a corner case"
    (git-fixes).
  - fs/block: Check for IOCB_DIRECT in generic_atomic_write_valid()
    (git-fixes).
  - block/fs: Pass an iocb to generic_atomic_write_valid()
    (git-fixes).
  - commit 18a317b
  - drm/xe/client: bo->client does not need bos_lock (git-fixes).
  - drm/i915/selftests: avoid using uninitialized context
    (git-fixes).
  - drm/amdgpu: bail out when failed to load fw in
    psp_init_cap_microcode() (git-fixes).
  - amdkfd: properly free gang_ctx_bo when failed to init user queue
    (git-fixes).
  - drm: Fix DSC BPP increment decoding (git-fixes).
  - gpu: host1x: Fix a use of uninitialized mutex (git-fixes).
  - drm/tests: hdmi: Fix WW_MUTEX_SLOWPATH failures (git-fixes).
  - spi: sn-f-ospi: Fix division by zero (git-fixes).
  - regmap-irq: Add missing kfree() (git-fixes).
  - Bluetooth: btintel_pcie: Fix a potential race condition
    (git-fixes).
  - batman-adv: fix panic during interface removal (git-fixes).
  - can: rockchip: rkcanfd_handle_rx_fifo_overflow_int(): bail
    out if skb cannot be allocated (git-fixes).
  - can: etas_es58x: fix potential NULL pointer dereference on
    udev->serial (git-fixes).
  - can: c_can: fix unbalanced runtime PM disable in error path
    (git-fixes).
  - can: ctucanfd: handle skb allocation failure (git-fixes).
  - can: j1939: j1939_sk_send_loop(): fix unable to send messages
    with data length zero (git-fixes).
  - Documentation/networking: fix basic node example document ISO
    15765-2 (git-fixes).
  - wifi: ath12k: fix handling of 6 GHz rules (git-fixes).
  - ax25: Fix refcount leak caused by setting SO_BINDTODEVICE
    sockopt (git-fixes).
  - commit c1eb6bd
  - scsi: mpt3sas: Set ioc->manu_pg11.EEDPTagMode directly to 1
    (git-fixes).
  - commit 57032e5
  - scsi: sg: Enable runtime power management (git-fixes).
  - Refresh
    patches.suse/scsi-sg-Fix-slab-use-after-free-read-in-sg_release.patch.
  - commit 234612c

++++ kernel-rt:

  - block: model freeze & enter queue as lock for supporting lockdep
    (git-fixes).
  - Refresh
    patches.suse/block-fix-uaf-for-flush-rq-while-iterating-tags.patch.
  - commit da1d6bf
  - blk-mq: add non_owner variant of start_freeze/unfreeze queue
    APIs (git-fixes).
  - Refresh
    patches.suse/blk-mq-add-number-of-queue-calc-helper.patch.
  - Refresh
    patches.suse/blk-mq-introduce-blk_mq_map_hw_queues.patch.
  - commit 1793948
  - blk-mq: Make blk_mq_quiesce_tagset() hold the tag list mutex
    less long (git-fixes).
  - block: fix ordering between checking BLK_MQ_S_STOPPED request
    adding (git-fixes).
  - block: fix ordering between checking QUEUE_FLAG_QUIESCED
    request adding (git-fixes).
  - block: fix missing dispatching request when queue is started
    or unquiesced (git-fixes).
  - Revert "blk-throttle: Fix IO hang for a corner case"
    (git-fixes).
  - fs/block: Check for IOCB_DIRECT in generic_atomic_write_valid()
    (git-fixes).
  - block/fs: Pass an iocb to generic_atomic_write_valid()
    (git-fixes).
  - commit 18a317b
  - drm/xe/client: bo->client does not need bos_lock (git-fixes).
  - drm/i915/selftests: avoid using uninitialized context
    (git-fixes).
  - drm/amdgpu: bail out when failed to load fw in
    psp_init_cap_microcode() (git-fixes).
  - amdkfd: properly free gang_ctx_bo when failed to init user queue
    (git-fixes).
  - drm: Fix DSC BPP increment decoding (git-fixes).
  - gpu: host1x: Fix a use of uninitialized mutex (git-fixes).
  - drm/tests: hdmi: Fix WW_MUTEX_SLOWPATH failures (git-fixes).
  - spi: sn-f-ospi: Fix division by zero (git-fixes).
  - regmap-irq: Add missing kfree() (git-fixes).
  - Bluetooth: btintel_pcie: Fix a potential race condition
    (git-fixes).
  - batman-adv: fix panic during interface removal (git-fixes).
  - can: rockchip: rkcanfd_handle_rx_fifo_overflow_int(): bail
    out if skb cannot be allocated (git-fixes).
  - can: etas_es58x: fix potential NULL pointer dereference on
    udev->serial (git-fixes).
  - can: c_can: fix unbalanced runtime PM disable in error path
    (git-fixes).
  - can: ctucanfd: handle skb allocation failure (git-fixes).
  - can: j1939: j1939_sk_send_loop(): fix unable to send messages
    with data length zero (git-fixes).
  - Documentation/networking: fix basic node example document ISO
    15765-2 (git-fixes).
  - wifi: ath12k: fix handling of 6 GHz rules (git-fixes).
  - ax25: Fix refcount leak caused by setting SO_BINDTODEVICE
    sockopt (git-fixes).
  - commit c1eb6bd
  - scsi: mpt3sas: Set ioc->manu_pg11.EEDPTagMode directly to 1
    (git-fixes).
  - commit 57032e5
  - scsi: sg: Enable runtime power management (git-fixes).
  - Refresh
    patches.suse/scsi-sg-Fix-slab-use-after-free-read-in-sg_release.patch.
  - commit 234612c

++++ libblockdev:

  - update to 3.1.1:
    * Use glib2 G_GNUC_UNUSED in place of UNUSED locally defined
    * Port to G_GNUC_INTERNAL for controlling symbols visibility
    * Fix some more occurrences of missing port to G_GNUC_UNUSED
    * dm_logging: Annotate redirect_dm_log() printf format
    * tests: Add NVMe persistent discovery controller tests
    * tests: Add NVMe controller type checks
    * Makefile: Fix bumpver to work with micro versions
    * tests: Manually remove removed PVs from LVM devices file
    * tests: Ignore LVM devices file for non-LVM tests
    * tests: Fix removing custom LVM devices file
    * nvme: Add bd_nvme_is_tech_avail to the API file
    * lvm-dbus: Fix passing size for pvresize over DBus
  - Update to 3.1.0:
    * Add BDPluginSpec constructor and use it in plugin_specs_from_names
    * overrides: Remove unused 'sys' import
    * swap: Add support for checking label and UUID format
    * fs: Add a function to check label format for F2FS
    * fs: Add a generic function to check for fs info availability
    * fs: Fix allowed UUID for generic mkfs with VFAT
    * fs: Add support for getting filesystem min size for NTFS and Ext
    * Mark NVDIMM plugin as deprecated since 3.1
    * part: Fix potential double free when getting parttype
    * Fix missing progress initialization in bd_crypto_luks_add_key
    * lvm-dbus: Fix leaking error
    * lvm-dbus: Avoid using already-freed memory
    * utils: Add expected printf string annotation
    * fs: Report reason for open() and ioctl() failures
  - Add %{_libdir}/libbd_s390.so for s390x because missing file identitied
  - Update to 3.0.4:
    * plugins: use g_autofree for free'ing g_char's
    * plugins: btrfs: use g_autofree where possible for g_free
    * fs: correct btrfs set label description
    * nvme: Rework memory allocation for device ioctls
    * spec: Obsolete vdo plugin packages
    * spec: Move obsoleted devel subpackages to libblockdev-devel
    * ci: Bump actions/checkout from v3 to v4
    * part: Do not open disk read-write for read only operations
    * fs: Disable progress for ntfsresize
    * packit: Add configuration for downstream builds
    * logging: Default to DEBUG log level if compiled with --enable-debug
    * Use log function when calling a plugin function that is not loaded
    * lvm-dbus: Replace g_critical calls with bd_utils_log_format
    * tests: Fail early when recompilation fails in library_test
  - Update to version 3.0.3:
    * Always use "--fs ignore" with lvresize
    * nvme:
  - Use interim buffer for nvme_get_log_sanitize()
  - Generate HostID when missing
    * tests:
  - Specificy required versions when importing GLib and BlockDev
    introspection
  - Minor NVMe HostNQN fixes
  - Replace deprecated unittest assert calls
    * fs:
  - Fix leaking directories with temporary mounts
  - Fix memory leak
    * crypto: Correctly convert passphrases from Python to C
  - Update to version 3.0.2:
    * Use ntfsinfo instead of ntfscluster for faster
    bd_fs_ntfs_get_info.
    * Restrict list of exported symbols via -export-symbols-regex.
    * lib: Silence the missing DEFAULT_CONF_DIR_PATH.
    * loop: Report BD_LOOP_ERROR_DEVICE on empty loop devices.
    * fs: Fix unused error in extract_e2fsck_progress.
    * fs: Use read-only mount where possible for generic FS
    functions.
    * fs: Document that generic functions can mount filesystems.
    * fs: Avoid excess logging in extract_e2fsck_progress.
  - Restructure all sub-packages in the spec file to enhance
    maintainability.
  - Update to 3.0.1:
    * New bugfix release of the libblockdev library with multiple
    fixes.
    * loop: Define LOOP_SET_BLOCK_SIZE is not defined. And remove
    bd_loop_get_autoclear definition.
    * crypto: Remove stray struct redefinition.
    * fs: Simplify struct BDFSInfo. And add missing copy and free
    functions to the header file.
    * vdo_stats: Remove unused libparted include.
    * lvm: Make _vglock_start_stop static. Fix declaration for
    bd_lvm_vdolvpoolname. And add bd_lvm_segdata_copy/free to the
    header file.
    * Make the conf.d directory versioned.
  - Changes from version 3.0.0:
    * New major release of the libblockdev library. This release
    contains a large API overhaul.
    * VDO a KBD plugins were removed.
    * New NVMe plugin was added.
    * Runtime dependencies are no longer checked during plugin
    initialization.
    * Part plugin was rewritten to use libfdisk instead of libparted
    * Crypto plugin API went through an extensive rewrite.
    * Support for new technologies was added to the crypto plugin:
    FileVault2 encryption, DM Integrity, LUKS2 tokens.
    * Filesystem plugin adds support for btrfs, F2FS, NILFS2, exFAT
    and UDF.
    * Support for new filesystem operations was added to the plugin:
    setting label and UUID, generic mkfs function and API for
    getting feature support for filesystems.
    * dmraid support was removed from the DM plugin.
    * Python 2 support was dropped.
  - Drop no longer needed libblockdev-fix-libkmod-include.patch
  - Drop no longer supported sub-packages with their dependencies,
    and their configure options, following upstream changes: python2
    (python-devel), bcache, dmraid (dmraid-devel BuildRequires) and
    kbd.
  - Add (gcc >= 11 or gcc11) boolean BuildRequires to ensure the
    package is buildable on Leap 15.5, where the gcc meta-package is
    of version 7.
  - Bump the SO version to 3 for the shared library and GI bindings
    sub-packages.
  - Add ext2fs, fdisk, and libkeyutils pkgconfig() BuildRequires.
    The first is a new dependency for the FS plugin. The second, for
    the PART plugin. And the latter, for the CRYPTO plugin (before,
    the explicit_bzero() function would be searched for).
  - Add libnvme-devel >= 1.3 BuildRequires, and pass --with-nvme to
    configure, needed for the NVMe plugin (new upstream addition).
  - Pass --with-tools to configure, ensuring we keep building the
    libblockdev tools.

++++ libbytesize:

  - Add NEWS.rst to source documentation
  - Add %python3_fix_shebang to fix binaries dependency on
    /usr/bin/python3
  - Update to release 2.10
    * remove dependency on python3-six
  - Rename python3-libbytesize sub-package to python3-bytesize. This
    is the expected name by its consumers.
  - Update to version 2.9:
    * This release contains fixes for some small issues.
    * Updated translations.

++++ systemd:

  - Import commit e03ffd74c4a30c1c75e05874ce18d31e503437b7 (merge of v257.3)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/47794646786ae4ddb6d3deb2030e2761447999ec...e03ffd74c4a30c1c75e05874ce18d31e503437b7
  - Import commit 47794646786ae4ddb6d3deb2030e2761447999ec
    4779464678 import-pubring.gpg: add openSUSE build key (bsc#1236751)
    2c8382881f systemd-pull: support .asc and .sha256.* signature (bsc#1236887)

++++ udisks2:

  - Drop rcFOO symlinks for CODE16 (PED-266).
  - update to version 2.10.1
  - Update Ukrainian translation
  - tests: Wipe used devices for LVM2 RAID tests
  - tests: Settle down before checking the LVM RAID MissingPhysicalVolumes property
  - tests: Rescan vdevs after lvm raid tests
  - Update German translation
  - tests: Mark UDF fstab filesystem tests as unstable
  - tests: Add offline and online filesystem grow tests
  - doc: Clarify the Filesystem.Size property presence
  - udiskslinuxfilesystem: Force native tools for mounted XFS fs size retrieval
  - udiskslinuxfilesystem: Refactor internal whitelists
  - tests: Fix Python class invocation in nvme tests
  - udisksctl: Add "--no-partition-scan" option for "loop-setup" command
  - tests: Fix regex escaping
  - integration-test: Fix invalid escaping
  - tests: Mark LVM RAID tests as unstable
  - tests: Fix LSM drive objects crawl
  - iscsi: Fix login on firmware-discovered nodes
  - udiskslinuxmanager: Properly handle disabled modules
  - tests: Replace deprecated unittest assert calls
  - udisksctl: Guard object lookup
  - Update ka.po
  - udiskslinuxloop: Avoid warnings on empty loop devices
  - Update Polish translation
  - Limit getting filesystem size only to Ext and XFS
  - build: Check for gobject-introspection m4 macro presence
  - tests: start the polkitd mock with the corresponding user if it exists
  - Add Obsoletes tags for libudisks2-0_bcache and libudisks2-0_zram
    modules, dropped on latest version bump, so they get removed from
    end users' systems upon system upgrade.
  - Drop unnecessary/discouraged %{?systemd_requires} from spec file.
  - Update to version 2.10.0:
    + This release brings large number of internal changes, while
    keeping the promise of API stability. This development cycle
    was mostly driven by libblockdev 3.0 API overhaul.
    + Partitioning was ported to libfdisk.
    + The kbd and vdo libblockdev plugins were removed and so were
    zram, bcache and vdo udisks modules.
    + Definition of supported filesystems was moved to libblockdev
    and filesystem operations were unified.
    + Native NVMe support has been added through libnvme.
    + Syntax of configurable mount options was extended to separate
    filesystem signature and filesystem driver used for mounting.
    + A number of workarounds was placed around the
    org.freedesktop.UDisks2.Filesystem.Size property value
    retrieval to avoid excessive I/O traffic whenever possible.
    + Bash and Zsh completion enhancements.
    + lvm2 module uevent handling improvements.
    + ATA Secure Erase is now allowed only on top-level block
    objects.
    + Extra iSCSI node parameters are now honoured properly.
    + FIPS mode fixes.
    + Added support for resolving devices by PARTLABEL and PARTUUID.
    + Full support for setting filesystem and partition UUIDs.
    + Dynamic mountpoint name sanitization and ACL fixes.
    + Added support for LVM2 RAID.
    + UUID of Bitlocker volumes is now properly exposed.
    + Added an option to force/avoid creation of mdraid write-intent
    bitmap.
    + Updated translations.
  - Drop default_luks_encryption macro definition. It's no longer
    needed as upstream defaults to LUKS2 now.
  - Drop bcache, vdo and zram sub-packages, following upstream
    changes, and libblockdev-kbd(-devel) BuildRequires/Requires.
  - Drop bogus build requirement on libblockdev-lvm-dbus-devel, and
    move libblockdev-lvm-devel BuildRequires to the lvm2 module
    sub-package.
  - Move libconfig and libstoragemgmt pkgconfig() BuildRequires to
    the lsm module sub-package, and libblockdev-btrfs-devel
    BuildRequires to the btrfs modules sub-package, which is where
    they belong.
  - Add libblockdev-nvme-devel BuildRequires and libblockdev-nvme
    Requires as new required dependencies.
  - Drop harden_udisks2-zram-setup@.service.patch: It's unneeded now
    that the zram module has been deprecated.
  - Drop merged upstream patches:
    0001-udisksata-Move-the-low-level-PM-state-call.patch,
    0001-udiskslinuxfilesystem-Make-the-size-property-retriev.patch,
    0001-udiskslinuxmountoptions-Do-not-free-static-daemon-re.patch,
    0001-udiskslinuxprovider-Only-update-related-objects-on-u.patch.
  - Split Bash and Zsh (new to this release) completion scripts to
    sub-packages of their own.
  - Amend GPL-2.0-or-later License tags to LGPL-2.0-or-later for the
    btrfs, lvm2 and lsm UDisks modules sub-packages. This correction
    is based on what's explicitly stated on the source code from
    UDisks modules' folders under the modules/ top-level directory.

++++ netavark:

  - Remove netavark-1.14.0.obscpio checked-in mistakenly.
  - Use recommended way to require latest rust—require cargo.

++++ runc:

  - Update to runc v1.2.5. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.5>.

++++ xkeyboard-config:

  - update to 2.44 (boo#1237205)
    * Fixes and updates to multiple layouts, making them match
    current and updated specificatiopns
    * Changes to multiple layouts that change behavior
    * Add Diktor layout ru(diktor), and RuIntl layouts set
    ru(ruintl_ru),   ru(ruintl_en).
    * Expanded options for caps locking behavior for multiple
    layouts
    * Add <I570> keycode (KEY_REFRESH_RATE_TOGGLE)

------------------------------------------------------------------
------------------  2025-2-13  -  Feb 13 2025  -------------------
------------------------------------------------------------------

++++ curl:

  - Update to 8.12.1:
    * Bugfixes:
  - asyn-thread: fix build with 'CURL_DISABLE_SOCKETPAIR'
  - asyn-thread: fix HTTPS RR crash
  - asyn-thread: fix the returned bitmask from Curl_resolver_getsock
  - asyn-thread: survive a c-ares channel set to NULL
  - cmake: always reference OpenSSL and ZLIB via imported targets
  - cmake: respect 'GNUTLS_CFLAGS' when detected via 'pkg-config'
  - cmake: respect 'GNUTLS_LIBRARY_DIRS' in 'libcurl.pc' and 'curl-config'
  - content_encoding: #error on too old zlib
  - imap: TLS upgrade fix
  - ldap: drop support for legacy Novell LDAP SDK
  - libssh2: comparison is always true because rc <= -1
  - libssh2: raise lowest supported version to 1.2.8
  - libssh: drop support for libssh older than 0.9.0
  - openssl-quic: ignore ciphers for h3
  - pop3: TLS upgrade fix
  - runtests: fix the disabling of the memory tracking
  - runtests: quote commands to support paths with spaces
  - scache: add magic checks
  - smb: silence '-Warray-bounds' with gcc 13+
  - smtp: TLS upgrade fix
  - tool_cfgable: sort struct fields by size, use bitfields for booleans
  - tool_getparam: add "TLS required" flag for each such option
  - vtls: fix multissl-init
  - wakeup_write: make sure the eventfd write sends eight bytes

++++ grub2:

  - Fix out of memory issue on PowerPC by increasing RMA size (bsc#1236744)
    * 0001-powerpc-increase-MIN-RMA-size-for-CAS-negotiation.patch

++++ kernel-default:

  - scsi: core: Do not retry I/Os during depopulation (git-fixes).
  - scsi: mpi3mr: Fix possible crash when setting up bsg fails
    (git-fixes).
  - scsi: st: Don't set pos_unknown just after device recognition
    (git-fixes).
  - scsi: myrb: Remove dead code (git-fixes).
  - scsi: qla2xxx: Move FCE Trace buffer allocation to user control
    (git-fixes).
  - scsi: iscsi: Fix redundant response for
    ISCSI_UEVENT_GET_HOST_STATS request (git-fixes).
  - scsi: core: Fix command pass through retry regression
    (git-fixes).
  - scsi: scsi_debug: Fix hrtimer support for ndelay (git-fixes).
  - scsi: mpi3mr: Handling of fault code for insufficient power
    (git-fixes).
  - scsi: mpi3mr: Start controller indexing from 0 (git-fixes).
  - scsi: mpi3mr: Synchronize access to ioctl data buffer
    (git-fixes).
  - scsi: qla1280: Fix hw revision numbering for ISP1020/1040
    (git-fixes).
  - scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after
    device reset (git-fixes).
  - scsi: st: Don't modify unknown block number in MTIOCGET
    (git-fixes).
  - scsi: hisi_sas: Enable all PHYs that are not disabled by user
    during controller reset (git-fixes).
  - commit 73a1130
  - sched/debug: Provide slice length for fair tasks (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Fix inaccurate h_nr_runnable accounting with
    delayed dequeue (bsc#1234634 (Scheduler functional and
    performance backports)).
  - lazy tlb: fix hotplug exit race with MMU_LAZY_TLB_SHOOTDOWN
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Use str_enabled_disabled() helper in
    update_selcpu_topology() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: Use sizeof_field for key_len in dsq_hash_params
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Use the NUMA scheduling domain for NUMA optimizations
    (bsc#1234634 (Scheduler functional and performance backports)).
  - torture: Add dowarn argument to torture_sched_setaffinity()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Prioritize migrating eligible tasks in
    sched_balance_rq() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - rseq: Validate read-only fields under DEBUG_RSEQ config
    (bsc#1234634 (Scheduler functional and performance backports)).
  - lockdep: Move lockdep_assert_locked() under #ifdef
    CONFIG_PROVE_LOCKING (bsc#1234634 (Scheduler functional and
    performance backports)).
  - lockdep: Mark chain_hlock_class_idx() with __maybe_unused
    (bsc#1234634 (Scheduler functional and performance backports)).
  - lockdep: Document MAX_LOCKDEP_CHAIN_HLOCKS calculation
    (bsc#1234634 (Scheduler functional and performance backports)).
  - locking/ww_mutex/test: Use swap() macro (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/wake_q: Add helper to call wake_up_q after unlock with
    preemption disabled (bsc#1234634 (Scheduler functional and
    performance backports)).
  - exec: Make sure task->comm is always NUL-terminated (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_ext: initialize kit->cursor.flags (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/rtmutex: Make sure we wake anything on the wake_q
    when we release the lock->wait_lock (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex
    (bsc#1234634 (Scheduler functional and performance backports)).
  - posix-timers: Cure si_sys_private race (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/mutex: Expose __mutex_owner() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/mutex: Make mutex::wait_lock irq safe (bsc#1234634
    (Scheduler functional and performance backports)).
  - locking/mutex: Remove wakeups from under mutex::wait_lock
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: remove unused __HAVE_THREAD_FUNCTIONS hook support
    (bsc#1234634 (Scheduler functional and performance backports)).
  - locking/osq_lock: Use atomic_try_cmpxchg_release() in
    osq_unlock() (bsc#1234634 (Scheduler functional and performance
    backports)).
  - locking/rtmutex: Fix misleading comment (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/pvqspinlock: Convert fields of 'enum vcpu_state' to
    uppercase (bsc#1234634 (Scheduler functional and performance
    backports)).
  - lockdep: Use info level for lockdep initial info messages
    (bsc#1234634 (Scheduler functional and performance backports)).
  - lockdep: Add lockdep_cleanup_dead_cpu() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/ww_mutex: Adjust to lockdep nest_lock requirements
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 75dae08
  - usb: xhci: fix ring expansion regression in 6.13-rc1
    (jsc#PED-10906).
  - commit 2b24cc0
  - Update
    patches.suse/s390-debug-Pass-in-and-enforce-output-buffer-size-for-format-handlers.patch
    (git-fixes bsc#1234755 jsc#PED-11161).
  - commit 5e23e2a
  - s390/pci: Add pci_msg debug view to PCI report (jsc#PED-11161).
  - s390/debug: Add a reverse mode for debug_dump() (jsc#PED-11161).
  - s390/debug: Add debug_dump() to write debug view to a string
    buffer (jsc#PED-11161).
  - s390/debug: Split private data alloc/free out of file operations
    (jsc#PED-11161).
  - s390/debug: Simplify and document debug_next_entry() logic
    (jsc#PED-11161).
  - s390/pci: Report PCI error recovery results via SCLP
    (jsc#PED-11161).
  - commit d92d766
  - s390/diag: Move diag.c to diag specific folder (jsc#PED-12044).
  - s390/diag324: Retrieve power readings via diag 0x324
    (jsc#PED-12044).
  - s390/diag: Create misc device /dev/diag (jsc#PED-12044).
  - commit 21143cc
  - usb: xhci: refactor xhci_td_cleanup() to return void
    (jsc#PED-10906).
  - commit 60cb49d
  - usb: xhci: remove unused arguments from td_to_noop()
    (jsc#PED-10906).
  - commit 17866c8
  - usb: xhci: improve xhci_clear_command_ring() (jsc#PED-10906).
  - commit 9f64dbb
  - usb: xhci: request MSI/-X according to requested amount
    (jsc#PED-10906).
  - commit 8cf7b56
  - usb: xhci: move link TRB quirk to xhci_gen_setup()
    (jsc#PED-10906).
  - commit 1d53caf
  - usb: xhci: simplify TDs start and end naming scheme in struct
    'xhci_td' (jesc#PED-10906).
  - commit 5eda71a
  - xhci: pci: Fix indentation in the PCI device ID definitions
    (jsc#PED-10906).
  - commit 9679ec8
  - s390x config: enable vertical CPU polarization by default (jsc#PED-10331)
  - commit 41d6235
  - xhci: pci: Use standard pattern for device IDs (jsc#PED-10906).
  - commit 3ae969e
  - usb: xhci: add xhci_initialize_ring_segments() (jsc#PED-10906).
  - commit 576f71b
  - usb: xhci: rework xhci_link_segments() (jsc#PED-10906).
  - commit 13e18a0
  - usb: xhci: refactor xhci_link_rings() to use source and
    destination rings (jsc#PED-10906).
  - commit 90c0bd4
  - usb: xhci: rework xhci_free_segments_for_ring() (jsc#PED-10906).
  - commit 93a58c0
  - usb: xhci: adjust xhci_alloc_segments_for_ring() arguments
    (jsc#PED-10906).
  - commit 0ce1882
  - usb: xhci: remove option to change a default ring's TRB cycle
    bit (jsc#PED-10906).
  - commit 0379d4e
  - usb: xhci: introduce macro for ring segment list iteration
    (jsc#PED-10906).
  - commit 2fdef8c
  - xhci: debugfs: Add virt endpoint state to xhci debugfs
    (jsc#PED-10906).
  - commit 9e1a656
  - xhci: trace stream context at Set TR Deq command completion
    (jsc#PED-10906).
  - Refresh
    patches.suse/usb-xhci-Fix-TD-invalidation-under-pending-Set-TR-De.patch.
  - commit b9965d9
  - xhci: add stream context tracing (jsc#PED-10906).
  - commit 2301fc5
  - xhci: Don't trace ring at every enqueue or dequeue increase
    (jsc#PED-10906).
  - commit 2cbfb0a
  - xhci: show DMA address of TRB when tracing TRBs (jsc#PED-10906).
  - commit e22a715
  - xhci: Cleanup Candence controller PCI device and vendor ID usage
    (jsc#PED-10906).
  - commit fb9a885
  - usb: xhci: Fix sum_trb_lengths() (jsc#PED-10906).
  - commit 0631220
  - mptcp: sysctl: sched: avoid using current->nsproxy (CVE-2025-21642 bsc#1236572)
  - commit d313630
  - mptcp: sysctl: blackhole timeout: avoid using current->nsproxy (CVE-2025-21641 bsc#1236124)
  - commit 3010ecf
  - Update config files.
    Set TSX_MODE to upstream default.
  - commit 761f591

++++ kernel-rt:

  - scsi: core: Do not retry I/Os during depopulation (git-fixes).
  - scsi: mpi3mr: Fix possible crash when setting up bsg fails
    (git-fixes).
  - scsi: st: Don't set pos_unknown just after device recognition
    (git-fixes).
  - scsi: myrb: Remove dead code (git-fixes).
  - scsi: qla2xxx: Move FCE Trace buffer allocation to user control
    (git-fixes).
  - scsi: iscsi: Fix redundant response for
    ISCSI_UEVENT_GET_HOST_STATS request (git-fixes).
  - scsi: core: Fix command pass through retry regression
    (git-fixes).
  - scsi: scsi_debug: Fix hrtimer support for ndelay (git-fixes).
  - scsi: mpi3mr: Handling of fault code for insufficient power
    (git-fixes).
  - scsi: mpi3mr: Start controller indexing from 0 (git-fixes).
  - scsi: mpi3mr: Synchronize access to ioctl data buffer
    (git-fixes).
  - scsi: qla1280: Fix hw revision numbering for ISP1020/1040
    (git-fixes).
  - scsi: st: Add MTIOCGET and MTLOAD to ioctls allowed after
    device reset (git-fixes).
  - scsi: st: Don't modify unknown block number in MTIOCGET
    (git-fixes).
  - scsi: hisi_sas: Enable all PHYs that are not disabled by user
    during controller reset (git-fixes).
  - commit 73a1130
  - sched/debug: Provide slice length for fair tasks (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Fix inaccurate h_nr_runnable accounting with
    delayed dequeue (bsc#1234634 (Scheduler functional and
    performance backports)).
  - lazy tlb: fix hotplug exit race with MMU_LAZY_TLB_SHOOTDOWN
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Use str_enabled_disabled() helper in
    update_selcpu_topology() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: Use sizeof_field for key_len in dsq_hash_params
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Use the NUMA scheduling domain for NUMA optimizations
    (bsc#1234634 (Scheduler functional and performance backports)).
  - torture: Add dowarn argument to torture_sched_setaffinity()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Prioritize migrating eligible tasks in
    sched_balance_rq() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - rseq: Validate read-only fields under DEBUG_RSEQ config
    (bsc#1234634 (Scheduler functional and performance backports)).
  - lockdep: Move lockdep_assert_locked() under #ifdef
    CONFIG_PROVE_LOCKING (bsc#1234634 (Scheduler functional and
    performance backports)).
  - lockdep: Mark chain_hlock_class_idx() with __maybe_unused
    (bsc#1234634 (Scheduler functional and performance backports)).
  - lockdep: Document MAX_LOCKDEP_CHAIN_HLOCKS calculation
    (bsc#1234634 (Scheduler functional and performance backports)).
  - locking/ww_mutex/test: Use swap() macro (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/wake_q: Add helper to call wake_up_q after unlock with
    preemption disabled (bsc#1234634 (Scheduler functional and
    performance backports)).
  - exec: Make sure task->comm is always NUL-terminated (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_ext: initialize kit->cursor.flags (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/rtmutex: Make sure we wake anything on the wake_q
    when we release the lock->wait_lock (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking: rtmutex: Fix wake_q logic in task_blocks_on_rt_mutex
    (bsc#1234634 (Scheduler functional and performance backports)).
  - posix-timers: Cure si_sys_private race (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/mutex: Expose __mutex_owner() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/mutex: Make mutex::wait_lock irq safe (bsc#1234634
    (Scheduler functional and performance backports)).
  - locking/mutex: Remove wakeups from under mutex::wait_lock
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: remove unused __HAVE_THREAD_FUNCTIONS hook support
    (bsc#1234634 (Scheduler functional and performance backports)).
  - locking/osq_lock: Use atomic_try_cmpxchg_release() in
    osq_unlock() (bsc#1234634 (Scheduler functional and performance
    backports)).
  - locking/rtmutex: Fix misleading comment (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/pvqspinlock: Convert fields of 'enum vcpu_state' to
    uppercase (bsc#1234634 (Scheduler functional and performance
    backports)).
  - lockdep: Use info level for lockdep initial info messages
    (bsc#1234634 (Scheduler functional and performance backports)).
  - lockdep: Add lockdep_cleanup_dead_cpu() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - locking/ww_mutex: Adjust to lockdep nest_lock requirements
    (bsc#1234634 (Scheduler functional and performance backports)).
  - commit 75dae08
  - usb: xhci: fix ring expansion regression in 6.13-rc1
    (jsc#PED-10906).
  - commit 2b24cc0
  - Update
    patches.suse/s390-debug-Pass-in-and-enforce-output-buffer-size-for-format-handlers.patch
    (git-fixes bsc#1234755 jsc#PED-11161).
  - commit 5e23e2a
  - s390/pci: Add pci_msg debug view to PCI report (jsc#PED-11161).
  - s390/debug: Add a reverse mode for debug_dump() (jsc#PED-11161).
  - s390/debug: Add debug_dump() to write debug view to a string
    buffer (jsc#PED-11161).
  - s390/debug: Split private data alloc/free out of file operations
    (jsc#PED-11161).
  - s390/debug: Simplify and document debug_next_entry() logic
    (jsc#PED-11161).
  - s390/pci: Report PCI error recovery results via SCLP
    (jsc#PED-11161).
  - commit d92d766
  - s390/diag: Move diag.c to diag specific folder (jsc#PED-12044).
  - s390/diag324: Retrieve power readings via diag 0x324
    (jsc#PED-12044).
  - s390/diag: Create misc device /dev/diag (jsc#PED-12044).
  - commit 21143cc
  - usb: xhci: refactor xhci_td_cleanup() to return void
    (jsc#PED-10906).
  - commit 60cb49d
  - usb: xhci: remove unused arguments from td_to_noop()
    (jsc#PED-10906).
  - commit 17866c8
  - usb: xhci: improve xhci_clear_command_ring() (jsc#PED-10906).
  - commit 9f64dbb
  - usb: xhci: request MSI/-X according to requested amount
    (jsc#PED-10906).
  - commit 8cf7b56
  - usb: xhci: move link TRB quirk to xhci_gen_setup()
    (jsc#PED-10906).
  - commit 1d53caf
  - usb: xhci: simplify TDs start and end naming scheme in struct
    'xhci_td' (jesc#PED-10906).
  - commit 5eda71a
  - xhci: pci: Fix indentation in the PCI device ID definitions
    (jsc#PED-10906).
  - commit 9679ec8
  - s390x config: enable vertical CPU polarization by default (jsc#PED-10331)
  - commit 41d6235
  - xhci: pci: Use standard pattern for device IDs (jsc#PED-10906).
  - commit 3ae969e
  - usb: xhci: add xhci_initialize_ring_segments() (jsc#PED-10906).
  - commit 576f71b
  - usb: xhci: rework xhci_link_segments() (jsc#PED-10906).
  - commit 13e18a0
  - usb: xhci: refactor xhci_link_rings() to use source and
    destination rings (jsc#PED-10906).
  - commit 90c0bd4
  - usb: xhci: rework xhci_free_segments_for_ring() (jsc#PED-10906).
  - commit 93a58c0
  - usb: xhci: adjust xhci_alloc_segments_for_ring() arguments
    (jsc#PED-10906).
  - commit 0ce1882
  - usb: xhci: remove option to change a default ring's TRB cycle
    bit (jsc#PED-10906).
  - commit 0379d4e
  - usb: xhci: introduce macro for ring segment list iteration
    (jsc#PED-10906).
  - commit 2fdef8c
  - xhci: debugfs: Add virt endpoint state to xhci debugfs
    (jsc#PED-10906).
  - commit 9e1a656
  - xhci: trace stream context at Set TR Deq command completion
    (jsc#PED-10906).
  - Refresh
    patches.suse/usb-xhci-Fix-TD-invalidation-under-pending-Set-TR-De.patch.
  - commit b9965d9
  - xhci: add stream context tracing (jsc#PED-10906).
  - commit 2301fc5
  - xhci: Don't trace ring at every enqueue or dequeue increase
    (jsc#PED-10906).
  - commit 2cbfb0a
  - xhci: show DMA address of TRB when tracing TRBs (jsc#PED-10906).
  - commit e22a715
  - xhci: Cleanup Candence controller PCI device and vendor ID usage
    (jsc#PED-10906).
  - commit fb9a885
  - usb: xhci: Fix sum_trb_lengths() (jsc#PED-10906).
  - commit 0631220
  - mptcp: sysctl: sched: avoid using current->nsproxy (CVE-2025-21642 bsc#1236572)
  - commit d313630
  - mptcp: sysctl: blackhole timeout: avoid using current->nsproxy (CVE-2025-21641 bsc#1236124)
  - commit 3010ecf
  - Update config files.
    Set TSX_MODE to upstream default.
  - commit 761f591

++++ openssh:

  - Fix a MitM attack against OpenSSH's VerifyHostKeyDNS-enabled
    client and a DoS attack against OpenSSH's client and server
    (bsc#1237040, CVE-2025-26465, bsc#1237041, CVE-2025-26466):
    * fix-CVE-2025-26465-and-CVE-2025-26466.patch

++++ rebootmgr:

  - Update to version 3.2+git20250213.bff65b1:
    * Release version 3.2
    * Handle case that main-window is not set correct
    * rebootmgrd: fix instantly strategy

------------------------------------------------------------------
------------------  2025-2-12  -  Feb 12 2025  -------------------
------------------------------------------------------------------

++++ crypto-policies:

  - Remove dangling symlink for the libreswan config [bsc#1236858]
  - Remove also sequoia config and generator files
  - Remove not needed fips bind mount service

++++ dhcpcd:

  - Update to 10.2.0
    * dhcp6: start request when advertise received after IRT
    * dhcpcd: stdout output sometimes empty when redirected to a file
    * Fix help text formatting
    * Apply lastlease behavior to DHCPv6
    * dhcpcd not ignoring source-based routes on linux
    * DHCP6: lastlease behavior after Confim non-response
    * Allow limited RLIMIT_FSIZE when dumping lease
    * IPv6: Avoid uninitialized ifp state when adding address
    * DHCPv6: Add support for sending Option 17 (VSIO)
    * Exit the timesyncd hook if not on systemd and not executable
    * Add route lifetime from Router Advertisement
    * revert e3c5de1
    * Fix using multiple enterprise IDs with vendclass (Option 124
    DHCP / Option 16 DHCPv6)
    * Update route if acquired time changes
    * Always send req for InfoRefreshTime option on Inform-Req
    * Increase max IPv4 clientid
    * Update build.yml to fix BSD builds

++++ docker-compose:

  - remove docker-compose-switch dependency
  - Update to version 2.33.0:
    * Important
  - This release introduce support for Bake to manage builds as
    an alternative to the internal buildkit client. This new
    feature can be enabled by setting COMPOSE_BAKE=1 variable.
    Bake will become the default builder in a future release.
    * Improvements
  - let user know bake is now supported by @ndeloof in #12524
  - support additional_context reference to another service by
    @ndeloof in #12485
  - add support for BUILDKIT_PROGRESS by @ndeloof in #12458
  - add --with-env flag to publish command by @glours in #12482
  - Update ls --quiet help description by @maxproske in #12541
  - Publish warn display env vars by @glours in #12486
    * Fixes
  - Fix bake support by @ndeloof in #12507
  - Update link in stats --help output by @maxproske in #12523
  - Properly handle "builtin" seccomp profile by @r-bk in #12478
  - manage watch applied to mulitple services by @ndeloof in
    [#12469]
    * Internal
  - use main branch for docs upstream validation workflow by
    @crazy-max in #12487
  - fix provenance for binaries and generate sbom by @crazy-max
    in #12479
  - add codeowners file by @glours in #12480
  - remove exit code per error type used by legacy metrics system
    by @ndeloof in #12502
  - Dockerfile: update golangci-lint to v1.63.4 by @thaJeztah in
    [#12546]
  - Full test coverage for compatibility cmd by @maxproske in
    [#12528]
  - don't send raw os.Args to opentelemetry but a pseudo command
    line by @ndeloof in #12530
  - add docker engine v28.x to the test-matrix by @thaJeztah in
    [#12539]
  - enable copyloopvar linter by @thaJeztah in #12542
  - go.mod: remove toolchain directive by @thaJeztah in #12551
    * Dependencies
  - bump buildx v0.20.1 by @ndeloof in #12488
  - bump docker to v27.5.1 by @ndeloof in #12491
  - bump compose-go v2.4.8 by @ndeloof in #12543
  - bump golang.org/x/sys from 0.28.0 to 0.30.0 by @dependabot in
    [#12529]
  - bump github.com/moby/term v0.5.2 by @thaJeztah in #12540
  - bump github.com/otiai10/copy from 1.14.0 to 1.14.1 by
    @dependabot in #12493
  - bump github.com/jonboulle/clockwork from 0.4.0 to 0.5.0 by
    @dependabot in #12430
  - bump github.com/spf13/pflag from 1.0.5 to 1.0.6 by
    @dependabot in #12548
  - bump golang.org/x/sync from 0.10.0 to 0.11.0 by @dependabot
    in #12547
  - bump gotest.tools/v3 from 3.5.1 to 3.5.2 by @dependabot in
    [#12549]

++++ guestfs-tools:

  - Update to version 1.53.6 (jsc#PED-8910)
    * build: Move baseline OCaml to 4.08
    * builder: add various templates for rhel and fedora
    * po-docs: A couple adjustments and updates

++++ kernel-default:

  - brd: defer automatic disk creation until module initialization
    succeeds (CVE-2024-56693 bsc#1235418).
  - commit 4ea5368
  - usb: xhci: Remove unused parameters of next_trb()
    (jsc#PED-10906).
  - commit 4ce0d38
  - xhci: Add Isochronous TRB fields to TRB tracer (jsc#PED-10906).
  - commit 62ff2a5
  - xhci: add helper to stop endpoint and wait for completion
    (jsc#PED-10906).
  - Refresh
    patches.suse/usb-xhci-Avoid-queuing-redundant-Stop-Endpoint-comma.patch.
  - commit 1863002
  - usb: Switch back to struct platform_driver::remove()
    (jsc#PED-10906).
  - commit 5d10743
  - mm: zswap: move allocations during CPU init outside the lock
    (git-fixes).
  - commit 6c847ee
  - usb: host: fix typo in the comment (jsc#PED-10906).
  - commit 1243816
  - mm: zswap: properly synchronize freeing resources during CPU
    hotunplug (bsc#1237029 CVE-2025-21693).
  - commit 91784aa
  - vfio/platform: check the bounds of read/write syscalls
    (bsc#1237045 CVE-2025-21687).
  - commit 8ac3968
  - net: sched: fix ets qdisc OOB Indexing (bsc#1237028
    CVE-2025-21692).
  - commit a3b6e33
  - ASoC: fsl_utils: Add function to constrain rates (jsc#PED-12016)
  - commit d9c4732
  - dt-bindings: clock: imx93: Add SPDIF IPG clk (jsc#PED-12016)
  - commit 1672b95
  - dt-bindings: clock: Add i.MX91 clock support (jsc#PED-12016)
  - commit 24a24f1
  - dt-bindings: clock: imx93: Drop IMX93_CLK_END macro definition (jsc#PED-12016)
  - commit 5c1986d
  - io_uring/rsrc: require cloned buffers to share accounting
    contexts (CVE-2025-21686 bsc#1237043).
  - commit 864eac2
  - cachestat: fix page cache statistics permission checking
    (bsc#1237032 CVE-2024-57950).
  - commit 751ac1a
  - ASoC: fsl_sai: Add sample rate constraint (jsc#PED-12016)
  - commit 6510a2e
  - usb: typec: tcpci: set local CC to Rd only when cc1/cc2 status is Rp (jsc#PED-12016)
  - commit 45143cb
  - tty: serial: fsl_lpuart: flush RX and TX FIFO when lpuart shutdown (jsc#PED-12016)
  - commit 1e6dbc5
  - tty: serial: fsl_lpuart: increase maximum uart_nr to 12 (jsc#PED-12016)
  - commit 33f1fe2
  - tty: serial: fsl_lpuart: add 7-bits format support on (jsc#PED-12016)
  - commit c193367
  - spi: spi-fsl-lpspi: support effective_speed_hz (jsc#PED-12016)
  - commit 4e04717
  - perf: imx9_perf: Introduce AXI filter version to refactor the driver (jsc#PED-12016)
  - commit e5aa649
  - perf: imx_perf: add support for i.MX91 platform (jsc#PED-12016)
  - commit ab04b10
  - nvmem: imx-ocotp-ele: set word length to 1 (jsc#PED-12016)
  - commit ac25b97
  - nvmem: imx-ocotp-ele: fix MAC address byte order (jsc#PED-12016)
  - commit 02edd36
  - nvmem: imx-ocotp-ele: fix reading from non zero offset (jsc#PED-12016)
  - commit d166349
  - nvmem: imx-ocotp-ele: simplify read beyond device check (jsc#PED-12016)
  - commit 764aad0
  - net: stmmac: imx: Use syscon_regmap_lookup_by_phandle_args (jsc#PED-12016)
  - commit 618e3d7
  - net: dwmac-imx: add imx93 clock input support in RMII mode (jsc#PED-12016)
  - commit bcac46a
  - net: dwmac-imx: Use helper rgmii_clock (jsc#PED-12016)
  - commit 792a263
  - net: phy: Add helper for mapping RGMII link speed to clock rate (jsc#PED-12016)
  - commit 9ebf4c7
  - net: stmmac: restructure the error path of stmmac_probe_config_dt() (jsc#PED-12016)
  - commit f9eed74
  - net: stmmac: Fix clock rate variables size (jsc#PED-12016)
  - commit c0ff972
  - net: fec: implement TSO descriptor cleanup (jsc#PED-12016)
  - commit 3b9cb06

++++ kernel-firmware-all:

  - Drop superfluous post scripts and Requires;
    this package doesn't need to treat post scripts by itself
  - Fix accidentally dropped buildreq-noarch

++++ kernel-rt:

  - brd: defer automatic disk creation until module initialization
    succeeds (CVE-2024-56693 bsc#1235418).
  - commit 4ea5368
  - usb: xhci: Remove unused parameters of next_trb()
    (jsc#PED-10906).
  - commit 4ce0d38
  - xhci: Add Isochronous TRB fields to TRB tracer (jsc#PED-10906).
  - commit 62ff2a5
  - xhci: add helper to stop endpoint and wait for completion
    (jsc#PED-10906).
  - Refresh
    patches.suse/usb-xhci-Avoid-queuing-redundant-Stop-Endpoint-comma.patch.
  - commit 1863002
  - usb: Switch back to struct platform_driver::remove()
    (jsc#PED-10906).
  - commit 5d10743
  - mm: zswap: move allocations during CPU init outside the lock
    (git-fixes).
  - commit 6c847ee
  - usb: host: fix typo in the comment (jsc#PED-10906).
  - commit 1243816
  - mm: zswap: properly synchronize freeing resources during CPU
    hotunplug (bsc#1237029 CVE-2025-21693).
  - commit 91784aa
  - vfio/platform: check the bounds of read/write syscalls
    (bsc#1237045 CVE-2025-21687).
  - commit 8ac3968
  - net: sched: fix ets qdisc OOB Indexing (bsc#1237028
    CVE-2025-21692).
  - commit a3b6e33
  - ASoC: fsl_utils: Add function to constrain rates (jsc#PED-12016)
  - commit d9c4732
  - dt-bindings: clock: imx93: Add SPDIF IPG clk (jsc#PED-12016)
  - commit 1672b95
  - dt-bindings: clock: Add i.MX91 clock support (jsc#PED-12016)
  - commit 24a24f1
  - dt-bindings: clock: imx93: Drop IMX93_CLK_END macro definition (jsc#PED-12016)
  - commit 5c1986d
  - io_uring/rsrc: require cloned buffers to share accounting
    contexts (CVE-2025-21686 bsc#1237043).
  - commit 864eac2
  - cachestat: fix page cache statistics permission checking
    (bsc#1237032 CVE-2024-57950).
  - commit 751ac1a
  - ASoC: fsl_sai: Add sample rate constraint (jsc#PED-12016)
  - commit 6510a2e
  - usb: typec: tcpci: set local CC to Rd only when cc1/cc2 status is Rp (jsc#PED-12016)
  - commit 45143cb
  - tty: serial: fsl_lpuart: flush RX and TX FIFO when lpuart shutdown (jsc#PED-12016)
  - commit 1e6dbc5
  - tty: serial: fsl_lpuart: increase maximum uart_nr to 12 (jsc#PED-12016)
  - commit 33f1fe2
  - tty: serial: fsl_lpuart: add 7-bits format support on (jsc#PED-12016)
  - commit c193367
  - spi: spi-fsl-lpspi: support effective_speed_hz (jsc#PED-12016)
  - commit 4e04717
  - perf: imx9_perf: Introduce AXI filter version to refactor the driver (jsc#PED-12016)
  - commit e5aa649
  - perf: imx_perf: add support for i.MX91 platform (jsc#PED-12016)
  - commit ab04b10
  - nvmem: imx-ocotp-ele: set word length to 1 (jsc#PED-12016)
  - commit ac25b97
  - nvmem: imx-ocotp-ele: fix MAC address byte order (jsc#PED-12016)
  - commit 02edd36
  - nvmem: imx-ocotp-ele: fix reading from non zero offset (jsc#PED-12016)
  - commit d166349
  - nvmem: imx-ocotp-ele: simplify read beyond device check (jsc#PED-12016)
  - commit 764aad0
  - net: stmmac: imx: Use syscon_regmap_lookup_by_phandle_args (jsc#PED-12016)
  - commit 618e3d7
  - net: dwmac-imx: add imx93 clock input support in RMII mode (jsc#PED-12016)
  - commit bcac46a
  - net: dwmac-imx: Use helper rgmii_clock (jsc#PED-12016)
  - commit 792a263
  - net: phy: Add helper for mapping RGMII link speed to clock rate (jsc#PED-12016)
  - commit 9ebf4c7
  - net: stmmac: restructure the error path of stmmac_probe_config_dt() (jsc#PED-12016)
  - commit f9eed74
  - net: stmmac: Fix clock rate variables size (jsc#PED-12016)
  - commit c0ff972
  - net: fec: implement TSO descriptor cleanup (jsc#PED-12016)
  - commit 3b9cb06

++++ libguestfs:

  - Update to version 1.55.4 (jsc#PED-8910)
    * appliance/init: Fix /usr/sbin symlinks in Fedora 42+
    * Various translation updates

++++ rpm:

  - make the rpm package not depend on libarchive
    * move the rpmuncompress tool to rpm-build
    * rewrite rpm2archive to not use libarchive for cpio/tar writing
    * new patch: rpm2archive.diff
  - revert buildroot macro setting that did more harm than good
  - add set_to_buildtime and set_to_source_date_epoch mtime policy
    support
    * new patch: mtime_policy_set.diff
  - drop unused 0001-Add-option-to-set-mtime-of-files-in-rpms.patch
    patch
  - do not output debug messages in rpmspec -q if a buildsystem is
    used
    * new patch: buildsys.diff

++++ libzypp:

  - Don't issue deprecated warnings if -DNDEBUG is set (bsc#1236983)
    Released libyui packages compile with -Werror=deprecated-declarations
    so we can't add deprecated warnings without breaking them.
  - make gcc15 happy (fixes #613)
  - version 17.36.1 (35)

++++ python-M2Crypto:

  - The real license is BSD 2-Clause, not MIT.

++++ qemu:

  - Fix bsc#1228343:
    * tests/acpi: q35: Update host address width in DMAR (bsc#1228343)
    * intel_iommu: Set default aw_bits to 48 starting from QEMU 9.2 (bsc#1228343)
    * tests/acpi: q35: allow DMAR acpi table changes (bsc#1228343)
  - Full boot order support (jsc#PED-958):
    * pc-bios: Update the s390 bios images with the recent changes (jsc#PED-958)
    * pc-bios/s390-ccw: Abort IPL on invalid loadparm (jsc#PED-958)
    * pc-bios/s390-ccw/netmain: Fix error messages with regards to the TFTP server (jsc#PED-958)
    * pc-bios/s390-ccw: Fix boot problem with virtio-net devices (jsc#PED-958)
    * pc-bios/s390-ccw/virtio: Add a function to reset a virtio device (jsc#PED-958)
    * hw/s390x: Fix crash that occurs when inspecting older versioned machines types (jsc#PED-958)
  - Update to latest upstream release, 9.2.1:
    The full list of changes are available at:
    https://lore.kernel.org/qemu-devel/qemu-stable-9.2.1-20250207102656@cover.tls.msk.ru/
    Highlights include:
    * 9pfs: fix regression regarding CVE-2023-2861
    * tcg: Reset free_temps before tcg_optimize
    * tcg/riscv: Fix StoreStore barrier generation
    * x86/loader: only patch linux kernels
    * roms: re-add edk2-basetools target
    * pc-bios: add missing riscv64 descriptor
    * hw/intc/arm_gicv3_its: Zero initialize local DTEntry etc structs
    * meson.build: Disallow libnfs v6 to fix the broken macOS build
    * target/i386: Reset TSCs of parked vCPUs too on VM reset
    * hw/intc/riscv_aplic: Fix APLIC in_clrip and clripnum write emulation
    * s390x/s390-virtio-ccw: don't crash on weird RAM sizes
    * target/loongarch: Use actual operand size with vbsrl check
    * docs: Correct '-runas' and '-fsdev/-virtfs proxy' indentation
    * docs: Correct release of TCG trace-events removal
    * target/i386/cpu: Fix notes for CPU models
    * migration/multifd: Fix compile error caused by page_size usage
    * migration/multifd: Fix compat with QEMU < 9.0
    * migration: Add more error handling to analyze-migration.py
    * migration: Remove unused argument in vmsd_desc_field_end
    * migration: Fix parsing of s390 stream
    * s390x: Fix CSS migration
    * migration: Rename vmstate_info_nullptr
    * ...

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20250211 release (bsc#1237096)
  - Security updates for INTEL-SA-01166 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01166.html
    * CVE-2024-31068: Improper Finite State Machines (FSMs) in Hardware
    Logic for some Intel Processors may allow privileged user to
    potentially enable denial of service via local access.
  - Security updates for INTEL-SA-01213 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01213.html
    * CVE-2024-36293: A potential security vulnerability in some Intel
    Software Guard Extensions (Intel SGX) Platforms may allow denial
    of service. Intel is releasing microcode updates to mitigate this
    potential vulnerability.
  - Security updates for INTEL-SA-01139 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01139.html
    * not clear which CVEs are fixed here, and which are in UEFI BIOS updates.
  - Security updates for INTEL-SA-01228 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01228.html
    * CVE-2024-39355: A potential security vulnerability in some
    13th and 14th Generation Intel Core Processors may allow denial
    of service. Intel is releasing microcode and UEFI reference code
    updates to mitigate this potential vulnerability.
  - Security updates for INTEL-SA-01194 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01194.html
    * CVE-2024-37020: A potential security vulnerability in the Intel
    Data Streaming Accelerator (Intel DSA) for some Intel Xeon Processors
    may allow denial of service. Intel is releasing software updates to
    mitigate this potential vulnerability.
  - Update for functional issues. Refer to Intel Core Ultra Processor https://cdrdv2.intel.com/v1/dl/getContent/792254 for details.
  - Update for functional issues. Refer to 13th/14th Generation Intel Core Processor Specification Update https://cdrdv2.intel.com/v1/dl/getContent/740518 for details.
  - Update for functional issues. Refer to 12th Generation Intel Core Processor Family https://cdrdv2.intel.com/v1/dl/getContent/682436 for details.
  - Update for functional issues. Refer to 11th Gen Intel Core Processor Specification Update https://cdrdv2.intel.com/v1/dl/getContent/631123 for details.
  - Update for functional issues. Refer to 8th and 9th Generation Intel Core Processor Family Spec Update https://cdrdv2.intel.com/v1/dl/getContent/337346 for details.
  - Update for functional issues. Refer to 5th Gen Intel Xeon Scalable Processors Specification Update https://cdrdv2.intel.com/v1/dl/getContent/793902 for details.
  - Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update https://cdrdv2.intel.com/v1/dl/getContent/772415 for details.
  - Update for functional issues. Refer to 3rd Generation Intel Xeon Processor Scalable Family Specification Update https://cdrdv2.intel.com/v1/dl/getContent/637780 for details.
  - Update for functional issues. Refer to Intel Xeon D-2700 Processor Specification Update https://cdrdv2.intel.com/v1/dl/getContent/714071 for details.
  - Update for functional issues. Refer to Intel Xeon E-2300 Processor Specification Update https://cdrdv2.intel.com/v1/dl/getContent/709192 for details.
  - Update for functional issues. Refer to Intel Xeon 6700-Series Processor Specification Update https://cdrdv2.intel.com/v1/dl/getContent/820922 for details.
  - Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series https://cdrdv2.intel.com/v1/dl/getContent/764616 for details
    [#]## New Platforms
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | SRF-SP         | C0       | 06-af-03/01 |          | 03000330 | Xeon 6700-Series Processors with E-Cores
    [#]## Updated Platforms
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ADL            | C0       | 06-97-02/07 | 00000037 | 00000038 | Core Gen12
    | ADL            | H0       | 06-97-05/07 | 00000037 | 00000038 | Core Gen12
    | ADL            | L0       | 06-9a-03/80 | 00000435 | 00000436 | Core Gen12
    | ADL            | R0       | 06-9a-04/80 | 00000435 | 00000436 | Core Gen12
    | ADL-N          | N0       | 06-be-00/19 | 0000001a | 0000001c | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    | AZB            | A0/R0    | 06-9a-04/40 | 00000007 | 00000009 | Intel(R) Atom(R) C1100
    | CFL-H          | R0       | 06-9e-0d/22 | 00000100 | 00000102 | Core Gen9 Mobile
    | CFL-H/S/E3     | U0       | 06-9e-0a/22 | 000000f8 | 000000fa | Core Gen8 Desktop, Mobile, Xeon E
    | EMR-SP         | A0       | 06-cf-01/87 | 21000283 | 21000291 | Xeon Scalable Gen5
    | EMR-SP         | A1       | 06-cf-02/87 | 21000283 | 21000291 | Xeon Scalable Gen5
    | ICL-D          | B0       | 06-6c-01/10 | 010002b0 | 010002c0 | Xeon D-17xx, D-27xx
    | ICX-SP         | Dx/M1    | 06-6a-06/87 | 0d0003e7 | 0d0003f5 | Xeon Scalable Gen3
    | RPL-E/HX/S     | B0       | 06-b7-01/32 | 0000012b | 0000012c | Core Gen13/Gen14
    | RPL-H/P/PX 6+8 | J0       | 06-ba-02/e0 | 00004123 | 00004124 | Core Gen13
    | RPL-HX/S       | C0       | 06-bf-02/07 | 00000037 | 00000038 | Core Gen13/Gen14
    | RPL-U 2+8      | Q0       | 06-ba-03/e0 | 00004123 | 00004124 | Core Gen13
    | RPL-S          | H0       | 06-bf-05/07 | 00000037 | 00000038 | Core Gen13/Gen14
    | RKL-S          | B0       | 06-a7-01/02 | 00000062 | 00000063 | Core Gen11
    | SPR-HBM        | Bx       | 06-8f-08/10 | 2c000390 | 2c0003e0 | Xeon Max
    | SPR-SP         | E4/S2    | 06-8f-07/87 | 2b000603 | 2b000620 | Xeon Scalable Gen4
    | SPR-SP         | E5/S3    | 06-8f-08/87 | 2b000603 | 2b000620 | Xeon Scalable Gen4
    | TWL            | N0       | 06-be-00/19 | 0000001a | 0000001c | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    [#]## New Disclosures Updated in Prior Releases
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | CFL-H/S        | P0       | 06-9e-0c/22 | 000000f6 | 000000f8 | Core Gen9

++++ zypper:

  - Let zypper dup fail in case of (temporarily) unaccessible repos
    (bsc#1228434, bsc#1236939, fixes #446)
  - version 1.14.84

------------------------------------------------------------------
------------------  2025-2-11  -  Feb 11 2025  -------------------
------------------------------------------------------------------

++++ aardvark-dns:

  - Update to version 1.14.0:
    * Release v1.14.0
    * release notes for v1.14.0
    * update release notes from v1.13.1
    * run cargo update
    * fix lint issues with rust 1.84
    * chore(deps): update dependency containers/automation_images to v20250131
    * fix(deps): update rust crate clap to ~4.5.28
    * fix(deps): update rust crate log to 0.4.25
    * fix(deps): update rust crate tokio to 1.43.0
    * chore(deps): update dependency containers/automation_images to v20250107
    * fix(deps): update rust crate clap to ~4.5.23
    * fix(deps): update rust crate libc to 0.2.169
    * fix(deps): update hickory-dns monorepo to 0.24.2
    * Cargo.lock: bump some versions
    * run cargo update
    * cargo: set rust-version
    * fix(deps): update rust crate clap to ~4.5.21
    * fix(deps): update rust crate libc to 0.2.167
    * OWNERS: remove edsantiago
    * fix(deps): update rust crate libc to 0.2.165
    * fix(deps): update rust crate libc to 0.2.164
    * chore(deps): update dependency containers/automation_images to v20241107
    * fix(deps): update rust crate tokio to 1.41.1
    * fix(deps): update rust crate libc to 0.2.162
    * test: make jq query work on centos stream 9
    * [skip-ci] Packit: disable osh-diff-scan
    * support ipv6 link local addresses in resolv.conf
    * [skip-ci] Packit: enable c9s downstream updates
    * [skip-ci] TMT: install builddeps downstream
    * [skip-ci] RPM: cleanup changelog conditionals
    * [skip-ci] Packit/TMT: idiomatic repo addition
    * [skip-ci] Packit: Remove epel jobs
    * tmt: install dnsmasq dependency
    * Bump to 1.14.0-dev

++++ python-kiwi:

  - The ubuntu 20.04 github runner is closing down
    Make sure to move to another runner for workloads which
    still uses ubuntu 20.04

++++ librsvg:

  - Update to version 2.59.90 (Unstable):
    + Basic support for the dominant-baseline property.
    + Report errors correctly from the parsers for attribute values.
    + Slightly improved test coverage.
    + Don't use defined() in C macro definitions, since it is not
    portable.
    + Parse the white-space property. It is not processed yet; this
    will come after the Outreachy internship.
    + Documentation fixes.
    + Many build fixes.
    + Improvements for cross builds.
    + Fix CRLF characters in Python sources.

++++ kdump:

  - upgrade to version 2.0.16:
    * fix KDUMP_AUTO_RESIZE (bsc#1236921)
    * dracut: fix filtering ro keys in kdump_bond_config (bsc#1233137)
    * spec: add dependency on ethtool
    * allow negative KDUMP_KEEP_OLD_DUMPS (bsc#1234845)

++++ kernel-default:

  - mmc: pwrseq_simple: Handle !RESET_CONTROLLER properly (jsc#PED-12016)
  - commit e5cd33c
  - mmc: pwrseq_simple: add support for one reset control (jsc#PED-12016)
  - commit 30494ea
  - irqchip/gic-v3: Handle CPU_PM_ENTER_FAILED correctly (jsc#PED-12016)
  - commit de54886
  - i2c: imx-lpi2c: make controller available until the system enters (jsc#PED-12016)
  - commit 588e6b2
  - i2c: imx-lpi2c: add target mode support (jsc#PED-12016)
  - commit 9414869
  - i2c: imx-lpi2c: add eDMA mode support for LPI2C (jsc#PED-12016)
  - commit 07d963c
  - s390/fpu: Add fpc exception handler / remove fixup section again
    (git-fixes bsc#1237061).
  - commit 65e32a8
  - s390/pci: Fix SR-IOV for PFs initially in standby (git-fixes
    bsc#1237059).
  - commit f0ee871
  - s390/topology: Improve topology detection (bsc#1236996).
  - commit 06dc0b0
  - clk: imx: Apply some clks only for i.MX93 (jsc#PED-12016)
  - commit 0f650e5
  - clk: imx93: Add IMX93_CLK_SPDIF_IPG clock (jsc#PED-12016)
  - commit 073d7ef
  - clk: imx: add i.MX91 clk (jsc#PED-12016)
  - commit 46b8cd9
  - clk: imx93: Move IMX93_CLK_END macro to clk driver (jsc#PED-12016)
  - commit 890578b
  - s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS
    (git-fixes bsc#1237054).
  - commit 79eba3a
  - seccomp: Stub for !CONFIG_SECCOMP (git-fixes bsc#1237053).
  - commit b92853d
  - KVM: s390: vsie: fix some corner-cases when grabbing vsie pages
    (git-fixes bsc#1237049).
  - commit d4d35a7
  - soc: imx: Add SoC device register for i.MX9 (jsc#PED-12016)
  - commit 6e43782
  - soc: imx8m: Use devm_* to simplify probe failure handling (jsc#PED-12016)
  - commit e0205ec
  - soc: imx8m: Remove global soc_uid (jsc#PED-12016)
  - commit fab4815
  - EDAC/fsl_ddr: Add support for i.MX9 DDR controller (jsc#PED-12016)
  - commit df25446
  - EDAC/fsl_ddr: Fix bad bit shift operations (jsc#PED-12016)
  - commit ce70346
  - EDAC/fsl_ddr: Move global variables into struct fsl_mc_pdata (jsc#PED-12016)
  - commit baa1744
  - EDAC/fsl_ddr: Pass down fsl_mc_pdata in ddr_in32() and ddr_out32() (jsc#PED-12016)
  - commit 4f4af2c
  - net/smc: support ipv4 mapped ipv6 addr client for smc-r v2
    (bsc#1236995).
  - commit a6e1ba4
  - x86/Documentation: Update algo in init_size description of
    boot protocol (git-fixes).
  - commit 9166589
  - util_macros.h: fix/rework find_closest() macros (git-fixes).
  - commit 7e910c6
  - netlink: typographical error in nlmsg_type constants definition
    (git-fixes).
  - commit 0e6f2bb
  - irqchip/gic-v3-its: Don't enable interrupts in
    its_irq_set_vcpu_affinity() (CVE-2024-57949 bsc#1236950).
  - commit 081a1c9
  - PM: sleep: core: Restrict power.set_active propagation
    (git-fixes).
  - commit ae91759
  - HID: hid-steam: Don't use cancel_delayed_work_sync in IRQ
    context (git-fixes).
  - HID: hid-steam: Move hidraw input (un)registering to work
    (git-fixes).
  - HID: hid-thrustmaster: fix stack-out-of-bounds read in
    usb_check_int_endpoints() (git-fixes).
  - HID: multitouch: Add NULL check in mt_input_configured
    (git-fixes).
  - HID: winwing: Add NULL check in winwing_init_led() (git-fixes).
  - pinctrl: pinconf-generic: Print unsigned value if a format is
    registered (git-fixes).
  - pinctrl: cy8c95x0: Respect IRQ trigger settings from firmware
    (git-fixes).
  - pinctrl: cy8c95x0: Rename PWMSEL to SELPWM (git-fixes).
  - pinctrl: cy8c95x0: Enable regmap locking for debug (git-fixes).
  - pinctrl: cy8c95x0: Avoid accessing reserved registers
    (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - HID: hid-steam: Don't use cancel_delayed_work_sync in IRQ
    context (git-fixes).
  - HID: hid-steam: Move hidraw input (un)registering to work
    (git-fixes).
  - HID: hid-thrustmaster: fix stack-out-of-bounds read in
    usb_check_int_endpoints() (git-fixes).
  - HID: multitouch: Add NULL check in mt_input_configured
    (git-fixes).
  - HID: winwing: Add NULL check in winwing_init_led() (git-fixes).
  - pinctrl: pinconf-generic: Print unsigned value if a format is
    registered (git-fixes).
  - pinctrl: cy8c95x0: Respect IRQ trigger settings from firmware
    (git-fixes).
  - pinctrl: cy8c95x0: Rename PWMSEL to SELPWM (git-fixes).
  - pinctrl: cy8c95x0: Enable regmap locking for debug (git-fixes).
  - pinctrl: cy8c95x0: Avoid accessing reserved registers
    (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - commit 99e9fb4
  - netdev: prevent accessing NAPI instances from another namespace
    (jsc#PED-12085).
  - netdev-genl: Hold rcu_read_lock in napi_set (jsc#PED-12085).
  - commit f11f99b
  - scsi: storvsc: Set correct data length for sending SCSI command
    without payload (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - scsi: storvsc: Set correct data length for sending SCSI command
    without payload (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - commit 272f93e

++++ kernel-firmware-amdgpu:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-ath10k:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-ath11k:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-ath12k:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-atheros:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-bluetooth:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-bnx2:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-brcm:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-chelsio:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-dpaa2:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-i915:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file
  - Update aliases
  - Update to version 20250210 (git commit 5bc5868b7ee5):
    * i915: Update Xe2LPD DMC to v2.28

++++ kernel-firmware-intel:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-iwlwifi:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file
  - Update aliases

++++ kernel-firmware-liquidio:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-marvell:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-media:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-mediatek:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file
  - Update aliases

++++ kernel-firmware-mellanox:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-mwifiex:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-network:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-nfp:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-nvidia:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-platform:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file
  - Update aliases

++++ kernel-firmware-prestera:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-qcom:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-qlogic:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-radeon:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-realtek:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-serial:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-sound:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file
  - Update to version 20250210 (git commit 5bc5868b7ee5):
    * ASoC: tas2781: Add regbin firmware by index for single device

++++ kernel-firmware-ti:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-ueagle:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-firmware-usb-network:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ kernel-rt:

  - mmc: pwrseq_simple: Handle !RESET_CONTROLLER properly (jsc#PED-12016)
  - commit e5cd33c
  - mmc: pwrseq_simple: add support for one reset control (jsc#PED-12016)
  - commit 30494ea
  - irqchip/gic-v3: Handle CPU_PM_ENTER_FAILED correctly (jsc#PED-12016)
  - commit de54886
  - i2c: imx-lpi2c: make controller available until the system enters (jsc#PED-12016)
  - commit 588e6b2
  - i2c: imx-lpi2c: add target mode support (jsc#PED-12016)
  - commit 9414869
  - i2c: imx-lpi2c: add eDMA mode support for LPI2C (jsc#PED-12016)
  - commit 07d963c
  - s390/fpu: Add fpc exception handler / remove fixup section again
    (git-fixes bsc#1237061).
  - commit 65e32a8
  - s390/pci: Fix SR-IOV for PFs initially in standby (git-fixes
    bsc#1237059).
  - commit f0ee871
  - s390/topology: Improve topology detection (bsc#1236996).
  - commit 06dc0b0
  - clk: imx: Apply some clks only for i.MX93 (jsc#PED-12016)
  - commit 0f650e5
  - clk: imx93: Add IMX93_CLK_SPDIF_IPG clock (jsc#PED-12016)
  - commit 073d7ef
  - clk: imx: add i.MX91 clk (jsc#PED-12016)
  - commit 46b8cd9
  - clk: imx93: Move IMX93_CLK_END macro to clk driver (jsc#PED-12016)
  - commit 890578b
  - s390: Add '-std=gnu11' to decompressor and purgatory CFLAGS
    (git-fixes bsc#1237054).
  - commit 79eba3a
  - seccomp: Stub for !CONFIG_SECCOMP (git-fixes bsc#1237053).
  - commit b92853d
  - KVM: s390: vsie: fix some corner-cases when grabbing vsie pages
    (git-fixes bsc#1237049).
  - commit d4d35a7
  - soc: imx: Add SoC device register for i.MX9 (jsc#PED-12016)
  - commit 6e43782
  - soc: imx8m: Use devm_* to simplify probe failure handling (jsc#PED-12016)
  - commit e0205ec
  - soc: imx8m: Remove global soc_uid (jsc#PED-12016)
  - commit fab4815
  - EDAC/fsl_ddr: Add support for i.MX9 DDR controller (jsc#PED-12016)
  - commit df25446
  - EDAC/fsl_ddr: Fix bad bit shift operations (jsc#PED-12016)
  - commit ce70346
  - EDAC/fsl_ddr: Move global variables into struct fsl_mc_pdata (jsc#PED-12016)
  - commit baa1744
  - EDAC/fsl_ddr: Pass down fsl_mc_pdata in ddr_in32() and ddr_out32() (jsc#PED-12016)
  - commit 4f4af2c
  - net/smc: support ipv4 mapped ipv6 addr client for smc-r v2
    (bsc#1236995).
  - commit a6e1ba4
  - x86/Documentation: Update algo in init_size description of
    boot protocol (git-fixes).
  - commit 9166589
  - util_macros.h: fix/rework find_closest() macros (git-fixes).
  - commit 7e910c6
  - netlink: typographical error in nlmsg_type constants definition
    (git-fixes).
  - commit 0e6f2bb
  - irqchip/gic-v3-its: Don't enable interrupts in
    its_irq_set_vcpu_affinity() (CVE-2024-57949 bsc#1236950).
  - commit 081a1c9
  - PM: sleep: core: Restrict power.set_active propagation
    (git-fixes).
  - commit ae91759
  - HID: hid-steam: Don't use cancel_delayed_work_sync in IRQ
    context (git-fixes).
  - HID: hid-steam: Move hidraw input (un)registering to work
    (git-fixes).
  - HID: hid-thrustmaster: fix stack-out-of-bounds read in
    usb_check_int_endpoints() (git-fixes).
  - HID: multitouch: Add NULL check in mt_input_configured
    (git-fixes).
  - HID: winwing: Add NULL check in winwing_init_led() (git-fixes).
  - pinctrl: pinconf-generic: Print unsigned value if a format is
    registered (git-fixes).
  - pinctrl: cy8c95x0: Respect IRQ trigger settings from firmware
    (git-fixes).
  - pinctrl: cy8c95x0: Rename PWMSEL to SELPWM (git-fixes).
  - pinctrl: cy8c95x0: Enable regmap locking for debug (git-fixes).
  - pinctrl: cy8c95x0: Avoid accessing reserved registers
    (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - HID: hid-steam: Don't use cancel_delayed_work_sync in IRQ
    context (git-fixes).
  - HID: hid-steam: Move hidraw input (un)registering to work
    (git-fixes).
  - HID: hid-thrustmaster: fix stack-out-of-bounds read in
    usb_check_int_endpoints() (git-fixes).
  - HID: multitouch: Add NULL check in mt_input_configured
    (git-fixes).
  - HID: winwing: Add NULL check in winwing_init_led() (git-fixes).
  - pinctrl: pinconf-generic: Print unsigned value if a format is
    registered (git-fixes).
  - pinctrl: cy8c95x0: Respect IRQ trigger settings from firmware
    (git-fixes).
  - pinctrl: cy8c95x0: Rename PWMSEL to SELPWM (git-fixes).
  - pinctrl: cy8c95x0: Enable regmap locking for debug (git-fixes).
  - pinctrl: cy8c95x0: Avoid accessing reserved registers
    (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - commit 99e9fb4
  - netdev: prevent accessing NAPI instances from another namespace
    (jsc#PED-12085).
  - netdev-genl: Hold rcu_read_lock in napi_set (jsc#PED-12085).
  - commit f11f99b
  - scsi: storvsc: Set correct data length for sending SCSI command
    without payload (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - scsi: storvsc: Set correct data length for sending SCSI command
    without payload (git-fixes).
  - jiffies: Cast to unsigned long in secs_to_jiffies() conversion
    (git-fixes).
  - commit 272f93e

++++ openssl-3:

  - Update to 3.2.4:
    * Fixed RFC7250 handshakes with unauthenticated servers don't abort as
    expected. [bsc#1236599, CVE-2024-12797]
    * Fixed timing side-channel in ECDSA signature computation. [CVE-2024-13176]
    * Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic
    curve parameters. [CVE-2024-9143]
  - Remove patch openssl-CVE-2024-13176.patch
  - Rebase patches:
    * openssl-3-add_EVP_DigestSqueeze_api.patch
    * openssl-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch
    * openssl-FIPS-RSA-encapsulate.patch
    * openssl-disable-fipsinstall.patch

++++ openssl:

  - Update to 3.2.4

++++ liburing:

  - disable even more tests

++++ netavark:

  - Update to version 1.14.0:
    * Release v1.14.0
    * release notes for v1.14.0
    * update release notes from v1.13.1
    * run cargo update
    * Finalize firewalld port forwarding support
    * chore(deps): update rust crate once_cell to 1.20.3
    * fix(deps): update rust crate rand to 0.9.0
    * Add handling for firewalld's StrictForwardPorts setting
    * fix lint issues wirh rust 1.84
    * chore(deps): update dependency containers/automation_images to v20250131
    * chore(deps): update rust crate tempfile to 3.16.0
    * rename macvlan_dhcp.rs to dhcp.rs
    * bridge: only allow dhcp with unmanaged mode
    * bridge: support DHCP ipam driver
    * fix(deps): update rust crate ipnet to 2.11.0
    * fix(deps): update rust crate serde_json to 1.0.136
    * fix(deps): update rust crate log to 0.4.24
    * bridge: add vlan support
    * fix(deps): update rust crate tokio to 1.43.0
    * fix(deps): update rust crate serde_json to 1.0.135
    * New VM Images
    * fix(deps): update rust crate clap to ~4.5.23
    * chore(deps): update rust crate tempfile to 3.15.0
    * fix(deps): update rust crate nispor to 1.2.22
    * fix(deps): update rust crate serde_json to 1.0.134
    * fix(deps): update rust crate env_logger to 0.11.6
    * Add container hostname to DHCP requests and use container id as client id
    * fix(deps): update rust crate mozim to 0.2.5
    * generate protobuf in OUT_DIR
    * fix(deps): update rust crate tower to 0.5.2
    * Cargo.lock: bump some versions
    * run cargo update
    * cargo: set rust-version
    * fix new rust 1.83 lint errors
    * OWNERS: remove edsantiago
    * setup: on av errors cleanup again
    * nftables: add daddr match to port forward jump rule
    * network: bridge: don't change forwarding sysctl for internal bridges
    * network: bridge: add support for unmanaged mode
    * test-dhcp: remove deprecated ifconfig/brctl commands
    * fix new rust 1.82 lint errors
    * update ci images
    * fix(deps): update rust crate serde_json to 1.0.133
    * network: bridge: add support for host_interface_name option
    * network: add support for network-specific options
    * fix(deps): update rust crate ipnet to 2.10.1
    * chore(deps): update rust crate tempfile to 3.14.0
    * fix(deps): update rust crate tokio to 1.41.1
    * fix(deps): update rust crate anyhow to 1.0.93
    * fix(deps): update rust crate url to 2.5.3
    * [skip-ci] RPM: cleanup changelog conditionals
    * fix(deps): update rust crate anyhow to 1.0.92
    * Bump to 1.14.0-dev

++++ rebootmgr:

  - Update to version 3.0+git20250211.a56a554:
    * rebootmgr.service: fix Type=notify
  - Readd compat symlink of rebootmgrctl for tukit

++++ ucode-amd:

  - Fix license description for kernel-firmware-tools package
  - Clean up spec file

++++ vim:

  - update to 9.1.1101
    * insexpand.c hard to read
    * tests: Test_log_nonexistent only works on Linux
    * Update base-syntax, improve variable matching
    * Vim9: import with extends may crash
    * leaking memory with completing multi lines
    * --log with non-existent path causes a crash
    * if_perl: Perl 5.38 adds new symbols causing link failure
    * tests: matchparen plugin test wrongly named
    * Vim9: problem finding implemented method in type hierarchy
    * runtime(qf): Update syntax file, match second delimiter
    * tests: output of test ...win32_ctrl_z depends on python version
    * tests: fix expected return code for python 3.13 on Windows
    * tests: timeout might be a bit too small
    * tests: test_terminwscroll_topline2 unreliable
    * tests: No check when tests are run under Github actions
    * tests: plugin tests are named inconsistently
    * Vim9: import with extends may crash
    * completion doesn't work with multi lines
    * filetype: cmmt files are not recognized
    * Unable to persistently ignore events in a window and its buffers
    * improve syntax highlighting
    * setreg() doesn't correctly handle mbyte chars in blockwise mode
    * unexpected DCS responses may cause out of bounds reads
    * has('bsd') is true for GNU/Hurd
    * filetype: Mill files are not recognized
    * GUI late startup leads to uninitialized scrollbars
    * Add support for lz4 to tar & gzip plugin
    * Terminal ansi colors off by one after tgc reset
    * included syntax items do not understand contains=TOP
    * vim_strnchr() is strange and unnecessary
    * Vim9: len variable not used in compile_load()
    * runtime(vim): Update base-syntax, match :debuggreedy count prefix
    * Strange error when heredoc marker starts with "trim"
    * tests: test_compiler fails on Windows without Maven
    * 'diffopt' "linematch" cannot be used with {n} less than 10
    * args missing after failing to redefine a function
    * Cannot control cursor positioning of getchar()
    * preinsert text completions not deleted with <C-W>/<C-U>
    * getchar() can't distinguish between C-I and Tab
    * tests: Test_termwinscroll_topline2 fails on MacOS
    * heap-use-after-free and stack-use-after-scope with :14verbose
    * no digraph for "Approaches the limit"
    * not possible to use plural forms with gettext()
    * too many strlen() calls in userfunc.c
    * terminal: E315 when dragging the terminal with the mouse
    * runtime(openPlugin): fix unclosed parenthesis in GetWordUnderCursor()
    * runtime(doc): Tweak documentation style a bit
    * tests: test_glvs fails when unarchiver not available
    * Vim always enables 'termguicolors' in a terminal
    * completion: input text deleted with preinsert when adding leader
    * translation(sr): Missing Serbian translation for the tutor
    * Superfluous cleanup steps in test_ins_complete.vim
    * runtime(netrw): correct wrong version check
    * Vim doesn't highlight to be inserted text when completing
    * runtime(netrw): upstream snapshot of v176
    * runtime(dist/vim9): fix regressions in dist#vim9#Open
    * runtime(hyprlang): fix string recognition
    * make install fails because of a missing dependency
    * runtime(asm): add byte directives to syntax script
    * Vim doesn't work well with TERM=xterm-direct
    * runtime(filetype): commit 99181205c5f8284a3 breaks V lang detection
    * runtime: decouple Open and Launch commands and gx mapping from netrw
    * "nosort" enables fuzzy filtering even if "fuzzy" isn't in 'completeopt'
    * runtime(just): fix typo in syntax file
    * runtime(filetype): Improve Verilog detection by checking for modules definition
    * tests: off-by-one error in CheckCWD in test_debugger.vim
    * tests: no support for env variables when running Vim in terminal
    * too many strlen() calls in os_unix.c
    * insert-completed items are always sorted
    * crash after scrolling and pasting in silent Ex mode
    * Makefiles uses non-portable syntax
    * fuzzymatching doesn't prefer matching camelcase
    * filetype: N-Tripels and TriG files are not recognized
    * Vim9: Patch 9.1.1014 causes regressions
    * translation(sr): Update Serbian messages translation

++++ virt-manager:

  - Spec file modifications for SLES16 and some cleanups
    virt-manager.spec
  - Add additional detection code for SLES 16 media (bsc#1236252)
    virtinst-add-sle16-detection-support.patch

------------------------------------------------------------------
------------------  2025-2-10  -  Feb 10 2025  -------------------
------------------------------------------------------------------

++++ canutils:

  - version update to 2025.01
    * Support of new kernel features:
    * Full CAN XL support for candump, canplayer, cangen, log2asc,
    asc2log, lib
    * cangen: support socket priority
    * Improvements and features:
    * ISOBUS (ISO11783-13) File Server Interface (isobusfs-srv,
    isobusfs-cli)
    * Add j1939_datatime_cli
    * cansequence: allow to bind on "any" interface
    * cansequence: add support to send and receive CAN-FD
    * canfdtest: add support for loopback testing
    * isotpdump: option to capture functional addressing traffic
    * isotpdump: add color support for functional addressing traffic
    * isotprecv: add option to enable dynamic flow control
    parameters (Linux 6.9+)
    * cangen: add missing long CAN frame view for len8_dlc and eff
    * canbusload: add auto detection of CAN interfaces
    * canbusload: show RX/TX direction in bargraph
    * canbusload: support busload statistic and busload visualization

++++ fuse-overlayfs:

  - version update to 1.14
    * isolate security xattrs for STAT_OVERRIDE_CONTAINERS. Prefix all security xattrs with XATTR_CONTAINERS_OVERRIDE_PREFIX.
    * prefer user.containers.override_stat over user.fuseoverlayfs.
    * do not force -1 for owner overriding extended attributes. Otherwise the value is written to the override extended attribute.
    * fix file owner retrieval for chmod.
    * honor umask with xattr_permissions.
    * honor mode for devices with xattr_permissions.
    * propagate extended attributes permissions with copyup.

++++ glibc:

  - Use rpm.execute when available (bsc#1236869)

++++ kernel-default:

  - iommu: Manage driver probe deferral better (bsc#1235032).
  - iommu/arm-smmu-v3: Clean up more on probe failure (bsc#1235032).
  - iommu/arm-smmu: Make instance lookup robust (bsc#1235032,
    CVE-2024-56568).
  - commit 029e52d

++++ kernel-firmware-bluetooth:

  - Update to version 20250208 (git commit 4ccb15a9dbfa):
    * WHENCE: split generic QCA section into USB and serial sections
    * rtl_bt: Update RTL8852B BT USB FW to 0x0474_842D

++++ kernel-rt:

  - iommu: Manage driver probe deferral better (bsc#1235032).
  - iommu/arm-smmu-v3: Clean up more on probe failure (bsc#1235032).
  - iommu/arm-smmu: Make instance lookup robust (bsc#1235032,
    CVE-2024-56568).
  - commit 029e52d

++++ gcc15:

  - Update to GCC trunk head, 15.0.1+git7452

++++ gpgme:

  - Update to 1.24.2:
    * Fix regression for RSA in gpgme_pubkey_algo_string
    * Prevent failing tests after 2027-05-15
  - drop python313.patch, is included

++++ ncurses:

  - Add ncurses patch 20250208
    + change etip.h.in to include either/both of <new> and <exception>,
    needed for another old BSD.
    + update st (report by Alexander Kashpir) -TD
    + add note for ghostty 1.1.0 -TD
    + fix a few issues found with coverity.
  - Correct offset of patches
    * ncurses-5.9-ibm327x.dif
    * ncurses-6.4.dif
    * ncurses-6.5-ghostty.dif

++++ libzypp:

  - Drop zypp-CheckAccessDeleted in favor of 'zypper ps'.
  - Fix Repoverification plugin not being executed (fixes #614)
  - Refresh: Fetch the master index file before key and signature
    (bsc#1236820)
  - Allow libzypp to compile with C++20.
  - Deprecate RepoReports we do not trigger.
  - version 17.36.0 (35)

++++ python-anyio:

  - Update to 4.8.0:
    * Added experimental support for running functions in
    subinterpreters on Python 3.13 and later
    * Added support for the copy(), copy_into(), move() and move_into()
    methods in anyio.Path, available in Python 3.14
    * Changed TaskGroup on asyncio to always spawn tasks non-eagerly,
    even if using a task factory created
    via asyncio.create_eager_task_factory(), to preserve expected
    Trio-like task scheduling semantics (PR by @agronholm and @graingert)
    * Configure SO_RCVBUF, SO_SNDBUF and TCP_NODELAY on the selector
    thread waker socket pair (this should improve the performance of
    wait_readable() and wait_writable() when using the ProactorEventLoop)
    (#836; PR by @graingert)
    * Fixed AssertionError when using nest-asyncio (#840)
    * Fixed return type annotation of various context managers'
    __exit__ method (#847; PR by @Enegg)
  - from 4.7.0:
    * Updated TaskGroup to work with asyncio's eager task factories (#764)
    * Added the wait_readable() and wait_writable() functions which will
    accept an object with a .fileno() method or an integer handle, and
    deprecated their now obsolete versions (wait_socket_readable() and
    wait_socket_writable()) (PR by @davidbrochart)
    * Changed EventAdapter (an Event with no bound async backend) to allow
    set() to work even before an async backend is bound to it (#819)
    * Added support for wait_readable() and wait_writable() on
    ProactorEventLoop (used on asyncio + Windows by default)
    * Fixed a misleading ValueError in the context of DNS failures
    (#815; PR by @graingert)
    * Fixed the return type annotations of readinto() and readinto1()
    methods in the anyio.AsyncFile class (#825)
    * Fixed TaskInfo.has_pending_cancellation() on asyncio returning
    false positives in cleanup code on Python >= 3.11
    (#832; PR by @gschaffner)
    * Fixed cancelled cancel scopes on asyncio calling
    asyncio.Task.uncancel when propagating a CancelledError on exit
    to a cancelled parent scope (#790; PR by @gschaffner)

++++ sysvinit:

  - Update to sysvinit 3.14
    * Re-introduced DESTDIR flag in src/Makefile to assist building on Arch.
    * Fixed typo in init.8 manual page.
    * Expand process length in inittab to allow a command line 253 characters
    (up from 127). Expand child process structure to accomidate 253
    and some buffer room for newline/NULL.
    * Clear buffer when reading long lines from inittab, avoids garbage left
    over from old lines with long commands or comments.
    * Drop lines which are too long from inttab conf and log warning rather
    than truncate.

++++ thin-provisioning-tools:

  - thin-provisioning-tools lacks symlinks and related man pages (boo#1236800)
    * Call make install to generate symbolic links of comamnds
    * Update %files section to include above symbolic links and man

++++ zypper:

  - New system-architecture command (bsc#1236384)
    Prints the detected system architecture.
  - version 1.14.83
  - requires: libzypp >= 17.36.0.
  - Change versioncmp command to return exit code according to the
    comparison result (#593)
  - version 1.14.82

------------------------------------------------------------------
------------------  2025-2-9  -  Feb 9 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.9 → 10.2.10
  - Poetry build sdist timestamps set to epoch 0
    Newer versions of poetry set the timestamp for all source
    files to epoch 0. Such sources are not accepted by e.g
    Debian FTP servers and in general I don't like when tools
    changes their behavior just like that. This commit forces
    an older version of poetry for the purpose of creating the
    sdist tarball which then gets published on pypi. The
    argumentation for reproducible builds by forcing source
    files to a certain timestamp doesn't fly for me. I'm open
    for any better solution though. This Fixes #2730

++++ kernel-default:

  - seccomp: passthrough uretprobe systemcall without filtering
    (git-fixes).
  - drm/amd/display: Add hubp cache reset when powergating
    (stable-fixes).
  - wifi: rtw89: avoid to init mgnt_entry list twice when WoWLAN
    failed (git-fixes).
  - wifi: rtw89: chan: fix soft lockup in
    rtw89_entity_recalc_mgnt_roles() (git-fixes).
  - wifi: rtw89: chan: manage active interfaces (stable-fixes).
  - wifi: rtw89: handle entity active flag per PHY (stable-fixes).
  - commit f959305

++++ kernel-rt:

  - seccomp: passthrough uretprobe systemcall without filtering
    (git-fixes).
  - drm/amd/display: Add hubp cache reset when powergating
    (stable-fixes).
  - wifi: rtw89: avoid to init mgnt_entry list twice when WoWLAN
    failed (git-fixes).
  - wifi: rtw89: chan: fix soft lockup in
    rtw89_entity_recalc_mgnt_roles() (git-fixes).
  - wifi: rtw89: chan: manage active interfaces (stable-fixes).
  - wifi: rtw89: handle entity active flag per PHY (stable-fixes).
  - commit f959305

++++ protobuf-c:

  - Update to release 1.5.1
    * Order `oneof` union members from largest to smallest
    * Better compatibility with protobuf >= 26.0
  - Delete 711.patch (merged)

------------------------------------------------------------------
------------------  2025-2-8  -  Feb 8 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/i915/dp: Iterate DSC BPP from high to low on all platforms
    (git-fixes).
  - drm/i915/dp: fix the Adaptive sync Operation mode for SDP
    (git-fixes).
  - drm/i915/guc: Debug print LRC state entries only if the context
    is pinned (git-fixes).
  - drm/i915: Fix page cleanup on DMA remap failure (git-fixes).
  - drm/i915/pmu: Fix zero delta busyness issue (git-fixes).
  - drm/xe/devcoredump: Move exec queue snapshot to Contexts section
    (git-fixes).
  - gpu: drm_dp_cec: fix broken CEC adapter properties check
    (git-fixes).
  - accel/ivpu: Clear runtime_error after
    pm_runtime_resume_and_get() fails (git-fixes).
  - drm/komeda: Add check for komeda_get_layer_fourcc_list()
    (git-fixes).
  - firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry (git-fixes).
  - ACPI: property: Fix return value for nval == 0 in
    acpi_data_prop_read() (git-fixes).
  - ACPI: PRM: Remove unnecessary strict handler address checks
    (git-fixes).
  - gpio: pca953x: Improve interrupt support (git-fixes).
  - PCI/TPH: Restore TPH Requester Enable correctly (git-fixes).
  - PCI/ASPM: Fix L1SS saving (git-fixes).
  - selftests: mptcp: connect: -f: no reconnect (git-fixes).
  - commit 902a5b3
  - tools build: Remove the libunwind feature tests from the ones
    detected when test-all.o builds (git-fixes).
  - commit f82da74
  - perf annotate: Use an array for the disassembler preference
    (git-fixes).
  - perf test: Fix parallel/sequential option documentation
    (git-fixes).
  - perf test stat: Avoid hybrid assumption when virtualized
    (git-fixes).
  - perf symbol: Prefer non-label symbols with same address
    (git-fixes).
  - perf stat: Fix trailing comma when there is no metric unit
    (git-fixes).
  - tools features: Don't check for libunwind devel files by default
    (git-fixes).
  - commit e8b27c5

++++ kernel-rt:

  - drm/i915/dp: Iterate DSC BPP from high to low on all platforms
    (git-fixes).
  - drm/i915/dp: fix the Adaptive sync Operation mode for SDP
    (git-fixes).
  - drm/i915/guc: Debug print LRC state entries only if the context
    is pinned (git-fixes).
  - drm/i915: Fix page cleanup on DMA remap failure (git-fixes).
  - drm/i915/pmu: Fix zero delta busyness issue (git-fixes).
  - drm/xe/devcoredump: Move exec queue snapshot to Contexts section
    (git-fixes).
  - gpu: drm_dp_cec: fix broken CEC adapter properties check
    (git-fixes).
  - accel/ivpu: Clear runtime_error after
    pm_runtime_resume_and_get() fails (git-fixes).
  - drm/komeda: Add check for komeda_get_layer_fourcc_list()
    (git-fixes).
  - firmware: iscsi_ibft: fix ISCSI_IBFT Kconfig entry (git-fixes).
  - ACPI: property: Fix return value for nval == 0 in
    acpi_data_prop_read() (git-fixes).
  - ACPI: PRM: Remove unnecessary strict handler address checks
    (git-fixes).
  - gpio: pca953x: Improve interrupt support (git-fixes).
  - PCI/TPH: Restore TPH Requester Enable correctly (git-fixes).
  - PCI/ASPM: Fix L1SS saving (git-fixes).
  - selftests: mptcp: connect: -f: no reconnect (git-fixes).
  - commit 902a5b3
  - tools build: Remove the libunwind feature tests from the ones
    detected when test-all.o builds (git-fixes).
  - commit f82da74
  - perf annotate: Use an array for the disassembler preference
    (git-fixes).
  - perf test: Fix parallel/sequential option documentation
    (git-fixes).
  - perf test stat: Avoid hybrid assumption when virtualized
    (git-fixes).
  - perf symbol: Prefer non-label symbols with same address
    (git-fixes).
  - perf stat: Fix trailing comma when there is no metric unit
    (git-fixes).
  - tools features: Don't check for libunwind devel files by default
    (git-fixes).
  - commit e8b27c5

++++ nfs-utils:

  - update to 2.8.2:
    * exports: Fix referrals when --enable-junction=no
    * nfsidmap(v2): Add guards around [nfsidmap] usages of [sysconf].
    * libnsm(v2): fix the safer atomic filenames fix
    * libnsm: fix the safer atomic filenames fix
    * nfsd: dump default number of threads to 16
    * autoconf: don't build nfsdcltrack by default
    * nfs(5): Update rsize/wsize options
    * nfsdctl: clarify when versions can be set on the man page
    * nfsdctl: fix up the help text in version_usage()
    * libnsm: safer atomic filenames
    * nfs-utils: fixup statd testing simulator host arg
    * mount.nfs: retry NFSv3 mount after NFSv4 failure in auto negotiation

++++ mokutil:

  - update to 0.7.2:
    * mokutil: revert the default listing to the verbose form
  - update to 0.7.1:
    * Fix an off-by-one reading passwords from a file.
    * Short certificate listing by default

++++ pcsc-tools:

  - update to 1.7.2:
    * A number of new ATRs
    * build system and portability changes

++++ python-maturin:

  - update to 1.8.2:
    * Exclude packages not in the dependency tree when finding
    bindings in #2426
    * Use uv automatically when running maturin develop inside uv-
    created virtualenv in #2433
    * Consider abi3 minor version when resolving Python
    interpreters in #2437
    * Handle archived dylibs on AIX in #2442
    * Fix unnecessary rebuilds due to pyo3 config file modified
    time change in #2446
    * Fix the name of the .data directory in the generated wheel in
    [#2449]
    * Update minimal manylinux version for loongarch64 in #2451

------------------------------------------------------------------
------------------  2025-2-7  -  Feb 7 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update to 332
  - Updated naming convention for motd to issue and relevant patches
  - Added 0007-Remove-DynamicUser-setting-as-these-conflict-with-re.patch
    since dynamic users can't be resolved since systemd is missing in nsswitch
    bsc#1230638

++++ kernel-default:

  - perf probe: Fix uninitialized variable
    (perf-sle16-v6.13-userspace-update).
  - libperf: evlist: Fix --cpu argument on hybrid platform
    (perf-sle16-v6.13-userspace-update).
  - perf test expr: Fix system_tsc_freq for only x86
    (perf-sle16-v6.13-userspace-update).
  - perf test hwmon_pmu: Fix event file location
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Use openat rather than dup to refresh directory
    (perf-sle16-v6.13-userspace-update).
  - perf ftrace: Fix undefined behavior in cmp_profile_data()
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix precise_ip fallback logic
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix build error on generated/fs_at_flags_array.c
    (perf-sle16-v6.13-userspace-update).
  - perf machine: Initialize machine->env to address a segfault
    (perf-sle16-v6.13-userspace-update).
  - perf test: Don't signal all processes on system when
    interrupting tests (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix build-id event recording
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Fix hwmon parsing with PMU name test
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Ensure hwmon key union is zeroed before use
    (perf-sle16-v6.13-userspace-update).
  - perf tests hwmon_pmu: Remove double evlist__delete()
    (perf-sle16-v6.13-userspace-update).
  - perf/test: fix perf ftrace test on s390
    (perf-sle16-v6.13-userspace-update).
  - perf bpf-filter: Return -ENOMEM directly when pfi allocation
    fails (perf-sle16-v6.13-userspace-update).
  - perf test: Correct hwmon test PMU detection
    (perf-sle16-v6.13-userspace-update).
  - perf: Remove unused del_perf_probe_events()
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Move pmu_metrics_table__find and remove ARM override
    (perf-sle16-v6.13-userspace-update).
  - perf jevents: Add map_for_cpu()
    (perf-sle16-v6.13-userspace-update).
  - perf header: Pass a perf_cpu rather than a PMU to get_cpuid_str
    (perf-sle16-v6.13-userspace-update).
  - perf header: Avoid transitive PMU includes
    (perf-sle16-v6.13-userspace-update).
  - perf arm64 header: Use cpu argument in get_cpuid
    (perf-sle16-v6.13-userspace-update).
  - perf header: Refactor get_cpuid to take a CPU for ARM
    (perf-sle16-v6.13-userspace-update).
  - perf header: Move is_cpu_online to numa bench
    (perf-sle16-v6.13-userspace-update).
  - perf jevents: fix breakage when do perf stat on system metric
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add missing __exit calls in tool/hwmon tests
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Make leader sampling test work without branch event
    (perf-sle16-v6.13-userspace-update).
  - perf util: Remove kernel version deadcode
    (perf-sle16-v6.13-userspace-update).
  - perf test shell trace_exit_race: Use --no-comm to avoid cases
    where COMM isn't resolved (perf-sle16-v6.13-userspace-update).
  - perf test shell trace_exit_race: Show what went wrong in
    verbose mode (perf-sle16-v6.13-userspace-update).
  - perf tests: Add test for trace output loss
    (perf-sle16-v6.13-userspace-update).
  - perf trace: Avoid garbage when not printing a syscall's
    arguments (perf-sle16-v6.13-userspace-update).
  - perf trace: Do not lose last events in a race
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Introduce quotation marks support
    (perf-sle16-v6.13-userspace-update).
  - perf string: Add strpbrk_esq() and strdup_esq() for escape
    and quote (perf-sle16-v6.13-userspace-update).
  - perf probe: Accept FUNC@* to specify function name explicitly
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix to ignore escaped characters in --lines option
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix error message for failing to find line range
    (perf-sle16-v6.13-userspace-update).
  - perf trace: Fix tracing itself, creating feedback loops
    (perf-sle16-v6.13-userspace-update).
  - perf timechart: Remove redundant variable assignment
    (perf-sle16-v6.13-userspace-update).
  - perf list: Fix topic and pmu_name argument order
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix typos Muliplier -> Multiplier
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Allow configuring what disassemblers to use
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Define stubs for the LLVM and capstone
    disassemblers (perf-sle16-v6.13-userspace-update).
  - perf disasm: Introduce symbol__disassemble_objdump()
    (perf-sle16-v6.13-userspace-update).
  - perf build: Remove PERF_HAVE_DWARF_REGS
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Remove get_arch_regstr code
    (perf-sle16-v6.13-userspace-update).
  - perf xtensa: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf sparc: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf sh: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf s390: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf riscv: Remove dwarf-regs.c and add dwarf-regs-table.h
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Move powerpc dwarf-regs out of arch
    (perf-sle16-v6.13-userspace-update).
  - perf mips: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf loongarch: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Move csky dwarf-regs out of arch
    (perf-sle16-v6.13-userspace-update).
  - perf arm: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf arm64: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Move x86 dwarf-regs out of arch
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Pass ELF flags to get_dwarf_regstr
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Pass accurate disassembly machine to
    get_dwarf_regnum (perf-sle16-v6.13-userspace-update).
  - perf disasm: Add e_machine/e_flags to struct arch
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Add EM_HOST and EF_HOST defines
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Remove
    PERF_HAVE_ARCH_REGS_QUERY_REGISTER_OFFSET
    (perf-sle16-v6.13-userspace-update).
  - perf bpf-prologue: Remove unused file
    (perf-sle16-v6.13-userspace-update).
  - perf docs: Document tool and hwmon events
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add hwmon "PMU" test
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Add calls enabling the hwmon_pmu
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Add a tool PMU exposing events from hwmon in
    sysfs (perf-sle16-v6.13-userspace-update).
  - perf test: Add hwmon filename parser test
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Add hwmon filename parser
    (perf-sle16-v6.13-userspace-update).
  - perf build: Include libtraceevent headers directly indicated
    by pkg-config (perf-sle16-v6.13-userspace-update).
  - perf script python: Adjust objdump start/end per map pgoff
    parameter (perf-sle16-v6.13-userspace-update).
  - perf script cs_etm: Add map_pgoff to python dictionary
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Expand metric+unit buffer size
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Add the empty-pmu-events build to .gitignore
    (perf-sle16-v6.13-userspace-update).
  - perf: event: Remove deadcode
    (perf-sle16-v6.13-userspace-update).
  - perf trace: avoid garbage when not printing a trace event's
    arguments (perf-sle16-v6.13-userspace-update).
  - perf test: Fix ftrace test with regex patterns
    (perf-sle16-v6.13-userspace-update).
  - perf test: Remove dangling CFLAGS for removed attr.o object
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Add all shellcheck_log to gitignore
    (perf-sle16-v6.13-userspace-update).
  - perf build: Add missing cflags when building with custom
    libtraceevent (perf-sle16-v6.13-userspace-update).
  - perf test: Remove cpu-list BPF cgroup counter test
    (perf-sle16-v6.13-userspace-update).
  - perf build: Make libunwind opt-in rather than opt-out
    (perf-sle16-v6.13-userspace-update).
  - perf test: Use sqrtloop workload to test bperf event
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Support inherit events during fork() for bperf
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Use old behavior when opening old SPE files
    (perf-sle16-v6.13-userspace-update).
  - perf ftrace latency: Fix unit on histogram first entry when
    using --use-nsec (perf-sle16-v6.13-userspace-update).
  - perf, riscv: Wire up perf trace support for RISC-V
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix retrieval of source files from a debuginfod
    server (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Update --itrace help text
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Correctly set sample flags
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Use ARM_SPE_OP_BRANCH_ERET when synthesizing
    branches (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Set sample.addr to target address for instruction
    sample (perf-sle16-v6.13-userspace-update).
  - perf vendor events arm64: Add i.MX91 DDR Performance Monitor
    metrics (perf-sle16-v6.13-userspace-update).
  - perf test: Sort tests placing exclusive tests last
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a signal handler to kill forked child processes
    (perf-sle16-v6.13-userspace-update).
  - perf test: Make parallel testing the default
    (perf-sle16-v6.13-userspace-update).
  - perf test: Run parallel tests in two passes
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a signal handler around running a test
    (perf-sle16-v6.13-userspace-update).
  - perf test: Tag parallel failing shell tests with "(exclusive)"
    (perf-sle16-v6.13-userspace-update).
  - perf test: Avoid list test blocking on writing to stdout
    (perf-sle16-v6.13-userspace-update).
  - perf test: Reduce scope of parallel variable
    (perf-sle16-v6.13-userspace-update).
  - perf test: Display number of active running tests
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Fix not cleaning up disasm_line in
    symbol__disassemble_raw() (perf-sle16-v6.13-userspace-update).
  - perf disasm: Use disasm_line__free() to properly free
    disasm_line (perf-sle16-v6.13-userspace-update).
  - perf test: Add precise_max subtest to the perf record shell test
    (perf-sle16-v6.13-userspace-update).
  - perf record: Just use "cycles:P" as the default event
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Check fallback error and order
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Move x86__is_amd_cpu() to util/env.c
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Detect missing kernel features properly
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Do not set exclude_guest for precise_ip
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Simplify evsel__add_modifier()
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Don't set attr.exclude_guest by default
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Add fallback for exclude_guest
    (perf-sle16-v6.13-userspace-update).
  - perf tools: sched-pipe bench: add (-n) nonblocking benchmark
    (perf-sle16-v6.13-userspace-update).
  - perf test: Document the -w/--workload option
    (perf-sle16-v6.13-userspace-update).
  - perf test: Introduce --list-workloads to list the available
    workloads (perf-sle16-v6.13-userspace-update).
  - perf test: Introduce workloads__for_each()
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events amd: Update Zen 5 data cache fill events
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events amd: Add Zen 5 data fabric metrics
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events amd: Add Zen 5 data fabric events
    (perf-sle16-v6.13-userspace-update).
  - perf test: Fix perf test case 84 on s390
    (perf-sle16-v6.13-userspace-update).
  - perf test: Update all metrics test like metricgroups test
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename CONFIG_DWARF to CONFIG_LIBDW
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename HAVE_DWARF_SUPPORT to HAVE_LIBDW_SUPPORT
    (perf-sle16-v6.13-userspace-update).
  - perf libdw: Remove unnecessary defines
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Move elfutils support check to libdw check
    (perf-sle16-v6.13-userspace-update).
  - perf build: Combine test-dwarf-getcfi into test-libdw
    (perf-sle16-v6.13-userspace-update).
  - perf build: Combine test-dwarf-getlocations into test-libdw
    (perf-sle16-v6.13-userspace-update).
  - perf build: Combine libdw-dwarf-unwind into libdw feature tests
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename test-dwarf to test-libdw
    (perf-sle16-v6.13-userspace-update).
  - perf build: Remove defined but never used variable
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename NO_DWARF to NO_LIBDW
    (perf-sle16-v6.13-userspace-update).
  - perf build: Fix LIBDW_DIR (perf-sle16-v6.13-userspace-update).
  - perf test: Move attr files into shell directory where they
    are used (perf-sle16-v6.13-userspace-update).
  - perf test: Remove C test wrapper for attr.py
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a shell wrapper for "Setup struct
    perf_event_attr" (perf-sle16-v6.13-userspace-update).
  - perf probe: Correct demangled symbols in C++ program
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Disable metric thresholds for CSV and JSON
    metric-only mode (perf-sle16-v6.13-userspace-update).
  - perf stat: Add metric-threshold to json output
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Change color to threshold in print_metric
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Drop metric-unit if unit is NULL
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Display "none" for NaN with metric only json
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Fix/add parameter names for print_metric
    (perf-sle16-v6.13-userspace-update).
  - perf color: Add printf format checking and resolve issues
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix libdw memory leak
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Fix capstone memory leak
    (perf-sle16-v6.13-userspace-update).
  - tools/perf/powerpc/util: Add support to handle compatible mode
    PVR for perf json events (perf-sle16-v6.13-userspace-update).
  - tools/perf/pmu-events/powerpc: Add support for compat events
    in json (perf-sle16-v6.13-userspace-update).
  - perf dso: Fix symtab_type for kmod compression
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Improve log for long event name failure
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Check group string length
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Use the MAX_EVENT_NAME_LEN macro
    (perf-sle16-v6.13-userspace-update).
  - perf test: Speed up some tests using perf list
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Refine helper arch_is_topdown_metrics()
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Make topdown metrics comparators be symmetric
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Remove duplicate io.h header
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Add Cortex CPUs to common data source encoding
    list (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Add Neoverse-V2 to common data source encoding
    list (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Remove the unused 'midr' field
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Use metadata to decide the data source feature
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Introduce arm_spe__is_homogeneous()
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Rename the common data source encoding
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Rename arm_spe__synth_data_source_generic()
    (perf-sle16-v6.13-userspace-update).
  - perf test: Delete unused Intel CQM test
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Fix missing inherit + sample read check
    (perf-sle16-v6.13-userspace-update).
  - perf sched timehist: Add pre-migration wait time option
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Remove unnecessary parentheses
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix possible compiler warnings in hashmap
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix compiler error in util/tool_pmu.c
    (perf-sle16-v6.13-userspace-update).
  - tools/perf/tests: Remove duplicate evlist__delete in
    tests/tool_pmu.c (perf-sle16-v6.13-userspace-update).
  - tools/perf/tests: Fix compilation error with strncpy in
    tests/tool_pmu (perf-sle16-v6.13-userspace-update).
  - perf report: Display columns Predicted/Abort/Cycles in
  - -branch-history (perf-sle16-v6.13-userspace-update).
  - perf tests: Add tool PMU test
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Switch to standard pmu functions and json
    descriptions (perf-sle16-v6.13-userspace-update).
  - perf jevents: Add tool event json under a common architecture
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Move expr literals to tool_pmu
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Rename perf_tool_event__* to tool_pmu__*
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Rename enum perf_tool_event to tool_pmu_event
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Factor tool events into their own PMU
    (perf-sle16-v6.13-userspace-update).
  - perf parse-events: Expose/rename config_term_name
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Allow hardcoded terms to be applied to attributes
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Simplify an asprintf error message
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Remove unused color_fwrite_lines
    (perf-sle16-v6.13-userspace-update).
  - perf test x86: Fix typo in intel-pt-test
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Remove unused add_perf_probe_events
    (perf-sle16-v6.13-userspace-update).
  - perf test attr: Add back missing topdown events
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Dump metadata with version 2
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Support metadata version 2
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Save per CPU information in metadata
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Calculate meta data size
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Define metadata header version 2
    (perf-sle16-v6.13-userspace-update).
  - perf list: update option desc in man page
    (perf-sle16-v6.13-userspace-update).
  - perf test: Restore sample rate for perf_event_attr
    (perf-sle16-v6.13-userspace-update).
  - perf trace: Keep exited threads for summary
    (perf-sle16-v6.13-userspace-update).
  - perf/test: perf test 86 fails on s390
    (perf-sle16-v6.13-userspace-update).
  - tools/perf: Allow inherit + PERF_SAMPLE_READ when opening events
    (perf-sle16-v6.13-userspace-update).
  - tools/perf: Correctly calculate sample period for inherited
    SAMPLE_READ values (perf-sle16-v6.13-userspace-update).
  - perf test: Skip not fail syscall tp fields test when
    insufficient permissions (perf-sle16-v6.13-userspace-update).
  - perf test: Skip not fail tp fields test when insufficient
    permissions (perf-sle16-v6.13-userspace-update).
  - perf test: Fix memory leaks on event-times error paths
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Fix affinity memory leaks on error path
    (perf-sle16-v6.13-userspace-update).
  - perf jevents: Don't stop at the first matched pmu when searching
    a events table (perf-sle16-v6.13-userspace-update).
  - perf tests: Add more topdown events regroup tests
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Add topdown events counting and sampling tests
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Add leader sampling test in record tests
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Don't move topdown metric events in group
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Correct leader selection with sample_read
    enabled (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Complete topdown slots/metrics events check
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Reduce a variables scope
    (perf-sle16-v6.13-userspace-update).
  - perf vender events arm64: Use "Topdown" as topdown metric
    group name (perf-sle16-v6.13-userspace-update).
  - perf test: Use ARRAY_SIZE for array length
    (perf-sle16-v6.13-userspace-update).
  - perf/test: Speed up test case perf annotate basic tests
    (perf-sle16-v6.13-userspace-update).
  - perf mem: Fix printing PERF_MEM_LVLNUM_{L2_MHB|MSC}
    (perf-sle16-v6.13-userspace-update).
  - perf sched replay: Remove unused parts of the code
    (perf-sle16-v6.13-userspace-update).
  - libperf: Explicitly specify install-html dependencies
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a test for default perf stat command
    (perf-sle16-v6.13-userspace-update).
  - perf test: Make stat test work on DT devices
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Remove pmu_name (perf-sle16-v6.13-userspace-update).
  - perf evsel x86: Make evsel__has_perf_metrics work for legacy
    events (perf-sle16-v6.13-userspace-update).
  - perf stat: Remove evlist__add_default_attrs use strings
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Uniquify event name improvements
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Add alternate_hw_config and use in evsel__match
    (perf-sle16-v6.13-userspace-update).
  - perf test: Ignore security failures in all PMU test
    (perf-sle16-v6.13-userspace-update).
  - perf symbol: Do not fixup end address of labels
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events arm64: imx95: add
    imx95_bandwidth_usage.lpddr4x metric
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Stop repeating when ref_perf_stat() returns -1
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Close cork_fd when create_perf_stat_counter() failed
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: display dmesg command of showing a hardcoded path
    (perf-sle16-v6.13-userspace-update).
  - perf test: cs-etm: Test Coresight disassembly script
    (perf-sle16-v6.13-userspace-update).
  - perf scripts python cs-etm: Add start and stop arguments
    (perf-sle16-v6.13-userspace-update).
  - perf scripts python cs-etm: Improve arguments
    (perf-sle16-v6.13-userspace-update).
  - perf scripts python cs-etm: Update to use argparse
    (perf-sle16-v6.13-userspace-update).
  - perf scripting python: Add function to get a config value
    (perf-sle16-v6.13-userspace-update).
  - perf cs-etm: Use new OpenCSD consistency checks
    (perf-sle16-v6.13-userspace-update).
  - perf cs-etm: Don't flush when packet_queue fills up
    (perf-sle16-v6.13-userspace-update).
  - perf test: Be more tolerant of metricgroup failures
    (perf-sle16-v6.13-userspace-update).
  - perf tools: update expected diff for lib/list_sort.c
    (perf-sle16-v6.13-userspace-update).
  - commit d7ab8b5
  - mptcp: fix recvbuffer adjust on sleeping rcvmsg (git-fixes)
  - commit d852207
  - smb: client: fix double free of TCP_Server_Info::hostname
    (CVE-2025-21673 bsc#1236689).
  - commit 5cebe70
  - openvswitch: fix lockup on tx to unregistering netdev with
    carrier (CVE-2025-21681 bsc#1236702).
  - commit 66a9042
  - cpuidle: teo: Update documentation after previous changes
    (git-fixes).
  - commit 2f5bf5c
  - mac802154: check local interfaces before deleting sdata list
    (CVE-2024-57948 bsc#1236677).
  - commit 684a927
  - cpufreq: qcom: Implement clk_ops::determine_rate() for
    qcom_cpufreq* clocks (git-fixes).
  - cpufreq: qcom: Fix qcom_cpufreq_hw_recalc_rate() to query LUT
    if LMh IRQ is not available (git-fixes).
  - commit 89b10dc
  - cpufreq: fix using cpufreq-dt as module (git-fixes).
  - commit a8a7426
  - doc: update managed_irq documentation (bsc#1236897).
  - blk-mq: issue warning when offlining hctx with online isolcpus
    (bsc#1236897).
  - blk-mq: use hk cpus only when isolcpus=managed_irq is enabled
    (bsc#1236897).
  - lib/group_cpus: honor housekeeping config when grouping CPUs
    (bsc#1236897).
  - virtio: blk/scsi: use block layer helpers to calculate num of
    queues (bsc#1236897).
  - scsi: use block layer helpers to calculate num of queues
    (bsc#1236897).
  - nvme-pci: use block layer helpers to calculate num of queues
    (bsc#1236897).
  - blk-mq: add number of queue calc helper (bsc#1236897).
  - lib/group_cpus: let group_cpu_evenly return number initialized
    masks (bsc#1236897).
  - commit 489fc8c
  - net/l2tp: fix warning in l2tp_exit_net found by syzbot (CVE-2024-53211 bsc#1234961)
  - commit 92b3970
  - blk-mq: create correct map for fallback case (bsc#1236896).
  - blk-mq: remove unused queue mapping helpers (bsc#1236896).
  - virtio: blk/scsi: replace blk_mq_virtio_map_queues with
    blk_mq_map_hw_queues (bsc#1236896).
  - nvme: replace blk_mq_pci_map_queues with blk_mq_map_hw_queues
    (bsc#1236896).
  - scsi: replace blk_mq_pci_map_queues with blk_mq_map_hw_queues
    (bsc#1236896).
  - blk-mq: introduce blk_mq_map_hw_queues (bsc#1236896).
  - virtio: hookup irq_get_affinity callback (bsc#1236896).
  - PCI: hookup irq_get_affinity callback (bsc#1236896).
  - driver core: bus: add irq_get_affinity callback to bus_type
    (bsc#1236896).
  - commit eedefae
  - selftests/bpf: Add apply_bytes test to
    test_txmsg_redir_wait_sndmem in test_sockmap (bsc#1235485
    CVE-2024-56633).
  - tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg
    (bsc#1235485 CVE-2024-56633).
  - commit 3adbbcc
  - selftests: net: Add busy_poll_test (jsc#PED-12085).
  - eventpoll: Control irq suspension for prefer_busy_poll (jsc#PED-12085).
  - eventpoll: Trigger napi_busy_loop, if prefer_busy_poll is set
    (jsc#PED-12085).
  - commit 170f675

++++ kernel-firmware-all:

  - Update the version number to 20250206:
    no actual content change, just for making the transition smoother

++++ kernel-firmware-amdgpu:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-ath10k:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-ath11k:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-ath12k:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-atheros:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-bluetooth:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-bnx2:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-brcm:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-chelsio:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-dpaa2:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-i915:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-intel:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-iwlwifi:

  - Update to version 20250206 (git commit aaae2fb60f75):
    * iwlwifi: add Bz/gl FW for core93-123 release
    * iwlwifi: update ty/So/Ma firmwares for core93-123 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core93-82 release

++++ kernel-firmware-liquidio:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-marvell:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-media:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-mediatek:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-mellanox:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-mwifiex:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-network:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-nfp:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-nvidia:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-platform:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-prestera:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-qcom:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-qlogic:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-radeon:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-realtek:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-serial:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-sound:

  - Update to version 20250206 (git commit aaae2fb60f75):
    * ASoC: tas2781: Add dsp firmware for new projects

++++ kernel-firmware-ti:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-ueagle:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-firmware-usb-network:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

++++ kernel-rt:

  - perf probe: Fix uninitialized variable
    (perf-sle16-v6.13-userspace-update).
  - libperf: evlist: Fix --cpu argument on hybrid platform
    (perf-sle16-v6.13-userspace-update).
  - perf test expr: Fix system_tsc_freq for only x86
    (perf-sle16-v6.13-userspace-update).
  - perf test hwmon_pmu: Fix event file location
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Use openat rather than dup to refresh directory
    (perf-sle16-v6.13-userspace-update).
  - perf ftrace: Fix undefined behavior in cmp_profile_data()
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix precise_ip fallback logic
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix build error on generated/fs_at_flags_array.c
    (perf-sle16-v6.13-userspace-update).
  - perf machine: Initialize machine->env to address a segfault
    (perf-sle16-v6.13-userspace-update).
  - perf test: Don't signal all processes on system when
    interrupting tests (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix build-id event recording
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Fix hwmon parsing with PMU name test
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Ensure hwmon key union is zeroed before use
    (perf-sle16-v6.13-userspace-update).
  - perf tests hwmon_pmu: Remove double evlist__delete()
    (perf-sle16-v6.13-userspace-update).
  - perf/test: fix perf ftrace test on s390
    (perf-sle16-v6.13-userspace-update).
  - perf bpf-filter: Return -ENOMEM directly when pfi allocation
    fails (perf-sle16-v6.13-userspace-update).
  - perf test: Correct hwmon test PMU detection
    (perf-sle16-v6.13-userspace-update).
  - perf: Remove unused del_perf_probe_events()
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Move pmu_metrics_table__find and remove ARM override
    (perf-sle16-v6.13-userspace-update).
  - perf jevents: Add map_for_cpu()
    (perf-sle16-v6.13-userspace-update).
  - perf header: Pass a perf_cpu rather than a PMU to get_cpuid_str
    (perf-sle16-v6.13-userspace-update).
  - perf header: Avoid transitive PMU includes
    (perf-sle16-v6.13-userspace-update).
  - perf arm64 header: Use cpu argument in get_cpuid
    (perf-sle16-v6.13-userspace-update).
  - perf header: Refactor get_cpuid to take a CPU for ARM
    (perf-sle16-v6.13-userspace-update).
  - perf header: Move is_cpu_online to numa bench
    (perf-sle16-v6.13-userspace-update).
  - perf jevents: fix breakage when do perf stat on system metric
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add missing __exit calls in tool/hwmon tests
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Make leader sampling test work without branch event
    (perf-sle16-v6.13-userspace-update).
  - perf util: Remove kernel version deadcode
    (perf-sle16-v6.13-userspace-update).
  - perf test shell trace_exit_race: Use --no-comm to avoid cases
    where COMM isn't resolved (perf-sle16-v6.13-userspace-update).
  - perf test shell trace_exit_race: Show what went wrong in
    verbose mode (perf-sle16-v6.13-userspace-update).
  - perf tests: Add test for trace output loss
    (perf-sle16-v6.13-userspace-update).
  - perf trace: Avoid garbage when not printing a syscall's
    arguments (perf-sle16-v6.13-userspace-update).
  - perf trace: Do not lose last events in a race
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Introduce quotation marks support
    (perf-sle16-v6.13-userspace-update).
  - perf string: Add strpbrk_esq() and strdup_esq() for escape
    and quote (perf-sle16-v6.13-userspace-update).
  - perf probe: Accept FUNC@* to specify function name explicitly
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix to ignore escaped characters in --lines option
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix error message for failing to find line range
    (perf-sle16-v6.13-userspace-update).
  - perf trace: Fix tracing itself, creating feedback loops
    (perf-sle16-v6.13-userspace-update).
  - perf timechart: Remove redundant variable assignment
    (perf-sle16-v6.13-userspace-update).
  - perf list: Fix topic and pmu_name argument order
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix typos Muliplier -> Multiplier
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Allow configuring what disassemblers to use
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Define stubs for the LLVM and capstone
    disassemblers (perf-sle16-v6.13-userspace-update).
  - perf disasm: Introduce symbol__disassemble_objdump()
    (perf-sle16-v6.13-userspace-update).
  - perf build: Remove PERF_HAVE_DWARF_REGS
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Remove get_arch_regstr code
    (perf-sle16-v6.13-userspace-update).
  - perf xtensa: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf sparc: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf sh: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf s390: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf riscv: Remove dwarf-regs.c and add dwarf-regs-table.h
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Move powerpc dwarf-regs out of arch
    (perf-sle16-v6.13-userspace-update).
  - perf mips: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf loongarch: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Move csky dwarf-regs out of arch
    (perf-sle16-v6.13-userspace-update).
  - perf arm: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf arm64: Remove dwarf-regs.c
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Move x86 dwarf-regs out of arch
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Pass ELF flags to get_dwarf_regstr
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Pass accurate disassembly machine to
    get_dwarf_regnum (perf-sle16-v6.13-userspace-update).
  - perf disasm: Add e_machine/e_flags to struct arch
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Add EM_HOST and EF_HOST defines
    (perf-sle16-v6.13-userspace-update).
  - perf dwarf-regs: Remove
    PERF_HAVE_ARCH_REGS_QUERY_REGISTER_OFFSET
    (perf-sle16-v6.13-userspace-update).
  - perf bpf-prologue: Remove unused file
    (perf-sle16-v6.13-userspace-update).
  - perf docs: Document tool and hwmon events
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add hwmon "PMU" test
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Add calls enabling the hwmon_pmu
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Add a tool PMU exposing events from hwmon in
    sysfs (perf-sle16-v6.13-userspace-update).
  - perf test: Add hwmon filename parser test
    (perf-sle16-v6.13-userspace-update).
  - perf hwmon_pmu: Add hwmon filename parser
    (perf-sle16-v6.13-userspace-update).
  - perf build: Include libtraceevent headers directly indicated
    by pkg-config (perf-sle16-v6.13-userspace-update).
  - perf script python: Adjust objdump start/end per map pgoff
    parameter (perf-sle16-v6.13-userspace-update).
  - perf script cs_etm: Add map_pgoff to python dictionary
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Expand metric+unit buffer size
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Add the empty-pmu-events build to .gitignore
    (perf-sle16-v6.13-userspace-update).
  - perf: event: Remove deadcode
    (perf-sle16-v6.13-userspace-update).
  - perf trace: avoid garbage when not printing a trace event's
    arguments (perf-sle16-v6.13-userspace-update).
  - perf test: Fix ftrace test with regex patterns
    (perf-sle16-v6.13-userspace-update).
  - perf test: Remove dangling CFLAGS for removed attr.o object
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Add all shellcheck_log to gitignore
    (perf-sle16-v6.13-userspace-update).
  - perf build: Add missing cflags when building with custom
    libtraceevent (perf-sle16-v6.13-userspace-update).
  - perf test: Remove cpu-list BPF cgroup counter test
    (perf-sle16-v6.13-userspace-update).
  - perf build: Make libunwind opt-in rather than opt-out
    (perf-sle16-v6.13-userspace-update).
  - perf test: Use sqrtloop workload to test bperf event
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Support inherit events during fork() for bperf
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Use old behavior when opening old SPE files
    (perf-sle16-v6.13-userspace-update).
  - perf ftrace latency: Fix unit on histogram first entry when
    using --use-nsec (perf-sle16-v6.13-userspace-update).
  - perf, riscv: Wire up perf trace support for RISC-V
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix retrieval of source files from a debuginfod
    server (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Update --itrace help text
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Correctly set sample flags
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Use ARM_SPE_OP_BRANCH_ERET when synthesizing
    branches (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Set sample.addr to target address for instruction
    sample (perf-sle16-v6.13-userspace-update).
  - perf vendor events arm64: Add i.MX91 DDR Performance Monitor
    metrics (perf-sle16-v6.13-userspace-update).
  - perf test: Sort tests placing exclusive tests last
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a signal handler to kill forked child processes
    (perf-sle16-v6.13-userspace-update).
  - perf test: Make parallel testing the default
    (perf-sle16-v6.13-userspace-update).
  - perf test: Run parallel tests in two passes
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a signal handler around running a test
    (perf-sle16-v6.13-userspace-update).
  - perf test: Tag parallel failing shell tests with "(exclusive)"
    (perf-sle16-v6.13-userspace-update).
  - perf test: Avoid list test blocking on writing to stdout
    (perf-sle16-v6.13-userspace-update).
  - perf test: Reduce scope of parallel variable
    (perf-sle16-v6.13-userspace-update).
  - perf test: Display number of active running tests
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Fix not cleaning up disasm_line in
    symbol__disassemble_raw() (perf-sle16-v6.13-userspace-update).
  - perf disasm: Use disasm_line__free() to properly free
    disasm_line (perf-sle16-v6.13-userspace-update).
  - perf test: Add precise_max subtest to the perf record shell test
    (perf-sle16-v6.13-userspace-update).
  - perf record: Just use "cycles:P" as the default event
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Check fallback error and order
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Move x86__is_amd_cpu() to util/env.c
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Detect missing kernel features properly
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Do not set exclude_guest for precise_ip
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Simplify evsel__add_modifier()
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Don't set attr.exclude_guest by default
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Add fallback for exclude_guest
    (perf-sle16-v6.13-userspace-update).
  - perf tools: sched-pipe bench: add (-n) nonblocking benchmark
    (perf-sle16-v6.13-userspace-update).
  - perf test: Document the -w/--workload option
    (perf-sle16-v6.13-userspace-update).
  - perf test: Introduce --list-workloads to list the available
    workloads (perf-sle16-v6.13-userspace-update).
  - perf test: Introduce workloads__for_each()
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events amd: Update Zen 5 data cache fill events
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events amd: Add Zen 5 data fabric metrics
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events amd: Add Zen 5 data fabric events
    (perf-sle16-v6.13-userspace-update).
  - perf test: Fix perf test case 84 on s390
    (perf-sle16-v6.13-userspace-update).
  - perf test: Update all metrics test like metricgroups test
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename CONFIG_DWARF to CONFIG_LIBDW
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename HAVE_DWARF_SUPPORT to HAVE_LIBDW_SUPPORT
    (perf-sle16-v6.13-userspace-update).
  - perf libdw: Remove unnecessary defines
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Move elfutils support check to libdw check
    (perf-sle16-v6.13-userspace-update).
  - perf build: Combine test-dwarf-getcfi into test-libdw
    (perf-sle16-v6.13-userspace-update).
  - perf build: Combine test-dwarf-getlocations into test-libdw
    (perf-sle16-v6.13-userspace-update).
  - perf build: Combine libdw-dwarf-unwind into libdw feature tests
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename test-dwarf to test-libdw
    (perf-sle16-v6.13-userspace-update).
  - perf build: Remove defined but never used variable
    (perf-sle16-v6.13-userspace-update).
  - perf build: Rename NO_DWARF to NO_LIBDW
    (perf-sle16-v6.13-userspace-update).
  - perf build: Fix LIBDW_DIR (perf-sle16-v6.13-userspace-update).
  - perf test: Move attr files into shell directory where they
    are used (perf-sle16-v6.13-userspace-update).
  - perf test: Remove C test wrapper for attr.py
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a shell wrapper for "Setup struct
    perf_event_attr" (perf-sle16-v6.13-userspace-update).
  - perf probe: Correct demangled symbols in C++ program
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Disable metric thresholds for CSV and JSON
    metric-only mode (perf-sle16-v6.13-userspace-update).
  - perf stat: Add metric-threshold to json output
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Change color to threshold in print_metric
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Drop metric-unit if unit is NULL
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Display "none" for NaN with metric only json
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Fix/add parameter names for print_metric
    (perf-sle16-v6.13-userspace-update).
  - perf color: Add printf format checking and resolve issues
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Fix libdw memory leak
    (perf-sle16-v6.13-userspace-update).
  - perf disasm: Fix capstone memory leak
    (perf-sle16-v6.13-userspace-update).
  - tools/perf/powerpc/util: Add support to handle compatible mode
    PVR for perf json events (perf-sle16-v6.13-userspace-update).
  - tools/perf/pmu-events/powerpc: Add support for compat events
    in json (perf-sle16-v6.13-userspace-update).
  - perf dso: Fix symtab_type for kmod compression
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Improve log for long event name failure
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Check group string length
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Use the MAX_EVENT_NAME_LEN macro
    (perf-sle16-v6.13-userspace-update).
  - perf test: Speed up some tests using perf list
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Refine helper arch_is_topdown_metrics()
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Make topdown metrics comparators be symmetric
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Remove duplicate io.h header
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Add Cortex CPUs to common data source encoding
    list (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Add Neoverse-V2 to common data source encoding
    list (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Remove the unused 'midr' field
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Use metadata to decide the data source feature
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Introduce arm_spe__is_homogeneous()
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Rename the common data source encoding
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Rename arm_spe__synth_data_source_generic()
    (perf-sle16-v6.13-userspace-update).
  - perf test: Delete unused Intel CQM test
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Fix missing inherit + sample read check
    (perf-sle16-v6.13-userspace-update).
  - perf sched timehist: Add pre-migration wait time option
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Remove unnecessary parentheses
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix possible compiler warnings in hashmap
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Fix compiler error in util/tool_pmu.c
    (perf-sle16-v6.13-userspace-update).
  - tools/perf/tests: Remove duplicate evlist__delete in
    tests/tool_pmu.c (perf-sle16-v6.13-userspace-update).
  - tools/perf/tests: Fix compilation error with strncpy in
    tests/tool_pmu (perf-sle16-v6.13-userspace-update).
  - perf report: Display columns Predicted/Abort/Cycles in
  - -branch-history (perf-sle16-v6.13-userspace-update).
  - perf tests: Add tool PMU test
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Switch to standard pmu functions and json
    descriptions (perf-sle16-v6.13-userspace-update).
  - perf jevents: Add tool event json under a common architecture
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Move expr literals to tool_pmu
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Rename perf_tool_event__* to tool_pmu__*
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Rename enum perf_tool_event to tool_pmu_event
    (perf-sle16-v6.13-userspace-update).
  - perf tool_pmu: Factor tool events into their own PMU
    (perf-sle16-v6.13-userspace-update).
  - perf parse-events: Expose/rename config_term_name
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Allow hardcoded terms to be applied to attributes
    (perf-sle16-v6.13-userspace-update).
  - perf pmu: Simplify an asprintf error message
    (perf-sle16-v6.13-userspace-update).
  - perf tools: Remove unused color_fwrite_lines
    (perf-sle16-v6.13-userspace-update).
  - perf test x86: Fix typo in intel-pt-test
    (perf-sle16-v6.13-userspace-update).
  - perf probe: Remove unused add_perf_probe_events
    (perf-sle16-v6.13-userspace-update).
  - perf test attr: Add back missing topdown events
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Dump metadata with version 2
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Support metadata version 2
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Save per CPU information in metadata
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Calculate meta data size
    (perf-sle16-v6.13-userspace-update).
  - perf arm-spe: Define metadata header version 2
    (perf-sle16-v6.13-userspace-update).
  - perf list: update option desc in man page
    (perf-sle16-v6.13-userspace-update).
  - perf test: Restore sample rate for perf_event_attr
    (perf-sle16-v6.13-userspace-update).
  - perf trace: Keep exited threads for summary
    (perf-sle16-v6.13-userspace-update).
  - perf/test: perf test 86 fails on s390
    (perf-sle16-v6.13-userspace-update).
  - tools/perf: Allow inherit + PERF_SAMPLE_READ when opening events
    (perf-sle16-v6.13-userspace-update).
  - tools/perf: Correctly calculate sample period for inherited
    SAMPLE_READ values (perf-sle16-v6.13-userspace-update).
  - perf test: Skip not fail syscall tp fields test when
    insufficient permissions (perf-sle16-v6.13-userspace-update).
  - perf test: Skip not fail tp fields test when insufficient
    permissions (perf-sle16-v6.13-userspace-update).
  - perf test: Fix memory leaks on event-times error paths
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Fix affinity memory leaks on error path
    (perf-sle16-v6.13-userspace-update).
  - perf jevents: Don't stop at the first matched pmu when searching
    a events table (perf-sle16-v6.13-userspace-update).
  - perf tests: Add more topdown events regroup tests
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Add topdown events counting and sampling tests
    (perf-sle16-v6.13-userspace-update).
  - perf tests: Add leader sampling test in record tests
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Don't move topdown metric events in group
    (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Correct leader selection with sample_read
    enabled (perf-sle16-v6.13-userspace-update).
  - perf x86/topdown: Complete topdown slots/metrics events check
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Reduce a variables scope
    (perf-sle16-v6.13-userspace-update).
  - perf vender events arm64: Use "Topdown" as topdown metric
    group name (perf-sle16-v6.13-userspace-update).
  - perf test: Use ARRAY_SIZE for array length
    (perf-sle16-v6.13-userspace-update).
  - perf/test: Speed up test case perf annotate basic tests
    (perf-sle16-v6.13-userspace-update).
  - perf mem: Fix printing PERF_MEM_LVLNUM_{L2_MHB|MSC}
    (perf-sle16-v6.13-userspace-update).
  - perf sched replay: Remove unused parts of the code
    (perf-sle16-v6.13-userspace-update).
  - libperf: Explicitly specify install-html dependencies
    (perf-sle16-v6.13-userspace-update).
  - perf test: Add a test for default perf stat command
    (perf-sle16-v6.13-userspace-update).
  - perf test: Make stat test work on DT devices
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Remove pmu_name (perf-sle16-v6.13-userspace-update).
  - perf evsel x86: Make evsel__has_perf_metrics work for legacy
    events (perf-sle16-v6.13-userspace-update).
  - perf stat: Remove evlist__add_default_attrs use strings
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Uniquify event name improvements
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: Add alternate_hw_config and use in evsel__match
    (perf-sle16-v6.13-userspace-update).
  - perf test: Ignore security failures in all PMU test
    (perf-sle16-v6.13-userspace-update).
  - perf symbol: Do not fixup end address of labels
    (perf-sle16-v6.13-userspace-update).
  - perf vendor events arm64: imx95: add
    imx95_bandwidth_usage.lpddr4x metric
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Stop repeating when ref_perf_stat() returns -1
    (perf-sle16-v6.13-userspace-update).
  - perf stat: Close cork_fd when create_perf_stat_counter() failed
    (perf-sle16-v6.13-userspace-update).
  - perf evsel: display dmesg command of showing a hardcoded path
    (perf-sle16-v6.13-userspace-update).
  - perf test: cs-etm: Test Coresight disassembly script
    (perf-sle16-v6.13-userspace-update).
  - perf scripts python cs-etm: Add start and stop arguments
    (perf-sle16-v6.13-userspace-update).
  - perf scripts python cs-etm: Improve arguments
    (perf-sle16-v6.13-userspace-update).
  - perf scripts python cs-etm: Update to use argparse
    (perf-sle16-v6.13-userspace-update).
  - perf scripting python: Add function to get a config value
    (perf-sle16-v6.13-userspace-update).
  - perf cs-etm: Use new OpenCSD consistency checks
    (perf-sle16-v6.13-userspace-update).
  - perf cs-etm: Don't flush when packet_queue fills up
    (perf-sle16-v6.13-userspace-update).
  - perf test: Be more tolerant of metricgroup failures
    (perf-sle16-v6.13-userspace-update).
  - perf tools: update expected diff for lib/list_sort.c
    (perf-sle16-v6.13-userspace-update).
  - commit d7ab8b5
  - mptcp: fix recvbuffer adjust on sleeping rcvmsg (git-fixes)
  - commit d852207
  - smb: client: fix double free of TCP_Server_Info::hostname
    (CVE-2025-21673 bsc#1236689).
  - commit 5cebe70
  - openvswitch: fix lockup on tx to unregistering netdev with
    carrier (CVE-2025-21681 bsc#1236702).
  - commit 66a9042
  - cpuidle: teo: Update documentation after previous changes
    (git-fixes).
  - commit 2f5bf5c
  - mac802154: check local interfaces before deleting sdata list
    (CVE-2024-57948 bsc#1236677).
  - commit 684a927
  - cpufreq: qcom: Implement clk_ops::determine_rate() for
    qcom_cpufreq* clocks (git-fixes).
  - cpufreq: qcom: Fix qcom_cpufreq_hw_recalc_rate() to query LUT
    if LMh IRQ is not available (git-fixes).
  - commit 89b10dc
  - cpufreq: fix using cpufreq-dt as module (git-fixes).
  - commit a8a7426
  - doc: update managed_irq documentation (bsc#1236897).
  - blk-mq: issue warning when offlining hctx with online isolcpus
    (bsc#1236897).
  - blk-mq: use hk cpus only when isolcpus=managed_irq is enabled
    (bsc#1236897).
  - lib/group_cpus: honor housekeeping config when grouping CPUs
    (bsc#1236897).
  - virtio: blk/scsi: use block layer helpers to calculate num of
    queues (bsc#1236897).
  - scsi: use block layer helpers to calculate num of queues
    (bsc#1236897).
  - nvme-pci: use block layer helpers to calculate num of queues
    (bsc#1236897).
  - blk-mq: add number of queue calc helper (bsc#1236897).
  - lib/group_cpus: let group_cpu_evenly return number initialized
    masks (bsc#1236897).
  - commit 489fc8c
  - net/l2tp: fix warning in l2tp_exit_net found by syzbot (CVE-2024-53211 bsc#1234961)
  - commit 92b3970
  - blk-mq: create correct map for fallback case (bsc#1236896).
  - blk-mq: remove unused queue mapping helpers (bsc#1236896).
  - virtio: blk/scsi: replace blk_mq_virtio_map_queues with
    blk_mq_map_hw_queues (bsc#1236896).
  - nvme: replace blk_mq_pci_map_queues with blk_mq_map_hw_queues
    (bsc#1236896).
  - scsi: replace blk_mq_pci_map_queues with blk_mq_map_hw_queues
    (bsc#1236896).
  - blk-mq: introduce blk_mq_map_hw_queues (bsc#1236896).
  - virtio: hookup irq_get_affinity callback (bsc#1236896).
  - PCI: hookup irq_get_affinity callback (bsc#1236896).
  - driver core: bus: add irq_get_affinity callback to bus_type
    (bsc#1236896).
  - commit eedefae
  - selftests/bpf: Add apply_bytes test to
    test_txmsg_redir_wait_sndmem in test_sockmap (bsc#1235485
    CVE-2024-56633).
  - tcp_bpf: Fix the sk_mem_uncharge logic in tcp_bpf_sendmsg
    (bsc#1235485 CVE-2024-56633).
  - commit 3adbbcc
  - selftests: net: Add busy_poll_test (jsc#PED-12085).
  - eventpoll: Control irq suspension for prefer_busy_poll (jsc#PED-12085).
  - eventpoll: Trigger napi_busy_loop, if prefer_busy_poll is set
    (jsc#PED-12085).
  - commit 170f675

++++ gcc15:

  - Remove SPU-specific sections
    * SPU target was dropped upstream in GCC 10

++++ libcontainers-common:

  - fix shortnames.config by updating them from upstream

++++ dtc:

  - Update to 1.7.2:
    * pylibfdt: Don't emit warnings from swig generate C code
    * fdtoverlay: provide better error message for missing /__symbols__
    * pylibfdt/libfdt.i: Use SWIG_AppendOutput
    * Escape spaces in depfile with backslashes.
    * libfdt.h: whitespace consistency fixups
    * libfdt.h: typo and consistency fixes
  - Revert previous commit and use upstream fix for glibc 2.41:
    * ce1d858.patch

++++ selinux-policy:

  - Improve semodule stderr logging during install/update: Verbose logging
    will just confuse users and the policy will be rebuild later in the update
    process correctly, if there was an earlier error. These transient errors
    are only related to the order in which packages are installed.

++++ ucode-amd:

  - Update to version 20250206 (git commit aaae2fb60f75):
    just a version bump without content changes for making the smooth
    repo transition

------------------------------------------------------------------
------------------  2025-2-6  -  Feb 6 2025  -------------------
------------------------------------------------------------------

++++ curl:

  - Update to 8.12.0:
    * Security fixes:
  - [bsc#1234068, CVE-2024-11053] curl could leak the password used
    for the first host to the followed-to host under certain circumstances.
  - [bsc#1232528, CVE-2024-9681] HSTS subdomain overwrites parent cache entry
  - [bsc#1236589, CVE-2025-0665] eventfd double close
    * Changes:
  - curl: add byte range support to --variable reading from file
  - curl: make --etag-save acknowledge --create-dirs
  - getinfo: fix CURLINFO_QUEUE_TIME_T and add 'time_queue' var
  - getinfo: provide info which auth was used for HTTP and proxy
  - hyper: drop support
  - openssl: add support to use keys and certificates from PKCS#11 provider
  - QUIC: 0RTT for gnutls via CURLSSLOPT_EARLYDATA
  - vtls: feature ssls-export for SSL session im-/export
    * Bugfixes:
  - altsvc: avoid integer overflow in expire calculation
  - asyn-ares: acknowledge CURLOPT_DNS_SERVERS set to NULL
  - asyn-ares: fix memory leak
  - asyn-ares: initial HTTPS resolve support
  - asyn-thread: use c-ares to resolve HTTPS RR
  - async-thread: avoid closing eventfd twice
  - cd2nroff: do not insist on quoted <> within backticks
  - cd2nroff: support "none" as a TLS backend
  - conncache: count shutdowns against host and max limits
  - content_encoding: drop support for zlib before 1.2.0.4
  - content_encoding: namespace GZIP flag constants
  - content_encoding: put the decomp buffers into the writer structs
  - content_encoding: support use of custom libzstd memory functions
  - cookie: cap expire times to 400 days
  - cookie: parse only the exact expire date
  - curl: return error if etag options are used with multiple URLs
  - curl_multi_fdset: include the shutdown connections in the set
  - curl_sha512_256: rename symbols to the curl namespace
  - curl_url_set.md: adjust the added-in to 7.62.0
  - doh: send HTTPS RR requests for all HTTP(S) transfers
  - easy: allow connect-only handle reuse with easy_perform
  - easy: make curl_easy_perform() return error if connection still there
  - easy_lock: use Sleep(1) for thread yield on old Windows
  - ECH: update APIs to those agreed with OpenSSL maintainers
  - GnuTLS: fix 'time_appconnect' for early data
  - HTTP/2: strip TE request header
  - http2: fix data_pending check
  - http2: fix value stored to 'result' is never read
  - http: ignore invalid Retry-After times
  - http_aws_sigv4: Fix invalid compare function handling zero-length pairs
  - https-connect: start next immediately on failure
  - lib: redirect handling by protocol handler
  - multi: fix curl_multi_waitfds reporting of fd_count
  - netrc: 'default' with no credentials is not a match
  - netrc: fix password-only entries
  - netrc: restore _netrc fallback logic
  - ngtcp2: fix memory leak on connect failure
  - openssl: define `HAVE_KEYLOG_CALLBACK` before use
  - openssl: fix ECH logic
  - osslq: use SSL_poll to determine writeability of QUIC streams
  - sectransp: free certificate on error
  - select: avoid a NULL deref in cwfds_add_sock
  - src: omit hugehelp and ca-embed from libcurltool
  - ssl session cache: change cache dimensions
  - system.h: add 64-bit curl_off_t definitions for NonStop
  - telnet: handle single-byte input option
  - TLS: check connection for SSL use, not handler
  - tool_formparse.c: make curlx_uztoso a static in here
  - tool_formparse: accept digits in --form type= strings
  - tool_getparam: ECH param parsing refix
  - tool_getparam: fail --hostpubsha256 if libssh2 is not used
  - tool_getparam: fix "Ignored Return Value"
  - tool_getparam: fix memory leak on error in parse_ech
  - tool_getparam: fix the ECH parser
  - tool_operate: make --etag-compare always accept a non-existing file
  - transfer: fix CURLOPT_CURLU override logic
  - urlapi: fix redirect to a new fragment or query (only)
  - vquic: make vquic_send_packets not return without setting psent
  - vtls: fix default SSL backend as a fallback
  - vtls: only remember the expiry timestamp in session cache
  - websocket: fix message send corruption
  - x509asn1: add parse recursion limit
    * Rebase pathes:
  - libcurl-ocloexec.patch
  - dont-mess-with-rpmoptflags.patch

++++ kernel-default:

  - net: Add control functions for irq suspension (jsc#PED-12085).
  - net: Add napi_struct parameter irq_suspend_timeout (jsc#PED-12085).
  - netdev-genl: Support setting per-NAPI config values (jsc#PED-12085).
  - netdev-genl: Dump gro_flush_timeout (jsc#PED-12085).
  - netdev-genl: Dump napi_defer_hard_irqs (jsc#PED-12085).
  - commit ab1d6a3
  - iommufd: Fix struct iommu_hwpt_pgfault init and padding
    (git-fixes).
  - commit c2fe2e2
  - iommufd/fault: Destroy response and mutex in
    iommufd_fault_destroy() (git-fixes).
  - commit 4f00cba
  - sched: sch_cake: add bounds checks to host bulk flow fairness
    counts (CVE-2025-21647 bsc#1236133).
  - commit 1c89f89
  - x86/topology: Use x86_sched_itmt_flags for PKG domain unconditionally (jsc#PED-12062).
  - commit 744bcec
  - x86/topology: Remove x86_smt_flags and use cpu_smt_flags directly (jsc#PED-12062).
  - commit 069f91c
  - x86/itmt: Move the "sched_itmt_enabled" sysctl to debugfs (jsc#PED-12062).
  - commit 9c6e214
  - x86/itmt: Use guard() for itmt_update_mutex (jsc#PED-12062).
  - commit c195153
  - x86/itmt: Convert "sysctl_sched_itmt_enabled" to boolean (jsc#PED-12062).
  - commit 9dfc635

++++ kernel-firmware-all:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-amdgpu:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-ath10k:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-ath11k:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-ath12k:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-atheros:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-bluetooth:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-bnx2:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-brcm:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-chelsio:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-dpaa2:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-i915:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-intel:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-iwlwifi:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-liquidio:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-marvell:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-media:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-mediatek:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-mellanox:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-mwifiex:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-network:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-nfp:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-nvidia:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-platform:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-prestera:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-qcom:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-qlogic:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-radeon:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-realtek:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-serial:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-sound:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-ti:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-ueagle:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-firmware-usb-network:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

++++ kernel-rt:

  - net: Add control functions for irq suspension (jsc#PED-12085).
  - net: Add napi_struct parameter irq_suspend_timeout (jsc#PED-12085).
  - netdev-genl: Support setting per-NAPI config values (jsc#PED-12085).
  - netdev-genl: Dump gro_flush_timeout (jsc#PED-12085).
  - netdev-genl: Dump napi_defer_hard_irqs (jsc#PED-12085).
  - commit ab1d6a3
  - iommufd: Fix struct iommu_hwpt_pgfault init and padding
    (git-fixes).
  - commit c2fe2e2
  - iommufd/fault: Destroy response and mutex in
    iommufd_fault_destroy() (git-fixes).
  - commit 4f00cba
  - sched: sch_cake: add bounds checks to host bulk flow fairness
    counts (CVE-2025-21647 bsc#1236133).
  - commit 1c89f89
  - x86/topology: Use x86_sched_itmt_flags for PKG domain unconditionally (jsc#PED-12062).
  - commit 744bcec
  - x86/topology: Remove x86_smt_flags and use cpu_smt_flags directly (jsc#PED-12062).
  - commit 069f91c
  - x86/itmt: Move the "sched_itmt_enabled" sysctl to debugfs (jsc#PED-12062).
  - commit 9c6e214
  - x86/itmt: Use guard() for itmt_update_mutex (jsc#PED-12062).
  - commit c195153
  - x86/itmt: Convert "sysctl_sched_itmt_enabled" to boolean (jsc#PED-12062).
  - commit 9dfc635

++++ gcc15:

  - Adjust cross compiler requirements to use %requires_ge
  - Fix condition on whether to enable plugins or JIT support to
    not check sle_version which is not defined in SLFO but to check
    is_opensuse and suse_version instead.

++++ sqlite3:

  - Update to release 3.49.0:
    * Enhancements to the query planner:
  - Improve the query-time index optimization so that it works on
    WITHOUT ROWID tables.
  - Better query plans for large star-query joins. This fixes
    three different performance regressions that were reported
    on the SQLite Forum.
  - When two or more queries have the same estimated cost, use
    the one with the fewer bytes per row.
    * Enhance the iif() SQL function so that it can accept any number
    of arguments greater than or equal to two.
    * Enhance the session extension so that it works on databases
    that make use of generated columns.
    * Omit the SQLITE_USE_STDIO_FOR_CONSOLE compile-time option which
    was not implemented correctly and never worked right. In its place
    add the SQLITE_USE_W32_FOR_CONSOLE_IO compile-time option. This
    option applies to command-line tools like the CLI only, not to the
    SQLite core. It causes Win32 APIs to be used for console I/O
    instead of stdio. This option affects Windows builds only.
    * Three new options to sqlite3_db_config(). All default "on".
    SQLITE_DBCONFIG_ENABLE_ATTACH_CREATE
    SQLITE_DBCONFIG_ENABLE_ATTACH_WRITE
    SQLITE_DBCONFIG_ENABLE_COMMENTS

++++ systemd:

  - triggers.systemd: convert posix.fork() and posix.exec() to rpm.execute() (bsc#1236741)
  - Update 0009-pid1-handle-console-specificities-weirdness-for-s390.patch to not
    warn when "conmode=" is not specified on s390x (bsc#1236725).

++++ libtasn1:

  - libtasn1 4.20.0:
    * Fix CVE-2024-12133: Potential DoS in handling of numerous
    SEQUENCE OF or SET OF elements (boo#1236878)
    * The release tarball is now reproducible
    * Update gnulib files and various build/maintenance fixes.
  - update upstream signing key

++++ wtmpdb:

  - Update to version 0.71.0+git20250206.608632a:
    * Fix expected output of wtmpdb_rotate() test
    * Make header usable from C++

++++ pam_pkcs11:

  - Update to 0.6.13
    * Added pkcs11-eventmgr systemd service unit.
    * Updated Russian translations for pam_pkcs11 (thx Max Kosmach      and Andrey Cherepanov).
    * Fixed possible authentication bypass (CVE-2025-24032):
    * Use signatures to verify authentication by default      (thx Frank Morgner).
    * Fixed possible authentication bypass (CVE-2025-24531):
    * Restoring the original card_only / wait_for_card behavior      (thx Matthias Gerstner, Frank Morgner).
    * Move pam_securetty.so upward in the example PAM config.
    * Set 'slot_num' configuration parameter to 0 by default     (thx Jpereyra316).
    * Print details about configuration parse errors (thx Jpereyra316).
    * Add Chinese (Simplified) translation.
    * Capitalize all PAM messages (thx Alynx Zhou).
    * Made pkcs11_make_hash_link support whitespaces in file names
    * Drop 0001-Set-slot_num-configuration-parameter-to-0-by-default.patch
    * Drop 0001-memory-leak-fixes.patch
    * Rebase pam_pkcs11-0.5.3-nss-conf.patch
    * Rebase pam_pkcs11-0.6.0-nss-autoconf.patch

++++ skopeo:

  - Add patches for CVE-2024-6104 & CVE-2023-45288
    Add patches:
    * 0001-http2-close-connections-when-receiving-too-many-head.patch (CVE-2023-45288, bsc#1236483)
    * 0002-Switch-hashicorp-go-retryablehttp-to-the-SUSE-fork.patch (CVE-2024-6104, bsc#1227056)
    Remove patch:
    * 0001-Use-securejoin.SecureJoin-when-forming-userns-paths.patch
    Skopeo is not affected by the CVE-2024-9676, thus this patch is not necessary

++++ ucode-amd:

  - Split to each indiviaul build for each topic (bsc#1236966):
    the uncompressed big kernel-firmware package is deprecated now
  - Update to version 20250205 (git commit 429bdd620eb1):
    * amdgpu: DMCUB update for DCN401
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath12k: QCN9274 hw2.0: update to WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: update board-2.bin
    * ath11k: WCN6750 hw1.0: update board-2.bin
    * ath11k: QCN9074 hw1.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: QCA6698AQ hw2.1: add to WLAN.HSP.1.1-04479-QCAHSPSWPL_V1_V2_SILICONZ_IOE-1
    * ath11k: QCA6698AQ hw2.1: add board-2.bin
    * ath11k: QCA6390 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: update to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.6
    * ath11k: QCA2066 hw2.1: update board-2.bin
    * ath11k: IPQ8074 hw2.0: update to WLAN.HK.2.9.0.1-02146-QCAHKSWPL_SILICONZ-1
    * ath11k: IPQ6018 hw1.0: update to WLAN.HK.2.7.0.1-02409-QCAHKSWPL_SILICONZ-1
    * copy-firmware: Fix 'No such file or directory' error.
    * ath11k: add device-specific firmware for QCM6490 boards
    * qca: add more WCN3950 1.3 NVM files
    * qca: add firmware for WCN3950 chips
    * qca: move QCA6390 firmware to separate section
    * qca: restore licence information for WCN399x firmware
    * amdgpu: DMCUB updates for various ASICs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * qca: Update Bluetooth WCN6750 1.1.0-00476 firmware to 1.1.3-00069
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
    * qcom:x1e80100: Support for Lenovo T14s G6 Qualcomm platform
  - Update aliases from 6.13

------------------------------------------------------------------
------------------  2025-2-5  -  Feb 5 2025  -------------------
------------------------------------------------------------------

++++ chrony:

  - Update to version 4.6.1:
    * Add ntsaeads directive to enable only selected AEAD algorithms
    for NTS.
    * Negotiate use of compliant NTS keys with AES-128-GCM-SIV AEAD
    algorithm.
    * Switch to compliant NTS keys if first response from server is
    NTS NAK.

++++ lvm2-device-mapper:

  - thin-provisioning-tools 1.1.0 requires device-mapper-devel, this creates a cycle (boo#1236749)
    * update lvm2.spec
  - remove build require dependency thin-provisioning-tools from devicemapper
  - remove thin-provisioning-tools related configure options from devicemapper
  - remove a trivial empty line in extra_opts if default_use_devices_file=1

++++ diffutils:

  - diffutils 3.11:
    * quote file names more consistently in diagnostics
    * diff now outputs more information when symbolic links differ
    * diff's --ignore-case (-i) and --ignore-file-name-case options
    now support multi-byte characters
    * diff now supports multi-byte characters when treating white
    space
    * In options like --expand-tabs (-t), --ignore-space-change (-b)
    and --ignore-tab-expansion (-E), diff now recognizes non-ASCII
    space characters and counts columns for non-ASCII characters.
    * cmp -bl no longer omits "M-" from bytes with the high bit set
    in single-byte locales like en_US.iso8859-1
    * cmp -i N and -n N no longer fail merely because N is enormous.
    * cmp -s no longer mishandles /proc files
    * diff -E no longer mishandles some input lines containing '\a',
    '\b', '\f', '\r', '\v', or '\0'.
    * diff -ly no longer mishandles non-ASCII input.
    * diff - A/B now works correctly when standard input is a
    directory, by reading a file named B in that directory.
    * diff no longer suffers from race conditions in some cases when
    comparing files in a mutating file system

++++ gsettings-desktop-schemas:

  - Replace cantarell-fonts Recommends with adwaita-fonts: follow
    upstreams change from 48.beta.

++++ kernel-default:

  - RDMA/mlx5: Fix link status down event for MPV (git-fixes)
  - commit 34e8f80
  - Documentation/powerpc/fadump: add additional parameter feature
    details (bsc#1236743 ltc#211409).
  - powerpc: increase MIN RMA size for CAS negotiation (bsc#1236743
    ltc#211409).
  - powerpc/fadump: fix additional param memory reservation for
    HASH MMU (bsc#1236743 ltc#211409).
  - powerpc: export MIN RMA size (bsc#1236743 ltc#211409).
  - commit dbac901
  - vsock: Keep the binding until socket destruction (git-fixes)
  - commit 5950ee8
  - vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] (CVE-2025-21666 bsc#1236680)
  - commit 55d1d4a
  - vsock: reset socket state when de-assigning the transport (git-fixes)
  - commit 383ac2c
  - vsock/virtio: cancel close work in the destructor (git-fixes)
  - commit 4252990
  - vsock/bpf: return early if transport is not assigned (CVE-2025-21670 bsc#1236685)
  - commit e7946d0
  - vsock/virtio: discard packets if the transport changes (CVE-2025-21669 bsc#1236683)
  - commit a36ac6c
  - Update config files: disable tomoyo lsm (jsc#PED-12020)
  - commit 08c6cff
  - net/mlx5: Clear port select structure when fail to create (bsc#1236694 CVE-2025-21675)
  - commit 7d1f9fd
  - mptcp: fix TCP options overflow. (bsc#1235914 CVE-2024-57882)
  - commit edaa080
  - net: defer final 'struct net' free in netns dismantle
    (CVE-2024-56658 bsc#1235441).
  - commit d1e2d42
  - Refresh
    patches.suse/powerpc-book3s64-hugetlb-Fix-disabling-hugetlb-when-fadump-is-active.patch.
  - commit 4cd4a3a

++++ kernel-rt:

  - RDMA/mlx5: Fix link status down event for MPV (git-fixes)
  - commit 34e8f80
  - Documentation/powerpc/fadump: add additional parameter feature
    details (bsc#1236743 ltc#211409).
  - powerpc: increase MIN RMA size for CAS negotiation (bsc#1236743
    ltc#211409).
  - powerpc/fadump: fix additional param memory reservation for
    HASH MMU (bsc#1236743 ltc#211409).
  - powerpc: export MIN RMA size (bsc#1236743 ltc#211409).
  - commit dbac901
  - vsock: Keep the binding until socket destruction (git-fixes)
  - commit 5950ee8
  - vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] (CVE-2025-21666 bsc#1236680)
  - commit 55d1d4a
  - vsock: reset socket state when de-assigning the transport (git-fixes)
  - commit 383ac2c
  - vsock/virtio: cancel close work in the destructor (git-fixes)
  - commit 4252990
  - vsock/bpf: return early if transport is not assigned (CVE-2025-21670 bsc#1236685)
  - commit e7946d0
  - vsock/virtio: discard packets if the transport changes (CVE-2025-21669 bsc#1236683)
  - commit a36ac6c
  - Update config files: disable tomoyo lsm (jsc#PED-12020)
  - commit 08c6cff
  - net/mlx5: Clear port select structure when fail to create (bsc#1236694 CVE-2025-21675)
  - commit 7d1f9fd
  - mptcp: fix TCP options overflow. (bsc#1235914 CVE-2024-57882)
  - commit edaa080
  - net: defer final 'struct net' free in netns dismantle
    (CVE-2024-56658 bsc#1235441).
  - commit d1e2d42
  - Refresh
    patches.suse/powerpc-book3s64-hugetlb-Fix-disabling-hugetlb-when-fadump-is-active.patch.
  - commit 4cd4a3a

++++ lvm2:

  - thin-provisioning-tools 1.1.0 requires device-mapper-devel, this creates a cycle (boo#1236749)
    * update lvm2.spec
  - remove build require dependency thin-provisioning-tools from devicemapper
  - remove thin-provisioning-tools related configure options from devicemapper
  - remove a trivial empty line in extra_opts if default_use_devices_file=1

++++ python313-core:

  - Update to 3.13.2:
  - Tools/Demos
  - gh-128152: Fix a bug where Argument Clinic’s C
    pre-processor parser tried to parse pre-processor
    directives inside C comments. Patch by Erlend Aasland.
  - Tests
  - gh-127906: Test the limited C API in test_cppext. Patch by
    Victor Stinner.
  - gh-127637: Add tests for the dis command-line
    interface. Patch by Bénédikt Tran.
  - gh-126925: iOS test results are now streamed during test
    execution, and the deprecated xcresulttool is no longer
    used.
  - Security
  - gh-105704: When using urllib.parse.urlsplit() and
    urllib.parse.urlparse() host parsing would not reject
    domain names containing square brackets ([ and ]). Square
    brackets are only valid for IPv6 and IPvFuture hosts
    according to RFC 3986 Section 3.2.2. (CVE-2025-0938,
    bsc#1236705)
  - gh-127655: Fixed the
    asyncio.selector_events._SelectorSocketTransport
    transport not pausing writes for the protocol when
    the buffer reaches the high water mark when using
    asyncio.WriteTransport.writelines() (CVE-2024-12254,
    bsc#1234290).
  - gh-126108: Fix a possible NULL pointer dereference in
    PySys_AddWarnOptionUnicode().
  - gh-80222: Fix bug in the folding of quoted strings
    when flattening an email message using a modern email
    policy. Previously when a quoted string was folded so
    that it spanned more than one line, the surrounding
    quotes and internal escapes would be omitted. This could
    theoretically be used to spoof header lines using a
    carefully constructed quoted string if the resulting
    rendered email was transmitted or re-parsed.
  - gh-119511: Fix a potential denial of service in the imaplib
    module. When connecting to a malicious server, it could
    cause an arbitrary amount of memory to be allocated. On
    many systems this is harmless as unused virtual memory is
    only a mapping, but if this hit a virtual address size
    limit it could lead to a MemoryError or other process
    crash. On unusual systems or builds where all allocated
    memory is touched and backed by actual ram or storage
    it could’ve consumed resources doing so until similarly
    crashing.
  - Library
  - gh-129502: Unlikely errors in preparing arguments for
    ctypes callback are now handled in the same way as errors
    raised in the callback of in converting the result of
    the callback – using sys.unraisablehook() instead of
    sys.excepthook() and not setting sys.last_exc and other
    variables.
  - gh-129403: Corrected ValueError message for asyncio.Barrier
    and threading.Barrier.
  - gh-129409: Fix an integer overflow in the csv module when
    writing a data field larger than 2GB.
  - gh-118761: Improve import time of subprocess by lazy
    importing locale and signal. Patch by Taneli Hukkinen.
  - gh-129346: In sqlite3, handle out-of-memory when creating
    user-defined SQL functions.
  - gh-129061: Fix FORCE_COLOR and NO_COLOR when empty
    strings. Patch by Hugo van Kemenade.
  - gh-128550: Removed an incorrect optimization relating
    to eager tasks in asyncio.TaskGroup that resulted in
    cancellations being missed.
  - gh-128991: Release the enter frame reference within bdb
    callback
  - gh-128978: Fix a NameError in
    sysconfig.expand_makefile_vars(). Patch by Bénédikt Tran.
  - gh-128961: Fix a crash when setting state on an exhausted
    array.array iterator.
  - gh-128894: Fix
    traceback.TracebackException._format_syntax_error not to
    fail on exceptions with custom metadata.
  - gh-128916: Do not attempt to set SO_REUSEPORT on sockets of
    address families other than AF_INET and AF_INET6, as it is
    meaningless with these address families, and the call with
    fail with Linux kernel 6.12.9 and newer.
  - gh-128679: Fix tracemalloc.stop() race condition. Fix
    tracemalloc to support calling tracemalloc.stop() in
    one thread, while another thread is tracing memory
    allocations. Patch by Victor Stinner.
  - gh-128636: Fix PyREPL failure when os.environ is
    overwritten with an invalid value.
  - gh-128562: Fix possible conflicts in generated tkinter
    widget names if the widget class name ends with a digit.
  - gh-128498: Default to stdout isatty for color detection
    instead of stderr. Patch by Hugo van Kemenade.
  - gh-128552: Fix cyclic garbage introduced
    by asyncio.loop.create_task() and
    asyncio.TaskGroup.create_task() holding a reference to the
    created task if it is eager.
  - gh-128479: Fix asyncio.staggered.staggered_race() leaking
    tasks and issuing an unhandled exception.
  - gh-128400: Fix crash when using
    faulthandler.dump_traceback() while other threads are
    active on the free threaded build.
  - gh-88834: Unify the instance check for typing.Union and
    types.UnionType: Union now uses the instance checks against
    its parameters instead of the subclass checks.
  - gh-128302: Fix
    xml.dom.xmlbuilder.DOMEntityResolver.resolveEntity(), which
    was broken by the Python 3.0 transition.
  - gh-128302: Allow xml.dom.xmlbuilder.DOMParser.parse()
    to correctly handle xml.dom.xmlbuilder.DOMInputSource
    instances that only have a systemId attribute set.
  - gh-112064: Fix incorrect handling of negative read sizes in
    HTTPResponse.read. Patch by Yury Manushkin.
  - gh-58956: Fixed a frame reference leak in bdb.
  - gh-128131: Completely support random access of uncompressed
    unencrypted read-only zip files obtained by ZipFile.open.
  - gh-112328: enum.EnumDict can now be used without resorting
    to private API.
  - gh-127975: Avoid reusing quote types in ast.unparse() if
    not needed.
  - gh-128062: Revert the font of turtledemo’s menu bar to its
    default value and display the shortcut keys in the correct
    position.
  - gh-128014: Fix resetting the default window icon by passing
    default='' to the tkinter method wm_iconbitmap().
  - gh-115514: Fix exceptions and incomplete writes after
    asyncio._SelectorTransport is closed before writes are
    completed.
  - gh-41872: Fix quick extraction of module docstrings from
    a file in pydoc. It now supports docstrings with single
    quotes, escape sequences, raw string literals, and other
    Python syntax.
  - gh-127060: Set TERM environment variable to “dumb” to
    disable traceback colors in IDLE, since IDLE doesn’t
    understand ANSI escape sequences. Patch by Victor Stinner.
  - gh-126742: Fix support of localized error messages reported
    by dlerror(3) and gdbm_strerror in ctypes and dbm.gnu
    functions respectively. Patch by Bénédikt Tran.
  - gh-127873: When -E is set, only ignore PYTHON_COLORS
    and not FORCE_COLOR/NO_COLOR/TERM when colourising
    output. Patch by Hugo van Kemenade.
  - gh-127870: Detect recursive calls in ctypes _as_parameter_
    handling. Patch by Victor Stinner.
  - gh-127847: Fix the position when doing interleaved seeks
    and reads in uncompressed, unencrypted zip files returned
    by zipfile.ZipFile.open().
  - gh-127732: The platform module now correctly detects
    Windows Server 2025.
  - gh-126821: macOS and iOS apps can now choose to redirect
    stdout and stderr to the system log during interpreter
    configuration.
  - gh-93312: Include <sys/pidfd.h> to get os.PIDFD_NONBLOCK
    constant. Patch by Victor Stinner.
  - gh-83662: Add missing __class_getitem__ method to the
    Python implementation of functools.partial(), to make it
    compatible with the C version. This is mainly relevant for
    alternative Python implementations like PyPy and GraalPy,
    because CPython will usually use the C-implementation of
    that function.
  - gh-127586: multiprocessing.pool.Pool now properly restores
    blocked signal handlers of the parent thread when creating
    processes via either spawn or forkserver.
  - gh-98188: Fix an issue in
    email.message.Message.get_payload() where data cannot be
    decoded if the Content Transfer Encoding mechanism contains
    trailing whitespaces or additional junk text. Patch by Hui
    Liu.
  - gh-127257: In ssl, system call failures that OpenSSL
    reports using ERR_LIB_SYS are now raised as OSError.
  - gh-127096: Do not recreate unnamed section on every read in
    configparser.ConfigParser. Patch by Andrey Efremov.
  - gh-127196: Fix crash when dict with keys in invalid
    encoding were passed to several functions in _interpreters
    module.
  - gh-126775: Make linecache.checkcache() thread safe and GC
    re-entrancy safe.
  - gh-126332: Fix _pyrepl crash when entering a double CTRL-Z
    on an overflowing line.
  - gh-126225: getopt and optparse are no longer marked as
    deprecated. There are legitimate reasons to use one of
    these modules in preference to argparse, and none of these
    modules are at risk of being removed from the standard
    library. Of the three, argparse remains the recommended
    default choice, unless one of the concerns noted at the top
    of the optparse module documentation applies.
  - gh-125553: Fix round-trip invariance for backslash
    continuations in tokenize.untokenize().
  - gh-123987: Fixed issue in NamespaceReader where a non-path
    item in a namespace path, such as a sentinel added by an
    editable installer, would break resource loading.
  - gh-123401: The http.cookies module now supports parsing
    obsolete RFC 850 date formats, in accordance with RFC 9110
    requirements. Patch by Nano Zheng.
  - gh-122431: readline.append_history_file() now raises a
    ValueError when given a negative value.
  - gh-119257: Show tab completions menu below the current
    line, which results in less janky behaviour, and fixes a
    cursor movement bug. Patch by Daniel Hollas
  - Documentation
  - gh-125722: Require Sphinx 8.1.3 or later to build the
    Python documentation. Patch by Adam Turner.
  - gh-67206: Document that string.printable is not
    printable in the POSIX sense. In particular,
    string.printable.isprintable() returns False. Patch by
    Bénédikt Tran.
  - Core and Builtins
  - gh-129345: Fix null pointer dereference in syslog.openlog()
    when an audit hook raises an exception.
  - gh-129093: Fix f-strings such as f'{expr=}' sometimes not
    displaying the full expression when the expression contains
    !=.
  - gh-124363: Treat debug expressions in f-string as raw
    strings. Patch by Pablo Galindo
  - gh-128799: Add frame of except* to traceback when it wraps
    a naked exception.
  - gh-128078: Fix a SystemError when using anext() with a
    default tuple value. Patch by Bénédikt Tran.
  - gh-128717: Fix a crash when setting the recursion limit
    while other threads are active on the free threaded build.
  - gh-128330: Restore terminal control characters on REPL
    exit.
  - gh-128079: Fix a bug where except* does not properly check
    the return value of an ExceptionGroup’s split() function,
    leading to a crash in some cases. Now when split() returns
    an invalid object, except* raises a TypeError with the
    original raised ExceptionGroup object chained to it.
  - gh-128030: Avoid error from calling
    PyModule_GetFilenameObject on a non-module object when
    importing a non-existent symbol from a non-module object.
  - gh-127903: Objects/unicodeobject.c: fix a crash on DEBUG
    builds in _copy_characters when there is nothing to copy.
  - gh-127599: Fix statistics for increments of object
    reference counts (in particular, when a reference count was
    increased by more than 1 in a single operation).
  - gh-127651: When raising ImportError for missing symbols
    in from imports, use __file__ in the error message if
    __spec__.origin is not a location
  - gh-127582: Fix non-thread-safe object resurrection when
    calling finalizers and watcher callbacks in the free
    threading build.
  - gh-127434: The iOS compiler shims can now accept arguments
    with spaces.
  - gh-127536: Add missing locks around some list assignment
    operations in the free threading build.
  - gh-126862: Fix a possible overflow when a class inherits
    from an absurd number of super-classes. Reported by Valery
    Fedorenko. Patch by Bénédikt Tran.
  - gh-127349: Fixed the error when resizing terminal in Python
    REPL. Patch by Semyon Moroz.
  - gh-126076: Relocated objects such as tuple, bytes and
    str objects are properly tracked by tracemalloc and its
    associated hooks. Patch by Pablo Galindo.
  - C API
  - gh-127791: Fix loss of callbacks after more than one call
    to PyUnstable_AtExit().
  - Build
  - gh-129539: Don’t redefine EX_OK when the system has the
    sysexits.h header.
  - gh-128472: Skip BOLT optimization of functions using
    computed gotos, fixing errors on build with LLVM 19.
  - gh-123925: Fix building the curses module on platforms with
    libncurses but without libncursesw.
  - gh-128321: Set LIBS instead of LDFLAGS when checking if
    sqlite3 library functions are available. This fixes the
    ordering of linked libraries during checks, which was
    incorrect when using a statically linked libsqlite3.
  - gh-127865: Fix build failure on systems without
    thread-locals support.
  - Remove upstreamed patches:
  - CVE-2024-12254-unbound-mem-buffering-SelectorSocketTransport.writelines.patch
  - Add doc-py38-to-py36.patch to make documentation buildable on
    SLE with older Sphinx.

++++ tiff:

  - Update test/test_directory.c not to fail on big-endian machines.
    * Add tiff-4.7.0-test_directory.patch
    Fix memory leaks (fixes issue #652)
    * Resolves bsc#1236834
    fix build fail on s390x

++++ python313:

  - Update to 3.13.2:
  - Tools/Demos
  - gh-128152: Fix a bug where Argument Clinic’s C
    pre-processor parser tried to parse pre-processor
    directives inside C comments. Patch by Erlend Aasland.
  - Tests
  - gh-127906: Test the limited C API in test_cppext. Patch by
    Victor Stinner.
  - gh-127637: Add tests for the dis command-line
    interface. Patch by Bénédikt Tran.
  - gh-126925: iOS test results are now streamed during test
    execution, and the deprecated xcresulttool is no longer
    used.
  - Security
  - gh-105704: When using urllib.parse.urlsplit() and
    urllib.parse.urlparse() host parsing would not reject
    domain names containing square brackets ([ and ]). Square
    brackets are only valid for IPv6 and IPvFuture hosts
    according to RFC 3986 Section 3.2.2. (CVE-2025-0938,
    bsc#1236705)
  - gh-127655: Fixed the
    asyncio.selector_events._SelectorSocketTransport
    transport not pausing writes for the protocol when
    the buffer reaches the high water mark when using
    asyncio.WriteTransport.writelines() (CVE-2024-12254,
    bsc#1234290).
  - gh-126108: Fix a possible NULL pointer dereference in
    PySys_AddWarnOptionUnicode().
  - gh-80222: Fix bug in the folding of quoted strings
    when flattening an email message using a modern email
    policy. Previously when a quoted string was folded so
    that it spanned more than one line, the surrounding
    quotes and internal escapes would be omitted. This could
    theoretically be used to spoof header lines using a
    carefully constructed quoted string if the resulting
    rendered email was transmitted or re-parsed.
  - gh-119511: Fix a potential denial of service in the imaplib
    module. When connecting to a malicious server, it could
    cause an arbitrary amount of memory to be allocated. On
    many systems this is harmless as unused virtual memory is
    only a mapping, but if this hit a virtual address size
    limit it could lead to a MemoryError or other process
    crash. On unusual systems or builds where all allocated
    memory is touched and backed by actual ram or storage
    it could’ve consumed resources doing so until similarly
    crashing.
  - Library
  - gh-129502: Unlikely errors in preparing arguments for
    ctypes callback are now handled in the same way as errors
    raised in the callback of in converting the result of
    the callback – using sys.unraisablehook() instead of
    sys.excepthook() and not setting sys.last_exc and other
    variables.
  - gh-129403: Corrected ValueError message for asyncio.Barrier
    and threading.Barrier.
  - gh-129409: Fix an integer overflow in the csv module when
    writing a data field larger than 2GB.
  - gh-118761: Improve import time of subprocess by lazy
    importing locale and signal. Patch by Taneli Hukkinen.
  - gh-129346: In sqlite3, handle out-of-memory when creating
    user-defined SQL functions.
  - gh-129061: Fix FORCE_COLOR and NO_COLOR when empty
    strings. Patch by Hugo van Kemenade.
  - gh-128550: Removed an incorrect optimization relating
    to eager tasks in asyncio.TaskGroup that resulted in
    cancellations being missed.
  - gh-128991: Release the enter frame reference within bdb
    callback
  - gh-128978: Fix a NameError in
    sysconfig.expand_makefile_vars(). Patch by Bénédikt Tran.
  - gh-128961: Fix a crash when setting state on an exhausted
    array.array iterator.
  - gh-128894: Fix
    traceback.TracebackException._format_syntax_error not to
    fail on exceptions with custom metadata.
  - gh-128916: Do not attempt to set SO_REUSEPORT on sockets of
    address families other than AF_INET and AF_INET6, as it is
    meaningless with these address families, and the call with
    fail with Linux kernel 6.12.9 and newer.
  - gh-128679: Fix tracemalloc.stop() race condition. Fix
    tracemalloc to support calling tracemalloc.stop() in
    one thread, while another thread is tracing memory
    allocations. Patch by Victor Stinner.
  - gh-128636: Fix PyREPL failure when os.environ is
    overwritten with an invalid value.
  - gh-128562: Fix possible conflicts in generated tkinter
    widget names if the widget class name ends with a digit.
  - gh-128498: Default to stdout isatty for color detection
    instead of stderr. Patch by Hugo van Kemenade.
  - gh-128552: Fix cyclic garbage introduced
    by asyncio.loop.create_task() and
    asyncio.TaskGroup.create_task() holding a reference to the
    created task if it is eager.
  - gh-128479: Fix asyncio.staggered.staggered_race() leaking
    tasks and issuing an unhandled exception.
  - gh-128400: Fix crash when using
    faulthandler.dump_traceback() while other threads are
    active on the free threaded build.
  - gh-88834: Unify the instance check for typing.Union and
    types.UnionType: Union now uses the instance checks against
    its parameters instead of the subclass checks.
  - gh-128302: Fix
    xml.dom.xmlbuilder.DOMEntityResolver.resolveEntity(), which
    was broken by the Python 3.0 transition.
  - gh-128302: Allow xml.dom.xmlbuilder.DOMParser.parse()
    to correctly handle xml.dom.xmlbuilder.DOMInputSource
    instances that only have a systemId attribute set.
  - gh-112064: Fix incorrect handling of negative read sizes in
    HTTPResponse.read. Patch by Yury Manushkin.
  - gh-58956: Fixed a frame reference leak in bdb.
  - gh-128131: Completely support random access of uncompressed
    unencrypted read-only zip files obtained by ZipFile.open.
  - gh-112328: enum.EnumDict can now be used without resorting
    to private API.
  - gh-127975: Avoid reusing quote types in ast.unparse() if
    not needed.
  - gh-128062: Revert the font of turtledemo’s menu bar to its
    default value and display the shortcut keys in the correct
    position.
  - gh-128014: Fix resetting the default window icon by passing
    default='' to the tkinter method wm_iconbitmap().
  - gh-115514: Fix exceptions and incomplete writes after
    asyncio._SelectorTransport is closed before writes are
    completed.
  - gh-41872: Fix quick extraction of module docstrings from
    a file in pydoc. It now supports docstrings with single
    quotes, escape sequences, raw string literals, and other
    Python syntax.
  - gh-127060: Set TERM environment variable to “dumb” to
    disable traceback colors in IDLE, since IDLE doesn’t
    understand ANSI escape sequences. Patch by Victor Stinner.
  - gh-126742: Fix support of localized error messages reported
    by dlerror(3) and gdbm_strerror in ctypes and dbm.gnu
    functions respectively. Patch by Bénédikt Tran.
  - gh-127873: When -E is set, only ignore PYTHON_COLORS
    and not FORCE_COLOR/NO_COLOR/TERM when colourising
    output. Patch by Hugo van Kemenade.
  - gh-127870: Detect recursive calls in ctypes _as_parameter_
    handling. Patch by Victor Stinner.
  - gh-127847: Fix the position when doing interleaved seeks
    and reads in uncompressed, unencrypted zip files returned
    by zipfile.ZipFile.open().
  - gh-127732: The platform module now correctly detects
    Windows Server 2025.
  - gh-126821: macOS and iOS apps can now choose to redirect
    stdout and stderr to the system log during interpreter
    configuration.
  - gh-93312: Include <sys/pidfd.h> to get os.PIDFD_NONBLOCK
    constant. Patch by Victor Stinner.
  - gh-83662: Add missing __class_getitem__ method to the
    Python implementation of functools.partial(), to make it
    compatible with the C version. This is mainly relevant for
    alternative Python implementations like PyPy and GraalPy,
    because CPython will usually use the C-implementation of
    that function.
  - gh-127586: multiprocessing.pool.Pool now properly restores
    blocked signal handlers of the parent thread when creating
    processes via either spawn or forkserver.
  - gh-98188: Fix an issue in
    email.message.Message.get_payload() where data cannot be
    decoded if the Content Transfer Encoding mechanism contains
    trailing whitespaces or additional junk text. Patch by Hui
    Liu.
  - gh-127257: In ssl, system call failures that OpenSSL
    reports using ERR_LIB_SYS are now raised as OSError.
  - gh-127096: Do not recreate unnamed section on every read in
    configparser.ConfigParser. Patch by Andrey Efremov.
  - gh-127196: Fix crash when dict with keys in invalid
    encoding were passed to several functions in _interpreters
    module.
  - gh-126775: Make linecache.checkcache() thread safe and GC
    re-entrancy safe.
  - gh-126332: Fix _pyrepl crash when entering a double CTRL-Z
    on an overflowing line.
  - gh-126225: getopt and optparse are no longer marked as
    deprecated. There are legitimate reasons to use one of
    these modules in preference to argparse, and none of these
    modules are at risk of being removed from the standard
    library. Of the three, argparse remains the recommended
    default choice, unless one of the concerns noted at the top
    of the optparse module documentation applies.
  - gh-125553: Fix round-trip invariance for backslash
    continuations in tokenize.untokenize().
  - gh-123987: Fixed issue in NamespaceReader where a non-path
    item in a namespace path, such as a sentinel added by an
    editable installer, would break resource loading.
  - gh-123401: The http.cookies module now supports parsing
    obsolete RFC 850 date formats, in accordance with RFC 9110
    requirements. Patch by Nano Zheng.
  - gh-122431: readline.append_history_file() now raises a
    ValueError when given a negative value.
  - gh-119257: Show tab completions menu below the current
    line, which results in less janky behaviour, and fixes a
    cursor movement bug. Patch by Daniel Hollas
  - Documentation
  - gh-125722: Require Sphinx 8.1.3 or later to build the
    Python documentation. Patch by Adam Turner.
  - gh-67206: Document that string.printable is not
    printable in the POSIX sense. In particular,
    string.printable.isprintable() returns False. Patch by
    Bénédikt Tran.
  - Core and Builtins
  - gh-129345: Fix null pointer dereference in syslog.openlog()
    when an audit hook raises an exception.
  - gh-129093: Fix f-strings such as f'{expr=}' sometimes not
    displaying the full expression when the expression contains
    !=.
  - gh-124363: Treat debug expressions in f-string as raw
    strings. Patch by Pablo Galindo
  - gh-128799: Add frame of except* to traceback when it wraps
    a naked exception.
  - gh-128078: Fix a SystemError when using anext() with a
    default tuple value. Patch by Bénédikt Tran.
  - gh-128717: Fix a crash when setting the recursion limit
    while other threads are active on the free threaded build.
  - gh-128330: Restore terminal control characters on REPL
    exit.
  - gh-128079: Fix a bug where except* does not properly check
    the return value of an ExceptionGroup’s split() function,
    leading to a crash in some cases. Now when split() returns
    an invalid object, except* raises a TypeError with the
    original raised ExceptionGroup object chained to it.
  - gh-128030: Avoid error from calling
    PyModule_GetFilenameObject on a non-module object when
    importing a non-existent symbol from a non-module object.
  - gh-127903: Objects/unicodeobject.c: fix a crash on DEBUG
    builds in _copy_characters when there is nothing to copy.
  - gh-127599: Fix statistics for increments of object
    reference counts (in particular, when a reference count was
    increased by more than 1 in a single operation).
  - gh-127651: When raising ImportError for missing symbols
    in from imports, use __file__ in the error message if
    __spec__.origin is not a location
  - gh-127582: Fix non-thread-safe object resurrection when
    calling finalizers and watcher callbacks in the free
    threading build.
  - gh-127434: The iOS compiler shims can now accept arguments
    with spaces.
  - gh-127536: Add missing locks around some list assignment
    operations in the free threading build.
  - gh-126862: Fix a possible overflow when a class inherits
    from an absurd number of super-classes. Reported by Valery
    Fedorenko. Patch by Bénédikt Tran.
  - gh-127349: Fixed the error when resizing terminal in Python
    REPL. Patch by Semyon Moroz.
  - gh-126076: Relocated objects such as tuple, bytes and
    str objects are properly tracked by tracemalloc and its
    associated hooks. Patch by Pablo Galindo.
  - C API
  - gh-127791: Fix loss of callbacks after more than one call
    to PyUnstable_AtExit().
  - Build
  - gh-129539: Don’t redefine EX_OK when the system has the
    sysexits.h header.
  - gh-128472: Skip BOLT optimization of functions using
    computed gotos, fixing errors on build with LLVM 19.
  - gh-123925: Fix building the curses module on platforms with
    libncurses but without libncursesw.
  - gh-128321: Set LIBS instead of LDFLAGS when checking if
    sqlite3 library functions are available. This fixes the
    ordering of linked libraries during checks, which was
    incorrect when using a statically linked libsqlite3.
  - gh-127865: Fix build failure on systems without
    thread-locals support.
  - Remove upstreamed patches:
  - CVE-2024-12254-unbound-mem-buffering-SelectorSocketTransport.writelines.patch
  - Add doc-py38-to-py36.patch to make documentation buildable on
    SLE with older Sphinx.

++++ python-gobject:

  - Update to version 3.51.0:
    + Use `girepository` 2.0 for GIR mappings.
    + Use Python's vectorcall protocol internally.
    + Improved API for asyncio.
    + Deprecation: The pygtkcompat module now throws an exception
    when imported.
    + Method signatures are exposed from PyGObject now.
    + Convenience API for Gdk.RGBA got GDK 4, similar to GDK 3.
    + Use standard `enum` module for enums and flags in PyGObject.
    + Added an option to skip automatic initialization of GTK and
    GDK.
    + Fixed iterator protocol implementation for properties.
    + Various code and documentation improvements.

++++ python-legacy-cgi:

  - Update to 2.6.2
    * Remove the <4 Python requirement

++++ qemu:

  - Fix bsc#1235709:
    * target/s390x: Fix MVC not always invalidating translation blocks

------------------------------------------------------------------
------------------  2025-2-4  -  Feb 4 2025  -------------------
------------------------------------------------------------------

++++ ca-certificates-mozilla:

  - update to 2.74 state of Mozilla SSL root CAs:
    Removed:
    * SwissSign Silver CA - G2
    Added:
    * D-TRUST BR Root CA 2 2023
    * D-TRUST EV Root CA 2 2023
  - remove extensive signature printing in comments of the cert
    bundle

++++ checkpolicy:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * Code improvements and bug fixes
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ cloud-init:

  - Add cloud-init-direxist.patch (bsc#1236720)
    + Make sure the directory exists, if not create it, before writing in that
    location.

++++ container-selinux:

  - OBS service file: use the tagged commit for archive versioning and don't
    just archive the latest changes from the main branch using the latest tag

++++ crypto-policies:

  - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165]
    * openssl: stricter enabling of Ciphersuites
    * openssl: make use of -CBC and -AESGCM keywords
    * openssl: add TLS 1.3 Brainpool identifiers
    * fix warning on using experimental key_exchanges
    * update-crypto-policies: don't output FIPS warning in fips mode
    * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256
    * openssh, libssh: refactor kx maps to use tuples
    * alg_lists: mark MLKEM768/SNTRUP kex experimental
    * nss: revert enabling mlkem768secp256r1
    * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber
    * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768
    * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768
    * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768
    * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256
    * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384...
    * python/update-crypto-policies: pacify pylint
    * fips-mode-setup: tolerate fips dracut module presence w/o FIPS
    * fips-mode-setup: small Argon2 detection fix
    * SHA1: add __openssl_block_sha1_signatures = 0
    * fips-mode-setup: block if LUKS devices using Argon2 are detected
    * update-crypto-policies: skip warning on --set=FIPS if bootc
    * fips-setup-helper: skip warning, BTW
    * fips-mode-setup: force --no-bootcfg when UKI is detected
    * fips-setup-helper: add a libexec helper for anaconda
    * fips-crypto-policy-overlay: automount FIPS policy
    * openssh: make dss no longer enableble, support is dropped
    * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768
    * DEFAULT: switch to rh-allow-sha1-signatures = no...
    * java: drop unused javasystem backend
    * java: stop specifying jdk.tls.namedGroups in javasystem
    * ec_min_size: introduce and use in java, default to 256
    * java: use and include jdk.disabled.namedCurves
    * BSI: Update BSI policy for new 2024 minimum recommendations
    * fips-mode-setup: flashy ticking warning upon use
    * fips-mode-setup: add another scary "unsupported"
    * CONTRIBUTING.md: add a small section on updating policies
    * CONTRIBUTING.md: remove trailing punctuation from headers
    * BSI: switch to 3072 minimum RSA key size
    * java: make hash, mac and sign more orthogonal
    * java: specify jdk.tls.namedGroups system property
    * java: respect more key size restrictions
    * java: disable anon ciphersuites, tying them to NULL...
    * java: start controlling / disable DTLSv1.0
    * nss: wire KYBER768 to XYBER768D00
    * nss: unconditionally load p11-kit-proxy.so
    * gnutls: make DTLS0.9 controllable again
    * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH
    * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE
    * gnutls: remove extraneous newline
    * sequoia: move away from subprocess.getstatusoutput
    * python/cryptopolicies/cryptopolicies.py: add trailing commas
    * python, tests: rename MalformedLine to MalformedLineError
    * Makefile: introduce SKIP_LINTING flag for packagers to use
    * Makefile: run ruff
    * tests: use pathlib
    * tests: run(check=True) + CalledProcessError where convenient
    * tests: use subprocess.run
    * tests/krb5.py: check all generated policies
    * tests: print to stderr on error paths
    * tests/nss.py: also use encoding='utf-8'
    * tests/nss.py: also use removesuffix
    * tests/nss.py: skip creating tempfiles
    * tests/java.pl -> tests/java.py
    * tests/gnutls.pl -> tests/gnutls.py
    * tests/openssl.pl -> tests/openssl.py
    * tests/verify-output.pl: remove
    * libreswan: do not use up pfs= / ikev2= keywords for default behaviour
    * Rebase patches:
  - crypto-policies-no-build-manpages.patch
  - crypto-policies-policygenerators.patch
  - crypto-policies-supported.patch
  - crypto-policies-nss.patch

++++ findutils:

  - do not crash when file system loop was encountered [bsc#1231472]
  - added patches
    fix https://git.savannah.gnu.org/cgit/findutils.git/commit/?id=e5d6eb919b9
    + findutils-avoid-crash-system-loop.patch
  - modified patches
    % findutils-xautofs.patch (p1)

++++ gsettings-desktop-schemas:

  - Update to version 48.beta:
    + Switch to Adwaita Fonts
    + Split data recording and limits in time limits schema
    + Set more useful defaults on stylus buttons
    + Updated translations.

++++ kernel-default:

  - mm/compaction: fix UBSAN shift-out-of-bounds warning (git fixes
    (mm/compaction)).
  - commit 42344d4
  - mm: don't try THP alignment for FS without get_unmapped_area
    (bsc#1236648).
  - commit 95593b1
  - mm: respect mmap hint address when aligning for THP
    (bsc#1236648).
  - commit 1ea50ed
  - mm: remove unnecessary page_table_lock on stack expansion
    (bsc#1236648).
  - commit 6f2730b
  - mm: remove misleading 'unlikely' hint in
    vms_gather_munmap_vmas() (bsc#1236648).
  - commit 5eed911
  - mm: correct typo in MMAP_STATE() macro (bsc#1236648).
  - vma: detect infinite loop in vma tree (bsc#1236648).
  - commit f1dbf1d
  - Update
    patches.suse/nvme-tcp-Fix-I-O-queue-cpu-spreading-for-multiple-co.patch
    (git-fixes bsc#1224049).
  - commit b40b27f
  - xfs: Add error handling for xfs_reflink_cancel_cow_range
    (git-fixes).
  - commit b508427
  - xfs: Propagate errors from xfs_reflink_cancel_cow_range in
    xfs_dax_write_iomap_end (git-fixes).
  - commit e231dcf
  - xfs: don't call remap_verify_area with sb write protection held
    (git-fixes).
  - commit b243b98
  - r8169: enable SG/TSO on selected chip versions per default
    (bsc#1235874).
  - commit 2795291
  - tools: ynl: c: correct reverse decode of empty attrs
    (git-fixes).
  - net/mlx5e: Fix inversion dependency warning while enabling
    IPsec tunnel (CVE-2025-21674 bsc#1236688).
  - net: fec: handle page_pool_dev_alloc_pages error (CVE-2025-21676
    bsc#1236696).
  - pfcp: Destroy device along with udp socket's netns dismantle
    (CVE-2025-21677 bsc#1236697).
  - gtp: Destroy device along with udp socket's netns dismantle
    (CVE-2025-21678 bsc#1236698).
  - gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp()
    (git-fixes).
  - eth: bnxt: always recalculate features after XDP clearing,
    fix null-deref (CVE-2025-21682 bsc#1236703).
  - commit 7d6efad
  - Update config files: Switch to CONFIG_PREEMPT_RT
  - commit af14e50
  - selftests/bpf: validate that tail call invalidates packet
    pointers (git-fixes).
  - bpf: consider that tail calls invalidate packet pointers
    (git-fixes).
  - bpf: refactor bpf_helper_changes_pkt_data to use helper number
    (git-fixes).
  - bpf: Remove unnecessary kfree(im_node) in lpm_trie_update_elem
    (git-fixes).
  - bpf: Zero index arg error string for dynptr and iter
    (git-fixes).
  - selftests/bpf: Add tests for iter arg check (git-fixes).
  - bpf: Ensure reg is PTR_TO_STACK in process_iter_arg (git-fixes).
  - bpftool: fix potential NULL pointer dereferencing in prog_dump()
    (git-fixes).
  - bpf: put bpf_link's program when link is safe to be deallocated
    (git-fixes).
  - selftests/bpf: Add push/pop checking for msg_verify_data in
    test_sockmap (git-fixes).
  - selftests/bpf: Fix total_bytes in msg_loop_rx in test_sockmap
    (git-fixes).
  - selftests/bpf: Fix SENDPAGE data logic in test_sockmap
    (git-fixes).
  - selftests/bpf: Add txmsg_pass to pull/push/pop in test_sockmap
    (git-fixes).
  - selftests/bpf: Fix txmsg_redir of test_txmsg_pull in
    test_sockmap (git-fixes).
  - selftests/bpf: Fix msg_verify_data in test_sockmap (git-fixes).
  - selftests/bpf: add missing header include for htons (git-fixes).
  - bpf: Add kernel symbol for struct_ops trampoline (git-fixes).
  - bpf: Use function pointers count as struct_ops links count
    (git-fixes).
  - selftests/bpf: skip the timer_lockup test for single-CPU nodes
    (git-fixes).
  - selftests/bpf: Test the update operations for htab of maps
    (git-fixes).
  - selftests/bpf: Move ENOTSUPP from bpf_util.h (git-fixes).
  - bpf: Call free_htab_elem() after htab_unlock_bucket()
    (git-fixes).
  - selftests/bpf: Add kprobe session verifier test for return value
    (git-fixes).
  - bpf: Allow return values 0 and 1 for kprobe session (git-fixes).
  - selftests/bpf: Clean up open-coded gettid syscall invocations
    (git-fixes).
  - selftests/bpf: Add tests for tail calls with locks and refs
    (git-fixes).
  - bpf: Unify resource leak checks (git-fixes).
  - bpf: Tighten tail call checks for lingering locks, RCU,
    preempt_disable (git-fixes).
  - bpf, bpftool: Fix incorrect disasm pc (git-fixes).
  - libbpf: move global data mmap()'ing into bpf_object__load()
    (git-fixes).
  - selftests/bpf: fix test_spin_lock_fail.c's global vars usage
    (git-fixes).
  - selftests/bpf: Add test to verify tailcall and freplace
    restrictions (git-fixes).
  - bpf: Prevent tailcall infinite loop caused by freplace
    (git-fixes).
  - libbpf: never interpret subprogs in .text as entry programs
    (git-fixes).
  - samples/bpf: Fix a resource leak (git-fixes).
  - libbpf: fix sym_is_subprog() logic for weak global subprogs
    (git-fixes).
  - selftests/bpf: Fix backtrace printing for selftests crashes
    (git-fixes).
  - bpf: Fix the xdp_adjust_tail sample prog issue (git-fixes).
  - selftests: bpf: Add missing per-arch include path (git-fixes).
  - libbpf: Add missing per-arch include path (git-fixes).
  - libbpf: Fix output .symtab byte-order during linking
    (git-fixes).
  - selftests/bpf: Fix uprobe_multi compilation error (git-fixes).
  - libbpf: Fix expected_attach_type set handling in program load
    callback (git-fixes).
  - commit 9b2dc81

++++ kernel-rt:

  - mm/compaction: fix UBSAN shift-out-of-bounds warning (git fixes
    (mm/compaction)).
  - commit 42344d4
  - mm: don't try THP alignment for FS without get_unmapped_area
    (bsc#1236648).
  - commit 95593b1
  - mm: respect mmap hint address when aligning for THP
    (bsc#1236648).
  - commit 1ea50ed
  - mm: remove unnecessary page_table_lock on stack expansion
    (bsc#1236648).
  - commit 6f2730b
  - mm: remove misleading 'unlikely' hint in
    vms_gather_munmap_vmas() (bsc#1236648).
  - commit 5eed911
  - mm: correct typo in MMAP_STATE() macro (bsc#1236648).
  - vma: detect infinite loop in vma tree (bsc#1236648).
  - commit f1dbf1d
  - Update
    patches.suse/nvme-tcp-Fix-I-O-queue-cpu-spreading-for-multiple-co.patch
    (git-fixes bsc#1224049).
  - commit b40b27f
  - xfs: Add error handling for xfs_reflink_cancel_cow_range
    (git-fixes).
  - commit b508427
  - xfs: Propagate errors from xfs_reflink_cancel_cow_range in
    xfs_dax_write_iomap_end (git-fixes).
  - commit e231dcf
  - xfs: don't call remap_verify_area with sb write protection held
    (git-fixes).
  - commit b243b98
  - r8169: enable SG/TSO on selected chip versions per default
    (bsc#1235874).
  - commit 2795291
  - tools: ynl: c: correct reverse decode of empty attrs
    (git-fixes).
  - net/mlx5e: Fix inversion dependency warning while enabling
    IPsec tunnel (CVE-2025-21674 bsc#1236688).
  - net: fec: handle page_pool_dev_alloc_pages error (CVE-2025-21676
    bsc#1236696).
  - pfcp: Destroy device along with udp socket's netns dismantle
    (CVE-2025-21677 bsc#1236697).
  - gtp: Destroy device along with udp socket's netns dismantle
    (CVE-2025-21678 bsc#1236698).
  - gtp: Use for_each_netdev_rcu() in gtp_genl_dump_pdp()
    (git-fixes).
  - eth: bnxt: always recalculate features after XDP clearing,
    fix null-deref (CVE-2025-21682 bsc#1236703).
  - commit 7d6efad
  - Update config files: Switch to CONFIG_PREEMPT_RT
  - commit af14e50
  - selftests/bpf: validate that tail call invalidates packet
    pointers (git-fixes).
  - bpf: consider that tail calls invalidate packet pointers
    (git-fixes).
  - bpf: refactor bpf_helper_changes_pkt_data to use helper number
    (git-fixes).
  - bpf: Remove unnecessary kfree(im_node) in lpm_trie_update_elem
    (git-fixes).
  - bpf: Zero index arg error string for dynptr and iter
    (git-fixes).
  - selftests/bpf: Add tests for iter arg check (git-fixes).
  - bpf: Ensure reg is PTR_TO_STACK in process_iter_arg (git-fixes).
  - bpftool: fix potential NULL pointer dereferencing in prog_dump()
    (git-fixes).
  - bpf: put bpf_link's program when link is safe to be deallocated
    (git-fixes).
  - selftests/bpf: Add push/pop checking for msg_verify_data in
    test_sockmap (git-fixes).
  - selftests/bpf: Fix total_bytes in msg_loop_rx in test_sockmap
    (git-fixes).
  - selftests/bpf: Fix SENDPAGE data logic in test_sockmap
    (git-fixes).
  - selftests/bpf: Add txmsg_pass to pull/push/pop in test_sockmap
    (git-fixes).
  - selftests/bpf: Fix txmsg_redir of test_txmsg_pull in
    test_sockmap (git-fixes).
  - selftests/bpf: Fix msg_verify_data in test_sockmap (git-fixes).
  - selftests/bpf: add missing header include for htons (git-fixes).
  - bpf: Add kernel symbol for struct_ops trampoline (git-fixes).
  - bpf: Use function pointers count as struct_ops links count
    (git-fixes).
  - selftests/bpf: skip the timer_lockup test for single-CPU nodes
    (git-fixes).
  - selftests/bpf: Test the update operations for htab of maps
    (git-fixes).
  - selftests/bpf: Move ENOTSUPP from bpf_util.h (git-fixes).
  - bpf: Call free_htab_elem() after htab_unlock_bucket()
    (git-fixes).
  - selftests/bpf: Add kprobe session verifier test for return value
    (git-fixes).
  - bpf: Allow return values 0 and 1 for kprobe session (git-fixes).
  - selftests/bpf: Clean up open-coded gettid syscall invocations
    (git-fixes).
  - selftests/bpf: Add tests for tail calls with locks and refs
    (git-fixes).
  - bpf: Unify resource leak checks (git-fixes).
  - bpf: Tighten tail call checks for lingering locks, RCU,
    preempt_disable (git-fixes).
  - bpf, bpftool: Fix incorrect disasm pc (git-fixes).
  - libbpf: move global data mmap()'ing into bpf_object__load()
    (git-fixes).
  - selftests/bpf: fix test_spin_lock_fail.c's global vars usage
    (git-fixes).
  - selftests/bpf: Add test to verify tailcall and freplace
    restrictions (git-fixes).
  - bpf: Prevent tailcall infinite loop caused by freplace
    (git-fixes).
  - libbpf: never interpret subprogs in .text as entry programs
    (git-fixes).
  - samples/bpf: Fix a resource leak (git-fixes).
  - libbpf: fix sym_is_subprog() logic for weak global subprogs
    (git-fixes).
  - selftests/bpf: Fix backtrace printing for selftests crashes
    (git-fixes).
  - bpf: Fix the xdp_adjust_tail sample prog issue (git-fixes).
  - selftests: bpf: Add missing per-arch include path (git-fixes).
  - libbpf: Add missing per-arch include path (git-fixes).
  - libbpf: Fix output .symtab byte-order during linking
    (git-fixes).
  - selftests/bpf: Fix uprobe_multi compilation error (git-fixes).
  - libbpf: Fix expected_attach_type set handling in program load
    callback (git-fixes).
  - commit 9b2dc81

++++ dtc:

  - Mark assembler output as noexecstack

++++ libseccomp:

  - add 62-sim-arch_transactions-remove-fuzzer.patch to fix s390x build
    (https://github.com/seccomp/libseccomp/issues/455)

++++ libselinux:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * libselinux: deprecate security_disable(3)
    * libselinux/utils: introduce selabel_compare
    * improved selabel_lookup performance
    * libselinux: support parallel usage of selabel_lookup(3)
    * Improved man pages
    * Always build for LFS mode on 32-bit archs.
    * Binary fcontext files format changed, files using old format are ignored
    * Code improvements and bug fixes
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - Drop libselinux-set-free-d-data-to-NULL.patch: included upstream
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ libsemanage:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * libsemanage: Preserve file context and ownership in policy store
    * libsemanage: Optionally allow duplicate declarations
    * Improved man pages
    * libsemanage: Mute error messages from selinux_restorecon introduced in 3.8-rc1
    * Code improvements and bug fixes
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ libsepol:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * libsepol: Support nlmsg extended permissions
    * libsepol: Add policy capability netlink_xperm
    * libsepol: add support for xperms in conditional policies
    * Code improvements and bug fixes
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ libssh:

  - Do not Require cmake from the devel package: there is no
    requirement that consumers would be using cmake.
  - Own %{_libdir}/cmake to not leave traces when uninstalling the
    package and being the only one left installing files to that
    directory.

++++ systemd:

  - Move systemd-userwork from the experimental sub-package to the main package (bsc#1236643)
    It is likely an oversight from when systemd-userdb was migrated from the
    experimental package to the main one.

++++ libxkbcommon:

  - Update to release 1.8
    * `NoSymbol` is now systematically dropped in multi-keysyms
    levels.
    * Added the upper case mapping ß → ẞ (`ssharp` → `U1E9E`). This
    enable to type ẞ using CapsLock thanks to the internal
    capitalization rules.
    * Updated keysyms case mappings to cover full Unicode 16.0.
    * Implemented the `GroupLatch` action, usually activated with
    the keysym `ISO_Group_Latch`.
    * Symbols: Added support for multiple actions per levels.

++++ nvidia-open-driver-G06-signed:

  - Add a directory identifying the KMP and its version to the module
    install path - i.e.:
    <kernel_version>/nvidia-open-driver-G06-signed-<version>/updates
    instead of:
    <kernel_version>/updates
    This avoids conflicts when a new version is built against the
    same kernel release.

++++ openSUSE-repos-LeapMicro:

  - Fix build with RPM 4.20: the construct %else ifarch … was never
    valid; anything behing 'else' was simply ignored and now leads to
    an error.

++++ policycoreutils:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * policycoreutils: introduce unsetfiles
    * Code improvements and bug fixes
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - Update make_targets.patch
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ python-configobj:

  - Update to 5.0.9
    * Drop support for Python 2 and <3.7
    * Fix CVE-2023-26112, ReDoS attack
  - Drop CVE-2023-26112.patch, merged upstream
  - Drop remove_six.patch, fixed upstream

++++ python313-pyparsing:

  - update to 3.2.1:
    * Updated generated railroad diagrams to make non-terminal
    elements links to their related sub-diagrams. This _greatly_
    improves navigation of the diagram, especially for
    large, complex parsers.
    * Simplified railroad diagrams emitted for parsers using
    `infix_notation`, by hiding lookahead terms. Renamed
    internally generated expressions for clarity, and improved
    diagramming.
    * Improved performance of `cpp_style_comment`,
    `c_style_comment`, `common.fnumber`
    and `common.ieee_float` Regex expressions.
    * Add missing type annotations to `match_only_at_col`,
    `replace_with`, `remove_quotes`, `with_attribute`, and
    `with_class`. Issue #585 reported by rafrafrek.

++++ libselinux-bindings:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * libselinux: deprecate security_disable(3)
    * libselinux/utils: introduce selabel_compare
    * improved selabel_lookup performance
    * libselinux: support parallel usage of selabel_lookup(3)
    * Improved man pages
    * Always build for LFS mode on 32-bit archs.
    * Binary fcontext files format changed, files using old format are ignored
    * Code improvements and bug fixes
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - Drop 1231587-build-libselinux-with-swig-4.3.0.patch: fixed upstream
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ python-semanage:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * libsemanage: Preserve file context and ownership in policy store
    * libsemanage: Optionally allow duplicate declarations
    * Improved man pages
    * libsemanage: Mute error messages from selinux_restorecon introduced in 3.8-rc1
    * Code improvements and bug fixes
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - Drop 1231587-build-libsemanage-with-swig-4.3.0.patch: fixed upstream
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ restorecond:

  - Update to version 3.8
    https://github.com/SELinuxProject/selinux/releases/tag/3.8
    * No functional change
  - For a more in depth list of changes see
    https://github.com/SELinuxProject/selinux/releases/download/3.8/shortlog-3.8.txt
  - Drop 1231512-Set-GLib-IO-channels-to-binary-mode.patch: included upstream
  - Drop 1231512-Set-GLib-IO-channels-to-nonblocking.patch: included upstream
  - keyring: Update Petr Lautrbach <lautrbach@redhat.com>
    * removed 0xBC3905F235179CF1 (expired: 2024-10-25)
    * added 0xFB4C685B5DC1C13E (expires: 2026-11-04)

++++ tuned:

  - Add LIBEXECDIR=%{_prefix}/lib to adopt libexecdir and remove
    the sed hack in spec due to mainline git 410344b8dbc64bada45be
  - Update to version 2.25.1.0+git.889387b:
    * new release (2.25.1)
    * disk: Add missing remove parameter
    * plugins: Add missing instance parameters
    * Makefile: Add support for installation to custom $LIBEXECDIR
    * new release (2.25.0)
    * plugin_scheduler: add switch to disable processing of kthreads
    * sap-hana: Set transparent_hugepages to madvise
    * bootloader: export Grub variables to make them available in submenus
    * functions: Create a new parser object for each string expansion
    * utils: Rename `PluginLoader` to `ClassLoader`
    * plugin_net: handle cqe-mode-rx ethtool option
    * profiles: Correct CPU governor settings
    * utils.commands: Fix CPU online detection when not present
    * new release (2.25.0-rc.1)
    * docs: fixed docs generation on centos-7
    * plugin_scheduler: fixed API
    * plugin_scheduler: make perf support optional
    * plugin_net: added support for hotplug and rename
    * scheduler: Postpone cgroup blacklist check and double-check after fail
    * makefile: added support for installation to custom $BINDIR/$SBINDIR
    * tuned-ppd: Do not always clear holds with TuneD profile change signal
    * tuned-ppd: Check that TuneD profile change signal is relevant
    * doc: enable documentation generation on RHEL with asciidoc
    * scheduler: Log process info when its affinity cannot be changed

------------------------------------------------------------------
------------------  2025-2-3  -  Feb 3 2025  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Update to version 2.0.5:
    + This release adds the following features:
  - Allow emulating devices reading EFI keys
  - Allow skipping device tests by CPU architecture
    + This release fixes the following bugs:
  - Cleanup Dell kestrel devices when disconnected
  - Correctly build binary EFI_SIGNATURE_LIST objects
  - Do not allow dbx updates when no ESP was found
  - Ignore BootXXXX entries that do not exist when checking the dbx
  - Ignore EFI binaries that are zero-sized, or not well formed
  - Inhibit dbx updates if snapd is not available when using Ubuntu-style FDE
  - Only match the device checksum if the protocol matches
  - Raise authentication requirements for emulation-load
  - Request to upload failed reports for install/downgrade too
  - Use the kernel architecture when building the dbx instance ID
  - Write sbatlevel to PE/COFF files correctly
    + This release adds support for the following hardware:
  - More ELAN Fingerprint readers
  - Star Labs StarLite Magnetic Keyboard

++++ gtk3:

  - Fix %filetriggerpostun for icon cache: ensure the icons that have
    just been removed are also cleared from the cache. We can't
    shortcut on upgrades, even though this would be nice. In context
    of RPM 4.20 this started breaking (boo#1236740).

++++ kernel-default:

  - NFSv4.2: mark OFFLOAD_CANCEL MOVEABLE (git-fixes).
  - commit 29678bd
  - NFSv4.2: fix COPY_NOTIFY xdr buf size calculation (git-fixes).
  - commit d5313f5
  - nfs: fix incorrect error handling in LOCALIO (git-fixes).
  - commit 9daaf72
  - Revert "SUNRPC: Reduce thread wake-up rate when receiving
    large RPC messages" (git-fixes).
  - commit 39ec528
  - NFSD: Insulate nfsd4_encode_read_plus_data() from page
    boundaries in the encode buffer (git-fixes).
  - commit ffa4780
  - NFSD: Insulate nfsd4_encode_read_plus() from page boundaries
    in the encode buffer (git-fixes).
  - commit fd89a72
  - NFSD: Insulate nfsd4_encode_read() from page boundaries in
    the encode buffer (git-fixes).
  - commit a5474b1
  - NFSD: fix decoding in nfs4_xdr_dec_cb_getattr (git-fixes).
  - commit 744c03a
  - nfsd: fix legacy client tracking initialization (git-fixes).
  - commit b058f86
  - net: inet6: do not leave a dangling sk pointer in inet6_create()
    (CVE-2024-56600 bsc#1235217).
  - commit 001ffac
  - printk: Defer legacy printing when holding printk_cpu_sync
    (bsc#1236733).
  - commit 35fb637
  - iomap: avoid avoid truncating 64-bit offset to 32 bits
    (git-fixes).
  - commit dcd6fd5
  - iomap: pass byte granular end position to iomap_add_to_ioend
    (git-fixes).
  - commit 3e58ba8
  - cachefiles: Parse the "secctx" immediately (git-fixes).
  - commit d3745ec
  - dlm: fix srcu_read_lock() return type to int (git-fixes).
  - commit befab55
  - dlm: fix removal of rsb struct that is master and dir record
    (git-fixes).
  - commit 0dc790e
  - xfs: check for dead buffers in xfs_buf_find_insert (git-fixes).
  - commit 518b962
  - xfs: fix a double completion for buffers on in-memory targets
    (git-fixes).
  - commit 230cef5
  - xfs/libxfs: replace kmalloc() and memcpy() with kmemdup()
    (git-fixes).
  - commit e30e5c1
  - Update config files: remove XEN PV support and kernel side PV device
    backends (jsc#PED-11779)
  - commit 31e5715
  - arm64: dts: marvell: cn9131-cf-solidwan: fix cp1 comphy links (git-fixes)
  - commit c3b3ad4
  - arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma (git-fixes)
  - commit 040d5bd
  - arm64: dts: rockchip: fix num-channels property of wolfvision pf5 mic (git-fixes)
  - commit 80bffba
  - arm64: dts: rockchip: Fix PCIe3 handling for Edgeble-6TOPS Modules (git-fixes)
  - commit 6eeb73e
  - arm64: dts: rockchip: Fix sdmmc access on rk3308-rock-s0 v1.1 boards (git-fixes)
  - commit 0f4955c
  - arm64: tegra: Fix Tegra234 PCIe interrupt-map (git-fixes)
  - commit 17b2e93
  - arm64: tegra: Disable Tegra234 sce-fabric node (git-fixes)
  - commit 5fbc68f
  - arm64: tegra: Fix typo in Tegra234 dce-fabric compatible (git-fixes)
  - commit b60c09f
  - xfs: don't shut down the filesystem for media failures beyond
    end of log (git-fixes).
  - commit b3253c4
  - arm64: tegra: Fix DMA ID for SPI2 (git-fixes)
  - commit ed27827
  - gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag
    (git-fixes).
  - commit 2bdb106
  - arm64: dts: rockchip: Fix Turing RK1 PCIe3 hang (git-fixes)
  - commit 6545f4a
  - arm64: dts: rockchip: Split up RK3588's PCIe pinctrls (git-fixes)
  - commit ee6c1d3
  - arm64/mm: Override PARange for !LPA2 and use it consistently (git-fixes)
  - commit 46430f7
  - arm64/mm: Reduce PA space to 48 bits when LPA2 is not enabled (git-fixes)
  - commit 1e5b33c
  - arm64: Filter out SVE hwcaps when FEAT_SVE isn't implemented (git-fixes)
  - commit 6644a3b
  - arm64/sme: Move storage of reg_smidr to __cpuinfo_store_cpu() (git-fixes)
  - commit ee0c3e4
  - arm64: stacktrace: Don't WARN when unwinding other tasks (git-fixes)
  - commit c1b5cbf
  - nvme: fix bogus kzalloc() return check in
    nvme_init_effects_log() (git-fixes).
  - commit d42e4b8
  - USB: serial: option: add Neoway N723-EA support (git-fixes).
  - commit e972bca
  - USB: serial: option: add MeiG Smart SRM815 (git-fixes).
  - commit 77f7a0f
  - USB: serial: cp210x: add Phoenix Contact UPS Device (git-fixes).
  - commit f332140
  - usb-storage: Add max sectors quirk for Nokia 208 (git-fixes).
  - commit 0ad9095
  - nvme: Add error path for xa_store in nvme_init_effects
    (git-fixes).
  - nvme: Add error check for xa_store in nvme_get_effects_log
    (git-fixes).
  - nvme-tcp: Fix I/O queue cpu spreading for multiple controllers
    (git-fixes).
  - nvmet: propagate npwg topology (git-fixes).
  - commit 7f10443
  - usbnet: ipheth: fix DPE OoB read (git-fixes).
  - commit b2a02b8
  - usbnet: ipheth: break up NCM header size computation
    (git-fixes).
  - commit 7a83cc0
  - usbnet: ipheth: refactor NCM datagram loop (git-fixes).
  - commit 095ff33
  - scsi: storvsc: Ratelimit warning logs to prevent VM denial of
    service (git-fixes).
  - scsi: storvsc: Don't assume cpu_possible_mask is dense
    (git-fixes).
  - hyperv: Do not overlap the hvcall IO areas in
    hv_vtl_apicid_to_vp_id() (git-fixes).
  - hyperv: Do not overlap the hvcall IO areas in get_vtl()
    (git-fixes).
  - hyperv: Enable the hypercall output page for the VTL mode
    (git-fixes).
  - hv_balloon: Fallback to generic_online_page() for non-HV hot
    added mem (git-fixes).
  - Drivers: hv: vmbus: Log on missing offers if any (git-fixes).
  - Drivers: hv: vmbus: Wait for boot-time offers during boot and
    resume (git-fixes).
  - uio_hv_generic: Add a check for HV_NIC for send, receive
    buffers setup (git-fixes).
  - iommu/hyper-v: Don't assume cpu_possible_mask is dense
    (git-fixes).
  - Drivers: hv: Don't assume cpu_possible_mask is dense
    (git-fixes).
  - x86/hyperv: Don't assume cpu_possible_mask is dense (git-fixes).
  - hyperv: Remove the now unused hyperv-tlfs.h files (git-fixes).
  - hyperv: Switch from hyperv-tlfs.h to hyperv/hvhdk.h (git-fixes).
  - hyperv: Add new Hyper-V headers in include/hyperv (git-fixes).
  - hyperv: Clean up unnecessary #includes (git-fixes).
  - hyperv: Move hv_connection_id to hyperv-tlfs.h (git-fixes).
  - hv_netvsc: Replace one-element array with flexible array member
    (git-fixes).
  - commit bf2065f

++++ kernel-rt:

  - NFSv4.2: mark OFFLOAD_CANCEL MOVEABLE (git-fixes).
  - commit 29678bd
  - NFSv4.2: fix COPY_NOTIFY xdr buf size calculation (git-fixes).
  - commit d5313f5
  - nfs: fix incorrect error handling in LOCALIO (git-fixes).
  - commit 9daaf72
  - Revert "SUNRPC: Reduce thread wake-up rate when receiving
    large RPC messages" (git-fixes).
  - commit 39ec528
  - NFSD: Insulate nfsd4_encode_read_plus_data() from page
    boundaries in the encode buffer (git-fixes).
  - commit ffa4780
  - NFSD: Insulate nfsd4_encode_read_plus() from page boundaries
    in the encode buffer (git-fixes).
  - commit fd89a72
  - NFSD: Insulate nfsd4_encode_read() from page boundaries in
    the encode buffer (git-fixes).
  - commit a5474b1
  - NFSD: fix decoding in nfs4_xdr_dec_cb_getattr (git-fixes).
  - commit 744c03a
  - nfsd: fix legacy client tracking initialization (git-fixes).
  - commit b058f86
  - net: inet6: do not leave a dangling sk pointer in inet6_create()
    (CVE-2024-56600 bsc#1235217).
  - commit 001ffac
  - printk: Defer legacy printing when holding printk_cpu_sync
    (bsc#1236733).
  - commit 35fb637
  - iomap: avoid avoid truncating 64-bit offset to 32 bits
    (git-fixes).
  - commit dcd6fd5
  - iomap: pass byte granular end position to iomap_add_to_ioend
    (git-fixes).
  - commit 3e58ba8
  - cachefiles: Parse the "secctx" immediately (git-fixes).
  - commit d3745ec
  - dlm: fix srcu_read_lock() return type to int (git-fixes).
  - commit befab55
  - dlm: fix removal of rsb struct that is master and dir record
    (git-fixes).
  - commit 0dc790e
  - xfs: check for dead buffers in xfs_buf_find_insert (git-fixes).
  - commit 518b962
  - xfs: fix a double completion for buffers on in-memory targets
    (git-fixes).
  - commit 230cef5
  - xfs/libxfs: replace kmalloc() and memcpy() with kmemdup()
    (git-fixes).
  - commit e30e5c1
  - Update config files: remove XEN PV support and kernel side PV device
    backends (jsc#PED-11779)
  - commit 31e5715
  - arm64: dts: marvell: cn9131-cf-solidwan: fix cp1 comphy links (git-fixes)
  - commit c3b3ad4
  - arm64: dts: rockchip: increase gmac rx_delay on rk3399-puma (git-fixes)
  - commit 040d5bd
  - arm64: dts: rockchip: fix num-channels property of wolfvision pf5 mic (git-fixes)
  - commit 80bffba
  - arm64: dts: rockchip: Fix PCIe3 handling for Edgeble-6TOPS Modules (git-fixes)
  - commit 6eeb73e
  - arm64: dts: rockchip: Fix sdmmc access on rk3308-rock-s0 v1.1 boards (git-fixes)
  - commit 0f4955c
  - arm64: tegra: Fix Tegra234 PCIe interrupt-map (git-fixes)
  - commit 17b2e93
  - arm64: tegra: Disable Tegra234 sce-fabric node (git-fixes)
  - commit 5fbc68f
  - arm64: tegra: Fix typo in Tegra234 dce-fabric compatible (git-fixes)
  - commit b60c09f
  - xfs: don't shut down the filesystem for media failures beyond
    end of log (git-fixes).
  - commit b3253c4
  - arm64: tegra: Fix DMA ID for SPI2 (git-fixes)
  - commit ed27827
  - gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag
    (git-fixes).
  - commit 2bdb106
  - arm64: dts: rockchip: Fix Turing RK1 PCIe3 hang (git-fixes)
  - commit 6545f4a
  - arm64: dts: rockchip: Split up RK3588's PCIe pinctrls (git-fixes)
  - commit ee6c1d3
  - arm64/mm: Override PARange for !LPA2 and use it consistently (git-fixes)
  - commit 46430f7
  - arm64/mm: Reduce PA space to 48 bits when LPA2 is not enabled (git-fixes)
  - commit 1e5b33c
  - arm64: Filter out SVE hwcaps when FEAT_SVE isn't implemented (git-fixes)
  - commit 6644a3b
  - arm64/sme: Move storage of reg_smidr to __cpuinfo_store_cpu() (git-fixes)
  - commit ee0c3e4
  - arm64: stacktrace: Don't WARN when unwinding other tasks (git-fixes)
  - commit c1b5cbf
  - nvme: fix bogus kzalloc() return check in
    nvme_init_effects_log() (git-fixes).
  - commit d42e4b8
  - USB: serial: option: add Neoway N723-EA support (git-fixes).
  - commit e972bca
  - USB: serial: option: add MeiG Smart SRM815 (git-fixes).
  - commit 77f7a0f
  - USB: serial: cp210x: add Phoenix Contact UPS Device (git-fixes).
  - commit f332140
  - usb-storage: Add max sectors quirk for Nokia 208 (git-fixes).
  - commit 0ad9095
  - nvme: Add error path for xa_store in nvme_init_effects
    (git-fixes).
  - nvme: Add error check for xa_store in nvme_get_effects_log
    (git-fixes).
  - nvme-tcp: Fix I/O queue cpu spreading for multiple controllers
    (git-fixes).
  - nvmet: propagate npwg topology (git-fixes).
  - commit 7f10443
  - usbnet: ipheth: fix DPE OoB read (git-fixes).
  - commit b2a02b8
  - usbnet: ipheth: break up NCM header size computation
    (git-fixes).
  - commit 7a83cc0
  - usbnet: ipheth: refactor NCM datagram loop (git-fixes).
  - commit 095ff33
  - scsi: storvsc: Ratelimit warning logs to prevent VM denial of
    service (git-fixes).
  - scsi: storvsc: Don't assume cpu_possible_mask is dense
    (git-fixes).
  - hyperv: Do not overlap the hvcall IO areas in
    hv_vtl_apicid_to_vp_id() (git-fixes).
  - hyperv: Do not overlap the hvcall IO areas in get_vtl()
    (git-fixes).
  - hyperv: Enable the hypercall output page for the VTL mode
    (git-fixes).
  - hv_balloon: Fallback to generic_online_page() for non-HV hot
    added mem (git-fixes).
  - Drivers: hv: vmbus: Log on missing offers if any (git-fixes).
  - Drivers: hv: vmbus: Wait for boot-time offers during boot and
    resume (git-fixes).
  - uio_hv_generic: Add a check for HV_NIC for send, receive
    buffers setup (git-fixes).
  - iommu/hyper-v: Don't assume cpu_possible_mask is dense
    (git-fixes).
  - Drivers: hv: Don't assume cpu_possible_mask is dense
    (git-fixes).
  - x86/hyperv: Don't assume cpu_possible_mask is dense (git-fixes).
  - hyperv: Remove the now unused hyperv-tlfs.h files (git-fixes).
  - hyperv: Switch from hyperv-tlfs.h to hyperv/hvhdk.h (git-fixes).
  - hyperv: Add new Hyper-V headers in include/hyperv (git-fixes).
  - hyperv: Clean up unnecessary #includes (git-fixes).
  - hyperv: Move hv_connection_id to hyperv-tlfs.h (git-fixes).
  - hv_netvsc: Replace one-element array with flexible array member
    (git-fixes).
  - commit bf2065f

++++ gcc15:

  - Update to GCC trunk head, 15.0.1+git7330
  - For cross compilers require the same or newer binutils, newlib
    or cross-glibc that was used at build time.  [bsc#1232526]

++++ libjcat:

  - Update to version 0.2.3:
    + Do not close the base stream when using
    jcat_file_import_stream().
    + Skip ed25519 part of a test with -Ded25519=false.

++++ ncurses:

  - Add ncurses patch 20250201
    + add <new> to the possible headers declaring the C++ std::bad_alloc
    (report by Carl Hansen).
    + modify check for stdbool.h to be more conservative in case the
    headers are used with a compiler other than that which was used to
    configure (Redhat #2342514).
    + improve MKlib_gen.sh handling of "bool" type, for building link_test
    + improve formatting/style of manpages (patches by Branden Robinson).

++++ rpm:

  - allow to have the primary binding signature in the unhashed area
    * updated rpmpgp_legacy-1.0.tar.gz to rpmpgp_legacy-1.1.tar.gz

++++ libvirt:

  - spec: Change hooks dependency from libvirtd to the qemu driver
    bsc#1236378

++++ wtmpdb:

  - Update to version 0.71.0+git20250203.86b8442:
    * Release version 0.71.0
    * zero struct tm before calling strptime()
    * Accept classic 'last -N' form for max entries
    * tst-varlink: fix order of error checking
    * CI: use valgrind
    * Run meson test in verbose mode
    * tst-varlink works only if run as root
    * Use meson feature and not combo options
    * Add CI for openSUSE
    * CI: make sure sqlite3 devel is installed

++++ nvidia-open-driver-G06-signed:

  - fixed build against openSUSE:Factory by defining %_builddir
    if needed (boo#1236746)
  - no longer try to patch %post/%postun; no changes needed any longer
  - trigger script needs to be triggered now by nvidia-common-G06,
    which replaced kernel-firmware-nvidia-gspx-G06{,-cuda} packages
  - fixed version of 'Provides: nvidia-open-signed-kmp = <version>'
    of nvidia-open-signed-cuda-kmp in preamble file
  - fixed
    warning: File listed twice: /usr/src/kernel-modules/nvidia-570.86.16-default

++++ opensuse-migration-tool:

  - Update to version 20250129.63f1e30:
    * Check for x86_64-v2 capability prior migrating to 16.0
    * Use custom dialogrc
    * Activate green only with 24bit/truecolor
    * Use same colors for digits as for dialog options
    * Do not use yellow for title nor active button
    * Update README.md

------------------------------------------------------------------
------------------  2025-2-2  -  Feb 2 2025  -------------------
------------------------------------------------------------------

++++ gstreamer:

  - Update to version 1.24.12:
    + Highlighted bugfixes:
  - d3d12: Fix shaders failing to compile with newer dxc versions
  - decklinkvideosink: Fix handling of caps framerate in auto
    mode; also a decklinkaudiosink fix
  - devicemonitor: Fix potential crash macOS when a device is
    unplugged
  - gst-libav: Fix crash in audio encoders like avenc_ac3 if
    input data has insufficient alignment
  - gst-libav: Fix build against FFmpeg 4.2 as in Ubuntu 20.04
  - gst-editing-services: Fix Python library name fetching on
    Windows
  - netclientclock: Don't store failed internal clocks in the
    cache, so applications can re-try later
  - oggdemux: Seeking and duration fixes
  - osxaudiosrc: Fixes for failing init/no output on recent iOS
    versions
  - qtdemux: Use mvhd transform matrix and support for flipping
  - rtpvp9pay: Fix profile parsing
  - splitmuxsrc: Fix use with decodebin3 which would occasionally
    fail with an assertion when seeking
  - tsdemux: Fix backwards PTS wraparound detection with
    ignore-pcr=true
  - video-overlay-composition: Declare the video/size/orientation
    tags for the meta and implement scale transformations
  - vtdec: Fix seeks occasionally hanging on macOS due to a race
    condition when draining
  - webrtc: Fix duplicate payload types with RTX and multiple
    video codecs
  - win32-pluginoader: Make sure not to create any windows when
    inspecting plugins
  - wpe: Various fixes for re-negotiation, latency reporting,
    progress messages on startup
  - x264enc: Add missing data to AvcDecoderConfigurationRecord in
    codec_data for high profile variants
  - cerbero: Support using ccache with cmake if enabled
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - device: Fix racy nullptr deref on macOS when a device is
    unplugged
  - iterator: Added error handling to filtered iterators
  - netclientclock: Don't ever store failed internal clocks in
    the cache
  - netclock-replay: use gst_c_args when building, fixing build
    failure on Solaris
  - pluginloader-win32: create no window
  - pluginloader-win32: fix use after free in
    find_helper_bin_location
  - sparsefile: ensure error is set when read_buffer() returns 0
  - basetransform: fix incorrect logging inside
    gst_base_transform_query_caps

++++ gstreamer-plugins-base:

  - Update to version 1.24.12:
    + oggdemux: fixes seeking in some cases by not overwriting a
    valid duration with CLOCK_TIME_NONE
    + video-overlay-composition: Declare the video/size/orientation
    tags for the meta & implement scale transformation
    + Various fixes found from adding extra warning flags

++++ kernel-default:

  - Revert "media: uvcvideo: Require entities to have a non-zero
    unique ID" (bsc#1235894).
  - wifi: rtl8xxxu: add more missing rtl8192cu USB IDs
    (stable-fixes).
  - drm/amd/display: Initialize denominator defaults to 1
    (stable-fixes).
  - drm/amd/display: Use HW lock mgr for PSR1 (stable-fixes).
  - drm/connector: hdmi: Validate supported_formats matches
    ycbcr_420_allowed (stable-fixes).
  - commit 839fcdd

++++ kernel-rt:

  - Revert "media: uvcvideo: Require entities to have a non-zero
    unique ID" (bsc#1235894).
  - wifi: rtl8xxxu: add more missing rtl8192cu USB IDs
    (stable-fixes).
  - drm/amd/display: Initialize denominator defaults to 1
    (stable-fixes).
  - drm/amd/display: Use HW lock mgr for PSR1 (stable-fixes).
  - drm/connector: hdmi: Validate supported_formats matches
    ycbcr_420_allowed (stable-fixes).
  - commit 839fcdd

++++ at-spi2-core:

  - Update to version 2.55.2 (Unstable):
    + Attempt to fix a use after free in the atk bridge.
    + Add a switch role.

++++ xz:

  - update to 5.6.4:
    * liblzma: Fix LZMA/LZMA2 encoder on big endian ARM64.
    * xz: Fix --filters= and --filters1= ... --filters9= options
    parsing. They require an argument, thus "xz --filters lzma2"
    should work in addition to "xz --filters=lzma2".
    * Updates to documentation, translations, build system files
  - package license files in all packages

------------------------------------------------------------------
------------------  2025-2-1  -  Feb 1 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.8 → 10.2.9

++++ kernel-default:

  - ASoC: acp: Support microphone from Lenovo Go S (stable-fixes).
  - ALSA: pcm: use new array-copying-wrapper (stable-fixes).
  - ALSA: usb-audio: Add delay quirk for iBasso DC07 Pro
    (stable-fixes).
  - commit ccad405
  - PCI: Restore original INTX_DISABLE bit by pcim_intx()
    (git-fixes).
  - kconfig: fix memory leak in sym_warn_unmet_dep() (git-fixes).
  - kconfig: fix file name in warnings when loading
    KCONFIG_DEFCONFIG_LIST (git-fixes).
  - genksyms: fix memory leak when the same symbol is read from
    * .symref file (git-fixes).
  - genksyms: fix memory leak when the same symbol is added from
    source (git-fixes).
  - ata: libata-core: Add ATA_QUIRK_NOLPM for Samsung SSD 870 QVO
    drives (git-fixes).
  - ASoC: amd: acp: Fix possible deadlock (git-fixes).
  - ASoC: da7213: Initialize the mutex (git-fixes).
  - ASoC: rockchip: i2s_tdm: Re-add the set_sysclk callback
    (git-fixes).
  - ALSA: hda: Fix headset detection failure due to unstable sort
    (git-fixes).
  - ALSA: hda/realtek: Fix quirk matching for Legion Pro 7
    (git-fixes).
  - commit 4daaa58

++++ kernel-rt:

  - ASoC: acp: Support microphone from Lenovo Go S (stable-fixes).
  - ALSA: pcm: use new array-copying-wrapper (stable-fixes).
  - ALSA: usb-audio: Add delay quirk for iBasso DC07 Pro
    (stable-fixes).
  - commit ccad405
  - PCI: Restore original INTX_DISABLE bit by pcim_intx()
    (git-fixes).
  - kconfig: fix memory leak in sym_warn_unmet_dep() (git-fixes).
  - kconfig: fix file name in warnings when loading
    KCONFIG_DEFCONFIG_LIST (git-fixes).
  - genksyms: fix memory leak when the same symbol is read from
    * .symref file (git-fixes).
  - genksyms: fix memory leak when the same symbol is added from
    source (git-fixes).
  - ata: libata-core: Add ATA_QUIRK_NOLPM for Samsung SSD 870 QVO
    drives (git-fixes).
  - ASoC: amd: acp: Fix possible deadlock (git-fixes).
  - ASoC: da7213: Initialize the mutex (git-fixes).
  - ASoC: rockchip: i2s_tdm: Re-add the set_sysclk callback
    (git-fixes).
  - ALSA: hda: Fix headset detection failure due to unstable sort
    (git-fixes).
  - ALSA: hda/realtek: Fix quirk matching for Legion Pro 7
    (git-fixes).
  - commit 4daaa58

++++ which:

  - Update to 2.23:
    * The function that decides if a found path is executable
    (file_status) was updated to that of bash version 5.2.
  - add upstream signing key
  - drop obsolete texinfo packaging macros

------------------------------------------------------------------
------------------  2025-1-31  -  Jan 31 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - io_uring/eventfd: ensure io_eventfd_signal() defers another
    RCU period (CVE-2025-21655 bsc#1236163).
  - commit 8c48635
  - io_uring/eventfd: abstract out ev_fd put helper (CVE-2025-21655
    bsc#1236163).
  - commit 3ee0779
  - io_uring/sqpoll: zero sqd->thread on tctx errors (CVE-2025-21633
    bsc#1236108).
  - commit e81e97d
  - sched_ext: update scx_bpf_dsq_insert() doc for SCX_DSQ_LOCAL_ON
    (git fixes (sched)).
  - cpufreq: schedutil: Fix superfluous updates caused by
    need_freq_update (git fixes (sched)).
  - sched/fair: Fix update_cfs_group() vs DELAY_DEQUEUE (git fixes
    (sched)).
  - sched/fair: Fix EEVDF entity placement bug causing scheduling
    lag (git fixes (sched)).
  - sched_ext: idle: Refresh idle masks during idle-to-idle
    transitions (git fixes (sched)).
  - freezer, sched: Report frozen tasks as 'D' instead of 'R'
    (git fixes (sched)).
  - epoll: Add synchronous wakeup support for ep_poll_callback
    (git fixes (sched)).
  - commit 3d30d97
  - mm/rodata_test: use READ_ONCE() to read const variable
    (git-fixes).
  - commit d31a779
  - cpufreq/amd-pstate: Fix prefcore rankings (git-fixes).
  - commit 6e54c2a
  - rtc: zynqmp: Fix optional clock name property (git-fixes).
  - rtc: loongson: clear TOY_MATCH0_REG in loongson_rtc_isr()
    (git-fixes).
  - rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
    (git-fixes).
  - rtc: tps6594: Fix integer overflow on 32bit systems (git-fixes).
  - PM: sleep: core: Synchronize runtime PM status of parents and
    children (git-fixes).
  - PM: hibernate: Add error handling for syscore_suspend()
    (git-fixes).
  - Bluetooth: L2CAP: accept zero as a special value for MTU
    auto-selection (git-fixes).
  - Bluetooth: btnxpuart: Fix glitches seen in dual A2DP streaming
    (git-fixes).
  - Bluetooth: btusb: mediatek: Add locks for
    usb_driver_claim_interface() (git-fixes).
  - usbnet: ipheth: use static NDP16 location in URB (git-fixes).
  - usbnet: ipheth: check that DPE points past NCM header
    (git-fixes).
  - usbnet: ipheth: fix possible overflow in DPE length check
    (git-fixes).
  - net: usb: rtl8150: enable basic endpoint checking (git-fixes).
  - net: phy: c45-tjaxx: add delay between MDIO write and read in
    soft_reset (git-fixes).
  - net: rose: fix timer races against user threads (git-fixes).
  - net: phy: marvell-88q2xxx: Fix temperature measurement with
    reset-gpios (git-fixes).
  - NFC: nci: Add bounds checking in nci_hci_create_pipe()
    (git-fixes).
  - docs: power: Fix footnote reference for Toshiba Satellite
    P10-554 (git-fixes).
  - gpio: mxc: remove dead code after switch to DT-only (git-fixes).
  - commit ca8e15a
  - docs: ABI: sysfs-bus-event_source-devices-vpa-pmu: Fix htmldocs
    errors (jsc#PED-10947, git-fixes).
  - commit 84a7517
  - perf/x86/intel: Add PMU support for ArrowLake-H (jsc#PED-10527).
  - perf/x86/intel: Support hybrid PMU with multiple atom uarchs
    (jsc#PED-10527).
  - x86/cpu/intel: Define helper to get CPU core native ID
    (jsc#PED-10527).
  - perf/x86: Refine hybrid_pmu_type defination (jsc#PED-10527).
  - commit d4840cf
  - perf/x86/intel/uncore: Add Clearwater Forest support
    (jsc#PED-10657).
  - commit 3b2b3d7
  - perf/x86/intel: Add Arrow Lake U support (jsc#PED-10525).
  - commit 7de75f6
  - powerpc/perf: Add per-task/process monitoring to vpa_pmu driver
    (jsc#PED-10947).
  - powerpc/kvm: Add vpa latency counters to kvm_vcpu_arch
    (jsc#PED-10947).
  - docs: ABI: sysfs-bus-event_source-devices-vpa-pmu: Document
    sysfs event format entries for vpa_pmu (jsc#PED-10947).
  - commit a4dd907
  - powerpc/perf: Add perf interface to expose vpa counters
    (jsc#PED-10947).
  - Update config files (ppc64le/default/CONFIG_VPA_PMU)
  - Update supported.conf (arch/powerpc/perf/vpa-pmu)
  - commit f7b6f3e
  - perf/x86/rapl: Add core energy counter support for AMD CPUs
    (jsc#PED-11773).
  - perf/x86/rapl: Move the cntr_mask to rapl_pmus struct
    (jsc#PED-11773).
  - perf/x86/rapl: Remove the global variable rapl_msrs
    (jsc#PED-11773).
  - perf/x86/rapl: Modify the generic variable names to *_pkg*
    (jsc#PED-11773).
  - perf/x86/rapl: Add arguments to the init and cleanup functions
    (jsc#PED-11773).
  - perf/x86/rapl: Make rapl_model struct global (jsc#PED-11773).
  - perf/x86/rapl: Rename rapl_pmu variables (jsc#PED-11773).
  - perf/x86/rapl: Remove the cpu_to_rapl_pmu() function
    (jsc#PED-11773).
  - x86/topology: Introduce topology_logical_core_id()
    (jsc#PED-11773).
  - perf/x86/rapl: Remove the unused get_rapl_pmu_cpumask() function
    (jsc#PED-11773).
  - perf/x86/rapl: Clean up cpumask and hotplug (jsc#PED-11773).
  - perf/x86/rapl: Move the pmu allocation out of CPU hotplug
    (jsc#PED-11773).
  - x86/amd: Use heterogeneous core topology for identifying boost
    numerator (jsc#PED-11773).
  - x86/cpu: Add CPU type to struct cpuinfo_topology
    (jsc#PED-11773).
  - x86/cpu: Enable SD_ASYM_PACKING for PKG domain on AMD
    (jsc#PED-11773).
  - x86/cpufeatures: Add X86_FEATURE_AMD_HETEROGENEOUS_CORES
    (jsc#PED-11773).
  - x86/cpufeatures: Rename X86_FEATURE_FAST_CPPC to have AMD prefix
    (jsc#PED-11773).
  - commit c61d138

++++ kernel-rt:

  - io_uring/eventfd: ensure io_eventfd_signal() defers another
    RCU period (CVE-2025-21655 bsc#1236163).
  - commit 8c48635
  - io_uring/eventfd: abstract out ev_fd put helper (CVE-2025-21655
    bsc#1236163).
  - commit 3ee0779
  - io_uring/sqpoll: zero sqd->thread on tctx errors (CVE-2025-21633
    bsc#1236108).
  - commit e81e97d
  - sched_ext: update scx_bpf_dsq_insert() doc for SCX_DSQ_LOCAL_ON
    (git fixes (sched)).
  - cpufreq: schedutil: Fix superfluous updates caused by
    need_freq_update (git fixes (sched)).
  - sched/fair: Fix update_cfs_group() vs DELAY_DEQUEUE (git fixes
    (sched)).
  - sched/fair: Fix EEVDF entity placement bug causing scheduling
    lag (git fixes (sched)).
  - sched_ext: idle: Refresh idle masks during idle-to-idle
    transitions (git fixes (sched)).
  - freezer, sched: Report frozen tasks as 'D' instead of 'R'
    (git fixes (sched)).
  - epoll: Add synchronous wakeup support for ep_poll_callback
    (git fixes (sched)).
  - commit 3d30d97
  - mm/rodata_test: use READ_ONCE() to read const variable
    (git-fixes).
  - commit d31a779
  - cpufreq/amd-pstate: Fix prefcore rankings (git-fixes).
  - commit 6e54c2a
  - rtc: zynqmp: Fix optional clock name property (git-fixes).
  - rtc: loongson: clear TOY_MATCH0_REG in loongson_rtc_isr()
    (git-fixes).
  - rtc: pcf85063: fix potential OOB write in PCF85063 NVMEM read
    (git-fixes).
  - rtc: tps6594: Fix integer overflow on 32bit systems (git-fixes).
  - PM: sleep: core: Synchronize runtime PM status of parents and
    children (git-fixes).
  - PM: hibernate: Add error handling for syscore_suspend()
    (git-fixes).
  - Bluetooth: L2CAP: accept zero as a special value for MTU
    auto-selection (git-fixes).
  - Bluetooth: btnxpuart: Fix glitches seen in dual A2DP streaming
    (git-fixes).
  - Bluetooth: btusb: mediatek: Add locks for
    usb_driver_claim_interface() (git-fixes).
  - usbnet: ipheth: use static NDP16 location in URB (git-fixes).
  - usbnet: ipheth: check that DPE points past NCM header
    (git-fixes).
  - usbnet: ipheth: fix possible overflow in DPE length check
    (git-fixes).
  - net: usb: rtl8150: enable basic endpoint checking (git-fixes).
  - net: phy: c45-tjaxx: add delay between MDIO write and read in
    soft_reset (git-fixes).
  - net: rose: fix timer races against user threads (git-fixes).
  - net: phy: marvell-88q2xxx: Fix temperature measurement with
    reset-gpios (git-fixes).
  - NFC: nci: Add bounds checking in nci_hci_create_pipe()
    (git-fixes).
  - docs: power: Fix footnote reference for Toshiba Satellite
    P10-554 (git-fixes).
  - gpio: mxc: remove dead code after switch to DT-only (git-fixes).
  - commit ca8e15a
  - docs: ABI: sysfs-bus-event_source-devices-vpa-pmu: Fix htmldocs
    errors (jsc#PED-10947, git-fixes).
  - commit 84a7517
  - perf/x86/intel: Add PMU support for ArrowLake-H (jsc#PED-10527).
  - perf/x86/intel: Support hybrid PMU with multiple atom uarchs
    (jsc#PED-10527).
  - x86/cpu/intel: Define helper to get CPU core native ID
    (jsc#PED-10527).
  - perf/x86: Refine hybrid_pmu_type defination (jsc#PED-10527).
  - commit d4840cf
  - perf/x86/intel/uncore: Add Clearwater Forest support
    (jsc#PED-10657).
  - commit 3b2b3d7
  - perf/x86/intel: Add Arrow Lake U support (jsc#PED-10525).
  - commit 7de75f6
  - powerpc/perf: Add per-task/process monitoring to vpa_pmu driver
    (jsc#PED-10947).
  - powerpc/kvm: Add vpa latency counters to kvm_vcpu_arch
    (jsc#PED-10947).
  - docs: ABI: sysfs-bus-event_source-devices-vpa-pmu: Document
    sysfs event format entries for vpa_pmu (jsc#PED-10947).
  - commit a4dd907
  - powerpc/perf: Add perf interface to expose vpa counters
    (jsc#PED-10947).
  - Update config files (ppc64le/default/CONFIG_VPA_PMU)
  - Update supported.conf (arch/powerpc/perf/vpa-pmu)
  - commit f7b6f3e
  - perf/x86/rapl: Add core energy counter support for AMD CPUs
    (jsc#PED-11773).
  - perf/x86/rapl: Move the cntr_mask to rapl_pmus struct
    (jsc#PED-11773).
  - perf/x86/rapl: Remove the global variable rapl_msrs
    (jsc#PED-11773).
  - perf/x86/rapl: Modify the generic variable names to *_pkg*
    (jsc#PED-11773).
  - perf/x86/rapl: Add arguments to the init and cleanup functions
    (jsc#PED-11773).
  - perf/x86/rapl: Make rapl_model struct global (jsc#PED-11773).
  - perf/x86/rapl: Rename rapl_pmu variables (jsc#PED-11773).
  - perf/x86/rapl: Remove the cpu_to_rapl_pmu() function
    (jsc#PED-11773).
  - x86/topology: Introduce topology_logical_core_id()
    (jsc#PED-11773).
  - perf/x86/rapl: Remove the unused get_rapl_pmu_cpumask() function
    (jsc#PED-11773).
  - perf/x86/rapl: Clean up cpumask and hotplug (jsc#PED-11773).
  - perf/x86/rapl: Move the pmu allocation out of CPU hotplug
    (jsc#PED-11773).
  - x86/amd: Use heterogeneous core topology for identifying boost
    numerator (jsc#PED-11773).
  - x86/cpu: Add CPU type to struct cpuinfo_topology
    (jsc#PED-11773).
  - x86/cpu: Enable SD_ASYM_PACKING for PKG domain on AMD
    (jsc#PED-11773).
  - x86/cpufeatures: Add X86_FEATURE_AMD_HETEROGENEOUS_CORES
    (jsc#PED-11773).
  - x86/cpufeatures: Rename X86_FEATURE_FAST_CPPC to have AMD prefix
    (jsc#PED-11773).
  - commit c61d138

++++ npth:

  - Update to 1.8:
    * New function npth_get_version
    * New macros NPTH_VERSION and NPTH_VERSION_NUMBER
    * Fix INSERT_EXPOSE_RWLOCK_API for musl C library
    * Return a run-time error if npth_rwlock_timedrdlock is not
    supported

++++ liburing:

  - disable sqwait.t and nop.t for 15.6

------------------------------------------------------------------
------------------  2025-1-30  -  Jan 30 2025  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Remove 0005-cockpit-ws-user-remove-default-deps.patch
  - Fix dynamic users for 330 since systemd isn't included in the
    nsswitch.conf
  - Tidy up pam_oath removal for leap
  - Ship a new pam file since Leap15 doesn't have pam_oath
  - Don't change motd if we don't have pam_oath
  - Properly fix pidfd_getpid
  - This can be dropped once we update again as it's been upstreamed

++++ branding-SLE:

  - Bump to version 16 (bsc#1235774)

++++ python-kiwi:

  - Classify missing chkstat as debug message
    chkstat is a distribution specific tool. If it is
    present we use it, if not we don't but it's not worth
    a warning. This Fixes #2711
  - Allow to run setfiles multi threaded
    Use option -T0 for newer setfiles version.
    This Fixes #2719
  - Add rd.kiwi.dialog.timeout option
    Allow to configure the timeout value for dialogs displayed
    by the kiwi dracut code. By default the timeout is set to
    60 seconds. With the special value "off" the dialog will
    never timeout. This Fixes #2718
  - Make sure copy actions does not drop context
    Use shutil.copy2 to copy files preserving their
    attributes in the grub BootLoader space.
    This Fixes #2709
  - Improve unit test for archive target_dir
    Add a test case with absolute path in the target_dir
    to make sure we never unpack the archive to the host
    system. The actual issue was resolved together with
    the implementation in #1953 and commit
    78238a993c966d1229cd2fc1f5923673a90de14d
    This Fixes #2701
  - Fixed profiled overlay imports
    When building an image for profile: SOME and providing
    an overlay directory named SOME/... kiwi will sync the
    contents of this overlay directory to the root tree.
    However it took the toplevel name SOME/ into account
    which is unwanted because only the sub data structure
    should be synced into the new root tree. This
    Fixes #2690

++++ kernel-default:

  - mm: correctly reference merged VMA (bsc#1236648).
  - commit 35b5461
  - mm/vma: the pgoff is correct if can_merge_right (bsc#1236648).
  - commit 7e8683d
  - mm: defer second attempt at merge on mmap() (bsc#1236648).
  - commit b2d49c9
  - mm: remove unnecessary reset state logic on merge new VMA
    (bsc#1236648).
  - commit b13bccd
  - mm: refactor __mmap_region() (bsc#1236648).
  - commit 88a5663
  - mm: isolate mmap internal logic to mm/vma.c (bsc#1236648).
  - commit d29a53f
  - tools: testing: add additional vma_internal.h stubs
    (bsc#1236648).
  - commit db16c3e
  - cpufreq/amd-pstate: Use boost numerator for upper bound of
    frequencies (git-fixes).
  - cpufreq/amd-pstate: Store the boost numerator as highest perf
    again (git-fixes).
  - commit 6f5ef23
  - cpufreq/amd-pstate: Detect preferred core support before driver
    registration (git-fixes).
  - cpufreq/amd-pstate: Move registration after static function
    call update (git-fixes).
  - cpufreq/amd-pstate: Push adjust_perf vfunc init into cpu_init
    (git-fixes).
  - cpufreq/amd-pstate: Align offline flow of shared memory and
    MSR based systems (git-fixes).
  - cpufreq/amd-pstate: Call cppc_set_epp_perf in the reenable
    function (git-fixes).
  - cpufreq/amd-pstate: Do not attempt to clear MSR_AMD_CPPC_ENABLE
    (git-fixes).
  - cpufreq/amd-pstate: Rename functions that enable CPPC
    (git-fixes).
  - cpufreq/amd-pstate: Remove the redundant amd_pstate_set_driver()
    call (git-fixes).
  - cpufreq/amd-pstate: Remove the switch case in amd_pstate_init()
    (git-fixes).
  - cpufreq/amd-pstate: Call amd_pstate_set_driver() in
    amd_pstate_register_driver() (git-fixes).
  - cpufreq/amd-pstate: Call amd_pstate_register() in
    amd_pstate_init() (git-fixes).
  - cpufreq/amd-pstate: Set the initial min_freq to
    lowest_nonlinear_freq (git-fixes).
  - cpufreq/amd-pstate: Remove the redundant verify() function
    (git-fixes).
  - cpufreq/amd-pstate: Rename MSR and shared memory specific
    functions (git-fixes).
  - commit 3a64362
  - cpufreq: ACPI: Fix max-frequency computation (git-fixes
    jsc#PED-12064).
  - commit 8847124
  - Move upstreamed lpfc and initramfs patches into sorted section
  - commit 3188ca8
  - Input: synaptics - fix crash when enabling pass-through port
    (bsc#1219522).
  - commit 37ec4ab
  - powerpc/pseries/eeh: Fix get PE state translation (bsc#1215199).
  - commit 9a95d7d
  - Update config files.
    Disable accidentally enabled option
    ppc64le:
    CONFIG_IRQ_TIME_ACCOUNTING=n
  - commit 482ad8d
  - ALSA: hda/realtek: Workaround for resume on Dell Venue 11 Pro
    7130 (bsc#1235686).
  - commit 9e21a47
  - powerpc/pseries/iommu: Don't unset window if it was never set
    (jsc#PED-10539 git-fixes).
  - commit 198b0d2
  - cpufreq: Move endif to the end of Kconfig file (git-fixes).
  - commit bff3dd1
  - RDMA/efa: Align interrupt related fields to same type (jsc#PED-11323)
  - commit a47f3d4
  - RDMA/hns: Support fast path for link-down events dispatching (jsc#PED-11323)
  - commit f1c4b07
  - RDMA/mlx5: Handle link status event only for LAG device (jsc#PED-11323)
  - commit 0a2c27a
  - RDMA/pvrdma: Support report_port_event() ops (jsc#PED-11323)
  - commit e6aa938
  - RDMA/mlx4: Support report_port_event() ops (jsc#PED-11323)
  - commit c56ddb4
  - RDMA/usnic: Support report_port_event() ops (jsc#PED-11323)
  - commit a5970c5
  - RDMA/siw: Remove deliver net device event (jsc#PED-11323)
  - commit 4efbd9d
  - RDMA/rxe: Remove deliver net device event (jsc#PED-11323)
  - commit 1346d71
  - RDMA/irdma: Remove deliver net device event (jsc#PED-10421)
  - commit 59a167e
  - RDMA/bnxt_re: Remove deliver net device event (jsc#PED-11235)
  - commit 7c9ae24
  - RDMA/core: Support link status events dispatching (jsc#PED-11323)
  - commit 49e4368
  - RDMA/core: Add ib_query_netdev_port() to query netdev port by IB device. (jsc#PED-11323)
  - commit 0534314
  - RDMA/core: Remove unused ib_copy_path_rec_from_user (jsc#PED-11323)
  - commit 150e860
  - RDMA/core: Remove unused ibdev_printk (jsc#PED-11323)
  - commit 7975ae5
  - RDMA/core: Remove unused ib_find_exact_cached_pkey (jsc#PED-11323)
  - commit e46a588
  - RDMA/core: Remove unused ib_ud_header_unpack (jsc#PED-11323)
  - commit d4c2ff6
  - RDMA/irdma: Remove unused irdma_cqp_*_fpm_val_cmd functions (jsc#PED-10421)
  - commit ad0bc98
  - IB/hfi1: Remove unused hfi1_format_hwerrors (jsc#PED-10421)
  - commit 6bd5a79
  - RDMA/bnxt_re: Remove unnecessary header file inclusion (jsc#PED-11235)
  - commit 213b4f3
  - RDMA/bnxt_re: Eliminate need for some forward declarations (jsc#PED-11235)
  - commit 786aa2c
  - RDMA/bnxt_re: Optimize error handling in bnxt_re_probe (jsc#PED-11235)
  - commit 71f48c3
  - RDMA/bnxt_re: Remove unnecessary goto in bnxt_re_netdev_event (jsc#PED-11235)
  - commit 4141d4d
  - RDMA/bnxt_re: Remove extra new line in bnxt_re_netdev_event (jsc#PED-11235)
  - commit dc177d4
  - RDMA/mlx5: Extend ODP statistics with operation count (jsc#PED-1123)
    Refresh patches.suse/RDMA-mlx5-Fix-indirect-mkey-ODP-page-count.patch
  - commit e60ad0e
  - RDMA/mlx4: Use DMA iterator to write MTT (jsc#PED-1123)
  - commit 1a553db
  - RDMA/mlx4: Use ib_umem_find_best_pgsz() to calculate MTT size (jsc#PED-1123)
  - commit 25cc31e
  - dmaengine: ti: edma: fix OF node reference leaks in edma_driver
    (git-fixes).
  - regulator: core: Add missing newline character (git-fixes).
  - wifi: ath12k: fix read pointer after free in
    ath12k_mac_assign_vif_to_vdev() (git-fixes).
  - wifi: rtw89: fix proceeding MCC with wrong scanning state
    after sequence changes (git-fixes).
  - commit 04018e2

++++ kernel-firmware-all:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-amdgpu:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-ath10k:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-ath11k:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-ath12k:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-atheros:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-bluetooth:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-bnx2:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-brcm:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-chelsio:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-dpaa2:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-i915:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-intel:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-iwlwifi:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-liquidio:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-marvell:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-media:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-mediatek:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-mellanox:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-mwifiex:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-network:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-nfp:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-nvidia:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-platform:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-prestera:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-qcom:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-qlogic:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-radeon:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-realtek:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-serial:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-sound:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-ti:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-ueagle:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-firmware-usb-network:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

++++ kernel-rt:

  - mm: correctly reference merged VMA (bsc#1236648).
  - commit 35b5461
  - mm/vma: the pgoff is correct if can_merge_right (bsc#1236648).
  - commit 7e8683d
  - mm: defer second attempt at merge on mmap() (bsc#1236648).
  - commit b2d49c9
  - mm: remove unnecessary reset state logic on merge new VMA
    (bsc#1236648).
  - commit b13bccd
  - mm: refactor __mmap_region() (bsc#1236648).
  - commit 88a5663
  - mm: isolate mmap internal logic to mm/vma.c (bsc#1236648).
  - commit d29a53f
  - tools: testing: add additional vma_internal.h stubs
    (bsc#1236648).
  - commit db16c3e
  - cpufreq/amd-pstate: Use boost numerator for upper bound of
    frequencies (git-fixes).
  - cpufreq/amd-pstate: Store the boost numerator as highest perf
    again (git-fixes).
  - commit 6f5ef23
  - cpufreq/amd-pstate: Detect preferred core support before driver
    registration (git-fixes).
  - cpufreq/amd-pstate: Move registration after static function
    call update (git-fixes).
  - cpufreq/amd-pstate: Push adjust_perf vfunc init into cpu_init
    (git-fixes).
  - cpufreq/amd-pstate: Align offline flow of shared memory and
    MSR based systems (git-fixes).
  - cpufreq/amd-pstate: Call cppc_set_epp_perf in the reenable
    function (git-fixes).
  - cpufreq/amd-pstate: Do not attempt to clear MSR_AMD_CPPC_ENABLE
    (git-fixes).
  - cpufreq/amd-pstate: Rename functions that enable CPPC
    (git-fixes).
  - cpufreq/amd-pstate: Remove the redundant amd_pstate_set_driver()
    call (git-fixes).
  - cpufreq/amd-pstate: Remove the switch case in amd_pstate_init()
    (git-fixes).
  - cpufreq/amd-pstate: Call amd_pstate_set_driver() in
    amd_pstate_register_driver() (git-fixes).
  - cpufreq/amd-pstate: Call amd_pstate_register() in
    amd_pstate_init() (git-fixes).
  - cpufreq/amd-pstate: Set the initial min_freq to
    lowest_nonlinear_freq (git-fixes).
  - cpufreq/amd-pstate: Remove the redundant verify() function
    (git-fixes).
  - cpufreq/amd-pstate: Rename MSR and shared memory specific
    functions (git-fixes).
  - commit 3a64362
  - cpufreq: ACPI: Fix max-frequency computation (git-fixes
    jsc#PED-12064).
  - commit 8847124
  - Move upstreamed lpfc and initramfs patches into sorted section
  - commit 3188ca8
  - Input: synaptics - fix crash when enabling pass-through port
    (bsc#1219522).
  - commit 37ec4ab
  - powerpc/pseries/eeh: Fix get PE state translation (bsc#1215199).
  - commit 9a95d7d
  - Update config files.
    Disable accidentally enabled option
    ppc64le:
    CONFIG_IRQ_TIME_ACCOUNTING=n
  - commit 482ad8d
  - ALSA: hda/realtek: Workaround for resume on Dell Venue 11 Pro
    7130 (bsc#1235686).
  - commit 9e21a47
  - powerpc/pseries/iommu: Don't unset window if it was never set
    (jsc#PED-10539 git-fixes).
  - commit 198b0d2
  - cpufreq: Move endif to the end of Kconfig file (git-fixes).
  - commit bff3dd1
  - RDMA/efa: Align interrupt related fields to same type (jsc#PED-11323)
  - commit a47f3d4
  - RDMA/hns: Support fast path for link-down events dispatching (jsc#PED-11323)
  - commit f1c4b07
  - RDMA/mlx5: Handle link status event only for LAG device (jsc#PED-11323)
  - commit 0a2c27a
  - RDMA/pvrdma: Support report_port_event() ops (jsc#PED-11323)
  - commit e6aa938
  - RDMA/mlx4: Support report_port_event() ops (jsc#PED-11323)
  - commit c56ddb4
  - RDMA/usnic: Support report_port_event() ops (jsc#PED-11323)
  - commit a5970c5
  - RDMA/siw: Remove deliver net device event (jsc#PED-11323)
  - commit 4efbd9d
  - RDMA/rxe: Remove deliver net device event (jsc#PED-11323)
  - commit 1346d71
  - RDMA/irdma: Remove deliver net device event (jsc#PED-10421)
  - commit 59a167e
  - RDMA/bnxt_re: Remove deliver net device event (jsc#PED-11235)
  - commit 7c9ae24
  - RDMA/core: Support link status events dispatching (jsc#PED-11323)
  - commit 49e4368
  - RDMA/core: Add ib_query_netdev_port() to query netdev port by IB device. (jsc#PED-11323)
  - commit 0534314
  - RDMA/core: Remove unused ib_copy_path_rec_from_user (jsc#PED-11323)
  - commit 150e860
  - RDMA/core: Remove unused ibdev_printk (jsc#PED-11323)
  - commit 7975ae5
  - RDMA/core: Remove unused ib_find_exact_cached_pkey (jsc#PED-11323)
  - commit e46a588
  - RDMA/core: Remove unused ib_ud_header_unpack (jsc#PED-11323)
  - commit d4c2ff6
  - RDMA/irdma: Remove unused irdma_cqp_*_fpm_val_cmd functions (jsc#PED-10421)
  - commit ad0bc98
  - IB/hfi1: Remove unused hfi1_format_hwerrors (jsc#PED-10421)
  - commit 6bd5a79
  - RDMA/bnxt_re: Remove unnecessary header file inclusion (jsc#PED-11235)
  - commit 213b4f3
  - RDMA/bnxt_re: Eliminate need for some forward declarations (jsc#PED-11235)
  - commit 786aa2c
  - RDMA/bnxt_re: Optimize error handling in bnxt_re_probe (jsc#PED-11235)
  - commit 71f48c3
  - RDMA/bnxt_re: Remove unnecessary goto in bnxt_re_netdev_event (jsc#PED-11235)
  - commit 4141d4d
  - RDMA/bnxt_re: Remove extra new line in bnxt_re_netdev_event (jsc#PED-11235)
  - commit dc177d4
  - RDMA/mlx5: Extend ODP statistics with operation count (jsc#PED-1123)
    Refresh patches.suse/RDMA-mlx5-Fix-indirect-mkey-ODP-page-count.patch
  - commit e60ad0e
  - RDMA/mlx4: Use DMA iterator to write MTT (jsc#PED-1123)
  - commit 1a553db
  - RDMA/mlx4: Use ib_umem_find_best_pgsz() to calculate MTT size (jsc#PED-1123)
  - commit 25cc31e
  - dmaengine: ti: edma: fix OF node reference leaks in edma_driver
    (git-fixes).
  - regulator: core: Add missing newline character (git-fixes).
  - wifi: ath12k: fix read pointer after free in
    ath12k_mac_assign_vif_to_vdev() (git-fixes).
  - wifi: rtw89: fix proceeding MCC with wrong scanning state
    after sequence changes (git-fixes).
  - commit 04018e2

++++ krb5:

  - Prevent overflow when calculating ulog block size. An authenticated
    attacker can cause kadmind to write beyond the end of the mapped
    region for the iprop log file, likely causing a process crash;
    (CVE-2025-24528); (bsc#1236619).
  - Add patch 0010-CVE-2025-24528.patch

++++ libguestfs:

  - Update to version 1.55.3 (jsc#PED-8910)
    * build: Move baseline OCaml to 4.08
    * Various translation updates

++++ lttng-ust:

  - Add python3-setuptools BuildRequires, needed for Python 3.13.

++++ rpm:

  - Split unshare plugin configuration into a new "rpm-plugin-unshare"
    subpackage. This disables the plugin unless the new package
    is installed.
  - enable config.guess/sub update also for loongarch64 architecture
  - update config.guess/sub files to current state from autoconf-2.72

++++ ucode-amd:

  - Update to version 20250129 (git commit 211fbc287a0b):
    * linux-firmware: Update FW files for MRVL SD8997 chips
    * i915: Update Xe2LPD DMC to v2.27
    * qca: Update Bluetooth WCN6856 firmware 2.1.0-00642 to 2.1.0-00650
    * rtl_bt: Update RTL8852B BT USB FW to 0x049B_5037
    * amdgpu: Update ISP FW for isp v4.1.1
    * trivial: contrib: wrap the process in try/except to catch server issues
    * trivial: contrib: use python-magic to detect encoding of emails
    * QCA: Add Bluetooth firmware for QCA6698
  - Drop the versions in Requires in kernel-firmare-all meta package
  - Fix a minor bug in the check script

------------------------------------------------------------------
------------------  2025-1-29  -  Jan 29 2025  -------------------
------------------------------------------------------------------

++++ babeltrace:

  - Add explicit python3-setuptools BuildRequires: needed when
    building with Python 3.13.

++++ haproxy:

  - Update to version 3.1.3+git0.929bedf83:
    * [RELEASE] Released version 3.1.3
    * BUILD: ssl: more cleaner approach to WolfSSL without renegotiation
    * BUILD: ssl: allow to build without the renegotiation API of WolfSSL
    * CLEANUP: quic: remove unused prototype
    * BUG/MINOR: stream: Properly handle "on-marked-up shutdown-backup-sessions"
    * BUG/MINOR: ssl: put ssl_sock_load_ca under SSL_NO_GENERATE_CERTIFICATES
    * BUG/MINOR: quic: do not increase congestion window if app limited
    * BUG/MEDIUM: mux-h1: Properly close H1C if an error is reported before sending data
    * BUILD: quic: Move an ASSUME_NONNULL() for variable which is not null
    * MINOR: quic: Add a BUG_ON() on quic_tx_packet refcount
    * BUG/MINOR: quic: ensure a detached coalesced packet can't access its neighbours
    * BUG/MINOR: init: set HAPROXY_STARTUP_VERSION from the variable, not the macro
    * BUG/MAJOR: log/sink: possible sink collision in sink_new_from_srv()
    * BUG/MAJOR: quic: reject too large CRYPTO frames
    * BUG/MEDIUM: promex: Use right context pointers to dump backends extra-counters
    * BUG/MEDIUM: stktable: fix missing lock on some table converters
    * BUG/MINOR: quic: reject NEW_TOKEN frames from clients
    * BUG/MINOR: stktable: fix big-endian compatiblity in smp_to_stkey()
  - Update to version 3.1.2+git0.cda631a79:
    * [RELEASE] Released version 3.1.2
    * BUG/MEDIUM: h1-htx: Properly handle bodyless messages
    * BUG/MEDIUM: promex/resolvers: Don't dump metrics if no nameserver is defined
    * BUG/MINOR: mux-quic: handle closure of uni-stream
    * MINOR: mux-quic: change return value of qcs_attach_sc()
    * MINOR: mux-quic: add traces on sd attach
    * BUG/MINOR: mux-quic: fix wakeup on qcc_set_error()
    * MINOR: config: Alert about extra arguments for errorfile and errorloc
    * BUG/MINOR: log: Allow to use if/unless conditionnals for do-log action
    * BUG/MEDIUM: mux-quic: do not attach on already closed stream
    * BUG/MAJOR: mux-quic: properly fix BUG_ON on empty STREAM emission
    * Revert "BUG/MAJOR: mux-quic: fix BUG_ON on empty STREAM emission"
    * BUG/MEDIUM: mux-h2: Count copied data when looping on RX bufs in h2_rcv_buf()
    * BUG/MAJOR: mux-quic: fix BUG_ON on empty STREAM emission
    * DOC: config: add missing "track-sc0" in action keywords matrix
    * BUG/MINOR: stats: fix segfault caused by uninitialized value in "show schema json"
    * BUG/MEDIUM: queue: Make process_srv_queue return the number of streams
    * MINOR: hlua: rename "tune.lua.preserve-smp-bool" to "tune.lua.bool-sample-conversion"
    * BUG/MINOR: h2/rhttp: fix HTTP2 conn counters on reverse
    * CLEANUP: mux-quic: remove dead err label in qcc_build_frms()
    * BUG/MEDIUM: mux-quic: prevent BUG_ON() by refreshing frms on MAX_DATA
    * REGTESTS: fix lua-based regtests using tune.lua.smp-preserve-bool
    * MINOR: hlua: add option to preserve bool type from smp to lua
    * DOC: config: add "tune.lua.burst-timeout" to the list of global parameters
    * DOC: config: reorder "tune.lua.*" keywords by alphabetical order
    * DOC: config: add example for server "track" keyword
    * MINOR: mux-quic: hide traces when woken up on pacing only
    * MINOR: trace: implement tracing disabling API
    * MEDIUM: mux-quic: remove pacing specific code on qcc_io_cb
    * MEDIUM/OPTIM: mux-quic: do not rebuild frms list on every send
    * MINOR: mux-quic: split STREAM and RS/SS emission
    * MINOR: mux-quic: extract code to build STREAM frames list
    * MEDIUM/OPTIM: mux-quic: implement purg_list
    * MEDIUM/OPTIM: mux-quic: define a recv_list for demux resumption
    * MINOR: mux-quic: refactor wait-for-handshake support
    * MINOR: quic: add traces
    * CLEANUP: mux-quic: remove unused qcc member send_retry_list
    * BUG/MEDIUM: mux-quic: do not mix qcc_io_send() return codes with pacing
    * BUILD: debug: only dump/reset glitch counters when really defined
    * BUG/MEDIUM: queues: Do not use pendconn_grab_from_px().
    * BUG/MEDIUM: queues: Make sure we call process_srv_queue() when leaving
    * BUG/MEDIUM: stconn: Only consider I/O timers to update stream's expiration date
    * CLEANUP: quic: Rename some BBR functions in relation with bw probing
    * BUG/MINOR: quic: missing Startup accelerating probing bw states
    * REGTESTS: ssl: add a PEM with mix of LF and CRLF line endings
    * BUG/MINOR: cli: cli_snd_buf: preserve \r\n for payload lines
    * BUG/MINOR: quic: too permissive exit condition for high loss detection in Startup (BBR)
    * BUG/MINOR: quic: fix the wrong tracked recovery start time value
    * CLEANUP: quic: remove a wrong comment about ->app_limited (drs)
    * MINOR: quic: reduce the private data size of QUIC cc algos
    * BUG/MINOR: quic: reduce packet losses at least during ProbeBW_CRUISE (BBR)
    * BUG/MINOR: quic: underflow issue for bbr_inflight_hi_from_lost_packet()
    * BUG/MINOR: quic: remove max_bw filter from delivery rate sampling
    * BUG/MINOR: quic: wrong bbr_target_inflight() implementation
    * BUG/MINOR: quic: fix BBB max bandwidth oscillation issue.
    * BUG/MINOR: quic: wrong logical statement in in_recovery_period() (BBR)
    * MINOR: window_filter: rely on the time to update the filter samples (QUIC/BBR)

++++ kernel-default:

  - virtio-blk: don't keep queue frozen during system suspend
    (CVE-2024-57946 bsc#1236247).
  - commit 7fd5c04
  - netfilter: x_tables: fix LED ID check in led_tg_check()
    (CVE-2024-56650 bsc#1235430).
  - commit 7f5dabf
  - tpm: send_data: Wait longer for the TPM to become ready
    (bsc#1235870).
  - commit cf67b6d
  - serial: sh-sci: Increment the runtime usage counter for the
    earlycon device (git-fixes).
  - serial: sh-sci: Clean sci_ports after at earlycon exit
    (git-fixes).
  - serial: sh-sci: Do not probe the serial port if its slot in
    sci_ports is in use (git-fixes).
  - serial: sh-sci: Move runtime PM enable to sci_probe_single()
    (git-fixes).
  - serial: sh-sci: Drop __initdata macro for port_cfg (git-fixes).
  - tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN
    (git-fixes).
  - tty: xilinx_uartps: split sysrq handling (git-fixes).
  - serial: 8250: Adjust the timeout for FIFO mode (git-fixes).
  - commit d006f88
  - driver core: class: Fix wild pointer dereferences in API
    class_dev_iter_next() (git-fixes).
  - devcoredump: cleanup some comments (git-fixes).
  - tools/bootconfig: Fix the wrong format specifier (git-fixes).
  - serial: sh-sci: Do not probe the serial port if its slot in
    sci_ports[] is in use (git-fixes).
  - serial: sh-sci: Drop __initdata macro for port_cfg (git-fixes).
  - tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN
    (git-fixes).
  - tty: xilinx_uartps: split sysrq handling (git-fixes).
  - serial: 8250: Adjust the timeout for FIFO mode (git-fixes).
  - tty: mips_ejtag_fdc: fix one more u8 warning (git-fixes).
  - LoongArch: Fix warnings during S3 suspend (git-fixes).
  - commit b05d21a

++++ kernel-rt:

  - virtio-blk: don't keep queue frozen during system suspend
    (CVE-2024-57946 bsc#1236247).
  - commit 7fd5c04
  - netfilter: x_tables: fix LED ID check in led_tg_check()
    (CVE-2024-56650 bsc#1235430).
  - commit 7f5dabf
  - tpm: send_data: Wait longer for the TPM to become ready
    (bsc#1235870).
  - commit cf67b6d
  - serial: sh-sci: Increment the runtime usage counter for the
    earlycon device (git-fixes).
  - serial: sh-sci: Clean sci_ports after at earlycon exit
    (git-fixes).
  - serial: sh-sci: Do not probe the serial port if its slot in
    sci_ports is in use (git-fixes).
  - serial: sh-sci: Move runtime PM enable to sci_probe_single()
    (git-fixes).
  - serial: sh-sci: Drop __initdata macro for port_cfg (git-fixes).
  - tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN
    (git-fixes).
  - tty: xilinx_uartps: split sysrq handling (git-fixes).
  - serial: 8250: Adjust the timeout for FIFO mode (git-fixes).
  - commit d006f88
  - driver core: class: Fix wild pointer dereferences in API
    class_dev_iter_next() (git-fixes).
  - devcoredump: cleanup some comments (git-fixes).
  - tools/bootconfig: Fix the wrong format specifier (git-fixes).
  - serial: sh-sci: Do not probe the serial port if its slot in
    sci_ports[] is in use (git-fixes).
  - serial: sh-sci: Drop __initdata macro for port_cfg (git-fixes).
  - tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN
    (git-fixes).
  - tty: xilinx_uartps: split sysrq handling (git-fixes).
  - serial: 8250: Adjust the timeout for FIFO mode (git-fixes).
  - tty: mips_ejtag_fdc: fix one more u8 warning (git-fixes).
  - LoongArch: Fix warnings during S3 suspend (git-fixes).
  - commit b05d21a

++++ gcc15:

  - Update to GCC trunk head, 15.0.1+git7269
  - Disable building the experimental rust frontend everywhere since
    the cargo build dependency is unwanted.
  - Adjust the list of RISC-V intrinsic includes.

++++ systemd:

  - Port path_id_compat to the sd_device API

++++ libxml2:

  - fix decompression from stdin [bsc#1236346]
  - added patches
    fix https://gitlab.gnome.org/nwellnhof/libxml2/-/commit/6208f86edd59e31a51a8d9b300d428504adb25a7
    + libxml2-support-compressed-input-from-stdin.patch

++++ libxml2-python:

  - fix decompression from stdin [bsc#1236346]
  - added patches
    fix https://gitlab.gnome.org/nwellnhof/libxml2/-/commit/6208f86edd59e31a51a8d9b300d428504adb25a7
    + libxml2-support-compressed-input-from-stdin.patch

++++ rebootmgr:

  - Update to version 3.0+git20250129.eed876f:
    * Release version 3.1
    * rebootmgrd: fix check if new strategy is valid

------------------------------------------------------------------
------------------  2025-1-28  -  Jan 28 2025  -------------------
------------------------------------------------------------------

++++ cifs-utils:

  - Require a cifs.idmap plugin, suggest wb-cifs-idmap-plugin as
    default (idmapwb.so)

++++ filesystem:

  - add Provides: may-perform-usrmerge (bsc#1236481)

++++ kernel-default:

  - tools/power turbostat: Add initial support for GraniteRapids-D
    (jsc#PED-10490).
  - commit 5b7dffe
  - Enable iSER support for s390x (jsc#PED-3319)
  - commit b386466
  - selftests/mm: virtual_address_range: avoid reading from VM_IO
    mappings (git-fixes).
  - selftests/mm: virtual_address_range: unmap chunks after
    validation (git-fixes).
  - selftests/mm/cow: modify the incorrect checking parameters
    (git-fixes).
  - selftests/mm: use selftests framework to print test result
    (git-fixes).
  - selftests/mm: fix condition in uffd_move_test_common()
    (git-fixes).
  - selftests: mm: fix conversion specifiers in transact_test()
    (git-fixes).
  - clk: clk-loongson2: Fix the number count of clk provider
    (git-fixes).
  - clk: sunxi-ng: a100: enable MMC clock reparenting (git-fixes).
  - clk: mmp2: call pm_genpd_init() only after genpd.name is set
    (git-fixes).
  - clk: thead: Fix cpu2vp_clk for TH1520 AP_SUBSYS clocks
    (git-fixes).
  - clk: thead: Add CLK_IGNORE_UNUSED to fix TH1520 boot
    (git-fixes).
  - clk: thead: Fix clk gate registration to pass flags (git-fixes).
  - clk: qcom: gcc-sdm845: Do not use shared clk_ops for QUPs
    (git-fixes).
  - clk: qcom: gcc-x1e80100: Do not turn off usb_2 controller GDSC
    (git-fixes).
  - clk: qcom: gcc-mdm9607: Fix cmd_rcgr offset for blsp1_uart6 rcg
    (git-fixes).
  - clk: qcom: camcc-x1e80100: Set titan_top_gdsc as the parent
    GDSC of subordinate GDSCs (git-fixes).
  - clk: qcom: clk-alpha-pll: fix alpha mode configuration
    (git-fixes).
  - clk: qcom: dispcc-sm6350: Add missing parent_map for a clock
    (git-fixes).
  - clk: qcom: gcc-sm6350: Add missing parent_map for two clocks
    (git-fixes).
  - clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate
    (git-fixes).
  - clk: qcom: gcc-sm8650: Do not turn off PCIe GDSCs during
    gdsc_disable() (git-fixes).
  - clk: qcom: gcc-sm8550: Do not turn off PCIe GDSCs during
    gdsc_disable() (git-fixes).
  - clk: imx8mp: Fix clkout1/2 support (git-fixes).
  - clk: sunxi-ng: a64: stop force-selecting PLL-MIPI as TCON0
    parent (git-fixes).
  - clk: ralink: mtmips: remove duplicated 'xtal' clock for Ralink
    SoC RT3883 (git-fixes).
  - clk: mediatek: mt2701-img: add missing dummy clk (git-fixes).
  - clk: mediatek: mt2701-mm: add missing dummy clk (git-fixes).
  - clk: mediatek: mt2701-bdp: add missing dummy clk (git-fixes).
  - clk: mediatek: mt2701-aud: fix conversion to
    mtk_clk_simple_probe (git-fixes).
  - clk: mediatek: mt2701-vdec: fix conversion to
    mtk_clk_simple_probe (git-fixes).
  - clk: renesas: cpg-mssr: Fix 'soc' node handling in
    cpg_mssr_reserved_init() (git-fixes).
  - clk: analogbits: Fix incorrect calculation of vco rate delta
    (git-fixes).
  - clk: fix an OF node reference leak in of_clk_get_parent_name()
    (git-fixes).
  - pstore/blk: trivial typo fixes (git-fixes).
  - selftests/mm: set allocated memory to non-zero content in cow
    test (git-fixes).
  - clk: clk-imx8mp-audiomix: fix function signature (git-fixes).
  - clk: thead: Fix TH1520 emmc and shdci clock rate (git-fixes).
  - efivarfs: Fix error on non-existent file (stable-fixes).
  - qca_spi: Make driver probing reliable (git-fixes).
  - qca_spi: Fix clock speed for multiple QCA7000 (git-fixes).
  - commit 52abd40
  - PCI: rcar-ep: Fix incorrect variable used when calling
    devm_request_mem_region() (git-fixes).
  - PCI: microchip: Set inbound address translation for coherent
    or non-coherent mode (git-fixes).
  - PCI: imx6: Add missing reference clock disable logic
    (git-fixes).
  - PCI: imx6: Deassert apps_reset in imx_pcie_deassert_core_reset()
    (git-fixes).
  - PCI: imx6: Skip controller_id generation logic for i.MX7D
    (git-fixes).
  - PCI: imx6: Configure PHY based on Root Complex or Endpoint mode
    (git-fixes).
  - PCI: dwc: Always stop link in the dw_pcie_suspend_noirq
    (git-fixes).
  - PCI: qcom: Update ICC and OPP values after Link Up event
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Fix check for DMA MEMCPY test
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Set dma_chan_rx pointer to NULL
    on error (git-fixes).
  - PCI: dwc: ep: Prevent changing BAR size/flags in
    pci_epc_set_bar() (git-fixes).
  - PCI: dwc: ep: Write BAR_MASK before iATU registers in
    pci_epc_set_bar() (git-fixes).
  - PCI: endpoint: Finish virtual EP removal in
    pci_epf_remove_vepf() (git-fixes).
  - PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
    (git-fixes).
  - PCI/ASPM: Save parent L1SS config in pci_save_aspm_l1ss_state()
    (git-fixes).
  - commit 6aedcaa
  - genirq: Make handle_enforce_irqctx() unconditionally available
    (git-fixes).
  - commit c47d221
  - Refresh patches.suse/tpm-Map-the-ACPI-provided-event-log.patch.
    Add Alt-commit.
  - commit 256dd4e
  - ipmi: ssif_bmc: Fix new request loss when bmc ready for a
    response (git-fixes).
  - ipmi: ipmb: Add check devm_kasprintf() returned value
    (git-fixes).
  - commit 513ad80
  - x86: Fix build regression with CONFIG_KEXEC_JUMP enabled (git-fixes).
  - commit e16e19e
  - clocksource: Make negative motion detection more robust (git-fixes).
  - commit fca041b
  - drm/v3d: Assign job pointer to NULL before signaling the fence
    (git-fixes).
  - drm/amd/display: Fix error pointers in
    amdgpu_dm_crtc_mem_type_changed (git-fixes).
  - iio: light: as73211: fix channel handling in only-color
    triggered buffer (git-fixes).
  - intel_th: core: fix kernel-doc warnings (git-fixes).
  - bus: mhi: host: Free mhi_buf vector inside
    mhi_alloc_bhie_table() (git-fixes).
  - iio: iio-mux: kzalloc instead of devm_kzalloc to ensure page
    alignment (git-fixes).
  - iio: adc: ad_sigma_delta: Handle CS assertion as intended in
    ad_sd_read_reg_raw() (git-fixes).
  - iio: adc: ad7124: Refuse invalid input specifiers (git-fixes).
  - iio: adc: ad7124: Don't create more channels than the driver
    can handle (git-fixes).
  - extcon: realtek: fix NULL deref check in extcon_rtk_type_c_probe
    (git-fixes).
  - misc: fastrpc: Fix copy buffer page size (git-fixes).
  - misc: fastrpc: Fix registered buffer page address (git-fixes).
  - misc: fastrpc: Deregister device nodes properly in error
    scenarios (git-fixes).
  - VMCI: fix reference to ioctl-number.rst (git-fixes).
  - drivers/card_reader/rtsx_usb: Restore interrupt based detection
    (git-fixes).
  - uio: uio_dmem_genirq: check the return value of devm_kasprintf()
    (git-fixes).
  - uio: Fix return value of poll (git-fixes).
  - misc: misc_minor_alloc to use ida for all dynamic/misc dynamic
    minors (git-fixes).
  - pps: Fix a use-after-free (git-fixes).
  - Revert "usb: gadget: u_serial: Disable ep before setting port to
    null to fix the crash caused by port being null" (stable-fixes).
  - usb: typec: tcpci: Prevent Sink disconnection before
    vPpsShutdown in SPR PPS (git-fixes).
  - usb: dwc3: core: Defer the probe until USB power supply ready
    (git-fixes).
  - USB: serial: quatech2: fix null-ptr-deref in
    qt2_process_read_urb() (git-fixes).
  - usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to
    PD_T_SENDER_RESPONSE (git-fixes).
  - usb: host: xhci-plat: Assign shared_hcd->rsrc_start (git-fixes).
  - usb: dwc3-am62: Fix an OF node leak in phy_syscon_pll_refclk()
    (git-fixes).
  - usb: dwc3: Skip resume if pm_runtime_set_active() fails
    (git-fixes).
  - usb: xhci: Fix NULL pointer dereference on certain command
    aborts (git-fixes).
  - usb: gadget: f_tcm: Don't prepare BOT write request twice
    (git-fixes).
  - usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint
    (git-fixes).
  - usb: gadget: f_tcm: Fix Get/SetInterface return value
    (git-fixes).
  - usb: gadget: f_tcm: Decrement command ref count on cleanup
    (git-fixes).
  - usb: gadget: f_tcm: Translate error to sense (git-fixes).
  - usb: gadget: f_tcm: Don't free command immediately (git-fixes).
  - usb: gadget: functionfs: fix spellos (git-fixes).
  - pwm: microchip-core: fix incorrect comparison with max period
    (git-fixes).
  - power: reset: as3722-poweroff: Remove unnecessary return in
    as3722_poweroff_probe (git-fixes).
  - power: ip5xxx_power: Fix return value on ADC read errors
    (git-fixes).
  - commit f4aee60

++++ kernel-rt:

  - tools/power turbostat: Add initial support for GraniteRapids-D
    (jsc#PED-10490).
  - commit 5b7dffe
  - Enable iSER support for s390x (jsc#PED-3319)
  - commit b386466
  - selftests/mm: virtual_address_range: avoid reading from VM_IO
    mappings (git-fixes).
  - selftests/mm: virtual_address_range: unmap chunks after
    validation (git-fixes).
  - selftests/mm/cow: modify the incorrect checking parameters
    (git-fixes).
  - selftests/mm: use selftests framework to print test result
    (git-fixes).
  - selftests/mm: fix condition in uffd_move_test_common()
    (git-fixes).
  - selftests: mm: fix conversion specifiers in transact_test()
    (git-fixes).
  - clk: clk-loongson2: Fix the number count of clk provider
    (git-fixes).
  - clk: sunxi-ng: a100: enable MMC clock reparenting (git-fixes).
  - clk: mmp2: call pm_genpd_init() only after genpd.name is set
    (git-fixes).
  - clk: thead: Fix cpu2vp_clk for TH1520 AP_SUBSYS clocks
    (git-fixes).
  - clk: thead: Add CLK_IGNORE_UNUSED to fix TH1520 boot
    (git-fixes).
  - clk: thead: Fix clk gate registration to pass flags (git-fixes).
  - clk: qcom: gcc-sdm845: Do not use shared clk_ops for QUPs
    (git-fixes).
  - clk: qcom: gcc-x1e80100: Do not turn off usb_2 controller GDSC
    (git-fixes).
  - clk: qcom: gcc-mdm9607: Fix cmd_rcgr offset for blsp1_uart6 rcg
    (git-fixes).
  - clk: qcom: camcc-x1e80100: Set titan_top_gdsc as the parent
    GDSC of subordinate GDSCs (git-fixes).
  - clk: qcom: clk-alpha-pll: fix alpha mode configuration
    (git-fixes).
  - clk: qcom: dispcc-sm6350: Add missing parent_map for a clock
    (git-fixes).
  - clk: qcom: gcc-sm6350: Add missing parent_map for two clocks
    (git-fixes).
  - clk: qcom: clk-rpmh: prevent integer overflow in recalc_rate
    (git-fixes).
  - clk: qcom: gcc-sm8650: Do not turn off PCIe GDSCs during
    gdsc_disable() (git-fixes).
  - clk: qcom: gcc-sm8550: Do not turn off PCIe GDSCs during
    gdsc_disable() (git-fixes).
  - clk: imx8mp: Fix clkout1/2 support (git-fixes).
  - clk: sunxi-ng: a64: stop force-selecting PLL-MIPI as TCON0
    parent (git-fixes).
  - clk: ralink: mtmips: remove duplicated 'xtal' clock for Ralink
    SoC RT3883 (git-fixes).
  - clk: mediatek: mt2701-img: add missing dummy clk (git-fixes).
  - clk: mediatek: mt2701-mm: add missing dummy clk (git-fixes).
  - clk: mediatek: mt2701-bdp: add missing dummy clk (git-fixes).
  - clk: mediatek: mt2701-aud: fix conversion to
    mtk_clk_simple_probe (git-fixes).
  - clk: mediatek: mt2701-vdec: fix conversion to
    mtk_clk_simple_probe (git-fixes).
  - clk: renesas: cpg-mssr: Fix 'soc' node handling in
    cpg_mssr_reserved_init() (git-fixes).
  - clk: analogbits: Fix incorrect calculation of vco rate delta
    (git-fixes).
  - clk: fix an OF node reference leak in of_clk_get_parent_name()
    (git-fixes).
  - pstore/blk: trivial typo fixes (git-fixes).
  - selftests/mm: set allocated memory to non-zero content in cow
    test (git-fixes).
  - clk: clk-imx8mp-audiomix: fix function signature (git-fixes).
  - clk: thead: Fix TH1520 emmc and shdci clock rate (git-fixes).
  - efivarfs: Fix error on non-existent file (stable-fixes).
  - qca_spi: Make driver probing reliable (git-fixes).
  - qca_spi: Fix clock speed for multiple QCA7000 (git-fixes).
  - commit 52abd40
  - PCI: rcar-ep: Fix incorrect variable used when calling
    devm_request_mem_region() (git-fixes).
  - PCI: microchip: Set inbound address translation for coherent
    or non-coherent mode (git-fixes).
  - PCI: imx6: Add missing reference clock disable logic
    (git-fixes).
  - PCI: imx6: Deassert apps_reset in imx_pcie_deassert_core_reset()
    (git-fixes).
  - PCI: imx6: Skip controller_id generation logic for i.MX7D
    (git-fixes).
  - PCI: imx6: Configure PHY based on Root Complex or Endpoint mode
    (git-fixes).
  - PCI: dwc: Always stop link in the dw_pcie_suspend_noirq
    (git-fixes).
  - PCI: qcom: Update ICC and OPP values after Link Up event
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Fix check for DMA MEMCPY test
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Set dma_chan_rx pointer to NULL
    on error (git-fixes).
  - PCI: dwc: ep: Prevent changing BAR size/flags in
    pci_epc_set_bar() (git-fixes).
  - PCI: dwc: ep: Write BAR_MASK before iATU registers in
    pci_epc_set_bar() (git-fixes).
  - PCI: endpoint: Finish virtual EP removal in
    pci_epf_remove_vepf() (git-fixes).
  - PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
    (git-fixes).
  - PCI/ASPM: Save parent L1SS config in pci_save_aspm_l1ss_state()
    (git-fixes).
  - commit 6aedcaa
  - genirq: Make handle_enforce_irqctx() unconditionally available
    (git-fixes).
  - commit c47d221
  - Refresh patches.suse/tpm-Map-the-ACPI-provided-event-log.patch.
    Add Alt-commit.
  - commit 256dd4e
  - ipmi: ssif_bmc: Fix new request loss when bmc ready for a
    response (git-fixes).
  - ipmi: ipmb: Add check devm_kasprintf() returned value
    (git-fixes).
  - commit 513ad80
  - x86: Fix build regression with CONFIG_KEXEC_JUMP enabled (git-fixes).
  - commit e16e19e
  - clocksource: Make negative motion detection more robust (git-fixes).
  - commit fca041b
  - drm/v3d: Assign job pointer to NULL before signaling the fence
    (git-fixes).
  - drm/amd/display: Fix error pointers in
    amdgpu_dm_crtc_mem_type_changed (git-fixes).
  - iio: light: as73211: fix channel handling in only-color
    triggered buffer (git-fixes).
  - intel_th: core: fix kernel-doc warnings (git-fixes).
  - bus: mhi: host: Free mhi_buf vector inside
    mhi_alloc_bhie_table() (git-fixes).
  - iio: iio-mux: kzalloc instead of devm_kzalloc to ensure page
    alignment (git-fixes).
  - iio: adc: ad_sigma_delta: Handle CS assertion as intended in
    ad_sd_read_reg_raw() (git-fixes).
  - iio: adc: ad7124: Refuse invalid input specifiers (git-fixes).
  - iio: adc: ad7124: Don't create more channels than the driver
    can handle (git-fixes).
  - extcon: realtek: fix NULL deref check in extcon_rtk_type_c_probe
    (git-fixes).
  - misc: fastrpc: Fix copy buffer page size (git-fixes).
  - misc: fastrpc: Fix registered buffer page address (git-fixes).
  - misc: fastrpc: Deregister device nodes properly in error
    scenarios (git-fixes).
  - VMCI: fix reference to ioctl-number.rst (git-fixes).
  - drivers/card_reader/rtsx_usb: Restore interrupt based detection
    (git-fixes).
  - uio: uio_dmem_genirq: check the return value of devm_kasprintf()
    (git-fixes).
  - uio: Fix return value of poll (git-fixes).
  - misc: misc_minor_alloc to use ida for all dynamic/misc dynamic
    minors (git-fixes).
  - pps: Fix a use-after-free (git-fixes).
  - Revert "usb: gadget: u_serial: Disable ep before setting port to
    null to fix the crash caused by port being null" (stable-fixes).
  - usb: typec: tcpci: Prevent Sink disconnection before
    vPpsShutdown in SPR PPS (git-fixes).
  - usb: dwc3: core: Defer the probe until USB power supply ready
    (git-fixes).
  - USB: serial: quatech2: fix null-ptr-deref in
    qt2_process_read_urb() (git-fixes).
  - usb: typec: tcpm: set SRC_SEND_CAPABILITIES timeout to
    PD_T_SENDER_RESPONSE (git-fixes).
  - usb: host: xhci-plat: Assign shared_hcd->rsrc_start (git-fixes).
  - usb: dwc3-am62: Fix an OF node leak in phy_syscon_pll_refclk()
    (git-fixes).
  - usb: dwc3: Skip resume if pm_runtime_set_active() fails
    (git-fixes).
  - usb: xhci: Fix NULL pointer dereference on certain command
    aborts (git-fixes).
  - usb: gadget: f_tcm: Don't prepare BOT write request twice
    (git-fixes).
  - usb: gadget: f_tcm: ep_autoconfig with fullspeed endpoint
    (git-fixes).
  - usb: gadget: f_tcm: Fix Get/SetInterface return value
    (git-fixes).
  - usb: gadget: f_tcm: Decrement command ref count on cleanup
    (git-fixes).
  - usb: gadget: f_tcm: Translate error to sense (git-fixes).
  - usb: gadget: f_tcm: Don't free command immediately (git-fixes).
  - usb: gadget: functionfs: fix spellos (git-fixes).
  - pwm: microchip-core: fix incorrect comparison with max period
    (git-fixes).
  - power: reset: as3722-poweroff: Remove unnecessary return in
    as3722_poweroff_probe (git-fixes).
  - power: ip5xxx_power: Fix return value on ADC read errors
    (git-fixes).
  - commit f4aee60

++++ util-linux-systemd:

  - Create and own directories /etc/blkid.conf.d and
    /usr/etc/blkid.conf.d (boo#1235887#c3).
  - Add missingok for /etc/blkid.conf.

++++ util-linux:

  - Create and own directories /etc/blkid.conf.d and
    /usr/etc/blkid.conf.d (boo#1235887#c3).
  - Add missingok for /etc/blkid.conf.

++++ nvidia-open-driver-G06-signed:

  - update non-CUDA variant to 570.86.16 (boo#1236658)
  - supersedes aarch64-TW-buildfix.patch
  - supersedes set-FOP_UNSIGNED_OFFSET-for-nv_drm_fops.fop_flags.patch

++++ rebootmgr:

  - Update to version 3.0+git20250128.8fa577c:
    * Import version 3.0 based on sd-varlink

++++ velociraptor-client:

  - Use llvm17 for SLE15SP6+

++++ systemd-presets-common-SUSE:

  - Enable wtmpdbd.socket to start wtmpdbd via socket activation.
    A seperate daemon for wtmpdb access is required to solve
    https://sourceware.org/bugzilla/show_bug.cgi?id=24492

++++ virt-manager:

  - Upstream bug fixes (bsc#1027942) (jsc#PED-8910)
    001-cli-Support-cpu-maximum.patch
    002-gui-Support-maximum-CPU-mode.patch
    003-cpu-Prefer-maximum-mode-for-many-emulated-guests.patch
    004-domcaps-get-list-of-supported-panic-device-models.patch
    005-tests-Update-capabilities-for-advertisting-panic-device-models.patch
    006-addhardware-panic-Fill-in-model-combo-with-advertised-values-by-libvirt.patch
    007-cli-man-Always-list-osinfo-before-os-variant.patch
    008-snapshots-default-to-same-snapshot-mode-as-currently-used-snapshot.patch
    009-snapshots-warn-users-to-not-mix-snapshot-modes.patch
  - Drop virtinst-dont-use-special-copy-cpu-features.patch

------------------------------------------------------------------
------------------  2025-1-27  -  Jan 27 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.7 → 10.2.8
  - Use multipath child instead of parent device
    On multipath systems we need to find underlying child device
    instead of using parent device.
    This prevents listing all parent devices for a multipath device

++++ filesystem:

  - Add support for loongarch64

++++ gawk:

  - Stop using -fprofile-arcs in the final build
    instrumentation is not wanted there and
    it broke reproducible builds (boo#1040589)

++++ kernel-default:

  - padata: add pd get/put refcnt helper (git-fixes).
  - commit 816d211
  - RDMA/hns: Clean up the legacy CONFIG_INFINIBAND_HNS (git-fixes)
  - RDMA/mlx5: Fix implicit ODP use after free (git-fixes)
  - RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error (git-fixes)
  - RDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]" (git-fixes)
  - RDMA/cxgb4: Notify rdma stack for IB_EVENT_QP_LAST_WQE_REACHED event (git-fixes)
  - RDMA/mlx5: Fix indirect mkey ODP page count (git-fixes)
  - RDMA/rtrs: Add missing deinit() call (git-fixes)
  - RDMA/bnxt_re: Fix to drop reference to the mmap entry in case of error (git-fixes)
  - RDMA/srp: Fix error handling in srp_add_port (git-fixes)
  - RDMA/rxe: Fix mismatched max_msg_sz (git-fixes)
  - rdma/cxgb4: Prevent potential integer overflow on 32bit (git-fixes)
  - RDMA/mlx4: Avoid false error about access to uninitialized gids array (git-fixes)
  - commit 8a1518e
  - padata: avoid UAF for reorder_work (git-fixes).
  - padata: fix UAF in padata_reorder (git-fixes).
  - commit 0ccb421
  - fork: avoid inappropriate uprobe access to invalid mm
    (bsc#1236477).
  - commit d6bd244
  - x86/kexec: Restore GDT on return from ::preserve_context kexec (git-fixes).
  - commit 394a2d2
  - timekeeping: Always check for negative motion (git-fixes).
  - commit 6a6f244
  - cgroup/cpuset: remove kernfs active break (bsc#1236110).
  - commit 0d4d6ef
  - cgroup/cpuset: Prevent leakage of isolated CPUs into sched
    domains (jsc#PED-11934).
  - cgroup/cpuset: Remove stale text (jsc#PED-11934).
  - cgroup/cpuset: Disable cpuset_cpumask_can_shrink() test if
    not load balancing (jsc#PED-11934).
  - cgroup/cpuset: Enforce at most one
    rebuild_sched_domains_locked() call per operation
    (jsc#PED-11934).
  - cgroup/cpuset: Revert "Allow suppression of sched domain
    rebuild in update_cpumasks_hier()" (jsc#PED-11934).
  - commit b370227
  - bug: Use RCU instead RCU-sched to protect module_bug_list
    (bsc#1234370).
  - static_call: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - kprobes: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - bpf: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - jump_label: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - jump_label: Use RCU in all users of __module_address()
    (bsc#1234370).
  - x86: Use RCU in all users of __module_address() (bsc#1234370).
  - cfi: Use RCU while invoking __module_address() (bsc#1234370).
  - arm64: module: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - module: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - module: Use RCU in all users of __module_address()
    (bsc#1234370).
  - module: Use RCU in search_module_extables() (bsc#1234370).
  - module: Allow __module_address() to be called from RCU section
    (bsc#1234370).
  - module: Use RCU in __is_module_percpu_address() (bsc#1234370).
  - module: Use RCU in find_symbol() (bsc#1234370).
  - module: Remove module_assert_mutex_or_preempt() from
    try_add_tainted_module() (bsc#1234370).
  - module: Use RCU in module_kallsyms_on_each_symbol()
    (bsc#1234370).
  - module: Use RCU in __find_kallsyms_symbol_value() (bsc#1234370).
  - module: Use RCU in find_module_all() (bsc#1234370).
  - module: Use RCU in module_get_kallsym() (bsc#1234370).
  - module: Use RCU in find_kallsyms_symbol() (bsc#1234370).
  - module: Use proper RCU assignment in add_kallsyms()
    (bsc#1234370).
  - module: Begin to move from RCU-sched to RCU (bsc#1234370).
  - module: Extend the preempt disabled section in
    dereference_symbol_descriptor() (bsc#1234370).
  - commit 9b774cd
  - x86/ioapic: Remove a stray tab in the IO-APIC type string (git-fixes).
  - commit c9344f1
  - net: stmmac: dwmac-tegra: Read iommu stream id from device tree
    (CVE-2025-21663 bsc#1236260).
  - commit f877716
  - KVM: x86: Advertise SRSO_USER_KERNEL_NO to userspace (git-fixes).
  - commit 9294b74
  - x86/bugs: Add SRSO_USER_KERNEL_NO support (git-fixes).
  - commit 6001f65
  - maple_tree: simplify split calculation (git-fixes).
  - latencytop: use correct kernel-doc format for func params
    (git-fixes).
  - kasan: fix typo in kasan_poison_new_object documentation
    (git-fixes).
  - lib/inflate.c: remove dead code (git-fixes).
  - firewire: test: Fix potential null dereference in firewire
    kunit test (git-fixes).
  - maple_tree: reload mas before the second call for mas_empty_area
    (git-fixes).
  - commit 7ba9d83

++++ kernel-rt:

  - padata: add pd get/put refcnt helper (git-fixes).
  - commit 816d211
  - RDMA/hns: Clean up the legacy CONFIG_INFINIBAND_HNS (git-fixes)
  - RDMA/mlx5: Fix implicit ODP use after free (git-fixes)
  - RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error (git-fixes)
  - RDMA/rxe: Fix the warning "__rxe_cleanup+0x12c/0x170 [rdma_rxe]" (git-fixes)
  - RDMA/cxgb4: Notify rdma stack for IB_EVENT_QP_LAST_WQE_REACHED event (git-fixes)
  - RDMA/mlx5: Fix indirect mkey ODP page count (git-fixes)
  - RDMA/rtrs: Add missing deinit() call (git-fixes)
  - RDMA/bnxt_re: Fix to drop reference to the mmap entry in case of error (git-fixes)
  - RDMA/srp: Fix error handling in srp_add_port (git-fixes)
  - RDMA/rxe: Fix mismatched max_msg_sz (git-fixes)
  - rdma/cxgb4: Prevent potential integer overflow on 32bit (git-fixes)
  - RDMA/mlx4: Avoid false error about access to uninitialized gids array (git-fixes)
  - commit 8a1518e
  - padata: avoid UAF for reorder_work (git-fixes).
  - padata: fix UAF in padata_reorder (git-fixes).
  - commit 0ccb421
  - fork: avoid inappropriate uprobe access to invalid mm
    (bsc#1236477).
  - commit d6bd244
  - x86/kexec: Restore GDT on return from ::preserve_context kexec (git-fixes).
  - commit 394a2d2
  - timekeeping: Always check for negative motion (git-fixes).
  - commit 6a6f244
  - cgroup/cpuset: remove kernfs active break (bsc#1236110).
  - commit 0d4d6ef
  - cgroup/cpuset: Prevent leakage of isolated CPUs into sched
    domains (jsc#PED-11934).
  - cgroup/cpuset: Remove stale text (jsc#PED-11934).
  - cgroup/cpuset: Disable cpuset_cpumask_can_shrink() test if
    not load balancing (jsc#PED-11934).
  - cgroup/cpuset: Enforce at most one
    rebuild_sched_domains_locked() call per operation
    (jsc#PED-11934).
  - cgroup/cpuset: Revert "Allow suppression of sched domain
    rebuild in update_cpumasks_hier()" (jsc#PED-11934).
  - commit b370227
  - bug: Use RCU instead RCU-sched to protect module_bug_list
    (bsc#1234370).
  - static_call: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - kprobes: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - bpf: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - jump_label: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - jump_label: Use RCU in all users of __module_address()
    (bsc#1234370).
  - x86: Use RCU in all users of __module_address() (bsc#1234370).
  - cfi: Use RCU while invoking __module_address() (bsc#1234370).
  - arm64: module: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - module: Use RCU in all users of __module_text_address()
    (bsc#1234370).
  - module: Use RCU in all users of __module_address()
    (bsc#1234370).
  - module: Use RCU in search_module_extables() (bsc#1234370).
  - module: Allow __module_address() to be called from RCU section
    (bsc#1234370).
  - module: Use RCU in __is_module_percpu_address() (bsc#1234370).
  - module: Use RCU in find_symbol() (bsc#1234370).
  - module: Remove module_assert_mutex_or_preempt() from
    try_add_tainted_module() (bsc#1234370).
  - module: Use RCU in module_kallsyms_on_each_symbol()
    (bsc#1234370).
  - module: Use RCU in __find_kallsyms_symbol_value() (bsc#1234370).
  - module: Use RCU in find_module_all() (bsc#1234370).
  - module: Use RCU in module_get_kallsym() (bsc#1234370).
  - module: Use RCU in find_kallsyms_symbol() (bsc#1234370).
  - module: Use proper RCU assignment in add_kallsyms()
    (bsc#1234370).
  - module: Begin to move from RCU-sched to RCU (bsc#1234370).
  - module: Extend the preempt disabled section in
    dereference_symbol_descriptor() (bsc#1234370).
  - commit 9b774cd
  - x86/ioapic: Remove a stray tab in the IO-APIC type string (git-fixes).
  - commit c9344f1
  - net: stmmac: dwmac-tegra: Read iommu stream id from device tree
    (CVE-2025-21663 bsc#1236260).
  - commit f877716
  - KVM: x86: Advertise SRSO_USER_KERNEL_NO to userspace (git-fixes).
  - commit 9294b74
  - x86/bugs: Add SRSO_USER_KERNEL_NO support (git-fixes).
  - commit 6001f65
  - maple_tree: simplify split calculation (git-fixes).
  - latencytop: use correct kernel-doc format for func params
    (git-fixes).
  - kasan: fix typo in kasan_poison_new_object documentation
    (git-fixes).
  - lib/inflate.c: remove dead code (git-fixes).
  - firewire: test: Fix potential null dereference in firewire
    kunit test (git-fixes).
  - maple_tree: reload mas before the second call for mas_empty_area
    (git-fixes).
  - commit 7ba9d83

++++ ncurses:

  - Add ncurses patch 20250125
    + improve error-handling in c++ binding (report by Mingjie Shen).
    + strict compiler-warning fixes for upcoming gcc15
  - Install missed ticw.pc
  - Update README.devel

++++ openvswitch:

  - Update openvswitch to 3.3.2. For a list of changes, check
    https://github.com/openvswitch/ovs/blob/v3.3.2/NEWS
  - Update OVN to 24.03.5. For a list of changes, check
    https://github.com/ovn-org/ovn/blob/v24.03.5/NEWS
  - This update fix CVE-2025-0650 ovn: egress ACLs may be bypassed
    via specially crafted UDP packet (bsc#1236353)

++++ python313-core:

  - Configure externally_managed with a bcond
    https://en.opensuse.org/openSUSE:Python:Externally_managed
    bsc#1228165

++++ liburing:

  - disable more tests on s390x

++++ nvidia-open-driver-G06-signed:

  - Update to 565.77
  - non-CUDA variant:
    * get rid of modproee.d and dracut.cd files and udev magic;
    instead require nvidia-common-G06
    * Supplements: switch to really supported devices; not only the
    initially supported ones without graphical output
  - update non-CUDA and CUDA variant to 570.86.15

++++ osinfo-db:

  - Update to database version 20250124 (jsc#PED-8910)
    osinfo-db-20250124.tar.xz
  - Drop patches contained in new tarball
    add-opensuse-leap-15.6-support.patch
    add-sle15sp6-support.patch
    add-slem5.5-support.patch

++++ python313:

  - Configure externally_managed with a bcond
    https://en.opensuse.org/openSUSE:Python:Externally_managed
    bsc#1228165

++++ rebootmgr:

  - Update to version 3.0+git20250127.73667d7:
    * rebootmgrctl: implement verbose dump-config verb
    * Fix search path for vendor config file
    * Add CI with openSUSE container
    * Add new methods and use UID auth
  - Add timezone to BuildRequires for test suite

++++ rust-keylime:

  - Update to version 0.2.7+1:
    * dist: Enable logging for keylime library in the service
    * Bump version to 0.2.7
    * scripts: Download coverage data from Testing Farm directly
    * main: Remove unnecessary lifetime
    * cargo: Bump pretty_env_logger to version 0.5.0
    * scripts: Fix regex in download_packit_coverage.sh
    * cargo: Bump clap crate to version 4.5.23
    * cargo: Bump base64 crate to version 0.22.1
    * build(deps): bump log from 0.4.22 to 0.4.25
    * build(deps): bump serde_json from 1.0.133 to 1.0.135
    * cargo: Bump tokio crate to version 1.42.0
    * packit: Fix RPM builds on copr
    * cargo: Bump thiserror crate to version 0.2.9
    * cargo: Update reqwest to version 0.12.12
    * build(deps): bump libc from 0.2.168 to 0.2.169
    * build(deps): bump glob from 0.3.1 to 0.3.2
    * version: Implement API version validation and ordering
    * main: Support using multiple API versions for registration
    * keylime: Introduce the registrar_client module
    * Provide endpoints under multiple API versions
    * Move 'serialization' module to the keylime library
    * Drop unnecessary dependency on common::API_VERSION
    * keylime-agent.conf: Bump version to 2.3
    * build(deps): bump serde from 1.0.210 to 1.0.217
    * build(deps): bump pest_derive from 2.7.14 to 2.7.15
    * build(deps): bump pest from 2.7.14 to 2.7.15
    * build(deps): bump libc from 0.2.167 to 0.2.168
    * config: Make IAK and IDevID certificates optional
    * Fix warnings reported by clippy
    * workflows: Run job in the CI container directly
    * tests: Add unit test for device ID builder
    * main: Move IAK/IDevID related code to dedicated module
    * tests: Add script to generate IAK and IDevID certificates
    * build(deps): bump openssl from 0.10.66 to 0.10.68
    * build(deps): bump uuid from 1.10.0 to 1.11.0
    * build(deps): bump serde_json from 1.0.128 to 1.0.133
    * build(deps): bump actix-web from 4.5.1 to 4.9.0
    * build(deps): bump reqwest from 0.12.7 to 0.12.9
    * tests/setup_swtpm.sh: Add script to setup temporary TPM
    * Use a single TPM context and avoid race conditions during tests
    * config: Enable passing a hostname instead of IP
    * build(deps): bump clap from 4.3.11 to 4.5.21
    * build(deps): bump tempfile from 3.10.1 to 3.14.0
    * build(deps): bump pest_derive from 2.7.6 to 2.7.14
    * build(deps): bump pest from 2.7.6 to 2.7.14
    * build(deps): bump codecov/codecov-action from 4 to 5
    * workflows: Submit the coverage for merged PR from Fedora 41
    * tests: Use Fedora 41 to generate code coverage
    * api: Make API configuration modular
    * agent_handler: Move the /agent scope configuration
    * notifications_handler: Move the /notifications scope configuration
    * quotes_handler: Move the /quotes scope configuration to quotes_handler
    * keys_handler: Move /keys scope configuration to keys_handler
    * Use ${DESTDIR} for config
    * Fix showing wrong UUID
    * build(deps): bump actix-rt from 2.9.0 to 2.10.0
    * config: Refactor AgentConfig Source trait implementation
    * build(deps): bump log from 0.4.21 to 0.4.22
    * build(deps): bump serde_json from 1.0.120 to 1.0.128
    * tpm: check if EK certificate has valid ASN.1 DER encoding
    * build(deps): bump futures from 0.3.27 to 0.3.31
    * cargo: Bump reqwest to version 0.12.7
    * build(deps): bump serde from 1.0.203 to 1.0.210
    * tests: Add more tests to Packit CI
    * build(deps): bump docker/build-push-action from 5 to 6
    * tests: apply workarounds to known bugs

++++ selinux-policy:

  - Update to version 20240604+git689.da1e0e20:
    * Transition samba-dcerpcd pid file from smbd_var_run_t to winbind_var_run_t (bsc#1235801)
    * /run/samba/samba-dcerpcd.pid needs fc type winbind_rpcd_var_run_t (bsc#1235801)
    * Adjust rpcd_lsad, samba-bgqd, samba-dcerpcd to SUSE-specific part (bsc#1235801)
    * Transition nmbd pid file from smbd_var_run_t to nmbd_var_run_t (bsc#1235801)

++++ velociraptor-client:

  - Don't try to build or use system-user-velociraptor on SLE12

++++ sysuser-tools:

  - Add support for "u!" with useradd (shadow). busybox has no
    support for account/password expiration

++++ tuned:

  - Fix grub.cfg path (bsc#1236491)
    A 0001-tuned-consts-Fix-grub.cfg-path-in-SLE.patch

------------------------------------------------------------------
------------------  2025-1-26  -  Jan 26 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - remoteproc: mtk_scp: Only populate devices for SCP cores
    (git-fixes).
  - remoteproc: omap: Handle ARM dma_iommu_mapping (git-fixes).
  - remoteproc: core: Fix ida_free call while not allocated
    (git-fixes).
  - watchdog: rti_wdt: Fix an OF node leak in rti_wdt_probe()
    (git-fixes).
  - mtd: rawnand: brcmnand: fix status read of brcmnand_waitfunc
    (git-fixes).
  - mtd: spinand: Remove write_enable_op() in markbad() (git-fixes).
  - mtd: onenand: Fix uninitialized retlen in do_otp_read()
    (git-fixes).
  - PCI: rcar-ep: Fix incorrect variable used when calling
    devm_request_mem_region() (git-fixes).
  - PCI: imx6: Add missing reference clock disable logic
    (git-fixes).
  - PCI: imx6: Deassert apps_reset in imx_pcie_deassert_core_reset()
    (git-fixes).
  - PCI: imx6: Skip controller_id generation logic for i.MX7D
    (git-fixes).
  - PCI: imx6: Configure PHY based on Root Complex or Endpoint mode
    (git-fixes).
  - PCI: dwc: Always stop link in the dw_pcie_suspend_noirq
    (git-fixes).
  - PCI: qcom: Update ICC and OPP values after Link Up event
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Fix check for DMA MEMCPY test
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Set dma_chan_rx pointer to NULL
    on error (git-fixes).
  - PCI: dwc: ep: Prevent changing BAR size/flags in
    pci_epc_set_bar() (git-fixes).
  - PCI: dwc: ep: Write BAR_MASK before iATU registers in
    pci_epc_set_bar() (git-fixes).
  - PCI: endpoint: Finish virtual EP removal in
    pci_epf_remove_vepf() (git-fixes).
  - PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
    (git-fixes).
  - PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1
    (git-fixes).
  - PCI/ASPM: Save parent L1SS config in pci_save_aspm_l1ss_state()
    (git-fixes).
  - media: nuvoton: Fix an error check in npcm_video_ece_init()
    (git-fixes).
  - media: dvb-usb-v2: af9035: fix ISO C90 compilation error on
    af9035_i2c_master_xfer (git-fixes).
  - staging: media: imx: fix OF node leak in
    imx_media_add_of_subdevs() (git-fixes).
  - media: mmp: Bring back registration of the device (git-fixes).
  - media: nxp: imx8-isi: fix v4l2-compliance test errors
    (git-fixes).
  - media: uvcvideo: Propagate buf->error to userspace (git-fixes).
  - media: uvcvideo: Remove dangling pointers (git-fixes).
  - media: uvcvideo: Remove redundant NULL assignment (git-fixes).
  - media: uvcvideo: Only save async fh if success (git-fixes).
  - media: uvcvideo: Support partial control reads (git-fixes).
  - media: uvcvideo: Fix event flags in uvc_ctrl_send_events
    (git-fixes).
  - media: uvcvideo: Fix double free in error path (git-fixes).
  - media: uvcvideo: Fix crash during unbind if gpio unit is in use
    (git-fixes).
  - staging: media: max96712: fix kernel oops when removing module
    (git-fixes).
  - media: camif-core: Add check for clk_enable() (git-fixes).
  - media: mipi-csis: Add check for clk_enable() (git-fixes).
  - media: ov5640: fix get_light_freq on auto (git-fixes).
  - media: mc: fix endpoint iteration (git-fixes).
  - media: i2c: ds90ub960: Fix UB9702 VC map (git-fixes).
  - media: i2c: ds90ub960: Fix logging SP & EQ status only for
    UB9702 (git-fixes).
  - media: i2c: ds90ub960: Fix use of non-existing registers on
    UB9702 (git-fixes).
  - media: i2c: ds90ub960: Fix UB9702 refclk register access
    (git-fixes).
  - media: i2c: ds90ub9x3: Fix extra fwnode_handle_put()
    (git-fixes).
  - media: i2c: ov9282: Correct the exposure offset (git-fixes).
  - media: intel/ipu6: remove cpu latency qos request on error
    (git-fixes).
  - media: ccs: Fix cleanup order in ccs_probe() (git-fixes).
  - media: imx296: Add standby delay during probe (git-fixes).
  - media: i2c: imx412: Add missing newline to prints (git-fixes).
  - media: i2c: imx290: Register 0x3011 varies between imx327 and
    imx290 (git-fixes).
  - media: ccs: Clean up parsed CCS static data on parse failure
    (git-fixes).
  - media: ccs: Fix CCS static data parsing for large block sizes
    (git-fixes).
  - media: marvell: Add check for clk_enable() (git-fixes).
  - media: stm32: dcmipp: correct dma_set_mask_and_coherent mask
    value (git-fixes).
  - media: lmedm04: Handle errors for lme2510_int_read (git-fixes).
  - media: rc: iguanair: handle timeouts (git-fixes).
  - media: rkisp1: Fix unused value issue (git-fixes).
  - media: imx-jpeg: Fix potential error pointer dereference in
    detach_pm() (git-fixes).
  - commit aae4fa1

++++ kernel-rt:

  - remoteproc: mtk_scp: Only populate devices for SCP cores
    (git-fixes).
  - remoteproc: omap: Handle ARM dma_iommu_mapping (git-fixes).
  - remoteproc: core: Fix ida_free call while not allocated
    (git-fixes).
  - watchdog: rti_wdt: Fix an OF node leak in rti_wdt_probe()
    (git-fixes).
  - mtd: rawnand: brcmnand: fix status read of brcmnand_waitfunc
    (git-fixes).
  - mtd: spinand: Remove write_enable_op() in markbad() (git-fixes).
  - mtd: onenand: Fix uninitialized retlen in do_otp_read()
    (git-fixes).
  - PCI: rcar-ep: Fix incorrect variable used when calling
    devm_request_mem_region() (git-fixes).
  - PCI: imx6: Add missing reference clock disable logic
    (git-fixes).
  - PCI: imx6: Deassert apps_reset in imx_pcie_deassert_core_reset()
    (git-fixes).
  - PCI: imx6: Skip controller_id generation logic for i.MX7D
    (git-fixes).
  - PCI: imx6: Configure PHY based on Root Complex or Endpoint mode
    (git-fixes).
  - PCI: dwc: Always stop link in the dw_pcie_suspend_noirq
    (git-fixes).
  - PCI: qcom: Update ICC and OPP values after Link Up event
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Fix check for DMA MEMCPY test
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Set dma_chan_rx pointer to NULL
    on error (git-fixes).
  - PCI: dwc: ep: Prevent changing BAR size/flags in
    pci_epc_set_bar() (git-fixes).
  - PCI: dwc: ep: Write BAR_MASK before iATU registers in
    pci_epc_set_bar() (git-fixes).
  - PCI: endpoint: Finish virtual EP removal in
    pci_epf_remove_vepf() (git-fixes).
  - PCI: endpoint: Destroy the EPC device in devm_pci_epc_destroy()
    (git-fixes).
  - PCI: Avoid putting some root ports into D3 on TUXEDO Sirius Gen1
    (git-fixes).
  - PCI/ASPM: Save parent L1SS config in pci_save_aspm_l1ss_state()
    (git-fixes).
  - media: nuvoton: Fix an error check in npcm_video_ece_init()
    (git-fixes).
  - media: dvb-usb-v2: af9035: fix ISO C90 compilation error on
    af9035_i2c_master_xfer (git-fixes).
  - staging: media: imx: fix OF node leak in
    imx_media_add_of_subdevs() (git-fixes).
  - media: mmp: Bring back registration of the device (git-fixes).
  - media: nxp: imx8-isi: fix v4l2-compliance test errors
    (git-fixes).
  - media: uvcvideo: Propagate buf->error to userspace (git-fixes).
  - media: uvcvideo: Remove dangling pointers (git-fixes).
  - media: uvcvideo: Remove redundant NULL assignment (git-fixes).
  - media: uvcvideo: Only save async fh if success (git-fixes).
  - media: uvcvideo: Support partial control reads (git-fixes).
  - media: uvcvideo: Fix event flags in uvc_ctrl_send_events
    (git-fixes).
  - media: uvcvideo: Fix double free in error path (git-fixes).
  - media: uvcvideo: Fix crash during unbind if gpio unit is in use
    (git-fixes).
  - staging: media: max96712: fix kernel oops when removing module
    (git-fixes).
  - media: camif-core: Add check for clk_enable() (git-fixes).
  - media: mipi-csis: Add check for clk_enable() (git-fixes).
  - media: ov5640: fix get_light_freq on auto (git-fixes).
  - media: mc: fix endpoint iteration (git-fixes).
  - media: i2c: ds90ub960: Fix UB9702 VC map (git-fixes).
  - media: i2c: ds90ub960: Fix logging SP & EQ status only for
    UB9702 (git-fixes).
  - media: i2c: ds90ub960: Fix use of non-existing registers on
    UB9702 (git-fixes).
  - media: i2c: ds90ub960: Fix UB9702 refclk register access
    (git-fixes).
  - media: i2c: ds90ub9x3: Fix extra fwnode_handle_put()
    (git-fixes).
  - media: i2c: ov9282: Correct the exposure offset (git-fixes).
  - media: intel/ipu6: remove cpu latency qos request on error
    (git-fixes).
  - media: ccs: Fix cleanup order in ccs_probe() (git-fixes).
  - media: imx296: Add standby delay during probe (git-fixes).
  - media: i2c: imx412: Add missing newline to prints (git-fixes).
  - media: i2c: imx290: Register 0x3011 varies between imx327 and
    imx290 (git-fixes).
  - media: ccs: Clean up parsed CCS static data on parse failure
    (git-fixes).
  - media: ccs: Fix CCS static data parsing for large block sizes
    (git-fixes).
  - media: marvell: Add check for clk_enable() (git-fixes).
  - media: stm32: dcmipp: correct dma_set_mask_and_coherent mask
    value (git-fixes).
  - media: lmedm04: Handle errors for lme2510_int_read (git-fixes).
  - media: rc: iguanair: handle timeouts (git-fixes).
  - media: rkisp1: Fix unused value issue (git-fixes).
  - media: imx-jpeg: Fix potential error pointer dereference in
    detach_pm() (git-fixes).
  - commit aae4fa1

++++ python-cryptography:

  - Update to version 44.0.0:
    * BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.9.
    * Deprecated Python 3.7 support. Python 3.7 is no longer supported by
    the Python core team. Support for Python 3.7 will be removed in a future
    cryptography release.
    * Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 3.4.0.
    * macOS wheels are now built against the macOS 10.13 SDK. Users on older
    versions of macOS should upgrade, or they will need to build cryptography
    themselves.
    * Enforce the RFC 5280 requirement that extended key usage extensions must not be empty.
    * Added support for timestamp extraction to the :class:`~cryptography.fernet.MultiFernet` class.
    * Relax the Authority Key Identifier requirements on root CA certificates
    during X.509 verification to allow fields permitted by RFC 5280 but
    forbidden by the CA/Browser BRs.
    * Added support for
    :class:`~cryptography.hazmat.primitives.kdf.argon2.Argon2id` when using
    OpenSSL 3.2.0+.
    * Added support for the :class:`~cryptography.x509.Admissions` certificate extension.
    * Added basic support for PKCS7 decryption (including S/MIME 3.2) via
    :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`,
    :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_pem`,
    and :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_smime`.
  - Update specfile to accommodate new project structure at version 44.0.0
  - Update no-pytest_benchmark.patch

------------------------------------------------------------------
------------------  2025-1-25  -  Jan 25 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Increase size for agama integration test build
    Agama needs more space to build now
  - Fixed agama integration test
    rubygem-byebug and rubygem-agama-yast seems to
    no longer exist
  - Update TW integration tests
    Package nscd was dropped from TW

++++ gtk3:

  - Update to version 3.24.48:
    + GtkFileChooser: Stop replacing : (colon) with U+2236 (ratio)
    + GtkEmojiChooser: Update to Unicode 16 / CLDR 46
    + GtkSpinButton:
  - Use semantically appropriate icon names
  - Make numeric spin buttons always LTR
    + GtkEntry:
  - Stop guessing text direction from keyboard layout
  - Add a shortcut and context menu item to change text direction
    + GtkEventControllerMotion: Make enter and leave signals work
    + Accessibility: Use message dialog titles as names
    + GDK: Fix portal handling of gvfs files
    + Wayland:
  - Support the xdg_foreign_v2 protocol
  - Try to fix monitor geometry on sway
  - Improve font setting fallback
  - Use a better default cursor size
  - Fix a crash during DND
    + Updated translations.

++++ kernel-default:

  - ALSA: hda/realtek: Enable Mute LED on HP Laptop 14s-fq1xxx
    (stable-fixes).
  - ALSA: usb-audio: Add delay quirk for USB Audio Device
    (stable-fixes).
  - ALSA: hda/realtek: Enable headset mic on Positivo C6400
    (stable-fixes).
  - commit 6acf6ed
  - rhashtable: Fix rhashtable_try_insert test (git-fixes).
  - commit f5a7305
  - mailbox: zynqmp: Remove invalid __percpu annotation in
    zynqmp_ipi_probe() (git-fixes).
  - mailbox: tegra-hsp: Clear mailbox before using message
    (git-fixes).
  - i3c: master: Fix missing 'ret' assignment in set_speed()
    (git-fixes).
  - i3c: dw: Fix use-after-free in dw_i3c_master driver due to
    race condition (git-fixes).
  - efi: sysfb_efi: fix W=1 warnings when EFI is not set
    (git-fixes).
  - of: address: Fix empty resource handling in
    __of_address_resource_bounds() (git-fixes).
  - of/fdt: Restore possibility to use both ACPI and FDT from
    bootloader (git-fixes).
  - of: reserved-memory: Do not make kmemleak ignore freed address
    (git-fixes).
  - of: reserved-memory: Fix using wrong number of cells to get
    property 'alignment' (git-fixes).
  - of: property: Avoiding using uninitialized variable @imaplen
    in parse_interrupt_map() (git-fixes).
  - of: Correct child specifier used as input of the 2nd nexus node
    (git-fixes).
  - of: Fix of_find_node_opts_by_path() handling of
    alias+path+options (git-fixes).
  - soc: samsung: exynos-pmu: Fix uninitialized ret in
    tensor_set_bits_atomic() (git-fixes).
  - firmware: qcom: scm: Cleanup global '__scm' on probe failures
    (git-fixes).
  - firmware: qcom: scm: Fix missing read barrier in
    qcom_scm_get_tzmem_pool() (git-fixes).
  - firmware: qcom: scm: Fix missing read barrier in
    qcom_scm_is_available() (git-fixes).
  - soc: qcom: socinfo: Avoid out of bounds read of serial number
    (git-fixes).
  - soc: qcom: smem_state: fix missing of_node_put in error path
    (git-fixes).
  - soc: qcom: llcc: Enable LLCC_WRCACHE at boot on X1 (git-fixes).
  - soc: mediatek: mtk-devapc: Fix leaking IO map on driver remove
    (git-fixes).
  - soc: mediatek: mtk-devapc: Fix leaking IO map on error paths
    (git-fixes).
  - memory: tegra20-emc: fix an OF node reference bug in
    tegra_emc_find_node_by_ram_code() (git-fixes).
  - soc: atmel: fix device_node release in atmel_soc_device_init()
    (git-fixes).
  - fbdev: omapfb: Fix an OF node leak in
    dss_of_port_get_parent_device() (git-fixes).
  - ASoC: Intel: avs: Fix init-config parsing (git-fixes).
  - ASoC: Intel: avs: Fix theoretical infinite loop (git-fixes).
  - ASoC: Intel: avs: Fix the minimum firmware version numbers
    (git-fixes).
  - ASoC: Intel: avs: Do not readq() u32 registers (git-fixes).
  - ASoC: sun4i-spdif: Add clock multiplier settings (git-fixes).
  - ASoC: Intel: sof_sdw: correct mach_params->dmic_num (git-fixes).
  - ASoC: wcd937x: Use *-y for Makefile (git-fixes).
  - ASoC: mediatek: mt8365: Use *-y for Makefile (git-fixes).
  - ASoC: cs40l50: Use *-y for Makefile (git-fixes).
  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 83JX, 83MC and
    83NM (git-fixes).
  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 83LC (git-fixes).
  - ALSA: hda/realtek - Fixed headphone distorted sound on Acer
    Aspire A115-31 laptop (git-fixes).
  - ALSA: hda: Fix compilation of snd_hdac_adsp_xxx() helpers
    (git-fixes).
  - ALSA: seq: Make dependency on UMP clearer (git-fixes).
  - padata: fix UAF in padata_reorder (git-fixes).
  - padata: fix sysfs store callback check (git-fixes).
  - crypto: iaa - Fix IAA disabling that occurs when sync_mode is
    set to 'async' (git-fixes).
  - crypto: ixp4xx - fix OF node reference leaks in
    init_ixp_crypto() (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead invalid authsize
    (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead icv error (git-fixes).
  - rhashtable: Fix potential deadlock by moving schedule_work
    outside lock (git-fixes).
  - crypto: qce - fix priority to be less than ARMv8 CE (git-fixes).
  - crypto: qce - unregister previously registered algos in error
    path (git-fixes).
  - crypto: qce - fix goto jump in error path (git-fixes).
  - crypto: caam - use JobR's space to access page 0 regs
    (git-fixes).
  - crypto: api - Fix boot-up self-test race (git-fixes).
  - crypto: tegra - do not transfer req when tegra init fails
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix PFC_MASK for RZ/V2H and RZ/G3E
    (git-fixes).
  - pinctrl: amd: Take suspend type into consideration which pins
    are non-wake (git-fixes).
  - pinctrl: stm32: Add check for clk_enable() (git-fixes).
  - pinctrl: samsung: fix fwnode refcount cleanup if
    platform_get_irq_optional() fails (git-fixes).
  - pinctrl: samsung: Fix irq handling if an error occurs in
    exynos_irq_demux_eint16_31() (git-fixes).
  - pinctrl: nomadik: Add check for clk_enable() (git-fixes).
  - platform/x86: serdev_helpers: Check for serial_ctrl_uid ==
    NULL (git-fixes).
  - platform/x86: x86-android-tablets: make platform data be static
    (git-fixes).
  - platform/mellanox: mlxbf-pmc: incorrect type in assignment
    (git-fixes).
  - commit 04804af
  - Move upstreamed TPM patch into sorted section
  - commit a914dc3

++++ kernel-rt:

  - ALSA: hda/realtek: Enable Mute LED on HP Laptop 14s-fq1xxx
    (stable-fixes).
  - ALSA: usb-audio: Add delay quirk for USB Audio Device
    (stable-fixes).
  - ALSA: hda/realtek: Enable headset mic on Positivo C6400
    (stable-fixes).
  - commit 6acf6ed
  - rhashtable: Fix rhashtable_try_insert test (git-fixes).
  - commit f5a7305
  - mailbox: zynqmp: Remove invalid __percpu annotation in
    zynqmp_ipi_probe() (git-fixes).
  - mailbox: tegra-hsp: Clear mailbox before using message
    (git-fixes).
  - i3c: master: Fix missing 'ret' assignment in set_speed()
    (git-fixes).
  - i3c: dw: Fix use-after-free in dw_i3c_master driver due to
    race condition (git-fixes).
  - efi: sysfb_efi: fix W=1 warnings when EFI is not set
    (git-fixes).
  - of: address: Fix empty resource handling in
    __of_address_resource_bounds() (git-fixes).
  - of/fdt: Restore possibility to use both ACPI and FDT from
    bootloader (git-fixes).
  - of: reserved-memory: Do not make kmemleak ignore freed address
    (git-fixes).
  - of: reserved-memory: Fix using wrong number of cells to get
    property 'alignment' (git-fixes).
  - of: property: Avoiding using uninitialized variable @imaplen
    in parse_interrupt_map() (git-fixes).
  - of: Correct child specifier used as input of the 2nd nexus node
    (git-fixes).
  - of: Fix of_find_node_opts_by_path() handling of
    alias+path+options (git-fixes).
  - soc: samsung: exynos-pmu: Fix uninitialized ret in
    tensor_set_bits_atomic() (git-fixes).
  - firmware: qcom: scm: Cleanup global '__scm' on probe failures
    (git-fixes).
  - firmware: qcom: scm: Fix missing read barrier in
    qcom_scm_get_tzmem_pool() (git-fixes).
  - firmware: qcom: scm: Fix missing read barrier in
    qcom_scm_is_available() (git-fixes).
  - soc: qcom: socinfo: Avoid out of bounds read of serial number
    (git-fixes).
  - soc: qcom: smem_state: fix missing of_node_put in error path
    (git-fixes).
  - soc: qcom: llcc: Enable LLCC_WRCACHE at boot on X1 (git-fixes).
  - soc: mediatek: mtk-devapc: Fix leaking IO map on driver remove
    (git-fixes).
  - soc: mediatek: mtk-devapc: Fix leaking IO map on error paths
    (git-fixes).
  - memory: tegra20-emc: fix an OF node reference bug in
    tegra_emc_find_node_by_ram_code() (git-fixes).
  - soc: atmel: fix device_node release in atmel_soc_device_init()
    (git-fixes).
  - fbdev: omapfb: Fix an OF node leak in
    dss_of_port_get_parent_device() (git-fixes).
  - ASoC: Intel: avs: Fix init-config parsing (git-fixes).
  - ASoC: Intel: avs: Fix theoretical infinite loop (git-fixes).
  - ASoC: Intel: avs: Fix the minimum firmware version numbers
    (git-fixes).
  - ASoC: Intel: avs: Do not readq() u32 registers (git-fixes).
  - ASoC: sun4i-spdif: Add clock multiplier settings (git-fixes).
  - ASoC: Intel: sof_sdw: correct mach_params->dmic_num (git-fixes).
  - ASoC: wcd937x: Use *-y for Makefile (git-fixes).
  - ASoC: mediatek: mt8365: Use *-y for Makefile (git-fixes).
  - ASoC: cs40l50: Use *-y for Makefile (git-fixes).
  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 83JX, 83MC and
    83NM (git-fixes).
  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 83LC (git-fixes).
  - ALSA: hda/realtek - Fixed headphone distorted sound on Acer
    Aspire A115-31 laptop (git-fixes).
  - ALSA: hda: Fix compilation of snd_hdac_adsp_xxx() helpers
    (git-fixes).
  - ALSA: seq: Make dependency on UMP clearer (git-fixes).
  - padata: fix UAF in padata_reorder (git-fixes).
  - padata: fix sysfs store callback check (git-fixes).
  - crypto: iaa - Fix IAA disabling that occurs when sync_mode is
    set to 'async' (git-fixes).
  - crypto: ixp4xx - fix OF node reference leaks in
    init_ixp_crypto() (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead invalid authsize
    (git-fixes).
  - crypto: hisilicon/sec2 - fix for aead icv error (git-fixes).
  - rhashtable: Fix potential deadlock by moving schedule_work
    outside lock (git-fixes).
  - crypto: qce - fix priority to be less than ARMv8 CE (git-fixes).
  - crypto: qce - unregister previously registered algos in error
    path (git-fixes).
  - crypto: qce - fix goto jump in error path (git-fixes).
  - crypto: caam - use JobR's space to access page 0 regs
    (git-fixes).
  - crypto: api - Fix boot-up self-test race (git-fixes).
  - crypto: tegra - do not transfer req when tegra init fails
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix PFC_MASK for RZ/V2H and RZ/G3E
    (git-fixes).
  - pinctrl: amd: Take suspend type into consideration which pins
    are non-wake (git-fixes).
  - pinctrl: stm32: Add check for clk_enable() (git-fixes).
  - pinctrl: samsung: fix fwnode refcount cleanup if
    platform_get_irq_optional() fails (git-fixes).
  - pinctrl: samsung: Fix irq handling if an error occurs in
    exynos_irq_demux_eint16_31() (git-fixes).
  - pinctrl: nomadik: Add check for clk_enable() (git-fixes).
  - platform/x86: serdev_helpers: Check for serial_ctrl_uid ==
    NULL (git-fixes).
  - platform/x86: x86-android-tablets: make platform data be static
    (git-fixes).
  - platform/mellanox: mlxbf-pmc: incorrect type in assignment
    (git-fixes).
  - commit 04804af
  - Move upstreamed TPM patch into sorted section
  - commit a914dc3

++++ pcsc-ccid:

  - Version 1.6.1
    * fix 'parse' build issues on some systems (pthread & strlcpy)
    * Some other minor improvements

++++ python-referencing:

  - Update to version 0.36.2:
    * Release using the newer twine release to preserve PEP 639
    license metadata.

------------------------------------------------------------------
------------------  2025-1-24  -  Jan 24 2025  -------------------
------------------------------------------------------------------

++++ bash:

  - As in bash-sh there is only a symbolic link avoid to require a version

++++ drbd:

  -  drbd failed to build with SLFO kernel candidate (bsc#1235595)
    * update drbd.spec

++++ kernel-default:

  - dm thin: make get_first_thin use rcu-safe list first function (CVE-2025-21664 bsc#1236262)
  - commit bce62ed
  - selinux: ignore unknown extended permissions (CVE-2024-57931 bsc#1236192)
  - commit edbf793
  - net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute (CVE-2025-21653 bsc#1236161)
  - commit bfe69c3
  - ipvlan: Fix use-after-free in ipvlan_get_iflink() (CVE-2025-21652 bsc#1236160)
  - commit ed4d75b
  - net/sctp: Prevent autoclose integer overflow in sctp_association_init() (CVE-2024-57938 bsc#1236182)
  - commit cb64cb6
  - fgraph: Add READ_ONCE() when accessing fgraph_array[] (CVE-2024-57934 bsc#1236179)
  - commit f0f5c56
  - topology: Keep the cpumask unchanged when printing cpumap (CVE-2024-57917 bsc#1236127)
  - commit 29e8746
  - mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim() (CVE-2024-57884 bsc#1235948)
  - commit cd69bfc
  - netrom: check buffer length before accessing it (CVE-2024-57802 bsc#1235941)
  - commit fecc867
  - wifi: ath12k: fix tx power, max reg power update to firmware
    (git-fixes).
  - wifi: mt76: mt7996: fix ldpc setting (git-fixes).
  - wifi: mt76: mt7996: fix definition of tx descriptor (git-fixes).
  - wifi: mt76: mt7996: fix incorrect indexing of MIB FW event
    (git-fixes).
  - wifi: mt76: mt7996: fix HE Phy capability (git-fixes).
  - wifi: mt76: mt7996: fix the capability of reception of EHT MU
    PPDU (git-fixes).
  - wifi: mt76: mt7996: add max mpdu len capability (git-fixes).
  - wifi: mt76: mt7996: fix register mapping (git-fixes).
  - wifi: mt76: mt7915: fix register mapping (git-fixes).
  - wifi: mt76: mt7915: fix omac index assignment after hardware
    reset (git-fixes).
  - wifi: mt76: mt7915: firmware restart on devices with a second
    pcie link (git-fixes).
  - wifi: mt76: only enable tx worker after setting the channel
    (git-fixes).
  - wifi: mt76: mt7996: fix rx filter setting for bfee functionality
    (git-fixes).
  - wifi: mt76: mt7925: Properly handle responses for commands
    with events (git-fixes).
  - wifi: mt76: mt7925: Cleanup MLO settings post-disconnection
    (git-fixes).
  - wifi: mt76: mt7925: Update mt7925_mcu_uni_[tx,rx]_ba for MLO
    (git-fixes).
  - wifi: mt76: mt7925: Init secondary link PM state (git-fixes).
  - wifi: mt76: mt7925: Update secondary link PS flow (git-fixes).
  - wifi: mt76: mt7925: Update mt7925_unassign_vif_chanctx for
    per-link BSS (git-fixes).
  - wifi: mt76: mt7925: Update mt792x_rx_get_wcid for per-link STA
    (git-fixes).
  - wifi: mt76: mt7925: Update mt7925_mcu_sta_update for BC in
    ASSOC state (git-fixes).
  - wifi: mt76: Enhance mt7925_mac_link_sta_add to support MLO
    (git-fixes).
  - wifi: mt76: mt7925: Enhance mt7925_mac_link_bss_add to support
    MLO (git-fixes).
  - wifi: mt76: mt7925: Fix CNM Timeout with Single Active Link
    in MLO (git-fixes).
  - wifi: mt76: mt7925: fix wrong parameter for related cmd of
    chan info (git-fixes).
  - wifi: mt76: mt7925: Fix incorrect WCID phy_idx assignment
    (git-fixes).
  - wifi: mt76: mt7925: Fix incorrect WCID assignment for MLO
    (git-fixes).
  - wifi: mt76: mt7925: Fix incorrect MLD address in bss_mld_tlv
    for MLO support (git-fixes).
  - wifi: mt76: connac: Extend mt76_connac_mcu_uni_add_dev for MLO
    (git-fixes).
  - wifi: mt76: mt7915: fix overflows seen when writing limit
    attributes (git-fixes).
  - wifi: mt76: mt7996: fix overflows seen when writing limit
    attributes (git-fixes).
  - wifi: mt76: mt7925: fix the invalid ip address for arp offload
    (git-fixes).
  - wifi: mt76: mt7925: fix get wrong chip cap from incorrect
    pointer (git-fixes).
  - commit 0569918
  - wifi: mt76: mt7925: fix wrong band_idx setting when enable
    sniffer mode (git-fixes).
  - wifi: mt76: mt7925: fix NULL deref check in
    mt7925_change_vif_links (git-fixes).
  - wifi: mt76: mt7915: add module param to select 5 GHz or 6 GHz
    on MT7916 (git-fixes).
  - wifi: mt76: mt7915: Fix an error handling path in
    mt7915_add_interface() (git-fixes).
  - wifi: mt76: mt7921: fix using incorrect group cipher after
    disconnection (git-fixes).
  - wifi: mt76: mt76u_vendor_request: Do not print error messages
    when -EPROTO (git-fixes).
  - wifi: mt76: mt7915: Fix mesh scan on MT7916 DBDC (git-fixes).
  - wifi: mt76: mt7925: fix off by one in mt7925_load_clc()
    (git-fixes).
  - wifi: rtw88: 8703b: Fix RX/TX issues (git-fixes).
  - wifi: rtw89: fix race between cancel_hw_scan and hw_scan
    completion (git-fixes).
  - wifi: rtw89: mcc: consider time limits not divisible by 1024
    (git-fixes).
  - wifi: rtlwifi: rtl8821ae: Fix media status report (git-fixes).
  - wifi: cfg80211: adjust allocation of colocated AP data
    (git-fixes).
  - wifi: mac80211: don't flush non-uploaded STAs (git-fixes).
  - wifi: mac80211: Fix common size calculation for ML element
    (git-fixes).
  - wifi: mac80211: fix tid removal during mesh forwarding
    (git-fixes).
  - wifi: cfg80211: Move cfg80211_scan_req_add_chan() n_channels
    increment earlier (git-fixes).
  - wifi: mac80211: prohibit deactivating all links (git-fixes).
  - wifi: iwlwifi: mvm: don't count mgmt frames as MPDU (git-fixes).
  - wifi: iwlwifi: mvm: avoid NULL pointer dereference (git-fixes).
  - commit 98d9d6c
  - tools: Sync if_xdp.h uapi tooling header (git-fixes).
  - wifi: iwlwifi: fw: read STEP table from correct UEFI var
    (git-fixes).
  - wifi: wlcore: fix unbalanced pm_runtime calls (git-fixes).
  - wifi: mt76: mt7996: fix invalid interface combinations
    (git-fixes).
  - wifi: rtlwifi: pci: wait for firmware loading before releasing
    memory (git-fixes).
  - wifi: rtlwifi: fix memory leaks and invalid access at probe
    error path (git-fixes).
  - wifi: rtlwifi: destroy workqueue at rtl_deinit_core (git-fixes).
  - wifi: rtlwifi: remove unused check_buddy_priv (git-fixes).
  - wifi: rtlwifi: usb: fix workqueue leak when probe fails
    (git-fixes).
  - wifi: rtlwifi: fix init_sw_vars leak when probe fails
    (git-fixes).
  - wifi: rtlwifi: wait for firmware loading before releasing memory
    (git-fixes).
  - wifi: rtlwifi: rtl8192se: rise completion of firmware loading
    as last step (git-fixes).
  - wifi: rtlwifi: do not complete firmware loading needlessly
    (git-fixes).
  - wifi: rtlwifi: rtl8821ae: phy: restore removed code to fix
    infinite loop (git-fixes).
  - wifi: brcmfmac: add missing header include for brcmf_dbg
    (git-fixes).
  - wifi: ath11k: cleanup struct ath11k_mon_data (git-fixes).
  - wifi: ath11k: cleanup struct ath11k_reg_tpc_power_info
    (git-fixes).
  - wifi: wcn36xx: fix channel survey memory allocation size
    (git-fixes).
  - wifi: ath11k: Fix unexpected return buffer manager error for
    WCN6750/WCN6855 (git-fixes).
  - wifi: cfg80211: tests: Fix potential NULL dereference in
    test_cfg80211_parse_colocated_ap() (git-fixes).
  - commit d9471b1
  - keys: drop shadowing dead prototype (git-fixes).
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch.
  - commit 9473efe
  - ktest.pl: Fix typo "accesing" (git-fixes).
  - ktest.pl: Fix typo in comment (git-fixes).
  - ktest.pl: Remove unused declarations in run_bisect_test function
    (git-fixes).
  - ktest.pl: Check kernelrelease return in get_version (git-fixes).
  - selftests: ktap_helpers: Fix uninitialized variable (git-fixes).
  - selftests/landlock: Fix error message (git-fixes).
  - selftests/landlock: Fix build with non-default pthread linking
    (git-fixes).
  - landlock: Handle weird files (git-fixes).
  - KEYS: trusted: dcp: fix improper sg use with CONFIG_VMAP_STACK=y
    (git-fixes).
  - selftests/rseq: Fix handling of glibc without rseq support
    (git-fixes).
  - selftests/ftrace: Fix to use remount when testing mount GID
    option (git-fixes).
  - selftests: harness: fix printing of mismatch values in
    __EXPECT() (git-fixes).
  - selftests: timers: clocksource-switch: Adapt progress to
    kselftest framework (git-fixes).
  - selftest: media_tests: fix trivial UAF typo (git-fixes).
  - Input: davinci-keyscan - remove leftover header (git-fixes).
  - Input: bbnsm_pwrkey - add remove hook (git-fixes).
  - HID: core: Fix assumption that Resolution Multipliers must be
    in Logical Collections (git-fixes).
  - HID: fix generic desktop D-Pad controls (git-fixes).
  - HID: hid-thrustmaster: Fix warning in thrustmaster_probe by
    adding endpoint check (git-fixes).
  - HID: multitouch: fix support for Goodix PID 0x01e9 (git-fixes).
  - Revert "HID: multitouch: Add support for lenovo Y9000P Touchpad"
    (stable-fixes).
  - HID: wacom: Initialize brightness of LED trigger (git-fixes).
  - ipmi: ssif_bmc: Fix new request loss when bmc ready for a
    response (git-fixes).
  - ipmi: ipmb: Add check devm_kasprintf() returned value
    (git-fixes).
  - pwm: stm32: Add check for clk_enable() (git-fixes).
  - pwm: stm32-lp: Add check for clk_enable() (git-fixes).
  - hwmon: Fix help text for aspeed-g6-pwm-tach (git-fixes).
  - leds: cht-wcove: Use devm_led_classdev_register() to avoid
    memory leak (git-fixes).
  - leds: netxbig: Fix an OF node reference leak in
    netxbig_leds_get_of_pdata() (git-fixes).
  - leds: lp8860: Write full EEPROM, not only half of it
    (git-fixes).
  - mfd: syscon: Fix race in device_node_get_regmap() (git-fixes).
  - HID: hid-sensor-hub: don't use stale platform-data on remove
    (git-fixes).
  - spi: zynq-qspi: Add check for clk_enable() (git-fixes).
  - regulator: of: Implement the unwind path of of_regulator_match()
    (git-fixes).
  - gpio: pca953x: log an error when failing to get the reset GPIO
    (git-fixes).
  - net/rose: prevent integer overflows in rose_setsockopt()
    (git-fixes).
  - selinux: Fix SCTP error inconsistency in selinux_socket_bind()
    (git-fixes).
  - selftests/powerpc: Fix argument order to timer_sub()
    (git-fixes).
  - commit df484ba
  - drm/connector: hdmi: Do atomic check when necessary (git-fixes).
  - drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()
    (git-fixes).
  - drm/msm/mdp4: correct LCDC regulator name (git-fixes).
  - drm/msm: don't clean up priv->kms prematurely (git-fixes).
  - drm/msm: Check return value of of_dma_configure() (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on X1E80100 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8650 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8550 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8350 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8250 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SC8180X (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8150 (git-fixes).
  - drm/msm/dpu: provide DSPP and correct LM config for SDM670
    (git-fixes).
  - drm/msm/dpu1: don't choke on disabling the writeback connector
    (git-fixes).
  - drm/msm/dpu: fix x1e80100 intf_6 underrun/vsync interrupt
    (git-fixes).
  - drm/msm/hdmi: simplify code in pll_get_integloop_gain
    (git-fixes).
  - drm/msm/dp: set safe_to_exit_level before printing it
    (git-fixes).
  - drm/amdgpu: fix gpu recovery disable with per queue reset
    (git-fixes).
  - drm/amdgpu: tear down ttm range manager for doorbell in
    amdgpu_ttm_fini() (git-fixes).
  - drm/etnaviv: Fix page property being used for non writecombine
    buffers (git-fixes).
  - drm/xe/tracing: Fix a potential TP_printk UAF (git-fixes).
  - Revert "drm/i915/dpt: Make DPT object unshrinkable"
    (stable-fixes).
  - Revert "drm/amd/display: Fix green screen issue after suspend"
    (stable-fixes).
  - drm/amdgpu: simplify return statement in amdgpu_ras_eeprom_init
    (git-fixes).
  - drm/amdgpu/vcn: reset fw_shared under SRIOV (git-fixes).
  - drm/amdgpu: Fix potential NULL pointer dereference in
    atomctrl_get_smc_sclk_range_table (git-fixes).
  - drm/amd/pm: Fix an error handling path in
    vega10_enable_se_edc_force_stall_config() (git-fixes).
  - drm/bridge: it6505: Change definition of AUX_FIFO_MAX_SIZE
    (git-fixes).
  - drm/rockchip: vop2: include rockchip_drm_drv.h (git-fixes).
  - commit b984ce6
  - ACPI: fan: cleanup resources in the error path of .probe()
    (git-fixes).
  - cpupower: fix TSC MHz calculation (git-fixes).
  - Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc
    (git-fixes).
  - Bluetooth: btrtl: check for NULL in btrtl_setup_realtek()
    (git-fixes).
  - Bluetooth: btbcm: Fix NULL deref in btbcm_get_board_name()
    (git-fixes).
  - ax25: rcu protect dev->ax25_ptr (git-fixes).
  - Align git commit ID abbreviation guidelines and checks
    (git-fixes).
  - drm/rockchip: vop2: Add check for 32 bpp format for rk3588
    (git-fixes).
  - drm/rockchip: vop2: Check linear format for Cluster windows
    on rk3566/8 (git-fixes).
  - drm/rockchip: vop2: Setup delay cycle for Esmart2/3 (git-fixes).
  - drm/rockchip: vop2: Set AXI id for rk3588 (git-fixes).
  - drm/connector: Allow clearing HDMI infoframes (git-fixes).
  - drm/rcar-du: dsi: Fix PHY lock bit check (git-fixes).
  - drm/rockchip: vop2: Fix the windows switch between different
    layers (git-fixes).
  - drm/panthor: Preserve the result returned by panthor_fw_resume()
    (git-fixes).
  - drm/rockchip: vop2: Fix the mixer alpha setup for layer 0
    (git-fixes).
  - drm/rockchip: vop2: Fix cluster windows alpha ctrl regsiters
    offset (git-fixes).
  - drm: renesas: rz-du: Drop DU_MCR0_DPI_OE macro (git-fixes).
  - drm: renesas: rz-du: Increase supported resolutions (git-fixes).
  - drm/rockchip: vop2: fix rk3588 dp+dsi maxclk verification
    (git-fixes).
  - drm/tidss: Fix race condition while handling interrupt registers
    (git-fixes).
  - drm/tidss: Clear the interrupt status for interrupts being
    disabled (git-fixes).
  - drm/tidss: Fix issue in irq handling causing irq-flood issue
    (git-fixes).
  - drm/v3d: Stop active perfmon if it is being destroyed
    (git-fixes).
  - accel/ivpu: Fix Qemu crash when running in passthrough
    (git-fixes).
  - drm/v3d: Fix performance counter source settings on V3D 7.x
    (git-fixes).
  - drm/rockchip: cdn-dp: Use drm_connector_helper_hpd_irq_event()
    (git-fixes).
  - commit ef0aef7
  - net/ipv6: release expired exception dst cached in socket
    (CVE-2024-56644 bsc#1235133).
  - commit a89d415
  - Update config files.
  - commit 5e1aa47
  - fortify: Move FORTIFY_SOURCE under 'Kernel hardening options'
    (jsc#PED-11838).
  - mm: security: Check early if HARDENED_USERCOPY is enabled
    (jsc#PED-11838).
  - mm: security: Allow default HARDENED_USERCOPY to be set at
    compile time (jsc#PED-11838).
  - mm: security: Move hardened usercopy under 'Kernel hardening
    options' (jsc#PED-11838).
  - commit 1f3276d
  - Delete
    patches.suse/mm-security-Allow-default-HARDENED_USERCOPY-to-be-set-at-compile-time.patch.
  - Delete
    patches.suse/mm-security-Move-hardened-usercopy-under-Kernel-hardening-options.patch.
  - commit 871e2b7
  - drm/i915/fb: Relax clear color alignment to 64 bytes
    (stable-fixes).
  - drm/amdgpu: fix fw attestation for MP0_14_0_{2/3}
    (stable-fixes).
  - drm/amdgpu: always sync the GFX pipe on ctx switch
    (stable-fixes).
  - drm/amdgpu: disable gfxoff with the compute workload on gfx12
    (stable-fixes).
  - drm/amd/display: Disable replay and psr while VRR is enabled
    (stable-fixes).
  - drm/amd/display: Fix PSR-SU not support but still call the
    amdgpu_dm_psr_enable (stable-fixes).
  - drm/amdgpu/smu13: update powersave optimizations (stable-fixes).
  - nouveau/fence: handle cross device fences properly
    (stable-fixes).
  - commit a60ee67

++++ kernel-rt:

  - dm thin: make get_first_thin use rcu-safe list first function (CVE-2025-21664 bsc#1236262)
  - commit bce62ed
  - selinux: ignore unknown extended permissions (CVE-2024-57931 bsc#1236192)
  - commit edbf793
  - net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute (CVE-2025-21653 bsc#1236161)
  - commit bfe69c3
  - ipvlan: Fix use-after-free in ipvlan_get_iflink() (CVE-2025-21652 bsc#1236160)
  - commit ed4d75b
  - net/sctp: Prevent autoclose integer overflow in sctp_association_init() (CVE-2024-57938 bsc#1236182)
  - commit cb64cb6
  - fgraph: Add READ_ONCE() when accessing fgraph_array[] (CVE-2024-57934 bsc#1236179)
  - commit f0f5c56
  - topology: Keep the cpumask unchanged when printing cpumap (CVE-2024-57917 bsc#1236127)
  - commit 29e8746
  - mm: vmscan: account for free pages to prevent infinite Loop in throttle_direct_reclaim() (CVE-2024-57884 bsc#1235948)
  - commit cd69bfc
  - netrom: check buffer length before accessing it (CVE-2024-57802 bsc#1235941)
  - commit fecc867
  - wifi: ath12k: fix tx power, max reg power update to firmware
    (git-fixes).
  - wifi: mt76: mt7996: fix ldpc setting (git-fixes).
  - wifi: mt76: mt7996: fix definition of tx descriptor (git-fixes).
  - wifi: mt76: mt7996: fix incorrect indexing of MIB FW event
    (git-fixes).
  - wifi: mt76: mt7996: fix HE Phy capability (git-fixes).
  - wifi: mt76: mt7996: fix the capability of reception of EHT MU
    PPDU (git-fixes).
  - wifi: mt76: mt7996: add max mpdu len capability (git-fixes).
  - wifi: mt76: mt7996: fix register mapping (git-fixes).
  - wifi: mt76: mt7915: fix register mapping (git-fixes).
  - wifi: mt76: mt7915: fix omac index assignment after hardware
    reset (git-fixes).
  - wifi: mt76: mt7915: firmware restart on devices with a second
    pcie link (git-fixes).
  - wifi: mt76: only enable tx worker after setting the channel
    (git-fixes).
  - wifi: mt76: mt7996: fix rx filter setting for bfee functionality
    (git-fixes).
  - wifi: mt76: mt7925: Properly handle responses for commands
    with events (git-fixes).
  - wifi: mt76: mt7925: Cleanup MLO settings post-disconnection
    (git-fixes).
  - wifi: mt76: mt7925: Update mt7925_mcu_uni_[tx,rx]_ba for MLO
    (git-fixes).
  - wifi: mt76: mt7925: Init secondary link PM state (git-fixes).
  - wifi: mt76: mt7925: Update secondary link PS flow (git-fixes).
  - wifi: mt76: mt7925: Update mt7925_unassign_vif_chanctx for
    per-link BSS (git-fixes).
  - wifi: mt76: mt7925: Update mt792x_rx_get_wcid for per-link STA
    (git-fixes).
  - wifi: mt76: mt7925: Update mt7925_mcu_sta_update for BC in
    ASSOC state (git-fixes).
  - wifi: mt76: Enhance mt7925_mac_link_sta_add to support MLO
    (git-fixes).
  - wifi: mt76: mt7925: Enhance mt7925_mac_link_bss_add to support
    MLO (git-fixes).
  - wifi: mt76: mt7925: Fix CNM Timeout with Single Active Link
    in MLO (git-fixes).
  - wifi: mt76: mt7925: fix wrong parameter for related cmd of
    chan info (git-fixes).
  - wifi: mt76: mt7925: Fix incorrect WCID phy_idx assignment
    (git-fixes).
  - wifi: mt76: mt7925: Fix incorrect WCID assignment for MLO
    (git-fixes).
  - wifi: mt76: mt7925: Fix incorrect MLD address in bss_mld_tlv
    for MLO support (git-fixes).
  - wifi: mt76: connac: Extend mt76_connac_mcu_uni_add_dev for MLO
    (git-fixes).
  - wifi: mt76: mt7915: fix overflows seen when writing limit
    attributes (git-fixes).
  - wifi: mt76: mt7996: fix overflows seen when writing limit
    attributes (git-fixes).
  - wifi: mt76: mt7925: fix the invalid ip address for arp offload
    (git-fixes).
  - wifi: mt76: mt7925: fix get wrong chip cap from incorrect
    pointer (git-fixes).
  - commit 0569918
  - wifi: mt76: mt7925: fix wrong band_idx setting when enable
    sniffer mode (git-fixes).
  - wifi: mt76: mt7925: fix NULL deref check in
    mt7925_change_vif_links (git-fixes).
  - wifi: mt76: mt7915: add module param to select 5 GHz or 6 GHz
    on MT7916 (git-fixes).
  - wifi: mt76: mt7915: Fix an error handling path in
    mt7915_add_interface() (git-fixes).
  - wifi: mt76: mt7921: fix using incorrect group cipher after
    disconnection (git-fixes).
  - wifi: mt76: mt76u_vendor_request: Do not print error messages
    when -EPROTO (git-fixes).
  - wifi: mt76: mt7915: Fix mesh scan on MT7916 DBDC (git-fixes).
  - wifi: mt76: mt7925: fix off by one in mt7925_load_clc()
    (git-fixes).
  - wifi: rtw88: 8703b: Fix RX/TX issues (git-fixes).
  - wifi: rtw89: fix race between cancel_hw_scan and hw_scan
    completion (git-fixes).
  - wifi: rtw89: mcc: consider time limits not divisible by 1024
    (git-fixes).
  - wifi: rtlwifi: rtl8821ae: Fix media status report (git-fixes).
  - wifi: cfg80211: adjust allocation of colocated AP data
    (git-fixes).
  - wifi: mac80211: don't flush non-uploaded STAs (git-fixes).
  - wifi: mac80211: Fix common size calculation for ML element
    (git-fixes).
  - wifi: mac80211: fix tid removal during mesh forwarding
    (git-fixes).
  - wifi: cfg80211: Move cfg80211_scan_req_add_chan() n_channels
    increment earlier (git-fixes).
  - wifi: mac80211: prohibit deactivating all links (git-fixes).
  - wifi: iwlwifi: mvm: don't count mgmt frames as MPDU (git-fixes).
  - wifi: iwlwifi: mvm: avoid NULL pointer dereference (git-fixes).
  - commit 98d9d6c
  - tools: Sync if_xdp.h uapi tooling header (git-fixes).
  - wifi: iwlwifi: fw: read STEP table from correct UEFI var
    (git-fixes).
  - wifi: wlcore: fix unbalanced pm_runtime calls (git-fixes).
  - wifi: mt76: mt7996: fix invalid interface combinations
    (git-fixes).
  - wifi: rtlwifi: pci: wait for firmware loading before releasing
    memory (git-fixes).
  - wifi: rtlwifi: fix memory leaks and invalid access at probe
    error path (git-fixes).
  - wifi: rtlwifi: destroy workqueue at rtl_deinit_core (git-fixes).
  - wifi: rtlwifi: remove unused check_buddy_priv (git-fixes).
  - wifi: rtlwifi: usb: fix workqueue leak when probe fails
    (git-fixes).
  - wifi: rtlwifi: fix init_sw_vars leak when probe fails
    (git-fixes).
  - wifi: rtlwifi: wait for firmware loading before releasing memory
    (git-fixes).
  - wifi: rtlwifi: rtl8192se: rise completion of firmware loading
    as last step (git-fixes).
  - wifi: rtlwifi: do not complete firmware loading needlessly
    (git-fixes).
  - wifi: rtlwifi: rtl8821ae: phy: restore removed code to fix
    infinite loop (git-fixes).
  - wifi: brcmfmac: add missing header include for brcmf_dbg
    (git-fixes).
  - wifi: ath11k: cleanup struct ath11k_mon_data (git-fixes).
  - wifi: ath11k: cleanup struct ath11k_reg_tpc_power_info
    (git-fixes).
  - wifi: wcn36xx: fix channel survey memory allocation size
    (git-fixes).
  - wifi: ath11k: Fix unexpected return buffer manager error for
    WCN6750/WCN6855 (git-fixes).
  - wifi: cfg80211: tests: Fix potential NULL dereference in
    test_cfg80211_parse_colocated_ap() (git-fixes).
  - commit d9471b1
  - keys: drop shadowing dead prototype (git-fixes).
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch.
  - commit 9473efe
  - ktest.pl: Fix typo "accesing" (git-fixes).
  - ktest.pl: Fix typo in comment (git-fixes).
  - ktest.pl: Remove unused declarations in run_bisect_test function
    (git-fixes).
  - ktest.pl: Check kernelrelease return in get_version (git-fixes).
  - selftests: ktap_helpers: Fix uninitialized variable (git-fixes).
  - selftests/landlock: Fix error message (git-fixes).
  - selftests/landlock: Fix build with non-default pthread linking
    (git-fixes).
  - landlock: Handle weird files (git-fixes).
  - KEYS: trusted: dcp: fix improper sg use with CONFIG_VMAP_STACK=y
    (git-fixes).
  - selftests/rseq: Fix handling of glibc without rseq support
    (git-fixes).
  - selftests/ftrace: Fix to use remount when testing mount GID
    option (git-fixes).
  - selftests: harness: fix printing of mismatch values in
    __EXPECT() (git-fixes).
  - selftests: timers: clocksource-switch: Adapt progress to
    kselftest framework (git-fixes).
  - selftest: media_tests: fix trivial UAF typo (git-fixes).
  - Input: davinci-keyscan - remove leftover header (git-fixes).
  - Input: bbnsm_pwrkey - add remove hook (git-fixes).
  - HID: core: Fix assumption that Resolution Multipliers must be
    in Logical Collections (git-fixes).
  - HID: fix generic desktop D-Pad controls (git-fixes).
  - HID: hid-thrustmaster: Fix warning in thrustmaster_probe by
    adding endpoint check (git-fixes).
  - HID: multitouch: fix support for Goodix PID 0x01e9 (git-fixes).
  - Revert "HID: multitouch: Add support for lenovo Y9000P Touchpad"
    (stable-fixes).
  - HID: wacom: Initialize brightness of LED trigger (git-fixes).
  - ipmi: ssif_bmc: Fix new request loss when bmc ready for a
    response (git-fixes).
  - ipmi: ipmb: Add check devm_kasprintf() returned value
    (git-fixes).
  - pwm: stm32: Add check for clk_enable() (git-fixes).
  - pwm: stm32-lp: Add check for clk_enable() (git-fixes).
  - hwmon: Fix help text for aspeed-g6-pwm-tach (git-fixes).
  - leds: cht-wcove: Use devm_led_classdev_register() to avoid
    memory leak (git-fixes).
  - leds: netxbig: Fix an OF node reference leak in
    netxbig_leds_get_of_pdata() (git-fixes).
  - leds: lp8860: Write full EEPROM, not only half of it
    (git-fixes).
  - mfd: syscon: Fix race in device_node_get_regmap() (git-fixes).
  - HID: hid-sensor-hub: don't use stale platform-data on remove
    (git-fixes).
  - spi: zynq-qspi: Add check for clk_enable() (git-fixes).
  - regulator: of: Implement the unwind path of of_regulator_match()
    (git-fixes).
  - gpio: pca953x: log an error when failing to get the reset GPIO
    (git-fixes).
  - net/rose: prevent integer overflows in rose_setsockopt()
    (git-fixes).
  - selinux: Fix SCTP error inconsistency in selinux_socket_bind()
    (git-fixes).
  - selftests/powerpc: Fix argument order to timer_sub()
    (git-fixes).
  - commit df484ba
  - drm/connector: hdmi: Do atomic check when necessary (git-fixes).
  - drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()
    (git-fixes).
  - drm/msm/mdp4: correct LCDC regulator name (git-fixes).
  - drm/msm: don't clean up priv->kms prematurely (git-fixes).
  - drm/msm: Check return value of of_dma_configure() (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on X1E80100 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8650 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8550 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8350 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8250 (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SC8180X (git-fixes).
  - drm/msm/dpu: link DSPP_2/_3 blocks on SM8150 (git-fixes).
  - drm/msm/dpu: provide DSPP and correct LM config for SDM670
    (git-fixes).
  - drm/msm/dpu1: don't choke on disabling the writeback connector
    (git-fixes).
  - drm/msm/dpu: fix x1e80100 intf_6 underrun/vsync interrupt
    (git-fixes).
  - drm/msm/hdmi: simplify code in pll_get_integloop_gain
    (git-fixes).
  - drm/msm/dp: set safe_to_exit_level before printing it
    (git-fixes).
  - drm/amdgpu: fix gpu recovery disable with per queue reset
    (git-fixes).
  - drm/amdgpu: tear down ttm range manager for doorbell in
    amdgpu_ttm_fini() (git-fixes).
  - drm/etnaviv: Fix page property being used for non writecombine
    buffers (git-fixes).
  - drm/xe/tracing: Fix a potential TP_printk UAF (git-fixes).
  - Revert "drm/i915/dpt: Make DPT object unshrinkable"
    (stable-fixes).
  - Revert "drm/amd/display: Fix green screen issue after suspend"
    (stable-fixes).
  - drm/amdgpu: simplify return statement in amdgpu_ras_eeprom_init
    (git-fixes).
  - drm/amdgpu/vcn: reset fw_shared under SRIOV (git-fixes).
  - drm/amdgpu: Fix potential NULL pointer dereference in
    atomctrl_get_smc_sclk_range_table (git-fixes).
  - drm/amd/pm: Fix an error handling path in
    vega10_enable_se_edc_force_stall_config() (git-fixes).
  - drm/bridge: it6505: Change definition of AUX_FIFO_MAX_SIZE
    (git-fixes).
  - drm/rockchip: vop2: include rockchip_drm_drv.h (git-fixes).
  - commit b984ce6
  - ACPI: fan: cleanup resources in the error path of .probe()
    (git-fixes).
  - cpupower: fix TSC MHz calculation (git-fixes).
  - Bluetooth: L2CAP: handle NULL sock pointer in l2cap_sock_alloc
    (git-fixes).
  - Bluetooth: btrtl: check for NULL in btrtl_setup_realtek()
    (git-fixes).
  - Bluetooth: btbcm: Fix NULL deref in btbcm_get_board_name()
    (git-fixes).
  - ax25: rcu protect dev->ax25_ptr (git-fixes).
  - Align git commit ID abbreviation guidelines and checks
    (git-fixes).
  - drm/rockchip: vop2: Add check for 32 bpp format for rk3588
    (git-fixes).
  - drm/rockchip: vop2: Check linear format for Cluster windows
    on rk3566/8 (git-fixes).
  - drm/rockchip: vop2: Setup delay cycle for Esmart2/3 (git-fixes).
  - drm/rockchip: vop2: Set AXI id for rk3588 (git-fixes).
  - drm/connector: Allow clearing HDMI infoframes (git-fixes).
  - drm/rcar-du: dsi: Fix PHY lock bit check (git-fixes).
  - drm/rockchip: vop2: Fix the windows switch between different
    layers (git-fixes).
  - drm/panthor: Preserve the result returned by panthor_fw_resume()
    (git-fixes).
  - drm/rockchip: vop2: Fix the mixer alpha setup for layer 0
    (git-fixes).
  - drm/rockchip: vop2: Fix cluster windows alpha ctrl regsiters
    offset (git-fixes).
  - drm: renesas: rz-du: Drop DU_MCR0_DPI_OE macro (git-fixes).
  - drm: renesas: rz-du: Increase supported resolutions (git-fixes).
  - drm/rockchip: vop2: fix rk3588 dp+dsi maxclk verification
    (git-fixes).
  - drm/tidss: Fix race condition while handling interrupt registers
    (git-fixes).
  - drm/tidss: Clear the interrupt status for interrupts being
    disabled (git-fixes).
  - drm/tidss: Fix issue in irq handling causing irq-flood issue
    (git-fixes).
  - drm/v3d: Stop active perfmon if it is being destroyed
    (git-fixes).
  - accel/ivpu: Fix Qemu crash when running in passthrough
    (git-fixes).
  - drm/v3d: Fix performance counter source settings on V3D 7.x
    (git-fixes).
  - drm/rockchip: cdn-dp: Use drm_connector_helper_hpd_irq_event()
    (git-fixes).
  - commit ef0aef7
  - net/ipv6: release expired exception dst cached in socket
    (CVE-2024-56644 bsc#1235133).
  - commit a89d415
  - Update config files.
  - commit 5e1aa47
  - fortify: Move FORTIFY_SOURCE under 'Kernel hardening options'
    (jsc#PED-11838).
  - mm: security: Check early if HARDENED_USERCOPY is enabled
    (jsc#PED-11838).
  - mm: security: Allow default HARDENED_USERCOPY to be set at
    compile time (jsc#PED-11838).
  - mm: security: Move hardened usercopy under 'Kernel hardening
    options' (jsc#PED-11838).
  - commit 1f3276d
  - Delete
    patches.suse/mm-security-Allow-default-HARDENED_USERCOPY-to-be-set-at-compile-time.patch.
  - Delete
    patches.suse/mm-security-Move-hardened-usercopy-under-Kernel-hardening-options.patch.
  - commit 871e2b7
  - drm/i915/fb: Relax clear color alignment to 64 bytes
    (stable-fixes).
  - drm/amdgpu: fix fw attestation for MP0_14_0_{2/3}
    (stable-fixes).
  - drm/amdgpu: always sync the GFX pipe on ctx switch
    (stable-fixes).
  - drm/amdgpu: disable gfxoff with the compute workload on gfx12
    (stable-fixes).
  - drm/amd/display: Disable replay and psr while VRR is enabled
    (stable-fixes).
  - drm/amd/display: Fix PSR-SU not support but still call the
    amdgpu_dm_psr_enable (stable-fixes).
  - drm/amdgpu/smu13: update powersave optimizations (stable-fixes).
  - nouveau/fence: handle cross device fences properly
    (stable-fixes).
  - commit a60ee67

++++ multipath-tools:

  - Update to version 0.11.0+164+suse.24eeee7
  - Reviewed Upstream changes from 0.12 development
    * Continued rework of the path checker loop
    * multipathd now sets the port_state of Fibre Channel remote ports to
    "marginal" for NVMe devices, too (with nvme_core.multipath=N only).
    * Make sure maps are reloaded in the path checker loop after detecting an
    inconsistent or wrong kernel state (bsc#1236392)
    * Make sure udev and systemd notice changes in multipath path state
    when devices are added to or removed from multipath maps (bsc#1236321)
    * Fix path grouping if a path device is added while offline with group_by_tpg
    and group_by_serial path grouping policy
    (gh#opensvc/multipath-tools#108, bsc#1236392)
    * Fix the problem that `group_by_tpg` might be disabled if one or more
    paths were offline during initial configuration (bsc#1236392)
    * Fix multipathd crash because of invalid path group index value, for example
    if an invalid path device was removed from a map.
    (gh#opensvc/multipath-tools#105, bsc#1236392)
  - Changes in Upstream 0.11.0 (see also NEWS.md)
    * multipathd: set rport port_state to marginal for NVMe devices
    * Fixed a memory leak in the nvme foreign library.
    * Fixed a problem in the marginal path detection algorithm that could cause
    the io error check for a recently failed path to be delayed.
    (bsc#1236390)
    * multipath-tools: add HPE MSA Gen7 (2070/2072) to hwtable
    * multipath-tools: add SCST to hwtable
    * Add defaults for SCST and HPE MSA Gen7 to hwtable
    * Reduce log level of harmless "map ... doesn't exist" message
    (bsc#1236390)
    * Fixes for handling empty or incompletely created multipath maps
    (bsc#1236390)
    * During map creation, fixed the case where a map with different name, but
    matching UUID and matching type was already present. multipathd
    previously failed to set up such maps. Now it will reload them with the
    correct content. (bsc#1236390)

++++ ncurses:

  - Drop support of build ncurses applications with ABI 5 but leave
    the shared libraries for older applications using ABI 5
  - Add new package libncurses6-compat with the shared libraries
    without weak (p)thread support for foreign ncurses applications.
    Use with LD_LIBRARY_PATH=/usr/lib64/ncurses6nt (boo#1132282)

++++ libpwquality:

  - pwquality.conf moved from /etc/security to /usr/lib/security

++++ libseccomp:

  - Update to release 2.6.0
    * Multiplexed syscall support for ppc
    * Add support for the SECCOMP_FILTER_FLAG_WAIT_KILLABLE_RECV flag
    * Add support for transactions with the
    seccomp_transaction_start(), seccomp_transaction_commit(), and
    seccomp_transaction_reject() APIs
    * Add support for binary tree filters without syscalls
    * Add support for the kernel’s implementation change of
    SECCOMP_IOCTL_NOTIF_ID_VALID

++++ libselinux:

  - Update selinux-ready to clarify that kernel options aren't necessary
    on newer (open)SUSE versions

++++ osinfo-db:

  - Add support for openSUSE Leap 16.0 (jsc#PED-8910)
    add-opensuse-leap-16.0-support.patch

++++ python-distro:

  - Use libalternatives instead of update-alternatives, bsc#1235785

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#190
  - re-add --refresh option (bsc#1236393)
  - update tests
  - 1.24

------------------------------------------------------------------
------------------  2025-1-23  -  Jan 23 2025  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Add config-server subpackage (bsc#1224868).

++++ ca-certificates-mozilla:

  - Define two macros to break a build cycle with p11-kit.

++++ kernel-default:

  - Update
    patches.suse/ALSA-seq-oss-Fix-races-at-processing-SysEx-messages.patch
    (stable-fixes CVE-2024-57893 bsc#1235920).
  - Update
    patches.suse/RDMA-bnxt_re-Fix-max-SGEs-for-the-Work-Request.patch
    (jsc#PED-10682 jsc#PED-11231 CVE-2024-57936 bsc#1236181).
  - Update
    patches.suse/RDMA-hns-Fix-accessing-invalid-dip_ctx-during-destro.patch
    (git-fixes CVE-2024-57935 bsc#1236180).
  - Update
    patches.suse/RDMA-uverbs-Prevent-integer-overflow-issue.patch
    (git-fixes CVE-2024-57890 bsc#1235919).
  - Update
    patches.suse/arm64-ptrace-fix-partial-SETREGSET-for-NT_ARM_TAGGED_ADDR_CTRL.patch
    (git-fixes CVE-2024-57874 bsc#1235808).
  - Update
    patches.suse/cpufreq-CPPC-Fix-possible-null-ptr-deref-for-cppc_ge.patch
    (git-fixes CVE-2024-53230 bsc#1235976).
  - Update
    patches.suse/cpufreq-CPPC-Fix-possible-null-ptr-deref-for-cpufreq.patch
    (git-fixes CVE-2024-53231 bsc#1235977).
  - Update
    patches.suse/drm-adv7511-Fix-use-after-free-in-adv7533_attach_dsi.patch
    (git-fixes CVE-2024-57887 bsc#1235952).
  - Update
    patches.suse/drm-amd-display-Add-check-for-granularity-in-dml-cei.patch
    (stable-fixes CVE-2024-57922 bsc#1236080).
  - Update
    patches.suse/drm-amd-display-fix-divide-error-in-DM-plane-scale-c.patch
    (git-fixes CVE-2024-57919 bsc#1236070).
  - Update
    patches.suse/drm-amd-display-fix-page-fault-due-to-max-surface-de.patch
    (git-fixes CVE-2024-57918 bsc#1236128).
  - Update
    patches.suse/drm-amdgpu-Add-a-lock-when-accessing-the-buddy-trim-.patch
    (git-fixes CVE-2024-57921 bsc#1236076).
  - Update
    patches.suse/drm-amdkfd-Correct-the-migration-DMA-map-direction.patch
    (stable-fixes CVE-2024-57897 bsc#1235969).
  - Update
    patches.suse/drm-amdkfd-wq_release-signals-dma_fence-only-when-av.patch
    (git-fixes CVE-2024-57920 bsc#1236072).
  - Update
    patches.suse/drm-dp_mst-Ensure-mst_primary-pointer-is-valid-in-dr.patch
    (stable-fixes CVE-2024-57798 bsc#1235818).
  - Update
    patches.suse/drm-dp_mst-Fix-resetting-msg-rx-state-after-topology.patch
    (git-fixes CVE-2024-57876 bsc#1235806).
  - Update
    patches.suse/drm-mediatek-Set-private-all_drm_private-i-drm-to-NU.patch
    (git-fixes CVE-2024-57926 bsc#1236082).
  - Update
    patches.suse/drm-xe-Fix-fault-on-fd-close-after-unbind.patch
    (git-fixes CVE-2024-57844 bsc#1235945).
  - Update
    patches.suse/drm-xe-Fix-tlb-invalidation-when-wedging.patch
    (git-fixes CVE-2025-21644 bsc#1236085).
  - Update
    patches.suse/exfat-fix-the-infinite-loop-in-exfat_readdir.patch
    (git-fixes CVE-2024-57940 bsc#1236227).
  - Update
    patches.suse/exfat-fix-the-new-buffer-was-not-zeroed-before-writing.patch
    (git-fixes CVE-2024-57943 bsc#1236230).
  - Update
    patches.suse/gpio-virtuser-fix-missing-lookup-table-cleanups.patch
    (git-fixes CVE-2025-21661 bsc#1236201).
  - Update
    patches.suse/hwmon-drivetemp-Fix-driver-producing-garbage-data-wh.patch
    (git-fixes CVE-2025-21656 bsc#1236248).
  - Update
    patches.suse/iio-adc-at91-call-input_free_device-on-allocated-iio.patch
    (git-fixes CVE-2024-57904 bsc#1236078).
  - Update
    patches.suse/iio-adc-rockchip_saradc-fix-information-leak-in-trig.patch
    (git-fixes CVE-2024-57907 bsc#1236090).
  - Update
    patches.suse/iio-adc-ti-ads1119-fix-information-leak-in-triggered.patch
    (git-fixes CVE-2024-57905 bsc#1236083).
  - Update
    patches.suse/iio-adc-ti-ads1298-Add-NULL-check-in-ads1298_init.patch
    (git-fixes CVE-2024-57944 bsc#1236197).
  - Update
    patches.suse/iio-adc-ti-ads8688-fix-information-leak-in-triggered.patch
    (git-fixes CVE-2024-57906 bsc#1236088).
  - Update
    patches.suse/iio-dummy-iio_simply_dummy_buffer-fix-information-le.patch
    (git-fixes CVE-2024-57911 bsc#1236098).
  - Update
    patches.suse/iio-imu-kmx61-fix-information-leak-in-triggered-buff.patch
    (git-fixes CVE-2024-57908 bsc#1236091).
  - Update
    patches.suse/iio-light-bh1745-fix-information-leak-in-triggered-b.patch
    (git-fixes CVE-2024-57909 bsc#1236095).
  - Update
    patches.suse/iio-light-vcnl4035-fix-information-leak-in-triggered.patch
    (git-fixes CVE-2024-57910 bsc#1236097).
  - Update
    patches.suse/iio-pressure-zpa2326-fix-information-leak-in-trigger.patch
    (git-fixes CVE-2024-57912 bsc#1236101).
  - Update
    patches.suse/misc-microchip-pci1xxxx-Resolve-kernel-panic-during-.patch
    (git-fixes CVE-2024-57916 bsc#1236125).
  - Update
    patches.suse/net-mlx5e-Skip-restore-TC-rules-for-vport-rep-withou.patch
    (jsc#PED-11331 CVE-2024-57801 bsc#1235940).
  - Update
    patches.suse/netfs-Fix-ceph-copy-to-cache-on-write-begin.patch
    (git-fixes CVE-2024-57942 bsc#1236229).
  - Update
    patches.suse/netfs-Fix-enomem-handling-in-buffered-reads.patch
    (git-fixes CVE-2024-57928 bsc#1236092).
  - Update
    patches.suse/netfs-Fix-the-non-cancellation-of-copy-when-cache-is-temporarily-disabled.patch
    (git-fixes CVE-2024-57941 bsc#1236228).
  - Update
    patches.suse/nfs-Fix-oops-in-nfs_netfs_init_request-when-copying-to-cache.patch
    (git-fixes CVE-2024-57927 bsc#1236089).
  - Update patches.suse/nvmet-Don-t-overflow-subsysnqn.patch
    (git-fixes CVE-2024-53681 bsc#1235904).
  - Update
    patches.suse/platform-x86-amd-pmc-Only-disable-IRQ1-wakeup-where-.patch
    (git-fixes CVE-2025-21645 bsc#1236131).
  - Update
    patches.suse/powerpc-pseries-vas-Add-close-callback-in-vas_vm_ops.patch
    (bsc#1234825 CVE-2024-56765 bsc#1235643).
  - Update
    patches.suse/s390-cpum_sf-Handle-CPU-hotplug-remove-during-sampling.patch
    (git-fixes bsc#1234715 CVE-2024-57849 bsc#1235814).
  - Update
    patches.suse/usb-gadget-f_fs-Remove-WARN_ON-in-functionfs_bind.patch
    (git-fixes CVE-2024-57913 bsc#1236102).
  - Update
    patches.suse/usb-gadget-u_serial-Disable-ep-before-setting-port-t.patch
    (git-fixes CVE-2024-57915 bsc#1236120).
  - Update
    patches.suse/usb-typec-tcpci-fix-NULL-pointer-issue-on-shared-irq.patch
    (git-fixes CVE-2024-57914 bsc#1236119).
  - Update
    patches.suse/wifi-cfg80211-clear-link-ID-from-bitmap-during-link-.patch
    (stable-fixes CVE-2024-57898 bsc#1235966).
  - Update
    patches.suse/wifi-mac80211-fix-mbss-changed-flags-corruption-on-3.patch
    (stable-fixes CVE-2024-57899 bsc#1235924).
  - Update
    patches.suse/workqueue-Do-not-warn-when-cancelling-WQ_MEM_RECLAIM-work-from-WQ_MEM_RECLAIM-worker.patch
    (bsc#1235416 CVE-2024-57888 bsc#1235918).
  - Update
    patches.suse/x86-fpu-Ensure-shadow-stack-is-active-before-getting-regis.patch
    (git-fixes CVE-2025-21632 bsc#1236106).
  - commit 54bbd23
  - net: inet: do not leave a dangling sk pointer in inet_create()
    (CVE-2024-56601 bsc#1235230).
  - commit 9915dd5
  - bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog (CVE-2024-56665 bsc#1235489)
  - commit c21f948
  - psi: Fix race when task wakes up before psi_sched_switch()
    adjusts flags (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched, psi: Don't account irq time if sched_clock_irqtime is
    disabled (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Don't account irq time if sched_clock_irqtime is disabled
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Define sched_clock_irqtime as static key (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Do not compute overloaded status unnecessarily
    during lb (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Do not compute NUMA Balancing stats unnecessarily
    during lb (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/debug: Change need_resched warnings to pr_err (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Encapsulate set custom slice in a __setparam_fair()
    function (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Fix race between yield_to() and try_to_wake_up()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - docs: Update Schedstat version to 17 (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/stats: Print domain name in /proc/schedstat (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Move sched domain name out of CONFIG_SCHED_DEBUG
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Report the different kinds of imbalances in
    /proc/schedstat (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/fair: Cleanup in migrate_degrades_locality() to improve
    readability (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Fix value reported by hot tasks pulled in
    /proc/schedstat (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/fair: Update comments after sched_tick() rename
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fix CPU bandwidth limit bypass during CPU hotplug
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: deadline: Cleanup goto label in
    pick_earliest_pushable_dl_task (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Untangle NEXT_BUDDY and pick_next_task()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Mark m*_vruntime() with __maybe_unused (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Fix variable declaration position (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Do not try to migrate delayed dequeue task
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Rename cfs_rq.nr_running into nr_queued (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Remove unused cfs_rq.idle_nr_running (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Rename cfs_rq.idle_h_nr_running into h_nr_idle
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Removed unsued cfs_rq.h_nr_delayed (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Use the new cfs_rq.h_nr_runnable (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Add new cfs_rq.h_nr_runnable (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Rename h_nr_running into h_nr_queued (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Unify HK_TYPE_{TIMER|TICK|MISC} to HK_TYPE_KERNEL_NOISE
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/isolation: Consolidate housekeeping cpumasks that
    are always identical (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/isolation: Make "isolcpus=nohz" equivalent to "nohz_full"
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Remove HK_TYPE_SCHED (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Remove CONFIG_CFS_BANDWIDTH=n definition of
    cfs_bandwidth_used() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/deadline: Consolidate Timer Cancellation (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/deadline: Check bandwidth overflow earlier for hotplug
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Correctly account for allocated bandwidth during
    hotplug (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/deadline: Restore dl_server bandwidth on non-destructive
    root domain changes (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: add READ_ONCE to task_on_rq_queued (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Don't try to catch up excess steal time (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit fa2e8c2
  - doc/README.SUSE: Point to the updated version of LKMPG
  - commit 624b259
  - mm: reinstate ability to map write-sealed memfd mappings
    read-only (bsc#1236186).
  - commit ded0978
  - Update
    patches.suse/x86-fpu-Ensure-shadow-stack-is-active-before-getting-regis.patch
    (git-fixes CVE-2025-21632 bsc#1236106).
    Add CVE.
  - commit 887d7c3
  - net: restrict SO_REUSEPORT to inet sockets (bsc#1235967 CVE-2024-57903)
  - commit 58fab3c
  - net: hns3: fix kernel crash when 1588 is sent on HIP08 devices (bsc#1236143 CVE-2025-21649)
  - commit 475f3b6
  - net/mlx5: Fix variable not being completed when function returns (bsc#1236198 CVE-2025-21662)
  - commit 07f6c41

++++ kernel-firmware-all:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-amdgpu:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-ath10k:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-ath11k:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-ath12k:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-atheros:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-bluetooth:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-bnx2:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-brcm:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-chelsio:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-dpaa2:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-i915:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-intel:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-iwlwifi:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-liquidio:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-marvell:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-media:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-mediatek:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-mellanox:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-mwifiex:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-network:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-nfp:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-nvidia:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-platform:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-prestera:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-qcom:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-qlogic:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-radeon:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-realtek:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-serial:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-sound:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-ti:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-ueagle:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-firmware-usb-network:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

++++ kernel-rt:

  - Update
    patches.suse/ALSA-seq-oss-Fix-races-at-processing-SysEx-messages.patch
    (stable-fixes CVE-2024-57893 bsc#1235920).
  - Update
    patches.suse/RDMA-bnxt_re-Fix-max-SGEs-for-the-Work-Request.patch
    (jsc#PED-10682 jsc#PED-11231 CVE-2024-57936 bsc#1236181).
  - Update
    patches.suse/RDMA-hns-Fix-accessing-invalid-dip_ctx-during-destro.patch
    (git-fixes CVE-2024-57935 bsc#1236180).
  - Update
    patches.suse/RDMA-uverbs-Prevent-integer-overflow-issue.patch
    (git-fixes CVE-2024-57890 bsc#1235919).
  - Update
    patches.suse/arm64-ptrace-fix-partial-SETREGSET-for-NT_ARM_TAGGED_ADDR_CTRL.patch
    (git-fixes CVE-2024-57874 bsc#1235808).
  - Update
    patches.suse/cpufreq-CPPC-Fix-possible-null-ptr-deref-for-cppc_ge.patch
    (git-fixes CVE-2024-53230 bsc#1235976).
  - Update
    patches.suse/cpufreq-CPPC-Fix-possible-null-ptr-deref-for-cpufreq.patch
    (git-fixes CVE-2024-53231 bsc#1235977).
  - Update
    patches.suse/drm-adv7511-Fix-use-after-free-in-adv7533_attach_dsi.patch
    (git-fixes CVE-2024-57887 bsc#1235952).
  - Update
    patches.suse/drm-amd-display-Add-check-for-granularity-in-dml-cei.patch
    (stable-fixes CVE-2024-57922 bsc#1236080).
  - Update
    patches.suse/drm-amd-display-fix-divide-error-in-DM-plane-scale-c.patch
    (git-fixes CVE-2024-57919 bsc#1236070).
  - Update
    patches.suse/drm-amd-display-fix-page-fault-due-to-max-surface-de.patch
    (git-fixes CVE-2024-57918 bsc#1236128).
  - Update
    patches.suse/drm-amdgpu-Add-a-lock-when-accessing-the-buddy-trim-.patch
    (git-fixes CVE-2024-57921 bsc#1236076).
  - Update
    patches.suse/drm-amdkfd-Correct-the-migration-DMA-map-direction.patch
    (stable-fixes CVE-2024-57897 bsc#1235969).
  - Update
    patches.suse/drm-amdkfd-wq_release-signals-dma_fence-only-when-av.patch
    (git-fixes CVE-2024-57920 bsc#1236072).
  - Update
    patches.suse/drm-dp_mst-Ensure-mst_primary-pointer-is-valid-in-dr.patch
    (stable-fixes CVE-2024-57798 bsc#1235818).
  - Update
    patches.suse/drm-dp_mst-Fix-resetting-msg-rx-state-after-topology.patch
    (git-fixes CVE-2024-57876 bsc#1235806).
  - Update
    patches.suse/drm-mediatek-Set-private-all_drm_private-i-drm-to-NU.patch
    (git-fixes CVE-2024-57926 bsc#1236082).
  - Update
    patches.suse/drm-xe-Fix-fault-on-fd-close-after-unbind.patch
    (git-fixes CVE-2024-57844 bsc#1235945).
  - Update
    patches.suse/drm-xe-Fix-tlb-invalidation-when-wedging.patch
    (git-fixes CVE-2025-21644 bsc#1236085).
  - Update
    patches.suse/exfat-fix-the-infinite-loop-in-exfat_readdir.patch
    (git-fixes CVE-2024-57940 bsc#1236227).
  - Update
    patches.suse/exfat-fix-the-new-buffer-was-not-zeroed-before-writing.patch
    (git-fixes CVE-2024-57943 bsc#1236230).
  - Update
    patches.suse/gpio-virtuser-fix-missing-lookup-table-cleanups.patch
    (git-fixes CVE-2025-21661 bsc#1236201).
  - Update
    patches.suse/hwmon-drivetemp-Fix-driver-producing-garbage-data-wh.patch
    (git-fixes CVE-2025-21656 bsc#1236248).
  - Update
    patches.suse/iio-adc-at91-call-input_free_device-on-allocated-iio.patch
    (git-fixes CVE-2024-57904 bsc#1236078).
  - Update
    patches.suse/iio-adc-rockchip_saradc-fix-information-leak-in-trig.patch
    (git-fixes CVE-2024-57907 bsc#1236090).
  - Update
    patches.suse/iio-adc-ti-ads1119-fix-information-leak-in-triggered.patch
    (git-fixes CVE-2024-57905 bsc#1236083).
  - Update
    patches.suse/iio-adc-ti-ads1298-Add-NULL-check-in-ads1298_init.patch
    (git-fixes CVE-2024-57944 bsc#1236197).
  - Update
    patches.suse/iio-adc-ti-ads8688-fix-information-leak-in-triggered.patch
    (git-fixes CVE-2024-57906 bsc#1236088).
  - Update
    patches.suse/iio-dummy-iio_simply_dummy_buffer-fix-information-le.patch
    (git-fixes CVE-2024-57911 bsc#1236098).
  - Update
    patches.suse/iio-imu-kmx61-fix-information-leak-in-triggered-buff.patch
    (git-fixes CVE-2024-57908 bsc#1236091).
  - Update
    patches.suse/iio-light-bh1745-fix-information-leak-in-triggered-b.patch
    (git-fixes CVE-2024-57909 bsc#1236095).
  - Update
    patches.suse/iio-light-vcnl4035-fix-information-leak-in-triggered.patch
    (git-fixes CVE-2024-57910 bsc#1236097).
  - Update
    patches.suse/iio-pressure-zpa2326-fix-information-leak-in-trigger.patch
    (git-fixes CVE-2024-57912 bsc#1236101).
  - Update
    patches.suse/misc-microchip-pci1xxxx-Resolve-kernel-panic-during-.patch
    (git-fixes CVE-2024-57916 bsc#1236125).
  - Update
    patches.suse/net-mlx5e-Skip-restore-TC-rules-for-vport-rep-withou.patch
    (jsc#PED-11331 CVE-2024-57801 bsc#1235940).
  - Update
    patches.suse/netfs-Fix-ceph-copy-to-cache-on-write-begin.patch
    (git-fixes CVE-2024-57942 bsc#1236229).
  - Update
    patches.suse/netfs-Fix-enomem-handling-in-buffered-reads.patch
    (git-fixes CVE-2024-57928 bsc#1236092).
  - Update
    patches.suse/netfs-Fix-the-non-cancellation-of-copy-when-cache-is-temporarily-disabled.patch
    (git-fixes CVE-2024-57941 bsc#1236228).
  - Update
    patches.suse/nfs-Fix-oops-in-nfs_netfs_init_request-when-copying-to-cache.patch
    (git-fixes CVE-2024-57927 bsc#1236089).
  - Update patches.suse/nvmet-Don-t-overflow-subsysnqn.patch
    (git-fixes CVE-2024-53681 bsc#1235904).
  - Update
    patches.suse/platform-x86-amd-pmc-Only-disable-IRQ1-wakeup-where-.patch
    (git-fixes CVE-2025-21645 bsc#1236131).
  - Update
    patches.suse/powerpc-pseries-vas-Add-close-callback-in-vas_vm_ops.patch
    (bsc#1234825 CVE-2024-56765 bsc#1235643).
  - Update
    patches.suse/s390-cpum_sf-Handle-CPU-hotplug-remove-during-sampling.patch
    (git-fixes bsc#1234715 CVE-2024-57849 bsc#1235814).
  - Update
    patches.suse/usb-gadget-f_fs-Remove-WARN_ON-in-functionfs_bind.patch
    (git-fixes CVE-2024-57913 bsc#1236102).
  - Update
    patches.suse/usb-gadget-u_serial-Disable-ep-before-setting-port-t.patch
    (git-fixes CVE-2024-57915 bsc#1236120).
  - Update
    patches.suse/usb-typec-tcpci-fix-NULL-pointer-issue-on-shared-irq.patch
    (git-fixes CVE-2024-57914 bsc#1236119).
  - Update
    patches.suse/wifi-cfg80211-clear-link-ID-from-bitmap-during-link-.patch
    (stable-fixes CVE-2024-57898 bsc#1235966).
  - Update
    patches.suse/wifi-mac80211-fix-mbss-changed-flags-corruption-on-3.patch
    (stable-fixes CVE-2024-57899 bsc#1235924).
  - Update
    patches.suse/workqueue-Do-not-warn-when-cancelling-WQ_MEM_RECLAIM-work-from-WQ_MEM_RECLAIM-worker.patch
    (bsc#1235416 CVE-2024-57888 bsc#1235918).
  - Update
    patches.suse/x86-fpu-Ensure-shadow-stack-is-active-before-getting-regis.patch
    (git-fixes CVE-2025-21632 bsc#1236106).
  - commit 54bbd23
  - net: inet: do not leave a dangling sk pointer in inet_create()
    (CVE-2024-56601 bsc#1235230).
  - commit 9915dd5
  - bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog (CVE-2024-56665 bsc#1235489)
  - commit c21f948
  - psi: Fix race when task wakes up before psi_sched_switch()
    adjusts flags (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched, psi: Don't account irq time if sched_clock_irqtime is
    disabled (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Don't account irq time if sched_clock_irqtime is disabled
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Define sched_clock_irqtime as static key (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Do not compute overloaded status unnecessarily
    during lb (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Do not compute NUMA Balancing stats unnecessarily
    during lb (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/debug: Change need_resched warnings to pr_err (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Encapsulate set custom slice in a __setparam_fair()
    function (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Fix race between yield_to() and try_to_wake_up()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - docs: Update Schedstat version to 17 (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/stats: Print domain name in /proc/schedstat (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Move sched domain name out of CONFIG_SCHED_DEBUG
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Report the different kinds of imbalances in
    /proc/schedstat (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/fair: Cleanup in migrate_degrades_locality() to improve
    readability (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/fair: Fix value reported by hot tasks pulled in
    /proc/schedstat (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/fair: Update comments after sched_tick() rename
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fix CPU bandwidth limit bypass during CPU hotplug
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: deadline: Cleanup goto label in
    pick_earliest_pushable_dl_task (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Untangle NEXT_BUDDY and pick_next_task()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Mark m*_vruntime() with __maybe_unused (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Fix variable declaration position (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Do not try to migrate delayed dequeue task
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Rename cfs_rq.nr_running into nr_queued (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Remove unused cfs_rq.idle_nr_running (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Rename cfs_rq.idle_h_nr_running into h_nr_idle
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Removed unsued cfs_rq.h_nr_delayed (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Use the new cfs_rq.h_nr_runnable (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Add new cfs_rq.h_nr_runnable (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Rename h_nr_running into h_nr_queued (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Unify HK_TYPE_{TIMER|TICK|MISC} to HK_TYPE_KERNEL_NOISE
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/isolation: Consolidate housekeeping cpumasks that
    are always identical (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/isolation: Make "isolcpus=nohz" equivalent to "nohz_full"
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Remove HK_TYPE_SCHED (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/fair: Remove CONFIG_CFS_BANDWIDTH=n definition of
    cfs_bandwidth_used() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/deadline: Consolidate Timer Cancellation (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/deadline: Check bandwidth overflow earlier for hotplug
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/deadline: Correctly account for allocated bandwidth during
    hotplug (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched/deadline: Restore dl_server bandwidth on non-destructive
    root domain changes (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: add READ_ONCE to task_on_rq_queued (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Don't try to catch up excess steal time (bsc#1234634
    (Scheduler functional and performance backports)).
  - commit fa2e8c2
  - doc/README.SUSE: Point to the updated version of LKMPG
  - commit 624b259
  - mm: reinstate ability to map write-sealed memfd mappings
    read-only (bsc#1236186).
  - commit ded0978
  - Update
    patches.suse/x86-fpu-Ensure-shadow-stack-is-active-before-getting-regis.patch
    (git-fixes CVE-2025-21632 bsc#1236106).
    Add CVE.
  - commit 887d7c3
  - net: restrict SO_REUSEPORT to inet sockets (bsc#1235967 CVE-2024-57903)
  - commit 58fab3c
  - net: hns3: fix kernel crash when 1588 is sent on HIP08 devices (bsc#1236143 CVE-2025-21649)
  - commit 475f3b6
  - net/mlx5: Fix variable not being completed when function returns (bsc#1236198 CVE-2025-21662)
  - commit 07f6c41

++++ python-Pygments:

  - Drop dependency on ca-certificates-mozilla-prebuilt to really
    avoid buildcycles

++++ qemu:

  - CPU model for new IBM Z HW (jsc#PED-10266):
    * s390x/cpumodel: gen17 model
    * s390x/cpumodel: Add PLO-extension facility
    * s390x/cpumodel: correct PLO feature wording
    * s390x/cpumodel: Add Sequential-Instruction-Fetching facility
    * s390x/cpumodel: add Ineffective-nonconstrained-transaction facility
    * s390x/cpumodel: add Vector-Packed-Decimal-Enhancement facility 3
    * s390x/cpumodel: add Miscellaneous-Instruction-Extensions Facility 4
    * s390x/cpumodel: add Vector Enhancements facility 3
    * s390x/cpumodel: add Concurrent-functions facility support
    * linux-headers: Update to Linux 6.13-rc1
    * s390x/cpumodel: Add ptff Query Time-Stamp Event (QTSE) support
    * s390x/cpumodel: add msa13 subfunctions
    * s390x/cpumodel: add msa12 changes
    * s390x/cpumodel: add msa11 subfunctions
    * s390x/cpumodel: add msa10 subfunctions

++++ strace:

  - Update to strace 6.13
    * Implemented decoding of getxattrat, setxattrat, listxattrat,
    and removexattrat syscalls.
    * Updated decoding of struct io_uring_clone_buffers, struct io_uring_napi,
    and struct perf_event_attr.
    * Updated decoding of crypto_user_alg netlink attributes of NETLINK_CRYPTO.
    * Implemented decoding of IFLA_MCTP_PHYS_BINDING netlink attribute.
    * Updated lists of AT_*, BPF_*, FAN_*, IORING_*, MADV_*, NT_*, and SCM_*
    constants.
    * Updated lists of ioctl commands from Linux 6.13.

++++ ucode-amd:

  - Update to version 20250122 (git commit 0e16f416fa29):
    * amdgpu: revert DMCUB 3.1.4 firmware (bsc#1236196)
    * amlogic: update firmware for w265s2

------------------------------------------------------------------
------------------  2025-1-22  -  Jan 22 2025  -------------------
------------------------------------------------------------------

++++ chrony:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ lvm2-device-mapper:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ python-kiwi:

  - Fix documentation regarding URI styles
    In reference to commit 760a65558f9e2e91d3eaa3a2f9503ff596984b48
    the support for iso:// URI types was dropped some time ago.
    However, the documentation was not properly updated. This
    commit fixes it

++++ firewalld:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ open-iscsi:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ kernel-default:

  - s390/futex: Fix FUTEX_OP_ANDN implementation (git-fixes
    bsc#1236286).
  - commit 0dace5e
  - tracing: Prevent bad count for tracing_cpumask_write (CVE-2024-56763 bsc#1235638)
  - commit ddb87c7
  - dccp: Fix memory leak in dccp_feat_change_recv (CVE-2024-56643 bsc#1235132)
  - commit a463e51
  - net: stmmac: fix TSO DMA API usage causing oops (CVE-2024-56719 bsc#1235591)
  - commit 303cb71
  - net: mscc: ocelot: fix incorrect IFH SRC_PORT field in ocelot_ifh_set_basic() (CVE-2024-56717 bsc#1235588)
  - commit 9d81d98
  - EDAC/igen6: Avoid segmentation fault on module unload (CVE-2024-56708 bsc#1235564)
  - commit b104d19
  - net/smc: initialize close_work early to avoid warning (CVE-2024-56641 bsc#1235526)
  - commit 004c5ba
  - net: hsr: must allocate more bytes for RedBox support (CVE-2024-56639 bsc#1235525)
  - commit 5287ee6
  - btrfs: fix transaction atomicity bug when enabling simple quotas
    (bsc#1235792 CVE-2024-57806).
  - btrfs: flush delalloc workers queue before stopping cleaner
    kthread during unmount (bsc#1235965 CVE-2024-57896).
  - commit c277493
  - net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of
    bounds issue (CVE-2025-21650 bsc#1236144).
  - net: hns3: don't auto enable misc vector (CVE-2025-21651
    bsc#1236145).
  - gve: guard XSK operations on the existence of queues
    (CVE-2024-57933 bsc#1236178).
  - gve: guard XDP xmit NDO on existence of xdp queues
    (CVE-2024-57932 bsc#1236190).
  - commit 234dcb0
  - Update config files. Make zsmalloc the default for zswap (bsc#1235938)
  - commit 5f343bc
  - Update config files. Enable CONFIG_READ_ONLY_THP_FOR_FS (bsc#1235939)
  - commit afec79a
  - powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in
    DDW (bsc#1218470 ltc#204531).
  - commit 0e16ef6
  - Delete
    patches.suse/0001-kvm-Reintroduce-nopvspin-kernel-parameter.patch.
    This patch was required for a performance issue with specific kernels
  - commit 77171c1

++++ kernel-rt:

  - s390/futex: Fix FUTEX_OP_ANDN implementation (git-fixes
    bsc#1236286).
  - commit 0dace5e
  - tracing: Prevent bad count for tracing_cpumask_write (CVE-2024-56763 bsc#1235638)
  - commit ddb87c7
  - dccp: Fix memory leak in dccp_feat_change_recv (CVE-2024-56643 bsc#1235132)
  - commit a463e51
  - net: stmmac: fix TSO DMA API usage causing oops (CVE-2024-56719 bsc#1235591)
  - commit 303cb71
  - net: mscc: ocelot: fix incorrect IFH SRC_PORT field in ocelot_ifh_set_basic() (CVE-2024-56717 bsc#1235588)
  - commit 9d81d98
  - EDAC/igen6: Avoid segmentation fault on module unload (CVE-2024-56708 bsc#1235564)
  - commit b104d19
  - net/smc: initialize close_work early to avoid warning (CVE-2024-56641 bsc#1235526)
  - commit 004c5ba
  - net: hsr: must allocate more bytes for RedBox support (CVE-2024-56639 bsc#1235525)
  - commit 5287ee6
  - btrfs: fix transaction atomicity bug when enabling simple quotas
    (bsc#1235792 CVE-2024-57806).
  - btrfs: flush delalloc workers queue before stopping cleaner
    kthread during unmount (bsc#1235965 CVE-2024-57896).
  - commit c277493
  - net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of
    bounds issue (CVE-2025-21650 bsc#1236144).
  - net: hns3: don't auto enable misc vector (CVE-2025-21651
    bsc#1236145).
  - gve: guard XSK operations on the existence of queues
    (CVE-2024-57933 bsc#1236178).
  - gve: guard XDP xmit NDO on existence of xdp queues
    (CVE-2024-57932 bsc#1236190).
  - commit 234dcb0
  - Update config files. Make zsmalloc the default for zswap (bsc#1235938)
  - commit 5f343bc
  - Update config files. Enable CONFIG_READ_ONLY_THP_FOR_FS (bsc#1235939)
  - commit afec79a
  - powerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in
    DDW (bsc#1218470 ltc#204531).
  - commit 0e16ef6
  - Delete
    patches.suse/0001-kvm-Reintroduce-nopvspin-kernel-parameter.patch.
    This patch was required for a performance issue with specific kernels
  - commit 77171c1

++++ kexec-tools:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ multipath-tools:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ rdma-core:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ lvm2:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ openssl-3:

  - bsc#1236136 CVE-2024-13176: Fix timing side-channel in ECDSA signature computation
    * Add patch openssl-CVE-2024-13176.patch

++++ parted:

  - fixed build with gcc15
    added patches:
  - parted-do-version.patch

++++ tpm2.0-abrmd:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ libzypp:

  - Create '.keep_packages' in the package cache dir to enforce
    keeping downloaded packages of all repos cahed there (bsc#1232458)
  - version 17.35.19 (35)

++++ logrotate:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ mcelog:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ mdadm:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ nvidia-open-driver-G06-signed:

  - preamble: let -cuda KMP conflict with no-cuda variants < 550.135
    (bsc#1236191)

++++ openssh:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ pam_pkcs11:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ passt:

  - Update to version 20250121.4f2c8e7:
    * vhost_user: Drop packet with unsupported iovec array
    * tcp: Set PSH flag for last incoming packets in a batch
    * tcp: Set ACK flag on *all* RST segments, even for client in SYN-SENT state
    * tcp: Disable Nagle's algorithm (set TCP_NODELAY) on all sockets
    * tcp: Buffer sizes are *not* inherited on accept()/accept4()
    * vhost_user: remove ASSERT() on iovec number
    * vhost-user: Report to front-end we support VHOST_USER_PROTOCOL_F_DEVICE_STATE
    * vhost-user: add VHOST_USER_SET_DEVICE_STATE_FD command
    * vhost-user: add VHOST_USER_CHECK_DEVICE_STATE command
    * vhost-user: Report to front-end we support VHOST_USER_PROTOCOL_F_LOG_SHMFD
    * vhost-user: add VHOST_USER_SET_LOG_BASE command
    * vhost-user: Pass vu_dev to more virtio functions
    * vhost-user: add VHOST_USER_SET_LOG_FD command
    * vhost-user: update protocol features and commands list
    * tcp: Mask EPOLLIN altogether if we're blocked waiting on an ACK from the guest
    * tcp: Set EPOLLET when when reading from a socket fails with EAGAIN
    * tcp: Don't subscribe to EPOLLOUT events on STALLED
    * tcp: Fix ACK sequence getting out of sync on EPOLLOUT wake-up
    * vhost_user: fix multibuffer from linux
    * test/pasta_podman: Run Podman tests on a single CPU thread
    * checksum: fix checksum with odd base address
    * tcp_splice: Set (again) TCP_NODELAY on both sides
    * seccomp: Unconditionally allow accept(2) even if accept4(2) is present
    * virtio: Use const pointer for vu_dev
    * udp_flow: Don't block multicast and broadcast messages
    * Makefile: Report error and stop if we can't set TARGET
    * README: Mark vhost-user as supported

++++ qemu:

  - Build properly with the latest version of Sphinx:
    * [openSUSE][RPM] Fix the build with the latest Sphinx

++++ rsync:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ tuned:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ zypper:

  - lr: show the repositories keep-packages flag (bsc#1232458)
    It is shown in the  details view or by using -k,--keep-packages.
    In addition libyzpp supports to enforce keeping downloaded
    packages of all repos within a package cache by creating a
    '.keep_packages' file there.
  - version 1.14.81

------------------------------------------------------------------
------------------  2025-1-21  -  Jan 21 2025  -------------------
------------------------------------------------------------------

++++ cifs-utils:

  - Migrate away from update-alternatives, replaced by package
    conflicts (bsc#1235788);

++++ python-kiwi:

  - Fix return value of grub helper methods
    The grub helper methods to find grub tools returns a
    None value if the tool cannot be found. This None value
    could be used later in a Command call where it will be
    used in a join() command to log the resulting commandline.
    This join() call then fails and raises an unhandled error
    causing a stack trace in the application. This commit
    fixes it

++++ kernel-default:

  - netfs: Fix kernel async DIO (CVE-2025-21643 bsc#1236129).
  - commit 5091c6e
  - KVM: x86: Play nice with protected guests in
    complete_hypercall_exit() (CVE-2024-55881 bsc#1235745).
  - commit 1b22d6c
  - netfilter: ipset: Hold module reference while requesting a module (CVE-2024-56637 bsc#1235523)
  - commit 690c0e7
  - btrfs: zlib: fix avail_in bytes for s390 zlib HW compression
    path (CVE-2024-57923 bsc#1236081).
  - commit 8a7a4cd
  - geneve: do not assume mac header is set in geneve_xmit_skb() (CVE-2024-56636 bsc#1235520)
  - commit 952c736
  - dm array: fix releasing a faulty array block twice in
    dm_array_cursor_end (bsc#1236096, CVE-2024-57929).
  - commit 39a2cb0
  - net: avoid potential UAF in default_operstate() (CVE-2024-56635 bsc#1235519)
  - commit 3ce7665
  - net: lapb: increase LAPB_HEADER_LEN (CVE-2024-56659 bsc#1235439)
  - commit f8467db
  - net: enetc: Do not configure preemptible TCs if SIs do not support (CVE-2024-56649 bsc#1235449)
  - commit 72c14cf
  - smb: Initialize cfid->tcon before performing network ops (CVE-2024-56729 bsc#1235503)
  - commit 01281af
  - usb: typec: ucsi: Fix connector status writing past buffer size
    (git-fixes).
  - commit cef7f7d
  - reenabled kABI padding for rfkill subsystem
  - commit 6ada0c1
  - reenabled kABI padding for fpga subsystem
  - commit 2829876
  - reenabled kABI paddings for atheros wifi
  - commit e1e449a
  - reenable kABI paddings for mediatek wifi
  - commit 3acd857
  - reenable kABI padding for realtek wifi
  - commit f74657e
  - selftests/mm: add self tests for guard page feature
    (jsc#PED-11997).
  - commit 60e0640
  - tools: testing: update tools UAPI header for mman-common.h
    (jsc#PED-11997).
  - commit 8363626
  - mm: madvise: implement lightweight guard page mechanism
    (jsc#PED-11997).
  - commit ef64fd4
  - mm: add PTE_MARKER_GUARD PTE marker (jsc#PED-11997).
  - commit 8bdd1e7
  - mm: pagewalk: add the ability to install PTEs (jsc#PED-11997).
  - commit 05dd309
  - mm/madvise: unrestrict process_madvise() for current process
    (jsc#PED-11997).
  - commit 520a012
  - mm: refactor mm_access() to not return NULL (jsc#PED-11997).
  - commit f4b336b
  - x86/cpu/topology: Remove limit of CPUs due to disabled IO/APIC (git-fixes).
  - commit 62783ca
  - x86/microcode/intel: Remove unnecessary cache writeback and invalidation (git-fixes).
  - commit dc8791d
  - x86/tdx: Dynamically disable SEPT violations from causing #VEs (git-fixes).
  - commit 496a9c3
  - x86/tdx: Rename tdx_parse_tdinfo() to tdx_setup() (git-fixes).
  - commit 5e1ffad
  - x86/tdx: Introduce wrappers to read and write TD metadata (git-fixes).
  - commit 755075a
  - x86/pkeys: Ensure updated PKRU value is XRSTOR'd (git-fixes).
  - commit 51df86b
  - x86/pkeys: Change caller of update_pkru_in_sigframe() (git-fixes).
  - commit 978efb4
  - x86/fpu: Ensure shadow stack is active before "getting" registers (git-fixes).
  - commit 46e75e2
  - x86/mm: Carve out INVLPG inline asm for use by others (git-fixes).
  - commit e895153
  - x86: fix off-by-one in access_ok() (git-fixes).
  - commit 4b269aa
  - x86/asm: Make serialize() always_inline (git-fixes).
  - commit f957994
  - x86/CPU/AMD: WARN when setting EFER.AUTOIBRS if and only if the WRMSR  fails (git-fixes).
  - commit c5e60f6
  - x86/microcode/AMD: Flush patch buffer mapping after application (git-fixes).
  - commit d8e2f7c
  - x86/fred: Fix the FRED RSP0 MSR out of sync with its per-CPU cache (git-fixes).
  - commit bb3c863
  - Reviewed
    patches.suse/0004-MODSIGN-checking-the-blacklisted-hash-before-loading.patch
  - commit 0e6968e
  - Reviewed
    patches.suse/0003-Add-external-no-support-as-bad-taint-module.patch
  - commit 86de2cb

++++ kernel-firmware-all:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-amdgpu:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-ath10k:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-ath11k:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-ath12k:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-atheros:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-bluetooth:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-bnx2:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-brcm:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-chelsio:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-dpaa2:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-i915:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-intel:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-iwlwifi:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-liquidio:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-marvell:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-media:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-mediatek:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-mellanox:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-mwifiex:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-network:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-nfp:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-nvidia:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-platform:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-prestera:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-qcom:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-qlogic:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-radeon:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-realtek:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-serial:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-sound:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-ti:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-ueagle:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-firmware-usb-network:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ kernel-rt:

  - netfs: Fix kernel async DIO (CVE-2025-21643 bsc#1236129).
  - commit 5091c6e
  - KVM: x86: Play nice with protected guests in
    complete_hypercall_exit() (CVE-2024-55881 bsc#1235745).
  - commit 1b22d6c
  - netfilter: ipset: Hold module reference while requesting a module (CVE-2024-56637 bsc#1235523)
  - commit 690c0e7
  - btrfs: zlib: fix avail_in bytes for s390 zlib HW compression
    path (CVE-2024-57923 bsc#1236081).
  - commit 8a7a4cd
  - geneve: do not assume mac header is set in geneve_xmit_skb() (CVE-2024-56636 bsc#1235520)
  - commit 952c736
  - dm array: fix releasing a faulty array block twice in
    dm_array_cursor_end (bsc#1236096, CVE-2024-57929).
  - commit 39a2cb0
  - net: avoid potential UAF in default_operstate() (CVE-2024-56635 bsc#1235519)
  - commit 3ce7665
  - net: lapb: increase LAPB_HEADER_LEN (CVE-2024-56659 bsc#1235439)
  - commit f8467db
  - net: enetc: Do not configure preemptible TCs if SIs do not support (CVE-2024-56649 bsc#1235449)
  - commit 72c14cf
  - smb: Initialize cfid->tcon before performing network ops (CVE-2024-56729 bsc#1235503)
  - commit 01281af
  - usb: typec: ucsi: Fix connector status writing past buffer size
    (git-fixes).
  - commit cef7f7d
  - reenabled kABI padding for rfkill subsystem
  - commit 6ada0c1
  - reenabled kABI padding for fpga subsystem
  - commit 2829876
  - reenabled kABI paddings for atheros wifi
  - commit e1e449a
  - reenable kABI paddings for mediatek wifi
  - commit 3acd857
  - reenable kABI padding for realtek wifi
  - commit f74657e
  - selftests/mm: add self tests for guard page feature
    (jsc#PED-11997).
  - commit 60e0640
  - tools: testing: update tools UAPI header for mman-common.h
    (jsc#PED-11997).
  - commit 8363626
  - mm: madvise: implement lightweight guard page mechanism
    (jsc#PED-11997).
  - commit ef64fd4
  - mm: add PTE_MARKER_GUARD PTE marker (jsc#PED-11997).
  - commit 8bdd1e7
  - mm: pagewalk: add the ability to install PTEs (jsc#PED-11997).
  - commit 05dd309
  - mm/madvise: unrestrict process_madvise() for current process
    (jsc#PED-11997).
  - commit 520a012
  - mm: refactor mm_access() to not return NULL (jsc#PED-11997).
  - commit f4b336b
  - x86/cpu/topology: Remove limit of CPUs due to disabled IO/APIC (git-fixes).
  - commit 62783ca
  - x86/microcode/intel: Remove unnecessary cache writeback and invalidation (git-fixes).
  - commit dc8791d
  - x86/tdx: Dynamically disable SEPT violations from causing #VEs (git-fixes).
  - commit 496a9c3
  - x86/tdx: Rename tdx_parse_tdinfo() to tdx_setup() (git-fixes).
  - commit 5e1ffad
  - x86/tdx: Introduce wrappers to read and write TD metadata (git-fixes).
  - commit 755075a
  - x86/pkeys: Ensure updated PKRU value is XRSTOR'd (git-fixes).
  - commit 51df86b
  - x86/pkeys: Change caller of update_pkru_in_sigframe() (git-fixes).
  - commit 978efb4
  - x86/fpu: Ensure shadow stack is active before "getting" registers (git-fixes).
  - commit 46e75e2
  - x86/mm: Carve out INVLPG inline asm for use by others (git-fixes).
  - commit e895153
  - x86: fix off-by-one in access_ok() (git-fixes).
  - commit 4b269aa
  - x86/asm: Make serialize() always_inline (git-fixes).
  - commit f957994
  - x86/CPU/AMD: WARN when setting EFER.AUTOIBRS if and only if the WRMSR  fails (git-fixes).
  - commit c5e60f6
  - x86/microcode/AMD: Flush patch buffer mapping after application (git-fixes).
  - commit d8e2f7c
  - x86/fred: Fix the FRED RSP0 MSR out of sync with its per-CPU cache (git-fixes).
  - commit bb3c863
  - Reviewed
    patches.suse/0004-MODSIGN-checking-the-blacklisted-hash-before-loading.patch
  - commit 0e6968e
  - Reviewed
    patches.suse/0003-Add-external-no-support-as-bad-taint-module.patch
  - commit 86de2cb

++++ libcbor:

  - Explicitly BuildRequire sphinx_rtd_theme.

++++ pcp:

  - Fix symlink race; CVE-2024-45770; (bsc#1230552)
    + 0012-src-pmpost-pmpost.c-guard-against-possible-symlink-a.patch
  - Fix pmstore corruption; CVE-2024-45769 (bsc#1230551)
    + 0013-src-libpcp-src-p_result.c-correct-buffer-over-run-te.patch
    + 0014-src-libpcp-src-p_result.c-hardening-of-the-result-PD.patch
    + 0015-src-libpcp-src-p_result.c-hardening-of-result-PDU-ev.patch
    + 0016-src-libpcp-src-p_result.c-rework-PDU-integrity-check.patch
    + 0017-src-libpcp-src-p_result.c-re-instate-__pmPrintResult.patch
    + 0018-src-libpcp-src-p_result.c-re-instate-__pmPrintResult.patch
    + 0019-src-libpcp-src-p_result.c-32-bit-fix-for-SUSE-Issue-.patch

++++ sssd:

  - Migrate away from update-alternatives, replaced by package
    conflicts; (bsc#1235789); (bsc#1216739);

++++ wtmpdb:

  - Update to version 0.70.0+git20250121.3e409b5:
    * Fix installation of all wtmpdbd man page variants
    * Release version 0.70.0
    * Add wtmpdbd.8 manual page
    * wtmpdbd: fix printing help text
    * wtmpdbd: more fine granular log level filtering
    * wtmpdbd: implement varlink_event_loop_with_idle
    * wtmpdbd.socket: fix socket descriptor name
    * meson: no longer check for v258 sd-varlink function

++++ policycoreutils:

  - Drop manually generated typelib(Gtk) Requires: this was the
    minimal fix to eliminate usage of pythonj-gtk, but the python
    code references more typelibs; hence add gobject-introspection
    BuildRequires in order to inspect the code for typelib()
    dependencies.
  - Replace python3-gobject Requires for python3-gobject-Gdk: as this
    is a GUI application, we do need to Gdk bridge too.
  - Replace python-gtk Requires for -gui with introspection typelib for Gtk 3

++++ selinux-policy:

  - Update to version 20240604+git684.814e5b91:
    * wtmpdbd systemd service uses NoNewPrivileges (bsc#1235660)

++++ suse-module-tools:

    * Fix "initrd: file not found" error in sd-boot setup
    (gh#openSUSE/suse-module-tools#113, gh#openSUSE/sdbootutil#122)

++++ ucode-amd:

  - Update to version 20250120 (git commit 634d0a0aa07b):
    * mediatek MT7925: update bluetooth firmware to 20250113153307
    * linux-firmware: update firmware for MT7925 WiFi device
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update yellow carp firmware
    * qcom: correct licence information for SA8775P binaries
    * qcom: update SLPI firmware for RB5 board
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * qcom: add DSP firmware for SA8775p platform
    * qcom: correct venus firmware versions
    * qcom: add missing version information
    * linux-firmware: Update firmware (v10) for mt7988 internal
    * iwlwifi: add Bz FW for core90-93 release
    * linux-firmware: wilc3000: add firmware for WILC3000 WiFi device
    * rtw89: 8852b: update fw to v0.29.29.8
    * rtw89: 8852c: update fw to v0.27.122.0
    * rtw89: 8922a: update fw to v0.35.54.0
    * rtw89: 8922a: update fw to v0.35.52.1 and stuffs
    * rtw89: 8852bt: update fw to v0.29.110.0
    * rtw89: 8852b: update fw to v0.29.29.7
  - Fix license for qcom_q6v5_pas
  - Update aliases from 6.13

++++ vim:

  - updade to 9.1.1043
    * [security]: segfault in win_line()
    * update helptags
    * filetype: just files are not recognized
    * Update base-syntax, match ternary and falsy operators
    * Vim9: out-of-bound access when echoing an enum
    * Vim9: imported type cannot be used as func return type
    * runtime(kconfig): updated ftplugin and syntax script
    * runtime(doc): rename last t_BG reference to t_RB
    * Vim9: comments are outdated
    * tests: test_channel.py fails with IPv6
    * runtime(vim): Update base-syntax, fix is/isnot operator matching
    * Vim9: confusing error when using abstract method via super
    * make install fails when using shadowdir
    * Vim9: memory leak with blob2str()
    * runtime(tex): add texEmphStyle to texMatchGroup in syntax script
    * runtime(netrw): upstream snapshot of v175
    * Vim9: compiling abstract method fails without return
    * runtime(c): add new constexpr keyword to syntax file (C23)
    * tests: shaderslang was removed from test_filetype erroneously
    * link error when FEAT_SPELL not defined
    * Coverity complains about insecure data handling
    * runtime(sh): update syntax script
    * runtime(c): Add missing syntax test files
    * filetype: setting bash filetype is backwards incompatible
    * runtime(c): Update syntax and ftplugin files
    * the installer can be improved
    * too many strlen() calls in screen.c
    * no sanitize check when running linematch
    * filetype: swc configuration files are not recognized
    * runtime(netrw): change netrw maintainer
    * wrong return type of blob2str()
    * blob2str/str2blob() do not support list of strings
    * runtime(doc): fix typo in usr_02.txt
    * Coverity complains about dereferencing NULL pointer
    * linematch option value not completed
    * string might be used without a trailing NUL
    * no way to get current selected item in a async context
    * filetype: fd ignore files are not recognized
    * v9.1.0743 causes regression with diff mode
    * runtime(doc): fix base64 encode/decode examples
    * Vim9: Patch 9.1.1013 causes a few problems
    * Not possible to convert string2blob and blob2string
    * Coverity complains about dereferencing NULL value
    * Vim9: variable not found in transitive import
    * runtime(colors): Update colorschemes, include new unokai colorscheme
    * Vim9: Regression caused by patch v9.1.0646
    * runtime(lyrics): support milliseconds in syntax script
    * runtime(vim): Split Vim legacy and Vim9 script indent tests
    * Vim9: class interface inheritance not correctly working
    * popupmenu internal error with some abbr in completion item
    * filetype: VisualCode setting file not recognized
    * diff feature can be improved
    * tests: test for patch 9.1.1006 doesn't fail without the patch
    * filetype: various ignore are not recognized
    * tests: Load screendump files with "git vimdumps"
    * PmenuMatch completion highlight can be combined
    * completion text is highlighted even with no pattern found
    * tests: a few termdebug tests are flaky
    * [security]: heap-buffer-overflow with visual mode
    * runtime(doc): add package-<name> helptags for included packages
    * Vim9: unknown func error with interface declaring func var
    * runtime(filetype): don't detect string interpolation as angular
    * ComplMatchIns highlight hard to read on light background
    * runtime(vim): Update base-syntax, highlight literal string quote escape
    * runtime(editorconfig): set omnifunc to syntaxcomplete func
    * tests: ruby tests fail with Ruby 3.4
    * Vim9: leaking finished exception
    * runtime(tiasm):  use correct syntax name tiasm in syntax script
    * filetype: TI assembly files are not recognized
    * too many strlen() calls in drawscreen.c
    * runtime(xf86conf): add section name OutputClass to syntax script
    * ComplMatchIns may highlight wrong text
    * runtime(vim): Update base-syntax, improve ex-bang matching
    * runtime(doc): clarify buffer deletion on popup_close()
    * filetype: shaderslang files are not detected
    * Vim9: not able to use comment after opening curly brace

------------------------------------------------------------------
------------------  2025-1-20  -  Jan 20 2025  -------------------
------------------------------------------------------------------

++++ bash-completion:

  - No longer ship completion for secret-tool, which belongs to
    libsecret and newly brings the completions by itself.
    https://github.com/scop/bash-completion/issues/1317

++++ cloud-init:

  - Support python 3.13 (bsc#1233649):
    + pep-594-drop-pipes.patch, gh#canonical/cloud-init#4392
    + cloud-init-fix-python313.patch, gh#canonical/cloud-init#4669
    + cloud-init-dont-assume-ordering-of-ThreadPoolExecutor.patch gh#canonical/cloud-init#5052

++++ python-kiwi:

  - Added disk validation for duplicate installs
    Installing the same image to different storage disks on the
    same machine creates device conflicts with unexpected side
    effects. This commit adds a validation based on the PTUUID
    of the disk image to check if another device on the system
    has the same ID and if yes, does not allow to install the
    image again including a message which device takes the same
    identifier. This references bsc#1228741
  - Fixed documentation for signing key attribute
    The source locator name for local files was incorrect

++++ fwupd:

  - Update to version 2.0.4+4:
    + dell-kestrel: cleanup the devices when disconnected
    + Raise authentication requirements for emulation-load
    + uefi-dbx: Only list the version in the quirk file key
  - Update to version 2.0.4:
    + This release adds the following features:
  - Record the entire USB descriptor in the emulation data
  - Return defined return code when network metadata refresh
    fails
    + This release fixes the following bugs:
  - Add a new private flag of 'delayed-removal' to remove a
    footgun
  - Added a more specific instance ID for qc-s5gen2 USB devices
  - Add fadvise64 to the systemd syscall allowlist
  - Add the Unifying bootloader VID/PID as a full instance ID
  - Allow disabling zero-length packet for modem-manager devices
  - Allow recovering Logitech Bolt receiver in bootloader mode
  - Correctly parse CSV streams without trailing NULs
  - Detect if network is reachable before downloading metadata
  - Disabling reading the OptionROM device after dumping
  - Do not claim kernel interface to avoid Parade downstream port
    resets
  - Do not save BootOrder when measuring system integrity
  - Enumerate child nordic-hid devices correctly
  - Fix a possible critical warning for Mediatek scaler devices
  - Fix Firehose padding for some modem-manager devices
  - Fix UEFI capsule updates when using 4096 byte NVME blocksize
  - Get the Dell dock update package version correctly
  - Never read more of the composite stream from a partial stream
  - Notify snapd about DBX updates
  - Probe sd_mod before starting
  - Properly handle FU_DEVICE_PRIVATE_FLAG_NO_GENERIC_GUIDS
  - Remove the test for CSME 18 manufacturing lock
  - Restore the Logitech compatibility UFY instance IDs
  - Show the correct version when installing a same-device
    composite update
  - Show updates with problems when using 'fwupdmgr get-releases'
  - Split up the AMD GPU VBIOS P/N for the version
  - Use attr USB4_TYPE rather than guessing from
    thunderbolt_domain
  - Use the ISO date as a dbx version number for the Microsoft
    KEK
  - Use the KEK to set the dbx vendor ID

++++ glibc:

  - Disable nscd support (bsc#1235247)

++++ hicolor-icon-theme:

  - Update to version 0.18:
    * Provide a pkgconfig file
    * Create HiDPI directories
    * Port build system to Meson
  - Create devel subpackage for pkgconfig file
  - Create all directories under symbolic
    (needed by budgie-desktop)
  - Create 1024x1024 HiDPI directories

++++ kernel-default:

  - tpm: ibmvtpm: Set TPM_OPS_AUTO_STARTUP flag on driver
    (git-fixes).
  - commit 6f0e558
  - net: mana: Cleanup "mana" debugfs dir after cleanup of all children (git-fixes).
  - commit 7180a8a
  - RDMA/hns: Fix missing flush CQE for DWQE (git-fixes)
  - commit 87b30f5
  - RDMA/hns: Fix warning storm caused by invalid input in IO path (git-fixes)
  - commit e09ea24
  - RDMA/hns: Fix accessing invalid dip_ctx during destroying QP (git-fixes)
  - commit d0ac89c
  - RDMA/hns: Fix mapping error of zero-hop WQE buffer (git-fixes)
  - commit 87de660
  - RDMA/nldev: Set error code in rdma_nl_notify_event (git-fixes)
  - commit c4562bf
  - RDMA/core: Fix ENODEV error for iWARP test over vlan (git-fixes)
  - commit a0b253d
  - RDMA/uverbs: Prevent integer overflow issue (git-fixes)
  - commit aeb3e97
  - Reviewed
    patches.suse/0001-PKCS-7-Check-codeSigning-EKU-of-certificates-in-PKCS.patch
  - commit c96f4a3
  - Reviewed
    patches.suse/0001-X.509-Fix-the-parser-of-extended-key-usage-for-lengt.patch
  - commit b4da5d5
  - Reviewed
    patches.suse/0004-Documentation-admin-guide-module-signing.rst-add-ope.patch
  - commit 4076611
  - Reviewed
    patches.suse/0003-modsign-Add-codeSigning-EKU-when-generating-X.509-ke.patch
  - commit 3ca6e63
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch.
    Update config files.
    CONFIG_CHECK_CODESIGN_EKU
  - commit 3293035
  - Refresh
    patches.suse/0001-X.509-Add-CodeSigning-extended-key-usage-parsing.patch.
  - commit af592d7
  - ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv
    (bsc#1235964 CVE-2024-57892).
  - commit c39636c
  - efi: remove EFI secret key when booting with secure boot
    disabled (jsc#PED-1444).
  - commit b444d73

++++ kernel-rt:

  - tpm: ibmvtpm: Set TPM_OPS_AUTO_STARTUP flag on driver
    (git-fixes).
  - commit 6f0e558
  - net: mana: Cleanup "mana" debugfs dir after cleanup of all children (git-fixes).
  - commit 7180a8a
  - RDMA/hns: Fix missing flush CQE for DWQE (git-fixes)
  - commit 87b30f5
  - RDMA/hns: Fix warning storm caused by invalid input in IO path (git-fixes)
  - commit e09ea24
  - RDMA/hns: Fix accessing invalid dip_ctx during destroying QP (git-fixes)
  - commit d0ac89c
  - RDMA/hns: Fix mapping error of zero-hop WQE buffer (git-fixes)
  - commit 87de660
  - RDMA/nldev: Set error code in rdma_nl_notify_event (git-fixes)
  - commit c4562bf
  - RDMA/core: Fix ENODEV error for iWARP test over vlan (git-fixes)
  - commit a0b253d
  - RDMA/uverbs: Prevent integer overflow issue (git-fixes)
  - commit aeb3e97
  - Reviewed
    patches.suse/0001-PKCS-7-Check-codeSigning-EKU-of-certificates-in-PKCS.patch
  - commit c96f4a3
  - Reviewed
    patches.suse/0001-X.509-Fix-the-parser-of-extended-key-usage-for-lengt.patch
  - commit b4da5d5
  - Reviewed
    patches.suse/0004-Documentation-admin-guide-module-signing.rst-add-ope.patch
  - commit 4076611
  - Reviewed
    patches.suse/0003-modsign-Add-codeSigning-EKU-when-generating-X.509-ke.patch
  - commit 3ca6e63
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch.
    Update config files.
    CONFIG_CHECK_CODESIGN_EKU
  - commit 3293035
  - Refresh
    patches.suse/0001-X.509-Add-CodeSigning-extended-key-usage-parsing.patch.
  - commit af592d7
  - ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv
    (bsc#1235964 CVE-2024-57892).
  - commit c39636c
  - efi: remove EFI secret key when booting with secure boot
    disabled (jsc#PED-1444).
  - commit b444d73

++++ util-linux-systemd:

  - Move blkid.conf to /usr/etc (boo#1235887).

++++ gcc15:

  - New package, inherits from gcc14
  - Take patches inherited from GCC 14.
    * gcc-add-defaultsspec.diff, add the ability to provide a specs
    file that is read by default
    * tls-no-direct.diff, avoid direct %fs references on x86 to not
    slow down Xen
    * gcc43-no-unwind-tables.diff, do not produce unwind tables for
    CRT files
    * gcc41-ppc32-retaddr.patch, fix expansion of __builtin_return_addr
    for ppc, just a testcase
    * gcc44-textdomain.patch, make translation files version specific
    and adjust textdomain to find them
    * gcc44-rename-info-files.patch, fix cross-references in info files
    when renaming them to be version specific
    * gcc48-libstdc++-api-reference.patch, fix link in the installed
    libstdc++ html documentation
    * gcc7-remove-Wexpansion-to-defined-from-Wextra.patch, removes
    new warning from -Wextra
    * gcc7-avoid-fixinc-error.diff
    * gcc9-reproducible-builds-buildid-for-checksum.patch
    * gcc9-reproducible-builds.patch
    * gcc11-gdwarf-4-default.patch, default to -gdwarf-4 on old products

++++ util-linux:

  - Move blkid.conf to /usr/etc (boo#1235887).

++++ dav1d:

  - Update to version 1.5.1
    * Rewrite of the looprestoration (SGR, wiener) to reduce stack
    usage
    * Rewrite of {put,prep}_scaled functions
    * Improvements on the SSSE3 SGR
    * Improvements on ARM32/ARM64 looprestoration optimizations
    * RISC-V: blend optimizations for high bitdepth
    * Power9: blend optimizations for 8bpc
    * Port RISC-V to POSIX/non-Linux OS
    * AArch64: Add Neon implementation of load_tmvs
    * Fix a rare, but possible deadlock, in flush()

++++ ncurses:

  - Add ncurses patch 20250118
    + improve pattern used for configure --with-xterm-kbs option (report by
    Mingyu Wang)
    + update configure macros, from work on cdk and dialog.
    + change a parameter name in curs_sp_funcs.3x, for consistency (patch
    by "WHR").
    > patches by Branden Robinson:
    + improve formatting/style of manpages
    + change winwstr() to a generated function, using the macro definition,
    moving its handling of negative length parameter into winnwstr().
    + correct actual-function name in a few trace calls.

++++ shadow:

  - bsc#1235453: Set SYS_{UID,GID}_MIN to 201:
    After repeated similar requests to change the ID ranges we set the
    above mentioned value to 201. The max value will stay at 499.
    This range should be sufficient and will give us leeway for the
    future.
    It's not straightforward to find out which static UIDs/GIDs are
    used in all packages.
    Update shadow-login_defs-suse.patch

++++ wtmpdb:

  - Update to version 0.60.0+git20250120.64d23d8:
    * Release version 0.60.0
    * Merge reader/write socket to one generic one
    * wtmpdbd: add Ping, SetLogLevel and GetEnvironment

++++ libzypp:

  - Fix missing UID checks in repomanager workflow (fixes #603)
  - version 17.35.18 (35)
  - Move cmake config files to LIB_INSTALL_DIR/cmake/Zypp (fixes #28)
  - Fix 'zypper ps' when running in incus container (bsc#1229106)
    Should apply to lxc and lxd containers as well.
  - Re-enable 'rpm --runposttrans' usage for chrooted systems
    (bsc#1216091)
  - version 17.35.17 (35)

++++ permissions:

  - Update to version 1699_20250120:
    * profiles: whitelist nvidia-modprobe (bsc#1230950)

++++ selinux-policy:

  - Update to version 20240604+git682.1bebca04:
    * Label xrdp scripts in /etc as bin_t (bsc#1233738)
    * introduce unconfined_service_transition_to_unconfined_user boolean (bsc#1233738)
    * Allow database rotation for wtmpdbd_t
    * Allow wtmpdbd to send messages notifications
    * Introduce policy for wtmpdbd (bsc#1235660)

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#189
  - make update-bootloader an alias for pbl and re-add still in-use
    legacy options (bsc#1235320)
  - update tests
  - 1.23
  - merge gh#openSUSE/perl-bootloader#188
  - really enforce bash everywhere now (bsc#1231018)
  - 1.22

------------------------------------------------------------------
------------------  2025-1-19  -  Jan 19 2025  -------------------
------------------------------------------------------------------

++++ lzlib:

  - Update to release 1.15
    * Lzlib now reports a nonzero first LZMA byte as a
    LZ_data_error.
    * LZ_Errno, LZ_Encoder, and LZ_Decoder are now declared in
    lzlib.h as typedef.

++++ pango:

  - Update to version 1.56.1:
    + Avoid criticals when there are no fonts
    + fontconfig:
  - Handle lack of FC_FONT_WRAPPER in font cache
  - Prefer application fonts even if they are older

------------------------------------------------------------------
------------------  2025-1-18  -  Jan 18 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.6 → 10.2.7
  - Update documentation
    Added a new troubleshooting chapter as subsection to
    the Build Host Constraints named Package Manager Behavior.
    It serves the purpose to describe options for the customer
    to change the default package manager behavior which
    we from the kiwi side do not influence intentionally.
    This is a followup change to bsc#1235448

++++ kernel-default:

  - scsi: mpi3mr: Fix corrupt config pages PHY state is switched
    in sysfs (CVE-2024-57804 bsc#1235779).
  - commit aa77f1e
  - soc: ti: pruss: Fix pruss APIs (git-fixes).
  - reset: rzg2l-usbphy-ctrl: Assign proper of node to the allocated
    device (git-fixes).
  - platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev
    race (git-fixes).
  - platform/x86: dell-uart-backlight: fix serdev race (git-fixes).
  - Revert "mtd: spi-nor: core: replace dummy buswidth from addr
    to data" (git-fixes).
  - hwmon: (ltc2991) Fix mixed signed/unsigned in DIV_ROUND_CLOSEST
    (git-fixes).
  - hwmon: (tmp513) Fix division of negative numbers (git-fixes).
  - gpio: xilinx: Convert gpio_lock to raw spinlock (git-fixes).
  - i2c: testunit: on errors, repeat NACK until STOP (git-fixes).
  - i2c: rcar: fix NACK handling when being a target (git-fixes).
  - i2c: mux: demux-pinctrl: check initial mux selection, too
    (git-fixes).
  - i2c: atr: Fix client detach (git-fixes).
  - i2c: core: fix reference leak in i2c_register_adapter()
    (git-fixes).
  - pmdomain: imx8mp-blk-ctrl: add missing loop break condition
    (git-fixes).
  - selftests: mptcp: avoid spurious errors on disconnect
    (git-fixes).
  - drm/amd/pm:  fix BUG: scheduling while atomic (stable-fixes).
  - drm/amdkfd: wq_release signals dma_fence only when available
    (git-fixes).
  - drm/amd/display: Add check for granularity in dml ceil/floor
    helpers (stable-fixes).
  - drm/amd/display: increase MAX_SURFACES to the value supported
    by hw (stable-fixes).
  - pmdomain: imx: gpcv2: fix an OF node reference leak in
    imx_gpcv2_probe() (git-fixes).
  - commit edae5a9
  - block: RCU protect disk->conv_zones_bitmap (bsc#1235820,
    CVE-2024-57875).
  - commit 76c266d
  - ublk: detach gendisk from ublk device if add_disk() fails
    (bsc#1235634, CVE-2024-56764).
  - commit 3688e07

++++ kernel-rt:

  - scsi: mpi3mr: Fix corrupt config pages PHY state is switched
    in sysfs (CVE-2024-57804 bsc#1235779).
  - commit aa77f1e
  - soc: ti: pruss: Fix pruss APIs (git-fixes).
  - reset: rzg2l-usbphy-ctrl: Assign proper of node to the allocated
    device (git-fixes).
  - platform/x86: lenovo-yoga-tab2-pro-1380-fastcharger: fix serdev
    race (git-fixes).
  - platform/x86: dell-uart-backlight: fix serdev race (git-fixes).
  - Revert "mtd: spi-nor: core: replace dummy buswidth from addr
    to data" (git-fixes).
  - hwmon: (ltc2991) Fix mixed signed/unsigned in DIV_ROUND_CLOSEST
    (git-fixes).
  - hwmon: (tmp513) Fix division of negative numbers (git-fixes).
  - gpio: xilinx: Convert gpio_lock to raw spinlock (git-fixes).
  - i2c: testunit: on errors, repeat NACK until STOP (git-fixes).
  - i2c: rcar: fix NACK handling when being a target (git-fixes).
  - i2c: mux: demux-pinctrl: check initial mux selection, too
    (git-fixes).
  - i2c: atr: Fix client detach (git-fixes).
  - i2c: core: fix reference leak in i2c_register_adapter()
    (git-fixes).
  - pmdomain: imx8mp-blk-ctrl: add missing loop break condition
    (git-fixes).
  - selftests: mptcp: avoid spurious errors on disconnect
    (git-fixes).
  - drm/amd/pm:  fix BUG: scheduling while atomic (stable-fixes).
  - drm/amdkfd: wq_release signals dma_fence only when available
    (git-fixes).
  - drm/amd/display: Add check for granularity in dml ceil/floor
    helpers (stable-fixes).
  - drm/amd/display: increase MAX_SURFACES to the value supported
    by hw (stable-fixes).
  - pmdomain: imx: gpcv2: fix an OF node reference leak in
    imx_gpcv2_probe() (git-fixes).
  - commit edae5a9
  - block: RCU protect disk->conv_zones_bitmap (bsc#1235820,
    CVE-2024-57875).
  - commit 76c266d
  - ublk: detach gendisk from ublk device if add_disk() fails
    (bsc#1235634, CVE-2024-56764).
  - commit 3688e07

++++ libxslt:

  - Remove the test_bad regression test that fails with old libxml2
    as suggested by upstream devs:
    * https://gitlab.gnome.org/GNOME/libxslt/-/issues/126
  - Allow building with older libxml2 versions:
    * tests: Make runtest compile with older libxml2 versions
    * https://gitlab.gnome.org/GNOME/libxslt/issues/125
    * Add libxslt-test-compile-with-older-libxml2-versions.patch

------------------------------------------------------------------
------------------  2025-1-17  -  Jan 17 2025  -------------------
------------------------------------------------------------------

++++ coreutils:

  - Update to 9.6:
    Bug fixes
    * cp fixes support for --update=none-fail, which would have been
    rejected as an invalid option.
    [bug introduced in coreutils-9.5]
    * cp,mv --update no longer overrides --interactive or --force.
    [bug introduced in coreutils-9.3]
    * csplit no longer creates empty files given empty input.
    [This bug was present in "the beginning".]
    * ls and printf fix shell quoted output in the edge case of escaped
    first and last characters, and single quotes in the string.
    [bug introduced in coreutils-8.26]
    * ls -l no longer outputs "Permission denied" errors on NFS
    which may happen with files without read permission, and which resulted
    in inaccurate indication of ACLs (missing '+' flag after mode).
    [bug introduced in coreutils-9.4]
    * ls -l no longer outputs "Not supported" errors on virtiofs.
    [bug introduced in coreutils-9.4]
    * mv works again with macFUSE file systems.  Previously it would
    have exited with a "Function not implemented" error.
    [bug introduced in coreutils-8.28]
    * nproc gives more consistent results on systems with more than 1024 CPUs.
    Previously it would have ignored the affinity mask on such systems.
    [bug introduced with nproc in coreutils-8.1]
    * numfmt --from=iec-i now works with numbers without a suffix.
    Previously such numbers were rejected with an error.
    [bug introduced with numfmt in coreutils-8.21]
    * printf now diagnoses attempts to treat empty strings as numbers,
    as per POSIX. For example, "printf '%d' ''" now issues a diagnostic
    and fails instead of silently succeeding.
    [This bug was present in "the beginning".]
    * pwd no longer outputs an erroneous double slash on systems
    where the system getcwd() was completely replaced.
    [bug introduced in coreutils-9.2]
    * 'shuf' generates more-random output when the output is small.
    [bug introduced in coreutils-8.6]
    * `tail --follow=name` no longer waits indefinitely for watched
    file names that are moved elsewhere within the same file system.
    [bug introduced in coreutils-8.24]
    * `tail --follow` without --retry, will consistently exit with failure status
    where inotify is not used, when all followed files become inaccessible.
    [This bug was present in "the beginning".]
    * `tail --follow --pid=PID` will now exit when the PID dies,
    even in the presence of blocking inputs like unopened fifos.
    [This bug was present in "the beginning".]
    * 'tail -c 4096 /dev/zero' no longer loops forever.
    [This bug was present in "the beginning".]
    Changes in behavior
    * 'factor' now buffers output more efficiently in some cases.
    * install -C now dereferences symlink sources when comparing,
    rather than always treating as different and performing the copy.
    * kill -l and -t now list signal 0, as it's a valid signal to send.
    * ls's -f option now simply acts like -aU, instead of also ignoring
    some earlier options.  For example 'ls -fl' and 'ls -lf' are now
    equivalent because -f no longer ignores an earlier -l.  The new
    behavior is more orthogonal and is compatible with FreeBSD.
    * stat -f -c%T now reports the "fuseblk" file system type as "fuse",
    given that there is no longer a distinct "ctl" fuse variant file system.
    New Features
    * cksum -a now supports the "crc32b" option, which calculates the CRC
    of the input as defined by ITU V.42, as used by gzip for example.
    For performance pclmul instructions are used where supported.
    * ls now supports the --sort=name option,
    to explicitly select the default operation of sorting by file name.
    * printf now supports indexed arguments, using the POSIX:2024 specified
    %<i>$ format, where '<i>' is an integer referencing a particular argument,
    thus allowing repetition or reordering of printf arguments.
    * test supports the POSIX:2024 specified '<' and '>' operators with strings,
    to compare the string locale collating order.
    * timeout now supports the POSIX:2024 specified -f, and -p short options,
    corresponding to --foreground, and --preserve-status respectively.
    Improvements
    * cksum -a crc, makes use of AVX2, AVX512, and ARMv8 SIMD extensions
    for time reductions of up to 40%, 60%, and 80% respectively.
    * 'head -c NUM', 'head -n NUM', 'nl -l NUM', 'nproc --ignore NUM',
    'tail -c NUM', 'tail -n NUM', and 'tail --max-unchanged-stats NUM’
    no longer fail merely because NUM stands for 2**64 or more.
    * sort operates more efficiently when used on pseudo files with
    an apparent size of 0, like those in /proc.
    * stat and tail now know about the "bcachefs", and "pidfs" file system types.
    stat -f -c%T now reports the file system type,
    and tail -f uses inotify for these file systems.
    * wc now reads a minimum of 256KiB at a time.
    This was previously 16KiB and increasing to 256KiB was seen to increase
    wc -l performance by about 10% when reading cached files on modern systems.
  - coreutils-fix-gnulib-time_r-tests.patch: Remove now-upstream patch.
  - coreutils-9.6-ls-Z-crash-fix.patch: Add upstream patch from after the release.
  - coreutils.spec (Patch920): Exchange names of above patch files accordingly.
  - coreutils-i18n.patch: Refresh patch, manually porting some upstream fixes
    into the i18n chunks for expand.c, fold.c and unexpand.c.
  - Refresh all other patches:
    * coreutils-disable_tests.patch
    * coreutils-remove_hostname_documentation.patch
    * coreutils-remove_kill_documentation.patch
    * coreutils-skip-gnulib-test-tls.patch
    * coreutils-tests-shorten-extreme-factor-tests.patch
    * coreutils-tests-workaround-make-fdleak.patch

++++ coreutils-systemd:

  - Update to 9.6:
    Bug fixes
    * cp fixes support for --update=none-fail, which would have been
    rejected as an invalid option.
    [bug introduced in coreutils-9.5]
    * cp,mv --update no longer overrides --interactive or --force.
    [bug introduced in coreutils-9.3]
    * csplit no longer creates empty files given empty input.
    [This bug was present in "the beginning".]
    * ls and printf fix shell quoted output in the edge case of escaped
    first and last characters, and single quotes in the string.
    [bug introduced in coreutils-8.26]
    * ls -l no longer outputs "Permission denied" errors on NFS
    which may happen with files without read permission, and which resulted
    in inaccurate indication of ACLs (missing '+' flag after mode).
    [bug introduced in coreutils-9.4]
    * ls -l no longer outputs "Not supported" errors on virtiofs.
    [bug introduced in coreutils-9.4]
    * mv works again with macFUSE file systems.  Previously it would
    have exited with a "Function not implemented" error.
    [bug introduced in coreutils-8.28]
    * nproc gives more consistent results on systems with more than 1024 CPUs.
    Previously it would have ignored the affinity mask on such systems.
    [bug introduced with nproc in coreutils-8.1]
    * numfmt --from=iec-i now works with numbers without a suffix.
    Previously such numbers were rejected with an error.
    [bug introduced with numfmt in coreutils-8.21]
    * printf now diagnoses attempts to treat empty strings as numbers,
    as per POSIX. For example, "printf '%d' ''" now issues a diagnostic
    and fails instead of silently succeeding.
    [This bug was present in "the beginning".]
    * pwd no longer outputs an erroneous double slash on systems
    where the system getcwd() was completely replaced.
    [bug introduced in coreutils-9.2]
    * 'shuf' generates more-random output when the output is small.
    [bug introduced in coreutils-8.6]
    * `tail --follow=name` no longer waits indefinitely for watched
    file names that are moved elsewhere within the same file system.
    [bug introduced in coreutils-8.24]
    * `tail --follow` without --retry, will consistently exit with failure status
    where inotify is not used, when all followed files become inaccessible.
    [This bug was present in "the beginning".]
    * `tail --follow --pid=PID` will now exit when the PID dies,
    even in the presence of blocking inputs like unopened fifos.
    [This bug was present in "the beginning".]
    * 'tail -c 4096 /dev/zero' no longer loops forever.
    [This bug was present in "the beginning".]
    Changes in behavior
    * 'factor' now buffers output more efficiently in some cases.
    * install -C now dereferences symlink sources when comparing,
    rather than always treating as different and performing the copy.
    * kill -l and -t now list signal 0, as it's a valid signal to send.
    * ls's -f option now simply acts like -aU, instead of also ignoring
    some earlier options.  For example 'ls -fl' and 'ls -lf' are now
    equivalent because -f no longer ignores an earlier -l.  The new
    behavior is more orthogonal and is compatible with FreeBSD.
    * stat -f -c%T now reports the "fuseblk" file system type as "fuse",
    given that there is no longer a distinct "ctl" fuse variant file system.
    New Features
    * cksum -a now supports the "crc32b" option, which calculates the CRC
    of the input as defined by ITU V.42, as used by gzip for example.
    For performance pclmul instructions are used where supported.
    * ls now supports the --sort=name option,
    to explicitly select the default operation of sorting by file name.
    * printf now supports indexed arguments, using the POSIX:2024 specified
    %<i>$ format, where '<i>' is an integer referencing a particular argument,
    thus allowing repetition or reordering of printf arguments.
    * test supports the POSIX:2024 specified '<' and '>' operators with strings,
    to compare the string locale collating order.
    * timeout now supports the POSIX:2024 specified -f, and -p short options,
    corresponding to --foreground, and --preserve-status respectively.
    Improvements
    * cksum -a crc, makes use of AVX2, AVX512, and ARMv8 SIMD extensions
    for time reductions of up to 40%, 60%, and 80% respectively.
    * 'head -c NUM', 'head -n NUM', 'nl -l NUM', 'nproc --ignore NUM',
    'tail -c NUM', 'tail -n NUM', and 'tail --max-unchanged-stats NUM’
    no longer fail merely because NUM stands for 2**64 or more.
    * sort operates more efficiently when used on pseudo files with
    an apparent size of 0, like those in /proc.
    * stat and tail now know about the "bcachefs", and "pidfs" file system types.
    stat -f -c%T now reports the file system type,
    and tail -f uses inotify for these file systems.
    * wc now reads a minimum of 256KiB at a time.
    This was previously 16KiB and increasing to 256KiB was seen to increase
    wc -l performance by about 10% when reading cached files on modern systems.
  - coreutils-fix-gnulib-time_r-tests.patch: Remove now-upstream patch.
  - coreutils-9.6-ls-Z-crash-fix.patch: Add upstream patch from after the release.
  - coreutils.spec (Patch920): Exchange names of above patch files accordingly.
  - coreutils-i18n.patch: Refresh patch, manually porting some upstream fixes
    into the i18n chunks for expand.c, fold.c and unexpand.c.
  - Refresh all other patches:
    * coreutils-disable_tests.patch
    * coreutils-remove_hostname_documentation.patch
    * coreutils-remove_kill_documentation.patch
    * coreutils-skip-gnulib-test-tls.patch
    * coreutils-tests-shorten-extreme-factor-tests.patch
    * coreutils-tests-workaround-make-fdleak.patch

++++ dracut:

  - Update to version 059+suse.651.g303e60b5:
    Sync SLFO with Factory (bsc#1236018):
    * fix(dracut): rework timeout for devices added via --mount and --add-device (bsc#1231792)
    * fix(systemd): copy 20-systemd-stub.conf into the initrd
    * feat(systemd-coredump): save coredumps to journal
    * fix(suse-initrd): shellcheck SC1007
    * fix(pcsc): add libpcsclite_real.so.*
    * fix(dracut-systemd): use expected PS1 in the emergency shell
    * fix(dracut-systemd): unquote systemd conf strings
    * feat: add header comment to generators
    * refactor: change TimeoutSec=0 to TimeoutSec=infinity
    * fix(dracut.sh): do not add cmdline for force_drivers if --kernel-only
    * fix(btrfs): write cmdline in install()
    * fix(dracut.sh): omit compressed kernel modules from find searching exec files
    * fix(dracut): don't apply aggressive strip to kernel modules
    * fix(dracut-install): copy xattr when use clone ioctl
    * fix(systemd-ask-password): no graphical output in aarch64 (bsc#1224404)
    * perf(drm): group dracut_instmods calls
    * fix: do not write to /usr/lib/modprobe.d at boot
    * fix(install.d): skip if dracut is not the initrd or UKI generator
    * style(install.d): shfmt reformat
    * fix(suse-initrd): clean return of installkernel() (bsc#1223467)
    * fix(dracut.spec): do not check if fillup template exists at %post end
    * fix(dracut): move hooks directory from /usr/lib to /var/lib (bsc#1218068)
    * feat(tpm2-tss): add tpm2.target and systemd-tpm2-generator
    * fix(systemd): explicitly install some libs that will not be statically included
    * fix(dracut-lib): only remove initqueue/finished scripts, not the hook dir
    * fix(dracut-util): avoid memory leak
    * fix(dracut-install): memory leak in two `hashmap_put` calls if key exists
    * fix(dracut-install): release memory allocated for regular expressions
    * fix(dracut-install): memory leak in `--modalias` option
    * refactor(dracut-install): strerror(errno) -> %m
    * perf(dracut-install): don't strdup() environment block
    * perf(dracut-install): don't reallocate {src,dst}path in hmac_install()
    * perf(dracut-install): don't strdup() excessively for dracut_install()
    * perf(dracut-install): stat() w/unused buf -> access(F_OK) in dracut-install
    * perf(dracut-install): multiple single-character strstr()s -> strpbrk()
    * chore: remove src/install/hashmap.lo
    * feat(dracut): add option to disable automatic guessing of output file (bsc#1213648)
    * fix(systemd-pcrphase): rename systemd-pcrphase binary to systemd-pcrextend

++++ kernel-default:

  - KVM: arm64: Get rid of userspace_irqchip_in_use (CVE-2024-53195
    bsc#1234957).
  - commit 4e1a286
  - KVM: arm64: Don't retire aborted MMIO instruction
    (CVE-2024-53196 bsc#1234906).
  - commit c7394cd
  - xen: Fix the issue of resource not being properly released in
    xenbus_dev_probe() (CVE-2024-53198 bsc#1234923).
  - commit a0f3f9e
  - x86/static-call: Remove early_boot_irqs_disabled check to fix
    Xen PVH dom0 (git-fixes).
  - commit 8264638
  - mm: hugetlb: independent PMD page table shared count
    (CVE-2024-57883 bsc#1235947).
  - commit 454014f
  - ASoC: tas2781: Fix occasional calibration failture (git-fixes).
  - commit 9c36ea2
  - drm/xe: Mark ComputeCS read mode as UC on iGPU (git-fixes).
  - drm/xe/oa: Add missing VISACTL mux registers (git-fixes).
  - drm/xe: make change ccs_mode a synchronous action (git-fixes).
  - drm/xe: introduce xe_gt_reset and xe_gt_wait_for_reset
    (git-fixes).
  - drm/amd/display: Do not elevate mem_type change to full update
    (git-fixes).
  - drm/amd/display: Do not wait for PSR disable on vbl enable
    (git-fixes).
  - Revert "drm/amd/display: Enable urgent latency adjustments
    for DCN35" (git-fixes).
  - drm/amd/display: Validate mdoe under MST LCT=1 case as well
    (git-fixes).
  - drm/v3d: Ensure job pointer is set to NULL after job completion
    (git-fixes).
  - drm/vmwgfx: Add new keep_resv BO param (git-fixes).
  - drm/vmwgfx: Unreserve BO on error (git-fixes).
  - drm/tests: helpers: Fix compiler warning (git-fixes).
  - commit 0fe40cd
  - config: enable
    CONFIG_INTEL_IOMMU_SCALABLE_MODE_DEFAULT_ON
  - commit 7266c28
  - ftrace: Fix regression with module command in stack_trace_filter
    (CVE-2024-56569 bsc#1235031).
  - commit edf09c4
  - Move upstreamed DRM patch into sorted section
  - commit efd17c1

++++ kernel-rt:

  - KVM: arm64: Get rid of userspace_irqchip_in_use (CVE-2024-53195
    bsc#1234957).
  - commit 4e1a286
  - KVM: arm64: Don't retire aborted MMIO instruction
    (CVE-2024-53196 bsc#1234906).
  - commit c7394cd
  - xen: Fix the issue of resource not being properly released in
    xenbus_dev_probe() (CVE-2024-53198 bsc#1234923).
  - commit a0f3f9e
  - x86/static-call: Remove early_boot_irqs_disabled check to fix
    Xen PVH dom0 (git-fixes).
  - commit 8264638
  - mm: hugetlb: independent PMD page table shared count
    (CVE-2024-57883 bsc#1235947).
  - commit 454014f
  - ASoC: tas2781: Fix occasional calibration failture (git-fixes).
  - commit 9c36ea2
  - drm/xe: Mark ComputeCS read mode as UC on iGPU (git-fixes).
  - drm/xe/oa: Add missing VISACTL mux registers (git-fixes).
  - drm/xe: make change ccs_mode a synchronous action (git-fixes).
  - drm/xe: introduce xe_gt_reset and xe_gt_wait_for_reset
    (git-fixes).
  - drm/amd/display: Do not elevate mem_type change to full update
    (git-fixes).
  - drm/amd/display: Do not wait for PSR disable on vbl enable
    (git-fixes).
  - Revert "drm/amd/display: Enable urgent latency adjustments
    for DCN35" (git-fixes).
  - drm/amd/display: Validate mdoe under MST LCT=1 case as well
    (git-fixes).
  - drm/v3d: Ensure job pointer is set to NULL after job completion
    (git-fixes).
  - drm/vmwgfx: Add new keep_resv BO param (git-fixes).
  - drm/vmwgfx: Unreserve BO on error (git-fixes).
  - drm/tests: helpers: Fix compiler warning (git-fixes).
  - commit 0fe40cd
  - config: enable
    CONFIG_INTEL_IOMMU_SCALABLE_MODE_DEFAULT_ON
  - commit 7266c28
  - ftrace: Fix regression with module command in stack_trace_filter
    (CVE-2024-56569 bsc#1235031).
  - commit edf09c4
  - Move upstreamed DRM patch into sorted section
  - commit efd17c1

++++ kubevirt:

  - Fix guest-console-log failure during live migration and Harvester upgrades
    0001-feat-pass-timeout-from-virt-monitor-to-virt-tail.patch
  - Fix SEV(ES) guests not being bootable from incompatible firmware
    0002-Ensure-SEV-VMs-use-stateless-OVMF-firmware.patch (bsc#1232762)
  - Update to version 1.4.0
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.4.0
  - Drop patches
    0001-Consider-the-new-DV-reason-ImagePullFailed.patch
    0002-tests-Set-FSGroup-to-ensure-proper-permissions.patch
  - Add patches
    0001-feat-pass-timeout-from-virt-monitor-to-virt-tail.patch
    0002-Ensure-SEV-VMs-use-stateless-OVMF-firmware.patch (bsc#1232762)

++++ libxslt:

  - Update to 1.1.42:
    * Regressions:
  - extensions: Readd call to xmlCheckFilename with older libxml2
    * Improvments:
  - utils: Don't use deprecated xmlCharEncodingHandler member
  - transform: Handle filesystem paths after libxml2 changes
  - locale: Work around issue with FreeBSD's strxfrm_l
    * Build systems:
  - cmake: Add LIBXSLT_WITH_PROGRAMS option (Don Olmstead)
  - cmake: Fix HAVE_GCRYPT check
  - Update to 1.1.41:
    * Removals:
  - autotools: Stop installing libxslt.m4
  - autotools: Remove RPM build
    * Improvements:
  - libxslt: Set _FILE_OFFSET_BITS to 64
  - xsltproc: Remove unneeded includes
  - include: Don't define ATTRIBUTE_UNUSED in public header
  - xsltproc: Make "-" read from stdin
    * Build systems:
  - cmake: Adjust paths for UNIX or UNIX-like target systems (Daniel E)
    * Tests:
  - cmake: Link testplugin with libxml2
  - tests: Link testplugin with libxml2
  - tests: Fix expected error after libxml2 change
  - runtest: Switch to xmlFormatError
  - fuzz: Avoid accessing internal struct members
  - Update to 1.1.40:
    * Removals:
  - xsltproc: remove maxparserdepth option (Mike Dalessio)
    * Improvements:
  - functions: xmlXPtrNewContext is deprecated
  - xsltproc: Stop calling xmlMemoryDump
  - xsltproc: Prefer XML_PARSE_NONET over xmlNoNetEntityLoader
  - functions: Fix build if libxml2 modules are disabled
  - extensions: Don't call deprecated xmlCheckFilename
  - documents: Don't set ctxt->directory
  - exslt: Fix EXSLT functions without parameters
    * Build systems:
  - build: Remove mem-debug option
    * Remove patches upstream:
  - gcc14-runtest-no-const.patch
  - 0001-tests-Fix-build-with-older-libxml2.patch

++++ wtmpdb:

  - Update to version 0.50.0+git20250117.a9b48cf:
    * wtmpdbd.service: secure more
    * wtmpdb: Implement json output for last (#20)

++++ libxml2:

  - Update to 2.13.5:
    * Regressions:
  - xmlIO: Fix reading from non-regular files like pipes
  - xmlreader: Fix return value of xmlTextReaderReadString
  - parser: Fix loading of parameter entities in external DTDs
  - parser: Fix downstream code that swaps DTDs
  - parser: Fix detection of duplicate attributes
  - string: Fix va_copy fallback
    * Bug fixes:
  - xpath: Fix parsing of non-ASCII names
  - Update to 2.13.4:
    * Regressions:
  - parser: Make unsupported encodings an error in declarations
  - io: don't set the executable bit when creating files
  - xmlcatalog: Improved fix for #699
  - Revert "catalog: Fetch XML catalog before dumping"
  - io: Add missing calls to xmlInitParser
  - tree: Restore return value of xmlNodeListGetString with NULL list
  - parser: Fix error handling after reaching limit
  - parser: Make xmlParseChunk return an error if parser was stopped
    * Bug fixes:
  - python: Fix SAX driver with character streams
    * Improvements:
  - xpath: Make recursion check work with xmlXPathCompile
  - parser: Report at least one fatal error
  - Update to 2.13.3:
    * Security:
  - [bsc#1234812, CVE-2024-40896] Fix XXE protection in downstream code
    * Regressions:
  - autotools: Use AC_CHECK_DECL to check for getentropy
  - xinclude: Fix fallback for text includes
  - io: Don't call getcwd in xmlParserGetDirectory
  - io: Fix return value of xmlFileRead
  - parser: Fix error return of xmlParseBalancedChunkMemory
    * Improvements:
  - xinclude: Set error handler when parsing text
  - Undeprecate xmlKeepBlanksDefault
  - Update to 2.13.2:
    * Regressions:
  - tree: Fix handling of empty strings in xmlNodeParseContent
  - valid: Restore ID lookup
  - parser: Reenable ctxt->directory
  - uri: Handle filesystem paths in xmlBuildRelativeURISafe
  - encoding: Make xmlFindCharEncodingHandler return UTF-8 handler
  - encoding: Fix encoding lookup with xmlOpenCharEncodingHandler
  - include: Define ATTRIBUTE_UNUSED for clang
  - uri: Fix xmlBuildURI with NULL base
    * Regressions:
  - parser: Selectively reenable reading from "-"
  - reader: Fix xmlTextReaderReadString
  - xinclude: Set XPath context doc
  - xinclude: Load included documents with XML_PARSE_DTDLOAD
  - include: Don't redefine ATTRIBUTE_UNUSED
  - include: Readd circular dependency between tree.h and parser.h
  - xinclude: Add missing include
  - xinclude: Don't raise error on empty nodeset
  - parser: Make failure to load main document a warning
  - tree: Fix freeing entities via xmlFreeNode
  - parser: Pass global object to sax->setDocumentLocator
    * Improvements:
  - io: Fix resetting xmlParserInputBufferCreateFilename hook
    * Documentation:
  - Fix typo in NEWS (--with-html -> --with-http)
  - doc: Don't mention xmlNewInputURL

++++ osinfo-db:

  - Add support for SLES-16 (bsc#1236252) (jsc#PED-8910)
    add-sles16-support.patch

++++ pam_u2f:

  - update to 1.3.1:
    * Fix incorrect usage of PAM_IGNORE (YSA-2025-01, CVE-2025-23013, bsc#1233517).
    * Changed return value when nouserok is enabled and the user has no
    credentials, PAM_IGNORE is used instead of PAM_SUCCESS.
    * Hardened checks of authfile permissions.
    * Hardened checks for nouserok.
    * Improved debug messages.
    * Improved documentation.

++++ libxml2-python:

  - Update to 2.13.5:
    * Regressions:
  - xmlIO: Fix reading from non-regular files like pipes
  - xmlreader: Fix return value of xmlTextReaderReadString
  - parser: Fix loading of parameter entities in external DTDs
  - parser: Fix downstream code that swaps DTDs
  - parser: Fix detection of duplicate attributes
  - string: Fix va_copy fallback
    * Bug fixes:
  - xpath: Fix parsing of non-ASCII names
  - Update to 2.13.4:
    * Regressions:
  - parser: Make unsupported encodings an error in declarations
  - io: don't set the executable bit when creating files
  - xmlcatalog: Improved fix for #699
  - Revert "catalog: Fetch XML catalog before dumping"
  - io: Add missing calls to xmlInitParser
  - tree: Restore return value of xmlNodeListGetString with NULL list
  - parser: Fix error handling after reaching limit
  - parser: Make xmlParseChunk return an error if parser was stopped
    * Bug fixes:
  - python: Fix SAX driver with character streams
    * Improvements:
  - xpath: Make recursion check work with xmlXPathCompile
  - parser: Report at least one fatal error
  - Update to 2.13.3:
    * Security:
  - [bsc#1234812, CVE-2024-40896] Fix XXE protection in downstream code
    * Regressions:
  - autotools: Use AC_CHECK_DECL to check for getentropy
  - xinclude: Fix fallback for text includes
  - io: Don't call getcwd in xmlParserGetDirectory
  - io: Fix return value of xmlFileRead
  - parser: Fix error return of xmlParseBalancedChunkMemory
    * Improvements:
  - xinclude: Set error handler when parsing text
  - Undeprecate xmlKeepBlanksDefault
  - Update to 2.13.2:
    * Regressions:
  - tree: Fix handling of empty strings in xmlNodeParseContent
  - valid: Restore ID lookup
  - parser: Reenable ctxt->directory
  - uri: Handle filesystem paths in xmlBuildRelativeURISafe
  - encoding: Make xmlFindCharEncodingHandler return UTF-8 handler
  - encoding: Fix encoding lookup with xmlOpenCharEncodingHandler
  - include: Define ATTRIBUTE_UNUSED for clang
  - uri: Fix xmlBuildURI with NULL base
    * Regressions:
  - parser: Selectively reenable reading from "-"
  - reader: Fix xmlTextReaderReadString
  - xinclude: Set XPath context doc
  - xinclude: Load included documents with XML_PARSE_DTDLOAD
  - include: Don't redefine ATTRIBUTE_UNUSED
  - include: Readd circular dependency between tree.h and parser.h
  - xinclude: Add missing include
  - xinclude: Don't raise error on empty nodeset
  - parser: Make failure to load main document a warning
  - tree: Fix freeing entities via xmlFreeNode
  - parser: Pass global object to sax->setDocumentLocator
    * Improvements:
  - io: Fix resetting xmlParserInputBufferCreateFilename hook
    * Documentation:
  - Fix typo in NEWS (--with-html -> --with-http)
  - doc: Don't mention xmlNewInputURL

++++ python-pyserial:

  - fix alternatives

++++ python-referencing:

  - Update to version 0.36.1:
    * Add a lower pin on typing-extensions for the version we depend
    on.
  - Update to version 0.36.0:
    * Declare support for Python 3.13.

++++ python-rich:

  - Add pygments.patch to fix tests with Pygments 2.19

++++ python-rpds-py:

  - Update to version 0.22.3:
    * Properly tag a release fixing the soundness issue.
    * Bump to PyO3 0.23.3, avoiding 0.23.x's previous soundness
    issues.
    * [pre-commit.ci] pre-commit autoupdate
  - Update to version 0.22.1:
    * Tag a release for regaining all the Windows wheels.
    * ci: separate free-threaded and standard 3.13 distribution
    builds
    * Bump pyo3 from 0.23.1 to 0.23.2
  - Update to version 0.22.0:
    * Bump to 0.22.0 for a free-threading-supported beta release.
    * Enable free-threaded wheel builds
    * [pre-commit.ci] pre-commit autoupdate
    * [pre-commit.ci] auto fixes from pre-commit.com hooks
    * revert changes to wheel-building config
    * work around CPython issue 127065
    * declare support for free-threading
    * [pre-commit.ci] pre-commit autoupdate
    * Bump pyo3 from 0.23.0 to 0.23.1
    * Build on all branches.
    * Skip zizmor in pre-commit.ci as well.
    * add 3.13t to CI config
    * point Cargo.toml at pyo3 0.23 on crates.io
    * update rpds.py for PyO3 0.23
    * [pre-commit.ci] pre-commit autoupdate
    * Bump the zizmor version.

++++ rsync:

  - Update to 3.4.1
    * BUG FIXES:
  - fixed handling of -⁠H flag with conflict in internal flag values
  - fixed a user after free in logging of failed rename
  - fixed build on systems without openat()
  - removed dependency on alloca() in bundled popt
    * DEVELOPER RELATED:
  - fix to permissions handling in the developer release script
  - Drop 705.patch, because now in upstream.

++++ suse-module-tools:

  - Update to version 16.0.56:
    * rpm-script: create /boot/vmlinuz and /boot/initrd in kiwi environment
    (bsc#1234275, bsc#1234759)

++++ velociraptor-client:

  - Reorganize llvm dependency version conditionals
  - Use llvm17 for Leap 15.5
  - Update to version 0.7.0.4.git142.862ef23:
    * github: fix deprecated upload artifact again
    * Update npm packages
    Includes fixes for the following vulnerabilities:
    CVE-2023-45133
    CVE-2023-46234
    CVE-2024-55565
    CVE-2024-45296
    CVE-2023-44270
    CVE-2024-47068
    CVE-2024-23331
    CVE-2024-31207
    CVE-2024-45812
    CVE-2024-45811
    * Update go dependencies
    Includes fixes for the following vulnerabilities:
    CVE-2024-45338
    CVE-2024-37298
    CVE-2024-24786
    CVE-2023-45683 (bsc#1216310)
    CVE-2023-1732
    * Update jwt to 4.5.1
    Fixes CVE-2024-51744 (bsc#1232944)
    * Update go-retryablehttp to 0.7.7
    Fixes CVE-2024-6104 (bsc#1227061)
    * Update go-oidc and go-jose
    Fixes CVE-2024-28180 (bsc#1235168)
    * Update dompurify to 3.1.3
    Fixes CVE-2024-47875 (bsc#1231574)
    * Update package-lock.json
    * Update micromatch to 4.0.8
    Partial fix for CVE-2024-4067 (bsc#1224367)
    Partial fix for CVE-2024-4068 (bsc#1224296)
    * Update axios to 1.7.9
    Fixes CVE-2024-39338 (bsc#1229424)
    * Update cross-spawn to 7.0.6
    Fixes CVE-2024-21538 (bsc#1233845)
    * Update elliptic to 6.6.1
    Update contains fixes for:
    CVE-2024-48949 (bsc#1231558)
    CVE-2024-48948 (bsc#1231685)
    CVE-2024-42459 (bsc#1232543)
    CVE-2024-42460 (bsc#1232543)
    CVE-2024-42461 (bsc#1232543)
    * Update follow-redirects to 1.15.6
    Fixes CVE-2024-28849 (bsc#1221456)
    * fix: gui/velociraptor/package.json to reduce vulnerabilities
    Fixes CVE-2022-25883 (bsc#1212572)
  - Drop CVE-2022-25883-npm-watch-semver-deps.patch
    * Fix was included upstream

++++ tuned:

  - Update to version 2.24.1.50+git.13dfc68:
    * scheduler: updated sched knobs for kernels 6.6+
    * plugin_cpu: allow raw energy_performance_preference values
    * Do not initialize kvm low latency if kvm not present
  - Do not conflict with power-profiles-daemon, this is managed via
    ppd-service in the tuned-ppd subpackage (bsc#1234754)

++++ virt-manager:

  - Fix issue being able to detect SLES 16 media (jsc#PED-8910)
    See also bsc#1236252
    virtinst-add-sle16-detection-support.patch

++++ zypper:

  - Try to refresh update repos first to have updated GPG keys on
    the fly (bsc#1234752)
    An update repo may contain a prolonged GPG key for the GA repo.
    Refreshing the update repo first updates a trusted key on the fly
    and avoids a 'key has expired' warning being issued when
    refreshing the GA repo.
  - Refresh: restore legacy behavior and suppress Exception
    reporting as non-root (bsc#1235636)
  - version 1.14.80

------------------------------------------------------------------
------------------  2025-1-16  -  Jan 16 2025  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Update to version 2.32.4:
    * add missing tag for build during merge workflow
    * ci: re-use local source to build binary images
    * ci: use local source for binary builds

++++ kernel-default:

  - RDMA/siw: Remove direct link to net_device (bsc#1235946 CVE-2024-57857)
  - commit a26645d
  - af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK
    (CVE-2024-57901 bsc#1235900).
  - net: wwan: t7xx: Fix FSM command timeout issue (CVE-2024-39282
    bsc#1235903).
  - commit f820992
  - tpm: Map the ACPI provided event log (bsc#1233260 bsc#1233259
    bsc#1232421).
  - commit 9c4f937
  - RDMA/rtrs: Ensure 'ib_sge list' is accessible (bsc#1235902 CVE-2024-36476)
  - commit 5e76f66
  - RDMA/rxe: Remove the direct link to net_device (bsc#1235906 CVE-2024-57795)
  - commit 09cd979
  - iommu/vt-d: Remove cache tags before disabling ATS
    (CVE-2024-56669 bsc#1235245).
  - commit f02f36b
  - iommu/vt-d: Fix qi_batch NULL pointer with nested parent  domain
    (CVE-2024-56668 bsc#1235017).
  - commit 1757163
  - mm: use aligned address in copy_user_gigantic_page()
    (CVE-2024-51729 bsc#1235741).
  - commit 3c62d9b
  - bpf: fix recursive lock when verdict program return SK_PASS (CVE-2024-56694 bsc#1235412)
  - commit dfde0f5
  - bpf: fix OOB devmap writes when deleting elements (CVE-2024-56615 bsc#1235426)
  - commit 997fa6c
  - xsk: fix OOB map writes when deleting elements (CVE-2024-56614 bsc#1235424)
  - commit 4dda137
  - mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MM (CVE-2024-56611 bsc#1235391)
  - commit 3a11b51

++++ kernel-rt:

  - RDMA/siw: Remove direct link to net_device (bsc#1235946 CVE-2024-57857)
  - commit a26645d
  - af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK
    (CVE-2024-57901 bsc#1235900).
  - net: wwan: t7xx: Fix FSM command timeout issue (CVE-2024-39282
    bsc#1235903).
  - commit f820992
  - tpm: Map the ACPI provided event log (bsc#1233260 bsc#1233259
    bsc#1232421).
  - commit 9c4f937
  - RDMA/rtrs: Ensure 'ib_sge list' is accessible (bsc#1235902 CVE-2024-36476)
  - commit 5e76f66
  - RDMA/rxe: Remove the direct link to net_device (bsc#1235906 CVE-2024-57795)
  - commit 09cd979
  - iommu/vt-d: Remove cache tags before disabling ATS
    (CVE-2024-56669 bsc#1235245).
  - commit f02f36b
  - iommu/vt-d: Fix qi_batch NULL pointer with nested parent  domain
    (CVE-2024-56668 bsc#1235017).
  - commit 1757163
  - mm: use aligned address in copy_user_gigantic_page()
    (CVE-2024-51729 bsc#1235741).
  - commit 3c62d9b
  - bpf: fix recursive lock when verdict program return SK_PASS (CVE-2024-56694 bsc#1235412)
  - commit dfde0f5
  - bpf: fix OOB devmap writes when deleting elements (CVE-2024-56615 bsc#1235426)
  - commit 997fa6c
  - xsk: fix OOB map writes when deleting elements (CVE-2024-56614 bsc#1235424)
  - commit 4dda137
  - mm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MM (CVE-2024-56611 bsc#1235391)
  - commit 3a11b51

++++ llvm19:

  - Update to version 19.1.7.
    * This release contains bug-fixes for the LLVM 19.1.0 release.
    This release is API and ABI compatible with 19.1.0.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ freeipmi:

  - freeimpi 1.6.15:
    * In ipmi-config, fix incorrect output of
    IPv6_Dynamic_Address_Source_Type
    * In ipmi-oem, increase precision of Dell cumulative energy
    output
    * Do not advertise options that are only available when special
    debugging is compiled into FreeIPMI
    * libfreeipmi: remove unnecessary / duplicate parameter checks
    * Minor documentation updates
  - drop gcc-14.patch

++++ ncurses:

  - Drop all ghostty terminfo entries as ghostty read also its own
    termcap files even with terminfo (boo#1235689)

++++ pango:

  - Update to version 1.56.0+12:
    * Deal with FC_FONT_WRAPPER more graciously
    * itemize: Limp along harder
    * build: Reshuffle docs build
    * build: Move gir to toplevel meson.build
    * build: Generate glib deprecation defines
    * build: Sync naming with gtk

++++ libsoup:

  - Update to version 3.6.4:
    + http2: Fix regression on 32bit systems when reading response
    data.

++++ sqlite3:

  - Re-enable SONAME which got disabled by default in 3.48.0.
    * https://www.sqlite.org/src/forumpost/5a3b44f510df8ded
    * https://sqlite.org/forum/forumpost/ab8f15697a

++++ libvirt:

  - Update to libvirt 11.0.0
  - jsc#PED-5899, jsc#PED-8909, jsc#PED-9543, jsc#PED-9854,
    jsc#PED-9855
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v11-0-0-2025-01-15

++++ wtmpdb:

  - Update to version 0.50.0+git20250110.cbabeb7:
    * Harden wtmpdbd.service
    * libwtmpdb: fallback to sqlite if SELinux blocks varlink socket

++++ python-libvirt-python:

  - Update to 11.0.0
  - Add all new APIs and constants in libvirt 11.0.0
  - jsc#PED-5899, jsc#PED-8909, jsc#PED-9543, jsc#PED-9854,
    jsc#PED-9855

++++ python-setuptools:

  - Also provide python3-setuptools-wheel for the primary flavor.

++++ rsync:

  - update to 3.4.1
    * fixed handling of -H flag with conflict in internal flag values
    (replaces 705.patch)
    * fixed a user after free in logging of failed rename
    * fixed build on systems without openat()
    * removed dependency on alloca() in bundled popt

++++ timezone:

  - Update to 2025a:
    * Paraguay adopts permanent -03 starting spring 2024
    * Improve pre-1991 data for the Philippines
    * Etc/Unknown is now reserved

++++ tuned:

  - Update to version 2.24.1.44+git.cc168b9:
    * tuned-ppd: Remove the use of StrEnum
    * tuned-ppd: Disallow releasing profile holds of other processes
    * tuned-ppd: Unify polkit policy with power-profiles-daemon
    * Obsolete power-profiles-daemon
    * Document new vm plugin options
    * Adjust profiles to set dirty_(bytes|ratio) via the vm plugin
    * vm: Add support for dirty_(bytes|ratio) sysctl parameters
    * tuned-ppd: Support the new UPower PPD namespace
    * tuned-ppd: Enable changing profile via function keys
    * tuned-ppd: Use inotify to check for performance degradation
    * tuned-ppd: Require the presence of the balanced profile
    * tuned-ppd: Add the version property
    * tuned-ppd: Add docstrings
    * tuned-ppd: Keep track of active and base profile
    * tuned-ppd: Fix UPower signal handler initialization
    * Add variables to BLS entries only if grub is used
    * powertop2tuned: use default user profile path from the consts
    * tuned-ppd: Use effective hold profile when adding profile holds
    * Bump doc/manual revision date and number
    * Clean up plugin docstrings
    * Add a script for generation of plugin docs from docstrings
    * scheduler: Do not assume that perf events have type attribute
    * Fix the error in the raise statement of check_positive()
    * fix: expand variables in Plugin._verify_all_device_commands
    * Allow shared service drop-in directory
    * drop support for cpuspeed
    * Parse no_turbo cpu plugin option using commands.get_bool

------------------------------------------------------------------
------------------  2025-1-15  -  Jan 15 2025  -------------------
------------------------------------------------------------------

++++ glib2:

  - Update to version 2.82.4:
    + Fix a double-unref crash which affects many apps which use
    pygobject to export objects on D-Bus
    + Bugs fixed:
  - Fix regression: lollypop crashes on startup
  - Revert "gdbus: Fix leak of method invocation when registering
    an object with closures"
  - ci: Add release component to automate tarball publishing

++++ kernel-default:

  - iommu/tegra241-cmdqv: Fix alignment failure at max_n_shift (CVE-2024-53225 bsc#1235006)
  - commit d17bd9f
  - ring-buffer: Fix overflow in __rb_map_vma (bsc#1235752
    CVE-2024-56368).
  - commit 887043f
  - mm: use aligned address in clear_gigantic_page() (bsc#1235742
    CVE-2024-52319).
  - commit cf2082f
  - netdevsim: prevent bad user input in
    nsim_dev_health_break_write() (bsc#1235587 CVE-2024-56716).
  - commit 64a78e2
  - bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors
    (bsc#1235555 CVE-2024-56675).
  - commit 9dd9586
  - net: netdevsim: fix nsim_pp_hold_write() (bsc#1235554
    CVE-2024-56713).
  - commit 9b9335e
  - mm/gup: handle NULL pages in unpin_user_pages() (bsc#1235388
    CVE-2024-56612).
  - commit 58f5e58
  - xsk: Free skb when TX metadata options are invalid (bsc#1235000
    CVE-2024-53236).
  - commit 488293a
  - ipc: fix memleak if msg_init_ns failed in create_ipc_ns
    (bsc#1234893 CVE-2024-53175).
  - commit ee73306
  - ocfs2: fix uninitialized value in ocfs2_file_read_iter() (CVE-2024-53155 bsc#1234855)
  - commit 29d10db
  - btrfs: add a sanity check for btrfs root in btrfs_search_slot()
    (CVE-2024-56774 bsc#1235653).
  - commit 7fe00e3
  - ocfs2: free inode when ocfs2_get_init_inode() fails (CVE-2024-56630 bsc#1235479)
  - commit 892fcc7
  - ceph: give up on paths longer than PATH_MAX (CVE-2024-53685 bsc#1235720)
  - commit 96cf2d2
  - bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again (CVE-2024-48881 bsc#1235727)
  - commit 7611048
  - vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages() (CVE-2024-56742 bsc#1235613)
  - commit 561ef4c
  - net/smc: check return value of sock_recvmsg when draining clc
    data (CVE-2024-57791 bsc#1235759).
  - commit 3137fae
  - udmabuf: change folios array from kmalloc to kvmalloc (CVE-2024-56544 bsc#1235067)
  - commit e18704f
  - scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb() (CVE-2024-56748 bsc#1235627)
  - commit bf1507f
  - scsi: ufs: core: sysfs: Prevent div by zero (CVE-2024-56622 bsc#1235251)
  - commit e1723b2
  - scsi: ufs: core: Cancel RTC work during ufshcd_remove() (CVE-2024-56621 bsc#1235228)
  - commit dcbc4ba
  - scsi: ufs: qcom: Only free platform MSIs when ESI is enabled (CVE-2024-56620 bsc#1235227)
  - commit a4f3898
  - virt: tdx-guest: Just leak decrypted memory on unrecoverable
    errors (CVE-2024-57793 bsc#1235768).
  - commit 5a20f80
  - stackdepot: fix stack_depot_save_flags() in NMI context
    (CVE-2024-48876 bsc#1235726).
  - commit 21d9f52
  - x86/fred: Clear WFE in missing-ENDBRANCH #CPs (CVE-2024-56761
    bsc#1235633).
  - commit d326277
  - net: ethernet: oa_tc6: fix tx skb race condition between
    reference pointers (CVE-2024-56788 bsc#1235754).
  - tools/net/ynl: fix sub-message key lookup for nested attributes
    (git-fixes).
  - net: tun: fix tun_napi_alloc_frags() (CVE-2024-56372
    bsc#1235753).
  - net: renesas: rswitch: avoid use-after-put for a device tree
    node (CVE-2024-55639 bsc#1235737).
  - commit ab1ee58
  - KVM: SVM: Allow guest writes to set MSR_AMD64_DE_CFG bits
    (bsc#1234635).
  - commit ad88ff2
  - mm/page_alloc: don't call pfn_to_page() on possibly non-existent
    PFN in split_large_buddy() (CVE-2024-57881 bsc#1235843).
  - commit 47fc212
  - Reviewed
    patches.suse/0001-efi-do-not-automatically-generate-secret-key.patch
  - commit 64be71e
  - Reviewed
    patches.suse/0011-PM-hibernate-require-hibernate-snapshot-image-to-be-.patch
  - commit fac3c3b
  - Refresh
    patches.suse/0010-PM-hibernate-a-option-to-request-that-snapshot-image.patch.
    Update config files.
    CONFIG_HIBERNATE_VERIFICATION_FORCE is not set
  - commit d0b09b5
  - Refresh
    patches.suse/0009-PM-hibernate-prevent-EFI-secret-key-to-be-regenerate.patch.
  - commit 38aa2b2

++++ kernel-rt:

  - iommu/tegra241-cmdqv: Fix alignment failure at max_n_shift (CVE-2024-53225 bsc#1235006)
  - commit d17bd9f
  - ring-buffer: Fix overflow in __rb_map_vma (bsc#1235752
    CVE-2024-56368).
  - commit 887043f
  - mm: use aligned address in clear_gigantic_page() (bsc#1235742
    CVE-2024-52319).
  - commit cf2082f
  - netdevsim: prevent bad user input in
    nsim_dev_health_break_write() (bsc#1235587 CVE-2024-56716).
  - commit 64a78e2
  - bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors
    (bsc#1235555 CVE-2024-56675).
  - commit 9dd9586
  - net: netdevsim: fix nsim_pp_hold_write() (bsc#1235554
    CVE-2024-56713).
  - commit 9b9335e
  - mm/gup: handle NULL pages in unpin_user_pages() (bsc#1235388
    CVE-2024-56612).
  - commit 58f5e58
  - xsk: Free skb when TX metadata options are invalid (bsc#1235000
    CVE-2024-53236).
  - commit 488293a
  - ipc: fix memleak if msg_init_ns failed in create_ipc_ns
    (bsc#1234893 CVE-2024-53175).
  - commit ee73306
  - ocfs2: fix uninitialized value in ocfs2_file_read_iter() (CVE-2024-53155 bsc#1234855)
  - commit 29d10db
  - btrfs: add a sanity check for btrfs root in btrfs_search_slot()
    (CVE-2024-56774 bsc#1235653).
  - commit 7fe00e3
  - ocfs2: free inode when ocfs2_get_init_inode() fails (CVE-2024-56630 bsc#1235479)
  - commit 892fcc7
  - ceph: give up on paths longer than PATH_MAX (CVE-2024-53685 bsc#1235720)
  - commit 96cf2d2
  - bcache: revert replacing IS_ERR_OR_NULL with IS_ERR again (CVE-2024-48881 bsc#1235727)
  - commit 7611048
  - vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages() (CVE-2024-56742 bsc#1235613)
  - commit 561ef4c
  - net/smc: check return value of sock_recvmsg when draining clc
    data (CVE-2024-57791 bsc#1235759).
  - commit 3137fae
  - udmabuf: change folios array from kmalloc to kvmalloc (CVE-2024-56544 bsc#1235067)
  - commit e18704f
  - scsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb() (CVE-2024-56748 bsc#1235627)
  - commit bf1507f
  - scsi: ufs: core: sysfs: Prevent div by zero (CVE-2024-56622 bsc#1235251)
  - commit e1723b2
  - scsi: ufs: core: Cancel RTC work during ufshcd_remove() (CVE-2024-56621 bsc#1235228)
  - commit dcbc4ba
  - scsi: ufs: qcom: Only free platform MSIs when ESI is enabled (CVE-2024-56620 bsc#1235227)
  - commit a4f3898
  - virt: tdx-guest: Just leak decrypted memory on unrecoverable
    errors (CVE-2024-57793 bsc#1235768).
  - commit 5a20f80
  - stackdepot: fix stack_depot_save_flags() in NMI context
    (CVE-2024-48876 bsc#1235726).
  - commit 21d9f52
  - x86/fred: Clear WFE in missing-ENDBRANCH #CPs (CVE-2024-56761
    bsc#1235633).
  - commit d326277
  - net: ethernet: oa_tc6: fix tx skb race condition between
    reference pointers (CVE-2024-56788 bsc#1235754).
  - tools/net/ynl: fix sub-message key lookup for nested attributes
    (git-fixes).
  - net: tun: fix tun_napi_alloc_frags() (CVE-2024-56372
    bsc#1235753).
  - net: renesas: rswitch: avoid use-after-put for a device tree
    node (CVE-2024-55639 bsc#1235737).
  - commit ab1ee58
  - KVM: SVM: Allow guest writes to set MSR_AMD64_DE_CFG bits
    (bsc#1234635).
  - commit ad88ff2
  - mm/page_alloc: don't call pfn_to_page() on possibly non-existent
    PFN in split_large_buddy() (CVE-2024-57881 bsc#1235843).
  - commit 47fc212
  - Reviewed
    patches.suse/0001-efi-do-not-automatically-generate-secret-key.patch
  - commit 64be71e
  - Reviewed
    patches.suse/0011-PM-hibernate-require-hibernate-snapshot-image-to-be-.patch
  - commit fac3c3b
  - Refresh
    patches.suse/0010-PM-hibernate-a-option-to-request-that-snapshot-image.patch.
    Update config files.
    CONFIG_HIBERNATE_VERIFICATION_FORCE is not set
  - commit d0b09b5
  - Refresh
    patches.suse/0009-PM-hibernate-prevent-EFI-secret-key-to-be-regenerate.patch.
  - commit 38aa2b2

++++ libsolv:

  - Provide a symbol specific for the ruby-version
    so yast does not break across updates (boo#1235598)

++++ python-charset-normalizer:

  - Use libalternatives instead of update-alternatives, bsc#1235781

++++ python-httpx:

  - Use libalternatives instead of update-alternatives, bsc#1235784
  - don't run tests in strict async mode, upstream doesn't either
  - disable flaky test

++++ python-pyserial:

  - Use libalternatives instead of update-alternatives, bsc#1235782

++++ python-setuptools:

  - Explicitly BuildRequire python-rpm-packaging: when primary flavor
    is added, this is auto-installed by dependencies. But as we now
    build the primary flavor separated, we have to ensure to also
    have it present in the other cases, in order to get the python(abi)
    dependencies added.
  - Split out the primary Python build.

++++ rebootmgr:

  - Update to version 3.0+git20250114.f74a9d5:
    * Add bash-completion for rebootmgrctl

++++ rsync:

  - Backport patch from PR 705 to fix broken handling of hashes and
    hard links:
    * Add 705.patch
  - Update to 3.4
    * Bump to protocol 32
    Drop CVE patches:
    * Drop rsync-gcc14.patch
    * Removed rsync-CVE-2024-12084-overflow-01.patch
    * Removed rsync-CVE-2024-12084-overflow-02.patch
    * Removed rsync-CVE-2024-12085.patch
    * Removed rsync-CVE-2024-12086_01.patch
    * Removed rsync-CVE-2024-12086_02.patch
    * Removed rsync-CVE-2024-12086_03.patch
    * Removed rsync-CVE-2024-12086_04.patch
    * Removed rsync-CVE-2024-12087_01.patch
    * Removed rsync-CVE-2024-12087_02.patch
    * Removed rsync-CVE-2024-12088.patch
    * Removed rsync-CVE-2024-12747.patch

------------------------------------------------------------------
------------------  2025-1-14  -  Jan 14 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Drop still present tox artifacts
    There were still some left over tox files and the
    documentation contribution chapter was also wrong at
    several places

++++ git:

  - update to 2.48.1: (boo#1235600 boo#1235601)
    * CVE-2024-50349, CVE-2024-52006:
    refuse to accept URLs that contain control sequences

++++ gpg2:

  - Update to 2.5.3
    * gpg: Allow for signature subpackets of up to 30000 octets.
    [rG36dbca3e69]
    * gpg: Silence expired trusted-key diagnostics in quiet mode.  [T7351]
    * gpg: Allow smaller session keys with Kyber and enforce the use of
    AES-256 if useful.  [T7472]
    * gpg: Fix regression in key generation from existing card key.
    [T7309,T7457]
    * gpg: Print a warning if the card backup key could not be written.
    [T2169]
    * The --supervised options of gpg-agent and dirmngr have been
    renamed to --deprecated-supervised as preparation for their removal.
    [rGa019a0fcd8]
    * There is no more default for a keyserver.

++++ kernel-default:

  - Revert "block, bfq: merge bfq_release_process_ref() into
    bfq_put_cooperator()" (CVE-2024-53182 bsc#1234946).
  - block: fix uaf for flush rq while iterating tags (CVE-2024-53170
    bsc#1234888).
  - scsi: qedi: Fix a possible memory leak in
    qedi_alloc_and_init_sb() (CVE-2024-56747 bsc#1234934).
  - scsi: bfa: Fix use-after-free in bfad_im_module_exit()
    (CVE-2024-53227 bsc#1235011).
  - scsi: hisi_sas: Create all dump files during debugfs
    initialization (CVE-2024-56588 bsc#1235123).
  - commit d7ec03b
  - smb: client: fix TCP timers deadlock after rmmod (bsc#1235723,
    CVE-2024-54680).
  - commit 067db58
  - x86/cpu: Add Lunar Lake to list of CPUs with a broken MONITOR implementation (jsc#PED-11963).
  - commit 40fc24b
  - scsi: hisi_sas: Add cond_resched() for no forced preemption model (CVE-2024-56589 bsc#1235241)
  - commit 5616a9a
  - Enable CONFIG_BUG_ON_DATA_CORRUPTION (jsc#PED-11849)
  - commit ad832d9
  - arm64: dts: rockchip: add hevc power domain clock to rk3328
    (git-fixes).
  - commit 4ced1a7
  - arm64: dts: rockchip: rename rfkill label for Radxa ROCK 5B
    (git-fixes).
  - commit 1aa0c5f
  - arm64: dts: imx95: correct the address length of
    netcmix_blk_ctrl (git-fixes).
  - commit 261c0be
  - Remove superflous References tags.
  - Refresh
    patches.suse/0001-Lock-down-x86_64-kernel-in-secure-boot-mode-in-subsy.patch.
  - Refresh
    patches.suse/0002-security-Add-a-kernel-lockdown-flag-for-early-boot-s.patch.
  - commit 53733e1
  - arm64: dts: broadcom: Fix L2 linesize for Raspberry Pi 5
    (git-fixes).
  - commit 34dcb38
  - reinstating kABI paddings for crypto
  - commit dcd0a1e
  - Refresh patches.suse/crypto-add-suse_kabi_padding.patch.
  - commit 7e643ee
  - reinstate PCI kABI paddings
  - commit d5bb436
  - Reinstating kABI padding for Thunderbolt
  - commit 13936cf
  - usb: typec: Add attribute file showing the USB Modes of the
    partner (git-fixes).
  - Refresh patches.suse/paddings-add-for-type-C-new-in-SP5.patch.
  - commit 1aae08b
  - Delete patches.suse/btrfs-fix-use-after-free-waiting-for-encoded-read-en.patch (bsc#1235128)
  - commit 6ac27ed
  - Update config files.
    Disable HARDENED_USERCOPY by default but can be re-enabled via the kernel
    command line.
  - commit b89f0e3
  - usb: typec: Add attribute file showing the supported USB modes
    of the port (git-fixes).
  - Refresh patches.suse/paddings-add-for-type-C-new-in-SP5.patch.
  - commit 2fd6860
  - mm: security: Allow default HARDENED_USERCOPY to be set at
    compile time (jsc#PED-11838).
  - mm: security: Move hardened usercopy under 'Kernel hardening
    options' (jsc#PED-11838).
  - commit 6f73ffe
  - usb: typec: ucsi: Fix a missing bits to bytes conversion in
    ucsi_init() (git-fixes).
  - commit 7a60998
  - usb: typec: ucsi: Convert connector specific commands to bitmaps
    (git-fixes).
  - commit 1060e28
  - usb: typec: ucsi: Helper for Get Connector Status command
    (git-fixes).
  - commit 7530947
  - usb: typec: ucsi: Add support for the partner USB Modes
    (git-fixes).
  - commit bb31d21
  - usb: typec: ucsi: Supply the USB capabilities to the ports
    (git-fixes).
  - commit a77d656
  - usb: typec: ucsi: UCSI2.0 Set Sink Path command support
    (git-fixes).
  - commit 0376245
  - usb: typec: ucsi: glink: use device_for_each_child_node_scoped()
    (git-fixes).
  - commit 3691738
  - Refresh
    patches.suse/0008-PM-hibernate-Generate-and-verify-signature-for-snaps.patch.
    Update config files.
    CONFIG_HIBERNATE_VERIFICATION
    CONFIG_EFI_SECRET_KEY
    CONFIG_HIDDEN_AREA
  - commit 4b57a00
  - Refresh
    patches.suse/0007-PM-hibernate-encrypt-hidden-area.patch.
  - commit a1cdd8d
  - Refresh
    patches.suse/0006-efi-allow-user-to-regenerate-secret-key.patch.
  - commit 498aa9e

++++ kernel-default-base:

  - Add virtiofs

++++ kernel-rt:

  - Revert "block, bfq: merge bfq_release_process_ref() into
    bfq_put_cooperator()" (CVE-2024-53182 bsc#1234946).
  - block: fix uaf for flush rq while iterating tags (CVE-2024-53170
    bsc#1234888).
  - scsi: qedi: Fix a possible memory leak in
    qedi_alloc_and_init_sb() (CVE-2024-56747 bsc#1234934).
  - scsi: bfa: Fix use-after-free in bfad_im_module_exit()
    (CVE-2024-53227 bsc#1235011).
  - scsi: hisi_sas: Create all dump files during debugfs
    initialization (CVE-2024-56588 bsc#1235123).
  - commit d7ec03b
  - smb: client: fix TCP timers deadlock after rmmod (bsc#1235723,
    CVE-2024-54680).
  - commit 067db58
  - x86/cpu: Add Lunar Lake to list of CPUs with a broken MONITOR implementation (jsc#PED-11963).
  - commit 40fc24b
  - scsi: hisi_sas: Add cond_resched() for no forced preemption model (CVE-2024-56589 bsc#1235241)
  - commit 5616a9a
  - Enable CONFIG_BUG_ON_DATA_CORRUPTION (jsc#PED-11849)
  - commit ad832d9
  - arm64: dts: rockchip: add hevc power domain clock to rk3328
    (git-fixes).
  - commit 4ced1a7
  - arm64: dts: rockchip: rename rfkill label for Radxa ROCK 5B
    (git-fixes).
  - commit 1aa0c5f
  - arm64: dts: imx95: correct the address length of
    netcmix_blk_ctrl (git-fixes).
  - commit 261c0be
  - Remove superflous References tags.
  - Refresh
    patches.suse/0001-Lock-down-x86_64-kernel-in-secure-boot-mode-in-subsy.patch.
  - Refresh
    patches.suse/0002-security-Add-a-kernel-lockdown-flag-for-early-boot-s.patch.
  - commit 53733e1
  - arm64: dts: broadcom: Fix L2 linesize for Raspberry Pi 5
    (git-fixes).
  - commit 34dcb38
  - reinstating kABI paddings for crypto
  - commit dcd0a1e
  - Refresh patches.suse/crypto-add-suse_kabi_padding.patch.
  - commit 7e643ee
  - reinstate PCI kABI paddings
  - commit d5bb436
  - Reinstating kABI padding for Thunderbolt
  - commit 13936cf
  - usb: typec: Add attribute file showing the USB Modes of the
    partner (git-fixes).
  - Refresh patches.suse/paddings-add-for-type-C-new-in-SP5.patch.
  - commit 1aae08b
  - Delete patches.suse/btrfs-fix-use-after-free-waiting-for-encoded-read-en.patch (bsc#1235128)
  - commit 6ac27ed
  - Update config files.
    Disable HARDENED_USERCOPY by default but can be re-enabled via the kernel
    command line.
  - commit b89f0e3
  - usb: typec: Add attribute file showing the supported USB modes
    of the port (git-fixes).
  - Refresh patches.suse/paddings-add-for-type-C-new-in-SP5.patch.
  - commit 2fd6860
  - mm: security: Allow default HARDENED_USERCOPY to be set at
    compile time (jsc#PED-11838).
  - mm: security: Move hardened usercopy under 'Kernel hardening
    options' (jsc#PED-11838).
  - commit 6f73ffe
  - usb: typec: ucsi: Fix a missing bits to bytes conversion in
    ucsi_init() (git-fixes).
  - commit 7a60998
  - usb: typec: ucsi: Convert connector specific commands to bitmaps
    (git-fixes).
  - commit 1060e28
  - usb: typec: ucsi: Helper for Get Connector Status command
    (git-fixes).
  - commit 7530947
  - usb: typec: ucsi: Add support for the partner USB Modes
    (git-fixes).
  - commit bb31d21
  - usb: typec: ucsi: Supply the USB capabilities to the ports
    (git-fixes).
  - commit a77d656
  - usb: typec: ucsi: UCSI2.0 Set Sink Path command support
    (git-fixes).
  - commit 0376245
  - usb: typec: ucsi: glink: use device_for_each_child_node_scoped()
    (git-fixes).
  - commit 3691738
  - Refresh
    patches.suse/0008-PM-hibernate-Generate-and-verify-signature-for-snaps.patch.
    Update config files.
    CONFIG_HIBERNATE_VERIFICATION
    CONFIG_EFI_SECRET_KEY
    CONFIG_HIDDEN_AREA
  - commit 4b57a00
  - Refresh
    patches.suse/0007-PM-hibernate-encrypt-hidden-area.patch.
  - commit a1cdd8d
  - Refresh
    patches.suse/0006-efi-allow-user-to-regenerate-secret-key.patch.
  - commit 498aa9e

++++ util-linux-systemd:

  - Update to version 2.40.4:
    * agetty: Prevent cursor escape (bsc#1194818, drop
    util-linux-agetty-prevent-cursor-escape.patch)
    add "systemd" to --version output\
    * chcpu(8): Document CPU deconfiguring behavior
    * fdisk: SGI fixes
    * hardlink: fix memory corruption
    * hardlink.1 directory|file is mandatory
    * lib/env: fix env_list_setenv() for strings without '='
    * libblkid:
    (exfat) validate fields used by prober
    (gpt) use blkid_probe_verify_csum() for partition array
    checksum
    add FSLASTBLOCK for swaparea
    bitlocker fix version on big-endian systems
    * libfdisk: make sure libblkid uses the same sector size
    * libmount:
    extract common error handling function
    propagate first error of multiple filesystem types
    * logger: correctly format tv_usec
    * lscpu: Skip aarch64 decode path for rest of the architectures
    (bsc#1229476, drop util-linux-lscpu-skip-aarch64-decode.patch)
    * lsns: ignore ESRCH errors reported when accessing files under
    /proc
    * mkswap: set selinux label also when creating file
    * more: make sure we have data on stderr
    * nsenter: support empty environ
    * umount, losetup: Document loop destroy behavior
    (bsc#1159034, drop
    util-linux-umount-losetup-lazy-destruction.patch,
    util-linux-umount-losetup-lazy-destruction-generated.patch).
    * uuidd: fix /var/lib/libuuid mode uuidd-tmpfiles.conf
    fix /var/lib/libuuid mode uuidd-tmpfiles.conf
    * Many other fixes, improvements and code cleanup. For the
    complete list see
    https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.40/v2.40.3-ReleaseNotes
    https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.40/v2.40.4-ReleaseNotes
  - Refresh util-linux.keyring. Key validity was extended.

++++ at-spi2-core:

  - Update to version 2.55.0.1 (Unstable):
    + Fix regression in 2.55.0 where ungrabbing keys did not work
    reliably.

++++ util-linux:

  - Update to version 2.40.4:
    * agetty: Prevent cursor escape (bsc#1194818, drop
    util-linux-agetty-prevent-cursor-escape.patch)
    add "systemd" to --version output\
    * chcpu(8): Document CPU deconfiguring behavior
    * fdisk: SGI fixes
    * hardlink: fix memory corruption
    * hardlink.1 directory|file is mandatory
    * lib/env: fix env_list_setenv() for strings without '='
    * libblkid:
    (exfat) validate fields used by prober
    (gpt) use blkid_probe_verify_csum() for partition array
    checksum
    add FSLASTBLOCK for swaparea
    bitlocker fix version on big-endian systems
    * libfdisk: make sure libblkid uses the same sector size
    * libmount:
    extract common error handling function
    propagate first error of multiple filesystem types
    * logger: correctly format tv_usec
    * lscpu: Skip aarch64 decode path for rest of the architectures
    (bsc#1229476, drop util-linux-lscpu-skip-aarch64-decode.patch)
    * lsns: ignore ESRCH errors reported when accessing files under
    /proc
    * mkswap: set selinux label also when creating file
    * more: make sure we have data on stderr
    * nsenter: support empty environ
    * umount, losetup: Document loop destroy behavior
    (bsc#1159034, drop
    util-linux-umount-losetup-lazy-destruction.patch,
    util-linux-umount-losetup-lazy-destruction-generated.patch).
    * uuidd: fix /var/lib/libuuid mode uuidd-tmpfiles.conf
    fix /var/lib/libuuid mode uuidd-tmpfiles.conf
    * Many other fixes, improvements and code cleanup. For the
    complete list see
    https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.40/v2.40.3-ReleaseNotes
    https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.40/v2.40.4-ReleaseNotes
  - Refresh util-linux.keyring. Key validity was extended.

++++ libxcrypt:

  - Update to 4.4.38
    * Fix several "-Wunterminated-string-initialization", which are seen by
    upcoming GCC 15.x (issue #194).
    * Fix "-Wmaybe-uninitialized" in crypt.c, which is seen by GCC 13.3.0.
    * Skip test/explicit-bzero if compiling with ASAN.
    * Drop hard requirement for the pkg-config binary (issue #198).
  - Use %ldconfig_scriptlets

++++ sqlite3:

  - Update to release 3.48.0:
    * Improved EXPLAIN QUERY PLAN output for covering indexes.
    * Allow a two-argument version of the iif() SQL function.
    * Also allow if() as an alternative spelling for iif().
    * Add the ".dbtotxt" command to the CLI.
    * Add the SQLITE_IOCAP_SUBPAGE_READ property to the
    xDeviceCharacteristics method of the sqlite3_io_methods object.
    * Add the SQLITE_PREPARE_DONT_LOG option to sqlite3_prepare_v3()
    that prevents warning messages being sent to the error log if
    the SQL is ill-formed. This allows sqlite3_prepare_v3() to be
    used to do test compiles of SQL to check for validity without
    polluting the error log with false messages.
    * Increase the minimum allowed value of SQLITE_LIMIT_LENGTH from
    1 to 30.
    * Added the SQLITE_FCNTL_NULL_IO file control.
    * Extend the FTS5 auxiliary API xInstToken() to work with prefix
    queries via the insttoken configuration option and the
    fts5_insttoken() SQL function.
    * Increase the maximum number of arguments to an SQL function
    from 127 to 1000.
    * Obsoletes sqlite3-6216bfcb.patch .

++++ nvidia-open-driver-G06-signed:

  - Update to 550.144.03 (bsc#1235461, boo#1235871)
    * fixes CVE-2024-0131, CVE-2024-0147, CVE-2024-0149,
    CVE-2024-0150, CVE-2024-53869

++++ opensc:

  - Update to version 0.26.1
    General improvements
    * Align allocations of sc_mem_secure_alloc (#3281).
    * Fix -O3 gcc optimization failure on amd64 and ppc64el (#3299).
    pkcs11-spy
    * Avoid crash while spying C_GetInterface() (#3275).
    TCOS
    * Fix reading certificate (#3296).

++++ ovmf:

  - Update to edk2-stable202411
  - Features (https://github.com/tianocore/edk2/releases):
  - MdeModulePkg: Added PPI support in UFS PEI driver
  - DynamicTablesPkg: Adds SPMI table generator
  - MdeModulePkg: PeiMain: Add Delayed Dispatch PPI Implementation
  - UefiPayloadPkg: Add Secure Boot support
  - MdeModulePkg/TerminalDxe: Add VTUTF8 to Putty function key map
  - DynamicTablesPkg: Adds ACPI HPET table generator
  - Update Openssl 3.0.15
  - DynamicTablesPkg: Adds WSMT generator for X64
  - Enable UPL support for RISC-V
  - Patches (git log --oneline --date-order edk2-stable202408..edk2-stable202411):
    0f3867fa6e UefiPayloadPkg/UefiPayloadEntry: Fix PT protection in 5 level paging
    c28721484d MedModulePkg/DxeIplPeim: Fix pagetable protection region in 5 level paging
    13fad60156 UefiCpuPkg: Fix unchecked returns and potential integer overflows
    843f0c129e Maintainers.txt: Update M and R for UefiCpuPkg and StandaloneMmPkg
    fe1272dc57 NetworkPkg/DxeNetLib: make mSecureHashAlgorithms static
    cd681f5f6a MdePkg/DxeRngLib: make mSecureHashAlgorithms static
    d1c8a88e3b Maintainers.txt: update Leif's email address
    cb87aada97 ArmPlatformPkg: Honour RES1 fields in CPTR_EL2
    1bd09ad193 MdePkg: Define AARCH64_CPTR_RES1 and AARCH64_CPTR_DEFAULT
    ef35863880 ArmPlatformPkg,MdePkg: Rename AARCH64 CPACR_CP_FULL_ACCESS
    6f07aeb49c ArmPlatformPkg: Document that we don't support HCR_EL2.E2H being set
    3299c36ba1 EmulatorPkg WinThunk: Use Win32 API to get Performance Frequency and Count
    e12a8d83fa FatPkg/FatPei: Simplify the GPT Header Check
    ef4f3aa3f7 MdePkg: MdeLibs.dsc.inc: Apwhich are merged to edk2-stable202408:e public Architectural MSRs from MdePkg
    5a73776156 UefiCpuPkg: Use public Architectural MSRs from MdePkg
    961a9e1d76 MdePkg: Added definition of AMD specific public MSRs
    b904377d0d EmbeddedPkg/PrePiHobLib: Remove Non-RT Types from Mem Type Info HOB
    d1372720a8 ArmVirtPkg/MemoryInitPei: Remove Non-RT Types from Mem Type Info HOB
    7da3dcd45d ArmPlatformPkg/MemoryInitPei: Remove Non-RT Types from Mem Type Info HOB
    d8984e86c7 ArmVirtPkg: mark fixed network PCDs
    2ffd6d2e82 OvmfPkg: mark fixed network PCDs
    fc9f06de6f NetworkPkg: mark fixed network PCDs
    9cab9905af ArmVirtPkg: use NetworkDynamicPcds include file
    7ccda1a0b3 OvmfPkg: use NetworkDynamicPcds include file
    1db5895c39 NetworkPkg: introduce include file for dynamic PCDs
    599c8309a5 NetworkPkg/Dhcp6Dxe: Fix sanitizer issues
    171335e34e UefiCpuPkg/MtrrLib: Fix unit test read overflow
    fadf4f377e MdePkg/Test/DevicePathLib: Remove FreePool(NULL)
    d5600f4f5a CryptoPkg/BaseCryptLib: Fix serial number read overrun
    12e1b1f8ef UefiCpuPkg/SecCore: Consume PcdMaxMappingAddressBeforeTempRamExit
    e1b09dfca4 UefiCpuPkg/UefiCpuPkg.dec: Add PcdMaxMappingAddressBeforeTempRamExit
    836942fbad StandaloneMmPkg/MemLib: remove unnecessary check
    da8fd23dbb StandaloneMmPkg/Core: Check Resource HOB and Mmram ranges
    3adb507175 StandaloneMmPkg/Core: add a new InitializeMmHobList()
    d24bb10b1d StandaloneMmPkg/MemLib: Check if the non-MMRAM buffer is valid
    025cec183d StandaloneMmPkg/MemLib: Add an internal header file
    b19f1311d6 StandaloneMmPkg/Core: Remove unneeded check
    734406184f StandaloneMmPkg/MmIpl: Optimize hob pointer check flow
    6f17fe30bf CryptoPkg: Added MM_STANDALONE support in CryptoPkg.
    ccbe6f5030 CryptoPkg: Increase ScratchMemory buffer for openssl 3.0.15
    95d8a1c255 UnitTestFrameworkPkg: Use TianoCore mirror of subhook submodule
    47ba459fc1 CryptoPkg: Updated the missed architectures.
    03d8907321 UefiCpuPkg: Remove AMD 32-bit SMRAM save state map
    b7735a087a MdePkg: CodeQL Fixes.
    a9901a7748 MdeModulePkg: SataControllerSupported checks DevicePath Protocol
    d13f31c3fe UefiPayloadPkg ：ACPI memory node
    60c6486f79 UefiPayloadPkg：Add SMBIOS node.
    de19273e89 UefiPayloadPkg: Modify PCI root reg .
    aac5b3eca3 StandaloneMmPkg/MmIpl: Max physical address bits if disable 5 page level
    79ad703b55 ArmPlatformPkg: CodeQL Fixes.
    7327089f63 ArmVirtPkg: KvmTool: Fix clang linker error
    b72d3495ee MdePkg: Add Google Mock Library for PostCodeLib
    fc6a8bb131 Maintainers: Revert "Remove Ard Biesheuvel from all packages"
    004232c6af UefiCpuPkg/MmUnblockMemoryLib: Check if buffer range is valid
    acce74762b MdeModulePkg: Adding support for authenticated variable storage data format
    56dfab9a8a StandaloneMmPkg/Core: Shadow Standalone BFV into MMRAM
    11d4edc7c6 UefiCpuPkg/PiSmmCpuDxeSmm: Fix extraneous parentheses
    8d74a37944 StandaloneMmPkg/Core: RUpdate openssl library to 3.0.15a in-place option
    8af71632d6 DynamicTablesPkg: Drop the unnecessary comparision of UINT8 max value
    9e56b4373b EmbeddedPkg: Add MDEPKG_NDEBUG to RELEASE build
    8f04804593 EmbeddedPkg: Remove non-needed MDEPKG_NDEBUG dependent code
    051ef932bd BaseTools/GenFw X64: Detect GOTCPRELX relaxations applied by LLD
    9c557575a1 MdePkg/Include/Guid: Fix EFI_CXL_COMPONENT_EVENT_LOG in Cper.h
    4ab8c3cf99 ShellPkg: Updated Type 4 Info as per Smbios 3.8.0
    9dc7fb819c MdePkg: Updated Type 4 Info as per Smbios 3.8.0
    ad522d9609 DynamicTablesPkg: Update X64 FADT XPm1aEvtBlk
    11bd2fa072 Update CI config following CompilerIntrinsicsLib move from ArmPkg
    cb1db8b9b9 DynamicTablesPkg: Update creator id for WSMT table
    7b3969c951 MdeModulePkg UsbNetwork: Use USB class definition from MdePkg
    e2ab098e65 ShellPkg/SmbiosView: Correct wrong length offset usage in SMBIOS Type4
    a19f50bb95 MdePkg/Include/Guid: Rename CXL definitions in Cper.h
    8f84eb0e76 BaseTools: Remove -Wno-unneeded-internal-declaration from CLANGDWARF
    ae83c6b7fd MdePkg: Fix null macros for XCODE5 and CLANG
    6e197a8ba5 MdePkg: Add Google Test Library and Protocol
    866abb2338 MdeModulePkg: Replace rwhich are merged to edk2-stable202408: missing CXL definitions to Cper.h
    79598f34fa MdeModulePkg: PeiMain: Updated dispatcher for delayed dispatch
    d64d1e195c MdeModulePkg: PeiMain: Introduce implementation of delayed dispatch
    b3f36e151d MdePkg: Update Delayed Dispatch PPI as per PI 1.8 A Spec
    e19cc32bce edksetup.sh: Fix the Issue of PYTHON_COMMAND Un-Configurable
    b7342074a6 UnitTestFrameworkPkg: VS2022 Support on UnitTest.
    1b19ccfdfa Add USB Association Descriptor definitions
    d44b82270b ArmPkg: CodeQL Fixes.
    a232e0cd2f UefiCpuPkg/PiSmmCpuDxeSmm: Save and restore CR2 only if SmiProfile enable
    92c1274467 MdePkg: Describe storage location of config tables as per PI 1.7 A spec
    caec6089cf MdePkg: Clarify EFI_MM_SX_DISPATCH_PROTOCOL.Register() as per PI 1.7 A spec
    c80f456ef4 MdePkg: Define PI Specification Version Macro
    b3efbda166 NetworkPkg/HttpBootDxe: Report download error when resume attempts fail
    081cf576a2 DynamicTablesPkg: Update FADT fixed feature flags validation
    21767dcf4e RedfishPkg/RedfishCredentialDxe: Fix 'too many arguments' error
    fcd9570c8d UefiCpuPkg/PiSmmCpuDxeSmm: Consume SmmCpuPlatformHookBeforeMmiHandler func
    e34460c8b2 OvmfPkg/Library: Impl SmmCpuPlatformHookBeforeMmiHandler func
    7d4da670ea UefiCpuPkg: Add SmmCpuPlatformHookBeforeMmiHandler
    2351165f1b UefiCpuPkg/PiSmmCpuDxeSmm: Clarification for BSP & APs Sync Flow
    d2a41d1a7a Maintainers.txt: Update GitHub username for myself
    0bae161fed UefiCpuPkg/MpLib: Remove NotifyOnS3SmmInitDonePpi
    6f17bd5eaf UefiCpuPkg/S3: Skip CR3 modification in S3Resume for 64-bit PEI
    da1c6dd62a UefiPayloadPkg: Add Secure Boot support
    7bac0a940e BaseTools/SetupGit.py: Fix invalid choice 'edk2-test'
    fd619ec460 BaseTools/CodeQl: Give preference to Plugin settings
    06da7daab1 FmpDevicePkg/FmpDependencyLib: Fix potential overflow in loop
    550c38a299 UefiPayloadPkg : Roll back the sequence of gEfiEndOfPeiSignalPpiGuid.
    2ee050d1d5 UnitTestFrameworkPkg: UnitTestLib: Support Failure Strings of 512 Chars
    d99045f392 MdePkg: DebugLib: Check Signature in CR in Release Builds
    77c070b1a7 EmulatorPkg: Add Signature to Graphics Structure
    596773f5e3 DynamicTablesPkg: AmlLib: Fix CodeQL Issue
    80d9b44491 Maintainers.txt: Add myself as UefiPayloadPkg maintainer
    8cce048d48 DynamicTablesPkg: Correct _PSD package format
    54469a6918 ShellPkg: Fix Optional Data rewriting with bcfg
    b21cf3bd5b ShellPkg: ShellLevel2StripQuotes: Strip consecutive quotes
    df884297fd ShellPkg/AcpiView: RASF Parser
    c82bf392c5 ShellPkg/AcpiView: RAS2 Parser - Remove unused define
    91d806917f OvmfPkg: RiscV64: build BaseRiscVFpuLib
    f8c738577f UefiCpuPkg: RiscV64: initialize FPU
    28dd588ca8 MdePkg/BaseLib: RISC-V: Add FPU CSR constants
    7123940665 MdePkg: MdeLibs.dsc.inc: Introduce CUSTOM_STACK_CHECK_LIB Macro
    2fdc39d09d MdeModulePkg/UefiBootManagerLib: Build proper SD/MMC boot descriptions
    f962adc8a0 DynamicTablesPkg: Adds SPMI table generator
    0958b762fb MdePkg/IndustryStandard: Adds SPMI macros
    d2e8118461 StandaloneMmPkg: CodeQL Fixes.
    e73ec56942 MdePkg: Improving readability of CVE patch for PeCoffLoaderRelocateImage
    cac73c45c4 ArmVirtPkg/ArmVirtQemu: avoid unnecessary use of $(ARCH) conditional
    3297be20bb Maintainers.txt: add Leif Lindholm as additional BaseFdtLib maintainer
    eac33b88f4 Maintainers.txt: add all files in BaseFdtLib to component
    9a1d54665c MdePkg: add various additional functions to BaseFdtLib
    450a001c09 MdePkg: export additional Property functions from BaseFdtLib
    5bad560935 MdePkg: export FdtAddressCells/FdtSizeCells from BaseFdtLib
    9ba11ee131 MdePkg: export FdtOpenInto/FdtPack from BaseFdtLib
    9dc9a4bae6 MdePkg: export some additional macros from BaseFdtLib
    0cc9963cc9 MdePkg: align BaseFdtLib function prototypes
    8292296893 MdePkg: add FdtStrerror wrapper to BaseFdtLib
    8040fdbb8b MdePkg: consistently use "Property" in BaseFdtLib
    bf7dbf6380 MdePkg,UefiPayloadPkg: improve BaseFdtLib memreserve helper style
    4f4673846f .github/GitHub.py: Update bot in redundant comment check
    c95233b852 MdePkg: Fix overflow issue in BasePeCoffLib
    517019a553 .gitignore: Ignore Python venv files
    a6b472131e IntelFsp2Pkg : Refactor BaseFspCommonLib to reduce binary size
    21e1fc5400 BaseTools: LinuxGcc5ToolChain: Run for GCC Toolchain
    10783187dd .pytool/UncrustifyCheck: Show errors in output
    48b5815d77 RedfishPkg/Include: add common RedfishPkg header file.
    8b295e0aad NetworkPkg/Dhcp6Dxe: Fix extraneous parentheses
    e548e1cd73 CryptoPkg: Fix unused variable in CryptX509.c
    90fb3c6cfc CryptoPkg/OpensslLib: Fix build on XCODE5
    95292a0f24 MdeModulePkg/VariablePolicyLib: Fix extraneous parentheses
    0aa93aecb7 MdePkg: Fix DEBUG_CODE and PERF_CODE macros for XCODE5
    cc47e82703 BaseTools: Fix redefinition of UINT8_MAX in Decompress.c on XCODE5
    ded3ae2cf4 ArmPkg: drop FdtLib resolution from .dsc
    0693c66f76 EmbeddedPkg: add missing BaseLib/BaseMemoryLib declarations
    dab548a51b ArmVirtPkg: add QemuVirtMemInfoLib missing dependency/includes
    fe93b3745f DynamicTablesPkg/FdtHwInfoParserLib: add missing resolutions/includes
    3ed4f43f83 CryptoPkg: Update generated files based on openssl 3.0.15
    c13f9de56d CryptoPkg: Update openssl submodule to 3.0.15
    2936b7d162 ArmVirtPkg: Correct PcdDxeNxMemoryProtectionPolicy comment
    39462fcd99 openssl: add Library/OpensslLib/openssl to includes, drop e_os.h hack
    67c303cb5f CrtLibSupport: add intptr_t
    c371460cb4 CrtLibSupport: add timezone
    0ec54d8d0c CrtLibSupport: add mktime()
    af73d37741 CrtLibSupport: factor out EFI_TIME -> time_t calculation to new function
    ebf7daa583 CrtLibSupport: fix gettimeofday()
    609c7e8679 CrtLibSupport: add sleep()
    b8122cc9d8 ShellPkg: add missing linefeed in reset message
    a131839a3d FatPkg: Improvements to Fat to Fix File Corruption
    3ef6a71ed1 FatPkg: Check BlockIo Device Has Supported BlockSize
    4c3bffaeb3 UefiPayloadPkg: Enhance ReadMe.md for ELF and FIT
    1a89c690a1 CryptoPkg/OpensslLib: Create SM3-only version of the library
    1815f35b87 CryptoPkg: Add unit testcase for SM3
    89309fee81 CryptoPkg/MbedTls CLANGDWARF: Replace outdated CLANG3x references
    6820004b3e BaseTools: Fix multiple 'invalid escape sequence' warnings in tests
    0354e89fc9 UefiPayloadPkg: Add LOCKBOX_SUPPORT in UPL and set it as FALSE in default
    14bfcc4021 UefiPayloadPkg: Align relocation item with spec
    222e2854fe BaseTools: Update RETURN_ERROR Macro in BaseTypes.h
    c358009352 Set PcdSerialClockRate from SerialPortInfo in UefiPayloadEntry
    3a3b12cbda UefiCpuPkg/MtrrLib: MtrrLibIsMtrrSupported always return FALSE in TD-Guest
    ff8a7d101f Maintainers.txt: Add Sami Mujawar as maintainer for Arm modules
    5901f19a87 DynamicTablesPkg: Adds ACPI SSDT HPET table generator
    fada1cea46 DynamicTablesPkg: Adds ACPI HPET table generator
    21e8a85653 MdeModulePkg/TerminalDxe: Add VTUTF8 to Putty function key map
    170fa8ecd4 BaseTools/tools_def ARM: Disable stack protector with CLANGDWARF
    779642283a Maintainers: Remove Ard Biesheuvel from all packages
    b0d1cb59c7 UefiCpuPkg/AmdSmmCpuFeaturesLib: Skip SMBASE configuration
    670e263419 UefiPayloadPkg: Move FADT check to consumer coode.
    7843c8da06 RedfishPkg/Include: move protocol version definition to protocol header
    be36ddb234 ArmPkg: Avoid building ArmCrashDumpDxe on ARM
    73dbb68006 NetworkPkg/HttpBootDxe: Correctly uninstall HttpBootCallbackProtocol
    1f32b5a30e UefiPayloadPkg: Handle simple reserved ranges from DT
    043045cd6e MdePkg: Add reserved mem fdt helpers
    099aff9137 UefiPayloadPkg: Add support for Root bridge parser
    c511663cfa UefiPayloadPkg: Add support for Special Purpose memory
    5cd9e7ce87 UefiPayloadPkg: Remove unnecessary ACPI checks
    7fdb360046 UefiPayloadPkg: Enable RiscV64 entry point to UPL
    1f4ae34f13 UniversalPayload: Add RISC-V support for UPL PCDs
    9fff9912fd UefiPayloadPkg: Parse fdt and create smbios table
    4d35077048 UefiPayloadPkg: Bugfix: Do not parse NULL nodes
    ed665ef38c UefiPayloadPkg: Handle ordering issue with option node
    121af960e2 OvmfPkg/CpuHotplugSmm: delay SMM exit
    ec18fa81d3 OvmfPkg: Use TdInfo instead of fw_cfg to get cpu count in TDVF
    262ab6259f OvmfPkg/RiscVVirtQemu: Remove non-needed !include line
    273f43cec9 MdePkg/DxeRngLib: Add gEfiRngAlgorithmArmRndr to the secure algorithms
    5ed8f64647 MdePkg/DxeRngLib: Use PcdEnforceSecureRngAlgorithms for default algorithm
    c04c4534c4 MdePkg/DxeRngLib: Refactor Rng algorithm selection
    bc02b255a8 MdePkg: Move PcdEnforceSecureRngAlgorithms from NetworkPkg
    5c8bdb190f MdePkg DebugLib: Enable FILE NAME as DEBUG ASSERT for GCC12
    69139e39bc NetworkPkg/HttpBootDxe: Resume an interrupted boot file download.
    5262108822 MdePkg/Http11.h: Add HTTP header definitions.
    964c22b8ea MdeModulePkg: Fix buffer overflow in MergeMemoryMap
    a9b38305b6 MdePkg: Remove Old Stack Check Lib Implementation
    f53f029122 BaseTools: Add Stack Cookie Support to MSVC and GCC IA32/X64/ARM/AARCH64
    cac0955658 BaseTools: Update Stack Cookie Logic
    5e07b97094 UnitTestFrameworkPkg: Add StackCheckLib
    17744fc9ce UefiPayloadPkg: Add StackCheckLib
    dfc397133b UefiCpuPkg: Add StackCheckLib
    7b4b1d2bd3 StandaloneMmPkg: Add StackCheckLib
    d7a0a7ae4a SourceLevelDebugPkg: Add StackCheckLib
    2e8fb6b406 ShellPkg: Add StackCheckLib
    ce347727a0 SignedCapsulePkg: Add StackCheckLibNull
    7ca87dcc6a SecurityPkg: Add StackCheckLibNull
    78d5d27470 RedfishPkg: Add StackCheckLibNull
    e4c3c3eb65 PrmPkg: Add StackCheckLibNull
    a275f10186 PcAtChipsetPkg: Add StackCheckLib
    538b10f157 OvmfPkg: Add StackCheckLibNull
    fefd017851 NetworkPkg: Add StackCheckLib
    000b61eff8 MdeModulePkg: Add StackCheckLib
    847561eb53 IntelFsp2WrapperPkg: Add StackCheckLib
    254e4cfa8c IntelFsp2Pkg: Add StackCheckLibNull
    715a695c3d FmpDevicePkg: Add StackCheckLibNull
    6f0ba20471 FatPkg: Add StackCheckLibNull
    ae5953dea0 EmulatorPkg: Add StackCheckLibNull
    e7c0ad3661 EmbeddedPkg: Add StackCheckLibNull
    8c21bc7157 DynamicTablesPkg: Add StackCheckLibNull
    c9320adf22 CryptoPkg: Add StackCheckLib
    02e6c73a99 ArmVirtPkg: Add Null Stack Check Lib
    acab6dbf87 ArmPlatformPkg: Add Null Stack Check Lib
    d1faaa8eae ArmPkg: Remove Deprecated Stack Check Lib
    5000568969 MdePkg: Create Stack Check Lib
    ac43bbacde MdePkg: Create Stack Check Null Libs
    3a9da5f329 MdePkg: Add Stack Cookie Interrupt Vector PCD
    26c3818011 UnitTestFrameworkPkg: Move common includes to their own file
    837bb62661 NetworkPkg: PxeBcDhcp6GoogleTest: Fix Stack Smashing Unit Test
    6706fe6e23 ArmPkg/ArmLib: Drop set/way Dcache operations
    bec02ea9de MdePkg/ArmLib: Drop routines that maintain the entire D-cache
    bb403511d4 ArmVirtPkg: Fix unable to build with -D NETWORK_ENABLE=0
    14d7ae94bc OvmfPkg: Fix unable to build OVMF with -D NETWORK_ENABLE=0
    af60615f0e NetworkPkg: Fix unable to build OVMF with -D NETWORK_ENABLE=0
    8f74b95a21 MdePkg: Move CompilerIntrinsicsLib from ArmPkg
    734e71f428 MdePkg: Move AsmMacroIoLib*.h from ArmPkg
    656665d289 ArmPkg: CompilerIntrinsicsLib: Use AsmMacroIoLibV8.h for AARCH64 ASM
    fe6b6feca7 OvmfPkg/LoongArchVirt: Modify loongarch uefi firmware size
    1197fb3383 ShellPkg/AcpiView: RAS2 Parser
    dfc242c2dd MdePkg/Acpi65.h: Add RAS2 table defs and signature as in ACPI 6.5
    babccb841d MdeModulePkg: Enable Data Terminal at end of serial
    bacee5113e MdePkg/IpmiNetFnGroupExtension.h: Enforce structure alignment
    e41e728c16 Refactor SetMemWrapper to reduce binary size
    03c8ec6ce2 MdeModulePkg/DxeCapsuleLibFmp: Check BootService Status to Use ESRT Cache
    dadd8c7a95 MdeModulePkg/DxeCapsuleLibFmp: Change the Event Notify to Cache ESRT Table
    f2557032d6 NetworkPkg/MnpDxe: Convert TX buffer allocation messages to DEBUG_VERBOSE
    589304e67f Support Report Status Code in the UefiPxe driver.
    58b4bf7b7e StandaloneMmPkg/MmIpl: Correct unblocked memory regions attribute
    14c9ba1a2c IntelFsp2Pkg: Support FSP API to save and restore page table
    9a4088777f .pytool/EccCheck: Trim leading path to modified directory
    1328938560 MdeModulePkg/VariableRuntimeDxe: Fix VariablePolicyProtocol PRODUCES
    b1ce2e1b67 ArmPkg/ArmPsciMpServices: GetProcessorInfo copies incorrect structure
    61f9695f20 BaseTools: Remove Pip BaseTools
    3885a3edad NetworkPkg/DxeNetLib: Update misleading comment
    e5715711a4 OvmfPkg/QemuFwCfgS3Lib: Disable S3 detection in TDVF
    043615ae8b MdePkg/BaseLib: Add NULL version Tdx functions for other architectures
    b437b5ca4c UefiCpuPkg/PiSmmCpuDxeSmm: Remove RestrictedMemoryAccess check for MM CPU
    b4820f2d65 UefiCpuPkg/PiSmmCpuDxeSmm: Clean mCpuSmmRestrictedMemoryAccess
    633a755d99 UefiCpuPkg/PiSmmCpuDxeSmm: Update IfReadOnlyPageTableNeeded
    4f6614fc18 UefiCpuPkg/PiSmmCpuDxeSmm: Correct SetPageTableAttributes func usage
    f6eb069e17 UefiCpuPkg/PiSmmCpuDxeSmm: Deadloop if PFAddr is not supported by system
    c8ce84d067 UefiCpuPkg/PiSmmCpuDxeSmm: Always save and restore CR2
    897284d47d UefiCpuPkg/PiSmmCpuDxeSmm: Fix IsSmmCommBufferForbiddenAddress check
    c047353a12 UefiCpuPkg/PiSmmCpuDxeSmm: Avoid to access MCA_CAP if CPU does not support
    253b3d678a MdeModulePkg/Core/Pei: Add error handling for Section Length
    9dabe005f0 MdePkg/IndustryStandard: Add definitions for IPMI Boot Progress Code
    bfb33c0e09 BaseTools: Disable MSVC volatileMetadata for VS2019 and VS2022 for X64
    013d51771a EmbeddedPkg/PrePiHobLib: Fix SetBootMode return value
    1204de7b50 EmbeddedPkg/PrePiHobLib: Align Doxygen comment between code and header
    3151798123 ShellPkg: Acpiview: Add GICC field parsing
    f0dc9e1504 MdeModulePkg: UefiBootManagerLib: Update assert condition
    03bc4252fb XhciDxe: Fail the start of malfunctioning XHCI controllers
    7b9f2018d1 RedfishPkg: PlatformHostInterfaceBmcUsbNicLib: use credential protocol
    7acd8c9bd2 RedfishPkg: PlatformHostInterfaceBmcUsbNicLib: fix compilation warning
    c9a59facd8 RedfishPkg: RedfishDiscoverDxe: fix compilation warning
    2ddce71142 EmulatorPkg: fix X64 Unix/Host segfault with GCC toolchain profile
    99d60cbd39 ArmVirtPkg ARM: Move to MbedTls for crypto
    1240a722f8 SecurityPkg: Tcg2Acpi: Remove _DSM Memory Clear and _PTS
    a4245b265d SecurityPkg: Tcg2Smm: Remove Memory Clear SMI Handler
    559affab2e MdeModulePkg: Fix redundant call to RestoreTpl()
    b17ac09cc4 MdeModulePkg: Add extra RestoreTpl() call in DiskIo
    afba5358c8 ArmVirtPkg: Resolve RngLib via RngDxe for TRNG support
    8504d2be17 MdeModulePkg/FaultTolerantWriteDxe: Fix buffer overrun issue
    1a89d9887f MdePkg:Update Return Error Macro in Base.h
    5bb4f9694a OvmfPkg/PlatformPei: Build gCcEventEntryHobGuid at First
    d997d3c62f OvmfPkg: Use TdHob instead of e820tables to get memory info in TDVF
    e48acc0fa9 ShellPkg/SmbiosView: Add new Socket Type for SMBIOS Type4
    aebe9625c9 MdePkg/SmBios.h: Add new Processor Upgrade definition for SMBIOS Type4
    7f505d377b MdePkg/SmBios.h: Add new Socket Type for SMBIOS Type4
    72cf76868c NetworkPkg/WifiConnectionManagerDxe: Fix Connection Manager HII errors
    cb9bdf3753 SecurityPkg: Optimization by moving PeiServicesLocatePpi outside loop
    a859f4fc03 MdePkg: Fix a buffer overread.
    909849be87 pip-requirements.txt: Bump versions of several packages and fix URL
    f0f14aac3d FatPkg/EnhancedFatDxe: Downgrade debug level for no media found
    5b6ec1a7f4 UefiPayloadPkg/UefiPayloadPkg.ci.yaml: Add PrEval CI config
    d214d75be0 UefiCpuPkg/UefiCpuPkg.ci.yaml: Add PrEval CI config
    6e727ed9dd StandaloneMmPkg/StandaloneMmPkg.ci.yaml: Add PrEval CI config
    7c10472983 SourceLevelDebugPkg/SourceLevelDebugPkg.ci.yaml: Add PrEval CI config
    abf21d76e7 SignedCapsulePkg/SignedCapsulePkg.ci.yaml: Add PrEval CI config
    0cfed09674 ShellPkg/ShellPkg.ci.yaml: Add PrEval CI config
    6ead9a8b80 SecurityPkg/SecurityPkg.ci.yaml: Add PrEval CI config
    89bad0726c PcAtChipsetPkg/PcAtChipsetPkg.ci.yaml: Add PrEval CI config
    ea5581186e NetworkPkg/NetworkPkg.ci.yaml: Add PrEval CI config
    c79487605a EmulatorPkg/EmulatorPkg.ci.yaml: Add PrEval CI config
    2ccf94d37b ArmPlatformPkg/ArmPlatformPkg.ci.yaml: Add PrEval CI config
    715200ea60 ArmPkg/ArmPkg.ci.yaml: Add PrEval CI config
    814470b834 NetworkPkg/SnpDxe: return error for unsupported parameter
    82c5cacd13 NetworkPkg: DxeHttpLib: Use HTTP error 429
    829f773e5c MdePkg: Add HTTP error 429
    eaf78e43f2 MdeModulePkg: Enable VarCheckHiiLibStandaloneMm.
    df58def118 MdeModulePkg: Add VarCheckHiiLibStandaloneMm.
    02f6774803 MdeModulePkg: Move DUMP_VAR_CHECK_HII in common file
    45cf57ce79 MdeModulePkg: Relocate VarCheckHiiInternalDumpHex, VarCheckHiiQuestion
    3956f4e392 MdeModulePkg: Wrap SetVariableCheckHandlerHii as a common API
    db43a80c10 MdeModulePkg: Rename VarCheckHiiLibNullClass as VarCheckHiiLib.
    5718c9b06f MdeModulePkg: Modified BuildVarCheckHiiBin parameter to IN OUT.
    ee1e163a2f MdeModulePkg: Enable VarCheckHiiLibMmDependency
    6b3ac9cbf8 MdeModulePkg: Add VarCheckHiiLibMmDependency library.
    4aea90ea53 MdeModulePkg: Relocation of mVarCheckHiiBin declaration
    238ccc5944 DynamicTablesPkg: Adds generic ACPI Creator ID
    5dafa13d62 DynamicTablesPkg: Adds WSMT generator for X64
    a5f5432728 SecurityPkg: Fix break missing at TPM_ALG_KEYEDHASH case
    50871ee0ec BaseTools: GenMake: FIx missing logs from GenMake.py
    91853ca6a5 MdeModulePkg/VariableStandaloneMm: Notify variable write ready in MM
    af15e4535d ArmPkg: Fix timer wrap-around
    4ef87f455b MdePkg: Add Reset Reason definitions
    f7abf6af2d SecurityPkg: Fix exponent unmarshaled as 16 bits
    96b90e150c SecurityPkg: Measure Invoke EBS even in failure case
    baecba68a3 MdePkg: Remove duplicate source from BaseMemoryLib INF files
    95ee7f3ef7 BaseTools: Trim: Add header/footer for ASL include
    90d861f63d CryptoPkg/BaseCryptLibMbedTls: Fix uninitialized variable errors
    468a36b22f CryptoPkg/OpensslLib CLANGDWARF: Use gnu99 C dialect for asm() support
    5c63e22a9f OvmfPkg: Move kernel hashes section to end
    662272ef41 Sync AARCH64 GCD Capabilities with Page Table
    2069a63a8e OvmfPkg/PlatformInitLib: allow switching to 4-level paging
    f6092b5e2b MdePkg: Remove the old name of LoongArch CSR 0x20
    bc518f81fd OvmfPkg: Using the new name of LoongArch CSR 0x20 register
    2fe24171ac UefiCpuPkg: Using the new name of LoongArch CSR 0x20 register
    a066ca16d3 MdePkg: Rename the LoongArch CSR 0x20 register
    d5c7bba504 StandaloneMmPkg: Restart dispatcher once MM entry is registered for X64
    0b0b7041cc OvmfPkg/OvmfXen: Introduce Xen's ResetSystemLib, to use xen hypercall
    6ed258d89d OvmfPkg/XenHypercallLib: Add SchedOp hypercall
    043eab84e5 OvmfPkg/XenPlatformPei: Remove Hypercall Page
    0e6f6c715c OvmfPkg/XenHypercallLib: Use direct hypercalls
    9d5a9940e4 OvmfPkg: Refactor PcdSetNxForStack usage in TDVF
    a1b0703e8e EmbeddedPkg: Improve LocateAndInstallAcpiFromFvConditional
    5aa6842715 MdeModulePkg/VariableStandaloneMm: Fix TCG MOR secure feature issue
    f31aa47dee MdePkg: CoreValidateHandle Optimization
    0596e5fa05 MdeModulePkg: CoreValidateHandle Optimization
    a63a7dbf85 ArmVirtPkg: Drop incorrect reference to LzmaDecompressLib
    0a6d41ba0a ArmPlatformPkg/ArmPlatformLib: Drop unused MPCore routines
    5c566abb12 ArmVirtPkg/ArmPlatformLib: Drop unused MPCore routines
    5749b70b5a ArmPlatformPkg: Retire PrePi
    029c7a2829 ArmPlatformPkg: Retire PrePeiCore
    76c5f035a1 ArmPlatformPkg: Retire ArmPlatformStackLib
    391666da2c OvmfPkg/QemuVideoDxe: ignore display resolutions smaller than 640x480
    58035e8b5e OvmfPkg/VirtioGpuDxe: ignore display resolutions smaller than 640x480
    6a7be5a841 DynamicTablesPkg: AML code generation for IO resouce descriptor.
    b6c4708c4d MdeModulePkg/Bus/Pci/NvmExpressDxe: Nvm Express Media Sanitize Protocol.
    7801fe428b MdePkg Nvme.h: Update fields from 1.4c specification.
    1169122c6f MdeModulePkg NonDiscoverablePciDeviceIo: MMIO Memory XP By Default
    01735bbe4a MdeModulePkg: Gcd: Only Update gMemoryMap Attributes if Correct GCD Type
    bb248a9509 MdeModulePkg: MAT Set RO/XP on Code/Data Sections Outside Image Memory
    254641f342 MdeModulePkg: MAT: Do Not Set EfiMemoryMappedIo[PortSpace] Attrs
    31f0225005 RedfishPkg/RedfishHttpDxe: check response content type.
    14e6c48103 RedfishPkg/RedfishHttpDxe: add status code check for modification request
    2fe9b6c22f MdePkg:BaseArmTrngLibNull: Assert causing FVP stalling
    383f729ac0 OvmfPkg/PlatformInitLib: Reserve Sec Page Tables in TDVF
    9cd66aca1a CryptoPkg:  Support BrainpoolP512r1 algorithm
    41a51d1735 ArmPkg/GenericWatchdogDxe: Disable WDOG before the protocol installed
    7cde720e51 ShellPkg: Correct smbiosview strings and conditions for SMBIOS Type9
    319835abb8 UefiCpuPkg/MpInitLib: Skip X2APIC enabling when BSP in X2APIC already
    7ed3989166 UefiCpuPkg/MpInitLib: Sync BSP's APIC mode to APs in InitConfig path
    94f68d0b56 UefiCpuPkg/MpInitLib: Separate X2APIC enabling to subfunction
    84e7b74c8c UefiCpuPkg/UefiCpuPkg.dsc: Include PiSmmCpuStandaloneMm and required Libs
    0de7882b46 UefiCpuPkg/PiSmmCpuDxeSmm: Simplify SMM Profile Size Calculation
    2e6ca59e33 UefiCpuPkg/PiSmmCpuDxeSmm: Avoid PcdCpuSmmProfileEnable check in MM
    ae0d54cd43 UefiCpuPkg/PiSmmCpuDxeSmm: Cleanup SMM_CPU_SYNC_MODE
    1816c78f43 UefiCpuPkg/PiSmmCpuDxeSmm: Refine DxeSmm PageTable update logic
    5bcf6049f2 UefiCpuPkg/PiSmmCpuDxeSmm: Add PiSmmCpuStandaloneMm.inf
    3690d30a6e UefiCpuPkg/PiSmmCpuDxeSmm: Check logging PF address for MM
    0593183d76 UefiCpuPkg/PiSmmCpuDxeSmm: Start SMM Profile early for MM
    79468b58c3 UefiCpuPkg/PiSmmCpuDxeSmm: Differentiate PerformRemainingTasks
    268397a892 UefiCpuPkg/PiSmmCpuDxeSmm: Enable CodeAccessCheck in MM Entry Point
    1c19ccd510 UefiCpuPkg/PiSmmCpuDxeSmm: Refactor code to create default Page Table
    14cb36685b UefiCpuPkg/PiSmmCpuDxeSmm: Add PiCpuStandaloneMmEntry for MM
    7b9b4ed57f UefiCpuPkg/PiSmmCpuDxeSmm: Add GetSupportedMaxLogicalProcessorNumber
    167e902624 UefiCpuPkg/PiSmmCpuDxeSmm: Impl IsSmmCommBufferForbiddenAddress for MM
    9ee5334796 UefiCpuPkg/PiSmmCpuDxeSmm: Define mIsStandaloneMm to indicate SMM or MM
    5f88a44637 UefiCpuPkg/PiSmmCpuDxeSmm: Impl GetSmiCommandPort for MM
    ee54bda382 UefiCpuPkg/PiSmmCpuDxeSmm: Impl CreateExtendedProtectionRange for MM
    614d6c91bf UefiCpuPkg/PiSmmCpuDxeSmm: Impl GetSmmCpuSyncConfigData for MM
    1f22b96b11 UefiCpuPkg/PiSmmCpuDxeSmm: Impl GetAcpiS3EnableFlag for MM
    502a9122a4 UefiCpuPkg/PiSmmCpuDxeSmm: Impl GetSmmProfileData for MM
    cc996831bd UefiCpuPkg/PiSmmCpuDxeSmm: Add empty .c for MM CPU specific impl
    9d9bbb6f5f UefiCpuPkg/PiSmmCpuDxeSmm: Move GetSmiCommandPort into DxeSmm Code
    abc2f59523 UefiCpuPkg/PiSmmCpuDxeSmm: Move GetUefiMemoryMap into DxeSmm code
    0c037b5fa7 UefiCpuPkg/PiSmmCpuDxeSmm: Create extended protection MemRegion in func
    d480f106a6 UefiCpuPkg/PiSmmCpuDxeSmm: Get SmmCpuSyncConfig data from func
    23c5ee6e23 UefiCpuPkg/PiSmmCpuDxeSmm: Move GetAcpiS3EnableFlag into DxeSmm code
    5547d1487c UefiCpuPkg/PiSmmCpuDxeSmm: Move SMM profile data allocation into func
    89fe9c5d79 UefiCpuPkg/PiSmmCpuDxeSmm: Use SMM Variable to set SmmProfileBase
    c8a1295d3e UefiCpuPkg/PiSmmCpuDxeSmm: Get SMRAM info from gEfiSmmSmramMemoryGuid
    8ccf7f65e5 UefiCpuPkg/PiSmmCpuDxeSmm: Centralize Non-Mmram Mem Management Code
    cc5df45eb6 UefiCpuPkg/PiSmmCpuDxeSmm: Move common code into PiSmmCpuCommon.c
    cd29383f77 UefiCpuPkg/PiSmmCpuDxeSmm: Rename PiSmmCpuDxeSmm.h to PiSmmCpuCommon.h
    2a15750b79 UefiCpuPkg/PiSmmCpuDxeSmm: Update gSmst to gMmst
    cfaccc89a2 StandaloneMmPkg/Core: Migrate Memory Allocation Hob into MMRAM
    6b69f564a9 StandaloneMmPkg/Core: Add MemoryAttributes support
    b7931cafea StandaloneMmPkg/Core: Install protocol to notify MmEndOfPei event
    c8df60801f StandaloneMmPkg: Support using gEfiSmmSmramMemoryGuid to get MMRAM range
    487fa274c4 StandaloneMmPkg/Core: Restart dispatcher once MmEntryPoint is registered
    003a4d4ef4 StandaloneMmPkg/Core: Remove unused mMmramRanges and mMmramRangeCount
    f0254c9a1c StandaloneMmPkg: Remove definition for MM_CORE_PRIVATE_DATA
    0f89005d71 StandaloneMmMemLib: Drop MM_CORE_PRIVATE_DATA
    189398dcf8 StandaloneMmCoreMemoryAllocationLib: Drop MM_CORE_PRIVATE_DATA
    18591343b2 StandaloneMmPkg/Core: Drop MM_CORE_PRIVATE_DATA
    24e41d1fa3 StandaloneMmPkg/Core: Introduce MM Communication Buffer
    68487b4736 StandaloneMmPkg/Core: Switch to MM HobList after MM HostList is ready
    dd775aa4d4 StandaloneMmPkg/Core: Install Loaded Image Protocol for MM Core
    a44830727a StandaloneMmPkg/Core: Install Loaded Image Protocol for MM drivers
    6dc14fb5b4 StandaloneMmPkg/Core: Remove traditional MM driver support
    6855567d52 StandaloneMmPkg/MmIpl: Create memory resource HOBs
    378aff173c StandaloneMmPkg/MmIpl: Create MM profile data HOBs
    c775cc762e StandaloneMmPkg/MmIpl: Create misc HOBs for CPU
    0d91ebd96f StandaloneMmPkg/MmIpl: Create standalone MM foundation related HOBs
    5aa5ecd5ff StandaloneMmPkg/MmIpl: Dispatch StandaloneMm drivers in MM
    3ac296def1 StandaloneMmPkg/MmIpl: Install end of PEI notify PPI
    e98eca076a StandaloneMmPkg/MmIpl: Install MmCommunicationPpi
    8d764088ea StandaloneMmPkg/MmIpl: load MM Core and execute MM Core in MM RAM
    d7e6b863a1 StandaloneMmPkg/MmIpl: build MM communication buffer HOB
    e363c0b729 StandaloneMmPkg/MmIpl: StandaloneMmIplPei driver entrypoint
    82d2f6b3c3 MdeModulePkg/SmmCommunicationBufferDxe: Re-use FixedCommBuffer
    d64766bde6 StandaloneMmPkg: Create some notification of protocol and Event
    a2a8558958 StandaloneMmPkg: Install gEfiMmCommunicationProtocolGuid
    cf9b568405 StandaloneMmPkg: Install gEfiMmCommunication2ProtocolGuid
    eef29d5100 StandaloneMmPkg: Add a new MmCommunicationDxe driver
    0806fb60d4 StandaloneMmPkg: Create null instance for MmPlatformHobProducerLib
    c0b1ad64e4 UefiCpuPkg: Enable MmUnblockMemoryLib
    8f21911951 UefiCpuPkg: Add MM Unblock Page Library
    630e819bf3 StandaloneMmPkg/StandaloneMmPkg.ci.yaml: Add UefiCpuPkg dependency
    56908fd4be StandaloneMmPkg/StandaloneMmPkg.dec: Add gEventMmDispatchGuid
    43e8801410 StandaloneMmPkg: Add MmPlatformHobProducerLib library class
    0f36b5fa0a UefiCpuPkg: Add ACPI S3 Enable HOB definition
    39d9e15a9e UefiCpuPkg: Add MM CPU Sync Config definitions
    2c5d329e20 UefiCpuPkg: Add MM Profile related definitions
    21a2c8ae2a UefiCpuPkg: Add Unblock Region HOB definition
    45098bf1b8 MdeModulePkg/MdeModulePkg.dec: Add PcdMmCommBufferPages PCD
    ff04469d33 MdeModulePkg: Add MM Communication Buffer definition
    82b1f69196 MdePkg/MdePkg.dec: Add gEfiMmEndOfPeiProtocol definition
    1fd2f9ec8f IntelFsp2Pkg: Align FSP global data pointer for X64 build
    a0ac7cf67a UefiPayloadPkg: Update UefiPayload driver for FDT support.
    0c4d6bb405 UefiPayloadPkg: Update PayloadLoader to suport FDT.
    b0c6b049c4 UefiPayloadPkg: Add FDT Paser relative LIBs.
    a297b81b62 UefiPayloadPkg: Support Debug function when Hob was not available.
    04d8d94a42 UefiPayloadPkg: Addd header files for FDT structure and function.
    c3997e329a MdePkg: Fix build error after enable FDT support.
    90d0ec17e7 MdePkg/BaseFdtLib: Add FdtNodeOffsetByCompatible()
    99e4c8ea93 OvmfPkg/LoongArchVirt: Clear the PGD series registers
    25da777d95 Maintainers.txt: Cleanup inactive maintainers.
    39a999eb1d ArmPlatformPkg: Initialize Serial Port Before Writing
    ded4191e10 Maintainers.txt: Remove Susovan Mohapatra
    cc7bb9a86e IntelFsp2Pkg: Correcting Data Region Length of MCUD section
    a0594ca403 GitHub Action: Bump github/issue-labeler from 3.1 to 3.4
    b2a431868c UefiCpuPkg: CpuPageTableLibTestHost: Disable Random Test Suite
    efaf8931bb OvmfPkg/TdTcg2Dxe: Fix the SeparatorEvent issue in RTMRs
    ccda91c286 MdePkg: Define BrainpoolP512r1
    5a06afa7dd SecurityPkg: Allocate EfiACPIMemoryNVS buffer for TCG2
    fadb9dcb9d SecurityPkg: Correct Pages for TCG2 communication buffer
    0e8af88034 NetworkPkg: Improve GetBootFile() code flow
    f3040bed3c .mergify: Fix pull_request_rules deprecation
    1cc0fae8d9 MdeModulePkg/RamDiskDxe: fix memory leak on error path.
  - Add libbpf1 (libbpf.so.1) as a BuildRequires to satisfy build dependencies.
  - Add ovmf-Revert-Add-Stack-Cookie-Support-to-MSVC-and-GCC.patch (bsc#1236009)
    f53f029122d4 BaseTools: Add Stack Cookie Support to MSVC and GCC IA32/X64/ARM/AARCH64
  - Update openssl library to 3.0.15
  - Remove patch which are merged to edk2-stable202411:
  - ovmf-MdePkg-DebugLib-Enable-FILE-NAME-as-DEBUG-ASSERT-for.patch
    5c8bdb190f MdePkg DebugLib: Enable FILE NAME as DEBUG ASSERT for GCC12

++++ rsync:

  - Security update,CVE-2024-12747, bsc#1235475 race condition in handling symbolic links
    * Added rsync-CVE-2024-12747.patch

++++ velociraptor-client:

  - Update to version 0.7.0.4.git126.27cfbe1:
    * bpf: fix plugins not stopping when context cancelled
    * tcpsnoop: move parsing to its own function
    * bpf plugins: remove depreciated libbpfgo calls
    * bpf plugins: add context to error logs
    * chattrsnoop: fix files not getting closed
    * chattrsnoop: move hashing from plugin to artifact
    * RPM artifact: start checks immediately on artifact load
    * rpm plugin: fix ndb magic error
    * audit s390x: fix arch filter rules errors
    * github: fix deprecated upload artifact
    * tcpsnoop: fix ipv6 local and remote addresses order
    * tcpsnoop: fix missing ipv6 outbound connections
    * Linux.Events.ProcessExecutions: remove parent cmdline
    * audit: reduce FileBufferLeaseSize to ease GC overhead
    * audit: fix auditBuf allocation and go vet warnings
    * audit: fix plugin shutdown race condition
    * audit: fix audit client data races
    * audit: fix race in subscriber
    * audit: prevent Windows loading audit package
    * sdjournal: fix package causing test failures
    * github: run linux unit tests

------------------------------------------------------------------
------------------  2025-1-13  -  Jan 13 2025  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Update to version 2.32.3:
    * ci: update bake-action to v6
    * simplification
    * image can be set to a local ID, that isn't a valid docker ref
    * can't render progress concurrently with buildkit
    * exclude one-off container running convergence
    * Only override service mac if set on the main network.

++++ python-kiwi:

  - Add support for reading optional pkgmgr env file
    If there is a file .kiwi.package_manager.env in the root of
    the image tree it will be read and put into the caller environment for
    the selected package and repository manager. There are features
    in e.g zypper which can only be used via env variables.
    This Fixes bsc#1235448
  - Auto convert unit test XML data to schema v8.3
  - Rename btrfs_root_is_snapshot
    Rename btrfs_root_is_snapshot to btrfs_root_is_snapper_snapshot.
    This happens in preparation for the changes suggested in #2697
    where we want to get rid of snapper specific btrfs code which
    will be available in snapper natively soon. To make sure a btrfs
    layout specific to snapper(and SUSE), the implicitly used attribute
    named btrfs_root_is_snapshot now becomes explicit and its new
    name will indicate that snapper sits behind it. Along with the
    rename a XSLT stylesheet to automatically convert the old name
    into the new name for schema v8.3 will be performed.
  - Bump version: 10.2.5 → 10.2.6

++++ git:

  - update to 2.48.0
    * Reference consistency checks: git refs verify
    * Reflogs can now be migrated with git refs migrate
    * git is free of memory leaks as covered by the test suite
    * Performance improvements
    * Other improvements, UI changes, options extensions and largely
    compatible behavior changes as listed in
    https://raw.githubusercontent.com/git/git/refs/tags/v2.48.0/Documentation/RelNotes/2.48.0.txt

++++ kernel-default:

  - Update
    patches.suse/ACPI-x86-Add-adev-NULL-check-to-acpi_quirk_skip_serd.patch
    (stable-fixes CVE-2024-56782 bsc#1235629).
  - Update
    patches.suse/ALSA-6fire-Release-resources-at-card-release.patch
    (git-fixes CVE-2024-53239 bsc#1235054).
  - Update
    patches.suse/ALSA-caiaq-Use-snd_card_free_when_closed-at-disconne.patch
    (git-fixes CVE-2024-56531 bsc#1235057).
  - Update
    patches.suse/ALSA-control-Avoid-WARN-for-symlink-errors.patch
    (git-fixes CVE-2024-56657 bsc#1235432).
  - Update
    patches.suse/ALSA-core-Fix-possible-NULL-dereference-caused-by-ku.patch
    (git-fixes CVE-2024-56696 bsc#1235539).
  - Update
    patches.suse/ALSA-memalloc-prefer-dma_mapping_error-over-explicit.patch
    (git-fixes CVE-2024-57800 bsc#1235772).
  - Update
    patches.suse/ALSA-pcm-Add-sanity-NULL-check-for-the-default-mmap-.patch
    (stable-fixes CVE-2024-53180 bsc#1234929).
  - Update
    patches.suse/ALSA-us122l-Use-snd_card_free_when_closed-at-disconn.patch
    (git-fixes CVE-2024-56532 bsc#1235059).
  - Update
    patches.suse/ALSA-usb-audio-Fix-out-of-bounds-reads-when-finding-.patch
    (stable-fixes CVE-2024-53150 bsc#1234834).
  - Update
    patches.suse/ALSA-usb-audio-Fix-potential-out-of-bound-accesses-f.patch
    (git-fixes CVE-2024-53197 bsc#1235464).
  - Update
    patches.suse/ALSA-usx2y-Use-snd_card_free_when_closed-at-disconne.patch
    (git-fixes CVE-2024-56533 bsc#1235053).
  - Update
    patches.suse/ASoC-Intel-sof_sdw-Add-space-for-a-terminator-into-D.patch
    (git-fixes CVE-2024-57880 bsc#1235800).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-dai-Do-not-release-the-link-DMA-o.patch
    (git-fixes CVE-2024-57805 bsc#1235790).
  - Update
    patches.suse/ASoC-imx-audmix-Add-NULL-check-in-imx_audmix_probe.patch
    (git-fixes CVE-2024-53199 bsc#1234967).
  - Update
    patches.suse/ASoC-mediatek-Check-num_codecs-is-not-zero-to-avoid-.patch
    (git-fixes CVE-2024-56685 bsc#1235561).
  - Update
    patches.suse/Bluetooth-L2CAP-do-not-leave-dangling-sk-pointer-on-.patch
    (stable-fixes CVE-2024-56605 bsc#1235061).
  - Update patches.suse/Bluetooth-MGMT-Fix-possible-deadlocks.patch
    (git-fixes CVE-2024-53207 bsc#1234907).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-slab-use-after-free-Read-in-set_p.patch
    (git-fixes CVE-2024-53208 bsc#1234909).
  - Update
    patches.suse/Bluetooth-RFCOMM-avoid-leaving-dangling-sk-pointer-i.patch
    (stable-fixes CVE-2024-56604 bsc#1235056).
  - Update
    patches.suse/Bluetooth-btmtk-adjust-the-position-to-init-iso-data.patch
    (git-fixes CVE-2024-53238 bsc#1234910).
  - Update
    patches.suse/Bluetooth-btmtk-avoid-UAF-in-btmtk_process_coredump.patch
    (git-fixes CVE-2024-56653 bsc#1235531).
  - Update
    patches.suse/Bluetooth-btusb-mediatek-add-intf-release-flow-when-.patch
    (stable-fixes CVE-2024-56757 bsc#1235619).
  - Update
    patches.suse/Bluetooth-fix-use-after-free-in-device_for_each_chil.patch
    (git-fixes CVE-2024-53237 bsc#1235007).
  - Update
    patches.suse/Bluetooth-hci_conn-Use-disable_delayed_work_sync.patch
    (stable-fixes CVE-2024-56591 bsc#1235052).
  - Update
    patches.suse/Bluetooth-hci_core-Fix-not-checking-skb-length-on-hc.patch
    (stable-fixes CVE-2024-56590 bsc#1235038).
  - Update
    patches.suse/Bluetooth-hci_event-Fix-using-rcu_read_-un-lock-whil.patch
    (git-fixes CVE-2024-56654 bsc#1235532).
  - Update
    patches.suse/Bluetooth-iso-Always-release-hdev-at-the-end-of-iso_.patch
    (git-fixes CVE-2024-57879 bsc#1235802).
  - Update
    patches.suse/Bluetooth-iso-Fix-circular-lock-in-iso_conn_big_sync.patch
    (git-fixes CVE-2024-54191 bsc#1235717).
  - Update
    patches.suse/Bluetooth-iso-Fix-circular-lock-in-iso_listen_bis.patch
    (git-fixes CVE-2024-54460 bsc#1235722).
  - Update
    patches.suse/HID-wacom-fix-when-get-product-name-maybe-null-point.patch
    (git-fixes CVE-2024-56629 bsc#1235473).
  - Update
    patches.suse/NFSD-Prevent-NULL-dereference-in-nfsd4_process_cb_update.patch
    (git-fixes CVE-2024-53217 bsc#1234999).
  - Update
    patches.suse/NFSD-Prevent-a-potential-integer-overflow.patch
    (git-fixes CVE-2024-53146 bsc#1234853).
  - Update
    patches.suse/NFSv4.0-Fix-a-use-after-free-problem-in-the-asynchronous-open.patch
    (git-fixes CVE-2024-53173 bsc#1234891).
  - Update patches.suse/PCI-Fix-reset_method_store-memory-leak.patch
    (git-fixes CVE-2024-56745 bsc#1235563).
  - Update
    patches.suse/PCI-Fix-use-after-free-of-slot-bus-on-hot-remove.patch
    (stable-fixes CVE-2024-53194 bsc#1235459).
  - Update
    patches.suse/PCI-MSI-Handle-lack-of-irqdomain-gracefully.patch
    (git-fixes CVE-2024-56760 bsc#1235616).
  - Update
    patches.suse/PCI-endpoint-Fix-PCI-domain-ID-release-in-pci_epc_de.patch
    (git-fixes CVE-2024-56561 bsc#1235105).
  - Update
    patches.suse/PCI-endpoint-epf-mhi-Avoid-NULL-dereference-if-DT-la.patch
    (git-fixes CVE-2024-56689 bsc#1235543).
  - Update
    patches.suse/PCI-imx6-Fix-suspend-resume-support-on-i.MX6QDL.patch
    (stable-fixes CVE-2024-57809 bsc#1235793).
  - Update
    patches.suse/PCI-qcom-ep-Move-controller-cleanups-to-qcom_pcie_pe.patch
    (git-fixes CVE-2024-53153 bsc#1234830).
  - Update
    patches.suse/PCI-tegra194-Move-controller-cleanups-to-pex_ep_even.patch
    (git-fixes CVE-2024-53152 bsc#1234841).
  - Update
    patches.suse/RDMA-hns-Fix-cpu-stuck-caused-by-printings-during-re.patch
    (jsc#PED-11250 CVE-2024-56722 bsc#1235570).
  - Update
    patches.suse/RDMA-mlx5-Move-events-notifier-registration-to-be-af.patch
    (git-fixes CVE-2024-53224 bsc#1235009).
  - Update
    patches.suse/RDMA-rxe-Fix-the-qp-flush-warnings-in-req.patch
    (jsc#PED-11323 CVE-2024-53229 bsc#1234905).
  - Update
    patches.suse/SUNRPC-make-sure-cache-entry-active-before-cache_show.patch
    (git-fixes CVE-2024-53174 bsc#1234899).
  - Update
    patches.suse/accel-ivpu-Fix-WARN-in-ivpu_ipc_send_receive_interna.patch
    (git-fixes CVE-2024-54193 bsc#1235713).
  - Update
    patches.suse/accel-ivpu-Fix-general-protection-fault-in-ivpu_bo_l.patch
    (git-fixes CVE-2024-54455 bsc#1235719).
  - Update
    patches.suse/accel-ivpu-Prevent-recovery-invocation-during-probe-.patch
    (git-fixes CVE-2024-56540 bsc#1235063).
  - Update
    patches.suse/acpi-nfit-vmalloc-out-of-bounds-Read-in-acpi_nfit_ct.patch
    (git-fixes CVE-2024-56662 bsc#1235533).
  - Update
    patches.suse/ad7780-fix-division-by-zero-in-ad7780_write_raw.patch
    (git-fixes CVE-2024-56567 bsc#1234916).
  - Update
    patches.suse/af_packet-avoid-erroring-out-after-sock_init_data-in.patch
    (CVE-2024-56606 bsc#123541 bsc#1235417).
  - Update
    patches.suse/apparmor-test-Fix-memory-leak-for-aa_unpack_strdup.patch
    (git-fixes CVE-2024-56741 bsc#1235502).
  - Update
    patches.suse/arm64-ptrace-fix-partial-SETREGSET-for-NT_ARM_FPMR.patch
    (git-fixes CVE-2024-57878 bsc#1235803).
  - Update
    patches.suse/arm64-ptrace-fix-partial-SETREGSET-for-NT_ARM_POE.patch
    (git-fixes CVE-2024-57877 bsc#1235804).
  - Update
    patches.suse/blk-cgroup-Fix-UAF-in-blkcg_unpin_online.patch
    (bsc#1234726 CVE-2024-56672 bsc#1235534).
  - Update
    patches.suse/bnxt_en-Fix-aggregation-ID-mask-to-prevent-oops-on-5.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2024-56656 bsc#1235444).
  - Update
    patches.suse/cacheinfo-Allocate-memory-during-CPU-hotplug-if-not-done-f.patch
    (jsc#PED-10467 CVE-2024-56617 bsc#1235429).
  - Update
    patches.suse/can-dev-can_set_termination-allow-sleeping-GPIOs.patch
    (git-fixes CVE-2024-56625 bsc#1235223).
  - Update
    patches.suse/can-hi311x-hi3110_can_ist-fix-potential-use-after-fr.patch
    (git-fixes CVE-2024-56651 bsc#1235528).
  - Update
    patches.suse/can-j1939-j1939_session_new-fix-skb-reference-counti.patch
    (git-fixes CVE-2024-56645 bsc#1235134).
  - Update
    patches.suse/clk-clk-apple-nco-Add-NULL-check-in-applnco_probe.patch
    (git-fixes CVE-2024-53154 bsc#1234826).
  - Update
    patches.suse/clk-clk-loongson2-Fix-memory-corruption-bug-in-struc.patch
    (git-fixes CVE-2024-53193 bsc#1234902).
  - Update
    patches.suse/clk-clk-loongson2-Fix-potential-buffer-overflow-in-f.patch
    (git-fixes CVE-2024-53192 bsc#1234956).
  - Update
    patches.suse/clk-ralink-mtmips-fix-clocks-probe-order-in-oldest-r.patch
    (git-fixes CVE-2024-53223 bsc#1234976).
  - Update
    patches.suse/crypto-bcm-add-error-check-in-the-ahash_hmac_init-fu.patch
    (git-fixes CVE-2024-56681 bsc#1235557).
  - Update
    patches.suse/crypto-caam-Fix-the-pointer-passed-to-caam_qi_shutdo.patch
    (git-fixes CVE-2024-56754 bsc#1234918).
  - Update
    patches.suse/crypto-pcrypt-Call-crypto-layer-directly-when-padata.patch
    (git-fixes CVE-2024-56690 bsc#1235428).
  - Update
    patches.suse/crypto-qat-qat_420xx-fix-off-by-one-in-uof_get_name.patch
    (git-fixes CVE-2024-53163 bsc#1234828).
  - Update
    patches.suse/crypto-qat-qat_4xxx-fix-off-by-one-in-uof_get_name.patch
    (git-fixes CVE-2024-53162 bsc#1234843).
  - Update
    patches.suse/dlm-fix-dlm_recover_members-refcount-on-error.patch
    (git-fixes CVE-2024-56749 bsc#1235628).
  - Update
    patches.suse/dlm-fix-possible-lkb_resource-null-dereference.patch
    (git-fixes CVE-2024-47809 bsc#1235714).
  - Update
    patches.suse/dma-debug-fix-a-possible-deadlock-on-radix_lock.patch
    (stable-fixes CVE-2024-47143 bsc#1235710).
  - Update
    patches.suse/dmaengine-at_xdmac-avoid-null_prt_deref-in-at_xdmac_.patch
    (git-fixes CVE-2024-56767 bsc#1235160).
  - Update
    patches.suse/drivers-soc-xilinx-add-the-missing-kfree-in-xlnx_add.patch
    (git-fixes CVE-2024-56546 bsc#1235070).
  - Update
    patches.suse/drm-amd-display-Adding-array-index-check-to-prevent-.patch
    (stable-fixes CVE-2024-56784 bsc#1235654).
  - Update
    patches.suse/drm-amd-display-Fix-handling-of-plane-refcount.patch
    (stable-fixes CVE-2024-56775 bsc#1235657).
  - Update
    patches.suse/drm-amd-display-Fix-null-check-for-pipe_ctx-plane_st-2bc96c9.patch
    (git-fixes CVE-2024-53200 bsc#1234968).
  - Update
    patches.suse/drm-amd-display-Fix-null-check-for-pipe_ctx-plane_st.patch
    (git-fixes CVE-2024-53201 bsc#1234969).
  - Update
    patches.suse/drm-amd-display-Fix-out-of-bounds-access-in-dcn21_li.patch
    (stable-fixes CVE-2024-56608 bsc#1235487).
  - Update
    patches.suse/drm-amd-display-fix-a-memleak-issue-when-driver-is-r.patch
    (git-fixes CVE-2024-56542 bsc#1234908).
  - Update
    patches.suse/drm-amdgpu-Fix-the-memory-allocation-issue-in-amdgpu.patch
    (git-fixes CVE-2024-56697 bsc#1235544).
  - Update patches.suse/drm-amdgpu-don-t-access-invalid-sched.patch
    (git-fixes CVE-2024-46896 bsc#1235707).
  - Update patches.suse/drm-amdgpu-fix-usage-slab-after-free.patch
    (stable-fixes CVE-2024-56551 bsc#1235075).
  - Update
    patches.suse/drm-amdgpu-gfx9-Add-Cleaner-Shader-Deinitialization-.patch
    (git-fixes CVE-2024-56753 bsc#1235631).
  - Update
    patches.suse/drm-amdgpu-set-the-right-AMDGPU-sg-segment-limitatio.patch
    (stable-fixes CVE-2024-56594 bsc#1235413).
  - Update
    patches.suse/drm-amdkfd-Dereference-null-return-value.patch
    (git-fixes CVE-2024-56666 bsc#1235242).
  - Update
    patches.suse/drm-amdkfd-Use-dynamic-allocation-for-CU-occupancy-a.patch
    (git-fixes CVE-2024-56695 bsc#1235541).
  - Update
    patches.suse/drm-dp_mst-Fix-MST-sideband-message-body-length-chec.patch
    (stable-fixes CVE-2024-56616 bsc#1235427).
  - Update
    patches.suse/drm-i915-Fix-NULL-pointer-dereference-in-capture_eng.patch
    (git-fixes CVE-2024-56667 bsc#1235016).
  - Update
    patches.suse/drm-modes-Avoid-divide-by-zero-harder-in-drm_mode_vr.patch
    (stable-fixes CVE-2024-56369 bsc#1235750).
  - Update
    patches.suse/drm-nouveau-gr-gf100-Fix-missing-unlock-in-gf100_gr_.patch
    (git-fixes CVE-2024-56752 bsc#1234937).
  - Update
    patches.suse/drm-panel-himax-hx83102-Add-a-check-to-prevent-NULL-.patch
    (git-fixes CVE-2024-56711 bsc#1235562).
  - Update
    patches.suse/drm-sti-avoid-potential-dereference-of-error-pointer-831214f.patch
    (git-fixes CVE-2024-56776 bsc#1235647).
  - Update
    patches.suse/drm-sti-avoid-potential-dereference-of-error-pointer-e965e77.patch
    (git-fixes CVE-2024-56777 bsc#1235641).
  - Update
    patches.suse/drm-sti-avoid-potential-dereference-of-error-pointer.patch
    (git-fixes CVE-2024-56778 bsc#1235635).
  - Update
    patches.suse/drm-vc4-hdmi-Avoid-hang-with-debug-registers-when-su.patch
    (git-fixes CVE-2024-56683 bsc#1235497).
  - Update
    patches.suse/drm-xe-guc_submit-fix-race-around-suspend_pending.patch
    (git-fixes CVE-2024-56552 bsc#1235071).
  - Update patches.suse/drm-xe-reg_sr-Remove-register-pool.patch
    (git-fixes CVE-2024-56652 bsc#1235529).
  - Update
    patches.suse/drm-xlnx-zynqmp_disp-layer-may-be-null-while-releasi.patch
    (git-fixes CVE-2024-56537 bsc#1235049).
  - Update
    patches.suse/drm-zynqmp_kms-Unplug-DRM-device-before-removal.patch
    (git-fixes CVE-2024-56538 bsc#1235051).
  - Update
    patches.suse/efi-libstub-Free-correct-pointer-on-failure.patch
    (git-fixes CVE-2024-56573 bsc#1235042).
  - Update
    patches.suse/erofs-fix-blksize-PAGE_SIZE-for-file-backed-mounts.patch
    (git-fixes CVE-2024-56750 bsc#1235630).
  - Update patches.suse/erofs-fix-file-backed-mounts-over-FUSE.patch
    (git-fixes CVE-2024-53235 bsc#1234998).
  - Update
    patches.suse/erofs-handle-NONHEAD-delta-1-lclusters-gracefully.patch
    (git-fixes CVE-2024-53234 bsc#1235045).
  - Update
    patches.suse/exfat-fix-out-of-bounds-access-of-directory-entries.patch
    (git-fixes CVE-2024-53147 bsc#1234857).
  - Update
    patches.suse/fbdev-sh7760fb-Fix-a-possible-memory-leak-in-sh7760f.patch
    (git-fixes CVE-2024-56746 bsc#1235622).
  - Update
    patches.suse/firmware-arm_scpi-Check-the-DVFS-OPP-count-returned-.patch
    (git-fixes CVE-2024-53157 bsc#1234827).
  - Update
    patches.suse/firmware_loader-Fix-possible-resource-leak-in-fw_log.patch
    (git-fixes CVE-2024-53202 bsc#1234970).
  - Update
    patches.suse/gpio-graniterapids-Fix-vGPIO-driver-crash.patch
    (stable-fixes CVE-2024-56671 bsc#1235018).
  - Update
    patches.suse/gpio-grgpio-Add-NULL-check-in-grgpio_probe.patch
    (git-fixes CVE-2024-56634 bsc#1235486).
  - Update
    patches.suse/i3c-Use-i3cdev-desc-info-instead-of-calling-i3c_devi.patch
    (stable-fixes CVE-2024-43098 bsc#1235703).
  - Update
    patches.suse/i3c-master-Fix-miss-free-init_dyn_addr-at-i3c_master.patch
    (git-fixes CVE-2024-56562 bsc#1234930).
  - Update
    patches.suse/i3c-mipi-i3c-hci-Mask-ring-interrupts-before-ring-st.patch
    (stable-fixes CVE-2024-45828 bsc#1235705).
  - Update
    patches.suse/igb-Fix-potential-invalid-memory-access-in-igb_init_.patch
    (jsc#PED-10426 jsc#PED-10425 CVE-2024-52332 bsc#1235700).
  - Update
    patches.suse/iio-adc-ad7923-Fix-buffer-overflow-for-tx_buf-and-ri.patch
    (git-fixes CVE-2024-56557 bsc#1235122).
  - Update
    patches.suse/io_uring-check-for-overflows-in-io_pin_pages.patch
    (git-fixes CVE-2024-53187 bsc#1234947).
  - Update
    patches.suse/io_uring-check-if-iowq-is-killed-before-queuing.patch
    (git-fixes CVE-2024-56709 bsc#1235552).
  - Update
    patches.suse/io_uring-tctx-work-around-xa_store-allocation-error-.patch
    (git-fixes CVE-2024-56584 bsc#1235117).
  - Update patches.suse/iommu-s390-Implement-blocking-domain.patch
    (git-fixes bsc#1234350 CVE-2024-53232 bsc#1235050).
  - Update
    patches.suse/iommufd-Fix-out_fput-in-iommufd_fault_alloc.patch
    (git-fixes CVE-2024-56624 bsc#1235469).
  - Update
    patches.suse/ionic-Fix-netdev-notifier-unregister-on-failure.patch
    (jsc#PED-11378 CVE-2024-56715 bsc#1235612).
  - Update patches.suse/ionic-no-double-destroy-workqueue.patch
    (jsc#PED-11378 CVE-2024-56714 bsc#1235558).
  - Update
    patches.suse/irqchip-riscv-aplic-Prevent-crash-when-MSI-domain-is.patch
    (git-fixes CVE-2024-56682 bsc#1235559).
  - Update
    patches.suse/kcsan-Turn-report_filterlist_lock-into-a-raw_spinloc.patch
    (stable-fixes CVE-2024-56610 bsc#1235390).
  - Update
    patches.suse/kunit-Fix-potential-null-dereference-in-kunit_device.patch
    (git-fixes CVE-2024-56773 bsc#1235594).
  - Update
    patches.suse/kunit-string-stream-Fix-a-UAF-bug-in-kunit_init_suit.patch
    (git-fixes CVE-2024-56772 bsc#1235651).
  - Update
    patches.suse/leds-class-Protect-brightness_show-with-led_cdev-led.patch
    (stable-fixes CVE-2024-56587 bsc#1235125).
  - Update
    patches.suse/mailbox-mtk-cmdq-fix-wrong-use-of-sizeof-in-cmdq_get.patch
    (git-fixes CVE-2024-56684 bsc#1235560).
  - Update
    patches.suse/media-atomisp-Add-check-for-rgby_data-memory-allocat.patch
    (git-fixes CVE-2024-56705 bsc#1235568).
  - Update
    patches.suse/media-dvb-frontends-dib3000mb-fix-uninit-value-in-di.patch
    (git-fixes CVE-2024-56769 bsc#1235155).
  - Update
    patches.suse/media-i2c-tc358743-Fix-crash-in-the-probe-error-path.patch
    (git-fixes CVE-2024-56576 bsc#1235019).
  - Update
    patches.suse/media-imx-jpeg-Ensure-power-suppliers-be-suspended-b.patch
    (git-fixes CVE-2024-56575 bsc#1235039).
  - Update
    patches.suse/media-imx-jpeg-Set-video-drvdata-before-register-vid.patch
    (git-fixes CVE-2024-56578 bsc#1235115).
  - Update
    patches.suse/media-intel-ipu6-do-not-handle-interrupts-when-devic.patch
    (git-fixes CVE-2024-56680 bsc#1235556).
  - Update
    patches.suse/media-mtk-jpeg-Fix-null-ptr-deref-during-unload-modu.patch
    (git-fixes CVE-2024-56577 bsc#1235112).
  - Update
    patches.suse/media-platform-allegro-dvt-Fix-possible-memory-leak-.patch
    (git-fixes CVE-2024-56572 bsc#1235043).
  - Update
    patches.suse/media-qcom-camss-fix-error-path-on-configuration-of-.patch
    (git-fixes CVE-2024-56580 bsc#1235114).
  - Update
    patches.suse/media-ts2020-fix-null-ptr-deref-in-ts2020_probe.patch
    (git-fixes CVE-2024-56574 bsc#1235040).
  - Update
    patches.suse/media-uvcvideo-Require-entities-to-have-a-non-zero-u.patch
    (git-fixes CVE-2024-56571 bsc#1235037).
  - Update
    patches.suse/media-wl128x-Fix-atomicity-violation-in-fmc_send_cmd.patch
    (git-fixes CVE-2024-56700 bsc#1235500).
  - Update
    patches.suse/mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-PMIC-dev.patch
    (git-fixes CVE-2024-56723 bsc#1235571).
  - Update
    patches.suse/mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-TMU-devi.patch
    (git-fixes CVE-2024-56724 bsc#1235577).
  - Update
    patches.suse/mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-USB-Type.patch
    (git-fixes CVE-2024-56691 bsc#1235425).
  - Update
    patches.suse/msft-hv-3081-hv_sock-Initializing-vsk-trans-to-NULL-to-prevent-a-.patch
    (git-fixes CVE-2024-53103 bsc#1234024).
  - Update
    patches.suse/msft-hv-3082-HID-hyperv-streamline-driver-probe-to-avoid-devres-i.patch
    (git-fixes CVE-2024-56545 bsc#1235069).
  - Update
    patches.suse/msft-hv-3095-Drivers-hv-util-Avoid-accessing-a-ringbuffer-not-ini.patch
    (git-fixes CVE-2024-55916 bsc#1235747).
  - Update
    patches.suse/mtd-rawnand-fix-double-free-in-atmel_pmecc_create_us.patch
    (git-fixes CVE-2024-56766 bsc#1235219).
  - Update
    patches.suse/mtd-spinand-winbond-Fix-512GW-01GW-01JW-and-02JW-ECC.patch
    (git-fixes CVE-2024-56771 bsc#1235649).
  - Update
    patches.suse/net-mlx5-DR-prevent-potential-error-pointer-derefere.patch
    (jsc#PED-11331 CVE-2024-56660 bsc#1235437).
  - Update
    patches.suse/net-usb-lan78xx-Fix-double-free-issue-with-interrupt.patch
    (git-fixes CVE-2024-53213 bsc#1234973).
  - Update
    patches.suse/nfs-blocklayout-Don-t-attempt-unregister-for-invalid-block-device.patch
    (git-fixes CVE-2024-53167 bsc#1234886).
  - Update
    patches.suse/nfs-localio-must-clear-res.replen-in-nfs_local_read_done.patch
    (git-fixes CVE-2024-56740 bsc#1234932).
  - Update
    patches.suse/nfs_common-must-not-hold-RCU-while-calling-nfsd_file_put_local.patch
    (git-fixes CVE-2024-56743 bsc#1235614).
  - Update
    patches.suse/nfsd-fix-nfs4_openowner-leak-when-concurrent-nfsd4_open-occur.patch
    (git-fixes CVE-2024-56779 bsc#1235632).
  - Update
    patches.suse/nfsd-make-sure-exp-active-before-svc_export_show.patch
    (git-fixes CVE-2024-56558 bsc#1235100).
  - Update
    patches.suse/nvme-fabrics-fix-kernel-crash-while-shutting-down-co.patch
    (git-fixes CVE-2024-53169 bsc#1234900).
  - Update
    patches.suse/nvme-pci-fix-freeing-of-the-HMB-descriptor-table.patch
    (git-fixes CVE-2024-56756 bsc#1234922).
  - Update
    patches.suse/nvme-rdma-unquiesce-admin_q-before-destroy-it.patch
    (git-fixes CVE-2024-49569 bsc#1235730).
  - Update
    patches.suse/nvme-tcp-fix-the-memleak-while-create-new-ctrl-faile.patch
    (git-fixes CVE-2024-56632 bsc#1235483).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-cn10.patch
    (jsc#PED-11317 CVE-2024-56726 bsc#1235582).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-69297b0d.patch
    (jsc#PED-11317 CVE-2024-56725 bsc#1235578).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-bd3110bc.patch
    (jsc#PED-11317 CVE-2024-56727 bsc#1235583).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-e26f8eac.patch
    (jsc#PED-11317 CVE-2024-56728 bsc#1235656).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-f5b942e6.patch
    (jsc#PED-11317 CVE-2024-56707 bsc#1235545).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2.patch
    (jsc#PED-11317 CVE-2024-56679 bsc#1235498).
  - Update
    patches.suse/phy-realtek-usb-fix-NULL-deref-in-rtk_usb2phy_probe.patch
    (git-fixes CVE-2024-53205 bsc#1234954).
  - Update
    patches.suse/phy-realtek-usb-fix-NULL-deref-in-rtk_usb3phy_probe.patch
    (git-fixes CVE-2024-53204 bsc#1234955).
  - Update
    patches.suse/phy-rockchip-samsung-hdptx-Set-drvdata-before-enabli.patch
    (git-fixes CVE-2024-57799 bsc#1235770).
  - Update
    patches.suse/pinmux-Use-sequential-access-to-access-desc-pinmux-d.patch
    (stable-fixes CVE-2024-47141 bsc#1235708).
  - Update
    patches.suse/pmdomain-imx-gpcv2-Adjust-delay-after-power-up-hands.patch
    (git-fixes CVE-2024-56618 bsc#1235465).
  - Update
    patches.suse/power-supply-gpio-charger-Fix-set-charge-current-lim.patch
    (git-fixes CVE-2024-57792 bsc#1235764).
  - Update
    patches.suse/powerpc-fadump-Move-fadump_cma_init-to-setup_arch-af.patch
    (bsc#1215199 CVE-2024-56677 bsc#1235494).
  - Update
    patches.suse/powerpc-mm-fault-Fix-kfence-page-fault-reporting.patch
    (bsc#1194869 CVE-2024-56678 bsc#1235495).
  - Update
    patches.suse/powerpc-pseries-Fix-dtl_access_lock-to-be-a-rw_semap.patch
    (bsc#1194869 CVE-2024-56701 bsc#1235496).
  - Update patches.suse/regulator-axp20x-AXP717-set-ramp_delay.patch
    (git-fixes CVE-2024-53682 bsc#1235718).
  - Update
    patches.suse/rtc-check-if-__rtc_read_time-was-successful-in-rtc_t.patch
    (git-fixes CVE-2024-56739 bsc#1235611).
  - Update
    patches.suse/s390-cpum_sf-Fix-and-protect-memory-allocation-of-SDBs-with-mutex.patch
    (git-fixes bsc#1234348 CVE-2024-56706 bsc#1235586).
  - Update
    patches.suse/s390-entry-Mark-IRQ-entries-to-fix-stack-depot-warnings.patch
    (git-fixes bsc#1234356 CVE-2024-57838 bsc#1235798).
  - Update
    patches.suse/s390-iucv-MSG_PEEK-causes-memory-leak-in-iucv_sock_destruct.patch
    (git-fixes bsc#1234351 CVE-2024-53210 bsc#1234971).
  - Update
    patches.suse/s390-pci-Fix-potential-double-remove-of-hotplug-slot.patch
    (git-fixes bsc#1234354 CVE-2024-56699 bsc#1235490).
  - Update
    patches.suse/sched-deadline-Fix-warning-in-migrate_enable-for-boosted-tasks.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2024-56583 bsc#1235118).
  - Update patches.suse/sched-fair-Fix-NEXT_BUDDY.patch (bsc#1234634
    (Scheduler functional and performance backports) CVE-2024-49573
    bsc#1235743).
  - Update patches.suse/sched-fix-warning-in-sched_setaffinity.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2024-41932 bsc#1235699).
  - Update
    patches.suse/scsi-megaraid_sas-Fix-for-a-potential-deadlock.patch
    (jsc#PED-11259 CVE-2024-57807 bsc#1235761).
  - Update
    patches.suse/scsi-qla2xxx-Fix-use-after-free-on-unload.patch
    (bsc#1235406 CVE-2024-56623 bsc#1235466).
  - Update
    patches.suse/soc-imx8m-Probe-the-SoC-driver-as-platform-driver.patch
    (stable-fixes CVE-2024-56787 bsc#1235663).
  - Update
    patches.suse/soc-qcom-geni-se-fix-array-underflow-in-geni_se_clk_.patch
    (git-fixes CVE-2024-53158 bsc#1234811).
  - Update
    patches.suse/spi-mpc52xx-Add-cancel_work_sync-before-module-remov.patch
    (git-fixes CVE-2024-50051 bsc#1235739).
  - Update
    patches.suse/sunrpc-clear-XPRT_SOCK_UPD_TIMEOUT-when-reset-transport.patch
    (git-fixes CVE-2024-56688 bsc#1235538).
  - Update
    patches.suse/sunrpc-fix-one-UAF-issue-caused-by-sunrpc-kernel-tcp-socket.patch
    (git-fixes CVE-2024-53168 bsc#1234887).
  - Update patches.suse/svcrdma-Address-an-integer-overflow.patch
    (git-fixes CVE-2024-53151 bsc#1234829).
  - Update
    patches.suse/svcrdma-fix-miss-destroy-percpu_counter-in-svc_rdma_proc_init.patch
    (git-fixes CVE-2024-53215 bsc#1234962).
  - Update
    patches.suse/thermal-testing-Initialize-some-variables-annoteded-.patch
    (git-fixes CVE-2024-56676 bsc#1235493).
  - Update patches.suse/tipc-fix-NULL-deref-in-cleanup_bearer.patch
    (bsc#1235433 CVE-2024-56661 bsc#1234931).
  - Update patches.suse/unicode-Fix-utf8_load-error-path.patch
    (git-fixes CVE-2024-53233 bsc#1235046).
  - Update
    patches.suse/usb-dwc3-gadget-Fix-looping-of-queued-SG-entries.patch
    (git-fixes CVE-2024-56698 bsc#1235491).
  - Update
    patches.suse/usb-gadget-u_serial-Fix-the-issue-that-gs_start_io-c.patch
    (git-fixes CVE-2024-56670 bsc#1235488).
  - Update
    patches.suse/usb-musb-Fix-hardware-lockup-on-first-Rx-endpoint-re.patch
    (git-fixes CVE-2024-56687 bsc#1235537).
  - Update
    patches.suse/usb-typec-fix-potential-array-underflow-in-ucsi_ccg_.patch
    (git-fixes CVE-2024-53203 bsc#1235001).
  - Update
    patches.suse/usb-typec-ucsi-glink-fix-off-by-one-in-connector_sta.patch
    (git-fixes CVE-2024-53149 bsc#1234842).
  - Update
    patches.suse/wifi-ath10k-avoid-NULL-pointer-error-during-sdio-rem.patch
    (stable-fixes CVE-2024-56599 bsc#1235138).
  - Update
    patches.suse/wifi-ath12k-Skip-Rx-TID-cleanup-for-self-peer.patch
    (git-fixes CVE-2024-56543 bsc#1235065).
  - Update
    patches.suse/wifi-ath12k-fix-atomic-calls-in-ath12k_mac_op_set_bi.patch
    (stable-fixes CVE-2024-56607 bsc#1235423).
  - Update patches.suse/wifi-ath12k-fix-crash-when-unbinding.patch
    (git-fixes CVE-2024-53188 bsc#1234948).
  - Update
    patches.suse/wifi-ath12k-fix-use-after-free-in-ath12k_dp_cc_clean.patch
    (git-fixes CVE-2024-56541 bsc#1235064).
  - Update patches.suse/wifi-ath12k-fix-warning-when-unbinding.patch
    (git-fixes CVE-2024-53191 bsc#1234952).
  - Update
    patches.suse/wifi-ath9k-add-range-check-for-conn_rsp_epid-in-htc_.patch
    (git-fixes CVE-2024-53156 bsc#1234846).
  - Update
    patches.suse/wifi-brcmfmac-Fix-oops-due-to-NULL-pointer-dereferen.patch
    (stable-fixes CVE-2024-56593 bsc#1235252).
  - Update
    patches.suse/wifi-cw1200-Fix-potential-NULL-dereference.patch
    (git-fixes CVE-2024-56536 bsc#1234911).
  - Update
    patches.suse/wifi-mwifiex-Fix-memcpy-field-spanning-write-warning.patch
    (git-fixes CVE-2024-56539 bsc#1234963).
  - Update
    patches.suse/wifi-nl80211-fix-NL80211_ATTR_MLO_LINK_ID-off-by-one.patch
    (git-fixes CVE-2024-56663 bsc#1235454).
  - Update
    patches.suse/wifi-nl80211-fix-bounds-checker-error-in-nl80211_par.patch
    (git-fixes CVE-2024-53189 bsc#1234949).
  - Update
    patches.suse/wifi-rtlwifi-Drastically-reduce-the-attempts-to-read.patch
    (stable-fixes CVE-2024-53190 bsc#1234950).
  - Update
    patches.suse/wifi-rtw88-use-ieee80211_purge_tx_queue-to-purge-TX-.patch
    (stable-fixes CVE-2024-56609 bsc#1235389).
  - Update
    patches.suse/wifi-rtw89-check-return-value-of-ieee80211_probereq_.patch
    (stable-fixes CVE-2024-48873 bsc#1235716).
  - Update
    patches.suse/wifi-rtw89-coex-check-NULL-return-of-kmalloc-in-btc_.patch
    (git-fixes CVE-2024-56535 bsc#1235044).
  - Update
    patches.suse/xfs-unlock-inodes-when-erroring-out-of-xfs_trans_alloc_dir.patch
    (git-fixes CVE-2024-55641 bsc#1235740).
  - commit b21bae3
  - padding for extending cgroup controllers (bsc#1207439).
  - commit 7b2e72c
  - padding for more cgroup controllers (jsc#PED-8461).
  - commit 417e2c0
  - KVM: s390: Reject KVM_SET_GSI_ROUTING on ucontrol VMs (git-fixes
    bsc#1235755).
  - KVM: s390: Reject setting flic pfault attributes on ucontrol
    VMs (git-fixes bsc#1235756).
  - KVM: s390: vsie: fix virtual/physical address in unpin_scb()
    (git-fixes bsc#1235757).
  - commit 25f73de
  - s390x config: IOMMU_DEFAULT_DMA_LAZY=y (bsc#1235646)
  - commit 2199130
  - net: usb: qmi_wwan: add Telit FE910C04 compositions (git-fixes).
  - commit a8a3e1b
  - misc: microchip: pci1xxxx: Resolve return code mismatch during
    GPIO set config (git-fixes).
  - misc: microchip: pci1xxxx: Resolve kernel panic during GPIO
    IRQ handling (git-fixes).
  - interconnect: icc-clk: check return values of devm_kasprintf()
    (git-fixes).
  - interconnect: qcom: icc-rpm: Set the count member before
    accessing the flex array (git-fixes).
  - iio: adc: ti-ads1119: fix sample size in scan struct for
    triggered buffer (git-fixes).
  - iio: inkern: call iio_device_put() only on mapped devices
    (git-fixes).
  - iio: adc: ad9467: Fix the "don't allow reading vref if not
    available" case (git-fixes).
  - iio: adc: at91: call input_free_device() on allocated iio_dev
    (git-fixes).
  - iio: adc: ad7173: fix using shared static info struct
    (git-fixes).
  - iio: adc: ti-ads124s08: Use gpiod_set_value_cansleep()
    (git-fixes).
  - iio: adc: ti-ads1119: fix information leak in triggered buffer
    (git-fixes).
  - iio: pressure: zpa2326: fix information leak in triggered buffer
    (git-fixes).
  - iio: adc: rockchip_saradc: fix information leak in triggered
    buffer (git-fixes).
  - iio: imu: kmx61: fix information leak in triggered buffer
    (git-fixes).
  - iio: light: vcnl4035: fix information leak in triggered buffer
    (git-fixes).
  - iio: light: bh1745: fix information leak in triggered buffer
    (git-fixes).
  - iio: adc: ti-ads8688: fix information leak in triggered buffer
    (git-fixes).
  - iio: dummy: iio_simply_dummy_buffer: fix information leak in
    triggered buffer (git-fixes).
  - iio: test: Fix GTS test config (git-fixes).
  - iio: adc: ti-ads1298: Add NULL check in ads1298_init
    (git-fixes).
  - iio: adc: stm32-dfsdm: handle label as an optional property
    (git-fixes).
  - iio: adc: ad4695: fix buffered read, single sample timings
    (git-fixes).
  - iio: imu: inv_icm42600: fix timestamps after suspend if sensor
    is on (git-fixes).
  - iio: gyro: fxas21002c: Fix missing data update in trigger
    handler (git-fixes).
  - iio: test : check null return of kunit_kmalloc in
    iio_rescale_test_scale (git-fixes).
  - iio: adc: ad7124: Disable all channels at probe time
    (git-fixes).
  - staging: iio: ad9832: Correct phase range check (git-fixes).
  - staging: iio: ad9834: Correct phase range check (git-fixes).
  - usb: typec: fix pm usage counter imbalance in
    ucsi_ccg_sync_control() (git-fixes).
  - usb: gadget: midi2: Reverse-select at the right place
    (git-fixes).
  - usb: gadget: f_fs: Remove WARN_ON in functionfs_bind
    (git-fixes).
  - USB: core: Disable LPM only for non-suspended ports (git-fixes).
  - usb: fix reference leak in usb_new_device() (git-fixes).
  - usb: typec: tcpci: fix NULL pointer issue on shared irq case
    (git-fixes).
  - usb: gadget: u_serial: Disable ep before setting port to null
    to fix the crash caused by port being null (git-fixes).
  - usb: chipidea: ci_hdrc_imx: decrement device's refcount in
    .remove() and in the error path of .probe() (git-fixes).
  - usb: gadget: configfs: Ignore trailing LF for user strings to
    cdev (git-fixes).
  - USB: usblp: return error when setting unsupported protocol
    (git-fixes).
  - usb: gadget: f_uac2: Fix incorrect setting of bNumEndpoints
    (git-fixes).
  - usb: typec: tcpm/tcpci_maxim: fix error code in
    max_contaminant_read_resistance_kohm() (git-fixes).
  - usb: host: xhci-plat: set skip_phy_initialization if software
    node has XHCI_SKIP_PHY_INIT property (git-fixes).
  - usb: dwc3-am62: Disable autosuspend during remove (git-fixes).
  - usb: dwc3: gadget: fix writing NYET threshold (git-fixes).
  - commit 708e579
  - serial: stm32: use port lock wrappers for break control
    (git-fixes).
  - tty: serial: 8250: Fix another runtime PM usage counter
    underflow (git-fixes).
  - commit 2e58518

++++ kernel-firmware-all:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-amdgpu:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-ath10k:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-ath11k:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-ath12k:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-atheros:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-bluetooth:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-bnx2:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-brcm:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-chelsio:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-dpaa2:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-i915:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-intel:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-iwlwifi:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-liquidio:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-marvell:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-media:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-mediatek:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-mellanox:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-mwifiex:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-network:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-nfp:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-nvidia:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-platform:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-prestera:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-qcom:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-qlogic:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-radeon:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-realtek:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-serial:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-sound:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-ti:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-ueagle:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-firmware-usb-network:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

++++ kernel-rt:

  - Update
    patches.suse/ACPI-x86-Add-adev-NULL-check-to-acpi_quirk_skip_serd.patch
    (stable-fixes CVE-2024-56782 bsc#1235629).
  - Update
    patches.suse/ALSA-6fire-Release-resources-at-card-release.patch
    (git-fixes CVE-2024-53239 bsc#1235054).
  - Update
    patches.suse/ALSA-caiaq-Use-snd_card_free_when_closed-at-disconne.patch
    (git-fixes CVE-2024-56531 bsc#1235057).
  - Update
    patches.suse/ALSA-control-Avoid-WARN-for-symlink-errors.patch
    (git-fixes CVE-2024-56657 bsc#1235432).
  - Update
    patches.suse/ALSA-core-Fix-possible-NULL-dereference-caused-by-ku.patch
    (git-fixes CVE-2024-56696 bsc#1235539).
  - Update
    patches.suse/ALSA-memalloc-prefer-dma_mapping_error-over-explicit.patch
    (git-fixes CVE-2024-57800 bsc#1235772).
  - Update
    patches.suse/ALSA-pcm-Add-sanity-NULL-check-for-the-default-mmap-.patch
    (stable-fixes CVE-2024-53180 bsc#1234929).
  - Update
    patches.suse/ALSA-us122l-Use-snd_card_free_when_closed-at-disconn.patch
    (git-fixes CVE-2024-56532 bsc#1235059).
  - Update
    patches.suse/ALSA-usb-audio-Fix-out-of-bounds-reads-when-finding-.patch
    (stable-fixes CVE-2024-53150 bsc#1234834).
  - Update
    patches.suse/ALSA-usb-audio-Fix-potential-out-of-bound-accesses-f.patch
    (git-fixes CVE-2024-53197 bsc#1235464).
  - Update
    patches.suse/ALSA-usx2y-Use-snd_card_free_when_closed-at-disconne.patch
    (git-fixes CVE-2024-56533 bsc#1235053).
  - Update
    patches.suse/ASoC-Intel-sof_sdw-Add-space-for-a-terminator-into-D.patch
    (git-fixes CVE-2024-57880 bsc#1235800).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-dai-Do-not-release-the-link-DMA-o.patch
    (git-fixes CVE-2024-57805 bsc#1235790).
  - Update
    patches.suse/ASoC-imx-audmix-Add-NULL-check-in-imx_audmix_probe.patch
    (git-fixes CVE-2024-53199 bsc#1234967).
  - Update
    patches.suse/ASoC-mediatek-Check-num_codecs-is-not-zero-to-avoid-.patch
    (git-fixes CVE-2024-56685 bsc#1235561).
  - Update
    patches.suse/Bluetooth-L2CAP-do-not-leave-dangling-sk-pointer-on-.patch
    (stable-fixes CVE-2024-56605 bsc#1235061).
  - Update patches.suse/Bluetooth-MGMT-Fix-possible-deadlocks.patch
    (git-fixes CVE-2024-53207 bsc#1234907).
  - Update
    patches.suse/Bluetooth-MGMT-Fix-slab-use-after-free-Read-in-set_p.patch
    (git-fixes CVE-2024-53208 bsc#1234909).
  - Update
    patches.suse/Bluetooth-RFCOMM-avoid-leaving-dangling-sk-pointer-i.patch
    (stable-fixes CVE-2024-56604 bsc#1235056).
  - Update
    patches.suse/Bluetooth-btmtk-adjust-the-position-to-init-iso-data.patch
    (git-fixes CVE-2024-53238 bsc#1234910).
  - Update
    patches.suse/Bluetooth-btmtk-avoid-UAF-in-btmtk_process_coredump.patch
    (git-fixes CVE-2024-56653 bsc#1235531).
  - Update
    patches.suse/Bluetooth-btusb-mediatek-add-intf-release-flow-when-.patch
    (stable-fixes CVE-2024-56757 bsc#1235619).
  - Update
    patches.suse/Bluetooth-fix-use-after-free-in-device_for_each_chil.patch
    (git-fixes CVE-2024-53237 bsc#1235007).
  - Update
    patches.suse/Bluetooth-hci_conn-Use-disable_delayed_work_sync.patch
    (stable-fixes CVE-2024-56591 bsc#1235052).
  - Update
    patches.suse/Bluetooth-hci_core-Fix-not-checking-skb-length-on-hc.patch
    (stable-fixes CVE-2024-56590 bsc#1235038).
  - Update
    patches.suse/Bluetooth-hci_event-Fix-using-rcu_read_-un-lock-whil.patch
    (git-fixes CVE-2024-56654 bsc#1235532).
  - Update
    patches.suse/Bluetooth-iso-Always-release-hdev-at-the-end-of-iso_.patch
    (git-fixes CVE-2024-57879 bsc#1235802).
  - Update
    patches.suse/Bluetooth-iso-Fix-circular-lock-in-iso_conn_big_sync.patch
    (git-fixes CVE-2024-54191 bsc#1235717).
  - Update
    patches.suse/Bluetooth-iso-Fix-circular-lock-in-iso_listen_bis.patch
    (git-fixes CVE-2024-54460 bsc#1235722).
  - Update
    patches.suse/HID-wacom-fix-when-get-product-name-maybe-null-point.patch
    (git-fixes CVE-2024-56629 bsc#1235473).
  - Update
    patches.suse/NFSD-Prevent-NULL-dereference-in-nfsd4_process_cb_update.patch
    (git-fixes CVE-2024-53217 bsc#1234999).
  - Update
    patches.suse/NFSD-Prevent-a-potential-integer-overflow.patch
    (git-fixes CVE-2024-53146 bsc#1234853).
  - Update
    patches.suse/NFSv4.0-Fix-a-use-after-free-problem-in-the-asynchronous-open.patch
    (git-fixes CVE-2024-53173 bsc#1234891).
  - Update patches.suse/PCI-Fix-reset_method_store-memory-leak.patch
    (git-fixes CVE-2024-56745 bsc#1235563).
  - Update
    patches.suse/PCI-Fix-use-after-free-of-slot-bus-on-hot-remove.patch
    (stable-fixes CVE-2024-53194 bsc#1235459).
  - Update
    patches.suse/PCI-MSI-Handle-lack-of-irqdomain-gracefully.patch
    (git-fixes CVE-2024-56760 bsc#1235616).
  - Update
    patches.suse/PCI-endpoint-Fix-PCI-domain-ID-release-in-pci_epc_de.patch
    (git-fixes CVE-2024-56561 bsc#1235105).
  - Update
    patches.suse/PCI-endpoint-epf-mhi-Avoid-NULL-dereference-if-DT-la.patch
    (git-fixes CVE-2024-56689 bsc#1235543).
  - Update
    patches.suse/PCI-imx6-Fix-suspend-resume-support-on-i.MX6QDL.patch
    (stable-fixes CVE-2024-57809 bsc#1235793).
  - Update
    patches.suse/PCI-qcom-ep-Move-controller-cleanups-to-qcom_pcie_pe.patch
    (git-fixes CVE-2024-53153 bsc#1234830).
  - Update
    patches.suse/PCI-tegra194-Move-controller-cleanups-to-pex_ep_even.patch
    (git-fixes CVE-2024-53152 bsc#1234841).
  - Update
    patches.suse/RDMA-hns-Fix-cpu-stuck-caused-by-printings-during-re.patch
    (jsc#PED-11250 CVE-2024-56722 bsc#1235570).
  - Update
    patches.suse/RDMA-mlx5-Move-events-notifier-registration-to-be-af.patch
    (git-fixes CVE-2024-53224 bsc#1235009).
  - Update
    patches.suse/RDMA-rxe-Fix-the-qp-flush-warnings-in-req.patch
    (jsc#PED-11323 CVE-2024-53229 bsc#1234905).
  - Update
    patches.suse/SUNRPC-make-sure-cache-entry-active-before-cache_show.patch
    (git-fixes CVE-2024-53174 bsc#1234899).
  - Update
    patches.suse/accel-ivpu-Fix-WARN-in-ivpu_ipc_send_receive_interna.patch
    (git-fixes CVE-2024-54193 bsc#1235713).
  - Update
    patches.suse/accel-ivpu-Fix-general-protection-fault-in-ivpu_bo_l.patch
    (git-fixes CVE-2024-54455 bsc#1235719).
  - Update
    patches.suse/accel-ivpu-Prevent-recovery-invocation-during-probe-.patch
    (git-fixes CVE-2024-56540 bsc#1235063).
  - Update
    patches.suse/acpi-nfit-vmalloc-out-of-bounds-Read-in-acpi_nfit_ct.patch
    (git-fixes CVE-2024-56662 bsc#1235533).
  - Update
    patches.suse/ad7780-fix-division-by-zero-in-ad7780_write_raw.patch
    (git-fixes CVE-2024-56567 bsc#1234916).
  - Update
    patches.suse/af_packet-avoid-erroring-out-after-sock_init_data-in.patch
    (CVE-2024-56606 bsc#123541 bsc#1235417).
  - Update
    patches.suse/apparmor-test-Fix-memory-leak-for-aa_unpack_strdup.patch
    (git-fixes CVE-2024-56741 bsc#1235502).
  - Update
    patches.suse/arm64-ptrace-fix-partial-SETREGSET-for-NT_ARM_FPMR.patch
    (git-fixes CVE-2024-57878 bsc#1235803).
  - Update
    patches.suse/arm64-ptrace-fix-partial-SETREGSET-for-NT_ARM_POE.patch
    (git-fixes CVE-2024-57877 bsc#1235804).
  - Update
    patches.suse/blk-cgroup-Fix-UAF-in-blkcg_unpin_online.patch
    (bsc#1234726 CVE-2024-56672 bsc#1235534).
  - Update
    patches.suse/bnxt_en-Fix-aggregation-ID-mask-to-prevent-oops-on-5.patch
    (jsc#PED-10684 jsc#PED-11230 CVE-2024-56656 bsc#1235444).
  - Update
    patches.suse/cacheinfo-Allocate-memory-during-CPU-hotplug-if-not-done-f.patch
    (jsc#PED-10467 CVE-2024-56617 bsc#1235429).
  - Update
    patches.suse/can-dev-can_set_termination-allow-sleeping-GPIOs.patch
    (git-fixes CVE-2024-56625 bsc#1235223).
  - Update
    patches.suse/can-hi311x-hi3110_can_ist-fix-potential-use-after-fr.patch
    (git-fixes CVE-2024-56651 bsc#1235528).
  - Update
    patches.suse/can-j1939-j1939_session_new-fix-skb-reference-counti.patch
    (git-fixes CVE-2024-56645 bsc#1235134).
  - Update
    patches.suse/clk-clk-apple-nco-Add-NULL-check-in-applnco_probe.patch
    (git-fixes CVE-2024-53154 bsc#1234826).
  - Update
    patches.suse/clk-clk-loongson2-Fix-memory-corruption-bug-in-struc.patch
    (git-fixes CVE-2024-53193 bsc#1234902).
  - Update
    patches.suse/clk-clk-loongson2-Fix-potential-buffer-overflow-in-f.patch
    (git-fixes CVE-2024-53192 bsc#1234956).
  - Update
    patches.suse/clk-ralink-mtmips-fix-clocks-probe-order-in-oldest-r.patch
    (git-fixes CVE-2024-53223 bsc#1234976).
  - Update
    patches.suse/crypto-bcm-add-error-check-in-the-ahash_hmac_init-fu.patch
    (git-fixes CVE-2024-56681 bsc#1235557).
  - Update
    patches.suse/crypto-caam-Fix-the-pointer-passed-to-caam_qi_shutdo.patch
    (git-fixes CVE-2024-56754 bsc#1234918).
  - Update
    patches.suse/crypto-pcrypt-Call-crypto-layer-directly-when-padata.patch
    (git-fixes CVE-2024-56690 bsc#1235428).
  - Update
    patches.suse/crypto-qat-qat_420xx-fix-off-by-one-in-uof_get_name.patch
    (git-fixes CVE-2024-53163 bsc#1234828).
  - Update
    patches.suse/crypto-qat-qat_4xxx-fix-off-by-one-in-uof_get_name.patch
    (git-fixes CVE-2024-53162 bsc#1234843).
  - Update
    patches.suse/dlm-fix-dlm_recover_members-refcount-on-error.patch
    (git-fixes CVE-2024-56749 bsc#1235628).
  - Update
    patches.suse/dlm-fix-possible-lkb_resource-null-dereference.patch
    (git-fixes CVE-2024-47809 bsc#1235714).
  - Update
    patches.suse/dma-debug-fix-a-possible-deadlock-on-radix_lock.patch
    (stable-fixes CVE-2024-47143 bsc#1235710).
  - Update
    patches.suse/dmaengine-at_xdmac-avoid-null_prt_deref-in-at_xdmac_.patch
    (git-fixes CVE-2024-56767 bsc#1235160).
  - Update
    patches.suse/drivers-soc-xilinx-add-the-missing-kfree-in-xlnx_add.patch
    (git-fixes CVE-2024-56546 bsc#1235070).
  - Update
    patches.suse/drm-amd-display-Adding-array-index-check-to-prevent-.patch
    (stable-fixes CVE-2024-56784 bsc#1235654).
  - Update
    patches.suse/drm-amd-display-Fix-handling-of-plane-refcount.patch
    (stable-fixes CVE-2024-56775 bsc#1235657).
  - Update
    patches.suse/drm-amd-display-Fix-null-check-for-pipe_ctx-plane_st-2bc96c9.patch
    (git-fixes CVE-2024-53200 bsc#1234968).
  - Update
    patches.suse/drm-amd-display-Fix-null-check-for-pipe_ctx-plane_st.patch
    (git-fixes CVE-2024-53201 bsc#1234969).
  - Update
    patches.suse/drm-amd-display-Fix-out-of-bounds-access-in-dcn21_li.patch
    (stable-fixes CVE-2024-56608 bsc#1235487).
  - Update
    patches.suse/drm-amd-display-fix-a-memleak-issue-when-driver-is-r.patch
    (git-fixes CVE-2024-56542 bsc#1234908).
  - Update
    patches.suse/drm-amdgpu-Fix-the-memory-allocation-issue-in-amdgpu.patch
    (git-fixes CVE-2024-56697 bsc#1235544).
  - Update patches.suse/drm-amdgpu-don-t-access-invalid-sched.patch
    (git-fixes CVE-2024-46896 bsc#1235707).
  - Update patches.suse/drm-amdgpu-fix-usage-slab-after-free.patch
    (stable-fixes CVE-2024-56551 bsc#1235075).
  - Update
    patches.suse/drm-amdgpu-gfx9-Add-Cleaner-Shader-Deinitialization-.patch
    (git-fixes CVE-2024-56753 bsc#1235631).
  - Update
    patches.suse/drm-amdgpu-set-the-right-AMDGPU-sg-segment-limitatio.patch
    (stable-fixes CVE-2024-56594 bsc#1235413).
  - Update
    patches.suse/drm-amdkfd-Dereference-null-return-value.patch
    (git-fixes CVE-2024-56666 bsc#1235242).
  - Update
    patches.suse/drm-amdkfd-Use-dynamic-allocation-for-CU-occupancy-a.patch
    (git-fixes CVE-2024-56695 bsc#1235541).
  - Update
    patches.suse/drm-dp_mst-Fix-MST-sideband-message-body-length-chec.patch
    (stable-fixes CVE-2024-56616 bsc#1235427).
  - Update
    patches.suse/drm-i915-Fix-NULL-pointer-dereference-in-capture_eng.patch
    (git-fixes CVE-2024-56667 bsc#1235016).
  - Update
    patches.suse/drm-modes-Avoid-divide-by-zero-harder-in-drm_mode_vr.patch
    (stable-fixes CVE-2024-56369 bsc#1235750).
  - Update
    patches.suse/drm-nouveau-gr-gf100-Fix-missing-unlock-in-gf100_gr_.patch
    (git-fixes CVE-2024-56752 bsc#1234937).
  - Update
    patches.suse/drm-panel-himax-hx83102-Add-a-check-to-prevent-NULL-.patch
    (git-fixes CVE-2024-56711 bsc#1235562).
  - Update
    patches.suse/drm-sti-avoid-potential-dereference-of-error-pointer-831214f.patch
    (git-fixes CVE-2024-56776 bsc#1235647).
  - Update
    patches.suse/drm-sti-avoid-potential-dereference-of-error-pointer-e965e77.patch
    (git-fixes CVE-2024-56777 bsc#1235641).
  - Update
    patches.suse/drm-sti-avoid-potential-dereference-of-error-pointer.patch
    (git-fixes CVE-2024-56778 bsc#1235635).
  - Update
    patches.suse/drm-vc4-hdmi-Avoid-hang-with-debug-registers-when-su.patch
    (git-fixes CVE-2024-56683 bsc#1235497).
  - Update
    patches.suse/drm-xe-guc_submit-fix-race-around-suspend_pending.patch
    (git-fixes CVE-2024-56552 bsc#1235071).
  - Update patches.suse/drm-xe-reg_sr-Remove-register-pool.patch
    (git-fixes CVE-2024-56652 bsc#1235529).
  - Update
    patches.suse/drm-xlnx-zynqmp_disp-layer-may-be-null-while-releasi.patch
    (git-fixes CVE-2024-56537 bsc#1235049).
  - Update
    patches.suse/drm-zynqmp_kms-Unplug-DRM-device-before-removal.patch
    (git-fixes CVE-2024-56538 bsc#1235051).
  - Update
    patches.suse/efi-libstub-Free-correct-pointer-on-failure.patch
    (git-fixes CVE-2024-56573 bsc#1235042).
  - Update
    patches.suse/erofs-fix-blksize-PAGE_SIZE-for-file-backed-mounts.patch
    (git-fixes CVE-2024-56750 bsc#1235630).
  - Update patches.suse/erofs-fix-file-backed-mounts-over-FUSE.patch
    (git-fixes CVE-2024-53235 bsc#1234998).
  - Update
    patches.suse/erofs-handle-NONHEAD-delta-1-lclusters-gracefully.patch
    (git-fixes CVE-2024-53234 bsc#1235045).
  - Update
    patches.suse/exfat-fix-out-of-bounds-access-of-directory-entries.patch
    (git-fixes CVE-2024-53147 bsc#1234857).
  - Update
    patches.suse/fbdev-sh7760fb-Fix-a-possible-memory-leak-in-sh7760f.patch
    (git-fixes CVE-2024-56746 bsc#1235622).
  - Update
    patches.suse/firmware-arm_scpi-Check-the-DVFS-OPP-count-returned-.patch
    (git-fixes CVE-2024-53157 bsc#1234827).
  - Update
    patches.suse/firmware_loader-Fix-possible-resource-leak-in-fw_log.patch
    (git-fixes CVE-2024-53202 bsc#1234970).
  - Update
    patches.suse/gpio-graniterapids-Fix-vGPIO-driver-crash.patch
    (stable-fixes CVE-2024-56671 bsc#1235018).
  - Update
    patches.suse/gpio-grgpio-Add-NULL-check-in-grgpio_probe.patch
    (git-fixes CVE-2024-56634 bsc#1235486).
  - Update
    patches.suse/i3c-Use-i3cdev-desc-info-instead-of-calling-i3c_devi.patch
    (stable-fixes CVE-2024-43098 bsc#1235703).
  - Update
    patches.suse/i3c-master-Fix-miss-free-init_dyn_addr-at-i3c_master.patch
    (git-fixes CVE-2024-56562 bsc#1234930).
  - Update
    patches.suse/i3c-mipi-i3c-hci-Mask-ring-interrupts-before-ring-st.patch
    (stable-fixes CVE-2024-45828 bsc#1235705).
  - Update
    patches.suse/igb-Fix-potential-invalid-memory-access-in-igb_init_.patch
    (jsc#PED-10426 jsc#PED-10425 CVE-2024-52332 bsc#1235700).
  - Update
    patches.suse/iio-adc-ad7923-Fix-buffer-overflow-for-tx_buf-and-ri.patch
    (git-fixes CVE-2024-56557 bsc#1235122).
  - Update
    patches.suse/io_uring-check-for-overflows-in-io_pin_pages.patch
    (git-fixes CVE-2024-53187 bsc#1234947).
  - Update
    patches.suse/io_uring-check-if-iowq-is-killed-before-queuing.patch
    (git-fixes CVE-2024-56709 bsc#1235552).
  - Update
    patches.suse/io_uring-tctx-work-around-xa_store-allocation-error-.patch
    (git-fixes CVE-2024-56584 bsc#1235117).
  - Update patches.suse/iommu-s390-Implement-blocking-domain.patch
    (git-fixes bsc#1234350 CVE-2024-53232 bsc#1235050).
  - Update
    patches.suse/iommufd-Fix-out_fput-in-iommufd_fault_alloc.patch
    (git-fixes CVE-2024-56624 bsc#1235469).
  - Update
    patches.suse/ionic-Fix-netdev-notifier-unregister-on-failure.patch
    (jsc#PED-11378 CVE-2024-56715 bsc#1235612).
  - Update patches.suse/ionic-no-double-destroy-workqueue.patch
    (jsc#PED-11378 CVE-2024-56714 bsc#1235558).
  - Update
    patches.suse/irqchip-riscv-aplic-Prevent-crash-when-MSI-domain-is.patch
    (git-fixes CVE-2024-56682 bsc#1235559).
  - Update
    patches.suse/kcsan-Turn-report_filterlist_lock-into-a-raw_spinloc.patch
    (stable-fixes CVE-2024-56610 bsc#1235390).
  - Update
    patches.suse/kunit-Fix-potential-null-dereference-in-kunit_device.patch
    (git-fixes CVE-2024-56773 bsc#1235594).
  - Update
    patches.suse/kunit-string-stream-Fix-a-UAF-bug-in-kunit_init_suit.patch
    (git-fixes CVE-2024-56772 bsc#1235651).
  - Update
    patches.suse/leds-class-Protect-brightness_show-with-led_cdev-led.patch
    (stable-fixes CVE-2024-56587 bsc#1235125).
  - Update
    patches.suse/mailbox-mtk-cmdq-fix-wrong-use-of-sizeof-in-cmdq_get.patch
    (git-fixes CVE-2024-56684 bsc#1235560).
  - Update
    patches.suse/media-atomisp-Add-check-for-rgby_data-memory-allocat.patch
    (git-fixes CVE-2024-56705 bsc#1235568).
  - Update
    patches.suse/media-dvb-frontends-dib3000mb-fix-uninit-value-in-di.patch
    (git-fixes CVE-2024-56769 bsc#1235155).
  - Update
    patches.suse/media-i2c-tc358743-Fix-crash-in-the-probe-error-path.patch
    (git-fixes CVE-2024-56576 bsc#1235019).
  - Update
    patches.suse/media-imx-jpeg-Ensure-power-suppliers-be-suspended-b.patch
    (git-fixes CVE-2024-56575 bsc#1235039).
  - Update
    patches.suse/media-imx-jpeg-Set-video-drvdata-before-register-vid.patch
    (git-fixes CVE-2024-56578 bsc#1235115).
  - Update
    patches.suse/media-intel-ipu6-do-not-handle-interrupts-when-devic.patch
    (git-fixes CVE-2024-56680 bsc#1235556).
  - Update
    patches.suse/media-mtk-jpeg-Fix-null-ptr-deref-during-unload-modu.patch
    (git-fixes CVE-2024-56577 bsc#1235112).
  - Update
    patches.suse/media-platform-allegro-dvt-Fix-possible-memory-leak-.patch
    (git-fixes CVE-2024-56572 bsc#1235043).
  - Update
    patches.suse/media-qcom-camss-fix-error-path-on-configuration-of-.patch
    (git-fixes CVE-2024-56580 bsc#1235114).
  - Update
    patches.suse/media-ts2020-fix-null-ptr-deref-in-ts2020_probe.patch
    (git-fixes CVE-2024-56574 bsc#1235040).
  - Update
    patches.suse/media-uvcvideo-Require-entities-to-have-a-non-zero-u.patch
    (git-fixes CVE-2024-56571 bsc#1235037).
  - Update
    patches.suse/media-wl128x-Fix-atomicity-violation-in-fmc_send_cmd.patch
    (git-fixes CVE-2024-56700 bsc#1235500).
  - Update
    patches.suse/mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-PMIC-dev.patch
    (git-fixes CVE-2024-56723 bsc#1235571).
  - Update
    patches.suse/mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-TMU-devi.patch
    (git-fixes CVE-2024-56724 bsc#1235577).
  - Update
    patches.suse/mfd-intel_soc_pmic_bxtwc-Use-IRQ-domain-for-USB-Type.patch
    (git-fixes CVE-2024-56691 bsc#1235425).
  - Update
    patches.suse/msft-hv-3081-hv_sock-Initializing-vsk-trans-to-NULL-to-prevent-a-.patch
    (git-fixes CVE-2024-53103 bsc#1234024).
  - Update
    patches.suse/msft-hv-3082-HID-hyperv-streamline-driver-probe-to-avoid-devres-i.patch
    (git-fixes CVE-2024-56545 bsc#1235069).
  - Update
    patches.suse/msft-hv-3095-Drivers-hv-util-Avoid-accessing-a-ringbuffer-not-ini.patch
    (git-fixes CVE-2024-55916 bsc#1235747).
  - Update
    patches.suse/mtd-rawnand-fix-double-free-in-atmel_pmecc_create_us.patch
    (git-fixes CVE-2024-56766 bsc#1235219).
  - Update
    patches.suse/mtd-spinand-winbond-Fix-512GW-01GW-01JW-and-02JW-ECC.patch
    (git-fixes CVE-2024-56771 bsc#1235649).
  - Update
    patches.suse/net-mlx5-DR-prevent-potential-error-pointer-derefere.patch
    (jsc#PED-11331 CVE-2024-56660 bsc#1235437).
  - Update
    patches.suse/net-usb-lan78xx-Fix-double-free-issue-with-interrupt.patch
    (git-fixes CVE-2024-53213 bsc#1234973).
  - Update
    patches.suse/nfs-blocklayout-Don-t-attempt-unregister-for-invalid-block-device.patch
    (git-fixes CVE-2024-53167 bsc#1234886).
  - Update
    patches.suse/nfs-localio-must-clear-res.replen-in-nfs_local_read_done.patch
    (git-fixes CVE-2024-56740 bsc#1234932).
  - Update
    patches.suse/nfs_common-must-not-hold-RCU-while-calling-nfsd_file_put_local.patch
    (git-fixes CVE-2024-56743 bsc#1235614).
  - Update
    patches.suse/nfsd-fix-nfs4_openowner-leak-when-concurrent-nfsd4_open-occur.patch
    (git-fixes CVE-2024-56779 bsc#1235632).
  - Update
    patches.suse/nfsd-make-sure-exp-active-before-svc_export_show.patch
    (git-fixes CVE-2024-56558 bsc#1235100).
  - Update
    patches.suse/nvme-fabrics-fix-kernel-crash-while-shutting-down-co.patch
    (git-fixes CVE-2024-53169 bsc#1234900).
  - Update
    patches.suse/nvme-pci-fix-freeing-of-the-HMB-descriptor-table.patch
    (git-fixes CVE-2024-56756 bsc#1234922).
  - Update
    patches.suse/nvme-rdma-unquiesce-admin_q-before-destroy-it.patch
    (git-fixes CVE-2024-49569 bsc#1235730).
  - Update
    patches.suse/nvme-tcp-fix-the-memleak-while-create-new-ctrl-faile.patch
    (git-fixes CVE-2024-56632 bsc#1235483).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-cn10.patch
    (jsc#PED-11317 CVE-2024-56726 bsc#1235582).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-69297b0d.patch
    (jsc#PED-11317 CVE-2024-56725 bsc#1235578).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-bd3110bc.patch
    (jsc#PED-11317 CVE-2024-56727 bsc#1235583).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-e26f8eac.patch
    (jsc#PED-11317 CVE-2024-56728 bsc#1235656).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2-f5b942e6.patch
    (jsc#PED-11317 CVE-2024-56707 bsc#1235545).
  - Update
    patches.suse/octeontx2-pf-handle-otx2_mbox_get_rsp-errors-in-otx2.patch
    (jsc#PED-11317 CVE-2024-56679 bsc#1235498).
  - Update
    patches.suse/phy-realtek-usb-fix-NULL-deref-in-rtk_usb2phy_probe.patch
    (git-fixes CVE-2024-53205 bsc#1234954).
  - Update
    patches.suse/phy-realtek-usb-fix-NULL-deref-in-rtk_usb3phy_probe.patch
    (git-fixes CVE-2024-53204 bsc#1234955).
  - Update
    patches.suse/phy-rockchip-samsung-hdptx-Set-drvdata-before-enabli.patch
    (git-fixes CVE-2024-57799 bsc#1235770).
  - Update
    patches.suse/pinmux-Use-sequential-access-to-access-desc-pinmux-d.patch
    (stable-fixes CVE-2024-47141 bsc#1235708).
  - Update
    patches.suse/pmdomain-imx-gpcv2-Adjust-delay-after-power-up-hands.patch
    (git-fixes CVE-2024-56618 bsc#1235465).
  - Update
    patches.suse/power-supply-gpio-charger-Fix-set-charge-current-lim.patch
    (git-fixes CVE-2024-57792 bsc#1235764).
  - Update
    patches.suse/powerpc-fadump-Move-fadump_cma_init-to-setup_arch-af.patch
    (bsc#1215199 CVE-2024-56677 bsc#1235494).
  - Update
    patches.suse/powerpc-mm-fault-Fix-kfence-page-fault-reporting.patch
    (bsc#1194869 CVE-2024-56678 bsc#1235495).
  - Update
    patches.suse/powerpc-pseries-Fix-dtl_access_lock-to-be-a-rw_semap.patch
    (bsc#1194869 CVE-2024-56701 bsc#1235496).
  - Update patches.suse/regulator-axp20x-AXP717-set-ramp_delay.patch
    (git-fixes CVE-2024-53682 bsc#1235718).
  - Update
    patches.suse/rtc-check-if-__rtc_read_time-was-successful-in-rtc_t.patch
    (git-fixes CVE-2024-56739 bsc#1235611).
  - Update
    patches.suse/s390-cpum_sf-Fix-and-protect-memory-allocation-of-SDBs-with-mutex.patch
    (git-fixes bsc#1234348 CVE-2024-56706 bsc#1235586).
  - Update
    patches.suse/s390-entry-Mark-IRQ-entries-to-fix-stack-depot-warnings.patch
    (git-fixes bsc#1234356 CVE-2024-57838 bsc#1235798).
  - Update
    patches.suse/s390-iucv-MSG_PEEK-causes-memory-leak-in-iucv_sock_destruct.patch
    (git-fixes bsc#1234351 CVE-2024-53210 bsc#1234971).
  - Update
    patches.suse/s390-pci-Fix-potential-double-remove-of-hotplug-slot.patch
    (git-fixes bsc#1234354 CVE-2024-56699 bsc#1235490).
  - Update
    patches.suse/sched-deadline-Fix-warning-in-migrate_enable-for-boosted-tasks.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2024-56583 bsc#1235118).
  - Update patches.suse/sched-fair-Fix-NEXT_BUDDY.patch (bsc#1234634
    (Scheduler functional and performance backports) CVE-2024-49573
    bsc#1235743).
  - Update patches.suse/sched-fix-warning-in-sched_setaffinity.patch
    (bsc#1234634 (Scheduler functional and performance backports)
    CVE-2024-41932 bsc#1235699).
  - Update
    patches.suse/scsi-megaraid_sas-Fix-for-a-potential-deadlock.patch
    (jsc#PED-11259 CVE-2024-57807 bsc#1235761).
  - Update
    patches.suse/scsi-qla2xxx-Fix-use-after-free-on-unload.patch
    (bsc#1235406 CVE-2024-56623 bsc#1235466).
  - Update
    patches.suse/soc-imx8m-Probe-the-SoC-driver-as-platform-driver.patch
    (stable-fixes CVE-2024-56787 bsc#1235663).
  - Update
    patches.suse/soc-qcom-geni-se-fix-array-underflow-in-geni_se_clk_.patch
    (git-fixes CVE-2024-53158 bsc#1234811).
  - Update
    patches.suse/spi-mpc52xx-Add-cancel_work_sync-before-module-remov.patch
    (git-fixes CVE-2024-50051 bsc#1235739).
  - Update
    patches.suse/sunrpc-clear-XPRT_SOCK_UPD_TIMEOUT-when-reset-transport.patch
    (git-fixes CVE-2024-56688 bsc#1235538).
  - Update
    patches.suse/sunrpc-fix-one-UAF-issue-caused-by-sunrpc-kernel-tcp-socket.patch
    (git-fixes CVE-2024-53168 bsc#1234887).
  - Update patches.suse/svcrdma-Address-an-integer-overflow.patch
    (git-fixes CVE-2024-53151 bsc#1234829).
  - Update
    patches.suse/svcrdma-fix-miss-destroy-percpu_counter-in-svc_rdma_proc_init.patch
    (git-fixes CVE-2024-53215 bsc#1234962).
  - Update
    patches.suse/thermal-testing-Initialize-some-variables-annoteded-.patch
    (git-fixes CVE-2024-56676 bsc#1235493).
  - Update patches.suse/tipc-fix-NULL-deref-in-cleanup_bearer.patch
    (bsc#1235433 CVE-2024-56661 bsc#1234931).
  - Update patches.suse/unicode-Fix-utf8_load-error-path.patch
    (git-fixes CVE-2024-53233 bsc#1235046).
  - Update
    patches.suse/usb-dwc3-gadget-Fix-looping-of-queued-SG-entries.patch
    (git-fixes CVE-2024-56698 bsc#1235491).
  - Update
    patches.suse/usb-gadget-u_serial-Fix-the-issue-that-gs_start_io-c.patch
    (git-fixes CVE-2024-56670 bsc#1235488).
  - Update
    patches.suse/usb-musb-Fix-hardware-lockup-on-first-Rx-endpoint-re.patch
    (git-fixes CVE-2024-56687 bsc#1235537).
  - Update
    patches.suse/usb-typec-fix-potential-array-underflow-in-ucsi_ccg_.patch
    (git-fixes CVE-2024-53203 bsc#1235001).
  - Update
    patches.suse/usb-typec-ucsi-glink-fix-off-by-one-in-connector_sta.patch
    (git-fixes CVE-2024-53149 bsc#1234842).
  - Update
    patches.suse/wifi-ath10k-avoid-NULL-pointer-error-during-sdio-rem.patch
    (stable-fixes CVE-2024-56599 bsc#1235138).
  - Update
    patches.suse/wifi-ath12k-Skip-Rx-TID-cleanup-for-self-peer.patch
    (git-fixes CVE-2024-56543 bsc#1235065).
  - Update
    patches.suse/wifi-ath12k-fix-atomic-calls-in-ath12k_mac_op_set_bi.patch
    (stable-fixes CVE-2024-56607 bsc#1235423).
  - Update patches.suse/wifi-ath12k-fix-crash-when-unbinding.patch
    (git-fixes CVE-2024-53188 bsc#1234948).
  - Update
    patches.suse/wifi-ath12k-fix-use-after-free-in-ath12k_dp_cc_clean.patch
    (git-fixes CVE-2024-56541 bsc#1235064).
  - Update patches.suse/wifi-ath12k-fix-warning-when-unbinding.patch
    (git-fixes CVE-2024-53191 bsc#1234952).
  - Update
    patches.suse/wifi-ath9k-add-range-check-for-conn_rsp_epid-in-htc_.patch
    (git-fixes CVE-2024-53156 bsc#1234846).
  - Update
    patches.suse/wifi-brcmfmac-Fix-oops-due-to-NULL-pointer-dereferen.patch
    (stable-fixes CVE-2024-56593 bsc#1235252).
  - Update
    patches.suse/wifi-cw1200-Fix-potential-NULL-dereference.patch
    (git-fixes CVE-2024-56536 bsc#1234911).
  - Update
    patches.suse/wifi-mwifiex-Fix-memcpy-field-spanning-write-warning.patch
    (git-fixes CVE-2024-56539 bsc#1234963).
  - Update
    patches.suse/wifi-nl80211-fix-NL80211_ATTR_MLO_LINK_ID-off-by-one.patch
    (git-fixes CVE-2024-56663 bsc#1235454).
  - Update
    patches.suse/wifi-nl80211-fix-bounds-checker-error-in-nl80211_par.patch
    (git-fixes CVE-2024-53189 bsc#1234949).
  - Update
    patches.suse/wifi-rtlwifi-Drastically-reduce-the-attempts-to-read.patch
    (stable-fixes CVE-2024-53190 bsc#1234950).
  - Update
    patches.suse/wifi-rtw88-use-ieee80211_purge_tx_queue-to-purge-TX-.patch
    (stable-fixes CVE-2024-56609 bsc#1235389).
  - Update
    patches.suse/wifi-rtw89-check-return-value-of-ieee80211_probereq_.patch
    (stable-fixes CVE-2024-48873 bsc#1235716).
  - Update
    patches.suse/wifi-rtw89-coex-check-NULL-return-of-kmalloc-in-btc_.patch
    (git-fixes CVE-2024-56535 bsc#1235044).
  - Update
    patches.suse/xfs-unlock-inodes-when-erroring-out-of-xfs_trans_alloc_dir.patch
    (git-fixes CVE-2024-55641 bsc#1235740).
  - commit b21bae3
  - padding for extending cgroup controllers (bsc#1207439).
  - commit 7b2e72c
  - padding for more cgroup controllers (jsc#PED-8461).
  - commit 417e2c0
  - KVM: s390: Reject KVM_SET_GSI_ROUTING on ucontrol VMs (git-fixes
    bsc#1235755).
  - KVM: s390: Reject setting flic pfault attributes on ucontrol
    VMs (git-fixes bsc#1235756).
  - KVM: s390: vsie: fix virtual/physical address in unpin_scb()
    (git-fixes bsc#1235757).
  - commit 25f73de
  - s390x config: IOMMU_DEFAULT_DMA_LAZY=y (bsc#1235646)
  - commit 2199130
  - net: usb: qmi_wwan: add Telit FE910C04 compositions (git-fixes).
  - commit a8a3e1b
  - misc: microchip: pci1xxxx: Resolve return code mismatch during
    GPIO set config (git-fixes).
  - misc: microchip: pci1xxxx: Resolve kernel panic during GPIO
    IRQ handling (git-fixes).
  - interconnect: icc-clk: check return values of devm_kasprintf()
    (git-fixes).
  - interconnect: qcom: icc-rpm: Set the count member before
    accessing the flex array (git-fixes).
  - iio: adc: ti-ads1119: fix sample size in scan struct for
    triggered buffer (git-fixes).
  - iio: inkern: call iio_device_put() only on mapped devices
    (git-fixes).
  - iio: adc: ad9467: Fix the "don't allow reading vref if not
    available" case (git-fixes).
  - iio: adc: at91: call input_free_device() on allocated iio_dev
    (git-fixes).
  - iio: adc: ad7173: fix using shared static info struct
    (git-fixes).
  - iio: adc: ti-ads124s08: Use gpiod_set_value_cansleep()
    (git-fixes).
  - iio: adc: ti-ads1119: fix information leak in triggered buffer
    (git-fixes).
  - iio: pressure: zpa2326: fix information leak in triggered buffer
    (git-fixes).
  - iio: adc: rockchip_saradc: fix information leak in triggered
    buffer (git-fixes).
  - iio: imu: kmx61: fix information leak in triggered buffer
    (git-fixes).
  - iio: light: vcnl4035: fix information leak in triggered buffer
    (git-fixes).
  - iio: light: bh1745: fix information leak in triggered buffer
    (git-fixes).
  - iio: adc: ti-ads8688: fix information leak in triggered buffer
    (git-fixes).
  - iio: dummy: iio_simply_dummy_buffer: fix information leak in
    triggered buffer (git-fixes).
  - iio: test: Fix GTS test config (git-fixes).
  - iio: adc: ti-ads1298: Add NULL check in ads1298_init
    (git-fixes).
  - iio: adc: stm32-dfsdm: handle label as an optional property
    (git-fixes).
  - iio: adc: ad4695: fix buffered read, single sample timings
    (git-fixes).
  - iio: imu: inv_icm42600: fix timestamps after suspend if sensor
    is on (git-fixes).
  - iio: gyro: fxas21002c: Fix missing data update in trigger
    handler (git-fixes).
  - iio: test : check null return of kunit_kmalloc in
    iio_rescale_test_scale (git-fixes).
  - iio: adc: ad7124: Disable all channels at probe time
    (git-fixes).
  - staging: iio: ad9832: Correct phase range check (git-fixes).
  - staging: iio: ad9834: Correct phase range check (git-fixes).
  - usb: typec: fix pm usage counter imbalance in
    ucsi_ccg_sync_control() (git-fixes).
  - usb: gadget: midi2: Reverse-select at the right place
    (git-fixes).
  - usb: gadget: f_fs: Remove WARN_ON in functionfs_bind
    (git-fixes).
  - USB: core: Disable LPM only for non-suspended ports (git-fixes).
  - usb: fix reference leak in usb_new_device() (git-fixes).
  - usb: typec: tcpci: fix NULL pointer issue on shared irq case
    (git-fixes).
  - usb: gadget: u_serial: Disable ep before setting port to null
    to fix the crash caused by port being null (git-fixes).
  - usb: chipidea: ci_hdrc_imx: decrement device's refcount in
    .remove() and in the error path of .probe() (git-fixes).
  - usb: gadget: configfs: Ignore trailing LF for user strings to
    cdev (git-fixes).
  - USB: usblp: return error when setting unsupported protocol
    (git-fixes).
  - usb: gadget: f_uac2: Fix incorrect setting of bNumEndpoints
    (git-fixes).
  - usb: typec: tcpm/tcpci_maxim: fix error code in
    max_contaminant_read_resistance_kohm() (git-fixes).
  - usb: host: xhci-plat: set skip_phy_initialization if software
    node has XHCI_SKIP_PHY_INIT property (git-fixes).
  - usb: dwc3-am62: Disable autosuspend during remove (git-fixes).
  - usb: dwc3: gadget: fix writing NYET threshold (git-fixes).
  - commit 708e579
  - serial: stm32: use port lock wrappers for break control
    (git-fixes).
  - tty: serial: 8250: Fix another runtime PM usage counter
    underflow (git-fixes).
  - commit 2e58518

++++ libeconf:

  - Update to version 0.7.7:
    * Additional fix for parsing empty config files (bsc#1234405).

++++ ncurses:

  - Add ncurses patch 20250111
    + add check for infinite loop in tic's use-resolution.
    + increase limit on use-clauses from 32 to 40, warn but allow entries
    which exceed the old limit.
    + add some null-pointer checks after mallocs in test-programs.
  - Add patch ncurses-6.5-ghostty.dif
    * Add an alias which causes the link /usr/share/terminfo/x/xterm-ghostty
    to ../g/ghostty (bug boo#1235689)

++++ tiff:

  - Fix versioning of tiff-docs under Recommends

++++ python-httpcore:

  - Update to 1.0.7
    * Support `proxy=…` configuration on `ConnectionPool()`.

++++ suse-module-tools:

    * regenerate-initrd-posttrans: return error if regenerating all
    initrds fails (bsc#1234308)

++++ ucode-amd:

  - Update to version 20250111 (git commit b3049665a5d0):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update sdma 4.4.5 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update gc 9.4.4 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update vcn 5.0.0 firmware
    * amdgpu: update smu 14.0.3 firmware
    * amdgpu: update psp 14.0.3 firmware
    * amdgpu: update gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update smu 14.0.2 firmware
    * amdgpu: update psp 14.0.2 firmware
    * amdgpu: update gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update vcn 4.0.3 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * cirrus: cs35l56: Correct some links to address the correct amp instance
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetar core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * cirrus: cs35l41: Add Firmware for Ayaneo system 1f660105
    * Fix has_gnu_parallel function

------------------------------------------------------------------
------------------  2025-1-12  -  Jan 12 2025  -------------------
------------------------------------------------------------------

++++ containerd:

  - Update to containerd v1.7.25. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.25>
    <https://github.com/containerd/containerd/releases/tag/v1.7.24>
  - Rebase patches:
    * 0001-BUILD-SLE12-revert-btrfs-depend-on-kernel-UAPI-inste.patch

++++ transactional-update:

  - Version 5.0.0
  - Rework /etc handling; instead of maintaining complex overlay
    mount layers use a btrfs subvolume of the corresponding
    snapshot instead.
    Syncing changes before the reboot will be done by during boot
    (or during apply) by transactional-update-sync-etc-state
    instead. [jsc#SMO-367]
    Also resolves: [boo#1140472],
    [gh#openSUSE/transactional-update#117]
  - Add EXPERIMENTAL support for performing updates using a
    container image [gh#openSUSE/transactional-update#128]. Note
    that this command is only available via
    `transactional-update apply-oci ...` for now and cannot be
    triggered from the API or D-Bus interface. Moreover the syntax
    may and probably will change in future releases.
  - Removed `status` command - it was disabled by default for a
    long time already and unmaintained
  - tukit: Fix snippet directory in man page
  - t-u: Don't apply again if snapshot is current already
  - t-u: Prevent self-updates between major t-u versions because
    these usually require additional files
  - Fix missing files when using `make dist`
  - Unified Copyright headers
  - Make Bash scripts shellcheck compatible
  - Replace tabs with spaces in Shell scripts to avoid the complex
    tab / space changes
  - Various other minor internal optimizations and fixes

++++ gsettings-desktop-schemas:

  - Update to version 48.alpha:
    + Add screen limits schema
    + Fix gendered language in key descriptions
  - Add check section where we test that the schemas compile.

++++ kernel-default:

  - hwmon: (drivetemp) Fix driver producing garbage data when SCSI
    errors occur (git-fixes).
  - modpost: fix the missed iteration for the max bit in do_input()
    (git-fixes).
  - commit 5559cd4
  - Refresh
    patches.suse/0005-efi-generate-secret-key-in-EFI-boot-environment.patch.
    Update config files.
    CONFIG_EFI_SECRET_KEY is not set
  - commit f3e53e1
  - Refresh
    patches.suse/0002-hibernate-avoid-the-data-in-hidden-area-to-be-snapsh.patch.
  - commit 81704e7
  - Refresh
    patches.suse/0001-security-create-hidden-area-to-keep-sensitive-data.patch.
    Update config files.
    CONFIG_HIDDEN_AREA is not set
  - commit 53e4009
  - Refresh
    patches.suse/acpi-Disable-APEI-error-injection-if-the-kernel-is-lockeddown.patch.
  - commit 1526952

++++ kernel-rt:

  - hwmon: (drivetemp) Fix driver producing garbage data when SCSI
    errors occur (git-fixes).
  - modpost: fix the missed iteration for the max bit in do_input()
    (git-fixes).
  - commit 5559cd4
  - Refresh
    patches.suse/0005-efi-generate-secret-key-in-EFI-boot-environment.patch.
    Update config files.
    CONFIG_EFI_SECRET_KEY is not set
  - commit f3e53e1
  - Refresh
    patches.suse/0002-hibernate-avoid-the-data-in-hidden-area-to-be-snapsh.patch.
  - commit 81704e7
  - Refresh
    patches.suse/0001-security-create-hidden-area-to-keep-sensitive-data.patch.
    Update config files.
    CONFIG_HIDDEN_AREA is not set
  - commit 53e4009
  - Refresh
    patches.suse/acpi-Disable-APEI-error-injection-if-the-kernel-is-lockeddown.patch.
  - commit 1526952

++++ harfbuzz:

  - Update to version 10.2.0:
    + Consider Unicode Variation Selectors when subsetting “cmap”
    table.
    + Guard hb_cairo_glyphs_from_buffer() against malformed UTF-8
    strings.
    + Fix incorrect “COLR” v1 glyph scaling in hb-cairo.
    + Use locale-independent parsing of double numbers is “hb-subset”
    command line tool.
    + Fix incorrect zeroing of advance width of base glyphs in
    various “Courier New” font versions due to incorrect “GDEF”
    glyph classes.
    + Fix handling of long language codes with “HB_LEAN”
    configuration.
    + Update OpenType language system registry.
    + Allow all Myanmar tone marks (including visarga) in any order.
    + Don’t insert U+25CC DOTTED CIRCLE before superscript/subscript
    digits.
    + Handle Garay script as right to left script.
    + New API for serializing font tables and potentially repacking
    them in optimal way.
    + New API for converting font variation setting from and to
    strings.
    + Various build fixes.
    + Various subsetter and instancer fixes.
    + New API:
  - +hb_subset_serialize_link_t
  - +hb_subset_serialize_object_t
  - +hb_subset_serialize_or_fail()
  - +hb_subset_axis_range_from_string()
  - +hb_subset_axis_range_to_string()
  - Drop harfbuzz-CVE-2024-56732.patch: Fixed upstream.

------------------------------------------------------------------
------------------  2025-1-11  -  Jan 11 2025  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - thermal: of: fix OF node leak in of_thermal_zone_find()
    (git-fixes).
  - drm/mediatek: Add return value check when reading DPCD
    (git-fixes).
  - drm/mediatek: mtk_dsi: Add registers to pdata to fix
    MT8186/MT8188 (git-fixes).
  - drm/mediatek: Fix mode valid issue for dp (git-fixes).
  - drm/mediatek: Fix YCbCr422 color format issue for DP
    (git-fixes).
  - drm/mediatek: stop selecting foreign drivers (git-fixes).
  - drm/mediatek: Add support for 180-degree rotation in the
    display driver (git-fixes).
  - drm/mediatek: Only touch DISP_REG_OVL_PITCH_MSB if AFBC is
    supported (git-fixes).
  - drm/mediatek: Move mtk_crtc_finish_page_flip() to ddp_cmdq_cb()
    (git-fixes).
  - drm/mediatek: Set private->all_drm_private[i]->drm to NULL if
    mtk_drm_bind returns err (git-fixes).
  - Revert "drm/mediatek: dsi: Correct calculation formula of PHY
    Timing" (git-fixes).
  - drm/xe: Fix tlb invalidation when wedging (git-fixes).
  - drm/amdgpu: Add a lock when accessing the buddy trim function
    (git-fixes).
  - drm/amdkfd: fixed page fault when enable MES shader debugger
    (git-fixes).
  - drm/amd/display: fix divide error in DM plane scale calcs
    (git-fixes).
  - drm/amd/display: fix page fault due to max surface definition
    mismatch (git-fixes).
  - drm/amd/display: Remove unnecessary amdgpu_irq_get/put
    (git-fixes).
  - platform/x86: intel/pmc: Fix ioremap() of bad address
    (git-fixes).
  - platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042
    actually enabled it (git-fixes).
  - gpio: loongson: Fix Loongson-2K2000 ACPI GPIO register offset
    (git-fixes).
  - gpio: virtuser: fix handling of multiple conn_ids in lookup
    table (git-fixes).
  - gpio: virtuser: fix missing lookup table cleanups (git-fixes).
  - commit 993f2e5
  - kgdb: Check early kernel lockdown flag before using kgdb
    (bsc#1234646).
  - commit 8566b22
  - ACPI: Check early kernel lockdown flag before overlaying tables
    (bsc#1234646).
  - commit f711c7c
  - efi: Set early kernel lock down flag if booted in secure boot
    mode (bsc#1234646).
  - commit 00a355d
  - security: Add a kernel lockdown flag for early boot stage
    (bsc#1234646).
    Update config files.
    CONFIG_LOCK_DOWN_KERNEL_EARLY
  - commit d7ebed1
  - Lock down x86_64 kernel in secure boot mode in subsys_initcall
    stage (bsc#1234646).
  - commit 206dec9

++++ kernel-rt:

  - thermal: of: fix OF node leak in of_thermal_zone_find()
    (git-fixes).
  - drm/mediatek: Add return value check when reading DPCD
    (git-fixes).
  - drm/mediatek: mtk_dsi: Add registers to pdata to fix
    MT8186/MT8188 (git-fixes).
  - drm/mediatek: Fix mode valid issue for dp (git-fixes).
  - drm/mediatek: Fix YCbCr422 color format issue for DP
    (git-fixes).
  - drm/mediatek: stop selecting foreign drivers (git-fixes).
  - drm/mediatek: Add support for 180-degree rotation in the
    display driver (git-fixes).
  - drm/mediatek: Only touch DISP_REG_OVL_PITCH_MSB if AFBC is
    supported (git-fixes).
  - drm/mediatek: Move mtk_crtc_finish_page_flip() to ddp_cmdq_cb()
    (git-fixes).
  - drm/mediatek: Set private->all_drm_private[i]->drm to NULL if
    mtk_drm_bind returns err (git-fixes).
  - Revert "drm/mediatek: dsi: Correct calculation formula of PHY
    Timing" (git-fixes).
  - drm/xe: Fix tlb invalidation when wedging (git-fixes).
  - drm/amdgpu: Add a lock when accessing the buddy trim function
    (git-fixes).
  - drm/amdkfd: fixed page fault when enable MES shader debugger
    (git-fixes).
  - drm/amd/display: fix divide error in DM plane scale calcs
    (git-fixes).
  - drm/amd/display: fix page fault due to max surface definition
    mismatch (git-fixes).
  - drm/amd/display: Remove unnecessary amdgpu_irq_get/put
    (git-fixes).
  - platform/x86: intel/pmc: Fix ioremap() of bad address
    (git-fixes).
  - platform/x86/amd/pmc: Only disable IRQ1 wakeup where i8042
    actually enabled it (git-fixes).
  - gpio: loongson: Fix Loongson-2K2000 ACPI GPIO register offset
    (git-fixes).
  - gpio: virtuser: fix handling of multiple conn_ids in lookup
    table (git-fixes).
  - gpio: virtuser: fix missing lookup table cleanups (git-fixes).
  - commit 993f2e5
  - kgdb: Check early kernel lockdown flag before using kgdb
    (bsc#1234646).
  - commit 8566b22
  - ACPI: Check early kernel lockdown flag before overlaying tables
    (bsc#1234646).
  - commit f711c7c
  - efi: Set early kernel lock down flag if booted in secure boot
    mode (bsc#1234646).
  - commit 00a355d
  - security: Add a kernel lockdown flag for early boot stage
    (bsc#1234646).
    Update config files.
    CONFIG_LOCK_DOWN_KERNEL_EARLY
  - commit d7ebed1
  - Lock down x86_64 kernel in secure boot mode in subsys_initcall
    stage (bsc#1234646).
  - commit 206dec9

++++ at-spi2-core:

  - Update to version 2.55.0 (Unstable):
    + Improve warnings when setting a property.
    + Use the appropriate annotations for callbacks.
    + device: Support adding grabs given a keysym.
  - Update to version 2.54.1:
    + Fix various memory leaks.
    + Fix the build on FreeBSD.
  - Switch to source service for tarball.

++++ libsoup:

  - Update to version 3.6.3:
    + http2: Significantly reduce memory usage of large requests
    + server: Treat `ECONNREFUSED` when listening on IPv6 as
    unsupported
    + auth-digest: Fix handling missing nonce/realm in responses, as
    well as a leak
    + In `soup_uri_decode_data_uri()` fix handling of URIs with a
    path beginning with `//`
    + In `soup_message_headers_get_content_disposition()` fix
    possibility of NULL-deref and double-free
    + In `soup_header_parse_quality_list()` fix leak
    + In `soup_form_decode_multipart()` fix ownership annotation for
    the multipart object

++++ shadow:

  - Update to 4.17.2:
    * src/login_nopam.c: Fix compiler warnings #1170
    * lib/chkname.c: Put limits for LOGIN_NAME_MAX and sysconf(_SC_LOGIN_NAME_MAX) #1169
    * Use HTTPS in link to Wikipedia article on password strength #1164
    * lib/attr.h: use C23 attributes only with gcc >= 10 #1172
    * login: Fix no-pam authorization regression #1174
    * man: Add Portuguese translation #1178
    * Update French translation #1177
    * Add cheap defense mechanisms #1171
    * Add Romanian translation #1176

------------------------------------------------------------------
------------------  2025-1-10  -  Jan 10 2025  -------------------
------------------------------------------------------------------

++++ container-selinux:

  - Update to version 2.234.2:
    * TMT: enable epel idomatically
    * Packit: switch back to fedora-all
    * RPM: Bump Epoch to 4
    * rpm: ship manpage
    * Add proper labeling for RamaLama
    * Packit: remove rhel / epel jobs
    * packit: remove unused file

++++ python-kiwi:

  - Fixed donate button target

++++ kernel-default:

  - block, bfq: fix bfqq uaf in bfq_limit_depth() (CVE-2024-53166
    bsc#1234884).
  - commit 2d6266b
  - bpf, sockmap: Fix race between element replace and close()
    (CVE-2024-56664 bsc#1235249).
  - commit c6238ec
  - Disable ceph (jsc#PED-7242)
  - commit c5f8eec
  - Refresh
    patches.suse/0001-security-lockdown-expose-a-hook-to-lock-the-kernel-down.patch.
  - commit fe21847
  - tipc: fix NULL deref in cleanup_bearer() (bsc#1235433).
  - commit e901a2d
  - Enable CONFIG_LIST_HARDENED (jsc#PED-11842)
  - commit a16f97b
  - virtio_net: correct netdev_tx_reset_queue() invocation point
    (CVE-2024-56674 bsc#1235549).
  - commit d01521b
  - stackleak: disable stack erasing by default (jsc#PED-11837).
  - commit 25d95db
  - config: enable CONFIG_GCC_PLUGIN_STACKLEAK
    Keep it disabled via stack_erasing syscall to avoid overhead
  - commit 8cf8a17
  - Update config files. Enable CONFIG_RANDOM_KMALLOC_CACHES (jsc#PED-11846)
    except on zfcpdump, disable CONFIG_SLAB_BUCKETS on zfcpdump.
  - commit 23291c7
  - Reviewed
    patches.suse/s390-lock-down-kernel-in-secure-boot-mode.patch
  - commit 75d9cc5
  - Reviewed
    patches.suse/arm64-lock-down-kernel-in-secure-boot-mode.patch
  - commit a397f81
  - Refresh
    patches.suse/powerpc-lock-down-kernel-in-secure-boot-mode.patch.
  - commit 6f37879
  - Refresh
    patches.suse/0004-efi-Lock-down-the-kernel-at-the-integrity-level-if-b.patch.
  - commit c848190
  - Reviewed
    patches.suse/KEYS-Make-use-of-platform-keyring-for-module-signatu.patch
  - commit 5b00a1a
  - Refresh
    patches.suse/0003-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mode.patch.
    Update config files.
    CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT
  - commit 509a86d
  - Reviewed
    patches.suse/0002-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-boot-mode.patch
  - commit 6ffabc3
  - scsi: sg: Fix slab-use-after-free read in sg_release()
    (CVE-2024-56631 bsc#1235480).
  - commit 76de829
  - Refresh
    patches.suse/0001-security-lockdown-expose-a-hook-to-lock-the-kernel-down.patch.
  - commit 2157c81
  - Bluetooth: btmtk: Fix failed to send func ctrl for MediaTek
    devices (git-fixes).
  - Bluetooth: btnxpuart: Fix driver sending truncated data
    (git-fixes).
  - Bluetooth: MGMT: Fix Add Device to responding before completing
    (git-fixes).
  - Bluetooth: hci_sync: Fix not setting Random Address when
    required (git-fixes).
  - ieee802154: ca8210: Add missing check for kfifo_alloc() in
    ca8210_probe() (git-fixes).
  - drm/amdkfd: Correct the migration DMA map direction
    (stable-fixes).
  - drm/amdgpu: use sjt mec fw on gfx943 for sriov (stable-fixes).
  - wifi: mac80211: wake the queues in case of failure in resume
    (stable-fixes).
  - wifi: cfg80211: clear link ID from bitmap during link delete
    after clean up (stable-fixes).
  - wifi: mac80211: fix mbss changed flags corruption on 32 bit
    systems (stable-fixes).
  - Bluetooth: btmtk: Fix failed to send func ctrl for MediaTek
    devices (git-fixes).
  - Bluetooth: btnxpuart: Fix driver sending truncated data
    (git-fixes).
  - Bluetooth: MGMT: Fix Add Device to responding before completing
    (git-fixes).
  - Bluetooth: hci_sync: Fix not setting Random Address when
    required (git-fixes).
  - ieee802154: ca8210: Add missing check for kfifo_alloc() in
    ca8210_probe() (git-fixes).
  - drm/amdkfd: Correct the migration DMA map direction
    (stable-fixes).
  - drm/amdgpu: use sjt mec fw on gfx943 for sriov (stable-fixes).
  - wifi: mac80211: wake the queues in case of failure in resume
    (stable-fixes).
  - wifi: cfg80211: clear link ID from bitmap during link delete
    after clean up (stable-fixes).
  - wifi: mac80211: fix mbss changed flags corruption on 32 bit
    systems (stable-fixes).
  - commit d04ce72
  - 9p/xen: fix release of IRQ (CVE-2024-56704 bsc#1235584).
  - commit bf1ccfc
  - net: ieee802154: do not leave a dangling sk pointer in
    ieee802154_create() (CVE-2024-56602 bsc#1235521).
  - commit 8b46faa
  - udmabuf: fix memory leak on last export_udmabuf() error path
    (CVE-2024-56712 bsc#1235565).
  - commit 3d88b1a
  - x86/CPU/AMD: Terminate the erratum_1386_microcode array
    (CVE-2024-56721 bsc#1235566).
  - commit 09a03bf
  - net: hsr: avoid potential out-of-bound access in
    fill_frame_info() (CVE-2024-56648 bsc#1235451).
  - commit 333d1e7

++++ kernel-rt:

  - block, bfq: fix bfqq uaf in bfq_limit_depth() (CVE-2024-53166
    bsc#1234884).
  - commit 2d6266b
  - bpf, sockmap: Fix race between element replace and close()
    (CVE-2024-56664 bsc#1235249).
  - commit c6238ec
  - Disable ceph (jsc#PED-7242)
  - commit c5f8eec
  - Refresh
    patches.suse/0001-security-lockdown-expose-a-hook-to-lock-the-kernel-down.patch.
  - commit fe21847
  - tipc: fix NULL deref in cleanup_bearer() (bsc#1235433).
  - commit e901a2d
  - Enable CONFIG_LIST_HARDENED (jsc#PED-11842)
  - commit a16f97b
  - virtio_net: correct netdev_tx_reset_queue() invocation point
    (CVE-2024-56674 bsc#1235549).
  - commit d01521b
  - stackleak: disable stack erasing by default (jsc#PED-11837).
  - commit 25d95db
  - config: enable CONFIG_GCC_PLUGIN_STACKLEAK
    Keep it disabled via stack_erasing syscall to avoid overhead
  - commit 8cf8a17
  - Update config files. Enable CONFIG_RANDOM_KMALLOC_CACHES (jsc#PED-11846)
    except on zfcpdump, disable CONFIG_SLAB_BUCKETS on zfcpdump.
  - commit 23291c7
  - Reviewed
    patches.suse/s390-lock-down-kernel-in-secure-boot-mode.patch
  - commit 75d9cc5
  - Reviewed
    patches.suse/arm64-lock-down-kernel-in-secure-boot-mode.patch
  - commit a397f81
  - Refresh
    patches.suse/powerpc-lock-down-kernel-in-secure-boot-mode.patch.
  - commit 6f37879
  - Refresh
    patches.suse/0004-efi-Lock-down-the-kernel-at-the-integrity-level-if-b.patch.
  - commit c848190
  - Reviewed
    patches.suse/KEYS-Make-use-of-platform-keyring-for-module-signatu.patch
  - commit 5b00a1a
  - Refresh
    patches.suse/0003-efi-Lock-down-the-kernel-if-booted-in-secure-boot-mode.patch.
    Update config files.
    CONFIG_LOCK_DOWN_IN_EFI_SECURE_BOOT
  - commit 509a86d
  - Reviewed
    patches.suse/0002-efi-Add-an-EFI_SECURE_BOOT-flag-to-indicate-secure-boot-mode.patch
  - commit 6ffabc3
  - scsi: sg: Fix slab-use-after-free read in sg_release()
    (CVE-2024-56631 bsc#1235480).
  - commit 76de829
  - Refresh
    patches.suse/0001-security-lockdown-expose-a-hook-to-lock-the-kernel-down.patch.
  - commit 2157c81
  - Bluetooth: btmtk: Fix failed to send func ctrl for MediaTek
    devices (git-fixes).
  - Bluetooth: btnxpuart: Fix driver sending truncated data
    (git-fixes).
  - Bluetooth: MGMT: Fix Add Device to responding before completing
    (git-fixes).
  - Bluetooth: hci_sync: Fix not setting Random Address when
    required (git-fixes).
  - ieee802154: ca8210: Add missing check for kfifo_alloc() in
    ca8210_probe() (git-fixes).
  - drm/amdkfd: Correct the migration DMA map direction
    (stable-fixes).
  - drm/amdgpu: use sjt mec fw on gfx943 for sriov (stable-fixes).
  - wifi: mac80211: wake the queues in case of failure in resume
    (stable-fixes).
  - wifi: cfg80211: clear link ID from bitmap during link delete
    after clean up (stable-fixes).
  - wifi: mac80211: fix mbss changed flags corruption on 32 bit
    systems (stable-fixes).
  - Bluetooth: btmtk: Fix failed to send func ctrl for MediaTek
    devices (git-fixes).
  - Bluetooth: btnxpuart: Fix driver sending truncated data
    (git-fixes).
  - Bluetooth: MGMT: Fix Add Device to responding before completing
    (git-fixes).
  - Bluetooth: hci_sync: Fix not setting Random Address when
    required (git-fixes).
  - ieee802154: ca8210: Add missing check for kfifo_alloc() in
    ca8210_probe() (git-fixes).
  - drm/amdkfd: Correct the migration DMA map direction
    (stable-fixes).
  - drm/amdgpu: use sjt mec fw on gfx943 for sriov (stable-fixes).
  - wifi: mac80211: wake the queues in case of failure in resume
    (stable-fixes).
  - wifi: cfg80211: clear link ID from bitmap during link delete
    after clean up (stable-fixes).
  - wifi: mac80211: fix mbss changed flags corruption on 32 bit
    systems (stable-fixes).
  - commit d04ce72
  - 9p/xen: fix release of IRQ (CVE-2024-56704 bsc#1235584).
  - commit bf1ccfc
  - net: ieee802154: do not leave a dangling sk pointer in
    ieee802154_create() (CVE-2024-56602 bsc#1235521).
  - commit 8b46faa
  - udmabuf: fix memory leak on last export_udmabuf() error path
    (CVE-2024-56712 bsc#1235565).
  - commit 3d88b1a
  - x86/CPU/AMD: Terminate the erratum_1386_microcode array
    (CVE-2024-56721 bsc#1235566).
  - commit 09a03bf
  - net: hsr: avoid potential out-of-bound access in
    fill_frame_info() (CVE-2024-56648 bsc#1235451).
  - commit 333d1e7

++++ libpwquality:

  - Add libpwquality-fix-python-install.patch: Fix installation of
    python bindings after moving to setuptools.

++++ wtmpdb:

  - Update to version 0.50.0+git20250110.12da60f:
    * Release version 0.50.0
    * README: add wtmpdbd
    * wtmpdbd: Print stopped message
    * wtmpdbd.service: preset WTMPDBD_OPTS
    * wtmpdbd: don't call listen if started by a socket
    * tst-varlink: skip if varlink is not supported
    * libwtmpdb: set varlink_is_active to 0 without systemd
    * libwtmpdb: always define varlink checks
    * wtmpdb: define quiet only if we have systemd
    * libwtmpdb: return error if varlink support is missing
    * Send sd_notify(STOPPING=1);
    * Check if systemd has sd_varlink_server_listen_name()
    * wtmpdbd.service: optional read /etc/default/wtmpdbd
    * wtmpdbd: simplify creation of varlink sockets
    * Set umaks with varlink to 0077, improve error reporting
    * wtmpdbd: enable to start via sockets
    * libwtmpdb: handle ECONNRESET as wtmpdbd not running
    * libwtmpdb: fix crash in varlink if error==NULL
    * Install daemon in libexec directory
    * tst-get_id: skip if there is no db file
    * libwtmpdb: improve error return code
    * db path "varlink" will enforce varlink interface
    * Add service and socket files
    * wmtpdb: call wtmpdb_* functions with NULL as path
    * wtmpdbd: add socket activation
    * Implement varlink read_all client side
    * Make wtmpdbd support compiletime config
    * Add daemon using varlink for communication
    * Document that openssh is special
    * libwtmpdb: create wrapper around sqlite functions
    * Make mkdir_p more robust

------------------------------------------------------------------
------------------  2025-1-9  -  Jan 9 2025  -------------------
------------------------------------------------------------------

++++ container-selinux:

  - Add BuildRequires selinux-policy-%{selinuxtype} to enable building
    for SLFO. Might be removed in the future again when 1231252
    is fixed.

++++ fwupd:

  - Update to version 2.0.3:
    + This release adds the following features:
  - Add a power quirk for Framework systems
  - Speed up writing firmware to the new Dell dock
    + This release fixes the following bugs:
  - Deinitialize DRM after getting GPU marketing name to fix Xorg
    startup
  - Do not show 'Device has been removed' as a dock device error
  - Fix a warning about legion-hid2 progress going backwards
  - Fix some small memory leaks in realtek-mst and dell-kestrel
  - Only mark supported Logitech devices as updatable
  - Parse FDTs with missing END tokens to work on more
    ChromeBooks
  - Reduce the device emulation RSS requirement by ~40%
  - Skip checking BootXXXX entries when the partition does not
    exist
    + This release adds support for the following hardware:
  - Primax Ryder Mouse
  - Changes from version 2.0.2:
    + Add fwupdtool 'get-version-formats' and 'vercmp' commands
    + Add support for checking AMD HW configuration MSR
    + Add support for enumerate-only device emulation to increase
    test coverage
    + Add support for passing a JSON file for emulation instead of
    ZIP
    + Remove support for now-obsolete CSR DFU and Nitrokey devices
  - Changes from version 2.0.1:
    + Add API so that gnome-firmware can record devices for emulation
    + Save the emulation-tag devices to the database rather than the
    config file
  - Changes from version 2.0.0:
    + Drop legacy signing formats for verification of metadata and
    firmware
    + Reduce the runtime memory usage and CPU startup cost
    significantly
    + Remove all the long-deprecated legacy CLI tools
    + Remove libgusb and GUdev from plugins and use libusb and sysfs
    instead
    + Stream firmware binaries over a file descriptor rather than
    into memory
  - Drop harden_fwupd-offline-update.service.patch: offline service
    no longer exists.
  - Drop harden_fwupd-refresh.service.patch: merged upstream.
  - Drop fwupd-jscSLE-11766-close-efidir-leap-gap.patch: fwupd now
    falls back to ID_LIKE.
  - Bump shlib_sover to 3, following upstream.
  - Add python3-dbusmock BuildRequires: new dependency.
  - Update fwupd-bsc1130056-change-shim-path.patch to correct the
    path for shim.efi

++++ kernel-default:

  - supported.conf: All modules related to the Intel TPMI are supported (jsc#PED-4901 jsc#PED-4961 jsc#PED-4647)
  - commit 782043f
  - Update
    patches.suse/cpufreq-amd-pstate-Default-to-powersave-governor-whe.patch
    (jsc#PED-11639).
  - commit f371154
  - cpufreq: intel_pstate: Update Balance-performance EPP for
    Granite Rapids (jsc#PED-11771).
  - commit 907dba9
  - intel_idle: add Granite Rapids Xeon D support (jsc#PED-10589).
  - commit 3305026
  - af_packet: avoid erroring out after sock_init_data() in packet_create() (CVE-2024-56606 bsc#123541)
  - commit 4c171b7
  - smb: client: fix NULL ptr deref in crypto_aead_setkey() (CVE-2024-53185 bsc#1234901)
  - commit 16fd7dd
  - net: af_can: do not leave a dangling sk pointer in can_create() (CVE-2024-56603 bsc#1235415)
  - commit 358efec
  - ovl: Filter invalid inodes with missing lookup function
    (bsc#1235035 CVE-2024-56570).
  - commit 707d8d7
  - ceph: fix cred leak in ceph_mds_check_access() (CVE-2024-56563 bsc#1235107)
  - commit 2378163
  - Update
    patches.suse/comedi-Flush-partial-mappings-in-error-case.patch
    (git-fixes CVE-2024-53148 bsc#1234832).
    Add CVE reference.
  - commit 04ca6f4
  - tipc: Fix use-after-free of kernel socket in cleanup_bearer()
    (CVE-2024-56642 bsc#1235433).
  - commit 9a3730d
  - smb: client: fix use-after-free of signing key (CVE-2024-53179
    bsc#1234921).
  - commit 2e9abfc

++++ kernel-rt:

  - supported.conf: All modules related to the Intel TPMI are supported (jsc#PED-4901 jsc#PED-4961 jsc#PED-4647)
  - commit 782043f
  - Update
    patches.suse/cpufreq-amd-pstate-Default-to-powersave-governor-whe.patch
    (jsc#PED-11639).
  - commit f371154
  - cpufreq: intel_pstate: Update Balance-performance EPP for
    Granite Rapids (jsc#PED-11771).
  - commit 907dba9
  - intel_idle: add Granite Rapids Xeon D support (jsc#PED-10589).
  - commit 3305026
  - af_packet: avoid erroring out after sock_init_data() in packet_create() (CVE-2024-56606 bsc#123541)
  - commit 4c171b7
  - smb: client: fix NULL ptr deref in crypto_aead_setkey() (CVE-2024-53185 bsc#1234901)
  - commit 16fd7dd
  - net: af_can: do not leave a dangling sk pointer in can_create() (CVE-2024-56603 bsc#1235415)
  - commit 358efec
  - ovl: Filter invalid inodes with missing lookup function
    (bsc#1235035 CVE-2024-56570).
  - commit 707d8d7
  - ceph: fix cred leak in ceph_mds_check_access() (CVE-2024-56563 bsc#1235107)
  - commit 2378163
  - Update
    patches.suse/comedi-Flush-partial-mappings-in-error-case.patch
    (git-fixes CVE-2024-53148 bsc#1234832).
    Add CVE reference.
  - commit 04ca6f4
  - tipc: Fix use-after-free of kernel socket in cleanup_bearer()
    (CVE-2024-56642 bsc#1235433).
  - commit 9a3730d
  - smb: client: fix use-after-free of signing key (CVE-2024-53179
    bsc#1234921).
  - commit 2e9abfc

++++ pango:

  - Update to version 1.56.0:
    + Support setting font features in font descriptions
    + serialization:
  - Document the tab array format
  - Accept attributes without range
    + layout: Fix measuring ellipsis runs with shapes
    + build:
  - Require C11
  - Require GLib 2.80
  - Require cairo 1.18
  - Replace gcc-c++ with generic c++_compiler BuildRequires.
  - Drop help2man BuildRequires, upstream ported manpages for tools
    to rst2man/rst2html, and defaults to not build it. Follow
    upstream and do not build the man or html documentation for
    tools.

++++ systemd:

  - Upgrade systemd with systemd v257.2 from Base:System (revision:1574)
  - Rename 0001-udev-restore-some-legacy-symlinks-to-maintain-backwa.patch into
    0003-udev-restore-some-legacy-symlinks-to-maintain-backwa.patch
    Given that SLE16 will be based on SLFO, we have no choice but to continue
    supporting these compat symlinks. This compatibility code is no longer
    maintained in the Git repository though, as we primarily backport upstream
    commits these days. Additionally, the compat code rarely changes and often
    causes conflicts when merged into recent versions of systemd.
  - Drop 5003-99-systemd.rules-rework-SYSTEMD_READY-logic-for-devi.patch, it's
    part of systemd v256.
  - Drop 5004-udev-allow-denylist-for-reading-sysfs-attributes-whe.patch, it's
    part of systemd v256.

++++ python-charset-normalizer:

  - Update to 3.4.1
    * Project metadata are now stored using `pyproject.toml` instead of
    `setup.cfg` using setuptools as the build backend.
    * Enforce annotation delayed loading for a simpler and consistent
    types in the project.
    * Optional mypyc compilation upgraded to version 1.14 for Python >= 3.8
    * Added pre-commit configuration.
    * Added noxfile.
    * Removed `build-requirements.txt` as per using `pyproject.toml`
    native build configuration.
    * Removed `bin/integration.py` and `bin/serve.py` in favor of downstream
    integration test (see noxfile).
    * Removed `setup.cfg` in favor of `pyproject.toml` metadata configuration.
    * Removed unused `utils.range_scan` function.
    * Converting content to Unicode bytes may insert `utf_8` instead of
    preferred `utf-8`. (#572)
    * Deprecation warning "'count' is passed as positional argument" when
    converting to Unicode bytes on Python 3.13+
  - Drop sed command to remove code coverage flags from pytest

++++ python-click:

  - Update to 8.1.8
    * Fix an issue with type hints for click.open_file(). :issue:2717
    * Fix issue where error message for invalid click.Path displays on
    multiple lines. :issue:2697
    * Fixed issue that prevented a default value of "" from being displayed in
    the help for an option. :issue:2500
    * The test runner handles stripping color consistently on Windows.
    :issue:2705
    * Show correct value for flag default when using default_map.
    :issue:2632
    * Fix click.echo(color=...) passing color to coloroma so it can be
    forced on Windows. :issue:2606.
  - Switch build system from setuptools to pyproject.toml
    * Add python-pip and python-wheel to BuildRequires
    * Replace %python_build with %pyproject_wheel
    * Replace %python_install with %pyproject_install
    * Update name for dist directory in %files section
  - Update BuildRequires from pyproject.toml

++++ rsync:

  - Security update, fix multiple vulnerabilities:
    * CVE-2024-12084, bsc#1234100 - Heap Buffer Overflow in Checksum Parsing
    * CVE-2024-12085, bsc#1234101 - Info Leak via uninitialized Stack contents defeats ASLR
    * CVE-2024-12086, bsc#1234102 - Server leaks arbitrary client files
    * CVE-2024-12087, bsc#1234103 - Server can make client write files outside of destination directory using symbolic links
    * CVE-2024-12088, bsc#1234104 - --safe-links Bypass
    * Added rsync-CVE-2024-12084-overflow-01.patch
    * Added rsync-CVE-2024-12084-overflow-02.patch
    * Added rsync-CVE-2024-12085.patch
    * Added rsync-CVE-2024-12086_01.patch
    * Added rsync-CVE-2024-12086_02.patch
    * Added rsync-CVE-2024-12086_03.patch
    * Added rsync-CVE-2024-12086_04.patch
    * Added rsync-CVE-2024-12087_01.patch
    * Added rsync-CVE-2024-12087_02.patch
    * Added rsync-CVE-2024-12088.patch

++++ selinux-policy:

  - Sync content of factory branch to SLFO (git commit: 33c703587e800be11fca3101b7caf2d4a5c77117,
    OBS Factory: selinux-policy-20241220) and update packaging for SLE 16.
    This includes:
  - Fix minimum policy by readding rpm module (bsc#1234314)
  - Fix minimum policy by readding snapper module (bsc#1234037)
  - Packaging rework: moving all config files to git repository
    https://gitlab.suse.de/selinux/selinux-policy
  - Moved booleans to dist/*/booleans.conf and dropped from package:
    * booleans-minimum.conf
  - user facing change: boolean settings are now the same as in upstream
    * booleans-mls.conf
  - user facing change: boolean settings are now the same as in upstream
    * booleans-targeted.conf
  - user facing change: kerberos_enabled boolean was not enabled due to a bug, now it is enabled
  - Moved booleans.subs_dist to dist/booleans.subs_dist and dropped from package
  - Moved customizable_types to dist/customizable_types and dropped from package
  - user facing change: using upstream version
  - Moved file_contexts.subs_dist to config/file_contexts.subs_dist and dropped from package
  - user facing change: changed systemd entries in file_contexts.subs_dist:
    /run/systemd/system -> dropped from file
    /run/systemd/generator.early /run/systemd/generator
    /run/systemd/generator.late /run/systemd/generator
  - Moved modules config to dist/<policytype>/modules.conf and dropped from package:
  - user facing change: minimum policy: modules base and contrib are merged into modules.lst
    and modules-enabled.lst was added which contains the enabled modules, replacing modules-minimum-disable.lst
    * modules-minimum-base.conf
    * modules-minimum-contrib.conf
    * modules-minimum-disable.lst
    * Added: modules-minimum.lst
  - user facing change: mls policy: modules base + contrib are merged into modules.lst
    * modules-mls-base.conf
    * modules-mls-contrib.conf
  - user facing change: targeted policy: modules base + contrib are merged into modules.lst:
    * modules-targeted-base.conf
    * modules-targeted-contrib.conf
  - Moved securetty config to config/appconfig-<policytype>/securetty_types and dropped from package
  - user facing change: using upstream version for all policy types
    * securetty_types-minimum
    * securetty_types-mls
    * securetty_types-targeted
  - Moved setrans config to dist/<policytype>/setrans.conf and dropped from package
    * setrans-minimum.conf
    * setrans-mls.conf
    * setrans-targeted.conf
  - Moved users config to dist/<policytype>/users and dropped from package
    * users-minimum
  - user facing change: added guest_u and xguest_u
    * users-mls
    * users-targeted
  - Fix debug-build.sh to follow symlinks when creating
    the tarball
  - Update embedded container-selinux version to commit:
    * 3f06c141bebc00a07eec4c0ded038aac4f2ae3f0
  - Sync modules-targeted-contrib.conf with Fedora targeted modules.conf
  - Disable build of the MLS policy. We currently don't know if it works
    and don't want to encourage users to apply it
  - Enable named_write_master_zones boolean by default (bsc#1229479)
  - Update to version 20240604+git675.f1f499c0:
    * Revert "Remove the fail2ban module sources"
    * Revert "Remove the linuxptp module sources"
    * Revert "Remove the amtu module sources"
    * Allow vhostmd_t list virtqemud pid dirs (bsc#1230961)
    * Allow auditctl signal auditd
    * Dontaudit systemd-coredump the sys_resource capability
    * Allow traceroute_t bind rawip sockets to unreserved ports
    * Fix the cups_read_pid_files() interface to use read_files_pattern
    * Allow virtqemud additional permissions for tmpfs_t blk devices
    * Allow virtqemud rw access to svirt_image_t chr files
    * Allow virtqemud rw and setattr access to fixed block devices
    * Label /etc/mdevctl.d/scripts.d with bin_t
    * Allow virtqemud open svirt_devpts_t char files
    * Allow virtqemud relabelfrom virt_log_t files
    * Allow svirt_tcg_t read virtqemud_t fifo_files
    * Allow virtqemud rw and setattr access to sev devices
    * Allow virtqemud directly read and write to a fixed disk
    * Allow virtqemud_t relabel virt_var_lib_t files
    * Allow virtqemud_t relabel virtqemud_var_run_t sock_files
    * Add gnome_filetrans_gstreamer_admin_home_content() interface
    * Label /dev/swradio, /dev/v4l-subdev, /dev/v4l-touch with v4l_device_t
    * Make bootupd_t permissive
    * Allow init_t nnp domain transition to locate_t
    * allow gdm and iiosensorproxy talk to each other via D-bus
    * Allow systemd-journald getattr nsfs files
    * Allow sendmail to map mail server configuration files
    * Allow procmail to read mail aliases
    * Allow cifs.idmap helper to set attributes on kernel keys
    * Allow irqbalance setpcap capability in the user namespace
    * Allow sssd_selinux_manager_t the setcap process permission
    * Allow systemd-sleep manage efivarfs files
    * Allow systemd-related domains getattr nsfs files
    * Allow svirt_t the sys_rawio capability
    * Allow alsa watch generic device directories
    * Move systemd-homed interfaces to seperate optional_policy block
    * Move systemd-homed interfaces to seperate optional_policy block (bsc#1234228)
    * Update samba-bgqd policy
    * Update virtlogd policy
    * Allow svirt_t the sys_rawio capability
    * Allow qemu-ga the dac_override and dac_read_search capabilities
    * Add policy for importctl (bsc#1232670)
    * adjust kandim binary paths (bsc#1232328)
    * Allow bacula execute container in the container domain
    * Allow httpd get attributes of dirsrv unit files
    * Allow samba-bgqd read cups config files
    * Add label rshim_var_run_t for /run/rshim.pid
    * [5/5][sync from 'mysql-selinux'] Add mariadb-backup
    * [4/5][sync from 'mysql-selinux'] Fix regex to also match '/var/lib/mysql/mysqlx.sock'
    * [3/5][sync from 'mysql-selinux'] Allow mysqld_t to read and write to the 'memory.pressure' file in cgroup2
    * [2/5][sync from 'mysql-selinux'] 2nd attempt to fix rhbz#2186996 rhbz#2221433 rhbz#2245705
    * [1/5][sync from 'mysql-selinux'] Allow 'mysqld' to use '/usr/bin/hostname'
    * Allow systemd-networkd read mount pid files
    * Update policy for samba-bgqd
    * Allow chronyd read networkmanager's pid files
    * Allow staff user connect to generic tcp ports
    * Allow gnome-remote-desktop dbus chat with policykit
    * Allow tlp the setpgid process permission
    * Update the bootupd policy
    * Allow sysadm_t use the io_uring API
    * Allow sysadm user dbus chat with virt-dbus
    * Allow virtqemud_t read virsh_t files
    * Allow virt_dbus_t connect to virtd_t over a unix stream socket
    * Allow systemd-tpm2-generator read hardware state information
    * Allow coreos-installer-generator execute generic programs
    * Allow coreos-installer domain transition on udev execution
    * Add workaround for /run/rpmdb lockfile (bsc#1231127)
    * Add dedicated health-checker module (bsc#1231127)
    * Revert "Allow unconfined_t execute kmod in the kmod domain"
    * Allow iio-sensor-proxy create and use unix dgram socket
    * Allow virtstoraged read vm sysctls
    * Support ssh connections via systemd-ssh-generator
    * Label all semanage store files in /etc as semanage_store_t
    * Add file transition for nvidia-modeset
    * Re-add kanidm module to dist/targeted/modules.conf
    * Add SUSE-specific file contexts to file_contexts.subs_dist
    * Disallow execstack in dist/minimum/booleans.conf
    * Add SUSE-specific booleans to dist/targeted/booleans.conf
    * Add SUSE specific modules to targeted modules.conf
    * Label /var/cache/systemd/home with systemd_homed_cache_t
    * Allow login_userdomain connect to systemd-homed over a unix socket
    * Allow boothd connect to systemd-homed over a unix socket
    * Allow systemd-homed get attributes of a tmpfs filesystem
    * Allow abrt-dump-journal-core connect to systemd-homed over a unix socket
    * Allow aide connect to systemd-homed over a unix socket
    * Label /dev/hfi1_[0-9]+ devices
    * Remove the openct module sources
    * Remove the timidity module sources
    * Enable the slrn module
    * Remove i18n_input module sources
    * Enable the distcc module
    * Remove the ddcprobe module sources
    * Remove the timedatex module sources
    * Remove the djbdns module sources
    * Confine iio-sensor-proxy
    * Allow staff user nlmsg_write
    * Update policy for xdm with confined users
    * Allow virtnodedev watch mdevctl config dirs
    * Allow ssh watch home config dirs
    * Allow ssh map home configs files
    * Allow ssh read network sysctls
    * Allow chronyc sendto to chronyd-restricted
    * Allow cups sys_ptrace capability in the user namespace
    * Add policy for systemd-homed
    * Remove fc entry for /usr/bin/pump
    * Label /usr/bin/noping and /usr/bin/oping with ping_exec_t
    * Allow accountsd read gnome-initial-setup tmp files
    * Allow xdm write to gnome-initial-setup fifo files
    * Allow rngd read and write generic usb devices
    * Allow qatlib search the content of the kernel debugging filesystem
    * Allow qatlib connect to systemd-machined over a unix socket
    * mls/modules.conf - fix typo
    * Use dist/targeted/modules.conf in build workflow
    * Fix default and dist config files
    * Allow unprivileged user watch /run/systemd
    * CI: update to actions/checkout@v4
    * Allow boothd connect to kernel over a unix socket
    * Clean up and sync securetty_types
    * Bring config files from dist-git into the source repo
    * Confine gnome-remote-desktop
    * Allow virtstoraged execute mount programs in the mount domain
    * Make mdevctl_conf_t member of the file_type attribute
    * Allow virt_dbus_t to connect to virtd_t over unix_stream_socket (bsc#1232655)
    * Label /var/livepatches as lib_t for ULP on micro (bsc#1228879)
    * Allow dirsrv-snmp map dirsv_tmpfs_t files
    * Label /usr/lib/node_modules_22/npm/bin with bin_t
    * Add policy for /usr/libexec/samba/samba-bgqd
    * Allow gnome-remote-desktop watch /etc directory
    * Allow rpcd read network sysctls
    * Allow journalctl connect to systemd-userdbd over a unix socket
    * Allow some confined users send to lldpad over a unix dgram socket
    * Allow lldpad send to unconfined_t over a unix dgram socket
    * Allow lldpd connect to systemd-machined over a unix socket
    * Confine the ktls service
    * Allow dirsrv read network sysctls
    * Label /run/sssd with sssd_var_run_t
    * Label /etc/sysctl.d and /run/sysctl.d with system_conf_t
    * Allow unconfined_t execute kmod in the kmod domain
    * Allow confined users r/w to screen unix stream socket
    * Label /root/.screenrc and /root/.tmux.conf with screen_home_t
    * Allow virtqemud read virtd_t files
    * Allow ping_t read network sysctls
    * Allow systemd-homework connect to init over a unix socket
    * Fix systemd-homed blobs directory permissions
    * Allow virtqemud read sgx_vepc devices
    * Allow lldpad create and use netlink_generic_socket
    * Allow snapperd to execute systemctl (bsc#1231489)
    * rsync: add rsync_exec_commands boolean and enable it by default (bsc#1231494)
    * Allow slpd to create TCPDIAG netlink socket (bsc#1231491)
    * Allow slpd to use sys_chroot (bsc#1231491)
    * Allow openvswitch-ipsec use strongswan (bsc#1231493)
    * Allow systemd-homework write to init pid socket
    * Allow init create /var/cache/systemd/home
    * Confine the pcm service
    * Allow login_userdomain read thumb tmp files
    * Update power-profiles-daemon policy
    * Fix the /etc/mdevctl\.d(/.*)? regexp
    * Grant rhsmcertd chown capability & userdb access
    * Allow iio-sensor-proxy the bpf capability
    * Allow systemd-machined the kill user-namespace capability
    * Remove the fail2ban module sources
    * Remove the linuxptp module sources
    * Remove legacy rules for slrnpull
    * Remove the aiccu module sources
    * Remove the bcfg2 module sources
    * Remove the amtu module sources
    * Remove the rhev module sources
    * Remove all file context entries for /bin and /lib
    * Allow ptp4l the sys_admin capability
    * Confine power-profiles-daemon
    * Label /var/cache/systemd/home with systemd_homed_cache_t
    * Allow login_userdomain connect to systemd-homed over a unix socket
    * Allow boothd connect to systemd-homed over a unix socket
    * Allow systemd-homed get attributes of a tmpfs filesystem
    * Allow abrt-dump-journal-core connect to systemd-homed over a unix socket
    * Allow aide connect to systemd-homed over a unix socket
    * Label /dev/hfi1_[0-9]+ devices
    * Remove the openct module sources
    * Remove the timidity module sources
    * Enable the slrn module
    * Remove i18n_input module sources
    * Enable the distcc module
    * Remove the ddcprobe module sources
    * Remove the timedatex module sources
    * Remove the djbdns module sources
    * Confine iio-sensor-proxy
    * Allow staff user nlmsg_write
    * Update policy for xdm with confined users
    * Allow virtnodedev watch mdevctl config dirs
    * Allow ssh watch home config dirs
    * Allow ssh map home configs files
    * Allow ssh read network sysctls
    * Allow chronyc sendto to chronyd-restricted
    * Allow cups sys_ptrace capability in the user namespace
    * Label auutyast binaries correctly
    * Allow snapperd to manage unlabeled_t files (bsc#1230966)
    * Add policy for systemd-homed
    * Revert "Allow virtstoraged to manage images (bsc#1228742)"
    * Remove fc entry for /usr/bin/pump
    * Label /usr/bin/noping and /usr/bin/oping with ping_exec_t
    * Allow accountsd read gnome-initial-setup tmp files
    * Allow xdm write to gnome-initial-setup fifo files
    * Allow rngd read and write generic usb devices
    * Allow qatlib search the content of the kernel debugging filesystem
    * Allow qatlib connect to systemd-machined over a unix socket
    * mls/modules.conf - fix typo
    * Use dist/targeted/modules.conf in build workflow
    * Fix default and dist config files
    * Allow unprivileged user watch /run/systemd
    * CI: update to actions/checkout@v4
    * Allow boothd connect to kernel over a unix socket
    * Clean up and sync securetty_types
    * Bring config files from dist-git into the source repo
    * Confine gnome-remote-desktop
    * Allow systemd_ibft_rule_generator_t to create udev_rules_t dirs (bsc#1230011)
    * Allow virtstoraged execute mount programs in the mount domain
    * Make mdevctl_conf_t member of the file_type attribute
    * Allow systemd_udev_trigger_generator_t list and read sysctls (bsc#1230315)
    * Initial policy for udev-trigger-generator (bsc#1230315)
    * Allow init_t mount syslog socket (bsc#1230134)
    * Allow init_t create syslog files (bsc#1230134)
    * Introduce initial policy for btrfs-soft-reboot-generator (bsc#1230134)
    * Label /etc/mdevctl.d with mdevctl_conf_t
    * Sync users with Fedora targeted users
    * Update policy for rpc-virtstorage
    * Allow virtstoraged get attributes of configfs dirs
    * Fix SELinux policy for sandbox X server to fix 'sandbox -X' command
    * Update bootupd policy when ESP is not mounted
    * Allow thumb_t map dri devices
    * Allow samba use the io_uring API
    * Allow the sysadm user use the secretmem API
    * Allow nut-upsmon read systemd-logind session files
    * Allow sysadm_t to create PF_KEY sockets
    * Update bootupd policy for the removing-state-file test
    * Allow xen to use qemu as dom0 disk backend (bsc#1228540)
    * Label /var/lib/xen/xenstore as xenstored_var_lib_t (bsc#1228540)
    * Allow coreos-installer-generator manage mdadm_conf_t files
    * Allow virtstoraged to manage images (bsc#1228742)
    * Allow virtstoraged_t domtrans to udev (bsc#1228742)
    * Allow setsebool_t relabel selinux data files
    * Allow virtqemud relabelfrom virtqemud_var_run_t dirs
    * Use better escape method for "interface"
    * Allow init and systemd-logind to inherit fds from sshd
    * Allow systemd-ssh-generator read sysctl files
    * Sync modules.conf with Fedora targeted modules
    * Allow systemd-ssh-generator to load net-pf-40 (bsc#1229766)
    * Allow virtqemud relabel user tmp files and socket files
    * Add missing sys_chroot capability to groupadd policy
    * Label /run/libvirt/qemu/channel with virtqemud_var_run_t
    * Allow rasdaemon write access to sysfs (bsc#1229587)
    * Allow xl to access hypercall interfaces to xen hypervisor (bsc#1228540)
    * Initial policy for syslog-ng (bsc#1229153)
    * Allow virtqemud relabelfrom also for file and sock_file
    * Add virt_create_log() and virt_write_log() interfaces
    * allow sshd_t and sshd_net_t access to ssh vsockets (bsc#1228831)

++++ sysvinit:

  - Update to sysvinit 3.13
    * Adjusted manual page install location. Patch provided
    by Mark Hindley.
    sysvinit (3.12) released; urgency=low
    * There were instances of the ctime() function being called in multiple files without
    checking the return value (can be NULL) and without checking the length of the
    returned information. While there _should_ never be a case where ctime() fails
    assuming success and length of returned string isn't ideal (or future-proof).
    We now check the return value of ctime() in bootlogd, dowall, last, logsave, and
    shutdown. Where no valid value is returned we supply a dummy value (usually a
    space in place of the expected time stamp). We also no longer assume returned string
    is at least 11-16 characters.
    * Re-commit flexible Makefile for GoboLinux.
    * Make sure pty.h and sys/sysmacros.h are included when building bootlogd on
    systems with glibc.
    * Fixed typos and syntax in manual page for init.8.
    Edits provided by : Bjarni Ingi Gislason.
    * Allow setting of location of the /usr directory in src/Makefile.
    This is handled by the usrdir variable.
    * Make sure src/Makefile uses sysconfdir (/etc by default) when installing
    configuration files.
    * Fix typos and syntax in pidof manual page.
  - Port patches
    * sysvinit-2.88dsf-suse.patch
    * sysvinit-2.90.dif

------------------------------------------------------------------
------------------  2025-1-8  -  Jan 8 2025  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Update to version 2.32.2:
    * remove engine v25 from e2e test matrix The 1st version
    available for Ubuntu 24.x is Docker Engine v26
    * fix relative path in compose file
    * bump compose-go to v2.4.7
    * replace tibdex/github-app-token by official GitHub
    create-github-app-token
    * bump golang.org/x/net to v0.33.0 to fix potential security
    issue https://github.com/golang/go/issues/70906
    * checkExpectedVolumes must ignore anonymous volumes
    * When retrying to resolveOrCreateNetwork, retry with a valid
    network name
    * only check bind mount conflict if sync action is involved
    * use the 3 latest major versions of the engine to run e2e step
    * bump Golang version to v1.22.10 and update CI actions
    * add --pull to run command
    * CI to validate fmt
    * `make fmt` so any contributor can enforce formatting
    * format code with gofumpt

++++ python-kiwi:

  - Added LUKS reencryption support
    Added rd.kiwi.oem.luks.reencrypt boot option consumed by the
    kiwi-repart dracut module. For OEM LUKS2 encrypted disk images.
    If set, reencrypts the disk prior an eventual resize and therefore
    creates a new key pool and master key. The reencryption is advisable
    if the image binary is not protected. With access to the image
    binary it's possible to extract the luks header which then allows to
    decrypt the data unless it was reencrypted. The reencryption process
    only runs if the checksum of the luks header still matches the one
    from the original disk image. Be aware that the reencryption will
    ask for the passphrase if the image has been built with an initial
    luks passphrase.
  - Fixed arm/tumbleweed/test-image-rpi
    No ruby required for this integration test build

++++ drbd:

  - fix the warning of blk_validate_limits when running drbdadm down (boo#1235399)
    * add patch
    boo1235399-fix_the_warning_of_blk_validate_limits.patch

++++ drbd-utils:

  - Update drbd-utils from 9.25.0 to 9.29.0
    * Changelog from Linbit:
    9.29.0
  - ----------
    * drbdmeta: fix initialization for external md
    * build: allow disbling keyutils
    * tests: export sanitized environment
    * drbdmon: various improvements
    * build: add cyclonedx
    * drbsetup,v9: fix multiple paths drbdsetup show --json
    strictly spreaking breaking change, but maily used internally
    * events2: expose if device is open
    * drbdadm: fix undefined behavior that triggered on amd64
    * shared: fix out-of-bounds access in parsing
    * drbsetup,v9: event consistency with peer devices
    * drbdadm: fix parsing of v8.4 configs for compatibility
    * drbdmeta: fix segfault for check-resize on intentionally diskless
    * drbd-promote@.service: check if ExecCondition is available
    9.28.0
  - ----------
    * events2: set may_promote:no promotion_score:0 while
    force-io-failure:yes
    * drbdsetup,v9: show TLS in connection status
    * drbdsetup,v9: add udev command
    * 8.3: remove
    * crm-fence-peer.9.sh: fixes for pacemaker 2.1.7
    * events2: improved out of order message handling
    9.27.0
  - ----------
    * adjust,v9: retry for diskless primaries
    * tests: sanitize env (e.g., TZ)
    * drbdmeta: dump and restore the members field
    9.26.0
  - ----------
    * config,v9: new config option load-balance-paths
    * config,v9: new config options rdma-ctrls-(snd|rcv)buf-size
    * drbdadm,v9: fix segfault if proxy has no path
    * drbd: increase maximum CPU mask size
    * systemd: introduce drbd-graceful-shutdown.service
    * drbdmeta,v9: fix regression, allow attach after offline resize
    * drbdsetup,v9: add path established information to JSON status
    * events2: terminate on module unload even under --poll
    * events2: specif exit code if module unload
    * docs: add spdx license file
    * drbdmon: various smaller improvements
    * drbdsetup,v9: support for TLS/kTLS
    * remove patches which are already included in upstream code:
    0001-drbdadm-v9-do-not-segfault-when-re-configuring-proxy.patch
    0002-user-drbrdmon-add-missing-stdint.h-includes.patch
    0003-Introduce-default_types.h-header.patch
    bsc-1219263_crm-fence-peer.9.sh-fix-parsing-in_ccm-crmd-fields-o.patch
    bsc-1219263_crm-fence-peer.9.sh-use-join-of-node_state-to-judge-.patch
    bsc-1233273_drbd.ocf-update-regex-of-sed-for-new-output-from-crm.patch
    usrmerge_move_lib_to_prefix_lib.patch
    * add upstream patches to align commit 0a014f290802:
    0001-drbd-verify.py-relax-host-key-checking.patch
    0002-DRBDmon-Disabled-DRBD-commands-warning-only-for-actu.patch
    0003-DRBDmon-Integrate-global-local-command-delegation.patch
    0004-DRBDmon-Adjust-events-log-supplier-program-name.patch
    0005-DRBDmon-Add-drbd-events-log-supplier.patch
    0006-DRBDmon-Adjust-Makefile.patch
    0007-DRBDmon-Version-V1R4M1.patch
    0008-drbdadm-add-proxy-options-to-add-connection-command.patch
    0009-Do-not-hardcode-paths-in-services-and-scripts.patch
    0010-Fix-typo-in-warning-there-is-no-po4a-translage-comma.patch
    0011-drbd.ocf-explicitly-timeout-crm_master-IPC-early.patch
    0012-drbd.ocf-the-text-output-of-crm_resource-locate-has-.patch
    * update patches according to source code changes:
    bsc-1233273_drbd.ocf-replace-crm_master-with-ocf_promotion_score.patch
    fence-after-pacemaker-down.patch
    * modify upstream patch for passing build:
    0009-Do-not-hardcode-paths-in-services-and-scripts.patch
    * add new service:
    drbd-graceful-shutdown.service
    * add new binrary:
    drbd-events-log-supplier

++++ glib-networking:

  - Update to version 2.80.1:
    + OpenSSL:
  - Fix crash in complete_handshake
  - Fix invalid free in
    openssl_get_binding_tls_server_end_point()
    + TLS test should handle G_IO_ERROR_WOULD_BLOCK
    + Updated translations.

++++ hwdata:

  - Update to version 0.391:
    * Update pci and vendor ids

++++ kernel-default:

  - powerpc/book3s64/hugetlb: Fix disabling hugetlb when fadump
    is active (bsc#1235108).
  - commit 8c55a2a
  - nvmet-loop: avoid using mutex in IO hotpath (git-fixes).
  - nvmet: Don't overflow subsysnqn (git-fixes).
  - nvme-pci: 512 byte aligned dma pool segment quirk (git-fixes).
  - nvme-rdma: unquiesce admin_q before destroy it (git-fixes).
  - nvme-tcp: fix the memleak while create new ctrl failed
    (git-fixes).
  - nvme-fabrics: handle zero MAXCMD without closing the connection
    (git-fixes).
  - nvme: don't apply NVME_QUIRK_DEALLOCATE_ZEROES when DSM is
    not supported (git-fixes).
  - nvmet-loop: avoid using mutex in IO hotpath (git-fixes).
  - nvmet: Don't overflow subsysnqn (git-fixes).
  - nvme-pci: 512 byte aligned dma pool segment quirk (git-fixes).
  - nvme-rdma: unquiesce admin_q before destroy it (git-fixes).
  - nvme-tcp: fix the memleak while create new ctrl failed
    (git-fixes).
  - nvme-fabrics: handle zero MAXCMD without closing the connection
    (git-fixes).
  - nvme: don't apply NVME_QUIRK_DEALLOCATE_ZEROES when DSM is
    not supported (git-fixes).
  - commit 64d03b4
  - workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work
    from !WQ_MEM_RECLAIM worker (bsc#1235416).
  - commit d1a20d8
  - btrfs: fix use-after-free waiting for encoded read endios (bsc#1235128)
  - commit faccece
  - scsi: lpfc: Copyright updates for 14.4.0.7 patches
    (bsc#1235409).
  - scsi: lpfc: Update lpfc version to 14.4.0.7 (bsc#1235409).
  - scsi: lpfc: Add support for large fw object application layer
    reads (bsc#1235409).
  - scsi: lpfc: Update definition of firmware configuration mbox
    cmds (bsc#1235409).
  - scsi: lpfc: Change lpfc_nodelist save_flags member into a
    bitmask (bsc#1235409).
  - scsi: lpfc: Add handling for LS_RJT reason explanation
    authentication required (bsc#1235409).
  - scsi: lpfc: Modify handling of ADISC based on ndlp state and
    RPI registration (bsc#1235409).
  - scsi: lpfc: Delete NLP_TARGET_REMOVE flag due to obsolete usage
    (bsc#1235409).
  - scsi: lpfc: Restrict the REG_FCFI MAM field to FCoE adapters
    only (bsc#1235409).
  - scsi: lpfc: Redefine incorrect type in lpfc_create_device_data()
    (bsc#1235409).
  - scsi: lpfc: Copyright updates for 14.4.0.7 patches
    (bsc#1235409).
  - scsi: lpfc: Update lpfc version to 14.4.0.7 (bsc#1235409).
  - scsi: lpfc: Add support for large fw object application layer
    reads (bsc#1235409).
  - scsi: lpfc: Update definition of firmware configuration mbox
    cmds (bsc#1235409).
  - scsi: lpfc: Change lpfc_nodelist save_flags member into a
    bitmask (bsc#1235409).
  - scsi: lpfc: Add handling for LS_RJT reason explanation
    authentication required (bsc#1235409).
  - scsi: lpfc: Modify handling of ADISC based on ndlp state and
    RPI registration (bsc#1235409).
  - scsi: lpfc: Delete NLP_TARGET_REMOVE flag due to obsolete usage
    (bsc#1235409).
  - scsi: lpfc: Restrict the REG_FCFI MAM field to FCoE adapters
    only (bsc#1235409).
  - scsi: lpfc: Redefine incorrect type in lpfc_create_device_data()
    (bsc#1235409).
  - commit a46e8c0
  - btrfs: fix use-after-free in btrfs_encoded_read_endio() (CVE-2024-56582 bsc#1235128)
  - commit c77e8af
  - PCI/TPH: Add TPH documentation (jsc#PED-11562).
  - PCI/TPH: Add Steering Tag support (jsc#PED-11562).
  - PCI: Add TLP Processing Hints (TPH) support (jsc#PED-11562).
  - Update config files (CONFIG_PCIE_TPH=y).
  - commit bd308e1
  - scsi: qla2xxx: Update version to 10.02.09.400-k (bsc#1235406).
  - scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
    (bsc#1235406).
  - scsi: qla2xxx: Fix NVMe and NPIV connect issue (bsc#1235406).
  - scsi: qla2xxx: Remove check req_sg_cnt should be equal to
    rsp_sg_cnt (bsc#1235406).
  - scsi: qla2xxx: Fix use after free on unload (bsc#1235406).
  - scsi: qla2xxx: Fix abort in bsg timeout (bsc#1235406).
  - scsi: qla2xxx: Update version to 10.02.09.400-k (bsc#1235406).
  - scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
    (bsc#1235406).
  - scsi: qla2xxx: Fix NVMe and NPIV connect issue (bsc#1235406).
  - scsi: qla2xxx: Remove check req_sg_cnt should be equal to
    rsp_sg_cnt (bsc#1235406).
  - scsi: qla2xxx: Fix use after free on unload (bsc#1235406).
  - scsi: qla2xxx: Fix abort in bsg timeout (bsc#1235406).
  - commit e644331
  - vfio/pci: Properly hide first-in-list PCIe extended capability
    (bsc#1235004 CVE-2024-53214).
  - commit 989377b
  - fs: fix is_mnt_ns_file() (git-fixes).
  - commit f76cd98
  - erofs: use buffered I/O for file-backed mounts by default
    (git-fixes).
  - commit 699c7cc
  - erofs: reference `struct erofs_device_info` for erofs_map_dev
    (git-fixes).
  - commit c6ac991
  - erofs: use `struct erofs_device_info` for the primary device
    (git-fixes).
  - commit 426336f
  - erofs: add erofs_sb_free() helper (git-fixes).
  - commit 468b714
  - nfs: Fix oops in nfs_netfs_init_request() when copying to cache
    (git-fixes).
  - commit d2c36d1
  - netfs: Fix is-caching check in read-retry (git-fixes).
  - commit d3ca9e7
  - netfs: Fix the (non-)cancellation of copy when cache is
    temporarily disabled (git-fixes).
  - commit b8f5973
  - netfs: Fix ceph copy to cache on write-begin (git-fixes).
  - commit 4931632
  - netfs: Fix missing barriers by using clear_and_wake_up_bit()
    (git-fixes).
  - commit 59b3732
  - netfs: Fix enomem handling in buffered reads (git-fixes).
  - commit d3c3d24
  - exfat: fix the infinite loop in __exfat_free_cluster()
    (git-fixes).
  - commit 32d6d4e
  - exfat: fix the new buffer was not zeroed before writing
    (git-fixes).
  - commit faf023a
  - exfat: fix the infinite loop in exfat_readdir() (git-fixes).
  - commit 5136005
  - dlm: fix possible lkb_resource null dereference (git-fixes).
  - commit 490216a

++++ kernel-rt:

  - powerpc/book3s64/hugetlb: Fix disabling hugetlb when fadump
    is active (bsc#1235108).
  - commit 8c55a2a
  - nvmet-loop: avoid using mutex in IO hotpath (git-fixes).
  - nvmet: Don't overflow subsysnqn (git-fixes).
  - nvme-pci: 512 byte aligned dma pool segment quirk (git-fixes).
  - nvme-rdma: unquiesce admin_q before destroy it (git-fixes).
  - nvme-tcp: fix the memleak while create new ctrl failed
    (git-fixes).
  - nvme-fabrics: handle zero MAXCMD without closing the connection
    (git-fixes).
  - nvme: don't apply NVME_QUIRK_DEALLOCATE_ZEROES when DSM is
    not supported (git-fixes).
  - nvmet-loop: avoid using mutex in IO hotpath (git-fixes).
  - nvmet: Don't overflow subsysnqn (git-fixes).
  - nvme-pci: 512 byte aligned dma pool segment quirk (git-fixes).
  - nvme-rdma: unquiesce admin_q before destroy it (git-fixes).
  - nvme-tcp: fix the memleak while create new ctrl failed
    (git-fixes).
  - nvme-fabrics: handle zero MAXCMD without closing the connection
    (git-fixes).
  - nvme: don't apply NVME_QUIRK_DEALLOCATE_ZEROES when DSM is
    not supported (git-fixes).
  - commit 64d03b4
  - workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work
    from !WQ_MEM_RECLAIM worker (bsc#1235416).
  - commit d1a20d8
  - btrfs: fix use-after-free waiting for encoded read endios (bsc#1235128)
  - commit faccece
  - scsi: lpfc: Copyright updates for 14.4.0.7 patches
    (bsc#1235409).
  - scsi: lpfc: Update lpfc version to 14.4.0.7 (bsc#1235409).
  - scsi: lpfc: Add support for large fw object application layer
    reads (bsc#1235409).
  - scsi: lpfc: Update definition of firmware configuration mbox
    cmds (bsc#1235409).
  - scsi: lpfc: Change lpfc_nodelist save_flags member into a
    bitmask (bsc#1235409).
  - scsi: lpfc: Add handling for LS_RJT reason explanation
    authentication required (bsc#1235409).
  - scsi: lpfc: Modify handling of ADISC based on ndlp state and
    RPI registration (bsc#1235409).
  - scsi: lpfc: Delete NLP_TARGET_REMOVE flag due to obsolete usage
    (bsc#1235409).
  - scsi: lpfc: Restrict the REG_FCFI MAM field to FCoE adapters
    only (bsc#1235409).
  - scsi: lpfc: Redefine incorrect type in lpfc_create_device_data()
    (bsc#1235409).
  - scsi: lpfc: Copyright updates for 14.4.0.7 patches
    (bsc#1235409).
  - scsi: lpfc: Update lpfc version to 14.4.0.7 (bsc#1235409).
  - scsi: lpfc: Add support for large fw object application layer
    reads (bsc#1235409).
  - scsi: lpfc: Update definition of firmware configuration mbox
    cmds (bsc#1235409).
  - scsi: lpfc: Change lpfc_nodelist save_flags member into a
    bitmask (bsc#1235409).
  - scsi: lpfc: Add handling for LS_RJT reason explanation
    authentication required (bsc#1235409).
  - scsi: lpfc: Modify handling of ADISC based on ndlp state and
    RPI registration (bsc#1235409).
  - scsi: lpfc: Delete NLP_TARGET_REMOVE flag due to obsolete usage
    (bsc#1235409).
  - scsi: lpfc: Restrict the REG_FCFI MAM field to FCoE adapters
    only (bsc#1235409).
  - scsi: lpfc: Redefine incorrect type in lpfc_create_device_data()
    (bsc#1235409).
  - commit a46e8c0
  - btrfs: fix use-after-free in btrfs_encoded_read_endio() (CVE-2024-56582 bsc#1235128)
  - commit c77e8af
  - PCI/TPH: Add TPH documentation (jsc#PED-11562).
  - PCI/TPH: Add Steering Tag support (jsc#PED-11562).
  - PCI: Add TLP Processing Hints (TPH) support (jsc#PED-11562).
  - Update config files (CONFIG_PCIE_TPH=y).
  - commit bd308e1
  - scsi: qla2xxx: Update version to 10.02.09.400-k (bsc#1235406).
  - scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
    (bsc#1235406).
  - scsi: qla2xxx: Fix NVMe and NPIV connect issue (bsc#1235406).
  - scsi: qla2xxx: Remove check req_sg_cnt should be equal to
    rsp_sg_cnt (bsc#1235406).
  - scsi: qla2xxx: Fix use after free on unload (bsc#1235406).
  - scsi: qla2xxx: Fix abort in bsg timeout (bsc#1235406).
  - scsi: qla2xxx: Update version to 10.02.09.400-k (bsc#1235406).
  - scsi: qla2xxx: Supported speed displayed incorrectly for VPorts
    (bsc#1235406).
  - scsi: qla2xxx: Fix NVMe and NPIV connect issue (bsc#1235406).
  - scsi: qla2xxx: Remove check req_sg_cnt should be equal to
    rsp_sg_cnt (bsc#1235406).
  - scsi: qla2xxx: Fix use after free on unload (bsc#1235406).
  - scsi: qla2xxx: Fix abort in bsg timeout (bsc#1235406).
  - commit e644331
  - vfio/pci: Properly hide first-in-list PCIe extended capability
    (bsc#1235004 CVE-2024-53214).
  - commit 989377b
  - fs: fix is_mnt_ns_file() (git-fixes).
  - commit f76cd98
  - erofs: use buffered I/O for file-backed mounts by default
    (git-fixes).
  - commit 699c7cc
  - erofs: reference `struct erofs_device_info` for erofs_map_dev
    (git-fixes).
  - commit c6ac991
  - erofs: use `struct erofs_device_info` for the primary device
    (git-fixes).
  - commit 426336f
  - erofs: add erofs_sb_free() helper (git-fixes).
  - commit 468b714
  - nfs: Fix oops in nfs_netfs_init_request() when copying to cache
    (git-fixes).
  - commit d2c36d1
  - netfs: Fix is-caching check in read-retry (git-fixes).
  - commit d3ca9e7
  - netfs: Fix the (non-)cancellation of copy when cache is
    temporarily disabled (git-fixes).
  - commit b8f5973
  - netfs: Fix ceph copy to cache on write-begin (git-fixes).
  - commit 4931632
  - netfs: Fix missing barriers by using clear_and_wake_up_bit()
    (git-fixes).
  - commit 59b3732
  - netfs: Fix enomem handling in buffered reads (git-fixes).
  - commit d3c3d24
  - exfat: fix the infinite loop in __exfat_free_cluster()
    (git-fixes).
  - commit 32d6d4e
  - exfat: fix the new buffer was not zeroed before writing
    (git-fixes).
  - commit faf023a
  - exfat: fix the infinite loop in exfat_readdir() (git-fixes).
  - commit 5136005
  - dlm: fix possible lkb_resource null dereference (git-fixes).
  - commit 490216a

++++ systemd:

  - Import commit 7fa3b5018bfffa176c77a2a5794dce792eebadcb (merge of v257.2)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/47eea9ee9f46537bc18d6a64fa21fd9c50538e13...7fa3b5018bfffa176c77a2a5794dce792eebadcb

++++ libvirt:

  - Convert from tar_scm to obs_scm: allow OBS internal data
    structure to be more efficient by using .obscpio files

++++ rt-tests:

  - Update to version 2.8:
    https://lore.kernel.org/linux-rt-users/20241128215059.40116-1-jkacur@redhat.com/
  - Revert back to tar.gz from git.kernel.org (2.7 was moved to "older" subfolder
    in https://mirrors.kernel.org, it shows it's not stable URL).

++++ zypper:

  - info: Allow to query a specific version (jsc#PED-11268)
    To query for a specific version simply append "-<version>" or
    "-<version>-<release>" to the "<name>" pattern. Note that the
    edition part must always match exactly.
  - version 1.14.79

------------------------------------------------------------------
------------------  2025-1-7  -  Jan 7 2025  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Plain zipl loader needs boot partition
    If the rootfs is something zipl cannot read, we need an
    extra boot partition using a supported filesystem
  - Fixed IBM-Cloud-Standard profile
    The test-image-MicroOS integration test builds an IBM-Cloud-Standard
    profile as encrypted variant with a random key that is not protected
    by an encrypted boot image. This doesn't make sense. Thus the
    encryption setup for the IBM cloud standard build got removed.
    Use the IBM-Cloud-Secure-Execution profile to test encrypted
    secure linux builds
  - Fixed test-image-qcow-openstack
    rsh package was dropped from TW

++++ glibc:

  - Correctly determine livepatching support

++++ gstreamer:

  - Update to version 1.24.11:
    + Highlighted bugfixes:
  - playback: Fix SSA/ASS subtitles with embedded fonts
  - decklink: add missing video modes and fix 8K video modes
  - matroskamux: spec compliance fixes for audio-only files
  - onnx: disable onnxruntime telemetry
  - qtdemux: Fix base offset update when doing segment seeks
  - srtpdec: Fix a use-after-free issue
  - (uri)decodebin3: Fix stream change scenarios, possible
    deadlock on shutdown
  - video: fix missing alpha flag in AV12 format description
  - avcodecmap: Add some more channel position mappings
  - cerbero bootstrap fixes for Windows 11
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements
    + gstreamer:
  - No changes.

++++ gstreamer-plugins-base:

  - Update to version 1.24.11:
    + appsrc: Decrease log level for item drop
    + gl: raise WARNING instead of ERROR when no connector is
    connected
    + decodebin3: Free main input even if it is not part of the list
    of inputs
    + urisourcebin:
  - Avoid deadlock on shutdown
  - Only rewrite stream-start event once
  - Reference counting leak
    + urisourcebin/(uri)decodebin3: Fix stream change scenarios
    + playbin3: leak detected with A/V playback and window closed
    + videodecoder:
  - Gracefully handle missing data without prior input segment
  - Set decode only flag by decode only buffer
    video: fix AV12 format lacking the
    GST_VIDEO_FORMAT_FLAG_ALPHA flag
    + Fix SSA/ASS subtitles with embedded fonts

++++ kernel-default:

  - powerpc/pseries/vas: Add close() callback in vas_vm_ops struct
    (bsc#1234825).
  - commit 2674760
  - ethtool: Fix access to uninitialized fields in set RXNFC command
    (git-fixes).
  - net: Make napi_hash_lock irq safe (git-fixes).
  - commit 9fa4e00
  - octeontx2-pf: RVU representor driver (jsc#PED-11317).
  - Update config files.
  - supported.conf: mark new OcteonTx2 submodule rvu_rep supported.
  - commit c4b0aa9
  - testing: net-drv: add basic shaper test (jsc#PED-10419).
  - Update config files.
  - commit 04716f4
  - net: sfc: Correct key_len for efx_tc_ct_zone_ht_params
    (jsc#PED-11366).
  - net/mlx5e: Keep netdev when leave switchdev for devlink set
    legacy only (jsc#PED-11331).
  - net/mlx5e: Skip restore TC rules for vport rep without loaded
    flag (jsc#PED-11331).
  - net/mlx5e: macsec: Maintain TX SA from encoding_sa
    (jsc#PED-11331).
  - net/mlx5: DR, select MSIX vector 0 for completion queue creation
    (jsc#PED-11331).
  - RDMA/mlx5: Enable multiplane mode only when it is supported
    (jsc#PED-11325).
  - RDMA/bnxt_re: Fix error recovery sequence (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix the locking while accessing the QP table
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix MSN table size for variable wqe mode
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Add send queue size check for variable wqe
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Disable use of reserved wqes (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix max_qp_wrs reported (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix reporting hw_ver in query_device
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix to export port num to ib_query_qp
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix setting mandatory attributes for modify_qp
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Add check for path mtu in modify_qp (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix the check for 9060 condition (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Don't fail destroy QP and cleanup debugfs earlier
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Avoid sending the modify QP workaround for latest
    adapters (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Avoid initializing the software queue for user
    queues (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix max SGEs for the Work Request (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/mlx5: Enforce same type port association for multiport RoCE
    (jsc#PED-11325).
  - RDMA/bnxt_re: Remove always true dattr validity check
    (jsc#PED-10682 jsc#PED-11231).
  - octeontx2-pf: fix error handling of devlink port in
    rvu_rep_create() (jsc#PED-11317).
  - octeontx2-pf: fix netdev memory leak in rvu_rep_create()
    (jsc#PED-11317).
  - idpf: trigger SW interrupt when exiting wb_on_itr mode
    (jsc#PED-10581).
  - idpf: add support for SW triggered interrupts (jsc#PED-10581).
  - qed: fix possible uninit pointer read in
    qed_mcp_nvm_info_populate() (jsc#PED-9648 jsc#PED-11293).
  - chelsio/chtls: prevent potential integer overflow on 32bit
    (git-fixes).
  - ionic: use ee->offset when returning sprom data (jsc#PED-11378).
  - ionic: no double destroy workqueue (jsc#PED-11378).
  - ionic: Fix netdev notifier unregister on failure
    (jsc#PED-11378).
  - bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips
    (jsc#PED-10684 jsc#PED-11230).
  - octeontx2-af: Fix installation of PF multicast rule
    (jsc#PED-11317).
  - cxgb4: use port number to set mac addr (git-fixes).
  - bnxt_en: Fix potential crash when dumping FW log coredump
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Fix GSO type for HW GRO packets on 5750X chips
    (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: DR, prevent potential error pointer dereference
    (jsc#PED-11331).
  - bpf, vsock: Invoke proto::close on close() (jsc#PED-11028).
  - bpf, vsock: Fix poll() missing a queue (jsc#PED-11028).
  - igb: Fix potential invalid memory access in igb_init_module()
    (jsc#PED-10426 jsc#PED-10425).
  - ixgbe: Correct BASE-BX10 compliance code (jsc#PED-9647
    jsc#PED-9646).
  - ixgbe: downgrade logging of unsupported VF API version to debug
    (jsc#PED-9647 jsc#PED-9646).
  - ixgbevf: stop attempting IPSEC offload on Mailbox API 1.5
    (jsc#PED-9647 jsc#PED-9646).
  - idpf: set completion tag for "empty" bufs associated with a
    packet (jsc#PED-10581).
  - ice: Fix VLAN pruning in switchdev mode (jsc#PED-10419).
  - ice: Fix NULL pointer dereference in switchdev (jsc#PED-10419).
  - ice: fix PHY timestamp extraction for ETH56G (jsc#PED-10419).
  - ice: fix PHY Clock Recovery availability check (jsc#PED-10419).
  - net/mlx5e: Remove workaround to avoid syndrome for internal port
    (jsc#PED-11331).
  - net/mlx5e: SD, Use correct mdev to build channel param
    (jsc#PED-11331).
  - net/mlx5: E-Switch, Fix switching to switchdev mode in MPV
    (jsc#PED-11331).
  - net/mlx5: E-Switch, Fix switching to switchdev mode with IB
    device disabled (jsc#PED-11331).
  - net/mlx5: HWS: Properly set bwc queue locks lock classes
    (jsc#PED-11331).
  - net/mlx5: HWS: Fix memory leak in mlx5hws_definer_calc_layout
    (jsc#PED-11331).
  - bnxt_en: handle tpa_info in queue API implementation
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: refactor bnxt_alloc_rx_rings() to call
    bnxt_alloc_rx_agg_bmap() (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: refactor tpa_info alloc/free into helpers
    (jsc#PED-10684 jsc#PED-11230).
  - net/qed: allow old cards not supporting "num_images" to work
    (jsc#PED-9648 jsc#PED-11293).
  - octeontx2-af: Fix SDP MAC link credits configuration
    (jsc#PED-11317).
  - bnxt_en: ethtool: Supply ntuple rss context action
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Unregister PTP during PCI shutdown and suspend
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Refactor bnxt_ptp_init() (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Fix receive ring space parameters when XDP is active
    (jsc#PED-10684 jsc#PED-11230 CVE-2024-53209 bsc#1235002).
  - bnxt_en: Fix queue start to update vnic RSS table (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Set backplane link modes correctly for ethtool
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Reserve rings after PCIe AER recovery if NIC interface
    is down (jsc#PED-10684 jsc#PED-11230).
  - octeontx2-af: Quiesce traffic before NIX block reset
    (jsc#PED-11317).
  - octeontx2-af: RPM: fix stale FCFEC counters (jsc#PED-11317).
  - octeontx2-af: RPM: fix stale RSFEC counters (jsc#PED-11317).
  - octeontx2-af: RPM: Fix low network performance (jsc#PED-11317).
  - octeontx2-af: RPM: Fix mismatch in lmac type (jsc#PED-11317).
  - vdpa/mlx5: Fix suboptimal range on iotlb iteration
    (jsc#PED-11331).
  - RDMA/mlx5: Add implementation for ufile_hw_cleanup device
    operation (jsc#PED-11325).
  - RDMA/mlx5: Ensure active slave attachment to the bond IB device
    (jsc#PED-11325).
  - RDMA/mlx5: Call dev_put() after the blocking notifier
    (jsc#PED-11325).
  - RDMA/mlx5: Support querying per-plane IB PortCounters
    (jsc#PED-11325).
  - RDMA/mlx5: Support OOO RX WQE consumption (jsc#PED-11325).
  - net/mlx5: Introduce data placement ordering bits
    (jsc#PED-11331).
  - i40e: Fix handling changed priv flags (jsc#PED-10428).
  - bnxt_en: Add FW trace coredump segments to the coredump
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Add a new ethtool -W dump flag (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Add 2 parameters to bnxt_fill_coredump_seg_hdr()
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Add functions to copy host context memory
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Do not free FW log context memory (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Manage the FW trace context memory (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Allocate backing store memory for FW trace logs
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Add a 'force' parameter to bnxt_free_ctx_mem()
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Refactor bnxt_free_ctx_mem() (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Add mem_valid bit to struct bnxt_ctx_mem_type
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Update firmware interface spec to 1.10.3.85
    (jsc#PED-10684 jsc#PED-11230).
  - e1000: Hold RTNL when e1000_down can be called (jsc#PED-10422).
  - igbvf: remove unused spinlock (jsc#PED-10426 jsc#PED-10425).
  - igb: Fix 2 typos in comments in igb_main.c (jsc#PED-10426
    jsc#PED-10425).
  - igc: remove autoneg parameter from igc_mac_info (jsc#PED-10417).
  - ixgbe: Break include dependency cycle (jsc#PED-9647
    jsc#PED-9646).
  - ice: Unbind the workqueue (jsc#PED-10419).
  - ice: use stack variable for virtchnl_supported_rxdids
    (jsc#PED-10419).
  - ice: initialize pf->supported_rxdids immediately after loading
    DDP (jsc#PED-10419).
  - ice: only allow Tx promiscuous for multicast (jsc#PED-10419).
  - ice: Add support for persistent NAPI config (jsc#PED-10419).
  - ice: support optional flags in signature segment header
    (jsc#PED-10419).
  - ice: refactor "last" segment of DDP pkg (jsc#PED-10419).
  - ice: extend dump serdes equalizer values feature
    (jsc#PED-10419).
  - ice: rework of dump serdes equalizer values feature
    (jsc#PED-10419).
  - ndo_fdb_del: Add a parameter to report whether notification
    was sent (jsc#PED-10419).
  - ndo_fdb_add: Add a parameter to report whether notification
    was sent (jsc#PED-10428).
  - octeontx2-pf: Fix spelling mistake "reprentator" ->
    "representor" (jsc#PED-11317).
  - bnxt_en: optimize gettimex64 (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: only allow set_rxnfc with rss + ring_cookie if
    driver opts in (jsc#PED-11366).
  - octeontx2-pf: Adds TC offload support (jsc#PED-11317).
  - octeontx2-pf: Implement offload stats ndo for representors
    (jsc#PED-11317).
  - octeontx2-pf: Add devlink port support (jsc#PED-11317).
  - octeontx2-pf: Add representors for sdp MAC (jsc#PED-11317).
  - octeontx2-pf: Configure VF mtu via representor (jsc#PED-11317).
  - octeontx2-pf: Add support to sync link state between representor
    and VFs (jsc#PED-11317).
  - octeontx2-pf: Get VF stats via representor (jsc#PED-11317).
  - octeontx2-af: Add packet path between representor and VF
    (jsc#PED-11317).
  - octeontx2-pf: Add basic net_device_ops (jsc#PED-11317).
  - octeontx2-pf: Create representor netdev (jsc#PED-11317).
  - eth: bnxt: use page pool for head frags (jsc#PED-10684
    jsc#PED-11230).
  - net/mlx5e: SHAMPO, Rework header allocation loop
    (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Drop info array (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Change frag page setup order during
    allocation (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Fix page_index calculation inconsistency
    (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Simplify UMR allocation for headers
    (jsc#PED-11331).
  - net/mlx5: Make vport QoS enablement more flexible for future
    extensions (jsc#PED-11331).
  - net/mlx5: Integrate esw_qos_vport_enable logic into rate
    operations (jsc#PED-11331).
  - net/mlx5: Generalize scheduling element operations
    (jsc#PED-11331).
  - net/mlx5: Refactor scheduling element configuration bitmasks
    (jsc#PED-11331).
  - net/mlx5: Generalize max_rate and min_rate setting for nodes
    (jsc#PED-11331).
  - net/mlx5: Simplify QoS normalization by removing error handling
    (jsc#PED-11331).
  - net/mlx5: E-switch, refactor eswitch mode change
    (jsc#PED-11331).
  - bnxt_en: add unlocked version of bnxt_refclk_read (jsc#PED-10684
    jsc#PED-11230).
  - net: atlantic: use irq_update_affinity_hint() (jsc#PED-11287).
  - bnxt_en: use irq_update_affinity_hint() (jsc#PED-10684
    jsc#PED-11230).
  - octeontx2-af: Knobs for NPC default rule counters
    (jsc#PED-11317).
  - octeontx2-af: Refactor few NPC mcam APIs (jsc#PED-11317).
  - mlx5/core: deduplicate {mlx5_,}eq_update_ci() (jsc#PED-11331).
  - mlx5/core: relax memory barrier in eq_update_ci()
    (jsc#PED-11331).
  - bridge: Allow deleting FDB entries with non-existent VLAN
    (jsc#PED-10419).
  - mlx5/core: Schedule EQ comp tasklet only if necessary
    (jsc#PED-11331).
  - net: sfc: use ethtool string helpers (jsc#PED-11366).
  - net: bnx2x: use ethtool string helpers (jsc#PED-10901
    jsc#PED-11308).
  - bnxt_en: ethtool: Support unset l4proto on ip4/ip6 ntuple rules
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: ethtool: Remove ip4/ip6 ntuple support for IPPROTO_RAW
    (jsc#PED-10684 jsc#PED-11230).
  - sfc: Remove more unused functions (jsc#PED-11366).
  - sfc: Remove unused mcdi functions (jsc#PED-11366).
  - sfc: Remove unused efx_mae_mport_vf (jsc#PED-11366).
  - sfc: Remove falcon deadcode (jsc#PED-11366).
  - bnxt_en: replace PTP spinlock with seqlock (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: cache only 24 bits of hw counter (jsc#PED-10684
    jsc#PED-11230).
  - mlx5_en: use read sequence for gettimex64 (jsc#PED-11331).
  - net/mlx5e: do not create xdp_redirect for non-uplink rep
    (jsc#PED-11331).
  - net/mlx5e: move XDP_REDIRECT sq to dynamic allocation
    (jsc#PED-11331).
  - net/mlx5: HWS, renamed the files in accordance with naming
    convention (jsc#PED-11331).
  - net/mlx5: DR, moved all the SWS code into a separate directory
    (jsc#PED-11331).
  - net/mlx5: Rework esw qos domain init and cleanup
    (jsc#PED-11331).
  - dim: pass dim_sample to net_dim() by reference (jsc#PED-10581).
  - dim: make dim_calc_stats() inputs const pointers
    (jsc#PED-11331).
  - net: bnxt: use ethtool string helpers (jsc#PED-10684
    jsc#PED-11230).
  - net/mlx5: DPLL, Add clock quality level op implementation
    (jsc#PED-11331).
  - dpll: add clock quality level attribute and op (jsc#PED-11331).
  - octeontx2-pf: Move shared APIs to header file (jsc#PED-11317).
  - octeontx2-pf: Reuse PF max mtu value (jsc#PED-11317).
  - octeontx2-pf: Add new APIs for queue memory alloc/free
    (jsc#PED-11317).
  - octeontx2-pf: Define common API for HW resources configuration
    (jsc#PED-11317).
  - net: qlogic: use ethtool string helpers (jsc#PED-9648
    jsc#PED-11293).
  - net: marvell: use ethtool string helpers (jsc#PED-11317).
  - mlx5: simplify EQ interrupt polling logic (jsc#PED-11331).
  - mlx5: fix typo in "mlx5_cqwq_get_cqe_enahnced_comp"
    (jsc#PED-11331).
  - ibmvnic: use ethtool string helpers (jsc#PED_10911
    jsc#PED-3606).
  - net/mlx5e: Update features on ring size change (jsc#PED-11331).
  - net/mlx5e: Update features on MTU change (jsc#PED-11331).
  - vsock: do not leave dangling sk pointer in vsock_create()
    (jsc#PED-11028).
  - net/mlx5: unique names for per device caches (jsc#PED-11331).
  - net: atlantic: support reading SFP module info (jsc#PED-11287).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dcbnl.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dmac_flt.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in cn10k.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_ethtool.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_common.c
    (jsc#PED-11317).
  - virtchnl: fix m68k build (jsc#PED-10423).
  - net/mlx5: fs, rename modify header struct member action
    (jsc#PED-11331).
  - net/mlx5: fs, rename packet reformat struct member action
    (jsc#PED-11331).
  - net/mlx5: Only create VEPA flow table when in VEPA mode
    (jsc#PED-11331).
  - net/mlx5: Add sync reset drop mode support (jsc#PED-11331).
  - net/mlx5: Generalize QoS operations for nodes and vports
    (jsc#PED-11331).
  - net/mlx5: Simplify QoS scheduling element configuration
    (jsc#PED-11331).
  - net/mlx5: Remove vport QoS enabled flag (jsc#PED-11331).
  - net/mlx5: Refactor vport QoS to use scheduling node structure
    (jsc#PED-11331).
  - net/mlx5: Refactor vport scheduling element creation function
    (jsc#PED-11331).
  - net/mlx5: Introduce node struct and rename group terminology
    to node (jsc#PED-11331).
  - net/mlx5: Rename vport QoS group reference to parent
    (jsc#PED-11331).
  - net/mlx5: Restrict domain list insertion to root TSAR ancestors
    (jsc#PED-11331).
  - net/mlx5: Add parent group support in rate group structure
    (jsc#PED-11331).
  - net/mlx5: Introduce node type to rate group structure
    (jsc#PED-11331).
  - net/mlx5: Refactor QoS group scheduling element creation
    (jsc#PED-11331).
  - eth: Fix typo 'accelaration'. 'exprienced' and 'rewritting'
    (jsc#PED-3526 jsc#PED-11226).
  - tg3: Increase buffer size for IRQ label (jsc#PED-3526
    jsc#PED-11226).
  - mlx4: Add support for persistent NAPI config to RX CQs
    (jsc#PED-10418 jsc#PED11336).
  - mlx5: Add support for persistent NAPI config (jsc#PED-11331).
  - bnxt: Add support for persistent NAPI config (jsc#PED-10684
    jsc#PED-11230).
  - net: napi: Add napi_config (jsc#PED-10419).
  - net: napi: Make gro_flush_timeout per-NAPI (jsc#PED-10419).
  - net: napi: Make napi_defer_hard_irqs per-NAPI (jsc#PED-10419).
  - tg3: Address byte-order miss-matches (jsc#PED-3526
    jsc#PED-11226).
  - tg3: Link queues to NAPIs (jsc#PED-3526 jsc#PED-11226).
  - tg3: Link IRQs to NAPI instances (jsc#PED-3526 jsc#PED-11226).
  - iavf: add support to exchange qos capabilities (jsc#PED-10423).
  - iavf: Add net_shaper_ops support (jsc#PED-10423).
  - ice: Support VF queue rate limit and quanta size configuration
    (jsc#PED-10419).
  - virtchnl: support queue rate limit and quanta size configuration
    (jsc#PED-10419).
  - net-shapers: implement cap validation in the core
    (jsc#PED-10419).
  - net: shaper: implement introspection support (jsc#PED-10419).
  - netlink: spec: add shaper introspection support (jsc#PED-10419).
  - net-shapers: implement shaper cleanup on queue deletion
    (jsc#PED-10419).
  - net-shapers: implement delete support for NODE scope shaper
    (jsc#PED-10419).
  - net-shapers: implement NL group operation (jsc#PED-10419).
  - net-shapers: implement NL set and delete operations
    (jsc#PED-10419).
  - net-shapers: implement NL get operation (jsc#PED-10419).
  - netlink: spec: add shaper YAML spec (jsc#PED-10419).
  - genetlink: extend info user-storage to match NL cb ctx
    (jsc#PED-10419).
  - net/mlx5: Add support check for TSAR types in QoS scheduling
    (jsc#PED-11331).
  - net/mlx5: Unify QoS element type checks across NIC and E-Switch
    (jsc#PED-11331).
  - net/mlx5: qos: Refactor locking to a qos domain mutex
    (jsc#PED-11331).
  - net/mlx5: qos: Store rate groups in a qos domain
    (jsc#PED-11331).
  - net/mlx5: qos: Rename rate group 'list' as 'parent_entry'
    (jsc#PED-11331).
  - net/mlx5: qos: Add an explicit 'dev' to vport trace calls
    (jsc#PED-11331).
  - net/mlx5: qos: Store the eswitch in a mlx5_esw_rate_group
    (jsc#PED-11331).
  - net/mlx5: qos: Drop 'esw' param from vport qos functions
    (jsc#PED-11331).
  - net/mlx5: qos: Always create group0 (jsc#PED-11331).
  - net/mlx5: qos: Maintain rate group vport members in a list
    (jsc#PED-11331).
  - net/mlx5: qos: Refactor and document bw_share calculation
    (jsc#PED-11331).
  - net/mlx5: qos: Consistently name vport vars as 'vport'
    (jsc#PED-11331).
  - net/mlx5: qos: Rename vport 'tsar' into 'sched_elem'
    (jsc#PED-11331).
  - net/mlx5: qos: Flesh out element_attributes in mlx5_ifc.h
    (jsc#PED-11331).
  - e1000: Link NAPI instances to queues and IRQs (jsc#PED-10422).
  - e1000e: Link NAPI instances to queues and IRQs (jsc#PED-10420).
  - e1000e: Remove duplicated writel() in e1000_configure_tx/rx()
    (jsc#PED-10420).
  - igb: Cleanup unused declarations (jsc#PED-10426 jsc#PED-10425).
  - iavf: Remove unused declarations (jsc#PED-10423).
  - ice: Cleanup unused declarations (jsc#PED-10419).
  - ice: Use common error handling code in two functions
    (jsc#PED-10419).
  - ice: Make use of assign_bit() API (jsc#PED-10419).
  - ice: store max_frame and rx_buf_len only in ice_rx_ring
    (jsc#PED-10419).
  - ice: consistently use q_idx in ice_vc_cfg_qs_msg()
    (jsc#PED-10419).
  - ice: add E830 HW VF mailbox message limit support
    (jsc#PED-10419).
  - ice: Implement ethtool reset support (jsc#PED-10419).
  - doc: net: Fix .rst rendering of net_cachelines pages
    (jsc#PED-10419).
  - idpf: Don't hard code napi_struct size (jsc#PED-10581).
  - vmxnet3: support higher link speeds from vmxnet3 v9
    (jsc#PED-11024).
  - ipv4: remove fib_info_devhash (jsc#PED-10419).
  - ipv4: remove fib_info_lock (jsc#PED-10419).
  - ipv4: use rcu in ip_fib_check_default() (jsc#PED-10419).
  - ipv4: remove fib_devindex_hashfn() (jsc#PED-10419).
  - sfc: add per-queue RX bytes stats (jsc#PED-11366).
  - sfc: implement per-queue TSO (hw_gso) stats (jsc#PED-11366).
  - sfc: implement per-queue rx drop and overrun stats
    (jsc#PED-11366).
  - sfc: account XDP TXes in netdev base stats (jsc#PED-11366).
  - sfc: add n_rx_overlength to ethtool stats (jsc#PED-11366).
  - sfc: implement basic per-queue stats (jsc#PED-11366).
  - sfc: remove obsolete counters from struct efx_channel
    (jsc#PED-11366).
  - net: add IFLA_MAX_PACING_OFFLOAD_HORIZON device attribute
    (jsc#PED-10419).
  - ice: Drop auxbus use for PTP to finalize ice_adapter move
    (jsc#PED-10419).
  - ice: Use ice_adapter for PTP shared data instead of auxdev
    (jsc#PED-10419).
  - ice: Initial support for E825C hardware in ice_adapter
    (jsc#PED-10419).
  - ice: Add ice_get_ctrl_ptp() wrapper to simplify the code
    (jsc#PED-10419).
  - ice: Introduce ice_get_phy_model() wrapper (jsc#PED-10419).
  - ice: Enable 1PPS out from CGU for E825C products
    (jsc#PED-10419).
  - ice: Read SDP section from NVM for pin definitions
    (jsc#PED-10419).
  - ice: Disable shared pin on E810 on setfunc (jsc#PED-10419).
  - ice: Cache perout/extts requests and check flags
    (jsc#PED-10419).
  - ice: Align E810T GPIO to other products (jsc#PED-10419).
  - ice: Add SDPs support for E825C (jsc#PED-10419).
  - ice: Implement ice_ptp_pin_desc (jsc#PED-10419).
  - net/mlx5: hw counters: Remove mlx5_fc_create_ex (jsc#PED-11331).
  - net/mlx5: hw counters: Don't maintain a counter count
    (jsc#PED-11331).
  - net/mlx5: hw counters: Drop unneeded cacheline alignment
    (jsc#PED-11331).
  - net/mlx5: hw counters: Replace IDR+lists with xarray
    (jsc#PED-11331).
  - net/mlx5: hw counters: Use kvmalloc for bulk query buffer
    (jsc#PED-11331).
  - net/mlx5: hw counters: Make fc_stats & fc_pool private
    (jsc#PED-11331).
  - octeontx2-af: Change block parameter to const pointer in
    get_lf_str_list (jsc#PED-11317).
  - qed: put cond_resched() in qed_dmae_operation_wait()
    (jsc#PED-9648 jsc#PED-11293).
  - qed: allow the callee of qed_mcp_nvm_read() to sleep
    (jsc#PED-9648 jsc#PED-11293).
  - qed: put cond_resched() in qed_grc_dump_ctx_data() (jsc#PED-9648
    jsc#PED-11293).
  - qed: make 'ethtool -d' 10 times faster (jsc#PED-9648
    jsc#PED-11293).
  - ibmvnic: Add stat for tx direct vs tx batched (jsc#PED_10911
    jsc#PED-3606).
  - ipv4: avoid quadratic behavior in FIB insertion of common
    address (jsc#PED-10419).
  - commit affc8ea
  - pmdomain: core: add dummy release function to genpd device
    (git-fixes).
  - commit a551144
  - drm/amdgpu: rework resume handling for display (v2)
    (stable-fixes).
  - commit b4013fc
  - dmaengine: loongson2-apb: Change GENMASK to GENMASK_ULL
    (git-fixes).
  - commit 6fbbd7d
  - drm/xe: Move the coredump registration to the worker thread
    (git-fixes).
  - commit 2b22b2b
  - drm/xe: Take PM ref in delayed snapshot capture worker
    (git-fixes).
  - commit e6eb1c2
  - wifi: iwlwifi: be less noisy if the NIC is dead in S3
    (bsc#1012628).
  - commit 636dbb8
  - ASoC: dt-bindings: realtek,rt5645: Fix CPVDD voltage comment
    (git-fixes).
  - commit 08e9225
  - media: ipu6: use the IPU6 DMA mapping APIs to do mapping
    (stable-fixes).
  - commit 43b4f15
  - drm/amd/display: Add option to retrieve detile buffer size
    (stable-fixes).
  - commit acb618b
  - pinctrl: freescale: fix COMPILE_TEST error with PINCTRL_IMX_SCU
    (stable-fixes).
  - commit e5efdb1
  - drm/xe/guc/ct: Flush g2h worker in case of g2h response timeout
    (stable-fixes).
  - commit f607e51
  - pmdomain: imx: gpcv2: Adjust delay after power up handshake
    (git-fixes).
  - commit ef0da9b
  - pmdomain: core: Fix error path in pm_genpd_init() when ida
    alloc fails (git-fixes).
  - pmdomain: core: Add missing put_device() (git-fixes).
  - commit cd9a63e
  - spmi: pmic-arb: fix return path in
    for_each_available_child_of_node() (git-fixes).
  - commit 550e3b3
  - usb: xhci: Avoid queuing redundant Stop Endpoint commands
    (git-fixes).
  - commit cabee38
  - MAINTAINERS: update location of media main tree (stable-fixes).
  - commit 6ee41d4
  - net: rfkill: gpio: Add check for clk_enable() (git-fixes).
  - commit 5bd30ef
  - drm: fsl-dcu: enable PIXCLK on LS1021A (git-fixes).
  - commit 4a514d1
  - drm/vc4: Introduce generation number enum (stable-fixes).
  - Refresh
    patches.suse/drm-vc4-Match-drm_dev_enter-and-exit-calls-in-vc4_hv-cf1c87d.patch.
  - commit afddd1c
  - drm/vc4: Correct generation check in vc4_hvs_lut_load
    (git-fixes).
  - commit ce18613
  - ASoC: dt-bindings: mt6359: Update generic node name and
    dmic-mode (git-fixes).
  - commit d641daf
  - thermal/lib: Fix memory leak on error in thermal_genl_auto()
    (git-fixes).
  - tools/lib/thermal: Make more generic the command encoding
    function (stable-fixes).
  - commit d312e68
  - configs: Enable CONFIG_PAGE_POISONING (jsc#PED-11843)
    Page poisoning must still be enabled by kernel command line
    page_poison=on.
  - commit 0bc6079
  - x86/static-call: fix 32-bit build (git-fixes).
  - commit 05b1f89
  - zram: fix NULL pointer in comp_algorithm_show() (bsc#1234974
    CVE-2024-53222).
  - commit d85c3b1

++++ kernel-firmware-all:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-amdgpu:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-ath10k:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-ath11k:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-ath12k:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-atheros:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-bluetooth:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-bnx2:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-brcm:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-chelsio:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-dpaa2:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-i915:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-intel:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-iwlwifi:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-liquidio:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-marvell:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-media:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-mediatek:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-mellanox:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-mwifiex:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-network:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-nfp:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-nvidia:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-platform:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-prestera:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-qcom:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-qlogic:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-radeon:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-realtek:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-serial:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-sound:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-ti:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-ueagle:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-firmware-usb-network:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ kernel-rt:

  - powerpc/pseries/vas: Add close() callback in vas_vm_ops struct
    (bsc#1234825).
  - commit 2674760
  - ethtool: Fix access to uninitialized fields in set RXNFC command
    (git-fixes).
  - net: Make napi_hash_lock irq safe (git-fixes).
  - commit 9fa4e00
  - octeontx2-pf: RVU representor driver (jsc#PED-11317).
  - Update config files.
  - supported.conf: mark new OcteonTx2 submodule rvu_rep supported.
  - commit c4b0aa9
  - testing: net-drv: add basic shaper test (jsc#PED-10419).
  - Update config files.
  - commit 04716f4
  - net: sfc: Correct key_len for efx_tc_ct_zone_ht_params
    (jsc#PED-11366).
  - net/mlx5e: Keep netdev when leave switchdev for devlink set
    legacy only (jsc#PED-11331).
  - net/mlx5e: Skip restore TC rules for vport rep without loaded
    flag (jsc#PED-11331).
  - net/mlx5e: macsec: Maintain TX SA from encoding_sa
    (jsc#PED-11331).
  - net/mlx5: DR, select MSIX vector 0 for completion queue creation
    (jsc#PED-11331).
  - RDMA/mlx5: Enable multiplane mode only when it is supported
    (jsc#PED-11325).
  - RDMA/bnxt_re: Fix error recovery sequence (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix the locking while accessing the QP table
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix MSN table size for variable wqe mode
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Add send queue size check for variable wqe
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Disable use of reserved wqes (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix max_qp_wrs reported (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix reporting hw_ver in query_device
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix to export port num to ib_query_qp
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix setting mandatory attributes for modify_qp
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Add check for path mtu in modify_qp (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Fix the check for 9060 condition (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/bnxt_re: Don't fail destroy QP and cleanup debugfs earlier
    (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Avoid sending the modify QP workaround for latest
    adapters (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Avoid initializing the software queue for user
    queues (jsc#PED-10682 jsc#PED-11231).
  - RDMA/bnxt_re: Fix max SGEs for the Work Request (jsc#PED-10682
    jsc#PED-11231).
  - RDMA/mlx5: Enforce same type port association for multiport RoCE
    (jsc#PED-11325).
  - RDMA/bnxt_re: Remove always true dattr validity check
    (jsc#PED-10682 jsc#PED-11231).
  - octeontx2-pf: fix error handling of devlink port in
    rvu_rep_create() (jsc#PED-11317).
  - octeontx2-pf: fix netdev memory leak in rvu_rep_create()
    (jsc#PED-11317).
  - idpf: trigger SW interrupt when exiting wb_on_itr mode
    (jsc#PED-10581).
  - idpf: add support for SW triggered interrupts (jsc#PED-10581).
  - qed: fix possible uninit pointer read in
    qed_mcp_nvm_info_populate() (jsc#PED-9648 jsc#PED-11293).
  - chelsio/chtls: prevent potential integer overflow on 32bit
    (git-fixes).
  - ionic: use ee->offset when returning sprom data (jsc#PED-11378).
  - ionic: no double destroy workqueue (jsc#PED-11378).
  - ionic: Fix netdev notifier unregister on failure
    (jsc#PED-11378).
  - bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips
    (jsc#PED-10684 jsc#PED-11230).
  - octeontx2-af: Fix installation of PF multicast rule
    (jsc#PED-11317).
  - cxgb4: use port number to set mac addr (git-fixes).
  - bnxt_en: Fix potential crash when dumping FW log coredump
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Fix GSO type for HW GRO packets on 5750X chips
    (jsc#PED-10684 jsc#PED-11230).
  - net/mlx5: DR, prevent potential error pointer dereference
    (jsc#PED-11331).
  - bpf, vsock: Invoke proto::close on close() (jsc#PED-11028).
  - bpf, vsock: Fix poll() missing a queue (jsc#PED-11028).
  - igb: Fix potential invalid memory access in igb_init_module()
    (jsc#PED-10426 jsc#PED-10425).
  - ixgbe: Correct BASE-BX10 compliance code (jsc#PED-9647
    jsc#PED-9646).
  - ixgbe: downgrade logging of unsupported VF API version to debug
    (jsc#PED-9647 jsc#PED-9646).
  - ixgbevf: stop attempting IPSEC offload on Mailbox API 1.5
    (jsc#PED-9647 jsc#PED-9646).
  - idpf: set completion tag for "empty" bufs associated with a
    packet (jsc#PED-10581).
  - ice: Fix VLAN pruning in switchdev mode (jsc#PED-10419).
  - ice: Fix NULL pointer dereference in switchdev (jsc#PED-10419).
  - ice: fix PHY timestamp extraction for ETH56G (jsc#PED-10419).
  - ice: fix PHY Clock Recovery availability check (jsc#PED-10419).
  - net/mlx5e: Remove workaround to avoid syndrome for internal port
    (jsc#PED-11331).
  - net/mlx5e: SD, Use correct mdev to build channel param
    (jsc#PED-11331).
  - net/mlx5: E-Switch, Fix switching to switchdev mode in MPV
    (jsc#PED-11331).
  - net/mlx5: E-Switch, Fix switching to switchdev mode with IB
    device disabled (jsc#PED-11331).
  - net/mlx5: HWS: Properly set bwc queue locks lock classes
    (jsc#PED-11331).
  - net/mlx5: HWS: Fix memory leak in mlx5hws_definer_calc_layout
    (jsc#PED-11331).
  - bnxt_en: handle tpa_info in queue API implementation
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: refactor bnxt_alloc_rx_rings() to call
    bnxt_alloc_rx_agg_bmap() (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: refactor tpa_info alloc/free into helpers
    (jsc#PED-10684 jsc#PED-11230).
  - net/qed: allow old cards not supporting "num_images" to work
    (jsc#PED-9648 jsc#PED-11293).
  - octeontx2-af: Fix SDP MAC link credits configuration
    (jsc#PED-11317).
  - bnxt_en: ethtool: Supply ntuple rss context action
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Unregister PTP during PCI shutdown and suspend
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Refactor bnxt_ptp_init() (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Fix receive ring space parameters when XDP is active
    (jsc#PED-10684 jsc#PED-11230 CVE-2024-53209 bsc#1235002).
  - bnxt_en: Fix queue start to update vnic RSS table (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Set backplane link modes correctly for ethtool
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Reserve rings after PCIe AER recovery if NIC interface
    is down (jsc#PED-10684 jsc#PED-11230).
  - octeontx2-af: Quiesce traffic before NIX block reset
    (jsc#PED-11317).
  - octeontx2-af: RPM: fix stale FCFEC counters (jsc#PED-11317).
  - octeontx2-af: RPM: fix stale RSFEC counters (jsc#PED-11317).
  - octeontx2-af: RPM: Fix low network performance (jsc#PED-11317).
  - octeontx2-af: RPM: Fix mismatch in lmac type (jsc#PED-11317).
  - vdpa/mlx5: Fix suboptimal range on iotlb iteration
    (jsc#PED-11331).
  - RDMA/mlx5: Add implementation for ufile_hw_cleanup device
    operation (jsc#PED-11325).
  - RDMA/mlx5: Ensure active slave attachment to the bond IB device
    (jsc#PED-11325).
  - RDMA/mlx5: Call dev_put() after the blocking notifier
    (jsc#PED-11325).
  - RDMA/mlx5: Support querying per-plane IB PortCounters
    (jsc#PED-11325).
  - RDMA/mlx5: Support OOO RX WQE consumption (jsc#PED-11325).
  - net/mlx5: Introduce data placement ordering bits
    (jsc#PED-11331).
  - i40e: Fix handling changed priv flags (jsc#PED-10428).
  - bnxt_en: Add FW trace coredump segments to the coredump
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Add a new ethtool -W dump flag (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Add 2 parameters to bnxt_fill_coredump_seg_hdr()
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Add functions to copy host context memory
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Do not free FW log context memory (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Manage the FW trace context memory (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Allocate backing store memory for FW trace logs
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Add a 'force' parameter to bnxt_free_ctx_mem()
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Refactor bnxt_free_ctx_mem() (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: Add mem_valid bit to struct bnxt_ctx_mem_type
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: Update firmware interface spec to 1.10.3.85
    (jsc#PED-10684 jsc#PED-11230).
  - e1000: Hold RTNL when e1000_down can be called (jsc#PED-10422).
  - igbvf: remove unused spinlock (jsc#PED-10426 jsc#PED-10425).
  - igb: Fix 2 typos in comments in igb_main.c (jsc#PED-10426
    jsc#PED-10425).
  - igc: remove autoneg parameter from igc_mac_info (jsc#PED-10417).
  - ixgbe: Break include dependency cycle (jsc#PED-9647
    jsc#PED-9646).
  - ice: Unbind the workqueue (jsc#PED-10419).
  - ice: use stack variable for virtchnl_supported_rxdids
    (jsc#PED-10419).
  - ice: initialize pf->supported_rxdids immediately after loading
    DDP (jsc#PED-10419).
  - ice: only allow Tx promiscuous for multicast (jsc#PED-10419).
  - ice: Add support for persistent NAPI config (jsc#PED-10419).
  - ice: support optional flags in signature segment header
    (jsc#PED-10419).
  - ice: refactor "last" segment of DDP pkg (jsc#PED-10419).
  - ice: extend dump serdes equalizer values feature
    (jsc#PED-10419).
  - ice: rework of dump serdes equalizer values feature
    (jsc#PED-10419).
  - ndo_fdb_del: Add a parameter to report whether notification
    was sent (jsc#PED-10419).
  - ndo_fdb_add: Add a parameter to report whether notification
    was sent (jsc#PED-10428).
  - octeontx2-pf: Fix spelling mistake "reprentator" ->
    "representor" (jsc#PED-11317).
  - bnxt_en: optimize gettimex64 (jsc#PED-10684 jsc#PED-11230).
  - net: ethtool: only allow set_rxnfc with rss + ring_cookie if
    driver opts in (jsc#PED-11366).
  - octeontx2-pf: Adds TC offload support (jsc#PED-11317).
  - octeontx2-pf: Implement offload stats ndo for representors
    (jsc#PED-11317).
  - octeontx2-pf: Add devlink port support (jsc#PED-11317).
  - octeontx2-pf: Add representors for sdp MAC (jsc#PED-11317).
  - octeontx2-pf: Configure VF mtu via representor (jsc#PED-11317).
  - octeontx2-pf: Add support to sync link state between representor
    and VFs (jsc#PED-11317).
  - octeontx2-pf: Get VF stats via representor (jsc#PED-11317).
  - octeontx2-af: Add packet path between representor and VF
    (jsc#PED-11317).
  - octeontx2-pf: Add basic net_device_ops (jsc#PED-11317).
  - octeontx2-pf: Create representor netdev (jsc#PED-11317).
  - eth: bnxt: use page pool for head frags (jsc#PED-10684
    jsc#PED-11230).
  - net/mlx5e: SHAMPO, Rework header allocation loop
    (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Drop info array (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Change frag page setup order during
    allocation (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Fix page_index calculation inconsistency
    (jsc#PED-11331).
  - net/mlx5e: SHAMPO, Simplify UMR allocation for headers
    (jsc#PED-11331).
  - net/mlx5: Make vport QoS enablement more flexible for future
    extensions (jsc#PED-11331).
  - net/mlx5: Integrate esw_qos_vport_enable logic into rate
    operations (jsc#PED-11331).
  - net/mlx5: Generalize scheduling element operations
    (jsc#PED-11331).
  - net/mlx5: Refactor scheduling element configuration bitmasks
    (jsc#PED-11331).
  - net/mlx5: Generalize max_rate and min_rate setting for nodes
    (jsc#PED-11331).
  - net/mlx5: Simplify QoS normalization by removing error handling
    (jsc#PED-11331).
  - net/mlx5: E-switch, refactor eswitch mode change
    (jsc#PED-11331).
  - bnxt_en: add unlocked version of bnxt_refclk_read (jsc#PED-10684
    jsc#PED-11230).
  - net: atlantic: use irq_update_affinity_hint() (jsc#PED-11287).
  - bnxt_en: use irq_update_affinity_hint() (jsc#PED-10684
    jsc#PED-11230).
  - octeontx2-af: Knobs for NPC default rule counters
    (jsc#PED-11317).
  - octeontx2-af: Refactor few NPC mcam APIs (jsc#PED-11317).
  - mlx5/core: deduplicate {mlx5_,}eq_update_ci() (jsc#PED-11331).
  - mlx5/core: relax memory barrier in eq_update_ci()
    (jsc#PED-11331).
  - bridge: Allow deleting FDB entries with non-existent VLAN
    (jsc#PED-10419).
  - mlx5/core: Schedule EQ comp tasklet only if necessary
    (jsc#PED-11331).
  - net: sfc: use ethtool string helpers (jsc#PED-11366).
  - net: bnx2x: use ethtool string helpers (jsc#PED-10901
    jsc#PED-11308).
  - bnxt_en: ethtool: Support unset l4proto on ip4/ip6 ntuple rules
    (jsc#PED-10684 jsc#PED-11230).
  - bnxt_en: ethtool: Remove ip4/ip6 ntuple support for IPPROTO_RAW
    (jsc#PED-10684 jsc#PED-11230).
  - sfc: Remove more unused functions (jsc#PED-11366).
  - sfc: Remove unused mcdi functions (jsc#PED-11366).
  - sfc: Remove unused efx_mae_mport_vf (jsc#PED-11366).
  - sfc: Remove falcon deadcode (jsc#PED-11366).
  - bnxt_en: replace PTP spinlock with seqlock (jsc#PED-10684
    jsc#PED-11230).
  - bnxt_en: cache only 24 bits of hw counter (jsc#PED-10684
    jsc#PED-11230).
  - mlx5_en: use read sequence for gettimex64 (jsc#PED-11331).
  - net/mlx5e: do not create xdp_redirect for non-uplink rep
    (jsc#PED-11331).
  - net/mlx5e: move XDP_REDIRECT sq to dynamic allocation
    (jsc#PED-11331).
  - net/mlx5: HWS, renamed the files in accordance with naming
    convention (jsc#PED-11331).
  - net/mlx5: DR, moved all the SWS code into a separate directory
    (jsc#PED-11331).
  - net/mlx5: Rework esw qos domain init and cleanup
    (jsc#PED-11331).
  - dim: pass dim_sample to net_dim() by reference (jsc#PED-10581).
  - dim: make dim_calc_stats() inputs const pointers
    (jsc#PED-11331).
  - net: bnxt: use ethtool string helpers (jsc#PED-10684
    jsc#PED-11230).
  - net/mlx5: DPLL, Add clock quality level op implementation
    (jsc#PED-11331).
  - dpll: add clock quality level attribute and op (jsc#PED-11331).
  - octeontx2-pf: Move shared APIs to header file (jsc#PED-11317).
  - octeontx2-pf: Reuse PF max mtu value (jsc#PED-11317).
  - octeontx2-pf: Add new APIs for queue memory alloc/free
    (jsc#PED-11317).
  - octeontx2-pf: Define common API for HW resources configuration
    (jsc#PED-11317).
  - net: qlogic: use ethtool string helpers (jsc#PED-9648
    jsc#PED-11293).
  - net: marvell: use ethtool string helpers (jsc#PED-11317).
  - mlx5: simplify EQ interrupt polling logic (jsc#PED-11331).
  - mlx5: fix typo in "mlx5_cqwq_get_cqe_enahnced_comp"
    (jsc#PED-11331).
  - ibmvnic: use ethtool string helpers (jsc#PED_10911
    jsc#PED-3606).
  - net/mlx5e: Update features on ring size change (jsc#PED-11331).
  - net/mlx5e: Update features on MTU change (jsc#PED-11331).
  - vsock: do not leave dangling sk pointer in vsock_create()
    (jsc#PED-11028).
  - net/mlx5: unique names for per device caches (jsc#PED-11331).
  - net: atlantic: support reading SFP module info (jsc#PED-11287).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dcbnl.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dmac_flt.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in cn10k.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_ethtool.c
    (jsc#PED-11317).
  - octeontx2-pf: handle otx2_mbox_get_rsp errors in otx2_common.c
    (jsc#PED-11317).
  - virtchnl: fix m68k build (jsc#PED-10423).
  - net/mlx5: fs, rename modify header struct member action
    (jsc#PED-11331).
  - net/mlx5: fs, rename packet reformat struct member action
    (jsc#PED-11331).
  - net/mlx5: Only create VEPA flow table when in VEPA mode
    (jsc#PED-11331).
  - net/mlx5: Add sync reset drop mode support (jsc#PED-11331).
  - net/mlx5: Generalize QoS operations for nodes and vports
    (jsc#PED-11331).
  - net/mlx5: Simplify QoS scheduling element configuration
    (jsc#PED-11331).
  - net/mlx5: Remove vport QoS enabled flag (jsc#PED-11331).
  - net/mlx5: Refactor vport QoS to use scheduling node structure
    (jsc#PED-11331).
  - net/mlx5: Refactor vport scheduling element creation function
    (jsc#PED-11331).
  - net/mlx5: Introduce node struct and rename group terminology
    to node (jsc#PED-11331).
  - net/mlx5: Rename vport QoS group reference to parent
    (jsc#PED-11331).
  - net/mlx5: Restrict domain list insertion to root TSAR ancestors
    (jsc#PED-11331).
  - net/mlx5: Add parent group support in rate group structure
    (jsc#PED-11331).
  - net/mlx5: Introduce node type to rate group structure
    (jsc#PED-11331).
  - net/mlx5: Refactor QoS group scheduling element creation
    (jsc#PED-11331).
  - eth: Fix typo 'accelaration'. 'exprienced' and 'rewritting'
    (jsc#PED-3526 jsc#PED-11226).
  - tg3: Increase buffer size for IRQ label (jsc#PED-3526
    jsc#PED-11226).
  - mlx4: Add support for persistent NAPI config to RX CQs
    (jsc#PED-10418 jsc#PED11336).
  - mlx5: Add support for persistent NAPI config (jsc#PED-11331).
  - bnxt: Add support for persistent NAPI config (jsc#PED-10684
    jsc#PED-11230).
  - net: napi: Add napi_config (jsc#PED-10419).
  - net: napi: Make gro_flush_timeout per-NAPI (jsc#PED-10419).
  - net: napi: Make napi_defer_hard_irqs per-NAPI (jsc#PED-10419).
  - tg3: Address byte-order miss-matches (jsc#PED-3526
    jsc#PED-11226).
  - tg3: Link queues to NAPIs (jsc#PED-3526 jsc#PED-11226).
  - tg3: Link IRQs to NAPI instances (jsc#PED-3526 jsc#PED-11226).
  - iavf: add support to exchange qos capabilities (jsc#PED-10423).
  - iavf: Add net_shaper_ops support (jsc#PED-10423).
  - ice: Support VF queue rate limit and quanta size configuration
    (jsc#PED-10419).
  - virtchnl: support queue rate limit and quanta size configuration
    (jsc#PED-10419).
  - net-shapers: implement cap validation in the core
    (jsc#PED-10419).
  - net: shaper: implement introspection support (jsc#PED-10419).
  - netlink: spec: add shaper introspection support (jsc#PED-10419).
  - net-shapers: implement shaper cleanup on queue deletion
    (jsc#PED-10419).
  - net-shapers: implement delete support for NODE scope shaper
    (jsc#PED-10419).
  - net-shapers: implement NL group operation (jsc#PED-10419).
  - net-shapers: implement NL set and delete operations
    (jsc#PED-10419).
  - net-shapers: implement NL get operation (jsc#PED-10419).
  - netlink: spec: add shaper YAML spec (jsc#PED-10419).
  - genetlink: extend info user-storage to match NL cb ctx
    (jsc#PED-10419).
  - net/mlx5: Add support check for TSAR types in QoS scheduling
    (jsc#PED-11331).
  - net/mlx5: Unify QoS element type checks across NIC and E-Switch
    (jsc#PED-11331).
  - net/mlx5: qos: Refactor locking to a qos domain mutex
    (jsc#PED-11331).
  - net/mlx5: qos: Store rate groups in a qos domain
    (jsc#PED-11331).
  - net/mlx5: qos: Rename rate group 'list' as 'parent_entry'
    (jsc#PED-11331).
  - net/mlx5: qos: Add an explicit 'dev' to vport trace calls
    (jsc#PED-11331).
  - net/mlx5: qos: Store the eswitch in a mlx5_esw_rate_group
    (jsc#PED-11331).
  - net/mlx5: qos: Drop 'esw' param from vport qos functions
    (jsc#PED-11331).
  - net/mlx5: qos: Always create group0 (jsc#PED-11331).
  - net/mlx5: qos: Maintain rate group vport members in a list
    (jsc#PED-11331).
  - net/mlx5: qos: Refactor and document bw_share calculation
    (jsc#PED-11331).
  - net/mlx5: qos: Consistently name vport vars as 'vport'
    (jsc#PED-11331).
  - net/mlx5: qos: Rename vport 'tsar' into 'sched_elem'
    (jsc#PED-11331).
  - net/mlx5: qos: Flesh out element_attributes in mlx5_ifc.h
    (jsc#PED-11331).
  - e1000: Link NAPI instances to queues and IRQs (jsc#PED-10422).
  - e1000e: Link NAPI instances to queues and IRQs (jsc#PED-10420).
  - e1000e: Remove duplicated writel() in e1000_configure_tx/rx()
    (jsc#PED-10420).
  - igb: Cleanup unused declarations (jsc#PED-10426 jsc#PED-10425).
  - iavf: Remove unused declarations (jsc#PED-10423).
  - ice: Cleanup unused declarations (jsc#PED-10419).
  - ice: Use common error handling code in two functions
    (jsc#PED-10419).
  - ice: Make use of assign_bit() API (jsc#PED-10419).
  - ice: store max_frame and rx_buf_len only in ice_rx_ring
    (jsc#PED-10419).
  - ice: consistently use q_idx in ice_vc_cfg_qs_msg()
    (jsc#PED-10419).
  - ice: add E830 HW VF mailbox message limit support
    (jsc#PED-10419).
  - ice: Implement ethtool reset support (jsc#PED-10419).
  - doc: net: Fix .rst rendering of net_cachelines pages
    (jsc#PED-10419).
  - idpf: Don't hard code napi_struct size (jsc#PED-10581).
  - vmxnet3: support higher link speeds from vmxnet3 v9
    (jsc#PED-11024).
  - ipv4: remove fib_info_devhash (jsc#PED-10419).
  - ipv4: remove fib_info_lock (jsc#PED-10419).
  - ipv4: use rcu in ip_fib_check_default() (jsc#PED-10419).
  - ipv4: remove fib_devindex_hashfn() (jsc#PED-10419).
  - sfc: add per-queue RX bytes stats (jsc#PED-11366).
  - sfc: implement per-queue TSO (hw_gso) stats (jsc#PED-11366).
  - sfc: implement per-queue rx drop and overrun stats
    (jsc#PED-11366).
  - sfc: account XDP TXes in netdev base stats (jsc#PED-11366).
  - sfc: add n_rx_overlength to ethtool stats (jsc#PED-11366).
  - sfc: implement basic per-queue stats (jsc#PED-11366).
  - sfc: remove obsolete counters from struct efx_channel
    (jsc#PED-11366).
  - net: add IFLA_MAX_PACING_OFFLOAD_HORIZON device attribute
    (jsc#PED-10419).
  - ice: Drop auxbus use for PTP to finalize ice_adapter move
    (jsc#PED-10419).
  - ice: Use ice_adapter for PTP shared data instead of auxdev
    (jsc#PED-10419).
  - ice: Initial support for E825C hardware in ice_adapter
    (jsc#PED-10419).
  - ice: Add ice_get_ctrl_ptp() wrapper to simplify the code
    (jsc#PED-10419).
  - ice: Introduce ice_get_phy_model() wrapper (jsc#PED-10419).
  - ice: Enable 1PPS out from CGU for E825C products
    (jsc#PED-10419).
  - ice: Read SDP section from NVM for pin definitions
    (jsc#PED-10419).
  - ice: Disable shared pin on E810 on setfunc (jsc#PED-10419).
  - ice: Cache perout/extts requests and check flags
    (jsc#PED-10419).
  - ice: Align E810T GPIO to other products (jsc#PED-10419).
  - ice: Add SDPs support for E825C (jsc#PED-10419).
  - ice: Implement ice_ptp_pin_desc (jsc#PED-10419).
  - net/mlx5: hw counters: Remove mlx5_fc_create_ex (jsc#PED-11331).
  - net/mlx5: hw counters: Don't maintain a counter count
    (jsc#PED-11331).
  - net/mlx5: hw counters: Drop unneeded cacheline alignment
    (jsc#PED-11331).
  - net/mlx5: hw counters: Replace IDR+lists with xarray
    (jsc#PED-11331).
  - net/mlx5: hw counters: Use kvmalloc for bulk query buffer
    (jsc#PED-11331).
  - net/mlx5: hw counters: Make fc_stats & fc_pool private
    (jsc#PED-11331).
  - octeontx2-af: Change block parameter to const pointer in
    get_lf_str_list (jsc#PED-11317).
  - qed: put cond_resched() in qed_dmae_operation_wait()
    (jsc#PED-9648 jsc#PED-11293).
  - qed: allow the callee of qed_mcp_nvm_read() to sleep
    (jsc#PED-9648 jsc#PED-11293).
  - qed: put cond_resched() in qed_grc_dump_ctx_data() (jsc#PED-9648
    jsc#PED-11293).
  - qed: make 'ethtool -d' 10 times faster (jsc#PED-9648
    jsc#PED-11293).
  - ibmvnic: Add stat for tx direct vs tx batched (jsc#PED_10911
    jsc#PED-3606).
  - ipv4: avoid quadratic behavior in FIB insertion of common
    address (jsc#PED-10419).
  - commit affc8ea
  - pmdomain: core: add dummy release function to genpd device
    (git-fixes).
  - commit a551144
  - drm/amdgpu: rework resume handling for display (v2)
    (stable-fixes).
  - commit b4013fc
  - dmaengine: loongson2-apb: Change GENMASK to GENMASK_ULL
    (git-fixes).
  - commit 6fbbd7d
  - drm/xe: Move the coredump registration to the worker thread
    (git-fixes).
  - commit 2b22b2b
  - drm/xe: Take PM ref in delayed snapshot capture worker
    (git-fixes).
  - commit e6eb1c2
  - wifi: iwlwifi: be less noisy if the NIC is dead in S3
    (bsc#1012628).
  - commit 636dbb8
  - ASoC: dt-bindings: realtek,rt5645: Fix CPVDD voltage comment
    (git-fixes).
  - commit 08e9225
  - media: ipu6: use the IPU6 DMA mapping APIs to do mapping
    (stable-fixes).
  - commit 43b4f15
  - drm/amd/display: Add option to retrieve detile buffer size
    (stable-fixes).
  - commit acb618b
  - pinctrl: freescale: fix COMPILE_TEST error with PINCTRL_IMX_SCU
    (stable-fixes).
  - commit e5efdb1
  - drm/xe/guc/ct: Flush g2h worker in case of g2h response timeout
    (stable-fixes).
  - commit f607e51
  - pmdomain: imx: gpcv2: Adjust delay after power up handshake
    (git-fixes).
  - commit ef0da9b
  - pmdomain: core: Fix error path in pm_genpd_init() when ida
    alloc fails (git-fixes).
  - pmdomain: core: Add missing put_device() (git-fixes).
  - commit cd9a63e
  - spmi: pmic-arb: fix return path in
    for_each_available_child_of_node() (git-fixes).
  - commit 550e3b3
  - usb: xhci: Avoid queuing redundant Stop Endpoint commands
    (git-fixes).
  - commit cabee38
  - MAINTAINERS: update location of media main tree (stable-fixes).
  - commit 6ee41d4
  - net: rfkill: gpio: Add check for clk_enable() (git-fixes).
  - commit 5bd30ef
  - drm: fsl-dcu: enable PIXCLK on LS1021A (git-fixes).
  - commit 4a514d1
  - drm/vc4: Introduce generation number enum (stable-fixes).
  - Refresh
    patches.suse/drm-vc4-Match-drm_dev_enter-and-exit-calls-in-vc4_hv-cf1c87d.patch.
  - commit afddd1c
  - drm/vc4: Correct generation check in vc4_hvs_lut_load
    (git-fixes).
  - commit ce18613
  - ASoC: dt-bindings: mt6359: Update generic node name and
    dmic-mode (git-fixes).
  - commit d641daf
  - thermal/lib: Fix memory leak on error in thermal_genl_auto()
    (git-fixes).
  - tools/lib/thermal: Make more generic the command encoding
    function (stable-fixes).
  - commit d312e68
  - configs: Enable CONFIG_PAGE_POISONING (jsc#PED-11843)
    Page poisoning must still be enabled by kernel command line
    page_poison=on.
  - commit 0bc6079
  - x86/static-call: fix 32-bit build (git-fixes).
  - commit 05b1f89
  - zram: fix NULL pointer in comp_algorithm_show() (bsc#1234974
    CVE-2024-53222).
  - commit d85c3b1

++++ libgcrypt:

  - Fix redefinition error of 'rol64'. Remove not used rol64()
    definition after removing the built-in jitter rng.
    * Add libgcrypt-rol64-redefinition.patch

++++ samba:

  - Update to 4.21.3
    * More possible replication loops against Azure AD;
    (bso#15701).
    * Compound rename from Mac clients can fail with
    NT_STATUS_INTERNAL_ERROR if the file has a lease;
    (bso#15697).
    * vfs crossrename seems not work correctly; (bso#15724).
    * After 'machine password timeout' /etc/krb5.keytab is not
    updated; (bso#6750).
    * Memory leak wbcCtxLookupSid; (bso#15771).
    * Fix heap-user-after-free with association groups;
    (bso#15765).
    * Segfault in vfs_btrfs; (bso#15758).
    * Avoid event failure race when disabling an event script;
    (bso#15755).

++++ ncurses:

  - Add ncurses patch 20250104
    + modify tput to warn about capabilities which expect parameters where
    none are given; also repair the feature where multiple capabilities
    can be handled on a single line.
    + cleanup use-clauses -TD
    + add linux+lockeys, xterm+r5+lockeys, xterm+r5+fkeys -TD
    + add vt220+ufkeys, vt220+sfkeys
    + revert man/manlinks.sed change, which loses aliases (cf: 20241228).
    + modify MKlib_gen.c to allow for Solaris's definition of NULL as 0L
  - Add ncurses patch 20241228
    + correct conditional-compile for a case when the C compiler does not
    have a bool type.
    + add ghostty -TD
    > patches by Branden Robinson:
    + add comments to generated term.h to hint the configure options used
    + use same subdir-convention for term.h, in configure script
    + improve formatting/style of manpages
  - Add ncurses patch 20241221
    + modify ncurses/tinfo/MKfallback.sh to work with MacOS sed, which
    lacks BSD-style \< and \>
    + trim padding from sgr expresion used in trim_sgr0, to avoid copying
    the padding into the resulting sgr0 (report by Rajeev Pillai).
    + strict compiler-warning fixes for upcoming gcc15
  - Add ncurses patch 20241214
    + avoid redefining bool in curses.h if the platform already supports
    that type (cf: 20241123).
    + move include <curses.h> from etip.h.in to cursesw.h, to work around
    breakage in Apple's port of ncurses.
    + strict compiler-warning fixes for upcoming gcc15
  - Port patches
    * ncurses-5.9-ibm327x.dif
    * ncurses-6.4.dif

++++ rpm:

  - make misuses of %global with %buildroot work again
    * new patch: undefbuildroot.diff

++++ slang:

  - Update to version 2.3.3+git16.89d32bb:
    * pre2.3.4-16: Removed unnecessary chack for a NULL string in keymap.c:find_the_key, and corrected a potential memory leak in the sltoken.c:compile_byte_compiled_multistring function
    * pre2.3.4-15: Added UTF-16 surrogate handling to the expand_escaped_string function and json module
    * pre2.3.4-14: Added fcntl_getpipe_sz and fcntl_setpipe_sz functions to the fcntl module to get and set the buffer size for pipes
    * pre2.3.4-13: Initialize the variables provided by the %g operator to zero to not leak uninitialized data from the stack if not set by %P. (Miroslav Lichvar)
    * pre2.3.4-12: modules/chksum_sha2.c: Use memcpy to avoid type-punning warning
    * pre2.3.4-11: lib/timestamp.sl: Fixed a bug involving leap years
    * pre2.3.4-10: Updated the Unicode tables to v15 from v10
    * pre2.3.4-9: src/slang.ver: Removed the undefined symbol SLang_Rline_Quit, which was causing a link error on Gentoo Linux (Michal Rostecki)
    * pre2.3.4-8: check for NULL return value from the ctime function
    * pre2.3.4-7: mkfiles/makefile.m32: Added install1 target to work with versions of mingw make that cannot process the install target.  Previously this required editing the makefile (windows-specific)
  - download from git://git.jedsoft.org/git/slang.git
    * drop slang-2.3.3.tar.bz2.asc and slang.keyring
  - rename patches
    * slang.patch to 0001-Use-termcap.patch
    * slang-autoconf.patch to 0002-Fix-CFLAGS-and-generate-sl-config.h.patch
    * slang-fsuid.patch to 0003-Enforce-use-of-setfsuid.patch

++++ runc:

  - Update to runc v1.2.4. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.4>.
  - Update runc.keyring to match upstream.

++++ systemd-presets-common-SUSE:

  - Remove enable nscd, nscd doesn't work anymore with systemd 257
    [bsc#1234904]

++++ ucode-amd:

  - Update to version 20250106 (git commit e39831b1a9d7):
    * rtl_bt: Add separate config for RLT8723CS Bluetooth part
    * amdgpu: revert VCN 3.1.2 firmware
    * amdgpu: revert yellow carp VCN firmware
    * amdgpu: revert sienna cichlid VCN firmware
    * amdgpu: revert navy flounder VCN firmware
    * amdgpu: revert dimgrey cavefish VCN firmware
    * WHENCE: Link the Raspberry Pi CM5 and 500 to the 4B
    * copy-firmware.sh: Fix typo in error message.
    * Add support to install files/symlinks in parallel.
    * Makefile: Remove obsolete/broken reference.
    * check_whence.py: Use a more portable shebang.
    * rtl_bt: Update RTL8852B BT USB FW to 0x04BE_1F5E

++++ vim:

  - update to 9.1.0993
    * 9.1.0993: New 'cmdheight' behavior may be surprising
    * runtime(sh): fix typo in Last Change header
    * 9.1.0992: Vim9: double-free after v9.1.0988
    * 9.1.0991: v:stacktrace has wrong type in Vim9 script
    * runtime(sh): add PS0 to bashSpecialVariables in syntax script
    * runtime(vim): Remove trailing comma from match_words
    * runtime(zsh): sync syntax script with upstream repo
    * runtime(doc): Capitalise the mnemonic "Zero" for the 'z' flag of search()
    * 9.1.0990: Inconsistent behavior when changing cmdheight
    * 9.1.0989: Vim9: Whitespace after the final enum value causes a syntax error
    * runtime(java): Quietly opt out for unsupported markdown.vim versions
    * runtime(vim): fix failing vim syntax test
    * 9.1.0988: Vim9: no error when using uninitialized var in new()
    * runtime(doc): update index.txt
    * 9.1.0987: filetype: cake files are not recognized
    * 9.1.0986: filetype: 'jj' filetype is a bit imprecise
    * runtime(jj): Support diffs in jj syntax
    * runtime(vim): Update matchit pattern, no Vim9 short names
    * 9.1.0985: Vim9: some ex commands can be shortened
    * 9.1.0984: exception handling can be improved
    * runtime(doc): update doc for :horizontal
    * runtime(doc): update index.txt, windows.txt and version9.txt
    * runtime(doc): Tweak documentation about base64 function
    * runtime(chordpro): update syntax script
    * 9.1.0983: not able to get the displayed items in complete_info()
    * runtime(doc): use standard SGR format at :h xterm-true-color
    * 9.1.0982: TI linker files are not recognized
    * runtime(vim): update vim generator syntax script
    * 9.1.0981: tests: typo in test_filetype.vim
    * 9.1.0980: no support for base64 en-/decoding functions in Vim Script
    * syntax(sh): Improve the recognition of bracket expressions
    * runtime(doc): mention how NUL bytes are handled
    * 9.1.0979: VMS: type warning with $XDG_VIMRC_FILE
    * 9.1.0978: GUI tests sometimes fail when setting 'scroll' options
    * 9.1.0977: filetype: msbuild filetypes are not recognized
    * 9.1.0976: Vim9: missing return statement with throw
    * 9.1.0975: Vim9: interpolated string expr not working in object methods
    * 9.1.0974: typo in change of commit v9.1.0873
    * 9.1.0973: too many strlen() calls in fileio.c
    * runtime(sh): set shellcheck as the compiler for supported shells
    * runtime(doc): Fix enum example syntax
    * 9.1.0972: filetype: TI linker map files are not recognized
    * runtime(vim): Improve syntax script generator for Vim Script
    * 9.1.0971: filetype: SLNX files are not recognized
    * 9.1.0970: VMS: build errors on VMS architecture
    * runtime(doc): Fix documentation typos
    * runtime(doc): update for new keyprotocol option value (after v9.1.0969)
    * 9.1.0969: ghostty not using kitty protocol by default
    * 9.1.0968: tests: GetFileNameChecks() isn't fully sorted by filetype name
    * runtime(doc): update version9.txt for bash filetype
    * runtime(netrw): update last change header for #16265
    * runtime(doc): fix doc error in :r behaviour
    * 9.1.0967: SpotBugs compiler setup can be further improved
    * 9.1.0966: Vim9: :enum command can be shortened
    * runtime(compiler): include a basic bash syntax checker compiler
    * 9.1.0965: filetype: sh filetype set when detecting the use of bash
    * runtime(doc): clarify ARCH value for 32-bit in INSTALLpc.txt
    * 9.1.0963: fuzzy-matching does not prefer full match
    * 9.1.0962: filetype: bun.lock file is not recognized
    * runtime(vim): update indentation plugin for Vim script
    * runtime(doc): tweak documentation style in helphelp.txt
    * runtime(vim): Update base-syntax, allow parens in default arguments
    * runtime(doc): mention auto-format using clang-format for sound.c/sign.c
    * runtime(help): fix typo s/additional/arbitrary/
    * runtime(help): Add better support for language annotation highlighting
    * 9.1.0961: filetype: TI gel files are not recognized
    * 9.1.0960: filetype: hy history files are not recognized
    * translation(fi): Fix typoes in Finish menu translation
    * 9.1.0959: Coverity complains about type conversion
    * runtime(vim): Use supported syntax in indent tests
    * 9.1.0958: filetype: supertux2 config files detected as lisp
    * 9.1.0956: completion may crash, completion highlight wrong with preview window
    * 9.1.0955: Vim9: vim9compile.c can be further improved
    * runtime(doc): move help tag E1182
    * runtime(graphql): contribute vim-graphql to Vim core
    * 9.1.0954: popupmenu.c can be improved
    * 9.1.0953: filetype: APKBUILD files not correctly detected
    * 9.1.0952: Vim9: missing type checking for any type assignment
    * 9.1.0951: filetype: jshell files are not recognized
    * runtime(dockerfile): do not set commentstring in syntax script
    * 9.1.0950: filetype: fennelrc files are not recognized
    * runtime(netrw): do not double escape Vim special characters
    * git: ignore reformatting change of netrw plugin
    * runtime(netrw): more reformating #16248
    * runtime(doc): Add a note about handling symbolic links in starting.txt
    * 9.1.0949: popups inconsistently shifted to the left
    * git: ignore reformatting change of netrw plugin
    * runtime(netrw): change indent size from 1 to 2
    * 9.1.0948: Missing cmdline completion for :pbuffer
    * runtime(tutor): Reformat tutor1
    * 9.1.0947: short-description
    * 9.1.0946: cross-compiling fails on osx-arm64
    * 9.1.0945: ComplMatchIns highlight doesn't end after inserted text
    * translation(sv): re-include the change from #16240
    * 9.1.0944: tests: test_registers fails when not run under X11
    * 9.1.0943: Vim9: vim9compile.c can be further improved
    * runtime(doc): Update README and mention make check to verify
    * translation(sv): partly revert commit 98874dca6d0b60ccd6fc3a140b3ec
    * runtime(vim): update base-syntax after v9.1.0936
    * 9.1.0942: a few typos were found
    * 9.1.0941: ComplMatchIns doesn't work after multibyte chars
    * runtime(doc): Fix style in fold.txt
    * translation(sv): Fix typo in Swedish translation
    * 9.1.0940: Wrong cursor shape with "gq" and 'indentexpr' executes :normal
    * runtime(doc): fix some small errors
    * 9.1.0939: make installtutor fails
    * 9.1.0938: exclusive selection not respected when re-selecting block mode
    * 9.1.0937: test_undolist() is flaky
    * 9.1.0936: cannot highlight completed text
    * 9.1.0935: SpotBugs compiler can be improved
    * 9.1.0934: hard to view an existing buffer in the preview window
    * runtime(doc): document how to minimize fold computation costs
    * 9.1.0933: Vim9: vim9compile.c can be further improved
    * 9.1.0932: new Italian tutor not installed
    * runtime(doc): fix a few minor errors from the last doc updates
    * translation(it): add Italian translation for the interactive tutor
    * runtime(doc): update the change.txt help file
    * runtime(help): Add Vim lang annotation support for codeblocks
    * 9.1.0931: ml_get error in terminal buffer
    * 9.1.0930: tests: test_terminal2 may hang in GUI mode
    * 9.1.0929: filetype: lalrpop files are not recognized
    * 9.1.0928: tests: test_popupwin fails because the filter command fails
    * editorconfig: set trim_trailing_whitespace = false for src/testdir/test*.vim
    * 9.1.0927: style issues in insexpand.c
    * 9.1.0926: filetype: Pixi lock files are not recognized
    * runtime(doc): Add a reference to |++opt| and |+cmd| at `:h :pedit`
    * runtime(doc): add a note about inclusive motions and exclusive selection
    * 9.1.0925: Vim9: expression compiled when not necessary
    * 9.1.0924: patch 9.1.0923 causes issues
    * 9.1.0923: too many strlen() calls in filepath.c
    * 9.1.0923: wrong MIN macro in popupmenu.c
    * 9.1.0921: popupmenu logic is a bit convoluted
    * 9.1.0920: Vim9: compile_assignment() too long
    * 9.1.0919: filetype: some assembler files are not recognized
    * runtime(netrw): do not pollute search history with symlinks
    * 9.1.0918: tiny Vim crashes with fuzzy buffer completion
    * 9.1.0917: various vartabstop and shiftround bugs when shifting lines
    * runtime(typst): add definition lists to formatlistpat, update maintainer
    * 9.1.0916: messages.c is exceeding 80 columns
    * runtime(proto): include filetype plugin for protobuf
    * 9.1.0915: GVim: default font size a bit too small
    * 9.1.0914: Vim9: compile_assignment() is too long
    * 9.1.0913: no error check for neg values for 'messagesopt'
    * runtime(netrw): only check first arg of netrw_browsex_viewer for being executable
    * 9.1.0912: xxd: integer overflow with sparse files and -autoskip
    * 9.1.0911: Variable name for 'messagesopt' doesn't match short name
    * 9.1.0910: 'messagesopt' does not check max wait time
    * runtime(doc): update wrong Vietnamese localization tag
    * 9.1.0909: Vim9: crash when calling instance method

------------------------------------------------------------------
------------------  2025-1-6  -  Jan 6 2025  -------------------
------------------------------------------------------------------

++++ btrfsprogs:

  - update to 6.12
    * subvolume delete: add new option to do recursive subvolume deletion (for
    regular user delete only accessible subvolumes)
    * mkfs:
    * new option --subvol to create subvolumes in given paths, read-write,
    read-only and default
    * add hard link detection support for --rootdir option
    * fixes:
    * receive: message verbosity fixes
    * check: fix false positive report of missing checksum for extent holes
    * check: handle compressed extents when checking tree log
    * when asking Y/N user questions, flush the terminal so the question is
    displayed (e.g. btrfstune -S)
    * other
    * code refactoring, error handling
    * python packaging fixes
    * documentation updates
    * new tests
  - update to 6.11
    * check:
    * check items in tree-log
    * detect invalid file extent items for symlinks
    * properly detect inode cache and suggest removal by 'clear-ino-cache'
    * convert: fix symlink length checks
    * fi show: remove stray newline at the end of the output
    * fixes:
    * open devices in write-exclusive mode in most commands, prevent
    concurrent mount by other programs
    * rescue clear-ino-cache: fix subvolume iteration that can fail in some cases
    * map-logical: fix first extent searching condition
    * fi resize: warn if new size is below 256M
    * tree-checker:
    * slightly stricter file type validation
    * verify device extent items
    * other:
    * documentation updates
    * ship btrfs-ioctl manual page (incomplete)

++++ cloud-init:

  - Add cloud-init-wait-for-net.patch (bsc#1227237)
    + Wait for udev once if we cannot find the expected MAC

++++ gpg2:

  - note updated 2.5.x build dependencies

++++ kbd:

  - Update to version 2.7.1:
    * setfont: Fixed regression in argument parsing.
    * dumpkeys: Fixed dumpkeys on pc and non-pc architectures.
    * libkeymap: Add API to get/set keymap keywords.
    Export functions to convert the value to kernel code.
    Fix double kbdfile open.
    Dump action codes for keycode 0.
    * libkfont: Fix buffer allocation for doubled font.
    Check console mode.
    * keymaps:
    Add hcesar layout, for portuguese speaking countries.
    Update Colemak-DH keymaps with upstream changes.
    sv-latin1.map: make Ctrl+AltGr+9 act as Ctrl+].
    * fonts:
    Remove non-free Agafari fonts. (bnc#95915,
    remove repack_kbd.sh)
    * other:
    Update man pages.
    Remove deprecated startup scripts.
    (Refresh kbd-2.0.2-fix-bashisms.patch.)
    Remove outdated docs.
    (Drop kbd-1.15.2-docu-X11R6-xorg.patch.)
    Update translations.
  - Drop upstreamed patches: kbd-1.15.2-sv-latin1-keycode10.patch,
    kbd-2.0.2-doshell-reference.patch.
  - Refresh kbd-1.15.5-loadkeys-search-path.patch.
  - Releases are signed, add kbd.keyring and the signature.
  - sysconfig.keyboard: KBD_NUMLOCK="bios" works only on systems
    without Secure Boot. Document that. Change the default to
    KBD_NUMLOCK="no". (boo#1212141)
  - kbdsettings-nox86.patch: Update and return missing chunk.

++++ kernel-default:

  - mm/slub: Avoid list corruption when removing a slab from the
    full list (CVE-2024-56566 bsc#1235033).
  - commit ab1309f
  - x86/cacheinfo: Delete global num_cache_leaves (jsc#PED-10467).
  - commit b0f961c
  - cacheinfo: Allocate memory during CPU hotplug if not done from the primary CPU (jsc#PED-10467).
  - commit 948fe91
  - nfsd: fix UAF when access ex_uuid or ex_stats (CVE-2024-53216
    bsc#1235003).
  - SUNRPC: no need get cache ref when protected by rcu
    (CVE-2024-53216 bsc#1235003).
  - nfsd: no need get cache ref when protected by rcu
    (CVE-2024-53216 bsc#1235003).
  - SUNRPC: introduce cache_check_rcu to help check in rcu context
    (CVE-2024-53216 bsc#1235003).
  - commit 1400ad6
  - blacklist.conf:
  - Delete
    patches.suse/nfsd-release-svc_expkey-svc_export-with-rcu_work.patch.
    This was reverted upstream.  There is a better fix.
  - commit 3a96ba3

++++ kernel-rt:

  - mm/slub: Avoid list corruption when removing a slab from the
    full list (CVE-2024-56566 bsc#1235033).
  - commit ab1309f
  - x86/cacheinfo: Delete global num_cache_leaves (jsc#PED-10467).
  - commit b0f961c
  - cacheinfo: Allocate memory during CPU hotplug if not done from the primary CPU (jsc#PED-10467).
  - commit 948fe91
  - nfsd: fix UAF when access ex_uuid or ex_stats (CVE-2024-53216
    bsc#1235003).
  - SUNRPC: no need get cache ref when protected by rcu
    (CVE-2024-53216 bsc#1235003).
  - nfsd: no need get cache ref when protected by rcu
    (CVE-2024-53216 bsc#1235003).
  - SUNRPC: introduce cache_check_rcu to help check in rcu context
    (CVE-2024-53216 bsc#1235003).
  - commit 1400ad6
  - blacklist.conf:
  - Delete
    patches.suse/nfsd-release-svc_expkey-svc_export-with-rcu_work.patch.
    This was reverted upstream.  There is a better fix.
  - commit 3a96ba3

++++ liburing:

  - disable some tests for older kernels & strange archs

++++ libvirt:

  - security: apparmor: Fix probing of apparmor availability on the
    VM host when using modular daemons
    bsc#1235079

++++ python-Pygments:

  - update to version 2.19.1:
    * Ini: Fix quoted string regression introduced in 2.19.0
    * Lua: Fix a regression introduced in 2.19.0
  - additional changes from version 2.19.0:
    * New lexers:
    + CodeQL (#2819)
    + Debian Sources (#2788, #2747)
    + Gleam (#2662)
    + GoogleSQL (#2820, #2814)
    + JSON5 (#2734, #1880)
    + Maple (#2763, #2548)
    + NumbaIR (#2433)
    + PDDL (#2799, #2616)
    + Rego (#2794)
    + TableGen (#2751)
    + Vue.js (#2832)
    * Updated lexers:
    + BQN: Various improvements (#2789)
    + C#: Fix number highlighting (#986, #2727), add ``file``
    keyword (#2726, #2805, #2806), add various other keywords
    (#2745, #2770)
    + CSS: Add ``revert`` (#2766, #2775)
    + Debian control: Add ``Change-By`` field (#2757)
    + Elip: Improve punctuation handling (#2651)
    + Igor: Add ``int`` (#2801)
    + Ini: Fix quoted strings with embedded comment characters
    (#2767, #2720)
    + Java: Support functions returning types containing a question
    mark (#2737)
    + JavaScript: Support private identiiers (#2729, #2671)
    + LLVM: Add ``splat``, improve floating-point number parsing
    (#2755)
    + Lua: Improve variable detection, add built-in functions
    (#2829)
    + Macaulay2: Update to 1.24.11 (#2800)
    + PostgreSQL: Add more ``EXPLAIN`` keywords (#2785),
    handle ``/`` (#2774)
    + S-Lexer: Fix keywords (#2082, #2750)
    + TransactSQL: Fix single-line comments (#2717)
    + Turtle: Fix triple quoted strings (#2744, #2758)
    + Typst: Various improvements (#2724)
    + Various: Add ``^`` as an operator to Matlab, Octave and
    Scilab (#2798)
    + Vyper: Add ``staticcall`` and ``extcall`` (#2719)
    * Mark file extensions for ``HTML/XML+Evoque`` as aliases (#2743)
    * Add a color for ``Operator.Word`` to the ``rrt`` style (#2709)
    * Fix broken link in the documentation (#2803, #2804)
    * Drop executable bit where not needed (#2781)
    * Reduce Mojo priority relative to Python in ``analyze_text´`
    (#2771, #2772)
    * Fix documentation builds (#2712)
    * Match example file names to the lexer's name (#2713, #2715)
    * Ensure lexer metadata is present (#2714)
    * Search more directories on macOS for fonts (#2809)
    * Improve test robustness (#2812)

++++ python-psutil:

  - Update to 6.1.1
    * 2471_: use Vulture CLI tool to detect dead code.
    * 2418_, [Linux]: fix race condition in case /proc/PID/stat does not exist, but
    /proc/PID does, resulting in FileNotFoundError.
    * 2470_, [Linux]: `users()`_ may return "localhost" instead of the actual IP
    address of the user logged in.

------------------------------------------------------------------
------------------  2025-1-5  -  Jan 5 2025  -------------------
------------------------------------------------------------------

++++ glibc:

  - Define _enable_debug_packages for rpm 4.20

------------------------------------------------------------------
------------------  2025-1-4  -  Jan 4 2025  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.3.3
  - -> https://docs.mesa3d.org/relnotes/24.3.3
  - Update to release 24.3.2
  - -> https://docs.mesa3d.org/relnotes/24.3.2
  - supersedes the following patches:
    * 0001-dri-don-t-fetch-X11-modifiers-if-we-don-t-support-th.patch
    * 0002-egl-wayland-only-supply-LINEAR-modifier-when-support.patch
    * 0003-egl-wayland-fallback-to-implicit-modifiers-if-advert.patch

++++ Mesa-drivers:

  - Update to release 24.3.3
  - -> https://docs.mesa3d.org/relnotes/24.3.3
  - Update to release 24.3.2
  - -> https://docs.mesa3d.org/relnotes/24.3.2
  - supersedes the following patches:
    * 0001-dri-don-t-fetch-X11-modifiers-if-we-don-t-support-th.patch
    * 0002-egl-wayland-only-supply-LINEAR-modifier-when-support.patch
    * 0003-egl-wayland-fallback-to-implicit-modifiers-if-advert.patch

++++ kernel-default:

  - ALSA hda/realtek: Add quirk for Framework F111:000C
    (stable-fixes).
  - ALSA: seq: oss: Fix races at processing SysEx messages
    (stable-fixes).
  - commit c470d47
  - selftests: net: local_termination: require mausezahn
    (git-fixes).
  - wifi: cw1200: Fix potential NULL dereference (git-fixes).
  - wifi: iwlwifi: mvm: Fix __counted_by usage in
    cfg80211_wowlan_nd_* (git-fixes).
  - wifi: iwlwifi: fix CRF name for Bz (git-fixes).
  - net: phy: micrel: Dynamically control external clock of KSZ PHY
    (git-fixes).
  - pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap
    locking (git-fixes).
  - ALSA: seq: Check UMP support for midi_version change
    (git-fixes).
  - Revert "ALSA: ump: Don't enumeration invalid groups for legacy
    rawmidi" (stable-fixes).
  - ALSA: hda/tas2781: Ignore SUBSYS_ID not found for tas2563
    projects (git-fixes).
  - ALSA: usb-audio: US16x08: Initialize array before use
    (git-fixes).
  - drm: adv7511: Drop dsi single lane support (git-fixes).
  - drm: adv7511: Fix use-after-free in adv7533_attach_dsi()
    (git-fixes).
  - drm/bridge: adv7511_audio: Update Audio InfoFrame properly
    (git-fixes).
  - drm/i915/dg1: Fix power gate sequence (git-fixes).
  - drm/i915/cx0_phy: Fix C10 pll programming sequence (git-fixes).
  - drm/xe: Fix fault on fd close after unbind (git-fixes).
  - drm/xe/pf: Use correct function to check LMEM provisioning
    (git-fixes).
  - drm/xe: Wait for migration job before unmapping pages
    (git-fixes).
  - drm/xe: Use non-interruptible wait when moving BO to system
    (git-fixes).
  - drm/xe: Revert some changes that break a mesa debug tool
    (git-fixes).
  - drm/dp_mst: Ensure mst_primary pointer is valid in
    drm_dp_mst_handle_up_req() (stable-fixes).
  - commit 40c61fe

++++ kernel-rt:

  - ALSA hda/realtek: Add quirk for Framework F111:000C
    (stable-fixes).
  - ALSA: seq: oss: Fix races at processing SysEx messages
    (stable-fixes).
  - commit c470d47
  - selftests: net: local_termination: require mausezahn
    (git-fixes).
  - wifi: cw1200: Fix potential NULL dereference (git-fixes).
  - wifi: iwlwifi: mvm: Fix __counted_by usage in
    cfg80211_wowlan_nd_* (git-fixes).
  - wifi: iwlwifi: fix CRF name for Bz (git-fixes).
  - net: phy: micrel: Dynamically control external clock of KSZ PHY
    (git-fixes).
  - pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap
    locking (git-fixes).
  - ALSA: seq: Check UMP support for midi_version change
    (git-fixes).
  - Revert "ALSA: ump: Don't enumeration invalid groups for legacy
    rawmidi" (stable-fixes).
  - ALSA: hda/tas2781: Ignore SUBSYS_ID not found for tas2563
    projects (git-fixes).
  - ALSA: usb-audio: US16x08: Initialize array before use
    (git-fixes).
  - drm: adv7511: Drop dsi single lane support (git-fixes).
  - drm: adv7511: Fix use-after-free in adv7533_attach_dsi()
    (git-fixes).
  - drm/bridge: adv7511_audio: Update Audio InfoFrame properly
    (git-fixes).
  - drm/i915/dg1: Fix power gate sequence (git-fixes).
  - drm/i915/cx0_phy: Fix C10 pll programming sequence (git-fixes).
  - drm/xe: Fix fault on fd close after unbind (git-fixes).
  - drm/xe/pf: Use correct function to check LMEM provisioning
    (git-fixes).
  - drm/xe: Wait for migration job before unmapping pages
    (git-fixes).
  - drm/xe: Use non-interruptible wait when moving BO to system
    (git-fixes).
  - drm/xe: Revert some changes that break a mesa debug tool
    (git-fixes).
  - drm/dp_mst: Ensure mst_primary pointer is valid in
    drm_dp_mst_handle_up_req() (stable-fixes).
  - commit 40c61fe

++++ nvidia-open-driver-G06-signed:

  - set-FOP_UNSIGNED_OFFSET-for-nv_drm_fops.fop_flags.patch
    * needed for Kernel 6.12 for 565.57.01 driver; already fixed
    for 550.142
  - -> https://forums.developer.nvidia.com/t/patch-for-565-57-01-linux-kernel-6-12/313260

------------------------------------------------------------------
------------------  2025-1-3  -  Jan 3 2025  -------------------
------------------------------------------------------------------

++++ guestfs-tools:

  - Update to version 1.53.5 (jsc#PED-8910)
    * builder: Update opensuse.gpg key
    * mlcustomize/customize_run.ml: Move 'in' to new line
    * mlstdutils/guestfs_config: Define host_os
    * mlcustomize, mltools: Check guest OS is compatible before
    allowing --run
    * Remove mlv2v/ subdirectory
    * resize: Update xpath command
  - Drop builder-update-openSUSE.gpg-key.patch

++++ kernel-default:

  - virtiofs: use pages instead of pointer for kernel direct IO
    (CVE-2024-53219 bsc#1235010).
  - netfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING
    (CVE-2024-56755 bsc#1234920).
  - cachefiles: Fix NULL pointer dereference in object->file
    (CVE-2024-56549 bsc#1234912).
  - commit 6497a18
  - sysfs: Add /sys/kernel/realtime entry (bsc#1234370).
  - commit 67c8a0e
  - Revert "drm/i915: Depend on !PREEMPT_RT." (bsc#1234370).
  - drm/i915/guc: Consider also RCU depth in busy loop
    (bsc#1234370).
  - drm/i915: Drop the irqs_disabled() check (bsc#1234370).
  - drm/i915/gt: Use spin_lock_irq() instead of local_irq_disable()
    + spin_lock() (bsc#1234370).
  - drm/i915: Disable tracing points on PREEMPT_RT (bsc#1234370).
  - drm/i915: Don't check for atomic context on PREEMPT_RT
    (bsc#1234370).
  - drm/i915: Don't disable interrupts on PREEMPT_RT during atomic
    updates (bsc#1234370).
  - drm/i915: Use preempt_disable/enable_rt() where recommended
    (bsc#1234370).
  - commit d7bae3c
  - preempt: Add a generic function to return the preemption string
    (bsc#1234370).
  - commit 240e711
  - serial: 8250: Revert "drop lockdep annotation from
    serial8250_clear_IER()" (bsc#1234370).
  - serial: 8250: Switch to nbcon console (bsc#1234370).
  - commit 6ed51c3
  - Add SLERT-specific patches (bsc#1234370):
  - patches.suse/rt-Add-documentation-describing-what-RT-kernel-config-changes-to-default.patch
  - patches.suse/rt-Add-documentation-describing-what-kernel-debug-options-to-add-for-testing.patch
  - patches.suse/rt-Add-helper-script-to-refresh-RT-configs-based-on-the-parent.patch
  - commit a177908
  - Bluetooth: btusb: mediatek: add intf release flow when usb
    disconnect (stable-fixes).
  - Refresh
    patches.suse/Bluetooth-btmtk-adjust-the-position-to-init-iso-data.patch.
  - commit 53f7776
  - mmc: sdhci-msm: fix crypto key eviction (git-fixes).
  - ACPI/IORT: Add PMCG platform information for HiSilicon HIP09A
    (stable-fixes).
  - regmap: Use correct format specifier for logging range errors
    (stable-fixes).
  - spi: omap2-mcspi: Fix the IS_ERR() bug for
    devm_clk_get_optional_enabled() (stable-fixes).
  - spi: intel: Add Panther Lake SPI controller support
    (stable-fixes).
  - watchdog: mediatek: Add support for MT6735 TOPRGU/WDT
    (stable-fixes).
  - watchdog: rzg2l_wdt: Power on the watchdog domain in the
    restart handler (stable-fixes).
  - watchdog: it87_wdt: add PWRGD enable quirk for Qotom QCML04
    (stable-fixes).
  - platform/x86: asus-nb-wmi: Ignore unknown event 0xCF
    (stable-fixes).
  - Bluetooth: btusb: mediatek: change the conditions for ISO
    interface (stable-fixes).
  - Bluetooth: btusb: mediatek: add callback function in
    btusb_disconnect (stable-fixes).
  - Bluetooth: btusb: mediatek: move Bluetooth power off command
    position (stable-fixes).
  - commit ae01e54

++++ kernel-rt:

  - virtiofs: use pages instead of pointer for kernel direct IO
    (CVE-2024-53219 bsc#1235010).
  - netfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING
    (CVE-2024-56755 bsc#1234920).
  - cachefiles: Fix NULL pointer dereference in object->file
    (CVE-2024-56549 bsc#1234912).
  - commit 6497a18
  - sysfs: Add /sys/kernel/realtime entry (bsc#1234370).
  - commit 67c8a0e
  - Revert "drm/i915: Depend on !PREEMPT_RT." (bsc#1234370).
  - drm/i915/guc: Consider also RCU depth in busy loop
    (bsc#1234370).
  - drm/i915: Drop the irqs_disabled() check (bsc#1234370).
  - drm/i915/gt: Use spin_lock_irq() instead of local_irq_disable()
    + spin_lock() (bsc#1234370).
  - drm/i915: Disable tracing points on PREEMPT_RT (bsc#1234370).
  - drm/i915: Don't check for atomic context on PREEMPT_RT
    (bsc#1234370).
  - drm/i915: Don't disable interrupts on PREEMPT_RT during atomic
    updates (bsc#1234370).
  - drm/i915: Use preempt_disable/enable_rt() where recommended
    (bsc#1234370).
  - commit d7bae3c
  - preempt: Add a generic function to return the preemption string
    (bsc#1234370).
  - commit 240e711
  - serial: 8250: Revert "drop lockdep annotation from
    serial8250_clear_IER()" (bsc#1234370).
  - serial: 8250: Switch to nbcon console (bsc#1234370).
  - commit 6ed51c3
  - Add SLERT-specific patches (bsc#1234370):
  - patches.suse/rt-Add-documentation-describing-what-RT-kernel-config-changes-to-default.patch
  - patches.suse/rt-Add-documentation-describing-what-kernel-debug-options-to-add-for-testing.patch
  - patches.suse/rt-Add-helper-script-to-refresh-RT-configs-based-on-the-parent.patch
  - commit a177908
  - Bluetooth: btusb: mediatek: add intf release flow when usb
    disconnect (stable-fixes).
  - Refresh
    patches.suse/Bluetooth-btmtk-adjust-the-position-to-init-iso-data.patch.
  - commit 53f7776
  - mmc: sdhci-msm: fix crypto key eviction (git-fixes).
  - ACPI/IORT: Add PMCG platform information for HiSilicon HIP09A
    (stable-fixes).
  - regmap: Use correct format specifier for logging range errors
    (stable-fixes).
  - spi: omap2-mcspi: Fix the IS_ERR() bug for
    devm_clk_get_optional_enabled() (stable-fixes).
  - spi: intel: Add Panther Lake SPI controller support
    (stable-fixes).
  - watchdog: mediatek: Add support for MT6735 TOPRGU/WDT
    (stable-fixes).
  - watchdog: rzg2l_wdt: Power on the watchdog domain in the
    restart handler (stable-fixes).
  - watchdog: it87_wdt: add PWRGD enable quirk for Qotom QCML04
    (stable-fixes).
  - platform/x86: asus-nb-wmi: Ignore unknown event 0xCF
    (stable-fixes).
  - Bluetooth: btusb: mediatek: change the conditions for ISO
    interface (stable-fixes).
  - Bluetooth: btusb: mediatek: add callback function in
    btusb_disconnect (stable-fixes).
  - Bluetooth: btusb: mediatek: move Bluetooth power off command
    position (stable-fixes).
  - commit ae01e54

++++ c-ares:

  - skip-test.patch replaced with upstream unit test fix
    a531524a3d085fcd9a5e25d5f6cbdb953082c2b9.patch

++++ libguestfs:

  - Update to version 1.55.2 (jsc#PED-8910)
    * lib/inspect-osinfo.c: Add Windows Server 2025 osinfo
    * appliance: Use stable owner, group and mtime in appliance
    tarballs
    * mltools: Replace jansson with json-c
    * lib/info.c: Replace jansson with json-c
    * lib/qemu.c: Replace jansson with json-c
    * lib: direct: Remove test for qemu mandatory locking
    * Various language translations
    * Fix dhcpcd failing on systemd-resolved stub
    * mlcustomize: Add heuristic support for Windows Server 2025
    * mlcustomize/customize_run.ml: Move 'in' to new line
    * mlstdutils/guestfs_config: Define host_os
    * mlcustomize, mltools: Check guest OS is compatible before
    allowing --run
    * generator: Remove common/mlv2v/uefi.ml{,i} files
    * qemuopts: Add ability to add raw, unquoted output to qemu
    scripts
    * qemuopts: Fix missing break statement
    * mlstdutils: Remove Option module
    * Remove test for caml_alloc_initialized_string
    * build: Move baseline OCaml to 4.08

++++ libvirt:

  - tests: Extend EOY check in virtimetest
    boo#1234995

++++ python-maturin:

  - Update to 1.8.1
    * Downgrade invalid version info in `pyproject.toml` error to
    warning in #2417
    * Make `maturin develop` fail if version info is invalid in
    pyproject.toml in #2418
    * Don't add wheel data to sdist in #2367
    * Add sparcv9 architecture support in #2380
    * Properly handle dynamic version in pyproject.toml in #2391
    * Fix xwin cross compile on non-Windows system in #2391
    * Fix interpreter selection for abi3 bindings in #2392
    * Use the official recommended naming pattern for cffi module
    file in #2406
    * Add Linux armv5te architecture support in #2409
    * Only build Python 3.13t wheels by default for `pyo3` 0.23+ in
    [#2413]

------------------------------------------------------------------
------------------  2025-1-2  -  Jan 2 2025  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20250102.c08e614:
    * Load distrobox_profile.sh

++++ kbd:

  - Remove obsolete parts of suse-add.tar.bz2 (jsc#PED-7977),
    possible BREAKING CHANGES for obscure configurations:
    * Replace consolefonts/Cyr_a8x*.psf with upstream instances.
    * Replace consolefonts/cp850-full-8x*.psfu with upstream
    instances.
    * Drop consolefonts/lat5--*.psfu in favor of upstream
    lat5-*.psfu, exactly the same fonts with a better unimap.
    * Drop consolefonts/lat7.psf as it is lat7a-16.psf in the
    upstream.
    * Drop consolefonts/lt-brim-8x14.psfu in favor of upstream
    lat7a-14.psfu, exactly the same fonts with a better unimap.
    * Drop keymaps/i386/qwerty/Pl02.map in favor of nearly equal
    upstream pl2.map.
    * Drop keymaps/i386/qwerty/br-abnt-alt.map in favor of nearly
    equal upstream br-abnt.map.
    * Drop keymaps/i386/qwerty/tj_alt-UTF8.map that is already
    upstreamed.
    * Drop unimaps/iso07*.uni that is already upstreamed.
  - Remove broken KBD_DISABLE_CAPS_LOCK feature (sysconfig.keyboard,
    kbdsettings, boo#1179897, jsc#PED-7814).
    Can be replaced by KEYMAP="{my map} disable.capslock" in
    /etc/vconsole.conf.

++++ kernel-default:

  - slab: Fix too strict alignment check in create_cache()
    (CVE-2024-56560 bsc#1234925).
  - commit 13fdc6a
  - EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161
    bsc#1234856).
  - commit 9d9eb76
  - supported.conf: externally supported drivers/s390/crypto/pkey_* (jsc#PED-11872)
  - commit 4f63bae
  - s390/pci: Expose FIDPARM attribute in sysfs (jsc#PED-11868).
  - commit 11fe795

++++ kernel-rt:

  - slab: Fix too strict alignment check in create_cache()
    (CVE-2024-56560 bsc#1234925).
  - commit 13fdc6a
  - EDAC/bluefield: Fix potential integer overflow (CVE-2024-53161
    bsc#1234856).
  - commit 9d9eb76
  - supported.conf: externally supported drivers/s390/crypto/pkey_* (jsc#PED-11872)
  - commit 4f63bae
  - s390/pci: Expose FIDPARM attribute in sysfs (jsc#PED-11868).
  - commit 11fe795

++++ libxcrypt:

  - Update to 4.4.37
    * Several fixes to the manpages (issue #185).
    * Only test the needed makecontext signature during configure (issue #178).
    * Fix -Werror=strict-overflow in lib/crypt-bcrypt.c, which is seen by GCC
    4.8.5 (issue #197).
  - Symlink duplicated manpages

++++ libnettle:

  - Update to nettle 3.10.1:
    * Bug fixes:
  - Fix buffer overread in the new sha256 assembly for
    powerpc64, as well as a stack alignment issue.
  - Added missing nettle_mac structs for hmac-gosthash.
  - Fix configure test for valgrind, to not attempt to run
    valgrind on executables built using memory sanitizers.
    * Enable back the gcm regression test:
  - Remove libnettle-powerpc64-skip-AES-GCM-test.patch
    * Remove patches upstream:
  - libnettle-powerpc64-sha256-fix-loading-overreads.patch
  - libnettle-powerpc64-sha256-adjust-stack-offset-for-non-volatile-registers.patch
  - libnettle-powerpc64-remove-m4_unquote-sha256.patch

++++ python-attrs:

  - update to 24.3.0:
    * Python 3.7 has been dropped.
    * Introduce `attrs.NothingType`, for annotating types
    consistent with `attrs.NOTHING`.
    * Allow mutating `__suppress_context__` and `__notes__` on
    frozen exceptions.
    * `attrs.converters.optional()` works again when taking
    `attrs.converters.pipe()` or another Converter as its
    argument.
    * *attrs* instances now support `copy.replace()`.
    * `attrs.validators.instance_of()`'s type hints now allow for
    union types.
    * For example: `instance_of(str | int)`

++++ yast2:

  - Fix failing tests with ruby 3.4 (gh#yast/yast-yast2#1314)
  - 5.0.11

------------------------------------------------------------------
------------------  2025-1-1  -  Jan 1 2025  -------------------
------------------------------------------------------------------

++++ dpdk:

  -  Fix CVE-2024-11614 [bsc#1234718] - Denial Of Service from malicious guest on hypervisors using DPDK Vhost library
  -  Added patch,
    + dpdk-CVE-2024-11614.patch

++++ hyper-v:

  - update route parsing in kvp daemon (9bbb8a07)
  - reduce resource usage in hv_kvp_daemon (175c71c2)
  - reduce resouce usage in hv_get_dns_info helper (a4d024fe)
  - hv_kvp_daemon: Pass NIC name to hv_get_dns_info as well (07dfa6e8)
  - terminate fcopy daemon if read from uio fails (a9640fcd)
  - change permissions of NetworkManager configuration file (91ae69c7)
  - Fix a complier warning in the fcopy uio daemon (cb1b78f1)
  - remove obsolete kvptest.ps1.txt which failed since a decade
  - remove obsolete rpm postinstall code for SLE11SP2

++++ kernel-firmware-all:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-amdgpu:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-ath10k:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-ath11k:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-ath12k:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-atheros:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-bluetooth:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-bnx2:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-brcm:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-chelsio:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-dpaa2:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-i915:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-intel:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-iwlwifi:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-liquidio:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-marvell:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-media:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-mediatek:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-mellanox:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-mwifiex:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-network:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-nfp:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-nvidia:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-platform:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-prestera:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-qcom:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-qlogic:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-radeon:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-realtek:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-serial:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-sound:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-ti:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-ueagle:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kernel-firmware-usb-network:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

++++ kexec-tools:

  - force -std=gnu99 because C99 because the code uses features

++++ ucode-amd:

  - Update to version 20241220 (git commit 9cf329b39cf1):
    * cnm: update chips&media wave521c firmware.
    * WHENCE: Add "Info:" tag to text that's clearly not part of the license
    * rtl_nic: add firmware rtl8125bp-2
    * qcom: venus-5.4: update firmware binary for sc7180 and qcs615
    * cirrus: cs35l56: Correct filenames of SSID 17aa3832
    * cirrus: cs35l56: Add and update firmware for various Cirrus CS35L54 and CS35L56 laptops
    * cirrus: cs35l56: Correct SSID order for 103c8d01 103c8d08 10431f43

------------------------------------------------------------------
------------------  2024-12-31  -  Dec 31 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix genprotimg for s390 builds
    A recent change on genprotimg now forbids to use --cert in
    combination with --no-verify, even though this was allowed
    before.

++++ kernel-default:

  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 21QA and 21QB
    (git-fixes).
  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 21Q6 and 21Q7
    (git-fixes).
  - riscv: Fix wrong usage of __pa() on a fixmap address
    (git-fixes).
  - commit 70097d1
  - stddef: make __struct_group() UAPI C++-friendly (git-fixes).
  - thunderbolt: Improve redrive mode handling (git-fixes).
  - thunderbolt: Don't display nvm_version unless upgrade supported
    (git-fixes).
  - thunderbolt: Add support for Intel Panther Lake-M/P
    (stable-fixes).
  - xhci: Turn NEC specific quirk for handling Stop Endpoint errors
    generic (stable-fixes).
  - USB: serial: option: add Telit FE910C04 rmnet compositions
    (stable-fixes).
  - USB: serial: option: add MediaTek T7XX compositions
    (stable-fixes).
  - USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready
    (stable-fixes).
  - USB: serial: option: add MeiG Smart SLM770A (stable-fixes).
  - USB: serial: option: add TCL IK512 MBIM & ECM (stable-fixes).
  - usb: typec: ucsi: Fix completion notifications (git-fixes).
  - usb: dwc2: Fix HCD port connection race (git-fixes).
  - usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature (git-fixes).
  - usb: dwc2: Fix HCD resume (git-fixes).
  - usb: gadget: u_serial: Fix the issue that gs_start_io crashed
    due to accessing null pointer (git-fixes).
  - usb: misc: onboard_usb_dev: skip suspend/resume sequence for
    USB5744 SMBus support (git-fixes).
  - usb: dwc3: xilinx: make sure pipe clock is deselected in usb2
    only mode (git-fixes).
  - usb: core: hcd: only check primary hcd skip_phy_initialization
    (git-fixes).
  - usb: gadget: midi2: Fix interpretation of is_midi1 bits
    (git-fixes).
  - usb: dwc3: imx8mp: fix software node kernel dump (git-fixes).
  - usb: typec: anx7411: fix OF node reference leaks in
    anx7411_typec_switch_probe() (git-fixes).
  - usb: typec: anx7411: fix fwnode_handle reference leak
    (git-fixes).
  - usb: host: max3421-hcd: Correctly abort a USB request
    (git-fixes).
  - usb: ehci-hcd: fix call balance of clocks handling routines
    (git-fixes).
  - spi: rockchip: Fix PM runtime count on no-op cs (git-fixes).
  - spi: aspeed: Fix an error handling path in
    aspeed_spi_[read|write]_user() (git-fixes).
  - Revert "unicode: Don't special case ignorable code points"
    (stable-fixes).
  - usb: typec: ucsi: glink: be more precise on orientation-aware
    ports (stable-fixes).
  - usb: typec: ucsi: Do not call ACPI _DSM method for UCSI read
    operations (stable-fixes).
  - usb: chipidea: udc: handle USB Error Interrupt if IOC not set
    (stable-fixes).
  - usb: chipidea: udc: create bounce buffer for problem sglist
    entries if possible (stable-fixes).
  - usb: chipidea: udc: limit usb request length to max 16KB
    (stable-fixes).
  - usb: chipidea: add CI_HDRC_HAS_SHORT_PKT_LIMIT flag
    (stable-fixes).
  - thermal/drivers/qcom/tsens-v1: Add support for MSM8937 tsens
    (stable-fixes).
  - wifi: brcmfmac: Fix oops due to NULL pointer dereference in
    brcmf_sdiod_sglist_rw() (stable-fixes).
  - wifi: ipw2x00: libipw_rx_any(): fix bad alignment
    (stable-fixes).
  - wifi: ath5k: add PCI ID for Arcadyan devices (stable-fixes).
  - wifi: ath5k: add PCI ID for SX76X (stable-fixes).
  - wifi: ath10k: avoid NULL pointer error during sdio remove
    (stable-fixes).
  - wifi: ath12k: fix atomic calls in
    ath12k_mac_op_set_bitrate_mask() (stable-fixes).
  - wifi: rtw89: check return value of ieee80211_probereq_get()
    for RNR (stable-fixes).
  - wifi: rtw88: use ieee80211_purge_tx_queue() to purge TX skb
    (stable-fixes).
  - spi: spi-fsl-lpspi: Adjust type of scldiv (stable-fixes).
  - commit e030fc8
  - power: supply: bq24190: Fix BQ24296 Vbus regulator support
    (git-fixes).
  - power: supply: cros_charge-control: hide start threshold on
    v2 cmd (git-fixes).
  - power: supply: cros_charge-control: allow start_threshold ==
    end_threshold (git-fixes).
  - power: supply: cros_charge-control: add mutex for driver data
    (git-fixes).
  - power: supply: gpio-charger: Fix set charge current limits
    (git-fixes).
  - selftests/memfd: run sysctl tests when PID namespace support
    is enabled (git-fixes).
  - selftests: openvswitch: fix tcpdump execution (git-fixes).
  - regulator: axp20x: AXP717: set ramp_delay (git-fixes).
  - kselftest/arm64: abi: fix SVCR detection (git-fixes).
  - selftests: netfilter: Stabilize rpath.sh (git-fixes).
  - selftests: mlxsw: sharedbuffer: Ensure no extra packets are
    counted (git-fixes).
  - selftests: mlxsw: sharedbuffer: Remove duplicate test cases
    (git-fixes).
  - selftests: mlxsw: sharedbuffer: Remove h1 ingress test case
    (git-fixes).
  - selftests/ftrace: adjust offset for kprobe syntax error test
    (git-fixes).
  - selftests/damon: add _damon_sysfs.py to TEST_FILES (git-fixes).
  - selftest: hugetlb_dio: fix test naming (git-fixes).
  - selftests: hid: fix typo and exit code (git-fixes).
  - setlocalversion: work around "git describe" performance
    (stable-fixes).
  - rtc: cmos: avoid taking rtc_lock for extended period of time
    (stable-fixes).
  - serial: 8250_dw: Add Sophgo SG2044 quirk (stable-fixes).
  - selftests: rds: move test.py to TEST_FILES (git-fixes).
  - regulator: qcom-rpmh: Update ranges for FTSMPS525
    (stable-fixes).
  - selftests/mount_setattr: Fix failures on 64K PAGE_SIZE kernels
    (git-fixes).
  - remoteproc: qcom: pas: enable SAR2130P audio DSP support
    (stable-fixes).
  - selftests/damon/debugfs_duplicate_context_creation: hide errors
    from expected file write failures (git-fixes).
  - selftests/damon/_debugfs_common: hide expected error message
    from test_write_result() (git-fixes).
  - selftests/damon/huge_count_read_write: remove unnecessary
    debugging message (git-fixes).
  - selftests/damon/huge_count_read_write: provide sufficiently
    large buffer for DEPRECATED file read (git-fixes).
  - selftests: netfilter: Fix missing return values in
    conntrack_dump_flush (git-fixes).
  - selftests: net: really check for bg process completion
    (git-fixes).
  - soc: imx8m: Probe the SoC driver as platform driver
    (stable-fixes).
  - soc: qcom: pd-mapper: Add QCM6490 PD maps (stable-fixes).
  - soc: qcom: llcc: Use designated initializers for LLC settings
    (stable-fixes).
  - regmap: maple: Provide lockdep (sub)class for maple tree's
    internal lock (stable-fixes).
  - selftests/resctrl: Protect against array overflow when reading
    strings (stable-fixes).
  - selftests/resctrl: Protect against array overrun during iMC
    config parsing (git-fixes).
  - selftests/resctrl: Fix memory overflow due to unhandled
    wraparound (git-fixes).
  - selftests/resctrl: Print accurate buffer size as part of MBM
    results (git-fixes).
  - selftests/mm: Fix unused function warning for
    aarch64_write_signal_pkey() (git-fixes).
  - kselftest/arm64: Don't leak pipe fds in pac.exec_sign_all()
    (stable-fixes).
  - kselftest/arm64: Fix encoding for SVE B16B16 test (git-fixes).
  - kselftest/arm64: Log fp-stress child startup errors to stdout
    (stable-fixes).
  - kselftest/arm64: mte: fix printf type warnings about longs
    (git-fixes).
  - kselftest/arm64: mte: fix printf type warnings about __u64
    (git-fixes).
  - kselftest/arm64: hwcap: fix f8dp2 cpuinfo name (git-fixes).
  - kselftest/arm64: signal: drop now redundant GNU_SOURCE
    definition (git-fixes).
  - commit 5e98b23
  - platform/x86: mlx-platform: call pci_dev_put() to balance the
    refcount (git-fixes).
  - PCI/MSI: Handle lack of irqdomain gracefully (git-fixes).
  - phy: core: Fix an OF node refcount leakage in
    of_phy_provider_lookup() (git-fixes).
  - phy: core: Fix an OF node refcount leakage in _of_phy_get()
    (git-fixes).
  - phy: core: Fix that API devm_phy_destroy() fails to destroy
    the phy (git-fixes).
  - phy: core: Fix that API devm_of_phy_provider_unregister()
    fails to unregister the phy provider (git-fixes).
  - phy: core: Fix that API devm_phy_put() fails to release the phy
    (git-fixes).
  - phy: rockchip: samsung-hdptx: Set drvdata before enabling
    runtime PM (git-fixes).
  - phy: qcom-qmp: Fix register name in RX Lane config of SC8280XP
    (git-fixes).
  - phy: rockchip: naneng-combphy: fix phy reset (git-fixes).
  - phy: usb: Toggle the PHY power during init (git-fixes).
  - platform/chrome: cros_ec_lpc: fix product identity for early
    Framework Laptops (git-fixes).
  - mtd: rawnand: arasan: Fix missing de-registration of NAND
    (git-fixes).
  - mtd: rawnand: arasan: Fix double assertion of chip-select
    (git-fixes).
  - mtd: diskonchip: Cast an operand to prevent potential overflow
    (git-fixes).
  - mtd: rawnand: fix double free in atmel_pmecc_create_user()
    (git-fixes).
  - of/irq: Fix using uninitialized variable @addr_len in API
    of_irq_parse_one() (git-fixes).
  - of/irq: Fix interrupt-map cell length check in
    of_irq_parse_imap_parent() (git-fixes).
  - of: Fix refcount leakage for OF node returned by
    __of_get_dma_parent() (git-fixes).
  - of: Fix error path in of_parse_phandle_with_args_map()
    (git-fixes).
  - of: address: Preserve the flags portion on 1:1 dma-ranges
    mapping (git-fixes).
  - of: property: fw_devlink: Do not use interrupt-parent directly
    (git-fixes).
  - objtool/x86: allow syscall instruction (stable-fixes).
  - p2sb: Do not scan and remove the P2SB device when it is unhidden
    (git-fixes).
  - p2sb: Move P2SB hide and unhide code to p2sb_scan_and_cache()
    (stable-fixes).
  - p2sb: Introduce the global flag p2sb_hidden_by_bios
    (stable-fixes).
  - p2sb: Factor out p2sb_read_from_cache() (stable-fixes).
  - PCI: vmd: Add DID 8086:B06F and 8086:B60B for Intel client SKUs
    (stable-fixes).
  - PCI: qcom: Add support for IPQ9574 (stable-fixes).
  - PCI: Add ACS quirk for Wangxun FF5xxx NICs (stable-fixes).
  - PCI: Detect and trust built-in Thunderbolt chips (stable-fixes).
  - PCI: Add 'reset_subordinate' to reset hierarchy below bridge
    (stable-fixes).
  - PCI: starfive: Enable controller runtime PM before probing
    host bridge (stable-fixes).
  - PCI: vmd: Set devices to D0 before enabling PM L1 Substates
    (stable-fixes).
  - pinctrl: qcom: spmi-mpp: Add PM8937 compatible (stable-fixes).
  - pinctrl: qcom-pmic-gpio: add support for PM8937 (stable-fixes).
  - pinmux: Use sequential access to access desc->pinmux data
    (stable-fixes).
  - of: Allow overlay kunit tests to run CONFIG_OF_OVERLAY=n
    (git-fixes).
  - of/fdt: add dt_phys arg to early_init_dt_scan and
    early_init_dt_verify (git-fixes).
  - commit 52557e8
  - media: dvb-frontends: dib3000mb: fix uninit-value in
    dib3000_write_reg (git-fixes).
  - mmc: mtk-sd: disable wakeup in .remove() and in the error path
    of .probe() (git-fixes).
  - mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC
    quirk (git-fixes).
  - modpost: Add .irqentry.text to OTHER_SECTIONS (stable-fixes).
  - mmc: sdhci-pci: Add DMI quirk for missing CD GPIO on Vexia
    Edu Atla 10 tablet (stable-fixes).
  - misc: eeprom: eeprom_93cx6: Add quirk for extra read clock cycle
    (stable-fixes).
  - media: cx231xx: Add support for Dexatek USB Video Grabber
    1d19:6108 (stable-fixes).
  - media: uvcvideo: Force UVC version to 1.0a for 0408:4033
    (stable-fixes).
  - media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared
    camera (stable-fixes).
  - media: uvcvideo: RealSense D421 Depth module metadata
    (stable-fixes).
  - mmc: mtk-sd: Fix MMC_CAP2_CRYPTO flag setting (git-fixes).
  - mmc: mtk-sd: Fix error handle of probe function (git-fixes).
  - mmc: core: Use GFP_NOIO in ACMD22 (git-fixes).
  - mmc: mtk-sd: fix devm_clk_get_optional usage (stable-fixes).
  - mmc: mtk-sd: use devm_mmc_alloc_host (stable-fixes).
  - mmc: core: Adjust ACMD22 to SDUC (stable-fixes).
  - mmc: sd: SDUC Support Recognition (stable-fixes).
  - mmc: sdhci-esdhc-imx: enable quirks SDHCI_QUIRK_NO_LED
    (stable-fixes).
  - mmc: core: Add SD card quirk for broken poweroff notification
    (stable-fixes).
  - commit ba13df0
  - Update config files: CONFIG_HISILICON_ERRATUM_162100801=y
  - commit ff7aefc
  - linux/dmaengine.h: fix a few kernel-doc warnings (git-fixes).
  - irqchip/gic-v3: Work around insecure GIC integrations
    (git-fixes).
  - lib: stackinit: hide never-taken branch from compiler
    (stable-fixes).
  - irqchip/gicv3-its: Add workaround for hip09 ITS erratum
    162100801 (stable-fixes).
  - iio: light: ltr501: Add LTER0303 to the supported devices
    (stable-fixes).
  - iio: adc: ad7192: properly check spi_get_device_match_data()
    (stable-fixes).
  - mailbox: pcc: Check before sending MCTP PCC response ACK
    (stable-fixes).
  - leds: class: Protect brightness_show() with led_cdev->led_access
    mutex (stable-fixes).
  - kcsan: Turn report_filterlist_lock into a raw_spinlock
    (stable-fixes).
  - commit d2834e2
  - i2c: microchip-core: fix "ghost" detections (git-fixes).
  - i2c: microchip-core: actually use repeated sends (git-fixes).
  - i2c: imx: add imx7d compatible string for applying erratum
    ERR007805 (git-fixes).
  - hwmon: (tmp513) Fix interpretation of values of Temperature
    Result and Limit Registers (git-fixes).
  - hwmon: (tmp513) Fix Current Register value interpretation
    (git-fixes).
  - hwmon: (tmp513) Fix interpretation of values of Shunt Voltage
    and Limit Registers (git-fixes).
  - i915/guc: Accumulate active runtime on gt reset (git-fixes).
  - i915/guc: Ensure busyness counter increases motonically
    (git-fixes).
  - i915/guc: Reset engine utilization buffer before registration
    (git-fixes).
  - i2c: riic: Always round-up when calculating bus period
    (git-fixes).
  - i2c: pnx: Fix timeout in wait functions (git-fixes).
  - gpio: graniterapids: Fix GPIO Ack functionality (stable-fixes).
  - gpio: graniterapids: Check if GPIO line can be used for IRQs
    (stable-fixes).
  - gpio: graniterapids: Determine if GPIO pad can be used by driver
    (stable-fixes).
  - gpio: graniterapids: Fix invalid RXEVCFG register bitmask
    (stable-fixes).
  - gpio: graniterapids: Fix invalid GPI_IS register offset
    (stable-fixes).
  - gpio: graniterapids: Fix incorrect BAR assignment
    (stable-fixes).
  - gpio: graniterapids: Fix vGPIO driver crash (stable-fixes).
  - gpio: ljca: Initialize num before accessing item in
    ljca_gpio_config (git-fixes).
  - i3c: Use i3cdev->desc->info instead of calling
    i3c_device_get_info() to avoid deadlock (stable-fixes).
  - i3c: mipi-i3c-hci: Mask ring interrupts before ring stop request
    (stable-fixes).
  - i3c: master: Fix dynamic address leak when 'assigned-address'
    is present (git-fixes).
  - i3c: master: Extend address status bit to 4 and add
    I3C_ADDR_SLOT_EXT_DESIRED (stable-fixes).
  - i3c: master: Replace hard code 2 with macro
    I3C_ADDR_SLOT_STATUS_BITS (stable-fixes).
  - i2c: i801: Add support for Intel Panther Lake (stable-fixes).
  - HID: add per device quirk to force bind to hid-generic
    (stable-fixes).
  - HID: magicmouse: Apple Magic Trackpad 2 USB-C driver support
    (stable-fixes).
  - gpio: grgpio: Add NULL check in grgpio_probe (git-fixes).
  - iio: magnetometer: fix if () scoped_guard() formatting
    (git-fixes).
  - hwmon: (nct6775) Add 665-ACE/600M-CL to ASUS WMI monitoring list
    (stable-fixes).
  - commit 0ebc937
  - drm/amdgpu/nbio7.0: fix IP version check (stable-fixes).
  - drm/amd: Update strapping for NBIO 2.5.0 (stable-fixes).
  - drm/amdgpu: Handle NULL bo->tbo.resource (again) in
    amdgpu_vm_bo_update (git-fixes).
  - drm/amdgpu: fix amdgpu_coredump (stable-fixes).
  - drm/amdgpu/smu14.0.2: fix IP version check (stable-fixes).
  - drm/amdgpu/gfx12: fix IP version check (stable-fixes).
  - drm/amdgpu/mmhub4.1: fix IP version check (stable-fixes).
  - drm/amdgpu/nbio7.11: fix IP version check (stable-fixes).
  - drm/amdgpu/nbio7.7: fix IP version check (stable-fixes).
  - drm/amdgpu: don't access invalid sched (git-fixes).
  - drm/modes: Avoid divide by zero harder in drm_mode_vrefresh()
    (stable-fixes).
  - drm/display: use ERR_PTR on DP tunnel manager creation fail
    (git-fixes).
  - drm/panel: synaptics-r63353: Fix regulator unbalance
    (git-fixes).
  - drm/panel: st7701: Add prepare_prev_first flag to drm_panel
    (git-fixes).
  - drm/panel: novatek-nt35950: fix return value check in
    nt35950_probe() (git-fixes).
  - drm/panel: himax-hx83102: Add a check to prevent NULL pointer
    dereference (git-fixes).
  - firmware: arm_ffa: Fix the race around setting
    ffa_dev->properties (git-fixes).
  - drm/panic: remove spurious empty line to clean warning
    (git-fixes).
  - drm/amdkfd: pause autosuspend when creating pdd (stable-fixes).
  - drm/amdgpu: fix when the cleaner shader is emitted (git-fixes).
  - drm/amdkfd: hard-code MALL cacheline size for gfx11, gfx12
    (stable-fixes).
  - drm/amdkfd: hard-code cacheline size for gfx11 (stable-fixes).
  - drm/amdkfd: Dereference null return value (git-fixes).
  - drm/amd/pm: Set SMU v13.0.7 default workload type
    (stable-fixes).
  - drm/amdgpu: fix UVD contiguous CS mapping problem
    (stable-fixes).
  - drm/xe/reg_sr: Remove register pool (git-fixes).
  - drm/xe: Call invalidation_fence_fini for PT inval fences in
    error state (git-fixes).
  - drm/xe: fix the ERR_PTR() returned on failure to allocate tiny
    pt (git-fixes).
  - drm/i915: Fix memory leak by correcting cache object name in
    error handler (git-fixes).
  - drm/i915: Fix NULL pointer dereference in capture_engine
    (git-fixes).
  - drm/i915/color: Stop using non-posted DSB writes for legacy LUT
    (git-fixes).
  - drm/amd/pm: fix and simplify workload handling (stable-fixes).
  - drm/amd/display: Limit VTotal range to max hw cap minus fp
    (stable-fixes).
  - drm/amd/display: Correct prefetch calculation (stable-fixes).
  - drm/amd/display: Add a left edge pixel if in YCbCr422 or
    YCbCr420 and odm (stable-fixes).
  - drm/amdkfd: hard-code cacheline for gc943,gc944 (stable-fixes).
  - drm/amdkfd: add MEC version that supports no PCIe atomics for
    GFX12 (stable-fixes).
  - drm/amdgpu/hdp7.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp6.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp5.2: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp5.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp4.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/dp_mst: Verify request type in the corresponding down
    message reply (stable-fixes).
  - drm/dp_mst: Fix MST sideband message body length check
    (stable-fixes).
  - drm/amdgpu/vcn: reset fw_shared when VCPU buffers corrupted
    on vcn v4.0.3 (stable-fixes).
  - drm/amd/display: Ignore scalar validation failure if pipe is
    phantom (stable-fixes).
  - Revert "drm/amd/display: parse umc_info or vram_info based on
    ASIC" (stable-fixes).
  - drm/panic: Add ABGR2101010 support (stable-fixes).
  - drm/amdgpu: set the right AMDGPU sg segment limitation
    (stable-fixes).
  - drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov
    (stable-fixes).
  - drm/amd/display: Prune Invalid Modes For HDMI Output
    (stable-fixes).
  - drm/amd/display: parse umc_info or vram_info based on ASIC
    (stable-fixes).
  - drm/amd/display: Remove hw w/a toggle if on DP2/HPO
    (stable-fixes).
  - drm/amd/display: Fix underflow when playing 8K video in full
    screen mode (stable-fixes).
  - drm/xe/devcoredump: Update handling of xe_force_wake_get return
    (stable-fixes).
  - drm/xe/forcewake: Add a helper xe_force_wake_ref_has_domain()
    (stable-fixes).
  - drm/sched: memset() 'job' in drm_sched_job_init()
    (stable-fixes).
  - drm/panel: simple: Add Microchip AC69T88A LVDS Display panel
    (stable-fixes).
  - drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr
    (stable-fixes).
  - drm/amdgpu: Dereference the ATCS ACPI buffer (stable-fixes).
  - drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts
    for vega20_ih (stable-fixes).
  - drm/amdgpu/gfx9: Add cleaner shader for GFX9.4.2 (stable-fixes).
  - drm/amd/display: Adding array index check to prevent memory
    corruption (stable-fixes).
  - drm/amd/display: Full exit out of IPS2 when all allow signals
    have been cleared (stable-fixes).
  - drm/amd/display: disable SG displays on cyan skillfish
    (stable-fixes).
  - drm/amd/display: calculate final viewport before TAP
    optimization (stable-fixes).
  - drm/amd/display: Fix garbage or black screen when resetting otg
    (stable-fixes).
  - drm/amd/display: skip disable CRTC in seemless bootup case
    (stable-fixes).
  - drm/radeon/r600_cs: Fix possible int overflow in
    r600_packet3_check() (stable-fixes).
  - drm/amd/display: Fix out-of-bounds access in
    'dcn21_link_encoder_create' (stable-fixes).
  - drm/display: Fix building with GCC 15 (stable-fixes).
  - drm/xe/xe3: Add initial set of workarounds (stable-fixes).
  - drm/xe/ptl: L3bank mask is not available on the media GT
    (stable-fixes).
  - drm/xe/guc: Copy GuC log prior to dumping (stable-fixes).
  - drm/xe/devcoredump: Add ASCII85 dump helper function
    (stable-fixes).
  - drm/xe/devcoredump: Improve section headings and add tile info
    (stable-fixes).
  - drm/xe/devcoredump: Use drm_puts and already cached local
    variables (stable-fixes).
  - drm/xe/pciid: Add new PCI id for ARL (stable-fixes).
  - drm/xe/pciids: Add PVC's PCI device ID macros (stable-fixes).
  - drm/xe/pciids: separate ARL and MTL PCI IDs (stable-fixes).
  - drm/xe/pciids: separate RPL-U and RPL-P PCI IDs (stable-fixes).
  - drm/mcde: Enable module autoloading (stable-fixes).
  - firmware: qcom: scm: Allow QSEECOM on Dell XPS 13 9345
    (stable-fixes).
  - firmware: qcom: scm:  Allow QSEECOM on Lenovo Yoga Slim 7x
    (stable-fixes).
  - gpio: grgpio: use a helper variable to store the address of
    ofdev->dev (stable-fixes).
  - gpio: free irqs that are still requested when the chip is
    being removed (stable-fixes).
  - commit d415f2b
  - dmaengine: tegra: Return correct DMA status when paused
    (git-fixes).
  - dmaengine: mv_xor: fix child node refcount handling in early
    exit (git-fixes).
  - dmaengine: fsl-edma: implement the cleanup path of
    fsl_edma3_attach_pd() (git-fixes).
  - dmaengine: amd: qdma: Remove using the private get and set
    dma_ops APIs (git-fixes).
  - dmaengine: apple-admac: Avoid accessing registers in probe
    (git-fixes).
  - dmaengine: dw: Select only supported masters for ACPI devices
    (git-fixes).
  - dmaengine: at_xdmac: avoid null_prt_deref in
    at_xdmac_prep_dma_memset (git-fixes).
  - dma-buf: Fix __dma_buf_debugfs_list_del argument for
    !CONFIG_DEBUG_FS (git-fixes).
  - can: m_can: fix missed interrupts with m_can_pci (git-fixes).
  - can: m_can: set init flag earlier in probe (git-fixes).
  - cxl/region: Fix region creation for greater than x2 switches
    (git-fixes).
  - cxl/pci: Fix potential bogus return value upon successful
    probing (git-fixes).
  - crypto: hisilicon/debugfs - fix the struct pointer incorrectly
    offset problem (git-fixes).
  - Documentation: PM: Clarify pm_runtime_resume_and_get() return
    value (git-fixes).
  - Documentation: networking: Add a caveat to nexthop_compat_mode
    sysctl (git-fixes).
  - clk: en7523: Initialize num before accessing hws in
    en7523_register_clocks() (git-fixes).
  - clk: en7523: Fix wrong BUS clock for EN7581 (git-fixes).
  - dma-buf: fix dma_fence_array_signaled v4 (stable-fixes).
  - clk: qcom: clk-alpha-pll: Add NSS HUAYRA ALPHA PLL support
    for ipq9574 (stable-fixes).
  - clk: qcom: dispcc-sm8550: enable support for SAR2130P
    (stable-fixes).
  - clk: qcom: tcsrcc-sm8550: add SAR2130P support (stable-fixes).
  - clk: qcom: rpmh: add support for SAR2130P (stable-fixes).
  - clk: qcom: rcg2: add clk_rcg2_shared_floor_ops (stable-fixes).
  - drm/bridge: it6505: Enable module autoloading (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO GEEK
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO Founder
    edition (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model
    (stable-fixes).
  - drm/vc4: hvs: Set AXI panic modes for the HVS (stable-fixes).
  - drm/vc4: hdmi: Avoid log spam for audio start failure
    (stable-fixes).
  - dma-debug: fix a possible deadlock on radix_lock (stable-fixes).
  - Documentation: tipc: fix formatting issue in tipc.rst
    (git-fixes).
  - cleanup: Adjust scoped_guard() macros to avoid potential warning
    (stable-fixes).
  - crypto: ecdsa - Avoid signed integer overflow on signature
    decoding (stable-fixes).
  - commit 8e66607
  - ASoC: SOF: Intel: hda-dai: Do not release the link DMA on STOP
    (git-fixes).
  - ASoC: amd: ps: Fix for enabling DMIC on acp63 platform via
    _DSD entry (git-fixes).
  - ALSA: sh: Fix wrong argument order for copy_from_iter()
    (git-fixes).
  - ALSA: memalloc: prefer dma_mapping_error() over explicit
    address checking (git-fixes).
  - accel/ivpu: Fix WARN in ivpu_ipc_send_receive_internal()
    (git-fixes).
  - accel/ivpu: Fix general protection fault in ivpu_bo_list()
    (git-fixes).
  - ata: sata_highbank: fix OF node reference leak in
    highbank_initialize_phys() (git-fixes).
  - amdgpu/uvd: get ring reference from rq scheduler (git-fixes).
  - ACPICA: events/evxfregn: don't release the ContextMutex that
    was never acquired (git-fixes).
  - ACPI: resource: Fix memory resource type union access
    (git-fixes).
  - acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl
    (git-fixes).
  - ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array
    (git-fixes).
  - ASoC: fsl_spdif: change IFACE_PCM to IFACE_MIXER (git-fixes).
  - ASoC: fsl_xcvr: change IFACE_PCM to IFACE_MIXER (git-fixes).
  - ASoC: tas2781: Fix calibration issue in stress test (git-fixes).
  - ASoC: amd: yc: Fix the wrong return value (git-fixes).
  - ALSA: control: Avoid WARN() for symlink errors (git-fixes).
  - ALSA: usb-audio: Add implicit feedback quirk for Yamaha THR5
    (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic on Acer Nitro 5
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for microphone on Lenovo Thinkpad
    T14s Gen 6 21M1CTO1WW (stable-fixes).
  - ASoC: amd: yc: fix internal mic on Redmi G 2022 (stable-fixes).
  - ACPI: x86: Clean up Asus entries in acpi_quirk_skip_dmi_ids[]
    (stable-fixes).
  - ACPI: x86: Add skip i2c clients quirk for Acer Iconia One 8
    A1-840 (stable-fixes).
  - accel/qaic: Add AIC080 support (stable-fixes).
  - ASoC: hdmi-codec: reorder channel allocation list
    (stable-fixes).
  - ASoC: Intel: soc-acpi-intel-arl-match: Add rt722 and rt1320
    support (stable-fixes).
  - ASoC: sdw_utils: Add quirk to exclude amplifier function
    (stable-fixes).
  - ASoC: Intel: sof_sdw: Add quirks for some new Lenovo laptops
    (stable-fixes).
  - ASoC: Intel: sof_sdw: Add quirk for cs42l43 system using host
    DMICs (stable-fixes).
  - ASoC: sdw_utils: Add a quirk to allow the cs42l43 mic DAI to
    be ignored (stable-fixes).
  - ASoC: sdw_utils: Add support for exclusion DAI quirks
    (stable-fixes).
  - ASoC: Intel: avs: Fix return status of
    avs_pcm_hw_constraints_init() (stable-fixes).
  - ASoC: Intel: sof_rt5682: Add HDMI-In capture with rt5682
    support for MTL (stable-fixes).
  - Bluetooth: btusb: Add 3 HWIDs for MT7925 (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0489/e124 for MT7925
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0489/e111 for MT7925
    (stable-fixes).
  - Bluetooth: Set quirks for ATS2851 (stable-fixes).
  - Bluetooth: Support new quirks for ATS2851 (stable-fixes).
  - Bluetooth: Add new quirks for ATS2851 (stable-fixes).
  - Bluetooth: hci_core: Fix not checking skb length on
    hci_acldata_packet (stable-fixes).
  - Bluetooth: hci_conn: Use disable_delayed_work_sync
    (stable-fixes).
  - Bluetooth: btusb: Add USB HW IDs for MT7920/MT7925
    (stable-fixes).
  - Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device
    tables (stable-fixes).
  - Bluetooth: hci_conn: Reduce hci_conn_drop() calls in two
    functions (stable-fixes).
  - Bluetooth: RFCOMM: avoid leaving dangling sk pointer in
    rfcomm_sock_alloc() (stable-fixes).
  - Bluetooth: L2CAP: do not leave dangling sk pointer on error
    in l2cap_sock_create() (stable-fixes).
  - ACPI: video: force native for Apple MacbookPro11,2 and Air7,2
    (stable-fixes).
  - ACPI: x86: Add adev NULL check to
    acpi_quirk_skip_serdev_enumeration() (stable-fixes).
  - ACPI: x86: Make UART skip quirks work on PCI UARTs without an
    UID (stable-fixes).
  - commit f768efe
  - io_uring: check if iowq is killed before queuing (git-fixes).
  - commit d272417

++++ kernel-rt:

  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 21QA and 21QB
    (git-fixes).
  - ASoC: Intel: sof_sdw: Fix DMI match for Lenovo 21Q6 and 21Q7
    (git-fixes).
  - riscv: Fix wrong usage of __pa() on a fixmap address
    (git-fixes).
  - commit 70097d1
  - stddef: make __struct_group() UAPI C++-friendly (git-fixes).
  - thunderbolt: Improve redrive mode handling (git-fixes).
  - thunderbolt: Don't display nvm_version unless upgrade supported
    (git-fixes).
  - thunderbolt: Add support for Intel Panther Lake-M/P
    (stable-fixes).
  - xhci: Turn NEC specific quirk for handling Stop Endpoint errors
    generic (stable-fixes).
  - USB: serial: option: add Telit FE910C04 rmnet compositions
    (stable-fixes).
  - USB: serial: option: add MediaTek T7XX compositions
    (stable-fixes).
  - USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready
    (stable-fixes).
  - USB: serial: option: add MeiG Smart SLM770A (stable-fixes).
  - USB: serial: option: add TCL IK512 MBIM & ECM (stable-fixes).
  - usb: typec: ucsi: Fix completion notifications (git-fixes).
  - usb: dwc2: Fix HCD port connection race (git-fixes).
  - usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature (git-fixes).
  - usb: dwc2: Fix HCD resume (git-fixes).
  - usb: gadget: u_serial: Fix the issue that gs_start_io crashed
    due to accessing null pointer (git-fixes).
  - usb: misc: onboard_usb_dev: skip suspend/resume sequence for
    USB5744 SMBus support (git-fixes).
  - usb: dwc3: xilinx: make sure pipe clock is deselected in usb2
    only mode (git-fixes).
  - usb: core: hcd: only check primary hcd skip_phy_initialization
    (git-fixes).
  - usb: gadget: midi2: Fix interpretation of is_midi1 bits
    (git-fixes).
  - usb: dwc3: imx8mp: fix software node kernel dump (git-fixes).
  - usb: typec: anx7411: fix OF node reference leaks in
    anx7411_typec_switch_probe() (git-fixes).
  - usb: typec: anx7411: fix fwnode_handle reference leak
    (git-fixes).
  - usb: host: max3421-hcd: Correctly abort a USB request
    (git-fixes).
  - usb: ehci-hcd: fix call balance of clocks handling routines
    (git-fixes).
  - spi: rockchip: Fix PM runtime count on no-op cs (git-fixes).
  - spi: aspeed: Fix an error handling path in
    aspeed_spi_[read|write]_user() (git-fixes).
  - Revert "unicode: Don't special case ignorable code points"
    (stable-fixes).
  - usb: typec: ucsi: glink: be more precise on orientation-aware
    ports (stable-fixes).
  - usb: typec: ucsi: Do not call ACPI _DSM method for UCSI read
    operations (stable-fixes).
  - usb: chipidea: udc: handle USB Error Interrupt if IOC not set
    (stable-fixes).
  - usb: chipidea: udc: create bounce buffer for problem sglist
    entries if possible (stable-fixes).
  - usb: chipidea: udc: limit usb request length to max 16KB
    (stable-fixes).
  - usb: chipidea: add CI_HDRC_HAS_SHORT_PKT_LIMIT flag
    (stable-fixes).
  - thermal/drivers/qcom/tsens-v1: Add support for MSM8937 tsens
    (stable-fixes).
  - wifi: brcmfmac: Fix oops due to NULL pointer dereference in
    brcmf_sdiod_sglist_rw() (stable-fixes).
  - wifi: ipw2x00: libipw_rx_any(): fix bad alignment
    (stable-fixes).
  - wifi: ath5k: add PCI ID for Arcadyan devices (stable-fixes).
  - wifi: ath5k: add PCI ID for SX76X (stable-fixes).
  - wifi: ath10k: avoid NULL pointer error during sdio remove
    (stable-fixes).
  - wifi: ath12k: fix atomic calls in
    ath12k_mac_op_set_bitrate_mask() (stable-fixes).
  - wifi: rtw89: check return value of ieee80211_probereq_get()
    for RNR (stable-fixes).
  - wifi: rtw88: use ieee80211_purge_tx_queue() to purge TX skb
    (stable-fixes).
  - spi: spi-fsl-lpspi: Adjust type of scldiv (stable-fixes).
  - commit e030fc8
  - power: supply: bq24190: Fix BQ24296 Vbus regulator support
    (git-fixes).
  - power: supply: cros_charge-control: hide start threshold on
    v2 cmd (git-fixes).
  - power: supply: cros_charge-control: allow start_threshold ==
    end_threshold (git-fixes).
  - power: supply: cros_charge-control: add mutex for driver data
    (git-fixes).
  - power: supply: gpio-charger: Fix set charge current limits
    (git-fixes).
  - selftests/memfd: run sysctl tests when PID namespace support
    is enabled (git-fixes).
  - selftests: openvswitch: fix tcpdump execution (git-fixes).
  - regulator: axp20x: AXP717: set ramp_delay (git-fixes).
  - kselftest/arm64: abi: fix SVCR detection (git-fixes).
  - selftests: netfilter: Stabilize rpath.sh (git-fixes).
  - selftests: mlxsw: sharedbuffer: Ensure no extra packets are
    counted (git-fixes).
  - selftests: mlxsw: sharedbuffer: Remove duplicate test cases
    (git-fixes).
  - selftests: mlxsw: sharedbuffer: Remove h1 ingress test case
    (git-fixes).
  - selftests/ftrace: adjust offset for kprobe syntax error test
    (git-fixes).
  - selftests/damon: add _damon_sysfs.py to TEST_FILES (git-fixes).
  - selftest: hugetlb_dio: fix test naming (git-fixes).
  - selftests: hid: fix typo and exit code (git-fixes).
  - setlocalversion: work around "git describe" performance
    (stable-fixes).
  - rtc: cmos: avoid taking rtc_lock for extended period of time
    (stable-fixes).
  - serial: 8250_dw: Add Sophgo SG2044 quirk (stable-fixes).
  - selftests: rds: move test.py to TEST_FILES (git-fixes).
  - regulator: qcom-rpmh: Update ranges for FTSMPS525
    (stable-fixes).
  - selftests/mount_setattr: Fix failures on 64K PAGE_SIZE kernels
    (git-fixes).
  - remoteproc: qcom: pas: enable SAR2130P audio DSP support
    (stable-fixes).
  - selftests/damon/debugfs_duplicate_context_creation: hide errors
    from expected file write failures (git-fixes).
  - selftests/damon/_debugfs_common: hide expected error message
    from test_write_result() (git-fixes).
  - selftests/damon/huge_count_read_write: remove unnecessary
    debugging message (git-fixes).
  - selftests/damon/huge_count_read_write: provide sufficiently
    large buffer for DEPRECATED file read (git-fixes).
  - selftests: netfilter: Fix missing return values in
    conntrack_dump_flush (git-fixes).
  - selftests: net: really check for bg process completion
    (git-fixes).
  - soc: imx8m: Probe the SoC driver as platform driver
    (stable-fixes).
  - soc: qcom: pd-mapper: Add QCM6490 PD maps (stable-fixes).
  - soc: qcom: llcc: Use designated initializers for LLC settings
    (stable-fixes).
  - regmap: maple: Provide lockdep (sub)class for maple tree's
    internal lock (stable-fixes).
  - selftests/resctrl: Protect against array overflow when reading
    strings (stable-fixes).
  - selftests/resctrl: Protect against array overrun during iMC
    config parsing (git-fixes).
  - selftests/resctrl: Fix memory overflow due to unhandled
    wraparound (git-fixes).
  - selftests/resctrl: Print accurate buffer size as part of MBM
    results (git-fixes).
  - selftests/mm: Fix unused function warning for
    aarch64_write_signal_pkey() (git-fixes).
  - kselftest/arm64: Don't leak pipe fds in pac.exec_sign_all()
    (stable-fixes).
  - kselftest/arm64: Fix encoding for SVE B16B16 test (git-fixes).
  - kselftest/arm64: Log fp-stress child startup errors to stdout
    (stable-fixes).
  - kselftest/arm64: mte: fix printf type warnings about longs
    (git-fixes).
  - kselftest/arm64: mte: fix printf type warnings about __u64
    (git-fixes).
  - kselftest/arm64: hwcap: fix f8dp2 cpuinfo name (git-fixes).
  - kselftest/arm64: signal: drop now redundant GNU_SOURCE
    definition (git-fixes).
  - commit 5e98b23
  - platform/x86: mlx-platform: call pci_dev_put() to balance the
    refcount (git-fixes).
  - PCI/MSI: Handle lack of irqdomain gracefully (git-fixes).
  - phy: core: Fix an OF node refcount leakage in
    of_phy_provider_lookup() (git-fixes).
  - phy: core: Fix an OF node refcount leakage in _of_phy_get()
    (git-fixes).
  - phy: core: Fix that API devm_phy_destroy() fails to destroy
    the phy (git-fixes).
  - phy: core: Fix that API devm_of_phy_provider_unregister()
    fails to unregister the phy provider (git-fixes).
  - phy: core: Fix that API devm_phy_put() fails to release the phy
    (git-fixes).
  - phy: rockchip: samsung-hdptx: Set drvdata before enabling
    runtime PM (git-fixes).
  - phy: qcom-qmp: Fix register name in RX Lane config of SC8280XP
    (git-fixes).
  - phy: rockchip: naneng-combphy: fix phy reset (git-fixes).
  - phy: usb: Toggle the PHY power during init (git-fixes).
  - platform/chrome: cros_ec_lpc: fix product identity for early
    Framework Laptops (git-fixes).
  - mtd: rawnand: arasan: Fix missing de-registration of NAND
    (git-fixes).
  - mtd: rawnand: arasan: Fix double assertion of chip-select
    (git-fixes).
  - mtd: diskonchip: Cast an operand to prevent potential overflow
    (git-fixes).
  - mtd: rawnand: fix double free in atmel_pmecc_create_user()
    (git-fixes).
  - of/irq: Fix using uninitialized variable @addr_len in API
    of_irq_parse_one() (git-fixes).
  - of/irq: Fix interrupt-map cell length check in
    of_irq_parse_imap_parent() (git-fixes).
  - of: Fix refcount leakage for OF node returned by
    __of_get_dma_parent() (git-fixes).
  - of: Fix error path in of_parse_phandle_with_args_map()
    (git-fixes).
  - of: address: Preserve the flags portion on 1:1 dma-ranges
    mapping (git-fixes).
  - of: property: fw_devlink: Do not use interrupt-parent directly
    (git-fixes).
  - objtool/x86: allow syscall instruction (stable-fixes).
  - p2sb: Do not scan and remove the P2SB device when it is unhidden
    (git-fixes).
  - p2sb: Move P2SB hide and unhide code to p2sb_scan_and_cache()
    (stable-fixes).
  - p2sb: Introduce the global flag p2sb_hidden_by_bios
    (stable-fixes).
  - p2sb: Factor out p2sb_read_from_cache() (stable-fixes).
  - PCI: vmd: Add DID 8086:B06F and 8086:B60B for Intel client SKUs
    (stable-fixes).
  - PCI: qcom: Add support for IPQ9574 (stable-fixes).
  - PCI: Add ACS quirk for Wangxun FF5xxx NICs (stable-fixes).
  - PCI: Detect and trust built-in Thunderbolt chips (stable-fixes).
  - PCI: Add 'reset_subordinate' to reset hierarchy below bridge
    (stable-fixes).
  - PCI: starfive: Enable controller runtime PM before probing
    host bridge (stable-fixes).
  - PCI: vmd: Set devices to D0 before enabling PM L1 Substates
    (stable-fixes).
  - pinctrl: qcom: spmi-mpp: Add PM8937 compatible (stable-fixes).
  - pinctrl: qcom-pmic-gpio: add support for PM8937 (stable-fixes).
  - pinmux: Use sequential access to access desc->pinmux data
    (stable-fixes).
  - of: Allow overlay kunit tests to run CONFIG_OF_OVERLAY=n
    (git-fixes).
  - of/fdt: add dt_phys arg to early_init_dt_scan and
    early_init_dt_verify (git-fixes).
  - commit 52557e8
  - media: dvb-frontends: dib3000mb: fix uninit-value in
    dib3000_write_reg (git-fixes).
  - mmc: mtk-sd: disable wakeup in .remove() and in the error path
    of .probe() (git-fixes).
  - mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC
    quirk (git-fixes).
  - modpost: Add .irqentry.text to OTHER_SECTIONS (stable-fixes).
  - mmc: sdhci-pci: Add DMI quirk for missing CD GPIO on Vexia
    Edu Atla 10 tablet (stable-fixes).
  - misc: eeprom: eeprom_93cx6: Add quirk for extra read clock cycle
    (stable-fixes).
  - media: cx231xx: Add support for Dexatek USB Video Grabber
    1d19:6108 (stable-fixes).
  - media: uvcvideo: Force UVC version to 1.0a for 0408:4033
    (stable-fixes).
  - media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared
    camera (stable-fixes).
  - media: uvcvideo: RealSense D421 Depth module metadata
    (stable-fixes).
  - mmc: mtk-sd: Fix MMC_CAP2_CRYPTO flag setting (git-fixes).
  - mmc: mtk-sd: Fix error handle of probe function (git-fixes).
  - mmc: core: Use GFP_NOIO in ACMD22 (git-fixes).
  - mmc: mtk-sd: fix devm_clk_get_optional usage (stable-fixes).
  - mmc: mtk-sd: use devm_mmc_alloc_host (stable-fixes).
  - mmc: core: Adjust ACMD22 to SDUC (stable-fixes).
  - mmc: sd: SDUC Support Recognition (stable-fixes).
  - mmc: sdhci-esdhc-imx: enable quirks SDHCI_QUIRK_NO_LED
    (stable-fixes).
  - mmc: core: Add SD card quirk for broken poweroff notification
    (stable-fixes).
  - commit ba13df0
  - Update config files: CONFIG_HISILICON_ERRATUM_162100801=y
  - commit ff7aefc
  - linux/dmaengine.h: fix a few kernel-doc warnings (git-fixes).
  - irqchip/gic-v3: Work around insecure GIC integrations
    (git-fixes).
  - lib: stackinit: hide never-taken branch from compiler
    (stable-fixes).
  - irqchip/gicv3-its: Add workaround for hip09 ITS erratum
    162100801 (stable-fixes).
  - iio: light: ltr501: Add LTER0303 to the supported devices
    (stable-fixes).
  - iio: adc: ad7192: properly check spi_get_device_match_data()
    (stable-fixes).
  - mailbox: pcc: Check before sending MCTP PCC response ACK
    (stable-fixes).
  - leds: class: Protect brightness_show() with led_cdev->led_access
    mutex (stable-fixes).
  - kcsan: Turn report_filterlist_lock into a raw_spinlock
    (stable-fixes).
  - commit d2834e2
  - i2c: microchip-core: fix "ghost" detections (git-fixes).
  - i2c: microchip-core: actually use repeated sends (git-fixes).
  - i2c: imx: add imx7d compatible string for applying erratum
    ERR007805 (git-fixes).
  - hwmon: (tmp513) Fix interpretation of values of Temperature
    Result and Limit Registers (git-fixes).
  - hwmon: (tmp513) Fix Current Register value interpretation
    (git-fixes).
  - hwmon: (tmp513) Fix interpretation of values of Shunt Voltage
    and Limit Registers (git-fixes).
  - i915/guc: Accumulate active runtime on gt reset (git-fixes).
  - i915/guc: Ensure busyness counter increases motonically
    (git-fixes).
  - i915/guc: Reset engine utilization buffer before registration
    (git-fixes).
  - i2c: riic: Always round-up when calculating bus period
    (git-fixes).
  - i2c: pnx: Fix timeout in wait functions (git-fixes).
  - gpio: graniterapids: Fix GPIO Ack functionality (stable-fixes).
  - gpio: graniterapids: Check if GPIO line can be used for IRQs
    (stable-fixes).
  - gpio: graniterapids: Determine if GPIO pad can be used by driver
    (stable-fixes).
  - gpio: graniterapids: Fix invalid RXEVCFG register bitmask
    (stable-fixes).
  - gpio: graniterapids: Fix invalid GPI_IS register offset
    (stable-fixes).
  - gpio: graniterapids: Fix incorrect BAR assignment
    (stable-fixes).
  - gpio: graniterapids: Fix vGPIO driver crash (stable-fixes).
  - gpio: ljca: Initialize num before accessing item in
    ljca_gpio_config (git-fixes).
  - i3c: Use i3cdev->desc->info instead of calling
    i3c_device_get_info() to avoid deadlock (stable-fixes).
  - i3c: mipi-i3c-hci: Mask ring interrupts before ring stop request
    (stable-fixes).
  - i3c: master: Fix dynamic address leak when 'assigned-address'
    is present (git-fixes).
  - i3c: master: Extend address status bit to 4 and add
    I3C_ADDR_SLOT_EXT_DESIRED (stable-fixes).
  - i3c: master: Replace hard code 2 with macro
    I3C_ADDR_SLOT_STATUS_BITS (stable-fixes).
  - i2c: i801: Add support for Intel Panther Lake (stable-fixes).
  - HID: add per device quirk to force bind to hid-generic
    (stable-fixes).
  - HID: magicmouse: Apple Magic Trackpad 2 USB-C driver support
    (stable-fixes).
  - gpio: grgpio: Add NULL check in grgpio_probe (git-fixes).
  - iio: magnetometer: fix if () scoped_guard() formatting
    (git-fixes).
  - hwmon: (nct6775) Add 665-ACE/600M-CL to ASUS WMI monitoring list
    (stable-fixes).
  - commit 0ebc937
  - drm/amdgpu/nbio7.0: fix IP version check (stable-fixes).
  - drm/amd: Update strapping for NBIO 2.5.0 (stable-fixes).
  - drm/amdgpu: Handle NULL bo->tbo.resource (again) in
    amdgpu_vm_bo_update (git-fixes).
  - drm/amdgpu: fix amdgpu_coredump (stable-fixes).
  - drm/amdgpu/smu14.0.2: fix IP version check (stable-fixes).
  - drm/amdgpu/gfx12: fix IP version check (stable-fixes).
  - drm/amdgpu/mmhub4.1: fix IP version check (stable-fixes).
  - drm/amdgpu/nbio7.11: fix IP version check (stable-fixes).
  - drm/amdgpu/nbio7.7: fix IP version check (stable-fixes).
  - drm/amdgpu: don't access invalid sched (git-fixes).
  - drm/modes: Avoid divide by zero harder in drm_mode_vrefresh()
    (stable-fixes).
  - drm/display: use ERR_PTR on DP tunnel manager creation fail
    (git-fixes).
  - drm/panel: synaptics-r63353: Fix regulator unbalance
    (git-fixes).
  - drm/panel: st7701: Add prepare_prev_first flag to drm_panel
    (git-fixes).
  - drm/panel: novatek-nt35950: fix return value check in
    nt35950_probe() (git-fixes).
  - drm/panel: himax-hx83102: Add a check to prevent NULL pointer
    dereference (git-fixes).
  - firmware: arm_ffa: Fix the race around setting
    ffa_dev->properties (git-fixes).
  - drm/panic: remove spurious empty line to clean warning
    (git-fixes).
  - drm/amdkfd: pause autosuspend when creating pdd (stable-fixes).
  - drm/amdgpu: fix when the cleaner shader is emitted (git-fixes).
  - drm/amdkfd: hard-code MALL cacheline size for gfx11, gfx12
    (stable-fixes).
  - drm/amdkfd: hard-code cacheline size for gfx11 (stable-fixes).
  - drm/amdkfd: Dereference null return value (git-fixes).
  - drm/amd/pm: Set SMU v13.0.7 default workload type
    (stable-fixes).
  - drm/amdgpu: fix UVD contiguous CS mapping problem
    (stable-fixes).
  - drm/xe/reg_sr: Remove register pool (git-fixes).
  - drm/xe: Call invalidation_fence_fini for PT inval fences in
    error state (git-fixes).
  - drm/xe: fix the ERR_PTR() returned on failure to allocate tiny
    pt (git-fixes).
  - drm/i915: Fix memory leak by correcting cache object name in
    error handler (git-fixes).
  - drm/i915: Fix NULL pointer dereference in capture_engine
    (git-fixes).
  - drm/i915/color: Stop using non-posted DSB writes for legacy LUT
    (git-fixes).
  - drm/amd/pm: fix and simplify workload handling (stable-fixes).
  - drm/amd/display: Limit VTotal range to max hw cap minus fp
    (stable-fixes).
  - drm/amd/display: Correct prefetch calculation (stable-fixes).
  - drm/amd/display: Add a left edge pixel if in YCbCr422 or
    YCbCr420 and odm (stable-fixes).
  - drm/amdkfd: hard-code cacheline for gc943,gc944 (stable-fixes).
  - drm/amdkfd: add MEC version that supports no PCIe atomics for
    GFX12 (stable-fixes).
  - drm/amdgpu/hdp7.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp6.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp5.2: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp5.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/amdgpu/hdp4.0: do a posting read when flushing HDP
    (stable-fixes).
  - drm/dp_mst: Verify request type in the corresponding down
    message reply (stable-fixes).
  - drm/dp_mst: Fix MST sideband message body length check
    (stable-fixes).
  - drm/amdgpu/vcn: reset fw_shared when VCPU buffers corrupted
    on vcn v4.0.3 (stable-fixes).
  - drm/amd/display: Ignore scalar validation failure if pipe is
    phantom (stable-fixes).
  - Revert "drm/amd/display: parse umc_info or vram_info based on
    ASIC" (stable-fixes).
  - drm/panic: Add ABGR2101010 support (stable-fixes).
  - drm/amdgpu: set the right AMDGPU sg segment limitation
    (stable-fixes).
  - drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov
    (stable-fixes).
  - drm/amd/display: Prune Invalid Modes For HDMI Output
    (stable-fixes).
  - drm/amd/display: parse umc_info or vram_info based on ASIC
    (stable-fixes).
  - drm/amd/display: Remove hw w/a toggle if on DP2/HPO
    (stable-fixes).
  - drm/amd/display: Fix underflow when playing 8K video in full
    screen mode (stable-fixes).
  - drm/xe/devcoredump: Update handling of xe_force_wake_get return
    (stable-fixes).
  - drm/xe/forcewake: Add a helper xe_force_wake_ref_has_domain()
    (stable-fixes).
  - drm/sched: memset() 'job' in drm_sched_job_init()
    (stable-fixes).
  - drm/panel: simple: Add Microchip AC69T88A LVDS Display panel
    (stable-fixes).
  - drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr
    (stable-fixes).
  - drm/amdgpu: Dereference the ATCS ACPI buffer (stable-fixes).
  - drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts
    for vega20_ih (stable-fixes).
  - drm/amdgpu/gfx9: Add cleaner shader for GFX9.4.2 (stable-fixes).
  - drm/amd/display: Adding array index check to prevent memory
    corruption (stable-fixes).
  - drm/amd/display: Full exit out of IPS2 when all allow signals
    have been cleared (stable-fixes).
  - drm/amd/display: disable SG displays on cyan skillfish
    (stable-fixes).
  - drm/amd/display: calculate final viewport before TAP
    optimization (stable-fixes).
  - drm/amd/display: Fix garbage or black screen when resetting otg
    (stable-fixes).
  - drm/amd/display: skip disable CRTC in seemless bootup case
    (stable-fixes).
  - drm/radeon/r600_cs: Fix possible int overflow in
    r600_packet3_check() (stable-fixes).
  - drm/amd/display: Fix out-of-bounds access in
    'dcn21_link_encoder_create' (stable-fixes).
  - drm/display: Fix building with GCC 15 (stable-fixes).
  - drm/xe/xe3: Add initial set of workarounds (stable-fixes).
  - drm/xe/ptl: L3bank mask is not available on the media GT
    (stable-fixes).
  - drm/xe/guc: Copy GuC log prior to dumping (stable-fixes).
  - drm/xe/devcoredump: Add ASCII85 dump helper function
    (stable-fixes).
  - drm/xe/devcoredump: Improve section headings and add tile info
    (stable-fixes).
  - drm/xe/devcoredump: Use drm_puts and already cached local
    variables (stable-fixes).
  - drm/xe/pciid: Add new PCI id for ARL (stable-fixes).
  - drm/xe/pciids: Add PVC's PCI device ID macros (stable-fixes).
  - drm/xe/pciids: separate ARL and MTL PCI IDs (stable-fixes).
  - drm/xe/pciids: separate RPL-U and RPL-P PCI IDs (stable-fixes).
  - drm/mcde: Enable module autoloading (stable-fixes).
  - firmware: qcom: scm: Allow QSEECOM on Dell XPS 13 9345
    (stable-fixes).
  - firmware: qcom: scm:  Allow QSEECOM on Lenovo Yoga Slim 7x
    (stable-fixes).
  - gpio: grgpio: use a helper variable to store the address of
    ofdev->dev (stable-fixes).
  - gpio: free irqs that are still requested when the chip is
    being removed (stable-fixes).
  - commit d415f2b
  - dmaengine: tegra: Return correct DMA status when paused
    (git-fixes).
  - dmaengine: mv_xor: fix child node refcount handling in early
    exit (git-fixes).
  - dmaengine: fsl-edma: implement the cleanup path of
    fsl_edma3_attach_pd() (git-fixes).
  - dmaengine: amd: qdma: Remove using the private get and set
    dma_ops APIs (git-fixes).
  - dmaengine: apple-admac: Avoid accessing registers in probe
    (git-fixes).
  - dmaengine: dw: Select only supported masters for ACPI devices
    (git-fixes).
  - dmaengine: at_xdmac: avoid null_prt_deref in
    at_xdmac_prep_dma_memset (git-fixes).
  - dma-buf: Fix __dma_buf_debugfs_list_del argument for
    !CONFIG_DEBUG_FS (git-fixes).
  - can: m_can: fix missed interrupts with m_can_pci (git-fixes).
  - can: m_can: set init flag earlier in probe (git-fixes).
  - cxl/region: Fix region creation for greater than x2 switches
    (git-fixes).
  - cxl/pci: Fix potential bogus return value upon successful
    probing (git-fixes).
  - crypto: hisilicon/debugfs - fix the struct pointer incorrectly
    offset problem (git-fixes).
  - Documentation: PM: Clarify pm_runtime_resume_and_get() return
    value (git-fixes).
  - Documentation: networking: Add a caveat to nexthop_compat_mode
    sysctl (git-fixes).
  - clk: en7523: Initialize num before accessing hws in
    en7523_register_clocks() (git-fixes).
  - clk: en7523: Fix wrong BUS clock for EN7581 (git-fixes).
  - dma-buf: fix dma_fence_array_signaled v4 (stable-fixes).
  - clk: qcom: clk-alpha-pll: Add NSS HUAYRA ALPHA PLL support
    for ipq9574 (stable-fixes).
  - clk: qcom: dispcc-sm8550: enable support for SAR2130P
    (stable-fixes).
  - clk: qcom: tcsrcc-sm8550: add SAR2130P support (stable-fixes).
  - clk: qcom: rpmh: add support for SAR2130P (stable-fixes).
  - clk: qcom: rcg2: add clk_rcg2_shared_floor_ops (stable-fixes).
  - drm/bridge: it6505: Enable module autoloading (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO GEEK
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO Founder
    edition (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model
    (stable-fixes).
  - drm/vc4: hvs: Set AXI panic modes for the HVS (stable-fixes).
  - drm/vc4: hdmi: Avoid log spam for audio start failure
    (stable-fixes).
  - dma-debug: fix a possible deadlock on radix_lock (stable-fixes).
  - Documentation: tipc: fix formatting issue in tipc.rst
    (git-fixes).
  - cleanup: Adjust scoped_guard() macros to avoid potential warning
    (stable-fixes).
  - crypto: ecdsa - Avoid signed integer overflow on signature
    decoding (stable-fixes).
  - commit 8e66607
  - ASoC: SOF: Intel: hda-dai: Do not release the link DMA on STOP
    (git-fixes).
  - ASoC: amd: ps: Fix for enabling DMIC on acp63 platform via
    _DSD entry (git-fixes).
  - ALSA: sh: Fix wrong argument order for copy_from_iter()
    (git-fixes).
  - ALSA: memalloc: prefer dma_mapping_error() over explicit
    address checking (git-fixes).
  - accel/ivpu: Fix WARN in ivpu_ipc_send_receive_internal()
    (git-fixes).
  - accel/ivpu: Fix general protection fault in ivpu_bo_list()
    (git-fixes).
  - ata: sata_highbank: fix OF node reference leak in
    highbank_initialize_phys() (git-fixes).
  - amdgpu/uvd: get ring reference from rq scheduler (git-fixes).
  - ACPICA: events/evxfregn: don't release the ContextMutex that
    was never acquired (git-fixes).
  - ACPI: resource: Fix memory resource type union access
    (git-fixes).
  - acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl
    (git-fixes).
  - ASoC: Intel: sof_sdw: Add space for a terminator into DAIs array
    (git-fixes).
  - ASoC: fsl_spdif: change IFACE_PCM to IFACE_MIXER (git-fixes).
  - ASoC: fsl_xcvr: change IFACE_PCM to IFACE_MIXER (git-fixes).
  - ASoC: tas2781: Fix calibration issue in stress test (git-fixes).
  - ASoC: amd: yc: Fix the wrong return value (git-fixes).
  - ALSA: control: Avoid WARN() for symlink errors (git-fixes).
  - ALSA: usb-audio: Add implicit feedback quirk for Yamaha THR5
    (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic on Acer Nitro 5
    (stable-fixes).
  - ASoC: amd: yc: Add quirk for microphone on Lenovo Thinkpad
    T14s Gen 6 21M1CTO1WW (stable-fixes).
  - ASoC: amd: yc: fix internal mic on Redmi G 2022 (stable-fixes).
  - ACPI: x86: Clean up Asus entries in acpi_quirk_skip_dmi_ids[]
    (stable-fixes).
  - ACPI: x86: Add skip i2c clients quirk for Acer Iconia One 8
    A1-840 (stable-fixes).
  - accel/qaic: Add AIC080 support (stable-fixes).
  - ASoC: hdmi-codec: reorder channel allocation list
    (stable-fixes).
  - ASoC: Intel: soc-acpi-intel-arl-match: Add rt722 and rt1320
    support (stable-fixes).
  - ASoC: sdw_utils: Add quirk to exclude amplifier function
    (stable-fixes).
  - ASoC: Intel: sof_sdw: Add quirks for some new Lenovo laptops
    (stable-fixes).
  - ASoC: Intel: sof_sdw: Add quirk for cs42l43 system using host
    DMICs (stable-fixes).
  - ASoC: sdw_utils: Add a quirk to allow the cs42l43 mic DAI to
    be ignored (stable-fixes).
  - ASoC: sdw_utils: Add support for exclusion DAI quirks
    (stable-fixes).
  - ASoC: Intel: avs: Fix return status of
    avs_pcm_hw_constraints_init() (stable-fixes).
  - ASoC: Intel: sof_rt5682: Add HDMI-In capture with rt5682
    support for MTL (stable-fixes).
  - Bluetooth: btusb: Add 3 HWIDs for MT7925 (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0489/e124 for MT7925
    (stable-fixes).
  - Bluetooth: btusb: Add new VID/PID 0489/e111 for MT7925
    (stable-fixes).
  - Bluetooth: Set quirks for ATS2851 (stable-fixes).
  - Bluetooth: Support new quirks for ATS2851 (stable-fixes).
  - Bluetooth: Add new quirks for ATS2851 (stable-fixes).
  - Bluetooth: hci_core: Fix not checking skb length on
    hci_acldata_packet (stable-fixes).
  - Bluetooth: hci_conn: Use disable_delayed_work_sync
    (stable-fixes).
  - Bluetooth: btusb: Add USB HW IDs for MT7920/MT7925
    (stable-fixes).
  - Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device
    tables (stable-fixes).
  - Bluetooth: hci_conn: Reduce hci_conn_drop() calls in two
    functions (stable-fixes).
  - Bluetooth: RFCOMM: avoid leaving dangling sk pointer in
    rfcomm_sock_alloc() (stable-fixes).
  - Bluetooth: L2CAP: do not leave dangling sk pointer on error
    in l2cap_sock_create() (stable-fixes).
  - ACPI: video: force native for Apple MacbookPro11,2 and Air7,2
    (stable-fixes).
  - ACPI: x86: Add adev NULL check to
    acpi_quirk_skip_serdev_enumeration() (stable-fixes).
  - ACPI: x86: Make UART skip quirks work on PCI UARTs without an
    UID (stable-fixes).
  - commit f768efe
  - io_uring: check if iowq is killed before queuing (git-fixes).
  - commit d272417

++++ harfbuzz:

  - Add harfbuzz-CVE-2024-56732.patch: guard
    hb_cairo_glyphs_from_buffer() against bad UTF-8 (CVE-2024-56732).

++++ shadow:

  - Update to 4.17.1:
    * Fix `su -` regression #1163

------------------------------------------------------------------
------------------  2024-12-30  -  Dec 30 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - io_uring: Fix registered ring file refcount leak (git-fixes).
  - io_uring: Change res2 parameter type in io_uring_cmd_done
    (git-fixes).
  - io_uring/tctx: work around xa_store() allocation error issue
    (git-fixes).
  - io_uring: fix corner case forgetting to vunmap (git-fixes).
  - io_uring: check for overflows in io_pin_pages (git-fixes).
  - commit bbcd0cb
  - Update
    patches.suse/s390-stacktrace-Use-break-instead-of-return-statement.patch
    (git-fixes bsc#1234352 CVE-2024-56550 bsc#1234915).
  - commit fb93bc1
  - preempt: Move PREEMPT_RT before PREEMPT in vermagic (git-fixes).
  - commit bd70ce5

++++ kernel-rt:

  - io_uring: Fix registered ring file refcount leak (git-fixes).
  - io_uring: Change res2 parameter type in io_uring_cmd_done
    (git-fixes).
  - io_uring/tctx: work around xa_store() allocation error issue
    (git-fixes).
  - io_uring: fix corner case forgetting to vunmap (git-fixes).
  - io_uring: check for overflows in io_pin_pages (git-fixes).
  - commit bbcd0cb
  - Update
    patches.suse/s390-stacktrace-Use-break-instead-of-return-statement.patch
    (git-fixes bsc#1234352 CVE-2024-56550 bsc#1234915).
  - commit fb93bc1
  - preempt: Move PREEMPT_RT before PREEMPT in vermagic (git-fixes).
  - commit bd70ce5

++++ kexec-tools:

  - update to 2.0.30:
    * arm64: Support UKI image format
    * bug fixes

++++ c-ares:

  - c-ares 1.34.4
    This is a bugfix release.
    Changes:
    QNX Port: Port to QNX 8, add primary config reading support, add CI build. PR #934, PR #937, PR #938
    Bugfixes:
    Empty TXT records were not being preserved. PR #922
    docs: update deprecation notices for ares_create_query() and ares_mkquery(). PR #910
    license: some files weren't properly updated. PR #920
    Fix bind local device regression from 1.34.0. PR #929, PR #931, PR #935
    CMake: set policy version to prevent deprecation warnings. PR #932
    CMake: shared and static library names should be the same on unix platforms like autotools uses. PR #933
    Update to latest autoconf archive macros for enhanced system compatibility. PR #936
    In version 1.34.3
    This is a bugfix release.
    Changes:
    Build the release package in an automated way so we can provide provenance as per SLSA3. PR #906
    Bugfixes:
    Some upstream servers are non-compliant with EDNS options, resend queries without EDNS. Issue #911
    TSAN warns on missing lock, but lock isn't actually necessary. PR #915
    ares_getaddrinfo() for AF_UNSPEC should retry IPv4 if only IPv6 is received. 765d558
    ares_send() shouldn't return ARES_EBADRESP, its ARES_EBADQUERY. 91519e7
    Fix typos in man pages. PR #905
  - skip-test.patch: fix failing tests

++++ xxhash:

  - Update to release 0.8.3
    * Corrects an edge case in ``XXH3_128bits_withSecretandSeed``
    that could generate invalid results.
    * xxhash now knows command-line arguments ``--filelist``,
    ``--files-from``.

------------------------------------------------------------------
------------------  2024-12-29  -  Dec 29 2024  -------------------
------------------------------------------------------------------

++++ filesystem:

  - Remove /usr/etc/skel/bin/

------------------------------------------------------------------
------------------  2024-12-28  -  Dec 28 2024  -------------------
------------------------------------------------------------------

++++ bash:

  - Move (/etc/skel/.bashrc) and (/etc/skel/.profile) to (/usr/etc/skel/).

++++ pango:

  - Update to version 1.55.0 (Unstable):
    + Support Unicode 16
    + Add pango_font_map_add_font_file
    + fontconfig: Reject patterns without FC_FILE
    + coretext:
  - Actually use .AppleSystemUIFont
  - Keep track of variations
    + build:
  - Require harfbuzz 8.4.0
  - Require fontconfig 2.15
  - Require meson 1.2.0

------------------------------------------------------------------
------------------  2024-12-27  -  Dec 27 2024  -------------------
------------------------------------------------------------------

++++ filesystem:

  - Add /usr/$march directories for HPPA. Will be packaging both
    hppa-suse-linux and hppa64-suse-linux because the compiler
    suite is usually configured with the latter on this arch.

++++ shadow:

  - Update to 4.17.0:
    * Fix the lower part of the domain of csrand_uniform()
    * Fix use of volatile pointer
    * Use 'dist-hook' to clean up <tests/unit/Makefile>
    * Use str2[u]l() instead of atoi(3)
    * Use a2i() in various places
    * Fix const correctness
    * Use uid_t for holding UIDs (and GIDs)
    * Move all sprintf(3)-like APIs to a subdirectory
    * Move all copying APIs to a subdirectory
    * Fix forever loop on ENOMEM
    * Fix REALLOC() nmemb calculation
    * Remove id(1)
    * Remove groups(1)
    * Use local time for human-readable dates
    * Use %F instead of %Y-%m-%d with strftime(3)
    * is_valid{user,group}_name(): Set errno to distinguish the reasons
    * Recommend --badname only if it is useful
    * Add fmkomstemp() to fix mode of </etc/default/useradd>
    * Fix use-after-free bug in sgetgrent()
    * Update Catalan translation
    * Remove references to cppw, cpgr
    * groupadd, groupmod: Update gshadow file with -U
    * Added option -a for listing active users only, optimized using if aflg,return
    * Added information in lastlog man page for new option '-a'
    * Plenty of code cleanup and clarifications

++++ python-Jinja2:

  - Update to 3.1.5:
    * The sandboxed environment handles indirect calls to str.format,
    such as by passing a stored reference to a filter that calls
    its argument. GHSA-q2x7-8rv6-6q7h
    * Escape template name before formatting it into error messages,
    to avoid issues with names that contain f-string syntax. #1792,
    GHSA-gmj6-6f8f-6699
    * Sandbox does not allow clear and pop on known mutable sequence
    types. #2032
    * Calling sync render for an async template uses asyncio.run. #1952
    * Avoid unclosed auto_aiter warnings. #1960
    * Return an aclose-able AsyncGenerator from
    Template.generate_async. #1960
    * Avoid leaving root_render_func() unclosed in
    Template.generate_async. #1960
    * Avoid leaving async generators unclosed in blocks, includes and
    extends. #1960
    * The runtime uses the correct concat function for the current
    environment when calling block references. #1701
    * Make |unique async-aware, allowing it to be used after another
    async-aware filter. #1781
    * |int filter handles OverflowError from scientific notation. #1921
    * Make compiling deterministic for tuple unpacking in a {% set ... %}
    call. #2021
    * Fix dunder protocol (copy/pickle/etc) interaction with Undefined
    objects. #2025
    * Fix copy/pickle support for the internal missing object. #2027
    * Environment.overlay(enable_async) is applied correctly. #2061
    * The error message from FileSystemLoader includes the paths that
    were searched. #1661
    * PackageLoader shows a clearer error message when the package does
    not contain the templates directory. #1705
    * Improve annotations for methods returning copies. #1880
    * urlize does not add mailto: to values like @a@b. #1870
    * Tests decorated with @pass_context can be used with the
    |select filter. #1624
    * Using set for multiple assignment (a, b = 1, 2) does not fail when
    the target is a namespace attribute. #1413
    * Using set in all branches of {% if %}{% elif %}{% else %} blocks does
    not cause the variable to be considered initially undefined. #1253
  - drop fix-ftbfs-with-python313.patch, merged upstream

------------------------------------------------------------------
------------------  2024-12-26  -  Dec 26 2024  -------------------
------------------------------------------------------------------

++++ systemd:

  - systemd-update-helper: backport commit 2d0af8bc354f4a1429ce
    Since user@.service has `Type=notify-reload` (making the reloading process
    synchronous) and reloading implies reexecuting with `ReloadSignal=RTMIN+25`,
    reexecuting user managers synchronously can be achieved with `systemctl reload
    user@*.service" now.
  - Upgrade to v257.1 (commit 47eea9ee9f46537bc18d6a64fa21fd9c50538e13)
    See https://github.com/openSUSE/systemd/blob/SUSE/v257/NEWS for details.
  - This upgrade includes the following bug fixes:
  - commit 9258e27f4a1ddf2834d0cadd66770ad65e55e066 (boo#1233752, bsc#1234313)
  - commit 423de11f046cc2c9b6904e4eff71d6a48cd661c9 (boo#1233752, bsc#1234313)
  - commit 2ae79a31b7c7947e2c16e18eb85ac5607ebc40b6 (bsc#1232844)
  - Drop 5006-tpm2-util-Also-retry-unsealing-after-policy_pcr-retu.patch and
    5005-Revert-boot-Make-initrd_prepare-semantically-equival.patch
    These two patches have bee merged upstream and are included in v257.1, see
    above.
  - Our testsuite sub-package has been broken by upstream after they decided to
    remove the bash test runner, see https://github.com/systemd/systemd/pull/34271
    for details. For running the testsuite, the systemd git repository has to be
    cloned for now. We'll try to adapt the testsuite sub-package these changes.

++++ pcr-oracle:

  - Add fix-event-reshash-for-cryptouuid.patch to detect the crypto
    device with the 'cryptouuid' prefix

------------------------------------------------------------------
------------------  2024-12-25  -  Dec 25 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - tools/hv: reduce resource usage in hv_kvp_daemon (git-fixes).
  - tools/hv: add a .gitignore file (git-fixes).
  - tools/hv: reduce resouce usage in hv_get_dns_info helper
    (git-fixes).
  - hv/hv_kvp_daemon: Pass NIC name to hv_get_dns_info as well
    (git-fixes).
  - Drivers: hv: util: Avoid accessing a ringbuffer not initialized
    yet (git-fixes).
  - Drivers: hv: util: Don't force error code to ENODEV in
    util_probe() (git-fixes).
  - tools/hv: terminate fcopy daemon if read from uio fails
    (git-fixes).
  - drivers: hv: Convert open-coded timeouts to secs_to_jiffies()
    (git-fixes).
  - tools: hv: change permissions of NetworkManager configuration
    file (git-fixes).
  - x86/hyperv: Fix hv tsc page based sched_clock for hibernation
    (git-fixes).
  - tools: hv: Fix a complier warning in the fcopy uio daemon
    (git-fixes).
  - jiffies: Define secs_to_jiffies() (git-fixes).
  - commit 9c8b4b3

++++ kernel-rt:

  - tools/hv: reduce resource usage in hv_kvp_daemon (git-fixes).
  - tools/hv: add a .gitignore file (git-fixes).
  - tools/hv: reduce resouce usage in hv_get_dns_info helper
    (git-fixes).
  - hv/hv_kvp_daemon: Pass NIC name to hv_get_dns_info as well
    (git-fixes).
  - Drivers: hv: util: Avoid accessing a ringbuffer not initialized
    yet (git-fixes).
  - Drivers: hv: util: Don't force error code to ENODEV in
    util_probe() (git-fixes).
  - tools/hv: terminate fcopy daemon if read from uio fails
    (git-fixes).
  - drivers: hv: Convert open-coded timeouts to secs_to_jiffies()
    (git-fixes).
  - tools: hv: change permissions of NetworkManager configuration
    file (git-fixes).
  - x86/hyperv: Fix hv tsc page based sched_clock for hibernation
    (git-fixes).
  - tools: hv: Fix a complier warning in the fcopy uio daemon
    (git-fixes).
  - jiffies: Define secs_to_jiffies() (git-fixes).
  - commit 9c8b4b3

------------------------------------------------------------------
------------------  2024-12-24  -  Dec 24 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - nfsd: restore callback functionality for NFSv4.0 (git-fixes).
  - commit bf279e8

++++ kernel-rt:

  - nfsd: restore callback functionality for NFSv4.0 (git-fixes).
  - commit bf279e8

++++ systemd:

  - Fix systemd-network recommending libidn2-devel (boo#1234765)

------------------------------------------------------------------
------------------  2024-12-23  -  Dec 23 2024  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Correct efi_fw_update arch list:
    * Remove ppc64le and s390x - these aren't supported
    * Add armv6hl/armv7hl and riscv64 - support recently added

++++ kernel-default:

  - xfs: return from xfs_symlink_verify early on V4 filesystems
    (git-fixes).
  - commit 6019ea4
  - xfs: fix sb_spino_align checks for large fsblock sizes
    (git-fixes).
  - commit 98c6cb3
  - xfs: only run precommits once per transaction object
    (git-fixes).
  - commit 574f714
  - xfs: unlock inodes when erroring out of xfs_trans_alloc_dir
    (git-fixes).
  - commit 49dd5e2
  - xfs: fix scrub tracepoints when inode-rooted btrees are involved
    (git-fixes).
  - commit 9d264ae
  - xfs: update btree keys correctly when _insrec splits an inode
    root block (git-fixes).
  - commit 16300ea
  - xfs: fix null bno_hint handling in xfs_rtallocate_rtg
    (git-fixes).
  - commit 64c1638
  - xfs: set XFS_SICK_INO_SYMLINK_ZAPPED explicitly when zapping
    a symlink (git-fixes).
  - commit 9828305
  - xfs: don't drop errno values when we fail to ficlone the entire
    range (git-fixes).
  - commit 701e2f2
  - xfs: return a 64-bit block count from xfs_btree_count_blocks
    (git-fixes).
  - commit 2c2d3e0
  - NFS/pnfs: Fix a live lock between recalled layouts and layoutget
    (git-fixes).
  - commit 4b27d0f
  - nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur
    (git-fixes).
  - commit 866861d
  - SUNRPC: make sure cache entry active before cache_show
    (git-fixes).
  - commit 46da6e3
  - NFSD: Prevent a potential integer overflow (git-fixes).
  - commit afa1145
  - erofs: fix PSI memstall accounting (git-fixes).
  - commit 33a3df5
  - epoll: annotate racy check (git-fixes).
  - commit 94df11a
  - exfat: fix uninit-value in __exfat_get_dentry_set (git-fixes).
  - commit 092c2f6
  - exfat: fix out-of-bounds access of directory entries
    (git-fixes).
  - commit bca1b1b

++++ kernel-rt:

  - xfs: return from xfs_symlink_verify early on V4 filesystems
    (git-fixes).
  - commit 6019ea4
  - xfs: fix sb_spino_align checks for large fsblock sizes
    (git-fixes).
  - commit 98c6cb3
  - xfs: only run precommits once per transaction object
    (git-fixes).
  - commit 574f714
  - xfs: unlock inodes when erroring out of xfs_trans_alloc_dir
    (git-fixes).
  - commit 49dd5e2
  - xfs: fix scrub tracepoints when inode-rooted btrees are involved
    (git-fixes).
  - commit 9d264ae
  - xfs: update btree keys correctly when _insrec splits an inode
    root block (git-fixes).
  - commit 16300ea
  - xfs: fix null bno_hint handling in xfs_rtallocate_rtg
    (git-fixes).
  - commit 64c1638
  - xfs: set XFS_SICK_INO_SYMLINK_ZAPPED explicitly when zapping
    a symlink (git-fixes).
  - commit 9828305
  - xfs: don't drop errno values when we fail to ficlone the entire
    range (git-fixes).
  - commit 701e2f2
  - xfs: return a 64-bit block count from xfs_btree_count_blocks
    (git-fixes).
  - commit 2c2d3e0
  - NFS/pnfs: Fix a live lock between recalled layouts and layoutget
    (git-fixes).
  - commit 4b27d0f
  - nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur
    (git-fixes).
  - commit 866861d
  - SUNRPC: make sure cache entry active before cache_show
    (git-fixes).
  - commit 46da6e3
  - NFSD: Prevent a potential integer overflow (git-fixes).
  - commit afa1145
  - erofs: fix PSI memstall accounting (git-fixes).
  - commit 33a3df5
  - epoll: annotate racy check (git-fixes).
  - commit 94df11a
  - exfat: fix uninit-value in __exfat_get_dentry_set (git-fixes).
  - commit 092c2f6
  - exfat: fix out-of-bounds access of directory entries
    (git-fixes).
  - commit bca1b1b

++++ openssl-3:

  - Add support for userspace livepatching on ppc64le (jsc#PED-11850).
  - Use gcc-13 for ppc64le.

++++ regionServiceClientConfigAzure:

  - Update to version 2.2.2
    + Replacing certificate for rgnsrv-azure-southeastasia to get
    rid of weird chain cert
  - Update to version 2.2.1
    + New 4096 certificate for rgnsrv-azure-southeastasia

++++ regionServiceClientConfigEC2:

  - Update to version 4.3.2
    + Fix us-east-1 cert
  - Update to version 4.3.1
    + New 4096 certificate for rgnsrv-ec2-us-east1

------------------------------------------------------------------
------------------  2024-12-22  -  Dec 22 2024  -------------------
------------------------------------------------------------------

++++ systemd:

  - Import commit f962392e1e0d5683a2adebf09698b5fda02f9cfc (merge of v256.10)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/290170c8550bf2de4b5085ecdf7f056769944444...f962392e1e0d5683a2adebf09698b5fda02f9cfc

++++ vulkan-loader:

  - Update to tag 1.4.304
    * Emulate VK_EXT_surface_maintenance1 if not supported by a driver
    * Add handle checking to test instance & device creation
    * Add settings test for layer control OFF & VK_INSTANCE_LAYERS
    * Make Settings file "ON" take priority over disable env-var
    * Log what caused each layer to be enabled
    * Log when Filter Env-Vars act when settings file is active
    * Add more logging when the settings file has invalid members

------------------------------------------------------------------
------------------  2024-12-21  -  Dec 21 2024  -------------------
------------------------------------------------------------------

++++ fwupd:

  - Update to version 1.9.27:
    + This release fixes the following bugs:
  - Add a power quirk for Framework systems
  - Allow cros-ec repair the device after flush failure
  - Check the VLI USB3 firmware size before erasing
  - Disallow DBX updates on the Samsung Galaxy Book2 360
  - Do not show 'Device has been removed' as a dock error
  - Do not use a CMSE11 function when using CSME18
  - Fix an unlikely memory leak when using ModemManger Sahara devices
  - Fix a tiny memory leak in algoltek-usb when checking status
  - Mark UEFI dbx updates as affecting full disk encryption
  - Parse FDTs with missing END tokens
  - Rename the dell-k2 plugin to dell-kestrel and rework the update flow
    + This release adds support for the following hardware:
  - Google GID8 Headset
  - Parade PS188
  - Primax Ryder Mouse
  - Update to version 1.9.26:
    + This release fixes the following bugs:
  - Add HSI tests for Arrow and Meteor Lake CSME
  - Allow UEFI capsule config values to be set with fwupdmgr modify-config
  - Check for the logitech-bulkcontroller response packet length correctly
  - Fix using ID_LIKE for fallback when ESP isn't mounted
  - Fix various Coverity-reported overflowed constants
  - Only compare the first 10 characters of the AMD GPU part number
    + This release adds support for the following hardware:
  - Jabra PanaCast
  - Some Lenovo Legion HID devices

------------------------------------------------------------------
------------------  2024-12-20  -  Dec 20 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix documentation for repo, package gpg settings
    In contrast to the documentation, kiwi sets default values
    for any gpg setting if not explicitly specified differently.
    We want to avoid to inherit a behavior from how the distribution
    packages the package manager. This commit fixes the documentation
    to be in line with the implementation

++++ kernel-default:

  - config: enable CONFIG_DEBUG_WX
    References: jsc#PED-11834
  - commit 1b5f22c
  - s390/debug: Pass in and enforce output buffer size for format
    handlers (git-fixes bsc#1234755).
  - commit 430b82f
  - arm64: ptrace: fix partial SETREGSET for NT_ARM_POE (git-fixes)
  - commit be5e333
  - arm64: ptrace: fix partial SETREGSET for NT_ARM_FPMR (git-fixes)
  - commit a39fa97
  - arm64: ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL (git-fixes)
  - commit ac2dfa2
  - arm64: mm: Fix zone_dma_limit calculation (git-fixes)
  - commit 8778362
  - serial: sh-sci: Check if TX data was written to device in
    .tx_empty() (git-fixes).
  - commit 3191962
  - sched/core: Update kernel boot parameters for LAZY preempt
    (bsc#1234370).
  - sched: No PREEMPT_RT=y for all{yes,mod}config (bsc#1234370).
  - commit 7d6dbbf
  - sched, x86: Enable Lazy preemption (bsc#1234370).
  - Update config files.
  - commit c439fcd
  - tracing: Record task flag NEED_RESCHED_LAZY (bsc#1234370).
  - tracing: Remove TRACE_FLAG_IRQS_NOSUPPORT (bsc#1234370).
  - sched, x86: Update the comment for TIF_NEED_RESCHED_LAZY
    (bsc#1234370).
  - riscv: add PREEMPT_LAZY support (bsc#1234370).
  - sched: Enable PREEMPT_DYNAMIC for PREEMPT_RT (bsc#1234370).
  - sched: Add Lazy preemption model (bsc#1234370).
  - sched: Add TIF_NEED_RESCHED_LAZY infrastructure (bsc#1234370).
  - commit 32e8d26

++++ kernel-rt:

  - config: enable CONFIG_DEBUG_WX
    References: jsc#PED-11834
  - commit 1b5f22c
  - s390/debug: Pass in and enforce output buffer size for format
    handlers (git-fixes bsc#1234755).
  - commit 430b82f
  - arm64: ptrace: fix partial SETREGSET for NT_ARM_POE (git-fixes)
  - commit be5e333
  - arm64: ptrace: fix partial SETREGSET for NT_ARM_FPMR (git-fixes)
  - commit a39fa97
  - arm64: ptrace: fix partial SETREGSET for NT_ARM_TAGGED_ADDR_CTRL (git-fixes)
  - commit ac2dfa2
  - arm64: mm: Fix zone_dma_limit calculation (git-fixes)
  - commit 8778362
  - serial: sh-sci: Check if TX data was written to device in
    .tx_empty() (git-fixes).
  - commit 3191962
  - sched/core: Update kernel boot parameters for LAZY preempt
    (bsc#1234370).
  - sched: No PREEMPT_RT=y for all{yes,mod}config (bsc#1234370).
  - commit 7d6dbbf
  - sched, x86: Enable Lazy preemption (bsc#1234370).
  - Update config files.
  - commit c439fcd
  - tracing: Record task flag NEED_RESCHED_LAZY (bsc#1234370).
  - tracing: Remove TRACE_FLAG_IRQS_NOSUPPORT (bsc#1234370).
  - sched, x86: Update the comment for TIF_NEED_RESCHED_LAZY
    (bsc#1234370).
  - riscv: add PREEMPT_LAZY support (bsc#1234370).
  - sched: Enable PREEMPT_DYNAMIC for PREEMPT_RT (bsc#1234370).
  - sched: Add Lazy preemption model (bsc#1234370).
  - sched: Add TIF_NEED_RESCHED_LAZY infrastructure (bsc#1234370).
  - commit 32e8d26

++++ qemu:

  - Update to latest upstream release, 9.2.0:
    The full list of changes are available at:
    https://wiki.qemu.org/ChangeLog/9.2
    Highlights include:
    * virtio-gpu: support for 3D acceleration of Vulkan applications via
    Venus Vulkan driver in the guest and virglrenderer host library
    * crypto: GLib crypto backend now supports SHA-384 hashes
    * migration: QATzip-accelerated compression support while using multiple
    migration streams
    * Rust: experimental support for device models written in Rust (for
    development use only)
    * ARM: emulation support for FEAT_EBF16, FEAT_CMOW architecture features
    * ARM: support for two-stage SMMU translation for sbsa-ref and virt boards
    * ARM: support for CPU Security Extensions for xilinx-zynq-a9 board
    * ARM: 64GB+ memory support when using HVF acceleration on newer Macs
    * HPPA: SeaBIOS-hppa v17 firmware with various fixes and enhancements
    * RISC-V: IOMMU support for virt machine
    * RISC-V: support for control flow integrity and Svvptc extensions, and
    support for Bit-Manipulation extension on OpenTitan boards
    * RISC-V: improved performance for vector unit-stride/whole register
    ld/st instructions
    * s390x: support for booting from other devices if the previous ones fail
    * x86: support for new nitro-enclave machine type that can emulate
    * AWS Nitro Enclave and can boot from Enclave Image Format files.
    * x86: KVM support for enabling AVX10, as well as enabling specific
    AVX10 versions via command-line
    * and lots more...
  - Other changes:
    * Removed deprecated 'cris' support
    * Removed deprecated virtfs-proxy-helper
    * (`--enable-rust` not addressed yet)

------------------------------------------------------------------
------------------  2024-12-19  -  Dec 19 2024  -------------------
------------------------------------------------------------------

++++ dbus-broker:

  - Requires(pre): systemd >= 253.6 to ensure scripts in %post are
    run correctly, (bsc#1234697) Thanks to Thorsten for the detailed
    report.

++++ python-kiwi:

  - Drop insecure and unsupported md5 digest
    Decommission the Checksum.md5() method and move all places
    in code to sha256(). The md5 digest is considered insecure
    and has also been removed from hashlib as a supported digest.
    This Fixes #2696
  - Fix config functions action
    The action failed on the setup of the runtime because the upgrade
    of pip failed.
  - Bump version: 10.2.4 → 10.2.5

++++ kernel-default:

  - blk-cgroup: Fix UAF in blkcg_unpin_online() (bsc#1234726).
  - commit 991b744
  - s390/cpum_sf: Handle CPU hotplug remove during sampling
    (git-fixes bsc#1234715).
  - commit 6c44c98

++++ kernel-rt:

  - blk-cgroup: Fix UAF in blkcg_unpin_online() (bsc#1234726).
  - commit 991b744
  - s390/cpum_sf: Handle CPU hotplug remove during sampling
    (git-fixes bsc#1234715).
  - commit 6c44c98

++++ llvm19:

  - Update to version 19.1.6.
    * This release contains bug-fixes for the LLVM 19.1.0 release.
    This release is API and ABI compatible with 19.1.0.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ procps:

  - Update to procps-ng-4.0.5
    * library
    increment current, revision and age to 0: 1:0:0
    internal: days/users when value is 0                   issue #303
    internal: dont print 60s but increment minute          issue #302
    internal: stat api fixed remaining cpu distortions     issue #321
    internal: only count user sessions
    internal: Recover from meminfo seek using LXC          Debian #1072831
    internal: stat api no longer counts guest tics twice   issue #339
    external: zswap & zswapped added to meminfo api
    external: schedule class added to pids api
    external: disk sleep added to pids api, sleep revised  issue #265
    external: docker containers added to pids api
    external: procps_users new exported function
    external: procps_uptime_snprint uses given upseconds
    external: procps_container_uptime
    external: meminfo api adds SecPageTables, Unaccepted
    external: pids api now provides open file descriptors
    external: 'info' parm removed from all 'VAL' macros    issue #332
    external: Add procps_sigmask_names
    external: Add procps_capability_names
    external: Add PIDS_CAP__PRM Permitted Capabilities
    * build-sys: Added --disable-pidwait and fixed logic     issue #352
    * kill: Correctly parse negative pids                    issue #354
    * pgrep: select process by environment variable          issue #167
    * pgrep: Rework pidfile reading to include stdin         issue #318
    * pmap: Don't escape correct UTF-8 characters
    * ps: Add environ field
    * ps: Add htprv and htshr fields for HugeTables
    * ps: restore lost tasks for options --sort with -H      issue #304
    * ps: add 'docker' containers field, similar to 'lxc'
    * ps: Restore AIX free-format                            issue #323
    * ps: can display open file descriptors for each task
    * ps: Fix signames scanning                              issue #341
    * ps: Add -o pcap,pcaps to show permitted capabilities
    * ps: Zombies show <defunct> in the commandname          issue #355
    * ps: Use quick mode if possible                         merge #239
    * slabtop: Add --human option for slab size
    * snice: Minor fix for help screen                       Debian #1086441
    * sysctl: Add glob excludes                              merge #206
    * sysctl: --all skips stat_refresh                       Debian #978688
    * top: added a 'CLS' scheduling class field, like ps
    * top: exploit library addition of 'disk sleep'          issue #265
    * top: add 'docker' containers field, similar to 'lxc'
    * top: provides additional control over colors
    * top: can display open file descriptors for each task
    * top: corrected cpu % for hosts with qemu processes     issue #339
    * top: remains functional if /proc mounted subset=pid
    * top: can display a task's permitted capabilities (^A)
    * uptime: Add container uptime option                    issue #300
    * vmstat: Add page allocation to --stats
    * vmstat.8: si/so are changed by --unit                  Debian #1061944
    * w: Don't segfault with -s option                       issue #301
    * w: Cache pids list                                     issue #305
    * w: Add container uptime option
    * w.1: Note utmp is for non-systemd                      Debian #1080333
    * watch: use clock_gettime                               issue #295
    * watch.1: --chgexit only works for visible changes      Debian #729569
    * hugetop: a new utility to show huge page information   merge #214
  - Remove patches now upstream or fixed
    * 79042e07.patch
    * procps-ng-4.0.4-idletime-no-tty.patch
    * procps-ng-4.0.4-w-array-bounds.patch
  - Port patches
    * procps-ng-3.3.10-errno.patch
    * procps-ng-3.3.10-slab.patch
    * procps-ng-3.3.10-xen.dif
    * procps-ng-3.3.11-pmap4suse.patch
    * procps-ng-3.3.8-ignore-scan_unevictable_pages.patch
    * procps-ng-3.3.8-petabytes.patch
    * procps-ng-3.3.8-readeof.patch
    * procps-ng-3.3.8-tinfo.dif
    * procps-ng-3.3.8-vmstat-terabyte.dif
    * procps-ng-3.3.9-w-notruncate.diff
    * procps-ng-4.0.0-floats.dif
    * procps-ng-4.0.0-integer-overflow.patch
    * procps-ng-4.0.4-ignore-sysctl_conf.patch
    * procps-v3.3.3-columns.dif
    * procps-v3.3.3-read-sysctls-also-from-boot-sysctl.conf-kernelversion.diff

++++ rpm:

  - backport debug_package regression fix from upstream
    * new patch: debugpackage.diff
  - fix segfault in rpmtsNextFiles
    * new patch: nextfiles.diff

++++ python-urllib3:

  - Skip some flaky tests that fail sometimes in OBS (bsc#1234681)

++++ rebootmgr:

  - Update to version 3.0+git20241219.7166827:
    * Remove left overs from dbus related manual page
    * Use int64 to parse JSON for time_t
    * Set varlink info
    * Move announce_ready() call to a later place
    * Require libeconf 0.7.5
    * Free event loop in destroy context.
    * Add missing error reply
    * Remove unused log_type variable
    * Add internal error to varlink interface
    * Move varlink definition into own file
    * Update manual pages

------------------------------------------------------------------
------------------  2024-12-18  -  Dec 18 2024  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 27.4.1-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/27/#2741>
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * cli-0001-docs-include-required-tools-in-source-tree.patch

++++ kernel-default:

  - x86/xen: remove hypercall page (XSA-466 CVE-2024-53241
    bsc#1234282).
  - commit cc077cb
  - x86/xen: use new hypercall functions instead of hypercall page
    (XSA-466 CVE-2024-53241 bsc#1234282).
  - commit cf705e2
  - x86/xen: add central hypercall functions (XSA-466 CVE-2024-53241
    bsc#1234282).
  - commit 8d7a3d3
  - x86/xen: don't do PV iret hypercall through hypercall page
    (XSA-466 CVE-2024-53241 bsc#1234282).
  - commit 1847ea1
  - x86/static-call: provide a way to do very early static-call
    updates (XSA-466 CVE-2024-53241 bsc#1234282).
  - commit 518b891
  - objtool/x86: allow syscall instruction (XSA-466 CVE-2024-53241
    bsc#1234282).
  - commit c82a684
  - x86: make get_cpu_vendor() accessible from Xen code (XSA-466
    CVE-2024-53241 bsc#1234282).
  - commit 827db39
  - xen/netfront: fix crash when removing device (XSA-465
    CVE-2024-53240 bsc#1234281).
  - commit 683acf2
  - s390/mm: Consider KMSAN modules metadata for paging levels
    (git-fixes bsc#1234686).
  - s390/ipl: Fix never less than zero warning (git-fixes
    bsc#1234685).
  - s390/mm: Fix DirectMap accounting (git-fixes bsc#1234687).
  - commit 4ad9925
  - RDMA/mlx5: Move events notifier registration to be after device registration (git-fixes)
  - commit 38f5ec4

++++ kernel-rt:

  - x86/xen: remove hypercall page (XSA-466 CVE-2024-53241
    bsc#1234282).
  - commit cc077cb
  - x86/xen: use new hypercall functions instead of hypercall page
    (XSA-466 CVE-2024-53241 bsc#1234282).
  - commit cf705e2
  - x86/xen: add central hypercall functions (XSA-466 CVE-2024-53241
    bsc#1234282).
  - commit 8d7a3d3
  - x86/xen: don't do PV iret hypercall through hypercall page
    (XSA-466 CVE-2024-53241 bsc#1234282).
  - commit 1847ea1
  - x86/static-call: provide a way to do very early static-call
    updates (XSA-466 CVE-2024-53241 bsc#1234282).
  - commit 518b891
  - objtool/x86: allow syscall instruction (XSA-466 CVE-2024-53241
    bsc#1234282).
  - commit c82a684
  - x86: make get_cpu_vendor() accessible from Xen code (XSA-466
    CVE-2024-53241 bsc#1234282).
  - commit 827db39
  - xen/netfront: fix crash when removing device (XSA-465
    CVE-2024-53240 bsc#1234281).
  - commit 683acf2
  - s390/mm: Consider KMSAN modules metadata for paging levels
    (git-fixes bsc#1234686).
  - s390/ipl: Fix never less than zero warning (git-fixes
    bsc#1234685).
  - s390/mm: Fix DirectMap accounting (git-fixes bsc#1234687).
  - commit 4ad9925
  - RDMA/mlx5: Move events notifier registration to be after device registration (git-fixes)
  - commit 38f5ec4

++++ libbpf:

  - Drop libbpf-Fix-NULL-pointer-dereference-in-bpf_object__c.patch
    * included since 1.4.0

++++ libzypp:

  - Url: queryparams without value should not have a trailing "=".
  - version 17.35.16 (35)

++++ python-maturin:

  - Update to 1.7.8
    * Fix aarch64 Windows cross compilation by @messense in #2359
  - Release 1.7.7
    * fix abi3 interpreter discovery on Windows by @davidhewitt in
    [#2333]
    * fix: remove extra indent in generated CI by @jsstevenson in
    [#2340]
    * Upgrade cargo-xwin to unify rustls versions by @kornelski in
    [#2222]
    * Normalize python source directory path by @messense in #2343
    * Enable fat LTO for maturin release workflow by @messense in
    [#2344]
    * Use different binding dirs for different uniffi modules by
    @messense in #2348
    * Update minimal Python minor version for pyo3 0.23 by @messense
    in #2350
    * Limit minimal PyPy version based on bindings crate version by
    @messense in #2351
    * Remove hard coded pip show in fix_direct_url by @mbway in #2352
    * Do not use xwin to compile on Windows when MSVC compiler can
    build for the target by @messense in #2353
  - Release 1.7.6
    * allow -i 3.13t by @davidhewitt in #2324
    * propagate abiflags to wheel name on Windows by @davidhewitt in
    [#2325]
    * Add free-threaded wheel build to generate-ci by default by
    @messense in #2329
    * Bump metadata version to 2.4 to fix license bug by @konstin in
    [#2332]
  - Release 1.7.5
    * Auto detect Python 3.13 by @messense in #2248
    * feat: add skip attestation option to maturin ci github by
    @moldhouse in #2254
    * generate-ci: use macos-13 runner for x86_64 build job by
    @messense in #2255
    * Improve wheel reproducibility by sorting libs by @ycongal-smile
    in #2261
    * Fix inverted workspace inclusions by @konstin in #2262
    * Fix broken links to PyO3 building docs by @laurentS in #2270
    * Update goblin to 0.9 by @musicinmybrain in #2284
    * Don't resolve python interpreter when building sdist only by
    @messense in #2292
    * include timestamps in the suggested log format by @mbway in
    [#2304]
    * Add support for GNU/Hurd by @sthibaul in #2306
    * Fix __init__ exports when using multiple UniFFI bindings by
    @Nickersoft in #2305
    * Add free-threaded Python support by @messense in #2310
  - Fix _service file for cargo_vendor
  - Update description

++++ python-urllib3:

  - Ignore DeprecationWarning in tests (bsc#1234681)

------------------------------------------------------------------
------------------  2024-12-17  -  Dec 17 2024  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to docker-buildx 0.19.3. See upstream changelog online at
    <https://github.com/docker/buildx/releases/tag/v0.19.3>

++++ docker-compose:

  - Update to version 2.32.1:
    * e2e test to prevent future regression
    * only check volume mounts for updated config

++++ fwupd-efi:

  - Update to version 1.7:
    * Fix compilation with GNU-EFI 4.0
  - Use upstream tarball: source service isn't useful on this
    package
  - Add 106.patch:
    * Improves ARM32 crt0 by splitting header and code
    * Use pkgconfig for gnu-efi - fixes RISC-V build
    * Update lds from gnu-efi 4.0

++++ kernel-default:

  - s390x config: drop netiucv and lcs drivers (jsc#PED-11160)
  - commit 160e70b
  - supported.conf: drop netiucv and lcs drivers (jsc#PED-11160)
  - commit b6e4c33

++++ kernel-rt:

  - s390x config: drop netiucv and lcs drivers (jsc#PED-11160)
  - commit 160e70b
  - supported.conf: drop netiucv and lcs drivers (jsc#PED-11160)
  - commit b6e4c33

++++ openssl-3:

  - Fix evp_properties section in the openssl.cnf file [bsc#1234647]
    * Rebase patches:
  - openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch
  - openssl-TESTS-Disable-default-provider-crypto-policies.patch

++++ rpm:

  - allow the buildroot to be a symbolic link in check-files
    (needed for pesign-obs-integration)
    * new patch: buildroot-symlink.diff

++++ snapper:

  - make some binary paths used in snbk configurable
    (gh#openSUSE/snapper#970)
  - version 0.12.1

++++ nvidia-open-driver-G06-signed:

  - Update to 550.142 (boo#1234675)
  - for SLE Micro 6.x use
    '%if 0%{?suse_version} == 1600 && !0%{?is_opensuse}'; SLE16
    doesn't set %sle_version and SLE Micro 6.x is already SLE16!

++++ tuned:

  - Move gobject dependency to gtk package as it is the only utility that
    imports gi.
  - Remove unnecessary cpupower dependency, sysfs fallback is used instead.

------------------------------------------------------------------
------------------  2024-12-16  -  Dec 16 2024  -------------------
------------------------------------------------------------------

++++ bash:

  - Remove bash-4.3-winch.dif as this is the (current) default

++++ lvm2-device-mapper:

  - Update lvm2 from LVM2.2.03.24 to LVM2.2.03.29
    * ** WHATS_NEW from 2.03.24 to 2.03.29 ***
    Version 2.03.29 - 09th December 2024
    ====================================
    Configure --enable/disable-sd-notify to control lvmlockd build with sd-notify.
    Allow test mode when lvmlockd is built without dlm support.
    Add a note about RAID + integrity synchronization to lvmraid(7) man page.
    Add a function for running lvconvert --repair on RAID LVs to lvmdbusd.
    Improve option section of man pages for listing commands ({pv,lv,vg}{s,display}).
    Fix renaming of raid sub LVs when converting a volume to raid (2.03.28).
    Fix segfault/VG write error for raid LV lvextend -i|--stripes -I|--stripesize.
    Revert ignore -i|--stripes, -I|--stripesize for lvextend on raid0 LV (2.03.27).
    Version 2.03.28 - 04th November 2024
    ====================================
    Use radix_tree to lookup for UUID within committed metadata.
    Use radix_tree to lookup LV list entry within VG struct.
    Introduce setting config/validate_metadata = full | none.
    Restore fs resize call for lvresize -r on the same size LV (2.03.17).
    Correct off-by-one devicesfile backup counting.
    Replace use of dm_hash with radix_tree for lv names and uuids.
    Refactor vg_validate with uniq_insert and better use of CPU caches.
    Add radix_tree_uniq_insert.
    Update DM cache when taking next VG lock instead of dropping it.
    Generate json string id only for json reporting.
    For vgsummary use new API call dm_config_parse_only_section().
    Use radix_tree for PV names mapping.
    Split check_lv_segment into separate _in/complete_vg variant.
    Use find_lv instead of find_lv_in_vg when possible.
    Do a mirror fixup only when mirrors with logs are imported.
    Add faster crc32 calculation from zlib code for x86_64.
    Fall back to direct zeroing if BLKZEROOUT fails during new LV initialization.
    Version 2.03.27 - 02nd October 2024
    ===================================
    Fix swap device size detection using blkid for lvresize/lvreduce/lvextend.
    Detect GPT partition table and pass partition filter if no partitions defined.
    Add global/sanlock_align_size option to configure sanlock lease size.
    Disable mem locking when activation/reserved_stack or reserved_memory is 0.
    Fix locking issues in lvmlockd leaving thin pool locked.
    Deprecate vdo settings vdo_write_policy and vdo_write_policy.
    Lots of typo fixes across lvm2 code base (codespell).
    Corrected integrity parameter interleave_sectors for DM table line.
    Ignore -i|--stripes, -I|--stripesize for lvextend on raid0 LV, like raid10.
    Do not accept duplicate device names for pvcreate.
    Version 2.03.26 - 23rd August 2024
    ==================================
    Fix internal error reported by pvmove on a VG with single PV.
    Also accept --mknodes --refresh for vgscan.
    Fix vgmknodes --refresh to wait for udev before checking /dev content.
    Use log/report_command_log=1 config setting by default for JSON output format.
    Fix unreleased memory pools on RAID lvextend.
    Add --integritysettings option to manipulate dm-integrity settings.
    Version 2.03.25 - 12nd July 2024
    ================================
    Utilize more radix_tree instead of dm_hash and btree.
    Refactor DM uuid caching from device_mapper directory.
    Enhance checking for DM uuid device.
    Fix lvm shell command completion on tab key (2.03.24).
    Avoid lockd_vg call to lvmlockd for local VGs.
    Allow forced change of locktype from none.
    Handle OPTIONS defined in /etc/sysconfig/lvmlockd.
    * ** WHATS_NEW_DM from 1.02.198 to 1.02.203 ***
    Version 1.02.203 - 09th December 2024
    =====================================
    Version 1.02.202 - 04th November 2024
    =====================================
    Introduce dm_config_parse_only_section to stop parsing after section.
    For shorter string use on stack buffers when generating sections.
    Enhance dm_config tokenizer.
    Version 1.02.201 - 02nd October 2024
    ====================================
    Cleanup udev sync semaphore if dm_{udev_create,task_set}_cookie fails.
    Improve error messages on failed udev cookie create/inc/dec operation.
    Version 1.02.200 - 23rd August 2024
    ===================================
    Version 1.02.199 - 12nd July 2024
    =================================
  - update lvm2.spec
  - change lvm2_version to 2.03.29
  - change upstream_device_mapper_version and device_mapper_version to 1.02.203
  - include new systemed files lvm-devices-import.path and lvm-devices-import.service in lvm2 package
  - add build dependency 'pkgconfig(systemd)' and configure option '--enable-sd-notify' for lvmlockd
  - remove unrecognized (since 2.03.01) configure parameter '--with-cluster' from lvmlockd

++++ python-kiwi:

  - Changed systemfiles provider
    Instead of providing a static list of filenames, provide a list
    of package names. It is expected that the pilot of flake-pilot
    resolves this list against the local package database to build
    up the filelist for provisioning

++++ kernel-default:

  - sched/dlserver: Fix dlserver time accounting (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/dlserver: Fix dlserver double enqueue (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/eevdf: More PELT vs DELAYED_DEQUEUE (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Fix sched_can_stop_tick() for fair tasks
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fix NEXT_BUDDY (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched/deadline: Fix warning in migrate_enable for boosted tasks
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Update kernel boot parameters for LAZY preempt
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Prevent wakeup of ksoftirqd during idle load balance
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Check idle_cpu() before need_resched() to detect
    ilb CPU turning busy (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/core: Remove the unnecessary need_resched() check
    in nohz_csd_func() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - softirq: Allow raising SCHED_SOFTIRQ from SMP-call-function on
    RT kernel (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: fix warning in sched_setaffinity (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/deadline: Fix replenish_dl_new_period dl_server condition
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Replace scx_next_task_picked() with switch_class()
    in comment (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Rename scx_bpf_dispatch[_vtime]_from_dsq*() ->
    scx_bpf_dsq_move[_vtime]*() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: Rename scx_bpf_consume() to
    scx_bpf_dsq_move_to_local() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: Rename scx_bpf_dispatch[_vtime]() to
    scx_bpf_dsq_insert[_vtime]() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: scx_bpf_dispatch_from_dsq_set_*() are allowed
    from unlocked context (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: add a missing rcu_read_lock/unlock pair at
    scx_select_cpu_dfl() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Clarify sched_ext_ops table for userland scheduler
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Enable the ops breather and eject BPF scheduler on
    softlockup (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Avoid live-locking bypass mode switching (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_ext: Fix incorrect use of bitwise AND (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_ext: Do not enable LLC/NUMA optimizations when domains
    overlap (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Introduce NUMA awareness to the default idle
    selection policy (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Replace set_arg_maybe_null() with __nullable CFI
    stub tags (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Rename CFI stubs to names that are recognized by BPF
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Introduce LLC awareness to the default idle
    selection policy (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Clarify ops.select_cpu() for single-CPU tasks
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: improve WAKE_SYNC behavior for default idle CPU
    selection (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Use btf_ids to resolve task_struct (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/ext: Use tg_cgroup() to elieminate duplicate code
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/ext: Fix unmatch trailing comment of
    CONFIG_EXT_GROUP_SCHED (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Factor out move_task_between_dsqs() from
    scx_dispatch_from_dsq() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched/idle: Switch to use hrtimer_setup_on_stack() (bsc#1234634
    (Scheduler functional and performance backports)).
  - hrtimers: Delete hrtimer_init_sleeper_on_stack() (bsc#1234634
    (Scheduler functional and performance backports)).
  - wait: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - timers: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - net: pktgen: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - futex: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - fs/aio: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_update_function() (bsc#1234634
    (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_setup_on_stack() (bsc#1234634
    (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - hrtimers: Add missing hrtimer_init() trace points (bsc#1234634
    (Scheduler functional and performance backports)).
  - timers: Move *sleep*() and timeout functions into a separate
    file (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched, x86: Enable Lazy preemption (bsc#1234634 (Scheduler
    functional and performance backports)).
  - Refresh configs
  - sched: Add Lazy preemption model (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: Add TIF_NEED_RESCHED_LAZY infrastructure (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/ext: Remove sched_fork() hack (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: Initialize idle tasks only once (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: psi: pass enqueue/dequeue flags to psi callbacks directly
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/uclamp: Fix unnused variable warning (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Split scheduler and execution contexts (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Split out __schedule() deactivate task logic into a
    helper (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Consolidate pick_*_task to task_is_pushable helper
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Add move_queued_task_locked helper (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Improve cache locality of RSEQ concurrency IDs for
    intermittent workloads (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: idle: Optimize the generic idle loop by removing
    needless memory barrier (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched/wait: Remove unused bit_wait_io_timeout (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: fix the comment for PREEMPT_SHORT (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: optimize the PLACE_LAG when se->vlag is zero
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: remove the DOUBLE_TICK feature (bsc#1234634
    (Scheduler functional and performance backports)).
  - softirq: use bit waits instead of var waits (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: add wait_var_event_io() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: Add wait/wake interface for variable updated under a lock
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Add test_and_clear_wake_up_bit() and
    atomic_dec_and_wake_up() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched: Document wait_var_event() family of functions and
    wake_up_var() (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Improve documentation for wake_up_bit/wait_on_bit
    family of functions (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: change wake_up_bit() and related function to expect
    unsigned long * (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/cpufreq: Ensure sd is rebuilt for EAS check (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_getattr: port to copy_struct_to_user (bsc#1234634
    (Scheduler functional and performance backports)).
  - uaccess: add copy_struct_to_user helper (bsc#1234634 (Scheduler
    functional and performance backports)).
  - commit 23379e3
  - s390/sclp: Allow user-space to provide PCI reports for optical
    modules (jsc#PED-11804).
  - commit 645b84a
  - net: mana: Fix irq_contexts memory leak in mana_gd_setup_irqs
    (git-fixes).
  - net: mana: Fix memory leak in mana_gd_setup_irqs (git-fixes).
  - commit e0ecd16
  - arm64: Ensure bits ASID[15:8] are masked out when the kernel uses (bsc#1234605)
  - commit b4e6c18

++++ kernel-rt:

  - sched/dlserver: Fix dlserver time accounting (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/dlserver: Fix dlserver double enqueue (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/eevdf: More PELT vs DELAYED_DEQUEUE (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: Fix sched_can_stop_tick() for fair tasks
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Fix NEXT_BUDDY (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched/deadline: Fix warning in migrate_enable for boosted tasks
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Update kernel boot parameters for LAZY preempt
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/core: Prevent wakeup of ksoftirqd during idle load balance
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: Check idle_cpu() before need_resched() to detect
    ilb CPU turning busy (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/core: Remove the unnecessary need_resched() check
    in nohz_csd_func() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - softirq: Allow raising SCHED_SOFTIRQ from SMP-call-function on
    RT kernel (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: fix warning in sched_setaffinity (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched/deadline: Fix replenish_dl_new_period dl_server condition
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Replace scx_next_task_picked() with switch_class()
    in comment (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Rename scx_bpf_dispatch[_vtime]_from_dsq*() ->
    scx_bpf_dsq_move[_vtime]*() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: Rename scx_bpf_consume() to
    scx_bpf_dsq_move_to_local() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: Rename scx_bpf_dispatch[_vtime]() to
    scx_bpf_dsq_insert[_vtime]() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched_ext: scx_bpf_dispatch_from_dsq_set_*() are allowed
    from unlocked context (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: add a missing rcu_read_lock/unlock pair at
    scx_select_cpu_dfl() (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Clarify sched_ext_ops table for userland scheduler
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Enable the ops breather and eject BPF scheduler on
    softlockup (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Avoid live-locking bypass mode switching (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_ext: Fix incorrect use of bitwise AND (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_ext: Do not enable LLC/NUMA optimizations when domains
    overlap (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Introduce NUMA awareness to the default idle
    selection policy (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Replace set_arg_maybe_null() with __nullable CFI
    stub tags (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Rename CFI stubs to names that are recognized by BPF
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: Introduce LLC awareness to the default idle
    selection policy (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Clarify ops.select_cpu() for single-CPU tasks
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched_ext: improve WAKE_SYNC behavior for default idle CPU
    selection (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched_ext: Use btf_ids to resolve task_struct (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/ext: Use tg_cgroup() to elieminate duplicate code
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/ext: Fix unmatch trailing comment of
    CONFIG_EXT_GROUP_SCHED (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched_ext: Factor out move_task_between_dsqs() from
    scx_dispatch_from_dsq() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched/idle: Switch to use hrtimer_setup_on_stack() (bsc#1234634
    (Scheduler functional and performance backports)).
  - hrtimers: Delete hrtimer_init_sleeper_on_stack() (bsc#1234634
    (Scheduler functional and performance backports)).
  - wait: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - timers: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - net: pktgen: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - futex: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - fs/aio: Switch to use hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_update_function() (bsc#1234634
    (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_setup_sleeper_on_stack()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_setup_on_stack() (bsc#1234634
    (Scheduler functional and performance backports)).
  - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init()
    (bsc#1234634 (Scheduler functional and performance backports)).
  - hrtimers: Add missing hrtimer_init() trace points (bsc#1234634
    (Scheduler functional and performance backports)).
  - timers: Move *sleep*() and timeout functions into a separate
    file (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched, x86: Enable Lazy preemption (bsc#1234634 (Scheduler
    functional and performance backports)).
  - Refresh configs
  - sched: Add Lazy preemption model (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: Add TIF_NEED_RESCHED_LAZY infrastructure (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/ext: Remove sched_fork() hack (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: Initialize idle tasks only once (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: psi: pass enqueue/dequeue flags to psi callbacks directly
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/uclamp: Fix unnused variable warning (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Split scheduler and execution contexts (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Split out __schedule() deactivate task logic into a
    helper (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Consolidate pick_*_task to task_is_pushable helper
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Add move_queued_task_locked helper (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: Improve cache locality of RSEQ concurrency IDs for
    intermittent workloads (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: idle: Optimize the generic idle loop by removing
    needless memory barrier (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched/wait: Remove unused bit_wait_io_timeout (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: fix the comment for PREEMPT_SHORT (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched/fair: optimize the PLACE_LAG when se->vlag is zero
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched/fair: remove the DOUBLE_TICK feature (bsc#1234634
    (Scheduler functional and performance backports)).
  - softirq: use bit waits instead of var waits (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched: add wait_var_event_io() (bsc#1234634 (Scheduler
    functional and performance backports)).
  - sched: Add wait/wake interface for variable updated under a lock
    (bsc#1234634 (Scheduler functional and performance backports)).
  - sched: Add test_and_clear_wake_up_bit() and
    atomic_dec_and_wake_up() (bsc#1234634 (Scheduler functional
    and performance backports)).
  - sched: Document wait_var_event() family of functions and
    wake_up_var() (bsc#1234634 (Scheduler functional and performance
    backports)).
  - sched: Improve documentation for wake_up_bit/wait_on_bit
    family of functions (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched: change wake_up_bit() and related function to expect
    unsigned long * (bsc#1234634 (Scheduler functional and
    performance backports)).
  - sched/cpufreq: Ensure sd is rebuilt for EAS check (bsc#1234634
    (Scheduler functional and performance backports)).
  - sched_getattr: port to copy_struct_to_user (bsc#1234634
    (Scheduler functional and performance backports)).
  - uaccess: add copy_struct_to_user helper (bsc#1234634 (Scheduler
    functional and performance backports)).
  - commit 23379e3
  - s390/sclp: Allow user-space to provide PCI reports for optical
    modules (jsc#PED-11804).
  - commit 645b84a
  - net: mana: Fix irq_contexts memory leak in mana_gd_setup_irqs
    (git-fixes).
  - net: mana: Fix memory leak in mana_gd_setup_irqs (git-fixes).
  - commit e0ecd16
  - arm64: Ensure bits ASID[15:8] are masked out when the kernel uses (bsc#1234605)
  - commit b4e6c18

++++ lvm2:

  - Update lvm2 from LVM2.2.03.24 to LVM2.2.03.29
    * ** WHATS_NEW from 2.03.24 to 2.03.29 ***
    Version 2.03.29 - 09th December 2024
    ====================================
    Configure --enable/disable-sd-notify to control lvmlockd build with sd-notify.
    Allow test mode when lvmlockd is built without dlm support.
    Add a note about RAID + integrity synchronization to lvmraid(7) man page.
    Add a function for running lvconvert --repair on RAID LVs to lvmdbusd.
    Improve option section of man pages for listing commands ({pv,lv,vg}{s,display}).
    Fix renaming of raid sub LVs when converting a volume to raid (2.03.28).
    Fix segfault/VG write error for raid LV lvextend -i|--stripes -I|--stripesize.
    Revert ignore -i|--stripes, -I|--stripesize for lvextend on raid0 LV (2.03.27).
    Version 2.03.28 - 04th November 2024
    ====================================
    Use radix_tree to lookup for UUID within committed metadata.
    Use radix_tree to lookup LV list entry within VG struct.
    Introduce setting config/validate_metadata = full | none.
    Restore fs resize call for lvresize -r on the same size LV (2.03.17).
    Correct off-by-one devicesfile backup counting.
    Replace use of dm_hash with radix_tree for lv names and uuids.
    Refactor vg_validate with uniq_insert and better use of CPU caches.
    Add radix_tree_uniq_insert.
    Update DM cache when taking next VG lock instead of dropping it.
    Generate json string id only for json reporting.
    For vgsummary use new API call dm_config_parse_only_section().
    Use radix_tree for PV names mapping.
    Split check_lv_segment into separate _in/complete_vg variant.
    Use find_lv instead of find_lv_in_vg when possible.
    Do a mirror fixup only when mirrors with logs are imported.
    Add faster crc32 calculation from zlib code for x86_64.
    Fall back to direct zeroing if BLKZEROOUT fails during new LV initialization.
    Version 2.03.27 - 02nd October 2024
    ===================================
    Fix swap device size detection using blkid for lvresize/lvreduce/lvextend.
    Detect GPT partition table and pass partition filter if no partitions defined.
    Add global/sanlock_align_size option to configure sanlock lease size.
    Disable mem locking when activation/reserved_stack or reserved_memory is 0.
    Fix locking issues in lvmlockd leaving thin pool locked.
    Deprecate vdo settings vdo_write_policy and vdo_write_policy.
    Lots of typo fixes across lvm2 code base (codespell).
    Corrected integrity parameter interleave_sectors for DM table line.
    Ignore -i|--stripes, -I|--stripesize for lvextend on raid0 LV, like raid10.
    Do not accept duplicate device names for pvcreate.
    Version 2.03.26 - 23rd August 2024
    ==================================
    Fix internal error reported by pvmove on a VG with single PV.
    Also accept --mknodes --refresh for vgscan.
    Fix vgmknodes --refresh to wait for udev before checking /dev content.
    Use log/report_command_log=1 config setting by default for JSON output format.
    Fix unreleased memory pools on RAID lvextend.
    Add --integritysettings option to manipulate dm-integrity settings.
    Version 2.03.25 - 12nd July 2024
    ================================
    Utilize more radix_tree instead of dm_hash and btree.
    Refactor DM uuid caching from device_mapper directory.
    Enhance checking for DM uuid device.
    Fix lvm shell command completion on tab key (2.03.24).
    Avoid lockd_vg call to lvmlockd for local VGs.
    Allow forced change of locktype from none.
    Handle OPTIONS defined in /etc/sysconfig/lvmlockd.
    * ** WHATS_NEW_DM from 1.02.198 to 1.02.203 ***
    Version 1.02.203 - 09th December 2024
    =====================================
    Version 1.02.202 - 04th November 2024
    =====================================
    Introduce dm_config_parse_only_section to stop parsing after section.
    For shorter string use on stack buffers when generating sections.
    Enhance dm_config tokenizer.
    Version 1.02.201 - 02nd October 2024
    ====================================
    Cleanup udev sync semaphore if dm_{udev_create,task_set}_cookie fails.
    Improve error messages on failed udev cookie create/inc/dec operation.
    Version 1.02.200 - 23rd August 2024
    ===================================
    Version 1.02.199 - 12nd July 2024
    =================================
  - update lvm2.spec
  - change lvm2_version to 2.03.29
  - change upstream_device_mapper_version and device_mapper_version to 1.02.203
  - include new systemed files lvm-devices-import.path and lvm-devices-import.service in lvm2 package
  - add build dependency 'pkgconfig(systemd)' and configure option '--enable-sd-notify' for lvmlockd
  - remove unrecognized (since 2.03.01) configure parameter '--with-cluster' from lvmlockd

++++ openvswitch:

  - Add proper dependency on /usr/sbin/ipsec on openvswitch-ipsec:
    without the binary present, the service crashes on startup
    (boo#1234617).

++++ rpm:

  - update to rpm-4.20.0
    * new BuildSystem directive
    * support for build scriptley augmenting
    * per-package build directory available as %builddir
    * --build-in-place automatically sets --noprep
    * new -C option for autosetup
    * better support for reproducible builds
    * support for group membership lines
    * new rpm.spawn() lua function
    * support indentation in spec tags
    * new rpmdump tool
  - switch to rpmpgp-legacy-1.0
  - disable buildroot check in rpmlintrc for now
  - refreshed patches:
    * brp.diff macrosin.diff rpmqpack.diff specfilemacro.diff
    * noprereqdeprec.diff fileattrs.diff assumeexec.diff
    * enable-postin-scripts-error.diff findsupplements.diff
    * db_conversion.diff canongnu.diff cmake_python_version.diff
    * zstdpool.diff posttrans.diff
    * auto-config-update-aarch64-ppc64le.diff
    * 0002-log-build-time-if-it-is-set-from-SOURCE_DATE_EPOCH.patch
    * 0003-Error-out-on-a-missing-changelog-date.patch
  - add compatibility %buildroot definition
  - backport unshare fix from upstream and extend it a bit
    * new patch: unshare.diff

++++ libsodium:

  - Update to 1.0.20
    * When using the traditional build system, -O3 is used instead of -Ofast.
    * Improved detection of the compiler flags required on aarch64.
    * Improved compatibility with custom build systems on aarch64.
    * crypto_kdf_hkdf_sha512_statebytes() was added.
    * Compatibility issues with LLVM 18 and AVX512 have been addressed.
    For the full changelog see: https://github.com/jedisct1/libsodium/releases/tag/1.0.20-RELEASE
    * Update baselibs.conf
  - Included from 1.0.19
    * New AEADs: AEGIS-128L and AEGIS-256 are now available in the
    crypto_aead_aegis128l_*() and crypto_aead_aegis256_*() namespaces. AEGIS is
    a family of authenticated ciphers for high-performance applications,
    leveraging hardware AES acceleration on x86_64 and aarch64. In addition to
    performance, AEGIS ciphers have unique properties making them easier and
    safer to use than AES-GCM. They can also be used as high-performance MACs.
    * The HKDF key derivation mechanism, required by many standard protocols, is
    now available in the crypto_kdf_hkdf_*() namespace. It is implemented for
    the SHA-256 and SHA-512 hash functions.

++++ sqlite3:

  - Add sqlite3-6216bfcb.patch to fix a test suite regression in
    3.47.0 on s390x. Only the test was broken, not the code itself.
    https://sqlite.org/forum/forumpost/7b2bab04c5

++++ systemd:

  - Add 5006-tpm2-util-Also-retry-unsealing-after-policy_pcr-retu.patch
    Backport of https://github.com/systemd/systemd/pull/35657, which fixes
    https://github.com/systemd/systemd/issues/35490 (boo#1233752, bsc#1234313).

++++ python-rpm:

  - update to rpm-4.20.0

++++ selinux-policy:

  - Update to version 20240604+git390.e897b9b3:
    * Allow vhostmd_t list virtqemud pid dirs (bsc#1230961)

------------------------------------------------------------------
------------------  2024-12-15  -  Dec 15 2024  -------------------
------------------------------------------------------------------

++++ ca-certificates-mozilla:

  - Updated to 2.72 state of Mozilla SSL root CAs (bsc#1234798)
    Removed:
  - SecureSign RootCA11
  - Security Communication RootCA3
    Added:
  - TWCA CYBER Root CA
  - TWCA Global Root CA G2
  - SecureSign Root CA12
  - SecureSign Root CA14
  - SecureSign Root CA15

++++ less:

  - Update to 668
    * Fix crash when using --header on command line
    * Fix possible crash when scrolling left/right or toggling -S
    * Fix bug when using #stop in a lesskey file
    * Fix bug when using --shift or --match-shift on command line with a parameter starting with '.'
    * Fix bug in R command when file size changes
    * Fix bug using --header when file does not fill screen
    * Fix ^X bug when output is not a terminal
    * Fix bug where ^Z is not handled immediately
    * Fix bug where first byte from a LESSOPEN filter is deleted if it is greater than 0x7F
    * Fix uninitialized variable in edit_ifile
    * Fix incorrect handling of UTF-8 chars in prompts
  - Add reproducible.patch to override build date (boo#1047218)

++++ spirv-tools:

  - Update to release 2024.4~rc2
    * General:
    * Add FPEncoding operand type. (#5726)
    * Support SPV_KHR_untyped_pointers, SPV_INTEL_global_variable_host_access,
    SPV_KHR_compute_shader_derivative
    * Vulkan 1.4 support (#5899)
    * Optimizer: Add knowledge of cooperative matrice
  - Delete 0001-SPV_KHR_untyped_pointers-Fix-verification-for-OpenCL.patch
    (merged)

------------------------------------------------------------------
------------------  2024-12-14  -  Dec 14 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.2.3 → 10.2.4

++++ libXau:

  - update to 1.0.12
    * This release adds support for building with meson as well as
    autoconf, thanks to the work of Dylan Baker.
  - switched to meson build system

++++ libXxf86vm:

  - Update to version 1.1.6
    * Remove "All rights reserved" from Oracle copyright notices
    * configure: Use LT_INIT from libtool 2 instead of deprecated AC_PROG_LIBTOOL
    * Add X.Org's standard C warning flags to AM_CFLAGS
    * Add -no-undefined flag to LDFLAGS to fix Windows builds

------------------------------------------------------------------
------------------  2024-12-13  -  Dec 13 2024  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 27.4.0-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/27/#274>
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * cli-0001-docs-include-required-tools-in-source-tree.patch
  - Remove upstreamed patches:
  - 0006-bsc1221916-update-to-patched-buildkit-version-to-fix.patch
  - 0007-bsc1214855-volume-use-AtomicWriteFile-to-save-volume.patch

++++ docker-compose:

  - Update to version 2.32.0:
    * e2e test for recreate volume
    * build(deps): bump google.golang.org/grpc from 1.68.0 to 1.68.1
    * build(deps): bump golang.org/x/crypto from 0.27.0 to 0.31.0
    * build(deps): bump golang.org/x/sys from 0.27.0 to 0.28.0
    * prompt user to confirm volume recreation
    * Recreate container on volume configuration change
    * introduce watch restart action
    * bump otel dependencies to v1.28.0 and v0.53.0 to align with
    buildx, buildkit and engine versions
    * bump docker/buildx to latest release
    * fix support for service.mac_address
    * update xx to v1.6.1 for compatibility with alpine 3.21 and file
    5.46+
    * build(deps): bump golang.org/x/sync from 0.9.0 to 0.10.0
    * Update pkg/e2e/watch_test.go
    * first watch action for a file event wins
    * fix
    * revisit TestDebounceBatching
    * introduce sync+exec watch action
    * log configuration error as a watch log event
    * do not require a build section but for `rebuild` action
    * pull --quiet should not drop status message, only progress
    * use latest engine tags
    * Bump buildx to 0.19.1
    * be sure everything has been cleanup at the end of each tests
    * add local config.json to test configuration dir if exists
    * disable failing TestBuildSSH test
    * fix build with bake

++++ kernel-default:

  - KVM: s390: add gen17 facilities to CPU model (jsc#PED-10311).
  - KVM: s390: add msa11 to cpu model (jsc#PED-10311).
  - KVM: s390: add concurrent-function facility to cpu model
    (jsc#PED-10311).
  - commit 61222cd
  - s390/crypto: Add hardware acceleration for full AES-XTS mode
    (jsc#PED-10314).
  - s390/crypto: Postpone the key split to key conversion
    (jsc#PED-10314).
  - s390/crypto: Introduce function for tokenize clearkeys
    (jsc#PED-10314).
  - s390/crypto: Generalize parameters for key conversion
    (jsc#PED-10314).
  - s390/crypto: Use module-local structures for protected keys
    (jsc#PED-10314).
  - s390/crypto: Convert to reverse x-mas tree, rename ret to rc
    (jsc#PED-10314).
  - s390/pkey: Tolerate larger key blobs (jsc#PED-10314).
  - commit 0dd8187
  - supported.conf: mark arch/s390/crypto/hmac_s390 as externally supported (jsc#PED-10324)
  - commit c4fa325
  - supported.conf: mark drivers/s390/crypto/pkey_uv as externally supported (jsc#PED-10318)
  - commit 50163dc
  - s390x config: enable PKEY_UV (jsc#PED-10318)
  - commit 1fa7668
  - s390/pkey: Add new pkey handler module pkey-uv (jsc#PED-10318).
  - s390/pkey: Build module name array selectively based on kernel
    config options (jsc#PED-10318).
  - s390/pkey: Rework pkey verify for protected keys
    (jsc#PED-10318).
  - s390/pkey: Simplify protected key length calculation code
    (jsc#PED-10318).
  - s390/zcrypt: Cleanup include zcrypt_api.h (jsc#PED-10318).
  - commit fa68c6e
  - s390/uvdevice: Support longer secret lists (jsc#PED-11785).
  - s390/uv: Retrieve UV secrets sysfs support (jsc#PED-11785).
  - s390/uvdevice: Increase indent in IOCTL definitions
    (jsc#PED-11785).
  - s390/uvdevice: Add Retrieve Secret IOCTL (jsc#PED-11785).
  - s390/uv: Retrieve UV secrets support (jsc#PED-11785).
  - s390/uv: Use a constant for more-data rc (jsc#PED-11785).
  - commit 0151068
  - s390/uv: Provide host-key hashes in sysfs (jsc#PED-11158).
  - s390/uv: Refactor uv-sysfs creation (jsc#PED-11158).
  - commit edbf800
  - s390/cio: Externalize full CMG characteristics (jsc#PED-11162).
  - commit 5d24d1b
  - s390x config: disable CONFIG_COMPAT (jsc#PED-7854)
  - commit d25f099
  - rpm/kernel-binary.spec.in: fix KMPs build on 6.13+ (bsc#1234454)
    Upstream commit 822b11a74ba2 (kbuild: use absolute path in the generated
    wrapper Makefile) sets also KBUILD_OUTPUT in objdir's Makefile before
    including srcdir's Makefile.
    So emulate this too, otherwise KMPs fail to build:
    /usr/src/linux-6.13.0-rc2-1.gf92fc5d/Makefile:782: /usr/src/linux-6.13.0-rc2-1.gf92fc5d/include/config/auto.conf: No such file or directory
  - commit 46168e5
  - s390/pci: Fix leak of struct zpci_dev when zpci_add_device()
    fails (jsc#PED-10325).
  - s390/pci: Ignore RID for isolated VFs (jsc#PED-10325).
  - s390/pci: Use topology ID for multi-function devices
    (jsc#PED-10325).
  - s390/pci: Sort PCI functions prior to creating virtual busses
    (jsc#PED-10325).
  - commit 30c6861
  - Bluetooth: btmtk: avoid UAF in btmtk_process_coredump
    (git-fixes).
  - Bluetooth: iso: Fix circular lock in iso_conn_big_sync
    (git-fixes).
  - Bluetooth: iso: Fix circular lock in iso_listen_bis (git-fixes).
  - Bluetooth: SCO: Add support for 16 bits transparent voice
    setting (git-fixes).
  - Bluetooth: iso: Fix recursive locking warning (git-fixes).
  - Bluetooth: iso: Always release hdev at the end of iso_listen_bis
    (git-fixes).
  - Bluetooth: hci_event: Fix using rcu_read_(un)lock while
    iterating (git-fixes).
  - Bluetooth: Improve setsockopt() handling of malformed user input
    (git-fixes).
  - batman-adv: Do not let TT changes list grows indefinitely
    (git-fixes).
  - batman-adv: Remove uninitialized data in full table TT response
    (git-fixes).
  - batman-adv: Do not send uninitialized TT changes (git-fixes).
  - wifi: cfg80211: sme: init n_channels before channels[] access
    (git-fixes).
  - wifi: mac80211: fix station NSS capability initialization order
    (git-fixes).
  - wifi: mac80211: fix a queue stall in certain cases of CSA
    (git-fixes).
  - wifi: mac80211: init cnt before accessing elem in
    ieee80211_copy_mbssid_beacon (git-fixes).
  - wifi: nl80211: fix NL80211_ATTR_MLO_LINK_ID off-by-one
    (git-fixes).
  - commit 87acd7b

++++ kernel-rt:

  - KVM: s390: add gen17 facilities to CPU model (jsc#PED-10311).
  - KVM: s390: add msa11 to cpu model (jsc#PED-10311).
  - KVM: s390: add concurrent-function facility to cpu model
    (jsc#PED-10311).
  - commit 61222cd
  - s390/crypto: Add hardware acceleration for full AES-XTS mode
    (jsc#PED-10314).
  - s390/crypto: Postpone the key split to key conversion
    (jsc#PED-10314).
  - s390/crypto: Introduce function for tokenize clearkeys
    (jsc#PED-10314).
  - s390/crypto: Generalize parameters for key conversion
    (jsc#PED-10314).
  - s390/crypto: Use module-local structures for protected keys
    (jsc#PED-10314).
  - s390/crypto: Convert to reverse x-mas tree, rename ret to rc
    (jsc#PED-10314).
  - s390/pkey: Tolerate larger key blobs (jsc#PED-10314).
  - commit 0dd8187
  - supported.conf: mark arch/s390/crypto/hmac_s390 as externally supported (jsc#PED-10324)
  - commit c4fa325
  - supported.conf: mark drivers/s390/crypto/pkey_uv as externally supported (jsc#PED-10318)
  - commit 50163dc
  - s390x config: enable PKEY_UV (jsc#PED-10318)
  - commit 1fa7668
  - s390/pkey: Add new pkey handler module pkey-uv (jsc#PED-10318).
  - s390/pkey: Build module name array selectively based on kernel
    config options (jsc#PED-10318).
  - s390/pkey: Rework pkey verify for protected keys
    (jsc#PED-10318).
  - s390/pkey: Simplify protected key length calculation code
    (jsc#PED-10318).
  - s390/zcrypt: Cleanup include zcrypt_api.h (jsc#PED-10318).
  - commit fa68c6e
  - s390/uvdevice: Support longer secret lists (jsc#PED-11785).
  - s390/uv: Retrieve UV secrets sysfs support (jsc#PED-11785).
  - s390/uvdevice: Increase indent in IOCTL definitions
    (jsc#PED-11785).
  - s390/uvdevice: Add Retrieve Secret IOCTL (jsc#PED-11785).
  - s390/uv: Retrieve UV secrets support (jsc#PED-11785).
  - s390/uv: Use a constant for more-data rc (jsc#PED-11785).
  - commit 0151068
  - s390/uv: Provide host-key hashes in sysfs (jsc#PED-11158).
  - s390/uv: Refactor uv-sysfs creation (jsc#PED-11158).
  - commit edbf800
  - s390/cio: Externalize full CMG characteristics (jsc#PED-11162).
  - commit 5d24d1b
  - s390x config: disable CONFIG_COMPAT (jsc#PED-7854)
  - commit d25f099
  - rpm/kernel-binary.spec.in: fix KMPs build on 6.13+ (bsc#1234454)
    Upstream commit 822b11a74ba2 (kbuild: use absolute path in the generated
    wrapper Makefile) sets also KBUILD_OUTPUT in objdir's Makefile before
    including srcdir's Makefile.
    So emulate this too, otherwise KMPs fail to build:
    /usr/src/linux-6.13.0-rc2-1.gf92fc5d/Makefile:782: /usr/src/linux-6.13.0-rc2-1.gf92fc5d/include/config/auto.conf: No such file or directory
  - commit 46168e5
  - s390/pci: Fix leak of struct zpci_dev when zpci_add_device()
    fails (jsc#PED-10325).
  - s390/pci: Ignore RID for isolated VFs (jsc#PED-10325).
  - s390/pci: Use topology ID for multi-function devices
    (jsc#PED-10325).
  - s390/pci: Sort PCI functions prior to creating virtual busses
    (jsc#PED-10325).
  - commit 30c6861
  - Bluetooth: btmtk: avoid UAF in btmtk_process_coredump
    (git-fixes).
  - Bluetooth: iso: Fix circular lock in iso_conn_big_sync
    (git-fixes).
  - Bluetooth: iso: Fix circular lock in iso_listen_bis (git-fixes).
  - Bluetooth: SCO: Add support for 16 bits transparent voice
    setting (git-fixes).
  - Bluetooth: iso: Fix recursive locking warning (git-fixes).
  - Bluetooth: iso: Always release hdev at the end of iso_listen_bis
    (git-fixes).
  - Bluetooth: hci_event: Fix using rcu_read_(un)lock while
    iterating (git-fixes).
  - Bluetooth: Improve setsockopt() handling of malformed user input
    (git-fixes).
  - batman-adv: Do not let TT changes list grows indefinitely
    (git-fixes).
  - batman-adv: Remove uninitialized data in full table TT response
    (git-fixes).
  - batman-adv: Do not send uninitialized TT changes (git-fixes).
  - wifi: cfg80211: sme: init n_channels before channels[] access
    (git-fixes).
  - wifi: mac80211: fix station NSS capability initialization order
    (git-fixes).
  - wifi: mac80211: fix a queue stall in certain cases of CSA
    (git-fixes).
  - wifi: mac80211: init cnt before accessing elem in
    ieee80211_copy_mbssid_beacon (git-fixes).
  - wifi: nl80211: fix NL80211_ATTR_MLO_LINK_ID off-by-one
    (git-fixes).
  - commit 87acd7b

++++ libeconf:

  - Update to version 0.7.6:
    * Do not try to parse files with name like ".." and "." (#227)
    * using econf_readConfig in econftool

------------------------------------------------------------------
------------------  2024-12-12  -  Dec 12 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - require llvm19/clang19 on sle15 >= sp6

++++ Mesa-drivers:

  - require llvm19/clang19 on sle15 >= sp6

++++ elfutils:

  - Add fix-static-linking.patch (bsc#1234445)

++++ haproxy:

  - Update to version 3.1.1+git0.717960de0:
    * [RELEASE] Released version 3.1.1
    * BUG/MINOR: hlua_fcn: restore server pairs iterator pointer consistency
    * BUG/MINOR: server-state: Fix expiration date of srvrq_check tasks
    * BUG/MINOR: http-fetch: Ignore empty argument string for query()
    * BUG/MEDIUM: stats/server: use watcher to track server during stats dump
    * MINOR: list: define a watcher type
    * BUG/MINOR: stats: decrement srv refcount on stats-file release
    * BUG/MINOR: resolvers: handle a possible strdup() failure
    * BUG/MINOR: ssl_crtlist: handle a possible strdup() failure
    * BUG/MINOR: namespace: handle a possible strdup() failure
    * BUG/MEDIUM: mworker: report status, if daemonized master fails
    * BUG/MEDIUM: startup: report status if daemonized process fails
    * BUG/MEDIUM: startup: don't daemonize if started with -c
    * BUG/MINOR: startup: fix error path for master, if can't open pidfile
    * BUG/MINOR: mworker: fix -D -W -sf/-st modes
    * BUG/MINOR: mworker: don't save program PIDs in oldpids
    * BUG/MINOR: mux-h2: fix expression when detecting excess of CONTINUATION frames
    * MINOR: mux-h2/glitches: add a description to the H2 glitches
    * CLEANUP: mux-h2/traces: reword certain ambiguous traces
    * MINOR: mux-h2/traces: add a missing trace on negative initial window size
    * BUILD: debug: fix build issues in COUNT_IF() with -Wunused-value
    * BUG/MINOR: debug: COUNT_IF() should return true/false
    * DOC: config: fix confusing init-state examples
    * BUG/MINOR: config: Fix parsing of accept-invalid-http-{request,response}
    * BUG/MEDIUM: mux-h2: make sure not to touch dummy streams when sending WU
    * BUG/MINOR: quic: remove startup alert if GSO unsupported
    * BUG/MINOR: quic: remove startup alert if conn socket-owner unsupported
    * BUG/MEDIUM: mux-quic: remove pacing status when everything is sent
    * BUG/MINOR: init: do not call fork_poller() for non-forked processes
    * BUG/MEDIUM: init: make sure only daemonized processes change their session
    * BUG/MINOR: quic: fix bbr_inflight() calls with wrong gain value
    * BUG/MINOR: startup: fix pidfile creation
    * BUG/MINOR: startup: close pidfd and free global.pidfile in handle_pidfile()
    * BUG/MINOR: signal: register default handler for SIGINT in signal_init()
    * BUILD: quic: fix a build error about an non initialized timestamp
    * BUG/MINOR: h1-htx: Use default reason if not set when formatting the response
    * BUG/MEDIUM: http-ana: Reset request flag about data sent to perform a L7 retry
    * BUG/MEDIUM: quic: prevent stream freeze on pacing
    * BUG/MEDIUM: event_hdl: fix uninitialized value in async mode when no data is provided
    * BUG/MINOR: improve BBR throughput on very fast links
    * BUG/MINOR: log: fix lf_text() behavior with empty string
    * MINOR: proxy: Add support of 421-Misdirected-Request in retry-on status
    * BUG/MEDIUM: sock: Remove FD_POLL_HUP during connect() if FD_POLL_ERR is not set

++++ kernel-default:

  - scsi: megaraid_sas: Fix for a potential deadlock
    (jsc#PED-11259).
  - commit 73f8b3c
  - Update config files: drop bfa driver (jsc#PED-6925)
  - commit 6eb9687
  - scsi: mpt3sas: Update driver version to 51.100.00.00
    (jsc#PED-11252).
  - commit a77a0f7
  - scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set
    during driver load time (jsc#PED-11252).
  - commit ab220b1
  - iommufd: Fix out_fput in iommufd_fault_alloc() (git-fixes).
  - commit b516daa
  - iommu/amd/pgtbl_v2: Take protection domain lock before
    invalidating TLB (git-fixes).
  - commit bfae336
  - scsi: storvsc: Do not flag MAINTENANCE_IN return of
    SRB_STATUS_DATA_OVERRUN as an error (git-fixes).
  - net :mana :Request a V2 response version for MANA_QUERY_GF_STAT
    (git-fixes).
  - net: mana: use ethtool string helpers (git-fixes).
  - net: mana: Enable debugfs files for MANA device (git-fixes).
  - hv_netvsc: Don't assume cpu_possible_mask is dense (git-fixes).
  - net: mana: Add get_link and get_link_ksettings in ethtool
    (git-fixes).
  - net: mana: Increase the DEF_RX_BUFFERS_PER_QUEUE to 1024
    (git-fixes).
  - commit a3a0c1e

++++ kernel-rt:

  - scsi: megaraid_sas: Fix for a potential deadlock
    (jsc#PED-11259).
  - commit 73f8b3c
  - Update config files: drop bfa driver (jsc#PED-6925)
  - commit 6eb9687
  - scsi: mpt3sas: Update driver version to 51.100.00.00
    (jsc#PED-11252).
  - commit a77a0f7
  - scsi: mpt3sas: Diag-Reset when Doorbell-In-Use bit is set
    during driver load time (jsc#PED-11252).
  - commit ab220b1
  - iommufd: Fix out_fput in iommufd_fault_alloc() (git-fixes).
  - commit b516daa
  - iommu/amd/pgtbl_v2: Take protection domain lock before
    invalidating TLB (git-fixes).
  - commit bfae336
  - scsi: storvsc: Do not flag MAINTENANCE_IN return of
    SRB_STATUS_DATA_OVERRUN as an error (git-fixes).
  - net :mana :Request a V2 response version for MANA_QUERY_GF_STAT
    (git-fixes).
  - net: mana: use ethtool string helpers (git-fixes).
  - net: mana: Enable debugfs files for MANA device (git-fixes).
  - hv_netvsc: Don't assume cpu_possible_mask is dense (git-fixes).
  - net: mana: Add get_link and get_link_ksettings in ethtool
    (git-fixes).
  - net: mana: Increase the DEF_RX_BUFFERS_PER_QUEUE to 1024
    (git-fixes).
  - commit a3a0c1e

++++ libdrm:

  - adjusted patches
    * n_libdrm-drop-valgrind-dep-generic.patch
    * n_libdrm-drop-valgrind-dep-intel.patch

++++ libsoup:

  - Update to version 3.6.1+4:
    + Fix ownership annotatin for soup_form_decode_multipart().
  - Convert to obs_scm source service: allow for easier maintenance.

++++ libvirt:

  - qemu: tpm: do not update profile name for transient domains
    Fixes a crash when starting a transient domain
    boo#1234438

++++ passt:

  - Update to version 20241211.09478d5:
    * treewide: Dodge dynamic memory allocation in strerror() from glibc > 2.40
    * pasta: make it possible to disable socket splicing
    * tap: Call vu_init() with --fd
    * tap: Use a common function to start a new connection
    * udp_vu: update segment size
    * flow: Remove over-zealous sanity checks in flow_sidx_hash()
    * udp: Improve detail of UDP endpoint sanity checking
    * perf/passt_vu_tcp: Make it shine
    * tcp_vu: Compute IPv4 header checksum if dlen changes
    * Makefile: Use make internal string functions
    * tcp_vu: Remove unnecessary tcp_vu_update_check() function
    * tcp: Merge tcp_fill_headers[46]() with each other
    * tcp: Merge tcp_update_check_tcp[46]()
    * tcp: Pass TCP header and payload separately to tcp_fill_headers[46]()
    * tcp: Pass TCP header and payload separately to tcp_update_check_tcp[46]()
    * iov, checksum: Replace csum_iov() with csum_iov_tail()
    * iov: iov tail helpers
    * tcp_vu: Change 'dlen' to ssize_t in tcp_vu_data_from_sock()
    * Fix build on 32bit target
    * virtio: check if avail ring is configured
    * tcp: Move tcp_l2_buf_fill_headers() to tcp_buf.c
    * test: Add tests for passt in vhost-user mode
    * vhost-user: add vhost-user
    * passt: rename tap_sock_init() to tap_backend_init()
    * tcp: Export headers functions
    * udp: Prepare udp.c to be shared with vhost-user
    * vhost-user: introduce vhost-user API
    * vhost-user: introduce virtio API
    * packet: replace struct desc by struct iovec

++++ python-six:

  - update to 1.17:
    * Add python 3.9 testing
    * Fix UserDict move in Python2
    * Delete pep8ignore and flakes-ignore
    * tkinter.tix was removed from Python 3.13, skip the test
    * Fix deprecation warning from setuptools
    * Python 3.14 removed the URLopener and FancyURLopener classes,
    from urllib.requests
    * Update copyright years
    * Expunge travis

------------------------------------------------------------------
------------------  2024-12-11  -  Dec 11 2024  -------------------
------------------------------------------------------------------

++++ curl:

  - Update to 8.11.1:
    * Security fixes:
  - netrc and redirect credential leak [bsc#1234068, CVE-2024-11053]
    * Bugfixes:
  - build: fix ECH to always enable HTTPS RR
  - cookie: treat cookie name case sensitively
  - curl-rustls.m4: keep existing 'CPPFLAGS'/'LDFLAGS' when detected
  - curl: use realtime in trace timestamps
  - digest: produce a shorter cnonce in Digest headers
  - docs: document default 'User-Agent'
  - docs: suggest --ssl-reqd instead of --ftp-ssl
  - duphandle: also init netrc
  - hostip: don't use the resolver for FQDN localhost
  - http_negotiate: allow for a one byte larger channel binding buffer
  - krb5: fix socket/sockindex confusion, MSVC compiler warnings
  - libssh: use libssh sftp_aio to upload file
  - libssh: when using IPv6 numerical address, add brackets
  - mime: fix reader stall on small read lengths
  - mk-ca-bundle: remove CKA_NSS_SERVER_DISTRUST_AFTER conditions
  - mprintf: fix the integer overflow checks
  - multi: fix callback for 'CURLMOPT_TIMERFUNCTION' not being called again when...
  - netrc: address several netrc parser flaws
  - netrc: support large file, longer lines, longer tokens
  - nghttp2: use custom memory functions
  - OpenSSL: improvde error message on expired certificate
  - openssl: remove three "Useless Assignments"
  - openssl: stop using SSL_CTX_ function prefix for our functions
  - pytest: add test for use of CURLMOPT_MAX_HOST_CONNECTIONS
  - rtsp: check EOS in the RTSP receive and return an error code
  - schannel: remove TLS 1.3 ciphersuite-list support
  - setopt: fix CURLOPT_HTTP_CONTENT_DECODING
  - setopt: fix missing options for builds without HTTP & MQTT
  - socket: handle binding to "host!<ip>"
  - socketpair: fix enabling 'USE_EVENTFD'
  - strtok: use namespaced 'strtok_r' macro instead of redefining it
    * Remove 0001-duphandle-also-init-netrc.patch upstream

++++ docker:

  - Update docker-buildx to v0.19.2. See upstream changelog online at
    <https://github.com/docker/buildx/releases/tag/v0.19.2>.
    Some notable changelogs from the last update:
    * <https://github.com/docker/buildx/releases/tag/v0.19.0>
    * <https://github.com/docker/buildx/releases/tag/v0.18.0>
  - Update to Go 1.22.
  - Add a new toggle file /etc/docker/suse-secrets-enable which allows users to
    disable the SUSEConnect integration with Docker (which creates special mounts
    in /run/secrets to allow container-suseconnect to authenticate containers
    with registries on registered hosts). bsc#1231348 bsc#1232999
    In order to disable these mounts, just do
    echo 0 > /etc/docker/suse-secrets-enable
    and restart Docker. In order to re-enable them, just do
    echo 1 > /etc/docker/suse-secrets-enable
    and restart Docker. Docker will output information on startup to tell you
    whether the SUSE secrets feature is enabled or not.
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch

++++ python-kiwi:

  - Update system files setup for containers
    The attribute provide_system_files creates a meta file in the
    root tree named 'systemfiles'. The contents of this file were
    produced by just a dump of the package database so far. For
    a more generic use of this data some adaptions were needed.
    First we allow to skip packages matching a pattern from being
    part of the system files. Next we do not put ghost and doc
    files into account. And last we handle library files in a different
    file named 'systemfiles.libs' where we do not add symlink targets
    if the target path is also part of the package. The consumer
    of this information is flake-pilot which syncs that library system
    files from the host via --copy-links. This allows a more generic
    use with regards to versioned libraries e.g. libc

++++ drbd:

  - Update DRBD version from 9.1.22 to 9.1.23 (boo#1234849)
    * Changelog from Linbit:
    9.1.23 (api:genl2/proto:86-101,118-121/transport:18)
  - -------
    * Fix a corner case that can happen when DRBD establishes multiple
    connections in parallel, which could lead one connection to end up in
    an inconsistent replication state of WFBitMapT/Established
    * Fix a corner case in which a reconciliation resync ends up in
    WFBitMapT/Established
    * Restrict protocol compatibility to the most recent 8.4 and 9.0 releases
    * Fix a corner case causing a module ref leak on drbd_transport_tcp;
    if it hits, you can not rmmod it
    * rate-limit resync progress while resync is paused
    * resync-target inherits history UUIDs when resync finishes,
    this can prevent unexpected "unrelared data" events later
    * Updated compatibility code for Linux 6.11 and 6.12
    * remove patches which already included in the new version:
    0001-drbd-properly-rate-limit-resync-progress-reports.patch
    0002-drbd-inherit-history-UUIDs-from-sync-source-when-res.patch
    0003-build-compat-fix-line-offset-in-annotation-pragmas-p.patch
    0004-drbd-fix-exposed_uuid-going-backward.patch
    0005-drbd-Proper-locking-around-new_current_uuid-on-a-dis.patch
    0006-build-CycloneDX-fix-bom-ref-add-purl.patch
    0007-build-Another-update-to-the-spdx-files.patch
    0008-build-generate-spdx.json-not-tag-value-format.patch
    0009-compat-fix-gen_patch_names-for-bdev_file_open_by_pat.patch
    0010-compat-fix-nla_nest_start_noflag-test.patch
    0011-compat-fix-blk_alloc_disk-rule.patch
    0012-drbd-remove-const-from-function-return-type.patch
    0013-drbd-don-t-set-max_write_zeroes_sectors-in-decide_on.patch
    0014-drbd-split-out-a-drbd_discard_supported-helper.patch
    0015-drbd-atomically-update-queue-limits-in-drbd_reconsid.patch
    0016-compat-test-and-patch-for-queue_limits_start_update.patch
    0017-compat-specify-which-essential-change-was-not-made.patch
    0018-gen_patch_names-reorder-blk_mode_t.patch
    0019-compat-fix-blk_queue_update_readahead-patch.patch
    0020-compat-test-and-patch-for-que_limits-max_hw_discard_.patch
    0021-compat-fixup-write_zeroes__no_capable.patch
    0022-compat-fixup-queue_flag_discard__yes_present.patch
    0023-drbd-move-flags-to-queue_limits.patch
    0024-compat-test-and-patch-for-queue_limits.features.patch
    0025-drbd-Annotate-struct-fifo_buffer-with-__counted_by.patch
    0026-compat-test-and-patch-for-__counted_by.patch
    0027-drbd-fix-function-cast-warnings-in-state-machine.patch
    0028-Add-missing-documentation-of-peer_device-parameter-t.patch
    0030-drbd-kref_put-path-when-kernel_accept-fails.patch
    0031-build-fix-typo-in-Makefile.spatch.patch
    0032-drbd-open-do-not-delay-open-if-already-Primary.patch
    * removed patch which is not needed anymore:
    boo1231290_fix_drbd_build_error_against_kernel_v6.11.0.patch
    boo1233222_fix_drbd_build_error_against_kernel_v6.11.6.patch
    bsc-1216666-compat-sock-Remove-sendpage-in-favour-of-sendmsg-MSG.patch
    * update:
    drbd_git_revision
    drbd.spec
    * add upstream patches to align commit d64ebe7eb7df:
    0001-drbd-Fix-memory-leak.patch

++++ gpg2:

  - Update to 2.5.2:
    * gpg: Add option 16 to --full-gen-key to create ECC+Kyber.  [T6638]
    * gpg: For composite algos add the algo string to the colons
    listings.  [T6638]
    * gpg: Validate the trustdb after the import of a trusted key.
    [T7200]
    * gpg: Exclude expired trusted keys from the key validation process.
    [T7200]
    * gpg: Fix a wrong decryption failed status for signed and OCB
    encrypted messages without a signature verification key.  [T7042]
    * gpg: Retain binary representation for import->export with Ed25519
    key signatures.  [T7426]
    * gpg: Fix comparing ed448 to ed25519 with --assert-pubkey-algo.
    [T7425]
    * gpg: Avoid a failure exit code for expired ultimately trusted
    keys.  [T7351]
    * gpg: Emit status error for an invalid ADSK.  [T7322]
    * gpg: Allow the use of an ADSK subkey as ADSK subkey.  [T6882]
    * gpg: Fix --quick-set-expire for V5 subkey fingerprints.  [T7298]
    * gpg: Robust error handling for SCD READKEY.  [T7309]
    * gpg: Fix cv25519 v5 export regression.  [T7316]
    * gpgsm: Nearly fourfold speedup of validated certificate listings.
    [T7308]
    * gpgsm: Improvement for some rare P12 files.  [rGf50dde6269]
    * gpgsm: Terminate key listing on output write error.  [T6185]
    * agent: Add option --status to the LISTRUSTED command.
    [rG4275d5fa7a]
    * agent: Fix detection of the yet unused trustflag de-vs.  [T5079]
    * agent: Allow ssh to sign data larger than the Assuan line length.
    [T7436]
    * keyboxd: Fix a race condition on the database handle.  [T7294]
    * dirmngr: A list of used URLs for loaded CRLs is printed first in
    the output of the LISTCRL command.  [T7337]
    * scd: More mitigations against lock ups with multiple cards or
    apps.  [T7323, T7402]
    * gpgtar: Use log-file from common.conf only in --batch mode.
    [rGb389e04ef5]
    * gpgtar: Fix directory creation during extraction.  [T7380]
    * gpg-mail-tube: Minor fixes.
    * gpgconf: Add list flag to trusted-key et al.  [T7313]
    * Implement GNUPG_ASSUME_COMPLIANCE envvar and registry key for
    testing de-vs compliance mode.  [rGb287fb5775,rG7b0be541a9]
    * Fix a race condition in creating the socket directory.  [T7332]

++++ kernel-default:

  - bnxt_en: Add support for RoCE sriov configuration (jsc#PED-11250)
  - commit a177146
  - Re-enable patches.suse/mlx5-add-parameter-to-disable-enhanced-IPoIB.patch (bsc#1142095, jsc#SLE-15175)
  - commit 7a74a29
  - locking/rt: Annotate unlock followed by lock for sparse
    (bsc#1234370).
  - locking/rt: Add sparse annotation for RCU (bsc#1234370).
  - locking/rt: Remove one __cond_lock() in RT's
    spin_trylock_irqsave() (bsc#1234370).
  - locking/rt: Add sparse annotation PREEMPT_RT's sleeping locks
    (bsc#1234370).
  - commit 79348e2
  - IB/cm: Rework sending DREQ when destroying a cm_id (jsc#PED-11323)
  - commit 5f6d0d2
  - IB/cm: Do not hold reference on cm_id unless needed (jsc#PED-11323)
  - commit aaede19
  - IB/cm: Explicitly mark if a response MAD is a retransmission (jsc#PED-11323)
  - commit 2d5950b
  - RDMA/nldev: Add IB device and net device rename events (jsc#PED-11323)
  - commit 3146d03
  - RDMA/core: Move ib_uverbs_file struct to uverbs_types.h (jsc#PED-11323)
  - commit dda2a0e
  - RDMA/core: Add device ufile cleanup operation (jsc#PED-11323)
  - commit b241858
  - RDMA/core: Implement RoCE GID port rescan and export delete function (jsc#PED-11323)
  - commit 9487e55
  - RDMA/rxe: Set queue pair cur_qp_state when being queried (jsc#PED-11323)
  - commit 1fda28e
  - RDMA/efa: Report link speed according to device attributes (jsc#PED-11323)
  - commit 96e5da5
  - RDMA/rxe: Fix the qp flush warnings in req (jsc#PED-11323)
  - commit df95324
  - This is very hard to fix upstream as it goes deeply into NFC core
  - commit 668fe23
  - RDMA: Use ethtool string helpers (jsc#PED-11323)
  - commit 486ec2b
  - RDMA/ipoib: Use the networking stack default for txqueuelen (jsc#PED-11323)
  - commit b26dae5
  - RDMA/efa: Add option to set QP service level on create (jsc#PED-11323)
  - commit d641492
  - RDMA/efa: Update device interface (jsc#PED-11323)
  - commit a356642
  - IB/hfi1: make clear_all_interrupts static (jsc#PED-8564)
  - commit 69cf48c
  - RDMA/hns: Fix different dgids mapping to the same dip_idx (jsc#PED-11250)
  - commit a935952
  - RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() (jsc#PED-11250)
  - commit 914d5d2
  - RDMA/hns: Fix out-of-order issue of requester when setting FENCE (jsc#PED-11250)
  - commit f34c3c1
  - RDMA/hns: Fix cpu stuck caused by printings during reset (jsc#PED-11250)
  - commit 6408c43
  - RDMA/hns: Use dev_* printings in hem code instead of ibdev_* (jsc#PED-11250)
  - commit 99377a7
  - RDMA/hns: Modify debugfs name (jsc#PED-11250)
  - commit 3839b8a
  - RDMA/hns: Fix flush cqe error when racing with destroy qp (jsc#PED-11250)
  - commit 39e568b
  - RDMA/hns: Fix an AEQE overflow error caused by untimely update of eq_db_ci (jsc#PED-11250)
  - commit 56699b7
  - RDMA/hns: Disassociate mmap pages for all uctx when HW is being reset (jsc#PED-11250)
  - commit 6230f20
  - RDMA/bnxt_re: Correct the sequence of device suspend (jsc#PED-11250)
  - commit 2ef4645
  - RDMA/bnxt_re: Use the default mode of congestion control (jsc#PED-11250)
  - commit 65235d2
  - RDMA/bnxt_re: Support different traffic class (jsc#PED-11250)
  - commit 1942a7b
  - RDMA/bnxt_re: Cache MSIx info to a local structure (jsc#PED-11250)
  - commit 1e3b642
  - RDMA/bnxt_re: Refurbish CQ to NQ hash calculation (jsc#PED-11250)
  - commit 69d4b35
  - RDMA/bnxt_re: Refactor NQ allocation (jsc#PED-11250)
  - commit 72bfe4d
  - RDMA/bnxt_re: Fail probe early when not enough MSI-x vectors are reserved (jsc#PED-11250)
  - commit 2d18123
  - RDMA/bnxt_re: Add set_func_resources support for P5/P7 adapters (jsc#PED-11250)
  - commit cbb163e
  - RDMA/bnxt_re: Enhance RoCE SRIOV resource configuration design (jsc#PED-11250)
  - commit 8e2b0d1
  - RDMA/bnxt_re: Add debugfs hook in the driver (jsc#PED-11250)
  - commit 7df4e4c
  - RDMA/bnxt_re: Support raw data query for each resources (jsc#PED-11250)
  - commit b35c9fe
  - RDMA/bnxt_re: Add support for querying HW contexts (jsc#PED-11250)
  - commit 03d0ac2
  - RDMA/bnxt_re: Support driver specific data collection using rdma tool (jsc#PED-11250)
  - commit 301d4c8
  - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey (jsc#PED-11250)
  - commit db78d83
  - RDMA/bnxt_re: Fix access flags for MR and QP modify (jsc#PED-11250)
  - commit 103dfc7
  - RDMA/bnxt_re: Add support for modify_device hook (jsc#PED-11250)
  - commit 2b5ef62
  - RDMA/bnxt_re: Add support for CQ rx coalescing (jsc#PED-11250)
  - commit 24d2ba3
  - RDMA/bnxt_re: Add support for optimized modify QP (jsc#PED-11250)
  - commit b0961e5
  - RDMA/core: Provide rdma_user_mmap_disassociate() to disassociate mmap pages (jsc#PED-11250)
  - commit 9dfd1ae
  - s390/dasd: fix redundant /proc/dasd* entries removal
    (bsc#1227694).
  - commit 3fe3c9b
  - softirq: Use a dedicated thread for timer wakeups on PREEMPT_RT
    (bsc#1234370).
  - timers: Use __raise_softirq_irqoff() to raise the softirq
    (bsc#1234370).
  - hrtimer: Use __raise_softirq_irqoff() to raise the softirq
    (bsc#1234370).
  - commit 648ddcf

++++ kernel-firmware-all:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-amdgpu:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-ath10k:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-ath11k:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-ath12k:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-atheros:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-bluetooth:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-bnx2:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-brcm:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-chelsio:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-dpaa2:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-i915:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-intel:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-iwlwifi:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-liquidio:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-marvell:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-media:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-mediatek:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-mellanox:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-mwifiex:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-network:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-nfp:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-nvidia:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-platform:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-prestera:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-qcom:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-qlogic:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-radeon:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-realtek:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-serial:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-sound:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-ti:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-ueagle:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-firmware-usb-network:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

++++ kernel-rt:

  - bnxt_en: Add support for RoCE sriov configuration (jsc#PED-11250)
  - commit a177146
  - Re-enable patches.suse/mlx5-add-parameter-to-disable-enhanced-IPoIB.patch (bsc#1142095, jsc#SLE-15175)
  - commit 7a74a29
  - locking/rt: Annotate unlock followed by lock for sparse
    (bsc#1234370).
  - locking/rt: Add sparse annotation for RCU (bsc#1234370).
  - locking/rt: Remove one __cond_lock() in RT's
    spin_trylock_irqsave() (bsc#1234370).
  - locking/rt: Add sparse annotation PREEMPT_RT's sleeping locks
    (bsc#1234370).
  - commit 79348e2
  - IB/cm: Rework sending DREQ when destroying a cm_id (jsc#PED-11323)
  - commit 5f6d0d2
  - IB/cm: Do not hold reference on cm_id unless needed (jsc#PED-11323)
  - commit aaede19
  - IB/cm: Explicitly mark if a response MAD is a retransmission (jsc#PED-11323)
  - commit 2d5950b
  - RDMA/nldev: Add IB device and net device rename events (jsc#PED-11323)
  - commit 3146d03
  - RDMA/core: Move ib_uverbs_file struct to uverbs_types.h (jsc#PED-11323)
  - commit dda2a0e
  - RDMA/core: Add device ufile cleanup operation (jsc#PED-11323)
  - commit b241858
  - RDMA/core: Implement RoCE GID port rescan and export delete function (jsc#PED-11323)
  - commit 9487e55
  - RDMA/rxe: Set queue pair cur_qp_state when being queried (jsc#PED-11323)
  - commit 1fda28e
  - RDMA/efa: Report link speed according to device attributes (jsc#PED-11323)
  - commit 96e5da5
  - RDMA/rxe: Fix the qp flush warnings in req (jsc#PED-11323)
  - commit df95324
  - This is very hard to fix upstream as it goes deeply into NFC core
  - commit 668fe23
  - RDMA: Use ethtool string helpers (jsc#PED-11323)
  - commit 486ec2b
  - RDMA/ipoib: Use the networking stack default for txqueuelen (jsc#PED-11323)
  - commit b26dae5
  - RDMA/efa: Add option to set QP service level on create (jsc#PED-11323)
  - commit d641492
  - RDMA/efa: Update device interface (jsc#PED-11323)
  - commit a356642
  - IB/hfi1: make clear_all_interrupts static (jsc#PED-8564)
  - commit 69cf48c
  - RDMA/hns: Fix different dgids mapping to the same dip_idx (jsc#PED-11250)
  - commit a935952
  - RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() (jsc#PED-11250)
  - commit 914d5d2
  - RDMA/hns: Fix out-of-order issue of requester when setting FENCE (jsc#PED-11250)
  - commit f34c3c1
  - RDMA/hns: Fix cpu stuck caused by printings during reset (jsc#PED-11250)
  - commit 6408c43
  - RDMA/hns: Use dev_* printings in hem code instead of ibdev_* (jsc#PED-11250)
  - commit 99377a7
  - RDMA/hns: Modify debugfs name (jsc#PED-11250)
  - commit 3839b8a
  - RDMA/hns: Fix flush cqe error when racing with destroy qp (jsc#PED-11250)
  - commit 39e568b
  - RDMA/hns: Fix an AEQE overflow error caused by untimely update of eq_db_ci (jsc#PED-11250)
  - commit 56699b7
  - RDMA/hns: Disassociate mmap pages for all uctx when HW is being reset (jsc#PED-11250)
  - commit 6230f20
  - RDMA/bnxt_re: Correct the sequence of device suspend (jsc#PED-11250)
  - commit 2ef4645
  - RDMA/bnxt_re: Use the default mode of congestion control (jsc#PED-11250)
  - commit 65235d2
  - RDMA/bnxt_re: Support different traffic class (jsc#PED-11250)
  - commit 1942a7b
  - RDMA/bnxt_re: Cache MSIx info to a local structure (jsc#PED-11250)
  - commit 1e3b642
  - RDMA/bnxt_re: Refurbish CQ to NQ hash calculation (jsc#PED-11250)
  - commit 69d4b35
  - RDMA/bnxt_re: Refactor NQ allocation (jsc#PED-11250)
  - commit 72bfe4d
  - RDMA/bnxt_re: Fail probe early when not enough MSI-x vectors are reserved (jsc#PED-11250)
  - commit 2d18123
  - RDMA/bnxt_re: Add set_func_resources support for P5/P7 adapters (jsc#PED-11250)
  - commit cbb163e
  - RDMA/bnxt_re: Enhance RoCE SRIOV resource configuration design (jsc#PED-11250)
  - commit 8e2b0d1
  - RDMA/bnxt_re: Add debugfs hook in the driver (jsc#PED-11250)
  - commit 7df4e4c
  - RDMA/bnxt_re: Support raw data query for each resources (jsc#PED-11250)
  - commit b35c9fe
  - RDMA/bnxt_re: Add support for querying HW contexts (jsc#PED-11250)
  - commit 03d0ac2
  - RDMA/bnxt_re: Support driver specific data collection using rdma tool (jsc#PED-11250)
  - commit 301d4c8
  - RDMA/bnxt_re: Check cqe flags to know imm_data vs inv_irkey (jsc#PED-11250)
  - commit db78d83
  - RDMA/bnxt_re: Fix access flags for MR and QP modify (jsc#PED-11250)
  - commit 103dfc7
  - RDMA/bnxt_re: Add support for modify_device hook (jsc#PED-11250)
  - commit 2b5ef62
  - RDMA/bnxt_re: Add support for CQ rx coalescing (jsc#PED-11250)
  - commit 24d2ba3
  - RDMA/bnxt_re: Add support for optimized modify QP (jsc#PED-11250)
  - commit b0961e5
  - RDMA/core: Provide rdma_user_mmap_disassociate() to disassociate mmap pages (jsc#PED-11250)
  - commit 9dfd1ae
  - s390/dasd: fix redundant /proc/dasd* entries removal
    (bsc#1227694).
  - commit 3fe3c9b
  - softirq: Use a dedicated thread for timer wakeups on PREEMPT_RT
    (bsc#1234370).
  - timers: Use __raise_softirq_irqoff() to raise the softirq
    (bsc#1234370).
  - hrtimer: Use __raise_softirq_irqoff() to raise the softirq
    (bsc#1234370).
  - commit 648ddcf

++++ gpgme:

  - Update to 1.24.1:
    * Support the Kyber algorithm in key listings.
    * Allow building on some older Linux platforms.  [rM4a62318422]
    * Interface changes relative to the 1.24.0 release:
    GPGME_PK_KYBER                          NEW enum value.

++++ nfs-utils:

  - Require system-user-nobody for nfs-client as the statd user relies
    on `nogroup` from this package

++++ nvidia-open-driver-G06-signed:

  - Do not set %{?linux_make_arch} for running make modules/modules-install
  - supersedes 550.135.patch

++++ runc:

  - Update to runc v1.2.3. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.3>.

++++ selinux-policy:

  - Update to version 20240604+git388.baa001c6:
    * Label /run/libvirt/qemu/channel with virtqemud_var_run_t (bsc#1230961)

++++ socat:

  - Update to 1.8.0.2:
  - Security fix for readline.sh: arbitrary file overwrite via predictable /tmp
    directory (bsc#1225462 CVE-2024-54661)
  - Update to 1.8.0.1:
  - Bug fixes
  - UDP-SENDTO, UDPLITE-SENDTO, and IP-SENDTO addresses now select an IPv4
    address in case the server name resolves to both IPv4 and IPv6 addresses.
  - Guard applyopts_termios_value() with WITH_TERMIOS.
  - In some situations xioclose() was called nested what could cause hanging
    of OpenSSL in pthread_rwlock_wrlock().
  - socat 1.8.0.0 with addresses of type RECVFROM and option fork, where the
    second address failed to connect/open in the child process, entered a
    fork loop that was only stopped by FD exhaustion caused by FD leak.
  - socat 1.8.0.0 had an FD leak with addresses of type RECVFROM with fork.
  - With version 1.8.0.0, options ipv6-join-group and ipv6-join-source-group
    did not work.
  - IP-SENDTO and option pf (protocol-family) with protocol name (vs.numeric
    argument) failed with message: E retropts_int(): trailing garbage in
    numerical arg of option "protocol-family".
  - Fixed a possible buffer overrun with long log lines. In fact it does not
    write beyond end of buffer but lets pass excessive data to the write()
    function.
  - Reworked domain name resolution, centralized IPv4/IPv6 sorting.
  - Print warning about not checking CRLs in OpenSSL only in the first child
    process.
  - Features
  - Total inactivity timeout option -T 0 now means 0.0 seconds;
  - Changed socat-chain.sh, socat-mux.sh, and socat-broker.sh to work with
    older Socat versions.
  - socat-mux.sh and socat-broker.sh, when run as root, now internally use
    low (512..1023) UDP ports to increase security.
  - Added option ai-all (sets AI_ALL flag of getaddrinfo() resolver)
  - Socks5 now also allows syntax without socks port, and supports option
    socksport.
  - Removed 0004-udp-listen-bind4.patch (fixed by upstream socat-1.8.0.1).
  - Refreshed socat-test-without-tty.patch to match socat-1.8.0.1.

++++ sysuser-tools:

  - Directly check return value of systemd-sysusers

++++ ucode-amd:

  - Update to version 20241211 (git commit 163296523cd4):
    * rtl_nic: add firmware rtl8125d-2
    * linux-firmware: Update firmware file for Intel BlazarU core
    * QCA: Add Bluetooth nvm files for WCN785x
    * QCA: Update Bluetooth WCN785x firmware to 2.0.0-00515-2

------------------------------------------------------------------
------------------  2024-12-10  -  Dec 10 2024  -------------------
------------------------------------------------------------------

++++ Leap-Micro-release:

  - automatically generated by openSUSE-release-tools/pkglistgen

++++ python-kiwi:

  - Drop /dev/pts from bind mount locations
    This has created havoc in the Fedora build environments by
    fully unmounting /dev/pts and breaking the builders for
    subsquent tasks.
    This is a partial revert of commit daf1323c5ded7e4e7783205f5e30457b40eb322f.

++++ kernel-default:

  - config: remove unsupported configs
  - commit 1752d05
  - s390/entry: Mark IRQ entries to fix stack depot warnings
    (git-fixes bsc#1234356).
  - commit c8209d6
  - config: rename x86_64 and arm64 default and debug config files
    Move default to rt and debug to rt_debug, adjusting CONFIG_LOCALVERSION
    accordingly. No other changes.
  - commit 5e72780
  - rpm/config.sh: Specify RT variant and livepatching
  - commit daf200f
  - s390/pci: Fix potential double remove of hotplug slot (git-fixes
    bsc#1234354).
  - commit 7049f18
  - s390/vfio-ap: Remove gmap_convert_to_secure() from vfio_ap_ops
    (git-fixes bsc#1234353).
  - commit 474fbfd
  - s390/stacktrace: Use break instead of return statement
    (git-fixes bsc#1234352).
  - commit dae6da4
  - s390/iucv: MSG_PEEK causes memory leak in iucv_sock_destruct()
    (git-fixes bsc#1234351).
  - commit ac7d642
  - iommu/s390: Implement blocking domain (git-fixes bsc#1234350).
  - commit 6b9a77b
  - s390/syscalls: Avoid creation of arch/arch/ directory (git-fixes
    bsc#1234349).
  - commit 1f0d2c0
  - s390/cpum_sf: Fix and protect memory allocation of SDBs with
    mutex (git-fixes bsc#1234348).
  - commit 444f041
  - s390/pageattr: Implement missing kernel_page_present()
    (git-fixes bsc#1234347).
  - commit 3d52939
  - s390/cio: Do not unregister the subchannel based on DNV
    (git-fixes bsc#1234346).
  - commit 4347702
  - s390/facilities: Fix warning about shadow of global variable
    (git-fixes bsc#1234345).
  - commit 02f0405
  - drm/amdgpu: fix usage slab after free (stable-fixes).
  - drm/amd/pm: Remove arcturus min power limit (stable-fixes).
  - drm/amd/pm: skip setting the power source on smu v14.0.2/3
    (stable-fixes).
  - drm/amd/pm: disable pcie speed switching on Intel platform
    for smu v14.0.2/3 (stable-fixes).
  - drm/amdkfd: Use the correct wptr size (stable-fixes).
  - drm/amdgpu/pm: add gen5 display to the user on smu v14.0.2/3
    (stable-fixes).
  - drm/amd: Fix initialization mistake for NBIO 7.11 devices
    (stable-fixes).
  - drm/amd/display: Remove PIPE_DTO_SRC_SEL programming from
    set_dtbclk_dto (stable-fixes).
  - drm/amd/display: Fix handling of plane refcount (stable-fixes).
  - drm/amd/display: update pipe selection policy to check head pipe
    (stable-fixes).
  - drm/amd/pm: update current_socclk and current_uclk in
    gpu_metrics on smu v13.0.7 (stable-fixes).
  - PCI: imx6: Fix suspend/resume support on i.MX6QDL
    (stable-fixes).
  - drm/etnaviv: flush shader L1 cache after user commandstream
    (stable-fixes).
  - Revert "drm/xe/xe_guc_ads: save/restore OA registers and
    allowlist regs" (git-fixes).
  - drm/xe/xe_guc_ads: save/restore OA registers and allowlist regs
    (git-fixes).
  - commit fd87388
  - fcntl: make F_DUPFD_QUERY associative (git-fixes).
  - commit be385fd
  - fs: support relative paths with FSCONFIG_SET_STRING (git-fixes).
  - commit ef5bd8a
  - hostfs: Fix the NULL vs IS_ERR() bug for __filemap_get_folio()
    (git-fixes).
  - commit 5fd3bb3
  - erofs: handle NONHEAD !delta[1] lclusters gracefully
    (git-fixes).
  - commit 813ea9e
  - erofs: fix blksize < PAGE_SIZE for file-backed mounts
    (git-fixes).
  - commit b284b3f
  - erofs: fix file-backed mounts over FUSE (git-fixes).
  - commit 7bf2dba
  - nfs/blocklayout: Limit repeat device registration on failure
    (git-fixes).
  - commit 5b1e7a2
  - nfs/blocklayout: Don't attempt unregister for invalid block
    device (git-fixes).
  - commit 8ad811d
  - sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket
    (git-fixes).
  - commit bd7fa6f
  - SUNRPC: timeout and cancel TLS handshake with -ETIMEDOUT
    (git-fixes).
  - commit ee8bee6
  - sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
    (git-fixes).
  - commit 897270b
  - nfs: ignore SB_RDONLY when mounting nfs (git-fixes).
  - commit 99730eb
  - Revert "nfs: don't reuse partially completed requests in
    nfs_lock_and_join_requests" (git-fixes).
  - commit 890cbd2
  - Revert "fs: nfs: fix missing refcnt by replacing
    folio_set_private by folio_attach_private" (git-fixes).
  - commit e370dcb
  - nfs/localio: must clear res.replen in nfs_local_read_done
    (git-fixes).
  - commit cad5bd8
  - NFSv4.0: Fix a use-after-free problem in the asynchronous open()
    (git-fixes).
  - commit d12d418
  - nfs_common: must not hold RCU while calling nfsd_file_put_local
    (git-fixes).
  - commit 5734a19
  - NFSD: Fix nfsd4_shutdown_copy() (git-fixes).
  - commit ebfeeee
  - svcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init()
    (git-fixes).
  - commit 329fe63
  - nfsd: release svc_expkey/svc_export with rcu_work (git-fixes).
  - commit 97e3dac
  - nfsd: make sure exp active before svc_export_show (git-fixes).
  - commit a104268
  - NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
    (git-fixes).
  - commit 7f91920
  - NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
    (git-fixes).
  - commit aaee8d9
  - NFSD: Remove a never-true comparison (git-fixes).
  - commit c224daa
  - nfsd: drop inode parameter from nfsd4_change_attribute()
    (git-fixes).
  - commit dddb56b
  - svcrdma: Address an integer overflow (git-fixes).
  - commit a27962f

++++ kernel-rt:

  - config: remove unsupported configs
  - commit 1752d05
  - s390/entry: Mark IRQ entries to fix stack depot warnings
    (git-fixes bsc#1234356).
  - commit c8209d6
  - config: rename x86_64 and arm64 default and debug config files
    Move default to rt and debug to rt_debug, adjusting CONFIG_LOCALVERSION
    accordingly. No other changes.
  - commit 5e72780
  - rpm/config.sh: Specify RT variant and livepatching
  - commit daf200f
  - s390/pci: Fix potential double remove of hotplug slot (git-fixes
    bsc#1234354).
  - commit 7049f18
  - s390/vfio-ap: Remove gmap_convert_to_secure() from vfio_ap_ops
    (git-fixes bsc#1234353).
  - commit 474fbfd
  - s390/stacktrace: Use break instead of return statement
    (git-fixes bsc#1234352).
  - commit dae6da4
  - s390/iucv: MSG_PEEK causes memory leak in iucv_sock_destruct()
    (git-fixes bsc#1234351).
  - commit ac7d642
  - iommu/s390: Implement blocking domain (git-fixes bsc#1234350).
  - commit 6b9a77b
  - s390/syscalls: Avoid creation of arch/arch/ directory (git-fixes
    bsc#1234349).
  - commit 1f0d2c0
  - s390/cpum_sf: Fix and protect memory allocation of SDBs with
    mutex (git-fixes bsc#1234348).
  - commit 444f041
  - s390/pageattr: Implement missing kernel_page_present()
    (git-fixes bsc#1234347).
  - commit 3d52939
  - s390/cio: Do not unregister the subchannel based on DNV
    (git-fixes bsc#1234346).
  - commit 4347702
  - s390/facilities: Fix warning about shadow of global variable
    (git-fixes bsc#1234345).
  - commit 02f0405
  - drm/amdgpu: fix usage slab after free (stable-fixes).
  - drm/amd/pm: Remove arcturus min power limit (stable-fixes).
  - drm/amd/pm: skip setting the power source on smu v14.0.2/3
    (stable-fixes).
  - drm/amd/pm: disable pcie speed switching on Intel platform
    for smu v14.0.2/3 (stable-fixes).
  - drm/amdkfd: Use the correct wptr size (stable-fixes).
  - drm/amdgpu/pm: add gen5 display to the user on smu v14.0.2/3
    (stable-fixes).
  - drm/amd: Fix initialization mistake for NBIO 7.11 devices
    (stable-fixes).
  - drm/amd/display: Remove PIPE_DTO_SRC_SEL programming from
    set_dtbclk_dto (stable-fixes).
  - drm/amd/display: Fix handling of plane refcount (stable-fixes).
  - drm/amd/display: update pipe selection policy to check head pipe
    (stable-fixes).
  - drm/amd/pm: update current_socclk and current_uclk in
    gpu_metrics on smu v13.0.7 (stable-fixes).
  - PCI: imx6: Fix suspend/resume support on i.MX6QDL
    (stable-fixes).
  - drm/etnaviv: flush shader L1 cache after user commandstream
    (stable-fixes).
  - Revert "drm/xe/xe_guc_ads: save/restore OA registers and
    allowlist regs" (git-fixes).
  - drm/xe/xe_guc_ads: save/restore OA registers and allowlist regs
    (git-fixes).
  - commit fd87388
  - fcntl: make F_DUPFD_QUERY associative (git-fixes).
  - commit be385fd
  - fs: support relative paths with FSCONFIG_SET_STRING (git-fixes).
  - commit ef5bd8a
  - hostfs: Fix the NULL vs IS_ERR() bug for __filemap_get_folio()
    (git-fixes).
  - commit 5fd3bb3
  - erofs: handle NONHEAD !delta[1] lclusters gracefully
    (git-fixes).
  - commit 813ea9e
  - erofs: fix blksize < PAGE_SIZE for file-backed mounts
    (git-fixes).
  - commit b284b3f
  - erofs: fix file-backed mounts over FUSE (git-fixes).
  - commit 7bf2dba
  - nfs/blocklayout: Limit repeat device registration on failure
    (git-fixes).
  - commit 5b1e7a2
  - nfs/blocklayout: Don't attempt unregister for invalid block
    device (git-fixes).
  - commit 8ad811d
  - sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket
    (git-fixes).
  - commit bd7fa6f
  - SUNRPC: timeout and cancel TLS handshake with -ETIMEDOUT
    (git-fixes).
  - commit ee8bee6
  - sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport
    (git-fixes).
  - commit 897270b
  - nfs: ignore SB_RDONLY when mounting nfs (git-fixes).
  - commit 99730eb
  - Revert "nfs: don't reuse partially completed requests in
    nfs_lock_and_join_requests" (git-fixes).
  - commit 890cbd2
  - Revert "fs: nfs: fix missing refcnt by replacing
    folio_set_private by folio_attach_private" (git-fixes).
  - commit e370dcb
  - nfs/localio: must clear res.replen in nfs_local_read_done
    (git-fixes).
  - commit cad5bd8
  - NFSv4.0: Fix a use-after-free problem in the asynchronous open()
    (git-fixes).
  - commit d12d418
  - nfs_common: must not hold RCU while calling nfsd_file_put_local
    (git-fixes).
  - commit 5734a19
  - NFSD: Fix nfsd4_shutdown_copy() (git-fixes).
  - commit ebfeeee
  - svcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init()
    (git-fixes).
  - commit 329fe63
  - nfsd: release svc_expkey/svc_export with rcu_work (git-fixes).
  - commit 97e3dac
  - nfsd: make sure exp active before svc_export_show (git-fixes).
  - commit a104268
  - NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir()
    (git-fixes).
  - commit 7f91920
  - NFSD: Prevent NULL dereference in nfsd4_process_cb_update()
    (git-fixes).
  - commit aaee8d9
  - NFSD: Remove a never-true comparison (git-fixes).
  - commit c224daa
  - nfsd: drop inode parameter from nfsd4_change_attribute()
    (git-fixes).
  - commit dddb56b
  - svcrdma: Address an integer overflow (git-fixes).
  - commit a27962f

++++ json-glib:

  - Update to version 1.10.6:
    + Allow single quoted strings when running in non-strict mode.
    + Allow escaped characters when running in non-strict mode.
    + Add missing nullable annotation.

++++ netavark:

  - Update to version 1.13.1:
    * Release v1.13.1
    * Release notes for v1.13.1
    * setup: on av errors cleanup again
    * nftables: add daddr match to port forward jump rule

++++ python-argcomplete:

  - Update to version 3.5.2
    * Fix _parse_known_args monkeypatching. This fix is required to restore
    compatibility with Python 3.12.8 and 3.13.1.

++++ qemu:

  - Fix bsc#1232712. The problem must be addressed upstream. This is
    only a temporary measure, that should be reverted as soon as
    possible:
    * Revert "ui/curses: Do not use console_select()" (bsc#1232712)
    * Revert "hw/xen: Register framebuffer backend via xen_backend_init()" (bsc#1232712)

++++ suse-module-tools:

    * rpm-script: create dangling symlinks in kiwi environments
    (bsc#1234275)

------------------------------------------------------------------
------------------  2024-12-9  -  Dec 9 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - aarch64: disable build of etnaviv driver on sle15-sp7 due to
    python3-pycparser >= 2.20 not available
  - don't apply patches of previous changelog for s390x; Mesa 24.1.7
    doesn't suffer from this issue, only Mesa 24.3.1 ...

++++ Mesa-drivers:

  - aarch64: disable build of etnaviv driver on sle15-sp7 due to
    python3-pycparser >= 2.20 not available
  - don't apply patches of previous changelog for s390x; Mesa 24.1.7
    doesn't suffer from this issue, only Mesa 24.3.1 ...

++++ python-kiwi:

  - Fixed unit test

++++ glib2:

  - Update to version 2.82.3:
    + Fix compatibility with tzdata 2024b
    + Bugs fixed:
  - Test regressions with tzdata 2024b
  - gdatetime test: Do not assume PST8PDT was always exactly
  - 8/-7
  - glib: Don't require GLIB_DOMAIN to be a NUL-terminated string
  - gio: Fix GFileEnumerator leaks in gio tools
  - macos: Remove extraous space from type identifier
  - refstring: Fix race between releasing and re-acquiring an
    interned GRefString
  - appmonitor: Fix warning building test
  - grefstring: Mark a variable as potentially unused
  - gdbus: Fix leak of method invocation when registering an
    object with closures

++++ gstreamer:

  - Update to version 1.24.10:
    + Highlighted bugfixes:
  - More than 40 security fixes across a wide range of elements
    following an audit by the GitHub Security Lab, including the
    MP4, Matroska, Ogg and WAV demuxers, subtitle parsers, image
    decoders, audio decoders and the id3v2 tag parser.
  - avviddec: Fix regression that could trigger assertions about
    width/height mismatches.
  - appsink and appsrc fixes.
  - closed caption handling fixes.
  - decodebin3 and urisourcebin fixes.
  - glupload: dmabuf: Fix emulated tiled import.
  - level: fix LevelMeta values outside of the stated range.
  - mpegtsmux, flvmux: fix potential busy looping with high cpu
    usage in live mode.
  - pipeline dot file graph generation improvements.
  - qt(6): fix criticals with multiple qml(6)gl{src,sink}.
  - rtspsrc: Optionally timestamp RTP packets with their receive
    times in TCP/HTTP mode to enable clock drift handling.
  - splitmuxsrc: reduce number of file descriptors used.
  - systemclock: locking order fixes.
  - v4l2: fix possible v4l2videodec deadlock on shutdown; 8-bit
    bayer format fixes.
  - x265: Fix build with libx265 version >= 4.1 after
    masteringDisplayColorVolume API change.
  - macOS: fix rendering artifacts in retina displays, plus ptp
    clock fixes.
  - cargo: Default to thin lto for the release profile (for
    faster builds with lower memory requirements).
  - Various bug fixes, build fixes, memory leak fixes, and other
    stability and reliability improvements.
  - Updated translations.
    + gstreamer:
  - allocator: Avoid integer overflow when allocating sysmem and
    avoid integer overflow in qtdemux theora extension parsing
    (boo#1234449 CVE-2024-47606).
  - deviceprovider: fix leaking hidden providers.
  - gstreamer: prefix debug dot node names to prevent splitting.
  - pad: Never push sticky events in response to a FLUSH_STOP.
  - systemclock: Fix lock order violation and some cleanup.
  - utils: improve gst_util_ceil_log2().
  - ptp: use ip_mreq instead of ip_mreqn for macos.
  - tracers: unlock leaks tracer if already tracking.

++++ gstreamer-plugins-base:

  - Update to version 1.24.10:
    + appsink: fix timeout logic for gst_app_sink_try_pull_sample().
    + appsrc: Fix use-after-free when making buffer / buffer-lists
    writable.
    + audiostreamalign: Don't report disconts for every buffer if
    alignment-threshold is too small.
    + decodebin3: Unify collection switching checks.
    + discoverer:
  - Don't print channel layout for more than 64 channels
    (boo#1234453 CVE-2024-47600).
  - Make sure the missing elements details array is
    NULL-terminated in a thread-safe way.
  - Fix segfault in race condition adding a new uri.
    + id3v2: Don't try parsing extended header if not enough data is
    available (boo#1234460 CVE-2024-47542).
    + glupload: dmabuf: Fix emulated tiled import.
    + gl:
  - cocoa: fix rendering artifacts in retina displays.
  - meson: Don't use libdrm_dep in cc.has_header().
    + oggstream: fix invalid ogg_packet->packet accesses, address
    invalid writes CVE (boo#1234456 CVE-2024-47615).
    + opusdec: Set at most 64 channels to NONE position (boo#1234455
    CVE-2024-47607).
    + playbin: Fix caps leak in get_n_common_capsfeatures().
    + playbin3: ERROR when setting new HLS URI with instant-uri=true.
    + sdp: Add debug categories for message and mikey modules.
    + ssaparse: Search for closing brace after opening brace.
    + splitmuxsrc: Convert part reader to a bin with a non-async bus.
    + subparse: Check for NULL return of strchr() when parsing LRC
    subtitles (boo#1234450 CVE-2024-47835).
    + streamsynchronizer: Only send GAP events out of source pads.
    + urisourcebin: Also use event probe for HLS use-cases.
    + video-converter: Set TIME segment format on appsrc.
    + vorbisdec: Set at most 64 channels to NONE position
    (boo#1234415 CVE-2024-47538).
    + Translation for gst-plugins-base 1.24.0 not sync-ed with
    Translation Project.
    + Updated translations.

++++ kernel-default:

  - xfs: remove unknown compat feature check in superblock write
    validation (git-fixes).
  - commit 03498b6
  - xfs: fix chown with rt quota (git-fixes).
  - commit df1beba
  - xfs: fix simplify extent lookup in xfs_can_free_eofblocks
    (git-fixes).
  - commit 83617d6
  - xfs: sb_spino_align is not verified (git-fixes).
  - commit 1d6b422
  - dlm: fix dlm_recover_members refcount on error (git-fixes).
  - commit 32f05df
  - dlm: fix swapped args sb_flags vs sb_status (git-fixes).
  - commit 8a26d75
  - exfat: fix file being changed by unaligned direct write
    (git-fixes).
  - commit 5ecc480
  - config: remove all unsupported filesystems (jsc#PED-3637)
  - supported.conf:
  - Update config files.
  - commit ef4af57
  - Update
    patches.suse/initramfs-avoid-filename-buffer-overrun.patch
    (CVE-2024-53142 bsc#1232436).
  - commit b2d6f7d
  - sched/numa: fix memory leak due to the overwritten
    vma->numab_state (git fixes (sched/numa)).
  - commit ebb11c8
  - irqchip/stm32mp-exti: CONFIG_STM32MP_EXTI should not default
    to y when compile-testing (git-fixes).
  - iio: magnetometer: yas530: use signed integer type for clamp
    limits (git-fixes).
  - scatterlist: fix incorrect func name in kernel-doc (git-fixes).
  - kasan: make report_lock a raw spinlock (git-fixes).
  - commit 5b25167

++++ kernel-rt:

  - xfs: remove unknown compat feature check in superblock write
    validation (git-fixes).
  - commit 03498b6
  - xfs: fix chown with rt quota (git-fixes).
  - commit df1beba
  - xfs: fix simplify extent lookup in xfs_can_free_eofblocks
    (git-fixes).
  - commit 83617d6
  - xfs: sb_spino_align is not verified (git-fixes).
  - commit 1d6b422
  - dlm: fix dlm_recover_members refcount on error (git-fixes).
  - commit 32f05df
  - dlm: fix swapped args sb_flags vs sb_status (git-fixes).
  - commit 8a26d75
  - exfat: fix file being changed by unaligned direct write
    (git-fixes).
  - commit 5ecc480
  - config: remove all unsupported filesystems (jsc#PED-3637)
  - supported.conf:
  - Update config files.
  - commit ef4af57
  - Update
    patches.suse/initramfs-avoid-filename-buffer-overrun.patch
    (CVE-2024-53142 bsc#1232436).
  - commit b2d6f7d
  - sched/numa: fix memory leak due to the overwritten
    vma->numab_state (git fixes (sched/numa)).
  - commit ebb11c8
  - irqchip/stm32mp-exti: CONFIG_STM32MP_EXTI should not default
    to y when compile-testing (git-fixes).
  - iio: magnetometer: yas530: use signed integer type for clamp
    limits (git-fixes).
  - scatterlist: fix incorrect func name in kernel-doc (git-fixes).
  - kasan: make report_lock a raw spinlock (git-fixes).
  - commit 5b25167

++++ libcap:

  - Disable psx_test and b219174 tests in qemu emulation

++++ libeconf:

  - Update to version 0.7.5:
    * Removed PATH_MAX (Issue #220)
    * Add ROOT_PREFIX as option to replace TESTSDIR hack
    * CI: valgrind doesn't work together with sanitizers
    * econf_readConfig: don't allocate econf_file in error case
    * tests: use cleanup to free key_file for some tests
    * libeconf: don't allocate array from size 0
    * libeconf: fix use of uninitialized stat result if file does not exist
    * econftool: dynamically allocate xdg_config_dir
    * Disable clang <= 17, enable valgrind
    * Disable whitespace check
    * Disable deprecation warning for econftool and example
    * Add new CI with different compilers and valgrind
    * Test econf_readConfig()
    * Disable deprecation warning for tests
    * Implement econf_*freep functions for automatic cleanup
    * Cleanup *free functions

++++ ncurses:

  - Add ncurses patch 20241207
    + strict compiler-warning fixes for upcoming gcc15
  - Port patches means same fixes as above
    * FORTIFY_SOURCE_3-fix.patch
    * ncurses-6.4.dif

++++ sqlite3:

  - Update to release 3.47.2:
    * Fix a problem in text-to-floating-point conversion that affects
    text values where the first 16 significant digits are
    '1844674407370955'. This issue was introduced in 3.47.0 and
    only arises on x64 and i386 hardware.
    * Other minor bug fixes.
  - Enable the session extension, because NodeJS 22 needs it.

++++ libzypp:

  - Url query part: `=` is a safe char in value (bsc#1234304)
  - RpmDb: Recognize rpmdb.sqlite as database file (#593)
  - Fix typo (fixes #592)
  - cmake: check location of fcgi header and adjust include
    accordingly. On Debian and derivatives the fcgi headers
    are not stored in a fastcgi/ subdirectory.(#590)
  - version 17.35.15 (35)

++++ openSUSE-repos-LeapMicro:

  - Disable Leap flavor building on Leap Micro 6.1+
    which newly contains sle_version
  - Make new symlink and zypper addservice in postrans
    * To ensure that addition of service and symlink creation
    is executed only after the postun of old package.
    Otherwise we end up with no service and no repoindex symlink.
    * This supports migration from LeapMicro to MicroOS
    * Fixes gh#openSUSE/opensuse-migration-tool#17

++++ opensuse-migration-tool:

  - Update to version 20241209.76c6ef8:
    * Update README.md
    * Mention current system in the migration dialog
    * Allow migration from Tumbleweed to Slowroll

++++ sysuser-tools:

  - Drop SLE15 support and remove disable-systemd-sysusers.patch
  - sysuser-shadow: remove systemd 238 dependency, this does not
    work in a single RPM transaction [bsc#1234277]. Call
    systemd-sysuser instead again without --replace.

++++ xkeyboard-config:

  - python-3.11.patch/buildrequire python311-base
    * fixes build on Leap 15.6 and sle15-sp7

------------------------------------------------------------------
------------------  2024-12-8  -  Dec 8 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - 0001-dri-don-t-fetch-X11-modifiers-if-we-don-t-support-th.patch
    0002-egl-wayland-only-supply-LINEAR-modifier-when-support.patch
    0003-egl-wayland-fallback-to-implicit-modifiers-if-advert.patch
    * fixes mesa 24.3.1 gallium crash/segfault on GPUs without
    format modifiers (mesa issue#12253, mesa MR#32535, boo#1234302)

++++ Mesa-drivers:

  - 0001-dri-don-t-fetch-X11-modifiers-if-we-don-t-support-th.patch
    0002-egl-wayland-only-supply-LINEAR-modifier-when-support.patch
    0003-egl-wayland-fallback-to-implicit-modifiers-if-advert.patch
    * fixes mesa 24.3.1 gallium crash/segfault on GPUs without
    format modifiers (mesa issue#12253, mesa MR#32535, boo#1234302)

++++ python-kiwi:

  - Don't take ghost files into account
    When creating the system files information do not
    take ghost files and artifact files into account

++++ grub2:

  - Update PowerPC SBAT patches to upstream (bsc#1233730)
    * 0007-grub-mkimage-Create-new-ELF-note-for-SBAT.patch
    * 0008-grub-mkimage-Add-SBAT-metadata-into-ELF-note-for-Pow.patch
  - Replaced patches
    * 0007-mkimage-create-new-ELF-Note-for-SBAT.patch
    * 0008-mkimage-adding-sbat-data-into-sbat-ELF-Note-on-power.patch

++++ kernel-firmware-all:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-amdgpu:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-ath10k:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-ath11k:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-ath12k:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-atheros:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-bluetooth:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-bnx2:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-brcm:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-chelsio:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-dpaa2:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-i915:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-intel:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-iwlwifi:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-liquidio:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-marvell:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-media:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-mediatek:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-mellanox:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-mwifiex:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-network:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-nfp:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-nvidia:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-platform:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-prestera:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-qcom:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-qlogic:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-radeon:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-realtek:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-serial:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-sound:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-ti:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-ueagle:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ kernel-firmware-usb-network:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

++++ ucode-amd:

  - Update to version 20241206 (git commit 209c18b0e7cd):
    * amdgpu: update dmcub 0.0.246.0 firmware
    * Add top level license file.

------------------------------------------------------------------
------------------  2024-12-7  -  Dec 7 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ASoC: Intel: avs: da7219: Remove suspend_pre() and resume_post()
    (stable-fixes).
  - ALSA: hda/realtek: Fix spelling mistake "Firelfy" -> "Firefly"
    (git-fixes).
  - ALSA: hda/realtek: fix micmute LEDs don't work on HP Laptops
    (stable-fixes).
  - ALSA: usb-audio: Add extra PID for RME Digiface USB
    (stable-fixes).
  - ALSA: hda/realtek: Add support for Samsung Galaxy Book3 360
    (NP730QFG) (stable-fixes).
  - ALSA: hda/realtek: Enable mute and micmute LED on HP ProBook
    430 G8 (stable-fixes).
  - ALSA: usb-audio: add mixer mapping for Corsair HS80
    (stable-fixes).
  - ALSA: ump: Shut up truncated string warning (git-fixes).
  - ALSA: sh: Use standard helper for buffer accesses
    (stable-fixes).
  - ALSA: hda/conexant: fix Z60MR100 startup pop issue
    (stable-fixes).
  - ALSA: ump: Update legacy substream names upon FB info update
    (stable-fixes).
  - ALSA: ump: Indicate the inactive group in legacy substream names
    (stable-fixes).
  - ALSA: ump: Don't open legacy substream for an inactive group
    (stable-fixes).
  - commit 9157c44
  - drm/v3d: Enable Performance Counters before clearing them
    (git-fixes).
  - drm/dp_mst: Fix resetting msg rx state after topology removal
    (git-fixes).
  - drm/sti: Add __iomem for mixer_dbg_mxn's parameter (git-fixes).
  - dma-fence: Use kernel's sort for merging fences (git-fixes).
  - dma-fence: Fix reference leak on fence merge failure path
    (git-fixes).
  - ASoC: mediatek: mt8188-mt6359: Remove hardcoded dmic codec
    (git-fixes).
  - ASoC: SOF: ipc3-topology: fix resource leaks in
    sof_ipc3_widget_setup_comp_dai() (git-fixes).
  - ALSA: usb-audio: Fix a DMA to stack memory bug (git-fixes).
  - ALSA: hda/tas2781: Fix error code tas2781_read_acpi()
    (git-fixes).
  - ALSA: usb-audio: Notify xrun for low-latency mode (git-fixes).
  - ALSA: seq: ump: Fix seq port updates per FB info notify
    (git-fixes).
  - regmap: detach regmap from dev on regmap_exit (git-fixes).
  - spi: mpc52xx: Add cancel_work_sync before module remove
    (git-fixes).
  - mmc: core: Further prevent card detect during shutdown
    (git-fixes).
  - commit 9884b2e

++++ kernel-rt:

  - ASoC: Intel: avs: da7219: Remove suspend_pre() and resume_post()
    (stable-fixes).
  - ALSA: hda/realtek: Fix spelling mistake "Firelfy" -> "Firefly"
    (git-fixes).
  - ALSA: hda/realtek: fix micmute LEDs don't work on HP Laptops
    (stable-fixes).
  - ALSA: usb-audio: Add extra PID for RME Digiface USB
    (stable-fixes).
  - ALSA: hda/realtek: Add support for Samsung Galaxy Book3 360
    (NP730QFG) (stable-fixes).
  - ALSA: hda/realtek: Enable mute and micmute LED on HP ProBook
    430 G8 (stable-fixes).
  - ALSA: usb-audio: add mixer mapping for Corsair HS80
    (stable-fixes).
  - ALSA: ump: Shut up truncated string warning (git-fixes).
  - ALSA: sh: Use standard helper for buffer accesses
    (stable-fixes).
  - ALSA: hda/conexant: fix Z60MR100 startup pop issue
    (stable-fixes).
  - ALSA: ump: Update legacy substream names upon FB info update
    (stable-fixes).
  - ALSA: ump: Indicate the inactive group in legacy substream names
    (stable-fixes).
  - ALSA: ump: Don't open legacy substream for an inactive group
    (stable-fixes).
  - commit 9157c44
  - drm/v3d: Enable Performance Counters before clearing them
    (git-fixes).
  - drm/dp_mst: Fix resetting msg rx state after topology removal
    (git-fixes).
  - drm/sti: Add __iomem for mixer_dbg_mxn's parameter (git-fixes).
  - dma-fence: Use kernel's sort for merging fences (git-fixes).
  - dma-fence: Fix reference leak on fence merge failure path
    (git-fixes).
  - ASoC: mediatek: mt8188-mt6359: Remove hardcoded dmic codec
    (git-fixes).
  - ASoC: SOF: ipc3-topology: fix resource leaks in
    sof_ipc3_widget_setup_comp_dai() (git-fixes).
  - ALSA: usb-audio: Fix a DMA to stack memory bug (git-fixes).
  - ALSA: hda/tas2781: Fix error code tas2781_read_acpi()
    (git-fixes).
  - ALSA: usb-audio: Notify xrun for low-latency mode (git-fixes).
  - ALSA: seq: ump: Fix seq port updates per FB info notify
    (git-fixes).
  - regmap: detach regmap from dev on regmap_exit (git-fixes).
  - spi: mpc52xx: Add cancel_work_sync before module remove
    (git-fixes).
  - mmc: core: Further prevent card detect during shutdown
    (git-fixes).
  - commit 9884b2e

++++ mcelog:

  - Update to version 202:
    * mcelog: Wire up model-specific decoding for Clearwater Forest
    * mcelog: New model number for Clearwater Forest
  - jsc#PED-10052

++++ python-httpx:

  - Update to 0.28.1
    * Fix SSL case where verify=False together with client side
    certificates.
  - Release 0.28.0
    [#]# Deprecations:
    * We are working towards a simplified SSL configuration API.
    * For users of the standard verify=True or verify=False cases, or
    verify=<ssl_context> case this should require no changes. The
    following cases have been deprecated...
  - The verify argument as a string argument is now deprecated
    and will raise warnings.
  - The cert argument is now deprecated and will raise warnings.
    * Our revised SSL documentation covers how to implement the same
    behaviour with a more constrained API.
    [#]# The following changes are also included:
    * The deprecated proxies argument has now been removed.
    * The deprecated app argument has now been removed.
    * JSON request bodies use a compact representation. (#3363)
    * Review URL percent escape sets, based on WHATWG spec. (#3371,
    [#3373])
    * Ensure certifi and httpcore are only imported if required.
    (#3377)
    * Treat socks5h as a valid proxy scheme. (#3178)
    * Cleanup Request() method signature in line with
    client.request() and httpx.request(). (#3378)

++++ swtpm:

  - Fix build without %check (boo#1227364)

++++ vim:

  - update to 9.1.0908
  - refresh vim-7.3-mktemp_tutor.patch
    * 9.1.0908: not possible to configure :messages
    * 9.1.0907: printoptions:portrait does not change postscript Orientation
    * runtime(doc): Add vietnamese.txt to helps main TOC
    * 9.1.0906: filetype: Nvidia PTX files are not recognized
    * runtime(doc): updated version9.txt with changes from v9.1.0905
    * 9.1.0905: Missing information in CompleteDone event
    * 9.1.0904: Vim9: copy-paste error in class_defining_member()
    * 9.1.0903: potential overflow in spell_soundfold_wsal()
    * runtime(netrw): do not detach when launching external programs in gvim
    * runtime(doc): make tag alignment more consistent in filetype.txt
    * runtime(doc): fix wrong syntax and style of vietnamese.txt
    * translation(it): update Italian manpage for vimtutor
    * runtime(lua): add optional lua function folding
    * Filelist: include translations for Chapter 2 tutor
    * translation(vi): Update Vietnamese translation
    * runtime(doc): include vietnamese.txt
    * runtime(tutor): fix another typo in tutor2
    * runtime(doc): fix typo in vimtutor manpage
    * translation(it): update Italian manpage for vimtutor
    * translation(it): include Italian version of tutor chapter 2
    * runtime(tutor): regenerated some translated tutor1 files
    * runtime(tutor): fix typo in Chapter 2
    * 9.1.0902: filetype: Conda configuration files are not recognized
    * runtime(doc): Tweak documentation style a bit
    * runtime(tutor): update the tutor files and re-number the chapters
    * runtime(tutor): Update the makefiles for tutor1 and tutor2 files
    * 9.1.0901: MS-Windows: vimtutor batch script can be improved
    * runtime(doc): remove buffer-local completeopt todo item
    * 9.1.0900: Vim9: digraph_getlist() does not accept bool arg
    * runtime(typst): provide a formatlistpat in ftplugin
    * runtime(doc): Update documentation for "noselect" in 'completeopt'
    * 9.1.0899: default for 'backspace' can be set in C code
    * runtime(helptoc): reload cached g:helptoc.shell_prompt when starting toc
    * translation(ru): Updated messages translation
    * 9.1.0898: runtime(compiler): pytest compiler not included
    * 9.1.0897: filetype: pyrex files are not detected
    * runtime(compiler): update eslint compiler
    * 9.1.0896: completion list wrong after v9.1.0891
    * runtime(doc): document changed default value for 'history'
    * 9.1.0895: default history value is too small
    * 9.1.0894: No test for what the spotbug compiler parses
    * 9.1.0893: No test that undofile format does not regress
    * translation(de): update German manpages
    * runtime(compiler): include spotbugs Java linter
    * 9.1.0892: the max value of 'tabheight' is limited by other tabpages
    * runtime(po): remove poDiffOld/New, add po-format flags to syntax file
    * 9.1.0891: building the completion list array is inefficient
    * patch 9.1.0890: %! item not allowed for 'rulerformat'
    * runtime(gzip): load undofile if there exists one
    * 9.1.0889: Possible unnecessary redraw after adding/deleting lines
    * 9.1.0888: leftcol property not available in getwininfo()
    * 9.1.0887: Wrong expression in sign.c
    * 9.1.0886: filetype: debian control file not detected
    * runtime(c3): include c3 filetype plugin
    * 9.1.0885: style of sign.c can be improved
    * 9.1.0884: gcc warns about uninitialized variable
    * runtime(apache): Update syntax directives for apache server 2.4.62
    * translation(ru): updated vimtutor translation, update MAINTAINERS file
    * 9.1.0883: message history cleanup is missing some tests
    * runtime(doc): Expand docs on :! vs. :term
    * runtime(netrw): Fixing powershell execution issues on Windows
    * 9.1.0882: too many strlen() calls in insexpand.c
    * 9.1.0881: GUI: message dialog may not get focus
    * runtime(netrw): update netrw's decompress logic
    * runtime(apache): Update syntax keyword definition
    * runtime(misc): add Italian LICENSE and (top-level) README file
    * 9.1.0880: filetype: C3 files are not recognized
    * runtime(doc): add helptag for :HelpToc command
    * 9.1.0879: source is not consistently formatted
    * Add clang-format config file
    * runtime(compiler): fix escaping of arguments passed to :CompilerSet
    * 9.1.0878: termdebug: cannot enable DEBUG mode
    * 9.1.0877: tests: missing test for termdebug + decimal signs
    * 9.1.0876: filetype: openCL files are not recognized
    * 9.1.0875: filetype: hyprlang detection can be improved
    * 9.1.0874: filetype: karel files are not detected
    * 9.1.0873: filetype: Vivado files are not recognized
    * 9.1.0872: No test for W23 message
    * 9.1.0871: getcellpixels() can be further improved
    * 9.1.0870: too many strlen() calls in eval.c
    * 9.1.0869: Problem: curswant not set on gm in folded line
    * 9.1.0868: the warning about missing clipboard can be improved
    * runtime(doc): Makefile does not clean up all temporary files
    * 9.1.0867: ins_compl_add() has too many args
    * editorconfig: don't trim trailing whitespaces in runtime/doc
    * translation(am): Remove duplicate keys in desktop files
    * runtime(doc): update helptags
    * runtime(filetype): remove duplicated *.org file pattern
    * runtime(cfg): only consider leading // as starting a comment
    * 9.1.0866: filetype: LLVM IR files are not recognized
    * 9.1.0865: filetype: org files are not recognized
    * 9.1.0864: message history is fixed to 200
    * 9.1.0863: getcellpixels() can be further improved
    * runtime(sh): better function support for bash/zsh in indent script
    * runtime(netrw): small fixes to netrw#BrowseX
    * 9.1.0862: 'wildmenu' not enabled by default in nocp mode
    * runtime(doc): update how to report issues for mac Vim
    * runtime(doc): mention option-backslash at :h CompilerSet
    * runtime(compiler): include a Java Maven compiler plugin
    * runtime(racket): update Racket runtime files
    * runtime(doc): improve indentation in examples for netrw-handler
    * runtime(doc): improve examples for netrw-handler functions
    * runtime(idris2): include filetype,indent+syntax plugins for (L)Idris2 + ipkg
    * runtime(doc): clarify the use of filters and external commands
    * 9.1.0861: Vim9: no runtime check for object member access of any var
    * runtime(compiler): update pylint linter
    * 9.1.0860: tests: mouse_shape tests use hard code sleep value
    * 9.1.0859: several problems with the GLVS plugin
    * 9.1.0858: Coverity complains about dead code
    * runtime(tar): Update tar.vim to support permissions
    * 9.1.0857: xxd: --- is incorrectly recognized as end-of-options
    * 9.1.0851: too many strlen() calls in getchar.c
    * 9.1.0850: Vim9: cannot access nested object inside objects
    * runtime(tex): extra Number highlighting causes issues
    * runtime(vim): Fix indent after :silent! function
    * 9.1.0849: there are a few typos in the source
    * runtime(netrw): directory symlink not resolved in tree view
    * runtime(doc): add a table of supported Operating Systems
    * runtime(tex): update Last Change header in syntax script
    * runtime(doc): fix typo in g:termdebug_config
    * runtime(vim): Update base-syntax, improve :normal highlighting
    * runtime(tex): add Number highlighting to syntax file
    * runtime(doc): Tweak documentation style a bit
    * 9.1.0848: if_lua: v:false/v:true are not evaluated to boolean
    * runtime(dune): use :setl instead of :set in ftplugin
    * runtime(termdebug): allow to use decimal signs
    * translation(it): Updated Italian vimtutor
    * runtime(compiler): improve cppcheck
    * git: git-blame-ignore-revs shown as an error on Github
    * 9.1.0847: tests: test_popupwin fails because of updated help file
    * 9.1.0846: debug symbols for xxd are not cleaned in Makefile
    * runtime(structurizr): Update structurizr syntax
    * runtime(8th): updated 8th syntax
    * runtime(doc): Add pi_tutor.txt to help TOC
    * runtime(compiler): add mypy and ruff compiler; update pylint linter
    * runtime(netrw): fix several bugs in netrw tree listing
    * runtime(netrw): prevent polluting the search history
    * 9.1.0845: vimtutor shell script can be improved
    * 9.1.0844: if_python: no way to pass local vars to python
    * 9.1.0843: too many strlen() calls in undo.c
    * runtime(doc): update default value for fillchars option
    * runtime(compiler): fix typo in cppcheck compiler plugin
    * runtime(doc): simplify vimtutor manpage a bit more
    * runtime(matchparen): Add matchparen_disable_cursor_hl config option
    * 9.1.0842: not checking for the sync() systemcall
    * 9.1.0841: tests: still preferring python2 over python3
    * 9.1.0840: filetype: idris2 files are not recognized
    * 9.1.0839: filetype: leo files are not recognized
    * runtime(cook): include cook filetype plugin
    * runtime(debversions): Update Debian versions
    * patch 9.1.0838: vimtutor is bash-specific
    * runtime(doc): add help specific modeline to pi_tutor.txt
    * Filelist: vimtutor chapter 2 is missing in Filelist
    * 9.1.0837: cross-compiling has some issues
    * runtime(vimtutor): Add a second chapter

------------------------------------------------------------------
------------------  2024-12-6  -  Dec 6 2024  -------------------
------------------------------------------------------------------

++++ cockpit:

  - Update to 330
  - Web server: Increased sandboxing, setuid removal, bootc support
  - Development: New install mode using systemd-sysext

++++ cockpit-podman:

  - New version 99, updates since 91:
    * Update to translations
    * Bug fixes
    * pull images from registries without search API
    * Render ports are ranges in container integration tab

++++ fde-tools:

  - Enable build on loongarch64

++++ gobject-introspection:

  - Fix dependency generation for loongarch64.

++++ grub2:

  - Fix missing requires in SLE package (bsc#1234264) (bsc#1234272)

++++ kernel-default:

  - enable the disabled kdump-cma patchset
  - Refresh patches.suse/kdump-add-crashkernel-cma-suffix.patch.
  - Refresh
    patches.suse/kdump-crashkernel-cma-update-Documentation.patch.
  - Refresh
    patches.suse/kdump-implement-reserve_crashkernel_cma.patch.
  - Refresh
    patches.suse/kdump-wait-for-dma-to-time-out-when-using-cma.patch.
  - Refresh
    patches.suse/kdump-x86-implement-crashkernel-cma-reservation.patch.
  - commit c48df50
  - net: phy: microchip: Reset LAN88xx PHY to ensure clean link
    state on LAN7800/7850 (git-fixes).
  - can: j1939: j1939_session_new(): fix skb reference counting
    (git-fixes).
  - can: mcp251xfd: mcp251xfd_get_tef_len(): work around erratum
    DS80000789E 6 (git-fixes).
  - can: f81604: f81604_handle_can_bus_errors(): fix {rx,tx}_errors
    statistics (git-fixes).
  - can: ems_usb: ems_usb_rx_err(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: sja1000: sja1000_err(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: hi311x: hi3110_can_ist(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: ifi_canfd: ifi_canfd_handle_lec_err(): fix {rx,tx}_errors
    statistics (git-fixes).
  - can: m_can: m_can_handle_lec_err(): fix {rx,tx}_errors
    statistics (git-fixes).
  - can: hi311x: hi3110_can_ist(): fix potential use-after-free
    (git-fixes).
  - can: sun4i_can: sun4i_can_err(): call can_change_state()
    even if cf is NULL (git-fixes).
  - can: c_can: c_can_handle_bus_err(): update statistics if skb
    allocation fails (git-fixes).
  - can: gs_usb: add usb endpoint address detection at driver
    probe step (git-fixes).
  - can: dev: can_set_termination(): allow sleeping GPIOs
    (git-fixes).
  - HID: wacom: fix when get product name maybe null pointer
    (git-fixes).
  - HID: i2c-hid: Revert to using power commands to wake on resume
    (git-fixes).
  - watchdog: rti: of: honor timeout-sec property (git-fixes).
  - watchdog: mediatek: Make sure system reset gets asserted in
    mtk_wdt_restart() (git-fixes).
  - Revert "watchdog: s3c2410_wdt: use
    exynos_get_pmu_regmap_by_phandle() for PMU regs" (stable-fixes).
  - watchdog: apple: Actually flush writes after requesting watchdog
    restart (git-fixes).
  - watchdog: xilinx_wwdt: Calculate max_hw_heartbeat_ms using
    clock frequency (git-fixes).
  - iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call
    (git-fixes).
  - platform/x86: asus-wmi: Ignore return value when writing
    thermal policy (git-fixes).
  - irqchip/irq-mvebu-sei: Move misplaced select() callback to
    SEI CP domain (git-fixes).
  - kbuild: deb-pkg: Don't fail if modules.order is missing
    (git-fixes).
  - Revert "serial: sh-sci: Clean sci_ports[0] after at earlycon
    exit" (git-fixes).
  - serial: 8250_fintek: Add support for F81216E (stable-fixes).
  - serial: sh-sci: Clean sci_ports[0] after at earlycon exit
    (git-fixes).
  - kfifo: don't include dma-mapping.h in kfifo.h (git-fixes).
  - ASoC: amd: yc: Add a quirk for microfone on Lenovo ThinkPad
    P14s Gen 5 21MES00B00 (stable-fixes).
  - counter: ti-ecap-capture: Add check for clk_enable()
    (git-fixes).
  - counter: stm32-timer-cnt: Add check for clk_enable()
    (git-fixes).
  - counter: stm32-timer-cnt: fix device_node handling in
    probe_encoder() (git-fixes).
  - phy: airoha: Fix REG_CSR_2L_RX{0,1}_REV0 definitions
    (git-fixes).
  - phy: airoha: Fix REG_CSR_2L_JCPLL_SDM_HREN config in
    airoha_pcie_phy_init_ssc_jcpll() (git-fixes).
  - phy: airoha: Fix REG_PCIE_PMA_TX_RESET config in
    airoha_pcie_phy_init_csr_2l() (git-fixes).
  - phy: airoha: Fix REG_CSR_2L_PLL_CMN_RESERVE0 config in
    airoha_pcie_phy_init_clk_out() (git-fixes).
  - PCI: Fix use-after-free of slot->bus on hot remove
    (stable-fixes).
  - clk: en7523: fix estimation of fixed rate for EN7581
    (git-fixes).
  - clk: en7523: introduce chip_scu regmap (stable-fixes).
  - clk: en7523: move clock_register in hw_init callback
    (stable-fixes).
  - clk: en7523: remove REG_PCIE*_{MEM,MEM_MASK} configuration
    (stable-fixes).
  - drm/panthor: Fix OPP refcnt leaks in devfreq initialisation
    (git-fixes).
  - drm/amd/display: Reduce HPD Detection Interval for IPS
    (git-fixes).
  - drm/amd/display: Increase idle worker HPD detection time
    (stable-fixes).
  - drm/amd/display: Skip Invalid Streams from DSC Policy
    (stable-fixes).
  - drm/amd/display: Fix incorrect DSC recompute trigger
    (stable-fixes).
  - drm/panthor: record current and maximum device clock frequencies
    (stable-fixes).
  - drm/panthor: introduce job cycle and timestamp accounting
    (stable-fixes).
  - drm/vc4: hdmi: Increase audio MAI fifo dreq threshold
    (stable-fixes).
  - Bluetooth: ISO: Send BIG Create Sync via hci_sync (git-fixes).
  - Bluetooth: ISO: Do not emit LE BIG Create Sync if previous is
    pending (stable-fixes).
  - Bluetooth: ISO: Do not emit LE PA Create Sync if previous is
    pending (stable-fixes).
  - Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
    (stable-fixes).
  - Bluetooth: btintel: Do no pass vendor events to stack
    (git-fixes).
  - Bluetooth: btintel_pcie: Add handshake between driver and
    firmware (stable-fixes).
  - wifi: rtlwifi: Drastically reduce the attempts to read efuse
    in case of failures (stable-fixes).
  - wifi: rtw89: unlock on error path in
    rtw89_ops_unassign_vif_chanctx() (git-fixes).
  - wifi: rtw89: Fix TX fail with A2DP after scanning (git-fixes).
  - wifi: iwlwifi: mvm: tell iwlmei when we finished suspending
    (git-fixes).
  - wifi: iwlwifi: allow fast resume on ax200 (stable-fixes).
  - wifi: rtw89: tweak driver architecture for impending MLO support
    (stable-fixes).
  - wifi: rtw89: refactor STA related func ahead for MLO
    (stable-fixes).
  - wifi: rtw89: refactor VIF related func ahead for MLO
    (stable-fixes).
  - wifi: rtw89: read link_sta corresponding to the link
    (stable-fixes).
  - wifi: rtw89: read bss_conf corresponding to the link
    (stable-fixes).
  - wifi: rtw89: rename rtw89_sta to rtw89_sta_link ahead for MLO
    (stable-fixes).
  - wifi: rtw89: rename rtw89_vif to rtw89_vif_link ahead for MLO
    (stable-fixes).
  - netdevsim: copy addresses for both in and out paths (git-fixes).
  - docs: media: update location of the media patches
    (stable-fixes).
  - media: ipu6: not override the dma_ops of device in driver
    (git-fixes).
  - media: ipu6: Fix DMA and physical address debugging messages
    for 32-bit (stable-fixes).
  - clocksource/drivers/timer-ti-dm: Fix child node refcount
    handling (git-fixes).
  - clocksource/drivers:sp804: Make user selectable (git-fixes).
  - irqchip/riscv-aplic: Prevent crash when MSI domain is missing
    (git-fixes).
  - thermal: testing: Initialize some variables annoteded with
    _free() (git-fixes).
  - thermal: testing: Use DEFINE_FREE() and __free() to simplify
    code (stable-fixes).
  - thermal: core: Fix race between zone registration and system
    suspend (git-fixes).
  - thermal: core: Mark thermal zones as initializing to start with
    (git-fixes).
  - thermal: core: Represent suspend-related thermal zone flags
    as bits (stable-fixes).
  - thermal: core: Rearrange PM notification code (stable-fixes).
  - commit 5990dcc

++++ kernel-rt:

  - enable the disabled kdump-cma patchset
  - Refresh patches.suse/kdump-add-crashkernel-cma-suffix.patch.
  - Refresh
    patches.suse/kdump-crashkernel-cma-update-Documentation.patch.
  - Refresh
    patches.suse/kdump-implement-reserve_crashkernel_cma.patch.
  - Refresh
    patches.suse/kdump-wait-for-dma-to-time-out-when-using-cma.patch.
  - Refresh
    patches.suse/kdump-x86-implement-crashkernel-cma-reservation.patch.
  - commit c48df50
  - net: phy: microchip: Reset LAN88xx PHY to ensure clean link
    state on LAN7800/7850 (git-fixes).
  - can: j1939: j1939_session_new(): fix skb reference counting
    (git-fixes).
  - can: mcp251xfd: mcp251xfd_get_tef_len(): work around erratum
    DS80000789E 6 (git-fixes).
  - can: f81604: f81604_handle_can_bus_errors(): fix {rx,tx}_errors
    statistics (git-fixes).
  - can: ems_usb: ems_usb_rx_err(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: sun4i_can: sun4i_can_err(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: sja1000: sja1000_err(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: hi311x: hi3110_can_ist(): fix {rx,tx}_errors statistics
    (git-fixes).
  - can: ifi_canfd: ifi_canfd_handle_lec_err(): fix {rx,tx}_errors
    statistics (git-fixes).
  - can: m_can: m_can_handle_lec_err(): fix {rx,tx}_errors
    statistics (git-fixes).
  - can: hi311x: hi3110_can_ist(): fix potential use-after-free
    (git-fixes).
  - can: sun4i_can: sun4i_can_err(): call can_change_state()
    even if cf is NULL (git-fixes).
  - can: c_can: c_can_handle_bus_err(): update statistics if skb
    allocation fails (git-fixes).
  - can: gs_usb: add usb endpoint address detection at driver
    probe step (git-fixes).
  - can: dev: can_set_termination(): allow sleeping GPIOs
    (git-fixes).
  - HID: wacom: fix when get product name maybe null pointer
    (git-fixes).
  - HID: i2c-hid: Revert to using power commands to wake on resume
    (git-fixes).
  - watchdog: rti: of: honor timeout-sec property (git-fixes).
  - watchdog: mediatek: Make sure system reset gets asserted in
    mtk_wdt_restart() (git-fixes).
  - Revert "watchdog: s3c2410_wdt: use
    exynos_get_pmu_regmap_by_phandle() for PMU regs" (stable-fixes).
  - watchdog: apple: Actually flush writes after requesting watchdog
    restart (git-fixes).
  - watchdog: xilinx_wwdt: Calculate max_hw_heartbeat_ms using
    clock frequency (git-fixes).
  - iTCO_wdt: mask NMI_NOW bit for update_no_reboot_bit() call
    (git-fixes).
  - platform/x86: asus-wmi: Ignore return value when writing
    thermal policy (git-fixes).
  - irqchip/irq-mvebu-sei: Move misplaced select() callback to
    SEI CP domain (git-fixes).
  - kbuild: deb-pkg: Don't fail if modules.order is missing
    (git-fixes).
  - Revert "serial: sh-sci: Clean sci_ports[0] after at earlycon
    exit" (git-fixes).
  - serial: 8250_fintek: Add support for F81216E (stable-fixes).
  - serial: sh-sci: Clean sci_ports[0] after at earlycon exit
    (git-fixes).
  - kfifo: don't include dma-mapping.h in kfifo.h (git-fixes).
  - ASoC: amd: yc: Add a quirk for microfone on Lenovo ThinkPad
    P14s Gen 5 21MES00B00 (stable-fixes).
  - counter: ti-ecap-capture: Add check for clk_enable()
    (git-fixes).
  - counter: stm32-timer-cnt: Add check for clk_enable()
    (git-fixes).
  - counter: stm32-timer-cnt: fix device_node handling in
    probe_encoder() (git-fixes).
  - phy: airoha: Fix REG_CSR_2L_RX{0,1}_REV0 definitions
    (git-fixes).
  - phy: airoha: Fix REG_CSR_2L_JCPLL_SDM_HREN config in
    airoha_pcie_phy_init_ssc_jcpll() (git-fixes).
  - phy: airoha: Fix REG_PCIE_PMA_TX_RESET config in
    airoha_pcie_phy_init_csr_2l() (git-fixes).
  - phy: airoha: Fix REG_CSR_2L_PLL_CMN_RESERVE0 config in
    airoha_pcie_phy_init_clk_out() (git-fixes).
  - PCI: Fix use-after-free of slot->bus on hot remove
    (stable-fixes).
  - clk: en7523: fix estimation of fixed rate for EN7581
    (git-fixes).
  - clk: en7523: introduce chip_scu regmap (stable-fixes).
  - clk: en7523: move clock_register in hw_init callback
    (stable-fixes).
  - clk: en7523: remove REG_PCIE*_{MEM,MEM_MASK} configuration
    (stable-fixes).
  - drm/panthor: Fix OPP refcnt leaks in devfreq initialisation
    (git-fixes).
  - drm/amd/display: Reduce HPD Detection Interval for IPS
    (git-fixes).
  - drm/amd/display: Increase idle worker HPD detection time
    (stable-fixes).
  - drm/amd/display: Skip Invalid Streams from DSC Policy
    (stable-fixes).
  - drm/amd/display: Fix incorrect DSC recompute trigger
    (stable-fixes).
  - drm/panthor: record current and maximum device clock frequencies
    (stable-fixes).
  - drm/panthor: introduce job cycle and timestamp accounting
    (stable-fixes).
  - drm/vc4: hdmi: Increase audio MAI fifo dreq threshold
    (stable-fixes).
  - Bluetooth: ISO: Send BIG Create Sync via hci_sync (git-fixes).
  - Bluetooth: ISO: Do not emit LE BIG Create Sync if previous is
    pending (stable-fixes).
  - Bluetooth: ISO: Do not emit LE PA Create Sync if previous is
    pending (stable-fixes).
  - Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}()
    (stable-fixes).
  - Bluetooth: btintel: Do no pass vendor events to stack
    (git-fixes).
  - Bluetooth: btintel_pcie: Add handshake between driver and
    firmware (stable-fixes).
  - wifi: rtlwifi: Drastically reduce the attempts to read efuse
    in case of failures (stable-fixes).
  - wifi: rtw89: unlock on error path in
    rtw89_ops_unassign_vif_chanctx() (git-fixes).
  - wifi: rtw89: Fix TX fail with A2DP after scanning (git-fixes).
  - wifi: iwlwifi: mvm: tell iwlmei when we finished suspending
    (git-fixes).
  - wifi: iwlwifi: allow fast resume on ax200 (stable-fixes).
  - wifi: rtw89: tweak driver architecture for impending MLO support
    (stable-fixes).
  - wifi: rtw89: refactor STA related func ahead for MLO
    (stable-fixes).
  - wifi: rtw89: refactor VIF related func ahead for MLO
    (stable-fixes).
  - wifi: rtw89: read link_sta corresponding to the link
    (stable-fixes).
  - wifi: rtw89: read bss_conf corresponding to the link
    (stable-fixes).
  - wifi: rtw89: rename rtw89_sta to rtw89_sta_link ahead for MLO
    (stable-fixes).
  - wifi: rtw89: rename rtw89_vif to rtw89_vif_link ahead for MLO
    (stable-fixes).
  - netdevsim: copy addresses for both in and out paths (git-fixes).
  - docs: media: update location of the media patches
    (stable-fixes).
  - media: ipu6: not override the dma_ops of device in driver
    (git-fixes).
  - media: ipu6: Fix DMA and physical address debugging messages
    for 32-bit (stable-fixes).
  - clocksource/drivers/timer-ti-dm: Fix child node refcount
    handling (git-fixes).
  - clocksource/drivers:sp804: Make user selectable (git-fixes).
  - irqchip/riscv-aplic: Prevent crash when MSI domain is missing
    (git-fixes).
  - thermal: testing: Initialize some variables annoteded with
    _free() (git-fixes).
  - thermal: testing: Use DEFINE_FREE() and __free() to simplify
    code (stable-fixes).
  - thermal: core: Fix race between zone registration and system
    suspend (git-fixes).
  - thermal: core: Mark thermal zones as initializing to start with
    (git-fixes).
  - thermal: core: Represent suspend-related thermal zone flags
    as bits (stable-fixes).
  - thermal: core: Rearrange PM notification code (stable-fixes).
  - commit 5990dcc

++++ samba:

  - Update shipped /etc/samba/smb.conf to point to smb.conf
    man page;(bsc#1233880).

++++ python313-core:

  - Add CVE-2024-12254-unbound-mem-buffering-SelectorSocketTransport.writelines.patch
    preventing exhaustion of memory (gh#python/cpython#127655,
    bsc#1234290, CVE-2024-12254).

++++ qatlib:

  - update to 24.09.0:
    * Improved performance scaling in multi-thread applications
    * Set core affinity mapping based on NUMA
    (libnuma now required for building)
    * bug fixes, see https://github.com/intel/qatlib#resolved-issues

++++ shadow:

  - Update to 4.17.0 RC1:
    Pre-release without changelog

++++ libtpms:

  - Use gcc/g++-13 on Leap to fix the following failure:
    "tpm2_setprofile.c:49:24: error: initializer element is not constant"

++++ liburing:

  - switch to signed tarball -- thanks to Andreas.Stieger@gmx.de

++++ python313:

  - Add CVE-2024-12254-unbound-mem-buffering-SelectorSocketTransport.writelines.patch
    preventing exhaustion of memory (gh#python/cpython#127655,
    bsc#1234290, CVE-2024-12254).

++++ os-update:

  - Update to version 1.21+git.20241206:
    * Release version 1.21
    * Fix check for service restarts

------------------------------------------------------------------
------------------  2024-12-5  -  Dec 5 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.3.1
  - -> https://docs.mesa3d.org/relnotes/24.3.1

++++ Mesa-drivers:

  - Update to release 24.3.1
  - -> https://docs.mesa3d.org/relnotes/24.3.1

++++ gpg2:

  - Disable ibmswtpm2 on LoongArch64

++++ kernel-default:

  - powerpc/fadump: Move fadump_cma_init to setup_arch() after
    initmem_init() (bsc#1215199).
  - powerpc/fadump: Refactor and prepare fadump_cma_init for late
    init (bsc#1215199).
  - commit 1188346
  - powerpc/kexec: Fix return of uninitialized variable
    (bsc#1194869).
  - powerpc/sstep: make emulate_vsx_load and emulate_vsx_store
    static (bsc#1194869).
  - powerpc/pseries: Fix KVM guest detection for disabling
    hardlockup detector (bsc#1194869).
  - powerpc/pseries: Fix dtl_access_lock to be a rw_semaphore
    (bsc#1194869).
  - powerpc/mm/fault: Fix kfence page fault reporting (bsc#1194869).
  - commit b6fdd1f
  - Refresh patches.suse/0001-typeC-add-kABI-padding.patch.
  - Refresh
    patches.suse/0002-Add-a-void-suse_kabi_padding-placeholder-to-some-USB.patch.
  - Refresh
    patches.suse/new-paddings-for-the-new-features-of-TB.patch.
  - Refresh patches.suse/padding-XHCI-additional-padding.patch.
  - Refresh patches.suse/padding-ehci-core-structures.patch.
  - Refresh patches.suse/padding-ohci-core-structure-padding.patch.
  - Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch.
  - Refresh patches.suse/paddings-for-gadgets.patch.
  - commit 1d5b9ca
  - bpf, arm64: Remove garbage frame for struct_ops trampoline (git-fixes)
  - commit f62ac09
  - arm64: dts: rockchip: correct analog audio name on Indiedroid Nova (git-fixes)
  - commit f3d03a2
  - arm64: dts: allwinner: pinephone: Add mount matrix to accelerometer (git-fixes)
  - commit 8c31355
  - arm64: dts: freescale: imx8mp-verdin: Fix SD regulator startup delay (git-fixes)
  - commit 39fac3d
  - arm64: dts: freescale: imx8mm-verdin: Fix SD regulator startup delay (git-fixes)
  - commit e7350ce
  - arm64: dts: imx8mn-tqma8mqnl-mba8mx-usbot: fix coexistence of (git-fixes)
  - commit bf28c10
  - arm64: dts: rockchip: Remove 'enable-active-low' from two boards (git-fixes)
  - commit a573b02
  - arm64: dts: rockchip: pwm-leds for Orange Pi 5 (git-fixes)
  - commit 7d2d085
  - arm64: tegra: p2180: Add mandatory compatible for WiFi node (git-fixes)
  - commit d9c39de
  - arm64: probes: Disable kprobes/uprobes on MOPS instructions (git-fixes)
  - commit 1d64594
  - arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled (git-fixes)
  - commit 8da52a4
  - arm64: fix .data.rel.ro size assertion when CONFIG_LTO_CLANG (git-fixes)
  - commit bacb7d4
  - arm64: Expose ID_AA64ISAR1_EL1.XS to sanitised feature consumers (git-fixes)
  - commit 43f6bc3

++++ kernel-firmware-all:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-amdgpu:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-ath10k:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-ath11k:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-ath12k:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-atheros:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-bluetooth:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-bnx2:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-brcm:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-chelsio:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-dpaa2:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-i915:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-intel:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-iwlwifi:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-liquidio:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-marvell:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-media:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-mediatek:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-mellanox:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-mwifiex:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-network:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-nfp:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-nvidia:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-platform:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-prestera:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-qcom:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-qlogic:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-radeon:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-realtek:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-serial:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-sound:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-ti:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-ueagle:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-firmware-usb-network:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ kernel-rt:

  - powerpc/fadump: Move fadump_cma_init to setup_arch() after
    initmem_init() (bsc#1215199).
  - powerpc/fadump: Refactor and prepare fadump_cma_init for late
    init (bsc#1215199).
  - commit 1188346
  - powerpc/kexec: Fix return of uninitialized variable
    (bsc#1194869).
  - powerpc/sstep: make emulate_vsx_load and emulate_vsx_store
    static (bsc#1194869).
  - powerpc/pseries: Fix KVM guest detection for disabling
    hardlockup detector (bsc#1194869).
  - powerpc/pseries: Fix dtl_access_lock to be a rw_semaphore
    (bsc#1194869).
  - powerpc/mm/fault: Fix kfence page fault reporting (bsc#1194869).
  - commit b6fdd1f
  - Refresh patches.suse/0001-typeC-add-kABI-padding.patch.
  - Refresh
    patches.suse/0002-Add-a-void-suse_kabi_padding-placeholder-to-some-USB.patch.
  - Refresh
    patches.suse/new-paddings-for-the-new-features-of-TB.patch.
  - Refresh patches.suse/padding-XHCI-additional-padding.patch.
  - Refresh patches.suse/padding-ehci-core-structures.patch.
  - Refresh patches.suse/padding-ohci-core-structure-padding.patch.
  - Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch.
  - Refresh patches.suse/paddings-for-gadgets.patch.
  - commit 1d5b9ca
  - bpf, arm64: Remove garbage frame for struct_ops trampoline (git-fixes)
  - commit f62ac09
  - arm64: dts: rockchip: correct analog audio name on Indiedroid Nova (git-fixes)
  - commit f3d03a2
  - arm64: dts: allwinner: pinephone: Add mount matrix to accelerometer (git-fixes)
  - commit 8c31355
  - arm64: dts: freescale: imx8mp-verdin: Fix SD regulator startup delay (git-fixes)
  - commit 39fac3d
  - arm64: dts: freescale: imx8mm-verdin: Fix SD regulator startup delay (git-fixes)
  - commit e7350ce
  - arm64: dts: imx8mn-tqma8mqnl-mba8mx-usbot: fix coexistence of (git-fixes)
  - commit bf28c10
  - arm64: dts: rockchip: Remove 'enable-active-low' from two boards (git-fixes)
  - commit a573b02
  - arm64: dts: rockchip: pwm-leds for Orange Pi 5 (git-fixes)
  - commit 7d2d085
  - arm64: tegra: p2180: Add mandatory compatible for WiFi node (git-fixes)
  - commit d9c39de
  - arm64: probes: Disable kprobes/uprobes on MOPS instructions (git-fixes)
  - commit 1d64594
  - arm64: tls: Fix context-switching of tpidrro_el0 when kpti is enabled (git-fixes)
  - commit 8da52a4
  - arm64: fix .data.rel.ro size assertion when CONFIG_LTO_CLANG (git-fixes)
  - commit bacb7d4
  - arm64: Expose ID_AA64ISAR1_EL1.XS to sanitised feature consumers (git-fixes)
  - commit 43f6bc3

++++ llvm19:

  - Update to version 19.1.5.
    * This release contains bug-fixes for the LLVM 19.1.0 release.
    This release is API and ABI compatible with 19.1.0.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ libdrm:

  - update to 2.4.124
    * include/drm/README: update drm-next link to use gitlab instead of cgit
    * modetest: simplify planar YUV handling
    * modetest: add support for YUV422 and YUV444 plane format
    * xf86drm: print AMD modifiers properly
    * tests/util: Call `drmGetDevices2()` instead of `drmOpen()`ing all modules
    * android: add genrule for generated_static_table_fourcc.h
    * modetest: Make modetest availble to vendor on Android
    * build: simplify Linux system check

++++ nvidia-open-driver-G06-signed:

  - obsolete <=560.35.03 -cuda KMPs; mistakenly we released
    560.35.03 for SP4 ...

++++ pam:

  - pam_access: rework resolving of tokens as hostname
  - separate resolving of IP addresses from hostnames. Don't resolve TTYs or
    display variables as hostname.
  - Add "nodns" option to disallow resolving of tokens as hostname.
  - [pam_access-rework-resolving-of-tokens-as-hostname.patch, bsc#1233078,
    CVE-2024-10963]

++++ pam-full-src:

  - pam_access: rework resolving of tokens as hostname
  - separate resolving of IP addresses from hostnames. Don't resolve TTYs or
    display variables as hostname.
  - Add "nodns" option to disallow resolving of tokens as hostname.
  - [pam_access-rework-resolving-of-tokens-as-hostname.patch, bsc#1233078,
    CVE-2024-10963]

++++ psmisc:

  - add loongarch64 as peekfd supported arch

++++ python-netaddr:

  - Fix incorrect removal of shebangs
  - update to 1.3.0:
    * Added:
  - Add partial address expansion in IPNetwork via the
    expand_partial switch, this enables opting into pre-1.1.0
    behavior
    * Fixed:
  - Fix running the test suite on musl systems
  - Fix IPAddress IPv6 parsing with ZEROFILL enabled
  - Fix handling of the NOHOST flag in the IPNetwork copy
    constructor

++++ python-rich:

  - Switch to GitHub tarball so we can run the testsuite.
  - Correct version guard for typing_extensions Requires.
  - Drop Python 3.7 sections.

++++ ucode-amd:

  - Update to version 20241203 (git commit f5aeeb47697c):
    * amdgpu: update raven firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: update psp 13.0.14 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update vpe 6.1.3 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: add vcn 5.0.0 firmware
    * amdgpu: add smu 14.0.3 firmware
    * amdgpu: add sdma 7.0.1 firmware
    * amdgpu: add psp 14.0.3 firmware
    * amdgpu: add gc 12.0.1 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: add smu 14.0.2 firmware
    * amdgpu: add sdma 7.0.0 firmware
    * amdgpu: add psp 14.0.2 firmware
    * amdgpu: add gc 12.0.0 firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * upstream amdnpu firmware
  - Add amdnpu entries
  - Add missing license entry for amd_pmf

++++ virt-manager:

  - bsc#1234215 - fail to install a guest with virt-install and
    report "AttributeError: 'str' object has no attribute 'removeprefix'"
    virtinst-drop-removeprefix-usage.patch

------------------------------------------------------------------
------------------  2024-12-4  -  Dec 4 2024  -------------------
------------------------------------------------------------------

++++ gawk:

  - Reenable pma tests

++++ hwdata:

  - update to 0.390:
    * Update pci and vendor ids

++++ kernel-default:

  - hv_sock: Initializing vsk->trans to NULL to prevent a dangling
    pointer (git-fixes).
  - HID: hyperv: streamline driver probe to avoid devres issues
    (git-fixes).
  - commit ee23739
  - hyperv: keep generate_guest_id (bsc#1189965).
  - commit ec2fbf8

++++ kernel-rt:

  - hv_sock: Initializing vsk->trans to NULL to prevent a dangling
    pointer (git-fixes).
  - HID: hyperv: streamline driver probe to avoid devres issues
    (git-fixes).
  - commit ee23739
  - hyperv: keep generate_guest_id (bsc#1189965).
  - commit ec2fbf8

++++ pixman:

  - Increase test timeout on s390x. Several tests can be slow and
    sometimes times out in our builds.
  - Use autosetup macro.

++++ python313-core:

  - Update to 3.13.1:
  - Tools/Demos
  - gh-126807: Fix extraction warnings in pygettext.py caused
    by mistaking function definitions for function calls.
  - gh-126167: The iOS testbed was modified so that it can be
    used by third-party projects for testing purposes.
  - Tests
  - gh-126909: Fix test_os extended attribute tests to work on
    filesystems with 1 KiB xattr size limit.
  - gh-125041: Re-enable skipped tests for zlib on the
    s390x architecture: only skip checks of the compressed
    bytes, which can be different between zlib’s software
    implementation and the hardware-accelerated implementation.
  - gh-124295: Add translation tests to the argparse module.
  - Security
  - gh-126623: Upgrade libexpat to 2.6.4
  - gh-125140: Remove the current directory from sys.path when
    using PyREPL.
  - gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to
    consistently use the mapped IPv4 address value for deciding
    properties. Properties which have their behavior fixed are
    is_multicast, is_reserved, is_link_local, is_global, and
    is_unspecified.
  - Library
  - gh-127321: pdb.set_trace() will not stop at an opcode that
    does not have an associated line number anymore.
  - gh-127303: Publicly expose EXACT_TOKEN_TYPES in
    token.__all__.
  - gh-123967: Fix faulthandler for trampoline frames. If the
    top-most frame is a trampoline frame, skip it. Patch by
    Victor Stinner.
  - gh-127182: Fix io.StringIO.__setstate__() crash, when None
    was passed as the first value.
  - gh-127217: Fix urllib.request.pathname2url() for paths
    starting with multiple slashes on Posix.
  - gh-127035: Fix shutil.which on Windows. Now it looks at
    direct match if and only if the command ends with a PATHEXT
    extension or X_OK is not in mode. Support extensionless
    files if “.” is in PATHEXT. Support PATHEXT extensions that
    end with a dot.
  - gh-122273: Support PyREPL history on Windows. Patch by
    devdanzin and Victor Stinner.
  - gh-127078: Fix issue where urllib.request.url2pathname()
    failed to discard an extra slash before a UNC drive in the
    URL path on Windows.
  - gh-126766: Fix issue where urllib.request.url2pathname()
    failed to discard any ‘localhost’ authority present in the
    URL.
  - gh-127065: Fix crash when calling a operator.methodcaller()
    instance from multiple threads in the free threading build.
  - gh-126997: Fix support of STRING and GLOBAL opcodes with
    non-ASCII arguments in pickletools. pickletools.dis()
    now outputs non-ASCII bytes in STRING, BINSTRING and
    SHORT_BINSTRING arguments as escaped (\xXX).
  - gh-126316: grp: Make grp.getgrall() thread-safe by adding a
    mutex. Patch by Victor Stinner.
  - gh-126618: Fix the representation of itertools.count
    objects when the count value is sys.maxsize.
  - gh-85168: Fix issue where urllib.request.url2pathname() and
    pathname2url() always used UTF-8 when quoting and unquoting
    file URIs. They now use the filesystem encoding and error
    handler.
  - gh-67877: Fix memory leaks when regular expression matching
    terminates abruptly, either because of a signal or because
    memory allocation fails.
  - gh-126789: Fixed the values of sysconfig.get_config_vars(),
    sysconfig.get_paths(), and their siblings when the site
    initialization happens after sysconfig has built a cache
    for sysconfig.get_config_vars().
  - gh-126188: Update bundled pip to 24.3.1
  - gh-126780: Fix os.path.normpath() for drive-relative paths
    on Windows.
  - gh-126766: Fix issue where urllib.request.url2pathname()
    failed to discard two leading slashes introducing an empty
    authority section.
  - gh-126727: locale.nl_langinfo(locale.ERA) now returns
    multiple era description segments separated by
    semicolons. Previously it only returned the first segment
    on platforms with Glibc.
  - gh-126699: Allow collections.abc.AsyncIterator to be a base
    for Protocols.
  - gh-126654: Fix crash when non-dict was passed to several
    functions in _interpreters module.
  - gh-104745: Limit starting a patcher (from
    unittest.mock.patch() or unittest.mock.patch.object()) more
    than once without stopping it
  - gh-126595: Fix a crash when instantiating itertools.count
    with an initial count of sys.maxsize on debug builds. Patch
    by Bénédikt Tran.
  - gh-120423: Fix issue where urllib.request.pathname2url()
    mishandled Windows paths with embedded forward slashes.
  - gh-126565: Improve performances of zipfile.Path.open() for
    non-reading modes.
  - gh-126505: Fix bugs in compiling case-insensitive regular
    expressions with character classes containing non-BMP
    characters: upper-case non-BMP character did was ignored
    and the ASCII flag was ignored when matching a character
    range whose upper bound is beyond the BMP region.
  - gh-117378: Fixed the multiprocessing "forkserver"
    start method forkserver process to correctly inherit
    the parent’s sys.path during the importing of
    multiprocessing.set_forkserver_preload() modules in the
    same manner as sys.path is configured in workers before
    executing work items.
  - This bug caused some forkserver module preloading to
    silently fail to preload. This manifested as a performance
    degration in child processes when the sys.path was required
    due to additional repeated work in every worker.
  - It could also have a side effect of "" remaining in
    sys.path during forkserver preload imports instead of the
    absolute path from os.getcwd() at multiprocessing import
    time used in the worker sys.path.
  - The sys.path differences between phases in the child
    process could potentially have caused preload to import
    incorrect things from the wrong location. We are unaware of
    that actually having happened in practice.
  - gh-125679: The multiprocessing.Lock and
    multiprocessing.RLock repr values no longer say “unknown”
    on macOS.
  - gh-126476: Raise calendar.IllegalMonthError (now a subclass
    of IndexError) for calendar.month() when the input month is
    not correct.
  - gh-126489: The Python implementation of pickle no longer
    calls pickle.Pickler.persistent_id() for the result of
    persistent_id().
  - gh-126313: Fix an issue in curses.napms() when
    curses.initscr() has not yet been called. Patch by Bénédikt
    Tran.
  - gh-126303: Fix pickling and copying of os.sched_param
    objects.
  - gh-126138: Fix a use-after-free crash on asyncio.Task
    objects whose underlying coroutine yields an object that
    implements an evil __getattribute__(). Patch by Nico
    Posada.
  - gh-126220: Fix crash in cProfile.Profile and
    _lsprof.Profiler when their callbacks were directly called
    with 0 arguments.
  - gh-126212: Fix issue where urllib.request.pathname2url()
    and url2pathname() removed slashes from Windows DOS drive
    paths and URLs.
  - gh-126223: Raise a UnicodeEncodeError instead of a
    SystemError upon calling _interpreters.create() with an
    invalid Unicode character.
  - gh-126205: Fix issue where urllib.request.pathname2url()
    generated URLs beginning with four slashes (rather than
    two) when given a Windows UNC path.
  - gh-126105: Fix a crash in ast when the ast.AST._fields
    attribute is deleted.
  - gh-126106: Fixes a possible NULL pointer dereference in
    ssl.
  - gh-126080: Fix a use-after-free crash on asyncio.Task
    objects for which the underlying event loop implements an
    evil __getattribute__(). Reported by Nico-Posada. Patch by
    Bénédikt Tran.
  - gh-126083: Fixed a reference leak in asyncio.Task objects
    when reinitializing the same object with a non-None
    context. Patch by Nico Posada.
  - gh-125984: Fix use-after-free crashes on asyncio.Future
    objects for which the underlying event loop implements an
    evil __getattribute__(). Reported by Nico-Posada. Patch by
    Bénédikt Tran.
  - gh-125969: Fix an out-of-bounds crash when an evil
    asyncio.loop.call_soon() mutates the length of the internal
    callbacks list. Patch by Bénédikt Tran.
  - gh-125966: Fix a use-after-free crash in
    asyncio.Future.remove_done_callback(). Patch by Bénédikt
    Tran.
  - gh-125789: Fix possible crash when mutating list of
    callbacks returned by asyncio.Future._callbacks. It
    now always returns a new copy in C implementation
    _asyncio. Patch by Kumar Aditya.
  - gh-124452: Fix an issue in
    email.policy.EmailPolicy.header_source_parse() and
    email.policy.Compat32.header_source_parse() that introduced
    spurious leading whitespaces into header values when the
    header includes a newline character after the header name
    delimiter (:) and before the value.
  - gh-125884: Fixed the bug for pdb where it can’t set
    breakpoints on functions with certain annotations.
  - gh-125355: Fix several bugs in
    argparse.ArgumentParser.parse_intermixed_args().
  - The parser no longer changes temporarily during
    parsing.
  - Default values are not processed twice.
  - Required mutually exclusive groups containing
    positional arguments are now supported.
  - The missing arguments report now includes the names of
    all required optional and positional arguments.
  - Unknown options can be intermixed with positional
    arguments in parse_known_intermixed_args().
  - gh-125666: Avoid the exiting the interpreter if a null byte
    is given as input in the new REPL.
  - gh-125710: [Enum] fix hashable<->nonhashable comparisons
    for member values
  - gh-125631: Restore ability to set persistent_id and
    persistent_load attributes of instances of the Pickler and
    Unpickler classes in the pickle module.
  - gh-125378: Fixed the bug in pdb where after a multi-line
    command, an empty line repeats the first line of the
    multi-line command, instead of the full command.
  - gh-125682: Reject non-ASCII digits in the Python
    implementation of json.loads() conforming to the JSON
    specification.
  - gh-125660: Reject invalid unicode escapes for Python
    implementation of json.loads().
  - gh-125259: Fix the notes removal logic for errors thrown in
    enum initialization.
  - gh-125590: Allow FrameLocalsProxy to delete and pop if the
    key is not a fast variable.
  - gh-125519: Improve traceback if importlib.reload() is
    called with an object that is not a module. Patch by Alex
    Waygood.
  - gh-125451: Fix deadlock when
    concurrent.futures.ProcessPoolExecutor shuts down
    concurrently with an error when feeding a job to a worker
    process.
  - gh-125422: Fixed the bug where pdb and bdb can step into
    the bottom caller frame.
  - gh-100141: Fixed the bug where pdb will be stuck in an
    infinite loop when debugging an empty file.
  - gh-125115: Fixed a bug in pdb where arguments starting with
  - can’t be passed to the debugged script.
  - gh-53203: Fix time.strptime() for %c, %x and %X formats
    in many locales that use non-ASCII digits, like Persian,
    Burmese, Odia and Shan.
  - gh-125398: Fix the conversion of the VIRTUAL_ENV path in
    the activate script in venv when running in Git Bash for
    Windows.
  - gh-125316: Fix using functools.partial() as enum.Enum
    member. A FutureWarning with suggestion to use
    enum.member() is now emitted when the partial instance is
    used as an enum member.
  - gh-125245: Fix race condition when importing
    collections.abc, which could incorrectly return an empty
    module.
  - gh-125243: Fix data race when creating zoneinfo.ZoneInfo
    objects in the free threading build.
  - gh-125254: Fix a bug where ArgumentError includes the
    incorrect ambiguous option in argparse.
  - gh-125235: Keep tkinter TCL paths in venv pointing to base
    installation on Windows.
  - gh-61011: Fix inheritance of nested mutually
    exclusive groups from parent parser in
    argparse.ArgumentParser. Previously, all nested mutually
    exclusive groups lost their connection to the group
    containing them and were displayed as belonging directly to
    the parser.
  - gh-52551: Fix encoding issues in time.strftime(), the
    strftime() method of the datetime classes datetime, date
    and time and formatting of these classes. Characters
    not encodable in the current locale are now acceptable
    in the format string. Surrogate pairs and sequence
    of surrogatescape-encoded bytes are no longer
    recombinated. Embedded null character no longer terminates
    the format string.
  - gh-125118: Don’t copy arbitrary values to _Bool in the
    struct module.
  - gh-125069: Fix an issue where providing a pathlib.PurePath
    object as an initializer argument to a second PurePath
    object with a different parser resulted in arguments to
    the former object’s initializer being joined by the latter
    object’s parser.
  - gh-125096: If the PYTHON_BASIC_REPL environment variable
    is set, the site module no longer imports the _pyrepl
    module. Moreover, the site module now respects -E and -I
    command line options: ignore PYTHON_BASIC_REPL in this
    case. Patch by Victor Stinner.
  - gh-124969: Fix locale.nl_langinfo(locale.ALT_DIGITS) on
    platforms with glibc. Now it returns a string consisting of
    up to 100 semicolon-separated symbols (an empty string in
    most locales) on all Posix platforms. Previously it only
    returned the first symbol or an empty string.
  - gh-124960: Fix support for the barry_as_FLUFL future flag
    in the new REPL.
  - gh-124984: Fixed thread safety in ssl in the free-threaded
    build. OpenSSL operations are now protected by a per-object
    lock.
  - gh-124958: Fix refcycles in exceptions raised from
    asyncio.TaskGroup and the python implementation of
    asyncio.Future
  - gh-53203: Fix time.strptime() for %c and %x formats in many
    locales: Arabic, Bislama, Breton, Bodo, Kashubian, Chuvash,
    Estonian, French, Irish, Ge’ez, Gurajati, Manx Gaelic,
    Hebrew, Hindi, Chhattisgarhi, Haitian Kreyol, Japanese,
    Kannada, Korean, Marathi, Malay, Norwegian, Nynorsk,
    Punjabi, Rajasthani, Tok Pisin, Yoruba, Yue Chinese,
    Yau/Nungon and Chinese.
  - gh-124917: Allow calling os.path.exists() and
    os.path.lexists() with keyword arguments on Windows. Fixes
    a regression in 3.13.0.
  - gh-124653: Fix detection of the minimal Queue API needed by
    the logging module. Patch by Bénédikt Tran.
  - gh-124858: Fix reference cycles left in tracebacks
    in asyncio.open_connection() when used with
    happy_eyeballs_delay
  - gh-124390: Fixed AssertionError when using
    asyncio.staggered.staggered_race() with
    asyncio.eager_task_factory.
  - gh-124651: Properly quote template strings in venv
    activation scripts (bsc#1232241, CVE-2024-9287).
  - gh-116850: Fix argparse for namespaces with not directly
    writable dict (e.g. classes).
  - gh-58573: Fix conflicts between abbreviated long options in
    the parent parser and subparsers in argparse.
  - gh-124594: All asyncio REPL prompts run in the same
    context. Contributed by Bartosz Sławecki.
  - gh-61181: Fix support of choices with string value in
    argparse. Substrings of the specified string no longer
    considered valid values.
  - gh-80259: Fix argparse support of positional arguments with
    nargs='?', default=argparse.SUPPRESS and specified type.
  - gh-120378: Fix a crash related to an integer overflow in
    curses.resizeterm() and curses.resize_term().
  - gh-123884: Fixed bug in itertools.tee() handling of other
    tee inputs (a tee in a tee). The output now has the
    promised n independent new iterators. Formerly, the first
    iterator was identical (not independent) to the input
    iterator. This would sometimes give surprising results.
  - gh-58956: Fixed a bug in pdb where sometimes the breakpoint
    won’t trigger if it was set on a function which is already
    in the call stack.
  - gh-124345: argparse vim supports abbreviated single-dash
    long options separated by = from its value.
  - gh-104860: Fix disallowing abbreviation of single-dash long
    options in argparse with allow_abbrev=False.
  - gh-63143: Fix parsing mutually exclusive arguments in
    argparse. Arguments with the value identical to the default
    value (e.g. booleans, small integers, empty or 1-character
    strings) are no longer considered “not present”.
  - gh-72795: Positional arguments with nargs equal to '*' or
    argparse.REMAINDER are no longer required. This allows to
    use positional argument with nargs='*' and without default
    in mutually exclusive group and improves error message
    about required arguments.
  - gh-59317: Fix parsing positional argument with nargs equal
    to '?' or '*' if it is preceded by an option and another
    positional argument.
  - gh-53780: argparse now ignores the first "--" (double dash)
    between an option and command.
  - gh-124217: Add RFC 9637 reserved IPv6 block 3fff::/20 in
    ipaddress module.
  - gh-81691: Fix handling of multiple "--" (double dashes)
    in argparse. Only the first one has now been removed, all
    subsequent ones are now taken literally.
  - gh-123978: Remove broken time.thread_time() and
    time.thread_time_ns() on NetBSD.
  - gh-124008: Fix possible crash (in debug build), incorrect
    output or returning incorrect value from raw binary write()
    when writing to console on Windows.
  - gh-123935: Fix parent slots detection for dataclasses that
    inherit from classes with __dictoffset__.
  - gh-122765: Fix unbalanced quote errors occurring when
    activate.csh in venv was sourced with a custom prompt
    containing unpaired quotes or newlines.
  - gh-123370: Fix the canvas not clearing after running
    turtledemo clock.
  - gh-116810: Resolve a memory leak introduced in CPython
    3.10’s ssl when the ssl.SSLSocket.session property was
    accessed. Speeds up read and write access to said property
    by no longer unnecessarily cloning session objects via
    serialization.
  - gh-120754: Update unbounded read calls in zipfile to
    specify an explicit size putting a limit on how much data
    they may read. This also updates handling around ZIP max
    comment size to match the standard instead of reading
    comments that are one byte too long.
  - gh-70764: Fixed an issue where inspect.getclosurevars()
    would incorrectly classify an attribute name as a global
    variable when the name exists both as an attribute name and
    a global variable.
  - gh-118289: posixpath.realpath() now raises
    NotADirectoryError when strict mode is enabled and a
    non-directory path with a trailing slash is supplied.
  - gh-119826: Always return an absolute path for
    os.path.abspath() on Windows.
  - gh-117766: Always use str() to print choices in argparse.
  - gh-101955: Fix SystemError when match regular expression
    pattern containing some combination of possessive
    quantifier, alternative and capture group.
  - gh-88110: Fixed multiprocessing.Process reporting a
    .exitcode of 1 even on success when using the "fork" start
    method while using a concurrent.futures.ThreadPoolExecutor.
  - gh-71936: Fix a race condition in
    multiprocessing.pool.Pool.
  - bpo-46128: Strip unittest.IsolatedAsyncioTestCase stack
    frames from reported stacktraces.
  - bpo-14074: Fix argparse metavar processing to allow
    positional arguments to have a tuple metavar.
  - IDLE
  - gh-122392: Increase currently inadequate vertical spacing
    for the IDLE browsers (path, module, and stack) on
    high-resolution monitors.
  - Documentation
  - gh-126622: Added stub pages for removed modules explaining
    their removal, where to find replacements, and linking to
    the last Python version that supported them. Contributed by
    Ned Batchelder.
  - gh-125277: Require Sphinx 7.2.6 or later to build the
    Python documentation. Patch by Adam Turner.
  - gh-124872: Added definitions for context, current
    context, and context management protocol, updated
    related definitions to be consistent, and expanded the
    documentation for contextvars.Context.
  - gh-125018: The importlib.metadata documentation now
    includes semantic cross-reference targets for the
    significant documented APIs. This means intersphinx
    references like importlib.metadata.version() will now work
    as expected.
  - gh-70870: Clarified the dual usage of the term “free
    variable” (both the formal meaning of any reference
    to names defined outside the local scope, and the
    narrower pragmatic meaning of nonlocal variables named in
    co_freevars).
  - gh-121277: Writers of CPython’s documentation can now use
    next as the version for the versionchanged, versionadded,
    deprecated directives.
  - gh-60712: Include the object type in the lists of
    documented types. Change by Furkan Onder and Martin Panter.
  - bpo-34008: The Py_Main() documentation moved from the
    “Very High Level API” section to the “Initialization and
    Finalization” section.
  - Also make it explicit that we expect Py_Main to
    typically be called instead of Py_Initialize rather
    than after it (since Py_Main makes its own call to
    Py_Initialize). Document that calling both is supported
    but is version dependent on which settings will be applied
    correctly.
  - Core and Builtins
  - gh-113841: Fix possible undefined behavior division by zero
    in complex’s _Py_c_pow().
  - gh-127020: Fix a crash in the free threading build
    when PyCode_GetCode(), PyCode_GetVarnames(),
    PyCode_GetCellvars(), or PyCode_GetFreevars() were called
    from multiple threads at the same time.
  - gh-126980: Fix __buffer__() of bytearray crashing when READ
    or WRITE are passed as flags.
  - gh-126881: Fix crash in finalization of dtoa state. Patch
    by Kumar Aditya.
  - gh-126341: Now ValueError is raised instead of SystemError
    when trying to iterate over a released memoryview object.
  - gh-126688: Fix a crash when calling os.fork() on some
    operating systems, including SerenityOS.
  - gh-126066: Fix importlib to not write an incomplete
    .pyc files when a ulimit or some other operating system
    mechanism is preventing the write to go through fully.
  - gh-126312: Fix crash during garbage collection on an object
    frozen by gc.freeze() on the free-threaded build.
  - gh-126139: Provide better error location when attempting to
    use a future statement with an unknown future feature.
  - gh-126018: Fix a crash in sys.audit() when passing a
    non-string as first argument and Python was compiled in
    debug mode.
  - gh-125942: On Android, the errors setting of sys.stdout was
    changed from surrogateescape to backslashreplace.
  - gh-125859: Fix a crash in the free threading build when
    gc.get_objects() or gc.get_referrers() is called during an
    in-progress garbage collection.
  - gh-125703: Correctly honour tracemalloc hooks in
    specialized Py_DECREF paths. Patch by Pablo Galindo
  - gh-125593: Use color to highlight error locations in
    traceback from exception group
  - gh-125444: Fix illegal instruction for older Arm
    architectures. Patch by Diego Russo, testing by Ross
    Burton.
  - gh-124375: Fix a crash in the free threading build when the
    GC runs concurrently with a new thread starting.
  - gh-125221: Fix possible race condition when calling
    __reduce_ex__() for the first time in the free threading
    build.
  - gh-125038: Fix crash when iterating over a generator
    expression after direct changes on gi_frame.f_locals. Patch
    by Mikhail Efimov.
  - gh-123378: Fix a crash in the __str__() method of
    UnicodeError objects when the UnicodeError.start and
    UnicodeError.end values are invalid or out-of-range. Patch
    by Bénédikt Tran.
  - gh-116510: Fix a crash caused by immortal interned strings
    being shared between sub-interpreters that use basic
    single-phase init. In that case, the string can be used
    by an interpreter that outlives the interpreter that
    created and interned it. For interpreters that share
    obmalloc state, also share the interned dict with the main
    interpreter.
  - gh-122878: Use the pager binary, if available (e.g. on
    Debian and derivatives), to display REPL help().
  - gh-124188: Fix reading and decoding a line from the source
    file witn non-UTF-8 encoding for syntax errors raised in
    the compiler.
  - gh-123930: Improve the error message when a script
    shadowing a module from the standard library causes
    ImportError to be raised during a “from” import. Similarly,
    improve the error message when a script shadowing a third
    party module attempts to “from” import an attribute from
    that third party module while still initialising.
  - gh-122907: Building with HAVE_DYNAMIC_LOADING
    now works as well as it did in 3.12. Existing
    deficiences will be addressed separately. (See
    https://github.com/python/cpython/issues/122950.)
  - gh-118950: Fix bug where SSLProtocol.connection_lost wasn’t
    getting called when OSError was thrown on writing to
    socket.
  - gh-113570: Fixed a bug in reprlib.repr where it incorrectly
    called the repr method on shadowed Python built-in types.
  - gh-109746: If _thread.start_new_thread() fails to start a
    new thread, it deletes its state from interpreter and thus
    avoids its repeated cleanup on finalization.
  - C API
  - gh-126554: Fix error handling in ctypes.CDLL objects which
    could result in a crash in rare situations.
  - gh-125608: Fix a bug where dictionary watchers
    (e.g., PyDict_Watch()) on an object’s attribute dictionary
    (__dict__) were not triggered when the object’s attributes
    were modified.
  - bpo-34008: Added Py_IsInitialized to the list of APIs that
    are safe to call before the interpreter is initialized, and
    updated the embedding tests to cover it.
  - Build
  - gh-123877: Set wasm32-wasip1 as the WASI target. The old
    wasm32-wasi target is deprecated so it can be used for an
    eventual WASI 1.0.
  - gh-89640: Hard-code float word ordering as little endian on
    WASM.
  - gh-125940: The Android build now supports 16 KB page sizes.
  - gh-89640: Improve detection of float word ordering on Linux
    when link-time optimizations are enabled.
  - gh-125269: Fix detection of whether -latomic is needed when
    cross-compiling CPython using the configure script.
  - gh-121634: Allow for specifying the target compile triple
    for WASI.
  - gh-122578: Use WASI SDK 24 for testing.
  - gh-115382: Fix cross compile failures when the host and
    target SOABIs match.
  - Remove upstreamed patches:
  - CVE-2024-9287-venv_path_unquoted.patch

++++ libsoup:

  - Increase test timeout on s390x. The http2-body-stream test can be
    slow and sometimes times out in our builds.

++++ libtpms:

  - Add tpm2-Add-padding-to-OBJECT-for-32bit-targets.patch
  - Update to 0.10.0:
    * tpm2: Support for profiles: default-v1 & custom
    * tpm2: Add new API call TPMLIB_SetProfile to enable user to set a
    profile
    * tpm2: Extende TPMLIB_GetInfo to return profiles-related info
    * tpm2: Implemented crypto tests and restrictions on crypto related
    to FIPS-140-3; can be enabled with profiles
    * tpm2: Enable Camellia-192 and AES-192
    * tpm2: Implement TPMLIB_WasManufactured API call
    * tpm2: Fixes for issues detected by static analyzers
    * tpm2: Use OpenSSL-based KDFe implementation if possible
    * tpm2: Update to TPM 2 spec rev 183 (many changes)
    * tpm2: Better support for OpenSSL 3.x
    * tpm2: Use Carmichael function for RSA priv. exponent D (>= 2048
    bits)
    * tpm2: Fixes for CVE-2023-1017 and CVE-2023-1018
    * tpm2: Fix of SignedCompareB().
  - NOTE: This fix may result in backwards compatibility issues with PCR
    policies used by TPM2_PolicyCounterTimer and TPM2_PolicyNV when
    upgrading from v0.9 to v0.10.

++++ liburing:

  - switch URLs to the current location on github
  - Update to 2.8
    * Add support for incrementally/partially consumed provided buffers,
    usable with the provided buffer ring support.
    * Add support for foo_and_wait_min_timeout(), where it's possible to
    define a minimum timeout for waiting to get batches of completions,
    but if that fails, extend for a longer timeout without having any
    extra context switches.
    * Add support for using different clock sources for completion waiting.
    * Great increase coverage of test cases, test case improvements and
    fixes.
    * Don't leak _GNU_SOURCE via pkb-config --cflags
    * Support for address sanitizer
    * Add examples/kdigest sample program
    * Add discard helper, test, and man page
    * Man page updates
    * Sync with kernel 6.10
    * send/recv bundle support
    * accept nowait and CQE_F_MORE
    * Add and update test cases
    * Fix io_uring_queue_init_mem() returning a value that was too small,
    potentially causing memory corruption in userspace by overwriting
    64 bytes beyond the returned value. Also add test case for that.
    * Add 64-bit length variants of io_uring_prep_{m,f}advise()
    * Add BIND/LISTEN support and helpers / man pages
    * Add io_uring_enable_rings.3 man page
    * Fix bug in io_uring_prep_read_multishot()
    * Fixup bundle test cases
    * Add fixed-hugepage test case
    * Fix io_uring_prep_fixed_fd_install.3 man page
    * Note 'len' == 0 requirement in io_uring_prep_send.3 man page
    * Fix some test cases for skipping on older kernels
  - drop (they are upstream)
    * test-buf-ring-nommap-skip-the-test-on-queue-init-ENO.patch
    * test-buf-ring-nommap-zero-the-ringbuf-memory.patch
  - add
    * 0001-test-init-mem-zero-the-ringbuf-memory.patch
    * 0001-test-rsrc_tags-use-correct-buffer-index-for-test.patch
  - cleanup spec file

++++ nvidia-open-driver-G06-signed:

  - Make sure the correct FW package is installed on non-CUDA.

++++ opensuse-migration-tool:

  - Update to version 20241204.834c66a:
    * Ensure that we do not check for Immutability in dryrun
  - Update to version 20241204.89bbbc3:
    * Add immutable check
    * Drop the echo before running sudo
    * Ensure root permissions unless --dry-run
    * Update README.md

++++ python313:

  - Update to 3.13.1:
  - Tools/Demos
  - gh-126807: Fix extraction warnings in pygettext.py caused
    by mistaking function definitions for function calls.
  - gh-126167: The iOS testbed was modified so that it can be
    used by third-party projects for testing purposes.
  - Tests
  - gh-126909: Fix test_os extended attribute tests to work on
    filesystems with 1 KiB xattr size limit.
  - gh-125041: Re-enable skipped tests for zlib on the
    s390x architecture: only skip checks of the compressed
    bytes, which can be different between zlib’s software
    implementation and the hardware-accelerated implementation.
  - gh-124295: Add translation tests to the argparse module.
  - Security
  - gh-126623: Upgrade libexpat to 2.6.4
  - gh-125140: Remove the current directory from sys.path when
    using PyREPL.
  - gh-122792: Changed IPv4-mapped ipaddress.IPv6Address to
    consistently use the mapped IPv4 address value for deciding
    properties. Properties which have their behavior fixed are
    is_multicast, is_reserved, is_link_local, is_global, and
    is_unspecified.
  - Library
  - gh-127321: pdb.set_trace() will not stop at an opcode that
    does not have an associated line number anymore.
  - gh-127303: Publicly expose EXACT_TOKEN_TYPES in
    token.__all__.
  - gh-123967: Fix faulthandler for trampoline frames. If the
    top-most frame is a trampoline frame, skip it. Patch by
    Victor Stinner.
  - gh-127182: Fix io.StringIO.__setstate__() crash, when None
    was passed as the first value.
  - gh-127217: Fix urllib.request.pathname2url() for paths
    starting with multiple slashes on Posix.
  - gh-127035: Fix shutil.which on Windows. Now it looks at
    direct match if and only if the command ends with a PATHEXT
    extension or X_OK is not in mode. Support extensionless
    files if “.” is in PATHEXT. Support PATHEXT extensions that
    end with a dot.
  - gh-122273: Support PyREPL history on Windows. Patch by
    devdanzin and Victor Stinner.
  - gh-127078: Fix issue where urllib.request.url2pathname()
    failed to discard an extra slash before a UNC drive in the
    URL path on Windows.
  - gh-126766: Fix issue where urllib.request.url2pathname()
    failed to discard any ‘localhost’ authority present in the
    URL.
  - gh-127065: Fix crash when calling a operator.methodcaller()
    instance from multiple threads in the free threading build.
  - gh-126997: Fix support of STRING and GLOBAL opcodes with
    non-ASCII arguments in pickletools. pickletools.dis()
    now outputs non-ASCII bytes in STRING, BINSTRING and
    SHORT_BINSTRING arguments as escaped (\xXX).
  - gh-126316: grp: Make grp.getgrall() thread-safe by adding a
    mutex. Patch by Victor Stinner.
  - gh-126618: Fix the representation of itertools.count
    objects when the count value is sys.maxsize.
  - gh-85168: Fix issue where urllib.request.url2pathname() and
    pathname2url() always used UTF-8 when quoting and unquoting
    file URIs. They now use the filesystem encoding and error
    handler.
  - gh-67877: Fix memory leaks when regular expression matching
    terminates abruptly, either because of a signal or because
    memory allocation fails.
  - gh-126789: Fixed the values of sysconfig.get_config_vars(),
    sysconfig.get_paths(), and their siblings when the site
    initialization happens after sysconfig has built a cache
    for sysconfig.get_config_vars().
  - gh-126188: Update bundled pip to 24.3.1
  - gh-126780: Fix os.path.normpath() for drive-relative paths
    on Windows.
  - gh-126766: Fix issue where urllib.request.url2pathname()
    failed to discard two leading slashes introducing an empty
    authority section.
  - gh-126727: locale.nl_langinfo(locale.ERA) now returns
    multiple era description segments separated by
    semicolons. Previously it only returned the first segment
    on platforms with Glibc.
  - gh-126699: Allow collections.abc.AsyncIterator to be a base
    for Protocols.
  - gh-126654: Fix crash when non-dict was passed to several
    functions in _interpreters module.
  - gh-104745: Limit starting a patcher (from
    unittest.mock.patch() or unittest.mock.patch.object()) more
    than once without stopping it
  - gh-126595: Fix a crash when instantiating itertools.count
    with an initial count of sys.maxsize on debug builds. Patch
    by Bénédikt Tran.
  - gh-120423: Fix issue where urllib.request.pathname2url()
    mishandled Windows paths with embedded forward slashes.
  - gh-126565: Improve performances of zipfile.Path.open() for
    non-reading modes.
  - gh-126505: Fix bugs in compiling case-insensitive regular
    expressions with character classes containing non-BMP
    characters: upper-case non-BMP character did was ignored
    and the ASCII flag was ignored when matching a character
    range whose upper bound is beyond the BMP region.
  - gh-117378: Fixed the multiprocessing "forkserver"
    start method forkserver process to correctly inherit
    the parent’s sys.path during the importing of
    multiprocessing.set_forkserver_preload() modules in the
    same manner as sys.path is configured in workers before
    executing work items.
  - This bug caused some forkserver module preloading to
    silently fail to preload. This manifested as a performance
    degration in child processes when the sys.path was required
    due to additional repeated work in every worker.
  - It could also have a side effect of "" remaining in
    sys.path during forkserver preload imports instead of the
    absolute path from os.getcwd() at multiprocessing import
    time used in the worker sys.path.
  - The sys.path differences between phases in the child
    process could potentially have caused preload to import
    incorrect things from the wrong location. We are unaware of
    that actually having happened in practice.
  - gh-125679: The multiprocessing.Lock and
    multiprocessing.RLock repr values no longer say “unknown”
    on macOS.
  - gh-126476: Raise calendar.IllegalMonthError (now a subclass
    of IndexError) for calendar.month() when the input month is
    not correct.
  - gh-126489: The Python implementation of pickle no longer
    calls pickle.Pickler.persistent_id() for the result of
    persistent_id().
  - gh-126313: Fix an issue in curses.napms() when
    curses.initscr() has not yet been called. Patch by Bénédikt
    Tran.
  - gh-126303: Fix pickling and copying of os.sched_param
    objects.
  - gh-126138: Fix a use-after-free crash on asyncio.Task
    objects whose underlying coroutine yields an object that
    implements an evil __getattribute__(). Patch by Nico
    Posada.
  - gh-126220: Fix crash in cProfile.Profile and
    _lsprof.Profiler when their callbacks were directly called
    with 0 arguments.
  - gh-126212: Fix issue where urllib.request.pathname2url()
    and url2pathname() removed slashes from Windows DOS drive
    paths and URLs.
  - gh-126223: Raise a UnicodeEncodeError instead of a
    SystemError upon calling _interpreters.create() with an
    invalid Unicode character.
  - gh-126205: Fix issue where urllib.request.pathname2url()
    generated URLs beginning with four slashes (rather than
    two) when given a Windows UNC path.
  - gh-126105: Fix a crash in ast when the ast.AST._fields
    attribute is deleted.
  - gh-126106: Fixes a possible NULL pointer dereference in
    ssl.
  - gh-126080: Fix a use-after-free crash on asyncio.Task
    objects for which the underlying event loop implements an
    evil __getattribute__(). Reported by Nico-Posada. Patch by
    Bénédikt Tran.
  - gh-126083: Fixed a reference leak in asyncio.Task objects
    when reinitializing the same object with a non-None
    context. Patch by Nico Posada.
  - gh-125984: Fix use-after-free crashes on asyncio.Future
    objects for which the underlying event loop implements an
    evil __getattribute__(). Reported by Nico-Posada. Patch by
    Bénédikt Tran.
  - gh-125969: Fix an out-of-bounds crash when an evil
    asyncio.loop.call_soon() mutates the length of the internal
    callbacks list. Patch by Bénédikt Tran.
  - gh-125966: Fix a use-after-free crash in
    asyncio.Future.remove_done_callback(). Patch by Bénédikt
    Tran.
  - gh-125789: Fix possible crash when mutating list of
    callbacks returned by asyncio.Future._callbacks. It
    now always returns a new copy in C implementation
    _asyncio. Patch by Kumar Aditya.
  - gh-124452: Fix an issue in
    email.policy.EmailPolicy.header_source_parse() and
    email.policy.Compat32.header_source_parse() that introduced
    spurious leading whitespaces into header values when the
    header includes a newline character after the header name
    delimiter (:) and before the value.
  - gh-125884: Fixed the bug for pdb where it can’t set
    breakpoints on functions with certain annotations.
  - gh-125355: Fix several bugs in
    argparse.ArgumentParser.parse_intermixed_args().
  - The parser no longer changes temporarily during
    parsing.
  - Default values are not processed twice.
  - Required mutually exclusive groups containing
    positional arguments are now supported.
  - The missing arguments report now includes the names of
    all required optional and positional arguments.
  - Unknown options can be intermixed with positional
    arguments in parse_known_intermixed_args().
  - gh-125666: Avoid the exiting the interpreter if a null byte
    is given as input in the new REPL.
  - gh-125710: [Enum] fix hashable<->nonhashable comparisons
    for member values
  - gh-125631: Restore ability to set persistent_id and
    persistent_load attributes of instances of the Pickler and
    Unpickler classes in the pickle module.
  - gh-125378: Fixed the bug in pdb where after a multi-line
    command, an empty line repeats the first line of the
    multi-line command, instead of the full command.
  - gh-125682: Reject non-ASCII digits in the Python
    implementation of json.loads() conforming to the JSON
    specification.
  - gh-125660: Reject invalid unicode escapes for Python
    implementation of json.loads().
  - gh-125259: Fix the notes removal logic for errors thrown in
    enum initialization.
  - gh-125590: Allow FrameLocalsProxy to delete and pop if the
    key is not a fast variable.
  - gh-125519: Improve traceback if importlib.reload() is
    called with an object that is not a module. Patch by Alex
    Waygood.
  - gh-125451: Fix deadlock when
    concurrent.futures.ProcessPoolExecutor shuts down
    concurrently with an error when feeding a job to a worker
    process.
  - gh-125422: Fixed the bug where pdb and bdb can step into
    the bottom caller frame.
  - gh-100141: Fixed the bug where pdb will be stuck in an
    infinite loop when debugging an empty file.
  - gh-125115: Fixed a bug in pdb where arguments starting with
  - can’t be passed to the debugged script.
  - gh-53203: Fix time.strptime() for %c, %x and %X formats
    in many locales that use non-ASCII digits, like Persian,
    Burmese, Odia and Shan.
  - gh-125398: Fix the conversion of the VIRTUAL_ENV path in
    the activate script in venv when running in Git Bash for
    Windows.
  - gh-125316: Fix using functools.partial() as enum.Enum
    member. A FutureWarning with suggestion to use
    enum.member() is now emitted when the partial instance is
    used as an enum member.
  - gh-125245: Fix race condition when importing
    collections.abc, which could incorrectly return an empty
    module.
  - gh-125243: Fix data race when creating zoneinfo.ZoneInfo
    objects in the free threading build.
  - gh-125254: Fix a bug where ArgumentError includes the
    incorrect ambiguous option in argparse.
  - gh-125235: Keep tkinter TCL paths in venv pointing to base
    installation on Windows.
  - gh-61011: Fix inheritance of nested mutually
    exclusive groups from parent parser in
    argparse.ArgumentParser. Previously, all nested mutually
    exclusive groups lost their connection to the group
    containing them and were displayed as belonging directly to
    the parser.
  - gh-52551: Fix encoding issues in time.strftime(), the
    strftime() method of the datetime classes datetime, date
    and time and formatting of these classes. Characters
    not encodable in the current locale are now acceptable
    in the format string. Surrogate pairs and sequence
    of surrogatescape-encoded bytes are no longer
    recombinated. Embedded null character no longer terminates
    the format string.
  - gh-125118: Don’t copy arbitrary values to _Bool in the
    struct module.
  - gh-125069: Fix an issue where providing a pathlib.PurePath
    object as an initializer argument to a second PurePath
    object with a different parser resulted in arguments to
    the former object’s initializer being joined by the latter
    object’s parser.
  - gh-125096: If the PYTHON_BASIC_REPL environment variable
    is set, the site module no longer imports the _pyrepl
    module. Moreover, the site module now respects -E and -I
    command line options: ignore PYTHON_BASIC_REPL in this
    case. Patch by Victor Stinner.
  - gh-124969: Fix locale.nl_langinfo(locale.ALT_DIGITS) on
    platforms with glibc. Now it returns a string consisting of
    up to 100 semicolon-separated symbols (an empty string in
    most locales) on all Posix platforms. Previously it only
    returned the first symbol or an empty string.
  - gh-124960: Fix support for the barry_as_FLUFL future flag
    in the new REPL.
  - gh-124984: Fixed thread safety in ssl in the free-threaded
    build. OpenSSL operations are now protected by a per-object
    lock.
  - gh-124958: Fix refcycles in exceptions raised from
    asyncio.TaskGroup and the python implementation of
    asyncio.Future
  - gh-53203: Fix time.strptime() for %c and %x formats in many
    locales: Arabic, Bislama, Breton, Bodo, Kashubian, Chuvash,
    Estonian, French, Irish, Ge’ez, Gurajati, Manx Gaelic,
    Hebrew, Hindi, Chhattisgarhi, Haitian Kreyol, Japanese,
    Kannada, Korean, Marathi, Malay, Norwegian, Nynorsk,
    Punjabi, Rajasthani, Tok Pisin, Yoruba, Yue Chinese,
    Yau/Nungon and Chinese.
  - gh-124917: Allow calling os.path.exists() and
    os.path.lexists() with keyword arguments on Windows. Fixes
    a regression in 3.13.0.
  - gh-124653: Fix detection of the minimal Queue API needed by
    the logging module. Patch by Bénédikt Tran.
  - gh-124858: Fix reference cycles left in tracebacks
    in asyncio.open_connection() when used with
    happy_eyeballs_delay
  - gh-124390: Fixed AssertionError when using
    asyncio.staggered.staggered_race() with
    asyncio.eager_task_factory.
  - gh-124651: Properly quote template strings in venv
    activation scripts (bsc#1232241, CVE-2024-9287).
  - gh-116850: Fix argparse for namespaces with not directly
    writable dict (e.g. classes).
  - gh-58573: Fix conflicts between abbreviated long options in
    the parent parser and subparsers in argparse.
  - gh-124594: All asyncio REPL prompts run in the same
    context. Contributed by Bartosz Sławecki.
  - gh-61181: Fix support of choices with string value in
    argparse. Substrings of the specified string no longer
    considered valid values.
  - gh-80259: Fix argparse support of positional arguments with
    nargs='?', default=argparse.SUPPRESS and specified type.
  - gh-120378: Fix a crash related to an integer overflow in
    curses.resizeterm() and curses.resize_term().
  - gh-123884: Fixed bug in itertools.tee() handling of other
    tee inputs (a tee in a tee). The output now has the
    promised n independent new iterators. Formerly, the first
    iterator was identical (not independent) to the input
    iterator. This would sometimes give surprising results.
  - gh-58956: Fixed a bug in pdb where sometimes the breakpoint
    won’t trigger if it was set on a function which is already
    in the call stack.
  - gh-124345: argparse vim supports abbreviated single-dash
    long options separated by = from its value.
  - gh-104860: Fix disallowing abbreviation of single-dash long
    options in argparse with allow_abbrev=False.
  - gh-63143: Fix parsing mutually exclusive arguments in
    argparse. Arguments with the value identical to the default
    value (e.g. booleans, small integers, empty or 1-character
    strings) are no longer considered “not present”.
  - gh-72795: Positional arguments with nargs equal to '*' or
    argparse.REMAINDER are no longer required. This allows to
    use positional argument with nargs='*' and without default
    in mutually exclusive group and improves error message
    about required arguments.
  - gh-59317: Fix parsing positional argument with nargs equal
    to '?' or '*' if it is preceded by an option and another
    positional argument.
  - gh-53780: argparse now ignores the first "--" (double dash)
    between an option and command.
  - gh-124217: Add RFC 9637 reserved IPv6 block 3fff::/20 in
    ipaddress module.
  - gh-81691: Fix handling of multiple "--" (double dashes)
    in argparse. Only the first one has now been removed, all
    subsequent ones are now taken literally.
  - gh-123978: Remove broken time.thread_time() and
    time.thread_time_ns() on NetBSD.
  - gh-124008: Fix possible crash (in debug build), incorrect
    output or returning incorrect value from raw binary write()
    when writing to console on Windows.
  - gh-123935: Fix parent slots detection for dataclasses that
    inherit from classes with __dictoffset__.
  - gh-122765: Fix unbalanced quote errors occurring when
    activate.csh in venv was sourced with a custom prompt
    containing unpaired quotes or newlines.
  - gh-123370: Fix the canvas not clearing after running
    turtledemo clock.
  - gh-116810: Resolve a memory leak introduced in CPython
    3.10’s ssl when the ssl.SSLSocket.session property was
    accessed. Speeds up read and write access to said property
    by no longer unnecessarily cloning session objects via
    serialization.
  - gh-120754: Update unbounded read calls in zipfile to
    specify an explicit size putting a limit on how much data
    they may read. This also updates handling around ZIP max
    comment size to match the standard instead of reading
    comments that are one byte too long.
  - gh-70764: Fixed an issue where inspect.getclosurevars()
    would incorrectly classify an attribute name as a global
    variable when the name exists both as an attribute name and
    a global variable.
  - gh-118289: posixpath.realpath() now raises
    NotADirectoryError when strict mode is enabled and a
    non-directory path with a trailing slash is supplied.
  - gh-119826: Always return an absolute path for
    os.path.abspath() on Windows.
  - gh-117766: Always use str() to print choices in argparse.
  - gh-101955: Fix SystemError when match regular expression
    pattern containing some combination of possessive
    quantifier, alternative and capture group.
  - gh-88110: Fixed multiprocessing.Process reporting a
    .exitcode of 1 even on success when using the "fork" start
    method while using a concurrent.futures.ThreadPoolExecutor.
  - gh-71936: Fix a race condition in
    multiprocessing.pool.Pool.
  - bpo-46128: Strip unittest.IsolatedAsyncioTestCase stack
    frames from reported stacktraces.
  - bpo-14074: Fix argparse metavar processing to allow
    positional arguments to have a tuple metavar.
  - IDLE
  - gh-122392: Increase currently inadequate vertical spacing
    for the IDLE browsers (path, module, and stack) on
    high-resolution monitors.
  - Documentation
  - gh-126622: Added stub pages for removed modules explaining
    their removal, where to find replacements, and linking to
    the last Python version that supported them. Contributed by
    Ned Batchelder.
  - gh-125277: Require Sphinx 7.2.6 or later to build the
    Python documentation. Patch by Adam Turner.
  - gh-124872: Added definitions for context, current
    context, and context management protocol, updated
    related definitions to be consistent, and expanded the
    documentation for contextvars.Context.
  - gh-125018: The importlib.metadata documentation now
    includes semantic cross-reference targets for the
    significant documented APIs. This means intersphinx
    references like importlib.metadata.version() will now work
    as expected.
  - gh-70870: Clarified the dual usage of the term “free
    variable” (both the formal meaning of any reference
    to names defined outside the local scope, and the
    narrower pragmatic meaning of nonlocal variables named in
    co_freevars).
  - gh-121277: Writers of CPython’s documentation can now use
    next as the version for the versionchanged, versionadded,
    deprecated directives.
  - gh-60712: Include the object type in the lists of
    documented types. Change by Furkan Onder and Martin Panter.
  - bpo-34008: The Py_Main() documentation moved from the
    “Very High Level API” section to the “Initialization and
    Finalization” section.
  - Also make it explicit that we expect Py_Main to
    typically be called instead of Py_Initialize rather
    than after it (since Py_Main makes its own call to
    Py_Initialize). Document that calling both is supported
    but is version dependent on which settings will be applied
    correctly.
  - Core and Builtins
  - gh-113841: Fix possible undefined behavior division by zero
    in complex’s _Py_c_pow().
  - gh-127020: Fix a crash in the free threading build
    when PyCode_GetCode(), PyCode_GetVarnames(),
    PyCode_GetCellvars(), or PyCode_GetFreevars() were called
    from multiple threads at the same time.
  - gh-126980: Fix __buffer__() of bytearray crashing when READ
    or WRITE are passed as flags.
  - gh-126881: Fix crash in finalization of dtoa state. Patch
    by Kumar Aditya.
  - gh-126341: Now ValueError is raised instead of SystemError
    when trying to iterate over a released memoryview object.
  - gh-126688: Fix a crash when calling os.fork() on some
    operating systems, including SerenityOS.
  - gh-126066: Fix importlib to not write an incomplete
    .pyc files when a ulimit or some other operating system
    mechanism is preventing the write to go through fully.
  - gh-126312: Fix crash during garbage collection on an object
    frozen by gc.freeze() on the free-threaded build.
  - gh-126139: Provide better error location when attempting to
    use a future statement with an unknown future feature.
  - gh-126018: Fix a crash in sys.audit() when passing a
    non-string as first argument and Python was compiled in
    debug mode.
  - gh-125942: On Android, the errors setting of sys.stdout was
    changed from surrogateescape to backslashreplace.
  - gh-125859: Fix a crash in the free threading build when
    gc.get_objects() or gc.get_referrers() is called during an
    in-progress garbage collection.
  - gh-125703: Correctly honour tracemalloc hooks in
    specialized Py_DECREF paths. Patch by Pablo Galindo
  - gh-125593: Use color to highlight error locations in
    traceback from exception group
  - gh-125444: Fix illegal instruction for older Arm
    architectures. Patch by Diego Russo, testing by Ross
    Burton.
  - gh-124375: Fix a crash in the free threading build when the
    GC runs concurrently with a new thread starting.
  - gh-125221: Fix possible race condition when calling
    __reduce_ex__() for the first time in the free threading
    build.
  - gh-125038: Fix crash when iterating over a generator
    expression after direct changes on gi_frame.f_locals. Patch
    by Mikhail Efimov.
  - gh-123378: Fix a crash in the __str__() method of
    UnicodeError objects when the UnicodeError.start and
    UnicodeError.end values are invalid or out-of-range. Patch
    by Bénédikt Tran.
  - gh-116510: Fix a crash caused by immortal interned strings
    being shared between sub-interpreters that use basic
    single-phase init. In that case, the string can be used
    by an interpreter that outlives the interpreter that
    created and interned it. For interpreters that share
    obmalloc state, also share the interned dict with the main
    interpreter.
  - gh-122878: Use the pager binary, if available (e.g. on
    Debian and derivatives), to display REPL help().
  - gh-124188: Fix reading and decoding a line from the source
    file witn non-UTF-8 encoding for syntax errors raised in
    the compiler.
  - gh-123930: Improve the error message when a script
    shadowing a module from the standard library causes
    ImportError to be raised during a “from” import. Similarly,
    improve the error message when a script shadowing a third
    party module attempts to “from” import an attribute from
    that third party module while still initialising.
  - gh-122907: Building with HAVE_DYNAMIC_LOADING
    now works as well as it did in 3.12. Existing
    deficiences will be addressed separately. (See
    https://github.com/python/cpython/issues/122950.)
  - gh-118950: Fix bug where SSLProtocol.connection_lost wasn’t
    getting called when OSError was thrown on writing to
    socket.
  - gh-113570: Fixed a bug in reprlib.repr where it incorrectly
    called the repr method on shadowed Python built-in types.
  - gh-109746: If _thread.start_new_thread() fails to start a
    new thread, it deletes its state from interpreter and thus
    avoids its repeated cleanup on finalization.
  - C API
  - gh-126554: Fix error handling in ctypes.CDLL objects which
    could result in a crash in rare situations.
  - gh-125608: Fix a bug where dictionary watchers
    (e.g., PyDict_Watch()) on an object’s attribute dictionary
    (__dict__) were not triggered when the object’s attributes
    were modified.
  - bpo-34008: Added Py_IsInitialized to the list of APIs that
    are safe to call before the interpreter is initialized, and
    updated the embedding tests to cover it.
  - Build
  - gh-123877: Set wasm32-wasip1 as the WASI target. The old
    wasm32-wasi target is deprecated so it can be used for an
    eventual WASI 1.0.
  - gh-89640: Hard-code float word ordering as little endian on
    WASM.
  - gh-125940: The Android build now supports 16 KB page sizes.
  - gh-89640: Improve detection of float word ordering on Linux
    when link-time optimizations are enabled.
  - gh-125269: Fix detection of whether -latomic is needed when
    cross-compiling CPython using the configure script.
  - gh-121634: Allow for specifying the target compile triple
    for WASI.
  - gh-122578: Use WASI SDK 24 for testing.
  - gh-115382: Fix cross compile failures when the host and
    target SOABIs match.
  - Remove upstreamed patches:
  - CVE-2024-9287-venv_path_unquoted.patch

++++ python-MarkupSafe:

  - The test suite survives without
    ca-certificates-mozilla-prebuilt now, so we can remove BR (and
    avoid deadly cycles).

++++ python-bcrypt:

  - Update to 4.2.1
    * Bump version for 4.2.1 (#914)
    * Bump bcrypt from 0.15.1 to 0.16.0 in /src/_bcrypt (#912)
    * Fix warnings from pyo3 0.23 (#911)
    * Bump pyo3 from 0.22.6 to 0.23.1 in /src/_bcrypt (#909)
    * Bump libc from 0.2.162 to 0.2.164 in /src/_bcrypt (#910)
    * Bump cpufeatures from 0.2.14 to 0.2.15 in /src/_bcrypt (#908)
    * Bump libc from 0.2.161 to 0.2.162 in /src/_bcrypt (#907)
    * Bump pypa/gh-action-pypi-publish from 1.12.0 to 1.12.2 (#906)
    * Bump pyo3 from 0.22.5 to 0.22.6 in /src/_bcrypt (#905)
    * Bump pypa/gh-action-pypi-publish from 1.11.0 to 1.12.0 (#904)
    * Bump syn from 2.0.86 to 2.0.87 in /src/_bcrypt (#903)
    * Bump syn from 2.0.85 to 2.0.86 in /src/_bcrypt (#902)
    * Bump pypa/gh-action-pypi-publish from 1.10.3 to 1.11.0 (#901)
    * Bump actions/setup-python from 5.2.0 to 5.3.0 (#899)
    * Bump syn from 2.0.82 to 2.0.85 in /src/_bcrypt (#898)
    * Bump actions/checkout from 4.2.1 to 4.2.2 (#897)
    * Bump actions/cache from 4.1.1 to 4.1.2 (#896)
    * Bump proc-macro2 from 1.0.88 to 1.0.89 in /src/_bcrypt (#895)
    * Bump syn from 2.0.79 to 2.0.82 in /src/_bcrypt (#894)
    * Bump libc from 0.2.159 to 0.2.161 in /src/_bcrypt (#893)
    * Bump proc-macro2 from 1.0.87 to 1.0.88 in /src/_bcrypt (#892)
    * Bump pyo3 from 0.22.4 to 0.22.5 in /src/_bcrypt (#891)
    * Bump pyo3 from 0.22.3 to 0.22.4 in /src/_bcrypt (#890)
    * Update CI for 3.13 (#888)
    * Bump actions/upload-artifact from 4.4.2 to 4.4.3 (#889)
    * Bump actions/upload-artifact from 4.4.1 to 4.4.2 (#886)
    * Bump actions/cache from 4.1.0 to 4.1.1 (#887)
    * Bump proc-macro2 from 1.0.86 to 1.0.87 in /src/_bcrypt (#884)
    * Bump actions/upload-artifact from 4.4.0 to 4.4.1 (#883)
    * Bump actions/checkout from 4.2.0 to 4.2.1 (#882)
    * Bump actions/cache from 4.0.2 to 4.1.0 (#881)
    * Bump once_cell from 1.20.1 to 1.20.2 in /src/_bcrypt (#880)
    * Bump once_cell from 1.20.0 to 1.20.1 in /src/_bcrypt (#878)
    * Bump portable-atomic from 1.8.0 to 1.9.0 in /src/_bcrypt (#877)
    * Bump syn from 2.0.77 to 2.0.79 in /src/_bcrypt (#879)
    * Bump autocfg from 1.3.0 to 1.4.0 in /src/_bcrypt (#876)
    * Bump actions/checkout from 4.1.7 to 4.2.0 (#875)
    * Bump libc from 0.2.158 to 0.2.159 in /src/_bcrypt (#874)
    * Bump portable-atomic from 1.7.0 to 1.8.0 in /src/_bcrypt (#873)
    * Bump once_cell from 1.19.0 to 1.20.0 in /src/_bcrypt (#871)
    * Bump pyo3 from 0.22.2 to 0.22.3 in /src/_bcrypt (#872)
    * Bump unicode-ident from 1.0.12 to 1.0.13 in /src/_bcrypt (#870)
    * Bump cpufeatures from 0.2.13 to 0.2.14 in /src/_bcrypt (#869)
    * Bump actions/attest-build-provenance from 1.4.2 to 1.4.3 (#868)
    * Correctly use `console` language fence (#867)
    * Bump actions/upload-artifact from 4.3.6 to 4.4.0 (#866)
    * Bump syn from 2.0.76 to 2.0.77 in /src/_bcrypt (#865)
    * Bump actions/setup-python from 5.1.1 to 5.2.0 (#862)
    * Bump syn from 2.0.75 to 2.0.76 in /src/_bcrypt (#861)
    * Bump actions/attest-build-provenance from 1.4.1 to 1.4.2 (#859)
    * Bump quote from 1.0.36 to 1.0.37 in /src/_bcrypt (#858)
    * Bump libc from 0.2.157 to 0.2.158 in /src/_bcrypt (#857)
    * Bump syn from 2.0.74 to 2.0.75 in /src/_bcrypt (#855)
    * Bump libc from 0.2.156 to 0.2.157 in /src/_bcrypt (#856)
    * Bump libc from 0.2.155 to 0.2.156 in /src/_bcrypt (#854)
    * Bump cpufeatures from 0.2.12 to 0.2.13 in /src/_bcrypt (#853)
    * Bump syn from 2.0.72 to 2.0.74 in /src/_bcrypt (#851)
    * Bump actions/attest-build-provenance from 1.4.0 to 1.4.1 (#852)
    * Bump actions/upload-artifact from 4.3.5 to 4.3.6 (#850)
    * Bump actions/upload-artifact from 4.3.4 to 4.3.5 (#849)
    * Bump target-lexicon from 0.12.15 to 0.12.16 in /src/_bcrypt (#848)
    * Bump actions/attest-build-provenance from 1.3.3 to 1.4.0 (#847)
    * Bump version_check from 0.9.4 to 0.9.5 in /src/_bcrypt (#846)
    * Fix pypi-publish.yml for paths with spaces (#844)

++++ python-rpds-py:

  - Update to version 0.21.0:
    * Release v0.21.0
    * Oh hello there zizmor.
    * Add a link to the upstream repo.
    * The packaging docs apparently discourage license.
    * bump pyO3 to 0.22.6
    * Update requirements.
    * Drop support for 3.8, which is EOL.
    * Bump to 0.20.1.
    * Set --profile=dev in tests to catch issues like #86.
    * Bump pyo3 from 0.22.3 to 0.22.5
    * Bump wntrblm/nox from 2024.04.15 to 2024.10.09
    * [pre-commit.ci] pre-commit autoupdate
    * Bump pyo3 from 0.22.2 to 0.22.3
    * Bump archery from 1.2.0 to 1.2.1
    * Fix hashing overflow issues
    * Tag a release.
    * Minor comment typo.
    * [pre-commit.ci] pre-commit autoupdate
    * Bump hynek/setup-cached-uv from 1 to 2
    * Tag a release.
    * Bump pyo3 from 0.22.1 to 0.22.2
    * Better result handling
    * Fix ruff configuration section
    * Fix styling
    * Turn on hashing tests for HashTrieMap
    * Remove hash error handling for elements in HashTrieSet
    * Implement __hash__ for HashTrieMap
    * Fix tests
    * Remove __hash__ for HashTrieMap
    * Fix testing
    * Re-implement __hash__ for unordered collections
    * Make Python versions in GitHub Actions consistent
    * Move to the v4 artifact actions.
    * Newer ruff + minor linter tweaks.
    * Let pre-commit.ci handle pre-commit.
    * uv in the noxfile and CI.
    * Add the 3.13 classifier.
    * Bump to 0.19.0
    * Update requirements.
    * Revise inline comments
    * Implement __hash__ for HashTrieMap
    * Add __hash__ to ListPy
    * Implement __hash__ for HashTrieSetPy
    * Update PyO3 from 0.22.0 to 0.22.1
    * Use #[derive(FromPyObject)] instead of manual impl
    * Remove redundant Python::wiht_gil calls
    * Add Python 3.13 to GitHub actions CI
    * Fix clippy warnings
    * Remove redundant Python::with_gil calls
    * Fix formatting
    * WIP
    * WIP
    * Bump pyo3 from 0.20.3 to 0.22.0
    * [pre-commit.ci] pre-commit autoupdate
    * deps: bump libc from 0.2.147 to 0.2.155
    * WIP
    * Tag a release for PyO3 0.20.3 support.
    * [pre-commit.ci] pre-commit autoupdate
    * Update requirements.
    * [pre-commit.ci] pre-commit autoupdate
    * Bump wntrblm/nox from 2024.03.02 to 2024.04.15
    * [pre-commit.ci] pre-commit autoupdate
    * [pre-commit.ci] pre-commit autoupdate
    * Bump softprops/action-gh-release from 1 to 2
    * Bump wntrblm/nox from 2023.04.22 to 2024.03.02
    * Bump archery from 1.1.0 to 1.2.0
    * Bump pyo3 from 0.20.2 to 0.20.3
    * I'm one person, not two.
    * [pre-commit.ci] pre-commit autoupdate
    * Type annotation and test for HashTrieMap.update.
    * [pre-commit.ci] pre-commit autoupdate
    * Bump pre-commit/action from 3.0.0 to 3.0.1
    * [pre-commit.ci] auto fixes from pre-commit.com hooks
    * [pre-commit.ci] pre-commit autoupdate
    * Implement Queue.__hash__.
    * Explicitly remind ourselves that dict.values != dict.values in the tests.
    * Yet again, same mistake.
    * Remove a non-doc dependency.
    * Reimplement view types for maps.
    * Start reworking the HashTrieMap methods that should return views.
    * And same for HashTrieMap.
    * And now an iterator for HashTrieSet.
    * Trim down the manual Py wrapping too.
    * Proper List + Queue iterators.
    * Bump pyo3 from 0.20.1 to 0.20.2
    * Bump pyo3 from 0.20.0 to 0.20.1
    * Type annotation for fromkeys.
    * Release v0.16.1
    * Add HashTrieMap.fromkeys with dict.fromkeys' signature.
    * [pre-commit.ci] pre-commit autoupdate
    * Fix the Queue type annotations.
    * Install cargo in RTD.
    * Release v0.15.0 for docs!
    * Still install the package obviously, and minor spelling and style fix.
    * Enable the rest of the ruff rulesets.
    * Simple docs.
    * Fix HashTrieMap.get to properly take 2 arguments.
    * Le type annotacions
    * Expose rpds.Queue.
    * [pre-commit.ci] pre-commit autoupdate
    * Bump actions/setup-python from 4 to 5
    * Update pre-commit hooks.
    * Fix HashTrieMap __repr__s, which need to repr() the key as well.
    * Add the explicit Tidelift link.
    * Release v0.13.1.
    * Fix `drop_first` method name for typing
    * Release v0.13.0
    * Configure Black in pyproject.toml
    * [pre-commit.ci] auto fixes from pre-commit.com hooks
    * Add pickle support
    * [pre-commit.ci] pre-commit autoupdate
    * Bump rpds from 1.0.1 to 1.1.0
    * That's what I get for copy/paste.
    * Skip Rust on pre-commit.ci which doesn't seem to have Rust installed.
    * Bump archery from 1.0.0 to 1.1.0
    * List.drop_front
    * Update for PyO3 0.20.0.
    * Update pre-commit hooks.
    * [pre-commit.ci] pre-commit autoupdate
    * Publish to PyPI using trusted publishing.
    * Try enabling sccache.
    * Build wheel for Windows on Python 3.12
    * Give up entirely for now.
    * Flail again for Windows.
    * There is apparently no --release argument for sdist.
    * Build an sdist in a separate explicit job.
    * Give up for  now. Let's get 3.12 working.
    * Take 3 on PyPy+Windows.
    * Try again to get PyPy 3.x versions on Windows.
    * Drop PyPy 3.8 which seems to fail.
    * Release v0.10.4
    * Try building wheels for more Windows interpreters as well.
    * Release v0.10.3
    * Update test dependencies.
    * Remove an unused test dependency on hypothesis
    * Bump rpds from 1.0.0 to 1.0.1
    * Bump actions/checkout from 3 to 4
    * Release v0.10.2
    * Update pre-commit hooks.
    * Enable clippy and fix what it complains about.
    * Update requirements.
    * Don't use nox.session.create_tmp.
    * Release 0.10.0.
    * Unused.
    * Bump rpds from 0.13.0 to 1.0.0
    * Bump pyo3 from 0.19.1 to 0.19.2
    * Add a security policy.
    * More correct listing of nox envs for the GitHub actions workflow
    * Bump archery from 0.5.0 to 1.0.0
    * Take 3, try using setup-python with multiple versions.
    * Try enabling pre-releases in the setup-python action.
    * Declare support for 3.12.
    * Link to rpds.
    * Update deps and bump the version.
    * Update target-lexicon to support loongarch64 architecture
    * Again forget to bump the version properly...
    * Try adding wheels for PyPy3.10 and CPython 3.12
    * Also build wheels for macOS 3.9 and others.
    * Add a note on installation instructions (and the need for rust).
    * One more wheel for aarch64.
    * Fix the needs list as well.
    * Let's see if this gets us MUSL wheels.
    * Fix the badge URLs.
    * Sigh and the lock too...
    * Actually bump the version to 0.8.3.
    * Add the missing Project URLs for PyPI
    * Add rpds to known_first_party for isort.
    * Bump to PyO3 v0.19
    * Bump pre-commit.
    * Bump wntrblm/nox from 2022.11.21 to 2023.04.22
    * Update pre-commit hooks.
    * Bump pyo3 from 0.18.2 to 0.18.3
    * Bump pyo3 from 0.18.1 to 0.18.2
    * Exclude bots from release notes.

++++ swtpm:

  - Update to 0.10.0:
    + swtpm:
    * Requires libtpms v0.10.0
    * Display tpmstate-opt-lock as a new capability
    * Add support for lock option parameter to tpmstate option
    * nvstore_linear: Add support for file-backend locking
    * Remove broken logic to check for neither dir nor file backend
    * Use ptm_cap_n to build PTM_GET_CAPABILITY response
    * Define a structure to return PTM_GET_CAPABILITY result
    * Implement --print-info to run TPMLIB_GetInfo with flags
    * Support --profile fd= to read profile from file descriptor
    * Support --profile file= to read profile from file
    * Ignore remove-disabled parameter on non-'custom' profile
    * Check for good entropy source in chroot environment
    * Implement a check for HMAC+sha1 for testing future restriction
    * Implement function to check whether a crypto algorithm is
    disabled
    * Print cmdarg-print-profiles as part of capabilities
    * Check whether SHA1 signature support is disabled in profile
    * Use TPMLIB_WasManufactured to check whether profile was applied
    * Determine whether OpenSSL needs to be configured (FIPs, SHA1
    signature)
    * Add support for --print-profiles option
    * Print profile names as part of capabilities JSON
    * Display new capability to allow setting a profile
    * Add support for --profile option to set a profile on TPM 2
    + swtpm_setup:
    * Comment flags for storage primary key and deprecate --create-spk
    * Implement --print-profiles to display all profile
    * Add profile entries to swtpm_setup.conf written by swtpm_setup
    * Add support for --profile-name option
    * Accept profiles with name starting with 'custom:'
    * Support default profile from file in swtpm_setup.conf
    * Support --profile-file-fd to read profile from file descriptor
    * Support --profile-file to read profile from file
    * Always log the active profile
    * Implement --profile-remove-fips-disabled option
    * Read default profile from swtpm_setup.conf
    * Print profile names as part of capabilities JSON
    * Add support for --profile parameter
    * Get default rsa keysize from setup_setup.conf if not given
    + swtpm_ioctl:
    * Use ptm_cap_n for non-CUSE PTM_GET_CAPABILITY response
    + selinux:
    * Change write to append for appending to log
    * Add rule for logging to svirt_image_t labeled files from swtpm_t
    + tests:
    * Update IBMTSS2 test suite to v2.4.0
    * Test activation of PCR banks when not all are available
    * Enable SWTPM_TEST_PROFILE for running test_tpm2_ibmtss2 with
    profile
    * Add a check for OPENSSL_ENABLE_SHA1_SIGNATURES in log file
    * Consolidate custom profile test cases and check for
    StateFormatLevel
    * Convert test_samples_create_tpmca to run installed
    * Mention test_tpm2_libtpms_versions_profiles requiring
    env. variables
    * allow running ibmtss2 tests against installed version
    * Derive support for CUSE from SWTPM_EXE help screen
    * Set OPENSSL_ENABLE_SHA1_SIGNATURES=1 for IBMTSS2 test
    * Extend test case testing across libtpms versions
    * Add test case for testing profiles across libtpms versions
    * Test the --profile option of swtpm_setup and swtpm
    * teach them to run installed
    * add installed-runner.sh
    * install tests on the system
    * lookup system binaries if INSTALLED is set
    + build-sys:
    * enable 64-bit file API on 32-bit systems
    * Add -Wshadow to the CFLAGS
    * Require that libtpms v0.10 is available for TPMLIB_SetProfile

++++ os-update:

  - Update to version 1.20+git.20241204:
    * Release version 1.20
    * Switch from pandoc to go-md2man
    * Add option to ignore services at all

------------------------------------------------------------------
------------------  2024-12-3  -  Dec 3 2024  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update to 10.3.11 (bsc#1234050)
    + Send registration code for the extensions, not only base product

++++ cockpit-machines:

  - Update to 324:
    * Limit size of descriptions
  - Changes from 323:
    * Action to add a TPM
  - Changes from 322:
    * Bug fixes and translation updates
  - Changes form 321:
    * Drop usage of virtinterfaced
  - Changes from 320:
    * Improve snapshot memory path handling
    * Add support for VM descriptions
  - Changes from 319:
    * Translation updates
    * Bug fixes
  - Changes from 318.1:
    * Translation updates
  - Changes from 318:
    * Translation updates
    * Test fixes
  - Changes from 317:
    * Bug fixes

++++ python-kiwi:

  - Bump version: 10.2.2 → 10.2.3
  - Update STYLEROOT to SUSE 2022

++++ grub2:

  - Update the TPM2 patches to the upstream final version
    * Update 0001-key_protector-Add-key-protectors-framework.patch
    * Replace 0002-tpm2-Add-TPM-Software-Stack-TSS.patch with
    grub2-add-tss2-support.patch
    * Replace 0003-key_protector-Add-TPM2-Key-Protector.patch with
    0001-key_protector-Add-TPM2-Key-Protector.patch
    * Replace 0005-util-grub-protect-Add-new-tool.patch with
    0001-util-grub-protect-Add-new-tool.patch
    * Replace 0001-tpm2-Implement-NV-index.patch with
    0001-tpm2_key_protector-Implement-NV-index.patch
    * Replace 0001-tpm2-Support-authorized-policy.patch with
    0001-tpm2_key_protector-Support-authorized-policy.patch
  - Refresh the TPM2 related patches
    * grub-read-pcr.patch
    * 0001-tpm2-Add-extra-RSA-SRK-types.patch
    * grub2-bsc1220338-key_protector-implement-the-blocklist.patch
    * safe_tpm_pcr_snapshot.patch
    * tpm-record-pcrs.patch

++++ kernel-default:

  - Update
    patches.suse/media-uvcvideo-Skip-parsing-frames-of-type-UVC_VS_UN.patch
    (git-fixes CVE-2024-53104 bsc#1234025).
  - commit 381f9fa
  - config.sh: Update Bugzilla product
  - commit 5d4ad4d
  - cgroup/bpf: only cgroup v2 can be attached by bpf programs
    (bsc#1234108).
  - Revert "cgroup: Fix memory leak caused by missing
    cgroup_bpf_offline" (bsc#1234108).
  - commit 440fba7
  - kernel-doc: allow object-like macros in ReST output (git-fixes).
  - commit 58f47a6
  - checkpatch: always parse orig_commit in fixes tag (git-fixes).
  - accel/ivpu: Prevent recovery invocation during probe and resume
    (git-fixes).
  - cleanup: Remove address space of returned pointer (git-fixes).
  - commit 9e46c4d

++++ kernel-rt:

  - Update
    patches.suse/media-uvcvideo-Skip-parsing-frames-of-type-UVC_VS_UN.patch
    (git-fixes CVE-2024-53104 bsc#1234025).
  - commit 381f9fa
  - config.sh: Update Bugzilla product
  - commit 5d4ad4d
  - cgroup/bpf: only cgroup v2 can be attached by bpf programs
    (bsc#1234108).
  - Revert "cgroup: Fix memory leak caused by missing
    cgroup_bpf_offline" (bsc#1234108).
  - commit 440fba7
  - kernel-doc: allow object-like macros in ReST output (git-fixes).
  - commit 58f47a6
  - checkpatch: always parse orig_commit in fixes tag (git-fixes).
  - accel/ivpu: Prevent recovery invocation during probe and resume
    (git-fixes).
  - cleanup: Remove address space of returned pointer (git-fixes).
  - commit 9e46c4d

++++ libnettle:

  - ppcl64le: POWER10 performance enhancements for cryptography [jsc#PED-9904]
    * powerpc64/sha256: fix loading overreads by loading less and shifting
    * powerpc64/sha256: adjust stack offset for storing non-volatile registers
    * powerpc64: remove use of m4_unquote in the load step for sha256
    * Temporarily skip the gcm test: libnettle-powerpc64-skip-AES-GCM-test.patch
    * Add patches:
  - libnettle-powerpc64-sha256-fix-loading-overreads.patch
  - libnettle-powerpc64-sha256-adjust-stack-offset-for-non-volatile-registers.patch
  - libnettle-powerpc64-remove-m4_unquote-sha256.patch

++++ ncurses:

  - Add ncurses patch 20241130
    + improve configure check for lint program.
    + adjust options in test-programs to allow for consistent use of -c/-l
    for command/logging.
    + modify win_driver.c for MinGW to handle shift-tab and control-tab as
    back-tab (report by Axel Reinhold)

++++ systemd:

  - Add 5005-Revert-boot-Make-initrd_prepare-semantically-equival.patch
    Revert commit d64193a2a652b15db9cb9ed10c6b77a17ca46cd2 until the regression it
    caused, reported at https://github.com/systemd/systemd/issues/35439, is fixed
    (see also bsc#1233752 for its downstream counterpart).
  - Disable EFI support on architectures that are not EFI-compliant
  - Import commit 290170c8550bf2de4b5085ecdf7f056769944444 (merge of v256.9)
    This merge includes the following fix:
    cf7b3cc182 pid1: make clear that $WATCHDOG_USEC is set for the shutdown binary, noone else (bsc#1232227)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/c7671762b39ead7f8f9e70064256f5efaccedeca...290170c8550bf2de4b5085ecdf7f056769944444

++++ nvidia-open-driver-G06-signed:

  - kmp-trigger.sh:
    * avoid to return with exit code != 0 if modules could not be
    unloaded for some reason

++++ python-PyJWT:

  - Update to version 2.10.1 (bsc#1234038, CVE-2024-53861):
    * Prevent partial matching of iss claim. Thanks @fabianbadoi!
    (See: GHSA-75c5-xw7c-p5pm)

++++ supportutils:

  - Changes to version 3.2.9
    + Map running PIDs to RPM package owner aiding BPF program detection (bsc#1222896, bsc#1213291, PED-8221)
    + Supportconfig available in current distro (PED-7131)
    + Corrected display issues (bsc#1231396)
    + NFS takes too long, showmount times out (bsc#1231423)
    + Merged sle15 and master branches (bsc#1233726, PED-11669)

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#185
  - provide default settings in cases where kernel and initrd
    symlinks are missing (bsc#1233956)
  - update test results
  - 1.21

------------------------------------------------------------------
------------------  2024-12-2  -  Dec 2 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add support for loongarch64
    This Fixes #2684
  - Fix broken links in the documentation
  - Fix legacy_bios_mode detection
    The code in this method does not work correctly if the
    firmware is set to 'bios'. In bios only mode the method
    returned a false value which is incorrect as it should
    return a true value in this case. Without this patch
    ISO images will fail to boot because no loader gets
    configured.
  - Added /dev/pts to bind mount locations
    During runtime several kernel filesystems are bind mounted into
    the image root system such that programs expecting it can work.
    /dev/pts was not needed so far but seems to be a good addition
    to the list to make tools like sudo to work properly when called
    e.g. from a config.sh script. This Fixes #2686

++++ elfutils:

  - Remove files packaged by elfutils-debuginfod

++++ glibc:

  - Add support for loongarch64

++++ iptables:

  - Add iptables-nft-fix-interface-comparisons.patch
    * fix '-C' commands for nft backend (bsc#1233690)

++++ kernel-default:

  - fs/file.c: add fast path in find_next_fd() (jsc#PED-10666).
  - commit 408b57f
  - fs/file.c: conditionally clear full_fds (jsc#PED-10666).
  - commit 26a9b57
  - fs/file.c: remove sanity_check and add likely/unlikely in
    alloc_fd() (jsc#PED-10666).
  - commit 5da9b0b
  - nvme-fabrics: fix kernel crash while shutting down controller
    (git-fixes).
  - Revert "nvme: make keep-alive synchronous operation"
    (git-fixes).
  - nvme/multipath: Fix RCU list traversal to use SRCU primitive
    (git-fixes).
  - nvme-pci: reverse request order in nvme_queue_rqs (git-fixes).
  - nvme-pci: fix freeing of the HMB descriptor table (git-fixes).
  - commit 534c003
  - scsi: lpfc: Copyright updates for 14.4.0.6 patches (bsc#1233241
    jsc#PED-10904).
  - scsi: lpfc: Update lpfc version to 14.4.0.6 (bsc#1233241
    jsc#PED-10904).
  - scsi: lpfc: Change lpfc_nodelist nlp_flag member into a bitmask
    (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Remove NLP_RELEASE_RPI flag from nodelist structure
    (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Prevent NDLP reference count underflow in
    dev_loss_tmo callback (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Add cleanup of nvmels_wq after HBA reset
    (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Check SLI_ACTIVE flag in FDMI cmpl before submitting
    follow up FDMI (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Update lpfc_els_flush_cmd() to check for SLI_ACTIVE
    before BSG flag (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Call lpfc_sli4_queue_unset() in restart and rmmod
    paths (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Check devloss callbk done flag for potential stale
    NDLP ptrs (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Modify CGN warning signal calculation based on
    EDC response (bsc#1233241 jsc#PED-10904).
  - commit 954c8fe
  - Refresh patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch
  - refreshed contexts
  - mm_struct: taken out of randomized substruct
  - sock: moved from middle to the end
  - commit 12002b5
  - PCI/pwrctl: Ensure that pwrctl drivers are probed before PCI
    client drivers (git-fixes).
  - PCI/pwrctl: Create pwrctl device only if at least one power
    supply is present (git-fixes).
  - PCI/pwrctl: Use of_platform_device_create() to create pwrctl
    devices (git-fixes).
  - commit 5ac4fb1

++++ kernel-firmware-all:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-amdgpu:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-ath10k:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-ath11k:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-ath12k:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-atheros:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-bluetooth:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-bnx2:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-brcm:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-chelsio:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-dpaa2:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-i915:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-intel:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-iwlwifi:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-liquidio:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-marvell:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-media:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-mediatek:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-mellanox:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-mwifiex:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-network:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-nfp:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-nvidia:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-platform:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-prestera:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-qcom:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-qlogic:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-radeon:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-realtek:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-serial:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-sound:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-ti:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-ueagle:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-firmware-usb-network:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ kernel-rt:

  - fs/file.c: add fast path in find_next_fd() (jsc#PED-10666).
  - commit 408b57f
  - fs/file.c: conditionally clear full_fds (jsc#PED-10666).
  - commit 26a9b57
  - fs/file.c: remove sanity_check and add likely/unlikely in
    alloc_fd() (jsc#PED-10666).
  - commit 5da9b0b
  - nvme-fabrics: fix kernel crash while shutting down controller
    (git-fixes).
  - Revert "nvme: make keep-alive synchronous operation"
    (git-fixes).
  - nvme/multipath: Fix RCU list traversal to use SRCU primitive
    (git-fixes).
  - nvme-pci: reverse request order in nvme_queue_rqs (git-fixes).
  - nvme-pci: fix freeing of the HMB descriptor table (git-fixes).
  - commit 534c003
  - scsi: lpfc: Copyright updates for 14.4.0.6 patches (bsc#1233241
    jsc#PED-10904).
  - scsi: lpfc: Update lpfc version to 14.4.0.6 (bsc#1233241
    jsc#PED-10904).
  - scsi: lpfc: Change lpfc_nodelist nlp_flag member into a bitmask
    (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Remove NLP_RELEASE_RPI flag from nodelist structure
    (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Prevent NDLP reference count underflow in
    dev_loss_tmo callback (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Add cleanup of nvmels_wq after HBA reset
    (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Check SLI_ACTIVE flag in FDMI cmpl before submitting
    follow up FDMI (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Update lpfc_els_flush_cmd() to check for SLI_ACTIVE
    before BSG flag (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Call lpfc_sli4_queue_unset() in restart and rmmod
    paths (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Check devloss callbk done flag for potential stale
    NDLP ptrs (bsc#1233241 jsc#PED-10904).
  - scsi: lpfc: Modify CGN warning signal calculation based on
    EDC response (bsc#1233241 jsc#PED-10904).
  - commit 954c8fe
  - Refresh patches.suse/kabi-Add-placeholders-to-a-couple-of-important-struc.patch
  - refreshed contexts
  - mm_struct: taken out of randomized substruct
  - sock: moved from middle to the end
  - commit 12002b5
  - PCI/pwrctl: Ensure that pwrctl drivers are probed before PCI
    client drivers (git-fixes).
  - PCI/pwrctl: Create pwrctl device only if at least one power
    supply is present (git-fixes).
  - PCI/pwrctl: Use of_platform_device_create() to create pwrctl
    devices (git-fixes).
  - commit 5ac4fb1

++++ libcap:

  - update to 2.73:
    * https://sites.google.com/site/fullycapable/release-notes-for-libcap?authuser=0#h.7yd7ab9ppagk

++++ libgcrypt:

  - Remove unrecognized option: --enable-m-guard

++++ libosinfo:

  - Update to version 1.12.0 (jsc#PED-8910)
    * Some memory leak fixes
    * Adapt to change in libxml2
    * Several CI improvements
    * Several translations improvements
  - Drop 0001-osinfo-Make-xmlError-struct-constant-in-propagate_li.patch

++++ snapper:

  - added new workflow using only two steps to installation-helper
    (gh#openSUSE/snapper#944)

++++ libvirt:

  - Update to libvirt 10.10.0
  - jsc#PED-8909, jsc#PED-9543, jsc#PED-9854, jsc#PED-9855
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v10-10-0-2024-12-02

++++ opensuse-migration-tool:

  - Update to version 20241202.1a4772b:
    * Fix missing mv and missing DRYRUN
    * Use https instead of git in a README git clone examples
    * Update README.md with opensuse-migration tool and new repo paths

++++ python-libvirt-python:

  - Update to 10.10.0
  - Add all new APIs and constants in libvirt 10.10.0
  - jsc#PED-8909, jsc#PED-9543, jsc#PED-9854, jsc#PED-9855

++++ ucode-amd:

  - Update to version 20241128 (git commit ea71da6f0690):
    * i915: Update Xe2LPD DMC to v2.24
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * iwlwifi: add Bz-gf FW for core89-91 release
    * amdgpu: update smu 13.0.10 firmware
    * amdgpu: update sdma 6.0.3 firmware
    * amdgpu: update psp 13.0.10 firmware
    * amdgpu: update gc 11.0.3 firmware
    * amdgpu: add smu 13.0.14 firmware
    * amdgpu: add sdma 4.4.5 firmware
    * amdgpu: add psp 13.0.14 firmware
    * amdgpu: add gc 9.4.4 firmware
    * amdgpu: update vcn 3.1.2 firmware
    * amdgpu: update psp 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update psp 14.0.4 firmware
    * amdgpu: update gc 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update vcn 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update psp 13.0.0 firmware
    * amdgpu: update gc 11.0.0 firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update psp 13.0.11 firmware
    * amdgpu: update gc 11.0.4 firmware
    * amdgpu: update vcn 4.0.2 firmware
    * amdgpu: update psp 13.0.4 firmware
    * amdgpu: update gc 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update vpe 6.1.1 firmware
    * amdgpu: update vcn 4.0.6 firmware
    * amdgpu: update psp 14.0.1 firmware
    * amdgpu: update gc 11.5.1 firmware
    * amdgpu: update vcn 4.0.5 firmware
    * amdgpu: update psp 14.0.0 firmware
    * amdgpu: update gc 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update arcturus firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update sdma 4.4.2 firmware
    * amdgpu: update psp 13.0.6 firmware
    * amdgpu: update gc 9.4.3 firmware
    * amdgpu: update vcn 4.0.4 firmware
    * amdgpu: update psp 13.0.7 firmware
    * amdgpu: update gc 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
  - Update aliases from 6.13-rc1

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#184
  - bash in SLE15 works differently than in TW; adjust for
    differences (bsc#1231018)
  - 1.20

------------------------------------------------------------------
------------------  2024-12-1  -  Dec 1 2024  -------------------
------------------------------------------------------------------

++++ elfutils:

  - update to 0.192
    CONDUCT: A new code of conduct has been adopted.  See the
    CONDUCT file for more information.
    debuginfod: Add per-file signature verification for integrity
    checking, using RPM IMA scheme from Fedora/RHEL.
    New API for metadata queries: file name -> buildid.
    Server-side extraction of files from kernel debuginfo
    packages is significantly faster. Now takes < 0.25 seconds,
    down from ~50 seconds.
    libdw: New functions dwfl_set_sysroot, dwfl_frame_unwound_source
    and dwfl_unwound_source_str.
    stacktrace: Experimental new tool that can process a stream of stack
    samples from the Sysprof profiler and unwind them into call
    chains. Enable on x86 with --enable-stacktrace. See
    README.eu-stacktrace in the development branch for detailed
    usage instructions:
    https://sourceware.org/cgit/elfutils/tree/README.eu-stacktrace?h=users/serhei/eu-stacktrace

++++ kernel-default:

  - serial: amba-pl011: fix build regression (git-fixes).
  - commit e7439f2
  - tools/power turbostat: Fix child's argument forwarding
    (git-fixes).
  - tools/power turbostat: Fix trailing '\n' parsing (git-fixes).
  - modpost: remove incorrect code in do_eisa_entry() (git-fixes).
  - Rename .data.once to .data..once to fix resetting WARN*_ONCE
    (git-fixes).
  - Rename .data.unlikely to .data..unlikely (git-fixes).
  - rtc: ab-eoz9: don't fail temperature reads on undervoltage
    notification (git-fixes).
  - rtc: rzn1: fix BCD to rtc_time conversion errors (git-fixes).
  - rtc: check if __rtc_read_time was successful in
    rtc_timer_do_work() (git-fixes).
  - rtc: abx80x: Fix WDT bit position of the status register
    (git-fixes).
  - rtc: bbnsm: add remove hook (git-fixes).
  - rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - mtd: ubi: fix unreleased fwnode_handle in find_volume_fwnode()
    (git-fixes).
  - serial: amba-pl011: Fix RX stall when DMA is used (git-fixes).
  - tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
    (git-fixes).
  - serial: 8250: omap: Move pm_runtime_get_sync (git-fixes).
  - commit c7930d4

++++ kernel-rt:

  - serial: amba-pl011: fix build regression (git-fixes).
  - commit e7439f2
  - tools/power turbostat: Fix child's argument forwarding
    (git-fixes).
  - tools/power turbostat: Fix trailing '\n' parsing (git-fixes).
  - modpost: remove incorrect code in do_eisa_entry() (git-fixes).
  - Rename .data.once to .data..once to fix resetting WARN*_ONCE
    (git-fixes).
  - Rename .data.unlikely to .data..unlikely (git-fixes).
  - rtc: ab-eoz9: don't fail temperature reads on undervoltage
    notification (git-fixes).
  - rtc: rzn1: fix BCD to rtc_time conversion errors (git-fixes).
  - rtc: check if __rtc_read_time was successful in
    rtc_timer_do_work() (git-fixes).
  - rtc: abx80x: Fix WDT bit position of the status register
    (git-fixes).
  - rtc: bbnsm: add remove hook (git-fixes).
  - rtc: st-lpc: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - mtd: ubi: fix unreleased fwnode_handle in find_volume_fwnode()
    (git-fixes).
  - serial: amba-pl011: Fix RX stall when DMA is used (git-fixes).
  - tty: ldsic: fix tty_ldisc_autoload sysctl's proc_handler
    (git-fixes).
  - serial: 8250: omap: Move pm_runtime_get_sync (git-fixes).
  - commit c7930d4

------------------------------------------------------------------
------------------  2024-11-30  -  Nov 30 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - USB: chaoskey: Fix possible deadlock chaoskey_list_lock
    (git-fixes).
  - commit 3c5d214
  - ALSA: hda: improve bass speaker support for ASUS Zenbook
    UM5606WA (stable-fixes).
  - ALSA: hda/realtek: Apply quirk for Medion E15433 (stable-fixes).
  - ALSA: hda: Show the codec quirk info at probing (stable-fixes).
  - ALSA: hda/realtek: Set PCBeep to default value for ALC274
    (stable-fixes).
  - ALSA: hda/tas2781: Add speaker id check for ASUS projects
    (stable-fixes).
  - ALSA: hda/realtek: Enable speaker pins for Medion E15443
    platform (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for
    EliteBook X G1i (stable-fixes).
  - ALSA: usb-audio: Fix out of bounds reads when finding clock
    sources (stable-fixes).
  - ALSA: hda/realtek: Fix Internal Speaker and Mic boost of
    Infinix Y4 Max (stable-fixes).
  - ALSA: pcm: Add sanity NULL check for the default mmap fault
    handler (stable-fixes).
  - ALSA: hda: Poll jack events for LS7A HD-Audio (stable-fixes).
  - ALSA: usb-audio: Make mic volume workarounds globally applicable
    (stable-fixes).
  - ALSA: usb-audio: Add Pioneer DJ/AlphaTheta DJM-A9 Mixer
    (stable-fixes).
  - ALSA: hda: Fix build error without CONFIG_SND_DEBUG (git-fixes).
  - ALSA: usb-audio: Use snprintf instead of sprintf in
    build_mixer_unit_ctl (stable-fixes).
  - ALSA: hda/realtek: Use codec SSID matching for Lenovo devices
    (stable-fixes).
  - ALSA: hda/conexant: Use the new codec SSID matching
    (stable-fixes).
  - ALSA: hda: Use own quirk lookup helper (stable-fixes).
  - commit 0775b0e
  - interconnect: qcom: icc-rpmh: probe defer incase of missing
    QoS clock dependency (git-fixes).
  - iio: adc: pac1921: Check for error code from devm_mutex_init()
    call (git-fixes).
  - iio: adc: ad4000: Check for error code from devm_mutex_init()
    call (git-fixes).
  - iio: accel: kxcjk-1013: Revert "Add support for KX022-1020"
    (git-fixes).
  - =?UTF-8?q?iio:=20accel:=20kxcjk-1013:=20Remove=20redundan?=
    =?UTF-8?q?t=20I=C2=B2C=20ID?= (git-fixes).
  - iio: Fix fwnode_handle in __fwnode_iio_channel_get_by_name()
    (git-fixes).
  - iio: accel: adxl380: fix raw sample read (git-fixes).
  - iio: accel: kx022a: Fix raw read format (git-fixes).
  - iio: gts: fix infinite loop for gain_to_scaletables()
    (git-fixes).
  - iio: gts: Fix uninitialized symbol 'ret' (git-fixes).
  - iio: adc: ad4000: fix reading unsigned data (git-fixes).
  - iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer
    (git-fixes).
  - iio: backend: fix wrong pointer passed to IS_ERR() (git-fixes).
  - iio: invensense: fix multiple odr switch when FIFO is off
    (git-fixes).
  - goldfish: Fix unused const variable 'goldfish_pipe_acpi_match'
    (git-fixes).
  - misc: rtsx: Cleanup on DRV_NAME cardreader variables
    (git-fixes).
  - iio: dac: adi-axi-dac: fix wrong register bitfield (git-fixes).
  - iio: adc: ad7606: Fix typo in the driver name (git-fixes).
  - iio: light: al3010: Fix an error handling path in al3010_probe()
    (git-fixes).
  - misc: apds990x: Fix missing pm_runtime_disable() (git-fixes).
  - staging: vchiq_arm: Fix missing refcount decrement in error
    path for fw_node (git-fixes).
  - usb: dwc3: gadget: Fix looping of queued SG entries (git-fixes).
  - usb: dwc3: gadget: Fix checking for number of TRBs left
    (git-fixes).
  - usb: dwc3: ep0: Don't clear ep0 DWC3_EP_TRANSFER_STARTED
    (git-fixes).
  - Revert "usb: gadget: composite: fix OS descriptors w_value
    logic" (git-fixes).
  - usb: ehci-spear: fix call balance of sehci clk handling routines
    (git-fixes).
  - USB: serial: ftdi_sio: Fix atomicity violation in
    get_serial_info() (git-fixes).
  - usb: dwc3: gadget: Add missing check for single port RAM in
    TxFIFO resizing logic (git-fixes).
  - usb: typec: fix potential array underflow in
    ucsi_ccg_sync_control() (git-fixes).
  - usb: misc: ljca: set small runtime autosuspend delay
    (git-fixes).
  - usb: misc: ljca: move usb_autopm_put_interface() after wait
    for response (git-fixes).
  - usb: musb: Fix hardware lockup on first Rx endpoint request
    (git-fixes).
  - usb: typec: ucsi: glink: fix off-by-one in connector_status
    (git-fixes).
  - usb: xhci: Fix TD invalidation under pending Set TR Dequeue
    (git-fixes).
  - usb: xhci: Limit Stop Endpoint retries (git-fixes).
  - xhci: Don't perform Soft Retry for Etron xHCI host (git-fixes).
  - xhci: Fix control transfer error on Etron xHCI host (git-fixes).
  - xhci: Don't issue Reset Device command to Etron xHCI host
    (git-fixes).
  - xhci: Combine two if statements for Etron xHCI host (git-fixes).
  - phy: realtek: usb: fix NULL deref in rtk_usb3phy_probe
    (git-fixes).
  - phy: realtek: usb: fix NULL deref in rtk_usb2phy_probe
    (git-fixes).
  - usb: gadget: uvc: wake pump everytime we update the free list
    (git-fixes).
  - USB: chaoskey: fail open after removal (git-fixes).
  - usb: yurex: make waiting on yurex_write interruptible
    (git-fixes).
  - usb: using mutex lock and supporting O_NONBLOCK flag in
    iowarrior_read() (git-fixes).
  - net: mdio-ipq4019: add missing error check (git-fixes).
  - commit 251ecb2
  - drm/xe/migrate: use XE_BO_FLAG_PAGETABLE (git-fixes).
  - drm/xe/migrate: fix pat index usage (git-fixes).
  - drm/xe/guc_submit: fix race around suspend_pending (git-fixes).
  - Revert "drm/radeon: Delay Connector detecting when HPD singals
    is unstable" (stable-fixes).
  - drm/amd/display: Fix null check for pipe_ctx->plane_state in
    hwss_setup_dpp (git-fixes).
  - drm/amd/display: Fix null check for pipe_ctx->plane_state in
    dcn20_program_pipe (git-fixes).
  - drm/radeon: Fix spurious unplug event on radeon HDMI
    (git-fixes).
  - drm/amd: Add some missing straps from NBIO 7.11.0 (git-fixes).
  - drm/xe: Mark preempt fence workqueue as reclaim (git-fixes).
  - drm/xe/ufence: Wake up waiters after setting ufence->signalled
    (git-fixes).
  - ASoC: SOF: ipc3-topology: Convert the topology pin index to
    ALH dai index (git-fixes).
  - ASoC: mediatek: Check num_codecs is not zero to avoid panic
    during probe (git-fixes).
  - ASoC: amd: yc: Fix for enabling DMIC on acp6x via _DSD entry
    (git-fixes).
  - ASoC: imx-audmix: Add NULL check in imx_audmix_probe
    (git-fixes).
  - ALSA: ump: Fix evaluation of MIDI 1.0 FB info (git-fixes).
  - ALSA: core: Fix possible NULL dereference caused by
    kunit_kzalloc() (git-fixes).
  - ALSA: hda/realtek: Update ALC225 depop procedure (git-fixes).
  - ALSA: rawmidi: Fix kvfree() call in spinlock (git-fixes).
  - ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy
    and Mbox devices (git-fixes).
  - ALSA: hda/realtek: Update ALC256 depop procedure (git-fixes).
  - ALSA: ac97: bus: Fix the mistake in the comment (git-fixes).
  - bus: mhi: host: Switch trace_mhi_gen_tre fields to native endian
    (git-fixes).
  - ad7780: fix division by zero in ad7780_write_raw() (git-fixes).
  - comedi: Flush partial mappings in error case (git-fixes).
  - firmware_loader: Fix possible resource leak in
    fw_log_firmware_info() (git-fixes).
  - driver core: fw_devlink: Stop trying to optimize cycle detection
    logic (git-fixes).
  - devres: Fix page faults when tracing devres from unloaded
    modules (git-fixes).
  - apparmor: fix 'Do simple duplicate message elimination'
    (git-fixes).
  - apparmor: test: Fix memory leak for aa_unpack_strdup()
    (git-fixes).
  - commit 62cfe63

++++ kernel-rt:

  - USB: chaoskey: Fix possible deadlock chaoskey_list_lock
    (git-fixes).
  - commit 3c5d214
  - ALSA: hda: improve bass speaker support for ASUS Zenbook
    UM5606WA (stable-fixes).
  - ALSA: hda/realtek: Apply quirk for Medion E15433 (stable-fixes).
  - ALSA: hda: Show the codec quirk info at probing (stable-fixes).
  - ALSA: hda/realtek: Set PCBeep to default value for ALC274
    (stable-fixes).
  - ALSA: hda/tas2781: Add speaker id check for ASUS projects
    (stable-fixes).
  - ALSA: hda/realtek: Enable speaker pins for Medion E15443
    platform (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for
    EliteBook X G1i (stable-fixes).
  - ALSA: usb-audio: Fix out of bounds reads when finding clock
    sources (stable-fixes).
  - ALSA: hda/realtek: Fix Internal Speaker and Mic boost of
    Infinix Y4 Max (stable-fixes).
  - ALSA: pcm: Add sanity NULL check for the default mmap fault
    handler (stable-fixes).
  - ALSA: hda: Poll jack events for LS7A HD-Audio (stable-fixes).
  - ALSA: usb-audio: Make mic volume workarounds globally applicable
    (stable-fixes).
  - ALSA: usb-audio: Add Pioneer DJ/AlphaTheta DJM-A9 Mixer
    (stable-fixes).
  - ALSA: hda: Fix build error without CONFIG_SND_DEBUG (git-fixes).
  - ALSA: usb-audio: Use snprintf instead of sprintf in
    build_mixer_unit_ctl (stable-fixes).
  - ALSA: hda/realtek: Use codec SSID matching for Lenovo devices
    (stable-fixes).
  - ALSA: hda/conexant: Use the new codec SSID matching
    (stable-fixes).
  - ALSA: hda: Use own quirk lookup helper (stable-fixes).
  - commit 0775b0e
  - interconnect: qcom: icc-rpmh: probe defer incase of missing
    QoS clock dependency (git-fixes).
  - iio: adc: pac1921: Check for error code from devm_mutex_init()
    call (git-fixes).
  - iio: adc: ad4000: Check for error code from devm_mutex_init()
    call (git-fixes).
  - iio: accel: kxcjk-1013: Revert "Add support for KX022-1020"
    (git-fixes).
  - =?UTF-8?q?iio:=20accel:=20kxcjk-1013:=20Remove=20redundan?=
    =?UTF-8?q?t=20I=C2=B2C=20ID?= (git-fixes).
  - iio: Fix fwnode_handle in __fwnode_iio_channel_get_by_name()
    (git-fixes).
  - iio: accel: adxl380: fix raw sample read (git-fixes).
  - iio: accel: kx022a: Fix raw read format (git-fixes).
  - iio: gts: fix infinite loop for gain_to_scaletables()
    (git-fixes).
  - iio: gts: Fix uninitialized symbol 'ret' (git-fixes).
  - iio: adc: ad4000: fix reading unsigned data (git-fixes).
  - iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer
    (git-fixes).
  - iio: backend: fix wrong pointer passed to IS_ERR() (git-fixes).
  - iio: invensense: fix multiple odr switch when FIFO is off
    (git-fixes).
  - goldfish: Fix unused const variable 'goldfish_pipe_acpi_match'
    (git-fixes).
  - misc: rtsx: Cleanup on DRV_NAME cardreader variables
    (git-fixes).
  - iio: dac: adi-axi-dac: fix wrong register bitfield (git-fixes).
  - iio: adc: ad7606: Fix typo in the driver name (git-fixes).
  - iio: light: al3010: Fix an error handling path in al3010_probe()
    (git-fixes).
  - misc: apds990x: Fix missing pm_runtime_disable() (git-fixes).
  - staging: vchiq_arm: Fix missing refcount decrement in error
    path for fw_node (git-fixes).
  - usb: dwc3: gadget: Fix looping of queued SG entries (git-fixes).
  - usb: dwc3: gadget: Fix checking for number of TRBs left
    (git-fixes).
  - usb: dwc3: ep0: Don't clear ep0 DWC3_EP_TRANSFER_STARTED
    (git-fixes).
  - Revert "usb: gadget: composite: fix OS descriptors w_value
    logic" (git-fixes).
  - usb: ehci-spear: fix call balance of sehci clk handling routines
    (git-fixes).
  - USB: serial: ftdi_sio: Fix atomicity violation in
    get_serial_info() (git-fixes).
  - usb: dwc3: gadget: Add missing check for single port RAM in
    TxFIFO resizing logic (git-fixes).
  - usb: typec: fix potential array underflow in
    ucsi_ccg_sync_control() (git-fixes).
  - usb: misc: ljca: set small runtime autosuspend delay
    (git-fixes).
  - usb: misc: ljca: move usb_autopm_put_interface() after wait
    for response (git-fixes).
  - usb: musb: Fix hardware lockup on first Rx endpoint request
    (git-fixes).
  - usb: typec: ucsi: glink: fix off-by-one in connector_status
    (git-fixes).
  - usb: xhci: Fix TD invalidation under pending Set TR Dequeue
    (git-fixes).
  - usb: xhci: Limit Stop Endpoint retries (git-fixes).
  - xhci: Don't perform Soft Retry for Etron xHCI host (git-fixes).
  - xhci: Fix control transfer error on Etron xHCI host (git-fixes).
  - xhci: Don't issue Reset Device command to Etron xHCI host
    (git-fixes).
  - xhci: Combine two if statements for Etron xHCI host (git-fixes).
  - phy: realtek: usb: fix NULL deref in rtk_usb3phy_probe
    (git-fixes).
  - phy: realtek: usb: fix NULL deref in rtk_usb2phy_probe
    (git-fixes).
  - usb: gadget: uvc: wake pump everytime we update the free list
    (git-fixes).
  - USB: chaoskey: fail open after removal (git-fixes).
  - usb: yurex: make waiting on yurex_write interruptible
    (git-fixes).
  - usb: using mutex lock and supporting O_NONBLOCK flag in
    iowarrior_read() (git-fixes).
  - net: mdio-ipq4019: add missing error check (git-fixes).
  - commit 251ecb2
  - drm/xe/migrate: use XE_BO_FLAG_PAGETABLE (git-fixes).
  - drm/xe/migrate: fix pat index usage (git-fixes).
  - drm/xe/guc_submit: fix race around suspend_pending (git-fixes).
  - Revert "drm/radeon: Delay Connector detecting when HPD singals
    is unstable" (stable-fixes).
  - drm/amd/display: Fix null check for pipe_ctx->plane_state in
    hwss_setup_dpp (git-fixes).
  - drm/amd/display: Fix null check for pipe_ctx->plane_state in
    dcn20_program_pipe (git-fixes).
  - drm/radeon: Fix spurious unplug event on radeon HDMI
    (git-fixes).
  - drm/amd: Add some missing straps from NBIO 7.11.0 (git-fixes).
  - drm/xe: Mark preempt fence workqueue as reclaim (git-fixes).
  - drm/xe/ufence: Wake up waiters after setting ufence->signalled
    (git-fixes).
  - ASoC: SOF: ipc3-topology: Convert the topology pin index to
    ALH dai index (git-fixes).
  - ASoC: mediatek: Check num_codecs is not zero to avoid panic
    during probe (git-fixes).
  - ASoC: amd: yc: Fix for enabling DMIC on acp6x via _DSD entry
    (git-fixes).
  - ASoC: imx-audmix: Add NULL check in imx_audmix_probe
    (git-fixes).
  - ALSA: ump: Fix evaluation of MIDI 1.0 FB info (git-fixes).
  - ALSA: core: Fix possible NULL dereference caused by
    kunit_kzalloc() (git-fixes).
  - ALSA: hda/realtek: Update ALC225 depop procedure (git-fixes).
  - ALSA: rawmidi: Fix kvfree() call in spinlock (git-fixes).
  - ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy
    and Mbox devices (git-fixes).
  - ALSA: hda/realtek: Update ALC256 depop procedure (git-fixes).
  - ALSA: ac97: bus: Fix the mistake in the comment (git-fixes).
  - bus: mhi: host: Switch trace_mhi_gen_tre fields to native endian
    (git-fixes).
  - ad7780: fix division by zero in ad7780_write_raw() (git-fixes).
  - comedi: Flush partial mappings in error case (git-fixes).
  - firmware_loader: Fix possible resource leak in
    fw_log_firmware_info() (git-fixes).
  - driver core: fw_devlink: Stop trying to optimize cycle detection
    logic (git-fixes).
  - devres: Fix page faults when tracing devres from unloaded
    modules (git-fixes).
  - apparmor: fix 'Do simple duplicate message elimination'
    (git-fixes).
  - apparmor: test: Fix memory leak for aa_unpack_strdup()
    (git-fixes).
  - commit 62cfe63

++++ nvidia-open-driver-G06-signed:

  - only obsolete 555 CUDA driver/firmware packages
  - preamble:
    no longer need to provide nvidia-open-driver-G06-kmp because
    since 565.57.01 to the list of requires of nvidia-compute-G06
    the -signed packages has been added
  - For CUDA update version to 565.57.01

------------------------------------------------------------------
------------------  2024-11-29  -  Nov 29 2024  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Update to version 2.31.0:
    * bump containerd to v1.7,24
    * bump google.golang.org/grpc to v1.68.0
    * build(deps): bump github.com/moby/buildkit from 0.17.1 to
    0.17.2
    * build(deps): bump github.com/compose-spec/compose-go/v2
    * only stop dependent containers ... if there's some
    * disable TestNetworkConfigChanged which is unstable on CI
    * only check attached networks on running containers
    * fix: commit tests
    * feat: add commit command
    * run build tests against bake
    * delegate build to buildx bake
    * build(deps): bump github.com/stretchr/testify from 1.9.0 to
    1.10.0
    * use service.stop to stop dependent containers
    * Update wait-timeout flag usage to include the unit
    * go.mod: github.com/docker/cli v27.4.0-rc.2
    * go.mod: github.com/docker/docker v27.4.0-rc.2
    * go.mod: github.com/docker/cli 8d1bacae3e49 (v27.4.0-rc.2-dev)
    * go.mod: github.com/docker/cli v27.4.0-rc.1
    * go.mod: github.com/docker/docker v27.4.0-rc.1
    * Update pkg/compose/convergence.go
    * detect network config changes and recreate if needed
    * go.mod: github.com/docker/buildx v0.18.0
    * go.mod: github.com/moby/buildkit v0.17.1
    * gha: test against docker engine v27.4.0
    * push empty descriptor layer when using OCI version 1.1 for
    Compose artifact it fixes a repository creation issue when
    pushing the 1st time a Compose OCI artifact on the Hub
    * remove ddev e2e tests
    * implement remove-orphans on run
    * ci: enable testifylint linter
    * Emit events for building images
    * Fix compose images that reutn a different image with the same
    ID
    * remove obsolete containers first on scale down
    * pass stal bot inactivity limit from 6 to 3 months
    * fix(config): Print service names with --no-interpolate
    * build(deps): bump golang.org/x/sys from 0.26.0 to 0.27.0
    * build(deps): bump golang.org/x/sync from 0.8.0 to 0.9.0

++++ python-kiwi:

  - xorriso: respect efiparttable and gpt_hybrid_mbr
    This should make the xorriso-based ISO build path respect the
    'efiparttable' and 'gpt_hybrid_mbr' settings when building a
    UEFI-compatible image, making it write a GPT disk label by default
    instead of an MBR (msdos) one. If it's building an image that is not
    UEFI-compatible it will always write an MBR label, regardless of
    this setting.
    If 'gpt_hybrid_mbr' is set, xorriso will write an Ubuntu-style
    MBR/GPT hybrid partition table, where the MBR partition table
    includes a partition with type 00 and the bootable flag, as well
    as the partition with type ee required by the UEFI spec. This
    mildly violates the UEFI spec but may make the image bootable on
    native BIOS or CSM firmwares which refuse to boot from a disk with
    no partition marked 'bootable' in the MBR. If 'gpt_hybrid_mbr' is
    not set, xorriso will write a strictly UEFI-spec compliant label,
    with just the 'protective MBR' required by the UEFI spec (no
    bootable partition) and the correct GPT partition table. Note
    this is somewhat different from what gpt_hybrid_mbr does for
    disk images.
    Also, we now pass -compliance no_emul_toc when building ISOs, as
    recommended by upstream in
    https://lists.gnu.org/archive/html/bug-xorriso/2024-11/msg00012.html
    This tool is generally always going to be building ISOs intended
    for write-once use, not multi-session use (and which are rarely,
    these days, written to physical discs at all anyway).
    Signed-off-by: Adam Williamson <awilliam@redhat.com>

++++ grub2:

  - Support s390x Secure Execution (jsc#PED-9531)
    * grub2-s390x-secure-execution-support.patch
  - Update grub2-s390x-set-hostonly.patch to add the patch header
    and the description

++++ kernel-default:

  - SLE16: supported.conf: arm64: fix more split-modules errors
    Following errors are fixed:
    [ 6207s] The following optional modules are used by extra modules:
    [ 6207s] industrialio_hw_consumer needed by stm32_adfsdm
    [ 6207s] industrialio_hw_consumer needed by stm32_dfsdm_adc
    [ 6207s] stm32_dfsdm_adc needed by stm32_adfsdm
    [ 6207s] stm32_dfsdm_core needed by stm32_adfsdm
    [ 6207s] stm32_dfsdm_core needed by stm32_dfsdm_adc
    [ 6207s] stm32_lptimer_trigger needed by stm32_adfsdm
    [ 6207s] stm32_lptimer_trigger needed by stm32_dfsdm_adc
    [ 6207s] stm32_timer_trigger needed by stm32_adfsdm
    [ 6207s] stm32_timer_trigger needed by stm32_dfsdm_adc
  - commit 1bedf5a
  - cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_power()
    (git-fixes).
  - cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_cost()
    (git-fixes).
  - drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_lut_load
    (git-fixes).
  - commit a70686d
  - SLE16: supported.conf: arm64: fix split-modules errors
    Fix following errors:
    [ 6849s] The following optional modules are used by extra modules:
    [ 6849s] ad_sigma_delta needed by ad7173
    [ 6849s] bmi088_accel_core needed by bmi088_accel_i2c
    [ 6849s] clk_qcom needed by camcc_sc8280xp
    [ 6849s] clk_qcom needed by camcc_sm4450
    [ 6849s] clk_qcom needed by camcc_sm7150
    [ 6849s] clk_qcom needed by camcc_sm8150
    [ 6849s] clk_qcom needed by camcc_sm8650
    [ 6849s] clk_qcom needed by camcc_x1e80100
    [ 6849s] clk_qcom needed by dispcc_sm4450
    [ 6849s] clk_qcom needed by dispcc_sm7150
    [ 6849s] clk_qcom needed by dispcc_x1e80100
    [ 6849s] clk_qcom needed by ecpricc_qdu1000
    [ 6849s] clk_qcom needed by gcc_ipq5018
    [ 6849s] clk_qcom needed by gcc_sdx75
    [ 6849s] clk_qcom needed by gcc_sm4450
    [ 6849s] clk_qcom needed by gcc_sm8650
    [ 6849s] clk_qcom needed by gcc_x1e80100
    [ 6849s] clk_qcom needed by gpucc_qcm2290
    [ 6849s] clk_qcom needed by gpucc_sm4450
    [ 6849s] clk_qcom needed by gpucc_sm8450
    [ 6849s] clk_qcom needed by gpucc_sm8550
    [ 6849s] clk_qcom needed by gpucc_sm8650
    [ 6849s] clk_qcom needed by gpucc_x1e80100
    [ 6849s] clk_qcom needed by lpasscc_sc8280xp
    [ 6849s] clk_qcom needed by nsscc_qca8k
    [ 6849s] clk_qcom needed by tcsrcc_sm8650
    [ 6849s] clk_qcom needed by tcsrcc_x1e80100
    [ 6849s] clk_qcom needed by videocc_sm7150
    [ 6849s] clk_qcom needed by videocc_sm8350
    [ 6849s] clk_qcom needed by videocc_sm8450
    [ 6849s] clk_qcom needed by videocc_sm8550
    [ 6849s] ecc_mtk needed by spi_mtk_snfi
    [ 6849s] industrialio_buffer_dma needed by adi_axi_dac
    [ 6849s] industrialio_buffer_dma needed by industrialio_buffer_dmaengine
    [ 6849s] industrialio_buffer_dmaengine needed by adi_axi_dac
    [ 6849s] industrialio_hw_consumer needed by stm32_adfsdm
    [ 6849s] industrialio_hw_consumer needed by stm32_dfsdm_adc
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm4250_lpass_lpi
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm6115_lpass_lpi
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm8350_lpass_lpi
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm8650_lpass_lpi
    [ 6849s] rcar_fcp needed by rcar_du_drm
    [ 6849s] rcar_fcp needed by rzg2l_du_drm
    [ 6849s] rcar_fcp needed by vsp1
    [ 6849s] v4l2_mem2mem needed by stm32_dma2d
    [ 6849s] vsp1 needed by rcar_du_drm
    [ 6849s] vsp1 needed by rzg2l_du_drm
    Mark all new iio modules as optional
  - commit d15d3ea
  - clk: mediatek: drop two dead config options (git-fixes).
  - Update config files.
  - commit 720e07f
  - power: sequencing: make the QCom PMU pwrseq driver depend on
    CONFIG_OF (git-fixes).
  - Update config files.
  - commit 3044556
  - drm/fbdev-dma: Select FB_DEFERRED_IO (git-fixes).
  - Update config files.
  - commit 9b9fb95
  - drm/panic: allow verbose version check (git-fixes).
  - drm/panic: allow verbose boolean for clarity (git-fixes).
  - drm/panic: correctly indent continuation of line in list item
    (git-fixes).
  - drm/panic: remove redundant field when assigning value
    (git-fixes).
  - drm/panic: prefer eliding lifetimes (git-fixes).
  - drm/panic: remove unnecessary borrow in alignment_pattern
    (git-fixes).
  - drm/panic: avoid reimplementing Iterator::find (git-fixes).
  - fbdev: sh7760fb: Fix a possible memory leak in
    sh7760fb_alloc_mem() (git-fixes).
  - drm/amdkfd: Fix wrong usage of INIT_WORK() (git-fixes).
  - drm/amdgpu: Fix map/unmap queue logic (git-fixes).
  - drm/amdgpu: fix ACA bank count boundary check error (git-fixes).
  - drm/panfrost: Add missing OPP table refcnt decremental
    (git-fixes).
  - drm: use ATOMIC64_INIT() for atomic64_t (git-fixes).
  - drm/bridge: it6505: Fix inverted reset polarity (git-fixes).
  - drm/vkms: Drop unnecessary call to drm_crtc_cleanup()
    (git-fixes).
  - drm/etnaviv: hold GPU lock across perfmon sampling (git-fixes).
  - drm/etnaviv: Request pages from DMA32 zone on addressing_limited
    (git-fixes).
  - drm/amdkfd: Use dynamic allocation for CU occupancy array in
    'kfd_get_cu_occupancy()' (git-fixes).
  - drm/amdgpu: fix comment about amdgpu.abmlevel defaults
    (git-fixes).
  - drm/amdgpu: Fix the memory allocation issue in
    amdgpu_discovery_get_nps_info() (git-fixes).
  - drm/msm/dpu: cast crtc_clk calculation to u64 in
    _dpu_core_perf_calc_clk() (git-fixes).
  - drm/xe/hdcp: Fix gsc structure check in fw check status
    (git-fixes).
  - drm/mediatek: Fix child node refcount handling in early exit
    (git-fixes).
  - drm/msm/gpu: Check the status of registration to PM QoS
    (git-fixes).
  - drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - drm/msm: Fix some typos in comment (git-fixes).
  - drm/msm/dpu: drop LM_3 / LM_4 on MSM8998 (git-fixes).
  - drm/msm/dpu: drop LM_3 / LM_4 on SDM845 (git-fixes).
  - drm/msm/dpu: on SDM845 move DSPP_3 to LM_5 block (git-fixes).
  - drm: xlnx: zynqmp_dpsub: fix hotplug detection (git-fixes).
  - drm: xlnx: zynqmp_disp: layer may be null while releasing
    (git-fixes).
  - drm: zynqmp_kms: Unplug DRM device before removal (git-fixes).
  - drm/nouveau/gr/gf100: Fix missing unlock in gf100_gr_chan_new()
    (git-fixes).
  - drm/panfrost: Remove unused id_mask from struct panfrost_model
    (git-fixes).
  - drm: panel: nv3052c: correct spi_device_id for RG35XX panel
    (git-fixes).
  - Revert "drm/amdgpu/gfx9: put queue resets behind a debug option"
    (stable-fixes).
  - drm/amd/display: fix a memleak issue when driver is removed
    (git-fixes).
  - drm/amdgpu/gfx9: Add Cleaner Shader Deinitialization in gfx_v9_0
    Module (git-fixes).
  - drm/amdgpu: Fix JPEG v4.0.3 register write (git-fixes).
  - drm/panic: Select ZLIB_DEFLATE for DRM_PANIC_SCREEN_QR_CODE
    (git-fixes).
  - drm/bridge: tc358767: Fix link properties discovery (git-fixes).
  - drm/vc4: Match drm_dev_enter and exit calls in
    vc4_hvs_atomic_flush (git-fixes).
  - drm: panel: jd9365da-h3: Remove unused num_init_cmds structure
    member (git-fixes).
  - drm/bridge: it6505: Drop EDID cache on bridge power off
    (git-fixes).
  - drm/bridge: anx7625: Drop EDID cache on bridge power off
    (git-fixes).
  - drm/v3d: Flush the MMU before we supply more memory to the
    binner (git-fixes).
  - drm/v3d: Address race-condition in MMU flush (git-fixes).
  - drm/sti: avoid potential dereference of error pointers
    (git-fixes).
  - drm/sti: avoid potential dereference of error pointers in
    sti_gdp_atomic_check (git-fixes).
  - drm/sti: avoid potential dereference of error pointers in
    sti_hqvdp_atomic_check (git-fixes).
  - drm/panel: nt35510: Make new commands optional (git-fixes).
  - drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - drm/imx/dcss: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - drm/panic: Fix uninitialized spinlock acquisition with
    CONFIG_DRM_PANIC=n (git-fixes).
  - drm/v3d: Appease lockdep while updating GPU stats (git-fixes).
  - drm/omap: Fix locking in omap_gem_new_dmabuf() (git-fixes).
  - drm/omap: Fix possible NULL dereference (git-fixes).
  - drm/vc4: hvs: Correct logic on stopping an HVS channel
    (git-fixes).
  - drm/vc4: hvs: Remove incorrect limit from hvs_dlist debugfs
    function (git-fixes).
  - drm/vc4: hvs: Fix dlist debug not resetting the next entry
    pointer (git-fixes).
  - drm/vc4: hdmi: Avoid hang with debug registers when suspended
    (git-fixes).
  - drm/vc4: hvs: Don't write gamma luts on 2711 (git-fixes).
  - drm/mm: Mark drm_mm_interval_tree*() functions with
    __maybe_unused (git-fixes).
  - drm/imagination: Use pvr_vm_context_get() (git-fixes).
  - drm/imagination: Convert to use time_before macro (git-fixes).
  - commit febdd50
  - spi: Fix acpi deferred irq probe (git-fixes).
  - spi: atmel-quadspi: Fix register name in verbose logging
    function (git-fixes).
  - thermal: int3400: Fix reading of current_uuid for active policy
    (git-fixes).
  - remoteproc: qcom_q6v5_mss: Re-order writes to the IMEM region
    (git-fixes).
  - remoteproc: qcom_q6v5_pas: disable auto boot for wpss
    (git-fixes).
  - remoteproc: qcom: pas: add minidump_id to SM8350 resources
    (git-fixes).
  - remoteproc: qcom: adsp: Remove subdevs on the error path of
    adsp_probe() (git-fixes).
  - remoteproc: qcom: pas: Remove subdevs on the error path of
    adsp_probe() (git-fixes).
  - scatterlist: fix a typo (git-fixes).
  - unicode: Fix utf8_load() error path (git-fixes).
  - Revert "wifi: iwlegacy: do not skip frames with bad FCS"
    (git-fixes).
  - wifi: brcmfmac: release 'root' node in all execution paths
    (git-fixes).
  - wifi: rtw89: coex: check NULL return of kmalloc in
    btc_fw_set_monreg() (git-fixes).
  - wifi: nl80211: fix bounds checker error in
    nl80211_parse_sched_scan (git-fixes).
  - wifi: cfg80211: Remove the Medium Synchronization Delay validity
    check (git-fixes).
  - wifi: cw1200: Fix potential NULL dereference (git-fixes).
  - wifi: wfx: Fix error handling in wfx_core_init() (git-fixes).
  - wifi: ath12k: fix warning when unbinding (git-fixes).
  - wifi: ath12k: fix crash when unbinding (git-fixes).
  - wifi: ath12k: remove msdu_end structure for WCN7850 (git-fixes).
  - wifi: ath11k: Fix CE offset address calculation for WCN6750
    in SSR (git-fixes).
  - wifi: ath12k: fix one more memcpy size error (git-fixes).
  - wifi: ath12k: fix use-after-free in ath12k_dp_cc_cleanup()
    (git-fixes).
  - wifi: ath12k: Skip Rx TID cleanup for self peer (git-fixes).
  - wifi: ath10k: fix invalid VHT parameters in
    supported_vht_mcs_rate_nss2 (git-fixes).
  - wifi: ath10k: fix invalid VHT parameters in
    supported_vht_mcs_rate_nss1 (git-fixes).
  - wifi: ath9k: add range check for conn_rsp_epid in
    htc_connect_service() (git-fixes).
  - wifi: rtl8xxxu: Perform update_beacon_work when beaconing is
    enabled (git-fixes).
  - wifi: mwifiex: Fix memcpy() field-spanning write warning in
    mwifiex_config_scan() (git-fixes).
  - wifi: wilc1000: Set MAC after operation mode (git-fixes).
  - wifi: mwifiex: add missing locking for cfg80211 calls
    (git-fixes).
  - wifi: cfg80211: check radio iface combination for multi radio
    per wiphy (git-fixes).
  - wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
  - soc: fsl: cpm1: qmc: Set the ret error code on
    platform_get_irq() failure (git-fixes).
  - soc: fsl: rcpm: fix missing of_node_put() in
    copy_ippdexpcr1_setting() (git-fixes).
  - soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
    (git-fixes).
  - drivers: soc: xilinx: add the missing kfree in
    xlnx_add_cb_for_suspend() (git-fixes).
  - watchdog: Add HAS_IOPORT dependency for SBC8360 and SBC7240
    (git-fixes).
  - tpm: fix signed/unsigned bug when checking event logs
    (git-fixes).
  - =?UTF-8?q?spi:=20zynqmp-gqspi:=20Undo=20runtime=20PM=20ch?=
    =?UTF-8?q?anges=20at=20driver=20exit=20time=E2=80=8B?=
    (git-fixes).
  - spi: tegra210-quad: Avoid shift-out-of-bounds (git-fixes).
  - spi: spi-fsl-lpspi: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - regulator: rk808: Restrict DVS GPIOs to the RK808 variant only
    (git-fixes).
  - regulator: qcom-smd: make smd_vreg_rpm static (git-fixes).
  - scripts/kernel-doc: Do not track section counter across
    processed files (git-fixes).
  - Revert "scripts/faddr2line: Check only two symbols when
    calculating symbol size" (git-fixes).
  - thermal: core: Initialize thermal zones before registering them
    (git-fixes).
  - commit 96ef6e8
  - power: reset: ep93xx: add AUXILIARY_BUS dependency (git-fixes).
  - power: supply: rt9471: Use IC status regfield to report real
    charger status (git-fixes).
  - power: supply: rt9471: Fix wrong WDT function regfield
    declaration (git-fixes).
  - power: supply: bq27xxx: Fix registers of bq27426 (git-fixes).
  - power: supply: core: Remove might_sleep() from
    power_supply_put() (git-fixes).
  - PCI: Fix reset_method_store() memory leak (git-fixes).
  - PCI: tegra194: Move controller cleanups to
    pex_ep_event_pex_rst_deassert() (git-fixes).
  - PCI: rockchip-ep: Fix address translation unit programming
    (git-fixes).
  - PCI: qcom: Disable ASPM L0s for X1E80100 (git-fixes).
  - PCI: qcom-ep: Move controller cleanups to
    qcom_pcie_perst_deassert() (git-fixes).
  - PCI: qcom: Enable MSI interrupts together with Link up if
    'Global IRQ' is supported (git-fixes).
  - PCI: keystone: Add link up check to ks_pcie_other_map_bus()
    (git-fixes).
  - PCI: keystone: Set mode as Root Complex for "ti,keystone-pcie"
    compatible (git-fixes).
  - PCI: j721e: Deassert PERST# after a delay of PCIE_T_PVPERL_MS
    milliseconds (git-fixes).
  - PCI: dwc: ep: Fix advertised resizable BAR size regression
    (git-fixes).
  - pinctrl: k210: Undef K210_PC_DEFAULT (git-fixes).
  - pinctrl: qcom: spmi: fix debugfs drive strength (git-fixes).
  - pinctrl: renesas: Select PINCTRL_RZG2L for RZ/V2H(P) SoC
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix missing return in
    rzg2l_pinctrl_register() (git-fixes).
  - pinctrl: zynqmp: drop excess struct member description
    (git-fixes).
  - platform/x86: panasonic-laptop: Return errno correctly in show
    callback (git-fixes).
  - platform/x86/intel/pmt: allow user offset for PMT callbacks
    (git-fixes).
  - platform/x86: asus-wmi: Fix inconsistent use of thermal policies
    (git-fixes).
  - pmdomain: ti-sci: Add missing of_node_put() for args.np
    (git-fixes).
  - pwm: Assume a disabled PWM to emit a constant inactive output
    (git-fixes).
  - pwm: imx27: Workaround of the pwm output bug when decrease
    the duty cycle (git-fixes).
  - regmap: irq: Set lockdep class for hierarchical IRQ domains
    (git-fixes).
  - platform/chrome: cros_ec_typec: fix missing fwnode reference
    decrement (git-fixes).
  - commit fc6407d
  - net: phy: fix phy_ethtool_set_eee() incorrectly enabling LPI
    (git-fixes).
  - net: usb: lan78xx: Fix refcounting and autosuspend on invalid
    WoL configuration (git-fixes).
  - net: usb: lan78xx: Fix memory leak on device unplug by freeing
    PHY device (git-fixes).
  - net: usb: lan78xx: Fix double free issue with interrupt buffer
    allocation (git-fixes).
  - net: phy: ensure that genphy_c45_an_config_eee_aneg() sees
    new value of phydev->eee_cfg.eee_enabled (git-fixes).
  - PCI: endpoint: Clear secondary (not primary) EPC in
    pci_epc_remove_epf() (git-fixes).
  - PCI: endpoint: Fix PCI domain ID release in pci_epc_destroy()
    (git-fixes).
  - PCI: endpoint: epf-mhi: Avoid NULL dereference if DT lacks
    'mmio' (git-fixes).
  - PCI: of_property: Assign PCI instead of CPU bus address to
    dynamic PCI nodes (git-fixes).
  - PCI: cpqphp: Fix PCIBIOS_* return value confusion (git-fixes).
  - mtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02JW ECC
    information (git-fixes).
  - mtd: spinand: winbond: Fix 512GW and 02JW OOB layout
    (git-fixes).
  - mtd: rawnand: atmel: Fix possible memory leak (git-fixes).
  - mtd: spi-nor: core: replace dummy buswidth from addr to data
    (git-fixes).
  - mtd: spi-nor: spansion: Use nor->addr_nbytes in octal DTR mode
    in RD_ANY_REG_OP (git-fixes).
  - mtd: hyperbus: rpc-if: Add missing MODULE_DEVICE_TABLE
    (git-fixes).
  - mfd: rt5033: Fix missing regmap_del_irq_chip() (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Fix IRQ domain names duplication
    (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices
    (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device
    (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device
    (git-fixes).
  - mfd: da9052-spi: Change read-mask to write-mask (git-fixes).
  - mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to
    fix race (git-fixes).
  - net: phy: fix phylib's dual eee_enabled (git-fixes).
  - net: phy: dp83869: fix status reporting for 1000base-x
    autonegotiation (git-fixes).
  - media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED
    in uvc_parse_format (git-fixes).
  - media: platform: exynos4-is: Fix an OF node reference leak in
    fimc_md_is_isp_available (git-fixes).
  - media: atomisp: Add check for rgby_data memory allocation
    failure (git-fixes).
  - media: venus: sync with threaded IRQ during inst destruction
    (git-fixes).
  - media: venus: fix enc/dec destruction order (git-fixes).
  - media: intel/ipu6: do not handle interrupts when device is
    disabled (git-fixes).
  - media: ov08x40: Fix burst write sequence (git-fixes).
  - media: gspca: ov534-ov772x: Fix off-by-one error in
    set_frame_rate() (git-fixes).
  - media: venus: Fix pm_runtime_set_suspended() with runtime pm
    enabled (git-fixes).
  - media: amphion: Fix pm_runtime_set_suspended() with runtime
    pm enabled (git-fixes).
  - media: i2c: dw9768: Fix pm_runtime_set_suspended() with runtime
    pm enabled (git-fixes).
  - media: ipu6: remove architecture DMA ops dependency in Kconfig
    (git-fixes).
  - media: mantis: remove orphan mantis_core.h (git-fixes).
  - media: vb2: Fix comment (git-fixes).
  - mmc: mmc_spi: drop buggy snprintf() (git-fixes).
  - commit 1b8353d
  - mailbox, remoteproc: k3-m4+: fix compile testing (git-fixes).
  - mailbox: arm_mhuv2: clean up loop in get_irq_chan_comb()
    (git-fixes).
  - mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_get_clocks()
    (git-fixes).
  - lib/Kconfig.debug: move int_pow test option to runtime testing
    section (git-fixes).
  - lib: string_helpers: silence snprintf() output truncation
    warning (git-fixes).
  - maple_tree: refine mas_store_root() on storing NULL (git-fixes).
  - maple_tree: fix alloc node fail issue (git-fixes).
  - leds: ktd2692: Set missing timing properties (git-fixes).
  - leds: max5970: Fix unreleased fwnode_handle in probe function
    (git-fixes).
  - leds: lp55xx: Remove redundant test for invalid channel number
    (git-fixes).
  - leds: flash: mt6360: Fix device_for_each_child_node()
    refcounting in error paths (git-fixes).
  - media: v4l2-core: v4l2-dv-timings: check cvt/gtf result
    (git-fixes).
  - media: uvcvideo: Stop stream during unregister (git-fixes).
  - media: ipu6: remove redundant dependency in Kconfig (git-fixes).
  - media: i2c: ds90ub960: Fix missing return check on
    ub960_rxport_read call (git-fixes).
  - media: i2c: vgxy61: Fix an error handling path in
    vgxy61_detect() (git-fixes).
  - media: ti: j721e-csi2rx: Convert comma to semicolon (git-fixes).
  - media: i2c: max96717: clean up on error in
    max96717_subdev_init() (git-fixes).
  - media: qcom: camss: fix error path on configuration of power
    domains (git-fixes).
  - media: ts2020: fix null-ptr-deref in ts2020_probe() (git-fixes).
  - media: platform: allegro-dvt: Fix possible memory leak in
    allocate_buffers_internal() (git-fixes).
  - media: i2c: tc358743: Fix crash in the probe error path when
    using polling (git-fixes).
  - media: wl128x: Fix atomicity violation in fmc_send_cmd()
    (git-fixes).
  - media: imx-jpeg: Ensure power suppliers be suspended before
    detach them (git-fixes).
  - media: amphion: Set video drvdata before register video device
    (git-fixes).
  - media: imx-jpeg: Set video drvdata before register video device
    (git-fixes).
  - media: mtk-jpeg: Fix null-ptr-deref during unload module
    (git-fixes).
  - media: verisilicon: av1: Fix reference video buffer pointer
    assignment (git-fixes).
  - media: platform: rga: fix 32-bit DMA limitation (git-fixes).
  - media: uvcvideo: Require entities to have a non-zero unique ID
    (git-fixes).
  - commit dbf2447
  - gpio: exar: set value when external pull-up or pull-down is
    present (git-fixes).
  - gpio: zevio: Add missed label initialisation (git-fixes).
  - hwmon: (aquacomputer_d5next) Fix length of speed_input array
    (git-fixes).
  - hwmon: (tps23861) Fix reporting of negative temperatures
    (git-fixes).
  - i3c: master: svc: Modify enabled_events bit 7:0 to act as IBI
    enable counter (git-fixes).
  - i3c: master: svc: Fix pm_runtime_set_suspended() with runtime
    pm enabled (git-fixes).
  - i3c: master: Fix miss free init_dyn_addr at
    i3c_master_put_i3c_addrs() (git-fixes).
  - i3c: master: Remove i3c_dev_disable_ibi_locked(olddev) on
    device hotjoin (git-fixes).
  - i3c: master: svc: fix possible assignment of the same address
    to two devices (git-fixes).
  - Input: imagis - fix warning regarding 'imagis_3038_data'
    being unused (git-fixes).
  - Input: hycon-hy46xx - add missing dependency on REGMAP_I2C
    (git-fixes).
  - Input: hideep - add missing dependency on REGMAP_I2C
    (git-fixes).
  - Input: cs40l50 - fix wrong usage of INIT_WORK() (git-fixes).
  - kasan: move checks to do_strncpy_from_user (git-fixes).
  - kunit: Fix potential null dereference in
    kunit_device_driver_test() (git-fixes).
  - kunit: string-stream: Fix a UAF bug in kunit_init_suite()
    (git-fixes).
  - kunit: skb: use "gfp" variable instead of hardcoding GFP_KERNEL
    (git-fixes).
  - i2c: dev: Fix memory leak when underlying adapter does not
    support I2C (git-fixes).
  - dma-mapping: remove an outdated comment from dma-map-ops.h
    (git-fixes).
  - firmware: arm_scpi: Check the DVFS OPP count returned by the
    firmware (git-fixes).
  - efi/libstub: Free correct pointer on failure (git-fixes).
  - efi/libstub: fix efi_parse_options() ignoring the default
    command line (git-fixes).
  - HID: wacom: Interpret tilt data from Intuos Pro BT as signed
    values (git-fixes).
  - gpio: sloppy-logic-analyzer remove reference to
    rcu_momentary_dyntick_idle() (git-fixes).
  - Documentation: kgdb: Correct parameter error (git-fixes).
  - kcsan, seqlock: Fix incorrect assumption in read_seqbegin()
    (git-fixes).
  - kcsan, seqlock: Support seqcount_latch_t (git-fixes).
  - doc: rcu: update printed dynticks counter bits (git-fixes).
  - hwmon: (nct6775-core) Fix overflows seen when writing limit
    attributes (git-fixes).
  - hwmon: (pmbus/core) clear faults after setting smbalert mask
    (git-fixes).
  - crypto: cavium - Fix an error handling path in
    cpt_ucode_load_fw() (git-fixes).
  - crypto: bcm - add error check in the ahash_hmac_init function
    (git-fixes).
  - crypto: caam - add error check to caam_rsa_set_priv_key_form
    (git-fixes).
  - crypto: inside-secure - Fix the return value of
    safexcel_xcbcmac_cra_init() (git-fixes).
  - crypto: qat - Fix missing destroy_workqueue in adf_init_aer()
    (git-fixes).
  - crypto: hisilicon/qm - disable same error report before
    resetting (git-fixes).
  - crypto: cavium - Fix the if condition to exit loop after timeout
    (git-fixes).
  - crypto: x86/aegis128 - access 32-bit arguments as 32-bit
    (git-fixes).
  - firmware: google: Unregister driver_info on failure (git-fixes).
  - commit ba10c07
  - Bluetooth: MGMT: Fix possible deadlocks (git-fixes).
  - Bluetooth: MGMT: Fix slab-use-after-free Read in
    set_powered_sync (git-fixes).
  - cpufreq: mediatek-hw: Fix wrong return value in
    mtk_cpufreq_get_cpu_power() (git-fixes).
  - cpufreq: loongson3: Check for error code from devm_mutex_init()
    call (git-fixes).
  - cpufreq: scmi: Fix cleanup path when boost enablement fails
    (git-fixes).
  - cpufreq: CPPC: Fix possible null-ptr-deref for
    cppc_get_cpu_cost() (git-fixes).
  - cpufreq: CPPC: Fix possible null-ptr-deref for
    cpufreq_cpu_get_raw() (git-fixes).
  - Revert "cpufreq: brcmstb-avs-cpufreq: Fix initial command check"
    (stable-fixes).
  - cpufreq: loongson2: Unregister platform_driver on failure
    (git-fixes).
  - cppc_cpufreq: Use desired perf if feedback ctrs are 0 or
    unchanged (git-fixes).
  - clk: qcom: clk-alpha-pll: fix lucid 5lpe pll enabled check
    (git-fixes).
  - clk: qcom: clk-alpha-pll: drop lucid-evo pll enabled warning
    (git-fixes).
  - clk: qcom: gcc-qcs404: fix initial rate of GPLL3 (git-fixes).
  - clk: qcom: videocc-sm8550: depend on either gcc-sm8550 or
    gcc-sm8650 (git-fixes).
  - clk: clk-axi-clkgen: make sure to enable the AXI bus clock
    (git-fixes).
  - clk: sunxi-ng: d1: Fix PLL_AUDIO0 preset (git-fixes).
  - clk: imx: imx8-acm: Fix return value check in
    clk_imx_acm_attach_pm_domains() (git-fixes).
  - clk: imx: clk-scu: fix clk enable state save and restore
    (git-fixes).
  - clk: imx: fracn-gppll: fix pll power up (git-fixes).
  - clk: imx: fracn-gppll: correct PLL initialization flow
    (git-fixes).
  - clk: imx: lpcg-scu: SW workaround for errata (e10858)
    (git-fixes).
  - clk: renesas: rzg2l: Fix FOUTPOSTDIV clk (git-fixes).
  - clk: Allow kunit tests to run without OF_OVERLAY enabled
    (git-fixes).
  - clk: ralink: mtmips: fix clocks probe order in oldest ralink
    SoCs (git-fixes).
  - clk: ralink: mtmips: fix clock plan for Ralink SoC RT3883
    (git-fixes).
  - clk: clk-loongson2: Fix potential buffer overflow in
    flexible-array member access (git-fixes).
  - clk: clk-loongson2: Fix memory corruption bug in struct
    loongson2_clk_provider (git-fixes).
  - clk: clk-apple-nco: Add NULL check in applnco_probe (git-fixes).
  - clk: sophgo: avoid integer overflow in sg2042_pll_recalc_rate()
    (git-fixes).
  - ASoC: da7213: Populate max_register to regmap_config
    (git-fixes).
  - ASoC: codecs: Fix atomicity violation in
    snd_soc_component_get_drvdata() (git-fixes).
  - ASoC: rt722-sdca: Remove logically deadcode in rt722-sdca.c
    (git-fixes).
  - ASoC: amd: acp: fix for cpu dai index logic (git-fixes).
  - ASoC: amd: acp: fix for inconsistent indenting (git-fixes).
  - ASoC: fsl-asoc-card: Add missing handling of {hp,mic}-dt-gpios
    (git-fixes).
  - ASoC: fsl_micfil: fix regmap_write_bits usage (git-fixes).
  - ALSA: 6fire: Release resources at card release (git-fixes).
  - ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
    (git-fixes).
  - ALSA: us122l: Use snd_card_free_when_closed() at disconnection
    (git-fixes).
  - ALSA: usx2y: Use snd_card_free_when_closed() at disconnection
    (git-fixes).
  - Bluetooth: fix use-after-free in device_for_each_child()
    (git-fixes).
  - Bluetooth: ISO: Use kref to track lifetime of iso_conn
    (git-fixes).
  - Bluetooth: btbcm: fix missing of_node_put() in
    btbcm_get_board_name() (git-fixes).
  - Bluetooth: btmtk: adjust the position to init iso data anchor
    (git-fixes).
  - ACPI: CPPC: Fix _CPC register setting issue (git-fixes).
  - cpufreq/amd-pstate: Don't update CPPC request in
    amd_pstate_cpu_boost_update() (git-fixes).
  - cpufreq/amd-pstate: Fix non kerneldoc comment (git-fixes).
  - crypto: pcrypt - Call crypto layer directly when
    padata_do_parallel() return -EBUSY (git-fixes).
  - crypto: ecdsa - Update Kconfig help text for NIST P521
    (git-fixes).
  - crypto: qat - remove faulty arbiter config reset (git-fixes).
  - crypto: qat/qat_4xxx - fix off by one in uof_get_name()
    (git-fixes).
  - crypto: qat/qat_420xx - fix off by one in uof_get_name()
    (git-fixes).
  - crypto: qat - remove check after debugfs_create_dir()
    (git-fixes).
  - crypto: caam - Fix the pointer passed to caam_qi_shutdown()
    (git-fixes).
  - crypto: mxs-dcp - Fix AES-CBC with hardware-bound keys
    (git-fixes).
  - acpi/arm64: Adjust error handling procedure in
    gtdt_parse_timer_block() (git-fixes).
  - commit 9685db9
  - Revert "config: Update config for DRM graphics drivers (jsc#11186)"
    This reverts commit f8bed7719a0fa09b55bbc650f404bfd3a570f203.
    The reference to the Jira ticket is incorrect.
  - commit c7da338
  - SLE16: supported.conf: fix more errors reported by split-modules
    arm64:
    [ 6326s] The following unsupported modules are used by supported modules:
    [ 6326s] wire needed by w1_gpio
    [ 6326s] wire needed by w1_therm
    x86_64:
    [ 1616s] The following optional modules are used by extra modules:
    [ 1616s] cros_ec needed by cros_ec_lpcs
    [ 1616s] cros_ec needed by rtc_wilco_ec
    [ 1616s] cros_ec needed by wilco_ec
    [ 1616s] cros_ec_lpcs needed by rtc_wilco_ec
    [ 1616s] cros_ec_lpcs needed by wilco_ec
    [ 1616s] wilco_ec needed by rtc_wilco_ec
  - commit 9198e30
  - config: Fallout from running ./run_oldconfig.sh
  - commit 84c0ddd
  - config: x86_64: Enable HiSilicon BMC graphics driver (jsc#PED-11182)
  - commit a69a48e
  - drm/hibmc: Drop dependency on ARM64 (jsc#PED-11182).
  - commit ca797cd
  - cpufreq/amd-pstate: Default to "powersave" governor when in
    "active mode" on servers (bsc#1233975).
  - commit 454ab2e

++++ kernel-rt:

  - SLE16: supported.conf: arm64: fix more split-modules errors
    Following errors are fixed:
    [ 6207s] The following optional modules are used by extra modules:
    [ 6207s] industrialio_hw_consumer needed by stm32_adfsdm
    [ 6207s] industrialio_hw_consumer needed by stm32_dfsdm_adc
    [ 6207s] stm32_dfsdm_adc needed by stm32_adfsdm
    [ 6207s] stm32_dfsdm_core needed by stm32_adfsdm
    [ 6207s] stm32_dfsdm_core needed by stm32_dfsdm_adc
    [ 6207s] stm32_lptimer_trigger needed by stm32_adfsdm
    [ 6207s] stm32_lptimer_trigger needed by stm32_dfsdm_adc
    [ 6207s] stm32_timer_trigger needed by stm32_adfsdm
    [ 6207s] stm32_timer_trigger needed by stm32_dfsdm_adc
  - commit 1bedf5a
  - cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_power()
    (git-fixes).
  - cpufreq: CPPC: Fix wrong return value in cppc_get_cpu_cost()
    (git-fixes).
  - drm/vc4: Match drm_dev_enter and exit calls in vc4_hvs_lut_load
    (git-fixes).
  - commit a70686d
  - SLE16: supported.conf: arm64: fix split-modules errors
    Fix following errors:
    [ 6849s] The following optional modules are used by extra modules:
    [ 6849s] ad_sigma_delta needed by ad7173
    [ 6849s] bmi088_accel_core needed by bmi088_accel_i2c
    [ 6849s] clk_qcom needed by camcc_sc8280xp
    [ 6849s] clk_qcom needed by camcc_sm4450
    [ 6849s] clk_qcom needed by camcc_sm7150
    [ 6849s] clk_qcom needed by camcc_sm8150
    [ 6849s] clk_qcom needed by camcc_sm8650
    [ 6849s] clk_qcom needed by camcc_x1e80100
    [ 6849s] clk_qcom needed by dispcc_sm4450
    [ 6849s] clk_qcom needed by dispcc_sm7150
    [ 6849s] clk_qcom needed by dispcc_x1e80100
    [ 6849s] clk_qcom needed by ecpricc_qdu1000
    [ 6849s] clk_qcom needed by gcc_ipq5018
    [ 6849s] clk_qcom needed by gcc_sdx75
    [ 6849s] clk_qcom needed by gcc_sm4450
    [ 6849s] clk_qcom needed by gcc_sm8650
    [ 6849s] clk_qcom needed by gcc_x1e80100
    [ 6849s] clk_qcom needed by gpucc_qcm2290
    [ 6849s] clk_qcom needed by gpucc_sm4450
    [ 6849s] clk_qcom needed by gpucc_sm8450
    [ 6849s] clk_qcom needed by gpucc_sm8550
    [ 6849s] clk_qcom needed by gpucc_sm8650
    [ 6849s] clk_qcom needed by gpucc_x1e80100
    [ 6849s] clk_qcom needed by lpasscc_sc8280xp
    [ 6849s] clk_qcom needed by nsscc_qca8k
    [ 6849s] clk_qcom needed by tcsrcc_sm8650
    [ 6849s] clk_qcom needed by tcsrcc_x1e80100
    [ 6849s] clk_qcom needed by videocc_sm7150
    [ 6849s] clk_qcom needed by videocc_sm8350
    [ 6849s] clk_qcom needed by videocc_sm8450
    [ 6849s] clk_qcom needed by videocc_sm8550
    [ 6849s] ecc_mtk needed by spi_mtk_snfi
    [ 6849s] industrialio_buffer_dma needed by adi_axi_dac
    [ 6849s] industrialio_buffer_dma needed by industrialio_buffer_dmaengine
    [ 6849s] industrialio_buffer_dmaengine needed by adi_axi_dac
    [ 6849s] industrialio_hw_consumer needed by stm32_adfsdm
    [ 6849s] industrialio_hw_consumer needed by stm32_dfsdm_adc
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm4250_lpass_lpi
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm6115_lpass_lpi
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm8350_lpass_lpi
    [ 6849s] pinctrl_lpass_lpi needed by pinctrl_sm8650_lpass_lpi
    [ 6849s] rcar_fcp needed by rcar_du_drm
    [ 6849s] rcar_fcp needed by rzg2l_du_drm
    [ 6849s] rcar_fcp needed by vsp1
    [ 6849s] v4l2_mem2mem needed by stm32_dma2d
    [ 6849s] vsp1 needed by rcar_du_drm
    [ 6849s] vsp1 needed by rzg2l_du_drm
    Mark all new iio modules as optional
  - commit d15d3ea
  - clk: mediatek: drop two dead config options (git-fixes).
  - Update config files.
  - commit 720e07f
  - power: sequencing: make the QCom PMU pwrseq driver depend on
    CONFIG_OF (git-fixes).
  - Update config files.
  - commit 3044556
  - drm/fbdev-dma: Select FB_DEFERRED_IO (git-fixes).
  - Update config files.
  - commit 9b9fb95
  - drm/panic: allow verbose version check (git-fixes).
  - drm/panic: allow verbose boolean for clarity (git-fixes).
  - drm/panic: correctly indent continuation of line in list item
    (git-fixes).
  - drm/panic: remove redundant field when assigning value
    (git-fixes).
  - drm/panic: prefer eliding lifetimes (git-fixes).
  - drm/panic: remove unnecessary borrow in alignment_pattern
    (git-fixes).
  - drm/panic: avoid reimplementing Iterator::find (git-fixes).
  - fbdev: sh7760fb: Fix a possible memory leak in
    sh7760fb_alloc_mem() (git-fixes).
  - drm/amdkfd: Fix wrong usage of INIT_WORK() (git-fixes).
  - drm/amdgpu: Fix map/unmap queue logic (git-fixes).
  - drm/amdgpu: fix ACA bank count boundary check error (git-fixes).
  - drm/panfrost: Add missing OPP table refcnt decremental
    (git-fixes).
  - drm: use ATOMIC64_INIT() for atomic64_t (git-fixes).
  - drm/bridge: it6505: Fix inverted reset polarity (git-fixes).
  - drm/vkms: Drop unnecessary call to drm_crtc_cleanup()
    (git-fixes).
  - drm/etnaviv: hold GPU lock across perfmon sampling (git-fixes).
  - drm/etnaviv: Request pages from DMA32 zone on addressing_limited
    (git-fixes).
  - drm/amdkfd: Use dynamic allocation for CU occupancy array in
    'kfd_get_cu_occupancy()' (git-fixes).
  - drm/amdgpu: fix comment about amdgpu.abmlevel defaults
    (git-fixes).
  - drm/amdgpu: Fix the memory allocation issue in
    amdgpu_discovery_get_nps_info() (git-fixes).
  - drm/msm/dpu: cast crtc_clk calculation to u64 in
    _dpu_core_perf_calc_clk() (git-fixes).
  - drm/xe/hdcp: Fix gsc structure check in fw check status
    (git-fixes).
  - drm/mediatek: Fix child node refcount handling in early exit
    (git-fixes).
  - drm/msm/gpu: Check the status of registration to PM QoS
    (git-fixes).
  - drm/msm/adreno: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - drm/msm: Fix some typos in comment (git-fixes).
  - drm/msm/dpu: drop LM_3 / LM_4 on MSM8998 (git-fixes).
  - drm/msm/dpu: drop LM_3 / LM_4 on SDM845 (git-fixes).
  - drm/msm/dpu: on SDM845 move DSPP_3 to LM_5 block (git-fixes).
  - drm: xlnx: zynqmp_dpsub: fix hotplug detection (git-fixes).
  - drm: xlnx: zynqmp_disp: layer may be null while releasing
    (git-fixes).
  - drm: zynqmp_kms: Unplug DRM device before removal (git-fixes).
  - drm/nouveau/gr/gf100: Fix missing unlock in gf100_gr_chan_new()
    (git-fixes).
  - drm/panfrost: Remove unused id_mask from struct panfrost_model
    (git-fixes).
  - drm: panel: nv3052c: correct spi_device_id for RG35XX panel
    (git-fixes).
  - Revert "drm/amdgpu/gfx9: put queue resets behind a debug option"
    (stable-fixes).
  - drm/amd/display: fix a memleak issue when driver is removed
    (git-fixes).
  - drm/amdgpu/gfx9: Add Cleaner Shader Deinitialization in gfx_v9_0
    Module (git-fixes).
  - drm/amdgpu: Fix JPEG v4.0.3 register write (git-fixes).
  - drm/panic: Select ZLIB_DEFLATE for DRM_PANIC_SCREEN_QR_CODE
    (git-fixes).
  - drm/bridge: tc358767: Fix link properties discovery (git-fixes).
  - drm/vc4: Match drm_dev_enter and exit calls in
    vc4_hvs_atomic_flush (git-fixes).
  - drm: panel: jd9365da-h3: Remove unused num_init_cmds structure
    member (git-fixes).
  - drm/bridge: it6505: Drop EDID cache on bridge power off
    (git-fixes).
  - drm/bridge: anx7625: Drop EDID cache on bridge power off
    (git-fixes).
  - drm/v3d: Flush the MMU before we supply more memory to the
    binner (git-fixes).
  - drm/v3d: Address race-condition in MMU flush (git-fixes).
  - drm/sti: avoid potential dereference of error pointers
    (git-fixes).
  - drm/sti: avoid potential dereference of error pointers in
    sti_gdp_atomic_check (git-fixes).
  - drm/sti: avoid potential dereference of error pointers in
    sti_hqvdp_atomic_check (git-fixes).
  - drm/panel: nt35510: Make new commands optional (git-fixes).
  - drm/imx/ipuv3: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - drm/imx/dcss: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - drm/panic: Fix uninitialized spinlock acquisition with
    CONFIG_DRM_PANIC=n (git-fixes).
  - drm/v3d: Appease lockdep while updating GPU stats (git-fixes).
  - drm/omap: Fix locking in omap_gem_new_dmabuf() (git-fixes).
  - drm/omap: Fix possible NULL dereference (git-fixes).
  - drm/vc4: hvs: Correct logic on stopping an HVS channel
    (git-fixes).
  - drm/vc4: hvs: Remove incorrect limit from hvs_dlist debugfs
    function (git-fixes).
  - drm/vc4: hvs: Fix dlist debug not resetting the next entry
    pointer (git-fixes).
  - drm/vc4: hdmi: Avoid hang with debug registers when suspended
    (git-fixes).
  - drm/vc4: hvs: Don't write gamma luts on 2711 (git-fixes).
  - drm/mm: Mark drm_mm_interval_tree*() functions with
    __maybe_unused (git-fixes).
  - drm/imagination: Use pvr_vm_context_get() (git-fixes).
  - drm/imagination: Convert to use time_before macro (git-fixes).
  - commit febdd50
  - spi: Fix acpi deferred irq probe (git-fixes).
  - spi: atmel-quadspi: Fix register name in verbose logging
    function (git-fixes).
  - thermal: int3400: Fix reading of current_uuid for active policy
    (git-fixes).
  - remoteproc: qcom_q6v5_mss: Re-order writes to the IMEM region
    (git-fixes).
  - remoteproc: qcom_q6v5_pas: disable auto boot for wpss
    (git-fixes).
  - remoteproc: qcom: pas: add minidump_id to SM8350 resources
    (git-fixes).
  - remoteproc: qcom: adsp: Remove subdevs on the error path of
    adsp_probe() (git-fixes).
  - remoteproc: qcom: pas: Remove subdevs on the error path of
    adsp_probe() (git-fixes).
  - scatterlist: fix a typo (git-fixes).
  - unicode: Fix utf8_load() error path (git-fixes).
  - Revert "wifi: iwlegacy: do not skip frames with bad FCS"
    (git-fixes).
  - wifi: brcmfmac: release 'root' node in all execution paths
    (git-fixes).
  - wifi: rtw89: coex: check NULL return of kmalloc in
    btc_fw_set_monreg() (git-fixes).
  - wifi: nl80211: fix bounds checker error in
    nl80211_parse_sched_scan (git-fixes).
  - wifi: cfg80211: Remove the Medium Synchronization Delay validity
    check (git-fixes).
  - wifi: cw1200: Fix potential NULL dereference (git-fixes).
  - wifi: wfx: Fix error handling in wfx_core_init() (git-fixes).
  - wifi: ath12k: fix warning when unbinding (git-fixes).
  - wifi: ath12k: fix crash when unbinding (git-fixes).
  - wifi: ath12k: remove msdu_end structure for WCN7850 (git-fixes).
  - wifi: ath11k: Fix CE offset address calculation for WCN6750
    in SSR (git-fixes).
  - wifi: ath12k: fix one more memcpy size error (git-fixes).
  - wifi: ath12k: fix use-after-free in ath12k_dp_cc_cleanup()
    (git-fixes).
  - wifi: ath12k: Skip Rx TID cleanup for self peer (git-fixes).
  - wifi: ath10k: fix invalid VHT parameters in
    supported_vht_mcs_rate_nss2 (git-fixes).
  - wifi: ath10k: fix invalid VHT parameters in
    supported_vht_mcs_rate_nss1 (git-fixes).
  - wifi: ath9k: add range check for conn_rsp_epid in
    htc_connect_service() (git-fixes).
  - wifi: rtl8xxxu: Perform update_beacon_work when beaconing is
    enabled (git-fixes).
  - wifi: mwifiex: Fix memcpy() field-spanning write warning in
    mwifiex_config_scan() (git-fixes).
  - wifi: wilc1000: Set MAC after operation mode (git-fixes).
  - wifi: mwifiex: add missing locking for cfg80211 calls
    (git-fixes).
  - wifi: cfg80211: check radio iface combination for multi radio
    per wiphy (git-fixes).
  - wifi: mwifiex: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - wifi: p54: Use IRQF_NO_AUTOEN flag in request_irq() (git-fixes).
  - soc: fsl: cpm1: qmc: Set the ret error code on
    platform_get_irq() failure (git-fixes).
  - soc: fsl: rcpm: fix missing of_node_put() in
    copy_ippdexpcr1_setting() (git-fixes).
  - soc: ti: smartreflex: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - soc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()
    (git-fixes).
  - drivers: soc: xilinx: add the missing kfree in
    xlnx_add_cb_for_suspend() (git-fixes).
  - watchdog: Add HAS_IOPORT dependency for SBC8360 and SBC7240
    (git-fixes).
  - tpm: fix signed/unsigned bug when checking event logs
    (git-fixes).
  - =?UTF-8?q?spi:=20zynqmp-gqspi:=20Undo=20runtime=20PM=20ch?=
    =?UTF-8?q?anges=20at=20driver=20exit=20time=E2=80=8B?=
    (git-fixes).
  - spi: tegra210-quad: Avoid shift-out-of-bounds (git-fixes).
  - spi: spi-fsl-lpspi: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - regulator: rk808: Restrict DVS GPIOs to the RK808 variant only
    (git-fixes).
  - regulator: qcom-smd: make smd_vreg_rpm static (git-fixes).
  - scripts/kernel-doc: Do not track section counter across
    processed files (git-fixes).
  - Revert "scripts/faddr2line: Check only two symbols when
    calculating symbol size" (git-fixes).
  - thermal: core: Initialize thermal zones before registering them
    (git-fixes).
  - commit 96ef6e8
  - power: reset: ep93xx: add AUXILIARY_BUS dependency (git-fixes).
  - power: supply: rt9471: Use IC status regfield to report real
    charger status (git-fixes).
  - power: supply: rt9471: Fix wrong WDT function regfield
    declaration (git-fixes).
  - power: supply: bq27xxx: Fix registers of bq27426 (git-fixes).
  - power: supply: core: Remove might_sleep() from
    power_supply_put() (git-fixes).
  - PCI: Fix reset_method_store() memory leak (git-fixes).
  - PCI: tegra194: Move controller cleanups to
    pex_ep_event_pex_rst_deassert() (git-fixes).
  - PCI: rockchip-ep: Fix address translation unit programming
    (git-fixes).
  - PCI: qcom: Disable ASPM L0s for X1E80100 (git-fixes).
  - PCI: qcom-ep: Move controller cleanups to
    qcom_pcie_perst_deassert() (git-fixes).
  - PCI: qcom: Enable MSI interrupts together with Link up if
    'Global IRQ' is supported (git-fixes).
  - PCI: keystone: Add link up check to ks_pcie_other_map_bus()
    (git-fixes).
  - PCI: keystone: Set mode as Root Complex for "ti,keystone-pcie"
    compatible (git-fixes).
  - PCI: j721e: Deassert PERST# after a delay of PCIE_T_PVPERL_MS
    milliseconds (git-fixes).
  - PCI: dwc: ep: Fix advertised resizable BAR size regression
    (git-fixes).
  - pinctrl: k210: Undef K210_PC_DEFAULT (git-fixes).
  - pinctrl: qcom: spmi: fix debugfs drive strength (git-fixes).
  - pinctrl: renesas: Select PINCTRL_RZG2L for RZ/V2H(P) SoC
    (git-fixes).
  - pinctrl: renesas: rzg2l: Fix missing return in
    rzg2l_pinctrl_register() (git-fixes).
  - pinctrl: zynqmp: drop excess struct member description
    (git-fixes).
  - platform/x86: panasonic-laptop: Return errno correctly in show
    callback (git-fixes).
  - platform/x86/intel/pmt: allow user offset for PMT callbacks
    (git-fixes).
  - platform/x86: asus-wmi: Fix inconsistent use of thermal policies
    (git-fixes).
  - pmdomain: ti-sci: Add missing of_node_put() for args.np
    (git-fixes).
  - pwm: Assume a disabled PWM to emit a constant inactive output
    (git-fixes).
  - pwm: imx27: Workaround of the pwm output bug when decrease
    the duty cycle (git-fixes).
  - regmap: irq: Set lockdep class for hierarchical IRQ domains
    (git-fixes).
  - platform/chrome: cros_ec_typec: fix missing fwnode reference
    decrement (git-fixes).
  - commit fc6407d
  - net: phy: fix phy_ethtool_set_eee() incorrectly enabling LPI
    (git-fixes).
  - net: usb: lan78xx: Fix refcounting and autosuspend on invalid
    WoL configuration (git-fixes).
  - net: usb: lan78xx: Fix memory leak on device unplug by freeing
    PHY device (git-fixes).
  - net: usb: lan78xx: Fix double free issue with interrupt buffer
    allocation (git-fixes).
  - net: phy: ensure that genphy_c45_an_config_eee_aneg() sees
    new value of phydev->eee_cfg.eee_enabled (git-fixes).
  - PCI: endpoint: Clear secondary (not primary) EPC in
    pci_epc_remove_epf() (git-fixes).
  - PCI: endpoint: Fix PCI domain ID release in pci_epc_destroy()
    (git-fixes).
  - PCI: endpoint: epf-mhi: Avoid NULL dereference if DT lacks
    'mmio' (git-fixes).
  - PCI: of_property: Assign PCI instead of CPU bus address to
    dynamic PCI nodes (git-fixes).
  - PCI: cpqphp: Fix PCIBIOS_* return value confusion (git-fixes).
  - mtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02JW ECC
    information (git-fixes).
  - mtd: spinand: winbond: Fix 512GW and 02JW OOB layout
    (git-fixes).
  - mtd: rawnand: atmel: Fix possible memory leak (git-fixes).
  - mtd: spi-nor: core: replace dummy buswidth from addr to data
    (git-fixes).
  - mtd: spi-nor: spansion: Use nor->addr_nbytes in octal DTR mode
    in RD_ANY_REG_OP (git-fixes).
  - mtd: hyperbus: rpc-if: Add missing MODULE_DEVICE_TABLE
    (git-fixes).
  - mfd: rt5033: Fix missing regmap_del_irq_chip() (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Fix IRQ domain names duplication
    (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices
    (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device
    (git-fixes).
  - mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device
    (git-fixes).
  - mfd: da9052-spi: Change read-mask to write-mask (git-fixes).
  - mfd: tps65010: Use IRQF_NO_AUTOEN flag in request_irq() to
    fix race (git-fixes).
  - net: phy: fix phylib's dual eee_enabled (git-fixes).
  - net: phy: dp83869: fix status reporting for 1000base-x
    autonegotiation (git-fixes).
  - media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED
    in uvc_parse_format (git-fixes).
  - media: platform: exynos4-is: Fix an OF node reference leak in
    fimc_md_is_isp_available (git-fixes).
  - media: atomisp: Add check for rgby_data memory allocation
    failure (git-fixes).
  - media: venus: sync with threaded IRQ during inst destruction
    (git-fixes).
  - media: venus: fix enc/dec destruction order (git-fixes).
  - media: intel/ipu6: do not handle interrupts when device is
    disabled (git-fixes).
  - media: ov08x40: Fix burst write sequence (git-fixes).
  - media: gspca: ov534-ov772x: Fix off-by-one error in
    set_frame_rate() (git-fixes).
  - media: venus: Fix pm_runtime_set_suspended() with runtime pm
    enabled (git-fixes).
  - media: amphion: Fix pm_runtime_set_suspended() with runtime
    pm enabled (git-fixes).
  - media: i2c: dw9768: Fix pm_runtime_set_suspended() with runtime
    pm enabled (git-fixes).
  - media: ipu6: remove architecture DMA ops dependency in Kconfig
    (git-fixes).
  - media: mantis: remove orphan mantis_core.h (git-fixes).
  - media: vb2: Fix comment (git-fixes).
  - mmc: mmc_spi: drop buggy snprintf() (git-fixes).
  - commit 1b8353d
  - mailbox, remoteproc: k3-m4+: fix compile testing (git-fixes).
  - mailbox: arm_mhuv2: clean up loop in get_irq_chan_comb()
    (git-fixes).
  - mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_get_clocks()
    (git-fixes).
  - lib/Kconfig.debug: move int_pow test option to runtime testing
    section (git-fixes).
  - lib: string_helpers: silence snprintf() output truncation
    warning (git-fixes).
  - maple_tree: refine mas_store_root() on storing NULL (git-fixes).
  - maple_tree: fix alloc node fail issue (git-fixes).
  - leds: ktd2692: Set missing timing properties (git-fixes).
  - leds: max5970: Fix unreleased fwnode_handle in probe function
    (git-fixes).
  - leds: lp55xx: Remove redundant test for invalid channel number
    (git-fixes).
  - leds: flash: mt6360: Fix device_for_each_child_node()
    refcounting in error paths (git-fixes).
  - media: v4l2-core: v4l2-dv-timings: check cvt/gtf result
    (git-fixes).
  - media: uvcvideo: Stop stream during unregister (git-fixes).
  - media: ipu6: remove redundant dependency in Kconfig (git-fixes).
  - media: i2c: ds90ub960: Fix missing return check on
    ub960_rxport_read call (git-fixes).
  - media: i2c: vgxy61: Fix an error handling path in
    vgxy61_detect() (git-fixes).
  - media: ti: j721e-csi2rx: Convert comma to semicolon (git-fixes).
  - media: i2c: max96717: clean up on error in
    max96717_subdev_init() (git-fixes).
  - media: qcom: camss: fix error path on configuration of power
    domains (git-fixes).
  - media: ts2020: fix null-ptr-deref in ts2020_probe() (git-fixes).
  - media: platform: allegro-dvt: Fix possible memory leak in
    allocate_buffers_internal() (git-fixes).
  - media: i2c: tc358743: Fix crash in the probe error path when
    using polling (git-fixes).
  - media: wl128x: Fix atomicity violation in fmc_send_cmd()
    (git-fixes).
  - media: imx-jpeg: Ensure power suppliers be suspended before
    detach them (git-fixes).
  - media: amphion: Set video drvdata before register video device
    (git-fixes).
  - media: imx-jpeg: Set video drvdata before register video device
    (git-fixes).
  - media: mtk-jpeg: Fix null-ptr-deref during unload module
    (git-fixes).
  - media: verisilicon: av1: Fix reference video buffer pointer
    assignment (git-fixes).
  - media: platform: rga: fix 32-bit DMA limitation (git-fixes).
  - media: uvcvideo: Require entities to have a non-zero unique ID
    (git-fixes).
  - commit dbf2447
  - gpio: exar: set value when external pull-up or pull-down is
    present (git-fixes).
  - gpio: zevio: Add missed label initialisation (git-fixes).
  - hwmon: (aquacomputer_d5next) Fix length of speed_input array
    (git-fixes).
  - hwmon: (tps23861) Fix reporting of negative temperatures
    (git-fixes).
  - i3c: master: svc: Modify enabled_events bit 7:0 to act as IBI
    enable counter (git-fixes).
  - i3c: master: svc: Fix pm_runtime_set_suspended() with runtime
    pm enabled (git-fixes).
  - i3c: master: Fix miss free init_dyn_addr at
    i3c_master_put_i3c_addrs() (git-fixes).
  - i3c: master: Remove i3c_dev_disable_ibi_locked(olddev) on
    device hotjoin (git-fixes).
  - i3c: master: svc: fix possible assignment of the same address
    to two devices (git-fixes).
  - Input: imagis - fix warning regarding 'imagis_3038_data'
    being unused (git-fixes).
  - Input: hycon-hy46xx - add missing dependency on REGMAP_I2C
    (git-fixes).
  - Input: hideep - add missing dependency on REGMAP_I2C
    (git-fixes).
  - Input: cs40l50 - fix wrong usage of INIT_WORK() (git-fixes).
  - kasan: move checks to do_strncpy_from_user (git-fixes).
  - kunit: Fix potential null dereference in
    kunit_device_driver_test() (git-fixes).
  - kunit: string-stream: Fix a UAF bug in kunit_init_suite()
    (git-fixes).
  - kunit: skb: use "gfp" variable instead of hardcoding GFP_KERNEL
    (git-fixes).
  - i2c: dev: Fix memory leak when underlying adapter does not
    support I2C (git-fixes).
  - dma-mapping: remove an outdated comment from dma-map-ops.h
    (git-fixes).
  - firmware: arm_scpi: Check the DVFS OPP count returned by the
    firmware (git-fixes).
  - efi/libstub: Free correct pointer on failure (git-fixes).
  - efi/libstub: fix efi_parse_options() ignoring the default
    command line (git-fixes).
  - HID: wacom: Interpret tilt data from Intuos Pro BT as signed
    values (git-fixes).
  - gpio: sloppy-logic-analyzer remove reference to
    rcu_momentary_dyntick_idle() (git-fixes).
  - Documentation: kgdb: Correct parameter error (git-fixes).
  - kcsan, seqlock: Fix incorrect assumption in read_seqbegin()
    (git-fixes).
  - kcsan, seqlock: Support seqcount_latch_t (git-fixes).
  - doc: rcu: update printed dynticks counter bits (git-fixes).
  - hwmon: (nct6775-core) Fix overflows seen when writing limit
    attributes (git-fixes).
  - hwmon: (pmbus/core) clear faults after setting smbalert mask
    (git-fixes).
  - crypto: cavium - Fix an error handling path in
    cpt_ucode_load_fw() (git-fixes).
  - crypto: bcm - add error check in the ahash_hmac_init function
    (git-fixes).
  - crypto: caam - add error check to caam_rsa_set_priv_key_form
    (git-fixes).
  - crypto: inside-secure - Fix the return value of
    safexcel_xcbcmac_cra_init() (git-fixes).
  - crypto: qat - Fix missing destroy_workqueue in adf_init_aer()
    (git-fixes).
  - crypto: hisilicon/qm - disable same error report before
    resetting (git-fixes).
  - crypto: cavium - Fix the if condition to exit loop after timeout
    (git-fixes).
  - crypto: x86/aegis128 - access 32-bit arguments as 32-bit
    (git-fixes).
  - firmware: google: Unregister driver_info on failure (git-fixes).
  - commit ba10c07
  - Bluetooth: MGMT: Fix possible deadlocks (git-fixes).
  - Bluetooth: MGMT: Fix slab-use-after-free Read in
    set_powered_sync (git-fixes).
  - cpufreq: mediatek-hw: Fix wrong return value in
    mtk_cpufreq_get_cpu_power() (git-fixes).
  - cpufreq: loongson3: Check for error code from devm_mutex_init()
    call (git-fixes).
  - cpufreq: scmi: Fix cleanup path when boost enablement fails
    (git-fixes).
  - cpufreq: CPPC: Fix possible null-ptr-deref for
    cppc_get_cpu_cost() (git-fixes).
  - cpufreq: CPPC: Fix possible null-ptr-deref for
    cpufreq_cpu_get_raw() (git-fixes).
  - Revert "cpufreq: brcmstb-avs-cpufreq: Fix initial command check"
    (stable-fixes).
  - cpufreq: loongson2: Unregister platform_driver on failure
    (git-fixes).
  - cppc_cpufreq: Use desired perf if feedback ctrs are 0 or
    unchanged (git-fixes).
  - clk: qcom: clk-alpha-pll: fix lucid 5lpe pll enabled check
    (git-fixes).
  - clk: qcom: clk-alpha-pll: drop lucid-evo pll enabled warning
    (git-fixes).
  - clk: qcom: gcc-qcs404: fix initial rate of GPLL3 (git-fixes).
  - clk: qcom: videocc-sm8550: depend on either gcc-sm8550 or
    gcc-sm8650 (git-fixes).
  - clk: clk-axi-clkgen: make sure to enable the AXI bus clock
    (git-fixes).
  - clk: sunxi-ng: d1: Fix PLL_AUDIO0 preset (git-fixes).
  - clk: imx: imx8-acm: Fix return value check in
    clk_imx_acm_attach_pm_domains() (git-fixes).
  - clk: imx: clk-scu: fix clk enable state save and restore
    (git-fixes).
  - clk: imx: fracn-gppll: fix pll power up (git-fixes).
  - clk: imx: fracn-gppll: correct PLL initialization flow
    (git-fixes).
  - clk: imx: lpcg-scu: SW workaround for errata (e10858)
    (git-fixes).
  - clk: renesas: rzg2l: Fix FOUTPOSTDIV clk (git-fixes).
  - clk: Allow kunit tests to run without OF_OVERLAY enabled
    (git-fixes).
  - clk: ralink: mtmips: fix clocks probe order in oldest ralink
    SoCs (git-fixes).
  - clk: ralink: mtmips: fix clock plan for Ralink SoC RT3883
    (git-fixes).
  - clk: clk-loongson2: Fix potential buffer overflow in
    flexible-array member access (git-fixes).
  - clk: clk-loongson2: Fix memory corruption bug in struct
    loongson2_clk_provider (git-fixes).
  - clk: clk-apple-nco: Add NULL check in applnco_probe (git-fixes).
  - clk: sophgo: avoid integer overflow in sg2042_pll_recalc_rate()
    (git-fixes).
  - ASoC: da7213: Populate max_register to regmap_config
    (git-fixes).
  - ASoC: codecs: Fix atomicity violation in
    snd_soc_component_get_drvdata() (git-fixes).
  - ASoC: rt722-sdca: Remove logically deadcode in rt722-sdca.c
    (git-fixes).
  - ASoC: amd: acp: fix for cpu dai index logic (git-fixes).
  - ASoC: amd: acp: fix for inconsistent indenting (git-fixes).
  - ASoC: fsl-asoc-card: Add missing handling of {hp,mic}-dt-gpios
    (git-fixes).
  - ASoC: fsl_micfil: fix regmap_write_bits usage (git-fixes).
  - ALSA: 6fire: Release resources at card release (git-fixes).
  - ALSA: caiaq: Use snd_card_free_when_closed() at disconnection
    (git-fixes).
  - ALSA: us122l: Use snd_card_free_when_closed() at disconnection
    (git-fixes).
  - ALSA: usx2y: Use snd_card_free_when_closed() at disconnection
    (git-fixes).
  - Bluetooth: fix use-after-free in device_for_each_child()
    (git-fixes).
  - Bluetooth: ISO: Use kref to track lifetime of iso_conn
    (git-fixes).
  - Bluetooth: btbcm: fix missing of_node_put() in
    btbcm_get_board_name() (git-fixes).
  - Bluetooth: btmtk: adjust the position to init iso data anchor
    (git-fixes).
  - ACPI: CPPC: Fix _CPC register setting issue (git-fixes).
  - cpufreq/amd-pstate: Don't update CPPC request in
    amd_pstate_cpu_boost_update() (git-fixes).
  - cpufreq/amd-pstate: Fix non kerneldoc comment (git-fixes).
  - crypto: pcrypt - Call crypto layer directly when
    padata_do_parallel() return -EBUSY (git-fixes).
  - crypto: ecdsa - Update Kconfig help text for NIST P521
    (git-fixes).
  - crypto: qat - remove faulty arbiter config reset (git-fixes).
  - crypto: qat/qat_4xxx - fix off by one in uof_get_name()
    (git-fixes).
  - crypto: qat/qat_420xx - fix off by one in uof_get_name()
    (git-fixes).
  - crypto: qat - remove check after debugfs_create_dir()
    (git-fixes).
  - crypto: caam - Fix the pointer passed to caam_qi_shutdown()
    (git-fixes).
  - crypto: mxs-dcp - Fix AES-CBC with hardware-bound keys
    (git-fixes).
  - acpi/arm64: Adjust error handling procedure in
    gtdt_parse_timer_block() (git-fixes).
  - commit 9685db9
  - Revert "config: Update config for DRM graphics drivers (jsc#11186)"
    This reverts commit f8bed7719a0fa09b55bbc650f404bfd3a570f203.
    The reference to the Jira ticket is incorrect.
  - commit c7da338
  - SLE16: supported.conf: fix more errors reported by split-modules
    arm64:
    [ 6326s] The following unsupported modules are used by supported modules:
    [ 6326s] wire needed by w1_gpio
    [ 6326s] wire needed by w1_therm
    x86_64:
    [ 1616s] The following optional modules are used by extra modules:
    [ 1616s] cros_ec needed by cros_ec_lpcs
    [ 1616s] cros_ec needed by rtc_wilco_ec
    [ 1616s] cros_ec needed by wilco_ec
    [ 1616s] cros_ec_lpcs needed by rtc_wilco_ec
    [ 1616s] cros_ec_lpcs needed by wilco_ec
    [ 1616s] wilco_ec needed by rtc_wilco_ec
  - commit 9198e30
  - config: Fallout from running ./run_oldconfig.sh
  - commit 84c0ddd
  - config: x86_64: Enable HiSilicon BMC graphics driver (jsc#PED-11182)
  - commit a69a48e
  - drm/hibmc: Drop dependency on ARM64 (jsc#PED-11182).
  - commit ca797cd
  - cpufreq/amd-pstate: Default to "powersave" governor when in
    "active mode" on servers (bsc#1233975).
  - commit 454ab2e

++++ gpgme:

  - Add gpgme-fix-python-install.patch: Fix the installation of the
    python bindings without having to move them around manually.

++++ python313-core:

  - Drop CVE-2023-52425-libexpat-2.6.0-backport-15.6.patch, not needed
    anymore because libexpat is updated to 2.6 in SP7. bsc#1233777

++++ logrotate:

  - Skip test-0110.sh which fails after update in the build chroot
    but not with identical settings on TW.
    * Add logrotate-3.22-skip-failing-test.patch

++++ nvidia-open-driver-G06-signed:

  - Add 'dummy' firmware package on SLE to work around update
    issues. On SLE, the firmware is installed directly from
    an NVIDIA-hosted repo.

++++ opensuse-migration-tool:

  - Update to version 20241129.2509e96:
    * Rename migration-tool to opensuse-migration-tool
    * Ensure that we use opensuse-migration-tool name consistently
    * Rename migration-tool.sh to opensuse-migration-tool
    * Use /usr/share/migration-tool/SLES.prod

++++ python313:

  - Drop CVE-2023-52425-libexpat-2.6.0-backport-15.6.patch, not needed
    anymore because libexpat is updated to 2.6 in SP7. bsc#1233777

++++ selinux-policy:

  - Update macros.selinux-policy to trigger a full relabel on transactional
    systems upon module installation. This is rather expensive and will
    hopefully be replaced by a more fine grained solution later on (bsc#1232753)

------------------------------------------------------------------
------------------  2024-11-28  -  Nov 28 2024  -------------------
------------------------------------------------------------------

++++ file:

  - Update to 5.46:
    * Add OFFPOSITIVE
    * avoid leaking symbols in libmagic
    * PR/562: jsummers: Search/regex offsets are absolute to the
    beginning of the file, so adjust them by subtracting the
    offset that the "use" starts so that we don't double-count it.
    * PR/543: matshch: bump nbuf so we can get the flags into the buffer.
    * Add Android elf notes (enh)
    * Add limit for number of magic warnings allowed
    * check regex bounds (found by clusterfuzz)
  - Remove patch file-5.45-type_t.dif now upstream
  - Port patches
    * file-4.24-autoconf.dif
    * file-5.17-option.dif
    * file-5.18-javacheck.dif
    * file-5.19-biorad.dif
    * file-5.19-printf.dif
    * file-5.19-zip2.0.dif
    * file-5.22-elf.dif
    * file-5.28-btrfs-image.dif
    * file-5.45-type_t.dif
    * file-secure_getenv.patch
  - Port patch file-5.45.dif and rename it to file-5.46.dif
    * Note that our kernel magics do not fit anymore as
    upstream now has a huge rework and extended features

++++ kernel-default:

  - amd-pstate: Switch to amd-pstate by default on some Server
    platforms (bsc#1233975).
  - commit 9c67ff1
  - amd-pstate: Set min_perf to nominal_perf for active mode
    performance gov (bsc#1233975).
  - commit 28d6ce6
  - SLE16: supported.conf: fix errors reported by split-modules
    Workaround false positives for implicitly declared modules
    by adding them explicitly.
  - commit 11a0cf1
  - Refresh patches.suse/powerpc-kexec_file-Add-KEXEC_SIG-support.patch.
    Avoid compiler warning
  - commit e0b7746
  - Refresh
    patches.suse/livepatch-mark-the-kernel-unsupported-when-disabling.patch.
  - commit b021387

++++ kernel-rt:

  - amd-pstate: Switch to amd-pstate by default on some Server
    platforms (bsc#1233975).
  - commit 9c67ff1
  - amd-pstate: Set min_perf to nominal_perf for active mode
    performance gov (bsc#1233975).
  - commit 28d6ce6
  - SLE16: supported.conf: fix errors reported by split-modules
    Workaround false positives for implicitly declared modules
    by adding them explicitly.
  - commit 11a0cf1
  - Refresh patches.suse/powerpc-kexec_file-Add-KEXEC_SIG-support.patch.
    Avoid compiler warning
  - commit e0b7746
  - Refresh
    patches.suse/livepatch-mark-the-kernel-unsupported-when-disabling.patch.
  - commit b021387

++++ cairo:

  - Convert to source service: allows for easier upgrades by the
    GNOME team.

++++ linuxptp:

  - Update to version 4.4:
    * Version 4.4
    * ts2phc: check is_running in ts2phc_pps_sink_poll()
    * ts2phc: check for errors on polling the sink devices
    * timemaster: Wait for udev to set up vclock devices.
    * ts2phc: Fix description of holdover option in man page.
    * ts2phc: Describe servo options in man page.
    * nmea: Fix tm_isdst uninitialized
    * Complete SNMP cleanup.
    * Add permanent subscription option
    * rtnl: check if the kernel provides if_team
    * port: Drop received 802.1AS packets with invalid transportSpecific values
    * ts2phc: Fix timestamp conversion for leap seconds.
    * nmea: Fix conversion of leap second.
    * ts2phc: Reset parser after RMC message.
    * Drop example snmpd.conf.
    * ts2phc: Add option to correct for NMEA delay.
    * ts2phc: Allow longer NMEA delays.
    * ts2phc: Move upper/lower rejection limit calculation.
    * ts2phc: Fix edge rejection for pulse widths over 0.5s.
    * ts2phc: Provide source type.
    * Filter any PTP frames with the source MAC of the local interface
    * ts2phc: Add holdover support.
    * ts2phc: Avoid unnecessary call of getppstime().
    * Version 4.3
    * ts2phc: Use CLOCK_MONOTONIC_RAW for NMEA PPS timestamp.
    * nsm: add authentication tlv for nsm
    * pmc: add authentication tlv for pmc
    * msg: add authentication tlv in management handling
    * sad: introduce sad_update_auth_tlv()
    * man: add man/README updates for authentication tlv
    * sad: introduce sad_append_auth_tlv() and sad_generate_icv()
    * sad: introduce sad_set_last_seqid() and sad_check_seqid()
    * port: add security processing to bc_event()
    * sad: introduce sad_process_auth() and sad_check_auth_tlv()
    * sad: introduce openssl mac library
    * sad: introduce gnupg mac library
    * sad: introduce gnutls mac library
    * sad: introduce nettle mac library
    * sad: introduce security association database
    * tlv: add authentication tlv
    * udp+udp6: Make IP addresses configurable.
    * Add support for '-l' option to tz2alt.c as documented in its man page.
    * Clean up compiler warnings about print_level.
    * Clean up compiler warning in ts2phc_pps_sink.c.
    * Clean up compiler warning in ts2phc.c.
    * Clean up compiler warning in port.c.
    * README: update mailing list.
    * ts2phc: interact with new kernel timestamp channel masks
    * lstab: Update Leap Second table validity
    * Fix indentation in example configs.
    * Document allowedLostResponses option.
    * config: Allow port sections with longer names.
    * sk: Fix descriptor leak in sk_get_if_info().
    * lstab: Don't free lstab on update.
    * lstab: Limit number of parsed leap seconds.
    * uds: Warn if replacing existing socket.
    * Add example Common Mean Link Delay Service configuration files.
    * Implement the COMMON_P2P delay mechanism.
    * Add a push notification for the CMLDS TLV.
    * Introduce the Common Mean Link Delay Information TLV.
    * pmc: Make SET SUBSCRIBE_EVENTS_NP forwards compatible.
    * pmc/uds: Configure the remote server address using the interface API.
    * interface: Add an optional remote address for use by the UDS transport.
    * ts2phc: Don't switch system clock to nanosecond mode.
    * Version 4.2
    * phc_ctl: Use util.h NSEC_PER_SEC macro instead of local macro
    * servo: Use util.h NSEC_PER_SEC macro instead of local macro
    * port: Use util.h NSEC_PER_SEC macro instead of local macro
    * util: Introduce NSEC_PER_SEC macro
    * port: Fix multiple pdelay response handling
    * Make allowedLostResponses configurable
    * ptp4l: Allow advertisement of legacy PTP 2.0 protocol
    * msg: Enable changing PTP message header version
    * linuxptp: Use ${CC} in incdefs.sh
    * include string.h for strncpy()
    * lstab: Update leapfile validity
    * print: Support log level in message tag.
    * phc2sys: Stop synchronization when ptp4l stops responding.
    * phc2sys: Better indicate domain with realtime clock.
    * pmc_agent: Make update interval configurable.
    * pmc_agent: Add function to check if still subscribed.
    * port: set_tmo_log() timer interval calculation fix
    * Add notification for changes in PARENT_DATA_SET.
    * clock: Downgrade log message about failed uds forward.
    * Avoid conflicting port IDs over PMC UDS
    * phc_ctl: Use pr_notice instead of pr_err for displaying adjusted frequency
    * phc_ctl: Add maximum offset capability
    * phc_ctl: Add phase command to support ADJ_OFFSET

++++ mcelog:

  - Update to version 201:
    * add listen backlog config for mcelog server
    * mcelog: Add basic support for Diamond Rapids
    * mcelog: Add support for other CPU families

++++ nvidia-open-driver-G06-signed:

  - preamble
    * resolve self conflicts of -cuda KMP during update by adding
    obsoletes to older versions (boo#1233332)

++++ opensuse-migration-tool:

  - Update to version 20241129.c1d6038:
    * Use /usr/share/migration-tool/SLES.prod
    * Working migration to pretty much all releases
    * Fix branding for SLE
    * Replace macro with etc as macro doesn't work
    * rpmsave Leap files after migration to TW/Slowroll
    * Update README.md
    * Fix license to Apache 2
    * Support for Leap->SLE
    * Fix repo naming
    * Add rpmsaving repos

++++ tuned:

  - Fix below security issues found by SUSE security review of latest
    polkit API additions. Kudos go to Matthias Gerstner (bsc#1232412)
  - fixed privileged execution of arbitrary scripts by active local user
    resolves: CVE-2024-52336
  - added sanity checks for API methods parameters
    resolves: CVE-2024-52337
  - Update to version 2.24.1.0+git.90c24ee:
    * new release (2.24.1)
    * spec: used macro for profiles path and other fixes
    * realtime: remove leftover use of tuna

++++ vim:

  - Fix for bsc#1231373 / CVE-2024-47814.
  - Fix for bsc#1229238 / CVE-2024-43374.
  - update to 9.1.0836
    * 9.1.0836: The vimtutor can be improved
    * 9.1.0835: :setglobal doesn't work properly for 'ffu' and 'tsrfu'
    * 9.1.0834: tests: 2html test fails
    * 9.1.0833: CI: recent ASAN changes do not work for indent tests
    * 9.1.0832: :set doesn't work for 'cot' and 'bkc' after :setlocal
    * runtime(doc): update help-toc description
    * runtime(2html): Make links use color scheme colors in TOhtml
    * 9.1.0831: 'findexpr' can't be used as lambad or Funcref
    * Filelist: include helptoc package
    * runtime(doc): include a TOC Vim9 plugin
    * Filelist: ignore .git-blame-ignore-revs
    * 9.1.0830: using wrong highlight group for spaces for popupmenu
    * runtime(typst): synchronize updates from the upstream typst.vim
    * git: ignore reformatting commit for git-blame (after v9.1.0829)
    * 9.1.0829: Vim source code uses a mix of tabs and spaces
    * 9.1.0828: string_T struct could be used more often
    * 9.1.0827: CI: tests can be improved
    * runtime(doc): remove stray sentence in pi_netrw.txt
    * 9.1.0826: filetype: sway files are not recognized
    * runtime(doc): Include netrw-gp in TOC
    * runtime(doc): mention 'iskeyword' at :h charclass()
    * runtime(doc): update help tags
    * 9.1.0825: compile error for non-diff builds
    * runtime(netrw): fix E874 when browsing remote directory which contains `~` character
    * runtime(doc): update coding style documentation
    * runtime(debversions): Add plucky (25.04) as Ubuntu release name
    * 9.1.0824: too many strlen() calls in register.c
    * 9.1.0823: filetype: Zephyr overlay files not recognized
    * runtime(doc): Clean up minor formatting issues for builtin functions
    * runtime(netrw): make :Launch/Open autoloadable
    * runtime(netrw): fix regression with x mapping on Cygwin
    * runtime(netrw): fix filetype detection for remote files
    * 9.1.0822: topline might be changed in diff mode unexpectedly
    * CI: huge linux builds should also run syntax & indent tests
    * 9.1.0821: 'findexpr' completion doesn't set v:fname to cmdline argument
    * 9.1.0820: tests: Mac OS tests are too flaky
    * runtime(awk): Highlight more awk comments in syntax script
    * runtime(netrw): add missing change for s:redir()
    * 9.1.0819: tests: using findexpr and imported func not tested
    * runtime(netrw): improve netrw's open-handling further
    * runtime(netrw): fix syntax error in netrwPlugin.vim
    * runtime(netrw): simplify gx file handling
    * 9.1.0818: some global functions are only used in single files
    * 9.1.0817: termdebug: cannot evaluate expr in a popup
    * runtime(defaults): Detect putty terminal and switch to dark background
    * 9.1.0816: tests: not clear what tests cause asan failures
    * runtime(doc): Remove some completed items from todo.txt
    * 9.1.0815: "above" virtual text causes wrong 'colorcolumn' position
    * runtime(syntax-tests): tiny vim fails because of line-continuation
    * 9.1.0814: mapset() may remove unrelated mapping
    * 9.1.0813: no error handling with setglobal and number types
    * 9.1.0812: Coverity warns about dereferencing NULL ptr
    * 9.1.0811: :find expansion does not consider 'findexpr'
    * 9.1.0810: cannot easily adjust the |:find| command
    * 9.1.0809: filetype: petalinux config files not recognized
    * 9.1.0808: Terminal scrollback doesn't shrink when decreasing 'termwinscroll'
    * 9.1.0807: tests: having 'nolist' in modelines isn't always desired
    * 9.1.0806: tests: no error check when setting global 'briopt'
    * 9.1.0805: tests: minor issues in gen_opt_test.vim
    * 9.1.0804: tests: no error check when setting global 'cc'
    * 9.1.0803: tests: no error check when setting global 'isk'
    * 9.1.0802: tests: no error check when setting global 'fdm' to empty value
    * 9.1.0801: tests: no error check when setting global 'termwinkey'
    * 9.1.0800: tests: no error check when setting global 'termwinsize'
    * runtime(doc): :ownsyntax also resets 'spelloptions'
    * 9.1.0799: tests: gettwinvar()/gettabwinvar() tests are not comprehensive
    * runtime(doc): Fix wrong Mac default options
    * 9.1.0798: too many strlen() calls in cmdhist.c
    * 9.1.0797: testing of options can be further improved
    * 9.1.0796: filetype: libtool files are not recognized
    * (typst): add folding to typst ftplugin
    * runtime(netrw): deprecate and remove netrwFileHandlers#Invoke()
    * 9.1.0795: filetype: Vivado memory info file are not recognized
    * 9.1.0794: tests: tests may fail on Windows environment
    * runtime(doc): improve the :colorscheme documentation
    * 9.1.0793: xxd: -e does add one extra space
    * 9.1.0792: tests: Test_set_values() is not comprehensive enough
    * runtime(swayconfig): add flag for bindsym/bindcode to syntax script
    * 9.1.0791: tests: errors in gen_opt_test.vim are not shown
    * runtime(compiler): check for compile_commands in build dirs for cppcheck
    * 9.1.0790: Amiga: AmigaOS4 build should use default runtime (newlib)
    * runtime(help): Update help syntax
    * runtime(help): fix end of sentence highlight in code examples
    * runtime(jinja): Support jinja syntax as secondary filetype
    * 9.1.0789: tests: ':resize + 5' has invalid space after '+'
    * 9.1.0788: <CSI>27;<mod>u is not decoded to literal Escape in kitty/foot
    * 9.1.0787: cursor position changed when using hidden terminal
    * 9.1.0786: tests: quickfix update test does not test location list
    * runtime(doc): add some docs for file-watcher programs
    * CI: uploading failed screendumps still fails on Cirrus CI
    * 9.1.0785: cannot preserve error position when setting quickfix list
    * 9.1.0784: there are several problems with python 3.13
    * 9.1.0783: 'spell' option setting has problems
    * 9.1.0782: tests: using wrong neomuttlog file name
    * runtime(doc): add preview flag to statusline example
    * 9.1.0781: tests: test_filetype fails
    * 9.1.0780: MS-Windows: incorrect Win32 error checking
    * 9.1.0779: filetype: neomuttlog files are not recognized
    * 9.1.0778: filetype: lf config files are not recognized
    * runtime(comment): fix commment toggle with mixed tabs & spaces
    * runtime(misc): Use consistent "Vim script" spelling
    * runtime(gleam): add ftplugin for gleam files
    * runtime(doc): link help-writing from write-local-help
    * 9.1.0777: filetype: Some upstream php files are not recognized
    * runtime(java): Define javaBlockStart and javaBlockOtherStart hl groups
    * runtime(doc): mention conversion rules for remote_expr()
    * runtime(tutor): Fix missing :s command in spanish translation section 4.4
    * 9.1.0776: test_strftime may fail because of missing TZ data
    * translation(am): Add Armenian language translation
    * 9.1.0775: tests: not enough tests for setting options
    * 9.1.0774: "shellcmdline" doesn't work with getcompletion()
    * 9.1.0773: filetype: some Apache files are not recognized
    * 9.1.0772: some missing changes from v9.1.0771
    * 9.1.0771: completion attribute hl_group is confusing
    * 9.1.0770: current command line completion is a bit limited
    * 9.1.0769: filetype: MLIR files are not recognized
    * 9.1.0768: MS-Windows: incorrect cursor position when restoring screen
    * runtime(nasm): Update nasm syntax script
    * 9.1.0767: A condition is always true in ex_getln.c
    * runtime(skill): Update syntax file to fix string escapes
    * runtime(help): highlight CTRL-<Key> correctly
    * runtime(doc): add missing usr_52 entry to toc
    * 9.1.0766: too many strlen() calls in ex_getln.c
    * runtime(doc): correct `vi` registers 1-9 documentation error
    * 9.1.0765: No test for patches 6.2.418 and 7.3.489
    * runtime(spec): set comments and commentstring options
    * NSIS: Include libgcc_s_sjlj-1.dll again
    * runtime(doc): clarify the effect of 'startofline' option
    * 9.1.0764: [security]: use-after-free when closing a buffer
    * runtime(vim): Update base-syntax file, improve class, enum and interface highlighting
    * 9.1.0763: tests: cannot run single syntax tests
    * 9.1.0762: 'cedit', 'termwinkey' and 'wildchar' may not be parsed correctly
    * 9.1.0761: :cd completion fails on Windows with backslash in path
    * 9.1.0760: tests: no error reported, if gen_opt_test.vim fails
    * 9.1.0759: screenpos() may return invalid position
    * runtime(misc): unset compiler in various ftplugins
    * runtime(doc): update formatting and syntax
    * runtime(compiler): add cppcheck linter compiler plugin
    * runtime(doc): Fix style in documents
    * runtime(doc): Fix to two-space convention in user manual
    * runtime(comment): consider &tabstop in lines after whitespace indent
    * 9.1.0758: it's possible to set an invalid key to 'wildcharm'
    * runtime(java): Manage circularity for every :syn-included syntax file
    * 9.1.0757: tests: messages files contains ANSI escape sequences
    * 9.1.0756: missing change from patch v9.1.0754
    * 9.1.0755: quickfix list does not handle hardlinks well
    * runtime(doc): 'filetype', 'syntax' and 'keymap' only allow alphanumeric + some characters
    * runtime(systemd): small fixes to &keywordprg in ftplugin
    * CI: macos-12 runner is being sunset, switch to 13
    * 9.1.0754: fixed order of items in insert-mode completion menu
    * runtime(comment): commenting might be off by one column
    * 9.1.0753: Wrong display when typing in diff mode with 'smoothscroll'
    * 9.1.0752: can set 'cedit' to an invalid value
    * runtime(doc): add `usr` tag to usr_toc.txt
    * 9.1.0751: Error callback for term_start() not used
    * 9.1.0750: there are some Win9x legacy references
    * runtime(java): Recognise the CommonMark form (///) of Javadoc comments
    * 9.1.0749: filetype: http files not recognized
    * runtime(comment): fix syntax error
    * CI: uploading failed screendump tests does not work Cirrus
    * 9.1.0748: :keep* commmands are sometimes misidentified as :k
    * runtime(indent): allow matching negative numbers for gnu indent config file
    * runtime(comment): add gC mapping to (un)comment rest of line
    * 9.1.0747: various typos in repo found
    * 9.1.0746: tests: Test_halfpage_longline() fails on large terminals
    * runtime(doc): reformat gnat example
    * runtime(doc): reformat ada_standard_types section
    * 9.1.0745: filetype: bun and deno history files not recognized
    * runtime(glvs): Correct the tag name of glvs-autoinstal
    * runtime(doc): include short form for :earlier/:later
    * runtime(doc): remove completed TODO
    * 9.1.0744: filetype: notmuch configs are not recognised
    * 9.1.0743: diff mode does not handle overlapping diffs correctly
    * runtime(glvs): fix a few issues
    * runtime(doc): Fix typo in :help :command-modifiers
    * 9.1.0742: getcmdprompt() implementation can be improved
    * runtime(docs): update `:set?` command behavior table
    * runtime(doc): update vim90 to vim91 in docs
    * runtime(doc): fix typo in :h dos-colors
    * 9.1.0741: No way to get prompt for input()/confirm()
    * runtime(doc): fix typo in version9.txt nrformat -> nrformats
    * runtime(rmd,rrst): 'fex' option not properly restored
    * runtime(netrw): remove extraneous closing bracket
    * 9.1.0740: incorrect internal diff with empty file
    * 9.1.0739: [security]: use-after-free in ex_getln.c
    * runtime(filetype): tests: Test_filetype_detection() fails
    * runtime(dist): do not output a message if executable is not found
    * 9.1.0738: filetype: rapid files are not recognized
    * runtime(modconf): remove erroneous :endif in ftplugin
    * runtime(lyrics): support multiple timestamps in syntax script
    * runtime(java): Optionally recognise _module_ import declarations
    * runtime(vim): Update base-syntax, improve folding function matches
    * CI: upload failed screendump tests also for Cirrus
    * 9.1.0737: tests: screendump tests may require a bit more time
    * runtime(misc): simplify keywordprg in various ftplugins
    * runtime(java): Optionally recognise all primitive constants in _switch-case_ labels
    * runtime(zsh,sh): set and unset compiler in ftplugin
    * runtime(netrw): using inefficient highlight pattern for 'mf'
    * 9.1.0736: Unicode tables are outdated
    * 9.1.0735: filetype: salt files are not recognized
    * 9.1.0734: filetype: jinja files are not recognized
    * runtime(zathurarc): add double-click-follow to syntax script
    * translation(ru): Updated messages translation
    * translation(it): updated xxd man page
    * translation(ru): updated xxd man page
    * 9.1.0733: keyword completion does not work with fuzzy
    * 9.1.0732: xxd: cannot use -b and -i together
    * runtime(java): Highlight javaConceptKind modifiers with StorageClass
    * runtime(doc): reword and reformat how to use defaults.vim
    * 9.1.0731: inconsistent case sensitive extension matching
    * runtime(vim): Update base-syntax, match Vim9 bool/null literal args to :if/:while/:return
    * runtime(netrw): delete confirmation not strict enough
    * 9.1.0730: Crash with cursor-screenline and narrow window
    * 9.1.0729: Wrong cursor-screenline when resizing window
    * 9.1.0728: [security]: heap-use-after-free in garbage collection with location list user data
    * runtime(doc): clarify the effect of the timeout for search()-functions
    * runtime(idlang): update syntax script
    * runtime(spec): Recognize epoch when making spec changelog in ftplugin
    * runtime(spec): add file triggers to syntax script
    * 9.1.0727: too many strlen() calls in option.c
    * runtime(make): add compiler/make.vim to reset compiler plugin settings
    * runtime(java): Recognise all available standard doclet tags
    * 9.1.0726: not using correct python3 API with dynamic linking
    * runtime(dosini): Update syntax script, spellcheck comments only
    * runtime(doc): Revert outdated comment in completeopt's fuzzy documentation
    * 9.1.0725: filetype: swiftinterface files are not recognized
    * runtime(pandoc): Update compiler plugin to use actual 'spelllang'
    * runtime(groff): Add compiler plugin for groff
    * 9.1.0724: if_python: link error with python 3.13 and stable ABI
    * 9.1.0723: if_python: dynamic linking fails with python3 >= 3.13
    * 9.1.0722: crash with large id in text_prop interface
    * 9.1.0721: tests: test_mksession does not consider XDG_CONFIG_HOME
    * runtime(glvs): update GetLatestVimScripts plugin
    * runtime(doc): Fix typo in :help :hide text
    * runtime(doc): buffers can be re-used
    * 9.1.0720: Wrong breakindentopt=list:-1 with multibyte or TABs
    * 9.1.0719: Resetting cell widths can make 'listchars' or 'fillchars' invalid
    * runtime(doc): Update version9.txt and mention $MYVIMDIR
  - Update to 9.1.0718:
    * v9.1.0718: hard to know the users personal Vim Runtime Directory
    * v9.1.0717: Unnecessary nextcmd NULL checks in parse_command_modifiers()
    Maintainers: fix typo in author name
    * v9.1.0716: resetting setcellwidth( doesn't update the screen
    runtime(hcl,terraform): Add runtime files for HCL and Terraform
    runtime(tmux): Update syntax script
    * v9.1.0715: Not correctly parsing color names (after v9.1.0709)
    * v9.1.0714: GuiEnter_Turkish test may fail
    * v9.1.0713: Newline causes E749 in Ex mode
    * v9.1.0712: missing dependency of Test_gettext_makefile
    * v9.1.0711: test_xxd may file when using different xxd
    * v9.1.0710: popup window may hide part of Command line
    runtime(vim): Update syntax, improve user-command matching
    * v9.1.0709: GUIEnter event not found in Turkish locale
    runtime(sudoers): improve recognized Runas_Spec and Tag_Spec items
    * v9.1.0708: Recursive window update does not account for reset skipcol
    runtime(nu): include filetype plugin
    * v9.1.0707: invalid cursor position may cause a crash
    * v9.1.0706: test_gettext fails when using shadow dir
    CI: Install locales-all package
    * v9.1.0705: Sorting of fuzzy filename completion is not stable
    translation(pt): update Portuguese/Brazilian menu translation
    runtime(vim): Update base-syntax, match bracket mark ranges
    runtime(doc): Update :help :command-complete list
    * v9.1.0704: inserting with a count is inefficient
    runtime(doc): use mkdir -p to save a command
    * v9.1.0703: crash with 2byte encoding and glob2regpat()
    runtime(hollywood): update syn highlight for If-Then statements
    and For-In-Loops
    * v9.1.0702: Patch 9.1.0700 broke CI
    * v9.1.0701: crash with NFA regex engine when searching for
    composing chars
    * v9.1.0700: crash with 2byte encoding and glob2regpat()
    * v9.1.0699: "dvgo" is not always an inclusive motion
    runtime(java): Provide support for syntax preview features
    * v9.1.0698: "Untitled" file not removed when running Test_crash1_3
    alone
    * v9.1.0697: heap-buffer-overflow in ins_typebuf
    * v9.1.0696: installing runtime files fails when using SHADOWDIR
    runtime(doc): fix typo
    * v9.1.0695: test_crash leaves Untitled file around
    translation(br): Update Brazilian translation
    translation(pt): Update menu_pt_br
    * v9.1.0694: matchparen is slow on a long line
    * v9.1.0693: Configure doesn't show result when not using python3
    stable abi
    * v9.1.0692: Wrong patlen value in ex_substitute()
    * v9.1.0691: stable-abi may cause segfault on Python 3.11
    runtime(vim): Update base-syntax, match :loadkeymap after colon and bar
    runtime(mane): Improve <Plug>ManBS mapping
    * v9.1.0690: cannot set special highlight kind in popupmenu
    translation(pt): Revert and fix wrong Portuguese menu translation
    files
    translation(pt): revert Portuguese menu translation
    translation(br): Update Brazilian translations
    runtime(vim): Update base-syntax, improve :let-heredoc highlighting
    * v9.1.0689: buffer-overflow in do_search( with 'rightleft'
    runtime(vim): Improve heredoc handling for all embedded scripts
    * v9.1.0688: dereferences NULL pointer in check_type_is_value()
    * v9.1.0687: Makefile may not install desktop files
    runtime(man): Fix <Plug>ManBS
    runtime(java): Make the bundled &foldtext function optional
    runtime(netrw): Change line on `mx` if command output exists
    runtime(netrw): Fix `mf`-selected entry highlighting
    runtime(htmlangular): add html syntax highlighting
    translation(it): Fix filemode of Italian manpages
    runtime(doc): Update outdated man.vim plugin information
    runtime(zip): simplify condition to detect MS-Windows
    * v9.1.0686: zip-plugin has problems with special characters
    runtime(pandoc): escape quotes in &errorformat for pandoc
    translation(it): updated Italian manpage
    * v9.1.0685: too many strlen( calls in usercmd.c
    runtime(doc): fix grammar in :h :keeppatterns
    runtime(pandoc): refine pandoc compiler settings
    * v9.1.0684: completion is inserted on Enter with "noselect"
    translation(ru): update man pages
    * v9.1.0683: mode( returns wrong value with <Cmd> mapping
    runtime(doc): remove trailing whitespace in cmdline.txt
    * v9.1.0682: Segfault with uninitialized funcref
    * v9.1.0681: Analyzing failed screendumps is hard
    runtime(doc): more clarification for the :keeppatterns needed
    * v9.1.0680: VMS does not have defined uintptr_t
    runtime(doc): improve typedchar documentation for KeyInputPre autocmd
    runtime(dist): verify that executable is in $PATH
    translation(it): update Italian manpages
    runtime(doc): clarify the effect of :keeppatterns after * v9.1.0677
    runtime(doc): update Makefile and make it portable between GNU and BSD
    * v9.1.0679: Rename from w_closing to w_locked is incomplete
    runtime(colors): update colorschemes
    runtime(vim): Update base-syntax, improve :let-heredoc highlighting
    runtime(doc): Updating the examples in the xxd manpage
    translation(ru): Updated uganda.rux
    runtime(yaml): do not re-indent when commenting out lines
    * v9.1.0678: use-after-free in alist_add()
    * v9.1.0677 :keepp does not retain the substitute pattern
    translation(ja): Update Japanese translations to latest release
    runtime(netrw): Drop committed trace lines
    runtime(netrw): Error popup not always used
    runtime(netrw): ErrorMsg( may throw E121
    runtime(tutor): update Makefile and make it portable between GNU and BSD
    translation: improve the po/cleanup.vim script
    runtime(lang): update Makefile and make it portable between GNU and BSD
    * v9.1.0676: style issues with man pages
    * v9.1.0675: Patch v9.1.0674 causes problems
    runtime(dosbatch): Show %%i as an argument in syntax file
    runtime(dosbatch): Add syn-sync to syntax file
    runtime(sql, mysql): fix E169: Command too recursive with
    sql_type_default = "mysql"
    * v9.1.0674: compiling abstract method fails because of missing return
    runtime(javascript): fix a few issues with syntax higlighting
    runtime(mediawiki): fix typo in doc, test for b:did_ftplugin var
    runtime(termdebug): Fix wrong test for balloon feature
    runtime(doc): Remove mentioning of the voting feature
    runtime(doc): add help tags for json + markdown global variables
    * v9.1.0673: too recursive func calls when calling super-class method
    runtime(syntax-tests): Facilitate the viewing of rendered screendumps
    runtime(doc): fix a few style issues
    * v9.1.0672: marker folds may get corrupted on undo
    * v9.1.0671 Problem:  crash with WinNewPre autocommand
    * v9.1.0670: po file encoding fails on *BSD during make
    translation(it): Update Italian translation
    translation: Stop using msgconv
    * v9.1.0669: stable python ABI not used by default
    Update .gitignore and .hgignore files
    * v9.1.0668: build-error with python3.12 and stable ABI
    translations: Update generated po files
    * v9.1.0667: Some other options reset curswant unnecessarily when set
    * v9.1.0666: assert_equal( doesn't show multibyte string correctly
    runtime(doc): clarify directory of Vim's executable vs CWD
    * v9.1.0665 :for loop
    runtime(proto): Add indent script for protobuf filetype
    * v9.1.0664: console vim did not switch back to main screen on exit
    runtime(zip): zip plugin does not work with Vim 9.0
    * v9.1.0663: zip test still resets 'shellslash' option
    runtime(zip): use defer to restore old settings
    runtime(zip): add a generic Message function
    runtime(zip): increment base version of zip plugin
    runtime(zip): raise minimum Vim version to * v9.0
    runtime(zip): refactor save and restore of options
    runtime(zip): remove test for fnameescape
    runtime(zip): use :echomsg instead of :echo
    runtime(zip): clean up and remove comments
    * v9.1.0662: filecopy( may return wrong value when readlink( fails
    * v9.1.0661: the zip plugin is not tested.
    runtime(zip): Fix for FreeBSD's unzip command
    runtime(doc): capitalize correctly
    * v9.1.0660: Shift-Insert does work on old conhost
    translation(it): update Italian manpage
    runtime(lua): add/subtract a 'shiftwidth' after '('/')' in indentexpr
    runtime(zip): escape '[' on Unix as well
    * v9.1.0659: MSVC Makefile is a bit hard to read
    runtime(doc): fix typo in syntax.txt
    runtime(doc): -x is only available when compiled with crypt feature
    * v9.1.0658: Coverity warns about dereferencing NULL pointer.
    runtime(colors): update Todo highlight in habamax colorscheme
    * v9.1.0657: MSVC build time can be optimized
    * v9.1.0656: MSVC Makefile CPU handling can be improved
    * v9.1.0655: goaccess config file not recognized
    CI: update clang compiler to version 20
    runtime(netrw): honor `g:netrw_alt{o,v}` for `:{S,H,V}explore`
    * v9.1.0654: completion does not respect completeslash with fuzzy
    * v9.1.0653: Patch v9.1.0648 not completely right
    * v9.1.0652: too many strlen( calls in syntax.c
    * v9.1.0651 :append
    * v9.1.0650: Coverity warning in cstrncmp()
    * v9.1.0649: Wrong comment for "len" argument of call_simple_func()
    * v9.1.0648: [security] double-free in dialog_changed()
    * v9.1.0647: [security] use-after-free in tagstack_clear_entry
    runtime(doc): re-format tag example lines, mention ctags --list-kinds
    * v9.1.0646: imported function may not be found
    runtime(java): Document "g:java_space_errors" and "g:java_comment_strings"
    runtime(java): Cluster optional group definitions and their group links
    runtime(java): Tidy up the syntax file
    runtime(java): Tidy up the documentation for "ft-java-syntax"
    runtime(colors): update habamax scheme - tweak diff/search/todo colors
    runtime(nohlsearch): add missing loaded_hlsearch guard
    runtime(kivy): Updated maintainer info for syntax script
    Maintainers: Add maintainer for ondir ftplugin + syntax files
    runtime(netrw): removing trailing slash when copying files in same
    directory
    * v9.1.0645: wrong match when searching multi-byte char case-insensitive
    runtime(html): update syntax script to sync by 250 minlines by default
    * v9.1.0644: Unnecessary STRLEN( when applying mapping
    runtime(zip): Opening a remote zipfile don't work
    runtime(cuda): source c and cpp ftplugins
    * v9.1.0643: cursor may end up on invalid position
    * v9.1.0642: Check that mapping rhs starts with lhs fails if not
    simplified
    * v9.1.0641: OLE enabled in console version
    runtime(thrift): add ftplugin, indent and syntax scripts
    * v9.1.0640: Makefile can be improved
    * v9.1.0639: channel timeout may wrap around
    * v9.1.0638: E1510 may happen when formatting a message for smsg()
    * v9.1.0637: Style issues in MSVC Makefile
  - Update apparmor.vim to latest version (from AppArmor 4.0.2)
  - add support for "all" and "userns" rules, and new profile flags
  - Update to 9.1.0636:
    * 9.1.0636: filetype: ziggy files are not recognized
    * 9.1.0635: filetype: SuperHTML template files not recognized
    * 9.1.0634: Ctrl-P not working by default
    * 9.1.0633: Compilation warnings with `-Wunused-parameter`
    * 9.1.0632: MS-Windows: Compiler Warnings
    Add support for Files-Included in syntax script
    tweak documentation style a bit
    * 9.1.0631: wrong completion list displayed with non-existing dir + fuzzy completion
    * 9.1.0630: MS-Windows: build fails with VIMDLL and mzscheme
    * 9.1.0629: Rename of pum hl_group is incomplete
    * 9.1.0628: MinGW: coverage files are not cleaned up
    * 9.1.0627: MinGW: build-error when COVERAGE is enabled
    * 9.1.0626: Vim9: need more tests with null objects
    include initial filetype plugin
    * 9.1.0625: tests: test output all translated messages for all translations
    * 9.1.0624: ex command modifiers not found
    * 9.1.0623: Mingw: errors when trying to delete non-existing files
    * 9.1.0622: MS-Windows: mingw-build can be optimized
    * 9.1.0621: MS-Windows: startup code can be improved
    * 9.1.0620: Vim9: segfauls with null objects
    * 9.1.0619: tests: test_popup fails
    * 9.1.0618: cannot mark deprecated attributes in completion menu
    * 9.1.0617: Cursor moves beyond first line of folded end of buffer
    * 9.1.0616: filetype: Make syntax highlighting off for MS Makefiles
    * 9.1.0615: Unnecessary STRLEN() in make_percent_swname()
    Add single-line comment syntax
    Add syntax test for comments
    Update maintainer info
    * 9.1.0614: tests: screendump tests fail due to recent syntax changes
    * 9.1.0613: tests: termdebug test may fail and leave file around
    Update base-syntax, improve :set highlighting
    Optionally highlight the :: token for method references
    * 9.1.0612: filetype: deno.lock file not recognized
    Use delete() for deleting directory
    escape filename before trying to delete it
    * 9.1.0611: ambiguous mappings not correctly resolved with modifyOtherKeys
    correctly extract file from zip browser
    * 9.1.0610: filetype: OpenGL Shading Language files are not detected
    Fix endless recursion in netrw#Explore()
    * 9.1.0609: outdated comments in Makefile
    update syntax script
    Fix flow mapping key detection
    Remove orphaned YAML syntax dump files
    * 9.1.0608: Coverity warns about a few potential issues
    Update syntax script and remove syn sync
    * 9.1.0607: termdebug: uses inconsistent style
    * 9.1.0606: tests: generated files may cause failure in test_codestyle
    * 9.1.0605: internal error with fuzzy completion
    * 9.1.0604: popup_filter during Press Enter prompt seems to hang
    translation: Update Serbian messages translation
    * 9.1.0603: filetype: use correct extension for Dracula
    * 9.1.0602: filetype: Prolog detection can be improved
    fix more inconsistencies in assert function docs
    * 9.1.0601: Wrong cursor position with 'breakindent' when wide char doesn't fit
    Update base-syntax, improve :map highlighting
    * 9.1.0600: Unused function and unused error constants
    * 9.1.0599: Termdebug: still get E1023 when specifying arguments
    correct wrong comment options
    fix typo "a xterm" -> "an xterm"
    * 9.1.0598: fuzzy completion does not work with default completion
    * 9.1.0597: KeyInputPre cannot get the (unmapped typed) key
    * 9.1.0596: filetype: devscripts config files are not recognized
    gdb file/folder check is now performed only in CWD.
    quote filename arguments using double quotes
    update syntax to SDC-standard 2.1
    minor updates.
    Cleanup :match and :loadkeymap syntax test files
    Update base-syntax, match types in Vim9 variable declarations
    * 9.1.0595: make errors out with the po Makefile
    * 9.1.0594: Unnecessary redraw when setting 'winfixbuf'
    using wrong highlight for UTF-8
    include simple syntax plugin
    * 9.1.0593: filetype: Asymptote files are not recognized
    add recommended indent options to ftplugin
    add recommended indent options to ftplugin
    add recommended indent options to ftplugin
    * 9.1.0592: filetype: Mediawiki files are not recognized
    * 9.1.0591: filetype: *.wl files are not recognized
    * 9.1.0590: Vim9: crash when accessing getregionpos() return value
    'cpoptions': Include "z" in the documented default
    * 9.1.0589: vi: d{motion} and cw work differently than expected
    update included colorschemes
    grammar fixes in options.txt
  - Add "Keywords" to gvim.desktop to make searching for gvim easier
  - Removed patches, as they're no longer required (refreshing them
    deleted their contents):
    * vim-7.3-help_tags.patch
    * vim-7.4-highlight_fstab.patch
  - Reorganise all applied patches in the spec file.
  - Update to 9.1.0588:
    * 9.1.0588: The maze program no longer compiles on newer clang
    runtime(typst): Add typst runtime files
    * 9.1.0587: tests: Test_gui_lowlevel_keyevent is still flaky
    * 9.1.0586: ocaml runtime files are outdated
    runtime(termdebug): fix a few issues
    * 9.1.0585: tests: test_cpoptions leaves swapfiles around
    * 9.1.0584: Warning about redeclaring f_id() non-static
    runtime(doc): Add hint how to load termdebug from vimrc
    runtime(doc): document global insert behavior
    * 9.1.0583: filetype: *.pdf_tex files are not recognized
    * 9.1.0582: Printed line doesn't overwrite colon when pressing Enter in Ex mode
    * 9.1.0581: Various lines are indented inconsistently
    * 9.1.0580: :lmap mapping for keypad key not applied when typed in Select mode
    * 9.1.0579: Ex command is still executed after giving E1247
    * 9.1.0578: no tests for :Tohtml
    * 9.1.0577: Unnecessary checks for v:sizeoflong in test_put.vim
    * 9.1.0576: tests: still an issue with test_gettext_make
    * 9.1.0575: Wrong comments in alt_tabpage()
    * 9.1.0574: ex: wrong handling of commands after bar
    runtime(doc): add a note for netrw bug reports
    * 9.1.0573: ex: no implicit print for single addresses
    runtime(vim): make &indentexpr available from the outside
    * 9.1.0572: cannot specify tab page closing behaviour
    runtime(doc): remove obsolete Ex insert behavior
    * 9.1.0571: tests: Test_gui_lowlevel_keyevent is flaky
    runtime(logindefs): update syntax with new keywords
    * 9.1.0570: tests: test_gettext_make can be improved
    runtime(filetype): Fix Prolog file detection regex
    * 9.1.0569: fnamemodify() treats ".." and "../" differently
    runtime(mojo): include mojo ftplugin and indent script
    * 9.1.0568: Cannot expand paths from 'cdpath' setting
    * 9.1.0567: Cannot use relative paths as findfile() stop directories
    * 9.1.0566: Stop dir in findfile() doesn't work properly w/o trailing slash
    * 9.1.0565: Stop directory doesn't work properly in 'tags'
    * 9.1.0564: id() can be faster
    * 9.1.0563: Cannot process any Key event
    * 9.1.0562: tests: inconsistency in test_findfile.vim
    runtime(fstab): Add missing keywords to fstab syntax
    * 9.1.0561: netbeans: variable used un-initialized (Coverity)
    * 9.1.0560: bindtextdomain() does not indicate an error
    * 9.1.0559: translation of vim scripts can be improved
    * 9.1.0558: filetype: prolog detection can be improved
    * 9.1.0557: moving in the buffer list doesn't work as documented
    runtime(doc): fix inconsistencies in :h file-searching
    * 9.1.0556: :bwipe doesn't remove file from jumplist of other tabpages
    runtime(htmlangular): correct comment
    * 9.1.0555: filetype: angular ft detection is still problematic
    * 9.1.0554: :bw leaves jumplist and tagstack data around
    * 9.1.0553: filetype: *.mcmeta files are not recognized
    * 9.1.0552: No test for antlr4 filetype
    * 9.1.0551: filetype: htmlangular files are not properly detected
    * 9.1.0550: filetype: antlr4 files are not recognized
    * 9.1.0549: fuzzycollect regex based completion not working as expected
    runtime(doc): autocmd_add() accepts a list not a dict
    * 9.1.0548: it's not possible to get a unique id for some vars
    runtime(tmux): Update syntax script
    * 9.1.0547: No way to get the arity of a Vim function
    * 9.1.0546: vim-tiny fails on CTRL-X/CTRL-A
    runtime(hlsplaylist): include hlsplaylist ftplugin file
    runtime(doc): fix typo in :h ft-csv-syntax
    runtime(doc): Correct shell command to get $VIMRUNTIME into
    shell
    * 9.1.0545: MSVC conversion warning
    * 9.1.0544: filetype: ldapconf files are not recognized
    runtime(cmakecache): include cmakecache ftplugin file
    runtime(lex): include lex ftplugin file
    runtime(yacc): include yacc ftplugin file
    runtime(squirrel): include squirrel ftplugin file
    runtime(objcpp): include objcpp ftplugin file
    runtime(tf): include tf ftplugin file
    runtime(mysql): include mysql ftplugin file
    runtime(javacc): include javacc ftplugin file
    runtime(cabal): include cabal ftplugin file
    runtime(cuda): include CUDA ftplugin file
    runtime(editorconfig): include editorconfig ftplugin file
    runtime(kivy): update kivy syntax, include ftplugin
    runtime(syntax-tests): Stop generating redundant "*_* 99.dump"
    files
    * 9.1.0543: Behavior of CursorMovedC is strange
    runtime(vim): Update base-syntax, improve :match command
    highlighting
    * 9.1.0542: Vim9: confusing string() output for object functions
    * 9.1.0541: failing test with Vim configured without channel
    * 9.1.0540: Unused assignment in sign_define_cmd()
    runtime(doc): add page-scrolling keys to index.txt
    runtime(doc): add reference to xterm-focus-event from
    FocusGained/Lost
    * 9.1.0539: Not enough tests for what v9.1.0535 fixed
    runtime(doc): clarify how to re-init csv syntax file
    * 9.1.0538: not possible to assign priority when defining a sign
    * 9.1.0537: signed number detection for CTRL-X/A can be improved
    * 9.1.0536: filetype: zone files are not recognized
    * 9.1.0535: newline escape wrong in ex mode
    runtime(man): honor cmd modifiers before `g:ft_man_open_mode`
    runtime(man): use `nnoremap` to map to Ex commands
    * 9.1.0534: completion wrong with fuzzy when cycling back to original
    runtime(syntax-tests): Abort and report failed cursor progress
    runtime(syntax-tests): Introduce self tests for screen dumping
    runtime(syntax-tests): Clear and redraw the ruler line with
    the shell info
    runtime(syntax-tests): Allow for folded and wrapped lines in
    syntax test files
    * 9.1.0533: Vim9: need more tests for nested objects equality
    CI: Pre-v* 9.0.0110 versions generate bogus documentation tag entries
    runtime(doc): Remove wrong help tag CTRL-SHIFT-CR
    * 9.1.0532: filetype: Cedar files not recognized
    runtime(doc): document further keys that scroll page up/down
    * 9.1.0531: resource leak in mch_get_random()
    runtime(tutor): Fix wrong spanish translation
    runtime(netrw): fix remaining case of register clobber
    * 9.1.0530: xxd: MSVC warning about non-ASCII character
    * 9.1.0529: silent! causes following try/catch to not work
    runtime(rust): use shiftwidth() in indent script
    * 9.1.0528: spell completion message still wrong in translations
    * 9.1.0527: inconsistent parameter in Makefiles for Vim executable
    * 9.1.0526: Unwanted cursor movement with pagescroll at start of buffer
    runtime(doc): mention $XDG_CONFIG_HOME instead of $HOME/.config
    * 9.1.0525: Right release selects immediately when pum is truncated.
    * 9.1.0524: the recursive parameter in the *_equal functions can be removed
    runtime(termdebug): Add Deprecation warnings
    * 9.1.0523: Vim9: cannot downcast an object
    * 9.1.0522: Vim9: string(object) hangs for recursive references
    * 9.1.0521: if_py: _PyObject_CallFunction_SizeT is dropped in Python 3.13
    * 9.1.0520: Vim9: incorrect type checking for modifying lists
    runtime(manpager): avoid readonly prompt
    * 9.1.0519: MS-Windows: libvterm compilation can be optimized
    * 9.1.0518: initialize the random buffer can be improved
    * 9.1.0517: MS-Windows: too long lines in Make_mvc.mak
    runtime(terraform): Add filetype plugin for terraform
    runtime(dockerfile): enable spellchecking of comments in
    syntax script
    runtime(doc): rename variable for pandoc markdown support
    runtime(doc): In builtin overview use {buf} as param for
    appendbufline/setbufline
    runtime(doc): clarify, that register 1-* 9 will always be shifted
    runtime(netrw): save and restore register 0-* 9, a and unnamed
    runtime(termdebug): Refactored StartDebug_term and EndDebug
    functions
    runtime(java): Compose "g:java_highlight_signature" and
    "g:java_highlight_functions"
    * 9.1.0516: need more tests for nested dicts and list comparision
    * 9.1.0515: Vim9: segfault in object_equal()
    * 9.1.0514: Vim9: issue with comparing objects recursively
    runtime(termdebug): Change some variables to Enums
    runtime(vim): Update base-syntax, fix function tail comments
    * 9.1.0513: Vim9: segfault with object comparison
  - Update to 9.1.0512:
    * Mode message for spell completion doesn't match allowed keys
    * CursorMovedC triggered wrongly with setcmdpos()
    * update runtime files
    * CI: test_gettext fails on MacOS14 + MSVC Win
    * not possible to translate Vim script messages
    * termdebug plugin can be further improved
    * add gomod filetype plugin
    * hard to detect cursor movement in the command line
    * Optionally highlight parameterised types
    * filetype: .envrc & .prettierignore not recognized
    * filetype: Faust files are not recognized
    * inner-tag textobject confused about ">" in attributes
    * cannot use fuzzy keyword completion
    * Remove the group exclusion list from @javaTop
    * wrong return type for execute() function
    * MS-Windows: too much legacy code
    * too complicated mapping restore in termdebug
    * simplify mapping
    * cannot switch buffer in a popup
    * MS-Windows: doesn't handle symlinks properly
    * getcmdcompltype() interferes with cmdline completion
    * termdebug can be further improved
    * update htmldjango detection
    * Improve Turkish documentation
    * include a simple csv filetype and syntax plugin
    * include the the simple nohlsearch package
    * matched text is highlighted case-sensitively
    * Matched text isn't highlighted in cmdline pum
    * Fix typos in several documents
    * clarify when text properties are cleared
    * improve the vim-shebang example
    * revert unintended formatting changes for termdebug
    * Add a config variable for commonly used compiler options
    * Wrong matched text highlighted in pum with 'rightleft'
    * bump length of character references in syntax script
    * properly check mapping variables using null_dict
    * fix KdlIndent and kdlComment in indent script
    * Test for patch 9.1.0489 doesn't fail without the fix
    * Fold multi-line comments with the syntax kind of &fdm
    * using wrong type for PlaceSign()
    * filetype: Vim-script files not detected by shebang line
    * revert unintended change to zip#Write()
    * add another tag for vim-shebang feature
    * Cmdline pum doesn't work properly with 'rightleft'
    * minor style problems with patch 9.1.0487
    * default completion may break with fuzzy
    * Wrong padding for pum "kind" with 'rightleft'
    * Update base-syntax, match shebang lines
    * MS-Windows: handle files with spaces properly
    * Restore HTML syntax file tests
    * completed item not update on fuzzy completion
    * filetype: Snakemake files are not recognized
    * make TermDebugSendCommand() a global function again
    * close all buffers in the same way
    * Matched text shouldn't be highlighted in "kind" and "menu"
    * fix wrong helptag for :defer
    * Update base-syntax, match :sleep arg
    * include Georgian keymap
    * Sorting of completeopt+=fuzzy is not stable
    * correctly test for windows in NetrwGlob()
    * glob() on windows fails with [] in directory name
    * rewrite mkdir() doc and simplify {flags} meaning
    * glob() not sufficiently tested
    * update return type for job_info()
    * termdebug plugin needs more love
    * correct return types for job_start() and job_status()
    * Update base-syntax, match :catch and :throw args
    * Include element values in non-marker annotations
    * Vim9: term_getjob() throws an exception on error
    * fuzzy string matching executed when not needed
    * fuzzy_match_str_with_pos() does unnecessary list operations
    * restore description of "$" in col() and virtcol()
    * deduplicate getpos(), line(), col(), virtcol()
    * Update g:vimsyn_comment_strings dump file tests
    * Use string interpolation instead of string concat
    * potential deref of NULL pointer in fuzzy_match_str_with_pos
    * block_editing errors out when using <enter>
    * Update base-syntax, configurable comment string highlighting
    * fix typos in syntax.txt
    * Cannot see matched text in popup menu
    * Update base-syntax, match multiline continued comments
    * clarify documentation for "v" position at line()
    * cmod_split modifier is always reset in term_start()
    * remove line-continuation characters
    * use shiftwidth() instead of &tabstop in indent script
    * Remove orphaned screen dump files
    * include syntax, indent and ftplugin files
    * CI: Test_ColonEight() fails on github runners
    * add missing Enabled field in syntax script
    * basic svelte ftplugin file
    * term_start() does not clear vertical modifier
    * fix mousemodel restoration by comparing against null_string
    * Added definitions of Vim scripts and plugins
    * Exclude lambda expressions from _when_ _switch-case_ label clauses
    * Fix saved_mousemodel check
    * Inconsistencies between functions for option flags
    * Crash when using autocmd_get() after removing event inside autocmd
    * Fix small style issues
    * add return type info for Vim function descriptions
    * Update Italian Vim manpage
    * disable the q mapping
    * Change 'cms' for C++ to '// %s'
    * fix type mismatch error
    * Fix wrong email address
    * convert termdebug plugin to Vim9 script
  - Update to 9.1.0470:
    * tests Test_ColonEight_MultiByte() fails sporadically
    * Cannot have buffer-local value for 'completeopt'
    * GvimExt does not consult HKEY_CURRENT_USER
    * typos in some comments
    * runtime(vim): Update base-syntax, allow whitespace before
    :substitute pattern
    * Missing comments for fuzzy completion
    * runtime(man): update Vim manpage
    * runtime(comment): clarify the usage of 'commentstring' option
    value
    * runtime(doc): clarify how fuzzy 'completeopt' should work
    * runtime(netrw): prevent accidental data loss
    * missing filecopy() function
    * no whitespace padding in commentstring option in ftplugins
    * no fuzzy-matching support for insert-completion
    * eval5() and eval7 are too complex
    * too many strlen() calls in drawline.c
    * filetype lintstagedrc files are not recognized
    * Vim9 import autoload does not work with symlink
    * Coverity complains about division by zero
    * tests test_gui fails on Wayland
    * Left shift is incorrect with vartabstop and shiftwidth=0
    * runtime(doc): clarify 'shortmess' flag "S"
    * MS-Windows compiler warning for size_t to int conversion
    * runtime(doc): include some vim9 script examples in the help
    * minor issues in test_filetype with rasi test
    * filetype rasi files are not recognized
    * runtime(java): Improve the matching of lambda expressions
    * Configure checks for libelf unnecessarily
    * No test for escaping '<' with shellescape()
    * check.vim complains about overlong comment lines
    * translation(it): Update Italian translation
    * evalc. code too complex
    * MS-Windows Compiler warnings
  - Update to 9.1.0448:
    * compiler warning in eval.c
    * remove remaining css code
    * Add ft_hare.txt to Reference Manual TOC
    * re-generate vim syntax from generator
    * fix syntax vim bug
    * completion may be wrong when deleting all chars
    * getregionpos() inconsistent for partly-selected multibyte char
    * fix highlighting nested and escaped quotes in string props
    * remove the indent plugin since it has too many issues
    * update Debian runtime files
    * Coverity warning after 9.1.0440
    * Not enough tests for getregion() with multibyte chars
    * Can't use blockwise selection with width for getregion()
    * update outdated syntax files
    * fix floating_modifier highlight
    * hare runtime files outdated
    * getregionpos() can't properly indicate positions beyond eol
    * function get_lval() is too long
    * Cannot filter the history
    * Wrong Ex command executed when :g uses '?' as delimiter
    * support floating_modifier none; revert broken highlighting
    * Motif requires non-const char pointer for XPM  data
    * Crash when using '?' as separator for :s
    * filetype: cygport files are not recognized
    * make errors trying to access autoload/zig
    * Wrong yanking with exclusive selection and ve=all
    * add missing help tags file
    * Ancient XPM preprocessor hack may cause build errors
    * include basic rescript ftplugin file
    * eval.c is too long
    * getregionpos() doesn't handle one char selection
    * check for gdb file/dir before using as buffer name
    * refactor zig ftplugin, remove auto format
    * Coverity complains about eval.c refactor
    * Tag guessing leaves wrong search history with very short names
    * some issues with termdebug mapping test
    * update matchit plugin to v1.20
    * too many strlen() calls in search.c
    * set commentstring option
    * update vb indent plugin as vim9script
    * filetype: purescript files are not recognized
    * filetype: slint files are not recognized
    * basic nim ftplugin file for comments
    * Add Arduino ftplugin and indent files
    * include basic typst ftplugin file
    * include basic prisma ftplugin file
    * include basic v ftplugin for comment support
    * getregionpos() wrong with blockwise mode and multibyte
    * function echo_string_core() is too long
    * hyprlang files are not recognized
    * add basic dart ftplugin file
    * basic ftplugin file for graphql
    * mention comment plugin at :h 'commentstring'
    * set commentstring for sql files in ftplugin
    * :browse oldfiles prompts even with single entry
    * eval.c not sufficiently tested
    * clarify why E195 is returned
    * clarify temporary file clean up
    * fix :NoMatchParen not working
    * Cannot move to previous/next rare word
    * add basic ftplugin file for sshdconfig
    * if_py: find_module has been removed in Python 3.12.0a7
    * some screen dump tests can be improved
    * Some functions are not tested
    * clarify instal instructions for comment package
    * Unable to leave long line with 'smoothscroll' and 'scrolloff'
    * fix typo in vim9script help file
    * Remove trailing spaces
    * clarify {special} argument for shellescape()
  - update to 9.1.0413
    * smoothscroll may cause infinite loop
    * add missing entries for the keys CTRL-W g<Tab> and <C-Tab>
    * update vi_diff.txt: add default value for 'flash'
    * typo in regexp_bt.c in DEBUG code
    * allow indented commands
    * Fix wrong define regex in ftplugin
    * Filter out non-Latin-1 characters for syntax tests
    * prefer scp over pscp
    * fix typo in usr_52.txt
    * too long functions in eval.c
    * warning about uninitialized variable
    * too many strlen() calls in the regexp engine
    * E16 fix, async keyword support for define
    * Stuck with long line and half-page scrolling
    * Divide by zero with getmousepos() and 'smoothscroll'
    * update and remove  some invalid links
    * update translation of xxd manpage
    * Recursively delete directories by default with netrw delete command
    * Strive to remain compatible for at least Vim 7.0
    * tests: xxd buffer overflow fails on 32-bit
    * Stop handpicking syntax groups for @javaTop
    * [security] xxd: buffer-overflow with specific flags
    * Vim9: not able to import file from start dir
    * filetype: mdd files detected as zsh filetype
    * filetype: zsh module files are not recognized
    * Remove hardcoded private.ppk logic from netrw
    * Vim9: confusing error message for unknown type
    * block_editing errors out when using del
    * add new items to scripts section in syntax plugin
    * Vim9: imported vars are not properly type checked
    * Wrong display with 'smoothscroll' when changing quickfix list
    * filetype: jj files are not recognized
    * getregionpos() may leak memory on error
    * The CODEOWNERS File is not useful
    * Remove and cleanup Win9x legacy from netrw
    * add MsgArea to 'highlight' option description
    * Cannot get a list of positions describing a region
    * Fix digit separator in syntax script for octals and floats
    * Update link to Wikipedia Vi page
    * clear $MANPAGER in ftplugin before shelling out
    * Fix typos in help documents
    * 'viewdir' not respecting $XDG_CONFIG_HOME
    * tests: Vim9 debug tests may be flaky
    * correct getscriptinfo() example
    * Vim9: could improve testing
    * test_sound fails on macos-12
    * update Serbian menu
    * update Slovak menu
    * update Slovenian menu
    * update Portuguese menu
    * update Dutch menu
    * update Korean menu
    * update Icelandic menu
    * update Czech menu
    * update Afrikaans menu
    * update German menu
    * filetype: inko files are not recognized
    * filetype: templ files are not recognized
    * cursor() and getregion() don't handle v:maxcol well
    * Vim9: null value tests not sufficient
    * update Catalan menu
    * filetype: stylus files not recognized
    * update spanish menu localization
    * regenerate helptags
    * Vim9: crash with null_class and null_object
    * Add tags about lazyloading of menu
    * tests: vt420 terminfo entry may not be found
    * filetype: .out files recognized as tex files
    * filetype: Kbuild files are not recognized
    * cbuffer and similar commands don't accept a range
    * Improve the recognition of the "indent" method declarations
    * Fix a typo in usr_30.txt
    * remove undefined var s:save_cpoptions and add include setting
    * missing setlocal in indent plugin
    * Calculating line height for unnecessary amount of lines
    * improve syntax file performance
    * There are a few typos
    * Vim9: no comments allowed after class vars
    * CI: remove trailing white space in documentation
    * Formatting text wrong when 'breakindent' is set
    * Add oracular (24.10) as Ubuntu release name
    * Vim9: Trailing commands after class/enum keywords ignored
    * tests: 1-second delay after Test_BufEnter_botline()
    * update helptags for jq syntax
    * include syntax, ftplugin and compiler plugin
    * fix typo synconcealend -> synconcealed
    * include a simple comment toggling plugin
    * wrong botline in BufEnter
    * clarify syntax vs matching mechanism
    * fix undefined variable in indent plugin
    * ops.c code uses too many strlen() calls
    * Calling CLEAR_FIELD() on the same struct twice
    * Vim9: compile_def_function() still too long
    * Update Serbian messages
    * clarify the effect of setting the shell to powershell
    * Improve the recognition of the "style" method declarations
    * Vim9: problem when importing autoloaded scripts
    * compile_def_function is too long
    * filetype: ondir files are not recognized
    * Crash when typing many keys with D- modifier
    * tests: test_vim9_builtin is a bit slow
    * update documentation
    * change the download URL of "libsodium"
    * tests: test_winfixbuf is a bit slow
    * Add filetype, syntax and indent plugin for Astro
    * expanding rc config files does not work well
    * Vim9: vim9type.c is too complicated
    * Vim9: does not handle autoloaded variables well
    * minor spell fix in starting.txt
    * wrong drawing in GUI with setcellwidth()
    * Add include and suffixesadd
    * Page scrolling should place cursor at window boundaries
    * align command line table
    * minor fixes to starting.txt
    * fix comment definition in filetype plugin
    * filetype: flake.lock files are not recognized
    * runtime(uci): No support for uci file types
    * Support "g:ftplugin_java_source_path" with archived files
    * tests: Test_autoload_import_relative_compiled fails on Windows
    * Finding cmd modifiers and cmdline-specials is inefficient
    * No test that completing a partial mapping clears 'showcmd'
    * tests: test_vim9_dissamble may fail
    * Vim9: need static type for typealias
    * X11 does not ignore smooth scroll event
    * A few typos in test_xdg when testing gvimrc
    * Patch v9.1.0338 fixed sourcing a script with import
    * Problem: gvimrc not sourced from XDG_CONFIG_HOME
    * Cursor wrong after using setcellwidth() in terminal
    * 'showcmd' wrong for partial mapping with multibyte
    * tests: test_taglist fails when 'helplang' contains non-english
    * Problem: a few memory leaks are found
    * Problem: Error with matchaddpos() and empty list
    * tests: xdg test uses screen dumps
    * Vim9: import through symlinks not correctly handled
    * Missing entry for XDG vimrc file in :version
    * tests: typo in test_xdg
    * runtime(i3config/swayconfig): update syntax scripts
    * document pandoc compiler and enable configuring arguments
    * String interpolation fails for List type
    * No test for highlight behavior with 'ambiwidth'
    * tests: test_xdg fails on the appimage repo
    * tests: some assert_equal() calls have wrong order of args
    * make install does not install all files
    * runtime(doc): fix typos in starting.txt

------------------------------------------------------------------
------------------  2024-11-27  -  Nov 27 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - trying to make buildservice happy by adding both tarballs to
    specfile ...

++++ Mesa-drivers:

  - trying to make buildservice happy by adding both tarballs to
    specfile ...

++++ docker:

  - Disable docker-buildx builds for SLES. It turns out that build containers
    with docker-buildx don't currently get the SUSE secrets mounts applied,
    meaning that container-suseconnect doesn't work when building images.
    bsc#1233819

++++ python-kiwi:

  - Added provide/require system files for containers
    Added the attributes provide_system_files and require_system_files
    to control the provider and requester of system files in
    container image builds. systemfiles is a metadata file which
    contains all files from the package database at call time.
    It is used in flake-pilot to provision the systemfiles data
    from the host into the container instance. One possible use
    case for this data is a flake registration which uses a
    base container that is derived from a runtime container but
    all data from the runtime should be provisioned from the
    host. Using this feature tightly couples the flake to the
    host OS distribution and version.
  - Bump version: 10.2.1 → 10.2.2
  - Fix scope issue
    Increase livetime of the the compressor instances
    to the livetime of RootImportOCI. They create temporary
    files which are referenced later and need to live longer
    than the block they got created in

++++ glib2:

  - Have the glib2-tools postun trigger exit normally if
    glib2-compile-schemas can't be run. Fixes error when uninstalling
    if libgio is uninstalled first (bsc#1231463).

++++ kernel-default:

  - Drop obsoleted patches and refresh/enable kabi padding patches
    Dropped:
    patches.suse/Input-elan_i2c-Add-deny-list-for-Lenovo-Yoga-Slim-7.patch
    patches.suse/Input-synaptics-retry-query-upon-error.patch
    patches.suse/drm-i915-lspcon-Separate-function-to-set-expected-mo.patch
    patches.suse/drm-i915-lspcon-Separate-lspcon-probe-and-lspcon-ini.patch
    patches.suse/drm-nouveau-blacklist-Turing-and-Ampere-models-as-default.patch
    patches.suse/firmware-qemu_fw_cfg-Do-not-hard-depend-on-CONFIG_HA.patch
    Refreshed:
    patches.suse/asoc-suse-kabi-padding.patch
    patches.suse/media-suse-kabi-padding.patch.
    patches.suse/soundwire-suse-kabi-padding.patch
    patches.suse/wireless-suse-kabi-padding.patch
  - commit 51775ca
  - Refresh: patches.suse/prepare-arm64-klp.
  - commit 477d95e
  - Refresh
    patches.suse/Revert-kallsyms-unexport-kallsyms_lookup_name-and-kallsyms_on_each_symbol.patch.
  - commit 6f8810b
  - Refresh
    patches.suse/Revert-Revert-kbuild-use-flive-patching-when-CONFIG_LIVEPATCH-is-enabled.patch.
  - commit 6ba47ba
  - Refresh
    patches.suse/livepatch-dump-ipa-clones.patch
    Update config files.
  - commit c9d0459
  - fadump: reserve param area if below boot_mem_top (jsc#PED-9891).
  - powerpc/fadump: allocate memory for additional parameters early
    (jsc#PED-9891).
  - commit 93c8306
  - Refresh
    patches.suse/livepatch-Add-sample-livepatch-module.patch.
  - commit cff40b1
  - Refresh patches.suse/kbuild-modpost-integrate-klp-convert.patch.
  - commit 5bfefc6
  - config: s390: Disable XE driver (jsc#PED-11187)
  - commit 9589455
  - config: x86_64: change HZ to upstream default
    References: jsc#PED-11606
  - commit 80f3e03
  - Refresh patches.suse/livepatch-Add-klp-convert-tool.patch.
  - commit e46c3e4
  - config: Update config for DRM graphics drivers (jsc#PED-11186)
    Also list additional modules as unsupported.
    Same as commit f8bed7719a0fa09b55bbc650f404bfd3a570f203, but with
    the correct reference to the Jira ticket.
  - config: Update config for DRM graphics drivers (jsc#11186)
    Also list additional modules as unsupported.
  - commit 26a7b09
  - Refresh
    patches.suse/livepatch-Create-and-include-UAPI-headers.patch.
  - commit 4e85f17
  - Refresh
    patches.suse/vsprintf-kallsyms-Prevent-invalid-data-when-printing.patch.
  - commit fd35952
  - Reenable patches.suse/tracing-Add-kabi-placeholders.patch.
    The added placeholders are useful for 6.12-based branches too.
  - commit 3f5f9a3
  - Delete
    patches.suse/kprobes-Fix-double-free-of-kretprobe_holder.patch.
    The patch is not needed for 6.12-based branches as they include upstream
    commit 4bbd93455659 ("kprobes: kretprobe scalability improvement") which
    reworked the affected area and also fixed the issue.
  - commit 988bf28
  - config: Disable obsolete fbdev drivers (jsc#PED-11183)
  - commit a294eeb
  - config: Fallout fom run_oldconfig.sh
  - commit 526ac06
  - Enable patches.suse/unsupported-features.patch: Support for tainting
    kernel when unsupported filesystem features are used.
  - commit 70a4d99
  - Delete patches.suse/readahead-request-tunables.patch: Now handled in
    udev rule
  - commit 6ef5420
  - Delete
    patches.suse/blk-wbt-Fix-detection-of-dirty-throttled-tasks.patch: Now
    upstream.
  - Delete
    patches.suse/nfs-Bump-default-write-congestion-size.patch: Upstream
    has a proper fix.
  - commit 5bb4f43
  - Enable patches.suse/ext4-unsupported-features.patch. There was no
    request to make these features (bigalloc) supported on ext4.
  - commit 636b72e

++++ kernel-rt:

  - Drop obsoleted patches and refresh/enable kabi padding patches
    Dropped:
    patches.suse/Input-elan_i2c-Add-deny-list-for-Lenovo-Yoga-Slim-7.patch
    patches.suse/Input-synaptics-retry-query-upon-error.patch
    patches.suse/drm-i915-lspcon-Separate-function-to-set-expected-mo.patch
    patches.suse/drm-i915-lspcon-Separate-lspcon-probe-and-lspcon-ini.patch
    patches.suse/drm-nouveau-blacklist-Turing-and-Ampere-models-as-default.patch
    patches.suse/firmware-qemu_fw_cfg-Do-not-hard-depend-on-CONFIG_HA.patch
    Refreshed:
    patches.suse/asoc-suse-kabi-padding.patch
    patches.suse/media-suse-kabi-padding.patch.
    patches.suse/soundwire-suse-kabi-padding.patch
    patches.suse/wireless-suse-kabi-padding.patch
  - commit 51775ca
  - Refresh: patches.suse/prepare-arm64-klp.
  - commit 477d95e
  - Refresh
    patches.suse/Revert-kallsyms-unexport-kallsyms_lookup_name-and-kallsyms_on_each_symbol.patch.
  - commit 6f8810b
  - Refresh
    patches.suse/Revert-Revert-kbuild-use-flive-patching-when-CONFIG_LIVEPATCH-is-enabled.patch.
  - commit 6ba47ba
  - Refresh
    patches.suse/livepatch-dump-ipa-clones.patch
    Update config files.
  - commit c9d0459
  - fadump: reserve param area if below boot_mem_top (jsc#PED-9891).
  - powerpc/fadump: allocate memory for additional parameters early
    (jsc#PED-9891).
  - commit 93c8306
  - Refresh
    patches.suse/livepatch-Add-sample-livepatch-module.patch.
  - commit cff40b1
  - Refresh patches.suse/kbuild-modpost-integrate-klp-convert.patch.
  - commit 5bfefc6
  - config: s390: Disable XE driver (jsc#PED-11187)
  - commit 9589455
  - config: x86_64: change HZ to upstream default
    References: jsc#PED-11606
  - commit 80f3e03
  - Refresh patches.suse/livepatch-Add-klp-convert-tool.patch.
  - commit e46c3e4
  - config: Update config for DRM graphics drivers (jsc#PED-11186)
    Also list additional modules as unsupported.
    Same as commit f8bed7719a0fa09b55bbc650f404bfd3a570f203, but with
    the correct reference to the Jira ticket.
  - config: Update config for DRM graphics drivers (jsc#11186)
    Also list additional modules as unsupported.
  - commit 26a7b09
  - Refresh
    patches.suse/livepatch-Create-and-include-UAPI-headers.patch.
  - commit 4e85f17
  - Refresh
    patches.suse/vsprintf-kallsyms-Prevent-invalid-data-when-printing.patch.
  - commit fd35952
  - Reenable patches.suse/tracing-Add-kabi-placeholders.patch.
    The added placeholders are useful for 6.12-based branches too.
  - commit 3f5f9a3
  - Delete
    patches.suse/kprobes-Fix-double-free-of-kretprobe_holder.patch.
    The patch is not needed for 6.12-based branches as they include upstream
    commit 4bbd93455659 ("kprobes: kretprobe scalability improvement") which
    reworked the affected area and also fixed the issue.
  - commit 988bf28
  - config: Disable obsolete fbdev drivers (jsc#PED-11183)
  - commit a294eeb
  - config: Fallout fom run_oldconfig.sh
  - commit 526ac06
  - Enable patches.suse/unsupported-features.patch: Support for tainting
    kernel when unsupported filesystem features are used.
  - commit 70a4d99
  - Delete patches.suse/readahead-request-tunables.patch: Now handled in
    udev rule
  - commit 6ef5420
  - Delete
    patches.suse/blk-wbt-Fix-detection-of-dirty-throttled-tasks.patch: Now
    upstream.
  - Delete
    patches.suse/nfs-Bump-default-write-congestion-size.patch: Upstream
    has a proper fix.
  - commit 5bb4f43
  - Enable patches.suse/ext4-unsupported-features.patch. There was no
    request to make these features (bigalloc) supported on ext4.
  - commit 636b72e

++++ pcp:

  - Replace dejavu-fonts with liberation-fonts.
  - Fix for bsc#1232695.

++++ sqlite3:

  - Update to release 3.47.1:
    * Fix the makefiles so that they once again honored DESTDIR for
    the "install" target.
    * Add the SQLITE_IOCAP_SUBPAGE_READ capability to the VFS, to
    work around issues on some non-standard VFSes caused by making
    SQLITE_DIRECT_OVERFLOW_READ the default in version 3.45.0.
    * Fix incorrect answers to certain obscure IN queries caused by
    new query optimizations added in the 3.47.0 release.
    * Other minor bug fixes.

++++ unbound:

  - add workaround for bug
    https://github.com/NLnetLabs/unbound/issues/509
    Starting up with 127.0.0.1 in the /etc/resolv.conf leads to long
    delays if the anchor update is being run as ExecStartPre in the
    unbound service

++++ netavark:

  - Fix source definition for netavark-iptables.conf and netavark-nftables.conf

++++ passt:

  - Update to version 20241127.c0fbc7e:
    * dhcp: Honour broadcast flag (RFC 2131, 4.1)
    * dhcp: Introduce support for Rapid Commit (option 80, RFC 4039)
    * dhcp: Use -1 as "missing option" length instead of 0
    * treewide: Introduce 'local mode' for disconnected setups
    * test: Improve logic for waiting for SLAAC & DAD to complete in NDP tests
    * ndp: Don't send first periodic router advertisement right after guest connects
    * test/perf: Select a single IPv6 namespace address in pasta tests
    * conf, passt.1: Update --mac-addr default in usage() and man page
    * passt.1: Fix "default" note about --map-guest-addr

------------------------------------------------------------------
------------------  2024-11-26  -  Nov 26 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - on s390x build Mesa 24.1.7 to fix colors with Xvnc (boo#1233167)
  - adjusted patches for Mesa 24.1.7:
    * python36-buildfix1-s390x.patch
    * u_dep_xcb-s390x.patch
    * u_mesa-CVE-2023-45913-s390x.patch

++++ Mesa-drivers:

  - on s390x build Mesa 24.1.7 to fix colors with Xvnc (boo#1233167)
  - adjusted patches for Mesa 24.1.7:
    * python36-buildfix1-s390x.patch
    * u_dep_xcb-s390x.patch
    * u_mesa-CVE-2023-45913-s390x.patch

++++ python-kiwi:

  - Bump version: 10.2.0 → 10.2.1

++++ haproxy:

  - Update to version 3.1.0+git0.f2b97918e:
    https://www.mail-archive.com/haproxy@formilux.org/msg45435.html
    https://www.haproxy.com/blog/announcing-haproxy-3-1

++++ kernel-default:

  - Re-enable fixup to the acpi_pad driver
  - commit 0dc7926
  - Re-enable prerequisite patch to set CONFIG_CPU_FREQ_DEFAULT_GOV_ONDEMAND=y
  - commit d5e1336
  - Re-enable defaulting to intel_pstate/powersave on non-HWP machines
  - commit b22515b
  - Re-enable idle-boost optimization for intel_pstate on non-HWP machines
  - commit 795714e
  - Re-enable intel_pstate optimization for low-utilization workloads on non-HWP machines
  - commit ce7c38f
  - Re-enable aggressive iowait boost for intel_pstate for non-HWP machines
  - commit 5b65f5b
  - Reenable broken cdrom quirk.
  - commit 6b9f78a
  - Reenable downstream powerpc patches.
  - commit 799a7a7
  - Reenable ppc KEXEC_SIG
    KEXEC option rework is now merged so this can be revisited but it's not
    upstream yet.
  - Update config files.
  - commit 933b828
  - Refresh sorted patches.
  - commit 0916037
  - Reenable crypto fix
  - commit 7f7a3e3
  - Lockdown patches need to be handled together.
  - commit a64f237
  - Reenable kABI placeholder
  - commit 6e585f9
  - Delete patches.rpmify/Revert-kbuild-Hack-for-depmod-not-handling-X.Y-versi.patch.
    Upstreamed
  - commit de5f3c4
  - Update config
    product version SLFO 1.2
    build project SLFO:Main:Build
    bugzilla product Micro 6.2
    build optional KMP
  - commit c86a93a
  - KVM: PPC: Book3S HV: Avoid returning to nested hypervisor on
    pending doorbells (bsc#1215199).
  - KVM: PPC: Book3S HV: Stop using vc->dpdes for nested KVM guests
    (bsc#1215199).
  - Revert "KVM: PPC: Book3S HV Nested: Stop forwarding all HFUs
    to L1" (bsc#1215199).
  - commit 78cb129
  - KVM: PPC: Book3S HV: Add Power11 capability support for Nested
    PAPR guests (jsc#PED-7970 jsc#PED-11016).
  - commit 1731e24
  - Delete
    patches.suse/reiserfs-mark-read-write-mode-unsupported.patch.
    We do not compile reiserfs at all for SLE16, so we can drop this patch
    completely.
  - commit 6f524a6
  - series.conf: Keep reserving space in cpu_hwcaps and cpu_hwcap_keys arrays
  - commit 5af8e9d
  - Refresh patches.suse/xfs-allow-mount-remount-when-stripe-width-alignment-.patch.
    We can retain this patch to make sure that customers that may be
    upgrading to SLE16 with previously formatted xfs filesystems susceptible
    to the issue mentioned in the patch will not face any upgrade issues.
  - commit 07642be
  - Delete patches.suse/xfs-remove-experimental-tag-for-dax-support.patch.
    Drop the patch as upstream [1] has removed the warning in v6.8 so we do
    not need to carry this any more.
    [1] commit 27c86d43bcdb ("xfs: drop experimental warning for FSDAX")
  - commit ad7a543
  - KVM: PPC: Book3S HV: Fix kmv -> kvm typo (jsc#PED-11016
    git-fixes).
  - commit 6002aff
  - platform/x86/amd: amd_3d_vcache: Add AMD 3D V-Cache optimizer driver (jsc#PED-11563).
  - Update config files.
  - commit d51966f
  - SLE16: supported.conf: further fixups
    Fix remaining warnings from kbuild
  - commit 5454218

++++ kernel-rt:

  - Re-enable fixup to the acpi_pad driver
  - commit 0dc7926
  - Re-enable prerequisite patch to set CONFIG_CPU_FREQ_DEFAULT_GOV_ONDEMAND=y
  - commit d5e1336
  - Re-enable defaulting to intel_pstate/powersave on non-HWP machines
  - commit b22515b
  - Re-enable idle-boost optimization for intel_pstate on non-HWP machines
  - commit 795714e
  - Re-enable intel_pstate optimization for low-utilization workloads on non-HWP machines
  - commit ce7c38f
  - Re-enable aggressive iowait boost for intel_pstate for non-HWP machines
  - commit 5b65f5b
  - Reenable broken cdrom quirk.
  - commit 6b9f78a
  - Reenable downstream powerpc patches.
  - commit 799a7a7
  - Reenable ppc KEXEC_SIG
    KEXEC option rework is now merged so this can be revisited but it's not
    upstream yet.
  - Update config files.
  - commit 933b828
  - Refresh sorted patches.
  - commit 0916037
  - Reenable crypto fix
  - commit 7f7a3e3
  - Lockdown patches need to be handled together.
  - commit a64f237
  - Reenable kABI placeholder
  - commit 6e585f9
  - Delete patches.rpmify/Revert-kbuild-Hack-for-depmod-not-handling-X.Y-versi.patch.
    Upstreamed
  - commit de5f3c4
  - Update config
    product version SLFO 1.2
    build project SLFO:Main:Build
    bugzilla product Micro 6.2
    build optional KMP
  - commit c86a93a
  - KVM: PPC: Book3S HV: Avoid returning to nested hypervisor on
    pending doorbells (bsc#1215199).
  - KVM: PPC: Book3S HV: Stop using vc->dpdes for nested KVM guests
    (bsc#1215199).
  - Revert "KVM: PPC: Book3S HV Nested: Stop forwarding all HFUs
    to L1" (bsc#1215199).
  - commit 78cb129
  - KVM: PPC: Book3S HV: Add Power11 capability support for Nested
    PAPR guests (jsc#PED-7970 jsc#PED-11016).
  - commit 1731e24
  - Delete
    patches.suse/reiserfs-mark-read-write-mode-unsupported.patch.
    We do not compile reiserfs at all for SLE16, so we can drop this patch
    completely.
  - commit 6f524a6
  - series.conf: Keep reserving space in cpu_hwcaps and cpu_hwcap_keys arrays
  - commit 5af8e9d
  - Refresh patches.suse/xfs-allow-mount-remount-when-stripe-width-alignment-.patch.
    We can retain this patch to make sure that customers that may be
    upgrading to SLE16 with previously formatted xfs filesystems susceptible
    to the issue mentioned in the patch will not face any upgrade issues.
  - commit 07642be
  - Delete patches.suse/xfs-remove-experimental-tag-for-dax-support.patch.
    Drop the patch as upstream [1] has removed the warning in v6.8 so we do
    not need to carry this any more.
    [1] commit 27c86d43bcdb ("xfs: drop experimental warning for FSDAX")
  - commit ad7a543
  - KVM: PPC: Book3S HV: Fix kmv -> kvm typo (jsc#PED-11016
    git-fixes).
  - commit 6002aff
  - platform/x86/amd: amd_3d_vcache: Add AMD 3D V-Cache optimizer driver (jsc#PED-11563).
  - Update config files.
  - commit d51966f
  - SLE16: supported.conf: further fixups
    Fix remaining warnings from kbuild
  - commit 5454218

++++ mozilla-nss:

  - Updated nss-fips-approved-crypto-non-ec.patch to not pass in
    bad targetKeyLength parameters when checking for FIPS approval
    after keygen. This was causing false rejections.

++++ qemu:

  - Fix bsc#1233530:
    * docs: use consistent markup for footnotes (bsc#1233530)
    * docs: avoid footnotes consisting of just URLs (bsc#1233530)
    * docs: fix invalid footnote syntax (bsc#1233692)
  - Fix bsc#1233530:
    * scsi: megasas: Internal cdbs have 16-byte length (bsc#1233530)
  - Fix bsc#1221812, bsc#1232283, bsc#1230978:
    * [openSUSE] block: Move qcow2 invalidation query-block op_blocker
  - Update to version 9.1.2:
    Full changelog here:
    https://lore.kernel.org/qemu-devel/21ba2773-11a6-45ad-bf98-9b5c2cdccb9b@tls.msk.ru/
    Some of the most notable features:
    * usb-hub: Fix handling port power control messages
    * hw/audio/hda: fix memory leak on audio setup
    * Revert "hw/audio/hda: fix memory leak on audio setup" (bsc#1232728)
    * hw/misc/mos6522: Fix bad class definition of the MOS6522 device
    * vfio/container: Fix container object destruction
    * target/i386: fix hang when using slow path for ptw_setl
    * tcg: Allow top bit of SIMD_DATA_BITS to be set in simd_desc()
    * linux-user/arm: Select vdso for be8 and be32 modes
    * linux-user/arm: Reduce vdso alignment to 4k
    * linux-user: Tolerate CONFIG_LSM_MMAP_MIN_ADDR
    * accel/tcg: Fix user-only probe_access_internal plugin check
    * target/arm: Drop user-only special case in sve_stN_r
    * linux-user: Fix setreuid and setregid to use direct syscalls
    * hw/i386/pc: Don't try to init PCI NICs if there is no PCI bus
    * target/i386: Fix legacy page table walk
    * 9pfs: fix crash on 'Treaddir' request
    * hw/nvme: fix handling of over-committed queues
    * migration: Ensure vmstate_save() sets errp
    * target/arm: Fix SVE SDOT/UDOT/USDOT (4-way, indexed)
    * target/arm: Add new MMU indexes for AArch32 Secure PL1&0
    * Revert "target/arm: Fix usage of MMU indexes when EL3 is AArch32"
    * acpi/disassemle-aml.sh: fix up after dir reorg
    * hw/acpi: Fix ordering of BDF in Generic Initiator PCI Device Handle.
    * qemu-ga: Fix a SIGSEGV in ga_run_command() helper
    * hw/sd/sdcard: Fix calculation of size when using eMMC boot partitions
    * tests/tcg: Replace -mpower8-vector with -mcpu=power8
    * hw/ssi/pnv_spi: Fixes Coverity CID 1558831
    * hw/ssi/pnv_spi: Return early in transfer()

++++ virt-manager:

  - Update to Version 5.0.0 (jsc#PED-8910)
    * virt-clone: colne serial files (Oleg Vasilev)
    * virt-clone: Copy disk permissions as well (Martin Kletzander)
    * virt-install: Add properties for AMD SEV-SNP (Daniel P. Berrangé)
    * virt-install: Add passt backend for user network interface
    * virt-install: Add support for --sound multichannel,stream (Lin Ma)
    * virt-install: Add support for --tpm backend.debug,backend.source (Lin Ma)
    * virt-xml: add --edit --convert-to-q35
    * virt-xml: add --edit --convert-to-vnc
    * virt-xml: Add --edit --boot uefi
    * virt-manager: Fix opening graphical console with egl-headless (Feng Jiang)
    * virt-manager: Add support to create external snapshots
    * virt-manager: Default to scaling=Always for consoles
    * virt-manager: switch to not forking by default
    * cli: Add more --disk options (Lin Ma)
    * cli: Add --memdev target.address_base for virtio-mem and virtio-pmem (Lin Ma)
    * cli: Add --features kvm.pv-ipi.state=on|off (Lin Ma)
    * cli: Add --video model.blob=on|off (Lin Ma)
    * Add missing Hyper-V features and enable most of them by default
    * Add loongarch support (Xianglai Li)
    * Add support for hvf domain type (Mohamed Akram)
    * Support creating sparse volumes on ZFS pools (Iain Buclaw)
    * UEFI improvements for riscv64 and loongarch64 VMs (Andrea Bolognani)
    * Add graphcis to riscv64 and aarch64
    * build: swtich from setuptools to meson
    * diskbackend: Drop support for sheepdog (Lin Ma)
    * cli: Deprecate --cpu host in favor of --cpu host-model (Andrea Bolognani)
  - Drop the following upstream patches contained in new tarball
    001-cli-disk-Add-driver.metadata_cache-options.patch
    002-tests-cli-Fix-test-output-after-previous-commit.patch
    003-fsdetails-Fix-an-error-with-source.socket-of-virtiofs.patch
    004-cli-Drop-unnecessary-disk-prop-aliases.patch
    005-tests-testdriver-Add-filesystem-socket-example.patch
    006-virtinstall-split-no_install-conditional-apart-to-track-code-coverage.patch
    007-virtinstall-fix-regression-with-boot-and-no-install-method.patch
    008-tests-Add-a-compat-check-for-linux2020-in-amd-sev-test-case.patch
    009-cli-cpu-Add-maxphysaddr.mode-bits-options.patch
    010-virt-install-help-required-options-are-wrong.patch
    011-cloner-Sync-uuid-and-sysinfo-system-uuid.patch
    012-virt-install-unattended-and-cloud-init-conflict.patch
    013-virt-install-Reuse-cli.fail_conflicting.patch
    014-cli-support-boot-loader.stateless-.patch
    015-diskbackend-Drop-support-for-sheepdog.patch
    016-Fix-pylint-pycodestyle-warnings-with-latest-versions.patch
    017-tests-cpio-set-owner-to-00.patch
    018-addhardware-Fix-backtrace-when-controller.index-is-None.patch
    019-Clean-up-FileChooser-usage-a-bit.patch
    020-guest-Query-availability-of-usb-redirdevs-in-domcaps.patch
    021-guest-Query-availability-of-spicevmc-channels-in-domcaps.patch
    022-tests-Add-domcaps-coverage-for-usb-redir-spicevmc-channel-checks.patch
    023-tests-Update-to-latest-kvm-domcaps.patch
    024-progress-Fix-showing-correct-final-total.patch
    025-virtinstall-Fix-the-allocating-disk-size-printed-by-the-progress-bar.patch
    026-virtinstall-Hide-total_size-in-the-progress-bar-if-it-doesnt-need.patch
    027-asyncjob-Fix-backtrace-when-no-cursor-theme-installed.patch
    029-asyncjob-Remove-unused-import.patch
    030-Packit-initial-enablement.patch
    031-virt-install-Recommend-boot-uefi.patch
    032-virt-install-Document-Secure-Boot-setups.patch
    033-cloner-clone-serial-files.patch
    034-tests-cli-test-serial-file-clone.patch
    035-man-virt-install-Add-a-note-about-different-behavior-of-boot-on-s390x.patch
    036-tests-uitests-Fix-window-reposition-on-f38.patch
    037-tests-livetests-work-around-qemu-media-change-regression.patch
    038-tests-uitests-Fix-manager-window-repositioning-test.patch
    039-tests-Default-uitests-to-verbosity-2.patch
    040-uitests-Make-hotplug-test-pass-on-both-f37-and-f38.patch
    041-uitests-More-attempts-at-making-manager-reposition-test-reliable.patch
    042-tests-uitests-make-menu-operations-more-robust.patch
    043-rpm-convert-license-to-SPDX-format.patch
    044-uitests-Drop-hotplug-work-around-f38-libvirt-is-fixed-now.patch
    045-virtinst-delay-lookup_capsinfo-until-we-really-need-it.patch
    046-virtinst-suppress-lookup_capsinfo-exception-in-machine-type-alias-check.patch
    047-tests-data-refresh-Fedora-tree-URLs-in-virt-install-osinfo-expected-XMLs.patch
    048-tests-Add-unit-test-coverage-for-539.patch
    049-fix-indentation-of-multiline-log.exception-invocations.patch
    050-virt-clone-Copy-disk-permissions-as-well.patch
    051-data-appstream-add-launchable-tag.patch
    052-Fix-some-pylint.patch
    055-connectauth-Drop-sanity-checking-for-libvirtd.patch
    056-delete-Fix-ambiguity-that-confused-pylint.patch
    057-Fix-filesystem-socket.source.patch
    058-uri-Mock-domcaps-returning-NO_SUPPORT.patch
    059-tests-cli-Adjust-hotplug-test-for-latest-libvirt.patch
    060-Fix-some-pylint.patch
    061-tests-ui-make-newvm-test-start-less-flakey.patch
    062-tests-ui-make-creatnet-test-start-less-flakey.patch
    063-Support-creating-sparse-volumes-on-ZFS-pools.patch
    064-domain-rename-handle-firmware-ending-with-.qcow2.patch
    065-testdriver-Add-portgroups-example-to-test-many-devices.patch
    066-netlist-Fix-UI-error-when-virtual-network-doesnt-exist.patch
    067-ui-details-fix-Applications-width.patch
    068-ui-details-Increased-scrolledview6s-height-request.patch
    069-uitests-Fix-walkUI-flakyness.patch
    070-uitests-Handle-slow-app-launch-on-fedora-39.patch
    071-createvm-Replace-deprecated-pkgutil.find_loader.patch
    072-Fix-pylint-3.1.0-issues.patch
    073-console-Move-embeddable_graphics-to-console.py.patch
    074-domain-Add-idx-parameter-to-open_graphics_fd.patch
    075-console-Select-the-first-embeddable-graphics-device-as-graphical-console.patch
    076-console-Cleanup-and-improve-console-menu-handling.patch
    077-cli-add-show-systray-option.patch
    078-man-document-show-systray-option.patch
    079-baseclass-Avoid-glib-Source-ID-XX-not-found-at-app-shutdown.patch
    080-uitests-More-handling-for-slow-startup-on-f39.patch
    081-systray-Cleanups-and-improvements-for-show-systray.patch
    082-virtinst-add-external-snapshot-capability.patch
    083-virtinst-snapshot-add-memory-file-attribute.patch
    084-virtManager-domain-allow-disk-only-snapshots.patch
    085-virtManager-add-support-to-create-external-snapshots.patch
    086-virtManager-ignore-agen-livecycle-event-for-shutoff-VMs.patch
    087-Allow-serial-console-resize-to-beyond-80-columns.patch
    088-tests-Fix-host-copy-XML-with-libvirt-10.1.0.patch
    089-hostdev-Fix-error-when-mdev-type_id-is-missing.patch
    090-db1b2fbc-Use-GtkFileChooserNative.patch
    091-uitests-Fix-with-GtkFileChooserNative.patch
    092-cli-Use-regex-for-grep-and-nogrep-args.patch
    093-cli-Fix-with-latest-libvirt.patch
    094-uitests-handle-newer-libvirt-test-driver-UpdateDevice-support.patch
    095-uitests-force-internal-snapshots-in-test_snapshot.py.patch
  - Drop the following downstream patches no longer required
    virtinst-dont-create-storage-pool-for-dryrun.patch
    virtinst-add-pvh-support.patch
    virtinst-enable-video-virtio-for-arm.patch
    virtinst-add-hyperv-performance-options.patch
    virtman-dont-specify-gtksource-version.patch
    virtman-language-fixes.patch

------------------------------------------------------------------
------------------  2024-11-25  -  Nov 25 2024  -------------------
------------------------------------------------------------------

++++ cockpit:

  - update to 329.1:
  - cockpit.js: Put back cockpit.{resolve,reject}() to fix subscription-manager-cockpit
  - Past updates:
    * 329
  - Shell: Extra warnings when connecting to remote hosts
    * 328:
  - Bug fixes and performance improvements
    * 327:
  - Connect to similar servers without Cockpit installed
    * 326:
  - cockpit-pcp package is now obsolete
  - cockpit/ws container: Connect to servers without installed Cockpit
  - cockpit/ws container: Support host specific SSH keys
  - Storage: Support for Stratis filesystem sizes and limits
    * 325:
  - client: Properly handle unknown SSH host keys
    * 324:
  - Bug fixes and performance improvements
    * 323.1:
  - Translation updates
    * 323:
  - login: Prevent multiple logins in a single browser session
  - Update documentation links

++++ python-kiwi:

  - Fixed use of fscreateoptions for iso type
    The information for fscreateoptions was not passed along to the
    tooling if a custom filesystem attribute was specified.
    This Fixes #2681
  - Allow to derive from multiple containers
    Add support for multi inheritance to the derived_from attribute
    In the order of a comma seperated list of docker source URI's
    a base tree is created. This was possible only with one container
    so far and Fixes #2680 as well as jira#OBS-354

++++ git:

  - update to 2.47.1:
    * Use after free and double freeing at the end in
    "git log -L... -p" had been identified and fixed.
    * "git maintenance start" crashed due to an uninitialized
    variable reference, which has been corrected.
    * Fail gracefully instead of crashing when attempting to write
    the contents of a corrupt in-core index as a tree object.
    * A "git fetch" from the superproject going down to a submodule
    used a wrong remote when the default remote names are set
    differently between them.
    * The "gitk" project tree has been synchronized again

++++ kernel-default:

  - SLE16: supported.conf: fix build errors
    Fix following errors in supported.conf
    x86_64:
    [ 1581s] warning: intel_skl_int3472_common not listed in supported.conf
    [ 1583s] warning: mlx90635 not listed in supported.conf
    [ 1584s] warning: nxp_c45_tja not listed in supported.conf
    [ 1584s] warning: processor_thermal_power_floor not listed in supported.conf
    [ 1584s] warning: processor_thermal_wt_hint not listed in supported.conf
    [ 1584s] warning: processor_thermal_wt_req not listed in supported.conf
    [ 1586s] warning: skx_edac_common not listed in supported.conf
    [ 1586s] warning: spi_pxa2xx_core not listed in supported.conf
    [ 1587s] warning: tipc_diag not listed in supported.conf
    [ 1589s] The following unsupported modules are used by supported modules:
    [ 1589s] libeth needed by iavf
    [ 1589s] libeth needed by idpf
    [ 1589s] libie needed by i40e
    [ 1589s] libie needed by iavf
    [ 1589s] libie needed by ice
    [ 1589s] libie needed by irdma
    [ 1589s] liquidio_core needed by liquidio
    [ 1589s] liquidio_core needed by liquidio_vf
    [ 1589s] nls_ucs2_utils needed by cifs
    [ 1589s] processor_thermal_power_floor needed by int3401_thermal
    [ 1589s] processor_thermal_power_floor needed by processor_thermal_device
    [ 1589s] processor_thermal_power_floor needed by processor_thermal_device_pci
    [ 1589s] processor_thermal_wt_hint needed by int3401_thermal
    [ 1589s] processor_thermal_wt_hint needed by processor_thermal_device
    [ 1589s] processor_thermal_wt_hint needed by processor_thermal_device_pci
    [ 1589s] processor_thermal_wt_req needed by int3401_thermal
    [ 1589s] processor_thermal_wt_req needed by processor_thermal_device
    [ 1589s] processor_thermal_wt_req needed by processor_thermal_device_pci
    [ 1589s] ptp_mock needed by netdevsim
    [ 1589s] pwrseq_core needed by hci_nokia
    [ 1589s] pwrseq_core needed by hci_uart
    [ 1589s] qcom_phy_lib needed by at803x
    [ 1589s] rpmb_core needed by mmc_block
    [ 1589s] rtw88_8723x needed by rtw88_8723d
    [ 1589s] rtw88_8723x needed by rtw88_8723de
    [ 1589s] skx_edac_common needed by i10nm_edac
    [ 1589s] skx_edac_common needed by skx_edac
    [ 1589s] snd_amd_sdw_acpi needed by snd_pci_ps
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_acp
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_rembrandt
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_renoir
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_vangogh
    [ 1589s] snd_hda_scodec_component needed by snd_hda_codec_realtek
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_i2c
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_spi
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_i2c
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_spi
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_i2c
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_sdw
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_shared
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_spi
    [ 1589s] snd_soc_es83xx_dsm_common needed by snd_soc_sst_byt_cht_es8316
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_skl_hda_dsp
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_cs42l42
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_nau8825
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_rt5682
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_ssp_amp
    [ 1589s] snd_soc_intel_sof_nuvoton_common needed by snd_soc_sof_nau8825
    [ 1589s] snd_soc_sdw_utils needed by snd_soc_sof_sdw
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_apl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_cnl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_icl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_lnl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_mtl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_skl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_tgl
    [ 1589s] soundwire_amd needed by snd_pci_ps
    [ 1589s] soundwire_amd needed by snd_sof_amd_acp
    [ 1589s] soundwire_amd needed by snd_sof_amd_rembrandt
    [ 1589s] soundwire_amd needed by snd_sof_amd_renoir
    [ 1589s] soundwire_amd needed by snd_sof_amd_vangogh
    [ 1589s] spi_pxa2xx_core needed by spi_pxa2xx_platform
    arm64:
    [ 6509s] warning: cpr not listed in supported.conf
    [ 6510s] warning: ffa_core not listed in supported.conf
    [ 6511s] warning: hclge_common not listed in supported.conf
    [ 6512s] warning: i2c_pasemi_core not listed in supported.conf
    [ 6512s] warning: i2c_pasemi_platform not listed in supported.conf
    [ 6512s] warning: imx_common not listed in supported.conf
    [ 6514s] warning: mlx90635 not listed in supported.conf
    [ 6515s] warning: mtk_adsp_common not listed in supported.conf
    [ 6516s] warning: nxp_c45_tja not listed in supported.conf
    [ 6516s] warning: phy_qcom_qmp_usbc not listed in supported.conf
    [ 6517s] warning: qcom_pmic_tcpm not listed in supported.conf
    [ 6518s] warning: rpmpd not listed in supported.conf
    [ 6518s] warning: rswitch not listed in supported.conf
    [ 6520s] warning: snd_soc_fsi not listed in supported.conf
    [ 6520s] warning: snd_soc_rcar not listed in supported.conf
    [ 6520s] warning: snd_soc_rz_ssi not listed in supported.conf
    [ 6520s] warning: snd_soc_stm32_sai_sub not listed in supported.conf
    [ 6520s] warning: snd_sof_imx8 not listed in supported.conf
    [ 6520s] warning: snd_sof_imx8m not listed in supported.conf
    [ 6520s] warning: snd_sof_imx8ulp not listed in supported.conf
    [ 6520s] warning: snd_sof_mt8186 not listed in supported.conf
    [ 6520s] warning: snd_sof_mt8195 not listed in supported.conf
    [ 6520s] warning: snd_sof_of not listed in supported.conf
    [ 6522s] warning: tipc_diag not listed in supported.conf
    [ 6525s] The following unsupported modules are used by supported modules:
    [ 6525s] apple_mailbox needed by apple_rtkit
    [ 6525s] apple_mailbox needed by nvme_apple
    [ 6525s] apple_rtkit needed by nvme_apple
    [ 6525s] apple_sart needed by nvme_apple
    [ 6525s] aux_hpd_bridge needed by pmic_glink_altmode
    [ 6525s] ffa_core needed by ffa_module
    [ 6525s] ffa_core needed by optee
    [ 6525s] hclge_common needed by hclge
    [ 6525s] hclge_common needed by hclgevf
    [ 6525s] k3_cppi_desc_pool needed by ti_am65_cpsw_nuss
    [ 6525s] libeth needed by iavf
    [ 6525s] libie needed by i40e
    [ 6525s] libie needed by iavf
    [ 6525s] libie needed by ice
    [ 6525s] libie needed by irdma
    [ 6525s] liquidio_core needed by liquidio
    [ 6525s] liquidio_core needed by liquidio_vf
    [ 6525s] mdio_regmap needed by dwmac_altr_socfpga
    [ 6525s] nls_ucs2_utils needed by cifs
    [ 6525s] ptp_mock needed by netdevsim
    [ 6525s] pwrseq_core needed by hci_nokia
    [ 6525s] pwrseq_core needed by hci_uart
    [ 6525s] qcom_ice needed by sdhci_msm
    [ 6525s] qcom_ice needed by ufs_qcom
    [ 6525s] qcom_pdr_msg needed by apr
    [ 6525s] qcom_pdr_msg needed by pdr_interface
    [ 6525s] qcom_pdr_msg needed by pmic_glink
    [ 6525s] qcom_pdr_msg needed by pmic_glink_altmode
    [ 6525s] qcom_pdr_msg needed by q6adm
    [ 6525s] qcom_pdr_msg needed by q6afe
    [ 6525s] qcom_pdr_msg needed by q6afe_clocks
    [ 6525s] qcom_pdr_msg needed by q6afe_dai
    [ 6525s] qcom_pdr_msg needed by q6apm_dai
    [ 6525s] qcom_pdr_msg needed by q6apm_lpass_dais
    [ 6525s] qcom_pdr_msg needed by q6asm
    [ 6525s] qcom_pdr_msg needed by q6asm_dai
    [ 6525s] qcom_pdr_msg needed by q6core
    [ 6525s] qcom_pdr_msg needed by q6prm
    [ 6525s] qcom_pdr_msg needed by q6prm_clocks
    [ 6525s] qcom_pdr_msg needed by q6routing
    [ 6525s] qcom_pdr_msg needed by snd_q6apm
    [ 6525s] qcom_phy_lib needed by at803x
    [ 6525s] rpmb_core needed by mmc_block
    [ 6525s] rpmb_core needed by optee
    [ 6525s] rtw88_8723x needed by rtw88_8723d
    [ 6525s] rtw88_8723x needed by rtw88_8723de
    [ 6525s] snd_hda_scodec_component needed by snd_hda_codec_realtek
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_i2c
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_spi
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_i2c
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_spi
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_i2c
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_sdw
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_shared
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_spi
    [ 6525s] snd_soc_wcd_classh needed by snd_soc_wcd9335
    [ 6525s] snd_soc_wcd_classh needed by snd_soc_wcd934x
    [ 6525s] snd_soc_wcd_classh needed by snd_soc_wcd938x
    [ 6525s] xilinx_core needed by xilinx_spi
    ppc64le:
    [ 2708s] warning: nxp_c45_tja not listed in supported.conf
    [ 2709s] warning: tipc_diag not listed in supported.conf
    [ 2712s] The following unsupported modules are used by supported modules:
    [ 2712s] aux_hpd_bridge needed by pmic_glink_altmode
    [ 2712s] curve25519_ppc64le needed by libcurve25519
    [ 2712s] curve25519_ppc64le needed by wireguard
    [ 2712s] libeth needed by iavf
    [ 2712s] libie needed by i40e
    [ 2712s] libie needed by iavf
    [ 2712s] libie needed by ice
    [ 2712s] libie needed by irdma
    [ 2712s] nls_ucs2_utils needed by cifs
    [ 2712s] ptp_mock needed by netdevsim
    [ 2712s] qcom_pdr_msg needed by pdr_interface
    [ 2712s] qcom_pdr_msg needed by pmic_glink
    [ 2712s] qcom_pdr_msg needed by pmic_glink_altmode
    [ 2712s] qcom_phy_lib needed by at803x
    [ 2712s] rtw88_8723x needed by rtw88_8723d
    [ 2712s] rtw88_8723x needed by rtw88_8723de
    [ 2712s] xilinx_core needed by xilinx_spi
    s390:
    [ 1303s] warning: nxp_c45_tja not listed in supported.conf
    [ 1304s] warning: serial_base not listed in supported.conf
    [ 1304s] warning: tipc_diag not listed in supported.conf
    [ 1305s] The following unsupported modules are used by supported modules:
    [ 1305s] nls_ucs2_utils needed by cifs
    [ 1305s] ptp_mock needed by netdevsim
    [ 1305s] qcom_phy_lib needed by at803x
  - commit 078fa22

++++ kernel-firmware-all:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-amdgpu:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-ath10k:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-ath11k:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-ath12k:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-atheros:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-bluetooth:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-bnx2:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-brcm:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-chelsio:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-dpaa2:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-i915:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-intel:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-iwlwifi:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-liquidio:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-marvell:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-media:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-mediatek:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-mellanox:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-mwifiex:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-network:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-nfp:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-nvidia:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-platform:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-prestera:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-qcom:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-qlogic:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-radeon:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-realtek:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-serial:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-sound:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-ti:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-ueagle:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-firmware-usb-network:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

++++ kernel-rt:

  - SLE16: supported.conf: fix build errors
    Fix following errors in supported.conf
    x86_64:
    [ 1581s] warning: intel_skl_int3472_common not listed in supported.conf
    [ 1583s] warning: mlx90635 not listed in supported.conf
    [ 1584s] warning: nxp_c45_tja not listed in supported.conf
    [ 1584s] warning: processor_thermal_power_floor not listed in supported.conf
    [ 1584s] warning: processor_thermal_wt_hint not listed in supported.conf
    [ 1584s] warning: processor_thermal_wt_req not listed in supported.conf
    [ 1586s] warning: skx_edac_common not listed in supported.conf
    [ 1586s] warning: spi_pxa2xx_core not listed in supported.conf
    [ 1587s] warning: tipc_diag not listed in supported.conf
    [ 1589s] The following unsupported modules are used by supported modules:
    [ 1589s] libeth needed by iavf
    [ 1589s] libeth needed by idpf
    [ 1589s] libie needed by i40e
    [ 1589s] libie needed by iavf
    [ 1589s] libie needed by ice
    [ 1589s] libie needed by irdma
    [ 1589s] liquidio_core needed by liquidio
    [ 1589s] liquidio_core needed by liquidio_vf
    [ 1589s] nls_ucs2_utils needed by cifs
    [ 1589s] processor_thermal_power_floor needed by int3401_thermal
    [ 1589s] processor_thermal_power_floor needed by processor_thermal_device
    [ 1589s] processor_thermal_power_floor needed by processor_thermal_device_pci
    [ 1589s] processor_thermal_wt_hint needed by int3401_thermal
    [ 1589s] processor_thermal_wt_hint needed by processor_thermal_device
    [ 1589s] processor_thermal_wt_hint needed by processor_thermal_device_pci
    [ 1589s] processor_thermal_wt_req needed by int3401_thermal
    [ 1589s] processor_thermal_wt_req needed by processor_thermal_device
    [ 1589s] processor_thermal_wt_req needed by processor_thermal_device_pci
    [ 1589s] ptp_mock needed by netdevsim
    [ 1589s] pwrseq_core needed by hci_nokia
    [ 1589s] pwrseq_core needed by hci_uart
    [ 1589s] qcom_phy_lib needed by at803x
    [ 1589s] rpmb_core needed by mmc_block
    [ 1589s] rtw88_8723x needed by rtw88_8723d
    [ 1589s] rtw88_8723x needed by rtw88_8723de
    [ 1589s] skx_edac_common needed by i10nm_edac
    [ 1589s] skx_edac_common needed by skx_edac
    [ 1589s] snd_amd_sdw_acpi needed by snd_pci_ps
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_acp
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_rembrandt
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_renoir
    [ 1589s] snd_amd_sdw_acpi needed by snd_sof_amd_vangogh
    [ 1589s] snd_hda_scodec_component needed by snd_hda_codec_realtek
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_i2c
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_spi
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_i2c
    [ 1589s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_spi
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_i2c
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_sdw
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_shared
    [ 1589s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_spi
    [ 1589s] snd_soc_es83xx_dsm_common needed by snd_soc_sst_byt_cht_es8316
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_skl_hda_dsp
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_cs42l42
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_nau8825
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_rt5682
    [ 1589s] snd_soc_intel_sof_board_helpers needed by snd_soc_sof_ssp_amp
    [ 1589s] snd_soc_intel_sof_nuvoton_common needed by snd_soc_sof_nau8825
    [ 1589s] snd_soc_sdw_utils needed by snd_soc_sof_sdw
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_apl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_cnl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_icl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_lnl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_mtl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_skl
    [ 1589s] snd_sof_intel_hda_generic needed by snd_sof_pci_intel_tgl
    [ 1589s] soundwire_amd needed by snd_pci_ps
    [ 1589s] soundwire_amd needed by snd_sof_amd_acp
    [ 1589s] soundwire_amd needed by snd_sof_amd_rembrandt
    [ 1589s] soundwire_amd needed by snd_sof_amd_renoir
    [ 1589s] soundwire_amd needed by snd_sof_amd_vangogh
    [ 1589s] spi_pxa2xx_core needed by spi_pxa2xx_platform
    arm64:
    [ 6509s] warning: cpr not listed in supported.conf
    [ 6510s] warning: ffa_core not listed in supported.conf
    [ 6511s] warning: hclge_common not listed in supported.conf
    [ 6512s] warning: i2c_pasemi_core not listed in supported.conf
    [ 6512s] warning: i2c_pasemi_platform not listed in supported.conf
    [ 6512s] warning: imx_common not listed in supported.conf
    [ 6514s] warning: mlx90635 not listed in supported.conf
    [ 6515s] warning: mtk_adsp_common not listed in supported.conf
    [ 6516s] warning: nxp_c45_tja not listed in supported.conf
    [ 6516s] warning: phy_qcom_qmp_usbc not listed in supported.conf
    [ 6517s] warning: qcom_pmic_tcpm not listed in supported.conf
    [ 6518s] warning: rpmpd not listed in supported.conf
    [ 6518s] warning: rswitch not listed in supported.conf
    [ 6520s] warning: snd_soc_fsi not listed in supported.conf
    [ 6520s] warning: snd_soc_rcar not listed in supported.conf
    [ 6520s] warning: snd_soc_rz_ssi not listed in supported.conf
    [ 6520s] warning: snd_soc_stm32_sai_sub not listed in supported.conf
    [ 6520s] warning: snd_sof_imx8 not listed in supported.conf
    [ 6520s] warning: snd_sof_imx8m not listed in supported.conf
    [ 6520s] warning: snd_sof_imx8ulp not listed in supported.conf
    [ 6520s] warning: snd_sof_mt8186 not listed in supported.conf
    [ 6520s] warning: snd_sof_mt8195 not listed in supported.conf
    [ 6520s] warning: snd_sof_of not listed in supported.conf
    [ 6522s] warning: tipc_diag not listed in supported.conf
    [ 6525s] The following unsupported modules are used by supported modules:
    [ 6525s] apple_mailbox needed by apple_rtkit
    [ 6525s] apple_mailbox needed by nvme_apple
    [ 6525s] apple_rtkit needed by nvme_apple
    [ 6525s] apple_sart needed by nvme_apple
    [ 6525s] aux_hpd_bridge needed by pmic_glink_altmode
    [ 6525s] ffa_core needed by ffa_module
    [ 6525s] ffa_core needed by optee
    [ 6525s] hclge_common needed by hclge
    [ 6525s] hclge_common needed by hclgevf
    [ 6525s] k3_cppi_desc_pool needed by ti_am65_cpsw_nuss
    [ 6525s] libeth needed by iavf
    [ 6525s] libie needed by i40e
    [ 6525s] libie needed by iavf
    [ 6525s] libie needed by ice
    [ 6525s] libie needed by irdma
    [ 6525s] liquidio_core needed by liquidio
    [ 6525s] liquidio_core needed by liquidio_vf
    [ 6525s] mdio_regmap needed by dwmac_altr_socfpga
    [ 6525s] nls_ucs2_utils needed by cifs
    [ 6525s] ptp_mock needed by netdevsim
    [ 6525s] pwrseq_core needed by hci_nokia
    [ 6525s] pwrseq_core needed by hci_uart
    [ 6525s] qcom_ice needed by sdhci_msm
    [ 6525s] qcom_ice needed by ufs_qcom
    [ 6525s] qcom_pdr_msg needed by apr
    [ 6525s] qcom_pdr_msg needed by pdr_interface
    [ 6525s] qcom_pdr_msg needed by pmic_glink
    [ 6525s] qcom_pdr_msg needed by pmic_glink_altmode
    [ 6525s] qcom_pdr_msg needed by q6adm
    [ 6525s] qcom_pdr_msg needed by q6afe
    [ 6525s] qcom_pdr_msg needed by q6afe_clocks
    [ 6525s] qcom_pdr_msg needed by q6afe_dai
    [ 6525s] qcom_pdr_msg needed by q6apm_dai
    [ 6525s] qcom_pdr_msg needed by q6apm_lpass_dais
    [ 6525s] qcom_pdr_msg needed by q6asm
    [ 6525s] qcom_pdr_msg needed by q6asm_dai
    [ 6525s] qcom_pdr_msg needed by q6core
    [ 6525s] qcom_pdr_msg needed by q6prm
    [ 6525s] qcom_pdr_msg needed by q6prm_clocks
    [ 6525s] qcom_pdr_msg needed by q6routing
    [ 6525s] qcom_pdr_msg needed by snd_q6apm
    [ 6525s] qcom_phy_lib needed by at803x
    [ 6525s] rpmb_core needed by mmc_block
    [ 6525s] rpmb_core needed by optee
    [ 6525s] rtw88_8723x needed by rtw88_8723d
    [ 6525s] rtw88_8723x needed by rtw88_8723de
    [ 6525s] snd_hda_scodec_component needed by snd_hda_codec_realtek
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_i2c
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l41_spi
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_i2c
    [ 6525s] snd_soc_cs_amp_lib needed by snd_hda_scodec_cs35l56_spi
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_i2c
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_sdw
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_shared
    [ 6525s] snd_soc_cs_amp_lib needed by snd_soc_cs35l56_spi
    [ 6525s] snd_soc_wcd_classh needed by snd_soc_wcd9335
    [ 6525s] snd_soc_wcd_classh needed by snd_soc_wcd934x
    [ 6525s] snd_soc_wcd_classh needed by snd_soc_wcd938x
    [ 6525s] xilinx_core needed by xilinx_spi
    ppc64le:
    [ 2708s] warning: nxp_c45_tja not listed in supported.conf
    [ 2709s] warning: tipc_diag not listed in supported.conf
    [ 2712s] The following unsupported modules are used by supported modules:
    [ 2712s] aux_hpd_bridge needed by pmic_glink_altmode
    [ 2712s] curve25519_ppc64le needed by libcurve25519
    [ 2712s] curve25519_ppc64le needed by wireguard
    [ 2712s] libeth needed by iavf
    [ 2712s] libie needed by i40e
    [ 2712s] libie needed by iavf
    [ 2712s] libie needed by ice
    [ 2712s] libie needed by irdma
    [ 2712s] nls_ucs2_utils needed by cifs
    [ 2712s] ptp_mock needed by netdevsim
    [ 2712s] qcom_pdr_msg needed by pdr_interface
    [ 2712s] qcom_pdr_msg needed by pmic_glink
    [ 2712s] qcom_pdr_msg needed by pmic_glink_altmode
    [ 2712s] qcom_phy_lib needed by at803x
    [ 2712s] rtw88_8723x needed by rtw88_8723d
    [ 2712s] rtw88_8723x needed by rtw88_8723de
    [ 2712s] xilinx_core needed by xilinx_spi
    s390:
    [ 1303s] warning: nxp_c45_tja not listed in supported.conf
    [ 1304s] warning: serial_base not listed in supported.conf
    [ 1304s] warning: tipc_diag not listed in supported.conf
    [ 1305s] The following unsupported modules are used by supported modules:
    [ 1305s] nls_ucs2_utils needed by cifs
    [ 1305s] ptp_mock needed by netdevsim
    [ 1305s] qcom_phy_lib needed by at803x
  - commit 078fa22

++++ samba:

  - Update to 4.21.2
    * smbd fails to correctly check sharemode against OVERWRITE
    dispositions; (bso#15732).
    * Panic in close_directory; (bso#15754).
    * winexe no longer works with samba 4.21; (bso#15752).
    * protocol error - Unclear debug message "pad length mismatch"
    for invalid bind packet; (bso#14356).
    * NetrGetLogonCapabilities QueryLevel 2 needs to be
    implemented; (bso#15425).
    * gss_accept_sec_context() from Heimdal does not imply
    GSS_C_MUTUAL_FLAG with GSS_C_DCE_STYLE; (bso#15740).
    * winbindd should call process_set_title() for locator child;
    (bso#15749).
    * Update CTDB to track all TCP connections to public IP
    addresses; (bso#15320).

++++ ncurses:

  - Add ncurses patch 20241123
    + remove dependency on stdbool.h from configure script check for type
    of bool when C++ binding is omitted (report by Sam James).
    + compiler-warning fixes

++++ libnetfilter_conntrack:

  - Specfile modernization

++++ libnvme:

  - Fix tests on s390
    * add 0002-test-mock-pass-thru-unknown-ioctls.patch

++++ mozilla-nspr:

  - update to version 4.36
    * remove support for OS/2
    * remove support for Unixware, Bsdi, old AIX, old HPUX9 & scoos
    * remove support for Windows 16 bit
    * renamed the prwin16.h header to prwin.h
    * configure was updated from 2.69 to 2.71
    * various build, test and automation script fixes
    * major parts of the source code were reformatted

++++ nvidia-open-driver-G06-signed:

  - fixed my wrong patch 550.135.patch I introduced right below;
    it fixed x86_64 build more-or-less accidently but broke aarch64
    build completely ...
  - Improve handling of conflicts between different flavors
    (gfx vs. CUDA) (bsc#1233332).
  - Update to 550.135 (boo#1233673)
  - 550.135.patch:
    * fixes wrong logic for checking supported architectures

++++ passt:

  - Update to version 20241121.238c69f:
    * tcp: Acknowledge keep-alive segments, ignore them for the rest
    * tcp: Reset ACK_TO_TAP_DUE flag whenever an ACK isn't needed anymore
    * ndp: Don't send unsolicited RAs if NDP is disabled
    * ndp: Don't send unsolicited router advertisement if we can't, yet
    * selinux: Use auth_read_passwd() interface for all our getpwnam() needs
    * ndp: Send unsolicited Router Advertisements
    * passt: Seed libc's pseudo random number generator
    * util: Add general low-level random bytes helper
    * ndp: Make route lifetime a #define
    * ndp: Use struct assignment in preference to memcpy() for IPv6 addresses
    * ndp: Split out helpers for sending specific NDP message types
    * ndp: Add ndp_send() helper
    * ndp: Remove redundant update to addr_seen
    * cppcheck: Don't check the system headers
    * linux_dep: Fix CLOSE_RANGE_UNSHARE availability handling
    * linux_dep: Move close_range() conditional handling to linux_dep.h
    * log: Only check for FALLOC_FL_COLLAPSE_RANGE availability at runtime
    * tap, tcp, util: Add some missing SOCK_CLOEXEC flags
    * passt: Use NOLINT clang-tidy block instead of NOLINTNEXTLINE
    * util: Define small and big thresholds for socket buffers as unsigned long long
    * tap: Cast TAP_BUF_BYTES - ETH_MAX_MTU to ssize_t, not TAP_BUF_BYTES
    * dhcpv6: Turn some option headers pointers to const
    * dhcpv6: Use for loop instead of goto to avoid false positive cppcheck warning
    * tcp: unify payload and flags l2 frames array
    * test: Improve test for NDP assigned prefix
    * test: Don't require 64-bit prefixes in perf tests
    * test: Make nstool hold robust against interruptions to control clients
    * test: Rename propagating signal handler
    * util: Work around cppcheck bug 6936
    * udp: Don't dereference uflow before NULL check in udp_reply_sock_handler()
    * ndp: Use const pointer for ndp_ns packet
    * linux_dep: Generalise tcp_info.h to handling Linux extension compatibility
    * fwd: Squash different-signedness comparison warning
    * util: Remove unused ffsl() function
    * clang: Add rudimentary clangd configuration
    * Makefile: Don't attempt to auto-detect stack size
    * Makefile: Use -DARCH for qrap only
    * seccomp: Simplify handling of AUDIT_ARCH
    * Makefile: Move NETNS_RUN_DIR definition to C code
    * netlink: RTA_PAYLOAD() returns int, not size_t
    * flow: Correct type of flowside_at_sidx()
    * arch: Avoid explicit access to 'environ'
    * clang: Move clang-tidy configuration from Makefile to .clang-tidy
    * Makefile: Simplify exclusion of qrap from static checks
    * clang: Add .clang-format file
    * test: Adjust misplaced sleeps in two_guests code
    * tap: Explicitly cast TUNSETIFF to fix build warning with musl on ppc64le
    * tcp: Fix build against musl, __sum16 comes from linux/types.h

++++ python-tornado6:

  - Update to 6.4.2:
    + Security Improvements:
    * Parsing of the cookie header is now much more efficient. The older
    algorithm sometimes had quadratic performance which allowed for a
    denial-of-service attack in which the server would spend excessive
    CPU time parsing cookies and block the event loop.
    (CVE-2024-52804, bsc#1233668)

++++ shared-mime-info:

  - Uninstall silently if update-mime-database is not present
    (bsc#1231463).

++++ ucode-amd:

  - Update to version 20241125 (git commit 508d770ee6f3):
    * ice: update ice DDP wireless_edge package to 1.3.20.0
    * ice: update ice DDP comms package to 1.3.52.0
    * ice: update ice DDP package to ice-1.3.41.0
    * amdgpu: update DMCUB to v9.0.10.0 for DCN314
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351

------------------------------------------------------------------
------------------  2024-11-24  -  Nov 24 2024  -------------------
------------------------------------------------------------------

++++ alsa:

  - Fix header inclusions for implicit dependnecies (bsc#1233682)
    0002-configure-Make-sequencer-dependent-on-rawmidi.patch
    0003-seq-include-UMP-headers.patch

------------------------------------------------------------------
------------------  2024-11-23  -  Nov 23 2024  -------------------
------------------------------------------------------------------

++++ setroubleshoot-plugins:

  - add 9e54f6a661330070ad25a0e86f197b3530bfc5c7.patch: fixes
    build with python 3.13+

------------------------------------------------------------------
------------------  2024-11-22  -  Nov 22 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.3.0
  - -> https://docs.mesa3d.org/relnotes/24.3.0

++++ Mesa-drivers:

  - Update to release 24.3.0
  - -> https://docs.mesa3d.org/relnotes/24.3.0

++++ gobject-introspection:

  - Add python3-setuptools Requires: needed for python 3.13 which
    dropped distutils; setuptools now provides it.

++++ kdump:

  - upgrade to version 2.0.12
    * fadump: pass additional parameters for capture kernel (jsc#PED-9889)

++++ kernel-default:

  - SLE16: supported.conf: mark all new modules as unsupported
  - commit 56358e9
  - SLE16: supported.conf: fix tabs using sort_supported.rb
    No content change
  - commit c2a9039

++++ kernel-firmware-all:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-amdgpu:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-ath10k:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-ath11k:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-ath12k:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-atheros:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-bluetooth:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-bnx2:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-brcm:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-chelsio:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-dpaa2:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-i915:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-intel:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-iwlwifi:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-liquidio:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-marvell:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-media:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-mediatek:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-mellanox:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-mwifiex:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-network:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-nfp:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-nvidia:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-platform:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-prestera:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-qcom:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-qlogic:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-radeon:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-realtek:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-serial:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-sound:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-ti:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-ueagle:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-firmware-usb-network:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

++++ kernel-rt:

  - SLE16: supported.conf: mark all new modules as unsupported
  - commit 56358e9
  - SLE16: supported.conf: fix tabs using sort_supported.rb
    No content change
  - commit c2a9039

++++ libpwquality:

  - Drop python 2.x support (it's been 4 years).
  - Add python3-setuptools BuildRequires which is needed for
    distutils.

++++ libsoup:

  - Update to version 3.6.1:
    + Fix `soup_uri_copy()` reading port as a long instead of an int
    + Fix possible NULL deref in `soup_uri_decode_data_uri()`
    + Fix possible overflow in `SoupContentSniffer`
    + Fix assertion in `soup_uri_decode_data_uri()` on URLs with a
    path starting with `//`
    + headers: Be more robust against invalid input when parsing
    params
    + websocket: Fix possibility of being stuck in a read loop
  - Drop patches fixed upstream:
    + 6adc0e3e.patch
    + 29b96fab.patch
    + a35222dd.patch
    + 4c9e75c6.patch

++++ python-setuptools:

  - remove duplicated "uses_network" skip

++++ ucode-amd:

  - Update to version 20241121 (git commit 48bb90cceb88):
    * linux-firmware: Update AMD cpu microcode
    * xe: Update GUC to v70.36.0 for BMG, LNL
    * i915: Update GUC to v70.36.0 for ADL-P, DG1, DG2, MTL, TGL

------------------------------------------------------------------
------------------  2024-11-21  -  Nov 21 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.3.0~rc2
  - -> https://www.phoronix.com/news/Mesa-24.3-rc2
  - Update to release 24.3.0~rc1
  - -> https://www.phoronix.com/news/Mesa-24.3-rc1-Released
  - refreshed patches:
    * n_drirc-disable-rgb10-for-chromium-on-amd.patch
    * python36-buildfix1.patch
    * python36-buildfix2.patch
    * tlsdesc_test.patch
    * u_mesa-CVE-2023-45913.patch
    * u_mesa-CVE-2023-45919.patch
    * u_mesa-CVE-2023-45922.patch
    * u_dep_xcb.patch
  - drop no longer supported options:
    * -Ddri3=enabled
    * -Ddri-search-path=%{_libdir}/dri
  - new files added in this update currently packaged as part of
    Mesa-dri:
    * %{_libdir}/gbm/dri_gbm.so

++++ Mesa-drivers:

  - Update to release 24.3.0~rc2
  - -> https://www.phoronix.com/news/Mesa-24.3-rc2
  - Update to release 24.3.0~rc1
  - -> https://www.phoronix.com/news/Mesa-24.3-rc1-Released
  - refreshed patches:
    * n_drirc-disable-rgb10-for-chromium-on-amd.patch
    * python36-buildfix1.patch
    * python36-buildfix2.patch
    * tlsdesc_test.patch
    * u_mesa-CVE-2023-45913.patch
    * u_mesa-CVE-2023-45919.patch
    * u_mesa-CVE-2023-45922.patch
    * u_dep_xcb.patch
  - drop no longer supported options:
    * -Ddri3=enabled
    * -Ddri-search-path=%{_libdir}/dri
  - new files added in this update currently packaged as part of
    Mesa-dri:
    * %{_libdir}/gbm/dri_gbm.so

++++ python-kiwi:

  - Bump version: 10.1.18 → 10.2.0
  - Add selinux test build to TW
    Also update derived docker integration test to latest Leap

++++ multipath-tools:

  - Update to version 0.11.0~1+118+suse.4a51b1a
    See NEWS.md for details about upstream changes in 0.11.0.
    * Pre-release of upstream 0.11.0
    * Rework of the path checking algorithm to reduce wait time and improve
    performance
    * Modified the systemd unit `multipathd.service` such that multipathd will now
    restart after a failure or crash (gh#opensvc/multipath-tools#100)
    * multipathd: move systemd watchdog handling into daemon (bsc#1232227)
    * libmultipath: dm_get_maps(): don't bail out for single-map failures
    (bsc#1233588, gh#opensvc/multipath-tools#102)
    * libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL
    * multipathd: fix deferred_failback_tick for reload removes

++++ opensuse-migration-tool:

  - Initial version from Hackweek

++++ python-setuptools:

  - Skip over the tests which require network.
  - Don't use pytest-xdist, it breaks test suite.
  - update to 75.6.0:
    * Preserve original PKG-INFO into METADATA when creating wheel
    (instead of calling wheel.metadata.pkginfo_to_metadata). This
    helps to be more compliant with the flow specified in PEP
    517.
    * Changed the WindowsSdkVersion, FrameworkVersion32 and
    FrameworkVersion64 properties of setuptools.msvc.PlatformInfo
    to return an empty tuple instead of None as a fallthrough
    case --  by :user:`Avasam`

------------------------------------------------------------------
------------------  2024-11-20  -  Nov 20 2024  -------------------
------------------------------------------------------------------

++++ avahi:

  - Add avahi-CVE-2024-52616.patch:
    Backporting 1dade81c from upstream: Properly randomize query id
    of DNS packets.
    (CVE-2024-52616, bsc#1233420)

++++ docker:

  - Add docker-integration-tests-devel subpackage for building and running the
    upstream Docker integration tests on machines to test that Docker works
    properly. Users should not install this package.
  - docker-rpmlintrc updated to include allow-list for all of the integration
    tests package, since it contains a bunch of stuff that wouldn't normally be
    allowed.

++++ python-kiwi:

  - kiwi/schema: Fix allowed value type for ISO publisher and application ID
    According to the spec, this should be constrained to 128 characters
    but also allow quite a few other special characters (as well as spaces).
    We didn't allow spaces in application ID, but allowed too much for Publisher.
    Now we set up both correctly.

++++ kernel-default:

  - SLE16: Update to v6.12
    Previous base was v6.12-rc7
  - commit 6f63baf
  - SLE16: s390x: update configs
  - commit 179d85e

++++ kernel-firmware-all:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-amdgpu:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-ath10k:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-ath11k:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-ath12k:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-atheros:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-bluetooth:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-bnx2:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-brcm:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-chelsio:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-dpaa2:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-i915:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-intel:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-iwlwifi:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-liquidio:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-marvell:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-media:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-mediatek:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-mellanox:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-mwifiex:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-network:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-nfp:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-nvidia:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-platform:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-prestera:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-qcom:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-qlogic:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-radeon:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-realtek:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-serial:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-sound:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-ti:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-ueagle:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-firmware-usb-network:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

++++ kernel-rt:

  - SLE16: Update to v6.12
    Previous base was v6.12-rc7
  - commit 6f63baf
  - SLE16: s390x: update configs
  - commit 179d85e

++++ gpgme:

  - Move the gpg python bindings out of the egg directory.

++++ python-PyJWT:

  - Update to version 2.10.0
    * chore: use sequence for typing rather than list
    * Add support for Python 3.13
    * [pre-commit.ci] pre-commit autoupdate
    * Add an RTD config file to resolve RTD build failures
    * docs: Update iat exception docs
    * Remove algorithm requirement for JWT API
    * [pre-commit.ci] pre-commit autoupdate
    * Create SECURITY.md
    * docs fix: decode_complete scope and algorithms
    * fix doctest for docs/usage.rst
    * fix test_utils.py not to xfail
    * Correct jwt.decode audience param doc expression
    * Add PS256 encoding and decoding usage
    * Add API docs for PyJWK
    * Refactor project configuration files from setup.cfg to pyproject.toml PEP-518
    * Add JWK support to JWT encode
    * Update pre-commit hooks to lint pyproject.toml
    * Add EdDSA algorithm encoding/decoding usage
    * Ruff linter and formatter changes
    * Validate sub and jti claims for the token
    * Add ES256 usage
    * Encode EC keys with a fixed bit length
    * [pre-commit.ci] pre-commit autoupdate
    * Drop support for Python 3.8
    * Prepare 2.10.0 release
    * Bump codecov/codecov-action from 4 to 5
    * [pre-commit.ci] pre-commit autoupdate

++++ python-psutil:

  - update to 6.1.0:
    * 2366_, [Windows]: drastically speedup `process_iter()`_. We
    now determine process unique identity by using process "fast"
    create time method. This will considerably speedup those apps
    which use `process_iter()`_ only once, e.g. to look for a
    process with a certain name.
    * 2446_: use pytest instead of unittest.
    * 2448_: add make install-sysdeps target to install the
    necessary system dependencies (python-dev, gcc, etc.) on all
    supported UNIX flavors.
    * 2449_: add make install-pydeps-test and make install-pydeps-
    dev targets. They can be used to install dependencies meant
    for running tests and for local development. They can also be
    installed via pip install .[test] and pip install .[dev].
    * 2456_: allow to run tests via python3 -m psutil.tests even if
    pytest module is not installed. This is useful for production
    environments that don't have pytest installed, but still want
    to be able to test psutil installation.
    * 2427_: psutil (segfault) on import in the free-threaded (no
    GIL) version of Python 3.13.  (patch by Sam Gross)
    * 2455_, [Linux]: IndexError may occur when reading
    /proc/pid/stat and field 40 (blkio_ticks) is missing.
    * 2457_, [AIX]: significantly improve the speed of
    `Process.open_files()`_ for some edge cases.
    * 2460_, [OpenBSD]: `Process.num_fds()`_ and
    `Process.open_files()`_ may fail with `NoSuchProcess`_ for
    PID 0. Instead, we now return "null" values (0 and []
    respectively).
  - drop skip_failing_tests.patch: obsolete

++++ python-rich:

  - update to 13.9.4:
    * Optimizations to cell_len which may speed up Rich / Textual
    output https://github.com/Textualize/rich/pull/3546
  - update to 13.9.3:
    * Fix a broken regex that resulted in the slow path being
    chosen for some operations. This fix should result in notable
    speedups for some operations, such as wrapping text.
    * Fixed broken regex that may have resulted in poor
    performance. https://github.com/Textualize/rich/pull/3535
  - update to 13.9.2:
    * A hotfix for highlighting in the table, and a fix for
    `Segment.split_cells`
    * Fixed `Table` columns not highlighting when added by
    `add_row` https://github.com/Textualize/rich/issues/3517
    * Fixed an issue with Segment.split_cells reported in Textual
    https://github.com/Textualize/textual/issues/5090
  - update to 13.9.1:
    * Fixed typing_extensions dependency
  - update to 13.9.0:
    * Dropped support for Python3.7
    * Rich will display tracebacks with finely grained error
    locations on python 3.11+
    * Fixed issue with Segment._split_cells
    * Fix auto detection of terminal size on Windows
    * `Text.style` now respected in Panel title/subtitle
  - update to 13.8.1:
    * Added support for Python 3.13
    * Fixed infinite loop when appending Text to same instance
  - update to 13.8.0:
    * Fixed `Table` rendering of box elements so "footer" elements
    truly appear at bottom of table, "mid" elements in main table
    body.
    * Fixed styles in Panel when Text objects are used for title
    * Fix pretty repr for `collections.deque`
    * Thread used in progress.track will exit if an exception
    occurs in a generator
    * Progress track thread is now a daemon thread
    * Fixed cached hash preservation upon clearing meta and links
    * Fixed overriding the `background_color` of `Syntax` not
    including padding
    * Fixed pretty printing of dataclasses with a default repr in
    Python 3.13
    * Fixed selective enabling of highlighting when disabled in the
    `Console`
    * Fixed BrokenPipeError writing an error message
    * Fixed superfluous space above Markdown tables
    * Fixed issue with record and capture interaction
    * Fixed control codes breaking in `append_tokens`
    * Fixed exception pretty printing a dataclass with missing
    * `RichHandler` errors and warnings will now use different
    colors (red and yellow)
    * Removed the empty line printed in jupyter while using
    `Progress`
    * Running tests in environment with `FORCE_COLOR` or `NO_COLOR`
    environment variables
    * ansi decoder will now strip problematic private escape
    sequences
    * Tree's ASCII_GUIDES and TREE_GUIDES constants promoted to
    class attributes
    * Adds a `case_sensitive` parameter to `prompt.Prompt`. This
    determines if the response is treated as case-sensitive.
    * Added `Console.on_broken_pipe`

++++ python-setuptools:

  - update to 75.5.0:
    * Removed support for
    SETUPTOOLS_DANGEROUSLY_SKIP_PYPROJECT_VALIDATION, as it is
    deemed prone to errors.
    * Added support for the environment variable
    SETUPTOOLS_DANGEROUSLY_SKIP_PYPROJECT_VALIDATION=true,
    allowing users to bypass the validation of pyproject.toml.
    This option should be used only as a last resort when
    resolving dependency issues, as it may lead to improper
    functioning. Users who enable this setting are responsible
    for ensuring that pyproject.toml complies with setuptools
    requirements. (#4611)  Attention! This environment variable
    was removed in a later version of setuptools.
    * Require Python 3.9 or later. (#4718)
    * Remove dependency on importlib_resources and the vendored
    copy of the library. Instead, setuptools consistently rely on
    stdlib's importlib.resources (available on Python 3.9+).
    (#4718)
    * Setuptools' bdist_wheel implementation no longer produces
    wheels with the m SOABI flag (pymalloc-related). This flag
    was removed on Python 3.8+ (see :obj:`sys.abiflags`). (#4718)
    * Updated vendored packaging version to 24.2. (#4740)
    * Merge with pypa/distutils@251797602, including fix for
    dirutil.mkpath handling in pypa/distutils#304.
    * Allowed using dict as an ordered type in
    setuptools.dist.check_requirements -- by :user:`Avasam`
    * Ensured methods in setuptools.modified preferably raise a
    consistent distutils.errors.DistutilsError type (except in
    the deprecated use case of SETUPTOOLS_USE_DISTUTILS=stdlib)
  - - by :user:`Avasam`
    * Fix the ABI tag when building a wheel using the debug build
    of Python 3.13 on Windows. Previously, the ABI tag was
    missing the "d" flag.
    * Fix clashes for optional-dependencies in pyproject.toml and
    extra_requires in setup.cfg/setup.py. As per PEP 621,
    optional-dependencies have to be honoured and dynamic
    behaviour is not allowed.
    * #4560
    * Made errors when parsing Distribution data more explicit
    about the expected type (tuple[str, ...] | list[str]) -- by
    :user:`Avasam`
    * Fix a TypeError when a Distribution's old included attribute
    was a tuple -- by :user:`Avasam`
    * Add workaround for bdist_wheel --dist-info-dir errors when
    customisation does not inherit from setuptools.
    * Re-use pre-existing .dist-info dir when creating wheels via
    the build backend APIs (PEP 517) and the metadata_directory
    argument is passed -- by :user:`pelson`.
    * Changed egg_info command to avoid adding an empty .egg-info
    directory while iterating over entry-points. This avoids
    triggering integration problems with
    importlib.metadata/importlib_metadata (reference:
    pypa/pyproject-hooks#206).
    * Deprecated bdist_wheel.universal configuration.
    * Removed reference to upload_docs module in entry points.
    * Declare also the dependencies used by distutils (adds
    jaraco.collections).
    * Removed upload_docs command.
    * Merge with pypa/distutils@7283751. Removed the register and
    upload commands and the config module that backs them
    (pypa/distutils#294). Removed the borland compiler. Replaced
    vendored dependencies with natural dependencies. Cygwin C
    compiler now gets compilers from sysconfig
    (pypa/distutils#296).
    * Fix cross-platform compilation using
    distutils._msvccompiler.MSVCCompiler -- by :user:`saschanaz`
    and :user:`Avasam`
    * Fixed TypeError in sdist filelist processing by adding
    support for pathlib Paths for the build_base.
    * Removed degraded and deprecated test_integration
    (easy_install) from the test suite.
    * Fixed TypeError in msvc.EnvironmentInfo.return_env when no
    runtime redistributables are installed.
    * Added support for defining ext-modules via pyproject.toml
    (EXPERIMENTAL, may change in future releases).
    * Merge with pypa/distutils@3dcdf8567, removing the duplicate
    vendored copy of packaging.
    * Restored setuptools.msvc.Environmentinfo as it is used
    externally.
    * Changed the type of error raised by
    setuptools.command.easy_install.CommandSpec.from_param on
    unsupported argument from AttributeError to TypeError -- by
    :user:`Avasam`
    * Added detection of ARM64 variant of MSVC -- by
    :user:`saschanaz`
    * Made setuptools.package_index.Credential a typing.NamedTuple
  - - by :user:`Avasam`
    * Reraise error from setuptools.command.easy_install.auto_chmod
    instead of nonsensical TypeError: 'Exception' object is not
    subscriptable -- by :user:`Avasam`
    * Fully typed all collection attributes in pkg_resources -- by
    :user:`Avasam`
    * Automatically exclude .tox|.nox|.venv directories from sdist.
    * Removed the monkeypatching of distutils._msvccompiler. Now
    all compiler logic is consolidated in distutils.
    * Synced with pypa/distutils@58fe058e4, including consolidating
    Visual Studio 2017 support (#4600, pypa/distutils#289),
    removal of deprecated legacy MSVC compiler modules
    (pypa/distutils#287), suppressing of errors when the home
    directory is missing (pypa/distutils#278), removal of wininst
    binaries (pypa/distutils#282).
    * #4592
    * Remove abc.ABCMeta metaclass from abstract classes.
    pypa/setuptools#4503 had an unintended consequence of causing
    potential TypeError: metaclass conflict: the metaclass of a
    derived class must be a (non-strict) subclass of the
    metaclasses of all its bases -- by :user:`Avasam`
    * Mark abstract base classes and methods with abc.ABC and
    abc.abstractmethod -- by :user:`Avasam`
    * Changed the order of type checks in
    setuptools.command.easy_install.CommandSpec.from_param to
    support any collections.abc.Iterable of str param -- by
    :user:`Avasam`
    * Prevent an error in bdist_wheel if compression is set to a
    str (even if valid) after finalizing options but before
    running the command. -- by :user:`Avasam`
    * Raises an exception when py_limited_api is used in a build
    with Py_GIL_DISABLED. This is currently not supported
    (python/cpython#111506).
    * Synced with pypa/distutils@30b7331 including fix for modified
    check on empty sources (pypa/distutils#284).
    * setuptools is replacing the usages of :pypi:`ordered_set`
    with simple instances of dict[Hashable, None]. This is done
    to remove the extra dependency and it is possible because
    since Python 3.7, dict maintain insertion order.
    * #4534, #4546, #4554, #4559, #4565
    * Merged with pypa/distutils@b7ee725f3 including: Support for
    Pathlike objects in data files and extensions
    (pypa/distutils#272, pypa/distutils#237), native support for
    C++ compilers (pypa/distuils#228) and removed unused
    get_msvcr() (pypa/distutils#274).

++++ ucode-amd:

  - Update to version 20241119 (git commit 60cdfe1831e8):
    * iwlwifi: add Bz-gf FW for core91-69 release
  - Update aliases from 6.12

------------------------------------------------------------------
------------------  2024-11-19  -  Nov 19 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.2.7
  - -> https://docs.mesa3d.org/relnotes/24.2.7
  - supersedes 0001-dril-Fixup-order-of-pixel-formats-in-drilConfigs.patch

++++ Mesa-drivers:

  - Update to release 24.2.7
  - -> https://docs.mesa3d.org/relnotes/24.2.7
  - supersedes 0001-dril-Fixup-order-of-pixel-formats-in-drilConfigs.patch

++++ kernel-default:

  - SLE16: arm64: update configs
  - commit e27a64b
  - SLE16: ppc64le: update configs
  - commit ac2a2eb

++++ kernel-rt:

  - SLE16: arm64: update configs
  - commit e27a64b
  - SLE16: ppc64le: update configs
  - commit ac2a2eb

++++ llvm19:

  - Update to version 19.1.4.
    * This release contains bug-fixes for the LLVM 19.1.0 release.
    This release is API and ABI compatible with 19.1.0.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ python-blinker:

  - update to 1.9.0:
    * Drop support for Python 3.8. :pr:`175`
    * Remove previously deprecated __version__, receiver_connected,
    Signal.temporarily_connected_to and WeakNamespace. :pr:`172`
    * Skip weakref signal cleanup if the interpreter is shutting
    down. :issue:`173`

++++ python-jsonpointer:

  - update to 3.0.0:
    * Add support for python 3.12
    * drop python 2.7 support
    * CI fixes

------------------------------------------------------------------
------------------  2024-11-18  -  Nov 18 2024  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update to 10.3.8 (bsc#1233333)
    + Fix the package requirements for cloud-regionsrv-client
    + Follow changes to suseconnect error reporting from stdout to stderr

++++ kernel-default:

  - SLE16: x86_64: update configs
  - commit d3cf7cc
  - kernel-binary: Enable livepatch package only when livepatch is enabled
    Otherwise the filelist may be empty failing the build (bsc#1218644).
  - commit f730eec

++++ kernel-rt:

  - SLE16: x86_64: update configs
  - commit d3cf7cc
  - kernel-binary: Enable livepatch package only when livepatch is enabled
    Otherwise the filelist may be empty failing the build (bsc#1218644).
  - commit f730eec

++++ gpgme:

  - Fix file list on Leap 15

++++ qemu:

  - Build and bug fixes:
    * edk2: update submodule to edk2-stable202408.01
    * Revert "hw/audio/hda: fix memory leak on audio setup" (bsc#1232728)

++++ strace:

  - Update to strace 6.12
    * Implemented decoding of EPIOCGPARAMS and EPIOCSPARAMS ioctl commands.
    * Implemented decoding of NS_GET_MNTNS_ID, NS_GET_PID_FROM_PIDNS,
    NS_GET_TGID_FROM_PIDNS, NS_GET_PID_IN_PIDNS, NS_GET_TGID_IN_PIDNS,
    NS_MNT_GET_INFO, NS_MNT_GET_NEXT, and NS_MNT_GET_PREV ioctl commands.
    * Implemented decoding of FRA_DSCP netlink attribute.
    * Implemented decoding of IORING_REGISTER_CLOCK and
    IORING_REGISTER_CLONE_BUFFERS opcodes of io_uring_register syscall.
    * Updated decoding of struct landlock_ruleset_attr.
    * Updated lists of AUDIT_*, ETHTOOL_*, F_*, IORING_*, LSM_*, MAP_*, MSG_*,
    NT_*, SCHED_*, SCM_*, SO_*, and V4L2_* constants.
    * Updated lists of ioctl commands from Linux 6.12.
    * Fix the syscall name printed by strace when PTRACE_GET_SYSCALL_INFO
    is in use and a syscall is restarted by a just attached tracee using
    restart_syscall mechanism.

------------------------------------------------------------------
------------------  2024-11-17  -  Nov 17 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix setup of kiwi environment variables
    Some kiwi env vars are initialized with an empty value
    and not overwritten if another value is provided. For
    the selected variables an empty value setting is not
    allowed because the schema also enforces the value to
    be set at least once. In addition a helpful option
    named --print-kiwi-env was added to the 'image info'
    command which allows to print the environment variables
    and their values.

++++ util-linux-systemd:

  - Skip aarch64 decode path for rest of the architectures
    (bsc#1229476, util-linux-lscpu-skip-aarch64-decode.patch).
  - agetty: Prevent login cursor escape (bsc#1194818,
    util-linux-agetty-prevent-cursor-escape.patch).
  - Document unexpected side effects of lazy destruction
    (bsc#1159034, util-linux-umount-losetup-lazy-destruction.patch,
    util-linux-umount-losetup-lazy-destruction-generated.patch).

++++ util-linux:

  - Skip aarch64 decode path for rest of the architectures
    (bsc#1229476, util-linux-lscpu-skip-aarch64-decode.patch).
  - agetty: Prevent login cursor escape (bsc#1194818,
    util-linux-agetty-prevent-cursor-escape.patch).
  - Document unexpected side effects of lazy destruction
    (bsc#1159034, util-linux-umount-losetup-lazy-destruction.patch,
    util-linux-umount-losetup-lazy-destruction-generated.patch).

------------------------------------------------------------------
------------------  2024-11-16  -  Nov 16 2024  -------------------
------------------------------------------------------------------

++++ llvm19:

  - Apply clang-shlib-symbol-versioning.patch to add symbol versions
    to libclang-cpp.so similar to libLLVM.so. This is required when
    multiple versions of the library are loaded into the same
    process. (boo#1219405, boo#1221183, boo#1233220)

++++ runc:

  - Update to runc v1.2.2. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.2>.

------------------------------------------------------------------
------------------  2024-11-15  -  Nov 15 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - SLE16: fix conflicts in the existing patches
  - commit d49a172
  - SLE16: set v6.12-rc7 as the base kernel
  - commit bebe581
  - SLE16: Add branch maintainers
  - commit 953623a
  - SLE16: delete old kABI values
  - commit ae7da2f
  - SLE16: Remove patches not needed in v6.12
    Disable all out-of-tree and kABI padding patches
    Remove all kABI consistency patches
    Base SUSE-2024 commit: 211ffe41382b ("Merge branch 'SLE15-SP6' into SUSE-2024")
  - commit cd4d89d
  - crypto: aes-gcm-p10 - Use the correct bit to test for P10
    (bsc#1232704).
  - commit b7937ab

++++ kernel-rt:

  - SLE16: fix conflicts in the existing patches
  - commit d49a172
  - SLE16: set v6.12-rc7 as the base kernel
  - commit bebe581
  - SLE16: Add branch maintainers
  - commit 953623a
  - SLE16: delete old kABI values
  - commit ae7da2f
  - SLE16: Remove patches not needed in v6.12
    Disable all out-of-tree and kABI padding patches
    Remove all kABI consistency patches
    Base SUSE-2024 commit: 211ffe41382b ("Merge branch 'SLE15-SP6' into SUSE-2024")
  - commit cd4d89d
  - crypto: aes-gcm-p10 - Use the correct bit to test for P10
    (bsc#1232704).
  - commit b7937ab

++++ alsa:

  - Fix incorrect versioned symbol for snd_seq_has_queue_tempo_base:
    0001-src-Versions.in.in-Update-_tempo_base-name.patch

++++ python313-core:

  - Allow building with default LLVM version 19: just replace the
    hard-coded LLVM_version in the scripts.

++++ libxml2:

  - Update to 2.13.0:
    * Major changes:
  - Most of the core code should now report malloc failures reliably. Some
    API functions were extended with versions that report malloc failures.
  - New API functions for error handling were added:
    + xmlCtxtSetErrorHandler
    + xmlXPathSetErrorHandler
    + xmlXIncludeSetErrorHandler
  - This makes it possible to register per-context error handlers without
    resorting to global handlers.
  - A few error messages were improved and consolidated. Please update
    downstream test suites accordingly.
  - A new parser option XML_PARSE_NO_XXE can be used to disable loading
    of external entities or DTDs. This is most useful in connection with
    XML_PARSE_NOENT.
  - Support for HTTP POST was removed.
  - Support for zlib, liblzma and HTTP is now disabled by default and has
    to be enabled by passing --with-zlib, --with-lzma or --with-http to
    configure. In legacy mode (--with-legacy) these options are enabled
    by default as before.
  - Support for FTP will be removed in the next release.
  - Support for the range and point extensions of the xpointer() scheme
    will be removed in the next release. The rest of the XPointer
    implementation won't be affected. The xpointer() scheme will behave
    like the xpath1() scheme.
  - Several more legacy symbols were deprecated. Users of the old "SAX1"
    API functions are encouraged to upgrade to the new "SAX2" API,
    available since version 2.6.0 from 2003.
    * Some deprecated global variables were made const:
  - htmlDefaultSAXHandler
  - oldXMLWDcompatibility
  - xmlDefaultSAXHandler
  - xmlDefaultSAXLocator
  - xmlParserDebugEntities
    * Deprecations and removals:
  - threads: Deprecate remaining ThrDef functions
  - unicode: Deprecate most xmlUCSIs* functions
  - memory: Remove memory debugging
  - tree: Deprecate xmlRegisterNodeDefault
  - tree: Deprecate xmlSetCompressMode
  - html: Deprecate htmlHandleOmittedElem
  - valid: Deprecate internal validation functions
  - valid: Deprecate old DTD serialization API
  - nanohttp: Deprecate public API
  - Remove VMS support
  - Remove Trio
    * Bug fixes:
  - parser: Fix base URI of internal parameter entities
  - tree: Handle predefined entities in xmlBufGetEntityRefContent
  - schemas: Allow unlimited length decimals, integers etc.
  - reader: Fix preservation of attributes
  - parser: Always decode entities in namespace URIs
  - relaxng: Fix tree corruption in xmlRelaxNGParseNameClass
  - schemas: Fix ADD_ANNOTATION
  - tree: Fix tree iteration in xmlDOMWrapRemoveNode
  - tree: Declare namespace on clone in xmlDOMWrapCloneNode
  - tree: Fix xmlAddSibling with last sibling
  - tree: Fix xmlDocSetRootElement with multiple top-level elements
  - catalog: Fetch XML catalog before dumping
  - html: Don't close fd in htmlCtxtReadFd
    * Improvements:
  - parser: Fix "Truncated multi-byte sequence" error
  - Add missing _cplusplus processing clause
  - parser: Rework handling of undeclared entities
  - SAX2: Warn if URI resolution failed
  - parser: Don't report error on invalid URI
  - xmllint: Clean up option handling
  - xmllint: Rework parsing
  - parser: Don't create undeclared entity refs in substitution mode
  - Make some globals const
  - reader: Make xmlTextReaderReadString non-recursive
  - reader: Rework xmlTextReaderRead{Inner,Outer}Xml
  - Remove redundant size check (Niels Dossche)
  - Remove redundant NULL check on cur
  - Remove always-false check old == cur
  - Remove redundant NULL check on cur
  - tree: Don't return empty localname in xmlSplitQName{2,3}
  - xinclude: Don't try to fix base of non-elements
  - tree: Don't coalesce text nodes in xmlAdd{Prev,Next}Sibling
  - SAX2: Optimize appending children
  - tree: Align xmlAddChild with other node insertion functions
  - html: Use binary search in htmlEntityValueLookup
  - io: Allocate output buffer with XML_BUFFER_ALLOC_IO
  - encoding: Don't shrink input too early in xmlCharEncOutput
  - tree: Tighten source doc check in xmlDOMWrapAdoptNode
  - tree: Check destParent->doc in xmlDOMWrapCloneNode
  - tree: Refactor text node updates
  - tree: Refactor node insertion
  - tree: Refactor element creation and parsing of attribute values
  - tree: Simplify xmlNodeGetContent, xmlBufGetNodeContent
  - buf: Don't use default buffer size for small strings
  - string: Fix xmlStrncatNew(NULL, "")
  - entities: Don't allow null name in xmlNewEntity
  - html: Fix quadratic behavior in htmlNodeDump
  - tree: Rewrite xmlSetTreeDoc
  - valid: Rework xmlAddID
  - tree: Remove unused node types
  - tree: Make namespace comparison more consistent
  - tree: Don't allow NULL name in xmlSetNsProp
  - tree: Rework xmlNodeListGetString
  - tree: Rework xmlTextMerge
  - tree: Rework xmlNodeSetName
  - tree: Simplify xmlAddChild with text parent
  - tree: Disallow setting content of entity reference nodes
  - tree: Rework xmlReconciliateNs
  - schemas: fix spurious warning about truncated snprintf output
  - xmlschemastypes: Remove unreachable if statement
  - relaxng: Remove useless if statement
  - tree: Check for integer overflow in xmlStringGetNodeList
  - http: Improve error message for HTTPS redirects
  - save: Move DTD serialization code to xmlsave.c
  - parser: Report fatal error if document entity couldn't be loaded
  - xpath: Fix return of empty node-set in xmlXPathNodeCollectAndTest
  - SAX2: Limit entity URI length to 2000 bytes
  - parser: Account for full size of non-well-formed entities
  - parser: Pop inputs if parsing DTD failed
  - parser: Fix quadratic behavior when copying entities
  - writer: Implement xmlTextWriterClose
  - parser: Avoid duplicate namespace errors
  - parser: Add XML_PARSE_NO_XXE parser option
  - parser: Make xmlParseContent more useful
  - error: Make xmlFormatError public
  - encoding: Check whether encoding handlers support input/output
  - SAX2: Enforce size limit in xmlSAX2Text with XML_PARSE_HUGE
  - parser: Lower maximum entity nesting depth
  - parser: Set depth limit to 2048 with XML_PARSE_HUGE
  - parser: Implement xmlCtxtSetOptions
  - parser: Always prefer option members over bitmask
  - parser: Don't modify SAX2 handler if XML_PARSE_SAX1 is set
  - parser: Rework parsing of attribute and entity values
  - save: Output U+FFFD replacement characters
  - parser: Simplify entity size accounting
  - parser: Avoid unwanted expansion of parameter entities
  - parser: Always copy content from entity to target
  - parser: Simplify control flow in xmlParseReference
  - parser: Remove xmlSetEntityReferenceFunc feature
  - parser: Push general entity input streams on the stack
  - parser: Move progressive flag into input struct
  - parser: Fix in-parameter-entity and in-external-dtd checks
  - xpath: Rewrite substring-before and substring-after
  - xinclude: Only set xml:base if necessary
  - xinclude: Allow empty nodesets
  - parser: Rework general entity parsing
  - io: Fix close error handling
  - io: Fix read/write error handling
  - io: More refactoring and unescaping fixes
  - io: Move some code from xmlIO.c to parserInternals.c
  - uri: Clean up special parsing modes
  - xinclude: Rework xml:base fixup
  - parser: Also set document properties when push parsing
  - include: Move non-generated parts from xmlversion.h.in
  - io: Remove support for HTTP POST
  - dict: Move local RNG state to global state
  - dict: Get random seed from system PRNG
  - io: Don't use "-" to read from stdin
  - io: Rework initialization
  - io: Consolidate error messages
  - xzlib: Fix harmless unsigned integer overflow
  - io: Always use unbuffered input
  - io: Fix detection of compressed streams
  - io: Pass error codes from xmlFileOpenReal to xmlNewInputFromFile
  - io: Rework default callbacks
  - error: Stop printing some errors by default
  - xpath: Don't free nodes of XSLT result value trees
  - valid: Fix handling of enumerations
  - parser: Allow recovery in xmlParseInNodeContext
  - encoding: Support ASCII in xmlLookupCharEncodingHandler
  - include: Remove useless 'const' from function arguments
  - Avoid EDG -Wignored-qualifiers warnings on wrong 'const *' to '* const'
    conversions (makise-homura)
  - Avoid EDG deprecation warnings for LCC compiler
  - Avoid EDG -Woverflow warnings on truncating conversions by manually
    truncating operand (makise-homura)
  - Avoid EDG -Wtype-limits warnings on unsigned comparisons with zero by
    conversion from unsigned int to int (makise-homura)
  - Avoid using no_sanitize attribute on EDG even if compiler shows as GCC
    * Build systems:
  - meson: convert boolean options to feature option
  - meson: Pass LIBXML_STATIC in dependency
  - meson: fix compilation with local binaries
  - meson: don't use dl dependency on old meson
  - meson: fix usage as a subproject
  - build: Remove --with-fexceptions configuration option
  - autotools: Remove --with-coverage configuration option
  - build: Disable HTTP support by default
  - Stop defining _REENTRANT
  - doc: Don't install example code
  - meson: Initial commit
  - build: Disable support for compression libraries by default
  - Set LIBXML2_FOUND if it has been properly configured
  - Makefile.am: omit $(top_builddir) from DEPS and LDADDS
    * Test suite
  - runtest: Work around broken EUC-JP support in musl iconv
  - runtest: Check for IBM-1141 encoding handler
  - fuzz: Add xmllint fuzzer
  - fuzz: Add fuzzer for XML reader API
  - fuzz: New tree API fuzzer
  - tests: Remove testOOM
  - Don't let gentest.py cast types to 'const somethingPtr' to avoid
  - Wignored-qualifiers
    * Rebase libxml2-make-XPATH_MAX_NODESET_LENGTH-configurable.patch

++++ libzypp:

  - The 20MB download limit must not apply to non-metadata files like
    package URLs provided via the CLI (bsc#1233393).
  - version 17.35.14 (35)

++++ python313:

  - Allow building with default LLVM version 19: just replace the
    hard-coded LLVM_version in the scripts.

++++ libxml2-python:

  - Update to 2.13.0:
    * Major changes:
  - Most of the core code should now report malloc failures reliably. Some
    API functions were extended with versions that report malloc failures.
  - New API functions for error handling were added:
    + xmlCtxtSetErrorHandler
    + xmlXPathSetErrorHandler
    + xmlXIncludeSetErrorHandler
  - This makes it possible to register per-context error handlers without
    resorting to global handlers.
  - A few error messages were improved and consolidated. Please update
    downstream test suites accordingly.
  - A new parser option XML_PARSE_NO_XXE can be used to disable loading
    of external entities or DTDs. This is most useful in connection with
    XML_PARSE_NOENT.
  - Support for HTTP POST was removed.
  - Support for zlib, liblzma and HTTP is now disabled by default and has
    to be enabled by passing --with-zlib, --with-lzma or --with-http to
    configure. In legacy mode (--with-legacy) these options are enabled
    by default as before.
  - Support for FTP will be removed in the next release.
  - Support for the range and point extensions of the xpointer() scheme
    will be removed in the next release. The rest of the XPointer
    implementation won't be affected. The xpointer() scheme will behave
    like the xpath1() scheme.
  - Several more legacy symbols were deprecated. Users of the old "SAX1"
    API functions are encouraged to upgrade to the new "SAX2" API,
    available since version 2.6.0 from 2003.
    * Some deprecated global variables were made const:
  - htmlDefaultSAXHandler
  - oldXMLWDcompatibility
  - xmlDefaultSAXHandler
  - xmlDefaultSAXLocator
  - xmlParserDebugEntities
    * Deprecations and removals:
  - threads: Deprecate remaining ThrDef functions
  - unicode: Deprecate most xmlUCSIs* functions
  - memory: Remove memory debugging
  - tree: Deprecate xmlRegisterNodeDefault
  - tree: Deprecate xmlSetCompressMode
  - html: Deprecate htmlHandleOmittedElem
  - valid: Deprecate internal validation functions
  - valid: Deprecate old DTD serialization API
  - nanohttp: Deprecate public API
  - Remove VMS support
  - Remove Trio
    * Bug fixes:
  - parser: Fix base URI of internal parameter entities
  - tree: Handle predefined entities in xmlBufGetEntityRefContent
  - schemas: Allow unlimited length decimals, integers etc.
  - reader: Fix preservation of attributes
  - parser: Always decode entities in namespace URIs
  - relaxng: Fix tree corruption in xmlRelaxNGParseNameClass
  - schemas: Fix ADD_ANNOTATION
  - tree: Fix tree iteration in xmlDOMWrapRemoveNode
  - tree: Declare namespace on clone in xmlDOMWrapCloneNode
  - tree: Fix xmlAddSibling with last sibling
  - tree: Fix xmlDocSetRootElement with multiple top-level elements
  - catalog: Fetch XML catalog before dumping
  - html: Don't close fd in htmlCtxtReadFd
    * Improvements:
  - parser: Fix "Truncated multi-byte sequence" error
  - Add missing _cplusplus processing clause
  - parser: Rework handling of undeclared entities
  - SAX2: Warn if URI resolution failed
  - parser: Don't report error on invalid URI
  - xmllint: Clean up option handling
  - xmllint: Rework parsing
  - parser: Don't create undeclared entity refs in substitution mode
  - Make some globals const
  - reader: Make xmlTextReaderReadString non-recursive
  - reader: Rework xmlTextReaderRead{Inner,Outer}Xml
  - Remove redundant size check (Niels Dossche)
  - Remove redundant NULL check on cur
  - Remove always-false check old == cur
  - Remove redundant NULL check on cur
  - tree: Don't return empty localname in xmlSplitQName{2,3}
  - xinclude: Don't try to fix base of non-elements
  - tree: Don't coalesce text nodes in xmlAdd{Prev,Next}Sibling
  - SAX2: Optimize appending children
  - tree: Align xmlAddChild with other node insertion functions
  - html: Use binary search in htmlEntityValueLookup
  - io: Allocate output buffer with XML_BUFFER_ALLOC_IO
  - encoding: Don't shrink input too early in xmlCharEncOutput
  - tree: Tighten source doc check in xmlDOMWrapAdoptNode
  - tree: Check destParent->doc in xmlDOMWrapCloneNode
  - tree: Refactor text node updates
  - tree: Refactor node insertion
  - tree: Refactor element creation and parsing of attribute values
  - tree: Simplify xmlNodeGetContent, xmlBufGetNodeContent
  - buf: Don't use default buffer size for small strings
  - string: Fix xmlStrncatNew(NULL, "")
  - entities: Don't allow null name in xmlNewEntity
  - html: Fix quadratic behavior in htmlNodeDump
  - tree: Rewrite xmlSetTreeDoc
  - valid: Rework xmlAddID
  - tree: Remove unused node types
  - tree: Make namespace comparison more consistent
  - tree: Don't allow NULL name in xmlSetNsProp
  - tree: Rework xmlNodeListGetString
  - tree: Rework xmlTextMerge
  - tree: Rework xmlNodeSetName
  - tree: Simplify xmlAddChild with text parent
  - tree: Disallow setting content of entity reference nodes
  - tree: Rework xmlReconciliateNs
  - schemas: fix spurious warning about truncated snprintf output
  - xmlschemastypes: Remove unreachable if statement
  - relaxng: Remove useless if statement
  - tree: Check for integer overflow in xmlStringGetNodeList
  - http: Improve error message for HTTPS redirects
  - save: Move DTD serialization code to xmlsave.c
  - parser: Report fatal error if document entity couldn't be loaded
  - xpath: Fix return of empty node-set in xmlXPathNodeCollectAndTest
  - SAX2: Limit entity URI length to 2000 bytes
  - parser: Account for full size of non-well-formed entities
  - parser: Pop inputs if parsing DTD failed
  - parser: Fix quadratic behavior when copying entities
  - writer: Implement xmlTextWriterClose
  - parser: Avoid duplicate namespace errors
  - parser: Add XML_PARSE_NO_XXE parser option
  - parser: Make xmlParseContent more useful
  - error: Make xmlFormatError public
  - encoding: Check whether encoding handlers support input/output
  - SAX2: Enforce size limit in xmlSAX2Text with XML_PARSE_HUGE
  - parser: Lower maximum entity nesting depth
  - parser: Set depth limit to 2048 with XML_PARSE_HUGE
  - parser: Implement xmlCtxtSetOptions
  - parser: Always prefer option members over bitmask
  - parser: Don't modify SAX2 handler if XML_PARSE_SAX1 is set
  - parser: Rework parsing of attribute and entity values
  - save: Output U+FFFD replacement characters
  - parser: Simplify entity size accounting
  - parser: Avoid unwanted expansion of parameter entities
  - parser: Always copy content from entity to target
  - parser: Simplify control flow in xmlParseReference
  - parser: Remove xmlSetEntityReferenceFunc feature
  - parser: Push general entity input streams on the stack
  - parser: Move progressive flag into input struct
  - parser: Fix in-parameter-entity and in-external-dtd checks
  - xpath: Rewrite substring-before and substring-after
  - xinclude: Only set xml:base if necessary
  - xinclude: Allow empty nodesets
  - parser: Rework general entity parsing
  - io: Fix close error handling
  - io: Fix read/write error handling
  - io: More refactoring and unescaping fixes
  - io: Move some code from xmlIO.c to parserInternals.c
  - uri: Clean up special parsing modes
  - xinclude: Rework xml:base fixup
  - parser: Also set document properties when push parsing
  - include: Move non-generated parts from xmlversion.h.in
  - io: Remove support for HTTP POST
  - dict: Move local RNG state to global state
  - dict: Get random seed from system PRNG
  - io: Don't use "-" to read from stdin
  - io: Rework initialization
  - io: Consolidate error messages
  - xzlib: Fix harmless unsigned integer overflow
  - io: Always use unbuffered input
  - io: Fix detection of compressed streams
  - io: Pass error codes from xmlFileOpenReal to xmlNewInputFromFile
  - io: Rework default callbacks
  - error: Stop printing some errors by default
  - xpath: Don't free nodes of XSLT result value trees
  - valid: Fix handling of enumerations
  - parser: Allow recovery in xmlParseInNodeContext
  - encoding: Support ASCII in xmlLookupCharEncodingHandler
  - include: Remove useless 'const' from function arguments
  - Avoid EDG -Wignored-qualifiers warnings on wrong 'const *' to '* const'
    conversions (makise-homura)
  - Avoid EDG deprecation warnings for LCC compiler
  - Avoid EDG -Woverflow warnings on truncating conversions by manually
    truncating operand (makise-homura)
  - Avoid EDG -Wtype-limits warnings on unsigned comparisons with zero by
    conversion from unsigned int to int (makise-homura)
  - Avoid using no_sanitize attribute on EDG even if compiler shows as GCC
    * Build systems:
  - meson: convert boolean options to feature option
  - meson: Pass LIBXML_STATIC in dependency
  - meson: fix compilation with local binaries
  - meson: don't use dl dependency on old meson
  - meson: fix usage as a subproject
  - build: Remove --with-fexceptions configuration option
  - autotools: Remove --with-coverage configuration option
  - build: Disable HTTP support by default
  - Stop defining _REENTRANT
  - doc: Don't install example code
  - meson: Initial commit
  - build: Disable support for compression libraries by default
  - Set LIBXML2_FOUND if it has been properly configured
  - Makefile.am: omit $(top_builddir) from DEPS and LDADDS
    * Test suite
  - runtest: Work around broken EUC-JP support in musl iconv
  - runtest: Check for IBM-1141 encoding handler
  - fuzz: Add xmllint fuzzer
  - fuzz: Add fuzzer for XML reader API
  - fuzz: New tree API fuzzer
  - tests: Remove testOOM
  - Don't let gentest.py cast types to 'const somethingPtr' to avoid
  - Wignored-qualifiers
    * Rebase libxml2-make-XPATH_MAX_NODESET_LENGTH-configurable.patch

------------------------------------------------------------------
------------------  2024-11-14  -  Nov 14 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Refresh patches.kabi/bpf-verifier-kABI-workarounds.patch (bsc#1233350)
    Correctly workaround kABI breakage that was introduced with fixes
    backported for bsc#1225903.
  - commit 52684a5
  - ASoC: SOF: ipc4-topology: Only handle dai_config with HW_PARAMS
    for ChainDMA (bsc#1233305).
  - commit 1b06409

++++ kernel-rt:

  - Refresh patches.kabi/bpf-verifier-kABI-workarounds.patch (bsc#1233350)
    Correctly workaround kABI breakage that was introduced with fixes
    backported for bsc#1225903.
  - commit 52684a5
  - ASoC: SOF: ipc4-topology: Only handle dai_config with HW_PARAMS
    for ChainDMA (bsc#1233305).
  - commit 1b06409

++++ python313-core:

  - Remove -IVendor/ from python-config boo#1231795
  - Require exact clang18 and llvm18, because apparently CPython is
    not ready for 19 yet (gh#python/cpython!125499).

++++ net-snmp:

  - Update to net-snmp-5.9.4 (bsc#1214364).
    add (rename):
    * net-snmp-5.9.4-add-lustre-fs-support.patch
    * net-snmp-5.9.4-add-netgroups-functionality.patch
    * net-snmp-5.9.4-fix-create-v3-user-outfile.patch
    * net-snmp-5.9.4-fixed-python2-bindings.patch
    * net-snmp-5.9.4-fix-Makefile.PL.patch
    * net-snmp-5.9.4-modern-rpm-api.patch
    * net-snmp-5.9.4-net-snmp-config-headercheck.patch
    * net-snmp-5.9.4-perl-tk-warning.patch
    * net-snmp-5.9.4-pie.patch
    * net-snmp-5.9.4-snmpstatus-suppress-output.patch
    * net-snmp-5.9.4-socket-path.patch
    * net-snmp-5.9.4-subagent-set-response.patch
    * net-snmp-5.9.4-suse-systemd-service-files.patch
    * net-snmp-5.9.4-testing-empty-arptable.patch
    delete (now part of v5.9.4):
    * net-snmp-5.9.3-disallow_SET_requests_with_NULL_varbind.patch
    * net-snmp-5.9.3-grep.patch
    delete (rename):
    * net-snmp-5.9.1-add-lustre-fs-support.patch
    * net-snmp-5.9.1-fix-Makefile.PL.patch
    * net-snmp-5.9.1-modern-rpm-api.patch
    * net-snmp-5.9.1-net-snmp-config-headercheck.patch
    * net-snmp-5.9.1-perl-tk-warning.patch
    * net-snmp-5.9.1-snmpstatus-suppress-output.patch
    * net-snmp-5.9.1-socket-path.patch
    * net-snmp-5.9.1-subagent-set-response.patch
    * net-snmp-5.9.1-suse-systemd-service-files.patch
    * net-snmp-5.9.1-testing-empty-arptable.patch
    * net-snmp-5.9.1-velocity-mib.patch
    * net-snmp-5.9.2-fix-create-v3-user-outfile.patch
    * net-snmp-5.9.2-pie.patch
    * net-snmp-5.9.3-fixed-python2-bindings.patch
  - Removing legacy MIBs used by Velocity Software (jira#PED-6416).
  - Re-add support for hostname netgroups that was removed accidentally and
    previously added with FATE#316305 (bsc#1207697).
    '@hostgroup' can be specified for multiple hosts
  - Hardening systemd services setting "ProtectHome=true" caused home directory
    size and allocation to be listed incorrectly (bsc#1206044).
    add (rename):
    * net-snmp-5.9.4-harden_snmpd.service.patch
    * net-snmp-5.9.4-harden_snmptrapd.service.patch
    delete (rename):
    * net-snmp-5.9.1-harden_snmpd.service.patch
    * net-snmp-5.9.1-harden_snmptrapd.service.patch
  - logrotate should use reload instead of restart (bsc#1232030)

++++ microos-tools:

  - Update to version 4.0+git6:
    * test: Check for AVC denials in the journal
    * test: More reliable output of combustion-validate
    * test: Remove workaround for boo#1230912
    * Label /sys before selinux-autorelabel units run (bsc#1232709)

++++ opensc:

  - Update to version 0.26.0
    Security
    * CVE-2024-45615: Usage of uninitialized values in libopensc#
    and pkcs15init (#3225).
    * CVE-2024-45616: Uninitialized values after incorrect check or
    usage of APDU response values in libopensc (#3225)
    * CVE-2024-45617: Uninitialized values after incorrect or missing
    checking return values of functions in libopensc (#3225)
    * CVE-2024-45618: Uninitialized values after incorrect or missing
    checking return values of functions in pkcs15init (#3225)
    * CVE-2024-45619: Incorrect handling length of buffers or files
    in libopensc (#3225)
    * CVE-2024-45620: Incorrect handling of the length of buffers or
    files in pkcs15init (#3225)
    * CVE-2024-8443: Heap buffer overflow in OpenPGP driver when
    generating key (#3219)
    General improvements
    * Fix reselection of DF after error in PKCS#15 layer (#3067)
    * Unify OpenSSL logging throughout code (#2922)
    * Extend the p11test to support kryoptic (#3141)
    * Fix for error in PCSC reconnection (#3150)
    * Fixed various issues reported by OSS-Fuzz and Coverity in
    drivers, PKCS#11 and PKCS#15 layer
    PKCS#15
    * Documentation for PKCS#15 profile files (#3132)
    minidriver
    * Support PinCacheAlwaysPrompt usable for PIV cards (#3167)
    pkcs11-tool
    * Show URI when listing token information (#3125) and objects
    * Do not limit size of objects to 5000 bytes (#3174)
    * Add support for AES CMAC (#3184)
    * Add support for AES GCM encryption (#3195)
    * Add support for RSA OAEP encryption (#3175)
    * Add support for HKDF (#3193)
    * Implement better support for wrapping and unwrapping (#3198)
    * Add support for EdDSA sign and verify (#2979)
    pkcs15-crypt
    * Fix PKCS#1 encoding function to correctly detect padding type
    piv-tool
    * Fix RSA key generation (#3158)
    * Avoid possible state change when matching unknown card (#3112)
    sc-hsm-tool
    * Cleanse buffer with plaintext key share (#3226)
    pkcs11-register
    * Fix pkcs11-register defaults on macOS and Windows (#3053)
    IDPrime
    * Fix identification of IDPrime 840 cards (#3146)
    * Fix container mapping for IDPrime 940 cards (#3220)
    * Reorder ATRs for matching cards (#3154)
    OpenPGP
    * Fix state tracking after erasing card (#3024)
    Belpic
    * Disable Applet V1.8 (#3109)
    MICARDO
    * Deactivate driver (#3152)
    SmartCard-HSM
    * Fix signing with secp521r1 signature (#3157)
    eOI
    * Set model via sc_card_ctl function (#3189)
    Rutoken
    * increase the minimum PIN size to support Rutoken ECP BIO.
    JPKI
    * Adjust parameters for public key in PKCS#15 emulator (#3182)
    D-Trust
    * Add support for ECDSA signatures and ECDH key agreement for
    D-Trust Signatures Cards 4.1/4.4 (#3240, #3248)
  - Drop patches (changes now in upstream):
    * opensc-CVE-2024-45615.patch
    * opensc-CVE-2024-45616.patch
    * opensc-CVE-2024-45617.patch
    * opensc-CVE-2024-45618.patch
    * opensc-CVE-2024-45619.patch
    * opensc-CVE-2024-45620.patch
    * opensc-CVE-2024-8443.patch

++++ python313:

  - Remove -IVendor/ from python-config boo#1231795
  - Require exact clang18 and llvm18, because apparently CPython is
    not ready for 19 yet (gh#python/cpython!125499).

++++ suseconnect-ng:

  - Update version to 1.13:
  - Integrating uptime-tracker
  - Honor auto-import-gpg-keys flag on migration (bsc#1231328)
  - Only send labels if targetting SCC
  - Skip the docker auth generation on RMT (bsc#1231185)
  - Add --set-labels to register command to set labels at registration time on SCC
  - Add a new function to display suse-uptime-tracker version
  - Integrate with uptime-tracker ( https://github.com/SUSE/uptime-tracker/ )
  - Add a command to show the info being gathered

------------------------------------------------------------------
------------------  2024-11-13  -  Nov 13 2024  -------------------
------------------------------------------------------------------

++++ curl:

  - Add patch to fix libcurl when netrc parsing is enabled.
    curl_easy_duphandle did not init netrc which broke applications such
    as for example git. gh#curl/curl#15496
    * 0001-duphandle-also-init-netrc.patch

++++ grub2:

  - Revert the patches related to BLS support in grub2-mkconfig, as they are not
    relevant to the current BLS integration and cause issues in older KIWI
    versions, which actively force it to be enabled by default (bsc#1233196)
    * 0002-Add-BLS-support-to-grub-mkconfig.patch
    * 0003-Add-grub2-switch-to-blscfg.patch
    * 0007-grub-switch-to-blscfg-adapt-to-openSUSE.patch
    * 0008-blscfg-reading-bls-fragments-if-boot-present.patch
    * 0009-10_linux-Some-refinement-for-BLS.patch
    * 0001-10_linux-Do-not-enable-BLSCFG-on-s390-emu.patch

++++ kernel-default:

  - io_uring/rw: fix missing NOWAIT check for O_DIRECT start write
    (git-fixes).
  - io_uring/sqpoll: close race on waiting for sqring entries
    (git-fixes).
  - commit 83eaece
  - mm: shmem: fix data-race in shmem_getattr() (CVE-2024-50228,
    bsc#1233204, git fixes (mm/shmem)).
  - commit 89c94b7
  - irqchip/gic-v4: Correctly deal with set_affinity on
    lazily-mapped VPEs (CVE-2024-50192 bsc#1233106).
  - commit 4258dbe
  - irqchip/gic-v4: Don't allow a VMOVP on a dying VPE
    (CVE-2024-50192 bsc#1233106).
  - kABI: Don't allow a VMOVP on a dying VPE (kabi CVE-2024-50192
    bsc#1233106).
  - irqchip/gic-v3-its: Avoid explicit cpumask allocation on stack
    (git-fixes).
  - commit 9bd7834
  - kABI fix for - Bluetooth: L2CAP: Fix
    div-by-zero in l2cap_le_flowctl_init()
    (CVE-2024-36968 bsc#1226130). - Refresh
    patches.suse/Bluetooth-Ignore-too-large-handle-values-in-BIG.patch.
  - Refresh
    patches.suse/Bluetooth-L2CAP-Fix-deadlock.patch. - Refresh
    patches.suse/Bluetooth-btnxpuart-Enable-Power-Save-feature-on-sta.patch.
  - Refresh
    patches.suse/bluetooth-hci-disallow-setting-handle-bigger-than-HC.patch.
  - Refresh
    patches.suse/bluetooth-l2cap-sync-sock-recv-cb-and-release.patch.
  - commit d93ac77
  - macsec: Fix use-after-free while sending the offloading packet
    (CVE-2024-50261 bsc#1233253).
  - commit 493a21e
  - kABI workaround for ASoC SOF (bsc#1233305).
  - commit d8b041e
  - ASoC: SOF: ipc4-topology: Add definition for generic switch/enum
    control (bsc#1233305).
  - Refresh
    patches.suse/ASoC-SOF-ipc4-topology-Correct-data-structures-for-t-e238b68.patch.
  - commit 6d4ee28
  - ASoC: SOF: topology: Parse DAI type token for dspless mode
    (bsc#1233305).
  - ASoC: SOF: topology: dynamically allocate and store DAI
    widget->private (bsc#1233305).
  - ASoC: SOF: ipc4-topology: change chain_dma handling in
    dai_config (bsc#1233305).
  - ASoC: SOF: ipc4-topology: set config_length based on
    device_count (bsc#1233305).
  - ASoC: SOF: Rename amd_bt sof_dai_type (bsc#1233305).
  - ASoC: SOF: Add i2s bt dai configuration support for AMD
    platforms (bsc#1233305).
  - ASoC: SOF: Refactor sof_i2s_tokens reading to update acpbt dai
    (bsc#1233305).
  - ASoC: SOF: IPC4: synchronize fw_config_params with fw
    definitions (bsc#1233305).
  - ASoC: SOF: Wire up buffer flags (bsc#1233305).
  - ASoC: SOF: add alignment for topology header file struct
    definition (bsc#1233305).
  - ASoC: SOF: align topology header file with sof topology header
    (bsc#1233305).
  - ASoC: SOF: ipc4-topology: Add module ID print during module
    set up (bsc#1233305).
  - ASoC: SOF: ipc4: Add data struct for module notification
    message from firmware (bsc#1233305).
  - ASoC: SOF: ipc4-topology: Helper to find an swidget by
    module/instance id (bsc#1233305).
  - ASoC: SOF: Add support for configuring PDM interface from
    topology (bsc#1233305).
  - ASoC: SOF: IPC4: get pipeline priority from topology
    (bsc#1233305).
  - ASoC: SOF: ipc4-mtrace: move debug slot related definitions
    to header.h (bsc#1233305).
  - ASoC: SOF: ipc4-control: Add support for ALSA enum control
    (bsc#1233305).
  - ASoC: SOF: ipc4-control: Add support for ALSA switch control
    (bsc#1233305).
  - ASoC: SOF: ipc4-topology: export
    sof_ipc4_copier_is_single_format (bsc#1233305).
  - ASoC: SOF: ipc4: Add new message type:
    SOF_IPC4_GLB_LOAD_LIBRARY_PREPARE (bsc#1233305).
  - ASoC: SOF: ipc4-topology: Add deep buffer size to debug prints
    (bsc#1233305).
  - ASoC: SOF: Deprecate invalid enums in IPC3 (bsc#1233305).
  - commit ccbfc43
  - ima: fix buffer overrun in ima_eventdigest_init_common
    (git-fixes).
  - commit 200c852

++++ kernel-firmware-all:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-amdgpu:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-ath10k:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-ath11k:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-ath12k:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-atheros:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-bluetooth:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-bnx2:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-brcm:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-chelsio:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-dpaa2:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-i915:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-intel:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-iwlwifi:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-liquidio:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-marvell:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-media:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-mediatek:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-mellanox:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-mwifiex:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-network:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-nfp:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-nvidia:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-platform:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-prestera:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-qcom:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-qlogic:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-radeon:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-realtek:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-serial:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-sound:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-ti:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-ueagle:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-firmware-usb-network:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ kernel-rt:

  - io_uring/rw: fix missing NOWAIT check for O_DIRECT start write
    (git-fixes).
  - io_uring/sqpoll: close race on waiting for sqring entries
    (git-fixes).
  - commit 83eaece
  - mm: shmem: fix data-race in shmem_getattr() (CVE-2024-50228,
    bsc#1233204, git fixes (mm/shmem)).
  - commit 89c94b7
  - irqchip/gic-v4: Correctly deal with set_affinity on
    lazily-mapped VPEs (CVE-2024-50192 bsc#1233106).
  - commit 4258dbe
  - irqchip/gic-v4: Don't allow a VMOVP on a dying VPE
    (CVE-2024-50192 bsc#1233106).
  - kABI: Don't allow a VMOVP on a dying VPE (kabi CVE-2024-50192
    bsc#1233106).
  - irqchip/gic-v3-its: Avoid explicit cpumask allocation on stack
    (git-fixes).
  - commit 9bd7834
  - kABI fix for - Bluetooth: L2CAP: Fix
    div-by-zero in l2cap_le_flowctl_init()
    (CVE-2024-36968 bsc#1226130). - Refresh
    patches.suse/Bluetooth-Ignore-too-large-handle-values-in-BIG.patch.
  - Refresh
    patches.suse/Bluetooth-L2CAP-Fix-deadlock.patch. - Refresh
    patches.suse/Bluetooth-btnxpuart-Enable-Power-Save-feature-on-sta.patch.
  - Refresh
    patches.suse/bluetooth-hci-disallow-setting-handle-bigger-than-HC.patch.
  - Refresh
    patches.suse/bluetooth-l2cap-sync-sock-recv-cb-and-release.patch.
  - commit d93ac77
  - macsec: Fix use-after-free while sending the offloading packet
    (CVE-2024-50261 bsc#1233253).
  - commit 493a21e
  - kABI workaround for ASoC SOF (bsc#1233305).
  - commit d8b041e
  - ASoC: SOF: ipc4-topology: Add definition for generic switch/enum
    control (bsc#1233305).
  - Refresh
    patches.suse/ASoC-SOF-ipc4-topology-Correct-data-structures-for-t-e238b68.patch.
  - commit 6d4ee28
  - ASoC: SOF: topology: Parse DAI type token for dspless mode
    (bsc#1233305).
  - ASoC: SOF: topology: dynamically allocate and store DAI
    widget->private (bsc#1233305).
  - ASoC: SOF: ipc4-topology: change chain_dma handling in
    dai_config (bsc#1233305).
  - ASoC: SOF: ipc4-topology: set config_length based on
    device_count (bsc#1233305).
  - ASoC: SOF: Rename amd_bt sof_dai_type (bsc#1233305).
  - ASoC: SOF: Add i2s bt dai configuration support for AMD
    platforms (bsc#1233305).
  - ASoC: SOF: Refactor sof_i2s_tokens reading to update acpbt dai
    (bsc#1233305).
  - ASoC: SOF: IPC4: synchronize fw_config_params with fw
    definitions (bsc#1233305).
  - ASoC: SOF: Wire up buffer flags (bsc#1233305).
  - ASoC: SOF: add alignment for topology header file struct
    definition (bsc#1233305).
  - ASoC: SOF: align topology header file with sof topology header
    (bsc#1233305).
  - ASoC: SOF: ipc4-topology: Add module ID print during module
    set up (bsc#1233305).
  - ASoC: SOF: ipc4: Add data struct for module notification
    message from firmware (bsc#1233305).
  - ASoC: SOF: ipc4-topology: Helper to find an swidget by
    module/instance id (bsc#1233305).
  - ASoC: SOF: Add support for configuring PDM interface from
    topology (bsc#1233305).
  - ASoC: SOF: IPC4: get pipeline priority from topology
    (bsc#1233305).
  - ASoC: SOF: ipc4-mtrace: move debug slot related definitions
    to header.h (bsc#1233305).
  - ASoC: SOF: ipc4-control: Add support for ALSA enum control
    (bsc#1233305).
  - ASoC: SOF: ipc4-control: Add support for ALSA switch control
    (bsc#1233305).
  - ASoC: SOF: ipc4-topology: export
    sof_ipc4_copier_is_single_format (bsc#1233305).
  - ASoC: SOF: ipc4: Add new message type:
    SOF_IPC4_GLB_LOAD_LIBRARY_PREPARE (bsc#1233305).
  - ASoC: SOF: ipc4-topology: Add deep buffer size to debug prints
    (bsc#1233305).
  - ASoC: SOF: Deprecate invalid enums in IPC3 (bsc#1233305).
  - commit ccbfc43
  - ima: fix buffer overrun in ima_eventdigest_init_common
    (git-fixes).
  - commit 200c852

++++ libgpg-error:

  - Update to 1.51:
    * Add GPGRT_PROCESS_ALLOW_SET_FG for gpgrt_process_spawn. [rEb79d4206f4]
    * Add new spawn function to modify the environment. [T7307]
    * Fix missing environ var for macOS and others. [T7169,T7307]
    * Fix forgotten _gpgrt_post_syscall on create pipe failure. [rEbcab96484d]
    * Let gpgrt_poll return an error for a closed fd. [rE4a3dc85f69]
    * Fix build error introduced by C-committee stupidity. [T7344]
    * Interface changes relative to the 1.50 release:
  - _gpg_w32_gettext_use_utf8           EXTN (new value 2).
  - gpgrt_spawn_actions_set_env_rev     NEW.
  - GPGRT_PROCESS_ALLOW_SET_FG          NEW.
    * Release-info: https://dev.gnupg.org/T7164
    * Rebase libgpg-error-nobetasuffix.patch

++++ gpgme:

  - Update to 1.24.0:
    * Extended gpgme_op_decrypt* and gpgme_op_verify* to allow writing the
    output directly to a file. [T6550]
    * Extended gpgme_op_encrypt*, gpgme_op_encrypt_sign*, and gpgme_op_sign*
    to allow reading the input data directly from a file. [T6550]
    * Add information about designated revocation keys. [T7118]
    * New context flag "import-options". [T7152]
    * New context flag "proc-all-sigs". [T7261]
    * New context flag "known-notations". [T4060]
    * New info flags "beta_compliance". [rM1a7bc88ee7]
    * New function gpgme_op_setownertrust to make changing the owner trust
    easier and to allow enabling/disabling of keys (requires GnuPG 2.4.6). [T7239]
    * New flag to re-encrypt OpenPGP data (requires GnuPG 2.5.1). [T1825]
    * cpp: Provide information about designated revocation keys for a Key. [T7118]
    * cpp: Add safer member function returning text describing an error. [T5960]
    * cpp: Add support for setting the owner trust of keys and for enabling
    and disabling keys. [T7239]
    * qt: Build QGpgME for Qt 5 and Qt 6 simultaneously. [T7205]
    * qt: Install headers for Qt 5 and Qt 6 in separate folders. [T7161]
    * qt: Allow reading the data to decrypt/encrypt/sign/verify directly from
    files. [T6550]
    * qt: Allow writing the decrypted/encrypted/signed/verified data directly
    to files. [T6550]
    * qt: Allow specifying import options when importing keys. [T7152]
    * qt: Allow appending a detached signature to an existing file. [T6867]
    * qt: Add support for enabling and disabling keys. [T7239]
    * qt: Add support for new context flag "proc-all-sigs" to the jobs that
    verify data signatures.
    * Interface changes relative to the 1.23.2 release:
  - GPGME_ENCRYPT_FILE                      NEW.
  - GPGME_SIG_MODE_FILE                     NEW.
  - GPGME_ENCRYPT_ADD_RECP                  NEW.
  - GPGME_ENCRYPT_CHG_RECP                  NEW.
  - gpgme_key_t                             EXT: New field 'revkeys'.
  - gpgme_revocation_key_t                  NEW.
  - gpgme_set_ctx_flag                      EXT: New flag 'import-options'.
  - gpgme_set_ctx_flag                      EXT: New flag 'proc-all-sigs'.
  - gpgme_set_ctx_flag                      EXT: New flag 'known-notation'.
  - gpgme_op_setownertrust_start            NEW.
  - gpgme_op_setownertrust                  NEW.
  - gpgme_subkey_t                          EXT: New field 'beta_compliance'.
  - gpgme_signature_t                       EXT: New field 'beta_compliance'.
  - gpgme_decrypt_result_t                  EXT: New field 'beta_compliance'.
  - cpp: Context::EncryptFile               NEW.
  - cpp: Context::setOwnerTrust             NEW.
  - cpp: Context::startSetOwnerTrust        NEW.
  - cpp: Context::setKeyEnabled             NEW.
  - cpp: Context::startSetKeyEnabled        NEW.
  - cpp: SignatureMode::SignFile            NEW.
  - cpp: RevocationKey                      NEW.
  - cpp: Key::revocationKey                 NEW.
  - cpp: Key::numRevocationKeys             NEW.
  - cpp: Key::revocationKeys                NEW.
  - cpp: Key::isBetaCompliance              NEW.
  - cpp: Subkey::isBetaCompliance           NEW.
  - cpp: Error::asStdString                 NEW.
  - cpp: Error::asString                    DEPRECATED.
  - cpp: DecryptionResult::isBetaCompliance NEW.
  - cpp: Signature::isBetaCompliance        NEW.
  - qt: DecryptVerifyArchiveJob::setProcessAllSignatures NEW.
  - qt: DecryptVerifyArchiveJob::processAllSignatures    NEW.
  - qt: DecryptVerifyJob::setInputFile      NEW.
  - qt: DecryptVerifyJob::inputFile         NEW.
  - qt: DecryptVerifyJob::setOutputFile     NEW.
  - qt: DecryptVerifyJob::outputFile        NEW.
  - qt: DecryptVerifyJob::setProcessAllSignatures NEW.
  - qt: DecryptVerifyJob::processAllSignatures    NEW.
  - qt: EncryptJob::setRecipients           NEW.
  - qt: EncryptJob::recipients              NEW.
  - qt: EncryptJob::setInputFile            NEW.
  - qt: EncryptJob::inputFile               NEW.
  - qt: EncryptJob::setOutputFile           NEW.
  - qt: EncryptJob::outputFile              NEW.
  - qt: EncryptJob::setEncryptionFlags      NEW.
  - qt: EncryptJob::encryptionFlags         NEW.
  - qt: SignEncryptJob::setSigners          NEW.
  - qt: SignEncryptJob::signers             NEW.
  - qt: SignEncryptJob::setRecipients       NEW.
  - qt: SignEncryptJob::recipients          NEW.
  - qt: SignEncryptJob::setInputFile        NEW.
  - qt: SignEncryptJob::inputFile           NEW.
  - qt: SignEncryptJob::setOutputFile       NEW.
  - qt: SignEncryptJob::outputFile          NEW.
  - qt: SignEncryptJob::setEncryptionFlags  NEW.
  - qt: SignEncryptJob::encryptionFlags     NEW.
  - qt: SignJob::setSigners                 NEW.
  - qt: SignJob::signers                    NEW.
  - qt: SignJob::setInputFile               NEW.
  - qt: SignJob::inputFile                  NEW.
  - qt: SignJob::setOutputFile              NEW.
  - qt: SignJob::outputFile                 NEW.
  - qt: SignJob::setSigningFlags            NEW.
  - qt: SignJob::signingFlags               NEW.
  - qt: SignJob::setAppendSignature         NEW.
  - qt: SignJob::appendSignatureEnabled     NEW.
  - qt: VerifyDetachedJob::setSignatureFile NEW.
  - qt: VerifyDetachedJob::signatureFile    NEW.
  - qt: VerifyDetachedJob::setSignedFile    NEW.
  - qt: VerifyDetachedJob::signedFile       NEW.
  - qt: VerifyDetachedJob::setProcessAllSignatures NEW.
  - qt: VerifyDetachedJob::processAllSignatures    NEW.
  - qt: VerifyOpaqueJob::setInputFile       NEW.
  - qt: VerifyOpaqueJob::inputFile          NEW.
  - qt: VerifyOpaqueJob::setOutputFile      NEW.
  - qt: VerifyOpaqueJob::outputFile         NEW.
  - qt: VerifyOpaqueJob::setProcessAllSignatures NEW.
  - qt: VerifyOpaqueJob::processAllSignatures    NEW.
  - qt: ImportJob::setImportOptions         NEW.
  - qt: ImportJob::importOptions            NEW.
  - qt: QuickJob::startSetKeyEnabled        NEW.
    * Release-info: https://dev.gnupg.org/T7376
    * Rebase gpgme-suse-nobetasuffix.patch python313.patch
    * Remove patch upstream: gpgme-D545-obsolete-distutils.patch

++++ libsoup:

  - Add 4c9e75c6.patch: fix an intermittent test failure
    (glgo#GNOME/libsoup#399).

++++ libxml2:

  - add %{?sle15allpythons} macro [jsc#PED-68]
  - use %python_build and %python_install for 15

++++ libxml2-python:

  - add %{?sle15allpythons} macro [jsc#PED-68]
  - use %python_build and %python_install for 15

++++ ovmf:

  - Add ovmf-x86_64-sev-code.bin and ovmf-x86_64-sev-vars.bin back
    because -code/-vars mode still be used in some cases. (bsc#1232762)
  - Add 60-ovmf-x86_64-sev.json to descriptors.tar.xz for -code/-vars mode
    against SEV:
  - Removed features tag:
    "acpi-s4", "acpi-s3", "requires-smm", "secure-boot", "enrolled-keys"
  - Add features tag:
    "amd-sev", "amd-sev-es", "amd-sev-snp"
  - The 50-ovmf-x86_64-sev.json is for ovmf-x86_64-sev.bin unified image
    which is stateless mode.
  - The 60-ovmf-x86_64-sev.json is for ovmf-x86_64-sev-code/vars.bin.
    Please note that the -vars storage is non-secure because SEV does NOT
    support SMM (requires-smm).

++++ ucode-amd:

  - Update to version 20241113 (git commit 1727aceef4d2):
    * qcom: venus-5.4: add venus firmware file for qcs615
    * qcom: update venus firmware file for SC7280
    * QCA: Add 22 bluetooth firmware nvm files for QCA2066

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20241112 release (bsc#1233313)
  - CVE-2024-21853: Faulty finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel Xeon Processors may allow an authorized user to potentially enable denial of service via local access. Security updates for [INTEL-SA-01101](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01101.html)
  - CVE-2024-23918: Improper conditions check in some Intel Xeon processor memory controller configurations when using Intel SGX may allow a privileged user to potentially enable escalation of privilege via local access.  Security updates for [INTEL-SA-01079](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01079.html)
  - CVE-2024-21820: Incorrect default permissions in some Intel Xeon processor memory controller configurations when using Intel SGX may allow a privileged user to potentially enable escalation of privilege via local access. Security updates for [INTEL-SA-01079](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01079.html)
  - CVE-2024-24968: Improper finite state machines (FSMs) in hardware logic in some Intel Processors may allow an privileged user to potentially enable a denial of service via local access. Updated security updates for [INTEL-SA-01097](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01097.html)
  - CVE-2024-23984: Observable discrepancy in RAPL interface for some Intel Processors may allow a privileged user to potentially enable information disclosure via local access Updated security updates for [INTEL-SA-01103](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01103.html)
  - Update for functional issues. Refer to [Intel Core Ultra Processor](https://cdrdv2.intel.com/v1/dl/getContent/792254) for details.
  - Update for functional issues. Refer to [14th/13th Generation Intel Core Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
  - Update for functional issues. Refer to [12th Generation Intel Core Processor Family](https://cdrdv2.intel.com/v1/dl/getContent/682436) for details.
  - Update for functional issues. Refer to [5th Gen Intel Xeon Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/793902) for details.
  - Update for functional issues. Refer to [4th Gen Intel Xeon Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/772415) for details.
  - Update for functional issues. Refer to [3rd Generation Intel Xeon Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/637780) for details.
  - Update for functional issues. Refer to [Intel Xeon D-2700 Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/714071) for details.
  - Update for functional issues. Refer to [Intel Xeon D-1700 and D-1800 Processor Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/714069) for details
    New Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ADL            | C0       | 06-97-02/07 | 00000036 | 00000037 | Core Gen12
    | ADL            | H0       | 06-97-05/07 | 00000036 | 00000037 | Core Gen12
    | ADL            | L0       | 06-9a-03/80 | 00000434 | 00000435 | Core Gen12
    | ADL            | R0       | 06-9a-04/80 | 00000434 | 00000435 | Core Gen12
    | EMR-SP         | A0       | 06-cf-01/87 | 21000230 | 21000283 | Xeon Scalable Gen5
    | EMR-SP         | A1       | 06-cf-02/87 | 21000230 | 21000283 | Xeon Scalable Gen5
    | MTL            | C0       | 06-aa-04/e6 | 0000001f | 00000020 | Core™ Ultra Processor
    | RPL-H/P/PX 6+8 | J0       | 06-ba-02/e0 | 00004122 | 00004123 | Core Gen13
    | RPL-HX/S       | C0       | 06-bf-02/07 | 00000036 | 00000037 | Core Gen13/Gen14
    | RPL-S          | H0       | 06-bf-05/07 | 00000036 | 00000037 | Core Gen13/Gen14
    | RPL-U 2+8      | Q0       | 06-ba-03/e0 | 00004122 | 00004123 | Core Gen13
    | SPR-SP         | E3       | 06-8f-06/87 | 2b0005c0 | 2b000603 | Xeon Scalable Gen4
    | SPR-SP         | E4/S2    | 06-8f-07/87 | 2b0005c0 | 2b000603 | Xeon Scalable Gen4
    | SPR-SP         | E5/S3    | 06-8f-08/87 | 2b0005c0 | 2b000603 | Xeon Scalable Gen4
    New Disclosures Updated in Prior Releases:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ICL-D          | B0       | 06-6c-01/10 | 010002b0 | N/A      | Xeon D-17xx/D-18xx, D-27xx/D-28xx
    | ICX-SP         | Dx/M1    | 06-6a-06/87 | 0d0003e7 | N/A      | Xeon Scalable Gen3

------------------------------------------------------------------
------------------  2024-11-12  -  Nov 12 2024  -------------------
------------------------------------------------------------------

++++ aardvark-dns:

  - Update to version 1.13.1:
    * Release v1.13.1
    * release notes for 1.13.1
    * test: make jq query work on centos stream 9
    * [skip-ci] Packit/TMT: idiomatic repo addition
    * [skip-ci] Packit: Remove epel jobs
    * tmt: install dnsmasq dependency
    * [skip-ci] Packit: disable osh-diff-scan
    * [skip-ci] Packit: enable c9s downstream updates
    * [skip-ci] TMT: install builddeps downstream
    * [skip-ci] RPM: cleanup changelog conditionals
    * support ipv6 link local addresses in resolv.conf
    * cirrus: update DEST_BRANCH

++++ docker:

  - Remove DOCKER_NETWORK_OPTS from docker.service. This was removed from
    sysconfig a long time ago, and apparently this causes issues with systemd in
    some cases.

++++ docker-compose:

  - Update to version 2.30.3:
    * bump compose-go v2.4.4
    * Avoid starting all services on rebuild

++++ python-kiwi:

  - Add random key support for LUKS encryption
    Allow to pass luks="random". In random mode use the
    generated keyfile as the only key to decrypt. This is
    only secure if the generated initrd also gets protected
    e.g. through encryption like it is done with the secure
    linux execution on zSystems

++++ drbd-utils:

  - drbd: Support and adaptations for OCF 1.1 standard (bsc#1233273)
    * bsc-1233273_drbd.ocf-replace-crm_master-with-ocf_promotion_score.patch
    * bsc-1233273_drbd.ocf-update-regex-of-sed-for-new-output-from-crm.patch
    * bsc-1233273_drbd.ocf-update-for-OCF-1.1.patch

++++ guestfs-tools:

  - virt-builder ships with out-of-date openSUSE signing key
    resulting in a GPG failure
    builder-update-openSUSE.gpg-key.patch

++++ kernel-default:

  - KVM: arm64: Fix shift-out-of-bounds bug (CVE-2024-50139
    bsc#1233062).
  - commit dc4add6
  - KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
    (CVE-2024-50115 bsc#1232919).
  - commit b8f7c4d
  - Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init()
    (CVE-2024-36968 bsc#1226130).
  - Refresh
    patches.suse/Bluetooth-Ignore-too-large-handle-values-in-BIG.patch.
  - Refresh patches.suse/Bluetooth-L2CAP-Fix-deadlock.patch.
  - Refresh
    patches.suse/Bluetooth-btnxpuart-Enable-Power-Save-feature-on-sta.patch.
  - Refresh
    patches.suse/bluetooth-hci-disallow-setting-handle-bigger-than-HC.patch.
  - Refresh
    patches.suse/bluetooth-l2cap-sync-sock-recv-cb-and-release.patch.
  - commit c95a285
  - net: sched: fix use-after-free in taprio_change()
    (CVE-2024-50127 bsc#1232907).
  - commit 8d80c7f
  - fsdax: dax_unshare_iter needs to copy entire blocks
    (bsc#1233226, CVE-2024-50250).
  - fsdax: remove zeroing code from dax_unshare_iter  (bsc#1233226,
    CVE-2024-50250).
  - commit 94457ab
  - nilfs2: fix kernel bug due to missing clearing of checked flag
    (bsc#1233206 CVE-2024-50230).
  - commit ba9ac5c
  - drm/amd/display: Check null pointers before used (bsc#1232371 CVE-2024-49921)
  - commit 3bf6629

++++ kernel-firmware-all:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-amdgpu:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-ath10k:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-ath11k:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-ath12k:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-atheros:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-bluetooth:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-bnx2:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-brcm:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-chelsio:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-dpaa2:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-i915:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-intel:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-iwlwifi:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-liquidio:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-marvell:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-media:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-mediatek:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-mellanox:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-mwifiex:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-network:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-nfp:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-nvidia:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-platform:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-prestera:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-qcom:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-qlogic:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-radeon:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-realtek:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-serial:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-sound:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-ti:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-ueagle:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-firmware-usb-network:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ kernel-rt:

  - KVM: arm64: Fix shift-out-of-bounds bug (CVE-2024-50139
    bsc#1233062).
  - commit dc4add6
  - KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory
    (CVE-2024-50115 bsc#1232919).
  - commit b8f7c4d
  - Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init()
    (CVE-2024-36968 bsc#1226130).
  - Refresh
    patches.suse/Bluetooth-Ignore-too-large-handle-values-in-BIG.patch.
  - Refresh patches.suse/Bluetooth-L2CAP-Fix-deadlock.patch.
  - Refresh
    patches.suse/Bluetooth-btnxpuart-Enable-Power-Save-feature-on-sta.patch.
  - Refresh
    patches.suse/bluetooth-hci-disallow-setting-handle-bigger-than-HC.patch.
  - Refresh
    patches.suse/bluetooth-l2cap-sync-sock-recv-cb-and-release.patch.
  - commit c95a285
  - net: sched: fix use-after-free in taprio_change()
    (CVE-2024-50127 bsc#1232907).
  - commit 8d80c7f
  - fsdax: dax_unshare_iter needs to copy entire blocks
    (bsc#1233226, CVE-2024-50250).
  - fsdax: remove zeroing code from dax_unshare_iter  (bsc#1233226,
    CVE-2024-50250).
  - commit 94457ab
  - nilfs2: fix kernel bug due to missing clearing of checked flag
    (bsc#1233206 CVE-2024-50230).
  - commit ba9ac5c
  - drm/amd/display: Check null pointers before used (bsc#1232371 CVE-2024-49921)
  - commit 3bf6629

++++ alsa:

  - Update to alsa-lib 1.2.13:
    * static build fixes
    * documentation update for control remap API
    * PCM dmix fixes
    * pcm: implement snd_pcm_hw_params_get_sync() and obsolete snd_pcm_info_get_sync()
    * ump: Add a function to provide the packet word length of a UMP type
    * seq: Add snd_seq_{get|set}_ump_is_midi1() API functions
    * seq: Add API functions to set different tempo base values
    * seq: Add API helper functions for creating UMP Endpoint and Blocks
    * documentation fixes for UMP and sequencer API
    * test: Add an example programs for UMP
    For details, see:
    https://www.alsa-project.org/wiki/Changes_v1.2.12_v1.2.13#alsa-lib
  - Conditionally take libtool

++++ expat:

  - no source changes, just adding jira reference: jsc#SLE-21253

++++ mozilla-nss:

  - Updated nss-fips-approved-crypto-non-ec.patch to approve
    RSA signature verification  mechanisms with PKCS padding and
    legacy moduli (bsc#1222834).

++++ nghttp2:

  - version update to 1.64.0
    1.64.0
    * Change clang-format options by @tatsuhiro-t in #2240
    * build(deps): bump github.com/quic-go/quic-go from 0.46.0 to 0.47.0 by @dependabot in #2243
    * build(deps): bump golang.org/x/net from 0.28.0 to 0.29.0 by @dependabot in #2244
    * nghttp2_map: Port ngtcp2 changes by @tatsuhiro-t in #2245
    * h2load: Fix UDP datagram send/recv metric by @tatsuhiro-t in #2248
    * build(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 by @dependabot in #2252
    * fix race condition on h1 connection close by @TuxInvader in #2249
    * Gha ubuntu 24.04 by @tatsuhiro-t in #2254
    * GHA: Run tests for i686-w64-mingw32 host by @tatsuhiro-t in #2255
    * cmake: Fix c-ares v1.34.0 version detection failure by @tatsuhiro-t in #2256
    * fix: -Wextra-semi errors in nghttp2_helper.h by @codebytere in #2258
    * clang-format macros that do not need semicolon at the end by @tatsuhiro-t in #2259
    * Remove extra semicolons by @tatsuhiro-t in #2260
    * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2261
    * Do not allow '@' in :authority or host field values by @tatsuhiro-t in #2262
    * h2load: GRO buffer size should be 64KiB by @tatsuhiro-t in #2263
    * Bump libbpf to v1.4.6 by @tatsuhiro-t in #2264
    * Update nghttp2_check_authority doc by @tatsuhiro-t in #2265
    1.63.0
    * Bump libbpf to v1.4.2 by @tatsuhiro-t in #2191
    * build(deps): bump golang.org/x/net from 0.24.0 to 0.25.0 by @dependabot in #2193
    * nghttpx: Fix batch UDP QUIC packet dropped on GRO read by @tatsuhiro-t in #2196
    * CMakeLists.txt: allow to compile the C only lib without CXX compiler by @ThomasDevoogdt in #2200
    * build(deps): bump github.com/quic-go/quic-go from 0.43.1 to 0.44.0 by @dependabot in #2197
    * Fix compiler versions in readme by @ryandesign in #2203
    * build(deps): bump golang.org/x/net from 0.25.0 to 0.26.0 by @dependabot in #2205
    * build(deps): bump github.com/quic-go/quic-go from 0.44.0 to 0.45.0 by @dependabot in #2206
    * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2207
    * build(deps): bump docker/build-push-action from 5 to 6 by @dependabot in #2208
    * Add wolfSSL support by @tatsuhiro-t in #2209
    * Append --shallow-submodules to git clone --recursive by @tatsuhiro-t in #2210
    * Always append options to extra options by @tatsuhiro-t in #2211
    * build(deps): bump github.com/quic-go/quic-go from 0.45.0 to 0.45.1 by @dependabot in #2213
    * Disable dependency tracking by @tatsuhiro-t in #2214
    * Fix Dockerfile.android build failure by @tatsuhiro-t in #2215
    * Fix UDP_GRO struct cmsghdr data type by @tatsuhiro-t in #2216
    * GHA: Suppress warnings by @tatsuhiro-t in #2217
    * Fix levenshtein initialization by @tatsuhiro-t in #2218
    * build(deps): bump golang.org/x/net from 0.26.0 to 0.27.0 by @dependabot in #2220
    * Undefine NGHTTP2_NO_SSIZE_T if BUILDING_NGHTTP2 is defined by @tatsuhiro-t in #2224
    * Bump clang format by @tatsuhiro-t in #2226
    * Suppress old compiler error by @tatsuhiro-t in #2228
    * build(deps): bump github.com/quic-go/quic-go from 0.45.1 to 0.45.2 by @dependabot in #2229
    * build(deps): bump golang.org/x/net from 0.27.0 to 0.28.0 by @dependabot in #2231
    * build(deps): bump github.com/quic-go/quic-go from 0.45.2 to 0.46.0 by @dependabot in #2232
    * Bump ngtcp2 and its dependencies by @tatsuhiro-t in #2236
    * Bump libbpf to v1.4.5 by @tatsuhiro-t in #2237
    * Update go by @tatsuhiro-t in #2238
    * levenshtein: Use size_t by @tatsuhiro-t in #2239

++++ openssl-3:

  - Do not use HASHBANGPERL to avoid introducing a dependency on the
    perl-base package. [bsc#1233235]

++++ libsolv:

  - fix replaces_installed_package using the wrong solvable id
    when checking the noupdate map
  - make POOL_FLAG_ADDFILEPROVIDESFILTERED behaviour more standard
  - add rpm_query_idarray query function
  - support rpm's "orderwithrequires" dependency
  - bump version to 0.7.31

++++ libsoup:

  - Add 6adc0e3e.patch: websocket: Process the frame as soon as we
    read data (boo#1233287 CVE-2024-52532 glgo#GNOME/libsoup#391).
  - Add 29b96fab.patch: websocket-test: disconnect error copy after
    the test ends (glgo#GNOME/libsoup#391).
  - Add a35222dd.patch: be more robust against invalid input when
    parsing params (boo#1233292 CVE-2024-52531
    glgo#GNOME/libsoup!407).

++++ tiff:

  - make doc packages noarch. no need to have those per arch
  - ensure that the src rpms are named per build flavor:
    You might now ask why. Good question:
    1. the spec file during the build get patched. `@BUILD_FLAVOR@`
    gets replaced with the value. which means the src rpm between
    build flavor builds is not identical. Also the last built
    src.rpm will be published. with different content and runtime
    requires (aka our BuildRequires).
    2. for historical reasons the internal dependency tracking goes
    via the src.rpm package. So without having differently named
    src.rpms the build cycle we were trying to solve was not
    actually solved. So we append a suffix to the Name attribute
    in the preamble now.

++++ libzypp:

  - BuildCache: Don't try to retrieve missing raw metadata if no
    permission to write the cache (bsc#1225451)
  - RepoManager: throw RepoNoPermissionException if the user has no
    permission to update(write) the caches (bsc#1225451)
  - version 17.35.13 (35)

++++ ucode-amd:

  - Update to version 20241112 (git commit c57a0a42468b):
    * mediatek MT7922: update bluetooth firmware to 20241106163512
    * mediatek MT7921: update bluetooth firmware to 20241106151414
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * qcom: Add QDU100 firmware image files.
    * qcom: Update aic100 firmware files
    * dedup-firmware.sh: fix infinite loop for --verbose
    * rtl_bt: Update RTL8852BT/RTL8852BE-VT BT USB FW to 0x04D7_63F7
    * cnm: update chips&media wave521c firmware.
    * mediatek MT7920: update bluetooth firmware to 20241104091246
    * linux-firmware: update firmware for MT7920 WiFi device
    * copy-firmware.sh: Run check_whence.py only if in a git repo
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various Dell laptops
    * amdgpu: update DMCUB to v9.0.10.0 for DCN351
    * rtw89: 8852a: update fw to v0.13.36.2
    * rtw88: Add firmware v52.14.0 for RTL8812AU
    * i915: Update Xe2LPD DMC to v2.23
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * linux-firmware: update firmware for MT7925 WiFi device
    * WHENCE: Add sof-tolg for mt8195
    * linux-firmware: Update firmware file for Intel BlazarI core
    * qcom: Add link for QCS6490 GPU firmware
    * qcom: update gpu firmwares for qcs615 chipset
    * cirrus: cs35l56: Update firmware for Cirrus Amps for some HP laptops
    * mediatek: Add sof-tolg for mt8195
  - Drop obsoleted workaround patch: copy-file-skip-check.patch

++++ wget:

  - GNU wget 1.25.0:
    * New testcase for pathconf truncation
    * Fix libproxy build with --disable-debug
    * [BREAKING CHANGE] Support continious reading from stdin pipes
    * Properly re-implement userinfo parsing (rfc2396)
    * init: fix -Warray-bounds in setval_internal_tilde
    * Fix build error on MingW with `G_GETFL` and `F_SETFL` flags
    * Fix returning uninitialized variable
    * Fix a static analysis false positive
    * [BREAKING CHANGE] Fix CVE-2024-10524 (drop support for shorthand URLs)
    (bsc#1233256)
  - Remove committed patches
    * properly-re-implement-userinfo-parsing.patch
  - Renumber patches

++++ zypper:

  - Don't try to download missing raw metadata if cache is not
    writable (bsc#1225451)
  - man: Update 'search' command description.
    Hint to "se -v" showing the matches within the packages metadata.
    Explain that search strings starting with a "/" will implicitly
    look into the filelist as well. Otherfise an explicit "-f" is
    needed.
  - version 1.14.78

------------------------------------------------------------------
------------------  2024-11-11  -  Nov 11 2024  -------------------
------------------------------------------------------------------

++++ drbd:

  - drbd: fix build error against kernel v6.11.6 (boo#1233222)
    * add patch
    + boo1233222_fix_drbd_build_error_against_kernel_v6.11.6.patch

++++ gnutls:

  - Update to 3.8.8:
  - libgnutls: Experimental support for X25519MLKEM768 and
    SecP256r1MLKEM768 key exchange in TLS 1.3:  The support for
    post-quantum key exchanges has been extended to cover the final
    standard of ML-KEM, following draft-kwiatkowski-tls-ecdhe-mlkem.
    The minimum supported version of liboqs is bumped to 0.11.0.
  - libgnutls: All records included in an OCSP response are now checked
    in TLS: Previously, when multiple records are provided in a single
    OCSP response, only the first record was considered; now all those
    records are examined until the server certificate matches.
  - libgnutls: Handling of malformed compress_certificate extension is
    now more standard compliant: The server behavior of receiving a
    malformed compress_certificate extension now more strictly follows
    RFC 8879; return illegal_parameter alert instead of bad_certificate,
    as well as overlong extension data is properly rejected.
  - build: More flexible library linking options for compression
    libraries, TPM, and liboqs support: The configure options,
  - -with-zstd, --with-brotli, --with-zlib, --with-tpm2, and --with-liboqs
    now take 4 states: yes/link/dlopen/no, to specify how the libraries
    are linked or loaded.
    * Rebase gnutls-FIPS-140-3-references.patch

++++ kernel-default:

  - net/ncsi: Disable the ncsi work before freeing the associated
    structure (CVE-2024-49945 bsc#1232165).
  - commit 75d875c
  - e1000e: Remove Meteor Lake SMBUS workarounds (git-fixes).
  - i40e: fix race condition by adding filter's intermediate sync
    state (git-fixes).
  - commit f4e661d
  - Revert "mm/writeback: fix possible divide-by-zero in
    wb_dirty_limits(), again" (CVE-2024-42102 bsc#1233132).
  - commit 696592c
  - i2c: designware: do not hold SCL low when I2C_DYNAMIC_TAR_UPDATE
    is not set (git-fixes).
  - USB: serial: io_edgeport: fix use after free in debug printk
    (git-fixes).
  - usb: typec: fix potential out of bounds in
    ucsi_ccg_update_set_new_cam_cmd() (git-fixes).
  - usb: musb: sunxi: Fix accessing an released usb phy (git-fixes).
  - commit d16f490

++++ kernel-rt:

  - net/ncsi: Disable the ncsi work before freeing the associated
    structure (CVE-2024-49945 bsc#1232165).
  - commit 75d875c
  - e1000e: Remove Meteor Lake SMBUS workarounds (git-fixes).
  - i40e: fix race condition by adding filter's intermediate sync
    state (git-fixes).
  - commit f4e661d
  - Revert "mm/writeback: fix possible divide-by-zero in
    wb_dirty_limits(), again" (CVE-2024-42102 bsc#1233132).
  - commit 696592c
  - i2c: designware: do not hold SCL low when I2C_DYNAMIC_TAR_UPDATE
    is not set (git-fixes).
  - USB: serial: io_edgeport: fix use after free in debug printk
    (git-fixes).
  - usb: typec: fix potential out of bounds in
    ucsi_ccg_update_set_new_cam_cmd() (git-fixes).
  - usb: musb: sunxi: Fix accessing an released usb phy (git-fixes).
  - commit d16f490

++++ ledmon:

  - Update to version 1.1.0:
    Enhancements
    Various enhancements in tests, licensing and deployment
    Add --default-controller command to ledctl
    Bug fixes
    ledctl: add error message for missing devices
    ledctl: fix musl build failure by replacing on_exit() by atexit()
    Improve error handling for unsupported patters by falling back to normal
    Fix incorrect conversion of large integer values
    Fix compilation warnings
    Fix incorrect array index usage for block device and SES slot lookup

++++ ncurses:

  - Add ncurses patch 20241109
    + work around musl header ifdef's (report by Urs Jansen, cf: Gentoo
    [#920266]).
    + improve error-reporting in write_entry.c (report by Changqing Li).
    + remove unused #include from DJGPP configuration (report by Stas
    Sergeev).
    + workaround/fix issues from clang-analyze

++++ rpm:

  - Bump debugedit version (bsc#1233156)

++++ tiff:

  - In the previous change to enable the cmake based build
    we also needed python3-Sphinx to build the man pages, as unlike
    the autotools based build, the cmake based build does not fall
    back to the pre-built man pages.
    This causes build cycle. Split out the documentation building to
    break the cycle. The Tumbleweed release managers preferred this
    solution over a mini package.

++++ man:

  - Readd patch man-db-2.7.1-zio.dif
    * Use also in-memory decompression
  - Add patch man-db-2.13.0-no_abort.patch
    * Avoid abort of mandb due switching to user man if executed by root

++++ nvidia-open-driver-G06-signed:

  - kmp-trigger.sh:
    * avoid to return with exit code != 0 if no modules are loaded

++++ rebootmgr:

  - Add compatibility symlink for rebootmgrctl to sbin

++++ os-update:

  - Update to version 1.19+git.20241111:
    * Release version 1.19
    * Only provide application defaults as comments
    * Don't try to restart dbus-broker, use soft-reboot
    * Don't hardcode path of rebootmgrctl

------------------------------------------------------------------
------------------  2024-11-10  -  Nov 10 2024  -------------------
------------------------------------------------------------------

++++ python-packaging:

  - update to 24.2:
    * PEP 639: Implement License-Expression and License-File
    (:issue:`828`)
    * Use !r formatter for error messages with filenames
    (:issue:`844`)
    * Add support for PEP 730 iOS tags (:issue:`832`)
    * Fix prerelease detection for > and < (:issue:`794`)
    * Fix uninformative error message (:issue:`830`)
    * Refactor canonicalize_version (:issue:`793`)
    * Patch python_full_version unconditionally (:issue:`825`)
    * Fix doc for canonicalize_version to mention strip_trailing_zero
    and a typo in a docstring (:issue:`801`)
    * Fix typo in Version __str__ (:issue:`817`)
    * Support creating a SpecifierSet from an iterable of Specifier
    objects (:issue:`775`)

------------------------------------------------------------------
------------------  2024-11-9  -  Nov 9 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ASoC: stm: Prevent potential division by zero in
    stm32_sai_get_clk_div() (stable-fixes).
  - ASoC: stm: Prevent potential division by zero in
    stm32_sai_mclk_round_rate() (stable-fixes).
  - ASoC: amd: yc: Support dmic on another model of Lenovo Thinkpad
    E14 Gen 6 (stable-fixes).
  - ASoC: amd: yc: fix internal mic on Xiaomi Book Pro 14 2022
    (stable-fixes).
  - ASoC: tas2781: Add new driver version for tas2563 & tas2781
    qfn chip (stable-fixes).
  - commit 1f9992e
  - drm/amdgpu: Fix DPX valid mode check on GC 9.4.3 (git-fixes).
  - ASoC: SOF: sof-client-probes-ipc4: Set param_size extension bits
    (git-fixes).
  - ASoC: stm32: spdifrx: fix dma channel release in
    stm32_spdifrx_remove (git-fixes).
  - ALSA: firewire-lib: fix return value on fail in
    amdtp_tscm_init() (git-fixes).
  - media: pulse8-cec: fix data timestamp at pulse8_setup()
    (git-fixes).
  - media: stb0899_algo: initialize cfr before using it (git-fixes).
  - media: adv7604: prevent underflow condition when reporting
    colorspace (git-fixes).
  - media: cx24116: prevent overflows on SNR calculus (git-fixes).
  - media: ar0521: don't overflow when checking PLL values
    (git-fixes).
  - media: s5p-jpeg: prevent buffer overflows (git-fixes).
  - media: dvb_frontend: don't play tricks with underflow values
    (git-fixes).
  - media: dvbdev: prevent the risk of out of memory access
    (git-fixes).
  - media: v4l2-tpg: prevent the risk of a division by zero
    (git-fixes).
  - media: v4l2-ctrls-api: fix error handling for v4l2_g_ctrl()
    (git-fixes).
  - thunderbolt: Honor TMU requirements in the domain when setting
    TMU mode (stable-fixes).
  - wifi: iwlegacy: Clear stale interrupts before resuming device
    (stable-fixes).
  - USB: gadget: dummy-hcd: Fix "task hung" problem (git-fixes).
  - usb: gadget: dummy_hcd: execute hrtimer callback in softirq
    context (git-fixes).
  - usb: gadget: dummy_hcd: Set transfer interval to 1 microframe
    (stable-fixes).
  - usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler
    (stable-fixes).
  - commit c5281d0
  - nfs: avoid i_lock contention in nfs_clear_invalid_mapping
    (git-fixes).
  - commit e6016a1
  - nfs: Fix KMSAN warning in decode_getfattr_attrs() (git-fixes).
  - commit 9358249
  - NFS: remove revoked delegation from server's delegation list
    (git-fixes).
  - commit 6feb8eb
  - SUNRPC: Remove BUG_ON call sites (git-fixes).
  - commit 5969339
  - nilfs2: fix potential deadlock with newly created symlinks
    (git-fixes).
  - commit 002996c

++++ kernel-rt:

  - ASoC: stm: Prevent potential division by zero in
    stm32_sai_get_clk_div() (stable-fixes).
  - ASoC: stm: Prevent potential division by zero in
    stm32_sai_mclk_round_rate() (stable-fixes).
  - ASoC: amd: yc: Support dmic on another model of Lenovo Thinkpad
    E14 Gen 6 (stable-fixes).
  - ASoC: amd: yc: fix internal mic on Xiaomi Book Pro 14 2022
    (stable-fixes).
  - ASoC: tas2781: Add new driver version for tas2563 & tas2781
    qfn chip (stable-fixes).
  - commit 1f9992e
  - drm/amdgpu: Fix DPX valid mode check on GC 9.4.3 (git-fixes).
  - ASoC: SOF: sof-client-probes-ipc4: Set param_size extension bits
    (git-fixes).
  - ASoC: stm32: spdifrx: fix dma channel release in
    stm32_spdifrx_remove (git-fixes).
  - ALSA: firewire-lib: fix return value on fail in
    amdtp_tscm_init() (git-fixes).
  - media: pulse8-cec: fix data timestamp at pulse8_setup()
    (git-fixes).
  - media: stb0899_algo: initialize cfr before using it (git-fixes).
  - media: adv7604: prevent underflow condition when reporting
    colorspace (git-fixes).
  - media: cx24116: prevent overflows on SNR calculus (git-fixes).
  - media: ar0521: don't overflow when checking PLL values
    (git-fixes).
  - media: s5p-jpeg: prevent buffer overflows (git-fixes).
  - media: dvb_frontend: don't play tricks with underflow values
    (git-fixes).
  - media: dvbdev: prevent the risk of out of memory access
    (git-fixes).
  - media: v4l2-tpg: prevent the risk of a division by zero
    (git-fixes).
  - media: v4l2-ctrls-api: fix error handling for v4l2_g_ctrl()
    (git-fixes).
  - thunderbolt: Honor TMU requirements in the domain when setting
    TMU mode (stable-fixes).
  - wifi: iwlegacy: Clear stale interrupts before resuming device
    (stable-fixes).
  - USB: gadget: dummy-hcd: Fix "task hung" problem (git-fixes).
  - usb: gadget: dummy_hcd: execute hrtimer callback in softirq
    context (git-fixes).
  - usb: gadget: dummy_hcd: Set transfer interval to 1 microframe
    (stable-fixes).
  - usb: gadget: dummy_hcd: Switch to hrtimer transfer scheduler
    (stable-fixes).
  - commit c5281d0
  - nfs: avoid i_lock contention in nfs_clear_invalid_mapping
    (git-fixes).
  - commit e6016a1
  - nfs: Fix KMSAN warning in decode_getfattr_attrs() (git-fixes).
  - commit 9358249
  - NFS: remove revoked delegation from server's delegation list
    (git-fixes).
  - commit 6feb8eb
  - SUNRPC: Remove BUG_ON call sites (git-fixes).
  - commit 5969339
  - nilfs2: fix potential deadlock with newly created symlinks
    (git-fixes).
  - commit 002996c

++++ tiff:

  - switch build to cmake for the webp build - we need the cmake
    finder code

------------------------------------------------------------------
------------------  2024-11-8  -  Nov 8 2024  -------------------
------------------------------------------------------------------

++++ grub2:

  - Fix previous change as the variable has to be set earlier
    * 0001-10_linux-Do-not-enable-BLSCFG-on-s390-emu.patch
  - Do not enable blscfg on s390-emu
    * 0001-10_linux-Do-not-enable-BLSCFG-on-s390-emu.patch

++++ iptables:

  - Update to release 1.8.11
    * New arptables-translate tool
    * ebtables-nft: support --replace and --list-rules commands
    * iptables-translate: support socket match and TPROXY target

++++ kdump:

  - upgrade to version 2.0.11
    * fadump mkinitrd: propagate --debug to the inner dracut call
    * mkdumprd: look for kernel image under /boot as well

++++ kernel-default:

  - cpufreq: amd-pstate: add check for cpufreq_cpu_get's return
    value (CVE-2024-50009 bsc#1232318).
  - commit 15f7e86
  - ext4: fix error message when rejecting the default hash
    (bsc#1232264 CVE-2024-49968).
  - commit 5d137c7
  - sched/deadline: Fix task_struct reference leak (CVE-2024-41023
    bsc#1228430).
  - commit 3a83981
  - be2net: fix potential memory leak in be_xmit() (CVE-2024-50167
    bsc#1233049).
  - commit 376f8c7
  - can: mcp251xfd: mcp251xfd_get_tef_len(): fix length calculation
    (git-fixes).
  - can: mcp251xfd: mcp251xfd_ring_alloc(): fix coalescing
    configuration when switching CAN modes (git-fixes).
  - can: c_can: fix {rx,tx}_errors statistics (git-fixes).
  - pwm: imx-tpm: Use correct MODULO value for EPWM mode
    (git-fixes).
  - commit c5fa961

++++ kernel-rt:

  - cpufreq: amd-pstate: add check for cpufreq_cpu_get's return
    value (CVE-2024-50009 bsc#1232318).
  - commit 15f7e86
  - ext4: fix error message when rejecting the default hash
    (bsc#1232264 CVE-2024-49968).
  - commit 5d137c7
  - sched/deadline: Fix task_struct reference leak (CVE-2024-41023
    bsc#1228430).
  - commit 3a83981
  - be2net: fix potential memory leak in be_xmit() (CVE-2024-50167
    bsc#1233049).
  - commit 376f8c7
  - can: mcp251xfd: mcp251xfd_get_tef_len(): fix length calculation
    (git-fixes).
  - can: mcp251xfd: mcp251xfd_ring_alloc(): fix coalescing
    configuration when switching CAN modes (git-fixes).
  - can: c_can: fix {rx,tx}_errors statistics (git-fixes).
  - pwm: imx-tpm: Use correct MODULO value for EPWM mode
    (git-fixes).
  - commit c5fa961

++++ man:

  - Drop libzio integration (man-db-2.7.1-zio.dif, BuildRequires and flag)
    to restore acceptable performance (boo#1232837):

++++ python-cryptography:

  - Fix requires_eq replacement for distributions which do not have
    python3-cffi installed (such as SLE15 python module pythons)
    * gh#openSUSE/python-rpm-macros#185
  - Remove outdated section in description

++++ rebootmgr:

  - Update to version 2.6+git20241108.fc0c103:
    * Fix installation of .so man pages
    * Rework manpage generation
    * Switch from configure.ac to meson
    * Document that timezones are not supported
    * Release version 2.5

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#183
  - adjust tests
  - update test results
  - 1.19
  - merge gh#openSUSE/perl-bootloader#182
  - Use sdbootutil to set default entry
  - User sdbootutil to install a new kernel
  - Set default entry and add a new kernel via sdbootutil

------------------------------------------------------------------
------------------  2024-11-7  -  Nov 7 2024  -------------------
------------------------------------------------------------------

++++ container-selinux:

  - Update to version 2.233.0:
    * container_engine_t: small change to allow non root exec in a container
    * RPM: explicitly list ghosted paths and skip mode verification
    * container-selinux install on non selinux-policy-targeted systems (#332)
    * set container_log_t type for /var/log/kube-apiserver
    * Allow kubelet_t to create a sock file kubelet_var_lib_t
    * dontaudit spc_t to mmap_zero
    * Packit: update targets (#330)
    * container_engine_t: another round of small improvements (#327)
    * Allow container_device_plugin_t to use the network (#325)
    * RPM: cleanup changelog (#324)
    * TMT: Simplify tests

++++ docker-compose:

  - Update to version 2.30.2:
    * remove ArtifactType from Config in OCI v1.1 definition of the
    artifact
    * build(deps): bump github.com/compose-spec/compose-go/v2
    * Service being declared in a profile must not trigger
    re-creation
    * Add profile e2e test case to document in compose
    * Update `MAINTAINERS` file

++++ python-kiwi:

  - Added development group in pyproject setup
    generateDS and other tools are needed and were forgotten
    to be added when we deleted the tox dependency

++++ file:

  - file-seccomp.patch: glibc uses getrandom in malloc, rseq and prctl
    in various other places, allow these syscalls in seccomp filter.

++++ haproxy:

  - Update to version 3.0.6+git0.c2c009086:
    * [RELEASE] Released version 3.0.6
    * MINOR: debug: move the "recover now" warn message after the optional notes
    * BUILD: Missing inclusion header for ssize_t type
    * BUILD: debug: also declare strlen() in __ABORT_NOW()
    * DEBUG: wdt: add a stats counter "BlockedTrafficWarnings" in show info
    * DEBUG: wdt: make the blocked traffic warning delay configurable
    * DEBUG: cli: make it possible for "debug dev loop" to trigger warnings
    * DEBUG: wdt: better detect apparently locked up threads and warn about them
    * MINOR: debug: add a function to dump a stuck thread
    * MINOR: wdt: move the local timers to a struct
    * MINOR: debug: remove the redundant process.thread_info array from post_mortem
    * MINOR: debug: also add fdtab and acitvity to struct post_mortem
    * MINOR: debug: also add a pointer to struct global to post_mortem
    * MINOR: debug: do not limit backtraces to stuck threads
    * MINOR: debug: print gdb hints when crashing
    * MINOR: connection: add new sample fetch functions fc_err_name and bc_err_name
    * MINOR: rawsock: set connection error codes when returning from recv/send/splice
    * MINOR: connection: add more connection error codes to cover common errno
    * BUG/MINOR: stats: Fix the name for the total number of streams created
    * MINOR: stream/stats: Expose the total number of streams ever created in stats
    * MINOR: stream/stats: Expose the current number of streams in stats
    * MINOR: cli/debug: show dev: add cmdline and version
    * BUG/MINOR: quic: fix malformed probing packet building
    * CLEANUP: connection: properly name the CO_ER_SSL_FATAL enum entry
    * DOC: config: document connection error 44 (reverse connect failure)
    * BUG/MEDIUM: promex: Fix dump of extra counters
    * MINOR: stream: Save last evaluated rule on invalid yield
    * BUG/MINOR: http-ana: Report internal error if an action yields on a final eval
    * BUG/MEDIUM: mux-h1: Fix how timeouts are applied on H1 connections
    * DOC: config: add missing glitch_{cnt,rate} sample definitions
    * DOC: config: add missing glitch_{cnt,rate} data types
    * BUG/MINOR: ssl/cli: 'set ssl cert' does not check the transaction name correctly
    * BUG/MINOR: trace: stop rewriting argv with -dt
    * MINOR: cli: remove non-printable characters from 'debug dev fd'
    * MINOR: debug: store important pointers in post_mortem
    * MINOR: debug: place the post_mortem struct in its own section.
    * MINOR: debug: place a magic pattern at the beginning of post_mortem
    * MINOR: pools: export the pools variable
    * BUILD: debug: silence a build warning with threads disabled
    * BUG/MEDIUM: server: fix race on servers_list during server deletion
    * BUG/MINOR: stconn: Don't disable 0-copy FF if EOS was reported on consumer side
    * BUG/MINOR: http-ana: Fix wrong client abort reports during responses forwarding
    * BUG/MEDIUM: stconn: Report blocked send if sends are blocked by an error
    * BUG/MINOR: server: fix dynamic server leak with check on failed init
    * MINOR: activity/memprofile: show per-DSO stats
    * MINOR: activity/memprofile: always return "other" bin on NULL return address
    * BUG/MEDIUM: connection/http-reuse: fix address collision on unhandled address families
    * BUG/MEDIUM: mux-h2: Remove H2S from send list if data are sent via 0-copy FF
    * BUG/MEDIUM: stats-html: Never dump more data than expected during 0-copy FF
    * BUG/MINOR: mux-quic: do not close STREAM with empty FIN if no data sent
    * BUG/MINOR: mworker: fix mworker-max-reloads parser
    * DOC: config: fix rfc7239 forwarded typo in desc
    * BUG/MEDIUM: quic: avoid freezing 0RTT connections
    * BUG/MINOR: quic: avoid leaking post handshake frames
    * REGTESTS: Never reuse server connection in http-messaging/truncated.vtc
    * BUG/MAJOR: filters/htx: Add a flag to state the payload is altered by a filter
    * BUG/MEDIUM: stconn: Check FF data of SC to perform a shutdown in sc_notify()
    * BUG/MINOR: http-ana: Don't report a server abort if response payload is invalid
    * BUG/MEDIUM: stconn: Wait iobuf is empty to shut SE down during a check send
    * BUG/MINOR: httpclient: return NULL when no proxy available during httpclient_new()
    * BUG/MEDIUM: queue: make sure never to queue when there's no more served conns
    * BUG/MEDIUM: mux-quic: ensure timeout server is active for short requests
    * BUG/MEDIUM: hlua: properly handle sample func errors in hlua_run_sample_{fetch,conv}()
    * BUG/MEDIUM: hlua: make hlua_ctx_renew() safe
    * BUG/MEDIUM: server: server stuck in maintenance after FQDN change
    * MEDIUM: debug: on panic, make the target thread automatically allocate its buf
    * MINOR: debug: replace ha_thread_dump() with its two components
    * MINOR: debug: make ha_thread_dump_done() take the pointer to be used
    * MINOR: debug: slightly change the thread_dump_pointer signification
    * MINOR: debug: split ha_thread_dump() in two parts
    * MINOR: chunk: drop the global thread_dump_buffer
    * MINOR: debug: make mark_tainted() return the previous value
    * BUG/MINOR: http-ana: Disable fast-fwd for unfinished req waiting for upgrade
    * BUG/MINOR: mux-h1: Fix condition to set EOI on SE during zero-copy forwarding
    * BUG/MEDIUM: queue: always dequeue the backend when redistributing the last server
    * MINOR: server: make srv_shutdown_sessions() call pendconn_redistribute()
    * BUG/MINOR: queue: make sure that maintenance redispatches server queue
    * BUG/MEDIUM: stream: make stream_shutdown() async-safe
    * MINOR: task: define two new one-shot events for use with WOKEN_OTHER or MSG
    * MINOR: tools: do not attempt to use backtrace() on linux without glibc
    * BUILD: tools: only include execinfo.h for the real backtrace() function
    * BUG/MINOR: cfgparse-global: fix allowed args number for setenv
    * BUG/MINOR: server: make sure the HMAINT state is part of MAINT
    * BUG/MEDIUM: cli: Deadlock when setting frontend maxconn
    * BUG/MEDIUM: cli: Be sure to catch immediate client abort
    * BUG/MINOR: mux-quic: report glitches to session
    * REGTESTS: shorten a bit the delay for the h1/h2 upgrade test
    * REGTESTS: h1/h2: Update script testing H1/H2 protocol upgrades
    * BUG/MEDIUM: mux-h1/mux-h2: Reject upgrades with payload on H2 side only
    * MINOR: mux-h1: Set EOI on SE during demux when both side are in DONE state
    * BUG/MINOR: h2: reject extended connect for h2c protocol
    * BUG/MINOR: h1: do not forward h2c upgrade header token
    * MINOR: connection: No longer include stconn type header in connection-t.h

++++ hwdata:

    update to 0.389:
    * Update pci and vendor ids

++++ ignition:

  - Update to version 2.20.0:
    * Features
    * Support partitioning disk with mounted partitions
    * Support Proxmox VE
    * Support gzipped Akamai user_data
    * Changes
    * The Dracut module now installs partx
    * Mark the 3.5.0 config spec as stable
    * No longer accept configs with version 3.5.0-experimental
    * Create new 3.6.0-experimental config spec from 3.5.0
    * Bug fixes
    * Fix network race when phoning home on Equinix Metal
    * Fix Akamai Ignition base64 decoding on padded payloads
    * Fix Makefile GOARCH for loongarch64 (#1942)
  - Drop go build bugfix again, fixed upstream
  - Adapting 0002-allow-multiple-mounts-of-same-device.patch to new
    3.6.0 spec

++++ kernel-default:

  - blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (CVE-2024-50082 bsc#1232500)
  - commit 6a67bac
  - btrfs: fix uninitialized pointer free on read_alloc_one_name() error (CVE-2024-50087 bsc#1232499)
  - commit a3c097a
  - btrfs: fix uninitialized pointer free in add_inode_ref() (CVE-2024-50088 bsc#1232498)
  - commit 75b1127
  - net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() (CVE-2024-50084 bsc#1232494)
  - commit e53e21a
  - drm/amd/display: fix double free issue during amdgpu module unload (CVE-2024-49989 bsc#1232483)
  - commit 6511376
  - drm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35 (CVE-2024-50004 bsc#1232396)
  - commit d5739f8
  - drm/amd/display: Fix system hang while resume with TBT monitor (CVE-2024-50003 bsc#1232385)
  - commit 24ceb7a
  - thermal: intel: int340x: processor: Fix warning during module
    unload (git-fixes).
  - commit 2c3d870
  - mptcp: fix double-free on socket dismantle (CVE-2024-26782
    bsc#1222590).
  - mptcp: deal with large GSO size (CVE-2023-52778 bsc#1224948).
  - commit 86ee052
  - ext4: ext4_search_dir should return a proper error (bsc#1231920
    CVE-2024-47701).
  - commit 7c02130
  - ext4: explicitly exit when ext4_find_inline_entry returns an
    error (bsc#1231920 CVE-2024-47701).
  - commit e600961
  - ext4: return error on ext4_find_inline_entry (bsc#1231920
    CVE-2024-47701).
  - commit 39b6acc
  - igb: Disable threaded IRQ for igb_msix_other (git-fixes).
  - commit b8afad1
  - fs/inode: Prevent dump_mapping() accessing invalid
    dentry.d_name.name (bsc#1232387 CVE-2024-49934).
  - commit cf2a806
  - ext4: filesystems without casefold feature cannot be mounted
    with siphash (bsc#1232264 CVE-2024-49968).
  - commit 1907014
  - ext4: drop ppath from ext4_ext_replay_update_ex() to avoid
    double-free (bsc#1232096 CVE-2024-49983).
  - commit 4a6ac53
  - vfs: fix race between evice_inodes() and find_inode()&iput()
    (bsc#1231930 CVE-2024-47679).
  - commit dcf9f6e
  - ext4: avoid OOB when system.data xattr changes underneath the
    filesystem (bsc#1231920 CVE-2024-47701).
  - commit f292cb3
  - security/keys: fix slab-out-of-bounds in key_task_permission
    (git-fixes).
  - platform/x86/amd/pmc: Detect when STB is not available
    (git-fixes).
  - HID: core: zero-initialize the report buffer (git-fixes).
  - commit 277fa5f
  - mlxbf_gige: disable RX filters until RX path initialized
    (git-fixes).
  - commit f2b07e9
  - selftests/bpf: Add tests for sdiv/smod overflow cases
    (CVE-2024-49888 bsc#1232208).
  - commit b193d4f
  - initramfs: avoid filename buffer overrun (bsc#1232436).
  - commit 4918398
  - netfilter: bpf: must hold reference on net namespace
    (bsc#1232894 CVE-2024-50130).
  - commit 7d292ad
  - bpftool: Fix undefined behavior in qsort(NULL, 0,
    ...) (bsc#1232258 CVE-2024-49987).
  - commit 80f8e64

++++ kernel-rt:

  - blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (CVE-2024-50082 bsc#1232500)
  - commit 6a67bac
  - btrfs: fix uninitialized pointer free on read_alloc_one_name() error (CVE-2024-50087 bsc#1232499)
  - commit a3c097a
  - btrfs: fix uninitialized pointer free in add_inode_ref() (CVE-2024-50088 bsc#1232498)
  - commit 75b1127
  - net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() (CVE-2024-50084 bsc#1232494)
  - commit e53e21a
  - drm/amd/display: fix double free issue during amdgpu module unload (CVE-2024-49989 bsc#1232483)
  - commit 6511376
  - drm/amd/display: update DML2 policy EnhancedPrefetchScheduleAccelerationFinal DCN35 (CVE-2024-50004 bsc#1232396)
  - commit d5739f8
  - drm/amd/display: Fix system hang while resume with TBT monitor (CVE-2024-50003 bsc#1232385)
  - commit 24ceb7a
  - thermal: intel: int340x: processor: Fix warning during module
    unload (git-fixes).
  - commit 2c3d870
  - mptcp: fix double-free on socket dismantle (CVE-2024-26782
    bsc#1222590).
  - mptcp: deal with large GSO size (CVE-2023-52778 bsc#1224948).
  - commit 86ee052
  - ext4: ext4_search_dir should return a proper error (bsc#1231920
    CVE-2024-47701).
  - commit 7c02130
  - ext4: explicitly exit when ext4_find_inline_entry returns an
    error (bsc#1231920 CVE-2024-47701).
  - commit e600961
  - ext4: return error on ext4_find_inline_entry (bsc#1231920
    CVE-2024-47701).
  - commit 39b6acc
  - igb: Disable threaded IRQ for igb_msix_other (git-fixes).
  - commit b8afad1
  - fs/inode: Prevent dump_mapping() accessing invalid
    dentry.d_name.name (bsc#1232387 CVE-2024-49934).
  - commit cf2a806
  - ext4: filesystems without casefold feature cannot be mounted
    with siphash (bsc#1232264 CVE-2024-49968).
  - commit 1907014
  - ext4: drop ppath from ext4_ext_replay_update_ex() to avoid
    double-free (bsc#1232096 CVE-2024-49983).
  - commit 4a6ac53
  - vfs: fix race between evice_inodes() and find_inode()&iput()
    (bsc#1231930 CVE-2024-47679).
  - commit dcf9f6e
  - ext4: avoid OOB when system.data xattr changes underneath the
    filesystem (bsc#1231920 CVE-2024-47701).
  - commit f292cb3
  - security/keys: fix slab-out-of-bounds in key_task_permission
    (git-fixes).
  - platform/x86/amd/pmc: Detect when STB is not available
    (git-fixes).
  - HID: core: zero-initialize the report buffer (git-fixes).
  - commit 277fa5f
  - mlxbf_gige: disable RX filters until RX path initialized
    (git-fixes).
  - commit f2b07e9
  - selftests/bpf: Add tests for sdiv/smod overflow cases
    (CVE-2024-49888 bsc#1232208).
  - commit b193d4f
  - initramfs: avoid filename buffer overrun (bsc#1232436).
  - commit 4918398
  - netfilter: bpf: must hold reference on net namespace
    (bsc#1232894 CVE-2024-50130).
  - commit 7d292ad
  - bpftool: Fix undefined behavior in qsort(NULL, 0,
    ...) (bsc#1232258 CVE-2024-49987).
  - commit 80f8e64

++++ libXcursor:

  - Update to version 1.2.3
    * Change all *LoadImage(..., size) APIs to always return a cursor with the requested size.
    * Remove unnecessary MIN calls
    * build-fix
    * fix compiler warnings
    * improve manpage formatting
    * trim redundant code from the resize-calls
    * add new property "resized" and environment "XCURSOR_RESIZED"
    * add getter/setter for "resized" property
    * restore behavior of image-loading, provide resizing via internal function
    * provide internal variants of existing functions to pass "resized" parameter
    * use resized-parameter where available when loading images
    * add/use _XcursorLibraryLoadImages to pass resized-parameter when loading
    * add debug-logging for file.c, to help with analysis
    * add traces for library.c and xlib.c, also another internal function for dpy
    * document the new XCURSOR_RESIZED environment variable and resource "resized"
    * document/tidy the new set/get functions
    * changes will suggest new release
    * ensure ncomment and nimage values are positive
    * add debug-trace for the configuration information
    * fix overlooked compiler-warning
    * reduce the message-check to ignore the over-long one
    * amend per merge_requests/22#note_2642034
    * amend per merge_requests/22#note_2642042
    * Ignore invalid cursor files

++++ expat:

  - version update to 2.6.4
    * Security fixes: [bsc#1232601]
    [#915]  CVE-2024-50602 -- Fix crash within function XML_ResumeParser
    from a NULL pointer dereference by disallowing function
    XML_StopParser to (stop or) suspend an unstarted parser.
    A new error code XML_ERROR_NOT_STARTED was introduced to
    properly communicate this situation.  // CWE-476 CWE-754
    * Other changes:
    [#903]  CMake: Add alias target "expat::expat"
    [#905]  docs: Document use via CMake >=3.18 with FetchContent
    and SOURCE_SUBDIR and its consequences
    [#902]  tests: Reduce use of global parser instance
    [#904]  tests: Resolve duplicate handler
    [#317] #918  tests: Improve tests on doctype closing (ex CVE-2019-15903)
    [#914]  Fix signedness of format strings
    [#919] #920  Version info bumped from 10:3:9 (libexpat*.so.1.9.3)
    to 11:0:10 (libexpat*.so.1.10.0); see https://verbump.de/
    for what these numbers do

++++ openssl-3:

  - Add missing fixes for SHA3_squeeze and quic_multistream_test on
    pcc64 arch. [jsc#PED-10280]
    * Added openssl-3-fix-sha3-squeeze-ppc64.patch
    * Added openssl-3-fix-quic_multistream_test.patch

++++ libselinux:

  - Drop check_runlevel from selinux-ready script and remove restorecond
    from check_packages as we don't require it to be selinux-ready.

++++ python-certifi:

  - Make the test suite working just with the standard library.

++++ qemu:

  - Fix bsc#1228079:
    * target/i386: Expose IBPB-BRTYPE and SBPB CPUID bits to the guest (bsc#1228079)
  - Add further CPUID bits fixes:
    * target/i386: Expose new feature bits in CPUID 8000_0021_EAX/EBX
    * target/i386: Expose bits related to SRSO vulnerability
    * target/i386: Add PerfMonV2 feature bit
    * target/i386: Fix minor typo in NO_NESTED_DATA_BP feature bit

------------------------------------------------------------------
------------------  2024-11-6  -  Nov 6 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - 0001-dril-Fixup-order-of-pixel-formats-in-drilConfigs.patch
    * fixes colors for 'swrast' driver (boo#1230637, gitlab issue#11840)

++++ Mesa-drivers:

  - 0001-dril-Fixup-order-of-pixel-formats-in-drilConfigs.patch
    * fixes colors for 'swrast' driver (boo#1230637, gitlab issue#11840)

++++ crypto-policies:

  - Update to version 20241010.5930b9a:
    * LEGACY: enable 192-bit ciphers for nss pkcs12/smime
    * nss: be stricter with new purposes
    * nss: rewrite backend for 3.101
    * cryptopolicies: parent scopes for dumping purposes
    * policygenerators: move scoping inside generators
    * TEST-PQ: disable pure Kyber768
    * nss: wire XYBER768D00 to X25519-KYBER768
    * TEST-PQ: update
    * TEST-PQ: also enable sntrup761x25519-sha512@openssh.com
    * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values
    * TEST-PQ, python: add more groups, mark experimental
    * openssl: mark liboqsprovider groups optional with ?
    * Remove patches:
  - crypto-policies-revert-rh-allow-sha1-signatures.patch

++++ curl:

  - Update to 8.11.0:
    * Security fixes: [bsc#1232528, CVE-2024-9681]
  - curl: HSTS subdomain overwrites parent cache entry
    * Changes:
  - curl: --create-dirs works for --dump-header as well
  - gtls: Add P12 format support
  - ipfs: add options to disable
  - TLS: TLSv1.3 earlydata support for curl
  - WebSockets: make support official (non-experimental)
    * Bugfixes:
  - build: clarify CA embed is for curl tool, mark default, improve summary
  - build: show if CA bundle to embed was found
  - build: tidy up and improve versioned-symbols options
  - cmake/FindNGTCP2: use library path as hint for finding crypto module
  - cmake: disable default OpenSSL if BearSSL, GnuTLS or Rustls is enabled
  - cmake: rename LDAP dependency config variables to match Find modules
  - cmake: replace 'check_include_file_concat()' for LDAP and GSS detection
  - cmake: use OpenSSL for LDAP detection only if available
  - curl: add build options for safe/no CA bundle search (Windows)
  - curl: detect ECH support dynamically, not at build time
  - curl_addrinfo: support operating systems with only getaddrinfo(3)
  - ftp: fix 0-length last write on upload from stdin
  - gnutls: use session cache for QUIC
  - hsts: improve subdomain handling
  - hsts: support "implied LWS" properly around max-age
  - http2: auto reset stream on server eos
  - json.md: cli-option '--json' is an alias of '--data-binary'
  - lib: move curl_path.[ch] into vssh/
  - lib: remove function pointer typecasts for hmac/sha256/md5
  - libssh.c: handle EGAINS during proto-connect correctly
  - libssh2: use the filename buffer when getting the homedir
  - multi.c: warn/assert on stall only without timer
  - negotiate: conditional check around GSS & SSL specific code
  - netrc: cache the netrc file in memory
  - ngtcp2: do not loop on recv
  - ngtcp2: set max window size to 10x of initial (128KB)
  - openssl quic: populate x509 store before handshake
  - openssl: extend the OpenSSL error messages
  - openssl: improve retries on shutdown
  - quic: use send/recvmmsg when available
  - schannel: fix TLS cert verification by IP SAN
  - schannel: ignore error on recv beyond close notify
  - select: use poll() if existing, avoid poll() with no sockets
  - sendf: add condition to max-filesize check
  - server/mqttd: fix two memory leaks
  - setopt: return error for bad input to CURLOPT_RTSP_REQUEST
  - setopt_cptr: make overflow check only done when needed
  - tls: avoid abusing CURLE_SSL_ENGINE_INITFAILED
  - tool: support --show-headers AND --remote-header-name
  - tool_operate: make --skip-existing work for --parallel
  - url: connection reuse on h3 connections
  - url: use same credentials on redirect
  - urlapi: normalize the IPv6 address
  - version: say quictls in MSH3 builds
  - vquic: fix compiler warning with gcc + MUSL
  - vquic: recv_mmsg, use fewer, but larger buffers
  - vtls: convert Curl_pin_peer_pubkey to use dynbuf
  - vtls: convert pubkey_pem_to_der to use dynbuf
    * Rebase curl-secure-getenv.patch

++++ python-kiwi:

  - Added containers integration with OBS
    When building in the Open Build Service (OBS) there is no way
    to create outgoing connections from the build workers. To allow
    the <containers> section to fetch containers from the SUSE
    registry we need to apply an OCI URI translation into a local
    path. The actual OCI container image is expected to be provided
    by the obs backend on the worker. Along with this commit also an
    integration test named test-image-disk-containers is provided.
    This Fixes jira#OBS-351

++++ grub2:

  - Fix xen package contains debug_info files with the .module suffix by moving
    them to a separate xen-debug subpackage (bsc#1232573)

++++ kernel-default:

  - Update
    patches.suse/mm-mmap-no-need-to-call-khugepaged_enter_vma-for-sta.patch
    (jsc#PED-11442).
  - commit d087a3b
  - fbdev: efifb: Register sysfs groups through driver core
    (bsc#1232224 CVE-2024-49925).
  - commit 4fd0365
  - aes-gcm-p10: Use the correct bit to test for P10 (bsc#1232704).
  - commit f0dea0e

++++ kernel-rt:

  - Update
    patches.suse/mm-mmap-no-need-to-call-khugepaged_enter_vma-for-sta.patch
    (jsc#PED-11442).
  - commit d087a3b
  - fbdev: efifb: Register sysfs groups through driver core
    (bsc#1232224 CVE-2024-49925).
  - commit 4fd0365
  - aes-gcm-p10: Use the correct bit to test for P10 (bsc#1232704).
  - commit f0dea0e

++++ llvm19:

  - Enable lldb on s390x and ppc64le (bsc#1232906).

++++ bluez:

  - Update to 5.79:
    * Fix issue with handling address type while pairing.
    * Add support for allowing to set A2DP transport delay.
    * Add support for persistent userspace HID operation.
    * Add support for handling syncing to multiple BISes.
  - Drop Fix-crash-after-bt_uhid_unregister_all.patch, merged
    upstream.

++++ libftdi1:

  - Fix for SWIG 4.3.0, add patch swig-4.3.patch

++++ qemu:

  - Fix bsc#1232617:
    * qemu-ga: Fix a SIGSEGV in ga_run_command() helper (bsc#1232617)

++++ os-update:

  - Update to version 1.18+git.20241106:
    * Release version 1.18
    * Move vendor config to /usr/share/os-update
    * Unify indentation style

------------------------------------------------------------------
------------------  2024-11-5  -  Nov 5 2024  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update to 10.3.7 (bsc#1232770)
    + Fix the product triplet for LTSS, it is always SLES-LTSS, not
    $BASEPRODUCT-LTSS

++++ cockpit-podman:

  - correct-container-search.patch: Fixes issues searching containers
    bsc#1232687

++++ gstreamer:

  - Update to version 1.24.9:
    + Highlighted bugfixes:
  - gst-rtsp-server security fix
  - GstAggregator start time selection and latency query fixes
    for force-live mode
  - audioconvert: fix dynamic handling of mix matrix, and accept
    custom upstream event for setting one
  - encodebin: fix parser selection for encoders that support
    multiple codecs
  - flvmux improvments for pipelines where timestamps don't start
    at 0
  - glcontext: egl: Unrestrict the support base DRM formats
  - kms: Add IMX-DCSS auto-detection in sink and fix stride with
    planar formats in allocator
  - macOS main application event loop fixes
  - mpegtsdemux: Handle PTS/DTS wraparound with ignore-pcr=true
  - playbin3, decodebin3, parsebin, urisourcebin: fix races, and
    improve stability and stream-collection handling
  - rtpmanager: fix early RTCP SR generation for sparse streams
    like metadata
  - qml6glsrc: Reduce capture delay
  - qtdemux: fix parsing of rotation matrix with 180 degree
    rotation
  - rtpav1depay: added wait-for-keyframe and request-keyframe
    properties
  - srt: make work with newer libsrt versions and don't
    re-connect on authentication failure
  - v4l2 fixes and improvement
  - webrtcsink, webrtcbin and whepsrc fixes
  - cerbero: fix Python 3.13 compatibility, g-i with newer
    setuptools, bootstrap on Arch Linux; iOS build fixes
  - Ship qroverlay plugin in binary packages
  - Various bug fixes, memory leak fixes, and other stability and
    reliability improvements
    + Gstreamer:
  - aggregator:
    . Fix start time selection first with force-live
    . Fix live query when force-live is TRUE
  - parse-launch: Make sure children are bins before recursing in
  - macos: Fix race conditions in cocoa/application main event
    loop
  - multiqueue: Do not unref the query we get in pad->query

++++ gstreamer-plugins-base:

  - Update to version 1.24.9:
    + allocators: drmdumb: Fix bpp value for P010
    + audioconvert: fix dynamic handling of mix matrix, accept custom
    upstream event for setting one
    + decodebin3:
  - Make update/posting of collection messages atomic
  - Send selected stream message as long as not all the tracks
    can't select decoders
    + encodebasebin: Miscellaneous fixes
    + exiftag: Check the result of gst_date_time_new_local_time(),
    fixes criticals with malformed EXIF tags
    + glcontext: egl: Unrestrict the support base DRM formats
    + gldownload: use gst_gl_sync_meta_wait_cpu()
    + gl: Fix configure error when libdrm is a subproject
    + playback: Fix a variety of decodebin3/parsebin/urisourcebin
    races
    + playbin3: prevent crashing trying to play a corrupted mp4 file
    (WARNING : HIGH PITCHED CORRUPTED SOUND)
    + Revert "meson: Fix invalid include flag in uninstalled gl pc
    file"
    + urisourcebin:
  - Allow more cases for posting stream-collection
  - Ensure all stream-start are handled
    + urisourcebin/parsebin: Improve collection creation and handling

++++ health-checker:

  - Update to version 1.12+git20241105.2e2832f15742:
    * Set RemainAfterExit=yes
    * Fix header of NEWS file
  - Switch _service over to obs_scm and type="manual"

++++ kernel-default:

  - ublk: don't allow user copy for unprivileged device
    (CVE-2024-50080 bsc#1232502).
  - commit 267c92f
  - blk-mq: setup queue ->tag_set before initializing hctx
    (CVE-2024-50081 bsc#1232501).
  - commit 87d4a82
  - media: core: v4l2-ioctl: check if ioctl is known to avoid NULL
    name (git-fixes).
  - commit c862b93
  - media: videobuf2: fix typo: vb2_dbuf -> vb2_qbuf (git-fixes).
  - commit 92209c4
  - media: bttv: use audio defaults for winfast2000 (git-fixes).
  - commit 6e1da70
  - scsi: elx: libefc: Fix potential use after free in
    efc_nport_vport_del() (CVE-2024-49852 bsc#1232819).
  - commit 51395e6
  - Update config files.
    c37e85c135ce ("clocksource: Loosen clocksource watchdog constraints")
    introduced a new default for the time skew measured by the clocksource
    watchdog. The value was raised from 100 to 125 microseconds. Reflect this
    change in the kernel config. This is an x86_64 option only.
  - commit 14c1b2d
  - ALSA: usb-audio: Add quirk for HP 320 FHD Webcam (bsc#1232768).
  - commit 7c39137
  - kABI: bpf: struct bpf_func_state kABI workaround (CVE-2024-47703
    bsc#1231946).
  - commit fd45833
  - selftests/bpf: Workaround strict bpf_lsm return value check
    (CVE-2024-47703 bsc#1231946).
  - selftests/bpf: Add verifier tests for bpf lsm (CVE-2024-47703
    bsc#1231946).
  - selftests/bpf: Add return value checks for failed tests
    (CVE-2024-47703 bsc#1231946).
  - bpf: Fix compare error in function retval_range_within
    (CVE-2024-47703 bsc#1231946).
  - bpf, lsm: Add check for BPF LSM return value (CVE-2024-47703
    bsc#1231946).
  - Refresh patches.suse/bpf-Fail-verification-for-sign-extension-of-packet-d.patch
  - Refresh patches.kabi/bpf-struct-bpf_insn_access_aux-workaround.patch
  - selftests/bpf: fix timer/test_bad_ret subtest on
    test_progs-cpuv4 flavor (CVE-2024-47703 bsc#1231946).
  - commit a0c7d4f
  - rpmsg: glink: Handle rejected intent request better (git-fixes).
  - firmware: arm_scmi: Fix slab-use-after-free in
    scmi_bus_notifier() (git-fixes).
  - commit 01fe6bf

++++ kernel-rt:

  - ublk: don't allow user copy for unprivileged device
    (CVE-2024-50080 bsc#1232502).
  - commit 267c92f
  - blk-mq: setup queue ->tag_set before initializing hctx
    (CVE-2024-50081 bsc#1232501).
  - commit 87d4a82
  - media: core: v4l2-ioctl: check if ioctl is known to avoid NULL
    name (git-fixes).
  - commit c862b93
  - media: videobuf2: fix typo: vb2_dbuf -> vb2_qbuf (git-fixes).
  - commit 92209c4
  - media: bttv: use audio defaults for winfast2000 (git-fixes).
  - commit 6e1da70
  - scsi: elx: libefc: Fix potential use after free in
    efc_nport_vport_del() (CVE-2024-49852 bsc#1232819).
  - commit 51395e6
  - Update config files.
    c37e85c135ce ("clocksource: Loosen clocksource watchdog constraints")
    introduced a new default for the time skew measured by the clocksource
    watchdog. The value was raised from 100 to 125 microseconds. Reflect this
    change in the kernel config. This is an x86_64 option only.
  - commit 14c1b2d
  - ALSA: usb-audio: Add quirk for HP 320 FHD Webcam (bsc#1232768).
  - commit 7c39137
  - kABI: bpf: struct bpf_func_state kABI workaround (CVE-2024-47703
    bsc#1231946).
  - commit fd45833
  - selftests/bpf: Workaround strict bpf_lsm return value check
    (CVE-2024-47703 bsc#1231946).
  - selftests/bpf: Add verifier tests for bpf lsm (CVE-2024-47703
    bsc#1231946).
  - selftests/bpf: Add return value checks for failed tests
    (CVE-2024-47703 bsc#1231946).
  - bpf: Fix compare error in function retval_range_within
    (CVE-2024-47703 bsc#1231946).
  - bpf, lsm: Add check for BPF LSM return value (CVE-2024-47703
    bsc#1231946).
  - Refresh patches.suse/bpf-Fail-verification-for-sign-extension-of-packet-d.patch
  - Refresh patches.kabi/bpf-struct-bpf_insn_access_aux-workaround.patch
  - selftests/bpf: fix timer/test_bad_ret subtest on
    test_progs-cpuv4 flavor (CVE-2024-47703 bsc#1231946).
  - commit a0c7d4f
  - rpmsg: glink: Handle rejected intent request better (git-fixes).
  - firmware: arm_scmi: Fix slab-use-after-free in
    scmi_bus_notifier() (git-fixes).
  - commit 01fe6bf

++++ multipath-tools:

  - Update to version 0.10.0+108+suse.2c2e597:
    * Update fix for bsc#1232063 to upstream-accepted solution

++++ harfbuzz:

  - Update to version 10.1.0:
    + Fix the sign of fallback vertical glyph advance (used when font
    has no vertical advance data).
    + Increase maximum “CFF” operands limit 20 times to support more
    complex fonts.
    + Add “--face-loader” option to command line utilities.
    + Support “COLR” v0 table in hb_font_get_glyph_extents().
    + Add support for font functions that use Core Text APIs, similar
    to FreeType font functions. This allows, for example, using
    drawing fonts that use the new (and undocumented) “hvgl” table.
    + Update IANA and OT language registries, as well ase USE data
    files.
    + Fix build with ICU 76.
    + Various compiler warnings and build fixes.
    + Various subsetter fixes.

++++ openssl-3:

  - Support MSA 11 HMAC on s390x [jsc#PED-10274]
    * Add openssl-3-disable-hmac-hw-acceleration-with-engine-digest.patch
    * Add openssl-3-fix-hmac-digest-detection-s390x.patch
    * Add openssl-3-fix-memleak-s390x_HMAC_CTX_copy.patch
  - Add hardware acceleration for full AES-XTS [jsc#PED-10273]
    * Add openssl-3-hw-acceleration-aes-xts-s390x.patch

++++ snapper:

  - provide backup program for btrfs snapshots
  - version 0.12.0

++++ python-attrs:

  - Upgrade to 24.2.0:
  - Big releases always carry the risk of regressions, but never
    did I expect to break Python 3.14’s CI! On the plus side,
    attrs runs on 3.14 now.
  - Upgrade to 24.1.0:
  - The most notable is probably the possibility to receive self
    and field definitions in your converters by wrapping them
    into a attrs.Converter.
  - The other big thing is our own replacement
    for __init_subclass__ called (you guessed it)
    __attrs_init_subclass__. Check out the docs, if you're not
    sure what this is good for.
  - Finally, we've made more important steps to promote our "new"
    APIs (can you believe they're 4 years old!?) in the docs. If
    we missed anything, please let us know.
  - Remove upstreamed patch:
  - pytest8.patch

++++ python-cryptography:

  - Avoid using requires_eq, which after the last modifications
    conflicts with python singlespec (order of expansion).

++++ selinux-policy:

  - Update to version 20240604+git386.c88be3c5:
    * Allow virt_dbus_t to connect to virtd_t over unix_stream_socket (bsc#1232655)

++++ virt-manager:

  - dbus-1-x11 is being removed from Tumbleweed so drop dependency in
    virt-manager. Add dependency on python3-dbus-python.

------------------------------------------------------------------
------------------  2024-11-4  -  Nov 4 2024  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.610.g850d981a:
    * fix(dm): remove 59-persistent-storage-dm.rules (bsc#1232063)

++++ kernel-default:

  - Update references for patches.suse/tracing-timerlat-Fix-a-race-during-cpuhp-processing.patch (CVE-2024-49866 bsc#1232259 git-fixes)
  - commit d9311d0
  - Move out-of-tree patch into a proper section
  - commit c581359
  - Revert "ALSA: hda/conexant: Mute speakers at suspend / shutdown"
    (bsc#1228269).
  - commit 13ce240
  - scsi: lpfc: Update lpfc version to 14.4.0.5 (bsc#1232757).
  - scsi: lpfc: Support loopback tests with VMID enabled
    (bsc#1232757).
  - scsi: lpfc: Revise TRACE_EVENT log flag severities from KERN_ERR
    to KERN_WARNING (bsc#1232757).
  - scsi: lpfc: Ensure DA_ID handling completion before deleting
    an NPIV instance (bsc#1232757).
  - scsi: lpfc: Fix kref imbalance on fabric ndlps from dev_loss_tmo
    handler (bsc#1232757).
  - scsi: lpfc: Restrict support for 32 byte CDBs to specific HBAs
    (bsc#1232757 bsc#1228119).
  - scsi: lpfc: Update phba link state conditional before sending
    CMF_SYNC_WQE (bsc#1232757).
  - scsi: lpfc: Add ELS_RSP cmd to the list of WQEs to flush in
    lpfc_els_flush_cmd() (bsc#1232757).
  - scsi: lpfc: Remove trailing space after \n newline
    (bsc#1232757).
  - commit 3cf27b4
  - ext4: fix timer use-after-free on failed mount (CVE-2024-49960
    bsc#1232395).
  - commit bd6997d
  - net/xen-netback: prevent UAF in xenvif_flush_hash()
    (CVE-2024-49936 bsc#1232424).
  - commit ae05dab
  - tipc: guard against string buffer overrun (CVE-2024-49995
    bsc#1232432).
  - commit ada263e
  - drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer
    (CVE-2024-49991 bsc#1232282).
  - commit 1b15839
  - nvme: re-fix error-handling for io_uring nvme-passthrough
    (git-fixes).
  - nvmet-auth: assign dh_key to NULL after kfree_sensitive
    (git-fixes).
  - nvme-pci: fix race condition between reset and
    nvme_dev_disable() (git-fixes).
  - nvme: null terminate nvme_tls_attrs (git-fixes).
  - nvme-pci: set doorbell config before unquiescing (git-fixes).
  - commit d7598b1
  - mm: split critical region in remap_file_pages() and invoke
    LSMs in between (CVE-2024-47745 bsc#1232135 git-fix).
  - commit 8228ecb
  - Add alt-commit to AMDGPU patch
  - commit 9e50980
  - phy: tegra: xusb: Add error pointer check in xusb.c (git-fixes).
  - phy: freescale: imx8m-pcie: Do CMN_RST just before PHY PLL
    lock check (git-fixes).
  - phy: ti: phy-j721e-wiz: fix usxgmii configuration (git-fixes).
  - phy: qcom: qmp-combo: move driver data initialisation earlier
    (git-fixes).
  - phy: qcom: qmp-usb: fix NULL-deref on runtime suspend
    (git-fixes).
  - dmaengine: ti: k3-udma: Set EOP for all TRs in cyclic BCDMA
    transfer (git-fixes).
  - dmaengine: sh: rz-dmac: handle configs where one address is zero
    (git-fixes).
  - Revert "driver core: Fix uevent_show() vs driver detach race"
    (git-fixes).
  - usb: phy: Fix API devm_usb_put_phy() can not release the phy
    (git-fixes).
  - usb: typec: fix unreleased fwnode_handle in
    typec_port_register_altmodes() (git-fixes).
  - xhci: Fix Link TRB DMA in command ring stopped completion event
    (git-fixes).
  - xhci: Use pm_runtime_get to prevent RPM on unsupported systems
    (git-fixes).
  - usbip: tools: Fix detach_port() invalid port error path
    (git-fixes).
  - iio: adc: ad7124: fix division by zero in
    ad7124_set_channel_odr() (git-fixes).
  - staging: iio: frequency: ad9832: fix division by zero in
    ad9832_calc_freqreg() (git-fixes).
  - iio: light: veml6030: fix microlux value calculation
    (git-fixes).
  - iio: gts-helper: Fix memory leaks for the error path of
    iio_gts_build_avail_scale_table() (git-fixes).
  - iio: gts-helper: Fix memory leaks in
    iio_gts_build_avail_scale_table() (git-fixes).
  - mei: use kvmalloc for read buffer (git-fixes).
  - Input: edt-ft5x06 - fix regmap leak when probe fails
    (git-fixes).
  - modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on
    32-bit host (git-fixes).
  - modpost: fix acpi MODULE_DEVICE_TABLE built with mismatched
    endianness (git-fixes).
  - sumversion: Fix a memory leak in get_src_version() (git-fixes).
  - genirq/msi: Fix off-by-one error in msi_domain_alloc()
    (git-fixes).
  - commit df7fb9d
  - Refresh
    patches.suse/PCI-Fix-pci_enable_acs-support-for-the-ACS-quirks.patch.
    Update upstream status.
  - commit f283868
  - nfsd: cancel nfsd_shrinker_work using sync mode in
    nfs4_state_shutdown_net (git-fixes).
  - commit ed2b339
  - NFSv3: only use NFS timeout for MOUNT when protocols are
    compatible (bsc#1231016).
  - commit ddbeb4f
  - Update
    patches.suse/0002-x86-mm-ident_map-Use-gbpages-only-where-full-GB-page.patch
    (bsc#1220382 CVE-2024-50017 bsc#1232312).
  - Update patches.suse/ACPI-PAD-fix-crash-in-exit_round_robin.patch
    (stable-fixes CVE-2024-49935 bsc#1232370).
  - Update
    patches.suse/ACPI-battery-Fix-possible-crash-when-unregistering-a.patch
    (git-fixes CVE-2024-49955 bsc#1232154).
  - Update
    patches.suse/ACPI-sysfs-validate-return-type-of-_STR-method.patch
    (git-fixes CVE-2024-49860 bsc#1231861).
  - Update
    patches.suse/ACPICA-check-null-return-of-ACPI_ALLOCATE_ZEROED-in-.patch
    (stable-fixes CVE-2024-49962 bsc#1232314).
  - Update
    patches.suse/ALSA-asihpi-Fix-potential-OOB-array-access.patch
    (stable-fixes CVE-2024-50007 bsc#1232394).
  - Update
    patches.suse/Bluetooth-Call-iso_exit-on-module-unload.patch
    (git-fixes CVE-2024-50078 bsc#1232503).
  - Update
    patches.suse/Bluetooth-ISO-Fix-multiple-init-when-debugfs-is-disa.patch
    (git-fixes CVE-2024-50077 bsc#1232504).
  - Update
    patches.suse/Bluetooth-RFCOMM-FIX-possible-deadlock-in-rfcomm_sk_.patch
    (git-fixes CVE-2024-50044 bsc#1231904).
  - Update
    patches.suse/IB-core-Fix-ib_cache_setup_one-error-flow-cleanup.patch
    (git-fixes CVE-2024-47693 bsc#1232013).
  - Update
    patches.suse/IB-core-Implement-a-limit-on-UMAD-receive-List.patch
    (bsc#1228743 CVE-2024-42145 bsc#1223384).
  - Update
    patches.suse/Input-adp5589-keys-fix-NULL-pointer-dereference.patch
    (git-fixes CVE-2024-49871 bsc#1232287).
  - Update
    patches.suse/KEYS-prevent-NULL-pointer-dereference-in-find_asymme.patch
    (git-fixes CVE-2024-47743 bsc#1232129).
  - Update
    patches.suse/KVM-Use-dedicated-mutex-to-protect-kvm_usage_count-t.patch
    (git-fixes CVE-2024-47744 bsc#1232132).
  - Update
    patches.suse/PCI-keystone-Fix-if-statement-expression-in-ks_pcie_.patch
    (git-fixes CVE-2024-47756 bsc#1232185).
  - Update
    patches.suse/PCI-kirin-Fix-buffer-overflow-in-kirin_pcie_parse_po.patch
    (git-fixes CVE-2024-47751 bsc#1232127).
  - Update
    patches.suse/RDMA-cxgb4-Added-NULL-check-for-lookup_atid.patch
    (git-fixes CVE-2024-47749 bsc#1232180).
  - Update
    patches.suse/RDMA-hns-Fix-Use-After-Free-of-rsv_qp-on-HIP08.patch
    (git-fixes CVE-2024-47750 bsc#1232182).
  - Update
    patches.suse/RDMA-hns-Fix-spin_unlock_irqrestore-called-with-IRQs.patch
    (git-fixes CVE-2024-47735 bsc#1232111).
  - Update
    patches.suse/RDMA-iwcm-Fix-WARNING-at_kernel-workqueue.c-check_fl.patch
    (git-fixes CVE-2024-47696 bsc#1231864).
  - Update
    patches.suse/RDMA-rtrs-clt-Reset-cid-to-con_num-1-to-stay-in-boun.patch
    (git-fixes CVE-2024-47695 bsc#1231931).
  - Update
    patches.suse/RDMA-rtrs-srv-Avoid-null-pointer-deref-during-path-e.patch
    (git-fixes CVE-2024-50062 bsc#1232232).
  - Update
    patches.suse/aoe-fix-the-potential-use-after-free-problem-in-more.patch
    (bsc#1218562 CVE-2023-6270 CVE-2024-49982 bsc#1232097).
  - Update
    patches.suse/bpf-Fail-verification-for-sign-extension-of-packet-d.patch
    (git-fixes CVE-2024-47702 bsc#1231924).
  - Update
    patches.suse/bpf-Fix-helper-writes-to-read-only-maps.patch
    (git-fixes CVE-2024-49861 bsc#1232254).
  - Update
    patches.suse/bpf-Fix-use-after-free-in-bpf_uprobe_multi_link_attach.patch
    (git-fixes CVE-2024-47675 bsc#1231926).
  - Update
    patches.suse/bpf-Zero-former-ARG_PTR_TO_-LONG-INT-args-in-case-of.patch
    (git-fixes CVE-2024-47728 bsc#1232076).
  - Update
    patches.suse/bpf-correctly-handle-malformed-BPF_CORE_TYPE_ID_LOCA.patch
    (git-fixes CVE-2024-49850 bsc#1232189).
  - Update
    patches.suse/cachefiles-fix-dentry-leak-in-cachefiles_open_file.patch
    (bsc#1231183 CVE-2024-49870 bsc#1232279).
  - Update
    patches.suse/can-bcm-Clear-bo-bcm_proc_read-after-remove_proc_ent.patch
    (git-fixes CVE-2024-47709 bsc#1232048).
  - Update
    patches.suse/crypto-iaa-Fix-potential-use-after-free-bug.patch
    (git-fixes CVE-2024-47732 bsc#1232109).
  - Update
    patches.suse/cxl-pci-Fix-disabling-memory-if-DVSEC-CXL-Range-does.patch
    (git-fixes CVE-2024-26761 bsc#1230375).
  - Update
    patches.suse/driver-core-Fix-a-potential-null-ptr-deref-in-module.patch
    (git-fixes CVE-2024-47688 bsc#1232009).
  - Update
    patches.suse/driver-core-bus-Fix-double-free-in-driver-API-bus_re.patch
    (stable-fixes CVE-2024-50055 bsc#1232329).
  - Update
    patches.suse/drivers-media-dvb-frontends-rtl2830-fix-an-out-of-bo.patch
    (git-fixes CVE-2024-47697 bsc#1231858).
  - Update
    patches.suse/drivers-media-dvb-frontends-rtl2832-fix-an-out-of-bo.patch
    (git-fixes CVE-2024-47698 bsc#1231859).
  - Update
    patches.suse/drm-amd-display-Add-null-check-for-set_output_gamma-.patch
    (git-fixes CVE-2024-47720 bsc#1232043).
  - Update
    patches.suse/drm-amd-display-Check-null-pointer-before-dereferenc.patch
    (stable-fixes CVE-2024-50049 bsc#1232309).
  - Update
    patches.suse/drm-amd-display-fixed-integer-types-and-null-check-l.patch
    (git-fixes CVE-2024-26767 bsc#1230339).
  - Update
    patches.suse/drm-omapdrm-Add-missing-check-for-alloc_ordered_work.patch
    (git-fixes CVE-2024-49879 bsc#1232349).
  - Update
    patches.suse/drm-v3d-Stop-the-active-perfmon-before-being-destroy.patch
    (git-fixes CVE-2024-50031 bsc#1231947).
  - Update
    patches.suse/efistub-tpm-Use-ACPI-reclaim-memory-for-event-log-to.patch
    (stable-fixes CVE-2024-49858 bsc#1232251).
  - Update
    patches.suse/ep93xx-clock-Fix-off-by-one-in-ep93xx_div_recalc_rat.patch
    (git-fixes CVE-2024-47686 bsc#1232000).
  - Update
    patches.suse/exfat-fix-memory-leak-in-exfat_load_bitmap.patch
    (git-fixes CVE-2024-50013 bsc#1232080).
  - Update
    patches.suse/fbcon-Fix-a-NULL-pointer-dereference-issue-in-fbcon_.patch
    (stable-fixes CVE-2024-50048 bsc#1232310).
  - Update
    patches.suse/firmware-arm_scmi-Fix-double-free-in-OPTEE-transport.patch
    (git-fixes CVE-2024-49853 bsc#1232192).
  - Update patches.suse/firmware_loader-Block-path-traversal.patch
    (git-fixes CVE-2024-47742 bsc#1232126).
  - Update
    patches.suse/i2c-stm32f7-Do-not-prepare-unprepare-clock-during-ru.patch
    (git-fixes CVE-2024-49985 bsc#1232094).
  - Update
    patches.suse/i3c-master-cdns-Fix-use-after-free-vulnerability-in-.patch
    (stable-fixes CVE-2024-50061 bsc#1232263).
  - Update
    patches.suse/i3c-master-svc-Fix-use-after-free-vulnerability-in-s.patch
    (git-fixes CVE-2024-49874 bsc#1232295).
  - Update
    patches.suse/i40e-Fix-XDP-program-unloading-while-removing-the-dr.patch
    (git-fixes CVE-2024-41047 bsc#1228537).
  - Update
    patches.suse/idpf-fix-UAFs-when-destroying-the-queues.patch
    (git-fixes CVE-2024-44932 bsc#1229808).
  - Update
    patches.suse/idpf-fix-memory-leaks-and-crashes-while-performing-a.patch
    (git-fixes CVE-2024-44964 bsc#1230220).
  - Update
    patches.suse/iommufd-Protect-against-overflow-of-ALIGN-during-iov.patch
    (git-fixes CVE-2024-47719 bsc#1231865).
  - Update
    patches.suse/jffs2-prevent-xattr-node-from-overflowing-the-eraseblock.patch
    (git-fixes CVE-2024-38599 bsc#1226848 bsc#1223384).
  - Update patches.suse/jfs-Fix-uaf-in-dbFreeBits.patch (git-fixes
    CVE-2024-49903 bsc#1232362).
  - Update
    patches.suse/jfs-Fix-uninit-value-access-of-new_ea-in-ea_buffer.patch
    (git-fixes CVE-2024-49900 bsc#1232359).
  - Update
    patches.suse/jfs-check-if-leafidx-greater-than-num-leaves-per-dmap-tree.patch
    (git-fixes CVE-2024-49902 bsc#1232378).
  - Update
    patches.suse/jfs-fix-out-of-bounds-in-dbNextAG-and-diAlloc.patch
    (git-fixes CVE-2024-47723 bsc#1232050).
  - Update
    patches.suse/mailbox-bcm2835-Fix-timeout-during-suspend-mode.patch
    (git-fixes CVE-2024-49963 bsc#1232147).
  - Update
    patches.suse/md-Don-t-ignore-suspended-array-in-md_check_recovery-1baa.patch
    (bsc#1219596 CVE-2024-26758 bsc#1230341).
  - Update patches.suse/media-edia-dvbdev-fix-a-use-after-free.patch
    (git-fixes CVE-2024-27043 bsc#1223824 bsc#1218562).
  - Update
    patches.suse/media-i2c-ar0521-Use-cansleep-version-of-gpiod_set_v.patch
    (git-fixes CVE-2024-49961 bsc#1232148).
  - Update
    patches.suse/media-venus-fix-use-after-free-bug-in-venus_remove-d.patch
    (git-fixes CVE-2024-49981 bsc#1232098).
  - Update
    patches.suse/nbd-fix-race-between-timeout-and-normal-completion.patch
    (bsc#1230918 CVE-2024-49855 bsc#1232195).
  - Update
    patches.suse/net-phy-Remove-LED-entry-from-LEDs-list-on-unregiste.patch
    (git-fixes CVE-2024-50023 bsc#1231955).
  - Update
    patches.suse/net-test-for-not-too-small-csum_start-in-virtio_net_.patch
    (git-fixes CVE-2024-49947 bsc#1232162).
  - Update
    patches.suse/nfsd-call-cache_put-if-xdr_reserve_space-returns-NULL.patch
    (git-fixes CVE-2024-47737 bsc#1232056).
  - Update
    patches.suse/nfsd-map-the-EBADMSG-to-nfserr_io-to-avoid-warning.patch
    (git-fixes CVE-2024-49875 bsc#1232333).
  - Update
    patches.suse/nilfs2-fix-potential-null-ptr-deref-in-nilfs_btree_insert.patch
    (git-fixes CVE-2024-47699 bsc#1231916).
  - Update
    patches.suse/nilfs2-fix-potential-oob-read-in-nilfs_btree_check_delete.patch
    (git-fixes CVE-2024-47757 bsc#1232187).
  - Update
    patches.suse/nouveau-dmem-handle-kcalloc-allocation-failure.patch
    (git-fixes CVE-2024-26943 bsc#1230527).
  - Update
    patches.suse/ocfs2-cancel-dqi_sync_work-before-freeing-oinfo.patch
    (git-fixes CVE-2024-49966 bsc#1232141).
  - Update
    patches.suse/ocfs2-fix-null-ptr-deref-when-journal-load-failed.patch
    (git-fixes CVE-2024-49957 bsc#1232152).
  - Update
    patches.suse/ocfs2-fix-possible-null-ptr-deref-in-ocfs2_set_buffer_uptodate.patch
    (git-fixes CVE-2024-49877 bsc#1232339).
  - Update
    patches.suse/ocfs2-remove-unreasonable-unlock-in-ocfs2_read_blocks.patch
    (git-fixes CVE-2024-49965 bsc#1232142).
  - Update
    patches.suse/parport-Proper-fix-for-array-out-of-bounds-access.patch
    (git-fixes CVE-2024-50074 bsc#1232507).
  - Update
    patches.suse/pinctrl-apple-check-devm_kasprintf-returned-value.patch
    (git-fixes CVE-2024-50069 bsc#1232511).
  - Update
    patches.suse/platform-x86-ISST-Fix-the-KASAN-report-slab-out-of-b.patch
    (git-fixes CVE-2024-49886 bsc#1232196).
  - Update
    patches.suse/powercap-intel_rapl-Fix-off-by-one-in-get_rpi.patch
    (git-fixes CVE-2024-49862 bsc#1231871).
  - Update
    patches.suse/resource-fix-region_intersects-vs-add_memory_driver_.patch
    (git-fixes CVE-2024-49878 bsc#1232340).
  - Update
    patches.suse/scsi-fnic-Move-flush_work-initialization-out-of-if-b.patch
    (bsc#1230055 CVE-2024-50025 bsc#1231953).
  - Update
    patches.suse/scsi-lpfc-validate-hdwq-pointers-before-dereferencing-in.patch
    (bsc#1229429 jsc#PED-9899 CVE-2024-49891 bsc#1232218).
  - Update
    patches.suse/scsi-sd-Fix-off-by-one-error-in-sd_read_block_charac.patch
    (bsc#1223848 CVE-2024-47682 bsc#1231856).
  - Update
    patches.suse/serial-protect-uart_port_dtr_rts-in-uart_shutdown-to.patch
    (stable-fixes CVE-2024-50058 bsc#1232285).
  - Update
    patches.suse/tpm-Clean-up-TPM-space-after-command-failure.patch
    (git-fixes CVE-2024-49851 bsc#1232134).
  - Update
    patches.suse/tty-n_gsm-Fix-use-after-free-in-gsm_cleanup_mux.patch
    (stable-fixes CVE-2024-50073 bsc#1232520).
  - Update
    patches.suse/vhost-scsi-null-ptr-dereference-in-vhost_scsi_get_re.patch
    (git-fixes CVE-2024-49863 bsc#1232255).
  - Update
    patches.suse/vhost_vdpa-assign-irq-bypass-producer-token-correctl.patch
    (git-fixes CVE-2024-47748 bsc#1232174).
  - Update patches.suse/vmxnet3-Fix-missing-reserved-tailroom.patch
    (bsc#1226498 CVE-2024-27026 bsc#1223700).
  - Update
    patches.suse/vt-prevent-kernel-infoleak-in-con_font_get.patch
    (git-fixes CVE-2024-50076 bsc#1232505).
  - Update
    patches.suse/wifi-ath11k-fix-array-out-of-bound-access-in-SoC-sta.patch
    (stable-fixes CVE-2024-49930 bsc#1232260).
  - Update
    patches.suse/wifi-ath12k-fix-array-out-of-bound-access-in-SoC-sta.patch
    (stable-fixes CVE-2024-49931 bsc#1232275).
  - Update
    patches.suse/wifi-ath9k_htc-Use-__skb_set_length-for-resetting-ur.patch
    (stable-fixes CVE-2024-49938 bsc#1232552).
  - Update
    patches.suse/wifi-cfg80211-Set-correct-chandef-when-starting-CAC.patch
    (stable-fixes CVE-2024-49937 bsc#1232427).
  - Update
    patches.suse/wifi-iwlwifi-mvm-avoid-NULL-pointer-dereference.patch
    (stable-fixes CVE-2024-49929 bsc#1232253).
  - Update
    patches.suse/wifi-mac80211-don-t-use-rate-mask-for-offchannel-TX-.patch
    (git-fixes CVE-2024-47738 bsc#1232114).
  - Update
    patches.suse/wifi-mac80211-use-two-phase-skb-reclamation-in-ieee8.patch
    (git-fixes CVE-2024-47713 bsc#1232016).
  - Update
    patches.suse/wifi-mt76-mt7915-fix-oops-on-non-dbdc-mt7986.patch
    (git-fixes CVE-2024-47715 bsc#1231860).
  - Update
    patches.suse/wifi-mt76-mt7996-fix-NULL-pointer-dereference-in-mt7.patch
    (git-fixes CVE-2024-47681 bsc#1231855).
  - Update
    patches.suse/wifi-mt76-mt7996-use-hweight16-to-get-correct-tx-ant.patch
    (git-fixes CVE-2024-47714 bsc#1232018).
  - Update
    patches.suse/wifi-mwifiex-Fix-memcpy-field-spanning-write-warning.patch
    (stable-fixes CVE-2024-50008 bsc#1232317).
  - Update
    patches.suse/wifi-rtw88-always-wait-for-both-firmware-loading-att.patch
    (git-fixes CVE-2024-47718 bsc#1232015).
  - Update
    patches.suse/wifi-rtw89-avoid-reading-out-of-bounds-when-loading-.patch
    (stable-fixes CVE-2024-49928 bsc#1232250).
  - Update
    patches.suse/wifi-rtw89-avoid-to-add-interface-to-list-twice-when.patch
    (stable-fixes CVE-2024-49939 bsc#1232381).
  - Update
    patches.suse/wifi-wilc1000-fix-potential-RCU-dereference-issue-in.patch
    (git-fixes CVE-2024-47712 bsc#1232017).
  - Update
    patches.suse/xhci-tegra-fix-checked-USB2-port-number.patch
    (git-fixes CVE-2024-50075 bsc#1232506).
  - commit a270265
  - Update
    patches.suse/i3c-mipi-i3c-hci-Fix-out-of-bounds-access-in-hci_dma.patch
    (git-fixes CVE-2023-52766 bsc#1230620).
  - Update
    patches.suse/media-pci-cx23885-check-cx23885_vdev_init-return.patch
    (stable-fixes CVE-2023-52918 bsc#1232047).
  - Update
    patches.suse/nfc-nci-fix-possible-NULL-pointer-dereference-in-sen.patch
    (git-fixes CVE-2023-52919 bsc#1231988).
  - Update
    patches.suse/ntb-intel-Fix-the-NULL-vs-IS_ERR-bug-for-debugfs_cre.patch
    (git-fixes CVE-2023-52917 bsc#1231849).
  - Update
    patches.suse/tcp-do-not-accept-ACK-of-bytes-we-never-sent.patch
    (CVE-2023-52881 bsc#1225611 bsc#1223384).
  - Update patches.suse/wifi-ath11k-fix-htt-pktlog-locking.patch
    (git-fixes CVE-2023-52800 bsc#1230600).
  - commit 9859953
  - NFSD: Force all NFSv4.2 COPY requests to be synchronous
    (CVE-2024-49974 bsc#1232383).
  - commit 16045fc

++++ kernel-rt:

  - Update references for patches.suse/tracing-timerlat-Fix-a-race-during-cpuhp-processing.patch (CVE-2024-49866 bsc#1232259 git-fixes)
  - commit d9311d0
  - Move out-of-tree patch into a proper section
  - commit c581359
  - Revert "ALSA: hda/conexant: Mute speakers at suspend / shutdown"
    (bsc#1228269).
  - commit 13ce240
  - scsi: lpfc: Update lpfc version to 14.4.0.5 (bsc#1232757).
  - scsi: lpfc: Support loopback tests with VMID enabled
    (bsc#1232757).
  - scsi: lpfc: Revise TRACE_EVENT log flag severities from KERN_ERR
    to KERN_WARNING (bsc#1232757).
  - scsi: lpfc: Ensure DA_ID handling completion before deleting
    an NPIV instance (bsc#1232757).
  - scsi: lpfc: Fix kref imbalance on fabric ndlps from dev_loss_tmo
    handler (bsc#1232757).
  - scsi: lpfc: Restrict support for 32 byte CDBs to specific HBAs
    (bsc#1232757 bsc#1228119).
  - scsi: lpfc: Update phba link state conditional before sending
    CMF_SYNC_WQE (bsc#1232757).
  - scsi: lpfc: Add ELS_RSP cmd to the list of WQEs to flush in
    lpfc_els_flush_cmd() (bsc#1232757).
  - scsi: lpfc: Remove trailing space after \n newline
    (bsc#1232757).
  - commit 3cf27b4
  - ext4: fix timer use-after-free on failed mount (CVE-2024-49960
    bsc#1232395).
  - commit bd6997d
  - net/xen-netback: prevent UAF in xenvif_flush_hash()
    (CVE-2024-49936 bsc#1232424).
  - commit ae05dab
  - tipc: guard against string buffer overrun (CVE-2024-49995
    bsc#1232432).
  - commit ada263e
  - drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer
    (CVE-2024-49991 bsc#1232282).
  - commit 1b15839
  - nvme: re-fix error-handling for io_uring nvme-passthrough
    (git-fixes).
  - nvmet-auth: assign dh_key to NULL after kfree_sensitive
    (git-fixes).
  - nvme-pci: fix race condition between reset and
    nvme_dev_disable() (git-fixes).
  - nvme: null terminate nvme_tls_attrs (git-fixes).
  - nvme-pci: set doorbell config before unquiescing (git-fixes).
  - commit d7598b1
  - mm: split critical region in remap_file_pages() and invoke
    LSMs in between (CVE-2024-47745 bsc#1232135 git-fix).
  - commit 8228ecb
  - Add alt-commit to AMDGPU patch
  - commit 9e50980
  - phy: tegra: xusb: Add error pointer check in xusb.c (git-fixes).
  - phy: freescale: imx8m-pcie: Do CMN_RST just before PHY PLL
    lock check (git-fixes).
  - phy: ti: phy-j721e-wiz: fix usxgmii configuration (git-fixes).
  - phy: qcom: qmp-combo: move driver data initialisation earlier
    (git-fixes).
  - phy: qcom: qmp-usb: fix NULL-deref on runtime suspend
    (git-fixes).
  - dmaengine: ti: k3-udma: Set EOP for all TRs in cyclic BCDMA
    transfer (git-fixes).
  - dmaengine: sh: rz-dmac: handle configs where one address is zero
    (git-fixes).
  - Revert "driver core: Fix uevent_show() vs driver detach race"
    (git-fixes).
  - usb: phy: Fix API devm_usb_put_phy() can not release the phy
    (git-fixes).
  - usb: typec: fix unreleased fwnode_handle in
    typec_port_register_altmodes() (git-fixes).
  - xhci: Fix Link TRB DMA in command ring stopped completion event
    (git-fixes).
  - xhci: Use pm_runtime_get to prevent RPM on unsupported systems
    (git-fixes).
  - usbip: tools: Fix detach_port() invalid port error path
    (git-fixes).
  - iio: adc: ad7124: fix division by zero in
    ad7124_set_channel_odr() (git-fixes).
  - staging: iio: frequency: ad9832: fix division by zero in
    ad9832_calc_freqreg() (git-fixes).
  - iio: light: veml6030: fix microlux value calculation
    (git-fixes).
  - iio: gts-helper: Fix memory leaks for the error path of
    iio_gts_build_avail_scale_table() (git-fixes).
  - iio: gts-helper: Fix memory leaks in
    iio_gts_build_avail_scale_table() (git-fixes).
  - mei: use kvmalloc for read buffer (git-fixes).
  - Input: edt-ft5x06 - fix regmap leak when probe fails
    (git-fixes).
  - modpost: fix input MODULE_DEVICE_TABLE() built for 64-bit on
    32-bit host (git-fixes).
  - modpost: fix acpi MODULE_DEVICE_TABLE built with mismatched
    endianness (git-fixes).
  - sumversion: Fix a memory leak in get_src_version() (git-fixes).
  - genirq/msi: Fix off-by-one error in msi_domain_alloc()
    (git-fixes).
  - commit df7fb9d
  - Refresh
    patches.suse/PCI-Fix-pci_enable_acs-support-for-the-ACS-quirks.patch.
    Update upstream status.
  - commit f283868
  - nfsd: cancel nfsd_shrinker_work using sync mode in
    nfs4_state_shutdown_net (git-fixes).
  - commit ed2b339
  - NFSv3: only use NFS timeout for MOUNT when protocols are
    compatible (bsc#1231016).
  - commit ddbeb4f
  - Update
    patches.suse/0002-x86-mm-ident_map-Use-gbpages-only-where-full-GB-page.patch
    (bsc#1220382 CVE-2024-50017 bsc#1232312).
  - Update patches.suse/ACPI-PAD-fix-crash-in-exit_round_robin.patch
    (stable-fixes CVE-2024-49935 bsc#1232370).
  - Update
    patches.suse/ACPI-battery-Fix-possible-crash-when-unregistering-a.patch
    (git-fixes CVE-2024-49955 bsc#1232154).
  - Update
    patches.suse/ACPI-sysfs-validate-return-type-of-_STR-method.patch
    (git-fixes CVE-2024-49860 bsc#1231861).
  - Update
    patches.suse/ACPICA-check-null-return-of-ACPI_ALLOCATE_ZEROED-in-.patch
    (stable-fixes CVE-2024-49962 bsc#1232314).
  - Update
    patches.suse/ALSA-asihpi-Fix-potential-OOB-array-access.patch
    (stable-fixes CVE-2024-50007 bsc#1232394).
  - Update
    patches.suse/Bluetooth-Call-iso_exit-on-module-unload.patch
    (git-fixes CVE-2024-50078 bsc#1232503).
  - Update
    patches.suse/Bluetooth-ISO-Fix-multiple-init-when-debugfs-is-disa.patch
    (git-fixes CVE-2024-50077 bsc#1232504).
  - Update
    patches.suse/Bluetooth-RFCOMM-FIX-possible-deadlock-in-rfcomm_sk_.patch
    (git-fixes CVE-2024-50044 bsc#1231904).
  - Update
    patches.suse/IB-core-Fix-ib_cache_setup_one-error-flow-cleanup.patch
    (git-fixes CVE-2024-47693 bsc#1232013).
  - Update
    patches.suse/IB-core-Implement-a-limit-on-UMAD-receive-List.patch
    (bsc#1228743 CVE-2024-42145 bsc#1223384).
  - Update
    patches.suse/Input-adp5589-keys-fix-NULL-pointer-dereference.patch
    (git-fixes CVE-2024-49871 bsc#1232287).
  - Update
    patches.suse/KEYS-prevent-NULL-pointer-dereference-in-find_asymme.patch
    (git-fixes CVE-2024-47743 bsc#1232129).
  - Update
    patches.suse/KVM-Use-dedicated-mutex-to-protect-kvm_usage_count-t.patch
    (git-fixes CVE-2024-47744 bsc#1232132).
  - Update
    patches.suse/PCI-keystone-Fix-if-statement-expression-in-ks_pcie_.patch
    (git-fixes CVE-2024-47756 bsc#1232185).
  - Update
    patches.suse/PCI-kirin-Fix-buffer-overflow-in-kirin_pcie_parse_po.patch
    (git-fixes CVE-2024-47751 bsc#1232127).
  - Update
    patches.suse/RDMA-cxgb4-Added-NULL-check-for-lookup_atid.patch
    (git-fixes CVE-2024-47749 bsc#1232180).
  - Update
    patches.suse/RDMA-hns-Fix-Use-After-Free-of-rsv_qp-on-HIP08.patch
    (git-fixes CVE-2024-47750 bsc#1232182).
  - Update
    patches.suse/RDMA-hns-Fix-spin_unlock_irqrestore-called-with-IRQs.patch
    (git-fixes CVE-2024-47735 bsc#1232111).
  - Update
    patches.suse/RDMA-iwcm-Fix-WARNING-at_kernel-workqueue.c-check_fl.patch
    (git-fixes CVE-2024-47696 bsc#1231864).
  - Update
    patches.suse/RDMA-rtrs-clt-Reset-cid-to-con_num-1-to-stay-in-boun.patch
    (git-fixes CVE-2024-47695 bsc#1231931).
  - Update
    patches.suse/RDMA-rtrs-srv-Avoid-null-pointer-deref-during-path-e.patch
    (git-fixes CVE-2024-50062 bsc#1232232).
  - Update
    patches.suse/aoe-fix-the-potential-use-after-free-problem-in-more.patch
    (bsc#1218562 CVE-2023-6270 CVE-2024-49982 bsc#1232097).
  - Update
    patches.suse/bpf-Fail-verification-for-sign-extension-of-packet-d.patch
    (git-fixes CVE-2024-47702 bsc#1231924).
  - Update
    patches.suse/bpf-Fix-helper-writes-to-read-only-maps.patch
    (git-fixes CVE-2024-49861 bsc#1232254).
  - Update
    patches.suse/bpf-Fix-use-after-free-in-bpf_uprobe_multi_link_attach.patch
    (git-fixes CVE-2024-47675 bsc#1231926).
  - Update
    patches.suse/bpf-Zero-former-ARG_PTR_TO_-LONG-INT-args-in-case-of.patch
    (git-fixes CVE-2024-47728 bsc#1232076).
  - Update
    patches.suse/bpf-correctly-handle-malformed-BPF_CORE_TYPE_ID_LOCA.patch
    (git-fixes CVE-2024-49850 bsc#1232189).
  - Update
    patches.suse/cachefiles-fix-dentry-leak-in-cachefiles_open_file.patch
    (bsc#1231183 CVE-2024-49870 bsc#1232279).
  - Update
    patches.suse/can-bcm-Clear-bo-bcm_proc_read-after-remove_proc_ent.patch
    (git-fixes CVE-2024-47709 bsc#1232048).
  - Update
    patches.suse/crypto-iaa-Fix-potential-use-after-free-bug.patch
    (git-fixes CVE-2024-47732 bsc#1232109).
  - Update
    patches.suse/cxl-pci-Fix-disabling-memory-if-DVSEC-CXL-Range-does.patch
    (git-fixes CVE-2024-26761 bsc#1230375).
  - Update
    patches.suse/driver-core-Fix-a-potential-null-ptr-deref-in-module.patch
    (git-fixes CVE-2024-47688 bsc#1232009).
  - Update
    patches.suse/driver-core-bus-Fix-double-free-in-driver-API-bus_re.patch
    (stable-fixes CVE-2024-50055 bsc#1232329).
  - Update
    patches.suse/drivers-media-dvb-frontends-rtl2830-fix-an-out-of-bo.patch
    (git-fixes CVE-2024-47697 bsc#1231858).
  - Update
    patches.suse/drivers-media-dvb-frontends-rtl2832-fix-an-out-of-bo.patch
    (git-fixes CVE-2024-47698 bsc#1231859).
  - Update
    patches.suse/drm-amd-display-Add-null-check-for-set_output_gamma-.patch
    (git-fixes CVE-2024-47720 bsc#1232043).
  - Update
    patches.suse/drm-amd-display-Check-null-pointer-before-dereferenc.patch
    (stable-fixes CVE-2024-50049 bsc#1232309).
  - Update
    patches.suse/drm-amd-display-fixed-integer-types-and-null-check-l.patch
    (git-fixes CVE-2024-26767 bsc#1230339).
  - Update
    patches.suse/drm-omapdrm-Add-missing-check-for-alloc_ordered_work.patch
    (git-fixes CVE-2024-49879 bsc#1232349).
  - Update
    patches.suse/drm-v3d-Stop-the-active-perfmon-before-being-destroy.patch
    (git-fixes CVE-2024-50031 bsc#1231947).
  - Update
    patches.suse/efistub-tpm-Use-ACPI-reclaim-memory-for-event-log-to.patch
    (stable-fixes CVE-2024-49858 bsc#1232251).
  - Update
    patches.suse/ep93xx-clock-Fix-off-by-one-in-ep93xx_div_recalc_rat.patch
    (git-fixes CVE-2024-47686 bsc#1232000).
  - Update
    patches.suse/exfat-fix-memory-leak-in-exfat_load_bitmap.patch
    (git-fixes CVE-2024-50013 bsc#1232080).
  - Update
    patches.suse/fbcon-Fix-a-NULL-pointer-dereference-issue-in-fbcon_.patch
    (stable-fixes CVE-2024-50048 bsc#1232310).
  - Update
    patches.suse/firmware-arm_scmi-Fix-double-free-in-OPTEE-transport.patch
    (git-fixes CVE-2024-49853 bsc#1232192).
  - Update patches.suse/firmware_loader-Block-path-traversal.patch
    (git-fixes CVE-2024-47742 bsc#1232126).
  - Update
    patches.suse/i2c-stm32f7-Do-not-prepare-unprepare-clock-during-ru.patch
    (git-fixes CVE-2024-49985 bsc#1232094).
  - Update
    patches.suse/i3c-master-cdns-Fix-use-after-free-vulnerability-in-.patch
    (stable-fixes CVE-2024-50061 bsc#1232263).
  - Update
    patches.suse/i3c-master-svc-Fix-use-after-free-vulnerability-in-s.patch
    (git-fixes CVE-2024-49874 bsc#1232295).
  - Update
    patches.suse/i40e-Fix-XDP-program-unloading-while-removing-the-dr.patch
    (git-fixes CVE-2024-41047 bsc#1228537).
  - Update
    patches.suse/idpf-fix-UAFs-when-destroying-the-queues.patch
    (git-fixes CVE-2024-44932 bsc#1229808).
  - Update
    patches.suse/idpf-fix-memory-leaks-and-crashes-while-performing-a.patch
    (git-fixes CVE-2024-44964 bsc#1230220).
  - Update
    patches.suse/iommufd-Protect-against-overflow-of-ALIGN-during-iov.patch
    (git-fixes CVE-2024-47719 bsc#1231865).
  - Update
    patches.suse/jffs2-prevent-xattr-node-from-overflowing-the-eraseblock.patch
    (git-fixes CVE-2024-38599 bsc#1226848 bsc#1223384).
  - Update patches.suse/jfs-Fix-uaf-in-dbFreeBits.patch (git-fixes
    CVE-2024-49903 bsc#1232362).
  - Update
    patches.suse/jfs-Fix-uninit-value-access-of-new_ea-in-ea_buffer.patch
    (git-fixes CVE-2024-49900 bsc#1232359).
  - Update
    patches.suse/jfs-check-if-leafidx-greater-than-num-leaves-per-dmap-tree.patch
    (git-fixes CVE-2024-49902 bsc#1232378).
  - Update
    patches.suse/jfs-fix-out-of-bounds-in-dbNextAG-and-diAlloc.patch
    (git-fixes CVE-2024-47723 bsc#1232050).
  - Update
    patches.suse/mailbox-bcm2835-Fix-timeout-during-suspend-mode.patch
    (git-fixes CVE-2024-49963 bsc#1232147).
  - Update
    patches.suse/md-Don-t-ignore-suspended-array-in-md_check_recovery-1baa.patch
    (bsc#1219596 CVE-2024-26758 bsc#1230341).
  - Update patches.suse/media-edia-dvbdev-fix-a-use-after-free.patch
    (git-fixes CVE-2024-27043 bsc#1223824 bsc#1218562).
  - Update
    patches.suse/media-i2c-ar0521-Use-cansleep-version-of-gpiod_set_v.patch
    (git-fixes CVE-2024-49961 bsc#1232148).
  - Update
    patches.suse/media-venus-fix-use-after-free-bug-in-venus_remove-d.patch
    (git-fixes CVE-2024-49981 bsc#1232098).
  - Update
    patches.suse/nbd-fix-race-between-timeout-and-normal-completion.patch
    (bsc#1230918 CVE-2024-49855 bsc#1232195).
  - Update
    patches.suse/net-phy-Remove-LED-entry-from-LEDs-list-on-unregiste.patch
    (git-fixes CVE-2024-50023 bsc#1231955).
  - Update
    patches.suse/net-test-for-not-too-small-csum_start-in-virtio_net_.patch
    (git-fixes CVE-2024-49947 bsc#1232162).
  - Update
    patches.suse/nfsd-call-cache_put-if-xdr_reserve_space-returns-NULL.patch
    (git-fixes CVE-2024-47737 bsc#1232056).
  - Update
    patches.suse/nfsd-map-the-EBADMSG-to-nfserr_io-to-avoid-warning.patch
    (git-fixes CVE-2024-49875 bsc#1232333).
  - Update
    patches.suse/nilfs2-fix-potential-null-ptr-deref-in-nilfs_btree_insert.patch
    (git-fixes CVE-2024-47699 bsc#1231916).
  - Update
    patches.suse/nilfs2-fix-potential-oob-read-in-nilfs_btree_check_delete.patch
    (git-fixes CVE-2024-47757 bsc#1232187).
  - Update
    patches.suse/nouveau-dmem-handle-kcalloc-allocation-failure.patch
    (git-fixes CVE-2024-26943 bsc#1230527).
  - Update
    patches.suse/ocfs2-cancel-dqi_sync_work-before-freeing-oinfo.patch
    (git-fixes CVE-2024-49966 bsc#1232141).
  - Update
    patches.suse/ocfs2-fix-null-ptr-deref-when-journal-load-failed.patch
    (git-fixes CVE-2024-49957 bsc#1232152).
  - Update
    patches.suse/ocfs2-fix-possible-null-ptr-deref-in-ocfs2_set_buffer_uptodate.patch
    (git-fixes CVE-2024-49877 bsc#1232339).
  - Update
    patches.suse/ocfs2-remove-unreasonable-unlock-in-ocfs2_read_blocks.patch
    (git-fixes CVE-2024-49965 bsc#1232142).
  - Update
    patches.suse/parport-Proper-fix-for-array-out-of-bounds-access.patch
    (git-fixes CVE-2024-50074 bsc#1232507).
  - Update
    patches.suse/pinctrl-apple-check-devm_kasprintf-returned-value.patch
    (git-fixes CVE-2024-50069 bsc#1232511).
  - Update
    patches.suse/platform-x86-ISST-Fix-the-KASAN-report-slab-out-of-b.patch
    (git-fixes CVE-2024-49886 bsc#1232196).
  - Update
    patches.suse/powercap-intel_rapl-Fix-off-by-one-in-get_rpi.patch
    (git-fixes CVE-2024-49862 bsc#1231871).
  - Update
    patches.suse/resource-fix-region_intersects-vs-add_memory_driver_.patch
    (git-fixes CVE-2024-49878 bsc#1232340).
  - Update
    patches.suse/scsi-fnic-Move-flush_work-initialization-out-of-if-b.patch
    (bsc#1230055 CVE-2024-50025 bsc#1231953).
  - Update
    patches.suse/scsi-lpfc-validate-hdwq-pointers-before-dereferencing-in.patch
    (bsc#1229429 jsc#PED-9899 CVE-2024-49891 bsc#1232218).
  - Update
    patches.suse/scsi-sd-Fix-off-by-one-error-in-sd_read_block_charac.patch
    (bsc#1223848 CVE-2024-47682 bsc#1231856).
  - Update
    patches.suse/serial-protect-uart_port_dtr_rts-in-uart_shutdown-to.patch
    (stable-fixes CVE-2024-50058 bsc#1232285).
  - Update
    patches.suse/tpm-Clean-up-TPM-space-after-command-failure.patch
    (git-fixes CVE-2024-49851 bsc#1232134).
  - Update
    patches.suse/tty-n_gsm-Fix-use-after-free-in-gsm_cleanup_mux.patch
    (stable-fixes CVE-2024-50073 bsc#1232520).
  - Update
    patches.suse/vhost-scsi-null-ptr-dereference-in-vhost_scsi_get_re.patch
    (git-fixes CVE-2024-49863 bsc#1232255).
  - Update
    patches.suse/vhost_vdpa-assign-irq-bypass-producer-token-correctl.patch
    (git-fixes CVE-2024-47748 bsc#1232174).
  - Update patches.suse/vmxnet3-Fix-missing-reserved-tailroom.patch
    (bsc#1226498 CVE-2024-27026 bsc#1223700).
  - Update
    patches.suse/vt-prevent-kernel-infoleak-in-con_font_get.patch
    (git-fixes CVE-2024-50076 bsc#1232505).
  - Update
    patches.suse/wifi-ath11k-fix-array-out-of-bound-access-in-SoC-sta.patch
    (stable-fixes CVE-2024-49930 bsc#1232260).
  - Update
    patches.suse/wifi-ath12k-fix-array-out-of-bound-access-in-SoC-sta.patch
    (stable-fixes CVE-2024-49931 bsc#1232275).
  - Update
    patches.suse/wifi-ath9k_htc-Use-__skb_set_length-for-resetting-ur.patch
    (stable-fixes CVE-2024-49938 bsc#1232552).
  - Update
    patches.suse/wifi-cfg80211-Set-correct-chandef-when-starting-CAC.patch
    (stable-fixes CVE-2024-49937 bsc#1232427).
  - Update
    patches.suse/wifi-iwlwifi-mvm-avoid-NULL-pointer-dereference.patch
    (stable-fixes CVE-2024-49929 bsc#1232253).
  - Update
    patches.suse/wifi-mac80211-don-t-use-rate-mask-for-offchannel-TX-.patch
    (git-fixes CVE-2024-47738 bsc#1232114).
  - Update
    patches.suse/wifi-mac80211-use-two-phase-skb-reclamation-in-ieee8.patch
    (git-fixes CVE-2024-47713 bsc#1232016).
  - Update
    patches.suse/wifi-mt76-mt7915-fix-oops-on-non-dbdc-mt7986.patch
    (git-fixes CVE-2024-47715 bsc#1231860).
  - Update
    patches.suse/wifi-mt76-mt7996-fix-NULL-pointer-dereference-in-mt7.patch
    (git-fixes CVE-2024-47681 bsc#1231855).
  - Update
    patches.suse/wifi-mt76-mt7996-use-hweight16-to-get-correct-tx-ant.patch
    (git-fixes CVE-2024-47714 bsc#1232018).
  - Update
    patches.suse/wifi-mwifiex-Fix-memcpy-field-spanning-write-warning.patch
    (stable-fixes CVE-2024-50008 bsc#1232317).
  - Update
    patches.suse/wifi-rtw88-always-wait-for-both-firmware-loading-att.patch
    (git-fixes CVE-2024-47718 bsc#1232015).
  - Update
    patches.suse/wifi-rtw89-avoid-reading-out-of-bounds-when-loading-.patch
    (stable-fixes CVE-2024-49928 bsc#1232250).
  - Update
    patches.suse/wifi-rtw89-avoid-to-add-interface-to-list-twice-when.patch
    (stable-fixes CVE-2024-49939 bsc#1232381).
  - Update
    patches.suse/wifi-wilc1000-fix-potential-RCU-dereference-issue-in.patch
    (git-fixes CVE-2024-47712 bsc#1232017).
  - Update
    patches.suse/xhci-tegra-fix-checked-USB2-port-number.patch
    (git-fixes CVE-2024-50075 bsc#1232506).
  - commit a270265
  - Update
    patches.suse/i3c-mipi-i3c-hci-Fix-out-of-bounds-access-in-hci_dma.patch
    (git-fixes CVE-2023-52766 bsc#1230620).
  - Update
    patches.suse/media-pci-cx23885-check-cx23885_vdev_init-return.patch
    (stable-fixes CVE-2023-52918 bsc#1232047).
  - Update
    patches.suse/nfc-nci-fix-possible-NULL-pointer-dereference-in-sen.patch
    (git-fixes CVE-2023-52919 bsc#1231988).
  - Update
    patches.suse/ntb-intel-Fix-the-NULL-vs-IS_ERR-bug-for-debugfs_cre.patch
    (git-fixes CVE-2023-52917 bsc#1231849).
  - Update
    patches.suse/tcp-do-not-accept-ACK-of-bytes-we-never-sent.patch
    (CVE-2023-52881 bsc#1225611 bsc#1223384).
  - Update patches.suse/wifi-ath11k-fix-htt-pktlog-locking.patch
    (git-fixes CVE-2023-52800 bsc#1230600).
  - commit 9859953
  - NFSD: Force all NFSv4.2 COPY requests to be synchronous
    (CVE-2024-49974 bsc#1232383).
  - commit 16045fc

++++ multipath-tools:

  - Update to version 0.10.0+106+suse.ffbdb7a:
    * Fix reboot hang if uevent is processed for suspended device
    (bsc#1232063)

++++ ncurses:

  - Add ncurses patch 20241102
    + remove djgpp-specific initialization to binary mode (report/patch by
    Stas Sergeev).
    + add extended-keys for djgpp 2.05 -TD
  - Add ncurses patch 20241026
    + update ms-terminal -TD
    + add ms-terminal-direct -TD
    + correct dimensions in test/popup_msg.c, fixing an overrun (patch by
    Stas Sergeev, cf: 20211219).

++++ systemd:

  - Import commit aee28e4c20a053ea27f8be69f2ea981e43bcb0b6
    aee28e4c20 udev-builtin-path_id: SAS wide ports must have num_phys > 1 (bsc#1231610)
    280989cfa4 core: when switching root remove /run/systemd before executing the binary specified by init= (bsc#1227580)
  - Drop 5003-core-when-switching-root-remove-run-systemd-before-e.patch, this
    patch has been integrated in branch 'SUSE/v256', see above.

++++ libvirt:

  - json: do not call json_tokener_free with NULL
    Fixes potential SEGV in libvirt-nss module
    boo#1232726

++++ passt:

  - Update to version 20241030.ee7d0b6:
    * util: Don't use errno after a successful call in __daemon()
    * udp: Take care of cert-int09-c clang-tidy warning for enum udp_iov_idx
    * treewide: Address cert-err33-c clang-tidy warnings for clock and timer functions
    * treewide: Suppress clang-tidy warning if we already use O_CLOEXEC
    * Makefile: Disable readability-math-missing-parentheses clang-tidy check
    * treewide: Silence cert-err33-c clang-tidy warnings for fprintf()
    * treewide: Comply with CERT C rule ERR33-C for snprintf()
    * Makefile: Exclude qrap.c from clang-tidy checks
    * tcp: unify l2 TCPv4 and TCPv6 queues and structures
    * tcp: set ip and eth headers in l2 tap queues on the fly
    * test: remove obsolete images
    * tcp: cleanup tcp_buf_data_from_sock()
    * tcp: Use runtime tests for TCP_INFO fields
    * tcp: Generalise probing for tcpi_snd_wnd field
    * tcp: Remove compile-time dependency on struct tcp_info version
    * tcp_splice: fcntl(2) returns the size of the pipe, if F_SETPIPE_SZ succeeds
    * tcp_splice: splice() all we have to the writing side, not what we just read
    * tcp: Use structures to construct initial TCP options
    * fwd: Direct inbound spliced forwards to the guest's external address
    * test: Clarify test for spliced inbound transfers
    * passt.1: Clarify and update "Handling of local addresses" section
    * passt.1: Mark --stderr as deprecated more prominently
    * test: Wait for DAD on DHCPv6 addresses
    * test: Explicitly wait for DAD to complete on SLAAC addresses
    * arp: Fix a handful of small warts
    * tcp: Send "empty" handshake ACK before first data segment
    * test: Pass TRACE from run_term() into ./run from_term
    * test/lib/term: Always use printf for messages with escape sequences
    * conf: Add --dns-host option to configure host side nameserver
    * conf: Add command line switch to enable IP_FREEBIND socket option
    * udp: Update UDP checksum using an iovec array
    * tcp: Update TCP checksum using an iovec array
    * checksum: Add an offset argument in csum_iov()
    * pcap: Add an offset argument in pcap_iov()
    * tcp: Use tcp_payload_t rather than tcphdr
    * test: Kernel binary can now be passed via the KERNEL environmental variable
    * inany: Add inany_pton() helper
    * tcp, udp: Make {tcp,udp}_sock_init() take an inany address
    * util, pif: Replace sock_l4() with pif_sock_l4()
    * udp: Don't attempt to get dual-stack sockets in nonsensical cases
    * tcp: Allow checksum to be disabled
    * udp: Allow checksum to be disabled
    * util: Remove possible quadratic behaviour from write_remainder()
    * util: Add helper to write() all of a buffer
    * tcp: Make tcp_update_seqack_wnd()s force_seq parameter explicitly boolean
    * tcp: Simplify ifdef logic in tcp_update_seqack_wnd()
    * tcp: Clean up tcpi_snd_wnd probing
    * tcp: Make some extra functions private
    * tcp: Avoid overlapping memcpy() in DUP_ACK handling
    * tcp: Remove redundant initialisation of iov[TCP_IOV_ETH].iov_base

++++ suse-module-tools:

  - Update to version 16.0.53:
    * udevrules: Add rule to set maximum readahead window
    (jsc#PED-11154)

------------------------------------------------------------------
------------------  2024-11-3  -  Nov 3 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix rendering of SUSE docs
    The SUSE documentation is produced through a conversion
    of the ReST source into docbook. The name kiwi is reserved
    in the index and needs to be referenced as kiwi-ng when
    used as command.
  - Remove tox dependency
    tox was used as sort of a make target to run unit tests
    and more in a python virtualenv. However, since we switched
    everything to poetry it's no longer needed to let tox create
    the python virtual environments. This commit moves the tox
    targets into the Makefile and adapts the github workflow
    files accordingly. In addition the scripts container based
    tests were re-activated and fixed such that they succeed
    again.

++++ kernel-default:

  - fgraph: Change the name of cpuhp state to "fgraph:online"
    (git-fixes).
  - commit 59421b3
  - fgraph: Fix missing unlock in register_ftrace_graph()
    (git-fixes).
  - commit 60d91ed
  - fs/9p: drop inodes immediately on non-.L too (git-fixes).
  - commit 5fa5f19
  - 9p: explicitly deny setlease attempts (git-fixes).
  - commit 474852b
  - fs/9p: fix the cache always being enabled on files with qid
    flags (git-fixes).
  - commit 362152c
  - zonefs: Improve error handling (git-fixes).
  - commit cb63c4c
  - debugfs: fix automount d_fsdata usage (git-fixes).
  - commit 5f78a06
  - splice: fsnotify_access(in), fsnotify_modify(out) on success
    in tee (git-fixes).
  - commit d518e6d
  - splice: fsnotify_access(fd)/fsnotify_modify(fd) in vmsplice
    (git-fixes).
  - commit d630f18
  - splice: always fsnotify_access(in), fsnotify_modify(out)
    on success (git-fixes).
  - commit e7f8947
  - keys: Fix overwrite of key expiration on instantiation
    (git-fixes).
  - commit 323181d
  - audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
    (git-fixes).
  - commit e2db423
  - ocfs2: fix uninit-value in ocfs2_get_block() (git-fixes).
  - commit 426a4b1
  - keys, dns: Allow key types (eg. DNS) to be reclaimed immediately
    on expiry (git-fixes).
  - commit ce262a7
  - Revert "KEYS: encrypted: Add check for strsep" (git-fixes).
  - commit 7aa308c
  - ubifs: add check for crypto_shash_tfm_digest (git-fixes).
  - commit ea9ba15
  - ubifs: dbg_orphan_check: Fix missed key type checking
    (git-fixes).
  - commit 465ad1a
  - ubifs: Fix adding orphan entry twice for the same inode
    (git-fixes).
  - commit 93096ab
  - Revert "ubifs: ubifs_symlink: Fix memleak of inode->i_link in
    error path" (git-fixes).
  - commit 0a7c17d
  - ubifs: Fix unattached xattr inode if powercut happens after
    deleting (git-fixes).
  - commit 6c90268
  - audit: don't take task_lock() in audit_exe_compare() code path
    (git-fixes).
  - Refresh patches.suse/vfs-add-super_operations-get_inode_dev.
  - commit d4e23ef
  - uprobes: fix kernel info leak via "[uprobes]" vma (bsc#1231114
    CVE-2024-46828).
  - uprobes: turn xol_area->pages into xol_area->page (bsc#1231114).
  - uprobes: introduce the global struct vm_special_mapping
    xol_mapping (bsc#1231114).
  - commit 4f9954c
  - sched: sch_cake: fix bulk flow accounting logic for host
    fairness (bsc#1231114 CVE-2024-46828).
  - commit ad42d5f
  - xfs: fix finding a last resort AG in xfs_filestream_pick_ag
    (git-fixes).
  - commit a10af4c

++++ kernel-rt:

  - fgraph: Change the name of cpuhp state to "fgraph:online"
    (git-fixes).
  - commit 59421b3
  - fgraph: Fix missing unlock in register_ftrace_graph()
    (git-fixes).
  - commit 60d91ed
  - fs/9p: drop inodes immediately on non-.L too (git-fixes).
  - commit 5fa5f19
  - 9p: explicitly deny setlease attempts (git-fixes).
  - commit 474852b
  - fs/9p: fix the cache always being enabled on files with qid
    flags (git-fixes).
  - commit 362152c
  - zonefs: Improve error handling (git-fixes).
  - commit cb63c4c
  - debugfs: fix automount d_fsdata usage (git-fixes).
  - commit 5f78a06
  - splice: fsnotify_access(in), fsnotify_modify(out) on success
    in tee (git-fixes).
  - commit d518e6d
  - splice: fsnotify_access(fd)/fsnotify_modify(fd) in vmsplice
    (git-fixes).
  - commit d630f18
  - splice: always fsnotify_access(in), fsnotify_modify(out)
    on success (git-fixes).
  - commit e7f8947
  - keys: Fix overwrite of key expiration on instantiation
    (git-fixes).
  - commit 323181d
  - audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
    (git-fixes).
  - commit e2db423
  - ocfs2: fix uninit-value in ocfs2_get_block() (git-fixes).
  - commit 426a4b1
  - keys, dns: Allow key types (eg. DNS) to be reclaimed immediately
    on expiry (git-fixes).
  - commit ce262a7
  - Revert "KEYS: encrypted: Add check for strsep" (git-fixes).
  - commit 7aa308c
  - ubifs: add check for crypto_shash_tfm_digest (git-fixes).
  - commit ea9ba15
  - ubifs: dbg_orphan_check: Fix missed key type checking
    (git-fixes).
  - commit 465ad1a
  - ubifs: Fix adding orphan entry twice for the same inode
    (git-fixes).
  - commit 93096ab
  - Revert "ubifs: ubifs_symlink: Fix memleak of inode->i_link in
    error path" (git-fixes).
  - commit 0a7c17d
  - ubifs: Fix unattached xattr inode if powercut happens after
    deleting (git-fixes).
  - commit 6c90268
  - audit: don't take task_lock() in audit_exe_compare() code path
    (git-fixes).
  - Refresh patches.suse/vfs-add-super_operations-get_inode_dev.
  - commit d4e23ef
  - uprobes: fix kernel info leak via "[uprobes]" vma (bsc#1231114
    CVE-2024-46828).
  - uprobes: turn xol_area->pages into xol_area->page (bsc#1231114).
  - uprobes: introduce the global struct vm_special_mapping
    xol_mapping (bsc#1231114).
  - commit 4f9954c
  - sched: sch_cake: fix bulk flow accounting logic for host
    fairness (bsc#1231114 CVE-2024-46828).
  - commit ad42d5f
  - xfs: fix finding a last resort AG in xfs_filestream_pick_ag
    (git-fixes).
  - commit a10af4c

++++ python-blinker:

  - Add missing build require pallets_sphinx_themes
    to fix build error under Leap.

++++ python-legacy-cgi:

  - Add %{?sle15_python_module_pythons}

++++ vim:

  - update to 9.1.0836
    * 9.1.0836: The vimtutor can be improved
    * 9.1.0835: :setglobal doesn't work properly for 'ffu' and 'tsrfu'
    * 9.1.0834: tests: 2html test fails
    * 9.1.0833: CI: recent ASAN changes do not work for indent tests
    * 9.1.0832: :set doesn't work for 'cot' and 'bkc' after :setlocal
    * runtime(doc): update help-toc description
    * runtime(2html): Make links use color scheme colors in TOhtml
    * 9.1.0831: 'findexpr' can't be used as lambad or Funcref
    * Filelist: include helptoc package
    * runtime(doc): include a TOC Vim9 plugin
    * Filelist: ignore .git-blame-ignore-revs
    * 9.1.0830: using wrong highlight group for spaces for popupmenu
    * runtime(typst): synchronize updates from the upstream typst.vim
    * git: ignore reformatting commit for git-blame (after v9.1.0829)
    * 9.1.0829: Vim source code uses a mix of tabs and spaces
    * 9.1.0828: string_T struct could be used more often
    * 9.1.0827: CI: tests can be improved
    * runtime(doc): remove stray sentence in pi_netrw.txt
    * 9.1.0826: filetype: sway files are not recognized
    * runtime(doc): Include netrw-gp in TOC
    * runtime(doc): mention 'iskeyword' at :h charclass()
    * runtime(doc): update help tags
    * 9.1.0825: compile error for non-diff builds
    * runtime(netrw): fix E874 when browsing remote directory which contains `~` character
    * runtime(doc): update coding style documentation
    * runtime(debversions): Add plucky (25.04) as Ubuntu release name
    * 9.1.0824: too many strlen() calls in register.c
    * 9.1.0823: filetype: Zephyr overlay files not recognized
    * runtime(doc): Clean up minor formatting issues for builtin functions
    * runtime(netrw): make :Launch/Open autoloadable
    * runtime(netrw): fix regression with x mapping on Cygwin
    * runtime(netrw): fix filetype detection for remote files
    * 9.1.0822: topline might be changed in diff mode unexpectedly
    * CI: huge linux builds should also run syntax & indent tests
    * 9.1.0821: 'findexpr' completion doesn't set v:fname to cmdline argument
    * 9.1.0820: tests: Mac OS tests are too flaky
    * runtime(awk): Highlight more awk comments in syntax script
    * runtime(netrw): add missing change for s:redir()
    * 9.1.0819: tests: using findexpr and imported func not tested
    * runtime(netrw): improve netrw's open-handling further
    * runtime(netrw): fix syntax error in netrwPlugin.vim
    * runtime(netrw): simplify gx file handling
    * 9.1.0818: some global functions are only used in single files
    * 9.1.0817: termdebug: cannot evaluate expr in a popup
    * runtime(defaults): Detect putty terminal and switch to dark background
    * 9.1.0816: tests: not clear what tests cause asan failures
    * runtime(doc): Remove some completed items from todo.txt
    * 9.1.0815: "above" virtual text causes wrong 'colorcolumn' position
    * runtime(syntax-tests): tiny vim fails because of line-continuation
    * 9.1.0814: mapset() may remove unrelated mapping
    * 9.1.0813: no error handling with setglobal and number types
    * 9.1.0812: Coverity warns about dereferencing NULL ptr
    * 9.1.0811: :find expansion does not consider 'findexpr'
    * 9.1.0810: cannot easily adjust the |:find| command
    * 9.1.0809: filetype: petalinux config files not recognized
    * 9.1.0808: Terminal scrollback doesn't shrink when decreasing 'termwinscroll'
    * 9.1.0807: tests: having 'nolist' in modelines isn't always desired
    * 9.1.0806: tests: no error check when setting global 'briopt'
    * 9.1.0805: tests: minor issues in gen_opt_test.vim
    * 9.1.0804: tests: no error check when setting global 'cc'
    * 9.1.0803: tests: no error check when setting global 'isk'
    * 9.1.0802: tests: no error check when setting global 'fdm' to empty value
    * 9.1.0801: tests: no error check when setting global 'termwinkey'
    * 9.1.0800: tests: no error check when setting global 'termwinsize'
    * runtime(doc): :ownsyntax also resets 'spelloptions'
    * 9.1.0799: tests: gettwinvar()/gettabwinvar() tests are not comprehensive
    * runtime(doc): Fix wrong Mac default options
    * 9.1.0798: too many strlen() calls in cmdhist.c
    * 9.1.0797: testing of options can be further improved
    * 9.1.0796: filetype: libtool files are not recognized
    * (typst): add folding to typst ftplugin
    * runtime(netrw): deprecate and remove netrwFileHandlers#Invoke()
    * 9.1.0795: filetype: Vivado memory info file are not recognized
    * 9.1.0794: tests: tests may fail on Windows environment
    * runtime(doc): improve the :colorscheme documentation
    * 9.1.0793: xxd: -e does add one extra space
    * 9.1.0792: tests: Test_set_values() is not comprehensive enough
    * runtime(swayconfig): add flag for bindsym/bindcode to syntax script
    * 9.1.0791: tests: errors in gen_opt_test.vim are not shown
    * runtime(compiler): check for compile_commands in build dirs for cppcheck
    * 9.1.0790: Amiga: AmigaOS4 build should use default runtime (newlib)
    * runtime(help): Update help syntax
    * runtime(help): fix end of sentence highlight in code examples
    * runtime(jinja): Support jinja syntax as secondary filetype
    * 9.1.0789: tests: ':resize + 5' has invalid space after '+'
    * 9.1.0788: <CSI>27;<mod>u is not decoded to literal Escape in kitty/foot
    * 9.1.0787: cursor position changed when using hidden terminal
    * 9.1.0786: tests: quickfix update test does not test location list
    * runtime(doc): add some docs for file-watcher programs
    * CI: uploading failed screendumps still fails on Cirrus CI
    * 9.1.0785: cannot preserve error position when setting quickfix list
    * 9.1.0784: there are several problems with python 3.13
    * 9.1.0783: 'spell' option setting has problems
    * 9.1.0782: tests: using wrong neomuttlog file name
    * runtime(doc): add preview flag to statusline example
    * 9.1.0781: tests: test_filetype fails
    * 9.1.0780: MS-Windows: incorrect Win32 error checking
    * 9.1.0779: filetype: neomuttlog files are not recognized
    * 9.1.0778: filetype: lf config files are not recognized
    * runtime(comment): fix commment toggle with mixed tabs & spaces
    * runtime(misc): Use consistent "Vim script" spelling
    * runtime(gleam): add ftplugin for gleam files
    * runtime(doc): link help-writing from write-local-help
    * 9.1.0777: filetype: Some upstream php files are not recognized
    * runtime(java): Define javaBlockStart and javaBlockOtherStart hl groups
    * runtime(doc): mention conversion rules for remote_expr()
    * runtime(tutor): Fix missing :s command in spanish translation section 4.4
    * 9.1.0776: test_strftime may fail because of missing TZ data
    * translation(am): Add Armenian language translation
    * 9.1.0775: tests: not enough tests for setting options
    * 9.1.0774: "shellcmdline" doesn't work with getcompletion()
    * 9.1.0773: filetype: some Apache files are not recognized
    * 9.1.0772: some missing changes from v9.1.0771
    * 9.1.0771: completion attribute hl_group is confusing
    * 9.1.0770: current command line completion is a bit limited
    * 9.1.0769: filetype: MLIR files are not recognized
    * 9.1.0768: MS-Windows: incorrect cursor position when restoring screen
    * runtime(nasm): Update nasm syntax script
    * 9.1.0767: A condition is always true in ex_getln.c
    * runtime(skill): Update syntax file to fix string escapes
    * runtime(help): highlight CTRL-<Key> correctly
    * runtime(doc): add missing usr_52 entry to toc
    * 9.1.0766: too many strlen() calls in ex_getln.c
    * runtime(doc): correct `vi` registers 1-9 documentation error
    * 9.1.0765: No test for patches 6.2.418 and 7.3.489
    * runtime(spec): set comments and commentstring options
    * NSIS: Include libgcc_s_sjlj-1.dll again
    * runtime(doc): clarify the effect of 'startofline' option
    * 9.1.0764: [security]: use-after-free when closing a buffer
    * runtime(vim): Update base-syntax file, improve class, enum and interface highlighting
    * 9.1.0763: tests: cannot run single syntax tests
    * 9.1.0762: 'cedit', 'termwinkey' and 'wildchar' may not be parsed correctly
    * 9.1.0761: :cd completion fails on Windows with backslash in path
    * 9.1.0760: tests: no error reported, if gen_opt_test.vim fails
    * 9.1.0759: screenpos() may return invalid position
    * runtime(misc): unset compiler in various ftplugins
    * runtime(doc): update formatting and syntax
    * runtime(compiler): add cppcheck linter compiler plugin
    * runtime(doc): Fix style in documents
    * runtime(doc): Fix to two-space convention in user manual
    * runtime(comment): consider &tabstop in lines after whitespace indent
    * 9.1.0758: it's possible to set an invalid key to 'wildcharm'
    * runtime(java): Manage circularity for every :syn-included syntax file
    * 9.1.0757: tests: messages files contains ANSI escape sequences
    * 9.1.0756: missing change from patch v9.1.0754
    * 9.1.0755: quickfix list does not handle hardlinks well
    * runtime(doc): 'filetype', 'syntax' and 'keymap' only allow alphanumeric + some characters
    * runtime(systemd): small fixes to &keywordprg in ftplugin
    * CI: macos-12 runner is being sunset, switch to 13
    * 9.1.0754: fixed order of items in insert-mode completion menu
    * runtime(comment): commenting might be off by one column
    * 9.1.0753: Wrong display when typing in diff mode with 'smoothscroll'
    * 9.1.0752: can set 'cedit' to an invalid value
    * runtime(doc): add `usr` tag to usr_toc.txt
    * 9.1.0751: Error callback for term_start() not used
    * 9.1.0750: there are some Win9x legacy references
    * runtime(java): Recognise the CommonMark form (///) of Javadoc comments
    * 9.1.0749: filetype: http files not recognized
    * runtime(comment): fix syntax error
    * CI: uploading failed screendump tests does not work Cirrus
    * 9.1.0748: :keep* commmands are sometimes misidentified as :k
    * runtime(indent): allow matching negative numbers for gnu indent config file
    * runtime(comment): add gC mapping to (un)comment rest of line
    * 9.1.0747: various typos in repo found
    * 9.1.0746: tests: Test_halfpage_longline() fails on large terminals
    * runtime(doc): reformat gnat example
    * runtime(doc): reformat ada_standard_types section
    * 9.1.0745: filetype: bun and deno history files not recognized
    * runtime(glvs): Correct the tag name of glvs-autoinstal
    * runtime(doc): include short form for :earlier/:later
    * runtime(doc): remove completed TODO
    * 9.1.0744: filetype: notmuch configs are not recognised
    * 9.1.0743: diff mode does not handle overlapping diffs correctly
    * runtime(glvs): fix a few issues
    * runtime(doc): Fix typo in :help :command-modifiers
    * 9.1.0742: getcmdprompt() implementation can be improved
    * runtime(docs): update `:set?` command behavior table
    * runtime(doc): update vim90 to vim91 in docs
    * runtime(doc): fix typo in :h dos-colors
    * 9.1.0741: No way to get prompt for input()/confirm()
    * runtime(doc): fix typo in version9.txt nrformat -> nrformats
    * runtime(rmd,rrst): 'fex' option not properly restored
    * runtime(netrw): remove extraneous closing bracket
    * 9.1.0740: incorrect internal diff with empty file
    * 9.1.0739: [security]: use-after-free in ex_getln.c
    * runtime(filetype): tests: Test_filetype_detection() fails
    * runtime(dist): do not output a message if executable is not found
    * 9.1.0738: filetype: rapid files are not recognized
    * runtime(modconf): remove erroneous :endif in ftplugin
    * runtime(lyrics): support multiple timestamps in syntax script
    * runtime(java): Optionally recognise _module_ import declarations
    * runtime(vim): Update base-syntax, improve folding function matches
    * CI: upload failed screendump tests also for Cirrus
    * 9.1.0737: tests: screendump tests may require a bit more time
    * runtime(misc): simplify keywordprg in various ftplugins
    * runtime(java): Optionally recognise all primitive constants in _switch-case_ labels
    * runtime(zsh,sh): set and unset compiler in ftplugin
    * runtime(netrw): using inefficient highlight pattern for 'mf'
    * 9.1.0736: Unicode tables are outdated
    * 9.1.0735: filetype: salt files are not recognized
    * 9.1.0734: filetype: jinja files are not recognized
    * runtime(zathurarc): add double-click-follow to syntax script
    * translation(ru): Updated messages translation
    * translation(it): updated xxd man page
    * translation(ru): updated xxd man page
    * 9.1.0733: keyword completion does not work with fuzzy
    * 9.1.0732: xxd: cannot use -b and -i together
    * runtime(java): Highlight javaConceptKind modifiers with StorageClass
    * runtime(doc): reword and reformat how to use defaults.vim
    * 9.1.0731: inconsistent case sensitive extension matching
    * runtime(vim): Update base-syntax, match Vim9 bool/null literal args to :if/:while/:return
    * runtime(netrw): delete confirmation not strict enough
    * 9.1.0730: Crash with cursor-screenline and narrow window
    * 9.1.0729: Wrong cursor-screenline when resizing window
    * 9.1.0728: [security]: heap-use-after-free in garbage collection with location list user data
    * runtime(doc): clarify the effect of the timeout for search()-functions
    * runtime(idlang): update syntax script
    * runtime(spec): Recognize epoch when making spec changelog in ftplugin
    * runtime(spec): add file triggers to syntax script
    * 9.1.0727: too many strlen() calls in option.c
    * runtime(make): add compiler/make.vim to reset compiler plugin settings
    * runtime(java): Recognise all available standard doclet tags
    * 9.1.0726: not using correct python3 API with dynamic linking
    * runtime(dosini): Update syntax script, spellcheck comments only
    * runtime(doc): Revert outdated comment in completeopt's fuzzy documentation
    * 9.1.0725: filetype: swiftinterface files are not recognized
    * runtime(pandoc): Update compiler plugin to use actual 'spelllang'
    * runtime(groff): Add compiler plugin for groff
    * 9.1.0724: if_python: link error with python 3.13 and stable ABI
    * 9.1.0723: if_python: dynamic linking fails with python3 >= 3.13
    * 9.1.0722: crash with large id in text_prop interface
    * 9.1.0721: tests: test_mksession does not consider XDG_CONFIG_HOME
    * runtime(glvs): update GetLatestVimScripts plugin
    * runtime(doc): Fix typo in :help :hide text
    * runtime(doc): buffers can be re-used
    * 9.1.0720: Wrong breakindentopt=list:-1 with multibyte or TABs
    * 9.1.0719: Resetting cell widths can make 'listchars' or 'fillchars' invalid
    * runtime(doc): Update version9.txt and mention $MYVIMDIR

------------------------------------------------------------------
------------------  2024-11-2  -  Nov 2 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - static_call: Handle module init failure correctly in
    static_call_del_module() (bsc#1232083 CVE-2024-50002).
  - commit af953b9
  - ALSA: hda/realtek: Refactor and simplify Samsung Galaxy Book
    init (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-quirk-for-Huawei-MateBook-13-KL.patch.
  - commit 98d4026
  - ALSA: hda/realtek: Enable mic on Vaio VJFH52 (stable-fixes).
  - commit 7075c22
  - ALSA: hda/realtek: tas2781: Fix ROG ALLY X audio (stable-fixes).
  - commit e26a542
  - ALSA: hda/realtek: Fix headset mic on TUXEDO Stellaris 16 Gen6
    mb1 (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic on TUXEDO Gemini 17 Gen3
    (stable-fixes).
  - ALSA: usb-audio: Add quirks for Dell WD19 dock (stable-fixes).
  - ASoC: dapm: fix bounds checker error in dapm_widget_list_create
    (git-fixes).
  - ASoC: Intel: sst: Fix used of uninitialized ctx to log an error
    (git-fixes).
  - ASoC: Intel: sst: Support LPE0F28 ACPI HID (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla
    10 tablet (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add support for non ACPI instantiated
    codec (stable-fixes).
  - ASoC: codecs: rt5640: Always disable IRQs from
    rt5640_cancel_work() (stable-fixes).
  - ALSA: hda/realtek: Add subwoofer quirk for Infinix ZERO BOOK 13
    (stable-fixes).
  - ALSA: hda/realtek: Limit internal Mic boost on Dell platform
    (stable-fixes).
  - commit 0d350ca
  - drm/mediatek: Fix get efuse issue for MT8188 DPTX (git-fixes).
  - drm/amd/pm: Vangogh: Fix kernel memory out of bounds write
    (git-fixes).
  - ACPI: CPPC: Make rmw_lock a raw_spin_lock (git-fixes).
  - firmware: arm_sdei: Fix the input parameter of
    cpuhp_remove_state() (git-fixes).
  - kasan: Fix Software Tag-Based KASAN with GCC (git-fixes).
  - commit 2a07e04
  - Bluetooth: hci: fix null-ptr-deref in hci_read_supported_codecs
    (git-fixes).
  - wifi: cfg80211: clear wdev->cqm_config pointer on free
    (git-fixes).
  - Revert "wifi: iwlwifi: remove retry loops in start" (git-fixes).
  - wifi: iwlwifi: mvm: don't add default link in fw restart flow
    (git-fixes).
  - wifi: iwlwifi: mvm: Fix response handling in
    iwl_mvm_send_recovery_cmd() (git-fixes).
  - wifi: iwlwifi: mvm: don't leak a link on AP removal (git-fixes).
  - wifi: ath11k: Fix invalid ring usage in full monitor mode
    (git-fixes).
  - wifi: ath10k: Fix memory leak in management tx (git-fixes).
  - wifi: brcm80211: BRCM_TRACING should depend on TRACING
    (git-fixes).
  - wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys
    (git-fixes).
  - wifi: mac80211: do not pass a stopped vif to the driver in
    .get_txpower (git-fixes).
  - mac80211: MAC80211_MESSAGE_TRACING should depend on TRACING
    (git-fixes).
  - wifi: iwlegacy: Fix "field-spanning write" warning in
    il_enqueue_hcmd() (git-fixes).
  - ASoC: cs42l51: Fix some error handling paths in cs42l51_probe()
    (git-fixes).
  - platform/x86: dell-wmi: Ignore suspend notifications
    (stable-fixes).
  - ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix
    initial lid detection issue (stable-fixes).
  - ACPI: resource: Add LG 16T90SP to irq1_level_low_skip_override[]
    (stable-fixes).
  - drm/amd/display: Disable PSR-SU on Parade 08-01 TCON too
    (stable-fixes).
  - drm/amd: Guard against bad data for ATIF ACPI method
    (git-fixes).
  - usb: gadget: f_uac2: fix return value for UAC2_ATTRIBUTE_STRING
    store (git-fixes).
  - accel/qaic: Fix the for loop used to walk SG table (git-fixes).
  - drm/amd/amdgpu: Fix double unlock in amdgpu_mes_add_ring
    (git-fixes).
  - drm/msm/dpu: don't always program merge_3d block (git-fixes).
  - drm/msm: Allocate memory for disp snapshot with kvzalloc()
    (git-fixes).
  - drm/msm: Avoid NULL dereference in msm_disp_state_print_regs()
    (git-fixes).
  - drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate
    calculation (git-fixes).
  - drm/msm/dsi: improve/fix dsc pclk calculation (git-fixes).
  - drm/msm/dpu: check for overflow in _dpu_crtc_setup_lm_bounds()
    (git-fixes).
  - drm/msm/dpu: move CRTC resource assignment to
    dpu_encoder_virt_atomic_check (git-fixes).
  - drm/msm/dpu: make sure phys resources are properly initialized
    (git-fixes).
  - platform/x86: dell-sysman: add support for alienware products
    (stable-fixes).
  - drm/vboxvideo: Replace fake VLA at end of
    vbva_mouse_pointer_shape with real VLA (stable-fixes).
  - usb: gadget: f_uac2: fix non-newline-terminated function name
    (stable-fixes).
  - usb: gadget: f_uac2: Replace snprintf() with the safer
    scnprintf() variant (stable-fixes).
  - commit 09f40f7

++++ kernel-rt:

  - static_call: Handle module init failure correctly in
    static_call_del_module() (bsc#1232083 CVE-2024-50002).
  - commit af953b9
  - ALSA: hda/realtek: Refactor and simplify Samsung Galaxy Book
    init (stable-fixes).
  - Refresh
    patches.suse/ALSA-hda-realtek-Add-quirk-for-Huawei-MateBook-13-KL.patch.
  - commit 98d4026
  - ALSA: hda/realtek: Enable mic on Vaio VJFH52 (stable-fixes).
  - commit 7075c22
  - ALSA: hda/realtek: tas2781: Fix ROG ALLY X audio (stable-fixes).
  - commit e26a542
  - ALSA: hda/realtek: Fix headset mic on TUXEDO Stellaris 16 Gen6
    mb1 (stable-fixes).
  - ALSA: hda/realtek: Fix headset mic on TUXEDO Gemini 17 Gen3
    (stable-fixes).
  - ALSA: usb-audio: Add quirks for Dell WD19 dock (stable-fixes).
  - ASoC: dapm: fix bounds checker error in dapm_widget_list_create
    (git-fixes).
  - ASoC: Intel: sst: Fix used of uninitialized ctx to log an error
    (git-fixes).
  - ASoC: Intel: sst: Support LPE0F28 ACPI HID (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add DMI quirk for Vexia Edu Atla
    10 tablet (stable-fixes).
  - ASoC: Intel: bytcr_rt5640: Add support for non ACPI instantiated
    codec (stable-fixes).
  - ASoC: codecs: rt5640: Always disable IRQs from
    rt5640_cancel_work() (stable-fixes).
  - ALSA: hda/realtek: Add subwoofer quirk for Infinix ZERO BOOK 13
    (stable-fixes).
  - ALSA: hda/realtek: Limit internal Mic boost on Dell platform
    (stable-fixes).
  - commit 0d350ca
  - drm/mediatek: Fix get efuse issue for MT8188 DPTX (git-fixes).
  - drm/amd/pm: Vangogh: Fix kernel memory out of bounds write
    (git-fixes).
  - ACPI: CPPC: Make rmw_lock a raw_spin_lock (git-fixes).
  - firmware: arm_sdei: Fix the input parameter of
    cpuhp_remove_state() (git-fixes).
  - kasan: Fix Software Tag-Based KASAN with GCC (git-fixes).
  - commit 2a07e04
  - Bluetooth: hci: fix null-ptr-deref in hci_read_supported_codecs
    (git-fixes).
  - wifi: cfg80211: clear wdev->cqm_config pointer on free
    (git-fixes).
  - Revert "wifi: iwlwifi: remove retry loops in start" (git-fixes).
  - wifi: iwlwifi: mvm: don't add default link in fw restart flow
    (git-fixes).
  - wifi: iwlwifi: mvm: Fix response handling in
    iwl_mvm_send_recovery_cmd() (git-fixes).
  - wifi: iwlwifi: mvm: don't leak a link on AP removal (git-fixes).
  - wifi: ath11k: Fix invalid ring usage in full monitor mode
    (git-fixes).
  - wifi: ath10k: Fix memory leak in management tx (git-fixes).
  - wifi: brcm80211: BRCM_TRACING should depend on TRACING
    (git-fixes).
  - wifi: mac80211: skip non-uploaded keys in ieee80211_iter_keys
    (git-fixes).
  - wifi: mac80211: do not pass a stopped vif to the driver in
    .get_txpower (git-fixes).
  - mac80211: MAC80211_MESSAGE_TRACING should depend on TRACING
    (git-fixes).
  - wifi: iwlegacy: Fix "field-spanning write" warning in
    il_enqueue_hcmd() (git-fixes).
  - ASoC: cs42l51: Fix some error handling paths in cs42l51_probe()
    (git-fixes).
  - platform/x86: dell-wmi: Ignore suspend notifications
    (stable-fixes).
  - ACPI: button: Add DMI quirk for Samsung Galaxy Book2 to fix
    initial lid detection issue (stable-fixes).
  - ACPI: resource: Add LG 16T90SP to irq1_level_low_skip_override[]
    (stable-fixes).
  - drm/amd/display: Disable PSR-SU on Parade 08-01 TCON too
    (stable-fixes).
  - drm/amd: Guard against bad data for ATIF ACPI method
    (git-fixes).
  - usb: gadget: f_uac2: fix return value for UAC2_ATTRIBUTE_STRING
    store (git-fixes).
  - accel/qaic: Fix the for loop used to walk SG table (git-fixes).
  - drm/amd/amdgpu: Fix double unlock in amdgpu_mes_add_ring
    (git-fixes).
  - drm/msm/dpu: don't always program merge_3d block (git-fixes).
  - drm/msm: Allocate memory for disp snapshot with kvzalloc()
    (git-fixes).
  - drm/msm: Avoid NULL dereference in msm_disp_state_print_regs()
    (git-fixes).
  - drm/msm/dsi: fix 32-bit signed integer extension in pclk_rate
    calculation (git-fixes).
  - drm/msm/dsi: improve/fix dsc pclk calculation (git-fixes).
  - drm/msm/dpu: check for overflow in _dpu_crtc_setup_lm_bounds()
    (git-fixes).
  - drm/msm/dpu: move CRTC resource assignment to
    dpu_encoder_virt_atomic_check (git-fixes).
  - drm/msm/dpu: make sure phys resources are properly initialized
    (git-fixes).
  - platform/x86: dell-sysman: add support for alienware products
    (stable-fixes).
  - drm/vboxvideo: Replace fake VLA at end of
    vbva_mouse_pointer_shape with real VLA (stable-fixes).
  - usb: gadget: f_uac2: fix non-newline-terminated function name
    (stable-fixes).
  - usb: gadget: f_uac2: Replace snprintf() with the safer
    scnprintf() variant (stable-fixes).
  - commit 09f40f7

++++ llvm19:

  - Update to version 19.1.3.
    * This release contains bug-fixes for the LLVM 19.1.0 release.
    This release is API and ABI compatible with 19.1.0.
  - Rebase patches:
    * llvm-do-not-install-static-libraries.patch
    * llvm-suse-implicit-gnu.patch
  - Patch llvm-fix-build-failure-on-ppc64le.patch landed upstream.

------------------------------------------------------------------
------------------  2024-11-1  -  Nov 1 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix make build target
    Move the actions done by the tox target into the
    build target and call them there in a clean and easy
    to spot sequence. There is no need to call tox to
    prepare for the package submission, instead the
    checks and poetry runs to prepare for the package
    target should be called directly as part of the
    build target. In the future we might get rid of
    tox completely.
  - Bump version: 10.1.17 → 10.1.18

++++ grub2:

  - Fix grub.cfg is loaded from an unexpected fallback directory instead of the
    root directory during PXE boot when grub is loaded from the tftp root
    directory (bsc#1232391)
    * 0001-kern-main-Fix-cmdpath-in-root-directory.patch
    * grub2.spec: Refine PPC grub.elf early config to derive root from cmdpath
    directly, avoiding the unneeded search

++++ kernel-default:

  - drm/amd/display: Check null pointers before using them (CVE-2024-49922 bsc#1232374)
  - commit 342005c
  - drm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream' (CVE-2024-49912 bsc#1232367)
  - commit 2394db2
  - drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func (CVE-2024-49911 bsc#1232366)
  - commit 6c83ea7
  - drm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags (CVE-2024-49923 bsc#1232361)
  - commit 3759560
  - drm/amd/display: Fix index out of bounds in DCN30 degamma hardware format translation (CVE-2024-49895 bsc#1232352)
  - commit f36c162
  - drm/amd/display: Initialize denominators' default to 1 (CVE-2024-49899 bsc#1232358)
  - commit 282fa51
  - drm/amd/display: Check phantom_stream before it is used (CVE-2024-49897 bsc#1232355)
  - commit d3fcaed
  - drm/amd/display: Fix index out of bounds in degamma hardware format translation (CVE-2024-49894 bsc#1232354)
  - commit db76ccb
  - drm/amd/display: Add NULL check for function pointer in dcn32_set_output_transfer_func (CVE-2024-49909 bsc#1232337)
  - commit 11facc9
  - drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream (CVE-2024-49913 bsc#1232307)
  - commit 60f7853
  - drm/msm/adreno: Assign msm_gpu->pdev earlier to avoid nullptrs (CVE-2024-49901 bsc#1232305)
  - commit 69be7bb
  - RAS/AMD/ATL: Implement DF 4.5 NP2 denormalization (jsc#PED-10559).
  - commit 52d40f4
  - RAS/AMD/ATL: Validate address map when information is gathered (jsc#PED-10559).
  - commit 94e412f
  - RAS/AMD/ATL: Expand helpers for adding and removing base and hole (jsc#PED-10559).
  - commit 2b18348
  - RAS/AMD/ATL: Read DRAM hole base early (jsc#PED-10559).
  - commit e1cf5b5
  - RAS/AMD/ATL: Add amd_atl pr_fmt() prefix (jsc#PED-10559).
  - commit 17f78f9
  - drm/amd/display: Check null pointer before try to access it (bsc#1232332 CVE-2024-49906)
  - commit f2b2892
  - drm/amd/display: Add null check for pipe_ctx->plane_state in (bsc#1232369 CVE-2024-49914)
  - commit c236474
  - drm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (bsc#1232335 CVE-2024-49908)
  - commit 64a943f
  - drm/amd/display: Check null pointers before using dc->clk_mgr (bsc#1232334 CVE-2024-49907)
  - commit 366c63a
  - RDMA/bnxt_re: synchronize the qp-handle table array (git-fixes)
  - commit 866dbc5
  - RDMA/bnxt_re: Fix the usage of control path spin locks (git-fixes)
  - commit c834f25
  - RDMA/mlx5: Round max_rd_atomic/max_dest_rd_atomic up instead of down (git-fixes)
  - commit 3c270f2
  - RDMA/cxgb4: Dump vendor specific QP details (git-fixes)
  - commit 587d3b0
  - ext4: fix access to uninitialised lock in fc replay path (CVE-2024-50014 bsc#1232446)
  - commit 1b2ba45

++++ kernel-rt:

  - drm/amd/display: Check null pointers before using them (CVE-2024-49922 bsc#1232374)
  - commit 342005c
  - drm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream' (CVE-2024-49912 bsc#1232367)
  - commit 2394db2
  - drm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func (CVE-2024-49911 bsc#1232366)
  - commit 6c83ea7
  - drm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags (CVE-2024-49923 bsc#1232361)
  - commit 3759560
  - drm/amd/display: Fix index out of bounds in DCN30 degamma hardware format translation (CVE-2024-49895 bsc#1232352)
  - commit f36c162
  - drm/amd/display: Initialize denominators' default to 1 (CVE-2024-49899 bsc#1232358)
  - commit 282fa51
  - drm/amd/display: Check phantom_stream before it is used (CVE-2024-49897 bsc#1232355)
  - commit d3fcaed
  - drm/amd/display: Fix index out of bounds in degamma hardware format translation (CVE-2024-49894 bsc#1232354)
  - commit db76ccb
  - drm/amd/display: Add NULL check for function pointer in dcn32_set_output_transfer_func (CVE-2024-49909 bsc#1232337)
  - commit 11facc9
  - drm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream (CVE-2024-49913 bsc#1232307)
  - commit 60f7853
  - drm/msm/adreno: Assign msm_gpu->pdev earlier to avoid nullptrs (CVE-2024-49901 bsc#1232305)
  - commit 69be7bb
  - RAS/AMD/ATL: Implement DF 4.5 NP2 denormalization (jsc#PED-10559).
  - commit 52d40f4
  - RAS/AMD/ATL: Validate address map when information is gathered (jsc#PED-10559).
  - commit 94e412f
  - RAS/AMD/ATL: Expand helpers for adding and removing base and hole (jsc#PED-10559).
  - commit 2b18348
  - RAS/AMD/ATL: Read DRAM hole base early (jsc#PED-10559).
  - commit e1cf5b5
  - RAS/AMD/ATL: Add amd_atl pr_fmt() prefix (jsc#PED-10559).
  - commit 17f78f9
  - drm/amd/display: Check null pointer before try to access it (bsc#1232332 CVE-2024-49906)
  - commit f2b2892
  - drm/amd/display: Add null check for pipe_ctx->plane_state in (bsc#1232369 CVE-2024-49914)
  - commit c236474
  - drm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (bsc#1232335 CVE-2024-49908)
  - commit 64a943f
  - drm/amd/display: Check null pointers before using dc->clk_mgr (bsc#1232334 CVE-2024-49907)
  - commit 366c63a
  - RDMA/bnxt_re: synchronize the qp-handle table array (git-fixes)
  - commit 866dbc5
  - RDMA/bnxt_re: Fix the usage of control path spin locks (git-fixes)
  - commit c834f25
  - RDMA/mlx5: Round max_rd_atomic/max_dest_rd_atomic up instead of down (git-fixes)
  - commit 3c270f2
  - RDMA/cxgb4: Dump vendor specific QP details (git-fixes)
  - commit 587d3b0
  - ext4: fix access to uninitialised lock in fc replay path (CVE-2024-50014 bsc#1232446)
  - commit 1b2ba45

++++ openssl-3:

  - Support MSA 12 SHA3 on s390x [jsc#PED-10280]
    * Add openssl-3-add_EVP_DigestSqueeze_api.patch
    * Add openssl-3-support-multiple-sha3_squeeze_s390x.patch
    * Add openssl-3-add-xof-state-handling-s3_absorb.patch
    * Add openssl-3-fix-state-handling-sha3_absorb_s390x.patch
    * Add openssl-3-fix-state-handling-sha3_final_s390x.patch
    * Add openssl-3-fix-state-handling-shake_final_s390x.patch
    * Add openssl-3-fix-state-handling-keccak_final_s390x.patch
    * Add openssl-3-support-EVP_DigestSqueeze-in-digest-prov-s390x.patch
    * Add openssl-3-add-defines-CPACF-funcs.patch
    * Add openssl-3-add-hw-acceleration-hmac.patch
    * Add openssl-3-support-CPACF-sha3-shake-perf-improvement.patch
    * Add openssl-3-fix-s390x_sha3_absorb.patch
    * Add openssl-3-fix-s390x_shake_squeeze.patch

++++ libvirt:

  - Update to libvirt 10.9.0
  - jsc#PED-8909, jsc#PED-9854, jsc#PED-9855
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v10-9-0-2024-11-01

++++ netavark:

  - Set default firewall driver based on the project configuration (bsc#1231424)
    * Require correct dependencies
    * Add netavark-iptables.conf and netavark-nftables.conf

++++ python-libvirt-python:

  - Update to 10.9.0
  - Add all new APIs and constants in libvirt 10.9.0
  - jsc#PED-8909, jsc#PED-9854, jsc#PED-9855

++++ runc:

  - Update to runc v1.2.1. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.1>.

------------------------------------------------------------------
------------------  2024-10-31  -  Oct 31 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.2.6
  - -> https://docs.mesa3d.org/relnotes/24.2.6
  - added -32bit package for Mesa-libva since it's needed by Steam;
    reported on packman ML:
    https://lists.links2linux.de/pipermail/packman/2024-October/017985.html

++++ Mesa-drivers:

  - Update to release 24.2.6
  - -> https://docs.mesa3d.org/relnotes/24.2.6
  - added -32bit package for Mesa-libva since it's needed by Steam;
    reported on packman ML:
    https://lists.links2linux.de/pipermail/packman/2024-October/017985.html

++++ python-kiwi:

  - Fixed zipl caller environment
    zipl gets confused with an active sysfs mount inside
    the root tree at call time of zipl. This commit
    umounts the /sys bind mount in the image tree prior
    calling zipl
  - Fix s390 test-image-disk build
    Add missing kernel links used by suse tools
  - Bump version: 10.1.16 → 10.1.17

++++ librsvg:

  - Change license to LGPL-2.1-or-later AND MIT.

++++ kernel-default:

  - ext4: fix i_data_sem unlock order in ext4_ind_migrate() (CVE-2024-50006 bsc#1232442)
  - commit de0e62b
  - scsi: ufs: core: Remove SCSI host only if added (CVE-2024-46843
    bsc#1231100).
  - commit b455bee
  - io_uring: check if we need to reschedule during overflow flush
    (bsc#1232417 CVE-2024-50060).
  - commit 695bc5f
  - iommu/vt-d: Fix potential lockup if qi_submit_sync called
    with 0 count (bsc#1232316 CVE-2024-49993).
  - commit f1e5ce7
  - ext4: dax: fix overflowing extents beyond inode size when partially writing (CVE-2024-50015 bsc#1232079)
  - commit 9768b7c
  - jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error (CVE-2024-49959 bsc#1232149)
  - commit 8307a3a
  - of: Add cleanup.h based auto release via __free(device_node) markings (bsc#1232386)
  - commit 794e5ba
  - net: stmmac: dwmac-tegra: Fix link bring-up sequence (git-fixes)
  - commit 277d940
  - cpufreq: Avoid a bad reference count on CPU node (CVE-2024-50012 bsc#1232386)
  - commit 283b9a0
  - ext4: update orig_path in ext4_find_extent() (CVE-2024-49881 bsc#1232201)
  - commit 2ed2a04
  - ext4: fix slab-use-after-free in ext4_split_extent_at() (bsc#1232201)
  - commit c78e4be

++++ kernel-firmware-all:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-amdgpu:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-ath10k:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-ath11k:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-ath12k:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-atheros:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-bluetooth:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-bnx2:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-brcm:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-chelsio:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-dpaa2:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-i915:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-intel:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-iwlwifi:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-liquidio:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-marvell:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-media:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-mediatek:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-mellanox:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-mwifiex:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-network:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-nfp:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-nvidia:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-platform:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-prestera:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-qcom:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-qlogic:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-radeon:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-realtek:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-serial:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-sound:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-ti:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-ueagle:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-firmware-usb-network:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ kernel-rt:

  - ext4: fix i_data_sem unlock order in ext4_ind_migrate() (CVE-2024-50006 bsc#1232442)
  - commit de0e62b
  - scsi: ufs: core: Remove SCSI host only if added (CVE-2024-46843
    bsc#1231100).
  - commit b455bee
  - io_uring: check if we need to reschedule during overflow flush
    (bsc#1232417 CVE-2024-50060).
  - commit 695bc5f
  - iommu/vt-d: Fix potential lockup if qi_submit_sync called
    with 0 count (bsc#1232316 CVE-2024-49993).
  - commit f1e5ce7
  - ext4: dax: fix overflowing extents beyond inode size when partially writing (CVE-2024-50015 bsc#1232079)
  - commit 9768b7c
  - jbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error (CVE-2024-49959 bsc#1232149)
  - commit 8307a3a
  - of: Add cleanup.h based auto release via __free(device_node) markings (bsc#1232386)
  - commit 794e5ba
  - net: stmmac: dwmac-tegra: Fix link bring-up sequence (git-fixes)
  - commit 277d940
  - cpufreq: Avoid a bad reference count on CPU node (CVE-2024-50012 bsc#1232386)
  - commit 283b9a0
  - ext4: update orig_path in ext4_find_extent() (CVE-2024-49881 bsc#1232201)
  - commit 2ed2a04
  - ext4: fix slab-use-after-free in ext4_split_extent_at() (bsc#1232201)
  - commit c78e4be

++++ samba:

  - Add placeholder changelog for sle15-sp7; (jsc#PED-11210).

++++ libnvme:

  - Update to version 1.11:
    * prefix: Use Request or Response Length in DLEN and DOFF for MI
    * types: Add ETPVDS and SSI fields of sanitize status log
    * json: do not escape strings when printing the configuration
    * tree: do no export tls keys when not provided by user
    * types: add struct nvme_id_ctrl_nvm ver and lbamqf member variables
    * types: add NVMe 2.1 get log page LIDs
    * type: Added enums for ANSAN and RGCNS bit of OAES field
    * linux: fixup PSK HMAC type '0' handling
    * util: added error code for ENOKEY
    * fabrics: fix map error level in __nvmf_add_ctrl
    * fabrics: add ctrl connect interface
    * fabrics: use hex numbers when generating command line options
    * fabrics: rename first argument for argument macros
    * linux: handle key import correctly
    * linux: export keys to config
    * tree: read tls_configured_key and tls_keyring from sysfs
    * tree: move dhchap and tls sysfs parser into separate functions
    * json: move keystore operations out of the JSON parser
    * tree: add getter/setters for TLS PSK
    * linux: add import/export function for TLS pre-shared keys
    * linux: only return the description of a key
    * linux: use ssize_t as return type for nvme_identity_len
    * linux: reorder variable declarations
    * types: Added enum for SMVES event of PEL log
    * libnvme: add lockdown log page support(LID : 0x14)
    * libnvme: add EMVS support to sanitize command
    * types: Add TP4159 PCIe Infrastructure for Live Migration definitions
    * types: add NVME_CTRL_OAES get macro definitions
    * types: add NVME_CTRL_OAES_TTHR definition
    * types: add NVME_CTRL_FNA definitions to get field values
    * types: add NVME_VAL() definition
    * tree: fix tls key mem leak (bsc#1231668)
    * tree: fix dhchap_ctrl_key mem leak (bsc#1231668)
    * tree: fix dhchap_key mem leak (bsc#1231668)
    * types: add NVME_CHECK() definition to check nvme register field value
    * types: add kv opcodes
    * types: added new fields in nvme_nvme_id_ns
    * types: Add enum for Completion Condition of Get LBA status command
    * ioctl: refactoring set_features
    * types: add new fields added in TP4142
    * mi: add control primitive command
    * linux: Correct error handling for derive_psk_digest (bsc#1228376)
    * types: Added new field CSER in enum as per TP4167
  - build fix for OpenSSL 1.1
    * add 0001-linux-fix-derive_psk_digest-OpenSSL-1.1-version.patch

++++ nvme-cli:

  - Update to version 2.11:
    * docs: update check-tls-key arguments
    * nvme: add support to append TLS PSK to keyfile for check-tls-key
    * nvme: return correct error code in append_keyfile
    * docs: nvme-id-doman: dom{ia => ai}n
    * ocp: fix latency monitoring data structure entry endian
    * ocp: fix TCG configuration log endian
    * ocp: fix firmware activation history entry endian
    * docs: update gen-tls-key arguments
    * nvme: add support to add derive TLS PSK to keyfile
    * nvme: rename identity to version
    * nvme: set file permission for keyfile to owner only
    * nvme: export tls keys honoring version and hmac
    * nvmf-keys: add udev rule to import tls keys
    * docs: update TLS options
    * fabrics: add support to connect to accept a PSK command line
    * fabrics: add support to connect to accept a configuration
    * nvme: use unsigned char for hmac and identity
    * nvme-print: Add Sanitize Media Verification Event in PEL log
    * netapp-ontapdev: add err msg for no ontapdevices
    * netapp-smdev: add err msg for no smdevices
    * doc: Add sanitize command emvs option
    * ocp: combine to use GUID length definitions
    * nvme: update tls_key() handling
    * nvme-print-stdout: print VERS bit of SANICAP field
    * nvme: add EMVS support to sanitize command
    * ocp: remove callback function cast
    * doc: added commit conventions to contribution guidelines
    * ocp: fix ocp-print-stdout.c indentation error
    * ocp: fix ocp-nvme.c indentation errors
    * ocp: build ocp-nvme.c and ocp-telemetry-decode.c without json
    * ocp: split TCG configuration log print codes
    * ocp: split telemetry string log print codes
    * ocp: split device capabilities log print codes
    * ocp: split error recovery log print codes
    * ocp: split unsupported requirement log print codes
    * ocp: split latency monitor log print codes
    * ocp: move ocp telemetry log print function into ocp-print
    * ocp: split smart extended log print codes
    * ocp: split ocp-fw-activation-history print codes
    * plugins: update meson.build file to always build ocp plugin
    * ocp-print: move json code into separate files
    * nvme-print-json: display only verbose output
    * ocp-nvme: ocp plugin version update
    * nvme-print: print KV command set page header
    * doc: show where self-test results can be found
    * plugins/memblaze: fix a wrong id on smart-log-add
    * plugins/dapustor: smart-log-add fix
    * plugins/sed: add sid password change (bsc#1229677)
    * plugins/solidigm: Automatic retry smaller log chunk size.
    * ocp-nvme: Add LMDATA-37 for Latency Monitor Log
    * ocp-nvme: remove ocp log page version checking
    * wdc: Fix for Reading WDC C2 Vendor Unique Log Page
    * ocp: Fixes for OCP 2.5 Telemetry DA1 FIFO Event Parsing
    * nvme-print-json: update JSON verbose output for nvm-id-ctrl (bsc#1231668)
    * wdc: Add Support for SN5100S
    * nvme: Support show-regs for nvmeof
    * ocp: fix option handling in internal-log
    * Documentation: Added solidigm plugin commands
    * wdc: add support for SNTMP drive
    * nvme-print: print NSSES field of CAP register
    * ocp: fix GUID output
    * nvme-print-json: print controller register values in offset order
    * nvme-print-json: print CMBEBS and CMBSWTP in json format
    * nvme-print-stdout: update changed-ns-list-log output (bsc#1231668)
    * nvme: fix uninitialized value in error-log (bsc#1231668)
    * nvme: fix to convert metadata size to native byte order
    * nvme-print: fix error information log page endianness error
    * completions: add get-feature command changed option
    * doc: add get-feature command changed option
    * nvme: separate get NVME_GET_FEATURES_SEL_CHANGED definition
    * nvme: use NVME_GET_FEATURES_SEL definitions
    * nvme-print-stdout: use NVME_CTRL_OAES definitions
    * completion: add ocp set-telemetry-profile to zsh
    * completion: add solidgm work-tracker binding
    * plugins/solidigm: Added Workload Tracker Triggers and Wall Time
    * ocp: include util/types.h to use nvme_uint128_t
    * ocp: fix to set log data pointer allocated
    * nvme: use NVME_CHECK() to check get features select field value
    * ocp: split ocp-hwcomp log
    * completions: add ocp hardware-component-log command
    * doc: add ocp hardware-component-log command
    * ocp: add hwcomp log json output
    * ocp: add hwcomp log command list option
    * ocp: add hwcomp log command comp-id option
    * ocp: add hwcomp dummy definition
    * ocp: add support for hwcomp log page
    * nvme: use NVME_CTRL_FNA definitions
    * netapp-smdevices: print single device output too (bsc#1231668)
    * netapp-smdevices: segregate print routines (bsc#1231668)
    * Add Support for new SN655 PCI Device ID
    * nvme-print-json: extern json object add functions
    * ocp: add SMART / health information extended log page version 4
    * ocp: add error recovery log page version 3
    * ocp: add get-enable-ieee1667-silo command
    * fabrics: fix incorrect access filename check (bsc#1231668)
    * nvme: use NVME_GET_FEATURES_SEL_SUPPORTED definition
    * nvme-print-json: use _cleanup_free_
    * plugins/solidigm: fix use after free.
    * ocp: fix ocp-nvme.c coding style errors
    * ocp: Change C9 function names to use c9 instead
    * ocp: fix to return c9 log page data error to open file
    * ocp: fix to set return value to get c9 log page data
    * nvme: update nvme_insert_tls_key_versioned() return handling (bsc#1231668)
    * nvme-print-stdout: add print_array function
    * logging: add print_info function
    * util: extern uint128_t_to_double() function
    * nvme-print: sanitize error-log output (bsc#1231668)
    * plugins/solidigm : Fixing vs-internal-log to generate identify per allocated namespace.
    * nvme-print: added new fields for nvm_id_ns
    * plugins/fdp: bugfix error check to validate output format
    * plugins/wdc: fix json output for vs-nand-stats
    * nvme-print-stdout: use NVME_FEAT util definitions
    * nvme-print: update subsys verbose outputs (bsc#1231668)
    * nvme-print: add subsystype to the list-subsys output (bsc#1231668)
    * netapp: print output for single device too (bsc#1231668)
    * netapp: segregate the print routines (bsc#1231668)
    * netapp: fix uninitialized value from heap error (bsc#1231668)
    * nvme-print: print the new fields added in TP4142
    * plugins/innogrit: modify for project tacoma
    * wdc: Add Support for new SN-861 PCI device id
    * nvme-print: use LC_MEASUREMENT to check fahrenheit temperature
    * nvme-print: use Completion Condition enum
    * completions: add the zsh completion of the dapustor plugin
    * nvme-print: print the new fields added in TP4165
    * plugins/dapustor: dapustor smart-log-add update
    * nvme-print-stdout: Added print for new field CSER (TP4167)
    * plugins: Add a new DapuStor plugin and the smart-log-add command
    * docs: rename ocp-unsupported-req-log file
  - Drop build fix patch
    * remove 0001-docs-rename-ocp-unsupported-req-log-file.patch
  - Install 70-nvmf-keys.rules to the default udev rules directory

++++ rpm-config-SUSE:

  - Update to version 20241031:
    * Merge in changes that already happened in the package
  - Update to version 20241031:
    * Drop {set,verify}_permissions macros
    * Strip the explicit /bin/bash dependency for ksym macros
    * locale.prov: handle glibc-locale-base (boo#1221250)
    * lang_package: Add 'basename' option
    * %requires_eq|ge(): Report error if package version cannot be determined

++++ selinux-policy:

  - Update to version 20240604+git384.710b0da6:
    * Label /var/livepatches as lib_t for ULP on micro (bsc#1228879)

++++ ucode-amd:

  - Update to version 20241029 (git commit 048795eef350):
    * ath11k: move WCN6750 firmware to the device-specific subdir
    * xe: Update LNL GSC to v104.0.0.1263
    * i915: Update MTL/ARL GSC to v102.1.15.1926

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20241029 release (bsc#1230400)
    Update for functional issues. Refer to [14th/13th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
    Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | RPL-E/HX/S     | B0       | 06-b7-01/32 | 00000129 | 0000012b | Core Gen13/Gen14

------------------------------------------------------------------
------------------  2024-10-30  -  Oct 30 2024  -------------------
------------------------------------------------------------------

++++ aardvark-dns:

  - Update to version 1.13.0:
    * Release v1.13.0
    * Update release notes for 1.13.0
    * test: use dnsmasq over slirp4netns
    * coredns: forward names with no ndots as well
    * run cargo update
    * fix(deps): update rust crate tokio to 1.41.0
    * fix(deps): update rust crate flume to 0.11.1
    * fix(deps): update rust crate libc to 0.2.161
    * fix(deps): update rust crate libc to 0.2.160
    * fix(deps): update rust crate clap to ~4.5.20
    * cirrus: check for msrv build
    * define a MSRV policy
    * chore(deps): update dependency containers/automation_images to v20241010
    * [skip-ci] Packit: constrain koji job to the fedora package
    * dns: limit to 3 resolvers and use better timeout for them
    * OWNERS file audit and update
    * fix new lint error with rust 1.81
    * test: make them pass on RHEL/Centos Stream 9
    * Packit: disable F39 and separate out ELN
    * serve: parse resolv.conf ourselves
    * fix(deps): update rust crate libc to 0.2.159
    * coredns: allow host lookup of names
    * backend: return simple Vector in lookup()
    * coredns: use a TTL of 0 for our names
    * coredns: do not clonse the Record
    * netavark_cache_groom.sh: fix wrong branch
    * Packit: add sidetag to release with netavark
    * coredns: work on tcp requests concurrently
    * tcp: add timeout to connection
    * fix(deps): update rust crate tokio to 1.40.0
    * fix(deps): update rust crate libc to 0.2.158
    * chore(deps): update dependency containers/automation_images to v20240821
    * fix(deps): update rust crate tokio to 1.39.3
    * fix(deps): update rust crate libc to 0.2.156
    * Bump main version back to v1.13.0-dev

++++ docker-compose:

  - Update to version 2.30.1:
    * bump compose-go to version v2.4.2

++++ python-kiwi:

  - Fix coloring of build_status.sh flags
    Depending on the place of the status flag the color
    setup might fail. This commit fixes it
  - Add pytest-container as optional dependency
    The pyproject.toml listed pytest-container as dependency
    but it is used only to run the container based integration
    tests for the shell helper methods. For building the package
    this dependency should not be pulled in

++++ librsvg:

  - Update to version 2.59.2:
    + Fix stack overflow due to unbounded recursion.  Now there is
    a hard limit on the number of nested layers that an SVG
    document may have.  This is not a hard limit on the amount of
    stack space consumed, but it is a general mitigation.
    + Fix regression when rendering paths with very flat elliptical
    arcs.  This bug was introduced in 2.59.1 as part of the
    mitigation for paths with coordinates that Cairo is unable to
    handle.
    + Fix centering and text-anchor in general for scaled text.
    + Fix building with Rust 1.82 on Windows (Christoph Reiter).
    + Make cancellation work for all the resource loading
    functions.
    + Add documentation for rsvg-bench to the development guide.
    + Slight improvement in memory consumption for language tags.
    + Many updates to the developer's documentation, for Outreachy
    interns.

++++ grub2:

  - Fix CVE-2024-49504 (bsc#1229163) (bsc#1229164)
  - Restrict CLI access if the encrypted root device is automatically unlocked by
    the TPM. LUKS password authentication is required for access to be granted
    * 0001-cli_lock-Add-build-option-to-block-command-line-inte.patch
    * 0002-Requiring-authentication-after-tpm-unlock-for-CLI-ac.patch
  - Obsolete, as CLI access is now locked and granted access no longer requires
    the previous restrictions
    * 0002-Restrict-file-access-on-cryptodisk-print.patch
    * 0003-Restrict-ls-and-auto-file-completion-on-cryptodisk-p.patch
  - Rediff
    * 0004-Key-revocation-on-out-of-bound-file-access.patch
  - Enable support of Radix, Xive and Radix_gtse on Power (jsc#PED-9881)
    * 0001-kern-ieee1275-init-Add-IEEE-1275-Radix-support-for-K.patch

++++ kernel-default:

  - btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info()
    in walk_down_proc() (CVE-2024-46841 bsc#1231094).
  - commit fb4a0c7
  - ext4: aovid use-after-free in ext4_ext_insert_extent() (CVE-2024-49883 bsc#1232199)
  - commit 2db9cb5
  - blk_iocost: fix more out of bound shifts (CVE-2024-49933 bsc#1232368)
  - commit df53397
  - drm/amd/display: Fix index out of bounds in DCN30 color
    transformation (CVE-2024-49969 bsc#1232519).
  - commit 7d6c264
  - static_call: Replace pointless WARN_ON() in
    static_call_module_notify() (bsc#1232155 CVE-2024-49954).
  - commit 03b6c35
  - module: abort module loading when sysfs setup suffer errors
    (git-fixes).
  - Refresh patches.suse/add-suse-supported-flag.patch.
  - commit db27509
  - bpf,perf: Fix perf_event_detach_bpf_prog error handling
    (git-fixes).
  - commit 5b6b2d4
  - tracing: Consider the NULL character when validating the event
    length (git-fixes).
  - commit 6b1d97f
  - uprobe: avoid out-of-bounds memory access of fetching args
    (git-fixes).
  - uprobes: encapsulate preparation of uprobe args buffer
    (git-fixes).
  - commit ead6cfe
  - s390/pci: Handle PCI error codes other than 0x3a (git-fixes
    bsc#1232629).
  - commit e4948be
  - s390/sclp: Deactivate sclp after all its users (git-fixes
    bsc#1232628).
  - commit 9e889e7
  - s390/sclp_vt220: Convert newlines to CRLF instead of LFCR
    (git-fixes bsc#1232627).
  - commit 5725ee0
  - KVM: s390: Change virtual to physical address access in diag
    0x258 handler (git-fixes bsc#1232626).
  - commit 2b0b1e9
  - KVM: s390: gaccess: Check if guest address is in memslot
    (git-fixes bsc#1232623).
  - commit b583687
  - fgraph: Use CPU hotplug mechanism to initialize idle shadow
    stacks (git-fixes).
  - commit 4265ef9
  - mm: khugepaged: fix the arguments order in
    khugepaged_collapse_file trace point (git-fixes).
  - commit 43546b6
  - tracing/hwlat: Fix a race during cpuhp processing (git-fixes).
  - tracing/timerlat: Fix a race during cpuhp processing
    (git-fixes).
  - tracing/timerlat: Drop interface_lock in stop_kthread()
    (git-fixes).
  - tracing/timerlat: Fix duplicated kthread creation due to CPU
    online/offline (git-fixes).
  - tracing/osnoise: Fix build when timerlat is not enabled
    (git-fixes).
  - tracing/timerlat: Add interface_lock around clearing of kthread
    in stop_kthread() (git-fixes).
  - tracing/timerlat: Only clear timer if a kthread exists
    (git-fixes).
  - tracing/osnoise: Use a cpumask to know what threads are kthreads
    (git-fixes).
  - tracing/timerlat: Move hrtimer_init to timerlat_fd open()
    (git-fixes).
  - tracing/timerlat: Add user-space interface (git-fixes).
  - tracing/osnoise: Skip running osnoise if all instances are off
    (git-fixes).
  - tracing/osnoise: Switch from PF_NO_SETAFFINITY to
    migrate_disable (git-fixes).
  - commit 8482ad0
  - ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
    (git-fixes).
  - commit 24fea60
  - Refresh patches.suse/x86-fix-user-address-masking-non-canonical-speculation-iss.patch. (bsc#1232529)
    Give check_range a unique label. Otherwise the macro's 1b label
    conflicts with __get_user_1's 1 label and this causes the exception fixup
    entry, installed at the end of the file to match the wrong thing.
    Instead of matching __get_user_1's 1b label it will match check_range's 1b
    label when this macro is expanded for the last time in __get_user_8.
    This fixes intermittent random crashes when copying data from userspace.
  - commit 3a35fd0
  - jump_label: Fix static_key_slow_dec() yet again (git-fixes).
  - commit ab363f5
  - SUNRPC: Fixup gss_status tracepoint error output (git-fixes).
  - commit 84cc417

++++ kernel-rt:

  - btrfs: don't BUG_ON on ENOMEM from btrfs_lookup_extent_info()
    in walk_down_proc() (CVE-2024-46841 bsc#1231094).
  - commit fb4a0c7
  - ext4: aovid use-after-free in ext4_ext_insert_extent() (CVE-2024-49883 bsc#1232199)
  - commit 2db9cb5
  - blk_iocost: fix more out of bound shifts (CVE-2024-49933 bsc#1232368)
  - commit df53397
  - drm/amd/display: Fix index out of bounds in DCN30 color
    transformation (CVE-2024-49969 bsc#1232519).
  - commit 7d6c264
  - static_call: Replace pointless WARN_ON() in
    static_call_module_notify() (bsc#1232155 CVE-2024-49954).
  - commit 03b6c35
  - module: abort module loading when sysfs setup suffer errors
    (git-fixes).
  - Refresh patches.suse/add-suse-supported-flag.patch.
  - commit db27509
  - bpf,perf: Fix perf_event_detach_bpf_prog error handling
    (git-fixes).
  - commit 5b6b2d4
  - tracing: Consider the NULL character when validating the event
    length (git-fixes).
  - commit 6b1d97f
  - uprobe: avoid out-of-bounds memory access of fetching args
    (git-fixes).
  - uprobes: encapsulate preparation of uprobe args buffer
    (git-fixes).
  - commit ead6cfe
  - s390/pci: Handle PCI error codes other than 0x3a (git-fixes
    bsc#1232629).
  - commit e4948be
  - s390/sclp: Deactivate sclp after all its users (git-fixes
    bsc#1232628).
  - commit 9e889e7
  - s390/sclp_vt220: Convert newlines to CRLF instead of LFCR
    (git-fixes bsc#1232627).
  - commit 5725ee0
  - KVM: s390: Change virtual to physical address access in diag
    0x258 handler (git-fixes bsc#1232626).
  - commit 2b0b1e9
  - KVM: s390: gaccess: Check if guest address is in memslot
    (git-fixes bsc#1232623).
  - commit b583687
  - fgraph: Use CPU hotplug mechanism to initialize idle shadow
    stacks (git-fixes).
  - commit 4265ef9
  - mm: khugepaged: fix the arguments order in
    khugepaged_collapse_file trace point (git-fixes).
  - commit 43546b6
  - tracing/hwlat: Fix a race during cpuhp processing (git-fixes).
  - tracing/timerlat: Fix a race during cpuhp processing
    (git-fixes).
  - tracing/timerlat: Drop interface_lock in stop_kthread()
    (git-fixes).
  - tracing/timerlat: Fix duplicated kthread creation due to CPU
    online/offline (git-fixes).
  - tracing/osnoise: Fix build when timerlat is not enabled
    (git-fixes).
  - tracing/timerlat: Add interface_lock around clearing of kthread
    in stop_kthread() (git-fixes).
  - tracing/timerlat: Only clear timer if a kthread exists
    (git-fixes).
  - tracing/osnoise: Use a cpumask to know what threads are kthreads
    (git-fixes).
  - tracing/timerlat: Move hrtimer_init to timerlat_fd open()
    (git-fixes).
  - tracing/timerlat: Add user-space interface (git-fixes).
  - tracing/osnoise: Skip running osnoise if all instances are off
    (git-fixes).
  - tracing/osnoise: Switch from PF_NO_SETAFFINITY to
    migrate_disable (git-fixes).
  - commit 8482ad0
  - ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow
    (git-fixes).
  - commit 24fea60
  - Refresh patches.suse/x86-fix-user-address-masking-non-canonical-speculation-iss.patch. (bsc#1232529)
    Give check_range a unique label. Otherwise the macro's 1b label
    conflicts with __get_user_1's 1 label and this causes the exception fixup
    entry, installed at the end of the file to match the wrong thing.
    Instead of matching __get_user_1's 1b label it will match check_range's 1b
    label when this macro is expanded for the last time in __get_user_8.
    This fixes intermittent random crashes when copying data from userspace.
  - commit 3a35fd0
  - jump_label: Fix static_key_slow_dec() yet again (git-fixes).
  - commit ab363f5
  - SUNRPC: Fixup gss_status tracepoint error output (git-fixes).
  - commit 84cc417

++++ libbpf:

  - update to 1.5.0:
    * libbpf can now open (but not load!) BPF objects of non-native endianness,
    enabling cross-architecture support for BPF skeleton generation and BPF
    object introspection
    * BPF skeleton will now auto-attach SEC(".struct_ops") maps as part of
    <skeleton>__attach() call
    * BPF kprobe session programs support (SEC("kprobe.session"))
    * allow specifying kernel module name for fentry/fexit BPF programs
    (SEC(fentry/module:function)
    * libbpf recognizes LIBBPF_LOG_LEVEL environment variable, which can be used
    to set default log verboseness
    * BPF ringbuf APIs that limit maximum number of consumed records at a time
    (ring_buffer__consume_n(), ring__consume_n())
    * distilled BTF support (btf__distill_base(), btf__relocate())
    * BPF link-based attachment of BPF_PROG_TYPE_SOCKMAP programs
    (bpf_program__attach_sockmap())
    * bpf_object__token_fd() API to fetch BPF token FD of a BPF object, if any
    * fixes for fetching syscall arguments on arm64, s390x, risc-v architectures
    * better GCC-BPF source code compatibility
    * __bpf_fastcall support for a few BPF helpers
    * __uptr annotation definition added to bpf/bpf_helpers.h API header
    * fixes and improvements around handling missing and nulled out struct_ops
    programs
    * fixed mmap()-ing logic for global data, fixing interop between generic
    bpf_object__open() APIs and BPF subskeletons
    * BPF skeleton backwards compatibility handling fixes
    * handle LTO-produced *.llvm.<hash> symbols better
    * feature detection fixes in the presence of BPF token inside user namespace
    * older kernels have broken PID filtering logic for multi-uprobes, libbpf now
    detects this and avoids the use of multi-uprobes for USDTs
    * fix accidental drop of FD_CLOEXEC flag during BPF map reuse
    * few BTF dumper formatting fixes
    * a few more small fixes all around.
  - update to 1.4.7:
    * fix interop issues between generic bpf_object__open() APIs and BPF
    subskeleton w.r.t. global data handling
    * speed up BTF sanity checks by skipping already validated base BTF
    * fix legacy treatment of non-SEC()-annotated subprogram as entry BPF program
    in some cases

++++ libnl3:

  - Update to release 3.11
    * Add NLA_{SINT|UINT} attribute types
    * Add NLA functions for variable-length integers
    * link/bonding: add getters for attributes
    * lib/route: add support for bridge msti

++++ netavark:

  - Update to version 1.13.0:
    * Release v1.13.0
    * Updates release notes for v1.13.0
    * run cargo update
    * fix(deps): update rust crate hyper-util to 0.1.10
    * [skip-ci] Packit: Remove epel targets
    * fix(deps): update rust crate nftables to 0.5.0
    * fix(deps): update rust crate anyhow to 1.0.91
    * fix(deps): update rust crate tokio to 1.41.0
    * fix(deps): update rust crate anyhow to 1.0.90
    * Updated to zbus4
    * chore(deps): update dependency containers/automation_images to v20241010
    * test-dhcp: fix NOP test
    * fix new lint errors with rust 1.81
    * fix(deps): update rust crate clap to ~4.5.20
    * contrib/container_images: remove no longer used images
    * cirrus: check for msrv build
    * add new rust image to check for MSRV
    * define a MSRV policy
    * [skip-ci] Packit: constrain koji and bodhi to the fedora package
    * chore(deps): update rust crate once_cell to 1.20.2
    * fix(deps): update rust-futures monorepo to 0.3.31
    * OWNERS file audit and update
    * update tonic and prost dependencies
    * update tower to v0.5.1
    * fix(deps): update rust crate sysctl to 0.6.0
    * fix(deps): update rust crate netlink-packet-route to 0.21.0
    * chore(deps): update rust crate tempfile to 3.13.0
    * chore(deps): update rust crate once_cell to 1.20.1
    * fix(deps): update rust crate nispor to 1.2.21
    * fix(deps): update rust crate anyhow to 1.0.89
    * nftables: add dns dnat rule first
    * iptables: add dns dnat rule first
    * fix(deps): update rust crate anyhow to 1.0.88
    * nft: remove port forwarding rules correctly
    * fix(deps): update rust crate tokio-stream to 0.1.16
    * nft: do not parse localhost string ip
    * nft: use append() over push() where possible
    * Packit: add sidetag to release with aardvark-dns
    * fix(deps): update rust crate tokio to 1.40.0
    * fix(deps): update rust crate libc to 0.2.157
    * fix(deps): update rust crate tokio to 1.39.3
    * fix(deps): update rust crate libc to 0.2.156
    * aardvark: on start failure delete entries again
    * iptables: make dns rules cover tcp as well
    * nftables: make dns rules cover tcp as well
    * fix(deps): update rust crate serde_json to 1.0.123
    * remove superfluous formatters from debug stmt
    * chore(deps): update rust crate tempfile to 3.12.0
    * fix new rust 1.80 lint issues
    * silence new rust 1.80 warnings
    * chore(deps): update rust crate tempfile to 3.11.0
    * fix(deps): update rust crate serde_json to 1.0.122
    * Bumping main back to v1.13.0-dev for development

++++ python-M2Crypto:

  - Update to 0.43.0:
  - feat[m2]: add m2.time_t_bits to checking for 32bitness.
  - fix[tests]: Use only X509_VERSION_1 (0) as version for CSR.
  - fix[EC]: raise ValueError when load_key_bio() cannot read the
    file (bsc#1231589).
  - ci: use -mpip wheel instead of -mbuild
  - fix: use PyMem_Malloc() instead of malloc()
  - fix[hints]: more work on conversion of type hints to the py3k ones
  - fix: make the package build even on Python 3.6
  - ci[local]: skip freezing local tests
  - fix[hints]: remove AnyStr type
  - test: add suggested test for RSA.{get,set}_ex_data
  - fix: implement interfaces for RSA_{get,set}_ex_new_{data,index}
  - fix: generate src/SWIG/x509_v_flag.h to overcome weaknesses of
    swig
  - fix: replace literal enumeration of all VERIFY_ constants by a
    cycle
  - test: unify various test cases in test_ssl related to ftpslib
  - fix: replace deprecated url keyword in setup.cfg with complete
    project_urls map

++++ python-gobject:

  - Add python-pygobject provides: help packages to eliminate rpmlint
    warnings when comparing requrements.txt vs the packages depdency.
    'pygobject' is the proper upstream name.

++++ system-users:

  - system-user-nobody: remove shell for user nobody, all packages
    should be meanwhile adjusted, no other distribution has a shell
    for this user.

++++ toolbox:

  - Update to version 2.4+git20241030.2ae8421:
    * Adjust md syntax for go-md2man
    * Fix header
    * Sync README with manual page
    * Ignore generated toolbox.1 manual page

------------------------------------------------------------------
------------------  2024-10-29  -  Oct 29 2024  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update to 10.3.6 (jsc#PCT-471, bsc#1230615)
    + Fix sudo setup
    ~ permissions cloudguestregistryauth
    ~ directory ownership /etc/sudoers.d
    + spec file
    ~ Remove traces of registry related entries on SLE 12
    + Forward port
    ~ fix-for-sles12-disable-registry.patch
    ~ fix-for-sles12-no-trans_update.patch
    + Deregister non free extensions at registercloudguest --clean
    + Fix registry cleanup at registercloudguest --clean, don't remove files
    + Prevent duplicate search entries in registry setup
  - Update EC2 plugin to 1.0.5
    + Switch to using the region endpoint from IMDS to determine the region
    instead of deriving the data from the availability zone

++++ docker-compose:

  - Update to version 2.30.0:
    * Improvements
  - Introduce service hooks by @ndeloof (12166)
  - Introduce generate command as alpha command by @glours
    (12209)
  - Add export command by @jarqvi (12120)
  - Add support for CDI device request using devices by @ndeloof
    (12184)
  - Add support for bind recursive by @ndeloof (12210)
  - Allow usage of -f flag with OCI Compose artifacts by @glours
    (12220)
    * Fixes
  - Append unix-style relative path when computing container
    target path by @ndeloof (12145)
  - Wait for dependent service up to delay set by --wait-timeout
    by @ndeloof (12156)
  - Check secret source exists, as bind mount would create target
    by @ndeloof (12151)
  - After container restart register printer consumer by @jhrotko
    (12158)
  - Fix(down): Fix down command if specified services are not
    running by @idsulik (12164)
  - Show watch error message and open DD only when w is pressed
    by @jhrotko (12165)
  - Fix(push): Fix unexpected EOF on alpha publish by @idsulik
    (12169)
  - Fix(convergence): Serialize access to observed state by
    @anantadwi13 (12150)
  - Remove feature flag integration with Docker Desktop for
    ComposeUI and ComposeNav by @jhrotko (12192)
  - Support Dockerfile-specific ignore-file with watch by
    @ndeloof (12193)
  - Add support for raw env_file format by @ndeloof (12179)
  - Convert GPUs to DeviceRequests with implicit "gpu" capability
    by @ndeloof (12197)
  - Improve error message to include expected network label by
    @divinity76 (12213)
  - Don't use progress to render restart, which hides logs by
    @ndeloof (12226)
  - One-off containers are not indexed, and must be ignored by
    exec --index command by @ndeloof (12224)
  - Don't warn about uid/gid not being supported while ... they
    are by @ndeloof (12232)
  - Connect to external networks by name by @ndeloof (12234)
  - Fix push error message typo by @chris-crone (12237)
  - Fix(dockerignore): Add wildcard support to dockerignore.go by
    @idsulik (12239)
    * Internal
  - Remove bind options when creating a volume type by @jhrotko
    (12177)
  - pass device.options to engine by @ndeloof (12183)
  - Add security policy by @thaJeztah (12194)
  - Gha: set default permissions to "contents: read" by
    @thaJeztah (12195)
  - Desktop: allow this client to be identified via user-agent by
    @djs55 (12212)
  - Compose-go clean volume target to avoid ambiguous comparisons
    by @ndeloof (12208)
    * Dependencies
  - Bump docker v27.3.1 by @ndeloof (12178)
  - Build(deps): bump golang.org/x/sys from 0.25.0 to 0.26.0 by
    @dependabot (12189)
  - Bump compose-go to v2.3.0 by @glours (12198)
  - Bump compose-go to v2.4.0 by @glours (12231)
  - Bump compose-go to v2.4.1 by @glours (12243)
  - Build(deps): bump github.com/containerd/containerd from
    1.7.22 to 1.7.23 by @dependabot (12211)
  - Bump golang minimal version to 1.22 in go.mod by @glours
    (12246)
  - Bump go.uber.org/mock to v0.5.0 and google.golang.org/grpc to
    v1.67.1 by @glours (12245)

++++ guestfs-tools:

  - Update to version 1.53.4 (jsc#PED-8910)
    * mlcustomize: Update generated options for virt-v2v
    * Various build fixes and dependency changes

++++ kernel-default:

  - drm/amd/display: Deallocate DML memory if allocation fails (CVE-2024-49972 bsc#1232315)
  - commit dd5ab13
  - drm/amd/display: Check stream before comparing them (CVE-2024-49896 bsc#1232221)
  - commit 930546b
  - drm/amd/pm: ensure the fw_info is not null before using it (CVE-2024-49890 bsc#1232217)
  - commit a0e8b9f
  - drm/amd/display: Initialize get_bytes_per_element's default to 1 (CVE-2024-49892 bsc#1232220)
  - commit e1539d0
  - drivers/perf: Fix ali_drw_pmu driver interrupt status clearing (CVE-2024-47731 bsc#1232117)
  - commit 774dc33
  - padata: use integer wrap around to prevent deadlock on seq_nr overflow (CVE-2024-47739 bsc#1232124)
  - commit 7e58560
  - media: mediatek: vcodec: Fix H264 stateless decoder smatch warning (CVE-2024-47752 bsc#1232130)
  - commit 086cd43
  - media: mediatek: vcodec: Fix H264 multi stateless decoder smatch warning (CVE-2024-47754 bsc#1232131)
  - commit dacb1c6
  - media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning (CVE-2024-47753 bsc#1231868)
  - commit fed66a9
  - iommu/vt-d: Always reserve a domain ID for identity setup
    (git-fixes).
  - commit f7ecad0
  - btrfs: clean up our handling of refs == 0 in snapshot delete (CVE-2024-46840 bsc#1231105)
  - commit 788d396
  - kABI: bpf: struct bpf_map kABI workaround (CVE-2024-50063
    bsc#1232435).
  - selftests/bpf: Add test for lsm tail call (CVE-2024-50063
    bsc#1232435).
  - bpf: Prevent tail call between progs attached to different hooks
    (CVE-2024-50063 bsc#1232435).
  - commit 666246a
  - iommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI
    devices (git-fixes).
  - commit 28951a9
  - drm/amd/display: Check null pointers before multiple uses (bsc#1232313 CVE-2024-49920)
  - commit 5447aa1
  - drm/amd/display: Check link_res->hpo_dp_link_enc before using it (bsc#1231944)
  - commit bf57b96
  - drm/amd/display: Check null-initialized variables (bsc#1232222 CVE-2024-49898)
  - commit a00bfda
  - drm/amd/display: Check link_res->hpo_dp_link_enc before using it (bsc#1231944 CVE-2024-47704)
  - commit 931c899
  - spi: spi-fsl-dspi: Fix crash when not using GPIO chip select
    (git-fixes).
  - spi: mtk-snfi: fix kerneldoc for mtk_snand_is_page_ops()
    (git-fixes).
  - spi: atmel-quadspi: Fix wrong register value written to MR
    (git-fixes).
  - commit fd0b348
  - crypto: stm32/cryp - call finalize with bh disabled
    (CVE-2024-47658 bsc#1231436).
  - commit 2854148

++++ kernel-rt:

  - drm/amd/display: Deallocate DML memory if allocation fails (CVE-2024-49972 bsc#1232315)
  - commit dd5ab13
  - drm/amd/display: Check stream before comparing them (CVE-2024-49896 bsc#1232221)
  - commit 930546b
  - drm/amd/pm: ensure the fw_info is not null before using it (CVE-2024-49890 bsc#1232217)
  - commit a0e8b9f
  - drm/amd/display: Initialize get_bytes_per_element's default to 1 (CVE-2024-49892 bsc#1232220)
  - commit e1539d0
  - drivers/perf: Fix ali_drw_pmu driver interrupt status clearing (CVE-2024-47731 bsc#1232117)
  - commit 774dc33
  - padata: use integer wrap around to prevent deadlock on seq_nr overflow (CVE-2024-47739 bsc#1232124)
  - commit 7e58560
  - media: mediatek: vcodec: Fix H264 stateless decoder smatch warning (CVE-2024-47752 bsc#1232130)
  - commit 086cd43
  - media: mediatek: vcodec: Fix H264 multi stateless decoder smatch warning (CVE-2024-47754 bsc#1232131)
  - commit dacb1c6
  - media: mediatek: vcodec: Fix VP8 stateless decoder smatch warning (CVE-2024-47753 bsc#1231868)
  - commit fed66a9
  - iommu/vt-d: Always reserve a domain ID for identity setup
    (git-fixes).
  - commit f7ecad0
  - btrfs: clean up our handling of refs == 0 in snapshot delete (CVE-2024-46840 bsc#1231105)
  - commit 788d396
  - kABI: bpf: struct bpf_map kABI workaround (CVE-2024-50063
    bsc#1232435).
  - selftests/bpf: Add test for lsm tail call (CVE-2024-50063
    bsc#1232435).
  - bpf: Prevent tail call between progs attached to different hooks
    (CVE-2024-50063 bsc#1232435).
  - commit 666246a
  - iommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI
    devices (git-fixes).
  - commit 28951a9
  - drm/amd/display: Check null pointers before multiple uses (bsc#1232313 CVE-2024-49920)
  - commit 5447aa1
  - drm/amd/display: Check link_res->hpo_dp_link_enc before using it (bsc#1231944)
  - commit bf57b96
  - drm/amd/display: Check null-initialized variables (bsc#1232222 CVE-2024-49898)
  - commit a00bfda
  - drm/amd/display: Check link_res->hpo_dp_link_enc before using it (bsc#1231944 CVE-2024-47704)
  - commit 931c899
  - spi: spi-fsl-dspi: Fix crash when not using GPIO chip select
    (git-fixes).
  - spi: mtk-snfi: fix kerneldoc for mtk_snand_is_page_ops()
    (git-fixes).
  - spi: atmel-quadspi: Fix wrong register value written to MR
    (git-fixes).
  - commit fd0b348
  - crypto: stm32/cryp - call finalize with bh disabled
    (CVE-2024-47658 bsc#1231436).
  - commit 2854148

++++ c-ares:

  - c-ares 1.34.2
    Features:
    * adig: read arguments from adigrc. [PR #856]
    * Add new pending write callback optimization via `ares_set_pending_write_cb`. [PR #857]
    * New function `ares_process_fds()`. [PR #875]
    * Failed servers should be probed rather than redirecting queries which could
    cause unexpected latency. [PR #877]
    * adig: rework command line arguments to mimic dig from bind. [PR #890]
    * Add new method for overriding network functions
    `ares_set_socket_function_ex()` to properly support all new functionality.
    [PR #894]
    * Fix regression with custom socket callbacks due to DNS cookie support. [PR #895]
    * ares_socket: set IP_BIND_ADDRESS_NO_PORT on ares_set_local_ip* tcp sockets [PR #887]
    * URI parser/writer for ares_set_servers_csv()/ares_get_servers_csv(). [PR #882]
    Changes:
    * Connection handling modularization. [PR #857], [PR #876]
    * Expose library/utility functions to tools. [PR #860]
    * Remove `ares__` prefix, just use `ares_` for internal functions. [PR #872]
    Bugfixes:
    * fix: potential WIN32_LEAN_AND_MEAN redefinition.
    [PR #869]
    * Fix googletest v1.15 compatibility.
    [PR #874]
    * Fix pkgconfig thread dependencies.
    [PR #884]
    Features in 1.33.0:
    * Add DNS cookie support (RFC7873 + RFC9018) to help prevent off-path cache
    poisoning attacks. [PR #833]
    * Implement TCP FastOpen (TFO) RFC7413, which will make TCP reconnects 0-RTT
    on supported systems. [PR #840]
    Changes:
    * Reorganize source tree. [PR #822]
    * Refactoring of connection handling to prevent code duplication. [PR #839]
    * New dynamic array data structure to prevent simple logic flaws in array
    handling in various code paths. [PR #841]
    Bugfixes:
    * `ares_destroy()` race condition during shutdown due to missing lock. [PR #831]
    Features in 1.32:
    * Add support for DNS 0x20 to help prevent cache poisoning attacks, enabled
    by specifying `ARES_FLAG_DNS0x20`.  Disabled by default. [PR #800]
    * Rework query timeout logic to automatically adjust timeouts based on network
    conditions.  The timeout specified now is only used as a hint until there
    is enough history to calculate a more valid timeout. [PR #794]
    Changes:
    * DNS RR TXT strings should not be automatically concatenated as there are use
    cases outside of RFC 7208.  In order to maintain ABI compliance, the ability
    to retrieve TXT strings concatenated is retained as well as a new API to
    retrieve the individual strings.  This restores behavior from c-ares 1.20.0.
    [PR #801]
    * Clean up header inclusion logic to make hacking on code easier. [PR #797]
    * GCC/Clang: Enable even more strict warnings to catch more coding flaws. [253bdee]
    Bugfixes:
    * Tests: Fix thread race condition in test cases for EventThread. [PR #803]
    * Thread Saftey: `ares_timeout()` was missing lock. [74a64e4]

++++ nfs-utils:

  - Update to version 2.8.1
  - https://lore.kernel.org/linux-nfs/4a86eea3-973e-4535-8aa5-f3b8b5f7934d@redhat.com/
  - https://kernel.org/pub/linux/utils/nfs-utils/2.8.1/2.8.1-Changelog
  - Add new binary nfsdctl
  - The default number of nfsd threads is now 16 instead of 8
  - Removed patchs from previous releases
  - 0001-exportfs-remove-warning-if-neither-subtree_check-or-.patch
  - 0002-conffile-don-t-report-error-from-conf_init_file.patch
  - 0003-conffile-allow-usr-etc-to-provide-any-config-files-e.patch
  - 0004-fsidd-call-anonymous-sockets-by-their-name-only-don-.patch
  - 0001-gssd-revert-commit-a5f3b7ccb01c.patch
  - 0002-gssd-revert-commit-513630d720bd.patch
  - 0003-gssd-switch-to-using-rpc_gss_seccreate.patch
  - 0004-gssd-handle-KRB5_AP_ERR_BAD_INTEGRITY-for-machine-cr.patch
  - 0005-gssd-handle-KRB5_AP_ERR_BAD_INTEGRITY-for-user-crede.patch
  - 0006-configure-check-for-rpc_gss_seccreate.patch
  - Turn nfs-utils-1.0.7-bind-syntax.patch to git patch (bug reference,
    easier to refresh via git, likely it can be now removed)
  - Add BuildRequires libnl-3.0, readline

++++ libpng16:

  - version update to 1.6.44:
    * Hardened calculations in chroma handling to prevent overflows, and
    relaxed a constraint in cHRM validation to accomodate the standard
    ACES AP1 set of color primaries.
    (Contributed by John Bowler)
    * Removed the ASM implementation of ARM Neon optimizations and updated
    the build accordingly. Only the remaining C implementation shall be
    used from now on, thus ensuring the support of the PAC/BTI security
    features on ARM64.
    (Contributed by Ross Burton and John Bowler)
    * Fixed the pickup of the PNG_HARDWARE_OPTIMIZATIONS option in the
    CMake build on FreeBSD/amd64. This is an important performance fix
    on this platform.
    * Applied various fixes and improvements to the CMake build.
    (Contributed by Eric Riff, Benjamin Buch and Erik Scholz)
    * Added fuzzing targets for the simplified read API.
    (Contributed by Mikhail Khachayants)
    * Fixed a build error involving pngtest.c under a custom config.
    This was a regression introduced in a code cleanup in libpng-1.6.43.
    (Contributed by Ben Wagner)
    * Fixed and improved the config files for AppVeyor CI and Travis CI.
  - Drop upstream patch:
    * 563.patch

++++ microos-tools:

  - Update to version 4.0+git2:
    * Add RemainAfterExit=true to autorelabel services

++++ permissions:

  - Update to version 1699_20241029:
    * Add RPM macros; moved from rpm-config-SUSE
    * package RPM macros together with permctl, to avoid having to setup an
    extra sub-package.

++++ python-argcomplete:

  - Update to the version 3.5.1:
  - Restore compatibility with argparse in Python 3.12.7+
  - Use project.scripts instead of setuptools scripts
  - Test infrastructure improvements
  - Remove upstreamed patches:
  - argparse-3_12_7.patch
  - Add _multibuild (to make testing against fully installed package)

++++ python-httpcore:

  - Update to 1.0.6
    * Relax `trio` dependency pinning.
    * Handle `trio` raising `NotImplementedError` on unsupported platforms.
    * Handle mapping `ssl.SSLError` to `httpcore.ConnectError`.
  - Update Requires from pyproject.toml

++++ qemu:

  - Update to version 9.1.1:
    Full changelog here:
    https://lore.kernel.org/qemu-devel/7f0561ec-3564-4860-bacf-a98071a5ce52@tls.msk.ru/
    Some of the most notable features:
    * ui/dbus: fix filtering all update messages
    * ui/win32: fix potential use-after-free with dbus shared memory
    * ui/dbus: fix leak on message filtering
    * hw/audio/hda: fix memory leak on audio setup
    * hw/audio/hda: free timer on exit
    * hw/char/pl011: Use correct masks for IBRD and FBRD
    * hw/intc/arm_gicv3_cpuif: Add cast to match the documentation
    * hw/intc/arm_gicv3: Add cast to match the documentation
    * hw/intc/arm_gicv3: Add cast to match the documentation
    * meson: ensure -mcx16 is passed when detecting ATOMIC128
    * meson: define qemu_isa_flags
    * meson: fix machine option for x86_version
    * target/m68k: Always return a temporary from gen_lea_mode
    * tcg/ppc: Use TCG_REG_TMP2 for scratch index in prepare_host_addr
    * tcg/ppc: Use TCG_REG_TMP2 for scratch tcg_out_qemu_st
    * linux-user: Fix parse_elf_properties GNU0_MAGIC check
    * linux-user/flatload: Take mmap_lock in load_flt_binary()
    * vnc: fix crash when no console attached
    * testing: bump mips64el cross to bookworm and fix package list
    * hw/sd/sdcard: Fix handling of disabled boot partitions
    * target/arm: Avoid target_ulong for physical address lookups
    * block/reqlist: allow adding overlapping requests
    * util/timer: avoid deadlock when shutting down
    * hw/mips/jazz: fix typo in in-built NIC alias
    * tcg: Fix iteration step in 32-bit gvec operation
    * hw/loongarch/virt: Add description for virt machine type
    * migration/multifd: Fix p->iov leak in multifd-uadk.c
    * target/ppc: Fix migration of CPUs with TLB_EMB TLB type
    * target/hppa: Fix random 32-bit linux-user crashes
    * target/arm: Correct ID_AA64ISAR1_EL1 value for neoverse-v1
    * hw/char/stm32l4x5_usart.c: Enable USART ACK bit response
    * migration/multifd: Fix rb->receivedmap cleanup race
    * mac_dbdma: Remove leftover `dma_memory_unmap` calls
  - Fix boo#1231166:
    * [openSUSE][RPM] The qemu translation is not being installed (boo#1231166)

++++ skopeo:

  - Add patch for CVE-2024-9676 (bsc#1231698)
    * 0001-Use-securejoin.SecureJoin-when-forming-userns-paths.patch

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#181
  - explicitly use bash as shell (bsc#1231018)
  - 1.18

------------------------------------------------------------------
------------------  2024-10-28  -  Oct 28 2024  -------------------
------------------------------------------------------------------

++++ containerd:

  - Update to containerd v1.7.23. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.23>
  - Rebase patches:
    * 0001-BUILD-SLE12-revert-btrfs-depend-on-kernel-UAPI-inste.patch

++++ kernel-default:

  - smb: client: fix UAF in async decryption (bsc#1232418
    CVE-2024-50047).
  - commit 381863e
  - e1000e: fix force smbus during suspend flow (git-fixes).
  - commit f9cbf12
  - btrfs: wait for fixup workers before stopping cleaner kthread
    during umount (bsc#1232262 CVE-2024-49867).
  - btrfs: fix race setting file private on concurrent lseek using
    same fd (bsc#1231869 CVE-2024-47741).
  - commit af36a3e
  - ppp: fix ppp_async_encode() illegal access (CVE-2024-50035
    bsc#1232392).
  - net: avoid potential underflow in qdisc_pkt_len_init() with UFO
    (CVE-2024-49949 bsc#1232160).
  - commit f4bcea0
  - ice: map XDP queues to vectors in ice_vsi_map_rings_to_vectors()
    (git-fixes).
  - Refresh
    patches.suse/ice-move-netif_queue_set_napi-to-rtnl-protected-sect.patch.
  - commit 7b44c3c
  - net/mlx5: Check capability for fw_reset (git-fixes).
  - Refresh
    patches.suse/net-mlx5-Fix-MTMP-register-capability-offset-in-MCAM.patch.
  - commit 480249d
  - net/mlx5e: Don't call cleanup on profile rollback failure
    (git-fixes).
  - net/mlx5: Unregister notifier on eswitch init failure
    (git-fixes).
  - net/mlx5: Fix command bitmask initialization (git-fixes).
  - net/mlx5: Check for invalid vector index on EQ creation
    (git-fixes).
  - e1000e: change I219 (19) devices to ADP (git-fixes).
  - ice: Flush FDB entries before reset (git-fixes).
  - ice: Fix netif_is_ice() in Safe Mode (git-fixes).
  - ice: fix VLAN replay after reset (git-fixes).
  - ice: disallow DPLL_PIN_STATE_SELECTABLE for dpll output pins
    (git-fixes).
  - ice: clear port vlan config during reset (git-fixes).
  - ice: set correct dst VSI in only LAN filters (git-fixes).
  - net/mlx5: Added cond_resched() to crdump collection (git-fixes).
  - vduse: avoid using __GFP_NOFAIL (git-fixes).
  - igb: Always call igb_xdp_ring_update_tail() under Tx lock
    (git-fixes).
  - ice: fix VSI lists confusion when adding VLANs (git-fixes).
  - ice: fix accounting for filters shared by multiple VSIs
    (git-fixes).
  - ice: Fix lldp packets dropping after changing the number of
    channels (git-fixes).
  - net/mlx5: Add missing masks and QoS bit masks for scheduling
    elements (git-fixes).
  - net/mlx5: Explicitly set scheduling element and TSAR type
    (git-fixes).
  - net/mlx5e: Add missing link mode to ptys2ext_ethtool_map
    (git-fixes).
  - net/mlx5e: Add missing link modes to ptys2ethtool_map
    (git-fixes).
  - net/mlx5: Update the list of the PCI supported devices
    (git-fixes).
  - ice: do not bring the VSI up, if it was down before the XDP
    setup (git-fixes).
  - igc: Unlock on error in igc_io_resume() (git-fixes).
  - igb: Fix not clearing TimeSync interrupts for 82580 (git-fixes).
  - ice: fix truesize operations for PAGE_SIZE >= 8192 (git-fixes).
  - ice: fix ICE_LAST_OFFSET formula (git-fixes).
  - ice: fix page reuse when PAGE_SIZE is over 8k (git-fixes).
  - cxgb4: add forgotten u64 ivlan cast before shift (git-fixes).
  - igc: Fix qbv tx latency by setting gtxoffset (git-fixes).
  - igc: Fix reset adapter logics when tx mode change (git-fixes).
  - igc: Fix qbv_config_change_errors logics (git-fixes).
  - igc: Fix packet still tx after gate close by reducing i226
    MAC retry buffer (git-fixes).
  - net/mlx5e: Correctly report errors for ethtool rx flows
    (git-fixes).
  - ice: Fix reset handler (git-fixes).
  - idpf: fix UAFs when destroying the queues (git-fixes).
  - idpf: fix memleak in vport interrupt configuration (git-fixes).
  - idpf: fix memory leaks and crashes while performing a soft reset
    (git-fixes).
  - igc: Fix double reset adapter triggered from a single taprio
    cmd (git-fixes).
  - net/mlx5e: Add a check for the return value from
    mlx5_port_set_eth_ptys (git-fixes).
  - net/mlx5e: Require mlx5 tc classifier action support for IPsec
    prio capability (git-fixes).
  - net/mlx5: Lag, don't use the hardcoded value of the first port
    (git-fixes).
  - net/mlx5: Fix error handling in irq_pool_request_irq
    (git-fixes).
  - ice: add missing WRITE_ONCE when clearing ice_rx_ring::xdp_prog
    (git-fixes).
  - ice: replace synchronize_rcu with synchronize_net (git-fixes).
  - ice: don't busy wait for Rx queue disable in ice_qp_dis()
    (git-fixes).
  - ice: respect netif readiness in AF_XDP ZC related ndo's
    (git-fixes).
  - gve: Fix an edge case for TSO skb validity check (git-fixes).
  - ice: Fix recipe read procedure (git-fixes).
  - gve: Fix XDP TX completion handling when counters overflow
    (git-fixes).
  - RDMA/mlx5: Use sq timestamp as QP timestamp when RoCE is
    disabled (git-fixes).
  - idpf: avoid bloating &idpf_q_vector with big %NR_CPUS
    (git-fixes).
  - i40e: Fix XDP program unloading while removing the driver
    (git-fixes).
  - ice: use proper macro for testing bit (git-fixes).
  - ice: Reject pin requests with unsupported flags (git-fixes).
  - e1000e: Fix S0ix residency on corporate systems (git-fixes).
  - net/mlx5e: Add mqprio_rl cleanup and free in
    mlx5e_priv_cleanup() (git-fixes).
  - ice: Rebuild TC queues on VSI queue reconfiguration (git-fixes).
  - bnxt_en: Restore PTP tx_avail count in case of skb_pad() error
    (git-fixes).
  - ice: Fix VSI list rule with ICE_SW_LKUP_LAST type (git-fixes).
  - ice: implement AQ download pkg retry (git-fixes).
  - ice: fix 200G link speed message log (git-fixes).
  - ice: avoid IRQ collision to fix init failure on ACPI S3 resume
    (git-fixes).
  - bnxt_en: Cap the size of HWRM_PORT_PHY_QCFG forwarded response
    (git-fixes).
  - gve: ignore nonrelevant GSO type bits when processing TSO
    headers (git-fixes).
  - net/mlx5e: Fix features validation check for tunneled UDP
    (non-VXLAN) packets (git-fixes).
  - ice: add flag to distinguish reset from .ndo_bpf in XDP rings
    config (git-fixes).
  - ice: remove af_xdp_zc_qps bitmap (git-fixes).
  - ice: fix reads from NVM Shadow RAM on E830 and E825-C devices
    (git-fixes).
  - ice: fix iteration of TLVs in Preserved Fields Area (git-fixes).
  - net/mlx5: Stop waiting for PCI if pci channel is offline
    (git-fixes).
  - ice: fix 200G PHY types to link speed mapping (git-fixes).
  - e1000e: move force SMBUS near the end of enable_ulp function
    (git-fixes).
  - ice: fix accounting if a VLAN already exists (git-fixes).
  - idpf: don't enable NAPI and interrupts prior to allocating Rx
    buffers (git-fixes).
  - net/mlx5e: Fix UDP GSO for encapsulated packets (git-fixes).
  - net/mlx5e: Use rx_missed_errors instead of rx_dropped for
    reporting buffer exhaustion (git-fixes).
  - net/mlx5e: Fix IPsec tunnel mode offload feature check
    (git-fixes).
  - net/mlx5: Lag, do bond only if slaves agree on roce state
    (git-fixes).
  - idpf: Interpret .set_channels() input differently (git-fixes).
  - ice: Interpret .set_channels() input differently (git-fixes).
  - idpf: don't skip over ethtool tcp-data-split setting
    (git-fixes).
  - ice: Fix package download algorithm (git-fixes).
  - mlx5: stop warning for 64KB pages (git-fixes).
  - mlx5: avoid truncating error message (git-fixes).
  - qed: avoid truncating work queue length (git-fixes).
  - cxgb4: unnecessary check for 0 in the free_sge_txq_uld()
    function (git-fixes).
  - cxgb4: Properly lock TX queue for the selftest (git-fixes).
  - net: qede: use return from qede_parse_actions() (git-fixes).
  - net: qede: use return from qede_parse_flow_attr() for flow_spec
    (git-fixes).
  - net: qede: use return from qede_parse_flow_attr() for flower
    (git-fixes).
  - net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
    (git-fixes).
  - iavf: Fix TC config comparison with existing adapter TC config
    (git-fixes).
  - i40e: Report MFS in decimal base instead of hex (git-fixes).
  - eth: bnxt: fix counting packets discarded due to OOM and netpoll
    (git-fixes).
  - bnxt_en: Fix error recovery for 5760X (P7) chips (git-fixes).
  - bnxt_en: Fix the PCI-AER routines (git-fixes).
  - bnxt_en: refactor reset close code (git-fixes).
  - ice: Fix checking for unsupported keys on non-tunnel device
    (git-fixes).
  - ice: tc: allow zero flags in parsing tc flower (git-fixes).
  - ice: tc: check src_vsi in case of traffic from VF (git-fixes).
  - vdpa: Fix an error handling path in eni_vdpa_probe()
    (git-fixes).
  - vdpa_sim_blk: allocate the buffer zeroed (git-fixes).
  - vdpa_sim_blk: Fix the potential leak of mgmt_dev (git-fixes).
  - commit 58c03fe
  - dcache: keep dentry_hashtable or d_hash_shift even when not used (git-fixes).
  - commit d6ce9b3
  - x86: fix user address masking non-canonical speculation issue (git-fixes).
  - commit 561e50e
  - x86: make the masked_user_access_begin() macro use its argument only  once (git-fixes).
  - commit aa2495e
  - x86: do the user address masking outside the user access area (git-fixes).
  - commit a4b9c7b
  - x86: support user address masking instead of non-speculative conditional (git-fixes).
  - commit 6536d1f
  - runtime constants: add x86 architecture support (git-fixes).
  - commit 32e2def
  - runtime constants: add default dummy infrastructure (git-fixes).
  - commit dd17ee6
  - vfs: dcache: move hashlen_hash() from callers into d_hash() (git-fixes).
  - commit c440ebe
  - hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event (git-fixes).
  - commit 3dc5225

++++ kernel-firmware-all:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-amdgpu:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-ath10k:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-ath11k:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-ath12k:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-atheros:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-bluetooth:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-bnx2:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-brcm:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-chelsio:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-dpaa2:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-i915:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-intel:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-iwlwifi:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-liquidio:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-marvell:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-media:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-mediatek:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-mellanox:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-mwifiex:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-network:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-nfp:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-nvidia:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-platform:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-prestera:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-qcom:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-qlogic:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-radeon:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-realtek:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-serial:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-sound:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-ti:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-ueagle:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-firmware-usb-network:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ kernel-rt:

  - smb: client: fix UAF in async decryption (bsc#1232418
    CVE-2024-50047).
  - commit 381863e
  - e1000e: fix force smbus during suspend flow (git-fixes).
  - commit f9cbf12
  - btrfs: wait for fixup workers before stopping cleaner kthread
    during umount (bsc#1232262 CVE-2024-49867).
  - btrfs: fix race setting file private on concurrent lseek using
    same fd (bsc#1231869 CVE-2024-47741).
  - commit af36a3e
  - ppp: fix ppp_async_encode() illegal access (CVE-2024-50035
    bsc#1232392).
  - net: avoid potential underflow in qdisc_pkt_len_init() with UFO
    (CVE-2024-49949 bsc#1232160).
  - commit f4bcea0
  - ice: map XDP queues to vectors in ice_vsi_map_rings_to_vectors()
    (git-fixes).
  - Refresh
    patches.suse/ice-move-netif_queue_set_napi-to-rtnl-protected-sect.patch.
  - commit 7b44c3c
  - net/mlx5: Check capability for fw_reset (git-fixes).
  - Refresh
    patches.suse/net-mlx5-Fix-MTMP-register-capability-offset-in-MCAM.patch.
  - commit 480249d
  - net/mlx5e: Don't call cleanup on profile rollback failure
    (git-fixes).
  - net/mlx5: Unregister notifier on eswitch init failure
    (git-fixes).
  - net/mlx5: Fix command bitmask initialization (git-fixes).
  - net/mlx5: Check for invalid vector index on EQ creation
    (git-fixes).
  - e1000e: change I219 (19) devices to ADP (git-fixes).
  - ice: Flush FDB entries before reset (git-fixes).
  - ice: Fix netif_is_ice() in Safe Mode (git-fixes).
  - ice: fix VLAN replay after reset (git-fixes).
  - ice: disallow DPLL_PIN_STATE_SELECTABLE for dpll output pins
    (git-fixes).
  - ice: clear port vlan config during reset (git-fixes).
  - ice: set correct dst VSI in only LAN filters (git-fixes).
  - net/mlx5: Added cond_resched() to crdump collection (git-fixes).
  - vduse: avoid using __GFP_NOFAIL (git-fixes).
  - igb: Always call igb_xdp_ring_update_tail() under Tx lock
    (git-fixes).
  - ice: fix VSI lists confusion when adding VLANs (git-fixes).
  - ice: fix accounting for filters shared by multiple VSIs
    (git-fixes).
  - ice: Fix lldp packets dropping after changing the number of
    channels (git-fixes).
  - net/mlx5: Add missing masks and QoS bit masks for scheduling
    elements (git-fixes).
  - net/mlx5: Explicitly set scheduling element and TSAR type
    (git-fixes).
  - net/mlx5e: Add missing link mode to ptys2ext_ethtool_map
    (git-fixes).
  - net/mlx5e: Add missing link modes to ptys2ethtool_map
    (git-fixes).
  - net/mlx5: Update the list of the PCI supported devices
    (git-fixes).
  - ice: do not bring the VSI up, if it was down before the XDP
    setup (git-fixes).
  - igc: Unlock on error in igc_io_resume() (git-fixes).
  - igb: Fix not clearing TimeSync interrupts for 82580 (git-fixes).
  - ice: fix truesize operations for PAGE_SIZE >= 8192 (git-fixes).
  - ice: fix ICE_LAST_OFFSET formula (git-fixes).
  - ice: fix page reuse when PAGE_SIZE is over 8k (git-fixes).
  - cxgb4: add forgotten u64 ivlan cast before shift (git-fixes).
  - igc: Fix qbv tx latency by setting gtxoffset (git-fixes).
  - igc: Fix reset adapter logics when tx mode change (git-fixes).
  - igc: Fix qbv_config_change_errors logics (git-fixes).
  - igc: Fix packet still tx after gate close by reducing i226
    MAC retry buffer (git-fixes).
  - net/mlx5e: Correctly report errors for ethtool rx flows
    (git-fixes).
  - ice: Fix reset handler (git-fixes).
  - idpf: fix UAFs when destroying the queues (git-fixes).
  - idpf: fix memleak in vport interrupt configuration (git-fixes).
  - idpf: fix memory leaks and crashes while performing a soft reset
    (git-fixes).
  - igc: Fix double reset adapter triggered from a single taprio
    cmd (git-fixes).
  - net/mlx5e: Add a check for the return value from
    mlx5_port_set_eth_ptys (git-fixes).
  - net/mlx5e: Require mlx5 tc classifier action support for IPsec
    prio capability (git-fixes).
  - net/mlx5: Lag, don't use the hardcoded value of the first port
    (git-fixes).
  - net/mlx5: Fix error handling in irq_pool_request_irq
    (git-fixes).
  - ice: add missing WRITE_ONCE when clearing ice_rx_ring::xdp_prog
    (git-fixes).
  - ice: replace synchronize_rcu with synchronize_net (git-fixes).
  - ice: don't busy wait for Rx queue disable in ice_qp_dis()
    (git-fixes).
  - ice: respect netif readiness in AF_XDP ZC related ndo's
    (git-fixes).
  - gve: Fix an edge case for TSO skb validity check (git-fixes).
  - ice: Fix recipe read procedure (git-fixes).
  - gve: Fix XDP TX completion handling when counters overflow
    (git-fixes).
  - RDMA/mlx5: Use sq timestamp as QP timestamp when RoCE is
    disabled (git-fixes).
  - idpf: avoid bloating &idpf_q_vector with big %NR_CPUS
    (git-fixes).
  - i40e: Fix XDP program unloading while removing the driver
    (git-fixes).
  - ice: use proper macro for testing bit (git-fixes).
  - ice: Reject pin requests with unsupported flags (git-fixes).
  - e1000e: Fix S0ix residency on corporate systems (git-fixes).
  - net/mlx5e: Add mqprio_rl cleanup and free in
    mlx5e_priv_cleanup() (git-fixes).
  - ice: Rebuild TC queues on VSI queue reconfiguration (git-fixes).
  - bnxt_en: Restore PTP tx_avail count in case of skb_pad() error
    (git-fixes).
  - ice: Fix VSI list rule with ICE_SW_LKUP_LAST type (git-fixes).
  - ice: implement AQ download pkg retry (git-fixes).
  - ice: fix 200G link speed message log (git-fixes).
  - ice: avoid IRQ collision to fix init failure on ACPI S3 resume
    (git-fixes).
  - bnxt_en: Cap the size of HWRM_PORT_PHY_QCFG forwarded response
    (git-fixes).
  - gve: ignore nonrelevant GSO type bits when processing TSO
    headers (git-fixes).
  - net/mlx5e: Fix features validation check for tunneled UDP
    (non-VXLAN) packets (git-fixes).
  - ice: add flag to distinguish reset from .ndo_bpf in XDP rings
    config (git-fixes).
  - ice: remove af_xdp_zc_qps bitmap (git-fixes).
  - ice: fix reads from NVM Shadow RAM on E830 and E825-C devices
    (git-fixes).
  - ice: fix iteration of TLVs in Preserved Fields Area (git-fixes).
  - net/mlx5: Stop waiting for PCI if pci channel is offline
    (git-fixes).
  - ice: fix 200G PHY types to link speed mapping (git-fixes).
  - e1000e: move force SMBUS near the end of enable_ulp function
    (git-fixes).
  - ice: fix accounting if a VLAN already exists (git-fixes).
  - idpf: don't enable NAPI and interrupts prior to allocating Rx
    buffers (git-fixes).
  - net/mlx5e: Fix UDP GSO for encapsulated packets (git-fixes).
  - net/mlx5e: Use rx_missed_errors instead of rx_dropped for
    reporting buffer exhaustion (git-fixes).
  - net/mlx5e: Fix IPsec tunnel mode offload feature check
    (git-fixes).
  - net/mlx5: Lag, do bond only if slaves agree on roce state
    (git-fixes).
  - idpf: Interpret .set_channels() input differently (git-fixes).
  - ice: Interpret .set_channels() input differently (git-fixes).
  - idpf: don't skip over ethtool tcp-data-split setting
    (git-fixes).
  - ice: Fix package download algorithm (git-fixes).
  - mlx5: stop warning for 64KB pages (git-fixes).
  - mlx5: avoid truncating error message (git-fixes).
  - qed: avoid truncating work queue length (git-fixes).
  - cxgb4: unnecessary check for 0 in the free_sge_txq_uld()
    function (git-fixes).
  - cxgb4: Properly lock TX queue for the selftest (git-fixes).
  - net: qede: use return from qede_parse_actions() (git-fixes).
  - net: qede: use return from qede_parse_flow_attr() for flow_spec
    (git-fixes).
  - net: qede: use return from qede_parse_flow_attr() for flower
    (git-fixes).
  - net: qede: sanitize 'rc' in qede_add_tc_flower_fltr()
    (git-fixes).
  - iavf: Fix TC config comparison with existing adapter TC config
    (git-fixes).
  - i40e: Report MFS in decimal base instead of hex (git-fixes).
  - eth: bnxt: fix counting packets discarded due to OOM and netpoll
    (git-fixes).
  - bnxt_en: Fix error recovery for 5760X (P7) chips (git-fixes).
  - bnxt_en: Fix the PCI-AER routines (git-fixes).
  - bnxt_en: refactor reset close code (git-fixes).
  - ice: Fix checking for unsupported keys on non-tunnel device
    (git-fixes).
  - ice: tc: allow zero flags in parsing tc flower (git-fixes).
  - ice: tc: check src_vsi in case of traffic from VF (git-fixes).
  - vdpa: Fix an error handling path in eni_vdpa_probe()
    (git-fixes).
  - vdpa_sim_blk: allocate the buffer zeroed (git-fixes).
  - vdpa_sim_blk: Fix the potential leak of mgmt_dev (git-fixes).
  - commit 58c03fe
  - dcache: keep dentry_hashtable or d_hash_shift even when not used (git-fixes).
  - commit d6ce9b3
  - x86: fix user address masking non-canonical speculation issue (git-fixes).
  - commit 561e50e
  - x86: make the masked_user_access_begin() macro use its argument only  once (git-fixes).
  - commit aa2495e
  - x86: do the user address masking outside the user access area (git-fixes).
  - commit a4b9c7b
  - x86: support user address masking instead of non-speculative conditional (git-fixes).
  - commit 6536d1f
  - runtime constants: add x86 architecture support (git-fixes).
  - commit 32e2def
  - runtime constants: add default dummy infrastructure (git-fixes).
  - commit dd17ee6
  - vfs: dcache: move hashlen_hash() from callers into d_hash() (git-fixes).
  - commit c440ebe
  - hv_netvsc: Fix VF namespace also in synthetic NIC NETDEV_REGISTER event (git-fixes).
  - commit 3dc5225

++++ llvm19:

  - Update llvm19.keyring from upstream.

++++ openssl-3:

  - Update to 3.2.3:
    * Changes between 3.2.2 and 3.2.3:
  - Fixed possible denial of service in X.509 name checks. [CVE-2024-6119]
  - Fixed possible buffer overread in SSL_select_next_proto(). [CVE-2024-5535]
    * Changes between 3.2.1 and 3.2.2:
  - Fixed potential use after free after SSL_free_buffers() is called. [CVE-2024-4741]
  - Fixed an issue where checking excessively long DSA keys or parameters may
    be very slow. [CVE-2024-4603]
  - Improved EC/DSA nonce generation routines to avoid bias and timing
    side channel leaks.
  - Fixed an issue where some non-default TLS server configurations can cause
    unbounded memory growth when processing TLSv1.3 sessions. [CVE-2024-2511]
  - New atexit configuration switch, which controls whether the OPENSSL_cleanup
    is registered when libcrypto is unloaded. This can be used on platforms
    where using atexit() from shared libraries causes crashes on exit.
  - Fixed bug where SSL_export_keying_material() could not be used with QUIC
    connections.
    * Add openssl-skip-quic-pairwise.patch to adapt the pairwise tests.
    * Merge openssl-FIPS-release_num_in_version_string.patch into
    openssl-FIPS-services-minimize.patch
    * Rebase patches:
  - openssl-Add-changes-to-ectest-and-eccurve.patch
  - openssl-FIPS-140-3-keychecks.patch
  - openssl-FIPS-embed-hmac.patch
  - openssl-Remove-EC-curves.patch
  - openssl-skipped-tests-EC-curves.patch
  - openssl-FIPS-early-KATS.patch
  - openssl-Allow-disabling-of-SHA1-signatures.patch
  - openssl-3-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch
  - openssl-FIPS-limit-rsa-encrypt.patch
  - openssl-FIPS-Use-OAEP-in-KATs-support-fixed-OAEP-seed.patch
  - openssl-FIPS-Use-digest_sign-digest_verify-in-self-test.patch
  - openssl-FIPS-140-3-DRBG.patch
  - openssl-FIPS-140-3-zeroization.patch
  - openssl-Add-FIPS-indicator-parameter-to-HKDF.patch
  - openssl-FIPS-Remove-X9.31-padding-from-FIPS-prov.patch
  - openssl-FIPS-Add-explicit-indicator-for-key-length.patch
  - openssl-pbkdf2-Set-minimum-password-length-of-8-bytes.patch
  - openssl-FIPS-signature-Add-indicator-for-PSS-salt-length.patch
  - openssl-3-FIPS-GCM-Implement-explicit-indicator-for-IV-gen.patch
  - openssl-FIPS-enforce-EMS-support.patch
  - openssl-3-jitterentropy-3.4.0.patch
    * Remove not needed patches:
  - openssl-Allow-SHA1-in-seclevel-2-if-rh-allow-sha1-signatures.patch
  - openssl-3-FIPS-PCT_rsa_keygen.patch
  - Remove the engines' directories and symlinks that were added to
    allow parallel installations with openssl-1_1.
    * Remove openssl-3-use-include-directive.patch
  - Remove the hardcoded DEFAULT_SUSE cipherlist selection.
    * Remove openssl-DEFAULT_SUSE_cipher.patch

++++ openssl:

  - Update to 3.2.3

++++ lsof:

  - Add reproducible.patch to not store build host kernel version (boo#1232425)

++++ openssh:

  - Don't force using gcc11 on SLFO/ALP which have a newer version.
  - Add patches from upstream:
  - To fix a copy&paste oversight in an ifdef :
    * 0001-fix-utmpx-ifdef.patch
  - To fix a regression introduced when the "Match" criteria
    tokenizer was modified since it stopped supporting the
    "Match criteria=argument" format:
    * 0002-upstream-fix-regression-introduced-when-I-switched-the-Match.patch
  - To fix the previous patch which broke on negated Matches:
    * 0003-upstream-fix-previous-change-to-ssh_config-Match_-which-broken-on.patch
  - To fix the ML-KEM768x25519 kex algorithm on big-endian systems:
    * 0004-upstream-fix-ML-KEM768x25519-KEX-on-big-endian-systems-spotted-by.patch

++++ python-charset-normalizer:

  - switch to PEP517 build

++++ python313-pyparsing:

  - update to 3.2.0:
    * Discontinued support for Python 3.6, 3.7, and 3.8. Adopted
    new Python features from Python versions 3.7-3.9:
  - Updated type annotations to use built-in container types
    instead of names imported from the `typing` module
    (e.g., `list[str]` vs `List[str]`).
  - Reworked portions of the packrat cache to leverage
    insertion-preserving ordering in dicts (including removal of
    uses of `OrderedDict`).
  - Changed `pdb.set_trace()` call in `ParserElement.set_break()`
    to `breakpoint()`.
  - Converted `typing.NamedTuple` to `dataclasses.dataclass`
    in railroad diagramming code.
  - Added `from __future__ import annotations` to clean up
    some type annotations.

++++ ucode-amd:

  - Update to version 20241028 (git commit 987607d681cb):
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * i915: Add Xe3LPD DMC
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add firmware for Cirrus CS35L41
    * linux-firmware: Update firmware file for Intel BlazarU core
    * Makefile: error out of 'install' if COPYOPTS is set

++++ xkeyboard-config:

  - n_fi-kotoistus-metainfo.patch
    * add meta information for default variant of "fi" keyboard layout
    "kotoistus" needed for GNOME or other users of xkeyboard meta XML
    files (boo#1227420)

------------------------------------------------------------------
------------------  2024-10-27  -  Oct 27 2024  -------------------
------------------------------------------------------------------

++++ protobuf-c:

  - Implement naming guidelines and rename libprotobuf-c-devel back
    to just %name-devel. (The divergence came about on Nov 19 2021
    as a result of merging two subpackages.)

------------------------------------------------------------------
------------------  2024-10-26  -  Oct 26 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Drop USB dwc2 patch that caused a regression on RPi3 (bsc#1232342)
  - commit c84227d
  - ACPI: PRM: Clean up guid type in struct prm_handler_info
    (git-fixes).
  - commit 8c8a801
  - ALSA: hda/realtek: Add subwoofer quirk for Acer Predator G9-593
    (stable-fixes).
  - commit 595e400
  - ACPI: PRM: Find EFI_MEMORY_RUNTIME block for PRM handler and
    context (git-fixes).
  - ata: libata: Set DID_TIME_OUT for commands that actually timed
    out (git-fixes).
  - ASoC: max98388: Fix missing increment of variable slot_found
    (git-fixes).
  - ASoC: qcom: Fix NULL Dereference in
    asoc_qcom_lpass_cpu_platform_probe() (git-fixes).
  - ALSA: hda/realtek: Update default depop procedure (git-fixes).
  - ALSA: hda/tas2781: select CRC32 instead of CRC32_SARWATE
    (git-fixes).
  - ALSA: firewire-lib: Avoid division by zero in
    apply_constraint_to_size() (git-fixes).
  - cpufreq/amd-pstate: Fix amd_pstate mode switch on shared memory
    systems (git-fixes).
  - ntb: intel: Fix the NULL vs IS_ERR() bug for
    debugfs_create_dir() (git-fixes).
  - commit 33d7ff7

++++ kernel-rt:

  - Drop USB dwc2 patch that caused a regression on RPi3 (bsc#1232342)
  - commit c84227d
  - ACPI: PRM: Clean up guid type in struct prm_handler_info
    (git-fixes).
  - commit 8c8a801
  - ALSA: hda/realtek: Add subwoofer quirk for Acer Predator G9-593
    (stable-fixes).
  - commit 595e400
  - ACPI: PRM: Find EFI_MEMORY_RUNTIME block for PRM handler and
    context (git-fixes).
  - ata: libata: Set DID_TIME_OUT for commands that actually timed
    out (git-fixes).
  - ASoC: max98388: Fix missing increment of variable slot_found
    (git-fixes).
  - ASoC: qcom: Fix NULL Dereference in
    asoc_qcom_lpass_cpu_platform_probe() (git-fixes).
  - ALSA: hda/realtek: Update default depop procedure (git-fixes).
  - ALSA: hda/tas2781: select CRC32 instead of CRC32_SARWATE
    (git-fixes).
  - ALSA: firewire-lib: Avoid division by zero in
    apply_constraint_to_size() (git-fixes).
  - cpufreq/amd-pstate: Fix amd_pstate mode switch on shared memory
    systems (git-fixes).
  - ntb: intel: Fix the NULL vs IS_ERR() bug for
    debugfs_create_dir() (git-fixes).
  - commit 33d7ff7

++++ tuned:

  - Correct service cleanup calls in preun and postun scripts
  - Move tmpfile_create before service_add_post
  - Added python3-pyudev and python3-dbus-python as BuildRequires
    for added check section
  - Move user defined profiles
    from /etc/tuned/
    into subdirs /etc/tuned/PROFILE
    via spec's %post routine
  - Enable make test in check section
  - Update has at least parts of jsc#PED-10695

------------------------------------------------------------------
------------------  2024-10-25  -  Oct 25 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix networking in erofs integration test
    The network setup was systemd-networkd based but
    the provided network config was not for systemd

++++ kernel-default:

  - platform/x86: x86-android-tablets: Fix use after free on
    platform_device_register() errors (bsc#1232093 CVE-2024-49986).
  - commit a5650bf
  - thermal: core: Free tzp copy along with the thermal zone
    (bsc#1231951 CVE-2024-50027).
  - commit 5199a1f
  - device-dax: correct pgoff align in dax_set_mapping()
    (bsc#1231956 CVE-2024-50022).
  - commit 527a95e
  - ntb: ntb_hw_switchtec: Fix use after free vulnerability in
    switchtec_ntb_remove due to race condition (CVE-2024-50059
    bsc#1232345).
  - commit 4d86c47
  - mm: call the security_mmap_file() LSM hook in remap_file_pages()
    (CVE-2024-47745 bsc#1232135).
  - commit 18a36ea
  - Bluetooth: L2CAP: Fix uaf in l2cap_connect (CVE-2024-49950
    bsc#1232159).
  - commit c906740
  - rxrpc: Fix a race between socket set up and I/O thread creation
    (CVE-2024-49864 bsc#1232256).
  - commit 9a8fa8a
  - jfs: Fix sanity check in dbMount (git-fixes).
  - commit 82a9085
  - net/mlx5e: Fix NULL deref in mlx5e_tir_builder_alloc()
    (CVE-2024-50000 bsc#1232085).
  - commit fe8d0fb
  - ext4: fix double brelse() the buffer of the extents path
    (bsc#1232200 CVE-2024-49882).
  - ext4: no need to continue when the number of entries is 1
    (bsc#1232140 CVE-2024-49967).
  - commit 4a7f79c
  - nvme: disable CC.CRIME (NVME_CC_CRIME) (jsc#PED-9901).
  - commit e02c81e
  - ice: Fix improper handling of refcount in
    ice_sriov_set_msix_vec_count() (CVE-2024-50020 bsc#1231989).
  - Refresh patches.suse/ice-Fix-increasing-MSI-X-on-VF.patch.
  - commit 879bb19
  - igb: Do not bring the device up after non-fatal error
    (CVE-2024-50040 bsc#1231908).
  - ice: Fix improper handling of refcount in
    ice_dpll_init_rclk_pins() (CVE-2024-50021 bsc#1231957).
  - ppp: do not assume bh is held in ppp_channel_bridge_input()
    (CVE-2024-49946 bsc#1232164).
  - net/mlx5e: Fix crash caused by calling __xfrm_state_delete()
    twice (CVE-2024-49953 bsc#1232156).
  - net/mlx5: Fix error path in multi-packet WQE transmit
    (CVE-2024-50001 bsc#1232084).
  - net: seeq: Fix use after free vulnerability in ether3 Driver
    Due to Race Condition (CVE-2024-47747 bsc#1232145).
  - vdpa/mlx5: Fix invalid mr resource destroy (CVE-2024-47687
    bsc#1232003).
  - Revert "ixgbe: Manual AN-37 for troublesome link partners for
    X550 SFI" (git-fixes).
  - commit bf0d04c
  - net: usb: usbnet: fix name regression (get-fixes).
  - commit 05e3778
  - r8169: add tally counter fields added with RTL8125 (CVE-2024-49973 bsc#1232105)
  - commit bda1225
  - crypto: hisilicon/qm - flush all work before driver removed (bsc#1232075)
  - commit fe52020
  - crypto: hisilicon/qm - inject error before stopping queue (CVE-2024-47730 bsc#1232075)
  - commit 2ca1dd9

++++ kernel-rt:

  - platform/x86: x86-android-tablets: Fix use after free on
    platform_device_register() errors (bsc#1232093 CVE-2024-49986).
  - commit a5650bf
  - thermal: core: Free tzp copy along with the thermal zone
    (bsc#1231951 CVE-2024-50027).
  - commit 5199a1f
  - device-dax: correct pgoff align in dax_set_mapping()
    (bsc#1231956 CVE-2024-50022).
  - commit 527a95e
  - ntb: ntb_hw_switchtec: Fix use after free vulnerability in
    switchtec_ntb_remove due to race condition (CVE-2024-50059
    bsc#1232345).
  - commit 4d86c47
  - mm: call the security_mmap_file() LSM hook in remap_file_pages()
    (CVE-2024-47745 bsc#1232135).
  - commit 18a36ea
  - Bluetooth: L2CAP: Fix uaf in l2cap_connect (CVE-2024-49950
    bsc#1232159).
  - commit c906740
  - rxrpc: Fix a race between socket set up and I/O thread creation
    (CVE-2024-49864 bsc#1232256).
  - commit 9a8fa8a
  - jfs: Fix sanity check in dbMount (git-fixes).
  - commit 82a9085
  - net/mlx5e: Fix NULL deref in mlx5e_tir_builder_alloc()
    (CVE-2024-50000 bsc#1232085).
  - commit fe8d0fb
  - ext4: fix double brelse() the buffer of the extents path
    (bsc#1232200 CVE-2024-49882).
  - ext4: no need to continue when the number of entries is 1
    (bsc#1232140 CVE-2024-49967).
  - commit 4a7f79c
  - nvme: disable CC.CRIME (NVME_CC_CRIME) (jsc#PED-9901).
  - commit e02c81e
  - ice: Fix improper handling of refcount in
    ice_sriov_set_msix_vec_count() (CVE-2024-50020 bsc#1231989).
  - Refresh patches.suse/ice-Fix-increasing-MSI-X-on-VF.patch.
  - commit 879bb19
  - igb: Do not bring the device up after non-fatal error
    (CVE-2024-50040 bsc#1231908).
  - ice: Fix improper handling of refcount in
    ice_dpll_init_rclk_pins() (CVE-2024-50021 bsc#1231957).
  - ppp: do not assume bh is held in ppp_channel_bridge_input()
    (CVE-2024-49946 bsc#1232164).
  - net/mlx5e: Fix crash caused by calling __xfrm_state_delete()
    twice (CVE-2024-49953 bsc#1232156).
  - net/mlx5: Fix error path in multi-packet WQE transmit
    (CVE-2024-50001 bsc#1232084).
  - net: seeq: Fix use after free vulnerability in ether3 Driver
    Due to Race Condition (CVE-2024-47747 bsc#1232145).
  - vdpa/mlx5: Fix invalid mr resource destroy (CVE-2024-47687
    bsc#1232003).
  - Revert "ixgbe: Manual AN-37 for troublesome link partners for
    X550 SFI" (git-fixes).
  - commit bf0d04c
  - net: usb: usbnet: fix name regression (get-fixes).
  - commit 05e3778
  - r8169: add tally counter fields added with RTL8125 (CVE-2024-49973 bsc#1232105)
  - commit bda1225
  - crypto: hisilicon/qm - flush all work before driver removed (bsc#1232075)
  - commit fe52020
  - crypto: hisilicon/qm - inject error before stopping queue (CVE-2024-47730 bsc#1232075)
  - commit 2ca1dd9

++++ openssl-3:

  - Update to 3.2.1:
    * Changes between 3.2.0 and 3.2.1:
  - A file in PKCS12 format can contain certificates and keys and may come from
    an untrusted source. The PKCS12 specification allows certain fields to be
    NULL, but OpenSSL did not correctly check for this case. [CVE-2024-0727]
  - When function EVP_PKEY_public_check() is called on RSA public keys,
    a computation is done to confirm that the RSA modulus, n, is composite.
    For valid RSA keys, n is a product of two or more large primes and this
    computation completes quickly. However, if n is an overly large prime,
    then this computation would take a long time. [CVE-2023-6237]
  - Restore the encoding of SM2 PrivateKeyInfo and SubjectPublicKeyInfo to
    have the contained AlgorithmIdentifier.algorithm set to id-ecPublicKey
    rather than SM2.
  - The POLY1305 MAC (message authentication code) implementation in OpenSSL
    for PowerPC CPUs saves the contents of vector registers in different
    order than they are restored. [CVE-2023-6129]
  - Disable building QUIC server utility when OpenSSL is configured with 'no-apps'.
    * The openssl-crypto-policies-support.patch has been merged into
    openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch
    * Rename openssl-Disable-default-provider-for-test-suite.patch and rebase to
    openssl-TESTS-Disable-default-provider-crypto-policies.patch
    * Patches removed in the update:
  - openssl-Add_support_for_Windows_CA_certificate_store.patch
  - openssl-ec-56-bit-Limb-Solinas-Strategy-for-secp384r1.patch
  - openssl-ec-Use-static-linkage-on-nistp521-felem_-square-mul-.patch
  - openssl-ec-powerpc64le-Add-asm-implementation-of-felem_-squa.patch
  - openssl-ecc-Remove-extraneous-parentheses-in-secp384r1.patch
  - openssl-powerpc-ecc-Fix-stack-allocation-secp384r1-asm.patch
  - openssl-CVE-2024-41996.patch
  - openssl-CVE-2023-50782.patch
  - openssl-CVE-2024-9143.patch
    * Patches rebased:
  - openssl-3-use-include-directive.patch
  - openssl-Add-Kernel-FIPS-mode-flag-support.patch
  - openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch
  - openssl-DEFAULT_SUSE_cipher.patch
  - openssl-FIPS-embed-hmac.patch
  - openssl-Force-FIPS.patch
  - openssl-load-legacy-provider.patch
  - openssl-no-html-docs.patch
  - openssl-pkgconfig.patch
  - openssl-ppc64-config.patch
  - openssl-truststore.patch
  - Update to 3.2.0:
    * Changes between 3.1.x and 3.2.0:
  - Fix excessive time spent in DH check/ generation with large Q parameter
    value. [CVE-2023-5678]
  - The BLAKE2b hash algorithm supports a configurable output length
    by setting the "size" parameter.
  - Added a function to delete objects from store by URI - OSSL_STORE_delete()
    and the corresponding provider-storemgmt API function OSSL_FUNC_store_delete().
  - Added OSSL_FUNC_store_open_ex() provider-storemgmt API function to pass
    a passphrase callback when opening a store.
  - Changed the default salt length used by PBES2 KDF's (PBKDF2 and scrypt)
    from 8 bytes to 16 bytes.
  - Changed the default value of the 'ess_cert_id_alg' configuration
    option which is used to calculate the TSA's public key certificate
    identifier. The default algorithm is updated to be sha256 instead of sha1.
  - Added optimization for SM2 algorithm on aarch64. A new configure option
    'no-sm2-precomp' has been added to disable the precomputed table.
  - Added client side support for QUIC
  - Added secp384r1 implementation using Solinas' reduction to improve
    speed of the NIST P-384 elliptic curve. To enable the implementation
    the build option 'enable-ec_nistp_64_gcc_128' must be used.
  - Improved RFC7468 compliance of the asn1parse command.
  - Added SHA256/192 algorithm support.
  - Added support for securely getting root CA certificate update in CMP.
  - Improved contention on global write locks by using more read locks where
    appropriate.
  - Improved performance of OSSL_PARAM lookups in performance critical
    provider functions.
  - Added the SSL_get0_group_name() function to provide access to the
    name of the group used for the TLS key exchange.
  - Provide a new configure option 'no-http' that can be used to disable the
    HTTP support. Provide new configure options 'no-apps' and 'no-docs' to
    disable building the openssl command line application and the documentation.
  - Provide a new configure option 'no-ecx' that can be used to disable the
    X25519, X448, and EdDSA support.
  - When multiple OSSL_KDF_PARAM_INFO parameters are passed to
    the EVP_KDF_CTX_set_params() function they are now concatenated not just
    for the HKDF algorithm but also for SSKDF and X9.63 KDF algorithms.
  - Added OSSL_FUNC_keymgmt_im/export_types_ex() provider functions that get
    the provider context as a parameter.
  - TLS round-trip time calculation was added by a Brigham Young University
    Capstone team partnering with Sandia National Laboratories. A new function
    in ssl_lib titled SSL_get_handshake_rtt will calculate and retrieve this
    value.
  - Added the "-quic" option to s_client to enable connectivity to QUIC servers.
    QUIC requires the use of ALPN, so this must be specified via the "-alpn"
    option. Use of the "advanced" s_client command command via the "-adv" option
    is recommended.
  - Added an "advanced" command mode to s_client. Use this with the "-adv" option.
  - Add Raw Public Key (RFC7250) support.
  - Added support for modular exponentiation and CRT offloading for the
    S390x architecture.
  - Added further assembler code for the RISC-V architecture.
  - Added EC_GROUP_to_params() which creates an OSSL_PARAM array
    from a given EC_GROUP.
  - Improved support for non-default library contexts and property queries
    when parsing PKCS#12 files.
  - Implemented support for all five instances of EdDSA from RFC8032:
    Ed25519, Ed25519ctx, Ed25519ph, Ed448, and Ed448ph.
    The streaming is not yet supported for the HashEdDSA variants
    (Ed25519ph and Ed448ph).
  - Added SM4 optimization for ARM processors using ASIMD and AES HW instructions.
  - Implemented SM4-XTS support.
  - Added platform-agnostic OSSL_sleep() function.
  - Implemented deterministic ECDSA signatures (RFC6979) support.
  - Implemented AES-GCM-SIV (RFC8452) support.
  - Added support for pluggable (provider-based) TLS signature algorithms.
    This enables TLS 1.3 authentication operations with algorithms embedded
    in providers not included by default in OpenSSL. In combination with
    the already available pluggable KEM and X.509 support, this enables
    for example suitable providers to deliver post-quantum or quantum-safe
    cryptography to OpenSSL users.
  - Added support for pluggable (provider-based) CMS signature algorithms.
    This enables CMS sign and verify operations with algorithms embedded
    in providers not included by default in OpenSSL.
  - Implemented HPKE DHKEM support in providers used by HPKE (RFC9180) API.
  - Add support for certificate compression (RFC8879), including
    library support for Brotli and Zstandard compression.
  - Add the ability to add custom attributes to PKCS12 files. Add a new API
    PKCS12_create_ex2, identical to the existing PKCS12_create_ex but allows
    for a user specified callback and optional argument.
    Added a new PKCS12_SAFEBAG_set0_attr, which allows for a new attr to be
    added to the existing STACK_OF attrs.
  - Major refactor of the libssl record layer.
  - Add a mac salt length option for the pkcs12 command.
  - Add more SRTP protection profiles from RFC8723 and RFC8269.
  - Extended Kernel TLS (KTLS) to support TLS 1.3 receive offload.
  - Add support for TCP Fast Open (RFC7413) to macOS, Linux, and FreeBSD where
    supported and enabled.
  - Add ciphersuites based on DHE_PSK (RFC 4279) and ECDHE_PSK (RFC 5489)
    to the list of ciphersuites providing Perfect Forward Secrecy as
    required by SECLEVEL >= 3.
  - Add new SSL APIs to aid in efficiently implementing TLS/SSL fingerprinting.
    The SSL_CTRL_GET_IANA_GROUPS control code, exposed as the
    SSL_get0_iana_groups() function-like macro, retrieves the list of
    supported groups sent by the peer.
  - Fixed PEM_write_bio_PKCS8PrivateKey() and PEM_write_bio_PKCS8PrivateKey_nid()
    to make it possible to use empty passphrase strings.
  - The PKCS12_parse() function now supports MAC-less PKCS12 files.
  - Added ASYNC_set_mem_functions() and ASYNC_get_mem_functions() calls to be able
    to change functions used for allocating the memory of asynchronous call stack.
  - Added support for signed BIGNUMs in the OSSL_PARAM APIs.
  - A failure exit code is returned when using the openssl x509 command to check
    certificate attributes and the checks fail.
  - The default SSL/TLS security level has been changed from 1 to 2. RSA,
    DSA and DH keys of 1024 bits and above and less than 2048 bits and ECC keys
    of 160 bits and above and less than 224 bits were previously accepted by
    default but are now no longer allowed. By default TLS compression was
    already disabled in previous OpenSSL versions. At security level 2 it cannot
    be enabled.
  - The SSL_CTX_set_cipher_list family functions now accept ciphers using their
    IANA standard names.
  - The PVK key derivation function has been moved from b2i_PVK_bio_ex() into
    the legacy crypto provider as an EVP_KDF. Applications requiring this KDF
    will need to load the legacy crypto provider.
  - CCM8 cipher suites in TLS have been downgraded to security level zero
    because they use a short authentication tag which lowers their strength.
  - Subject or issuer names in X.509 objects are now displayed as UTF-8 strings
    by default. Also spaces surrounding '=' in DN output are removed.
  - Add X.509 certificate codeSigning purpose and related checks on key usage and
    extended key usage of the leaf certificate according to the CA/Browser Forum.
  - The 'x509', 'ca', and 'req' apps now produce X.509 v3 certificates.
    The '-x509v1' option of 'req' prefers generation of X.509 v1 certificates.
    'X509_sign()' and 'X509_sign_ctx()' make sure that the certificate has
    X.509 version 3 if the certificate information includes X.509 extensions.
  - Fix and extend certificate handling and the apps 'x509', 'verify' etc.
    such as adding a trace facility for debugging certificate chain building.
  - Various fixes and extensions to the CMP+CRMF implementation and the 'cmp' app
    in particular supporting requests for central key generation, generalized
    polling, and various types of genm/genp exchanges defined in CMP Updates.
  - Fixes and extensions to the HTTP client and to the HTTP server in 'apps/'
    like correcting the TLS and proxy support and adding tracing for debugging.
  - Extended the CMS API for handling 'CMS_SignedData' and 'CMS_EnvelopedData'.
  - 'CMS_add0_cert()' and 'CMS_add1_cert()' no longer throw an error if
    a certificate to be added is already present. 'CMS_sign_ex()' and
    'CMS_sign()' now ignore any duplicate certificates in their 'certs' argument
    and no longer throw an error for them.
  - Added BIO_s_dgram_pair() and BIO_s_dgram_mem() that provide memory-based
    BIOs with datagram semantics and support for BIO_sendmmsg() and BIO_recvmmsg()
    calls. They can be used as the transport BIOs for QUIC.
  - Add new BIO_sendmmsg() and BIO_recvmmsg() BIO methods which allow
    sending and receiving multiple messages in a single call. An implementation
    is provided for BIO_dgram. For further details, see BIO_sendmmsg(3).
  - Support for loading root certificates from the Windows certificate store
    has been added.
  - Enable KTLS with the TLS 1.3 CCM mode ciphersuites. Note that some linux
    kernel versions that support KTLS have a known bug in CCM processing. That
    has been fixed in stable releases starting from 5.4.164, 5.10.84, 5.15.7,
    and all releases since 5.16. KTLS with CCM ciphersuites should be only used
    on these releases.
  - Added '-ktls' option to 's_server' and 's_client' commands to enable the
    KTLS support.
  - Zerocopy KTLS sendfile() support on Linux.
  - The OBJ_ calls are now thread safe using a global lock.
  - New parameter '-digest' for openssl cms command allowing signing
    pre-computed digests and new CMS API functions supporting that
    functionality.
  - OPENSSL_malloc() and other allocation functions now raise errors on
    allocation failures. The callers do not need to explicitly raise errors
    unless they want to for tracing purposes.
  - Added support for Brainpool curves in TLS-1.3.
  - Support for Argon2d, Argon2i, Argon2id KDFs has been added along with
    a basic thread pool implementation for select platforms.

++++ openssl:

  - Update to 3.2.1
  - Update to 3.2.0

++++ snapper:

  - support creating empty snapshots (gh#openSUSE/snapper#944)

++++ toolbox:

  - Use go-md2man instead of pandoc to convert a markdown file to
    nroff. The dep chain is just much, much smaller.
  - Remove Leap and SLE Micro hacks from spec file, this products
    have to provide correct branding packages.
  - Update to version 2.3+git20241025.00f69f5:
    * Add manual page

------------------------------------------------------------------
------------------  2024-10-24  -  Oct 24 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - sock_map: Add a cond_resched() in sock_hash_free() (CVE-2024-47710 bsc#1232049)
  - commit 0ac9917
  - cifs: Fix buffer overflow when parsing NFS reparse points
    (bsc#1232089, CVE-2024-49996).
  - commit f42a100
  - netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() (CVE-2024-47685 bsc#1231998)
  - commit 8da2621
  - net: Fix an unsafe loop on the list (CVE-2024-50024 bsc#1231954)
  - commit 89e6925
  - ipv6: avoid possible NULL deref in rt6_uncached_list_flush_dev() (CVE-2024-47707 bsc#1231935)
  - commit cc8f915
  - netfilter: br_netfilter: fix panic with metadata_dst skb (CVE-2024-50045 bsc#1231903)
  - commit e6591d1
  - block, bfq: fix possible UAF for bfqq->bic with merge chain (CVE-2024-47706 bsc#1231942)
  - commit 5c1066e
  - tcp: check skb is non-NULL in tcp_rto_delta_us() (CVE-2024-47684 bsc#1231987)
  - commit e27a5c2
  - add bug references to existing mana changes (bsc#1232033, bsc#1232034, bsc#1232036).
  - commit e93ce92
  - filemap: remove use of wait bookmarks  (bsc#1224088).
  - commit 323bb54
  - config: Disable LAM on x86 (bsc#1217845)
    LAM is affected by speculative execution vulnerabilities so until LASS
    lands it's advisable to be disabled.
  - commit 405fa97
  - selftests/bpf: adjust global_func15 test to validate prog exit
    precision (CVE-2024-47703 bsc#1231946).
  - selftests/bpf: validate async callback return value check
    correctness (CVE-2024-47703 bsc#1231946).
  - bpf: enforce precision of R0 on program/async callback return
    (CVE-2024-47703 bsc#1231946).
  - bpf: unify async callback and program retval checks
    (CVE-2024-47703 bsc#1231946).
  - commit d5ff894
  - bpf: enforce precise retval range on program exit
    (CVE-2024-47703 bsc#1231946).
  - selftests/bpf: add selftest validating callback result is
    enforced (CVE-2024-47703 bsc#1231946).
  - bpf: enforce exact retval range on subprog/callback exit
    (CVE-2024-47703 bsc#1231946).
  - Refresh patches.kabi/bpf-verifier-kABI-workarounds.patch
  - bpf: provide correct register name for exception callback
    retval check (CVE-2024-47703 bsc#1231946).
  - bpf: rearrange bpf_func_state fields to save a bit of memory
    (CVE-2024-47703 bsc#1231946).
  - Refresh patches.suse/bpf-Add-some-comments-to-stack-representation.patch
  - Refresh patches.kabi/bpf-verifier-kABI-workarounds.patch
  - bpf: Treat first argument as return value for bpf_throw
    (CVE-2024-47703 bsc#1231946).
  - commit 5efe683
  - drm/amd/display: Add null check for head_pipe in
    dcn32_acquire_idle_pipe_for_head_pipe_in_layer (CVE-2024-49918
    bsc#1231967).
  - commit 0e6515f
  - drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs
    in dcn30_init_hw (bsc#1231965 CVE-2024-49917).
  - commit 0859f94

++++ kernel-rt:

  - sock_map: Add a cond_resched() in sock_hash_free() (CVE-2024-47710 bsc#1232049)
  - commit 0ac9917
  - cifs: Fix buffer overflow when parsing NFS reparse points
    (bsc#1232089, CVE-2024-49996).
  - commit f42a100
  - netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put() (CVE-2024-47685 bsc#1231998)
  - commit 8da2621
  - net: Fix an unsafe loop on the list (CVE-2024-50024 bsc#1231954)
  - commit 89e6925
  - ipv6: avoid possible NULL deref in rt6_uncached_list_flush_dev() (CVE-2024-47707 bsc#1231935)
  - commit cc8f915
  - netfilter: br_netfilter: fix panic with metadata_dst skb (CVE-2024-50045 bsc#1231903)
  - commit e6591d1
  - block, bfq: fix possible UAF for bfqq->bic with merge chain (CVE-2024-47706 bsc#1231942)
  - commit 5c1066e
  - tcp: check skb is non-NULL in tcp_rto_delta_us() (CVE-2024-47684 bsc#1231987)
  - commit e27a5c2
  - add bug references to existing mana changes (bsc#1232033, bsc#1232034, bsc#1232036).
  - commit e93ce92
  - filemap: remove use of wait bookmarks  (bsc#1224088).
  - commit 323bb54
  - config: Disable LAM on x86 (bsc#1217845)
    LAM is affected by speculative execution vulnerabilities so until LASS
    lands it's advisable to be disabled.
  - commit 405fa97
  - selftests/bpf: adjust global_func15 test to validate prog exit
    precision (CVE-2024-47703 bsc#1231946).
  - selftests/bpf: validate async callback return value check
    correctness (CVE-2024-47703 bsc#1231946).
  - bpf: enforce precision of R0 on program/async callback return
    (CVE-2024-47703 bsc#1231946).
  - bpf: unify async callback and program retval checks
    (CVE-2024-47703 bsc#1231946).
  - commit d5ff894
  - bpf: enforce precise retval range on program exit
    (CVE-2024-47703 bsc#1231946).
  - selftests/bpf: add selftest validating callback result is
    enforced (CVE-2024-47703 bsc#1231946).
  - bpf: enforce exact retval range on subprog/callback exit
    (CVE-2024-47703 bsc#1231946).
  - Refresh patches.kabi/bpf-verifier-kABI-workarounds.patch
  - bpf: provide correct register name for exception callback
    retval check (CVE-2024-47703 bsc#1231946).
  - bpf: rearrange bpf_func_state fields to save a bit of memory
    (CVE-2024-47703 bsc#1231946).
  - Refresh patches.suse/bpf-Add-some-comments-to-stack-representation.patch
  - Refresh patches.kabi/bpf-verifier-kABI-workarounds.patch
  - bpf: Treat first argument as return value for bpf_throw
    (CVE-2024-47703 bsc#1231946).
  - commit 5efe683
  - drm/amd/display: Add null check for head_pipe in
    dcn32_acquire_idle_pipe_for_head_pipe_in_layer (CVE-2024-49918
    bsc#1231967).
  - commit 0e6515f
  - drm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs
    in dcn30_init_hw (bsc#1231965 CVE-2024-49917).
  - commit 0859f94

++++ llvm19:

  - Update to version 19.1.2.
    * This release contains bug-fixes for the LLVM 19.1.0 release.
    This release is API and ABI compatible with 19.1.0.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ python313-core:

  - Add CVE-2024-9287-venv_path_unquoted.patch to properly quote
    path names provided when creating a virtual environment
    (bsc#1232241, CVE-2024-9287)

++++ pam:

  - Update to version 1.7.0
  - build: changed build system from autotools to meson.
  - libpam_misc: use ECHOCTL in the terminal input
  - pam_access: support UID and GID in access.conf
  - pam_env: install environment file in vendordir if vendordir is enabled
  - pam_issue: only count class user if logind support is enabled
  - pam_limits: use systemd-logind instead of utmp if logind support is enabled
  - pam_unix: compare password hashes in constant time
  - Multiple minor bug fixes, build fixes, portability fixes,
    documentation improvements, and translation updates.
  - Drop upstream patches:
  - pam-bsc1194818-cursor-escape.patch
  - pam_limits-systemd.patch
  - pam_issue-systemd.patch

++++ pam-full-src:

  - Update to version 1.7.0
  - build: changed build system from autotools to meson.
  - libpam_misc: use ECHOCTL in the terminal input
  - pam_access: support UID and GID in access.conf
  - pam_env: install environment file in vendordir if vendordir is enabled
  - pam_issue: only count class user if logind support is enabled
  - pam_limits: use systemd-logind instead of utmp if logind support is enabled
  - pam_unix: compare password hashes in constant time
  - Multiple minor bug fixes, build fixes, portability fixes,
    documentation improvements, and translation updates.
  - Drop upstream patches:
  - pam-bsc1194818-cursor-escape.patch
  - pam_limits-systemd.patch
  - pam_issue-systemd.patch

++++ python313:

  - Add CVE-2024-9287-venv_path_unquoted.patch to properly quote
    path names provided when creating a virtual environment
    (bsc#1232241, CVE-2024-9287)

++++ python-jsonschema-specifications:

  - update to 2024.10.1:
    * Declare support for Python 3.13

++++ python-requests:

  - Switch to pyproject macros.

++++ restorecond:

  - Fix issue where inotify events are not being handled properly
    * added: 1231512-Set-GLib-IO-channels-to-binary-mode.patch
  - Fix issue where restorecond -u is not terminating with SIGTERM (bsc#1231512)
    * added: 1231512-Set-GLib-IO-channels-to-nonblocking.patch

------------------------------------------------------------------
------------------  2024-10-23  -  Oct 23 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.1.15 → 10.1.16
  - Fix erofs requires in spec
    erofs-utils for SUSE only exists in Tumbleweed. The
    former conditon would also add the requirement for ALP
    and SLFO which is wrong. This commit fixes it

++++ gawk:

  - update to 5.3.1:
    * More subtle issues related to uninitialized array elements
    have been fixed.
    * A number of bugs in the debugger related to handling of
    arrays have been fixed.
    * Some subtle bugs in the API have been fixed.
    * Use of MPFR is now possible again on 32-bit Power PC Mac
    systems.
    * Race conditions around broken pipes for system() and read
    and write pipes should now be closed off.
    * Support for OSF/1 has been removed.
    * The never-documented --nostalgia option has been removed.
    It was causing bug reports.
    * The implementation of printf/sprintf has been thoroughly
    reworked in order to make the code more maintainable and to
    fix a goodly number of corner cases.

++++ grub2:

  - Fix error: /boot/grub2/x86_64-efi/bli.mod not found (bsc#1231591)

++++ kdump:

  - upgrade to version 2.0.10
    * calibrate: don't add percentage margin on top of LUKS memory (bsc#1229207)

++++ kernel-default:

  - ocfs2: reserve space for inline xattr before attaching reflink
    tree (bsc#1232151 CVE-2024-49958).
  - commit 9d01096
  - arm64: probes: Fix uprobes for big-endian kernels (git-fixes)
  - commit 5114e0b
  - arm64: probes: Fix simulate_ldr*_literal() (git-fixes)
  - commit 2795830
  - arm64: probes: Remove broken LDR (literal) uprobe support (git-fixes)
  - commit 83d2001
  - spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware (CVE-2024-47664 bsc#1231442)
  - commit 89945c9
  - arm64: Subscribe Microsoft Azure Cobalt 100 to erratum 3194386 (git-fixes)
  - commit ad9716f
  - arm64: errata: Expand speculative SSBS workaround once more (git-fixes)
  - commit f66e878
  - arm64: cputype: Add Neoverse-N3 definitions (git-fixes)
  - commit 6a20007
  - arm64: esr: Define ESR_ELx_EC_* constants as UL (git-fixes)
  - commit 28e8491
  - printk: Add notation to console_srcu locking (bsc#1232183).
  - commit b5edcce
  - Update patches.suse/kthread-unpark-only-parked-kthread.patch
    (git-fixes, bsc#1231990, CVE-2024-50019).
  - commit 1ac001a
  - x86/bugs: Do not use UNTRAIN_RET with IBPB on entry (git-fixes).
  - commit 9059d40
  - x86/bugs: Skip RSB fill at VMEXIT (git-fixes).
  - commit 1c2e2e9
  - supported.conf: mark ultravisor userspace access as supported (bsc#1232090)
    This is needed for secure execution attestations feature.
  - commit 9d4c7ad
  - x86/entry: Have entry_ibpb() invalidate return predictions (git-fixes).
  - commit 8e4a09c
  - x86/cpufeatures: Add a IBPB_NO_RET BUG flag (git-fixes).
  - commit 4411a53
  - config s390x: build ultravisor userspace access into the kernel (bsc#1232090)
    The new s390-tools attestation-related tools depends on this.  It's
    better to have this built into the kernel just like in all other
    branches.
  - commit 25c0449
  - x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET (git-fixes).
  - commit 589671a
  - x86/tdx: Fix "in-kernel MMIO" check (bsc#1232116 CVE-2024-47727).
  - commit 9b65946
  - selftests/bpf: Add test for sign extension in
    coerce_subreg_to_size_sx() (git-fixes).
  - selftests/bpf: Add test for truncation after sign extension
    in coerce_reg_to_size_sx() (git-fixes).
  - bpf: Fix truncation bug in coerce_reg_to_size_sx() (git-fixes).
  - selftests/bpf: Add test for sign extension in
    coerce_subreg_to_size_sx() (git-fixes).
  - selftests/bpf: Add test for truncation after sign extension
    in coerce_reg_to_size_sx() (git-fixes).
  - bpf: Fix truncation bug in coerce_reg_to_size_sx() (git-fixes).
  - commit 34bee66
  - xfs: fix freeing speculative preallocations for preallocated
    files (git-fixes).
  - commit 80e4f70
  - selftests/bpf: Add test for lsm tail call (CVE-2024-50063).
  - commit 810e00e
  - xfs: make sure sb_fdblocks is non-negative (git-fixes).
  - commit 258a678
  - xfs: remove a racy if_bytes check in xfs_reflink_end_cow_extent
    (git-fixes).
  - commit 4ab4091
  - xfs: convert delayed extents to unwritten when zeroing post
    eof blocks (git-fixes).
  - commit 6f12db2
  - xfs: make xfs_bmapi_convert_delalloc() to allocate the target
    offset (git-fixes).
  - commit 9f0f731
  - xfs: make the seq argument to xfs_bmapi_convert_delalloc()
    optional (git-fixes).
  - commit 504e0bc
  - xfs: validate recovered name buffers when recovering xattr items
    (git-fixes).
  - commit a53fc5e
  - xfs: check shortform attr entry flags specifically (git-fixes).
  - commit 621ec11
  - kABI: bpf: struct bpf_map kABI workaround (CVE-2024-50063).
  - bpf: Prevent tail call between progs attached to different hooks
    (CVE-2024-50063).
  - commit cef79ef
  - xfs: check opcode and iovec count match in
    xlog_recover_attri_commit_pass2 (git-fixes).
  - commit 2398ba4
  - fat: fix uninitialized variable (git-fixes).
  - commit 77f5dad
  - drm/amd/display: Add null check for head_pipe in
    dcn201_acquire_free_pipe_for_layer (CVE-2024-49919 bsc#1231968).
  - commit ff31b31
  - slip: make slhc_remember() more robust against malicious packets
    (CVE-2024-50033 bsc#1231914).
  - i40e: Fix macvlan leak by synchronizing access to
    mac_filter_hash (CVE-2024-50041 bsc#1231907).
  - ice: Fix increasing MSI-X on VF (CVE-2024-50042 bsc#1231906).
  - commit a1fb8a8
  - pinctrl: ocelot: fix system hang on level based interrupts
    (stable-fixes).
  - tty: n_gsm: Fix use-after-free in gsm_cleanup_mux
    (stable-fixes).
  - USB: serial: option: add Telit FN920C04 MBIM compositions
    (stable-fixes).
  - USB: serial: option: add support for Quectel EG916Q-GL
    (stable-fixes).
  - drm/vmwgfx: Handle surface check failure correctly (git-fixes).
  - drm/amdgpu/swsmu: Only force workload setup on init (git-fixes).
  - drm/radeon: Fix encoder->possible_clones (git-fixes).
  - commit 4fdf5d1
  - thermal: core: Reference count the zone in
    thermal_zone_get_by_id() (CVE-2024-50028 bsc#1231950).
  - commit a5813a1
  - bpf: Fix a sdiv overflow issue (CVE-2024-49888 bsc#1232208).
  - commit ce8f994

++++ kernel-rt:

  - ocfs2: reserve space for inline xattr before attaching reflink
    tree (bsc#1232151 CVE-2024-49958).
  - commit 9d01096
  - arm64: probes: Fix uprobes for big-endian kernels (git-fixes)
  - commit 5114e0b
  - arm64: probes: Fix simulate_ldr*_literal() (git-fixes)
  - commit 2795830
  - arm64: probes: Remove broken LDR (literal) uprobe support (git-fixes)
  - commit 83d2001
  - spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware (CVE-2024-47664 bsc#1231442)
  - commit 89945c9
  - arm64: Subscribe Microsoft Azure Cobalt 100 to erratum 3194386 (git-fixes)
  - commit ad9716f
  - arm64: errata: Expand speculative SSBS workaround once more (git-fixes)
  - commit f66e878
  - arm64: cputype: Add Neoverse-N3 definitions (git-fixes)
  - commit 6a20007
  - arm64: esr: Define ESR_ELx_EC_* constants as UL (git-fixes)
  - commit 28e8491
  - printk: Add notation to console_srcu locking (bsc#1232183).
  - commit b5edcce
  - Update patches.suse/kthread-unpark-only-parked-kthread.patch
    (git-fixes, bsc#1231990, CVE-2024-50019).
  - commit 1ac001a
  - x86/bugs: Do not use UNTRAIN_RET with IBPB on entry (git-fixes).
  - commit 9059d40
  - x86/bugs: Skip RSB fill at VMEXIT (git-fixes).
  - commit 1c2e2e9
  - supported.conf: mark ultravisor userspace access as supported (bsc#1232090)
    This is needed for secure execution attestations feature.
  - commit 9d4c7ad
  - x86/entry: Have entry_ibpb() invalidate return predictions (git-fixes).
  - commit 8e4a09c
  - x86/cpufeatures: Add a IBPB_NO_RET BUG flag (git-fixes).
  - commit 4411a53
  - config s390x: build ultravisor userspace access into the kernel (bsc#1232090)
    The new s390-tools attestation-related tools depends on this.  It's
    better to have this built into the kernel just like in all other
    branches.
  - commit 25c0449
  - x86/cpufeatures: Define X86_FEATURE_AMD_IBPB_RET (git-fixes).
  - commit 589671a
  - x86/tdx: Fix "in-kernel MMIO" check (bsc#1232116 CVE-2024-47727).
  - commit 9b65946
  - selftests/bpf: Add test for sign extension in
    coerce_subreg_to_size_sx() (git-fixes).
  - selftests/bpf: Add test for truncation after sign extension
    in coerce_reg_to_size_sx() (git-fixes).
  - bpf: Fix truncation bug in coerce_reg_to_size_sx() (git-fixes).
  - selftests/bpf: Add test for sign extension in
    coerce_subreg_to_size_sx() (git-fixes).
  - selftests/bpf: Add test for truncation after sign extension
    in coerce_reg_to_size_sx() (git-fixes).
  - bpf: Fix truncation bug in coerce_reg_to_size_sx() (git-fixes).
  - commit 34bee66
  - xfs: fix freeing speculative preallocations for preallocated
    files (git-fixes).
  - commit 80e4f70
  - selftests/bpf: Add test for lsm tail call (CVE-2024-50063).
  - commit 810e00e
  - xfs: make sure sb_fdblocks is non-negative (git-fixes).
  - commit 258a678
  - xfs: remove a racy if_bytes check in xfs_reflink_end_cow_extent
    (git-fixes).
  - commit 4ab4091
  - xfs: convert delayed extents to unwritten when zeroing post
    eof blocks (git-fixes).
  - commit 6f12db2
  - xfs: make xfs_bmapi_convert_delalloc() to allocate the target
    offset (git-fixes).
  - commit 9f0f731
  - xfs: make the seq argument to xfs_bmapi_convert_delalloc()
    optional (git-fixes).
  - commit 504e0bc
  - xfs: validate recovered name buffers when recovering xattr items
    (git-fixes).
  - commit a53fc5e
  - xfs: check shortform attr entry flags specifically (git-fixes).
  - commit 621ec11
  - kABI: bpf: struct bpf_map kABI workaround (CVE-2024-50063).
  - bpf: Prevent tail call between progs attached to different hooks
    (CVE-2024-50063).
  - commit cef79ef
  - xfs: check opcode and iovec count match in
    xlog_recover_attri_commit_pass2 (git-fixes).
  - commit 2398ba4
  - fat: fix uninitialized variable (git-fixes).
  - commit 77f5dad
  - drm/amd/display: Add null check for head_pipe in
    dcn201_acquire_free_pipe_for_layer (CVE-2024-49919 bsc#1231968).
  - commit ff31b31
  - slip: make slhc_remember() more robust against malicious packets
    (CVE-2024-50033 bsc#1231914).
  - i40e: Fix macvlan leak by synchronizing access to
    mac_filter_hash (CVE-2024-50041 bsc#1231907).
  - ice: Fix increasing MSI-X on VF (CVE-2024-50042 bsc#1231906).
  - commit a1fb8a8
  - pinctrl: ocelot: fix system hang on level based interrupts
    (stable-fixes).
  - tty: n_gsm: Fix use-after-free in gsm_cleanup_mux
    (stable-fixes).
  - USB: serial: option: add Telit FN920C04 MBIM compositions
    (stable-fixes).
  - USB: serial: option: add support for Quectel EG916Q-GL
    (stable-fixes).
  - drm/vmwgfx: Handle surface check failure correctly (git-fixes).
  - drm/amdgpu/swsmu: Only force workload setup on init (git-fixes).
  - drm/radeon: Fix encoder->possible_clones (git-fixes).
  - commit 4fdf5d1
  - thermal: core: Reference count the zone in
    thermal_zone_get_by_id() (CVE-2024-50028 bsc#1231950).
  - commit a5813a1
  - bpf: Fix a sdiv overflow issue (CVE-2024-49888 bsc#1232208).
  - commit ce8f994

++++ logrotate:

  - update to 3.22.0:
    * fix calculations for time differences
    * fix extension for zip compression
    * fix omitted copy for logs with `mail` and `rotate 0`
    * fix wrongly skipping copy with `copytruncate` and `compress`
    * fix ambiguities between `mode`, `UID` and `GID` parsing when
    not specifying all options
    * fix hang when encountering a named pipe
    * on prerotate failure logs are preserved instead of rotated
    * in case a configuration file was skipped due to unsafe
    permissions the
    * exit status after rotattion will be `1`
    * the state is no longer written to non-regular files
    * the systemd timer now correctly utilizes load distribution
    * add dateformat specifier `%z` for timezone offsets
    * change default mode for created `olddir` directories to
    `0755`
    * support quoted user and group names in `su`, `create`, and
    `createolddir`
  - update logroate.keyring: new maintainer

++++ nvidia-open-driver-G06-signed:

  - Update to 550.127.05 (boo#1232057)
    * Fixed a bug which could cause applications using GBM to crash
    when running with nvidia-drm.modeset=0.

++++ python-idna:

  - Update to 3.10
    * Reverted to Unicode 15.1.0 data. Unicode 16 has some significant changes
    to UTS46 processing that will require more work to properly implement.
  - from version 3.9
    * Update to Unicode 16.0.0
    * Deprecate setup.cfg in favour of pyproject.toml
    * Use ruff for code formatting

++++ python-immutables:

  - update to 0.21:
    * Drop typing_extensions dependency
    * Replace `_PyLong_Format` with `PyNumber_ToBase`

++++ sevctl:

  - Update to version 0.6.0:
    * Update to 0.6.0
    * session: Use anyhow macro for error return
    * Update sev crate to 4.0.0
    * secret: Use From::from conversion
    * Add Cargo.lock
    * show: Patching bug from clap migration
    * build(deps): update reqwest requirement from 0.11.18 to 0.12.4
    * build(deps): update bitfield requirement from 0.14.0 to 0.15.0

------------------------------------------------------------------
------------------  2024-10-22  -  Oct 22 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add vagrantconfig rule for vagrant format
    If the format="vagrant" attribute is set, a vagrantconfig
    section becomes mandatory. This commit enforces this rule
    on the schema. This Fixes #2666

++++ grub2:

  - Keep grub packaging and dependencies in the SLE-12 and SLE-15 builds

++++ hyper-v:

  - Add memory allocation check in hv_fcopy_start (94e86b17)
  - suppress the invalid warning for packed member alignment (207e03b0)
  - Add new fcopy application based on uio driver (82b0945c)
  - Add vmbus_bufring (45bab4d7)
  - kvp: Handle IPv4 and Ipv6 combination for keyfile format (f971f6dd)
  - kvp: Some small fixes for handling NM keyfiles (c3803203)
  - kvp: Support for keyfile based connection profile (42999c90)
  - kvp: remove unnecessary (void*) conversions (22589542)
  - Remove an extraneous "the" (f15f39fa)
  - change http to https in hv_kvp_daemon.c (fa52a4b2)
  - replace the copy of include/linux/hyperv.h with include/uapi/linux/hyperv.h (6de74d10)
  - merge individual udev rules files into a single rules file
  - package only files, not directories already owned by filesystem.rpm
  - remove braces from rpm spec macros
  - remove obsolete Group tag
  - replace RPM_BUILD_ROOT with buildroot
  - use a meaningful name for the UAPI include file
  - use a meaningful variable name for ifcfg in hv_set_ifconfig.sh

++++ kbd:

  - Enable libkfont
  - Rename libkeymap-devel to just kbd-devel (the recommendation is
    to reuse the SRPM base name)

++++ kernel-default:

  - kabi fix for NFSv4: Prevent NULL-pointer dereference in
    nfs42_complete_copies() (bsc#1231902 CVE-2024-50046).
  - NFSv4: Prevent NULL-pointer dereference in
    nfs42_complete_copies() (bsc#1231902 CVE-2024-50046).
  - commit e5e1a89
  - zram: don't free statically defined names (CVE-2024-50064
    bsc#1231901).
  - commit 645eb93
  - zram: free secondary algorithms names (CVE-2024-50064
    bsc#1231901).
  - commit 293822f
  - block: fix potential invalid pointer dereference in
    blk_add_partition (bsc#1231872 CVE-2024-47705).
  - block: print symbolic error name instead of error code
    (bsc#1231872).
  - commit fcde2ed
  - nfsd: return -EINVAL when namelen is 0 (CVE-2024-47692
    bsc#1231857).
  - commit 9ee6831
  - PCI: Fix pci_enable_acs() support for the ACS quirks (bsc#1229019).
  - commit 1bd1860
  - nilfs2: fix kernel bug due to missing clearing of buffer delay
    flag (git-fixes).
  - commit 472d949

++++ kernel-rt:

  - kabi fix for NFSv4: Prevent NULL-pointer dereference in
    nfs42_complete_copies() (bsc#1231902 CVE-2024-50046).
  - NFSv4: Prevent NULL-pointer dereference in
    nfs42_complete_copies() (bsc#1231902 CVE-2024-50046).
  - commit e5e1a89
  - zram: don't free statically defined names (CVE-2024-50064
    bsc#1231901).
  - commit 645eb93
  - zram: free secondary algorithms names (CVE-2024-50064
    bsc#1231901).
  - commit 293822f
  - block: fix potential invalid pointer dereference in
    blk_add_partition (bsc#1231872 CVE-2024-47705).
  - block: print symbolic error name instead of error code
    (bsc#1231872).
  - commit fcde2ed
  - nfsd: return -EINVAL when namelen is 0 (CVE-2024-47692
    bsc#1231857).
  - commit 9ee6831
  - PCI: Fix pci_enable_acs() support for the ACS quirks (bsc#1229019).
  - commit 1bd1860
  - nilfs2: fix kernel bug due to missing clearing of buffer delay
    flag (git-fixes).
  - commit 472d949

++++ dtc:

  - Update to 1.7.1:
    * dtc
    * Fix check for 10-bit I2C addresses
    * Improve documentation of -@ option
    * Update to libyaml >= 0.2.3
    * Improvements & fixes for device graph checks
    * Add -L / --local-fixups option
    * Add check for length of interrupt-map properties
    * libfdt
    * Add fdt_path_getprop_namelen()
    * Add fdt_get_symbol() and fdt_get_symbol_namelen()
    * Correct documentation of fdt_path_offset()
    * Correct documentation of fdt_appendprop_addrrange()
    * Validate aliases is fdt_get_alias_namelen()
    * Don't overwrite phandles when applying overlays
    * Require Python 3
    * pylibfdt
    * Support boolean properties
    * Fixes for current Python versions
    * General
    * Assorted bugfixes
    * Assorted build improvements
    * Assorted typo fixes in docs
    * Some additional testcases
    * Move to GitHub Actions based CI

++++ protobuf-c:

  - Modified patch:
    * 711.patch
    + Drop a hunk that was creating problems when the protoc-c
    was called directly and not just as a plugin to protoc

++++ sqlite3:

  - Update to release 3.47.0:
    * Allow arbitrary expressions in the second argument to the RAISE
    function.
    * If the RHS of the ->> operator is negative, then access array
    elements counting from the right.
    * Fix a problem with rolling back hot journal files in the
    seldom-used unix-dotfile VFS.
    * FTS5 tables can now be dropped even if they use a non-standard
    tokenizer that has not been registered.
    * Fix the group_concat() aggregate function so that it returns an
    empty string, not a NULL, if it receives a single input value
    which is an empty string.
    * Enhance the generate_series() table-valued function so that it
    is able to recognize and use constraints on its output value.
    Preupdate hooks now recognize when a column added by ALTER
    TABLE ADD COLUMN has a non-null default value.
    * Improved reuse of subqueries associated with the IN operator,
    especially when the IN operator has been duplicated due to
    predicate push-down.
    * Use a Bloom filter on subqueries on the right-hand side of the
    IN operator, in cases where that seems likely to improve
    performance.
    * Ensure that queries like "SELECT func(a) FROM tab GROUP BY 1"
    only invoke the func() function once per row.
    * No attempt is made to create automatic indexes on a column
    that is known to be non-selective because of its use in other
    indexes that have been analyzed.
    * Adjustments to the query planner so that it produces better
    plans for star queries with a large number of dimension
    tables.
    * Add the "order-by-subquery" optimization, that seeks to
    disable sort operations in outer queries if the desired order
    is obtained naturally due to ORDER BY clauses in subqueries.
    * The "indexed-subtype-expr" optimization strives to use
    expressions that are part of an index rather than recomputing
    the expression based on table values, as long as the query
    planner can prove that the subtype of the expression will
    never be used.
    * Miscellaneous coding tweaks for faster runtimes.
    * Add the experimental sqlite3_rsync program.
    * Add extension functions median(), percentile(),
    percentile_cont(), and percentile_disc() to the CLI.
    * Add the .www dot-command to the CLI.
    * The sqlite3_analyzer utility now provides a break-out of
    statistics for WITHOUT ROWID tables.
    * The sqldiff utility avoids creating an empty database if its
    second argument does not exist.
    * Enhance the sqlite_dbpage table-valued function such that
    INSERT can be used to increase or decrease the size of the
    database file.
    * SQLite no longer makes any use of the "long double" data type,
    as hardware support for long double is becoming less common
    and long double creates challenges for some compiler tool
    chains. Instead, SQLite uses Dekker's algorithm when extended
    precision is needed.
    * The TCL Interface for SQLite supports TCL9. Everything
    probably still works for TCL 8.5 and later, though this is not
    guaranteed. Users are encouraged to upgrade to TCL9.
    * Fix a corruption-causing bug in the JavaScript "opfs" VFS.
    Correct "mode=ro" handling for the "opfs" VFS.  Work around a
    couple of browser-specific OPFS quirks.
    * Add the fts5_tokenizer_v2 API and the locale=1 option, for
    creating custom locale-aware tokenizers and fts5 tables that
    may take advantage of them.
    * Add the contentless_unindexed=1 option, for creating
    contentless fts5 tables that store the values of any UNINDEXED
    columns persistently in the database.
    * Allow an FTS5 table to be dropped even if it uses a custom
    tokenizer whose implementation is not available.

++++ libssh2_org:

  - Update to 1.11.1:
    * build: enable '-pedantic-errors'
    * build: add 'LIBSSH2_NO_DEPRECATED' option
    * build: stop requiring libssl from openssl
    * disable DSA by default
    * hostkey: do not advertise ssh-rsa when SHA1 is disabled
    * kex: prevent possible double free of hostkey
    * kex: always check for null pointers before calling _libssh2_bn_set_word
    * kex: fix a memory leak in key exchange
    * kex: always add extension indicators to kex_algorithms
    * md5: allow disabling old-style encrypted private keys at build-time
    * openssl: free allocated resources when using openssl3
    * openssl: fix memory leaks in '_libssh2_ecdsa_curve_name_with_octal_new'
    and '_libssh2_ecdsa_verify'
    * openssl: fix calculating DSA public key with OpenSSL 3
    * openssl: initialize BIGNUMs to NULL in 'gen_publickey_from_dsa' for OpenSSL 3
    * openssl: fix cppcheck found NULL dereferences
    * openssl: delete internal 'read_openssh_private_key_from_memory()'
    * openssl: use OpenSSL 3 HMAC API, add 'no-deprecated' CI job
    * openssl: make a function static, add '#ifdef' comments
    * openssl: fix DSA code to use OpenSSL 3 API
    * openssl: fix 'EC_KEY' reference with OpenSSL 3 'no-deprecated' build
    * openssl: use non-deprecated APIs with OpenSSL 3.x
    * openssl: silence '-Wunused-value' warnings
    * openssl: add missing check for 'LIBRESSL_VERSION_NUMBER' before use
    * packet: properly bounds check packet_authagent_open()
    * pem: fix private keys encrypted with AES-GCM methods
    * reuse: provide SPDX identifiers
    * scp: fix missing cast for targets without large file support
    * session: support server banners up to 8192 bytes
    * session: add 'libssh2_session_callback_set2()'
    * session: handle EINTR from send/recv/poll/select to try again as the error is not fatal
    * sftp: increase SFTP_HANDLE_MAXLEN back to 4092
    * sftp: implement posix-rename@openssh.com
    * src: implement chacha20-poly1305@openssh.com
    * src: check the return value from '_libssh2_bn_*()' functions
    * src: support RSA-SHA2 cert-based authentication (rsa-sha2-512_cert and rsa-sha2-256_cert)
    * src: check hash update/final success
    * src: check hash init success
    * src: add 'strict KEX' to fix CVE-2023-48795 "Terrapin Attack"
    * transport: fix unstable connections over non-blocking sockets
    * transport: check ETM on remote end when receiving
    * transport: fix incorrect byte offset in debug message
    * userauth: avoid oob with huge interactive kbd response
    * userauth: add a new structure to separate memory read and file read
    * userauth: check whether '*key_method' is a NULL pointer instead of 'key_method'
    * Rebase libssh2-ocloexec.patch
    * Remove patches fixed upstream:
  - libssh2_org-CVE-2023-48795.patch
  - libssh2_org-CVE-2023-48795-ext.patch
  - libssh2_org-ETM-remote.patch

++++ libvirt:

  - spec: Use default_firewall_backend prjconf setting
  - spec: Loosen nwfilter dependency
    boo#1231798

++++ podman:

  - Add patch for CVE-2024-9676 (bsc#1231698):
    * 0004-Use-securejoin.SecureJoin-when-forming-userns-paths.patch
  - Rebase patches:
    * 0001-pkg-subscriptions-use-securejoin-for-the-container-p.patch
    * 0002-CVE-2024-9407-validate-bind-propagation-flag-setting.patch
    * 0003-Properly-validate-cache-IDs-and-sources.patch

++++ python-anyio:

  - update to 4.6.2:
    * Fixed regression caused by (\#807) that prevented the use
    of parametrized async fixtures
  - update to 4.6.1:
    * Fixed TaskGroup and CancelScope producing cyclic references
    in tracebacks when raising exceptions (\#806) (PR by
    @graingert)

++++ python-blinker:

  - update to 1.8.2:
    * Simplify type for _async_wrapper and _sync_wrapper arguments.
    :pr:`156`
    * Restore identity handling for str and int senders. :pr:`148`
    * Fix deprecated blinker.base.WeakNamespace import. :pr:`149`
    * Fix deprecated blinker.base.receiver_connected import.
    :pr:`153`
    * Use types from collections.abc instead of typing. :pr:`150`
    * Fully specify exported types as reported by pyright.
    :pr:`152`
    * Deprecate the __version__ attribute. Use feature detection,
    or importlib.metadata.version("blinker"), instead.
    :issue:`128`
    * Specify that the deprecated temporarily_connected_to will be
    removed in the next version.
    * Show a deprecation warning for the deprecated global
    receiver_connected signal and specify that it will be removed
    in the next version.
    * Show a deprecation warning for the deprecated WeakNamespace
    and specify that it will be removed in the next version.
    * Greatly simplify how the library uses weakrefs. This is a
    significant change internally but should not affect any
    public API. :pr:`144`
    * Expose the namespace used by signal() as default_namespace.
    :pr:`145`
  - add remove-sphinxextensions.patch to remove an optional
    sphinxextension

++++ python-charset-normalizer:

  - update to 3.4.0:
    * Argument `--no-preemptive` in the CLI to prevent the detector
    to search for hints.
    * Support for Python 3.13
    * Relax the TypeError exception thrown when trying to compare a
    CharsetMatch with anything else than a CharsetMatch.
    * Improved the general reliability of the detector based on
    user feedbacks. (#520) (#509) (#498) (#407)
    * Declared charset in content (preemptive detection) not
    changed when converting to utf-8 bytes.

++++ python-cryptography:

  - update to 43.0.3:
    * Fixed release metadata for cryptography-vectors
    * Fixed compilation when using LibreSSL 4.0.0.

++++ sysvinit:

  - Update to sysvinit 3.11
    * Some escape characters were included in the inittab manual page,
    but not displayed by the "man" command because they were not
    (ironically) properly escaped. This has been fixed.
    * Enabled chaining commands together in the inittab file. This
    allows the admin to run commands like
    "task1 && task2" or "task2 || task2" from the inittab file.
    * Fix typoes in halt manual page. Fixes provided by Bjarni Ingi Gislason.
    * Fix typos/markdown in fstab-decode manual page.
    Patch provided by Bjarni Ingi Gislason.

------------------------------------------------------------------
------------------  2024-10-21  -  Oct 21 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.1.14 → 10.1.15

++++ gpg2:

  - Update to 2.5.1:
    * gpg: The support for composite Kyber+ECC public key algorithms
    does now use the final FIPS-203 and LibrePGP specifications. The
    experimental keys from 2.5.0 are no longer supported. [T6815]
    * gpg: New commands --add-recipients and --change-recipients. [T1825]
    * gpg: New option --proc-all-sigs. [T7261]
    * gpg: Fix a regression in 2.5.0 in gpgme's tests. [T7195]
    * gpg: Make --no-literal work again for -c and --store. [T5852]
    * gpg: Improve detection of input data read errors. [T6528]
    * gpg: Fix getting key by IPGP record (rfc-4398). [T7288]
    * gpgsm: New option --assert-signer. [T7286]
    * gpgsm: More improvements to PKCS#12 parsing to cope with latest
    IVBB changes. [T7213]
    * agent: Fix KEYTOCARD command when used with a loopback pinentry. [T7283]
    * gpg-mail-tube: Make sure GNUPGHOME is set in vsd mode.  New option
  - -as-attach. [rG4511997e9e1b]
    * Now uses the process spawn API from libgpg-error. [T7192,T7194]
    * Removed the --enable-gpg-is-gpg2 configure time option.
    [rG2125f228d36c]
    * Rebase patches:
  - gnupg-add_legacy_FIPS_mode_option.patch
  - gnupg-revert-rfc4880bis.patch
  - gnupg-nobetasuffix.patch

++++ hwinfo:

  - merge gh#openSUSE/hwinfo#148
  - avoid reporting of spurious usb storage devices (bsc#1223330)
  - 23.3

++++ kernel-default:

  - Update
    patches.suse/xen-move-max_pfn-in-xen_memory_setup-out-of-function.patch
    (bsc#1226003 bsc#1231828).
  - commit ec3e6a6
  - x86/sev: Check for MWAITX and MONITORX opcodes in the #VC handler (git-fixes).
  - commit 23789e3
  - x86/apic: Make x2apic_disable() work correctly (git-fixes).
  - commit 546101e
  - x86/entry: Remove unwanted instrumentation in common_interrupt() (git-fixes).
  - commit 846156b
  - x86/mm: Use IPIs to synchronize LAM enablement (git-fixes).
  - commit 8a7a0be
  - x86/amd_nb: Add new PCI IDs for AMD family 1Ah model 60h (git-fixes).
  - commit 60a5f34
  - x86/PCI: Check pcie_find_root_port() return for NULL (git-fixes).
  - commit 7c1cc11
  - maple_tree: correct tree corruption on spanning store
    (git-fixes).
  - commit 2b034f1
  - x86/resctrl: Avoid overflow in MB settings in bw_validate() (git-fixes).
  - commit b2f0d6d
  - x86/resctrl: Annotate get_mem_config() functions as __init (git-fixes).
  - commit 7e80f38
  - x86/apic: Always explicitly disarm TSC-deadline timer (git-fixes).
  - commit 312d3e7
  - x86/CPU/AMD: Only apply Zenbleed fix for Zen2 during late microcode  load (git-fixes).
  - commit 0cb125d
  - ethtool: fail closed if we can't get max channel used in
    indirection tables (CVE-2024-46834 bsc#1231096).
  - commit 5cacc93
  - Bluetooth: btusb: Fix regression with fake CSR controllers
    0a12:0001 (git-fixes).
  - Bluetooth: bnep: fix wild-memory-access in proto_unregister
    (git-fixes).
  - Bluetooth: Remove debugfs directory on module init failure
    (git-fixes).
  - Bluetooth: Call iso_exit() on module unload (git-fixes).
  - Bluetooth: ISO: Fix multiple init when debugfs is disabled
    (git-fixes).
  - pinctrl: apple: check devm_kasprintf() returned value
    (git-fixes).
  - parport: Proper fix for array out-of-bounds access (git-fixes).
  - iio: frequency: admv4420: fix missing select REMAP_SPI in
    Kconfig (git-fixes).
  - iio: adc: ti-ads8688: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: hid-sensors: Fix an error handling path in
    _hid_sensor_set_report_latency() (git-fixes).
  - iio: dac: stm32-dac-core: add missing select REGMAP_MMIO in
    Kconfig (git-fixes).
  - iio: dac: ltc1660: add missing select REGMAP_SPI in Kconfig
    (git-fixes).
  - iio: dac: ad5770r: add missing select REGMAP_SPI in Kconfig
    (git-fixes).
  - iio: amplifiers: ada4250: add missing select REGMAP_SPI in
    Kconfig (git-fixes).
  - iio: frequency: adf4377: add missing select REMAP_SPI in Kconfig
    (git-fixes).
  - iio: proximity: mb1232: add missing select
    IIO_(TRIGGERED_)BUFFER in Kconfig (git-fixes).
  - iio: dac: ad5766: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: dac: ad3552r: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: adc: ti-lmp92064: add missing select REGMAP_SPI in Kconfig
    (git-fixes).
  - iio: adc: ti-ads124s08: add missing select
    IIO_(TRIGGERED_)BUFFER in Kconfig (git-fixes).
  - iio: accel: kx022a: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: light: veml6030: fix ALS sensor resolution (git-fixes).
  - iio: light: opt3001: add missing full-scale range value
    (git-fixes).
  - iio: light: veml6030: fix IIO device retrieval from embedded
    device (git-fixes).
  - iio: accel: bma400: Fix uninitialized variable field_value in
    tap event handling (git-fixes).
  - serial: imx: Update mctrl old_status on RTSD interrupt
    (git-fixes).
  - vt: prevent kernel-infoleak in con_font_get() (git-fixes).
  - xhci: Mitigate failed set dequeue pointer commands (git-fixes).
  - xhci: Fix incorrect stream context type macro (git-fixes).
  - xhci: tegra: fix checked USB2 port number (git-fixes).
  - usb: dwc3: Wait for EndXfer completion before restoring
    GUSB2PHYCFG (git-fixes).
  - usb: typec: altmode should keep reference to parent (git-fixes).
  - commit 5e08e81

++++ kernel-firmware-all:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-amdgpu:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-ath10k:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-ath11k:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-ath12k:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-atheros:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-bluetooth:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-bnx2:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-brcm:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-chelsio:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-dpaa2:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-i915:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-intel:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-iwlwifi:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-liquidio:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-marvell:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-media:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-mediatek:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-mellanox:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-mwifiex:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-network:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-nfp:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-nvidia:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-platform:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-prestera:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-qcom:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-qlogic:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-radeon:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-realtek:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-serial:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-sound:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-ti:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-ueagle:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-firmware-usb-network:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

++++ kernel-rt:

  - Update
    patches.suse/xen-move-max_pfn-in-xen_memory_setup-out-of-function.patch
    (bsc#1226003 bsc#1231828).
  - commit ec3e6a6
  - x86/sev: Check for MWAITX and MONITORX opcodes in the #VC handler (git-fixes).
  - commit 23789e3
  - x86/apic: Make x2apic_disable() work correctly (git-fixes).
  - commit 546101e
  - x86/entry: Remove unwanted instrumentation in common_interrupt() (git-fixes).
  - commit 846156b
  - x86/mm: Use IPIs to synchronize LAM enablement (git-fixes).
  - commit 8a7a0be
  - x86/amd_nb: Add new PCI IDs for AMD family 1Ah model 60h (git-fixes).
  - commit 60a5f34
  - x86/PCI: Check pcie_find_root_port() return for NULL (git-fixes).
  - commit 7c1cc11
  - maple_tree: correct tree corruption on spanning store
    (git-fixes).
  - commit 2b034f1
  - x86/resctrl: Avoid overflow in MB settings in bw_validate() (git-fixes).
  - commit b2f0d6d
  - x86/resctrl: Annotate get_mem_config() functions as __init (git-fixes).
  - commit 7e80f38
  - x86/apic: Always explicitly disarm TSC-deadline timer (git-fixes).
  - commit 312d3e7
  - x86/CPU/AMD: Only apply Zenbleed fix for Zen2 during late microcode  load (git-fixes).
  - commit 0cb125d
  - ethtool: fail closed if we can't get max channel used in
    indirection tables (CVE-2024-46834 bsc#1231096).
  - commit 5cacc93
  - Bluetooth: btusb: Fix regression with fake CSR controllers
    0a12:0001 (git-fixes).
  - Bluetooth: bnep: fix wild-memory-access in proto_unregister
    (git-fixes).
  - Bluetooth: Remove debugfs directory on module init failure
    (git-fixes).
  - Bluetooth: Call iso_exit() on module unload (git-fixes).
  - Bluetooth: ISO: Fix multiple init when debugfs is disabled
    (git-fixes).
  - pinctrl: apple: check devm_kasprintf() returned value
    (git-fixes).
  - parport: Proper fix for array out-of-bounds access (git-fixes).
  - iio: frequency: admv4420: fix missing select REMAP_SPI in
    Kconfig (git-fixes).
  - iio: adc: ti-ads8688: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: hid-sensors: Fix an error handling path in
    _hid_sensor_set_report_latency() (git-fixes).
  - iio: dac: stm32-dac-core: add missing select REGMAP_MMIO in
    Kconfig (git-fixes).
  - iio: dac: ltc1660: add missing select REGMAP_SPI in Kconfig
    (git-fixes).
  - iio: dac: ad5770r: add missing select REGMAP_SPI in Kconfig
    (git-fixes).
  - iio: amplifiers: ada4250: add missing select REGMAP_SPI in
    Kconfig (git-fixes).
  - iio: frequency: adf4377: add missing select REMAP_SPI in Kconfig
    (git-fixes).
  - iio: proximity: mb1232: add missing select
    IIO_(TRIGGERED_)BUFFER in Kconfig (git-fixes).
  - iio: dac: ad5766: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: dac: ad3552r: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: adc: ti-lmp92064: add missing select REGMAP_SPI in Kconfig
    (git-fixes).
  - iio: adc: ti-ads124s08: add missing select
    IIO_(TRIGGERED_)BUFFER in Kconfig (git-fixes).
  - iio: accel: kx022a: add missing select IIO_(TRIGGERED_)BUFFER
    in Kconfig (git-fixes).
  - iio: light: veml6030: fix ALS sensor resolution (git-fixes).
  - iio: light: opt3001: add missing full-scale range value
    (git-fixes).
  - iio: light: veml6030: fix IIO device retrieval from embedded
    device (git-fixes).
  - iio: accel: bma400: Fix uninitialized variable field_value in
    tap event handling (git-fixes).
  - serial: imx: Update mctrl old_status on RTSD interrupt
    (git-fixes).
  - vt: prevent kernel-infoleak in con_font_get() (git-fixes).
  - xhci: Mitigate failed set dequeue pointer commands (git-fixes).
  - xhci: Fix incorrect stream context type macro (git-fixes).
  - xhci: tegra: fix checked USB2 port number (git-fixes).
  - usb: dwc3: Wait for EndXfer completion before restoring
    GUSB2PHYCFG (git-fixes).
  - usb: typec: altmode should keep reference to parent (git-fixes).
  - commit 5e08e81

++++ util-linux-systemd:

  - Disable mountfd API again.
    (https://github.com/util-linux/util-linux/issues/3158)

++++ less:

  - Change preprocessor dependencies from Requires to Recommends. It's disabled by
    default and they are not necessary for less.

++++ util-linux:

  - Disable mountfd API again.
    (https://github.com/util-linux/util-linux/issues/3158)

++++ ncurses:

  - Add ncurses patch 20241019
    + fixes for compiler warnings/cppcheck.
    + build-fixes for DJGPP configuration (patches by Stas Sergeev)

++++ openssl-3:

  - Update to 3.1.7:
    * Major changes between OpenSSL 3.1.6 and OpenSSL 3.1.7 [3 Sep 2024]
  - Fixed possible denial of service in X.509 name checks (CVE-2024-6119)
  - Fixed possible buffer overread in SSL_select_next_proto()
    (CVE-2024-5535)
    * Major changes between OpenSSL 3.1.5 and OpenSSL 3.1.6 [4 Jun 2024]
  - Fixed potential use after free after SSL_free_buffers() is
    called (CVE-2024-4741)
  - Fixed an issue where checking excessively long DSA keys or
    parameters may be very slow (CVE-2024-4603)
  - Fixed unbounded memory growth with session handling in TLSv1.3
    (CVE-2024-2511)
    * Major changes between OpenSSL 3.1.4 and OpenSSL 3.1.5 [30 Jan 2024]
  - Fixed PKCS12 Decoding crashes (CVE-2024-0727)
  - Fixed Excessive time spent checking invalid RSA public keys
    [CVE-2023-6237)
  - Fixed POLY1305 MAC implementation corrupting vector registers
    on PowerPC CPUs which support PowerISA 2.07 (CVE-2023-6129)
  - Fix excessive time spent in DH check / generation with large
    Q parameter value (CVE-2023-5678)
    * Update openssl.keyring with BA5473A2B0587B07FB27CF2D216094DFD0CB81EF
    * Rebase patches:
  - openssl-Force-FIPS.patch
  - openssl-FIPS-embed-hmac.patch
  - openssl-FIPS-services-minimize.patch
  - openssl-FIPS-RSA-disable-shake.patch
  - openssl-CVE-2023-50782.patch
    * Remove patches fixed in the update:
  - openssl-Improve-performance-for-6x-unrolling-with-vpermxor-i.patch
  - openssl-CVE-2024-6119.patch openssl-CVE-2024-5535.patch
  - openssl-CVE-2024-4741.patch openssl-CVE-2024-4603.patch
  - openssl-CVE-2024-2511.patch openssl-CVE-2024-0727.patch
  - openssl-CVE-2023-6237.patch openssl-CVE-2023-6129.patch
  - openssl-CVE-2023-5678.patch
  - openssl-Enable-BTI-feature-for-md5-on-aarch64.patch
  - openssl-Fix-EVP_PKEY_CTX_add1_hkdf_info-behavior.patch
  - openssl-Handle-empty-param-in-EVP_PKEY_CTX_add1_hkdf_info.patch
  - reproducible.patch

++++ openssl:

  - Update to 3.1.7

++++ protobuf-c:

  - Added patch:
    * 711.patch
    + Backport the changes from the pull request #711
    https://github.com/protobuf-c/protobuf-c/pull/711 fixing
    build with protobuf 26.0+

++++ libsemanage:

  - Not conflict but obsolete libsemanage1 (bsc#1229757)

++++ nvidia-open-driver-G06-signed:

  - cuda-flavor
    provide also nvidia-open-driver-G06-kmp-$flavor = %version to
    workaround broken cuda-drivers

++++ ovmf:

  - Removed the following patch files because they are merged to
    edk2-stable202408:
  - ovmf-EmbeddedPkg-Library-Support-SOURCE_DATE_EPOCH-in-Vir.patch
  - ovmf-NetworkPkg-TcpDxe-Fixed-system-stuck-on-PXE-boot-flo.patch
  - Update to edk2-stable202408
  - Features (https://github.com/tianocore/edk2/releases):
    CryptoPkg:Add more crypto APIs (AESGCM/PEM/X509/RSA/PKCS5/PKCS7/Authenticode) based on Mbedtls
    CryptoPkg: Enable Openssl native instruction support for AARCH64
    CryptoPkg: Add support for aes128-sha256 and aes256-sha256 cipher
    UefiCpuPkg: S3 cleanup
    MdePkg/BaseLib: Add CRC16 CCITT False Implementation
    DynamicTablesPkg: ACPI TPM2 generator
    DynamicTablesPkg: Prepare for supporting other archs
    BaseTools: Add VS2022 support
    OvmfPkg: Add LoongArchVirt instance to OvmfPkg and enable it
  - Patches (git log --oneline --date-order edk2-stable202405..edk2-stable202408):
    b158dad150 EmulatorPkg: VS2022 Support on WinHost.
    b0f43dd3fd DynamicTablesPkg: Add parser for Tpm2 CM object
    d24df10cee DynamicTablesPkg: Add HexDump for CM Object parser
    75a9afa540 DynamicTablesPkg: ACPI TPM2 generator
    2bff58935f MdePkg: Tpm2Acpi.h: Max size for Parameters field
    ab6ad2fbdb NetworkPkg/DxeHttpLib: Support HTTP CONNECT message in Tx path.
    9761137743 RedfishPkg: Allow deletion of the bootstrap account
    a29a9cce5f MdePkg/BaseLib: Add CRC16 CCITT False Implementation.
    472be4d139 MdeModulePkg ConPlatform: Support IAD-style USB input devices.
    1b37b3659b .github/request-reviews.yml: Use GitHub App authentication
    51ada84cd5 .github/request-reviews.yml: Move workflow Py code to file
    59ad8aeda6 .github/request-reviews.yml: Formatting (non-functional)
    32a099c358 .github/request-reviews.yml: Improve doc and dbg messages
    f617b6ee0e .github/request-reviews.yml: Only post non-collab message once
    09ad1a0072 .github/request-reviews.yml: Add non-collab admin notification
    e86647decd .github/request-reviews.yml: Update PR reviewer exclusion
    eaf2b82eda .github/request-reviews.yml: Removed unused functionality
    d3e9e10770 .github/request-reviews.yml: Switch to PyGithub
    98f17cdcf4 .github/request-reviews.yml: Switch to GitPython
    057c26710a .github/request-reviews.yml: Cache PIP modules
    38c4cd4e88 .github/request-reviews.yml: Use sparse checkout
    5d43165ff8 UefiCpuPkg: rename and simplify IsAddressValid function
    cff0641360 UefiCpuPkg: remove unneeded code in SmmProfilePFHandler
    8b8ac5d986 UefiCpuPkg: rename the SmiDefaultPFHandler function
    cae90a8390 UefiCpuPkg: Remove duplicate code in SmiPfHandler
    b5c9bbff8e UefiCpuPkg:CpuDeadLoop in SmiPFHandler if SMM profile is disabled
    b3631ca944 UefiCpuPkg: remove unnecessary manipulation for smm page table
    9f29fbd33b UefiCpuPkg: always create full mapping SMM page table
    47bb9f9a97 UefiCpuPkg: Revert "UefiCpuPkg/PiSmmCpuDxeSmm: Fix system..."
    68b4c4b481 BaseTools/Capsule: Support Different Hash Algorithm for Payload Digest
    5ff99e0dab MdePkg /IoRemappingTable: Define additional IORT SMMUv3 node flags.
    159f1aee56 BaseTools/WinRcPath: Improve Performance.
    f203a6db92 OvmfPkg: Pass correct virtio-scsi request size
    24a375fcdd UefiCpuPkg/PiSmmCpuDxeSmm: Avoid use global variable in InitSmmS3Cr3
    8f3e132512 UefiCpuPkg/PiSmmCpuDxeSmm: Clean redundant SmmS3Cr3 Init
    66b4a2f91d UefiCpuPkg/PiSmmCpuDxeSmm: clean unused PCD for S3
    4f5de749cb DynamicTablesPkg/DynamicTableManagerDxe: Adds X64 GetAcpiTablePresenceInfo
    bc0fc75637 DynamicTablesPkg/AcpiFadtLib: Adds FADT X64 generator
    967cbd87b7 DynamicTablesPkg: Adds X64 namespace object
    87d3a6272c UefiCpuPkg/PiSmmCpuDxeSmm: Iterate page table to find proper entry
    24f8b97a9d UefiCpuPkg/PiSmmCpuDxeSmm: Remove assert check for PDE entry not exist
    f73b97fe7f UefiCpuPkg/PiSmmCpuDxeSmm: Check PDE entry exist or not before use
    9d8a5fbd0c UefiCpuPkg/PiSmmCpuDxeSmm: Enable single step after SmmProfile start
    bbee1cc852 DynamicTablesPkg: Fix some spelling mistakes found by cspell
    c26490ea29 EmbeddedPkg: Fix some spelling mistakes found by cspell
    669c5aa240 UefiPayloadPkg: Fix some spelling mistakes found by cspell
    1f6dbab8d9 RedfishPkg: Fix some spelling mistakes found by cspell
    ecb0d1e2cb MdePkg: Fix some spelling mistakes found by cspell
    394cbc4ab2 ArmVirtPkg: Fix some spelling mistakes found by cspell
    7b1646d454 ArmPlatformPkg: Fix some spelling mistakes found by cspell
    cf60ca4366 .pytool: Sort the list of words in cspell.base.yaml
    bd23183ac9 .pytool: Add "MPIDR" to the list of known words in cspell.base.yaml
    b0e7a75a49 ShellPkg/AcpiView: Add MPAM Parser
    3c8133ba87 ShellPkg: acpiview: Add routines to print reserved fields
    8a036c8913 ShellPkg: acpiview: Add routine to print 16 chars
    9e865f9579 ShellPkg/AcpiView: Update print-formatter prototype
    107d0c3800 ShellPkg/AcpiView: Update field-validator prototype
    29619603d2 MdePkg/IndustryStandard: Add definitions for MPAM ACPI specification
    5c9b889b81 IntelFsp2WrapperPkg/FspmWrapperPeim: Fix FspT/M address for measurement
    2d5390053f ArmVirtPkg: Switch all PrePeiCore users to new Sec.inf
    e85e29309e ArmPlatformPkg: Clone PrePeiUniCore into Sec
    91117d70d8 ArmPlatformPkg: Clone PrePiUniCore into PeilessSec
    bbe26ca2cc ArmPlatformPkg/PrePi: Make some functions STATIC
    12dc8d420b ArmPkg/ArmArchTimerLib: Drop pointless constructor
    e76b248d8f ArmPlatformPkg/PrePi: Drop call to TimerConstructor()
    8c10017aa7 ArmVirtPkg/PrePi: Drop call to TimerConstructor()
    1941a901f0 ArmPlatformPkg/PrePi: Drop secondary stack handling
    9c1bc36ad1 ArmPlatformPkg/PrePeiCore: Drop secondary stack handling
    96c8e75681 ArmPlatformPkg/PrePeiCore: Drop MPCore variant
    cee49c82d5 ArmPlatformPkg/PrePi: Drop MPCore variant
    4fc1c513f8 ArmPlatformPkg: Drop bogus reference to MPCore related PCD
    caac25e22e ArmVirtPkg: Drop bogus reference to MPCore related PCD
    a679ceca97 CryptoPkg: Enable Openssl Accel builds for AARCH64
    368f9b62a2 CryptoPkg/OpensslLib: Add AArch64Cap for arch specific hooks
    9403422f21 CryptoPkg/OpensslLib: Generate files for AARCH64 native support
    952ecf53f9 CryptoPkg/OpensslLib: Add native instruction support for AARCH64
    1715d67231 MdePkg/BaseRngLib: Prefer ArmReadIdAA64Isar0Reg() over ArmReadIdIsar0()
    30e53f8b5e MdePkg/BaseLib: AARCH64: Add ArmReadIdAA64Isar0Reg()
    a72d93e163 MdePkg/BaseLib: AARCH64: Add ArmReadCntPctReg()
    71b9bda1ac BaseTools/Scripts/BinToPcd.py: Update regex strings to use raw strings.
    85fad9912c MdePkg: Add PCI Express 6.0 Header Support
    7e5a5ae154 MdePkg/Acpi65.h: Fix GUID value
    eed43245df CodeQlQueries.qls: Pin to the 1.1.0 codeq/cpp-queries pack
    a9158fe9a6 StandaloneMmPkg: Enable SmmLockBoxMmDependency.
    3ada6c0db6 StandaloneMmPkg: Add LockBox Dependency Library
    1fc55a3933 OvmfPkg: Use heap memory for virtio-scsi request
    b342070ce6 OvmfPkg: Use heap memory for virtio-blk request
    02f7ecbbb2 EmbeddedPkg: Retire EfiResetSystemLib and ResetRuntimeDxe
    f9b021f84f OvmfPkg/LoongArchVirtQemu: Drop bogus references to EfiResetSystemLib
    03f49e4409 UefiCpuPkg: remove last instances of EFI_D_
    e2528a5209 OvmfPkg: remove last instances of EFI_D_
    9df400fd4d MdeModulePkg: NvmExpressDxe: Add Timeout Status Codes
    f8f34edd9d MdeModulePkg/UfsPassThruDxe: Migrate UFS Initial Completion Timeout to PCD
    5289ad177d MdeModulePkg/UfsBlockIoPei: Migrate UFS Initial Completion Timeout to PCD
    bc1c890e8e MdeModulePkg: Add the PcdUfsInitialCompletionTimeout in DEC File
    5b08df03f8 MdeModulePkg: Optimize PEI Core Migration Algorithm
    91a822749a BaseTools: fix build error with TOOL_CHAIN_TAG VS2015 & VS2015x86
    621a30c676 MdePkg: IORT header update for IORT Rev E.f spec
    84fc1ec52f MdePkg: Update HEST Revision As 2
    909abd7104 EmbeddedPkg: NonCoherentDmaLib: Set EFI_MEMORY_XP Capability on DMA Buffer
    be1d408773 DynamicTablesPkg: Add EFIAPI to generators hooks
    7537028fa5 DynamicTablesPkg: Fix conversion compiler warnings
    40a0dbdd18 DynamicTablesPkg: FdtHwInfoParserLib: Create wrapper to get INTC addr cells
    d8aa665b31 DynamicTablesPkg: FdtHwInfoParserLib: Move IRQ map to arch folder
    5782aef055 DynamicTablesPkg: FdtHwInfoParserLib: Move ArmLib.h to ArmGicCParser.c
    a7cc72c360 DynamicTablesPkg: FdtHwInfoParserLib: Make Serial Port parser arch neutral
    f16817ec84 DynamicTablesPkg: FdtHwInfoParserLib: Make Pci parser arch neutral
    4bb08e8863 DynamicTablesPkg: FdtHwInfoParserLib: Refactor to prepare for other archs
    e2fda42a22 DynamicTablesPkg: FdtHwInfoParserLib: Move ARM parsers to Arm directory
    47b830db58 DynamicTablesPkg: DynamicTableManagerDxe: Refactor PresenceArray
    dfd867bd83 DynamicTablesPkg: AcpiSsdtCpuTopologyLib: Avoid dependency on GICC
    c6e0eed072 DynamicTablesPkg: AcpiSratLib: Prepare to support other archs
    acaf99827f DynamicTablesPkg: AcpiSpcrLib: Prepare to support other archs
    2e6076edaf DynamicTablesPkg: AcpiDbg2Lib: Prepare to support other archs
    e69e1eea2c DynamicTablesPkg: AcpiFadtLib: Prepare to support other archs
    b242de55e2 DynamicTablesPkg: Acpi: Prepare common libraries to support other archs
    e640c04a7b DynamicTablesPkg: Acpi: Move generic libraries to common folder
    fb6a7147f3 DynamicTablesPkg: Move PSD info to Arch Common
    6466a6e63e DynamicTablesPkg: Move PCC Type 5 info to Arch Common
    e8119798b1 DynamicTablesPkg: Move PCC Type 3 & 4 info to Arch Common
    78b77d9ec4 DynamicTablesPkg: Move PCC Type2 info to Arch Common
    870cf728ef DynamicTablesPkg: Move PCC Type1 info to Arch Common
    db4496d30a DynamicTablesPkg: Move PCC Type0 info to Arch Common
    b0ecf17a31 DynamicTablesPkg: Move PCC structure definitions to Arch Common
    ff249c62e3 DynamicTablesPkg: Move Continuous perf control info to Arch Common
    afa7f8a6b1 DynamicTablesPkg: Move Cache info to Arch Common
    79dd25848e DynamicTablesPkg: Move Processor hierarchy info to Arch Common
    d7a47297cd DynamicTablesPkg: Rename GicCToken field in Processor Hierarchy Info
    ead3b42391 DynamicTablesPkg: Move LPI info object to Arch Common
    0b5abcb90e DynamicTablesPkg: Move Generic Initiator affinity info to Arch Common
    3a644f4a43 DynamicTablesPkg: Move PCI device Handle object to Arch Common
    0ca10ddc0f DynamicTablesPkg: Move ACPI device Handle object to Arch Common
    71b0e9decb DynamicTablesPkg: Move Mem Affinity Info to Arch Common
    11dcf74d42 DynamicTablesPkg: Move Pci Interrupt Map Info to Arch Common
    4333f5c316 DynamicTablesPkg: Move CM_ARM_GENERIC_INTERRUPT struct to Arch Common
    83b01dc5cc DynamicTablesPkg: Move Pci Address Map Info to Arch Common
    ae1ba78718 ArmVirtPkg: Kvmtool: Update Pci Config Space Info in Cfg Manager
    93bb65dcfc DynamicTablesPkg: Move Pci Config Space Info to Arm namespace
    4f29b082e8 DynamicTablesPkg: Move Cm Reference object to Arch Common
    8e9ece1234 DynamicTablesPkg: Move FADT Fixed Features Flags to Arch Common
    87a53216e7 DynamicTablesPkg: Move Hypervisor Vendor Id to Arch Common
    e5d8bd476c DynamicTablesPkg: Move Serial Port Info Objects to Arch Common
    1775c9d51c ArmVirtPkg: Kvmtool: Update Power Mgmt Profile info in Cfg Manager
    4362ddea7f DynamicTablesPkg: Move Power Mgmt Profile Info Object
    6dad45b7dd ArmVirtPkg: Kvmtool: Update ConfigMgr to support ArchCommon
    58c36ce09f DynamicTablesPkg: Drop Reserved29 object ID from Arm Namespace
    b0b0812a6e DynamicTablesPkg: Drop Cpu Info object ID from Arm Namespace
    fc8a16871c DynamicTablesPkg: Update documentation for CM_OBJECT_ID
    9c040c003a DynamicTablesPkg: Update DynamicPlatRepo for Arch Common namespace
    3c2d524ceb DynamicTablesPkg: TokenFixer: Return Non Arm NS objs as unsupported
    af337d1291 DynamicTablesPkg: Add support for ArchCommon objects in CmObjParser
    15ce6edd04 DynamicTablesPkg: Introduce an Arch Common Namespace header file
    cb3c2362cd DynamicTablesPkg: Introduce ObjectId to validate CmObject Parser Array
    991b70c0da DynamicTablesPkg: Replace ProcNodeIdInfo with EArmObjReserved29
    6fb4e7b4ad DynamicTablesPkg/SsdtCpuTopology: Update function's parameter description
    0dacb43505 DynamicTablesPkg: Introduce an Arch Common Namespace
    43e2395c1b MdeModulePkg: fix issue caused by uninitialized variable
    51edd4830d UefiCpuPkg: fix issue when SMM profile is enabled
    ecb1d67775 BaseTools/tools_def CLANGDWARF: Always use -Oz in RELEASE mode
    b7f963d570 FmpDevicePkg: Assert on PcdFmpDeviceImageTypeIdGuid Size Mismatch
    52eb643d07 ArmVirtPkg/ArmVirtQemu: Switch to generic ResetSystemLib
    08c60b40da ArmVirtPkg: Implement DT-based ArmMonitorLib for the PEI phase
    358b19e6bf ArmVirtPkg: Move to generic ArmPsciResetSystemLib
    418b8176b8 ArmPkg: Retire ArmSmcPsciResetSystemLib
    0343e75233 .github/request-reviews.yml: Switch to pull_request_target
    7868d509dd .azurepipelines: Disable the PR gate code coverage job
    d7e36ccbbd MdeModulePkg: Add NVMe Long Delay Time Events
    03ad59e631 MdeModulePkg: Consume SOC related ACPI table from ACPI Silicon HOB
    6589843cc6 BaseTools/codeql: Update to CodeQL 2.18.1
    6830074642 ShellPkg: Add missing apps
    ffc09b51cb MdeModulePkg: Remove EFI_MEMORY_* Defines
    c82ca2bb44 MdePkg: Move MEMORY_TYPE_* Defines to EFI_MEMORY_TYPE Enum
    41426040da BaseTools: Move MEMORY_TYPE_* Defines to EFI_MEMORY_TYPE Enum
    b1bce5e564 ArmPkg/ArmMonitorLib: Implement SMCCC protocol correctly and directly
    43130ae403 ArmPkg: Convert PcdMonitorConduitHvc to FixedAtBuild
    8665187b01 ShellPkg: Correct smbiosview strings for SMBIOS Type0
    556640bcea UefiCpuPkg/MpInitLib: Reduce compiler dependencies for LoongArch
    6271b617b4 .github/workflows/request-reviews.yml: Add workflow
    89a06a245b .github: Add GitHub helper python script
    3f0c4cee94 BaseTools/GetMaintainer.py: Add GitHub username argument
    a96d2a8f2d PrmPkg: Don't Set Access Attributes of Runtime MMIO Ranges
    a7abb77c59 ArmPkg: Introduce ResetSystemLib implementation based on ArmMonitorLib
    a9c8c47d53 ArmPkg: Disable AuditOnly mode for uncrustify
    d4ae23b1e6 ShellPkg: Support parser of MADT for LoongArch64
    9bc7a36120 UefiCpuPkg: Removing redundant parameter in RestoreVolatileRegisters
    6fe3137fe5 UefiCpuPkg: Change RestoreVolatileRegisters second parameter
    3912aa3d32 UefiCpuPkg: Combine the code to set ApInitDone
    9f06e5c702 UefiCpuPkg: Remove ApInitReconfig status
    4a0c77be68 UefiCpuPkg: Let AP always save/restore volatile registers
    7fc08c68cd UefiCpuPkg: Sync the init timer count instead of current timer count
    7033f359a9 UefiCpuPkg: Preserve Local APIC Timer Settings During BSP Switch
    76f441c57c UefiCpuPkg: Also exchange CPU_AP_DATA in SortApicId()
    f5901ff2a4 ArmPkg: Remove Deprecated ArmPsciResetSystemLib
    da591416ee BaseTools: Move GnuNoteBti.bin to BaseTools
    990bc4e562 BaseTools: Move GccLto Files to BaseTools
    f96298d75c ShellPkg/Acpiview: Add HEST Parser
    32e7f9aa6c UefiCpuPkg: Revert "UefiCpuPkg/PiSmmCpuDxeSmm:Map SMRAM in 4K..."
    46eb0ca29b ShellPkg: Changes to print Type17 in Smbiosview
    c5ab17430b ArmPlatformPkg: PL031RealTimeClockLib: Set MMIO Memory XP
    1b8ca81133 ArmVirtPkg: KvmtoolRtcFdtClientLib: Set MMIO Memory NX
    e10de1cb03 ArmPkg: ArmMmuLib: Add AARCH64 Memory Attribute Update Failure Log
    74833ca459 ArmPkg: ArmMmuLib: Add ARM32 Memory Attribute Update Failure Logging
    37287bf9ad ArmPkg: CpuDxe: Add Memory Attribute Protocol Logging
    c5582e435c ArmVirtPkg: QemuVirtMemInfoPeiLib: Allow Dynamic PcdSystemMemorySize
    8984fba2f2 EmbeddedPkg: Mark DMA Memory Allocations XP By Default
    469f29fe76 MdeModulePkg/VariablePolicyLib: Use wildcard character constant
    734aaff862 ArmPlatformPkg: Update LcdHwNullLib to prevent init
    489e4a60ea MdeModulePkg/SmiHandlerProfileInfo: Include profile SMI in profile
    62bf2aefc7 .pytool/Plugin: Improve plugin log messages
    cee9d1b16b MdeModulePkg: DxeCore: Fix Use-After-Free guard causing page fault
    0adc868b36 MdePkg/BaseLib: Optimize LOONGARCH64 csr usage
    11c50d6ca1 MdeModulePkg/UfsBlockIoPei: Wait fDeviceInit Be Cleared by Devices
    23d3fc056d ShellPkg/Acpiview: Add EINJ Parser
    873f35625d MdePkg/IndustryStandard: Update EINJ information according to ACPI 6.5
    5b429acec7 MdePkg/IndustryStandard: Add GET_EXECUTE_OPERATION_TIMINGS define
    c2d6e2e18a MdePkg/IndustryStandard: Add SET_ERROR_TYPE_WITH_ADDRESS define
    dd58d1227c MdePkg: Added support for Smbios 3.7.0 Spec
    e32d24ef8c MdePkg: Define SMBIOS Protocol header according IndustryStandard
    b3441e0100 MdeModulePkg/Core/DxeIplPeim: Enhance Code in DxeIplFindDxeCore Function
    43b7a856fa RedfishPkg: Reduce DEBUG_ERROR to DEBUG_MANAGEABILITY in various places
    6b4dd3625b MdeModulePkg/SmiHandlerProfileInfo: Declare correct XML encoding
    55b043732d MdePkg/UefiDebugLibDebugPortProtocol: ExitBootServicesCallback() static
    690f13fcb4 ArmPlatformPkg/Driver/PL061Gpio: Error checking for pin on release build
    f9c373c838 EmbeddedPkg: Add option to disable EFI Memory Attribute Protocol
    1bb9f47739 BaseTools/CodeQL: Removed unused static function query
    8e6ba0dcae BaseTools/HostBasedUnitTestRunner: Promote Unittest error to CI fail.
    5366def8d0 BaseTools: drop GeneralCheckNonAscii() from ECC
    8ade6d7bd1 BaseTools: fix consistent Ecc misspelling of ASCII
    8bb9145ad1 OvmfPkg: Add network support for LoongArch QEMU platform
    91226e1eec OvmfPkg/RiscVVirt: Configure zkr PCD for Virt
    b54bc983c6 MdePkg/Library: Add RISCV64 support to BaseRngLib
    d4dbe5e101 SecurityPkg/Tcg2Acpi: Revise debug print
    807ab61359 UefiPayloadPkg:Modify the PCD PcieResizableBar to dynamic PCD
    5dc6f19b38 OvmfPkg: Fix the wild pointer in Fdt16550SerialProtHookLib
    b92e16d5c3 BaseTools: Remove fno-plt from LoongArch CC flags
    2b6d0eb434 OvmfPkg/OvmfPkgX64: Set default value of CC_MEASUREMENT_ENABLE to TRUE
    2e7230f1ba IntelFsp2WrapperPkg: FSP measurement based on PcdFspMeasurementConfig
    72d6e247b7 MdePkg/StmApi.h: Add SMM_REV_ID definition for STM header
    f122c6f639 MdeModulePkg/RuntimeResetSystemLib: Make global static
    5c86b0b57c NetworkPkg/HttpDxe: Track HttpInstance URL buffer length.
    071d2cfab8 OvmfPkg/Sec: Skip setup MTRR early in TD-Guest
    0f45be1633 .github: Update pull_request_template.md
    6c061c4715 BaseTools/Ecc: Allow `static` as a modifier
    3abe627f29 RedfishPkg/RedfishPlatformConfigDxe: remove false alarm
    497766f709 ShellPkg: UefiShellDebug1CommandsLib: Conformance Profiles in Dmem.c
    960b6e8309 MdePkg: Adding EBBR EFI_CONFORMANCE_PROFILE_TABLE GUIDs
    3ad878fde5 MdePkg: Adding support for EFI_CONFORMANCE_PROFILE_TABLE
    f46b5b06c6 ShellPkg: UefiShellDebug1CommandsLib: Image Execution Table in Dmem.c
    749065300a ShellPkg: UefiShellDebug1CommandsLib: Dumping RT Properties in Dmem.c
    f91211049c MdeModulePkg: Remove PeiAllocatePool() Assert
    7aaee521a1 FmpDevicePkg: Correct broken Depex in FmpDxe
    426b69830e BaseTools: change non-ASCII characters in LinuxGcc5ToolChain.py
    95a6892aac BaseTools: Add VS2022 support.
    049e12c03d StandaloneMmPkg/Core: Dump all HOB info in entrypoint
    e94cbfc845 UefiPayloadPkg/UefiPayloadEntry: Use HobPrintLib to dump HOBs
    d5b03d5fba MdeModulePkg: Add HobPrintLib instance
    19bcc73213 MdeModulePkg: Add HobPrintLib header file
    d5fad2176c SecurityPkg/Tcg: Correct buffer valid check func
    0986faad97 MdeModulePkg/VariableSmm: Fix NonPrimary Buffer check issue
    8befdb1441 MdeModulePkg/VariableSmm: Add func for Primary Buffer valid check
    acfdb6771c MdeModulePkg/VarCheckPolicyLib: Fix buffer valid check for MM
    c0021d31f8 MdeModulePkg/VarCheckPolicyLib: Update buffer valid check func name
    67d3be644f MdeModulePkg/FaultTolerantWriteSmm: Update buffer valid check func name
    26bc42f1e3 BaseTools/GenerateCapsule.py: Fix checking for DepExp presence
    eeddb86aaa BaseTools/GenerateCapsule.py: Fix inconsistent error formatting
    47c1078175 BaseTools/GenerateCapsule.py: Require --output for --decode
    822ff966c6 BaseTools/GenerateCapsule.py: Better error message on --decode failure
    3be79ece37 BaseTools/GenerateCapsule.py: Disallow UpdateImageIndex == 0 on --encode
    8e7bd66dc1 BaseTools/GenerateCapsule.py: Fix --decode operation
    5a4a7172bc BaseTools/FmpCapsuleHeader.py: Explain error when throwing exceptions
    f8bf46be59 UefiCpuPkg/PiSmmCpuDxeSmm: Consume PcdCpuSmmApSyncTimeout2
    4efcd654ec Revert "UefiCpuPkg/PiSmmCpuDxeSmm: Consume PcdCpuSmmApSyncTimeout2"
    a3359ffb25 OvmfPkg/LoongArchVirt: Optimize the use of serial port libraries
    22d0babd33 MdeModulePkg/StandaloneMmReportStatusCodeLib: Support MM_CORE_STANDALONE
    a1d94d9e6e MdePkg/StandaloneMmServicesTableLib: Support MM_CORE_STANDALONE
    051c7bb434 StandaloneMmPkg: Fix section data length returned larger than actual data
    bef0d333dc UefiCpuPkg/PiSmmCpuDxeSmm: Fix system hang when SmmProfile enable
    9389b9a208 MdePkg/Tdx.h: Fix the order of NumVcpus and MaxVcpus
    ed9a64af1b SecurityPkg/Tcg2Config: avoid potential build error
    2809966189 OvmfPkg: Enable AMD SEV-ES DebugVirtualization
    63a7152471 UefiCpuPkg: Add AMD SEV-ES features support
    9f06feb5d2 OvmfPkg: Add AMD SEV-ES DebugVirtualization feature support
    3f28aa2fb0 MdePkg: Add AMD SEV features to PcdConfidentialComputingGuestAttr
    bc3a1ec2a2 MdePkg/Register/Amd: Define all bits from MSR_SEV_STATUS_REGISTER
    6852f6984b EmbeddedPkg/VirtualRealTimeClockLib: Support SOURCE_DATE_EPOCH
    8430c69dc1 MdePkg/Nvme.h: Add missing NVMe capability descriptions
    cdffb638c8 AmdSev: enable kernel hashes without initrd
    4e36bed812 MdeModulePkg/NvmExpressDxe: use format "0x%lx" for UINT64 values.
    4f73eef838 MdeModulePkg/NvmExpressDxe: fix format used for Eui64 conversion
    6b9307192b BaseTools: InfBuildData: Fix Private value retrieval
    592725d229 DscCompleteCheck: Allow git ignore syntax
    ed07a2bb11 MdeModulePkg/UsbBusDxe: USB issue fix when the port reset
    4f174696fd .pytool: CompilerPlugin: Pass through build vars
    6b256cef01 OvmfPkg: Create SP800155 HOBs from QemuFwCfgFile
    ff1c4fa168 MdePkg: UefiTcgPlatform.h updates
    b2216427ca EmbeddedPkg/.ci.yaml: add temporary workaround ECC exception
    e939ecf6c1 SecurityPkg: Consume gEdkiiTcg2AcpiCommunicateBufferHobGuid
    9a76c7945b SecurityPkg: Build gEdkiiTcg2AcpiCommunicateBufferHobGuid
    cb6ba975ae SecurityPkg: Add new gEdkiiTcg2AcpiCommunicateBufferHobGuid
    add3ca4e00 SecurityPkg:Consume gEdkiiTcgPhysicalPresenceInterfaceVerHobGuid
    97ede07beb SecurityPkg/Tcg2StandaloneMm:Consume gEdkiiTpmInstanceHobGuid
    cb38d27f1d SecurityPkg/Tcg2ConfigPei: Build two new HOBs
    f9950cceec SecurityPkg:Add new HOB for PhysicalPresenceInterfaceVersion
    5ab96f5437 SecurityPkg: Add a new gEdkiiTpmInstanceHobGuid
    8bf27965db DynamicTablesPkg: AmlLib remove unnecessary cast
    469d09d6b2 DynamicTablesPkg: AmlLib CONST cleanup
    8c09d862bf BaseTools: BinToPcd: Remove xdrlib dependency
    3b2025969e pip: bump edk2-pytool-library from 0.21.5 to 0.21.8
    dc3ed379df UefiCpuPkg/Library: Add MM_STANDALONE type for SmmCpuPlatformHookLib
    ed46e507e6 UefiCpuPkg/Library: Add MM_STANDALONE type for MmSaveStateLib
    a5f147b2a3 pip: bump edk2-pytool-extensions from 0.27.5 to 0.27.6
    6862b9d538 NetworkPkg/DxeNetLib: adjust PseudoRandom error logging
    ae09721a65 MdeModulePkg/DisplayEngineDxe: Support "^" and "V" key on pop-up form
    89377ece8f MdeModulePkg/ImagePropertiesRecordLib: Reduce debug level
    dc002d4f2d CryptoPkg: Fix wrong comment for CryptoPkg
    78bccfec9c OvmfPkg/Sec: use cache type #defines from ArchitecturalMsr.h
    71e6cc8dad UefiCpuPkg/MtrrLib.h: use cache type #defines from ArchitecturalMsr.h
    5bef25dca4 MdePkg/ArchitecturalMsr.h: add #defines for MTRR cache types
    ce4c76e46d OvmfPkg/Sec: Setup MTRR early in the boot process.
    e21bfae345 ReadMe.rst: Add mbedtls submodule license
    0333faf50e ArmPkg: delete PcdArmArchTimerFreqInHz
    7ee89453b5 ArmVirtPkg: drop use of PcdArmArchTimerFreqInHz
    a715d456de ArmPkg: drop manual ARM programming of generic timer frequency
    2fbaaa96d1 MdePkg/BaseLib: Fix an instruction write width error in LoongArch64
    5db0091418 UefiCpuPkg/ExceptionHandler: Fix a context error in LoongArch64
    dc93ff8a55 CryptoPkg: Extend TLS handshake debug output
    84d8eb08e1 CryptoPkg: Add SNI extension to TLS ClientHello
    10b4bb8d6d AmdSev: Halt on failed blob allocation
    56059941ec AmdSev: Rework Blob Verifier
    be38c01da2 OvmfPkg: refine TdTcg2Dxe
    d512bd3129 UefiCpuPkg: Correct the count of different type of Cache.
    57a890fd03 MdePkg: Check if compiler has __has_builtin before trying to use it
    95e220e95d MdePkg/ArmLib: Drop obsolete library declarations
    e76be772aa ArmPkg/ArmLib ArmMmuLib: Drop support for EL3/MON execution
    4d4f569924 MdeModulePkg: Avoid efi memory allocation for SP memory
    26a30abdd0 MdeModulePkg/DxeCapsuleLibFmp: Fix compilation error
    c1d1910be6 OvmfPkg/QemuVideoDxe: add feature PCD to remap framebuffer W/C
    ffce430d2b OvmfPkg/BhyvePkg: honor FwCfg when setting the bootorder
    bfda27ddc8 Maintainers.txt: Update maintainers and reviewers for OvmfPkg/LoongArchVirt
    7a1739d896 OvmfPkg/PlatformCI: Add CI coverage for LoongArchVirtQemu
    c2d6efaef9 OvmfPkg/LoongArchVirt: Add self introduction file
    d6dcf621df OvmfPkg/LoongArchVirt: Add build file
    e5e2cf48a9 OvmfPkg/LoongArchVirt: Support PEI phase
    9912434785 OvmfPkg/LoongArchVirt: Support SEC phase
    c63d90085b OvmfPkg/LoongArchVirt: Add reset system library
    79835e08f5 OvmfPkg/LoongArchVirt: Add real time clock library
    74433f66b1 OvmfPkg: Add a new GUID called gRtcRegisterBaseAddressHobGuid
    ab4b1f113d OvmfPkg/LoongArchVirt: Add the early serial port output library
    05f74f1ca7 OvmfPkg/LoongArchVirt: Add serial port hook library
    ace279c036 OvmfPkg/LoongArchVirt: Add CpuMmuInit library
    e3e27f22d2 OvmfPkg/LoongArchVirt: Add stable timer driver
    b0c5781671 .devcontainer: bump Fedora version to 39
    176b9d41f8 MdeModulePkg/Core/Pei: Install MigrateTempRamPpi
    537a81ae81 MdePkg/Include: Update AMD specification references
    a9def1ed9d MdePkg/Include: Update Msr.h header guard define
    17424fae4f MdePkg/Include: Remove deprecated AMD SEV-SNP header file
    55c3ecde32 UefiCpuPkg/MpInitLib: Update references to SEV-SNP header file
    d40c71ef3f MdePkg/Include: Update reference to SEV-SNP header file
    6eaeef2c9b MdePkg/Include: Add AMD SEV-SNP header file
    128513afcd MdeModulePkg:Add global variable mVariableRtCacheInfo
    081df0ec20 MdeModulePkg: Refine InitVariableCache()
    92974e3d18 MdeModulePkg:Remove the usage of PcdEnableVariableRuntimeCache
    689f415a49 MdeModulePkg:Consume gEdkiiVariableRuntimeCacheInfoHobGuid
    c1c2e474a2 MdeModulePkg:Remove unneed FreePages for RuntimeHobCacheBuffer
    645d9f6f8d MdeModulePkg:Remove unnecessary global variables
    d8f513de3e MdeModulePkg:Create gEdkiiVariableRuntimeCacheInfoHobGuid
    025a95b7ed MdeModulePkg:Add new gEdkiiVariableRuntimeCacheInfoHobGuid
    9fc61309bf ArmPkg/ProcessorSubClassDxe: Limit values to 0xFF
    587100a95d UefiCpuPkg/SmmCpuSyncLib: Add MM_STANDALONE tag.
    a7dbd2ac7b CryptoPkg: Fix strncpy for BaseCryptLibMbedTls
    aa99d36be9 BaseTools/BuildReport: Improve compile_commands generation
    d8095b36ab ArmPkg/CompilerIntrinsicsLib: provide __ashlti3
    a84876ba28 OvmfPkg/Xen: Fix use of networking
    cf323e2839 ArmPkg,MdePkg: Move ArmPkg/Chipset/Aarch64[|Mmu].h to MdePkg
    c68fb69dfe ArmPkg,MdePkg: Move ArmPkg/Chipset/ArmV7[|Mmu].h to MdePkg
    f2b9d5417d ArmPkg,MdePkg: move ArmLib.h to MdePkg
    5e776299a2 MdePkg/X86UnitTestHost: set rdrand cpuid bit
    94961b8817 CryptoPkg/Test: call ProcessLibraryConstructorList
    ce91687a1b OvmfPkg: Override PcdCpuSmmApSyncTimeout2 to 10ms
    870c1ae253 UefiCpuPkg: Refine the PCD usage comment
    cb3134612d UefiCpuPkg/PiSmmCpuDxeSmm: Consume PcdCpuSmmApSyncTimeout2
    af2bbe1b79 UefiCpuPkg: Add PcdCpuSmmApSyncTimeout2 PCD
    712797cf19 OvmfPkg: wire up RngDxe
    a61bc0accb SecurityPkg/RngDxe: add rng test
    c3a8ca7b54 MdePkg/BaseRngLib: Add a smoketest for RDRAND and check CPUID
    d3b32dca06 MdePkg/BaseLib: Let CpuDeadLoop() be breakable in debugger
    0982da4f50 UefiPayloadPkg: Enable UPL FIT build config from cmdline
    6d15276ced UefiPayloadPkg: Fix LoadDxeCore for payload size > 16MB
    3dcc7b73df ArmPkg: Revert "Allow SMC/HVC monitor conduit to be specified at runtime"
    2c19297e6c ArmVirtPkg/ArmVirtQemu: Revert "Permit the use of dynamic PCDs in PEI"
    7bcd49edd0 ArmVirtPkg: Revert "Use dynamic PCD to set the SMCCC conduit"
    059676e4fa ArmVirtPkg/ArmVirtQemu: Implement ArmMonitorLib for QEMU specifically
    5bea691233 ArmVirtPkg/PrePi: Enable VFP before calling into C code
    ab069d5801 OvmfPkg/QemuVideoDxe: purge VbeShim
    c36414b131 MdeModulePkg/DxeCapsuleLibFmp: Fix crash if no ESRT is found
    948f234170 CryptoPkg: Fix BaseCryptLib CrtWrapper strncpy and strcat
    df8c61e4c0 CryptoPkg: Fix BaseCryptLib CrtWrapper strcpy
    8c826be35c MdeModulePkg: In RemoveTableFromRsdt don't read from unallocated memory
    665b223d57 ShellPkg/Pci.c: Update supported link speed to PCIe Gen6
    80b59ff832 MdeModulePkg: Warn if out of flash space when writing variables
    f9c2f2fa0f BaseTools/Scripts: Fix PatchCheck commit range
    71606314f8 CryptoPkg: Fix wrong logic in X509GetTBSCert
    90cb1ec332 OvmfPkg/PlatformInitLib: allow PhysBits larger than 48
    603ad2d6ae OvmfPkg/PlatformInitLib: add support for GuestPhysBits
    65b0d08786 MdeModulePkg/HiiDatabaseDxe: Remove assert for VarStoreId = 0
    b45aff0dc9 OvmfPkg: add morlock support
    10ab1c67c4 ArmVirtPkg: Remove the NorFlashQemuLib
    10cd8b45ce MdePkg: Remove non-ASCII characters from header file
    e2e09d8512 MdePkg: Add Ipmi Net Sensor Thresholds command defines.
    7772e339bd ArmVirtPkg: Enable the non-hardcode version FdtNorFlashQemuLib
    cac1ea6c2a OvmfPkg: Add no hardcode version of FdtNorFlashQemuLib
    de4cc40b8c MdeModulePkg/HiiDatabaseDxe: Avoid struct assignment
    839bd17973 UefiCpuPkg:fix issue when splitting paging entry
    077760fec4 UefiCpuPkg: Remove GetAcpiCpuData() in CpuS3.c
    e3b3e907e1 MdeModulePkg:Remove MpService2Ppi field in SMM_S3_RESUME_STATE
    d390b163f8 UefiCpuPkg: Remove unneeded MpService2Ppi assignment
    341ee5c31b UefiCpuPkg:Remove code to wakeup AP and relocate ap
    525578bdd5 UefiCpuPkg:Remove code to handle APIC setting and Interrupt
    cdc1a88272 UefiCpuPkg:Relocate AP to new safe buffer in PeiMpLib
    669291db5a UefiCpuPkg: Install gEdkiiEndOfS3ResumeGuid in S3Resume
    fcd09b1edb UefiCpuPkg:Move some code in DxeMpLib to common place
    68310cd56a UefiCpuPkg:Abstract some DxeMpLib code to function
    ffb8481ba8 UefiCpuPkg: Disable PG in IA32 ApLoopCode
    7421ea1f2a UefiCpuPkg: Remove code to set register table
    b7db4d895a UefiCpuPkg:Set PcdCpuFeaturesInitOnS3Resume to TRUE
    db4101c308 UefiCpuPkg: Remove code to load mtrr setting
    ad245ffeff UefiCpuPkg: LoadMtrrData for all cpu in S3Resume
    3a516aa240 UefiCpuPkg: Save MTRR by lockbox in CpuS3DataDxe
    32a9ee736e UefiCpuPkg: Add locbox lib instance in DSC
    52a4bc65f6 OvmfPkg: Save MTRR by lockbox in CpuS3DataDxe
    87f22f4b5c MdeModulePkg: Add gEdkiiS3MtrrSettingGuid
    27b044605c ArmPkg: Set BIOS Segment to 0 in SMBIOS Type 0 table
    b0930e3f4e CryptoPkg/BaseCryptLib: Enable more functions for SMM/StandaloneMM
    de2330450f MdeModulePkg: Update GCD attribute conversion to support SP attribute
    7339bfeffa OvmfPkg/VirtioRngDxe: check if device is ready
    3b36aa96de CryptoPkg: Remove deprecated code related to SHA-1
    7c584bb048 CryptoPkg: Fix bug for correct return value checking when get X509Cert
    746cc5cc40 CryptoPkg: Add support for aes128-sha256 and aes256-sha256 cipher
    5f68a363d0 pip: bump edk2-pytool-extensions from 0.26.4 to 0.27.5
    a8dc6bf73f pip: bump edk2-pytool-library from 0.20.0 to 0.21.5
    ced13b93af NetworkPkg TcpDxe: Fixed system stuck on PXE boot flow in iPXE environment
    e784848116 pip: bump regex from 2023.12.25 to 2024.5.15
    9518d77eb8 OvmfPkg: Update VMM Hob list check to support new resource attributes
    c695e3182a MdePkg: Add Ipmi definitions header file for OEM net function
    cd4cebabf5 UefiPayloadPkg: Update ReadMe.md to swig install
    843f2d0964 EmulatorPkg: fix build error.
    30b6d08e27 StandaloneMmPkg: Initialize 'WillReturn' variable
    b40c64ec25 MdeModulePkg/SMM: Initialize 'WillReturn' variable
    79655e2768 SecurityPkg: Update libspdm submodule to use GitLab cmocka repo
    55f8bddade .github: Add PR template
    0e3189d406 BaseTools/Scripts: Remove Cc: tag check from PatchCheck.py
    08281572aa Add SM3 functions with openssl for Mbedtls
    ed7a3143b7 CryptoPkg: Update *.inf in BaseCryptLibMbedTls
    3096fcf81d CryptoPkg: Add ImageTimestampVerify based on Mbedtls
    27a7345882 CryptoPkg: Add AuthenticodeVerify based on Mbedtls
    b5412646db CryptoPkg: Add more RSA related functions based on Mbedtls
    e065735b1b CryptoPkg: Add Pkcs5 functions based on Mbedtls
    acfd991b68 CryptoPkg: Add Pkcs7 related functions based on Mbedtls
    40fa5cf299 CryptoPkg: Add X509 functions based on Mbedtls
    f44cc28972 CryptoPkg: Add Pem APIs based on Mbedtls
    8deeda7ce0 CryptoPkg: Add rand function for BaseCryptLibMbedTls
    1d8fedb0cd CryptoPkg: Add AeadAesGcm based on Mbedtls
    88a4de450f UefiCpuPkg/MpLib:Do not assume BSP is #0.
  - Removed patches which are merged to edk2-stable202408:
  - ovmf-EmbeddedPkg-Library-Support-SOURCE_DATE_EPOCH-in-Vir.patch (bsc#1217704)
    6852f6984bda EmbeddedPkg/VirtualRealTimeClockLib: Support SOURCE_DATE_EPOCH
  - ovmf-NetworkPkg-TcpDxe-Fixed-system-stuck-on-PXE-boot-flo.patch (bsc#1230587)
    ced13b93afea NetworkPkg TcpDxe: Fixed system stuck on PXE boot flow in iPXE environment
  - Add pylibfdt as new submodule
  - pylibfdt-cfff805481bdea27f900c32698171286542b8d3c.tar.gz
  - https://github.com/devicetree-org/pylibfdt/archive/cfff805481bdea27f900c32698171286542b8d3c.tar.gz
  - https://github.com/devicetree-org/pylibfdt/
  - edk2 commit ids:
    10416bf46e7e Tianocore: Support FDT library.
  - Updated ovmf.spec
  - unpacked pylibfdt-cfff805481bdea27f900c32698171286542b8d3c.tar.gz to MdePkg/Library/BaseFdtLib/libfdt
  - We also got image size issue when cross compiling x86_64 FD_SIZE_2MB image
    on aarch64 environment. So using x86_64-suse-linux-gcc-12 on SLE15-SP7 or
    Leap 15.4 codebases. Here is the pseudocode in ovmf.spec:
    ifnarch x86_64
    BuildRequires:  cross-x86_64-binutils
    if sle_version >= 150500 && sle_version <= 150700
    BuildRequires:  cross-x86_64-gcc12
    else
    BuildRequires:  cross-x86_64-gcc+gcc_version
    endif
    endif
  - The x86_64-suse-linux-gcc-12 be auto-linked to x86_64-suse-linux-gcc
    after installed cross-x86_64-gcc12. So we don't need to add any
    downstream patch for corss compiling x86_64 2MB image on aarch64.

++++ runc:

  - Update to runc v1.2.0. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.0>.
  - Remove upstreamed patches.
  - 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
  - 0002-bsc1221050-seccomp-patchbpf-rename-nativeArch-linuxA.patch
  - 0003-bsc1221050-seccomp-patchbpf-always-include-native-ar.patch
  - 0004-bsc1214960-nsenter-cloned_binary-remove-bindfd-logic.patch

++++ supermin:

  - Detect the correct kernel on aarch64 (jsc#PED-10545)
    detect-aarch64-kernel.patch

++++ ucode-amd:

  - Update to version 20241018 (git commit 2f0464118f40):
    * check_whence.py: skip some validation if git ls-files fails
    * qcom: Add Audio firmware for X1E80100 CRD/QCPs
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * brcm: replace NVRAM for Jetson TX1
    * rtlwifi: Update firmware for RTL8192FU to v7.3
    * make: separate installation and de-duplication targets
    * check_whence.py: check the permissions
    * Remove execute bit from firmware files
    * configure: remove unused file
    * rtl_nic: add firmware rtl8125d-1

------------------------------------------------------------------
------------------  2024-10-19  -  Oct 19 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - supported.conf: mark nhpoly1305 module as supported (bsc#1231035)
    In 59d03d7c990c, we marked adiantum as a supported module, I'm afraid
    we need to mark nhpoly1305 as supported too (as a dependecy) if we
    want adiantum to work.
    This makes tcrypt test case 219 (adiantum) pass on SLE15-SP6 (tested
    on z15 VM).
  - commit 01d2906

++++ kernel-rt:

  - supported.conf: mark nhpoly1305 module as supported (bsc#1231035)
    In 59d03d7c990c, we marked adiantum as a supported module, I'm afraid
    we need to mark nhpoly1305 as supported too (as a dependecy) if we
    want adiantum to work.
    This makes tcrypt test case 219 (adiantum) pass on SLE15-SP6 (tested
    on z15 VM).
  - commit 01d2906

++++ xfsprogs:

  - update to 6.11.0
  - mkfs: break up the rest of the rtinit() function
  - mkfs: clean up the rtinit() function
  - xfs_repair: use library functions for orphanage creation
  - xfs_repair: use library functions to reset root/rbm/rsum inodes
  - xfs_repair: don't crash in get_inode_parent
  - xfs_repair: fix exchrange upgrade
  - xfs_db: port the iunlink command to use the libxfs iunlink function
  - xfs_db/mdrestore/repair: don't use the incore struct xfs_sb for offsets into struct xfs_dsb
  - xfs_db/mkfs/xfs_repair: port to use XFS_ICREATE_UNLINKABLE
  - xfs_db: port the unlink command to use libxfs_droplink
  - libxfs: implement get_random_u32
  - libxfs: remove libxfs_dir_ialloc
  - libxfs: backport inode init code from the kernel
  - libxfs: pack icreate initialization parameters into a separate structure
  - xfs_io: add RWF_ATOMIC support to pwrite
  - libfrog: emulate deprecated attrlist functionality in libattr
  - misc: clean up code around attr_list_by_handle calls
  - fsck.xfs: fix fsck.xfs run by different shells when fsck.mode=force is set
  - libxfs: provide a memfd_create() wrapper if not present in libc
  - xfs_io: Fix fscrypt macros ordering
  - man: Update unit for fsx_extsize and fsx_cowextsize
  - xfs_db: release ip resource before returning from get_next_unlinked()
  - libxfs: kernel sync
  - ------------------------------------------------------------------

------------------------------------------------------------------
------------------  2024-10-18  -  Oct 18 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Enable intel Vulkan backends on riscv64 (boo#1231756)
  - Enable iris Gallium backend on riscv64, Power and on Arm, too

++++ Mesa-drivers:

  - Enable intel Vulkan backends on riscv64 (boo#1231756)
  - Enable iris Gallium backend on riscv64, Power and on Arm, too

++++ grub2:

  - Power guest secure boot with key management (jsc#PED-3520) (jsc#PED-9892)
    * 0001-ieee1275-Platform-Keystore-PKS-Support.patch
    * 0002-ieee1275-Read-the-DB-and-DBX-secure-boot-variables.patch
    * 0003-appendedsig-The-creation-of-trusted-and-distrusted-l.patch
    * 0004-appendedsig-While-verifying-the-kernel-use-trusted-a.patch
    * 0005-appendedsig-The-grub-command-s-trusted-and-distruste.patch
    * 0006-appendedsig-documentation.patch
    * 0007-mkimage-create-new-ELF-Note-for-SBAT.patch
    * 0008-mkimage-adding-sbat-data-into-sbat-ELF-Note-on-power.patch
    * grub2.spec : Building signed grub.elf with SBAT metadata
  - Support for NVMe multipath splitter (jsc#PED-10538)
    * 0001-ieee1275-support-added-for-multiple-nvme-bootpaths.patch
  - Deleted path (jsc#PED-10538)
    * 0001-grub2-Can-t-setup-a-default-boot-device-correctly-on.patch
    * 0001-grub2-Set-multiple-device-path-for-a-nvmf-boot-devic.patch

++++ kernel-default:

  - vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame
    (bsc#1226498).
  - vmxnet3: Fix missing reserved tailroom (bsc#1226498).
  - commit 1bd55aa
  - vmxnet3: update to version 9 (bsc#1226498).
  - vmxnet3: add command to allow disabling of offloads
    (bsc#1226498).
  - vmxnet3: add latency measurement support in vmxnet3
    (bsc#1226498).
  - vmxnet3: prepare for version 9 changes (bsc#1226498).
  - vmxnet3: Add XDP support (bsc#1226498).
  - commit 3fdc8e3
  - SUNRPC: Fix integer overflow in decode_rc_list() (git-fixes).
  - commit 15be003
  - NFSD: Mark filecache "down" if init fails (git-fixes).
  - commit ceca4b8
  - SUNRPC: clnt.c: Remove misleading comment (git-fixes).
  - commit 2e12710
  - nfs: fix memory leak in error path of nfs4_do_reclaim
    (git-fixes).
  - commit 1994ef6
  - nfsd: fix delegation_blocked() to block correctly for at least
    30 seconds (git-fixes).
  - commit f66078d
  - nfsd: return -EINVAL when namelen is 0 (git-fixes).
  - commit 1bc1c36
  - nfsd: call cache_put if xdr_reserve_space returns NULL
    (git-fixes).
  - commit 003f784
  - nfsd: map the EBADMSG to nfserr_io to avoid warning (git-fixes).
  - commit 5b8020a
  - NFSD: Fix NFSv4's PUTPUBFH operation (git-fixes).
  - commit 88290fb
  - nfsd: fix refcount leak when file is unhashed after being found
    (git-fixes).
  - commit 5a551a1
  - nfsd: remove unneeded EEXIST error check in nfsd_do_file_acquire
    (git-fixes).
  - commit 6d18e0e
  - NFS: Avoid unnecessary rescanning of the per-server delegation
    list (git-fixes).
  - commit e5841ef
  - NFSv4: Fix clearing of layout segments in layoutreturn
    (git-fixes).
  - commit ec4c812
  - ALSA: hda/conexant - Use cached pin control for Node 0x1d on
    HP EliteOne 1000 G2 (git-fixes).
  - ALSA/hda: intel-sdw-acpi: simplify sdw-master-count property
    read (stable-fixes).
  - ALSA/hda: intel-sdw-acpi: fetch fwnode once in
    sdw_intel_scan_controller() (stable-fixes).
  - ALSA/hda: intel-sdw-acpi: cleanup sdw_intel_scan_controller
    (stable-fixes).
  - ALSA: hda/tas2781: Add new quirk for Lenovo, ASUS, Dell projects
    (stable-fixes).
  - ALSA: line6: update contact information (stable-fixes).
  - ALSA: hda/conexant - Fix audio routing for HP EliteOne 1000 G2
    (stable-fixes).
  - ALSA: hda: Sound support for HP Spectre x360 16 inch model 2024
    (stable-fixes).
  - commit fb6c2ec
  - firmware: arm_scmi: Fix the double free in
    scmi_debugfs_common_setup() (git-fixes).
  - ALSA: hda/cs8409: Fix possible NULL dereference (git-fixes).
  - netdevsim: use cond_resched() in nsim_dev_trap_report_work()
    (git-fixes).
  - macsec: don't increment counters for an unrelated SA
    (git-fixes).
  - net: usb: usbnet: fix race in probe failure (git-fixes).
  - HID: plantronics: Workaround for an unexcepted opposite volume
    key (stable-fixes).
  - usb: xhci: Fix problem with xhci resume from suspend
    (stable-fixes).
  - usb: storage: ignore bogus device raised by JieLi BR21 USB
    sound chip (stable-fixes).
  - net: phy: Remove LED entry from LEDs list on unregister
    (git-fixes).
  - net: phy: bcm84881: Fix some error handling paths (git-fixes).
  - net: phy: dp83869: fix memory corruption when enabling fiber
    (git-fixes).
  - kthread: unpark only parked kthread (git-fixes).
  - unicode: Don't special case ignorable code points
    (stable-fixes).
  - fbdev: sisfb: Fix strbuf array overflow (stable-fixes).
  - fbcon: Fix a NULL pointer dereference issue in fbcon_putcs
    (stable-fixes).
  - drm/amd/display: Check null pointer before dereferencing se
    (stable-fixes).
  - driver core: bus: Fix double free in driver API bus_register()
    (stable-fixes).
  - driver core: bus: Return -EIO instead of 0 when show/store
    invalid bus attribute (stable-fixes).
  - comedi: ni_routing: tools: Check when the file could not be
    opened (stable-fixes).
  - serial: protect uart_port_dtr_rts() in uart_shutdown() too
    (stable-fixes).
  - usb: dwc2: Adjust the timing of USB Driver Interrupt
    Registration in the Crashkernel Scenario (stable-fixes).
  - usb: chipidea: udc: enable suspend interrupt after usb reset
    (stable-fixes).
  - i3c: master: cdns: Fix use after free vulnerability in
    cdns_i3c_master Driver Due to Race Condition (stable-fixes).
  - media: videobuf2-core: clear memory related fields in
    __vb2_plane_dmabuf_put() (stable-fixes).
  - clk: imx: Remove CLK_SET_PARENT_GATE for DRAM mux for i.MX7D
    (stable-fixes).
  - clk: bcm: bcm53573: fix OF node leak in init (stable-fixes).
  - i2c: i801: Use a different adapter-name for IDF adapters
    (stable-fixes).
  - mfd: intel_soc_pmic_chtwc: Make Lenovo Yoga Tab 3 X90F DMI
    match less strict (stable-fixes).
  - soundwire: intel_bus_common: enable interrupts before exiting
    reset (stable-fixes).
  - PCI: Mark Creative Labs EMU20k2 INTx masking as broken
    (stable-fixes).
  - PCI: Add ACS quirk for Qualcomm SA8775P (stable-fixes).
  - PCI: Add function 0 DMA alias quirk for Glenfly Arise chip
    (stable-fixes).
  - drm/amd/display: Revert "Check HDCP returned status"
    (stable-fixes).
  - HID: multitouch: Add support for lenovo Y9000P Touchpad
    (stable-fixes).
  - drm/amd/display: Remove a redundant check in authenticated_dp
    (stable-fixes).
  - HID: i2c-hid: Remove I2C_HID_QUIRK_SET_PWR_WAKEUP_DEV quirk
    (stable-fixes).
  - commit f829d20
  - RDMA/mlx5: Enforce umem boundaries for explicit ODP page faults (git-fixes)
  - commit b9b835e
  - RDMA/rtrs-srv: Avoid null pointer deref during path establishment (git-fixes)
  - commit cf9eccb
  - RDMA/mad: Improve handling of timed out WRs of mad agent (git-fixes)
  - commit 72bef76

++++ kernel-rt:

  - vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame
    (bsc#1226498).
  - vmxnet3: Fix missing reserved tailroom (bsc#1226498).
  - commit 1bd55aa
  - vmxnet3: update to version 9 (bsc#1226498).
  - vmxnet3: add command to allow disabling of offloads
    (bsc#1226498).
  - vmxnet3: add latency measurement support in vmxnet3
    (bsc#1226498).
  - vmxnet3: prepare for version 9 changes (bsc#1226498).
  - vmxnet3: Add XDP support (bsc#1226498).
  - commit 3fdc8e3
  - SUNRPC: Fix integer overflow in decode_rc_list() (git-fixes).
  - commit 15be003
  - NFSD: Mark filecache "down" if init fails (git-fixes).
  - commit ceca4b8
  - SUNRPC: clnt.c: Remove misleading comment (git-fixes).
  - commit 2e12710
  - nfs: fix memory leak in error path of nfs4_do_reclaim
    (git-fixes).
  - commit 1994ef6
  - nfsd: fix delegation_blocked() to block correctly for at least
    30 seconds (git-fixes).
  - commit f66078d
  - nfsd: return -EINVAL when namelen is 0 (git-fixes).
  - commit 1bc1c36
  - nfsd: call cache_put if xdr_reserve_space returns NULL
    (git-fixes).
  - commit 003f784
  - nfsd: map the EBADMSG to nfserr_io to avoid warning (git-fixes).
  - commit 5b8020a
  - NFSD: Fix NFSv4's PUTPUBFH operation (git-fixes).
  - commit 88290fb
  - nfsd: fix refcount leak when file is unhashed after being found
    (git-fixes).
  - commit 5a551a1
  - nfsd: remove unneeded EEXIST error check in nfsd_do_file_acquire
    (git-fixes).
  - commit 6d18e0e
  - NFS: Avoid unnecessary rescanning of the per-server delegation
    list (git-fixes).
  - commit e5841ef
  - NFSv4: Fix clearing of layout segments in layoutreturn
    (git-fixes).
  - commit ec4c812
  - ALSA: hda/conexant - Use cached pin control for Node 0x1d on
    HP EliteOne 1000 G2 (git-fixes).
  - ALSA/hda: intel-sdw-acpi: simplify sdw-master-count property
    read (stable-fixes).
  - ALSA/hda: intel-sdw-acpi: fetch fwnode once in
    sdw_intel_scan_controller() (stable-fixes).
  - ALSA/hda: intel-sdw-acpi: cleanup sdw_intel_scan_controller
    (stable-fixes).
  - ALSA: hda/tas2781: Add new quirk for Lenovo, ASUS, Dell projects
    (stable-fixes).
  - ALSA: line6: update contact information (stable-fixes).
  - ALSA: hda/conexant - Fix audio routing for HP EliteOne 1000 G2
    (stable-fixes).
  - ALSA: hda: Sound support for HP Spectre x360 16 inch model 2024
    (stable-fixes).
  - commit fb6c2ec
  - firmware: arm_scmi: Fix the double free in
    scmi_debugfs_common_setup() (git-fixes).
  - ALSA: hda/cs8409: Fix possible NULL dereference (git-fixes).
  - netdevsim: use cond_resched() in nsim_dev_trap_report_work()
    (git-fixes).
  - macsec: don't increment counters for an unrelated SA
    (git-fixes).
  - net: usb: usbnet: fix race in probe failure (git-fixes).
  - HID: plantronics: Workaround for an unexcepted opposite volume
    key (stable-fixes).
  - usb: xhci: Fix problem with xhci resume from suspend
    (stable-fixes).
  - usb: storage: ignore bogus device raised by JieLi BR21 USB
    sound chip (stable-fixes).
  - net: phy: Remove LED entry from LEDs list on unregister
    (git-fixes).
  - net: phy: bcm84881: Fix some error handling paths (git-fixes).
  - net: phy: dp83869: fix memory corruption when enabling fiber
    (git-fixes).
  - kthread: unpark only parked kthread (git-fixes).
  - unicode: Don't special case ignorable code points
    (stable-fixes).
  - fbdev: sisfb: Fix strbuf array overflow (stable-fixes).
  - fbcon: Fix a NULL pointer dereference issue in fbcon_putcs
    (stable-fixes).
  - drm/amd/display: Check null pointer before dereferencing se
    (stable-fixes).
  - driver core: bus: Fix double free in driver API bus_register()
    (stable-fixes).
  - driver core: bus: Return -EIO instead of 0 when show/store
    invalid bus attribute (stable-fixes).
  - comedi: ni_routing: tools: Check when the file could not be
    opened (stable-fixes).
  - serial: protect uart_port_dtr_rts() in uart_shutdown() too
    (stable-fixes).
  - usb: dwc2: Adjust the timing of USB Driver Interrupt
    Registration in the Crashkernel Scenario (stable-fixes).
  - usb: chipidea: udc: enable suspend interrupt after usb reset
    (stable-fixes).
  - i3c: master: cdns: Fix use after free vulnerability in
    cdns_i3c_master Driver Due to Race Condition (stable-fixes).
  - media: videobuf2-core: clear memory related fields in
    __vb2_plane_dmabuf_put() (stable-fixes).
  - clk: imx: Remove CLK_SET_PARENT_GATE for DRAM mux for i.MX7D
    (stable-fixes).
  - clk: bcm: bcm53573: fix OF node leak in init (stable-fixes).
  - i2c: i801: Use a different adapter-name for IDF adapters
    (stable-fixes).
  - mfd: intel_soc_pmic_chtwc: Make Lenovo Yoga Tab 3 X90F DMI
    match less strict (stable-fixes).
  - soundwire: intel_bus_common: enable interrupts before exiting
    reset (stable-fixes).
  - PCI: Mark Creative Labs EMU20k2 INTx masking as broken
    (stable-fixes).
  - PCI: Add ACS quirk for Qualcomm SA8775P (stable-fixes).
  - PCI: Add function 0 DMA alias quirk for Glenfly Arise chip
    (stable-fixes).
  - drm/amd/display: Revert "Check HDCP returned status"
    (stable-fixes).
  - HID: multitouch: Add support for lenovo Y9000P Touchpad
    (stable-fixes).
  - drm/amd/display: Remove a redundant check in authenticated_dp
    (stable-fixes).
  - HID: i2c-hid: Remove I2C_HID_QUIRK_SET_PWR_WAKEUP_DEV quirk
    (stable-fixes).
  - commit f829d20
  - RDMA/mlx5: Enforce umem boundaries for explicit ODP page faults (git-fixes)
  - commit b9b835e
  - RDMA/rtrs-srv: Avoid null pointer deref during path establishment (git-fixes)
  - commit cf9eccb
  - RDMA/mad: Improve handling of timed out WRs of mad agent (git-fixes)
  - commit 72bef76

++++ dav1d:

  - Update to version 1.5.0
    * WARNING: we removed some of the SSE2 optimizations, so if
    you care about systems without SSSE3, you should be careful
    when updating!
    * Optimize index offset calculations for decode_coefs
    * picture: copy HDR10+ and T35 metadata only to visible frames
    * SSSE3 new optimizations for 6-tap (8bit and hbd)
    * AArch64/SVE: Add HBD subpel filters using 128-bit SVE2
    * AArch64: Add USMMLA implempentation for 6-tap H/HV
    * AArch64: Optimize Armv8.0 NEON for HBD horizontal filters
    and 6-tap filters
    * Power9: Optimized ITX till 16x4.
    * Loongarch: numerous optimizations
    * RISC-V optimizations for pal, cdef_filter, ipred, mc_blend,
    mc_bdir, itx
    * Allow playing videos in full-screen mode in dav1dplay

++++ libpipeline:

  - Update to 1.5.8 (27 August 2024):
    * Upgrade to Gnulib `stable-202407`.  Building libpipeline now requires
    Automake >= 1.14.
    * Use C23-style `nullptr`.

++++ unbound:

  - Update to 1.22.0:
    Features:
    * Add iter-scrub-ns, iter-scrub-cname and max-global-quota
    configuration options.
    * Merge patch to fix for glue that is outside of zone, with
    `harden-unverified-glue`, from Karthik Umashankar (Microsoft).
    Enabling this option protects the Unbound resolver against bad
    glue, that is unverified out of zone glue, by resolving them.
    It uses the records as last resort if there is no other working
    glue.
    * Add redis-command-timeout: 20 and redis-connect-timeout: 200,
    that can set the timeout separately for commands and the
    connection set up to the redis server. If they are not
    specified, the redis-timeout value is used.
    * Log timestamps in ISO8601 format with timezone. This adds the
    option `log-time-iso: yes` that logs in ISO8601 format.
    * DNS over QUIC. This adds `quic-port: 853` and `quic-size: 8m`
    that enable dnsoverquic, and the counters `num.query.quic` and
    `mem.quic` in the statistics output. The feature needs to be
    enabled by compiling with libngtcp2, with
    `--with-libngtcp2=path` and libngtcp2 needs openssl+quic, pass
    that with `--with-ssl=path` to compile unbound as well.
    Bug Fixes:
    * unbound-control-setup hangs while testing for openssl presence
    starting from version 1.21.0.
    * Fix error: "memory exhausted" when defining more than 9994
    local-zones.
    * Fix documentation for cache_fill_missing function.
    * Fix Loads of logs: "validation failure: key for validation
    <domain>. is marked as invalid because of a previous" for
    non-DNSSEC signed zone.
    * Fix that when rpz is applied the message does not get picked up
    by the validator. That stops validation failures for the
    message.
    * Fix that stub-zone and forward-zone clauses do not exhaust
    memory for long content.
    * Fix to print port number in logs for auth zone transfer
    activities.
    * b.root renumbering.
    * Add new IANA trust anchor.
    * Fix config file read for dnstap-sample-rate.
    * Fix alloc-size and calloc-transposed-args compiler warnings.
    * Fix to limit NSEC and NSEC3 TTL when aggressive nsec is enabled
    (RFC9077).
    * Fix dns64 with prefetch that the prefetch is stored in cache.
    * Attempt to further fix doh_downstream_buffer_size.tdir
    flakiness.
    * More clear text for prefetch and minimal-responses in the
    unbound.conf man page.
    * Fix cache update when serve expired is used. Expired records
    are favored over resolution and validation failures when
    serve-expired is used.
    * Fix negative cache NSEC3 parameter compares for zero length
    NSEC3 salt.
    * Fix unbound-control-setup hangs sometimes depending on the
    openssl version.
    * Fix Cannot override tcp-upstream and tls-upstream with
    forward-tcp-upstream and forward-tls-upstream.
    * Fix to limit NSEC TTL for messages from cachedb. Fix to limit
    the prefetch ttl for messages after a CNAME with short TTL.
    * Fix to disable detection of quic configured ports when quic is
    not compiled in.
    * Fix harden-unverified-glue for AAAA cache_fill_missing lookups.
    * Fix contrib/aaaa-filter-iterator.patch for change in call
    signature for cache_fill_missing.
    * Fix to display warning if quic-port is set but dnsoverquic is
    not enabled when compiled.
    * Fix dnsoverquic to extend the number of streams when one is
    closed.
    * Fix for dnstap with dnscrypt and dnstap without dnsoverquic.
    * Fix for dnsoverquic and dnstap to use the correct dnstap
    environment.
  - Update keyring

++++ man:

  - Update to man-db 2.13.0 (29 August 2024)
    * Drop support for versions of groff before 1.21 (released on 2010-12-31).
    * Fix `man-suffixed-extension` test failure when not using the GNU
    hierarchy organization.
    * Fix `-Wmissing-variable-declarations` warnings with GCC 14.
    * Fix `-Wflex-array-member-not-at-end` warning with GCC 14.
    * Upgrade to Gnulib `stable-202407`.
    * Support running the test suite against an installed package; this is
    useful for systems such as Debian's autopkgtest framework.
  - Remove patch man-db-2.6.3-chinese.dif as not supported anymore
    due to newer groff versions
  - Port patches
    * man-db-2.6.3-listall.dif
    * man-db-2.7.1-zio.dif
    * man-db-2.9.4.patch
    * man-propose-online.patch

++++ nvidia-open-driver-G06-signed:

  - For CUDA update version to 560.35.03
  - supersedes kernel-6.10.patch
  - cuda-flavor
    * provide nvidia-open-driver-G06-kmp = %version to workaround
    broken cuda-drivers
  - nv-prefer-signed-open-driver
    * added comments for requirements
  - latest change hardcoded to 555.42.06; we no longer need this
    for 560
  - nv-prefer-signed-open-driver:
    * added specicic versions of cuda-drivers/cuda-drivers-xxx as
    preconditions for requiring specific version of
    nvidia-compute-G06
  - nv-prefer-signed-open-driver:
    * no longer require a specific version of
    nvidia-open-driver-G06-signed-cuda-kmp, so it can select the
    correct open driver KMP matching the cuda-runtime version
  - cuda-flavor:
    * added nvidia-compute-G06 = %version to preconditions for
    requiring kernel-firmware-nvidia-gspx-G06, since
    nvidia-compute-utils-G06 does not have a version-specific
    requires on nvidia-compute-G06

------------------------------------------------------------------
------------------  2024-10-17  -  Oct 17 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.2.5
  - -> https://docs.mesa3d.org/relnotes/24.2.5
  - drop u_fix-llvm19-build.patch
    included in upstream

++++ Mesa-drivers:

  - Update to release 24.2.5
  - -> https://docs.mesa3d.org/relnotes/24.2.5
  - drop u_fix-llvm19-build.patch
    included in upstream

++++ python-kiwi:

  - Fixed sphinx_rtd_theme setup
    Delete obsolete display_version attribute
  - Evaluate eficsm everywhere
    Fixed _supports_bios_modules() to take an eventually
    provided eficsm setup into account. The grub config still
    searches for i386 grub modules even if eficsm="false"
    is set.
  - Fixed debian bootstrap script calls
    Run scripts as commands with their native shebang and not
    through bash. Not all debian package scripts uses bash, some
    of them uses sh which can be a link to dash or other
    interpreters. This Fixes #2660
  - Update TW integration tests
    The package x86info was dropped from TW

++++ glib2:

  - Update to version 2.82.2:
    + Bugs fixed:
  - glib/gvariant: incorrect use of G_ANALYZER_ANALYZING
  - Multicast cannot be joined on Mac OS on non-default interface
  - glib/gvariant: Fix check for G_ANALYZER_ANALYZING
  - macos: Fix URL launcher
  - gopenuriportal: Fix two memory leaks
  - gio: Fix multicast iface selection on macOS
  - gdatainputstream: Fix length return value on UTF-8 validation
    failure
    + Updated translations.

++++ gtk3:

  - Eliminate usage of update-alternatives: GTK2 no longer provides
    gtk-update-icon-cache, thus eliminating the need for this extra
    complexity.

++++ kbd:

  - Fix subpackage names and their dependencies.
  - Add missing ldconfig scriptlets.

++++ kernel-default:

  - io_uring/sqpoll: do not put cpumask on stack (git-fixes).
  - io_uring/sqpoll: retain test for whether the CPU is valid
    (git-fixes).
  - commit ff84c2d
  - mm: avoid leaving partial pfn mappings around in error case
    (CVE-2024-47674 bsc#1231673).
  - commit 83d1625
  - RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop (git-fixes)
  - commit 21fb93d
  - RDMA/bnxt_re: Fix the GID table length (git-fixes)
  - commit 6a0779e
  - RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages (git-fixes)
  - commit d91ede3
  - RDMA/bnxt_re: Change the sequence of updating the CQ toggle value (git-fixes)
  - commit 414cbde
  - RDMA/bnxt_re: Return more meaningful error (git-fixes)
  - commit 6755798
  - RDMA/bnxt_re: Fix incorrect dereference of srq in async event (git-fixes)
  - commit 4e1ef61
  - RDMA/bnxt_re: Fix out of bound check (git-fixes)
  - commit d8d1339
  - RDMA/bnxt_re: Fix the max CQ WQEs for older adapters (git-fixes)
  - commit 598626b
  - RDMA/srpt: Make slab cache names unique (git-fixes)
  - commit 29c0fcb
  - RDMA/irdma: Fix misspelling of "accept*" (git-fixes)
  - commit 2566da7
  - RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP (git-fixes)
  - commit 89fa27f
  - RDMA/core: Fix ENODEV error for iWARP test over vlan (git-fixes)
  - commit 4c15511
  - RDMA/bnxt_re: Add a check for memory allocation (git-fixes)
  - commit abea295
  - RDMA/bnxt_re: Fix incorrect AVID type in WQE structure (git-fixes)
  - commit ae91db1
  - RDMA/bnxt_re: Fix a possible memory leak (git-fixes)
  - commit 77c3f34

++++ kernel-rt:

  - io_uring/sqpoll: do not put cpumask on stack (git-fixes).
  - io_uring/sqpoll: retain test for whether the CPU is valid
    (git-fixes).
  - commit ff84c2d
  - mm: avoid leaving partial pfn mappings around in error case
    (CVE-2024-47674 bsc#1231673).
  - commit 83d1625
  - RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop (git-fixes)
  - commit 21fb93d
  - RDMA/bnxt_re: Fix the GID table length (git-fixes)
  - commit 6a0779e
  - RDMA/bnxt_re: Fix a bug while setting up Level-2 PBL pages (git-fixes)
  - commit d91ede3
  - RDMA/bnxt_re: Change the sequence of updating the CQ toggle value (git-fixes)
  - commit 414cbde
  - RDMA/bnxt_re: Return more meaningful error (git-fixes)
  - commit 6755798
  - RDMA/bnxt_re: Fix incorrect dereference of srq in async event (git-fixes)
  - commit 4e1ef61
  - RDMA/bnxt_re: Fix out of bound check (git-fixes)
  - commit d8d1339
  - RDMA/bnxt_re: Fix the max CQ WQEs for older adapters (git-fixes)
  - commit 598626b
  - RDMA/srpt: Make slab cache names unique (git-fixes)
  - commit 29c0fcb
  - RDMA/irdma: Fix misspelling of "accept*" (git-fixes)
  - commit 2566da7
  - RDMA/cxgb4: Fix RDMA_CM_EVENT_UNREACHABLE error for iWARP (git-fixes)
  - commit 89fa27f
  - RDMA/core: Fix ENODEV error for iWARP test over vlan (git-fixes)
  - commit 4c15511
  - RDMA/bnxt_re: Add a check for memory allocation (git-fixes)
  - commit abea295
  - RDMA/bnxt_re: Fix incorrect AVID type in WQE structure (git-fixes)
  - commit ae91db1
  - RDMA/bnxt_re: Fix a possible memory leak (git-fixes)
  - commit 77c3f34

++++ libarchive:

  - Update to 3.7.7:
    * gzip: prevent a hang when processing a malformed gzip inside a gzip
    * tar: don't crash on truncated tar archives
    * tar: fix two leaks in tar header parsing
    * 7-zip: read/write symlink paths as UTF-8
    * cpio: exit with an error code if an entry could not be extracted
    * rar5: report encrypted entries
    * tar: fix truncation of entry pathnames in specific archives

++++ openssl-3:

  - Security fix: [bsc#1231741, CVE-2024-9143]
    * Low-level invalid GF(2^m) parameters lead to OOB memory access
    * Add openssl-CVE-2024-9143.patch
  - Security fix: [bsc#1220262, CVE-2023-50782]
    * Implicit rejection in PKCS#1 v1.5
    * Add openssl-CVE-2023-50782.patch

++++ libunistring:

  - update to 1.3:
    * Support Unicode version 16.0.0

++++ microos-tools:

  - Update to version 4.0+git1:
    * Regenerate initrd after selinux-autorelabel installation

++++ ppp:

  - Update to version 2.5.1:
    * Pppd can now measure and log the round-trip time (RTT) of LCP
    echo-requests and record them in a binary file structured as a
    circular buffer.  Other programs or scripts can examine the
    file and provide real-time statistics on link latency.
    This is enabled by a new "lcp-rtt-file" option.
    * New scripts net-init, net-pre-up and net-down are executed in
    the process of bringing the network interface up and down.
    They provide additional, more deterministic ways for pppd to
    interact with the rest of the networking configuration.
    * New options have been added to allow the system administrator
    to set the location of various scripts and secrets files.
    * A new "noresolvconf" option tells pppd not to write the
    /etc/ppp/resolv.conf file; DNS server addresses, if obtained
    from the peer, are still passed to scripts in the environment.
    * Pppd will now create the directory for the TDB connection
    database if it doesn't already exist.
  - Obsoleted patches:
    * ppp-mkdir-run.patch
    * ppp-pidfiles.patch
  - Drop the ppp_ prefix from /run/ppp_resolv.conf* and put it under
    /run/ppp like the other generated files.

++++ python-requests:

  - Add patch inject-default-ca-bundles.patch:
    * Inject the default CA bundles if they are not specified.
    (bsc#1226321, bsc#1231500)

------------------------------------------------------------------
------------------  2024-10-16  -  Oct 16 2024  -------------------
------------------------------------------------------------------

++++ cups:

  - Drop rcFOO symlinks for CODE16 (PED-266).

++++ dbus-1:

  - Drop rcFOO symlinks (PED-266).

++++ docker:

  - Further merge docker and docker-stable specfiles to minimise the differences.
    The main thing is that we now include both halves of the
    Conflicts/Provides/Obsoletes dance in both specfiles.
  - Update to docker-buildx v0.17.1 to match standalone docker-buildx package we
    are replacing. See upstream changelog online at
    <https://github.com/docker/buildx/releases/tag/v0.17.1>

++++ python-kiwi:

  - Turn DiskFormat into an ordinary class
  - it does not need to be an abstract base class
  - use f-strings where applicable instead of format()
  - change return type of _custom_args_for_format from list to tuple

++++ grub2:

  - Fix not a directory error from the minix filesystem, as leftover data on disk
    may contain its magic header so it gets misdetected (bsc#1231604)
    * grub2-install-fix-not-a-directory-error.patch

++++ kernel-default:

  - io_uring/rw: fix cflags posting for single issue multishot read
    (git-fixes).
  - commit 320c7ee
  - io_uring/net: harden multishot termination case for recv
    (git-fixes).
  - commit 6529e65
  - io_uring: check for presence of task_work rather than
    TIF_NOTIFY_SIGNAL (git-fixes).
  - commit 5b92400
  - io_uring/io-wq: inherit cpuset of cgroup in io worker
    (git-fixes).
  - commit 474a07e
  - io_uring/io-wq: do not allow pinning outside of cpuset
    (git-fixes).
  - commit e99d8a8
  - io_uring/rw: treat -EOPNOTSUPP for IOCB_NOWAIT like -EAGAIN
    (git-fixes).
  - io_uring/sqpoll: do not allow pinning outside of cpuset
    (git-fixes).
  - commit 37d0dce
  - io_uring/eventfd: move to more idiomatic RCU free usage
    (git-fixes).
  - commit 4e262c3
  - udf: Avoid excessive partition lengths (bsc#1230773
    CVE-2024-46777).
  - commit ec61258
  - fsnotify: clear PARENT_WATCHED flags lazily (bsc#1231439
    CVE-2024-47660).
  - commit 133a7e9
  - netem: fix return value if duplicate enqueue fails
    (CVE-2024-45016 bsc#1230429).
  - commit 8c9c269
  - media: pci: ipu3-cio2: Initialise timing struct to avoid a
    compiler warning (git-fixes).
  - commit c21df3e
  - wifi: rtw88: Fix USB/SDIO devices not transmitting beacons
    (git-fixes).
  - commit d46bb93
  - crypto: powerpc/p10-aes-gcm - Add dependency on CRYPTO_SIMD and
    re-enable CRYPTO_AES_GCM_P10 (bsc#1230501 ltc#208632).
  - Update config files.
  - crypto: powerpc/p10-aes-gcm - Register modules as SIMD
    (bsc#1230501 ltc#208632).
  - crypto: powerpc/p10-aes-gcm - Re-write AES/GCM stitched
    implementation (bsc#1230501 ltc#208632).
  - crypto: powerpc/p10-aes-gcm - Disable CRYPTO_AES_GCM_P10
    (bsc#1230501 ltc#208632).
  - powerpc/crypto: don't build aes-gcm-p10 by default (bsc#1230501
    ltc#208632).
  - powerpc/crypto: fix missing skcipher dependency for aes-gcm-p10
    (bsc#1230501 ltc#208632).
  - commit a579f42

++++ kernel-rt:

  - io_uring/rw: fix cflags posting for single issue multishot read
    (git-fixes).
  - commit 320c7ee
  - io_uring/net: harden multishot termination case for recv
    (git-fixes).
  - commit 6529e65
  - io_uring: check for presence of task_work rather than
    TIF_NOTIFY_SIGNAL (git-fixes).
  - commit 5b92400
  - io_uring/io-wq: inherit cpuset of cgroup in io worker
    (git-fixes).
  - commit 474a07e
  - io_uring/io-wq: do not allow pinning outside of cpuset
    (git-fixes).
  - commit e99d8a8
  - io_uring/rw: treat -EOPNOTSUPP for IOCB_NOWAIT like -EAGAIN
    (git-fixes).
  - io_uring/sqpoll: do not allow pinning outside of cpuset
    (git-fixes).
  - commit 37d0dce
  - io_uring/eventfd: move to more idiomatic RCU free usage
    (git-fixes).
  - commit 4e262c3
  - udf: Avoid excessive partition lengths (bsc#1230773
    CVE-2024-46777).
  - commit ec61258
  - fsnotify: clear PARENT_WATCHED flags lazily (bsc#1231439
    CVE-2024-47660).
  - commit 133a7e9
  - netem: fix return value if duplicate enqueue fails
    (CVE-2024-45016 bsc#1230429).
  - commit 8c9c269
  - media: pci: ipu3-cio2: Initialise timing struct to avoid a
    compiler warning (git-fixes).
  - commit c21df3e
  - wifi: rtw88: Fix USB/SDIO devices not transmitting beacons
    (git-fixes).
  - commit d46bb93
  - crypto: powerpc/p10-aes-gcm - Add dependency on CRYPTO_SIMD and
    re-enable CRYPTO_AES_GCM_P10 (bsc#1230501 ltc#208632).
  - Update config files.
  - crypto: powerpc/p10-aes-gcm - Register modules as SIMD
    (bsc#1230501 ltc#208632).
  - crypto: powerpc/p10-aes-gcm - Re-write AES/GCM stitched
    implementation (bsc#1230501 ltc#208632).
  - crypto: powerpc/p10-aes-gcm - Disable CRYPTO_AES_GCM_P10
    (bsc#1230501 ltc#208632).
  - powerpc/crypto: don't build aes-gcm-p10 by default (bsc#1230501
    ltc#208632).
  - powerpc/crypto: fix missing skcipher dependency for aes-gcm-p10
    (bsc#1230501 ltc#208632).
  - commit a579f42

++++ samba:

  -  Adjust spec to split out rpcd_* binaries into a separate
    sub package; (bsc#1231414).

++++ oath-toolkit:

  - Update 0001-usersfile-fix-potential-security-issues-in-PAM-modul.patch
    with bsc#1231699 improvements for security fix CVE-2024-47191

++++ python313-core:

  - With python311-Sphinx we don't need no-skipif-doctests.patch
    any more.

++++ nvidia-open-driver-G06-signed:

  - cuda-flavor:
    * require kernel-firmware-nvidia-gspx-G06 instead of
    kernel-firmware-nvidia-gspx-G06-cuda (which provides also
    kernel-firmware-nvidia-gspx-G06)
    * trigger removal of driver modules also on
    kernel-firmware-nvidia-gspx-G06
  - no longer hard-require kernel firmware package, but install it
    automatically once nvidia-compute-utils-G06 gets installed
  - trigger removal of driver modules with non-existing or wrong
    firmware when (new) firmware gets installed

++++ python313:

  - With python311-Sphinx we don't need no-skipif-doctests.patch
    any more.

++++ qemu:

  - Bug and CVE fixes:
    * softmmu/physmem: fix memory leak in dirty_memory_extend()
    * softmmu: Support concurrent bounce buffers (bsc#1230915, CVE-2024-8612)
    * accel/kvm: check for KVM_CAP_READONLY_MEM on VM (bsc#1231519)

++++ virtiofsd:

  - Update to version 1.12.0:
    * Bump version to v1.12.0
    * Add file-handles migration mode
    * Serialize mount FD map
    * Deserialize file handles
    * Build mount FD map on deserialization
    * Add MigrationMode::FileHandles
    * PassthroughFsV2
    * Allow deserializing serializable file handles
    * Extract serialized::Inode.deserialize_root_node()

------------------------------------------------------------------
------------------  2024-10-15  -  Oct 15 2024  -------------------
------------------------------------------------------------------

++++ ModemManager:

  - Drop rcFOO symlinks (PED-266).

++++ avahi:

  - Drop rcFOO symlinks (PED-266).

++++ fwupd:

  - Drop rcFOO symlinks (PED-266).

++++ kernel-default:

  - powercap: intel_rapl: Fix off by one in get_rpi() (git-fixes).
  - commit 6c73c0c
  - drm/amd/display: Disable DMCUB timeout for DCN35 (bsc#1231435 CVE-2024-46870)
  - commit 0a39326
  - drm/amd/display: Add disable timeout option (bsc#1231435)
  - commit cb303b5
  - Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch
    Drop superfluous file mode modifications in the patch that broke the
    patch expansion recently
  - commit e7ac9e1
  - Move upstreamed scsi patch into sorted section
  - commit 5db43b0

++++ kernel-firmware-all:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-amdgpu:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-ath10k:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-ath11k:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-ath12k:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-atheros:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-bluetooth:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-bnx2:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-brcm:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-chelsio:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-dpaa2:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-i915:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-intel:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-iwlwifi:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-liquidio:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-marvell:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-media:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-mediatek:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-mellanox:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-mwifiex:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-network:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-nfp:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-nvidia:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-platform:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-prestera:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-qcom:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-qlogic:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-radeon:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-realtek:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-serial:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-sound:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-ti:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-ueagle:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-firmware-usb-network:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

++++ kernel-rt:

  - powercap: intel_rapl: Fix off by one in get_rpi() (git-fixes).
  - commit 6c73c0c
  - drm/amd/display: Disable DMCUB timeout for DCN35 (bsc#1231435 CVE-2024-46870)
  - commit 0a39326
  - drm/amd/display: Add disable timeout option (bsc#1231435)
  - commit cb303b5
  - Refresh patches.suse/paddings-add-paddings-to-TypeC-stuff.patch
    Drop superfluous file mode modifications in the patch that broke the
    patch expansion recently
  - commit e7ac9e1
  - Move upstreamed scsi patch into sorted section
  - commit 5db43b0

++++ kubevirt:

  - Enable aarch64 build for SLE and mark it as techpreview (jsc#PED-10545)

++++ colord:

  - Drop rcFOO symlinks (PED-266).

++++ samba:

  - Update to 4.21.1
    * DH reconnect error handling can lead to stale sharemode
    entries; (bso#15624).
    * "inherit permissions = yes" triggers assert() in vfs_default
    when creating a stream; (bso#15695).
    * Samba 4.21.0 broke FreeIPA domain member integration;
    (bso#15715).
    * Missing conversion for msDS-UserTGTLifetime, msDS-
    ComputerTGTLifetime and msDS-ServiceTGTLifetime on "samba-
    tool domain auth policy modify"; (bso#15692).
    * irpc_destructor may crash during shutdown; (bso#15280).
    * Durable handle is not granted when a previous OPEN exists
    with NoOplock; (bso#15649).
    * Durable handle is granted but reconnect fails; (bso#15651).
    * Disconnected durable handles with RH lease should not be
    purged by a new non conflicting open; (bso#15708).
    * net ads testjoin and other commands use the wrong secrets.tdb
    in a cluster; (bso#15714).
    * 4.21 using --with-system-mitkrb5 requires MIT krb5 1.16 as
    rfc 8009 etypes are used; (bso#15726).
    * VFS_OPEN_HOW_WITH_BACKUP_INTENT breaks shadow_copy2;
    (bso#15730).
    * Samba 4.20.0 DLZ module crashes BIND on startup; (bso#15643).
    * Cannot build libldb lmdb backend on a build without AD DC;
    (bso#15721).
    * Consistent log level for sighup handler; (bso#15706).

++++ podman:

  - Add patch for CVE-2024-9675 (bsc#1231499):
    * 0003-Properly-validate-cache-IDs-and-sources.patch
  - Add patch for CVE-2024-9407 (bsc#1231208):
    * 0002-CVE-2024-9407-validate-bind-propagation-flag-setting.patch
  - Rebase patches:
    * 0001-pkg-subscriptions-use-securejoin-for-the-container-p.patch

++++ libselinux-bindings:

  - Add 1231587-build-libselinux-with-swig-4.3.0.patch to fix build
    failure with swig 4.3.0 (bsc#1231587)

++++ python-semanage:

  - Add 1231587-build-libsemanage-with-swig-4.3.0.patch to fix
    build failure with swig 4.3.0 (bsc#1231587)

++++ qemu:

  - Fix bsc#1231519 and bsc#1230140:
    * accel/kvm: check for KVM_CAP_READONLY_MEM on VM
    * target/ppc: Fix lxvx/stxvx facility check

++++ ucode-amd:

  - Update to version 20241014 (git commit 99f9c7ed1f4a):
    * iwlwifi: add gl/Bz FW for core91-69 release
    * iwlwifi: update ty/So/Ma firmwares for core91-69 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core91-69 release
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for a Lenovo Laptop
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for some ASUS laptops
    * cirrus: cs35l56: Add firmware for Cirrus Amps for some HP laptops
    * linux-firmware: update firmware for en8811h 2.5G ethernet phy
    * QCA: Add Bluetooth firmwares for WCN785x with UART transport

------------------------------------------------------------------
------------------  2024-10-14  -  Oct 14 2024  -------------------
------------------------------------------------------------------

++++ acpica:

  - Update to 20240927
    * Fix the acpixf.h file which caused issues for the last release
    (before this) 20240827
    * Fix the pointer offset for the SLIC table

++++ python-kiwi:

  - Add new containers section
    Allow to specify references to OCI containers in the
    image description like in the following example:
    <containers source="registry.suse.com" backend="podman">
    <container name="some" tag="some" path="/some/path"/>
    </containers>
    During the kiwi process the containers are fetched into a
    temporary location and a systemd service is configured to
    one time load the containers into the local registry at
    first boot of the system. This Fixes #2663

++++ fwupd:

  - Enable plugin_amdgpu: the plugin built succesfully

++++ keepalived:

  - Update to version 2.3.1+git86.59c39afe:
    * vrrp: allow specifing interval amd timeout to milli-second resolution
    * vrrp: on reload only configured track_script name was checked
    * lib: fix corruption of master-child_pid red black tree
    * lib: add micro-second timers to memory allocation debugging
    * core: update addattr_l to match current iproute2 code - almost
    * lib: add file missing from previous commit
    * all: suppress an increases alignment warning
    * core: use /* FALLTHROUGH */ rather than __fallthrough;
    * ipvs: resolve a "cast increases required alignment" warning
    * build: don't redefine FORTIFY_SOURCE if host environment defines it
    * vrrp ipvs: remove unused definition of XENFS_SUPER_MAGIC
    * vrrp ipvs: fix warnings related to signedness of statfs() f_flags
    * all: use correct format specifier for time fields
    * bfd: make alloc_bfd() return NULL rather than false on error
    * all: make min_auto_priority delay variable an unsigned
    * configure: explicitly set language to C for configure
    * itest: Warn if close after send not set in tcp_server for http
    * test: Make tcp_server use of SO_LINGER optional
    * core: remove diagnostic message accidently added in commit 7cb09b2
    * vrrp ipvs: Stop setting SO_LINGER on TCP sockets
    * test: update tcp_server and tcp_client
    * bfd: use time_t to avoid implicit ptr type casting
    * VRRP: add thread_timer_expired keyword as a synonym of timer_expired_backup

++++ kernel-default:

  - nbd: fix race between timeout and normal completion
    (bsc#1230918).
  - commit 57c54c8
  - ext4: mark fc as ineligible using an handle in ext4_xattr_set()
    (bsc#1231640).
  - ext4: use handle to mark fc as ineligible in
    __track_dentry_update() (bsc#1231639).
  - jbd2: correctly compare tids with tid_geq function in
    jbd2_fc_begin_commit (bsc#1231638).
  - ext4: fix incorrect tid assumption in ext4_fc_mark_ineligible()
    (bsc#1231637).
  - ext4: fix fast commit inode enqueueing during a full journal
    commit (bsc#1231636).
  - ext4: don't track ranges in fast_commit if inode has inlined
    data (bsc#1231635).
  - ext4: fix possible tid_t sequence overflows (bsc#1231634).
  - commit 6951914
  - net: sysfs: Fix /sys/class/net/<iface> path for statistics
    (git-fixes).
  - commit 54925d7
  - devlink: Fix command annotation documentation (git-fixes).
  - commit 2b95827
  - x86/Documentation: Indent 'note::' directive for protocol
    version number note (git-fixes).
  - commit ec31602
  - mm/filemap: optimize filemap folio adding (bsc#1231617).
  - lib/xarray: introduce a new helper xas_get_order (bsc#1231617).
  - mm/filemap: return early if failed to allocate memory for split
    (bsc#1231617).
  - commit c3c5888
  - srcu: Fix callbacks acceleration mishandling (git-fixes).
  - task_work: add kerneldoc annotation for 'data' argument
    (git-fixes).
  - commit a4661ee
  - HID: amd_sfh: Switch to device-managed dmam_alloc_coherent()
    (git-fixes).
  - hid: intel-ish-hid: Fix uninitialized variable 'rv' in
    ish_fw_xfer_direct_dma (git-fixes).
  - usb: dwc3: core: Stop processing of pending events if controller
    is halted (git-fixes).
  - usb: gadget: core: force synchronous registration (git-fixes).
  - commit 2bb6fd5

++++ kernel-firmware-all:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-amdgpu:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-ath10k:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-ath11k:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-ath12k:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-atheros:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-bluetooth:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-bnx2:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-brcm:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-chelsio:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-dpaa2:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-i915:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-intel:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-iwlwifi:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-liquidio:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-marvell:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-media:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-mediatek:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-mellanox:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-mwifiex:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-network:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-nfp:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-nvidia:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-platform:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-prestera:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-qcom:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-qlogic:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-radeon:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-realtek:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-serial:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-sound:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-ti:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-ueagle:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-firmware-usb-network:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ kernel-rt:

  - nbd: fix race between timeout and normal completion
    (bsc#1230918).
  - commit 57c54c8
  - ext4: mark fc as ineligible using an handle in ext4_xattr_set()
    (bsc#1231640).
  - ext4: use handle to mark fc as ineligible in
    __track_dentry_update() (bsc#1231639).
  - jbd2: correctly compare tids with tid_geq function in
    jbd2_fc_begin_commit (bsc#1231638).
  - ext4: fix incorrect tid assumption in ext4_fc_mark_ineligible()
    (bsc#1231637).
  - ext4: fix fast commit inode enqueueing during a full journal
    commit (bsc#1231636).
  - ext4: don't track ranges in fast_commit if inode has inlined
    data (bsc#1231635).
  - ext4: fix possible tid_t sequence overflows (bsc#1231634).
  - commit 6951914
  - net: sysfs: Fix /sys/class/net/<iface> path for statistics
    (git-fixes).
  - commit 54925d7
  - devlink: Fix command annotation documentation (git-fixes).
  - commit 2b95827
  - x86/Documentation: Indent 'note::' directive for protocol
    version number note (git-fixes).
  - commit ec31602
  - mm/filemap: optimize filemap folio adding (bsc#1231617).
  - lib/xarray: introduce a new helper xas_get_order (bsc#1231617).
  - mm/filemap: return early if failed to allocate memory for split
    (bsc#1231617).
  - commit c3c5888
  - srcu: Fix callbacks acceleration mishandling (git-fixes).
  - task_work: add kerneldoc annotation for 'data' argument
    (git-fixes).
  - commit a4661ee
  - HID: amd_sfh: Switch to device-managed dmam_alloc_coherent()
    (git-fixes).
  - hid: intel-ish-hid: Fix uninitialized variable 'rv' in
    ish_fw_xfer_direct_dma (git-fixes).
  - usb: dwc3: core: Stop processing of pending events if controller
    is halted (git-fixes).
  - usb: gadget: core: force synchronous registration (git-fixes).
  - commit 2bb6fd5

++++ libjcat:

  - Update to version 0.2.2:
    + New Features:
  - Add bt-logindex blob kind.
    + Bugfixes:
  - Increase test coverage for ED25519 support.
  - Save the auto-generated private key with 0600 file
    permissions.
  - Switch ED25519 support to not directly using Nettle.

++++ openssh:

  - Use %{with ...} instead of 0%{with ...}

++++ ucode-amd:

  - Update to version 20241011 (git commit 808cba847c70):
    * mtk_wed: add firmware for mt7988 Wireless Ethernet Dispatcher
    * ath12k: WCN7850 hw2.0: update board-2.bin (bsc#1230596)
    * ath12k: QCN9274 hw2.0: add to WLAN.WBE.1.3.1-00162-QCAHKSWPL_SILICONZ-1
    * ath12k: QCN9274 hw2.0: add board-2.bin
    * copy-firmware.sh: rename variables in symlink hanlding
    * copy-firmware.sh: remove no longer reachable test -L
    * copy-firmware.sh: remove no longer reachable test -f
    * copy-firmware.sh: call ./check_whence.py before parsing the file
    * copy-firmware.sh: warn if the destination folder is not empty
    * copy-firmware.sh: add err() helper
    * copy-firmware.sh: fix indentation
    * copy-firmware.sh: reset and consistently handle destdir
    * Revert "copy-firmware: Support additional compressor options"
    * copy-firmware.sh: flesh out and fix dedup-firmware.sh
    * Style update yaml files
    * editorconfig: add initial config file
    * check_whence.py: annotate replacement strings as raw
    * check_whence.py: LC_ALL=C sort -u the filelist
    * check_whence.py: ban link-to-a-link
    * check_whence.py: use consistent naming
    * Add a link from TAS2XXX1EB3.bin -> ti/tas2781/TAS2XXX1EB30.bin
    * tas2781: Upload dsp firmware for ASUS laptop 1EB30 & 1EB31
  - Skip invocation of check_whence.py at copying:
    copy-file-skip-check.patch
  - Refresh copy-file-ignore-README.patch
  - Drop obsoleted --ignore-duplicates option to copy-firmware.sh
  - Drop the ath12k workaround again

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#180
  - enhanced test cases
  - update test result data
  - reordered tests
  - add optional dash support in test cases
  - 1.17
  - merge gh#openSUSE/perl-bootloader#179
  - support both update-bootloader and perl-Bootloader as package
    name
  - merge gh#openSUSE/perl-bootloader#175
  - fix handling of missing grub_installdevice on powerpc (bsc#1230070)

------------------------------------------------------------------
------------------  2024-10-13  -  Oct 13 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - hwmon: (adt7470) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: (adm9240) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: (mc34vr500) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: (tmp513) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: intel-m10-bmc-hwmon: relabel Columbiaville to CVL Die
    Temperature (git-fixes).
  - commit 07e1f67

++++ kernel-rt:

  - hwmon: (adt7470) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: (adm9240) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: (mc34vr500) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: (tmp513) Add missing dependency on REGMAP_I2C
    (git-fixes).
  - hwmon: intel-m10-bmc-hwmon: relabel Columbiaville to CVL Die
    Temperature (git-fixes).
  - commit 07e1f67

------------------------------------------------------------------
------------------  2024-10-12  -  Oct 12 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - gpio: aspeed: Use devm_clk api to manage clock source
    (git-fixes).
  - gpio: aspeed: Add the flush write to ensure the write complete
    (git-fixes).
  - ata: libata: avoid superfluous disk spin down + spin up during
    hibernation (git-fixes).
  - nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy
    error (git-fixes).
  - nouveau/dmem: Fix privileged error in copy engine channel
    (git-fixes).
  - drm/vc4: Stop the active perfmon before being destroyed
    (git-fixes).
  - drm/v3d: Stop the active perfmon before being destroyed
    (git-fixes).
  - drm/i915/hdcp: fix connector refcounting (git-fixes).
  - commit 8534efe
  - kABI: bpf: struct bpf_insn_acces_aux kABI workaround (git-fixes).
  - commit c2cff36

++++ kernel-rt:

  - gpio: aspeed: Use devm_clk api to manage clock source
    (git-fixes).
  - gpio: aspeed: Add the flush write to ensure the write complete
    (git-fixes).
  - ata: libata: avoid superfluous disk spin down + spin up during
    hibernation (git-fixes).
  - nouveau/dmem: Fix vulnerability in migrate_to_ram upon copy
    error (git-fixes).
  - nouveau/dmem: Fix privileged error in copy engine channel
    (git-fixes).
  - drm/vc4: Stop the active perfmon before being destroyed
    (git-fixes).
  - drm/v3d: Stop the active perfmon before being destroyed
    (git-fixes).
  - drm/i915/hdcp: fix connector refcounting (git-fixes).
  - commit 8534efe
  - kABI: bpf: struct bpf_insn_acces_aux kABI workaround (git-fixes).
  - commit c2cff36

------------------------------------------------------------------
------------------  2024-10-11  -  Oct 11 2024  -------------------
------------------------------------------------------------------

++++ cifs-utils:

  - Update to version 7.1:
    * cifs: update documentation for sloppy mount option
    * docs: add closetimeo description
    * docs: add compress description
    * checkopts: update it to work with latest kernel version
    * cifs-utils: add documentation for multichannel and max_channels
    * cifs-utils: smbinfo: add gettconinfo command
    * Implement CLDAP Ping to find the closest site
    * mount.cifs.rst: update section about xattr/acl support
    * mount.cifs.rst: add missing reference for sssd
    * getcifsacl, setcifsacl: add missing <endian.h> include for le32toh
    * getcifsacl, setcifsacl: add missing <linux/limits.h> include for XATTR_SIZE_MAX
    * cifs-utils: Make automake treat /sbin as exec, not data
    * pam_cifscreds: fix warning on NULL arg passed to %s in pam_syslog()
    * cifs.upcall: fix UAF in get_cachename_from_process_env()
    * cifs-utils: add documentation for acregmax and acdirmax
    * setcifsacl: Fix uninitialized value.
    * Use explicit "#!/usr/bin/python3"

++++ drbd:

  - Update DRBD version from 9.1.16 to 9.1.22
    * Changelog from Linbit:
    9.1.22 (api:genl2/proto:86-121/transport:18)
  - -------
    * Upgrade from partial resync to a full resync if necessary when the
    user manually resolves a split-brain situation
    * Fix a potential NULL deref when a disk fails while doing a
    forget-peer operation.
    * Fix a rcu_read_lock()/rcu_read_unlock() imbalance
    * Restart the open() syscall when a process auto promoting a drbd device gets
    interrupted by a signal
    * Remove a deadlock that caused DRBD to connect sometimes
    exceptionally slow
    * Make detach operations interruptible
    * Added dev_is_open to events2 status information
    * Improve log readability for 2PC state changes and drbd-threads
    * Updated compability code for Linux 6.9
    9.1.21 (api:genl2/proto:86-121/transport:18)
  - -------
    * fix a deadlock that can trigger when deleting a connection and
    another connection going down in parallel. This is a regression of
    9.1.20
    * Fix an out-of-bounds access when scanning the bitmap. It leads to a
    crash when the bitmap ends on a page boundary, and this is also a
    regression in 9.1.20.
    9.1.20 (api:genl2/proto:86-121/transport:18)
  - -------
    * Fix a kernel crash that is sometimes triggered when downing drbd
    resources in a specific, unusual order (was triggered by the
    Kubernetes CSI driver)
    * Fix a rarely triggering kernel crash upon adding paths to a
    connection by rehauling the path lists' locking
    * Fix the continuation of an interrupted initial resync
    * Fix the state engine so that an incapable primary does not outdate
    indirectly reachable secondary nodes
    * Fix a logic bug that caused drbd to pretend that a peer's disk is
    outdated when doing a manual disconnect on a down connection; with
    that cured impact on fencing and quorum.
    * Fix forceful demotion of suspended devices
    * Rehaul of the build system to apply compatibility patches out of
    place that allows one to build for different target kernels from a
    single drbd source tree
    * Updated compability code for Linux 6.8
    9.1.19 (api:genl2/proto:86-121/transport:18)
  - -------
    * Fix a resync decision case where drbd wrongly decided to do a full
    resync, where a partial resync was sufficient; that happened in a
    specific connect order when all nodes were on the same data
    generation (UUID)
    * Fix the online resize code to obey cached size information about
    temporal unreachable nodes
    * Fix a rare corner case in which DRBD on a diskless primary node
    failed to re-issue a read request to another node with a backing
    disk upon connection loss on the connection where it shipped the
    read request initially
    * Make timeout during promotion attempts interruptible
    * No longer write activity-log updates on the secondary node in a
    cluster with precisely two nodes with backing disk; this is a
    performance optimization
    * Reduce CPU usage of acknowledgment processing
    9.1.18 (api:genl2/proto:86-121/transport:18)
  - -------
    * Fixed connecting nodes with differently sized backing disks,
    specifically when the smaller node is primary, before establishing
    the connections
    * Fixed thawing a device that has I/O frozen after loss of quorum
    when a configuration change eases its quorum requirements
    * Properly fail TLS if requested (only available in drbd-9.2)
    * Fixed a race condition that can cause auto-demote to trigger right
    after an explicit promote
    * Fixed a rare race condition that could mess up the handshake result
    before it is committed to the replication state.
    * Preserve "tiebreaker quorum" over a reboot of the last node (3-node
    clusters only)
    * Update compatibility code for Linux 6.6
    9.1.17 (api:genl2/proto:86-121/transport:18)
  - -------
    * fix a potential crash when configuring drbd to bind to a
    non-existent local IP address (this is a regression of drbd-9.1.8)
    * Cure a very seldom triggering race condition bug during
    establishing connections; when you triggered it, you got an OOPS
    hinting to list corruption
    * fix a race condition regarding operations on the bitmap while
    forgetting a bitmap slot and a pointless warning
    * Fix handling of unexpected (on a resource in secondary role) write
    requests
    * Fix a corner case that can cause a process to hang when closing the
    DRBD device, while a connection gets re-established
    * Correctly block signal delivery during auto-demote
    * Improve the reliability of establishing connections
    * Do not clear the transport with `net-options --set-defaults`. This
    fix avoids unexpected disconnect/connect cycles upon an `adjust`
    when using the 'lb-tcp' or 'rdma' transports in drbd-9.2.
    * New netlink packet to report path status to drbdsetup
    * Improvements to the content and rate-limiting of many log messages
    * Update compatibility code and follow Linux upstream development
    until Linux 6.5
    * remove patches which already included in the new version:
    0001-drbd-allow-transports-to-take-additional-krefs-on-a-.patch
    0002-drbd-improve-decision-about-marking-a-failed-disk-Ou.patch
    0003-drbd-fix-error-path-in-drbd_get_listener.patch
    0004-drbd-build-fix-spurious-re-build-attempt-of-compat.p.patch
    0005-drbd-log-error-code-when-thread-fails-to-start.patch
    0006-drbd-log-numeric-value-of-drbd_state_rv-as-well-as-s.patch
    0007-drbd-stop-defining-__KERNEL_SYSCALLS__.patch
    0008-compat-block-introduce-holder-ops.patch
    0009-drbd-reduce-net_ee-not-empty-info-to-a-dynamic-debug.patch
    0010-drbd-do-not-send-P_CURRENT_UUID-to-DRBD-8-peer-when-.patch
    0011-compat-block-pass-a-gendisk-to-open.patch
    0012-drbd-Restore-DATA_CORKED-and-CONTROL_CORKED-bits.patch
    0013-drbd-remove-unused-extern-for-conn_try_outdate_peer.patch
    0014-drbd-include-source-of-state-change-in-log.patch
    0015-compat-block-use-the-holder-as-indication-for-exclus.patch
    0016-drbd-Fix-net-options-set-defaults-to-not-clear-the-t.patch
    0017-drbd-propagate-exposed-UUIDs-only-into-established-c.patch
    0018-drbd-rework-autopromote.patch
    0019-compat-block-remove-the-unused-mode-argument-to-rele.patch
    0020-drbd-do-not-allow-auto-demote-to-be-interrupted-by-s.patch
    0021-compat-sock-Remove-sendpage-in-favour-of-sendmsg-MSG.patch
    0022-compat-block-replace-fmode_t-with-a-block-specific-t.patch
    0023-compat-genetlink-remove-userhdr-from-struct-genl_inf.patch
    0024-compat-fixup-FMODE_READ-FMODE_WRITE-usage.patch
    0025-compat-drdb-Convert-to-use-bdev_open_by_path.patch
    0026-compat-gate-blkdev_-patches-behind-bdev_open_by_path.patch
    boo1230635_01-compat-fix-nla_nest_start_noflag-test.patch
    boo1230635_02-drbd-port-block-device-access-to-file.patch
    * removed patches which are not needed anymore:
    boo1229062-re-enable-blk_queue_max_hw_sectors.patch
    bsc1226510-fix-build-err-against-6.9.3.patch
    * update:
    drbd_git_revision
    suse-coccinelle.patch
    drbd.spec
    * add upstream patches to align commit 13ada1be201e:
    0001-drbd-properly-rate-limit-resync-progress-reports.patch
    0002-drbd-inherit-history-UUIDs-from-sync-source-when-res.patch
    0003-build-compat-fix-line-offset-in-annotation-pragmas-p.patch
    0004-drbd-fix-exposed_uuid-going-backward.patch
    0005-drbd-Proper-locking-around-new_current_uuid-on-a-dis.patch
    0006-build-CycloneDX-fix-bom-ref-add-purl.patch
    0007-build-Another-update-to-the-spdx-files.patch
    0008-build-generate-spdx.json-not-tag-value-format.patch
    0009-compat-fix-gen_patch_names-for-bdev_file_open_by_pat.patch
    0010-compat-fix-nla_nest_start_noflag-test.patch
    0011-compat-fix-blk_alloc_disk-rule.patch
    0012-drbd-remove-const-from-function-return-type.patch
    0013-drbd-don-t-set-max_write_zeroes_sectors-in-decide_on.patch
    0014-drbd-split-out-a-drbd_discard_supported-helper.patch
    0015-drbd-atomically-update-queue-limits-in-drbd_reconsid.patch
    0016-compat-test-and-patch-for-queue_limits_start_update.patch
    0017-compat-specify-which-essential-change-was-not-made.patch
    0018-gen_patch_names-reorder-blk_mode_t.patch
    0019-compat-fix-blk_queue_update_readahead-patch.patch
    0020-compat-test-and-patch-for-que_limits-max_hw_discard_.patch
    0021-compat-fixup-write_zeroes__no_capable.patch
    0022-compat-fixup-queue_flag_discard__yes_present.patch
    0023-drbd-move-flags-to-queue_limits.patch
    0024-compat-test-and-patch-for-queue_limits.features.patch
    0025-drbd-Annotate-struct-fifo_buffer-with-__counted_by.patch
    0026-compat-test-and-patch-for-__counted_by.patch
    0027-drbd-fix-function-cast-warnings-in-state-machine.patch
    0028-Add-missing-documentation-of-peer_device-parameter-t.patch
    0030-drbd-kref_put-path-when-kernel_accept-fails.patch
    0031-build-fix-typo-in-Makefile.spatch.patch
    0032-drbd-open-do-not-delay-open-if-already-Primary.patch
    * add patch to fix kernel imcompatibility issue (boo#1231290):
    boo1231290_fix_drbd_build_error_against_kernel_v6.11.0.patch

++++ kernel-default:

  - Update patches.suse/ASoC-meson-axg-card-fix-use-after-free.patch
    (git-fixes CVE-2024-46849 bsc#1231073).
  - Update
    patches.suse/KVM-x86-Acquire-kvm-srcu-when-handling-KVM_SET_VCPU_.patch
    (git-fixes CVE-2024-46830 bsc#1231116).
  - Update
    patches.suse/PCI-keystone-Add-workaround-for-Errata-i2037-AM65x-S.patch
    (stable-fixes CVE-2024-47667 bsc#1231481).
  - Update patches.suse/USB-usbtmc-prevent-kernel-usb-infoleak.patch
    (git-fixes CVE-2024-47671 bsc#1231541).
  - Update patches.suse/arm64-tlb-Fix-TLBI-RANGE-operand.patch
    (bsc#1229585 CVE-2024-35980 bsc#1224574).
  - Update
    patches.suse/dma-buf-heaps-Fix-off-by-one-in-CMA-heap-fault-handl.patch
    (git-fixes CVE-2024-46852 bsc#1231082).
  - Update
    patches.suse/drm-amd-amdgpu-Check-tbo-resource-pointer.patch
    (stable-fixes CVE-2024-46807 bsc#1231138).
  - Update
    patches.suse/drm-amd-display-Add-array-index-check-for-hdcp-ddc-a.patch
    (stable-fixes CVE-2024-46804 bsc#1231132).
  - Update
    patches.suse/drm-amd-display-Avoid-overflow-from-uint32_t-to-uint.patch
    (stable-fixes CVE-2024-47661 bsc#1231496).
  - Update
    patches.suse/drm-amd-display-Avoid-race-between-dcn10_set_drr-and.patch
    (git-fixes CVE-2024-46851 bsc#1231081).
  - Update
    patches.suse/drm-amd-display-Check-BIOS-images-before-it-is-used.patch
    (stable-fixes CVE-2024-46809 bsc#1231148).
  - Update
    patches.suse/drm-amd-display-Check-gpio_id-before-used-as-array-i.patch
    (stable-fixes CVE-2024-46818 bsc#1231203).
  - Update
    patches.suse/drm-amd-display-Check-msg_id-before-processing-trans.patch
    (stable-fixes CVE-2024-46814 bsc#1231193).
  - Update
    patches.suse/drm-amd-display-Check-num_valid_sets-before-accessin.patch
    (stable-fixes CVE-2024-46815 bsc#1231195).
  - Update
    patches.suse/drm-amd-display-Correct-the-defined-value-for-AMDGPU.patch
    (stable-fixes CVE-2024-46871 bsc#1231434).
  - Update
    patches.suse/drm-amd-display-Fix-index-may-exceed-array-range-wit.patch
    (stable-fixes CVE-2024-46811 bsc#1231179).
  - Update
    patches.suse/drm-amd-display-Remove-register-from-DCN35-DMCUB-dia.patch
    (stable-fixes CVE-2024-47662 bsc#1231440).
  - Update
    patches.suse/drm-amd-display-Skip-inactive-planes-within-ModeSupp.patch
    (stable-fixes CVE-2024-46812 bsc#1231187).
  - Update
    patches.suse/drm-amd-display-Stop-amdgpu_dm-initialize-when-strea.patch
    (stable-fixes CVE-2024-46817 bsc#1231200).
  - Update
    patches.suse/drm-amd-display-added-NULL-check-at-start-of-dc_vali.patch
    (stable-fixes CVE-2024-46802 bsc#1231111).
  - Update
    patches.suse/drm-amd-pm-Fix-negative-array-index-read.patch
    (stable-fixes CVE-2024-46821 bsc#1231169).
  - Update
    patches.suse/drm-amdgpu-Fix-smatch-static-checker-warning.patch
    (stable-fixes CVE-2024-46835 bsc#1231098).
  - Update
    patches.suse/drm-amdgpu-Fix-the-warning-division-or-modulo-by-zer.patch
    (stable-fixes CVE-2024-46806 bsc#1231136).
  - Update
    patches.suse/drm-amdgpu-fix-the-waring-dereferencing-hive.patch
    (stable-fixes CVE-2024-46805 bsc#1231135).
  - Update
    patches.suse/drm-amdgpu-the-warning-dereferencing-obj-for-nbio_v7.patch
    (stable-fixes CVE-2024-46819 bsc#1231202).
  - Update
    patches.suse/drm-amdkfd-Check-debug-trap-enable-before-write-dbg_.patch
    (stable-fixes CVE-2024-46803 bsc#1231131).
  - Update
    patches.suse/drm-bridge-tc358767-Check-if-fully-initialized-befor.patch
    (stable-fixes CVE-2024-46810 bsc#1231178).
  - Update
    patches.suse/i3c-mipi-i3c-hci-Error-out-instead-on-BUG_ON-in-IBI-.patch
    (stable-fixes CVE-2024-47665 bsc#1231452).
  - Update
    patches.suse/lib-generic-radix-tree.c-Fix-rare-race-in-__genradix.patch
    (stable-fixes CVE-2024-47668 bsc#1231502).
  - Update
    patches.suse/msft-hv-3054-x86-hyperv-fix-kexec-crash-due-to-VP-assist-page-cor.patch
    (git-fixes CVE-2024-46864 bsc#1231108).
  - Update
    patches.suse/nilfs2-fix-state-management-in-error-path-of-log-writing-function.patch
    (git-fixes CVE-2024-47669 bsc#1231474).
  - Update
    patches.suse/ocfs2-add-bounds-checking-to-ocfs2_xattr_find_entry.patch
    (bsc#1228410 CVE-2024-41016 CVE-2024-47670 bsc#1231537).
  - Update
    patches.suse/perf-x86-intel-Limit-the-period-on-Haswell.patch
    (git-fixes CVE-2024-46848 bsc#1231072).
  - Update
    patches.suse/platform-x86-panasonic-laptop-Fix-SINF-array-out-of-.patch
    (git-fixes CVE-2024-46859 bsc#1231089).
  - Update
    patches.suse/rcu-Fix-buffer-overflow-in-print_cpu_stall_info.patch
    (bsc#1226623 CVE-2024-38576).
  - Update
    patches.suse/rcu-tasks-Fix-show_rcu_tasks_trace_gp_kthread-buffer-overflow.patch
    (bsc#1226631 CVE-2024-38577).
  - Update
    patches.suse/scsi-lpfc-Handle-mailbox-timeouts-in-lpfc_get_sfp_in.patch
    (bsc#1228857 CVE-2024-46842 bsc#1231101).
  - Update
    patches.suse/spi-nxp-fspi-fix-the-KASAN-report-out-of-bounds-bug.patch
    (git-fixes CVE-2024-46853 bsc#1231083).
  - Update
    patches.suse/spi-rockchip-Resolve-unbalanced-runtime-PM-system-PM.patch
    (git-fixes CVE-2024-46846 bsc#1231075).
  - Update
    patches.suse/staging-iio-frequency-ad9834-Validate-frequency-para.patch
    (git-fixes CVE-2024-47663 bsc#1231441).
  - Update
    patches.suse/usb-gadget-aspeed_udc-validate-endpoint-index-for-as.patch
    (stable-fixes CVE-2024-46836 bsc#1231092).
  - Update
    patches.suse/usbnet-ipheth-do-not-stop-RX-on-failing-RX-callback.patch
    (git-fixes CVE-2024-46861 bsc#1231102).
  - Update
    patches.suse/wifi-ath12k-fix-firmware-crash-due-to-invalid-peer-n.patch
    (stable-fixes CVE-2024-46827 bsc#1231171).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-wait-for-tx-queues-if-firmwar.patch
    (stable-fixes CVE-2024-47672 bsc#1231540).
  - Update
    patches.suse/wifi-iwlwifi-mvm-pause-TCM-when-the-firmware-is-stop.patch
    (stable-fixes CVE-2024-47673 bsc#1231539).
  - Update
    patches.suse/wifi-iwlwifi-mvm-use-IWL_FW_CHECK-for-link-ID-check.patch
    (stable-fixes CVE-2024-46825 bsc#1231170).
  - Update
    patches.suse/wifi-mt76-mt7921-fix-NULL-pointer-access-in-mt7921_i.patch
    (stable-fixes CVE-2024-46860 bsc#1231093).
  - commit 1ed6329
  - sched/smt: Fix unbalance sched_smt_present dec/inc
    (CVE-2024-44958 bsc#1230179).
  - sched/smt: Introduce sched_smt_present_inc/dec() helper
    (CVE-2024-44958 bsc#1230179).
  - commit b09820b
  - crypto: octeontx* - Select CRYPTO_AUTHENC (git-fixes).
  - commit 155c418
  - spi: spi-imx: Fix pm_runtime_set_suspended() with runtime pm
    enabled (git-fixes).
  - spi: s3c64xx: fix timeout counters in flush_fifo (git-fixes).
  - i2c: synquacer: Deal with optional PCLK correctly (git-fixes).
  - media: imx335: Fix reset-gpio handling (git-fixes).
  - i2c: xiic: Try re-initialization on bus busy timeout
    (git-fixes).
  - platform/x86: touchscreen_dmi: add nanote-next quirk
    (stable-fixes).
  - platform/x86: lenovo-ymc: Ignore the 0x0 state (stable-fixes).
  - hwmon: (nct6775) add G15CF to ASUS WMI monitoring list
    (stable-fixes).
  - power: reset: brcmstb: Do not go into infinite loop if reset
    fails (stable-fixes).
  - wifi: ath9k_htc: Use __skb_set_length() for resetting urb
    before resubmit (stable-fixes).
  - wifi: mt76: mt7915: hold dev->mt76.mutex while disabling tx
    worker (stable-fixes).
  - wifi: mt76: mt7915: add dummy HW offload of IEEE 802.11
    fragmentation (stable-fixes).
  - wifi: mt76: mt7915: disable tx worker during tx BA session
    enable/disable (stable-fixes).
  - wifi: rtw89: avoid reading out of bounds when loading TX power
    FW elements (stable-fixes).
  - wifi: rtw89: correct base HT rate mask for firmware
    (stable-fixes).
  - wifi: mwifiex: Fix memcpy() field-spanning write warning in
    mwifiex_cmd_802_11_scan_ext() (stable-fixes).
  - wifi: cfg80211: Set correct chandef when starting CAC
    (stable-fixes).
  - wifi: mac80211: fix RCU list iterations (stable-fixes).
  - wifi: iwlwifi: mvm: avoid NULL pointer dereference
    (stable-fixes).
  - wifi: iwlwifi: allow only CN mcc from WRDD (stable-fixes).
  - wifi: iwlwifi: mvm: drop wrong STA selection in TX
    (stable-fixes).
  - wifi: iwlwifi: mvm: Fix a race in scan abort flow
    (stable-fixes).
  - wifi: iwlwifi: mvm: use correct key iteration (stable-fixes).
  - wifi: ath9k: fix possible integer overflow in
    ath9k_get_et_stats() (stable-fixes).
  - wifi: ath11k: fix array out-of-bound access in SoC stats
    (stable-fixes).
  - wifi: ath12k: fix array out-of-bound access in SoC stats
    (stable-fixes).
  - wifi: rtw89: avoid to add interface to list twice when SER
    (stable-fixes).
  - wifi: rtw88: select WANT_DEV_COREDUMP (stable-fixes).
  - i2c: xiic: improve error message when transfer fails to start
    (stable-fixes).
  - i2c: synquacer: Remove a clk reference from struct synquacer_i2c
    (stable-fixes).
  - media: i2c: imx335: Enable regulator supplies (stable-fixes).
  - commit 490fb1f
  - ALSA: usb-audio: Replace complex quirk lines with macros
    (stable-fixes).
  - commit 6f67136
  - Bluetooth: RFCOMM: FIX possible deadlock in
    rfcomm_sk_state_change (git-fixes).
  - ACPI: battery: Fix possible crash when unregistering a battery
    hook (git-fixes).
  - ACPI: battery: Simplify battery hook locking (stable-fixes).
  - ACPI: resource: Add Asus ExpertBook B2502CVA to
    irq1_level_low_skip_override[] (stable-fixes).
  - ACPI: resource: Add Asus Vivobook X1704VAP to
    irq1_level_low_skip_override[] (stable-fixes).
  - HID: Ignore battery for all ELAN I2C-HID devices (stable-fixes).
  - HID: multitouch: Add support for Thinkpad X12 Gen 2 Kbd
    Portfolio (stable-fixes).
  - ASoC: codecs: wsa883x: Handle reading version failure
    (stable-fixes).
  - ALSA: usb-audio: Add logitech Audio profile quirk
    (stable-fixes).
  - ALSA: usb-audio: Define macros for quirk table entries
    (stable-fixes).
  - ALSA: hdsp: Break infinite MIDI input flush loop (stable-fixes).
  - ALSA: asihpi: Fix potential OOB array access (stable-fixes).
  - ALSA: usb-audio: Add input value sanity checks for standard
    types (stable-fixes).
  - ACPI: PAD: fix crash in exit_round_robin() (stable-fixes).
  - ACPI: video: Add force_vendor quirk for Panasonic Toughbook
    CF-18 (stable-fixes).
  - ACPI: CPPC: Add support for setting EPP register in FFH
    (stable-fixes).
  - ACPI: EC: Do not release locks during operation region accesses
    (stable-fixes).
  - ACPICA: iasl: handle empty connection_node (stable-fixes).
  - ACPICA: Fix memory leak if acpi_ps_get_next_field() fails
    (stable-fixes).
  - ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails
    (stable-fixes).
  - ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in
    acpi_db_convert_to_package() (stable-fixes).
  - crypto: octeontx2 - Fix authenc setkey (stable-fixes).
  - crypto: octeontx - Fix authenc setkey (stable-fixes).
  - Bluetooth: btusb: Add Realtek RTL8852C support ID 0x0489:0xe122
    (stable-fixes).
  - can: netlink: avoid call to do_set_data_bittiming callback
    with stale can_priv::ctrlmode (stable-fixes).
  - commit 650f32e
  - ocfs2: fix the la space leak when unmounting an ocfs2 volume
    (git-fixes).
  - commit 92d1b30
  - jfs: Fix uninit-value access of new_ea in ea_buffer (git-fixes).
  - commit b1e0ef1
  - jfs: check if leafidx greater than num leaves per dmap tree
    (git-fixes).
  - commit 4cb79e7
  - jfs: Fix uaf in dbFreeBits (git-fixes).
  - commit da4aab1
  - jfs: UBSAN: shift-out-of-bounds in dbFindBits (git-fixes).
  - commit fee8a70
  - kABI: bpf: enum bpf_{type_flag,arg_type} kABI workaround (git-fixes).
  - commit 93e6047

++++ kernel-rt:

  - Update patches.suse/ASoC-meson-axg-card-fix-use-after-free.patch
    (git-fixes CVE-2024-46849 bsc#1231073).
  - Update
    patches.suse/KVM-x86-Acquire-kvm-srcu-when-handling-KVM_SET_VCPU_.patch
    (git-fixes CVE-2024-46830 bsc#1231116).
  - Update
    patches.suse/PCI-keystone-Add-workaround-for-Errata-i2037-AM65x-S.patch
    (stable-fixes CVE-2024-47667 bsc#1231481).
  - Update patches.suse/USB-usbtmc-prevent-kernel-usb-infoleak.patch
    (git-fixes CVE-2024-47671 bsc#1231541).
  - Update patches.suse/arm64-tlb-Fix-TLBI-RANGE-operand.patch
    (bsc#1229585 CVE-2024-35980 bsc#1224574).
  - Update
    patches.suse/dma-buf-heaps-Fix-off-by-one-in-CMA-heap-fault-handl.patch
    (git-fixes CVE-2024-46852 bsc#1231082).
  - Update
    patches.suse/drm-amd-amdgpu-Check-tbo-resource-pointer.patch
    (stable-fixes CVE-2024-46807 bsc#1231138).
  - Update
    patches.suse/drm-amd-display-Add-array-index-check-for-hdcp-ddc-a.patch
    (stable-fixes CVE-2024-46804 bsc#1231132).
  - Update
    patches.suse/drm-amd-display-Avoid-overflow-from-uint32_t-to-uint.patch
    (stable-fixes CVE-2024-47661 bsc#1231496).
  - Update
    patches.suse/drm-amd-display-Avoid-race-between-dcn10_set_drr-and.patch
    (git-fixes CVE-2024-46851 bsc#1231081).
  - Update
    patches.suse/drm-amd-display-Check-BIOS-images-before-it-is-used.patch
    (stable-fixes CVE-2024-46809 bsc#1231148).
  - Update
    patches.suse/drm-amd-display-Check-gpio_id-before-used-as-array-i.patch
    (stable-fixes CVE-2024-46818 bsc#1231203).
  - Update
    patches.suse/drm-amd-display-Check-msg_id-before-processing-trans.patch
    (stable-fixes CVE-2024-46814 bsc#1231193).
  - Update
    patches.suse/drm-amd-display-Check-num_valid_sets-before-accessin.patch
    (stable-fixes CVE-2024-46815 bsc#1231195).
  - Update
    patches.suse/drm-amd-display-Correct-the-defined-value-for-AMDGPU.patch
    (stable-fixes CVE-2024-46871 bsc#1231434).
  - Update
    patches.suse/drm-amd-display-Fix-index-may-exceed-array-range-wit.patch
    (stable-fixes CVE-2024-46811 bsc#1231179).
  - Update
    patches.suse/drm-amd-display-Remove-register-from-DCN35-DMCUB-dia.patch
    (stable-fixes CVE-2024-47662 bsc#1231440).
  - Update
    patches.suse/drm-amd-display-Skip-inactive-planes-within-ModeSupp.patch
    (stable-fixes CVE-2024-46812 bsc#1231187).
  - Update
    patches.suse/drm-amd-display-Stop-amdgpu_dm-initialize-when-strea.patch
    (stable-fixes CVE-2024-46817 bsc#1231200).
  - Update
    patches.suse/drm-amd-display-added-NULL-check-at-start-of-dc_vali.patch
    (stable-fixes CVE-2024-46802 bsc#1231111).
  - Update
    patches.suse/drm-amd-pm-Fix-negative-array-index-read.patch
    (stable-fixes CVE-2024-46821 bsc#1231169).
  - Update
    patches.suse/drm-amdgpu-Fix-smatch-static-checker-warning.patch
    (stable-fixes CVE-2024-46835 bsc#1231098).
  - Update
    patches.suse/drm-amdgpu-Fix-the-warning-division-or-modulo-by-zer.patch
    (stable-fixes CVE-2024-46806 bsc#1231136).
  - Update
    patches.suse/drm-amdgpu-fix-the-waring-dereferencing-hive.patch
    (stable-fixes CVE-2024-46805 bsc#1231135).
  - Update
    patches.suse/drm-amdgpu-the-warning-dereferencing-obj-for-nbio_v7.patch
    (stable-fixes CVE-2024-46819 bsc#1231202).
  - Update
    patches.suse/drm-amdkfd-Check-debug-trap-enable-before-write-dbg_.patch
    (stable-fixes CVE-2024-46803 bsc#1231131).
  - Update
    patches.suse/drm-bridge-tc358767-Check-if-fully-initialized-befor.patch
    (stable-fixes CVE-2024-46810 bsc#1231178).
  - Update
    patches.suse/i3c-mipi-i3c-hci-Error-out-instead-on-BUG_ON-in-IBI-.patch
    (stable-fixes CVE-2024-47665 bsc#1231452).
  - Update
    patches.suse/lib-generic-radix-tree.c-Fix-rare-race-in-__genradix.patch
    (stable-fixes CVE-2024-47668 bsc#1231502).
  - Update
    patches.suse/msft-hv-3054-x86-hyperv-fix-kexec-crash-due-to-VP-assist-page-cor.patch
    (git-fixes CVE-2024-46864 bsc#1231108).
  - Update
    patches.suse/nilfs2-fix-state-management-in-error-path-of-log-writing-function.patch
    (git-fixes CVE-2024-47669 bsc#1231474).
  - Update
    patches.suse/ocfs2-add-bounds-checking-to-ocfs2_xattr_find_entry.patch
    (bsc#1228410 CVE-2024-41016 CVE-2024-47670 bsc#1231537).
  - Update
    patches.suse/perf-x86-intel-Limit-the-period-on-Haswell.patch
    (git-fixes CVE-2024-46848 bsc#1231072).
  - Update
    patches.suse/platform-x86-panasonic-laptop-Fix-SINF-array-out-of-.patch
    (git-fixes CVE-2024-46859 bsc#1231089).
  - Update
    patches.suse/rcu-Fix-buffer-overflow-in-print_cpu_stall_info.patch
    (bsc#1226623 CVE-2024-38576).
  - Update
    patches.suse/rcu-tasks-Fix-show_rcu_tasks_trace_gp_kthread-buffer-overflow.patch
    (bsc#1226631 CVE-2024-38577).
  - Update
    patches.suse/scsi-lpfc-Handle-mailbox-timeouts-in-lpfc_get_sfp_in.patch
    (bsc#1228857 CVE-2024-46842 bsc#1231101).
  - Update
    patches.suse/spi-nxp-fspi-fix-the-KASAN-report-out-of-bounds-bug.patch
    (git-fixes CVE-2024-46853 bsc#1231083).
  - Update
    patches.suse/spi-rockchip-Resolve-unbalanced-runtime-PM-system-PM.patch
    (git-fixes CVE-2024-46846 bsc#1231075).
  - Update
    patches.suse/staging-iio-frequency-ad9834-Validate-frequency-para.patch
    (git-fixes CVE-2024-47663 bsc#1231441).
  - Update
    patches.suse/usb-gadget-aspeed_udc-validate-endpoint-index-for-as.patch
    (stable-fixes CVE-2024-46836 bsc#1231092).
  - Update
    patches.suse/usbnet-ipheth-do-not-stop-RX-on-failing-RX-callback.patch
    (git-fixes CVE-2024-46861 bsc#1231102).
  - Update
    patches.suse/wifi-ath12k-fix-firmware-crash-due-to-invalid-peer-n.patch
    (stable-fixes CVE-2024-46827 bsc#1231171).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-wait-for-tx-queues-if-firmwar.patch
    (stable-fixes CVE-2024-47672 bsc#1231540).
  - Update
    patches.suse/wifi-iwlwifi-mvm-pause-TCM-when-the-firmware-is-stop.patch
    (stable-fixes CVE-2024-47673 bsc#1231539).
  - Update
    patches.suse/wifi-iwlwifi-mvm-use-IWL_FW_CHECK-for-link-ID-check.patch
    (stable-fixes CVE-2024-46825 bsc#1231170).
  - Update
    patches.suse/wifi-mt76-mt7921-fix-NULL-pointer-access-in-mt7921_i.patch
    (stable-fixes CVE-2024-46860 bsc#1231093).
  - commit 1ed6329
  - sched/smt: Fix unbalance sched_smt_present dec/inc
    (CVE-2024-44958 bsc#1230179).
  - sched/smt: Introduce sched_smt_present_inc/dec() helper
    (CVE-2024-44958 bsc#1230179).
  - commit b09820b
  - crypto: octeontx* - Select CRYPTO_AUTHENC (git-fixes).
  - commit 155c418
  - spi: spi-imx: Fix pm_runtime_set_suspended() with runtime pm
    enabled (git-fixes).
  - spi: s3c64xx: fix timeout counters in flush_fifo (git-fixes).
  - i2c: synquacer: Deal with optional PCLK correctly (git-fixes).
  - media: imx335: Fix reset-gpio handling (git-fixes).
  - i2c: xiic: Try re-initialization on bus busy timeout
    (git-fixes).
  - platform/x86: touchscreen_dmi: add nanote-next quirk
    (stable-fixes).
  - platform/x86: lenovo-ymc: Ignore the 0x0 state (stable-fixes).
  - hwmon: (nct6775) add G15CF to ASUS WMI monitoring list
    (stable-fixes).
  - power: reset: brcmstb: Do not go into infinite loop if reset
    fails (stable-fixes).
  - wifi: ath9k_htc: Use __skb_set_length() for resetting urb
    before resubmit (stable-fixes).
  - wifi: mt76: mt7915: hold dev->mt76.mutex while disabling tx
    worker (stable-fixes).
  - wifi: mt76: mt7915: add dummy HW offload of IEEE 802.11
    fragmentation (stable-fixes).
  - wifi: mt76: mt7915: disable tx worker during tx BA session
    enable/disable (stable-fixes).
  - wifi: rtw89: avoid reading out of bounds when loading TX power
    FW elements (stable-fixes).
  - wifi: rtw89: correct base HT rate mask for firmware
    (stable-fixes).
  - wifi: mwifiex: Fix memcpy() field-spanning write warning in
    mwifiex_cmd_802_11_scan_ext() (stable-fixes).
  - wifi: cfg80211: Set correct chandef when starting CAC
    (stable-fixes).
  - wifi: mac80211: fix RCU list iterations (stable-fixes).
  - wifi: iwlwifi: mvm: avoid NULL pointer dereference
    (stable-fixes).
  - wifi: iwlwifi: allow only CN mcc from WRDD (stable-fixes).
  - wifi: iwlwifi: mvm: drop wrong STA selection in TX
    (stable-fixes).
  - wifi: iwlwifi: mvm: Fix a race in scan abort flow
    (stable-fixes).
  - wifi: iwlwifi: mvm: use correct key iteration (stable-fixes).
  - wifi: ath9k: fix possible integer overflow in
    ath9k_get_et_stats() (stable-fixes).
  - wifi: ath11k: fix array out-of-bound access in SoC stats
    (stable-fixes).
  - wifi: ath12k: fix array out-of-bound access in SoC stats
    (stable-fixes).
  - wifi: rtw89: avoid to add interface to list twice when SER
    (stable-fixes).
  - wifi: rtw88: select WANT_DEV_COREDUMP (stable-fixes).
  - i2c: xiic: improve error message when transfer fails to start
    (stable-fixes).
  - i2c: synquacer: Remove a clk reference from struct synquacer_i2c
    (stable-fixes).
  - media: i2c: imx335: Enable regulator supplies (stable-fixes).
  - commit 490fb1f
  - ALSA: usb-audio: Replace complex quirk lines with macros
    (stable-fixes).
  - commit 6f67136
  - Bluetooth: RFCOMM: FIX possible deadlock in
    rfcomm_sk_state_change (git-fixes).
  - ACPI: battery: Fix possible crash when unregistering a battery
    hook (git-fixes).
  - ACPI: battery: Simplify battery hook locking (stable-fixes).
  - ACPI: resource: Add Asus ExpertBook B2502CVA to
    irq1_level_low_skip_override[] (stable-fixes).
  - ACPI: resource: Add Asus Vivobook X1704VAP to
    irq1_level_low_skip_override[] (stable-fixes).
  - HID: Ignore battery for all ELAN I2C-HID devices (stable-fixes).
  - HID: multitouch: Add support for Thinkpad X12 Gen 2 Kbd
    Portfolio (stable-fixes).
  - ASoC: codecs: wsa883x: Handle reading version failure
    (stable-fixes).
  - ALSA: usb-audio: Add logitech Audio profile quirk
    (stable-fixes).
  - ALSA: usb-audio: Define macros for quirk table entries
    (stable-fixes).
  - ALSA: hdsp: Break infinite MIDI input flush loop (stable-fixes).
  - ALSA: asihpi: Fix potential OOB array access (stable-fixes).
  - ALSA: usb-audio: Add input value sanity checks for standard
    types (stable-fixes).
  - ACPI: PAD: fix crash in exit_round_robin() (stable-fixes).
  - ACPI: video: Add force_vendor quirk for Panasonic Toughbook
    CF-18 (stable-fixes).
  - ACPI: CPPC: Add support for setting EPP register in FFH
    (stable-fixes).
  - ACPI: EC: Do not release locks during operation region accesses
    (stable-fixes).
  - ACPICA: iasl: handle empty connection_node (stable-fixes).
  - ACPICA: Fix memory leak if acpi_ps_get_next_field() fails
    (stable-fixes).
  - ACPICA: Fix memory leak if acpi_ps_get_next_namepath() fails
    (stable-fixes).
  - ACPICA: check null return of ACPI_ALLOCATE_ZEROED() in
    acpi_db_convert_to_package() (stable-fixes).
  - crypto: octeontx2 - Fix authenc setkey (stable-fixes).
  - crypto: octeontx - Fix authenc setkey (stable-fixes).
  - Bluetooth: btusb: Add Realtek RTL8852C support ID 0x0489:0xe122
    (stable-fixes).
  - can: netlink: avoid call to do_set_data_bittiming callback
    with stale can_priv::ctrlmode (stable-fixes).
  - commit 650f32e
  - ocfs2: fix the la space leak when unmounting an ocfs2 volume
    (git-fixes).
  - commit 92d1b30
  - jfs: Fix uninit-value access of new_ea in ea_buffer (git-fixes).
  - commit b1e0ef1
  - jfs: check if leafidx greater than num leaves per dmap tree
    (git-fixes).
  - commit 4cb79e7
  - jfs: Fix uaf in dbFreeBits (git-fixes).
  - commit da4aab1
  - jfs: UBSAN: shift-out-of-bounds in dbFindBits (git-fixes).
  - commit fee8a70
  - kABI: bpf: enum bpf_{type_flag,arg_type} kABI workaround (git-fixes).
  - commit 93e6047

++++ snapper:

  - generate dsc file for Ubuntu 24.10

++++ open-vm-tools:

  - convert to obs_scm
  - update to 12.5.0 (boo#1231826):
    There are no new features in the open-vm-tools 12.5.0 release.
    This is primarily a maintenance release that addresses a few
    critical problems, including:
    * A Github pull request has been integrated. Please see the
    Resolved Issues section of the Release Notes.
    * For a more complete list of issues resolved in this release,
    see the Resolved Issues section of the Release Notes.
    For complete details, see:
    https://github.com/vmware/open-vm-tools/releases/tag/stable-12.5.0
    Release Notes are available at:
    https://github.com/vmware/open-vm-tools/blob/stable-12.5.0/ReleaseNotes.md
    The granular changes that have gone into the 12.5.0 release are
    in the ChangeLog at:
    https://github.com/vmware/open-vm-tools/blob/stable-12.5.0/open-vm-tools/ChangeLog

++++ openssh:

  - Add a patch to fix a regression introduced in 9.6 that makes X11
    forwarding very slow. Submitted to upstream in
    https://bugzilla.mindrot.org/show_bug.cgi?id=3655#c4 . Fixes
    bsc#1229449:
    * fix-x11-regression-bsc1229449.patch
  - Remove empty line at the end of sshd-sle.pamd (bsc#1227456)

++++ python-legacy-cgi:

  - Initial release of 2.6.1.

++++ python-passlib:

  - Add patch no-crypt-with-python-313.patch:
    * Do not run tests requiring 'crypt' with Python 3.13.

------------------------------------------------------------------
------------------  2024-10-10  -  Oct 10 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - iommu/amd: Allocate the page table root using GFP_KERNEL
    (git-fixes).
  - commit cdbbb3f
  - iommu/amd: Fix typo of , instead of ; (git-fixes).
  - commit baf85d0
  - block: sed-opal: add ioctl IOC_OPAL_SET_SID_PW (bsc#1229677).
  - commit 5ca02dc
  - nvme-multipath: suppress partition scan until the disk is ready
    (bsc#1228244).
  - commit 5accc60

++++ kernel-firmware-all:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-amdgpu:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-ath10k:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-ath11k:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-ath12k:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-atheros:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-bluetooth:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-bnx2:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-brcm:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-chelsio:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-dpaa2:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-i915:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-intel:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-iwlwifi:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-liquidio:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-marvell:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-media:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-mediatek:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-mellanox:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-mwifiex:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-network:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-nfp:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-nvidia:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-platform:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-prestera:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-qcom:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-qlogic:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-radeon:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-realtek:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-serial:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-sound:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-ti:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-ueagle:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-firmware-usb-network:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

++++ kernel-rt:

  - iommu/amd: Allocate the page table root using GFP_KERNEL
    (git-fixes).
  - commit cdbbb3f
  - iommu/amd: Fix typo of , instead of ; (git-fixes).
  - commit baf85d0
  - block: sed-opal: add ioctl IOC_OPAL_SET_SID_PW (bsc#1229677).
  - commit 5ca02dc
  - nvme-multipath: suppress partition scan until the disk is ready
    (bsc#1228244).
  - commit 5accc60

++++ rdma-core:

  - Update to rdma-core v54.0
  - No release notes available

++++ libguestfs:

  - Update to version 1.54.0 (jsc#PED-8910)
    * Add detection of Circle Linux (Bella Zhang).
    * Add support for LoongArch (liuxiang).
    * Add detection of Kylin (grass-lu).
    * Add detection of openEuler (Wang Guoquan).
    * PARTUUID and PARTLABEL are now resolved in guest /etc/fstab.
    * New APIs findfs_partuuid and findfs_partlabel. These can be
    used to efficiently look up a filesystem by its GPT partition
    UUID or label.
    * Support for the following inactive or infrequently used device
    types has been removed: Gluster, Sheepdog, TFTP.
    * Add GOST R34.11-94 message digest algorithm to checksum APIs
    (Alexey Shabalin).
    * Allow nbd+unix:// URIs (NBD over Unix domain socket) in
    guestfish and other places.
    * Various part_* (partition) APIs related to GPT have been
    reimplemented to use util-linux sfdisk instead of sgdisk.
    Util-linux is more widely available, so this reduces
    dependencies in the common case. One optional API remains that
    still uses sgdisk. (Thanks Yongkui Guo).
    * Add cipher suboption to cryptsetup_open (Jonatan Pålsson).
    * Because of a bug, the part_get_gpt_attributes API could
    truncate the return value from 64 to 32 bits. This has been
    fixed.
    * Libguestfs will now no longer recommend using
    LIBGUESTFS_BACKEND=direct. This was shown previously when
    libvirt failed to start the appliance. However it is felt that
    this now does more harm than good.
    * Fix generation of virt-customize --chown parameter (Yongkui Guo)
    * In the appliance, reduce boot time when dhcp isn't needed
    (Olaf Hering).
    * A deadlock in the appliance caused by a regression in Linux
    6.11 has been worked around. The deadlock was also fixed in
    Linux 6.12.
  - Bug fixes
    * Fix rare hangs while starting the appliance, at 'echo noop'
    into /sys/block/{h,s,ub,v}d*/queue/scheduler
    * Drop dependency from libguestfs -> gdisk
    * libguestfs inspection does not know about /etc/fstab
    PARTLABEL=<label>
    * btrfs related c_api/tests are failing (unable to create quota
    group: Invalid argument)
    * Python how-to incorrect exception name
    * Rust test 410_close_event fails

++++ ndctl:

  - Update to version 80
    * cxl-list: add --media-errors option
    * cxl-list: always emit memdev firmware revision
    * daxctl: fail create-device with extra parameters
    * daxctl: remove unused options from create-device usage message
  - cxl-json-Fix-tracefs-include.patch

++++ numactl:

  - Update to version 2.0.18.10.g6c14bd5:
    * Save and restore errno when probing for SET_PREFERRED_MANY
    * libnuma: fix nodemask allocation size for get_mempolicy
    * Update numactl.c
    * numastat: eliminate hard-coded tables
    * Don't fail build when set_mempolicy_home_node syscall is unknown
    * numactl: Add documentation for weighted interleave
    * numactl: Fix RESOURCE_LEAK in show()
    * numademo: Fix the using of the uninitialized value
    * Add `-w` and `--weighted-interleave` for weighted interleave mode
    * Fix fallback for set_mempolicy_home_node syscall

++++ python313-core:

  - Add warning about no-GIL builds being experimental.

++++ python313:

  - Add warning about no-GIL builds being experimental.

++++ ucode-amd:

  - Update to version 20241010 (git commit d4e688aa74a0):
    * rtlwifi: Add firmware v39.0 for RTL8192DU
    * Revert "ath12k: WCN7850 hw2.0: update board-2.bin"
    (replaced with a newer firmware in this package instead)
  - update aliases

------------------------------------------------------------------
------------------  2024-10-9  -  Oct 9 2024  -------------------
------------------------------------------------------------------

++++ cockpit:

  - suse_docs.patch: update documentation to point at new links (bsc#1226050)
  - remove_rh_links.patch: remove additional hardcoded RH refs (bsc#1221336)
  - hide-pcp.patch: correct patch to properly disable pcp on micro
    (bsc#1226049)
  - suse-microos-branding.patch: use suse ID as branding instead of sle-micro
    (bsc#1227441)

++++ git:

  - update to 2.47.0:
    * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.47.0.txt
    * Many Porcelain commands that internally use the merge machinery
    were taught to consistently honor the diff.algorithm
    configuration.
    * A few descriptions in "git show-ref -h" have been clarified.
    * A 'P' command to "git add -p" that passes the patch hunk to the
    pager has been added.
    * "git grep -W" omits blank lines that follow the found function at
    the end of the file, just like it omits blank lines before the next
    function.
    * The value of http.proxy can have "path" at the end for a socks
    proxy that listens to a unix-domain socket, but we started to
    discard it when we taught proxy auth code path to use the
    credential helpers, which has been corrected.
    * The code paths to compact multiple reftable files have been updated
    to correctly deal with multiple compaction triggering at the same
    time.
    * Support to specify ref backend for submodules has been enhanced.
    * "git svn" has been taught about svn:global-ignores property
    recent versions of Subversion has.
    * The default object hash and ref backend format used to be settable
    only with explicit command line option to "git init" and
    environment variables, but now they can be configured in the user's
    global and system wide configuration.
    * "git send-email" learned "--translate-aliases" option that reads
    addresses from the standard input and emits the result of applying
    aliases on them to the standard output.
    * 'git for-each-ref' learned a new "--format" atom to find the branch
    that the history leading to a given commit "%(is-base:<commit>)" is
    likely based on.
    * The command line prompt support used to be littered with bash-isms,
    which has been corrected to work with more shells.
    * Support for the RUNTIME_PREFIX feature has been added to z/OS port.
    * "git send-email" learned "--mailmap" option to allow rewriting the
    recipient addresses.
    * "git mergetool" learned to use VSCode as a merge backend.
    * "git pack-redundant" has been marked for removal in Git 3.0.
    * One-line messages to "die" and other helper functions will get LF
    added by these helper functions, but many existing messages had an
    unnecessary LF at the end, which have been corrected.
    * The "scalar clone" command learned the "--no-tags" option.
    * The environment GIT_ADVICE has been intentionally kept undocumented
    to discourage its use by interactive users.  Add documentation to
    help tool writers.
    * "git apply --3way" learned to take "--ours" and other options.

++++ glibc:

  - Apply libc_nonshared.a workaround also on s390x and ppc64le (bsc#1231051)

++++ kernel-default:

  - fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
    (CVE-2024-45025 bsc#1230456).
  - commit c3824ef
  - i2c: core: Setup i2c_adapter runtime-pm before calling
    device_add() (git-fixes).
  - commit 5095dfb
  - i2c: ismt: kill transaction in hardware on timeout (git-fixes).
  - commit f6029bb
  - iommufd: Check the domain owner of the parent before creating
    a nesting domain (git-fixes).
  - commit 3ff7340
  - iommufd: Protect against overflow of ALIGN() during iova
    allocation (git-fixes).
  - commit fffeb67
  - iommu/amd: Do not set the D bit on AMD v2 table entries
    (git-fixes).
  - commit e3053a9
  - i2c: omap: wakeup the controller during suspend() callback
    (git-fixes).
  - commit 52f3dad
  - i2c: omap: switch to NOIRQ_SYSTEM_SLEEP_PM_OPS() and
    RUNTIME_PM_OPS() (git-fixes).
  - commit 3fe2f94
  - Drop the previous HD-audio TAS2781 fix (bsc#1230132)
    The proposed fix turned out to be incorrect
  - commit b3a4c29
  - Update config files: Enable NFSD_V2 (bsc#1230914)
    NFSv2 was disabled because of the upstream kernel commit 2f3a4b2ac2f2
    ("nfsd: allow disabling NFSv2 at compile time").
    Enable it for the few users who cannot upgrade to NFSv3.
    https://bugzilla.suse.com/show_bug.cgi?id=1230914#c5
  - commit 9e3254d
  - i2c: stm32f7: perform most of irq job in threaded handler
    (git-fixes).
  - commit 4a35980
  - i2c: i801: Add lis3lv02d for Dell XPS 15 7590 (git-fixes).
  - commit 38f58af
  - i2c: i801: Add lis3lv02d for Dell Precision 3540 (git-fixes).
  - commit 036aff9
  - i2c: cpm: Remove linux,i2c-index conversion from be32
    (git-fixes).
  - commit 5d04b4e
  - i2c: ocores: Move system PM hooks to the NOIRQ phase
    (git-fixes).
  - commit 0df7a53
  - i2c: ocores: Remove #ifdef guards for PM related functions
    (git-fixes).
  - commit ead06ad
  - wifi: iwlwifi: config: label 'gl' devices as discrete
    (git-fixes).
  - commit 6321867
  - kconfig: qconf: fix buffer overflow in debug links (git-fixes).
  - platform/x86: ISST: Fix the KASAN report slab-out-of-bounds bug
    (git-fixes).
  - i2c: stm32f7: Do not prepare/unprepare clock during runtime
    suspend/resume (git-fixes).
  - gpio: davinci: fix lazy disable (git-fixes).
  - drm/i915/gem: fix bitwise and logical AND mixup (git-fixes).
  - drm/sched: Always wake up correct scheduler in
    drm_sched_entity_push_job (git-fixes).
  - drm/sched: Add locking to drm_sched_entity_modify_sched
    (git-fixes).
  - drm: Consistently use struct drm_mode_rect for FB_DAMAGE_CLIPS
    (git-fixes).
  - Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE
    (git-fixes).
  - Bluetooth: btmrvl: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - ieee802154: Fix build error (git-fixes).
  - Input: adp5589-keys - fix adp5589_gpio_get_value() (git-fixes).
  - Input: adp5589-keys - fix NULL pointer dereference (git-fixes).
  - drm/amdgpu/vcn: enable AV1 on both instances (stable-fixes).
  - drm/amd/display: Validate backlight caps are sane
    (stable-fixes).
  - drm/amd/display: Skip to enable dsc if it has been off
    (stable-fixes).
  - drm/amd/display: Add HDMI DSC native YCbCr422 support
    (stable-fixes).
  - drm/amd/display: Clean up dsc blocks in accelerated mode
    (stable-fixes).
  - drm/amd/display: Round calculated vtotal (stable-fixes).
  - efistub/tpm: Use ACPI reclaim memory for event log to avoid
    corruption (stable-fixes).
  - iio: magnetometer: ak8975: drop incorrect AK09116 compatible
    (git-fixes).
  - Input: i8042 - add TUXEDO Stellaris 15 Slim Gen6 AMD to i8042
    quirk table (stable-fixes).
  - Input: i8042 - add another board name for TUXEDO Stellaris
    Gen5 AMD line (stable-fixes).
  - Input: i8042 - add TUXEDO Stellaris 16 Gen5 AMD to i8042 quirk
    table (stable-fixes).
  - hwmon: (max16065) Fix alarm attributes (git-fixes).
  - ACPI: resource: Add another DMI match for the TongFang GMxXGxx
    (stable-fixes).
  - wifi: rtw88: 8821cu: Remove VID/PID 0bda:c82c (stable-fixes).
  - ASoC: tas2781: Use of_property_read_reg() (stable-fixes).
  - wifi: iwlwifi: remove AX101, AX201 and AX203 support from LNL
    (stable-fixes).
  - hwmon: (max16065) Remove use of i2c_match_id() (stable-fixes).
  - nouveau/gsp: Avoid addressing beyond end of rpc->entries
    (stable-fixes).
  - thunderbolt: Improve DisplayPort tunnel setup process to be
    more robust (stable-fixes).
  - iio: magnetometer: ak8975: Fix 'Unexpected device' error
    (git-fixes).
  - iio: magnetometer: ak8975: Convert enum->pointer for data in
    the match tables (stable-fixes).
  - commit 85984c8
  - i2c: core: fix lockdep warning for sparsely nested adapter chain
    (git-fixes).
  - commit 691570d
  - i2c: exynos5: Calculate t_scl_l, t_scl_h according to i2c spec
    (git-fixes).
  - commit cbbb120
  - i2c: i801: add helper i801_restore_regs (git-fixes).
  - commit 3839f86
  - i2c: rcar: properly format a debug output (git-fixes).
  - commit e7085c8
  - selftests/bpf: Add a test case to write mtu result into .rodata
    (git-fixes).
  - selftests/bpf: Add a test case to write strtol result into
    .rodata (git-fixes).
  - commit 805bbba
  - selftests/bpf: Rename ARG_PTR_TO_LONG test description
    (git-fixes).
  - selftests/bpf: Fix ARG_PTR_TO_LONG {half-,}uninitialized test
    (git-fixes).
  - bpf: Zero former ARG_PTR_TO_{LONG,INT} args in case of error
    (git-fixes).
  - bpf: Improve check_raw_mode_ok test for MEM_UNINIT-tagged types
    (git-fixes).
  - commit 4580630
  - bpf: Fix helper writes to read-only maps (git-fixes).
  - bpf: Remove truncation test in bpf_strtol and bpf_strtoul
    helpers (git-fixes).
  - bpf: Fix bpf_strtol and bpf_strtoul helpers for 32bit
    (git-fixes).
  - commit 5fc2ffd
  - bpf: Remove tst_run from lwt_seg6local_prog_ops (bsc#1230801
    CVE-2024-46754).
  - commit a7335b8
  - bpf: Fix error message on kfunc arg type mismatch (git-fixes).
  - commit 04ed437
  - selftests/bpf: test for malformed BPF_CORE_TYPE_ID_LOCAL
    relocation (git-fixes).
  - bpf: correctly handle malformed BPF_CORE_TYPE_ID_LOCAL relos
    (git-fixes).
  - commit 67ebe66
  - selftests/bpf: Add tests for ldsx of pkt data/data_end/data_meta
    accesses (git-fixes).
  - bpf: Fail verification for sign-extension of packet
    data/data_end/data_meta (git-fixes).
  - bpf, lsm: Add disabled BPF LSM hook list (git-fixes).
  - commit df1486e
  - bpf, net: Fix a potential race in do_sock_getsockopt()
    (git-fixes).
  - bpf: Fix tailcall cases in test_bpf (git-fixes).
  - bpf, x64: Remove tail call detection (git-fixes).
  - bpf, verifier: Correct tail_call_reachable for bpf prog
    (git-fixes).
  - commit e072387

++++ kernel-rt:

  - fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
    (CVE-2024-45025 bsc#1230456).
  - commit c3824ef
  - i2c: core: Setup i2c_adapter runtime-pm before calling
    device_add() (git-fixes).
  - commit 5095dfb
  - i2c: ismt: kill transaction in hardware on timeout (git-fixes).
  - commit f6029bb
  - iommufd: Check the domain owner of the parent before creating
    a nesting domain (git-fixes).
  - commit 3ff7340
  - iommufd: Protect against overflow of ALIGN() during iova
    allocation (git-fixes).
  - commit fffeb67
  - iommu/amd: Do not set the D bit on AMD v2 table entries
    (git-fixes).
  - commit e3053a9
  - i2c: omap: wakeup the controller during suspend() callback
    (git-fixes).
  - commit 52f3dad
  - i2c: omap: switch to NOIRQ_SYSTEM_SLEEP_PM_OPS() and
    RUNTIME_PM_OPS() (git-fixes).
  - commit 3fe2f94
  - Drop the previous HD-audio TAS2781 fix (bsc#1230132)
    The proposed fix turned out to be incorrect
  - commit b3a4c29
  - Update config files: Enable NFSD_V2 (bsc#1230914)
    NFSv2 was disabled because of the upstream kernel commit 2f3a4b2ac2f2
    ("nfsd: allow disabling NFSv2 at compile time").
    Enable it for the few users who cannot upgrade to NFSv3.
    https://bugzilla.suse.com/show_bug.cgi?id=1230914#c5
  - commit 9e3254d
  - i2c: stm32f7: perform most of irq job in threaded handler
    (git-fixes).
  - commit 4a35980
  - i2c: i801: Add lis3lv02d for Dell XPS 15 7590 (git-fixes).
  - commit 38f58af
  - i2c: i801: Add lis3lv02d for Dell Precision 3540 (git-fixes).
  - commit 036aff9
  - i2c: cpm: Remove linux,i2c-index conversion from be32
    (git-fixes).
  - commit 5d04b4e
  - i2c: ocores: Move system PM hooks to the NOIRQ phase
    (git-fixes).
  - commit 0df7a53
  - i2c: ocores: Remove #ifdef guards for PM related functions
    (git-fixes).
  - commit ead06ad
  - wifi: iwlwifi: config: label 'gl' devices as discrete
    (git-fixes).
  - commit 6321867
  - kconfig: qconf: fix buffer overflow in debug links (git-fixes).
  - platform/x86: ISST: Fix the KASAN report slab-out-of-bounds bug
    (git-fixes).
  - i2c: stm32f7: Do not prepare/unprepare clock during runtime
    suspend/resume (git-fixes).
  - gpio: davinci: fix lazy disable (git-fixes).
  - drm/i915/gem: fix bitwise and logical AND mixup (git-fixes).
  - drm/sched: Always wake up correct scheduler in
    drm_sched_entity_push_job (git-fixes).
  - drm/sched: Add locking to drm_sched_entity_modify_sched
    (git-fixes).
  - drm: Consistently use struct drm_mode_rect for FB_DAMAGE_CLIPS
    (git-fixes).
  - Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE
    (git-fixes).
  - Bluetooth: btmrvl: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - ieee802154: Fix build error (git-fixes).
  - Input: adp5589-keys - fix adp5589_gpio_get_value() (git-fixes).
  - Input: adp5589-keys - fix NULL pointer dereference (git-fixes).
  - drm/amdgpu/vcn: enable AV1 on both instances (stable-fixes).
  - drm/amd/display: Validate backlight caps are sane
    (stable-fixes).
  - drm/amd/display: Skip to enable dsc if it has been off
    (stable-fixes).
  - drm/amd/display: Add HDMI DSC native YCbCr422 support
    (stable-fixes).
  - drm/amd/display: Clean up dsc blocks in accelerated mode
    (stable-fixes).
  - drm/amd/display: Round calculated vtotal (stable-fixes).
  - efistub/tpm: Use ACPI reclaim memory for event log to avoid
    corruption (stable-fixes).
  - iio: magnetometer: ak8975: drop incorrect AK09116 compatible
    (git-fixes).
  - Input: i8042 - add TUXEDO Stellaris 15 Slim Gen6 AMD to i8042
    quirk table (stable-fixes).
  - Input: i8042 - add another board name for TUXEDO Stellaris
    Gen5 AMD line (stable-fixes).
  - Input: i8042 - add TUXEDO Stellaris 16 Gen5 AMD to i8042 quirk
    table (stable-fixes).
  - hwmon: (max16065) Fix alarm attributes (git-fixes).
  - ACPI: resource: Add another DMI match for the TongFang GMxXGxx
    (stable-fixes).
  - wifi: rtw88: 8821cu: Remove VID/PID 0bda:c82c (stable-fixes).
  - ASoC: tas2781: Use of_property_read_reg() (stable-fixes).
  - wifi: iwlwifi: remove AX101, AX201 and AX203 support from LNL
    (stable-fixes).
  - hwmon: (max16065) Remove use of i2c_match_id() (stable-fixes).
  - nouveau/gsp: Avoid addressing beyond end of rpc->entries
    (stable-fixes).
  - thunderbolt: Improve DisplayPort tunnel setup process to be
    more robust (stable-fixes).
  - iio: magnetometer: ak8975: Fix 'Unexpected device' error
    (git-fixes).
  - iio: magnetometer: ak8975: Convert enum->pointer for data in
    the match tables (stable-fixes).
  - commit 85984c8
  - i2c: core: fix lockdep warning for sparsely nested adapter chain
    (git-fixes).
  - commit 691570d
  - i2c: exynos5: Calculate t_scl_l, t_scl_h according to i2c spec
    (git-fixes).
  - commit cbbb120
  - i2c: i801: add helper i801_restore_regs (git-fixes).
  - commit 3839f86
  - i2c: rcar: properly format a debug output (git-fixes).
  - commit e7085c8
  - selftests/bpf: Add a test case to write mtu result into .rodata
    (git-fixes).
  - selftests/bpf: Add a test case to write strtol result into
    .rodata (git-fixes).
  - commit 805bbba
  - selftests/bpf: Rename ARG_PTR_TO_LONG test description
    (git-fixes).
  - selftests/bpf: Fix ARG_PTR_TO_LONG {half-,}uninitialized test
    (git-fixes).
  - bpf: Zero former ARG_PTR_TO_{LONG,INT} args in case of error
    (git-fixes).
  - bpf: Improve check_raw_mode_ok test for MEM_UNINIT-tagged types
    (git-fixes).
  - commit 4580630
  - bpf: Fix helper writes to read-only maps (git-fixes).
  - bpf: Remove truncation test in bpf_strtol and bpf_strtoul
    helpers (git-fixes).
  - bpf: Fix bpf_strtol and bpf_strtoul helpers for 32bit
    (git-fixes).
  - commit 5fc2ffd
  - bpf: Remove tst_run from lwt_seg6local_prog_ops (bsc#1230801
    CVE-2024-46754).
  - commit a7335b8
  - bpf: Fix error message on kfunc arg type mismatch (git-fixes).
  - commit 04ed437
  - selftests/bpf: test for malformed BPF_CORE_TYPE_ID_LOCAL
    relocation (git-fixes).
  - bpf: correctly handle malformed BPF_CORE_TYPE_ID_LOCAL relos
    (git-fixes).
  - commit 67ebe66
  - selftests/bpf: Add tests for ldsx of pkt data/data_end/data_meta
    accesses (git-fixes).
  - bpf: Fail verification for sign-extension of packet
    data/data_end/data_meta (git-fixes).
  - bpf, lsm: Add disabled BPF LSM hook list (git-fixes).
  - commit df1486e
  - bpf, net: Fix a potential race in do_sock_getsockopt()
    (git-fixes).
  - bpf: Fix tailcall cases in test_bpf (git-fixes).
  - bpf, x64: Remove tail call detection (git-fixes).
  - bpf, verifier: Correct tail_call_reachable for bpf prog
    (git-fixes).
  - commit e072387

++++ libzypp:

  - PluginFrame: Send unescaped colons in header values
    (bsc#1231043)
    According to the STOMP protocol it would be correct to escape a
    colon in a header-value, but it breaks plugin receivers which do
    not expect this. The first colon separates header-name from
    header-value, so escaping in the header-value is not needed
    anyway.
    Escaping in the header-value affects especially the urlresolver
    plugins. The input URL is passed in a header, but sent back as
    raw data in the frames body. If the plugin receiver does not
    correctly unescape the URL we may get back a "https\c//" which is
    not usable.
  - Do not ignore return value of std::remove_if in MediaSyncFacade
    (fixes #579)
  - Fix hang in curl code with no network connection (bsc#1230912)
  - version 17.35.12 (35)

++++ python-certifi:

  - update to 2024.8.30:
    added certs:
    * TWCA CYBER Root CA O=TAIWAN-CA OU=Root CA
    * SecureSign Root CA12 O=Cybertrust Japan Co., Ltd.
    * SecureSign Root CA14 O=Cybertrust Japan Co., Ltd.
    * SecureSign Root CA15 O=Cybertrust Japan Co., Ltd.

++++ python-cffi:

  - update to 1.17.1:
    * Fix failing distutils.msvc9compiler imports under Windows (#118).
    * ffibuilder.emit_python_code() and ffibuiler.emit_c_code()
    accept file-like objects (#115).
    * ffiplatform calls are bypassed by ffibuilder.emit_python_code()
    and ffibuilder.emit_c_code() (#81).

++++ ovmf:

  - Add ovmf-MdePkg-DebugLib-Enable-FILE-NAME-as-DEBUG-ASSERT-for.patch
    '5c8bdb190f6d MdePkg DebugLib: Enable FILE NAME as DEBUG ASSERT for GCC12'
    (bsc#1230425)
  - Using gcc12 for building x86_64 ovmf image:
    As the item 'Changed the approach for creating the edk2 source code tarball'
    in 'Update to edk2-stable202405' change log. We modified the folder name in
    edk2-edk2-stable%{version}.tar.gz source code tarball to avoid the size
    problem against FD_SIZE_2MB config. (bsc#1230425)
    We can use gcc-12 to avoid the size problem because gcc-12 supported
    __FILE_NAME__ macro for reproducing the size of firmware image. So we
    applied the above 5c8bdb190f6d patch and aldo the following SLE15-SP7/
    Leap 15.7 specific patch for setting the gcc-12 as the default compiler
    for x86_64 ovmf:
  - ovmf-BaseTools-Using-gcc12-for-building-image.patch
    'BaseTools: Using gcc12 for building x86_64 ovmf image'
  - This patch only be applied to x86_64 image when building on SUSE
    15.5/15.6/15.7 codebases. Here is the pseudocode in ovmf.spec:
    ifarch x86_64
    if sle_version >= 150500 && sle_version <= 150700
    Patch13 ovmf-BaseTools-Using-gcc12-for-building-image.patch
    endif
    endif
    The main target is SLE15-SP7 and Leap 15.7. The SUSE 15.5/15.6 is
    for building in Virtualization development project on OBS:
  - Changed the edk2-edk2-stable202405.tar.gz back to the tarball which directly
    downloading from https://github.com/tianocore/edk2.
    Because we moved to gcc-12 for reducing the size of firmware image.
  - Against this change, we modified the setup command in %prep section in
    ovmf.spec back to original statement:
    new: %setup -q -n edk2-edk2-stable%{version}
    old: %setup -q -n edk2

------------------------------------------------------------------
------------------  2024-10-8  -  Oct 8 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - add bug reference for a mana change (bsc#1229769).
  - commit 64c619e
  - net/sched: taprio: extend minimum interval restriction to entire cycle too (CVE-2024-36244 bsc#1226797)
  - commit 5ade9d6
  - arm64: fix selection of HAVE_DYNAMIC_FTRACE_WITH_ARGS
    (git-fixes).
  - commit 7e90455
  - arm64: errata: Enable the AC03_CPU_38 workaround for ampere1a
    (git-fixes).
  - commit 994f16f
  - aoe: fix the potential use-after-free problem in more places
    (bsc#1218562 CVE-2023-6270).
  - commit 1a991ba
  - ALSA: hda: tas2781: Fix missing setup at runtime PM
    (bsc#1230132).
  - commit 3dc7842
  - Move upstreamed sound patch into sorted section
  - commit b11079c
  - kbuild,bpf: Add module-specific pahole flags for distilled
    base BTF (bsc#1230414 bsc#1229450).
  - kbuild: bpf: Tell pahole to DECL_TAG kfuncs (bsc#1230414
    bsc#1229450).
  - kbuild, bpf: Use test-ge check for v1.25-only pahole
    (bsc#1230414 bsc#1229450).
  - kbuild,bpf: Switch to using --btf_features for pahole v1.26
    and later (bsc#1230414 bsc#1229450).
  - kbuild: avoid too many execution of scripts/pahole-flags.sh
    (bsc#1230414 bsc#1229450).
  - btf, scripts: rust: drop is_rust_module.sh (bsc#1230414
    bsc#1229450).
  - commit e2cacce
  - Use pahole -j1 option for reproducible builds (bsc#1230414
    bsc#1229450).
  - commit 340585e
  - ceph: fix cap ref leak via netfs init_request (bsc#1231384).
  - commit ca24d43
  - vhost/scsi: null-ptr-dereference in vhost_scsi_get_req()
    (git-fixes).
  - commit 267df6b
  - virtio_console: fix misc probe bugs (git-fixes).
  - commit f7d3065
  - RDMA/mana_ib: use the correct page size for mapping user-mode
    doorbell page (git-fixes).
  - RDMA/mana_ib: use the correct page table index based on hardware
    page size (git-fixes).
  - tools: hv: rm .*.cmd when make clean (git-fixes).
  - x86/hyperv: Set X86_FEATURE_TSC_KNOWN_FREQ when Hyper-V provides
    frequency (git-fixes).
  - commit 059fd95
  - KVM: VMX: Set PFERR_GUEST_{FINAL,PAGE}_MASK if and only if
    the GVA is valid (git-fixes).
  - commit bb6f3d3
  - KVM: x86/mmu: Skip emulation on page fault iff 1+ SPs were
    unprotected (git-fixes).
  - commit bcfafe2
  - KVM: x86/mmu: Trigger unprotect logic only on write-protection
    page faults (git-fixes).
  - commit 322cf36

++++ kernel-firmware-all:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-amdgpu:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-ath10k:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-ath11k:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-ath12k:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-atheros:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-bluetooth:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-bnx2:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-brcm:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-chelsio:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-dpaa2:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-i915:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-intel:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-iwlwifi:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-liquidio:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-marvell:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-media:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-mediatek:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-mellanox:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-mwifiex:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-network:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-nfp:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-nvidia:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-platform:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-prestera:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-qcom:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-qlogic:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-radeon:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-realtek:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-serial:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-sound:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-ti:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-ueagle:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-firmware-usb-network:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ kernel-rt:

  - add bug reference for a mana change (bsc#1229769).
  - commit 64c619e
  - net/sched: taprio: extend minimum interval restriction to entire cycle too (CVE-2024-36244 bsc#1226797)
  - commit 5ade9d6
  - arm64: fix selection of HAVE_DYNAMIC_FTRACE_WITH_ARGS
    (git-fixes).
  - commit 7e90455
  - arm64: errata: Enable the AC03_CPU_38 workaround for ampere1a
    (git-fixes).
  - commit 994f16f
  - aoe: fix the potential use-after-free problem in more places
    (bsc#1218562 CVE-2023-6270).
  - commit 1a991ba
  - ALSA: hda: tas2781: Fix missing setup at runtime PM
    (bsc#1230132).
  - commit 3dc7842
  - Move upstreamed sound patch into sorted section
  - commit b11079c
  - kbuild,bpf: Add module-specific pahole flags for distilled
    base BTF (bsc#1230414 bsc#1229450).
  - kbuild: bpf: Tell pahole to DECL_TAG kfuncs (bsc#1230414
    bsc#1229450).
  - kbuild, bpf: Use test-ge check for v1.25-only pahole
    (bsc#1230414 bsc#1229450).
  - kbuild,bpf: Switch to using --btf_features for pahole v1.26
    and later (bsc#1230414 bsc#1229450).
  - kbuild: avoid too many execution of scripts/pahole-flags.sh
    (bsc#1230414 bsc#1229450).
  - btf, scripts: rust: drop is_rust_module.sh (bsc#1230414
    bsc#1229450).
  - commit e2cacce
  - Use pahole -j1 option for reproducible builds (bsc#1230414
    bsc#1229450).
  - commit 340585e
  - ceph: fix cap ref leak via netfs init_request (bsc#1231384).
  - commit ca24d43
  - vhost/scsi: null-ptr-dereference in vhost_scsi_get_req()
    (git-fixes).
  - commit 267df6b
  - virtio_console: fix misc probe bugs (git-fixes).
  - commit f7d3065
  - RDMA/mana_ib: use the correct page size for mapping user-mode
    doorbell page (git-fixes).
  - RDMA/mana_ib: use the correct page table index based on hardware
    page size (git-fixes).
  - tools: hv: rm .*.cmd when make clean (git-fixes).
  - x86/hyperv: Set X86_FEATURE_TSC_KNOWN_FREQ when Hyper-V provides
    frequency (git-fixes).
  - commit 059fd95
  - KVM: VMX: Set PFERR_GUEST_{FINAL,PAGE}_MASK if and only if
    the GVA is valid (git-fixes).
  - commit bb6f3d3
  - KVM: x86/mmu: Skip emulation on page fault iff 1+ SPs were
    unprotected (git-fixes).
  - commit bcfafe2
  - KVM: x86/mmu: Trigger unprotect logic only on write-protection
    page faults (git-fixes).
  - commit 322cf36

++++ spirv-tools:

  - Update to release 2024.4~rc1
    * Add knowledge of cooperative matrices
    * Add FPEncoding operand type
    * Allow for empty list of enums for an operand
    * Support SPV_KHR_untyped_pointers
    * properly handle the load and store cache control operand types
    * spirv-link: allow linking functions with different pointer arguments
    * Allow ArrayStride on untyped pointers
    * [OPT] Add SPV_KHR_ray_tracing_position_fetch to allow lists
    * Validate presence of Stride operand to OpCooperativeMatrix{Load,Store}KHR
    * [SPV_KHR_untyped_pointers] Fix verification of vload/vstore OpenCL.std instructions
    * spirv-opt: make traversal deterministic
    * add support for SPV_INTEL_global_variable_host_access
  - Add 0001-SPV_KHR_untyped_pointers-Fix-verification-for-OpenCL.patch
    for shaderc.

++++ efivar:

  - Adapt efivar-filter-gcc-march.patch to drop -march=native (boo#1231368)

++++ python313-core:

  - Update to 3.13.0:
    Major new features of the 3.13 series, compared to 3.12
    Some of the new major new features and changes in Python 3.13 are:
  - New features
  - A new and improved interactive interpreter, based on
    PyPy's, featuring multi-line editing and color support, as
    well as colorized exception tracebacks.
  - An experimental free-threaded build mode, which disables
    the Global Interpreter Lock, allowing threads to run
    more concurrently. The build mode is available as an
    experimental feature in the Windows and macOS installers as
    well.
  - A preliminary, experimental JIT, providing the ground work
    for significant performance improvements.
  - The locals() builtin function (and its C equivalent)
    now has well-defined semantics when mutating the
    returned mapping, which allows debuggers to operate more
    consistently.
  - A modified version of mimalloc is now included, optional
    but enabled by default if supported by the platform, and
    required for the free-threaded build mode.
  - Docstrings now have their leading indentation stripped,
    reducing memory use and the size of .pyc files. (Most tools
    handling docstrings already strip leading indentation.)
  - The dbm module has a new dbm.sqlite3 backend that is used
    by default when creating new files.
  - WASI is now a Tier 2 supported platform. Emscripten is
    no longer an officially supported platform (but Pyodide
    continues to support Emscripten).
  - Typing
  - Support for type defaults in type parameters.
  - A new type narrowing annotation, typing.TypeIs.
  - A new annotation for read-only items in TypeDicts.
  - A new annotation for marking deprecations in the type
    system.
  - Removals and new deprecations
  - PEP 594 (Removing dead batteries from the standard library)
    scheduled removals of many deprecated modules: aifc,
    audioop, chunk, cgi, cgitb, crypt, imghdr, mailcap, msilib,
    nis, nntplib, ossaudiodev, pipes, sndhdr, spwd, sunau,
    telnetlib, uu, xdrlib, lib2to3.
  - Many other removals of deprecated classes, functions and
    methods in various standard library modules.
  - C API removals and deprecations. (Some removals present
    in alpha 1 were reverted in alpha 2, as the removals were
    deemed too disruptive at this time.)
  - New deprecations, most of which are scheduled for removal
    from Python 3.15 or 3.16.
  - For more details on the changes to Python 3.13, see What's
    new in Python 3.13 in the documentation.

++++ systemd:

  - Import commit c7671762b39ead7f8f9e70064256f5efaccedeca (merge of v256.7)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/8a0ae4d90aff1d067a125ff9366eafc7dd5d4701...c7671762b39ead7f8f9e70064256f5efaccedeca

++++ vulkan-loader:

  - Update to release SDK-1.3.296
    * Use ASM unknown function trampolines on GN
    * Fix vkCreateSharedSwapchainsKHR not unwrapping handles correctly
    * Remove unused VkIcdSurface struct members
    * Add VK_IMPLICIT_LAYER_APTH & VK_ADD_IMPLICIT_LAYER_PATH env-vars
    * Fix windows_read_sorted_physical_devices buffer overrun

++++ python313:

  - Update to 3.13.0:
    Major new features of the 3.13 series, compared to 3.12
    Some of the new major new features and changes in Python 3.13 are:
  - New features
  - A new and improved interactive interpreter, based on
    PyPy's, featuring multi-line editing and color support, as
    well as colorized exception tracebacks.
  - An experimental free-threaded build mode, which disables
    the Global Interpreter Lock, allowing threads to run
    more concurrently. The build mode is available as an
    experimental feature in the Windows and macOS installers as
    well.
  - A preliminary, experimental JIT, providing the ground work
    for significant performance improvements.
  - The locals() builtin function (and its C equivalent)
    now has well-defined semantics when mutating the
    returned mapping, which allows debuggers to operate more
    consistently.
  - A modified version of mimalloc is now included, optional
    but enabled by default if supported by the platform, and
    required for the free-threaded build mode.
  - Docstrings now have their leading indentation stripped,
    reducing memory use and the size of .pyc files. (Most tools
    handling docstrings already strip leading indentation.)
  - The dbm module has a new dbm.sqlite3 backend that is used
    by default when creating new files.
  - WASI is now a Tier 2 supported platform. Emscripten is
    no longer an officially supported platform (but Pyodide
    continues to support Emscripten).
  - Typing
  - Support for type defaults in type parameters.
  - A new type narrowing annotation, typing.TypeIs.
  - A new annotation for read-only items in TypeDicts.
  - A new annotation for marking deprecations in the type
    system.
  - Removals and new deprecations
  - PEP 594 (Removing dead batteries from the standard library)
    scheduled removals of many deprecated modules: aifc,
    audioop, chunk, cgi, cgitb, crypt, imghdr, mailcap, msilib,
    nis, nntplib, ossaudiodev, pipes, sndhdr, spwd, sunau,
    telnetlib, uu, xdrlib, lib2to3.
  - Many other removals of deprecated classes, functions and
    methods in various standard library modules.
  - C API removals and deprecations. (Some removals present
    in alpha 1 were reverted in alpha 2, as the removals were
    deemed too disruptive at this time.)
  - New deprecations, most of which are scheduled for removal
    from Python 3.15 or 3.16.
  - For more details on the changes to Python 3.13, see What's
    new in Python 3.13 in the documentation.

++++ python-dnspython:

  - Skip some tests
    * that require a working resolver and external DNS resolution
    * that require an openssl3 version with support for
    ECDSA with deterministic signature (RFC 6979)"

++++ ucode-amd:

  - Update to version 20241004 (git commit bbb77872a8a7):
    * amdgpu: DMCUB DCN35 update
    * brcm: Add BCM4354 NVRAM for Jetson TX1
    * brcm: Link FriendlyElec NanoPi M4 to AP6356S nvram

++++ virt-manager:

  - bsc#1231400 - Virt-manager is missing support for AMD sev-snp
    virtman-add-sev-memory-support.patch

------------------------------------------------------------------
------------------  2024-10-7  -  Oct 7 2024  -------------------
------------------------------------------------------------------

++++ busybox:

  - Add patch to fix build on non-x86* architectures:
    * busybox-1.37.0-fix-conditional-for-sha1_process_block64_shaNI.patch

++++ dhcpcd:

  - Update to 10.1.0
    * dhcp: get_option_uint32/16 only accept options with correct len
    * Include frame header in buffer length

++++ git:

  - Update to version 2.46.2:
    * Revert the "git patch-id" change that went into 2.46.1,
    as it seems to have got a regression reported (I haven't verified,
    but it is better to keep a known breakage than adding an unintended
    regression).
    * In a few corner cases "git diff --exit-code" failed to report
    "changes" (e.g., renamed without any content change), which has
    been corrected.
    * The interpret-trailers command failed to recognise the end of the
    message when the commit log ends in an incomplete line.

++++ kernel-default:

  - KVM: VMX: Also clear SGX EDECCSSA in KVM CPU caps when SGX is
    disabled (git-fixes).
  - commit d7b7771
  - btrfs: send: fix invalid clone operation for file that got
    its size decreased (git-fixes).
  - commit 26ee3ac
  - KVM: x86: Exit to userspace if fastpath triggers one on
    instruction skip (git-fixes).
  - commit 1621f7b
  - KVM: x86: Dedup fastpath MSR post-handling logic (git-fixes).
  - commit c20ff7c
  - KVM: x86: Re-enter guest if WRMSR(X2APIC_ICR) fastpath is
    successful (git-fixes).
  - commit 0dc4c78
  - kABI fix of VM: x86: Re-split x2APIC ICR into ICR+ICR2 for AMD
    (x2AVIC) (git-fixes).
  - commit 0a6716e
  - KVM: x86: Re-split x2APIC ICR into ICR+ICR2 for AMD (x2AVIC)
    (git-fixes).
  - commit 6a07b23
  - KVM: x86: Move x2APIC ICR helper above kvm_apic_write_nodecode()
    (git-fixes).
  - commit 4f194f7
  - USB: misc: yurex: fix race between read and write (git-fixes).
  - commit 7f6ab55
  - USB: misc: cypress_cy7c63: check for short transfer (git-fixes).
  - commit 3dcfad1
  - USB: appledisplay: close race between probe and completion
    handler (git-fixes).
  - commit 888718f
  - KVM: x86: Enforce x2APIC's must-be-zero reserved ICR bits
    (git-fixes).
  - commit 891c3ef
  - usb: xhci: fix loss of data on Cadence xHC (git-fixes).
  - commit 9e9d585
  - KVM: Write the per-page "segment" when clearing (part of)
    a guest page (git-fixes).
  - commit dae8f10
  - xhci: Add a quirk for writing ERST in high-low order
    (git-fixes).
  - commit d0eccfc
  - drm/amd/display: Validate function returns (bsc#1230774 CVE-2024-46775)
  - commit fc9ad2b
  - KVM: Fix coalesced_mmio_has_room() to avoid premature userspace
    exit (git-fixes).
  - commit 93dbc58
  - KVM: Use dedicated mutex to protect kvm_usage_count to avoid
    deadlock (git-fixes).
  - commit 2ff88a8
  - Delete some more obsolete scripts
  - commit 9bb77f8
  - KVM: SVM: Disallow guest from changing userspace's
    MSR_AMD64_DE_CFG value (git-fixes).
  - commit c8fa16d
  - drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (CVE-2024-46816 bsc#1231197).
  - commit c05e7e2
  - net: test for not too small csum_start in
    virtio_net_hdr_to_skb() (git-fixes).
  - commit ed78dff
  - vhost_vdpa: assign irq bypass producer token correctly
    (git-fixes).
  - commit 1a9cba6
  - drm/amd/display: Check link_index before accessing dc->links (CVE-2024-46813 bsc#1231191).
  - commit eb31596
  - minmax: avoid overly complex min()/max() macro arguments in xen
    (git-fixes).
  - Refresh
    patches.suse/xen-move-max_pfn-in-xen_memory_setup-out-of-function.patch.
  - commit 754808b

++++ kernel-rt:

  - KVM: VMX: Also clear SGX EDECCSSA in KVM CPU caps when SGX is
    disabled (git-fixes).
  - commit d7b7771
  - btrfs: send: fix invalid clone operation for file that got
    its size decreased (git-fixes).
  - commit 26ee3ac
  - KVM: x86: Exit to userspace if fastpath triggers one on
    instruction skip (git-fixes).
  - commit 1621f7b
  - KVM: x86: Dedup fastpath MSR post-handling logic (git-fixes).
  - commit c20ff7c
  - KVM: x86: Re-enter guest if WRMSR(X2APIC_ICR) fastpath is
    successful (git-fixes).
  - commit 0dc4c78
  - kABI fix of VM: x86: Re-split x2APIC ICR into ICR+ICR2 for AMD
    (x2AVIC) (git-fixes).
  - commit 0a6716e
  - KVM: x86: Re-split x2APIC ICR into ICR+ICR2 for AMD (x2AVIC)
    (git-fixes).
  - commit 6a07b23
  - KVM: x86: Move x2APIC ICR helper above kvm_apic_write_nodecode()
    (git-fixes).
  - commit 4f194f7
  - USB: misc: yurex: fix race between read and write (git-fixes).
  - commit 7f6ab55
  - USB: misc: cypress_cy7c63: check for short transfer (git-fixes).
  - commit 3dcfad1
  - USB: appledisplay: close race between probe and completion
    handler (git-fixes).
  - commit 888718f
  - KVM: x86: Enforce x2APIC's must-be-zero reserved ICR bits
    (git-fixes).
  - commit 891c3ef
  - usb: xhci: fix loss of data on Cadence xHC (git-fixes).
  - commit 9e9d585
  - KVM: Write the per-page "segment" when clearing (part of)
    a guest page (git-fixes).
  - commit dae8f10
  - xhci: Add a quirk for writing ERST in high-low order
    (git-fixes).
  - commit d0eccfc
  - drm/amd/display: Validate function returns (bsc#1230774 CVE-2024-46775)
  - commit fc9ad2b
  - KVM: Fix coalesced_mmio_has_room() to avoid premature userspace
    exit (git-fixes).
  - commit 93dbc58
  - KVM: Use dedicated mutex to protect kvm_usage_count to avoid
    deadlock (git-fixes).
  - commit 2ff88a8
  - Delete some more obsolete scripts
  - commit 9bb77f8
  - KVM: SVM: Disallow guest from changing userspace's
    MSR_AMD64_DE_CFG value (git-fixes).
  - commit c8fa16d
  - drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (CVE-2024-46816 bsc#1231197).
  - commit c05e7e2
  - net: test for not too small csum_start in
    virtio_net_hdr_to_skb() (git-fixes).
  - commit ed78dff
  - vhost_vdpa: assign irq bypass producer token correctly
    (git-fixes).
  - commit 1a9cba6
  - drm/amd/display: Check link_index before accessing dc->links (CVE-2024-46813 bsc#1231191).
  - commit eb31596
  - minmax: avoid overly complex min()/max() macro arguments in xen
    (git-fixes).
  - Refresh
    patches.suse/xen-move-max_pfn-in-xen_memory_setup-out-of-function.patch.
  - commit 754808b

++++ xz:

  - Update to 5.6.3:
    * liblzma:
  - Fix x86-64 inline assembly compatibility with GNU Binutils
    older than 2.27.
  - Fix the build with GCC 4.2 on OpenBSD/sparc64.
    * xzdec: Display an error instead of failing silently if the
    unsupported option -M is specified.
    * lzmainfo: Fix integer overflows when rounding the dictionary and
    uncompressed sizes to the nearest mebibyte.
    * Autotools-based build:
  - Fix feature checks with link-time optimization (-flto).
  - Solaris: Fix a compatibility issue in version.sh. It matters
    if one wants to regenerate configure by running autoconf.
    * CMake:
  - Use paths relative to ${prefix} in liblzma.pc when possible.
    This is done only with CMake >= 3.20.
  - Prefer a C11 compiler over a C99 compiler but accept both.
  - Link Threads::Threads against liblzma using PRIVATE so that
  - pthread and such flags won't unnecessarily get included in
    the usage requirements of shared liblzma. That is,
    target_link_libraries(foo PRIVATE liblzma::liblzma) no
    longer adds -pthread if using POSIX threads and linking
    against shared liblzma. The threading flags are still added
    if linking against static liblzma.
    * Updated translations: Catalan, Chinese (simplified), and
    Brazilian Portuguese.

++++ ncurses:

  - Add ncurses patch 20241006
    + fixes for compiler warnings/cppcheck.
    + use xterm+alt+title in wezterm -TD

++++ unbound:

  - Update to 1.21.1:
    Security Fixes:
    * Fix CVE-2024-8508, unbounded name compression could lead to
    denial of service.
    [CVE-2024-8508, bsc#1231284]
  - Update keyring

++++ mcelog:

  - Update to version 200:
    * mcelog: Reduce default threshold for corrected error page offline
    * Revert "mcelog: Reduce default threshold for corrected error page offline"
    * mcelog: Add new model number for Panther Lake
    * server: Correct prameter type for connect() API

++++ microos-tools:

  - Update to version 4.0:
    * Release version 4.0
    * Have the autorelabel hook propagate failure from relabelling
    * Split SELinux relabelling code into separate package
    * Make 98selinux-microos usable on non-transactional systems
    * selinux-autorelabel-generator: Don't hardcode mountpoints
    * Consistently use tabs in selinux-autorelabel-generator
    * Add automated testing of SELinux relabelling functionality
    * Fix OBS workflow for pushes to master

++++ podman:

  - Add patch for CVE-2024-9341 (bsc#1231230):
    * 0001-pkg-subscriptions-use-securejoin-for-the-container-p.patch

++++ python-PyJWT:

  - Fix requirements

++++ os-update:

  - Update to version 1.17+git.20241007:
    * Refresh before dup
    * Always refresh

------------------------------------------------------------------
------------------  2024-10-6  -  Oct 6 2024  -------------------
------------------------------------------------------------------

++++ python-argcomplete:

  - Add argparse-3_12_7.patch which should actually fix
    gh#kislyuk/argcomplete#507.
  - Remove skip-failing-tests-3_12_7.patch, which is now
    unnecessary.

++++ python-dnspython:

  - Update to version 2.7.0
    * dns.query.https() and dns.asyncquery.https() now support
    HTTP/3 and the http_version parameter may be used to specify
    which version to use.
    * If the cryptography module is installed, then dnspython will
    now create deterministic ECDSA signatures by default.
    * The RESINFO and WALLET RdataTypes are now supported.
    * The COOKIE and Report-Channel EDNS0 options are now supported.
    * All supported RdataTypes can now be imported at a single time
    rather than lazily on first use by calling
    dns.rdata.load_all_types().
    * The SVCB and HTTPS records now support the ohttp parameter.
    * xfr() and inbound_xfr() now share a common implementation.
    * Tokens are now supported for QUIC and HTTP/3.
    * dns.message.from_wire() now saves the input wire format in the
    Message’s “wire” attribute. Likewise,
    dns.message.Message.to_wire() now records the generated wire
    format in that attribute.
    * The dns.message.Message object now has a get_options() helper
    to retrieve EDNS0 options of a specified type, and an
    extended_errors() helper to retrieve the list of EDE options
    in a message (if any).
    * dns.message.make_response() now has a copy mode which controls
    how sections are copied. By default, a copy mode appropriate
    for the opcode is used.
    This is currently dns.message.CopyMode.QUESTION for all opcodes
    * If an IP address is used as the hostname in a URL, the https
    query code now passes the sni_hostname to httpx as this is
    required to get httpx to validate the certificate and check for
    an IP subject alternative name.
    * The minimum supported aioquic version is now 1.0.0.
    * The minimum supported Python version is now 3.9.

------------------------------------------------------------------
------------------  2024-10-5  -  Oct 5 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ALSA: hda/conexant: Fix conflicting quirk for System76 Pangolin
    (git-fixes).
  - ALSA: line6: add hw monitor volume control to POD HD500X
    (stable-fixes).
  - ALSA: usb-audio: Add native DSD support for Luxman D-08u
    (stable-fixes).
  - ALSA: core: add isascii() check to card ID generator
    (stable-fixes).
  - ASoC: qcom: sm8250: add qrb4210-rb2-sndcard compatible string
    (stable-fixes).
  - ASoC: imx-card: Set card.owner to avoid a warning calltrace
    if SND=m (git-fixes).
  - ASoC: fsl_sai: Enable 'FIFO continue on error' FCONT bit
    (stable-fixes).
  - ASoC: codecs: lpass-rx-macro: add missing
    CDC_RX_BCL_VBAT_RF_PROC2 to default regs values (stable-fixes).
  - ASoC: atmel: mchp-pdmc: Skip ALSA restoration if substream
    runtime is uninitialized (git-fixes).
  - ASoC: amd: yc: Add quirk for HP Dragonfly pro one
    (stable-fixes).
  - Revert "ALSA: hda: Conditionally use snooping for AMD HDMI"
    (stable-fixes).
  - ALSA: hda/realtek: Add a quirk for HP Pavilion 15z-ec200
    (stable-fixes).
  - ALSA: silence integer wrapping warning (stable-fixes).
  - ALSA: Reorganize kerneldoc parameter names (stable-fixes).
  - ALSA: hda/realtek: Fix the push button function for the ALC257
    (git-fixes).
  - ALSA: hda/conexant: fix some typos (stable-fixes).
  - ALSA: mixer_oss: Remove some incorrect kfree_const() usages
    (git-fixes).
  - ALSA: hda/realtek: Add quirk for Huawei MateBook 13 KLV-WX9
    (stable-fixes).
  - ALSA: usb-audio: Add delay quirk for VIVO USB-C HEADSET
    (stable-fixes).
  - ALSA: hda/tas2781: Add new quirk for Lenovo Y990 Laptop
    (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LED for HP mt645 G8
    (stable-fixes).
  - commit 1cdc743

++++ kernel-rt:

  - ALSA: hda/conexant: Fix conflicting quirk for System76 Pangolin
    (git-fixes).
  - ALSA: line6: add hw monitor volume control to POD HD500X
    (stable-fixes).
  - ALSA: usb-audio: Add native DSD support for Luxman D-08u
    (stable-fixes).
  - ALSA: core: add isascii() check to card ID generator
    (stable-fixes).
  - ASoC: qcom: sm8250: add qrb4210-rb2-sndcard compatible string
    (stable-fixes).
  - ASoC: imx-card: Set card.owner to avoid a warning calltrace
    if SND=m (git-fixes).
  - ASoC: fsl_sai: Enable 'FIFO continue on error' FCONT bit
    (stable-fixes).
  - ASoC: codecs: lpass-rx-macro: add missing
    CDC_RX_BCL_VBAT_RF_PROC2 to default regs values (stable-fixes).
  - ASoC: atmel: mchp-pdmc: Skip ALSA restoration if substream
    runtime is uninitialized (git-fixes).
  - ASoC: amd: yc: Add quirk for HP Dragonfly pro one
    (stable-fixes).
  - Revert "ALSA: hda: Conditionally use snooping for AMD HDMI"
    (stable-fixes).
  - ALSA: hda/realtek: Add a quirk for HP Pavilion 15z-ec200
    (stable-fixes).
  - ALSA: silence integer wrapping warning (stable-fixes).
  - ALSA: Reorganize kerneldoc parameter names (stable-fixes).
  - ALSA: hda/realtek: Fix the push button function for the ALC257
    (git-fixes).
  - ALSA: hda/conexant: fix some typos (stable-fixes).
  - ALSA: mixer_oss: Remove some incorrect kfree_const() usages
    (git-fixes).
  - ALSA: hda/realtek: Add quirk for Huawei MateBook 13 KLV-WX9
    (stable-fixes).
  - ALSA: usb-audio: Add delay quirk for VIVO USB-C HEADSET
    (stable-fixes).
  - ALSA: hda/tas2781: Add new quirk for Lenovo Y990 Laptop
    (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LED for HP mt645 G8
    (stable-fixes).
  - commit 1cdc743

++++ python-argcomplete:

  - Add skip-failing-tests-3_12_7.patch as a temporary workaround,
    skip failing tests (gh#kislyuk/argcomplete#507).

------------------------------------------------------------------
------------------  2024-10-4  -  Oct 4 2024  -------------------
------------------------------------------------------------------

++++ audit-secondary:

  - Update audit.spec (bsc#1231236):
    * add requirement for 'awk' package
    * move some %post logic from audit to audit-rules

++++ busybox:

  - Fix busybox.config again (got broken with 1.37.0 update)
  - Cleanup spec file

++++ busybox-links:

  - Partly revert changes from Aug 8th 2023 to automatically detect
    changes in busybox configuration
  - Add getfattr applet to attr filelist

++++ cpupower:

  - Upstream fixed lib default installation path in 3a5bb5066f4c
    [- cpupower_exclude_kernel_Makefile.patch]

++++ python-kiwi:

  - Bump version: 10.1.13 → 10.1.14
  - Revert "Install usrmerge for Debian integration test"
    This reverts commit 95ac861741f14c4f35611c16328384c18e53dcfb.
    Solution needs to be provided in code
  - Install usrmerge for Debian integration test

++++ grub2:

  - Fix missng menu entry "Start bootloader from a read-only snapshot" by
    ensuring grub2-snapper-plugin is installed when both snapper and grub2-common
    are installed (bsc#1231271)
  - Fix OOM error in loading loopback file (bsc#1230840)
    * 0001-tpm-Skip-loopback-image-measurement.patch
  - Fix UEFI PXE boot failure on tagged VLAN network (bsc#1230263)
    * 0001-efinet-Skip-virtual-VLAN-devices-during-card-enumera.patch

++++ kernel-default:

  - rcu-tasks: Fix show_rcu_tasks_trace_gp_kthread buffer overflow
    (bsc#1226631).
  - commit 36faf07
  - scsi: fnic: Move flush_work initialization out of if block
    (bsc#1230055).
  - commit 9b5b899
  - rcu: Fix buffer overflow in print_cpu_stall_info()
    (bsc#1226623).
  - commit b695829
  - Replace ALP with SLFO
  - Refresh patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch
  - Update config files.
  - commit 267a9d3
  - Update config files.
    Update SUSE_VERSION to match SLFO project version
  - commit 0d531e8
  - config.sh: Remove Arm build project, we do not build armv7 configs
  - commit 359f219
  - config.sh: Update bugzilla product
  - commit 0688dde
  - rpm/release-projects: Add SLFO projects (bsc#1231293).
  - commit 9f2c584

++++ kernel-rt:

  - rcu-tasks: Fix show_rcu_tasks_trace_gp_kthread buffer overflow
    (bsc#1226631).
  - commit 36faf07
  - scsi: fnic: Move flush_work initialization out of if block
    (bsc#1230055).
  - commit 9b5b899
  - rcu: Fix buffer overflow in print_cpu_stall_info()
    (bsc#1226623).
  - commit b695829
  - Replace ALP with SLFO
  - Refresh patches.suse/kernel-add-product-identifying-information-to-kernel-build.patch
  - Update config files.
  - commit 267a9d3
  - Update config files.
    Update SUSE_VERSION to match SLFO project version
  - commit 0d531e8
  - config.sh: Remove Arm build project, we do not build armv7 configs
  - commit 359f219
  - config.sh: Update bugzilla product
  - commit 0688dde
  - rpm/release-projects: Add SLFO projects (bsc#1231293).
  - commit 9f2c584

++++ audit:

  - Update audit.spec: add requirement for 'awk' package (bsc#1231236)

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#173
  - grub2-bls: adjust config script test
  - grub2-bls: adjust install script test
  - grub2-bls: prefer sdbootutil over bootctl in install script
  - adjust test environment
  - grub2-bls: add default script
  - grub2-bls, systemd-boot: add default script test
  - grub2-bls: use bootctl to get default settings
  - adjust default-settings tests
  - update test result data
  - add emacs config
  - log efi boot manager config after install
  - adjust test data
  - support new grub2-bls package
  - 1.16

------------------------------------------------------------------
------------------  2024-10-3  -  Oct 3 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.2.4
  - -> https://docs.mesa3d.org/relnotes/24.2.4

++++ Mesa-drivers:

  - Update to release 24.2.4
  - -> https://docs.mesa3d.org/relnotes/24.2.4

++++ NetworkManager:

  - Update to version 1.50.0:
    + The support for "dhclient" has been deprecated, not built
    unless explicitely enabled, and will be removed in a future
    release. The internal DHCP client should be used instead and
    has been the default since version 1.20 (1.12 when built with
    meson).
    + Support matching a OVS system interface by MAC address.
    + Add a timeout option to connectivity checking.
    + Support configuring veth interfaces in nmtui.
    + When looking up the system hostname from the reverse DNS lookup
    of addresses configured on interfaces, NetworkManager now takes
    into account the content of /etc/hosts.
    + Revert to using sysctl ipv6.conf.default for ip6-privacy.
    + Allow specifying a system OVS interface by MAC address.
    + ndisc: Support multiple gateways for a single network.
    + wifi: Support configuring channel-width in AP mode.
    + keyfile: Stop writing offensive terms into keyfiles.
    + Support reapplying the VLANs on bridge ports.
    + Fix crash caused by malformed LLDP package if debug log is
    enabled.
    + Retry hostname resolution when it fails.
  - Drop NetworkManager-dont-enforce-ip-cleanup-on-device-deactivating.patch:
    Fixed upstream.
  - Rebase patches with quilt.

++++ busybox-links:

  - BuildRequire busybox: as we want to track the version of busybox,
    we need to ensure busybox is part of the buildroot.

++++ grub2:

  - Fix grub screen is filled with artifects from earlier post menu (bsc#1224465)
    * grub2-SUSE-Add-the-t-hotkey.patch
    * 0001-fix-grub-screen-filled-with-post-screen-artifects.patch

++++ kernel-default:

  - Update patches.suse/powerpc-qspinlock-Fix-deadlock-in-MCS-queue.patch
    (bsc#1230295 ltc#206656 CVE-2024-46797 bsc#1230831).
  - commit af09bb2
  - KVM: s390: Fix SORTL and DFLTCC instruction format error in
    __insn32_query (git-fixes bsc#1231276).
  - commit 39bab2d
  - s390/mm: Add cond_resched() to cmm_alloc/free_pages()
    (bsc#1228747).
  - commit d0c79ab
  - ELF: fix kernel.randomize_va_space double read (CVE-2024-46826 bsc#1231115)
  - commit 0519fb0

++++ kernel-rt:

  - Update patches.suse/powerpc-qspinlock-Fix-deadlock-in-MCS-queue.patch
    (bsc#1230295 ltc#206656 CVE-2024-46797 bsc#1230831).
  - commit af09bb2
  - KVM: s390: Fix SORTL and DFLTCC instruction format error in
    __insn32_query (git-fixes bsc#1231276).
  - commit 39bab2d
  - s390/mm: Add cond_resched() to cmm_alloc/free_pages()
    (bsc#1228747).
  - commit d0c79ab
  - ELF: fix kernel.randomize_va_space double read (CVE-2024-46826 bsc#1231115)
  - commit 0519fb0

++++ nftables:

  - Update to release 1.1.1
    * Reduce netlink cache dependencies to speed up incremental
    updates.
    * Allow zero burst in byte ratelimiter expression.
    * Fix double-free when users call nft_ctx_clear_vars() followed
    by nft_ctx_free().
    * Document that the tproxy statement is non-terminal (unlike in
    iptables). This allows for tproxy+log and tproxy+mark combos,
    see man nft(8) for details.
    * Add egress support for the `list hooks` subcommand.

++++ libnftnl:

  - Update to release 1.2.8
    * Fixes for incorrect validation of dynset netlink attributes
    from the kernel

++++ python-urllib3:

  - Update to 2.2.3:
    * Features
    + Added support for Python 3.13.
    * Bugfixes
    + Fixed the default encoding of chunked request bodies to be UTF-8
    instead of ISO-8859-1. All other methods of supplying a request body
    already use UTF-8 starting in urllib3 v2.0.
    + Fixed ResourceWarning on CONNECT with Python < 3.11.4 by backporting
    python/cpython#103472.
    + Fixed a crash where certain standard library hash functions were absent
    in restricted environments.
    + Added the Proxy-Authorization header to the list of headers to strip
    from requests when redirecting to a different host. As before,
    different headers can be set via Retry.remove_headers_on_redirect.
    + Allowed passing negative integers as amt to read methods of
    http.client.HTTPResponse as an alternative to None.
    + Fixed issue where InsecureRequestWarning was emitted for HTTPS
    connections when using Emscripten.
    + Fixed HTTPConnectionPool.urlopen to stop automatically casting
    non-proxy headers to HTTPHeaderDict. This change was premature as it
    did not apply to proxy headers and HTTPHeaderDict does not handle byte
    header values correctly yet.
    + Changed InvalidChunkLength to ProtocolError when response terminates
    before the chunk length is sent.
    + Changed ProtocolError to be more verbose on incomplete reads with
    excess content.
    + Added support for HTTPResponse.read1() method.
    + Fixed issue where requests against urls with trailing dots were
    failing due to SSL errors when using proxy.
    + Fixed HTTPConnection.proxy_is_verified and
    HTTPSConnection.proxy_is_verified to be always set to a boolean after
    connecting to a proxy. It could be None in some cases previously.
    + Fixed an issue where headers passed in a request with json= would be
    mutated
    + Fixed HTTPSConnection.is_verified to be set to False when connecting
    from a HTTPS proxy to an HTTP target. It was set to True previously.
    + Fixed handling of new error message from OpenSSL 3.2.0 when configuring
    an HTTP proxy as HTTPS
    + Fixed TLS 1.3 post-handshake auth when the server certificate
    validation is disabled
    * HTTP/2 (experimental)
    + Excluded Transfer-Encoding: chunked from HTTP/2 request body
    + Added a probing mechanism for determining whether a given target
    origin supports HTTP/2 via ALPN.
    + Add support for sending a request body with HTTP/2
    * Removals
    + Drop support for end-of-life PyPy3.8 and PyPy3.9.
  - Drop patches, they are now included upstream:
    * CVE-2024-37891.patch
    * openssl-3.2.patch
  - Included patched hypercorn, which is only unpacked and used for the test
    suite.

++++ sevctl:

  - Spec: Add direct dependency on cargo in addition to cargo-packaging.
    This fixes build errors on 15SP7 where the inherited version of Rust
    is too old
  - Service: Remove deprecated cargo_config and cargo_audit services, both
    are now handled by the cargo_vendor service

++++ virtiofsd:

  - Spec: Add direct dependency on cargo in addition to cargo-packaging.
    This fixes build errors on 15SP7 where the inherited version of Rust
    is too old

------------------------------------------------------------------
------------------  2024-10-2  -  Oct 2 2024  -------------------
------------------------------------------------------------------

++++ audit-secondary:

  - Readd audit-allow-manual-stop.patch (removed by mistake)

++++ kernel-default:

  - net/mlx5: Fix bridge mode operations when there are no VFs (CVE-2024-46857 bsc#1231087)
  - commit b20fc2c
  - netfilter: nft_socket: fix sk refcount leaks (CVE-2024-46855 bsc#1231085)
  - commit 6c66212
  - net: microchip: vcap: Fix use-after-free error in kunit test
    (CVE-2024-46831 bsc#1231117).
  - commit 630e2e8
  - vmalloc: modify the alloc_vmap_area() error message for better
    diagnostics (jsc#PED-10978).
  - mm: mmap: no need to call khugepaged_enter_vma() for stack
    (jsc#PED-10978).
  - commit 41e1775
  - nvme-pci: qdepth 1 quirk (git-fixes).
  - commit ee2b909
  - ALSA: hda/generic: Unconditionally prefer preferred_dacs pairs
    (bsc#1219803).
  - commit 020b49a

++++ kernel-rt:

  - net/mlx5: Fix bridge mode operations when there are no VFs (CVE-2024-46857 bsc#1231087)
  - commit b20fc2c
  - netfilter: nft_socket: fix sk refcount leaks (CVE-2024-46855 bsc#1231085)
  - commit 6c66212
  - net: microchip: vcap: Fix use-after-free error in kunit test
    (CVE-2024-46831 bsc#1231117).
  - commit 630e2e8
  - vmalloc: modify the alloc_vmap_area() error message for better
    diagnostics (jsc#PED-10978).
  - mm: mmap: no need to call khugepaged_enter_vma() for stack
    (jsc#PED-10978).
  - commit 41e1775
  - nvme-pci: qdepth 1 quirk (git-fixes).
  - commit ee2b909
  - ALSA: hda/generic: Unconditionally prefer preferred_dacs pairs
    (bsc#1219803).
  - commit 020b49a

++++ llvm19:

  - Update to version 19.1.1.
    * This release contains bug-fixes for the LLVM 19.1.0 release.
    This release is API and ABI compatible with 19.1.0.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ libeconf:

  - Updated license in the spec file to MIT.

++++ libproxy-client:

  - Update to version 0.5.9:
    + Ignore invalid proxy URL.
    + Memleak fixes.
    + kde: Add ReversedException support.
    + Fix memory leak using PX_FORCE_CONFIG.
    + Update msys2 build steps.
    + Remove white space in key value.
  - Changes from version 0.5.8:
    + Update repology list.
    + Properly handle empty proxy ignore entry.
    + Add support for direct keyword in PAC.

++++ libproxy-backend:

  - Update to version 0.5.9:
    + Ignore invalid proxy URL.
    + Memleak fixes.
    + kde: Add ReversedException support.
    + Fix memory leak using PX_FORCE_CONFIG.
    + Update msys2 build steps.
    + Remove white space in key value.
  - Changes from version 0.5.8:
    + Update repology list.
    + Properly handle empty proxy ignore entry.
    + Add support for direct keyword in PAC.

++++ systemd:

  - Clean up some remnants from when homed was in the experimental sub-package (bsc#1231048)

++++ python-PyYAML:

  - Update to 6.0.2
    * Support for Cython 3.x and Python 3.13
  - Adjust invocation path for testsuite
  - Adjust upstream source name in spec file
  - Drop build-with-cython3.patch, merged upstream

++++ python-anyio:

  - update to 4.6.0:
    * Dropped support for Python 3.8 (as #698 cannot be resolved
    without cancel message support)
    * Fixed 100% CPU use on asyncio while waiting for an exiting task
    group to finish while said task group is within a cancelled
    cancel scope (#695)
    * Fixed cancel scopes on asyncio not propagating CancelledError
    on exit when the enclosing cancel scope has been effectively
    cancelled (#698)
    * Fixed asyncio task groups not yielding control to the event
    loop at exit if there were no child tasks to wait on
    * Fixed inconsistent task uncancellation with asyncio cancel
    scopes belonging to a task group when said task group has child
    tasks running
  - update to 4.5.0:
    * Improved the performance of anyio.Lock and anyio.Semaphore on
    asyncio (even up to 50 %)
    * Added the fast_acquire parameter to anyio.Lock and
    anyio.Semaphore to further boost performance at the expense of
    safety (acquire() will not yield control back if there is no
    contention)
    * Added support for the from_uri(), full_match(), parser
    methods/properties in anyio.Path, newly added in Python 3.13
    (#737)
    * Added support for more keyword arguments for run_process() and
    open_process(): startupinfo, creationflags, pass_fds, user,
    group, extra_groups and umask (#742)
    * Improved the type annotations and support for PathLike in
    run_process() and open_process() to allow for path-like
    arguments, just like subprocess.Popen
    * Changed the ResourceWarning from an unclosed memory object
    stream to include its address for easier identification
    * Changed start_blocking_portal() to always use daemonic threads,
    to accommodate the "loitering event loop" use case
    * Bumped the minimum version of Trio to v0.26.1
    * Fixed __repr__() of MemoryObjectItemReceiver, when item is not
    defined (#767; PR by @Danipulok)
    * Fixed to_process.run_sync() failing to initialize if
    __main__.__file__ pointed to a file in a nonexistent directory
    (#696)
    * Fixed AssertionError: feed_data after feed_eof on asyncio when
    a subprocess is closed early, before its output has been read
    (#490)
    * Fixed TaskInfo.has_pending_cancellation() on asyncio not
    respecting shielded scopes (#771; PR by @gschaffner)
    * Fixed SocketStream.receive() returning bytearray instead of
    bytes when using asyncio with ProactorEventLoop (Windows)
    (#776)
    * Fixed quitting the debugger in a pytest test session while in
    an active task group failing the test instead of exiting the
    test session (because the exit exception arrives in an
    exception group)
    * Fixed support for Linux abstract namespaces in UNIX sockets
    that was broken in v4.2 (#781; PR by @tapetersen)
    * Fixed KeyboardInterrupt (ctrl+c) hanging the asyncio pytest
    runner

++++ salt:

  - Fix failing x509 tests with OpenSSL < 1.1
  - Avoid explicit reading of /etc/salt/minion (bsc#1220357)
  - Allow NamedLoaderContexts to be returned from loader
  - Revert the change making reactor less blocking (bsc#1230322)
  - Use --cachedir for extension_modules in salt-call (bsc#1226141)
  - Prevent using SyncWrapper with no reason
  - Fix the SELinux context for Salt Minion service (bsc#1219041)
  - Set contextvars as a build requirement for package
  - Increase warn_until_date date for code we still support
  - The test_debian test now uses port 80 for ubuntu keyserver
  - Fix too frequent systemd service restart in test_system test
  - Avoid crash on wrong output of systemctl version (bsc#1229539)
  - Improve error handling with different OpenSSL versions
  - Remove redundant run_func from salt.master.MWorker._handle_aes
  - Fix cloud minion configuration for multiple masters (bsc#1229109)
  - Use Pygit2 id instead of deprecated oid in gitfs
  - Fix few failing tests to work with both Salt and Salt bundle
  - Skip testing unsupported OpenSSL crypto algorithms
  - Added:
    * skip-more-tests-related-to-old-openssl-algorithms.patch
    * fix-the-selinux-context-for-salt-minion-service-bsc-.patch
    * allow-namedloadercontexts-to-be-returned-from-loader.patch
    * join-masters-if-it-is-a-list-671.patch
    * remove-redundant-run_func-from-salt.master.mworker._.patch
    * prevent-using-syncwrapper-with-no-reason.patch
    * fix-test_debian-to-work-in-our-infrastructure-676.patch
    * fix-x509-test-fails-on-old-openssl-systems-682.patch
    * make-tests-compatible-with-venv-bundle.patch
    * avoid-crash-on-wrong-output-of-systemctl-version-bsc.patch
    * revert-the-change-making-reactor-less-blocking-bsc-1.patch
    * avoid-explicit-reading-of-etc-salt-minion-bsc-122035.patch
    * improve-error-handling-with-different-openssl-versio.patch
    * replace-use-of-pygit2-deprecated-and-removed-1.15.0-.patch
    * fix-test_system-flaky-setup_teardown-fn.patch
    * use-cachedir-for-extension_modules-in-salt-call-bsc-.patch
    * fix-deprecated-code-677.patch

------------------------------------------------------------------
------------------  2024-10-1  -  Oct 1 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - u_mesa-CVE-2023-45913.patch
    * NULL pointer dereference via dri2GetGlxDrawableFromXDrawableId()
    (CVE-2023-45913, bsc#1222040)
  - u_mesa-CVE-2023-45919.patch
    * buffer over-read in glXQueryServerString()
    (CVE-2023-45919, bsc#1222041)
  - u_mesa-CVE-2023-45922.patch
    * segmentation violation in __glXGetDrawableAttribute()
    (CVE-2023-45922, bsc#1222042)

++++ Mesa-drivers:

  - u_mesa-CVE-2023-45913.patch
    * NULL pointer dereference via dri2GetGlxDrawableFromXDrawableId()
    (CVE-2023-45913, bsc#1222040)
  - u_mesa-CVE-2023-45919.patch
    * buffer over-read in glXQueryServerString()
    (CVE-2023-45919, bsc#1222041)
  - u_mesa-CVE-2023-45922.patch
    * segmentation violation in __glXGetDrawableAttribute()
    (CVE-2023-45922, bsc#1222042)

++++ audit-secondary:

  - Fix plugin termination when using systemd service units (bsc#1215377)
    * add auditd.service-fix-plugin-termination.patch

++++ branding-SLE:

  - grub2: fix progress bar positionning
  - grub2: add keybinding label for menu editing (bsc#888313).

++++ jeos-firstboot:

  - Update to version 1.5.3:
    * otp: Show the QR code in a separate window if necessary (bsc#1231177)

++++ kernel-default:

  - powerpc/code-patching: Add generic memory patching
    (bsc#1194869).
  - powerpc/code-patching: Perform hwsync in __patch_instruction()
    in case of failure (bsc#1194869).
  - commit 33b01a6
  - usbnet: fix cyclical race on disconnect with work queue
    (git-fixes).
  - Refresh
    patches.suse/0002-Add-a-void-suse_kabi_padding-placeholder-to-some-USB.patch.
  - commit 8272f2d
  - apparmor: fix possible NULL pointer dereference (CVE-2024-46721 bsc#1230710)
  - commit 2d35a7c
  - powerpc/64: Convert patch_instruction() to patch_u32()
    (bsc#1194869).
  - powerpc/boot: Only free if realloc() succeeds (bsc#1194869).
  - powerpc/boot: Handle allocation failure in simple_realloc()
    (bsc#1194869).
  - powerpc/xics: Check return value of kasprintf in
    icp_native_map_one_cpu (bsc#1194869).
  - powerpc/vdso: Fix VDSO data access when running in a non-root
    time namespace (bsc#1194869).
  - commit 0dec2e8
  - net: mana: Improve mana_set_channels() in low mem conditions
    (bsc#1230289).
  - net: mana: Implement get_ringparam/set_ringparam for mana
    (bsc#1229891).
  - net: dpaa: Pad packets to ETH_ZLEN (CVE-2024-46854 bsc#1231084).
  - ice: move netif_queue_set_napi to rtnl-protected sections
    (CVE-2024-46766 bsc#1230762).
  - ice: Add netif_device_attach/detach into PF reset flow
    (CVE-2024-46770 bsc#1230763).
  - bonding: change ipsec_lock from spin lock to mutex
    (CVE-2024-46678 bsc#1230550).
  - bonding: extract the use of real_device into local variable
    (CVE-2024-46678 bsc#1230550).
  - bonding: implement xdo_dev_state_free and call it after deletion
    (CVE-2024-46678 bsc#1230550).
  - commit 9ee67ad
  - powerpc/xmon: Fix disassembly CPU feature checks (bsc#1065729).
  - commit c675509
  - ACPICA: executer/exsystem: Don't nag user about every Stall()
    violating the spec (git-fixes).
  - ACPICA: Implement ACPI_WARNING_ONCE and ACPI_ERROR_ONCE
    (stable-fixes).
  - commit f94e799
  - cachefiles: fix dentry leak in cachefiles_open_file()
    (bsc#1231183).
  - ceph: remove the incorrect Fw reference check when dirtying
    pages (bsc#1231182).
  - commit ba82da7
  - rpm/check-for-config-changes: add HAVE_RUST and RUSTC_SUPPORTS_ to IGNORED_CONFIGS_RE
    They depend on SHADOW_CALL_STACK.
  - commit 65fa52b
  - can: mcp251xfd: move mcp251xfd_timestamp_start()/stop() into
    mcp251xfd_chip_start/stop() (stable-fixes).
  - Refresh
    patches.suse/can-mcp251xfd-clarify-the-meaning-of-timestamp.patch.
  - commit 6779985
  - USB: serial: pl2303: add device id for Macrosilicon MS3020
    (stable-fixes).
  - powercap/intel_rapl: Add support for AMD family 1Ah
    (stable-fixes).
  - ASoC: amd: yc: Add a quirk for MSI Bravo 17 (D7VEK)
    (stable-fixes).
  - ASoC: tda7419: fix module autoloading (stable-fixes).
  - ASoC: intel: fix module autoloading (stable-fixes).
  - ASoC: Intel: soc-acpi-cht: Make Lenovo Yoga Tab 3 X90F DMI
    match less strict (stable-fixes).
  - ALSA: hda: add HDMI codec ID for Intel PTL (stable-fixes).
  - drm: komeda: Fix an issue related to normalized zpos
    (stable-fixes).
  - can: mcp251xfd: mcp251xfd_ring_init(): check TX-coalescing
    configuration (stable-fixes).
  - spi: spidev: Add missing spi_device_id for jg10309-01
    (git-fixes).
  - spi: bcm63xx: Enable module autoloading (stable-fixes).
  - spi: spidev: Add an entry for elgin,jg10309-01 (stable-fixes).
  - hwmon: (asus-ec-sensors) remove VRM temp X570-E GAMING
    (stable-fixes).
  - wifi: iwlwifi: clear trans->state earlier upon error
    (stable-fixes).
  - wifi: mac80211: free skb on error path in
    ieee80211_beacon_get_ap() (stable-fixes).
  - wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead
    (stable-fixes).
  - wifi: iwlwifi: mvm: pause TCM when the firmware is stopped
    (stable-fixes).
  - wifi: iwlwifi: mvm: fix iwl_mvm_max_scan_ie_fw_cmd_room()
    (stable-fixes).
  - wifi: iwlwifi: mvm: fix iwl_mvm_scan_fits() calculation
    (stable-fixes).
  - wifi: iwlwifi: lower message level for FW buffer destination
    (stable-fixes).
  - platform/x86: x86-android-tablets: Make Lenovo Yoga Tab 3 X90F
    DMI match less strict (stable-fixes).
  - pinctrl: at91: make it work with current gpiolib (stable-fixes).
  - can: mcp251xfd: properly indent labels (stable-fixes).
  - commit a530f31

++++ kernel-firmware-all:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-amdgpu:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-ath10k:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-ath11k:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-ath12k:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-atheros:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-bluetooth:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-bnx2:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-brcm:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-chelsio:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-dpaa2:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-i915:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-intel:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-iwlwifi:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-liquidio:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-marvell:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-media:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-mediatek:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-mellanox:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-mwifiex:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-network:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-nfp:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-nvidia:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-platform:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-prestera:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-qcom:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-qlogic:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-radeon:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-realtek:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-serial:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-sound:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-ti:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-ueagle:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-firmware-usb-network:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ kernel-rt:

  - powerpc/code-patching: Add generic memory patching
    (bsc#1194869).
  - powerpc/code-patching: Perform hwsync in __patch_instruction()
    in case of failure (bsc#1194869).
  - commit 33b01a6
  - usbnet: fix cyclical race on disconnect with work queue
    (git-fixes).
  - Refresh
    patches.suse/0002-Add-a-void-suse_kabi_padding-placeholder-to-some-USB.patch.
  - commit 8272f2d
  - apparmor: fix possible NULL pointer dereference (CVE-2024-46721 bsc#1230710)
  - commit 2d35a7c
  - powerpc/64: Convert patch_instruction() to patch_u32()
    (bsc#1194869).
  - powerpc/boot: Only free if realloc() succeeds (bsc#1194869).
  - powerpc/boot: Handle allocation failure in simple_realloc()
    (bsc#1194869).
  - powerpc/xics: Check return value of kasprintf in
    icp_native_map_one_cpu (bsc#1194869).
  - powerpc/vdso: Fix VDSO data access when running in a non-root
    time namespace (bsc#1194869).
  - commit 0dec2e8
  - net: mana: Improve mana_set_channels() in low mem conditions
    (bsc#1230289).
  - net: mana: Implement get_ringparam/set_ringparam for mana
    (bsc#1229891).
  - net: dpaa: Pad packets to ETH_ZLEN (CVE-2024-46854 bsc#1231084).
  - ice: move netif_queue_set_napi to rtnl-protected sections
    (CVE-2024-46766 bsc#1230762).
  - ice: Add netif_device_attach/detach into PF reset flow
    (CVE-2024-46770 bsc#1230763).
  - bonding: change ipsec_lock from spin lock to mutex
    (CVE-2024-46678 bsc#1230550).
  - bonding: extract the use of real_device into local variable
    (CVE-2024-46678 bsc#1230550).
  - bonding: implement xdo_dev_state_free and call it after deletion
    (CVE-2024-46678 bsc#1230550).
  - commit 9ee67ad
  - powerpc/xmon: Fix disassembly CPU feature checks (bsc#1065729).
  - commit c675509
  - ACPICA: executer/exsystem: Don't nag user about every Stall()
    violating the spec (git-fixes).
  - ACPICA: Implement ACPI_WARNING_ONCE and ACPI_ERROR_ONCE
    (stable-fixes).
  - commit f94e799
  - cachefiles: fix dentry leak in cachefiles_open_file()
    (bsc#1231183).
  - ceph: remove the incorrect Fw reference check when dirtying
    pages (bsc#1231182).
  - commit ba82da7
  - rpm/check-for-config-changes: add HAVE_RUST and RUSTC_SUPPORTS_ to IGNORED_CONFIGS_RE
    They depend on SHADOW_CALL_STACK.
  - commit 65fa52b
  - can: mcp251xfd: move mcp251xfd_timestamp_start()/stop() into
    mcp251xfd_chip_start/stop() (stable-fixes).
  - Refresh
    patches.suse/can-mcp251xfd-clarify-the-meaning-of-timestamp.patch.
  - commit 6779985
  - USB: serial: pl2303: add device id for Macrosilicon MS3020
    (stable-fixes).
  - powercap/intel_rapl: Add support for AMD family 1Ah
    (stable-fixes).
  - ASoC: amd: yc: Add a quirk for MSI Bravo 17 (D7VEK)
    (stable-fixes).
  - ASoC: tda7419: fix module autoloading (stable-fixes).
  - ASoC: intel: fix module autoloading (stable-fixes).
  - ASoC: Intel: soc-acpi-cht: Make Lenovo Yoga Tab 3 X90F DMI
    match less strict (stable-fixes).
  - ALSA: hda: add HDMI codec ID for Intel PTL (stable-fixes).
  - drm: komeda: Fix an issue related to normalized zpos
    (stable-fixes).
  - can: mcp251xfd: mcp251xfd_ring_init(): check TX-coalescing
    configuration (stable-fixes).
  - spi: spidev: Add missing spi_device_id for jg10309-01
    (git-fixes).
  - spi: bcm63xx: Enable module autoloading (stable-fixes).
  - spi: spidev: Add an entry for elgin,jg10309-01 (stable-fixes).
  - hwmon: (asus-ec-sensors) remove VRM temp X570-E GAMING
    (stable-fixes).
  - wifi: iwlwifi: clear trans->state earlier upon error
    (stable-fixes).
  - wifi: mac80211: free skb on error path in
    ieee80211_beacon_get_ap() (stable-fixes).
  - wifi: iwlwifi: mvm: don't wait for tx queues if firmware is dead
    (stable-fixes).
  - wifi: iwlwifi: mvm: pause TCM when the firmware is stopped
    (stable-fixes).
  - wifi: iwlwifi: mvm: fix iwl_mvm_max_scan_ie_fw_cmd_room()
    (stable-fixes).
  - wifi: iwlwifi: mvm: fix iwl_mvm_scan_fits() calculation
    (stable-fixes).
  - wifi: iwlwifi: lower message level for FW buffer destination
    (stable-fixes).
  - platform/x86: x86-android-tablets: Make Lenovo Yoga Tab 3 X90F
    DMI match less strict (stable-fixes).
  - pinctrl: at91: make it work with current gpiolib (stable-fixes).
  - can: mcp251xfd: properly indent labels (stable-fixes).
  - commit a530f31

++++ python313-core:

  - Update to 3.13.0~rc3:
  - The most important change is rolling back the incremental
    cyclic garbage collector (GC), which was added in one of
    the alpha releases. The incremental GC had more significant
    performance regressions in specific workloads than we
    expected.
  - Tests
  - gh-124378: Updated test_ttk to pass with Tcl/Tk 8.6.15.
  - Library
  - gh-124538: Fixed crash when using gc.get_referents() on a
    capsule object.
  - gh-124498: Fix typing.TypeAliasType not to be generic, when
    type_params is an empty tuple.
  - gh-123017: Due to unreliable results on some devices,
    time.strftime() no longer accepts negative years on
    Android.
  - gh-123014: os.pidfd_open() and signal.pidfd_send_signal()
    are now unavailable when building against Android API
    levels older than 31, since the underlying system calls may
    cause a crash.
  - gh-124248: Fixed potential crash when using struct to
    process zero-width ‘Pascal string’ fields (0p).
  - gh-87041: Fix a bug in argparse where lengthy subparser
    argument help is incorrectly indented.
  - gh-124212: Fix invalid variable in venv handling of failed
    symlink on Windows
  - gh-124171: Add workaround for broken fmod() implementations
    on Windows, that loose zero sign (e.g. fmod(-10, 1) returns
    0.0). Patch by Sergey B Kirpichev.
  - gh-123934: Fix unittest.mock.MagicMock reseting magic
    methods return values after .reset_mock(return_value=True)
    was called.
  - gh-123968: Fix the command-line interface for the random
    module to select floats between 0 and N, not 1 and N.
  - gh-123892: Add "_wmi" to sys.stdlib_module_names. Patch by
    Victor Stinner.
  - gh-123339: Fix inspect.getsource() for classes
    in collections.abc and decimal (for pure Python
    implementation) modules. inspect.getcomments() now raises
    OSError instead of IndexError if the __firstlineno__ value
    for a class is out of bound.
  - gh-121735: When working with zip archives,
    importlib.resources now properly honors module-adjacent
    references (e.g. files(pkg.mod) and not just files(pkg)).
  - gh-122145: Fix an issue when reporting tracebacks
    corresponding to Python code emitting an empty AST
    body. Patch by Nikita Sobolev and Bénédikt Tran.
  - gh-119004: Fix a crash in OrderedDict.__eq__ when operands
    are mutated during the check. Patch by Bénédikt Tran.
  - bpo-44864: Do not translate user-provided strings in
    argparse.ArgumentParser.
  - IDLE
  - gh-112938: Fix uninteruptable hang when Shell gets rapid
    continuous output.
  - gh-120104: Fix padding in config and search dialog windows
    in IDLE.
  - Documentation
  - gh-124720: Update “Using Python on a Mac” section of the
    “Python Setup and Usage” document and include information
    on installing free-threading support.
  - gh-116622: Add an Android platform guide, and flag modules
    not available on Android.
  - Core and Builtins
  - gh-124567: Revert the incremental GC (in 3.13), since it’s
    not clear the benefits outweigh the costs at this point.
  - gh-124642: Fixed scalability issue in free-threaded builds
    for lock-free reads from dictionaries in multi-threaded
    scenarios
  - gh-116510: Fix a bug that can cause a crash when
    sub-interpreters use “basic” single-phase extension
    modules. Shared objects could refer to PyGC_Head nodes that
    had been freed as part of interpreter cleanup.
  - gh-124547: When deallocating an object with inline values
    whose __dict__ is still live: if memory allocation for the
    inline values fails, clear the dictionary. Prevents an
    interpreter crash.
  - gh-124513: Fix a crash in FrameLocalsProxy constructor:
    check the number of arguments. Patch by Victor Stinner.
  - gh-124442: Fix nondeterminism in compilation by sorting the
    value of __static_attributes__. Patch by kp2pml30.
  - gh-123856: Fix PyREPL failure when a keyboard interrupt is
    triggered after using a history search
  - gh-65961: Document the deprecation of setting and using
    __package__ and __cached__.
  - gh-124027: Support <page up>, <page down>, and <delete>
    keys in the Python REPL when $TERM is set to vt100.
  - gh-77894: Fix possible crash in the garbage collector when
    it tries to break a reference loop containing a memoryview
    object. Now a memoryview object can only be cleared if
    there are no buffers that refer it.
  - gh-123339: Setting the __module__ attribute for a class now
    removes the __firstlineno__ item from the type’s dict, so
    they will no longer be inconsistent.
  - C API
  - gh-124160: Fix crash when importing modules containing
    state and single-phase initialization in a subinterpreter.
  - gh-123880: Fixed a bug that prevented circular imports of
    extension modules that use single-phase initialization.
  - Build
  - gh-124487: Windows builds now use Windows 8.1 as their API
    baseline (installation already required Windows 8.1).
  - gh-124043: Building using --with-trace-refs is
    (temporarily) disallowed when the GIL is disabled.
  - Remove upstreamed patch:
  - gh-124040-fix-test-math-i586.patch
  - Drop .pyc files from docdir for reproducible builds (bsc#1230906).

++++ sssd:

  - Update filelists involving memberof.so and idmap/sss.so to
    avoid gobbling up one file into multiple sssd subpackages.
    (Between samba-4.20 and 4.21, %ldbdir changes from
    /usr/lib64/ldb2/modules/ldb to /usr/lib64/samba/ldb, so now
    `%_libdir/samba` is a bit too broad.)

++++ libvirt:

  - Update to libvirt 10.8.0
  - libvirt-daemon-driver-storage-core: Change dependency on
    nfs-utils from Requires to Recommends
  - Switch from YAJL to json-c for JSON parsing and formatting
  - jsc#PED-8909
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v10-8-0-2024-10-01

++++ opensc:

  - - Security fix: [CVE-2024-8443, bsc#1230364]
    * opensc: heap buffer overflow in OpenPGP driver when generating key
    * Added patch: opensc-CVE-2024-8443.patch
  - Security fix: [opensc-CVE-2024-45620, bsc#1230076]
  - Security fix: [opensc-CVE-2024-45619, bsc#1230075]
  - Security fix: [opensc-CVE-2024-45618, bsc#1230074]
  - Security fix: [opensc-CVE-2024-45617, bsc#1230073]
  - Security fix: [opensc-CVE-2024-45616, bsc#1230072]
  - Security fix: [opensc-CVE-2024-45615, bsc#1230071]
    * opensc: pkcs15init: Usage of uninitialized values in libopensc and pkcs15init
    * opensc: Uninitialized values after incorrect check or usage of APDU response values in libopensc
    * opensc: Uninitialized values after incorrect or missing checking return values of functions in libopensc
    * opensc: Uninitialized values after incorrect or missing checking return values of functions in pkcs15init
    * opensc: Incorrect handling length of buffers or files in libopensc
    * opensc: Incorrect handling of the length of buffers or files in pkcs15init
    * Added patches:
  - opensc-CVE-2024-45615.patch
  - opensc-CVE-2024-45616.patch
  - opensc-CVE-2024-45617.patch
  - opensc-CVE-2024-45618.patch
  - opensc-CVE-2024-45619.patch
  - opensc-CVE-2024-45620.patch

++++ python313:

  - Update to 3.13.0~rc3:
  - The most important change is rolling back the incremental
    cyclic garbage collector (GC), which was added in one of
    the alpha releases. The incremental GC had more significant
    performance regressions in specific workloads than we
    expected.
  - Tests
  - gh-124378: Updated test_ttk to pass with Tcl/Tk 8.6.15.
  - Library
  - gh-124538: Fixed crash when using gc.get_referents() on a
    capsule object.
  - gh-124498: Fix typing.TypeAliasType not to be generic, when
    type_params is an empty tuple.
  - gh-123017: Due to unreliable results on some devices,
    time.strftime() no longer accepts negative years on
    Android.
  - gh-123014: os.pidfd_open() and signal.pidfd_send_signal()
    are now unavailable when building against Android API
    levels older than 31, since the underlying system calls may
    cause a crash.
  - gh-124248: Fixed potential crash when using struct to
    process zero-width ‘Pascal string’ fields (0p).
  - gh-87041: Fix a bug in argparse where lengthy subparser
    argument help is incorrectly indented.
  - gh-124212: Fix invalid variable in venv handling of failed
    symlink on Windows
  - gh-124171: Add workaround for broken fmod() implementations
    on Windows, that loose zero sign (e.g. fmod(-10, 1) returns
    0.0). Patch by Sergey B Kirpichev.
  - gh-123934: Fix unittest.mock.MagicMock reseting magic
    methods return values after .reset_mock(return_value=True)
    was called.
  - gh-123968: Fix the command-line interface for the random
    module to select floats between 0 and N, not 1 and N.
  - gh-123892: Add "_wmi" to sys.stdlib_module_names. Patch by
    Victor Stinner.
  - gh-123339: Fix inspect.getsource() for classes
    in collections.abc and decimal (for pure Python
    implementation) modules. inspect.getcomments() now raises
    OSError instead of IndexError if the __firstlineno__ value
    for a class is out of bound.
  - gh-121735: When working with zip archives,
    importlib.resources now properly honors module-adjacent
    references (e.g. files(pkg.mod) and not just files(pkg)).
  - gh-122145: Fix an issue when reporting tracebacks
    corresponding to Python code emitting an empty AST
    body. Patch by Nikita Sobolev and Bénédikt Tran.
  - gh-119004: Fix a crash in OrderedDict.__eq__ when operands
    are mutated during the check. Patch by Bénédikt Tran.
  - bpo-44864: Do not translate user-provided strings in
    argparse.ArgumentParser.
  - IDLE
  - gh-112938: Fix uninteruptable hang when Shell gets rapid
    continuous output.
  - gh-120104: Fix padding in config and search dialog windows
    in IDLE.
  - Documentation
  - gh-124720: Update “Using Python on a Mac” section of the
    “Python Setup and Usage” document and include information
    on installing free-threading support.
  - gh-116622: Add an Android platform guide, and flag modules
    not available on Android.
  - Core and Builtins
  - gh-124567: Revert the incremental GC (in 3.13), since it’s
    not clear the benefits outweigh the costs at this point.
  - gh-124642: Fixed scalability issue in free-threaded builds
    for lock-free reads from dictionaries in multi-threaded
    scenarios
  - gh-116510: Fix a bug that can cause a crash when
    sub-interpreters use “basic” single-phase extension
    modules. Shared objects could refer to PyGC_Head nodes that
    had been freed as part of interpreter cleanup.
  - gh-124547: When deallocating an object with inline values
    whose __dict__ is still live: if memory allocation for the
    inline values fails, clear the dictionary. Prevents an
    interpreter crash.
  - gh-124513: Fix a crash in FrameLocalsProxy constructor:
    check the number of arguments. Patch by Victor Stinner.
  - gh-124442: Fix nondeterminism in compilation by sorting the
    value of __static_attributes__. Patch by kp2pml30.
  - gh-123856: Fix PyREPL failure when a keyboard interrupt is
    triggered after using a history search
  - gh-65961: Document the deprecation of setting and using
    __package__ and __cached__.
  - gh-124027: Support <page up>, <page down>, and <delete>
    keys in the Python REPL when $TERM is set to vt100.
  - gh-77894: Fix possible crash in the garbage collector when
    it tries to break a reference loop containing a memoryview
    object. Now a memoryview object can only be cleared if
    there are no buffers that refer it.
  - gh-123339: Setting the __module__ attribute for a class now
    removes the __firstlineno__ item from the type’s dict, so
    they will no longer be inconsistent.
  - C API
  - gh-124160: Fix crash when importing modules containing
    state and single-phase initialization in a subinterpreter.
  - gh-123880: Fixed a bug that prevented circular imports of
    extension modules that use single-phase initialization.
  - Build
  - gh-124487: Windows builds now use Windows 8.1 as their API
    baseline (installation already required Windows 8.1).
  - gh-124043: Building using --with-trace-refs is
    (temporarily) disallowed when the GIL is disabled.
  - Remove upstreamed patch:
  - gh-124040-fix-test-math-i586.patch
  - Drop .pyc files from docdir for reproducible builds (bsc#1230906).

++++ python-libvirt-python:

  - Update to 10.8.0
  - Add all new APIs and constants in libvirt 10.8.0
  - jsc#PED-8909

++++ systemd-presets-common-SUSE:

  - Enable audit-rules: audit-rules has been split form audit with
    version 4.0 in order to be able to load rules earlier.
    From audit changelog: One of the main features is the separation
    of loading rules and logging events into separate services,
    audit-rules.service and auditd.service.

++++ ucode-amd:

  - Update to version 20241001 (git commit 51e5af813eaf):
    * linux-firmware: add firmware for MediaTek Bluetooth chip (MT7920)
    * linux-firmware: add firmware for MT7920
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update PSP 14.0.4 firmware
    * amdgpu: update GC 11.5.2 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update SDMA 4.4.2 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update aldebaran firmware
    * qcom: update gpu firmwares for qcm6490 chipset
    * mt76: mt7996: add firmware files for mt7992 chipset
    * mt76: mt7996: add firmware files for mt7996 chipset variants
    * qcom: add gpu firmwares for sa8775p chipset
    * rtw89: 8922a: add fw format-2 v0.35.42.1
  - Pick up the fixed ath12k firmware from
    https://git.codelinaro.org/clo/ath-firmware/ath12k-firmware
    (bsc#1230596)
  - Update aliases from 6.11.x and 6.12-rc1

++++ yast2:

  - Removed obsolete USERADD_CMD, USERDEL_PRECMD, USERDEL_POSTCMD,
    GROUPADD_CMD (bsc#1231006)
  - 5.0.10

------------------------------------------------------------------
------------------  2024-9-30  -  Sep 30 2024  -------------------
------------------------------------------------------------------

++++ cockpit:

  - add 0006-totp-motd.patch for guidance to enabling totp to the mtod

++++ cups:

  - Version upgrade to 2.4.11:
    See https://github.com/openprinting/cups/releases
    CUPS 2.4.11 brings several bug fixes regarding IPP response
    validation, processing PPD values, Web UI support
    (checkbox support, modifying printers) and others fixes.
    Detailed list (from CHANGES.md):
    * Updated the maximum file descriptor limit
    for `cupsd` to 64k-1 (Issue #989)
    * Fixed `lpoptions -d` with a discovered
    but not added printer (Issue #833)
    * Fixed incorrect error message for HTTP/IPP errors (Issue #893)
    * Fixed JobPrivateAccess and SubscriptionPrivateAccess support
    for "all" (Issue #990)
    * Fixed issues with cupsGetDestMediaByXxx (Issue #993)
    * Fixed adding and modifying of printers
    via the web interface (Issue #998)
    * Fixed HTTP PeerCred authentication
    for domain users (Issue #1001)
    * Fixed checkbox support (Issue #1008)
    * Fixed printer state notifications (Issue #1013)
    * Fixed IPP Everywhere printer setup (Issue #1033)
    Issues are those at https://github.com/OpenPrinting/cups/issues
    In particular CUPS 2.4.11 contains those commit regarding
    IPP response validation and processing PPD values:
    * "Quote PPD localized strings"
    https://github.com/OpenPrinting/cups/commit/1e6ca5913eceee906038bc04cc7ccfbe2923bdfd
    plus a cleanup to "Fix warnings for unused vars"
    https://github.com/OpenPrinting/cups/commit/2abe1ba8a66864aa82cd9836b37e57103b8e1a3b
  - Adapted downgrade-autoconf-requirement.patch for CUPS 2.4.11
  - avoid_C99_mode_for_loop_initial_declarations.patch
    is no longer needed because the issue is fixed upstream.

++++ python-kiwi:

  - Support older apt versions for bootstrap
    This Fixes #2660

++++ glibc:

  - langpacks are no more used. Drop glibc-2.3.90-langpackdir.diff.

++++ haproxy:

  - Update to version 3.0.5+git0.8e879a52e: (VUL-0: CVE-2024-49214 boo#1231612)
    * [RELEASE] Released version 3.0.5
    * BUG/MINOR: quic: prevent freeze after early QCS closure
    * BUG/MEDIUM: quic: handle retransmit for standalone FIN STREAM
    * MINOR: quic: implement function to check if STREAM is fully acked
    * MINOR: quic: convert qc_stream_desc release field to flags
    * BUG/MINOR: cfgparse-listen: fix option httpslog override warning message
    * BUG/MEDIUM: promex: Wait to have the request before sending the response
    * BUG/MEDIUM: cache/stats: Wait to have the request before sending the response
    * BUG/MEDIUM: sc_strm/applet: Wake applet after a successfull synchronous send
    * DOC: config: Explicitly list relaxing rules for accept-invalid-http-* options
    * BUG/MINOR: peers: local entries updates may not be advertised after resync
    * BUG/MEDIUM: queue: implement a flag to check for the dequeuing
    * BUG/MINOR: clock: validate that now_offset still applies to the current date
    * BUG/MINOR: clock: make time jump corrections a bit more accurate
    * BUG/MINOR: polling: fix time reporting when using busy polling
    * MEDIUM: h1: Accept invalid T-E values with accept-invalid-http-response option
    * BUG/MINOR: pattern: do not leave a leading comma on "set" error messages
    * BUG/MINOR: h1-htx: Don't flag response as bodyless when a tunnel is established
    * BUG/MAJOR: mux-h1: Wake SC to perform 0-copy forwarding in CLOSING state
    * BUG/MEDIUM: pattern: prevent UAF on reused pattern expr
    * BUG/MINOR: pattern: prevent const sample from being tampered in pat_match_beg()
    * BUG/MEDIUM: clock: detect and cover jumps during execution
    * REGTESTS: fix random failures with wrong_ip_port_logging.vtc under load
    * DOC: configuration: place the HAPROXY_HTTP_LOG_FMT example on the correct line
    * BUG/MINOR: quic: Too short datagram during packet building failures (aws-lc only)
    * BUG/MINOR: quic: Crash from trace dumping SSL eary data status (AWS-LC)
    * BUG/MEDIUM: quic: always validate sender address on 0-RTT
    * MINOR: quic: Add trace for QUIC_EV_CONN_IO_CB event.
    * MINOR: quic: Implement qc_ssl_eary_data_accepted().
    * MINOR: quic: Modify NEW_TOKEN frame structure (qf_new_token struct)
    * BUG/MINOR: quic: Missing incrementation in NEW_TOKEN frame builder
    * MINOR: quic: Token for future connections implementation.
    * MEDIUM: ssl/quic: implement quic crypto with EVP_AEAD
    * MINOR: quic: Implement quic_tls_derive_token_secret().
    * MINOR: tools: Implement ipaddrcpy().
    * BUG/MEDIUM: clock: also update the date offset on time jumps
    * BUILD: quic: 32bits build broken by wrong integer conversions for printf()
    * BUG/MINOR: cfgparse-global: remove tune.fast-forward from common_kw_list
    * DOC: config: correct the table for option tcplog
    * BUG/MINOR: pattern: pat_ref_set: return 0 if err was found
    * BUG/MINOR: pattern: pat_ref_set: fix UAF reported by coverity
    * BUG/MINOR: h3: properly reject too long header responses
    * BUG/MINOR: proto_uxst: delete fd from fdtab if listen() fails
    * BUG/MINOR: mux-quic: do not send too big MAX_STREAMS ID
    * REGTESTS: mcli: test the pipelined commands on master CLI
    * BUG/MEDIUM: mworker/cli: fix pipelined modes on master CLI
    * MINOR: channel: implement ci_insert() function
    * BUG/MINOR: proto_tcp: keep error msg if listen() fails
    * BUG/MINOR: proto_tcp: delete fd from fdtab if listen() fails
    * BUG/MINOR: quic/trace: make quic_conn_enc_level_init() emit NEW not CLOSE
    * BUG/MINOR: trace/quic: make "qconn" selectable as a lockon criterion
    * BUG/MINOR: trace: automatically start in waiting mode with "start <evt>"
    * BUG/MEDIUM: trace: fix null deref in lockon mechanism since TRACE_ENABLED()
    * BUG/MINOR: trace/quic: permit to lock on frontend/connect/session etc
    * BUG/MINOR: trace/quic: enable conn/session pointer recovery from quic_conn
    * DOC: configuration: fix alphabetical ordering of {bs,fs}.aborted
    * BUG/MINOR: fcgi-app: handle a possible strdup() failure
    * BUG/MEDIUM: peer: Notify the applet won't consume data when it waits for sync
    * BUG/MEDIUM: mux-h2: Propagate term flags to SE on error in h2s_wake_one_stream
    * BUG/MEDIUM: h2: Only report early HTX EOM for tunneled streams
    * BUG/MEDIUM: http-ana: Report error on write error waiting for the response
    * BUG/MEDIUM: quic: prevent conn freeze on 0RTT undeciphered content
    * BUG/MEDIUM: ssl: 0-RTT initialized at the wrong place for AWS-LC
    * BUG/MEDIUM: ssl: reactivate 0-RTT for AWS-LC
    * BUG/MINOR: stconn: bs.id and fs.id had their dependencies incorrect
    * BUILD: mux-pt: Use the right name for the sedesc variable
    * BUG/MEDIUM: mux-pt/mux-h1: Release the pipe on connection error on sending path
    * BUG/MEDIUM: stconn: Report error on SC on send if a previous SE error was set
    * BUG/MEDIUM: server/addr: fix tune.events.max-events-at-once event miss and leak

++++ open-iscsi:

  - Update to version 2.1.10.suse+51.fea0fde82ed1:
    * Incudes upstream version 2.1.10 plus some fixes
    * Fix firmware targets startup to always be "onboot" (#482)
    (bsc#1228084)
    * Change a discovery function to void return type (#481)
    * Fix gcc issues (#480)
    * Bugfix read specific sysfs value "off" of session attribute (#466)
    * Fix bug where abort_tmo read failures were ignored. (#467)
    * grammar nitpicks (#464)
    * Fix memory leak in iscsi_check_session_use_count (#465)
    * improve the comments in idbm_lock() (#458)
    * Make it visible when memory allocation failure (#457)
    * Better handle multiple iscsiadm commands (#453)
    * iscsiadm: allow hostnames in node-mode commands (#451)
    * Modify how workqueue priority is set (#445)
    * Fix authmethod check by printing a warning message when CHAP used and authmethod=None (#443)
    * iscsid: Rescan devices on relogin (#444)
    * Adds missing characters in README. (#440)
    * Turn off iSCSI NOP-Outs, by default.
    * fix: add usr/iscsid_req.h missinig underline (#431) (#436)

++++ kernel-default:

  - mm/filemap: skip to create PMD-sized page cache if needed
    (bsc#1228454 CVE-2024-41031).
  - commit 03907fa
  - nvme-fabrics: use reserved tag for reg read/write command
    (bsc#1228620 CVE-2024-41082).
  - commit 239456c
  - kthread: Fix task state in kthread worker if being frozen
    (bsc#1231146).
  - commit fe88a62
  - supported.conf: mark adiantum and xctr crypto modules as supported (bsc#1231035)
  - commit 59d03d7
  - Refresh
    patches.suse/bpf-kprobe-remove-unused-declaring-of-bpf_kprobe_override.patch.
  - commit 5a0b269
  - bpf: Fix use-after-free in bpf_uprobe_multi_link_attach()
    (git-fixes).
  - commit 1884922
  - tracing: Avoid possible softlockup in tracing_iter_reset()
    (git-fixes).
  - commit d5df75c
  - tracing: Fix overflow in get_free_elt() (git-fixes
    CVE-2024-43890 bsc#1229764).
  - commit ceb524e
  - arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry (bsc#1231120 CVE-2024-46822)
  - commit cc6d7b5
  - mailbox: bcm2835: Fix timeout during suspend mode (git-fixes).
  - mailbox: rockchip: fix a typo in module autoloading (git-fixes).
  - i2c: designware: fix controller is holding SCL low while ENABLE
    bit is disabled (git-fixes).
  - drm/amd/display: handle nulled pipe context in DCE110's
    set_drr() (git-fixes).
  - drm/amdgpu: Fix get each xcp macro (git-fixes).
  - tomoyo: fallback to realpath if symlink's pathname does not
    exist (git-fixes).
  - cxl/pci: Fix to record only non-zero ranges (git-fixes).
  - ata: libata-scsi: Fix ata_msense_control() CDL page reporting
    (git-fixes).
  - firmware_loader: Block path traversal (git-fixes).
  - driver core: Fix a potential null-ptr-deref in
    module_add_driver() (git-fixes).
  - driver core: Fix error handling in driver API device_rename()
    (git-fixes).
  - ep93xx: clock: Fix off by one in ep93xx_div_recalc_rate()
    (git-fixes).
  - iio: magnetometer: ak8975: Fix reading for ak099xx sensors
    (git-fixes).
  - iio: chemical: bme680: Fix read/write ops to device by adding
    mutexes (git-fixes).
  - ABI: testing: fix admv8818 attr description (git-fixes).
  - iio: adc: ad7606: fix standby gpio state to match the
    documentation (git-fixes).
  - iio: adc: ad7606: fix oversampling gpio array (git-fixes).
  - tty: rp2: Fix reset with non forgiving PCIe host bridges
    (git-fixes).
  - USB: class: CDC-ACM: fix race between get_serial and set_serial
    (git-fixes).
  - usb: dwc2: drd: fix clock gating on USB role switch (git-fixes).
  - usb: cdnsp: Fix incorrect usb_request status (git-fixes).
  - USB: usbtmc: prevent kernel-usb-infoleak (git-fixes).
  - USB: serial: kobil_sct: restore initial terminal settings
    (git-fixes).
  - xhci: Set quirky xHC PCI hosts to D3 _after_ stopping and
    freeing them (git-fixes).
  - usb: dwc2: Skip clock gating on Broadcom SoCs (git-fixes).
  - spi: atmel-quadspi: Avoid overwriting delay register settings
    (git-fixes).
  - spi: spi-fsl-lpspi: Undo runtime PM changes at driver exit time
    (git-fixes).
  - spi: atmel-quadspi: Undo runtime PM changes at driver exit time
    (git-fixes).
  - rtc: at91sam9: fix OF node leak in probe() error path
    (git-fixes).
  - i3c: master: svc: Fix use after free vulnerability in
    svc_i3c_master Driver Due to Race Condition (git-fixes).
  - remoteproc: k3-r5: Fix error handling when power-up failed
    (git-fixes).
  - remoteproc: imx_rproc: Initialize workqueue earlier (git-fixes).
  - remoteproc: imx_rproc: Correct ddr alias for i.MX8M (git-fixes).
  - KEYS: prevent NULL pointer dereference in find_asymmetric_key()
    (git-fixes).
  - media: i2c: ar0521: Use cansleep version of gpiod_set_value()
    (git-fixes).
  - media: ov5675: Fix power on/off delay timings (git-fixes).
  - media: sun4i_csi: Implement link validate for sun4i_csi subdev
    (git-fixes).
  - media: platform: rzg2l-cru: rzg2l-csi2: Add missing
    MODULE_DEVICE_TABLE (git-fixes).
  - media: venus: fix use after free bug in venus_remove due to
    race condition (git-fixes).
  - media: uapi/linux/cec.h: cec_msg_set_reply_to: zero flags
    (git-fixes).
  - clk: ti: dra7-atl: Fix leak of of_nodes (git-fixes).
  - watchdog: imx_sc_wdt: Don't disable WDT in suspend (git-fixes).
  - pinctrl: single: fix missing error code in pcs_probe()
    (git-fixes).
  - xz: cleanup CRC32 edits from 2018 (git-fixes).
  - ata: pata_macio: Use WARN instead of BUG (stable-fixes).
  - commit c5ab3ca
  - Drop mm patches that caused regressions (bsc#1230413)
    Those should have been already dropped via SLE15-SP6 merge, but slipped
    due to incorrect merge conflict resolutions
  - commit 09dbc92
  - Move upstreamed SCSI patches into sorted section
  - commit aba5747
  - kcm: Serialise kcm_sendmsg() for the same socket (CVE-2024-44946
    bsc#1230015).
  - commit 4310760
  - nvme-multipath: avoid hang on inaccessible namespaces
    (bsc#1228244).
  - kcm: Serialise kcm_sendmsg() for the same socket
    (CVE-2024-44946,bsc#1230015).
  - commit a84ca87
  - nvme-multipath: system fails to create generic nvme device
    (bsc#1228244).
  - commit 4fc57d2
  - erofs: fix incorrect symlink detection in fast symlink
    (git-fixes).
  - commit 2e1ae75
  - afs: Don't cross .backup mountpoint from backup volume
    (git-fixes).
  - commit f35dae1
  - afs: Revert "afs: Hide silly-rename files from userspace"
    (git-fixes).
  - commit 11353bb

++++ kernel-rt:

  - mm/filemap: skip to create PMD-sized page cache if needed
    (bsc#1228454 CVE-2024-41031).
  - commit 03907fa
  - nvme-fabrics: use reserved tag for reg read/write command
    (bsc#1228620 CVE-2024-41082).
  - commit 239456c
  - kthread: Fix task state in kthread worker if being frozen
    (bsc#1231146).
  - commit fe88a62
  - supported.conf: mark adiantum and xctr crypto modules as supported (bsc#1231035)
  - commit 59d03d7
  - Refresh
    patches.suse/bpf-kprobe-remove-unused-declaring-of-bpf_kprobe_override.patch.
  - commit 5a0b269
  - bpf: Fix use-after-free in bpf_uprobe_multi_link_attach()
    (git-fixes).
  - commit 1884922
  - tracing: Avoid possible softlockup in tracing_iter_reset()
    (git-fixes).
  - commit d5df75c
  - tracing: Fix overflow in get_free_elt() (git-fixes
    CVE-2024-43890 bsc#1229764).
  - commit ceb524e
  - arm64: acpi: Harden get_cpu_for_acpi_id() against missing CPU entry (bsc#1231120 CVE-2024-46822)
  - commit cc6d7b5
  - mailbox: bcm2835: Fix timeout during suspend mode (git-fixes).
  - mailbox: rockchip: fix a typo in module autoloading (git-fixes).
  - i2c: designware: fix controller is holding SCL low while ENABLE
    bit is disabled (git-fixes).
  - drm/amd/display: handle nulled pipe context in DCE110's
    set_drr() (git-fixes).
  - drm/amdgpu: Fix get each xcp macro (git-fixes).
  - tomoyo: fallback to realpath if symlink's pathname does not
    exist (git-fixes).
  - cxl/pci: Fix to record only non-zero ranges (git-fixes).
  - ata: libata-scsi: Fix ata_msense_control() CDL page reporting
    (git-fixes).
  - firmware_loader: Block path traversal (git-fixes).
  - driver core: Fix a potential null-ptr-deref in
    module_add_driver() (git-fixes).
  - driver core: Fix error handling in driver API device_rename()
    (git-fixes).
  - ep93xx: clock: Fix off by one in ep93xx_div_recalc_rate()
    (git-fixes).
  - iio: magnetometer: ak8975: Fix reading for ak099xx sensors
    (git-fixes).
  - iio: chemical: bme680: Fix read/write ops to device by adding
    mutexes (git-fixes).
  - ABI: testing: fix admv8818 attr description (git-fixes).
  - iio: adc: ad7606: fix standby gpio state to match the
    documentation (git-fixes).
  - iio: adc: ad7606: fix oversampling gpio array (git-fixes).
  - tty: rp2: Fix reset with non forgiving PCIe host bridges
    (git-fixes).
  - USB: class: CDC-ACM: fix race between get_serial and set_serial
    (git-fixes).
  - usb: dwc2: drd: fix clock gating on USB role switch (git-fixes).
  - usb: cdnsp: Fix incorrect usb_request status (git-fixes).
  - USB: usbtmc: prevent kernel-usb-infoleak (git-fixes).
  - USB: serial: kobil_sct: restore initial terminal settings
    (git-fixes).
  - xhci: Set quirky xHC PCI hosts to D3 _after_ stopping and
    freeing them (git-fixes).
  - usb: dwc2: Skip clock gating on Broadcom SoCs (git-fixes).
  - spi: atmel-quadspi: Avoid overwriting delay register settings
    (git-fixes).
  - spi: spi-fsl-lpspi: Undo runtime PM changes at driver exit time
    (git-fixes).
  - spi: atmel-quadspi: Undo runtime PM changes at driver exit time
    (git-fixes).
  - rtc: at91sam9: fix OF node leak in probe() error path
    (git-fixes).
  - i3c: master: svc: Fix use after free vulnerability in
    svc_i3c_master Driver Due to Race Condition (git-fixes).
  - remoteproc: k3-r5: Fix error handling when power-up failed
    (git-fixes).
  - remoteproc: imx_rproc: Initialize workqueue earlier (git-fixes).
  - remoteproc: imx_rproc: Correct ddr alias for i.MX8M (git-fixes).
  - KEYS: prevent NULL pointer dereference in find_asymmetric_key()
    (git-fixes).
  - media: i2c: ar0521: Use cansleep version of gpiod_set_value()
    (git-fixes).
  - media: ov5675: Fix power on/off delay timings (git-fixes).
  - media: sun4i_csi: Implement link validate for sun4i_csi subdev
    (git-fixes).
  - media: platform: rzg2l-cru: rzg2l-csi2: Add missing
    MODULE_DEVICE_TABLE (git-fixes).
  - media: venus: fix use after free bug in venus_remove due to
    race condition (git-fixes).
  - media: uapi/linux/cec.h: cec_msg_set_reply_to: zero flags
    (git-fixes).
  - clk: ti: dra7-atl: Fix leak of of_nodes (git-fixes).
  - watchdog: imx_sc_wdt: Don't disable WDT in suspend (git-fixes).
  - pinctrl: single: fix missing error code in pcs_probe()
    (git-fixes).
  - xz: cleanup CRC32 edits from 2018 (git-fixes).
  - ata: pata_macio: Use WARN instead of BUG (stable-fixes).
  - commit c5ab3ca
  - Drop mm patches that caused regressions (bsc#1230413)
    Those should have been already dropped via SLE15-SP6 merge, but slipped
    due to incorrect merge conflict resolutions
  - commit 09dbc92
  - Move upstreamed SCSI patches into sorted section
  - commit aba5747
  - kcm: Serialise kcm_sendmsg() for the same socket (CVE-2024-44946
    bsc#1230015).
  - commit 4310760
  - nvme-multipath: avoid hang on inaccessible namespaces
    (bsc#1228244).
  - kcm: Serialise kcm_sendmsg() for the same socket
    (CVE-2024-44946,bsc#1230015).
  - commit a84ca87
  - nvme-multipath: system fails to create generic nvme device
    (bsc#1228244).
  - commit 4fc57d2
  - erofs: fix incorrect symlink detection in fast symlink
    (git-fixes).
  - commit 2e1ae75
  - afs: Don't cross .backup mountpoint from backup volume
    (git-fixes).
  - commit f35dae1
  - afs: Revert "afs: Hide silly-rename files from userspace"
    (git-fixes).
  - commit 11353bb

++++ ncurses:

  - Add ncurses patch 20240928
    + improve error-message from infocmp when a terminal entry cannot be
    opened (patch by Branden Robinson).
    + improve filtering of -L options in misc/gen-pkgconfig.in and in
    misc/ncurses-config.in
    + add check in wresize() for out-of-range dimensions (report by Peter
    Bierma).

++++ suse-module-tools:

  - Update to version 16.0.52:
    * rpm-script: create vmlinuz and initrd also in image build environments
    (bsc#1231040, bsc#1230858)
    * regenerate-initrd-posttrans: Fix SKIP_REGENERATE_INITRD_ALL
    (bsc#1228929)

------------------------------------------------------------------
------------------  2024-9-29  -  Sep 29 2024  -------------------
------------------------------------------------------------------

++++ coreutils:

  - coreutils-i18n.patch: fold(1): fix fold -b with UTF8 locale.
    Sync fix in I18N patch from Fedora/Redhat and add a test. (RHEL-60295)
    Original report: https://access.redhat.com/solutions/3459791

++++ coreutils-systemd:

  - coreutils-i18n.patch: fold(1): fix fold -b with UTF8 locale.
    Sync fix in I18N patch from Fedora/Redhat and add a test. (RHEL-60295)
    Original report: https://access.redhat.com/solutions/3459791

------------------------------------------------------------------
------------------  2024-9-28  -  Sep 28 2024  -------------------
------------------------------------------------------------------

++++ busybox:

  - Update to 1.37.0 (jsc#PED-13039)
  - remove unnecessary patch ash-fix-segfault-d417193cf.patch
  - Update default config to match 1.37.0 expectations
  - fix use-after-free in xasprintf (CVE-2023-42363, bsc#1217580)
  - fix use-after-free in awk evaluate (CVE-2023-42364, bsc#1217584)
  - fix use-after-free in awk copyvar (CVE-2023-42365, bsc#1217585)

++++ librsvg:

  - Update to version 2.59.1:
    + Two mitigations for crashes found throuh fuzz testing:
  - Cairo is easy to crash by giving it path coordinates that are
    outside of the range that it can represent internally with
    its fixed-point arithmetic. Fuzzers usually produce SVGs with
    very large numbers for coordinates, which overflow Cairo's
    arithmetic.
    This is just a *mitigation*, not a complete fix: librsvg will
    now check if path coordinates are outside of Cairo's
    supported range, and it will not render shapes with
    problematic coordinates. However, fuzzers may still produce
    coordinates that are in range but that still make Cairo
    crash. I am starting to learn Cairo's code to see if this can
    be fixed gradually.

++++ libjpeg-turbo:

  - update to 3.0.4:
    * Fixed an issue whereby the CPU usage of the default marker
    processor in the decompressor grew exponentially with the
    number of markers.  This caused an unreasonable slow-down in
    `jpeg_read_header()` if an application called `jpeg_save_markers()`
    to save markers of a particular type and then attempted to
    decompress a JPEG image containing an excessive number of markers
    of that type.
    * Hardened the default marker processor in the decompressor to guard
    against an issue (exposed by 3.0 beta2[6]) whereby attempting to
    decompress a specially-crafted malformed JPEG image (specifically
    an image with a complete 12-bit-per-sample Start Of Frame segment
    followed by an incomplete 8-bit-per-sample Start Of Frame segment)
    using buffered-image mode and input prefetching caused a segfault
    if the `fill_input_buffer()` method in the calling application's
    custom source manager incorrectly returned `FALSE` in response to a
    prematurely-terminated JPEG data stream.
    * Fixed an issue in cjpeg whereby, when generating a
    12-bit-per-sample or 16-bit-per-sample lossless JPEG image,
    specifying a point transform value greater than 7 resulted in an
    error ("Invalid progressive/lossless parameters") unless the
    `-precision` option was specified before the `-lossless` option.
    * Fixed a regression introduced by 3.0.3[3] that made it impossible
    for calling applications to generate 12-bit-per-sample
    arithmetic-coded lossy JPEG images using the TurboJPEG API.
    * Fixed an error ("Destination buffer is not large enough") that
    occurred when attempting to generate a full-color lossless JPEG
    image using the TurboJPEG Java API's `byte[]
    TJCompressor.compress()` method if the value of `TJ.PARAM_SUBSAMP`
    was not `TJ.SAMP_444`.
    * Fixed a segfault in djpeg that occurred if a negative width was
    specified with the `-crop` option.  Since the cropping region width
    was read into an unsigned 32-bit integer, a negative width was
    interpreted as a very large value.  With certain negative width and
    positive left boundary values, the bounds checks in djpeg and
    `jpeg_crop_scanline()` overflowed and did not detect the
    out-of-bounds width, which caused a buffer overrun in the
    upsampling or color conversion routine.  Both bounds checks now use
    64-bit integers to guard against overflow, and djpeg now checks for
    negative numbers when it parses the crop specification from the
    command line.
    * Fixed an issue whereby the TurboJPEG lossless transformation
    function and methods checked the specified cropping region against
    the source image dimensions and level of chrominance subsampling
    rather than the destination image dimensions and level of
    chrominance subsampling, which caused some cropping regions to be
    unduly rejected when performing 90-degree rotation, 270-degree
    rotation, transposition, transverse transposition, or grayscale
    conversion.
    * Fixed an issue whereby the TurboJPEG lossless transformation
    function and methods did not honor
    `TJXOPT_COPYNONE`/`TJTransform.OPT_COPYNONE` unless it was
    specified for all lossless transforms.

++++ python-cryptography:

  - update to 43.0.1:
    * Updated Windows, macOS, and Linux wheels to be compiled with
    OpenSSL 3.3.2.

++++ python-maturin:

  - Update to 1.7.4
    * Fix musllinux rpath for non-cffi bindings
    gh#PyO3/maturin#2233
  - Changes in 1.7.3:
    * Fix pypi/testpypi upload
    gh#PyO3/maturin#2229
  - Changes in 1.7.2:
    * Split out test-windows-cross to speed up ci
    gh#PyO3/maturin#2188
    * Upgrade cargo-deny
    gh#PyO3/maturin#2200
    * Cross building fixes
    gh#PyO3/maturin#2204
    * UniFFI: supports bindings generated from multiple crates
    gh#PyO3/maturin#2208
    * doc: add -r/--release flag info to tutorial
    gh#PyO3/maturin#2211
    * Enable --all-features when building source distribution
    gh#PyO3/maturin#2215
    * Replace "." with "/" in module_name
    gh#PyO3/maturin#2219

------------------------------------------------------------------
------------------  2024-9-27  -  Sep 27 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Run package scripts in apt bootstrap phase
    The bootstrap procedure based on apt only runs a manual
    collection of package scripts. This commit refactors the
    code that unpacks the bootstrap packages to a python
    implementation and adds a method to run the bootstrap
    scripts from all packages resolved by apt.

++++ gnutls:

  - Build with liboqs to support the X25519Kyber768 post-quantum key
    exchange algorithm.

++++ kernel-default:

  - scsi: sd: Fix off-by-one error in
    sd_read_block_characteristics() (bsc#1223848).
  - commit 621f2fb
  - scsi: ibmvfc: Add max_sectors module parameter (bsc#1216223).
  - commit af0ff0f
  - drm/amd/display: Check denominator crb_pipes before used (CVE-2024-46772 bsc#1230772)
  - commit 322be4a
  - arm64: dts: allwinner: h616: Add r_i2c pinctrl nodes
    (git-fixes).
  - commit 642d7e6
  - arm64: dts: imx8-ss-dma: Fix adc0 closing brace location
    (git-fixes).
  - commit 970cc49
  - arm64: dts: rockchip: Correct vendor prefix for Hardkernel
    ODROID-M1 (git-fixes).
  - commit 87f0ae6
  - arm64: dts: rockchip: Raise Pinebook Pro's panel backlight
    PWM frequency (git-fixes).
  - commit 1582b94
  - arm64: dts: rockchip: Correct the Pinebook Pro battery design
    capacity (git-fixes).
  - commit 3b2ebbf
  - arm64: dts: exynos: exynos7885-jackpotlte: Correct RAM amount
    to 4GB (git-fixes).
  - commit 1059c29
  - arm64: signal: Fix some under-bracketed UAPI macros (git-fixes).
  - commit 9704ff3
  - arm64: dts: rockchip: override BIOS_DISABLE signal via GPIO
    hog on RK3399 Puma (git-fixes).
  - commit 6052a8c
  - arm64: dts: rockchip: fix eMMC/SPI corruption when audio has
    been used on RK3399 Puma (git-fixes).
  - commit 8b3743b
  - Update
    patches.suse/powerpc-pseries-make-max-polling-consistent-for-long.patch
    (bsc#1215199 jsc#PED-10954).
  - Update
    patches.suse/security-integrity-fix-pointer-to-ESL-data-and-.patch
    (bsc#1012628 jsc#PED-5085 jsc#PED-10954).
  - commit ec9be2c
  - arm64: dts: rockchip: fix PMIC interrupt pin in pinctrl for
    ROCK Pi E (git-fixes).
  - commit 7527015
  - arm64: acpi: Move get_cpu_for_acpi_id() to a header (git-fixes).
  - commit 42389f0
  - ipmi:ssif: Improve detecting during probing (bsc#1228771)
    Move patch into the sorted section.
  - commit 77cf6fc
  - Update patches.suse/ALSA-line6-Fix-racy-access-to-midibuf.patch
    (stable-fixes CVE-2024-44954 bsc#1230176).
  - Update
    patches.suse/ASoC-dapm-Fix-UAF-for-snd_soc_pcm_runtime-object.patch
    (git-fixes CVE-2024-46798 bsc#1230830).
  - Update
    patches.suse/Bluetooth-btnxpuart-Fix-Null-pointer-dereference-in-.patch
    (stable-fixes CVE-2024-46749 bsc#1230780).
  - Update
    patches.suse/Bluetooth-btnxpuart-Shutdown-timer-and-prevent-rearm.patch
    (stable-fixes CVE-2024-44962 bsc#1230213).
  - Update
    patches.suse/HID-amd_sfh-free-driver_data-after-destroying-hid-de.patch
    (stable-fixes CVE-2024-46746 bsc#1230751).
  - Update
    patches.suse/HID-cougar-fix-slab-out-of-bounds-Read-in-cougar_rep.patch
    (stable-fixes CVE-2024-46747 bsc#1230752).
  - Update patches.suse/Input-MT-limit-max-slots.patch (stable-fixes
    CVE-2024-45008 bsc#1230248).
  - Update
    patches.suse/Input-uinput-reject-requests-with-unreasonable-numbe.patch
    (stable-fixes CVE-2024-46745 bsc#1230748).
  - Update
    patches.suse/KVM-arm64-Make-ICC_-SGI-_EL1-undef-in-the-absence-of.patch
    (git-fixes CVE-2024-46707 bsc#1230582).
  - Update
    patches.suse/KVM-s390-fix-validity-interception-issue-when-gisa-is-switched-off.patch
    (git-fixes bsc#1229167 CVE-2024-45005 bsc#1230173).
  - Update
    patches.suse/PCI-Add-missing-bridge-lock-to-pci_bus_lock.patch
    (stable-fixes CVE-2024-46750 bsc#1230783).
  - Update
    patches.suse/Squashfs-sanity-check-symbolic-link-size.patch
    (git-fixes CVE-2024-46744 bsc#1230747).
  - Update
    patches.suse/VMCI-Fix-use-after-free-when-removing-resource-in-vm.patch
    (git-fixes CVE-2024-46738 bsc#1230731).
  - Update
    patches.suse/bpf-Fix-a-kernel-verifier-crash-in-stacksafe.patch
    (bsc#1225903 CVE-2024-45020 bsc#1230433).
  - Update
    patches.suse/btrfs-fix-race-between-direct-IO-write-and-fsync-whe.patch
    (git-fixes CVE-2024-46734 bsc#1230726).
  - Update
    patches.suse/can-bcm-Remove-proc-entry-when-dev-is-unregistered.patch
    (git-fixes CVE-2024-46771 bsc#1230766).
  - Update
    patches.suse/can-mcp251x-fix-deadlock-if-an-interrupt-occurs-duri.patch
    (git-fixes CVE-2024-46791 bsc#1230821).
  - Update
    patches.suse/char-xillybus-Check-USB-endpoints-when-probing-devic.patch
    (git-fixes CVE-2024-45011 bsc#1230440).
  - Update
    patches.suse/char-xillybus-Don-t-destroy-workqueue-from-work-item.patch
    (stable-fixes CVE-2024-45007 bsc#1230175).
  - Update
    patches.suse/dmaengine-altera-msgdma-properly-free-descriptor-in-.patch
    (stable-fixes CVE-2024-46716 bsc#1230715).
  - Update
    patches.suse/driver-core-Fix-uevent_show-vs-driver-detach-race.patch
    (git-fixes CVE-2024-44952 bsc#1230178).
  - Update
    patches.suse/driver-iio-add-missing-checks-on-iio_info-s-callback.patch
    (stable-fixes CVE-2024-46715 bsc#1230700).
  - Update
    patches.suse/drm-amd-display-Assign-linear_pitch_alignment-even-f.patch
    (stable-fixes CVE-2024-46732 bsc#1230711).
  - Update
    patches.suse/drm-amd-display-Check-UnboundedRequestEnabled-s-valu.patch
    (stable-fixes CVE-2024-46778 bsc#1230776).
  - Update
    patches.suse/drm-amd-display-Check-denominator-pbn_div-before-use.patch
    (stable-fixes CVE-2024-46773 bsc#1230791).
  - Update
    patches.suse/drm-amd-display-Check-index-for-aux_rd_interval-befo.patch
    (stable-fixes CVE-2024-46728 bsc#1230703).
  - Update
    patches.suse/drm-amd-display-Ensure-array-index-tg_inst-won-t-be-.patch
    (stable-fixes CVE-2024-46730 bsc#1230701).
  - Update
    patches.suse/drm-amd-display-Ensure-index-calculation-will-not-ov.patch
    (stable-fixes CVE-2024-46726 bsc#1230706).
  - Update
    patches.suse/drm-amd-display-Run-DC_LOG_DC-after-checking-link-li.patch
    (stable-fixes CVE-2024-46776 bsc#1230775).
  - Update
    patches.suse/drm-amd-display-Skip-wbscl_set_scaler_filter-if-filt.patch
    (stable-fixes CVE-2024-46714 bsc#1230699).
  - Update
    patches.suse/drm-amd-display-avoid-using-null-object-of-framebuff.patch
    (git-fixes CVE-2024-46694 bsc#1230511).
  - Update
    patches.suse/drm-amd-pm-fix-the-Out-of-bounds-read-warning.patch
    (stable-fixes CVE-2024-46731 bsc#1230709).
  - Update
    patches.suse/drm-amdgpu-Fix-out-of-bounds-read-of-df_v1_7_channel.patch
    (stable-fixes CVE-2024-46724 bsc#1230725).
  - Update
    patches.suse/drm-amdgpu-Fix-out-of-bounds-write-warning.patch
    (stable-fixes CVE-2024-46725 bsc#1230705).
  - Update
    patches.suse/drm-amdgpu-Forward-soft-recovery-errors-to-userspace.patch
    (stable-fixes CVE-2024-44961 bsc#1230207).
  - Update patches.suse/drm-amdgpu-Validate-TA-binary-size.patch
    (stable-fixes CVE-2024-44977 bsc#1230217).
  - Update
    patches.suse/drm-amdgpu-fix-dereference-after-null-check.patch
    (stable-fixes CVE-2024-46720 bsc#1230724).
  - Update
    patches.suse/drm-amdgpu-fix-mc_data-out-of-bounds-read-warning.patch
    (stable-fixes CVE-2024-46722 bsc#1230712).
  - Update
    patches.suse/drm-amdgpu-fix-ucode-out-of-bounds-read-warning.patch
    (stable-fixes CVE-2024-46723 bsc#1230702).
  - Update
    patches.suse/drm-mgag200-Bind-I2C-lifetime-to-DRM-device.patch
    (git-fixes CVE-2024-44967 bsc#1230224).
  - Update
    patches.suse/drm-msm-dpu-cleanup-FB-if-dpu_format_populate_layout.patch
    (git-fixes CVE-2024-44982 bsc#1230204).
  - Update
    patches.suse/drm-msm-dpu-move-dpu_encoder-s-connector-assignment-.patch
    (git-fixes CVE-2024-45015 bsc#1230444).
  - Update
    patches.suse/drm-vmwgfx-Fix-prime-with-external-buffers.patch
    (git-fixes CVE-2024-46709 bsc#1230539).
  - Update
    patches.suse/fs-netfs-fscache_cookie-add-missing-n_accesses-check.patch
    (bsc#1229455 CVE-2024-45000 bsc#1230170).
  - Update
    patches.suse/fscache-delete-fscache_cookie_lru_timer-when-fscache-.patch
    (bsc#1230602 CVE-2024-46786 bsc#1230813).
  - Update
    patches.suse/fuse-Initialize-beyond-EOF-page-contents-before-setti.patch
    (bsc#1229456 CVE-2024-44947).
  - Update
    patches.suse/hwmon-adc128d818-Fix-underflows-seen-when-writing-li.patch
    (stable-fixes CVE-2024-46759 bsc#1230814).
  - Update
    patches.suse/hwmon-lm95234-Fix-underflows-seen-when-writing-limit.patch
    (stable-fixes CVE-2024-46758 bsc#1230812).
  - Update
    patches.suse/hwmon-nct6775-core-Fix-underflows-seen-when-writing-.patch
    (stable-fixes CVE-2024-46757 bsc#1230809).
  - Update
    patches.suse/hwmon-w83627ehf-Fix-underflows-seen-when-writing-lim.patch
    (stable-fixes CVE-2024-46756 bsc#1230806).
  - Update
    patches.suse/media-dvb-usb-v2-af9035-Fix-null-ptr-deref-in-af9035.patch
    (git-fixes CVE-2023-52915 bsc#1230270).
  - Update
    patches.suse/misc-fastrpc-Fix-double-free-of-buf-in-error-path.patch
    (git-fixes CVE-2024-46741 bsc#1230749).
  - Update
    patches.suse/mmc-mmc_test-Fix-NULL-dereference-on-allocation-fail.patch
    (git-fixes CVE-2024-45028 bsc#1230450).
  - Update
    patches.suse/msft-hv-3046-uio_hv_generic-Fix-kernel-NULL-pointer-dereference-i.patch
    (git-fixes CVE-2024-46739 bsc#1230732).
  - Update
    patches.suse/msft-hv-3048-net-mana-Fix-error-handling-in-mana_create_txq-rxq-s.patch
    (git-fixes CVE-2024-46784 bsc#1230771).
  - Update
    patches.suse/net-ethernet-mtk_wed-fix-use-after-free-panic-in-mtk.patch
    (git-fixes CVE-2024-44997 bsc#1230232).
  - Update
    patches.suse/net-mana-Fix-RX-buf-alloc_size-alignment-and-atomic-.patch
    (bsc#1229086 CVE-2024-45001 bsc#1230244).
  - Update
    patches.suse/net-phy-Fix-missing-of_node_put-for-leds.patch
    (git-fixes CVE-2024-46767 bsc#1230787).
  - Update
    patches.suse/nfc-pn533-Add-poll-mod-list-filling-check.patch
    (git-fixes CVE-2024-46676 bsc#1230535).
  - Update
    patches.suse/nilfs2-fix-missing-cleanup-on-rollforward-recovery-error.patch
    (git-fixes CVE-2024-46781 bsc#1230768).
  - Update
    patches.suse/nilfs2-protect-references-to-superblock-parameters-exposed-in-sysfs.patch
    (git-fixes CVE-2024-46780 bsc#1230808).
  - Update
    patches.suse/nouveau-firmware-use-dma-non-coherent-allocator.patch
    (git-fixes CVE-2024-45012 bsc#1230441).
  - Update
    patches.suse/nvmet-tcp-fix-kernel-crash-if-commands-allocation-fa.patch
    (git-fixes CVE-2024-46737 bsc#1230730).
  - Update
    patches.suse/pci-hotplug-pnv_php-Fix-hotplug-driver-crash-on-Powe.patch
    (stable-fixes CVE-2024-46761 bsc#1230761).
  - Update patches.suse/perf-Fix-event-leak-upon-exit.patch
    (git-fixes CVE-2024-43870 bsc#1229494).
  - Update
    patches.suse/pinctrl-single-fix-potential-NULL-dereference-in-pcs.patch
    (git-fixes CVE-2024-46685 bsc#1230515).
  - Update
    patches.suse/powerpc-qspinlock-Fix-deadlock-in-MCS-queue.patch
    (bac#1230295 ltc#206656 CVE-2024-46797 bsc#1230831).
  - Update
    patches.suse/powerpc-rtas-Prevent-Spectre-v1-gadget-construction-.patch
    (bsc#1227487 CVE-2024-46774 bsc#1230767).
  - Update
    patches.suse/s390-dasd-fix-error-recovery-leading-to-data-corruption-on-ESE-devices.patch
    (git-fixes bsc#1229452 CVE-2024-45026 bsc#1230454).
  - Update
    patches.suse/s390-sclp-Prevent-release-of-buffer-in-I-O.patch
    (git-fixes bsc#1229169 CVE-2024-44969 bsc#1230200).
  - Update
    patches.suse/soc-qcom-cmd-db-Map-shared-memory-as-WC-not-WB.patch
    (git-fixes CVE-2024-46689 bsc#1230524).
  - Update
    patches.suse/thunderbolt-Mark-XDomain-as-unplugged-when-router-is.patch
    (stable-fixes CVE-2024-46702 bsc#1230589).
  - Update
    patches.suse/tty-serial-fsl_lpuart-mark-last-busy-before-uart_add.patch
    (git-fixes CVE-2024-46706 bsc#1230580).
  - Update
    patches.suse/usb-dwc3-core-Prevent-USB-core-invalid-event-buffer-.patch
    (stable-fixes CVE-2024-46675 bsc#1230533).
  - Update
    patches.suse/usb-dwc3-st-fix-probed-platform-device-ref-count-on-.patch
    (git-fixes CVE-2024-46674 bsc#1230507).
  - Update
    patches.suse/usb-gadget-core-Check-for-unset-descriptor.patch
    (git-fixes CVE-2024-44960 bsc#1230191).
  - Update
    patches.suse/usb-typec-ucsi-Fix-null-pointer-dereference-in-trace.patch
    (stable-fixes CVE-2024-46719 bsc#1230722).
  - Update
    patches.suse/wifi-brcmfmac-cfg80211-Handle-SSID-based-pmksa-delet.patch
    (git-fixes CVE-2024-46672 bsc#1230459).
  - Update
    patches.suse/wifi-mwifiex-Do-not-return-unused-priv-in-mwifiex_ge.patch
    (stable-fixes CVE-2024-46755 bsc#1230802).
  - Update
    patches.suse/wifi-rtw88-usb-schedule-rx-work-after-everything-is-.patch
    (stable-fixes CVE-2024-46760 bsc#1230753).
  - Update
    patches.suse/x86-mm-Fix-pti_clone_pgtable-alignment-assumption.patch
    (git-fixes CVE-2024-44965 bsc#1230221).
  - Update
    patches.suse/x86-mtrr-Check-if-fixed-MTRRs-exist-before-saving-them.patch
    (git-fixes CVE-2024-44948 bsc#1230174).
  - Update
    patches.suse/xhci-Fix-Panther-point-NULL-pointer-deref-at-full-sp.patch
    (git-fixes CVE-2024-45006 bsc#1230247).
  - commit 6da06c4
  - Update patches.suse/gfs2-Fix-NULL-pointer-dereference-in-gfs2_log_flush.patch (bsc#1230948)
  - commit 90a5b1b

++++ kernel-rt:

  - scsi: sd: Fix off-by-one error in
    sd_read_block_characteristics() (bsc#1223848).
  - commit 621f2fb
  - scsi: ibmvfc: Add max_sectors module parameter (bsc#1216223).
  - commit af0ff0f
  - drm/amd/display: Check denominator crb_pipes before used (CVE-2024-46772 bsc#1230772)
  - commit 322be4a
  - arm64: dts: allwinner: h616: Add r_i2c pinctrl nodes
    (git-fixes).
  - commit 642d7e6
  - arm64: dts: imx8-ss-dma: Fix adc0 closing brace location
    (git-fixes).
  - commit 970cc49
  - arm64: dts: rockchip: Correct vendor prefix for Hardkernel
    ODROID-M1 (git-fixes).
  - commit 87f0ae6
  - arm64: dts: rockchip: Raise Pinebook Pro's panel backlight
    PWM frequency (git-fixes).
  - commit 1582b94
  - arm64: dts: rockchip: Correct the Pinebook Pro battery design
    capacity (git-fixes).
  - commit 3b2ebbf
  - arm64: dts: exynos: exynos7885-jackpotlte: Correct RAM amount
    to 4GB (git-fixes).
  - commit 1059c29
  - arm64: signal: Fix some under-bracketed UAPI macros (git-fixes).
  - commit 9704ff3
  - arm64: dts: rockchip: override BIOS_DISABLE signal via GPIO
    hog on RK3399 Puma (git-fixes).
  - commit 6052a8c
  - arm64: dts: rockchip: fix eMMC/SPI corruption when audio has
    been used on RK3399 Puma (git-fixes).
  - commit 8b3743b
  - Update
    patches.suse/powerpc-pseries-make-max-polling-consistent-for-long.patch
    (bsc#1215199 jsc#PED-10954).
  - Update
    patches.suse/security-integrity-fix-pointer-to-ESL-data-and-.patch
    (bsc#1012628 jsc#PED-5085 jsc#PED-10954).
  - commit ec9be2c
  - arm64: dts: rockchip: fix PMIC interrupt pin in pinctrl for
    ROCK Pi E (git-fixes).
  - commit 7527015
  - arm64: acpi: Move get_cpu_for_acpi_id() to a header (git-fixes).
  - commit 42389f0
  - ipmi:ssif: Improve detecting during probing (bsc#1228771)
    Move patch into the sorted section.
  - commit 77cf6fc
  - Update patches.suse/ALSA-line6-Fix-racy-access-to-midibuf.patch
    (stable-fixes CVE-2024-44954 bsc#1230176).
  - Update
    patches.suse/ASoC-dapm-Fix-UAF-for-snd_soc_pcm_runtime-object.patch
    (git-fixes CVE-2024-46798 bsc#1230830).
  - Update
    patches.suse/Bluetooth-btnxpuart-Fix-Null-pointer-dereference-in-.patch
    (stable-fixes CVE-2024-46749 bsc#1230780).
  - Update
    patches.suse/Bluetooth-btnxpuart-Shutdown-timer-and-prevent-rearm.patch
    (stable-fixes CVE-2024-44962 bsc#1230213).
  - Update
    patches.suse/HID-amd_sfh-free-driver_data-after-destroying-hid-de.patch
    (stable-fixes CVE-2024-46746 bsc#1230751).
  - Update
    patches.suse/HID-cougar-fix-slab-out-of-bounds-Read-in-cougar_rep.patch
    (stable-fixes CVE-2024-46747 bsc#1230752).
  - Update patches.suse/Input-MT-limit-max-slots.patch (stable-fixes
    CVE-2024-45008 bsc#1230248).
  - Update
    patches.suse/Input-uinput-reject-requests-with-unreasonable-numbe.patch
    (stable-fixes CVE-2024-46745 bsc#1230748).
  - Update
    patches.suse/KVM-arm64-Make-ICC_-SGI-_EL1-undef-in-the-absence-of.patch
    (git-fixes CVE-2024-46707 bsc#1230582).
  - Update
    patches.suse/KVM-s390-fix-validity-interception-issue-when-gisa-is-switched-off.patch
    (git-fixes bsc#1229167 CVE-2024-45005 bsc#1230173).
  - Update
    patches.suse/PCI-Add-missing-bridge-lock-to-pci_bus_lock.patch
    (stable-fixes CVE-2024-46750 bsc#1230783).
  - Update
    patches.suse/Squashfs-sanity-check-symbolic-link-size.patch
    (git-fixes CVE-2024-46744 bsc#1230747).
  - Update
    patches.suse/VMCI-Fix-use-after-free-when-removing-resource-in-vm.patch
    (git-fixes CVE-2024-46738 bsc#1230731).
  - Update
    patches.suse/bpf-Fix-a-kernel-verifier-crash-in-stacksafe.patch
    (bsc#1225903 CVE-2024-45020 bsc#1230433).
  - Update
    patches.suse/btrfs-fix-race-between-direct-IO-write-and-fsync-whe.patch
    (git-fixes CVE-2024-46734 bsc#1230726).
  - Update
    patches.suse/can-bcm-Remove-proc-entry-when-dev-is-unregistered.patch
    (git-fixes CVE-2024-46771 bsc#1230766).
  - Update
    patches.suse/can-mcp251x-fix-deadlock-if-an-interrupt-occurs-duri.patch
    (git-fixes CVE-2024-46791 bsc#1230821).
  - Update
    patches.suse/char-xillybus-Check-USB-endpoints-when-probing-devic.patch
    (git-fixes CVE-2024-45011 bsc#1230440).
  - Update
    patches.suse/char-xillybus-Don-t-destroy-workqueue-from-work-item.patch
    (stable-fixes CVE-2024-45007 bsc#1230175).
  - Update
    patches.suse/dmaengine-altera-msgdma-properly-free-descriptor-in-.patch
    (stable-fixes CVE-2024-46716 bsc#1230715).
  - Update
    patches.suse/driver-core-Fix-uevent_show-vs-driver-detach-race.patch
    (git-fixes CVE-2024-44952 bsc#1230178).
  - Update
    patches.suse/driver-iio-add-missing-checks-on-iio_info-s-callback.patch
    (stable-fixes CVE-2024-46715 bsc#1230700).
  - Update
    patches.suse/drm-amd-display-Assign-linear_pitch_alignment-even-f.patch
    (stable-fixes CVE-2024-46732 bsc#1230711).
  - Update
    patches.suse/drm-amd-display-Check-UnboundedRequestEnabled-s-valu.patch
    (stable-fixes CVE-2024-46778 bsc#1230776).
  - Update
    patches.suse/drm-amd-display-Check-denominator-pbn_div-before-use.patch
    (stable-fixes CVE-2024-46773 bsc#1230791).
  - Update
    patches.suse/drm-amd-display-Check-index-for-aux_rd_interval-befo.patch
    (stable-fixes CVE-2024-46728 bsc#1230703).
  - Update
    patches.suse/drm-amd-display-Ensure-array-index-tg_inst-won-t-be-.patch
    (stable-fixes CVE-2024-46730 bsc#1230701).
  - Update
    patches.suse/drm-amd-display-Ensure-index-calculation-will-not-ov.patch
    (stable-fixes CVE-2024-46726 bsc#1230706).
  - Update
    patches.suse/drm-amd-display-Run-DC_LOG_DC-after-checking-link-li.patch
    (stable-fixes CVE-2024-46776 bsc#1230775).
  - Update
    patches.suse/drm-amd-display-Skip-wbscl_set_scaler_filter-if-filt.patch
    (stable-fixes CVE-2024-46714 bsc#1230699).
  - Update
    patches.suse/drm-amd-display-avoid-using-null-object-of-framebuff.patch
    (git-fixes CVE-2024-46694 bsc#1230511).
  - Update
    patches.suse/drm-amd-pm-fix-the-Out-of-bounds-read-warning.patch
    (stable-fixes CVE-2024-46731 bsc#1230709).
  - Update
    patches.suse/drm-amdgpu-Fix-out-of-bounds-read-of-df_v1_7_channel.patch
    (stable-fixes CVE-2024-46724 bsc#1230725).
  - Update
    patches.suse/drm-amdgpu-Fix-out-of-bounds-write-warning.patch
    (stable-fixes CVE-2024-46725 bsc#1230705).
  - Update
    patches.suse/drm-amdgpu-Forward-soft-recovery-errors-to-userspace.patch
    (stable-fixes CVE-2024-44961 bsc#1230207).
  - Update patches.suse/drm-amdgpu-Validate-TA-binary-size.patch
    (stable-fixes CVE-2024-44977 bsc#1230217).
  - Update
    patches.suse/drm-amdgpu-fix-dereference-after-null-check.patch
    (stable-fixes CVE-2024-46720 bsc#1230724).
  - Update
    patches.suse/drm-amdgpu-fix-mc_data-out-of-bounds-read-warning.patch
    (stable-fixes CVE-2024-46722 bsc#1230712).
  - Update
    patches.suse/drm-amdgpu-fix-ucode-out-of-bounds-read-warning.patch
    (stable-fixes CVE-2024-46723 bsc#1230702).
  - Update
    patches.suse/drm-mgag200-Bind-I2C-lifetime-to-DRM-device.patch
    (git-fixes CVE-2024-44967 bsc#1230224).
  - Update
    patches.suse/drm-msm-dpu-cleanup-FB-if-dpu_format_populate_layout.patch
    (git-fixes CVE-2024-44982 bsc#1230204).
  - Update
    patches.suse/drm-msm-dpu-move-dpu_encoder-s-connector-assignment-.patch
    (git-fixes CVE-2024-45015 bsc#1230444).
  - Update
    patches.suse/drm-vmwgfx-Fix-prime-with-external-buffers.patch
    (git-fixes CVE-2024-46709 bsc#1230539).
  - Update
    patches.suse/fs-netfs-fscache_cookie-add-missing-n_accesses-check.patch
    (bsc#1229455 CVE-2024-45000 bsc#1230170).
  - Update
    patches.suse/fscache-delete-fscache_cookie_lru_timer-when-fscache-.patch
    (bsc#1230602 CVE-2024-46786 bsc#1230813).
  - Update
    patches.suse/fuse-Initialize-beyond-EOF-page-contents-before-setti.patch
    (bsc#1229456 CVE-2024-44947).
  - Update
    patches.suse/hwmon-adc128d818-Fix-underflows-seen-when-writing-li.patch
    (stable-fixes CVE-2024-46759 bsc#1230814).
  - Update
    patches.suse/hwmon-lm95234-Fix-underflows-seen-when-writing-limit.patch
    (stable-fixes CVE-2024-46758 bsc#1230812).
  - Update
    patches.suse/hwmon-nct6775-core-Fix-underflows-seen-when-writing-.patch
    (stable-fixes CVE-2024-46757 bsc#1230809).
  - Update
    patches.suse/hwmon-w83627ehf-Fix-underflows-seen-when-writing-lim.patch
    (stable-fixes CVE-2024-46756 bsc#1230806).
  - Update
    patches.suse/media-dvb-usb-v2-af9035-Fix-null-ptr-deref-in-af9035.patch
    (git-fixes CVE-2023-52915 bsc#1230270).
  - Update
    patches.suse/misc-fastrpc-Fix-double-free-of-buf-in-error-path.patch
    (git-fixes CVE-2024-46741 bsc#1230749).
  - Update
    patches.suse/mmc-mmc_test-Fix-NULL-dereference-on-allocation-fail.patch
    (git-fixes CVE-2024-45028 bsc#1230450).
  - Update
    patches.suse/msft-hv-3046-uio_hv_generic-Fix-kernel-NULL-pointer-dereference-i.patch
    (git-fixes CVE-2024-46739 bsc#1230732).
  - Update
    patches.suse/msft-hv-3048-net-mana-Fix-error-handling-in-mana_create_txq-rxq-s.patch
    (git-fixes CVE-2024-46784 bsc#1230771).
  - Update
    patches.suse/net-ethernet-mtk_wed-fix-use-after-free-panic-in-mtk.patch
    (git-fixes CVE-2024-44997 bsc#1230232).
  - Update
    patches.suse/net-mana-Fix-RX-buf-alloc_size-alignment-and-atomic-.patch
    (bsc#1229086 CVE-2024-45001 bsc#1230244).
  - Update
    patches.suse/net-phy-Fix-missing-of_node_put-for-leds.patch
    (git-fixes CVE-2024-46767 bsc#1230787).
  - Update
    patches.suse/nfc-pn533-Add-poll-mod-list-filling-check.patch
    (git-fixes CVE-2024-46676 bsc#1230535).
  - Update
    patches.suse/nilfs2-fix-missing-cleanup-on-rollforward-recovery-error.patch
    (git-fixes CVE-2024-46781 bsc#1230768).
  - Update
    patches.suse/nilfs2-protect-references-to-superblock-parameters-exposed-in-sysfs.patch
    (git-fixes CVE-2024-46780 bsc#1230808).
  - Update
    patches.suse/nouveau-firmware-use-dma-non-coherent-allocator.patch
    (git-fixes CVE-2024-45012 bsc#1230441).
  - Update
    patches.suse/nvmet-tcp-fix-kernel-crash-if-commands-allocation-fa.patch
    (git-fixes CVE-2024-46737 bsc#1230730).
  - Update
    patches.suse/pci-hotplug-pnv_php-Fix-hotplug-driver-crash-on-Powe.patch
    (stable-fixes CVE-2024-46761 bsc#1230761).
  - Update patches.suse/perf-Fix-event-leak-upon-exit.patch
    (git-fixes CVE-2024-43870 bsc#1229494).
  - Update
    patches.suse/pinctrl-single-fix-potential-NULL-dereference-in-pcs.patch
    (git-fixes CVE-2024-46685 bsc#1230515).
  - Update
    patches.suse/powerpc-qspinlock-Fix-deadlock-in-MCS-queue.patch
    (bac#1230295 ltc#206656 CVE-2024-46797 bsc#1230831).
  - Update
    patches.suse/powerpc-rtas-Prevent-Spectre-v1-gadget-construction-.patch
    (bsc#1227487 CVE-2024-46774 bsc#1230767).
  - Update
    patches.suse/s390-dasd-fix-error-recovery-leading-to-data-corruption-on-ESE-devices.patch
    (git-fixes bsc#1229452 CVE-2024-45026 bsc#1230454).
  - Update
    patches.suse/s390-sclp-Prevent-release-of-buffer-in-I-O.patch
    (git-fixes bsc#1229169 CVE-2024-44969 bsc#1230200).
  - Update
    patches.suse/soc-qcom-cmd-db-Map-shared-memory-as-WC-not-WB.patch
    (git-fixes CVE-2024-46689 bsc#1230524).
  - Update
    patches.suse/thunderbolt-Mark-XDomain-as-unplugged-when-router-is.patch
    (stable-fixes CVE-2024-46702 bsc#1230589).
  - Update
    patches.suse/tty-serial-fsl_lpuart-mark-last-busy-before-uart_add.patch
    (git-fixes CVE-2024-46706 bsc#1230580).
  - Update
    patches.suse/usb-dwc3-core-Prevent-USB-core-invalid-event-buffer-.patch
    (stable-fixes CVE-2024-46675 bsc#1230533).
  - Update
    patches.suse/usb-dwc3-st-fix-probed-platform-device-ref-count-on-.patch
    (git-fixes CVE-2024-46674 bsc#1230507).
  - Update
    patches.suse/usb-gadget-core-Check-for-unset-descriptor.patch
    (git-fixes CVE-2024-44960 bsc#1230191).
  - Update
    patches.suse/usb-typec-ucsi-Fix-null-pointer-dereference-in-trace.patch
    (stable-fixes CVE-2024-46719 bsc#1230722).
  - Update
    patches.suse/wifi-brcmfmac-cfg80211-Handle-SSID-based-pmksa-delet.patch
    (git-fixes CVE-2024-46672 bsc#1230459).
  - Update
    patches.suse/wifi-mwifiex-Do-not-return-unused-priv-in-mwifiex_ge.patch
    (stable-fixes CVE-2024-46755 bsc#1230802).
  - Update
    patches.suse/wifi-rtw88-usb-schedule-rx-work-after-everything-is-.patch
    (stable-fixes CVE-2024-46760 bsc#1230753).
  - Update
    patches.suse/x86-mm-Fix-pti_clone_pgtable-alignment-assumption.patch
    (git-fixes CVE-2024-44965 bsc#1230221).
  - Update
    patches.suse/x86-mtrr-Check-if-fixed-MTRRs-exist-before-saving-them.patch
    (git-fixes CVE-2024-44948 bsc#1230174).
  - Update
    patches.suse/xhci-Fix-Panther-point-NULL-pointer-deref-at-full-sp.patch
    (git-fixes CVE-2024-45006 bsc#1230247).
  - commit 6da06c4
  - Update patches.suse/gfs2-Fix-NULL-pointer-dereference-in-gfs2_log_flush.patch (bsc#1230948)
  - commit 90a5b1b

++++ libarchive:

  - Update to 3.7.6:
    * tar: clean up linkpath between entries
    * tar: fix memory leaks when processing symlinks or parsing pax headers
    * iso: be more cautious about parsing ISO-9660 timestamps
  - Version 3.7.5 changes:
    * fix multiple vulnerabilities identified by SAST
    * cpio: ignore out-of-range gid/uid/size/ino and harden AFIO parsing
    * lzop: prevent integer overflow
    * rar4: protect copy_from_lzss_window_to_unp() (CVE-2024-20696, bsc#1225971)
    * rar4: fix CVE-2024-26256 (CVE-2024-26256, bsc#1225972)
    * rar4: fix OOB in delta and audio filter
    * rar4: fix out of boundary access with large files
    * rar4: add boundary checks to rgb filter
    * rar4: fix OOB access with unicode filenames
    * rar5: clear 'data ready' cache on window buffer reallocs
    * rpm: calculate huge header sizes correctly
    * unzip: unify EOF handling
    * util: fix out of boundary access in mktemp functions
    * uu: stop processing if lines are too long
    * 7zip: fix issue when skipping first file in 7zip archive that is a multiple
    of 65536 bytes
    * ar: fix archive entries having no type
    * lha: do not allow negative file sizes
    * lha: fix integer truncation on 32-bit systems
    * shar: check strdup return value
    * rar5: don't try to read rediculously long names
    * xar: fix another infinite loop and expat error handling
    * many Windows fixes, cleanups and improvements
  - Drop fix-soversion.patch, fix-bsdunzip-test.patch
    * Fixed upstream

++++ toolbox:

  - Revert last change and update SLE/Leap Micro images to 5.5 (bsc#1227328)

------------------------------------------------------------------
------------------  2024-9-26  -  Sep 26 2024  -------------------
------------------------------------------------------------------

++++ audit-secondary:

  - Update audit-secondary.spec:
    * Add "Requires: audit-rules" for audit package
    * Remove preun/postun handling of audit-rules.service

++++ python-kiwi:

  - Bump version: 10.1.12 → 10.1.13
  - Fix bundle extension for vagrant type
    When bundling result files that uses a vagrant type,
    kiwi creates them with the extension .vagrant.virtualbox.box
    or .vagrant.libvirt.box. The bundler code renames them using
    only the .box suffix which is too short as it is missing
    the subformat information. This commit fixes it and keeps
    this information in the result bundle file name.
    This Fixes #2656
  - Use simple quotas (squota) for volumes

++++ glibc:

  - gen-tempname-randomness.patch: Fix missing randomness in __gen_tempname
    (bsc#1230965, BZ #32214)

++++ kernel-default:

  - userfaultfd: fix checks for huge PMDs (CVE-2024-46787
    bsc#1230815).
  - commit a236c90
  - cachefiles: Fix non-taking of sb_writers around set/removexattr
    (bsc#1231008).
  - commit 1b01b3e
  - RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds (git-fixes)
  - commit a6683f0
  - PCI: dwc: Expose dw_pcie_ep_exit() to module (git-fixes).
  - Refresh
    patches.suse/PCI-dwc-endpoint-Introduce-.pre_init-and-.deinit.patch.
  - commit 34c9950
  - PCI: xilinx-nwl: Clean up clock on probe failure/removal
    (git-fixes).
  - PCI: xilinx-nwl: Fix off-by-one in INTx IRQ handler (git-fixes).
  - PCI: qcom-ep: Enable controller resources like PHY only after
    refclk is available (git-fixes).
  - PCI: kirin: Fix buffer overflow in kirin_pcie_parse_port()
    (git-fixes).
  - PCI: keystone: Fix if-statement expression in ks_pcie_quirk()
    (git-fixes).
  - PCI: imx6: Fix missing call to phy_power_off() in error handling
    (git-fixes).
  - PCI: dra7xx: Fix error handling when IRQ request fails in probe
    (git-fixes).
  - PCI: dra7xx: Fix threaded IRQ request for "dra7xx-pcie-main"
    IRQ (git-fixes).
  - PCI: Wait for Link before restoring Downstream Buses
    (git-fixes).
  - commit 1528eee

++++ kernel-rt:

  - userfaultfd: fix checks for huge PMDs (CVE-2024-46787
    bsc#1230815).
  - commit a236c90
  - cachefiles: Fix non-taking of sb_writers around set/removexattr
    (bsc#1231008).
  - commit 1b01b3e
  - RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds (git-fixes)
  - commit a6683f0
  - PCI: dwc: Expose dw_pcie_ep_exit() to module (git-fixes).
  - Refresh
    patches.suse/PCI-dwc-endpoint-Introduce-.pre_init-and-.deinit.patch.
  - commit 34c9950
  - PCI: xilinx-nwl: Clean up clock on probe failure/removal
    (git-fixes).
  - PCI: xilinx-nwl: Fix off-by-one in INTx IRQ handler (git-fixes).
  - PCI: qcom-ep: Enable controller resources like PHY only after
    refclk is available (git-fixes).
  - PCI: kirin: Fix buffer overflow in kirin_pcie_parse_port()
    (git-fixes).
  - PCI: keystone: Fix if-statement expression in ks_pcie_quirk()
    (git-fixes).
  - PCI: imx6: Fix missing call to phy_power_off() in error handling
    (git-fixes).
  - PCI: dra7xx: Fix error handling when IRQ request fails in probe
    (git-fixes).
  - PCI: dra7xx: Fix threaded IRQ request for "dra7xx-pcie-main"
    IRQ (git-fixes).
  - PCI: Wait for Link before restoring Downstream Buses
    (git-fixes).
  - commit 1528eee

++++ libeconf:

  - Update to version 0.7.4:
    * Fixed memory leaks (#219)
    * Fixed: econf_readDirs crashes if one of the paths is NULL (#211)
    * Added links to man page. E.g. "man econf_readConfig" is working now.
    * Handle groups correctly which do not have any key entry.

++++ expat:

  - updated keyring [https://build.suse.de/request/show/345282]
  - modified sources
    % expat.keyring

++++ libnetfilter_conntrack:

  - Update to release 1.1.0
    * Enhancements for filtering dump and flush commands, see
    struct nfct_filter_dump and nfct_nlmsg_build_filter().
    * ctnetlink event BPF fixes (endianness issue, IPv6 matching)
    and enhancements (zone matching).

++++ patterns-base:

  - Bump to 6.1

++++ python-passlib:

  - Only run the full testsuite in openSUSE

------------------------------------------------------------------
------------------  2024-9-25  -  Sep 25 2024  -------------------
------------------------------------------------------------------

++++ bash:

  - Add upstream patches
    * bash52-037
    Fix the case where text to be completed from the line buffer (quoted) is
    compared to the common prefix of the possible matches (unquoted) and the
    quoting makes the former appear to be longer than the latter. Readline
    assumes the match doesn't add any characters to the word and doesn't display
    multiple matches.
    * bash52-036
    When readline is accumulating bytes until it reads a complete multibyte
    character, reading a byte that makes the multibyte character invalid can
    result in discarding the bytes in the partial character.
    * bash52-035
    There are systems that supply one of select or pselect, but not both.
    * bash52-034
    If we parse a compound assignment during an alias expansion, it's possible
    to have the current input string popped out from underneath the parse. In
    this case, we should not restore the input we were using when we began to
    parse the compound assignment.
    * bash52-033
    A typo in the autoconf test for strtold causes false negatives for strtold
    being available and working when compiled with gcc-14.
  - Port patch bash-3.2-printf.patch to fit change in bash52-033

++++ python-kiwi:

  - Add quota attribute to volume section
    Allow to set quota per volume for the btrfs filesystem
    This Fixes #2651

++++ filesystem:

  - Move /srv/www hierachy to the packages which use them
    [bsc#1231027]

++++ fwupd:

  - Update to version 1.9.25:
    + This release fixes the following bugs:
  - Fix checking new Synaptics MST firmware size
  - Make another ModemManager instance ID visible for firmware
    matching
  - Never set a zero-length device name when matching the vendor
    name
  - Recalculate the device supported flag when reparenting
    devices
  - Reduce idle power consumption of paired logitech-hidpp
    devices
  - Retry the open action to fix BC901 NVMe reload
    + This release adds support for the following hardware:
  - Algoltek devices supporting sector erase
  - Dell K2 dock
  - Intel USB4 hub 5787
  - More MediaTek scaler devices
  - Nordic HID devices supporting DFUv1

++++ health-checker:

  - Update to version 1.12+git20240925.08fb1bc:
    * Release version 1.12
    * Fix typos: replaced `health-checker.state` occurances with
    `health-check.state` (#23)
    * Improve rpmdb consistency check (#21)
    * Drop crio, etcd and kubelet
    * Implement missing stop argument
  - Remove plugins-kubic and plugins-caasp packages - the tests were
    removed upstream because the products were EOL

++++ kernel-default:

  - WIP DO NOT PUSH btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk() (CVE-2024-46687 bsc#1230518)
  - commit 17b4a47
  - exfat: fix memory leak in exfat_load_bitmap() (git-fixes).
  - commit 9f477b0
  - net: ip_tunnel: prevent perpetual headroom growth
    (CVE-2024-26804 bsc#1222629).
  - commit 0ca3b23
  - Input: ps2-gpio - use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - commit 45cee3b
  - Input: ilitek_ts_i2c - avoid wrong input subsystem sync
    (git-fixes).
  - commit e5e587b
  - Input: tsc2004/5 - fix reset handling on probe (git-fixes).
  - commit 1366de4
  - Input: tsc2004/5 - do not hard code interrupt trigger
    (git-fixes).
  - commit 110dbdb
  - Input: tsc2004/5 - use device core to create driver-specific
    device attributes (git-fixes).
  - commit 958966c
  - Input: adp5588-keys - fix check on return code (git-fixes).
  - commit d15133c
  - drm/amd/display: Fix incorrect size calculation for loop (bsc#1230704 CVE-2024-46729)
  - commit 55d78a7
  - RDMA/hns: Fix ah error counter in sw stat not increasing (git-fixes)
  - commit d7bebcf
  - RDMA/mlx5: Fix MR cache temp entries cleanup (git-fixes)
  - commit b0aa848
  - RDMA/mlx5: Drop redundant work canceling from clean_keys() (git-fixes)
  - commit 6800d7e
  - RDMA/irdma: fix error message in irdma_modify_qp_roce() (git-fixes)
  - commit dcf63e1
  - RDMA/cxgb4: Added NULL check for lookup_atid (git-fixes)
  - commit 23d3195
  - RDMA/mlx5: Obtain upper net device only when needed (git-fixes)
  - commit ca2d8dc
  - RDMA/hns: Fix restricted __le16 degrades to integer issue (git-fixes)
  - commit 4481358
  - RDMA/hns: Optimize hem allocation performance (git-fixes)
  - commit 7afe440
  - RDMA/hns: Fix 1bit-ECC recovery address in non-4K OS (git-fixes)
  - commit 25e36c2
  - RDMA/hns: Fix VF triggering PF reset in abnormal interrupt handler (git-fixes)
  - commit a18704a
  - RDMA/hns: Fix spin_unlock_irqrestore() called with IRQs enabled (git-fixes)
  - commit 7b15e64
  - RDMA/hns: Fix the overflow risk of hem_list_calc_ba_range() (git-fixes)
  - commit 60eb35c
  - RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08 (git-fixes)
  - commit 3ab1ca2
  - RDMA/hns: Don't modify rq next block addr in HIP09 QPC (git-fixes)
  - commit 7100eb8
  - RDMA/mlx5: Limit usage of over-sized mkeys from the MR cache (git-fixes)
  - commit 914ed66
  - RDMA/mlx5: Fix counter update on MR cache mkey creation (git-fixes)
  - commit 60e75bb
  - RDMA/erdma: Return QP state in erdma_query_qp (git-fixes)
  - commit 09a59c3
  - IB/core: Fix ib_cache_setup_one error flow cleanup (git-fixes)
  - commit 38bf526
  - RDMA/rtrs: Reset hb_missed_cnt after receiving other traffic from peer (git-fixes)
  - commit c4f28a8
  - RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency (git-fixes)
  - commit 0456b72
  - RDMA/core: Remove unused declaration rdma_resolve_ip_route() (git-fixes)
  - commit 4cb7201
  - Revert "PCI: Extend ACS configurability (bsc#1228090)." (bsc#1229019)
    This reverts commit 571e4310e81312c847a5caee7e45e66aeea2a169. It breaks
    ACS on certain platforms. Even 6.11 is affected. So drop for now and
    investigate.
  - commit 3b92a44

++++ kernel-rt:

  - WIP DO NOT PUSH btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk() (CVE-2024-46687 bsc#1230518)
  - commit 17b4a47
  - exfat: fix memory leak in exfat_load_bitmap() (git-fixes).
  - commit 9f477b0
  - net: ip_tunnel: prevent perpetual headroom growth
    (CVE-2024-26804 bsc#1222629).
  - commit 0ca3b23
  - Input: ps2-gpio - use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - commit 45cee3b
  - Input: ilitek_ts_i2c - avoid wrong input subsystem sync
    (git-fixes).
  - commit e5e587b
  - Input: tsc2004/5 - fix reset handling on probe (git-fixes).
  - commit 1366de4
  - Input: tsc2004/5 - do not hard code interrupt trigger
    (git-fixes).
  - commit 110dbdb
  - Input: tsc2004/5 - use device core to create driver-specific
    device attributes (git-fixes).
  - commit 958966c
  - Input: adp5588-keys - fix check on return code (git-fixes).
  - commit d15133c
  - drm/amd/display: Fix incorrect size calculation for loop (bsc#1230704 CVE-2024-46729)
  - commit 55d78a7
  - RDMA/hns: Fix ah error counter in sw stat not increasing (git-fixes)
  - commit d7bebcf
  - RDMA/mlx5: Fix MR cache temp entries cleanup (git-fixes)
  - commit b0aa848
  - RDMA/mlx5: Drop redundant work canceling from clean_keys() (git-fixes)
  - commit 6800d7e
  - RDMA/irdma: fix error message in irdma_modify_qp_roce() (git-fixes)
  - commit dcf63e1
  - RDMA/cxgb4: Added NULL check for lookup_atid (git-fixes)
  - commit 23d3195
  - RDMA/mlx5: Obtain upper net device only when needed (git-fixes)
  - commit ca2d8dc
  - RDMA/hns: Fix restricted __le16 degrades to integer issue (git-fixes)
  - commit 4481358
  - RDMA/hns: Optimize hem allocation performance (git-fixes)
  - commit 7afe440
  - RDMA/hns: Fix 1bit-ECC recovery address in non-4K OS (git-fixes)
  - commit 25e36c2
  - RDMA/hns: Fix VF triggering PF reset in abnormal interrupt handler (git-fixes)
  - commit a18704a
  - RDMA/hns: Fix spin_unlock_irqrestore() called with IRQs enabled (git-fixes)
  - commit 7b15e64
  - RDMA/hns: Fix the overflow risk of hem_list_calc_ba_range() (git-fixes)
  - commit 60eb35c
  - RDMA/hns: Fix Use-After-Free of rsv_qp on HIP08 (git-fixes)
  - commit 3ab1ca2
  - RDMA/hns: Don't modify rq next block addr in HIP09 QPC (git-fixes)
  - commit 7100eb8
  - RDMA/mlx5: Limit usage of over-sized mkeys from the MR cache (git-fixes)
  - commit 914ed66
  - RDMA/mlx5: Fix counter update on MR cache mkey creation (git-fixes)
  - commit 60e75bb
  - RDMA/erdma: Return QP state in erdma_query_qp (git-fixes)
  - commit 09a59c3
  - IB/core: Fix ib_cache_setup_one error flow cleanup (git-fixes)
  - commit 38bf526
  - RDMA/rtrs: Reset hb_missed_cnt after receiving other traffic from peer (git-fixes)
  - commit c4f28a8
  - RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency (git-fixes)
  - commit 0456b72
  - RDMA/core: Remove unused declaration rdma_resolve_ip_route() (git-fixes)
  - commit 4cb7201
  - Revert "PCI: Extend ACS configurability (bsc#1228090)." (bsc#1229019)
    This reverts commit 571e4310e81312c847a5caee7e45e66aeea2a169. It breaks
    ACS on certain platforms. Even 6.11 is affected. So drop for now and
    investigate.
  - commit 3b92a44

++++ harfbuzz:

  - Update to version 10.0.1:
    + Relax sanitization checks for “morx” subtables to fix broken
    AAT shaping of macOS 15.0 version of GeezaPro.
  - Switch to source service for tarball.

++++ samba:

  - Support needed packaging changes required update to samba-4.21.0
    Update samba.spec, baselibs.conf to deliver libldb packages.

++++ libpcap:

  - enable rdma support (bsc#1230894)

++++ microos-tools:

  - Update to version 2.21+git16:
    * selinux: Avoid parameter duplication
    * 98selinux-microos: Use a single thread for relabelling /etc
    * Use all cores for SELinux restorecon (related to jsc#SMO-382)
  - _service: Omit +git0 suffix in versions

++++ openssh:

  - Add a const to the openssl 1.1/RSA section of sshkey_is_private
    to keep it similar to what it used before the 9.9 rebase:
    * openssh-8.1p1-audit.patch
  - Add a openssl11 bcond to the spec file for the SLE12 case
    instead of checking suse_version in different parts.
  - Move conditional patches to a number >= 1000.

++++ python-lxml:

  - 5.3.0 (2024-08-10)
    Features added
  - GH#421: Nested CDATA sections are no longer rejected but split
    on output to represent ]]> correctly. Patch by Gertjan Klein.
    Bugs fixed
  - LP#2060160: Attribute values serialised differently in
    xmlfile.element() and xmlfile.write().
  - LP#2058177: The ISO-Schematron implementation could fail on
    unknown prefixes. Patch by David Lakin.
    Other changes
  - LP#2067707: The strip_cdata option in HTMLParser() turned out
    to be useless and is now deprecated.
  - Built with Cython 3.0.11.

++++ selinux-policy:

  - Update to version 20240604+git382.24f674cf:
    * Allow snapperd to manage unlabeled_t files (bsc#1230966)

------------------------------------------------------------------
------------------  2024-9-24  -  Sep 24 2024  -------------------
------------------------------------------------------------------

++++ curl:

  - Update to 8.10.1:
    * Bugfixes:
  - autotools: fix `--with-ca-embed` build rule
  - cmake: ensure `CURL_USE_OPENSSL`/`USE_OPENSSL_QUIC` are set in sync
  - cmake: fix MSH3 to appear on the feature list
  - connect: store connection info when really done
  - FTP: partly revert eeb7c1280742f5c8fa48a4340fc1e1a1a2c7075a
  - http2: when uploading data from stdin, fix eos forwarding
  - http: make max-filesize check not count ignored bodies
  - lib: fix AF_INET6 use outside of USE_IPV6
  - multi: check that the multi handle is valid in curl_multi_assign
  - QUIC: on connect, keep on trying on draining server
  - request: correctly reset the eos_sent flag
  - setopt: remove superfluous use of ternary expressions
  - singleuse: drop `Curl_memrchr()` for no-HTTP builds
  - tool_cb_wrt: use "curl_response" if no file name in URL
  - transfer: fix sendrecv() without interim poll
  - vtls: fix `Curl_ssl_conn_config_match` doc param

++++ python-kiwi:

  - Fix globbing with exclude with regex
    This fixes a collection of bugs when producing erofs images.
    On one hand, this ensures that an exclude of `/sys` doesn't accidentally
    match `/lib/libsystemd.so`, only `/sys/whatever`.
    On the other hand, this ensures that `/dev/*` does match `/dev/vda` and
    not just `/dev///////////`.
    This fixes libsystemd.so getting dropped in Kiwi-built FEX images.
    Signed-off-by: Alyssa Rosenzweig <alyssa@rosenzweig.io>
  - Honour custom exclude for filesystem builds
    All other call sites honour the custom exclude file, it's just this one
    that needs to be fixed. This unblocks use of Kiwi for generating FEX
    rootfs.
    Closes: #2652
    Signed-off-by: Alyssa Rosenzweig <alyssa@rosenzweig.io>

++++ transactional-update:

  - Version 4.8.3
  - Check return value of register command [bsc#1230901]

++++ jeos-firstboot:

  - Add dependency on cracklib for cracklib-check

++++ kernel-default:

  - btrfs: handle errors from btrfs_dec_ref() properly (CVE-2024-46753 bsc#1230796)
  - commit 3e3b2cb
  - media: vicodec: allow en/decoder cmd w/o CAPTURE (git-fixes).
  - commit 62ef4d1
  - media: qcom: camss: Remove use_count guard in stop_streaming
    (git-fixes).
  - commit ef85228
  - Revert "media: tuners: fix error return code of
    hybrid_tuner_request_state()" (git-fixes).
  - drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds
    write error (git-fixes).
  - drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds
    write error (git-fixes).
  - commit 48dc3a9
  - net: bridge: xmit: make sure we have at least eth header len
    bytes (CVE-2024-38538 bsc#1226606).
  - commit 2548071
  - PKCS#7: Check codeSigning EKU of certificates in PKCS#7
    (bsc#1226666).
  - commit dbae63e

++++ kernel-rt:

  - btrfs: handle errors from btrfs_dec_ref() properly (CVE-2024-46753 bsc#1230796)
  - commit 3e3b2cb
  - media: vicodec: allow en/decoder cmd w/o CAPTURE (git-fixes).
  - commit 62ef4d1
  - media: qcom: camss: Remove use_count guard in stop_streaming
    (git-fixes).
  - commit ef85228
  - Revert "media: tuners: fix error return code of
    hybrid_tuner_request_state()" (git-fixes).
  - drivers: media: dvb-frontends/rtl2830: fix an out-of-bounds
    write error (git-fixes).
  - drivers: media: dvb-frontends/rtl2832: fix an out-of-bounds
    write error (git-fixes).
  - commit 48dc3a9
  - net: bridge: xmit: make sure we have at least eth header len
    bytes (CVE-2024-38538 bsc#1226606).
  - commit 2548071
  - PKCS#7: Check codeSigning EKU of certificates in PKCS#7
    (bsc#1226666).
  - commit dbae63e

++++ sqlite3:

  - Update to release 3.46.1:
    * Improved robustness while parsing the tokenize= arguments in
    FTS5.
    * Enhancements to covering index prediction in the query planner.
    * Do not let the number of terms on a VALUES clause be limited by
    SQLITE_LIMIT_COMPOUND_SELECT, even if the VALUES clause
    contains elements that appear to be variables due to
    double-quoted string literals.
    * Fix the window function version of group_concat() so that it
    returns an empty string if it has one or more empty string
    inputs.
    * In FTS5 secure-delete mode, fix false-positive integrity-check
    reports about corrupt indexes.
    * Syntax errors in ALTER TABLE should always return SQLITE_ERROR.
    In some cases, they were formerly returning SQLITE_INTERNAL.
    * Other minor fixes.

++++ pam_pkcs11:

  - Fix for boo#1230870:
    * Add patch 0001-memory-leak-fixes.patch
  - Add -Wno-implicit-function-declaration to CFLAGS to fix build
    with gcc14 and newer

++++ python-Jinja2:

  - Fix build error under Leap.

++++ python-oauthlib:

  - Fix build error under Leap.

++++ python-pyserial:

  - Fix build error under Leap.

++++ selinux-policy:

  - Fix macros.selinux-policy (bsc#1230897)
  - %selinux_relabel_post should not relabel files in
    transactional systems in %post as the policy is not loaded
    into the kernel directly after install, instead the relabelling
    will happen on the next boot

++++ toolbox:

  - Update SLE/Leap Micro images from 5.4 to 6.0 (bsc#1227328)

------------------------------------------------------------------
------------------  2024-9-23  -  Sep 23 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - libvdpau_gallium was linked directly into libgallium-*.so.*.
    Drop the subpackage and provides/obsolete it via Mesa-dri which
    ships libgallium-*.so.*.
  - drop u_fix_rust_bindgen.patch
    included in update
  - Update to release 24.2.3
  - -> https://docs.mesa3d.org/relnotes/24.2.3
  - disable build of rusticl on sle15; meson is just too old ...
  - buildrequires: rusticl needs mesa >= 1.4.0
  - tlsdesc_test.patch: disable LTO in tlsdesc_test to suppress TLS
    relaxation (patch by Andreas Schwab <schwab@suse.de>); see also
    https://gitlab.freedesktop.org/mesa/mesa/-/issues/11929
  - buildrequire llvm19-devel/clang19-devel on sle15-sp7

++++ Mesa-drivers:

  - libvdpau_gallium was linked directly into libgallium-*.so.*.
    Drop the subpackage and provides/obsolete it via Mesa-dri which
    ships libgallium-*.so.*.
  - drop u_fix_rust_bindgen.patch
    included in update
  - Update to release 24.2.3
  - -> https://docs.mesa3d.org/relnotes/24.2.3
  - disable build of rusticl on sle15; meson is just too old ...
  - buildrequires: rusticl needs mesa >= 1.4.0
  - tlsdesc_test.patch: disable LTO in tlsdesc_test to suppress TLS
    relaxation (patch by Andreas Schwab <schwab@suse.de>); see also
    https://gitlab.freedesktop.org/mesa/mesa/-/issues/11929
  - buildrequire llvm19-devel/clang19-devel on sle15-sp7

++++ ModemManager:

  - Update to version 1.22.0:
    + A new "MSG" (message) log verbosity level is introduced, which
    is also the new default one if none explicitly defined. This
    level takes the place of the old "INFO" level, as a level
    including the most important messages that should be logged
    without needing to be warnings or errors. The new "INFO" level
    is more verbose than "MSG" but less verbose than "DBG", and may
    be useful as default in systems where active debugging of WWAN
    related issues is required. E.g. all user operations triggered
    via DBus method calls are logged in "INFO" level.
    + Introduced the concept of "personal information" which should
    by default not be included in log messages. Enabling personal
    information in logs requires to run the daemon with the
    '--log-personal-info' option. This feature is mostly
    implemented for QMI and MBIM specific logs, but hasn't yet been
    included in generic daemon logs or when using the AT protocol.
    Changes and fixes related to this feature will be cherry-picked
    and included in the future stable branch updates.
  - Update URL and Source adresses.

++++ python-kiwi:

  - test: storage: update clone_device tests with new block size
    Signed-off-by: Isaac True <isaac@is.having.coffee>

++++ gstreamer:

  - Update to version 1.24.8:
    + Highlighted bugfixes:
  - decodebin3: collection handling fixes
  - encodebin: Fix pad removal (and smart rendering in
    gst-editing-services)
  - glimagesink: Fix cannot resize viewport when video size
    changed in caps
  - matroskamux, webmmux: fix firefox compatibility issue with
    Opus audio streams
  - mpegtsmux: Wait for data on all pads before deciding on a
    best pad unless timing out
  - splitmuxsink: Override LATENCY query to pretend to downstream
    that we're not live
  - video: QoS event handling improvements
  - voamrwbenc: fix list of bitrates
  - vtenc: Restart encoding session when certain errors are
    detected
  - wayland: Fix ABI break in WL context type name
  - webrtcbin: Prevent crash when attempting to set answer on
    invalid SDP
  - cerbero: ship vp8/vp9 software encoders again, which went
    missing in 1.24.7; ship transcode plugin
  - Various bug fixes, memory leak fixes, and other stability and
    reliability improvements
    + gstreamer:
  - clock: Fix unchecked overflows in linear regression code
  - meta: Add missing include of gststructure.h
  - pad: Check data NULL-ness when probes are stopped
  - aggregator: Immediately return NONE from
    simple_get_next_time() on non-TIME segments

++++ gstreamer-plugins-base:

  - Update to version 1.24.8:
    + decodebin3: Fix collection identity check
    + encodebin: Fix pad removal
    + glimagesink: Fix cannot resize viewport when video size changed
    in caps
    + video: Don't overshoot QoS earliest time by a factor of 2
    + meson: gst-play: link to libm
  - Drop gst-plugins-base-decodebin3-collection-identity-check.patch:
    Fixed upstream.
  - Rebase add_wayland_dep_to_tests.patch with quilt.

++++ kernel-default:

  - xen/swiotlb: fix allocated size (git-fixes).
  - commit 199871d
  - xen/swiotlb: add alignment check for dma buffers (bsc#1229928).
  - commit 0ffbc04
  - xen: tolerate ACPI NVS memory overlapping with Xen allocated
    memory (bsc#1226003).
  - commit 3dc14d8
  - xen: allow mapping ACPI data using a different physical address
    (bsc#1226003).
  - commit 0928eec
  - x86/tdx: Fix data leak in mmio_read() (CVE-2024-46794 bsc#1230825)
  - commit 9a2a1c2
  - tcp_bpf: fix return value of tcp_bpf_sendmsg() (CVE-2024-46783 bsc#1230810)
  - commit eb9d143
  - nvme: fix namespace removal list (git-fixes).
  - commit b45d192
  - ublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery() (CVE-2024-46735 bsc#1230727)
  - commit 23e039f
  - Update references for patches.suse/nvmet-tcp-fix-kernel-crash-if-commands-allocation-fa.patch (CVE-2024-46737 bsc#1230730)
  - commit 8ce7f58
  - xen: add capability to remap non-RAM pages to different PFNs
    (bsc#1226003).
  - commit 47109fd
  - net/mlx5e: SHAMPO, Fix incorrect page release (CVE-2024-46717 bsc#1230719)
  - commit d6a30a9
  - xen: move max_pfn in xen_memory_setup() out of function scope
    (bsc#1226003).
  - commit 2750357
  - xen: move checks for e820 conflicts further up (bsc#1226003).
  - commit 191a602
  - xen: introduce generic helper checking for memory map conflicts
    (bsc#1226003).
  - commit eb57cec
  - xen: use correct end address of kernel for conflict checking
    (bsc#1226003).
  - commit c40fc6b
  - scsi: lpfc: Copyright updates for 14.4.0.4 patches (bsc#1229429
    jsc#PED-9899).
  - scsi: lpfc: Update lpfc version to 14.4.0.4 (bsc#1229429
    jsc#PED-9899).
  - scsi: lpfc: Update PRLO handling in direct attached topology
    (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Fix unsolicited FLOGI kref imbalance when in direct
    attached topology (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Fix unintentional double clearing of vmid_flag
    (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Validate hdwq pointers before dereferencing in
    reset/errata paths (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Remove redundant vport assignment when building
    an abort request (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Change diagnostic log flag during receipt of
    unknown ELS cmds (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Fix overflow build issue (bsc#1229429 jsc#PED-9899).
  - commit 18ec475
  - drm/vmwgfx: Prevent unmapping active read buffers (bsc#1230540 CVE-2024-46710)
  - commit 84f019d
  - nvme-tcp: fix link failure for TCP auth (git-fixes).
  - nvmet: Identify-Active Namespace ID List command should reject
    invalid nsid (git-fixes).
  - nvme-pci: Add sleep quirk for Samsung 990 Evo (git-fixes).
  - nvme-pci: allocate tagset on reset if necessary (git-fixes).
  - nvmet-tcp: fix kernel crash if commands allocation fails
    (git-fixes).
  - nvme/pci: Add APST quirk for Lenovo N60z laptop (git-fixes).
  - nvme: use srcu for iterating namespace list (git-fixes).
    Refresh:
  - patches.suse/nvme-tcp-sanitize-tls-key-handling.patch
  - nvmet-rdma: fix possible bad dereference when freeing rsps
    (git-fixes).
  - nvmet-tcp: do not continue for invalid icreq (git-fixes).
  - nvme: clear caller pointer on identify failure (git-fixes).
  - nvmet-trace: avoid dereferencing pointer too early (git-fixes).
  - commit 7382ad4
  - Update
    patches.suse/KVM-arm64-vgic-v2-Check-for-non-NULL-vCPU-in-vgic_v2.patch
    (git-fixes CVE-2024-36953 bsc#1225812).
  - Update
    patches.suse/vfio-pci-fix-potential-memory-leak-in-vfio_intx_enab.patch
    (git-fixes CVE-2024-38632 bsc#1226860).
    Add CVE references.
  - commit c9c3b6f

++++ kernel-rt:

  - xen/swiotlb: fix allocated size (git-fixes).
  - commit 199871d
  - xen/swiotlb: add alignment check for dma buffers (bsc#1229928).
  - commit 0ffbc04
  - xen: tolerate ACPI NVS memory overlapping with Xen allocated
    memory (bsc#1226003).
  - commit 3dc14d8
  - xen: allow mapping ACPI data using a different physical address
    (bsc#1226003).
  - commit 0928eec
  - x86/tdx: Fix data leak in mmio_read() (CVE-2024-46794 bsc#1230825)
  - commit 9a2a1c2
  - tcp_bpf: fix return value of tcp_bpf_sendmsg() (CVE-2024-46783 bsc#1230810)
  - commit eb9d143
  - nvme: fix namespace removal list (git-fixes).
  - commit b45d192
  - ublk_drv: fix NULL pointer dereference in ublk_ctrl_start_recovery() (CVE-2024-46735 bsc#1230727)
  - commit 23e039f
  - Update references for patches.suse/nvmet-tcp-fix-kernel-crash-if-commands-allocation-fa.patch (CVE-2024-46737 bsc#1230730)
  - commit 8ce7f58
  - xen: add capability to remap non-RAM pages to different PFNs
    (bsc#1226003).
  - commit 47109fd
  - net/mlx5e: SHAMPO, Fix incorrect page release (CVE-2024-46717 bsc#1230719)
  - commit d6a30a9
  - xen: move max_pfn in xen_memory_setup() out of function scope
    (bsc#1226003).
  - commit 2750357
  - xen: move checks for e820 conflicts further up (bsc#1226003).
  - commit 191a602
  - xen: introduce generic helper checking for memory map conflicts
    (bsc#1226003).
  - commit eb57cec
  - xen: use correct end address of kernel for conflict checking
    (bsc#1226003).
  - commit c40fc6b
  - scsi: lpfc: Copyright updates for 14.4.0.4 patches (bsc#1229429
    jsc#PED-9899).
  - scsi: lpfc: Update lpfc version to 14.4.0.4 (bsc#1229429
    jsc#PED-9899).
  - scsi: lpfc: Update PRLO handling in direct attached topology
    (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Fix unsolicited FLOGI kref imbalance when in direct
    attached topology (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Fix unintentional double clearing of vmid_flag
    (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Validate hdwq pointers before dereferencing in
    reset/errata paths (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Remove redundant vport assignment when building
    an abort request (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Change diagnostic log flag during receipt of
    unknown ELS cmds (bsc#1229429 jsc#PED-9899).
  - scsi: lpfc: Fix overflow build issue (bsc#1229429 jsc#PED-9899).
  - commit 18ec475
  - drm/vmwgfx: Prevent unmapping active read buffers (bsc#1230540 CVE-2024-46710)
  - commit 84f019d
  - nvme-tcp: fix link failure for TCP auth (git-fixes).
  - nvmet: Identify-Active Namespace ID List command should reject
    invalid nsid (git-fixes).
  - nvme-pci: Add sleep quirk for Samsung 990 Evo (git-fixes).
  - nvme-pci: allocate tagset on reset if necessary (git-fixes).
  - nvmet-tcp: fix kernel crash if commands allocation fails
    (git-fixes).
  - nvme/pci: Add APST quirk for Lenovo N60z laptop (git-fixes).
  - nvme: use srcu for iterating namespace list (git-fixes).
    Refresh:
  - patches.suse/nvme-tcp-sanitize-tls-key-handling.patch
  - nvmet-rdma: fix possible bad dereference when freeing rsps
    (git-fixes).
  - nvmet-tcp: do not continue for invalid icreq (git-fixes).
  - nvme: clear caller pointer on identify failure (git-fixes).
  - nvmet-trace: avoid dereferencing pointer too early (git-fixes).
  - commit 7382ad4
  - Update
    patches.suse/KVM-arm64-vgic-v2-Check-for-non-NULL-vCPU-in-vgic_v2.patch
    (git-fixes CVE-2024-36953 bsc#1225812).
  - Update
    patches.suse/vfio-pci-fix-potential-memory-leak-in-vfio_intx_enab.patch
    (git-fixes CVE-2024-38632 bsc#1226860).
    Add CVE references.
  - commit c9c3b6f

++++ harfbuzz:

  - Update to version 10.0.0:
    + Unicode 16.0.0 support.
    + Various documentation fixes.
    + Various build fixes.
    + Add API to allow HarfBuzz client to set what glyph to use when
    a Unicode Variation Selector is not supported by the font,
    which would allow the client to customize what happens in this
    case, by using a different font for example.
    + Add a callback to for “hb_face_t” for getting the list of table
    tags. This is now used to make calling
    “hb_face_get_table_tags()” work on a faces created by
    “hb_face_create_for_tables()” (e.g. faces returned by
    “hb_subset_or_fail()”).
    + CGJ and Mongolian Variation Selectors are now ignored during
    glyph positioning, previously they would block both glyph
    substitution and positioning across them.
    + Support cairo script as an output format for “hb-view” command
    line tool.
    + Drop an optimization that would cause HarfBuzz not apply pair
    positioning lookup subtables under certain circumstances, for
    compatibility with other implementations that do apply these
    subtables.
    + Subsetting will now fail if source font has no glyphs, so
    feeding the subsetter invalid data will not silently return an
    empty face.
    + If after partially instancing a font no variation data is left
    (the instance is fully static), don’t consider this a failure.
    + Workaround a Firefox bug in displaying SVGs generated be
    “hb-view” command line tool under certain circumstances.
    + Fix bug in macroman mapping for “cmap” table.
    + Fix difference shaping output when HarfBuzz is built with with
    “HB_NO_OT_RULESETS_FAST_PATH” enabled.
    + Various subsetting and instancing fixes.
    + Various fuzzing fixes.
    + Add “with_libstdcxx” meson build option.

++++ libmbim:

  - Update to version 1.30.0:
    + New Intel Mutual Authentication service
    + New Intel Tools service
    + New Google service
    + Extended the Microsoft-defined Basic Connect Extensions service
  - Drop patches included upstream:
    + 0001-intel-mutual-authentication-new-service-fcc-lock.patch
    + 0002-intel-tools-new-service-trace-config.patch

++++ ncurses:

  - Add ncurses patch 20240922
    + add a few null-pointer checks in ncurses
    + improve test-driver in ncurses/link_test.c
    + restore background character in manpages as described in X/Open
    Curses section 3.3.6, and add option "-c" to test programs to
    illustrate a non-blank character in the window background property.
    + improve formatting/style of manpages (patches by Branden Robinson).
    + modify ncurses*-config to add -I option in --cflag where needed for
  - -disable-overwrite to match ".pc" files.
    + disallow directories and block/character devices in safe-open.
    + amend scr_restore() and scr_init() to remove the target window only
    after validating the source window which will replace the target
    (report by Zixi Liu).

++++ orc:

  - Update to version 0.4.40:
    + Security: Minor follow-up fixes for CVE-2024-40897
    + Fix include header use from C++
    + orccodemem: Assorted memory mapping fixes
    + powerpc: fix div255w which still used the inexact substitution
    + powerpc: Disable VSX and ISA 2.07 for Apple targets
    + powerpc: Allow detection of ppc64 in Mac OS
    + x86: work around old GCC versions (pre 9.0) having broken
    xgetbv implementationsv
    + x86: consider MSYS2/Cygwin as Windows for ABI purposes only
    + x86: handle unnatural and misaligned array pointers
    + x86: Fix non-C11 typedefs
    + x86: try fixing AVX detection again by adding check for XSAVE
    + Some compatibility fixes for Musl
    + meson: Fix detecting XSAVE on older AppleClangv
    + Check return values of malloc() and realloc()

++++ openssh:

  - Update to openssh 9.9p1:
    = Future deprecation notice
    * OpenSSH plans to remove support for the DSA signature algorithm
    in early 2025. This release disables DSA by default at compile
    time. DSA, as specified in the SSHv2 protocol, is inherently
    weak - being limited to a 160 bit private key and use of the
    SHA1 digest. Its estimated security level is only 80 bits
    symmetric equivalent.
    OpenSSH has disabled DSA keys by default since 2015 but has
    retained run-time optional support for them. DSA was the only
    mandatory-to-implement algorithm in the SSHv2 RFCs, mostly
    because alternative algorithms were encumbered by patents when
    the SSHv2 protocol was specified.
    This has not been the case for decades at this point and better
    algorithms are well supported by all actively-maintained SSH
    implementations. We do not consider the costs of maintaining
    DSA in OpenSSH to be justified and hope that removing it from
    OpenSSH can accelerate its wider deprecation in supporting
    cryptography libraries.
    = Potentially-incompatible changes
    * ssh(1): remove support for pre-authentication compression.
    OpenSSH has only supported post-authentication compression in
    the server for some years. Compression before authentication
    significantly increases the attack surface of SSH servers and
    risks creating oracles that reveal information about
    information sent during authentication.
    * ssh(1), sshd(8): processing of the arguments to the "Match"
    configuration directive now follows more shell-like rules for
    quoted strings, including allowing nested quotes and \-escaped
    characters. If configurations contained workarounds for the
    previous simplistic quote handling then they may need to be
    adjusted. If this is the case, it's most likely to be in the
    arguments to a "Match exec" confition. In this case, moving the
    command to be evaluated from the Match line to an external
    shell script is easiest way to preserve compatibility with both
    the old and new versions.
    = New features
    * ssh(1), sshd(8): add support for a new hybrid post-quantum key
    exchange based on the FIPS 203 Module-Lattice Key Enapsulation
    mechanism (ML-KEM) combined with X25519 ECDH as described by
    https://datatracker.ietf.org/doc/html/draft-kampanakis-curdle-ssh-pq-ke-03
    This algorithm "mlkem768x25519-sha256" is available by default.
    * ssh(1): the ssh_config "Include" directive can now expand
    environment as well as the same set of %-tokens "Match Exec"
    supports.
    * sshd(8): add a sshd_config "RefuseConnection" option that, if
    set will terminate the connection at the first authentication
    request.
    * sshd(8): add a "refuseconnection" penalty class to sshd_config
    PerSourcePenalties that is applied when a connection is dropped
    by the new RefuseConnection keyword.
    * sshd(8): add a "Match invalid-user" predicate to sshd_config
    Match options that matches when the target username is not
    valid on the server.
    * ssh(1), sshd(8): update the Streamlined NTRUPrime code to a
    substantially faster implementation.
    * ssh(1), sshd(8): the hybrid Streamlined NTRUPrime/X25519 key
    exchange algorithm now has an IANA-assigned name in addition to
    the "@openssh.com" vendor extension name. This algorithm is now
    also available under this name "sntrup761x25519-sha512"
    * ssh(1), sshd(8), ssh-agent(1): prevent private keys from being
    included in core dump files for most of their lifespans. This
    is in addition to pre-existing controls in ssh-agent(1) and
    sshd(8) that prevented coredumps. This feature is supported on
    OpenBSD, Linux and FreeBSD.
    * All: convert key handling to use the libcrypto EVP_PKEY API,
    with the exception of DSA.
    * sshd(8): add a random amount of jitter (up to 4 seconds) to the
    grace login time to make its expiry unpredictable.
    = Bugfixes
    * sshd(8): relax absolute path requirement back to what it was
    prior to OpenSSH 9.8, which incorrectly required that sshd was
    started with an absolute path in inetd mode. bz3717
    * sshd(8): fix regression introduced in openssh-9.8 that swapped
    the order of source and destination addresses in some sshd log
    messages.
    * sshd(8): do not apply authorized_keys options when signature
    verification fails. Prevents more restrictive key options being
    incorrectly applied to subsequent keys in authorized_keys.
    bz3733
    * ssh-keygen(1): include pathname in some of ssh-keygen's
    passphrase prompts. Helps the user know what's going on when
    ssh-keygen is invoked via other tools. Requested in GHPR503
    * ssh(1), ssh-add(1): make parsing user@host consistently look
    for the last '@' in the string rather than the first. This
    makes it possible to more consistently use usernames that
    contain '@' characters.
    * ssh(1), sshd(8): be more strict in parsing key type names. Only
    allow short names (e.g "rsa") in user-interface code and
    require full SSH protocol names (e.g. "ssh-rsa") everywhere
    else. bz3725
    * regress: many performance and correctness improvements to the
    re-keying regression test.
    * ssh-keygen(1): clarify that ed25519 is the default key type
    generated and clarify that rsa-sha2-512 is the default
    signature scheme when RSA is in use. GHPR505
    * sshd(8): fix minor memory leak in Subsystem option parsing;
    GHPR515
    * All: additional hardening and consistency checks for the sshbuf
    code.
    * sshd(8): reduce default logingrace penalty to ensure that a
    single forgotton login that times out will be below the penalty
    threshold.
    * ssh(1): fix proxy multiplexing (-O proxy) bug. If a mux started
    with ControlPersist then later has a forwarding added using mux
    proxy connection and the forwarding was used, then when the mux
    proxy session terminated, the mux master process would issue a
    bad message that terminated the connection.
    = Portability
    * sync contrib/ssh-copy-id to the latest upstream version.
    * regress: improve portablility for some awk(1) usage
    (e.g. Solaris)
    * In the contrib/redhat RPM spec file, without_openssl was
    previously incorrectly enabled unconditionally.
    * sshd(8) restore audit call before exit that regressed in
    openssh-9.8. Fixes an issue where the SSH_CONNECTION_ABANDON
    event was not recorded.
    * sshd(8): add support for class-imposed loging restrictions on
    FreeBSD. Allowing auth_hostok(3) and auth_timeok(3) to control
    logins.
    * Build fixes for Musl libc.
    * Fix detection of setres*id on GNU/Hurd
  - Drop patches that were already merged by upstream:
    * fix-memleak-in-process_server_config_line_depth.patch
    * fix-audit-fail-attempt.patch
  - Rebase patch with significant changes:
    * openssh-8.1p1-audit.patch
  - Rebase patches with context or trivial changes:
    * openssh-7.7p1-fips.patch
    * openssh-8.0p1-gssapi-keyex.patch
    * openssh-9.6p1-crypto-policies-man.patch
    * openssh-mitigate-lingering-secrets.patch
  - Several spec file fixes so the package builds and can be
    installed in SLE 15 SP5 and SLE 12 SP5
  - Use gcc11 when building in SLE12 and SLE15.

------------------------------------------------------------------
------------------  2024-9-22  -  Sep 22 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Add u_fix-llvm19-build.patch to fix build with LLVM 19 on ARM.
  - Update minimum version requirements based on meson.build.
  - Fix build on s390x: apparently we don't have libvdpau_gallium.so.

++++ Mesa-drivers:

  - Add u_fix-llvm19-build.patch to fix build with LLVM 19 on ARM.
  - Update minimum version requirements based on meson.build.
  - Fix build on s390x: apparently we don't have libvdpau_gallium.so.

++++ kernel-default:

  - nilfs2: fix potential oob read in nilfs_btree_check_delete()
    (git-fixes).
  - commit cc0f59d
  - nilfs2: determine empty node blocks as corrupted (git-fixes).
  - commit 3244e52
  - nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()
    (git-fixes).
  - commit 90f4e49

++++ kernel-rt:

  - nilfs2: fix potential oob read in nilfs_btree_check_delete()
    (git-fixes).
  - commit cc0f59d
  - nilfs2: determine empty node blocks as corrupted (git-fixes).
  - commit 3244e52
  - nilfs2: fix potential null-ptr-deref in nilfs_btree_insert()
    (git-fixes).
  - commit 90f4e49

++++ llvm19:

  - Update to version 19.1.0.
    * For details, see the release notes:
  - https://releases.llvm.org/19.1.0/docs/ReleaseNotes.html
  - https://releases.llvm.org/19.1.0/tools/clang/docs/ReleaseNotes.html
  - https://releases.llvm.org/19.1.0/tools/clang/tools/extra/docs/ReleaseNotes.html
  - https://releases.llvm.org/19.1.0/projects/libcxx/docs/ReleaseNotes.html
  - https://releases.llvm.org/19.1.0/tools/lld/docs/ReleaseNotes.html
    * New LLVM tool: reduce-chunk-list to help find bugs using debug
    counters. See the Programmer's Manual for usage.
    * New Clang tools: clang-installapi for Apple-related package
    management, clang-nvlink-wrapper as a wrapper around `nvlink`.
  - No longer include OpenMP offload libraries.
  - Rebase patches:
    * clang-fix-openmp-test.patch
    * libcxx-test-library-path.patch
    * llvm-do-not-install-static-libraries.patch
    * llvm_build_tablegen_component_as_shared_library.patch
  - Remove obsolete patches:
    * lld-default-sha1.patch because upstream switched to sha1.
    * llvm-remove-clang-only-flags.patch because warning flags are no
    longer autodetected.
    * openmp-dont-run-gpu-arch.patch because we're excluding the
    offload project for now.
  - Add llvm-fix-build-failure-on-ppc64le.patch to fix ppc64le build.
  - Require Python 3.11 on Leap because we need Python >= 3.8 now.

++++ pinentry:

  - Make pinentry-efl optional

------------------------------------------------------------------
------------------  2024-9-21  -  Sep 21 2024  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Update to version 2.29.7:
    * revert commits link to mount API over bind changes
  - Update to version 2.29.6:
    * don't set propagation if target engine isn't linux
    * build(deps): bump github.com/docker/docker v27.3.0-rc.2
    * build(deps): bump github.com/docker/cli v27.3.0-rc.2
  - Update to version 2.29.5:
    * set propagation default
    * Remove custom codeql workflow
  - Update to version 2.29.4:
    * fix import
    * chore(watch): Add debug log when skipping service without build
    context
    * stop dependent containers before recreating diverged service
    * Fixed possible `nil` pointer dereference
    * bump github.com/docker/buildx v0.17.1
    * build(deps): bump docker, docker/cli to v27.3.0-rc.1
    * gha: test against docker engine v27.3.0

++++ nvidia-open-driver-G06-signed:

  - Update to 550.120 (boo#1230779)
    * Fixed a bug that could cause kernel crashes upon attempting
    KMS operations through DRM when nvidia_drm was loaded with
    modeset=0.
  - aarch64-TW-buildfix.patch
    * fixes build on aarch64 with latest TW kernel

------------------------------------------------------------------
------------------  2024-9-20  -  Sep 20 2024  -------------------
------------------------------------------------------------------

++++ acpica:

  - Fix acpica-no-compiletime.patch to omit build date from xen .h files
    (boo#1230856, boo#1047218)

++++ dracut:

  - Update to version 059+suse.607.g2d95edb5:
    Fixes for NVMeoF boot (bsc#1230468):
    * fix(nvmf): install (only) required nvmf modules
    * fix(nvmf): require NVMeoF modules
    * fix(nvmf): move /etc/nvme/host{nqn,id} requirement to hostonly
    Fixes for bsc#1230354:
    * feat(systemd): always install libsystemd libraries
    * fix(dracut): do not add all lib subdirs to `LD_LIBRARY_PATH` with `--sysroot`

++++ python-kiwi:

  - storage: clone_device: increase dd block size
    Increasing the block size used for dd reduces the time needed to clone a
    device.
    Signed-off-by: Isaac True <isaac@is.having.coffee>

++++ git:

  - Update to version 2.46.1;
    * "git checkout --ours" (no other arguments) complained that the
    option is incompatible with branch switching, which is technically
    correct, but found confusing by some users.  It now says that the
    user needs to give pathspec to specify what paths to checkout.
    * It has been documented that we avoid "VAR=VAL shell_func" and why.
    * "git add -p" by users with diff.suppressBlankEmpty set to true
    failed to parse the patch that represents an unmodified empty line
    with an empty line (not a line with a single space on it), which
    has been corrected.
    * "git rebase --help" referred to "offset" (the difference between
    the location a change was taken from and the change gets replaced)
    incorrectly and called it "fuzz", which has been corrected.
    * "git notes add -m '' --allow-empty" and friends that take prepared
    data to create notes should not invoke an editor, but it started
    doing so since Git 2.42, which has been corrected.
    * An expensive operation to prepare tracing was done in re-encoding
    code path even when the tracing was not requested, which has been
    corrected.
    * Perforce tests have been updated.
    * The credential helper to talk to OSX keychain sometimes sent
    garbage bytes after the username, which has been corrected.
    * A recent update broke "git ls-remote" used outside a repository,
    which has been corrected.
    * "git config --value=foo --fixed-value section.key newvalue" barfed
    when the existing value in the configuration file used the
    valueless true syntax, which has been corrected.
    * "git reflog expire" failed to honor annotated tags when computing
    reachable commits.
    * A flakey test and incorrect calls to strtoX() functions have been
    fixed.
    * Follow-up on 2.45.1 regression fix.
    * "git rev-list ... | git diff-tree -p --remerge-diff --stdin" should
    behave more or less like "git log -p --remerge-diff" but instead it
    crashed, forgetting to prepare a temporary object store needed.
    * The patch parser in "git patch-id" has been tightened to avoid
    getting confused by lines that look like a patch header in the log
    message.
    * "git bundle unbundle" outside a repository triggered a BUG()
    unnecessarily, which has been corrected.
    * The code forgot to discard unnecessary in-core commit buffer data
    for commits that "git log --skip=<number>" traversed but omitted
    from the output, which has been corrected.
    * "git verify-pack" and "git index-pack" started dying outside a
    repository, which has been corrected.
    * A corner case bug in "git stash" was fixed.

++++ glib2:

  - Update to version 2.82.1:
    + Fix a potential buffer overflow in `GSocks4aProxy` (boo#1233282
    CVE-2024-52533).
    + Bugs fixed:
  - Test /unix-mounts/get-mount-entries fails unless libmount is
    enabled
  - Buffer overflow in set_connect_msg()
  - tests: Test against a sample mtab file in unix-mounts for
    getmntent()
  - tests: Run lint tests with detected bash
  - docs(glib): Fix link in string-utils ref
  - Move to Apple Silicon based runner
  - gsocks4aproxy: Fix a single byte buffer overflow in connect
    messages
    + Updated translations.

++++ kernel-default:

  - media: mtk-vcodec: potential null pointer deference in SCP (CVE-2024-40973 bsc#1227890)
  - commit ce5074d
  - btrfs: don't BUG_ON() when 0 reference count at
    btrfs_lookup_extent_info() (bsc#1230786 CVE-2024-46751).
  - btrfs: reduce nesting for extent processing at
    btrfs_lookup_extent_info() (bsc#1230794 CVE-2024-46752).
  - btrfs: remove superfluous metadata check at
    btrfs_lookup_extent_info() (bsc#1230794 CVE-2024-46752).
  - btrfs: replace BUG_ON() with error handling at
    update_ref_for_cow() (bsc#1230794 CVE-2024-46752).
  - btrfs: simplify setting the full backref flag at
    update_ref_for_cow() (bsc#1230794 CVE-2024-46752).
  - btrfs: remove NULL transaction support for
    btrfs_lookup_extent_info() (bsc#1230794 CVE-2024-46752).
  - btrfs: remove level argument from btrfs_set_block_flags
    (bsc#1230794 CVE-2024-46752).
  - commit a1c1176
  - btrfs: send: allow cloning non-aligned extent if it ends at
    i_size (bsc#1230854).
  - commit e9cad4b
  - ocfs2: cancel dqi_sync_work before freeing oinfo (git-fixes).
  - commit 1f37ac4
  - ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
    (git-fixes).
  - commit b7bf7eb
  - ocfs2: remove unreasonable unlock in ocfs2_read_blocks
    (git-fixes).
  - commit e2cb129
  - ocfs2: fix null-ptr-deref when journal load failed (git-fixes).
  - commit b463b02
  - jfs: fix out-of-bounds in dbNextAG() and diAlloc() (git-fixes).
  - commit d948d87
  - of/irq: Prevent device address out-of-bounds read in interrupt
    map walk (CVE-2024-46743 bsc#1230756).
  - commit 300f40a
  - i2c: qcom-geni: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - i2c: isch: Add missed 'else' (git-fixes).
  - i2c: xiic: Wait for TX empty to avoid missed TX NAKs
    (git-fixes).
  - i2c: aspeed: Update the stop sw state when the bus recovery
    occurs (git-fixes).
  - resource: fix region_intersects() vs add_memory_driver_managed()
    (git-fixes).
  - drivers:drm:exynos_drm_gsc:Fix wrong assignment in gsc_bind()
    (git-fixes).
  - drm/msm: fix %s null argument error (git-fixes).
  - drm/msm/dsi: correct programming sequence for SM8350 / SM8450
    (git-fixes).
  - drm/msm/a5xx: workaround early ring-buffer emptiness check
    (git-fixes).
  - drm/msm/a5xx: fix races in preemption evaluation stage
    (git-fixes).
  - drm/msm/a5xx: properly clear preemption records on resume
    (git-fixes).
  - drm/msm/a5xx: disable preemption in submits by default
    (git-fixes).
  - drm/msm: Fix incorrect file name output in adreno_request_fw()
    (git-fixes).
  - drm/mediatek: ovl_adaptor: Add missing of_node_put()
    (git-fixes).
  - drm: omapdrm: Add missing check for alloc_ordered_workqueue
    (git-fixes).
  - drm/radeon/evergreen_cs: fix int overflow errors in cs track
    offsets (git-fixes).
  - drm/amd/amdgpu: Properly tune the size of struct (git-fixes).
  - drm/radeon: properly handle vbios fake edid sizing (git-fixes).
  - drm/amdgpu: properly handle vbios fake edid sizing (git-fixes).
  - drm/amd/display: Add null check for set_output_gamma in
    dcn30_set_output_transfer_func (git-fixes).
  - drm/amdgpu: fix a possible null pointer dereference (git-fixes).
  - drm/radeon: fix null pointer dereference in
    radeon_add_common_modes (git-fixes).
  - drm/vc4: hdmi: Handle error case of pm_runtime_resume_and_get
    (git-fixes).
  - drm/bridge: lontium-lt8912b: Validate mode in
    drm_bridge_funcs::mode_valid() (git-fixes).
  - drm/rockchip: dw_hdmi: Fix reading EDID when using a forced mode
    (git-fixes).
  - drm/rockchip: vop: Allow 4096px width scaling (git-fixes).
  - drm/rockchip: vop: enable VOP_FEATURE_INTERNAL_RGB on RK3066
    (git-fixes).
  - drm/rockchip: vop: clear DMA stop bit on RK3066 (git-fixes).
  - drm/stm: ltdc: check memory returned by devm_kzalloc()
    (git-fixes).
  - drm/stm: Fix an error handling path in stm_drm_platform_probe()
    (git-fixes).
  - ata: libata: Clear DID_TIME_OUT for ATA PT commands with sense
    data (git-fixes).
  - HID: wacom: Do not warn about dropped packets for first packet
    (git-fixes).
  - HID: wacom: Support sequence numbers smaller than 16-bit
    (git-fixes).
  - tpm: Clean up TPM space after command failure (git-fixes).
  - ipmi: docs: don't advertise deprecated sysfs entries
    (git-fixes).
  - commit b4e4911

++++ kernel-rt:

  - media: mtk-vcodec: potential null pointer deference in SCP (CVE-2024-40973 bsc#1227890)
  - commit ce5074d
  - btrfs: don't BUG_ON() when 0 reference count at
    btrfs_lookup_extent_info() (bsc#1230786 CVE-2024-46751).
  - btrfs: reduce nesting for extent processing at
    btrfs_lookup_extent_info() (bsc#1230794 CVE-2024-46752).
  - btrfs: remove superfluous metadata check at
    btrfs_lookup_extent_info() (bsc#1230794 CVE-2024-46752).
  - btrfs: replace BUG_ON() with error handling at
    update_ref_for_cow() (bsc#1230794 CVE-2024-46752).
  - btrfs: simplify setting the full backref flag at
    update_ref_for_cow() (bsc#1230794 CVE-2024-46752).
  - btrfs: remove NULL transaction support for
    btrfs_lookup_extent_info() (bsc#1230794 CVE-2024-46752).
  - btrfs: remove level argument from btrfs_set_block_flags
    (bsc#1230794 CVE-2024-46752).
  - commit a1c1176
  - btrfs: send: allow cloning non-aligned extent if it ends at
    i_size (bsc#1230854).
  - commit e9cad4b
  - ocfs2: cancel dqi_sync_work before freeing oinfo (git-fixes).
  - commit 1f37ac4
  - ocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate
    (git-fixes).
  - commit b7bf7eb
  - ocfs2: remove unreasonable unlock in ocfs2_read_blocks
    (git-fixes).
  - commit e2cb129
  - ocfs2: fix null-ptr-deref when journal load failed (git-fixes).
  - commit b463b02
  - jfs: fix out-of-bounds in dbNextAG() and diAlloc() (git-fixes).
  - commit d948d87
  - of/irq: Prevent device address out-of-bounds read in interrupt
    map walk (CVE-2024-46743 bsc#1230756).
  - commit 300f40a
  - i2c: qcom-geni: Use IRQF_NO_AUTOEN flag in request_irq()
    (git-fixes).
  - i2c: isch: Add missed 'else' (git-fixes).
  - i2c: xiic: Wait for TX empty to avoid missed TX NAKs
    (git-fixes).
  - i2c: aspeed: Update the stop sw state when the bus recovery
    occurs (git-fixes).
  - resource: fix region_intersects() vs add_memory_driver_managed()
    (git-fixes).
  - drivers:drm:exynos_drm_gsc:Fix wrong assignment in gsc_bind()
    (git-fixes).
  - drm/msm: fix %s null argument error (git-fixes).
  - drm/msm/dsi: correct programming sequence for SM8350 / SM8450
    (git-fixes).
  - drm/msm/a5xx: workaround early ring-buffer emptiness check
    (git-fixes).
  - drm/msm/a5xx: fix races in preemption evaluation stage
    (git-fixes).
  - drm/msm/a5xx: properly clear preemption records on resume
    (git-fixes).
  - drm/msm/a5xx: disable preemption in submits by default
    (git-fixes).
  - drm/msm: Fix incorrect file name output in adreno_request_fw()
    (git-fixes).
  - drm/mediatek: ovl_adaptor: Add missing of_node_put()
    (git-fixes).
  - drm: omapdrm: Add missing check for alloc_ordered_workqueue
    (git-fixes).
  - drm/radeon/evergreen_cs: fix int overflow errors in cs track
    offsets (git-fixes).
  - drm/amd/amdgpu: Properly tune the size of struct (git-fixes).
  - drm/radeon: properly handle vbios fake edid sizing (git-fixes).
  - drm/amdgpu: properly handle vbios fake edid sizing (git-fixes).
  - drm/amd/display: Add null check for set_output_gamma in
    dcn30_set_output_transfer_func (git-fixes).
  - drm/amdgpu: fix a possible null pointer dereference (git-fixes).
  - drm/radeon: fix null pointer dereference in
    radeon_add_common_modes (git-fixes).
  - drm/vc4: hdmi: Handle error case of pm_runtime_resume_and_get
    (git-fixes).
  - drm/bridge: lontium-lt8912b: Validate mode in
    drm_bridge_funcs::mode_valid() (git-fixes).
  - drm/rockchip: dw_hdmi: Fix reading EDID when using a forced mode
    (git-fixes).
  - drm/rockchip: vop: Allow 4096px width scaling (git-fixes).
  - drm/rockchip: vop: enable VOP_FEATURE_INTERNAL_RGB on RK3066
    (git-fixes).
  - drm/rockchip: vop: clear DMA stop bit on RK3066 (git-fixes).
  - drm/stm: ltdc: check memory returned by devm_kzalloc()
    (git-fixes).
  - drm/stm: Fix an error handling path in stm_drm_platform_probe()
    (git-fixes).
  - ata: libata: Clear DID_TIME_OUT for ATA PT commands with sense
    data (git-fixes).
  - HID: wacom: Do not warn about dropped packets for first packet
    (git-fixes).
  - HID: wacom: Support sequence numbers smaller than 16-bit
    (git-fixes).
  - tpm: Clean up TPM space after command failure (git-fixes).
  - ipmi: docs: don't advertise deprecated sysfs entries
    (git-fixes).
  - commit b4e4911

++++ cairo:

  - Add b9eed915f9a67380e7ef9d8746656455c43f67e2.patch: cff: Don't
    fail if no local subs. Fix regression when writing PDFs with
    fonts.

++++ libxslt:

  - Add libxslt-reproducible.patch to make xml output deterministic (boo#1062303)

------------------------------------------------------------------
------------------  2024-9-19  -  Sep 19 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req() (CVE-2024-46686 bsc#1230517)
  - commit a155846
  - firmware: qcom: scm: Mark get_wq_ctx() as atomic call (CVE-2024-46692 bsc#1230520)
  - commit ee65da0
  - scsi: aacraid: Fix double-free on probe failure (CVE-2024-46673 bsc#1230506)
  - commit 49aab2b
  - gtp: fix a potential NULL pointer dereference (CVE-2024-46677 bsc#1230549)
  - commit 9cdd14b
  - ethtool: check device is present when getting link settings (CVE-2024-46679 bsc#1230556)
  - commit 68643d1
  - md/raid5: avoid BUG_ON() while continue reshape after
    reassembling (bsc#1229790, CVE-2024-43914).
  - commit bfb799a
  - xfs: restrict when we try to align cow fork delalloc to cowextsz
    hints (git-fixes).
  - commit 96ac1b7
  - clk: Provide !COMMON_CLK dummy for devm_clk_rate_exclusive_get()
    (bsc#1227885).
  - commit bf3362b
  - Replace git-fixes tag by bsc#1226507,
    patches.suse/md-Don-t-wait-for-MD_RECOVERY_NEEDED-for-HOT_REMOVE_DISK-ioctl-a1fd.patch
    (bsc#1226507).
  - commit b04e0cb
  - closures: Change BUG_ON() to WARN_ON() (bsc#1229004,
    CVE-2024-42252).
  - commit 84b7984
  - clk: Add a devm variant of clk_rate_exclusive_get()
    (bsc#1227885).
  - commit b6fb747
  - r8152: add vendor/device ID pair for D-Link DUB-E250
    (git-fixes).
  - Refresh
    patches.suse/r8152-add-vendor-device-ID-pair-for-ASUS-USB-C2500.patch.
  - commit 0c077ab
  - usbnet: ipheth: fix carrier detection in modes 1 and 4
    (git-fixes).
  - commit 591cebb
  - usbnet: ipheth: do not stop RX on failing RX callback
    (git-fixes).
  - commit c58c483
  - usbnet: ipheth: drop RX URBs with no payload (git-fixes).
  - commit 73a78e2
  - KVM: arm64: Disallow copying MTE to guest memory while KVM is
    dirty logging (git-fixes).
  - commit 3cf4c02
  - usbnet: ipheth: remove extraneous rx URB length check
    (git-fixes).
  - commit 507443a
  - usbnet: ipheth: add CDC NCM support (git-fixes).
  - commit 1bf1d1e
  - KVM: arm64: Release pfn, i.e. put page, if copying MTE tags
    hits ZONE_DEVICE (git-fixes).
  - commit 64bccd6
  - usbnet: ipheth: transmit URBs without trailing padding
    (git-fixes).
  - usbnet: ipheth: fix risk of NULL pointer deallocation
    (git-fixes).
  - commit d804072
  - KVM: arm64: Invalidate EL1&0 TLB entries for all VMIDs in nvhe
    hyp init (git-fixes).
  - commit 30df9d2
  - drm/amd/display: Solve mst monitors blank out problem after
    resume (git-fixes).
  - commit cd94b30
  - virtio-net: synchronize probe with ndo_set_features (git-fixes).
  - commit 1a471dd
  - fbdev: hpfb: Fix an error handling path in hpfb_dio_probe()
    (git-fixes).
  - hwmon: (ntc_thermistor) fix module autoloading (git-fixes).
  - hwmon: (max16065) Fix overflows seen when writing limits
    (git-fixes).
  - mtd: powernv: Add check devm_kasprintf() returned value
    (git-fixes).
  - mtd: slram: insert break after errors in parsing the map
    (git-fixes).
  - power: supply: hwmon: Fix missing temp1_max_alarm attribute
    (git-fixes).
  - power: supply: Drop use_cnt check from
    power_supply_property_is_writeable() (git-fixes).
  - power: supply: max17042_battery: Fix SOC threshold calc w/
    no current sense (git-fixes).
  - power: supply: axp20x_battery: Remove design from min and max
    voltage (git-fixes).
  - pinctrl: meteorlake: Add Arrow Lake-H/U ACPI ID (stable-fixes).
  - drm/amdgpu/atomfirmware: Silence UBSAN warning (stable-fixes).
  - drm/amd/display: Avoid race between dcn10_set_drr() and
    dc_state_destruct() (git-fixes).
  - Input: synaptics - enable SMBus for HP Elitebook 840 G2
    (stable-fixes).
  - Input: ads7846 - ratelimit the spi_sync error message
    (stable-fixes).
  - drm/msm/adreno: Fix error return if missing firmware-name
    (stable-fixes).
  - scripts: kconfig: merge_config: config files: add a trailing
    newline (stable-fixes).
  - platform/surface: aggregator_registry: Add support for Surface
    Laptop Go 3 (stable-fixes).
  - platform/surface: aggregator_registry: Add Support for Surface
    Pro 10 (stable-fixes).
  - HID: multitouch: Add support for GT7868Q (stable-fixes).
  - drm/mediatek: Set sensible cursor width/height values to fix
    crash (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Ayn Loki Max
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Ayn Loki Zero
    (stable-fixes).
  - wifi: mt76: mt7921: fix NULL pointer access in
    mt7921_ipv6_addr_change (stable-fixes).
  - net: phy: vitesse: repair vsc73xx autonegotiation
    (stable-fixes).
  - cxl/core: Fix incorrect vendor debug UUID define (git-fixes).
  - drm/amd/display: Fix FEC_READY write on DP LT (stable-fixes).
  - drm/amd/display: Defer handling mst up request in resume
    (stable-fixes).
  - drm/amd/display: Disable error correction if it's not supported
    (stable-fixes).
  - commit 040b0ea
  - Update patches.suse/NFS-never-reuse-a-NFSv4-0-lock-owner.patch
    (bsc#1227726 bsc#1230733 bsc#1230971)
  - commit 1f8ff5f

++++ kernel-rt:

  - smb/client: avoid dereferencing rdata=NULL in smb2_new_read_req() (CVE-2024-46686 bsc#1230517)
  - commit a155846
  - firmware: qcom: scm: Mark get_wq_ctx() as atomic call (CVE-2024-46692 bsc#1230520)
  - commit ee65da0
  - scsi: aacraid: Fix double-free on probe failure (CVE-2024-46673 bsc#1230506)
  - commit 49aab2b
  - gtp: fix a potential NULL pointer dereference (CVE-2024-46677 bsc#1230549)
  - commit 9cdd14b
  - ethtool: check device is present when getting link settings (CVE-2024-46679 bsc#1230556)
  - commit 68643d1
  - md/raid5: avoid BUG_ON() while continue reshape after
    reassembling (bsc#1229790, CVE-2024-43914).
  - commit bfb799a
  - xfs: restrict when we try to align cow fork delalloc to cowextsz
    hints (git-fixes).
  - commit 96ac1b7
  - clk: Provide !COMMON_CLK dummy for devm_clk_rate_exclusive_get()
    (bsc#1227885).
  - commit bf3362b
  - Replace git-fixes tag by bsc#1226507,
    patches.suse/md-Don-t-wait-for-MD_RECOVERY_NEEDED-for-HOT_REMOVE_DISK-ioctl-a1fd.patch
    (bsc#1226507).
  - commit b04e0cb
  - closures: Change BUG_ON() to WARN_ON() (bsc#1229004,
    CVE-2024-42252).
  - commit 84b7984
  - clk: Add a devm variant of clk_rate_exclusive_get()
    (bsc#1227885).
  - commit b6fb747
  - r8152: add vendor/device ID pair for D-Link DUB-E250
    (git-fixes).
  - Refresh
    patches.suse/r8152-add-vendor-device-ID-pair-for-ASUS-USB-C2500.patch.
  - commit 0c077ab
  - usbnet: ipheth: fix carrier detection in modes 1 and 4
    (git-fixes).
  - commit 591cebb
  - usbnet: ipheth: do not stop RX on failing RX callback
    (git-fixes).
  - commit c58c483
  - usbnet: ipheth: drop RX URBs with no payload (git-fixes).
  - commit 73a78e2
  - KVM: arm64: Disallow copying MTE to guest memory while KVM is
    dirty logging (git-fixes).
  - commit 3cf4c02
  - usbnet: ipheth: remove extraneous rx URB length check
    (git-fixes).
  - commit 507443a
  - usbnet: ipheth: add CDC NCM support (git-fixes).
  - commit 1bf1d1e
  - KVM: arm64: Release pfn, i.e. put page, if copying MTE tags
    hits ZONE_DEVICE (git-fixes).
  - commit 64bccd6
  - usbnet: ipheth: transmit URBs without trailing padding
    (git-fixes).
  - usbnet: ipheth: fix risk of NULL pointer deallocation
    (git-fixes).
  - commit d804072
  - KVM: arm64: Invalidate EL1&0 TLB entries for all VMIDs in nvhe
    hyp init (git-fixes).
  - commit 30df9d2
  - drm/amd/display: Solve mst monitors blank out problem after
    resume (git-fixes).
  - commit cd94b30
  - virtio-net: synchronize probe with ndo_set_features (git-fixes).
  - commit 1a471dd
  - fbdev: hpfb: Fix an error handling path in hpfb_dio_probe()
    (git-fixes).
  - hwmon: (ntc_thermistor) fix module autoloading (git-fixes).
  - hwmon: (max16065) Fix overflows seen when writing limits
    (git-fixes).
  - mtd: powernv: Add check devm_kasprintf() returned value
    (git-fixes).
  - mtd: slram: insert break after errors in parsing the map
    (git-fixes).
  - power: supply: hwmon: Fix missing temp1_max_alarm attribute
    (git-fixes).
  - power: supply: Drop use_cnt check from
    power_supply_property_is_writeable() (git-fixes).
  - power: supply: max17042_battery: Fix SOC threshold calc w/
    no current sense (git-fixes).
  - power: supply: axp20x_battery: Remove design from min and max
    voltage (git-fixes).
  - pinctrl: meteorlake: Add Arrow Lake-H/U ACPI ID (stable-fixes).
  - drm/amdgpu/atomfirmware: Silence UBSAN warning (stable-fixes).
  - drm/amd/display: Avoid race between dcn10_set_drr() and
    dc_state_destruct() (git-fixes).
  - Input: synaptics - enable SMBus for HP Elitebook 840 G2
    (stable-fixes).
  - Input: ads7846 - ratelimit the spi_sync error message
    (stable-fixes).
  - drm/msm/adreno: Fix error return if missing firmware-name
    (stable-fixes).
  - scripts: kconfig: merge_config: config files: add a trailing
    newline (stable-fixes).
  - platform/surface: aggregator_registry: Add support for Surface
    Laptop Go 3 (stable-fixes).
  - platform/surface: aggregator_registry: Add Support for Surface
    Pro 10 (stable-fixes).
  - HID: multitouch: Add support for GT7868Q (stable-fixes).
  - drm/mediatek: Set sensible cursor width/height values to fix
    crash (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Ayn Loki Max
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Ayn Loki Zero
    (stable-fixes).
  - wifi: mt76: mt7921: fix NULL pointer access in
    mt7921_ipv6_addr_change (stable-fixes).
  - net: phy: vitesse: repair vsc73xx autonegotiation
    (stable-fixes).
  - cxl/core: Fix incorrect vendor debug UUID define (git-fixes).
  - drm/amd/display: Fix FEC_READY write on DP LT (stable-fixes).
  - drm/amd/display: Defer handling mst up request in resume
    (stable-fixes).
  - drm/amd/display: Disable error correction if it's not supported
    (stable-fixes).
  - commit 040b0ea
  - Update patches.suse/NFS-never-reuse-a-NFSv4-0-lock-owner.patch
    (bsc#1227726 bsc#1230733 bsc#1230971)
  - commit 1f8ff5f

++++ openssl-3:

  - Security fix: [bsc#1230698, CVE-2024-41996]
    * Validating the order of the public keys in the Diffie-Hellman
    Key Agreement Protocol, when an approved safe prime is used.
    * Added openssl-CVE-2024-41996.patch

++++ shim:

  - Update shim-install to limit the scope of the 'removable'
    SL-Micro to the image booting with TPM2 unsealing (bsc#1210382)
    * 769e41d Limit the removable option to encrypted SL-Micro

++++ swtpm:

  - Fix swtpm custom module (bsc#1229131)
  - Add patch: 1229131-fix-swtpm-selinux-policy-mismatch.patch
  - this can be removed once swtpm upstream sorts out their custom selinux module.
    see: https://github.com/stefanberger/swtpm/issues/885
    there were a couple changes in the selinux-policy libvirt handling
    which causes the logfile in /var/log/swtpm/libvirt/qemu/*.log to be labeled
    virt_log_t instead of var_log_t. this patch allows swtpm_t to open the virt_log_t

------------------------------------------------------------------
------------------  2024-9-18  -  Sep 18 2024  -------------------
------------------------------------------------------------------

++++ chrony:

  - Update to version 4.6:
    * Add activate option to local directive to set activation threshold
    * Add ipv4 and ipv6 options to server/pool/peer directive
    * Add kod option to ratelimit directive for server KoD RATE support
    * Add leapseclist directive to read NIST/IERS leap-seconds.list file
    * Add ptpdomain directive to set PTP domain for NTP over PTP
    * Allow disabling pidfile
    * Improve copy server option to accept unsynchronised status instantly
    * Log one selection failure on start
    * Add offset command to modify source offset correction
    * Add timestamp sources to ntpdata report
    * Fix crash on sources reload during initstepslew or RTC initialisation
    * Fix source refreshment to not repeat failed name resolving attempts
    * Obsoletes chrony-124-tai.patch
  - The project's new home is https://chrony-project.org/ .

++++ cockpit:

  - support optional TOTP for authentication, requires pam_oath

++++ docker:

  - Add %{_sysconfdir}/audit/rules.d to filelist.

++++ glibc:

  - Use nss-systemd by default also in SLE (bsc#1230638)

++++ jeos-firstboot:

  - Update to version 1.5.2:
    * otp: Use the system nodename as issuer in the QR code
    * otp: Use more obvious dd | base32 instead of tr | head

++++ kernel-default:

  - i2c: lpi2c: Avoid calling clk_get_rate during transfer
    (bsc#1227885 CVE-2024-40965).
  - commit abb755c
  - x86/mm/ident_map: Use gbpages only where full GB page should
    be mapped (bsc#1220382).
  - x86/kexec: Add EFI config table identity mapping for kexec
    kernel (bsc#1220382).
  - commit 26eab5b
  - Move upstreamed nvme patches into sorted section
  - commit 1e42d2f
  - spi: ppc4xx: Avoid returning 0 when failed to parse and map IRQ
    (git-fixes).
  - commit 1cec71a
  - ASoC: meson: Remove unused declartion in header file
    (git-fixes).
  - ASoC: soc-ac97: Fix the incorrect description (git-fixes).
  - ASoC: rt5682: Return devm_of_clk_add_hw_provider to transfer
    the error (git-fixes).
  - ASoC: tas2781-i2c: Get the right GPIO line (git-fixes).
  - ASoC: cs42l42: Convert comma to semicolon (git-fixes).
  - ASoC: rt5682s: Return devm_of_clk_add_hw_provider to transfer
    the error (git-fixes).
  - ALSA: hda: cs35l41: fix module autoloading (git-fixes).
  - selftests: lib: remove strscpy test (git-fixes).
  - scripts: sphinx-pre-install: remove unnecessary double check
    for $cur_version (git-fixes).
  - Documentation: ioctl: document 0x07 ioctl code (git-fixes).
  - module: Fix KCOV-ignored file name (git-fixes).
  - reset: k210: fix OF node leak in probe() error path (git-fixes).
  - reset: berlin: fix OF node leak in probe() error path
    (git-fixes).
  - bus: integrator-lm: fix OF node leak in probe() (git-fixes).
  - soc: fsl: cpm1: tsa: Fix tsa_write8() (git-fixes).
  - firmware: tegra: bpmp: Drop unused mbox_client_to_bpmp()
    (git-fixes).
  - firmware: arm_scmi: Fix double free in OPTEE transport
    (git-fixes).
  - soc: versatile: integrator: fix OF node leak in probe() error
    path (git-fixes).
  - memory: mtk-smi: Use devm_clk_get_enabled() (git-fixes).
  - memory: tegra186-emc: drop unused to_tegra186_emc() (git-fixes).
  - spi: bcm63xx: Fix module autoloading (git-fixes).
  - spi: rpc-if: Add missing MODULE_DEVICE_TABLE (git-fixes).
  - spi: meson-spicc: convert comma to semicolon (git-fixes).
  - spi: ppc4xx: handle irq_of_parse_and_map() errors (git-fixes).
  - regulator: core: Fix regulator_is_supported_voltage() kerneldoc
    return value (git-fixes).
  - regulator: core: Fix short description for
    _regulator_check_status_enabled() (git-fixes).
  - regulator: Return actual error in of_regulator_bulk_get_all()
    (git-fixes).
  - regulator: rt5120: Convert comma to semicolon (git-fixes).
  - regulator: wm831x-isink: Convert comma to semicolon (git-fixes).
  - clocksource/drivers/qcom: Add missing iounmap() on errors in
    msm_dt_timer_init() (git-fixes).
  - commit 994b020

++++ kernel-rt:

  - i2c: lpi2c: Avoid calling clk_get_rate during transfer
    (bsc#1227885 CVE-2024-40965).
  - commit abb755c
  - x86/mm/ident_map: Use gbpages only where full GB page should
    be mapped (bsc#1220382).
  - x86/kexec: Add EFI config table identity mapping for kexec
    kernel (bsc#1220382).
  - commit 26eab5b
  - Move upstreamed nvme patches into sorted section
  - commit 1e42d2f
  - spi: ppc4xx: Avoid returning 0 when failed to parse and map IRQ
    (git-fixes).
  - commit 1cec71a
  - ASoC: meson: Remove unused declartion in header file
    (git-fixes).
  - ASoC: soc-ac97: Fix the incorrect description (git-fixes).
  - ASoC: rt5682: Return devm_of_clk_add_hw_provider to transfer
    the error (git-fixes).
  - ASoC: tas2781-i2c: Get the right GPIO line (git-fixes).
  - ASoC: cs42l42: Convert comma to semicolon (git-fixes).
  - ASoC: rt5682s: Return devm_of_clk_add_hw_provider to transfer
    the error (git-fixes).
  - ALSA: hda: cs35l41: fix module autoloading (git-fixes).
  - selftests: lib: remove strscpy test (git-fixes).
  - scripts: sphinx-pre-install: remove unnecessary double check
    for $cur_version (git-fixes).
  - Documentation: ioctl: document 0x07 ioctl code (git-fixes).
  - module: Fix KCOV-ignored file name (git-fixes).
  - reset: k210: fix OF node leak in probe() error path (git-fixes).
  - reset: berlin: fix OF node leak in probe() error path
    (git-fixes).
  - bus: integrator-lm: fix OF node leak in probe() (git-fixes).
  - soc: fsl: cpm1: tsa: Fix tsa_write8() (git-fixes).
  - firmware: tegra: bpmp: Drop unused mbox_client_to_bpmp()
    (git-fixes).
  - firmware: arm_scmi: Fix double free in OPTEE transport
    (git-fixes).
  - soc: versatile: integrator: fix OF node leak in probe() error
    path (git-fixes).
  - memory: mtk-smi: Use devm_clk_get_enabled() (git-fixes).
  - memory: tegra186-emc: drop unused to_tegra186_emc() (git-fixes).
  - spi: bcm63xx: Fix module autoloading (git-fixes).
  - spi: rpc-if: Add missing MODULE_DEVICE_TABLE (git-fixes).
  - spi: meson-spicc: convert comma to semicolon (git-fixes).
  - spi: ppc4xx: handle irq_of_parse_and_map() errors (git-fixes).
  - regulator: core: Fix regulator_is_supported_voltage() kerneldoc
    return value (git-fixes).
  - regulator: core: Fix short description for
    _regulator_check_status_enabled() (git-fixes).
  - regulator: Return actual error in of_regulator_bulk_get_all()
    (git-fixes).
  - regulator: rt5120: Convert comma to semicolon (git-fixes).
  - regulator: wm831x-isink: Convert comma to semicolon (git-fixes).
  - clocksource/drivers/qcom: Add missing iounmap() on errors in
    msm_dt_timer_init() (git-fixes).
  - commit 994b020

++++ bluez:

  - add Fix-crash-after-bt_uhid_unregister_all.patch to fix crashes
    when devices disconnect or go to sleep

++++ libeconf:

  - Update to version 0.7.3:
    * Groups handled in an own list (#218)
    * Add econftool as dependency of its tests
    * Simplify snprintf call
    * Remove unused functions and reduce variable visibility (#213)
    * Fix typos (#212)

++++ systemd:

  - Import commit 8a0ae4d90aff1d067a125ff9366eafc7dd5d4701 (merge of v256.6)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/bef0958f4db1b774c23505e93537ffe16f1b3894...8a0ae4d90aff1d067a125ff9366eafc7dd5d4701

++++ tiff:

  - Update to 4.7.0:
    * This version restores in the default build the availability of
    the tools that had been dropped in v4.6.0
    See https://libtiff.gitlab.io/libtiff/rfcs/rfc2_restoring_needed_tools.html#rfc2-restoring-needed-tools
    * Software configuration changes:
    + autoconf build: configure.ac: avoid -Werror passed to CFLAGS to interfere with feature detection
    + autoconf build: fix error when running make clean (fixes issue #630)
    + autoconf build: back off the minimum required automake version to 1.11
    + autoconf.ac: fix detection of windows.h for mingw (fixes issue #605)
    + libtiff-4.pc: Fix Requires.private missing Lerc. It provides a .pc file
    starting from version 4 (in autoconf builds, we assume that liblerc is at least version 4)
    + CMake: Fix TIFF_INCLUDE_DIRS
    + CMake: MinGW compilers don't need a .def file for shared library
    + CMake: move libdeflate and Lerc to Requires.private
    + CMake: enable resource compilation on all Windows.
    * Library changes:
    + Add TIFFOpenOptionsSetMaxCumulatedMemAlloc(). This function complements
    TIFFOpenOptionsSetMaxSingleMemAlloc() to define the maximum cumulated memory
    allocations in byte, for a given TIFF handle, that libtiff internal memory
    allocation functions are allowed.
    + TIFFWriteDirectory(): Avoid overwriting following data if an IFD is enlarged.
    + TIFFXYZToRGB: avoid integer overflow (fixes issue #644)
    + uv_decode() and uv_encode(): avoid potential out-of-bounds array index (fixes issue #645)
    + Fix cases where tif_curdir is set incorrectly. Fix cases where the current directory number (tif_curdir)
    is set inconsistently or incorrectly, depending on the previous history.
    + TIFFRead[Scanline/EncodedStrip/EncodeTile]: 0-initialize output buffer if setupdecode fails ;
    most codecs: zero-initialize (not-yet-written parts of) output buffer if failure (fixes issue #375)
    + OJPEG: reset subsampling_convert_state=0 in OJPEGPreDecode (fixes issue #183)
    + ThunderRLE: fix failure when decoding last run. Bug seen with GhostPDL
    + LERC codec: deal with issues with multi-band PlanarConfig=Contig and NaN values
    + tif_fax3.c: error out after a number of times end-of-file has been reached (fixes issue #583)
    + LZW: avoid warning about misaligned address with UBSAN (fixes issue #616)
    + TIFFReadRGBAStrip/TIFFReadRGBATile: add more validation of col/row (fixes issue #622, CVE-2023-52356)
    + tif_dirread.c: only issue TIFFGetFileSize() for large enough RAM requests
    + Avoid FPEs (division by zero) in tif_getimage.c.
    + Avoiding FPE (division by zero) for TIFFhowmany_32() and TIFFhowmany_64() macros by checking for
    denominator not zero before macros are executed. (fixes issue #628)
    + Add non-zero check before division in TIFFComputeStrip()
    + Fix wrong return of TIFFIsBigTIFF() in case byte-swapping is active
    + Setting the TIFFFieldInfo field set_field_type should consider field_writecount not field_readcount
    + Avoid memory leaks when using TIFFCreateDirectory() by releasing the allocated memory in the tif-structure.
    + For non-terminated ASCII arrays, the buffer is first enlarged before a NULL is set at the end to
    avoid deleting the last character. (fixes issue #579)
    + Check return value of _TIFFCreateAnonField(). (fixes issue #624, CVE-2024-7006)
    + Prevent some out-of-memory attacks (https://gitlab.com/libtiff/libtiff/-/issues/614#note_1602683857)
    + Ensure absolute seeking is forced independent of TIFFReadDirectory success. (fixes issue #618)
    + tif_dirinfo.c: re-enable TIFFTAG_EP_CFAREPEATPATTERNDIM and TIFFTAG_EP_CFAPATTERN tags (fixes issue #608)
    + Fix warnings with GCC 14
    + tif_dir.c: Log source file, line number, and input tif for directory count error (fixes issue #627)
    + Last usage of get_field_type of TIFFField structure at TIFFWriteDirectorySec() changed to using set_field_type.
    + tif_jpeg.c/tif_ojpeg.c: remove likely ifdef tricks related to old compilers or unusual setups
    + Remove _TIFFUInt64ToFloat() and _TIFFUInt64ToDouble()
    + Remove support for _MSC_VER < 1500.
    + Use #ifdef _WIN32 to test for Windows, and tiffio.h: remove definition of __WIN32__
    * Documentation:
    + Amend manpages for changes in current directory index behaviour
    + Note on using TIFFFlush() before TIFFClose() to check that the data has been successfully written to the file. (fixes issue #506)
    + Update TIFF documentation about TIFFOpenOptions.rst and TIFFOpenOptionsSetMaxSingleMemAlloc() usage and some other small fixes (relates to CVE-2024-7006)
    * Re-added tools:
    + fax2ps
    + fax2tiff
    + pal2rgb
    + ppm2tiff
    + raw2tiff
    + rgb2ycbcr (not installed)
    + thumbnail (not installed)
    + tiff2bw
    + tiff2rgba
    + tiffcmp
    + tiffcrop
    + tiffdither
    + tiffgt
    + tiffmedian
    + tiff2ps
    + tiff2pdf
    * New/improved functionality:
    + tiff2rgba: Add background gradient option for alpha compositing
    + tiffcp: -i flag restored
    * Bug fixes for tools:
    + tiffcrop: address Coverity scan issues 1605444, 1605445, and 16054
    + tiffcrop: Apply "Fix heap-buffer-overflow in function extractImageSection"
    + tiffcrop: fix buffer overflows, use after free (fixes issue #542, issue #550, issue #552)
    + tiff2pdf: address Coverity scan issues
    + tiff2pdf: fix inconsistent PLANARCONFIG value for the input and output TIFF
    + tiff2pdf: fix issue with JPEG restart-interval marker when converting from JPEG-compressed files (fixes issue #539)
    + tiff2pdf: red and blue were being swapped for RGBA decoding (fixes issue #253)
    + tiff2pdf: fixes issue #596
    + thumbnail: address Coverity scan issues
    + tiffcp: Add check for limitMalloc return to fix Coverity 1603334
    + tiffcp: preserve TIFFTAG_REFERENCEBLACKWHITE when doing YCbCr JPEG -> YCbCr JPEG
    + tiffcp: replace PHOTOMETRIC_YCBCR with PHOTOMETRIC_RGB when outputing to compression != JPEG (refs issue #571)
    + tiffcp: do not copy tags YCBCRCOEFFICIENTS, YCBCRSUBSAMPLING, YCBCRPOSITIONING, REFERENCEBLACKWHITE. Only set YCBCRSUBSAMPLING when generating YCbCr JPEG
    + tiffcp: Check also codec of input image, not only from output image (fixes issue #606)
    + Add some basic sanity checks for tiffcp and tiffcrop RGB->YCbCr JPEG conversions.
    + fax2ps and fax2tiff: memory leak fixes (fixes issue #476)
    + tiffmedian: memory leak fixes (fixes issue #599)
    + fax2tiff: fix EOFB interpretation (fixes issue #191)
    + fax2tiff: fix issue with unreasonable width input (fixes issue #249)
    + tiffcp and tiffcrop: fixes issue #228
    + tiff2rgba: fixes issue #469
    + tiffdither: fixes issue #473
    + tiffdump: fix wrong printf formatter in error message (Coverity 1472932)
    + tiffset: avoid false positive Coverity Scan warning on 64-bit builds (Coverity 1518997)
    + tifcp/tiffset: use correct format specifiers
    * Changes to contributed and unsupported tools
    + contrib/addtiffo: validate return of TIFFWriteEncodedXXXX() calls (Coverity 1024680)
  - Remove patches contained in upstream:
    * tiff-CVE-2023-52356.patch
    * tiff-CVE-2024-7006.patch
  - Tools are not built for now due to test failure: `FAIL: tiffcp-32bpp-None-jpeg.sh`

++++ mdadm:

  - Detail: remove duplicated code (bsc#1226413)
    0008-Detail-remove-duplicated-code.patch
  - mdadm: Fix native --detail --export (bsc#1226413)
    0009-mdadm-Fix-native-detail-export.patch

++++ setools:

  - Add upstream tarball signature
  - Add key 85649089C9F385B35F40568D21698FD29D4355A4 to setools.keyring

++++ ovmf:

  - ovmf-rpmlintrc: Add wildcard to make the filter effective on 15.x
    again
  - Add ovmf-NetworkPkg-TcpDxe-Fixed-system-stuck-on-PXE-boot-flo.patch
    NetworkPkg TcpDxe: Fixed system stuck on PXE boot flow in
    (bsc#1230587)

------------------------------------------------------------------
------------------  2024-9-17  -  Sep 17 2024  -------------------
------------------------------------------------------------------

++++ audit-secondary:

  - Update to 4.0
  - Drop python2 support
  - Drop auvirt and autrace programs
  - Drop SysVinit support
  - Require the use of the 5.0 or later kernel headers
  - New README.md file
  - Rewrite legacy service functions in terms of systemctl
  - Consolidate and update end of event detection to a common function
  - Split off rule loading from auditd.service into audit-rules.service
  - Refactor libaudit.h to split out logging functions and record numbers
  - Speed up aureport --summary reports
  - Limit libaudit python bindings to logging functions
  - Add a metrics function for auparse
  - Change auditctl to use pidfd_send_signal for signaling auditd
  - Adjust watches to optimize syscalls hooked when watch file access
  - Drop nispom rules
  - Add intepretations for fsconfig, fsopen, fsmount, & move_mount
  - Many code fixups (cgzones)
  - Update syscall and interpretation tables to the 6.8 kernel
    (from v3.1.2)
  - When processing a run level change, make auditd exit
  - In auditd, fix return code when rules added in immutable mode
  - In auparse, when files are given, also consider EUID for access
  - Auparse now interprets unnamed/anonymous sockets (Enzo Matsumiya)
  - Disable Python bindings from setting rules due to swig bug (S. Trofimovich)
  - Update all lookup tables for the 6.5 kernel
  - Don't be as paranoid about auditctl -R file permissions
  - In ausearch, correct subject/object search to be an and if both are given
  - Adjust formats for 64 bit time_t
  - Fix segfault in python bindings around the feed API
  - Add feed_has_data, get_record_num, and get/goto_field_num to python bindings
  - Update spec:
    * Move rules-related files into new subpackage `audit-rules':
    * Files moved:
  - /sbin/auditctl, /sbin/augenrules,
    /etc/audit/{audit.rules,rules.d/audit.rules,audit-stop.rules}
  - manpages for auditctl, augenrules, and audit.rules
  - /etc/audit is now owned by `audit-rules' as well
    * Add new file /usr/lib/systemd/system/audit-rules.service
    * Remove in-house create-augenrules-service.patch that generated
    augenrules.service systemd unit service
    * Remove ownership of /usr/share/audit
    * Create /usr/share/audit-rules directory on %install
    * Remove audit-userspace-517-compat.patch (fixed upstream)
    * Remove libev-werror.patch (fixed upstream)
    * Remove audit-allow-manual-stop.patch (fixed upstream)
    * Add fix-auparse-test.patch (downstream):
    Upstream tests uses a static value (42) for 'gdm' uid/gid (based
    on Fedora values, apparently).  Replace these occurrences with
    'unknown(123456)'
    * Replace '--with-python' with '--with-python3' on %configure
    * Remove autrace and auvirt references (upstream)
    * Replace README with README.md
  - Drop `--enable-systemd' from %configure as SysV-style scripts
    aren't supported in upstream since
    113ae191758c ("Drop support for SysVinit")

++++ python-kiwi:

  - Bump version: 10.1.11 → 10.1.12
  - Add missing erofscompression validation
    In the filesystem builder I forgot to evaluate the
    erofscompression attribute. This Fixes #2647

++++ drbd:

  - drbdadm down fails to remove sysfs holder file (boo#1230635)
    * add patch
    + boo1230635_01-compat-fix-nla_nest_start_noflag-test.patch
    + boo1230635_02-drbd-port-block-device-access-to-file.patch
    * update patch
    + bsc1226510-fix-build-err-against-6.9.3.patch

++++ kernel-default:

  - cpufreq: ti-cpufreq: Introduce quirks to handle syscon fails
    appropriately (git-fixes).
  - ACPI: CPPC: Fix MASK_VAL() usage (git-fixes).
  - ACPI: PMIC: Remove unneeded check in
    tps68470_pmic_opregion_probe() (git-fixes).
  - ACPI: sysfs: validate return type of _STR method (git-fixes).
  - crypto: ccp - do not request interrupt on cmd completion when
    irqs disabled (git-fixes).
  - hwrng: mtk - Use devm_pm_runtime_enable (git-fixes).
  - crypto: ccp - Properly unregister /dev/sev on sev
    PLATFORM_STATUS failure (git-fixes).
  - hwrng: cctrng - Add missing clk_disable_unprepare in
    cctrng_resume (git-fixes).
  - hwrng: bcm2835 - Add missing clk_disable_unprepare in
    bcm2835_rng_init (git-fixes).
  - crypto: iaa - Fix potential use after free bug (git-fixes).
  - crypto: xor - fix template benchmarking (git-fixes).
  - can: m_can: m_can_close(): stop clocks after device has been
    shut down (git-fixes).
  - can: m_can: enable NAPI before enabling interrupts (git-fixes).
  - can: bcm: Clear bo->bcm_proc_read after remove_proc_entry()
    (git-fixes).
  - Bluetooth: btusb: Fix not handling ZPL/short-transfer
    (git-fixes).
  - Bluetooth: hci_sync: Ignore errors from
    HCI_OP_REMOTE_NAME_REQ_CANCEL (git-fixes).
  - Bluetooth: hci_core: Fix sending MGMT_EV_CONNECT_FAILED
    (git-fixes).
  - wifi: mt76: mt7925: fix a potential array-index-out-of-bounds
    issue for clc (git-fixes).
  - wifi: mt76: mt7615: check devm_kasprintf() returned value
    (git-fixes).
  - wifi: mt76: mt7921: Check devm_kasprintf() returned value
    (git-fixes).
  - wifi: mt76: mt7915: check devm_kasprintf() returned value
    (git-fixes).
  - wifi: mt76: mt7996: fix uninitialized TLV data (git-fixes).
  - wifi: mt76: mt7915: fix rx filter setting for bfee functionality
    (git-fixes).
  - wifi: mt76: mt7603: fix mixed declarations and code (git-fixes).
  - wifi: mt76: connac: fix checksum offload fields of connac3 RXD
    (git-fixes).
  - wifi: mt76: mt7996: fix NULL pointer dereference in
    mt7996_mcu_sta_bfer_he (git-fixes).
  - wifi: mt76: mt7996: fix EHT beamforming capability check
    (git-fixes).
  - wifi: mt76: mt7996: fix HE and EHT beamforming capabilities
    (git-fixes).
  - wifi: mt76: mt7996: fix wmm set of station interface to 3
    (git-fixes).
  - wifi: mt76: mt7996: fix traffic delay when switching back to
    working channel (git-fixes).
  - wifi: mt76: mt7996: use hweight16 to get correct tx antenna
    (git-fixes).
  - wifi: mt76: mt7921: fix wrong UNII-4 freq range check for the
    channel usage (git-fixes).
  - wifi: mt76: mt7915: fix oops on non-dbdc mt7986 (git-fixes).
  - wifi: rtw88: remove CPT execution branch never used (git-fixes).
  - wifi: wilc1000: fix potential RCU dereference issue in
    wilc_parse_join_bss_param (git-fixes).
  - wifi: mac80211: use two-phase skb reclamation in
    ieee80211_do_stop() (git-fixes).
  - wifi: cfg80211: fix two more possible UBSAN-detected off-by-one
    errors (git-fixes).
  - wifi: cfg80211: fix UBSAN noise in cfg80211_wext_siwscan()
    (git-fixes).
  - wifi: mac80211: fix the comeback long retry times (git-fixes).
  - wifi: cfg80211: fix bug of mapping AF3x to incorrect User
    Priority (git-fixes).
  - wifi: iwlwifi: mvm: increase the time between ranging
    measurements (git-fixes).
  - wifi: mac80211: don't use rate mask for offchannel TX either
    (git-fixes).
  - wifi: ath12k: fix invalid AMPDU factor calculation in
    ath12k_peer_assoc_h_he() (git-fixes).
  - wifi: ath12k: match WMI BSS chan info structure with firmware
    definition (git-fixes).
  - wifi: ath12k: fix BSS chan info request WMI command (git-fixes).
  - wifi: ath9k: Remove error checks when creating debugfs entries
    (git-fixes).
  - wifi: rtw88: always wait for both firmware loading attempts
    (git-fixes).
  - wifi: rtw88: 8822c: Fix reported RX band width (git-fixes).
  - wifi: brcmfmac: introducing fwil query functions (git-fixes).
  - can: j1939: use correct function name in comment (git-fixes).
  - commit ffce0ad

++++ kernel-rt:

  - cpufreq: ti-cpufreq: Introduce quirks to handle syscon fails
    appropriately (git-fixes).
  - ACPI: CPPC: Fix MASK_VAL() usage (git-fixes).
  - ACPI: PMIC: Remove unneeded check in
    tps68470_pmic_opregion_probe() (git-fixes).
  - ACPI: sysfs: validate return type of _STR method (git-fixes).
  - crypto: ccp - do not request interrupt on cmd completion when
    irqs disabled (git-fixes).
  - hwrng: mtk - Use devm_pm_runtime_enable (git-fixes).
  - crypto: ccp - Properly unregister /dev/sev on sev
    PLATFORM_STATUS failure (git-fixes).
  - hwrng: cctrng - Add missing clk_disable_unprepare in
    cctrng_resume (git-fixes).
  - hwrng: bcm2835 - Add missing clk_disable_unprepare in
    bcm2835_rng_init (git-fixes).
  - crypto: iaa - Fix potential use after free bug (git-fixes).
  - crypto: xor - fix template benchmarking (git-fixes).
  - can: m_can: m_can_close(): stop clocks after device has been
    shut down (git-fixes).
  - can: m_can: enable NAPI before enabling interrupts (git-fixes).
  - can: bcm: Clear bo->bcm_proc_read after remove_proc_entry()
    (git-fixes).
  - Bluetooth: btusb: Fix not handling ZPL/short-transfer
    (git-fixes).
  - Bluetooth: hci_sync: Ignore errors from
    HCI_OP_REMOTE_NAME_REQ_CANCEL (git-fixes).
  - Bluetooth: hci_core: Fix sending MGMT_EV_CONNECT_FAILED
    (git-fixes).
  - wifi: mt76: mt7925: fix a potential array-index-out-of-bounds
    issue for clc (git-fixes).
  - wifi: mt76: mt7615: check devm_kasprintf() returned value
    (git-fixes).
  - wifi: mt76: mt7921: Check devm_kasprintf() returned value
    (git-fixes).
  - wifi: mt76: mt7915: check devm_kasprintf() returned value
    (git-fixes).
  - wifi: mt76: mt7996: fix uninitialized TLV data (git-fixes).
  - wifi: mt76: mt7915: fix rx filter setting for bfee functionality
    (git-fixes).
  - wifi: mt76: mt7603: fix mixed declarations and code (git-fixes).
  - wifi: mt76: connac: fix checksum offload fields of connac3 RXD
    (git-fixes).
  - wifi: mt76: mt7996: fix NULL pointer dereference in
    mt7996_mcu_sta_bfer_he (git-fixes).
  - wifi: mt76: mt7996: fix EHT beamforming capability check
    (git-fixes).
  - wifi: mt76: mt7996: fix HE and EHT beamforming capabilities
    (git-fixes).
  - wifi: mt76: mt7996: fix wmm set of station interface to 3
    (git-fixes).
  - wifi: mt76: mt7996: fix traffic delay when switching back to
    working channel (git-fixes).
  - wifi: mt76: mt7996: use hweight16 to get correct tx antenna
    (git-fixes).
  - wifi: mt76: mt7921: fix wrong UNII-4 freq range check for the
    channel usage (git-fixes).
  - wifi: mt76: mt7915: fix oops on non-dbdc mt7986 (git-fixes).
  - wifi: rtw88: remove CPT execution branch never used (git-fixes).
  - wifi: wilc1000: fix potential RCU dereference issue in
    wilc_parse_join_bss_param (git-fixes).
  - wifi: mac80211: use two-phase skb reclamation in
    ieee80211_do_stop() (git-fixes).
  - wifi: cfg80211: fix two more possible UBSAN-detected off-by-one
    errors (git-fixes).
  - wifi: cfg80211: fix UBSAN noise in cfg80211_wext_siwscan()
    (git-fixes).
  - wifi: mac80211: fix the comeback long retry times (git-fixes).
  - wifi: cfg80211: fix bug of mapping AF3x to incorrect User
    Priority (git-fixes).
  - wifi: iwlwifi: mvm: increase the time between ranging
    measurements (git-fixes).
  - wifi: mac80211: don't use rate mask for offchannel TX either
    (git-fixes).
  - wifi: ath12k: fix invalid AMPDU factor calculation in
    ath12k_peer_assoc_h_he() (git-fixes).
  - wifi: ath12k: match WMI BSS chan info structure with firmware
    definition (git-fixes).
  - wifi: ath12k: fix BSS chan info request WMI command (git-fixes).
  - wifi: ath9k: Remove error checks when creating debugfs entries
    (git-fixes).
  - wifi: rtw88: always wait for both firmware loading attempts
    (git-fixes).
  - wifi: rtw88: 8822c: Fix reported RX band width (git-fixes).
  - wifi: brcmfmac: introducing fwil query functions (git-fixes).
  - can: j1939: use correct function name in comment (git-fixes).
  - commit ffce0ad

++++ audit:

  - Update to 4.0
  - Drop python2 support
  - Drop auvirt and autrace programs
  - Drop SysVinit support
  - Require the use of the 5.0 or later kernel headers
  - New README.md file
  - Rewrite legacy service functions in terms of systemctl
  - Consolidate and update end of event detection to a common function
  - Split off rule loading from auditd.service into audit-rules.service
  - Refactor libaudit.h to split out logging functions and record numbers
  - Speed up aureport --summary reports
  - Limit libaudit python bindings to logging functions
  - Add a metrics function for auparse
  - Change auditctl to use pidfd_send_signal for signaling auditd
  - Adjust watches to optimize syscalls hooked when watch file access
  - Drop nispom rules
  - Add intepretations for fsconfig, fsopen, fsmount, & move_mount
  - Many code fixups (cgzones)
  - Update syscall and interpretation tables to the 6.8 kernel
    (from v3.1.2)
  - When processing a run level change, make auditd exit
  - In auditd, fix return code when rules added in immutable mode
  - In auparse, when files are given, also consider EUID for access
  - Auparse now interprets unnamed/anonymous sockets (Enzo Matsumiya)
  - Disable Python bindings from setting rules due to swig bug (S. Trofimovich)
  - Update all lookup tables for the 6.5 kernel
  - Don't be as paranoid about auditctl -R file permissions
  - In ausearch, correct subject/object search to be an and if both are given
  - Adjust formats for 64 bit time_t
  - Fix segfault in python bindings around the feed API
  - Add feed_has_data, get_record_num, and get/goto_field_num to python bindings
  - Update spec:
    * Add fix-auparse-test.patch (downstream):
    Upstream tests uses a static value (42) for 'gdm' uid/gid (based
    on Fedora values, apparently).  Replace these occurrences with
    'unknown(123456)'
    * Replace '--with-python' with '--with-python3' on %configure
    * Add new headers 'audit_logging.h' and 'audit-records.h' for
    audit-devel

++++ wayland:

  - Update to release 1.23.1:
    * meson: Fix use of install_data() without specifying install_dir
    * Put WL_DEPRECATED in front of the function declarations
    * client: Handle proxies with no queue
    * scanner: extract validator function emission to helper function
    * scanner: fix validator for bitfields
    * tests: add enum bitfield test

++++ osinfo-db:

  - Add support for SLE Micro 6.1 (jsc#PED-8910)
    add-slem6.1-support.patch
  - Drop support for Leap 15.7. Next major version is Leap 16
    add-opensuse-leap-15.7-support.patch
  - Adjust place holder release-date for sle15sp7
    add-sle15sp7-support.patch

++++ virt-manager:

  - Fix SUSE SL Micro detection
    virtinst-add-slem60-detection-support.patch

------------------------------------------------------------------
------------------  2024-9-16  -  Sep 16 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Include PI and comments in XSL stylesheets
    So far comments and processing instructions (PI) were
    ignored when applying the XSL stylesheets. This commit
    updates all stylesheets to take them into account

++++ transactional-update:

  - Version 4.8.2
  - Allow specifying only low value with setup-kdump [bsc#1230537]

++++ librsvg:

  - Update to version 2.59.0:
    + The biggest change in this release is that librsvg now uses the
    Meson build system instead of autotools.
    + With Meson, librsvg now builds a lot more reliably on Windows
    and MacOS.
    + Librsvg now uses Meson instead of Autotools
    + There is a -Davif meson option to include support for AVIF in
    the image-rs crate, which librsvg uses to load raster images.
    + Librsvg now explicitly builds only its supported raster formats
    for image-rs: JPEG, PNG, GIF, WEBP, and optional compile-time
    support for AVIF). Other raster image formats are not
    supported, to minimize the attack surface.
    + Librsvg now supports cancellable rendering; you can start
    rendering an RsvgHandle in one thread, and stop it from another
    thread with a GCancellable. In the C API, you can use the
    rsvg_handle_set_cancellable_for_rendering() function; in the
    Rust API, CairoRenderer now has a with_cancellable() method.
    + For Rust users, there is now a 'librsvg-rebind' crate that
    binds the C API for use from Rust. Internally this links to the
    system's librsvg shared library, in contrast with the 'librsvg'
    crate, which is statically linked and which has a native Rust
    API. The 'librsvg-rebind' crate is for cases where the
    additional code size from static linking is not desired. This
    librsvg-rebind crate is available from crates.io.
    + A bunch of fixes to bugs found through fuzz testing.
  - Use ldconfig_scriptlets macro for some of the post(un) handling.

++++ kernel-default:

  - net: tighten bad gso csum offset check in virtio_net_hdr
    (git-fixes).
  - commit 6b94c45
  - KVM: SVM: fix emulation of msr reads/writes of MSR_FS_BASE
    and MSR_GS_BASE (git-fixes).
  - commit aeba695
  - fscache: delete fscache_cookie_lru_timer when fscache exits
    to avoid  UAF (bsc#1230602).
  - commit d2c95a5
  - Update
    patches.suse/virtio_net-Fix-napi_skb_cache_put-warning.patch
    (git-fixes CVE-2024-43835 bsc#1229289).
  - commit b9542fb
  - x86/hyperv: fix kexec crash due to VP assist page corruption
    (git-fixes).
  - Drivers: hv: vmbus: Fix the misplaced function description
    (git-fixes).
  - commit c60d936
  - Update references
    patches.suse/selinux-smack-don-t-bypass-permissions-check-in-inod.patch
    (stable-fixes CVE-2024-46695 bsc#1230519).
  - commit 2a7bb57
  - NFSv4: Add missing rescheduling points in
    nfs_client_return_marked_delegations (git-fixes).
  - commit a563f31
  - nfsd: Don't leave work of closing files to a work queue
    (bsc#1228140).
  - Refresh
    patches.suse/nfsd-use-__fput_sync-to-avoid-delayed-closing-of-fil.patch.
  - commit 83ce74a

++++ kernel-firmware-all:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-amdgpu:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-ath10k:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-ath11k:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-ath12k:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-atheros:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-bluetooth:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-bnx2:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-brcm:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-chelsio:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-dpaa2:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-i915:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-intel:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-iwlwifi:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-liquidio:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-marvell:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-media:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-mediatek:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-mellanox:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-mwifiex:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-network:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-nfp:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-nvidia:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-platform:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-prestera:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-qcom:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-qlogic:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-radeon:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-realtek:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-serial:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-sound:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-ti:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-ueagle:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-firmware-usb-network:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

++++ kernel-rt:

  - net: tighten bad gso csum offset check in virtio_net_hdr
    (git-fixes).
  - commit 6b94c45
  - KVM: SVM: fix emulation of msr reads/writes of MSR_FS_BASE
    and MSR_GS_BASE (git-fixes).
  - commit aeba695
  - fscache: delete fscache_cookie_lru_timer when fscache exits
    to avoid  UAF (bsc#1230602).
  - commit d2c95a5
  - Update
    patches.suse/virtio_net-Fix-napi_skb_cache_put-warning.patch
    (git-fixes CVE-2024-43835 bsc#1229289).
  - commit b9542fb
  - x86/hyperv: fix kexec crash due to VP assist page corruption
    (git-fixes).
  - Drivers: hv: vmbus: Fix the misplaced function description
    (git-fixes).
  - commit c60d936
  - Update references
    patches.suse/selinux-smack-don-t-bypass-permissions-check-in-inod.patch
    (stable-fixes CVE-2024-46695 bsc#1230519).
  - commit 2a7bb57
  - NFSv4: Add missing rescheduling points in
    nfs_client_return_marked_delegations (git-fixes).
  - commit a563f31
  - nfsd: Don't leave work of closing files to a work queue
    (bsc#1228140).
  - Refresh
    patches.suse/nfsd-use-__fput_sync-to-avoid-delayed-closing-of-fil.patch.
  - commit 83ce74a

++++ libcbor:

  - The doc fails to build with an assert in sphinx in 15sp6 also.

++++ ncurses:

  - Add ncurses patch 20240914
    + modify _nc_flush() to also flush stderr to help the flash capability
    to work in bash (patch by Harm te Hennepe, cf: 20201128)
    + omit -g and -fXXX flags from CFLAGS in misc/ncurses-config.in
    + improve formatting/style of manpages (patches by Branden Robinson).
    + improve examples in NCURSES-Programming-HOWTO.html
    + update comments in terminfo.src -TD

++++ shim:

  - Update shim-install to use the 'removable' way for SL-Micro
    (bsc#1230316)
    * 433cc4e Always use the removable way for SL-Micro

++++ ucode-amd:

  - Update to version 20240913 (git commit bcbdd1670bc3):
    * amdgpu: update DMCUB to v0.0.233.0 DCN351
    * copy-firmware: Handle links to uncompressed files
    * WHENCE: Fix battmgr.jsn entry type
  - Drop obsoleted workaround patch:
    copy-firmware-fix-symlink-without-compress.patch
  - Temporary revert for ath12k firmware (bsc#1230596)

------------------------------------------------------------------
------------------  2024-9-15  -  Sep 15 2024  -------------------
------------------------------------------------------------------

++++ librsvg:

  - Update to version 2.58.94:
    + The minimum supported Rust version (MSRV) is 1.77.2.
    + Fix assertion failures with large Hue value in hsl() or hwb()
    colors.
    + Limit the baseFrequency for feTurbulence to avoid integer
    overflow.
    + Only make exported symbols visible in the library's binary.
    + Fix the -Davif=enabled feature; it was not being handled
    correctly at compilation time.
    + Ensure compatibility with Binutils < 2.39.
    + Build fixes for Windows.

++++ gsettings-desktop-schemas:

  - Update to version 47.1:
    + meson: Fix project version
  - Changes from version 47.0:
    + Updated translations.

++++ kernel-default:

  - ASoC: meson: axg-card: fix 'use-after-free' (git-fixes).
  - ASoC: codecs: avoid possible garbage value in peb2466_reg_read()
    (git-fixes).
  - commit 5a67afd

++++ kernel-rt:

  - ASoC: meson: axg-card: fix 'use-after-free' (git-fixes).
  - ASoC: codecs: avoid possible garbage value in peb2466_reg_read()
    (git-fixes).
  - commit 5a67afd

++++ at-spi2-core:

  - Update to version 2.54.0:
    + Updated translations.

++++ python-cryptography:

  - Fix building on SLE based distributions

++++ strace:

  - Update to strace 6.11
    * Implemented decoding of uretprobe syscall.
    * Implemented decoding of WDIOC_GETSUPPORT and WDIOC_SETOPTIONS ioctl
    commands.
    * Enhanced decoding of unknown ioctl commands in non-abbreviated mode
    by printing the contents of the ioctl argument buffer in hexadecimal format.
    * Updated decoding of listmount, statmount, and statx syscalls.
    * Updated lists of ETHTOOL_*, IORING_*, IPPROTO_*, RWF_*, STATX_*, and V4L2_*
    constants.
    * Updated lists of ioctl commands from Linux 6.11.

------------------------------------------------------------------
------------------  2024-9-14  -  Sep 14 2024  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Update to version 2.29.3:
    * show sync files only in debug level
    * chore(watch): Add changed files path/count to log
    * build(deps): bump golang.org/x/sync from 0.7.0 to 0.8.0
    * bump compose-go to version v2.2.0
    * Restore compose v1 behavior to recreate containers when ran
    with -V
    * fix linting issues with golangci-lint 1.60.2
    * bump golang to version 1.22.7
    * bump dependencies versions, engine and cli v27.2.1 containerd
    v1.7.22 buildx v0.17.0 buildkit v0.16.0
    * build(deps): bump golang.org/x/sys from 0.22.0 to 0.25.0
    * Fix typos
    * Use logrus instead of direct output to stderr.
    * attach: close streams when done
    * Fix typo in pull.go
    * Allow combination of bind mounts and 'rebuild' watches
    * service hash must exlude depends_on
    * prefer mount API over bind
    * docs: duplicate documentation for root cmd
    * docs(wait): Fix wait command description
    * allow to add empty line in the logs when nav menu activated
    * upgrade docker versions

++++ dpdk:

  - Enable (disabled by default) installation of headers needed
    to build drivers.

++++ librsvg:

  - Update to version 2.58.92:
    + Librsvg is now part of Google's oss-fuzz and is fuzz-tested
    automatically - see
    https://gnome.pages.gitlab.gnome.org/librsvg/devel-docs/oss_fuzz.html
    for details.
    + This release has two bug fixes from fuzz testing, and a new API
    call:
  - Don't leak XML entities when the XML document fails to parse.
  - Fix stack overflow in <use> reference cycle.
  - Librsvg now supports cancellable rendering; you can start
    rendering an RsvgHandle in one thread, and stop it from
    another thread with a GCancellable. In the C API, you can use
    the rsvg_handle_set_cancellable_for_rendering() function; in
    the Rust API, CairoRenderer now has a with_cancellable()
    method.
    + Many build fixes for Windows, MacOS, iOS, and cross-compilation
    + Continued refactoring for a render tree.
    + Many fixes to the documentation.

++++ kernel-default:

  - kABI workaround for soc-qcom pmic_glink changes (CVE-2024-46693
    bsc#1230521).
  - commit 9a06e25
  - usb: typec: ucsi: Move unregister out of atomic section
    (CVE-2024-46691 bsc#1230526).
  - soc: qcom: pmic_glink: Fix race during initialization
    (CVE-2024-46693 bsc#1230521).
  - commit 26dd9b4
  - spi: nxp-fspi: fix the KASAN report out-of-bounds bug
    (git-fixes).
  - drm/syncobj: Fix syncobj leak in drm_syncobj_eventfd_ioctl
    (git-fixes).
  - drm/nouveau/fb: restore init() for ramgp102 (git-fixes).
  - dma-buf: heaps: Fix off-by-one in CMA heap fault handler
    (git-fixes).
  - drm/i915/guc: prevent a possible int overflow in wq offsets
    (git-fixes).
  - usbnet: ipheth: race between ipheth_close and error handling
    (stable-fixes).
  - commit 8d8bf2f
  - md/raid1: Fix data corruption for degraded array with slow disk
    (bsc#1230455, CVE-2024-45023).
  - commit 34cd7b5

++++ kernel-rt:

  - kABI workaround for soc-qcom pmic_glink changes (CVE-2024-46693
    bsc#1230521).
  - commit 9a06e25
  - usb: typec: ucsi: Move unregister out of atomic section
    (CVE-2024-46691 bsc#1230526).
  - soc: qcom: pmic_glink: Fix race during initialization
    (CVE-2024-46693 bsc#1230521).
  - commit 26dd9b4
  - spi: nxp-fspi: fix the KASAN report out-of-bounds bug
    (git-fixes).
  - drm/syncobj: Fix syncobj leak in drm_syncobj_eventfd_ioctl
    (git-fixes).
  - drm/nouveau/fb: restore init() for ramgp102 (git-fixes).
  - dma-buf: heaps: Fix off-by-one in CMA heap fault handler
    (git-fixes).
  - drm/i915/guc: prevent a possible int overflow in wq offsets
    (git-fixes).
  - usbnet: ipheth: race between ipheth_close and error handling
    (stable-fixes).
  - commit 8d8bf2f
  - md/raid1: Fix data corruption for degraded array with slow disk
    (bsc#1230455, CVE-2024-45023).
  - commit 34cd7b5

------------------------------------------------------------------
------------------  2024-9-13  -  Sep 13 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - drop U_egl-x11-sw-fix-partial-image-uploads.patch:
    the code in the function saw further fixes later on in the 24.2
    branch.
  - U_egl-x11-sw-fix-partial-image-uploads.patch
    * culprit for the regression in 24.1.4; reverse apply this for
    now (boo#1228164)

++++ Mesa-drivers:

  - drop U_egl-x11-sw-fix-partial-image-uploads.patch:
    the code in the function saw further fixes later on in the 24.2
    branch.
  - U_egl-x11-sw-fix-partial-image-uploads.patch
    * culprit for the regression in 24.1.4; reverse apply this for
    now (boo#1228164)

++++ cryptsetup:

  - Update to 2.7.5:
    * Fix possible online reencryption data corruption (only in 2.7.x).
    In some situations (initializing a suspended device-mapper device),
    cryptsetup disabled direct-io device access. This caused unsafe
    online reencryption operations that could lead to data corruption.
    The code now adds strict checks (and aborts the operation) and
    changes direct-io detection code to prevent data corruption.
    * Fix a clang compilation error in SSH token plugin.
    As clang linker treats missing symbols as errors, the linker phase
    for the SSH token failed as the optional cryptsetup_token_buffer_free
    was not defined.
    * Fix crypto backend initialization in crypt_format_luks2_opal API call.

++++ dpdk:

  - Use python macros from build config

++++ python-kiwi:

  - Bump version: 10.1.10 → 10.1.11
  - doc: Add login information test build test images
  - Bump version: 10.1.9 → 10.1.10

++++ librsvg:

  - Update to version 2.58.91:
    + Librsvg now requires cairo version 1.18.0 or later.
    + Librsvg now explicitly builds only its supported raster
    formats for image-rs: JPEG, PNG, GIF, WEBP, and optional
    compile-time support for AVIF. Other raster image formats are
    not supported, to minimize the attack surface.
    + Don't generate gdk-pixbuf loaders cache if DESTDIR is set.
    + Documentation updates for meson.
    + Document the fact that the default DPI in the C API for
    RsvgHandle is 90 DPI, unlike rsvg-convert and the Rust API,
    which use 96 DPI.
    + Document the security considerations for the image-rs crate
    and the raster image formats that librsvg supports.
    + Fix and fine-tune compilation on Windows (MSVC and msys2),
    MacOS, and Android.
    + Fix installation when only compiling the static library.
    + Update Pango for CI and fix a test file. The test suite now
    includes the DejaVu Sans font, which supports extra
    glyphs/languages for the test suite.
  - Changesfrom version 2.58.90:
    + librsvg has been ported to the Meson build system.  Librsvg no
    longer uses autotools!
    + Changes in this release:
  - Librsvg now uses Meson instead of Autotools.
  - There is a -Davif meson option to include support for AVIF in
    the image-rs crate, which librsvg uses to load raster images.
  - Start revamping the fuzzing infrastructure.
  - Add cargo-c and pkgconfig(dav1d) BuildRequires: new dependencies.

++++ gobject-introspection:

  - Update to version 1.82.0:
    + Require GLib 2.82.0

++++ groff:

  - Add groff-restore-hyphen-minus.patch (bsc#1226153)

++++ kernel-default:

  - perf/x86/intel: Limit the period on Haswell (git-fixes).
  - perf/x86: Fix smp_processor_id()-in-preemptible warnings
    (git-fixes).
  - perf/x86/intel/cstate: Add pkg C2 residency counter for Sierra
    Forest (git-fixes).
  - ARM: 9406/1: Fix callchain_trace() return value (git-fixes).
  - bpf, events: Use prog to emit ksymbol event for main program
    (git-fixes).
  - perf/x86/intel: Add a distinct name for Granite Rapids
    (git-fixes).
  - perf/x86/intel/ds: Fix non 0 retire latency on Raptorlake
    (git-fixes).
  - perf/x86/intel/uncore: Fix the bits of the CHA extended umask
    for SPR (git-fixes).
  - perf: Fix event leak upon exit (git-fixes).
  - perf/x86/intel/cstate: Fix Alderlake/Raptorlake/Meteorlake
    (git-fixes).
  - perf: Fix default aux_watermark calculation (git-fixes).
  - perf: Prevent passing zero nr_pages to rb_alloc_aux()
    (git-fixes).
  - perf: Fix perf_aux_size() for greater-than 32-bit size
    (git-fixes).
  - perf/x86/intel/pt: Fix pt_topa_entry_for_page() address
    calculation (git-fixes).
  - perf/x86/intel/pt: Fix a topa_entry base address calculation
    (git-fixes).
  - perf/x86/intel/pt: Fix topa_entry base length (git-fixes).
  - perf/x86: Serialize set_attr_rdpmc() (git-fixes).
  - perf/core: Fix missing wakeup when waiting for context reference
    (git-fixes).
  - perf/x86/intel: Factor out the initialization code for SPR
    (git fixes).
  - perf/x86/intel: Use the common uarch name for the shared
    functions (git fixes).
  - commit bb48e43
  - nvme: move stopping keep-alive into nvme_uninit_ctrl() (CVE-2024-45013 bsc#1230442)
  - commit ce739c4
  - i2c: tegra: Do not mark ACPI devices as irq safe (CVE-2024-45029 bsc#1230451)
  - commit 2870112
  - netfilter: flowtable: initialise extack before use (CVE-2024-45018 bsc#1230431)
  - commit 8b44b15
  - net/mlx5e: Take state lock during tx timeout reporter (CVE-2024-45019 bsc#1230432)
  - commit 2552371
  - net/mlx5: Fix IPsec RoCE MPV trace call (CVE-2024-45017 bsc#1230430)
  - commit 60aac02
  - igb: cope with large MAX_SKB_FRAGS (CVE-2024-45030 bsc#1230457)
  - commit d2d3c69
  - Move s390 kabi patch into the kabi section
  - commit 4ab5d36
  - s390/uv: Don't call folio_wait_writeback() without a folio
    reference (git-fixes bsc#1229380 CVE-2024-43832).
  - s390/mm: Convert gmap_make_secure to use a folio (git-fixes
    bsc#1230562).
  - s390/mm: Convert make_page_secure to use a folio (git-fixes
    bsc#1230563).
  - s390: allow pte_offset_map_lock() to fail (git-fixes
    bsc#1230564).
  - commit 7069eb7
  - mm/vmalloc: fix page mapping if vm_area_alloc_pages() with
    high order fallback to order 0 (CVE-2024-45022 bsc#1230435).
  - commit cc8880a
  - Revert "mm/sparsemem: fix race in accessing memory_section->usage"
    This reverts commit 6aa8957889611fbe7f06353f917cfb3d9620a680 to fix a regression (bsc#1230413)
  - commit 720e36b
  - Revert "mm, kmsan: fix infinite recursion due to RCU critical section"
    This reverts commit 16ad73a9f4c2888f3bc28513f5e9a88d753f8741 to fix a regression (bsc#1230413)
  - commit 2fd5290
  - Revert "mm: prevent derefencing NULL ptr in pfn_section_valid()"
    This reverts commit 35f619d3c421219e07bc89d2d6a37fbff25519fe to fix a refression
    (bsc#1230413)
  - commit 7e5afd7
  - memcg_write_event_control(): fix a user-triggerable oops
    (CVE-2024-45021 bsc#1230434).
  - commit 99a85a8
  - platform/x86: panasonic-laptop: Allocate 1 entry extra in the
    sinf array (git-fixes).
  - platform/x86: panasonic-laptop: Fix SINF array out of bounds
    accesses (git-fixes).
  - usb: dwc3: core: update LC timer as per USB Spec V3.2
    (stable-fixes).
  - lib/generic-radix-tree.c: Fix rare race in
    __genradix_ptr_alloc() (stable-fixes).
  - kselftests: dmabuf-heaps: Ensure the driver name is
    null-terminated (stable-fixes).
  - regmap: maple: work around gcc-14.1 false-positive warning
    (stable-fixes).
  - phy: zynqmp: Take the phy mutex in xlate (stable-fixes).
  - pcmcia: Use resource_size function on resource object
    (stable-fixes).
  - pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv
    (stable-fixes).
  - PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)
    (stable-fixes).
  - PCI: Add missing bridge lock to pci_bus_lock() (stable-fixes).
  - usb: gadget: aspeed_udc: validate endpoint index for ast udc
    (stable-fixes).
  - usb: uas: set host status byte on data completion error
    (stable-fixes).
  - media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse
    (stable-fixes).
  - media: vivid: don't set HDMI TX controls if there are no HDMI
    outputs (stable-fixes).
  - media: vivid: fix wrong sizeimage value for mplane
    (stable-fixes).
  - leds: spi-byte: Call of_node_put() on error path (stable-fixes).
  - wifi: rtw88: usb: schedule rx work after everything is set up
    (stable-fixes).
  - wifi: rtw89: wow: prevent to send unexpected H2C during download
    Firmware (stable-fixes).
  - wifi: mwifiex: Do not return unused priv in
    mwifiex_get_priv_by_id() (stable-fixes).
  - wifi: ath12k: fix firmware crash due to invalid peer nss
    (stable-fixes).
  - wifi: ath12k: fix uninitialize symbol error on
    ath12k_peer_assoc_h_he() (stable-fixes).
  - wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3
    (stable-fixes).
  - wifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check
    (stable-fixes).
  - commit 3b57fa8
  - Squashfs: sanity check symbolic link size (git-fixes).
  - commit fa6af4a
  - hwmon: (pmbus) Conditionally clear individual status bits for
    pmbus rev >= 1.2 (git-fixes).
  - Input: uinput - reject requests with unreasonable number of
    slots (stable-fixes).
  - HID: amd_sfh: free driver_data after destroying hid device
    (stable-fixes).
  - HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
    (stable-fixes).
  - i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA
    setup (stable-fixes).
  - Input: ili210x - use kvmalloc() to allocate buffer for firmware
    update (stable-fixes).
  - drm/amdgpu: reject gang submit on reserved VMIDs (stable-fixes).
  - drm/amdgpu: Set no_hw_access when VF request full GPU fails
    (stable-fixes).
  - drm/amdgpu/display: handle gfx12 in
    amdgpu_dm_plane_format_mod_supported (stable-fixes).
  - drm/amdgpu: handle gfx12 in amdgpu_display_verify_sizes
    (stable-fixes).
  - drm/amdgpu: check for LINEAR_ALIGNED correctly in
    check_tiling_flags_gfx6 (stable-fixes).
  - drm/amd/display: Check denominator pbn_div before used
    (stable-fixes).
  - drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts
    (stable-fixes).
  - drm/amdgpu: Fix smatch static checker warning (stable-fixes).
  - drm/amdgpu: add missing error handling in function
    amdgpu_gmc_flush_gpu_tlb_pasid (stable-fixes).
  - drm/amd/display: Check HDCP returned status (stable-fixes).
  - hwmon: (w83627ehf) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - hwmon: (nct6775-core) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - hwmon: (lm95234) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - hwmon: (adc128d818) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - commit 2fa929e
  - Revert "mm/sparsemem: fix race in accessing memory_section->usage"
    This reverts commit 6aa8957889611fbe7f06353f917cfb3d9620a680.
  - commit 5376e5a
  - Revert "mm, kmsan: fix infinite recursion due to RCU critical section"
    This reverts commit 16ad73a9f4c2888f3bc28513f5e9a88d753f8741.
  - commit 505329c
  - Revert "mm: prevent derefencing NULL ptr in pfn_section_valid()"
    This reverts commit 35f619d3c421219e07bc89d2d6a37fbff25519fe.
  - commit 937414d
  - ata: libata: Fix memory leak for error path in ata_host_alloc()
    (git-fixes).
  - devres: Initialize an uninitialized struct member
    (stable-fixes).
  - ASoc: TAS2781: replace beXX_to_cpup with get_unaligned_beXX
    for potentially broken alignment (stable-fixes).
  - ASoC: topology: Properly initialize soc_enum values
    (stable-fixes).
  - ALSA: hda: Add input value sanity checks to HDMI channel map
    controls (stable-fixes).
  - ALSA: control: Apply sanity check of input values for user
    elements (stable-fixes).
  - crypto: qat - fix unintentional re-enabling of error interrupts
    (stable-fixes).
  - drm/amd/display: Run DC_LOG_DC after checking link->link_enc
    (stable-fixes).
  - drm/amd/display: Check UnboundedRequestEnabled's value
    (stable-fixes).
  - drm/amd: Add gfx12 swizzle mode defs (stable-fixes).
  - Bluetooth: btnxpuart: Fix Null pointer dereference in
    btnxpuart_flush() (stable-fixes).
  - can: mcp251xfd: rx: add workaround for erratum DS80000789E 6
    of mcp2518fd (stable-fixes).
  - can: mcp251xfd: rx: prepare to workaround broken RX FIFO head
    index erratum (stable-fixes).
  - can: mcp251xfd: mcp251xfd_handle_rxif_ring_uinc(): factor out
    in separate function (stable-fixes).
  - can: mcp251xfd: clarify the meaning of timestamp (stable-fixes).
  - can: kvaser_pciefd: Skip redundant NULL pointer check in ISR
    (stable-fixes).
  - ACPI: processor: Fix memory leaks in error paths of
    processor_add() (stable-fixes).
  - ACPI: processor: Return an error if acpi_processor_get_info()
    fails in processor_add() (stable-fixes).
  - cpufreq: amd-pstate: fix the highest frequency issue which
    limits performance (git-fixes).
  - cpufreq: amd-pstate: Enable amd-pstate preferred core support
    (stable-fixes).
  - ACPI: CPPC: Add helper to get the highest performance value
    (stable-fixes).
  - Bluetooth: hci_sync: Add helper functions to manipulate cmd_sync
    queue (stable-fixes).
  - Bluetooth: hci_event: Use HCI error defines instead of magic
    values (stable-fixes).
  - commit 96be389

++++ kernel-firmware-all:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-amdgpu:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-ath10k:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-ath11k:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-ath12k:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-atheros:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-bluetooth:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-bnx2:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-brcm:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-chelsio:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-dpaa2:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-i915:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-intel:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-iwlwifi:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-liquidio:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-marvell:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-media:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-mediatek:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-mellanox:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-mwifiex:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-network:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-nfp:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-nvidia:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-platform:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-prestera:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-qcom:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-qlogic:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-radeon:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-realtek:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-serial:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-sound:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-ti:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-ueagle:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-firmware-usb-network:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

++++ kernel-rt:

  - perf/x86/intel: Limit the period on Haswell (git-fixes).
  - perf/x86: Fix smp_processor_id()-in-preemptible warnings
    (git-fixes).
  - perf/x86/intel/cstate: Add pkg C2 residency counter for Sierra
    Forest (git-fixes).
  - ARM: 9406/1: Fix callchain_trace() return value (git-fixes).
  - bpf, events: Use prog to emit ksymbol event for main program
    (git-fixes).
  - perf/x86/intel: Add a distinct name for Granite Rapids
    (git-fixes).
  - perf/x86/intel/ds: Fix non 0 retire latency on Raptorlake
    (git-fixes).
  - perf/x86/intel/uncore: Fix the bits of the CHA extended umask
    for SPR (git-fixes).
  - perf: Fix event leak upon exit (git-fixes).
  - perf/x86/intel/cstate: Fix Alderlake/Raptorlake/Meteorlake
    (git-fixes).
  - perf: Fix default aux_watermark calculation (git-fixes).
  - perf: Prevent passing zero nr_pages to rb_alloc_aux()
    (git-fixes).
  - perf: Fix perf_aux_size() for greater-than 32-bit size
    (git-fixes).
  - perf/x86/intel/pt: Fix pt_topa_entry_for_page() address
    calculation (git-fixes).
  - perf/x86/intel/pt: Fix a topa_entry base address calculation
    (git-fixes).
  - perf/x86/intel/pt: Fix topa_entry base length (git-fixes).
  - perf/x86: Serialize set_attr_rdpmc() (git-fixes).
  - perf/core: Fix missing wakeup when waiting for context reference
    (git-fixes).
  - perf/x86/intel: Factor out the initialization code for SPR
    (git fixes).
  - perf/x86/intel: Use the common uarch name for the shared
    functions (git fixes).
  - commit bb48e43
  - nvme: move stopping keep-alive into nvme_uninit_ctrl() (CVE-2024-45013 bsc#1230442)
  - commit ce739c4
  - i2c: tegra: Do not mark ACPI devices as irq safe (CVE-2024-45029 bsc#1230451)
  - commit 2870112
  - netfilter: flowtable: initialise extack before use (CVE-2024-45018 bsc#1230431)
  - commit 8b44b15
  - net/mlx5e: Take state lock during tx timeout reporter (CVE-2024-45019 bsc#1230432)
  - commit 2552371
  - net/mlx5: Fix IPsec RoCE MPV trace call (CVE-2024-45017 bsc#1230430)
  - commit 60aac02
  - igb: cope with large MAX_SKB_FRAGS (CVE-2024-45030 bsc#1230457)
  - commit d2d3c69
  - Move s390 kabi patch into the kabi section
  - commit 4ab5d36
  - s390/uv: Don't call folio_wait_writeback() without a folio
    reference (git-fixes bsc#1229380 CVE-2024-43832).
  - s390/mm: Convert gmap_make_secure to use a folio (git-fixes
    bsc#1230562).
  - s390/mm: Convert make_page_secure to use a folio (git-fixes
    bsc#1230563).
  - s390: allow pte_offset_map_lock() to fail (git-fixes
    bsc#1230564).
  - commit 7069eb7
  - mm/vmalloc: fix page mapping if vm_area_alloc_pages() with
    high order fallback to order 0 (CVE-2024-45022 bsc#1230435).
  - commit cc8880a
  - Revert "mm/sparsemem: fix race in accessing memory_section->usage"
    This reverts commit 6aa8957889611fbe7f06353f917cfb3d9620a680 to fix a regression (bsc#1230413)
  - commit 720e36b
  - Revert "mm, kmsan: fix infinite recursion due to RCU critical section"
    This reverts commit 16ad73a9f4c2888f3bc28513f5e9a88d753f8741 to fix a regression (bsc#1230413)
  - commit 2fd5290
  - Revert "mm: prevent derefencing NULL ptr in pfn_section_valid()"
    This reverts commit 35f619d3c421219e07bc89d2d6a37fbff25519fe to fix a refression
    (bsc#1230413)
  - commit 7e5afd7
  - memcg_write_event_control(): fix a user-triggerable oops
    (CVE-2024-45021 bsc#1230434).
  - commit 99a85a8
  - platform/x86: panasonic-laptop: Allocate 1 entry extra in the
    sinf array (git-fixes).
  - platform/x86: panasonic-laptop: Fix SINF array out of bounds
    accesses (git-fixes).
  - usb: dwc3: core: update LC timer as per USB Spec V3.2
    (stable-fixes).
  - lib/generic-radix-tree.c: Fix rare race in
    __genradix_ptr_alloc() (stable-fixes).
  - kselftests: dmabuf-heaps: Ensure the driver name is
    null-terminated (stable-fixes).
  - regmap: maple: work around gcc-14.1 false-positive warning
    (stable-fixes).
  - phy: zynqmp: Take the phy mutex in xlate (stable-fixes).
  - pcmcia: Use resource_size function on resource object
    (stable-fixes).
  - pci/hotplug/pnv_php: Fix hotplug driver crash on Powernv
    (stable-fixes).
  - PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0)
    (stable-fixes).
  - PCI: Add missing bridge lock to pci_bus_lock() (stable-fixes).
  - usb: gadget: aspeed_udc: validate endpoint index for ast udc
    (stable-fixes).
  - usb: uas: set host status byte on data completion error
    (stable-fixes).
  - media: qcom: camss: Add check for v4l2_fwnode_endpoint_parse
    (stable-fixes).
  - media: vivid: don't set HDMI TX controls if there are no HDMI
    outputs (stable-fixes).
  - media: vivid: fix wrong sizeimage value for mplane
    (stable-fixes).
  - leds: spi-byte: Call of_node_put() on error path (stable-fixes).
  - wifi: rtw88: usb: schedule rx work after everything is set up
    (stable-fixes).
  - wifi: rtw89: wow: prevent to send unexpected H2C during download
    Firmware (stable-fixes).
  - wifi: mwifiex: Do not return unused priv in
    mwifiex_get_priv_by_id() (stable-fixes).
  - wifi: ath12k: fix firmware crash due to invalid peer nss
    (stable-fixes).
  - wifi: ath12k: fix uninitialize symbol error on
    ath12k_peer_assoc_h_he() (stable-fixes).
  - wifi: brcmsmac: advertise MFP_CAPABLE to enable WPA3
    (stable-fixes).
  - wifi: iwlwifi: mvm: use IWL_FW_CHECK for link ID check
    (stable-fixes).
  - commit 3b57fa8
  - Squashfs: sanity check symbolic link size (git-fixes).
  - commit fa6af4a
  - hwmon: (pmbus) Conditionally clear individual status bits for
    pmbus rev >= 1.2 (git-fixes).
  - Input: uinput - reject requests with unreasonable number of
    slots (stable-fixes).
  - HID: amd_sfh: free driver_data after destroying hid device
    (stable-fixes).
  - HID: cougar: fix slab-out-of-bounds Read in cougar_report_fixup
    (stable-fixes).
  - i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA
    setup (stable-fixes).
  - Input: ili210x - use kvmalloc() to allocate buffer for firmware
    update (stable-fixes).
  - drm/amdgpu: reject gang submit on reserved VMIDs (stable-fixes).
  - drm/amdgpu: Set no_hw_access when VF request full GPU fails
    (stable-fixes).
  - drm/amdgpu/display: handle gfx12 in
    amdgpu_dm_plane_format_mod_supported (stable-fixes).
  - drm/amdgpu: handle gfx12 in amdgpu_display_verify_sizes
    (stable-fixes).
  - drm/amdgpu: check for LINEAR_ALIGNED correctly in
    check_tiling_flags_gfx6 (stable-fixes).
  - drm/amd/display: Check denominator pbn_div before used
    (stable-fixes).
  - drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts
    (stable-fixes).
  - drm/amdgpu: Fix smatch static checker warning (stable-fixes).
  - drm/amdgpu: add missing error handling in function
    amdgpu_gmc_flush_gpu_tlb_pasid (stable-fixes).
  - drm/amd/display: Check HDCP returned status (stable-fixes).
  - hwmon: (w83627ehf) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - hwmon: (nct6775-core) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - hwmon: (lm95234) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - hwmon: (adc128d818) Fix underflows seen when writing limit
    attributes (stable-fixes).
  - commit 2fa929e
  - Revert "mm/sparsemem: fix race in accessing memory_section->usage"
    This reverts commit 6aa8957889611fbe7f06353f917cfb3d9620a680.
  - commit 5376e5a
  - Revert "mm, kmsan: fix infinite recursion due to RCU critical section"
    This reverts commit 16ad73a9f4c2888f3bc28513f5e9a88d753f8741.
  - commit 505329c
  - Revert "mm: prevent derefencing NULL ptr in pfn_section_valid()"
    This reverts commit 35f619d3c421219e07bc89d2d6a37fbff25519fe.
  - commit 937414d
  - ata: libata: Fix memory leak for error path in ata_host_alloc()
    (git-fixes).
  - devres: Initialize an uninitialized struct member
    (stable-fixes).
  - ASoc: TAS2781: replace beXX_to_cpup with get_unaligned_beXX
    for potentially broken alignment (stable-fixes).
  - ASoC: topology: Properly initialize soc_enum values
    (stable-fixes).
  - ALSA: hda: Add input value sanity checks to HDMI channel map
    controls (stable-fixes).
  - ALSA: control: Apply sanity check of input values for user
    elements (stable-fixes).
  - crypto: qat - fix unintentional re-enabling of error interrupts
    (stable-fixes).
  - drm/amd/display: Run DC_LOG_DC after checking link->link_enc
    (stable-fixes).
  - drm/amd/display: Check UnboundedRequestEnabled's value
    (stable-fixes).
  - drm/amd: Add gfx12 swizzle mode defs (stable-fixes).
  - Bluetooth: btnxpuart: Fix Null pointer dereference in
    btnxpuart_flush() (stable-fixes).
  - can: mcp251xfd: rx: add workaround for erratum DS80000789E 6
    of mcp2518fd (stable-fixes).
  - can: mcp251xfd: rx: prepare to workaround broken RX FIFO head
    index erratum (stable-fixes).
  - can: mcp251xfd: mcp251xfd_handle_rxif_ring_uinc(): factor out
    in separate function (stable-fixes).
  - can: mcp251xfd: clarify the meaning of timestamp (stable-fixes).
  - can: kvaser_pciefd: Skip redundant NULL pointer check in ISR
    (stable-fixes).
  - ACPI: processor: Fix memory leaks in error paths of
    processor_add() (stable-fixes).
  - ACPI: processor: Return an error if acpi_processor_get_info()
    fails in processor_add() (stable-fixes).
  - cpufreq: amd-pstate: fix the highest frequency issue which
    limits performance (git-fixes).
  - cpufreq: amd-pstate: Enable amd-pstate preferred core support
    (stable-fixes).
  - ACPI: CPPC: Add helper to get the highest performance value
    (stable-fixes).
  - Bluetooth: hci_sync: Add helper functions to manipulate cmd_sync
    queue (stable-fixes).
  - Bluetooth: hci_event: Use HCI error defines instead of magic
    values (stable-fixes).
  - commit 96be389

++++ kexec-tools:

  - To create rckexec-reload, the service binary is required at
    build time. This binary is provided by aaa_base. Make sure this
    package is available during build.

++++ oath-toolkit:

  - Fix security issue CVE-2024-47191 by adding
    0001-usersfile-fix-potential-security-issues-in-PAM-modul.patch .
  - Add patch to implement new null_usersfile_okay argument
    42-null_usersfile_okay.patch .
  - Makes this version 2.6.11.12 to be able to depend on it.

++++ p11-kit:

  - Update to 0.25.5:
    * iter: fix recursive attribute loading
    * fix building on FreeBSD 14.0 (amd64)
    * Remove p11-kit-d938f4a8a3a2.patch upstream
  - Update to 0.25.4:
    * rpc: add support for recursive attributes
    * p11-kit: add function to check run-time version of the library
    * p11-kit: expose version information through macros
    * p11-kit: add option to specify CKA_ID in generate-keypair and
    import-object commands
    * p11-kit: add --provider option to specify PKCS#11 module when
    using p11-kit commands
    * p11-kit: fix a bug where eddsa mechanism isn't recognized in
    generate-keypair
    * p11-kit: fallback to C_GetFunctionList when C_GetInterface
    returns CKR_FUNCTION_NOT_SUPPORTED
    * bug and build fixes

++++ libssh:

  - Update to version 0.11.1:
    * Fixed default TTY modes that are set when stdin is not
    connected to tty.
    * Fixed zlib cleanup procedure, which could crash on i386.
    * Various test fixes improving their stability.
    * Remove 0001-disable-timeout-test-on-slow-buildsystems.patch
    to enable slow tests also in s390 s390x ppc64le.
  - Set BuildArch: noarch for the config package as it only ships
    configuration files.

++++ makedumpfile:

  - move makedumpfile-R.pl from /usr/bin to
    /usr/share/makedumpfile-{version} (bsc#1230448)

++++ python-msgpack:

  - Update to 1.1.0
    * Avoid using floating points during timestamp-datetime conversions in #591
    * use ruff instead of black in #598
    * update Cython and setuptools in #599
    * Add experimental support for Python 3.13 in #600
    * update README in #561
    * update cibuildwheel to 2.17 in #601
    * implement buffer protocol in #602
    * Remove unused code in #603
    * packer: add buf_size option in #604
    * update readme in #605
    * cython: better exception handling in #606
    * better error checks in #607
    * Cleanup code and pyproject in #608
    * Release v1.1.0rc1 in #609
    * do not install cython as build dependency in #610
    * update Cython to 3.0.11 in #617
    * update cibuildwheel to 2.20.0 in #618
    * Release v1.1.0rc2 in #619
    * MNT: use PyLong_* instead of PyInt_* in #620
    * release v1.1.0 in #622

++++ python-setuptools:

  - Remove BuildRequires on wheel, it has been adopted since 71.1.
  - Sort out test suite changes.

++++ sevctl:

  - Update vendored dependencies and re-enable cargo update obs service (bsc#1229953)
  - Service: Remove deprecated cargo_config and cargo_audit services, both
    are now handled by the cargo_vendor services

++++ suseconnect-ng:

  - Update version to 1.12:
  - Set the filesystem root on zypper when given (bsc#1230229,bsc#1229014)

++++ ucode-amd:

  - Update to version 20240912 (git commit 47c72fee8fe3):
    * amdgpu: Add VPE 6.1.3 microcode
    * amdgpu: add SDMA 6.1.2 microcode
    * amdgpu: Add support for PSP 14.0.4
    * amdgpu: add GC 11.5.2 microcode
    * qcom: qcm6490: add ADSP and CDSP firmware
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
  - Temporary fix for the missing symlink installations:
    copy-firmware-fix-symlink-without-compress.patch

------------------------------------------------------------------
------------------  2024-9-12  -  Sep 12 2024  -------------------
------------------------------------------------------------------

++++ afterburn:

  - enable all arches

++++ python-kiwi:

  - bootloader: Fix up ppc64 bootinfo again
    To make the code look pretty extra newline is inserted at the start of
    bootinfo file. This appears to break boot on Power9 PowerVM LPARs.
  - Add support for erofs
    erofs is an alternative readonly filesystem that can be
    used as alternative to squashfs. This Fixes #2633
  - Fixed enclave integration test
    The SELinux policy of Fedora Rawhide when running completely in
    an initrd is not suitable to let the system boot up. Thus the
    current solution is to boot in permissive mode. A better solution
    for the future would probably be a selinux policy for enclaves

++++ gettext-runtime:

  - Move envsubst requires into main package, gettext.sh is not part of
    gettext-tools, but gettext-runtime (fixes boo#1227070)

++++ librsvg:

  - Update to version 2.58.4:
    + Fix regression when using an SVG inside a feImage element.

++++ kernel-default:

  - virtio_net: Fix napi_skb_cache_put warning (git-fixes).
  - commit 860ef0a
  - virtio_net: fixing XDP for fully checksummed packets handling
    (git-fixes).
  - commit 77fb9e7
  - s390/dasd: Fix redundant /proc/dasd* entries removal
    (bsc#1227694).
  - commit b66530a
  - Move upstreamed input patch into sorted section
  - commit e197a51
  - KVM: SVM: Don't advertise Bus Lock Detect to guest if SVM
    support is missing (git-fixes).
  - commit 42f7b0c
  - KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS
    (git-fixes).
  - commit 610cfdd
  - KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3
    (git-fixes).
  - commit bae7627
  - kABI: Workaround kABI change in
    patches.suse/iommu-dma-Trace-bounce-buffer-usage-when-mapping-buf.patch
    (git-fixes).
  - Refresh
    patches.suse/iommu-dma-Trace-bounce-buffer-usage-when-mapping-buf.patch.
  - commit d37ca1f
  - KVM: arm64: Do not re-initialize the KVM lock (git-fixes).
  - commit b05c6c8
  - s390/dasd: Remove DMA alignment (LTC#208933 bsc#1230426
    git-fixes).
  - commit 5b1f3c2
  - KVM: arm64: vgic-v2: Check for non-NULL vCPU in
    vgic_v2_parse_attr() (git-fixes).
  - commit 4ccaaf2
  - KVM: arm64: Don't pass a TLBI level hint when zapping table
    entries (git-fixes).
  - commit e3cb3e5
  - KVM: arm64: nvhe: Ignore SVE hint in SMCCC function ID
    (git-fixes).
  - commit 9d7939a
  - KVM: arm64: Block unsafe FF-A calls from the host (git-fixes).
  - commit 6327e50
  - minmax: reduce min/max macro expansion in atomisp driver
    (git-fixes).
  - commit 6d37707
  - net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register() (CVE-2024-44971 bsc#1230211)
  - commit f262d95
  - tcp: prevent concurrent execution of tcp_sk_exit_batch (CVE-2024-44991 bsc#1230195)
  - commit 179b01d

++++ kernel-rt:

  - virtio_net: Fix napi_skb_cache_put warning (git-fixes).
  - commit 860ef0a
  - virtio_net: fixing XDP for fully checksummed packets handling
    (git-fixes).
  - commit 77fb9e7
  - s390/dasd: Fix redundant /proc/dasd* entries removal
    (bsc#1227694).
  - commit b66530a
  - Move upstreamed input patch into sorted section
  - commit e197a51
  - KVM: SVM: Don't advertise Bus Lock Detect to guest if SVM
    support is missing (git-fixes).
  - commit 42f7b0c
  - KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS
    (git-fixes).
  - commit 610cfdd
  - KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3
    (git-fixes).
  - commit bae7627
  - kABI: Workaround kABI change in
    patches.suse/iommu-dma-Trace-bounce-buffer-usage-when-mapping-buf.patch
    (git-fixes).
  - Refresh
    patches.suse/iommu-dma-Trace-bounce-buffer-usage-when-mapping-buf.patch.
  - commit d37ca1f
  - KVM: arm64: Do not re-initialize the KVM lock (git-fixes).
  - commit b05c6c8
  - s390/dasd: Remove DMA alignment (LTC#208933 bsc#1230426
    git-fixes).
  - commit 5b1f3c2
  - KVM: arm64: vgic-v2: Check for non-NULL vCPU in
    vgic_v2_parse_attr() (git-fixes).
  - commit 4ccaaf2
  - KVM: arm64: Don't pass a TLBI level hint when zapping table
    entries (git-fixes).
  - commit e3cb3e5
  - KVM: arm64: nvhe: Ignore SVE hint in SMCCC function ID
    (git-fixes).
  - commit 9d7939a
  - KVM: arm64: Block unsafe FF-A calls from the host (git-fixes).
  - commit 6327e50
  - minmax: reduce min/max macro expansion in atomisp driver
    (git-fixes).
  - commit 6d37707
  - net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register() (CVE-2024-44971 bsc#1230211)
  - commit f262d95
  - tcp: prevent concurrent execution of tcp_sk_exit_batch (CVE-2024-44991 bsc#1230195)
  - commit 179b01d

++++ bluez:

  - Mark the configuration files as 'noreplace'.
  - Update to 5.78:
    * Fix issue with handling notification of scanned BISes to BASS
    * Fix issue with handling checking BIS caps against peer caps.
    * Fix issue with handling MGMT Set Device Flags overwrites.
    * Fix issue with handling ASE notification order.
    * Fix issue with handling BIG Info report events.
    * Fix issue with handling PACS Server role.
    * Fix issue with registering UHID_START multiple times.
    * Fix issue with pairing method not setting auto-connect.
  - Fix 3 rpmlint warnings, some configuration files were not marked as so.

++++ python313-core:

  - Make it build for SLE SP7 (jsc#PED-10075):
  - Add CVE-2023-52425-libexpat-2.6.0-backport-15.6.patch to build in
    SLE-15-SP7.
  - Add fix-test-recursion-limit-15.6.patch, gh#python/cpython#115083
  - Add gh-124040-fix-test-math-i586.patch, gh#python/cpython#124042

++++ libzypp:

  - Deprecate librpmDb::db_const_iterator default ctor (bsc#1230267)
    It's preferred to explicitly tell the root directory of the
    system whose database you want to query.
  - version 17.35.11 (35)

++++ openssh:

  - Drop most of openssh-6.6p1-keycat.patch (actually, it was just
    commented out). The keycat binary isn't really installed nor
    supported, so we can drop it, except for the code that is used
    by other SELinux patches, which is what I kept from that patch
    (boo#1229072).
  - Add patch submitted to upstream to fix RFC4256 implementation
    so that keyboard-interactive authentication method can send
    instructions and sshd shows them to users even before a prompt
    is requested. This fixes MFA push notifications (boo#1229010).
    * 0001-auth-pam-Immediately-report-instructions-to-clients-and-fix-handling-in-ssh-client.patch

++++ pam:

  - baselibs.conf: add pam-userdb

++++ pam-full-src:

  - baselibs.conf: add pam-userdb

++++ passt:

  - Fix passt-selinux to use selinux macros instead of calling semodule
    by hand, which leads to unwanted policy reload on Micro (bsc#1229132)

++++ python313:

  - Make it build for SLE SP7 (jsc#PED-10075):
  - Add CVE-2023-52425-libexpat-2.6.0-backport-15.6.patch to build in
    SLE-15-SP7.
  - Add fix-test-recursion-limit-15.6.patch, gh#python/cpython#115083
  - Add gh-124040-fix-test-math-i586.patch, gh#python/cpython#124042

++++ python-gobject:

  - Update to version 3.50.0:
    + tests: Fix event test errors when GTK is not installed

++++ selinux-policy:

  - Update to version 20240604+git380.95302f48:
    * Allow systemd_ibft_rule_generator_t to create udev_rules_t dirs (bsc#1230011)
    * Allow systemd_udev_trigger_generator_t list and read sysctls (bsc#1230315)
    * Initial policy for udev-trigger-generator (bsc#1230315)

++++ timezone:

  - Update to 2024b:
    * Improve historical data for Mexico, Mongolia, and Portugal.
    * System V names are now obsolescent.
    * The main data form now uses %z.
    * The code now conforms to RFC 8536 for early timestamps.
    * Support POSIX.1-2024, which removes asctime_r and ctime_r.
    * Assume POSIX.2-1992 or later for shell scripts.
    * SUPPORT_C89 now defaults to 1.

------------------------------------------------------------------
------------------  2024-9-11  -  Sep 11 2024  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update to 10.3.5
    + Update spec file to build in all code streams,
    SLE 12, SLE 15, ALP, and SLFO and have proper dependencies

++++ containerd:

  - Update to containerd v1.7.22. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.22>
  - Bump minimum Go version to 1.22.
  - Rebase patches:
    * 0001-BUILD-SLE12-revert-btrfs-depend-on-kernel-UAPI-inste.patch

++++ curl:

  - Update to version 8.10.0:
    * Security fixes:
  - [bsc#1230093, CVE-2024-8096] curl: OCSP stapling bypass with GnuTLS
    * Changes:
  - curl: make --rate accept "number of units"
  - curl: make --show-headers the same as --include
  - curl: support --dump-header % to direct to stderr
  - curl: support embedding a CA bundle and --dump-ca-embed
  - curl: support repeated use of the verbose option; -vv etc
  - curl: use libuv for parallel transfers with --test-event
  - vtls: stop offering alpn http/1.1 for http2-prior-knowledge
    * Bugfixes:
  - curl: allow 500MB data URL encode strings
  - curl: warn on unsupported SSL options
  - Curl_rand_bytes to control env override
  - curl_sha512_256: fix symbol collisions with nettle library
  - dist: fix reproducible build from release tarball
  - http2: fix GOAWAY message sent to server
  - http2: improve rate limiting of downloads
  - INSTALL.md: MultiSSL and QUIC are mutually exclusive
  - lib: add eos flag to send methods
  - lib: make SSPI global symbols use Curl_ prefix
  - lib: prefer `CURL_SHA256_DIGEST_LENGTH` over the unprefixed name
  - lib: remove the final strncpy() calls
  - lib: remove use of RANDOM_FILE
  - Makefile.mk: fixup enabling libidn2
  - max-filesize.md: mention zero disables the limit
  - mime: avoid inifite loop in client reader
  - ngtcp2: use NGHTTP3 prefix instead of NGTCP2 for errors in h3 callbacks
  - openssl quic: fix memory leak
  - openssl: certinfo errors now fail correctly
  - openssl: fix the data race when sharing an SSL session between threads
  - openssl: improve shutdown handling
  - POP3: fix multi-line responses
  - pop3: use the protocol handler ->write_resp
  - progress: ratelimit/progress tweaks
  - rand: only provide weak random when needed
  - sectransp: fix setting tls version
  - setopt: make CURLOPT_TFTP_BLKSIZE accept bad values
  - sha256: fix symbol collision between nettle (GnuTLS) and OpenSSL
  - sigpipe: init the struct so that first apply ignores
  - smb: convert superflous assign into assert
  - smtp: add tracing feature
  - spnego_gssapi: implement TLS channel bindings for openssl
  - src: delete `curlx_m*printf()` aliases
  - ssh: deduplicate SSH backend includes (and fix libssh cmake unity build)
  - tool_operhlp: fix "potentially uninitialized local variable 'pc' used"
  - tool_paramhlp: bump maximum post data size in memory to 16GB
  - transfer: skip EOS read when download done
  - url: fix connection reuse for HTTP/2 upgrades
  - urlapi: verify URL *decoded* hostname when set
  - urldata: introduce `data->mid`, a unique identifier inside a multi
  - vtls: add SSLSUPP_CIPHER_LIST
  - vtls: fix static function name collisions between TLS backends
  - vtls: init ssl peer only once
  - websocket: introduce blocking sends
  - ws: flags to opcodes should ignore CURLWS_CONT flag
  - x509asn1: raise size limit for x509 certification information
    * Remove curl-sigpipe.patch upstream
    * Rebase curl-secure-getenv.patch

++++ python-kiwi:

  - limit eif_build requires to fedora >= 42
  - Bump version: 10.1.8 → 10.1.9
  - Added sshd to nitro-enclave integration test
  - Fixed container sync options
    Do not exclude/filter any security/xattr capabilities.
  - Update container integration test
    Add getcap to check on filesystem capabilities
  - Add new build type provides for enclave
    Add a provides tag (read by the open buildservice) for the new
    enclave builder. Also add a recommends to eif_builder in
    the systemdeps-core meta package

++++ keepalived:

  - Update service file to use manual mode as disabled is deprecated
  - switch to TAG_OFFSET for a more readable version
  - Update to version 2.3.1+git59.b6681f98:
    * all: update how pidfile handled after reload with new configuration
    * Revert "all: ensure pidfile is created if a reload causes child to start"
    * Revert "all: update how pidfile handled after reload with new configuration"
    * all: update how pidfile handled after reload with new configuration
    * all: ensure pidfile is created if a reload causes child to start

++++ kernel-default:

  - bonding: fix xfrm real_dev null pointer dereference (CVE-2024-44989 bsc#1230193)
  - commit 5caf0d2
  - perf arch events: Fix duplicate RISC-V SBI firmware event name
    (git-fixes).
  - commit 4570763
  - perf tool: fix dereferencing NULL al->maps (git-fixes).
  - commit 5e4751b
  - perf intel-pt: Fix exclude_guest setting (git-fixes).
  - commit e69b63b
  - perf intel-pt: Fix aux_watermark calculation for 64-bit size
    (git-fixes).
  - commit e3b3bca
  - perf report: Fix condition in sort__sym_cmp() (git-fixes).
  - commit c3e65ee
  - perf pmus: Fixes always false when compare duplicates aliases
    (git-fixes).
  - commit 8eeac69
  - tools/perf: Fix the string match for "/tmp/perf-$PID.map"
    files in dso__load (git-fixes).
  - commit 9a7d0fb
  - bonding: fix null pointer deref in bond_ipsec_offload_ok
    (CVE-2024-44990 bsc#1230194).
  - media: aspeed: Fix memory overwrite if timing is 1600x900
    (CVE-2023-52916 bsc#1230269).
  - commit 7cce3c7
  - perf test: Make test_arm_callgraph_fp.sh more robust
    (git-fixes).
  - commit 8d430e5
  - perf stat: Fix the hard-coded metrics calculation on the hybrid
    (git-fixes).
  - commit 0fe6062
  - perf pmu: Assume sysfs events are always the same case
    (git-fixes).
  - Refresh
    patches.suse/perf-pmu-Count-sys-and-cpuid-JSON-events-separately.patch.
  - commit 0eb9b05
  - rtla/osnoise: Prevent NULL dereference in error handling
    (CVE-2024-45002 bsc#1230169).
  - net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
    (CVE-2024-44970 bsc#1230209).
  - commit 33e2b5d
  - lirc: rc_dev_get_from_fd(): fix file leak (git-fixes).
  - commit b3b20de
  - thunderbolt: Fix calculation of consumed USB3 bandwidth on a
    path (git-fixes).
  - commit c3642e6
  - Move fixes into sorted section (bsc#1230119)
  - commit c8d5e3a
  - Refresh patches.suse/ipmi-ssif-Improve-detecting-during-probing.patch
    Add commit id and move away from out-of-tree section
  - commit ceb6869
  - Move upstreamed kaslr patch into sorted section
  - commit 554594b
  - net: dsa: mv88e6xxx: Fix out-of-bound access (CVE-2024-44988 bsc#1230192)
  - commit 5ca3065
  - ipv6: prevent UAF in ip6_send_skb() (CVE-2024-44987 bsc#1230185)
  - commit 075c292
  - perf tools: Add/use PMU reverse lookup from config to name
    (git-fixes).
  - commit 62632fc
  - perf tools: Use pmus to describe type from attribute
    (git-fixes).
  - commit 3dc616b
  - perf: script: add raw|disasm arguments to --insn-trace option
    (git-fixes).
  - Refresh
    patches.suse/perf-script-Show-also-errors-for-insn-trace-option.patch.
  - commit f716aa4
  - perf annotate: Use global annotation_options (git-fixes).
  - Refresh
    patches.suse/perf-annotate-Fix-annotation_calc_lines-to-pass-correct-address-to-get_srcline.patch.
  - commit b70a6bc
  - perf top: Convert to the global annotation_options (git-fixes).
  - commit c12ae1d
  - perf report: Convert to the global annotation_options
    (git-fixes).
  - commit e5bcc3a
  - perf annotate: Introduce global annotation_options (git-fixes).
  - commit b458961
  - perf maps: Move symbol maps functions to maps.c (git-fixes).
  - Refresh
    patches.suse/perf-symbols-Fix-ownership-of-string-in-dso__load_vmlinux.patch.
  - commit 93caf35
  - perf annotate: Split branch stack cycles information out of
    'struct annotation_line' (git-fixes).
  - commit 733d4c0
  - perf machine thread: Remove exited threads by default
    (git-fixes).
  - commit 3c4b077
  - Update references for patches.suse/ipv6-fix-possible-UAF-in-ip6_finish_output2.patch (CVE-2024-44986 bsc#1230230 bsc#1230206)
  - commit 814e7ee
  - bnxt_en: Fix double DMA unmapping for XDP_REDIRECT (CVE-2024-44984 bsc#1230240)
  - commit 43e2e07
  - gtp: pull network headers in gtp_dev_xmit() (CVE-2024-44999 bsc#1230233)
  - commit 057aaf8

++++ kernel-firmware-all:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-amdgpu:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-ath10k:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-ath11k:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-ath12k:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-atheros:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-bluetooth:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-bnx2:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-brcm:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-chelsio:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-dpaa2:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-i915:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-intel:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-iwlwifi:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-liquidio:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-marvell:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-media:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-mediatek:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-mellanox:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-mwifiex:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-network:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-nfp:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-nvidia:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-platform:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-prestera:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-qcom:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-qlogic:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-radeon:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-realtek:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-serial:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-sound:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-ti:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-ueagle:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-firmware-usb-network:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ kernel-rt:

  - bonding: fix xfrm real_dev null pointer dereference (CVE-2024-44989 bsc#1230193)
  - commit 5caf0d2
  - perf arch events: Fix duplicate RISC-V SBI firmware event name
    (git-fixes).
  - commit 4570763
  - perf tool: fix dereferencing NULL al->maps (git-fixes).
  - commit 5e4751b
  - perf intel-pt: Fix exclude_guest setting (git-fixes).
  - commit e69b63b
  - perf intel-pt: Fix aux_watermark calculation for 64-bit size
    (git-fixes).
  - commit e3b3bca
  - perf report: Fix condition in sort__sym_cmp() (git-fixes).
  - commit c3e65ee
  - perf pmus: Fixes always false when compare duplicates aliases
    (git-fixes).
  - commit 8eeac69
  - tools/perf: Fix the string match for "/tmp/perf-$PID.map"
    files in dso__load (git-fixes).
  - commit 9a7d0fb
  - bonding: fix null pointer deref in bond_ipsec_offload_ok
    (CVE-2024-44990 bsc#1230194).
  - media: aspeed: Fix memory overwrite if timing is 1600x900
    (CVE-2023-52916 bsc#1230269).
  - commit 7cce3c7
  - perf test: Make test_arm_callgraph_fp.sh more robust
    (git-fixes).
  - commit 8d430e5
  - perf stat: Fix the hard-coded metrics calculation on the hybrid
    (git-fixes).
  - commit 0fe6062
  - perf pmu: Assume sysfs events are always the same case
    (git-fixes).
  - Refresh
    patches.suse/perf-pmu-Count-sys-and-cpuid-JSON-events-separately.patch.
  - commit 0eb9b05
  - rtla/osnoise: Prevent NULL dereference in error handling
    (CVE-2024-45002 bsc#1230169).
  - net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
    (CVE-2024-44970 bsc#1230209).
  - commit 33e2b5d
  - lirc: rc_dev_get_from_fd(): fix file leak (git-fixes).
  - commit b3b20de
  - thunderbolt: Fix calculation of consumed USB3 bandwidth on a
    path (git-fixes).
  - commit c3642e6
  - Move fixes into sorted section (bsc#1230119)
  - commit c8d5e3a
  - Refresh patches.suse/ipmi-ssif-Improve-detecting-during-probing.patch
    Add commit id and move away from out-of-tree section
  - commit ceb6869
  - Move upstreamed kaslr patch into sorted section
  - commit 554594b
  - net: dsa: mv88e6xxx: Fix out-of-bound access (CVE-2024-44988 bsc#1230192)
  - commit 5ca3065
  - ipv6: prevent UAF in ip6_send_skb() (CVE-2024-44987 bsc#1230185)
  - commit 075c292
  - perf tools: Add/use PMU reverse lookup from config to name
    (git-fixes).
  - commit 62632fc
  - perf tools: Use pmus to describe type from attribute
    (git-fixes).
  - commit 3dc616b
  - perf: script: add raw|disasm arguments to --insn-trace option
    (git-fixes).
  - Refresh
    patches.suse/perf-script-Show-also-errors-for-insn-trace-option.patch.
  - commit f716aa4
  - perf annotate: Use global annotation_options (git-fixes).
  - Refresh
    patches.suse/perf-annotate-Fix-annotation_calc_lines-to-pass-correct-address-to-get_srcline.patch.
  - commit b70a6bc
  - perf top: Convert to the global annotation_options (git-fixes).
  - commit c12ae1d
  - perf report: Convert to the global annotation_options
    (git-fixes).
  - commit e5bcc3a
  - perf annotate: Introduce global annotation_options (git-fixes).
  - commit b458961
  - perf maps: Move symbol maps functions to maps.c (git-fixes).
  - Refresh
    patches.suse/perf-symbols-Fix-ownership-of-string-in-dso__load_vmlinux.patch.
  - commit 93caf35
  - perf annotate: Split branch stack cycles information out of
    'struct annotation_line' (git-fixes).
  - commit 733d4c0
  - perf machine thread: Remove exited threads by default
    (git-fixes).
  - commit 3c4b077
  - Update references for patches.suse/ipv6-fix-possible-UAF-in-ip6_finish_output2.patch (CVE-2024-44986 bsc#1230230 bsc#1230206)
  - commit 814e7ee
  - bnxt_en: Fix double DMA unmapping for XDP_REDIRECT (CVE-2024-44984 bsc#1230240)
  - commit 43e2e07
  - gtp: pull network headers in gtp_dev_xmit() (CVE-2024-44999 bsc#1230233)
  - commit 057aaf8

++++ nvidia-open-driver-G06-signed:

  - CUDA build: removed entries from pci_ids-555.42.06 since this is
    doing more harm than benefit (bsc#1230368)

++++ pam-config:

  - Add PreRequires for pam-extra, several other packages depend on
    that pam_limits is installed and enabled by default
  - Update to version 2.11+git.20240911:
    * Only add pam_limits if available

++++ python-configobj:

  - Refresh CVE-2023-26112.patch according to the last state of
    gh#DiffSK/configobj!236.

++++ qemu:

  - Re-enable vhdx support in qemu-img:
    * [openSUSE][RPM] explicitly enable qemu-img support for vhdx and vpc

++++ ucode-amd:

  - Update to version 20240911 (git commit 59def907425d):
    * rtl_bt: Update RTL8852B BT USB FW to 0x0447_9301 (bsc#1229272)

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20240910 release (bsc#1230400)
  - CVE-2024-23984: Observable discrepancy in RAPL interface for some Intel Processors may allow a privileged user to potentially enable information disclosure via local access. [INTEL-SA-01103](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01103.html)
  - CVE-2024-24968: Improper finite state machines (FSMs) in hardware logic in some Intel Processors may allow an privileged user to potentially enable a denial of service via local access  [INTEL-SA-01097](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01097.html)
  - Update for functional issues. Refer to [Intel® Core™ Ultra Processor](https://cdrdv2.intel.com/v1/dl/getContent/792254) for details.
  - Update for functional issues. Refer to [13th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
  - Update for functional issues. Refer to [12th Generation Intel® Core™ Processor Family](https://cdrdv2.intel.com/v1/dl/getContent/682436) for details.
  - Update for functional issues. Refer to [Intel® Processors and Intel® Core™ i3 N-Series](https://cdrdv2.intel.com/v1/dl/getContent/764616) for details.
    [#]## New Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | TWL            | N0       | 06-be-00/19 |          | 0000001a | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    [#]## Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ADL            | C0       | 06-97-02/07 | 00000035 | 00000036 | Core Gen12
    | ADL            | H0       | 06-97-05/07 | 00000035 | 00000036 | Core Gen12
    | ADL            | L0       | 06-9a-03/80 | 00000433 | 00000434 | Core Gen12
    | ADL            | R0       | 06-9a-04/80 | 00000433 | 00000434 | Core Gen12
    | ADL-N          | N0       | 06-be-00/11 | 00000017 | 0000001a | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    | MTL            | C0       | 06-aa-04/e6 | 0000001e | 0000001f | Core™ Ultra Processor
    | RPL-E/HX/S     | B0       | 06-b7-01/32 | 00000123 | 00000129 | Core Gen13/Gen14
    | RPL-H/P/PX 6+8 | J0       | 06-ba-02/e0 | 00004121 | 00004122 | Core Gen13
    | RPL-HX/S       | C0       | 06-bf-02/07 | 00000035 | 00000036 | Core Gen13/Gen14
    | RPL-S          | H0       | 06-bf-05/07 | 00000035 | 00000036 | Core Gen13/Gen14
    | RPL-U 2+8      | Q0       | 06-ba-03/e0 | 00004121 | 00004122 | Core Gen13

++++ wget:

  - Update wget.keyring: use release-team keyring
  - Don't reference source URL when the linked sources change over time

++++ wpa_supplicant:

  - update to v2.11:
    * Wi-Fi Easy Connect
  - add support for DPP release 3
  - allow Configurator parameters to be provided during config exchange
    * HE/IEEE 802.11ax/Wi-Fi 6
  - various fixes
    * EHT/IEEE 802.11be/Wi-Fi 7
  - add preliminary support
    * SAE: add support for fetching the password from a RADIUS server
    * support OpenSSL 3.0 API changes
    * support background radar detection and CAC with some additional
    drivers
    * support RADIUS ACL/PSK check during 4-way handshake (wpa_psk_radius=3)
    * EAP-SIM/AKA: support IMSI privacy
    * improve 4-way handshake operations
  - use Secure=1 in message 3 during PTK rekeying
    * OCV: do not check Frequency Segment 1 Channel Number for 160 MHz cases
    to avoid interoperability issues
    * support new SAE AKM suites with variable length keys
    * support new AKM for 802.1X/EAP with SHA384
    * extend PASN support for secure ranging
    * FT: Use SHA256 to derive PMKID for AKM 00-0F-AC:3 (FT-EAP)
  - this is based on additional details being added in the IEEE 802.11
    standard
  - the new implementation is not backwards compatible
    * improved ACS to cover additional channel types/bandwidths
    * extended Multiple BSSID support
    * fix beacon protection with FT protocol (incorrect BIGTK was provided)
    * support unsynchronized service discovery (USD)
    * add preliminary support for RADIUS/TLS
    * add support for explicit SSID protection in 4-way handshake
    (a mitigation for CVE-2023-52424; disabled by default for now, can be
    enabled with ssid_protection=1)
    * fix SAE H2E rejected groups validation to avoid downgrade attacks
    * use stricter validation for some RADIUS messages
    * a large number of other fixes, cleanup, and extensions
  - refresh patches:
    wpa_supplicant-dump-certificate-as-PEM-in-debug-mode.diff
    wpa_supplicant-sigusr1-changes-debuglevel.patch
  - drop patches:
    CVE-2023-52160.patch
    dbus-Fix-property-DebugShowKeys-and-DebugTimestamp.patch

------------------------------------------------------------------
------------------  2024-9-10  -  Sep 10 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - integrated changes by Andreas Schwab <schwab@suse.de>
    * enable glamor also for driver build
    * update rust crates
    + syn 2.0.39
    + proc_macro2 1.0.86
    * enable valgrind also on riscv64
    * added libvdpau_gallium package for generic VDPAU state tracker
    * switch from "swrast" to "softpipe,llvmpipe" drivers
    * use "-Dllvm-orcjit=true" for riscv64 build
    * added libgallium to Mesa-dri package
  - re-disable llvm for non-driver build by switching from "swrast"
    to "softpipe" for gallium drivers in that case
  - make previous changelog a bit nicer

++++ Mesa-drivers:

  - integrated changes by Andreas Schwab <schwab@suse.de>
    * enable glamor also for driver build
    * update rust crates
    + syn 2.0.39
    + proc_macro2 1.0.86
    * enable valgrind also on riscv64
    * added libvdpau_gallium package for generic VDPAU state tracker
    * switch from "swrast" to "softpipe,llvmpipe" drivers
    * use "-Dllvm-orcjit=true" for riscv64 build
    * added libgallium to Mesa-dri package
  - re-disable llvm for non-driver build by switching from "swrast"
    to "softpipe" for gallium drivers in that case
  - make previous changelog a bit nicer

++++ python-kiwi:

  - Update enclave documentation
    Fixup repo setup in the build documentation
  - Bump version: 10.1.7 → 10.1.8
  - Fixed enclave documentation
    Path to the build test was not correct
  - Update test-image-nitro-enclave package list
    Fixup package list to match Fedora rawhide
  - Move test-image-nitro-enclave to rawhide
  - Fix ppc64 chrp bootinfo generation

++++ kernel-default:

  - perf record: Lazy load kernel symbols (git-fixes).
  - commit 84efd43
  - Detect memory allocation failure in
    annotated_source__alloc_histograms (bsc#1227962).
  - commit 6424d7a
  - Add alternate commit id for git-fixes.
    Refresh
    patches.suse/perf-evlist-Fix-evlist__new_default-for-1-core-PMU.patch.
  - commit 3b7c481
  - thunderbolt: There are only 5 basic router registers in pre-USB4
    routers (git-fixes).
  - commit 065ac58
  - thunderbolt: Fix rollback in tb_port_lane_bonding_enable()
    for lane 1 (git-fixes).
  - commit 108e81e
  - ipmi:ssif: Improve detecting during probing (bsc#1228771)
  - commit db0a09e
  - thunderbolt: Fix XDomain rx_lanes_show and tx_lanes_show
    (git-fixes).
  - commit b11c099
  - Drop soundwire patch that caused a regression (bsc#1230350)
    Deleted:
    patches.suse/soundwire-stream-fix-programming-slave-ports-for-non.patch
  - commit 5c05eeb
  - btrfs: fix race between direct IO write and fsync when using
    same fd (git-fixes).
  - commit dc59ebc
  - mm/swap: fix race when skipping swapcache (CVE-2024-26759
    bsc#1230340).
  - commit 990c0c6
  - kABI workaround for cros_ec stuff (git-fixes).
  - commit cb01b4e
  - platform/chrome: cros_ec_lpc: MEC access can use an AML mutex
    (stable-fixes).
  - commit d9de020

++++ kernel-firmware-all:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-amdgpu:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-ath10k:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-ath11k:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-ath12k:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-atheros:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-bluetooth:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-bnx2:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-brcm:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-chelsio:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-dpaa2:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-i915:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-intel:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-iwlwifi:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-liquidio:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-marvell:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-media:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-mediatek:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-mellanox:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-mwifiex:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-network:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-nfp:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-nvidia:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-platform:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-prestera:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-qcom:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-qlogic:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-radeon:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-realtek:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-serial:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-sound:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-ti:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-ueagle:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-firmware-usb-network:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

++++ kernel-rt:

  - perf record: Lazy load kernel symbols (git-fixes).
  - commit 84efd43
  - Detect memory allocation failure in
    annotated_source__alloc_histograms (bsc#1227962).
  - commit 6424d7a
  - Add alternate commit id for git-fixes.
    Refresh
    patches.suse/perf-evlist-Fix-evlist__new_default-for-1-core-PMU.patch.
  - commit 3b7c481
  - thunderbolt: There are only 5 basic router registers in pre-USB4
    routers (git-fixes).
  - commit 065ac58
  - thunderbolt: Fix rollback in tb_port_lane_bonding_enable()
    for lane 1 (git-fixes).
  - commit 108e81e
  - ipmi:ssif: Improve detecting during probing (bsc#1228771)
  - commit db0a09e
  - thunderbolt: Fix XDomain rx_lanes_show and tx_lanes_show
    (git-fixes).
  - commit b11c099
  - Drop soundwire patch that caused a regression (bsc#1230350)
    Deleted:
    patches.suse/soundwire-stream-fix-programming-slave-ports-for-non.patch
  - commit 5c05eeb
  - btrfs: fix race between direct IO write and fsync when using
    same fd (git-fixes).
  - commit dc59ebc
  - mm/swap: fix race when skipping swapcache (CVE-2024-26759
    bsc#1230340).
  - commit 990c0c6
  - kABI workaround for cros_ec stuff (git-fixes).
  - commit cb01b4e
  - platform/chrome: cros_ec_lpc: MEC access can use an AML mutex
    (stable-fixes).
  - commit d9de020

++++ gdbm:

  - version update to 1.24
    * New gdbm_load option: --update
    * Fix semantics of gdbm_load -r
    * Use getline in gdbmtool shell.
    * New function: gdbm_load_from_file_ext
    * Bugfixes
    * * Fix binary dump format for key and/or data of zero size.
    (see https://puszcza.gnu.org.ua/bugs/?565)
    * * Fix location tracking and recover command in gdbtool.
    (see https://puszcza.gnu.org.ua/bugs/?566)
    * * Fix possible buffer underflow in gdbmload.
    * * Ensure any padding bytes in avail_elem structure are filled with 0.
    (fixes https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1031276)
    * * Improve the documentation.
  - modified patches
    % gdbm-no-build-date.patch (refreshed)
  - deleted patches
  - bsc1209583.patch (upstreamed)

++++ tdb:

  - Update to 1.4.12
    * Regression fix for ABI problem
    TDB_1_4_11 vs. TDB_1.4.11
  - Update to 1.4.11
    * Add tdbdump -x option to output all data as hex values
    * Add missing overflow check for num_values in pytdb.c
    * Remove Py2 related tests
    * Update times in tdb_transaction_commit per fd, not per name
    * Fix compilation with TDB_TRACE=1
    * Allow tracing of internal tdb

++++ netavark:

  - Update to version 1.12.2:
    * Release v1.12.2
    * Release notes for 1.12.2
    * fix new rust 1.80 lint issues
    * silence new rust 1.80 warnings
    * aardvark: on start failure delete entries again
    * iptables: make dns rules cover tcp as well
    * nftables: make dns rules cover tcp as well

++++ pam:

  - pam_limits-systemd.patch: update to final PR

++++ pam-full-src:

  - pam_limits-systemd.patch: update to final PR

++++ ucode-amd:

  - Update to version 20240910 (git commit 2a7b69a3fa30):
    * realtek: rt1320: Add patch firmware of MCU
    * i915: Update MTL DMC v2.23
    * cirrus: cs35l56: Add firmware for Cirrus CS35L54 for some HP laptops

------------------------------------------------------------------
------------------  2024-9-9  -  Sep 9 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fixed documentation header
    Fixed double H1 headers from the boxbuild tweaks chapter.
  - Bump version: 10.1.6 → 10.1.7
  - Move EXEC log message to the right place
    The log information of the command execution was not printed
    directly before the actual command invocation. There are other
    actions after the log information (e.g Path.which) which itself
    produce log information prior the real subprocess execution.
    This is very misleading when reading the log file and fixed
    in this commit.
  - Add support for architectures in deb source file
    When apt resolves packages on a multiarch repo it can happen
    that dependencies for packages from other architectures are
    pulled into the solver process but are not provided by any
    repository. To overcome this behavior the repository can
    be setup to serve packages only for a specified architecture
    or list of architectures. This is related to
    OSInside/kiwi-descriptions#102

++++ gsettings-desktop-schemas:

  - Update to version 47.rc:
    + Updated translations.

++++ kernel-default:

  - Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
    (git-fixes).
  - uio_hv_generic: Fix kernel NULL pointer dereference in
    hv_uio_rescind (git-fixes).
  - net: mana: Fix error handling in mana_create_txq/rxq's NAPI
    cleanup (git-fixes).
  - commit 27572d4
  - x86/pat: Fix W^X violation false-positives when running as
    Xen PV guest (bsc#1221527).
  - commit 9acf0ca
  - x86/pat: Restructure _lookup_address_cpa() (bsc#1221527).
  - commit 56f7c9c
  - powerpc/qspinlock: Fix deadlock in MCS queue (bac#1230295
    ltc#206656).
  - commit c4a2ba1
  - Refresh
    patches.kabi/kabi-dm_blk_ioctl-implement-path-failover-for-SG_IO.patch.
  - Refresh
    patches.suse/dm_blk_ioctl-implement-path-failover-for-SG_IO.patch.
  - commit 73c5a36
  - x86/mm: Use lookup_address_in_pgd_attr() in show_fault_oops()
    (bsc#1221527).
  - commit 84d383c
  - x86/pat: Introduce lookup_address_in_pgd_attr() (bsc#1221527).
  - commit 09ca5ca
  - drm/amd/display: Replace dm_execute_dmub_cmd with
    dc_wake_and_execute_dmub_cmd (git-fixes).
  - commit 6d87705
  - wifi: cfg80211: make hash table duplicates more survivable
    (stable-fixes).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 62f6e12
  - VMCI: Fix use-after-free when removing resource in
    vmci_resource_remove() (git-fixes).
  - misc: fastrpc: Fix double free of 'buf' in error path
    (git-fixes).
  - iio: fix scale application in
    iio_convert_raw_to_processed_unlocked (git-fixes).
  - iio: adc: ad7124: fix config comparison (git-fixes).
  - iio: adc: ad7124: fix chip ID mismatch (git-fixes).
  - iio: buffer-dmaengine: fix releasing dma channel on error
    (git-fixes).
  - iio: adc: ad7606: remove frstdata check for serial mode
    (git-fixes).
  - staging: iio: frequency: ad9834: Validate frequency parameter
    value (git-fixes).
  - usb: dwc3: Avoid waking up gadget during startxfer (git-fixes).
  - net: usb: qmi_wwan: add MeiG Smart SRM825L (stable-fixes).
  - drm/gpuvm: fix missing dependency to DRM_EXEC (git-fixes).
  - drm: panel-orientation-quirks: Add quirk for OrangePi Neo
    (stable-fixes).
  - drm/fb-helper: Don't schedule_work() to flush frame buffer
    during panic() (stable-fixes).
  - PCI: al: Check IORESOURCE_BUS existence during probe
    (stable-fixes).
  - usb: typec: ucsi: Fix null pointer dereference in trace
    (stable-fixes).
  - usbip: Don't submit special requests twice (stable-fixes).
  - media: uvcvideo: Enforce alignment of frame and interval
    (stable-fixes).
  - wifi: ath12k: initialize 'ret' in
    ath12k_dp_rxdma_ring_sel_config_wcn7850() (stable-fixes).
  - wifi: ath11k: initialize 'ret' in
    ath11k_qmi_load_file_target_mem() (stable-fixes).
  - wifi: ath12k: initialize 'ret' in
    ath12k_qmi_load_file_target_mem() (stable-fixes).
  - wifi: rtw89: ser: avoid multiple deinit on same CAM
    (stable-fixes).
  - wifi: mac80211: check ieee80211_bss_info_change_notify()
    against MLD (stable-fixes).
  - wifi: cfg80211: restrict operation during radar detection
    (stable-fixes).
  - pwm: xilinx: Fix u32 overflow issue in 32-bit width PWM mode
    (stable-fixes).
  - hwmon: (k10temp) Check return value of amd_smn_read()
    (stable-fixes).
  - regmap: spi: Fix potential off-by-one when calculating reserved
    size (stable-fixes).
  - commit 73bbd93
  - clocksource/drivers/imx-tpm: Fix next event not taking effect
    sometime (git-fixes).
  - clocksource/drivers/imx-tpm: Fix return -ETIME when delta
    exceeds INT_MAX (git-fixes).
  - dma-debug: avoid deadlock between dma debug vs printk and
    netconsole (stable-fixes).
  - drm/amdgpu: fix contiguous handling for IB parsing v2
    (git-fixes).
  - dmaengine: altera-msgdma: properly free descriptor in
    msgdma_free_descriptor (stable-fixes).
  - dmaengine: altera-msgdma: use irq variant of spin_lock/unlock
    while invoking callbacks (stable-fixes).
  - driver: iio: add missing checks on iio_info's callback access
    (stable-fixes).
  - drm/amd/display: Skip wbscl_set_scaler_filter if filter is null
    (stable-fixes).
  - drm/amd/display: Check BIOS images before it is used
    (stable-fixes).
  - drm/amd/display: Avoid overflow from uint32_t to uint8_t
    (stable-fixes).
  - drm/amd/display: use preferred link settings for dp signal only
    (stable-fixes).
  - drm/amd/display: Remove register from DCN35 DMCUB diagnostic
    collection (stable-fixes).
  - drm/amd/display: Correct the defined value for
    AMDGPU_DMUB_NOTIFICATION_MAX (stable-fixes).
  - drm/amd/display: added NULL check at start of dc_validate_stream
    (stable-fixes).
  - drm/amd/display: Wake DMCUB before sending a command for replay
    feature (stable-fixes).
  - drm/amd/display: Don't use fsleep for PSR exit waits on dmub
    replay (stable-fixes).
  - drm/amdgpu: fix overflowed constant warning in
    mmhub_set_clockgating() (stable-fixes).
  - drm/amdgpu: add lock in kfd_process_dequeue_from_device
    (stable-fixes).
  - drm/amdgpu: add lock in amdgpu_gart_invalidate_tlb
    (stable-fixes).
  - drm/amdgpu: add skip_hw_access checks for sriov (stable-fixes).
  - drm/bridge: tc358767: Check if fully initialized before
    signalling HPD event via IRQ (stable-fixes).
  - drm/meson: plane: Add error handling (stable-fixes).
  - drm/drm-bridge: Drop conditionals around of_node pointers
    (stable-fixes).
  - drm/amd/display: Add null checks for 'stream' and 'plane'
    before dereferencing (stable-fixes).
  - drm/amdgu: fix Unintentional integer overflow for mall size
    (stable-fixes).
  - drm/amdgpu: update type of buf size to u32 for eeprom functions
    (stable-fixes).
  - drm/amd/display: Fix pipe addition logic in
    calc_blocks_to_ungate DCN35 (stable-fixes).
  - drm/kfd: Correct pinned buffer handling at kfd restore and
    validate process (stable-fixes).
  - drm/amd/pm: check negtive return for table entries
    (stable-fixes).
  - drm/amdgpu: the warning dereferencing obj for nbio_v7_4
    (stable-fixes).
  - drm/amd/pm: check specific index for smu13 (stable-fixes).
  - drm/amd/pm: check specific index for aldebaran (stable-fixes).
  - drm/amdgpu: fix the waring dereferencing hive (stable-fixes).
  - drm/amdgpu: fix dereference after null check (stable-fixes).
  - drm/amdgpu: Fix the warning division or modulo by zero
    (stable-fixes).
  - drm/amdgpu/pm: Check input value for CUSTOM profile mode
    setting on legacy SOCs (stable-fixes).
  - drm/amdkfd: Reconcile the definition and use of oem_id in
    struct kfd_topology_device (stable-fixes).
  - drm/amdgpu: fix mc_data out-of-bounds read warning
    (stable-fixes).
  - drm/amdgpu: fix ucode out-of-bounds read warning (stable-fixes).
  - drm/amdgpu: Fix uninitialized variable warning in
    amdgpu_info_ioctl (stable-fixes).
  - drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number
    (stable-fixes).
  - drm/amdkfd: Check debug trap enable before write dbg_ev_file
    (stable-fixes).
  - drm/amdgpu: Fix out-of-bounds write warning (stable-fixes).
  - drm/amdgpu: Fix the uninitialized variable warning
    (stable-fixes).
  - drm/amdgpu/pm: Fix uninitialized variable agc_btc_response
    (stable-fixes).
  - drm/amdgpu/pm: Fix uninitialized variable warning for smu10
    (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warnings for vangogh_ppt
    (stable-fixes).
  - drm/amd/amdgpu: Check tbo resource pointer (stable-fixes).
  - drm/amd/display: Fix index may exceed array range within
    fpu_update_bw_bounding_box (stable-fixes).
  - drm/amd/display: Skip inactive planes within
    ModeSupportAndSystemConfiguration (stable-fixes).
  - drm/amd/display: Ensure index calculation will not overflow
    (stable-fixes).
  - drm/amd/display: Fix Coverity INTEGER_OVERFLOW within
    decide_fallback_link_setting_max_bw_policy (stable-fixes).
  - drm/amd/display: Spinlock before reading event (stable-fixes).
  - drm/amd/display: Fix Coverity INTEGER_OVERFLOW within
    dal_gpio_service_create (stable-fixes).
  - drm/amd/display: Fix Coverity INTERGER_OVERFLOW within
    construct_integrated_info (stable-fixes).
  - drm/amd/display: Check msg_id before processing transcation
    (stable-fixes).
  - drm/amd/display: Check num_valid_sets before accessing
    reader_wm_sets[] (stable-fixes).
  - drm/amd/display: Add array index check for hdcp ddc access
    (stable-fixes).
  - drm/amd/display: Check index for aux_rd_interval before using
    (stable-fixes).
  - drm/amd/display: Stop amdgpu_dm initialize when stream nums
    greater than 6 (stable-fixes).
  - drm/amd/display: Check gpio_id before used as array index
    (stable-fixes).
  - drm/amd/display: Ensure array index tg_inst won't be -1
    (stable-fixes).
  - drm/amdgpu: avoid reading vf2pf info size from FB
    (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warnings for vega10_hwmgr
    (stable-fixes).
  - drm/amdgpu: fix uninitialized scalar variable warning
    (stable-fixes).
  - drm/amd/pm: fix the Out-of-bounds read warning (stable-fixes).
  - drm/amd/pm: Fix negative array index read (stable-fixes).
  - drm/amd/pm: fix warning using uninitialized value of
    max_vid_step (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warning for smu8_hwmgr
    (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warning (stable-fixes).
  - drm/amdgpu/pm: Check the return value of smum_send_msg_to_smc
    (stable-fixes).
  - drm/amdgpu: fix overflowed array index read warning
    (stable-fixes).
  - drm/amdgpu: Handle sg size limit for contiguous allocation
    (stable-fixes).
  - drm/amd/display: Assign linear_pitch_alignment even for VM
    (stable-fixes).
  - drm/amd/display: Handle the case which quad_part is equal 0
    (stable-fixes).
  - drm/amdgpu: Fix uninitialized variable warning in
    amdgpu_afmt_acr (stable-fixes).
  - cpufreq: scmi: Avoid overflow of target_freq in fast switch
    (stable-fixes).
  - commit e23c4dc
  - RDMA/efa: Properly handle unexpected AQ completions (git-fixes)
  - commit 8c8b9e5

++++ kernel-rt:

  - Drivers: hv: vmbus: Fix rescind handling in uio_hv_generic
    (git-fixes).
  - uio_hv_generic: Fix kernel NULL pointer dereference in
    hv_uio_rescind (git-fixes).
  - net: mana: Fix error handling in mana_create_txq/rxq's NAPI
    cleanup (git-fixes).
  - commit 27572d4
  - x86/pat: Fix W^X violation false-positives when running as
    Xen PV guest (bsc#1221527).
  - commit 9acf0ca
  - x86/pat: Restructure _lookup_address_cpa() (bsc#1221527).
  - commit 56f7c9c
  - powerpc/qspinlock: Fix deadlock in MCS queue (bac#1230295
    ltc#206656).
  - commit c4a2ba1
  - Refresh
    patches.kabi/kabi-dm_blk_ioctl-implement-path-failover-for-SG_IO.patch.
  - Refresh
    patches.suse/dm_blk_ioctl-implement-path-failover-for-SG_IO.patch.
  - commit 73c5a36
  - x86/mm: Use lookup_address_in_pgd_attr() in show_fault_oops()
    (bsc#1221527).
  - commit 84d383c
  - x86/pat: Introduce lookup_address_in_pgd_attr() (bsc#1221527).
  - commit 09ca5ca
  - drm/amd/display: Replace dm_execute_dmub_cmd with
    dc_wake_and_execute_dmub_cmd (git-fixes).
  - commit 6d87705
  - wifi: cfg80211: make hash table duplicates more survivable
    (stable-fixes).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 62f6e12
  - VMCI: Fix use-after-free when removing resource in
    vmci_resource_remove() (git-fixes).
  - misc: fastrpc: Fix double free of 'buf' in error path
    (git-fixes).
  - iio: fix scale application in
    iio_convert_raw_to_processed_unlocked (git-fixes).
  - iio: adc: ad7124: fix config comparison (git-fixes).
  - iio: adc: ad7124: fix chip ID mismatch (git-fixes).
  - iio: buffer-dmaengine: fix releasing dma channel on error
    (git-fixes).
  - iio: adc: ad7606: remove frstdata check for serial mode
    (git-fixes).
  - staging: iio: frequency: ad9834: Validate frequency parameter
    value (git-fixes).
  - usb: dwc3: Avoid waking up gadget during startxfer (git-fixes).
  - net: usb: qmi_wwan: add MeiG Smart SRM825L (stable-fixes).
  - drm/gpuvm: fix missing dependency to DRM_EXEC (git-fixes).
  - drm: panel-orientation-quirks: Add quirk for OrangePi Neo
    (stable-fixes).
  - drm/fb-helper: Don't schedule_work() to flush frame buffer
    during panic() (stable-fixes).
  - PCI: al: Check IORESOURCE_BUS existence during probe
    (stable-fixes).
  - usb: typec: ucsi: Fix null pointer dereference in trace
    (stable-fixes).
  - usbip: Don't submit special requests twice (stable-fixes).
  - media: uvcvideo: Enforce alignment of frame and interval
    (stable-fixes).
  - wifi: ath12k: initialize 'ret' in
    ath12k_dp_rxdma_ring_sel_config_wcn7850() (stable-fixes).
  - wifi: ath11k: initialize 'ret' in
    ath11k_qmi_load_file_target_mem() (stable-fixes).
  - wifi: ath12k: initialize 'ret' in
    ath12k_qmi_load_file_target_mem() (stable-fixes).
  - wifi: rtw89: ser: avoid multiple deinit on same CAM
    (stable-fixes).
  - wifi: mac80211: check ieee80211_bss_info_change_notify()
    against MLD (stable-fixes).
  - wifi: cfg80211: restrict operation during radar detection
    (stable-fixes).
  - pwm: xilinx: Fix u32 overflow issue in 32-bit width PWM mode
    (stable-fixes).
  - hwmon: (k10temp) Check return value of amd_smn_read()
    (stable-fixes).
  - regmap: spi: Fix potential off-by-one when calculating reserved
    size (stable-fixes).
  - commit 73bbd93
  - clocksource/drivers/imx-tpm: Fix next event not taking effect
    sometime (git-fixes).
  - clocksource/drivers/imx-tpm: Fix return -ETIME when delta
    exceeds INT_MAX (git-fixes).
  - dma-debug: avoid deadlock between dma debug vs printk and
    netconsole (stable-fixes).
  - drm/amdgpu: fix contiguous handling for IB parsing v2
    (git-fixes).
  - dmaengine: altera-msgdma: properly free descriptor in
    msgdma_free_descriptor (stable-fixes).
  - dmaengine: altera-msgdma: use irq variant of spin_lock/unlock
    while invoking callbacks (stable-fixes).
  - driver: iio: add missing checks on iio_info's callback access
    (stable-fixes).
  - drm/amd/display: Skip wbscl_set_scaler_filter if filter is null
    (stable-fixes).
  - drm/amd/display: Check BIOS images before it is used
    (stable-fixes).
  - drm/amd/display: Avoid overflow from uint32_t to uint8_t
    (stable-fixes).
  - drm/amd/display: use preferred link settings for dp signal only
    (stable-fixes).
  - drm/amd/display: Remove register from DCN35 DMCUB diagnostic
    collection (stable-fixes).
  - drm/amd/display: Correct the defined value for
    AMDGPU_DMUB_NOTIFICATION_MAX (stable-fixes).
  - drm/amd/display: added NULL check at start of dc_validate_stream
    (stable-fixes).
  - drm/amd/display: Wake DMCUB before sending a command for replay
    feature (stable-fixes).
  - drm/amd/display: Don't use fsleep for PSR exit waits on dmub
    replay (stable-fixes).
  - drm/amdgpu: fix overflowed constant warning in
    mmhub_set_clockgating() (stable-fixes).
  - drm/amdgpu: add lock in kfd_process_dequeue_from_device
    (stable-fixes).
  - drm/amdgpu: add lock in amdgpu_gart_invalidate_tlb
    (stable-fixes).
  - drm/amdgpu: add skip_hw_access checks for sriov (stable-fixes).
  - drm/bridge: tc358767: Check if fully initialized before
    signalling HPD event via IRQ (stable-fixes).
  - drm/meson: plane: Add error handling (stable-fixes).
  - drm/drm-bridge: Drop conditionals around of_node pointers
    (stable-fixes).
  - drm/amd/display: Add null checks for 'stream' and 'plane'
    before dereferencing (stable-fixes).
  - drm/amdgu: fix Unintentional integer overflow for mall size
    (stable-fixes).
  - drm/amdgpu: update type of buf size to u32 for eeprom functions
    (stable-fixes).
  - drm/amd/display: Fix pipe addition logic in
    calc_blocks_to_ungate DCN35 (stable-fixes).
  - drm/kfd: Correct pinned buffer handling at kfd restore and
    validate process (stable-fixes).
  - drm/amd/pm: check negtive return for table entries
    (stable-fixes).
  - drm/amdgpu: the warning dereferencing obj for nbio_v7_4
    (stable-fixes).
  - drm/amd/pm: check specific index for smu13 (stable-fixes).
  - drm/amd/pm: check specific index for aldebaran (stable-fixes).
  - drm/amdgpu: fix the waring dereferencing hive (stable-fixes).
  - drm/amdgpu: fix dereference after null check (stable-fixes).
  - drm/amdgpu: Fix the warning division or modulo by zero
    (stable-fixes).
  - drm/amdgpu/pm: Check input value for CUSTOM profile mode
    setting on legacy SOCs (stable-fixes).
  - drm/amdkfd: Reconcile the definition and use of oem_id in
    struct kfd_topology_device (stable-fixes).
  - drm/amdgpu: fix mc_data out-of-bounds read warning
    (stable-fixes).
  - drm/amdgpu: fix ucode out-of-bounds read warning (stable-fixes).
  - drm/amdgpu: Fix uninitialized variable warning in
    amdgpu_info_ioctl (stable-fixes).
  - drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number
    (stable-fixes).
  - drm/amdkfd: Check debug trap enable before write dbg_ev_file
    (stable-fixes).
  - drm/amdgpu: Fix out-of-bounds write warning (stable-fixes).
  - drm/amdgpu: Fix the uninitialized variable warning
    (stable-fixes).
  - drm/amdgpu/pm: Fix uninitialized variable agc_btc_response
    (stable-fixes).
  - drm/amdgpu/pm: Fix uninitialized variable warning for smu10
    (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warnings for vangogh_ppt
    (stable-fixes).
  - drm/amd/amdgpu: Check tbo resource pointer (stable-fixes).
  - drm/amd/display: Fix index may exceed array range within
    fpu_update_bw_bounding_box (stable-fixes).
  - drm/amd/display: Skip inactive planes within
    ModeSupportAndSystemConfiguration (stable-fixes).
  - drm/amd/display: Ensure index calculation will not overflow
    (stable-fixes).
  - drm/amd/display: Fix Coverity INTEGER_OVERFLOW within
    decide_fallback_link_setting_max_bw_policy (stable-fixes).
  - drm/amd/display: Spinlock before reading event (stable-fixes).
  - drm/amd/display: Fix Coverity INTEGER_OVERFLOW within
    dal_gpio_service_create (stable-fixes).
  - drm/amd/display: Fix Coverity INTERGER_OVERFLOW within
    construct_integrated_info (stable-fixes).
  - drm/amd/display: Check msg_id before processing transcation
    (stable-fixes).
  - drm/amd/display: Check num_valid_sets before accessing
    reader_wm_sets[] (stable-fixes).
  - drm/amd/display: Add array index check for hdcp ddc access
    (stable-fixes).
  - drm/amd/display: Check index for aux_rd_interval before using
    (stable-fixes).
  - drm/amd/display: Stop amdgpu_dm initialize when stream nums
    greater than 6 (stable-fixes).
  - drm/amd/display: Check gpio_id before used as array index
    (stable-fixes).
  - drm/amd/display: Ensure array index tg_inst won't be -1
    (stable-fixes).
  - drm/amdgpu: avoid reading vf2pf info size from FB
    (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warnings for vega10_hwmgr
    (stable-fixes).
  - drm/amdgpu: fix uninitialized scalar variable warning
    (stable-fixes).
  - drm/amd/pm: fix the Out-of-bounds read warning (stable-fixes).
  - drm/amd/pm: Fix negative array index read (stable-fixes).
  - drm/amd/pm: fix warning using uninitialized value of
    max_vid_step (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warning for smu8_hwmgr
    (stable-fixes).
  - drm/amd/pm: fix uninitialized variable warning (stable-fixes).
  - drm/amdgpu/pm: Check the return value of smum_send_msg_to_smc
    (stable-fixes).
  - drm/amdgpu: fix overflowed array index read warning
    (stable-fixes).
  - drm/amdgpu: Handle sg size limit for contiguous allocation
    (stable-fixes).
  - drm/amd/display: Assign linear_pitch_alignment even for VM
    (stable-fixes).
  - drm/amd/display: Handle the case which quad_part is equal 0
    (stable-fixes).
  - drm/amdgpu: Fix uninitialized variable warning in
    amdgpu_afmt_acr (stable-fixes).
  - cpufreq: scmi: Avoid overflow of target_freq in fast switch
    (stable-fixes).
  - commit e23c4dc
  - RDMA/efa: Properly handle unexpected AQ completions (git-fixes)
  - commit 8c8b9e5

++++ nvidia-open-driver-G06-signed:

  - For CUDA (preamble file):
    * added: Provides: nvidia-open-driver-G06-signed-cuda-kmp-$flavor = %version
    which is needed for 'zypper install <package> = <version>'
    * added: Provides/Conflicts: nvidia-open-driver-G06-signed-kmp-$flavor = %version
    useful for containers

++++ passt:

  - Update to version 20240906.6b38f07:
    * apparmor: Allow read access to /proc/sys/net/ipv4/ip_local_port_range
    * selinux: Allow read access to /proc/sys/net/ipv4/ip_local_port_range
    * tap: Don't risk truncating frames on full buffer in tap_pasta_input()
    * tap: Restructure in tap_pasta_input()
    * tap: Improve handling of EINTR in tap_passt_input()
    * tap: Split out handling of EPOLLIN events
    * util: Fix order of operands and carry of one second in timespec_diff_us()
    * cppcheck: Work around some cppcheck 2.15.0 redundantInitialization warnings
    * tcp: Use EPOLLET for any state of not established connections
    * udp: Handle more error conditions in udp_sock_errs()
    * udp: Treat errors getting errors as unrecoverable
    * udp: Split socket error handling out from udp_sock_recv()
    * flow: Helpers to log details of a flow
    * udp: Allow UDP flows to be prematurely closed
    * flow: Fix incorrect hash probe in flowside_lookup()
    * log: Don't prefix log file messages with time and severity if they're continuations
    * Makefile: Enable _FORTIFY_SOURCE iff needed
    * fwd, conf: Probe host's ephemeral ports
    * conf, fwd: Don't attempt to forward port 0
    * conf, fwd: Make ephemeral port logic more flexible
    * seccomp.sh: Try to account for terminal width while formatting list of system calls
    * udp: Use dual stack sockets for port forwarding when possible
    * udp: Remove unnnecessary local from udp_sock_init()
    * udp: Merge udp[46]_mh_recv arrays
    * test: Look for possible sshd-session paths (if it's there at all) in mbuto's profile

++++ python-oauthlib:

  - Cherry-pick upstream patch to make UtilsTests.test_filter_params Python 3.13+ compatible
    * Make-UtilsTests.test_filter_params-Python-3.13-compatible.patch

++++ ovmf:

  - Update to edk2-stable202405
  - Features (https://github.com/tianocore/edk2/releases):
    MAT Logic Incorrectly Reports Runtime Images
    SecurityPkg:Add EFI Device Authentication Signature Database and SPDM
    CryptoPkg:add additional RSAES-OAEP crypto functions
    OvmfPkg:Add 5-level paging support
    OvmfPkg:SEV-SNP Support for running under an SVSM
    OvmfPkg:RBP register shall be cleared in TDVMCALL
    OvmfPkg:Harden #VC instruction emulation (CVE-2024-25742)
    Add SPI bus driver stack
    NetworkPkg: Predictable TCP ISNs
    NetworkPkg: Use of a Weak PseudoRandom Number Generator
    UefiCpuPkg: Add new SmmRelocationLib library
  - Patches (git log --oneline --date-order edk2-stable202402..edk2-stable202405):
    3e722403cd ArmVirtPkg/ArmVirtQemu: Add RngDxe driver
    66c69871e7 ArmVirtPkg: Reverse inclusion order of MdeLibs.inc and ArmVirt.dsc.inc
    c98f7f7550 ArmVirtPkg: Use dynamic PCD to set the SMCCC conduit
    865229bcc8 ArmVirtPkg/ArmVirtQemu: Permit the use of dynamic PCDs in PEI
    4ddf2448ed MdePkg/BaseRngLib AARCH64: Remove overzealous ASSERT()
    9440986d4e ArmVirtPkg: Move PcdMonitorConduitHvc
    32460bb5b1 ArmPkg: Allow SMC/HVC monitor conduit to be specified at runtime
    207b6d68a0 NetworkPkg: Update the PxeBcDhcp6GoogleTest due to underlying changes
    dff3d3811f MdePkg: Add MockHash2 Protocol for testing
    4afb939531 MdePkg: Adds Protocol for MockRng
    72a9ef1c8a MdePkg: Add MockUefiBootServicesTableLib
    1904a64bcc NetworkPkg TcpDxe: SECURITY PATCH CVE-2023-45236
    4c4ceb2ceb NetworkPkg: SECURITY PATCH CVE-2023-45237
    a85336531c SecurityPkg RngDxe: Remove incorrect limitation on GetRng
    e10d83234c ArmVirtPkg: Add Hash2DxeCrypto to ArmVirtPkg
    677204f941 ArmVirtPkg PlatformCI: Support virtio-rng-pci
    cb9d711891 OvmfPkg: Add Hash2DxeCrypto to OvmfPkg
    4f58e0cf99 OvmfPkg PlatformCI: Support virtio-rng-pci
    024a291b3e EmulatorPkg: Add Hash2DxeCrypto to EmulatorPkg
    319bb7223a EmulatorPkg: Add RngDxe to EmulatorPkg
    7142e64841 CodeQL: Update from 2.16.1 to 2.17.3
    284dbac43d MdeModulePkg: Potential UINT32 overflow in S3 ResumeCount
    558a25366d MdePkg/BaseLib: Fix AARCH64 compilation error
    4b6ee06a09 MdePkg: Add MmUnblockMemoryLib to MdeLibs.dsc
    3c0b84420f DynamicTablesPkg: Adds integer to the AML package node
    25996a3441 MdePkg: Updated SpcrTable structure for Revision_4
    b82c9631da OvmfPkg: Use newly defined Unaccepted Memory Type
    f3b0ee0cee MdePkg: Update Delayed Dispatch PPI as per PI 1.8 Spec
    09340de246 MdeModulePkg: Use newly defined Unaccepted Memory Type
    6fd2d58d5d MdePkg: Define Unaccepted Memory Type
    b538d6a1b1 MdePkg: Add new Resource Attributes defined in PI 1.8 Spec
    b04e11b4c4 MdePkg: Add definition for NVMe Over Fabric Device Path
    5cbfb93abe UefiCpuPkg/Library: Support to get processor extended info
    952b5cf94c MdeModulePkg: Adding SpiHc Drivers
    82b0358e3f MdeModulePkg: SpiHc: SpiHc Drivers
    5590cefe93 MdeModulePkg:BaseSpiHcPlatformLib: Adding NULL lib instance
    916f495e77 MdeModulePkg: Adding SpiBus Drivers
    efc7ccf906 MdeModulePkg/Bus/Spi/SpiBus: Adding SpiBus Drivers
    fa7fdb89a3 MdePkg/SpiConfiguration: Correct the definition spelling
    2727231b0a UefiCpuPkg/PiSmmCpuDxeSmm: Remove SmBases relocation logic
    23ed7f209c UefiPayloadPkg/UefiPayloadPkg.dsc: Include SmmRelocationLib
    6b3a89a9fd OvmfPkg/PlatformPei: Relocate SmBases in PEI phase
    4a6400b084 OvmfPkg/SmmCpuFeaturesLib: Check Smbase Relocation is done or not
    04c36d5a1b OvmfPkg: Refine SmmAccess implementation
    6a468a8b55 OvmfPkg/PlatformInitLib: Create gEfiSmmSmramMemoryGuid
    3dfd64305b OvmfPkg/SmmRelocationLib: Add library instance for OVMF
    47f212295f UefiCpuPkg/SmmRelocationLib: Add library instance for AMD
    c56ea95b28 UefiCpuPkg/SmmRelocationLib: Remove unnecessary CpuIndex
    9783dc01cc UefiCpuPkg/SmmRelocationLib: Remove unnecessary global variable
    7421094136 UefiCpuPkg/SmmRelocationLib: Avoid unnecessary memory allocation
    42e8fa84f7 UefiCpuPkg/SmmRelocationLib: Rename global variables
    51fcd2023b UefiCpuPkg/SmmRelocationLib: Add SmmRelocationLib library instance
    af9b851732 UefiCpuPkg: Add SmmRelocationLib class
    987bea6525 UefiCpuPkg/PiSmmCpuDxeSmm: Handle the NULL gMpInformation2HobGuid
    1c0d4ae2c0 MdeModulePkg/XhciDxe: Add PCD for the delay of HCRST
    c12bbc1490 MdeModulePkg/XhciDxe: Reset endpoint while USB Transaction error
    17f333f2a4 OvmfPkg: Add sp800155Event3 support
    7097c97bde SecurityPkg: Recognize sp800155Event3 event
    370c55b2ba MdePkg: Add TcgSp800155Event3 type info
    24fa360857 RedfishPkg: Rename x-uefi-redfish to x-UEFI-redfish
    248aa153f6 IntelFsp2Pkg/PatchFv.py: FIX for GCC 32BIT build error
    fecf55a66a OvmfPkg/CcExitLib: Drop special handling for Encrypted MMIO to APIC
    f0ed194236 OvmfPkg: Don't make APIC MMIO accesses with encryption bit set
    fd290ab862 OvmfPkg/ResetVector: Clear SEV encryption bit for non-leaf PTEs
    5f783827bb Maintainers.txt: Update my email address
    5d4c5253e8 Maintainers.txt: Update StandaloneMmPkg and UefiCpuPkg Reviewer
    ec6e59aefe OvmfPkg: Remove QemuFwCfgLibMmio.inf
    1699845c5f OvmfPkg/RiscVVirt: Enable QemuFwCfgMmioDxeLib.inf
    3a4efc98b0 ArmVirtPkg: Enable QemuFwCfgMmioDxeLib.inf
    3d87214a20 OvmfPkg: Copy the same new INF as QemuFwCfgLibMmio.inf
    fcce7f77e6 OvmfPkg: Add the QemuFwCfgMmioLib PEI stage version
    748d57d40f OvmfPkg: Add the way of HOBs in QemuFwCfgLibMmio
    5e31c5666d OvmfPkg: Separate QemuFwCfgLibMmio.c into two files
    e942b85a21 OvmfPkg: Add a GUID for QemuFwCfgLib
    0c74aa2073 UefiCpuPkg/Library: Cleanup debug message in LmceSupport
    88781ccd74 ReadMe.rst: Add libspdm submodule license
    54a4fd9b35 SecurityPkg: Add libspdm submodule
    9bc2725198 .gitmodule: Add libspdm submodule for EDKII
    cf3b34c0b8 .pytool/CISettings.py: add libspdm submodule.
    750d763623 SecurityPkg: add DeviceSecurity support
    c3f615a1bd SecurityPkg: Add TCG PFP 1.06 support.
    d8e4c4b000 MdeModulePkg/Variable: Add TCG SPDM device measurement update
    74db2ed3e5 MdePkg: Add devAuthBoot GlobalVariable
    5f391c6606 MdePkg: Add TCG PFP 1.06 support.
    338fd26b8f MdePkg: Add SPDM1.2 support.
    094727264f MdePkg: Add Cxl30.h into IndustryStandard
    c0dfe3ec1f BaseTools/GetUtcDateTime.py: Python 3.12 support
    66c24219ad OvmfPkg/VirtHstiDxe: do not load driver in confidential guests
    90b6725562 Update to CodeQL 2.16.1
    d97f964f7c BaseTools/Fmmt.py: Python 3.12 support
    e3fa6986ae OvmfPkg: Harden #VC instruction emulation somewhat (CVE-2024-25742)
    86c8d69146 IntelFsp2Pkg/PatchFv.py: Python 3.12 support
    680030a6ec IntelFsp2Pkg/GenCfgOpt.py: Python 3.12 support
    7dd7b89058 ArmVirtPkg/ArmVirtQemu: always build XIP code with strict alignment
    f29160a896 OvmfPkg/VirtHstiDxe: add README.md
    506740982b OvmfPkg/VirtHstiDxe: add code flash check
    ddc43e7a41 OvmfPkg/VirtHstiDxe: add varstore flash check
    538b8944c1 OvmfPkg: Add VirtHstiDxe to OVMF firmware build
    d0906f602b OvmfPkg: Add VirtHstiDxe driver
    be92e09206 OvmfPkg/IntelTdx: Update TDVF README
    6780b3aba0 Maintainers: AMD as SPI driver stack maintainer
    1dc752d903 MdeModulePkg: Add SPI NOR FLash SFDP drivers to DSC
    8b02ecc5f0 MdeModulePkg/SpiNorFlashJedecSfdp: SPI NOR Flash JEDEC SFDP
    6dc09fda04 MdeModulePkg: Add definitions in DEC for SPI NOR Flash SFDP driver
    390b10b548 MdePkg/Include: Add SPI NOR Flash JEDEC SFDP header file
    7dec566775 MdePkg/Include: Update definitions of SPI related header files
    0afb874349 OvmfPkg/BaseMemEncryptLib: Check for presence of an SVSM when not at VMPL0
    47001ab989 Ovmfpkg/CcExitLib: Provide SVSM discovery support
    a010681f74 UefiCpuPkg/MpInitLib: AP creation support under an SVSM
    28fecae8a3 OvmfPkg/AmdSvsmLib: Add support for the SVSM create/delete vCPU calls
    18fdffe825 OvmfPkg/BaseMemEncryptSevLib: Maximize Page State Change efficiency
    b505f11f39 OvmfPkg/AmdSvsmLib: Add support for the SVSM_CORE_PVALIDATE call
    5a67a2efa7 OvmfPkg: Create a calling area used to communicate with the SVSM
    f6bf37c171 OvmfPkg/BaseMemEncryptSevLib: Use AmdSvsmSnpPvalidate() to validate pages
    ee89b59430 UefiCpuPkg/MpInitLib: Use AmdSvsmSnpVmsaRmpAdjust() to set/clear VMSA
    6ced1e91ef Ovmfpkg/AmdSvsmLib: Create AmdSvsmLib to handle SVSM related services
    789727ccf3 Ovmfpkg: Prepare OvmfPkg to use the AmdSvsmLib library
    d2b18e6bc2 UefiPayloadPkg: Prepare UefiPayloadPkg to use the AmdSvsmLib library
    30d274e354 UefiCpuPkg/AmdSvsmLib: Create the AmdSvsmLib library to support an SVSM
    c0bf953fe8 MdePkg/BaseLib: Add a new VMGEXIT instruction invocation for SVSM
    8ccbf075f0 MdePkg/Register/Amd: Define the SVSM related information
    069f9911a3 OvmfPkg/BaseMemEncryptSevLib: Maximize Page State Change efficiency
    2b330b57db OvmfPkg/BaseMemEncryptSevLib: Re-organize page state change support
    f40c1f2a30 MdePkg: Avoid hardcoded value for number of Page State Change entries
    5fe9db0f82 OvmfPkg/BaseMemEncryptSevLib: Calculate memory size for Page State Change
    6b14ef6b28 OvmfPkg/BaseMemEncryptSevLib: Fix uncrustify errors
    4bd3b5ab13 OvmfPkg/PlatformPei: Retrieve APIC IDs from the hypervisor
    5bdb091133 UefiCpuPkg/MpInitLib: Always use AP Create if GhcbApicIds HOB is present
    8a6471819b MdePkg: GHCB APIC ID retrieval support definitions
    c212fec9cf OvmfPkg/BaseMemEncryptLib: Fix error check from AsmRmpAdjust()
    61185f1d50 SecurityPkg: Delete TdTcg2Dxe and HashLibTdx in SecurityPkg
    93fac4fd7b OvmfPkg: Update TdTcg2Dxe path in OvmfPkgX64 and IntelTdxX64.dsc
    c98fbda328 OvmfPkg/TdTcg2Dxe: Add TdTcg2Dxe
    93ff80a218 OmvfPkg/HashLibTdx: Add HashLibTdx
    71aaf7a308 Security/SecTpmMeasurementLibTdx: Delete unused SecTpmMeasurementLibTdx
    fcfdbe2987 NetworkPkg/WifiConnectionManagerDxe: Update UI according to UEFI spec
    b6cd5ddce9 SecurityPkg/OpalPasswordDxe: Force reparsing IFR binary when RETRIEVE
    32e2968a1e SecurityPkg/OpalPasswordDxe: Change callback action to meet UEFI spec
    7ea05d8fe9 ShellPkg/SmbiosView: Support New ProcessorUpgrade for SMBIOS Type4
    bfcf2d66c7 MdePkg/SmBios.h: Add New ProcessorUpgrade definitions for SMBIOS Type4
    6363872629 UefiCpuPkg/UefiCpuPkg.dsc: Add CpuMmio2Dxe.inf to LoongArch64 field
    0b2f97c00a UefiCpuPkg: Add CpuDxe driver for LoongArch64
    abaf405ed9 UefiCpuPkg: Add multiprocessor library for LoongArch64
    392a368533 UefiCpuPkg: Add a new GUID to store the processors resource
    032830e968 UefiCpuPkg: Add CpuMmuLib to UefiCpuPkg
    c5fb47ddab UefiCpuPkg: Added a new PCD named PcdLoongArchExceptionVectorBaseAddress
    78e5019071 UefiCpuPkg: Add CpuMmuLib.h to UefiCpuPkg
    7750468c37 UefiCpuPkg: Add CPU exception library for LoongArch
    439030bc37 UefiCpuPkg: Add LoongArch64 CPU Timer instance
    cc63e04afc UefiCpuPkg/CpuDxe: Reorder the INF file alphabetically
    022ddb8f84 UefiCpuPkg/MpInitLib: Reorder the INF files alphabetically
    fecca982e3 UefiCpuPkg/CpuExceptionHandlerLib: Reorder the INF files alphabetically
    18ad6485a9 UefiCpuPkg/CpuTimerLib: Reorder the INF file alphabetically
    70892b13b2 StandaloneMmPkg: Support to unregister MMI handler in MMI handlers
    74f6ce6734 MdeModulePkg/SMM: Support to unregister SMI handler in SMI handlers
    da7858117f Revert ae1079b386a597108a8070652bf7cdaa4ec3dda3
    b594fba4ec Revert 17b28722008eab745ce186b72cd325944cbe6bf0
    de95e919be Revert 049ff6c39c73edd3709c05bd0e46184320471358
    31cd5ee8c0 Revert 2ec8f0c6407f062441b205b900038933865c7b3c
    5ba3602e45 BaseTools: Use Stronger Matching for NULL Linked Libraries
    d77efa2ebe BaseTools: Don't Recurse NULL Includes Not Linked to Module
    0707d9296d SecurityPkg/Tcg2Config: Hide BIOS unsupported hash algorithm from UI
    e25808f501 MdePkg: Update the comments of GetInformation function
    98f150a954 MdeModulePkg/AcpiTableDxe: Prefer xDSDT over DSDT when installing tables
    963671d380 ShellPkg: Update smbiosview type 4 with SMBIOS 3.6 fields
    665789b61b IntelFsp2WrapperPkg: Fsp T UPD Structure Bug Fix
    013006e4ef IntelFsp2WrapperPkg: Fsp T new ARCH UPD Support
    543add1d41 IntelFsp2Pkg: Fsp T new ARCH UPD Support
    932db9df0c MdeModulePkg/AcpiTableDxe: PCD switch to avoid using ACPI reclaim memory
    b7f8779fe1 OvmfPkg/RiscVVirt: Disable Svpbmt extension
    3d5352d934 UefiCpuPkg: RISC-V: MMU: Support Svpbmt extension
    6ddfbeb0d6 UefiCpuPkg: RISC-V: MMU: Explictly use UINT64 instead of UINTN
    f1203a4099 MdePkg.dec: RISC-V: Define override bit for Svpbmt extension
    c98c14576f CryptoPkg/BaseCryptLibUnitTest: add unit test functions
    503344cdbd CryptoPkg/Driver: add additional RSAES-OAEP crypto functions
    89ff5da9f9 CryptoPkg/BaseCryptLib: add additional RSAES-OAEP crypto functions
    ee28bea4c0 SecurityPkg/SecureBootConfigDxe: Update UI according to UEFI spec
    8707f835ae ArmPkg: Remove ArmCortexA9.h
    ee249efe8c ArmPkg: Remove ArmCortexA5x.h
    6fb3cc05dc RedfishPkg/RedfishPlatformConfigDxe: support menu path report
    79d4d8a81c EmulatorPkg/Redfish: Use edk2 Redfish debug PCDs
    2e4e41d012 RedfishPkg/RedfishPlatformConfigDxe: HII string is deleted unexpectedly
    c8f56800fd RedfishPkg/RedfishPlatformConfigDxe:Add RefishDebugLib support
    b0be42516e RedfishPkg/RedfishDebugLib: Introduce Redfish DEBUG macro
    29114fc574 RedfishPkg/RedfishPlatformConfigDxe: Config language searching optimization
    b387114113 EmulatorPkg: Update the comments of ReadKeyStroke and ReadKeyStrokeEx
    7cc2010f46 EmbeddedPkg: Update the comments of ReadKeyStroke and ReadKeyStrokeEx
    b79a64d26e ShellPkg: Update the comments of ReadKeyStroke and ReadKeyStrokeEx
    e043e3e3bf MdeModulePkg: Update the comments of ReadKeyStroke and ReadKeyStrokeEx
    8f698f0a64 CryptoPkg: Remove interdependence for RsaPssVerify
    d402de2222 CryptoPkg: Update Md5/Sha1/Sha2 by using new mbedtls api
    278250045b CryptoPkg: Update OPTIONAL location for BaseCryptLibMbedTls
    37f63deeef MdeModulePkg: MemoryProtection: Use ImageRecordPropertiesLib
    596f856c13 MdeModulePkg: ImagePropertiesRecordLib: Consolidate Usage
    1fb6462c67 MdeModulePkg: ImagePropertiesRecordLib: Use SectionAlignment for CodeSize
    7fde22823d MdePkg: Add gEfiDeviceSignatureDatabaseGuid to dec
    e4e1f6229c MdePkg: Add UEFI 2.10 DeviceAuthentication
    cf58f47623 ShellPkg/Acpiview: Adds ACPI WSMT Table parse
    4b9312de05 ShellPkg/Acpiview: Adds HPET parser
    7f1ffba5de MdeModulePkg/Xhci: Skip another size round up for TRB address
    35f6a2780e OvmfPkg/TdxDxe: Clear the registers before tdcall
    a1a6da80aa OvmfPkg/CcExitLib: Update TDVMCALL_EXPOSE_REGS_MASK
    07c49d5d40 MdePkg/BaseLib: Update TDVMCALL_EXPOSE_REGS_MASK
    3840c35e34 IntelFsp2WrapperPkg: Error handling of FspmWrapperInit()
    ccbbc2a5c8 IntelFsp2WrapperPkg: Error handling of TpmMeasureAndLogDataWithFlags()
    e7486b5064 MdeModulePkg: DxeCore: Do Not Apply Guards to Unsupported Types
    68461c2c37 MdeModulePkg: DxeCore: Correct Runtime Granularity Memory Type
    bf8f16f771 MdeModulePkg: DxeCore: Fix CodeQL Error in FreePages
    019feb42a1 MdeModulePkg: Remove ArmPkg Dependency
    5572b43c67 BaseTools/GenFds: Apply OEM_CAPSULE_FLAGS during Capsule generation.
    308e6e0936 DynamicTablesPkg/SSDT: Require Package node in hierarchy
    6b3a512149 SecurityPkg: Update ReceiveData and SendData function description
    6f67ed45e0 MdeModulePkg: Update ReceiveData and SendData function description
    a8b80149e1 MdePkg: Update ReceiveData and SendData function description
    ddaf39263a EmbeddedPkg/NonCoherentIoMmuDxe: Make SetAttributes always succeed
    ccf91b518f Maintainers.txt: remove Laszlo's entries
    1c0db23151 UefiPayloadPkg: auto-generate SEC ProcessLibraryConstructorList() decl
    18fc96c9a9 UefiCpuPkg: auto-generate SEC ProcessLibraryConstructorList() decl
    1e603ac0d8 IntelFsp2Pkg: auto-generate SEC ProcessLibraryConstructorList() decl
    063a831c66 EmulatorPkg: auto-generate SEC ProcessLibraryConstructorList() decl
    f71a76ee01 ArmVirtPkg: auto-generate SEC ProcessLibraryConstructorList() decl
    91460083f1 ArmPlatformPkg: auto-generate SEC ProcessLibraryConstructorList() decl
    524feaa32f OvmfPkg/RiscVVirt/Sec: clean up ProcessLibraryConstructorList() decl
    9f9bf82209 OvmfPkg/IntelTdx: auto-gen & fix SEC ProcessLibraryConstructorList() decl
    1fbc121cfe OvmfPkg: auto-generate (and fix) SEC ProcessLibraryConstructorList() decl
    da4aa451ba pip-requirements.txt: require edk2-basetools version 0.1.51
    e60529df58 UefiPayloadPkg: Make Dsc accomodative of other archs
    2a0d4a2641 OvmfPkg/SmbiosPlatformDxe: tweak fallback release date again
    918288ab5a .github/workflows/codeql.yml: Update actions being deprecated
    bff9815b61 BaseTools/GenFds: Resolve absolute workspace INF paths
    1ae5bee967 DynamicTablesPkg/SsdtSerialPortFixupLib: Add Interrupt node for SPIs only
    855f528199 ArmPkg/ArmGicArchLib: Add macros for SPI and extended SPI ranges
    970aacd191 UefiPayloadPkg: UPL arch backward support ELF
    3775122ede ShellPkg/SmbiosView: Support New ProcessorFamily for SMBIOS Type4
    47723854fd MdePkg/SmBios.h: Add New ProcessorFamily definitions for SMBIOS Type4
    275d0a39c4 OvmfPkg/ResetVector: wire up 5-level paging for TDX
    318b0d714a OvmfPkg/ResetVector: print post codes for 4/5 level paging
    49b7faba1d OvmfPkg/ResetVector: add 5-level paging support
    e3bd782373 OvmfPkg/ResetVector: split SEV and non-CoCo workflows
    b7a97bfac5 OvmfPkg/ResetVector: split TDX BSP workflow
    4329b5b0cd OvmfPkg/ResetVector: add CreatePageTables4Level macro
    52e44713d2 OvmfPkg/ResetVector: add ClearOvmfPageTables macro
    fded08e744 OvmfPkg/ResetVector: improve page table flag names
    371940932d MdeModulePkg/Core/Pei: Improve the copy performance
    2ec8f0c640 StandaloneMmPkg: Disallow unregister MMI handler in other MMI handler
    049ff6c39c StandaloneMmPkg: Support to unregister MMI handler inside MMI handler
    17b2872200 MdeModulePkg/SMM: Disallow unregister SMI handler in other SMI handler
    ae1079b386 MdeModulePkg/SMM: Support to unregister SMI handler inside SMI handler
    dcffad2491 UefiCpuPkg/CpuPageTableLib: qualify page table accesses as volatile
    d159e22913 UefiCpuPkg/CpuPageTableLib: Fix IN OUT parameters marked as IN
    dc7cfa9bab UefiCpuPkg/MpInitLib: add struct MP_HAND_OFF_CONFIG
    bac9c74080 BaseTools/AutoGen: declare ProcessLibraryConstructorList() for SEC modules
    adebfe121c OvmfPkg/PlatformInitLib: add 5-level paging support
    13fbc16556 MdeModulePkg/DxeIplPeim: rename variable
    73ac735be8 MdeModulePkg/DxeIplPeim: fix PcdUse5LevelPageTable assert
    d9a6e7b0b8 RedfishPkg/RedfishCrtLib: fix unresolved external symbol issue
    d4c76fa17d RedfishPkg/RedfishDebugLib: use RedfishHttpLib
    422dfaab31 RedfishPkg/RedfishLib: include RedfishServiceData.h
    9da786c16f RedfishPkg: introduce RedfishHttpLib
    0ce2012c6c RedfishPkg: implement Redfish HTTP protocol
    1988f2df29 RedfishPkg: introduce Redfish HTTP protocol
    3e91e42136 BaseTools: Syntax warning invalid escape sequence \C
    6d571c0070 BaseTools/Scripts/PatchCheck: Error if commit modifies multiple packages
    0bbec15b54 BaseTools/Scripts/PatchCheck: Error if no Cc tags are present
    45ad13bb64 BaseTools/Scripts/PatchCheck: Return CommitMessageCheck errors
    dae8c29dab BaseTools/Scripts/PatchCheck: Update Author checks
    e59a40b92c EmbeddedPkg/Scripts/LauterbachT32: Fix EfiLoadDxe.cmm
    aceb3490a2 OvmfPkg/PlatformPei: log pei memory cap details
    3ad1d7eb7b OvmfPkg/PlatformPei: rewrite page table calculation
    8757e648d1 OvmfPkg/PlatformPei: consider AP stacks for pei memory cap
    9d32a02a72 OvmfPkg/PlatformPei: log a warning when memory is tight
    ba9c3ceaf8 StandaloneMmPkg: Arm: Update to use the new StandaloneMmCpu driver
    e7a7169446 StandaloneMmPkg: Make StandaloneMmCpu driver architecture independent
    74b5309da9 RedfishPkg/RestJsonStructureDxe: Refine REST JSON C Structure DXE driver
    33c81c25bb MdeModulePkg/TraceHubDebugSysTLib: Use wider type for loop comparisons
    d25421d0d8 UefiCpuPkg/MpInitLib: return early in GetBspNumber()
    5e09b5d6d7 UefiCpuPkg/MpInitLib: Add support for multiple HOBs to SaveCpuMpData()
    c8e77454b5 UefiCpuPkg/MpInitLib: Add support for multiple HOBs to MpInitLibInitialize
    e2c9d8eba4 UefiCpuPkg/MpInitLib: Add support for multiple HOBs to SwitchApContext()
    b485230462 UefiCpuPkg/MpInitLib: Add support for multiple HOBs to GetBspNumber()
    a3ee1eea96 UefiCpuPkg/MpInitLib: Add support for multiple HOBs to GetMpHandOffHob
    1f161a7915 MdeModulePkg/Bus/Usb/UsbNetwork: Check array index range before access
    68238d4f94 MdePkg Updated the comments of EFI_SYSTEM_TABLE and ReadKeyStroke
    44fdc4f398 BaseTools: Update keybaord map based on UEFI spec 2.10
    d0c0e1960a MdePkg: Update keybaord map based on UEFI spec 2.10
    ba96acd963 ArmVirtPkg/XenAcpiPlatformDxe: Install FACS table from DT
    f881b4d129 OvmfPkg: only add shell to FV in case secure boot is disabled
    bc982869dd OvmfPkg/CI: copy shell to virtual drive
    8d7c48e0e7 OvmfPkg: switch MicrovmX64 to new shell include files
    6bb39cfd00 OvmfPkg: switch IntelTdxX64 to new shell include files
    a7a0443751 OvmfPkg: switch AmdSevX64 to new shell include files
    796e1b82df OvmfPkg: switch OvmfPkgIa32X64 to new shell include files
    65200edb3a OvmfPkg: switch OvmfPkgIa32 to new shell include files
    bda5b4a6cf OvmfPkg: ShellDxe.fdf.inc: add VariablePolicyDynamicCommand to FV
    7f17a15564 OvmfPkg: Shell*.inc: allow building without network support
    b25f84d7b3 OvmfPkg: add ShellDxe.fdf.inc
    efca2c6cfc OvmfPkg: add ShellLibs.dsc.inc
    2cb466cc2c OvmfPkg: add ShellComponents.dsc.inc
    7fa4a984c4 UefiPayloadPkg/Gop: Clean up unused protocol and Guid
    11ad164bce UefiPayloadPkg: Make UPL build script arch agnostic
    8ccd63d14d UefiCpuPkg: Fix issue that IsModified is wrongly set in PageTableMap
    c10e5703fe UefiCpuPkg/CpuMpPei: Don't write CR3 in ConvertMemoryPageToNotPresent
    2f4b07b668 UefiCpuPkg/CpuPageTableLib: Enhance function header for PageTableMap()
    2ca8d55974 UefiCpuPkg/PiSmmCpuDxeSmm: Check BspIndex first before lock cmpxchg
    d698bcfe4f UefiCpuPkg/PiSmmCpuDxeSmm: Avoid BspIndex typecasting
  - Removed patches which are merged to edk2-stable202405:
  - ovmf-OvmfPkg-SmbiosPlatformDxe-tweak-fallback-release-dat.patch
    9aa057b29834 OvmfPkg/SmbiosPlatformDxe: tweak fallback release date again
  - Add brotli as new submodule
  - brotli-f4153a09f87cbb9c826d8fc12c74642bb2d879ea.tar.gz
  - https://github.com/google/brotli/archive/f4153a09f87cbb9c826d8fc12c74642bb2d879ea.tar.gz
  - https://github.com/google/brotli
  - edk2 commit ids:
    1193aa2dfbbd MdeModulePkg: update brotli submodule
    42af706dfba7 BaseTools: Update brotli submodule
  - Updated ovmf.spec
  - unpacked brotli-f4153a09f87cbb9c826d8fc12c74642bb2d879ea.tar.gz to
    BaseTools/Source/C/BrotliCompress/brotli and
    MdeModulePkg/Library/BrotliCustomDecompressLib/brotli
  - We add brotli back to ovmf.spec as a submodule to align with edk2 mainline.
    Then we can remove ovmf-disable-brotli.patch to reduce the number of downstream patches.
  - removed ovmf-disable-brotli.patch
  - Add libspdm as new submodule
  - libspdm-50924a4c8145fc721e17208f55814d2b38766fe6.tar.gz
  - https://github.com/DMTF/libspdm/archive/50924a4c8145fc721e17208f55814d2b38766fe6.tar.gz
  - https://github.com/DMTF/libspdm.git
  - edk2 commit ids:
    79655e276860 SecurityPkg: Update libspdm submodule to use GitLab cmocka repo
    54a4fd9b35ca SecurityPkg: Add libspdm submodule
    9bc272519868 .gitmodule: Add libspdm submodule for EDKII
  - Updated ovmf.spec
  - unpacked libspdm-50924a4c8145fc721e17208f55814d2b38766fe6.tar.gz to SecurityPkg/DeviceSecurity/SpdmLib/libspdm
  - Changed the approach for creating the edk2 source code tarball:
  - Original approach for getting the edk2 source code tarball is
    directly downloading edk2-edk2-stable%{version}.tar.gz from
    https://github.com/tianocore/edk2.
  - New approach is that we download edk2-edk2-stable%{version}.tar.gz
    from https://github.com/tianocore/edk2. Then we repackage the tarball
    for renaming the build root folder from edk2-edk2-stable%{version}/ to
    edk2/. This approach can reduce the size of FV image against
    FD_SIZE_2MB config.
    (I believe that the reason is "gcc -g" produced bigger image when the
    name of build root folder has longer name)
  - A advantage by using edk2/ as the build root folder name is that it
    aligns with the edk2 git project name. In development stage, developer
    should find that the FV image size is too big for FD_SIZE_2MB config.
    So we use the same name of build root folder with development stage.
  - Another approach for getting the source tarball is using git in local
    edk2 git repo:
    git archive --format=tar.gz -o ./edk2-edk2-stable%{version}.tar.gz --prefix=edk2/ edk2-stable%{version}
    For example:
    git archive --format=tar.gz -o ./edk2-edk2-stable202405.tar.gz --prefix=edk2/ edk2-stable202405
  - Against this change, we modified the setup command in %prep section in
    ovmf.spec:
    old: %setup -q -n edk2-edk2-stable%{version}
    new: %setup -q -n edk2

------------------------------------------------------------------
------------------  2024-9-8  -  Sep 8 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to release 24.2.2
  - -> https://docs.mesa3d.org/relnotes/24.2.2
  - -> https://docs.mesa3d.org/relnotes/24.2.1
  - -> https://docs.mesa3d.org/relnotes/24.2.0
  - refreshed the following patches with quilt:
    * U_fix-mpeg1_2-decode-mesa-20.2.patch
    * n_add-Mesa-headers-again.patch
    * n_stop-iris-flicker.patch
    * u_dep_xcb.patch
    * u_fix_rust_bindgen.patch
  - dropped U_radeonsi-vcn-Add-decode-DPB-buffers-as-CS-dependency.patch
  - New BuildRequires:
    * python3-PyYAML
  - enable llvm also for non-driver build to fix:
    "llvmpipe requires LLVM and is enabled, but LLVM is disabled".

++++ Mesa-drivers:

  - Update to release 24.2.2
  - -> https://docs.mesa3d.org/relnotes/24.2.2
  - -> https://docs.mesa3d.org/relnotes/24.2.1
  - -> https://docs.mesa3d.org/relnotes/24.2.0
  - refreshed the following patches with quilt:
    * U_fix-mpeg1_2-decode-mesa-20.2.patch
    * n_add-Mesa-headers-again.patch
    * n_stop-iris-flicker.patch
    * u_dep_xcb.patch
    * u_fix_rust_bindgen.patch
  - dropped U_radeonsi-vcn-Add-decode-DPB-buffers-as-CS-dependency.patch
  - New BuildRequires:
    * python3-PyYAML
  - enable llvm also for non-driver build to fix:
    "llvmpipe requires LLVM and is enabled, but LLVM is disabled".

++++ kernel-default:

  - clk: qcom: gcc-sc8280xp: don't use parking clk_ops for QUPs
    (git-fixes).
  - clk: qcom: gcc-sm8550: Don't park the USB RCG at registration
    time (git-fixes).
  - clk: qcom: gcc-sm8550: Don't use parking clk_ops for QUPs
    (git-fixes).
  - clk: qcom: ipq9574: Update the alpha PLL type for GPLLs
    (git-fixes).
  - clk: qcom: clk-alpha-pll: Fix zonda set_rate failure when PLL
    is disabled (git-fixes).
  - clk: qcom: clk-alpha-pll: Fix the trion pll postdiv set rate
    API (git-fixes).
  - clk: qcom: clk-alpha-pll: Fix the pll post div mask (git-fixes).
  - commit 060a67a

++++ kernel-rt:

  - clk: qcom: gcc-sc8280xp: don't use parking clk_ops for QUPs
    (git-fixes).
  - clk: qcom: gcc-sm8550: Don't park the USB RCG at registration
    time (git-fixes).
  - clk: qcom: gcc-sm8550: Don't use parking clk_ops for QUPs
    (git-fixes).
  - clk: qcom: ipq9574: Update the alpha PLL type for GPLLs
    (git-fixes).
  - clk: qcom: clk-alpha-pll: Fix zonda set_rate failure when PLL
    is disabled (git-fixes).
  - clk: qcom: clk-alpha-pll: Fix the trion pll postdiv set rate
    API (git-fixes).
  - clk: qcom: clk-alpha-pll: Fix the pll post div mask (git-fixes).
  - commit 060a67a

++++ python-httpx:

  - update to 0.27.2:
    * Reintroduced supposedly-private `URLTypes` shortcut.
    * Support for `zstd` content decoding using the python
    `zstandard` package is added. Installable using
    `httpx[zstd]`.
    * Improved error messaging for `InvalidURL` exceptions.
    * Fix `app` type signature in `ASGITransport`.

++++ python-idna:

  - update to 3.8:
    * Fix regression where IDNAError exception was not being
    produced for certain inputs.
    * Add support for Python 3.13, drop support for Python 3.5 as
    it is no longer testable.
    * Documentation improvements
    * Updates to package testing using Github actions

------------------------------------------------------------------
------------------  2024-9-7  -  Sep 7 2024  -------------------
------------------------------------------------------------------

++++ docker:

  - Mark docker-buildx as required since classic "docker build" has been
    deprecated since Docker 23.0. bsc#1230331
  - Import docker-buildx v0.16.2 as a subpackage. Previously this was a separate
    package, but with docker-stable it will be necessary to maintain the packages
    together and it makes more sense to have them live in the same OBS package.
    bsc#1230333
  - Make some minor name macro updates to help with the docker-stable package
    fork.

++++ kernel-default:

  - ALSA: hda/realtek - Fix inactive headset mic jack for ASUS
    Vivobook 15 X1504VAP (stable-fixes).
  - ALSA: hda/realtek: Support mute LED on HP Laptop 14-dq2xxx
    (stable-fixes).
  - ALSA: hda/realtek: Enable Mute Led for HP Victus 15-fb1xxx
    (stable-fixes).
  - ALSA: hda/realtek: extend quirks for Clevo V5[46]0
    (stable-fixes).
  - ALSA: hda/realtek: add patch for internal mic in Lenovo V145
    (stable-fixes).
  - ALSA: hda/conexant: Add pincfg quirk to enable top speakers
    on Sirius devices (stable-fixes).
  - commit 5538dd8
  - ASoC: sunxi: sun4i-i2s: fix LRCLK polarity in i2s mode
    (git-fixes).
  - ASoc: SOF: topology: Clear SOF link platform name upon unload
    (git-fixes).
  - ASoC: tegra: Fix CBB error during probe() (git-fixes).
  - ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object (git-fixes).
  - mmc: cqhci: Fix checking of CQHCI_HALT state (git-fixes).
  - mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K
    (git-fixes).
  - mmc: sdhci-of-aspeed: fix module autoloading (git-fixes).
  - mmc: core: apply SD quirks earlier during probe (git-fixes).
  - gpio: modepin: Enable module autoloading (git-fixes).
  - gpio: rockchip: fix OF node leak in probe() (git-fixes).
  - Revert "drm/amdgpu: align pp_power_profile_mode with kernel
    docs" (stable-fixes).
  - nouveau: fix the fwsec sb verification register (git-fixes).
  - drm/i915/fence: Mark debug_fence_free() with __maybe_unused
    (git-fixes).
  - drm/i915/fence: Mark debug_fence_init_onstack() with
    __maybe_unused (git-fixes).
  - drm/i915: Do not attempt to load the GSC multiple times
    (git-fixes).
  - commit 7a89765

++++ kernel-rt:

  - ALSA: hda/realtek - Fix inactive headset mic jack for ASUS
    Vivobook 15 X1504VAP (stable-fixes).
  - ALSA: hda/realtek: Support mute LED on HP Laptop 14-dq2xxx
    (stable-fixes).
  - ALSA: hda/realtek: Enable Mute Led for HP Victus 15-fb1xxx
    (stable-fixes).
  - ALSA: hda/realtek: extend quirks for Clevo V5[46]0
    (stable-fixes).
  - ALSA: hda/realtek: add patch for internal mic in Lenovo V145
    (stable-fixes).
  - ALSA: hda/conexant: Add pincfg quirk to enable top speakers
    on Sirius devices (stable-fixes).
  - commit 5538dd8
  - ASoC: sunxi: sun4i-i2s: fix LRCLK polarity in i2s mode
    (git-fixes).
  - ASoc: SOF: topology: Clear SOF link platform name upon unload
    (git-fixes).
  - ASoC: tegra: Fix CBB error during probe() (git-fixes).
  - ASoC: dapm: Fix UAF for snd_soc_pcm_runtime object (git-fixes).
  - mmc: cqhci: Fix checking of CQHCI_HALT state (git-fixes).
  - mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K
    (git-fixes).
  - mmc: sdhci-of-aspeed: fix module autoloading (git-fixes).
  - mmc: core: apply SD quirks earlier during probe (git-fixes).
  - gpio: modepin: Enable module autoloading (git-fixes).
  - gpio: rockchip: fix OF node leak in probe() (git-fixes).
  - Revert "drm/amdgpu: align pp_power_profile_mode with kernel
    docs" (stable-fixes).
  - nouveau: fix the fwsec sb verification register (git-fixes).
  - drm/i915/fence: Mark debug_fence_free() with __maybe_unused
    (git-fixes).
  - drm/i915/fence: Mark debug_fence_init_onstack() with
    __maybe_unused (git-fixes).
  - drm/i915: Do not attempt to load the GSC multiple times
    (git-fixes).
  - commit 7a89765

++++ python313-core:

  - Update to 3.13.0~rc2:
  - Tools/Demos
  - gh-123418: Update GitHub CI workflows to use OpenSSL 3.0.15
    and multissltests to use 3.0.15, 3.1.7, and 3.2.3.
  - Tests
  - gh-119727: Add --single-process command line option to
    Python test runner (regrtest). Patch by Victor Stinner.
  - gh-101525: Skip test_gdb if the binary is relocated by
    BOLT. Patch by Donghee Na.
  - Security
  - gh-123678: Upgrade libexpat to 2.6.3
  - gh-121285: Remove backtracking from tarfile header parsing
    for hdrcharset, PAX, and GNU sparse headers (bsc#1230227,
    CVE-2024-6232).
  - Library
  - gh-123448: Fixed memory leak of typing.NoDefault by moving
    it to the static types array.
  - gh-123409: Fix ipaddress.IPv6Address.reverse_pointer output
    according to RFC 3596, §2.5. Patch by Bénédikt Tran.
  - gh-123270: Applied a more surgical fix for malformed
    payloads in zipfile.Path causing infinite loops (gh-122905)
    without breaking contents using legitimate characters
    (bsc#1229704, CVE-2024-8088).
  - gh-123228: Fix return type for
    _pyrepl.readline._ReadlineWrapper.get_line_buffer() to be
    str(). Patch by Sergey B Kirpichev.
  - gh-123240: Raise audit events for the input() in the new
    REPL.
  - gh-123243: Fix memory leak in _decimal.
  - gh-122546: Consistently use same file name for different
    exceptions in the new repl. Patch by Sergey B Kirpichev.
  - gh-123213: xml.etree.ElementTree.Element.extend() and
    Element assignment no longer hide the internal exception if
    an erronous generator is passed. Patch by Bar Harel.
  - gh-85110: Preserve relative path in URL without netloc in
    urllib.parse.urlunsplit() and urllib.parse.urlunparse().
  - gh-123067: Fix quadratic complexity in parsing "-quoted
    cookie values with backslashes by http.cookies
    (bsc#1229596, CVE-2024-7592)
  - gh-122981: Fix inspect.getsource() for generated classes
    with Python base classes (e.g. enums).
  - gh-122903: zipfile.Path.glob now correctly matches
    directories instead of silently omitting them.
  - gh-122905: zipfile.Path objects now sanitize names from the
    zipfile.
  - gh-122695: Fixed double-free when using gc.get_referents()
    with a freed asyncio.Future iterator.
  - gh-116263: logging.handlers.RotatingFileHandler no longer
    rolls over empty log files.
  - gh-105376: Restore the deprecated logging warn() method. It
    was removed in Python 3.13 alpha 1. Keep the deprecated
    warn() method in Python 3.13. Patch by Victor Stinner.
  - gh-122744: Bump the version of pip bundled in ensurepip to
    version 24.2.
  - gh-118814: Fix the typing.TypeVar constructor when name is
    passed by keyword.
  - gh-122478: Remove internal frames from tracebacks
    shown in code.InteractiveInterpreter with non-default
    sys.excepthook(). Save correct tracebacks in
    sys.last_traceback and update __traceback__ attribute of
    sys.last_value and sys.last_exc.
  - gh-116622: On Android, the FICLONE and FICLONERANGE
    constants are no longer exposed by fcntl, as these ioctls
    are blocked by SELinux.
  - gh-82378: Make sure that the new REPL interprets
    sys.tracebacklimit in the same way that the classic REPL
    did.
  - gh-122334: Fix crash when importing ssl after the main
    interpreter restarts.
  - gh-87320: In code.InteractiveInterpreter, handle exceptions
    caused by calling a non-default sys.excepthook(). Before,
    the exception bubbled up to the caller, ending the REPL.
  - gh-121650: email headers with embedded newlines
    are now quoted on output. The generator will
    now refuse to serialize (write) headers
    that are unsafely folded or delimited; see
    verify_generated_headers. (Contributed by Bas Bloemsaat and
    Petr Viktorin in gh-121650.; CVE-2024-6923, bsc#1228780,
    also bsc#1257181, CVE-2026-1299)
  - gh-121723: Make logging.config.dictConfig() accept any
    object implementing the Queue public API. See the queue
    configuration section for details. Patch by Bénédikt Tran.
  - gh-122081: Fix a crash in the decimal.IEEEContext()
    optional function available via the EXTRA_FUNCTIONALITY
    configuration flag.
  - gh-121804: Correctly show error locations, when SyntaxError
    raised in new repl. Patch by Sergey B Kirpichev.
  - gh-121151: Fix wrapping of long usage text of arguments
    inside a mutually exclusive group in argparse.
  - gh-108172: webbrowser honors OS preferred browser on Linux
    when its desktop entry name contains the text of a known
    browser name.
  - gh-109109: You can now get the raw TLS                    .
    Cocertificate chains from TLS connections                   .
    Covia ssl.SSLSocket.get_verified_chain() and                .
    Cossl.SSLSocket.get_unverified_chain() methods ntributed by .
    CoMateusz Nowak                                             .
  - IDLE
  - gh-120083: Add explicit black IDLE Hovertip foreground
    color needed for recent macOS. Fixes Sonoma showing
    unreadable white on pale yellow. Patch by John Riggles.
  - Core and Builtins
  - gh-123572: Fix key mappings for various F-keys in Windows
    for the new REPL. Patch by devdanzin
  - gh-123484: Fix _Py_DebugOffsets for long objects to be
    relative to the start of the object rather than the start
    of a subobject.
  - gh-123344: Add AST optimizations for type parameter
    defaults.
  - gh-123321: Prevent Parser/myreadline race condition from
    segfaulting on multi-threaded use. Patch by Bar Harel and
    Amit Wienner.
  - gh-123177: Fix a bug causing stray prompts to appear in the
    middle of wrapped lines in the new REPL.
  - gh-122982: Extend the deprecation period for bool inversion
    (~) by two years.
  - gh-123177: Deactivate line wrap in the Apple Terminal via a
    ANSI escape code. Patch by Pablo Galindo
  - gh-123229: Fix valgrind warning by initializing the
    f-string buffers to 0 in the tokenizer. Patch by Pablo
    Galindo
  - gh-122298: Restore printout of GC stats when
    gc.set_debug(gc.DEBUG_STATS) is called. This featue was
    accidentally removed when implementing incremental GC.
  - gh-121804: Correctly show error locations when a
    SyntaxError is raised in the basic REPL. Patch by Sergey B
    Kirpichev.
  - gh-123142: Fix too-wide source location in exception
    tracebacks coming from broken iterables in comprehensions.
  - gh-123048: Fix a bug where pattern matching code could emit
    a JUMP_FORWARD with no source location.
  - gh-123123: Fix displaying SyntaxError exceptions covering
    multiple lines. Patch by Pablo Galindo
  - gh-123083: Fix a potential use-after-free in
    STORE_ATTR_WITH_HINT.
  - gh-123022: Fix crash in free-threaded build when calling
    Py_Initialize() from a non-main thread.
  - gh-122888: Fix crash on certain calls to str() with
    positional arguments of the wrong type. Patch by Jelle
    Zijlstra.
  - gh-116622: Fix Android stdout and stderr messages being
    truncated or lost.
  - gh-122527: Fix a crash that occurred when a
    PyStructSequence was deallocated after its type’s
    dictionary was cleared by the GC. The type’s tp_basicsize
    now accounts for non-sequence fields that aren’t included
    in the Py_SIZE of the sequence.
  - gh-122445: Add only fields which are modified via self.* to
    __static_attributes__.
  - gh-98442: Fix too wide source locations of the cleanup
    instructions of a with statement.
  - gh-93691: Fix source locations of instructions generated
    for with statements.
  - gh-120097: FrameLocalsProxy now subclasses
    collections.abc.Mapping and can be matched as a mapping in
    match statements
  - C API
  - gh-122728: Fix PyEval_GetLocals() to avoid SystemError
    (“bad argument to internal function”). Patch by Victor
    Stinner.
  - Build
  - gh-123297: Propagate the value of LDFLAGS to LDCXXSHARED in
    sysconfig. Patch by Pablo Galindo
  - gh-116622: Rename build variable MODULE_LDFLAGS back
    to LIBPYTHON, as it’s used by package build systems
    (e.g. Meson).
  - gh-118943: Fix an issue where the experimental JIT could be
    built several times by the make regen-all target, leading
    to possible race conditions on heavily parallelized builds.
  - gh-118943: Fix a possible race condition affecting parallel
    builds configured with --enable-experimental-jit, in which
    FileNotFoundError could be caused by another process
    already moving jit_stencils.h.new to jit_stencils.h.
  - Remove upstreamed patches:
  - bso1227999-reproducible-builds.patch
  - CVE-2024-8088-inf-loop-zipfile_Path.patch
  - gh120226-fix-sendfile-test-kernel-610.patch
  - gh122136-test_asyncio-kernel-buffer-data.patch
  - fix_configure_rst.patch
  - CVE-2024-6923-email-hdr-inject.patch

++++ python313:

  - Update to 3.13.0~rc2:
  - Tools/Demos
  - gh-123418: Update GitHub CI workflows to use OpenSSL 3.0.15
    and multissltests to use 3.0.15, 3.1.7, and 3.2.3.
  - Tests
  - gh-119727: Add --single-process command line option to
    Python test runner (regrtest). Patch by Victor Stinner.
  - gh-101525: Skip test_gdb if the binary is relocated by
    BOLT. Patch by Donghee Na.
  - Security
  - gh-123678: Upgrade libexpat to 2.6.3
  - gh-121285: Remove backtracking from tarfile header parsing
    for hdrcharset, PAX, and GNU sparse headers (bsc#1230227,
    CVE-2024-6232).
  - Library
  - gh-123448: Fixed memory leak of typing.NoDefault by moving
    it to the static types array.
  - gh-123409: Fix ipaddress.IPv6Address.reverse_pointer output
    according to RFC 3596, §2.5. Patch by Bénédikt Tran.
  - gh-123270: Applied a more surgical fix for malformed
    payloads in zipfile.Path causing infinite loops (gh-122905)
    without breaking contents using legitimate characters
    (bsc#1229704, CVE-2024-8088).
  - gh-123228: Fix return type for
    _pyrepl.readline._ReadlineWrapper.get_line_buffer() to be
    str(). Patch by Sergey B Kirpichev.
  - gh-123240: Raise audit events for the input() in the new
    REPL.
  - gh-123243: Fix memory leak in _decimal.
  - gh-122546: Consistently use same file name for different
    exceptions in the new repl. Patch by Sergey B Kirpichev.
  - gh-123213: xml.etree.ElementTree.Element.extend() and
    Element assignment no longer hide the internal exception if
    an erronous generator is passed. Patch by Bar Harel.
  - gh-85110: Preserve relative path in URL without netloc in
    urllib.parse.urlunsplit() and urllib.parse.urlunparse().
  - gh-123067: Fix quadratic complexity in parsing "-quoted
    cookie values with backslashes by http.cookies
    (bsc#1229596, CVE-2024-7592)
  - gh-122981: Fix inspect.getsource() for generated classes
    with Python base classes (e.g. enums).
  - gh-122903: zipfile.Path.glob now correctly matches
    directories instead of silently omitting them.
  - gh-122905: zipfile.Path objects now sanitize names from the
    zipfile.
  - gh-122695: Fixed double-free when using gc.get_referents()
    with a freed asyncio.Future iterator.
  - gh-116263: logging.handlers.RotatingFileHandler no longer
    rolls over empty log files.
  - gh-105376: Restore the deprecated logging warn() method. It
    was removed in Python 3.13 alpha 1. Keep the deprecated
    warn() method in Python 3.13. Patch by Victor Stinner.
  - gh-122744: Bump the version of pip bundled in ensurepip to
    version 24.2.
  - gh-118814: Fix the typing.TypeVar constructor when name is
    passed by keyword.
  - gh-122478: Remove internal frames from tracebacks
    shown in code.InteractiveInterpreter with non-default
    sys.excepthook(). Save correct tracebacks in
    sys.last_traceback and update __traceback__ attribute of
    sys.last_value and sys.last_exc.
  - gh-116622: On Android, the FICLONE and FICLONERANGE
    constants are no longer exposed by fcntl, as these ioctls
    are blocked by SELinux.
  - gh-82378: Make sure that the new REPL interprets
    sys.tracebacklimit in the same way that the classic REPL
    did.
  - gh-122334: Fix crash when importing ssl after the main
    interpreter restarts.
  - gh-87320: In code.InteractiveInterpreter, handle exceptions
    caused by calling a non-default sys.excepthook(). Before,
    the exception bubbled up to the caller, ending the REPL.
  - gh-121650: email headers with embedded newlines
    are now quoted on output. The generator will
    now refuse to serialize (write) headers
    that are unsafely folded or delimited; see
    verify_generated_headers. (Contributed by Bas Bloemsaat and
    Petr Viktorin in gh-121650.; CVE-2024-6923, bsc#1228780,
    also bsc#1257181, CVE-2026-1299)
  - gh-121723: Make logging.config.dictConfig() accept any
    object implementing the Queue public API. See the queue
    configuration section for details. Patch by Bénédikt Tran.
  - gh-122081: Fix a crash in the decimal.IEEEContext()
    optional function available via the EXTRA_FUNCTIONALITY
    configuration flag.
  - gh-121804: Correctly show error locations, when SyntaxError
    raised in new repl. Patch by Sergey B Kirpichev.
  - gh-121151: Fix wrapping of long usage text of arguments
    inside a mutually exclusive group in argparse.
  - gh-108172: webbrowser honors OS preferred browser on Linux
    when its desktop entry name contains the text of a known
    browser name.
  - gh-109109: You can now get the raw TLS                    .
    Cocertificate chains from TLS connections                   .
    Covia ssl.SSLSocket.get_verified_chain() and                .
    Cossl.SSLSocket.get_unverified_chain() methods ntributed by .
    CoMateusz Nowak                                             .
  - IDLE
  - gh-120083: Add explicit black IDLE Hovertip foreground
    color needed for recent macOS. Fixes Sonoma showing
    unreadable white on pale yellow. Patch by John Riggles.
  - Core and Builtins
  - gh-123572: Fix key mappings for various F-keys in Windows
    for the new REPL. Patch by devdanzin
  - gh-123484: Fix _Py_DebugOffsets for long objects to be
    relative to the start of the object rather than the start
    of a subobject.
  - gh-123344: Add AST optimizations for type parameter
    defaults.
  - gh-123321: Prevent Parser/myreadline race condition from
    segfaulting on multi-threaded use. Patch by Bar Harel and
    Amit Wienner.
  - gh-123177: Fix a bug causing stray prompts to appear in the
    middle of wrapped lines in the new REPL.
  - gh-122982: Extend the deprecation period for bool inversion
    (~) by two years.
  - gh-123177: Deactivate line wrap in the Apple Terminal via a
    ANSI escape code. Patch by Pablo Galindo
  - gh-123229: Fix valgrind warning by initializing the
    f-string buffers to 0 in the tokenizer. Patch by Pablo
    Galindo
  - gh-122298: Restore printout of GC stats when
    gc.set_debug(gc.DEBUG_STATS) is called. This featue was
    accidentally removed when implementing incremental GC.
  - gh-121804: Correctly show error locations when a
    SyntaxError is raised in the basic REPL. Patch by Sergey B
    Kirpichev.
  - gh-123142: Fix too-wide source location in exception
    tracebacks coming from broken iterables in comprehensions.
  - gh-123048: Fix a bug where pattern matching code could emit
    a JUMP_FORWARD with no source location.
  - gh-123123: Fix displaying SyntaxError exceptions covering
    multiple lines. Patch by Pablo Galindo
  - gh-123083: Fix a potential use-after-free in
    STORE_ATTR_WITH_HINT.
  - gh-123022: Fix crash in free-threaded build when calling
    Py_Initialize() from a non-main thread.
  - gh-122888: Fix crash on certain calls to str() with
    positional arguments of the wrong type. Patch by Jelle
    Zijlstra.
  - gh-116622: Fix Android stdout and stderr messages being
    truncated or lost.
  - gh-122527: Fix a crash that occurred when a
    PyStructSequence was deallocated after its type’s
    dictionary was cleared by the GC. The type’s tp_basicsize
    now accounts for non-sequence fields that aren’t included
    in the Py_SIZE of the sequence.
  - gh-122445: Add only fields which are modified via self.* to
    __static_attributes__.
  - gh-98442: Fix too wide source locations of the cleanup
    instructions of a with statement.
  - gh-93691: Fix source locations of instructions generated
    for with statements.
  - gh-120097: FrameLocalsProxy now subclasses
    collections.abc.Mapping and can be matched as a mapping in
    match statements
  - C API
  - gh-122728: Fix PyEval_GetLocals() to avoid SystemError
    (“bad argument to internal function”). Patch by Victor
    Stinner.
  - Build
  - gh-123297: Propagate the value of LDFLAGS to LDCXXSHARED in
    sysconfig. Patch by Pablo Galindo
  - gh-116622: Rename build variable MODULE_LDFLAGS back
    to LIBPYTHON, as it’s used by package build systems
    (e.g. Meson).
  - gh-118943: Fix an issue where the experimental JIT could be
    built several times by the make regen-all target, leading
    to possible race conditions on heavily parallelized builds.
  - gh-118943: Fix a possible race condition affecting parallel
    builds configured with --enable-experimental-jit, in which
    FileNotFoundError could be caused by another process
    already moving jit_stencils.h.new to jit_stencils.h.
  - Remove upstreamed patches:
  - bso1227999-reproducible-builds.patch
  - CVE-2024-8088-inf-loop-zipfile_Path.patch
  - gh120226-fix-sendfile-test-kernel-610.patch
  - gh122136-test_asyncio-kernel-buffer-data.patch
  - fix_configure_rst.patch
  - CVE-2024-6923-email-hdr-inject.patch

------------------------------------------------------------------
------------------  2024-9-6  -  Sep 6 2024  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20240906.742565b:
    * yama-enable-ptrace: enforce changed behavior upon installation (bsc#1221763)
    * Avoid unnecessary /bin/bash dependency
    * sysctl: Fixup of not setting kernel.pid_max on 32b archs (bsc#1227117)

++++ containerized-data-importer:

  - Update to version 1.60.1
    Release notes https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.60.1
  - Drop upstreamed patch
    0001-Bump-github.com-containers-image-v5-to-v5.30.1.patch
  - Add registry path for SLE15 SP7
  - Bump to the latest tag 1.60.1-150600.3.9.1

++++ python-kiwi:

  - Bump version: 10.1.5 → 10.1.6

++++ kernel-default:

  - ipv6: fix possible UAF in ip6_finish_output2() (bsc#1230206)
  - commit 64f6ea9
  - ipv6: prevent possible UAF in ip6_xmit() (CVE-2024-44985 bsc#1230206)
  - commit 209198a
  - vfs: Don't evict inode under the inode lru traversing context
    (CVE-2024-45003 bsc#1230245).
  - commit 630b67a
  - Restore dropped fields for bluetooth MGMT/SMP structs
    (git-fixes).
  - commit 5313ecb
  - usbnet: modern method to get random MAC (git-fixes).
  - net: phy: Fix missing of_node_put() for leds (git-fixes).
  - Bluetooth: MGMT: Ignore keys being loaded with invalid type
    (git-fixes).
  - Revert "Bluetooth: MGMT/SMP: Fix address type when using SMP
    over BREDR/LE" (git-fixes).
  - can: mcp251x: fix deadlock if an interrupt occurs during
    mcp251x_open (git-fixes).
  - can: mcp251xfd: fix ring configuration when switching from
    CAN-CC to CAN-FD mode (git-fixes).
  - can: m_can: Release irq on error in m_can_open (git-fixes).
  - can: bcm: Remove proc entry when dev is unregistered
    (git-fixes).
  - spi: rockchip: Resolve unbalanced runtime PM / system PM
    handling (git-fixes).
  - regulator: core: Stub devm_regulator_bulk_get_const() if
    !CONFIG_REGULATOR (git-fixes).
  - platform/x86: dell-smbios: Fix error path in dell_smbios_init()
    (git-fixes).
  - commit b6769e6
  - serial: sc16is7xx: fix invalid FIFO access with special register
    set (CVE-2024-44950 bsc#1230180).
  - serial: sc16is7xx: fix TX fifo corruption (CVE-2024-44951
    bsc#1230181).
  - serial: sc16is7xx: refactor FIFO access functions to increase
    commonality (CVE-2024-44951 bsc#1230181).
  - commit 4ab54b2
  - NFS: never reuse a NFSv4.0 lock-owner (bsc#1227726).
  - commit ed692a4

++++ kernel-rt:

  - ipv6: fix possible UAF in ip6_finish_output2() (bsc#1230206)
  - commit 64f6ea9
  - ipv6: prevent possible UAF in ip6_xmit() (CVE-2024-44985 bsc#1230206)
  - commit 209198a
  - vfs: Don't evict inode under the inode lru traversing context
    (CVE-2024-45003 bsc#1230245).
  - commit 630b67a
  - Restore dropped fields for bluetooth MGMT/SMP structs
    (git-fixes).
  - commit 5313ecb
  - usbnet: modern method to get random MAC (git-fixes).
  - net: phy: Fix missing of_node_put() for leds (git-fixes).
  - Bluetooth: MGMT: Ignore keys being loaded with invalid type
    (git-fixes).
  - Revert "Bluetooth: MGMT/SMP: Fix address type when using SMP
    over BREDR/LE" (git-fixes).
  - can: mcp251x: fix deadlock if an interrupt occurs during
    mcp251x_open (git-fixes).
  - can: mcp251xfd: fix ring configuration when switching from
    CAN-CC to CAN-FD mode (git-fixes).
  - can: m_can: Release irq on error in m_can_open (git-fixes).
  - can: bcm: Remove proc entry when dev is unregistered
    (git-fixes).
  - spi: rockchip: Resolve unbalanced runtime PM / system PM
    handling (git-fixes).
  - regulator: core: Stub devm_regulator_bulk_get_const() if
    !CONFIG_REGULATOR (git-fixes).
  - platform/x86: dell-smbios: Fix error path in dell_smbios_init()
    (git-fixes).
  - commit b6769e6
  - serial: sc16is7xx: fix invalid FIFO access with special register
    set (CVE-2024-44950 bsc#1230180).
  - serial: sc16is7xx: fix TX fifo corruption (CVE-2024-44951
    bsc#1230181).
  - serial: sc16is7xx: refactor FIFO access functions to increase
    commonality (CVE-2024-44951 bsc#1230181).
  - commit 4ab54b2
  - NFS: never reuse a NFSv4.0 lock-owner (bsc#1227726).
  - commit ed692a4

++++ libzypp:

  - API refactoring. Prevent zypper from using now private libzypp
    symbols (bsc#1230267)
  - Conflicts: zypper <= 1.14.76
  - version 17.35.10 (35)

++++ pam:

  - Add systemd-logind support to pam_limits (pam_limits-systemd.patch)
  - Remove /usr/etc/pam.d, everything should be migrated
  - Remove pam_limits from default common-sessions* files. pam_limits
    is now part of pam-extra and not in our default generated config.
  - pam_issue-systemd.patch: only count class user sessions

++++ pam-config:

  - Update to version 2.11+git.20240906:
    * Move pam_limits before pam_systemd

++++ pam-full-src:

  - Add systemd-logind support to pam_limits (pam_limits-systemd.patch)
  - Remove /usr/etc/pam.d, everything should be migrated
  - Remove pam_limits from default common-sessions* files. pam_limits
    is now part of pam-extra and not in our default generated config.
  - pam_issue-systemd.patch: only count class user sessions

++++ python-gobject:

  - Update to version 3.49.0:
    + Rename master branch to main
    + Drop support for Python 3.8
    + Add Override for Gio.DataInputStream
    + Treat GParamSpec as any other fundamental type
    + override connection.register_object to prevent an invocation
    object from leaking
    + Various PyPy related fixes
    + bind_property: Accept keyword arguments
    + Various documentation improvements
    + Python2 / GTK2 cleanups
    + asyncio integration with support to await Gio async functions
    + meson: move from .egg-info to .dist-info/METADATA
    + build: fixes for building with gobject-introspection 1.81
  - Stop removing executable bits from examples, no longer needed.

++++ python-looseversion:

  - Add %{?sle15_python_module_pythons}

++++ rsync:

  - rsync-gcc14.patch: fixed the ipv6 configure check (bsc#1230156)

++++ zypper:

  - API refactoring. Prevent zypper from using now private libzypp
    symbols (bsc#1230267)
  - BuildRequires:  libzypp-devel >= 17.35.10.
  - Fix wrong numbers used in CommitSummary skipped/failed messages.
  - version 1.14.77

------------------------------------------------------------------
------------------  2024-9-5  -  Sep 5 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to bugfix release 24.1.7
  - -> https://docs.mesa3d.org/relnotes/24.1.7
  - Supersedes the following patch:
    * U_radeonsi-vcn-Add-decode-DPB-buffers-as-CS-dependency.patch
  - Rebase patches with quilt.

++++ Mesa-drivers:

  - Update to bugfix release 24.1.7
  - -> https://docs.mesa3d.org/relnotes/24.1.7
  - Supersedes the following patch:
    * U_radeonsi-vcn-Add-decode-DPB-buffers-as-CS-dependency.patch
  - Rebase patches with quilt.

++++ containerd:

  - Update to containerd v1.7.21. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.21>
    Fixes CVE-2023-47108. bsc#1217070
    Fixes CVE-2023-45142. bsc#1228553
  - Rebase patches:
    * 0001-BUILD-SLE12-revert-btrfs-depend-on-kernel-UAPI-inste.patch

++++ dpdk:

  - Fix build on aarch64 with gcc14:
    * 0001-examples-vm_power_manager-add-missing-header.patch

++++ python-kiwi:

  - add allowExtraConfig and exportFlags to ovftool options
    Add allowExtraConfig and exportFlags to ovftool options
  - Bump version: 10.1.4 → 10.1.5

++++ gnutls:

  - FIPS: Allow to perform the integrity check with the hmac provided
    by each library [bsc#1226724]
    * Rebase gnutls-FIPS-HMAC-nettle-hogweed-gmp.patch

++++ iputils:

  - Update to version 20240905 (mostly ping fixes release)
    https://github.com/iputils/iputils/releases/tag/20240905
  - Fix tarball url

++++ kernel-default:

  - atm: idt77252: prevent use after free in dequeue_rx()
    (CVE-2024-44998 bsc#1230171).
  - commit fd57936
  - tcp: add sanity checks to rx zerocopy (CVE-2024-26640
    bsc#1221650).
  - commit 21286c2
  - USB: serial: option: add MeiG Smart SRM825L (git-fixes).
  - commit 047a639
  - nilfs2: fix state management in error path of log writing
    function (git-fixes).
  - commit 9b55988
  - cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
    (git-fixes).
  - commit a322b71
  - usb: dwc3: core: Prevent USB core invalid event buffer address
    access (git-fixes).
  - commit de7b6b3
  - nilfs2: fix missing cleanup on rollforward recovery error
    (git-fixes).
  - commit b4149d3
  - nilfs2: protect references to superblock parameters exposed
    in sysfs (git-fixes).
  - commit e7215f6
  - arm64: tlb: Allow range operation for MAX_TLBI_RANGE_PAGES (bsc#1229585)
  - commit a52467b
  - arm64: tlb: Improve __TLBI_VADDR_RANGE() (bsc#1229585)
  - commit 26752eb
  - arm64: tlb: Fix TLBI RANGE operand (bsc#1229585)
  - commit 24bd468
  - arm64/mm: Update tlb invalidation routines for FEAT_LPA2 (bsc#1229585)
  - commit b8ec0d4
  - arm64/mm: Modify range-based tlbi to decrement scale (bsc#1229585)
  - commit e08c708
  - USB: serial: option: add MeiG Smart SRM825L (stable-fixes).
  - cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
    (stable-fixes).
  - usb: dwc3: core: Prevent USB core invalid event buffer address
    access (stable-fixes).
  - selinux,smack: don't bypass permissions check in inode_setsecctx
    hook (stable-fixes).
  - drm/amdgpu/swsmu: always force a state reprogram on init
    (stable-fixes).
  - drm/amdgpu: align pp_power_profile_mode with kernel docs
    (stable-fixes).
  - commit 1d64229

++++ kernel-rt:

  - atm: idt77252: prevent use after free in dequeue_rx()
    (CVE-2024-44998 bsc#1230171).
  - commit fd57936
  - tcp: add sanity checks to rx zerocopy (CVE-2024-26640
    bsc#1221650).
  - commit 21286c2
  - USB: serial: option: add MeiG Smart SRM825L (git-fixes).
  - commit 047a639
  - nilfs2: fix state management in error path of log writing
    function (git-fixes).
  - commit 9b55988
  - cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
    (git-fixes).
  - commit a322b71
  - usb: dwc3: core: Prevent USB core invalid event buffer address
    access (git-fixes).
  - commit de7b6b3
  - nilfs2: fix missing cleanup on rollforward recovery error
    (git-fixes).
  - commit b4149d3
  - nilfs2: protect references to superblock parameters exposed
    in sysfs (git-fixes).
  - commit e7215f6
  - arm64: tlb: Allow range operation for MAX_TLBI_RANGE_PAGES (bsc#1229585)
  - commit a52467b
  - arm64: tlb: Improve __TLBI_VADDR_RANGE() (bsc#1229585)
  - commit 26752eb
  - arm64: tlb: Fix TLBI RANGE operand (bsc#1229585)
  - commit 24bd468
  - arm64/mm: Update tlb invalidation routines for FEAT_LPA2 (bsc#1229585)
  - commit b8ec0d4
  - arm64/mm: Modify range-based tlbi to decrement scale (bsc#1229585)
  - commit e08c708
  - USB: serial: option: add MeiG Smart SRM825L (stable-fixes).
  - cdc-acm: Add DISABLE_ECHO quirk for GE HealthCare UI Controller
    (stable-fixes).
  - usb: dwc3: core: Prevent USB core invalid event buffer address
    access (stable-fixes).
  - selinux,smack: don't bypass permissions check in inode_setsecctx
    hook (stable-fixes).
  - drm/amdgpu/swsmu: always force a state reprogram on init
    (stable-fixes).
  - drm/amdgpu: align pp_power_profile_mode with kernel docs
    (stable-fixes).
  - commit 1d64229

++++ libXi:

  - Update to version 1.8.2
    * This release includes fixes for malloc failures and a double
    alignment issue on some machines. XFreeDeviceInfo can now be
    called with NULL and XGetFeedbackControl is more robust in
    the face of a malicious X server sending random data. Plus a
    typo fix in the man page.

++++ expat:

  - Update to 2.6.3:
    * Security fixes:
  - CVE-2024-45490, bsc#1229930 -- Calling function XML_ParseBuffer with
    len < 0 without noticing and then calling XML_GetBuffer
    will have XML_ParseBuffer fail to recognize the problem
    and XML_GetBuffer corrupt memory.
    With the fix, XML_ParseBuffer now complains with error
    XML_ERROR_INVALID_ARGUMENT just like sibling XML_Parse
    has been doing since Expat 2.2.1, and now documented.
    Impact is denial of service to potentially artitrary code
    execution.
  - CVE-2024-45491, bsc#1229931 -- Internal function dtdCopy can have an
    integer overflow for nDefaultAtts on 32-bit platforms
    (where UINT_MAX equals SIZE_MAX).
    Impact is denial of service to potentially artitrary code
    execution.
  - CVE-2024-45492, bsc#1229932 -- Internal function nextScaffoldPart can
    have an integer overflow for m_groupSize on 32-bit
    platforms (where UINT_MAX equals SIZE_MAX).
    Impact is denial of service to potentially artitrary code
    execution.
    * Other changes:
  - Autotools: Sync CMake templates with CMake 3.28
  - Autotools: Always provide path to find(1) for portability
  - Autotools: Ensure that the m4 directory always exists.
  - Autotools: Simplify handling of SIZEOF_VOID_P
  - Autotools: Support non-GNU sed
  - Autotools|CMake: Fix main() to main(void)
  - Autotools|CMake: Fix compile tests for HAVE_SYSCALL_GETRANDOM
  - Autotools|CMake: Stop requiring dos2unix
  - CMake: Fix check for symbols size_t and off_t
  - docs|tests: Convert README to Markdown and update
  - Windows: Drop support for Visual Studio <=15.0/2017
  - Drop needless XML_DTD guards around is_param access
  - Fix typo in a code comment
  - Version info bumped from 10:2:9 (libexpat*.so.1.9.2)
    to 10:3:9 (libexpat*.so.1.9.3); see https://verbump.de/
    for what these numbers do

++++ samba:

  - Package ceph_new VFS module.
  - Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when truncated;
    (bso#15699); (bsc#1229684).

++++ qemu:

  - Spec file fixing (for properly building 9.1) and improvements:
    * [openSUSE][RPM] Consolidate disabling all features during 'configure' in a macro
    * [openSUSE][RPM] Consolidate handling of conditional features
    * [openSUSE][RPM] (commented out) services for qemu-pr-helper
    * [openSUSE][RPM] package qemu-vmsr-helper
    * [openSUSE][RPM] configure: Fix with-pkgversion option
    * [openSUSE][RPM] Exclude riscv edk2 files
    * [openSUSE][RPM] Remove nios2
    * [openSUSE][RPM] Update tests acpi path
    * [openSUSE][RPM] configure: remove options for removed features
  - Update to version 9.1.0:
    Full changelog here: https://wiki.qemu.org/ChangeLog/9.1
    Some of the most notable features:
    * migration: compression offload support via Intel In-Memory Analytics
    Accelerator (IAA) or User Space Accelerator Development Kit (UADK),
    along with enhanced support for postcopy failure recovery
    * virtio: support for VIRTIO_F_NOTIFICATION_DATA, allowing guest
    drivers to provide additional data as part of sending device notifications
    for performance/debug purposes
    * guest-agent: support for guest-network-get-route command on linux,
    guest-ssh-* commands on Windows, and enhanced CLI support for
    configuring allowed/blocked commands
    * block: security fixes for QEMU NBD server and NBD TLS encryption
    * ARM: emulation support for FEAT_NMI, FEAT_CSV2_3, FEAT_ETS2,
    FEAT_Spec_FPACC, FEAT_WFxT, FEAT_Debugv8p8 architecture features
    * ARM: nested/two-stage page table support for emulated SMMUv3
    * ARM: xilinx_zynq board support for cache controller and multiple
    CPUs, and B-L475E-IOT01A board support for a DM163 display
    * LoongArch: support for directly booting an ELF kernel and for running
    up to 256 vCPUs via extioi virt extension
    * LoongArch: enhanced debug/GDB support
    * RISC-V: support for version 1.13 of privileged architecture specification
    * RISC-V: support for Zve32x, Zve64x, Zimop, Zcmop, Zama16b, Zabha,
    Zawrs, and Smcntrpmf extensions
    * RISC-V: enhanced debug/GDB support and general fixes
    * SPARC: emulation support for FMAF, IMA, VIS3, and VIS4 architecture
    features
    * x86: KVM support for running AMD SEV-SNP guests
    * x86: CPU emulation support for Icelake-Server-v7, SapphireRapids-v3,
    and SierraForest
    The following bugs/CVEs were solved (in 9.0.x) with backports that are
    now included in 9.1 upstream:
  - CVE-2024-4467 (bsc#1227322)
  - CVE-2024-7409 (bsc#1229007)

++++ rsync:

  - Add rsyncd-return-from-list-command-with-0.patch to not treat #list as failure

++++ suse-module-tools:

  - Update to version 16.0.51:
    * Improve handling of /boot/vmlinuz and /boot/initrd symlinks
    (boo#1207703)
    * Add preliminary support for mkosi-initrd
    * spec file: remove redundant dependency on sdbootutil

++++ vim:

  - Update to 9.1.0718:
    * v9.1.0718: hard to know the users personal Vim Runtime Directory
    * v9.1.0717: Unnecessary nextcmd NULL checks in parse_command_modifiers()
    Maintainers: fix typo in author name
    * v9.1.0716: resetting setcellwidth( doesn't update the screen
    runtime(hcl,terraform): Add runtime files for HCL and Terraform
    runtime(tmux): Update syntax script
    * v9.1.0715: Not correctly parsing color names (after v9.1.0709)
    * v9.1.0714: GuiEnter_Turkish test may fail
    * v9.1.0713: Newline causes E749 in Ex mode
    * v9.1.0712: missing dependency of Test_gettext_makefile
    * v9.1.0711: test_xxd may file when using different xxd
    * v9.1.0710: popup window may hide part of Command line
    runtime(vim): Update syntax, improve user-command matching
    * v9.1.0709: GUIEnter event not found in Turkish locale
    runtime(sudoers): improve recognized Runas_Spec and Tag_Spec items
    * v9.1.0708: Recursive window update does not account for reset skipcol
    runtime(nu): include filetype plugin
    * v9.1.0707: invalid cursor position may cause a crash
    * v9.1.0706: test_gettext fails when using shadow dir
    CI: Install locales-all package
    * v9.1.0705: Sorting of fuzzy filename completion is not stable
    translation(pt): update Portuguese/Brazilian menu translation
    runtime(vim): Update base-syntax, match bracket mark ranges
    runtime(doc): Update :help :command-complete list
    * v9.1.0704: inserting with a count is inefficient
    runtime(doc): use mkdir -p to save a command
    * v9.1.0703: crash with 2byte encoding and glob2regpat()
    runtime(hollywood): update syn highlight for If-Then statements
    and For-In-Loops
    * v9.1.0702: Patch 9.1.0700 broke CI
    * v9.1.0701: crash with NFA regex engine when searching for
    composing chars
    * v9.1.0700: crash with 2byte encoding and glob2regpat()
    * v9.1.0699: "dvgo" is not always an inclusive motion
    runtime(java): Provide support for syntax preview features
    * v9.1.0698: "Untitled" file not removed when running Test_crash1_3
    alone
    * v9.1.0697: heap-buffer-overflow in ins_typebuf
    * v9.1.0696: installing runtime files fails when using SHADOWDIR
    runtime(doc): fix typo
    * v9.1.0695: test_crash leaves Untitled file around
    translation(br): Update Brazilian translation
    translation(pt): Update menu_pt_br
    * v9.1.0694: matchparen is slow on a long line
    * v9.1.0693: Configure doesn't show result when not using python3
    stable abi
    * v9.1.0692: Wrong patlen value in ex_substitute()
    * v9.1.0691: stable-abi may cause segfault on Python 3.11
    runtime(vim): Update base-syntax, match :loadkeymap after colon and bar
    runtime(mane): Improve <Plug>ManBS mapping
    * v9.1.0690: cannot set special highlight kind in popupmenu
    translation(pt): Revert and fix wrong Portuguese menu translation
    files
    translation(pt): revert Portuguese menu translation
    translation(br): Update Brazilian translations
    runtime(vim): Update base-syntax, improve :let-heredoc highlighting
    * v9.1.0689: buffer-overflow in do_search( with 'rightleft'
    runtime(vim): Improve heredoc handling for all embedded scripts
    * v9.1.0688: dereferences NULL pointer in check_type_is_value()
    * v9.1.0687: Makefile may not install desktop files
    runtime(man): Fix <Plug>ManBS
    runtime(java): Make the bundled &foldtext function optional
    runtime(netrw): Change line on `mx` if command output exists
    runtime(netrw): Fix `mf`-selected entry highlighting
    runtime(htmlangular): add html syntax highlighting
    translation(it): Fix filemode of Italian manpages
    runtime(doc): Update outdated man.vim plugin information
    runtime(zip): simplify condition to detect MS-Windows
    * v9.1.0686: zip-plugin has problems with special characters
    runtime(pandoc): escape quotes in &errorformat for pandoc
    translation(it): updated Italian manpage
    * v9.1.0685: too many strlen( calls in usercmd.c
    runtime(doc): fix grammar in :h :keeppatterns
    runtime(pandoc): refine pandoc compiler settings
    * v9.1.0684: completion is inserted on Enter with "noselect"
    translation(ru): update man pages
    * v9.1.0683: mode( returns wrong value with <Cmd> mapping
    runtime(doc): remove trailing whitespace in cmdline.txt
    * v9.1.0682: Segfault with uninitialized funcref
    * v9.1.0681: Analyzing failed screendumps is hard
    runtime(doc): more clarification for the :keeppatterns needed
    * v9.1.0680: VMS does not have defined uintptr_t
    runtime(doc): improve typedchar documentation for KeyInputPre autocmd
    runtime(dist): verify that executable is in $PATH
    translation(it): update Italian manpages
    runtime(doc): clarify the effect of :keeppatterns after * v9.1.0677
    runtime(doc): update Makefile and make it portable between GNU and BSD
    * v9.1.0679: Rename from w_closing to w_locked is incomplete
    runtime(colors): update colorschemes
    runtime(vim): Update base-syntax, improve :let-heredoc highlighting
    runtime(doc): Updating the examples in the xxd manpage
    translation(ru): Updated uganda.rux
    runtime(yaml): do not re-indent when commenting out lines
    * v9.1.0678: use-after-free in alist_add()
    * v9.1.0677 :keepp does not retain the substitute pattern
    translation(ja): Update Japanese translations to latest release
    runtime(netrw): Drop committed trace lines
    runtime(netrw): Error popup not always used
    runtime(netrw): ErrorMsg( may throw E121
    runtime(tutor): update Makefile and make it portable between GNU and BSD
    translation: improve the po/cleanup.vim script
    runtime(lang): update Makefile and make it portable between GNU and BSD
    * v9.1.0676: style issues with man pages
    * v9.1.0675: Patch v9.1.0674 causes problems
    runtime(dosbatch): Show %%i as an argument in syntax file
    runtime(dosbatch): Add syn-sync to syntax file
    runtime(sql, mysql): fix E169: Command too recursive with
    sql_type_default = "mysql"
    * v9.1.0674: compiling abstract method fails because of missing return
    runtime(javascript): fix a few issues with syntax higlighting
    runtime(mediawiki): fix typo in doc, test for b:did_ftplugin var
    runtime(termdebug): Fix wrong test for balloon feature
    runtime(doc): Remove mentioning of the voting feature
    runtime(doc): add help tags for json + markdown global variables
    * v9.1.0673: too recursive func calls when calling super-class method
    runtime(syntax-tests): Facilitate the viewing of rendered screendumps
    runtime(doc): fix a few style issues
    * v9.1.0672: marker folds may get corrupted on undo
    * v9.1.0671 Problem:  crash with WinNewPre autocommand
    * v9.1.0670: po file encoding fails on *BSD during make
    translation(it): Update Italian translation
    translation: Stop using msgconv
    * v9.1.0669: stable python ABI not used by default
    Update .gitignore and .hgignore files
    * v9.1.0668: build-error with python3.12 and stable ABI
    translations: Update generated po files
    * v9.1.0667: Some other options reset curswant unnecessarily when set
    * v9.1.0666: assert_equal( doesn't show multibyte string correctly
    runtime(doc): clarify directory of Vim's executable vs CWD
    * v9.1.0665 :for loop
    runtime(proto): Add indent script for protobuf filetype
    * v9.1.0664: console vim did not switch back to main screen on exit
    runtime(zip): zip plugin does not work with Vim 9.0
    * v9.1.0663: zip test still resets 'shellslash' option
    runtime(zip): use defer to restore old settings
    runtime(zip): add a generic Message function
    runtime(zip): increment base version of zip plugin
    runtime(zip): raise minimum Vim version to * v9.0
    runtime(zip): refactor save and restore of options
    runtime(zip): remove test for fnameescape
    runtime(zip): use :echomsg instead of :echo
    runtime(zip): clean up and remove comments
    * v9.1.0662: filecopy( may return wrong value when readlink( fails
    * v9.1.0661: the zip plugin is not tested.
    runtime(zip): Fix for FreeBSD's unzip command
    runtime(doc): capitalize correctly
    * v9.1.0660: Shift-Insert does work on old conhost
    translation(it): update Italian manpage
    runtime(lua): add/subtract a 'shiftwidth' after '('/')' in indentexpr
    runtime(zip): escape '[' on Unix as well
    * v9.1.0659: MSVC Makefile is a bit hard to read
    runtime(doc): fix typo in syntax.txt
    runtime(doc): -x is only available when compiled with crypt feature
    * v9.1.0658: Coverity warns about dereferencing NULL pointer.
    runtime(colors): update Todo highlight in habamax colorscheme
    * v9.1.0657: MSVC build time can be optimized
    * v9.1.0656: MSVC Makefile CPU handling can be improved
    * v9.1.0655: goaccess config file not recognized
    CI: update clang compiler to version 20
    runtime(netrw): honor `g:netrw_alt{o,v}` for `:{S,H,V}explore`
    * v9.1.0654: completion does not respect completeslash with fuzzy
    * v9.1.0653: Patch v9.1.0648 not completely right
    * v9.1.0652: too many strlen( calls in syntax.c
    * v9.1.0651 :append
    * v9.1.0650: Coverity warning in cstrncmp()
    * v9.1.0649: Wrong comment for "len" argument of call_simple_func()
    * v9.1.0648: [security] double-free in dialog_changed()
    * v9.1.0647: [security] use-after-free in tagstack_clear_entry
    runtime(doc): re-format tag example lines, mention ctags --list-kinds
    * v9.1.0646: imported function may not be found
    runtime(java): Document "g:java_space_errors" and "g:java_comment_strings"
    runtime(java): Cluster optional group definitions and their group links
    runtime(java): Tidy up the syntax file
    runtime(java): Tidy up the documentation for "ft-java-syntax"
    runtime(colors): update habamax scheme - tweak diff/search/todo colors
    runtime(nohlsearch): add missing loaded_hlsearch guard
    runtime(kivy): Updated maintainer info for syntax script
    Maintainers: Add maintainer for ondir ftplugin + syntax files
    runtime(netrw): removing trailing slash when copying files in same
    directory
    * v9.1.0645: wrong match when searching multi-byte char case-insensitive
    runtime(html): update syntax script to sync by 250 minlines by default
    * v9.1.0644: Unnecessary STRLEN( when applying mapping
    runtime(zip): Opening a remote zipfile don't work
    runtime(cuda): source c and cpp ftplugins
    * v9.1.0643: cursor may end up on invalid position
    * v9.1.0642: Check that mapping rhs starts with lhs fails if not
    simplified
    * v9.1.0641: OLE enabled in console version
    runtime(thrift): add ftplugin, indent and syntax scripts
    * v9.1.0640: Makefile can be improved
    * v9.1.0639: channel timeout may wrap around
    * v9.1.0638: E1510 may happen when formatting a message for smsg()
    * v9.1.0637: Style issues in MSVC Makefile

------------------------------------------------------------------
------------------  2024-9-4  -  Sep 4 2024  -------------------
------------------------------------------------------------------

++++ aardvark-dns:

  - Update to version 1.12.2:
    * Release v1.12.2
    * Update release notes for 1.12.2
    * coredns: work on tcp requests concurrently
    * tcp: add timeout to connection (fixes bsc#1230153 / CVE-2024-8418)
    * cirrus: update branch names

++++ docker-compose:

  - Build with go 1.22 to avoid issues when processing go.mod per
    https://github.com/golang/go/issues/62278#issuecomment-1698829945

++++ python-kiwi:

  - create EFI/BOOT only if UEFI boot is intended
  - Fix boot support for ISO media on ppc64
    add CHRP boot support for ppc64 and add xorriso option to avoid
    file name reduction to MS-DOS compatible 8.3 format

++++ kernel-default:

  - Resort io_uring kABI patches
    These ended up in the wrong section.  Push them to the right place, next
    to the other io_uring kabi patches.
  - commit f218522
  - kABI: Split kABI out of 'io_uring: Re-add dummy_ubuf for kABI purposes'
    When introducing this patch, I merged the kABI patch with the actual
    backport, which is not recommended.  Split it up, such that the backport
    is similar to the upstream patch and handle the kABI issue exactly the
    same way, but through a separate kABI patch.
  - commit 5b3aa8f
  - kABI: Split kABI out of 'io_uring/kbuf: get rid of bl->is_ready'
    When introducing this patch, I merged the kABI patch with the actual
    backport, which is not recommended.  Split it up, such that the backport
    is similar to the upstream patch and handle the kABI issue exactly the
    same way, but through a separate kABI patch.
  - commit d39d376
  - ext4: sanity check for NULL pointer after ext4_force_shutdown
    (bsc#1229753 CVE-2024-43898).
  - commit d9361cb
  - udf: Fix bogus checksum computation in udf_rename() (bsc#1229389
    CVE-2024-43845).
  - commit 985c73e
  - ext4: fix infinite loop when replaying fast_commit (bsc#1229394
    CVE-2024-43828).
  - commit c9c168b
  - block: fix deadlock between sd_remove & sd_release (bsc#1229371
    CVE-2024-42294).
  - commit a556834
  - udf: Avoid using corrupted block bitmap buffer (bsc#1229362
    CVE-2024-42306).
  - commit 26b3a5d
  - ext4: check dot and dotdot of dx_root before making dir indexed
    (bsc#1229363 CVE-2024-42305).
  - commit d42c7e5
  - mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray
    (bsc#1229001 CVE-2024-42243).
  - commit 962c57e
  - protect the fetch of ->fd[fd] in do_dup2() from mispredictions
    (bsc#1229334 CVE-2024-42265).
  - commit 1088a58
  - ext4: make sure the first directory block is not a hole
    (bsc#1229364 CVE-2024-42304).
  - commit 0ee54f7
  - netfilter: ctnetlink: use helper function to calculate expect ID
    (CVE-2024-44944 bsc#1229899).
  - commit da9b5c6
  - sctp: Fix null-ptr-deref in reuseport_add_sock()
    (CVE-2024-44935 bsc#1229810).
  - commit c34ddb2
  - perf/x86/uncore: Cleanup unused unit structure (bsc#1230119).
  - commit 48a66a6
  - perf/x86/uncore: Apply the unit control RB tree to PCI uncore
    units (bsc#1230119).
  - commit e202e9f
  - perf/x86/uncore: Apply the unit control RB tree to MSR uncore
    units (bsc#1230119).
  - commit 8a1e34d
  - perf/x86/uncore: Apply the unit control RB tree to MMIO uncore
    units (bsc#1230119).
  - commit 956825c
  - perf/x86/uncore: Retrieve the unit ID from the unit control
    RB tree (bsc#1230119).
  - commit 81ab2f7
  - perf/x86/uncore: Support per PMU cpumask (bsc#1230119).
  - commit e0b1be5
  - perf/x86/uncore: Save the unit control address of all units
    (bsc#1230119).
  - commit 3062251
  - perf/x86/intel/uncore: Support HBM and CXL PMON counters
    (bsc#1230119).
  - commit a4c2665
  - fuse: update stats for pages in dropped aux writeback list
    (bsc#1230125).
  - fuse: fix memory leak in fuse_create_open (bsc#1230124).
  - fuse: use unsigned type for getxattr/listxattr size truncation
    (bsc#1230123).
  - commit c8902bc
  - Split kabi part of dm_blk_ioctl-implement-path-failover-for-SG_IO.patch
  - kabi: dm_blk_ioctl: implement path failover for SG_IO
    (bsc#1183045, bsc#1216776).
  - Refresh
    patches.suse/dm_blk_ioctl-implement-path-failover-for-SG_IO.patch.
  - commit 9a2ecb0
  - NFSD: Fix frame size warning in svc_export_parse() (git-fixes).
  - NFSD: Rewrite synopsis of nfsd_percpu_counters_init()
    (git-fixes).
  - commit 3ab58b8
  - kABI: Split kABI out of io_uring/kbuf: protect io_buffer_list teardown with a
    reference
    When introducing this patch, I merged the kABI patch with the actual
    backport, which is not recommended.  Split it up, such that the backport
    is similar to the upstream patch and handle the kABI issue exactly the
    same way, but through a separate kABI patch.
  - commit 08e57d6

++++ kernel-firmware-all:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-amdgpu:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-ath10k:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-ath11k:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-ath12k:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-atheros:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-bluetooth:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-bnx2:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-brcm:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-chelsio:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-dpaa2:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-i915:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-intel:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-iwlwifi:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-liquidio:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-marvell:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-media:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-mediatek:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-mellanox:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-mwifiex:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-network:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-nfp:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-nvidia:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-platform:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-prestera:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-qcom:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-qlogic:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-radeon:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-realtek:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-serial:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-sound:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-ti:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-ueagle:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-firmware-usb-network:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ kernel-rt:

  - Resort io_uring kABI patches
    These ended up in the wrong section.  Push them to the right place, next
    to the other io_uring kabi patches.
  - commit f218522
  - kABI: Split kABI out of 'io_uring: Re-add dummy_ubuf for kABI purposes'
    When introducing this patch, I merged the kABI patch with the actual
    backport, which is not recommended.  Split it up, such that the backport
    is similar to the upstream patch and handle the kABI issue exactly the
    same way, but through a separate kABI patch.
  - commit 5b3aa8f
  - kABI: Split kABI out of 'io_uring/kbuf: get rid of bl->is_ready'
    When introducing this patch, I merged the kABI patch with the actual
    backport, which is not recommended.  Split it up, such that the backport
    is similar to the upstream patch and handle the kABI issue exactly the
    same way, but through a separate kABI patch.
  - commit d39d376
  - ext4: sanity check for NULL pointer after ext4_force_shutdown
    (bsc#1229753 CVE-2024-43898).
  - commit d9361cb
  - udf: Fix bogus checksum computation in udf_rename() (bsc#1229389
    CVE-2024-43845).
  - commit 985c73e
  - ext4: fix infinite loop when replaying fast_commit (bsc#1229394
    CVE-2024-43828).
  - commit c9c168b
  - block: fix deadlock between sd_remove & sd_release (bsc#1229371
    CVE-2024-42294).
  - commit a556834
  - udf: Avoid using corrupted block bitmap buffer (bsc#1229362
    CVE-2024-42306).
  - commit 26b3a5d
  - ext4: check dot and dotdot of dx_root before making dir indexed
    (bsc#1229363 CVE-2024-42305).
  - commit d42c7e5
  - mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray
    (bsc#1229001 CVE-2024-42243).
  - commit 962c57e
  - protect the fetch of ->fd[fd] in do_dup2() from mispredictions
    (bsc#1229334 CVE-2024-42265).
  - commit 1088a58
  - ext4: make sure the first directory block is not a hole
    (bsc#1229364 CVE-2024-42304).
  - commit 0ee54f7
  - netfilter: ctnetlink: use helper function to calculate expect ID
    (CVE-2024-44944 bsc#1229899).
  - commit da9b5c6
  - sctp: Fix null-ptr-deref in reuseport_add_sock()
    (CVE-2024-44935 bsc#1229810).
  - commit c34ddb2
  - perf/x86/uncore: Cleanup unused unit structure (bsc#1230119).
  - commit 48a66a6
  - perf/x86/uncore: Apply the unit control RB tree to PCI uncore
    units (bsc#1230119).
  - commit e202e9f
  - perf/x86/uncore: Apply the unit control RB tree to MSR uncore
    units (bsc#1230119).
  - commit 8a1e34d
  - perf/x86/uncore: Apply the unit control RB tree to MMIO uncore
    units (bsc#1230119).
  - commit 956825c
  - perf/x86/uncore: Retrieve the unit ID from the unit control
    RB tree (bsc#1230119).
  - commit 81ab2f7
  - perf/x86/uncore: Support per PMU cpumask (bsc#1230119).
  - commit e0b1be5
  - perf/x86/uncore: Save the unit control address of all units
    (bsc#1230119).
  - commit 3062251
  - perf/x86/intel/uncore: Support HBM and CXL PMON counters
    (bsc#1230119).
  - commit a4c2665
  - fuse: update stats for pages in dropped aux writeback list
    (bsc#1230125).
  - fuse: fix memory leak in fuse_create_open (bsc#1230124).
  - fuse: use unsigned type for getxattr/listxattr size truncation
    (bsc#1230123).
  - commit c8902bc
  - Split kabi part of dm_blk_ioctl-implement-path-failover-for-SG_IO.patch
  - kabi: dm_blk_ioctl: implement path failover for SG_IO
    (bsc#1183045, bsc#1216776).
  - Refresh
    patches.suse/dm_blk_ioctl-implement-path-failover-for-SG_IO.patch.
  - commit 9a2ecb0
  - NFSD: Fix frame size warning in svc_export_parse() (git-fixes).
  - NFSD: Rewrite synopsis of nfsd_percpu_counters_init()
    (git-fixes).
  - commit 3ab58b8
  - kABI: Split kABI out of io_uring/kbuf: protect io_buffer_list teardown with a
    reference
    When introducing this patch, I merged the kABI patch with the actual
    backport, which is not recommended.  Split it up, such that the backport
    is similar to the upstream patch and handle the kABI issue exactly the
    same way, but through a separate kABI patch.
  - commit 08e57d6

++++ libbpf:

  - update to 1.4.6:
    * BPF skeleton forward compatibility fix (f6f2402);
    * BTF endianness inheritance bug fix (fe28fae).

++++ colord:

  - Remove script in %pre to change ownership of /var/lib/colord
    (bsc#1208056).

++++ hivex:

  - Update hivex to version 1.3.24
    * no changelog provided

++++ procps:

  - procps-ng-4.0.4-idletime-no-tty.patch: don't print idle time without tty
  - procps-ng-4.0.4-w-array-bounds.patch: fix array bounds violation

++++ rpm:

  - move perl packaging to own package
    adapt fileattrs.diff

++++ osinfo-db:

  - Add support for openSUSE Leap 15.7 (jsc#PED-8910)
    add-opensuse-leap-15.7-support.patch
  - Add support for SLE-15-SP7 (jsc#PED-8910) (bsc#1230160)
    add-sle15sp7-support.patch

++++ selinux-policy:

  - Fix macros.selinux-policy (bsc#1229132)
  - %selinux_modules_install and %selinux_modules_uninstall will
    now only execute load_policy if $TRANSACTIONAL_UPDATE is not set
    (aka only if they are not in a transactional system)
  - $TRANSACTIONAL_UPDATE is set here:
    https://github.com/openSUSE/transactional-update/blob/bd524d3ddfcd9aeebb7b90d3e0e8eed09b796a86/lib/Transaction.cpp#L428

++++ supermin:

  - Update to version 5.3.5 (jsc#PED-8910)
    * Fix qemu-kvm example command

++++ ucode-amd:

  - Update to version 20240903 (git commit 96af55bd3d0b):
    * amdgpu: Revert sienna cichlid dmcub firmware update (bsc#1230007)
    * iwlwifi: add Bz FW for core89-58 release
    * rtl_nic: add firmware rtl8126a-3
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)

++++ xfsprogs:

  - update to 6.10.1
  - fix C++ compilation errors in xfs_fs.h
  - ------------------------------------------------------------------

------------------------------------------------------------------
------------------  2024-9-3  -  Sep 3 2024  -------------------
------------------------------------------------------------------

++++ acpica:

  - Update to version 20240827
    * Fix the PHAT table working: ensure that the PHAT firmware health
    record offset works correctly, fix various sub-table offsets,
    prevent segmentation faults when encountering invalid device paths.
    * Fix the optional table 4-byte signature.
    * Correct the dumping of SLIC and DBG2 tables.
    * Add support for QWordPCC and DWordPCC
    * Fix the integer to hex string conversions
    * Detecting FACS in reduced HW mode and allowing setting waking
    vector thereby waking up from S3 state
    * Fixing issues with crossing page boundaries when mapping operation regions
    * Update the support for IORT, HMAT, MPAM, AEST, CEDT, SPCR etc. tables
    * Fix multiple issues with table parsing, compilation and disassembly
    * Allow for more flexibility in _DSM usage.

++++ python-kiwi:

  - Fix initrd permissions
    kiwi stored the initrd for ISO images as 600 which might
    be too restrictive. This commit makes sure the initrd is
    stored as 644 and Fixes bsc#1229257
  - Fixed ramdisk size setup
    For setting up the brd rd_size option kiwi creates
    99-brd.conf used at load time of the kernel brd driver.
    The location for the conf file is set to /etc/modprobe.d/
    However, in newer versions the location has changed to
    /usr/lib/modprobe.d/ and /etc/modprobe.d is no longer
    expected to exist. This commit makes sure /etc/modprobe.d
    is created if not present.
  - Bump version: 10.1.3 → 10.1.4

++++ gobject-introspection:

  - Update to version 1.81.4:
    + Add rpath when building the type dumper on macOS
    + Fix regression in the installation of GIRepository-2.0.typelib
  - Update to version 1.81.2:
    * Add strict mode warning for enumeration members starting with a
    number
    * Set deprecation message for signals and properties
    * Fix HTML definition lists in the documentation generator
    * Catch up with Python-Markdown 3.4 extension API changes
    * Propagate scanner errors
    * Do not break when parsing ARM SVE types in system headers
    * Pair pointer GTypes with their opaque structure
    * Fix property accessor pairing
    * Handle pid_t, etc. as their own top-level types
    * Add warning for closure annotation
    * Warn on invalid callback annotations
    * Make sure to set a GError with an invalid introspect-dump
    string
    * Move gobject-introspection tests to a submodule
    * Remove dependency on distutils.msvccompiler
    * Be more thorough about applying -Wl,--no-as-needed option
    * Documentation and build fixes

++++ haproxy:

  - Update to version 3.0.4+git0.7a59afa93: (CVE-2024-45506 boo#1229993)
    * [RELEASE] Released version 3.0.4
    * BUG/MEDIUM: mux-pt: Fix condition to perform a shutdown for writes in mux_pt_shut()
    * BUG/MINOR: Crash on O-RTT RX packet after dropping Initial pktns
    * BUG/MINOR: quic: Too shord datagram during O-RTT handshakes (aws-lc only)
    * BUG/MAJOR: mux-h2: always clear MUX_MFULL and DEM_MROOM when clearing the mbuf
    * MINOR: mux-h2: try to clear DEM_MROOM and MUX_MFULL at more places
    * BUG/MEDIUM: mux-h1: Properly handle empty message when an error is triggered
    * BUG/MINOR: quic: unexploited retransmission cases for Initial pktns.
    * BUG/MEDIUM: cli: Always release back endpoint between two commands on the mcli
    * BUG/MEDIUM: mux-pt: Never fully close the connection on shutdown
    * BUG/MINIR: proxy: Match on 429 status when trying to perform a L7 retry
    * BUG/MEDIUM: stream: Prevent mux upgrades if client connection is no longer ready
    * BUG/MEDIUM: mux-h2: Set ES flag when necessary on 0-copy data forwarding
    * MINOR: proxy: Add support of 429-Too-Many-Requests in retry-on status
    * DOC: quic: fix default minimal value for max window size
    * MEDIUM: log: relax some checks and emit diag warnings instead in lf_expr_postcheck()
    * Revert "MEDIUM: sink: don't set NOLINGER flag on the outgoing stream interface"
    * BUG/MEDIUM: init: fix fd_hard_limit default in compute_ideal_maxconn
    * MEDIUM: init: set default for fd_hard_limit via DEFAULT_MAXFD (take #2)
    * BUG/MEDIUM: queue: deal with a rare TOCTOU in assign_server_and_queue()
    * MINOR: queue: add a function to check for TOCTOU after queueing
    * MEDIUM: h1: allow to preserve keep-alive on T-E + C-L
    * MINOR: quic: Add information to "show quic" for CUBIC cc.
    * MINOR: quic: Dump TX in flight bytes vs window values ratio.
    * BUG/MEDIUM: jwt: Clear SSL error queue on error when checking the signature
    * BUG/MINOR: quic: Lack of precision when computing K (cubic only cc)
    * MEDIUM: sink: don't set NOLINGER flag on the outgoing stream interface
    * BUG/MINOR: quic: Non optimal first datagram.
    * BUG/MINOR: cli: Atomically inc the global request counter between CLI commands
    * BUG/MINOR: server: Don't warn fallback IP is used during init-addr resolution
    * BUG/MINOR: stick-table: fix crash for src_inc_gpc() without stkcounter
    * DOC: config: improve the http-keep-alive section
    * DOC: configuration: issuers-chain-path not compatible with OCSP
    * BUG/MAJOR: mux-h2: force a hard error upon short read with pending error
    * BUG/MEDIUM: ssl_sock: fix deadlock in ssl_sock_load_ocsp() on error path
    * DOC: install: don't reference removed CPU arg
    * BUG/MEDIUM: debug/cli: fix "show threads" crashing with low thread counts
    * BUG/MINOR: session: Eval L4/L5 rules defined in the default section
    * CLEANUP: quic: rename TID affinity elements
    * CLEANUP: proto: rename TID affinity callbacks
    * BUG/MEDIUM: quic: prevent crash on accept queue full
    * BUILD: listener: silence a build warning about unused value without threads
    * MINOR: proto: extend connection thread rebind API

++++ kbd:

  - Build libkeymap and create additional subpackages.

++++ kernel-default:

  - usb: typec: ucsi: Wait 20ms before reading CCI after a reset
    (git-fixes).
  - commit 26d16be

++++ kernel-firmware-all:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-amdgpu:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-ath10k:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-ath11k:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-ath12k:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-atheros:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-bluetooth:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-bnx2:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-brcm:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-chelsio:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-dpaa2:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-i915:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-intel:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-iwlwifi:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-liquidio:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-marvell:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-media:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-mediatek:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-mellanox:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-mwifiex:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-network:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-nfp:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-nvidia:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-platform:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-prestera:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-qcom:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-qlogic:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-radeon:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-realtek:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-serial:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-sound:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-ti:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-ueagle:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-firmware-usb-network:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

++++ kernel-rt:

  - usb: typec: ucsi: Wait 20ms before reading CCI after a reset
    (git-fixes).
  - commit 26d16be

++++ llvm19:

  - Enable zstd compression support again.

++++ libvirt:

  - Update to libvirt 10.7.0
  - CVE-2024-8235, bsc#1230024
  - Unconditionally disable building the interface driver
  - Remove SysV rc* compatibility symlinks
  - jsc#PED-8909
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v10-7-0-2024-09-02

++++ xxhash:

  - Add inline.patch to resolve FTBFS on gcc-14 + -Og.

++++ python-libvirt-python:

  - Update to 10.7.0
  - Add all new APIs and constants in libvirt 10.7.0
  - jsc#PED-8909

++++ runc:

  - Update to runc v1.2.0~rc3. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.0-rc.3>.
    Includes the patch for CVE-2024-45310. bsc#1230092
    [ This was only ever released for SLES and Leap. ]
  - Update to runc v1.1.14. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.1.14>.
    Includes the patch for CVE-2024-45310. bsc#1230092
  - Rebase patches:
    * 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
    * 0002-bsc1221050-seccomp-patchbpf-rename-nativeArch-linuxA.patch
    * 0003-bsc1221050-seccomp-patchbpf-always-include-native-ar.patch
    * 0004-bsc1214960-nsenter-cloned_binary-remove-bindfd-logic.patch

++++ ucode-amd:

  - Update to version 20240830 (git commit d6c600d46981):
    * amdgpu: update DMCUB to v0.0.232.0 for DCN314 and DCN351
    * qcom: vpu: restore compatibility with kernels before 6.6

------------------------------------------------------------------
------------------  2024-9-2  -  Sep 2 2024  -------------------
------------------------------------------------------------------

++++ boost-base:

  - fix compilation of compute module (gh#boostorg/uuid#166)
  - boost-compute-uuid.patch: added

++++ dpdk:

  - Update to LTS version 23.11. Some are the fixes are below,
    * app/crypto-perf: add missing op resubmission
    * app/crypto-perf: fix copy segment size
    * app/crypto-perf: fix data comparison
    * app/crypto-perf: fix encrypt operation verification
    * app/crypto-perf: fix next segment mbuf
    * app/crypto-perf: fix out-of-place mbuf size
    * app/crypto-perf: verify strdup return
    * app/dma-perf: verify strdup return
    * app/dumpcap: verify strdup return
    * app/graph: fix build reason
    * app/pdump: verify strdup return
    * app/testpmd: fix --stats-period option check
    * app/testpmd: fix GRO packets flush on timeout
    * app/testpmd: fix async flow create failure handling
    * app/testpmd: fix async indirect action list creation
    * app/testpmd: fix auto-completion for indirect action list
    * app/testpmd: fix burst option parsing
    * app/testpmd: fix crash in multi-process forwarding
    * app/testpmd: fix error message for invalid option
    * app/testpmd: fix flow modify tag typo
    * app/testpmd: hide --bitrate-stats in help if disabled
    * app/testpmd: return if no packets in GRO heavy weight mode
    * app/testpmd: verify strdup return
    * build: fix linker warnings about undefined symbols
    * build: fix reasons conflict
    * build: link static libs with whole-archive in subproject
    * build: pass cflags in subproject
    * buildtools/cmdline: fix IP address initializer
    * buildtools/cmdline: fix generated code for IP addresses
    * bus/dpaa: verify strdup return
    * bus/fslmc: verify strdup return
    * bus/vdev: fix devargs in secondary process
    * bus/vdev: verify strdup return
    * ci: update versions of actions in GHA
    * common/cnxk: fix RSS RETA configuration
    * common/cnxk: fix Tx MTU configuration
    * common/cnxk: fix VLAN check for inner header
    * common/cnxk: fix inline device pointer check
    * common/cnxk: fix link config for SDP
    * common/cnxk: fix mbox region copy
    * common/cnxk: fix mbox struct attributes
    * common/cnxk: fix memory leak in CPT init
    * common/cnxk: fix possible out-of-bounds access
    * common/cnxk: remove CN9K inline IPsec FP opcodes
    * common/cnxk: remove dead code
    * common/mlx5: fix calloc parameters
    * common/mlx5: fix duplicate read of general capabilities
    * common/mlx5: fix query sample info capability
    * common/qat: fix legacy flag
    * common/sfc_efx/base: use C11 static assert
    * config: fix CPU instruction set for cross-build
    * crypto/cnxk: fix CN9K ECDH public key verification
    * crypto/qat: fix crash with CCM null AAD pointer
    * cryptodev: remove unused extern variable
    * dma/dpaa2: fix logtype register
    * dma/idxd: verify strdup return
    * dmadev: fix calloc parameters
    * doc: add --latencystats option in testpmd guide
    * doc: add link speeds configuration in features table
    * doc: add traffic manager in features table
    * doc: fix aging poll frequency option in cnxk guide
    * doc: fix commands in eventdev test tool guide
    * doc: fix configuration in baseband 5GNR driver guide
    * doc: fix default IP fragments maximum in programmer guide
    * doc: fix typo in packet framework guide
    * doc: fix typo in profiling guide
    * doc: fix typos in cryptodev overview
    * doc: remove cmdline polling mode deprecation notice
    * doc: update link to Windows DevX in mlx5 guide
    * drivers/net: fix buffer overflow for packet types list
    * dts: fix smoke tests driver regex
    * dts: strip whitespaces from stdout and stderr
    * eal/x86: add AMD vendor check for TSC calibration
    * eal: verify strdup return
    * ethdev: fix NVGRE encap flow action description
    * event/cnxk: fix dequeue timeout configuration
    * event/cnxk: verify strdup return
    * event/dlb2: remove superfluous memcpy
    * eventdev/crypto: fix enqueueing
    * eventdev: fix Doxygen processing of vector struct
    * eventdev: fix calloc parameters
    * eventdev: improve Doxygen comments on configure struct
    * examples/ipsec-secgw: fix Rx queue ID in Rx callback
    * examples/ipsec-secgw: fix cryptodev to SA mapping
    * examples/ipsec-secgw: fix typo in error message
    * examples/ipsec-secgw: fix width of variables
    * examples/l3fwd: fix Rx over not ready port
    * examples/l3fwd: fix Rx queue configuration
    * examples/packet_ordering: fix Rx with reorder mode disabled
    * examples/qos_sched: fix memory leak in args parsing
    * examples/vhost: verify strdup return
    * gro: fix reordering of packets
    * hash: remove some dead code
    * kernel/freebsd: fix module build on FreeBSD 14
    * lib: add newline in logs
    * lib: remove redundant newline from logs
    * lib: use dedicated logtypes and macros
    * ml/cnxk: fix xstats calculation
    * net/af_xdp: fix leak on XSK configuration failure
    * net/af_xdp: fix memzone leak on config failure
    * net/bnx2x: fix calloc parameters
    * net/bnx2x: fix warnings about memcpy lengths
    * net/bnxt: fix 50G and 100G forced speed
    * net/bnxt: fix array overflow
    * net/bnxt: fix backward firmware compatibility
    * net/bnxt: fix deadlock in ULP timer callback
    * net/bnxt: fix null pointer dereference
    * net/bnxt: fix number of Tx queues being created
    * net/bnxt: fix speed change from 200G to 25G on Thor
    * net/bnxt: modify locking for representor Tx
    * net/bonding: fix flow count query
    * net/cnxk: add cookies check for multi-segment offload
    * net/cnxk: fix MTU limit
    * net/cnxk: fix Rx packet format check condition
    * net/cnxk: fix aged flow query
    * net/cnxk: fix buffer size configuration
    * net/cnxk: fix flow RSS configuration
    * net/cnxk: fix indirect mbuf handling in Tx
    * net/cnxk: fix mbuf fields in multi-segment Tx
    * net/cnxk: improve Tx performance for SW mbuf free
    * net/ena/base: fix metrics excessive memory consumption
    * net/ena/base: limit exponential backoff
    * net/ena/base: restructure interrupt handling
    * net/ena: fix fast mbuf free
    * net/ena: fix mbuf double free in fast free mode
    * net/failsafe: fix memory leak in args parsing
    * net/gve: fix DQO for chained descriptors
    * net/hns3: enable PFC for all user priorities
    * net/hns3: fix VF multiple count on one reset
    * net/hns3: fix disable command with firmware
    * net/hns3: fix reset level comparison
    * net/hns3: refactor PF mailbox message struct
    * net/hns3: refactor VF mailbox message struct
    * net/hns3: refactor handle mailbox function
    * net/hns3: refactor send mailbox function
    * net/hns3: remove QinQ insert support for VF
    * net/hns3: support new device
    * net/i40e: remove incorrect 16B descriptor read block
    * net/i40e: remove redundant judgment in flow parsing
    * net/iavf: fix crash on VF start
    * net/iavf: fix memory leak on security context error
    * net/iavf: fix no polling mode switching
    * net/iavf: remove error logs for VLAN offloading
    * net/iavf: remove incorrect 16B descriptor read block
    * net/ice: fix link update
    * net/ice: fix memory leaks
    * net/ice: fix tunnel TSO capabilities
    * net/ice: remove incorrect 16B descriptor read block
    * net/igc: fix timesync disable
    * net/ionic: fix RSS query
    * net/ionic: fix device close
    * net/ionic: fix missing volatile type for cqe pointers
    * net/ixgbe: fix memoy leak after device init failure
    * net/ixgbe: increase VF reset timeout
    * net/ixgbevf: fix RSS init for x550 NICs
    * net/mana: fix memory leak on MR allocation
    * net/mana: handle MR cache expansion failure
    * net/mana: prevent values overflow returned from RDMA layer
    * net/memif: fix crash with Tx burst larger than 255
    * net/memif: fix extra mbuf refcnt update in zero copy Tx
    * net/mlx5/hws: check not supported fields in VXLAN
    * net/mlx5/hws: enable multiple integrity items
    * net/mlx5/hws: fix ESP flow matching validation
    * net/mlx5/hws: fix VLAN inner type
    * net/mlx5/hws: fix VLAN item in non-relaxed mode
    * net/mlx5/hws: fix direct index insert on depend WQE
    * net/mlx5/hws: fix memory access in L3 decapsulation
    * net/mlx5/hws: fix port ID for root table
    * net/mlx5/hws: fix tunnel protocol checks
    * net/mlx5/hws: skip item when inserting rules by index
    * net/mlx5: fix DR context release ordering
    * net/mlx5: fix GENEVE TLV option management
    * net/mlx5: fix GENEVE option item translation
    * net/mlx5: fix HWS meter actions availability
    * net/mlx5: fix HWS registers initialization
    * net/mlx5: fix IP-in-IP tunnels recognition
    * net/mlx5: fix VLAN ID in flow modify
    * net/mlx5: fix VLAN handling in meter split
    * net/mlx5: fix age position in hairpin split
    * net/mlx5: fix async flow create error handling
    * net/mlx5: fix condition of LACP miss flow
    * net/mlx5: fix connection tracking action validation
    * net/mlx5: fix conntrack action handle representation
    * net/mlx5: fix counters map in bonding mode
    * net/mlx5: fix drop action release timing
    * net/mlx5: fix error packets drop in regular Rx
    * net/mlx5: fix flow action template expansion
    * net/mlx5: fix flow configure validation
    * net/mlx5: fix flow counter cache starvation
    * net/mlx5: fix flow tag modification
    * net/mlx5: fix indirect action async job initialization
    * net/mlx5: fix jump action validation
    * net/mlx5: fix meter policy priority
    * net/mlx5: fix modify flex item
    * net/mlx5: fix non-masked indirect list meter translation
    * net/mlx5: fix parameters verification in HWS table create
    * net/mlx5: fix rollback on failed flow configure
    * net/mlx5: fix stats query crash in secondary process
    * net/mlx5: fix sync flow meter action
    * net/mlx5: fix sync meter processing in HWS
    * net/mlx5: fix template clean up of FDB control flow rule
    * net/mlx5: fix use after free when releasing Tx queues
    * net/mlx5: fix warning about copy length
    * net/mlx5: prevent ioctl failure log flooding
    * net/mlx5: prevent querying aged flows on uninit port
    * net/mlx5: remove GENEVE options length limitation
    * net/mlx5: remove device status check in flow creation
    * net/mlx5: remove duplication of L3 flow item validation
    * net/netvsc: fix VLAN metadata parsing
    * net/nfp: fix IPsec data endianness
    * net/nfp: fix NFD3 metadata process
    * net/nfp: fix NFDk metadata process
    * net/nfp: fix Rx descriptor
    * net/nfp: fix Rx memory leak
    * net/nfp: fix calloc parameters
    * net/nfp: fix device close
    * net/nfp: fix device resource freeing
    * net/nfp: fix getting firmware VNIC version
    * net/nfp: fix initialization failure flow
    * net/nfp: fix resource leak for CoreNIC firmware
    * net/nfp: fix resource leak for PF initialization
    * net/nfp: fix resource leak for VF
    * net/nfp: fix resource leak for device initialization
    * net/nfp: fix resource leak for exit of CoreNIC firmware
    * net/nfp: fix resource leak for exit of flower firmware
    * net/nfp: fix resource leak for flower firmware
    * net/nfp: fix switch domain free check
    * net/nfp: fix uninitialized variable
    * net/nfp: free switch domain ID on close
    * net/nfp: verify strdup return
    * net/sfc: fix calloc parameters
    * net/softnic: fix include of log library
    * net/tap: do not overwrite flow API errors
    * net/tap: fix traffic control handle calculation
    * net/thunderx: fix DMAC control register update
    * net/virtio: fix vDPA device init advertising control queue
    * net/virtio: remove duplicate queue xstats
    * net/vmxnet3: fix initialization on FreeBSD
    * net/vmxnet3: ignore Rx queue interrupt setup on FreeBSD
    * net: add macros for VLAN metadata parsing
    * net: fix TCP/UDP checksum with padding data
    * pipeline: fix calloc parameters
    * rawdev: fix calloc parameters
    * rcu: fix acked token in debug log
    * rcu: use atomic operation on acked token
    * regexdev: fix logtype register
    * telemetry: fix connected clients count
    * telemetry: fix empty JSON dictionaries
    * test/cfgfile: fix typo in error messages
    * test/event: fix crash in Tx adapter freeing
    * test/event: skip test if no driver is present
    * test/mbuf: fix external mbuf case with assert enabled
    * test/power: fix typo in error message
    * test: assume C source files are UTF-8 encoded
    * test: do not count skipped tests as executed
    * test: fix probing in secondary process
    * test: verify strdup return
    * vdpa/mlx5: fix queue enable drain CQ
    * version: 23.11.1-rc2
    * vhost: fix VDUSE device destruction failure
    * vhost: fix deadlock during vDPA SW live migration
    * vhost: fix memory leak in Virtio Tx split path
    * vhost: fix virtqueue access check in VDUSE setup
    * vhost: fix virtqueue access check in datapath
    * vhost: fix virtqueue access check in vhost-user setup
  - Fix macro aarch64_machine for thunderx and aarch64 build
  - Drop building KMP as there are no Kernel modules available.
  - Drop the below patches as KNI is removed from DPDK repository
    * 0002-SLE15-SP3-compatibility-patch-for-kni.patch
    * kni-fix-build-with-Linux-6.10.patch
    * kni-fix-build-with-Linux-6.8.patch
    * preamble
  - Updated the below patch for DPDK v23.11
    * 0001-fix-cpu-compatibility.patch

++++ python-kiwi:

  - Add note about guestOS values for vmware ovftools.
  - Add note about guestOS values for vmware platform.
  - Fixed resize of dos table type on s390
    On s390, parted is used to detect the partition table type.
    In contrast to blkid the name for DOS tables is reported
    as 'msdos' and not 'dos' which impacts several conditions
    in the kiwi initrd code which checks for 'dos'. This commit
    fixes the get_partition_table_type() method to return a
    consistent table name for DOS tables. This Fixes bsc#1228729
  - Revert "remove dependency on /usr/bin/python"
    This reverts commit 15b450188483b567ca10bb459bf50ed90e905bb7.
    The change provided here entirely broke kiwi in OBS. With this
    patch applied every image build in OBS fails with the following
    message: 'line 1: /usr/sbin/kiwi: No such file or directory'
  - Bump version: 10.1.2 → 10.1.3

++++ gnutls:

  - Update to 3.8.7:
    * libgnutls: New configure option to compile out DSA support
    The --disable-dsa configure option has been added to completely
    disable DSA algorithm support.
    * libgnutls: Experimental support for X25519Kyber768Draft00 key
    exchange in TLS. For testing purposes, the hybrid post-quantum
    key exchange defined in draft-tls-westerbaan-xyber768d00 has been
    implemented using liboqs. Since the algorithm is still not finalized,
    the support of this key exchange is disabled by default and can be
    enabled with the --with-liboqs configure option.
    * Rebase patches:
  - gnutls-FIPS-140-3-references.patch
  - gnutls-FIPS-HMAC-nettle-hogweed-gmp.patch

++++ kernel-default:

  - Update config files (jsc#PED-10537).
    ppc64le: NR_CPUS=8192
    This alings with x86.
  - commit fce54e8
  - ceph: periodically flush the cap releases (bsc#1230056).
  - commit e22b6e0
  - Bluetooth: Fix usage of __hci_cmd_sync_status (git-fixes).
  - commit 1bec58d
  - Bluetooth: L2CAP: Fix deadlock (git-fixes).
  - commit 13aba13
  - net/sched: act_ct: fix skb leak and crash on ooo frags
    (CVE-2023-52610 bsc#1221610).
  - commit 7a32533
  - bluetooth/l2cap: sync sock recv cb and release (bsc#1228576
    CVE-2024-41062).
  - commit 6553526
  - mm: prevent derefencing NULL ptr in pfn_section_valid()
    (git-fixes).
  - commit 35f619d
  - mm, kmsan: fix infinite recursion due to RCU critical section
    (git-fixes).
  - commit 16ad73a
  - mm/sparsemem: fix race in accessing memory_section->usage
    (bsc#1221326 CVE-2023-52489).
  - commit 6aa8957
  - net: mana: Fix race of mana_hwc_post_rx_wqe and new hwc response (git-fixes).
  - commit 4dc1da1

++++ kernel-rt:

  - Update config files (jsc#PED-10537).
    ppc64le: NR_CPUS=8192
    This alings with x86.
  - commit fce54e8
  - ceph: periodically flush the cap releases (bsc#1230056).
  - commit e22b6e0
  - Bluetooth: Fix usage of __hci_cmd_sync_status (git-fixes).
  - commit 1bec58d
  - Bluetooth: L2CAP: Fix deadlock (git-fixes).
  - commit 13aba13
  - net/sched: act_ct: fix skb leak and crash on ooo frags
    (CVE-2023-52610 bsc#1221610).
  - commit 7a32533
  - bluetooth/l2cap: sync sock recv cb and release (bsc#1228576
    CVE-2024-41062).
  - commit 6553526
  - mm: prevent derefencing NULL ptr in pfn_section_valid()
    (git-fixes).
  - commit 35f619d
  - mm, kmsan: fix infinite recursion due to RCU critical section
    (git-fixes).
  - commit 16ad73a
  - mm/sparsemem: fix race in accessing memory_section->usage
    (bsc#1221326 CVE-2023-52489).
  - commit 6aa8957
  - net: mana: Fix race of mana_hwc_post_rx_wqe and new hwc response (git-fixes).
  - commit 4dc1da1

++++ cairo:

  - Update to version 1.18.2:
    + The malloc-stats code has been removed from the tests directory
    the canonical location for it is:
    https://github.com/behdad/malloc-stats
    + Cairo now requires a version of pixman equal to, or newer than,
    0.40.
    + There have been multiple build fixes for newer versions of GCC
    for MSVC; for Solaris; and on macOS 10.7.
    + PNG errors caused by loading malformed data are correctly
    propagated to callers, so they can handle the case.
    + Both stroke and fill colors are now set when showing glyphs on
    a PDF surface.
    + All the font options are copied when creating a fallback font
    object.
    + When drawing text on macOS, Cairo now tries harder to select
    the appropriate font name.
    + Cairo now prefers the COLRv1 table inside a font, if one is
    available.
    + Cairo requires a C11 toolchain when building.

++++ ncurses:

  - Add ncurses patch 20240831
    + build-fix for a case in msys2 where gettimeofday() was available but
    the fallback was partly configured.
    > patch by Rafael Kitover:
    + separate the _NC_WINDOWS platform macro into _NC_WINDOWS_NATIVE,
    for MinGW and other native Win32 support, and _NC_WINDOWS, to make
    some Win32 features available under the Cygwin runtime, in this case
    the term-driver.
    + make some minor adjustments to allow
    ./configure --enable-term-driver
    to also work on Cygwin platforms such as Cygwin and MSYS2.

++++ libpcap:

  - Update to 1.10.5:
    * Security fixes:
  - [bsc#1230020, CVE-2023-7256] double free via addrinfo in sock_initaddress()
  - [bsc#1230034, CVE-2024-8006] null pointer derefence in pcap_findalldevs_ex()
    * Thread safety: Make some static variables thread-local
    * Packet filtering:
  - Return an error from pcap_compile() if the scanner fails to initialize.
  - Optimizer fix from Archit Shah to recompute dominators after moving
    code; (although the resulting filter isn't empty).
  - Optimizer fix from Archit Shah to mark value as unknown when store
    of that value is deleted.
    * Linux:
  - Don't use DLT_LINUX_SLL2 for anything other than the "any" device.
  - Avoid 32-bit unsigned integer overflow in USB captures.
  - Fix a file descriptor leak.
  - Fix DLT_CAN_SOCKETCAN handling of CAN FD.
  - Add CAN XL support to DLT_CAN_SOCKETCAN.
  - Clean up the code that sets the "real" ("original") length for
    isochronous USB transfers.
  - Avoid unnecessary blocking on recvmsg() in the Bluetooth monitor and
    Bluetoth modules.
    * Haiku:
  - Report non-existent devices correctly.
  - Fix handling of packet statistics.
  - Fix packet timestamping.
  - Fix packet filtering with low snaplen.
  - Improve connection status reporting.
  - Add support for promiscuous mode.
  - Detect DLTs and loopback capture support at run time.
  - Report IEEE 802.11 as PCAP_IF_WIRELESS.
    * BSD, macOS, AIX, Solaris 11, Linux:
  - Add a new error PCAP_ERROR_CAPTURE_NOTSUP, for use if a capture
    mechanism is not present, in the hopes that, for example,
    attempts to capture on Windows Services for Linux 1, in which
    the NT kernel attempts to simulate Linux system calls but does
    not support packet sockets, can get an error that better
    indicates the underlying problem.
    * AirPcap: Format an error message if we run out of memory.
    * nflog: Make sure we don't overflow when rounding up the TLV length.
    * rpcap:
  - Handle routines removed in at least some OpenSSL libraries.
  - CVE-2023-7256: Clean up sock_initaddress() and its callers to avoid
    double frees in some cases.
  - Don't define SOCKET ourselves; instead, define PCAP_SOCKET as int
    on UN*Xes and as SOCKET on Windows.
  - CVE-2024-8006: Fix pcap_findalldevs_ex() not to crash if passed a
    file:// URL with a path to a directory that cannot be opened.
    * Savefiles:
  - Handle DLT_/LINKTYPE_ mapping better, to handle some
    OpenBSD-specific link types better.
  - Treat if_tsoffset as signed in pcapng files, as the spec says.
  - Don't try to fix the "real" length for isochronous USB
    transfers if the number of USB descriptors is too large.
  - Reject pcap files where one of the reserved fields in the
    "link-layer type plus other stuff" is non-zero.
    * Rebase libpcap-1.0.0-s390.patch

++++ python313-core:

  - Add gh120226-fix-sendfile-test-kernel-610.patch to avoid
    failing test_sendfile_close_peer_in_the_middle_of_receiving
    tests on Linux >= 6.10 (GH-120227).

++++ xmlsec1:

  - Update to 1.2.41:
    * (xmlsec-mscng,xmlsec-mscrypto) Improved certificates verification.
    * (xmlsec-gnutls) Added support for self-signed certificates.
    * (xmlsec-core) Fix deprecated functions in LibXML2 2.13.1
    including disabling HTTP support by default
    (use '--enable-http' option to re-enable it).

++++ python313:

  - Add gh120226-fix-sendfile-test-kernel-610.patch to avoid
    failing test_sendfile_close_peer_in_the_middle_of_receiving
    tests on Linux >= 6.10 (GH-120227).

++++ rust-keylime:

  - Update vendored crates (bsc#1229952, bsc#1230029, CVE-2024-43806)
    * rustix 0.37.25
    * rustix 0.38.34
    * shlex  1.3.0
  - Update to version 0.2.6+13:
    * Enable test functional/iak-idevid-persisted-and-protected
    * build(deps): bump uuid from 1.7.0 to 1.10.0
    * build(deps): bump openssl from 0.10.64 to 0.10.66
    * keylime-agent/src/revocation: Fix comment indentation
    * keylime/crypto: Fix indentation of documentation comment
    * build(deps): bump thiserror from 1.0.59 to 1.0.63
    * build(deps): bump serde_json from 1.0.116 to 1.0.120
    * dependabot: Extend to also monitor workflow actions
    * ci: Disable Packit CI on CentOS Stream 9
    * ci: use CODECOV_TOKEN when submitting coverage data
    * revocation: Use into() for unfallible transformation
    * secure_mount: Fix possible infinite loop
    * error: Rename enum variants to avoid clippy warning

++++ timezone:

  - Split tzselect script into a subpackage to prevent awk getting into minimal
    containers and recommend tzselect by the main package
    Fixes bsc#1230054

------------------------------------------------------------------
------------------  2024-9-1  -  Sep 1 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix bundle extension for archive types
    When bundling result files that uses an archive type like
    tbz or docker, kiwi creates them with the extension tar.xz/tar.gz
    The bundler code only uses the extension from the last tuple
    in a "." split which is wrong for "tar." filenames. This commit
    adds an exception to the prefix rule for this output filenames
    and Fixes #2628
  - Fix ImageSystem mount procedure
    The mount() method did not take custom partitions into account.
    This commit fixes it. This Fixes #2619

++++ kernel-default:

  - xfs: Fix missing interval for missing_owner in xfs fsmap
    (git-fixes).
  - commit 5448ab5
  - xfs: use XFS_BUF_DADDR_NULL for daddrs in getfsmap code
    (git-fixes).
  - commit 288ad9b
  - xfs: Fix the owner setting issue for rmap query in xfs fsmap
    (git-fixes).
  - commit 49b5eec
  - usb: cdnsp: fix for Link TRB with TC (git-fixes).
  - usb: dwc3: st: add missing depopulate in probe error path
    (git-fixes).
  - usb: dwc3: st: fix probed platform device ref count on probe
    error path (git-fixes).
  - usb: core: sysfs: Unmerge @usb3_hardware_lpm_attr_group in
    remove_power_attributes() (git-fixes).
  - usb: typec: fsa4480: Relax CHIP_ID check (git-fixes).
  - usb: dwc3: omap: add missing depopulate in probe error path
    (git-fixes).
  - usb: cdnsp: fix incorrect index in cdnsp_get_hw_deq function
    (git-fixes).
  - soc: qcom: pmic_glink: Actually communicate when remote goes
    down (git-fixes).
  - soc: qcom: cmd-db: Map shared memory as WC, not WB (git-fixes).
  - commit 7121142

++++ kernel-rt:

  - xfs: Fix missing interval for missing_owner in xfs fsmap
    (git-fixes).
  - commit 5448ab5
  - xfs: use XFS_BUF_DADDR_NULL for daddrs in getfsmap code
    (git-fixes).
  - commit 288ad9b
  - xfs: Fix the owner setting issue for rmap query in xfs fsmap
    (git-fixes).
  - commit 49b5eec
  - usb: cdnsp: fix for Link TRB with TC (git-fixes).
  - usb: dwc3: st: add missing depopulate in probe error path
    (git-fixes).
  - usb: dwc3: st: fix probed platform device ref count on probe
    error path (git-fixes).
  - usb: core: sysfs: Unmerge @usb3_hardware_lpm_attr_group in
    remove_power_attributes() (git-fixes).
  - usb: typec: fsa4480: Relax CHIP_ID check (git-fixes).
  - usb: dwc3: omap: add missing depopulate in probe error path
    (git-fixes).
  - usb: cdnsp: fix incorrect index in cdnsp_get_hw_deq function
    (git-fixes).
  - soc: qcom: pmic_glink: Actually communicate when remote goes
    down (git-fixes).
  - soc: qcom: cmd-db: Map shared memory as WC, not WB (git-fixes).
  - commit 7121142

++++ gpgme:

  - add python313.patch to enable python 3.13 building

------------------------------------------------------------------
------------------  2024-8-31  -  Aug 31 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - dmaengine: dw: Add memory bus width verification (git-fixes).
  - dmaengine: dw: Add peripheral bus width verification
    (git-fixes).
  - soundwire: stream: fix programming slave ports for non-continous
    port maps (git-fixes).
  - commit b7e9784

++++ kernel-rt:

  - dmaengine: dw: Add memory bus width verification (git-fixes).
  - dmaengine: dw: Add peripheral bus width verification
    (git-fixes).
  - soundwire: stream: fix programming slave ports for non-continous
    port maps (git-fixes).
  - commit b7e9784

++++ at-spi2-core:

  - Update to version 2.53.90:
    + Make ATSPI_ROLE_PUSH_BUTTON an enum value again.
    + atk: Align button role with AT-SPI one.
    + Fix warning when atspi_event_quit is called multiple times.

++++ libfido2:

  - update to 1.15.0:
    * bio, credman: improved CTAP 2.1 support.
    * hid_osx: fix issue where fido_hid_read() may block
    unnecessarily; gh#757.
    * fido2-token -I: print maxcredbloblen.
    * hid_linux: improved support for uhid devices.
    * New API calls:
  - fido_cred_set_attobj;
  - fido_cred_x5c_list_count;
  - fido_cred_x5c_list_len;
  - fido_cred_x5c_list_ptr.

++++ libjpeg-turbo:

  - update to 3.0.3:
    * The x86-64 SIMD extensions now include support for Intel
    Control-flow Enforcement Technology (CET), which is enabled
    automatically if CET is enabled in the C compiler.
    * Fixed a regression introduced by 3.0 beta2[6] that made it
    impossible for calling applications to supply custom Huffman
    tables when generating 12-bit-per-component lossy JPEG images
    using the libjpeg API.
    * Fixed a segfault that occurred when attempting to use the
    jpegtran `-drop` option with a specially-crafted malformed
    input image or drop image (specifically an image in which all
    of the scans contain fewer components than the number of
    components specified in the Start Of Frame segment.)

++++ python-cffi:

  - update to 1.17.0:
    * Add support for Python 3.13.
    * In API mode, when you get a function from a C library by writing
    `fn = lib.myfunc`, you get an object of a special type for
    performance reasons, instead of a `<cdata 'C-function-type'>`.
    Before version 1.17 you could only call such objects.
    You could write `ffi.addressof(lib, "myfunc")` in order to get
    a real `<cdata>` object, based on the idea that in these cases
    in C you'd usually write `&myfunc` instead of `myfunc`.  In
    version 1.17, the special object `lib.myfunc` can now be passed
    in many places where CFFI expects
    a regular `<cdata>` object.  For example, you can now pass
    it as a callback to a C function call, or write it inside a C
    structure field of the correct pointer-to-function type, or use
    `ffi.cast()` or `ffi.typeof()` on it.
  - drop py313-compat.patch, py313-use-format-unraisable.patch,
    py313-use-hashpointer.patch (upstream)

++++ python313-pyparsing:

  - update to 3.1.4:
    * Fix to type annotation that referenced `re.Pattern`. Since
    this type was introduced in Python 3.7, using this type
    definition broke Python 3.6 installs of pyparsing.
    * Added new `Tag` ParserElement, for inserting metadata into
    the parsed results.
    This allows a parser to add metadata or annotations to the
    parsed tokens.
    * The `Tag` element also accepts an optional `value`
    parameter, defaulting to `True`.
    See the new `tag_metadata.py` example in the `examples`
    directory.
    * Fixed issue where PEP8 compatibility names for
    `ParserElement` static methods were
    not themselves defined as `staticmethods`. When called
    using a `ParserElement` instance, this resulted  in a
    `TypeError` exception.
    * To address a compatibility issue in RDFLib, added a property
    setter for the `ParserElement.name` property, to call
    `ParserElement.set_name`.
    * Modified `ParserElement.set_name()` to accept a None value,
    to clear the defined name and corresponding error message for
    a `ParserElement`.
    * Updated railroad diagram generation for `ZeroOrMore` and
    `OneOrMore` expressions with `stop_on` expressions, while
    investigating #558
    * Added exception type to `trace_parse_action` exception
    output, while investigating SO question posted by medihack.
    * Added `set_name` calls to internal expressions generated in
    `infix_notation`, for improved railroad diagramming.
    * Fixed bug (and corresponding test code) in `delta_time`
    example that did not handle weekday references in time
    expressions
    * Minor performance speedup in `trim_arity`, to benefit any
    parsers using parse actions.
    * Added early testing support for Python 3.13 with JIT enabled.

------------------------------------------------------------------
------------------  2024-8-30  -  Aug 30 2024  -------------------
------------------------------------------------------------------

++++ boost-base:

  - update to 1.86.0
    * process turned into compile library
    * for details on all changes see,
    https://www.boost.org/users/history/version_1_86_0.html
  - boost-aarch64-flags.patch: updated
  - boost-1.57.0-python-abi_letters.patch: updated
  - boost-process.patch: removed (included upstream)
  - boost-charconv-quadmath.patch: removed (improved upstream)

++++ cryptsetup:

  - cryptsetup-fips140-3.patch: extend the password for PBKDF2 benchmarking
    to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975)

++++ lvm2-device-mapper:

  - [SLFO] systemd 254 is missing reworked SYSTEMD_READY logic in device mapper udev rules (bsc#1229518)
    * update udev dependency version in lvm2.spec

++++ transactional-update:

  - Version 4.8.1
  - tukit: fix --drop-if-no-change after apply [bsc#1229900]

++++ ignition:

  - Drop "go clean" from the upstream build script: since we build in
    clean environments, we don't have caches. Additionally, the way
    it is used does not even work and reports:
    go: clean -cache cannot be used with package arguments
    The error was masked until GO 1.23, as the test wether go
    supported caching was checking for go 1.23 formatted output.

++++ kernel-default:

  - Update
    patches.suse/0001-net-rds-fix-possible-cp-null-dereference.patch
    (git-fixes CVE-2024-35902 bsc#1224496).
  - Update
    patches.suse/ASoC-TAS2781-Fix-tasdev_load_calibrated_data.patch
    (git-fixes CVE-2024-42278 bsc#1229403).
  - Update
    patches.suse/ASoC-amd-Adjust-error-handling-in-case-of-absent-cod.patch
    (git-fixes CVE-2024-43818 bsc#1229296).
  - Update
    patches.suse/ASoC-fsl-fsl_qmc_audio-Check-devm_kasprintf-returned.patch
    (git-fixes CVE-2024-42298 bsc#1229369).
  - Update
    patches.suse/Bluetooth-MGMT-Add-error-handling-to-pair_device.patch
    (git-fixes CVE-2024-43884 bsc#1229739).
  - Update
    patches.suse/KVM-Always-flush-async-PF-workqueue-when-vCPU-is-bei.patch
    (git-fixes CVE-2024-26976 bsc#1223635).
  - Update
    patches.suse/PCI-DPC-Fix-use-after-free-on-concurrent-DPC-and-hot.patch
    (git-fixes CVE-2024-42302 bsc#1229366).
  - Update
    patches.suse/PCI-endpoint-Clean-up-error-handling-in-vpci_scan_bu.patch
    (git-fixes CVE-2024-43875 bsc#1229486).
  - Update
    patches.suse/PCI-endpoint-pci-epf-test-Make-use-of-cached-epc_fea.patch
    (git-fixes CVE-2024-43824 bsc#1229320).
  - Update
    patches.suse/PCI-keystone-Fix-NULL-pointer-dereference-in-case-of.patch
    (git-fixes CVE-2024-43823 bsc#1229303).
  - Update
    patches.suse/PCI-rcar-Demote-WARN-to-dev_warn_ratelimited-in-rcar.patch
    (git-fixes CVE-2024-43876 bsc#1229485).
  - Update
    patches.suse/RDMA-hns-Fix-soft-lockup-under-heavy-CEQE-load.patch
    (git-fixes CVE-2024-43872 bsc#1229489).
  - Update
    patches.suse/RDMA-iwcm-Fix-a-use-after-free-related-to-destroying.patch
    (git-fixes CVE-2024-42285 bsc#1229381).
  - Update
    patches.suse/Revert-ALSA-firewire-lib-operate-for-period-elapse-e.patch
    (bsc#1208783 CVE-2024-42274 bsc#1229417).
  - Update
    patches.suse/SUNRPC-add-a-missing-rpc_stat-for-TCP-TLS.patch
    (git-fixes CVE-2024-36907 bsc#1225751).
  - Update
    patches.suse/bpf-arm64-Fix-trampoline-for-BPF_TRAMP_F_CALL_ORIG.patch
    (git-fixes CVE-2024-43840 bsc#1229344).
  - Update
    patches.suse/btrfs-fix-double-inode-unlock-for-direct-IO-sync-wri.patch
    (git-fixes CVE-2024-43885 bsc#1229747).
  - Update
    patches.suse/btrfs-fix-extent-map-use-after-free-when-adding-page.patch
    (git-fixes CVE-2024-42314 bsc#1229355).
  - Update
    patches.suse/cgroup-cpuset-Prevent-UAF-in-proc_cpuset_show.patch
    (bsc#1228801 CVE-2024-43853 bsc#1229292).
  - Update
    patches.suse/crypto-ccp-Fix-null-pointer-dereference-in-__sev_snp.patch
    (git-fixes CVE-2024-43874 bsc#1229487).
  - Update
    patches.suse/devres-Fix-memory-leakage-caused-by-driver-API-devm_.patch
    (git-fixes CVE-2024-43871 bsc#1229490).
  - Update
    patches.suse/dma-fix-call-order-in-dmam_free_coherent.patch
    (git-fixes CVE-2024-43856 bsc#1229346).
  - Update
    patches.suse/drm-admgpu-fix-dereferencing-null-pointer-context.patch
    (stable-fixes CVE-2024-43906 bsc#1229785).
  - Update
    patches.suse/drm-amd-display-Add-NULL-check-for-afb-before-derefe.patch
    (stable-fixes CVE-2024-43903 bsc#1229781).
  - Update
    patches.suse/drm-amd-display-Add-null-checker-before-passing-vari.patch
    (stable-fixes CVE-2024-43902 bsc#1229767).
  - Update
    patches.suse/drm-amd-display-Skip-Recompute-DSC-Params-if-no-Stre.patch
    (stable-fixes CVE-2024-43895 bsc#1229755).
  - Update
    patches.suse/drm-amd-pm-Fix-the-null-pointer-dereference-for-vega.patch
    (stable-fixes CVE-2024-43905 bsc#1229784).
  - Update
    patches.suse/drm-amdgpu-Fix-the-null-pointer-dereference-to-ras_m.patch
    (stable-fixes CVE-2024-43908 bsc#1229788).
  - Update
    patches.suse/drm-amdgpu-pm-Fix-the-null-pointer-dereference-for-s.patch
    (stable-fixes CVE-2024-43909 bsc#1229789).
  - Update
    patches.suse/drm-amdgpu-pm-Fix-the-null-pointer-dereference-in-ap.patch
    (stable-fixes CVE-2024-43907 bsc#1229787).
  - Update
    patches.suse/drm-client-fix-null-pointer-dereference-in-drm_clien.patch
    (git-fixes CVE-2024-43894 bsc#1229746).
  - Update
    patches.suse/drm-gma500-fix-null-pointer-dereference-in-cdv_intel.patch
    (git-fixes CVE-2024-42310 bsc#1229358).
  - Update
    patches.suse/drm-gma500-fix-null-pointer-dereference-in-psb_intel.patch
    (git-fixes CVE-2024-42309 bsc#1229359).
  - Update
    patches.suse/drm-nouveau-prime-fix-refcount-underflow.patch
    (git-fixes CVE-2024-43867 bsc#1229493).
  - Update patches.suse/drm-qxl-Add-check-for-drm_cvt_mode.patch
    (git-fixes CVE-2024-43829 bsc#1229341).
  - Update
    patches.suse/drm-vmwgfx-Fix-a-deadlock-in-dma-buf-fence-polling.patch
    (git-fixes CVE-2024-43863 bsc#1229497).
  - Update
    patches.suse/exfat-fix-potential-deadlock-on-__exfat_get_dentry_set.patch
    (git-fixes CVE-2024-42315 bsc#1229354).
  - Update
    patches.suse/gpio-prevent-potential-speculation-leaks-in-gpio_dev.patch
    (stable-fixes CVE-2024-44931 bsc#1229837).
  - Update
    patches.suse/hfs-fix-to-initialize-fields-of-hfs_inode_info-after-hfs_alloc_inode.patch
    (git-fixes CVE-2024-42311 bsc#1229413).
  - Update
    patches.suse/iio-Fix-the-sorting-functionality-in-iio_gts_build_a.patch
    (git-fixes CVE-2024-43825 bsc#1229298).
  - Update
    patches.suse/jfs-Fix-array-index-out-of-bounds-in-diFree.patch
    (git-fixes CVE-2024-43858 bsc#1229414).
  - Update
    patches.suse/jfs-Fix-shift-out-of-bounds-in-dbDiscardAG.patch
    (git-fixes CVE-2024-44938 bsc#1229792).
  - Update
    patches.suse/jfs-fix-null-ptr-deref-in-dtInsertEntry.patch
    (git-fixes CVE-2024-44939 bsc#1229820).
  - Update
    patches.suse/kobject_uevent-Fix-OOB-access-within-zap_modalias_en.patch
    (git-fixes CVE-2024-42292 bsc#1229373).
  - Update
    patches.suse/kvm-s390-Reject-memory-region-operations-for-ucontrol-VMs.patch
    (git-fixes bsc#1229168 CVE-2024-43819 bsc#1229290).
  - Update
    patches.suse/leds-trigger-Unregister-sysfs-attributes-before-call.patch
    (git-fixes CVE-2024-43830 bsc#1229305).
  - Update
    patches.suse/lib-objagg-Fix-general-protection-fault.patch
    (git-fixes CVE-2024-43846 bsc#1229360).
  - Update
    patches.suse/libbpf-Use-OPTS_SET-macro-in-bpf_xdp_query.patch
    (git-fixes CVE-2024-27050 bsc#1223767).
  - Update
    patches.suse/mISDN-Fix-a-use-after-free-in-hfcmulti_tx.patch
    (git-fixes CVE-2024-42280 bsc#1229388).
  - Update
    patches.suse/mailbox-mtk-cmdq-Move-devm_mbox_controller_register-.patch
    (git-fixes CVE-2024-42319 bsc#1229350).
  - Update
    patches.suse/md-raid5-fix-deadlock-that-raid5d-wait-for-itself-to-clear-MD_SB_CHANGE_PENDING-151f.patch
    (git-fixes CVE-2024-39476 bsc#1227437).
  - Update
    patches.suse/media-imx-pxp-Fix-ERR_PTR-dereference-in-pxp_probe.patch
    (git-fixes CVE-2024-42303 bsc#1229365).
  - Update
    patches.suse/media-pci-ivtv-Add-check-for-DMA-map-result.patch
    (git-fixes CVE-2024-43877 bsc#1229484).
  - Update
    patches.suse/media-v4l-async-Fix-NULL-pointer-dereference-in-addi.patch
    (git-fixes CVE-2024-43833 bsc#1229299).
  - Update
    patches.suse/media-venus-fix-use-after-free-in-vdec_close.patch
    (git-fixes CVE-2024-42313 bsc#1229356).
  - Update
    patches.suse/media-xc2028-avoid-use-after-free-in-load_firmware_c.patch
    (stable-fixes CVE-2024-43900 bsc#1229756).
  - Update
    patches.suse/memcg-protect-concurrent-access-to-mem_cgroup_idr.patch
    (git-fixes CVE-2024-43892 bsc#1229761).
  - Update
    patches.suse/net-drop-bad-gso-csum_start-and-offset-in-virtio_net.patch
    (git-fixes CVE-2024-43897 bsc#1229752).
  - Update
    patches.suse/net-iucv-fix-use-after-free-in-iucv_sock_close.patch
    (bsc#1228973 CVE-2024-42271 bsc#1229400).
  - Update patches.suse/net-missing-check-virtio.patch (git-fixes
    CVE-2024-43817 bsc#1229312).
  - Update
    patches.suse/net-usb-qmi_wwan-fix-memory-leak-for-not-ip-packets.patch
    (git-fixes CVE-2024-43861 bsc#1229500).
  - Update
    patches.suse/nfs-pass-explicit-offset-count-to-trace-events.patch
    (git-fixes CVE-2024-43826 bsc#1229294).
  - Update
    patches.suse/nvme-pci-add-missing-condition-check-for-existence-o.patch
    (git-fixes CVE-2024-42276 bsc#1229410).
  - Update
    patches.suse/padata-Fix-possible-divide-by-0-panic-in-padata_mt_h.patch
    (git-fixes CVE-2024-43889 bsc#1229743).
  - Update
    patches.suse/remoteproc-imx_rproc-Skip-over-memory-region-when-no.patch
    (git-fixes CVE-2024-43860 bsc#1229319).
  - Update
    patches.suse/s390-dasd-fix-error-checks-in-dasd_copy_pair_store.patch
    (git-fixes bsc#1229173 CVE-2024-42320 bsc#1229349).
  - Update
    patches.suse/scsi-lpfc-Revise-lpfc_prep_embed_io-routine-with-pro.patch
    (bsc#1228857 CVE-2024-43816 bsc#1229318).
  - Update
    patches.suse/scsi-qla2xxx-Complete-command-early-within-lock.patch
    (bsc#1228850 CVE-2024-42287 bsc#1229392).
  - Update
    patches.suse/scsi-qla2xxx-During-vport-delete-send-async-logout-e.patch
    (bsc#1228850 CVE-2024-42289 bsc#1229399).
  - Update
    patches.suse/scsi-qla2xxx-Fix-for-possible-memory-corruption.patch
    (bsc#1228850 CVE-2024-42288 bsc#1229398).
  - Update
    patches.suse/scsi-qla2xxx-validate-nvme_local_port-correctly.patch
    (bsc#1228850 CVE-2024-42286 bsc#1229395).
  - Update
    patches.suse/serial-core-check-uartclk-for-zero-to-avoid-divide-b.patch
    (stable-fixes CVE-2024-43893 bsc#1229759).
  - Update
    patches.suse/soc-qcom-pdr-protect-locator_addr-with-the-main-mute.patch
    (git-fixes CVE-2024-43849 bsc#1229307).
  - Update
    patches.suse/soc-xilinx-rename-cpu_number1-to-dummy_cpu_number.patch
    (git-fixes CVE-2024-43851 bsc#1229313).
  - Update
    patches.suse/spi-microchip-core-ensure-TX-and-RX-FIFOs-are-empty-.patch
    (git-fixes CVE-2024-42279 bsc#1229390).
  - Update
    patches.suse/usb-vhci-hcd-Do-not-drop-references-before-new-refer.patch
    (stable-fixes CVE-2024-43883 bsc#1229707).
  - Update
    patches.suse/vhost-vsock-always-initialize-seqpacket_allow.patch
    (git-fixes CVE-2024-43873 bsc#1229488).
  - Update
    patches.suse/wifi-ath12k-change-DMA-direction-while-mapping-reinj.patch
    (git-fixes CVE-2024-43881 bsc#1229480).
  - Update
    patches.suse/wifi-ath12k-fix-invalid-memory-access-while-processi.patch
    (git-fixes CVE-2024-43847 bsc#1229291).
  - Update
    patches.suse/wifi-cfg80211-handle-2x996-RU-allocation-in-cfg80211.patch
    (git-fixes CVE-2024-43879 bsc#1229482).
  - Update
    patches.suse/wifi-nl80211-disallow-setting-special-AP-channel-wid.patch
    (stable-fixes CVE-2024-43912 bsc#1229830).
  - Update
    patches.suse/wifi-rtw89-Fix-array-index-mistake-in-rtw89_sta_info.patch
    (git-fixes CVE-2024-43842 bsc#1229317).
  - Update
    patches.suse/wifi-virt_wifi-avoid-reporting-connection-success-wi.patch
    (git-fixes CVE-2024-43841 bsc#1229304).
  - commit 140ec33
  - iommu/amd: Convert comma to semicolon (git-fixes).
  - commit 2714d8b
  - scsi: lpfc: Fix a possible null pointer dereference (bsc#1229315
    CVE-2024-43821).
  - commit eb73e94
  - iommu/vt-d: Fix identity map bounds in si_domain_init()
    (git-fixes).
  - commit b4d27e5
  - iommufd/device: Fix hwpt at err_unresv in
    iommufd_device_do_replace() (git-fixes).
  - commit bbc9a65
  - virtiofs: forbid newlines in tags (bsc#1229940).
  - commit 61514ce
  - trace/pid_list: Change gfp flags in pid_list_fill_irq()
    (git-fixes).
  - commit 88d1dac
  - evm: don't copy up 'security.evm' xattr (git-fixes).
  - commit d3bb5af
  - afs: fix __afs_break_callback() / afs_drop_open_mmap() race
    (git-fixes).
  - commit 150e615
  - jfs: define xtree root and page independently (git-fixes).
  - commit fc62e49
  - kernfs: fix false-positive WARN(nr_mmapped) in
    kernfs_drain_open_files (git-fixes).
  - commit 7fa46d1
  - gfs2: setattr_chown: Add missing initialization (git-fixes).
  - commit 9b6ef3b
  - nfc: pn533: Add poll mod list filling check (git-fixes).
  - wifi: wfx: repair open network AP mode (git-fixes).
  - wifi: iwlwifi: fw: fix wgds rev 3 exact size (git-fixes).
  - wifi: mwifiex: duplicate static structs used in driver instances
    (git-fixes).
  - Input: i8042 - use new forcenorestore quirk to replace old
    buggy quirk combination (stable-fixes).
  - Input: i8042 - add forcenorestore quirk to leave controller
    untouched even on s3 (stable-fixes).
  - platform/surface: aggregator: Fix warning when controller is
    destroyed in probe (git-fixes).
  - thunderbolt: Mark XDomain as unplugged when router is removed
    (stable-fixes).
  - Input: MT - limit max slots (stable-fixes).
  - usb: dwc3: core: Skip setting event buffers for host only
    controllers (stable-fixes).
  - platform/x86: lg-laptop: fix %s null argument warning
    (stable-fixes).
  - rtc: nct3018y: fix possible NULL dereference (stable-fixes).
  - usb: gadget: fsl: Increase size of name buffer for endpoints
    (stable-fixes).
  - media: drivers/media/dvb-core: copy user arrays safely
    (stable-fixes).
  - media: pci: cx23885: check cx23885_vdev_init() return
    (stable-fixes).
  - memory: stm32-fmc2-ebi: check regmap_read return value
    (stable-fixes).
  - memory: tegra: Skip SID programming if SID registers aren't set
    (stable-fixes).
  - Revert "usb: gadget: uvc: cleanup request when not in correct
    state" (stable-fixes).
  - usb: gadget: uvc: cleanup request when not in correct state
    (stable-fixes).
  - staging: ks7010: disable bh on tx_dev_lock (stable-fixes).
  - staging: iio: resolver: ad2s1210: fix use before initialization
    (stable-fixes).
  - ssb: Fix division by zero issue in ssb_calc_clock_rate
    (stable-fixes).
  - commit b84d799
  - drm/vmwgfx: Fix prime with external buffers (git-fixes).
  - drm/i915/dsi: Make Lenovo Yoga Tab 3 X90F DMI match less strict
    (git-fixes).
  - drm/amd/display: avoid using null object of framebuffer
    (git-fixes).
  - Bluetooth: hci_core: Fix not handling hibernation actions
    (git-fixes).
  - drm/amdgpu: Validate TA binary size (stable-fixes).
  - drm/msm/dpu: take plane rotation into account for wide planes
    (git-fixes).
  - drm/msm/dpu: move dpu_encoder's connector assignment to
    atomic_enable() (git-fixes).
  - char: xillybus: Refine workqueue handling (git-fixes).
  - char: xillybus: Don't destroy workqueue from work item running
    on it (stable-fixes).
  - drm/amdgpu: Actually check flags for all context ops
    (stable-fixes).
  - drm/amdgpu/jpeg4: properly set atomics vmid field
    (stable-fixes).
  - drm/amdgpu/jpeg2: properly set atomics vmid field
    (stable-fixes).
  - drm/amd/display: fix s2idle entry for DCN3.5+ (stable-fixes).
  - drm/amdgpu: fix dereference null return value for the function
    amdgpu_vm_pt_parent (stable-fixes).
  - hwmon: (ltc2992) Fix memory leak in ltc2992_parse_dt()
    (git-fixes).
  - firmware: cirrus: cs_dsp: Initialize debugfs_root to invalid
    (stable-fixes).
  - drm/msm/dpu: capture snapshot on the first commit_done timeout
    (stable-fixes).
  - drm/msm/dpu: split dpu_encoder_wait_for_event into two functions
    (stable-fixes).
  - drm/lima: set gp bus_stop bit before hard reset (stable-fixes).
  - drm/panel: nt36523: Set 120Hz fps for xiaomi,elish panels
    (stable-fixes).
  - gpio: sysfs: extend the critical section for unregistering
    sysfs devices (stable-fixes).
  - Bluetooth: bnep: Fix out-of-bound access (stable-fixes).
  - hwmon: (pc87360) Bounds check data->innr usage (stable-fixes).
  - ASoC: SOF: ipc4: check return value of snd_sof_ipc_msg_data
    (stable-fixes).
  - drm/msm/dpu: drop MSM_ENC_VBLANK support (stable-fixes).
  - drm/msm/dpu: use drmm-managed allocation for dpu_encoder_phys
    (stable-fixes).
  - drm/msm/mdss: Rename path references to mdp_path (stable-fixes).
  - drm/msm/mdss: switch mdss to use devm_of_icc_get()
    (stable-fixes).
  - drm/msm/dpu: try multirect based on mdp clock limits
    (stable-fixes).
  - drm/msm: Reduce fallout of fence signaling vs reclaim hangs
    (stable-fixes).
  - drm/rockchip: vop2: clear afbc en and transform bit for cluster
    window at linear mode (stable-fixes).
  - Bluetooth: hci_conn: Check non NULL function before calling
    for HFP offload (stable-fixes).
  - i2c: stm32f7: Add atomic_xfer method to driver (stable-fixes).
  - i2c: riic: avoid potential division by zero (stable-fixes).
  - i3c: mipi-i3c-hci: Do not unmap region not mapped for transfer
    (stable-fixes).
  - i3c: mipi-i3c-hci: Remove BUG() when Ring Abort request times
    out (stable-fixes).
  - ASoC: SOF: Intel: hda-dsp: Make sure that no irq handler is
    pending before suspend (stable-fixes).
  - ASoC: cs35l45: Checks index of cs35l45_irqs[] (stable-fixes).
  - clk: visconti: Add bounds-checking coverage for struct
    visconti_pll_provider (stable-fixes).
  - hwmon: (ltc2992) Avoid division by zero (stable-fixes).
  - commit 1b92ddd

++++ kernel-rt:

  - Update
    patches.suse/0001-net-rds-fix-possible-cp-null-dereference.patch
    (git-fixes CVE-2024-35902 bsc#1224496).
  - Update
    patches.suse/ASoC-TAS2781-Fix-tasdev_load_calibrated_data.patch
    (git-fixes CVE-2024-42278 bsc#1229403).
  - Update
    patches.suse/ASoC-amd-Adjust-error-handling-in-case-of-absent-cod.patch
    (git-fixes CVE-2024-43818 bsc#1229296).
  - Update
    patches.suse/ASoC-fsl-fsl_qmc_audio-Check-devm_kasprintf-returned.patch
    (git-fixes CVE-2024-42298 bsc#1229369).
  - Update
    patches.suse/Bluetooth-MGMT-Add-error-handling-to-pair_device.patch
    (git-fixes CVE-2024-43884 bsc#1229739).
  - Update
    patches.suse/KVM-Always-flush-async-PF-workqueue-when-vCPU-is-bei.patch
    (git-fixes CVE-2024-26976 bsc#1223635).
  - Update
    patches.suse/PCI-DPC-Fix-use-after-free-on-concurrent-DPC-and-hot.patch
    (git-fixes CVE-2024-42302 bsc#1229366).
  - Update
    patches.suse/PCI-endpoint-Clean-up-error-handling-in-vpci_scan_bu.patch
    (git-fixes CVE-2024-43875 bsc#1229486).
  - Update
    patches.suse/PCI-endpoint-pci-epf-test-Make-use-of-cached-epc_fea.patch
    (git-fixes CVE-2024-43824 bsc#1229320).
  - Update
    patches.suse/PCI-keystone-Fix-NULL-pointer-dereference-in-case-of.patch
    (git-fixes CVE-2024-43823 bsc#1229303).
  - Update
    patches.suse/PCI-rcar-Demote-WARN-to-dev_warn_ratelimited-in-rcar.patch
    (git-fixes CVE-2024-43876 bsc#1229485).
  - Update
    patches.suse/RDMA-hns-Fix-soft-lockup-under-heavy-CEQE-load.patch
    (git-fixes CVE-2024-43872 bsc#1229489).
  - Update
    patches.suse/RDMA-iwcm-Fix-a-use-after-free-related-to-destroying.patch
    (git-fixes CVE-2024-42285 bsc#1229381).
  - Update
    patches.suse/Revert-ALSA-firewire-lib-operate-for-period-elapse-e.patch
    (bsc#1208783 CVE-2024-42274 bsc#1229417).
  - Update
    patches.suse/SUNRPC-add-a-missing-rpc_stat-for-TCP-TLS.patch
    (git-fixes CVE-2024-36907 bsc#1225751).
  - Update
    patches.suse/bpf-arm64-Fix-trampoline-for-BPF_TRAMP_F_CALL_ORIG.patch
    (git-fixes CVE-2024-43840 bsc#1229344).
  - Update
    patches.suse/btrfs-fix-double-inode-unlock-for-direct-IO-sync-wri.patch
    (git-fixes CVE-2024-43885 bsc#1229747).
  - Update
    patches.suse/btrfs-fix-extent-map-use-after-free-when-adding-page.patch
    (git-fixes CVE-2024-42314 bsc#1229355).
  - Update
    patches.suse/cgroup-cpuset-Prevent-UAF-in-proc_cpuset_show.patch
    (bsc#1228801 CVE-2024-43853 bsc#1229292).
  - Update
    patches.suse/crypto-ccp-Fix-null-pointer-dereference-in-__sev_snp.patch
    (git-fixes CVE-2024-43874 bsc#1229487).
  - Update
    patches.suse/devres-Fix-memory-leakage-caused-by-driver-API-devm_.patch
    (git-fixes CVE-2024-43871 bsc#1229490).
  - Update
    patches.suse/dma-fix-call-order-in-dmam_free_coherent.patch
    (git-fixes CVE-2024-43856 bsc#1229346).
  - Update
    patches.suse/drm-admgpu-fix-dereferencing-null-pointer-context.patch
    (stable-fixes CVE-2024-43906 bsc#1229785).
  - Update
    patches.suse/drm-amd-display-Add-NULL-check-for-afb-before-derefe.patch
    (stable-fixes CVE-2024-43903 bsc#1229781).
  - Update
    patches.suse/drm-amd-display-Add-null-checker-before-passing-vari.patch
    (stable-fixes CVE-2024-43902 bsc#1229767).
  - Update
    patches.suse/drm-amd-display-Skip-Recompute-DSC-Params-if-no-Stre.patch
    (stable-fixes CVE-2024-43895 bsc#1229755).
  - Update
    patches.suse/drm-amd-pm-Fix-the-null-pointer-dereference-for-vega.patch
    (stable-fixes CVE-2024-43905 bsc#1229784).
  - Update
    patches.suse/drm-amdgpu-Fix-the-null-pointer-dereference-to-ras_m.patch
    (stable-fixes CVE-2024-43908 bsc#1229788).
  - Update
    patches.suse/drm-amdgpu-pm-Fix-the-null-pointer-dereference-for-s.patch
    (stable-fixes CVE-2024-43909 bsc#1229789).
  - Update
    patches.suse/drm-amdgpu-pm-Fix-the-null-pointer-dereference-in-ap.patch
    (stable-fixes CVE-2024-43907 bsc#1229787).
  - Update
    patches.suse/drm-client-fix-null-pointer-dereference-in-drm_clien.patch
    (git-fixes CVE-2024-43894 bsc#1229746).
  - Update
    patches.suse/drm-gma500-fix-null-pointer-dereference-in-cdv_intel.patch
    (git-fixes CVE-2024-42310 bsc#1229358).
  - Update
    patches.suse/drm-gma500-fix-null-pointer-dereference-in-psb_intel.patch
    (git-fixes CVE-2024-42309 bsc#1229359).
  - Update
    patches.suse/drm-nouveau-prime-fix-refcount-underflow.patch
    (git-fixes CVE-2024-43867 bsc#1229493).
  - Update patches.suse/drm-qxl-Add-check-for-drm_cvt_mode.patch
    (git-fixes CVE-2024-43829 bsc#1229341).
  - Update
    patches.suse/drm-vmwgfx-Fix-a-deadlock-in-dma-buf-fence-polling.patch
    (git-fixes CVE-2024-43863 bsc#1229497).
  - Update
    patches.suse/exfat-fix-potential-deadlock-on-__exfat_get_dentry_set.patch
    (git-fixes CVE-2024-42315 bsc#1229354).
  - Update
    patches.suse/gpio-prevent-potential-speculation-leaks-in-gpio_dev.patch
    (stable-fixes CVE-2024-44931 bsc#1229837).
  - Update
    patches.suse/hfs-fix-to-initialize-fields-of-hfs_inode_info-after-hfs_alloc_inode.patch
    (git-fixes CVE-2024-42311 bsc#1229413).
  - Update
    patches.suse/iio-Fix-the-sorting-functionality-in-iio_gts_build_a.patch
    (git-fixes CVE-2024-43825 bsc#1229298).
  - Update
    patches.suse/jfs-Fix-array-index-out-of-bounds-in-diFree.patch
    (git-fixes CVE-2024-43858 bsc#1229414).
  - Update
    patches.suse/jfs-Fix-shift-out-of-bounds-in-dbDiscardAG.patch
    (git-fixes CVE-2024-44938 bsc#1229792).
  - Update
    patches.suse/jfs-fix-null-ptr-deref-in-dtInsertEntry.patch
    (git-fixes CVE-2024-44939 bsc#1229820).
  - Update
    patches.suse/kobject_uevent-Fix-OOB-access-within-zap_modalias_en.patch
    (git-fixes CVE-2024-42292 bsc#1229373).
  - Update
    patches.suse/kvm-s390-Reject-memory-region-operations-for-ucontrol-VMs.patch
    (git-fixes bsc#1229168 CVE-2024-43819 bsc#1229290).
  - Update
    patches.suse/leds-trigger-Unregister-sysfs-attributes-before-call.patch
    (git-fixes CVE-2024-43830 bsc#1229305).
  - Update
    patches.suse/lib-objagg-Fix-general-protection-fault.patch
    (git-fixes CVE-2024-43846 bsc#1229360).
  - Update
    patches.suse/libbpf-Use-OPTS_SET-macro-in-bpf_xdp_query.patch
    (git-fixes CVE-2024-27050 bsc#1223767).
  - Update
    patches.suse/mISDN-Fix-a-use-after-free-in-hfcmulti_tx.patch
    (git-fixes CVE-2024-42280 bsc#1229388).
  - Update
    patches.suse/mailbox-mtk-cmdq-Move-devm_mbox_controller_register-.patch
    (git-fixes CVE-2024-42319 bsc#1229350).
  - Update
    patches.suse/md-raid5-fix-deadlock-that-raid5d-wait-for-itself-to-clear-MD_SB_CHANGE_PENDING-151f.patch
    (git-fixes CVE-2024-39476 bsc#1227437).
  - Update
    patches.suse/media-imx-pxp-Fix-ERR_PTR-dereference-in-pxp_probe.patch
    (git-fixes CVE-2024-42303 bsc#1229365).
  - Update
    patches.suse/media-pci-ivtv-Add-check-for-DMA-map-result.patch
    (git-fixes CVE-2024-43877 bsc#1229484).
  - Update
    patches.suse/media-v4l-async-Fix-NULL-pointer-dereference-in-addi.patch
    (git-fixes CVE-2024-43833 bsc#1229299).
  - Update
    patches.suse/media-venus-fix-use-after-free-in-vdec_close.patch
    (git-fixes CVE-2024-42313 bsc#1229356).
  - Update
    patches.suse/media-xc2028-avoid-use-after-free-in-load_firmware_c.patch
    (stable-fixes CVE-2024-43900 bsc#1229756).
  - Update
    patches.suse/memcg-protect-concurrent-access-to-mem_cgroup_idr.patch
    (git-fixes CVE-2024-43892 bsc#1229761).
  - Update
    patches.suse/net-drop-bad-gso-csum_start-and-offset-in-virtio_net.patch
    (git-fixes CVE-2024-43897 bsc#1229752).
  - Update
    patches.suse/net-iucv-fix-use-after-free-in-iucv_sock_close.patch
    (bsc#1228973 CVE-2024-42271 bsc#1229400).
  - Update patches.suse/net-missing-check-virtio.patch (git-fixes
    CVE-2024-43817 bsc#1229312).
  - Update
    patches.suse/net-usb-qmi_wwan-fix-memory-leak-for-not-ip-packets.patch
    (git-fixes CVE-2024-43861 bsc#1229500).
  - Update
    patches.suse/nfs-pass-explicit-offset-count-to-trace-events.patch
    (git-fixes CVE-2024-43826 bsc#1229294).
  - Update
    patches.suse/nvme-pci-add-missing-condition-check-for-existence-o.patch
    (git-fixes CVE-2024-42276 bsc#1229410).
  - Update
    patches.suse/padata-Fix-possible-divide-by-0-panic-in-padata_mt_h.patch
    (git-fixes CVE-2024-43889 bsc#1229743).
  - Update
    patches.suse/remoteproc-imx_rproc-Skip-over-memory-region-when-no.patch
    (git-fixes CVE-2024-43860 bsc#1229319).
  - Update
    patches.suse/s390-dasd-fix-error-checks-in-dasd_copy_pair_store.patch
    (git-fixes bsc#1229173 CVE-2024-42320 bsc#1229349).
  - Update
    patches.suse/scsi-lpfc-Revise-lpfc_prep_embed_io-routine-with-pro.patch
    (bsc#1228857 CVE-2024-43816 bsc#1229318).
  - Update
    patches.suse/scsi-qla2xxx-Complete-command-early-within-lock.patch
    (bsc#1228850 CVE-2024-42287 bsc#1229392).
  - Update
    patches.suse/scsi-qla2xxx-During-vport-delete-send-async-logout-e.patch
    (bsc#1228850 CVE-2024-42289 bsc#1229399).
  - Update
    patches.suse/scsi-qla2xxx-Fix-for-possible-memory-corruption.patch
    (bsc#1228850 CVE-2024-42288 bsc#1229398).
  - Update
    patches.suse/scsi-qla2xxx-validate-nvme_local_port-correctly.patch
    (bsc#1228850 CVE-2024-42286 bsc#1229395).
  - Update
    patches.suse/serial-core-check-uartclk-for-zero-to-avoid-divide-b.patch
    (stable-fixes CVE-2024-43893 bsc#1229759).
  - Update
    patches.suse/soc-qcom-pdr-protect-locator_addr-with-the-main-mute.patch
    (git-fixes CVE-2024-43849 bsc#1229307).
  - Update
    patches.suse/soc-xilinx-rename-cpu_number1-to-dummy_cpu_number.patch
    (git-fixes CVE-2024-43851 bsc#1229313).
  - Update
    patches.suse/spi-microchip-core-ensure-TX-and-RX-FIFOs-are-empty-.patch
    (git-fixes CVE-2024-42279 bsc#1229390).
  - Update
    patches.suse/usb-vhci-hcd-Do-not-drop-references-before-new-refer.patch
    (stable-fixes CVE-2024-43883 bsc#1229707).
  - Update
    patches.suse/vhost-vsock-always-initialize-seqpacket_allow.patch
    (git-fixes CVE-2024-43873 bsc#1229488).
  - Update
    patches.suse/wifi-ath12k-change-DMA-direction-while-mapping-reinj.patch
    (git-fixes CVE-2024-43881 bsc#1229480).
  - Update
    patches.suse/wifi-ath12k-fix-invalid-memory-access-while-processi.patch
    (git-fixes CVE-2024-43847 bsc#1229291).
  - Update
    patches.suse/wifi-cfg80211-handle-2x996-RU-allocation-in-cfg80211.patch
    (git-fixes CVE-2024-43879 bsc#1229482).
  - Update
    patches.suse/wifi-nl80211-disallow-setting-special-AP-channel-wid.patch
    (stable-fixes CVE-2024-43912 bsc#1229830).
  - Update
    patches.suse/wifi-rtw89-Fix-array-index-mistake-in-rtw89_sta_info.patch
    (git-fixes CVE-2024-43842 bsc#1229317).
  - Update
    patches.suse/wifi-virt_wifi-avoid-reporting-connection-success-wi.patch
    (git-fixes CVE-2024-43841 bsc#1229304).
  - commit 140ec33
  - iommu/amd: Convert comma to semicolon (git-fixes).
  - commit 2714d8b
  - scsi: lpfc: Fix a possible null pointer dereference (bsc#1229315
    CVE-2024-43821).
  - commit eb73e94
  - iommu/vt-d: Fix identity map bounds in si_domain_init()
    (git-fixes).
  - commit b4d27e5
  - iommufd/device: Fix hwpt at err_unresv in
    iommufd_device_do_replace() (git-fixes).
  - commit bbc9a65
  - virtiofs: forbid newlines in tags (bsc#1229940).
  - commit 61514ce
  - trace/pid_list: Change gfp flags in pid_list_fill_irq()
    (git-fixes).
  - commit 88d1dac
  - evm: don't copy up 'security.evm' xattr (git-fixes).
  - commit d3bb5af
  - afs: fix __afs_break_callback() / afs_drop_open_mmap() race
    (git-fixes).
  - commit 150e615
  - jfs: define xtree root and page independently (git-fixes).
  - commit fc62e49
  - kernfs: fix false-positive WARN(nr_mmapped) in
    kernfs_drain_open_files (git-fixes).
  - commit 7fa46d1
  - gfs2: setattr_chown: Add missing initialization (git-fixes).
  - commit 9b6ef3b
  - nfc: pn533: Add poll mod list filling check (git-fixes).
  - wifi: wfx: repair open network AP mode (git-fixes).
  - wifi: iwlwifi: fw: fix wgds rev 3 exact size (git-fixes).
  - wifi: mwifiex: duplicate static structs used in driver instances
    (git-fixes).
  - Input: i8042 - use new forcenorestore quirk to replace old
    buggy quirk combination (stable-fixes).
  - Input: i8042 - add forcenorestore quirk to leave controller
    untouched even on s3 (stable-fixes).
  - platform/surface: aggregator: Fix warning when controller is
    destroyed in probe (git-fixes).
  - thunderbolt: Mark XDomain as unplugged when router is removed
    (stable-fixes).
  - Input: MT - limit max slots (stable-fixes).
  - usb: dwc3: core: Skip setting event buffers for host only
    controllers (stable-fixes).
  - platform/x86: lg-laptop: fix %s null argument warning
    (stable-fixes).
  - rtc: nct3018y: fix possible NULL dereference (stable-fixes).
  - usb: gadget: fsl: Increase size of name buffer for endpoints
    (stable-fixes).
  - media: drivers/media/dvb-core: copy user arrays safely
    (stable-fixes).
  - media: pci: cx23885: check cx23885_vdev_init() return
    (stable-fixes).
  - memory: stm32-fmc2-ebi: check regmap_read return value
    (stable-fixes).
  - memory: tegra: Skip SID programming if SID registers aren't set
    (stable-fixes).
  - Revert "usb: gadget: uvc: cleanup request when not in correct
    state" (stable-fixes).
  - usb: gadget: uvc: cleanup request when not in correct state
    (stable-fixes).
  - staging: ks7010: disable bh on tx_dev_lock (stable-fixes).
  - staging: iio: resolver: ad2s1210: fix use before initialization
    (stable-fixes).
  - ssb: Fix division by zero issue in ssb_calc_clock_rate
    (stable-fixes).
  - commit b84d799
  - drm/vmwgfx: Fix prime with external buffers (git-fixes).
  - drm/i915/dsi: Make Lenovo Yoga Tab 3 X90F DMI match less strict
    (git-fixes).
  - drm/amd/display: avoid using null object of framebuffer
    (git-fixes).
  - Bluetooth: hci_core: Fix not handling hibernation actions
    (git-fixes).
  - drm/amdgpu: Validate TA binary size (stable-fixes).
  - drm/msm/dpu: take plane rotation into account for wide planes
    (git-fixes).
  - drm/msm/dpu: move dpu_encoder's connector assignment to
    atomic_enable() (git-fixes).
  - char: xillybus: Refine workqueue handling (git-fixes).
  - char: xillybus: Don't destroy workqueue from work item running
    on it (stable-fixes).
  - drm/amdgpu: Actually check flags for all context ops
    (stable-fixes).
  - drm/amdgpu/jpeg4: properly set atomics vmid field
    (stable-fixes).
  - drm/amdgpu/jpeg2: properly set atomics vmid field
    (stable-fixes).
  - drm/amd/display: fix s2idle entry for DCN3.5+ (stable-fixes).
  - drm/amdgpu: fix dereference null return value for the function
    amdgpu_vm_pt_parent (stable-fixes).
  - hwmon: (ltc2992) Fix memory leak in ltc2992_parse_dt()
    (git-fixes).
  - firmware: cirrus: cs_dsp: Initialize debugfs_root to invalid
    (stable-fixes).
  - drm/msm/dpu: capture snapshot on the first commit_done timeout
    (stable-fixes).
  - drm/msm/dpu: split dpu_encoder_wait_for_event into two functions
    (stable-fixes).
  - drm/lima: set gp bus_stop bit before hard reset (stable-fixes).
  - drm/panel: nt36523: Set 120Hz fps for xiaomi,elish panels
    (stable-fixes).
  - gpio: sysfs: extend the critical section for unregistering
    sysfs devices (stable-fixes).
  - Bluetooth: bnep: Fix out-of-bound access (stable-fixes).
  - hwmon: (pc87360) Bounds check data->innr usage (stable-fixes).
  - ASoC: SOF: ipc4: check return value of snd_sof_ipc_msg_data
    (stable-fixes).
  - drm/msm/dpu: drop MSM_ENC_VBLANK support (stable-fixes).
  - drm/msm/dpu: use drmm-managed allocation for dpu_encoder_phys
    (stable-fixes).
  - drm/msm/mdss: Rename path references to mdp_path (stable-fixes).
  - drm/msm/mdss: switch mdss to use devm_of_icc_get()
    (stable-fixes).
  - drm/msm/dpu: try multirect based on mdp clock limits
    (stable-fixes).
  - drm/msm: Reduce fallout of fence signaling vs reclaim hangs
    (stable-fixes).
  - drm/rockchip: vop2: clear afbc en and transform bit for cluster
    window at linear mode (stable-fixes).
  - Bluetooth: hci_conn: Check non NULL function before calling
    for HFP offload (stable-fixes).
  - i2c: stm32f7: Add atomic_xfer method to driver (stable-fixes).
  - i2c: riic: avoid potential division by zero (stable-fixes).
  - i3c: mipi-i3c-hci: Do not unmap region not mapped for transfer
    (stable-fixes).
  - i3c: mipi-i3c-hci: Remove BUG() when Ring Abort request times
    out (stable-fixes).
  - ASoC: SOF: Intel: hda-dsp: Make sure that no irq handler is
    pending before suspend (stable-fixes).
  - ASoC: cs35l45: Checks index of cs35l45_irqs[] (stable-fixes).
  - clk: visconti: Add bounds-checking coverage for struct
    visconti_pll_provider (stable-fixes).
  - hwmon: (ltc2992) Avoid division by zero (stable-fixes).
  - commit 1b92ddd

++++ json-glib:

  - Update to version 1.10.0:
    + Allow disabling installed tests
    + Support parsing multiple root statements in non-strict mode
    + Allow loading files >4GB with json-glib-validate
  - Add docutils BuildRequires: New dependency (rst2man)

++++ lvm2:

  - [SLFO] systemd 254 is missing reworked SYSTEMD_READY logic in device mapper udev rules (bsc#1229518)
    * update udev dependency version in lvm2.spec

++++ suse-module-tools:

  - Update to version 16.0.50:
    * Generate initrd for the default snapshot (boo#1224773)

------------------------------------------------------------------
------------------  2024-8-29  -  Aug 29 2024  -------------------
------------------------------------------------------------------

++++ fwupd-efi:

  - Update to version 1.6:
    * Require gnu-efi 3.0.18 or later
    * Ship an objcopy capable LDS for ARM64
    * Detect gnu-efi via pkgconfig
    * Backport the ctors and dtors work from gnu-efi upstream
    * Tidy up crt0 generator
    * Add RISC-V support
    * Fix per NX bit and UEFI 2.10 Microsoft requirements
  - Remove un-needed BRs:
    * pkgconfig(efiboot)
    * pkgconfig(efivar)
  - Remove shim requirement: it doesn't need it, it's a UEFI binary
  - Restore ix86 and ARM32 support
  - Add RISC-V support
  - Remove patches (fixed upstream):
    * binutils-2.38-arm-objcopy.patch
    * binutils-2.38-arm-system-crt0.patch
    * ARM-fixes.patch

++++ guestfs-tools:

  - Update to version 1.53.3 (jsc#PED-8910)
    * Update common submodule
    Further refinements to Windows firstboot code.
    mlcustomize: Add some comments to firstboot batch file
    mlcustomize: Reboot Windows between each firstboot script
    mlcustomize: Move virt-customize modules to mlcustomize/

++++ kernel-default:

  - jump_label: Fix the fix, brown paper bags galore (git-fixes).
  - commit 89b2827
  - jump_label: Simplify and clarify
    static_key_fast_inc_cpus_locked() (git-fixes).
  - commit 954eaa3
  - jump_label: Clarify condition in
    static_key_fast_inc_not_disabled() (git-fixes).
  - commit eb457dc
  - jump_label: Fix concurrency issues in static_key_slow_dec()
    (git-fixes).
  - commit 6e92a06
  - tracing: Return from tracing_buffers_read() if the file has
    been closed (bsc#1229136 git-fixes).
  - commit 8dc8510
  - kprobes: Fix to check symbol prefixes correctly (git-fixes).
  - commit e8b168b
  - kprobes: Prohibit probing on CFI preamble symbol (git-fixes).
  - commit 2f9e2b1
  - bpf: kprobe: remove unused declaring of bpf_kprobe_override
    (git-fixes).
  - commit 4045c94
  - wifi: mac80211: fix NULL dereference at band check in starting
    tx ba session (CVE-2024-43911 bsc#1229827).
  - commit 0892b94
  - syscalls: fix compat_sys_io_pgetevents_time64 usage (git-fixes).
  - commit b90dd07
  - iommu: sprd: Avoid NULL deref in sprd_iommu_hw_en
    (CVE-2024-42277 bsc#1229409).
  - commit ede2511

++++ kernel-rt:

  - jump_label: Fix the fix, brown paper bags galore (git-fixes).
  - commit 89b2827
  - jump_label: Simplify and clarify
    static_key_fast_inc_cpus_locked() (git-fixes).
  - commit 954eaa3
  - jump_label: Clarify condition in
    static_key_fast_inc_not_disabled() (git-fixes).
  - commit eb457dc
  - jump_label: Fix concurrency issues in static_key_slow_dec()
    (git-fixes).
  - commit 6e92a06
  - tracing: Return from tracing_buffers_read() if the file has
    been closed (bsc#1229136 git-fixes).
  - commit 8dc8510
  - kprobes: Fix to check symbol prefixes correctly (git-fixes).
  - commit e8b168b
  - kprobes: Prohibit probing on CFI preamble symbol (git-fixes).
  - commit 2f9e2b1
  - bpf: kprobe: remove unused declaring of bpf_kprobe_override
    (git-fixes).
  - commit 4045c94
  - wifi: mac80211: fix NULL dereference at band check in starting
    tx ba session (CVE-2024-43911 bsc#1229827).
  - commit 0892b94
  - syscalls: fix compat_sys_io_pgetevents_time64 usage (git-fixes).
  - commit b90dd07
  - iommu: sprd: Avoid NULL deref in sprd_iommu_hw_en
    (CVE-2024-42277 bsc#1229409).
  - commit ede2511

++++ multipath-tools:

  - Update to 0.10.0+103+suse.0fc97cd
  - Update to upstream 0.10.0 (see also NEWS.md)
    * The `multipathd show daemon` command now shows `(reconfigure pending)`
    if a reconfiguration has been triggered but not finished yet.
    * Refactored the path checker loop. Paths are now checked for each multipath
    map in turn
    * Renamed public functions, variables, and macros to comply with the glibc policy
    for reserved names (gh#opensvc/multipath-tools#91)
    * Fixed bug that caused queueing to be always disabled if flushing a map failed
    (bug introduced in 0.9.8). (bsc#1229898)
    * Fixed failure to remove maps even with `deferred_remove` (bug introduced in
    0.9.9). (bsc#1229898)
    * Fixed old mpathpersist bug leading to the error message "configured reservation
    key doesn't match: 0x0" when `reservation_key` was configured in the
    multipaths section of `multipath.conf`. (bsc#1228926, gh#opensvc/multipath-tools#92)
    * Fixed output of `multipath -t` and `multipath -T` for the options
    `force_sync` and `retrigger_tries`. (bsc#1229898, gh#opensvc/multipath-tools#88)
    * Fixed adding maps by WWID in CLI (command `add map $WWID`). (bsc#1229898)

++++ libguestfs:

  - Update to version 1.53.6 (jsc#PED-8910)
    * Various MacOS fixes and enhancements
    * ocaml: INSTALL_OCAMLLIB Makefile parameter
    * appliance/init: Don't set impossible "noop" disk scheduler
    * Pull in some fixes from the common submodule.
    mlcustomize: Add Inject_virtio_win.inject_blnsvr implementation
    mlcustomize: firstboot: Use Linux path for Powershell script path
    mlcustomize: firstboot: Use powershell.exe instead of path
    mlcustomize: firstboot: Use Powershell -NoProfile flag
    mlcustomize: Revert delay installation of qemu-ga MSI
    mldrivers/linux_kernels.ml: Prefix general information with ^info:
    mlcustomize: Use Start-Process -Wait to run qemu-ga installer
    mlcustomize: Add Firstboot.firstboot_dir function
    mlcustomize: Place powershell scripts into <firstboot_dir>\Temp
    mlcustomize: Inject qemu-ga & blnsvr into <firstboot_dir>/Temp
    mlcustomize: Write qemu-ga log file name to log.txt
    mlcustomize: Add some comments to firstboot batch file
    mlcustomize: Reboot Windows between each firstboot script

++++ python313-core:

  - Add gh122136-test_asyncio-kernel-buffer-data.patch fixing
    gh#python/cpython#122136 (changes in kernel provide different
    amount of data in the socket buffers).
  - Remove skip_test_abort_clients.patch, which is not needed any
    more.

++++ snapper:

  - use .snapshots dir for 'btrfs qgroup clear-stale' (bsc#1229904)
  - version 0.11.2

++++ python313:

  - Add gh122136-test_asyncio-kernel-buffer-data.patch fixing
    gh#python/cpython#122136 (changes in kernel provide different
    amount of data in the socket buffers).
  - Remove skip_test_abort_clients.patch, which is not needed any
    more.

++++ python-requests:

  - Remove Requires on python-py, it should have been removed earlier.

------------------------------------------------------------------
------------------  2024-8-28  -  Aug 28 2024  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update to 10.3.4
    + Modify the message when network access over a specific IP version does
    not work. This is an informational message and should not look like
    an error
    + Inform the user that LTSS registration takes a little longer
    + Add fix-for-sles12-no-trans_update.patch
    + SLE 12 family has no products with transactional-update we do not
    need to look for this condition
  - From 10.3.3 (bsc#1229472)
    + Handle changes in process structure to properly identify the running
    zypper parent process and only check for 1 PID
  - From 10.3.2
    + Remove rgnsrv-clnt-fix-docker-setup.patch included upstream
  - From 10.3.1 (jsc#PCT-400)
    + Add support for LTSS registration
    + Add fix-for-sles12-disable-registry.patch
    ~ No container support in SLE 12

++++ git:

  - Change less requirement to path to allow for use with BusyBox

++++ kernel-default:

  - Update references patches.suse/drm-amd-display-Add-null-checks-for-stream-and-plane.patch (CVE-2024-43904 bsc#1229768 stable-fixes)
  - commit aaa26ef
  - kabi: lib: objagg: Put back removed metod in struct objagg_ops
    (CVE-2024-43880 bsc#1229481).
  - commit 9566f2d
  - net/sched: initialize noop_qdisc owner (git-fixes).
  - commit 66e8d18
  - drm/amd/display: Fix null pointer deref in dcn20_resource.c (CVE-2024-43899 bsc#1229754).
  - commit 1811990
  - exec: Fix ToCToU between perm check and set-uid/gid usage
    (CVE-2024-43882 bsc#1229503).
  - commit 7a21b9d
  - ALSA: hda/realtek: support HP Pavilion Aero 13-bg0xxx Mute LED
    (stable-fixes).
  - ALSA: hda/realtek: Fix the speaker output on Samsung Galaxy
    Book3 Ultra (stable-fixes).
  - ASoC: allow module autoloading for table board_ids
    (stable-fixes).
  - ASoC: allow module autoloading for table db1200_pids
    (stable-fixes).
  - ASoC: mediatek: mt8188: Mark AFE_DAC_CON0 register as volatile
    (stable-fixes).
  - ASoC: SOF: mediatek: Add missing board compatible
    (stable-fixes).
  - ALSA: hda/realtek - FIxed ALC285 headphone no sound
    (stable-fixes).
  - ALSA: hda/realtek - Fixed ALC256 headphone no sound
    (stable-fixes).
  - ALSA: hda/realtek: Enable mute/micmute LEDs on HP Laptop
    14-ey0xxx (stable-fixes).
  - ALSA: hda/realtek: Implement sound init sequence for Samsung
    Galaxy Book3 Pro 360 (stable-fixes).
  - commit 97adcb2
  - ip6_tunnel: Fix broken GRO (bsc#1229444).
  - net/mlx5: Always drain health in shutdown callback
    (CVE-2024-43866 bsc#1229495).
  - mlxsw: spectrum_acl_erp: Fix object nesting warning
    (CVE-2024-43880 bsc#1229481).
  - commit d9a404d
  - pinctrl: rockchip: correct RK3328 iomux width flag for GPIO2-B
    pins (git-fixes).
  - pinctrl: starfive: jh7110: Correct the level trigger
    configuration of iev register (git-fixes).
  - pinctrl: mediatek: common-v2: Fix broken bias-disable for
    PULL_PU_PD_RSEL_TYPE (git-fixes).
  - pinctrl: single: fix potential NULL dereference in
    pcs_get_function() (git-fixes).
  - ASoC: SOF: amd: Fix for acp init sequence (git-fixes).
  - ASoC: amd: acp: fix module autoloading (git-fixes).
  - ALSA: seq: Skip event type filtering for UMP events (git-fixes).
  - commit 3fa4a0b

++++ kernel-firmware-all:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-amdgpu:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-ath10k:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-ath11k:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-ath12k:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-atheros:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-bluetooth:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-bnx2:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-brcm:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-chelsio:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-dpaa2:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-i915:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-intel:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-iwlwifi:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-liquidio:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-marvell:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-media:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-mediatek:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-mellanox:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-mwifiex:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-network:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-nfp:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-nvidia:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-platform:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-prestera:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-qcom:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-qlogic:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-radeon:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-realtek:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-serial:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-sound:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-ti:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-ueagle:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-firmware-usb-network:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

++++ kernel-rt:

  - Update references patches.suse/drm-amd-display-Add-null-checks-for-stream-and-plane.patch (CVE-2024-43904 bsc#1229768 stable-fixes)
  - commit aaa26ef
  - kabi: lib: objagg: Put back removed metod in struct objagg_ops
    (CVE-2024-43880 bsc#1229481).
  - commit 9566f2d
  - net/sched: initialize noop_qdisc owner (git-fixes).
  - commit 66e8d18
  - drm/amd/display: Fix null pointer deref in dcn20_resource.c (CVE-2024-43899 bsc#1229754).
  - commit 1811990
  - exec: Fix ToCToU between perm check and set-uid/gid usage
    (CVE-2024-43882 bsc#1229503).
  - commit 7a21b9d
  - ALSA: hda/realtek: support HP Pavilion Aero 13-bg0xxx Mute LED
    (stable-fixes).
  - ALSA: hda/realtek: Fix the speaker output on Samsung Galaxy
    Book3 Ultra (stable-fixes).
  - ASoC: allow module autoloading for table board_ids
    (stable-fixes).
  - ASoC: allow module autoloading for table db1200_pids
    (stable-fixes).
  - ASoC: mediatek: mt8188: Mark AFE_DAC_CON0 register as volatile
    (stable-fixes).
  - ASoC: SOF: mediatek: Add missing board compatible
    (stable-fixes).
  - ALSA: hda/realtek - FIxed ALC285 headphone no sound
    (stable-fixes).
  - ALSA: hda/realtek - Fixed ALC256 headphone no sound
    (stable-fixes).
  - ALSA: hda/realtek: Enable mute/micmute LEDs on HP Laptop
    14-ey0xxx (stable-fixes).
  - ALSA: hda/realtek: Implement sound init sequence for Samsung
    Galaxy Book3 Pro 360 (stable-fixes).
  - commit 97adcb2
  - ip6_tunnel: Fix broken GRO (bsc#1229444).
  - net/mlx5: Always drain health in shutdown callback
    (CVE-2024-43866 bsc#1229495).
  - mlxsw: spectrum_acl_erp: Fix object nesting warning
    (CVE-2024-43880 bsc#1229481).
  - commit d9a404d
  - pinctrl: rockchip: correct RK3328 iomux width flag for GPIO2-B
    pins (git-fixes).
  - pinctrl: starfive: jh7110: Correct the level trigger
    configuration of iev register (git-fixes).
  - pinctrl: mediatek: common-v2: Fix broken bias-disable for
    PULL_PU_PD_RSEL_TYPE (git-fixes).
  - pinctrl: single: fix potential NULL dereference in
    pcs_get_function() (git-fixes).
  - ASoC: SOF: amd: Fix for acp init sequence (git-fixes).
  - ASoC: amd: acp: fix module autoloading (git-fixes).
  - ALSA: seq: Skip event type filtering for UMP events (git-fixes).
  - commit 3fa4a0b

++++ samba:

  -  Bad variable definition for ParseTuple causing test failure for
    Smb3UnixTests.test_create_context_reparse; (bso#15702).
  - Update to 4.21.0
    * Incorrect FSCTL_QUERY_ALLOCATED_RANGES response when
    truncated; (bso#15699).
    * Bad variable definition for ParseTuple causing test failure
    for Smb3UnixTests.test_create_context_reparse; (bso#15702).
    * Add new vfs_ceph module (based on low level API);
    (bso#15686).
    * samba-tool can not load the default configuration file;
    (bso#15698).
    * Crash when readlinkat fails; (bso#15700).
    * Can't add/delete special keys to keytab for nfs, cifs, http
    etc; (bso#15689).
    * Compound SMB2 requests don't return
    NT_STATUS_NETWORK_SESSION_EXPIRED for all requests, confuses
    MacOSX clients; (bso#15696).
    * --version-* options are still not ergonomic, and they reject
    tilde characters; (bso#15673).
    * ldb_version.h is missing from ldb public library;
    (bso#15690).
    * Can not add/delete special keys to keytab for nfs, cifs, http
    etc; (bso#15689).
    * undefined reference to winbind_lookup_name_ex; (bso#15687).
    * per user veto and hide file syntax is to complex;
    (bso#15688).

++++ openvswitch:

  - Update openvswitch to 3.3.1. For a list of changes, check
    https://github.com/openvswitch/ovs/blob/v3.3.1/NEWS
  - Update OVN to 24.03.3. For a list of changes, check
    https://github.com/ovn-org/ovn/blob/v24.03.3/NEWS
  - Drop upstream fixed patches,
    * CVE-2023-1668.patch
    * CVE-2023-3152.patch
    * CVE-2023-5366.patch
    * openvswitch-2.17.8-gcc14-build-fix.patch
    * openvswitch-CVE-2023-3966.patch
  - Updated the patch for version v3.3.1
    * install-ovsdb-tools.patch

++++ python313-core:

  - Add CVE-2024-8088-inf-loop-zipfile_Path.patch to prevent
    malformed payload to cause infinite loops in zipfile.Path
    (bsc#1229704, CVE-2024-8088).

++++ nvidia-open-driver-G06-signed:

  - reverted CUDA update version to 560.x.y due to changes in CUDA
    repository with CUDA 12.6/560.x.y drivers
  - kernel-6.10.patch:
    * fixes build of 555.42.06 against Kernel 6.10

++++ python313:

  - Add CVE-2024-8088-inf-loop-zipfile_Path.patch to prevent
    malformed payload to cause infinite loops in zipfile.Path
    (bsc#1229704, CVE-2024-8088).

++++ thin-provisioning-tools:

  - Update to version 1.1.0:
    * Bump version to 1.1.0
    * [doc] Update CHANGES
    * [build] Update dependencies
    * [thin_migrate] Tweak the checking routines
    * [thin_migrate] Enforce that the source device be read-only
    * [thin_migrate] Do not open the source device exclusively
    * [man] Update thin_migrate man page
    * [man] Update thin_dump man page
    * v1.0.14
    * [doc] Update CHANGES
    * [build] Update Makefile to install thin_migrate
    * [build] Update dependencies
    * [thin_migrate] Check file type of the output device
    * [thin_migrate] Fix suspicious open options suggested by clippy
    * [doc] Update links in GPLv3
    * [file_utils] Remove unexpected target_arch 'powerpc64le'
    * [man] Fix the buffer size descriptions for cache_writeback
    * [doc] Update TODO list
    * [doc] Fix typos
    * [man] Fix man page formatting
    * [man] Add man page for thin_migrate
    * [thin_migrate] Fix file size check on the output file
    * [thin_migrate] Add progress bar
    * [copier] Make the ProgressReporter reusable
    * [thin_migrate] Update devicemapper-rs registry
    * [thin_migrate] Hide unimplemented delta-id option and related code
    * [thin_migrate] Remove unused code
    * [thin_migrate] Hide unused --zero-dest option
    * [thin_migrate] Tweak the value names in help text
    * [thin_migrate] Fix buffer size settings for the copier
    * [thin_migrate] Use direct io for better performance and error handling
    * [copier] Factor out common code
    * [space_map] Improve error tolerance of ref counting
    * [thin_check] Fix overriding roots not working if the original one broke
    * [thin_migrate] Apply cargo fmt, and fix clippy lints
    * [thin_migrate] Remove unused functions and fields
    * [thin_migrate] Fix copier parameters
    * [thin_migrate] Fix mapping stream outputs
    * [thin_migrate] Fix getting block device file size
    * [thin_migrate] Temporarily skip progress display
    * [thin_migrate] Fix opening pool metadata exclusively
    * Builds but not tested yet
    * wip
    * [thin_migrate] wip
    * [thin_migrate] work in progress
    * [btree] add lookup function
    * [thin_migrate] wip

++++ ucode-amd:

  - Update to version 20240826 (git commit bec4fd18cc57):
    (including ath11k f/w updates for bsc#1234027)
    * amdgpu: DMCUB updates forvarious AMDGPU ASICs
    * rtw89: 8922a: add fw format-1 v0.35.41.0
    * linux-firmware: update firmware for MT7925 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7925)
    * rtl_bt: Add firmware and config files for RTL8922A
    * rtl_bt: Add firmware file for the the RTL8723CS Bluetooth part
    * rtl_bt: de-dupe identical config.bin files
    * rename rtl8723bs_config-OBDA8723.bin -> rtl_bt/rtl8723bs_config.bin
    * linux-firmware: Update AMD SEV firmware
    * linux-firmware: update firmware for MT7996
    * Revert "i915: Update MTL DMC v2.22"
    * ath12k: WCN7850 hw2.0: update board-2.bin
    * ath11k: WCN6855 hw2.0: update to WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41
    * ath11k: WCN6855 hw2.0: update board-2.bin
    * ath11k: QCA2066 hw2.1: add to WLAN.HSP.1.1-03926.13-QCAHSPSWPL_V2_SILICONZ_CE-2.52297.3
    * ath11k: QCA2066 hw2.1: add board-2.bin
    * ath11k: IPQ5018 hw1.0: update to WLAN.HK.2.6.0.1-01291-QCAHKSWPL_SILICONZ-1
    * qcom: vpu: add video firmware for sa8775p
    * amdgpu: DMCUB updates for various AMDGPU ASICs

------------------------------------------------------------------
------------------  2024-8-27  -  Aug 27 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - remove dependency on /usr/bin/python

++++ glib2:

  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang{,_path} macros, [bsc#1212476]

++++ kernel-default:

  - ice: Fix NULL pointer access, if PF doesn't support SRIOV_LAG
    (bsc#1228737).
  - commit f1a9730
  - kABI: vfio: struct virqfd kABI workaround (CVE-2024-26812
    bsc#1222808).
  - commit ae735c0
  - net/sched: Fix mirred deadlock on device recursion
    (CVE-2024-27010 bsc#1223720).
  - commit 8c34ee8
  - Fix reference in patches.suse/netfilter-tproxy-bail-out-if-IP-has-been-disabled-on.patch (CVE-2024-36270 bsc#1226798)
  - commit 052d917
  - net: qdisc: preserve kabi for struct QDisc (CVE-2024-27010 bsc#1223720).
  - commit e31d466
  - mm/userfaultfd: reset ptes when close() for wr-protected ones
    (CVE-2024-36881 bsc#1225718).
  - commit 2267d46
  - mm/mglru: fix div-by-zero in vmpressure_calc_level()
    (CVE-2024-42316 bsc#1229353).
  - commit ba00671
  - md/raid1: set max_sectors during early return from
    choose_slow_rdev() (git-fixes).
  - md/raid5: recheck if reshape has finished with device_lock held
    (git-fixes).
  - md: Don't wait for MD_RECOVERY_NEEDED for HOT_REMOVE_DISK ioctl
    (git-fixes).
  - md/raid5: fix spares errors about rcu usage (git-fixes).
  - md/md-bitmap: fix writing non bitmap pages (git-fixes).
  - md: fix deadlock between mddev_suspend and flush bio
    (bsc#1229342, CVE-2024-43855).
  - md: change the return value type of md_write_start to void
    (git-fixes).
  - md: do not delete safemode_timer in mddev_suspend (git-fixes).
  - md: don't account sync_io if iostats of the disk is disabled
    (git-fixes).
  - md: add check for sleepers in md_wakeup_thread() (git-fixes).
  - md/raid5: fix deadlock that raid5d() wait for itself to clear
    MD_SB_CHANGE_PENDING (git-fixes).
  - md: add a mddev_add_trace_msg helper (git-fixes).
  - Revert "Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in
    raid5d"" (git-fixes).
  - md: fix a suspicious RCU usage warning (git-fixes).
  - md/raid1: support read error check (git-fixes).
  - commit f1ec0d4
  - md: factor out a helper exceed_read_errors() to check
    read_errors (git-fixes).
  - Refresh for the above change,
    patches.suse/md-display-timeout-error.patch.
    patches.suse/md-raid1-10-add-a-helper-raid1_check_read_range-f298.patch.
  - commit 035e3f0
  - Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d"
    (git-fixes).
  - commit 5cc0fdd

++++ kernel-rt:

  - ice: Fix NULL pointer access, if PF doesn't support SRIOV_LAG
    (bsc#1228737).
  - commit f1a9730
  - kABI: vfio: struct virqfd kABI workaround (CVE-2024-26812
    bsc#1222808).
  - commit ae735c0
  - net/sched: Fix mirred deadlock on device recursion
    (CVE-2024-27010 bsc#1223720).
  - commit 8c34ee8
  - Fix reference in patches.suse/netfilter-tproxy-bail-out-if-IP-has-been-disabled-on.patch (CVE-2024-36270 bsc#1226798)
  - commit 052d917
  - net: qdisc: preserve kabi for struct QDisc (CVE-2024-27010 bsc#1223720).
  - commit e31d466
  - mm/userfaultfd: reset ptes when close() for wr-protected ones
    (CVE-2024-36881 bsc#1225718).
  - commit 2267d46
  - mm/mglru: fix div-by-zero in vmpressure_calc_level()
    (CVE-2024-42316 bsc#1229353).
  - commit ba00671
  - md/raid1: set max_sectors during early return from
    choose_slow_rdev() (git-fixes).
  - md/raid5: recheck if reshape has finished with device_lock held
    (git-fixes).
  - md: Don't wait for MD_RECOVERY_NEEDED for HOT_REMOVE_DISK ioctl
    (git-fixes).
  - md/raid5: fix spares errors about rcu usage (git-fixes).
  - md/md-bitmap: fix writing non bitmap pages (git-fixes).
  - md: fix deadlock between mddev_suspend and flush bio
    (bsc#1229342, CVE-2024-43855).
  - md: change the return value type of md_write_start to void
    (git-fixes).
  - md: do not delete safemode_timer in mddev_suspend (git-fixes).
  - md: don't account sync_io if iostats of the disk is disabled
    (git-fixes).
  - md: add check for sleepers in md_wakeup_thread() (git-fixes).
  - md/raid5: fix deadlock that raid5d() wait for itself to clear
    MD_SB_CHANGE_PENDING (git-fixes).
  - md: add a mddev_add_trace_msg helper (git-fixes).
  - Revert "Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in
    raid5d"" (git-fixes).
  - md: fix a suspicious RCU usage warning (git-fixes).
  - md/raid1: support read error check (git-fixes).
  - commit f1ec0d4
  - md: factor out a helper exceed_read_errors() to check
    read_errors (git-fixes).
  - Refresh for the above change,
    patches.suse/md-display-timeout-error.patch.
    patches.suse/md-raid1-10-add-a-helper-raid1_check_read_range-f298.patch.
  - commit 035e3f0
  - Revert "md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d"
    (git-fixes).
  - commit 5cc0fdd

++++ libdrm:

  - update to 2.4.123
    * amdgpu: add new marketing names
    * amdgpu: add new marketing names
    * Convert to Android.bp
    * libs: Tie DSO minor versions to libdrm version
    * readdir_r is deprecated.
    * Fix FTBS on undefined clock_gettime() and asprintf()
    * Export include dirs with -isystem
    * Makes libdrm available on host
    * Adds libdrm_headers
    * Make libdrm recovery_available
    * add crosvm to com.android.virt
    * Enable GPU in crosvm
    * Android.bp: Add include exports for android dir
    * Disable ioctl signed overload for Bionic libc
    * build: bump version to 2.4.123
    * Delete all Makefile.sources files
    * tests: Make modetest and proptest cc_binary in Android.bp

++++ systemd:

  - Don't try to restart the udev socket units anymore (bsc#1228809)
    There's currently no way to restart a socket activable service and its socket
    units "atomically" and safely.

++++ qemu:

  - Fix bsc#1221812:
    * [openSUSE] block: Reschedule query-block during qcow2 invalidation (bsc#1221812)
  - Fixup a previous patch (cure a build warning):
    * [openSUSE] fixup patch "pc: q35: Allow 1024 cpus for old machine types"
  - Infra improvement:
    * [openSUSE] Workflows for Virtualization:Staging:TDX

------------------------------------------------------------------
------------------  2024-8-26  -  Aug 26 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Update to version 1.48.10:
    + nmcli/edit: fix memory leak in extract_setting_and_property
    + autotools: fix another filename that was renamed
    + gitlab: fix helper scripts to support DNF5
    + CI: update the imported templates_sha
    + autotools: fix filename that was renamed
    + format: run nm-code-format
    + policy: retry hostname resolution when it fails
    + platform: add small backoff time before resync
    + bridge: reapply port VLANs only when necessary
    + platform: add nmp_utils_bridge_normalized_vlans_equal()
    + platform: support reading bridge VLANs
    + device: support reapplying bridge-port VLANs
    + bridge: change the signature for
    nm_platform_link_set_bridge_vlans()
    + platform: add define for IFLA_BOND_SLAVE_PRIO
    + lldp: fix multiple access to argument in logging macro
    + lldp: fix crash dereferencing NULL pointer during debug logging
    + policy: unblock the autoconnect for children when parent is
    available

++++ transactional-update:

  - Version 4.8.0
  - Add sd-boot (systemd-boot) support for most commands
  - Add support for specifying migration arguments
    [gh#openSUSE/transactional-update#127] [jsc#PED-10375]
    [jsc#PED-9786]
  - Support kdump setup on platforms without kdump high/low
    settings (e.g. S/390 or PPC64le [bsc#1229138]
  - Preserve current working directory if possible when entering
    transactional-update environment [bsc#1227452]; also adds the
    current path to the Bash prompt
  - Fix plugin system to support special characters in commands

++++ glib2:

  - Update to version 2.82.0:
    + Change the default value of -Dglib_debug from `auto` to
    `enabled` for developers — distributions will almost certainly
    want to override it to `-Dglib_debug=disabled` for package
    release builds though.
    + Revert per-instance locking changes in `GCancellable` as they
    introduced new races.
    + Bugs fixed:
  - Investigate trampoline performance implications in
    g_mutex_lock_impl() changes
  - Default value for glib_debug meson option
  - wrong comment in gmessage.c:escape_string
  - Should check for epoll_create1 rather than epoll_create
  - Gio.MenuModel docs have an outdated UI example
  - gunixmounts: Fix use of uninitialised variable
  - tests: Run expected-to-hang cancellable tests in subprocesses
  - CI/msys2-mingw32: Set the G_DEBUGGER environment variable
  - Revert "GCancellable: Use per-instance mutex logic instead of
    global critical sections”
  - Various small backports
  - Backport “gthread: Move thread _impl functions to static
    inlines for speed”
    + Updated translations.
  - Pass glib_debug=disabled to meson as recommended by upstream and
    pass sysprof=disabled to meson, avoid pulling in extra
    dependencies.
  - Drop python enviroment fix, no longer needed.
  - Update to version 2.80.5:
    + Bugs fixed:
  - Fix gsocketclient-slow test on FreeBSD
  - glib-private: fix build under Cygwin
  - tests: Fix compilation of resolver-parsing test on FreeBSD
  - introspection: Correct GIO-Windows pkg-config name
    + Updated translations

++++ hwdata:

  - update to 0.385:
    * Update pci and vendor ids

++++ kernel-default:

  - net/mlx5e: Fix CT entry update leaks of modify header context (CVE-2024-43864 bsc#1229496)
  - commit 316a4fe
  - rpm/check-for-config-changes: Exclude ARCH_USING_PATCHABLE_FUNCTION_ENTRY
    gcc version dependent, at least on ppc
  - commit 16da158
  - af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
    (bsc#1226846 CVE-2024-38596).
  - Update
    patches.suse/af_unix-Fix-data-races-around-sk-sk_shutdown.patch
    (git-fixes bsc#1226846).
  - commit 7ceb0cd
  - ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work
    (CVE-2024-26631 bsc#1221630).
  - commit 317a097
  - netfilter: nf_tables: unconditionally flush pending work before notifier (CVE-2024-42109 bsc#1228505)
  - commit 7a6a06c
  - cxl/region: Avoid null pointer dereference in region lookup (CVE-2024-41084 bsc#1228472)
  - commit fc1408b
  - cxl/region: Move cxl_dpa_to_region() work to the region driver (bsc#1228472)
  - commit ac0e984
  - ipv6: fix possible race in __fib6_drop_pcpu_from() (CVE-2024-40905 bsc#1227761)
  - commit 6fcd399
  - ipv6: sr: fix memleak in seg6_hmac_init_algo (CVE-2024-39489 bsc#1227623)
  - commit c55beb2
  - swiotlb: do not set total_used to 0 in
    swiotlb_create_debugfs_files() (git-fixes).
  - swiotlb: fix swiotlb_bounce() to do partial sync's correctly
    (git-fixes).
  - commit 99fe6bb
  - x86/kaslr: Expose and use the end of the physical memory
    address space (bsc#1229443).
  - commit 5b98c4e
  - tls: fix missing memory barrier in tls_init (CVE-2024-36489 bsc#1226874)
  - commit 67db543
  - iommu: Add kABI workaround patch (bsc#1223742
    CVE-2024-27079).
  - commit c4ebc76
  - btrfs: copy dir permission and time when creating a stub
    subvolume (bsc#1228321).
  - commit 46e95d1

++++ kernel-rt:

  - net/mlx5e: Fix CT entry update leaks of modify header context (CVE-2024-43864 bsc#1229496)
  - commit 316a4fe
  - rpm/check-for-config-changes: Exclude ARCH_USING_PATCHABLE_FUNCTION_ENTRY
    gcc version dependent, at least on ppc
  - commit 16da158
  - af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg
    (bsc#1226846 CVE-2024-38596).
  - Update
    patches.suse/af_unix-Fix-data-races-around-sk-sk_shutdown.patch
    (git-fixes bsc#1226846).
  - commit 7ceb0cd
  - ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work
    (CVE-2024-26631 bsc#1221630).
  - commit 317a097
  - netfilter: nf_tables: unconditionally flush pending work before notifier (CVE-2024-42109 bsc#1228505)
  - commit 7a6a06c
  - cxl/region: Avoid null pointer dereference in region lookup (CVE-2024-41084 bsc#1228472)
  - commit fc1408b
  - cxl/region: Move cxl_dpa_to_region() work to the region driver (bsc#1228472)
  - commit ac0e984
  - ipv6: fix possible race in __fib6_drop_pcpu_from() (CVE-2024-40905 bsc#1227761)
  - commit 6fcd399
  - ipv6: sr: fix memleak in seg6_hmac_init_algo (CVE-2024-39489 bsc#1227623)
  - commit c55beb2
  - swiotlb: do not set total_used to 0 in
    swiotlb_create_debugfs_files() (git-fixes).
  - swiotlb: fix swiotlb_bounce() to do partial sync's correctly
    (git-fixes).
  - commit 99fe6bb
  - x86/kaslr: Expose and use the end of the physical memory
    address space (bsc#1229443).
  - commit 5b98c4e
  - tls: fix missing memory barrier in tls_init (CVE-2024-36489 bsc#1226874)
  - commit 67db543
  - iommu: Add kABI workaround patch (bsc#1223742
    CVE-2024-27079).
  - commit c4ebc76
  - btrfs: copy dir permission and time when creating a stub
    subvolume (bsc#1228321).
  - commit 46e95d1

++++ kubevirt:

  - Update to version 1.3.1
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.3.1
  - Fix DV error report via VM printable status
    0001-Consider-the-new-DV-reason-ImagePullFailed.patch
  - Fix permission error in storage migration tests
    0002-tests-Set-FSGroup-to-ensure-proper-permissions.patch

++++ ncurses:

  - Add ncurses patch 20240824
    + modify infocmp and tabs to use actual name in usage and header.
    + modify test/demo_keyok.c to accept ^Q for quit, for consistency.

++++ libsoup:

    6adc0e3e.patch
  - Update to version 3.6.0:
    + Allow HTTP/2 to be used with non-HTTP proxies
  - Changes from version 3.5.2:
    + Strictly forbid NUL bytes in headers
    + Fix minor leaks
  - Changes from version 3.5.1:
    + Add `SOUP_METHOD_PATCH`
    + websocket: Add `SoupWebsocketConnection:keepalive-pong-timeout`
    property
    + Increase maxmimum size of HTTP headers
    + Fix `soup_uri_copy()` in Vala
    + Fix leak in `soup_message_new_from_encoded_form()`
    + multipart: Improve handling of messages missing termination
    + logger:
  - Fix request filter function being called with response user
    data
  - Fix response bodies never being logged if request bodies
    aren't
  - Add Soup-Host to logged headers for when Host is missing
    + cookies:
  - Fix incorrect logic in determining same-site cookies
  - Limit the Max-Age to 1 year
    + cookie-jar-db: Explicitly handle old databases lacking
    same-site column

++++ systemd:

  - Move 80-container-host0.network back to the network sub-package (bsc#1229098)
    Rev 428 mistakenly moved it to the container sub-package.

++++ rsync:

  - add patch rsync-run-dir.patch:
    * Drop dependency on /var/run compat symlink, this causes problems
    on image based systems

++++ systemd-presets-common-SUSE:

  - Enable soft-reboot-cleanup.service to make soft-reboot possible
    with container and/or firewalld.

++++ virt-manager:

  - Solve bsc#1228384 --dry-run creating pools in a different way
    virtinst-dont-create-storage-pool-for-dryrun.patch

++++ xfsprogs:

  - update to 6.10.0
  - debian: enable xfs_scrub_all systemd timer services by default
  - mkfs: set autofsck filesystem property
  - xfs_scrub: use the autofsck fsproperty to select mode
  - xfs_scrub: allow sysadmin to control background scrubs
  - xfs_property: add a new tool to administer fs properties
  - xfs_db: add a command to list xattrs
  - xfs_db: improve getting and setting extended attributes
  - xfs_io: edit filesystem properties
  - xfs_scrub: defer phase5 file scans if dirloop fails
  - xfs_repair: wipe ondisk parent pointers when there are none
  - xfs_scrub: detect and repair directory tree corruptions
  - xfs_repair: update ondisk parent pointer records
  - xfs_spaceman: report directory tree corruption in the health information
  - xfsprogs: support vectored scrub
  - man: document vectored scrub mode
  - man2: update ioctl_xfs_scrub_metadata.2 for parent pointers
  - mkfs: enable formatting with parent pointers
  - mkfs: Add parent pointers during protofile creation
  - xfs_repair: check parent pointers
  - xfs_db: compute hashes of parent pointers
  - xfs_db: add link and unlink expert commands
  - xfs_repair: build a parent pointer index
  - xfs_db: add a parents command to list the parents of a file
  - xfs_db: obfuscate dirent and parent pointer names consistently
  - xfs_db: report parent pointers embedded in xattrs
  - xfs_db: report parent bit on xattrs
  - xfs_db: report parent pointers in version command
  - xfs_scrub: use parent pointers to report lost file data
  - xfs_scrub: use parent pointers when possible to report file operations
  - xfs_logprint: decode parent pointers in ATTRI items fully
  - xfs_io: Add i, n and f flags to parent command
  - xfs_io: adapt parent command to new parent pointer ioctls
  - libfrog: report parent pointers to userspace
  - libfrog: add parent pointer support code
  - man: document the XFS_IOC_GETPARENTS ioctl
  - xfs_logprint: dump new attr log item fields
  - xfs_scrub_all: failure reporting for the xfs_scrub_all job
  - xfs_repair: check free space requirements before allowing upgrades
  - xfs_scrub_all: convert systemctl calls to dbus
  - xfs_scrub_all: trigger automatic media scans once per month
  - xfs_scrub: add an optimization-only mode
  - xfs_scrub_all: add CLI option for easier debugging
  - xfs_scrub_all: enable periodic file data scrubs automatically
  - xfs_scrub: automatic downgrades to dry-run mode in service mode
  - xfs_scrub_all: support metadata+media scans of all filesystems
  - xfs_scrub_all: fail fast on masked units
  - xfs_scrub_all: remove journalctl background process
  - xfs_scrub_all: only use the xfs_scrub@ systemd services in service mode
  - xfs_scrub: tune fstrim minlen parameter based on free space histograms
  - xfs_scrub: improve responsiveness while trimming the filesystem
  - xfs_scrub: tighten up the security on the background systemd service
  - xfs_scrub: don't call FITRIM after runtime errors
  - xfs_scrub: use dynamic users when running as a systemd service
  - xfs_scrub: report FITRIM errors properly
  - xfs_scrub.service: reduce background CPU usage to less than one core if possible
  - xfs_scrub: don't close stdout when closing the progress bar
  - xfs_scrub: fix the work estimation for phase 8
  - libfrog: print cdf of free space buckets
  - libfrog: print wider columns for free space histogram
  - xfs_scrub: ignore phase 8 if the user disabled fstrim
  - xfs_scrub: move FITRIM to phase 8
  - xfs_scrub: improve thread scheduling repair items during phase 4
  - xfs_scrub: avoid potential UAF after freeing a duplicate name entry
  - xfs_scrub: enable users to bump information messages to warnings
  - xfs_scrub: retry incomplete repairs
  - xfs_scrub: warn about difficult repairs to rt and quota metadata
  - xfs_scrub: any inconsistency in metadata should trigger difficulty warnings
  - mkfs: add a formatting option for exchange-range
  - xfs_repair: add exchange-range to file systems
  - xfs_scrub: fix missing scrub coverage for broken inodes
  - xfs_scrub: log when a repair was unnecessary
  - libfrog: advertise exchange-range support
  - xfs_io: create exchangerange command to test file range exchange ioctl
  - xfs_fsr: skip the xattr/forkoff levering with the newer swapext implementations
  - xfs_fsr: convert to bulkstat v5 ioctls
  - xfs_logprint: support dumping exchmaps log items
  - xfs_db: advertise exchange-range in the version command
  - libfrog: add support for exchange range ioctl family
  - libhandle: add support for bulkstat v5
  - man: document XFS_FSOP_GEOM_FLAGS_EXCHRANGE
  - man: document the exchange-range ioctl
  - xfs_repair: don't crash on -vv
  - xfsprogs: Remove support for split-/usr installs
  - libxfs: kernel sync
  - ------------------------------------------------------------------

------------------------------------------------------------------
------------------  2024-8-25  -  Aug 25 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Fix random GPU crash with AMDGPU (bsc#1229050):
    U_radeonsi-vcn-Add-decode-DPB-buffers-as-CS-dependency.patch
    (credits go to Takashi Iwai!)

++++ Mesa-drivers:

  - Fix random GPU crash with AMDGPU (bsc#1229050):
    U_radeonsi-vcn-Add-decode-DPB-buffers-as-CS-dependency.patch
    (credits go to Takashi Iwai!)

++++ python-kiwi:

  - Add support for isomd5sum for tagging iso files
    The isomd5sum tool suite is used and available on all supported
    distributions except SUSE distributions, and is necessary to produce
    conformant ISOs for most Linux distributions.
    This change adds support for isomd5sum tool suite for kiwi, though
    it does not extend the kiwi-live dracut module to use it. The upstream
    dracut dmsquash-live module must be used instead.
    Co-authored-by: Dan Čermák <dcermak@suse.com>

++++ gsettings-desktop-schemas:

  - Update to version 47.beta:
    + Add break-reminder schema
    + Provide a new pressure range for styli
    + Add SwitchMonitor and Keybinding to the tablet stylus actions
    + Switch back to Cantarell font
    + Updated translations.
  - Changes from version 47.alpha:
    + Add key to tweak font rendering
    + Include Settings in sort order
    + Add key to pick accent color
    + Updated translations.
  - Rebase patch.

++++ nvidia-open-driver-G06-signed:

  - For CUDA update version to 560.35.03

++++ python-maturin:

  - Update to 1.7.1
    * Update clap_complete_command to v0.6.1
    gh#PyO3/maturin#2144
    * Fix platform tags when cross-compiling universal2
    gh#PyO3/maturin#2153
    * Fix Typo in Migration Guide
    gh#PyO3/maturin#2162
    * Fix rust 1.80 clippy errors
    gh#PyO3/maturin#2164
    * Don't check .gitignore files in parent directories
    gh#PyO3/maturin#2158
    * Replace --skip-auditwheel with --auditwheel option
    gh#PyO3/maturin#2165
    * Remove install_requires and setup_requires from setup.py
    gh#PyO3/maturin#2171
    * Use modern stripping option
    gh#PyO3/maturin#2173
    * Move project metadata from setup.py to pyproject.toml
    gh#PyO3/maturin#2175
    * Update manylinux/musllinux policies to the latest main
    gh#PyO3/maturin#2178
    * use just licenses as the license directory in a wheel
    gh#PyO3/maturin#2181
    * Forward cargo package --list warnings
    gh#PyO3/maturin#2186
    * Add current package context to source dist error
    gh#PyO3/maturin#2187
    * Place source dist readmes next to Cargo.toml
    gh#PyO3/maturin#2184

++++ tuned:

  - Migrate profiles to /etc/tuned/profiles/ and /usr/lib/tuned/profiles/
    * Per upstream #615 and #609
  - Update to version 2.24.0.2+git.c082797:
    * controller init: set _on_battery before switching profile
  - New release (2.24.0)
    * Clear plugin repository when stopping tuning
    * man: add description of the balanced-battery profile
  - New release (2.24.0-rc.1)
    * chore: remove dead irqbalance functions
    * plugin_irqbalance: switch to IRQBALANCE_BANNED_CPULIST
    * hotplug: wait for device initialization
    * Add `functions` to the files copied by the release-cp Makefile target
    * Add package2cpus and packages2uncores matcher functions
    * uncore: Allow to configure frequency limits using percent
    * plugin_scheduler: Adjust error logging in _set_affinity
    * fix: expand variables in plugin_irq
    * tests: Restore TuneD service after the error messages test
    * tests: Do not run tunedDisableSystemdRateLimitingStart via rlRun
    * Enable controller reset for audio by default
    * tuned-ppd: Adjust log message emitted when battery status changes
    * tuned-ppd: Refactor daemon initialization
    * tuned-ppd: Remove magic constant "unknown"
    * Add support for controlling amd-pstate core performance boost
    * spec: Start tuned-ppd right away if swapping from active PPD
    * spec: Add standard systemd scriptlet macros for tuned-ppd
    * tuned-ppd: Remove PIDFile from the systemd service file
    * tuned-ppd: Add an option to log to a file
    * Install script functions and recommend.d to /usr/lib/tuned/
    * Rename TUNED_PROFILESDIR to TUNED_PROFILES_DIR
    * CNF-13015: Fix helper function not accessing the correct return result
    * CNF-13015: Add helper function to run `lscpu` and parse result using regex
    parameters - This is similar to the cpuinfo function that reads from
    /proc/cpuinfo - Unfortunately that function was insufficient for our needs
    as we need to identify both the Vendor and Architecture reliably

------------------------------------------------------------------
------------------  2024-8-24  -  Aug 24 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - kiwi/builder/live: Log the correct value for Application ID
    Since it is now possible to set a custom application ID, we want
    to see this when it is being used for the image.
  - kiwi/builder/live: Clean up leftover dracut configuration file
    The existence of this file breaks installers on live media that
    sync the full filesystem to disk and are not aware of this configuration
    before generating the target system initramfs.

++++ kernel-default:

  - nouveau/firmware: use dma non-coherent allocator (git-fixes).
  - drm/amdgpu/sdma5.2: limit wptr workaround to sdma 5.2.1
    (git-fixes).
  - drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails
    (git-fixes).
  - drm/msm/dp: reset the link phy params before link training
    (git-fixes).
  - drm/msm/dp: fix the max supported bpp logic (git-fixes).
  - drm/msm/dpu: don't play tricks with debug macros (git-fixes).
  - mmc: mmc_test: Fix NULL dereference on allocation failure
    (git-fixes).
  - mmc: dw_mmc: allow biu and ciu clocks to defer (git-fixes).
  - mmc: mtk-sd: receive cmd8 data when hs400 tuning fail
    (git-fixes).
  - commit ec72baf

++++ kernel-rt:

  - nouveau/firmware: use dma non-coherent allocator (git-fixes).
  - drm/amdgpu/sdma5.2: limit wptr workaround to sdma 5.2.1
    (git-fixes).
  - drm/msm/dpu: cleanup FB if dpu_format_populate_layout fails
    (git-fixes).
  - drm/msm/dp: reset the link phy params before link training
    (git-fixes).
  - drm/msm/dp: fix the max supported bpp logic (git-fixes).
  - drm/msm/dpu: don't play tricks with debug macros (git-fixes).
  - mmc: mmc_test: Fix NULL dereference on allocation failure
    (git-fixes).
  - mmc: dw_mmc: allow biu and ciu clocks to defer (git-fixes).
  - mmc: mtk-sd: receive cmd8 data when hs400 tuning fail
    (git-fixes).
  - commit ec72baf

------------------------------------------------------------------
------------------  2024-8-23  -  Aug 23 2024  -------------------
------------------------------------------------------------------

++++ dracut:

  - Update to version 059+suse.598.g824fcff4:
    * fix(dracut): ldd output borked with `--sysroot` (bsc#1228659)
    * feat(systemd*): include systemd config files from /usr/lib/systemd (bsc#1228398)
    * fix(dracut-functions.sh): only return block devices from get_persistent_dev
    * fix(convertfs): shellcheck
    * fix(convertfs): error in conditional expressions (bsc#1228847)

++++ python-kiwi:

  - Allow string versions and test "word" versions
    There are descriptions out in the wild that use "non-numeric" versions
    in their descriptions, particularly without separators for splitting.
    This change switches all of this to strings rather than assuming
    numbers and gracefully handles the single word case.

++++ gstreamer:

  - Update to version 1.24.7:
    + Highlighted bugfixes:
  - Fix APE and Musepack audio file and GIF playback with FFmpeg
    7.0
  - playbin3: Fix potential deadlock with multiple playbin3s with
    glimagesink used in parallel
  - qt6: various qmlgl6src and qmlgl6sink fixes and improvements
  - rtspsrc: expose property to force usage of non-compliant
    setup URLs for RTSP servers where the automatic fallback
    doesn't work
  - urisourcebin: gapless playback and program switching fixes
  - v4l2: various fixes
  - va: Fix potential deadlock with multiple va elements used in
    parallel
  - meson: option to disable gst-full for static-library build
    configurations that do not need this
  - Various bug fixes, memory leak fixes, and other stability and
    reliability improvements
    + gstreamer:
  - bin: Don't keep the object lock while setting a GstContext
    when handling NEED_CONTEXT
  - core: Log pad name, not just the pointer

++++ gstreamer-plugins-base:

  - Update to version 1.24.7:
    + pbutils: descriptions: use subsampling factor to get YUV
    subsampling
    + rtspconnection: Handle invalid argument properly
    + urisourcebin:
  - Actually drop EOS on old-school pad switch
  - Don't hold lock when emitting about-to-finish
    + gst-launch deadlock with two playbin3s
    + xvimagesink: Fix crash in pool on error

++++ kernel-default:

  - filelock: Fix fcntl/close race recovery compat path (bsc#1228427
    CVE-2024-41020).
  - commit 2c615e8
  - vfio/pci: fix potential memory leak in vfio_intx_enable()
    (git-fixes).
  - commit 45c2786
  - vfio: Introduce interface to flush virqfd inject workqueue
    (CVE-2024-26812 bsc#1222808).
  - commit 0704da7
  - vfio/pci: Create persistent INTx handler (CVE-2024-26812
    bsc#1222808).
  - commit c0eeff7
  - netfilter: nf_tables: discard table flag update with pending
    basechain deletion (CVE-2024-35897 bsc#1224510).
  - netfilter: nf_tables: reject table flag and netdev basechain
    updates (CVE-2024-35897 bsc#1224510).
  - commit bc3bca5
  - kabi: restore const specifier in flow_offload_route_init()
    (CVE-2024-27403 bsc#1224415).
  - netfilter: nft_flow_offload: reset dst in route object after
    setting up flow (CVE-2024-27403 bsc#1224415).
  - commit f1d28bc
  - Bluetooth: MGMT: Add error handling to pair_device()
    (git-fixes).
  - Bluetooth: SMP: Fix assumption of Central always being Initiator
    (git-fixes).
  - Bluetooth: hci_core: Fix LE quote calculation (git-fixes).
  - commit 82ede4a
  - netfilter: nf_tables: fix memleak in map from abort path
    (CVE-2024-27011 bsc#1223803).
  - commit df3e052
  - KVM: Reject overly excessive IDs in KVM_CREATE_VCPU (git-fixes).
  - commit acfc6dd
  - KVM: arm64: Fix __pkvm_init_switch_pgd call ABI (git-fixes).
  - commit ca5dde8
  - KVM: Stop processing *all* memslots when "null" mmu_notifier
    handler is found (git-fixes).
  - commit edcaf30
  - virt: guest_memfd: fix reference leak on hwpoisoned page
    (git-fixes).
  - commit 7ac89c3
  - KVM: arm64: AArch32: Fix spurious trapping of conditional
    instructions (git-fixes).
  - commit 6b4a32b
  - KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
    (git-fixes).
  - commit d2c979d

++++ kernel-rt:

  - filelock: Fix fcntl/close race recovery compat path (bsc#1228427
    CVE-2024-41020).
  - commit 2c615e8
  - vfio/pci: fix potential memory leak in vfio_intx_enable()
    (git-fixes).
  - commit 45c2786
  - vfio: Introduce interface to flush virqfd inject workqueue
    (CVE-2024-26812 bsc#1222808).
  - commit 0704da7
  - vfio/pci: Create persistent INTx handler (CVE-2024-26812
    bsc#1222808).
  - commit c0eeff7
  - netfilter: nf_tables: discard table flag update with pending
    basechain deletion (CVE-2024-35897 bsc#1224510).
  - netfilter: nf_tables: reject table flag and netdev basechain
    updates (CVE-2024-35897 bsc#1224510).
  - commit bc3bca5
  - kabi: restore const specifier in flow_offload_route_init()
    (CVE-2024-27403 bsc#1224415).
  - netfilter: nft_flow_offload: reset dst in route object after
    setting up flow (CVE-2024-27403 bsc#1224415).
  - commit f1d28bc
  - Bluetooth: MGMT: Add error handling to pair_device()
    (git-fixes).
  - Bluetooth: SMP: Fix assumption of Central always being Initiator
    (git-fixes).
  - Bluetooth: hci_core: Fix LE quote calculation (git-fixes).
  - commit 82ede4a
  - netfilter: nf_tables: fix memleak in map from abort path
    (CVE-2024-27011 bsc#1223803).
  - commit df3e052
  - KVM: Reject overly excessive IDs in KVM_CREATE_VCPU (git-fixes).
  - commit acfc6dd
  - KVM: arm64: Fix __pkvm_init_switch_pgd call ABI (git-fixes).
  - commit ca5dde8
  - KVM: Stop processing *all* memslots when "null" mmu_notifier
    handler is found (git-fixes).
  - commit edcaf30
  - virt: guest_memfd: fix reference leak on hwpoisoned page
    (git-fixes).
  - commit 7ac89c3
  - KVM: arm64: AArch32: Fix spurious trapping of conditional
    instructions (git-fixes).
  - commit 6b4a32b
  - KVM: arm64: Allow AArch32 PSTATE.M to be restored as System mode
    (git-fixes).
  - commit d2c979d

++++ llvm19:

  - Split off clang shared runtime libraries into libclang_rtX, so
    that they can be used by other packages without requiring the
    entire compiler tool chain. This is still not ergonomical: the
    libraries don't sit in %{_libdir}, so an RPATH or setting
    LD_LIBRARY_PATH is required, and they don't have an SO version,
    so zypper won't know which version to is needed. (boo#1225784)

++++ openssh:

  - Add patch to fix sshd not logging in the audit failed login
    attempts (submitted to upstream in
    https://github.com/openssh/openssh-portable/pull/516):
    * fix-audit-fail-attempt.patch
  - Use --enable-dsa-keys when building openssh. It's required if
    the user sets the crypto-policy mode to LEGACY, where DSA keys
    should be allowed. The option was added by upstream in 9.7 and
    set to disabled by default.
  - These two changes fix 2 of the 3 issues reported in bsc#1229650.

------------------------------------------------------------------
------------------  2024-8-22  -  Aug 22 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Add NetworkManager-dont-enforce-ip-cleanup-on-device-deactivating.patch:
    device: don't enforce IP cleanup on deactivating state
    (bsc#1228154, glfd#NetworkManager/NetworkManager!2016).

++++ dpdk:

  - Update to LTS release version v22.11.6
    * http://doc.dpdk.org/guides-22.11/rel_notes/release_22_11.html
  - Drop patch (included upstream):
    * kni-fix-build-with-Linux-6.8.patch (22.11.6)

++++ fwupd:

  - Update to version 1.9.24:
    + This release fixes the following bugs:
  - Add support for capsule on disk for Dell systems
  - Do not re-use the connection cache to fix Redfish BMC restart
  - Exclude known recovery partitions when choosing an ESP volume
  - Fix the VLI usb3 private flag registration
    + This release adds support for the following hardware:
  - More Mediatek scaler devices
  - Parade USB hubs

++++ kernel-default:

  - KVM: arm64: Fix AArch32 register narrowing on userspace write
    (git-fixes).
  - commit c002253
  - KVM: fix kvm_mmu_memory_cache allocation warning (git-fixes).
  - commit 9570c83
  - KVM: Always flush async #PF workqueue when vCPU is being
    destroyed (git-fixes).
  - commit bbeeae4
  - iommu: Add static iommu_ops->release_domain (bsc#1223742
    CVE-2024-27079).
  - iommu/vt-d: Fix NULL domain on device release (bsc#1223742
    CVE-2024-27079).
  - Refresh
    patches.suse/iommu-vt-d-Fix-WARN_ON-in-iommu-probe-path.patch.
  - commit 5ddde3c
  - KVM: Make KVM_MEM_GUEST_MEMFD mutually exclusive with
    KVM_MEM_READONLY (git-fixes).
  - commit 7a71a2a
  - KVM: arm64: vgic-its: Test for valid IRQ in MOVALL handler
    (git-fixes).
  - commit ebc54df
  - KVM: arm64: vgic-its: Test for valid IRQ in
    its_sync_lpi_pending_table() (git-fixes).
  - commit 989930f
  - KVM: arm64: Add missing memory barriers when switching to
    pKVM's hyp pgd (git-fixes).
  - commit 5599b84
  - KVM: arm64: vgic-v4: Restore pending state on host userspace
    write (git-fixes).
  - commit ba9826d
  - KVM: arm64: vgic: Force vcpu vgic teardown on vcpu destroy
    (git-fixes).
  - commit 26e04aa
  - KVM: arm64: vgic: Add a non-locking primitive for
    kvm_vgic_vcpu_destroy() (git-fixes).
  - commit 686bc1c
  - netfilter: nft_limit: reject configurations that cause integer
    overflow (CVE-2024-26668 bsc#1222335).
  - commit 8ea214b
  - netfilter: nf_tables: set dormant flag on hook register failure
    (CVE-2024-26835 bsc#1222967).
  - commit 8f4d028
  - KVM: arm64: vgic: Simplify kvm_vgic_destroy() (git-fixes).
  - commit 3a96863
  - Revert "KVM: Prevent module exit until all VMs are freed"
    (git-fixes).
  - commit c075225
  - netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for
    inet/ingress basechain (CVE-2024-26808 bsc#1222634).
  - commit 7f0379b
  - KVM: arm64: GICv4: Do not perform a map to a mapped vLPI
    (git-fixes).
  - commit 919175d
  - netfilter: nft_set_pipapo: release elements in clone only from
    destroy path (CVE-2024-26809 bsc#1222633).
  - commit d3a3287
  - KVM: arm64: vgic-v2: Use cpuid from userspace as vcpu_id
    (git-fixes).
  - commit 7b3deae
  - KVM: arm64: timers: Correctly handle TGE flip with CNTPOFF_EL2
    (git-fixes).
  - commit 48c0cad
  - netfilter: nf_tables: fix memleak when more than 255 elements
    expired (CVE-2023-52581 bsc#1220877).
  - commit 26441fd
  - KVM: Protect vcpu->pid dereference via debugfs with RCU
    (git-fixes).
  - commit 55ae2a6
  - KVM: arm64: timers: Fix resource leaks in kvm_timer_hyp_init()
    (git-fixes).
  - commit f80cefe
  - bpf: Fix updating attached freplace prog in prog_array map
    (bsc#1229297 CVE-2024-43837).
  - commit a9d7d77
  - dma-direct: Leak pages on dma_set_decrypted() failure (bsc#1224535 CVE-2024-35939).
  - commit 7de8166
  - ice: Add a per-VF limit on number of FDIR filters
    (CVE-2024-42291 bsc#1229374).
  - commit ee2b93b
  - net/mlx5: Fix missing lock on sync reset reload (CVE-2024-42268
    bsc#1229391).
  - commit 268cdf6
  - selftests/bpf: Add a test to verify previous stacksafe() fix
    (bsc#1225903).
  - bpf: Fix a kernel verifier crash in stacksafe() (bsc#1225903).
  - commit dab2844
  - xdp: fix invalid wait context of page_pool_destroy() (CVE-2024-43834 bsc#1229314)
  - commit 6348ec4
  - clk: mediatek: mt7622-apmixedsys: Fix an error handling path
    in clk_mt8135_apmixed_probe() (bsc#1224711 CVE-2024-27433).
  - commit 30e1ef1
  - netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu() (CVE-2024-36286 bsc#1226801)
  - commit 3278d5d
  - netfilter: tproxy: bail out if IP has been disabled on the device (CVE-2024-36270 1226798)
  - commit 26814d6
  - netfilter: nf_conntrack_h323: Add protection for bmp length out of range (CVE-2024-26851 bsc#1223074)
  - commit 6ad2cbe

++++ kernel-rt:

  - KVM: arm64: Fix AArch32 register narrowing on userspace write
    (git-fixes).
  - commit c002253
  - KVM: fix kvm_mmu_memory_cache allocation warning (git-fixes).
  - commit 9570c83
  - KVM: Always flush async #PF workqueue when vCPU is being
    destroyed (git-fixes).
  - commit bbeeae4
  - iommu: Add static iommu_ops->release_domain (bsc#1223742
    CVE-2024-27079).
  - iommu/vt-d: Fix NULL domain on device release (bsc#1223742
    CVE-2024-27079).
  - Refresh
    patches.suse/iommu-vt-d-Fix-WARN_ON-in-iommu-probe-path.patch.
  - commit 5ddde3c
  - KVM: Make KVM_MEM_GUEST_MEMFD mutually exclusive with
    KVM_MEM_READONLY (git-fixes).
  - commit 7a71a2a
  - KVM: arm64: vgic-its: Test for valid IRQ in MOVALL handler
    (git-fixes).
  - commit ebc54df
  - KVM: arm64: vgic-its: Test for valid IRQ in
    its_sync_lpi_pending_table() (git-fixes).
  - commit 989930f
  - KVM: arm64: Add missing memory barriers when switching to
    pKVM's hyp pgd (git-fixes).
  - commit 5599b84
  - KVM: arm64: vgic-v4: Restore pending state on host userspace
    write (git-fixes).
  - commit ba9826d
  - KVM: arm64: vgic: Force vcpu vgic teardown on vcpu destroy
    (git-fixes).
  - commit 26e04aa
  - KVM: arm64: vgic: Add a non-locking primitive for
    kvm_vgic_vcpu_destroy() (git-fixes).
  - commit 686bc1c
  - netfilter: nft_limit: reject configurations that cause integer
    overflow (CVE-2024-26668 bsc#1222335).
  - commit 8ea214b
  - netfilter: nf_tables: set dormant flag on hook register failure
    (CVE-2024-26835 bsc#1222967).
  - commit 8f4d028
  - KVM: arm64: vgic: Simplify kvm_vgic_destroy() (git-fixes).
  - commit 3a96863
  - Revert "KVM: Prevent module exit until all VMs are freed"
    (git-fixes).
  - commit c075225
  - netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for
    inet/ingress basechain (CVE-2024-26808 bsc#1222634).
  - commit 7f0379b
  - KVM: arm64: GICv4: Do not perform a map to a mapped vLPI
    (git-fixes).
  - commit 919175d
  - netfilter: nft_set_pipapo: release elements in clone only from
    destroy path (CVE-2024-26809 bsc#1222633).
  - commit d3a3287
  - KVM: arm64: vgic-v2: Use cpuid from userspace as vcpu_id
    (git-fixes).
  - commit 7b3deae
  - KVM: arm64: timers: Correctly handle TGE flip with CNTPOFF_EL2
    (git-fixes).
  - commit 48c0cad
  - netfilter: nf_tables: fix memleak when more than 255 elements
    expired (CVE-2023-52581 bsc#1220877).
  - commit 26441fd
  - KVM: Protect vcpu->pid dereference via debugfs with RCU
    (git-fixes).
  - commit 55ae2a6
  - KVM: arm64: timers: Fix resource leaks in kvm_timer_hyp_init()
    (git-fixes).
  - commit f80cefe
  - bpf: Fix updating attached freplace prog in prog_array map
    (bsc#1229297 CVE-2024-43837).
  - commit a9d7d77
  - dma-direct: Leak pages on dma_set_decrypted() failure (bsc#1224535 CVE-2024-35939).
  - commit 7de8166
  - ice: Add a per-VF limit on number of FDIR filters
    (CVE-2024-42291 bsc#1229374).
  - commit ee2b93b
  - net/mlx5: Fix missing lock on sync reset reload (CVE-2024-42268
    bsc#1229391).
  - commit 268cdf6
  - selftests/bpf: Add a test to verify previous stacksafe() fix
    (bsc#1225903).
  - bpf: Fix a kernel verifier crash in stacksafe() (bsc#1225903).
  - commit dab2844
  - xdp: fix invalid wait context of page_pool_destroy() (CVE-2024-43834 bsc#1229314)
  - commit 6348ec4
  - clk: mediatek: mt7622-apmixedsys: Fix an error handling path
    in clk_mt8135_apmixed_probe() (bsc#1224711 CVE-2024-27433).
  - commit 30e1ef1
  - netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu() (CVE-2024-36286 bsc#1226801)
  - commit 3278d5d
  - netfilter: tproxy: bail out if IP has been disabled on the device (CVE-2024-36270 1226798)
  - commit 26814d6
  - netfilter: nf_conntrack_h323: Add protection for bmp length out of range (CVE-2024-26851 bsc#1223074)
  - commit 6ad2cbe

++++ openssl-3:

  - Security fix: [bsc#1229465, CVE-2024-6119]
    * possible denial of service in X.509 name checks
    * openssl-CVE-2024-6119.patch

++++ passt:

  - Update to version 20240821.1d6142f:
    * README: pasta is indeed a supported back-end for rootless Docker
    * util: Don't stop on unrelated values when looking for --fd in close_open_files()
    * test: Update list of dependencies in README.md
    * tcp, udp: Allow timerfd_gettime64() and recvmmsg_time64() on arm (armhf)
    * util: Provide own version of close_range(), and no-op fallback
    * udp_flow: Add missing unistd.h include for close()
    * test: Duplicate existing recvfrom() valgrind suppression for recv()
    * test/passt.mbuto: Install sshd-session OpenSSH's split process
    * test/passt.mbuto: Run sshd from vsock proxy with absolute path
    * test/lib/setup: Transform i686 kernel architecture name into QEMU name (i386)
    * treewide: Allow additional system calls for i386/i686
    * fwd, conf: Allow NAT of the guest's assigned address
    * fwd: Distinguish translatable from untranslatable addresses on inbound
    * conf: Allow address remapped to host to be configured
    * test: Reconfigure IPv6 address after changing MTU
    * conf, fwd: Split notion of gateway/router from guest-visible host address
    * Don't take "our" MAC address from the host
    * fwd: Split notion of "our tap address" from gateway for IPv4
    * fwd: Helpers to clarify what host addresses aren't guest accessible
    * Initialise our_tap_ll to ip6.gw when suitable
    * Clarify which addresses in ip[46]_ctx are meaningful where
    * treewide: Change misleading 'addr_ll' name
    * util: Correct sock_l4() binding for link local addresses
    * conf: Remove incorrect initialisation of addr_ll_seen
    * conf: Treat --dns addresses as guest visible addresses
    * conf: Correct setting of dns_match address in add_dns6()
    * conf: Move adding of a nameserver from resolv.conf into subfunction
    * conf: Move DNS array bounds checks into add_dns[46]
    * conf: More accurately count entries added in get_dns()
    * conf: Use array indices rather than pointers for DNS array slots
    * treewide: Use struct assignment instead of memcpy() for IP addresses
    * treewide: Rename MAC address fields for clarity
    * util: Helper for formatting MAC addresses
    * treewide: Use "our address" instead of "forwarding address"
    * netlink: Fix typo in function comment for nl_addr_set()
    * pasta: Disable neighbour solicitations on device up to prevent DAD
    * netlink, pasta: Fetch link-local address from namespace interface once it's up
    * netlink, pasta: Disable DAD for link-local addresses on namespace interface
    * netlink, pasta: Turn nl_link_up() into a generic function to set link flags
    * netlink, pasta: Split MTU setting functionality out of nl_link_up()
    * netlink: Fix typo in function comment for nl_addr_get()
    * test: Speed up by cutting on eye candy and performance test duration

++++ virt-manager:

  - Upstream bug fixes (bsc#1027942) (jsc#PED-8910)
    094-uitests-handle-newer-libvirt-test-driver-UpdateDevice-support.patch
    095-uitests-force-internal-snapshots-in-test_snapshot.py.patch

------------------------------------------------------------------
------------------  2024-8-21  -  Aug 21 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - fix build with current rust-bindgen
    * u_fix_rust_bindgen.patch

++++ Mesa-drivers:

  - fix build with current rust-bindgen
    * u_fix_rust_bindgen.patch

++++ aaa_base:

  - Update to version 84.87+git20240821.fbabe1d:
    * Add helper service for soft-reboot

++++ ca-certificates:

  - Fix source archive

++++ combustion:

  - Update to version 1.4+git8:
    * Avoid misleading "Application returned with exit status 1" message
    * CI: Add an ignition config which mounts /sysroot/home
    * Bind mount API filesystems individually
    * Check for leftover /sysroot mounts on combustion exit

++++ dhcpcd:

  - Update to 10.0.10
    * Option 2: Fix stdin parsing
    * IPv4LL: Restart ARP probling on address conflict
    * DHCP: Handle option 108 correctly when receiving 0.0.0.0 OFFER
    * DHCP: No longer set interface mtu
    * Update privsep-linux.c to allow statx

++++ gstreamer-plugins-base:

  - Add gst-plugins-base-decodebin3-collection-identity-check.patch:
  - Fixes a assertion causing crash on track change. Upstream bug:
    https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/3742

++++ kernel-default:

  - net: bridge: mst: fix suspicious rcu usage in br_mst_set_state
    (CVE-2024-40920 bsc#1227781).
  - net: bridge: mst: pass vlan group directly to
    br_mst_vlan_set_state (CVE-2024-40921 bsc#1227784).
  - net: bridge: mst: fix vlan use-after-free (CVE-2024-36979
    bsc#1226604).
  - commit 7beae73
  - erofs: fix inconsistent per-file compression format (bsc#1220252, CVE-2024-26590).
  - commit 4f99bd1
  - perf: hisi: Fix use-after-free when register pmu fails
    (bsc#1225582 CVE-2023-52859).
  - commit a50ce06
  - printk/panic: Allow cpu backtraces to be written into ringbuffer
    during panic (bsc#1225607).
  - commit 1ebfff4
  - net: drop bad gso csum_start and offset in virtio_net_hdr
    (git-fixes).
  - commit 6d27b13
  - selftests/bpf: Test for null-pointer-deref bugfix in
    resolve_prog_type() (bsc#1229297 CVE-2024-43837).
  - bpf: Fix null pointer dereference in resolve_prog_type()
    for BPF_PROG_TYPE_EXT (bsc#1229297 CVE-2024-43837).
  - commit 37e60d8
  - bpf: simplify btf_get_prog_ctx_type() into
    btf_is_prog_ctx_type() (git-fixes).
  - Refresh patches.suse/bpf-don-t-infer-PTR_TO_CTX-for-programs-with-unnamed.patch
  - Refresh patches.suse/bpf-handle-bpf_user_pt_regs_t-typedef-explicitly-for.patch
  - bpf: extract bpf_ctx_convert_map logic and make it more reusable
    (git-fixes).
  - Refresh patches.suse/bpf-handle-bpf_user_pt_regs_t-typedef-explicitly-for.patch
  - commit a1a0c24
  - vhost: Release worker mutex during flushes (git-fixes).
  - commit be0d4d9
  - virtio: reenable config if freezing device failed (git-fixes).
  - commit d96d64e
  - kabi fix for SUNRPC: add a missing rpc_stat for TCP TLS
    (git-fixes).
  - SUNRPC: add a missing rpc_stat for TCP TLS (git-fixes).
  - commit 4fa6f6d
  - netfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init() (CVE-2024-42270 bsc#1229404)
  - commit eb407e1
  - netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init() (CVE-2024-42269 bsc#1229402)
  - commit 6f31e8c
  - tipc: Return non-zero value from tipc_udp_addr2str() on error (CVE-2024-42284 bsc#1229382)
  - commit 003e7ab
  - net: nexthop: Initialize all fields in dumped nexthops (CVE-2024-42283 bsc#1229383)
  - commit dd830eb
  - sysctl: always initialize i_uid/i_gid (CVE-2024-42312 bsc#1229357)
  - commit 683a109
  - block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854 bsc#1229345)
  - commit bc065ac

++++ kernel-rt:

  - net: bridge: mst: fix suspicious rcu usage in br_mst_set_state
    (CVE-2024-40920 bsc#1227781).
  - net: bridge: mst: pass vlan group directly to
    br_mst_vlan_set_state (CVE-2024-40921 bsc#1227784).
  - net: bridge: mst: fix vlan use-after-free (CVE-2024-36979
    bsc#1226604).
  - commit 7beae73
  - erofs: fix inconsistent per-file compression format (bsc#1220252, CVE-2024-26590).
  - commit 4f99bd1
  - perf: hisi: Fix use-after-free when register pmu fails
    (bsc#1225582 CVE-2023-52859).
  - commit a50ce06
  - printk/panic: Allow cpu backtraces to be written into ringbuffer
    during panic (bsc#1225607).
  - commit 1ebfff4
  - net: drop bad gso csum_start and offset in virtio_net_hdr
    (git-fixes).
  - commit 6d27b13
  - selftests/bpf: Test for null-pointer-deref bugfix in
    resolve_prog_type() (bsc#1229297 CVE-2024-43837).
  - bpf: Fix null pointer dereference in resolve_prog_type()
    for BPF_PROG_TYPE_EXT (bsc#1229297 CVE-2024-43837).
  - commit 37e60d8
  - bpf: simplify btf_get_prog_ctx_type() into
    btf_is_prog_ctx_type() (git-fixes).
  - Refresh patches.suse/bpf-don-t-infer-PTR_TO_CTX-for-programs-with-unnamed.patch
  - Refresh patches.suse/bpf-handle-bpf_user_pt_regs_t-typedef-explicitly-for.patch
  - bpf: extract bpf_ctx_convert_map logic and make it more reusable
    (git-fixes).
  - Refresh patches.suse/bpf-handle-bpf_user_pt_regs_t-typedef-explicitly-for.patch
  - commit a1a0c24
  - vhost: Release worker mutex during flushes (git-fixes).
  - commit be0d4d9
  - virtio: reenable config if freezing device failed (git-fixes).
  - commit d96d64e
  - kabi fix for SUNRPC: add a missing rpc_stat for TCP TLS
    (git-fixes).
  - SUNRPC: add a missing rpc_stat for TCP TLS (git-fixes).
  - commit 4fa6f6d
  - netfilter: iptables: Fix null-ptr-deref in iptable_nat_table_init() (CVE-2024-42270 bsc#1229404)
  - commit eb407e1
  - netfilter: iptables: Fix potential null-ptr-deref in ip6table_nat_table_init() (CVE-2024-42269 bsc#1229402)
  - commit 6f31e8c
  - tipc: Return non-zero value from tipc_udp_addr2str() on error (CVE-2024-42284 bsc#1229382)
  - commit 003e7ab
  - net: nexthop: Initialize all fields in dumped nexthops (CVE-2024-42283 bsc#1229383)
  - commit dd830eb
  - sysctl: always initialize i_uid/i_gid (CVE-2024-42312 bsc#1229357)
  - commit 683a109
  - block: initialize integrity buffer to zero before writing it to media (CVE-2024-43854 bsc#1229345)
  - commit bc065ac

++++ kmod:

  - Update to release 33
    * Add weak dependencies
    * Stop parsing .alias files from modprobe.d directories
  - Delete no-stylesheet-download.patch (merged)
  - Add 0001-testsuite-fix-path-for-test-user.patch

++++ ncurses:

  - Break dependency cycle between libncurses6 which provides "ncurses"
    by only let terminfo-base recommending "ncurses"

------------------------------------------------------------------
------------------  2024-8-20  -  Aug 20 2024  -------------------
------------------------------------------------------------------

++++ cockpit:

  - remove requires on pam_oath completely. It will be re-introduced
    later when it works with optional enrollment
  - add 0005-cockpit-ws-user-remove-default-deps.patch (bsc#1229146)

++++ kernel-default:

  - ipvs: properly dereference pe in ip_vs_add_service (CVE-2024-42322 bsc#1229347)
  - commit 5abcd51
  - vhost-vdpa: switch to use vmf_insert_pfn() in the fault handler
    (git-fixes).
  - commit efaee02
  - net: missing check virtio (git-fixes).
  - commit 547a4d8
  - vhost/vsock: always initialize seqpacket_allow (git-fixes).
  - commit 1501797
  - vhost: Use virtqueue mutex for swapping worker (git-fixes).
  - commit ee31e9d
  - nvme-sysfs: add 'tls_keyring' attribute (bsc#1221857).
  - nvme-sysfs: add 'tls_configured_key' sysfs attribute
    (bsc#1221857).
  - nvme: split off TLS sysfs attributes into a separate group
    (bsc#1221857).
  - nvme: add a newline to the 'tls_key' sysfs attribute
    (bsc#1221857).
  - nvme-tcp: check for invalidated or revoked key (bsc#1221857).
  - nvme-tcp: sanitize TLS key handling (bsc#1221857).
  - nvme: tcp: remove unnecessary goto statement (bsc#1221857).
  - commit 95902b1
  - Refresh patches.suse/nvme-fabrics-typo-in-nvmf_parse_key.patch.
    Move into sorted section.
  - commit 24e43c3
  - vhost-scsi: Handle vhost_vq_work_queue failures for events
    (git-fixes).
  - commit bb54ef9
  - Update DRM patch reference (CVE-2024-42308 bsc#1229411)
  - commit ddc1933
  - Update
    patches.suse/nvme-tcp-fix-compile-time-checks-for-TLS-mode.patch
    (jsc#PED-6252 jsc#PED-5728 jsc#PED-5062 jsc#PED-3535
    bsc#1221857).
    Fix backporting error.
  - commit 35c7df3
  - Update parport patch reference (CVE-2024-42301 bsc#1229407)
  - commit 6707829
  - Refresh
    patches.suse/nvme-tcp-strict-pdu-pacing-to-avoid-send-stalls-on-T.patch.
    Use the version which got upload upstream.
  - commit 4896f98
  - virtio_net: use u64_stats_t infra to avoid data-races
    (git-fixes).
  - commit 1825530
  - usb: typec: fsa4480: Check if the chip is really there
    (git-fixes).
  - commit 771af75
  - usb: typec: fsa4480: Add support to swap SBU orientation
    (git-fixes).
  - commit b744e01
  - usb: typec: fsa4480: add support for Audio Accessory Mode
    (git-fixes).
  - commit 471d14e
  - usb: typec: fsa4480: rework mux & switch setup to handle more
    states (git-fixes).
  - commit dc03605
  - irqchip/imx-irqsteer: Handle runtime power management correctly
    (CVE-2024-42290 bsc#1229379).
  - commit a3bbc63
  - landlock: Don't lose track of restrictions on cred_transfer
    (bsc#1229351 CVE-2024-42318).
  - commit e161e74
  - apparmor: Fix null pointer deref when receiving skb during sock creation (bsc#1229287, CVE-2023-52889).
  - commit 7a47d08
  - kABI fix of: virtio-crypto: handle config changed by work queue
    (git-fixes).
  - commit 2e4646f
  - nvme-multipath: implement "queue-depth" iopolicy (bsc#1227706).
  - nvme-multipath: prepare for "queue-depth" iopolicy
    (bsc#1227706).
  - commit 796fd31
  - nilfs2: handle inconsistent state in nilfs_btnode_create_block()
    (bsc#1229370 CVE-2024-42295).
  - commit 34231c4
  - arm64: dts: imx8mp: Fix pgc vpu locations (git-fixes)
  - commit 6f29859
  - arm64: dts: imx8mp: Fix pgc_mlmix location (git-fixes)
  - commit 6b6ab8a
  - soc: qcom: icc-bwmon: Fix refcount imbalance seen during
    bwmon_remove (CVE-2024-43850 bsc#1229316).
  - soc: qcom: icc-bwmon: Set default thresholds dynamically
    (CVE-2024-43850 bsc#1229316).
  - commit e842a77
  - arm64: dts: imx8mp: add HDMI power-domains (git-fixes)
  - commit 88b7cca
  - arm64: dts: imx8mp: Add NPU Node (git-fixes)
  - commit 55a2e84
  - media: mediatek: vcodec: Handle invalid decoder vsi
    (CVE-2024-43831 bsc#1229309).
  - commit a7b1ec0
  - bna: adjust 'name' buf size of bna_tcb and bna_ccb structures
    (CVE-2024-43839 bsc#1229301).
  - net: mana: Add support for page sizes other than 4KB on ARM64
    (jsc#PED-8491 bsc#1226530).
  - commit 24750b5
  - Squashfs: fix variable overflow triggered by sysbot (git-fixes).
  - commit 90b77e5
  - squashfs: squashfs_read_data need to check if the length is 0
    (git-fixes).
  - commit 1ab3d64
  - jfs: Fix shift-out-of-bounds in dbDiscardAG (git-fixes).
  - commit f862c1b
  - jfs: fix null ptr deref in dtInsertEntry (git-fixes).
  - commit 72d65ab
  - reiserfs: fix uninit-value in comp_keys (git-fixes).
  - commit aeea4b8
  - Update
    patches.suse/0001-netlink-add-nla-be16-32-types-to-minlen-array.patch
    (CVE-2024-26849 bsc#1223053).
    Fixes: 2747893c94d9b55340403026d9430f2f93947449
  - commit 4cf09d7
  - virtio-crypto: handle config changed by work queue (git-fixes).
  - Refresh
    patches.suse/crypto-virtio-Wait-for-tasklet-to-complete-on-device.patch.
  - commit 3719b45
  - fuse: Initialize beyond-EOF page contents before setting
    uptodate (bsc#1229456).
  - fs/netfs/fscache_cookie: add missing "n_accesses" check
    (bsc#1229455).
  - commit 1ffdccd
  - s390/dasd: fix error recovery leading to data corruption on
    ESE devices (git-fixes bsc#1229452).
  - commit 421d882
  - blacklist.conf: Change entry to alt-commit
  - Refresh patches.suse/tools-Disable-__packed-attribute-compiler-warning-due-to-Werror-attributes.patch.
  - commit a7c7d40
  - net/iucv: fix the allocation size of iucv_path_table array
    (git-fixes bsc#1229451).
  - commit 4e0b259
  - Refresh patches.suse/0001-drm-mst-Fix-NULL-pointer-dereference-at-drm_dp_add_p.patch (git-fixes)
    Alt-commit
  - commit 98e41cf
  - Refresh patches.suse/drm-i915-vma-Fix-UAF-on-destroy-against-retire-race.patch (git-fixes)
    Alt-commit
  - commit 11ef901
  - Refresh patches.suse/drm-amd-display-Send-DTBCLK-disable-message-on-first.patch (git-fixes)
    Alt-commit
  - commit 6d9aa0a
  - Refresh patches.suse/drm-amd-display-Fix-DPSTREAM-CLK-on-and-off-sequence.patch (git-fixes)
    Alt-commit
  - commit 24768b9
  - tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
    (CVE-2024-41007 bsc#1227863).
  - commit 35aaaf5
  - HID: wacom: Defer calculation of resolution until
    resolution_code is known (git-fixes).
  - ALSA: usb: Fix UBSAN warning in parse_audio_unit()
    (stable-fixes).
  - commit a485c9b
  - bpf: Fix a segment issue when downgrading gso_size (bsc#1229386
    CVE-2024-42281).
  - commit f593f1f

++++ kernel-rt:

  - ipvs: properly dereference pe in ip_vs_add_service (CVE-2024-42322 bsc#1229347)
  - commit 5abcd51
  - vhost-vdpa: switch to use vmf_insert_pfn() in the fault handler
    (git-fixes).
  - commit efaee02
  - net: missing check virtio (git-fixes).
  - commit 547a4d8
  - vhost/vsock: always initialize seqpacket_allow (git-fixes).
  - commit 1501797
  - vhost: Use virtqueue mutex for swapping worker (git-fixes).
  - commit ee31e9d
  - nvme-sysfs: add 'tls_keyring' attribute (bsc#1221857).
  - nvme-sysfs: add 'tls_configured_key' sysfs attribute
    (bsc#1221857).
  - nvme: split off TLS sysfs attributes into a separate group
    (bsc#1221857).
  - nvme: add a newline to the 'tls_key' sysfs attribute
    (bsc#1221857).
  - nvme-tcp: check for invalidated or revoked key (bsc#1221857).
  - nvme-tcp: sanitize TLS key handling (bsc#1221857).
  - nvme: tcp: remove unnecessary goto statement (bsc#1221857).
  - commit 95902b1
  - Refresh patches.suse/nvme-fabrics-typo-in-nvmf_parse_key.patch.
    Move into sorted section.
  - commit 24e43c3
  - vhost-scsi: Handle vhost_vq_work_queue failures for events
    (git-fixes).
  - commit bb54ef9
  - Update DRM patch reference (CVE-2024-42308 bsc#1229411)
  - commit ddc1933
  - Update
    patches.suse/nvme-tcp-fix-compile-time-checks-for-TLS-mode.patch
    (jsc#PED-6252 jsc#PED-5728 jsc#PED-5062 jsc#PED-3535
    bsc#1221857).
    Fix backporting error.
  - commit 35c7df3
  - Update parport patch reference (CVE-2024-42301 bsc#1229407)
  - commit 6707829
  - Refresh
    patches.suse/nvme-tcp-strict-pdu-pacing-to-avoid-send-stalls-on-T.patch.
    Use the version which got upload upstream.
  - commit 4896f98
  - virtio_net: use u64_stats_t infra to avoid data-races
    (git-fixes).
  - commit 1825530
  - usb: typec: fsa4480: Check if the chip is really there
    (git-fixes).
  - commit 771af75
  - usb: typec: fsa4480: Add support to swap SBU orientation
    (git-fixes).
  - commit b744e01
  - usb: typec: fsa4480: add support for Audio Accessory Mode
    (git-fixes).
  - commit 471d14e
  - usb: typec: fsa4480: rework mux & switch setup to handle more
    states (git-fixes).
  - commit dc03605
  - irqchip/imx-irqsteer: Handle runtime power management correctly
    (CVE-2024-42290 bsc#1229379).
  - commit a3bbc63
  - landlock: Don't lose track of restrictions on cred_transfer
    (bsc#1229351 CVE-2024-42318).
  - commit e161e74
  - apparmor: Fix null pointer deref when receiving skb during sock creation (bsc#1229287, CVE-2023-52889).
  - commit 7a47d08
  - kABI fix of: virtio-crypto: handle config changed by work queue
    (git-fixes).
  - commit 2e4646f
  - nvme-multipath: implement "queue-depth" iopolicy (bsc#1227706).
  - nvme-multipath: prepare for "queue-depth" iopolicy
    (bsc#1227706).
  - commit 796fd31
  - nilfs2: handle inconsistent state in nilfs_btnode_create_block()
    (bsc#1229370 CVE-2024-42295).
  - commit 34231c4
  - arm64: dts: imx8mp: Fix pgc vpu locations (git-fixes)
  - commit 6f29859
  - arm64: dts: imx8mp: Fix pgc_mlmix location (git-fixes)
  - commit 6b6ab8a
  - soc: qcom: icc-bwmon: Fix refcount imbalance seen during
    bwmon_remove (CVE-2024-43850 bsc#1229316).
  - soc: qcom: icc-bwmon: Set default thresholds dynamically
    (CVE-2024-43850 bsc#1229316).
  - commit e842a77
  - arm64: dts: imx8mp: add HDMI power-domains (git-fixes)
  - commit 88b7cca
  - arm64: dts: imx8mp: Add NPU Node (git-fixes)
  - commit 55a2e84
  - media: mediatek: vcodec: Handle invalid decoder vsi
    (CVE-2024-43831 bsc#1229309).
  - commit a7b1ec0
  - bna: adjust 'name' buf size of bna_tcb and bna_ccb structures
    (CVE-2024-43839 bsc#1229301).
  - net: mana: Add support for page sizes other than 4KB on ARM64
    (jsc#PED-8491 bsc#1226530).
  - commit 24750b5
  - Squashfs: fix variable overflow triggered by sysbot (git-fixes).
  - commit 90b77e5
  - squashfs: squashfs_read_data need to check if the length is 0
    (git-fixes).
  - commit 1ab3d64
  - jfs: Fix shift-out-of-bounds in dbDiscardAG (git-fixes).
  - commit f862c1b
  - jfs: fix null ptr deref in dtInsertEntry (git-fixes).
  - commit 72d65ab
  - reiserfs: fix uninit-value in comp_keys (git-fixes).
  - commit aeea4b8
  - Update
    patches.suse/0001-netlink-add-nla-be16-32-types-to-minlen-array.patch
    (CVE-2024-26849 bsc#1223053).
    Fixes: 2747893c94d9b55340403026d9430f2f93947449
  - commit 4cf09d7
  - virtio-crypto: handle config changed by work queue (git-fixes).
  - Refresh
    patches.suse/crypto-virtio-Wait-for-tasklet-to-complete-on-device.patch.
  - commit 3719b45
  - fuse: Initialize beyond-EOF page contents before setting
    uptodate (bsc#1229456).
  - fs/netfs/fscache_cookie: add missing "n_accesses" check
    (bsc#1229455).
  - commit 1ffdccd
  - s390/dasd: fix error recovery leading to data corruption on
    ESE devices (git-fixes bsc#1229452).
  - commit 421d882
  - blacklist.conf: Change entry to alt-commit
  - Refresh patches.suse/tools-Disable-__packed-attribute-compiler-warning-due-to-Werror-attributes.patch.
  - commit a7c7d40
  - net/iucv: fix the allocation size of iucv_path_table array
    (git-fixes bsc#1229451).
  - commit 4e0b259
  - Refresh patches.suse/0001-drm-mst-Fix-NULL-pointer-dereference-at-drm_dp_add_p.patch (git-fixes)
    Alt-commit
  - commit 98e41cf
  - Refresh patches.suse/drm-i915-vma-Fix-UAF-on-destroy-against-retire-race.patch (git-fixes)
    Alt-commit
  - commit 11ef901
  - Refresh patches.suse/drm-amd-display-Send-DTBCLK-disable-message-on-first.patch (git-fixes)
    Alt-commit
  - commit 6d9aa0a
  - Refresh patches.suse/drm-amd-display-Fix-DPSTREAM-CLK-on-and-off-sequence.patch (git-fixes)
    Alt-commit
  - commit 24768b9
  - tcp: use signed arithmetic in tcp_rtx_probe0_timed_out()
    (CVE-2024-41007 bsc#1227863).
  - commit 35aaaf5
  - HID: wacom: Defer calculation of resolution until
    resolution_code is known (git-fixes).
  - ALSA: usb: Fix UBSAN warning in parse_audio_unit()
    (stable-fixes).
  - commit a485c9b
  - bpf: Fix a segment issue when downgrading gso_size (bsc#1229386
    CVE-2024-42281).
  - commit f593f1f

++++ llvm19:

  - Add minor version to Python shebangs. (boo#1212476)
  - Remove shebang and executable bit where not needed.

++++ nfs-utils:

  - add 0001-gssd-revert-commit-a5f3b7ccb01c.patch,
    0002-gssd-revert-commit-513630d720bd.patch,
    0003-gssd-switch-to-using-rpc_gss_seccreate.patch,
    0004-gssd-handle-KRB5_AP_ERR_BAD_INTEGRITY-for-machine-cr.patch,
    0005-gssd-handle-KRB5_AP_ERR_BAD_INTEGRITY-for-user-crede.patch,
    0006-configure-check-for-rpc_gss_seccreate.patch: fixes for
    libtirpc 1.3.5

++++ ovmf:

  - Removed -code/-vars files of AMD SEV flavor because SEV ovmf only
    supports unified image.
  - Updated 50-ovmf-x86_64-sev.json descriptor
  - Use ovmf-x86_64-sev.bin unified image instead of separate images
    ovmf-x86_64-sev-code/vars.bin.
  - add "mode": "stateless", currently SEV ovmf only supports
    stateless mode.
  - Removed "amd-sev" and "amd-sev-es" feature tags from the following
    descriptors because we separate SEV as a flavor:
    60-ovmf-x86_64-2m.json
    60-ovmf-x86_64.json
  - Add descriptors.tar.xz.README as the readme of descriptors.tar.xz

------------------------------------------------------------------
------------------  2024-8-19  -  Aug 19 2024  -------------------
------------------------------------------------------------------

++++ bash:

  - Add upstream patches
    * bash52-027
    The configure test for the presence of strtoimax(3) is inverted.
    * bash52-028
    A DEBUG trap in an asynchronous process can steal the controlling terminal
    away from the calling shell, causing it to exit.
    * bash52-030
    `wait -n' can fail to return some jobs if they exit due to signals the shell
    does not report to the user.
    * bash52-031
    There is a memory leak in the code that implements the optimized $(<file)
    expansion for some code paths.
    * bash52-032
    When printing functions containing coprocesses, the displayed coproc command
    has the word COPROC inserted unconditionally, resulting in function bodies
    that cannot be re-read as input.

++++ kernel-default:

  - kABI fix for net/sched: flower: Fix chain template offload
    (CVE-2024-26669 bsc#1222350).
  - net/sched: flower: Fix chain template offload (CVE-2024-26669
    bsc#1222350).
  - commit 43f1cd6
  - kABI fix for rxrpc: Fix delayed ACKs to not set the reference
    serial number (CVE-2024-26677 bsc#1222387).
  - rxrpc: Fix delayed ACKs to not set the reference serial number
    (CVE-2024-26677 bsc#1222387).
  - commit c3c3a27
  - Update patches.suse/cpu-SMT-Enable-SMT-only-if-a-core-is-online.patch
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1229327 ltc#206365).
  - Update patches.suse/powerpc-topology-Check-if-a-core-is-online.patch
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1229327 ltc#206365).
  - commit fd7ec4b
  - xprtrdma: Fix rpcrdma_reqs_reset() (git-fixes).
  - gss_krb5: Fix the error handling path for
    crypto_sync_skcipher_setkey (git-fixes).
  - commit c717fae
  - SUNRPC: Fix a race to wake a sync task (git-fixes).
  - nfs: pass explicit offset/count to trace events (git-fixes).
  - commit 6f41a0a
  - NFSv4.1 another fix for EXCHGID4_FLAG_USE_PNFS_DS for DS server
    (git-fixes).
  - NFSD: Support write delegations in LAYOUTGET (git-fixes).
  - nfs: don't invalidate dentries on transient errors (git-fixes).
  - nfs: propagate readlink errors in nfs_symlink_filler
    (git-fixes).
  - nfs: make the rpc_stat per net namespace (git-fixes).
  - nfs: expose /proc/net/sunrpc/nfs in net namespaces (git-fixes).
  - sunrpc: add a struct rpc_stats arg to rpc_create_args
    (git-fixes).
  - commit 6ab4001
  - Update
    patches.suse/ata-libata-core-Fix-double-free-on-error.patch
    (git-fixes CVE-2024-41087 bsc#1228740 bsc#1228466).
  - Update
    patches.suse/cachefiles-add-missing-lock-protection-when-polling.patch
    (bsc#1229256 CVE-2024-42250 bsc#1228977).
  - Update
    patches.suse/cachefiles-defer-exposing-anon_fd-until-after-copy_to.patch
    (bsc#1229251 CVE-2024-40913 bsc#1227839).
  - Update
    patches.suse/cachefiles-fix-slab-use-after-free-in-cachefiles_onde.patch
    (bsc#1229247 CVE-2024-39510 bsc#1227734).
  - Update
    patches.suse/cachefiles-fix-slab-use-after-free-in-cachefiles_ondemand_daemon_read.patch
    (bsc#1229246 CVE-2024-40899 bsc#1227758).
  - Update
    patches.suse/drm-i915-gem-Fix-Virtual-Memory-mapping-boundaries-c.patch
    (git-fixes CVE-2024-42259 bsc#1229156).
  - Update
    patches.suse/powerpc-pseries-Whitelist-dtl-slub-object-for-copyin.patch
    (bsc#1194869 CVE-2024-41065 bsc#1228636).
  - commit 3fec826
  - char: xillybus: Check USB endpoints when probing device
    (git-fixes).
  - Revert "misc: fastrpc: Restrict untrusted app to attach to
    privileged PD" (git-fixes).
  - tty: atmel_serial: use the correct RTS flag (git-fixes).
  - tty: serial: fsl_lpuart: mark last busy before uart_add_one_port
    (git-fixes).
  - xhci: Fix Panther point NULL pointer deref at full-speed
    re-enumeration (git-fixes).
  - Revert "usb: typec: tcpm: clear pd_event queue in PORT_RESET"
    (git-fixes).
  - commit e3fe681
  - Refresh patches.suse/SUNRPC-avoid-soft-lockup-when-transmitting-UDP-to-re.patch.
    Add git-commit
  - commit 7a1e763

++++ kernel-rt:

  - kABI fix for net/sched: flower: Fix chain template offload
    (CVE-2024-26669 bsc#1222350).
  - net/sched: flower: Fix chain template offload (CVE-2024-26669
    bsc#1222350).
  - commit 43f1cd6
  - kABI fix for rxrpc: Fix delayed ACKs to not set the reference
    serial number (CVE-2024-26677 bsc#1222387).
  - rxrpc: Fix delayed ACKs to not set the reference serial number
    (CVE-2024-26677 bsc#1222387).
  - commit c3c3a27
  - Update patches.suse/cpu-SMT-Enable-SMT-only-if-a-core-is-online.patch
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1229327 ltc#206365).
  - Update patches.suse/powerpc-topology-Check-if-a-core-is-online.patch
    (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes
    bsc#1229327 ltc#206365).
  - commit fd7ec4b
  - xprtrdma: Fix rpcrdma_reqs_reset() (git-fixes).
  - gss_krb5: Fix the error handling path for
    crypto_sync_skcipher_setkey (git-fixes).
  - commit c717fae
  - SUNRPC: Fix a race to wake a sync task (git-fixes).
  - nfs: pass explicit offset/count to trace events (git-fixes).
  - commit 6f41a0a
  - NFSv4.1 another fix for EXCHGID4_FLAG_USE_PNFS_DS for DS server
    (git-fixes).
  - NFSD: Support write delegations in LAYOUTGET (git-fixes).
  - nfs: don't invalidate dentries on transient errors (git-fixes).
  - nfs: propagate readlink errors in nfs_symlink_filler
    (git-fixes).
  - nfs: make the rpc_stat per net namespace (git-fixes).
  - nfs: expose /proc/net/sunrpc/nfs in net namespaces (git-fixes).
  - sunrpc: add a struct rpc_stats arg to rpc_create_args
    (git-fixes).
  - commit 6ab4001
  - Update
    patches.suse/ata-libata-core-Fix-double-free-on-error.patch
    (git-fixes CVE-2024-41087 bsc#1228740 bsc#1228466).
  - Update
    patches.suse/cachefiles-add-missing-lock-protection-when-polling.patch
    (bsc#1229256 CVE-2024-42250 bsc#1228977).
  - Update
    patches.suse/cachefiles-defer-exposing-anon_fd-until-after-copy_to.patch
    (bsc#1229251 CVE-2024-40913 bsc#1227839).
  - Update
    patches.suse/cachefiles-fix-slab-use-after-free-in-cachefiles_onde.patch
    (bsc#1229247 CVE-2024-39510 bsc#1227734).
  - Update
    patches.suse/cachefiles-fix-slab-use-after-free-in-cachefiles_ondemand_daemon_read.patch
    (bsc#1229246 CVE-2024-40899 bsc#1227758).
  - Update
    patches.suse/drm-i915-gem-Fix-Virtual-Memory-mapping-boundaries-c.patch
    (git-fixes CVE-2024-42259 bsc#1229156).
  - Update
    patches.suse/powerpc-pseries-Whitelist-dtl-slub-object-for-copyin.patch
    (bsc#1194869 CVE-2024-41065 bsc#1228636).
  - commit 3fec826
  - char: xillybus: Check USB endpoints when probing device
    (git-fixes).
  - Revert "misc: fastrpc: Restrict untrusted app to attach to
    privileged PD" (git-fixes).
  - tty: atmel_serial: use the correct RTS flag (git-fixes).
  - tty: serial: fsl_lpuart: mark last busy before uart_add_one_port
    (git-fixes).
  - xhci: Fix Panther point NULL pointer deref at full-speed
    re-enumeration (git-fixes).
  - Revert "usb: typec: tcpm: clear pd_event queue in PORT_RESET"
    (git-fixes).
  - commit e3fe681
  - Refresh patches.suse/SUNRPC-avoid-soft-lockup-when-transmitting-UDP-to-re.patch.
    Add git-commit
  - commit 7a1e763

++++ ncurses:

  - Add ncurses patch 20240817
    + review/update foot for 1.18.1 -TD
    + add a note about DomTerm 3.2.0 -TD
    + add new glob-expressions variables to list in config.status script
    (patch by Werner Fink).
    + add --enable-install-prefix to modify behavior of $DESTDIR to merge
    or replace the value set by --prefix (adapted from suggestion by
    Eli Zaretskii).
  - Remove patch fix-20240810.patch as now upstream
  - Correct offsets of patches
    * ncurses-5.9-ibm327x.dif
    * ncurses-6.4.dif

++++ readline:

  - Add upstream patches
    * readline82-011
    Some systems (e.g., macOS) send signals early on in interactive
    initialization, so readline should retry a failed open of the init file.
    * readline82-012
    If a user happens to bind do-lowercase-version to something that isn't a
    capital letter, so _rl_to_lower doesn't change anything and the result is
    still bound to do-lowercase-version, readline can recurse infinitely.
    * readline82-013
    When readline is accumulating bytes until it reads a complete multibyte
    character, reading a byte that makes the multibyte character invalid can
    result in discarding the bytes in the partial character.
  - Port patch readline-8.2.dif

++++ systemd:

  - Import commit bef0958f4db1b774c23505e93537ffe16f1b3894 (merge of v256.5)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/5bba1ebe17564b606cc5d1c07b14123c305019a7...bef0958f4db1b774c23505e93537ffe16f1b3894
  - Make the 32bit version of libudev.so available again (bsc#1228223)
    The symlink for building 32bit applications was mistakenly dropped when the
    content of libudev-devel was merged into systemd-devel.
    Provide the 32bit flavor of systemd-devel again, which should restore the plug
    and play support in Wine for 32bit windows applications.

++++ tiff:

  - security update:
    * CVE-2024-7006 [bsc#1228924]
    Fix pointer deref in tif_dirinfo.c
    + tiff-CVE-2024-7006.patch

++++ libvirt-glib:

  - BuildRequire gettext-devel instead of gettext: allow OBS to
    shortcut through gettext-runtime-mini.

++++ velociraptor-client:

  - Update node modules with security fixes.
    * Fixes CVE-2024-39338 (bsc#1229424)
    * Remove CVE-2024-28849-follow-redirects-drop-proxy-authorization.patch
    as the update is included.

++++ update-bootloader:

  - rename package perl-Bootloader to update-bootloader (bsc#1214361)
  - 1.15

------------------------------------------------------------------
------------------  2024-8-18  -  Aug 18 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - xfs: attr forks require attr, not attr2 (git-fixes).
  - commit d1644af
  - i2c: qcom-geni: Add missing geni_icc_disable in
    geni_i2c_runtime_resume (git-fixes).
  - i2c: Use IS_REACHABLE() for substituting empty ACPI functions
    (git-fixes).
  - commit 37fcb0e
  - Move upstreamed powerpc patches into sorted section
  - commit 7bdd775
  - xfs: journal geometry is not properly bounds checked
    (git-fixes).
  - commit 7680aeb

++++ kernel-rt:

  - xfs: attr forks require attr, not attr2 (git-fixes).
  - commit d1644af
  - i2c: qcom-geni: Add missing geni_icc_disable in
    geni_i2c_runtime_resume (git-fixes).
  - i2c: Use IS_REACHABLE() for substituting empty ACPI functions
    (git-fixes).
  - commit 37fcb0e
  - Move upstreamed powerpc patches into sorted section
  - commit 7bdd775
  - xfs: journal geometry is not properly bounds checked
    (git-fixes).
  - commit 7680aeb

++++ libxmlb:

  - update to 0.3.19:
    * Add xb_version_string() to get the runtime ABI version
    * - Add the runtime version as the default XMLb invalidation
    GUID

------------------------------------------------------------------
------------------  2024-8-17  -  Aug 17 2024  -------------------
------------------------------------------------------------------

++++ dpdk:

  - Update to LTS release version v22.11.5
    * http://doc.dpdk.org/guides-22.11/rel_notes/release_22_11.html
  - Drop patches (included upstream):
    * 0001-kni-fix-build-with-Linux-6.3.patch (22.11.3)
    * 0001-kni-fix-build-with-Linux-6.5.patch (22.11.3)

++++ python-kiwi:

  - Add documentation for boxbuild tweaks

++++ kernel-default:

  - arm64: Fix KASAN random tag seed initialization (git-fixes)
  - commit a300263
  - arm64: ACPI: NUMA: initialize all values of acpi_early_node_map to (git-fixes)
  - commit a089c62
  - spi: Add empty versions of ACPI functions (stable-fixes).
  - i2c: Fix conditional for substituting empty ACPI functions
    (stable-fixes).
  - commit 3dc083c
  - gpio: mlxbf3: Support shutdown() function (git-fixes).
  - ALSA: hda/tas2781: Use correct endian conversion (git-fixes).
  - ALSA: usb-audio: Support Yamaha P-125 quirk entry
    (stable-fixes).
  - ALSA: hda/tas2781: fix wrong calibrated data order (git-fixes).
  - ALSA: usb-audio: Add delay quirk for VIVO USB-C-XE710 HEADSET
    (stable-fixes).
  - ALSA: hda/realtek: Add support for new HP G12 laptops
    (stable-fixes).
  - ALSA: hda/realtek: Fix noise from speakers on Lenovo IdeaPad
    3 15IAU7 (git-fixes).
  - ALSA: timer: Relax start tick time check for slave timer
    elements (git-fixes).
  - drm/amd/display: Adjust cursor position (git-fixes).
  - drm/amd/display: fix cursor offset on rotation 180 (git-fixes).
  - device property: Add cleanup.h based fwnode_handle_put()
    scope based cleanup (stable-fixes).
  - commit 51be9a0

++++ kernel-rt:

  - arm64: Fix KASAN random tag seed initialization (git-fixes)
  - commit a300263
  - arm64: ACPI: NUMA: initialize all values of acpi_early_node_map to (git-fixes)
  - commit a089c62
  - spi: Add empty versions of ACPI functions (stable-fixes).
  - i2c: Fix conditional for substituting empty ACPI functions
    (stable-fixes).
  - commit 3dc083c
  - gpio: mlxbf3: Support shutdown() function (git-fixes).
  - ALSA: hda/tas2781: Use correct endian conversion (git-fixes).
  - ALSA: usb-audio: Support Yamaha P-125 quirk entry
    (stable-fixes).
  - ALSA: hda/tas2781: fix wrong calibrated data order (git-fixes).
  - ALSA: usb-audio: Add delay quirk for VIVO USB-C-XE710 HEADSET
    (stable-fixes).
  - ALSA: hda/realtek: Add support for new HP G12 laptops
    (stable-fixes).
  - ALSA: hda/realtek: Fix noise from speakers on Lenovo IdeaPad
    3 15IAU7 (git-fixes).
  - ALSA: timer: Relax start tick time check for slave timer
    elements (git-fixes).
  - drm/amd/display: Adjust cursor position (git-fixes).
  - drm/amd/display: fix cursor offset on rotation 180 (git-fixes).
  - device property: Add cleanup.h based fwnode_handle_put()
    scope based cleanup (stable-fixes).
  - commit 51be9a0

------------------------------------------------------------------
------------------  2024-8-16  -  Aug 16 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fixed wrong log level on --logfile
    When using --logfile, the log generated there matches the
    stdout log (which without --debug, does not include any debug info).
    This is in contrast to the automatically generated one in the
    output directory, which always does and also not following the
    way how it is documented. This Fixes #2503

++++ librsvg:

  - Update to version 2.58.3:
    + A couple of fixes from fuzz testing:
  - Fix assertion failures with large Hue value in hsl() or hwb()
    colors.
  - Limit the baseFrequency for feTurbulence to avoid integer
    overflow.
  - Remove an obsolete test.

++++ kernel-default:

  - xfs: allow cross-linking special files without project quota
    (git-fixes).
  - commit 8d26aca
  - KVM: nVMX: Check for pending posted interrupts when looking
    for nested events (git-fixes).
  - commit 0b1027c
  - KVM: VMX: Split out the non-virtualization part of
    vmx_interrupt_blocked() (git-fixes).
  - commit 47fc351
  - xfs: use consistent uid/gid when grabbing dquots for inodes
    (git-fixes).
  - commit c1c88ce
  - xfs: honor init_xattrs in xfs_init_new_inode for !ATTR fs
    (git-fixes).
  - commit fae2711
  - xfs: allow unlinked symlinks and dirs with zero size
    (git-fixes).
  - commit 184b713
  - KVM: x86/mmu: Bug the VM if KVM tries to split a !hugepage SPTE
    (git-fixes).
  - commit 96acab8
  - xfs: fix unlink vs cluster buffer instantiation race
    (git-fixes).
  - commit 0ae592b
  - xfs: upgrade the extent counters in xfs_reflink_end_cow_extent
    later (git-fixes).
  - commit 730a4f0
  - xfs: match lock mode in xfs_buffered_write_iomap_begin()
    (git-fixes).
  - commit e70a195
  - xfs: require XFS_SB_FEAT_INCOMPAT_LOG_XATTRS for attr log
    intent item recovery (git-fixes).
  - commit 85919a1
  - xfs: don't use current->journal_info (git-fixes).
  - commit d96f684
  - KVM: nVMX: Request immediate exit iff pending nested event
    needs injection (git-fixes).
  - commit 9d306b8
  - cachefiles: add missing lock protection when polling
    (bsc#1229256).
  - cachefiles: cyclic allocation of msg_id to avoid reuse
    (bsc#1228499 CVE-2024-41050).
  - cachefiles: wait for ondemand_object_worker to finish when
    dropping  object (bsc#1228468 CVE-2024-41051).
  - cachefiles: cancel all requests for the object that is being
    dropped (bsc#1229255).
  - cachefiles: stop sending new request when dropping object
    (bsc#1229254).
  - cachefiles: propagate errors from vfs_getxattr() to avoid
    infinite  loop (bsc#1229253).
  - cachefiles: make on-demand read killable (bsc#1229252).
  - cachefiles: Set object to close if ondemand_id < 0 in copen
    (bsc#1228643 CVE-2024-41074).
  - cachefiles: defer exposing anon_fd until after copy_to_user()
    succeeds (bsc#1229251).
  - cachefiles: never get a new anonymous fd if ondemand_id is valid
    (bsc#1229250).
  - cachefiles: add spin_lock for cachefiles_ondemand_info
    (bsc#1229249).
  - cachefiles: add consistency check for copen/cread (bsc#1228646
    CVE-2024-41075).
  - cachefiles: remove err_put_fd label in
    cachefiles_ondemand_daemon_read() (bsc#1229248).
  - cachefiles: fix slab-use-after-free in
    cachefiles_ondemand_daemon_read() (bsc#1229247).
  - cachefiles: fix slab-use-after-free in
    cachefiles_ondemand_get_fd() (bsc#1229246).
  - cachefiles, erofs: Fix NULL deref in when cachefiles is not
    doing  ondemand-mode (bsc#1229245).
  - cachefiles: add restore command to recover inflight ondemand
    read  requests (bsc#1229244).
  - cachefiles: narrow the scope of triggering EPOLLIN events in
    ondemand  mode (bsc#1229243).
  - cachefiles: resend an open request if the read request's object
    is  closed (bsc#1229241).
  - cachefiles: extract ondemand info field from cachefiles_object
    (bsc#1229240).
  - cachefiles: introduce object ondemand state (bsc#1229239).
  - commit 3d893c5
  - KVM: nVMX: Add a helper to get highest pending from Posted
    Interrupt vector (git-fixes).
  - commit ebf04ff
  - KVM: VMX: Switch __vmx_exit() and kvm_x86_vendor_exit() in
    vmx_exit() (git-fixes).
  - commit 8ef91ee
  - KVM: x86: Limit check IDs for KVM_SET_BOOT_CPU_ID (git-fixes).
  - commit 395837f
  - KVM: VMX: Move posted interrupt descriptor out of VMX code
    (git-fixes).
  - commit feb966b
  - xfs: allow symlinks with short remote targets (bsc#1229160).
  - commit e82d4ad
  - x86/xen: Convert comma to semicolon (git-fixes).
  - commit c8d2d16
  - net: mana: Fix doorbell out of order violation and avoid
    unnecessary doorbell rings (bsc#1229154).
  - net: mana: Fix RX buf alloc_size alignment and atomic op panic
    (bsc#1229086).
  - commit 59cb1c7
  - wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion
    (git-fixes).
  - net: ethernet: mtk_wed: fix use-after-free panic in
    mtk_wed_setup_tc_block_cb() (git-fixes).
  - media: Revert "media: dvb-usb: Fix unexpected infinite loop
    in dvb_usb_read_remote_control()" (git-fixes).
  - commit daf04e2

++++ kernel-rt:

  - xfs: allow cross-linking special files without project quota
    (git-fixes).
  - commit 8d26aca
  - KVM: nVMX: Check for pending posted interrupts when looking
    for nested events (git-fixes).
  - commit 0b1027c
  - KVM: VMX: Split out the non-virtualization part of
    vmx_interrupt_blocked() (git-fixes).
  - commit 47fc351
  - xfs: use consistent uid/gid when grabbing dquots for inodes
    (git-fixes).
  - commit c1c88ce
  - xfs: honor init_xattrs in xfs_init_new_inode for !ATTR fs
    (git-fixes).
  - commit fae2711
  - xfs: allow unlinked symlinks and dirs with zero size
    (git-fixes).
  - commit 184b713
  - KVM: x86/mmu: Bug the VM if KVM tries to split a !hugepage SPTE
    (git-fixes).
  - commit 96acab8
  - xfs: fix unlink vs cluster buffer instantiation race
    (git-fixes).
  - commit 0ae592b
  - xfs: upgrade the extent counters in xfs_reflink_end_cow_extent
    later (git-fixes).
  - commit 730a4f0
  - xfs: match lock mode in xfs_buffered_write_iomap_begin()
    (git-fixes).
  - commit e70a195
  - xfs: require XFS_SB_FEAT_INCOMPAT_LOG_XATTRS for attr log
    intent item recovery (git-fixes).
  - commit 85919a1
  - xfs: don't use current->journal_info (git-fixes).
  - commit d96f684
  - KVM: nVMX: Request immediate exit iff pending nested event
    needs injection (git-fixes).
  - commit 9d306b8
  - cachefiles: add missing lock protection when polling
    (bsc#1229256).
  - cachefiles: cyclic allocation of msg_id to avoid reuse
    (bsc#1228499 CVE-2024-41050).
  - cachefiles: wait for ondemand_object_worker to finish when
    dropping  object (bsc#1228468 CVE-2024-41051).
  - cachefiles: cancel all requests for the object that is being
    dropped (bsc#1229255).
  - cachefiles: stop sending new request when dropping object
    (bsc#1229254).
  - cachefiles: propagate errors from vfs_getxattr() to avoid
    infinite  loop (bsc#1229253).
  - cachefiles: make on-demand read killable (bsc#1229252).
  - cachefiles: Set object to close if ondemand_id < 0 in copen
    (bsc#1228643 CVE-2024-41074).
  - cachefiles: defer exposing anon_fd until after copy_to_user()
    succeeds (bsc#1229251).
  - cachefiles: never get a new anonymous fd if ondemand_id is valid
    (bsc#1229250).
  - cachefiles: add spin_lock for cachefiles_ondemand_info
    (bsc#1229249).
  - cachefiles: add consistency check for copen/cread (bsc#1228646
    CVE-2024-41075).
  - cachefiles: remove err_put_fd label in
    cachefiles_ondemand_daemon_read() (bsc#1229248).
  - cachefiles: fix slab-use-after-free in
    cachefiles_ondemand_daemon_read() (bsc#1229247).
  - cachefiles: fix slab-use-after-free in
    cachefiles_ondemand_get_fd() (bsc#1229246).
  - cachefiles, erofs: Fix NULL deref in when cachefiles is not
    doing  ondemand-mode (bsc#1229245).
  - cachefiles: add restore command to recover inflight ondemand
    read  requests (bsc#1229244).
  - cachefiles: narrow the scope of triggering EPOLLIN events in
    ondemand  mode (bsc#1229243).
  - cachefiles: resend an open request if the read request's object
    is  closed (bsc#1229241).
  - cachefiles: extract ondemand info field from cachefiles_object
    (bsc#1229240).
  - cachefiles: introduce object ondemand state (bsc#1229239).
  - commit 3d893c5
  - KVM: nVMX: Add a helper to get highest pending from Posted
    Interrupt vector (git-fixes).
  - commit ebf04ff
  - KVM: VMX: Switch __vmx_exit() and kvm_x86_vendor_exit() in
    vmx_exit() (git-fixes).
  - commit 8ef91ee
  - KVM: x86: Limit check IDs for KVM_SET_BOOT_CPU_ID (git-fixes).
  - commit 395837f
  - KVM: VMX: Move posted interrupt descriptor out of VMX code
    (git-fixes).
  - commit feb966b
  - xfs: allow symlinks with short remote targets (bsc#1229160).
  - commit e82d4ad
  - x86/xen: Convert comma to semicolon (git-fixes).
  - commit c8d2d16
  - net: mana: Fix doorbell out of order violation and avoid
    unnecessary doorbell rings (bsc#1229154).
  - net: mana: Fix RX buf alloc_size alignment and atomic op panic
    (bsc#1229086).
  - commit 59cb1c7
  - wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion
    (git-fixes).
  - net: ethernet: mtk_wed: fix use-after-free panic in
    mtk_wed_setup_tc_block_cb() (git-fixes).
  - media: Revert "media: dvb-usb: Fix unexpected infinite loop
    in dvb_usb_read_remote_control()" (git-fixes).
  - commit daf04e2

++++ pcre2:

  - Fix GitHub issue #415: Test suite fails when targeting i686.
    The fix is taken straight from PR #418, also on GitHub.
  - Add patch file:
    * pcre2-10.44-github-issue-415.patch

------------------------------------------------------------------
------------------  2024-8-15  -  Aug 15 2024  -------------------
------------------------------------------------------------------

++++ btrfsprogs:

  - update to 6.10.1
    * mkfs: rework --rootdir traversal, skip hardlinks and create new inodes
    instead, also warn about them, this did not work as expected and will be
    fixed in the future
    * receive: search in older trees for UUIDs when detecting clone sources
    * libbtrfsutil: bindings available at https://pypi.org/project/btrfsutil
    * libbtrfs:
    * patchlevel version update 0.1.4
    * cleanup in headers, removed unused definitions, no functional changes
    * don't ship list.h and rbtree.h
    * other: documentation updates

++++ cloud-regionsrv-client:

  - Add rgnsrv-clnt-fix-docker-setup.patch (bsc#1229137)
    + The entry for the update infrastructure registry mirror was written
    incorrectly causing docker daemon startup to fail.

++++ kernel-default:

  - filelock: Remove locks reliably when fcntl/close race is
    detected (CVE-2024-41012 bsc#1228247).
  - commit a736b9b
  - io_uring: fix possible deadlock in
    io_register_iowq_max_workers() (bsc#1228616 CVE-2024-41080).
  - commit eae6448
  - io_uring: fix io_match_task must_hold (git-fixes).
  - io_uring: tighten task exit cancellations (git-fixes).
  - commit f9ce2d8
  - io_uring: Fix probe of disabled operations (git-fixes).
  - io_uring/advise: support 64-bit lengths (git-fixes).
  - commit 7566a8d
  - io_uring: Drop per-ctx dummy_ubuf (git-fixes).
  - commit 2717cc1
  - powerpc/kexec_file: fix cpus node update to FDT (bsc#1194869).
  - powerpc/pseries: Whitelist dtl slub object for copying to
    userspace (bsc#1194869).
  - powerpc/kexec: make the update_cpus_node() function public
    (bsc#1194869).
  - powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
    (bsc#1194869).
  - powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for
    CONFIG_PCI=n (bsc#1194869).
  - powerpc/io: Avoid clang null pointer arithmetic warnings
    (bsc#1194869).
  - powerpc/pseries: Add failure related checks for h_get_mpp and
    h_get_ppp (bsc#1194869).
  - powerpc/kexec: split CONFIG_KEXEC_FILE and CONFIG_CRASH_DUMP
    (bsc#1194869).
  - powerpc: xor_vmx: Add '-mhard-float' to CFLAGS (bsc#1194869).
  - powerpc/radix: Move some functions into #ifdef
    CONFIG_KVM_BOOK3S_HV_POSSIBLE (bsc#1194869).
  - commit 4e7f0fe
  - arm64: errata: Expand speculative SSBS workaround (again) (git-fixes)
  - commit e589bbc
  - arm64: cputype: Add Cortex-A725 definitions (git-fixes)
  - commit 0d04176
  - arm64: cputype: Add Cortex-X1C definitions (git-fixes)
  - commit 6a5ea61
  - arm64: errata: Expand speculative SSBS workaround (git-fixes)
  - commit f75d6ba
  - arm64: errata: Unify speculative SSBS errata logic (git-fixes).
    Update config files.
  - commit ffaab08
  - arm64: cputype: Add Cortex-X925 definitions (git-fixes)
  - commit 3c8ddb7
  - arm64: cputype: Add Cortex-A720 definitions (git-fixes)
  - commit f5fd7c6
  - arm64: cputype: Add Cortex-X3 definitions (git-fixes)
  - commit d87d988
  - arm64: errata: Add workaround for Arm errata 3194386 and 3312417 (git-fixes)
    Refresh patches.suse/kabi-arm64-reserve-space-in-cpu_hwcaps-and-cpu_hwcap.patch
    and enable around.
  - commit b3747ef
  - arm64: cputype: Add Neoverse-V3 definitions (git-fixes)
  - commit 78aeee9
  - arm64: cputype: Add Cortex-X4 definitions (git-fixes)
  - commit 2841965
  - arm64: barrier: Restore spec_bar() macro (git-fixes)
  - commit 5c935b6
  - arm64: Add Neoverse-V2 part (git-fixes)
  - commit 0f9f30b
  - net/rds: fix possible cp null dereference (git-fixes).
  - commit cac3126
  - s390/pci: Add missing virt_to_phys() for directed DIBV
    (git-fixes bsc#1229174).
  - commit ea8e3e7
  - s390/dasd: fix error checks in dasd_copy_pair_store()
    (git-fixes bsc#1229173).
  - commit f5c4fe8
  - s390/pci: Allow allocation of more than 1 MSI interrupt
    (git-fixes bsc#1229172).
  - s390/pci: Refactor arch_setup_msi_irqs() (git-fixes
    bsc#1229172).
  - commit ad8c54b
  - s390/cpum_cf: Fix endless loop in CF_DIAG event stop (git-fixes
    bsc#1229171).
  - commit 94c7469
  - s390/uv: Panic for set and remove shared access UVC errors
    (git-fixes bsc#1229170).
  - commit 447c271
  - s390/sclp: Prevent release of buffer in I/O (git-fixes
    bsc#1229169).
  - commit 9daf007
  - kvm: s390: Reject memory region operations for ucontrol VMs
    (git-fixes bsc#1229168).
  - commit 14a9742
  - KVM: s390: fix validity interception issue when gisa is switched
    off (git-fixes bsc#1229167).
  - commit 5c4e348
  - Update patch reference of USB patch (jsc#PED-10108)
  - commit edfa08b
  - USB: serial: debug: do not echo input by default (stable-fixes).
  - usb: vhci-hcd: Do not drop references before new references
    are gained (stable-fixes).
  - serial: core: check uartclk for zero to avoid divide by zero
    (stable-fixes).
  - media: xc2028: avoid use-after-free in load_firmware_cb()
    (stable-fixes).
  - media: uvcvideo: Fix the bandwdith quirk on USB 3.x
    (stable-fixes).
  - media: uvcvideo: Ignore empty TS packets (stable-fixes).
  - media: amphion: Remove lock in s_ctrl callback (stable-fixes).
  - wifi: nl80211: don't give key data to userspace (stable-fixes).
  - PCI: Add Edimax Vendor ID to pci_ids.h (stable-fixes).
  - wifi: ath12k: fix memory leak in ath12k_dp_rx_peer_frag_setup()
    (stable-fixes).
  - wifi: nl80211: disallow setting special AP channel widths
    (stable-fixes).
  - gpio: prevent potential speculation leaks in
    gpio_device_get_desc() (stable-fixes).
  - commit 2335bf9
  - docs: KVM: Fix register ID of SPSR_FIQ (git-fixes).
  - drm/i915/gem: Adjust vma offset for framebuffer mmap offset
    (stable-fixes).
  - drm/amd/display: Skip Recompute DSC Params if no Stream on Link
    (stable-fixes).
  - drm/amdgpu: Forward soft recovery errors to userspace
    (stable-fixes).
  - drm/dp_mst: Skip CSN if topology probing is not done yet
    (stable-fixes).
  - drm/mediatek/dp: Fix spurious kfree() (git-fixes).
  - drm/amd/display: Add null checker before passing variables
    (stable-fixes).
  - Revert "drm/amd/display: Add NULL check for 'afb' before
    dereferencing in amdgpu_dm_plane_handle_cursor_update"
    (stable-fixes).
  - drm/amd/display: Add NULL check for 'afb' before dereferencing
    in amdgpu_dm_plane_handle_cursor_update (stable-fixes).
  - drm/bridge: analogix_dp: properly handle zero sized AUX
    transactions (stable-fixes).
  - drm/amd/pm: Fix the null pointer dereference for vega10_hwmgr
    (stable-fixes).
  - drm/radeon: Remove __counted_by from StateArray.states[]
    (git-fixes).
  - drm/amdgpu: Add lock around VF RLCG interface (stable-fixes).
  - drm/admgpu: fix dereferencing null pointer context
    (stable-fixes).
  - drm/amdgpu/pm: Fix the null pointer dereference in
    apply_state_adjust_rules (stable-fixes).
  - drm/amdgpu: Fix the null pointer dereference to ras_manager
    (stable-fixes).
  - drm/amdgpu/pm: Fix the null pointer dereference for smu7
    (stable-fixes).
  - drm/amdgpu/pm: Fix the param type of set_power_profile_mode
    (stable-fixes).
  - drm/amdgpu: fix potential resource leak warning (stable-fixes).
  - drm/amd/display: Add delay to improve LTTPR UHBR interop
    (stable-fixes).
  - Bluetooth: btnxpuart: Shutdown timer and prevent rearming when
    driver unloading (stable-fixes).
  - can: mcp251xfd: tef: update workaround for erratum DS80000789E
    6 of mcp2518fd (stable-fixes).
  - can: mcp251xfd: tef: prepare to workaround broken TEF FIFO
    tail index erratum (stable-fixes).
  - ACPI: SBS: manage alarm sysfs attribute through psy core
    (stable-fixes).
  - ACPI: battery: create alarm sysfs attribute atomically
    (stable-fixes).
  - clocksource/drivers/sh_cmt: Address race condition for clock
    events (stable-fixes).
  - commit 2a8ca72

++++ kernel-rt:

  - filelock: Remove locks reliably when fcntl/close race is
    detected (CVE-2024-41012 bsc#1228247).
  - commit a736b9b
  - io_uring: fix possible deadlock in
    io_register_iowq_max_workers() (bsc#1228616 CVE-2024-41080).
  - commit eae6448
  - io_uring: fix io_match_task must_hold (git-fixes).
  - io_uring: tighten task exit cancellations (git-fixes).
  - commit f9ce2d8
  - io_uring: Fix probe of disabled operations (git-fixes).
  - io_uring/advise: support 64-bit lengths (git-fixes).
  - commit 7566a8d
  - io_uring: Drop per-ctx dummy_ubuf (git-fixes).
  - commit 2717cc1
  - powerpc/kexec_file: fix cpus node update to FDT (bsc#1194869).
  - powerpc/pseries: Whitelist dtl slub object for copying to
    userspace (bsc#1194869).
  - powerpc/kexec: make the update_cpus_node() function public
    (bsc#1194869).
  - powerpc/xmon: Check cpu id in commands "c#", "dp#" and "dx#"
    (bsc#1194869).
  - powerpc/64: Set _IO_BASE to POISON_POINTER_DELTA not 0 for
    CONFIG_PCI=n (bsc#1194869).
  - powerpc/io: Avoid clang null pointer arithmetic warnings
    (bsc#1194869).
  - powerpc/pseries: Add failure related checks for h_get_mpp and
    h_get_ppp (bsc#1194869).
  - powerpc/kexec: split CONFIG_KEXEC_FILE and CONFIG_CRASH_DUMP
    (bsc#1194869).
  - powerpc: xor_vmx: Add '-mhard-float' to CFLAGS (bsc#1194869).
  - powerpc/radix: Move some functions into #ifdef
    CONFIG_KVM_BOOK3S_HV_POSSIBLE (bsc#1194869).
  - commit 4e7f0fe
  - arm64: errata: Expand speculative SSBS workaround (again) (git-fixes)
  - commit e589bbc
  - arm64: cputype: Add Cortex-A725 definitions (git-fixes)
  - commit 0d04176
  - arm64: cputype: Add Cortex-X1C definitions (git-fixes)
  - commit 6a5ea61
  - arm64: errata: Expand speculative SSBS workaround (git-fixes)
  - commit f75d6ba
  - arm64: errata: Unify speculative SSBS errata logic (git-fixes).
    Update config files.
  - commit ffaab08
  - arm64: cputype: Add Cortex-X925 definitions (git-fixes)
  - commit 3c8ddb7
  - arm64: cputype: Add Cortex-A720 definitions (git-fixes)
  - commit f5fd7c6
  - arm64: cputype: Add Cortex-X3 definitions (git-fixes)
  - commit d87d988
  - arm64: errata: Add workaround for Arm errata 3194386 and 3312417 (git-fixes)
    Refresh patches.suse/kabi-arm64-reserve-space-in-cpu_hwcaps-and-cpu_hwcap.patch
    and enable around.
  - commit b3747ef
  - arm64: cputype: Add Neoverse-V3 definitions (git-fixes)
  - commit 78aeee9
  - arm64: cputype: Add Cortex-X4 definitions (git-fixes)
  - commit 2841965
  - arm64: barrier: Restore spec_bar() macro (git-fixes)
  - commit 5c935b6
  - arm64: Add Neoverse-V2 part (git-fixes)
  - commit 0f9f30b
  - net/rds: fix possible cp null dereference (git-fixes).
  - commit cac3126
  - s390/pci: Add missing virt_to_phys() for directed DIBV
    (git-fixes bsc#1229174).
  - commit ea8e3e7
  - s390/dasd: fix error checks in dasd_copy_pair_store()
    (git-fixes bsc#1229173).
  - commit f5c4fe8
  - s390/pci: Allow allocation of more than 1 MSI interrupt
    (git-fixes bsc#1229172).
  - s390/pci: Refactor arch_setup_msi_irqs() (git-fixes
    bsc#1229172).
  - commit ad8c54b
  - s390/cpum_cf: Fix endless loop in CF_DIAG event stop (git-fixes
    bsc#1229171).
  - commit 94c7469
  - s390/uv: Panic for set and remove shared access UVC errors
    (git-fixes bsc#1229170).
  - commit 447c271
  - s390/sclp: Prevent release of buffer in I/O (git-fixes
    bsc#1229169).
  - commit 9daf007
  - kvm: s390: Reject memory region operations for ucontrol VMs
    (git-fixes bsc#1229168).
  - commit 14a9742
  - KVM: s390: fix validity interception issue when gisa is switched
    off (git-fixes bsc#1229167).
  - commit 5c4e348
  - Update patch reference of USB patch (jsc#PED-10108)
  - commit edfa08b
  - USB: serial: debug: do not echo input by default (stable-fixes).
  - usb: vhci-hcd: Do not drop references before new references
    are gained (stable-fixes).
  - serial: core: check uartclk for zero to avoid divide by zero
    (stable-fixes).
  - media: xc2028: avoid use-after-free in load_firmware_cb()
    (stable-fixes).
  - media: uvcvideo: Fix the bandwdith quirk on USB 3.x
    (stable-fixes).
  - media: uvcvideo: Ignore empty TS packets (stable-fixes).
  - media: amphion: Remove lock in s_ctrl callback (stable-fixes).
  - wifi: nl80211: don't give key data to userspace (stable-fixes).
  - PCI: Add Edimax Vendor ID to pci_ids.h (stable-fixes).
  - wifi: ath12k: fix memory leak in ath12k_dp_rx_peer_frag_setup()
    (stable-fixes).
  - wifi: nl80211: disallow setting special AP channel widths
    (stable-fixes).
  - gpio: prevent potential speculation leaks in
    gpio_device_get_desc() (stable-fixes).
  - commit 2335bf9
  - docs: KVM: Fix register ID of SPSR_FIQ (git-fixes).
  - drm/i915/gem: Adjust vma offset for framebuffer mmap offset
    (stable-fixes).
  - drm/amd/display: Skip Recompute DSC Params if no Stream on Link
    (stable-fixes).
  - drm/amdgpu: Forward soft recovery errors to userspace
    (stable-fixes).
  - drm/dp_mst: Skip CSN if topology probing is not done yet
    (stable-fixes).
  - drm/mediatek/dp: Fix spurious kfree() (git-fixes).
  - drm/amd/display: Add null checker before passing variables
    (stable-fixes).
  - Revert "drm/amd/display: Add NULL check for 'afb' before
    dereferencing in amdgpu_dm_plane_handle_cursor_update"
    (stable-fixes).
  - drm/amd/display: Add NULL check for 'afb' before dereferencing
    in amdgpu_dm_plane_handle_cursor_update (stable-fixes).
  - drm/bridge: analogix_dp: properly handle zero sized AUX
    transactions (stable-fixes).
  - drm/amd/pm: Fix the null pointer dereference for vega10_hwmgr
    (stable-fixes).
  - drm/radeon: Remove __counted_by from StateArray.states[]
    (git-fixes).
  - drm/amdgpu: Add lock around VF RLCG interface (stable-fixes).
  - drm/admgpu: fix dereferencing null pointer context
    (stable-fixes).
  - drm/amdgpu/pm: Fix the null pointer dereference in
    apply_state_adjust_rules (stable-fixes).
  - drm/amdgpu: Fix the null pointer dereference to ras_manager
    (stable-fixes).
  - drm/amdgpu/pm: Fix the null pointer dereference for smu7
    (stable-fixes).
  - drm/amdgpu/pm: Fix the param type of set_power_profile_mode
    (stable-fixes).
  - drm/amdgpu: fix potential resource leak warning (stable-fixes).
  - drm/amd/display: Add delay to improve LTTPR UHBR interop
    (stable-fixes).
  - Bluetooth: btnxpuart: Shutdown timer and prevent rearming when
    driver unloading (stable-fixes).
  - can: mcp251xfd: tef: update workaround for erratum DS80000789E
    6 of mcp2518fd (stable-fixes).
  - can: mcp251xfd: tef: prepare to workaround broken TEF FIFO
    tail index erratum (stable-fixes).
  - ACPI: SBS: manage alarm sysfs attribute through psy core
    (stable-fixes).
  - ACPI: battery: create alarm sysfs attribute atomically
    (stable-fixes).
  - clocksource/drivers/sh_cmt: Address race condition for clock
    events (stable-fixes).
  - commit 2a8ca72

++++ bluez:

  - add bluez-no-cups-devel-buildreq.patch to avoid cups-devel
    buildrequires which results in an excessive build loop

++++ unbound:

  - Update to 1.21.0:
    Security Fixes:
    * Merge #1073: fix null pointer dereference issue in function
    ub_ctx_set_fwd.
    [CVE-2024-43167, bsc#1229068]
    Features:
    * Fix #1071: [FR] Clear both in-memory and cachedb module cache
    with `unbound-control flush*` commands.
    * Fix #144: Port ipset to BSD pf tables.
    * Add dnstap-sample-rate that logs only 1/N messages, for high
    volume server environments. Thanks Dan Luther.
    * Add root key 38696 from 2024 for DNSSEC validation. It is added
    to the default root keys in unbound-anchor. The content can be
    inspected with `unbound-anchor -l`.
    * Merge #1090: Cookie secret file. Adds `cookie-secret-file:
    "unbound_cookiesecrets.txt"` option to store cookie secrets for
    EDNS COOKIE secret rollover. The remote control
    add_cookie_secret, activate_cookie_secret and
    drop_cookie_secret commands can be used for rollover, the
    command print_cookie_secrets shows the values in use.
    Bug Fixes:
    * Fix CAMP issues with global quota. Thanks to Huayi
    Duan, Marco Bearzi, Jodok Vieli, and Cagin Tanir from NetSec
    group, ETH Zurich.
    * Fix CacheFlush issues with limit on NS RRs. Thanks to Yehuda
    Afek, Anat Bremler-Barr, Shoham Danino and Yuval Shavitt
    (Tel-Aviv University and Reichman University).
    * Merge #1062: Fix potential overflow bug while parsing port in
    function cfg_mark_ports.
    * Fix for #1062: declaration before statement, avoid print of
    null, and redundant check for array size.
    * Fix to squelch udp connect errors in the log at low verbosity
    about invalid argument for IPv6 link local addresses.
    * Fix when the mesh jostle is exceeded that nameserver targets
    are marked as resolved, so that the lookup is not stuck on the
    requestlist.
    * Add missing common functions to tdir tests.
    * Merge #1070: Fix rtt assignement for low values of
    infra-cache-max-rtt.
    * Merge #1069: Fix unbound-control stdin commands for
    multi-process Unbounds.
    * Fix unbound-control commands that read stdin in multi-process
    operation (local_zones_remove, local_zones, local_datas_remove,
    local_datas, view_local_datas_remove, view_local_datas). They
    will be properly distributed to all processes. dump_cache and
    load_cache are no longer supported in multi-process operation.
    * Remove testdata/remote-threaded.tdir.
    testdata/09-unbound-control.tdir now checks both single and
    multi process/thread operation.
    * Fix to print a parse error when config is read with no name for
    a forward-zone, stub-zone or view.
    * Fix for parse end of forward-zone, stub-zone and view.
    * Fix for #1064: Fix that cachedb expired messages are considered
    insecure, and thus can be served to clients when dnssec is
    enabled.
    * Fix #1059: Intermittent DNS blocking failure with local-zone
    and always_nxdomain. Addition of local_zones dynamically via
    unbound-control was not finding the zone's parent correctly.
    * Fix #1064: Unbound 1.20 Cachedb broken?
    * Fix unused variable warning on compilation with no thread
    support.
    * unbound-control-setup: check openssl availability before doing
    anything, patch from Michael Tokarev.
    * Update patch to remove 'command' shell builtin and update error
    text.
    * Fix to enable that SERVFAIL is cached, for a short period, for
    more cases. In the cases where limits are exceeded.
    * Fix spelling of tcp-idle-timeout docs, from Michael Tokarev.
    * Merge #1078: Only check old pid if no username.
    * Fix #1079: tags from tagged rpz zones are no longer honored
    after upgrade from 1.19.3 to 1.20.0.
    * Fix for #1079: fix RPZ taglist in iterator callback that no
    client info is like no taglist intersection.
    * Fix to squelch connection reset by peer errors from log. And
    fix that the tcp read errors are labeled as initial for the
    first calls.
    * Merge #1080: AddressSanitizer detection in tdir tests and
    memory leak fixes.
    * Fix memory leak when reload_keep_cache is used and num-threads
    changes.
    * Fix memory leak on exit for unbound-dnstap-socket; creates
    false negatives during testing.
    * Fix memory leak in setup of dsa sig.
    * Fix typos for 'the the' in text.
    * Fix validation for repeated use of a DNAME record.
    * Add unit test for validation of repeated use of a DNAME record.
    * Fix #1091: Build fails with OpenSSL >= 3.0 built with
    OPENSSL_NO_DEPRECATED.
    * Fix #1092: Ubuntu 22.04 Jammy fails to compile unbound 1.20.0;
    by adding helpful text for the Python interpreter version and
    allowing the default pkg-config unavailability error message to
    be shown.
    * Fix pkg-config availability check in dnstap/dnstap.m4 and
    systemd.m4.
    * Explicitly set the RD bit for the mesh query flags when
    prefetching. These queries have no waiting client but they need
    to be treated as recursive.
    * Fix ip-ratelimit-cookie setting, it was not applied.
    * Fix to remove unused include from the readzone test program.
    * Fix unused variable warning in do_cache_remove.
    * Fix compile warning in worker pthread id printout.
    * Add unit test skip files and bison and flex output to
    gitignore.
    * Fix to use modstack_init in zonemd unit test.
    * Fix to remove unneeded linebreak in fptr_wlist.c.
    * Fix compile warnings in fptr_wlist.c.
    * Fix for repeated use of a DNAME record: first overallocate and
    then move the exact size of the init value to avoid false
    positive heap overflow reads from address sanitizers.
    * Fix to print details about the failure to lookup a DNSKEY
    record when validation fails due to the missing DNSKEY. Also
    for key prime and DS lookups.
    * Fix for neater printout for error for missing DS response.
    * Fix neater printout.
    * Fix #1099: Unbound core dump on SIGSEGV.
    * Fix for #1099: Fix to check for deleted RRset when the contents
    is updated and fetched after it is stored, and also check for a
    changed RRset.
    * Don't check for message TTL changes if the RRsets remain the
    same.
    * Fix that validation reason failure that uses string print uses
    separate buffer that is passed, from the scratch validation
    buffer.
    * Fixup algo_needs_reason string buffer length.
    * Fix shadowed error string variable in validator dnskey
    handling.
    * Update list of known EDE codes.
    * For #773: In contrib/unbound.service.in set unbound to start
    after network-online.target. Also for
    contrib/unbound_portable.service.in.
    * Fix #1103: unbound 1.20.0 segmentation fault with nghttp2.
    * For #1103: fix to also drop mesh state reference when a h2
    reply is dropped.
    * Add RPZ tag tests in acl_interface.tdir.
    * For #1102: clearer text for using interface-* options for the
    loopback interface.
    * For #1103: fix to also drop mesh state reference when the
    discard limit is reached, when there is an error making a new
    recursion state and when the connection is dropped with
    is_drop.
    * For #1103: Fix to drop mesh state reference for the http2
    stream associated with the reply, not the currently active
    stream. And it does not remove it twice on a mesh_send_reply
    call. The reply h2_stream is NULL when not in use, for more
    initialisation.
    * Fix dnstap wakeup, a running wakeup timer is left to expire and
    not increased, a timer is started when the dtio thread is
    sleeping, the timer set disabled when the dtio thread goes to
    sleep, and after sleep the thread checks to see if there are
    messages to log immediately.
    * Merge #1110: Make fallthrough explicit for libworker.c.
    * For #1110: Test for fallthrough attribute in configure and add
    fallthrough attribute annotations.
    * Fix compile when the compiler does not support the noreturn
    attribute.
    * Fix to have empty definition when not supported for weak
    attribute.
    * Fix uninitialized variable warning in create_tcp_accept_sock.
    * Fix link of dnstap without openssl.
    * Fix link of unbound-dnstap-socket without openssl.
    * Fix #1106: ratelimit-below-domain logs the wrong FROM address.
    * Cleanup ede.tdir test.
    * For #935 and #1104, clarify RPZ order and semantics.
    * Fix to document parameters of auth_zone_verify_zonemd_with_key.
    * Fix for #1114: Fix that cache fill for forward-host names is
    performed, so that with nonzero target-fetch-policy it fetches
    forwarder addresses and uses them from cache. Also updated that
    delegation point cache fill routines use CDflag for AAAA
    message lookups, so that its negative lookup stops a recursion
    since the cache uses the bit for disambiguation for dns64 but
    the recursion uses CDflag for the AAAA target lookups, so the
    check correctly stops a useless recursion by its cache lookup.
    * Fix dnstap test program, cleans up to have clean memory on
    exit, for tap_data_free, does not delete NULL items. Also it
    does not try to free the tail, specifically in the free of the
    list since that picked up the next item in the list for its
    loop causing invalid free. Added internal unit test to
    unbound-dnstap-socket for that.
    * Fix that the worker mem report with alloc stats does not
    attempt to print memory use of forwards and hints if they have
    been deleted already.
    * Fix that alloc stats has strdup checks, it stops debuggers from
    complaining about mismatch at free time.
    * Fix testbound for alloc stats strdup in util/alloc.c.
    * Fix that alloc stats for forwards and hints are printed, and
    when alloc stats is enabled, the unit test for unbound control
    waits for reloads to complete.
    * Fix that for windows the module startup is called and sets up
    the module-config.
    * Fix spelling for the cache-min-negative-ttl entry in the
    example.conf.

++++ passt:

  - Update to version 20240814.61c0b0d:
    * flow: Don't crash if guest attempts to connect to port 0
    * conf: Don't ignore -t and -u options after -D
    * ndp.c: Turn NDP responder into more declarative implementation
    * conf: Delay handling -D option until after addresses are configured
    * Correct inaccurate comments on ip[46]_ctx::addr
    * log: Don't prefix message with timestamp on --debug if it's a continuation
    * conf: Stop parsing options at first non-option argument
    * passt, util: Close any open file that the parent might have leaked
    * nstool: Propagate SIGTERM to processes executed in the namespace
    * nstool: Fix some trivial typos
    * log: Avoid duplicate calls to logtime()
    * log: Handle errors from clock_gettime()
    * log: Correct formatting of timestamps
    * util: Some corrections for timespec_diff_us
    * conf, pasta: Make -g and -a skip route/addresses copy for matching IP version only

++++ selinux-policy:

  - Update to version 20240604+git376.0406315d:
    * Dontaudit dac_override of fstab generator (bsc#1229127)
    * Update libvirt policy
    * Add port 80/udp and 443/udp to http_port_t definition
    * Additional updates stalld policy for bpf usage
    * Label systemd-pcrextend and systemd-pcrlock properly
    * Label /run/udev/rules.d as udev_rules_t
    * Provide type for sysstat lock files (bsc#1228247)
    * Allow coreos_installer_t work with partitions
    * Revert "Allow coreos-installer-generator work with partitions"
    * Add policy for systemd-pcrextend
    * Update policy for systemd-getty-generator
    * Allow snapper to delete unlabeled_t files (bsc#1228889)
    * Allow ip command write to ipsec's logs
    * Allow virt_driver_domain read virtd-lxc files in /proc
    * Revert "Allow svirt read virtqemud fifo files"
    * Update virtqemud policy for libguestfs usage
    * Allow virtproxyd create and use its private tmp files
    * Allow virtproxyd read network state
    * Allow virt_driver_domain create and use log files in /var/log (bsc#1227483)
    * Allow samba-dcerpcd work with ctdb cluster
    * Allow NetworkManager_dispatcher_t send SIGKILL to plugins
    * Allow setroubleshootd execute sendmail with a domain transition
    * Allow key.dns_resolve set attributes on the kernel key ring
    * Update qatlib policy for v24.02 with new features
    * Label /var/lib/systemd/sleep with systemd_sleep_var_lib_t
    * Allow tlp status power services
    * Allow virtqemud domain transition on passt execution
    * Allow virt_driver_domain connect to systemd-userdbd over a unix socket
    * Allow boothd connect to systemd-userdbd over a unix socket
    * Update policy for awstats scripts
    * Allow bitlbee execute generic programs in system bin directories
    * Allow login_userdomain read aliases file
    * Allow login_userdomain read ipsec config files
    * Allow login_userdomain read all pid files
    * Allow rsyslog read systemd-logind session files
    * Allow libvirt-dbus stream connect to virtlxcd
    * Use new kanidm interfaces
    * Initial module for kanidm
    * Update bootupd policy
    * Allow rhsmcertd read/write access to /dev/papr-sysparm
    * Label /dev/papr-sysparm and /dev/papr-vpd
    * Allow abrt-dump-journal-core connect to winbindd
    * Allow systemd-hostnamed shut down nscd
    * Allow systemd-pstore send a message to syslogd over a unix domain
    * Allow postfix_domain map postfix_etc_t files
    * Allow microcode create /sys/devices/system/cpu/microcode/reload
    * Allow rhsmcertd read, write, and map ica tmpfs files
    * Support SGX devices
    * Allow initrc_t transition to passwd_t
    * Update fstab and cryptsetup generators policy
    * Allow xdm_t read and write the dma device
    * Update stalld policy for bpf usage
    * Allow systemd_gpt_generator to getattr on DOS directories
    * Make cgroup_memory_pressure_t a part of the file_type attribute
    * Allow ssh_t to change role to system_r
    * Update policy for coreos generators
    * Allow init_t nnp domain transition to firewalld_t
    * Label /run/modprobe.d with modules_conf_t
    * Allow virtnodedevd run udev with a domain transition
    * Allow virtnodedev_t create and use virtnodedev_lock_t
    * Allow virtstoraged manage files with virt_content_t type
    * Allow virtqemud unmount a filesystem with extended attributes
    * Allow svirt_t connect to unconfined_t over a unix domain socket
    * Update afterburn file transition policy
    * Allow systemd_generator read attributes of all filesystems
    * Allow fstab-generator read and write cryptsetup-generator unit file
    * Allow cryptsetup-generator read and write fstab-generator unit file
    * Allow systemd_generator map files in /etc
    * Allow systemd_generator read init's process state
    * Allow coreos-installer-generator read sssd public files
    * Allow coreos-installer-generator work with partitions
    * Label /etc/mdadm.conf.d with mdadm_conf_t
    * Confine coreos generators
    * Label /run/metadata with afterburn_runtime_t
    * Allow afterburn list ssh home directory
    * Label samba certificates with samba_cert_t
    * Label /run/coreos-installer-reboot with coreos_installer_var_run_t
    * Allow virtqemud read virt-dbus process state
    * Allow staff user dbus chat with virt-dbus
    * Allow staff use watch /run/systemd
    * Allow systemd_generator to write kmsg
    * Allow virtqemud connect to sanlock over a unix stream socket
    * Allow virtqemud relabel virt_var_run_t directories
    * Allow svirt_tcg_t read vm sysctls
    * Allow virtnodedevd connect to systemd-userdbd over a unix socket
    * Allow svirt read virtqemud fifo files
    * Allow svirt attach_queue to a virtqemud tun_socket
    * Allow virtqemud run ssh client with a transition
    * Allow virt_dbus_t connect to virtqemud_t over a unix stream socket
    * Update keyutils policy
    * Allow sshd_keygen_t connect to userdbd over a unix stream socket
    * Allow postfix-smtpd read mysql config files
    * Allow locate stream connect to systemd-userdbd
    * Allow the staff user use wireshark
    * Allow updatedb connect to userdbd over a unix stream socket
    * Allow gpg_t set attributes of public-keys.d
    * Allow gpg_t get attributes of login_userdomain stream
    * Allow systemd_getty_generator_t read /proc/1/environ
    * Allow systemd_getty_generator_t to read and write to tty_device_t
    * Drop publicfile module
    * Remove permissive domain for systemd_nsresourced_t
    * Change fs_dontaudit_write_cgroup_files() to apply to cgroup_t
    * Label /usr/bin/samba-gpupdate with samba_gpupdate_exec_t
    * Allow to create and delete socket files created by rhsm.service
    * Allow virtnetworkd exec shell when virt_hooks_unconfined is on
    * Allow unconfined_service_t transition to passwd_t
    * Support /var is empty
    * Allow abrt-dump-journal read all non_security socket files
    * Allow timemaster write to sysfs files
    * Dontaudit domain write cgroup files
    * Label /usr/lib/node_modules/npm/bin with bin_t
    * Allow ip the setexec permission
    * Allow systemd-networkd write files in /var/lib/systemd/network
    * Fix typo in systemd_nsresourced_prog_run_bpf()

------------------------------------------------------------------
------------------  2024-8-14  -  Aug 14 2024  -------------------
------------------------------------------------------------------

++++ keepalived:

  - Update to version 2.3.1+git.1723301895.df93f341:
    * all: Ensure pid file exists when respawning child process
    * vrrp: check ifindex != 0 before using the interface
    * vrrp: Duplicate/drop MLDv1 listener reports on VMACs
    * core: ensure only one instance of keepalived can run per config_id
    * configure: add --enable-(cflags,cppflags,ldflags) options
    * configure: add --enable-sanitize-(undefined,leak,memory,scudo,hwaddress) options
    * vrrp: change vrrp_in_chk_vips to return bool rather than int
    * core: cosmetic code layout change
    * core: remove some duplicate include files
    * vrrp: stop memory leak when error in configuring vrrp_iptables
    (bsc#1228123) VUL-0: CVE-2024-41184: keepalived: integer overflow in vrrp_ipsets_handler

++++ kernel-default:

  - Update patch reference for SPI patch (jsc#PED-10105)
  - commit a896d55
  - kabi fix for KVM: s390: fix LPSWEY handling (bsc#1227634
    git-fixes).
  - KVM: s390: fix LPSWEY handling (bsc#1227634 git-fixes).
  - commit 576de67
  - kernfs: Convert kernfs_path_from_node_locked() from strlcpy()
    to strscpy() (bsc#1229134).
  - Refresh
    patches.suse/cgroup-cpuset-Prevent-UAF-in-proc_cpuset_show.patch.
  - commit bc8376b
  - Update patch reference for iwlwifi fix (jsc#PED-10055)
  - commit 73fda85
  - Input: i8042 - add Fujitsu Lifebook E756 to i8042 quirk table
    (bsc#1229056).
  - commit 0ae7f4e
  - bpf: hardcode BPF_PROG_PACK_SIZE to 2MB * num_possible_nodes()
    (git-fixes).
  - bpf: don't infer PTR_TO_CTX for programs with unnamed context
    type (git-fixes).
  - bpf: handle bpf_user_pt_regs_t typedef explicitly for PTR_TO_CTX
    global arg (git-fixes).
  - bpf: Mark bpf_spin_{lock,unlock}() helpers with notrace
    correctly (git-fixes).
  - commit dd0591b
  - net, sunrpc: Remap EPERM in case of connection failure in
    xs_tcp_setup_socket (CVE-2024-42246 bsc#1228989).
  - commit 12865c8
  - tools/resolve_btfids: Fix comparison of distinct pointer types
    warning in resolve_btfids (git-fixes).
  - tools/resolve_btfids: fix build with musl libc (git-fixes).
  - commit f42b517

++++ kernel-rt:

  - Update patch reference for SPI patch (jsc#PED-10105)
  - commit a896d55
  - kabi fix for KVM: s390: fix LPSWEY handling (bsc#1227634
    git-fixes).
  - KVM: s390: fix LPSWEY handling (bsc#1227634 git-fixes).
  - commit 576de67
  - kernfs: Convert kernfs_path_from_node_locked() from strlcpy()
    to strscpy() (bsc#1229134).
  - Refresh
    patches.suse/cgroup-cpuset-Prevent-UAF-in-proc_cpuset_show.patch.
  - commit bc8376b
  - Update patch reference for iwlwifi fix (jsc#PED-10055)
  - commit 73fda85
  - Input: i8042 - add Fujitsu Lifebook E756 to i8042 quirk table
    (bsc#1229056).
  - commit 0ae7f4e
  - bpf: hardcode BPF_PROG_PACK_SIZE to 2MB * num_possible_nodes()
    (git-fixes).
  - bpf: don't infer PTR_TO_CTX for programs with unnamed context
    type (git-fixes).
  - bpf: handle bpf_user_pt_regs_t typedef explicitly for PTR_TO_CTX
    global arg (git-fixes).
  - bpf: Mark bpf_spin_{lock,unlock}() helpers with notrace
    correctly (git-fixes).
  - commit dd0591b
  - net, sunrpc: Remap EPERM in case of connection failure in
    xs_tcp_setup_socket (CVE-2024-42246 bsc#1228989).
  - commit 12865c8
  - tools/resolve_btfids: Fix comparison of distinct pointer types
    warning in resolve_btfids (git-fixes).
  - tools/resolve_btfids: fix build with musl libc (git-fixes).
  - commit f42b517

++++ lz4:

  - Switch to cmake build system: Creates extra cmake modules for
    consuming projects

++++ ncurses:

  - Add patch fix-20240810.patch
    * Workaround for changes in last patch 20240810 that is provide
    GLOB_FULLPATH_POSIX and GLOB_FULLPATH_OTHER in status script

++++ polkit:

  - BuildRequire gettext-devel instead of gettext: Allows OBS to
    shortcut throught gettext-runtime-mini.

++++ wtmpdb:

  - Update to version 0.13.0+git.20240814:
    * wtmpdb-update-boot service requires dbus

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20240813 release (bsc#1229129)
  - CVE-2024-24853: Security updates for [INTEL-SA-01083](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01083.html)
  - CVE-2024-25939: Security updates for [INTEL-SA-01118](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01118.html)
  - CVE-2024-24980: Security updates for [INTEL-SA-01100](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01100.html)
  - CVE-2023-42667: Security updates for [INTEL-SA-01038](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01038.html)
  - CVE-2023-49141: Security updates for [INTEL-SA-01046](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01046.html)
    Other issues fixed:
  - Update for functional issues. Refer to [Intel® Core™ Ultra Processor](https://cdrdv2.intel.com/v1/dl/getContent/792254) for details.
  - Update for functional issues. Refer to [3rd Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/637780) for details.
  - Update for functional issues. Refer to [3rd Generation Intel® Xeon® Scalable Processors Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/634897) for details.
  - Update for functional issues. Refer to [2nd Generation Intel® Xeon® Processor Scalable Family Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/338848) for details
  - Update for functional issues. Refer to [Intel® Xeon® D-2700 Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/714071) for details.
  - Update for functional issues. Refer to [Intel® Xeon® E-2300 Processor Specification Update ](https://cdrdv2.intel.com/v1/dl/getContent/709192) for details.
  - Update for functional issues. Refer to [13th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/740518) for details.
  - Update for functional issues. Refer to [12th Generation Intel® Core™ Processor Family](https://cdrdv2.intel.com/v1/dl/getContent/682436) for details.
  - Update for functional issues. Refer to [11th Gen Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/631123) for details.
  - Update for functional issues. Refer to [10th Gen Intel® Core™ Processor Families Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/341079) for details.
  - Update for functional issues. Refer to [10th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/615213) for details.
  - Update for functional issues. Refer to [8th and 9th Generation Intel® Core™ Processor Family Spec Update](https://cdrdv2.intel.com/v1/dl/getContent/337346) for details.
  - Update for functional issues. Refer to [8th Generation Intel® Core™ Processor Families Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/338025) for details.
  - Update for functional issues. Refer to [7th and 8th Generation Intel® Core™ Processor Specification Update](https://cdrdv2.intel.com/v1/dl/getContent/334663) for details.
  - Update for functional issues. Refer to [Intel® Processors and Intel® Core™ i3 N-Series](https://cdrdv2.intel.com/v1/dl/getContent/764616) for details.
  - Update for functional issues. Refer to [Intel® Atom® x6000E Series, and Intel® Pentium® and Celeron® N and J Series Processors for Internet of Things (IoT) Applications](https://cdrdv2.intel.com/v1/dl/getContent/636674) for details.
    Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | AML-Y22        | H0       | 06-8e-09/10 | 000000f4 | 000000f6 | Core Gen8 Mobile
    | AML-Y42        | V0       | 06-8e-0c/94 | 000000fa | 000000fc | Core Gen10 Mobile
    | CFL-H          | R0       | 06-9e-0d/22 | 000000fc | 00000100 | Core Gen9 Mobile
    | CFL-H/S        | P0       | 06-9e-0c/22 | 000000f6 | 000000f8 | Core Gen9
    | CFL-H/S/E3     | U0       | 06-9e-0a/22 | 000000f6 | 000000f8 | Core Gen8 Desktop, Mobile, Xeon E
    | CFL-S          | B0       | 06-9e-0b/02 | 000000f4 | 000000f6 | Core Gen8
    | CFL-S          | P0       | 06-9e-0c/22 | 000000f6 | 000000f8 | Core Gen9 Desktop
    | CFL-U43e       | D0       | 06-8e-0a/c0 | 000000f4 | 000000f6 | Core Gen8 Mobile
    | CLX-SP         | B1       | 06-55-07/bf | 05003605 | 05003707 | Xeon Scalable Gen2
    | CML-H          | R1       | 06-a5-02/20 | 000000fa | 000000fc | Core Gen10 Mobile
    | CML-S102       | Q0       | 06-a5-05/22 | 000000fa | 000000fc | Core Gen10
    | CML-S62        | G1       | 06-a5-03/22 | 000000fa | 000000fc | Core Gen10
    | CML-U42        | V0       | 06-8e-0c/94 | 000000fa | 000000fc | Core Gen10 Mobile
    | CML-U62 V1     | A0       | 06-a6-00/80 | 000000fa | 000000fe | Core Gen10 Mobile
    | CML-U62 V2     | K1       | 06-a6-01/80 | 000000fa | 000000fc | Core Gen10 Mobile
    | CML-Y42        | V0       | 06-8e-0c/94 | 000000fa | 000000fc | Core Gen10 Mobile
    | CPX-SP         | A1       | 06-55-0b/bf | 07002802 | 07002904 | Xeon Scalable Gen3
    | EHL            | B1       | 06-96-01/01 | 00000019 | 0000001a | Pentium J6426/N6415, Celeron J6412/J6413/N6210/N6211, Atom x6000E
    | ICL-D          | B0       | 06-6c-01/10 | 01000290 | 010002b0 | Xeon D-17xx, D-27xx
    | ICL-U/Y        | D1       | 06-7e-05/80 | 000000c4 | 000000c6 | Core Gen10 Mobile
    | ICX-SP         | Dx/M1    | 06-6a-06/87 | 0d0003d1 | 0d0003e7 | Xeon Scalable Gen3
    | KBL-R U        | Y0       | 06-8e-0a/c0 | 000000f4 | 000000f6 | Core Gen8 Mobile
    | KBL-U23e       | J1       | 06-8e-09/c0 | 000000f4 | 000000f6 | Core Gen7 Mobile
    | KBL-U/Y        | H0       | 06-8e-09/c0 | 000000f4 | 000000f6 | Core Gen7 Mobile
    | MTL            | C-0      | 06-aa-04/e6 | 0000001c | 0000001e | Core™ Ultra Processor
    | RKL-S          | B0       | 06-a7-01/02 | 0000005e | 00000062 | Core Gen11
    | TGL            | B0/B1    | 06-8c-01/80 | 000000b6 | 000000b8 | Core Gen11 Mobile
    | TGL-H          | R0       | 06-8d-01/c2 | 00000050 | 00000052 | Core Gen11 Mobile
    | TGL-R          | C0       | 06-8c-02/c2 | 00000036 | 00000038 | Core Gen11 Mobile
    | WHL-U          | V0       | 06-8e-0c/94 | 000000fa | 000000fc | Core Gen8 Mobile
    | WHL-U          | W0       | 06-8e-0b/d0 | 000000f4 | 000000f6 | Core Gen8 Mobile

------------------------------------------------------------------
------------------  2024-8-13  -  Aug 13 2024  -------------------
------------------------------------------------------------------

++++ lvm2-device-mapper:

  - lvm2-monitor.service fails to start (boo#1228854)
    + bug-1228854_lvm2-monitor-service-start-after-system-fully-booted.patch

++++ docker-compose:

  - Update to version 2.29.2:
    * initial sync files that modified after image creation
    * initial sync for root directory
    * Removes redundant condition from toAPIBuildOptions in build.go
    * docs: Update docker compose kill usage
    * Fix stop on file chane for sync-restart action
    * bump engine and cli to v27.1.1, buildx to v0.16.1
    * remove all dependabot update PRs for OTel dependencies
    * gp.mod: github.com/gofrs/flock v0.12.1
    * go.mod: golang.org/x/sys v0.22.0
    * update to go1.21.12

++++ grub2:

  - Introduces a new package, grub2-x86_64-efi-bls, which includes a
    straightforward grubbls.efi file. This file can be copied to the EFI System
    Partition (ESP) along with boot fragments in the Boot Loader Specification
    (BLS) format
    * 0001-Streamline-BLS-and-improve-PCR-stability.patch
  - Fix crash in bli module (bsc#1226497)
    * 0001-bli-Fix-crash-in-get_part_uuid.patch
  - Rework package dependencies: grub2-common now includes common userland
    utilities and is required by grub2 platform packages. grub2 is now a meta
    package that pulls in the default platform package.

++++ kernel-default:

  - btrfs: fix leak of qgroup extent records after transaction abort
    (git-fixes).
  - btrfs: fix ordered extent split error handling in
    btrfs_dio_submit_io (git-fixes).
  - btrfs: use irq safe locking when running and adding delayed
    iputs (git-fixes).
  - commit 59b18df
  - btrfs: fix extent map use-after-free when adding pages to
    compressed bio (git-fixes).
  - commit b3e7c96
  - Drop libata patch that caused a regression (bsc#1229054)
  - commit 3d5faca
  - btrfs: fix double inode unlock for direct IO sync writes
    (git-fixes).
  - btrfs: fix corruption after buffer fault in during direct IO
    append write (git-fixes).
  - btrfs: use a btrfs_inode local variable at btrfs_sync_file()
    (git-fixes).
  - btrfs: pass a btrfs_inode to btrfs_wait_ordered_range()
    (git-fixes).
  - btrfs: pass a btrfs_inode to btrfs_fdatawrite_range()
    (git-fixes).
  - btrfs: use a btrfs_inode in the log context (struct
    btrfs_log_ctx) (git-fixes).
  - btrfs: make btrfs_finish_ordered_extent() return void
    (git-fixes).
  - btrfs: ensure fast fsync waits for ordered extents after a
    write failure (git-fixes).
  - btrfs: rename err to ret in btrfs_direct_write() (git-fixes).
  - btrfs: uninline some static inline helpers from tree-log.h
    (git-fixes).
  - btrfs: use btrfs_finish_ordered_extent to complete buffered
    writes (git-fixes).
  - btrfs: use btrfs_finish_ordered_extent to complete direct writes
    (git-fixes).
  - btrfs: use btrfs_finish_ordered_extent to complete compressed
    writes (git-fixes).
  - btrfs: open code end_extent_writepage in
    end_bio_extent_writepage (git-fixes).
  - btrfs: add a btrfs_finish_ordered_extent helper (git-fixes).
  - btrfs: factor out a btrfs_queue_ordered_fn helper (git-fixes).
  - btrfs: factor out a can_finish_ordered_extent helper
    (git-fixes).
  - btrfs: use bbio->ordered in btrfs_csum_one_bio (git-fixes).
  - btrfs: add an ordered_extent pointer to struct btrfs_bio
    (git-fixes).
  - btrfs: open code btrfs_bio_end_io in btrfs_dio_submit_io
    (git-fixes).
  - btrfs: add a is_data_bbio helper (git-fixes).
  - btrfs: remove btrfs_add_ordered_extent (git-fixes).
  - btrfs: pass an ordered_extent to btrfs_submit_compressed_write
    (git-fixes).
  - btrfs: pass an ordered_extent to btrfs_reloc_clone_csums
    (git-fixes).
  - btrfs: merge the two calls to btrfs_add_ordered_extent in
    run_delalloc_nocow (git-fixes).
  - btrfs: limit write bios to a single ordered extent (git-fixes).
  - commit 90ea198
  - powerpc/topology: Check if a core is online (bsc#1214285
    bsc#1205462 ltc#200161 ltc#200588 git-fixes).
  - cpu/SMT: Enable SMT only if a core is online (bsc#1214285
    bsc#1205462 ltc#200161 ltc#200588 git-fixes).
  - commit 3d340df
  - Update patch reference for MD patch (jsc#PED-10029 jsc#PED-10045)
  - commit 1bf8fd1
  - Update patch refefernce for MFD patch (jsc#PED-10029)
  - commit f36d989
  - platform/x86/amd/hsmp: Check HSMP support on AMD family of processors (jsc#PED-8779).
  - commit c606582
  - platform/x86/amd/hsmp: switch to use device_add_groups() (jsc#PED-8779).
  - commit 4007799
  - platform/x86/amd/hsmp: Change devm_kzalloc() to devm_kcalloc() (jsc#PED-8779).
  - commit 9854658
  - platform/x86/amd/hsmp: Remove extra parenthesis and add a space (jsc#PED-8779).
  - commit 0a84b39
  - platform/x86/amd/hsmp: Check num_sockets against MAX_AMD_SOCKETS (jsc#PED-8779).
  - commit 85ba4b7
  - platform/x86/amd/hsmp: Non-ACPI support for AMD F1A_M00~0Fh (jsc#PED-8779).
  - commit 1b89039
  - platform/x86/amd/hsmp: Add support for ACPI based probing (jsc#PED-8779).
  - commit 73c2646
  - platform/x86/amd/hsmp: Restructure sysfs group creation (jsc#PED-8779).
  - commit 9e31807
  - platform/x86/amd/hsmp: Move dev from platdev to hsmp_socket (jsc#PED-8779).
  - commit f6baa58
  - platform/x86/amd/hsmp: Define a struct to hold mailbox regs (jsc#PED-8779).
  - commit 07f864e
  - platform/x86/amd/hsmp: Create static func to handle platdev (jsc#PED-8779).
  - commit d5ea9be
  - platform/x86/amd/hsmp: Cache pci_dev in struct hsmp_socket (jsc#PED-8779).
  - commit d314cb6
  - platform/x86/amd/hsmp: Move hsmp_test to probe (jsc#PED-8779).
  - commit b00829d
  - tools/resolve_btfids: Fix cross-compilation to non-host
    endianness (git-fixes).
  - tools/resolve_btfids: Refactor set sorting with types from
    btf_ids.h (git-fixes).
  - libbpf: Use OPTS_SET() macro in bpf_xdp_query() (git-fixes).
  - commit 6fc7b9e
  - libbpf: Add missing LIBBPF_API annotation to
    libbpf_set_memlock_rlim API (git-fixes).
  - selftests/bpf: Disable IPv6 for lwt_redirect test (git-fixes).
  - libbpf: Fix faccessat() usage on Android (git-fixes).
  - selftests/bpf: Wait for the netstamp_needed_key static key to
    be turned on (git-fixes).
  - commit 89d6f3b
  - selftests/bpf: Fix the flaky tc_redirect_dtime test (git-fixes).
  - selftest/bpf: Add map_in_maps with BPF_MAP_TYPE_PERF_EVENT_ARRAY
    values (git-fixes).
  - libbpf: Apply map_set_def_max_entries() for inner_maps on
    creation (git-fixes).
  - selftests/bpf: Fix potential premature unload in bpf_testmod
    (git-fixes).
  - bpftool: Silence build warning about calloc() (git-fixes).
  - commit 7aaf2fc
  - x86/asm: Use %c/%n instead of %P operand modifier in asm  templates (git-fixes).
  - Refresh
    patches.suse/x86-uaccess-Fix-missed-zeroing-of-ia32-u64-get_user-range-.patch.
  - commit 97ffc68
  - selftests/bpf: Fix up xdp bonding test wrt feature flags
    (git-fixes).
  - selftests/bpf: fix compiler warnings in RELEASE=1 mode
    (git-fixes).
  - selftests/bpf: Relax time_tai test for equal timestamps in
    tai_forward (git-fixes).
  - bpf: Set uattr->batch.count as zero before batched update or
    deletion (git-fixes).
  - bpf: Remove unnecessary wait from bpf_map_copy_value()
    (git-fixes).
  - commit 19ebfe6
  - bpf: enforce precision of R0 on callback return (git-fixes).
  - selftests/bpf: Fix erroneous bitmask operation (git-fixes).
  - bpf/tests: Remove duplicate JSGT tests (git-fixes).
  - bpftool: mark orphaned programs during prog show (git-fixes).
  - commit 2b6a18e
  - bpf: Fix a few selftest failures due to llvm18 change
    (git-fixes).
  - selftests/bpf: Fix issues in setup_classid_environment()
    (git-fixes).
  - selftests/bpf: Add assert for user stacks in test_task_stack
    (git-fixes).
  - selftests/bpf: Fix pyperf180 compilation failure with clang18
    (git-fixes).
  - bpf: Add crosstask check to __bpf_get_stack (git-fixes).
  - commit fce00e9
  - bpf, lpm: Fix check prefixlen before walking trie (git-fixes).
  - selftests/bpf: satisfy compiler by having explicit return in
    btf test (git-fixes).
  - selftests/bpf: fix RELEASE=1 build for tc_opts (git-fixes).
  - bpf: Fix prog_array_map_poke_run map poke update (git-fixes).
  - commit ca200c8

++++ kernel-firmware-all:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-amdgpu:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-ath10k:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-ath11k:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-ath12k:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-atheros:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-bluetooth:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-bnx2:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-brcm:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-chelsio:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-dpaa2:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-i915:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-intel:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-iwlwifi:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-liquidio:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-marvell:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-media:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-mediatek:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-mellanox:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-mwifiex:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-network:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-nfp:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-nvidia:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-platform:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-prestera:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-qcom:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-qlogic:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-radeon:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-realtek:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-serial:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-sound:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-ti:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-ueagle:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-firmware-usb-network:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

++++ kernel-rt:

  - btrfs: fix leak of qgroup extent records after transaction abort
    (git-fixes).
  - btrfs: fix ordered extent split error handling in
    btrfs_dio_submit_io (git-fixes).
  - btrfs: use irq safe locking when running and adding delayed
    iputs (git-fixes).
  - commit 59b18df
  - btrfs: fix extent map use-after-free when adding pages to
    compressed bio (git-fixes).
  - commit b3e7c96
  - Drop libata patch that caused a regression (bsc#1229054)
  - commit 3d5faca
  - btrfs: fix double inode unlock for direct IO sync writes
    (git-fixes).
  - btrfs: fix corruption after buffer fault in during direct IO
    append write (git-fixes).
  - btrfs: use a btrfs_inode local variable at btrfs_sync_file()
    (git-fixes).
  - btrfs: pass a btrfs_inode to btrfs_wait_ordered_range()
    (git-fixes).
  - btrfs: pass a btrfs_inode to btrfs_fdatawrite_range()
    (git-fixes).
  - btrfs: use a btrfs_inode in the log context (struct
    btrfs_log_ctx) (git-fixes).
  - btrfs: make btrfs_finish_ordered_extent() return void
    (git-fixes).
  - btrfs: ensure fast fsync waits for ordered extents after a
    write failure (git-fixes).
  - btrfs: rename err to ret in btrfs_direct_write() (git-fixes).
  - btrfs: uninline some static inline helpers from tree-log.h
    (git-fixes).
  - btrfs: use btrfs_finish_ordered_extent to complete buffered
    writes (git-fixes).
  - btrfs: use btrfs_finish_ordered_extent to complete direct writes
    (git-fixes).
  - btrfs: use btrfs_finish_ordered_extent to complete compressed
    writes (git-fixes).
  - btrfs: open code end_extent_writepage in
    end_bio_extent_writepage (git-fixes).
  - btrfs: add a btrfs_finish_ordered_extent helper (git-fixes).
  - btrfs: factor out a btrfs_queue_ordered_fn helper (git-fixes).
  - btrfs: factor out a can_finish_ordered_extent helper
    (git-fixes).
  - btrfs: use bbio->ordered in btrfs_csum_one_bio (git-fixes).
  - btrfs: add an ordered_extent pointer to struct btrfs_bio
    (git-fixes).
  - btrfs: open code btrfs_bio_end_io in btrfs_dio_submit_io
    (git-fixes).
  - btrfs: add a is_data_bbio helper (git-fixes).
  - btrfs: remove btrfs_add_ordered_extent (git-fixes).
  - btrfs: pass an ordered_extent to btrfs_submit_compressed_write
    (git-fixes).
  - btrfs: pass an ordered_extent to btrfs_reloc_clone_csums
    (git-fixes).
  - btrfs: merge the two calls to btrfs_add_ordered_extent in
    run_delalloc_nocow (git-fixes).
  - btrfs: limit write bios to a single ordered extent (git-fixes).
  - commit 90ea198
  - powerpc/topology: Check if a core is online (bsc#1214285
    bsc#1205462 ltc#200161 ltc#200588 git-fixes).
  - cpu/SMT: Enable SMT only if a core is online (bsc#1214285
    bsc#1205462 ltc#200161 ltc#200588 git-fixes).
  - commit 3d340df
  - Update patch reference for MD patch (jsc#PED-10029 jsc#PED-10045)
  - commit 1bf8fd1
  - Update patch refefernce for MFD patch (jsc#PED-10029)
  - commit f36d989
  - platform/x86/amd/hsmp: Check HSMP support on AMD family of processors (jsc#PED-8779).
  - commit c606582
  - platform/x86/amd/hsmp: switch to use device_add_groups() (jsc#PED-8779).
  - commit 4007799
  - platform/x86/amd/hsmp: Change devm_kzalloc() to devm_kcalloc() (jsc#PED-8779).
  - commit 9854658
  - platform/x86/amd/hsmp: Remove extra parenthesis and add a space (jsc#PED-8779).
  - commit 0a84b39
  - platform/x86/amd/hsmp: Check num_sockets against MAX_AMD_SOCKETS (jsc#PED-8779).
  - commit 85ba4b7
  - platform/x86/amd/hsmp: Non-ACPI support for AMD F1A_M00~0Fh (jsc#PED-8779).
  - commit 1b89039
  - platform/x86/amd/hsmp: Add support for ACPI based probing (jsc#PED-8779).
  - commit 73c2646
  - platform/x86/amd/hsmp: Restructure sysfs group creation (jsc#PED-8779).
  - commit 9e31807
  - platform/x86/amd/hsmp: Move dev from platdev to hsmp_socket (jsc#PED-8779).
  - commit f6baa58
  - platform/x86/amd/hsmp: Define a struct to hold mailbox regs (jsc#PED-8779).
  - commit 07f864e
  - platform/x86/amd/hsmp: Create static func to handle platdev (jsc#PED-8779).
  - commit d5ea9be
  - platform/x86/amd/hsmp: Cache pci_dev in struct hsmp_socket (jsc#PED-8779).
  - commit d314cb6
  - platform/x86/amd/hsmp: Move hsmp_test to probe (jsc#PED-8779).
  - commit b00829d
  - tools/resolve_btfids: Fix cross-compilation to non-host
    endianness (git-fixes).
  - tools/resolve_btfids: Refactor set sorting with types from
    btf_ids.h (git-fixes).
  - libbpf: Use OPTS_SET() macro in bpf_xdp_query() (git-fixes).
  - commit 6fc7b9e
  - libbpf: Add missing LIBBPF_API annotation to
    libbpf_set_memlock_rlim API (git-fixes).
  - selftests/bpf: Disable IPv6 for lwt_redirect test (git-fixes).
  - libbpf: Fix faccessat() usage on Android (git-fixes).
  - selftests/bpf: Wait for the netstamp_needed_key static key to
    be turned on (git-fixes).
  - commit 89d6f3b
  - selftests/bpf: Fix the flaky tc_redirect_dtime test (git-fixes).
  - selftest/bpf: Add map_in_maps with BPF_MAP_TYPE_PERF_EVENT_ARRAY
    values (git-fixes).
  - libbpf: Apply map_set_def_max_entries() for inner_maps on
    creation (git-fixes).
  - selftests/bpf: Fix potential premature unload in bpf_testmod
    (git-fixes).
  - bpftool: Silence build warning about calloc() (git-fixes).
  - commit 7aaf2fc
  - x86/asm: Use %c/%n instead of %P operand modifier in asm  templates (git-fixes).
  - Refresh
    patches.suse/x86-uaccess-Fix-missed-zeroing-of-ia32-u64-get_user-range-.patch.
  - commit 97ffc68
  - selftests/bpf: Fix up xdp bonding test wrt feature flags
    (git-fixes).
  - selftests/bpf: fix compiler warnings in RELEASE=1 mode
    (git-fixes).
  - selftests/bpf: Relax time_tai test for equal timestamps in
    tai_forward (git-fixes).
  - bpf: Set uattr->batch.count as zero before batched update or
    deletion (git-fixes).
  - bpf: Remove unnecessary wait from bpf_map_copy_value()
    (git-fixes).
  - commit 19ebfe6
  - bpf: enforce precision of R0 on callback return (git-fixes).
  - selftests/bpf: Fix erroneous bitmask operation (git-fixes).
  - bpf/tests: Remove duplicate JSGT tests (git-fixes).
  - bpftool: mark orphaned programs during prog show (git-fixes).
  - commit 2b6a18e
  - bpf: Fix a few selftest failures due to llvm18 change
    (git-fixes).
  - selftests/bpf: Fix issues in setup_classid_environment()
    (git-fixes).
  - selftests/bpf: Add assert for user stacks in test_task_stack
    (git-fixes).
  - selftests/bpf: Fix pyperf180 compilation failure with clang18
    (git-fixes).
  - bpf: Add crosstask check to __bpf_get_stack (git-fixes).
  - commit fce00e9
  - bpf, lpm: Fix check prefixlen before walking trie (git-fixes).
  - selftests/bpf: satisfy compiler by having explicit return in
    btf test (git-fixes).
  - selftests/bpf: fix RELEASE=1 build for tc_opts (git-fixes).
  - bpf: Fix prog_array_map_poke_run map poke update (git-fixes).
  - commit ca200c8

++++ lvm2:

  - lvm2-monitor.service fails to start (boo#1228854)
    + bug-1228854_lvm2-monitor-service-start-after-system-fully-booted.patch

++++ ncurses:

  - Add ncurses patch 20240810
    + modify misc/Makefile.in and misc/run_tic.in so that $DESTDIR is set
    and used only in the makefile.
    + modify CF_WITH_PKG_CONFIG_LIBDIR to allow for pkg-config using
    DOS/Windows pathname syntax (report by Eli Zaretskii).
    + improve glob-expressions in configure script
    + remove unused Get_Menu_Screen() macro from menu.priv.h
    + update config.guess, config.sub
  - Add ncurses patch 20240727
    + improve formatting/style of manpages (patches by Branden Robinson).
    + fixes for compiler warnings/cppcheck.
    + modify wattron/wattroff calls in form/m_post.c to call wattr_on and
    wattr_off to omit cast used in the former for X/Open compatibility
    (patch by Bill Gray).
    + modify wezterm, omitting its broken left/right margin feature (report
    by Thayne McCombs) -TD
  - Modify patch ncurses-6.4.dif to get offsets correct

++++ tpm2.0-abrmd:

  - Fix SELinux sbin/bin merge (bsc#1229047)
    1229047-fix-bin-sbin-selinux.patch
    Can be dropped once https://github.com/tpm2-software/tpm2-abrmd/pull/846
    is merged upstream

++++ python-PyJWT:

  - Skip failing test gh#jpadilla/pyjwt#802

++++ python-argcomplete:

  - require ca-certificates-mozilla for the pip >= 24.2

++++ suse-module-tools:

  - Update to version 16.0.49:
    * Require sdbootutil if already installed

++++ sysvinit:

  - Add patch killproc-2.23.dif
    * Fix shell command in Makefile to get detection statx declaration correct
  - Update to sysvinit 3.10
    * When the user executes "machinectl stop", systemd sends SIGRTMIN+4 to PID 1
    in the container, and expects that to initiate a graceful shutdown (power-off).
    SysV init now catches this signal and initiates a shutdown (shutdown -hP now).
  - floppym provided patch to accomplish this.
    * Fix issue in bootlogd which could cause the service to enter an endless loop
    (and use too much CPU) when it is able to open a device for writing, but not actually
    able to write to it. This resulted in bootlogd closing and re-opening the device over
    and over. Now bootlogd should simply fail gracefully when it cannot write to an open
    file/device.
    * Fix formatting in shutdown.8 manual page. Cleaned up whitespace and special characters.
    * Patch for man/Makefile to fix the clean recipe.
    Provided by Lucas Nussabaum and Mark Hindley
    * On Linux systems, allow reboot command to pass a message
    to the system firmware during the restart. This is
    accomplished with the -m flag.
    * Patch from kraj which allows hddown to compile
    when musl is the C library.

++++ ucode-amd:

  - Update to version 20240809 (git commit 36db650dae03):
    * qcom: update path for video firmware for vpu-1/2/3.0
    * QCA: Update Bluetooth WCN685x 2.1 firmware to 2.1.0-00642
    * rtw89: 8852c: add fw format-1 v0.27.97.0
    * rtw89: 8852bt: add firmware 0.29.91.0
    * amdgpu: Update ISP FW for isp v4.1.1
    * mediatek: Update mt8195 SOF firmware
    * amdgpu: DMCUB updates for DCN314
    * xe: First GuC release v70.29.2 for BMG
    * xe: Add GuC v70.29.2 for LNL
    * i915: Add GuC v70.29.2 for ADL-P, DG1, DG2, MTL, and TGL
    * i915: Update MTL DMC v2.22
    * i915: update MTL GSC to v102.0.10.1878
    * xe: Add BMG HuC 8.2.10
    * xe: Add GSC 104.0.0.1161 for LNL
    * xe: Add LNL HuC 9.4.13
    * i915: update DG2 HuC to v7.10.16
    * amdgpu: Update ISP FW for isp v4.1.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00641

------------------------------------------------------------------
------------------  2024-8-12  -  Aug 12 2024  -------------------
------------------------------------------------------------------

++++ accountsservice:

  - Drop as-fate318433-prevent-same-account-multi-logins.patch.
    Gnome-shell now has similar functionality upstream.

++++ cockpit:

  - new version 322:
    * shell: Deprecate host switcher
    * files: Permissions column in details view
  - suse_docs.patch: refreshed
    For details, see https://cockpit-project.org/blog/cockpit-322.html

++++ combustion:

  - Update to version 1.4+git4:
    * Add basic automated testing
    * Don't wait for other config sources if combustion.url is set
    * Improve documentation for config sources a bit
    * Stop gpg-agent before umounting /sysroot

++++ curl:

  - Fix regression introduced in version 8.9.1:
    * sigpipe: init the struct so that first apply ignores
    * Add curl-sigpipe.patch

++++ python-kiwi:

  - Fixed arch flag for namedCollection
    The arch flag in a namedCollection was not taken into account.
    This commit fixes this and also makes sure the result information
    is sorted and unique like we have it for the package lists.
    This Fixes #2600

++++ drbd:

  - drbd: fix build error against kernel v6.10.3 (boo#1229062)
    * add patch
    + boo1229062-re-enable-blk_queue_max_hw_sectors.patch

++++ gpg2:

  - Remove explicit runtime library dependency, pick ease of
    maintenance in Tumbleweed over mixed project use runtime bugs.

++++ kernel-default:

  - scsi: mpi3mr: Use proper format specifier in
    mpi3mr_sas_port_add() (bsc#1228754 CVE-2024-42159 git-fixes).
  - scsi: mpi3mr: Sanitise num_phys (bsc#1228754 CVE-2024-42159).
  - commit e024eb0
  - tcp_metrics: validate source addr length
    (CVE-2024-42154 bsc#1228507).
  - commit a83d949
  - selftests/bpf: check if max number of bpf_loop iterations is
    tracked (git-fixes).
    Refresh
    patches.suse/selftests-bpf-test-case-for-callback_depth-states-pr.patch.
  - selftests/bpf: fix bpf_loop_bench for new callback verification
    scheme (git-fixes).
  - selftests/bpf: Add netkit to tc_redirect selftest (git-fixes).
  - selftests/bpf: De-veth-ize the tc_redirect test case
    (git-fixes).
  - bpf: fix control-flow graph checking in privileged mode
    (git-fixes).
  - commit 27db2c6
  - bpf: Fix check_stack_write_fixed_off() to correctly spill imm
    (git-fixes).
  - bpf: Fix unnecessary -EBUSY from htab_lock_bucket (git-fixes).
  - commit b5c430e
  - mm/shmem: disable PMD-sized page cache if needed (CVE-2024-42241
    bsc#1228986).
  - commit 8ecdd91
  - x86/mm: Fix pti_clone_pgtable() alignment assumption (git-fixes).
  - commit 1d041a1
  - x86/mm: Fix pti_clone_entry_text() for i386 (git-fixes).
  - commit 5407674
  - x86/pci: Skip early E820 check for ECAM region (git-fixes).
  - commit 7ac1bfc
  - x86/mtrr: Check if fixed MTRRs exist before saving them (git-fixes).
  - commit 03de6ee
  - x86/entry/64: Remove obsolete comment on tracing vs. SYSRET (git-fixes).
  - commit 41708c1
  - memcg: protect concurrent access to mem_cgroup_idr (git-fixes).
  - commit e9979b2
  - Revert "sched/fair: Make sure to try to detach at least one
    movable task" (CVE-2024-42245 bsc#1228978).
  - commit bff0dc0
  - selftests/bpf: Make linked_list failure test more robust
    (git-fixes).
  - bpf: Ensure proper register state printing for cond jumps
    (git-fixes).
  - commit 2ec4f49
  - ipv6: sr: fix incorrect unregister order (git-fixes).
  - commit f975fdd
  - ipv6: sr: fix possible use-after-free and null-ptr-deref
    (CVE-2024-26735 bsc#1222372).
  - commit 75aaed9
  - bpftool: Align output skeleton ELF code (git-fixes).
  - samples/bpf: syscall_tp_user: Fix array out-of-bound access
    (git-fixes).
  - samples/bpf: syscall_tp_user: Rename num_progs into nr_tests
    (git-fixes).
  - bpf: Fix kfunc callback register type handling (git-fixes).
  - commit ee3cca0
  - bpf: Detect IP == ksym.end as part of BPF program (git-fixes).
  - commit b5b57d0
  - selftests/bpf: Skip module_fentry_shadow test when bpf_testmod
    is not available (git-fixes).
  - commit 85b5d5e
  - bpftool: Fix -Wcast-qual warning (git-fixes).
  - commit 0417873
  - net: bridge: switchdev: Skip MDB replays of deferred events
    on offload (CVE-2024-26837 bsc#1222973).
  - commit 2f55c98
  - s390/pkey: Wipe copies of protected- and secure-keys
    (CVE-2024-42155 bsc#1228733).
  - s390/pkey: Wipe copies of clear-key structures on failure
    (CVE-2024-42156 bsc#1228722).
  - s390/pkey: Wipe sensitive data on failure (CVE-2024-42157
    bsc#1228727).
  - s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings
    (CVE-2024-42158 bsc#1228720).
  - s390/pkey: introduce dynamic debugging for pkey (bsc#1228720).
  - s390/pkey: harmonize pkey s390 debug feature calls
    (bsc#1228720).
  - commit 72f0617
  - usb: gadget: u_serial: Set start_delayed during suspend
    (git-fixes).
  - usb: gadget: core: Check for unset descriptor (git-fixes).
  - usb: gadget: u_audio: Check return codes from usb_ep_enable
    and config_ep_by_speed (git-fixes).
  - driver core: Fix uevent_show() vs driver detach race
    (git-fixes).
  - thermal/drivers/broadcom: Fix race between removal and clock
    disable (git-fixes).
  - thermal: bcm2835: Convert to platform remove callback returning
    void (stable-fixes).
  - commit 9bfd8af
  - selftests/bpf: Cover verifier checks for mutating
    sockmap/sockhash (bsc#1226885 CVE-2024-38662).
  - Revert "bpf, sockmap: Prevent lock inversion deadlock in map
    delete elem" (bsc#1226885 CVE-2024-38662).
  - bpf: Allow delete from sockmap/sockhash only if update is
    allowed (bsc#1226885 CVE-2024-38662).
  - commit 7f528cf
  - rpm/kernel-binary.spec.in: fix klp_symbols macro
    The commit below removed openSUSE filter from %ifs of the klp_symbols
    definition. But it removed -c of grep too and that causes:
    error: syntax error in expression:  01 && (  || 1 )
    error:                                        ^
    error: unmatched (:  01 && (  || 1 )
    error:                     ^
    error: kernel-default.spec:137: bad %if condition:  01 && (  || 1 )
    So reintroduce -c to the PTF's grep.
    Fixes: fd0b293bebaf (kernel-binary.spec.in: Enable klp_symbols on openSUSE Tumbleweed (boo#1229042).)
  - commit 4a36fe3

++++ kernel-rt:

  - scsi: mpi3mr: Use proper format specifier in
    mpi3mr_sas_port_add() (bsc#1228754 CVE-2024-42159 git-fixes).
  - scsi: mpi3mr: Sanitise num_phys (bsc#1228754 CVE-2024-42159).
  - commit e024eb0
  - tcp_metrics: validate source addr length
    (CVE-2024-42154 bsc#1228507).
  - commit a83d949
  - selftests/bpf: check if max number of bpf_loop iterations is
    tracked (git-fixes).
    Refresh
    patches.suse/selftests-bpf-test-case-for-callback_depth-states-pr.patch.
  - selftests/bpf: fix bpf_loop_bench for new callback verification
    scheme (git-fixes).
  - selftests/bpf: Add netkit to tc_redirect selftest (git-fixes).
  - selftests/bpf: De-veth-ize the tc_redirect test case
    (git-fixes).
  - bpf: fix control-flow graph checking in privileged mode
    (git-fixes).
  - commit 27db2c6
  - bpf: Fix check_stack_write_fixed_off() to correctly spill imm
    (git-fixes).
  - bpf: Fix unnecessary -EBUSY from htab_lock_bucket (git-fixes).
  - commit b5c430e
  - mm/shmem: disable PMD-sized page cache if needed (CVE-2024-42241
    bsc#1228986).
  - commit 8ecdd91
  - x86/mm: Fix pti_clone_pgtable() alignment assumption (git-fixes).
  - commit 1d041a1
  - x86/mm: Fix pti_clone_entry_text() for i386 (git-fixes).
  - commit 5407674
  - x86/pci: Skip early E820 check for ECAM region (git-fixes).
  - commit 7ac1bfc
  - x86/mtrr: Check if fixed MTRRs exist before saving them (git-fixes).
  - commit 03de6ee
  - x86/entry/64: Remove obsolete comment on tracing vs. SYSRET (git-fixes).
  - commit 41708c1
  - memcg: protect concurrent access to mem_cgroup_idr (git-fixes).
  - commit e9979b2
  - Revert "sched/fair: Make sure to try to detach at least one
    movable task" (CVE-2024-42245 bsc#1228978).
  - commit bff0dc0
  - selftests/bpf: Make linked_list failure test more robust
    (git-fixes).
  - bpf: Ensure proper register state printing for cond jumps
    (git-fixes).
  - commit 2ec4f49
  - ipv6: sr: fix incorrect unregister order (git-fixes).
  - commit f975fdd
  - ipv6: sr: fix possible use-after-free and null-ptr-deref
    (CVE-2024-26735 bsc#1222372).
  - commit 75aaed9
  - bpftool: Align output skeleton ELF code (git-fixes).
  - samples/bpf: syscall_tp_user: Fix array out-of-bound access
    (git-fixes).
  - samples/bpf: syscall_tp_user: Rename num_progs into nr_tests
    (git-fixes).
  - bpf: Fix kfunc callback register type handling (git-fixes).
  - commit ee3cca0
  - bpf: Detect IP == ksym.end as part of BPF program (git-fixes).
  - commit b5b57d0
  - selftests/bpf: Skip module_fentry_shadow test when bpf_testmod
    is not available (git-fixes).
  - commit 85b5d5e
  - bpftool: Fix -Wcast-qual warning (git-fixes).
  - commit 0417873
  - net: bridge: switchdev: Skip MDB replays of deferred events
    on offload (CVE-2024-26837 bsc#1222973).
  - commit 2f55c98
  - s390/pkey: Wipe copies of protected- and secure-keys
    (CVE-2024-42155 bsc#1228733).
  - s390/pkey: Wipe copies of clear-key structures on failure
    (CVE-2024-42156 bsc#1228722).
  - s390/pkey: Wipe sensitive data on failure (CVE-2024-42157
    bsc#1228727).
  - s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings
    (CVE-2024-42158 bsc#1228720).
  - s390/pkey: introduce dynamic debugging for pkey (bsc#1228720).
  - s390/pkey: harmonize pkey s390 debug feature calls
    (bsc#1228720).
  - commit 72f0617
  - usb: gadget: u_serial: Set start_delayed during suspend
    (git-fixes).
  - usb: gadget: core: Check for unset descriptor (git-fixes).
  - usb: gadget: u_audio: Check return codes from usb_ep_enable
    and config_ep_by_speed (git-fixes).
  - driver core: Fix uevent_show() vs driver detach race
    (git-fixes).
  - thermal/drivers/broadcom: Fix race between removal and clock
    disable (git-fixes).
  - thermal: bcm2835: Convert to platform remove callback returning
    void (stable-fixes).
  - commit 9bfd8af
  - selftests/bpf: Cover verifier checks for mutating
    sockmap/sockhash (bsc#1226885 CVE-2024-38662).
  - Revert "bpf, sockmap: Prevent lock inversion deadlock in map
    delete elem" (bsc#1226885 CVE-2024-38662).
  - bpf: Allow delete from sockmap/sockhash only if update is
    allowed (bsc#1226885 CVE-2024-38662).
  - commit 7f528cf
  - rpm/kernel-binary.spec.in: fix klp_symbols macro
    The commit below removed openSUSE filter from %ifs of the klp_symbols
    definition. But it removed -c of grep too and that causes:
    error: syntax error in expression:  01 && (  || 1 )
    error:                                        ^
    error: unmatched (:  01 && (  || 1 )
    error:                     ^
    error: kernel-default.spec:137: bad %if condition:  01 && (  || 1 )
    So reintroduce -c to the PTF's grep.
    Fixes: fd0b293bebaf (kernel-binary.spec.in: Enable klp_symbols on openSUSE Tumbleweed (boo#1229042).)
  - commit 4a36fe3

++++ kexec-tools:

  - update to 2.0.29:
    * update man and --help
    * powerpc/kexec_load: add hotplug support
    * kexec_load: Use new kexec flag for hotplug support
    * x86-linux-setup.c: Use POSIX basename API
    * LoongArch: fix load command line segment error
    * LoongArch: add multi crash kernel segment support
    * LoongArch: fix kernel image size error
    * Arm: Fix add_buffer_phys_virt() align issue
    * Fix incorrect Free Software Foundation address in the license
    * util_lib/elf_info.c: fix a warning
    * kexec_file: add kexec_file flag to support debug printing
    * workflow: update to use checkout@v4
  - drop kexec-dont-use-kexec_file_load-on-xen.patch, upstream
  - drop fix-building-on-x86_64-with-binutils-2.41.patch, upstream
  - kexec-tools-riscv-hotplug.patch: Fix build for riscv64.

++++ rdma-core:

  - Update to rdma-core v53.0
  - No release notes available
  - Remove Added-suffix-libdrm-to-CMakeLists.txt-for-drm.patch
    as it was merged upstream.

++++ protobuf-c:

  - BuildRequire a C++ compiler, previously pulled in via protobuf

++++ nvidia-open-driver-G06-signed:

  - Update to 550.107.02 (boo#1229716)

++++ openssh:

  - Fix a dbus connection leaked in the logind patch that was
    missing a sd_bus_unref call (found by Matthias Gerstner):
    * logind_set_tty.patch
  - Add a patch that fixes a small memory leak when parsing the
    subsystem configuration option:
    * fix-memleak-in-process_server_config_line_depth.patch

++++ python-cryptography:

  - Fix building optimized binaries with debuginfo.

++++ python-oauthlib:

  - Skip failing test with jwt 2.9.0
    gh#oauthlib/oauthlib#877

++++ ovmf:

  - Add ovmf-x86_64-sev flavor to X64 against AMD SEV.
  - Moved "-D SECURE_BOOT_ENABLE" from OVMF_FLAGS to EXTRA_FLAGS_X64,
    , BUILD_OPTIONS_X86, BUILD_OPTIONS_AA64 and BUILD_OPTIONS_RV64
    because SEV can NOT work with secure boot.
  - Removed ovmf-Revert-OvmfPkg-PlatformPei-Update-ReserveEmuVariable.patch
    because the SEV ovmf be separated from X64 ovmf as an independent flavor.
  - The original patch reverts "58eb8517ad OvmfPkg/PlatformPei: Update
    ReserveEmuVariableNvStore" which affects all ovmf flavor.
  - The secure boot be disabled in SEV flavor, so we do not need revert
    58eb8517ad anymore. (bsc#1209266)
  - Add 50-ovmf-x86_64-sev.json to descriptors.tar.xz for SEV flavor
  - Removed features tag:
    "acpi-s3", "requires-smm", "secure-boot", "enrolled-keys"
  - Add features tag:
    "amd-sev", "amd-sev-es", "amd-sev-snp"

++++ velociraptor-client:

  - Move system-user-velociraptor to the client flavor build in order
    to build it on all architectures.

------------------------------------------------------------------
------------------  2024-8-11  -  Aug 11 2024  -------------------
------------------------------------------------------------------

++++ aide:

  -  Update to 0.18.8:
    * Fix concurrent reading of extended attributes (xattrs)
    * Raise warning if both input databases are the same
  -  Update to 0.18.7:
    * Add missing library CFLAGS
    * Fix typo in aide.conf manual page
    * Fix 64-bit time_t on 32-bit architectures
    * Fix debug logging for returned attributes
    * Fix condition for error message of failing to open gzipped files
  - rebased aide-0.18-as-needed.patch

++++ kernel-default:

  - i2c: qcom-geni: Add missing geni_icc_disable in
    geni_i2c_runtime_resume (git-fixes).
  - i2c: qcom-geni: Add missing clk_disable_unprepare in
    geni_i2c_runtime_resume (git-fixes).
  - i2c: smbus: Send alert notifications to all devices if source
    not found (git-fixes).
  - i2c: smbus: Improve handling of stuck alerts (git-fixes).
  - spi: spi-fsl-lpspi: Fix scldiv calculation (git-fixes).
  - spi: spidev: Add missing spi_device_id for bh2228fv (git-fixes).
  - drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
    (git-fixes).
  - drm/client: fix null pointer dereference in
    drm_client_modeset_probe (git-fixes).
  - commit e093c66

++++ kernel-rt:

  - i2c: qcom-geni: Add missing geni_icc_disable in
    geni_i2c_runtime_resume (git-fixes).
  - i2c: qcom-geni: Add missing clk_disable_unprepare in
    geni_i2c_runtime_resume (git-fixes).
  - i2c: smbus: Send alert notifications to all devices if source
    not found (git-fixes).
  - i2c: smbus: Improve handling of stuck alerts (git-fixes).
  - spi: spi-fsl-lpspi: Fix scldiv calculation (git-fixes).
  - spi: spidev: Add missing spi_device_id for bh2228fv (git-fixes).
  - drm/i915/gem: Fix Virtual Memory mapping boundaries calculation
    (git-fixes).
  - drm/client: fix null pointer dereference in
    drm_client_modeset_probe (git-fixes).
  - commit e093c66

++++ libpng16:

  - Fix missing backslash

++++ update-alternatives:

  - Update to version 1.22.11.
    The full changelog is very large. Please check it here:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.11
  - Changes from 1.22.10:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.10
  - Changes from 1.22.9:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.9
  - Changes from 1.22.8:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.8
  - Changes from 1.22.7:
    https://git.dpkg.org/cgit/dpkg/dpkg.git/tree/debian/changelog?h=1.22.7
  - Refresh patch:
    * openssl.patch

------------------------------------------------------------------
------------------  2024-8-10  -  Aug 10 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - Update patch references for ASoC regression fixes (bsc#1229045 bsc#1229046)
  - commit 4e3f007
  - rpm/kernel-binary.spec.in: Fix build regression
    The previous fix forgot to take over grep -c option that broke the
    conditional expression
  - commit d29edf2
  - Moved upstreamed ASoC patch into sorted section
  - commit 3058bc3
  - ASoC: cs35l56: Patch CS35L56_IRQ1_MASK_18 to the default value
    (stable-fixes).
  - ASoC: amd: yc: Support mic on Lenovo Thinkpad E14 Gen 6
    (stable-fixes).
  - ASoC: cs35l56: Handle OTP read latency over SoundWire
    (stable-fixes).
  - ASoC: nau8822: Lower debug print priority (stable-fixes).
  - ASoC: fsl_micfil: Expand the range of FIFO watermark mask
    (stable-fixes).
  - ASoC: amd: yc: Support mic on HP 14-em0002la (stable-fixes).
  - ALSA: hda/realtek: Add Framework Laptop 13 (Intel Core Ultra)
    to quirks (stable-fixes).
  - ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4
    (stable-fixes).
  - ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list
    (stable-fixes).
  - ALSA: line6: Fix racy access to midibuf (stable-fixes).
  - ASoC: cs35l56: Patch CS35L56_IRQ1_MASK_18 to the default value
    (stable-fixes).
  - ASoC: amd: yc: Support mic on Lenovo Thinkpad E14 Gen 6
    (stable-fixes).
  - ASoC: cs35l56: Handle OTP read latency over SoundWire
    (stable-fixes).
  - ASoC: nau8822: Lower debug print priority (stable-fixes).
  - ASoC: fsl_micfil: Expand the range of FIFO watermark mask
    (stable-fixes).
  - ASoC: amd: yc: Support mic on HP 14-em0002la (stable-fixes).
  - ALSA: hda/realtek: Add Framework Laptop 13 (Intel Core Ultra)
    to quirks (stable-fixes).
  - ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4
    (stable-fixes).
  - ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list
    (stable-fixes).
  - ALSA: line6: Fix racy access to midibuf (stable-fixes).
  - commit a8c8868
  - ASoC: meson: axg-fifo: fix irq scheduling issue with PREEMPT_RT
    (git-fixes).
  - ASoC: SOF: Remove libraries from topology lookups (git-fixes).
  - ASoC: codecs: wsa884x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa883x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa881x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wcd938x-sdw: Correct Soundwire ports mask
    (git-fixes).
  - ALSA: usb-audio: Re-add ScratchAmp quirk entries (git-fixes).
  - ASoC: meson: axg-fifo: fix irq scheduling issue with PREEMPT_RT
    (git-fixes).
  - ASoC: SOF: Remove libraries from topology lookups (git-fixes).
  - ASoC: codecs: wsa884x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa883x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa881x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wcd938x-sdw: Correct Soundwire ports mask
    (git-fixes).
  - ALSA: usb-audio: Re-add ScratchAmp quirk entries (git-fixes).
  - commit cdc2939

++++ kernel-rt:

  - Update patch references for ASoC regression fixes (bsc#1229045 bsc#1229046)
  - commit 4e3f007
  - rpm/kernel-binary.spec.in: Fix build regression
    The previous fix forgot to take over grep -c option that broke the
    conditional expression
  - commit d29edf2
  - Moved upstreamed ASoC patch into sorted section
  - commit 3058bc3
  - ASoC: cs35l56: Patch CS35L56_IRQ1_MASK_18 to the default value
    (stable-fixes).
  - ASoC: amd: yc: Support mic on Lenovo Thinkpad E14 Gen 6
    (stable-fixes).
  - ASoC: cs35l56: Handle OTP read latency over SoundWire
    (stable-fixes).
  - ASoC: nau8822: Lower debug print priority (stable-fixes).
  - ASoC: fsl_micfil: Expand the range of FIFO watermark mask
    (stable-fixes).
  - ASoC: amd: yc: Support mic on HP 14-em0002la (stable-fixes).
  - ALSA: hda/realtek: Add Framework Laptop 13 (Intel Core Ultra)
    to quirks (stable-fixes).
  - ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4
    (stable-fixes).
  - ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list
    (stable-fixes).
  - ALSA: line6: Fix racy access to midibuf (stable-fixes).
  - ASoC: cs35l56: Patch CS35L56_IRQ1_MASK_18 to the default value
    (stable-fixes).
  - ASoC: amd: yc: Support mic on Lenovo Thinkpad E14 Gen 6
    (stable-fixes).
  - ASoC: cs35l56: Handle OTP read latency over SoundWire
    (stable-fixes).
  - ASoC: nau8822: Lower debug print priority (stable-fixes).
  - ASoC: fsl_micfil: Expand the range of FIFO watermark mask
    (stable-fixes).
  - ASoC: amd: yc: Support mic on HP 14-em0002la (stable-fixes).
  - ALSA: hda/realtek: Add Framework Laptop 13 (Intel Core Ultra)
    to quirks (stable-fixes).
  - ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4
    (stable-fixes).
  - ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list
    (stable-fixes).
  - ALSA: line6: Fix racy access to midibuf (stable-fixes).
  - commit a8c8868
  - ASoC: meson: axg-fifo: fix irq scheduling issue with PREEMPT_RT
    (git-fixes).
  - ASoC: SOF: Remove libraries from topology lookups (git-fixes).
  - ASoC: codecs: wsa884x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa883x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa881x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wcd938x-sdw: Correct Soundwire ports mask
    (git-fixes).
  - ALSA: usb-audio: Re-add ScratchAmp quirk entries (git-fixes).
  - ASoC: meson: axg-fifo: fix irq scheduling issue with PREEMPT_RT
    (git-fixes).
  - ASoC: SOF: Remove libraries from topology lookups (git-fixes).
  - ASoC: codecs: wsa884x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa883x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wsa881x: Correct Soundwire ports mask (git-fixes).
  - ASoC: codecs: wcd938x-sdw: Correct Soundwire ports mask
    (git-fixes).
  - ALSA: usb-audio: Re-add ScratchAmp quirk entries (git-fixes).
  - commit cdc2939

++++ nvidia-open-driver-G06-signed:

  - For CUDA update version to 560.28.03

++++ python-M2Crypto:

  - Update 0.42.0:
  - allow ASN1_{Integer,String} be initialized directly
  - minimal infrastructure for type hints for a C extension and
    some type hints for some basic modules
  - time_t on 32bit Linux is 32bit (integer) not 64bit (long)
  - EOS for CentOS 7
  - correct checking for OpenSSL version number on Windows
  - make compatible with Python 3.13 (replace PyEval_CallObject
    with PyObject_CallObject)
  - fix typo in extern function signature (and proper type of
    engine_ctrl_cmd_string())
  - move the package to Sorucehut
  - setup CI to use Sourcehut CI
  - setup CI on GitLab for Windows as well (remove Appveyor)
  - initial draft of documentation for migration to
    pyca/cryptography
  - fix Read the Docs configuration (contributed kindly by Facundo
    Tuesca)
  - Remove upstreamed 32bit_ASN1_Time.patch
  - Remove python-M2Crypto.keyring, because PyPI broke GPG support

------------------------------------------------------------------
------------------  2024-8-9  -  Aug 9 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Update to version 1.48.8:
    + ovs: fix triggering stage3 activation without DHCP client
    initialized
    + config: parse autoconnect-ports value on config
    + ndisc: preserve router preferences

++++ aaa_base:

  - Update to version 84.87+git20240809.5d13eb4:
    * cleanup aaa_base.post and fold back into specfile

++++ cockpit-podman:

  - Fix systemd units folder for leap and sle (Similar issue like boo#1226541)

++++ cockpit-tukit:

  - 38.patch: pending build fixes against newer cockpit

++++ python-kiwi:

  - Fix handling of zipl.conf in plain zipl bootloader
    When using the plain zipl bootloader kiwi created a /etc/zipl.conf
    file. However, this file was only useful during image build as it
    points to a loop target device and geometry but does not represent
    a proper config file to be used in the running system. In addition
    the different distributors provides their own version and layout
    of the zipl.conf to be used inside of the system and with their
    respective tools. Thus this commit changes the way how kiwi operates
    in a way that the zipl.conf used in the initial image only exists
    during the image build process. An eventual present /etc/zipl.conf
    will not be touched by kiwi. This Fixes #2597

++++ ethtool:

  - update to upstream release 6.10
    * Feature: suport for PoE in PSE (--show-pse and --set-pse)
    * Feature: add statistics support to tsinfo (-T)
    * Feature: add JSON output to base command (no option)
    * Feature: add JSON output to EEE info (--show-eee)
    * Fix: qsfp: better handling on page 03h read failure (-m)
    * Fix: handle zero arguments for module eeprom dump (-m)
    * Fix: check for missing arguments in do_srxfh() (-X)
    * Misc: more descriptive error when JSON output is not available

++++ kernel-default:

  - kernel-binary.spec.in: Enable klp_symbols on openSUSE Tumbleweed (boo#1229042).
    After the Jump project the kernel used by SLE and openSUSE Leap are the
    same. As consequence the klp_symbols variable is set, enabling
    kernel-default-livepatch-devel on both SLE and openSUSE.
    The current rules to avoid enabling the package exclude openSUSE
    Tumbleweed alone, which doesn't makes sense for now. Enabling
    kernel-default-livepatch-devel on TW makes it easier to test the
    creation of kernel livepatches of the next SLE versions.
  - commit fd0b293
  - Split kABI workaround of recent hyperv fixes (bsc#1229040, bsc#1225745, CVE-2024-36911, bsc#1225717, CVE-2024-36910, bsc#1225744, CVE-2024-36909)
  - commit 3639306
  - Yet more build fix without patches.kabi (bsc#1226502)
  - commit 6bc3429
  - Fix build errors without patches.kabi (bsc#1226502)
    Now patches.suse/x86-Stop-using-weak-symbols-for-__iowrite32_copy.patch
    has a full backport and later partially reverted via
    patches.kabi/kabi-partial-revert-commit-20516d6e51dd.patch
  - commit 44c5e90
  - landlock: Fix d_parent walk (CVE-2024-40938 bsc#1227840).
  - commit 36de641
  - net: fix sk_memory_allocated_{add|sub} vs softirqs
    (bsc#1228757).
  - commit a963c0f
  - minmax: fix up min3() and max3() too (bsc#1229024).
  - minmax: improve macro expansion and type checking (bsc#1229024).
  - minmax: simplify min()/max()/clamp() implementation
    (bsc#1229024).
  - minmax: don't use max() in situations that want a C constant
    expression (bsc#1229024).
  - minmax: make generic MIN() and MAX() macros available everywhere
    (bsc#1229024).
  - minmax: simplify and clarify min_t()/max_t() implementation
    (bsc#1229024).
  - minmax: add a few more MIN_T/MAX_T users (bsc#1229024).
  - minmax: avoid overly complicated constant expressions in VM code
    (bsc#1229024).
  - drm/radeon/evergreen_cs: Clean up errors in evergreen_cs.c
    (bsc#1229024).
  - commit c64c296
  - Update
    patches.suse/ALSA-emux-improve-patch-ioctl-data-validation.patch
    (stable-fixes CVE-2024-42097 bsc#1228766).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-fix-null-deref-on-system-suspend-.patch
    (git-fixes CVE-2024-41037 bsc#1228508).
  - Update
    patches.suse/ASoC-amd-acp-add-a-null-check-for-chip_pdev-structur.patch
    (git-fixes CVE-2024-42074 bsc#1228481).
  - Update
    patches.suse/ASoC-fsl-asoc-card-set-priv-pdev-before-using-it.patch
    (git-fixes CVE-2024-42089 bsc#1228450).
  - Update
    patches.suse/Bluetooth-ISO-Check-socket-flag-instead-of-hcon.patch
    (git-fixes CVE-2024-42141 bsc#1228502).
  - Update
    patches.suse/Bluetooth-Ignore-too-large-handle-values-in-BIG.patch
    (git-fixes CVE-2024-42133 bsc#1228511).
  - Update
    patches.suse/Bluetooth-hci_core-cancel-all-works-upon-hci_unregis.patch
    (stable-fixes CVE-2024-41063 bsc#1228580).
  - Update
    patches.suse/Bluetooth-qca-Fix-BT-enable-failure-again-for-QCA639.patch
    (git-fixes CVE-2024-42137 bsc#1228563).
  - Update patches.suse/PCI-MSI-Fix-UAF-in-msi_capability_init.patch
    (git-fixes CVE-2024-41096 bsc#1228479).
  - Update
    patches.suse/RDMA-restrack-Fix-potential-invalid-address-access.patch
    (git-fixes CVE-2024-42080 bsc#1228673).
  - Update
    patches.suse/USB-core-Fix-duplicate-endpoint-bug-by-clearing-rese.patch
    (git-fixes CVE-2024-41035 bsc#1228485).
  - Update patches.suse/USB-serial-mos7840-fix-crash-on-resume.patch
    (git-fixes CVE-2024-42244 bsc#1228967).
  - Update
    patches.suse/ata-libata-core-Fix-null-pointer-dereference-on-erro.patch
    (git-fixes CVE-2024-41098 bsc#1228467).
  - Update
    patches.suse/bluetooth-hci-disallow-setting-handle-bigger-than-HC.patch
    (git-fixes CVE-2024-42132 bsc#1228492).
  - Update
    patches.suse/bpf-Fail-bpf_timer_cancel-when-callback-is-being-can.patch
    (bsc#1228531 CVE-2024-41045 CVE-2024-42239 bsc#1228979).
  - Update
    patches.suse/can-mcp251xfd-fix-infinite-loop-when-xmit-fails.patch
    (git-fixes CVE-2024-41088 bsc#1228469).
  - Update
    patches.suse/cdrom-rearrange-last_media_change-check-to-avoid-uni.patch
    (stable-fixes CVE-2024-42136 bsc#1228758).
  - Update
    patches.suse/crypto-aead-cipher-zeroize-key-buffer-after-use.patch
    (stable-fixes CVE-2024-42229 bsc#1228708).
  - Update
    patches.suse/crypto-ecdh-explicitly-zeroize-private_key.patch
    (stable-fixes CVE-2024-42098 bsc#1228779).
  - Update
    patches.suse/drm-amd-display-ASSERT-when-failing-to-find-index-by.patch
    (stable-fixes CVE-2024-42117 bsc#1228582).
  - Update
    patches.suse/drm-amd-display-Check-index-msg_id-before-read-or-wr.patch
    (stable-fixes CVE-2024-42121 bsc#1228590).
  - Update
    patches.suse/drm-amd-display-Check-pipe-offset-before-setting-vbl.patch
    (stable-fixes CVE-2024-42120 bsc#1228588).
  - Update
    patches.suse/drm-amd-display-Fix-array-index-out-of-bounds-in-dml.patch
    (stable-fixes CVE-2024-41061 bsc#1228572).
  - Update
    patches.suse/drm-amd-display-Fix-overlapping-copy-within-dml_core.patch
    (stable-fixes CVE-2024-42227 bsc#1228707).
  - Update
    patches.suse/drm-amd-display-Skip-finding-free-audio-for-unknown-.patch
    (stable-fixes CVE-2024-42119 bsc#1228584).
  - Update
    patches.suse/drm-amd-display-Skip-pipe-if-the-pipe-idx-not-set-pr.patch
    (stable-fixes CVE-2024-42064 bsc#1228586).
  - Update
    patches.suse/drm-amdgpu-Fix-signedness-bug-in-sdma_v4_0_process_t.patch
    (git-fixes CVE-2024-41022 bsc#1228429).
  - Update
    patches.suse/drm-amdgpu-Using-uninitialized-value-size-when-calli.patch
    (stable-fixes CVE-2024-42228 bsc#1228667).
  - Update
    patches.suse/drm-amdgpu-avoid-using-null-object-of-framebuffer.patch
    (stable-fixes CVE-2024-41093 bsc#1228660).
  - Update
    patches.suse/drm-fbdev-dma-Only-set-smem_start-is-enable-per-modu.patch
    (git-fixes CVE-2024-41094 bsc#1228458).
  - Update
    patches.suse/drm-i915-gt-Fix-potential-UAF-by-revoke-of-fence-reg.patch
    (git-fixes CVE-2024-41092 bsc#1228483).
  - Update
    patches.suse/drm-lima-fix-shared-irq-handling-on-driver-remove.patch
    (stable-fixes CVE-2024-42127 bsc#1228721).
  - Update
    patches.suse/drm-nouveau-dispnv04-fix-null-pointer-dereference-in-66edf3f.patch
    (stable-fixes CVE-2024-41095 bsc#1228662).
  - Update
    patches.suse/drm-nouveau-dispnv04-fix-null-pointer-dereference-in.patch
    (stable-fixes CVE-2024-41089 bsc#1228658).
  - Update
    patches.suse/drm-nouveau-fix-null-pointer-dereference-in-nouveau_.patch
    (git-fixes CVE-2024-42101 bsc#1228495).
  - Update
    patches.suse/drm-panel-ilitek-ili9881c-Fix-warning-with-GPIO-cont.patch
    (stable-fixes CVE-2024-42087 bsc#1228677).
  - Update
    patches.suse/drm-radeon-check-bo_va-bo-is-non-NULL-before-using-i.patch
    (stable-fixes CVE-2024-41060 bsc#1228567).
  - Update
    patches.suse/filelock-fix-potential-use-after-free-in-posix_lock_inode.patch
    (git-fixes CVE-2024-41049 bsc#1228486).
  - Update
    patches.suse/firmware-cs_dsp-Fix-overflow-checking-of-wmfw-header.patch
    (git-fixes CVE-2024-41039 bsc#1228515).
  - Update
    patches.suse/firmware-cs_dsp-Prevent-buffer-overrun-when-processi.patch
    (git-fixes CVE-2024-41038 bsc#1228509).
  - Update
    patches.suse/firmware-cs_dsp-Return-error-if-block-header-overflo.patch
    (git-fixes CVE-2024-42238 bsc#1228991).
  - Update
    patches.suse/firmware-cs_dsp-Use-strnlen-on-name-fields-in-V1-wmf.patch
    (git-fixes CVE-2024-41056 bsc#1228480).
  - Update
    patches.suse/firmware-cs_dsp-Validate-payload-length-before-proce.patch
    (git-fixes CVE-2024-42237 bsc#1228992).
  - Update
    patches.suse/genirq-cpuhotplug-x86-vector-Prevent-vector-leak-dur.patch
    (git-fixes CVE-2024-31076 bsc#1226765).
  - Update
    patches.suse/gpio-davinci-Validate-the-obtained-number-of-IRQs.patch
    (git-fixes CVE-2024-42092 bsc#1228447).
  - Update
    patches.suse/gpio-pca953x-fix-pca953x_irq_bus_sync_unlock-race.patch
    (stable-fixes CVE-2024-42253 bsc#1229005).
  - Update
    patches.suse/i2c-pnx-Fix-potential-deadlock-warning-from-del_time.patch
    (git-fixes CVE-2024-42153 bsc#1228510).
  - Update
    patches.suse/iio-chemical-bme680-Fix-overflows-in-compensate-func.patch
    (git-fixes CVE-2024-42086 bsc#1228452).
  - Update
    patches.suse/jffs2-Fix-potential-illegal-address-access-in-jffs2_free_inode.patch
    (git-fixes CVE-2024-42115 bsc#1228656).
  - Update
    patches.suse/libceph-fix-race-between-delayed_work-and-ceph_monc_s.patch
    (bsc#1228192 CVE-2024-42232 bsc#1228959).
  - Update
    patches.suse/media-dvb-frontends-tda10048-Fix-integer-overflow.patch
    (stable-fixes CVE-2024-42223 bsc#1228726).
  - Update
    patches.suse/misc-fastrpc-Fix-memory-leak-in-audio-daemon-attach-.patch
    (git-fixes CVE-2024-41025 bsc#1228527).
  - Update
    patches.suse/misc-fastrpc-Restrict-untrusted-app-to-attach-to-pri.patch
    (git-fixes CVE-2024-41024 bsc#1228525).
  - Update
    patches.suse/mm-Avoid-overflows-in-dirty-throttling-logic.patch
    (bsc#1222364 CVE-2024-26720 CVE-2024-42131 bsc#1228650).
  - Update
    patches.suse/msft-hv-3022-net-mana-Fix-possible-double-free-in-error-handling-.patch
    (git-fixes CVE-2024-42069 bsc#1228463).
  - Update
    patches.suse/net-can-j1939-Initialize-unused-data-in-j1939_send_o.patch
    (git-fixes CVE-2024-42076 bsc#1228484).
  - Update
    patches.suse/net-can-j1939-enhanced-error-handling-for-tightly-re.patch
    (git-fixes CVE-2023-52887 bsc#1228426).
  - Update
    patches.suse/nfc-nci-Add-the-inconsistency-check-between-the-inpu.patch
    (stable-fixes CVE-2024-42130 bsc#1228687).
  - Update
    patches.suse/nilfs2-add-missing-check-for-inode-numbers-on-direct.patch
    (stable-fixes CVE-2024-42104 bsc#1228654).
  - Update patches.suse/nvme-avoid-double-free-special-payload.patch
    (git-fixes CVE-2024-41073 bsc#1228635).
  - Update patches.suse/nvmet-always-initialize-cqe.result.patch
    (git-fixes CVE-2024-41079 bsc#1228615).
  - Update
    patches.suse/nvmet-fix-a-possible-leak-when-destroy-a-ctrl-during.patch
    (git-fixes CVE-2024-42152 bsc#1228724).
  - Update
    patches.suse/ocfs2-fix-DIO-failure-due-to-insufficient-transaction-credits.patch
    (git-fixes CVE-2024-42077 bsc#1228516).
  - Update
    patches.suse/ocfs2-strict-bound-check-before-memcmp-in-ocfs2_xatt.patch
    (bsc#1228410 CVE-2024-41016).
  - Update patches.suse/orangefs-fix-out-of-bounds-fsid-access.patch
    (git-fixes CVE-2024-42143 bsc#1228748).
  - Update
    patches.suse/pinctrl-fix-deadlock-in-create_pinctrl-when-handling.patch
    (git-fixes CVE-2024-42090 bsc#1228449).
  - Update
    patches.suse/platform-x86-toshiba_acpi-Fix-array-out-of-bounds-ac.patch
    (git-fixes CVE-2024-41028 bsc#1228539).
  - Update
    patches.suse/powerpc-Avoid-nmi_enter-nmi_exit-in-real-mode-interr.patch
    (bsc#1221645 ltc#205739 bsc#1223191 CVE-2024-42126 bsc#1228718).
  - Update
    patches.suse/powerpc-pseries-Fix-scv-instruction-crash-with-kexec.patch
    (bsc#1194869 CVE-2024-42230 bsc#1228489).
  - Update
    patches.suse/thermal-drivers-mediatek-lvts_thermal-Check-NULL-ptr.patch
    (stable-fixes CVE-2024-42144 bsc#1228666).
  - Update
    patches.suse/usb-atm-cxacru-fix-endpoint-checking-in-cxacru_bind.patch
    (git-fixes CVE-2024-41097 bsc#1228513).
  - Update
    patches.suse/usb-dwc3-core-remove-lock-of-otg-mode-during-gadget-.patch
    (git-fixes CVE-2024-42085 bsc#1228456).
  - Update
    patches.suse/usb-gadget-configfs-Prevent-OOB-read-write-in-usb_st.patch
    (stable-fixes CVE-2024-42236 bsc#1228964).
  - Update
    patches.suse/usb-xhci-prevent-potential-failure-in-handle_tx_even.patch
    (stable-fixes CVE-2024-42226 bsc#1228709).
  - Update
    patches.suse/wifi-cfg80211-restrict-NL80211_ATTR_TXQ_QUANTUM-valu.patch
    (git-fixes CVE-2024-42114 bsc#1228564).
  - Update
    patches.suse/wifi-cfg80211-wext-add-extra-SIOCSIWSCAN-data-check.patch
    (stable-fixes CVE-2024-41072 bsc#1228626).
  - Update
    patches.suse/wifi-mac80211-Avoid-address-calculations-via-out-of-.patch
    (stable-fixes CVE-2024-41071 bsc#1228625).
  - Update
    patches.suse/wifi-mt76-replace-skb_put-with-skb_put_zero.patch
    (stable-fixes CVE-2024-42225 bsc#1228710).
  - Update
    patches.suse/wifi-rtw89-fw-scan-offload-prohibit-all-6-GHz-channe.patch
    (bsc#1227149 CVE-2024-42125 bsc#1228674).
  - Update
    patches.suse/x86-bhi-Avoid-warning-in-DB-handler-due-to-BHI-mitigation
    (git-fixes CVE-2024-42240 bsc#1228966).
    Add CVE references.
  - commit dfa8582
  - Bluetooth: hci_sync: avoid dup filtering when passive scanning
    with adv monitor (git-fixes).
  - Bluetooth: l2cap: always unlock channel in
    l2cap_conless_channel() (git-fixes).
  - net: usb: qmi_wwan: fix memory leak for not ip packets
    (git-fixes).
  - padata: Fix possible divide-by-0 panic in padata_mt_helper()
    (git-fixes).
  - kcov: properly check for softirq context (git-fixes).
  - commit fc99a65
  - wireguard: allowedips: avoid unaligned 64-bit memory accesses
    (CVE-2024-42247 bsc#1228988).
  - commit 12abe6d
  - selftests/bpf: Add netlink helper library (bsc#1228021
    CVE-2024-41010).
  - Fix BPF selftest build failure
  - commit c3e9de4
  - x86/numa: Fix the sort compare func used in numa_fill_memblks()
    (git-fixes).
  - x86/numa: Fix the address overlap check in numa_fill_memblks()
    (git-fixes).
  - commit b42baa2

++++ kernel-rt:

  - kernel-binary.spec.in: Enable klp_symbols on openSUSE Tumbleweed (boo#1229042).
    After the Jump project the kernel used by SLE and openSUSE Leap are the
    same. As consequence the klp_symbols variable is set, enabling
    kernel-default-livepatch-devel on both SLE and openSUSE.
    The current rules to avoid enabling the package exclude openSUSE
    Tumbleweed alone, which doesn't makes sense for now. Enabling
    kernel-default-livepatch-devel on TW makes it easier to test the
    creation of kernel livepatches of the next SLE versions.
  - commit fd0b293
  - Split kABI workaround of recent hyperv fixes (bsc#1229040, bsc#1225745, CVE-2024-36911, bsc#1225717, CVE-2024-36910, bsc#1225744, CVE-2024-36909)
  - commit 3639306
  - Yet more build fix without patches.kabi (bsc#1226502)
  - commit 6bc3429
  - Fix build errors without patches.kabi (bsc#1226502)
    Now patches.suse/x86-Stop-using-weak-symbols-for-__iowrite32_copy.patch
    has a full backport and later partially reverted via
    patches.kabi/kabi-partial-revert-commit-20516d6e51dd.patch
  - commit 44c5e90
  - landlock: Fix d_parent walk (CVE-2024-40938 bsc#1227840).
  - commit 36de641
  - net: fix sk_memory_allocated_{add|sub} vs softirqs
    (bsc#1228757).
  - commit a963c0f
  - minmax: fix up min3() and max3() too (bsc#1229024).
  - minmax: improve macro expansion and type checking (bsc#1229024).
  - minmax: simplify min()/max()/clamp() implementation
    (bsc#1229024).
  - minmax: don't use max() in situations that want a C constant
    expression (bsc#1229024).
  - minmax: make generic MIN() and MAX() macros available everywhere
    (bsc#1229024).
  - minmax: simplify and clarify min_t()/max_t() implementation
    (bsc#1229024).
  - minmax: add a few more MIN_T/MAX_T users (bsc#1229024).
  - minmax: avoid overly complicated constant expressions in VM code
    (bsc#1229024).
  - drm/radeon/evergreen_cs: Clean up errors in evergreen_cs.c
    (bsc#1229024).
  - commit c64c296
  - Update
    patches.suse/ALSA-emux-improve-patch-ioctl-data-validation.patch
    (stable-fixes CVE-2024-42097 bsc#1228766).
  - Update
    patches.suse/ASoC-SOF-Intel-hda-fix-null-deref-on-system-suspend-.patch
    (git-fixes CVE-2024-41037 bsc#1228508).
  - Update
    patches.suse/ASoC-amd-acp-add-a-null-check-for-chip_pdev-structur.patch
    (git-fixes CVE-2024-42074 bsc#1228481).
  - Update
    patches.suse/ASoC-fsl-asoc-card-set-priv-pdev-before-using-it.patch
    (git-fixes CVE-2024-42089 bsc#1228450).
  - Update
    patches.suse/Bluetooth-ISO-Check-socket-flag-instead-of-hcon.patch
    (git-fixes CVE-2024-42141 bsc#1228502).
  - Update
    patches.suse/Bluetooth-Ignore-too-large-handle-values-in-BIG.patch
    (git-fixes CVE-2024-42133 bsc#1228511).
  - Update
    patches.suse/Bluetooth-hci_core-cancel-all-works-upon-hci_unregis.patch
    (stable-fixes CVE-2024-41063 bsc#1228580).
  - Update
    patches.suse/Bluetooth-qca-Fix-BT-enable-failure-again-for-QCA639.patch
    (git-fixes CVE-2024-42137 bsc#1228563).
  - Update patches.suse/PCI-MSI-Fix-UAF-in-msi_capability_init.patch
    (git-fixes CVE-2024-41096 bsc#1228479).
  - Update
    patches.suse/RDMA-restrack-Fix-potential-invalid-address-access.patch
    (git-fixes CVE-2024-42080 bsc#1228673).
  - Update
    patches.suse/USB-core-Fix-duplicate-endpoint-bug-by-clearing-rese.patch
    (git-fixes CVE-2024-41035 bsc#1228485).
  - Update patches.suse/USB-serial-mos7840-fix-crash-on-resume.patch
    (git-fixes CVE-2024-42244 bsc#1228967).
  - Update
    patches.suse/ata-libata-core-Fix-null-pointer-dereference-on-erro.patch
    (git-fixes CVE-2024-41098 bsc#1228467).
  - Update
    patches.suse/bluetooth-hci-disallow-setting-handle-bigger-than-HC.patch
    (git-fixes CVE-2024-42132 bsc#1228492).
  - Update
    patches.suse/bpf-Fail-bpf_timer_cancel-when-callback-is-being-can.patch
    (bsc#1228531 CVE-2024-41045 CVE-2024-42239 bsc#1228979).
  - Update
    patches.suse/can-mcp251xfd-fix-infinite-loop-when-xmit-fails.patch
    (git-fixes CVE-2024-41088 bsc#1228469).
  - Update
    patches.suse/cdrom-rearrange-last_media_change-check-to-avoid-uni.patch
    (stable-fixes CVE-2024-42136 bsc#1228758).
  - Update
    patches.suse/crypto-aead-cipher-zeroize-key-buffer-after-use.patch
    (stable-fixes CVE-2024-42229 bsc#1228708).
  - Update
    patches.suse/crypto-ecdh-explicitly-zeroize-private_key.patch
    (stable-fixes CVE-2024-42098 bsc#1228779).
  - Update
    patches.suse/drm-amd-display-ASSERT-when-failing-to-find-index-by.patch
    (stable-fixes CVE-2024-42117 bsc#1228582).
  - Update
    patches.suse/drm-amd-display-Check-index-msg_id-before-read-or-wr.patch
    (stable-fixes CVE-2024-42121 bsc#1228590).
  - Update
    patches.suse/drm-amd-display-Check-pipe-offset-before-setting-vbl.patch
    (stable-fixes CVE-2024-42120 bsc#1228588).
  - Update
    patches.suse/drm-amd-display-Fix-array-index-out-of-bounds-in-dml.patch
    (stable-fixes CVE-2024-41061 bsc#1228572).
  - Update
    patches.suse/drm-amd-display-Fix-overlapping-copy-within-dml_core.patch
    (stable-fixes CVE-2024-42227 bsc#1228707).
  - Update
    patches.suse/drm-amd-display-Skip-finding-free-audio-for-unknown-.patch
    (stable-fixes CVE-2024-42119 bsc#1228584).
  - Update
    patches.suse/drm-amd-display-Skip-pipe-if-the-pipe-idx-not-set-pr.patch
    (stable-fixes CVE-2024-42064 bsc#1228586).
  - Update
    patches.suse/drm-amdgpu-Fix-signedness-bug-in-sdma_v4_0_process_t.patch
    (git-fixes CVE-2024-41022 bsc#1228429).
  - Update
    patches.suse/drm-amdgpu-Using-uninitialized-value-size-when-calli.patch
    (stable-fixes CVE-2024-42228 bsc#1228667).
  - Update
    patches.suse/drm-amdgpu-avoid-using-null-object-of-framebuffer.patch
    (stable-fixes CVE-2024-41093 bsc#1228660).
  - Update
    patches.suse/drm-fbdev-dma-Only-set-smem_start-is-enable-per-modu.patch
    (git-fixes CVE-2024-41094 bsc#1228458).
  - Update
    patches.suse/drm-i915-gt-Fix-potential-UAF-by-revoke-of-fence-reg.patch
    (git-fixes CVE-2024-41092 bsc#1228483).
  - Update
    patches.suse/drm-lima-fix-shared-irq-handling-on-driver-remove.patch
    (stable-fixes CVE-2024-42127 bsc#1228721).
  - Update
    patches.suse/drm-nouveau-dispnv04-fix-null-pointer-dereference-in-66edf3f.patch
    (stable-fixes CVE-2024-41095 bsc#1228662).
  - Update
    patches.suse/drm-nouveau-dispnv04-fix-null-pointer-dereference-in.patch
    (stable-fixes CVE-2024-41089 bsc#1228658).
  - Update
    patches.suse/drm-nouveau-fix-null-pointer-dereference-in-nouveau_.patch
    (git-fixes CVE-2024-42101 bsc#1228495).
  - Update
    patches.suse/drm-panel-ilitek-ili9881c-Fix-warning-with-GPIO-cont.patch
    (stable-fixes CVE-2024-42087 bsc#1228677).
  - Update
    patches.suse/drm-radeon-check-bo_va-bo-is-non-NULL-before-using-i.patch
    (stable-fixes CVE-2024-41060 bsc#1228567).
  - Update
    patches.suse/filelock-fix-potential-use-after-free-in-posix_lock_inode.patch
    (git-fixes CVE-2024-41049 bsc#1228486).
  - Update
    patches.suse/firmware-cs_dsp-Fix-overflow-checking-of-wmfw-header.patch
    (git-fixes CVE-2024-41039 bsc#1228515).
  - Update
    patches.suse/firmware-cs_dsp-Prevent-buffer-overrun-when-processi.patch
    (git-fixes CVE-2024-41038 bsc#1228509).
  - Update
    patches.suse/firmware-cs_dsp-Return-error-if-block-header-overflo.patch
    (git-fixes CVE-2024-42238 bsc#1228991).
  - Update
    patches.suse/firmware-cs_dsp-Use-strnlen-on-name-fields-in-V1-wmf.patch
    (git-fixes CVE-2024-41056 bsc#1228480).
  - Update
    patches.suse/firmware-cs_dsp-Validate-payload-length-before-proce.patch
    (git-fixes CVE-2024-42237 bsc#1228992).
  - Update
    patches.suse/genirq-cpuhotplug-x86-vector-Prevent-vector-leak-dur.patch
    (git-fixes CVE-2024-31076 bsc#1226765).
  - Update
    patches.suse/gpio-davinci-Validate-the-obtained-number-of-IRQs.patch
    (git-fixes CVE-2024-42092 bsc#1228447).
  - Update
    patches.suse/gpio-pca953x-fix-pca953x_irq_bus_sync_unlock-race.patch
    (stable-fixes CVE-2024-42253 bsc#1229005).
  - Update
    patches.suse/i2c-pnx-Fix-potential-deadlock-warning-from-del_time.patch
    (git-fixes CVE-2024-42153 bsc#1228510).
  - Update
    patches.suse/iio-chemical-bme680-Fix-overflows-in-compensate-func.patch
    (git-fixes CVE-2024-42086 bsc#1228452).
  - Update
    patches.suse/jffs2-Fix-potential-illegal-address-access-in-jffs2_free_inode.patch
    (git-fixes CVE-2024-42115 bsc#1228656).
  - Update
    patches.suse/libceph-fix-race-between-delayed_work-and-ceph_monc_s.patch
    (bsc#1228192 CVE-2024-42232 bsc#1228959).
  - Update
    patches.suse/media-dvb-frontends-tda10048-Fix-integer-overflow.patch
    (stable-fixes CVE-2024-42223 bsc#1228726).
  - Update
    patches.suse/misc-fastrpc-Fix-memory-leak-in-audio-daemon-attach-.patch
    (git-fixes CVE-2024-41025 bsc#1228527).
  - Update
    patches.suse/misc-fastrpc-Restrict-untrusted-app-to-attach-to-pri.patch
    (git-fixes CVE-2024-41024 bsc#1228525).
  - Update
    patches.suse/mm-Avoid-overflows-in-dirty-throttling-logic.patch
    (bsc#1222364 CVE-2024-26720 CVE-2024-42131 bsc#1228650).
  - Update
    patches.suse/msft-hv-3022-net-mana-Fix-possible-double-free-in-error-handling-.patch
    (git-fixes CVE-2024-42069 bsc#1228463).
  - Update
    patches.suse/net-can-j1939-Initialize-unused-data-in-j1939_send_o.patch
    (git-fixes CVE-2024-42076 bsc#1228484).
  - Update
    patches.suse/net-can-j1939-enhanced-error-handling-for-tightly-re.patch
    (git-fixes CVE-2023-52887 bsc#1228426).
  - Update
    patches.suse/nfc-nci-Add-the-inconsistency-check-between-the-inpu.patch
    (stable-fixes CVE-2024-42130 bsc#1228687).
  - Update
    patches.suse/nilfs2-add-missing-check-for-inode-numbers-on-direct.patch
    (stable-fixes CVE-2024-42104 bsc#1228654).
  - Update patches.suse/nvme-avoid-double-free-special-payload.patch
    (git-fixes CVE-2024-41073 bsc#1228635).
  - Update patches.suse/nvmet-always-initialize-cqe.result.patch
    (git-fixes CVE-2024-41079 bsc#1228615).
  - Update
    patches.suse/nvmet-fix-a-possible-leak-when-destroy-a-ctrl-during.patch
    (git-fixes CVE-2024-42152 bsc#1228724).
  - Update
    patches.suse/ocfs2-fix-DIO-failure-due-to-insufficient-transaction-credits.patch
    (git-fixes CVE-2024-42077 bsc#1228516).
  - Update
    patches.suse/ocfs2-strict-bound-check-before-memcmp-in-ocfs2_xatt.patch
    (bsc#1228410 CVE-2024-41016).
  - Update patches.suse/orangefs-fix-out-of-bounds-fsid-access.patch
    (git-fixes CVE-2024-42143 bsc#1228748).
  - Update
    patches.suse/pinctrl-fix-deadlock-in-create_pinctrl-when-handling.patch
    (git-fixes CVE-2024-42090 bsc#1228449).
  - Update
    patches.suse/platform-x86-toshiba_acpi-Fix-array-out-of-bounds-ac.patch
    (git-fixes CVE-2024-41028 bsc#1228539).
  - Update
    patches.suse/powerpc-Avoid-nmi_enter-nmi_exit-in-real-mode-interr.patch
    (bsc#1221645 ltc#205739 bsc#1223191 CVE-2024-42126 bsc#1228718).
  - Update
    patches.suse/powerpc-pseries-Fix-scv-instruction-crash-with-kexec.patch
    (bsc#1194869 CVE-2024-42230 bsc#1228489).
  - Update
    patches.suse/thermal-drivers-mediatek-lvts_thermal-Check-NULL-ptr.patch
    (stable-fixes CVE-2024-42144 bsc#1228666).
  - Update
    patches.suse/usb-atm-cxacru-fix-endpoint-checking-in-cxacru_bind.patch
    (git-fixes CVE-2024-41097 bsc#1228513).
  - Update
    patches.suse/usb-dwc3-core-remove-lock-of-otg-mode-during-gadget-.patch
    (git-fixes CVE-2024-42085 bsc#1228456).
  - Update
    patches.suse/usb-gadget-configfs-Prevent-OOB-read-write-in-usb_st.patch
    (stable-fixes CVE-2024-42236 bsc#1228964).
  - Update
    patches.suse/usb-xhci-prevent-potential-failure-in-handle_tx_even.patch
    (stable-fixes CVE-2024-42226 bsc#1228709).
  - Update
    patches.suse/wifi-cfg80211-restrict-NL80211_ATTR_TXQ_QUANTUM-valu.patch
    (git-fixes CVE-2024-42114 bsc#1228564).
  - Update
    patches.suse/wifi-cfg80211-wext-add-extra-SIOCSIWSCAN-data-check.patch
    (stable-fixes CVE-2024-41072 bsc#1228626).
  - Update
    patches.suse/wifi-mac80211-Avoid-address-calculations-via-out-of-.patch
    (stable-fixes CVE-2024-41071 bsc#1228625).
  - Update
    patches.suse/wifi-mt76-replace-skb_put-with-skb_put_zero.patch
    (stable-fixes CVE-2024-42225 bsc#1228710).
  - Update
    patches.suse/wifi-rtw89-fw-scan-offload-prohibit-all-6-GHz-channe.patch
    (bsc#1227149 CVE-2024-42125 bsc#1228674).
  - Update
    patches.suse/x86-bhi-Avoid-warning-in-DB-handler-due-to-BHI-mitigation
    (git-fixes CVE-2024-42240 bsc#1228966).
    Add CVE references.
  - commit dfa8582
  - Bluetooth: hci_sync: avoid dup filtering when passive scanning
    with adv monitor (git-fixes).
  - Bluetooth: l2cap: always unlock channel in
    l2cap_conless_channel() (git-fixes).
  - net: usb: qmi_wwan: fix memory leak for not ip packets
    (git-fixes).
  - padata: Fix possible divide-by-0 panic in padata_mt_helper()
    (git-fixes).
  - kcov: properly check for softirq context (git-fixes).
  - commit fc99a65
  - wireguard: allowedips: avoid unaligned 64-bit memory accesses
    (CVE-2024-42247 bsc#1228988).
  - commit 12abe6d
  - selftests/bpf: Add netlink helper library (bsc#1228021
    CVE-2024-41010).
  - Fix BPF selftest build failure
  - commit c3e9de4
  - x86/numa: Fix the sort compare func used in numa_fill_memblks()
    (git-fixes).
  - x86/numa: Fix the address overlap check in numa_fill_memblks()
    (git-fixes).
  - commit b42baa2

++++ libssh:

  - Update to version 0.11.0
    https://www.libssh.org/2024/08/08/libssh-0-11-0-release/
  - Updated 0001-disable-timeout-test-on-slow-buildsystems.patch
  - Removed libssh-fix-ipv6-hostname-regression.patch

++++ makedumpfile:

  - add (bsc#1226183)
    * make-reserve_diskspace-do-nothing-for-flattened-form.patch

++++ selinux-policy:

  - Update to version 20240604+git249.ce3c66e6:
    * Provide type for sysstat lock files (bsc#1228247)
    * Label /run/udev/rules.d as udev_rules_t
    * Allow snapper to delete unlabeled_t files (bsc#1228889)

------------------------------------------------------------------
------------------  2024-8-8  -  Aug 8 2024  -------------------
------------------------------------------------------------------

++++ accel-config:

  - Update to 4.1.8:
    * Check for error return from iaa_do_crypto
    * Clean up resource leak in accfg_wq_get_occupancy
    * Update dsa_config_test_runner.sh
  - 4.1.7 changelog:
    * Typo fixes
    * Make verbose logging optional
    * Clean up typo
    * Don't attempt to disable non-existent devices
    * Don't list attributes not present
    * add required SECURITY.md file for OSSF Scorecard compliance

++++ cockpit:

  - revert load pam_oath, because it enforces the file for otp secrets to exist,
    will try again once pam_oath can have that optional

++++ python-kiwi:

  - Bump version: 10.1.1 → 10.1.2
  - Improve error reporting for remote deployment
    Add new method called show_log_and_quit which displays
    the written error log file as a file box to the user
  - Update test-image-orthos integration test
    Update the test such that you can also build it locally.
    Change the remote installation target to be a ramdisk
    for easy testing of remote deployments
  - Setup default minimum volume size per filesystem
    The former method provided a static value but there are huge
    differences for the minimum size requirement of a filesystem.
    For example extX is fine with 30MB whereas XFS requires 300MB.
    This commit adds a more dynamic default value based on the
    used filesystem.

++++ kernel-default:

  - inet_diag: Initialize pad field in struct inet_diag_req_v2
    (CVE-2024-42106 bsc#1228493).
  - commit 87d015b
  - x86/numa: Fix SRAT lookup of CFMWS ranges with
    numa_fill_memblks() (git-fixes).
  - ACPI/NUMA: Apply SRAT proximity domain to entire CFMWS window
    (git-fixes).
  - x86/numa: Introduce numa_fill_memblks() (git-fixes).
  - commit 7f40727
  - ACPI: processor_idle: use raw_safe_halt() in
    acpi_idle_play_dead() (git-fixes).
  - perf/smmuv3: Enable HiSilicon Erratum 162001900 quirk for
    HIP08/09 (git-fixes).
  - commit 23f94eb
  - Update
    patches.suse/crypto-hisilicon-debugfs-Fix-debugfs-uninit-process-.patch
    (bsc#1228764 CVE-2024-42147).
  - commit 9b42aa7
  - serial: 8250_omap: Fix Errata i2310 with RX FIFO level check
    (bsc#1228446 CVE-2024-42095).
  - commit 6d3406b
  - serial: 8250_omap: Implementation of Errata i2310 (bsc#1228446
    CVE-2024-42095).
  - commit a3bd324
  - net/iucv: fix use after free in iucv_sock_close() (bsc#1228973).
  - commit c3ed1a0
  - s390/sclp: Fix sclp_init() cleanup on failure (bsc#1228579
    CVE-2024-41068).
  - commit a8db9f2
  - config.sh: generate and install compile_commands.json (bsc#1228971)
    This file contains the command line options used to compile every C file.
    It's useful for the livepatching team.
  - kernel-binary: generate and install compile_commands.json (bsc#1228971)
    This file contains the command line options used to compile every C file.
    It's useful for the livepatching team.
  - commit 15eff3e
  - irqdomain: Fixed unbalanced fwnode get and put (git-fixes).
  - genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU
    offline (git-fixes).
  - genirq/generic_chip: Make irq_remove_generic_chip() irqdomain
    aware (git-fixes).
  - genirq/matrix: Exclude managed interrupts in
    irq_matrix_allocated() (git-fixes).
  - commit 592adb3
  - selftests/bpf: Test pinning bpf timer to a core (bsc#1228531
    CVE-2024-41045).
  - Refresh patches.suse/selftests-bpf-Test-racing-between-bpf_timer_cancel_a.patch
  - commit 1026c30
  - bpf: Add ability to pin bpf timer to calling CPU (bsc#1228531
    CVE-2024-41045).
  - commit 060adb3
  - power: supply: qcom_battmgr: return EAGAIN when firmware
    service is not up (git-fixes).
  - power: supply: axp288_charger: Round constant_charge_voltage
    writes down (git-fixes).
  - power: supply: axp288_charger: Fix constant_charge_voltage
    writes (git-fixes).
  - commit 5ff04d3
  - selftests/bpf: Add timer lockup selftest (bsc#1228531
    CVE-2024-41045).
  - bpf: Defer work in bpf_timer_cancel_and_free (bsc#1228531
    CVE-2024-41045).
  - bpf: Fail bpf_timer_cancel when callback is being cancelled
    (bsc#1228531 CVE-2024-41045).
  - bpf: replace bpf_timer_cancel_and_free with a generic helper
    (bsc#1228531 CVE-2024-41045).
  - bpf: replace bpf_timer_set_callback with a generic helper
    (bsc#1228531 CVE-2024-41045).
  - bpf: replace bpf_timer_init with a generic helper (bsc#1228531
    CVE-2024-41045).
  - bpf: make timer data struct more generic (bsc#1228531
    CVE-2024-41045).
  - bpf: Check map->usercnt after timer->timer is assigned
    (bsc#1228531 CVE-2024-41045).
  - commit a65dc5b

++++ kernel-rt:

  - inet_diag: Initialize pad field in struct inet_diag_req_v2
    (CVE-2024-42106 bsc#1228493).
  - commit 87d015b
  - x86/numa: Fix SRAT lookup of CFMWS ranges with
    numa_fill_memblks() (git-fixes).
  - ACPI/NUMA: Apply SRAT proximity domain to entire CFMWS window
    (git-fixes).
  - x86/numa: Introduce numa_fill_memblks() (git-fixes).
  - commit 7f40727
  - ACPI: processor_idle: use raw_safe_halt() in
    acpi_idle_play_dead() (git-fixes).
  - perf/smmuv3: Enable HiSilicon Erratum 162001900 quirk for
    HIP08/09 (git-fixes).
  - commit 23f94eb
  - Update
    patches.suse/crypto-hisilicon-debugfs-Fix-debugfs-uninit-process-.patch
    (bsc#1228764 CVE-2024-42147).
  - commit 9b42aa7
  - serial: 8250_omap: Fix Errata i2310 with RX FIFO level check
    (bsc#1228446 CVE-2024-42095).
  - commit 6d3406b
  - serial: 8250_omap: Implementation of Errata i2310 (bsc#1228446
    CVE-2024-42095).
  - commit a3bd324
  - net/iucv: fix use after free in iucv_sock_close() (bsc#1228973).
  - commit c3ed1a0
  - s390/sclp: Fix sclp_init() cleanup on failure (bsc#1228579
    CVE-2024-41068).
  - commit a8db9f2
  - config.sh: generate and install compile_commands.json (bsc#1228971)
    This file contains the command line options used to compile every C file.
    It's useful for the livepatching team.
  - kernel-binary: generate and install compile_commands.json (bsc#1228971)
    This file contains the command line options used to compile every C file.
    It's useful for the livepatching team.
  - commit 15eff3e
  - irqdomain: Fixed unbalanced fwnode get and put (git-fixes).
  - genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU
    offline (git-fixes).
  - genirq/generic_chip: Make irq_remove_generic_chip() irqdomain
    aware (git-fixes).
  - genirq/matrix: Exclude managed interrupts in
    irq_matrix_allocated() (git-fixes).
  - commit 592adb3
  - selftests/bpf: Test pinning bpf timer to a core (bsc#1228531
    CVE-2024-41045).
  - Refresh patches.suse/selftests-bpf-Test-racing-between-bpf_timer_cancel_a.patch
  - commit 1026c30
  - bpf: Add ability to pin bpf timer to calling CPU (bsc#1228531
    CVE-2024-41045).
  - commit 060adb3
  - power: supply: qcom_battmgr: return EAGAIN when firmware
    service is not up (git-fixes).
  - power: supply: axp288_charger: Round constant_charge_voltage
    writes down (git-fixes).
  - power: supply: axp288_charger: Fix constant_charge_voltage
    writes (git-fixes).
  - commit 5ff04d3
  - selftests/bpf: Add timer lockup selftest (bsc#1228531
    CVE-2024-41045).
  - bpf: Defer work in bpf_timer_cancel_and_free (bsc#1228531
    CVE-2024-41045).
  - bpf: Fail bpf_timer_cancel when callback is being cancelled
    (bsc#1228531 CVE-2024-41045).
  - bpf: replace bpf_timer_cancel_and_free with a generic helper
    (bsc#1228531 CVE-2024-41045).
  - bpf: replace bpf_timer_set_callback with a generic helper
    (bsc#1228531 CVE-2024-41045).
  - bpf: replace bpf_timer_init with a generic helper (bsc#1228531
    CVE-2024-41045).
  - bpf: make timer data struct more generic (bsc#1228531
    CVE-2024-41045).
  - bpf: Check map->usercnt after timer->timer is assigned
    (bsc#1228531 CVE-2024-41045).
  - commit a65dc5b

++++ python313-core:

  - Update list of skipped tests in qemu linux-user emulation

++++ liburing:

  - Skip test buf-ring-nommap.t if ENOMEM appears (happens in ppc64le arch).
    * test-buf-ring-nommap-skip-the-test-on-queue-init-ENO.patch

++++ python313:

  - Update list of skipped tests in qemu linux-user emulation

++++ rpm-config-SUSE:

  - Use a deterministic binarychangelogtrim
    based on build times of BuildRequires (boo#1047218)

++++ sysstat:

  - Updated sysstat-8.1.6-sa1sa2lock.diff to use flock to create the
    lockfile. Using lockfile would require additional SELinux permissions.
    Require util-linux instead of procmail for this (bsc#1228246)

++++ virtiofsd:

  - Service: Remove deprecated cargo_config and cargo_audit services, both
    are now handled by the cargo_vendor service
  - Add new upstream features for the libvirt/virtiofsd interop config
  - Fix build failure after update to Rust 1.80 (bsc#1228972)
  - Update to version 1.11.1:
    * Changes since 1.11.0:
    * Add "separate-options" capability
    * Force-call DESTROY on INIT
    * Do not require --shared-dir to print capabilities
    * Enable notification on vring failure
    * Bump version to v1.11.0
    * deps: Update to the latest rust-vmm crates
    * deps: Update to the latest libc
    * Note migration capability
    * README: Document new migration switches
    * Introduce --migration-mode switch
    * Introduce --migration-confirm-paths
    * PassthroughFs::init: Point to NegotiatedOpts
    * Implement device state deserialization
    * Add get_path_by_fd()/printable_fd() functions
    * Implement device state serialization
    * Implement preserialization/premigration
    * Define our serialized device state
    * Introduce serializable file handles
    * Introduce --migration-verify-handles
    * Introduce --migration-on-error switch
    * Allow explicitly invalid inodes and handles
    * Split try_lookup() off of do_lookup()
    * Add ReadDir::new_no_seek()
    * Put open_root_node() into own function
    * Add type for strong inode references
    * Hide InodeStore locking
    * Remove `&Inode` indirection
    * Add device state infrastructure
    * Add ErrorContext, ResultErrorContext traits
    * Add other_io_error() utility function
    * Add support for dirty memory logging
    * opt: Introduce --allow-mmap flag
    * fuse: Enable DIRECT_IO_ALLOW_MMAP with --allow-mmap
    * Add '--shared-dir' as required if '-o' is missing
    * Close the listener in the parent process
    * Check if the socket parent directory exists
    * Check if the shared directory exists
    * deps: Bump syslog version
    * Increase maximum virtqueue size to 32768
    * Allow multiple uid/gid maps
    * Hide clippy warning in readdir
    * Shorten `std::result::Result` where possible
    * Remove redundant Result imports
    * deps: Bump vhost and vhost-user-backend versions
    * Remove virtio-bindings feature
    * Directly write uid/gidmap where possible
    * Fix clippy warning: Complicated `match` condition
    * Fix clippy warning: Skip converting to owned
    * Fix clippy warning: Make use of `.cloned()`
    * Fix new compiler warnings

------------------------------------------------------------------
------------------  2024-8-7  -  Aug 7 2024  -------------------
------------------------------------------------------------------

++++ aardvark-dns:

  - Update to version 1.12.1:
    * Release v1.12.1
    * Updated release notes for 1.12.1
    * Change av cargo categories
    * Bump to 1.13.0-dev
    * Release 1.12.0
    * Release notes for 1.12
    * config: ignore enoent errors while reading configs
    * run cargo update
    * update upsteam resolvers on each refresh
    * fix(deps): update rust crate syslog to v7
    * fix(deps): update rust crate tokio to 1.39.2
    * add tcp support for forwarding (bsc#1234660)
    * add tcp listening support
    * test: add new test to check for startup error
    * return bind error to caller on first start
    * add our own error type and use it over anyhow
    * server: use anyhow to wrap parse_configs error
    * server: split out main loop into new function
    * main: remove aardvark-dns error prefix
    * coredns: remove unnecessary try_join! call
    * coredns: drop pointless name var
    * serve: read nameservers once
    * replace signal-hook with tokio::signal
    * serve: fix broken error logging
    * server: improve parent <-> child error handling
    * add some basic perf check script
    * fix(deps): update rust crate tokio to 1.39.0
    * coredns: create reply_ip() function
    * coredns: match dns type explicitly
    * server: use only one tokio runtime
    * coredns: improve indentation for process_message()
    * coredns: move upstream resolvers detection later
    * coredns: do not clone sender
    * read AARDVARK_NO_PROXY once
    * coredns: move main code out of select!
    * coredns: fix "name" naming
    * coredns: remove unused forward_addr/port
    * coredns: fix handling of dns search domain
    * coredns: rework PTR lookup flow
    * fix(deps): update rust crate tokio to 1.38.1
    * [skip-ci] TMT: Reorg upstream tests for downstream reusability
    * [skip-ci] Packit: use `packages: [aardvark-dns-fedora]` for podman-next builds
    * Be sure to have at least Epoch 2 to preserve upgrade path in c10s.
    * fix(deps): update rust crate log to 0.4.22
    * [CI:BUILD] rpm: Update Rust macro usage
    * fix(deps): update rust crate tokio to 1.38.0
    * Bump to 1.12.0-dev

++++ cockpit:

  - fix-libexecdir.patch: Fix libexecdir for leap and sle (bsc#1223533)
  - Fix systemd units folder for leap and sle (bsc#1226541)
  - Recommend cockpit-packagekit if zypper is installed
  - load pam_oath for optional TOTP for authentication

++++ python-kiwi:

  - Increase default volume size
    So far 30MB was set as default volume size which is by far
    too small for a number of filesystems, e.g btrfs and also XFS.
    This commit increases the default volume size such that all
    modern filesystems builds if the default volume size is used.
  - Update test-image-raid
    Apart from testing raid this integration test also tests
    a certain LVM volume setup. The test has been updated
    to use the btrfs filesystem because it has the most strict
    size requirements.

++++ jeos-firstboot:

  - Update to version 1.5.0:
    * Add module for TOTP setup (jsc#CPT-84)
    * Add module for user creation
    * Set LC_COLLATE=C.UTF-8
    * Document module API in README.md
    * Let modules specify title, description and priority
    * jeos-firstboot-functions: Simplify _find_modules
    * Use tabs for indentation everywhere
    * Drop stale README file

++++ kernel-default:

  - Move upstreamed sound patches into sorted section
  - commit df9598d
  - ASoC: amd: yc: Add quirk entry for OMEN by HP Gaming Laptop
    16-n0xxx (bsc#1227182).
  - commit 645364b
  - tcp: avoid too many retransmit packets (CVE-2024-41007
    bsc#1227863).
  - commit 8f47fe6
  - mlxsw: core_linecards: Fix double memory deallocation in case
    of invalid INI file (CVE-2024-42138 bsc#1228500).
  - ice: Don't process extts if PTP is disabled (CVE-2024-42107
    bsc#1228494).
  - ice: Fix improper extts handling (CVE-2024-42139 bsc#1228503).
  - net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx()
    from __netif_rx() (CVE-2024-42110 bsc#1228501).
  - net: txgbe: initialize num_q_vectors for MSI/INTx interrupts
    (CVE-2024-42113 bsc#1228568).
  - bnx2x: Fix multiple UBSAN array-index-out-of-bounds
    (CVE-2024-42148 bsc#1228487).
  - net/mlx5: E-switch, Create ingress ACL when needed
    (CVE-2024-42142 bsc#1228491).
  - mlxsw: spectrum_buffers: Fix memory corruptions on Spectrum-4
    systems (CVE-2024-42073 bsc#1228457).
  - gve: Account for stopped queues when reading NIC stats
    (CVE-2024-42162 bsc#1228706).
  - commit e94d07a
  - packaging: Add case-sensitive perl option parsing
    A recent change in Getopt::Long [1]:
    Changes in version 2.55
  - ----------------------
    * Fix long standing bug that duplicate options were not detected
    when the options differ in case while ignore_case is in effect.
    This will now yield a warning and become a fatal error in a future
    release.
    perl defaults to ignore_case by default, switch it off to avoid
    accidental misparsing of options.
    This was suggested after similar change in scripts/.
  - commit e978477
  - xdp: Remove WARN() from __xdp_reg_mem_model() (bsc#1228482
    CVE-2024-42082).
  - commit 73e7677
  - arm64: jump_label: Ensure patched jump_labels are visible to all CPUs (git-fixes)
  - commit 2480247
  - KVM: arm64: Fix clobbered ELR in sync abort/SError (git-fixes)
  - commit 90dba9e
  - bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG (git-fixes)
  - commit e10a18b
  - arm64: armv8_deprecated: Fix warning in isndep cpuhp starting process (git-fixes)
  - commit bae6c4b
  - nvme-pci: do not directly handle subsys reset fallout
    (bsc#1220066).
  - commit 2082e5f
  - platform/x86/intel/ifs: Initialize union ifs_status to zero
    (git-fixes).
  - commit b291cc1

++++ kernel-rt:

  - Move upstreamed sound patches into sorted section
  - commit df9598d
  - ASoC: amd: yc: Add quirk entry for OMEN by HP Gaming Laptop
    16-n0xxx (bsc#1227182).
  - commit 645364b
  - tcp: avoid too many retransmit packets (CVE-2024-41007
    bsc#1227863).
  - commit 8f47fe6
  - mlxsw: core_linecards: Fix double memory deallocation in case
    of invalid INI file (CVE-2024-42138 bsc#1228500).
  - ice: Don't process extts if PTP is disabled (CVE-2024-42107
    bsc#1228494).
  - ice: Fix improper extts handling (CVE-2024-42139 bsc#1228503).
  - net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx()
    from __netif_rx() (CVE-2024-42110 bsc#1228501).
  - net: txgbe: initialize num_q_vectors for MSI/INTx interrupts
    (CVE-2024-42113 bsc#1228568).
  - bnx2x: Fix multiple UBSAN array-index-out-of-bounds
    (CVE-2024-42148 bsc#1228487).
  - net/mlx5: E-switch, Create ingress ACL when needed
    (CVE-2024-42142 bsc#1228491).
  - mlxsw: spectrum_buffers: Fix memory corruptions on Spectrum-4
    systems (CVE-2024-42073 bsc#1228457).
  - gve: Account for stopped queues when reading NIC stats
    (CVE-2024-42162 bsc#1228706).
  - commit e94d07a
  - packaging: Add case-sensitive perl option parsing
    A recent change in Getopt::Long [1]:
    Changes in version 2.55
  - ----------------------
    * Fix long standing bug that duplicate options were not detected
    when the options differ in case while ignore_case is in effect.
    This will now yield a warning and become a fatal error in a future
    release.
    perl defaults to ignore_case by default, switch it off to avoid
    accidental misparsing of options.
    This was suggested after similar change in scripts/.
  - commit e978477
  - xdp: Remove WARN() from __xdp_reg_mem_model() (bsc#1228482
    CVE-2024-42082).
  - commit 73e7677
  - arm64: jump_label: Ensure patched jump_labels are visible to all CPUs (git-fixes)
  - commit 2480247
  - KVM: arm64: Fix clobbered ELR in sync abort/SError (git-fixes)
  - commit 90dba9e
  - bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG (git-fixes)
  - commit e10a18b
  - arm64: armv8_deprecated: Fix warning in isndep cpuhp starting process (git-fixes)
  - commit bae6c4b
  - nvme-pci: do not directly handle subsys reset fallout
    (bsc#1220066).
  - commit 2082e5f
  - platform/x86/intel/ifs: Initialize union ifs_status to zero
    (git-fixes).
  - commit b291cc1

++++ samba:

  - Fix a crash when joining offline and 'kerberos method' includes
    keytab; (bsc#1228732).

++++ python313-core:

  - Add CVE-2024-6923-email-hdr-inject.patch to prevent email
    header injection due to unquoted newlines (bsc#1228780,
    CVE-2024-6923).
  - Adding bso1227999-reproducible-builds.patch fixing bsc#1227999
    adding reproducibility patches from gh#python/cpython!121872
    and gh#python/cpython!121883.
  - Add skip_test_abort_clients.patch (gh#python/cpython#122136)
    skip not yet fixed failing test
  - %{profileopt} variable is set according to the variable
    %{do_profiling} (bsc#1227999)
  - Update bluez-devel-vendor.tar.xz

++++ netavark:

  - Update to version 1.12.1:
    * Release v1.12.1
    * Update release notes for v1.12.1
    * Change nv cargo categories
    * Bump to 1.13.0-dev
    * Release 1.12
    * Release Notes for 1.12
    * run cargo update
    * rpm: use nftables as default for f41
    * fix(deps): update rust crate serde_json to 1.0.121
    * fix(deps): update rust crate tokio to 1.39.2
    * aardvark-dns: trim whitespaces from error text
    * fix(deps): update rust crate env_logger to 0.11.5
    * [skip-ci] RPM: handle iptables/nftables dependencies
    * fix aardvark-dns error handling
    * fix(deps): update rust crate tokio to 1.39.1
    * fix(deps): update rust crate env_logger to 0.11.4
    * fix(deps): update rust crate tokio to 1.38.1
    * update mozim to 0.2.4 (bsc#1236567)
    * fix(deps): update rust crate serde_json to 1.0.120
    * netavark: dhcp_proxy: use dns servers from dhcp lease
    * fix(deps): update rust crate serde_json to 1.0.119
    * fix(deps): update rust crate netlink-packet-route to 0.20.1
    * fix(deps): update rust crate log to 0.4.22
    * Fix Epoch so upgrade path is preserved from Fedora/RHEL.
    * test: add macvlan metric test
    * fix(deps): update rust crate serde_json to 1.0.118
    * fix(deps): update rust crate url to 2.5.2
    * fix(deps): update rust crate prost to 0.12.6
    * fix(deps): update rust crate url to 2.5.1
    * fix(deps): update rust crate iptables to 0.5.2
    * [CI:BUILD] rpm: Update Rust macro usage
    * fix(deps): update rust crate nftables to 0.4.1
    * fix(deps): update rust crate tokio to 1.38.0
    * Bump to 1.12.0-dev

++++ pam:

  - Prevent cursor escape from the login prompt [bsc#1194818]
    * Added: pam-bsc1194818-cursor-escape.patch

++++ pam-full-src:

  - Prevent cursor escape from the login prompt [bsc#1194818]
    * Added: pam-bsc1194818-cursor-escape.patch

++++ python313:

  - Add CVE-2024-6923-email-hdr-inject.patch to prevent email
    header injection due to unquoted newlines (bsc#1228780,
    CVE-2024-6923).
  - Adding bso1227999-reproducible-builds.patch fixing bsc#1227999
    adding reproducibility patches from gh#python/cpython!121872
    and gh#python/cpython!121883.
  - Add skip_test_abort_clients.patch (gh#python/cpython#122136)
    skip not yet fixed failing test
  - %{profileopt} variable is set according to the variable
    %{do_profiling} (bsc#1227999)
  - Update bluez-devel-vendor.tar.xz

++++ sysuser-tools:

  - Remove check for .buildenv to see failures in OBS
  - usermod: revert renamed arguments

------------------------------------------------------------------
------------------  2024-8-6  -  Aug 6 2024  -------------------
------------------------------------------------------------------

++++ combustion:

  - Update to version 1.4:
    * Add support for remote config files using combustion.url (jsc#PED-8591)

++++ dbus-broker:

  - Looks like we need systemd_user_ scripts for some upgrades to
    work

++++ python-kiwi:

  - Use shutil.which for Path.which
  - Drop Path.remove & Path.rename
    Both methods were only used in one place each and it makes much more sense to
    use the pathlib builtin methods instead
  - Replace Path.create implementation with pathlib builtin
  - Bump version: 10.1.0 → 10.1.1

++++ fwupd:

  - Update to version 1.9.23:
    + Fix a regression in 1.9.22 that caused some devices not to
    probe correctly.
    + Try harder to get a valid response when flashing usi-dock
    devices.

++++ guestfs-tools:

  - Update to version 1.53.2 (jsc#PED-6305)
    * Implement --inject-blnsvr operation
    * mlcustomize: firstboot: Use Linux path for Powershell script path
    * mlcustomize: firstboot: Use powershell.exe instead of path
    * mlcustomize: firstboot: Use Powershell -NoProfile flag
    * mlcustomize: Revert delay installation of qemu-ga MSI
    * mldrivers/linux_kernels.ml: Prefix general information with ^info:
    * mlcustomize: Use Start-Process -Wait to run qemu-ga installer
    * mlcustomize: Add Firstboot.firstboot_dir function
    * mlcustomize: Place powershell scripts into <firstboot_dir>\Temp
    * mlcustomize: Inject qemu-ga & blnsvr into <firstboot_dir>/Temp
    * mlcustomize: Write qemu-ga log file name to log.txt

++++ kernel-default:

  - scsi: qedi: Fix crash while reading debugfs attribute
    (bsc#1227929 CVE-2024-40978).
  - block/ioctl: prefer different overflow check (bsc#1227867
    CVE-2024-41000).
  - commit 4cc5e60
  - tipc: force a dst refcount before doing decryption (CVE-2024-40983 bsc#1227819).
  - commit cee1bad
  - net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()
    (CVE-2024-40995 bsc#1227830).
  - commit 0580a17
  - PCI: hv: Return zero, not garbage, when reading
    PCI_INTERRUPT_PIN (git-fixes).
  - RDMA/mana_ib: Use virtual address in dma regions for MRs
    (git-fixes).
  - commit 9336dc6
  - bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD
    (bsc#1228756 CVE-2024-42161).
  - commit 64d3ad2
  - ASoC: topology: Fix route memory corruption (CVE-2024-41069
    bsc#1228644).
  - ASoC: topology: Clean up route loading (CVE-2024-41069
    bsc#1228644).
  - commit 30d44d4
  - md-cluster: keeping kabi compatibility for upstream commit
    35a0a409fa26 (bsc#1223395).
  - md-cluster: fix no recovery job when adding/re-adding a disk
    (bsc#1223395).
  - md-cluster: fix hanging issue while a new disk adding
    (bsc#1223395).
  - commit dac906f
  - tools/perf: Fix timing issue with parallel threads in perf
    bench wake-up-parallel (bsc#1227747).
  - tools/perf: Fix perf bench epoll to enable the run when some
    CPU's are offline (bsc#1227747).
  - tools/perf: Fix perf bench futex to enable the run when some
    CPU's are offline (bsc#1227747).
  - commit 7bc1e4f

++++ kernel-rt:

  - scsi: qedi: Fix crash while reading debugfs attribute
    (bsc#1227929 CVE-2024-40978).
  - block/ioctl: prefer different overflow check (bsc#1227867
    CVE-2024-41000).
  - commit 4cc5e60
  - tipc: force a dst refcount before doing decryption (CVE-2024-40983 bsc#1227819).
  - commit cee1bad
  - net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc()
    (CVE-2024-40995 bsc#1227830).
  - commit 0580a17
  - PCI: hv: Return zero, not garbage, when reading
    PCI_INTERRUPT_PIN (git-fixes).
  - RDMA/mana_ib: Use virtual address in dma regions for MRs
    (git-fixes).
  - commit 9336dc6
  - bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD
    (bsc#1228756 CVE-2024-42161).
  - commit 64d3ad2
  - ASoC: topology: Fix route memory corruption (CVE-2024-41069
    bsc#1228644).
  - ASoC: topology: Clean up route loading (CVE-2024-41069
    bsc#1228644).
  - commit 30d44d4
  - md-cluster: keeping kabi compatibility for upstream commit
    35a0a409fa26 (bsc#1223395).
  - md-cluster: fix no recovery job when adding/re-adding a disk
    (bsc#1223395).
  - md-cluster: fix hanging issue while a new disk adding
    (bsc#1223395).
  - commit dac906f
  - tools/perf: Fix timing issue with parallel threads in perf
    bench wake-up-parallel (bsc#1227747).
  - tools/perf: Fix perf bench epoll to enable the run when some
    CPU's are offline (bsc#1227747).
  - tools/perf: Fix perf bench futex to enable the run when some
    CPU's are offline (bsc#1227747).
  - commit 7bc1e4f

++++ samba:

  - Update to 4.20.4
    * --version-* options are still not ergonomic, and they reject
    tilde characters; (bso#15673).
  - Update to 4.20.3
    * Running samba-bgqd a a standalone systemd service does not
    work; (bso#15683).
    * When claims enabled with heimdal kerberos, unable to log on
    to a Windows computer when user account need to change their
    own password; (bso#15655).
    * Invalid client warning about command line passwords;
    (bso#15671).
    * Version string is truncated in manpages; (bso#15672).
    * cmdline_burn does not always burn secrets; (bso#15674).
    * Samba does not parse SDDL found in defaultSecurityDescriptor
    in AD_DS_Classes_Windows_Server_v1903.ldf; (bso#15685).
    * The images don\'t build after the git security release and
    CentOS 8 Stream is EOL; (bso#15660).
    * Fix clock skew error message and memory cache clock skew
    recovery; (bso#15676).
    * Heimdal ignores _gsskrb5_decapsulate errors in
    init_sec_context/repl_mutual; (bso#15603).
    * s4:ldap_server: does not support tls channel bindings for
    sasl binds; (bso#15621).
    * CTDB socket output queues may suffer unbounded delays under
    some special conditions; (bso#15678).

++++ passt:

  - Update to version 20240806.ee36266:
    * log, passt: Keep printing to stderr when passt is running in foreground
    * tcp_splice: Fix side in OUT_WAIT flag setting
    * util: Use unsigned (size_t) value for iov length
    * udp_flow: move all udp_flow functions to udp_flow.c
    * udp_flow: Remove udp_meta_t from the parameters of udp_flow_from_sock()
    * log: Make logfile_write() private
    * pasta: Save errno on signal handler entry, restore on return when needed
    * pasta: modify hostname when detaching new namespace
    * Fix typo in README file
    * fedora/rpkg: List myself as author for changelog entries

++++ virt-manager:

  - Fix test failure with libvirt version 10.6.0
    092-cli-Use-regex-for-grep-and-nogrep-args.patch
    093-cli-Fix-with-latest-libvirt.patch

------------------------------------------------------------------
------------------  2024-8-5  -  Aug 5 2024  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20240805.7513b28:
    * Remove obsolete resolv+ manual page
    * Remove obsolete defaultdomain.5 manual page
    * Move /etc/skel to /usr/etc/skel (hermetic-usr)
    * Remove obsolete refresh_initrd
    * Add deprecation notice for service [jsc#PED-266]

++++ afterburn:

  - enable upstream tests

++++ audit-secondary:

  - Remove rcaudit symlink [jsc#PED-266]

++++ ca-certificates:

  - Update to version 2+git20240805.fd24d50:
    * Remove rc symlink [jsc#PED-266]

++++ python-kiwi:

  - Mandatory package scripts for Debian bootstrap
    Make sure to run some mandatory package pre/post scripts
    such that settings like /etc/passwd, a root user, etc..
    exists. This action can also be done in post_bootstrap.sh
    but I think it's better to do this in the core code
  - Bump version: 10.0.28 → 10.1.0
  - kiwi no longer uses debootstrap
    For building Debian based images we used debootstrap to
    bootstrap an empty root until apt-get could be used to
    complete the job. This has now changed such hat apt-get
    is also used for bootstrapping a new system. The concept
    and also potential alternatives to the way kiwi bootstraps
    Debian based systems can be found here:
    * https://osinside.github.io/kiwi/working_with_images/build_without_debianbootstrap.html
    Due to the drop of debootstrap it might happen that
    package lists of existing image descriptions needs to be
    extended with packages that were formerly pulled in by
    debootstrap but did not get properly pulled in with the
    new apt based bootstrap. As reference please check out the
    integration tests from here:
    * https://github.com/OSInside/kiwi/tree/main/build-tests/x86/ubuntu
    * https://github.com/OSInside/kiwi/tree/main/build-tests/x86/debian
    Thanks
  - Bump version: 10.0.27 → 10.0.28

++++ kernel-default:

  - powerpc: fix a file leak in kvm_vcpu_ioctl_enable_cap()
    (bsc#1194869).
  - KVM: PPC: Book3S HV: Fix the set_one_reg for MMCR3
    (bsc#1194869).
  - commit f36d7ca
  - KVM: PPC: Book3S HV: Handle pending exceptions on guest entry
    with MSR_EE (bsc#1215199).
  - commit 6051d0b
  - liquidio: Adjust a NULL pointer handling path in
    lio_vf_rep_copy_packet (CVE-2024-39506 bsc#1227729).
  - commit 6f4e943
  - kabi/severity: add nvme common code
    The nvme common code is also allowed to change the data structures, there
    are only internal users.
  - commit 3abdbd5
  - apparmor: unpack transition table if dfa is not present
    (bsc#1226031).
  - commit 10a598f
  - scsi: lpfc: Update lpfc version to 14.4.0.3 (bsc#1228857).
  - scsi: lpfc: Revise lpfc_prep_embed_io routine with proper
    endian macro usages (bsc#1228857).
  - scsi: lpfc: Fix incorrect request len mbox field when setting
    trunking via sysfs (bsc#1228857).
  - scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
    (bsc#1228857).
  - scsi: lpfc: Fix handling of fully recovered fabric node in
    dev_loss callbk (bsc#1228857).
  - scsi: lpfc: Relax PRLI issue conditions after GID_FT response
    (bsc#1228857).
  - scsi: lpfc: Allow DEVICE_RECOVERY mode after RSCN receipt if
    in PRLI_ISSUE state (bsc#1228857).
  - scsi: lpfc: Cancel ELS WQE instead of issuing abort when SLI
    port is inactive (bsc#1228857).
  - commit c4b9763
  - scsi: qla2xxx: Convert comma to semicolon (bsc#1228850).
  - scsi: qla2xxx: Update version to 10.02.09.300-k (bsc#1228850).
  - scsi: qla2xxx: Use QP lock to search for bsg (bsc#1228850).
  - scsi: qla2xxx: Reduce fabric scan duplicate code (bsc#1228850).
  - scsi: qla2xxx: Fix optrom version displayed in FDMI
    (bsc#1228850).
  - scsi: qla2xxx: During vport delete send async logout explicitly
    (bsc#1228850).
  - scsi: qla2xxx: Complete command early within lock (bsc#1228850).
  - scsi: qla2xxx: Fix flash read failure (bsc#1228850).
  - scsi: qla2xxx: Return ENOBUFS if sg_cnt is more than one for
    ELS cmds (bsc#1228850).
  - scsi: qla2xxx: Fix for possible memory corruption (bsc#1228850).
  - scsi: qla2xxx: validate nvme_local_port correctly (bsc#1228850).
  - scsi: qla2xxx: Unable to act on RSCN for port online
    (bsc#1228850).
  - scsi: qla2xxx: Remove unused struct 'scsi_dif_tuple'
    (bsc#1228850).
  - scsi: qla2xxx: Fix debugfs output for fw_resource_count
    (bsc#1228850).
  - scsi: qla2xxx: Indent help text (bsc#1228850).
  - scsi: qla2xxx: Drop driver owner assignment (bsc#1228850).
  - scsi: qla2xxx: Avoid possible run-time warning with long
    model_num (bsc#1228850).
  - string.h: Introduce memtostr() and memtostr_pad() (bsc#1228849).
  - commit 072d194
  - nvme-pci: add missing condition check for existence of mapped
    data (git-fixes).
  - nvme-pci: Fix the instructions for disabling power management
    (git-fixes).
  - nvmet-auth: fix nvmet_auth hash error handling (git-fixes).
  - nvmet: make 'tsas' attribute idempotent for RDMA (git-fixes).
  - nvme: fixup comment for nvme RDMA Provider Type (git-fixes).
  - nvmet: do not return 'reserved' for empty TSAS values
    (git-fixes).
  - nvme: fix NVME_NS_DEAC may incorrectly identifying the disk
    as EXT_LBA (git-fixes).
  - nvmet: always initialize cqe.result (git-fixes).
  - nvme: avoid double free special payload (git-fixes).
  - nvmet: fix a possible leak when destroy a ctrl during qp
    establishment (git-fixes).
  - nvme: adjust multiples of NVME_CTRL_PAGE_SIZE in offset
    (git-fixes).
  - nvme-multipath: find NUMA path only for online numa-node
    (git-fixes).
  - commit 7935501
  - check-for-config-changes: ignore also GCC_ASM_GOTO_OUTPUT_BROKEN
    Mainline commit f2f6a8e88717 ("init/Kconfig: remove
    CONFIG_GCC_ASM_GOTO_OUTPUT_WORKAROUND") replaced
    GCC_ASM_GOTO_OUTPUT_WORKAROUND with GCC_ASM_GOTO_OUTPUT_BROKEN. Ignore both
    when checking config changes.
  - commit b60be3e

++++ kernel-rt:

  - powerpc: fix a file leak in kvm_vcpu_ioctl_enable_cap()
    (bsc#1194869).
  - KVM: PPC: Book3S HV: Fix the set_one_reg for MMCR3
    (bsc#1194869).
  - commit f36d7ca
  - KVM: PPC: Book3S HV: Handle pending exceptions on guest entry
    with MSR_EE (bsc#1215199).
  - commit 6051d0b
  - liquidio: Adjust a NULL pointer handling path in
    lio_vf_rep_copy_packet (CVE-2024-39506 bsc#1227729).
  - commit 6f4e943
  - kabi/severity: add nvme common code
    The nvme common code is also allowed to change the data structures, there
    are only internal users.
  - commit 3abdbd5
  - apparmor: unpack transition table if dfa is not present
    (bsc#1226031).
  - commit 10a598f
  - scsi: lpfc: Update lpfc version to 14.4.0.3 (bsc#1228857).
  - scsi: lpfc: Revise lpfc_prep_embed_io routine with proper
    endian macro usages (bsc#1228857).
  - scsi: lpfc: Fix incorrect request len mbox field when setting
    trunking via sysfs (bsc#1228857).
  - scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
    (bsc#1228857).
  - scsi: lpfc: Fix handling of fully recovered fabric node in
    dev_loss callbk (bsc#1228857).
  - scsi: lpfc: Relax PRLI issue conditions after GID_FT response
    (bsc#1228857).
  - scsi: lpfc: Allow DEVICE_RECOVERY mode after RSCN receipt if
    in PRLI_ISSUE state (bsc#1228857).
  - scsi: lpfc: Cancel ELS WQE instead of issuing abort when SLI
    port is inactive (bsc#1228857).
  - commit c4b9763
  - scsi: qla2xxx: Convert comma to semicolon (bsc#1228850).
  - scsi: qla2xxx: Update version to 10.02.09.300-k (bsc#1228850).
  - scsi: qla2xxx: Use QP lock to search for bsg (bsc#1228850).
  - scsi: qla2xxx: Reduce fabric scan duplicate code (bsc#1228850).
  - scsi: qla2xxx: Fix optrom version displayed in FDMI
    (bsc#1228850).
  - scsi: qla2xxx: During vport delete send async logout explicitly
    (bsc#1228850).
  - scsi: qla2xxx: Complete command early within lock (bsc#1228850).
  - scsi: qla2xxx: Fix flash read failure (bsc#1228850).
  - scsi: qla2xxx: Return ENOBUFS if sg_cnt is more than one for
    ELS cmds (bsc#1228850).
  - scsi: qla2xxx: Fix for possible memory corruption (bsc#1228850).
  - scsi: qla2xxx: validate nvme_local_port correctly (bsc#1228850).
  - scsi: qla2xxx: Unable to act on RSCN for port online
    (bsc#1228850).
  - scsi: qla2xxx: Remove unused struct 'scsi_dif_tuple'
    (bsc#1228850).
  - scsi: qla2xxx: Fix debugfs output for fw_resource_count
    (bsc#1228850).
  - scsi: qla2xxx: Indent help text (bsc#1228850).
  - scsi: qla2xxx: Drop driver owner assignment (bsc#1228850).
  - scsi: qla2xxx: Avoid possible run-time warning with long
    model_num (bsc#1228850).
  - string.h: Introduce memtostr() and memtostr_pad() (bsc#1228849).
  - commit 072d194
  - nvme-pci: add missing condition check for existence of mapped
    data (git-fixes).
  - nvme-pci: Fix the instructions for disabling power management
    (git-fixes).
  - nvmet-auth: fix nvmet_auth hash error handling (git-fixes).
  - nvmet: make 'tsas' attribute idempotent for RDMA (git-fixes).
  - nvme: fixup comment for nvme RDMA Provider Type (git-fixes).
  - nvmet: do not return 'reserved' for empty TSAS values
    (git-fixes).
  - nvme: fix NVME_NS_DEAC may incorrectly identifying the disk
    as EXT_LBA (git-fixes).
  - nvmet: always initialize cqe.result (git-fixes).
  - nvme: avoid double free special payload (git-fixes).
  - nvmet: fix a possible leak when destroy a ctrl during qp
    establishment (git-fixes).
  - nvme: adjust multiples of NVME_CTRL_PAGE_SIZE in offset
    (git-fixes).
  - nvme-multipath: find NUMA path only for online numa-node
    (git-fixes).
  - commit 7935501
  - check-for-config-changes: ignore also GCC_ASM_GOTO_OUTPUT_BROKEN
    Mainline commit f2f6a8e88717 ("init/Kconfig: remove
    CONFIG_GCC_ASM_GOTO_OUTPUT_WORKAROUND") replaced
    GCC_ASM_GOTO_OUTPUT_WORKAROUND with GCC_ASM_GOTO_OUTPUT_BROKEN. Ignore both
    when checking config changes.
  - commit b60be3e

++++ util-linux-systemd:

  - Update to version 2.40.2:
    * cfdisk: fix possible integer overflow
    * libmount: improving robustness in reading kernel messages,
    add pidfs to pseudo fs list
    * lscpu: New Arm Cortex part numbers
    fix hang of lscpu -e (bsc#1225598)
    * lsfd: Refactor the pidfd logic, support pidfs
    (obsoletes
    0001-include-Include-unistd.h-in-pidfd-utils.h-for-syscal.patch,
    0002-lsfd-Refactor-the-pidfd-logic-into-lsfd-pidfd.c.patch,
    0003-lsfd-Support-pidfs.patch,
    0004-lsfd-test-Adapt-test-cases-for-pidfs.patch)
    * mkswap.8.adoc: update note regarding swapfile creation
    * setpgid: make -f work
    * Many other fixes, improvements and code cleanup. For the
    complete list see
    https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.40/v2.40.2-ReleaseNotes
  - Enable kernel mountfd API, as it should be already stable
    (PED-9752).
  - Move autoreconf back to %build.
  - Add devel dependencies.
  - Remove util-linux-rpmlintrc. It is no more needed with multibuild.

++++ util-linux:

  - Update to version 2.40.2:
    * cfdisk: fix possible integer overflow
    * libmount: improving robustness in reading kernel messages,
    add pidfs to pseudo fs list
    * lscpu: New Arm Cortex part numbers
    fix hang of lscpu -e (bsc#1225598)
    * lsfd: Refactor the pidfd logic, support pidfs
    (obsoletes
    0001-include-Include-unistd.h-in-pidfd-utils.h-for-syscal.patch,
    0002-lsfd-Refactor-the-pidfd-logic-into-lsfd-pidfd.c.patch,
    0003-lsfd-Support-pidfs.patch,
    0004-lsfd-test-Adapt-test-cases-for-pidfs.patch)
    * mkswap.8.adoc: update note regarding swapfile creation
    * setpgid: make -f work
    * Many other fixes, improvements and code cleanup. For the
    complete list see
    https://mirrors.edge.kernel.org/pub/linux/utils/util-linux/v2.40/v2.40.2-ReleaseNotes
  - Enable kernel mountfd API, as it should be already stable
    (PED-9752).
  - Move autoreconf back to %build.
  - Add devel dependencies.
  - Remove util-linux-rpmlintrc. It is no more needed with multibuild.

++++ bluez:

  - update to 5.77:
    * Fix issue with storing and handling connection parameters.
    * Fix issue with handling device that are marked as temporary.
    * Fix issue with HID and special handling for non-keyboards.
    * Fix issue with BR/EDR not support when discoverable is off.
    * Add support for initial implementation of ASHA profile.
    * Fix issue with broadcast channel location and stream
    capabilities.
    * Fix issue with handling BIS management and synchronization.
    * Fix issue with handling Extended Advertising.
    * Fix issue with UserspaceHID and replay structures.
    * Add support for providing PPCP characteristic.
    * Fix issue with build system and header inclusion.
    * Fix issue with not enabling Wideband Speech when available.
    * Fix issue with UserspaceHID and Bluetooth Classic devices.
    * Fix issue with checking for services being connected.
    * Fix issue with GATT client connection creation.
    * Fix issue with OBEX and small file transfers.
    * Fix issue with handling pairing with Apple AirPods.
    * Fix issue with BAP and setting up broadcast source.
    * Fix issue with BAP and register all endpoints.
    * Fix issue with BAP and missing metadata property.
    * Fix issue with BAP and not handling out of order responses.
    * Fix issue with BAP and attempting to set device as
    connectable.
    * Add support for CCP plugin for call control profile.
    * Fix issue with BAP and handling stream IO linking.
    * Fix issue with BAP and setup of multiple streams per
    endpoint.
    * Fix issue with AVDTP and potential incorrect transaction
    label.
    * Fix issue with A2DP and handling crash on suspend.
    * Fix issue with GATT database and an invalid pointer.
    * Add support for AICS service.
  - drop bluez-test-2to3.diff, bluez-cups-libexec.patch:
    upstream has different solutions for ages, use those instead
  - drop fix-link-key-address-type.patch,
    fix-a2dp-suspend-crash.patch: upstream
  - add fix-a2dp-suspend-crash.patch (Issue #701 in upstream)

++++ libvirt:

  - Update to libvirt 10.6.0
  - jsc#PED-8909
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v10-6-0-2024-08-05

++++ libzypp:

  - single_rpmtrans: fix installation of .src.rpms (bsc#1228647)
  - version 17.35.9 (35)

++++ pcr-oracle:

  - Add support-ecc-srk.patch to support ECC SRK
  - Add fix-testcase-empty-efi-variables.patch to fix the testcase
    playback on empty EFI variables

++++ python-PyJWT:

  - Update to version 2.9.0
    * Drop support for Python 3.7 (EOL) by @hugovk in #910
    * Allow JWT issuer claim validation to accept a list of
    strings too by @mattpollak in #913
    * Fix unnecessary string concatenation by @sirosen in #904
    * Fix docs for ``jwt.decode_complete`` to include ``strict_aud``
    option by @woodruffw in #923
    * Fix docs step by @jpadilla in #950
    * Fix: Remove an unused variable from example code block
    by @kenkoooo in #958
    * Add support for Python 3.12 by @hugovk in #910
    * Improve performance of ``is_ssh_key`` + add unit test by @bdraco in #940
    * Allow ``jwt.decode()`` to accept a PyJWK object by @luhn in #886
    * Make ``algorithm_name`` attribute available on PyJWK by @luhn in #886
    * Raise ``InvalidKeyError`` on invalid PEM keys to be compatible
    with cryptography 42.x.x by @CollinEMac in #952
    * Raise an exception when required cryptography dependency
    is missing by @tobloef in #963

++++ python-libvirt-python:

  - Update to 10.6.0
  - Add all new APIs and constants in libvirt 10.6.0
  - jsc#PED-8909

++++ selinux-policy:

  - Update to version 20240604+git244.3664e356:
    * Dontaudit search of snapper grub plugin to nscd socket (bsc#1228745)
    * Fix labels for bind/named
    * Initial policy for ibft-rule-generator (bsc#1228402)
    * Initial policy for systemd-status-mail (bsc#1228402)
    * Label /usr/libexec/netconfig/ppp/ip-up pppd_initrc_exec_t (bsc#1228385)
    * Allow pppd to manage sysnet directories (bsc#1228385)
    * Allow snapper grub plugin to manage unlabeled_t and read link files

++++ sysuser-tools:

  - Implement UID:GID support for busybox
  - Reenable UID:GID support

------------------------------------------------------------------
------------------  2024-8-4  -  Aug 4 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - RDMA: Fix netdev tracker in ib_device_set_netdev (git-fixes)
  - commit 3130571
  - bnxt_re: Fix imm_data endianness (git-fixes)
  - commit 49ce7dd
  - RDMA/hns: Fix mbx timing out before CMD execution is completed (git-fixes)
  - commit 09de886
  - RDMA/hns: Fix insufficient extend DB for VFs. (git-fixes)
  - commit 9e511e1
  - RDMA/hns: Fix undifined behavior caused by invalid max_sge (git-fixes)
  - commit 75c8a8f
  - RDMA/hns: Fix shift-out-bounds when max_inline_data is 0 (git-fixes)
  - commit f76d2ac
  - RDMA/hns: Fix missing pagesize and alignment check in FRMR (git-fixes)
  - commit 3200c5d
  - RDMA/hns: Fix unmatch exception handling when init eq table fails (git-fixes)
  - commit 1c3f5bc
  - RDMA/hns: Fix soft lockup under heavy CEQE load (git-fixes)
  - commit bae3b01
  - RDMA/hns: Check atomic wr length (git-fixes)
  - commit 53b999f
  - RDMA/device: Return error earlier if port in not valid (git-fixes)
  - commit 1a6c9cf
  - RDMA/rxe: Don't set BTH_ACK_MASK for UC or UD QPs (git-fixes)
  - commit ecbc61e
  - RDMA/mlx4: Fix truncated output warning in alias_GUID.c (git-fixes)
  - commit 9a0a984
  - RDMA/mlx4: Fix truncated output warning in mad.c (git-fixes)
  - commit e923a91
  - RDMA/cache: Release GID table even if leak is detected (git-fixes)
  - commit e73316e
  - RDMA/mlx5: Set mkeys for dmabuf at PAGE_SIZE (git-fixes)
  - commit ee50dd0
  - RDMA/iwcm: Fix a use-after-free related to destroying CM IDs (git-fixes)
  - commit 6b71029
  - IB/core: Implement a limit on UMAD receive List (bsc#1228743 CVE-2024-42145)
  - commit 673df57
  - xfs: convert comma to semicolon (git-fixes).
  - commit 8f18daf
  - hfs: fix to initialize fields of hfs_inode_info after
    hfs_alloc_inode() (git-fixes).
  - commit 1aa4511
  - kABI workaround for sound core UMP conversion (stable-fixes).
  - commit b9e008a
  - ALSA: seq: ump: Explicitly reset RPN with Null RPN
    (stable-fixes).
  - ALSA: seq: ump: Transmit RPN/NRPN message at each MSB/LSB data
    reception (stable-fixes).
  - ALSA: seq: ump: Use the common RPN/bank conversion context
    (stable-fixes).
  - ALSA: ump: Explicitly reset RPN with Null RPN (stable-fixes).
  - ALSA: ump: Transmit RPN/NRPN message at each MSB/LSB data
    reception (stable-fixes).
  - commit 508da4c
  - kabi/severities: ignore kABI for FireWire sound local symbols (bsc#1208783)
  - commit 041506f
  - Drop doubly put References tags in sound patches
  - commit 92b6eba
  - Revert "ALSA: firewire-lib: operate for period elapse event
    in process context" (bsc#1208783).
  - commit 2045d7f
  - Revert "ALSA: firewire-lib: obsolete workqueue for period
    update" (bsc#1208783).
  - commit 09a87ea
  - spi: microchip-core: switch to use modern name (stable-fixes).
  - Refresh
    patches.suse/spi-microchip-core-defer-asserting-chip-select-until.patch.
  - commit 31d15b3
  - spi: microchip-core: fix init function not setting the master
    and motorola modes (git-fixes).
  - drm/amdgpu: reset vm state machine after gpu reset(vram lost)
    (stable-fixes).
  - drm/amd/display: Check for NULL pointer (stable-fixes).
  - drm/amdgpu/sdma5.2: Update wptr registers as well as doorbell
    (stable-fixes).
  - efi/libstub: Zero initialize heap allocated struct screen_info
    (git-fixes).
  - PCI: loongson: Enable MSI in LS7A Root Complex (stable-fixes).
  - dev/parport: fix the array out-of-bounds risk (stable-fixes).
  - clk: qcom: kpss-xcc: Return of_clk_add_hw_provider to transfer
    the error (git-fixes).
  - clk: qcom: Park shared RCGs upon registration (git-fixes).
  - clk: qcom: gpucc-sa8775p: Update wait_val fields for GPU GDSC's
    (git-fixes).
  - clk: qcom: gpucc-sa8775p: Park RCG's clk source at XO during
    disable (git-fixes).
  - clk: qcom: gpucc-sa8775p: Remove the CLK_IS_CRITICAL and
    ALWAYS_ON flags (git-fixes).
  - clk: qcom: gcc-sa8775p: Update the GDSC wait_val fields and
    flags (git-fixes).
  - clk: qcom: gpucc-sm8350: Park RCG's clk source at XO during
    disable (git-fixes).
  - clk: qcom: camcc-sc7280: Add parent dependency to all camera
    GDSCs (git-fixes).
  - clk: qcom: gcc-sc7280: Update force mem core bit for UFS ICE
    clock (git-fixes).
  - clk: en7523: fix rate divider for slic and spi clocks
    (git-fixes).
  - drm/etnaviv: don't block scheduler when GPU is still active
    (stable-fixes).
  - media: uvcvideo: Add quirk for invalid dev_sof in Logitech C920
    (git-fixes).
  - media: uvcvideo: Quirk for invalid dev_sof in Logitech C922
    (stable-fixes).
  - ata: libata-scsi: Honor the D_SENSE bit for CK_COND=1 and no
    error (stable-fixes).
  - ata: libata-scsi: Do not overwrite valid sense data when
    CK_COND=1 (stable-fixes).
  - Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x13d3:0x3591
    (stable-fixes).
  - Bluetooth: btusb: Add RTL8852BE device 0489:e125 to device
    tables (stable-fixes).
  - wifi: rtw88: usb: Fix disconnection after beacon loss
    (stable-fixes).
  - media: uvcvideo: Disable autosuspend for Insta360 Link
    (stable-fixes).
  - sbitmap: use READ_ONCE to access map->word (stable-fixes).
  - Bluetooth: Add device 13d3:3572 IMC Networks Bluetooth Radio
    (stable-fixes).
  - commit 5fabaee

++++ kernel-rt:

  - RDMA: Fix netdev tracker in ib_device_set_netdev (git-fixes)
  - commit 3130571
  - bnxt_re: Fix imm_data endianness (git-fixes)
  - commit 49ce7dd
  - RDMA/hns: Fix mbx timing out before CMD execution is completed (git-fixes)
  - commit 09de886
  - RDMA/hns: Fix insufficient extend DB for VFs. (git-fixes)
  - commit 9e511e1
  - RDMA/hns: Fix undifined behavior caused by invalid max_sge (git-fixes)
  - commit 75c8a8f
  - RDMA/hns: Fix shift-out-bounds when max_inline_data is 0 (git-fixes)
  - commit f76d2ac
  - RDMA/hns: Fix missing pagesize and alignment check in FRMR (git-fixes)
  - commit 3200c5d
  - RDMA/hns: Fix unmatch exception handling when init eq table fails (git-fixes)
  - commit 1c3f5bc
  - RDMA/hns: Fix soft lockup under heavy CEQE load (git-fixes)
  - commit bae3b01
  - RDMA/hns: Check atomic wr length (git-fixes)
  - commit 53b999f
  - RDMA/device: Return error earlier if port in not valid (git-fixes)
  - commit 1a6c9cf
  - RDMA/rxe: Don't set BTH_ACK_MASK for UC or UD QPs (git-fixes)
  - commit ecbc61e
  - RDMA/mlx4: Fix truncated output warning in alias_GUID.c (git-fixes)
  - commit 9a0a984
  - RDMA/mlx4: Fix truncated output warning in mad.c (git-fixes)
  - commit e923a91
  - RDMA/cache: Release GID table even if leak is detected (git-fixes)
  - commit e73316e
  - RDMA/mlx5: Set mkeys for dmabuf at PAGE_SIZE (git-fixes)
  - commit ee50dd0
  - RDMA/iwcm: Fix a use-after-free related to destroying CM IDs (git-fixes)
  - commit 6b71029
  - IB/core: Implement a limit on UMAD receive List (bsc#1228743 CVE-2024-42145)
  - commit 673df57
  - xfs: convert comma to semicolon (git-fixes).
  - commit 8f18daf
  - hfs: fix to initialize fields of hfs_inode_info after
    hfs_alloc_inode() (git-fixes).
  - commit 1aa4511
  - kABI workaround for sound core UMP conversion (stable-fixes).
  - commit b9e008a
  - ALSA: seq: ump: Explicitly reset RPN with Null RPN
    (stable-fixes).
  - ALSA: seq: ump: Transmit RPN/NRPN message at each MSB/LSB data
    reception (stable-fixes).
  - ALSA: seq: ump: Use the common RPN/bank conversion context
    (stable-fixes).
  - ALSA: ump: Explicitly reset RPN with Null RPN (stable-fixes).
  - ALSA: ump: Transmit RPN/NRPN message at each MSB/LSB data
    reception (stable-fixes).
  - commit 508da4c
  - kabi/severities: ignore kABI for FireWire sound local symbols (bsc#1208783)
  - commit 041506f
  - Drop doubly put References tags in sound patches
  - commit 92b6eba
  - Revert "ALSA: firewire-lib: operate for period elapse event
    in process context" (bsc#1208783).
  - commit 2045d7f
  - Revert "ALSA: firewire-lib: obsolete workqueue for period
    update" (bsc#1208783).
  - commit 09a87ea
  - spi: microchip-core: switch to use modern name (stable-fixes).
  - Refresh
    patches.suse/spi-microchip-core-defer-asserting-chip-select-until.patch.
  - commit 31d15b3
  - spi: microchip-core: fix init function not setting the master
    and motorola modes (git-fixes).
  - drm/amdgpu: reset vm state machine after gpu reset(vram lost)
    (stable-fixes).
  - drm/amd/display: Check for NULL pointer (stable-fixes).
  - drm/amdgpu/sdma5.2: Update wptr registers as well as doorbell
    (stable-fixes).
  - efi/libstub: Zero initialize heap allocated struct screen_info
    (git-fixes).
  - PCI: loongson: Enable MSI in LS7A Root Complex (stable-fixes).
  - dev/parport: fix the array out-of-bounds risk (stable-fixes).
  - clk: qcom: kpss-xcc: Return of_clk_add_hw_provider to transfer
    the error (git-fixes).
  - clk: qcom: Park shared RCGs upon registration (git-fixes).
  - clk: qcom: gpucc-sa8775p: Update wait_val fields for GPU GDSC's
    (git-fixes).
  - clk: qcom: gpucc-sa8775p: Park RCG's clk source at XO during
    disable (git-fixes).
  - clk: qcom: gpucc-sa8775p: Remove the CLK_IS_CRITICAL and
    ALWAYS_ON flags (git-fixes).
  - clk: qcom: gcc-sa8775p: Update the GDSC wait_val fields and
    flags (git-fixes).
  - clk: qcom: gpucc-sm8350: Park RCG's clk source at XO during
    disable (git-fixes).
  - clk: qcom: camcc-sc7280: Add parent dependency to all camera
    GDSCs (git-fixes).
  - clk: qcom: gcc-sc7280: Update force mem core bit for UFS ICE
    clock (git-fixes).
  - clk: en7523: fix rate divider for slic and spi clocks
    (git-fixes).
  - drm/etnaviv: don't block scheduler when GPU is still active
    (stable-fixes).
  - media: uvcvideo: Add quirk for invalid dev_sof in Logitech C920
    (git-fixes).
  - media: uvcvideo: Quirk for invalid dev_sof in Logitech C922
    (stable-fixes).
  - ata: libata-scsi: Honor the D_SENSE bit for CK_COND=1 and no
    error (stable-fixes).
  - ata: libata-scsi: Do not overwrite valid sense data when
    CK_COND=1 (stable-fixes).
  - Bluetooth: btusb: Add Realtek RTL8852BE support ID 0x13d3:0x3591
    (stable-fixes).
  - Bluetooth: btusb: Add RTL8852BE device 0489:e125 to device
    tables (stable-fixes).
  - wifi: rtw88: usb: Fix disconnection after beacon loss
    (stable-fixes).
  - media: uvcvideo: Disable autosuspend for Insta360 Link
    (stable-fixes).
  - sbitmap: use READ_ONCE to access map->word (stable-fixes).
  - Bluetooth: Add device 13d3:3572 IMC Networks Bluetooth Radio
    (stable-fixes).
  - commit 5fabaee

------------------------------------------------------------------
------------------  2024-8-3  -  Aug 3 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Update documentation
    kiwi no longer uses debootstrap

++++ kernel-default:

  - ALSA: hda/realtek: Add quirk for Acer Aspire E5-574G
    (stable-fixes).
  - commit ae4c81e
  - ALSA: hda: Conditionally use snooping for AMD HDMI (git-fixes).
  - ALSA: usb-audio: Correct surround channels in UAC1 channel map
    (git-fixes).
  - ALSA: seq: ump: Optimize conversions from SysEx to UMP
    (git-fixes).
  - ALSA: hda: conexant: Fix headset auto detect fail in the
    polling mode (git-fixes).
  - drm/vmwgfx: Fix overlay when using Screen Targets (git-fixes).
  - drm/vmwgfx: Fix a deadlock in dma buf fence polling (git-fixes).
  - drm/virtio: Fix type of dma-fence context variable (git-fixes).
  - drm/nouveau: prime: fix refcount underflow (git-fixes).
  - drm/i915: Fix possible int overflow in skl_ddi_calculate_wrpll()
    (git-fixes).
  - drm/i915/hdcp: Fix HDCP2_STREAM_STATUS macro (git-fixes).
  - i915/perf: Remove code to update PWR_CLK_STATE for gen12
    (git-fixes).
  - commit 581e0b5
  - ptp: fix integer overflow in max_vclocks_store (bsc#1227829
    CVE-2024-40994).
  - commit f2dc01f

++++ kernel-rt:

  - ALSA: hda/realtek: Add quirk for Acer Aspire E5-574G
    (stable-fixes).
  - commit ae4c81e
  - ALSA: hda: Conditionally use snooping for AMD HDMI (git-fixes).
  - ALSA: usb-audio: Correct surround channels in UAC1 channel map
    (git-fixes).
  - ALSA: seq: ump: Optimize conversions from SysEx to UMP
    (git-fixes).
  - ALSA: hda: conexant: Fix headset auto detect fail in the
    polling mode (git-fixes).
  - drm/vmwgfx: Fix overlay when using Screen Targets (git-fixes).
  - drm/vmwgfx: Fix a deadlock in dma buf fence polling (git-fixes).
  - drm/virtio: Fix type of dma-fence context variable (git-fixes).
  - drm/nouveau: prime: fix refcount underflow (git-fixes).
  - drm/i915: Fix possible int overflow in skl_ddi_calculate_wrpll()
    (git-fixes).
  - drm/i915/hdcp: Fix HDCP2_STREAM_STATUS macro (git-fixes).
  - i915/perf: Remove code to update PWR_CLK_STATE for gen12
    (git-fixes).
  - commit 581e0b5
  - ptp: fix integer overflow in max_vclocks_store (bsc#1227829
    CVE-2024-40994).
  - commit f2dc01f

++++ python-Pygments:

  - fix build by forcing pip to use the prebuilt CA bundle

++++ sysuser-tools:

  - Disable UID:GID support for now

------------------------------------------------------------------
------------------  2024-8-2  -  Aug 2 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix test_process_result_bundle_as_rpm
  - Fix Debian/Ubuntu integration tests
    Remove package hacks for debootstrap, explicitly add
    required packages and or configurations.
  - Drop types-pkg_resources
    Got removed from PyPI

++++ grub2:

  - Fix btrfs subvolume for platform modules not mounting at runtime when the
    default subvolume is the topmost root tree (bsc#1228124)
    * grub2-btrfs-06-subvol-mount.patch
  - Rediff
    * 0001-Unify-the-check-to-enable-btrfs-relative-path.patch
  - Switch to '--no-hostonly' when creating the ZIPL initrd in the
    KIWI build environment to avoid some potential issues due to the
    missing modules
    * grub2-s390x-set-hostonly.patch

++++ kernel-default:

  - Update
    patches.suse/79b5b4b18bc8-mlxsw-spectrum_acl_tcam-Fix-possible-use-after-free-.patch
    (CVE-2024-35854 bsc#1224636 CVE-2024-35855 bsc#1224694).
  - Update
    patches.suse/ACPICA-Revert-ACPICA-avoid-Info-mapping-multiple-BAR.patch
    (git-fixes CVE-2024-40984 bsc#1227820).
  - Update
    patches.suse/ALSA-hda-cs35l41-Possible-null-pointer-dereference-i.patch
    (git-fixes CVE-2024-40964 bsc#1227818).
  - Update
    patches.suse/ALSA-hda-cs35l56-Fix-lifetime-of-cs_dsp-instance.patch
    (git-fixes CVE-2024-39491 bsc#1227627).
  - Update
    patches.suse/Bluetooth-hci_core-Fix-possible-buffer-overflow.patch
    (git-fixes CVE-2024-26889 bsc#1228195).
  - Update
    patches.suse/HID-core-remove-unnecessary-WARN_ON-in-implement.patch
    (git-fixes CVE-2024-39509 bsc#1227733).
  - Update
    patches.suse/HID-logitech-dj-Fix-memory-leak-in-logi_dj_recv_swit.patch
    (git-fixes CVE-2024-40934 bsc#1227796).
  - Update
    patches.suse/KVM-SVM-WARN-on-vNMI-NMI-window-iff-NMIs-are-outrigh.patch
    (git-fixes CVE-2024-39483 bsc#1227494).
  - Update
    patches.suse/KVM-arm64-Fix-circular-locking-dependency.patch
    (bsc#1222463 (CVE-2024-26691) CVE-2024-26691).
  - Update
    patches.suse/RDMA-mlx5-Add-check-for-srq-max_sge-attribute.patch
    (git-fixes CVE-2024-40990 bsc#1227824).
  - Update
    patches.suse/RDMA-rxe-Fix-responder-length-checking-for-UD-reques.patch
    (git-fixes CVE-2024-40992 bsc#1227826).
  - Update
    patches.suse/SUNRPC-Fix-loop-termination-condition-in-gss_free_in.patch
    (git-fixes CVE-2024-36288 bsc#1226834).
  - Update
    patches.suse/USB-class-cdc-wdm-Fix-CPU-lockup-caused-by-excessive.patch
    (git-fixes CVE-2024-40904 bsc#1227772).
  - Update
    patches.suse/arm64-asm-bug-Add-.align-2-to-the-end-of-__BUG_ENTRY.patch
    (git-fixes CVE-2024-39488 bsc#1227618).
  - Update
    patches.suse/ata-libata-core-Fix-double-free-on-error.patch
    (git-fixes CVE-2024-41087 bsc#1228740).
  - Update
    patches.suse/ax25-Fix-refcount-imbalance-on-inbound-connections.patch
    (git-fixes CVE-2024-40910 bsc#1227832).
  - Update
    patches.suse/batman-adv-bypass-empty-buckets-in-batadv_purge_orig.patch
    (stable-fixes CVE-2024-40981 bsc#1227864).
  - Update
    patches.suse/btrfs-zoned-allocate-dummy-checksums-for-zoned-NODAT.patch
    (bsc#1223731 CVE-2024-26944 CVE-2024-40962 bsc#1227815).
  - Update
    patches.suse/cachefiles-remove-requests-from-xarray-during-flushin.patch
    (bsc#1226588 CVE-2024-40900 bsc#1227760).
  - Update
    patches.suse/cpufreq-amd-pstate-fix-memory-leak-on-CPU-EPP-exit.patch
    (stable-fixes CVE-2024-40997 bsc#1227853).
  - Update
    patches.suse/crypto-hisilicon-sec-Fix-memory-leak-for-sec-resourc.patch
    (stable-fixes CVE-2024-41002 bsc#1227870).
  - Update
    patches.suse/crypto-qat-Fix-ADF_DEV_RESET_SYNC-memory-leak.patch
    (git-fixes CVE-2024-39493 bsc#1227620).
  - Update
    patches.suse/cxl-region-Fix-memregion-leaks-in-devm_cxl_add_regio.patch
    (git-fixes CVE-2024-40936 bsc#1227833).
  - Update
    patches.suse/drivers-core-synchronize-really_probe-and-dev_uevent.patch
    (git-fixes CVE-2024-39501 bsc#1227754).
  - Update
    patches.suse/drm-amdgpu-fix-UBSAN-warning-in-kv_dpm.c.patch
    (stable-fixes CVE-2024-40987 bsc#1228235).
  - Update
    patches.suse/drm-amdkfd-don-t-allow-mapping-the-MMIO-HDP-page-wit.patch
    (CVE-2024-41011 bsc#1228115 git-fixes bsc#1228114).
  - Update
    patches.suse/drm-bridge-cdns-mhdp8546-Fix-possible-null-pointer-d.patch
    (git-fixes CVE-2024-38548 bsc#1228202).
  - Update patches.suse/drm-drm_file-Fix-pid-refcounting-race.patch
    (git-fixes CVE-2024-39486 bsc#1227492).
  - Update
    patches.suse/drm-exynos-hdmi-report-safe-640x480-mode-as-a-fallba.patch
    (git-fixes CVE-2024-40916 bsc#1227846).
  - Update
    patches.suse/drm-exynos-vidi-fix-memory-leak-in-.get_modes.patch
    (stable-fixes CVE-2024-40932 bsc#1227828).
  - Update
    patches.suse/drm-i915-dpt-Make-DPT-object-unshrinkable.patch
    (git-fixes CVE-2024-40924 bsc#1227787).
  - Update
    patches.suse/drm-komeda-check-for-error-valued-pointer.patch
    (git-fixes CVE-2024-39505 bsc#1227728).
  - Update
    patches.suse/drm-lima-mask-irqs-in-timeout-path-before-hard-reset.patch
    (stable-fixes CVE-2024-40976 bsc#1227893).
  - Update
    patches.suse/drm-nouveau-don-t-attempt-to-schedule-hpd_work-on-he.patch
    (git-fixes CVE-2024-40926 bsc#1227791).
  - Update
    patches.suse/drm-radeon-fix-UBSAN-warning-in-kv_dpm.c.patch
    (stable-fixes CVE-2024-40988 bsc#1227957).
  - Update
    patches.suse/drm-shmem-helper-Fix-BUG_ON-on-mmap-PROT_WRITE-MAP_P.patch
    (git-fixes CVE-2024-39497 bsc#1227722).
  - Update
    patches.suse/io_uring-io-wq-Use-set_bit-and-test_bit-at-worker-fl.patch
    (git-fixes CVE-2024-39508 bsc#1227732).
  - Update
    patches.suse/io_uring-rsrc-don-t-lock-while-TASK_RUNNING.patch
    (git-fixes CVE-2024-40922 bsc#1227785).
  - Update
    patches.suse/io_uring-sqpoll-work-around-a-potential-audit-memory.patch
    (git-fixes CVE-2024-41001 bsc#1227869).
  - Update
    patches.suse/iommu-Return-right-value-in-iommu_sva_bind_device.patch
    (git-fixes CVE-2024-40945 bsc#1227802).
  - Update
    patches.suse/jfs-xattr-fix-buffer-overflow-for-invalid-xattr.patch
    (bsc#1227383 CVE-2024-40902 bsc#1227764).
  - Update
    patches.suse/mmc-davinci-Don-t-strip-remove-function-when-driver-.patch
    (git-fixes CVE-2024-39484 bsc#1227493).
  - Update
    patches.suse/nfs-Handle-error-of-rpc_proc_register-in-nfs_net_ini.patch
    (git-fixes CVE-2024-36939 bsc#1225838).
  - Update
    patches.suse/ocfs2-fix-races-between-hole-punching-and-AIO-DIO.patch
    (git-fixes CVE-2024-40943 bsc#1227849).
  - Update
    patches.suse/serial-imx-Introduce-timeout-when-waiting-on-transmi.patch
    (stable-fixes CVE-2024-40967 bsc#1227891).
  - Update
    patches.suse/sock_map-avoid-race-between-sock_map_close-and-sk_ps.patch
    (bsc#1225475 CVE-2023-52735 CVE-2024-39500 bsc#1227724).
  - Update
    patches.suse/ssb-Fix-potential-NULL-pointer-dereference-in-ssb_de.patch
    (stable-fixes CVE-2024-40982 bsc#1227865).
  - Update
    patches.suse/tracing-Build-event-generation-tests-only-as-modules.patch
    (git-fixes CVE-2024-41004 bsc#1227851).
  - Update
    patches.suse/tracing-trigger-Fix-to-return-error-if-failed-to-alloc-snapshot.patch
    (git-fixes CVE-2024-26920 bsc#1228237).
  - Update
    patches.suse/usb-typec-tcpm-fix-use-after-free-case-in-tcpm_regis.patch
    (git-fixes CVE-2024-40903 bsc#1227766).
  - Update
    patches.suse/vmci-prevent-speculation-leaks-by-sanitizing-event-i.patch
    (git-fixes CVE-2024-39499 bsc#1227725).
  - Update
    patches.suse/wifi-ath11k-rely-on-mac80211-debugfs-handling-for-vi.patch
    (bsc#1227149 CVE-2024-26637 bsc#1221652).
  - Update
    patches.suse/wifi-cfg80211-Lock-wiphy-in-cfg80211_get_station.patch
    (git-fixes CVE-2024-40911 bsc#1227792).
  - Update
    patches.suse/wifi-cfg80211-detect-stuck-ECSA-element-in-probe-res.patch
    (bsc#1227149 CVE-2024-26683 bsc#1222434).
  - Update
    patches.suse/wifi-cfg80211-validate-HE-operation-element-parsing.patch
    (bsc#1227149 CVE-2024-40930 bsc#1228236).
  - Update patches.suse/wifi-iwlwifi-Use-request_module_nowait.patch
    (bsc#1227149 CVE-2024-36970 bsc#1226127).
  - Update
    patches.suse/wifi-iwlwifi-mvm-check-n_ssids-before-accessing-the-.patch
    (git-fixes CVE-2024-40929 bsc#1227774).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-read-past-the-mfuart-notifcat.patch
    (git-fixes CVE-2024-40941 bsc#1227771).
  - Update
    patches.suse/wifi-iwlwifi-mvm-pick-the-version-of-SESSION_PROTECT.patch
    (bsc#1227149 CVE-2024-35913 bsc#1224485).
  - Update
    patches.suse/wifi-mac80211-Fix-deadlock-in-ieee80211_sta_ps_deliv.patch
    (git-fixes CVE-2024-40912 bsc#1227790).
  - Update
    patches.suse/wifi-mac80211-improve-CSA-ECSA-connection-refusal.patch
    (bsc#1227149 CVE-2024-26682 bsc#1222433).
  - Update
    patches.suse/wifi-mac80211-mesh-Fix-leak-of-mesh_preq_queue-objec.patch
    (git-fixes CVE-2024-40942 bsc#1227770).
  - Update
    patches.suse/wifi-mt76-connac-check-for-null-before-dereferencing.patch
    (bsc#1227149 CVE-2024-38609 bsc#1226751).
  - Update
    patches.suse/wifi-mt76-mt7921s-fix-potential-hung-tasks-during-ch.patch
    (stable-fixes CVE-2024-40977 bsc#1227950).
  - Update
    patches.suse/wifi-mt76-mt7925e-fix-use-after-free-in-free_irq.patch
    (bsc#1227149 CVE-2024-27049 bsc#1223763).
  - Update
    patches.suse/wifi-mt76-mt7996-fix-potential-memory-leakage-when-r.patch
    (bsc#1227149 CVE-2024-38563 bsc#1226743).
  - Update
    patches.suse/x86-kexec-Fix-bug-with-call-depth-tracking.patch
    (git-fixes CVE-2024-40944 bsc#1227883).
  - Update
    patches.suse/xhci-Handle-TD-clearing-for-multiple-streams-case.patch
    (git-fixes CVE-2024-40927 bsc#1227816).
  - commit 2cd72fd
  - Update
    patches.suse/SUNRPC-Fix-UAF-in-svc_tcp_listen_data_ready.patch
    (bsc#1012628 CVE-2023-52885 bsc#1227750).
  - Update
    patches.suse/USB-core-Fix-race-by-not-overwriting-udev-descriptor.patch
    (bsc#1213123 CVE-2023-37453 CVE-2023-52886 bsc#1227981).
  - Update
    patches.suse/btrfs-zoned-fix-lock-ordering-in-btrfs_zone_activate.patch
    (bsc#1223731 CVE-2024-26944 CVE-2023-52668 bsc#1224690).
  - Update
    patches.suse/wifi-ath12k-fix-the-error-handler-of-rfkill-config.patch
    (bsc#1227149 CVE-2023-52688 bsc#1224631).
  - commit 0637df8
  - scsi: qedf: Make qedf_execute_tmf() non-preemptible (CVE-2024-42124 bsc#1228705)
  - commit a8638c5
  - x86: stop playing stack games in profile_pc() (bsc#1228633
    CVE-2024-42096).
  - commit 5c85064
  - net: dsa: mv88e6xxx: Correct check for empty list (CVE-2024-42224 bsc#1228723)
  - commit 48e8710
  - skmsg: Skip zero length skb in sk_msg_recvmsg (CVE-2024-41048 bsc#1228565)
  - commit 1a6942b
  - netns: Make get_net_ns() handle zero refcount net
    (CVE-2024-40958 bsc#1227812).
  - commit f6c7d72
  - nvme_core: scan namespaces asynchronously (bsc#1224105).
  - commit e6f41be
  - net: wwan: iosm: Fix tainted pointer delete is case of region
    creation fail (CVE-2024-40939 bsc#1227799).
  - commit 0b93a9f
  - nsh: Restore skb->{protocol,data,mac_header} for outer header
    in nsh_gso_segment() (CVE-2024-36933 bsc#1225832).
  - commit 6740d82
  - net: core: reject skb_copy(_expand) for fraglist GSO skbs
    (CVE-2024-36929 bsc#1225814).
  - commit e49ed10
  - cgroup/cpuset: Prevent UAF in proc_cpuset_show() (bsc#1228801).
  - commit 8707a09
  - Drop MD patches that caused dependency cycles
    Also the patch was placed in a wrong directory.
    Deleted:
    patches.kabi/0002-md-cluster-fix-no-recovery-job-when-adding-re-adding.patch
    patches.suse/0001-md-cluster-fix-hanging-issue-while-a-new-disk-adding.patch
  - commit f696a5b
  - net: phy: micrel: Fix the KSZ9131 MDI-X status issue
    (git-fixes).
  - Bluetooth: hci_sync: Fix suspending with wrong filter policy
    (git-fixes).
  - Bluetooth: btintel: Fail setup on error (git-fixes).
  - wifi: ath12k: fix soft lockup on suspend (git-fixes).
  - wifi: cfg80211: fix reporting failed MLO links status with
    cfg80211_connect_done (git-fixes).
  - wifi: mac80211: use monitor sdata with driver only if desired
    (git-fixes).
  - net: phy: realtek: add support for RTL8366S Gigabit PHY
    (git-fixes).
  - net: usb: sr9700: fix uninitialized variable use in sr_mdio_read
    (git-fixes).
  - commit f33a0c2
  - ppp: reject claimed-as-LCP but actually malformed packets
    (CVE-2024-41044 bsc#1228530).
  - ibmvnic: Add tx check to prevent skb leak (CVE-2024-41066
    bsc#1228640).
  - net/dpaa2: Avoid explicit cpumask var allocation on stack
    (CVE-2024-42093 bsc#1228680).
  - commit 960e23f
  - drm/amd/display: Add NULL pointer check for kzalloc (bsc#1228591 CVE-2024-42122)
  - commit 22c79c5

++++ kernel-rt:

  - Update
    patches.suse/79b5b4b18bc8-mlxsw-spectrum_acl_tcam-Fix-possible-use-after-free-.patch
    (CVE-2024-35854 bsc#1224636 CVE-2024-35855 bsc#1224694).
  - Update
    patches.suse/ACPICA-Revert-ACPICA-avoid-Info-mapping-multiple-BAR.patch
    (git-fixes CVE-2024-40984 bsc#1227820).
  - Update
    patches.suse/ALSA-hda-cs35l41-Possible-null-pointer-dereference-i.patch
    (git-fixes CVE-2024-40964 bsc#1227818).
  - Update
    patches.suse/ALSA-hda-cs35l56-Fix-lifetime-of-cs_dsp-instance.patch
    (git-fixes CVE-2024-39491 bsc#1227627).
  - Update
    patches.suse/Bluetooth-hci_core-Fix-possible-buffer-overflow.patch
    (git-fixes CVE-2024-26889 bsc#1228195).
  - Update
    patches.suse/HID-core-remove-unnecessary-WARN_ON-in-implement.patch
    (git-fixes CVE-2024-39509 bsc#1227733).
  - Update
    patches.suse/HID-logitech-dj-Fix-memory-leak-in-logi_dj_recv_swit.patch
    (git-fixes CVE-2024-40934 bsc#1227796).
  - Update
    patches.suse/KVM-SVM-WARN-on-vNMI-NMI-window-iff-NMIs-are-outrigh.patch
    (git-fixes CVE-2024-39483 bsc#1227494).
  - Update
    patches.suse/KVM-arm64-Fix-circular-locking-dependency.patch
    (bsc#1222463 (CVE-2024-26691) CVE-2024-26691).
  - Update
    patches.suse/RDMA-mlx5-Add-check-for-srq-max_sge-attribute.patch
    (git-fixes CVE-2024-40990 bsc#1227824).
  - Update
    patches.suse/RDMA-rxe-Fix-responder-length-checking-for-UD-reques.patch
    (git-fixes CVE-2024-40992 bsc#1227826).
  - Update
    patches.suse/SUNRPC-Fix-loop-termination-condition-in-gss_free_in.patch
    (git-fixes CVE-2024-36288 bsc#1226834).
  - Update
    patches.suse/USB-class-cdc-wdm-Fix-CPU-lockup-caused-by-excessive.patch
    (git-fixes CVE-2024-40904 bsc#1227772).
  - Update
    patches.suse/arm64-asm-bug-Add-.align-2-to-the-end-of-__BUG_ENTRY.patch
    (git-fixes CVE-2024-39488 bsc#1227618).
  - Update
    patches.suse/ata-libata-core-Fix-double-free-on-error.patch
    (git-fixes CVE-2024-41087 bsc#1228740).
  - Update
    patches.suse/ax25-Fix-refcount-imbalance-on-inbound-connections.patch
    (git-fixes CVE-2024-40910 bsc#1227832).
  - Update
    patches.suse/batman-adv-bypass-empty-buckets-in-batadv_purge_orig.patch
    (stable-fixes CVE-2024-40981 bsc#1227864).
  - Update
    patches.suse/btrfs-zoned-allocate-dummy-checksums-for-zoned-NODAT.patch
    (bsc#1223731 CVE-2024-26944 CVE-2024-40962 bsc#1227815).
  - Update
    patches.suse/cachefiles-remove-requests-from-xarray-during-flushin.patch
    (bsc#1226588 CVE-2024-40900 bsc#1227760).
  - Update
    patches.suse/cpufreq-amd-pstate-fix-memory-leak-on-CPU-EPP-exit.patch
    (stable-fixes CVE-2024-40997 bsc#1227853).
  - Update
    patches.suse/crypto-hisilicon-sec-Fix-memory-leak-for-sec-resourc.patch
    (stable-fixes CVE-2024-41002 bsc#1227870).
  - Update
    patches.suse/crypto-qat-Fix-ADF_DEV_RESET_SYNC-memory-leak.patch
    (git-fixes CVE-2024-39493 bsc#1227620).
  - Update
    patches.suse/cxl-region-Fix-memregion-leaks-in-devm_cxl_add_regio.patch
    (git-fixes CVE-2024-40936 bsc#1227833).
  - Update
    patches.suse/drivers-core-synchronize-really_probe-and-dev_uevent.patch
    (git-fixes CVE-2024-39501 bsc#1227754).
  - Update
    patches.suse/drm-amdgpu-fix-UBSAN-warning-in-kv_dpm.c.patch
    (stable-fixes CVE-2024-40987 bsc#1228235).
  - Update
    patches.suse/drm-amdkfd-don-t-allow-mapping-the-MMIO-HDP-page-wit.patch
    (CVE-2024-41011 bsc#1228115 git-fixes bsc#1228114).
  - Update
    patches.suse/drm-bridge-cdns-mhdp8546-Fix-possible-null-pointer-d.patch
    (git-fixes CVE-2024-38548 bsc#1228202).
  - Update patches.suse/drm-drm_file-Fix-pid-refcounting-race.patch
    (git-fixes CVE-2024-39486 bsc#1227492).
  - Update
    patches.suse/drm-exynos-hdmi-report-safe-640x480-mode-as-a-fallba.patch
    (git-fixes CVE-2024-40916 bsc#1227846).
  - Update
    patches.suse/drm-exynos-vidi-fix-memory-leak-in-.get_modes.patch
    (stable-fixes CVE-2024-40932 bsc#1227828).
  - Update
    patches.suse/drm-i915-dpt-Make-DPT-object-unshrinkable.patch
    (git-fixes CVE-2024-40924 bsc#1227787).
  - Update
    patches.suse/drm-komeda-check-for-error-valued-pointer.patch
    (git-fixes CVE-2024-39505 bsc#1227728).
  - Update
    patches.suse/drm-lima-mask-irqs-in-timeout-path-before-hard-reset.patch
    (stable-fixes CVE-2024-40976 bsc#1227893).
  - Update
    patches.suse/drm-nouveau-don-t-attempt-to-schedule-hpd_work-on-he.patch
    (git-fixes CVE-2024-40926 bsc#1227791).
  - Update
    patches.suse/drm-radeon-fix-UBSAN-warning-in-kv_dpm.c.patch
    (stable-fixes CVE-2024-40988 bsc#1227957).
  - Update
    patches.suse/drm-shmem-helper-Fix-BUG_ON-on-mmap-PROT_WRITE-MAP_P.patch
    (git-fixes CVE-2024-39497 bsc#1227722).
  - Update
    patches.suse/io_uring-io-wq-Use-set_bit-and-test_bit-at-worker-fl.patch
    (git-fixes CVE-2024-39508 bsc#1227732).
  - Update
    patches.suse/io_uring-rsrc-don-t-lock-while-TASK_RUNNING.patch
    (git-fixes CVE-2024-40922 bsc#1227785).
  - Update
    patches.suse/io_uring-sqpoll-work-around-a-potential-audit-memory.patch
    (git-fixes CVE-2024-41001 bsc#1227869).
  - Update
    patches.suse/iommu-Return-right-value-in-iommu_sva_bind_device.patch
    (git-fixes CVE-2024-40945 bsc#1227802).
  - Update
    patches.suse/jfs-xattr-fix-buffer-overflow-for-invalid-xattr.patch
    (bsc#1227383 CVE-2024-40902 bsc#1227764).
  - Update
    patches.suse/mmc-davinci-Don-t-strip-remove-function-when-driver-.patch
    (git-fixes CVE-2024-39484 bsc#1227493).
  - Update
    patches.suse/nfs-Handle-error-of-rpc_proc_register-in-nfs_net_ini.patch
    (git-fixes CVE-2024-36939 bsc#1225838).
  - Update
    patches.suse/ocfs2-fix-races-between-hole-punching-and-AIO-DIO.patch
    (git-fixes CVE-2024-40943 bsc#1227849).
  - Update
    patches.suse/serial-imx-Introduce-timeout-when-waiting-on-transmi.patch
    (stable-fixes CVE-2024-40967 bsc#1227891).
  - Update
    patches.suse/sock_map-avoid-race-between-sock_map_close-and-sk_ps.patch
    (bsc#1225475 CVE-2023-52735 CVE-2024-39500 bsc#1227724).
  - Update
    patches.suse/ssb-Fix-potential-NULL-pointer-dereference-in-ssb_de.patch
    (stable-fixes CVE-2024-40982 bsc#1227865).
  - Update
    patches.suse/tracing-Build-event-generation-tests-only-as-modules.patch
    (git-fixes CVE-2024-41004 bsc#1227851).
  - Update
    patches.suse/tracing-trigger-Fix-to-return-error-if-failed-to-alloc-snapshot.patch
    (git-fixes CVE-2024-26920 bsc#1228237).
  - Update
    patches.suse/usb-typec-tcpm-fix-use-after-free-case-in-tcpm_regis.patch
    (git-fixes CVE-2024-40903 bsc#1227766).
  - Update
    patches.suse/vmci-prevent-speculation-leaks-by-sanitizing-event-i.patch
    (git-fixes CVE-2024-39499 bsc#1227725).
  - Update
    patches.suse/wifi-ath11k-rely-on-mac80211-debugfs-handling-for-vi.patch
    (bsc#1227149 CVE-2024-26637 bsc#1221652).
  - Update
    patches.suse/wifi-cfg80211-Lock-wiphy-in-cfg80211_get_station.patch
    (git-fixes CVE-2024-40911 bsc#1227792).
  - Update
    patches.suse/wifi-cfg80211-detect-stuck-ECSA-element-in-probe-res.patch
    (bsc#1227149 CVE-2024-26683 bsc#1222434).
  - Update
    patches.suse/wifi-cfg80211-validate-HE-operation-element-parsing.patch
    (bsc#1227149 CVE-2024-40930 bsc#1228236).
  - Update patches.suse/wifi-iwlwifi-Use-request_module_nowait.patch
    (bsc#1227149 CVE-2024-36970 bsc#1226127).
  - Update
    patches.suse/wifi-iwlwifi-mvm-check-n_ssids-before-accessing-the-.patch
    (git-fixes CVE-2024-40929 bsc#1227774).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-read-past-the-mfuart-notifcat.patch
    (git-fixes CVE-2024-40941 bsc#1227771).
  - Update
    patches.suse/wifi-iwlwifi-mvm-pick-the-version-of-SESSION_PROTECT.patch
    (bsc#1227149 CVE-2024-35913 bsc#1224485).
  - Update
    patches.suse/wifi-mac80211-Fix-deadlock-in-ieee80211_sta_ps_deliv.patch
    (git-fixes CVE-2024-40912 bsc#1227790).
  - Update
    patches.suse/wifi-mac80211-improve-CSA-ECSA-connection-refusal.patch
    (bsc#1227149 CVE-2024-26682 bsc#1222433).
  - Update
    patches.suse/wifi-mac80211-mesh-Fix-leak-of-mesh_preq_queue-objec.patch
    (git-fixes CVE-2024-40942 bsc#1227770).
  - Update
    patches.suse/wifi-mt76-connac-check-for-null-before-dereferencing.patch
    (bsc#1227149 CVE-2024-38609 bsc#1226751).
  - Update
    patches.suse/wifi-mt76-mt7921s-fix-potential-hung-tasks-during-ch.patch
    (stable-fixes CVE-2024-40977 bsc#1227950).
  - Update
    patches.suse/wifi-mt76-mt7925e-fix-use-after-free-in-free_irq.patch
    (bsc#1227149 CVE-2024-27049 bsc#1223763).
  - Update
    patches.suse/wifi-mt76-mt7996-fix-potential-memory-leakage-when-r.patch
    (bsc#1227149 CVE-2024-38563 bsc#1226743).
  - Update
    patches.suse/x86-kexec-Fix-bug-with-call-depth-tracking.patch
    (git-fixes CVE-2024-40944 bsc#1227883).
  - Update
    patches.suse/xhci-Handle-TD-clearing-for-multiple-streams-case.patch
    (git-fixes CVE-2024-40927 bsc#1227816).
  - commit 2cd72fd
  - Update
    patches.suse/SUNRPC-Fix-UAF-in-svc_tcp_listen_data_ready.patch
    (bsc#1012628 CVE-2023-52885 bsc#1227750).
  - Update
    patches.suse/USB-core-Fix-race-by-not-overwriting-udev-descriptor.patch
    (bsc#1213123 CVE-2023-37453 CVE-2023-52886 bsc#1227981).
  - Update
    patches.suse/btrfs-zoned-fix-lock-ordering-in-btrfs_zone_activate.patch
    (bsc#1223731 CVE-2024-26944 CVE-2023-52668 bsc#1224690).
  - Update
    patches.suse/wifi-ath12k-fix-the-error-handler-of-rfkill-config.patch
    (bsc#1227149 CVE-2023-52688 bsc#1224631).
  - commit 0637df8
  - scsi: qedf: Make qedf_execute_tmf() non-preemptible (CVE-2024-42124 bsc#1228705)
  - commit a8638c5
  - x86: stop playing stack games in profile_pc() (bsc#1228633
    CVE-2024-42096).
  - commit 5c85064
  - net: dsa: mv88e6xxx: Correct check for empty list (CVE-2024-42224 bsc#1228723)
  - commit 48e8710
  - skmsg: Skip zero length skb in sk_msg_recvmsg (CVE-2024-41048 bsc#1228565)
  - commit 1a6942b
  - netns: Make get_net_ns() handle zero refcount net
    (CVE-2024-40958 bsc#1227812).
  - commit f6c7d72
  - nvme_core: scan namespaces asynchronously (bsc#1224105).
  - commit e6f41be
  - net: wwan: iosm: Fix tainted pointer delete is case of region
    creation fail (CVE-2024-40939 bsc#1227799).
  - commit 0b93a9f
  - nsh: Restore skb->{protocol,data,mac_header} for outer header
    in nsh_gso_segment() (CVE-2024-36933 bsc#1225832).
  - commit 6740d82
  - net: core: reject skb_copy(_expand) for fraglist GSO skbs
    (CVE-2024-36929 bsc#1225814).
  - commit e49ed10
  - cgroup/cpuset: Prevent UAF in proc_cpuset_show() (bsc#1228801).
  - commit 8707a09
  - Drop MD patches that caused dependency cycles
    Also the patch was placed in a wrong directory.
    Deleted:
    patches.kabi/0002-md-cluster-fix-no-recovery-job-when-adding-re-adding.patch
    patches.suse/0001-md-cluster-fix-hanging-issue-while-a-new-disk-adding.patch
  - commit f696a5b
  - net: phy: micrel: Fix the KSZ9131 MDI-X status issue
    (git-fixes).
  - Bluetooth: hci_sync: Fix suspending with wrong filter policy
    (git-fixes).
  - Bluetooth: btintel: Fail setup on error (git-fixes).
  - wifi: ath12k: fix soft lockup on suspend (git-fixes).
  - wifi: cfg80211: fix reporting failed MLO links status with
    cfg80211_connect_done (git-fixes).
  - wifi: mac80211: use monitor sdata with driver only if desired
    (git-fixes).
  - net: phy: realtek: add support for RTL8366S Gigabit PHY
    (git-fixes).
  - net: usb: sr9700: fix uninitialized variable use in sr_mdio_read
    (git-fixes).
  - commit f33a0c2
  - ppp: reject claimed-as-LCP but actually malformed packets
    (CVE-2024-41044 bsc#1228530).
  - ibmvnic: Add tx check to prevent skb leak (CVE-2024-41066
    bsc#1228640).
  - net/dpaa2: Avoid explicit cpumask var allocation on stack
    (CVE-2024-42093 bsc#1228680).
  - commit 960e23f
  - drm/amd/display: Add NULL pointer check for kzalloc (bsc#1228591 CVE-2024-42122)
  - commit 22c79c5

++++ mozilla-nss:

  - Updated nss-fips-approved-crypto-non-ec.patch to enforce
    approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113).

++++ libnvme:

  - Update to version 1.10:
    * linux: update TLS version 1 PSK derivation (bsc#1228376)
    * tree: fix nvme_read_config() to not set errno if return 0
    * types: add new fields added in TP4165 (bsc#1231668)
    * types: Changed the space into tap space (bsc#1231668)
    * tree: handle no address phy slot dirs (bsc#1229193)
    * linux: Remove the use of OpenSSL Engine API
    * types: Added new controller attribute as per TP4104
    * tree: add helper to lookup hostnqn/hostid (bsc#1226216)
    * fabrics: extend hostnqn/hostid variable inject interface (bsc#1226216)
    * json: filter out pcie transport (bsc#1226216)
    * tree: preserve parsing order of a config file (bsc#1226216)
    * types: add new field added in TP4099
    * types: add new field added in TP4090 (bsc#1231668)
    * linux: add nvme_revoke_tls_key (bsc#1226197)
    * tree: fix segfault in nvme_free_tree() (bsc#1231668)
    * types: add PEL vendor specific and TCG defined events definitions
    * mi-mctp: initialize the rc variable in handle_mctp_endpoint()
    * linux: avoid potential null pointer dereference
    * linux: add nvme_get_ana_log_len_from_id_ctrl()
    * libnvme: export nvme_mi_admin_get_ana_log_atomic()
    * ioctl: add support for atomic, piecewise ANA log fetch
    * ioctl: replace nvme_ana_rsp_hdr in doc comments
    * ioctl: respect rae in nvme_get_log_ana()
    * ioctl: fix nvme_get_log_ana_groups() pointer type
    * types: add new filed added in TP4141a
    * mi: Probe quirks on first command submission
    * tree: optionally skip namespaces during scanning
    * ioctl: update nvme_set_var_size_tags() to properly use reftag
    * types: add enum for Protection Information Format
    * libnvme: Introduce functions to generate host identifier and host NQN (bsc#1226216)
    * fabrics: Unescape URI elements
    * tests: Add uriparser tests
    * fabrics: Introduce simple URI parser
    * linux: default init cleanup variable
    * linux: Fix uninitialized variables
    * types: add the nvme Cancel command opcode
    * log: split log variables from root object
    * log: keep log level logic in one place
    * mi: restore default ep timeout during admin_passthru
    * mi: fix the rc for nvme_mi_scan_ep
    * ccan/endian.h: Only define __{BIG,LITTLE}_ENDIAN if undefined.
    * Use C99 types for uint32_t
    * mi: fix the return error code.

++++ systemd:

  - Order the update of udev and systemd-boot right after systemd (bsc#1228659)

++++ libzypp:

  - Make sure not to statically linked installed tools (bsc#1228787)
  - version 17.35.8 (35)

++++ nvme-cli:

  - Update to version 2.10:
    * sed: Fix parsing of Discovery0 features
    * fabrics: avoid potential segfault in nvmf_dim() (bsc#1231668)
    * nvme: avoid segfault in show-topology (bsc#1226197)
    * fabrics: do not leak nvme_ctrl_t object on connect
    * nvme: extend help message when mmap regs fails
    * nvme: return -ENXIO value to open device if errno not set
    * wdc: OCP 2.5 Log Page Updates
    * fabrics: drop --quiet alias -S
    * fabrics: drop --disable-sqflow alias -d
    * fabrics: check if json config is existing (bsc#1231668)
    * plugins/ocp: fix UAF when printing telemetry log
    * nvme-print-stdout: fix persistent-event-log set feature event output
    * fabrics: do not report error when no modules are loaded when disconnecting
    * fabrics: use cleanup helper where possible
    * fabrics: print an error for ENOENT too
    * plugins/virtium: use time_t for time_stamp values
    * completions: add ocp set-error-injection command
    * doc: add ocp set-error-injection command
    * ocp: add set-error-injection command
    * nvme: use argconfig_parse_seen to check conditions
    * nvme: use proper mask to get correct lbafu value
    * utils: fix print formatting option
    * utils: cleanup includes in utils.h
    * utils: add missing header
    * nvme-print: Added print for two new fields for HMB feature
    * plugins/micron: Move OCP internal log parsing from Micron to OCP Plugin.
    * fabrics: remove unused _discover_from_json_config_file() argument
    * nvme: avoid unnecessary dup() + close() in io_mgmt_send()
    * util: remove unnecessary NULL check in cleanup_nvme_root()
    * nvme: use argconfig_parse_comma_sep_array_u16() in attach-ns
    * util: avoid duplication in argconfig_parse_comma_sep_array*()
    * util: remove redundant loop condition in argconfig_parse()
    * util: introduce is_null_or_empty() to avoid strlen()
    * util: reduce allocation sizes in argconfig_parse()
    * util: consolidate call paths to argconfig_parse_type()
    * util: reduce complexity of argconfig_parse_val()
    * util: reduce arguments passed to argconfig_parse_type()
    * util: remove empty default case in argconfig functions
    * util: remove unnecessary parentheses in argconfig_parse_type()
    * util: remove redundant cast in argconfig_parse_type()
    * util: inline argconfig_parse_byte()
    * util: remove redundant NULL check in argconfig_print_help()
    * util: use cleanup to avoid goto in argconfig_parse()
    * util: make argconfig_set_opt_val() a void function
    * util: remove argconfig_parse_val() declaration
    * util: remove argconfig CFG_SIZE type
    * wdc: Update and refactor the C0h log page parsing
    * ccan: Add freed pointer checking to delete strset member
    * fabrics: connect all hosts in config.json (bsc#1226216)
    * fabrics: refactore discover from json config (bsc#1226216)
    * fabrics: first read config before topology scanning (bsc#1226216)
    * fabrics: use helper to lookup default hostnqn/hostid (bsc#1226216)
    * fabrics: extend already connected message (bsc#1226216)
    * fabrics: use cleanup helper to free nvme root object
    * nvme: check MD size with PI size when PRACT set to 1
    * nvme-print: add new field added in TP4090
    * nvme-print-binary: add effects-log command output missed
    * completions: add ocp get-error-injection command
    * doc: add ocp get-error-injection command
    * ocp: add get-error-injection command
    * ocp: fix eol-plp-failure-mode command sel option value
    * doc: fix ocp eol-plp-failure-mode select short option
    * ocp: set UUID index for eol-plp-failure-mode command to get
    * nvme: fix verbose logging (bsc#1231668)
    * doc: fix micron ocp telemetry log parse title
    * nvme-rpmb: send RPMB_REQ_READ_RESULT for authentication key programming
    * plugins/micron: Add support for OCP telemetry log parsing
    * ocp: Update Plugin Version
    * nvme: fix lbaf inuse to use 6:5 bits
    * ocp: use NVME_ARGS macro definition by eol-plp-failure-mode command
    * nvme: extern NVME_ARGS macro definition
    * nvme: use _cleanup_free_ type buffer for get-feature command
    * plugins/ocp: Update telemetry string log page (C9h)
    * nvme-print-json: add get-feature command fahrenheit temperature output
    * nvme: add get-feature and id-ctrl commands fahrenheit outputs
    * nvme: delete smart-log command fahrenheit option
    * nvme-print: check locale to use temperatures in degrees fahrenheit
    * completion: add support for tls-key (bsc#1226197)
    * doc: add tls-key --revoke documentation (bsc#1226197)
    * doc: fix tls-key --keyfile shorthand (bsc#1226197)
    * nvme: add support to revoke TLS key (bsc#1226197)
    * nvme: return error code/message for TLS commands (bsc#1226197)
    * nvme: factor out import key function (bsc#1226197)
    * nvme: use cleanup helper to close file descriptor (bsc#1226216)
    * nvme-rpmb: use cleanup helper for STREAM objects
    * fabrics: use cleanup helper for STREAM objects
    * nvme: use cleanup helper for STREAM objects (bsc#1226216)
    * nvme: strip newline when parsing TLS key files (bsc#1226197)
    * nvme: use stdout for exporting TLS keys (bsc#1226197)
    * nvme: change _cleanup_file_ to _cleanup_fd_ (bsc#1226197)
    * common.h: Avoid using unsupported load/store instructions in arm64 VMs
    * ocp: OCP 2.5 Telemetry DA 1 and 2 Parsing Updates
    * nvme-print-stdout: refactor subsys config (bsc#1231668)
    * wdc: Fix compiler warning.
    * nvme: add flags type nvme_print_flags_t
    * nvme-print: Use 'unsigned int' instead of 'unsigned'
    * nvme: update parse_args() return value handling
    * nvme-print: Fix nvme_show_smart_log indentation error
    * nvme-print-stdout: Fix stdout_smart_log indentation error
    * nvme-print-binary: Fix binary_smart_log indentation error
    * completions: add smart-log command fahrenheit option
    * doc: Add smart-log command fahrenheit option
    * nvme: Add smart-log command fahrenheit option
    * nvme-print: add PEL vendor specific and TCG defined events strings
    * nvme-print: Print PEL reserved event string
    * completions: Add timeout option bash completions
    * completions: Add timeout option zsh completions
    * completions: Add io-mgmt-recv/send commands zsh completions
    * completions: Add /dev/nvme argument missed
    * completions: Change fw-activate command name to fw-commit
    * completions: Fix _nvme indentation errors (bsc#1226197)
    * completions: Fix bash-nvme-completion.sh indentation errors (bsc#1226197)
    * doc: Add nvme commands timeout option
    * nvme: Add support for delete-ns command timeout option
    * nvme: Change NVME_DEFAULT_IOCTL_TIMEOUT to use nvme_cfg timeout
    * nvme: Add nvme_cfg timeout default option
    * nvme: Add nvme_cfg global variable for NVME_ARGS default options
    * nvme: add helper function to get pif and sts value
    * nvme: choose PIF from QPIF if QPIFS supports and PIF is QTYPE
    * nvme: use libnvme's atomic ANA log page fetch
    * nvme: fix maximum ANA log page length calculation
    * nvme-print-json: add missing va_end()
    * fabrics: skip namespace scan for fabric commands
    * nvme-print: print the new fields added in TP4141a
    * plugins/ocp: underflow + index fixes for telemetry
    * plugins/ocp: Add ocp TCG Configuration Log Page
    * nvme-print-stdout: Add helper function to print PIF in string form
    * doc: fix format command info
    * nvme: telemetry: report the correct error if the ioctl() fails.
    * nvme-print: add the cancel opcode to the nvme_cmd_to_string() list
    * doc: fix ocp format issues
    * nbft: Reuse existing discovery controller
    * nbft: Skip SSNS records pointing to well-known discovery NQN
    * nbft: Perform actual discovery
    * util/cleanup: Add cleanup for struct nvme_fabrics_uri
    * fabrics: Make some symbols public (bsc#1226216)
    * nvme-print-stdout: fix format index in stdout_nvm_id_ns
    * plugins/solidigm: Added workload-tracker command
    * plugins/solidigm: Added extra VU fields to id-ctrl
    * nvme-print-stdout: print MEM bit of CTRATT field
    * nvme-print-stdout: fix to print the log line by line
    * fabrics: Always pass hostid and hostnqn (bsc#1226216)
    * plugins/ssstc: Replace __uint16_t with uint16_t
    * plugins/solidigm: Added log pages to vs-internal-logs
    * sed: perform a tper revert after lsp revert
    * plugins/nbft: Use default library logging
    * docs: Add missing OCP plugin docs to meson
    * ocp: Switch OCP plugin to use semantic versioning
    * nvme: fix fw-commit MUD result message
    * sed: only re-read partition table after unlock.
    * nvme-print-json: Fix LBA status DSLBA output as hexadecimal
    * nvme-print-json: Use NVME_PMRxxx register definitions to print
    * nvme-print-stdout: Fix PMRWBM register name
    * nvme-print-json: Fix channel configuration descriptors pointer
    * nvme-print-json: Fix linux kernel check patch errors
    * nvme-print: Added "Command and Feature Lockdown" string to LID 0x14
    * plugins/innogrit: `u_char` -> `unsigned char`
    * nvme: Use C99 types for uint32_t
    * nvme-print-stdout: print frl1/2/3 values for zns id-ns
    * solidigm: Eliminate <linux/limits.h>
    * nvme: remove double free in persistent-event-log
    * ocp: Add Get DSSD Power State Feature (FID: C7h)
    * nvme: initialize default library logging
    * nvme: use cleanup helper for nvme_root_t objects (bsc#1226197)
    * doc: add nvme connet ctrl-loss-tmo description
    * plugins/solidigm: Automatic enabling Data Area 4 when retrieving Telemetry.
  - always build the docs
    * add 0001-docs-rename-ocp-unsupported-req-log-file.patch

++++ salt:

  - Fix rich rule comparison in firewalld module (bsc#1222684)
  - test_vultrpy: adjust test expectation to prevent failure after Debian 10 EOL
  - Make auth.pam more robust with Salt Bundle and fix tests
  - Fix performance of user.list_groups with many remote groups
  - Fix "status.diskusage" function and exclude some tests for Salt Bundle
  - Skip certain tests if necessary for some OSes and set flaky ones
  - Add a timer to delete old env post update for venv-minion
  - Several fixes for tests to avoid errors and failures in some OSes
  - Speed up salt.matcher.confirm_top by using __context__
  - Do not call the async wrapper calls with the separate thread
  - Prevent OOM with high amount of batch async calls (bsc#1216063)
  - Add missing contextvars dependency in salt.version
  - Skip tests for unsupported algorithm on old OpenSSL version
  - Remove redundant `_file_find` call to the master
  - Prevent possible exception in tornado.concurrent.Future._set_done
  - Make reactor engine less blocking the EventPublisher
  - Make salt-master self recoverable on killing EventPublisher
  - Improve broken events catching and reporting
  - Make logging calls lighter
  - Remove unused import causing delays on starting salt-master
  - Mark python3-CherryPy as recommended package for the testsuite
  - Make "man" a recommended package instead of required
  - Added:
    * provide-systemd-timer-unit.patch
    * make-logging-calls-lighter.patch
    * add-missing-contextvars-dependency-in-salt.version.patch
    * prevent-oom-with-high-amount-of-batch-async-calls-bs.patch
    * prevent-possible-exception-in-tornado.concurrent.fut.patch
    * improve-broken-events-catching-and-reporting.patch
    * skip-tests-for-unsupported-algorithm-on-old-openssl-.patch
    * several-fixes-for-tests-to-avoid-errors-and-failures.patch
    * fix-user.list_groups-omits-remote-groups.patch
    * some-more-small-tests-fixes-enhancements-661.patch
    * skip-certain-tests-if-necessary-and-mark-some-flaky-.patch
    * firewalld-normalize-new-rich-rules-before-comparing-.patch
    * remove-redundant-_file_find-call-to-the-master.patch
    * fix-status.diskusage-and-exclude-some-tests-to-run-w.patch
    * remove-unused-import-causing-delays-on-starting-salt.patch
    * make-reactor-engine-less-blocking-the-eventpublisher.patch
    * test_vultrpy-adjust-test-expectation-to-prevent-fail.patch
    * speed-up-salt.matcher.confirm_top-by-using-__context.patch
    * do-not-call-the-async-wrapper-calls-with-the-separat.patch
    * make-salt-master-self-recoverable-on-killing-eventpu.patch

++++ sysuser-tools:

  - UID:GID: don't create group with GID if it does not exist
  - Rewrite UID:GID support to work with busybox and fix it for useradd

------------------------------------------------------------------
------------------  2024-8-1  -  Aug 1 2024  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20240801.75f05dd:
    * sysctl: Don't set kernel.pid_max on 32b archs (bsc#1227117)

++++ kernel-default:

  - workqueue: Improve scalability of workqueue watchdog touch
    (bsc#1193454).
  - commit 3c83768
  - workqueue: wq_watchdog_touch is always called with valid CPU
    (bsc#1193454).
  - commit 5cd5767
  - btrfs: qgroup: fix quota root leak after quota disable failure
    (bsc#1228655 CVE-2024-41078).
  - commit d598dd5
  - KVM: arm64: Disassociate vcpus from redistributor region on
    teardown (CVE-2024-40989 bsc#1227823).
  - commit 8e9651c
  - powerpc/eeh: avoid possible crash when edev->pdev changes
    (CVE-2024-41064 bsc#1228599).
  - commit 2510511
  - net: ks8851: Fix deadlock with the SPI chip variant (CVE-2024-41036 bsc#1228496)
  - commit 3cf617f
  - net/sched: Fix UAF when resolving a clash (CVE-2024-41040 bsc#1228518)
  - commit dea6a81
  - btrfs: make sure that WRITTEN is set on all metadata blocks (CVE-2024-35949 bsc#1224700)
    Changes: adjust returned error codes to -EUCLEAN and drop definition of
    the enum error.
  - commit 7880179

++++ kernel-rt:

  - workqueue: Improve scalability of workqueue watchdog touch
    (bsc#1193454).
  - commit 3c83768
  - workqueue: wq_watchdog_touch is always called with valid CPU
    (bsc#1193454).
  - commit 5cd5767
  - btrfs: qgroup: fix quota root leak after quota disable failure
    (bsc#1228655 CVE-2024-41078).
  - commit d598dd5
  - KVM: arm64: Disassociate vcpus from redistributor region on
    teardown (CVE-2024-40989 bsc#1227823).
  - commit 8e9651c
  - powerpc/eeh: avoid possible crash when edev->pdev changes
    (CVE-2024-41064 bsc#1228599).
  - commit 2510511
  - net: ks8851: Fix deadlock with the SPI chip variant (CVE-2024-41036 bsc#1228496)
  - commit 3cf617f
  - net/sched: Fix UAF when resolving a clash (CVE-2024-41040 bsc#1228518)
  - commit dea6a81
  - btrfs: make sure that WRITTEN is set on all metadata blocks (CVE-2024-35949 bsc#1224700)
    Changes: adjust returned error codes to -EUCLEAN and drop definition of
    the enum error.
  - commit 7880179

++++ python313-core:

  - Update to 3.13.0~rc1:
  - Tests
  - gh-59022: Add tests for pkgutil.extend_path(). Patch by
    Andreas Stocker.
  - gh-99242: os.getloadavg() may throw OSError when
    running regression tests under certain conditions (e.g.
    chroot). This error is now caught and ignored, since
    reporting load average is optional.
  - Security
  - gh-122133: Authenticate the socket connection for the
    socket.socketpair() fallback on platforms where AF_UNIX is
    not available like Windows.
  - Patch by Gregory P. Smith <greg@krypto.org> and Seth Larson
    <seth@python.org>. Reported by Ellie <el@horse64.org>
  - gh-121957: Fixed missing audit events around interactive
    use of Python, now also properly firing for python -i, as
    well as for python -m asyncio. The events in question are
    cpython.run_stdin and cpython.run_startup.
  - Library
  - gh-122400: Handle ValueErrors raised by os.stat() in
    filecmp.dircmp and filecmp.cmpfiles(). Patch by Bénédikt
    Tran.
  - gh-122311: Fix some error messages in pickle.
  - gh-122332: Fixed segfault with asyncio.Task.get_coro() when
    using an eager task factory.
  - gh-105733: ctypes.ARRAY() is now soft deprecated: it no
    longer emits deprecation warnings and is not scheduled for
    removal.
  - gh-122087: Restore inspect.ismethoddescriptor() and
    inspect.isroutine() returning False for functools.partial
    objects.
  - gh-122170: Handle ValueErrors raised by os.stat() in
    linecache. Patch by Bénédikt Tran.
  - gh-82951: Serializing objects with complex __qualname__
    (such as unbound methods and nested classes) by name no
    longer involves serializing parent objects by value in
    pickle protocols < 4.
  - gh-113785: csv now correctly parses numeric fields (when
    used with csv.QUOTE_NONNUMERIC or csv.QUOTE_STRINGS) which
    start with an escape character.
  - gh-122088: @warnings.deprecated now copies the
    coroutine status of functions and methods so that
    inspect.iscoroutinefunction() returns the correct result.
  - gh-120930: Fixed a bug introduced by gh-92081 that added an
    incorrect extra blank to encoded words occurring in wrapped
    headers.
  - gh-121474: Fix missing sanity check for parties arg in
    threading.Barrier constructor. Patch by Clinton Christian
    (pygeek).
  - gh-120289: Fixed the use-after-free issue in cProfile by
    disallowing disable() and clear() in external timers.
  - IDLE
  - gh-122482: Change About IDLE to direct users to
    discuss.python.org instead of the now unused idle-dev email
    and mailing list.
  - Core and Builtins
  - gh-116090: Fix an issue in JIT builds that prevented some
    for loops from correctly firing RAISE monitoring events.
  - gh-122208: Dictionary watchers now only deliver the
    PyDict_EVENT_ADDED event when the insertion is in a known
    good state to succeed.
  - gh-122300: Preserve AST nodes for f-string with
    single-element format specifiers. Patch by Pablo Galindo
  - gh-122029: Emit c_call events in sys.setprofile() when a
    PyMethodObject pointing to a PyCFunction is called.
  - gh-122026: Fix a bug that caused the tokenizer to not
    correctly identify mismatched parentheses inside f-strings
    in some situations. Patch by Pablo Galindo
  - gh-118934: Make PyEval_GetLocals return borrowed reference
  - C API
  - gh-116622: Make PyObject_Print work around a bug in Android
    and OpenBSD which prevented it from throwing an exception
    when trying to write to a read-only stream.
  - gh-121489: Export private _PyBytes_Join() again.
  - Build
  - gh-120522: Added a --with-app-store-compliance option to
    patch out known issues with macOS/iOS App Store review
    processes.

++++ tpm2.0-abrmd:

  - Update harden_tpm2-abrmd.service.patch to contain necessary SELinux
    changes (bsc#1209831)

++++ libzypp:

  - MediaPluginType must be resolved to a valid MediaHandler
    (bsc#1228208)
  - version 17.35.7 (35)

++++ makedumpfile:

  - add (bsc#1228388):
    * 0001-PATCH-Fix-failure-of-hugetlb-pages-exclusion-on-Linu.patch
    * 0002-PATCH-Fix-wrong-exclusion-of-Slab-pages-on-Linux-6.1.patch

++++ openssh:

  - Update to openssh 9.8p1:
    = Security
    * 1) Race condition in sshd(8) (bsc#1226642, CVE-2024-6387).
    A critical vulnerability in sshd(8) was present in Portable
    OpenSSH versions between 8.5p1 and 9.7p1 (inclusive) that may
    allow arbitrary code execution with root privileges.
    Successful exploitation has been demonstrated on 32-bit
    Linux/glibc systems with ASLR. Under lab conditions, the attack
    requires on average 6-8 hours of continuous connections up to
    the maximum the server will accept. Exploitation on 64-bit
    systems is believed to be possible but has not been
    demonstrated at this time. It's likely that these attacks will
    be improved upon.
    Exploitation on non-glibc systems is conceivable but has not
    been examined. Systems that lack ASLR or users of downstream
    Linux distributions that have modified OpenSSH to disable
    per-connection ASLR re-randomisation (yes - this is a thing, no
  - we don't understand why) may potentially have an easier path
    to exploitation. OpenBSD is not vulnerable.
    We thank the Qualys Security Advisory Team for discovering,
    reporting and demonstrating exploitability of this problem, and
    for providing detailed feedback on additional mitigation
    measures.
    * 2) Logic error in ssh(1) ObscureKeystrokeTiming (bsc#1227318,
    CVE-2024-39894).
    In OpenSSH version 9.5 through 9.7 (inclusive), when connected
    to an OpenSSH server version 9.5 or later, a logic error in the
    ssh(1) ObscureKeystrokeTiming feature (on by default) rendered
    this feature ineffective - a passive observer could still
    detect which network packets contained real keystrokes when the
    countermeasure was active because both fake and real keystroke
    packets were being sent unconditionally.
    This bug was found by Philippos Giavridis and also
    independently by Jacky Wei En Kung, Daniel Hugenroth and
    Alastair Beresford of the University of Cambridge Computer Lab.
    Worse, the unconditional sending of both fake and real
    keystroke packets broke another long-standing timing attack
    mitigation. Since OpenSSH 2.9.9 sshd(8) has sent fake keystoke
    echo packets for traffic received on TTYs in echo-off mode,
    such as when entering a password into su(8) or sudo(8). This
    bug rendered these fake keystroke echoes ineffective and could
    allow a passive observer of a SSH session to once again detect
    when echo was off and obtain fairly limited timing information
    about keystrokes in this situation (20ms granularity by
    default).
    This additional implication of the bug was identified by
    Jacky Wei En Kung, Daniel Hugenroth and Alastair Beresford and
    we thank them for their detailed analysis.
    This bug does not affect connections when
    ObscureKeystrokeTiming was disabled or sessions where no TTY
    was requested.
    = Future deprecation notice
    * OpenSSH plans to remove support for the DSA signature algorithm
    in early 2025. This release disables DSA by default at compile
    time.
    DSA, as specified in the SSHv2 protocol, is inherently weak -
    being limited to a 160 bit private key and use of the SHA1
    digest. Its estimated security level is only 80 bits symmetric
    equivalent.
    OpenSSH has disabled DSA keys by default since 2015 but has
    retained run-time optional support for them. DSA was the only
    mandatory-to-implement algorithm in the SSHv2 RFCs, mostly
    because alternative algorithms were encumbered by patents when
    the SSHv2 protocol was specified.
    This has not been the case for decades at this point and better
    algorithms are well supported by all actively-maintained SSH
    implementations. We do not consider the costs of maintaining
    DSA in OpenSSH to be justified and hope that removing it from
    OpenSSH can accelerate its wider deprecation in supporting
    cryptography libraries.
    This release, and its deactivation of DSA by default at
    compile-time, marks the second step in our timeline to finally
    deprecate DSA. The final step of removing DSA support entirely
    is planned for the first OpenSSH release of 2025.
    DSA support may be re-enabled in OpenBSD by setting
    "DSAKEY=yes" in Makefile.inc. To enable DSA support in
    portable OpenSSH, pass the "--enable-dsa-keys" option to
    configure.
    = Potentially-incompatible changes
    * all: as mentioned above, the DSA signature algorithm is now
    disabled at compile time.
    * sshd(8): the server will now block client addresses that
    repeatedly fail authentication, repeatedly connect without ever
    completing authentication or that crash the server. See the
    discussion of PerSourcePenalties below for more information.
    Operators of servers that accept connections from many users,
    or servers that accept connections from addresses behind NAT or
    proxies may need to consider these settings.
    * sshd(8): the server has been split into a listener binary,
    sshd(8), and a per-session binary "sshd-session". This allows
    for a much smaller listener binary, as it no longer needs to
    support the SSH protocol. As part of this work, support for
    disabling privilege separation (which previously required code
    changes to disable) and disabling re-execution of sshd(8) has
    been removed. Further separation of sshd-session into
    additional, minimal binaries is planned for the future.
    * sshd(8): several log messages have changed. In particular, some
    log messages will be tagged with as originating from a process
    named "sshd-session" rather than "sshd".
    * ssh-keyscan(1): this tool previously emitted comment lines
    containing the hostname and SSH protocol banner to standard
    error. This release now emits them to standard output, but adds
    a new "-q" flag to silence them altogether.
    * sshd(8): (portable OpenSSH only) sshd will no longer use
    argv[0] as the PAM service name. A new "PAMServiceName"
    sshd_config(5) directive allows selecting the service name at
    runtime. This defaults to "sshd". bz2101
    * (portable OpenSSH only) Automatically-generated files, such as
    configure, config.h.in, etc will now be checked in to the
    portable OpenSSH git release branch (e.g. V_9_8). This should
    ensure that the contents of the signed release branch exactly
    match the contents of the signed release tarball.
    = New features
    * sshd(8): as described above, sshd(8) will now penalise client
    addresses that, for various reasons, do not successfully
    complete authentication. This feature is controlled by a new
    sshd_config(5) PerSourcePenalties option and is on by default.
    sshd(8) will now identify situations where the session did not
    authenticate as expected. These conditions include when the
    client repeatedly attempted authentication unsucessfully
    (possibly indicating an attack against one or more accounts,
    e.g. password guessing), or when client behaviour caused sshd
    to crash (possibly indicating attempts to exploit bugs in
    sshd).
    When such a condition is observed, sshd will record a penalty
    of some duration (e.g. 30 seconds) against the client's
    address. If this time is above a minimum configurable
    threshold, then all connections from the client address will be
    refused (along with any others in the same
    PerSourceNetBlockSize CIDR range) until the penalty expire.
    Repeated offenses by the same client address will accrue
    greater penalties, up to a configurable maximum. Address ranges
    may be fully exempted from penalties, e.g. to guarantee access
    from a set of trusted management addresses, using the new
    sshd_config(5) PerSourcePenaltyExemptList option.
    We hope these options will make it significantly more difficult
    for attackers to find accounts with weak/guessable passwords or
    exploit bugs in sshd(8) itself. This option is enabled by
    default.
    * ssh(8): allow the HostkeyAlgorithms directive to disable the
    implicit fallback from certificate host key to plain host keys.
    = Bugfixes
    * misc: fix a number of inaccuracies in the PROTOCOL.*
    documentation files. GHPR430 GHPR487
    * all: switch to strtonum(3) for more robust integer parsing in
    most places.
    * ssh(1), sshd(8): correctly restore sigprocmask around ppoll()
    * ssh-keysign(8): stricter validation of messaging socket fd
    GHPR492
    * sftp(1): flush stdout after writing "sftp>" prompt when not
    using editline. GHPR480
    * sftp-server(8): fix home-directory extension implementation,
    it previously always returned the current user's home directory
    contrary to the spec. GHPR477
    * ssh-keyscan(1): do not close stdin to prevent error messages
    when stdin is read multiple times. E.g.
    echo localhost | ssh-keyscan -f - -f -
    * regression tests: fix rekey test that was testing the same KEX
    algorithm repeatedly instead of testing all of them. bz3692
    * ssh_config(5), sshd_config(5): clarify the KEXAlgorithms
    directive documentation, especially around what is supported
    vs available. bz3701.
    = Portability
    * sshd(8): expose SSH_AUTH_INFO_0 always to PAM auth modules
    unconditionally. The previous behaviour was to expose it only
    when particular authentication methods were in use.
    * build: fix OpenSSL ED25519 support detection. An incorrect
    function signature in configure.ac previously prevented
    enabling the recently added support for ED25519 private keys in
    PEM PKCS8 format.
    * ssh(1), ssh-agent(8): allow the presence of the WAYLAND_DISPLAY
    environment variable to enable SSH_ASKPASS, similarly to the
    X11 DISPLAY environment variable. GHPR479
    * build: improve detection of the -fzero-call-used-regs compiler
    flag. bz3673.
    * build: relax OpenSSL version check to accept all OpenSSL 3.x
    versions.
    * sshd(8): add support for notifying systemd on server listen and
    reload, using a standalone implementation that doesn't depend
    on libsystemd. bz2641
  - Update to openssh 9.7p1:
    = New features
    * ssh(1), sshd(8): add a "global" ChannelTimeout type that
    watches all open channels and will close all open channels if
    there is no traffic on any of them for the specified interval.
    This is in addition to the existing per-channel timeouts added
    recently.
    This supports situations like having both session and x11
    forwarding channels open where one may be idle for an extended
    period but the other is actively used. The global timeout could
    close both channels when both have been idle for too long.
    * All: make DSA key support compile-time optional, defaulting to
    on.
    = Bugfixes
    * sshd(8): don't append an unnecessary space to the end of
    subsystem arguments (bz3667)
    * ssh(1): fix the multiplexing "channel proxy" mode, broken when
    keystroke timing obfuscation was added. (GHPR#463)
    * ssh(1), sshd(8): fix spurious configuration parsing errors when
    options that accept array arguments are overridden (bz3657).
    * ssh-agent(1): fix potential spin in signal handler (bz3670)
    * Many fixes to manual pages and other documentation, including
    GHPR#462, GHPR#454, GHPR#442 and GHPR#441.
    * Greatly improve interop testing against PuTTY.
    = Portability
    * Improve the error message when the autoconf OpenSSL header
    check fails (bz#3668)
    * Improve detection of broken toolchain -fzero-call-used-regs
    support (bz3645).
    * Fix regress/misc/fuzz-harness fuzzers and make them compile
    without warnings when using clang16
  - Use gcc-11 in SLE to avoid a "parameter name omitted" error
  - Rebase patches:
    * logind_set_tty.patch
    * openssh-6.6.1p1-selinux-contexts.patch
    * openssh-6.6p1-keycat.patch
    * openssh-6.6p1-privsep-selinux.patch
    * openssh-7.6p1-cleanup-selinux.patch
    * openssh-7.7p1-cavstest-ctr.patch
    * openssh-7.7p1-cavstest-kdf.patch
    * openssh-7.7p1-fips.patch
    * openssh-7.7p1-fips_checks.patch
    * openssh-7.7p1-ldap.patch
    * openssh-7.7p1-pam_check_locks.patch
    * openssh-7.7p1-systemd-notify.patch
    * openssh-7.8p1-role-mls.patch
    * openssh-8.0p1-gssapi-keyex.patch
    * openssh-8.1p1-audit.patch
    * openssh-8.4p1-vendordir.patch
    * openssh-9.6p1-crypto-policies-man.patch
    * openssh-mitigate-lingering-secrets.patch
    * openssh-reenable-dh-group14-sha1-default.patch
    * wtmpdb.patch
  - Thanks to Fedora developers for an initial version of the
    rebase of the following patches:
    * openssh-8.0p1-gssapi-keyex.patch
    * openssh-7.8p1-role-mls.patch
    * openssh-8.1p1-audit.patch
  - Remove patches that are already included in 9.8p1:
    * fix-CVE-2024-6387.patch
    * 0001-upstream-fix-proxy-multiplexing-mode_-broken-when-keystroke.patch
    * 0001-upstream-correctly-restore-sigprocmask-around-ppoll.patch
    * 0001-upstream-when-sending-ObscureKeystrokeTiming-chaff-packets_.patch
  - Remove patch that is now merged into
    openssh-7.7p1-cavstest-ctr.patch and
    openssh-7.7p1-cavstest-kdf.patch where it belongs:
    * fix-missing-lz.patch

++++ passt:

  - Update to version 20240726.57a21d2:
    * tap: Improve handling of partially received frames on qemu socket
    * tap: Correctly handle frames of odd length
    * tap: Don't use EPOLLET on Qemu sockets
    * tap: Don't attempt to carry on if we get a bad frame length from qemu
    * tap: Better report errors receiving from QEMU socket
    * log: Fetch log times with CLOCK_MONOTONIC, not CLOCK_REALTIME
    * log: Initialise timestamp for relative log time also if we use a log file
    * log, util: Fix sub-second part in relative log time calculation
    * test/lib/perf_report: Fix highlight
    * test: Fix spurious test failure with systemd-resolved
    * fwd: Broaden what we consider for DNS specific forwarding rules
    * fwd: Refactor tests in fwd_nat_from_tap() for clarity
    * conf: Accept addresses enclosed by square brackets in port forwarding specifiers
    * tap: Exit if we fail to bind a UNIX domain socket with explicit path
    * test: iperf3 3.16 introduces multiple threads, drop our own implementation of that
    * test: Update names of symbols and slabinfo entries
    * test: Fix memory/passt tests, --netns-only is not a valid option for passt
    * log: Drop newlines in the middle of the perror()-like messages
    * tcp: Change SO_PEEK_OFF support message to debug()
    * tap: Don't quit if pasta gets EIO on writev() to tap, interface might be down
    * tcp: Correctly update SO_PEEK_OFF when tcp_send_frames() drops frames
    * tcp: probe for SO_PEEK_OFF both in tcpv4 and tcp6
    * udp: Rename UDP listening sockets
    * udp: Remove rdelta port forwarding maps
    * udp: Remove obsolete socket tracking
    * udp: Direct datagrams from host to guest via flow table
    * udp: Find or create flows for datagrams from tap interface
    * udp: Remove obsolete splice tracking
    * udp: Handle "spliced" datagrams with per-flow sockets
    * udp: Create flows for datagrams from originating sockets
    * fwd: Update flow forwarding logic for UDP
    * flow, icmp: Use general flow forwarding rules for ICMP
    * flow, tcp: Flow based NAT and port forwarding for TCP
    * icmp: Manage outbound socket address via flow table
    * flow: Helper to create sockets based on flowside
    * icmp: Eliminate icmp_id_map
    * icmp: Look up ping flows using flow hash
    * icmp: Obtain destination addresses from the flowsides
    * icmp: Remove redundant id field from flow table entry
    * tcp: Re-use flow hash for initial sequence number generation
    * flow, tcp: Generalise TCP hash table to general flow hash table
    * tcp, flow: Replace TCP specific hash function with general flow hash
    * tcp_splice: Eliminate SPLICE_V6 flag
    * tcp: Simplify endpoint validation using flowside information
    * tcp: Manage outbound address via flow table
    * tcp: Obtain guest address from flowside
    * tcp, flow: Remove redundant information, repack connection structures
    * flow: Common address information for target side
    * flow: Common address information for initiating side
    * doc: Extend zero-recv test with methods using msghdr
    * doc: Test behaviour of closing duplicate UDP sockets
    * tcp_splice: Use parameterised macros for per-side event/flag bits
    * flow: Introduce flow_foreach_sidei() macro
    * flow, tcp_splice: Prefer 'sidei' for variables referring to side index
    * flow, icmp, tcp: Clean up helpers for getting flow from index
    * udp: Handle errors on UDP sockets
    * util: Add AF_UNSPEC support to sockaddr_ntop()
    * udp, tcp: Tweak handling of no_udp and no_tcp flags
    * udp: Make udp_sock_recv static
    * conf: Don't configure port forwarding for a disabled protocol
    * tcp: handle shrunk window advertisements from guest
    * tcp: leverage support of SO_PEEK_OFF socket option when available
    * doc: Trivial fix for reuseaddr-priority
    * doc: Test behaviour of zero length datagram recv()s
    * doc: Add program to document and test assumptions about SO_REUSEADDR
    * udp: Consolidate datagram batching
    * udp: Move some more of sock_handler tasks into sub-functions
    * udp: Don't repeatedly initialise udp[46]_eth_hdr
    * udp: Unify udp[46]_l2_iov
    * udp: Unify udp[46]_mh_splice
    * udp: Rename IOV and mmsghdr arrays
    * udp: Pass full epoll reference through more of sock handler path
    * flow: Add flow_sidx_valid() helper
    * util: sock_l4() determine protocol from epoll type rather than the reverse
    * conf: Use the right maximum buffer size for c->sock_path
    * tcp_splice: Check return value of setsockopt() for SO_RCVLOWAT
    * conf: Copy up to MAXDNSRCH - 1 bytes, not MAXDNSRCH

++++ python313:

  - Update to 3.13.0~rc1:
  - Tests
  - gh-59022: Add tests for pkgutil.extend_path(). Patch by
    Andreas Stocker.
  - gh-99242: os.getloadavg() may throw OSError when
    running regression tests under certain conditions (e.g.
    chroot). This error is now caught and ignored, since
    reporting load average is optional.
  - Security
  - gh-122133: Authenticate the socket connection for the
    socket.socketpair() fallback on platforms where AF_UNIX is
    not available like Windows.
  - Patch by Gregory P. Smith <greg@krypto.org> and Seth Larson
    <seth@python.org>. Reported by Ellie <el@horse64.org>
  - gh-121957: Fixed missing audit events around interactive
    use of Python, now also properly firing for python -i, as
    well as for python -m asyncio. The events in question are
    cpython.run_stdin and cpython.run_startup.
  - Library
  - gh-122400: Handle ValueErrors raised by os.stat() in
    filecmp.dircmp and filecmp.cmpfiles(). Patch by Bénédikt
    Tran.
  - gh-122311: Fix some error messages in pickle.
  - gh-122332: Fixed segfault with asyncio.Task.get_coro() when
    using an eager task factory.
  - gh-105733: ctypes.ARRAY() is now soft deprecated: it no
    longer emits deprecation warnings and is not scheduled for
    removal.
  - gh-122087: Restore inspect.ismethoddescriptor() and
    inspect.isroutine() returning False for functools.partial
    objects.
  - gh-122170: Handle ValueErrors raised by os.stat() in
    linecache. Patch by Bénédikt Tran.
  - gh-82951: Serializing objects with complex __qualname__
    (such as unbound methods and nested classes) by name no
    longer involves serializing parent objects by value in
    pickle protocols < 4.
  - gh-113785: csv now correctly parses numeric fields (when
    used with csv.QUOTE_NONNUMERIC or csv.QUOTE_STRINGS) which
    start with an escape character.
  - gh-122088: @warnings.deprecated now copies the
    coroutine status of functions and methods so that
    inspect.iscoroutinefunction() returns the correct result.
  - gh-120930: Fixed a bug introduced by gh-92081 that added an
    incorrect extra blank to encoded words occurring in wrapped
    headers.
  - gh-121474: Fix missing sanity check for parties arg in
    threading.Barrier constructor. Patch by Clinton Christian
    (pygeek).
  - gh-120289: Fixed the use-after-free issue in cProfile by
    disallowing disable() and clear() in external timers.
  - IDLE
  - gh-122482: Change About IDLE to direct users to
    discuss.python.org instead of the now unused idle-dev email
    and mailing list.
  - Core and Builtins
  - gh-116090: Fix an issue in JIT builds that prevented some
    for loops from correctly firing RAISE monitoring events.
  - gh-122208: Dictionary watchers now only deliver the
    PyDict_EVENT_ADDED event when the insertion is in a known
    good state to succeed.
  - gh-122300: Preserve AST nodes for f-string with
    single-element format specifiers. Patch by Pablo Galindo
  - gh-122029: Emit c_call events in sys.setprofile() when a
    PyMethodObject pointing to a PyCFunction is called.
  - gh-122026: Fix a bug that caused the tokenizer to not
    correctly identify mismatched parentheses inside f-strings
    in some situations. Patch by Pablo Galindo
  - gh-118934: Make PyEval_GetLocals return borrowed reference
  - C API
  - gh-116622: Make PyObject_Print work around a bug in Android
    and OpenBSD which prevented it from throwing an exception
    when trying to write to a read-only stream.
  - gh-121489: Export private _PyBytes_Join() again.
  - Build
  - gh-120522: Added a --with-app-store-compliance option to
    patch out known issues with macOS/iOS App Store review
    processes.

++++ supportutils:

  - Changes to version 3.2.8
    + Avoid getting duplicate kernel verifications in boot.text (pr#190)
    + lvm: suppress file descriptor leak warnings from lvm commands (pr#191)
    + docker_info: Add timestamps to container logs (pr#196)
    + Key value pairs and container log timestamps (bsc#1222021 PED-8211, pr#198)
    + Update supportconfig get pam.d sorted (pr#199)
    + yast_files: Exclude .zcat (pr#201)
    + Sanitize grub bootloader (bsc#1227127, pr#203)
    + Sanitize regcodes (pr#204)
    + Improve product detection (pr#205)
    + Add read_values for s390x (bsc#1228265, pr#206)
    + hardware_info: Remove old alsa ver check (pr#209)
    + drbd_info: Fix incorrect escape of quotes (pr#210)

++++ swtpm:

  - update to 0.9.0:
  - fixes: boo#1226398
  - swtpm:
  - Use umask() to create/truncated state file rather than fchmod()
  - Use fchmod to set mode bits provided by user
  - Replace mkstemp with g_mkstemp_full (Coverity)
  - fix typo in help message
  - cuse: Fix Coverity complaints regarding locks
  - Fix double free in error path
  - Close fd after main loop
  - Restore logging to stderr on log open failure
  - swtpm_setup:
  - Fail --pcr-banks without --tpm2
  - Fail --decryption or --allow-signing without --tpm2
  - Initialized argv in get_swtpm_capabilities()
  - Flush spk after persisting to create room for another key
  - Refactor duplicate code into swtpm_tpm2_write_cert_nvram
  - Move persisting of certificate into tpm2_persist_certificate
  - Pass key_type to function creating filename for key
  - Add scheme parameter before curveid to createprimary_ecc
  - Rename is_ek to preserve for future extension
  - Mask-out EK and plaform certificate flags and set cert_flags
  - Move common code into new function read_certificate_file()
  - Exit with '0' upon --version rather than '1'
  - Close file descriptors passed to swtpm process on parent side
  - Make stdout unbuffered
  - Use medium duration on TSC_PhysicalPresence to avoid timeouts
  - Add poll() after write() and before read() to detect errors
  - swtpm_localca:
  - Add support for up to 20 bytes serial numbers
  - Introduce --key as more generic alias for --ek
  - Add missing NULL option to end of array
  - Make stdout unbuffered
  - swtpm_cert:
  - Add support for serial numbers up to 20 bytes long
  - swtpm_ioctl:
  - Separate return code from flags
  - Repeatedly call PTM_GET_INFO for long responses
  - selinux:
  - Re-add rule for svirt_tcg_t and user_tmp_t:sock_file (virt-install)
  - New SELinux policy that requires Fedora 40 or later
  - tests:
  - Fixed occurrences of stray '' before '-'
  - Rearrange order of test cases to run some also as 'root'
  - Add tests for command line options and combinations of options
  - Add softhsm_setup to shellcheck'ed files and fix issues
  - Add missing 'exit 1' on unexpected file size on --reconfigure
  - Add test cases for swtpm_cert with max serial number
  - Fix spelling mistakes
  - reformat regexs for easier readability and extension
  - ibmtss2: Add patch to disable x509 test with older libtpms
  - Upgrade to ibmtss2 v2.0.1
  - Fixed several issues detected by shellcheck
  - build-sys:
  - Add support for --disable-tests to disable tests
  - Display GMP_LIBS and GMP_CFLAGS
  - Only display warning if pkg-config for gmp fails
  - Add gmp library and devel package as dependency
  - use PKG_CHECK_MODULES to check libtpms version

------------------------------------------------------------------
------------------  2024-7-31  -  Jul 31 2024  -------------------
------------------------------------------------------------------

++++ btrfsprogs:

  - update to 6.10
    * inspect:
    * list-chunks: new command to print information about chunks (i.e.
    the physical chunks as stored on devices), sortable; requires root as
    it's using SEARCH_TREE ioctl
    * tree-stats:
    * new option -t to print only the given tree
    * add long options for size units
    * filesystem df: with increased verbosity print per-type information from sysfs
    * version: print a line with built-in features or options (+FEATURE1 -FEATURE2)
    * image: document option -s and its potential problems
    * fixes:
    * scrub status: user selected base for Rate values
    * receive: escape special characters in paths and xattrs
    * dump-tree: escape special characters in paths and xattrs
    * image: sanitizing filenames did not work properly in all cases
    * convert: fix displayed restored image path on rollback
    * tune change csum: do conversion in smaller batches
    * other:
    * build fixes for uClibc
    * build fix for python 3.13
    * documentation updates

++++ chrony:

  - Update clknetsim to snapshot 633a0be: fix missing stat/fstat with
    latest glibc.

++++ cockpit:

  - new version 321:
    * Bug fixes and performance improvements
  - vendor.tar.gz: dropped. Bundling now part of main tarball.
  - update_version.sh: use instead of `osc service mr` to do version
    updates. updated README.packaging

++++ cockpit-machines:

  - update_version.sh: add script for auto-updates
  - switch to upstream package-lock.json
  - do not run scripts during npm install
  - switch to source package instead of precombined upstream release

++++ cockpit-podman:

  - New version 91. Changes since 84:
    * Implement pull option for existing images
    * Use binary http channel for podman socket for non-UTF-8 robustness
    * Stop using obsolete cockpit.utf8_{de,en}coder() API
    * Translation updates
    * Bug fixes and performance improvements
  - update_version.sh: fetch package-lock.json from upstream
    instead of regenerating.

++++ containerized-data-importer:

  - Use the images based on SLE15 SP6 BCI: 1.59.0-150600.3.6.1

++++ cryptsetup:

  - Update to 2.7.4:
    * Detect device busy failure for device-mapper table-referenced
    devices.
    * Fix shared activation for dm-verity devices.
    * Add --shared option for veritysetup open action.
    * Do not use exclusive flag for the allocated backing loop files.
    * Fixes for problems found by static analyzers and Valgrind.
    * Fixes to tests and CI scripts.
  - Use fdupes to link identical man pages.

++++ curl:

  - Update to 8.9.1:
    * Security fixes:
  - curl: ASN.1 date parser overread [bsc#1228535, CVE-2024-7264]
    * Bugfixes:
  - cmake: detect 'libssh' via 'pkg-config'
  - cmake: detect 'nettle' when building with GnuTLS
  - connect: fix connection shutdown for event based processing
  - curl: more defensive socket code for --ip-tos
  - CURLOPT_SSL_CTX_FUNCTION.md: mention CA caching
  - CURLSHOPT_SHARE.md: mention sessions/cookies as not thread-safe
  - ftpserver.pl: make POP3 LIST serve content from the test file
  - lib: survive some NULL input args
  - os400: build cli manual.
  - os400: workaround an IBM ASCII run-time library bug
  - transfer: speed limiting fix for 32bit systems
  - vtls: avoid forward declaration in MultiSSL builds
  - x509asn1: unittests and fixes for gtime2str

++++ docker:

  - Update to Docker 26.1.5-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/26.1/#2615>
    bsc#1230294
  - This update includes fixes for:
    * CVE-2024-41110. bsc#1228324
    * CVE-2023-47108. bsc#1217070
    * CVE-2023-45142. bsc#1228553
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * 0006-bsc1221916-update-to-patched-buildkit-version-to-fix.patch
    * 0007-bsc1214855-volume-use-AtomicWriteFile-to-save-volume.patch
    * cli-0001-docs-include-required-tools-in-source-tree.patch
    [NOTE: This update was only ever released in SLES and Leap.]
  - Update to Docker 25.0.6-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/25.0/#2506>
  - This update includes fixes for:
    * CVE-2024-41110. bsc#1228324
    * CVE-2023-47108. bsc#1217070 bsc#1229806
    * CVE-2023-45142. bsc#1228553 bsc#1229806
  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
    * 0006-bsc1221916-update-to-patched-buildkit-version-to-fix.patch
    * 0007-bsc1214855-volume-use-AtomicWriteFile-to-save-volume.patch

++++ python-kiwi:

  - Fix test_process_result_bundle_as_rpm
    os.path.basename was called on a MagicMock object which
    sometimes confused pytest
  - CI: Add testing against Python 3.13
    Python 3.13 is shipping in Fedora Linux for Fedora Linux 41, so we
    should ensure kiwi is tested against it. The testing setup is
    based on the latest development version of 3.13 as it is not
    yet released.
  - Fix kiwi-repart restrictions
    The kiwi repart dracut module reads a profile file and if it
    does not exists it dies in the initrd. However, that profile
    file is not mandatory for the main resize functionality. Thus
    this commit turns this into a warning message. In addition
    the module-setup for 90kiwi-repart makes sure to include
    the required and optional profile files.
    This Fixes bsc#1228118

++++ fde-tools:

  - Add fde-tools-bsc1218181-replace-crypttab-key-path.patch to
    change the key path in crypttab to avoid the unexpected error
    (bsc#1218181)

++++ gstreamer:

  - Update to version 1.24.6:
    + Highlighted bugfixes:
  - Fix compatibility with FFmpeg 7.0.
  - qmlglsink: Fix failure to display content on recent Android
    devices.
  - adaptivedemux: Fix handling of closed caption streams.
  - cuda: Fix runtime compiler loading with old CUDA tookit.
  - decodebin3 stream selection handling fixes.
  - d3d11compositor, d3d12compositor: Fix transparent background
    mode with YUV output.
  - d3d12converter: Make gamma remap work as intended.
  - h264decoder: Update output frame duration for interlaced
    video when second field frame is discarded.
  - macOS audio device provider now listens to audio devices
    being added/removed at runtime.
  - Rust plugins: audioloudnorm, s3hlssink, gtk4paintablesink,
    livesync and webrtcsink fixes.
  - videoaggregator: preserve features in non-alpha caps for
    subclasses with non-system memory sink caps.
  - vtenc: Fix redistribute latency spam.
  - v4l2: fixes for complex video formats.
  - va: Fix strides when importing DMABUFs, dmabuf handle leaks,
    and blocklist unmaintained Intel i965 driver for encoding.
  - waylandsink: Fix surface cropping for rotated streams.
  - webrtcdsp: Enable multi_channel processing to fix handling of
    stereo streams.
  - Various bug fixes, memory leak fixes, and other stability and
    reliability improvements.

++++ gstreamer-plugins-base:

  - Update to version 1.24.6:
    + Highlighted bugfixes:
  - Fix compatibility with FFmpeg 7.0.
  - qmlglsink: Fix failure to display content on recent Android
    devices.
  - adaptivedemux: Fix handling of closed caption streams.
  - cuda: Fix runtime compiler loading with old CUDA tookit.
  - decodebin3 stream selection handling fixes.
  - d3d11compositor, d3d12compositor: Fix transparent background
    mode with YUV output.
  - d3d12converter: Make gamma remap work as intended.
  - h264decoder: Update output frame duration for interlaced
    video when second field frame is discarded.
  - macOS audio device provider now listens to audio devices
    being added/removed at runtime.
  - Rust plugins: audioloudnorm, s3hlssink, gtk4paintablesink,
    livesync and webrtcsink fixes.
  - videoaggregator: preserve features in non-alpha caps for
    subclasses with non-system memory sink caps.
  - vtenc: Fix redistribute latency spam.
  - v4l2: fixes for complex video formats.
  - va: Fix strides when importing DMABUFs, dmabuf handle leaks,
    and blocklist unmaintained Intel i965 driver for encoding.
  - waylandsink: Fix surface cropping for rotated streams.
  - webrtcdsp: Enable multi_channel processing to fix handling of
    stereo streams.
  - Various bug fixes, memory leak fixes, and other stability and
    reliability improvements.

++++ kernel-default:

  - ila: block BH in ila_output() (CVE-2024-41081 bsc#1228617)
  - commit b832793
  - NFSv4: Fix memory leak in nfs4_set_security_label (CVE-2024-41076 bsc#1228649)
  - commit c2db2a8
  - gfs2: Fix NULL pointer dereference in gfs2_log_flush
    (bsc#1228672 CVE-2024-42079).
  - commit 61cd0c5
  - Update patch reference for ASoC fix (CVE-2024-41069 bsc#1228644)
  - commit bc5c8af
  - Update patches.suse/nilfs2-fix-inode-number-range-checks.patch
    (stable-fixes bsc#1228665 CVE-2024-42105).
  - commit c8d5b4d
  - Update patches.suse/hfsplus-fix-uninit-value-in-copy_name.patch
    (git-fixes bsc#1228561 CVE-2024-41059).
  - commit f1238d0
  - cachefiles: fix slab-use-after-free in
    cachefiles_withdraw_cookie() (bsc#1228462 CVE-2024-41057).
  - cachefiles: fix slab-use-after-free in fscache_withdraw_volume()
    (bsc#1228459 CVE-2024-41058).
  - netfs, fscache: export fscache_put_volume() and add
    fscache_try_get_volume() (bsc#1228459 bsc#1228462).
  - commit a80ddf3
  - platform/chrome: cros_ec_proto: Lock device when updating MKBP
    version (git-fixes).
  - commit ab277a6
  - ocfs2: add bounds checking to ocfs2_check_dir_entry()
    (bsc#1228409 CVE-2024-41015).
  - ocfs2: strict bound check before memcmp in
    ocfs2_xattr_find_entry() (bsc#1228410).
  - ocfs2: add bounds checking to ocfs2_xattr_find_entry()
    (bsc#1228410 CVE-2024-41016).
  - commit ec6fa65
  - platform/chrome: cros_ec_proto: Lock device when updating MKBP
    version (git-fixes).
  - commit d441a76
  - Update patch reference of dmaengine fix (CVE-2024-40956 bsc#1227810)
  - commit d7e764c
  - vfio/pci: Disable auto-enable of exclusive INTx IRQ (bsc#1222625
    CVE-2024-27437).
  - commit de8901b
  - mm: vmalloc: check if a hash-index is in cpu_possible_mask (CVE-2024-41032 bsc#1228460)
  - commit 9b04845
  - seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors (CVE-2024-40957 bsc#1227811)
  - commit a8ab7dd
  - udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port() (CVE-2024-41041 bsc#1228520)
  - commit 74b98cc
  - net: do not leave a dangling sk pointer, when socket creation fails (CVE-2024-40954 bsc#1227808)
  - commit 5ea4aa9
  - netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers (CVE-2024-42070 bsc#1228470)
  - commit 3ac6386

++++ kernel-firmware-all:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-amdgpu:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-ath10k:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-ath11k:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-ath12k:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-atheros:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-bluetooth:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-bnx2:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-brcm:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-chelsio:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-dpaa2:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-i915:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-intel:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-iwlwifi:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-liquidio:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-marvell:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-media:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-mediatek:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-mellanox:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-mwifiex:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-network:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-nfp:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-nvidia:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-platform:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-prestera:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-qcom:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-qlogic:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-radeon:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-realtek:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-serial:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-sound:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-ti:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-ueagle:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-firmware-usb-network:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ kernel-rt:

  - ila: block BH in ila_output() (CVE-2024-41081 bsc#1228617)
  - commit b832793
  - NFSv4: Fix memory leak in nfs4_set_security_label (CVE-2024-41076 bsc#1228649)
  - commit c2db2a8
  - gfs2: Fix NULL pointer dereference in gfs2_log_flush
    (bsc#1228672 CVE-2024-42079).
  - commit 61cd0c5
  - Update patch reference for ASoC fix (CVE-2024-41069 bsc#1228644)
  - commit bc5c8af
  - Update patches.suse/nilfs2-fix-inode-number-range-checks.patch
    (stable-fixes bsc#1228665 CVE-2024-42105).
  - commit c8d5b4d
  - Update patches.suse/hfsplus-fix-uninit-value-in-copy_name.patch
    (git-fixes bsc#1228561 CVE-2024-41059).
  - commit f1238d0
  - cachefiles: fix slab-use-after-free in
    cachefiles_withdraw_cookie() (bsc#1228462 CVE-2024-41057).
  - cachefiles: fix slab-use-after-free in fscache_withdraw_volume()
    (bsc#1228459 CVE-2024-41058).
  - netfs, fscache: export fscache_put_volume() and add
    fscache_try_get_volume() (bsc#1228459 bsc#1228462).
  - commit a80ddf3
  - platform/chrome: cros_ec_proto: Lock device when updating MKBP
    version (git-fixes).
  - commit ab277a6
  - ocfs2: add bounds checking to ocfs2_check_dir_entry()
    (bsc#1228409 CVE-2024-41015).
  - ocfs2: strict bound check before memcmp in
    ocfs2_xattr_find_entry() (bsc#1228410).
  - ocfs2: add bounds checking to ocfs2_xattr_find_entry()
    (bsc#1228410 CVE-2024-41016).
  - commit ec6fa65
  - platform/chrome: cros_ec_proto: Lock device when updating MKBP
    version (git-fixes).
  - commit d441a76
  - Update patch reference of dmaengine fix (CVE-2024-40956 bsc#1227810)
  - commit d7e764c
  - vfio/pci: Disable auto-enable of exclusive INTx IRQ (bsc#1222625
    CVE-2024-27437).
  - commit de8901b
  - mm: vmalloc: check if a hash-index is in cpu_possible_mask (CVE-2024-41032 bsc#1228460)
  - commit 9b04845
  - seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors (CVE-2024-40957 bsc#1227811)
  - commit a8ab7dd
  - udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port() (CVE-2024-41041 bsc#1228520)
  - commit 74b98cc
  - net: do not leave a dangling sk pointer, when socket creation fails (CVE-2024-40954 bsc#1227808)
  - commit 5ea4aa9
  - netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers (CVE-2024-42070 bsc#1228470)
  - commit 3ac6386

++++ pv:

  - update to 1.8.12:
    * fix detection of output block device size
    * do not treat a zero/interrupted write as an end of file

++++ python-cryptography:

  - Update building of Rust modules to use modern cargo_vendor
    service
  - Remove unneeded use-offline-build.patch

++++ python-tornado6:

  - Update to version 6.4.1:
    + Security Improvements:
  - Parsing of the ``Transfer-Encoding`` header is now stricter.
    Unexpected transfer-encoding values were previously ignored
    and treated as the HTTP/1.0 default of read-until-close. This
    can lead to framing issues with certain proxies. We now treat
    any unexpected value as an error.
  - Handling of whitespace in headers now matches the RFC more
    closely. Only space and tab characters are treated as
    whitespace and stripped from the beginning and end of header
    values. Other unicode whitespace characters are now left
    alone. This could also lead to framing issues with certain
    proxies.
  - `tornado.curl_httpclient` now prohibits carriage return and
    linefeed headers in HTTP headers (matching the behavior of
    `simple_httpclient`). These characters could be used for
    header injection or request smuggling if untrusted data were
    used in headers.
    + General Changes:
  - `tornado.iostream`: `SLIOStream` now understands changes to
    error codes from OpenSSL 3.2. The main result of this change
    is to reduce the noise in the logs for certain errors.
  - `tornado.simple_httpclient`: `simple_httpclient` now
    prohibits carriage return characters in HTTP headers. It had
    previously prohibited only linefeed characters.
  - `tornado.testing`: `.AsyncTestCase` subclasses can now be
    instantiated without being associated with a test method.
    Improves compatibility with test discovery in Pytest 8.2.
  - Drop  support-pytest-8.2.patch: fixed upstream.
  - Drop openssl-3.2.patch: fixed upstream.

++++ ucode-amd:

  - Update to version 20240728 (git commit bcd040c21dc9):
    * amdgpu: update DMCUB to v0.0.227.0 for DCN35 and DCN351
    * Revert "iwlwifi: update ty/So/Ma firmwares for core89-58 release"
    (CVE-2023-47210, bsc#1225601, CVE-2023-38417, bsc#1225600)
    * linux-firmware: update firmware for MT7922 WiFi device
    * linux-firmware: update firmware for MT7921 WiFi device
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7922)
    * linux-firmware: update firmware for mediatek bluetooth chip (MT7921)
    * iwlwifi: add gl FW for core89-58 release
    * iwlwifi: update ty/So/Ma firmwares for core89-58 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core89-58 release
    * mediatek: Update mt8195 SOF firmware and sof-tplg
    * ASoC: tas2781: fix the license issue for tas781 firmware
    * rtl_bt: Update RTL8852B BT USB FW to 0x048F_4008
    * .gitignore: Ignore intermediate files
    * i915: Update Xe2LPD DMC to v2.21
    * qcom: move signed x1e80100 signed firmware to the SoC subdir
    * qcom: add video firmware file for vpu-3.0
    * intel: avs: Add topology file for I2S Analog Devices 4567
    * intel: avs: Add topology file for I2S Nuvoton 8825
    * intel: avs: Add topology file for I2S Maxim 98927
    * intel: avs: Add topology file for I2S Maxim 98373
    * intel: avs: Add topology file for I2S Maxim 98357a
    * intel: avs: Add topology file for I2S Dialog 7219
    * intel: avs: Add topology file for I2S Realtek 5663
    * intel: avs: Add topology file for I2S Realtek 5640
    * intel: avs: Add topology file for I2S Realtek 5514
    * intel: avs: Add topology file for I2S Realtek 298
    * intel: avs: Add topology file for I2S Realtek 286
    * intel: avs: Add topology file for I2S Realtek 274
    * intel: avs: Add topology file for Digital Microphone Array
    * intel: avs: Add topology file for HDMI codecs
    * intel: avs: Add topology file for HDAudio codecs
    * Add a copy of Apache-2.0
    * intel: avs: Update AudioDSP base firmware for APL-based platforms
  - Update aliases from 6.10.y and 6.11-rc1
  - Add the Provides/Obsoletes for avs-topology-firmware, as now the
    firmware files are provided in this package

++++ vim:

  - Update apparmor.vim to latest version (from AppArmor 4.0.2)
  - add support for "all" and "userns" rules, and new profile flags

------------------------------------------------------------------
------------------  2024-7-30  -  Jul 30 2024  -------------------
------------------------------------------------------------------

++++ cryptsetup:

  - Update to 2.7.3:
    * Do not allow formatting LUKS2 with Opal SED (hardware encryption)
    if the reported logical sector size for the block device and Opal
    encryption logical block differs.
    * Fixes to wiping LUKS2 headers after Opal locking area erase.
    * Mention the need for possible PSID revert before Opal format for some
    drives (man page).
    * Fix Bitlocker-compatible code to ignore newly seen metadata entries.
    * Fix interactive query retry if LUKS2 unbound keyslot is present.
    * Detect unsupported zoned devices for LUKS header devices.
    * Allow "capi" cipher format for benchmark command and fix parsing
    of plain IV in "capi" format.
    * Add support for HCTR2 encryption mode.
    * Source code now uses SPDX license identifiers instead of full
    license preambles.
    * Fix missing includes for cryptographic backend that could cause
    compilation errors for some systems.
    * Fix tests to work correctly in FIPS mode with recent OpenSSL 3.2.
    * Fix various (mostly false positive) issues detected by Coverity.

++++ python-kiwi:

  - Do not exclude the .profile env file by default
    kiwi's initrd modules read a .profile file which gets included
    into the initrd produced at build time. To allow rebuild of a
    host-only initrd from the booted system this information should
    be present such that it is possible to re-use kiwi initrd code.
  - Get rid of debootstrap
    Replace debootstrap with an apt-get based pre-download of
    packages followed by a dpkg-deb extraction.
    This Fixes #2599
  - Bump version: 10.0.26 → 10.0.27
  - Fix dracut-interactive with systemd 256
    With systemd 256, /usr (and thus also /bin/) is read-only in the initrd.
    Move dracut-interactive and its .service into /run instead.

++++ git:

  - update to 2.46.0
    UI, Workflows & Features
    * The "--rfc" option of "git format-patch" learned to take an
    optional string value to be used in place of "RFC" to tweak the
    "[PATCH]" on the subject header.
    * The credential helper protocol, together with the HTTP layer, have
    been enhanced to support authentication schemes different from
    username & password pair, like Bearer and NTLM.
    * Command line completion script (in contrib/) learned to complete
    "git symbolic-ref" a bit better (you need to enable plumbing
    commands to be completed with GIT_COMPLETION_SHOW_ALL_COMMANDS).
    * When the user responds to a prompt given by "git add -p" with an
    unsupported command, list of available commands were given, which
    was too much if the user knew what they wanted to type but merely
    made a typo.  Now the user gets a much shorter error message.
    * The color parsing code learned to handle 12-bit RGB colors, spelled
    as "#RGB" (in addition to "#RRGGBB" that is already supported).
    * The operation mode options (like "--get") the "git config" command
    uses have been deprecated and replaced with subcommands (like "git
    config get").
    * "git tag" learned the "--trailer" option to futz with the trailers
    in the same way as "git commit" does.
    * A new global "--no-advice" option can be used to disable all advice
    messages, which is meant to be used only in scripts.
    * Updates to symbolic refs can now be made as a part of ref
    transaction.
    * The trailer API has been reshuffled a bit.
    * Terminology to call various ref-like things are getting
    straightened out.
    * The command line completion script (in contrib/) has been adjusted
    to the recent update to "git config" that adopted subcommand based
    UI.
    * The knobs to tweak how reftable files are written have been made
    available as configuration variables.
    * When "git push" notices that the commit at the tip of the ref on
    the other side it is about to overwrite does not exist locally, it
    used to first try fetching it if the local repository is a partial
    clone. The command has been taught not to do so and immediately
    fail instead.
    * The promisor.quiet configuration knob can be set to true to make
    lazy fetching from promisor remotes silent.
    * The inter/range-diff output has been moved to the end of the patch
    when format-patch adds it to a single patch, instead of writing it
    before the patch text, to be consistent with what is done for a
    cover letter for a multi-patch series.
    * A new command has been added to migrate a repository that uses the
    files backend for its ref storage to use the reftable backend, with
    limitations.
    * "git diff --exit-code --ext-diff" learned to take the exit status
    of the external diff driver into account when deciding the exit
    status of the overall "git diff" invocation when configured to do
    so.
    * "git update-ref --stdin" learned to handle transactional updates of
    symbolic-refs.
    * "git format-patch --interdiff" for multi-patch series learned to
    turn on cover letters automatically (unless told never to enable
    cover letter with "--no-cover-letter" and such).
    * The "--heads" option of "ls-remote" and "show-ref" has been been
    deprecated; "--branches" replaces "--heads".
    * For over a year, setting add.interactive.useBuiltin configuration
    variable did nothing but giving a "this does not do anything"
    warning.  The warning has been removed.
    * The http transport can now be told to send request with
    authentication material without first getting a 401 response.
    * A handful of entries are added to the GitFAQ document.
    * "git var GIT_SHELL_PATH" should report the path to the shell used
    to spawn external commands, but it didn't do so on Windows, which
    has been corrected.
    Performance, Internal Implementation, Development Support etc.
    * Advertise "git contacts", a tool for newcomers to find people to
    ask review for their patches, a bit more in our developer
    documentation.
    * In addition to building the objects needed, try to link the objects
    that are used in fuzzer tests, to make sure at least they build
    without bitrot, in Linux CI runs.
    * Code to write out reftable has seen some optimization and
    simplification.
    * Tests to ensure interoperability between reftable written by jgit
    and our code have been added and enabled in CI.
    * The singleton index_state instance "the_index" has been eliminated
    by always instantiating "the_repository" and replacing references
    to "the_index"  with references to its .index member.
    * Git-GUI has a new maintainer, Johannes Sixt.
    * The "test-tool" has been taught to run testsuite tests in parallel,
    bypassing the need to use the "prove" tool.
    * The "whitespace check" task that was enabled for GitHub Actions CI
    has been ported to GitLab CI.
    * The refs API lost functions that implicitly assumes to work on the
    primary ref_store by forcing the callers to pass a ref_store as an
    argument.
    * Code clean-up to reduce inter-function communication inside
    builtin/config.c done via the use of global variables.
    * The pack bitmap code saw some clean-up to prepare for a follow-up topic.
    * Preliminary code clean-up for "git send-email".
    * The default "creation-factor" used by "git format-patch" has been
    raised to make it more aggressively find matching commits.
    * Before discovering the repository details, We used to assume SHA-1
    as the "default" hash function, which has been corrected. Hopefully
    this will smoke out codepaths that rely on such an unwarranted
    assumptions.
    * The project decision making policy has been documented.
    * The strcmp-offset tests have been rewritten using the unit test
    framework.
    * "git add -p" learned to complain when an answer with more than one
    letter is given to a prompt that expects a single letter answer.
    * The alias-expanded command lines are logged to the trace output.
    * A new test was added to ensure git commands that are designed to
    run outside repositories do work.
    * A few tests in reftable library have been rewritten using the
    unit test framework.
    * A pair of test helpers that essentially are unit tests on hash
    algorithms have been rewritten using the unit-tests framework.
    * A test helper that essentially is unit tests on the "decorate"
    logic has been rewritten using the unit-tests framework.
    * Many memory leaks in the sparse-checkout code paths have been
    plugged.
    * "make check-docs" noticed problems and reported to its output but
    failed to signal its findings with its exit status, which has been
    corrected.
    * Building with "-Werror -Wwrite-strings" is now supported.
    * To help developers, the build procedure now allows builders to use
    CFLAGS_APPEND to specify additional CFLAGS.
    * "oidtree" tests were rewritten to use the unit test framework.
    * The structure of the document that records longer-term project
    decisions to deprecate/remove/update various behaviour has been
    outlined.
    * The pseudo-merge reachability bitmap to help more efficient storage
    of the reachability bitmap in a repository with too many refs has
    been added.
    * When "git merge" sees that the index cannot be refreshed (e.g. due
    to another process doing the same in the background), it died but
    after writing MERGE_HEAD etc. files, which was useless for the
    purpose to recover from the failure.
    * The output from "git cat-file --batch-check" and "--batch-command
    (info)" should not be unbuffered, for which some tests have been
    added.
    * A CPP macro USE_THE_REPOSITORY_VARIABLE is introduced to help
    transition the codebase to rely less on the availability of the
    singleton the_repository instance.
    * "git version --build-options" reports the version information of
    OpenSSL and other libraries (if used) in the build.
    * Memory ownership rules for the in-core representation of
    remote.*.url configuration values have been straightened out, which
    resulted in a few leak fixes and code clarification.
    * When bundleURI interface fetches multiple bundles, Git failed to
    take full advantage of all bundles and ended up slurping duplicated
    objects, which has been corrected.
    * The code to deal with modified paths that are out-of-cone in a
    sparsely checked out working tree has been optimized.
    * An existing test of oidmap API has been rewritten with the
    unit-test framework.
    * The "ort" merge backend saw one bugfix for a crash that happens
    when inner merge gets killed, and assorted code clean-ups.
    * A new warning message is issued when a command has to expand a
    sparse index to handle working tree cruft that are outside of the
    sparse checkout.
    * The test framework learned to take the test body not as a single
    string but as a here-document.
    * "git push '' HEAD:there" used to hit a BUG(); it has been corrected
    to die with "fatal: bad repository ''".
    * What happens when http.cookieFile gets the special value "" has
    been clarified in the documentation.
    Fixes
    * "git rebase --signoff" used to forget that it needs to add a
    sign-off to the resulting commit when told to continue after a
    conflict stops its operation.
    * The procedure to build multi-pack-index got confused by the
    replace-refs mechanism, which has been corrected by disabling the
    latter.
    * The "-k" and "--rfc" options of "format-patch" will now error out
    when used together, as one tells us not to add anything to the
    title of the commit, and the other one tells us to add "RFC" in
    addition to "PATCH".
    * "git stash -S" did not handle binary files correctly, which has
    been corrected.
    * A scheduled "git maintenance" job is expected to work on all
    repositories it knows about, but it stopped at the first one that
    errored out.  Now it keeps going.
    * zsh can pretend to be a normal shell pretty well except for some
    glitches that we tickle in some of our scripts. Work them around
    so that "vimdiff" and our test suite works well enough with it.
    * Command line completion support for zsh (in contrib/) has been
    updated to stop exposing internal state to end-user shell
    interaction.
    * Tests that try to corrupt in-repository files in chunked format did
    not work well on macOS due to its broken "mv", which has been
    worked around.
    * The maximum size of attribute files is enforced more consistently.
    * Unbreak CI jobs so that we do not attempt to use Python 2 that has
    been removed from the platform.
    * Git 2.43 started using the tree of HEAD as the source of attributes
    in a bare repository, which has severe performance implications.
    For now, revert the change, without ripping out a more explicit
    support for the attr.tree configuration variable.
    * The "--exit-code" option of "git diff" command learned to work with
    the "--ext-diff" option.
    * Windows CI running in GitHub Actions started complaining about the
    order of arguments given to calloc(); the imported regex code uses
    the wrong order almost consistently, which has been corrected.
    * Expose "name conflict" error when a ref creation fails due to D/F
    conflict in the ref namespace, to improve an error message given by
    "git fetch".
    (merge 9339fca23e it/refs-name-conflict later to maint).
    * The SubmittingPatches document now refers folks to manpages
    translation project.
    * The documentation for "git diff --name-only" has been clarified
    that it is about showing the names in the post-image tree.
    * The credential helper that talks with osx keychain learned to avoid
    storing back the authentication material it just got received from
    the keychain.
    (merge e1ab45b2da kn/osxkeychain-skip-idempotent-store later to maint).
    * The chainlint script (invoked during "make test") did nothing when
    it failed to detect the number of available CPUs.  It now falls
    back to 1 CPU to avoid the problem.
    * Revert overly aggressive "layered defence" that went into 2.45.1
    and friends, which broke "git-lfs", "git-annex", and other use
    cases, so that we can rebuild necessary counterparts in the open.
    * "git init" in an already created directory, when the user
    configuration has includeif.onbranch, started to fail recently,
    which has been corrected.
    * Memory leaks in "git mv" has been plugged.
    * The safe.directory configuration knob has been updated to
    optionally allow leading path matches.
    * An overly large ".gitignore" files are now rejected silently.
    * Upon expiration event, the credential subsystem forgot to clear
    in-core authentication material other than password (whose support
    was added recently), which has been corrected.
    * Fix for an embarrassing typo that prevented Python2 tests from running
    anywhere.
    * Varargs functions that are unannotated as printf-like or execl-like
    have been annotated as such.
    * "git am" has a safety feature to prevent it from starting a new
    session when there already is a session going.  It reliably
    triggers when a mbox is given on the command line, but it has to
    rely on the tty-ness of the standard input.  Add an explicit way to
    opt out of this safety with a command line option.
    (merge 62c71ace44 jk/am-retry later to maint).
    * A leak in "git imap-send" that somehow escapes LSan has been
    plugged.
    * Setting core.abbrev too early before the repository set-up
    (typically in "git clone") caused segfault, which as been
    corrected.
    * When the user adds to "git rebase -i" instruction to "pick" a merge
    commit, the error experience is not pleasant.  Such an error is now
    caught earlier in the process that parses the todo list.
    * We forgot to normalize the result of getcwd() to NFC on macOS where
    all other paths are normalized, which has been corrected.  This still
    does not address the case where core.precomposeUnicode configuration
    is not defined globally.
    * Earlier we stopped using the tree of HEAD as the default source of
    attributes in a bare repository, but failed to document it.  This
    has been corrected.
    * "git update-server-info" and "git commit-graph --write" have been
    updated to use the tempfile API to avoid leaving cruft after
    failing.
    * An unused extern declaration for mingw has been removed to prevent
    it from causing build failure.
    * A helper function shared between two tests had a copy-paste bug,
    which has been corrected.
    * "git fetch-pack -k -k" without passing "--lock-pack" (which we
    never do ourselves) did not work at all, which has been corrected.
    * CI job to build minimum fuzzers learned to pass NO_CURL=NoThanks to
    the build procedure, as its build environment does not offer, or
    the rest of the build needs, anything cURL.
    (merge 4e66b5a990 jc/fuzz-sans-curl later to maint).
    * "git diff --no-ext-diff" when diff.external is configured ignored
    the "--color-moved" option.
    (merge 0f4b0d4cf0 rs/diff-color-moved-w-no-ext-diff-fix later to maint).
    * "git archive --add-virtual-file=<path>:<contents>" never paid
    attention to the --prefix=<prefix> option but the documentation
    said it would. The documentation has been corrected.
    (merge 72c282098d jc/archive-prefix-with-add-virtual-file later to maint).
    * When GIT_PAGER failed to spawn, depending on the code path taken,
    we failed immediately (correct) or just spew the payload to the
    standard output (incorrect).  The code now always fail immediately
    when GIT_PAGER fails.
    (merge 78f0a5d187 rj/pager-die-upon-exec-failure later to maint).
    * date parser updates to be more careful about underflowing epoch
    based timestamp.
    (merge 9d69789770 db/date-underflow-fix later to maint).
    * The Bloom filter used for path limited history traversal was broken
    on systems whose "char" is unsigned; update the implementation and
    bump the format version to 2.
    (merge 9c8a9ec787 tb/path-filter-fix later to maint).
    * Typofix.
    (merge 231cf7370e as/pathspec-h-typofix later to maint).
    * Code clean-up.
    (merge 4b837f821e rs/simplify-submodule-helper-super-prefix-invocation later to maint).
    * "git describe --dirty --broken" forgot to refresh the index before
    seeing if there is any chang, ("git describe --dirty" correctly did
    so), which has been corrected.
    (merge b8ae42e292 as/describe-broken-refresh-index-fix later to maint).
    * Test suite has been taught not to unnecessarily rely on DNS failing
    a bogus external name.
    (merge 407cdbd271 jk/tests-without-dns later to maint).
    * GitWeb update to use committer date consistently in rss/atom feeds.
    (merge cf6ead095b am/gitweb-feed-use-committer-date later to maint).
    * Custom control structures we invented more recently have been
    taught to the clang-format file.
    (merge 1457dff9be rs/clang-format-updates later to maint).
    * Developer build procedure fix.
    (merge df32729866 tb/dev-build-pedantic-fix later to maint).
    * "git push" that pushes only deletion gave an unnecessary and
    harmless error message when push negotiation is configured, which
    has been corrected.
    (merge 4d8ee0317f jc/disable-push-nego-for-deletion later to maint).
    * Address-looking strings found on the trailer are now placed on the
    Cc: list after running through sanitize_address by "git send-email".
    (merge c852531f45 cb/send-email-sanitize-trailer-addresses later to maint).
    * Tests that use GIT_TEST_SANITIZE_LEAK_LOG feature got their exit
    status inverted, which has been corrected.
    (merge 8c1d6691bc rj/test-sanitize-leak-log-fix later to maint).
    * The http.cookieFile and http.saveCookies configuration variables
    have a few values that need to be avoided, which are now ignored
    with warning messages.
    (merge 4f5822076f jc/http-cookiefile later to maint).
    * Repacking a repository with multi-pack index started making stupid
    pack selections in Git 2.45, which has been corrected.
    (merge 8fb6d11fad ds/midx-write-repack-fix later to maint).
    * Fix documentation mark-up regression in 2.45.
    (merge 6474da0aa4 ja/doc-markup-updates-fix later to maint).
    * Work around asciidoctor's css that renders `monospace` material
    in the SYNOPSIS section of manual pages as block elements.
    (merge d44ce6ddd5 js/doc-markup-updates-fix later to maint).
    * Other code cleanup, docfix, build fix, etc.
    (merge 493fdae046 ew/object-convert-leakfix later to maint).
    (merge 00f3661a0a ss/doc-eol-attr-fix later to maint).
    (merge 428c40da61 ri/doc-show-branch-fix later to maint).
    (merge 58696bfcaa jc/where-is-bash-for-ci later to maint).
    (merge 616e94ca24 tb/doc-max-tree-depth-fix later to maint).

++++ health-checker:

  - Update to version 1.11+git20240730.5dafd6a:
    * Add rpm db consistency plugin

++++ kernel-default:

  - KVM: PPC: Book3S HV: Prevent UAF in
    kvm_spapr_tce_attach_iommu_group() (bsc#1228581 CVE-2024-41070).
  - commit 89912c7
  - xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
    (CVE-2024-40959 bsc#1227884).
  - commit 3a174d1
  - Update config files.
    Disable vdpa drivers for Alibaba ENI and SolidNET (jsc#PED-8954, bsc#1227834)
  - commit 9287d7f
  - selftests/bpf: Extend tcx tests to cover late tcx_entry release
    (bsc#1228021 CVE-2024-41010).
  - bpf: Fix too early release of tcx_entry (bsc#1228021
    CVE-2024-41010).
  - commit 57180df
  - selftests/bpf: Add more ring buffer test coverage (bsc#1228020
    CVE-2024-41009).
  - bpf: Fix overrunning reservations in ringbuf (bsc#1228020
    CVE-2024-41009).
  - commit cd82cf6
  - md-cluster: fix no recovery job when adding/re-adding a disk
    (bsc#1223395).
  - md-cluster: fix hanging issue while a new disk adding
    (bsc#1223395).
  - commit d3c6e61
  - rpm/guards: fix precedence issue with control flow operator
    With perl 5.40 it report the following error on rpm/guards script:
    Possible precedence issue with control flow operator (exit) at scripts/guards line 208.
    Fix the issue by adding parenthesis around ternary operator.
  - commit dfba20e
  - HID: wacom: Modify pen IDs (git-fixes).
  - commit 9c450d7
  - Move upstreamed ASoC patch into sorted section
  - commit adae4df

++++ kernel-rt:

  - KVM: PPC: Book3S HV: Prevent UAF in
    kvm_spapr_tce_attach_iommu_group() (bsc#1228581 CVE-2024-41070).
  - commit 89912c7
  - xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr()
    (CVE-2024-40959 bsc#1227884).
  - commit 3a174d1
  - Update config files.
    Disable vdpa drivers for Alibaba ENI and SolidNET (jsc#PED-8954, bsc#1227834)
  - commit 9287d7f
  - selftests/bpf: Extend tcx tests to cover late tcx_entry release
    (bsc#1228021 CVE-2024-41010).
  - bpf: Fix too early release of tcx_entry (bsc#1228021
    CVE-2024-41010).
  - commit 57180df
  - selftests/bpf: Add more ring buffer test coverage (bsc#1228020
    CVE-2024-41009).
  - bpf: Fix overrunning reservations in ringbuf (bsc#1228020
    CVE-2024-41009).
  - commit cd82cf6
  - md-cluster: fix no recovery job when adding/re-adding a disk
    (bsc#1223395).
  - md-cluster: fix hanging issue while a new disk adding
    (bsc#1223395).
  - commit d3c6e61
  - rpm/guards: fix precedence issue with control flow operator
    With perl 5.40 it report the following error on rpm/guards script:
    Possible precedence issue with control flow operator (exit) at scripts/guards line 208.
    Fix the issue by adding parenthesis around ternary operator.
  - commit dfba20e
  - HID: wacom: Modify pen IDs (git-fixes).
  - commit 9c450d7
  - Move upstreamed ASoC patch into sorted section
  - commit adae4df

++++ libX11:

  - Update to 1.8.10; this release includes:
    * Re-fix XIM input sometimes jumbled (#205, #206, #207, #208, !246)
    * Fix various static analysis errors (!250)
    * Add compose sequences for Arabic hamza (!218), Ezh (!221), and
    hryvnia currency (!259)
    * Make colormap private interfaces thread safe (#215, !254)
    * Fix deadlock in XRebindKeysym() (!256)
    * Assorted memory handling cleanups (!251, !258)
    * Restore VAX support still in use by NetBSD (!257)

++++ openvswitch:

  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang_path macro, [bsc#1212476]

++++ procps:

  - Switch to procps 4 branch, absorbing the former procps4 package:
    + Add provides/obsoletes procps4: make zypper replace procps4
    with the main package for users that manually switched.
  - Aligning to the existing procps4 package, drop/add/modify
    patches:
    A    79042e07.patch
    A    procps-ng-4.0.0-integer-overflow.patch
    A    procps-ng-4.0.4-ignore-sysctl_conf.patch
    A    procps-ng-4.0.4-pmapX-not-twice-anymore.patch
    A    procps-ng-4.0.0-floats.dif
    D    CVE-2023-4016.patch
    D    bsc1195468-23da4f40.patch
    D    procps-3.3.17-bsc1181976.patch
    D    procps-3.3.17-ignore-sysctl_conf.patch
    D    procps-3.3.17-library-bsc1181475.patch
    D    procps-3.3.17-top-bsc1181475.patch
    D    procps-ng-3.3.10-integer-overflow.patch
    D    procps-ng-3.3.10-large_pcpu.patch
    D    procps-ng-3.3.17-logind.patch
    D    procps-ng-3.3.8-bnc634840.patch
    D    procps-ng-3.3.9-watch.patch
    D    procps-ng-3.3.8-accuracy.dif
    D    procps-ng-3.3.10-bnc634071_procstat2.diff
    D    procps-ng-3.3.10-fdleak.dif
    M    procps-ng-3.3.10-errno.patch
    M    procps-ng-3.3.10-slab.patch
    M    procps-ng-3.3.11-pmap4suse.patch
    M    procps-ng-3.3.8-ignore-scan_unevictable_pages.patch
    M    procps-ng-3.3.8-petabytes.patch
    M    procps-ng-3.3.8-readeof.patch
    M    procps-v3.3.3-pwdx.patch

++++ libzypp:

  - Export CredentialManager for legacy YAST versions (bsc#1228420)
  - version 17.35.6 (35)
  - Export asSolvable for YAST (bsc#1228420)
  - Fix 4 typos in zypp.conf.
  - version 17.35.5 (35)

++++ patch:

  - CVE-2019-20633.patch: Fix double-free/OOB read in pch.c (bsc#1167721)

++++ python-Jinja2:

  - Cherry-pick patch from Fedora to fix FTBFS with Python 3.13
    * fix-ftbfs-with-python313.patch
  - Add new build dependency python-trio to BuildRequires

++++ python-setuptools:

  - Update to 72.1.0:
    * Restore the tests command and deprecate access to the module.
    * Added return types to typed public functions.
    * Removed lingering unused code around Distribution._patched_dist.
    * Reset the backports module when enabling vendored packages.
    * Include all vendored files in the sdist.
    * Restored package data that went missing in 71.0. This change also
    incidentally causes tests to be installed once again.
    * Now setuptools declares its own dependencies in the core extra.
    Dependencies are still vendored for bootstrapping purposes, but
    setuptools will prefer installed dependencies if present. The core
    extra is used for informational purposes and should *not* be declared
    in package metadata (e.g. build-requires).
    * Support for loading distutils from the standard library is now
    deprecated, including use of SETUPTOOLS_USE_DISTUTILS=stdlib and
    importing distutils before importing setuptools.
    * Fix distribution name normalisation for valid versions that are not
    canonical (e.g. 1.0-2).

++++ regionServiceClientConfigAzure:

  - Update to version 2.2.0 (jsc#PCT-360)
    + Add IPv6 certs to enable IPv6 access of the update infrastructure
    + Add noipv6.patch to patch out IPv6 on SLE 12, no IPv6 support in SLE 12
    in the Public Cloud

++++ vim:

  - Update to 9.1.0636:
    * 9.1.0636: filetype: ziggy files are not recognized
    * 9.1.0635: filetype: SuperHTML template files not recognized
    * 9.1.0634: Ctrl-P not working by default
    * 9.1.0633: Compilation warnings with `-Wunused-parameter`
    * 9.1.0632: MS-Windows: Compiler Warnings
    Add support for Files-Included in syntax script
    tweak documentation style a bit
    * 9.1.0631: wrong completion list displayed with non-existing dir + fuzzy completion
    * 9.1.0630: MS-Windows: build fails with VIMDLL and mzscheme
    * 9.1.0629: Rename of pum hl_group is incomplete
    * 9.1.0628: MinGW: coverage files are not cleaned up
    * 9.1.0627: MinGW: build-error when COVERAGE is enabled
    * 9.1.0626: Vim9: need more tests with null objects
    include initial filetype plugin
    * 9.1.0625: tests: test output all translated messages for all translations
    * 9.1.0624: ex command modifiers not found
    * 9.1.0623: Mingw: errors when trying to delete non-existing files
    * 9.1.0622: MS-Windows: mingw-build can be optimized
    * 9.1.0621: MS-Windows: startup code can be improved
    * 9.1.0620: Vim9: segfauls with null objects
    * 9.1.0619: tests: test_popup fails
    * 9.1.0618: cannot mark deprecated attributes in completion menu
    * 9.1.0617: Cursor moves beyond first line of folded end of buffer
    * 9.1.0616: filetype: Make syntax highlighting off for MS Makefiles
    * 9.1.0615: Unnecessary STRLEN() in make_percent_swname()
    Add single-line comment syntax
    Add syntax test for comments
    Update maintainer info
    * 9.1.0614: tests: screendump tests fail due to recent syntax changes
    * 9.1.0613: tests: termdebug test may fail and leave file around
    Update base-syntax, improve :set highlighting
    Optionally highlight the :: token for method references
    * 9.1.0612: filetype: deno.lock file not recognized
    Use delete() for deleting directory
    escape filename before trying to delete it
    * 9.1.0611: ambiguous mappings not correctly resolved with modifyOtherKeys
    correctly extract file from zip browser
    * 9.1.0610: filetype: OpenGL Shading Language files are not detected
    Fix endless recursion in netrw#Explore()
    * 9.1.0609: outdated comments in Makefile
    update syntax script
    Fix flow mapping key detection
    Remove orphaned YAML syntax dump files
    * 9.1.0608: Coverity warns about a few potential issues
    Update syntax script and remove syn sync
    * 9.1.0607: termdebug: uses inconsistent style
    * 9.1.0606: tests: generated files may cause failure in test_codestyle
    * 9.1.0605: internal error with fuzzy completion
    * 9.1.0604: popup_filter during Press Enter prompt seems to hang
    translation: Update Serbian messages translation
    * 9.1.0603: filetype: use correct extension for Dracula
    * 9.1.0602: filetype: Prolog detection can be improved
    fix more inconsistencies in assert function docs
    * 9.1.0601: Wrong cursor position with 'breakindent' when wide char doesn't fit
    Update base-syntax, improve :map highlighting
    * 9.1.0600: Unused function and unused error constants
    * 9.1.0599: Termdebug: still get E1023 when specifying arguments
    correct wrong comment options
    fix typo "a xterm" -> "an xterm"
    * 9.1.0598: fuzzy completion does not work with default completion
    * 9.1.0597: KeyInputPre cannot get the (unmapped typed) key
    * 9.1.0596: filetype: devscripts config files are not recognized
    gdb file/folder check is now performed only in CWD.
    quote filename arguments using double quotes
    update syntax to SDC-standard 2.1
    minor updates.
    Cleanup :match and :loadkeymap syntax test files
    Update base-syntax, match types in Vim9 variable declarations
    * 9.1.0595: make errors out with the po Makefile
    * 9.1.0594: Unnecessary redraw when setting 'winfixbuf'
    using wrong highlight for UTF-8
    include simple syntax plugin
    * 9.1.0593: filetype: Asymptote files are not recognized
    add recommended indent options to ftplugin
    add recommended indent options to ftplugin
    add recommended indent options to ftplugin
    * 9.1.0592: filetype: Mediawiki files are not recognized
    * 9.1.0591: filetype: *.wl files are not recognized
    * 9.1.0590: Vim9: crash when accessing getregionpos() return value
    'cpoptions': Include "z" in the documented default
    * 9.1.0589: vi: d{motion} and cw work differently than expected
    update included colorschemes
    grammar fixes in options.txt

------------------------------------------------------------------
------------------  2024-7-29  -  Jul 29 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Add NetworkManager-dont-renew-bridge-dhcp-if-no-mac-on-wakeup.patch:
    manager: don't renew dhcp lease when software devices' MAC is empty
    (bsc#1225498, glfd#NetworkManager/NetworkManager#1587).

++++ dmidecode:

  - Update to upstream version 3.6 (jsc#PED-8647):
    * Support for SMBIOS 3.6.0. This includes new memory device types, new
    processor upgrades, and Loongarch support.
    * Support for SMBIOS 3.7.0. This includes new port types, new processor
    upgrades, new slot characteristics and new fields for memory modules.
    * Add bash completion.
    * Decode HPE OEM records 197, 239 and 245.
    * Implement options --list-strings and --list-types.
    * Update HPE OEM records 203, 212, 216, 221, 233, 236, 238 and 242.
    * Update Redfish support.
    * Bug fixes:
    Fix enabled slot characteristics not being printed
    * Minor improvements:
    Print slot width on its own line
    Use standard strings for slot width
    * Obsoletes arm-use-alignment-workaround.patch,
    dmioem-hpe-oem-record-237-firmware-change.patch and
    use-read_file-to-read-from-dump.patch.
    Update for HPE servers from upstream:
  - dmioem-update-hpe-oem-type-238.patch: Decode PCI bus segment in
    HPE type 238 records.
  - Drop legacy Provides: and Obsoletes: tags. The split from the
    pmtools package happened 15 years ago so they are no longer
    relevant.

++++ fwupd:

  - Update to version 1.9.22:
    + This release fixes the following bugs:
  - Add a PCB tag in the usi-dock GUID to distinguish different
    revisions.
  - Add explicit hidraw permission to fwupd.service to fix
    several devices.
  - Always load the flashrom plugin when using coreboot.
  - Be explicit with the rts54hub detach retry delay to fix the
    Acer D501.
  - Be more careful when setting thelio-io version strings.
  - Fix a critical warning if a device returns unexpected data
    from DFU upload.
  - Fix a critical warning if the DMI manufacturer is an empty
    string.
  - Fix several reported integer overflows from Coverity.
  - Fix the Blackbird and Talos II baseboard details.
  - Fix transient version number issue after flashing wacom-usb
    devices.
  - Increase the cros_ec acquiesce delay to manage additional
    reboots.
  - Only accept valid ASCII cabinet filenames.
  - Only require udevdir when gudev support is enabled.
  - Only show one PixArt receiver device per physical device.
  - Set the rts54hub version in more cases.
  - Speed up the daemon self tests by ~60%.
  - Use the bootloader build-timestamp as the fallback HWID BIOS
    version.
    + This release adds support for the following hardware:
  - Framework SD
  - Raspberry Pi 5 (unofficial)

++++ glibc:

  - Update to glibc 2.40
    * The <stdbit.h> header type-generic macros have been changed when using
    GCC 14.1 or later to use __builtin_stdc_bit_ceil etc. built-in functions
    * The GNU C Library now supports a feature test macro _ISOC23_SOURCE to
    enable features from the ISO C23 standard
    * The ISO C23 function families introduced in TS
    18661-4:2015 are now supported in <math.h>
    * A new tunable, glibc.rtld.enable_secure, can be used to run a program
    as if it were a setuid process
    * On Linux, the epoll header was updated to include epoll ioctl definitions
    and the related structure added in Linux kernel 6.9
    * The fortify functionality has been significantly enhanced for building
    programs with clang against the GNU C Library
    * Many functions have been added to the vector library for aarch64
    * On x86, memset can now use non-temporal stores to improve the performance
    of large writes
    * Architectures which use a 32-bit seconds-since-epoch field in struct
    lastlog, struct utmp, struct utmpx (such as i386, powerpc64le, rv32,
    rv64, x86-64) switched from a signed to an unsigned type for that
    field
    * __rseq_size now denotes the size of the active rseq area (20 bytes
    initially), not the size of struct rseq (32 bytes initially).
  - arm-dl-start-user.patch, duplocale-global-locale.patch,
    elf-parse-tunables.patch,
    glibc-CVE-2024-33599-nscd-Stack-based-buffer-overflow-in-n.patch,
    glibc-CVE-2024-33600-nscd-Avoid-null-pointer-crashes-after.patch,
    glibc-CVE-2024-33600-nscd-Do-not-send-missing-not-found-re.patch,
    glibc-CVE-2024-33601-CVE-2024-33602-nscd-netgroup-Use-two.patch,
    iconv-iso-2022-cn-ext.patch, nscd-netgroup-cache-timeout.patch,
    s390-clone-error-clobber-r7.patch, sigisemptyset.patch,
    stdbit-builtins.patch, utmp-time-bits.patch: Removed
  - glibc-2.3.90-langpackdir.diff: Rediff
  - bsc#1228041

++++ ignition:

  - Fix order of previous change - *first* remount rw, *then* create
    directory.

++++ kernel-default:

  - xfs: add bounds checking to xlog_recover_process_data
    (bsc#1228408 CVE-2024-41014).
  - commit bb0300d
  - xfs: don't walk off the end of a directory data block
    (bsc#1228405 CVE-2024-41013).
  - commit 8a0b7eb
  - jfs: don't walk off the end of ealist (bsc#1228403
    CVE-2024-41017).
  - commit 4159bc5
  - ext4: fold quota accounting into
    ext4_xattr_inode_lookup_create() (bsc#1227910 CVE-2024-40972).
  - commit 94f6f2b
  - ext4: fix mb_cache_entry's e_refcnt leak in
    ext4_xattr_block_cache_find() (bsc#1226993 CVE-2024-39276).
  - commit d72f4d7
  - block: fix request.queuelist usage in flush (bsc#1227789
    CVE-2024-40925).
  - commit 4903430
  - supported.conf: mark vdpa modules supported (jsc#PED-8954)
  - commit 483ffd4
  - ext4: do not create EA inode under buffer lock (bsc#1227910
    CVE-2024-40972).
  - commit 37fb4de
  - ext4: fix uninitialized ratelimit_state->lock access in
    __ext4_fill_super() (bsc#1227866 CVE-2024-40998).
  - commit cefc508
  - Update patch reference of AMDGPU fix (CVE-2024-41011 bsc#1228115)
  - commit 96de263
  - ceph: fix incorrect kmalloc size of pagevec mempool
    (bsc#1228417).
  - commit 84977b0
  - ima: Fix use-after-free on a dentry's dname.name (bsc#1227716 CVE-2024-39494).
  - commit f7cf8d6
  - btrfs: zoned: fix use-after-free due to race with dev replace
    (bsc#1227719 CVE-2024-39496).
  - commit c878f86
  - tun: add missing verification for short frame (CVE-2024-41091
    bsc#1228327).
  - tap: add missing verification for short frame (CVE-2024-41090
    bsc#1228328).
  - net: ena: Add validation for completion descriptors consistency
    (CVE-2024-40999 bsc#1227913).
  - commit 7fa5ae2
  - netlink: add nla be16/32 types to minlen array (CVE-2024-26849
    bsc#1223053).
  - commit 2747893
  - Refresh
    patches.kabi/tty-add-the-option-to-have-a-tty-reject-a-new-ldisc.patch.
    Fix build for CONFIG_VT=n (ppc64le/kvmsmall).
  - commit 9280ac5

++++ kernel-rt:

  - xfs: add bounds checking to xlog_recover_process_data
    (bsc#1228408 CVE-2024-41014).
  - commit bb0300d
  - xfs: don't walk off the end of a directory data block
    (bsc#1228405 CVE-2024-41013).
  - commit 8a0b7eb
  - jfs: don't walk off the end of ealist (bsc#1228403
    CVE-2024-41017).
  - commit 4159bc5
  - ext4: fold quota accounting into
    ext4_xattr_inode_lookup_create() (bsc#1227910 CVE-2024-40972).
  - commit 94f6f2b
  - ext4: fix mb_cache_entry's e_refcnt leak in
    ext4_xattr_block_cache_find() (bsc#1226993 CVE-2024-39276).
  - commit d72f4d7
  - block: fix request.queuelist usage in flush (bsc#1227789
    CVE-2024-40925).
  - commit 4903430
  - supported.conf: mark vdpa modules supported (jsc#PED-8954)
  - commit 483ffd4
  - ext4: do not create EA inode under buffer lock (bsc#1227910
    CVE-2024-40972).
  - commit 37fb4de
  - ext4: fix uninitialized ratelimit_state->lock access in
    __ext4_fill_super() (bsc#1227866 CVE-2024-40998).
  - commit cefc508
  - Update patch reference of AMDGPU fix (CVE-2024-41011 bsc#1228115)
  - commit 96de263
  - ceph: fix incorrect kmalloc size of pagevec mempool
    (bsc#1228417).
  - commit 84977b0
  - ima: Fix use-after-free on a dentry's dname.name (bsc#1227716 CVE-2024-39494).
  - commit f7cf8d6
  - btrfs: zoned: fix use-after-free due to race with dev replace
    (bsc#1227719 CVE-2024-39496).
  - commit c878f86
  - tun: add missing verification for short frame (CVE-2024-41091
    bsc#1228327).
  - tap: add missing verification for short frame (CVE-2024-41090
    bsc#1228328).
  - net: ena: Add validation for completion descriptors consistency
    (CVE-2024-40999 bsc#1227913).
  - commit 7fa5ae2
  - netlink: add nla be16/32 types to minlen array (CVE-2024-26849
    bsc#1223053).
  - commit 2747893
  - Refresh
    patches.kabi/tty-add-the-option-to-have-a-tty-reject-a-new-ldisc.patch.
    Fix build for CONFIG_VT=n (ppc64le/kvmsmall).
  - commit 9280ac5

++++ mozilla-nss:

  - Require `sed` for mozilla-nss-sysinit, as setup-nsssysinit.sh
    depends on it and will create a broken, empty config, if sed is
    missing (bsc#1227918)

++++ perl-pcsc:

  - version update to 1.4.16
    * moved to github
    * modernize a bit

++++ python-pycairo:

  - Update to 1.26.1
    * Fix Surface.set_mime_data() with Python 3.13 :pr:`366`
    This also fixes the test suite with Python 3.13b2.
    * Update vendored Windows wheel dependencies :pr:`370`

++++ python-pyserial:

  - Cherry-pick upstream patch to fix tests with Python 3.13
    * replace-deprecated-unittest-function.patch

++++ setroubleshoot:

  - Add libreport-gtk and python3-libreport into requirements for TW
    (fixes boo#1217042)

++++ sudo:

  - A quick note that bsc#1227574 is expected behavior in this
    version of sudo. It was a regression in 15.6 which doesn't have
    the /etc/ split for pam.d yet.

++++ supermin:

  - bsc#1228373 - supermin regression in Tumbleweed / Factory causes
    virt-inspector to fail
    add-rpm-database-location.patch
  - Drop disable-test-if-newer-ext2.patch

++++ update-bootloader:

  - merge gh#openSUSE/perl-bootloader#169
  - support grub2-bls (bsc#1226676, bsc#1208135)
  - better config file reading
  - add check whether bootloader is supported
  - unit test output changed, adjust reference data
  - adjust GRUB_ENABLE_BLSCFG when setting grub2-bls
  - add config, install, add-kernel, remove-kernel for grub2-bls
  - support --default option for grub2*
  - unify cmdline parsing code and move to library
  - add missing options for bls conforming loaders
  - updated tests
  - unify test case names
  - adjust documentation
  - 1.14

++++ virt-manager:

  - bsc#1228384 - virt-install generates unwanted libvirt storage
    pools when running with --dry-run --print-xml
    virtinst-dont-create-storage-pool-for-dryrun.patch

------------------------------------------------------------------
------------------  2024-7-28  -  Jul 28 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - spi: spidev: add correct compatible for Rohm BH2228FV
    (git-fixes).
  - spi: microchip-core: ensure TX and RX FIFOs are empty at start
    of a transfer (git-fixes).
  - spi: microchip-core: only disable SPI controller when register
    value change requires it (git-fixes).
  - spi: microchip-core: defer asserting chip select until just
    before write to TX FIFO (git-fixes).
  - spi: microchip-core: fix the issues in the isr (git-fixes).
  - clk: davinci: da8xx-cfgchip: Initialize clk_init_data before
    use (git-fixes).
  - decompress_bunzip2: fix rare decompression failure (git-fixes).
  - commit 536a80d

++++ kernel-rt:

  - spi: spidev: add correct compatible for Rohm BH2228FV
    (git-fixes).
  - spi: microchip-core: ensure TX and RX FIFOs are empty at start
    of a transfer (git-fixes).
  - spi: microchip-core: only disable SPI controller when register
    value change requires it (git-fixes).
  - spi: microchip-core: defer asserting chip select until just
    before write to TX FIFO (git-fixes).
  - spi: microchip-core: fix the issues in the isr (git-fixes).
  - clk: davinci: da8xx-cfgchip: Initialize clk_init_data before
    use (git-fixes).
  - decompress_bunzip2: fix rare decompression failure (git-fixes).
  - commit 536a80d

++++ libassuan:

  - update to 3.0.1 (shared library version 9)
    * API change: For new code, which uses libassuan with nPTH, use
    gpgrt_get_syscall_clamp and assuan_control, instead of the
    system_hooks API. Use of ASSUAN_SYSTEM_NPTH is deprecated with
    new API version 3.
    * Various API extensions
    * New socket flags "linger" and "reuseaddr"
  - drop extra gpg-error requirement on -devel, it is autogenerated
  - drop texinfo macro from spec files, handled via file triggers
  - package license texts

++++ regionServiceClientConfigGCE:

  - Version 4.2.0 (jsc#PCT-361)
    + Add IPv6 certs to supprt access of the update infrastructure via
    IPv6 on GCE instances.
    + Add noipv6.patch

------------------------------------------------------------------
------------------  2024-7-27  -  Jul 27 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ALSA: usb-audio: Add a quirk for Sonix HD USB Camera
    (stable-fixes).
  - ALSA: usb-audio: Move HD Webcam quirk to the right place
    (git-fixes).
  - ALSA: usb-audio: Fix microphone sound on HD webcam
    (stable-fixes).
  - commit 07826dc
  - auxdisplay: ht16k33: Drop reference after LED registration
    (git-fixes).
  - ASoC: SOF: ipc4-topology: Preserve the DMA Link ID for ChainDMA
    on unprepare (git-fixes).
  - ASoC: TAS2781: Fix tasdev_load_calibrated_data() (git-fixes).
  - ASoC: Intel: use soc_intel_is_byt_cr() only when IOSF_MBI is
    reachable (git-fixes).
  - ASoC: sof: amd: fix for firmware reload failure in Vangogh
    platform (git-fixes).
  - ASoC: SOF: imx8m: Fix DSP control regmap retrieval (git-fixes).
  - ALSA: hda/realtek: cs35l41: Fixup remaining asus strix models
    (git-fixes).
  - ALSA: ump: Force 1 Group for MIDI1 FBs (git-fixes).
  - ALSA: ump: Don't update FB name for static blocks (git-fixes).
  - drm/amd/amdgpu: Fix uninitialized variable warnings (git-fixes).
  - drm/i915/gt: Do not consider preemption during execlists_dequeue
    for gen8 (git-fixes).
  - drm/i915/dp: Don't switch the LTTPR mode on an active link
    (git-fixes).
  - commit d7e2deb

++++ kernel-rt:

  - ALSA: usb-audio: Add a quirk for Sonix HD USB Camera
    (stable-fixes).
  - ALSA: usb-audio: Move HD Webcam quirk to the right place
    (git-fixes).
  - ALSA: usb-audio: Fix microphone sound on HD webcam
    (stable-fixes).
  - commit 07826dc
  - auxdisplay: ht16k33: Drop reference after LED registration
    (git-fixes).
  - ASoC: SOF: ipc4-topology: Preserve the DMA Link ID for ChainDMA
    on unprepare (git-fixes).
  - ASoC: TAS2781: Fix tasdev_load_calibrated_data() (git-fixes).
  - ASoC: Intel: use soc_intel_is_byt_cr() only when IOSF_MBI is
    reachable (git-fixes).
  - ASoC: sof: amd: fix for firmware reload failure in Vangogh
    platform (git-fixes).
  - ASoC: SOF: imx8m: Fix DSP control regmap retrieval (git-fixes).
  - ALSA: hda/realtek: cs35l41: Fixup remaining asus strix models
    (git-fixes).
  - ALSA: ump: Force 1 Group for MIDI1 FBs (git-fixes).
  - ALSA: ump: Don't update FB name for static blocks (git-fixes).
  - drm/amd/amdgpu: Fix uninitialized variable warnings (git-fixes).
  - drm/i915/gt: Do not consider preemption during execlists_dequeue
    for gen8 (git-fixes).
  - drm/i915/dp: Don't switch the LTTPR mode on an active link
    (git-fixes).
  - commit d7e2deb

++++ vim:

  - Add "Keywords" to gvim.desktop to make searching for gvim easier

------------------------------------------------------------------
------------------  2024-7-26  -  Jul 26 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Update to version 1.48.6:
    + activation: Allow changing controller of exposed active
    connection
    + ovs: wait for the link to be ready before activating
    + policy: assert that the auto-activate list is empty on dispose

++++ aardvark-dns:

  - rust >= 1.70 is required to build more recent versions of this
    package. Also, BuildRequire cargo+rust to prevent conflicts with
    `cargo-packaging`.

++++ kernel-default:

  - ALSA: hda/conexant: Mute speakers at suspend / shutdown
    (bsc#1228269).
  - ALSA: hda/generic: Add a helper to mute speakers at
    suspend/shutdown (bsc#1228269).
  - commit e046d5e
  - Refresh the previous ASoC patch, landed in subsystem tree (bsc#1228269)
  - commit 180425d
  - kABI: tty: add the option to have a tty reject a new ldisc
    (kabi CVE-2024-40966 bsc#1227886).
  - tty: add the option to have a tty reject a new ldisc
    (CVE-2024-40966 bsc#1227886).
  - commit 00113b6
  - fs/file: fix the check in find_next_fd() (git-fixes).
  - commit 3ec6b68
  - erofs: ensure m_llen is reset to 0 if metadata is invalid
    (git-fixes).
  - commit 03e55bf
  - jfs: Fix array-index-out-of-bounds in diFree (git-fixes).
  - commit a89a289
  - hfsplus: fix uninit-value in copy_name (git-fixes).
  - commit 4f0ad7b
  - mISDN: Fix a use after free in hfcmulti_tx() (git-fixes).
  - devres: Fix memory leakage caused by driver API
    devm_free_percpu() (git-fixes).
  - devres: Fix devm_krealloc() wasting memory (git-fixes).
  - kobject_uevent: Fix OOB access within zap_modalias_env()
    (git-fixes).
  - watchdog: rzn1: Convert comma to semicolon (git-fixes).
  - watchdog: rzg2l_wdt: Check return status of pm_runtime_put()
    (git-fixes).
  - watchdog: rzg2l_wdt: Use pm_runtime_resume_and_get()
    (git-fixes).
  - dma: fix call order in dmam_free_coherent (git-fixes).
  - mISDN: fix MISDN_TIME_STAMP handling (git-fixes).
  - commit 69aa862
  - bpf: Fix a potential use-after-free in bpf_link_free()
    (bsc#1227798 CVE-2024-40909).
  - Refresh patches.kabi/bpf-bpf_link-and-bpf_link_ops-kABI-workaround.patch
  - commit 377837f

++++ kernel-rt:

  - ALSA: hda/conexant: Mute speakers at suspend / shutdown
    (bsc#1228269).
  - ALSA: hda/generic: Add a helper to mute speakers at
    suspend/shutdown (bsc#1228269).
  - commit e046d5e
  - Refresh the previous ASoC patch, landed in subsystem tree (bsc#1228269)
  - commit 180425d
  - kABI: tty: add the option to have a tty reject a new ldisc
    (kabi CVE-2024-40966 bsc#1227886).
  - tty: add the option to have a tty reject a new ldisc
    (CVE-2024-40966 bsc#1227886).
  - commit 00113b6
  - fs/file: fix the check in find_next_fd() (git-fixes).
  - commit 3ec6b68
  - erofs: ensure m_llen is reset to 0 if metadata is invalid
    (git-fixes).
  - commit 03e55bf
  - jfs: Fix array-index-out-of-bounds in diFree (git-fixes).
  - commit a89a289
  - hfsplus: fix uninit-value in copy_name (git-fixes).
  - commit 4f0ad7b
  - mISDN: Fix a use after free in hfcmulti_tx() (git-fixes).
  - devres: Fix memory leakage caused by driver API
    devm_free_percpu() (git-fixes).
  - devres: Fix devm_krealloc() wasting memory (git-fixes).
  - kobject_uevent: Fix OOB access within zap_modalias_env()
    (git-fixes).
  - watchdog: rzn1: Convert comma to semicolon (git-fixes).
  - watchdog: rzg2l_wdt: Check return status of pm_runtime_put()
    (git-fixes).
  - watchdog: rzg2l_wdt: Use pm_runtime_resume_and_get()
    (git-fixes).
  - dma: fix call order in dmam_free_coherent (git-fixes).
  - mISDN: fix MISDN_TIME_STAMP handling (git-fixes).
  - commit 69aa862
  - bpf: Fix a potential use-after-free in bpf_link_free()
    (bsc#1227798 CVE-2024-40909).
  - Refresh patches.kabi/bpf-bpf_link-and-bpf_link_ops-kABI-workaround.patch
  - commit 377837f

++++ p11-kit:

  - Added a backport of an upstream commit in p11-kit-d938f4a8a3a2.patch
    to avoid passing an incompatible pointer type to a function which is
    an error by default in GCC 14.

++++ wtmpdb:

  - Update to version 0.13.0+git.20240726:
    * Release version 0.13.0
    * Fix variable overflow and check for it (#15)

++++ python-cryptography:

  - update to 43.0.0:
    * BACKWARDS INCOMPATIBLE: Support for OpenSSL less than 1.1.1e
    has been removed.  Users on older version of OpenSSL will
    need to upgrade.
    * BACKWARDS INCOMPATIBLE: Dropped support for LibreSSL < 3.8.
    * Updated Windows, macOS, and Linux wheels to be compiled with
    OpenSSL 3.3.1.
    * Updated the minimum supported Rust version (MSRV) to 1.65.0,
    from 1.63.0.
    * :func:`~cryptography.hazmat.primitives.asymmetric.rsa.generat
    e_private_key` now enforces a minimum RSA key size of
    1024-bit. Note that 1024-bit is still considered insecure,
    users should generally use a key size of 2048-bits.
    * :func:`~cryptography.hazmat.primitives.serialization.pkcs7.se
    rialize_certificates` now emits ASN.1 that more closely
    follows the recommendations in RFC 2315.
    * Added new :doc:`/hazmat/decrepit/index` module which contains
    outdated and insecure cryptographic primitives. :class:`~cryp
    tography.hazmat.primitives.ciphers.algorithms.CAST5`, :class:
    `~cryptography.hazmat.primitives.ciphers.algorithms.SEED`, :c
    lass:`~cryptography.hazmat.primitives.ciphers.algorithms.IDEA
    `, and :class:`~cryptography.hazmat.primitives.ciphers.algori
    thms.Blowfish`, which were deprecated in 37.0.0, have been
    added to this module. They will be removed from the cipher
    module in 45.0.0.
    * Moved :class:`~cryptography.hazmat.primitives.ciphers.algorit
    hms.TripleDES` and :class:`~cryptography.hazmat.primitives.ci
    phers.algorithms.ARC4` into :doc:`/hazmat/decrepit/index` and
    deprecated them in the cipher module. They will be removed
    from the cipher module in 48.0.0.
    * Added support for deterministic
    :class:`~cryptography.hazmat.primitives.asymmetric.ec.ECDSA`
    (RFC 6979)
    * Added support for client certificate verification to the
    :mod:`X.509 path validation <cryptography.x509.verification>`
    APIs in the form of
    :class:`~cryptography.x509.verification.ClientVerifier`,
    :class:`~cryptography.x509.verification.VerifiedClient`, and
    PolicyBuilder :meth:`~cryptography.x509.verification.PolicyBu
    ilder.build_client_verifier`.
    * Added Certificate :attr:`~cryptography.x509.Certificate.publi
    c_key_algorithm_oid` and Certificate Signing Request :attr:`~
    cryptography.x509.CertificateSigningRequest.public_key_algori
    thm_oid` to determine the
    :class:`~cryptography.hazmat._oid.PublicKeyAlgorithmOID`
    Object Identifier of the public key found inside the
    certificate.
    * Added :attr:`~cryptography.x509.InvalidityDate.invalidity_dat
    e_utc`, a timezone-aware alternative to the naïve datetime
    attribute
    :attr:`~cryptography.x509.InvalidityDate.invalidity_date`.
    * Added support for parsing empty DN string in
    :meth:`~cryptography.x509.Name.from_rfc4514_string`.
    * Added the following properties that return timezone-aware
    datetime objects:
    :meth:`~cryptography.x509.ocsp.OCSPResponse.produced_at_utc`,
    :meth:`~cryptography.x509.ocsp.OCSPResponse.revocation_time_u
    tc`,
    :meth:`~cryptography.x509.ocsp.OCSPResponse.this_update_utc`,
    :meth:`~cryptography.x509.ocsp.OCSPResponse.next_update_utc`,
    :meth:`~cryptography.x509.ocsp.OCSPSingleResponse.revocation_
    time_utc`, :meth:`~cryptography.x509.ocsp.OCSPSingleResponse.
    this_update_utc`, :meth:`~cryptography.x509.ocsp.OCSPSingleRe
    sponse.next_update_utc`, These are timezone-aware variants of
    existing properties that return naïve datetime objects.
    * Added :func:`~cryptography.hazmat.primitives.asymmetric.rsa.r
    sa_recover_private_exponent`
    * Added :meth:`~cryptography.hazmat.primitives.ciphers.CipherCo
    ntext.reset_nonce` for altering the nonce of a cipher context
    without initializing a new instance. See the docs for
    additional restrictions.
    * :class:`~cryptography.x509.NameAttribute` now raises an
    exception when attempting to create a common name whose
    length is shorter or longer than RFC 5280 permits.
    * Added basic support for PKCS7 encryption (including SMIME)
    via :class:`~cryptography.hazmat.primitives.serialization.pkc
    s7.PKCS7EnvelopeBuilder`.
  - add use-offline-build.patch

++++ regionServiceClientConfigEC2:

  - Update to version 4.3.0 (bsc#1228363)
    + The IPv6 cert was switched up for the region server running in us-west-2
    and as such the SSL handshake was failing. Drop the incorrect cert
    and add the correct cert.
  - Switch the patch syntax away form the deprecated shorthand macro

++++ selinux-policy:

  - Enable sap module
  - Add equivalency in file_contexts.subs_dist
    * /bin /usr/bin
    * /sbin /usr/bin
    * /usr/sbin /usr/bin
    * /var/run /run
    * /var/lock /run/lock
  - Move to %posttrans to ensure selinux-policy got updated before
    the commands run (bsc#1221720)
  - Remove "Reference" from the package description. It's not the
    reference policy, but the Fedora branch of the policy
  - Update to version 20240604+git230.eb718617:
    * Initial policy for grub2 snapper plugin (bsc#1228205)
    * Set microos autorelabel script to systemd_autorelabel_generator_t
    * Allow systemd_generator to write kmsg
    * Initial policy for systemd growpart-generator (bsc#1226824)
    * Allow systemd_getty_generator_t read /proc/1/environ
    * Allow systemd_getty_generator_t to read and write to tty_device_t (bsc#1226888)
    * Change fc in rebootmgr module for /sbin -> /usr/bin
    * Change fc in rpm module for /sbin -> /usr/bin
    * Change fc in rsync module for /sbin -> /usr/bin
    * Change fc in wicked module for /sbin -> /usr/bin
    * Allow manage dosfs_t files to snapperd
    * Confine libvirt-dbus
    * Allow virtqemud the kill capability in user namespace
    * Allow rshim get options of the netlink class for KOBJECT_UEVENT family
    * Allow dhcpcd the kill capability
    * Allow systemd-networkd list /var/lib/systemd/network
    * Allow sysadm_t run systemd-nsresourced bpf programs
    * Update policy for systemd generators interactions
    * Allow create memory.pressure files with cgroup_memory_pressure_t
    * Add support for libvirt hooks
    * Allow certmonger read and write tpm devices
    * Allow all domains to connect to systemd-nsresourced over a unix socket
    * Allow systemd-machined read the vsock device
    * Update policy for systemd generators
    * Allow ptp4l_t request that the kernel load a kernel module
    * Allow sbd to trace processes in user namespace
    * Allow request-key execute scripts
    * Update policy for haproxyd
    * Add auth_rw_wtmpdb_login_records to domains using auth_manage_login_records
    * Add auth_rw_wtmpdb_login_records to modules
    * Allow xdm_t to read-write to wtmpdb (bsc#1225984)
    * Introduce types for wtmpdb and rw interface
    * Introduce wtmp_file_type attribute
    * Update policy for systemd-nsresourced
    * Correct sbin-related file context entries
    * Allow login_userdomain execute systemd-tmpfiles in the caller domain
    * Allow virt_driver_domain read files labeled unconfined_t
    * Allow virt_driver_domain dbus chat with policykit
    * Allow virtqemud manage nfs files when virt_use_nfs boolean is on
    * Add rules for interactions between generators
    * Label memory.pressure files with cgroup_memory_pressure_t
    * Revert "Allow some systemd services write to cgroup files"
    * Revert "Add policy for wtmpdb (bsc#1210717)"
    * Allow gnome control center to set autologin (bsc#1222978)
    * Update policy for systemd-nsresourced
    * Label /usr/bin/ntfsck with fsadm_exec_t
    * Allow systemd_fstab_generator_t read tmpfs files
    * Update policy for systemd-nsresourced
    * Dontaudit xdm_t to getattr on root_t (bsc#1223145)
    * Alias /usr/sbin to /usr/bin and change all /usr/sbin paths to /usr/bin
    * Remove a few lines duplicated between {dkim,milter}.fc
    * Alias /bin → /usr/bin and remove redundant paths
    * Drop duplicate line for /usr/sbin/unix_chkpwd
    * Drop duplicate paths for /usr/sbin
    * Allow systemd_fstab_generator_t read tmpfs files (bsc#1223599)
    * Update systemd-generator policy
    * Remove permissive domain for bootupd_t
    * Remove permissive domain for coreos_installer_t
    * Remove permissive domain for afterburn_t
    * Add the sap module to modules.conf
    * Move unconfined_domain(sap_unconfined_t) to an optional block
    * Create the sap module
    * Allow systemd-coredumpd sys_admin and sys_resource capabilities
    * Allow systemd-coredump read nsfs files
    * Allow generators auto file transition only for plain files
    * Allow systemd-hwdb write to the kernel messages device
    * Escape "interface" as a file name in a virt filetrans pattern
    * Allow gnome-software work for login_userdomain
    * Allow systemd-machined manage runtime sockets
    * Revert "Allow systemd-machined manage runtime sockets"
    * Allow postfix_domain connect to postgresql over a unix socket
    * Dontaudit systemd-coredump sys_admin capability
    * Allow all domains read and write z90crypt device
    * Allow tpm2 generator setfscreate
    * Allow systemd (PID 1) manage systemd conf files
    * Allow pulseaudio map its runtime files
    * Update policy for getty-generator
    * Allow systemd-hwdb send messages to kernel unix datagram sockets
    * Allow systemd-machined manage runtime sockets
    * Allow fstab-generator create unit file symlinks
    * Update policy for cryptsetup-generator
    * Update policy for fstab-generator
    * Allow virtqemud read vm sysctls
    * Allow collectd to trace processes in user namespace
    * Allow bootupd search efivarfs dirs
    * Add policy for systemd-mountfsd
    * Add policy for systemd-nsresourced
    * Update policy generators
    * Add policy for anaconda-generator
    * Update policy for fstab and gpt generators
    * Add policy for kdump-dep-generator
    * Add policy for a generic generator
    * Add policy for tpm2 generator
    * Add policy for ssh-generator
    * Add policy for second batch of generators
    * Update policy for systemd generators
    * ci: Adjust Cockpit test plans
    * Allow journald read systemd config files and directories
    * Allow systemd_domain read systemd_conf_t dirs
    * Fix bad Python regexp escapes
    * Allow fido services connect to postgres database
    * Revert "Update the README.md file with the c10s branch information"
    * Update the README.md file with the c10s branch information
    * Allow postfix smtpd map aliases file
    * Ensure dbus communication is allowed bidirectionally
    * Label systemd configuration files with systemd_conf_t
    * Label /run/systemd/machine with systemd_machined_var_run_t
    * Allow systemd-hostnamed read the vsock device
    * Allow sysadm execute dmidecode using sudo
    * Allow sudodomain list files in /var
    * Allow setroubleshootd get attributes of all sysctls
    * Allow various services read and write z90crypt device
    * Allow nfsidmap connect to systemd-homed
    * Allow sandbox_x_client_t dbus chat with accountsd
    * Allow system_cronjob_t dbus chat with avahi_t
    * Allow staff_t the io_uring sqpoll permission
    * Allow staff_t use the io_uring API
    * Add support for secretmem anon inode
    * Allow virtqemud read vfio devices
    * Allow virtqemud get attributes of a tmpfs filesystem
    * Allow svirt_t read vm sysctls
    * Allow virtqemud create and unlink files in /etc/libvirt/
    * Allow virtqemud get attributes of cifs files
    * Allow virtqemud get attributes of filesystems with extended attributes
    * Allow virtqemud get attributes of NFS filesystems
    * Allow virt_domain read and write usb devices conditionally
    * Allow virtstoraged use the io_uring API
    * Allow virtstoraged execute lvm programs in the lvm domain
    * Allow virtnodevd_t map /var/lib files
    * Allow svirt_tcg_t map svirt_image_t files
    * Allow abrt-dump-journal-core connect to systemd-homed
    * Allow abrt-dump-journal-core connect to systemd-machined
    * Allow sssd create and use io_uring
    * Allow selinux-relabel-generator create units dir
    * Allow dbus-broker read/write inherited user ttys
    * Define transitions for /run/libvirt/common and /run/libvirt/qemu
    * Allow systemd-sleep read raw disk data
    * Allow numad to trace processes in user namespace
    * Allow abrt-dump-journal-core connect to systemd-userdbd
    * Allow plymouthd read efivarfs files
    * Update the auth_dontaudit_read_passwd_file() interface
    * Label /dev/mmcblk0rpmb character device with removable_device_t
    * fix hibernate on btrfs swapfile (F40)
    * Allow nut to statfs()
    * Allow system dbusd service status systemd services
    * Allow systemd-timedated get the timemaster service status
    * Allow keyutils-dns-resolver connect to the system log service
    * Allow qemu-ga read vm sysctls
    * postfix: allow qmgr to delete mails in bounce/ directory
    * Remove duplicate in sysnetwork.fc
    * Rename /var/run/wicked* to /run/wicked*
    * Remove /var/run/rsyslog/additional-log-sockets.conf from logging.fc
    * policy: support pidfs
    * Confine selinux-autorelabel-generator.sh
    * Allow logwatch_mail_t read/write to init over a unix stream socket
    * Allow logwatch read logind sessions files
    * files_dontaudit_getattr_tmpfs_files allowed the access and didn't dontaudit it
    * files_dontaudit_mounton_modules_object allowed the access and didn't dontaudit it
    * Allow NetworkManager the sys_ptrace capability in user namespace
    * dontaudit execmem for modemmanager
    * Allow dhcpcd use unix_stream_socket
    * Allow dhcpc read /run/netns files
    * Update mmap_rw_file_perms to include the lock permission
    * Allow plymouthd log during shutdown
    * Add logging_watch_all_log_dirs() and logging_watch_all_log_files()
    * Allow journalctl_t read filesystem sysctls
    * Allow cgred_t to get attributes of cgroup filesystems
    * Allow wdmd read hardware state information
    * Allow wdmd list the contents of the sysfs directories
    * Allow linuxptp configure phc2sys and chronyd over a unix domain socket
    * Allow sulogin relabel tty1
    * Dontaudit sulogin the checkpoint_restore capability
    * Modify sudo_role_template() to allow getpgid
    * Allow userdomain get attributes of files on an nsfs filesystem
    * Allow opafm create NFS files and directories
    * Allow virtqemud create and unlink files in /etc/libvirt/
    * Allow virtqemud domain transition on swtpm execution
    * Add the swtpm.if interface file for interactions with other domains
    * Allow samba to have dac_override capability
    * systemd: allow sys_admin capability for systemd_notify_t
    * systemd: allow systemd_notify_t to send data to kernel_t datagram sockets
    * Allow thumb_t to watch and watch_reads mount_var_run_t
    * Allow krb5kdc_t map krb5kdc_principal_t files
    * Allow unprivileged confined user dbus chat with setroubleshoot
    * Allow login_userdomain map files in /var
    * Allow wireguard work with firewall-cmd
    * Differentiate between staff and sysadm when executing crontab with sudo
    * Add crontab_admin_domtrans interface
    * Allow abrt_t nnp domain transition to abrt_handle_event_t
    * Allow xdm_t to watch and watch_reads mount_var_run_t
    * Dontaudit subscription manager setfscreate and read file contexts
    * Don't audit crontab_domain write attempts to user home
    * Transition from sudodomains to crontab_t when executing crontab_exec_t
    * Add crontab_domtrans interface
    * Fix label of pseudoterminals created from sudodomain
    * Allow utempter_t use ptmx
    * Dontaudit rpmdb attempts to connect to sssd over a unix stream socket
    * Allow admin user read/write on fixed_disk_device_t
    * Only allow confined user domains to login locally without unconfined_login
    * Add userdom_spec_domtrans_confined_admin_users interface
    * Only allow admindomain to execute shell via ssh with ssh_sysadm_login
    * Add userdom_spec_domtrans_admin_users interface
    * Move ssh dyntrans to unconfined inside unconfined_login tunable policy
    * Update ssh_role_template() for user ssh-agent type
    * Allow init to inherit system DBus file descriptors
    * Allow init to inherit fds from syslogd
    * Allow any domain to inherit fds from rpm-ostree
    * Update afterburn policy
    * Allow init_t nnp domain transition to abrtd_t
    * Rename all /var/lock file context entries to /run/lock
    * Rename all /var/run file context entries to /run
  - Update container-selinux to a68865582e123856c191fe0ecbbba9301758e591

------------------------------------------------------------------
------------------  2024-7-25  -  Jul 25 2024  -------------------
------------------------------------------------------------------

++++ gnutls:

  - Update to 3.8.6:
    * libgnutls: PBMAC1 is now supported as a MAC mechanism for PKCS#12
    To be compliant with FIPS 140-3, PKCS#12 files with MAC based on
    PBKDF2 (PBMAC1) is now supported, according to the specification
    proposed in draft-ietf-lamps-pkcs12-pbmac1.
    * libgnutls: SHA3 extendable output functions (XOF) are now supported
    SHA3 XOF, SHAKE128 and SHAKE256, are now usable through a new
    public API gnutls_hash_squeeze.
    * API and ABI modifications:
  - gnutls_pkcs12_generate_mac3: New function
  - gnutls_pkcs12_flags_t: New enum
  - gnutls_hash_squeeze: New function
    * Rebase patches:
  - gnutls-FIPS-140-3-references.patch
  - gnutls-FIPS-jitterentropy.patch

++++ ignition:

  - Apply (temporary) upstream patch from fedora-coreos-config for
    compatibility with systemd 256.

++++ kernel-default:

  - drm/amd/display: Fix array-index-out-of-bounds in
    dml2/FCLKChangeSupport (stable-fixes).
  - drm/amd/display: Update efficiency bandwidth for dcn351
    (stable-fixes).
  - drm/ttm: Always take the bo delayed cleanup path for imported
    bos (git-fixes).
  - drm/amd/display: change dram_clock_latency to 34us for dcn35
    (stable-fixes).
  - drm/amdgpu: fix locking scope when flushing tlb (stable-fixes).
  - wifi: mac80211: Avoid address calculations via out of bounds
    array indexing (stable-fixes).
  - drm/amdkfd: Let VRAM allocations go to GTT domain on small APUs
    (stable-fixes).
  - drm/amd/display: ASSERT when failing to find index by
    plane/stream id (stable-fixes).
  - drm/amd/display: Fix overlapping copy within
    dml_core_mode_programming (stable-fixes).
  - drm/amd/display: Skip pipe if the pipe idx not set properly
    (stable-fixes).
  - drm/amd/display: Workaround register access in idle race with
    cursor (stable-fixes).
  - commit 830869c
  - ALSA: pcm_dmaengine: Don't synchronize DMA channel when DMA
    is paused (git-fixes).
  - commit aadeb44
  - spi: mux: set ctlr->bits_per_word_mask (stable-fixes).
  - wifi: iwlwifi: mvm: don't wake up rx_sync_waitq upon RFKILL
    (git-fixes).
  - wifi: iwlwifi: properly set WIPHY_FLAG_SUPPORTS_EXT_KEK_KCK
    (stable-fixes).
  - wifi: mac80211: disable softirqs for queued frame handling
    (git-fixes).
  - wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
    (stable-fixes).
  - wifi: cfg80211: wext: set ssids=NULL for passive scans
    (git-fixes).
  - wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()
    (stable-fixes).
  - wifi: iwlwifi: mvm: Fix scan abort handling with HW rfkill
    (stable-fixes).
  - wifi: iwlwifi: mvm: properly set 6 GHz channel direct probe
    option (stable-fixes).
  - wifi: iwlwifi: mvm: handle BA session teardown in RF-kill
    (stable-fixes).
  - wifi: iwlwifi: mvm: Handle BIGTK cipher in kek_kck cmd
    (stable-fixes).
  - wifi: iwlwifi: mvm: remove stale STA link data during restart
    (stable-fixes).
  - wifi: iwlwifi: mvm: d3: fix WoWLAN command version lookup
    (stable-fixes).
  - wifi: cfg80211: fix 6 GHz scan request building (stable-fixes).
  - wifi: mac80211: handle tasklet frames before stopping
    (stable-fixes).
  - wifi: mac80211: apply mcast rate only if interface is up
    (stable-fixes).
  - wifi: mac80211: mesh: init nonpeer_pm to active by default in
    mesh sdata (stable-fixes).
  - tools/power/cpupower: Fix Pstate frequency reporting on AMD
    Family 1Ah CPUs (stable-fixes).
  - tools/power turbostat: Remember global max_die_id
    (stable-fixes).
  - commit 37df9b4
  - phy: cadence-torrent: Check return value on register read
    (git-fixes).
  - kbuild: avoid build error when single DTB is turned into
    composite DTB (git-fixes).
  - remoteproc: stm32_rproc: Fix mailbox interrupts queuing
    (git-fixes).
  - remoteproc: k3-r5: Fix IPC-only mode detection (git-fixes).
  - remoteproc: imx_rproc: Fix refcount mistake in
    imx_rproc_addr_init (git-fixes).
  - remoteproc: imx_rproc: Skip over memory region when node value
    is NULL (git-fixes).
  - mailbox: mtk-cmdq: Move devm_mbox_controller_register() after
    devm_pm_runtime_enable() (git-fixes).
  - power: supply: ingenic: Fix some error handling paths in
    ingenic_battery_get_property() (git-fixes).
  - power: supply: ab8500: Fix error handling when calling
    iio_read_channel_processed() (git-fixes).
  - spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices
    (stable-fixes).
  - net: mac802154: Fix racy device stats updates by DEV_STATS_INC()
    and DEV_STATS_ADD() (stable-fixes).
  - platform/x86: lg-laptop: Use ACPI device handle when evaluating
    WMAB/WMBB (stable-fixes).
  - platform/x86: lg-laptop: Change ACPI device id (stable-fixes).
  - platform/x86: lg-laptop: Remove LGEX0815 hotkey handling
    (stable-fixes).
  - platform/x86: wireless-hotkey: Add support for LG Airplane
    Button (stable-fixes).
  - net: usb: qmi_wwan: add Telit FN912 compositions (stable-fixes).
  - Input: ads7846 - use spi_device_id table (stable-fixes).
  - mei: demote client disconnect warning on suspend to debug
    (stable-fixes).
  - kconfig: remove wrong expr_trans_bool() (stable-fixes).
  - kconfig: gconf: give a proper initial state to the Save button
    (stable-fixes).
  - commit f6cec75
  - dmaengine: ti: k3-udma: Fix BCHAN count with UHC and HC channels
    (git-fixes).
  - docs: crypto: async-tx-api: fix broken code example (git-fixes).
  - drm/radeon: check bo_va->bo is non-NULL before using it
    (stable-fixes).
  - drm/amd/display: Fix refresh rate range for some panel
    (stable-fixes).
  - drm/amd/display: Account for cursor prefetch BW in DML1 mode
    support (stable-fixes).
  - drm/amd/display: Add refresh rate range check (stable-fixes).
  - gpio: pca953x: fix pca953x_irq_bus_sync_unlock race
    (stable-fixes).
  - can: kvaser_usb: fix return value for hif_usb_send_regout
    (stable-fixes).
  - Input: xpad - add support for ASUS ROG RAIKIRI PRO
    (stable-fixes).
  - Input: i8042 - add Ayaneo Kun to i8042 quirk table
    (stable-fixes).
  - Input: elantech - fix touchpad state on resume for Lenovo N24
    (stable-fixes).
  - drm/vmwgfx: Fix missing HYPERVISOR_GUEST dependency
    (stable-fixes).
  - drm/amdgpu: Indicate CU havest info to CP (stable-fixes).
  - drm/exynos: dp: drop driver owner initialization (stable-fixes).
  - drm/mediatek: Call drm_atomic_helper_shutdown() at shutdown time
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Aya Neo KUN
    (stable-fixes).
  - HID: Ignore battery for ELAN touchscreens 2F2C and 4116
    (stable-fixes).
  - input: Add support for "Do Not Disturb" (stable-fixes).
  - input: Add event code for accessibility key (stable-fixes).
  - Input: silead - Always support 10 fingers (stable-fixes).
  - commit a5bc4da
  - Bluetooth: btnxpuart: Enable Power Save feature on startup
    (stable-fixes).
  - Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
    (stable-fixes).
  - ASoC: amd: yc: Fix non-functional mic on ASUS M5602RA
    (stable-fixes).
  - ASoC: rt722-sdca-sdw: add debounce time for type detection
    (stable-fixes).
  - ASoC: SOF: sof-audio: Skip unprepare for in-use widgets on
    error rollback (stable-fixes).
  - ASoC: ti: davinci-mcasp: Set min period size using FIFO config
    (stable-fixes).
  - ALSA: dmaengine: Synchronize dma channel after drop()
    (stable-fixes).
  - ASoC: ti: omap-hdmi: Fix too long driver name (stable-fixes).
  - ASoC: topology: Do not assign fields that are already set
    (stable-fixes).
  - ASoC: topology: Fix references to freed memory (stable-fixes).
  - bytcr_rt5640 : inverse jack detect for Archos 101 cesium
    (stable-fixes).
  - ASoC: rt722-sdca-sdw: add silence detection register as volatile
    (stable-fixes).
  - ALSA: dmaengine_pcm: terminate dmaengine before synchronize
    (stable-fixes).
  - ALSA: hda/relatek: Enable Mute LED on HP Laptop 15-gw0xxx
    (stable-fixes).
  - ALSA: PCM: Allow resume only for suspended streams
    (stable-fixes).
  - ACPI: EC: Avoid returning AE_OK on errors in address space
    handler (stable-fixes).
  - ACPI: EC: Abort address space access upon error (stable-fixes).
  - commit aa63c91
  - config/arm64: Enable CoreSight PMU drivers (bsc#1228289 jsc#PED-7859)
  - commit f80ff65
  - platform/x86: x86-android-tablets: Unregister devices in
    reverse order (CVE-2024-40975 bsc#1227926).
  - commit 16439fd
  - Avoid hw_desc array overrun in dw-axi-dmac (CVE-2024-40970
    bsc#1227899).
  - commit 8f7016c
  - ASoC: amd: yc: Support mic on Lenovo Thinkpad E16 Gen 2
    (bsc#1228269).
  - commit 78e0f74

++++ kernel-rt:

  - drm/amd/display: Fix array-index-out-of-bounds in
    dml2/FCLKChangeSupport (stable-fixes).
  - drm/amd/display: Update efficiency bandwidth for dcn351
    (stable-fixes).
  - drm/ttm: Always take the bo delayed cleanup path for imported
    bos (git-fixes).
  - drm/amd/display: change dram_clock_latency to 34us for dcn35
    (stable-fixes).
  - drm/amdgpu: fix locking scope when flushing tlb (stable-fixes).
  - wifi: mac80211: Avoid address calculations via out of bounds
    array indexing (stable-fixes).
  - drm/amdkfd: Let VRAM allocations go to GTT domain on small APUs
    (stable-fixes).
  - drm/amd/display: ASSERT when failing to find index by
    plane/stream id (stable-fixes).
  - drm/amd/display: Fix overlapping copy within
    dml_core_mode_programming (stable-fixes).
  - drm/amd/display: Skip pipe if the pipe idx not set properly
    (stable-fixes).
  - drm/amd/display: Workaround register access in idle race with
    cursor (stable-fixes).
  - commit 830869c
  - ALSA: pcm_dmaengine: Don't synchronize DMA channel when DMA
    is paused (git-fixes).
  - commit aadeb44
  - spi: mux: set ctlr->bits_per_word_mask (stable-fixes).
  - wifi: iwlwifi: mvm: don't wake up rx_sync_waitq upon RFKILL
    (git-fixes).
  - wifi: iwlwifi: properly set WIPHY_FLAG_SUPPORTS_EXT_KEK_KCK
    (stable-fixes).
  - wifi: mac80211: disable softirqs for queued frame handling
    (git-fixes).
  - wifi: cfg80211: wext: add extra SIOCSIWSCAN data check
    (stable-fixes).
  - wifi: cfg80211: wext: set ssids=NULL for passive scans
    (git-fixes).
  - wifi: mac80211: fix UBSAN noise in ieee80211_prep_hw_scan()
    (stable-fixes).
  - wifi: iwlwifi: mvm: Fix scan abort handling with HW rfkill
    (stable-fixes).
  - wifi: iwlwifi: mvm: properly set 6 GHz channel direct probe
    option (stable-fixes).
  - wifi: iwlwifi: mvm: handle BA session teardown in RF-kill
    (stable-fixes).
  - wifi: iwlwifi: mvm: Handle BIGTK cipher in kek_kck cmd
    (stable-fixes).
  - wifi: iwlwifi: mvm: remove stale STA link data during restart
    (stable-fixes).
  - wifi: iwlwifi: mvm: d3: fix WoWLAN command version lookup
    (stable-fixes).
  - wifi: cfg80211: fix 6 GHz scan request building (stable-fixes).
  - wifi: mac80211: handle tasklet frames before stopping
    (stable-fixes).
  - wifi: mac80211: apply mcast rate only if interface is up
    (stable-fixes).
  - wifi: mac80211: mesh: init nonpeer_pm to active by default in
    mesh sdata (stable-fixes).
  - tools/power/cpupower: Fix Pstate frequency reporting on AMD
    Family 1Ah CPUs (stable-fixes).
  - tools/power turbostat: Remember global max_die_id
    (stable-fixes).
  - commit 37df9b4
  - phy: cadence-torrent: Check return value on register read
    (git-fixes).
  - kbuild: avoid build error when single DTB is turned into
    composite DTB (git-fixes).
  - remoteproc: stm32_rproc: Fix mailbox interrupts queuing
    (git-fixes).
  - remoteproc: k3-r5: Fix IPC-only mode detection (git-fixes).
  - remoteproc: imx_rproc: Fix refcount mistake in
    imx_rproc_addr_init (git-fixes).
  - remoteproc: imx_rproc: Skip over memory region when node value
    is NULL (git-fixes).
  - mailbox: mtk-cmdq: Move devm_mbox_controller_register() after
    devm_pm_runtime_enable() (git-fixes).
  - power: supply: ingenic: Fix some error handling paths in
    ingenic_battery_get_property() (git-fixes).
  - power: supply: ab8500: Fix error handling when calling
    iio_read_channel_processed() (git-fixes).
  - spi: imx: Don't expect DMA for i.MX{25,35,50,51,53} cspi devices
    (stable-fixes).
  - net: mac802154: Fix racy device stats updates by DEV_STATS_INC()
    and DEV_STATS_ADD() (stable-fixes).
  - platform/x86: lg-laptop: Use ACPI device handle when evaluating
    WMAB/WMBB (stable-fixes).
  - platform/x86: lg-laptop: Change ACPI device id (stable-fixes).
  - platform/x86: lg-laptop: Remove LGEX0815 hotkey handling
    (stable-fixes).
  - platform/x86: wireless-hotkey: Add support for LG Airplane
    Button (stable-fixes).
  - net: usb: qmi_wwan: add Telit FN912 compositions (stable-fixes).
  - Input: ads7846 - use spi_device_id table (stable-fixes).
  - mei: demote client disconnect warning on suspend to debug
    (stable-fixes).
  - kconfig: remove wrong expr_trans_bool() (stable-fixes).
  - kconfig: gconf: give a proper initial state to the Save button
    (stable-fixes).
  - commit f6cec75
  - dmaengine: ti: k3-udma: Fix BCHAN count with UHC and HC channels
    (git-fixes).
  - docs: crypto: async-tx-api: fix broken code example (git-fixes).
  - drm/radeon: check bo_va->bo is non-NULL before using it
    (stable-fixes).
  - drm/amd/display: Fix refresh rate range for some panel
    (stable-fixes).
  - drm/amd/display: Account for cursor prefetch BW in DML1 mode
    support (stable-fixes).
  - drm/amd/display: Add refresh rate range check (stable-fixes).
  - gpio: pca953x: fix pca953x_irq_bus_sync_unlock race
    (stable-fixes).
  - can: kvaser_usb: fix return value for hif_usb_send_regout
    (stable-fixes).
  - Input: xpad - add support for ASUS ROG RAIKIRI PRO
    (stable-fixes).
  - Input: i8042 - add Ayaneo Kun to i8042 quirk table
    (stable-fixes).
  - Input: elantech - fix touchpad state on resume for Lenovo N24
    (stable-fixes).
  - drm/vmwgfx: Fix missing HYPERVISOR_GUEST dependency
    (stable-fixes).
  - drm/amdgpu: Indicate CU havest info to CP (stable-fixes).
  - drm/exynos: dp: drop driver owner initialization (stable-fixes).
  - drm/mediatek: Call drm_atomic_helper_shutdown() at shutdown time
    (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Aya Neo KUN
    (stable-fixes).
  - HID: Ignore battery for ELAN touchscreens 2F2C and 4116
    (stable-fixes).
  - input: Add support for "Do Not Disturb" (stable-fixes).
  - input: Add event code for accessibility key (stable-fixes).
  - Input: silead - Always support 10 fingers (stable-fixes).
  - commit a5bc4da
  - Bluetooth: btnxpuart: Enable Power Save feature on startup
    (stable-fixes).
  - Bluetooth: hci_core: cancel all works upon hci_unregister_dev()
    (stable-fixes).
  - ASoC: amd: yc: Fix non-functional mic on ASUS M5602RA
    (stable-fixes).
  - ASoC: rt722-sdca-sdw: add debounce time for type detection
    (stable-fixes).
  - ASoC: SOF: sof-audio: Skip unprepare for in-use widgets on
    error rollback (stable-fixes).
  - ASoC: ti: davinci-mcasp: Set min period size using FIFO config
    (stable-fixes).
  - ALSA: dmaengine: Synchronize dma channel after drop()
    (stable-fixes).
  - ASoC: ti: omap-hdmi: Fix too long driver name (stable-fixes).
  - ASoC: topology: Do not assign fields that are already set
    (stable-fixes).
  - ASoC: topology: Fix references to freed memory (stable-fixes).
  - bytcr_rt5640 : inverse jack detect for Archos 101 cesium
    (stable-fixes).
  - ASoC: rt722-sdca-sdw: add silence detection register as volatile
    (stable-fixes).
  - ALSA: dmaengine_pcm: terminate dmaengine before synchronize
    (stable-fixes).
  - ALSA: hda/relatek: Enable Mute LED on HP Laptop 15-gw0xxx
    (stable-fixes).
  - ALSA: PCM: Allow resume only for suspended streams
    (stable-fixes).
  - ACPI: EC: Avoid returning AE_OK on errors in address space
    handler (stable-fixes).
  - ACPI: EC: Abort address space access upon error (stable-fixes).
  - commit aa63c91
  - config/arm64: Enable CoreSight PMU drivers (bsc#1228289 jsc#PED-7859)
  - commit f80ff65
  - platform/x86: x86-android-tablets: Unregister devices in
    reverse order (CVE-2024-40975 bsc#1227926).
  - commit 16439fd
  - Avoid hw_desc array overrun in dw-axi-dmac (CVE-2024-40970
    bsc#1227899).
  - commit 8f7016c
  - ASoC: amd: yc: Support mic on Lenovo Thinkpad E16 Gen 2
    (bsc#1228269).
  - commit 78e0f74

++++ colord:

  - Build -D_FILE_OFFSET_BITS=64 and -D_TIME_BITS=64 in order to avoid
    wrong type being passed to gmtime_r on i586 (and perhaps other 32bit
    targets). [boo#1228331]

++++ mozilla-nss:

  - update to NSS 3.101.2
    * bmo#1905691 - ChaChaXor to return after the function

++++ libxml2:

  - Update to version 2.12.9:
    + Security: (CVE-2024-40896) Fix XXE protection in downstream
    code.
    + Improvements: Undeprecate xmlKeepBlanksDefault.

++++ libxml2-python:

  - Update to version 2.12.9:
    + Security: (CVE-2024-40896) Fix XXE protection in downstream
    code.
    + Improvements: Undeprecate xmlKeepBlanksDefault.

------------------------------------------------------------------
------------------  2024-7-24  -  Jul 24 2024  -------------------
------------------------------------------------------------------

++++ curl:

  - Update to 8.9.0:
    * Security fixes:
  - [bsc#1227888, CVE-2024-6197] curl: freeing stack buffer
    in utf8asn1str
  - [bsc#1228260, CVE-2024-6874] idn: tweak buffer use when
    converting with macidn
    * Changes:
  - curl: add --ip-tos (IP Type of Service / Traffic Class)
  - curl: add --mptcp
  - curl: add --vlan-priority
  - curl: add -w '%{num_retries}
  - gnutls: support CA caching
  - mbedtls: support CURLOPT_CERTINFO
  - noproxy: patterns need to be comma separated
  - socket: support binding to interface *AND* IP
  - tcpkeepalive: add CURLOPT_TCP_KEEPCNT and --keepalive-cnt
  - urlapi: add CURLU_NO_GUESS_SCHEME
  - wolfssl: support CA caching
    * Bugfixes:
  - connection: shutdown TLS (for FTP) better
  - curl-config: revert to backticks to support old target envs
  - curl: allow etag and content-disposition for 3xx reply
  - curl: bsearch the --write-out variable name
  - curl: check for --disable case *sensitively*
  - doh: fix leak and zero-length HTTPS RR crash
  - file: separate fake headers and body with a stand-alone CRLF
  - ftp: remove redundant null pointer check in loop condition
  - gnutls: improve TLS shutdown
  - gnutls: pass in SNI name, not hostname when checking cert
  - hostip: skip error check for infallible function call
  - http/3: add shutdown support
  - http/3: resume upload on ack if we have more data to send
  - lib: add a few DEBUGASSERT(data) to aid code analyzers
  - lib: add failure reason on bind errors
  - lib: graceful connection shutdown
  - lib: xfer_setup and non-blocking shutdown
  - multi: add multi->proto_hash, a key-value store for protocol data
  - multi: do a final progress update on connect failure
  - multi: fix multi_wait() timeout handling
  - multi: fix pollset during RESOLVING phase
  - ngtcp2+quictls: fix cert-status use
  - noproxy: test bad ipv6 net size first
  - openssl/gnutls: rectify the TLS version checks for QUIC
  - openssl: fix hostname handling when using ECH
  - openssl: stop duplicate ssl key logging for legacy OpenSSL
  - quic: enable UDP GRO
  - quic: openssl quic, cmake and doc version update to 3.3.0
  - quic: require at least OpenSSL 3.3 for QUIC
  - quic: update to quiche 0.22.0
  - smtp: for starttls, do full upgrade
  - tool_operate: avoid explicitly setting verifypeer to 1
  - tool_writeout: get certinfo only when needing it
  - transfer: avoid polling socket every transfer loop
  - transfer: conn close on paused upload
  - transfer: do not use EXPIRE_NOW while blocked
  - transfer: remove curl_upload_refill_watermark, no longer used
  - transfer: set CSELECT_IN if there is data pending
  - url: allow DoH transfers to override max connection limit
  - x509asn1: add some common ECDSA OIDs
  - x509asn1: ASN1tostr() should fail when 'constructed' is set
  - x509asn1: fallback to dotted OID representation
  - x509asn1: prevent NULL dereference
  - x509asn1: remove superfluous free()
  - x509asn1: remove two static variables
    * Rebase libcurl-ocloexec.patch
    * Remove curl-make-install-curl-config.patch upstream

++++ docker-compose:

  - Update to version 2.29.1:
    * Enhance JSON progress events with more fields.
    * bump compose-go v2.1.5
    * bump github.com/docker/cli v27.1.0
    * bump github.com/docker/docker v27.1.0
    * bump github.com/containerd/containerd v1.7.20
    * gha: add docker 27.1.0
    * fix(containers): fix sorting logic by adding secondary sorting
    for one-off containers

++++ dpdk:

  - use %autopatch even for older distros, -M *is* supported there

++++ kdump:

  - upgrade to version 2.0.9
    * start kdump-early earlier using DefaultDependencies=no
    * fadump: avoid re-registration if kernel is hotplug ready
    * mkdumprd: use pbl to get default kernel version (boo#1226676)

++++ kernel-default:

  - ima: Avoid blocking in RCU read-side critical section (bsc#1227803, CVE-2024-40947).
  - commit 6fea688
  - net/rds: fix WARNING in rds_conn_connect_if_down (CVE-2024-27024
    bsc#1223777).
  - commit 466c800
  - Update config files. Disable CONFIG_KFENCE on ppc64le (bsc#1226920)
  - commit 05180ef

++++ kernel-rt:

  - ima: Avoid blocking in RCU read-side critical section (bsc#1227803, CVE-2024-40947).
  - commit 6fea688
  - net/rds: fix WARNING in rds_conn_connect_if_down (CVE-2024-27024
    bsc#1223777).
  - commit 466c800
  - Update config files. Disable CONFIG_KFENCE on ppc64le (bsc#1226920)
  - commit 05180ef

++++ lua54:

  - Update to version 5.4.7:
    * Fixed 11 bugs from 5.4.6
    * Tests now run on shared libraries
  - Removed skip-tests_big-endian.patch: fixed upstream

++++ python313-core:

  - Update F00251-change-user-install-location.patch to install packages
    in /usr/local by default when using pip outside of a RPMBUILD
    environment.

++++ systemd:

  - Import commit 5bba1ebe17564b606cc5d1c07b14123c305019a7 (merge of v256.4)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/bd8b5ee3cf0466b6b78e167967468cf6f93ec807...5bba1ebe17564b606cc5d1c07b14123c305019a7
  - Add 5004-disable-session-freeze.patch as a temporary workaround for
    https://github.com/systemd/systemd/issues/33083

++++ python313:

  - Update F00251-change-user-install-location.patch to install packages
    in /usr/local by default when using pip outside of a RPMBUILD
    environment.

++++ qemu:

  - roms: Build ipxe with NO_WERROR=1 (bsc#1227960)
  - Update to version 9.0.2:
    Full list of backports here:
    https://lore.kernel.org/qemu-devel/1718081053.366429.1238758.nullmailer@tls.msk.ru/
    A selection of them is reported here too:
    hw/nvme: fix number of PIDs for FDP RUH update
    sphinx/qapidoc: Fix to generate doc for explicit, unboxed arguments
    char-stdio: Restore blocking mode of stdout on exit
    virtio: remove virtio_tswap16s() call in vring_packed_event_read()
    virtio-pci: Fix the failure process in kvm_virtio_pci_vector_use_one()
    tcg/optimize: Fix TCG_COND_TST* simplification of setcond2
    block: Parse filenames only when explicitly requested
    iotests/270: Don't store data-file with json: prefix in image
    iotests/244: Don't store data-file with protocol in image
    qcow2: Don't open data_file with BDRV_O_NO_IO
    tests: add testing of parameter=3D1 for SMP topology (bsc#1228169)
    hw/core: allow parameter=3D1 for SMP topology on any machine
    ...

++++ strace:

  - Update License tag (boo#1228216)

------------------------------------------------------------------
------------------  2024-7-23  -  Jul 23 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - bpf: Set run context for rawtp test_run callback (bsc#1227783
    CVE-2024-40908).
  - commit c965ae8
  - nfs: Fix up kabi after adding write_congestion_wait
    (bsc#1218442).
  - commit fa72236
  - ipv6: prevent possible NULL dereference in rt6_probe()
    (CVE-2024-40960 bsc#1227813).
  - commit acda250
  - PCI: keystone: Relocate ks_pcie_set/clear_dbi_mode()
    (git-fixes).
  - commit e717f73
  - x86/csum: clean up `csum_partial' further (git-fixes).
  - commit eb0657c
  - x86/resctrl: Remove redundant variable in mbm_config_write_domain() (git-fixes).
  - commit 7ae6079
  - x86/resctrl: Read supported bandwidth sources from CPUID (git-fixes).
  - commit 907534d
  - x86/shstk: Make return uprobe work with shadow stack (git-fixes).
  - commit a22c34a
  - x86/kconfig: Add as-instr64 macro to properly evaluate AS_WRUSS (git-fixes).
  - commit 0887d68
  - x86/insn: Add VEX versions of VPDPBUSD, VPDPBUSDS, VPDPWSSD and  VPDPWSSDS (git-fixes).
  - commit 4b4922f
  - x86/fpu: Fix AMD X86_BUG_FXSAVE_LEAK fixup (git-fixes).
  - commit 4c24788
  - x86/cpu: Provide default cache line size if not enumerated (git-fixes).
  - commit c2b6a76
  - x86/bhi: Avoid warning in #DB handler due to BHI mitigation :(git-fixes).
  - commit d32b5a4
  - x86/apic: Force native_apic_mem_read() to use the MOV instruction (git-fixes).
  - commit a7c18d6
  - x86/amd_nb: Check for invalid SMN reads (git-fixes).
  - commit 5e0a2ff
  - cachefiles: flush all requests after setting CACHEFILES_DEAD
    (bsc#1227797 CVE-2024-40935).
  - commit 6acb040
  - PCI: tegra194: Set EP alignment restriction for inbound ATU
    (git-fixes).
  - PCI: keystone: Fix NULL pointer dereference in case of DT
    error in ks_pcie_setup_rc_app_regs() (git-fixes).
  - PCI: keystone: Don't enable BAR 0 for AM654x (git-fixes).
  - commit 3d6a567
  - ipv6: prevent possible NULL deref in fib6_nh_init()
    (CVE-2024-40961 bsc#1227814).
  - commit 3de66de
  - PCI: Extend ACS configurability (bsc#1228090).
  - commit 3be1ce1
  - netfilter: nft_inner: validate mandatory meta and payload (bsc#1227757 CVE-2024-39504).
  - commit becdc7a

++++ kernel-rt:

  - bpf: Set run context for rawtp test_run callback (bsc#1227783
    CVE-2024-40908).
  - commit c965ae8
  - nfs: Fix up kabi after adding write_congestion_wait
    (bsc#1218442).
  - commit fa72236
  - ipv6: prevent possible NULL dereference in rt6_probe()
    (CVE-2024-40960 bsc#1227813).
  - commit acda250
  - PCI: keystone: Relocate ks_pcie_set/clear_dbi_mode()
    (git-fixes).
  - commit e717f73
  - x86/csum: clean up `csum_partial' further (git-fixes).
  - commit eb0657c
  - x86/resctrl: Remove redundant variable in mbm_config_write_domain() (git-fixes).
  - commit 7ae6079
  - x86/resctrl: Read supported bandwidth sources from CPUID (git-fixes).
  - commit 907534d
  - x86/shstk: Make return uprobe work with shadow stack (git-fixes).
  - commit a22c34a
  - x86/kconfig: Add as-instr64 macro to properly evaluate AS_WRUSS (git-fixes).
  - commit 0887d68
  - x86/insn: Add VEX versions of VPDPBUSD, VPDPBUSDS, VPDPWSSD and  VPDPWSSDS (git-fixes).
  - commit 4b4922f
  - x86/fpu: Fix AMD X86_BUG_FXSAVE_LEAK fixup (git-fixes).
  - commit 4c24788
  - x86/cpu: Provide default cache line size if not enumerated (git-fixes).
  - commit c2b6a76
  - x86/bhi: Avoid warning in #DB handler due to BHI mitigation :(git-fixes).
  - commit d32b5a4
  - x86/apic: Force native_apic_mem_read() to use the MOV instruction (git-fixes).
  - commit a7c18d6
  - x86/amd_nb: Check for invalid SMN reads (git-fixes).
  - commit 5e0a2ff
  - cachefiles: flush all requests after setting CACHEFILES_DEAD
    (bsc#1227797 CVE-2024-40935).
  - commit 6acb040
  - PCI: tegra194: Set EP alignment restriction for inbound ATU
    (git-fixes).
  - PCI: keystone: Fix NULL pointer dereference in case of DT
    error in ks_pcie_setup_rc_app_regs() (git-fixes).
  - PCI: keystone: Don't enable BAR 0 for AM654x (git-fixes).
  - commit 3d6a567
  - ipv6: prevent possible NULL deref in fib6_nh_init()
    (CVE-2024-40961 bsc#1227814).
  - commit 3de66de
  - PCI: Extend ACS configurability (bsc#1228090).
  - commit 3be1ce1
  - netfilter: nft_inner: validate mandatory meta and payload (bsc#1227757 CVE-2024-39504).
  - commit becdc7a

++++ vulkan-loader:

  - Update to release SDK-1.3.290
    * Remove faulty fallback for unknown functions
    * tests: Allow test ICD to handle NULL pApplicationInfo
    * Fix preloaded ICDs being freed with custom allocators
    * Fix RegCloseKey exeption when double-closing hKeys

++++ libzypp:

  - Fix typo in the geoip update pipeline (bsc#1228206)
  - Export RepoVariablesStringReplacer for yast2 (bsc#1228138)
  - version 17.35.4 (35)

++++ nvidia-open-driver-G06-signed:

  - better summary and description for KMP

++++ python-bcrypt:

  - Update to 4.2.0
    * Bump version for 4.2.0 release (#843)
    * Import improvements from cryptography wheel building and release (#840)
    * Remove setup.py (#842)
    * Small cleanup (#841)
    * Added 3.13 to CI (#839)
    * Bump portable-atomic from 1.6.0 to 1.7.0 in /src/_bcrypt (#836)
    * Bump syn from 2.0.71 to 2.0.72 in /src/_bcrypt (#837)
    * Bump pyo3 from 0.22.1 to 0.22.2 in /src/_bcrypt (#834)
    * Bump syn from 2.0.70 to 2.0.71 in /src/_bcrypt (#833)
    * Bump actions/setup-python from 5.1.0 to 5.1.1 (#832)
    * Bump syn from 2.0.69 to 2.0.70 in /src/_bcrypt (#831)
    * Bump target-lexicon from 0.12.14 to 0.12.15 in /src/_bcrypt (#830)
    * Don't import things from prelude (#829)
    * Bump actions/upload-artifact from 4.3.3 to 4.3.4 (#824)
    * Bump actions/download-artifact from 4.1.7 to 4.1.8 (#825)
    * Bump syn from 2.0.68 to 2.0.69 in /src/_bcrypt (#827)
    * Bump pyo3 from 0.22.0 to 0.22.1 in /src/_bcrypt (#828)
    * Update for new ruff syntax (#826)
    * Switch to using the new pyo3 syntax for declarative modules (#823)
    * Bump pyo3 to 0.22 (#822)
    * Bump bitflags from 2.5.0 to 2.6.0 in /src/_bcrypt (#821)
    * Bump syn from 2.0.67 to 2.0.68 in /src/_bcrypt (#818)
    * Bump syn from 2.0.66 to 2.0.67 in /src/_bcrypt (#817)
    * Bump proc-macro2 from 1.0.85 to 1.0.86 in /src/_bcrypt (#816)
    * Bump subtle from 2.5.0 to 2.6.0 in /src/_bcrypt (#814)
    * Bump redox_syscall from 0.5.1 to 0.5.2 in /src/_bcrypt (#813)
    * Bump actions/checkout from 4.1.6 to 4.1.7 (#812)
    * Bump proc-macro2 from 1.0.84 to 1.0.85 in /src/_bcrypt (#811)
    * Bump proc-macro2 from 1.0.83 to 1.0.84 in /src/_bcrypt (#808)
    * Bump zeroize from 1.7.0 to 1.8.1 in /src/_bcrypt (#809)
    * Bump parking_lot from 0.12.2 to 0.12.3 in /src/_bcrypt (#810)
    * Bump syn from 2.0.65 to 2.0.66 in /src/_bcrypt (#806)
    * alpine is 3.12 now (#807)
    * Bump proc-macro2 from 1.0.82 to 1.0.83 in /src/_bcrypt (#804)
    * Bump syn from 2.0.64 to 2.0.65 in /src/_bcrypt (#803)
    * Bump libc from 0.2.154 to 0.2.155 in /src/_bcrypt (#802)
    * Bump actions/checkout from 4.1.5 to 4.1.6 (#800)
    * Apply the wacky staticnode workaround to this repo (#801)
    * Bump syn from 2.0.63 to 2.0.64 in /src/_bcrypt (#799)
    * Bump syn from 2.0.61 to 2.0.63 in /src/_bcrypt (#798)
    * Try upgrading ubuntu in CI (#797)
    * Bump proc-macro2 from 1.0.81 to 1.0.82 in /src/_bcrypt (#796)
    * Bump syn from 2.0.60 to 2.0.61 in /src/_bcrypt (#795)
    * Bump getrandom from 0.2.14 to 0.2.15 in /src/_bcrypt (#794)
    * Bump actions/checkout from 3.6.0 to 4.1.5 (#793)

++++ rt-tests:

  - Fix archive URL

++++ virt-manager:

  - bsc#1228227 - libvirt missing default hyperv options causes
    windows guest performance degredation.
    virtinst-add-hyperv-performance-options.patch

------------------------------------------------------------------
------------------  2024-7-22  -  Jul 22 2024  -------------------
------------------------------------------------------------------

++++ lvm2-device-mapper:

  - enable devices file feature by default - see lvmdevices(8)
    * enable '--with-default-use-devices-file=1' in lvm2.spec
    * update commented default value of 'use_devicesfile' in lvm2.conf

++++ kernel-default:

  - nfs: Block on write congestion (bsc#1218442).
  - commit b7f1cad
  - nfs: Properly initialize server->writeback (bsc#1218442).
  - commit c293976
  - nfs: Drop pointless check from nfs_commit_release_pages()
    (bsc#1218442).
  - commit 20931fe
  - kabi/severities: cleanup and update for WiFi driver entries (bsc#1227149)
  - commit 777b4e0
  - wifi: libertas: Follow renaming of SPI "master" to "controller"
    (bsc#1227149).
  - wifi: cw1200: restore endian swapping (bsc#1227149).
  - wifi: wlcore: sdio: Rate limit wl12xx_sdio_raw_{read,write}()
    failures warns (bsc#1227149).
  - wifi: zd1211rw: silence sparse warnings (bsc#1227149).
  - wifi: rt2x00: silence sparse warnings (bsc#1227149).
  - wifi: brcmsmac: silence sparse warnings (bsc#1227149).
  - wifi: b43: silence sparse warnings (bsc#1227149).
  - wifi: brcmfmac: do not pass hidden SSID attribute as value
    directly (bsc#1227149).
  - wifi: brcmfmac: fweh: Fix boot crash on Raspberry Pi 4
    (bsc#1227149).
  - wifi: wilc1000: remove AKM suite be32 conversion for external
    auth request (bsc#1227149).
  - wifi: wilc1000: add missing read critical sections around vif
    list traversal (bsc#1227149).
  - wifi: wilc1000: fix declarations ordering (bsc#1227149).
  - wifi: wilc1000: use SRCU instead of RCU for vif list traversal
    (bsc#1227149).
  - wifi: wilc1000: split deeply nested RCU list traversal in
    dedicated helper (bsc#1227149).
  - wifi: wilc1000: validate chip id during bus probe (bsc#1227149).
  - wifi: brcmfmac: do not cast hidden SSID attribute value to
    boolean (bsc#1227149).
  - wifi: mwifiex: Refactor 1-element array into flexible array
    in struct mwifiex_ie_types_chan_list_param_set (bsc#1227149).
  - wifi: wilc1000: correct CRC7 calculation (bsc#1227149).
  - wifi: wilc1000: set preamble size to auto as default in
    wilc_init_fw_config() (bsc#1227149).
  - wifi: mwifiex: use kstrtoX_from_user() in debugfs handlers
    (bsc#1227149).
  - wifi: wilc1000: remove setting msg.spi (bsc#1227149).
  - wifi: cw1200: Convert to GPIO descriptors (bsc#1227149).
  - wifi: plfxlc: Drop unused include (bsc#1227149).
  - wifi: mwifiex: Drop unused headers (bsc#1227149).
  - wifi: ti: wlcore: sdio: Drop unused include (bsc#1227149).
  - wifi: cw1200: fix __le16 sparse warnings (bsc#1227149).
  - wifi: rsi: fix restricted __le32 degrades to integer sparse
    warnings (bsc#1227149).
  - wifi: zd1211rw: remove __nocast from zd_addr_t (bsc#1227149).
  - wifi: brcmfmac: add linefeed at end of file (bsc#1227149).
  - wifi: brcmfmac: allow per-vendor event handling (bsc#1227149).
  - wifi: brcmfmac: move feature overrides before feature_disable
    (bsc#1227149).
  - wifi: brcmfmac: export firmware interface functions
    (bsc#1227149).
  - wifi: rt2x00: simplify rt2x00crypto_rx_insert_iv()
    (bsc#1227149).
  - wifi: mwifiex: Use helpers to check multicast addresses
    (bsc#1227149).
  - wifi: brcmsmac: phy: Remove unreachable code (bsc#1227149).
  - wifi: wilc1000: fix incorrect power down sequence (bsc#1227149).
  - wifi: wilc1000: fix driver_handler when committing initial
    configuration (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wilc1000 (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wl18xx (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for p54spi (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for Broadcom WLAN
    (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wl1251 and wl12xx
    (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wlcore (bsc#1227149).
  - wifi: p54: fix GCC format truncation warning with
    wiphy->fw_version (bsc#1227149).
  - wifi: mwifiex: use cfg80211_ssid_eq() instead of
    mwifiex_ssid_cmp() (bsc#1227149).
  - wifi: rt2x00: remove useless code in
    rt2x00queue_create_tx_descriptor() (bsc#1227149).
  - commit 08ddd32
  - wifi: rt2x00: make watchdog param per device (bsc#1227149).
  - wifi: rt2x00: Simplify bool conversion (bsc#1227149).
  - wifi: mwifiex: mwifiex_process_sleep_confirm_resp(): remove
    unused priv variable (bsc#1227149).
  - wifi: rt2x00: disable RTS threshold for rt2800 by default
    (bsc#1227149).
  - wifi: rt2x00: introduce DMA busy check watchdog for rt2800
    (bsc#1227149).
  - wifi: wilc1000: simplify wilc_scan() (bsc#1227149).
  - wifi: wilc1000: cleanup struct wilc_conn_info (bsc#1227149).
  - wifi: wilc1000: always release SDIO host in wilc_sdio_cmd53()
    (bsc#1227149).
  - wifi: wilc1000: simplify remain on channel support
    (bsc#1227149).
  - wifi: brcmsmac: replace deprecated strncpy with memcpy
    (bsc#1227149).
  - wifi: brcm80211: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: rt2x00: rework MT7620 PA/LNA RF calibration (bsc#1227149).
  - wifi: rt2x00: rework MT7620 channel config function
    (bsc#1227149).
  - commit 055fd52
  - wifi: rt2x00: improve MT7620 register initialization
    (bsc#1227149).
  - wifi: wlcore: main: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: wlcore: boot: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: wl18xx: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: wl1251: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: rt2x00: fix rt2800 watchdog function (bsc#1227149).
  - wifi: brcmfmac: fix format-truncation warnings (bsc#1227149).
  - wifi: hostap: remove unused ioctl function (bsc#1227149).
  - wifi: atmel: remove unused ioctl function (bsc#1227149).
  - wifi: p54: Annotate struct p54_cal_database with __counted_by
    (bsc#1227149).
  - wifi: brcmfmac: fweh: Add __counted_by for struct
    brcmf_fweh_queue_item and use struct_size() (bsc#1227149).
  - wifi: hostap: Add __counted_by for struct prism2_download_data
    and use struct_size() (bsc#1227149).
  - wifi: wfx: implement wfx_remain_on_channel() (bsc#1227149).
  - wifi: wfx: allow to send frames during ROC (bsc#1227149).
  - wifi: wfx: scan_lock is global to the device (bsc#1227149).
  - wifi: wfx: simplify exclusion between scan and Rx filters
    (bsc#1227149).
  - wifi: wfx: introduce hif_scan_uniq() (bsc#1227149).
  - wifi: wfx: move wfx_skb_*() out of the header file
    (bsc#1227149).
  - wifi: wfx: relocate wfx_rate_mask_to_hw() (bsc#1227149).
  - wifi: wfx: fix power_save setting when AP is stopped
    (bsc#1227149).
  - commit 859f128
  - wifi: mwifiex: Replace one-element array with flexible-array
    member in struct mwifiex_ie_types_rxba_sync (bsc#1227149).
  - Refresh
    patches.suse/wifi-mwifiex-Sanity-check-tlv_len-and-tlv_bitmap_len.patch.
  - commit 0e5befb
  - wifi: rt2x00: fix MT7620 low RSSI issue (bsc#1227149).
  - wifi: rt2x00: remove redundant check if u8 array element is
    less than zero (bsc#1227149).
  - wifi: mwifiex: followup PCIE and related cleanups (bsc#1227149).
  - wifi: mwifiex: simplify PCIE write operations (bsc#1227149).
  - wifi: wilc1000: add back-off algorithm to balance tx queue
    packets (bsc#1227149).
  - wifi: mwifiex: use MODULE_FIRMWARE to add firmware files
    metadata (bsc#1227149).
  - wifi: mwifiex: cleanup struct mwifiex_sdio_mpa_rx (bsc#1227149).
  - wifi: brcmfmac: firmware: Annotate struct brcmf_fw_request
    with __counted_by (bsc#1227149).
  - wifi: brcmfmac: Annotate struct brcmf_gscan_config with
    __counted_by (bsc#1227149).
  - wifi: cw1200: Avoid processing an invalid TIM IE (bsc#1227149).
  - wifi: wlcore: sdio: Use module_sdio_driver macro to simplify
    the code (bsc#1227149).
  - wifi: wilc1000: Remove unused declarations (bsc#1227149).
  - wifi: rt2x00: limit MT7620 TX power based on eeprom calibration
    (bsc#1227149).
  - wifi: wfx: Use devm_kmemdup to replace devm_kmalloc + memcpy
    (bsc#1227149).
  - wifi: rsi: rsi_91x_usb_ops: Remove unnecessary (void*)
    conversions (bsc#1227149).
  - wifi: rsi: rsi_91x_usb: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_sdio_ops: Remove unnecessary (void*)
    conversions (bsc#1227149).
  - wifi: rsi: rsi_91x_sdio: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - commit a544c26
  - wifi: rsi: rsi_91x_main: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_mac80211: Remove unnecessary conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_hal: Remove unnecessary conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_debugfs: Remove unnecessary (void*)
    conversions (bsc#1227149).
  - wifi: rsi: rsi_91x_coex: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: rt2x00: correct MAC_SYS_CTRL register RX mask in
    R-Calibration (bsc#1227149).
  - wifi: mwifiex: fix comment typos in SDIO module (bsc#1227149).
  - wifi: mwifiex: cleanup adapter data (bsc#1227149).
  - wifi: mwifiex: use is_zero_ether_addr() instead of
    ether_addr_equal() (bsc#1227149).
  - wifi: mwifiex: drop BUG_ON from TX paths (bsc#1227149).
  - wifi: mwifiex: handle possible mwifiex_write_reg() errors
    (bsc#1227149).
  - wifi: mwifiex: handle possible sscanf() errors (bsc#1227149).
  - wifi: mwifiex: cleanup private data structures (bsc#1227149).
  - wlcore: spi: Remove redundant of_match_ptr() (bsc#1227149).
  - wifi: brcmsmac: cleanup SCB-related data types (bsc#1227149).
  - wifi: brcmsmac: remove more unused data types (bsc#1227149).
  - wifi: libertas: prefer kstrtoX() for simple integer conversions
    (bsc#1227149).
  - wifi: libertas: handle possible spu_write_u16() errors
    (bsc#1227149).
  - wifi: libertas: cleanup SDIO reset (bsc#1227149).
  - wifi: libertas: simplify list operations in free_if_spi_card()
    (bsc#1227149).
  - wifi: libertas: use convenient lists to manage SDIO packets
    (bsc#1227149).
  - wifi: libertas: add missing calls to cancel_work_sync()
    (bsc#1227149).
  - wifi: wilc1000: add SPI commands retry mechanism (bsc#1227149).
  - wifi: wilc1000: remove use of has_thrpt_enh3 flag (bsc#1227149).
  - wifi: brcmsmac: remove unused data type (bsc#1227149).
  - wifi: mwifiex: Set WIPHY_FLAG_NETNS_OK flag (bsc#1227149).
  - wifi: mwifiex: prefer strscpy() over strlcpy() (bsc#1227149).
  - wifi: zd1211rw: fix typo "tranmits" (bsc#1227149).
  - wifi: p54: Add missing MODULE_FIRMWARE macro (bsc#1227149).
  - wifi: hostap: fix stringop-truncations GCC warning
    (bsc#1227149).
  - wifi: brcmsmac: fix gnu_printf warnings (bsc#1227149).
  - wifi: brcmfmac: fix gnu_printf warnings (bsc#1227149).
  - wifi: rt2x00: fix the typo in comments (bsc#1227149).
  - wifi: brcmfmac: Detect corner error case earlier with log
    (bsc#1227149).
  - wifi: brcmutil: use helper function pktq_empty() instead of
    open code (bsc#1227149).
  - wifi: add HAS_IOPORT dependencies (bsc#1227149).
  - wifi: wilc1000: Increase ASSOC response buffer (bsc#1227149).
  - wifi: mwifiex: Use list_count_nodes() (bsc#1227149).
  - wifi: mwifiex: Use default @max_active for workqueues
    (bsc#1227149).
  - commit edbabc2
  - xfs: Add cond_resched to block unmap range and reflink remap
    path (bsc#1228211).
  - commit 4c79a42
  - supported.conf: Add support for v4l2-dv-timings
    (jsc#PED-8645)
  - commit 6262df7
  - supported.conf: Add support for v4l2-dv-timings
    (jsc#PED-8644)
  - commit a3622c5
  - netrom: Fix a memory leak in nr_heartbeat_expiry()
    (CVE-2024-41006 bsc#1227862).
  - commit 59ef181
  - arm64: dts: rockchip: Add missing power-domains for rk356x vop_mmu (git-fixes)
  - commit 6571948
  - arm64: dts: rockchip: Fix mic-in-differential usage on (git-fixes)
  - commit 67939cb
  - arm64: dts: rockchip: Fix mic-in-differential usage on rk3566-roc-pc (git-fixes)
  - commit 5ed815a
  - arm64: dts: rockchip: Drop invalid mic-in-differential on (git-fixes)
  - commit af4620a
  - arm64: dts: rockchip: Increase VOP clk rate on RK3328 (git-fixes)
  - commit 0171830
  - arm64: dts: rockchip: Update WIFi/BT related nodes on (git-fixes)
  - commit 2186774
  - arm64: dts: rockchip: Add mdio and ethernet-phy nodes to (git-fixes)
  - commit 7bd1596
  - arm64: dts: rockchip: Add pinctrl for UART0 to rk3308-rock-pi-s (git-fixes)
  - commit a5c559a
  - arm64: dts: rockchip: Add sdmmc related properties on (git-fixes)
  - commit 07ed999
  - arm64: dts: rockchip: Add sound-dai-cells for RK3368 (git-fixes)
  - commit 0d2dc44
  - arm64: dts: rockchip: fix PMIC interrupt pin on ROCK Pi E (git-fixes)
  - commit 17c17ec
  - arm64: dts: rockchip: Fix the value of `dlg,jack-det-rate` mismatch (git-fixes)
  - commit ef568ac
  - arm64: dts: rockchip: Rename LED related pinctrl nodes on (git-fixes)
  - commit 3ac3475
  - arm64: dts: rockchip: Fix SD NAND and eMMC init on rk3308-rock-pi-s (git-fixes)
  - commit f0f8ba5
  - arm64: dts: rockchip: Fix the DCDC_REG2 minimum voltage on Quartz64 (git-fixes)
  - commit a564fef
  - arm64: dts: imx8qm-mek: fix gpio number for reg_usdhc2_vmmc (git-fixes)
  - commit d7e72e1
  - arm64: dts: freescale: imx8mm-verdin: enable hysteresis on slow input (git-fixes)
  - commit ca6c1bb
  - arm64: dts: imx93-11x11-evk: Remove the 'no-sdio' property (git-fixes)
  - commit a10e3de
  - Move upstreamed patches into sorted section
  - commit 0bb0cc8
  - fuse: verify {g,u}id mount options correctly (bsc#1228193).
  - libceph: fix race between delayed_work() and ceph_monc_stop()
    (bsc#1228192).
  - commit 10e7bb9
  - nilfs2: avoid undefined behavior in nilfs_cnt32_ge macro
    (git-fixes).
  - checkpatch: really skip LONG_LINE_* when LONG_LINE is ignored
    (git-fixes).
  - rtc: interface: Add RTC offset to alarm after fix-up
    (git-fixes).
  - rtc: abx80x: Fix return value of nvmem callback on read
    (git-fixes).
  - rtc: cmos: Fix return value of nvmem callbacks (git-fixes).
  - rtc: isl1208: Fix return value of nvmem callbacks (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix TPU suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix TCLK suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: FIX PWM suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix IRQ suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix (H)SCIF3 suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix (H)SCIF1 suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix FXR_TXEN[AB] suffixes
    (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix CANFD5 suffix (git-fixes).
  - pinctrl: freescale: mxs: Fix refcount of child (git-fixes).
  - pinctrl: ti: ti-iodelay: fix possible memory leak when
    pinctrl_enable() fails (git-fixes).
  - pinctrl: single: fix possible memory leak when pinctrl_enable()
    fails (git-fixes).
  - pinctrl: core: fix possible memory leak when pinctrl_enable()
    fails (git-fixes).
  - pinctrl: rockchip: update rk3308 iomux routes (git-fixes).
  - selftests/sigaltstack: Fix ppc64 GCC build (git-fixes).
  - PCI: dw-rockchip: Fix initial PERST# GPIO value (git-fixes).
  - PCI: rockchip: Use GPIOD_OUT_LOW flag while requesting ep_gpio
    (git-fixes).
  - PCI: rcar: Demote WARN() to dev_warn_ratelimited() in
    rcar_pcie_wakeup() (git-fixes).
  - PCI: qcom-ep: Disable resources unconditionally during PERST#
    assert (git-fixes).
  - PCI: dwc: Fix index 0 incorrectly being interpreted as a free
    ATU slot (git-fixes).
  - PCI: endpoint: Fix error handling in epf_ntb_epc_cleanup()
    (git-fixes).
  - PCI: endpoint: Clean up error handling in vpci_scan_bus()
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Make use of cached 'epc_features'
    in pci_epf_test_core_init() (git-fixes).
  - PCI: Fix resource double counting on remove & rescan
    (git-fixes).
  - PCI/DPC: Fix use-after-free on concurrent DPC and hot-removal
    (git-fixes).
  - PCI: Introduce cleanup helpers for device reference counts
    and locks (stable-fixes).
  - commit a7e6cbc

++++ kernel-rt:

  - nfs: Block on write congestion (bsc#1218442).
  - commit b7f1cad
  - nfs: Properly initialize server->writeback (bsc#1218442).
  - commit c293976
  - nfs: Drop pointless check from nfs_commit_release_pages()
    (bsc#1218442).
  - commit 20931fe
  - kabi/severities: cleanup and update for WiFi driver entries (bsc#1227149)
  - commit 777b4e0
  - wifi: libertas: Follow renaming of SPI "master" to "controller"
    (bsc#1227149).
  - wifi: cw1200: restore endian swapping (bsc#1227149).
  - wifi: wlcore: sdio: Rate limit wl12xx_sdio_raw_{read,write}()
    failures warns (bsc#1227149).
  - wifi: zd1211rw: silence sparse warnings (bsc#1227149).
  - wifi: rt2x00: silence sparse warnings (bsc#1227149).
  - wifi: brcmsmac: silence sparse warnings (bsc#1227149).
  - wifi: b43: silence sparse warnings (bsc#1227149).
  - wifi: brcmfmac: do not pass hidden SSID attribute as value
    directly (bsc#1227149).
  - wifi: brcmfmac: fweh: Fix boot crash on Raspberry Pi 4
    (bsc#1227149).
  - wifi: wilc1000: remove AKM suite be32 conversion for external
    auth request (bsc#1227149).
  - wifi: wilc1000: add missing read critical sections around vif
    list traversal (bsc#1227149).
  - wifi: wilc1000: fix declarations ordering (bsc#1227149).
  - wifi: wilc1000: use SRCU instead of RCU for vif list traversal
    (bsc#1227149).
  - wifi: wilc1000: split deeply nested RCU list traversal in
    dedicated helper (bsc#1227149).
  - wifi: wilc1000: validate chip id during bus probe (bsc#1227149).
  - wifi: brcmfmac: do not cast hidden SSID attribute value to
    boolean (bsc#1227149).
  - wifi: mwifiex: Refactor 1-element array into flexible array
    in struct mwifiex_ie_types_chan_list_param_set (bsc#1227149).
  - wifi: wilc1000: correct CRC7 calculation (bsc#1227149).
  - wifi: wilc1000: set preamble size to auto as default in
    wilc_init_fw_config() (bsc#1227149).
  - wifi: mwifiex: use kstrtoX_from_user() in debugfs handlers
    (bsc#1227149).
  - wifi: wilc1000: remove setting msg.spi (bsc#1227149).
  - wifi: cw1200: Convert to GPIO descriptors (bsc#1227149).
  - wifi: plfxlc: Drop unused include (bsc#1227149).
  - wifi: mwifiex: Drop unused headers (bsc#1227149).
  - wifi: ti: wlcore: sdio: Drop unused include (bsc#1227149).
  - wifi: cw1200: fix __le16 sparse warnings (bsc#1227149).
  - wifi: rsi: fix restricted __le32 degrades to integer sparse
    warnings (bsc#1227149).
  - wifi: zd1211rw: remove __nocast from zd_addr_t (bsc#1227149).
  - wifi: brcmfmac: add linefeed at end of file (bsc#1227149).
  - wifi: brcmfmac: allow per-vendor event handling (bsc#1227149).
  - wifi: brcmfmac: move feature overrides before feature_disable
    (bsc#1227149).
  - wifi: brcmfmac: export firmware interface functions
    (bsc#1227149).
  - wifi: rt2x00: simplify rt2x00crypto_rx_insert_iv()
    (bsc#1227149).
  - wifi: mwifiex: Use helpers to check multicast addresses
    (bsc#1227149).
  - wifi: brcmsmac: phy: Remove unreachable code (bsc#1227149).
  - wifi: wilc1000: fix incorrect power down sequence (bsc#1227149).
  - wifi: wilc1000: fix driver_handler when committing initial
    configuration (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wilc1000 (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wl18xx (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for p54spi (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for Broadcom WLAN
    (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wl1251 and wl12xx
    (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wlcore (bsc#1227149).
  - wifi: p54: fix GCC format truncation warning with
    wiphy->fw_version (bsc#1227149).
  - wifi: mwifiex: use cfg80211_ssid_eq() instead of
    mwifiex_ssid_cmp() (bsc#1227149).
  - wifi: rt2x00: remove useless code in
    rt2x00queue_create_tx_descriptor() (bsc#1227149).
  - commit 08ddd32
  - wifi: rt2x00: make watchdog param per device (bsc#1227149).
  - wifi: rt2x00: Simplify bool conversion (bsc#1227149).
  - wifi: mwifiex: mwifiex_process_sleep_confirm_resp(): remove
    unused priv variable (bsc#1227149).
  - wifi: rt2x00: disable RTS threshold for rt2800 by default
    (bsc#1227149).
  - wifi: rt2x00: introduce DMA busy check watchdog for rt2800
    (bsc#1227149).
  - wifi: wilc1000: simplify wilc_scan() (bsc#1227149).
  - wifi: wilc1000: cleanup struct wilc_conn_info (bsc#1227149).
  - wifi: wilc1000: always release SDIO host in wilc_sdio_cmd53()
    (bsc#1227149).
  - wifi: wilc1000: simplify remain on channel support
    (bsc#1227149).
  - wifi: brcmsmac: replace deprecated strncpy with memcpy
    (bsc#1227149).
  - wifi: brcm80211: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: rt2x00: rework MT7620 PA/LNA RF calibration (bsc#1227149).
  - wifi: rt2x00: rework MT7620 channel config function
    (bsc#1227149).
  - commit 055fd52
  - wifi: rt2x00: improve MT7620 register initialization
    (bsc#1227149).
  - wifi: wlcore: main: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: wlcore: boot: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: wl18xx: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: wl1251: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: rt2x00: fix rt2800 watchdog function (bsc#1227149).
  - wifi: brcmfmac: fix format-truncation warnings (bsc#1227149).
  - wifi: hostap: remove unused ioctl function (bsc#1227149).
  - wifi: atmel: remove unused ioctl function (bsc#1227149).
  - wifi: p54: Annotate struct p54_cal_database with __counted_by
    (bsc#1227149).
  - wifi: brcmfmac: fweh: Add __counted_by for struct
    brcmf_fweh_queue_item and use struct_size() (bsc#1227149).
  - wifi: hostap: Add __counted_by for struct prism2_download_data
    and use struct_size() (bsc#1227149).
  - wifi: wfx: implement wfx_remain_on_channel() (bsc#1227149).
  - wifi: wfx: allow to send frames during ROC (bsc#1227149).
  - wifi: wfx: scan_lock is global to the device (bsc#1227149).
  - wifi: wfx: simplify exclusion between scan and Rx filters
    (bsc#1227149).
  - wifi: wfx: introduce hif_scan_uniq() (bsc#1227149).
  - wifi: wfx: move wfx_skb_*() out of the header file
    (bsc#1227149).
  - wifi: wfx: relocate wfx_rate_mask_to_hw() (bsc#1227149).
  - wifi: wfx: fix power_save setting when AP is stopped
    (bsc#1227149).
  - commit 859f128
  - wifi: mwifiex: Replace one-element array with flexible-array
    member in struct mwifiex_ie_types_rxba_sync (bsc#1227149).
  - Refresh
    patches.suse/wifi-mwifiex-Sanity-check-tlv_len-and-tlv_bitmap_len.patch.
  - commit 0e5befb
  - wifi: rt2x00: fix MT7620 low RSSI issue (bsc#1227149).
  - wifi: rt2x00: remove redundant check if u8 array element is
    less than zero (bsc#1227149).
  - wifi: mwifiex: followup PCIE and related cleanups (bsc#1227149).
  - wifi: mwifiex: simplify PCIE write operations (bsc#1227149).
  - wifi: wilc1000: add back-off algorithm to balance tx queue
    packets (bsc#1227149).
  - wifi: mwifiex: use MODULE_FIRMWARE to add firmware files
    metadata (bsc#1227149).
  - wifi: mwifiex: cleanup struct mwifiex_sdio_mpa_rx (bsc#1227149).
  - wifi: brcmfmac: firmware: Annotate struct brcmf_fw_request
    with __counted_by (bsc#1227149).
  - wifi: brcmfmac: Annotate struct brcmf_gscan_config with
    __counted_by (bsc#1227149).
  - wifi: cw1200: Avoid processing an invalid TIM IE (bsc#1227149).
  - wifi: wlcore: sdio: Use module_sdio_driver macro to simplify
    the code (bsc#1227149).
  - wifi: wilc1000: Remove unused declarations (bsc#1227149).
  - wifi: rt2x00: limit MT7620 TX power based on eeprom calibration
    (bsc#1227149).
  - wifi: wfx: Use devm_kmemdup to replace devm_kmalloc + memcpy
    (bsc#1227149).
  - wifi: rsi: rsi_91x_usb_ops: Remove unnecessary (void*)
    conversions (bsc#1227149).
  - wifi: rsi: rsi_91x_usb: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_sdio_ops: Remove unnecessary (void*)
    conversions (bsc#1227149).
  - wifi: rsi: rsi_91x_sdio: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - commit a544c26
  - wifi: rsi: rsi_91x_main: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_mac80211: Remove unnecessary conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_hal: Remove unnecessary conversions
    (bsc#1227149).
  - wifi: rsi: rsi_91x_debugfs: Remove unnecessary (void*)
    conversions (bsc#1227149).
  - wifi: rsi: rsi_91x_coex: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: rt2x00: correct MAC_SYS_CTRL register RX mask in
    R-Calibration (bsc#1227149).
  - wifi: mwifiex: fix comment typos in SDIO module (bsc#1227149).
  - wifi: mwifiex: cleanup adapter data (bsc#1227149).
  - wifi: mwifiex: use is_zero_ether_addr() instead of
    ether_addr_equal() (bsc#1227149).
  - wifi: mwifiex: drop BUG_ON from TX paths (bsc#1227149).
  - wifi: mwifiex: handle possible mwifiex_write_reg() errors
    (bsc#1227149).
  - wifi: mwifiex: handle possible sscanf() errors (bsc#1227149).
  - wifi: mwifiex: cleanup private data structures (bsc#1227149).
  - wlcore: spi: Remove redundant of_match_ptr() (bsc#1227149).
  - wifi: brcmsmac: cleanup SCB-related data types (bsc#1227149).
  - wifi: brcmsmac: remove more unused data types (bsc#1227149).
  - wifi: libertas: prefer kstrtoX() for simple integer conversions
    (bsc#1227149).
  - wifi: libertas: handle possible spu_write_u16() errors
    (bsc#1227149).
  - wifi: libertas: cleanup SDIO reset (bsc#1227149).
  - wifi: libertas: simplify list operations in free_if_spi_card()
    (bsc#1227149).
  - wifi: libertas: use convenient lists to manage SDIO packets
    (bsc#1227149).
  - wifi: libertas: add missing calls to cancel_work_sync()
    (bsc#1227149).
  - wifi: wilc1000: add SPI commands retry mechanism (bsc#1227149).
  - wifi: wilc1000: remove use of has_thrpt_enh3 flag (bsc#1227149).
  - wifi: brcmsmac: remove unused data type (bsc#1227149).
  - wifi: mwifiex: Set WIPHY_FLAG_NETNS_OK flag (bsc#1227149).
  - wifi: mwifiex: prefer strscpy() over strlcpy() (bsc#1227149).
  - wifi: zd1211rw: fix typo "tranmits" (bsc#1227149).
  - wifi: p54: Add missing MODULE_FIRMWARE macro (bsc#1227149).
  - wifi: hostap: fix stringop-truncations GCC warning
    (bsc#1227149).
  - wifi: brcmsmac: fix gnu_printf warnings (bsc#1227149).
  - wifi: brcmfmac: fix gnu_printf warnings (bsc#1227149).
  - wifi: rt2x00: fix the typo in comments (bsc#1227149).
  - wifi: brcmfmac: Detect corner error case earlier with log
    (bsc#1227149).
  - wifi: brcmutil: use helper function pktq_empty() instead of
    open code (bsc#1227149).
  - wifi: add HAS_IOPORT dependencies (bsc#1227149).
  - wifi: wilc1000: Increase ASSOC response buffer (bsc#1227149).
  - wifi: mwifiex: Use list_count_nodes() (bsc#1227149).
  - wifi: mwifiex: Use default @max_active for workqueues
    (bsc#1227149).
  - commit edbabc2
  - xfs: Add cond_resched to block unmap range and reflink remap
    path (bsc#1228211).
  - commit 4c79a42
  - supported.conf: Add support for v4l2-dv-timings
    (jsc#PED-8645)
  - commit 6262df7
  - supported.conf: Add support for v4l2-dv-timings
    (jsc#PED-8644)
  - commit a3622c5
  - netrom: Fix a memory leak in nr_heartbeat_expiry()
    (CVE-2024-41006 bsc#1227862).
  - commit 59ef181
  - arm64: dts: rockchip: Add missing power-domains for rk356x vop_mmu (git-fixes)
  - commit 6571948
  - arm64: dts: rockchip: Fix mic-in-differential usage on (git-fixes)
  - commit 67939cb
  - arm64: dts: rockchip: Fix mic-in-differential usage on rk3566-roc-pc (git-fixes)
  - commit 5ed815a
  - arm64: dts: rockchip: Drop invalid mic-in-differential on (git-fixes)
  - commit af4620a
  - arm64: dts: rockchip: Increase VOP clk rate on RK3328 (git-fixes)
  - commit 0171830
  - arm64: dts: rockchip: Update WIFi/BT related nodes on (git-fixes)
  - commit 2186774
  - arm64: dts: rockchip: Add mdio and ethernet-phy nodes to (git-fixes)
  - commit 7bd1596
  - arm64: dts: rockchip: Add pinctrl for UART0 to rk3308-rock-pi-s (git-fixes)
  - commit a5c559a
  - arm64: dts: rockchip: Add sdmmc related properties on (git-fixes)
  - commit 07ed999
  - arm64: dts: rockchip: Add sound-dai-cells for RK3368 (git-fixes)
  - commit 0d2dc44
  - arm64: dts: rockchip: fix PMIC interrupt pin on ROCK Pi E (git-fixes)
  - commit 17c17ec
  - arm64: dts: rockchip: Fix the value of `dlg,jack-det-rate` mismatch (git-fixes)
  - commit ef568ac
  - arm64: dts: rockchip: Rename LED related pinctrl nodes on (git-fixes)
  - commit 3ac3475
  - arm64: dts: rockchip: Fix SD NAND and eMMC init on rk3308-rock-pi-s (git-fixes)
  - commit f0f8ba5
  - arm64: dts: rockchip: Fix the DCDC_REG2 minimum voltage on Quartz64 (git-fixes)
  - commit a564fef
  - arm64: dts: imx8qm-mek: fix gpio number for reg_usdhc2_vmmc (git-fixes)
  - commit d7e72e1
  - arm64: dts: freescale: imx8mm-verdin: enable hysteresis on slow input (git-fixes)
  - commit ca6c1bb
  - arm64: dts: imx93-11x11-evk: Remove the 'no-sdio' property (git-fixes)
  - commit a10e3de
  - Move upstreamed patches into sorted section
  - commit 0bb0cc8
  - fuse: verify {g,u}id mount options correctly (bsc#1228193).
  - libceph: fix race between delayed_work() and ceph_monc_stop()
    (bsc#1228192).
  - commit 10e7bb9
  - nilfs2: avoid undefined behavior in nilfs_cnt32_ge macro
    (git-fixes).
  - checkpatch: really skip LONG_LINE_* when LONG_LINE is ignored
    (git-fixes).
  - rtc: interface: Add RTC offset to alarm after fix-up
    (git-fixes).
  - rtc: abx80x: Fix return value of nvmem callback on read
    (git-fixes).
  - rtc: cmos: Fix return value of nvmem callbacks (git-fixes).
  - rtc: isl1208: Fix return value of nvmem callbacks (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix TPU suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix TCLK suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: FIX PWM suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix IRQ suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix (H)SCIF3 suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix (H)SCIF1 suffixes (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix FXR_TXEN[AB] suffixes
    (git-fixes).
  - pinctrl: renesas: r8a779g0: Fix CANFD5 suffix (git-fixes).
  - pinctrl: freescale: mxs: Fix refcount of child (git-fixes).
  - pinctrl: ti: ti-iodelay: fix possible memory leak when
    pinctrl_enable() fails (git-fixes).
  - pinctrl: single: fix possible memory leak when pinctrl_enable()
    fails (git-fixes).
  - pinctrl: core: fix possible memory leak when pinctrl_enable()
    fails (git-fixes).
  - pinctrl: rockchip: update rk3308 iomux routes (git-fixes).
  - selftests/sigaltstack: Fix ppc64 GCC build (git-fixes).
  - PCI: dw-rockchip: Fix initial PERST# GPIO value (git-fixes).
  - PCI: rockchip: Use GPIOD_OUT_LOW flag while requesting ep_gpio
    (git-fixes).
  - PCI: rcar: Demote WARN() to dev_warn_ratelimited() in
    rcar_pcie_wakeup() (git-fixes).
  - PCI: qcom-ep: Disable resources unconditionally during PERST#
    assert (git-fixes).
  - PCI: dwc: Fix index 0 incorrectly being interpreted as a free
    ATU slot (git-fixes).
  - PCI: endpoint: Fix error handling in epf_ntb_epc_cleanup()
    (git-fixes).
  - PCI: endpoint: Clean up error handling in vpci_scan_bus()
    (git-fixes).
  - PCI: endpoint: pci-epf-test: Make use of cached 'epc_features'
    in pci_epf_test_core_init() (git-fixes).
  - PCI: Fix resource double counting on remove & rescan
    (git-fixes).
  - PCI/DPC: Fix use-after-free on concurrent DPC and hot-removal
    (git-fixes).
  - PCI: Introduce cleanup helpers for device reference counts
    and locks (stable-fixes).
  - commit a7e6cbc

++++ lvm2:

  - enable devices file feature by default - see lvmdevices(8)
    * enable '--with-default-use-devices-file=1' in lvm2.spec
    * update commented default value of 'use_devicesfile' in lvm2.conf

++++ lz4:

  - Update to release 1.10.0
    * Support for multithreading
    * Full support for dictionary compression
    * New compression level 2

++++ ncurses:

  - Add ncurses patch 20240720
    + improve formatting/style of manpages (patches by Branden Robinson).
    + modify configure script and misc/Makefile to accept glob expressions
    that include Windows/DOS drive-letters (report by Eli Zaretskii).
    + fix misspelled ifdef and correct return-value of _nc_mingw_tcflush in
    win_driver.c (report/patch by Eli Zaretskii).

++++ openssl-3:

  - Build with no-afalgeng [bsc#1226463]
  - Security fix: [bsc#1227138, CVE-2024-5535]
    * SSL_select_next_proto buffer overread
    * Add openssl-CVE-2024-5535.patch

++++ orc:

  - Update to version 0.4.39:
  - Security: Fix error message printing buffer overflow leading
    to possible code execution in orcc with specific input files
    (CVE-2024-40897). This only affects developers and CI
    environments using orcc, not users of liborc (boo#1228184)
  - div255w: fix off-by-one error in the implementations
  - x86: only run AVX detection if xgetbv is available
  - x86: fix AVX detection by implementing the check recommended
    by Intel
  - Only enable JIT compilation on Apple arm64 if running on macOS,
    fixes crashes on iOS
  - Fix potential crash in emulation mode if logging is enabled
  - Handle undefined TARGET_OS_OSX correctly
  - orconce: Fix typo in GCC __sync-based implementation
  - orconce: Fix usage of __STDC_NO_ATOMICS__
  - Fix build with MSVC 17.10 + C11
  - Support stack unwinding on Windows
  - Major opcode and instruction set code clean-ups and refactoring
  - Refactor allocation and chunk initialization of code regions
  - Fall back to emulation on Linux if JIT support is not
    available, e.g. because of SELinux sandboxing or noexec
    mounting)

++++ python313-core:

  - Update to 3.13.0~b4:
  - Tests
  - gh-121084: Fix test_typing random leaks. Clear typing ABC
    caches when running tests for refleaks (-R option): call
    _abc_caches_clear() on typing abstract classes and their
    subclasses.
  - gh-121160: Add a test for
    readline.set_history_length(). Note that this test may fail
    on readline libraries.
  - gh-121200: Fix test_expanduser_pwd2() of
    test_posixpath. Call getpwnam() to get pw_dir, since it
    can be different than getpwall() pw_dir.
  - gh-121188: When creating the JUnit XML file, regrtest
    now escapes characters which are invalid in XML, such
    as the chr(27) control character used in ANSI escape
    sequences.
  - Library
  - gh-57141: The shallow argument to filecmp.dircmp (new in
    Python 3.13) is now keyword-only.
  - gh-121245: Simplify handling of the history file in
    site.register_readline() helper. The CAN_USE_PYREPL
    variable now will be initialized, when imported.
  - gh-121332: Fix constructor of ast nodes with custom
    _attributes. Previously, passing custom attributes would
    raise a DeprecationWarning. Passing arguments to the
    constructor that are not in _fields or _attributes remains
    deprecated.
  - gh-121279: Avoid NameError for the warnings module when
    accessing the depracated atributes of the importlib.abc
    module.
  - gh-121245: Fix a bug in the handling of the command history
    of the new REPL that caused the history file to be wiped at
    REPL exit.
  - gh-87744: Fix waitpid race while calling send_signal() in
    asyncio.
  - gh-121018: Fixed other issues where argparse.ArgumentParser
    did not honor exit_on_error=False.
  - gh-120678: Fix regression in the new REPL that meant that
    globals from files passed using the -i argument would not
    be included in the REPL’s global namespace.
  - gh-120782: Fix wrong references of the datetime types after
    reloading the module.
  - gh-120713: datetime.datetime.strftime() now 0-pads years
    with less than four digits for the format specifiers %Y and
    %G on Linux.
  - gh-117983: Defer the threading import in importlib.util
    until lazy loading is used.
  - gh-119189: When using the ** operator or pow() with
    Fraction as the base and an exponent that is not rational,
    a float, or a complex, the fraction is no longer converted
    to a float.
  - gh-118714: Allow restart in post-mortem debugging of
    pdb. Removed restart message when the user quits pdb from
    post-mortem mode.
  - gh-105623: Fix performance degradation in
    logging.handlers.RotatingFileHandler.
  - IDLE
  - gh-78889: Stop Shell freezes by blocking user access to
    non-method sys.stdout.shell attributes, which are all
    private.
  - Documentation
  - gh-121749: Fix documentation for PyModule_AddObjectRef().
  - gh-120012: Clarify the behaviours of
    multiprocessing.Queue.empty() and
    multiprocessing.SimpleQueue.empty() on closed queues.
  - Core and Builtins
  - gh-121860: Fix crash when rematerializing a managed
    dictionary after it was deleted.
  - gh-121814: Fixed the SegFault when PyEval_SetTrace() is
    used with no Python frame on stack.
  - gh-121295: Fix PyREPL console getting into a blocked state
    after interrupting a long paste
  - gh-121794: Fix bug in free-threaded Python where a
    resurrected object could lead to a negative ref count
    assertion failure.
  - gh-121657: Improve the SyntaxError message if the user
    tries to use yield from outside a function.
  - gh-121609: Fix pasting of characters containing unicode
    character joiners in the new REPL. Patch by Marta Gomez
    Macias
  - gh-117482: Unexpected slot wrappers are no longer created
    for builtin static types in subinterpreters.
  - gh-121499: Fix a bug affecting how multi-line history was
    being rendered in the new REPL after interacting with the
    new screen cache. Patch by Pablo Galindo
  - gh-121497: Fix a bug that was preventing the REPL to
    correctly respect the history when an input hook was
    set. Patch by Pablo Galindo
  - gh-121012: Tier 2 execution now ensures that list iterators
    remain exhausted, once they become exhausted.
  - gh-121439: Allow tuples of length 20 in the freelist to be
    reused.
  - gh-121368: Fix race condition in _PyType_Lookup in the
    free-threaded build due to a missing memory fence. This
    could lead to _PyType_Lookup returning incorrect results on
    arm64.
  - gh-121130: Fix f-strings with debug expressions in format
    specifiers. Patch by Pablo Galindo
  - gh-121115: PyLong_AsNativeBytes() no longer
    uses __index__() methods by default. The
    Py_ASNATIVEBYTES_ALLOW_INDEX flag has been added to allow
    it.
  - C API
  - gh-89364: Export the PySignal_SetWakeupFd()
    function. Previously, the function was documented but
    it couldn’t be used in 3rd party code. Patch by Victor
    Stinner.
  - gh-113993: PyUnicode_InternInPlace() no longer
    Seprevents its argument from being garbage collected
    Several functions that take char * are now documented
    Seas possibly preventing string objects from being
    Segarbage collected; refer to their documentation
    Sefor details: PyUnicode_InternFromString(),
    SePyDict_SetItemString(), PyObject_SetAttrString(),
    SePyObject_DelAttrString(), PyUnicode_InternFromString(),
    Seand PyModule_Add* convenience functions
  - gh-113601: Removed debug build assertions related to
    interning strings, which were falsely triggered by stable
    ABI extensions.
  - gh-112136: Restore the private _PyArg_Parser structure and
    the private _PyArg_ParseTupleAndKeywordsFast() function,
    previously removed in Python 3.13 alpha 1. Patch by Victor
    Stinner.
  - Build
  - gh-120371: Support WASI SDK 22 by explicitly skipping
    functions that are just stubs in wasi-libc.
  - gh-121731: Fix mimalloc compile error on GNU/Hurd
  - gh-121487: Fix deprecation warning for ATOMIC_VAR_INIT in
    mimalloc.
  - gh-121467: Fix a Makefile bug that prevented mimalloc
    header files from being installed.
  - gh-121103: On POSIX systems, excluding macOS framework
    installs, the lib directory for the free-threaded build now
    includes a “t” suffix to avoid conflicts with a co-located
    default build installation.
  - gh-120831: The default minimum iOS version was increased to
    13.0.
  - gh-113565: Improve curses and curses.panel dependency
    checks in configure.
  - Remove %suse_update_desktop_file macro as it is not useful any
    more.
  - Update bluez-devel-vendor.tar.xz vendored files.

++++ systemd:

  - Add temporarily 5003-core-when-switching-root-remove-run-systemd-before-e.patch (bsc#1227580)
  - Don't mention any rpm macros inside comments, even if escaped (bsc#1228091)
    Otherwise pesign-obs-integration ends up re-packaging systemd with all macros
    inside comments unescaped leading to unpredictable behavior. Now why rpm
    expands rpm macros inside comments is the question...

++++ python-ec2metadata:

  - Obsolete the Python 3.6 build

++++ python-gcemetadata:

  - Obsolete the Python 3.6 build

++++ python313:

  - Update to 3.13.0~b4:
  - Tests
  - gh-121084: Fix test_typing random leaks. Clear typing ABC
    caches when running tests for refleaks (-R option): call
    _abc_caches_clear() on typing abstract classes and their
    subclasses.
  - gh-121160: Add a test for
    readline.set_history_length(). Note that this test may fail
    on readline libraries.
  - gh-121200: Fix test_expanduser_pwd2() of
    test_posixpath. Call getpwnam() to get pw_dir, since it
    can be different than getpwall() pw_dir.
  - gh-121188: When creating the JUnit XML file, regrtest
    now escapes characters which are invalid in XML, such
    as the chr(27) control character used in ANSI escape
    sequences.
  - Library
  - gh-57141: The shallow argument to filecmp.dircmp (new in
    Python 3.13) is now keyword-only.
  - gh-121245: Simplify handling of the history file in
    site.register_readline() helper. The CAN_USE_PYREPL
    variable now will be initialized, when imported.
  - gh-121332: Fix constructor of ast nodes with custom
    _attributes. Previously, passing custom attributes would
    raise a DeprecationWarning. Passing arguments to the
    constructor that are not in _fields or _attributes remains
    deprecated.
  - gh-121279: Avoid NameError for the warnings module when
    accessing the depracated atributes of the importlib.abc
    module.
  - gh-121245: Fix a bug in the handling of the command history
    of the new REPL that caused the history file to be wiped at
    REPL exit.
  - gh-87744: Fix waitpid race while calling send_signal() in
    asyncio.
  - gh-121018: Fixed other issues where argparse.ArgumentParser
    did not honor exit_on_error=False.
  - gh-120678: Fix regression in the new REPL that meant that
    globals from files passed using the -i argument would not
    be included in the REPL’s global namespace.
  - gh-120782: Fix wrong references of the datetime types after
    reloading the module.
  - gh-120713: datetime.datetime.strftime() now 0-pads years
    with less than four digits for the format specifiers %Y and
    %G on Linux.
  - gh-117983: Defer the threading import in importlib.util
    until lazy loading is used.
  - gh-119189: When using the ** operator or pow() with
    Fraction as the base and an exponent that is not rational,
    a float, or a complex, the fraction is no longer converted
    to a float.
  - gh-118714: Allow restart in post-mortem debugging of
    pdb. Removed restart message when the user quits pdb from
    post-mortem mode.
  - gh-105623: Fix performance degradation in
    logging.handlers.RotatingFileHandler.
  - IDLE
  - gh-78889: Stop Shell freezes by blocking user access to
    non-method sys.stdout.shell attributes, which are all
    private.
  - Documentation
  - gh-121749: Fix documentation for PyModule_AddObjectRef().
  - gh-120012: Clarify the behaviours of
    multiprocessing.Queue.empty() and
    multiprocessing.SimpleQueue.empty() on closed queues.
  - Core and Builtins
  - gh-121860: Fix crash when rematerializing a managed
    dictionary after it was deleted.
  - gh-121814: Fixed the SegFault when PyEval_SetTrace() is
    used with no Python frame on stack.
  - gh-121295: Fix PyREPL console getting into a blocked state
    after interrupting a long paste
  - gh-121794: Fix bug in free-threaded Python where a
    resurrected object could lead to a negative ref count
    assertion failure.
  - gh-121657: Improve the SyntaxError message if the user
    tries to use yield from outside a function.
  - gh-121609: Fix pasting of characters containing unicode
    character joiners in the new REPL. Patch by Marta Gomez
    Macias
  - gh-117482: Unexpected slot wrappers are no longer created
    for builtin static types in subinterpreters.
  - gh-121499: Fix a bug affecting how multi-line history was
    being rendered in the new REPL after interacting with the
    new screen cache. Patch by Pablo Galindo
  - gh-121497: Fix a bug that was preventing the REPL to
    correctly respect the history when an input hook was
    set. Patch by Pablo Galindo
  - gh-121012: Tier 2 execution now ensures that list iterators
    remain exhausted, once they become exhausted.
  - gh-121439: Allow tuples of length 20 in the freelist to be
    reused.
  - gh-121368: Fix race condition in _PyType_Lookup in the
    free-threaded build due to a missing memory fence. This
    could lead to _PyType_Lookup returning incorrect results on
    arm64.
  - gh-121130: Fix f-strings with debug expressions in format
    specifiers. Patch by Pablo Galindo
  - gh-121115: PyLong_AsNativeBytes() no longer
    uses __index__() methods by default. The
    Py_ASNATIVEBYTES_ALLOW_INDEX flag has been added to allow
    it.
  - C API
  - gh-89364: Export the PySignal_SetWakeupFd()
    function. Previously, the function was documented but
    it couldn’t be used in 3rd party code. Patch by Victor
    Stinner.
  - gh-113993: PyUnicode_InternInPlace() no longer
    Seprevents its argument from being garbage collected
    Several functions that take char * are now documented
    Seas possibly preventing string objects from being
    Segarbage collected; refer to their documentation
    Sefor details: PyUnicode_InternFromString(),
    SePyDict_SetItemString(), PyObject_SetAttrString(),
    SePyObject_DelAttrString(), PyUnicode_InternFromString(),
    Seand PyModule_Add* convenience functions
  - gh-113601: Removed debug build assertions related to
    interning strings, which were falsely triggered by stable
    ABI extensions.
  - gh-112136: Restore the private _PyArg_Parser structure and
    the private _PyArg_ParseTupleAndKeywordsFast() function,
    previously removed in Python 3.13 alpha 1. Patch by Victor
    Stinner.
  - Build
  - gh-120371: Support WASI SDK 22 by explicitly skipping
    functions that are just stubs in wasi-libc.
  - gh-121731: Fix mimalloc compile error on GNU/Hurd
  - gh-121487: Fix deprecation warning for ATOMIC_VAR_INIT in
    mimalloc.
  - gh-121467: Fix a Makefile bug that prevented mimalloc
    header files from being installed.
  - gh-121103: On POSIX systems, excluding macOS framework
    installs, the lib directory for the free-threaded build now
    includes a “t” suffix to avoid conflicts with a co-located
    default build installation.
  - gh-120831: The default minimum iOS version was increased to
    13.0.
  - gh-113565: Improve curses and curses.panel dependency
    checks in configure.
  - Remove %suse_update_desktop_file macro as it is not useful any
    more.
  - Update bluez-devel-vendor.tar.xz vendored files.

++++ python-msgpack:

  - Update to 1.0.8
    * Update Cython to 3.0.8. This fixes memory leak when iterating
    ``Unpacker`` object on Python 3.12.
    * Do not include C/Cython files in binary wheels.
  - Drop removal of C/Cython files from %install section

++++ runc:

    [ This was only ever released for SLES and Leap. ]
  - Update to runc v1.1.13. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.1.13>.
  - Rebase patches:
    * 0001-bsc1221050-libct-seccomp-patchbpf-rm-duplicated-code.patch
    * 0002-bsc1221050-seccomp-patchbpf-rename-nativeArch-linuxA.patch
    * 0003-bsc1221050-seccomp-patchbpf-always-include-native-ar.patch
  - Backport <https://github.com/opencontainers/runc/pull/3931> to fix a
    performance issue when running lots of containers, caused by systemd getting
    too many mount notifications. bsc#1214960
    + 0004-bsc1214960-nsenter-cloned_binary-remove-bindfd-logic.patch

++++ thin-provisioning-tools:

  - Update to version 1.0.13:
    * bump version to 1.0.13
    * [io_engine] Remove duplicate code in tests
    * [build] Update quick-xml to v0.36
    * [build] Update dependencies
    * [doc] Update CHANGES
    * [thin_check] Correct the number of devices to check in logs
    * [doc] Update TODO list
    * [man] Update man page for thin_ls
    * [io_engine] Add test cases for SyncIoEngine::write_many()
    * [io_engine] Enlarge the batch size for SyncIoEngine to do vectored write
    * [io_engine] Use vectored write in sync io
    * [tests] Use sha256sum to avoid collision
    * [all] Fix clippy lints
    * [tests] Fix thin snapshot xml generator
    * [tests] Fix the mapped_blocks for thins in generated xml
    * [thin_check] Log the number of exclusive devices in metadata snapshot
    * [devtools] Fix parsing subcommands through symlinks
    * deps: bump libc from 0.2.153 to 0.2.155
    * [thin_repair] Support repairing device details tree
    * [tests] Replace duplicate code with utility functions
    * [thin_repair] Remove unused code
    * [thin_repair] Preserve the timestamp of stale superblock if needed
    * [thin_explore] Fix missing version option
    * Add a nix flake to provide a dev env
    * [thin_delta] Update comments
    * [tests] Test cache_check --auto-repair and --clear-needs-check-flag
    * [tests] Introduce cache_generate_damage
    * [tests] Add broken pipe tests for cache_dump and era_dump
    * [cache_check] Extend the --clear-needs-check-flag option to have auto-repair caps
    * [thin_ls] Support listing the highest mapped block
    * [btree] Remove unused imports
    * [btree] Add BTreeIterator type
    * [*_dump] Simplify the handling of error context
    * [cache/era_dump] Do not print error messages on BrokenPipe (EPIPE)
    * [tests] Explicitly set the fifo capacity for triggering EPIPE
    * [tests] Support leaving TestDir undeleted for debugging failed commands
    * [tests] Ensure thin_dump's output in broken pipe tests
    * [tests] Fix closing the pipe fd twice
    * [tests] Explicitly set the pipe capacity for triggering EPIPE

++++ xfsprogs:

  - update to 6.9.0
  - xfs_db: Fix uninicialized error variable
  - mkfs.xfs: avoid potential overflowing expression in xfs_mkfs.c
  - xfs_io: fix mread with length 1 mod page size
  - xfs_repair: detect null buf passed to duration
  - xfs_io: fix gcc complaints about potentially uninitialized variables
  - xfs_scrub: upload clean bills of health
  - xfs_spaceman: report health of inode link counts
  - xfs_repair: reduce rmap bag memory usage when creating refcounts
  - xfs_repair: log when buffers fail CRC checks even if we just recompute it
  - xfs_scrub: use multiple threads to run scrubs that scan inodes
  - xfs_scrub: update health status if we get a clean bill of health
  - xfs_repair: verify on-disk rmap btrees with in-memory btree data
  - xfs_scrub: check file link counts
  - xfs_scrub: implement live quotacheck inode scan
  - libxfs: provide a kernel-compatible kasprintf
  - xfs_spaceman: report the health of quota counts
  - libxfs: partition memfd files to avoid using too many fds
  - libxfs: add xfile support
  - libxfs: teach buftargs to maintain their own buffer hashtable
  - libxfs: kernel sync
  - ------------------------------------------------------------------

------------------------------------------------------------------
------------------  2024-7-21  -  Jul 21 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.0.25 → 10.0.26

++++ strace:

  - Update to strace 6.10
    * Implemented --decode-fds=eventfd option to retrieve eventfd object details
    associated with eventfd file descriptors.
    * Implemented decoding of NETLINK_GENERIC nlctrl protocol.
    * Implemented decoding of F_DUPFD_QUERY fcntl.
    * Implemented decoding of mseal syscall.
    * Updated decoding of statx and prctl syscalls.
    * Updated decoding of BPF_RAW_TRACEPOINT_OPEN bpf command.
    * Updated lists of BPF_*, IORING_*, KEXEC_*, KEY_*, LANDLOCK_*, PR_*, STATX_*,
    TCP_*, TEE_*, V4L2_*, and *_MAGIC constants.
    * Updated lists of ioctl commands from Linux 6.10.
    * Worked around a bug introduced in Linux 6.5 that affected system call
    tampering on riscv64.

------------------------------------------------------------------
------------------  2024-7-20  -  Jul 20 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ALSA: hda/realtek: Fix the speaker output on Samsung Galaxy
    Book Pro 360 (stable-fixes).
  - ALSA: hda/tas2781: Add new quirk for Lenovo Hera2 Laptop
    (stable-fixes).
  - ASoC: SOF: ipc4-topology: Use correct queue_id for requesting
    input pin format (stable-fixes).
  - ALSA: hda/realtek: Enable headset mic on Positivo SU C1400
    (stable-fixes).
  - commit be4d8bf
  - eeprom: at24: Probe for DDR3 thermal sensor in the SPD case
    (stable-fixes).
  - Refresh
    patches.suse/eeprom-at24-fix-memory-corruption-race-condition.patch.
  - commit 82fbd42
  - Input: elan_i2c - do not leave interrupt disabled on suspend
    failure (git-fixes).
  - Input: qt1050 - handle CHIP_ID reading error (git-fixes).
  - interconnect: qcom: qcm2290: Fix mas_snoc_bimc RPM master ID
    (git-fixes).
  - iio: frequency: adrf6780: rm clk provider include (git-fixes).
  - iio: Fix the sorting functionality in
    iio_gts_build_avail_time_table (git-fixes).
  - eeprom: digsy_mtc: Fix 93xx46 driver probe failure (git-fixes).
  - Revert "usb: musb: da8xx: Set phy in OTG mode by default"
    (stable-fixes).
  - ALSA: seq: ump: Skip useless ports for static blocks
    (git-fixes).
  - ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value
    (git-fixes).
  - ASoC: amd: Adjust error handling in case of absent codec device
    (git-fixes).
  - ASoC: max98088: Check for clk_prepare_enable() error
    (git-fixes).
  - ASoC: qcom: Adjust issues in case of DT error in
    asoc_qcom_lpass_cpu_platform_probe() (git-fixes).
  - ASoC: cs35l56: Accept values greater than 0 as IRQ numbers
    (git-fixes).
  - ASoc: tas2781: Enable RCA-based playback without DSP firmware
    download (git-fixes).
  - crypto: qat - extend scope of lock in
    adf_cfg_add_key_value_param() (git-fixes).
  - hwrng: core - Fix wrong quality calculation at hw rng
    registration (git-fixes).
  - crypto: ccp - Fix null pointer dereference in
    __sev_snp_shutdown_locked (git-fixes).
  - crypto: ecdsa - Fix the public key format description
    (git-fixes).
  - hwrng: amd - Convert PCIBIOS_* return codes to errnos
    (git-fixes).
  - commit 7fcc337

++++ kernel-rt:

  - ALSA: hda/realtek: Fix the speaker output on Samsung Galaxy
    Book Pro 360 (stable-fixes).
  - ALSA: hda/tas2781: Add new quirk for Lenovo Hera2 Laptop
    (stable-fixes).
  - ASoC: SOF: ipc4-topology: Use correct queue_id for requesting
    input pin format (stable-fixes).
  - ALSA: hda/realtek: Enable headset mic on Positivo SU C1400
    (stable-fixes).
  - commit be4d8bf
  - eeprom: at24: Probe for DDR3 thermal sensor in the SPD case
    (stable-fixes).
  - Refresh
    patches.suse/eeprom-at24-fix-memory-corruption-race-condition.patch.
  - commit 82fbd42
  - Input: elan_i2c - do not leave interrupt disabled on suspend
    failure (git-fixes).
  - Input: qt1050 - handle CHIP_ID reading error (git-fixes).
  - interconnect: qcom: qcm2290: Fix mas_snoc_bimc RPM master ID
    (git-fixes).
  - iio: frequency: adrf6780: rm clk provider include (git-fixes).
  - iio: Fix the sorting functionality in
    iio_gts_build_avail_time_table (git-fixes).
  - eeprom: digsy_mtc: Fix 93xx46 driver probe failure (git-fixes).
  - Revert "usb: musb: da8xx: Set phy in OTG mode by default"
    (stable-fixes).
  - ALSA: seq: ump: Skip useless ports for static blocks
    (git-fixes).
  - ASoC: fsl: fsl_qmc_audio: Check devm_kasprintf() returned value
    (git-fixes).
  - ASoC: amd: Adjust error handling in case of absent codec device
    (git-fixes).
  - ASoC: max98088: Check for clk_prepare_enable() error
    (git-fixes).
  - ASoC: qcom: Adjust issues in case of DT error in
    asoc_qcom_lpass_cpu_platform_probe() (git-fixes).
  - ASoC: cs35l56: Accept values greater than 0 as IRQ numbers
    (git-fixes).
  - ASoc: tas2781: Enable RCA-based playback without DSP firmware
    download (git-fixes).
  - crypto: qat - extend scope of lock in
    adf_cfg_add_key_value_param() (git-fixes).
  - hwrng: core - Fix wrong quality calculation at hw rng
    registration (git-fixes).
  - crypto: ccp - Fix null pointer dereference in
    __sev_snp_shutdown_locked (git-fixes).
  - crypto: ecdsa - Fix the public key format description
    (git-fixes).
  - hwrng: amd - Convert PCIBIOS_* return codes to errnos
    (git-fixes).
  - commit 7fcc337

++++ libnl3:

  - Update to release 3.10
    * route: support for setting ageing time for dynamic bridge
    table entries
    * route: support for VLAN filtering on bridge ports
    * route: support for layer 3 filtering on bridges

++++ ucode-intel:

  - update to 20240531:
    * Update for functional issues. Refer to Intel® Pentium® Silver
    and Intel® Celeron® Processor Specification Update
  - Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | GLK            | B0       | 06-7a-01/01 | 00000040 | 00000042 | Pentium Silver N/J5xxx, Celeron N/J4xxx

------------------------------------------------------------------
------------------  2024-7-19  -  Jul 19 2024  -------------------
------------------------------------------------------------------

++++ coreutils:

  - Avoid empty scriptlets

++++ coreutils-systemd:

  - Avoid empty scriptlets

++++ python-kiwi:

  - Revise scripts_testing.rst
  - Revise schema_extensions.rst

++++ grub2:

  - Fix error in grub-install when root is on tmpfs (bsc#1226100)
    * 0001-grub-install-bailout-root-device-probing.patch
  - Fix incorrect Platform tag in rpm header (bsc#1217967)

++++ keepalived:

  - Update to 2.3.1
    https://www.keepalived.org/release-notes/Release-2.3.0.html
    https://www.keepalived.org/release-notes/Release-2.3.1.html

++++ kernel-default:

  - Add Alt-commit for amdgpu patch (git-fixes)
  - commit 7fbd801
  - gve: Clear napi->skb before dev_kfree_skb_any() (CVE-2024-40937
    bsc#1227836).
  - net: hns3: fix kernel crash problem in concurrent scenario
    (CVE-2024-39507 bsc#1227730).
  - net/mlx5: Fix tainted pointer delete is case of flow rules
    creation fail (CVE-2024-40940 bsc#1227800).
  - commit 8d4dcfb
  - net: ethtool: fix the error condition in
    ethtool_get_phy_stats_ethtool() (CVE-2024-40928 bsc#1227788).
  - commit be667d4
  - btrfs: zoned: fix lock ordering in btrfs_zone_activate()
    (bsc#1223731 CVE-2024-26944).
  - commit c6e27f8
  - vmxnet3: disable rx data ring on dma allocation failure
    (CVE-2024-40923 bsc#1227786).
  - commit 3828e87
  - mptcp: ensure snd_una is properly initialized on connect
    (CVE-2024-40931 bsc#1227780).
  - commit 60fd0e2
  - bnxt_en: Adjust logging of firmware messages in case of released
    token in __hwrm_send() (CVE-2024-40919 bsc#1227779).
  - commit c060c32
  - btrfs: zoned: allocate dummy checksums for zoned NODATASUM
    writes (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: fix use-after-free in do_zone_finish()
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: fix chunk map leak when loading block group zone
    info (bsc#1223731 CVE-2024-26944).
  - btrfs: fix unbalanced unlock of mapping_tree_lock (bsc#1223731
    CVE-2024-26944).
  - btrfs: remove stripe size local variable from
    insert_dev_extents() (bsc#1223731 CVE-2024-26944).
  - btrfs: use a dedicated data structure for chunk maps
    (bsc#1223731 CVE-2024-26944).
  - commit 201e016
  - btrfs: zoned: wait for data BG to be finished on direct IO
    allocation (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: drop no longer valid write pointer check
    (bsc#1223731 CVE-2024-26944).
  - commit a5e78f9
  - btrfs: do not require EXTENT_NOWAIT for btrfs_redirty_list_add()
    (bsc#1223731 CVE-2024-26944).
  - commit f638537
  - drm/mediatek: Add DRM_MODE_ROTATE_0 to rotation property
    (git-fixes).
  - commit f21db33
  - btrfs: drop gfp from parameter extent state helpers (bsc#1223731
    CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-make-find_first_extent_bit-return-a-boolean.patch.
  - Refresh
    patches.suse/btrfs-open-code-trivial-btrfs_add_excluded_extent.patch.
  - commit 2097a9c
  - drm/fbdev-dma: Fix framebuffer mode for big endian devices
    (git-fixes).
  - drm/msm/mdp5: Remove MDP_CAP_SRC_SPLIT from msm8x53_config
    (git-fixes).
  - drm/msm/dpu: drop validity checks for clear_pending_flush()
    ctl op (git-fixes).
  - drm/msm/dsi: set VIDEO_COMPRESSION_MODE_CTRL_WC (git-fixes).
  - USB: serial: option: add Rolling RW350-GL variants
    (stable-fixes).
  - USB: serial: option: add support for Foxconn T99W651
    (stable-fixes).
  - USB: serial: option: add Netprisma LCUK54 series modules
    (stable-fixes).
  - usb: gadget: configfs: Prevent OOB read/write in
    usb_string_copy() (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Panther Lake
    (stable-fixes).
  - USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
    (stable-fixes).
  - xhci: always resume roothubs if xHC was reset during resume
    (stable-fixes).
  - USB: serial: option: add Telit generic core-dump composition
    (stable-fixes).
  - USB: serial: option: add Fibocom FM350-GL (stable-fixes).
  - USB: serial: option: add Telit FN912 rmnet compositions
    (stable-fixes).
  - commit f9ac994
  - drm/msm/dpu: fix encoder irq wait skip (git-fixes).
  - drm/dp_mst: Fix all mstb marked as not probed after
    suspend/resume (git-fixes).
  - drm/panfrost: Mark simple_ondemand governor as softdep
    (git-fixes).
  - drm/lima: Mark simple_ondemand governor as softdep (git-fixes).
  - drm/mediatek: Remove less-than-zero comparison of an unsigned
    value (git-fixes).
  - drm/mediatek: Fix bit depth overwritten for mtk_ovl_set
    bit_depth() (git-fixes).
  - drm/mediatek: Support DRM plane alpha in Mixer (git-fixes).
  - drm/mediatek: Support DRM plane alpha in OVL (git-fixes).
  - drm/mediatek: Support RGBA8888 and RGBX8888 in OVL on MT8195
    (git-fixes).
  - drm/mediatek: Set DRM mode configs accordingly (git-fixes).
  - drm/mediatek: Add OVL compatible name for MT8195 (git-fixes).
  - drm/mediatek: Turn off the layers with zero width or height
    (git-fixes).
  - drm/mediatek: Fix destination alpha error in OVL (git-fixes).
  - drm/mediatek: Fix XRGB setting error in Mixer (git-fixes).
  - drm/mediatek: Fix XRGB setting error in OVL (git-fixes).
  - drm/mediatek: Use 8-bit alpha in ETHDR (git-fixes).
  - drm/mediatek: Add missing plane settings when async update
    (git-fixes).
  - drm/etnaviv: fix DMA direction handling for cached RW buffers
    (git-fixes).
  - Revert "drm/bridge: tc358767: Set default CLRSIPO count"
    (stable-fixes).
  - drm/qxl: Add check for drm_cvt_mode (git-fixes).
  - drm: zynqmp_kms: Fix AUX bus not getting unregistered
    (git-fixes).
  - drm: zynqmp_dpsub: Fix an error handling path in
    zynqmp_dpsub_probe() (git-fixes).
  - drm/bridge: samsung-dsim: Set P divider based on min/max of
    fin pll (git-fixes).
  - drm/bridge: it6505: fix hibernate to resume no display issue
    (git-fixes).
  - drm/panel: ilitek-ili9882t: Check for errors on the NOP in
    prepare() (git-fixes).
  - drm/panel: ilitek-ili9882t: If prepare fails, disable GPIO
    before regulators (git-fixes).
  - drm/panel: boe-tv101wum-nl6: Check for errors on the NOP in
    prepare() (git-fixes).
  - drm/panel: boe-tv101wum-nl6: If prepare fails, disable GPIO
    before regulators (git-fixes).
  - drm/panel: himax-hx8394: Handle errors from
    mipi_dsi_dcs_set_display_on() better (git-fixes).
  - drm/mgag200: Bind I2C lifetime to DRM device (git-fixes).
  - drm/mgag200: Set DDC timeout in milliseconds (git-fixes).
  - drm/mipi-dsi: Fix theoretical int overflow in
    mipi_dsi_generic_write_seq() (git-fixes).
  - drm/mipi-dsi: Fix theoretical int overflow in
    mipi_dsi_dcs_write_seq() (git-fixes).
  - commit 6fb58b4
  - drm/udl: Remove DRM_CONNECTOR_POLL_HPD (git-fixes).
  - drm/arm/komeda: Fix komeda probe failing if there are no links
    in the secondary pipeline (git-fixes).
  - drm/rockchip: vop2: Fix the port mux of VP2 (git-fixes).
  - drm/amd/display: Move 'struct scaler_data' off stack
    (git-fixes).
  - drm/amdgpu: Remove GC HW IP 9.3.0 from noretry=1 (git-fixes).
  - drm/amdgpu: Check if NBIO funcs are NULL in
    amdgpu_device_baco_exit (git-fixes).
  - drm/amdgpu: Fix memory range calculation (git-fixes).
  - drm/amd/pm: Fix aldebaran pcie speed reporting (git-fixes).
  - drm/amd/pm: remove logically dead code for renoir (git-fixes).
  - drm/amdkfd: Fix CU Masking for GFX 9.4.3 (git-fixes).
  - drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
    (git-fixes).
  - commit ba21687
  - Add Alt-commit to AMDGPU patches from 6.11-rc1
  - commit f4ae72a
  - PCI/ASPM: Update save_state when configuration changes (bsc#1226915)
  - commit 5192284
  - block: Move checking GENHD_FL_NO_PART to bdev_add_partition()
    (bsc#1226213).
  - commit 6855b2f
  - bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set() (CVE-2024-39487 bsc#1227573)
  - commit 1c7a482
  - tls: get psock ref after taking rxlock to avoid leak (CVE-2024-35908 bsc#1224490)
  - commit b0d23d0
  - netfilter: nf_tables: flush pending destroy work before exit_net release (CVE-2024-35899 bsc#1224499)
  - commit 8a86808

++++ kernel-rt:

  - Add Alt-commit for amdgpu patch (git-fixes)
  - commit 7fbd801
  - gve: Clear napi->skb before dev_kfree_skb_any() (CVE-2024-40937
    bsc#1227836).
  - net: hns3: fix kernel crash problem in concurrent scenario
    (CVE-2024-39507 bsc#1227730).
  - net/mlx5: Fix tainted pointer delete is case of flow rules
    creation fail (CVE-2024-40940 bsc#1227800).
  - commit 8d4dcfb
  - net: ethtool: fix the error condition in
    ethtool_get_phy_stats_ethtool() (CVE-2024-40928 bsc#1227788).
  - commit be667d4
  - btrfs: zoned: fix lock ordering in btrfs_zone_activate()
    (bsc#1223731 CVE-2024-26944).
  - commit c6e27f8
  - vmxnet3: disable rx data ring on dma allocation failure
    (CVE-2024-40923 bsc#1227786).
  - commit 3828e87
  - mptcp: ensure snd_una is properly initialized on connect
    (CVE-2024-40931 bsc#1227780).
  - commit 60fd0e2
  - bnxt_en: Adjust logging of firmware messages in case of released
    token in __hwrm_send() (CVE-2024-40919 bsc#1227779).
  - commit c060c32
  - btrfs: zoned: allocate dummy checksums for zoned NODATASUM
    writes (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: fix use-after-free in do_zone_finish()
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: fix chunk map leak when loading block group zone
    info (bsc#1223731 CVE-2024-26944).
  - btrfs: fix unbalanced unlock of mapping_tree_lock (bsc#1223731
    CVE-2024-26944).
  - btrfs: remove stripe size local variable from
    insert_dev_extents() (bsc#1223731 CVE-2024-26944).
  - btrfs: use a dedicated data structure for chunk maps
    (bsc#1223731 CVE-2024-26944).
  - commit 201e016
  - btrfs: zoned: wait for data BG to be finished on direct IO
    allocation (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: drop no longer valid write pointer check
    (bsc#1223731 CVE-2024-26944).
  - commit a5e78f9
  - btrfs: do not require EXTENT_NOWAIT for btrfs_redirty_list_add()
    (bsc#1223731 CVE-2024-26944).
  - commit f638537
  - drm/mediatek: Add DRM_MODE_ROTATE_0 to rotation property
    (git-fixes).
  - commit f21db33
  - btrfs: drop gfp from parameter extent state helpers (bsc#1223731
    CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-make-find_first_extent_bit-return-a-boolean.patch.
  - Refresh
    patches.suse/btrfs-open-code-trivial-btrfs_add_excluded_extent.patch.
  - commit 2097a9c
  - drm/fbdev-dma: Fix framebuffer mode for big endian devices
    (git-fixes).
  - drm/msm/mdp5: Remove MDP_CAP_SRC_SPLIT from msm8x53_config
    (git-fixes).
  - drm/msm/dpu: drop validity checks for clear_pending_flush()
    ctl op (git-fixes).
  - drm/msm/dsi: set VIDEO_COMPRESSION_MODE_CTRL_WC (git-fixes).
  - USB: serial: option: add Rolling RW350-GL variants
    (stable-fixes).
  - USB: serial: option: add support for Foxconn T99W651
    (stable-fixes).
  - USB: serial: option: add Netprisma LCUK54 series modules
    (stable-fixes).
  - usb: gadget: configfs: Prevent OOB read/write in
    usb_string_copy() (stable-fixes).
  - usb: dwc3: pci: add support for the Intel Panther Lake
    (stable-fixes).
  - USB: Add USB_QUIRK_NO_SET_INTF quirk for START BP-850k
    (stable-fixes).
  - xhci: always resume roothubs if xHC was reset during resume
    (stable-fixes).
  - USB: serial: option: add Telit generic core-dump composition
    (stable-fixes).
  - USB: serial: option: add Fibocom FM350-GL (stable-fixes).
  - USB: serial: option: add Telit FN912 rmnet compositions
    (stable-fixes).
  - commit f9ac994
  - drm/msm/dpu: fix encoder irq wait skip (git-fixes).
  - drm/dp_mst: Fix all mstb marked as not probed after
    suspend/resume (git-fixes).
  - drm/panfrost: Mark simple_ondemand governor as softdep
    (git-fixes).
  - drm/lima: Mark simple_ondemand governor as softdep (git-fixes).
  - drm/mediatek: Remove less-than-zero comparison of an unsigned
    value (git-fixes).
  - drm/mediatek: Fix bit depth overwritten for mtk_ovl_set
    bit_depth() (git-fixes).
  - drm/mediatek: Support DRM plane alpha in Mixer (git-fixes).
  - drm/mediatek: Support DRM plane alpha in OVL (git-fixes).
  - drm/mediatek: Support RGBA8888 and RGBX8888 in OVL on MT8195
    (git-fixes).
  - drm/mediatek: Set DRM mode configs accordingly (git-fixes).
  - drm/mediatek: Add OVL compatible name for MT8195 (git-fixes).
  - drm/mediatek: Turn off the layers with zero width or height
    (git-fixes).
  - drm/mediatek: Fix destination alpha error in OVL (git-fixes).
  - drm/mediatek: Fix XRGB setting error in Mixer (git-fixes).
  - drm/mediatek: Fix XRGB setting error in OVL (git-fixes).
  - drm/mediatek: Use 8-bit alpha in ETHDR (git-fixes).
  - drm/mediatek: Add missing plane settings when async update
    (git-fixes).
  - drm/etnaviv: fix DMA direction handling for cached RW buffers
    (git-fixes).
  - Revert "drm/bridge: tc358767: Set default CLRSIPO count"
    (stable-fixes).
  - drm/qxl: Add check for drm_cvt_mode (git-fixes).
  - drm: zynqmp_kms: Fix AUX bus not getting unregistered
    (git-fixes).
  - drm: zynqmp_dpsub: Fix an error handling path in
    zynqmp_dpsub_probe() (git-fixes).
  - drm/bridge: samsung-dsim: Set P divider based on min/max of
    fin pll (git-fixes).
  - drm/bridge: it6505: fix hibernate to resume no display issue
    (git-fixes).
  - drm/panel: ilitek-ili9882t: Check for errors on the NOP in
    prepare() (git-fixes).
  - drm/panel: ilitek-ili9882t: If prepare fails, disable GPIO
    before regulators (git-fixes).
  - drm/panel: boe-tv101wum-nl6: Check for errors on the NOP in
    prepare() (git-fixes).
  - drm/panel: boe-tv101wum-nl6: If prepare fails, disable GPIO
    before regulators (git-fixes).
  - drm/panel: himax-hx8394: Handle errors from
    mipi_dsi_dcs_set_display_on() better (git-fixes).
  - drm/mgag200: Bind I2C lifetime to DRM device (git-fixes).
  - drm/mgag200: Set DDC timeout in milliseconds (git-fixes).
  - drm/mipi-dsi: Fix theoretical int overflow in
    mipi_dsi_generic_write_seq() (git-fixes).
  - drm/mipi-dsi: Fix theoretical int overflow in
    mipi_dsi_dcs_write_seq() (git-fixes).
  - commit 6fb58b4
  - drm/udl: Remove DRM_CONNECTOR_POLL_HPD (git-fixes).
  - drm/arm/komeda: Fix komeda probe failing if there are no links
    in the secondary pipeline (git-fixes).
  - drm/rockchip: vop2: Fix the port mux of VP2 (git-fixes).
  - drm/amd/display: Move 'struct scaler_data' off stack
    (git-fixes).
  - drm/amdgpu: Remove GC HW IP 9.3.0 from noretry=1 (git-fixes).
  - drm/amdgpu: Check if NBIO funcs are NULL in
    amdgpu_device_baco_exit (git-fixes).
  - drm/amdgpu: Fix memory range calculation (git-fixes).
  - drm/amd/pm: Fix aldebaran pcie speed reporting (git-fixes).
  - drm/amd/pm: remove logically dead code for renoir (git-fixes).
  - drm/amdkfd: Fix CU Masking for GFX 9.4.3 (git-fixes).
  - drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq()
    (git-fixes).
  - commit ba21687
  - Add Alt-commit to AMDGPU patches from 6.11-rc1
  - commit f4ae72a
  - PCI/ASPM: Update save_state when configuration changes (bsc#1226915)
  - commit 5192284
  - block: Move checking GENHD_FL_NO_PART to bdev_add_partition()
    (bsc#1226213).
  - commit 6855b2f
  - bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set() (CVE-2024-39487 bsc#1227573)
  - commit 1c7a482
  - tls: get psock ref after taking rxlock to avoid leak (CVE-2024-35908 bsc#1224490)
  - commit b0d23d0
  - netfilter: nf_tables: flush pending destroy work before exit_net release (CVE-2024-35899 bsc#1224499)
  - commit 8a86808

++++ multipath-tools:

  - Update to version 0.9.9+161+suse.0c835ef:
    * Update to upstream reviewed code path (787e00d)
    * Added hardware defaults for Huawei storage arrays and XSG1 vendors
    * Refactored and improved the libultipath / libdevmapper interface
    * Fixed bug that caused queueing to be always disabled if flushing a map failed
    (bug introduced in 0.9.8). (bsc#1229898)
    * Fixed failure to remove maps even with `deferred_remove`
    (bug introduced in 0.9.9). (bsc#1229898)
    * CI improvements
    * Documentation fixes

++++ kubevirt:

  - Update to version 1.3.0
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.3.0
  - Drop upstreamed patch
    0001-Collect-component-Role-rules-under-operator-Role-ins.patch
  - Add registry path for SLE15 SP7

++++ pciutils:

  - Synchronize SLE-15 and openSUSE:Factory [jsc#PED-8393, bsc#1224138].
    The following patches are now obsolete in version 3.13.0:
    * lspci-Fixed-buffer-overflows-in-ls-tree.c.patch
    * pciutils-Add-PCIe-5.0-data-rate-32-GT-s-support.patch
    * pciutils-Add-PCIe-6.0-data-rate-64-GT-s-support.patch
    * pciutils-Add-decoding-of-vendor-specific-VPD-fields.patch
    * pciutils-VPD-Cleanup.patch
    * pciutils-VPD-When-printing-item-IDs-escape-non-ASCII-characte.patch

------------------------------------------------------------------
------------------  2024-7-18  -  Jul 18 2024  -------------------
------------------------------------------------------------------

++++ git:

  - Add CVE-2024-24577.patch
    * CVE-2024-24577: arbitrary code execution due to heap corruption
    in git_index_add (boo#1219660)

++++ kernel-default:

  - net/smc: reduce rtnl pressure in smc_pnet_create_pnetids_list() (CVE-2024-35934 bsc#1224641)
  - commit 812f420
  - net/sched: act_skbmod: prevent kernel-infoleak (CVE-2024-35893 bsc#1224512)
  - commit 5be3514
  - scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated
    memory (bsc#1227762 CVE-2024-40901).
  - commit 5eb5075
  - btrfs: pass NOWAIT for set/clear extent bits as another bit
    (bsc#1223731 CVE-2024-26944).
  - commit 33253df
  - btrfs: drop NOFAIL from set_extent_bit allocation masks
    (bsc#1223731 CVE-2024-26944).
  - commit 46559ec
  - btrfs: open code set_extent_bits (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-make-find_first_extent_bit-return-a-boolean.patch.
  - Refresh
    patches.suse/btrfs-open-code-trivial-btrfs_add_excluded_extent.patch.
  - commit 460a0d4
  - xfs: fix log recovery buffer allocation for the legacy h_size
    fixup (bsc#1227432 CVE-2024-39472).
  - commit 04ef30f
  - KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
    (CVE-2024-40953, bsc#1227806).
  - commit 60989df
  - Update config files (bsc#1227282).
    Update the CONFIG_LSM option to include the selinux LSM in the default set
    of LSMs. The selinux LSM will not get enabled because it is preceded by
    apparmor, which is the first exclusive LSM. Updating CONFIG_LSM resolves
    failures that result in the system not booting up when "security=selinux
    selinux=1" is passed to the kernel and SELinux policies are installed.
  - commit 0a95a78
  - xfs: use roundup_pow_of_two instead of ffs during xlog_find_tail
    (git-fixes).
  - commit 44812b1
  - wifi: mt76: connac: use muar idx 0xe for non-mt799x as well
    (bsc#1227149).
  - wifi: mt76: mt7996: fix potential memory leakage when reading
    chip temperature (bsc#1227149).
  - wifi: mt76: mt7996: fix uninitialized variable in
    mt7996_irq_tasklet() (bsc#1227149).
  - wifi: mt76: mt7925: ensure 4-byte alignment for suspend &
    wow command (bsc#1227149).
  - wifi: mt76: mt7996: fix size of txpower MCU command
    (bsc#1227149).
  - wifi: mt76: connac: check for null before dereferencing
    (bsc#1227149).
  - commit 4e5584e
  - wifi: mt76: Remove redundant assignment to variable tidno
    (bsc#1227149).
  - wifi: mt76: fix the issue of missing txpwr settings from ch153
    to ch177 (bsc#1227149).
  - wifi: mt76: mt7921: fix suspend issue on MediaTek COB platform
    (bsc#1227149).
  - wifi: mt76: mt7921: fix a potential association failure upon
    resuming (bsc#1227149).
  - wifi: mt76: mt7921: fix the unfinished command of regd_notifier
    before suspend (bsc#1227149).
  - wifi: mt76: mt792x: update the country list of EU for ACPI SAR
    (bsc#1227149).
  - wifi: mt76: mt7925e: fix use-after-free in free_irq()
    (bsc#1227149).
  - wifi: mt76: mt792x: add the illegal value check for mtcl table
    of acpi (bsc#1227149).
  - wifi: mt76: mt7925: fix the wrong data type for scan command
    (bsc#1227149).
  - wifi: mt76: set page_pool napi pointer for mmio devices
    (bsc#1227149).
  - wifi: mt76: mt792x: fix ethtool warning (bsc#1227149).
  - commit 3499113
  - wifi: mt76: connac: set correct muar_idx for mt799x chipsets
    (bsc#1227149).
  - wifi: mt76: mt7996: remove TXS queue setting (bsc#1227149).
  - wifi: mt76: mt7996: mark GCMP IGTK unsupported (bsc#1227149).
  - wifi: mt76: mt7996: ensure 4-byte alignment for beacon commands
    (bsc#1227149).
  - wifi: mt76: mt7996: check txs format before getting skb by pid
    (bsc#1227149).
  - wifi: mt76: mt7925: support temperature sensor (bsc#1227149).
  - wifi: mt76: mt7925: update PCIe DMA settings (bsc#1227149).
  - wifi: mt76: mt7925: add support to set ifs time by mcu command
    (bsc#1227149).
  - wifi: mt76: mt7925: add flow to avoid chip bt function fail
    (bsc#1227149).
  - wifi: mt76: mt7925: fix the wrong header translation config
    (bsc#1227149).
  - commit 7f22357
  - wifi: mt76: mt7925: fix WoW failed in encrypted mode
    (bsc#1227149).
  - wifi: mt76: mt7925: fix fw download fail (bsc#1227149).
  - wifi: mt76: mt7925: fix wmm queue mapping (bsc#1227149).
  - wifi: mt76: mt7925: fix mcu query command fail (bsc#1227149).
  - wifi: mt76: mt7925: fix SAP no beacon issue in 5Ghz and 6Ghz
    band (bsc#1227149).
  - wifi: mt76: mt7925: fix connect to 80211b mode fail in 2Ghz band
    (bsc#1227149).
  - wifi: mt76: mt76x2u: add netgear wdna3100v3 to device table
    (bsc#1227149).
  - wifi: mt76: mt792xu: enable dmashdl support (bsc#1227149).
  - wifi: mt76: usb: store usb endpoint in mt76_queue (bsc#1227149).
  - wifi: mt76: usb: create a dedicated queue for psd traffic
    (bsc#1227149).
  - commit 01e1acb
  - wifi: mt76: mt7996: fix fw loading timeout (bsc#1227149).
  - wifi: mt76: mt7915: update mt798x_wmac_adie_patch_7976
    (bsc#1227149).
  - wifi: mt76: mt7915: add locking for accessing mapped registers
    (bsc#1227149).
  - wifi: mt76: mt7915: fix error recovery with WED enabled
    (bsc#1227149).
  - wifi: mt76: check txs format before getting skb by pid
    (bsc#1227149).
  - wifi: mt76: disable HW AMSDU when using fixed rate
    (bsc#1227149).
  - wifi: mt76: mt7996: fix fortify warning (bsc#1227149).
  - commit 0013ef2
  - wifi: fill in MODULE_DESCRIPTION()s for mt76 drivers
    (bsc#1227149).
  - wifi: mt76: mt7996: Use DECLARE_FLEX_ARRAY() and fix
  - Warray-bounds warnings (bsc#1227149).
  - wifi: mt76: mt7921: fix wrong 6Ghz power type (bsc#1227149).
  - wifi: mt76: mt7921: fix CLC command timeout when suspend/resume
    (bsc#1227149).
  - wifi: mt76: mt7921: reduce the size of MCU firmware download
    Rx queue (bsc#1227149).
  - wifi: mt76: mt7996: set DMA mask to 36 bits for boards with
    more than 4GB of RAM (bsc#1227149).
  - wifi: mt76: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: mt76: mt7925: remove iftype from mt7925_init_eht_caps
    signature (bsc#1227149).
  - wifi: mt76: connac: add new definition of tx descriptor
    (bsc#1227149).
  - wifi: mt76: mt7996: adjust interface num and wtbl size for
    mt7992 (bsc#1227149).
  - commit cbff43f
  - wifi: mt76: mt7996: support mt7992 eeprom loading (bsc#1227149).
  - wifi: mt76: mt7996: rework register offsets for mt7992
    (bsc#1227149).
  - wifi: mt76: mt7996: add DMA support for mt7992 (bsc#1227149).
  - wifi: mt76: connac: add firmware support for mt7992
    (bsc#1227149).
  - wifi: mt76: mt7996: introduce mt7996_band_valid() (bsc#1227149).
  - wifi: mt76: mt7996: fix mt7996_mcu_all_sta_info_event struct
    packing (bsc#1227149).
  - wifi: mt76: mt7915: also MT7981 is 3T3R but nss2 on 5 GHz band
    (bsc#1227149).
  - wifi: mt76: mt7915: fix EEPROM offset of TSSI flag on MT7981
    (bsc#1227149).
  - wifi: mt76: connac: add beacon protection support for mt7996
    (bsc#1227149).
  - wifi: mt76: mt7996: rework ampdu params setting (bsc#1227149).
  - commit 3e59fd6
  - wifi: mt76: mt7996: add txpower setting support (bsc#1227149).
  - commit fd1825a
  - wifi: mt76: mt7996: fix alignment of sta info event
    (bsc#1227149).
  - wifi: mt76: mt7996: switch to mcu command for TX GI report
    (bsc#1227149).
  - wifi: mt76: use chainmask for power delta calculation
    (bsc#1227149).
  - wifi: mt76: change txpower init to per-phy (bsc#1227149).
  - wifi: mt76: mt7996: align the format of fixed rate command
    (bsc#1227149).
  - wifi: mt76: mt7996: handle IEEE80211_RC_SMPS_CHANGED
    (bsc#1227149).
  - wifi: mt76: connac: set fixed_bw bit in TX descriptor for
    fixed rate frames (bsc#1227149).
  - wifi: mt76: mt7996: adjust WFDMA settings to improve performance
    (bsc#1227149).
  - wifi: mt76: connac: add beacon duplicate TX mode support for
    mt7996 (bsc#1227149).
  - commit e90dd6a
  - wifi: mt76: move wed reset common code in mt76 module
    (bsc#1227149).
  - commit b63457a
  - wifi: mt76: mt7996: add thermal sensor device support
    (bsc#1227149).
  - wifi: mt76: connac: add thermal protection support for mt7996
    (bsc#1227149).
  - wifi: mt76: mt7996: add TX statistics for EHT mode in debugfs
    (bsc#1227149).
  - wifi: mt76: mt7996: add support for variants with auxiliary
    RX path (bsc#1227149).
  - wifi: mt76: mt7996: use u16 for val field in mt7996_mcu_set_rro
    signature (bsc#1227149).
  - wifi: mt76: dma: introduce __mt76_dma_queue_reset utility
    routine (bsc#1227149).
  - commit dd57284
  - wifi: mt76: increase MT_QFLAG_WED_TYPE size (bsc#1227149).
  - wifi: mt76: introduce wed pointer in mt76_queue (bsc#1227149).
  - wifi: mt76: introduce mt76_queue_is_wed_tx_free utility routine
    (bsc#1227149).
  - wifi: mt76: move mt76_net_setup_tc in common code (bsc#1227149).
  - wifi: mt76: move mt76_mmio_wed_offload_{enable,disable} in
    common code (bsc#1227149).
  - wifi: mt76: mmio: move mt76_mmio_wed_{init,release}_rx_buf in
    common code (bsc#1227149).
  - wifi: mt76: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: mt76: permit to load precal from NVMEM cell for mt7915
    (bsc#1227149).
  - wifi: mt76: permit to use alternative cell name to eeprom
    NVMEM load (bsc#1227149).
  - commit 15e9dc7
  - wifi: mt76: mt7921: support 5.9/6GHz channel config in acpi
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - commit 915b272
  - wifi: mt76: make mt76_get_of_eeprom static again (bsc#1227149).
  - wifi: mt76: limit support of precal loading for mt7915 to MTD
    only (bsc#1227149).
  - wifi: mt76: fix typo in mt76_get_of_eeprom_from_nvmem function
    (bsc#1227149).
  - wifi: mt76: mt7996: fix uninitialized variable in parsing txfree
    (bsc#1227149).
  - wifi: mt76: add ability to explicitly forbid LED registration
    with DT (bsc#1227149).
  - wifi: mt76: mt7925: fix typo in mt7925_init_he_caps
    (bsc#1227149).
  - wifi: mt76: mt7921: fix 6GHz disabled by the missing default
    CLC config (bsc#1227149).
  - net: fill in MODULE_DESCRIPTION()s in kuba@'s modules
    (bsc#1227149).
  - wifi: mt76: mt7921: fix kernel panic by accessing invalid 6GHz
    channel info (bsc#1227149).
  - commit b106ffb
  - wifi: mt76: Annotate struct mt76_rx_tid with __counted_by
    (bsc#1227149).
  - commit aecab86
  - wifi: mt76: mt7921: update the channel usage when the regd
    domain changed (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - commit b09df3f
  - wifi: mt76: mt7921: get regulatory information from the clc
    event (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - commit 04b07d9
  - wifi: mt76: mt7921: add 6GHz power type support for clc
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - commit b7bb561
  - wifi: mt76: mt7921: enable set txpower for UNII-4 (bsc#1227149).
  - wifi: mt76: mt7921: move connac nic capability handling to
    mt7921 (bsc#1227149).
  - wifi: mt76: reduce spin_lock_bh held up in mt76_dma_rx_cleanup
    (bsc#1227149).
  - wifi: mt76: mt7996: remove periodic MPDU TXS request
    (bsc#1227149).
  - wifi: mt76: mt7996: enable PPDU-TxS to host (bsc#1227149).
  - wifi: mt76: mt7996: Add mcu commands for getting sta tx
    statistic (bsc#1227149).
  - commit e37a1c7
  - Update config files for mt76 stuff (bsc#1227149)
  - commit debbb92
  - wifi: mt76: connac: add MBSSID support for mt7996 (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-update-beacon-size-limitation.patch.
  - commit 54772eb
  - wifi: mt76: mt7996: get tx_retries and tx_failed from txfree
    (bsc#1227149).
  - wifi: mt76: mt792x: move some common usb code in mt792x module
    (bsc#1227149).
  - wifi: mt76: mt792x: move mt7921_skb_add_usb_sdio_hdr in mt792x
    module (bsc#1227149).
  - wifi: mt76: mt7915 add tc offloading support (bsc#1227149).
  - wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips
    (bsc#1227149).
  - wifi: mt76: mt7915: update mpdu density capability
    (bsc#1227149).
  - wifi: mt76: check vif type before reporting cca and csa
    (bsc#1227149).
  - wifi: mt76: check sta rx control frame to multibss capability
    (bsc#1227149).
  - wifi: mt76: Use PTR_ERR_OR_ZERO() to simplify code
    (bsc#1227149).
  - commit 2106e27
  - wifi: mt76: mt7996: support per-band LED control (bsc#1227149).
  - wifi: mt76: mt7996: support more options for
    mt7996_set_bitrate_mask() (bsc#1227149).
  - wifi: mt76: mt7996: only set vif teardown cmds at remove
    interface (bsc#1227149).
  - wifi: mt76: connac: add more unified event IDs (bsc#1227149).
  - wifi: mt76: connac: add more unified command IDs (bsc#1227149).
  - wifi: mt76: connac: add data field in struct tlv (bsc#1227149).
  - wifi: mt76: connac: add eht support for tx power (bsc#1227149).
  - wifi: mt76: connac: add eht support for phy mode config
    (bsc#1227149).
  - wifi: mt76: connac: export functions for mt7925 (bsc#1227149).
  - wifi: mt76: mt792x: support mt7925 chip init (bsc#1227149).
  - commit 135e742
  - wifi: mt76: connac: introduce helper for mt7925 chipset
    (bsc#1227149).
  - wifi: mt76: mt7915: fix monitor mode issues (bsc#1227149).
  - wifi: mt76: add DMA mapping error check in mt76_alloc_txwi()
    (bsc#1227149).
  - wifi: mt76: fix race condition related to checking tx queue
    fill status (bsc#1227149).
  - wifi: mt76: use atomic iface iteration for pre-TBTT work
    (bsc#1227149).
  - wifi: mt76: mt7603: disable A-MSDU tx support on MT7628
    (bsc#1227149).
  - wifi: mt76: mt7603: add missing register initialization for
    MT7628 (bsc#1227149).
  - commit 6594bb5
  - net: ethernet: mtk_wed: introduce mtk_wed_buf structure
    (bsc#1227149).
  - net: ethernet: mtk_wed: rename mtk_rxbm_desc in mtk_wed_bm_desc
    (bsc#1227149).
  - wifi: mt76: Replace strlcpy() with strscpy() (bsc#1227149).
  - wifi: mt76: mt76x02: fix return value check in
    mt76x02_mac_process_rx (bsc#1227149).
  - wifi: mt76: mt7921: move mt7921u_disconnect mt792x-lib
    (bsc#1227149).
  - wifi: mt76: mt7921: move mt7921_dma_init in pci.c (bsc#1227149).
  - wifi: mt76: mt792x: move MT7921_PM_TIMEOUT and
    MT7921_HW_SCAN_TIMEOUT in common code (bsc#1227149).
  - wifi: mt76: mt76_connac3: move lmac queue enumeration in
    mt76_connac3_mac.h (bsc#1227149).
  - wifi: mt76: mt792x: move mt7921_load_firmware in mt792x-lib
    module (bsc#1227149).
  - commit 1179b28
  - wifi: mt76: mt792x: introduce mt792x-usb module (bsc#1227149).
  - commit bb743ca
  - wifi: mt76: mt7921: move acpi_sar code in mt792x-lib module
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - Refresh
    patches.suse/wifi-mt76-mt792x-fix-a-potential-loading-failure-of-.patch.
  - commit e00ae3f
  - wifi: mt76: mt7921: move runtime-pm pci code in mt792x-lib
    (bsc#1227149).
  - commit 35d834e
  - wifi: mt76: mt7921: move shared runtime-pm code on mt792x-lib
    (bsc#1227149).
  - commit 5efac2c
  - wifi: mt76: mt7921: move hif_ops macro in mt792x.h
    (bsc#1227149).
  - commit 945f2ed
  - wifi: mt76: mt792x: move more dma shared code in mt792x_dma
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921e-fix-use-after-free-in-free_irq.patch.
  - commit 4136c03
  - wifi: mt76: mt792x: introduce mt792x_irq_map (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921e-fix-use-after-free-in-free_irq.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921s-fix-potential-hung-tasks-during-ch.patch.
  - commit 94984c8
  - wifi: mt76: mt7921: move init shared code in mt792x-lib module
    (bsc#1227149).
  - wifi: mt76: mt7921: move debugfs shared code in mt792x-lib
    module (bsc#1227149).
  - wifi: mt76: mt7921: move dma shared code in mt792x-lib module
    (bsc#1227149).
  - commit 8138035
  - wifi: mt76: mt7921: move mac shared code in mt792x-lib module
    (bsc#1227149).
  - commit 118e960
  - wifi: mt76: mt792x: introduce mt792x-lib module (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit bba35bb
  - wifi: mt76: mt7921: move mt792x_hw_dev in mt792x.h
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit e5956d4
  - wifi: mt76: mt7921: move mt792x_mutex_{acquire/release} in
    mt792x.h (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit ea3046f
  - wifi: mt76: mt792x: move shared structure definition in mt792x.h
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit c60dc5e
  - wifi: mt76: mt7921: rename mt7921_dev in mt792x_dev
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921e-fix-use-after-free-in-free_irq.patch.
  - Refresh
    patches.suse/wifi-mt76-mt792x-fix-a-potential-loading-failure-of-.patch.
  - commit 845aa52
  - wifi: mt76: mt7921: rename mt7921_vif in mt792x_vif
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit d4d2c1b
  - wifi: mt76: mt7921: rename mt7921_hif_ops in mt792x_hif_ops
    (bsc#1227149).
  - wifi: mt76: mt7921: rename mt7921_phy in mt792x_phy
    (bsc#1227149).
  - wifi: mt76: mt7921: rename mt7921_sta in mt792x_sta
    (bsc#1227149).
  - commit 47cecdc
  - wifi: mt76: move rate info in mt76_vif (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7996-fix-rate-usage-of-inband-discovery-.patch.
  - commit 8909aa1
  - wifi: mt76: mt7921: convert acpisar and clc pointers to void
    (bsc#1227149).
  - wifi: mt76: mt7921: move common register definition in
    mt792x_regs.h (bsc#1227149).
  - wifi: mt76: mt7603: fix tx filter/flush function (bsc#1227149).
  - wifi: mt76: mt7603: fix beacon interval after disabling a
    single vif (bsc#1227149).
  - wifi: mt76: add support for providing eeprom in nvmem cells
    (bsc#1227149).
  - wifi: mt76: split get_of_eeprom in subfunction (bsc#1227149).
  - wifi: mt76: connac: add connac3 mac library (bsc#1227149).
  - mt76: connac: move more mt7921/mt7915 mac shared code in connac
    lib (bsc#1227149).
  - wifi: mt76: move ampdu_state in mt76_wcid (bsc#1227149).
  - commit 343ad65
  - wifi: mt76: mt7921: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit 72ca75a
  - wifi: mt76: mt7921: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7996: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7615: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7603: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7915: move poll_list in mt76_wcid (bsc#1227149).
  - wifi: mt76: mt7996: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - wifi: mt76: mt7615: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - wifi: mt76: mt7603: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - wifi: mt76: mt7915: move sta_poll_list and sta_poll_lock in
    mt76_dev (bsc#1227149).
  - commit 2965d6e
  - wifi: mt76: mt7996: increase tx token size (bsc#1227149).
  - wifi: mt76: mt7996: add muru support (bsc#1227149).
  - wifi: mt76: connac: add support to set ifs time by mcu command
    (bsc#1227149).
  - wifi: mt76: mt7996: enable VHT extended NSS BW feature
    (bsc#1227149).
  - wifi: mt76: connac: add support for dsp firmware download
    (bsc#1227149).
  - wifi: mt76: mt7996: move radio ctrl commands to proper functions
    (bsc#1227149).
  - wifi: mt76: mt7921: get rid of MT7921_RESET_TIMEOUT marco
    (bsc#1227149).
  - mt76: mt7996: rely on mt76_sta_stats in mt76_wcid (bsc#1227149).
  - wifi: mt76: mt7921: make mt7921_mac_sta_poll static
    (bsc#1227149).
  - wifi: mt76: mt7996: disable WFDMA Tx/Rx during SER recovery
    (bsc#1227149).
  - commit fc1c367
  - Update config files: adjust for Arm CONFIG_MT798X_WMAC (bsc#1227149)
  - commit 5938ea9
  - wifi: mt76: mt7921: rely on mib_stats shared definition
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit a519a6e
  - wifi: mt76: mt7915: disable WFDMA Tx/Rx during SER recovery
    (bsc#1227149).
  - wifi: mt76: mt7921: Support temp sensor (bsc#1227149).
  - wifi: mt76: mt7915: accumulate mu-mimo ofdma muru stats
    (bsc#1227149).
  - wifi: mt76: add tx_nss histogram to ethtool stats (bsc#1227149).
  - wifi: mt76: mt7921e: report tx retries/failed counts in tx
    free event (bsc#1227149).
  - wifi: mt76: mt7915: add support for MT7981 (bsc#1227149).
  - wifi: mt76: mt7996: rely on mib_stats shared definition
    (bsc#1227149).
  - wifi: mt76: mt7915: move mib_stats structure in mt76.h
    (bsc#1227149).
  - wifi: mt76: mt7921: remove macro duplication in regs.h
    (bsc#1227149).
  - commit c307798
  - wifi: mt76: mt7915: report tx retries/failed counts for non-WED
    path (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7915-rework-tx-packets-counting-when-WED.patch.
  - commit 25e2b06
  - wifi: mt76: mt7996: enable BSS_CHANGED_MU_GROUPS support
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-update-beacon-size-limitation.patch.
  - commit b121af9
  - wifi: mt76: mt7996: drop return in mt7996_sta_statistics
    (bsc#1227149).
  - wifi: mt76: mt7915: drop return in mt7915_sta_statistics
    (bsc#1227149).
  - wifi: mt76: report non-binding skb tx rate when WED is active
    (bsc#1227149).
  - wifi: mt76: enable UNII-4 channel 177 support (bsc#1227149).
  - wifi: mt76: mt7615: enable BSS_CHANGED_MU_GROUPS support
    (bsc#1227149).
  - wifi: mt7601u: replace strlcpy() with strscpy() (bsc#1227149).
  - wifi: mt7601u: delete dead code checking debugfs returns
    (bsc#1227149).
  - commit 3625743
  - exfat: fix potential deadlock on __exfat_get_dentry_set
    (git-fixes).
  - commit aaa908a
  - media: venus: fix use after free in vdec_close (git-fixes).
  - media: venus: flush all buffers in output plane streamoff
    (git-fixes).
  - media: v4l: subdev: Fix typo in documentation (git-fixes).
  - media: imx-pxp: Fix ERR_PTR dereference in pxp_probe()
    (git-fixes).
  - media: renesas: vsp1: Store RPF partition configuration per
    RPF instance (git-fixes).
  - media: renesas: vsp1: Fix _irqsave and _irq mix (git-fixes).
  - media: rcar-vin: Fix YUYV8_1X16 handling for CSI-2 (git-fixes).
  - media: imx-jpeg: Drop initial source change event if capture
    has been setup (git-fixes).
  - media: imx-jpeg: Remove some redundant error logs (git-fixes).
  - media: uvcvideo: Override default flags (git-fixes).
  - media: uvcvideo: Fix integer overflow calculating timestamp
    (git-fixes).
  - saa7134: Unchecked i2c_transfer function result fixed
    (git-fixes).
  - media: v4l: async: Fix NULL pointer dereference in adding
    ancillary links (git-fixes).
  - media: i2c: Fix imx412 exposure control (git-fixes).
  - media: imon: Fix race getting ictx->lock (git-fixes).
  - media: dvb-usb: Fix unexpected infinite loop in
    dvb_usb_read_remote_control() (git-fixes).
  - media: pci: ivtv: Add check for DMA map result (git-fixes).
  - leds: flash: leds-qcom-flash: Test the correct variable in init
    (git-fixes).
  - Revert "leds: led-core: Fix refcount leak in of_led_get()"
    (git-fixes).
  - leds: mt6360: Fix memory leak in mt6360_init_isnk_properties()
    (git-fixes).
  - leds: triggers: Flush pending brightness before activating
    trigger (git-fixes).
  - leds: ss4200: Convert PCIBIOS_* return codes to errnos
    (git-fixes).
  - leds: trigger: Unregister sysfs attributes before calling
    deactivate() (git-fixes).
  - mfd: omap-usb-tll: Use struct_size to allocate tll (git-fixes).
  - mfd: pm8008: Fix regmap irq chip initialisation (git-fixes).
  - ipmi: ssif_bmc: prevent integer overflow on 32bit systems
    (git-fixes).
  - ata: libata-scsi: Fix offsets for the fixed format sense data
    (git-fixes).
  - commit a8e6a5f
  - Update
    patches.suse/mptcp-ensure-snd_nxt-is-properly-initialized-on-conn.patch
    (CVE-2024-36889 bsc#1225746).
  - commit 98abb2b
  - mptcp: fix data races on remote_id (CVE-2024-27404 bsc#1224422)
  - commit ed12cfe

++++ kernel-rt:

  - net/smc: reduce rtnl pressure in smc_pnet_create_pnetids_list() (CVE-2024-35934 bsc#1224641)
  - commit 812f420
  - net/sched: act_skbmod: prevent kernel-infoleak (CVE-2024-35893 bsc#1224512)
  - commit 5be3514
  - scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated
    memory (bsc#1227762 CVE-2024-40901).
  - commit 5eb5075
  - btrfs: pass NOWAIT for set/clear extent bits as another bit
    (bsc#1223731 CVE-2024-26944).
  - commit 33253df
  - btrfs: drop NOFAIL from set_extent_bit allocation masks
    (bsc#1223731 CVE-2024-26944).
  - commit 46559ec
  - btrfs: open code set_extent_bits (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-make-find_first_extent_bit-return-a-boolean.patch.
  - Refresh
    patches.suse/btrfs-open-code-trivial-btrfs_add_excluded_extent.patch.
  - commit 460a0d4
  - xfs: fix log recovery buffer allocation for the legacy h_size
    fixup (bsc#1227432 CVE-2024-39472).
  - commit 04ef30f
  - KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
    (CVE-2024-40953, bsc#1227806).
  - commit 60989df
  - Update config files (bsc#1227282).
    Update the CONFIG_LSM option to include the selinux LSM in the default set
    of LSMs. The selinux LSM will not get enabled because it is preceded by
    apparmor, which is the first exclusive LSM. Updating CONFIG_LSM resolves
    failures that result in the system not booting up when "security=selinux
    selinux=1" is passed to the kernel and SELinux policies are installed.
  - commit 0a95a78
  - xfs: use roundup_pow_of_two instead of ffs during xlog_find_tail
    (git-fixes).
  - commit 44812b1
  - wifi: mt76: connac: use muar idx 0xe for non-mt799x as well
    (bsc#1227149).
  - wifi: mt76: mt7996: fix potential memory leakage when reading
    chip temperature (bsc#1227149).
  - wifi: mt76: mt7996: fix uninitialized variable in
    mt7996_irq_tasklet() (bsc#1227149).
  - wifi: mt76: mt7925: ensure 4-byte alignment for suspend &
    wow command (bsc#1227149).
  - wifi: mt76: mt7996: fix size of txpower MCU command
    (bsc#1227149).
  - wifi: mt76: connac: check for null before dereferencing
    (bsc#1227149).
  - commit 4e5584e
  - wifi: mt76: Remove redundant assignment to variable tidno
    (bsc#1227149).
  - wifi: mt76: fix the issue of missing txpwr settings from ch153
    to ch177 (bsc#1227149).
  - wifi: mt76: mt7921: fix suspend issue on MediaTek COB platform
    (bsc#1227149).
  - wifi: mt76: mt7921: fix a potential association failure upon
    resuming (bsc#1227149).
  - wifi: mt76: mt7921: fix the unfinished command of regd_notifier
    before suspend (bsc#1227149).
  - wifi: mt76: mt792x: update the country list of EU for ACPI SAR
    (bsc#1227149).
  - wifi: mt76: mt7925e: fix use-after-free in free_irq()
    (bsc#1227149).
  - wifi: mt76: mt792x: add the illegal value check for mtcl table
    of acpi (bsc#1227149).
  - wifi: mt76: mt7925: fix the wrong data type for scan command
    (bsc#1227149).
  - wifi: mt76: set page_pool napi pointer for mmio devices
    (bsc#1227149).
  - wifi: mt76: mt792x: fix ethtool warning (bsc#1227149).
  - commit 3499113
  - wifi: mt76: connac: set correct muar_idx for mt799x chipsets
    (bsc#1227149).
  - wifi: mt76: mt7996: remove TXS queue setting (bsc#1227149).
  - wifi: mt76: mt7996: mark GCMP IGTK unsupported (bsc#1227149).
  - wifi: mt76: mt7996: ensure 4-byte alignment for beacon commands
    (bsc#1227149).
  - wifi: mt76: mt7996: check txs format before getting skb by pid
    (bsc#1227149).
  - wifi: mt76: mt7925: support temperature sensor (bsc#1227149).
  - wifi: mt76: mt7925: update PCIe DMA settings (bsc#1227149).
  - wifi: mt76: mt7925: add support to set ifs time by mcu command
    (bsc#1227149).
  - wifi: mt76: mt7925: add flow to avoid chip bt function fail
    (bsc#1227149).
  - wifi: mt76: mt7925: fix the wrong header translation config
    (bsc#1227149).
  - commit 7f22357
  - wifi: mt76: mt7925: fix WoW failed in encrypted mode
    (bsc#1227149).
  - wifi: mt76: mt7925: fix fw download fail (bsc#1227149).
  - wifi: mt76: mt7925: fix wmm queue mapping (bsc#1227149).
  - wifi: mt76: mt7925: fix mcu query command fail (bsc#1227149).
  - wifi: mt76: mt7925: fix SAP no beacon issue in 5Ghz and 6Ghz
    band (bsc#1227149).
  - wifi: mt76: mt7925: fix connect to 80211b mode fail in 2Ghz band
    (bsc#1227149).
  - wifi: mt76: mt76x2u: add netgear wdna3100v3 to device table
    (bsc#1227149).
  - wifi: mt76: mt792xu: enable dmashdl support (bsc#1227149).
  - wifi: mt76: usb: store usb endpoint in mt76_queue (bsc#1227149).
  - wifi: mt76: usb: create a dedicated queue for psd traffic
    (bsc#1227149).
  - commit 01e1acb
  - wifi: mt76: mt7996: fix fw loading timeout (bsc#1227149).
  - wifi: mt76: mt7915: update mt798x_wmac_adie_patch_7976
    (bsc#1227149).
  - wifi: mt76: mt7915: add locking for accessing mapped registers
    (bsc#1227149).
  - wifi: mt76: mt7915: fix error recovery with WED enabled
    (bsc#1227149).
  - wifi: mt76: check txs format before getting skb by pid
    (bsc#1227149).
  - wifi: mt76: disable HW AMSDU when using fixed rate
    (bsc#1227149).
  - wifi: mt76: mt7996: fix fortify warning (bsc#1227149).
  - commit 0013ef2
  - wifi: fill in MODULE_DESCRIPTION()s for mt76 drivers
    (bsc#1227149).
  - wifi: mt76: mt7996: Use DECLARE_FLEX_ARRAY() and fix
  - Warray-bounds warnings (bsc#1227149).
  - wifi: mt76: mt7921: fix wrong 6Ghz power type (bsc#1227149).
  - wifi: mt76: mt7921: fix CLC command timeout when suspend/resume
    (bsc#1227149).
  - wifi: mt76: mt7921: reduce the size of MCU firmware download
    Rx queue (bsc#1227149).
  - wifi: mt76: mt7996: set DMA mask to 36 bits for boards with
    more than 4GB of RAM (bsc#1227149).
  - wifi: mt76: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: mt76: mt7925: remove iftype from mt7925_init_eht_caps
    signature (bsc#1227149).
  - wifi: mt76: connac: add new definition of tx descriptor
    (bsc#1227149).
  - wifi: mt76: mt7996: adjust interface num and wtbl size for
    mt7992 (bsc#1227149).
  - commit cbff43f
  - wifi: mt76: mt7996: support mt7992 eeprom loading (bsc#1227149).
  - wifi: mt76: mt7996: rework register offsets for mt7992
    (bsc#1227149).
  - wifi: mt76: mt7996: add DMA support for mt7992 (bsc#1227149).
  - wifi: mt76: connac: add firmware support for mt7992
    (bsc#1227149).
  - wifi: mt76: mt7996: introduce mt7996_band_valid() (bsc#1227149).
  - wifi: mt76: mt7996: fix mt7996_mcu_all_sta_info_event struct
    packing (bsc#1227149).
  - wifi: mt76: mt7915: also MT7981 is 3T3R but nss2 on 5 GHz band
    (bsc#1227149).
  - wifi: mt76: mt7915: fix EEPROM offset of TSSI flag on MT7981
    (bsc#1227149).
  - wifi: mt76: connac: add beacon protection support for mt7996
    (bsc#1227149).
  - wifi: mt76: mt7996: rework ampdu params setting (bsc#1227149).
  - commit 3e59fd6
  - wifi: mt76: mt7996: add txpower setting support (bsc#1227149).
  - commit fd1825a
  - wifi: mt76: mt7996: fix alignment of sta info event
    (bsc#1227149).
  - wifi: mt76: mt7996: switch to mcu command for TX GI report
    (bsc#1227149).
  - wifi: mt76: use chainmask for power delta calculation
    (bsc#1227149).
  - wifi: mt76: change txpower init to per-phy (bsc#1227149).
  - wifi: mt76: mt7996: align the format of fixed rate command
    (bsc#1227149).
  - wifi: mt76: mt7996: handle IEEE80211_RC_SMPS_CHANGED
    (bsc#1227149).
  - wifi: mt76: connac: set fixed_bw bit in TX descriptor for
    fixed rate frames (bsc#1227149).
  - wifi: mt76: mt7996: adjust WFDMA settings to improve performance
    (bsc#1227149).
  - wifi: mt76: connac: add beacon duplicate TX mode support for
    mt7996 (bsc#1227149).
  - commit e90dd6a
  - wifi: mt76: move wed reset common code in mt76 module
    (bsc#1227149).
  - commit b63457a
  - wifi: mt76: mt7996: add thermal sensor device support
    (bsc#1227149).
  - wifi: mt76: connac: add thermal protection support for mt7996
    (bsc#1227149).
  - wifi: mt76: mt7996: add TX statistics for EHT mode in debugfs
    (bsc#1227149).
  - wifi: mt76: mt7996: add support for variants with auxiliary
    RX path (bsc#1227149).
  - wifi: mt76: mt7996: use u16 for val field in mt7996_mcu_set_rro
    signature (bsc#1227149).
  - wifi: mt76: dma: introduce __mt76_dma_queue_reset utility
    routine (bsc#1227149).
  - commit dd57284
  - wifi: mt76: increase MT_QFLAG_WED_TYPE size (bsc#1227149).
  - wifi: mt76: introduce wed pointer in mt76_queue (bsc#1227149).
  - wifi: mt76: introduce mt76_queue_is_wed_tx_free utility routine
    (bsc#1227149).
  - wifi: mt76: move mt76_net_setup_tc in common code (bsc#1227149).
  - wifi: mt76: move mt76_mmio_wed_offload_{enable,disable} in
    common code (bsc#1227149).
  - wifi: mt76: mmio: move mt76_mmio_wed_{init,release}_rx_buf in
    common code (bsc#1227149).
  - wifi: mt76: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: mt76: permit to load precal from NVMEM cell for mt7915
    (bsc#1227149).
  - wifi: mt76: permit to use alternative cell name to eeprom
    NVMEM load (bsc#1227149).
  - commit 15e9dc7
  - wifi: mt76: mt7921: support 5.9/6GHz channel config in acpi
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - commit 915b272
  - wifi: mt76: make mt76_get_of_eeprom static again (bsc#1227149).
  - wifi: mt76: limit support of precal loading for mt7915 to MTD
    only (bsc#1227149).
  - wifi: mt76: fix typo in mt76_get_of_eeprom_from_nvmem function
    (bsc#1227149).
  - wifi: mt76: mt7996: fix uninitialized variable in parsing txfree
    (bsc#1227149).
  - wifi: mt76: add ability to explicitly forbid LED registration
    with DT (bsc#1227149).
  - wifi: mt76: mt7925: fix typo in mt7925_init_he_caps
    (bsc#1227149).
  - wifi: mt76: mt7921: fix 6GHz disabled by the missing default
    CLC config (bsc#1227149).
  - net: fill in MODULE_DESCRIPTION()s in kuba@'s modules
    (bsc#1227149).
  - wifi: mt76: mt7921: fix kernel panic by accessing invalid 6GHz
    channel info (bsc#1227149).
  - commit b106ffb
  - wifi: mt76: Annotate struct mt76_rx_tid with __counted_by
    (bsc#1227149).
  - commit aecab86
  - wifi: mt76: mt7921: update the channel usage when the regd
    domain changed (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - commit b09df3f
  - wifi: mt76: mt7921: get regulatory information from the clc
    event (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - commit 04b07d9
  - wifi: mt76: mt7921: add 6GHz power type support for clc
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - commit b7bb561
  - wifi: mt76: mt7921: enable set txpower for UNII-4 (bsc#1227149).
  - wifi: mt76: mt7921: move connac nic capability handling to
    mt7921 (bsc#1227149).
  - wifi: mt76: reduce spin_lock_bh held up in mt76_dma_rx_cleanup
    (bsc#1227149).
  - wifi: mt76: mt7996: remove periodic MPDU TXS request
    (bsc#1227149).
  - wifi: mt76: mt7996: enable PPDU-TxS to host (bsc#1227149).
  - wifi: mt76: mt7996: Add mcu commands for getting sta tx
    statistic (bsc#1227149).
  - commit e37a1c7
  - Update config files for mt76 stuff (bsc#1227149)
  - commit debbb92
  - wifi: mt76: connac: add MBSSID support for mt7996 (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-update-beacon-size-limitation.patch.
  - commit 54772eb
  - wifi: mt76: mt7996: get tx_retries and tx_failed from txfree
    (bsc#1227149).
  - wifi: mt76: mt792x: move some common usb code in mt792x module
    (bsc#1227149).
  - wifi: mt76: mt792x: move mt7921_skb_add_usb_sdio_hdr in mt792x
    module (bsc#1227149).
  - wifi: mt76: mt7915 add tc offloading support (bsc#1227149).
  - wifi: mt76: mt7925: add Mediatek Wi-Fi7 driver for mt7925 chips
    (bsc#1227149).
  - wifi: mt76: mt7915: update mpdu density capability
    (bsc#1227149).
  - wifi: mt76: check vif type before reporting cca and csa
    (bsc#1227149).
  - wifi: mt76: check sta rx control frame to multibss capability
    (bsc#1227149).
  - wifi: mt76: Use PTR_ERR_OR_ZERO() to simplify code
    (bsc#1227149).
  - commit 2106e27
  - wifi: mt76: mt7996: support per-band LED control (bsc#1227149).
  - wifi: mt76: mt7996: support more options for
    mt7996_set_bitrate_mask() (bsc#1227149).
  - wifi: mt76: mt7996: only set vif teardown cmds at remove
    interface (bsc#1227149).
  - wifi: mt76: connac: add more unified event IDs (bsc#1227149).
  - wifi: mt76: connac: add more unified command IDs (bsc#1227149).
  - wifi: mt76: connac: add data field in struct tlv (bsc#1227149).
  - wifi: mt76: connac: add eht support for tx power (bsc#1227149).
  - wifi: mt76: connac: add eht support for phy mode config
    (bsc#1227149).
  - wifi: mt76: connac: export functions for mt7925 (bsc#1227149).
  - wifi: mt76: mt792x: support mt7925 chip init (bsc#1227149).
  - commit 135e742
  - wifi: mt76: connac: introduce helper for mt7925 chipset
    (bsc#1227149).
  - wifi: mt76: mt7915: fix monitor mode issues (bsc#1227149).
  - wifi: mt76: add DMA mapping error check in mt76_alloc_txwi()
    (bsc#1227149).
  - wifi: mt76: fix race condition related to checking tx queue
    fill status (bsc#1227149).
  - wifi: mt76: use atomic iface iteration for pre-TBTT work
    (bsc#1227149).
  - wifi: mt76: mt7603: disable A-MSDU tx support on MT7628
    (bsc#1227149).
  - wifi: mt76: mt7603: add missing register initialization for
    MT7628 (bsc#1227149).
  - commit 6594bb5
  - net: ethernet: mtk_wed: introduce mtk_wed_buf structure
    (bsc#1227149).
  - net: ethernet: mtk_wed: rename mtk_rxbm_desc in mtk_wed_bm_desc
    (bsc#1227149).
  - wifi: mt76: Replace strlcpy() with strscpy() (bsc#1227149).
  - wifi: mt76: mt76x02: fix return value check in
    mt76x02_mac_process_rx (bsc#1227149).
  - wifi: mt76: mt7921: move mt7921u_disconnect mt792x-lib
    (bsc#1227149).
  - wifi: mt76: mt7921: move mt7921_dma_init in pci.c (bsc#1227149).
  - wifi: mt76: mt792x: move MT7921_PM_TIMEOUT and
    MT7921_HW_SCAN_TIMEOUT in common code (bsc#1227149).
  - wifi: mt76: mt76_connac3: move lmac queue enumeration in
    mt76_connac3_mac.h (bsc#1227149).
  - wifi: mt76: mt792x: move mt7921_load_firmware in mt792x-lib
    module (bsc#1227149).
  - commit 1179b28
  - wifi: mt76: mt792x: introduce mt792x-usb module (bsc#1227149).
  - commit bb743ca
  - wifi: mt76: mt7921: move acpi_sar code in mt792x-lib module
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-country-count-limitation-for-CL.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921-fix-incorrect-type-conversion-for-C.patch.
  - Refresh
    patches.suse/wifi-mt76-mt792x-fix-a-potential-loading-failure-of-.patch.
  - commit e00ae3f
  - wifi: mt76: mt7921: move runtime-pm pci code in mt792x-lib
    (bsc#1227149).
  - commit 35d834e
  - wifi: mt76: mt7921: move shared runtime-pm code on mt792x-lib
    (bsc#1227149).
  - commit 5efac2c
  - wifi: mt76: mt7921: move hif_ops macro in mt792x.h
    (bsc#1227149).
  - commit 945f2ed
  - wifi: mt76: mt792x: move more dma shared code in mt792x_dma
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921e-fix-use-after-free-in-free_irq.patch.
  - commit 4136c03
  - wifi: mt76: mt792x: introduce mt792x_irq_map (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7921e-fix-use-after-free-in-free_irq.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921s-fix-potential-hung-tasks-during-ch.patch.
  - commit 94984c8
  - wifi: mt76: mt7921: move init shared code in mt792x-lib module
    (bsc#1227149).
  - wifi: mt76: mt7921: move debugfs shared code in mt792x-lib
    module (bsc#1227149).
  - wifi: mt76: mt7921: move dma shared code in mt792x-lib module
    (bsc#1227149).
  - commit 8138035
  - wifi: mt76: mt7921: move mac shared code in mt792x-lib module
    (bsc#1227149).
  - commit 118e960
  - wifi: mt76: mt792x: introduce mt792x-lib module (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit bba35bb
  - wifi: mt76: mt7921: move mt792x_hw_dev in mt792x.h
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit e5956d4
  - wifi: mt76: mt7921: move mt792x_mutex_{acquire/release} in
    mt792x.h (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit ea3046f
  - wifi: mt76: mt792x: move shared structure definition in mt792x.h
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit c60dc5e
  - wifi: mt76: mt7921: rename mt7921_dev in mt792x_dev
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7921e-fix-use-after-free-in-free_irq.patch.
  - Refresh
    patches.suse/wifi-mt76-mt792x-fix-a-potential-loading-failure-of-.patch.
  - commit 845aa52
  - wifi: mt76: mt7921: rename mt7921_vif in mt792x_vif
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit d4d2c1b
  - wifi: mt76: mt7921: rename mt7921_hif_ops in mt792x_hif_ops
    (bsc#1227149).
  - wifi: mt76: mt7921: rename mt7921_phy in mt792x_phy
    (bsc#1227149).
  - wifi: mt76: mt7921: rename mt7921_sta in mt792x_sta
    (bsc#1227149).
  - commit 47cecdc
  - wifi: mt76: move rate info in mt76_vif (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - Refresh
    patches.suse/wifi-mt76-mt7996-fix-rate-usage-of-inband-discovery-.patch.
  - commit 8909aa1
  - wifi: mt76: mt7921: convert acpisar and clc pointers to void
    (bsc#1227149).
  - wifi: mt76: mt7921: move common register definition in
    mt792x_regs.h (bsc#1227149).
  - wifi: mt76: mt7603: fix tx filter/flush function (bsc#1227149).
  - wifi: mt76: mt7603: fix beacon interval after disabling a
    single vif (bsc#1227149).
  - wifi: mt76: add support for providing eeprom in nvmem cells
    (bsc#1227149).
  - wifi: mt76: split get_of_eeprom in subfunction (bsc#1227149).
  - wifi: mt76: connac: add connac3 mac library (bsc#1227149).
  - mt76: connac: move more mt7921/mt7915 mac shared code in connac
    lib (bsc#1227149).
  - wifi: mt76: move ampdu_state in mt76_wcid (bsc#1227149).
  - commit 343ad65
  - wifi: mt76: mt7921: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit 72ca75a
  - wifi: mt76: mt7921: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7996: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7615: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7603: rely on shared poll_list field
    (bsc#1227149).
  - wifi: mt76: mt7915: move poll_list in mt76_wcid (bsc#1227149).
  - wifi: mt76: mt7996: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - wifi: mt76: mt7615: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - wifi: mt76: mt7603: rely on shared sta_poll_list and
    sta_poll_lock (bsc#1227149).
  - wifi: mt76: mt7915: move sta_poll_list and sta_poll_lock in
    mt76_dev (bsc#1227149).
  - commit 2965d6e
  - wifi: mt76: mt7996: increase tx token size (bsc#1227149).
  - wifi: mt76: mt7996: add muru support (bsc#1227149).
  - wifi: mt76: connac: add support to set ifs time by mcu command
    (bsc#1227149).
  - wifi: mt76: mt7996: enable VHT extended NSS BW feature
    (bsc#1227149).
  - wifi: mt76: connac: add support for dsp firmware download
    (bsc#1227149).
  - wifi: mt76: mt7996: move radio ctrl commands to proper functions
    (bsc#1227149).
  - wifi: mt76: mt7921: get rid of MT7921_RESET_TIMEOUT marco
    (bsc#1227149).
  - mt76: mt7996: rely on mt76_sta_stats in mt76_wcid (bsc#1227149).
  - wifi: mt76: mt7921: make mt7921_mac_sta_poll static
    (bsc#1227149).
  - wifi: mt76: mt7996: disable WFDMA Tx/Rx during SER recovery
    (bsc#1227149).
  - commit fc1c367
  - Update config files: adjust for Arm CONFIG_MT798X_WMAC (bsc#1227149)
  - commit 5938ea9
  - wifi: mt76: mt7921: rely on mib_stats shared definition
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-move-struct-ieee80211_chanctx_conf-up-to-s.patch.
  - commit a519a6e
  - wifi: mt76: mt7915: disable WFDMA Tx/Rx during SER recovery
    (bsc#1227149).
  - wifi: mt76: mt7921: Support temp sensor (bsc#1227149).
  - wifi: mt76: mt7915: accumulate mu-mimo ofdma muru stats
    (bsc#1227149).
  - wifi: mt76: add tx_nss histogram to ethtool stats (bsc#1227149).
  - wifi: mt76: mt7921e: report tx retries/failed counts in tx
    free event (bsc#1227149).
  - wifi: mt76: mt7915: add support for MT7981 (bsc#1227149).
  - wifi: mt76: mt7996: rely on mib_stats shared definition
    (bsc#1227149).
  - wifi: mt76: mt7915: move mib_stats structure in mt76.h
    (bsc#1227149).
  - wifi: mt76: mt7921: remove macro duplication in regs.h
    (bsc#1227149).
  - commit c307798
  - wifi: mt76: mt7915: report tx retries/failed counts for non-WED
    path (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-mt7915-rework-tx-packets-counting-when-WED.patch.
  - commit 25e2b06
  - wifi: mt76: mt7996: enable BSS_CHANGED_MU_GROUPS support
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mt76-update-beacon-size-limitation.patch.
  - commit b121af9
  - wifi: mt76: mt7996: drop return in mt7996_sta_statistics
    (bsc#1227149).
  - wifi: mt76: mt7915: drop return in mt7915_sta_statistics
    (bsc#1227149).
  - wifi: mt76: report non-binding skb tx rate when WED is active
    (bsc#1227149).
  - wifi: mt76: enable UNII-4 channel 177 support (bsc#1227149).
  - wifi: mt76: mt7615: enable BSS_CHANGED_MU_GROUPS support
    (bsc#1227149).
  - wifi: mt7601u: replace strlcpy() with strscpy() (bsc#1227149).
  - wifi: mt7601u: delete dead code checking debugfs returns
    (bsc#1227149).
  - commit 3625743
  - exfat: fix potential deadlock on __exfat_get_dentry_set
    (git-fixes).
  - commit aaa908a
  - media: venus: fix use after free in vdec_close (git-fixes).
  - media: venus: flush all buffers in output plane streamoff
    (git-fixes).
  - media: v4l: subdev: Fix typo in documentation (git-fixes).
  - media: imx-pxp: Fix ERR_PTR dereference in pxp_probe()
    (git-fixes).
  - media: renesas: vsp1: Store RPF partition configuration per
    RPF instance (git-fixes).
  - media: renesas: vsp1: Fix _irqsave and _irq mix (git-fixes).
  - media: rcar-vin: Fix YUYV8_1X16 handling for CSI-2 (git-fixes).
  - media: imx-jpeg: Drop initial source change event if capture
    has been setup (git-fixes).
  - media: imx-jpeg: Remove some redundant error logs (git-fixes).
  - media: uvcvideo: Override default flags (git-fixes).
  - media: uvcvideo: Fix integer overflow calculating timestamp
    (git-fixes).
  - saa7134: Unchecked i2c_transfer function result fixed
    (git-fixes).
  - media: v4l: async: Fix NULL pointer dereference in adding
    ancillary links (git-fixes).
  - media: i2c: Fix imx412 exposure control (git-fixes).
  - media: imon: Fix race getting ictx->lock (git-fixes).
  - media: dvb-usb: Fix unexpected infinite loop in
    dvb_usb_read_remote_control() (git-fixes).
  - media: pci: ivtv: Add check for DMA map result (git-fixes).
  - leds: flash: leds-qcom-flash: Test the correct variable in init
    (git-fixes).
  - Revert "leds: led-core: Fix refcount leak in of_led_get()"
    (git-fixes).
  - leds: mt6360: Fix memory leak in mt6360_init_isnk_properties()
    (git-fixes).
  - leds: triggers: Flush pending brightness before activating
    trigger (git-fixes).
  - leds: ss4200: Convert PCIBIOS_* return codes to errnos
    (git-fixes).
  - leds: trigger: Unregister sysfs attributes before calling
    deactivate() (git-fixes).
  - mfd: omap-usb-tll: Use struct_size to allocate tll (git-fixes).
  - mfd: pm8008: Fix regmap irq chip initialisation (git-fixes).
  - ipmi: ssif_bmc: prevent integer overflow on 32bit systems
    (git-fixes).
  - ata: libata-scsi: Fix offsets for the fixed format sense data
    (git-fixes).
  - commit a8e6a5f
  - Update
    patches.suse/mptcp-ensure-snd_nxt-is-properly-initialized-on-conn.patch
    (CVE-2024-36889 bsc#1225746).
  - commit 98abb2b
  - mptcp: fix data races on remote_id (CVE-2024-27404 bsc#1224422)
  - commit ed12cfe

++++ libbpf:

  - update to 1.4.5:
    * Another small bug fix release backporting https://github.com/
    libbpf/libbpf/commit/d9f9fd5b22223ae69c62e083da6093d95a0db799
    which works around kernel-side bug with USDT PID filtering on
    kernels that support multi-uprobe (but have broken PID
    filtering).

++++ suse-module-tools:

  - Update to version 16.0.48:
    * Fix 64k check in check_arm_pagesize() that would cause OBS
    builds to fail

------------------------------------------------------------------
------------------  2024-7-17  -  Jul 17 2024  -------------------
------------------------------------------------------------------

++++ docker-compose:

  - Update to version 2.29.0:
    * fix: typos
    * update docs generation to avoid man pages generation
    * bump compose-go to v2.1.4, buildx to v0.16.0, containerd to
    v1.7.19 and buildx to v0.15.0
    * restore setEnvWithDotEnv
    * empty env variable with no value must be unset in container
    * exclude unnecessary resources after services have been selected
    * change time for stale bot
    * Remove debug mode and run twice a week
    * Add stale workflow
    * update docs
    * feat(watch): Add --prune option to docker-compose watch command
    * Remove COMPOSE_MENU env from e2e tests
    * Use rawjson for the build backend.
    * Set logging format to JSON.
    * Format errors as JSON when in JSON progress mode.
    * Pass 'plain' instead of 'json' to build backend
    * Add JSON stream progress writer
    * go.mod: docker/cli, docker/docker v27.0.3
    * gha: test against docker v27.0.3
    * go.mod: docker/cli, docker/docker v27.0.2

++++ python-kiwi:

  - Pass kernel cmdline to agama
    In the agama integration test make sure to pass along
    the kernel boot parameters to allow controlling the
    behavior of agama better

++++ kernel-default:

  - netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (CVE-2024-27020 bsc#1223815)
  - commit 79c457d
  - netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() (CVE-2024-27019 bsc#1223813)
  - commit 73c5c5f
  - btrfs: open code set_extent_bits_nowait (bsc#1223731
    CVE-2024-26944).
  - commit da5e600
  - btrfs: open code set_extent_dirty (bsc#1223731 CVE-2024-26944).
  - commit 3076056
  - btrfs: open code set_extent_new (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-make-find_first_extent_bit-return-a-boolean.patch.
  - commit 3afda0a
  - mm/page_table_check: fix crash on ZONE_DEVICE (CVE-2024-40948
    bsc#1227801).
  - commit 69b3c59
  - btrfs: open code set_extent_delalloc (bsc#1223731
    CVE-2024-26944).
  - btrfs: open code set_extent_defrag (bsc#1223731 CVE-2024-26944).
  - commit 646bcad
  - btrfs: use btrfs_next_item() at scrub.c:find_first_extent_item()
    (bsc#1223731 CVE-2024-26944).
  - btrfs: unexport extent_map_block_end() (bsc#1223731
    CVE-2024-26944).
  - btrfs: split assert into two different asserts when removing
    block group (bsc#1223731 CVE-2024-26944).
  - btrfs: mark sanity checks when getting chunk map as unlikely
    (bsc#1223731 CVE-2024-26944).
  - commit b0dd338
  - gro: fix ownership transfer (CVE-2024-35890 bsc#1224516).
  - commit 8c57ce0
  - mptcp: ensure snd_nxt is properly initialized on connect
    (CVE-2024-36889).
  - commit 724d285
  - ipv6: fib6_rules: avoid possible NULL dereference in
    fib6_rule_action() (CVE-2024-36902 bsc#1225719).
  - commit d8c5ba2
  - phonet: fix rtm_phonet_notify() skb allocation (CVE-2024-36946
    bsc#1225851).
  - commit a878203
  - r8169: Fix possible ring buffer corruption on fragmented Tx
    packets (CVE-2024-38586 bsc#1226750).
  - commit 1324b27
  - btrfs: zoned: factor out DUP bg handling from
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: factor out single bg handling from
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: factor out per-zone logic from
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: introduce a zone_info struct in
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - commit f06e144
  - wifi: virt_wifi: don't use strlen() in const context
    (git-fixes).
  - commit b4154c8
  - wifi: rtw89: Fix array index mistake in
    rtw89_sta_info_get_iter() (git-fixes).
  - wifi: rtl8xxxu: 8188f: Limit TX power index (git-fixes).
  - wifi: rtw89: 8852b: fix definition of KIP register number
    (git-fixes).
  - wifi: mac80211: chanctx emulation set CHANGE_CHANNEL when
    in_reconfig (git-fixes).
  - wifi: virt_wifi: avoid reporting connection success with wrong
    SSID (git-fixes).
  - wifi: ath12k: fix peer metadata parsing (git-fixes).
  - wifi: ath11k: fix wrong handling of CCMP256 and GCMP ciphers
    (git-fixes).
  - wifi: ath11k: fix RCU documentation in
    ath11k_mac_op_ipv6_changed() (git-fixes).
  - wifi: iwlwifi: mvm: don't limit VLP/AFC to UATS-enabled
    (git-fixes).
  - wifi: iwlwifi: fix iwl_mvm_get_valid_rx_ant() (git-fixes).
  - wifi: mac80211: correcty limit wider BW TDLS STAs (git-fixes).
  - wifi: mac80211: add ieee80211_tdls_sta_link_id() (stable-fixes).
  - commit 949fcca
  - wifi: cfg80211: handle 2x996 RU allocation in
    cfg80211_calculate_bitrate_he() (git-fixes).
  - wifi: cfg80211: fix typo in cfg80211_calculate_bitrate_he()
    (git-fixes).
  - wifi: ath12k: fix wrong definition of CE ring's base address
    (git-fixes).
  - wifi: ath11k: fix wrong definition of CE ring's base address
    (git-fixes).
  - wifi: ath12k: fix firmware crash during reo reinject
    (git-fixes).
  - wifi: ath12k: fix invalid memory access while processing
    fragmented packets (git-fixes).
  - wifi: ath12k: change DMA direction while mapping reinjected
    packets (git-fixes).
  - wifi: ath11k: restore country code during resume (git-fixes).
  - wifi: ath11k: refactor setting country code logic
    (stable-fixes).
  - wifi: ath12k: Fix tx completion ring (WBM2SW) setup failure
    (git-fixes).
  - wifi: ath12k: Correct 6 GHz frequency value in rx status
    (git-fixes).
  - wifi: ath12k: avoid duplicated vdev stop (git-fixes).
  - wifi: ath12k: drop failed transmitted frames from metric
    calculation (git-fixes).
  - wifi: ath12k: Don't drop tx_status in failure case (git-fixes).
  - wifi: rtw89: fix HW scan not aborting properly (git-fixes).
  - commit 7f555ea
  - wifi: mac80211: reset negotiated TTLM on disconnect (git-fixes).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit e02cbd1
  - wifi: mac80211: cancel multi-link reconf work on disconnect
    (git-fixes).
  - wifi: mwifiex: Fix interface type change (git-fixes).
  - wifi: brcmsmac: LCN PHY code is used for BCM4313 2G-only device
    (git-fixes).
  - vmlinux.lds.h: catch .bss..L* sections into BSS") (git-fixes).
  - wifi: mac80211: Recalc offload when monitor stop (git-fixes).
  - commit 0c5d63e
  - Bluetooth: hci_event: Set QoS encryption from BIGInfo report
    (git-fixes).
  - Bluetooth: btnxpuart: Add handling for boot-signature timeout
    errors (git-fixes).
  - Bluetooth: btintel: Refactor btintel_set_ppag() (git-fixes).
  - Bluetooth: hci_bcm4377: Use correct unit for timeouts
    (git-fixes).
  - lib: objagg: Fix general protection fault (git-fixes).
  - lib: test_objagg: Fix spelling (git-fixes).
  - lib: objagg: Fix spelling (git-fixes).
  - cpufreq: ti-cpufreq: Handle deferred probe with dev_err_probe()
    (git-fixes).
  - cpufreq/amd-pstate: Fix the scaling_max_freq setting on shared
    memory CPPC systems (git-fixes).
  - firmware: turris-mox-rwtm: Initialize completion before mailbox
    (git-fixes).
  - firmware: turris-mox-rwtm: Fix checking return value of
    wait_for_completion_timeout() (git-fixes).
  - firmware: turris-mox-rwtm: Do not complete if there are no
    waiters (git-fixes).
  - drivers: soc: xilinx: check return status of get_api_version()
    (git-fixes).
  - soc: xilinx: rename cpu_number1 to dummy_cpu_number (git-fixes).
  - soc: qcom: pdr: fix parsing of domains lists (git-fixes).
  - soc: qcom: pdr: protect locator_addr with the main mutex
    (git-fixes).
  - soc: qcom: rpmh-rsc: Ensure irqs aren't disabled by
    rpmh_rsc_send_data() callers (git-fixes).
  - soc: qcom: pmic_glink: Handle the return value of
    pmic_glink_init (git-fixes).
  - commit aea26b0

++++ kernel-rt:

  - netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (CVE-2024-27020 bsc#1223815)
  - commit 79c457d
  - netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get() (CVE-2024-27019 bsc#1223813)
  - commit 73c5c5f
  - btrfs: open code set_extent_bits_nowait (bsc#1223731
    CVE-2024-26944).
  - commit da5e600
  - btrfs: open code set_extent_dirty (bsc#1223731 CVE-2024-26944).
  - commit 3076056
  - btrfs: open code set_extent_new (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-make-find_first_extent_bit-return-a-boolean.patch.
  - commit 3afda0a
  - mm/page_table_check: fix crash on ZONE_DEVICE (CVE-2024-40948
    bsc#1227801).
  - commit 69b3c59
  - btrfs: open code set_extent_delalloc (bsc#1223731
    CVE-2024-26944).
  - btrfs: open code set_extent_defrag (bsc#1223731 CVE-2024-26944).
  - commit 646bcad
  - btrfs: use btrfs_next_item() at scrub.c:find_first_extent_item()
    (bsc#1223731 CVE-2024-26944).
  - btrfs: unexport extent_map_block_end() (bsc#1223731
    CVE-2024-26944).
  - btrfs: split assert into two different asserts when removing
    block group (bsc#1223731 CVE-2024-26944).
  - btrfs: mark sanity checks when getting chunk map as unlikely
    (bsc#1223731 CVE-2024-26944).
  - commit b0dd338
  - gro: fix ownership transfer (CVE-2024-35890 bsc#1224516).
  - commit 8c57ce0
  - mptcp: ensure snd_nxt is properly initialized on connect
    (CVE-2024-36889).
  - commit 724d285
  - ipv6: fib6_rules: avoid possible NULL dereference in
    fib6_rule_action() (CVE-2024-36902 bsc#1225719).
  - commit d8c5ba2
  - phonet: fix rtm_phonet_notify() skb allocation (CVE-2024-36946
    bsc#1225851).
  - commit a878203
  - r8169: Fix possible ring buffer corruption on fragmented Tx
    packets (CVE-2024-38586 bsc#1226750).
  - commit 1324b27
  - btrfs: zoned: factor out DUP bg handling from
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: factor out single bg handling from
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: factor out per-zone logic from
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: introduce a zone_info struct in
    btrfs_load_block_group_zone_info (bsc#1223731 CVE-2024-26944).
  - commit f06e144
  - wifi: virt_wifi: don't use strlen() in const context
    (git-fixes).
  - commit b4154c8
  - wifi: rtw89: Fix array index mistake in
    rtw89_sta_info_get_iter() (git-fixes).
  - wifi: rtl8xxxu: 8188f: Limit TX power index (git-fixes).
  - wifi: rtw89: 8852b: fix definition of KIP register number
    (git-fixes).
  - wifi: mac80211: chanctx emulation set CHANGE_CHANNEL when
    in_reconfig (git-fixes).
  - wifi: virt_wifi: avoid reporting connection success with wrong
    SSID (git-fixes).
  - wifi: ath12k: fix peer metadata parsing (git-fixes).
  - wifi: ath11k: fix wrong handling of CCMP256 and GCMP ciphers
    (git-fixes).
  - wifi: ath11k: fix RCU documentation in
    ath11k_mac_op_ipv6_changed() (git-fixes).
  - wifi: iwlwifi: mvm: don't limit VLP/AFC to UATS-enabled
    (git-fixes).
  - wifi: iwlwifi: fix iwl_mvm_get_valid_rx_ant() (git-fixes).
  - wifi: mac80211: correcty limit wider BW TDLS STAs (git-fixes).
  - wifi: mac80211: add ieee80211_tdls_sta_link_id() (stable-fixes).
  - commit 949fcca
  - wifi: cfg80211: handle 2x996 RU allocation in
    cfg80211_calculate_bitrate_he() (git-fixes).
  - wifi: cfg80211: fix typo in cfg80211_calculate_bitrate_he()
    (git-fixes).
  - wifi: ath12k: fix wrong definition of CE ring's base address
    (git-fixes).
  - wifi: ath11k: fix wrong definition of CE ring's base address
    (git-fixes).
  - wifi: ath12k: fix firmware crash during reo reinject
    (git-fixes).
  - wifi: ath12k: fix invalid memory access while processing
    fragmented packets (git-fixes).
  - wifi: ath12k: change DMA direction while mapping reinjected
    packets (git-fixes).
  - wifi: ath11k: restore country code during resume (git-fixes).
  - wifi: ath11k: refactor setting country code logic
    (stable-fixes).
  - wifi: ath12k: Fix tx completion ring (WBM2SW) setup failure
    (git-fixes).
  - wifi: ath12k: Correct 6 GHz frequency value in rx status
    (git-fixes).
  - wifi: ath12k: avoid duplicated vdev stop (git-fixes).
  - wifi: ath12k: drop failed transmitted frames from metric
    calculation (git-fixes).
  - wifi: ath12k: Don't drop tx_status in failure case (git-fixes).
  - wifi: rtw89: fix HW scan not aborting properly (git-fixes).
  - commit 7f555ea
  - wifi: mac80211: reset negotiated TTLM on disconnect (git-fixes).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit e02cbd1
  - wifi: mac80211: cancel multi-link reconf work on disconnect
    (git-fixes).
  - wifi: mwifiex: Fix interface type change (git-fixes).
  - wifi: brcmsmac: LCN PHY code is used for BCM4313 2G-only device
    (git-fixes).
  - vmlinux.lds.h: catch .bss..L* sections into BSS") (git-fixes).
  - wifi: mac80211: Recalc offload when monitor stop (git-fixes).
  - commit 0c5d63e
  - Bluetooth: hci_event: Set QoS encryption from BIGInfo report
    (git-fixes).
  - Bluetooth: btnxpuart: Add handling for boot-signature timeout
    errors (git-fixes).
  - Bluetooth: btintel: Refactor btintel_set_ppag() (git-fixes).
  - Bluetooth: hci_bcm4377: Use correct unit for timeouts
    (git-fixes).
  - lib: objagg: Fix general protection fault (git-fixes).
  - lib: test_objagg: Fix spelling (git-fixes).
  - lib: objagg: Fix spelling (git-fixes).
  - cpufreq: ti-cpufreq: Handle deferred probe with dev_err_probe()
    (git-fixes).
  - cpufreq/amd-pstate: Fix the scaling_max_freq setting on shared
    memory CPPC systems (git-fixes).
  - firmware: turris-mox-rwtm: Initialize completion before mailbox
    (git-fixes).
  - firmware: turris-mox-rwtm: Fix checking return value of
    wait_for_completion_timeout() (git-fixes).
  - firmware: turris-mox-rwtm: Do not complete if there are no
    waiters (git-fixes).
  - drivers: soc: xilinx: check return status of get_api_version()
    (git-fixes).
  - soc: xilinx: rename cpu_number1 to dummy_cpu_number (git-fixes).
  - soc: qcom: pdr: fix parsing of domains lists (git-fixes).
  - soc: qcom: pdr: protect locator_addr with the main mutex
    (git-fixes).
  - soc: qcom: rpmh-rsc: Ensure irqs aren't disabled by
    rpmh_rsc_send_data() callers (git-fixes).
  - soc: qcom: pmic_glink: Handle the return value of
    pmic_glink_init (git-fixes).
  - commit aea26b0

++++ samba:

  - Update samba-tool package to require python3-Markdown also in
    the Heimdal ADDC build.

++++ nftables:

  - Update to release 1.1.0
    * Restore compatibility set element dump with <= 0.9.8
    * Disallow empty interface names
    * Restore rule replace command
    * Search for group, rt_mark, rt_realms at
    /etc/iproute2, /usr/share/iproute2
    * Resolve some timezone issues
    * Support for variables in map expressions
    * VLAN support

++++ openssl-3:

  - Build with enabled sm2 and sm4 support [bsc#1222899]

++++ sssd:

  - Fix spec file for openSUSE ALP and SUSE SLFO, where the
    python3_fix_shebang_path RPM macro is not available

++++ pinentry:

  - update to 1.3.1:
    * qt: Install and use pinentry icon. [rPf9c252a8d9]
    * qt: Small fix for Qt5. [rP844360c9c9]
    * qt: Fix Windows build of Qt6. [rP34019f954a]
    * New envvar PINENTRY_KDE_USE_WALLET to enable the secret
    storage integration on KDE. [rP23753cfb03]

++++ python-psutil:

  - Update to version 6.0.0
    * 2109_: ``maxfile`` and ``maxpath`` fields were removed from the namedtuple
    returned by `disk_partitions()`_. Reason: on network filesystems (NFS) this
    can potentially take a very long time to complete.
    * 2366_, [Windows]: log debug message when using slower process APIs.
    * 2375_, [macOS]: provide arm64 wheels.  (patch by Matthieu Darbois)
    * 2396_: `process_iter()`_ no longer pre-emptively checks whether PIDs have
    been reused. This makes `process_iter()`_ around 20x times faster.
    * 2396_: a new ``psutil.process_iter.cache_clear()`` API can be used the clear
    `process_iter()`_ internal cache.
    * 2401_, Support building with free-threaded CPython 3.13. (patch by Sam Gross)
    * 2407_: `Process.connections()`_ was renamed to `Process.net_connections()`_.
    The old name is still available, but it's deprecated (triggers a
    ``DeprecationWarning``) and will be removed in the future.
    * 2425_: [Linux]: provide aarch64 wheels.  (patch by Matthieu Darbois / Ben Raz)
    * 2250_, [NetBSD]: `Process.cmdline()`_ sometimes fail with EBUSY. It usually
    happens for long cmdlines with lots of arguments. In this case retry getting
    the cmdline for up to 50 times, and return an empty list as last resort.
    * 2254_, [Linux]: offline cpus raise NotImplementedError in cpu_freq() (patch
    by Shade Gladden)
    * 2272_: Add pickle support to psutil Exceptions.
    * 2359_, [Windows], [CRITICAL]: `pid_exists()`_ disagrees with `Process`_ on
    whether a pid exists when ERROR_ACCESS_DENIED.
    * 2360_, [macOS]: can't compile on macOS < 10.13.  (patch by Ryan Schmidt)
    * 2362_, [macOS]: can't compile on macOS 10.11.  (patch by Ryan Schmidt)
    * 2365_, [macOS]: can't compile on macOS < 10.9.  (patch by Ryan Schmidt)
    * 2395_, [OpenBSD]: `pid_exists()`_ erroneously return True if the argument is
    a thread ID (TID) instead of a PID (process ID).
    * 2412_, [macOS]: can't compile on macOS 10.4 PowerPC due to missing `MNT_`
    constants.
    * 2109_: the namedtuple returned by `disk_partitions()`_' no longer has
    ``maxfile`` and ``maxpath`` fields.
    * 2396_: `process_iter()`_ no longer pre-emptively checks whether PIDs have
    been reused. If you want to check for PID reusage you are supposed to use
    `Process.is_running()`_ against the yielded `Process`_ instances. That will
    also automatically remove reused PIDs from `process_iter()`_ internal cache.
    * 2407_: `Process.connections()`_ was renamed to `Process.net_connections()`_.
    The old name is still available, but it's deprecated (triggers a
    ``DeprecationWarning``) and will be removed in the future.
  - from version 5.9.8
    * 2343_, [FreeBSD]: filter `net_connections()`_ returned list in C instead of
    Python, and avoid to retrieve unnecessary connection types unless explicitly
    asked. E.g., on an IDLE system with few IPv6 connections this will run around
    4 times faster. Before all connection types (TCP, UDP, UNIX) were retrieved
    internally, even if only a portion was returned.
    * 2342_, [NetBSD]: same as above (#2343) but for NetBSD.
    * 2349_: adopted black formatting style.
    * 930_, [NetBSD], [critical]: `net_connections()`_ implementation was broken.
    It could either leak memory or core dump.
    * 2340_, [NetBSD]: if process is terminated, `Process.cwd()`_ will return an
    empty string instead of raising `NoSuchProcess`_.
    * 2345_, [Linux]: fix compilation on older compiler missing DUPLEX_UNKNOWN.
    * 2222_, [macOS]: `cpu_freq()` now returns fixed values for `min` and `max`
    frequencies in all Apple Silicon chips.
  - Drop obsolete patch to skip tests on Python 2
    * skip_rlimit_tests_on_python2.patch
  - Update patch to skip failing tests for new version
    * skip_failing_tests.patch

------------------------------------------------------------------
------------------  2024-7-16  -  Jul 16 2024  -------------------
------------------------------------------------------------------

++++ dpdk:

  - add kni-fix-build-with-Linux-6.10.patch to fix build against
    kernel 6.8.
  - update kni-fix-build-with-Linux-6.8.patch -- it is upstream now.

++++ transactional-update:

  - It seems it's taking a longer time until the tests will be
    adopted to the new reboot behavior. Disable soft-reboot for now
    to unblock the regular transactional-update update.

++++ gettext-runtime:

  - Use %autosetup

++++ fontconfig:

  - Run autoreconf unconditionally to allow newer versions
    of Automake.

++++ guestfs-tools:

  - Update to version 1.53.1 (jsc#PED-6305)
    * Add support for LoongArch.
    * Suppress false use-after-free warning generated by GCC 14
    * m4/guestfs-c.m4: Re-add ./configure --enable-werror
    * make-fs: Use -S option with -z
    * sysprep: Make clearer that we do not support Windows
    * Fix bytecode compilation to output whole exe instead of using
  - custom
    * options: Allow nbd+unix:// URIs
  - Drop patches contained in new tarball
    Update-virt-customize-generated-files.patch
    Initialise-bar-fp-as-NULL.patch

++++ kernel-default:

  - btrfs: remove the need_raid_map parameter from btrfs_map_block()
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: skip splitting and logical rewriting on pre-alloc
    write (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: do not zone finish data relocation block group
    (bsc#1223731 CVE-2024-26944).
  - btrfs: add comments for btrfs_map_block() (bsc#1223731
    CVE-2024-26944).
  - commit 0c47c71
  - Revert "gfs2: fix glock shrinker ref issues" (git-fixes).
  - commit f7bfdba
  - gfs2: Fix "ignore unlock failures after withdraw" (git-fixes).
  - commit 519ac22
  - gfs2: Don't forget to complete delayed withdraw (git-fixes).
  - commit 7f71d47
  - gfs2: Fix invalid metadata access in punch_hole (git-fixes).
  - commit 1be0540
  - gfs2: Rename gfs2_lookup_{ simple => meta } (git-fixes).
  - commit d7e53ef
  - gfs2: Use mapping->gfp_mask for metadata inodes (git-fixes).
  - commit 78503fa
  - gfs2: convert to ctime accessor functions (git-fixes).
  - commit b024418
  - gfs2: Get rid of gfs2_alloc_blocks generation parameter
    (git-fixes).
  - commit e229d26
  - dlm: fix user space lock decision to copy lvb (git-fixes).
  - commit 9a5eade
  - ocfs2: fix DIO failure due to insufficient transaction credits
    (git-fixes).
  - commit cf885b6
  - ocfs2: use coarse time for new created files (git-fixes).
  - commit 61f3cb7
  - ocfs2: fix races between hole punching and AIO+DIO (git-fixes).
  - commit bdcd35b
  - filelock: fix potential use-after-free in posix_lock_inode
    (git-fixes).
  - commit 4ceada4
  - fs/pipe: Fix lockdep false-positive in watchqueue pipe_write()
    (git-fixes).
  - commit 047ac8f
  - tracefs: Add missing lockdown check to tracefs_create_dir()
    (git-fixes).
  - commit 65b8efc
  - f2fs: fix error path of __f2fs_build_free_nids (git-fixes).
  - commit 6c1efec
  - btrfs: zoned: re-enable metadata over-commit for zoned mode
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: don't activate non-DATA BG on allocation
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: no longer count fresh BG region as zone unusable
    (bsc#1223731 CVE-2024-26944).
  - commit cc48fd8
  - smb: client: fix deadlock in smb2_find_smb_tcon() (bsc#1227103,
    CVE-2024-39468).
  - commit 1548cc0
  - orangefs: fix out-of-bounds fsid access (git-fixes).
  - commit 8d69475
  - btrfs: zoned: activate metadata block group on write time
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: reserve zones for an active metadata/system
    block group (bsc#1223731 CVE-2024-26944).
  - commit 00c0b10
  - btrfs: zoned: update meta write pointer on zone finish
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: defer advancing meta write pointer (bsc#1223731
    CVE-2024-26944).
  - commit 9625328
  - net/mlx5: Always stop health timer during driver removal
    (CVE-2024-40906 bsc#1227763).
  - commit 3630f6e
  - btrfs: zoned: return int from btrfs_check_meta_write_pointer
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: introduce block group context to
    btrfs_eb_write_context (bsc#1223731 CVE-2024-26944).
  - btrfs: introduce struct to consolidate extent buffer write
    context (bsc#1223731 CVE-2024-26944).
  - commit d8f8b66
  - btrfs: zoned: use vcalloc instead of for vzalloc in
    btrfs_get_dev_zone_info (bsc#1223731 CVE-2024-26944).
  - commit 4837f02
  - btrfs: open code need_full_stripe conditions (bsc#1223731
    CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-be-a-bit-more-careful-when-setting-mirror.patch.
  - commit 0011c1e
  - nilfs2: fix incorrect inode allocation from reserved inodes
    (git-fixes).
  - commit 9ce9b3c
  - nilfs2: convert persistent object allocator to use kmap_local
    (git-fixes).
  - commit dc36fd2
  - netfilter: nf_tables: restore set elements when delete set fails
    (CVE-2024-27012 bsc#1223804).
  - commit 8ba3bb4
  - jffs2: Fix potential illegal address access in jffs2_free_inode
    (git-fixes).
  - commit 282ccaf
  - hfsplus: fix to avoid false alarm of circular locking
    (git-fixes).
  - commit 490432a
  - btrfs: open code btrfs_map_sblock (bsc#1223731 CVE-2024-26944).
  - commit 5fa5c99
  - btrfs: rename __btrfs_map_block to btrfs_map_block (bsc#1223731
    CVE-2024-26944).
  - commit de51f30
  - btrfs: remove unused btrfs_map_block (bsc#1223731
    CVE-2024-26944).
  - commit 0ff7c2f
  - btrfs: optimize simple reads in btrfsic_map_block (bsc#1223731
    CVE-2024-26944).
  - commit 3260913
  - btrfs: remove unused BTRFS_MAP_DISCARD (bsc#1223731
    CVE-2024-26944).
  - commit 68b562a
  - btrfs: pass the new logical address to split_extent_map
    (bsc#1223731 CVE-2024-26944).
  - commit c2e8884
  - btrfs: defer splitting of ordered extents until I/O completion
    (bsc#1223731 CVE-2024-26944).
  - commit 5ae3e38
  - btrfs: handle completed ordered extents in
    btrfs_split_ordered_extent (bsc#1223731 CVE-2024-26944).
  - commit ddd9e87
  - btrfs: atomically insert the new extent in
    btrfs_split_ordered_extent (bsc#1223731 CVE-2024-26944).
  - commit 4030656
  - btrfs: split btrfs_alloc_ordered_extent to allocation and
    insertion helpers (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/0002-btrfs-fix-qgroup_free_reserved_data-int-overflow.patch.
  - commit e1bc1c4
  - drm/mst: Fix NULL pointer dereference at drm_dp_add_payload_part2 (bsc#1227723 CVE-2024-39498)
  - commit bb19e55
  - btrfs: return the new ordered_extent from
    btrfs_split_ordered_extent (bsc#1223731 CVE-2024-26944).
  - commit c61ece3
  - btrfs: reorder conditions in btrfs_extract_ordered_extent
    (bsc#1223731 CVE-2024-26944).
  - commit 7ad1725
  - btrfs: move split_extent_map to extent_map.c (bsc#1223731
    CVE-2024-26944).
  - commit 4667690
  - btrfs: record orig_physical only for the original bio
    (bsc#1223731 CVE-2024-26944).
  - commit f1ddea8
  - btrfs: optimize the logical to physical mapping for zoned writes
    (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/0002-btrfs-fix-qgroup_free_reserved_data-int-overflow.patch.
  - commit 59cfe96
  - ionic: fix use after netif_napi_del() (CVE-2024-39502
    bsc#1227755).
  - commit a8905bd
  - netfilter: flowtable: validate pppoe header (CVE-2024-27016
    bsc#1223807).
  - commit 4c0256f
  - i40e: fix: remove needless retries of NVM update (bsc#1227736).
  - commit df4f038
  - spi: spi-microchip-core: Fix the number of chip selects
    supported (git-fixes).
  - spi: atmel-quadspi: Add missing check for clk_prepare
    (git-fixes).
  - gpio: mc33880: Convert comma to semicolon (git-fixes).
  - pwm: stm32: Always do lazy disabling (git-fixes).
  - hwmon: (max6697) Fix swapped temp{1,8} critical alarms
    (git-fixes).
  - hwmon: (max6697) Fix underflow when writing limit attributes
    (git-fixes).
  - hwmon: (adt7475) Fix default duty on fan is disabled
    (git-fixes).
  - platform/chrome: cros_ec_debugfs: fix wrong EC message version
    (git-fixes).
  - char: tpm: Fix possible memory leak in
    tpm_bios_measurements_open() (git-fixes).
  - tools/memory-model: Fix bug in lock.cat (git-fixes).
  - drm/gma500: fix null pointer dereference in
    cdv_intel_lvds_get_modes (git-fixes).
  - drm/gma500: fix null pointer dereference in
    psb_intel_lvds_get_modes (git-fixes).
  - drm/meson: fix canvas release in bind function (git-fixes).
  - commit 027008e
  - Move upstreamed patches into sorted section
  - commit da52786
  - ipv6: prevent NULL dereference in ip6_output() (CVE-2024-36901 bsc#1225711)
  - commit 299bf13
  - i40e: Do not use WQ_MEM_RECLAIM flag for workqueue (CVE-2024-36004 bsc#1224545)
  - commit 42d6eee
  - nbd: null check for nla_nest_start (CVE-2024-27025 bsc#1223778)
  - commit a23796b

++++ kernel-rt:

  - btrfs: remove the need_raid_map parameter from btrfs_map_block()
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: skip splitting and logical rewriting on pre-alloc
    write (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: do not zone finish data relocation block group
    (bsc#1223731 CVE-2024-26944).
  - btrfs: add comments for btrfs_map_block() (bsc#1223731
    CVE-2024-26944).
  - commit 0c47c71
  - Revert "gfs2: fix glock shrinker ref issues" (git-fixes).
  - commit f7bfdba
  - gfs2: Fix "ignore unlock failures after withdraw" (git-fixes).
  - commit 519ac22
  - gfs2: Don't forget to complete delayed withdraw (git-fixes).
  - commit 7f71d47
  - gfs2: Fix invalid metadata access in punch_hole (git-fixes).
  - commit 1be0540
  - gfs2: Rename gfs2_lookup_{ simple => meta } (git-fixes).
  - commit d7e53ef
  - gfs2: Use mapping->gfp_mask for metadata inodes (git-fixes).
  - commit 78503fa
  - gfs2: convert to ctime accessor functions (git-fixes).
  - commit b024418
  - gfs2: Get rid of gfs2_alloc_blocks generation parameter
    (git-fixes).
  - commit e229d26
  - dlm: fix user space lock decision to copy lvb (git-fixes).
  - commit 9a5eade
  - ocfs2: fix DIO failure due to insufficient transaction credits
    (git-fixes).
  - commit cf885b6
  - ocfs2: use coarse time for new created files (git-fixes).
  - commit 61f3cb7
  - ocfs2: fix races between hole punching and AIO+DIO (git-fixes).
  - commit bdcd35b
  - filelock: fix potential use-after-free in posix_lock_inode
    (git-fixes).
  - commit 4ceada4
  - fs/pipe: Fix lockdep false-positive in watchqueue pipe_write()
    (git-fixes).
  - commit 047ac8f
  - tracefs: Add missing lockdown check to tracefs_create_dir()
    (git-fixes).
  - commit 65b8efc
  - f2fs: fix error path of __f2fs_build_free_nids (git-fixes).
  - commit 6c1efec
  - btrfs: zoned: re-enable metadata over-commit for zoned mode
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: don't activate non-DATA BG on allocation
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: no longer count fresh BG region as zone unusable
    (bsc#1223731 CVE-2024-26944).
  - commit cc48fd8
  - smb: client: fix deadlock in smb2_find_smb_tcon() (bsc#1227103,
    CVE-2024-39468).
  - commit 1548cc0
  - orangefs: fix out-of-bounds fsid access (git-fixes).
  - commit 8d69475
  - btrfs: zoned: activate metadata block group on write time
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: reserve zones for an active metadata/system
    block group (bsc#1223731 CVE-2024-26944).
  - commit 00c0b10
  - btrfs: zoned: update meta write pointer on zone finish
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: defer advancing meta write pointer (bsc#1223731
    CVE-2024-26944).
  - commit 9625328
  - net/mlx5: Always stop health timer during driver removal
    (CVE-2024-40906 bsc#1227763).
  - commit 3630f6e
  - btrfs: zoned: return int from btrfs_check_meta_write_pointer
    (bsc#1223731 CVE-2024-26944).
  - btrfs: zoned: introduce block group context to
    btrfs_eb_write_context (bsc#1223731 CVE-2024-26944).
  - btrfs: introduce struct to consolidate extent buffer write
    context (bsc#1223731 CVE-2024-26944).
  - commit d8f8b66
  - btrfs: zoned: use vcalloc instead of for vzalloc in
    btrfs_get_dev_zone_info (bsc#1223731 CVE-2024-26944).
  - commit 4837f02
  - btrfs: open code need_full_stripe conditions (bsc#1223731
    CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-be-a-bit-more-careful-when-setting-mirror.patch.
  - commit 0011c1e
  - nilfs2: fix incorrect inode allocation from reserved inodes
    (git-fixes).
  - commit 9ce9b3c
  - nilfs2: convert persistent object allocator to use kmap_local
    (git-fixes).
  - commit dc36fd2
  - netfilter: nf_tables: restore set elements when delete set fails
    (CVE-2024-27012 bsc#1223804).
  - commit 8ba3bb4
  - jffs2: Fix potential illegal address access in jffs2_free_inode
    (git-fixes).
  - commit 282ccaf
  - hfsplus: fix to avoid false alarm of circular locking
    (git-fixes).
  - commit 490432a
  - btrfs: open code btrfs_map_sblock (bsc#1223731 CVE-2024-26944).
  - commit 5fa5c99
  - btrfs: rename __btrfs_map_block to btrfs_map_block (bsc#1223731
    CVE-2024-26944).
  - commit de51f30
  - btrfs: remove unused btrfs_map_block (bsc#1223731
    CVE-2024-26944).
  - commit 0ff7c2f
  - btrfs: optimize simple reads in btrfsic_map_block (bsc#1223731
    CVE-2024-26944).
  - commit 3260913
  - btrfs: remove unused BTRFS_MAP_DISCARD (bsc#1223731
    CVE-2024-26944).
  - commit 68b562a
  - btrfs: pass the new logical address to split_extent_map
    (bsc#1223731 CVE-2024-26944).
  - commit c2e8884
  - btrfs: defer splitting of ordered extents until I/O completion
    (bsc#1223731 CVE-2024-26944).
  - commit 5ae3e38
  - btrfs: handle completed ordered extents in
    btrfs_split_ordered_extent (bsc#1223731 CVE-2024-26944).
  - commit ddd9e87
  - btrfs: atomically insert the new extent in
    btrfs_split_ordered_extent (bsc#1223731 CVE-2024-26944).
  - commit 4030656
  - btrfs: split btrfs_alloc_ordered_extent to allocation and
    insertion helpers (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/0002-btrfs-fix-qgroup_free_reserved_data-int-overflow.patch.
  - commit e1bc1c4
  - drm/mst: Fix NULL pointer dereference at drm_dp_add_payload_part2 (bsc#1227723 CVE-2024-39498)
  - commit bb19e55
  - btrfs: return the new ordered_extent from
    btrfs_split_ordered_extent (bsc#1223731 CVE-2024-26944).
  - commit c61ece3
  - btrfs: reorder conditions in btrfs_extract_ordered_extent
    (bsc#1223731 CVE-2024-26944).
  - commit 7ad1725
  - btrfs: move split_extent_map to extent_map.c (bsc#1223731
    CVE-2024-26944).
  - commit 4667690
  - btrfs: record orig_physical only for the original bio
    (bsc#1223731 CVE-2024-26944).
  - commit f1ddea8
  - btrfs: optimize the logical to physical mapping for zoned writes
    (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/0002-btrfs-fix-qgroup_free_reserved_data-int-overflow.patch.
  - commit 59cfe96
  - ionic: fix use after netif_napi_del() (CVE-2024-39502
    bsc#1227755).
  - commit a8905bd
  - netfilter: flowtable: validate pppoe header (CVE-2024-27016
    bsc#1223807).
  - commit 4c0256f
  - i40e: fix: remove needless retries of NVM update (bsc#1227736).
  - commit df4f038
  - spi: spi-microchip-core: Fix the number of chip selects
    supported (git-fixes).
  - spi: atmel-quadspi: Add missing check for clk_prepare
    (git-fixes).
  - gpio: mc33880: Convert comma to semicolon (git-fixes).
  - pwm: stm32: Always do lazy disabling (git-fixes).
  - hwmon: (max6697) Fix swapped temp{1,8} critical alarms
    (git-fixes).
  - hwmon: (max6697) Fix underflow when writing limit attributes
    (git-fixes).
  - hwmon: (adt7475) Fix default duty on fan is disabled
    (git-fixes).
  - platform/chrome: cros_ec_debugfs: fix wrong EC message version
    (git-fixes).
  - char: tpm: Fix possible memory leak in
    tpm_bios_measurements_open() (git-fixes).
  - tools/memory-model: Fix bug in lock.cat (git-fixes).
  - drm/gma500: fix null pointer dereference in
    cdv_intel_lvds_get_modes (git-fixes).
  - drm/gma500: fix null pointer dereference in
    psb_intel_lvds_get_modes (git-fixes).
  - drm/meson: fix canvas release in bind function (git-fixes).
  - commit 027008e
  - Move upstreamed patches into sorted section
  - commit da52786
  - ipv6: prevent NULL dereference in ip6_output() (CVE-2024-36901 bsc#1225711)
  - commit 299bf13
  - i40e: Do not use WQ_MEM_RECLAIM flag for workqueue (CVE-2024-36004 bsc#1224545)
  - commit 42d6eee
  - nbd: null check for nla_nest_start (CVE-2024-27025 bsc#1223778)
  - commit a23796b

++++ util-linux-systemd:

  - uncomment "autoreconf --install" to use the new version of automake

++++ util-linux:

  - uncomment "autoreconf --install" to use the new version of automake

++++ libguestfs:

  - Update to version 1.53.5 (jsc#PED-6305)
    * generator/customize.ml: Split --chown parameter on ':' character
    * daemon: Add gost checksum command support
    * Add detection support for Circle Linux
    * Add support for LoongArch.
    * daemon: Fix file architecture translation for LoongArch
    * options: Allow nbd+unix:// URIs
    * daemon/parted: Assume sfdisk --part-type exists
    * daemon: Reimplement partition GPT functions using sfdisk
    * appliance: only wait for resolv.conf update if dhcpcd succeeded
    * generator/customize.ml: Add virt-customize --inject-blnsvr operation
    * lib: libvirt: Stop recommending LIBGUESTFS_BACKEND=direct
    * daemon: cryptsetup_open: Add --cipher
    * rust: Handle null pointer when creating slice
    * Remove gluster support
    * Remove sheepdog support
    * Remove tftp drive support
    * generator/daemon: Don't truncate 64 bit results from OCaml functions
    * daemon: Fix parsing in part_get_gpt_attributes
    * New APIs: findfs_partuuid and findfs_partlabel
    * inspection: Resolve PARTUUID= and PARTLABEL= in /etc/fstab
    * generator/actions_core.ml: Fix version field for new APIs
    * Kylin is centos derivative

++++ libnftnl:

  - Update to release 1.2.7
    * Avoid potential use-after-free when clearing set's expression
    list
    * Avoid misc buffer overflows in attribute setters
    * Implement nftnl_obj_unset symbol already exported in
    libnftnl.map
    * Remove unimplemented symbols from libnftnl.map
    * Validate per-expression and per-object attribute value and
    data length
    * Fix synproxy object setter with unaligned data

++++ systemd:

  - Skip running the test units in %check for now.
    Some tests don't appreciate to run inside the build environment of OBS
    currently and some of them take an unexpected long time to execute on both
    risc and s390x architectures.

++++ ovmf:

  - Update to edk2-stable202402
  - Features (https://github.com/tianocore/edk2/releases):
    NetworkPkg: Packet->Length is not updated before being used by Dhcp6AppendIaAddrOption to safely know it can append.
    NetworkPkg: Out-of-bounds read when processing IA_NA/IA_TA options in a DHCPv6 Advertise message
    Heap Buffer Overflow in Tcg2MeasureGptTable()
    Add LoongArch help functions and defines in MdePkg and move some ArmVirtPkg libraries and PCDs to OvmfPkg
    Add NVMe Sanitize command support to Nvme.h
    Remove CSM support from OvmfPkg
    MAT Logic Incorrectly Reports Runtime Images
  - Patches (git log --oneline --date-order edk2-stable202311..edk2-stable202402):
    edc6681206 UefiCpuPkg/PiSmmCpuDxeSmm: fix NULL deref when gSmmBaseHobGuid is missing
    72c441df36 UefiCpuPkg/PiSmmCpuDxeSmm: distinguish GetSmBase() failure modes
    5fd3078a2e NetworkPkg: : Updating SecurityFixes.yaml
    75deaf5c3c NetworkPkg: Dhcp6Dxe: Packet-Length is not updated before appending
    af3fad99d6 NetworkPkg: Dhcp6Dxe: Removes duplicate check and replaces with macro
    1c440a5ece NetworkPkg: Dhcp6Dxe: SECURITY PATCH CVE-2023-45229 Related Patch
    a1c426e844 UnitTestFrameworkPkg: Add DSC and host tests that always fail
    0a989069df UnitTestFrameworkPkg/SampleGoogleTest: Use EXPECT_ANY_THROW()
    2d144d7e14 UnitTestFrameworkPkg/UnitTestDebugAssertLib: Add GoogleTest support
    312ccaf81b UnitTestFrameworkPkg/UnitTestLib: GetActiveFrameworkHandle() no ASSERT()
    81b69f306f UnitTestFrameworkPkg: Expand host-based exception handling and gcov
    46c6de57b0 UnitTestFrameworkPkg: MSFT CC_FLAGS add /MT to for host builds
    ded41a64bd MdePkg/Include: Rename _DEBUG() to address name collision
    8801c75b4d OvmfPkg: Align XenRealTimeClockLib function headers with return values
    dcdc6f8e3f ArmPlatformPkg: Align PL031 library function headers with return values
    844ead5bce EmbeddedPkg: Align RealTimeClock function headers with return values
    ef4d35d4ed MdeModulePkg: Align RuntimeDxe function headers with UEFI return values
    e4ceae5c18 MdePkg: Add EFI_UNSUPPORTED return for some Runtime Service functions
    dcf2e39dce EmbeddedPkg: compiler error due to arithmetic operation on void pointer
    e32b58ab5a BaseTools: Remove Duplicate sets of SkuName and SkuId from allskuset
    8f316e99ec BaseTools: Optimize GenerateByteArrayValue and CollectPlatformGuids APIs
    4d1f0babe2 MdePkg: Add SynchronizationLib to MdeLibs.dsc.inc
    1d0b95f645 NetworkPkg: : Adds a SecurityFix.yaml file
    ff2986358f NetworkPkg: UefiPxeBcDxe: SECURITY PATCH CVE-2023-45235 Unit Tests
    fac297724e NetworkPkg: UefiPxeBcDxe: SECURITY PATCH CVE-2023-45235 Patch
    7f04c7a253 MdePkg: Test: Add gRT_GetTime Google Test Mock
    458c582685 NetworkPkg: UefiPxeBcDxe: SECURITY PATCH CVE-2023-45234 Unit Tests
    1b53515d53 NetworkPkg: UefiPxeBcDxe: SECURITY PATCH CVE-2023-45234 Patch
    c9c87f08dd NetworkPkg: Ip6Dxe: SECURITY PATCH CVE-2023-45232 Unit Tests
    4df0229ef9 NetworkPkg: Ip6Dxe: SECURITY PATCH CVE-2023-45232 Patch
    6f77463d72 NetworkPkg: Ip6Dxe: SECURITY PATCH CVE-2023-45231 Unit Tests
    bbfee34f41 NetworkPkg: Ip6Dxe: SECURITY PATCH CVE-2023-45231 Patch
    07362769ab NetworkPkg: Dhcp6Dxe: SECURITY PATCH CVE-2023-45229 Unit Tests
    1dbb10cc52 NetworkPkg: Dhcp6Dxe: SECURITY PATCH CVE-2023-45229 Patch
    5f3658197b NetworkPkg: Dhcp6Dxe: SECURITY PATCH CVE-2023-45230 Unit Tests
    8014ac2d7b NetworkPkg: : Add Unit tests to CI and create Host Test DSC
    f31453e8d6 NetworkPkg: Dhcp6Dxe: SECURITY PATCH CVE-2023-45230 Patch
    959f71c801 MdeModulePkg: Optimize CoreConnectSingleController
    9eddbab650 MdeModulePkg: Remove handle validation check in CoreGetProtocolInterface
    62b43ec896 ArmVirtPkg: Move PlatformBootManagerLib to OvmfPkg
    6bbce86d21 ArmVirtPkg: Move two PCD variables into OvmfPkg
    0cca97e0a8 ArmVirtPkg: Move the FdtSerialPortAddressLib to OvmfPkg
    5a3788bfca OvmfPkg/RiscVVirt: Remove PciCpuIo2Dxe from RiscVVirt
    010f7298ce OvmfPkg/RiscVVirt: Enable CpuMmio2Dxe
    147beaa5e7 ArmVirtPkg: Enable CpuMmio2Dxe
    55a0cdb61c UefiCpuPkg: Add a new CPU IO 2 driver named CpuMmio2Dxe
    54c2cdb241 ArmVirtPkg: Move PCD of FDT base address and FDT padding to OvmfPkg
    3db49a6ca8 EmbeddedPkg: Add PcdPrePiCpuIoSize width for LOONGARCH64
    f560c5d112 MdePkg: Add some comments for LoongArch exceptions
    3f8fb8aeb9 MdePkg: Add a new library named PeiServicesTablePointerLibKs0
    bc0b418cba MdePkg: Add IOCSR operation for LoongArch
    0565a8e885 MdePkg: Add CSR operation for LoongArch
    414ad233a5 MdePkg: Add read stable counter operation for LoongArch
    344dc4b9d3 MdePkg: Add LoongArch Cpucfg function
    2ff435b264 MdePkg: Add LoongArch64 local interrupt function set into BaseLib
    57684402e4 MdePkg: Add LoongArch64 exception function set into BaseLib
    e5b5073153 MdePkg: Add LoongArch64 FPU function set into BaseCpuLib
    9e1576bc10 MdePkg: Add the header file named Csr.h for LoongArch64
    ae59b8ba41 UefiCpuPkg/PiSmmCpuDxeSmm:Map SMRAM in 4K page granularity
    397a084b9b UefiCpuPkg: Add more Paging mode enumeration
    30a25f2778 UefiCpuPkg: Reduce and optimize access to attribute
    056b4bf74b BaseTools/Scripts/PatchCheck.py: Check for Change-id
    141dcaed6c UefiCpuPkg: Add cache operations support for Arch proto
    cd6f215223 OvmfPkg/ResetVector: Fix SNP CPUID table processing results for ECX/EDX
    a1b98c8f84 StandaloneMmPkg/Core: Output status in MMI handler assertion
    927ea1364d ShellPkg: Update smbiosview for LoongArch
    a3aab12c34 MdeModulePkg: Dxe: add LOONGARCH64 to mMachineTypeInfo
    3656352675 UefiPayloadPkg/Crypto: Support external Crypto drivers.
    97c3f5b8d2 OvmfPkg/IoMmuDxe: Provide an implementation for SetAttribute
    0e9b124f9c UefiCpuPkg/BaseXApic[X2]ApicLib: Implements AMD extended cpu topology
    d14526372d MdePkg: Adds AMD Extended CPU topology CPUID
    40a45b5a2b Basetools: Include PCD declarations from Library Instance
    af6e0e728f MdeModulePkg/Core/Dxe: Set MemoryTypeInfo bin range from HOB
    c5e702e45a MdeModulePkg/Core/Dxe: Initialize GCD before RT memory allocations
    909a9a5ae4 ArmPkg: Disable watchdog interaction after exiting boot services
    9ac93da5b5 ArmPkg: Introduce global mTimerPeriod and remove calculation
    beefa753f3 ArmPkg: Update GenericWatchdogDxe to allow setting full 48-bit offset
    98c7cb3be7 OvmfPkg/ResetVector: send post codes to qemu debug console
    a6013625a3 PcAtChipsetPkg/HpetTimerDxe: Fix nested interrupt time accuracy
    dc33394701 DynamicTablesPkg: Exempt some _CPC field from checks
    dec9d35738 DynamicTablesPkg: Add PcdDevelopmentPlatformRelaxations Pcd
    b2c4916344 DynamicTablesPkg: Add DynamicTablesScmiInfoLib
    fc04cfd119 DynamicTablesPkg: Generate _PSD in SsdtCpuTopologyGenerator
    3344495489 DynamicTablesPkg: Add AmlCreatePsdNode() to generate _PSD
    0a9060b259 DynamicTablesPkg: Add PsdToken field to CM_ARM_GICC_INFO object
    71ec5d3415 DynamicTablesPkg: Add CM_ARM_PSD_INFO object
    e3992e40c7 DynamicTablesPkg: Rename AmlCpcInfo.h to AcpiObjects.h
    ec15e345ae DynamicTablesPkg: Use new CPC revision macro
    9f0ebabb57 ArmPkg/ArmScmiDxe: Add PERFORMANCE_DESCRIBE_FASTCHANNEL support
    3630cdf6e7 ArmPkg/ArmScmiDxe: Rename PERFORMANCE_PROTOCOL_VERSION
    4c43209a74 MdePkg/Library/BaseCpuLibNull: Add missing X86 specific services
    7d7decfa3d UefiPayloadPkg/Crypto: Support external Crypto drivers.
    9a75b030cf StandaloneMmPkg/Hob: Integer Overflow in CreateHob()
    aeaee8944f EmbeddedPkg/Hob: Integer Overflow in CreateHob()
    049695a0b1 MdeModulePkg/PciBusDxe: Add feedback status for PciIoMap
    ff52277e37 MdeModulePkg/DriverSampleDxe: EFI_BROWSER_ACTION_REQUEST_QUESTION_APPLY
    588cfc63d2 MdeModulePkg/SetupBrowserDxe: EFI_BROWSER_ACTION_REQUEST_QUESTION_APPLY
    5694ff42d5 MdePkg: Add EFI_BROWSER_ACTION_REQUEST_QUESTION_APPLY
    97e1ef8730 MdePkg: Add FdtLib gmock support
    d24187a81f MdePkg/BaseFdtLib: Rename standard functions
    1063665fa5 MdeModulePkg/ResetSystemRuntimeDxe: Print Reset Data
    7f72c2829f MdePkg/Library/BaseCpuLibNull: Add StandardSignatureIsAuthenticAMD()
    417ebe6d1d MdePkg/Include/Guid: Update the definition of FileName in EFI_FILE_INFO
    2ddae5df31 StandaloneMmPkg/Core: Remove optimization for depex evaluation
    d97f3a1d80 .pytool/Plugin: UncrustifyCheck: use stat instead of os.stat
    313f9f0155 PrmPkg/PrmInfo: Drop -r parameter
    0b09397dfa UefiPayloadPkg: CbParseLib: Fix integer overflow
    0c6d29be8b CryptoPkg: Add dummy inttypes header to fix clang build
    da228b29bd MdePkg/Library/BaseIoLibIntrinsic: Fix TD MMIO read type cast
    5d016fe0a0 MdePkg/IndustryStandard: Add _PSD/_CPC/Coord types definitions
    0223bdd4e4 FmpDevicePkg: Add DECLARE_LENGTH opcode of dependency expression
    00bf6890a9 MdePkg: Add DECLARE_LENGTH opcode of dependency expression
    9d3fe85fcc NetworkPkg/Ip4Dxe: Fix Reset To Default
    264636d8e6 SecurityPkg: : Updating SecurityFixes.yaml after symbol rename
    326db0c907 SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4117/4118 symbol rename
    40adbb7f62 SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4117/4118 symbol rename
    b481b00f59 OvmfPkg/VirtNorFlashDxe: move DoErase code block into new function
    735d0a5e2e OvmfPkg/VirtNorFlashDxe: ValidateFvHeader: unwritten state is EOL too
    b25733c974 OvmfPkg/VirtNorFlashDxe: allow larger writes without block erase
    28ffd72689 OvmfPkg/VirtNorFlashDxe: add a loop for NorFlashWriteBuffer calls.
    35d8ea8097 OvmfPkg/VirtNorFlashDxe: clarify block write logic & fix shadowbuffer reads
    0395045ae3 OvmfPkg/VirtNorFlashDxe: add casts to UINTN and UINT32
    59f024c76e UefiPayloadPkg/Hob: Integer Overflow in CreateHob()
    9971b99461 RedfishPkg/JsonLib: Add JSON delete object function
    8f6d343ae6 SecurityPkg: : Adding CVE 2022-36764 to SecurityFixes.yaml
    0d341c01ee SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4118 - CVE 2022-36764
    c7b2794421 SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4118 - CVE 2022-36764
    1ddcb9fc6b SecurityPkg: : Adding CVE 2022-36763 to SecurityFixes.yaml
    4776a1b39e SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4117 - CVE 2022-36763
    2244465432 SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4117 - CVE 2022-36763
    a4b8944e27 MdePkg: Update the Label definitions of the EFI_NVDIMM_LABEL
    682a5ed1a2 NetworkPkg: RFC1323 definition changed to RFC7323
    638e4ca238 MdePkg: RFC1323 definition changed to RFC7323
    7c2757c298 MdePkg: Update the comments of callback in EFI_FORM_BROWSER2_PROTOCOL
    82e149f2bf OvmfPkg: CloudHv: Enable PcdUse1GPageTable
    6d204e8fbc OvmfPkg: Update PlatformAddressWidthInitialization for CloudHv
    bfad87ceec OvmfPkg: Add CloudHv support to PlatformScanE820 utility function.
    195e59bd0c MdePkg: Update the comments of HiiConfigAccess ExtractConfig
    d65b183f92 RedfishPkg/RedfishCrtLib: handle floating point number in JSON
    6a01fb2ea5 OvmfPkg: RiscVVirt: Fix network drivers not be built
    c15a899d83 NetworkPkg: Triger regularly scan only if not connect to AP
    f5b91c60ef UefiCpuPkg: change name of gMpInformationHobGuid2
    db59ff333d UefiCpuPkg:Limit PhysicalAddressBits in special case
    cfe4846572 UefiCpuPkg/PiSmmCpuDxeSmm: Optimize PatchSmmSaveStateMap and FlushTlbForAll
    2bce85bd86 pip-requirements.txt: Update to latest
    58355ec192 .pytool/Readme.md: Update matrix for DynamicTablesPkg
    0765ee6cd3 MdePkg/BaseLib: Fix boot DxeCore hang on riscv platform
    ebf378a1ad OvmfPkg/RiscVVirt: Override Sstc extension
    f91029947b UefiCpuPkg/CpuTimerDxeRiscV64: Add support for Sstc
    8ae17a71af MdePkg/BaseLib: RISC-V: Add function to update stimecmp register
    fd629ef6e3 MdePkg.dec: RISC-V: Define override bit for Sstc extension
    889535caf8 MdePkg: Update GetHealthStatus function description
    e7cfdc5f14 CryptoPkg: Fix redefinition error of int defines
    6c488a2f39 BaseTools: Fix raw strings containing valid escape characters
    7d055812cc IntelFsp2Pkg\Tools\ConfigEditor:Added new USF config workstream.
    bc34a79cd2 RedfishPkg/RedfishDebugLib: add function to print buffer.
    265b4ab91b RedfishPkg/RedfishRestExDxe: Update Supported function
    b0e892d8a9 RedfishPkg/RedfishRestExDxe: Uncrustify RedfishRestExDriver.h
    0a12d8bd55 RedfishPkg/RedfishRestExDxe: Implement EDKII_HTTP_CALLBACK_PROTOCOL
    8466480965 NetworkPkg/HttpDxe: Add HttpEventTlsConfigured HTTP callback event
    43ab6622a8 NetworkPkg/HttpDxe: Consider TLS certificate not found as a success case
    0abd598e3f NetworkPkg/HttpDxe: Refactor TlsCreateChild
    edba0779ba UefiPayloadPkg/UefiPayloadEntry: Remove SCI enabling check
    4a443f73fd OvmfPkg/VirtNorFlashDxe: sanity-check variables
    ae22b2f136 OvmfPkg/VirtNorFlashDxe: stop accepting gEfiVariableGuid
    3b1ddbddee OvmfPkg/RiscVVirt: use gEfiAuthenticatedVariableGuid unconditionally
    08a6528bac UefiCpuPkg: Check lower 24 bits of ProcessorNumber
    2a5c08caaf UefiCpuPkg: set EXTENDED_PROCESSOR_INFORMATION to 0
    f2b074398c MdePkg: Update the definition of EFI_NVDIMM_LABEL_FLAGS_LOCAL
    e7152e6186 CryptoPkg: fix gcc build fail for CryptoPkgMbedtls
    c3d865a4c2 UefiPayloadPkg: Add macro to enable selection of timer
    ff1305c9fb MdePkg: Update the definition of CapsuleImageSize on EFI_CAPSULE_HEADER
    9cf1d03ebe Add EFI_STATUS return to EMU_THUNK_PROTOCOL.SetTime()
    5a2490df0e EmulatorPkg: Update MMTimerThread() signature
    3114fd8ed7 EmulatorPkg: Improve comments in WinThunk.c
    e8166a852e UefiCpuPkg/CpuMpPei: Parallel get stack base for better performance.
    e449451770 CryptoPkg: move define to CrtLibSupport
    16c8cfc810 DynamicTablesPkg: Fix IA32 compilation errors
    ea658e35a9 DynamicTablesPkg: Fix X64 compilation errors
    7a5823f85b EmbeddedPkg: Add DtPlatformLoaderLib gmock support
    5804e94886 EmbeddedPkg: Add host based dependency to ci
    0d39caefb9 EmbeddedPkg/PrePiMemoryAllocationLib: Add ReallocatePool
    d7d4f09ff8 RedfishPkg: RedfishDiscoverDxe: add [] brackets to URI for IPv6 addresses
    91f1ce4e27 RedfishDiscoverDxe: handle memory allocation error conditions.
    139887a989 RedfishDiscoverDxe: release resources when refreshing information data
    f8de39afab RedfishDiscoverDxe: add a helper function deallocating string resources.
    d1c21f8d55 RedfishDiscoverDxe: refine InitInformationData() function
    17870bf3f5 RedfishDiscoverDxe: refine InitInformationData(), remove unnecessary casts
    2cd1b439d7 RedfishDiscoverDxe: introduce InitInformationData helper function
    9e3de4eee0 EmulatorPkg: RedfishPlatformHostInterfaceLib: get rid of unused variable
    5e2338d3df EmulatorPkg: fix typo. PcdRedfishServie -> PcdRedfishService
    24de462a9d RedfishPkg: add proper initialization of IPMI request
    8b59cb79fa RedfishPkg: add Component Name protocols to RedfishConfigHandler driver
    a87e8505b1 RedfishPkg: RedfishDiscoverDxe: fix memory leak on error path.
    d81813368a RedfishPkg: RedfishPlatformConfigDxe: reduce memory allocations
    0f66c2e687 RedfishPkg: get rid of unused definitions from RedfishCrtLib.h
    4fdd5165c1 RedfishPkg: fix RedfishPlatformCredentialLib library class name typo.
    59b4b5017c RedfishPkg: fix RedfishPlatformHostInterfaceLib library class name typo.
    58d9463939 UefiCpuPkg/PiSmmCpuDxeSmm: Reduce one round BSP & AP sync
    41d1c4475b UefiCpuPkg/PiSmmCpuDxeSmm: Invert ReleaseAllAPs & InitializeDebugAgent
    3a4ec6de01 UefiCpuPkg/PiSmmCpuDxeSmm: Align BSP and AP sync logic for SMI exit
    e1b62f3e28 UefiCpuPkg/PiSmmCpuDxeSmm: Check SMM Debug Agent support or not
    c7c2de798a MdeModulePkg/DebugAgentLibNull: Indicate SMM Debug Agent support or not
    7b3b39a2e4 SourceLevelDebugPkg/Library: Indicate SMM Debug Agent support or not
    54c662845f StandaloneMmPkg/Core: Remove dead code
    1065536c64 MdeModulePkg: Support customized FV Migration Information
    d01defe06b DynamicTablesPkg: AML Code generation to invoke a method
    29ce755cba DynamicTablesPkg: Corrects function pointer typedef of AML_PARSE_FUNCTION
    f8c918c46f DynamicTablesPkg: Corrects AmlCodeGenRdWordBusNumber parameters
    ea65643547 DynamicTablesPkg: AML Code generation for word I/O ranges
    5d533bbc27 BaseTools/GenFw: Correct offset when relocating an ADR
    9f0061a03b BaseTools: Resolve regex syntax warnings
    89705ad6c6 BaseTools: FMMT GuidTool Auto Select Config file Enabling
    a83d953dc2 UefiCpuPkg/PiSmmCpuDxeSmm: Consume SmmCpuSyncLib
    cc698d0335 UefiCpuPkg/PiSmmCpuDxeSmm: Simplify RunningApCount decrement
    0a248f169d UefiPayloadPkg: Specifies SmmCpuSyncLib instance
    32f84bd310 OvmfPkg: Specifies SmmCpuSyncLib instance
    69eb9ad4a1 UefiCpuPkg: Implements SmmCpuSyncLib library instance
    6f6a43cc8e MdePkg/MdeLibs.dsc.inc: Add SafeIntLib instance
    ba822d2851 UefiCpuPkg: Adds SmmCpuSyncLib library class
    e14a022246 UefiCpuPkg/PiSmmCpuDxeSmm: Optimize Semaphore Sync between BSP and AP
    8c1e9f9c6f MdeModulePkg/UefiBootManagerLib: Signal ReadyToBoot on platform recovery
    b1f33cbf81 OvmfPkg/RiscVVirt: Override for RISC-V CPU Features
    904b002c50 MdePkg: Utilize Cache Management Operations Implementation For RISC-V
    26727c2ae2 MdePkg: Implement RISC-V Cache Management Operations
    30faafd024 MdePkg: Rename Cache Management Function To Clarify Fence Based Op
    286b30f517 MdePkg: Move RISC-V Cache Management Declarations Into BaseLib
    3c66390e4a StandaloneMmPkg/Core: Fix the failure to find uncompressed inner FV
    4a9fcab124 StandaloneMmPkg/Core: Fix issue that offset calculation might be wrong
    0904161f6f StandaloneMmPkg/Core: Fix potential memory leak issue
    c012284048 StandaloneMmPkg/Core: Limit FwVol encapsulation section recursion
    74daeded0c ShellPkg: Tidy for code readability
    3ce5f2d445 FatPkg/FatPei: Check array offset before use
    7f5e75895b ArmPkg/DebugPeCoffExtraActionLib: Drop RVCT and Cygwin support
    59a952d9ab CloudHv: Add CI for CloudHv on AArch64
    b8a3eec88c RedfishPkg/RedfishDicovery: Remedy Redfish service discovery flow
    cee7ba349c ArmVirtQemu: Allow EFI memory attributes protocol to be disabled
    725acd0b9c UefiCpuPkg: Avoid assuming only one smmbasehob
    e51965ddd1 UefiCpuPkg: Cache core type in MpInfo2 HOB
    fc4f6627f8 UefiCpuPkg: Add a new field in MpInfo2 HOB
    be44fff723 UefiCpuPkg: Consume MpInfo2Hob in PiSmmCpuDxe
    e10f1f5a04 UefiCpuPkg: Build MpInfo2HOB in CpuMpPei
    c02eed8e5a UefiCpuPkg: Create gMpInformationHobGuid2 in UefiCpuPkg
    1d50544aa2 MdePkg:simplify Fifo API in BaseIoLibIntrinsic
    3c73532a8a MdePkg: Change IoLibFifo.c to IoLibFifoCc.c
    aa2f32cefa ArmVirtPkg: Sync debug level comments in ArmVirt.dsc.inc
    9e9c35970a MdePkg: Update MdePkg.uni with manageability debug level
    20ca600d67 MdePkg: Add manageability debug level to PcdFixedDebugPrintErrorLevel
    03be51e106 MdePkg: Improve wording of manageability debug level comment
    5b5481526f BaseTools: fixing FMMT ShrinkFv issue
    59f0d350a9 BaseTools: FMMT support ELF UPLD parser
    9627447625 BaseTools: FMMT replace output file is not generated successfully
    b5f5106c1e BaseTools: FMMT replace new free space fixing in replace
    bb13a4adab StandaloneMmPkg/StandaloneMmHobLib: Remove HOB creation
    85a5141a32 MdePkg: Add UEFI v2.10 ISA memory type definition
    3c40ee8c68 MdePkg: Define the DevicePath argument from LoadImage as optional
    2cd9d5f6fa Maintainers.txt: add Aaron Young as MptScsi and PvScsi reviewer
    ff22700fc0 Maintainers.txt: add Laszlo Ersek as a UefiCpuPkg maintainer
    408ca20a95 Maintainers.txt: add Laszlo Ersek as an OvmfPkg maintainer
    b59574a066 Maintainers.txt: add Laszlo Ersek as an ArmVirtPkg maintainer
    e8c23d1e27 OvmfPkg/MemEncryptSevLib: Fix address overflow during PVALIDATE
    7eb5040607 UefiCpuPkg/PiSmmCpuDxeSmm: Get processor extended information
    ad0b1cc144 UefiCpuPkg/BaseXApicLib: Fix CPUID_V2_EXTENDED_TOPOLOGY detection
    fe2abc9b74 ShellPkg: Fix typos
    eccdab611c OvmfPkg: remove CSM_ENABLE build macro
    605248f0fd OvmfPkg: remove Pcd8259LegacyModeEdgeLevel and Pcd8259LegacyModeMask
    cf9030f69f OvmfPkg: remove gEfiLegacy8259ProtocolGuid
    67864ffd52 OvmfPkg: remove 8259InterruptControllerDxe
    fb5c153abd OvmfPkg: exclude 8259InterruptControllerDxe
    05cffb6637 OvmfPkg: remove 8254TimerDxe
    89bd992b1f OvmfPkg: exclude 8254TimerDxe
    0e0a0a5ee8 OvmfPkg: remove Csm16
    528ae029ad OvmfPkg: remove Rule.Common.USER_DEFINED.CSM from all FDF files
    e8f860d924 OvmfPkg: exclude Csm16.inf / Csm16.bin
    769c46a9a2 OvmfPkg: remove <FrameworkDxe.h>
    f14317e9ba OvmfPkg: remove gEfiLegacyInterruptProtocolGuid
    504a0fed85 OvmfPkg: remove gEfiLegacyBiosProtocolGuid
    dd63cb95af OvmfPkg: remove gEfiLegacyBiosPlatformProtocolGuid
    f19b3d0cdc OvmfPkg: remove gEfiFirmwareVolumeProtocolGuid
    bc495d89d4 OvmfPkg: remove CsmSupportLib
    86cc0f15d9 OvmfPkg: unplug CsmSupportLib from BdsDxe
    8bd14e685e OvmfPkg: remove LegacyBiosDxe PCDs
    9d4becddba OvmfPkg: remove gEfiLegacyBiosGuid
    5161ba8ea0 OvmfPkg: remove gEfiIsaAcpiProtocolGuid
    0730f564ad OvmfPkg: remove gEfiIsaIoProtocolGuid
    d7e41ce340 OvmfPkg: exclude NullMemoryTestDxe driver
    f0c5d652d9 OvmfPkg: remove LegacyBiosDxe
    209480b047 Revert "OvmfPkg: don't assign PCI BARs above 4GiB when CSM enabled"
    87d0e572c8 OvmfPkg/IncompatiblePciDeviceSupportDxe: ignore CSM presence
    934b7f5a73 OvmfPkg: exclude LegacyBiosDxe
    ec60da4232 OvmfPkg: remove Bios Video PCDs
    4493d74e18 OvmfPkg: remove gEfiVgaMiniPortProtocolGuid
    59dc8743ce OvmfPkg: remove Csm/BiosThunk/VideoDxe
    ac79397267 OvmfPkg: exclude the CSM-based VideoDxe driver
    e948ceeb80 OvmfPkg: remove gEfiLegacyDevOrderVariableGuid
    545a5f6b68 OvmfPkg: remove LegacyBootMaintUiLib
    237a0564d4 OvmfPkg: unplug LegacyBootMaintUiLib from UiApp
    3f3e90d678 OvmfPkg: remove LegacyBootManagerLib
    0600bea167 OvmfPkg: unplug LegacyBootManagerLib from BdsDxe and UiApp
    3099db510e OvmfPkg: remove PcdCsmEnable
    506cc670c0 OvmfPkg: cripple CSM_ENABLE macro
    238690a30d OvmfPkg/Bhyve: use a proper PCI IO range
    553dfb0f57 UefiCpuPkg: Backup and Restore MSR IA32_U_CET in SMI handler.
    fd1dd8568c UefiCpuPkg: Only change CR4.CET bit for enable and disable CET.
    3018685da8 UefiCpuPkg: Use CET macro definitions in Cet.inc for SmiEntry.nasm files.
    04d47a9bf0 UefiCpuPkg: Use macro CR4_CET_BIT to replace hard code value in Cet.nasm.
    b5f20eca8a UefiCpuPkg: Add macro definitions for CET feature for NASM files.
    ff4c49a5ee MdeModulePkg/Bus: Fix XhciDxe Linker Issues
    df2ec2aab0 PcAtChipsetPkg: Fix AcpiTimerLib incompatibility with XhciDxe
    b59ab98049 BaseStackCheckLib: Fix STACK FAULT message
    7e18c9a788 UefiCpuPkg/CpuMpPei: Use CpuPageTableLib to set memory attribute.
    02d6f39bd5 UefiCpuPkg/CpuPageTableLib/TestCase: Refine test case for PAE paging.
    c83ffd2676 UefiCpuPkg/CpuPageTableLib: Init local variable before using it.
    ef3fde64aa MdePkg:Add NVME Sanitize command support to Nvme.h
    120aa60644 RedfishPkg/HostInterfaceBmcUsbNic: Fix potential memory corruption issue
    5cdeff1eb3 RedfishPkg/HostInterfaceBmcUsbNic: Fix incorrect HI protocol record size
    cf31257ec9 RedfishPkg/HostInterfaceBmcUsbNic: Correct MAC address reference
    cfafa45002 RedfishPkg/RedfishDiscovery: Refine SMBIOS 42h code
    4b5e2b3ac1 RedfishPkg/RedfishDiscovery: Add more debug message
    dbaf9d3046 RedfishPkg/RedfishConfigHandler: Correct the prototype of callback function
    8325fd6466 RedfishPkg/RedfishConfigHandler: Use Redfish HI readiness notification
    843ed20714 RedfishPkg/RedfishHostInterfaceDxe: Add Redfish HI readiness notification
    a3b56f93e1 RedfishPkg/BmcUsbNicLib: Update BMC USB NIC searching algorithm
    3e133f730b MdePkg/Test: Add google tests for BaseLib
    e2d4f75913 MdePkg/BaseLib: Fix CRC16-ANSI calculation
    7182621edc UnitTestFrameworkPkg/Readme.md: Remove gtest main() limitation
    c3769e392b UnitTestFrameworkPkg: Fix Google Test components with multiple files
    70b174e24d RedfishPkg/HostInterfaceBmcUsbNic: Set default Redfish service port
    534021965f MdeModulePkg: Optimize CoreInstallMultipleProtocolInterfaces
    26d484d086 .github/workflows/codeql.yml: Add emacs output
    b4f8c75e31 RedfishPkg: add explicit variable initialization
    ed923afda5 RedfishPkg: fix memory leak in HiiUtilityLib
    59b6b5059b EmbeddedPkg: Allow longer android kernel command line
    c0207583e0 EmbeddedPkg: Fix Android Boot Command Line Length Bug
    4f99b5fb93 BaseTools/Conf/target.template: Use VS2019 as default tool chain
    68d506e0d1 UefiCpuPkg/PiSmmCpuDxeSmm: Use NonSmm BSP as default SMM BSP.
    88580a79d4 MdeModulePkg/Variable: Merge variable header + data update into one step
    cdf36b1e36 .git-blame-ignore-revs: Ignore recent uncrustify commits
    466f2f0c5f MdeModulePkg/DxeCapsuleLibFmp: Fix crash with VirtualAddressMap omitted
    38ba4a64c5 ArmPkg/Drivers/CpuDxe: Use lower and upper attributes
    e1627f7720 Maintainers.txt: Remove myself as a tools maintainer
    9eec96bd4f OvmfPkg/ResetVector: Define SNP metadata for kernel hashes
    6436d9b693 OvmfPkg/AmdSev: Reorder MEMFD pages to match the order in OvmfPkgX64.fdf
    3c5f9ac5c3 UefiCpuPkg/MpInitLib: Copy SEV-ES save area pointer during APIC ID sorting
    447798cd3a UefiCpuPkg/MpInitLib: Use AsmCpuidEx() for CPUID_EXTENDED_TOPOLOGY leaf
    d451bba399 ArmPkg/ArmMmuLib: Use function pointer type
    0e9ce9146a OvmfPkg: Format with Uncrustify 73.0.8
    972e3b0b9d EmulatorPkg: Format with Uncrustify 73.0.8
    ec9cb4452e .pytool/UncrustifyCheck: Update to 73.0.8
    4ec2fab279 MdeModulePkg: Update DumpImageRecord() in ImagePropertiesRecordLib
    3565ee6c29 MdeModulePkg: Add Logic to Create/Delete Image Properties Records
    aa77dac3fb MdeModulePkg: Transition SMM MAT Logic to Use ImagePropertiesRecordLib
    960c7b25c2 UefiCpuPkg: Use Attribute From SMM MemoryAttributesTable if Nonzero
    cf78580a34 MdeModulePkg: Add NULL checks and Return Status to ImagePropertiesRecordLib
    7ae0516dd9 MdeModulePkg: Fix MAT SplitTable() Logic
    e2f2bbe208 MdeModulePkg: Fix MAT SplitRecord() Logic
    acb29d4cbe MdeModulePkg: Fix MAT Descriptor Count Calculation
    0a9e215312 MdeModulePkg: Add ImagePropertiesRecordLib Host-Based Unit Test
    7284c44951 MdeModulePkg: Move Some DXE MAT Logic to ImagePropertiesRecordLib
    561362368b MdeModulePkg: Update MemoryAttributesTable.c to Reduce Global Variable Use
    26460342d0 UefiPayloadPkg: Add ImagePropertiesRecordLib Instance
    1ef4e102c2 OvmfPkg: Add ImagePropertiesRecordLib Instance
    21b831c5b5 EmulatorPkg: Add ImagePropertiesRecordLib Instance
    16b1e88502 ArmVirtPkg: Add ImagePropertiesRecordLib Instance
    8bc44608b8 MdeModulePkg: Add ImagePropertiesRecordLib
    33e31c289c UefiCpuPkg/MpInitLib: Update the comments of _CPU_MP_DATA.
    cb3f41a937 UefiCpuPkg/MpInitLib: Enable execute disable bit.
  - Removed patches which are merged to edk2-stable202402:
  - ovmf-SecurityPkg-DxeTpm2MeasureBootLib-SECURITY-PATCH-4117.patch
    1ddcb9fc6b41 SecurityPkg: : Adding CVE 2022-36763 to SecurityFixes.yaml
  - ovmf-SecurityPkg-DxeTpmMeasureBootLib-SECURITY-PATCH-4117.patch
    4776a1b39ee0 SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4117 - CVE 2022-36763
  - ovmf-SecurityPkg-Adding-CVE-2022-36763-to-SecurityFixes.y.patch
    224446543206 SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4117 - CVE 2022-36763
  - ovmf-SecurityPkg-DxeTpm2MeasureBootLib-SECURITY-PATCH-4118.patch
    8f6d343ae639 SecurityPkg: : Adding CVE 2022-36764 to SecurityFixes.yaml
  - ovmf-SecurityPkg-DxeTpmMeasureBootLib-SECURITY-PATCH-4118.patch
    0d341c01eeab SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4118 - CVE 2022-36764
  - ovmf-SecurityPkg-Adding-CVE-2022-36764-to-SecurityFixes.y.patch
    c7b279442181 SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4118 - CVE 2022-36764
  - ovmf-SecurityPkg-DxeTpm2MeasureBootLib-SECURITY-PATCH-4117-4118-symbol-rename.patch
    264636d8e698 SecurityPkg: : Updating SecurityFixes.yaml after symbol rename
  - ovmf-SecurityPkg-DxeTpmMeasureBootLib-SECURITY-PATCH-4117-4118-symbol-rename.patch
    326db0c90720 SecurityPkg: DxeTpmMeasureBootLib: SECURITY PATCH 4117/4118 symbol rename
  - ovmf-SecurityPkg-Updating-SecurityFixes.yaml-after-symbol.patch
    40adbb7f628d SecurityPkg: DxeTpm2MeasureBootLib: SECURITY PATCH 4117/4118 symbol rename

++++ selinux-policy:

  - Fix systemd generator.early and generator.late file contexts (bsc#1227638)

++++ vim:

  - Removed patches, as they're no longer required (refreshing them
    deleted their contents):
    * vim-7.3-help_tags.patch
    * vim-7.4-highlight_fstab.patch
  - Reorganise all applied patches in the spec file.
  - Update to 9.1.0588:
    * 9.1.0588: The maze program no longer compiles on newer clang
    runtime(typst): Add typst runtime files
    * 9.1.0587: tests: Test_gui_lowlevel_keyevent is still flaky
    * 9.1.0586: ocaml runtime files are outdated
    runtime(termdebug): fix a few issues
    * 9.1.0585: tests: test_cpoptions leaves swapfiles around
    * 9.1.0584: Warning about redeclaring f_id() non-static
    runtime(doc): Add hint how to load termdebug from vimrc
    runtime(doc): document global insert behavior
    * 9.1.0583: filetype: *.pdf_tex files are not recognized
    * 9.1.0582: Printed line doesn't overwrite colon when pressing Enter in Ex mode
    * 9.1.0581: Various lines are indented inconsistently
    * 9.1.0580: :lmap mapping for keypad key not applied when typed in Select mode
    * 9.1.0579: Ex command is still executed after giving E1247
    * 9.1.0578: no tests for :Tohtml
    * 9.1.0577: Unnecessary checks for v:sizeoflong in test_put.vim
    * 9.1.0576: tests: still an issue with test_gettext_make
    * 9.1.0575: Wrong comments in alt_tabpage()
    * 9.1.0574: ex: wrong handling of commands after bar
    runtime(doc): add a note for netrw bug reports
    * 9.1.0573: ex: no implicit print for single addresses
    runtime(vim): make &indentexpr available from the outside
    * 9.1.0572: cannot specify tab page closing behaviour
    runtime(doc): remove obsolete Ex insert behavior
    * 9.1.0571: tests: Test_gui_lowlevel_keyevent is flaky
    runtime(logindefs): update syntax with new keywords
    * 9.1.0570: tests: test_gettext_make can be improved
    runtime(filetype): Fix Prolog file detection regex
    * 9.1.0569: fnamemodify() treats ".." and "../" differently
    runtime(mojo): include mojo ftplugin and indent script
    * 9.1.0568: Cannot expand paths from 'cdpath' setting
    * 9.1.0567: Cannot use relative paths as findfile() stop directories
    * 9.1.0566: Stop dir in findfile() doesn't work properly w/o trailing slash
    * 9.1.0565: Stop directory doesn't work properly in 'tags'
    * 9.1.0564: id() can be faster
    * 9.1.0563: Cannot process any Key event
    * 9.1.0562: tests: inconsistency in test_findfile.vim
    runtime(fstab): Add missing keywords to fstab syntax
    * 9.1.0561: netbeans: variable used un-initialized (Coverity)
    * 9.1.0560: bindtextdomain() does not indicate an error
    * 9.1.0559: translation of vim scripts can be improved
    * 9.1.0558: filetype: prolog detection can be improved
    * 9.1.0557: moving in the buffer list doesn't work as documented
    runtime(doc): fix inconsistencies in :h file-searching
    * 9.1.0556: :bwipe doesn't remove file from jumplist of other tabpages
    runtime(htmlangular): correct comment
    * 9.1.0555: filetype: angular ft detection is still problematic
    * 9.1.0554: :bw leaves jumplist and tagstack data around
    * 9.1.0553: filetype: *.mcmeta files are not recognized
    * 9.1.0552: No test for antlr4 filetype
    * 9.1.0551: filetype: htmlangular files are not properly detected
    * 9.1.0550: filetype: antlr4 files are not recognized
    * 9.1.0549: fuzzycollect regex based completion not working as expected
    runtime(doc): autocmd_add() accepts a list not a dict
    * 9.1.0548: it's not possible to get a unique id for some vars
    runtime(tmux): Update syntax script
    * 9.1.0547: No way to get the arity of a Vim function
    * 9.1.0546: vim-tiny fails on CTRL-X/CTRL-A
    runtime(hlsplaylist): include hlsplaylist ftplugin file
    runtime(doc): fix typo in :h ft-csv-syntax
    runtime(doc): Correct shell command to get $VIMRUNTIME into
    shell
    * 9.1.0545: MSVC conversion warning
    * 9.1.0544: filetype: ldapconf files are not recognized
    runtime(cmakecache): include cmakecache ftplugin file
    runtime(lex): include lex ftplugin file
    runtime(yacc): include yacc ftplugin file
    runtime(squirrel): include squirrel ftplugin file
    runtime(objcpp): include objcpp ftplugin file
    runtime(tf): include tf ftplugin file
    runtime(mysql): include mysql ftplugin file
    runtime(javacc): include javacc ftplugin file
    runtime(cabal): include cabal ftplugin file
    runtime(cuda): include CUDA ftplugin file
    runtime(editorconfig): include editorconfig ftplugin file
    runtime(kivy): update kivy syntax, include ftplugin
    runtime(syntax-tests): Stop generating redundant "*_* 99.dump"
    files
    * 9.1.0543: Behavior of CursorMovedC is strange
    runtime(vim): Update base-syntax, improve :match command
    highlighting
    * 9.1.0542: Vim9: confusing string() output for object functions
    * 9.1.0541: failing test with Vim configured without channel
    * 9.1.0540: Unused assignment in sign_define_cmd()
    runtime(doc): add page-scrolling keys to index.txt
    runtime(doc): add reference to xterm-focus-event from
    FocusGained/Lost
    * 9.1.0539: Not enough tests for what v9.1.0535 fixed
    runtime(doc): clarify how to re-init csv syntax file
    * 9.1.0538: not possible to assign priority when defining a sign
    * 9.1.0537: signed number detection for CTRL-X/A can be improved
    * 9.1.0536: filetype: zone files are not recognized
    * 9.1.0535: newline escape wrong in ex mode
    runtime(man): honor cmd modifiers before `g:ft_man_open_mode`
    runtime(man): use `nnoremap` to map to Ex commands
    * 9.1.0534: completion wrong with fuzzy when cycling back to original
    runtime(syntax-tests): Abort and report failed cursor progress
    runtime(syntax-tests): Introduce self tests for screen dumping
    runtime(syntax-tests): Clear and redraw the ruler line with
    the shell info
    runtime(syntax-tests): Allow for folded and wrapped lines in
    syntax test files
    * 9.1.0533: Vim9: need more tests for nested objects equality
    CI: Pre-v* 9.0.0110 versions generate bogus documentation tag entries
    runtime(doc): Remove wrong help tag CTRL-SHIFT-CR
    * 9.1.0532: filetype: Cedar files not recognized
    runtime(doc): document further keys that scroll page up/down
    * 9.1.0531: resource leak in mch_get_random()
    runtime(tutor): Fix wrong spanish translation
    runtime(netrw): fix remaining case of register clobber
    * 9.1.0530: xxd: MSVC warning about non-ASCII character
    * 9.1.0529: silent! causes following try/catch to not work
    runtime(rust): use shiftwidth() in indent script
    * 9.1.0528: spell completion message still wrong in translations
    * 9.1.0527: inconsistent parameter in Makefiles for Vim executable
    * 9.1.0526: Unwanted cursor movement with pagescroll at start of buffer
    runtime(doc): mention $XDG_CONFIG_HOME instead of $HOME/.config
    * 9.1.0525: Right release selects immediately when pum is truncated.
    * 9.1.0524: the recursive parameter in the *_equal functions can be removed
    runtime(termdebug): Add Deprecation warnings
    * 9.1.0523: Vim9: cannot downcast an object
    * 9.1.0522: Vim9: string(object) hangs for recursive references
    * 9.1.0521: if_py: _PyObject_CallFunction_SizeT is dropped in Python 3.13
    * 9.1.0520: Vim9: incorrect type checking for modifying lists
    runtime(manpager): avoid readonly prompt
    * 9.1.0519: MS-Windows: libvterm compilation can be optimized
    * 9.1.0518: initialize the random buffer can be improved
    * 9.1.0517: MS-Windows: too long lines in Make_mvc.mak
    runtime(terraform): Add filetype plugin for terraform
    runtime(dockerfile): enable spellchecking of comments in
    syntax script
    runtime(doc): rename variable for pandoc markdown support
    runtime(doc): In builtin overview use {buf} as param for
    appendbufline/setbufline
    runtime(doc): clarify, that register 1-* 9 will always be shifted
    runtime(netrw): save and restore register 0-* 9, a and unnamed
    runtime(termdebug): Refactored StartDebug_term and EndDebug
    functions
    runtime(java): Compose "g:java_highlight_signature" and
    "g:java_highlight_functions"
    * 9.1.0516: need more tests for nested dicts and list comparision
    * 9.1.0515: Vim9: segfault in object_equal()
    * 9.1.0514: Vim9: issue with comparing objects recursively
    runtime(termdebug): Change some variables to Enums
    runtime(vim): Update base-syntax, fix function tail comments
    * 9.1.0513: Vim9: segfault with object comparison

------------------------------------------------------------------
------------------  2024-7-15  -  Jul 15 2024  -------------------
------------------------------------------------------------------

++++ cockpit-machines:

  - Update to 316:
    * Bug fixes and performance improvements
  - Changes from 315:
    * Translation updates and bug fixes
  - Changes from 314:
    * Fix translation extraction
    * Translation updates
  - Changes from 313:
    * Updates to translations
  - Changes from 312:
    * Bug fixes and performance improvements
  - Changes from 311:
    * Allow pasting multiple SSH keys at once in Create VM dialog
    * Fix detaching host device for running VMs
  - Changes from 310:
    * Bug fixes and performance improvements
  - Changes from 309:
    * bug fixes and performance improvements
  - Changes from 308:
    * Add TPM when switching to EFI
    * Translation updates
    * Only use external snapshots for disks of type "file"
    * Skip empty media drives for external snapshots
    * Refresh VM after creating/reverting/deleting snapshots
    * Don't list disks in snapshot XML
    * Fix detaching host devices for running VMs

++++ python-kiwi:

  - Add <file> directive to incorporate custom files
    Usually custom files are managed by placing them as overlay
    files or archives. However, overlay files must be structured
    inside of a root/ subdirectory and archive files are binary
    data. It is therefore not straight forward to just reference
    one or more files as source files to the image description
    to be placed into the image. This commit adds a new <file>
    element which allows to do this. This Fixes #1953

++++ gsettings-desktop-schemas:

  - Update to version 46.1:
    + Updated translations.

++++ kernel-default:

  - btrfs: rename the bytenr field in struct btrfs_ordered_sum to
    logical (bsc#1223731 CVE-2024-26944).
  - btrfs: mark the len field in struct btrfs_ordered_sum as
    unsigned (bsc#1223731 CVE-2024-26944).
  - btrfs: don't call btrfs_record_physical_zoned for failed append
    (bsc#1223731 CVE-2024-26944).
  - btrfs: optimize out btrfs_is_zoned for !CONFIG_BLK_DEV_ZONED
    (bsc#1223731 CVE-2024-26944).
  - commit 7e64d12
  - btrfs: use SECTOR_SHIFT to convert LBA to physical offset
    (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-don-t-warn-if-discard-range-is-not-aligned-to-.patch.
  - commit ad23354
  - btrfs: don't hold an extra reference for redirtied buffers
    (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/0003-btrfs-free-qgroup-pertrans-reserve-on-transaction-ab.patch.
  - commit 47897b2
  - btrfs: export bitmap_test_range_all_{set,zero} (bsc#1223731
    CVE-2024-26944).
  - commit fcba900
  - Update patch reference for ath12k fix (CVE-2024-40979 bsc#1227855)
  - commit 0463455
  - mlxsw: spectrum_acl_tcam: Fix memory leak during rehash
    (CVE-2024-35853 bsc#1224604).
  - commit d46e600
  - mlxsw: spectrum_acl_tcam: Fix possible use-after-free during
    activity update (CVE-2024-35854 bsc#1224636).
  - commit 7cd7b18
  - phonet/pep: fix racy skb_queue_empty() use (CVE-2024-27402
    bsc#1224414).
  - commit 9f9d7b5
  - kprobe/ftrace: fix build error due to bad function definition
    (git-fixes).
  - commit 16bb0c0
  - net: prevent mss overflow in skb_segment() (CVE-2023-52435
    bsc#1220138).
  - commit b718cb4
  - netfilter: nf_tables: do not compare internal table flags on
    updates (CVE-2024-27065 bsc#1223836).
  - commit 0e49dd8
  - tracing/net_sched: NULL pointer dereference in
    perf_trace_qdisc_reset() (git-fixes).
  - commit c773566
  - tracing: Build event generation tests only as modules
    (git-fixes).
  - commit dd7f603
  - usb: ucsi: stm32: fix command completion handling (git-fixes).
  - commit 3155170
  - Bluetooth: qca: set power_ctrl_enabled on NULL returned by
    gpiod_get_optional() (git-fixes).
  - commit 3a34099
  - cachefiles: add output string to
    cachefiles_obj_[get|put]_ondemand_fd (git-fixes).
  - commit 12446de
  - iommu/vt-d: Allocate DMAR fault interrupts locally
    (bsc#1224767).
  - commit 85bf7e2
  - iommu/amd: Fix panic accessing amd_iommu_enable_faulting
    (bsc#1224767).
  - commit 567c8c9
  - netfilter: flowtable: incorrect pppoe tuple (CVE-2024-27015
    bsc#1223806).
  - commit e834f51
  - netfilter: nf_tables: Fix a memory leak in nf_tables_updchain
    (CVE-2024-27064 bsc#1223740).
  - commit daf6634
  - kprobe/ftrace: bail out if ftrace was killed (git-fixes).
  - commit 43ba702
  - tipc: Check the bearer type before calling
    tipc_udp_nl_bearer_add() (CVE-2024-26663 bsc#1222326).
  - commit fff5ef3
  - Update
    patches.suse/ring-buffer-Fix-a-race-between-readers-and-resize-checks.patch
    (bsc#1222893).
  - commit eebb09a
  - wifi: ath11k: Add coldboot calibration support for QCN9074
    (bsc#1227149).
  - wifi: ath11k: Split coldboot calibration hw_param (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-boot-failure-with-one-MSI-vector.patch.
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - commit e553d75
  - wifi: ath9k: avoid using uninitialized array (bsc#1227149).
  - Refresh patches.suse/wifi-ath9k-fix-fortify-warnings.patch.
  - commit 7a06512
  - iommu: Fix compilation without CONFIG_IOMMU_INTEL (git-fixes).
  - commit dcdbf4a
  - wifi: mt76: mt7615: add missing chanctx ops (bsc#1227149).
  - wifi: mt76: mt7915: add missing chanctx ops (bsc#1227149).
  - commit 5e9fc63

++++ kernel-rt:

  - btrfs: rename the bytenr field in struct btrfs_ordered_sum to
    logical (bsc#1223731 CVE-2024-26944).
  - btrfs: mark the len field in struct btrfs_ordered_sum as
    unsigned (bsc#1223731 CVE-2024-26944).
  - btrfs: don't call btrfs_record_physical_zoned for failed append
    (bsc#1223731 CVE-2024-26944).
  - btrfs: optimize out btrfs_is_zoned for !CONFIG_BLK_DEV_ZONED
    (bsc#1223731 CVE-2024-26944).
  - commit 7e64d12
  - btrfs: use SECTOR_SHIFT to convert LBA to physical offset
    (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/btrfs-don-t-warn-if-discard-range-is-not-aligned-to-.patch.
  - commit ad23354
  - btrfs: don't hold an extra reference for redirtied buffers
    (bsc#1223731 CVE-2024-26944).
  - Refresh
    patches.suse/0003-btrfs-free-qgroup-pertrans-reserve-on-transaction-ab.patch.
  - commit 47897b2
  - btrfs: export bitmap_test_range_all_{set,zero} (bsc#1223731
    CVE-2024-26944).
  - commit fcba900
  - Update patch reference for ath12k fix (CVE-2024-40979 bsc#1227855)
  - commit 0463455
  - mlxsw: spectrum_acl_tcam: Fix memory leak during rehash
    (CVE-2024-35853 bsc#1224604).
  - commit d46e600
  - mlxsw: spectrum_acl_tcam: Fix possible use-after-free during
    activity update (CVE-2024-35854 bsc#1224636).
  - commit 7cd7b18
  - phonet/pep: fix racy skb_queue_empty() use (CVE-2024-27402
    bsc#1224414).
  - commit 9f9d7b5
  - kprobe/ftrace: fix build error due to bad function definition
    (git-fixes).
  - commit 16bb0c0
  - net: prevent mss overflow in skb_segment() (CVE-2023-52435
    bsc#1220138).
  - commit b718cb4
  - netfilter: nf_tables: do not compare internal table flags on
    updates (CVE-2024-27065 bsc#1223836).
  - commit 0e49dd8
  - tracing/net_sched: NULL pointer dereference in
    perf_trace_qdisc_reset() (git-fixes).
  - commit c773566
  - tracing: Build event generation tests only as modules
    (git-fixes).
  - commit dd7f603
  - usb: ucsi: stm32: fix command completion handling (git-fixes).
  - commit 3155170
  - Bluetooth: qca: set power_ctrl_enabled on NULL returned by
    gpiod_get_optional() (git-fixes).
  - commit 3a34099
  - cachefiles: add output string to
    cachefiles_obj_[get|put]_ondemand_fd (git-fixes).
  - commit 12446de
  - iommu/vt-d: Allocate DMAR fault interrupts locally
    (bsc#1224767).
  - commit 85bf7e2
  - iommu/amd: Fix panic accessing amd_iommu_enable_faulting
    (bsc#1224767).
  - commit 567c8c9
  - netfilter: flowtable: incorrect pppoe tuple (CVE-2024-27015
    bsc#1223806).
  - commit e834f51
  - netfilter: nf_tables: Fix a memory leak in nf_tables_updchain
    (CVE-2024-27064 bsc#1223740).
  - commit daf6634
  - kprobe/ftrace: bail out if ftrace was killed (git-fixes).
  - commit 43ba702
  - tipc: Check the bearer type before calling
    tipc_udp_nl_bearer_add() (CVE-2024-26663 bsc#1222326).
  - commit fff5ef3
  - Update
    patches.suse/ring-buffer-Fix-a-race-between-readers-and-resize-checks.patch
    (bsc#1222893).
  - commit eebb09a
  - wifi: ath11k: Add coldboot calibration support for QCN9074
    (bsc#1227149).
  - wifi: ath11k: Split coldboot calibration hw_param (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-boot-failure-with-one-MSI-vector.patch.
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - commit e553d75
  - wifi: ath9k: avoid using uninitialized array (bsc#1227149).
  - Refresh patches.suse/wifi-ath9k-fix-fortify-warnings.patch.
  - commit 7a06512
  - iommu: Fix compilation without CONFIG_IOMMU_INTEL (git-fixes).
  - commit dcdbf4a
  - wifi: mt76: mt7615: add missing chanctx ops (bsc#1227149).
  - wifi: mt76: mt7915: add missing chanctx ops (bsc#1227149).
  - commit 5e9fc63

++++ ncurses:

  - Add ncurses patch 20240713
    + modify misc/ncurses-config.in, improved match with pkg-config output.

++++ openssl-3:

  - Add reproducible.patch to fix bsc#1223336
    aes-gcm-avx512.pl: fix non-reproducibility issue

++++ vde2:

  - Added vde2-C99.patch to avoid a C99 violation preventing the package
    to be built with GC 14.  [boo#1225950]

++++ libzypp:

  - Translation: updated .pot file.
  - Conflict with python zypp-plugin < 0.6.4 (bsc#1227793)
    Older zypp-plugins reject stomp headers including a '-'. Like the
    'content-length' header we may send.
  - Fix int overflow in Provider (fixes #559)
    This patch fixes an issue in safe_strtonum which caused
    timestamps to overflow in the Provider message parser.
  - Fix error reporting on repoindex.xml parse error (bsc#1227625)
  - version 17.35.3 (35)

++++ openssh:

  - Add sshd.socket and sshd@.service units as alternative to the
    sshd.service that makes systemd listen to the ssh port
    and run sshd per incoming connection. To enable this,
    disable sshd.service and enable sshd.socket . If you want to
    use a non standard sshd port with sshd.socket you can do
    "systemctl edit sshd.socket" and add something like:
    [Socket]
    ListenStream=8022
    which listens on port 8022 as well as on port 22. If you want
    to reset the list of listened ports and just use 8022, use:
    [Socket]
    ListenStream=
    ListenStream=8022
  - To enable a vsock listener in sshd (which allows to connect to
    libvirt VMs), the systemd-experimental package needs to be
    installed in the guest system, the libvirt-ssh-proxy package
    needs to be installed in the host and the vm needs to have
    vsock support (in virt-manager, click in "Add hardware" and
    add "VSOCK VirtIO").

++++ python-argcomplete:

  - Update to 3.4.0
    * No stdin for python calls from bash completion functions (#488)
  - Prevents usage of stdin by (python) executables that are called
    during completion generation. This prevents the completion locking up
    the entire shell when the python script is broken i.e. it enters an
    interactive mode (REPL) instead of generating the completions, as
    expected.
    * Localize shell variable REPLY to avoid overwriting users’ value (#489)
  - The variable REPLY is used by default by the ``read`` shell builtin
    to store the return value, and like all bash/zsh variables, is scoped
    globally. This change allows this variable to be used for other needs
    by appropriately scoping its internal use by an argcomplete utility
    function that uses ``read``.
  - Drop patches for issued fixed upstream
    * bash-repl.patch

++++ zypp-plugin:

  - Fix stomp header regex to include '-' (bsc#1227793)
  - version 0.6.4

------------------------------------------------------------------
------------------  2024-7-14  -  Jul 14 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.0.24 → 10.0.25

++++ kernel-default:

  - kABI workaround for wireless updates (bsc#1227149).
  - commit 956c903
  - i2c: rcar: bring hardware to known state when probing
    (git-fixes).
  - i2c: testunit: avoid re-issued work after read message
    (git-fixes).
  - i2c: mark HostNotify target address as used (git-fixes).
  - i2c: testunit: correct Kconfig description (git-fixes).
  - commit 834d4d5

++++ kernel-rt:

  - kABI workaround for wireless updates (bsc#1227149).
  - commit 956c903
  - i2c: rcar: bring hardware to known state when probing
    (git-fixes).
  - i2c: testunit: avoid re-issued work after read message
    (git-fixes).
  - i2c: mark HostNotify target address as used (git-fixes).
  - i2c: testunit: correct Kconfig description (git-fixes).
  - commit 834d4d5

------------------------------------------------------------------
------------------  2024-7-13  -  Jul 13 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - supported.conf: update for mt76 stuff (bsc#1227149)
  - commit 276fbe5
  - kabi/severities: cover all mt76 modules (bsc#1227149)
  - commit 8877f2f
  - wifi: mac80211: fix BSS_CHANGED_UNSOL_BCAST_PROBE_RESP
    (bsc#1227149).
  - commit a3d6465
  - wifi: mac80211: fix monitor channel with chanctx emulation
    (bsc#1227149).
  - wifi: cfg80211: validate HE operation element parsing
    (bsc#1227149).
  - wifi: mac80211: don't select link ID if not provided in scan
    request (bsc#1227149).
  - wifi: mac80211: check EHT/TTLM action frame length
    (bsc#1227149).
  - wifi: mac80211: correctly set active links upon TTLM
    (bsc#1227149).
  - wifi: cfg80211: set correct param change count in ML element
    (bsc#1227149).
  - wifi: mac80211: use deflink and fix typo in link ID check
    (bsc#1227149).
  - commit e4d62d6
  - kabi/severities: ignore kABI changes Realtek WiFi drivers (bsc#1227149)
    All those symbols are local and used for its own helpers
  - commit c402c7b
  - wifi: rtlwifi: Ignore IEEE80211_CONF_CHANGE_RETRY_LIMITS
    (bsc#1227149).
  - wifi: rtw89: wow: refine WoWLAN flows of HCI interrupts and
    low power mode (bsc#1227149).
  - wifi: rtl8xxxu: enable MFP support with security flag of RX
    descriptor (bsc#1227149).
  - wifi: rtw89: fw: scan offload prohibit all 6 GHz channel if
    no 6 GHz sband (bsc#1227149).
  - wifi: rtw89: 8852c: add quirk to set PCI BER for certain
    platforms (bsc#1227149).
  - wifi: rtw89: download firmware with five times retry
    (bsc#1227149).
  - commit 70ec305
  - wifi: rtw89: coex: fix configuration for shared antenna for
    8922A (bsc#1227149).
  - wifi: rtw89: wow: move release offload packet earlier for
    WoWLAN mode (bsc#1227149).
  - wifi: rtw89: wow: set security engine options for 802.11ax
    chips only (bsc#1227149).
  - wifi: rtw89: update suspend/resume for different generation
    (bsc#1227149).
  - wifi: rtw89: wow: update config mac function with different
    generation (bsc#1227149).
  - wifi: rtw89: update DMA function with different generation
    (bsc#1227149).
  - wifi: rtw89: wow: update WoWLAN status register for different
    generation (bsc#1227149).
  - wifi: rtw89: wow: update WoWLAN reason register for different
    chips (bsc#1227149).
  - wifi: rtw89: coex: Add coexistence policy to decrease WiFi
    packet CRC-ERR (bsc#1227149).
  - wifi: rtw89: coex: When Bluetooth not available don't set
    power/gain (bsc#1227149).
  - wifi: rtw89: coex: add return value to ensure H2C command is
    success or not (bsc#1227149).
  - wifi: rtw89: coex: Reorder H2C command index to align with
    firmware (bsc#1227149).
  - wifi: rtw89: coex: add BTC ctrl_info version 7 and related logic
    (bsc#1227149).
  - wifi: rtw89: coex: add init_info H2C command format version 7
    (bsc#1227149).
  - wifi: rtw89: 8922a: add coexistence helpers of SW grant
    (bsc#1227149).
  - wifi: rtw89: mac: add coexistence helpers {cfg/get}_plt
    (bsc#1227149).
  - wifi: rtlwifi: Remove rtl_intf_ops.read_efuse_byte
    (bsc#1227149).
  - wifi: rtl8xxxu: fix mixed declarations in rtl8xxxu_set_aifs()
    (bsc#1227149).
  - wifi: rtw89: pci: implement PCI CLK/ASPM/L1SS for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: Update EHT PHY beamforming capability
    (bsc#1227149).
  - wifi: rtw89: advertise missing extended scan feature
    (bsc#1227149).
  - wifi: rtlwifi: set initial values for unexpected cases of USB
    endpoint priority (bsc#1227149).
  - wifi: rtl8xxxu: check vif before using in rtl8xxxu_tx()
    (bsc#1227149).
  - wifi: rtlwifi: rtl8192cu: Fix TX aggregation (bsc#1227149).
  - commit e9149f1
  - wifi: rtw89: 8922a: add helper of set_channel (bsc#1227149).
  - wifi: rtw89: 8922a: add set_channel RF part (bsc#1227149).
  - wifi: rtw89: 8922a: add set_channel BB part (bsc#1227149).
  - wifi: rtw89: 8922a: add set_channel MAC part (bsc#1227149).
  - wifi: rtlwifi: rtl_usb: Store the endpoint addresses
    (bsc#1227149).
  - wifi: rtlwifi: rtl8192cu: Fix 2T2R chip type detection
    (bsc#1227149).
  - wifi: rtw89: 8922a: declare to support two chanctx
    (bsc#1227149).
  - wifi: rtw89: chan: support MCC on Wi-Fi 7 chips (bsc#1227149).
  - wifi: rtw89: fw: implement MRC H2C command functions
    (bsc#1227149).
  - wifi: rtw89: mac: implement MRC C2H event handling
    (bsc#1227149).
  - wifi: rtw89: fw: add definition of H2C command and C2H event
    for MRC series (bsc#1227149).
  - wifi: rtw89: change qutoa to DBCC by default for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: reference quota mode when setting Tx power
    (bsc#1227149).
  - wifi: rtw89: 8922a: implement AP mode related reg for BE
    generation (bsc#1227149).
  - wifi: rtw89: 8922a: correct register definition and merge IO
    for ctrl_nbtg_bt_tx() (bsc#1227149).
  - wifi: rtw89: differentiate narrow_bw_ru_dis setting according
    to chip gen (bsc#1227149).
  - wifi: rtw89: use PLCP information to match BSS_COLOR and AID
    (bsc#1227149).
  - wifi: rtw89: mac: reset PHY-1 hardware when going to
    enable/disable (bsc#1227149).
  - wifi: rtw89: mac: correct MUEDCA setting for MAC-1
    (bsc#1227149).
  - wifi: rtw89: mac: return held quota of DLE when changing MAC-1
    (bsc#1227149).
  - wifi: rtw89: load BB parameters to PHY-1 (bsc#1227149).
  - wifi: rtw89: correct PHY register offset for PHY-1
    (bsc#1227149).
  - wifi: rtw89: chan: MCC take reconfig into account (bsc#1227149).
  - wifi: rtw89: chan: move handling from add/remove to
    assign/unassign for MLO (bsc#1227149).
  - wifi: rtw89: chan: tweak weight recalc ahead before MLO
    (bsc#1227149).
  - wifi: rtw89: chan: tweak bitmap recalc ahead before MLO
    (bsc#1227149).
  - wifi: rtw89: chan: add sub-entity swap function to cover
    replacing (bsc#1227149).
  - wifi: rtw89: drop TIMING_BEACON_ONLY and sync beacon TSF by self
    (bsc#1227149).
  - wifi: rtl8xxxu: update rate mask per sta (bsc#1227149).
  - wifi: rtw89: fw: download firmware with key data for secure boot
    (bsc#1227149).
  - wifi: rtw89: fw: parse secure section from firmware file
    (bsc#1227149).
  - wifi: rtw89: fw: read firmware secure information from efuse
    (bsc#1227149).
  - wifi: rtw89: fw: consider checksum length of security data
    (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::rfk_hw_init (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::rfk_init_late to do initial
    RF calibrations later (bsc#1227149).
  - commit 28c4b55
  - wifi: rtw89: 8922a: rfk: implement chip_ops to call RF
    calibrations (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger TSSI (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger TXGAPK
    (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger DACK (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger DPK (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger RX DCK
    (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger IQK (bsc#1227149).
  - wifi: rtw89: rfk: send channel information to firmware for RF
    calibrations (bsc#1227149).
  - wifi: rtw89: rfk: add a completion to wait RF calibration
    report from C2H event (bsc#1227149).
  - wifi: rtl8xxxu: Add TP-Link TL-WN823N V2 (bsc#1227149).
  - wifi: rtl8xxxu: fix error messages (bsc#1227149).
  - wifi: rtw89: 8922a: add more fields to beacon H2C command to
    support multi-links (bsc#1227149).
  - wifi: rtw89: update ps_state register for chips with different
    generation (bsc#1227149).
  - wifi: rtw89: add new H2C for PS mode in 802.11be chip
    (bsc#1227149).
  - wifi: rtw89: 8922a: add ieee80211_ops::hw_scan (bsc#1227149).
  - wifi: rtw89: prepare scan leaf functions for wifi 7 ICs
    (bsc#1227149).
  - wifi: rtw89: debug: add FW log component for scan (bsc#1227149).
  - wifi: rtw89: update scan C2H messages for wifi 7 IC
    (bsc#1227149).
  - wifi: rtw89: 8922a: set chip_ops FEM and GPIO to NULL
    (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops to get thermal value
    (bsc#1227149).
  - wifi: rtw89: 8922a: add RF read/write v2 (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::cfg_txrx_path (bsc#1227149).
  - wifi: rtw89: 8922a: implement {stop,resume}_sch_tx and cfg_ppdu
    (bsc#1227149).
  - wifi: rtw89: 8922a: hook handlers of TX/RX descriptors to
    chip_ops (bsc#1227149).
  - wifi: rtw89: pci: validate RX tag for RXQ and RPQ (bsc#1227149).
  - wifi: rtw89: pci: interrupt v2 refine IMR for SER (bsc#1227149).
  - wifi: rtw89: pci: update SER timer unit and timeout time
    (bsc#1227149).
  - wifi: rtw89: fix disabling concurrent mode TX hang issue
    (bsc#1227149).
  - wifi: rtw89: fix HW scan timeout due to TSF sync issue
    (bsc#1227149).
  - wifi: rtw89: add wait/completion for abort scan (bsc#1227149).
  - wifi: rtw89: disable RTS when broadcast/multicast (bsc#1227149).
  - wifi: rtw89: Set default CQM config if not present
    (bsc#1227149).
  - wifi: rtw89: refine hardware scan C2H events (bsc#1227149).
  - wifi: rtw89: refine add_chan H2C command to encode_bits
    (bsc#1227149).
  - wifi: rtw89: 8922a: add BTG functions to assist BT coexistence
    to control TX/RX (bsc#1227149).
  - wifi: rtw89: 8922a: add TX power related ops (bsc#1227149).
  - wifi: rtw89: 8922a: add register definitions of H2C, C2H,
    page, RRSR and EDCCA (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops related to BB init
    (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::{enable,disable}_bb_rf
    (bsc#1227149).
  - wifi: rtw89: add mlo_dbcc_mode for WiFi 7 chips (bsc#1227149).
  - wifi: rtlwifi: Speed up firmware loading for USB (bsc#1227149).
  - wifi: rtl8xxxu: add missing number of sec cam entries for all
    variants (bsc#1227149).
  - wifi: rtl8xxxu: make instances of iface limit and combination
    to be static const (bsc#1227149).
  - wifi: rtl8xxxu: convert EN_DESC_ID of TX descriptor to le32 type
    (bsc#1227149).
  - wifi: rtlwifi: rtl8192de: Don't read register in
    _rtl92de_query_rxphystatus (bsc#1227149).
  - wifi: rtw89: fw: extend JOIN H2C command to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: fw: use struct to fill JOIN H2C command
    (bsc#1227149).
  - wifi: rtw89: fw: add H2C command to reset DMAC table for WiFi 7
    (bsc#1227149).
  - wifi: rtw89: fw: add H2C command to reset CMAC table for WiFi 7
    (bsc#1227149).
  - wifi: rtw89: fw: update TX AMPDU parameter to CMAC table
    (bsc#1227149).
  - wifi: rtw89: fw: add chip_ops to update CMAC table to associated
    station (bsc#1227149).
  - wifi: rtw89: fw: fill CMAC table to associated station for
    WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: fw: add H2C command to update security CAM v2
    (bsc#1227149).
  - wifi: rtw89: declare EXT NSS BW of VHT capability (bsc#1227149).
  - wifi: rtw89: add EHT capabilities for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: change supported bandwidths of chip_info to bit
    mask (bsc#1227149).
  - wifi: rtw89: adjust init_he_cap() to add EHT cap into
    iftype_data (bsc#1227149).
  - wifi: rtw88: use kstrtoX_from_user() in debugfs handlers
    (bsc#1227149).
  - wifi: rtl8xxxu: enable channel switch support (bsc#1227149).
  - wifi: rtlwifi: rtl_usb: Use sync register writes (bsc#1227149).
  - commit 055a697
  - wifi: rtlwifi: cleanup few rtlxxx_tx_fill_desc() routines
    (bsc#1227149).
  - wifi: rtw89: add chip_ops::update_beacon to abstract update
    beacon operation (bsc#1227149).
  - wifi: rtw89: add H2C command to download beacon frame for WiFi
    7 chips (bsc#1227149).
  - wifi: rtw89: use struct to fill H2C command to download beacon
    frame (bsc#1227149).
  - wifi: rtw89: add new H2C command to pause/sleep transmitting
    by MAC ID (bsc#1227149).
  - wifi: rtw89: refine H2C command that pause transmitting by
    MAC ID (bsc#1227149).
  - wifi: rtw89: fw: use struct to fill BA CAM H2C commands
    (bsc#1227149).
  - wifi: rtw89: 8922a: update BA CAM number to 24 (bsc#1227149).
  - wifi: rtw89: add chip_ops::h2c_ba_cam() to configure BA CAM
    (bsc#1227149).
  - wifi: rtw89: mac: add feature_init to initialize BA CAM V1
    (bsc#1227149).
  - wifi: rtw89: add firmware H2C command of BA CAM V1
    (bsc#1227149).
  - wifi: rtl8xxxu: Fix off by one initial RTS rate (bsc#1227149).
  - wifi: rtl8xxxu: Fix LED control code of RTL8192FU (bsc#1227149).
  - wifi: rtl8xxxu: declare concurrent mode support for 8188f
    (bsc#1227149).
  - wifi: rtl8xxxu: make supporting AP mode only on port 0
    transparent (bsc#1227149).
  - wifi: rtl8xxxu: add hw crypto support for AP mode (bsc#1227149).
  - wifi: rtl8xxxu: remove obsolete priv->vif (bsc#1227149).
  - wifi: rtl8xxxu: add macids for STA mode (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interface in start_ap()
    (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    bss_info_changed() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    {add,remove}_interface() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    watchdog_callback() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    configure_filter() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    update_beacon_work_callback() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in set_aifs()
    (bsc#1227149).
  - wifi: rtl8xxxu: support setting bssid register for multiple
    interfaces (bsc#1227149).
  - wifi: rtl8xxxu: don't parse CFO, if both interfaces are
    connected in STA mode (bsc#1227149).
  - wifi: rtl8xxxu: extend check for matching bssid to both
    interfaces (bsc#1227149).
  - wifi: rtl8xxxu: extend wifi connected check to both interfaces
    (bsc#1227149).
  - wifi: rtl8xxxu: support setting mac address register for both
    interfaces (bsc#1227149).
  - wifi: rtl8xxxu: 8188e: convert usage of priv->vif to
    priv->vifs[0] (bsc#1227149).
  - wifi: rtl8xxxu: support setting linktype for both interfaces
    (bsc#1227149).
  - wifi: rtl8xxxu: prepare supporting two virtual interfaces
    (bsc#1227149).
  - wifi: rtl8xxxu: remove assignment of priv->vif in
    rtl8xxxu_bss_info_changed() (bsc#1227149).
  - wifi: rtw88: 8822ce: refine power parameters for RFE type 5
    (bsc#1227149).
  - wifi: rtw89: mac: Fix spelling mistakes "notfify" -> "notify"
    (bsc#1227149).
  - wifi: rtw89: phy: set channel_info for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: phy: add BB wrapper of TX power for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: 8922a: add NCTL pre-settings for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: phy: ignore special data from BB parameter file
    (bsc#1227149).
  - wifi: rtw89: 8922a: update the register used in DIG and the
    DIG flow (bsc#1227149).
  - wifi: rtw89: 8922a: set RX gain along with set_channel operation
    (bsc#1227149).
  - wifi: rtw89: phy: add parser to support RX gain dynamic setting
    flow (bsc#1227149).
  - wifi: rtw89: phy: move bb_gain_info used by WiFi 6 chips to
    union (bsc#1227149).
  - wifi: rtw89: 8851b: update TX power tables to R37 (bsc#1227149).
  - wifi: rtw89: 8852b: update TX power tables to R36 (bsc#1227149).
  - wifi: rtw89: pci: use DBI function for 8852AE/8852BE/8851BE
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: phy: using calculate_bit_shift()
    (bsc#1227149).
  - wifi: rtw89: coex: To improve Wi-Fi performance while BT is idle
    (bsc#1227149).
  - wifi: rtw89: coex: Translate antenna configuration from ID to
    string (bsc#1227149).
  - commit d99b9e1
  - wifi: rtw89: coex: Update RF parameter control setting logic
    (bsc#1227149).
  - wifi: rtw89: coex: Add Bluetooth RSSI level information
    (bsc#1227149).
  - wifi: rtw89: coex: Set Bluetooth scan low-priority when Wi-Fi
    link/scan (bsc#1227149).
  - wifi: rtw89: coex: Update coexistence policy for Wi-Fi LPS
    (bsc#1227149).
  - wifi: rtw89: coex: Still show hardware grant signal info even
    Wi-Fi is PS (bsc#1227149).
  - wifi: rtw89: coex: Update BTG control related logic
    (bsc#1227149).
  - wifi: rtw89: coex: Add Pre-AGC control to enhance Wi-Fi RX
    performance (bsc#1227149).
  - wifi: rtw89: coex: Record down Wi-Fi initial mode information
    (bsc#1227149).
  - wifi: rtw89: coex: Fix wrong Wi-Fi role info and FDDT parameter
    members (bsc#1227149).
  - wifi: rtw88: use cfg80211_ssid_eq() instead of rtw_ssid_equal()
    (bsc#1227149).
  - wifi: rtw89: mac: implement to configure TX/RX engines for
    WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: mac: add sys_init and filter option for WiFi 7
    chips (bsc#1227149).
  - wifi: rtw89: only reset BB/RF for existing WiFi 6 chips while
    starting up (bsc#1227149).
  - wifi: rtw89: add DBCC H2C to notify firmware the status
    (bsc#1227149).
  - wifi: rtw89: mac: add suffix _ax to MAC functions (bsc#1227149).
  - wifi: rtw89: mac: add flags to check if CMAC and DMAC are
    enabled (bsc#1227149).
  - wifi: rtw89: 8922a: add power on/off functions (bsc#1227149).
  - wifi: rtw89: add XTAL SI for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: phy: print out RFK log with formatted string
    (bsc#1227149).
  - wifi: rtw89: parse and print out RFK log from C2H events
    (bsc#1227149).
  - wifi: rtw89: add C2H event handlers of RFK log and report
    (bsc#1227149).
  - wifi: rtw89: load RFK log format string from firmware file
    (bsc#1227149).
  - wifi: rtw89: fw: add version field to BB MCU firmware element
    (bsc#1227149).
  - wifi: rtw89: fw: load TX power track tables from fw_element
    (bsc#1227149).
  - wifi: rtw88: Use random MAC when efuse MAC invalid
    (bsc#1227149).
  - wifi: rtw89: avoid stringop-overflow warning (bsc#1227149).
  - wifi: rtw89: mac: refine SER setting during WiFi CPU power on
    (bsc#1227149).
  - wifi: rtw89: 8922a: dump MAC registers when SER occurs
    (bsc#1227149).
  - wifi: rtw89: 8922a: add SER IMR tables (bsc#1227149).
  - wifi: rtw89: fw: extend program counter dump for Wi-Fi 7 chip
    (bsc#1227149).
  - wifi: rtw89: 8922a: configure CRASH_TRIGGER FW feature
    (bsc#1227149).
  - wifi: rtw89: fix misbehavior of TX beacon in concurrent mode
    (bsc#1227149).
  - wifi: rtw89: refine remain on channel flow to improve P2P
    connection (bsc#1227149).
  - wifi: rtw89: Refine active scan behavior in 6 GHz (bsc#1227149).
  - wifi: rtw89: fix not entering PS mode after AP stops
    (bsc#1227149).
  - wifi: rtlwifi: Remove bridge vendor/device ids (bsc#1227149).
  - wifi: rtlwifi: Remove unused PCI related defines and struct
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Access full PMCS reg and use
    pci_regs.h (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Add pdev into
    _rtl8821ae_clear_pci_pme_status() (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Use pci_find_capability()
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Reverse PM Capability exists check
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Remove unnecessary PME_Status bit set
    (bsc#1227149).
  - wifi: rtlwifi: Convert to use PCIe capability accessors
    (bsc#1227149).
  - wifi: rtw89: mac: functions to configure hardware engine and
    quota for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: mac: use pointer to access functions of hardware
    engine and quota (bsc#1227149).
  - wifi: rtw89: mac: move code related to hardware engine to
    individual functions (bsc#1227149).
  - wifi: rtw89: mac: check queue empty according to chip gen
    (bsc#1227149).
  - wifi: rtw89: refine element naming used by queue empty check
    (bsc#1227149).
  - wifi: rtw89: add reserved size as factor of DLE used size
    (bsc#1227149).
  - wifi: rtw89: mac: add to get DLE reserved quota (bsc#1227149).
  - commit cf41ac5
  - wifi: rtw89: 8922a: extend and add quota number (bsc#1227149).
  - wifi: rtw89: debug: remove wrapper of rtw89_debug()
    (bsc#1227149).
  - wifi: rtw89: debug: add debugfs entry to disable dynamic
    mechanism (bsc#1227149).
  - wifi: rtw89: phy: dynamically adjust EDCCA threshold
    (bsc#1227149).
  - wifi: rtw89: debug: add to check if debug mask is enabled
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: phy: remove some useless code
    (bsc#1227149).
  - wifi: rtw88: debug: remove wrapper of rtw_dbg() (bsc#1227149).
  - wifi: rtw89: 8922a: read efuse content from physical map
    (bsc#1227149).
  - wifi: rtw89: 8922a: read efuse content via efuse map struct
    from logic map (bsc#1227149).
  - wifi: rtw89: 8852c: read RX gain offset from efuse for 6GHz
    channels (bsc#1227149).
  - wifi: rtw89: mac: add to access efuse for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: mac: use mac_gen pointer to access about efuse
    (bsc#1227149).
  - wifi: rtw89: 8922a: add 8922A basic chip info (bsc#1227149).
  - wifi: rtlwifi: drop unused const_amdpci_aspm (bsc#1227149).
  - wifi: rtw89: regd: update regulatory map to R65-R44
    (bsc#1227149).
  - wifi: rtw89: regd: handle policy of 6 GHz according to BIOS
    (bsc#1227149).
  - wifi: rtw89: acpi: process 6 GHz band policy from DSM
    (bsc#1227149).
  - wifi: rtlwifi: simplify rtl_action_proc() and rtl_tx_agg_start()
    (bsc#1227149).
  - wifi: rtw89: pci: update interrupt mitigation register for
    8922AE (bsc#1227149).
  - wifi: rtw89: pci: correct interrupt mitigation register for
    8852CE (bsc#1227149).
  - wifi: rtw89: 8922ae: add v2 interrupt handlers for 8922AE
    (bsc#1227149).
  - wifi: rtw89: pci: generalize interrupt status bits of interrupt
    handlers (bsc#1227149).
  - wifi: rtw89: pci: add pre_deinit to be called after probe
    complete (bsc#1227149).
  - wifi: rtw89: pci: stop/start DMA for level 1 recovery according
    to chip gen (bsc#1227149).
  - wifi: rtw89: pci: reset BDRAM according to chip gen
    (bsc#1227149).
  - wifi: rtw88: simplify __rtw_tx_work() (bsc#1227149).
  - wifi: rtw89: coex: use struct assignment to replace memcpy()
    to append TDMA content (bsc#1227149).
  - wifi: rtw89: pci: implement PCI mac_post_init for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: pci: add LTR v2 for WiFi 7 chip (bsc#1227149).
  - wifi: rtw89: pci: implement PCI mac_pre_init for WiFi 7 chips
    (bsc#1227149).
  - commit dcfcac7
  - wifi: rtw89: pci: use gen_def pointer to configure
    mac_{pre,post}_init and clear PCI ring index (bsc#1227149).
  - wifi: rtw89: pci: add PCI generation information to pci_info
    for each chip (bsc#1227149).
  - wifi: rtw89: extend PHY status parser to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: consider RX info for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: configure PPDU max user by chip (bsc#1227149).
  - wifi: rtw89: set entry size of address CAM to H2C field by chip
    (bsc#1227149).
  - wifi: rtw89: pci: generalize code of PCI control DMA IO for
    WiFi 7 (bsc#1227149).
  - wifi: rtw89: pci: add new RX ring design to determine full RX
    ring efficiently (bsc#1227149).
  - wifi: rtw89: pci: define PCI ring address for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: 8922ae: add 8922AE PCI entry and basic info
    (bsc#1227149).
  - wifi: rtlwifi: rtl92ee_dm_dynamic_primary_cca_check(): fix
    typo in function name (bsc#1227149).
  - wifi: rtlwifi: cleanup struct rtl_phy (bsc#1227149).
  - wifi: rtlwifi: cleanup struct rtl_hal (bsc#1227149).
  - wifi: rtw89: cleanup firmware elements parsing (bsc#1227149).
  - wifi: rtlwifi: drop chk_switch_dmdp() from HAL interface
    (bsc#1227149).
  - wifi: rtlwifi: drop fill_fake_txdesc() from HAL interface
    (bsc#1227149).
  - wifi: rtlwifi: drop pre_fill_tx_bd_desc() from HAL interface
    (bsc#1227149).
  - wifi: rtw89: move software DCFO compensation setting to proper
    position (bsc#1227149).
  - wifi: rtw89: correct the DCFO tracking flow to improve CFO
    compensation (bsc#1227149).
  - wifi: rtw89: modify the register setting and the flow of CFO
    tracking (bsc#1227149).
  - wifi: rtw89: phy: generalize valid bit of BSS color
    (bsc#1227149).
  - wifi: rtw89: phy: change naming related BT coexistence functions
    (bsc#1227149).
  - wifi: rtw88: dump firmware debug information in abnormal state
    (bsc#1227149).
  - wifi: rtw88: debug: add to check if debug mask is enabled
    (bsc#1227149).
  - wifi: rtlwifi: cleanup struct rtl_ps_ctl (bsc#1227149).
  - wifi: rtw89: mac: do bf_monitor only if WiFi 6 chips
    (bsc#1227149).
  - wifi: rtw89: mac: set bf_assoc capabilities according to chip
    gen (bsc#1227149).
  - wifi: rtw89: mac: set bfee_ctrl() according to chip gen
    (bsc#1227149).
  - wifi: rtw89: mac: add registers of MU-EDCA parameters for WiFi
    7 chips (bsc#1227149).
  - wifi: rtw89: mac: generalize register of MU-EDCA switch
    according to chip gen (bsc#1227149).
  - wifi: rtw89: mac: update RTS threshold according to chip gen
    (bsc#1227149).
  - wifi: rtlwifi: simplify TX command fill callbacks (bsc#1227149).
  - wifi: rtw89: coex: add annotation __counted_by() to struct
    rtw89_btc_btf_set_mon_reg (bsc#1227149).
  - wifi: rtw89: coex: add annotation __counted_by() for struct
    rtw89_btc_btf_set_slot_table (bsc#1227149).
  - wifi: rtw89: add EHT radiotap in monitor mode (bsc#1227149).
  - wifi: rtw89: show EHT rate in debugfs (bsc#1227149).
  - wifi: rtw89: parse TX EHT rate selected by firmware from RA
    C2H report (bsc#1227149).
  - wifi: rtw89: Add EHT rate mask as parameters of RA H2C command
    (bsc#1227149).
  - wifi: rtw89: parse EHT information from RX descriptor and PPDU
    status packet (bsc#1227149).
  - wifi: rtlwifi: use convenient list_count_nodes() (bsc#1227149).
  - commit 53661e1
  - wifi: rtlwifi: use unsigned long for bt_coexist_8723 timestamp
    (bsc#1227149).
  - wifi: rtw88: 8821c: tweak CCK TX filter setting for SRRC
    regulation (bsc#1227149).
  - wifi: rtw88: regd: update regulatory map to R64-R42
    (bsc#1227149).
  - wifi: rtw88: 8822c: update TX power limit to V70 (bsc#1227149).
  - wifi: rtw88: 8821c: update TX power limit to V67 (bsc#1227149).
  - wifi: rtw88: regd: configure QATAR and UK (bsc#1227149).
  - wifi: rtlwifi: remove unreachable code in
    rtl92d_dm_check_edca_turbo() (bsc#1227149).
  - wifi: rtw89: debug: txpwr table supports Wi-Fi 7 chips
    (bsc#1227149).
  - wifi: rtw89: debug: show txpwr table according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power RU limit according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power limit according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power offset according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power by rate according to chip gen
    (bsc#1227149).
  - wifi: rtw89: mac: get TX power control register according to
    chip gen (bsc#1227149).
  - wifi: rtlwifi: use unsigned long for rtl_bssid_entry timestamp
    (bsc#1227149).
  - wifi: rtw89: refine bandwidth 160MHz uplink OFDMA performance
    (bsc#1227149).
  - wifi: rtw89: refine uplink trigger based control mechanism
    (bsc#1227149).
  - wifi: rtw89: 8851b: update TX power tables to R34 (bsc#1227149).
  - wifi: rtw89: 8852b: update TX power tables to R35 (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R67 (bsc#1227149).
  - wifi: rtw89: regd: configure Thailand in regulation type
    (bsc#1227149).
  - wifi: rtlwifi: cleanup few rtlxxxx_set_hw_reg() routines
    (bsc#1227149).
  - wifi: rtw89: declare MCC in interface combination (bsc#1227149).
  - wifi: rtw89: 8852c: declare to support two chanctx
    (bsc#1227149).
  - wifi: rtw89: pause/proceed MCC for ROC and HW scan
    (bsc#1227149).
  - wifi: rtw89: mcc: fix NoA start time when GO is auxiliary
    (bsc#1227149).
  - wifi: rtw89: load TX power related tables from FW elements
    (bsc#1227149).
  - wifi: rtw89: phy: extend TX power common stuffs for Wi-Fi 7
    chips (bsc#1227149).
  - wifi: rtw89: load TX power by rate when RFE parms setup
    (bsc#1227149).
  - wifi: rtw89: phy: refine helpers used for raw TX power
    (bsc#1227149).
  - commit 62f3f4a
  - wifi: rtw89: indicate TX power by rate table inside RFE
    parameter (bsc#1227149).
  - wifi: rtw89: indicate TX shape table inside RFE parameter
    (bsc#1227149).
  - wifi: rtw89: add subband index of primary channel to struct
    rtw89_chan (bsc#1227149).
  - wifi: rtl8xxxu: Add a description about the device ID
    0x7392:0xb722 (bsc#1227149).
  - wifi: rtw89: add mac_gen pointer to access mac port registers
    (bsc#1227149).
  - wifi: rtw89: consolidate registers of mac port to struct
    (bsc#1227149).
  - wifi: rtw89: add chip_info::txwd_info size to generalize TX
    WD submit (bsc#1227149).
  - wifi: rtw89: add to fill TX descriptor v2 (bsc#1227149).
  - wifi: rtw89: add to fill TX descriptor for firmware command v2
    (bsc#1227149).
  - wifi: rtw89: add to query RX descriptor format v2 (bsc#1227149).
  - wifi: rtw89: mcc: deal with beacon NoA if GO exists
    (bsc#1227149).
  - wifi: rtw89: mcc: deal with BT slot change (bsc#1227149).
  - wifi: rtw89: mcc: deal with P2P PS change (bsc#1227149).
  - wifi: rtw89: mcc: track beacon offset and update when needed
    (bsc#1227149).
  - wifi: rtw89: mcc: update role bitmap when changed (bsc#1227149).
  - wifi: rtw89: 52c: rfk: disable DPK during MCC (bsc#1227149).
  - wifi: rtw89: rfk: disable driver tracking during MCC
    (bsc#1227149).
  - wifi: rtw89: 52c: rfk: refine MCC channel info notification
    (bsc#1227149).
  - wifi: rtw89: 8922a: set memory heap address for secure firmware
    (bsc#1227149).
  - wifi: rtw89: fw: refine download flow to support variant
    firmware suits (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::bb_preinit to enable BB
    before downloading firmware (bsc#1227149).
  - wifi: rtw89: fw: propagate an argument include_bb for BB MCU
    firmware (bsc#1227149).
  - wifi: rtw89: fw: add checking type for variant type of firmware
    (bsc#1227149).
  - wifi: rtw89: fw: implement supported functions of download
    firmware for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: fw: generalize download firmware flow by mac_gen
    pointers (bsc#1227149).
  - wifi: rtw89: fw: move polling function of firmware path ready
    to an individual function (bsc#1227149).
  - wifi: rtw89: mcc: trigger FW to start/stop MCC (bsc#1227149).
  - wifi: rtw89: fix typo of rtw89_fw_h2c_mcc_macid_bitmap()
    (bsc#1227149).
  - wifi: rtw89: mcc: decide pattern and calculate parameters
    (bsc#1227149).
  - wifi: rtw89: mcc: consider and determine BT duration
    (bsc#1227149).
  - commit bd46e4d
  - wifi: rtw89: mcc: fill fundamental configurations (bsc#1227149).
  - wifi: rtw89: mcc: initialize start flow (bsc#1227149).
  - wifi: rtw89: 8852c: Fix TSSI causes transmit power inaccuracy
    (bsc#1227149).
  - wifi: rtw89: 8852c: Update bandedge parameters for better
    performance (bsc#1227149).
  - wifi: rtl8xxxu: mark TOTOLINK N150UA V5/N150UA-B as tested
    (bsc#1227149).
  - wifi: rtw88: fix typo rtw8822cu_probe (bsc#1227149).
  - wifi: rtlwifi: rtl8723: Remove unused function
    rtl8723_cmd_send_packet() (bsc#1227149).
  - wifi: rtw89: Fix clang -Wimplicit-fallthrough in
    rtw89_query_sar() (bsc#1227149).
  - wifi: rtw89: phy: modify register setting of ENV_MNTR, PHYSTS
    and DIG (bsc#1227149).
  - wifi: rtw89: phy: add phy_gen_def::cr_base to support WiFi 7
    chips (bsc#1227149).
  - wifi: rtw89: mac: define register address of rx_filter to
    generalize code (bsc#1227149).
  - wifi: rtw89: mac: define internal memory address for WiFi 7 chip
    (bsc#1227149).
  - wifi: rtw89: mac: generalize code to indirectly access WiFi
    internal memory (bsc#1227149).
  - wifi: rtw89: mac: add mac_gen_def::band1_offset to map MAC
    band1 register address (bsc#1227149).
  - wifi: rtw89: initialize multi-channel handling (bsc#1227149).
  - wifi: rtw89: provide functions to configure NoA for beacon
    update (bsc#1227149).
  - wifi: rtw89: call rtw89_chan_get() by vif chanctx if aware of
    vif (bsc#1227149).
  - wifi: rtw89: sar: let caller decide the center frequency to
    query (bsc#1227149).
  - wifi: rtw89: refine rtw89_correct_cck_chan() by
    rtw89_hw_to_nl80211_band() (bsc#1227149).
  - wifi: rtw89: add function prototype for coex request duration
    (bsc#1227149).
  - wifi: rtw89: regd: update regulatory map to R64-R43
    (bsc#1227149).
  - wifi: rtw89: fix a width vs precision bug (bsc#1227149).
  - wifi: rtlwifi: use eth_broadcast_addr() to assign broadcast
    address (bsc#1227149).
  - wifi: rtw89: Introduce Time Averaged SAR (TAS) feature
    (bsc#1227149).
  - wifi: rtw89: return failure if needed firmware elements are
    not recognized (bsc#1227149).
  - wifi: rtw89: add to parse firmware elements of BB and RF tables
    (bsc#1227149).
  - wifi: rtw89: introduce infrastructure of firmware elements
    (bsc#1227149).
  - wifi: rtw89: add firmware suit for BB MCU 0/1 (bsc#1227149).
  - wifi: rtw89: add firmware parser for v1 format (bsc#1227149).
  - wifi: rtw89: introduce v1 format of firmware header
    (bsc#1227149).
  - wifi: rtw89: support firmware log with formatted text
    (bsc#1227149).
  - wifi: rtw89: recognize log format from firmware file
    (bsc#1227149).
  - wifi: rtw89: get data rate mode/NSS/MCS v1 from RX descriptor
    (bsc#1227149).
  - wifi: rtw89: add to display hardware rates v1 histogram in
    debugfs (bsc#1227149).
  - wifi: rtw89: add C2H RA event V1 to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: use struct to access RA report (bsc#1227149).
  - wifi: rtw89: use struct to access firmware C2H event header
    (bsc#1227149).
  - wifi: rtw89: add H2C RA command V1 to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: use struct to set RA H2C command (bsc#1227149).
  - wifi: rtw89: phy: rate pattern handles HW rate by chip gen
    (bsc#1227149).
  - commit cdaa97d
  - wifi: rtlwifi: simplify LED management (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-simplify-non-chanctx-drivers.patch.
  - commit 34b32c5
  - wifi: rtw89: define hardware rate v1 for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: add chip_info::chip_gen to determine chip
    generation (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8723BU (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8192EU (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8710BU (RTL8188GU)
    (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8192FU (bsc#1227149).
  - wifi: rtw88: simplify vif iterators (bsc#1227149).
  - wifi: rtw88: remove unused USB bulkout size set (bsc#1227149).
  - wifi: rtw88: remove unused and set but unused leftovers
    (bsc#1227149).
  - wifi: rtlwifi: cleanup USB interface (bsc#1227149).
  - wifi: rtw89: use struct to parse firmware header (bsc#1227149).
  - wifi: rtw89: TX power stuffs replace confusing naming of _max
    with _num (bsc#1227149).
  - wifi: rtw89: 8851b: configure to force 1 TX power value
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: update IQK to version 0x8
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add LCK track (bsc#1227149).
  - wifi: rtw89: 8851b: update TX power tables to R28 (bsc#1227149).
  - wifi: rtw89: 8851b: update RF radio A parameters to R28
    (bsc#1227149).
  - wifi: rtw88: fix not entering PS mode after AP stops
    (bsc#1227149).
  - wifi: rtw88: refine register based H2C command (bsc#1227149).
  - wifi: rtw88: Stop high queue during scan (bsc#1227149).
  - wifi: rtw88: Skip high queue in hci_flush (bsc#1227149).
  - wifi: rtw88: Fix AP mode incorrect DTIM behavior (bsc#1227149).
  - wifi: rtw88: use struct instead of macros to set TX desc
    (bsc#1227149).
  - wifi: rtw88: process VO packets without workqueue to avoid
    PTK rekey failed (bsc#1227149).
  - wifi: rtw88: Fix action frame transmission fail before
    association (bsc#1227149).
  - wifi: rtw89: fix spelling typo of IQK debug messages
    (bsc#1227149).
  - wifi: rtw89: cleanup rtw89_iqk_info and related code
    (bsc#1227149).
  - wifi: rtw89: cleanup private data structures (bsc#1227149).
  - wifi: rtw88: add missing unwind goto for
    __rtw_download_firmware() (bsc#1227149).
  - commit 9b282ce
  - wifi: rtlwifi: remove misused flag from HAL data (bsc#1227149).
  - wifi: rtlwifi: remove unused dualmac control leftovers
    (bsc#1227149).
  - wifi: rtlwifi: remove unused timer and related code
    (bsc#1227149).
  - wifi: rtw89: 8852c: update RF radio A/B parameters to R63
    (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R63 with 6 GHz
    power type (3 of 3) (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R63 with 6 GHz
    power type (2 of 3) (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R63 with 6 GHz
    power type (1 of 3) (bsc#1227149).
  - wifi: rtw89: process regulatory for 6 GHz power type
    (bsc#1227149).
  - wifi: rtw89: regd: update regulatory map to R64-R40
    (bsc#1227149).
  - wifi: rtw89: regd: judge 6 GHz according to chip and BIOS
    (bsc#1227149).
  - commit f81b870
  - wifi: rtw89: refine clearing supported bands to check 2/5 GHz
    first (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-annotate-iftype_data-pointer-with-spar.patch.
  - commit 1873f0a
  - wifi: rtw89: 8851b: configure CRASH_TRIGGER feature for 8851B
    (bsc#1227149).
  - wifi: rtw89: set TX power without precondition during setting
    channel (bsc#1227149).
  - wifi: rtw89: debug: txpwr table access only valid page according
    to chip (bsc#1227149).
  - wifi: rtw89: 8851b: enable hw_scan support (bsc#1227149).
  - wifi: rtlwifi: use helper function rtl_get_hdr() (bsc#1227149).
  - wifi: rtw89: use flexible array member in rtw89_btc_btf_tlv
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: Fix spelling mistake KIP_RESOTRE ->
    KIP_RESTORE (bsc#1227149).
  - wifi: rtw89: use struct to access register-based H2C/C2H
    (bsc#1227149).
  - wifi: rtw89: use struct and le32_get_bits() to access RX
    descriptor (bsc#1227149).
  - commit 21eb4e8
  - Update config files: update for the realtek wifi driver updates (bsc#1227149)
  - commit 33b8d09
  - wifi: rtw89: use struct and le32_get_bits() to access received
    PHY status IEs (bsc#1227149).
  - wifi: rtw89: use struct and le32_get_bits to access RX info
    (bsc#1227149).
  - wifi: rtw89: add chip_ops::query_rxdesc() and rxd_len as
    helpers to support newer chips (bsc#1227149).
  - wifi: rtw89: 8851b: add 8851be to Makefile and Kconfig
    (bsc#1227149).
  - wifi: rtw89: add tx_wake notify for 8851B (bsc#1227149).
  - wifi: rtw89: enlarge supported length of read_reg debugfs entry
    (bsc#1227149).
  - wifi: rtw89: 8851b: add RF configurations (bsc#1227149).
  - wifi: rtw89: 8851b: add MAC configurations to chip_info
    (bsc#1227149).
  - wifi: rtw89: 8851b: fill BB related capabilities to chip_info
    (bsc#1227149).
  - wifi: rtw89: 8851b: add TX power related functions
    (bsc#1227149).
  - commit 66eef0c
  - Update config files: update for the realtek wifi driver updates (bsc#1227149)
  - commit 75bc634
  - wifi: rtw89: refine packet offload handling under SER
    (bsc#1227149).
  - wifi: rtw89: tweak H2C TX waiting function for SER
    (bsc#1227149).
  - wifi: rtw89: ser: reset total_sta_assoc and tdls_peer when L2
    (bsc#1227149).
  - wifi: rtw88: Add support for the SDIO based RTL8723DS chipset
    (bsc#1227149).
  - wifi: rtw88: rtw8723d: Implement RTL8723DS (SDIO) efuse parsing
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add TSSI (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add DPK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add RX DCK (bsc#1227149).
  - wifi: rtw89: 8851b: add to parse efuse content (bsc#1227149).
  - wifi: rtw89: 8851b: add set channel function (bsc#1227149).
  - wifi: rtw89: 8851b: add basic power on function (bsc#1227149).
  - wifi: rtw89: 8851b: add BT coexistence support function
    (bsc#1227149).
  - wifi: rtw89: 8851b: configure GPIO according to RFE type
    (bsc#1227149).
  - wifi: rtw89: 8851b: add to read efuse version to recognize
    hardware version B (bsc#1227149).
  - wifi: rtl8xxxu: Rename some registers (bsc#1227149).
  - wifi: rtl8xxxu: Support new chip RTL8192FU (bsc#1227149).
  - wifi: rtw89: suppress the log for specific SER called
    CMDPSR_FRZTO (bsc#1227149).
  - wifi: rtw89: ser: L1 add pre-M0 and post-M0 states
    (bsc#1227149).
  - wifi: rtw89: pci: fix interrupt enable mask for HALT C2H of
    RTL8851B (bsc#1227149).
  - wifi: rtw89: support U-NII-4 channels on 5GHz band
    (bsc#1227149).
  - wifi: rtw89: regd: judge UNII-4 according to BIOS and chip
    (bsc#1227149).
  - wifi: rtw89: introduce realtek ACPI DSM method (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add IQK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add DACK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add RCK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add AACK (bsc#1227149).
  - wifi: rtw89: 8851b: add set_channel_rf() (bsc#1227149).
  - wifi: rtw89: 8851b: add DLE mem and HFC quota (bsc#1227149).
  - wifi: rtw89: 8851b: add support WoWLAN to 8851B (bsc#1227149).
  - wifi: rtw89: change naming of BA CAM from V1 to V0_EXT
    (bsc#1227149).
  - commit a1de2dd
  - wifi: rtw89: use chip_info::small_fifo_size to choose debug_mask
    (bsc#1227149).
  - wifi: rtw89: add CFO XTAL registers field to support 8851B
    (bsc#1227149).
  - wifi: rtw89: 8851b: add NCTL post table (bsc#1227149).
  - wifi: rtw89: 8851be: add 8851BE PCI entry and fill PCI
    capabilities (bsc#1227149).
  - wifi: rtw89: 8851b: add 8851B basic chip_info (bsc#1227149).
  - wifi: rtw89: scan offload wait for FW done ACK (bsc#1227149).
  - wifi: rtw89: mac: handle C2H receive/done ACK in interrupt
    context (bsc#1227149).
  - wifi: rtw89: packet offload wait for FW response (bsc#1227149).
  - wifi: rtw89: refine packet offload delete flow of 6 GHz probe
    (bsc#1227149).
  - wifi: rtw89: release bit in rtw89_fw_h2c_del_pkt_offload()
    (bsc#1227149).
  - wifi: rtw89: add EVM for antenna diversity (bsc#1227149).
  - wifi: rtw89: add RSSI based antenna diversity (bsc#1227149).
  - wifi: rtw89: initialize antenna for antenna diversity
    (bsc#1227149).
  - wifi: rtw89: add EVM and SNR statistics to debugfs
    (bsc#1227149).
  - wifi: rtw89: add RSSI statistics for the case of antenna
    diversity to debugfs (bsc#1227149).
  - wifi: rtw89: set capability of TX antenna diversity
    (bsc#1227149).
  - wifi: rtw89: use struct rtw89_phy_sts_ie0 instead of macro to
    access PHY IE0 status (bsc#1227149).
  - wifi: rtw88: fix incorrect error codes in rtw_debugfs_set_*
    (bsc#1227149).
  - wifi: rtw88: fix incorrect error codes in
    rtw_debugfs_copy_from_user (bsc#1227149).
  - wifi: rtl8xxxu: rtl8xxxu_rx_complete(): remove unnecessary
    return (bsc#1227149).
  - commit fef25cd
  - wifi: rtl8xxxu: Add sta_add() and sta_remove() callbacks
    (bsc#1227149).
  - commit a27e0ec
  - wifi: rtl8xxxu: Support USB RX aggregation for the newer chips
    (bsc#1227149).
  - wifi: rtl8xxxu: Set maximum number of supported stations
    (bsc#1227149).
  - wifi: rtl8xxxu: Declare AP mode support for 8188f (bsc#1227149).
  - wifi: rtl8xxxu: Remove usage of tx_info->control.rates[0].flags
    (bsc#1227149).
  - wifi: rtl8xxxu: Remove usage of ieee80211_get_tx_rate()
    (bsc#1227149).
  - wifi: rtl8xxxu: Clean up filter configuration (bsc#1227149).
  - wifi: rtl8xxxu: Enable hw seq for mgmt/non-QoS data frames
    (bsc#1227149).
  - wifi: rtl8xxxu: Add parameter macid to update_rate_mask
    (bsc#1227149).
  - wifi: rtl8xxxu: Put the macid in txdesc (bsc#1227149).
  - commit 6125130
  - wifi: radiotap: add bandwidth definition of EHT U-SIG
    (bsc#1227149).
  - wifi: ieee80211: add UL-bandwidth definition of trigger frame
    (bsc#1227149).
  - wifi: rtl8xxxu: Add parameter force to
    rtl8xxxu_refresh_rate_mask (bsc#1227149).
  - wifi: rtl8xxxu: Add parameter role to report_connect
    (bsc#1227149).
  - wifi: rtl8xxxu: Actually use macid in
    rtl8xxxu_gen2_report_connect (bsc#1227149).
  - wifi: rtl8xxxu: Allow creating interface in AP mode
    (bsc#1227149).
  - wifi: rtl8xxxu: Allow setting rts threshold to -1 (bsc#1227149).
  - wifi: rtl8xxxu: Add set_tim() callback (bsc#1227149).
  - wifi: rtl8xxxu: Add beacon functions (bsc#1227149).
  - wifi: rtl8xxxu: Select correct queue for beacon frames
    (bsc#1227149).
  - wifi: rtl8xxxu: Add start_ap() callback (bsc#1227149).
  - commit 02b75ed
  - wifi: iwlwifi: bump FW API to 90 for BZ/SC devices (bsc#1227149
    CVE-2023-47210 bsc#1225601 CVE-2023-38417 bsc#1225600).
  - commit ea4853c
  - wifi: iwlwifi: bump FW API to 89 for AX/BZ/SC devices
    (bsc#1227149 CVE-2023-47210 bsc#1225601 CVE-2023-38417
    bsc#1225600).
  - commit bc49209
  - ASoC: SOF: Intel: hda-pcm: Limit the maximum number of periods
    by MAX_BDL_ENTRIES (stable-fixes).
  - ASoC: rt711-sdw: add missing readable registers (stable-fixes).
  - ALSA: hda/realtek: Enable Mute LED on HP 250 G7 (stable-fixes).
  - ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
    (stable-fixes).
  - ALSA: hda/realtek: add quirk for Clevo V5[46]0TU (stable-fixes).
  - commit 1ddd32b
  - hpet: Support 32-bit userspace (git-fixes).
  - misc: fastrpc: Restrict untrusted app to attach to privileged PD
    (git-fixes).
  - misc: fastrpc: Fix ownership reassignment of remote heap
    (git-fixes).
  - misc: fastrpc: Fix memory leak in audio daemon attach operation
    (git-fixes).
  - misc: fastrpc: Avoid updating PD type for capability request
    (git-fixes).
  - misc: fastrpc: Copy the complete capability structure to user
    (git-fixes).
  - misc: fastrpc: Fix DSP capabilities request (git-fixes).
  - USB: serial: mos7840: fix crash on resume (git-fixes).
  - USB: core: Fix duplicate endpoint bug by clearing reserved
    bits in the descriptor (git-fixes).
  - firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files
    (git-fixes).
  - ASoC: SOF: Intel: hda: fix null deref on system suspend entry
    (git-fixes).
  - firmware: cs_dsp: Prevent buffer overrun when processing V2
    alg headers (git-fixes).
  - firmware: cs_dsp: Validate payload length before processing
    block (git-fixes).
  - firmware: cs_dsp: Return error if block header overflows file
    (git-fixes).
  - firmware: cs_dsp: Fix overflow checking of wmfw header
    (git-fixes).
  - ALSA: hda: cs35l41: Fix swapped l/r audio channels for Lenovo
    ThinBook 13x Gen4 (git-fixes).
  - commit 34ebce1

++++ kernel-firmware-all:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-amdgpu:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-ath10k:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-ath11k:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-ath12k:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-atheros:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-bluetooth:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-bnx2:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-brcm:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-chelsio:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-dpaa2:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-i915:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-intel:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-iwlwifi:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-liquidio:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-marvell:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-media:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-mediatek:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-mellanox:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-mwifiex:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-network:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-nfp:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-nvidia:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-platform:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-prestera:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-qcom:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-qlogic:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-radeon:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-realtek:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-serial:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-sound:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-ti:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-ueagle:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-firmware-usb-network:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

++++ kernel-rt:

  - supported.conf: update for mt76 stuff (bsc#1227149)
  - commit 276fbe5
  - kabi/severities: cover all mt76 modules (bsc#1227149)
  - commit 8877f2f
  - wifi: mac80211: fix BSS_CHANGED_UNSOL_BCAST_PROBE_RESP
    (bsc#1227149).
  - commit a3d6465
  - wifi: mac80211: fix monitor channel with chanctx emulation
    (bsc#1227149).
  - wifi: cfg80211: validate HE operation element parsing
    (bsc#1227149).
  - wifi: mac80211: don't select link ID if not provided in scan
    request (bsc#1227149).
  - wifi: mac80211: check EHT/TTLM action frame length
    (bsc#1227149).
  - wifi: mac80211: correctly set active links upon TTLM
    (bsc#1227149).
  - wifi: cfg80211: set correct param change count in ML element
    (bsc#1227149).
  - wifi: mac80211: use deflink and fix typo in link ID check
    (bsc#1227149).
  - commit e4d62d6
  - kabi/severities: ignore kABI changes Realtek WiFi drivers (bsc#1227149)
    All those symbols are local and used for its own helpers
  - commit c402c7b
  - wifi: rtlwifi: Ignore IEEE80211_CONF_CHANGE_RETRY_LIMITS
    (bsc#1227149).
  - wifi: rtw89: wow: refine WoWLAN flows of HCI interrupts and
    low power mode (bsc#1227149).
  - wifi: rtl8xxxu: enable MFP support with security flag of RX
    descriptor (bsc#1227149).
  - wifi: rtw89: fw: scan offload prohibit all 6 GHz channel if
    no 6 GHz sband (bsc#1227149).
  - wifi: rtw89: 8852c: add quirk to set PCI BER for certain
    platforms (bsc#1227149).
  - wifi: rtw89: download firmware with five times retry
    (bsc#1227149).
  - commit 70ec305
  - wifi: rtw89: coex: fix configuration for shared antenna for
    8922A (bsc#1227149).
  - wifi: rtw89: wow: move release offload packet earlier for
    WoWLAN mode (bsc#1227149).
  - wifi: rtw89: wow: set security engine options for 802.11ax
    chips only (bsc#1227149).
  - wifi: rtw89: update suspend/resume for different generation
    (bsc#1227149).
  - wifi: rtw89: wow: update config mac function with different
    generation (bsc#1227149).
  - wifi: rtw89: update DMA function with different generation
    (bsc#1227149).
  - wifi: rtw89: wow: update WoWLAN status register for different
    generation (bsc#1227149).
  - wifi: rtw89: wow: update WoWLAN reason register for different
    chips (bsc#1227149).
  - wifi: rtw89: coex: Add coexistence policy to decrease WiFi
    packet CRC-ERR (bsc#1227149).
  - wifi: rtw89: coex: When Bluetooth not available don't set
    power/gain (bsc#1227149).
  - wifi: rtw89: coex: add return value to ensure H2C command is
    success or not (bsc#1227149).
  - wifi: rtw89: coex: Reorder H2C command index to align with
    firmware (bsc#1227149).
  - wifi: rtw89: coex: add BTC ctrl_info version 7 and related logic
    (bsc#1227149).
  - wifi: rtw89: coex: add init_info H2C command format version 7
    (bsc#1227149).
  - wifi: rtw89: 8922a: add coexistence helpers of SW grant
    (bsc#1227149).
  - wifi: rtw89: mac: add coexistence helpers {cfg/get}_plt
    (bsc#1227149).
  - wifi: rtlwifi: Remove rtl_intf_ops.read_efuse_byte
    (bsc#1227149).
  - wifi: rtl8xxxu: fix mixed declarations in rtl8xxxu_set_aifs()
    (bsc#1227149).
  - wifi: rtw89: pci: implement PCI CLK/ASPM/L1SS for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: Update EHT PHY beamforming capability
    (bsc#1227149).
  - wifi: rtw89: advertise missing extended scan feature
    (bsc#1227149).
  - wifi: rtlwifi: set initial values for unexpected cases of USB
    endpoint priority (bsc#1227149).
  - wifi: rtl8xxxu: check vif before using in rtl8xxxu_tx()
    (bsc#1227149).
  - wifi: rtlwifi: rtl8192cu: Fix TX aggregation (bsc#1227149).
  - commit e9149f1
  - wifi: rtw89: 8922a: add helper of set_channel (bsc#1227149).
  - wifi: rtw89: 8922a: add set_channel RF part (bsc#1227149).
  - wifi: rtw89: 8922a: add set_channel BB part (bsc#1227149).
  - wifi: rtw89: 8922a: add set_channel MAC part (bsc#1227149).
  - wifi: rtlwifi: rtl_usb: Store the endpoint addresses
    (bsc#1227149).
  - wifi: rtlwifi: rtl8192cu: Fix 2T2R chip type detection
    (bsc#1227149).
  - wifi: rtw89: 8922a: declare to support two chanctx
    (bsc#1227149).
  - wifi: rtw89: chan: support MCC on Wi-Fi 7 chips (bsc#1227149).
  - wifi: rtw89: fw: implement MRC H2C command functions
    (bsc#1227149).
  - wifi: rtw89: mac: implement MRC C2H event handling
    (bsc#1227149).
  - wifi: rtw89: fw: add definition of H2C command and C2H event
    for MRC series (bsc#1227149).
  - wifi: rtw89: change qutoa to DBCC by default for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: reference quota mode when setting Tx power
    (bsc#1227149).
  - wifi: rtw89: 8922a: implement AP mode related reg for BE
    generation (bsc#1227149).
  - wifi: rtw89: 8922a: correct register definition and merge IO
    for ctrl_nbtg_bt_tx() (bsc#1227149).
  - wifi: rtw89: differentiate narrow_bw_ru_dis setting according
    to chip gen (bsc#1227149).
  - wifi: rtw89: use PLCP information to match BSS_COLOR and AID
    (bsc#1227149).
  - wifi: rtw89: mac: reset PHY-1 hardware when going to
    enable/disable (bsc#1227149).
  - wifi: rtw89: mac: correct MUEDCA setting for MAC-1
    (bsc#1227149).
  - wifi: rtw89: mac: return held quota of DLE when changing MAC-1
    (bsc#1227149).
  - wifi: rtw89: load BB parameters to PHY-1 (bsc#1227149).
  - wifi: rtw89: correct PHY register offset for PHY-1
    (bsc#1227149).
  - wifi: rtw89: chan: MCC take reconfig into account (bsc#1227149).
  - wifi: rtw89: chan: move handling from add/remove to
    assign/unassign for MLO (bsc#1227149).
  - wifi: rtw89: chan: tweak weight recalc ahead before MLO
    (bsc#1227149).
  - wifi: rtw89: chan: tweak bitmap recalc ahead before MLO
    (bsc#1227149).
  - wifi: rtw89: chan: add sub-entity swap function to cover
    replacing (bsc#1227149).
  - wifi: rtw89: drop TIMING_BEACON_ONLY and sync beacon TSF by self
    (bsc#1227149).
  - wifi: rtl8xxxu: update rate mask per sta (bsc#1227149).
  - wifi: rtw89: fw: download firmware with key data for secure boot
    (bsc#1227149).
  - wifi: rtw89: fw: parse secure section from firmware file
    (bsc#1227149).
  - wifi: rtw89: fw: read firmware secure information from efuse
    (bsc#1227149).
  - wifi: rtw89: fw: consider checksum length of security data
    (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::rfk_hw_init (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::rfk_init_late to do initial
    RF calibrations later (bsc#1227149).
  - commit 28c4b55
  - wifi: rtw89: 8922a: rfk: implement chip_ops to call RF
    calibrations (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger TSSI (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger TXGAPK
    (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger DACK (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger DPK (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger RX DCK
    (bsc#1227149).
  - wifi: rtw89: rfk: add H2C command to trigger IQK (bsc#1227149).
  - wifi: rtw89: rfk: send channel information to firmware for RF
    calibrations (bsc#1227149).
  - wifi: rtw89: rfk: add a completion to wait RF calibration
    report from C2H event (bsc#1227149).
  - wifi: rtl8xxxu: Add TP-Link TL-WN823N V2 (bsc#1227149).
  - wifi: rtl8xxxu: fix error messages (bsc#1227149).
  - wifi: rtw89: 8922a: add more fields to beacon H2C command to
    support multi-links (bsc#1227149).
  - wifi: rtw89: update ps_state register for chips with different
    generation (bsc#1227149).
  - wifi: rtw89: add new H2C for PS mode in 802.11be chip
    (bsc#1227149).
  - wifi: rtw89: 8922a: add ieee80211_ops::hw_scan (bsc#1227149).
  - wifi: rtw89: prepare scan leaf functions for wifi 7 ICs
    (bsc#1227149).
  - wifi: rtw89: debug: add FW log component for scan (bsc#1227149).
  - wifi: rtw89: update scan C2H messages for wifi 7 IC
    (bsc#1227149).
  - wifi: rtw89: 8922a: set chip_ops FEM and GPIO to NULL
    (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops to get thermal value
    (bsc#1227149).
  - wifi: rtw89: 8922a: add RF read/write v2 (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::cfg_txrx_path (bsc#1227149).
  - wifi: rtw89: 8922a: implement {stop,resume}_sch_tx and cfg_ppdu
    (bsc#1227149).
  - wifi: rtw89: 8922a: hook handlers of TX/RX descriptors to
    chip_ops (bsc#1227149).
  - wifi: rtw89: pci: validate RX tag for RXQ and RPQ (bsc#1227149).
  - wifi: rtw89: pci: interrupt v2 refine IMR for SER (bsc#1227149).
  - wifi: rtw89: pci: update SER timer unit and timeout time
    (bsc#1227149).
  - wifi: rtw89: fix disabling concurrent mode TX hang issue
    (bsc#1227149).
  - wifi: rtw89: fix HW scan timeout due to TSF sync issue
    (bsc#1227149).
  - wifi: rtw89: add wait/completion for abort scan (bsc#1227149).
  - wifi: rtw89: disable RTS when broadcast/multicast (bsc#1227149).
  - wifi: rtw89: Set default CQM config if not present
    (bsc#1227149).
  - wifi: rtw89: refine hardware scan C2H events (bsc#1227149).
  - wifi: rtw89: refine add_chan H2C command to encode_bits
    (bsc#1227149).
  - wifi: rtw89: 8922a: add BTG functions to assist BT coexistence
    to control TX/RX (bsc#1227149).
  - wifi: rtw89: 8922a: add TX power related ops (bsc#1227149).
  - wifi: rtw89: 8922a: add register definitions of H2C, C2H,
    page, RRSR and EDCCA (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops related to BB init
    (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::{enable,disable}_bb_rf
    (bsc#1227149).
  - wifi: rtw89: add mlo_dbcc_mode for WiFi 7 chips (bsc#1227149).
  - wifi: rtlwifi: Speed up firmware loading for USB (bsc#1227149).
  - wifi: rtl8xxxu: add missing number of sec cam entries for all
    variants (bsc#1227149).
  - wifi: rtl8xxxu: make instances of iface limit and combination
    to be static const (bsc#1227149).
  - wifi: rtl8xxxu: convert EN_DESC_ID of TX descriptor to le32 type
    (bsc#1227149).
  - wifi: rtlwifi: rtl8192de: Don't read register in
    _rtl92de_query_rxphystatus (bsc#1227149).
  - wifi: rtw89: fw: extend JOIN H2C command to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: fw: use struct to fill JOIN H2C command
    (bsc#1227149).
  - wifi: rtw89: fw: add H2C command to reset DMAC table for WiFi 7
    (bsc#1227149).
  - wifi: rtw89: fw: add H2C command to reset CMAC table for WiFi 7
    (bsc#1227149).
  - wifi: rtw89: fw: update TX AMPDU parameter to CMAC table
    (bsc#1227149).
  - wifi: rtw89: fw: add chip_ops to update CMAC table to associated
    station (bsc#1227149).
  - wifi: rtw89: fw: fill CMAC table to associated station for
    WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: fw: add H2C command to update security CAM v2
    (bsc#1227149).
  - wifi: rtw89: declare EXT NSS BW of VHT capability (bsc#1227149).
  - wifi: rtw89: add EHT capabilities for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: change supported bandwidths of chip_info to bit
    mask (bsc#1227149).
  - wifi: rtw89: adjust init_he_cap() to add EHT cap into
    iftype_data (bsc#1227149).
  - wifi: rtw88: use kstrtoX_from_user() in debugfs handlers
    (bsc#1227149).
  - wifi: rtl8xxxu: enable channel switch support (bsc#1227149).
  - wifi: rtlwifi: rtl_usb: Use sync register writes (bsc#1227149).
  - commit 055a697
  - wifi: rtlwifi: cleanup few rtlxxx_tx_fill_desc() routines
    (bsc#1227149).
  - wifi: rtw89: add chip_ops::update_beacon to abstract update
    beacon operation (bsc#1227149).
  - wifi: rtw89: add H2C command to download beacon frame for WiFi
    7 chips (bsc#1227149).
  - wifi: rtw89: use struct to fill H2C command to download beacon
    frame (bsc#1227149).
  - wifi: rtw89: add new H2C command to pause/sleep transmitting
    by MAC ID (bsc#1227149).
  - wifi: rtw89: refine H2C command that pause transmitting by
    MAC ID (bsc#1227149).
  - wifi: rtw89: fw: use struct to fill BA CAM H2C commands
    (bsc#1227149).
  - wifi: rtw89: 8922a: update BA CAM number to 24 (bsc#1227149).
  - wifi: rtw89: add chip_ops::h2c_ba_cam() to configure BA CAM
    (bsc#1227149).
  - wifi: rtw89: mac: add feature_init to initialize BA CAM V1
    (bsc#1227149).
  - wifi: rtw89: add firmware H2C command of BA CAM V1
    (bsc#1227149).
  - wifi: rtl8xxxu: Fix off by one initial RTS rate (bsc#1227149).
  - wifi: rtl8xxxu: Fix LED control code of RTL8192FU (bsc#1227149).
  - wifi: rtl8xxxu: declare concurrent mode support for 8188f
    (bsc#1227149).
  - wifi: rtl8xxxu: make supporting AP mode only on port 0
    transparent (bsc#1227149).
  - wifi: rtl8xxxu: add hw crypto support for AP mode (bsc#1227149).
  - wifi: rtl8xxxu: remove obsolete priv->vif (bsc#1227149).
  - wifi: rtl8xxxu: add macids for STA mode (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interface in start_ap()
    (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    bss_info_changed() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    {add,remove}_interface() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    watchdog_callback() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    configure_filter() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in
    update_beacon_work_callback() (bsc#1227149).
  - wifi: rtl8xxxu: support multiple interfaces in set_aifs()
    (bsc#1227149).
  - wifi: rtl8xxxu: support setting bssid register for multiple
    interfaces (bsc#1227149).
  - wifi: rtl8xxxu: don't parse CFO, if both interfaces are
    connected in STA mode (bsc#1227149).
  - wifi: rtl8xxxu: extend check for matching bssid to both
    interfaces (bsc#1227149).
  - wifi: rtl8xxxu: extend wifi connected check to both interfaces
    (bsc#1227149).
  - wifi: rtl8xxxu: support setting mac address register for both
    interfaces (bsc#1227149).
  - wifi: rtl8xxxu: 8188e: convert usage of priv->vif to
    priv->vifs[0] (bsc#1227149).
  - wifi: rtl8xxxu: support setting linktype for both interfaces
    (bsc#1227149).
  - wifi: rtl8xxxu: prepare supporting two virtual interfaces
    (bsc#1227149).
  - wifi: rtl8xxxu: remove assignment of priv->vif in
    rtl8xxxu_bss_info_changed() (bsc#1227149).
  - wifi: rtw88: 8822ce: refine power parameters for RFE type 5
    (bsc#1227149).
  - wifi: rtw89: mac: Fix spelling mistakes "notfify" -> "notify"
    (bsc#1227149).
  - wifi: rtw89: phy: set channel_info for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: phy: add BB wrapper of TX power for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: 8922a: add NCTL pre-settings for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: phy: ignore special data from BB parameter file
    (bsc#1227149).
  - wifi: rtw89: 8922a: update the register used in DIG and the
    DIG flow (bsc#1227149).
  - wifi: rtw89: 8922a: set RX gain along with set_channel operation
    (bsc#1227149).
  - wifi: rtw89: phy: add parser to support RX gain dynamic setting
    flow (bsc#1227149).
  - wifi: rtw89: phy: move bb_gain_info used by WiFi 6 chips to
    union (bsc#1227149).
  - wifi: rtw89: 8851b: update TX power tables to R37 (bsc#1227149).
  - wifi: rtw89: 8852b: update TX power tables to R36 (bsc#1227149).
  - wifi: rtw89: pci: use DBI function for 8852AE/8852BE/8851BE
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: phy: using calculate_bit_shift()
    (bsc#1227149).
  - wifi: rtw89: coex: To improve Wi-Fi performance while BT is idle
    (bsc#1227149).
  - wifi: rtw89: coex: Translate antenna configuration from ID to
    string (bsc#1227149).
  - commit d99b9e1
  - wifi: rtw89: coex: Update RF parameter control setting logic
    (bsc#1227149).
  - wifi: rtw89: coex: Add Bluetooth RSSI level information
    (bsc#1227149).
  - wifi: rtw89: coex: Set Bluetooth scan low-priority when Wi-Fi
    link/scan (bsc#1227149).
  - wifi: rtw89: coex: Update coexistence policy for Wi-Fi LPS
    (bsc#1227149).
  - wifi: rtw89: coex: Still show hardware grant signal info even
    Wi-Fi is PS (bsc#1227149).
  - wifi: rtw89: coex: Update BTG control related logic
    (bsc#1227149).
  - wifi: rtw89: coex: Add Pre-AGC control to enhance Wi-Fi RX
    performance (bsc#1227149).
  - wifi: rtw89: coex: Record down Wi-Fi initial mode information
    (bsc#1227149).
  - wifi: rtw89: coex: Fix wrong Wi-Fi role info and FDDT parameter
    members (bsc#1227149).
  - wifi: rtw88: use cfg80211_ssid_eq() instead of rtw_ssid_equal()
    (bsc#1227149).
  - wifi: rtw89: mac: implement to configure TX/RX engines for
    WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: mac: add sys_init and filter option for WiFi 7
    chips (bsc#1227149).
  - wifi: rtw89: only reset BB/RF for existing WiFi 6 chips while
    starting up (bsc#1227149).
  - wifi: rtw89: add DBCC H2C to notify firmware the status
    (bsc#1227149).
  - wifi: rtw89: mac: add suffix _ax to MAC functions (bsc#1227149).
  - wifi: rtw89: mac: add flags to check if CMAC and DMAC are
    enabled (bsc#1227149).
  - wifi: rtw89: 8922a: add power on/off functions (bsc#1227149).
  - wifi: rtw89: add XTAL SI for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: phy: print out RFK log with formatted string
    (bsc#1227149).
  - wifi: rtw89: parse and print out RFK log from C2H events
    (bsc#1227149).
  - wifi: rtw89: add C2H event handlers of RFK log and report
    (bsc#1227149).
  - wifi: rtw89: load RFK log format string from firmware file
    (bsc#1227149).
  - wifi: rtw89: fw: add version field to BB MCU firmware element
    (bsc#1227149).
  - wifi: rtw89: fw: load TX power track tables from fw_element
    (bsc#1227149).
  - wifi: rtw88: Use random MAC when efuse MAC invalid
    (bsc#1227149).
  - wifi: rtw89: avoid stringop-overflow warning (bsc#1227149).
  - wifi: rtw89: mac: refine SER setting during WiFi CPU power on
    (bsc#1227149).
  - wifi: rtw89: 8922a: dump MAC registers when SER occurs
    (bsc#1227149).
  - wifi: rtw89: 8922a: add SER IMR tables (bsc#1227149).
  - wifi: rtw89: fw: extend program counter dump for Wi-Fi 7 chip
    (bsc#1227149).
  - wifi: rtw89: 8922a: configure CRASH_TRIGGER FW feature
    (bsc#1227149).
  - wifi: rtw89: fix misbehavior of TX beacon in concurrent mode
    (bsc#1227149).
  - wifi: rtw89: refine remain on channel flow to improve P2P
    connection (bsc#1227149).
  - wifi: rtw89: Refine active scan behavior in 6 GHz (bsc#1227149).
  - wifi: rtw89: fix not entering PS mode after AP stops
    (bsc#1227149).
  - wifi: rtlwifi: Remove bridge vendor/device ids (bsc#1227149).
  - wifi: rtlwifi: Remove unused PCI related defines and struct
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Access full PMCS reg and use
    pci_regs.h (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Add pdev into
    _rtl8821ae_clear_pci_pme_status() (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Use pci_find_capability()
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Reverse PM Capability exists check
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: Remove unnecessary PME_Status bit set
    (bsc#1227149).
  - wifi: rtlwifi: Convert to use PCIe capability accessors
    (bsc#1227149).
  - wifi: rtw89: mac: functions to configure hardware engine and
    quota for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: mac: use pointer to access functions of hardware
    engine and quota (bsc#1227149).
  - wifi: rtw89: mac: move code related to hardware engine to
    individual functions (bsc#1227149).
  - wifi: rtw89: mac: check queue empty according to chip gen
    (bsc#1227149).
  - wifi: rtw89: refine element naming used by queue empty check
    (bsc#1227149).
  - wifi: rtw89: add reserved size as factor of DLE used size
    (bsc#1227149).
  - wifi: rtw89: mac: add to get DLE reserved quota (bsc#1227149).
  - commit cf41ac5
  - wifi: rtw89: 8922a: extend and add quota number (bsc#1227149).
  - wifi: rtw89: debug: remove wrapper of rtw89_debug()
    (bsc#1227149).
  - wifi: rtw89: debug: add debugfs entry to disable dynamic
    mechanism (bsc#1227149).
  - wifi: rtw89: phy: dynamically adjust EDCCA threshold
    (bsc#1227149).
  - wifi: rtw89: debug: add to check if debug mask is enabled
    (bsc#1227149).
  - wifi: rtlwifi: rtl8821ae: phy: remove some useless code
    (bsc#1227149).
  - wifi: rtw88: debug: remove wrapper of rtw_dbg() (bsc#1227149).
  - wifi: rtw89: 8922a: read efuse content from physical map
    (bsc#1227149).
  - wifi: rtw89: 8922a: read efuse content via efuse map struct
    from logic map (bsc#1227149).
  - wifi: rtw89: 8852c: read RX gain offset from efuse for 6GHz
    channels (bsc#1227149).
  - wifi: rtw89: mac: add to access efuse for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: mac: use mac_gen pointer to access about efuse
    (bsc#1227149).
  - wifi: rtw89: 8922a: add 8922A basic chip info (bsc#1227149).
  - wifi: rtlwifi: drop unused const_amdpci_aspm (bsc#1227149).
  - wifi: rtw89: regd: update regulatory map to R65-R44
    (bsc#1227149).
  - wifi: rtw89: regd: handle policy of 6 GHz according to BIOS
    (bsc#1227149).
  - wifi: rtw89: acpi: process 6 GHz band policy from DSM
    (bsc#1227149).
  - wifi: rtlwifi: simplify rtl_action_proc() and rtl_tx_agg_start()
    (bsc#1227149).
  - wifi: rtw89: pci: update interrupt mitigation register for
    8922AE (bsc#1227149).
  - wifi: rtw89: pci: correct interrupt mitigation register for
    8852CE (bsc#1227149).
  - wifi: rtw89: 8922ae: add v2 interrupt handlers for 8922AE
    (bsc#1227149).
  - wifi: rtw89: pci: generalize interrupt status bits of interrupt
    handlers (bsc#1227149).
  - wifi: rtw89: pci: add pre_deinit to be called after probe
    complete (bsc#1227149).
  - wifi: rtw89: pci: stop/start DMA for level 1 recovery according
    to chip gen (bsc#1227149).
  - wifi: rtw89: pci: reset BDRAM according to chip gen
    (bsc#1227149).
  - wifi: rtw88: simplify __rtw_tx_work() (bsc#1227149).
  - wifi: rtw89: coex: use struct assignment to replace memcpy()
    to append TDMA content (bsc#1227149).
  - wifi: rtw89: pci: implement PCI mac_post_init for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: pci: add LTR v2 for WiFi 7 chip (bsc#1227149).
  - wifi: rtw89: pci: implement PCI mac_pre_init for WiFi 7 chips
    (bsc#1227149).
  - commit dcfcac7
  - wifi: rtw89: pci: use gen_def pointer to configure
    mac_{pre,post}_init and clear PCI ring index (bsc#1227149).
  - wifi: rtw89: pci: add PCI generation information to pci_info
    for each chip (bsc#1227149).
  - wifi: rtw89: extend PHY status parser to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: consider RX info for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: configure PPDU max user by chip (bsc#1227149).
  - wifi: rtw89: set entry size of address CAM to H2C field by chip
    (bsc#1227149).
  - wifi: rtw89: pci: generalize code of PCI control DMA IO for
    WiFi 7 (bsc#1227149).
  - wifi: rtw89: pci: add new RX ring design to determine full RX
    ring efficiently (bsc#1227149).
  - wifi: rtw89: pci: define PCI ring address for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: 8922ae: add 8922AE PCI entry and basic info
    (bsc#1227149).
  - wifi: rtlwifi: rtl92ee_dm_dynamic_primary_cca_check(): fix
    typo in function name (bsc#1227149).
  - wifi: rtlwifi: cleanup struct rtl_phy (bsc#1227149).
  - wifi: rtlwifi: cleanup struct rtl_hal (bsc#1227149).
  - wifi: rtw89: cleanup firmware elements parsing (bsc#1227149).
  - wifi: rtlwifi: drop chk_switch_dmdp() from HAL interface
    (bsc#1227149).
  - wifi: rtlwifi: drop fill_fake_txdesc() from HAL interface
    (bsc#1227149).
  - wifi: rtlwifi: drop pre_fill_tx_bd_desc() from HAL interface
    (bsc#1227149).
  - wifi: rtw89: move software DCFO compensation setting to proper
    position (bsc#1227149).
  - wifi: rtw89: correct the DCFO tracking flow to improve CFO
    compensation (bsc#1227149).
  - wifi: rtw89: modify the register setting and the flow of CFO
    tracking (bsc#1227149).
  - wifi: rtw89: phy: generalize valid bit of BSS color
    (bsc#1227149).
  - wifi: rtw89: phy: change naming related BT coexistence functions
    (bsc#1227149).
  - wifi: rtw88: dump firmware debug information in abnormal state
    (bsc#1227149).
  - wifi: rtw88: debug: add to check if debug mask is enabled
    (bsc#1227149).
  - wifi: rtlwifi: cleanup struct rtl_ps_ctl (bsc#1227149).
  - wifi: rtw89: mac: do bf_monitor only if WiFi 6 chips
    (bsc#1227149).
  - wifi: rtw89: mac: set bf_assoc capabilities according to chip
    gen (bsc#1227149).
  - wifi: rtw89: mac: set bfee_ctrl() according to chip gen
    (bsc#1227149).
  - wifi: rtw89: mac: add registers of MU-EDCA parameters for WiFi
    7 chips (bsc#1227149).
  - wifi: rtw89: mac: generalize register of MU-EDCA switch
    according to chip gen (bsc#1227149).
  - wifi: rtw89: mac: update RTS threshold according to chip gen
    (bsc#1227149).
  - wifi: rtlwifi: simplify TX command fill callbacks (bsc#1227149).
  - wifi: rtw89: coex: add annotation __counted_by() to struct
    rtw89_btc_btf_set_mon_reg (bsc#1227149).
  - wifi: rtw89: coex: add annotation __counted_by() for struct
    rtw89_btc_btf_set_slot_table (bsc#1227149).
  - wifi: rtw89: add EHT radiotap in monitor mode (bsc#1227149).
  - wifi: rtw89: show EHT rate in debugfs (bsc#1227149).
  - wifi: rtw89: parse TX EHT rate selected by firmware from RA
    C2H report (bsc#1227149).
  - wifi: rtw89: Add EHT rate mask as parameters of RA H2C command
    (bsc#1227149).
  - wifi: rtw89: parse EHT information from RX descriptor and PPDU
    status packet (bsc#1227149).
  - wifi: rtlwifi: use convenient list_count_nodes() (bsc#1227149).
  - commit 53661e1
  - wifi: rtlwifi: use unsigned long for bt_coexist_8723 timestamp
    (bsc#1227149).
  - wifi: rtw88: 8821c: tweak CCK TX filter setting for SRRC
    regulation (bsc#1227149).
  - wifi: rtw88: regd: update regulatory map to R64-R42
    (bsc#1227149).
  - wifi: rtw88: 8822c: update TX power limit to V70 (bsc#1227149).
  - wifi: rtw88: 8821c: update TX power limit to V67 (bsc#1227149).
  - wifi: rtw88: regd: configure QATAR and UK (bsc#1227149).
  - wifi: rtlwifi: remove unreachable code in
    rtl92d_dm_check_edca_turbo() (bsc#1227149).
  - wifi: rtw89: debug: txpwr table supports Wi-Fi 7 chips
    (bsc#1227149).
  - wifi: rtw89: debug: show txpwr table according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power RU limit according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power limit according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power offset according to chip gen
    (bsc#1227149).
  - wifi: rtw89: phy: set TX power by rate according to chip gen
    (bsc#1227149).
  - wifi: rtw89: mac: get TX power control register according to
    chip gen (bsc#1227149).
  - wifi: rtlwifi: use unsigned long for rtl_bssid_entry timestamp
    (bsc#1227149).
  - wifi: rtw89: refine bandwidth 160MHz uplink OFDMA performance
    (bsc#1227149).
  - wifi: rtw89: refine uplink trigger based control mechanism
    (bsc#1227149).
  - wifi: rtw89: 8851b: update TX power tables to R34 (bsc#1227149).
  - wifi: rtw89: 8852b: update TX power tables to R35 (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R67 (bsc#1227149).
  - wifi: rtw89: regd: configure Thailand in regulation type
    (bsc#1227149).
  - wifi: rtlwifi: cleanup few rtlxxxx_set_hw_reg() routines
    (bsc#1227149).
  - wifi: rtw89: declare MCC in interface combination (bsc#1227149).
  - wifi: rtw89: 8852c: declare to support two chanctx
    (bsc#1227149).
  - wifi: rtw89: pause/proceed MCC for ROC and HW scan
    (bsc#1227149).
  - wifi: rtw89: mcc: fix NoA start time when GO is auxiliary
    (bsc#1227149).
  - wifi: rtw89: load TX power related tables from FW elements
    (bsc#1227149).
  - wifi: rtw89: phy: extend TX power common stuffs for Wi-Fi 7
    chips (bsc#1227149).
  - wifi: rtw89: load TX power by rate when RFE parms setup
    (bsc#1227149).
  - wifi: rtw89: phy: refine helpers used for raw TX power
    (bsc#1227149).
  - commit 62f3f4a
  - wifi: rtw89: indicate TX power by rate table inside RFE
    parameter (bsc#1227149).
  - wifi: rtw89: indicate TX shape table inside RFE parameter
    (bsc#1227149).
  - wifi: rtw89: add subband index of primary channel to struct
    rtw89_chan (bsc#1227149).
  - wifi: rtl8xxxu: Add a description about the device ID
    0x7392:0xb722 (bsc#1227149).
  - wifi: rtw89: add mac_gen pointer to access mac port registers
    (bsc#1227149).
  - wifi: rtw89: consolidate registers of mac port to struct
    (bsc#1227149).
  - wifi: rtw89: add chip_info::txwd_info size to generalize TX
    WD submit (bsc#1227149).
  - wifi: rtw89: add to fill TX descriptor v2 (bsc#1227149).
  - wifi: rtw89: add to fill TX descriptor for firmware command v2
    (bsc#1227149).
  - wifi: rtw89: add to query RX descriptor format v2 (bsc#1227149).
  - wifi: rtw89: mcc: deal with beacon NoA if GO exists
    (bsc#1227149).
  - wifi: rtw89: mcc: deal with BT slot change (bsc#1227149).
  - wifi: rtw89: mcc: deal with P2P PS change (bsc#1227149).
  - wifi: rtw89: mcc: track beacon offset and update when needed
    (bsc#1227149).
  - wifi: rtw89: mcc: update role bitmap when changed (bsc#1227149).
  - wifi: rtw89: 52c: rfk: disable DPK during MCC (bsc#1227149).
  - wifi: rtw89: rfk: disable driver tracking during MCC
    (bsc#1227149).
  - wifi: rtw89: 52c: rfk: refine MCC channel info notification
    (bsc#1227149).
  - wifi: rtw89: 8922a: set memory heap address for secure firmware
    (bsc#1227149).
  - wifi: rtw89: fw: refine download flow to support variant
    firmware suits (bsc#1227149).
  - wifi: rtw89: 8922a: add chip_ops::bb_preinit to enable BB
    before downloading firmware (bsc#1227149).
  - wifi: rtw89: fw: propagate an argument include_bb for BB MCU
    firmware (bsc#1227149).
  - wifi: rtw89: fw: add checking type for variant type of firmware
    (bsc#1227149).
  - wifi: rtw89: fw: implement supported functions of download
    firmware for WiFi 7 chips (bsc#1227149).
  - wifi: rtw89: fw: generalize download firmware flow by mac_gen
    pointers (bsc#1227149).
  - wifi: rtw89: fw: move polling function of firmware path ready
    to an individual function (bsc#1227149).
  - wifi: rtw89: mcc: trigger FW to start/stop MCC (bsc#1227149).
  - wifi: rtw89: fix typo of rtw89_fw_h2c_mcc_macid_bitmap()
    (bsc#1227149).
  - wifi: rtw89: mcc: decide pattern and calculate parameters
    (bsc#1227149).
  - wifi: rtw89: mcc: consider and determine BT duration
    (bsc#1227149).
  - commit bd46e4d
  - wifi: rtw89: mcc: fill fundamental configurations (bsc#1227149).
  - wifi: rtw89: mcc: initialize start flow (bsc#1227149).
  - wifi: rtw89: 8852c: Fix TSSI causes transmit power inaccuracy
    (bsc#1227149).
  - wifi: rtw89: 8852c: Update bandedge parameters for better
    performance (bsc#1227149).
  - wifi: rtl8xxxu: mark TOTOLINK N150UA V5/N150UA-B as tested
    (bsc#1227149).
  - wifi: rtw88: fix typo rtw8822cu_probe (bsc#1227149).
  - wifi: rtlwifi: rtl8723: Remove unused function
    rtl8723_cmd_send_packet() (bsc#1227149).
  - wifi: rtw89: Fix clang -Wimplicit-fallthrough in
    rtw89_query_sar() (bsc#1227149).
  - wifi: rtw89: phy: modify register setting of ENV_MNTR, PHYSTS
    and DIG (bsc#1227149).
  - wifi: rtw89: phy: add phy_gen_def::cr_base to support WiFi 7
    chips (bsc#1227149).
  - wifi: rtw89: mac: define register address of rx_filter to
    generalize code (bsc#1227149).
  - wifi: rtw89: mac: define internal memory address for WiFi 7 chip
    (bsc#1227149).
  - wifi: rtw89: mac: generalize code to indirectly access WiFi
    internal memory (bsc#1227149).
  - wifi: rtw89: mac: add mac_gen_def::band1_offset to map MAC
    band1 register address (bsc#1227149).
  - wifi: rtw89: initialize multi-channel handling (bsc#1227149).
  - wifi: rtw89: provide functions to configure NoA for beacon
    update (bsc#1227149).
  - wifi: rtw89: call rtw89_chan_get() by vif chanctx if aware of
    vif (bsc#1227149).
  - wifi: rtw89: sar: let caller decide the center frequency to
    query (bsc#1227149).
  - wifi: rtw89: refine rtw89_correct_cck_chan() by
    rtw89_hw_to_nl80211_band() (bsc#1227149).
  - wifi: rtw89: add function prototype for coex request duration
    (bsc#1227149).
  - wifi: rtw89: regd: update regulatory map to R64-R43
    (bsc#1227149).
  - wifi: rtw89: fix a width vs precision bug (bsc#1227149).
  - wifi: rtlwifi: use eth_broadcast_addr() to assign broadcast
    address (bsc#1227149).
  - wifi: rtw89: Introduce Time Averaged SAR (TAS) feature
    (bsc#1227149).
  - wifi: rtw89: return failure if needed firmware elements are
    not recognized (bsc#1227149).
  - wifi: rtw89: add to parse firmware elements of BB and RF tables
    (bsc#1227149).
  - wifi: rtw89: introduce infrastructure of firmware elements
    (bsc#1227149).
  - wifi: rtw89: add firmware suit for BB MCU 0/1 (bsc#1227149).
  - wifi: rtw89: add firmware parser for v1 format (bsc#1227149).
  - wifi: rtw89: introduce v1 format of firmware header
    (bsc#1227149).
  - wifi: rtw89: support firmware log with formatted text
    (bsc#1227149).
  - wifi: rtw89: recognize log format from firmware file
    (bsc#1227149).
  - wifi: rtw89: get data rate mode/NSS/MCS v1 from RX descriptor
    (bsc#1227149).
  - wifi: rtw89: add to display hardware rates v1 histogram in
    debugfs (bsc#1227149).
  - wifi: rtw89: add C2H RA event V1 to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: use struct to access RA report (bsc#1227149).
  - wifi: rtw89: use struct to access firmware C2H event header
    (bsc#1227149).
  - wifi: rtw89: add H2C RA command V1 to support WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: use struct to set RA H2C command (bsc#1227149).
  - wifi: rtw89: phy: rate pattern handles HW rate by chip gen
    (bsc#1227149).
  - commit cdaa97d
  - wifi: rtlwifi: simplify LED management (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-simplify-non-chanctx-drivers.patch.
  - commit 34b32c5
  - wifi: rtw89: define hardware rate v1 for WiFi 7 chips
    (bsc#1227149).
  - wifi: rtw89: add chip_info::chip_gen to determine chip
    generation (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8723BU (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8192EU (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8710BU (RTL8188GU)
    (bsc#1227149).
  - wifi: rtl8xxxu: Enable AP mode for RTL8192FU (bsc#1227149).
  - wifi: rtw88: simplify vif iterators (bsc#1227149).
  - wifi: rtw88: remove unused USB bulkout size set (bsc#1227149).
  - wifi: rtw88: remove unused and set but unused leftovers
    (bsc#1227149).
  - wifi: rtlwifi: cleanup USB interface (bsc#1227149).
  - wifi: rtw89: use struct to parse firmware header (bsc#1227149).
  - wifi: rtw89: TX power stuffs replace confusing naming of _max
    with _num (bsc#1227149).
  - wifi: rtw89: 8851b: configure to force 1 TX power value
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: update IQK to version 0x8
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add LCK track (bsc#1227149).
  - wifi: rtw89: 8851b: update TX power tables to R28 (bsc#1227149).
  - wifi: rtw89: 8851b: update RF radio A parameters to R28
    (bsc#1227149).
  - wifi: rtw88: fix not entering PS mode after AP stops
    (bsc#1227149).
  - wifi: rtw88: refine register based H2C command (bsc#1227149).
  - wifi: rtw88: Stop high queue during scan (bsc#1227149).
  - wifi: rtw88: Skip high queue in hci_flush (bsc#1227149).
  - wifi: rtw88: Fix AP mode incorrect DTIM behavior (bsc#1227149).
  - wifi: rtw88: use struct instead of macros to set TX desc
    (bsc#1227149).
  - wifi: rtw88: process VO packets without workqueue to avoid
    PTK rekey failed (bsc#1227149).
  - wifi: rtw88: Fix action frame transmission fail before
    association (bsc#1227149).
  - wifi: rtw89: fix spelling typo of IQK debug messages
    (bsc#1227149).
  - wifi: rtw89: cleanup rtw89_iqk_info and related code
    (bsc#1227149).
  - wifi: rtw89: cleanup private data structures (bsc#1227149).
  - wifi: rtw88: add missing unwind goto for
    __rtw_download_firmware() (bsc#1227149).
  - commit 9b282ce
  - wifi: rtlwifi: remove misused flag from HAL data (bsc#1227149).
  - wifi: rtlwifi: remove unused dualmac control leftovers
    (bsc#1227149).
  - wifi: rtlwifi: remove unused timer and related code
    (bsc#1227149).
  - wifi: rtw89: 8852c: update RF radio A/B parameters to R63
    (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R63 with 6 GHz
    power type (3 of 3) (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R63 with 6 GHz
    power type (2 of 3) (bsc#1227149).
  - wifi: rtw89: 8852c: update TX power tables to R63 with 6 GHz
    power type (1 of 3) (bsc#1227149).
  - wifi: rtw89: process regulatory for 6 GHz power type
    (bsc#1227149).
  - wifi: rtw89: regd: update regulatory map to R64-R40
    (bsc#1227149).
  - wifi: rtw89: regd: judge 6 GHz according to chip and BIOS
    (bsc#1227149).
  - commit f81b870
  - wifi: rtw89: refine clearing supported bands to check 2/5 GHz
    first (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-annotate-iftype_data-pointer-with-spar.patch.
  - commit 1873f0a
  - wifi: rtw89: 8851b: configure CRASH_TRIGGER feature for 8851B
    (bsc#1227149).
  - wifi: rtw89: set TX power without precondition during setting
    channel (bsc#1227149).
  - wifi: rtw89: debug: txpwr table access only valid page according
    to chip (bsc#1227149).
  - wifi: rtw89: 8851b: enable hw_scan support (bsc#1227149).
  - wifi: rtlwifi: use helper function rtl_get_hdr() (bsc#1227149).
  - wifi: rtw89: use flexible array member in rtw89_btc_btf_tlv
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: Fix spelling mistake KIP_RESOTRE ->
    KIP_RESTORE (bsc#1227149).
  - wifi: rtw89: use struct to access register-based H2C/C2H
    (bsc#1227149).
  - wifi: rtw89: use struct and le32_get_bits() to access RX
    descriptor (bsc#1227149).
  - commit 21eb4e8
  - Update config files: update for the realtek wifi driver updates (bsc#1227149)
  - commit 33b8d09
  - wifi: rtw89: use struct and le32_get_bits() to access received
    PHY status IEs (bsc#1227149).
  - wifi: rtw89: use struct and le32_get_bits to access RX info
    (bsc#1227149).
  - wifi: rtw89: add chip_ops::query_rxdesc() and rxd_len as
    helpers to support newer chips (bsc#1227149).
  - wifi: rtw89: 8851b: add 8851be to Makefile and Kconfig
    (bsc#1227149).
  - wifi: rtw89: add tx_wake notify for 8851B (bsc#1227149).
  - wifi: rtw89: enlarge supported length of read_reg debugfs entry
    (bsc#1227149).
  - wifi: rtw89: 8851b: add RF configurations (bsc#1227149).
  - wifi: rtw89: 8851b: add MAC configurations to chip_info
    (bsc#1227149).
  - wifi: rtw89: 8851b: fill BB related capabilities to chip_info
    (bsc#1227149).
  - wifi: rtw89: 8851b: add TX power related functions
    (bsc#1227149).
  - commit 66eef0c
  - Update config files: update for the realtek wifi driver updates (bsc#1227149)
  - commit 75bc634
  - wifi: rtw89: refine packet offload handling under SER
    (bsc#1227149).
  - wifi: rtw89: tweak H2C TX waiting function for SER
    (bsc#1227149).
  - wifi: rtw89: ser: reset total_sta_assoc and tdls_peer when L2
    (bsc#1227149).
  - wifi: rtw88: Add support for the SDIO based RTL8723DS chipset
    (bsc#1227149).
  - wifi: rtw88: rtw8723d: Implement RTL8723DS (SDIO) efuse parsing
    (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add TSSI (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add DPK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add RX DCK (bsc#1227149).
  - wifi: rtw89: 8851b: add to parse efuse content (bsc#1227149).
  - wifi: rtw89: 8851b: add set channel function (bsc#1227149).
  - wifi: rtw89: 8851b: add basic power on function (bsc#1227149).
  - wifi: rtw89: 8851b: add BT coexistence support function
    (bsc#1227149).
  - wifi: rtw89: 8851b: configure GPIO according to RFE type
    (bsc#1227149).
  - wifi: rtw89: 8851b: add to read efuse version to recognize
    hardware version B (bsc#1227149).
  - wifi: rtl8xxxu: Rename some registers (bsc#1227149).
  - wifi: rtl8xxxu: Support new chip RTL8192FU (bsc#1227149).
  - wifi: rtw89: suppress the log for specific SER called
    CMDPSR_FRZTO (bsc#1227149).
  - wifi: rtw89: ser: L1 add pre-M0 and post-M0 states
    (bsc#1227149).
  - wifi: rtw89: pci: fix interrupt enable mask for HALT C2H of
    RTL8851B (bsc#1227149).
  - wifi: rtw89: support U-NII-4 channels on 5GHz band
    (bsc#1227149).
  - wifi: rtw89: regd: judge UNII-4 according to BIOS and chip
    (bsc#1227149).
  - wifi: rtw89: introduce realtek ACPI DSM method (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add IQK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add DACK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add RCK (bsc#1227149).
  - wifi: rtw89: 8851b: rfk: add AACK (bsc#1227149).
  - wifi: rtw89: 8851b: add set_channel_rf() (bsc#1227149).
  - wifi: rtw89: 8851b: add DLE mem and HFC quota (bsc#1227149).
  - wifi: rtw89: 8851b: add support WoWLAN to 8851B (bsc#1227149).
  - wifi: rtw89: change naming of BA CAM from V1 to V0_EXT
    (bsc#1227149).
  - commit a1de2dd
  - wifi: rtw89: use chip_info::small_fifo_size to choose debug_mask
    (bsc#1227149).
  - wifi: rtw89: add CFO XTAL registers field to support 8851B
    (bsc#1227149).
  - wifi: rtw89: 8851b: add NCTL post table (bsc#1227149).
  - wifi: rtw89: 8851be: add 8851BE PCI entry and fill PCI
    capabilities (bsc#1227149).
  - wifi: rtw89: 8851b: add 8851B basic chip_info (bsc#1227149).
  - wifi: rtw89: scan offload wait for FW done ACK (bsc#1227149).
  - wifi: rtw89: mac: handle C2H receive/done ACK in interrupt
    context (bsc#1227149).
  - wifi: rtw89: packet offload wait for FW response (bsc#1227149).
  - wifi: rtw89: refine packet offload delete flow of 6 GHz probe
    (bsc#1227149).
  - wifi: rtw89: release bit in rtw89_fw_h2c_del_pkt_offload()
    (bsc#1227149).
  - wifi: rtw89: add EVM for antenna diversity (bsc#1227149).
  - wifi: rtw89: add RSSI based antenna diversity (bsc#1227149).
  - wifi: rtw89: initialize antenna for antenna diversity
    (bsc#1227149).
  - wifi: rtw89: add EVM and SNR statistics to debugfs
    (bsc#1227149).
  - wifi: rtw89: add RSSI statistics for the case of antenna
    diversity to debugfs (bsc#1227149).
  - wifi: rtw89: set capability of TX antenna diversity
    (bsc#1227149).
  - wifi: rtw89: use struct rtw89_phy_sts_ie0 instead of macro to
    access PHY IE0 status (bsc#1227149).
  - wifi: rtw88: fix incorrect error codes in rtw_debugfs_set_*
    (bsc#1227149).
  - wifi: rtw88: fix incorrect error codes in
    rtw_debugfs_copy_from_user (bsc#1227149).
  - wifi: rtl8xxxu: rtl8xxxu_rx_complete(): remove unnecessary
    return (bsc#1227149).
  - commit fef25cd
  - wifi: rtl8xxxu: Add sta_add() and sta_remove() callbacks
    (bsc#1227149).
  - commit a27e0ec
  - wifi: rtl8xxxu: Support USB RX aggregation for the newer chips
    (bsc#1227149).
  - wifi: rtl8xxxu: Set maximum number of supported stations
    (bsc#1227149).
  - wifi: rtl8xxxu: Declare AP mode support for 8188f (bsc#1227149).
  - wifi: rtl8xxxu: Remove usage of tx_info->control.rates[0].flags
    (bsc#1227149).
  - wifi: rtl8xxxu: Remove usage of ieee80211_get_tx_rate()
    (bsc#1227149).
  - wifi: rtl8xxxu: Clean up filter configuration (bsc#1227149).
  - wifi: rtl8xxxu: Enable hw seq for mgmt/non-QoS data frames
    (bsc#1227149).
  - wifi: rtl8xxxu: Add parameter macid to update_rate_mask
    (bsc#1227149).
  - wifi: rtl8xxxu: Put the macid in txdesc (bsc#1227149).
  - commit 6125130
  - wifi: radiotap: add bandwidth definition of EHT U-SIG
    (bsc#1227149).
  - wifi: ieee80211: add UL-bandwidth definition of trigger frame
    (bsc#1227149).
  - wifi: rtl8xxxu: Add parameter force to
    rtl8xxxu_refresh_rate_mask (bsc#1227149).
  - wifi: rtl8xxxu: Add parameter role to report_connect
    (bsc#1227149).
  - wifi: rtl8xxxu: Actually use macid in
    rtl8xxxu_gen2_report_connect (bsc#1227149).
  - wifi: rtl8xxxu: Allow creating interface in AP mode
    (bsc#1227149).
  - wifi: rtl8xxxu: Allow setting rts threshold to -1 (bsc#1227149).
  - wifi: rtl8xxxu: Add set_tim() callback (bsc#1227149).
  - wifi: rtl8xxxu: Add beacon functions (bsc#1227149).
  - wifi: rtl8xxxu: Select correct queue for beacon frames
    (bsc#1227149).
  - wifi: rtl8xxxu: Add start_ap() callback (bsc#1227149).
  - commit 02b75ed
  - wifi: iwlwifi: bump FW API to 90 for BZ/SC devices (bsc#1227149
    CVE-2023-47210 bsc#1225601 CVE-2023-38417 bsc#1225600).
  - commit ea4853c
  - wifi: iwlwifi: bump FW API to 89 for AX/BZ/SC devices
    (bsc#1227149 CVE-2023-47210 bsc#1225601 CVE-2023-38417
    bsc#1225600).
  - commit bc49209
  - ASoC: SOF: Intel: hda-pcm: Limit the maximum number of periods
    by MAX_BDL_ENTRIES (stable-fixes).
  - ASoC: rt711-sdw: add missing readable registers (stable-fixes).
  - ALSA: hda/realtek: Enable Mute LED on HP 250 G7 (stable-fixes).
  - ALSA: hda/realtek: Limit mic boost on VAIO PRO PX
    (stable-fixes).
  - ALSA: hda/realtek: add quirk for Clevo V5[46]0TU (stable-fixes).
  - commit 1ddd32b
  - hpet: Support 32-bit userspace (git-fixes).
  - misc: fastrpc: Restrict untrusted app to attach to privileged PD
    (git-fixes).
  - misc: fastrpc: Fix ownership reassignment of remote heap
    (git-fixes).
  - misc: fastrpc: Fix memory leak in audio daemon attach operation
    (git-fixes).
  - misc: fastrpc: Avoid updating PD type for capability request
    (git-fixes).
  - misc: fastrpc: Copy the complete capability structure to user
    (git-fixes).
  - misc: fastrpc: Fix DSP capabilities request (git-fixes).
  - USB: serial: mos7840: fix crash on resume (git-fixes).
  - USB: core: Fix duplicate endpoint bug by clearing reserved
    bits in the descriptor (git-fixes).
  - firmware: cs_dsp: Use strnlen() on name fields in V1 wmfw files
    (git-fixes).
  - ASoC: SOF: Intel: hda: fix null deref on system suspend entry
    (git-fixes).
  - firmware: cs_dsp: Prevent buffer overrun when processing V2
    alg headers (git-fixes).
  - firmware: cs_dsp: Validate payload length before processing
    block (git-fixes).
  - firmware: cs_dsp: Return error if block header overflows file
    (git-fixes).
  - firmware: cs_dsp: Fix overflow checking of wmfw header
    (git-fixes).
  - ALSA: hda: cs35l41: Fix swapped l/r audio channels for Lenovo
    ThinBook 13x Gen4 (git-fixes).
  - commit 34ebce1

++++ ucode-amd:

  - Update to version 20240712 (git commit ed874ed83cac):
    (bsc#1229069, CVE-2023-31315)
    * amdgpu: update DMCUB to v0.0.225.0 for Various AMDGPU Asics
    * qcom: add gpu firmwares for x1e80100 chipset (bsc#1219458)
    * linux-firmware: add firmware for qat_402xx devices
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update PSP 13.0.8 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VPE 6.1.1 firmware
    * amdgpu: update VCN 4.0.6 firmware
    * amdgpu: update SDMA 6.1.1 firmware
    * amdgpu: update PSP 14.0.1 firmware
    * amdgpu: update GC 11.5.1 firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update SDMA 6.1.0 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SMU 13.0.7 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update aldebaran firmware
    * linux-firmware: Update AMD cpu microcode
    * linux-firmware: Add ISH firmware file for Intel Lunar Lake platform
    * amdgpu: update DMCUB to v0.0.224.0 for Various AMDGPU Asics
    * cirrus: cs35l41: Update various firmware for ASUS laptops using CS35L41
    * amdgpu: Update ISP FW for isp v4.1.1

------------------------------------------------------------------
------------------  2024-7-12  -  Jul 12 2024  -------------------
------------------------------------------------------------------

++++ combustion:

  - Switch _service to use mode="manual"
  - Update to version 1.3+git11:
    * 30firstboot: Leave IPL DASD enablement to s390-tools (jsc#PED-8130)
    * Wait for tee to finish in example scripts (bsc#1222411)

++++ cryptsetup:

  - License: Replace legacy 'AND SUSE-GPL-2.0-with-openssl-exception' with
    'WITH cryptsetup-OpenSSL-exception' (the official SPDX exception).

++++ python-kiwi:

  - Fix mocking of test_process_result_bundle_as_rpm
  - Fixed logging behavior of Compress::get_format
    The get_format() method allows to check which compression format
    a given input stream has. This is done by calling the supported
    compression tools in a row and let them check if they can deal
    with the provided data or not. As a result error messages are
    logged for streams that some tool doesn't understand. However,
    those error messages are no errors and only the result of the
    checking. This information in the kiwi log file is confusing
    and several users already complained when they see information
    like:
    EXEC: Failed with stderr: /usr/bin/xz: ...: File format not recognized
    This commit changes how the compression tooling is called in a
    way that no exception is raised (which leads to the above error message)
    but the result returncode is used to decide on the success or
    error of the respective compression tooling.
  - Allow to set custom ISO Application ID
    Add new <type ... application_id="..."/> attribute to be set in
    the ISO header main block. The application ID was used as identifier
    in the legacy initrd code from former kiwi versions. Because of
    this there is still the compat layer which sets an App ID as MBR
    identifier string unless the new application_id overwrites it.
    This Fixes #1810
  - Bump version: 10.0.23 → 10.0.24

++++ librsvg:

  - Update to version 2.58.2:
    + Don't leak XML entities when the XML document fails to parse.
    + Fix stack overflow in <use> reference cycle.

++++ kernel-default:

  - net/smc: avoid data corruption caused by decline (bsc#1225088
    CVE-2023-52775).
  - commit 621e8ca
  - net: openvswitch: fix overwriting ct original tuple for  ICMPv6
    (bsc#1226783 CVE-2024-38558).
  - commit 748cf39
  - ipv6: sr: fix missing sk_buff release in seg6_input_core
    (bsc#1227626 CVE-2024-39490).
  - commit 3d59f52
  - mptcp: fix data re-injection from stale subflow (bsc#1223010
    CVE-2024-26826).
  - commit f3a102e
  - net/smc: fix illegal rmb_desc access in SMC-D connection dump
    (bsc#1220942 CVE-2024-26615).
  - commit f21afb0
  - kabi/severities: cover all ath/* drivers (bsc#1227149)
    All symbols in ath/* network drivers are local and can be ignored
  - commit d902566
  - Refresh kabi workaround ath updates (bsc#1227149#)
  - commit b0fa38b
  - wifi: mac80211: simplify non-chanctx drivers (bsc#1227149).
  - commit eeb4722
  - wifi: ath11k: move power type check to ASSOC stage when
    connecting to 6 GHz AP (bsc#1227149).
  - wifi: ath11k: fix WCN6750 firmware crash caused by 17 num_vdevs
    (bsc#1227149).
  - wifi: ath12k: fix the problem that down grade phy mode operation
    (bsc#1227149).
  - wifi: ath12k: check M3 buffer size as well whey trying to
    reuse it (bsc#1227149).
  - wifi: ath12k: fix kernel crash during resume (bsc#1227149).
  - wifi: ath9k: work around memset overflow warning (bsc#1227149).
  - wifi: ath12k: use correct flag field for 320 MHz channels
    (bsc#1227149).
  - commit 58db5ff
  - wifi: ath11k: use RCU when accessing struct inet6_dev::ac_list
    (bsc#1227149).
  - wifi: ath12k: fix license in p2p.c and p2p.h (bsc#1227149).
  - wifi: ath11k: constify MHI channel and controller configs
    (bsc#1227149).
  - wifi: ath12k: add rcu lock for ath12k_wmi_p2p_noa_event()
    (bsc#1227149).
  - wifi: ath11k: remove unused scan_events from struct
    scan_req_params (bsc#1227149).
  - wifi: ath11k: add support for QCA2066 (bsc#1227149).
  - wifi: ath11k: move pci.ops registration ahead (bsc#1227149).
  - commit 29f553c
  - wifi: ath11k: provide address list if chip supports 2 stations
    (bsc#1227149).
  - wifi: ath11k: support 2 station interfaces (bsc#1227149).
  - wifi: ath12k: remove the unused scan_events from
    ath12k_wmi_scan_req_arg (bsc#1227149).
  - wifi: ath12k: Remove unused scan_flags from struct
    ath12k_wmi_scan_req_arg (bsc#1227149).
  - wifi: ath12k: Do not use scan_flags from struct
    ath12k_wmi_scan_req_arg (bsc#1227149).
  - wifi: carl9170: Remove redundant assignment to pointer super
    (bsc#1227149).
  - wifi: ath11k: Remove scan_flags union from struct
    scan_req_params (bsc#1227149).
  - wifi: ath11k: Do not directly use scan_flags in struct
    scan_req_params (bsc#1227149).
  - wifi: ath12k: Fix uninitialized use of ret in
    ath12k_mac_allocate() (bsc#1227149).
  - wifi: ath11k: Really consistently use ath11k_vif_to_arvif()
    (bsc#1227149).
  - wifi: ath12k: advertise P2P dev support for WCN7850
    (bsc#1227149).
  - wifi: ath12k: designating channel frequency for ROC scan
    (bsc#1227149).
  - wifi: ath12k: move peer delete after vdev stop of station for
    WCN7850 (bsc#1227149).
  - wifi: ath12k: allow specific mgmt frame tx while vdev is not up
    (bsc#1227149).
  - wifi: ath12k: change WLAN_SCAN_PARAMS_MAX_IE_LEN from 256 to
    512 (bsc#1227149).
  - wifi: ath12k: implement remain on channel for P2P mode
    (bsc#1227149).
  - wifi: ath12k: implement handling of P2P NoA event (bsc#1227149).
  - wifi: ath12k: add P2P IE in beacon template (bsc#1227149).
  - wifi: ath12k: change interface combination for P2P mode
    (bsc#1227149).
  - wifi: ath12k: fix broken structure wmi_vdev_create_cmd
    (bsc#1227149).
  - commit 21d36c7
  - wifi: ath11k: initialize eirp_power before use (bsc#1227149).
  - wifi: ath12k: enable 802.11 power save mode in station mode
    (bsc#1227149).
  - wifi: ath12k: refactor the rfkill worker (bsc#1227149).
  - wifi: ath12k: add processing for TWT disable event
    (bsc#1227149).
  - wifi: ath12k: add processing for TWT enable event (bsc#1227149).
  - wifi: ath12k: disable QMI PHY capability learn in split-phy
    QCN9274 (bsc#1227149).
  - wifi: ath12k: Read board id to support split-PHY QCN9274
    (bsc#1227149).
  - wifi: ath12k: fix PCI read and write (bsc#1227149).
  - wifi: ath12k: add MAC id support in WBM error path
    (bsc#1227149).
  - wifi: ath12k: subscribe required word mask from rx tlv
    (bsc#1227149).
  - commit c884365
  - wifi: ath12k: remove hal_desc_sz from hw params (bsc#1227149).
  - wifi: ath12k: split hal_ops to support RX TLVs word mask
    compaction (bsc#1227149).
  - wifi: ath12k: fix firmware assert during insmod in memory
    segment mode (bsc#1227149).
  - wifi: ath12k: Add logic to write QRTR node id to scratch
    (bsc#1227149).
  - wifi: ath12k: fix fetching MCBC flag for QCN9274 (bsc#1227149).
  - wifi: ath12k: add support for peer meta data version
    (bsc#1227149).
  - wifi: ath12k: fetch correct pdev id from
    WMI_SERVICE_READY_EXT_EVENTID (bsc#1227149).
  - wifi: ath12k: indicate NON MBSSID vdev by default during vdev
    start (bsc#1227149).
  - wifi: ath12k: add firmware-2.bin support (bsc#1227149).
  - wifi: ath9k:  remove redundant assignment to variable ret
    (bsc#1227149).
  - commit 777dc1c
  - wifi: ath11k: fix connection failure due to unexpected peer
    delete (bsc#1227149).
  - wifi: ath11k: avoid forward declaration of
    ath11k_mac_start_vdev_delay() (bsc#1227149).
  - wifi: ath11k: rename ath11k_start_vdev_delay() (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wcn36xx (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for ar5523 (bsc#1227149).
  - commit d2a4b44
  - wifi: ath11k: remove invalid peer create logic (bsc#1227149).
  - wifi: ath11k: enable 36 bit mask for stream DMA (bsc#1227149).
  - wifi: ath10k: Fix enum ath10k_fw_crash_dump_type kernel-doc
    (bsc#1227149).
  - wifi: ath10k: Fix htt_data_tx_completion kernel-doc warning
    (bsc#1227149).
  - wifi: ath10k: fix htt_q_state_conf & htt_q_state kernel-doc
    (bsc#1227149).
  - wifi: ath10k: correctly document enum wmi_tlv_tx_pause_id
    (bsc#1227149).
  - wifi: ath10k: add missing wmi_10_4_feature_mask documentation
    (bsc#1227149).
  - wifi: ath12k: add support for collecting firmware log
    (bsc#1227149).
  - wifi: ath12k: Introduce the container for mac80211 hw
    (bsc#1227149).
  - wifi: ath12k: Refactor the mac80211 hw access from link/radio
    (bsc#1227149).
  - commit 614fabb
  - iommu/vt-d: Improve ITE fault handling if target device isn't
    present (git-fixes).
  - commit 134a3a5
  - wifi: ath12k: change MAC buffer ring size to 2048 (bsc#1227149).
  - wifi: ath12k: add support for BA1024 (bsc#1227149).
  - wifi: ath12k: fix wrong definitions of hal_reo_update_rx_queue
    (bsc#1227149).
  - wifi: ath10k: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: ath11k: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: ath12k: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: ath12k: add QMI PHY capability learn support
    (bsc#1227149).
  - wifi: ath12k: refactor QMI MLO host capability helper function
    (bsc#1227149).
  - wifi: ath11k: document HAL_RX_BUF_RBM_SW4_BM (bsc#1227149).
  - wifi: ath12k: ath12k_start_vdev_delay(): convert to use ar
    (bsc#1227149).
  - commit dd312dc
  - wifi: ath12k: refactor ath12k_mac_op_flush() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_ampdu_action()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_configure_filter()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_update_vif_offload()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_stop() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_start() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_conf_tx() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_bss_assoc() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_config() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_register() and
    ath12k_mac_unregister() (bsc#1227149).
  - commit b6ca728
  - wifi: ath12k: refactor ath12k_mac_setup_channels_rates()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_allocate() and
    ath12k_mac_destroy() (bsc#1227149).
  - wifi: ath12k: relocate ath12k_dp_pdev_pre_alloc() call
    (bsc#1227149).
  - wifi: ath12k: Use initializers for QMI message buffers
    (bsc#1227149).
  - wifi: ath12k: Add missing qmi_txn_cancel() calls (bsc#1227149).
  - wifi: ath12k: Remove unnecessary struct qmi_txn initializers
    (bsc#1227149).
  - wifi: ath11k: use WMI_VDEV_SET_TPC_POWER_CMDID when
    EXT_TPC_REG_SUPPORT for 6 GHz (bsc#1227149).
  - wifi: ath11k: add handler for WMI_VDEV_SET_TPC_POWER_CMDID
    (bsc#1227149).
  - wifi: ath11k: add WMI_TLV_SERVICE_EXT_TPC_REG_SUPPORT service
    bit (bsc#1227149).
  - wifi: ath11k: fill parameters for vdev set tpc power WMI command
    (bsc#1227149).
  - commit 3c338b0
  - wifi: ath11k: save max transmit power in vdev start response
    event from firmware (bsc#1227149).
  - commit 279ae7a
  - wifi: ath11k: add parse of transmit power envelope element
    (bsc#1227149).
  - commit e295f89
  - wifi: ath11k: save power spectral density(PSD) of regulatory
    rule (bsc#1227149).
  - wifi: ath11k: update regulatory rules when connect to AP on
    6 GHz band for station (bsc#1227149).
  - wifi: ath11k: update regulatory rules when interface added
    (bsc#1227149).
  - wifi: ath11k: fix a possible dead lock caused by ab->base_lock
    (bsc#1227149).
  - wifi: ath11k: store cur_regulatory_info for each radio
    (bsc#1227149).
  - wifi: ath11k: add support to select 6 GHz regulatory type
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_wmi_tlv_parse_alloc()
    (bsc#1227149).
  - wifi: ath11k: fix IOMMU errors on buffer rings (bsc#1227149).
  - commit d84dbd2
  - wifi: ath12k: Make QMI message rules const (bsc#1227149).
  - wifi: ath12k: support default regdb while searching board-2.bin
    for WCN7850 (bsc#1227149).
  - wifi: ath12k: add support to search regdb data in board-2.bin
    for WCN7850 (bsc#1227149).
  - wifi: ath12k: remove unused ATH12K_BD_IE_BOARD_EXT
    (bsc#1227149).
  - wifi: ath12k: add fallback board name without variant while
    searching board-2.bin (bsc#1227149).
  - wifi: ath12k: add string type to search board data in
    board-2.bin for WCN7850 (bsc#1227149).
  - wifi: ath10k: remove duplicate memset() in 10.4 TDLS peer update
    (bsc#1227149).
  - wifi: ath10k: use flexible array in struct
    wmi_tdls_peer_capabilities (bsc#1227149).
  - wifi: ath10k: remove unused template structs (bsc#1227149).
  - wifi: ath10k: remove struct wmi_pdev_chanlist_update_event
    (bsc#1227149).
  - commit e73f8dc
  - wifi: ath10k: use flexible arrays for WMI start scan TLVs
    (bsc#1227149).
  - wifi: ath10k: use flexible array in struct wmi_host_mem_chunks
    (bsc#1227149).
  - wifi: ath9k: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: ath9k: delete some unused/duplicate macros (bsc#1227149).
  - wifi: ath11k: refactor ath11k_wmi_tlv_parse_alloc()
    (bsc#1227149).
  - wifi: ath11k: rely on mac80211 debugfs handling for vif
    (bsc#1227149).
  - wifi: ath11k: workaround too long expansion sparse warnings
    (bsc#1227149).
  - Revert "wifi: ath12k: use ATH12K_PCI_IRQ_DP_OFFSET for DP IRQ"
    (bsc#1227149).
  - wifi: ath9k: reset survey of current channel after a scan
    started (bsc#1227149).
  - wifi: ath12k: fix the issue that the multicast/broadcast
    indicator is not read correctly for WCN7850 (bsc#1227149).
  - commit 6cf204e
  - wifi: ath11k: Fix ath11k_htc_record flexible record
    (bsc#1227149).
  - wifi: ath5k: remove unused ath5k_eeprom_info::ee_antenna
    (bsc#1227149).
  - wifi: ath10k: add support to allow broadcast action frame RX
    (bsc#1227149).
  - wifi: ath12k: avoid repeated wiphy access from hw (bsc#1227149).
  - wifi: ath12k: set IRQ affinity to CPU0 in case of one MSI vector
    (bsc#1227149).
  - wifi: ath12k: do not restore ASPM in case of single MSI vector
    (bsc#1227149).
  - wifi: ath12k: add support one MSI vector (bsc#1227149).
  - wifi: ath12k: refactor multiple MSI vector implementation
    (bsc#1227149).
  - wifi: ath12k: use ATH12K_PCI_IRQ_DP_OFFSET for DP IRQ
    (bsc#1227149).
  - wifi: ath12k: add CE and ext IRQ flag to indicate irq_handler
    (bsc#1227149).
  - commit 908caeb
  - wifi: ath12k: get msi_data again after request_irq is called
    (bsc#1227149).
  - wifi: wcn36xx: Convert to platform remove callback returning
    void (bsc#1227149).
  - wifi: ath5k: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: ath12k: avoid repeated hw access from ar (bsc#1227149).
  - wifi: ath12k: Optimize the mac80211 hw data access
    (bsc#1227149).
  - wifi: ath12k: add 320 MHz bandwidth enums (bsc#1227149).
  - wifi: ath11k: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: ath11k: remove ath11k_htc_record::pauload[] (bsc#1227149).
  - wifi: ath10k: Use DECLARE_FLEX_ARRAY() for ath10k_htc_record
    (bsc#1227149).
  - wifi: ath10k: remove ath10k_htc_record::pauload[] (bsc#1227149).
  - commit 67bc0a7
  - wifi: ath10k: Update Qualcomm Innovation Center, Inc. copyrights
    (bsc#1227149).
  - commit e13fd24
  - wifi: ath11k: Update Qualcomm Innovation Center, Inc. copyrights
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-do-not-dump-SRNG-statistics-during-resum.patch.
  - Refresh
    patches.suse/wifi-ath11k-fix-warning-on-DMA-ring-capabilities-eve.patch.
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - Refresh
    patches.suse/wifi-ath11k-thermal-don-t-try-to-register-multiple-t.patch.
  - commit a886227
  - wifi: ath9k: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath12k: refactor DP Rxdma ring structure (bsc#1227149).
  - wifi: ath12k: avoid explicit HW conversion argument in Rxdma
    replenish (bsc#1227149).
  - wifi: ath12k: avoid explicit RBM id argument in Rxdma replenish
    (bsc#1227149).
  - wifi: ath12k: avoid explicit mac id argument in Rxdma replenish
    (bsc#1227149).
  - wifi: ath12k: fix the error handler of rfkill config
    (bsc#1227149).
  - wifi: ath12k: use select for CRYPTO_MICHAEL_MIC (bsc#1227149).
  - wifi: ath11k: use select for CRYPTO_MICHAEL_MIC (bsc#1227149).
  - commit a869013
  - wifi: ath12k: Consolidate WMI peer flags (bsc#1227149).
  - wifi: ath11k: Consolidate WMI peer flags (bsc#1227149).
  - wifi: ath12k: Remove obsolete struct wmi_peer_flags_map
    * peer_flags (bsc#1227149).
  - wifi: ath11k: Remove obsolete struct wmi_peer_flags_map
    * peer_flags (bsc#1227149).
  - wifi: ath12k: Remove struct ath12k::ops (bsc#1227149).
  - wifi: ath11k: Remove struct ath11k::ops (bsc#1227149).
  - wifi: ath10k: Remove unused struct ath10k_htc_frame
    (bsc#1227149).
  - wifi: ath10k: simplify __ath10k_htt_tx_txq_recalc()
    (bsc#1227149).
  - wifi: ath11k: Remove unneeded semicolon (bsc#1227149).
  - wifi: ath10k: replace deprecated strncpy with memcpy
    (bsc#1227149).
  - commit e59240f
  - wifi: ath12k: drop NULL pointer check in
    ath12k_update_per_peer_tx_stats() (bsc#1227149).
  - Revert "wifi: ath11k: call ath11k_mac_fils_discovery() without
    condition" (bsc#1227149).
  - wifi: ath12k: Introduce and use ath12k_sta_to_arsta()
    (bsc#1227149).
  - wifi: ath12k: rename the sc naming convention to ab
    (bsc#1227149).
  - wifi: ath12k: rename the wmi_sc naming convention to wmi_ab
    (bsc#1227149).
  - commit f93677e
  - bus: mhi: host: allow MHI client drivers to provide the firmware
    via a pointer (bsc#1227149).
  - commit 494649c
  - wifi: ath11k: add firmware-2.bin support (bsc#1227149).
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - commit 677d325
  - wifi: ath11k: qmi: refactor ath11k_qmi_m3_load() (bsc#1227149).
  - commit 296ac8f
  - wifi: ath11k: rename the sc naming convention to ab
    (bsc#1227149).
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - Refresh
    patches.suse/wifi-ath11k-thermal-don-t-try-to-register-multiple-t.patch.
  - commit 6eedd0d
  - wifi: ath11k: rename the wmi_sc naming convention to wmi_ab
    (bsc#1227149).
  - wifi: ath6kl: replace deprecated strncpy with memcpy
    (bsc#1227149).
  - commit cd59b03
  - wifi: ath5k: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: ath12k: Remove ath12k_base::bd_api (bsc#1227149).
  - wifi: ath11k: Remove ath11k_base::bd_api (bsc#1227149).
  - wifi: ath12k: Enable Mesh support for QCN9274 (bsc#1227149).
  - wifi: ath12k: register EHT mesh capabilities (bsc#1227149).
  - wifi: ath11k: Use device_get_match_data() (bsc#1227149).
  - wifi: ath11k: Introduce and use ath11k_sta_to_arsta()
    (bsc#1227149).
  - wifi: ath11k: Remove unused struct ath11k_htc_frame
    (bsc#1227149).
  - wifi: ath12k: fix invalid m3 buffer address (bsc#1227149).
  - wifi: ath12k: add ath12k_qmi_free_resource() for recovery
    (bsc#1227149).
  - commit a18a8d4
  - wifi: ath12k: configure RDDM size to MHI for device recovery
    (bsc#1227149).
  - wifi: ath12k: add parsing of phy bitmap for reg rules
    (bsc#1227149).
  - wifi: ath11k: add parsing of phy bitmap for reg rules
    (bsc#1227149).
  - wifi: ath11k: ath11k_debugfs_register(): fix format-truncation
    warning (bsc#1227149).
  - wifi: ath12k: Consistently use ath12k_vif_to_arvif()
    (bsc#1227149).
  - wifi: ath11k: call ath11k_mac_fils_discovery() without condition
    (bsc#1227149).
  - wifi: ath12k: remove redundant memset() in
    ath12k_hal_reo_qdesc_setup() (bsc#1227149).
  - wifi: ath9k_htc: fix format-truncation warning (bsc#1227149).
  - wifi: ath12k: fix debug messages (bsc#1227149).
  - wifi: ath11k: fix CAC running state during virtual interface
    start (bsc#1227149).
  - commit c2f2e92
  - wifi: ath10k: simplify ath10k_peer_create() (bsc#1227149).
  - wifi: ath10k: indicate to mac80211 scan complete with aborted
    flag for ATH10K_SCAN_STARTING state (bsc#1227149).
  - wifi: ath: dfs_pattern_detector: Use flex array to simplify code
    (bsc#1227149).
  - wifi: carl9170: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath10k: consistently use kstrtoX_from_user() functions
    (bsc#1227149).
  - wifi: ath12k: add keep backward compatibility of PHY mode to
    avoid firmware crash (bsc#1227149).
  - wifi: ath12k: add read variant from SMBIOS for download board
    data (bsc#1227149).
  - wifi: ath12k: do not drop data frames from unassociated stations
    (bsc#1227149).
  - wifi: ath11k: mac: fix struct ieee80211_sband_iftype_data
    handling (bsc#1227149).
  - wifi: ath11k: fix ath11k_mac_op_remain_on_channel() stack usage
    (bsc#1227149).
  - commit b844022
  - wifi: ath12k: add msdu_end structure for WCN7850 (bsc#1227149).
  - wifi: ath12k: Set default beacon mode to burst mode
    (bsc#1227149).
  - wifi: ath12k: call ath12k_mac_fils_discovery() without condition
    (bsc#1227149).
  - wifi: ath11k: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath12k: enable IEEE80211_HW_SINGLE_SCAN_ON_ALL_BANDS
    for WCN7850 (bsc#1227149).
  - wifi: ath12k: change to treat alpha code na as world wide
    regdomain (bsc#1227149).
  - wifi: ath12k: indicate scan complete for scan canceled when
    scan running (bsc#1227149).
  - wifi: ath12k: indicate to mac80211 scan complete with aborted
    flag for ATH12K_SCAN_STARTING state (bsc#1227149).
  - wifi: ath12k: fix recovery fail while firmware crash when
    doing channel switch (bsc#1227149).
  - wifi: ath12k: add support for hardware rfkill for WCN7850
    (bsc#1227149).
  - commit 087627b
  - wifi: ath11k: use kstrtoul_from_user() where appropriate
    (bsc#1227149).
  - wifi: ath11k: remove unused members of 'struct ath11k_base'
    (bsc#1227149).
  - wifi: ath11k: drop redundant check in
    ath11k_dp_rx_mon_dest_process() (bsc#1227149).
  - wifi: ath11k: drop NULL pointer check in
    ath11k_update_per_peer_tx_stats() (bsc#1227149).
  - wifi: ath10k: drop HTT_DATA_TX_STATUS_DOWNLOAD_FAIL
    (bsc#1227149).
  - wifi: ath10k: Annotate struct ath10k_ce_ring with __counted_by
    (bsc#1227149).
  - wifi: wcn36xx: Annotate struct wcn36xx_hal_ind_msg with
    __counted_by (bsc#1227149).
  - wifi: ath12k: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath10k: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath6kl: remove unnecessary (void*) conversions
    (bsc#1227149).
  - commit 3f20dbc
  - wifi: ath5k: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: wcn36xx: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ar5523: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath9k: clean up function ath9k_hif_usb_resume
    (bsc#1227149).
  - wifi: ath11k: add chip id board name while searching board-2.bin
    for WCN6855 (bsc#1227149).
  - wifi: ath12k: change to initialize recovery variables earlier
    in ath12k_core_reset() (bsc#1227149).
  - wifi: ath12k: enable 320 MHz bandwidth for 6 GHz band in EHT
    PHY capability for WCN7850 (bsc#1227149).
  - wifi: ath9k: use u32 for txgain indexes (bsc#1227149).
  - wifi: ath9k: simplify ar9003_hw_process_ini() (bsc#1227149).
  - wifi: ath12k: fix radar detection in 160 MHz (bsc#1227149).
  - commit 0b35606
  - wifi: ath12k: fix WARN_ON during ath12k_mac_update_vif_chan
    (bsc#1227149).
  - wifi: ath11k: fix tid bitmap is 0 in peer rx mu stats
    (bsc#1227149).
  - wifi: ath11k: move references from rsvd2 to info fields
    (bsc#1227149).
  - wifi: ath11k: mhi: add a warning message for MHI_CB_EE_RDDM
    crash (bsc#1227149).
  - wifi: ath: Use is_multicast_ether_addr() to check multicast
    Ether address (bsc#1227149).
  - wifi: ath12k: Remove unused declarations (bsc#1227149).
  - wifi: ath5k: ath5k_hw_get_median_noise_floor(): use swap()
    (bsc#1227149).
  - wifi: ath: remove unused-but-set parameter (bsc#1227149).
  - wifi: ath11k: Remove unused declarations (bsc#1227149).
  - wifi: ath10k: fix Wvoid-pointer-to-enum-cast warning
    (bsc#1227149).
  - commit 1f3c3b8
  - wifi: ath11k: fix Wvoid-pointer-to-enum-cast warning
    (bsc#1227149).
  - wifi: ath11k: simplify the code with module_platform_driver
    (bsc#1227149).
  - wifi: ath12k: Fix a few spelling errors (bsc#1227149).
  - wifi: ath11k: Fix a few spelling errors (bsc#1227149).
  - wifi: ath10k: Fix a few spelling errors (bsc#1227149).
  - wifi: ath11k: Consistently use ath11k_vif_to_arvif()
    (bsc#1227149).
  - wifi: ath9k: Remove unused declarations (bsc#1227149).
  - wifi: ath9k: Remove unnecessary ternary operators (bsc#1227149).
  - wifi: ath9k: consistently use kstrtoX_from_user() functions
    (bsc#1227149).
  - wifi: ath9k: fix parameter check in ath9k_init_debug()
    (bsc#1227149).
  - commit 6c737fb
  - wifi: ath5k: Remove redundant dev_err() (bsc#1227149).
  - wifi: ath12k: avoid deadlock by change ieee80211_queue_work
    for regd_update_work (bsc#1227149).
  - wifi: ath12k: add handler for scan event WMI_SCAN_EVENT_DEQUEUED
    (bsc#1227149).
  - wifi: ath12k: relax list iteration in ath12k_mac_vif_unref()
    (bsc#1227149).
  - wifi: ath12k: configure puncturing bitmap (bsc#1227149).
  - wifi: ath12k: parse WMI service ready ext2 event (bsc#1227149).
  - wifi: ath12k: add MLO header in peer association (bsc#1227149).
  - wifi: ath12k: peer assoc for 320 MHz (bsc#1227149).
  - wifi: ath12k: add WMI support for EHT peer (bsc#1227149).
  - wifi: ath12k: prepare EHT peer assoc parameters (bsc#1227149).
  - commit 3191784
  - wifi: ath12k: add EHT PHY modes (bsc#1227149).
  - wifi: ath12k: propagate EHT capabilities to userspace
    (bsc#1227149).
  - wifi: ath12k: WMI support to process EHT capabilities
    (bsc#1227149).
  - wifi: ath12k: move HE capabilities processing to a new function
    (bsc#1227149).
  - commit 7fb64df
  - wifi: ath12k: rename HE capabilities setup/copy functions
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-annotate-iftype_data-pointer-with-spar.patch.
  - commit ddfeb0d
  - wifi: ath12k: change to use dynamic memory for channel list
    of scan (bsc#1227149).
  - wifi: ath12k: trigger station disconnect on hardware restart
    (bsc#1227149).
  - wifi: ath12k: Use pdev_id rather than mac_id to get pdev
    (bsc#1227149).
  - wifi: ath12k: correct the data_type from QMI_OPT_FLAG to
    QMI_UNSIGNED_1_BYTE for mlo_capable (bsc#1227149).
  - wifi: ath11k: Remove cal_done check during probe (bsc#1227149).
  - commit e204950
  - wifi: ath11k: simplify
    ath11k_mac_validate_vht_he_fixed_rate_settings() (bsc#1227149).
  - wifi: ath6kl: Remove error checking for debugfs_create_dir()
    (bsc#1227149).
  - wifi: ath5k: remove phydir check from ath5k_debug_init_device()
    (bsc#1227149).
  - wifi: drivers: Explicitly include correct DT includes
    (bsc#1227149).
  - wifi: ath10k: improve structure padding (bsc#1227149).
  - wifi: ath12k: fix conf_mutex in
    ath12k_mac_op_unassign_vif_chanctx() (bsc#1227149).
  - wifi: ath11k: debug: add ATH11K_DBG_CE (bsc#1227149).
  - commit 3345b7e
  - wifi: ath11k: htc: cleanup debug messages (bsc#1227149).
  - wifi: ath11k: don't use %pK (bsc#1227149).
  - wifi: ath11k: hal: cleanup debug message (bsc#1227149).
  - wifi: ath11k: debug: use all upper case in ATH11k_DBG_HAL
    (bsc#1227149).
  - wifi: ath11k: dp: cleanup debug message (bsc#1227149).
  - wifi: ath11k: pci: cleanup debug logging (bsc#1227149).
  - wifi: ath11k: wmi: add unified command debug messages
    (bsc#1227149).
  - wifi: ath11k: wmi: use common error handling style
    (bsc#1227149).
  - wifi: ath11k: wmi: cleanup error handling in
    ath11k_wmi_send_init_country_cmd() (bsc#1227149).
  - wifi: ath11k: remove unsupported event handlers (bsc#1227149).
  - commit 37105bd
  - wifi: ath11k: add WMI event debug messages (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-gtk-offload-status-event-locking.patch.
  - Refresh
    patches.suse/wifi-ath11k-fix-temperature-event-locking.patch.
  - commit 572fd2c
  - wifi: ath11k: remove manual mask names from debug messages
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-gtk-offload-status-event-locking.patch.
  - commit a7ae7bf
  - wifi: ath11k: print debug level in debug messages (bsc#1227149).
  - wifi: ath11k: debug: remove unused ATH11K_DBG_ANY (bsc#1227149).
  - wifi: ath12k: delete the timer rx_replenish_retry during rmmod
    (bsc#1227149).
  - wifi: ath12k: Use msdu_end to check MCBC (bsc#1227149).
  - wifi: ath12k: check hardware major version for WCN7850
    (bsc#1227149).
  - wifi: ath11k: update proper pdev/vdev id for testmode command
    (bsc#1227149).
  - wifi: atk10k: Don't opencode ath10k_pci_priv() in
    ath10k_ahb_priv() (bsc#1227149).
  - wifi: ath10k: Convert to platform remove callback returning void
    (bsc#1227149).
  - commit cafd8ed
  - wifi: ath10k: Drop checks that are always false (bsc#1227149).
  - wifi: ath10k: Drop cleaning of driver data from probe error
    path and remove (bsc#1227149).
  - wifi: ath11k: Add HTT stats for PHY reset case (bsc#1227149).
  - commit dde2040
  - wifi: ath11k: Allow ath11k to boot without caldata in ftm mode
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-do-not-dump-SRNG-statistics-during-resum.patch.
  - commit adbddfc
  - wifi: ath11k: factory test mode support (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-warning-on-DMA-ring-capabilities-eve.patch.
  - Refresh
    patches.suse/wifi-ath11k-rearrange-IRQ-enable-disable-in-reset-pa.patch.
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - commit 030f59a
  - wifi: ath11k: remove unused function ath11k_tm_event_wmi()
    (bsc#1227149).
  - wifi: ath12k: Add support to parse new WMI event for 6 GHz
    regulatory (bsc#1227149).
  - wifi: wil6210: wmi: Replace zero-length array with
    DECLARE_FLEX_ARRAY() helper (bsc#1227149).
  - wifi: wil6210: fw: Replace zero-length arrays with
    DECLARE_FLEX_ARRAY() helper (bsc#1227149).
  - wifi: ath11k: Send HT fixed rate in WMI peer fixed param
    (bsc#1227149).
  - wifi: ath11k: Relocate the func
    ath11k_mac_bitrate_mask_num_ht_rates() and change hweight16
    to hweight8 (bsc#1227149).
  - wifi: ath12k: increase vdev setup timeout (bsc#1227149).
  - wifi: ath11k: EMA beacon support (bsc#1227149).
  - wifi: ath11k: MBSSID beacon support (bsc#1227149).
  - wifi: ath11k: refactor vif parameter configurations
    (bsc#1227149).
  - wifi: ath11k: MBSSID parameter configuration in AP mode
    (bsc#1227149).
  - wifi: ath11k: rename MBSSID fields in wmi_vdev_up_cmd
    (bsc#1227149).
  - wifi: ath11k: MBSSID configuration during vdev create/start
    (bsc#1227149).
  - wifi: ath11k: driver settings for MBSSID and EMA (bsc#1227149).
  - wifi: ath: work around false-positive stringop-overread warning
    (bsc#1227149).
  - wifi: ath11k: Use list_count_nodes() (bsc#1227149).
  - wifi: ath10k: Use list_count_nodes() (bsc#1227149).
  - wifi: ath12k: fix potential wmi_mgmt_tx_queue race condition
    (bsc#1227149).
  - wifi: ath12k: add wait operation for tx management packets
    for flush from mac80211 (bsc#1227149).
  - wifi: ath12k: Remove some dead code (bsc#1227149).
  - wifi: ath12k: send WMI_PEER_REORDER_QUEUE_SETUP_CMDID when
    ADDBA session starts (bsc#1227149).
  - wifi: ath12k: set PERST pin no pull request for WCN7850
    (bsc#1227149).
  - wifi: ath12k: add qmi_cnss_feature_bitmap field to hardware
    parameters (bsc#1227149).
  - wifi: ath10/11/12k: Use alloc_ordered_workqueue() to create
    ordered workqueues (bsc#1227149).
  - commit 1763ceb
  - net: phy: microchip: lan87xx: reinit PHY after cable test
    (git-fixes).
  - i2c: pnx: Fix potential deadlock warning from del_timer_sync()
    call in isr (git-fixes).
  - drm/amdgpu/atomfirmware: silence UBSAN warning (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Valve Galileo
    (stable-fixes).
  - nilfs2: add missing check for inode numbers on directory entries
    (stable-fixes).
  - nilfs2: fix inode number range checks (stable-fixes).
  - drm/amdgpu: silence UBSAN warning (stable-fixes).
  - spi: cadence: Ensure data lines set to low during dummy-cycle
    period (stable-fixes).
  - regmap-i2c: Subtract reg size from max_write (stable-fixes).
  - platform/x86: touchscreen_dmi: Add info for the EZpad 6s Pro
    (stable-fixes).
  - platform/x86: touchscreen_dmi: Add info for GlobalSpace SolT
    IVW 11.6" tablet (stable-fixes).
  - nfc/nci: Add the inconsistency check between the input data
    length and count (stable-fixes).
  - Input: ff-core - prefer struct_size over open coded arithmetic
    (stable-fixes).
  - cdrom: rearrange last_media_change check to avoid unintentional
    overflow (stable-fixes).
  - serial: imx: Raise TX trigger level to 8 (stable-fixes).
  - usb: xhci: prevent potential failure in handle_tx_event()
    for Transfer events without TRB (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Check NULL ptr on
    lvts_data (stable-fixes).
  - firmware: dmi: Stop decoding on broken entry (stable-fixes).
  - i2c: i801: Annotate apanel_addr as __ro_after_init
    (stable-fixes).
  - media: dvb-frontends: tda10048: Fix integer overflow
    (stable-fixes).
  - media: s2255: Use refcount_t instead of atomic_t for
    num_channels (stable-fixes).
  - media: dvb-frontends: tda18271c2dd: Remove casting during div
    (stable-fixes).
  - media: dw2102: fix a potential buffer overflow (git-fixes).
  - media: dw2102: Don't translate i2c read into write
    (stable-fixes).
  - media: dvb-usb: dib0700_devices: Add missing release_firmware()
    (stable-fixes).
  - media: dvb: as102-fe: Fix as10x_register_addr packing
    (stable-fixes).
  - drm/amdgpu: fix the warning about the expression (int)size -
    len (stable-fixes).
  - drm/amdgpu: fix uninitialized scalar variable warning
    (stable-fixes).
  - drm/amd/display: Fix uninitialized variables in DM
    (stable-fixes).
  - drm/amd/display: Skip finding free audio for unknown engine_id
    (stable-fixes).
  - drm/amd/display: Check pipe offset before setting vblank
    (stable-fixes).
  - drm/amd/display: Check index msg_id before read or write
    (stable-fixes).
  - drm/amdgpu: Initialize timestamp for some legacy SOCs
    (stable-fixes).
  - drm/amdgpu: Using uninitialized value *size when calling
    amdgpu_vce_cs_reloc (stable-fixes).
  - drm/amdgpu: Fix uninitialized variable warnings (stable-fixes).
  - drm/lima: fix shared irq handling on driver remove
    (stable-fixes).
  - wifi: mt76: mt7996: add sanity checks for background radar
    trigger (stable-fixes).
  - wifi: mt76: replace skb_put with skb_put_zero (stable-fixes).
  - crypto: aead,cipher - zeroize key buffer after use
    (stable-fixes).
  - crypto: hisilicon/debugfs - Fix debugfs uninit process issue
    (stable-fixes).
  - commit 240e65e

++++ kernel-rt:

  - net/smc: avoid data corruption caused by decline (bsc#1225088
    CVE-2023-52775).
  - commit 621e8ca
  - net: openvswitch: fix overwriting ct original tuple for  ICMPv6
    (bsc#1226783 CVE-2024-38558).
  - commit 748cf39
  - ipv6: sr: fix missing sk_buff release in seg6_input_core
    (bsc#1227626 CVE-2024-39490).
  - commit 3d59f52
  - mptcp: fix data re-injection from stale subflow (bsc#1223010
    CVE-2024-26826).
  - commit f3a102e
  - net/smc: fix illegal rmb_desc access in SMC-D connection dump
    (bsc#1220942 CVE-2024-26615).
  - commit f21afb0
  - kabi/severities: cover all ath/* drivers (bsc#1227149)
    All symbols in ath/* network drivers are local and can be ignored
  - commit d902566
  - Refresh kabi workaround ath updates (bsc#1227149#)
  - commit b0fa38b
  - wifi: mac80211: simplify non-chanctx drivers (bsc#1227149).
  - commit eeb4722
  - wifi: ath11k: move power type check to ASSOC stage when
    connecting to 6 GHz AP (bsc#1227149).
  - wifi: ath11k: fix WCN6750 firmware crash caused by 17 num_vdevs
    (bsc#1227149).
  - wifi: ath12k: fix the problem that down grade phy mode operation
    (bsc#1227149).
  - wifi: ath12k: check M3 buffer size as well whey trying to
    reuse it (bsc#1227149).
  - wifi: ath12k: fix kernel crash during resume (bsc#1227149).
  - wifi: ath9k: work around memset overflow warning (bsc#1227149).
  - wifi: ath12k: use correct flag field for 320 MHz channels
    (bsc#1227149).
  - commit 58db5ff
  - wifi: ath11k: use RCU when accessing struct inet6_dev::ac_list
    (bsc#1227149).
  - wifi: ath12k: fix license in p2p.c and p2p.h (bsc#1227149).
  - wifi: ath11k: constify MHI channel and controller configs
    (bsc#1227149).
  - wifi: ath12k: add rcu lock for ath12k_wmi_p2p_noa_event()
    (bsc#1227149).
  - wifi: ath11k: remove unused scan_events from struct
    scan_req_params (bsc#1227149).
  - wifi: ath11k: add support for QCA2066 (bsc#1227149).
  - wifi: ath11k: move pci.ops registration ahead (bsc#1227149).
  - commit 29f553c
  - wifi: ath11k: provide address list if chip supports 2 stations
    (bsc#1227149).
  - wifi: ath11k: support 2 station interfaces (bsc#1227149).
  - wifi: ath12k: remove the unused scan_events from
    ath12k_wmi_scan_req_arg (bsc#1227149).
  - wifi: ath12k: Remove unused scan_flags from struct
    ath12k_wmi_scan_req_arg (bsc#1227149).
  - wifi: ath12k: Do not use scan_flags from struct
    ath12k_wmi_scan_req_arg (bsc#1227149).
  - wifi: carl9170: Remove redundant assignment to pointer super
    (bsc#1227149).
  - wifi: ath11k: Remove scan_flags union from struct
    scan_req_params (bsc#1227149).
  - wifi: ath11k: Do not directly use scan_flags in struct
    scan_req_params (bsc#1227149).
  - wifi: ath12k: Fix uninitialized use of ret in
    ath12k_mac_allocate() (bsc#1227149).
  - wifi: ath11k: Really consistently use ath11k_vif_to_arvif()
    (bsc#1227149).
  - wifi: ath12k: advertise P2P dev support for WCN7850
    (bsc#1227149).
  - wifi: ath12k: designating channel frequency for ROC scan
    (bsc#1227149).
  - wifi: ath12k: move peer delete after vdev stop of station for
    WCN7850 (bsc#1227149).
  - wifi: ath12k: allow specific mgmt frame tx while vdev is not up
    (bsc#1227149).
  - wifi: ath12k: change WLAN_SCAN_PARAMS_MAX_IE_LEN from 256 to
    512 (bsc#1227149).
  - wifi: ath12k: implement remain on channel for P2P mode
    (bsc#1227149).
  - wifi: ath12k: implement handling of P2P NoA event (bsc#1227149).
  - wifi: ath12k: add P2P IE in beacon template (bsc#1227149).
  - wifi: ath12k: change interface combination for P2P mode
    (bsc#1227149).
  - wifi: ath12k: fix broken structure wmi_vdev_create_cmd
    (bsc#1227149).
  - commit 21d36c7
  - wifi: ath11k: initialize eirp_power before use (bsc#1227149).
  - wifi: ath12k: enable 802.11 power save mode in station mode
    (bsc#1227149).
  - wifi: ath12k: refactor the rfkill worker (bsc#1227149).
  - wifi: ath12k: add processing for TWT disable event
    (bsc#1227149).
  - wifi: ath12k: add processing for TWT enable event (bsc#1227149).
  - wifi: ath12k: disable QMI PHY capability learn in split-phy
    QCN9274 (bsc#1227149).
  - wifi: ath12k: Read board id to support split-PHY QCN9274
    (bsc#1227149).
  - wifi: ath12k: fix PCI read and write (bsc#1227149).
  - wifi: ath12k: add MAC id support in WBM error path
    (bsc#1227149).
  - wifi: ath12k: subscribe required word mask from rx tlv
    (bsc#1227149).
  - commit c884365
  - wifi: ath12k: remove hal_desc_sz from hw params (bsc#1227149).
  - wifi: ath12k: split hal_ops to support RX TLVs word mask
    compaction (bsc#1227149).
  - wifi: ath12k: fix firmware assert during insmod in memory
    segment mode (bsc#1227149).
  - wifi: ath12k: Add logic to write QRTR node id to scratch
    (bsc#1227149).
  - wifi: ath12k: fix fetching MCBC flag for QCN9274 (bsc#1227149).
  - wifi: ath12k: add support for peer meta data version
    (bsc#1227149).
  - wifi: ath12k: fetch correct pdev id from
    WMI_SERVICE_READY_EXT_EVENTID (bsc#1227149).
  - wifi: ath12k: indicate NON MBSSID vdev by default during vdev
    start (bsc#1227149).
  - wifi: ath12k: add firmware-2.bin support (bsc#1227149).
  - wifi: ath9k:  remove redundant assignment to variable ret
    (bsc#1227149).
  - commit 777dc1c
  - wifi: ath11k: fix connection failure due to unexpected peer
    delete (bsc#1227149).
  - wifi: ath11k: avoid forward declaration of
    ath11k_mac_start_vdev_delay() (bsc#1227149).
  - wifi: ath11k: rename ath11k_start_vdev_delay() (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for wcn36xx (bsc#1227149).
  - wifi: fill in MODULE_DESCRIPTION()s for ar5523 (bsc#1227149).
  - commit d2a4b44
  - wifi: ath11k: remove invalid peer create logic (bsc#1227149).
  - wifi: ath11k: enable 36 bit mask for stream DMA (bsc#1227149).
  - wifi: ath10k: Fix enum ath10k_fw_crash_dump_type kernel-doc
    (bsc#1227149).
  - wifi: ath10k: Fix htt_data_tx_completion kernel-doc warning
    (bsc#1227149).
  - wifi: ath10k: fix htt_q_state_conf & htt_q_state kernel-doc
    (bsc#1227149).
  - wifi: ath10k: correctly document enum wmi_tlv_tx_pause_id
    (bsc#1227149).
  - wifi: ath10k: add missing wmi_10_4_feature_mask documentation
    (bsc#1227149).
  - wifi: ath12k: add support for collecting firmware log
    (bsc#1227149).
  - wifi: ath12k: Introduce the container for mac80211 hw
    (bsc#1227149).
  - wifi: ath12k: Refactor the mac80211 hw access from link/radio
    (bsc#1227149).
  - commit 614fabb
  - iommu/vt-d: Improve ITE fault handling if target device isn't
    present (git-fixes).
  - commit 134a3a5
  - wifi: ath12k: change MAC buffer ring size to 2048 (bsc#1227149).
  - wifi: ath12k: add support for BA1024 (bsc#1227149).
  - wifi: ath12k: fix wrong definitions of hal_reo_update_rx_queue
    (bsc#1227149).
  - wifi: ath10k: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: ath11k: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: ath12k: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: ath12k: add QMI PHY capability learn support
    (bsc#1227149).
  - wifi: ath12k: refactor QMI MLO host capability helper function
    (bsc#1227149).
  - wifi: ath11k: document HAL_RX_BUF_RBM_SW4_BM (bsc#1227149).
  - wifi: ath12k: ath12k_start_vdev_delay(): convert to use ar
    (bsc#1227149).
  - commit dd312dc
  - wifi: ath12k: refactor ath12k_mac_op_flush() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_ampdu_action()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_configure_filter()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_update_vif_offload()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_stop() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_start() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_conf_tx() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_bss_assoc() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_op_config() (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_register() and
    ath12k_mac_unregister() (bsc#1227149).
  - commit b6ca728
  - wifi: ath12k: refactor ath12k_mac_setup_channels_rates()
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_mac_allocate() and
    ath12k_mac_destroy() (bsc#1227149).
  - wifi: ath12k: relocate ath12k_dp_pdev_pre_alloc() call
    (bsc#1227149).
  - wifi: ath12k: Use initializers for QMI message buffers
    (bsc#1227149).
  - wifi: ath12k: Add missing qmi_txn_cancel() calls (bsc#1227149).
  - wifi: ath12k: Remove unnecessary struct qmi_txn initializers
    (bsc#1227149).
  - wifi: ath11k: use WMI_VDEV_SET_TPC_POWER_CMDID when
    EXT_TPC_REG_SUPPORT for 6 GHz (bsc#1227149).
  - wifi: ath11k: add handler for WMI_VDEV_SET_TPC_POWER_CMDID
    (bsc#1227149).
  - wifi: ath11k: add WMI_TLV_SERVICE_EXT_TPC_REG_SUPPORT service
    bit (bsc#1227149).
  - wifi: ath11k: fill parameters for vdev set tpc power WMI command
    (bsc#1227149).
  - commit 3c338b0
  - wifi: ath11k: save max transmit power in vdev start response
    event from firmware (bsc#1227149).
  - commit 279ae7a
  - wifi: ath11k: add parse of transmit power envelope element
    (bsc#1227149).
  - commit e295f89
  - wifi: ath11k: save power spectral density(PSD) of regulatory
    rule (bsc#1227149).
  - wifi: ath11k: update regulatory rules when connect to AP on
    6 GHz band for station (bsc#1227149).
  - wifi: ath11k: update regulatory rules when interface added
    (bsc#1227149).
  - wifi: ath11k: fix a possible dead lock caused by ab->base_lock
    (bsc#1227149).
  - wifi: ath11k: store cur_regulatory_info for each radio
    (bsc#1227149).
  - wifi: ath11k: add support to select 6 GHz regulatory type
    (bsc#1227149).
  - wifi: ath12k: refactor ath12k_wmi_tlv_parse_alloc()
    (bsc#1227149).
  - wifi: ath11k: fix IOMMU errors on buffer rings (bsc#1227149).
  - commit d84dbd2
  - wifi: ath12k: Make QMI message rules const (bsc#1227149).
  - wifi: ath12k: support default regdb while searching board-2.bin
    for WCN7850 (bsc#1227149).
  - wifi: ath12k: add support to search regdb data in board-2.bin
    for WCN7850 (bsc#1227149).
  - wifi: ath12k: remove unused ATH12K_BD_IE_BOARD_EXT
    (bsc#1227149).
  - wifi: ath12k: add fallback board name without variant while
    searching board-2.bin (bsc#1227149).
  - wifi: ath12k: add string type to search board data in
    board-2.bin for WCN7850 (bsc#1227149).
  - wifi: ath10k: remove duplicate memset() in 10.4 TDLS peer update
    (bsc#1227149).
  - wifi: ath10k: use flexible array in struct
    wmi_tdls_peer_capabilities (bsc#1227149).
  - wifi: ath10k: remove unused template structs (bsc#1227149).
  - wifi: ath10k: remove struct wmi_pdev_chanlist_update_event
    (bsc#1227149).
  - commit e73f8dc
  - wifi: ath10k: use flexible arrays for WMI start scan TLVs
    (bsc#1227149).
  - wifi: ath10k: use flexible array in struct wmi_host_mem_chunks
    (bsc#1227149).
  - wifi: ath9k: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: ath9k: delete some unused/duplicate macros (bsc#1227149).
  - wifi: ath11k: refactor ath11k_wmi_tlv_parse_alloc()
    (bsc#1227149).
  - wifi: ath11k: rely on mac80211 debugfs handling for vif
    (bsc#1227149).
  - wifi: ath11k: workaround too long expansion sparse warnings
    (bsc#1227149).
  - Revert "wifi: ath12k: use ATH12K_PCI_IRQ_DP_OFFSET for DP IRQ"
    (bsc#1227149).
  - wifi: ath9k: reset survey of current channel after a scan
    started (bsc#1227149).
  - wifi: ath12k: fix the issue that the multicast/broadcast
    indicator is not read correctly for WCN7850 (bsc#1227149).
  - commit 6cf204e
  - wifi: ath11k: Fix ath11k_htc_record flexible record
    (bsc#1227149).
  - wifi: ath5k: remove unused ath5k_eeprom_info::ee_antenna
    (bsc#1227149).
  - wifi: ath10k: add support to allow broadcast action frame RX
    (bsc#1227149).
  - wifi: ath12k: avoid repeated wiphy access from hw (bsc#1227149).
  - wifi: ath12k: set IRQ affinity to CPU0 in case of one MSI vector
    (bsc#1227149).
  - wifi: ath12k: do not restore ASPM in case of single MSI vector
    (bsc#1227149).
  - wifi: ath12k: add support one MSI vector (bsc#1227149).
  - wifi: ath12k: refactor multiple MSI vector implementation
    (bsc#1227149).
  - wifi: ath12k: use ATH12K_PCI_IRQ_DP_OFFSET for DP IRQ
    (bsc#1227149).
  - wifi: ath12k: add CE and ext IRQ flag to indicate irq_handler
    (bsc#1227149).
  - commit 908caeb
  - wifi: ath12k: get msi_data again after request_irq is called
    (bsc#1227149).
  - wifi: wcn36xx: Convert to platform remove callback returning
    void (bsc#1227149).
  - wifi: ath5k: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: ath12k: avoid repeated hw access from ar (bsc#1227149).
  - wifi: ath12k: Optimize the mac80211 hw data access
    (bsc#1227149).
  - wifi: ath12k: add 320 MHz bandwidth enums (bsc#1227149).
  - wifi: ath11k: Convert to platform remove callback returning void
    (bsc#1227149).
  - wifi: ath11k: remove ath11k_htc_record::pauload[] (bsc#1227149).
  - wifi: ath10k: Use DECLARE_FLEX_ARRAY() for ath10k_htc_record
    (bsc#1227149).
  - wifi: ath10k: remove ath10k_htc_record::pauload[] (bsc#1227149).
  - commit 67bc0a7
  - wifi: ath10k: Update Qualcomm Innovation Center, Inc. copyrights
    (bsc#1227149).
  - commit e13fd24
  - wifi: ath11k: Update Qualcomm Innovation Center, Inc. copyrights
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-do-not-dump-SRNG-statistics-during-resum.patch.
  - Refresh
    patches.suse/wifi-ath11k-fix-warning-on-DMA-ring-capabilities-eve.patch.
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - Refresh
    patches.suse/wifi-ath11k-thermal-don-t-try-to-register-multiple-t.patch.
  - commit a886227
  - wifi: ath9k: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath12k: refactor DP Rxdma ring structure (bsc#1227149).
  - wifi: ath12k: avoid explicit HW conversion argument in Rxdma
    replenish (bsc#1227149).
  - wifi: ath12k: avoid explicit RBM id argument in Rxdma replenish
    (bsc#1227149).
  - wifi: ath12k: avoid explicit mac id argument in Rxdma replenish
    (bsc#1227149).
  - wifi: ath12k: fix the error handler of rfkill config
    (bsc#1227149).
  - wifi: ath12k: use select for CRYPTO_MICHAEL_MIC (bsc#1227149).
  - wifi: ath11k: use select for CRYPTO_MICHAEL_MIC (bsc#1227149).
  - commit a869013
  - wifi: ath12k: Consolidate WMI peer flags (bsc#1227149).
  - wifi: ath11k: Consolidate WMI peer flags (bsc#1227149).
  - wifi: ath12k: Remove obsolete struct wmi_peer_flags_map
    * peer_flags (bsc#1227149).
  - wifi: ath11k: Remove obsolete struct wmi_peer_flags_map
    * peer_flags (bsc#1227149).
  - wifi: ath12k: Remove struct ath12k::ops (bsc#1227149).
  - wifi: ath11k: Remove struct ath11k::ops (bsc#1227149).
  - wifi: ath10k: Remove unused struct ath10k_htc_frame
    (bsc#1227149).
  - wifi: ath10k: simplify __ath10k_htt_tx_txq_recalc()
    (bsc#1227149).
  - wifi: ath11k: Remove unneeded semicolon (bsc#1227149).
  - wifi: ath10k: replace deprecated strncpy with memcpy
    (bsc#1227149).
  - commit e59240f
  - wifi: ath12k: drop NULL pointer check in
    ath12k_update_per_peer_tx_stats() (bsc#1227149).
  - Revert "wifi: ath11k: call ath11k_mac_fils_discovery() without
    condition" (bsc#1227149).
  - wifi: ath12k: Introduce and use ath12k_sta_to_arsta()
    (bsc#1227149).
  - wifi: ath12k: rename the sc naming convention to ab
    (bsc#1227149).
  - wifi: ath12k: rename the wmi_sc naming convention to wmi_ab
    (bsc#1227149).
  - commit f93677e
  - bus: mhi: host: allow MHI client drivers to provide the firmware
    via a pointer (bsc#1227149).
  - commit 494649c
  - wifi: ath11k: add firmware-2.bin support (bsc#1227149).
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - commit 677d325
  - wifi: ath11k: qmi: refactor ath11k_qmi_m3_load() (bsc#1227149).
  - commit 296ac8f
  - wifi: ath11k: rename the sc naming convention to ab
    (bsc#1227149).
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - Refresh
    patches.suse/wifi-ath11k-thermal-don-t-try-to-register-multiple-t.patch.
  - commit 6eedd0d
  - wifi: ath11k: rename the wmi_sc naming convention to wmi_ab
    (bsc#1227149).
  - wifi: ath6kl: replace deprecated strncpy with memcpy
    (bsc#1227149).
  - commit cd59b03
  - wifi: ath5k: replace deprecated strncpy with strscpy
    (bsc#1227149).
  - wifi: ath12k: Remove ath12k_base::bd_api (bsc#1227149).
  - wifi: ath11k: Remove ath11k_base::bd_api (bsc#1227149).
  - wifi: ath12k: Enable Mesh support for QCN9274 (bsc#1227149).
  - wifi: ath12k: register EHT mesh capabilities (bsc#1227149).
  - wifi: ath11k: Use device_get_match_data() (bsc#1227149).
  - wifi: ath11k: Introduce and use ath11k_sta_to_arsta()
    (bsc#1227149).
  - wifi: ath11k: Remove unused struct ath11k_htc_frame
    (bsc#1227149).
  - wifi: ath12k: fix invalid m3 buffer address (bsc#1227149).
  - wifi: ath12k: add ath12k_qmi_free_resource() for recovery
    (bsc#1227149).
  - commit a18a8d4
  - wifi: ath12k: configure RDDM size to MHI for device recovery
    (bsc#1227149).
  - wifi: ath12k: add parsing of phy bitmap for reg rules
    (bsc#1227149).
  - wifi: ath11k: add parsing of phy bitmap for reg rules
    (bsc#1227149).
  - wifi: ath11k: ath11k_debugfs_register(): fix format-truncation
    warning (bsc#1227149).
  - wifi: ath12k: Consistently use ath12k_vif_to_arvif()
    (bsc#1227149).
  - wifi: ath11k: call ath11k_mac_fils_discovery() without condition
    (bsc#1227149).
  - wifi: ath12k: remove redundant memset() in
    ath12k_hal_reo_qdesc_setup() (bsc#1227149).
  - wifi: ath9k_htc: fix format-truncation warning (bsc#1227149).
  - wifi: ath12k: fix debug messages (bsc#1227149).
  - wifi: ath11k: fix CAC running state during virtual interface
    start (bsc#1227149).
  - commit c2f2e92
  - wifi: ath10k: simplify ath10k_peer_create() (bsc#1227149).
  - wifi: ath10k: indicate to mac80211 scan complete with aborted
    flag for ATH10K_SCAN_STARTING state (bsc#1227149).
  - wifi: ath: dfs_pattern_detector: Use flex array to simplify code
    (bsc#1227149).
  - wifi: carl9170: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath10k: consistently use kstrtoX_from_user() functions
    (bsc#1227149).
  - wifi: ath12k: add keep backward compatibility of PHY mode to
    avoid firmware crash (bsc#1227149).
  - wifi: ath12k: add read variant from SMBIOS for download board
    data (bsc#1227149).
  - wifi: ath12k: do not drop data frames from unassociated stations
    (bsc#1227149).
  - wifi: ath11k: mac: fix struct ieee80211_sband_iftype_data
    handling (bsc#1227149).
  - wifi: ath11k: fix ath11k_mac_op_remain_on_channel() stack usage
    (bsc#1227149).
  - commit b844022
  - wifi: ath12k: add msdu_end structure for WCN7850 (bsc#1227149).
  - wifi: ath12k: Set default beacon mode to burst mode
    (bsc#1227149).
  - wifi: ath12k: call ath12k_mac_fils_discovery() without condition
    (bsc#1227149).
  - wifi: ath11k: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath12k: enable IEEE80211_HW_SINGLE_SCAN_ON_ALL_BANDS
    for WCN7850 (bsc#1227149).
  - wifi: ath12k: change to treat alpha code na as world wide
    regdomain (bsc#1227149).
  - wifi: ath12k: indicate scan complete for scan canceled when
    scan running (bsc#1227149).
  - wifi: ath12k: indicate to mac80211 scan complete with aborted
    flag for ATH12K_SCAN_STARTING state (bsc#1227149).
  - wifi: ath12k: fix recovery fail while firmware crash when
    doing channel switch (bsc#1227149).
  - wifi: ath12k: add support for hardware rfkill for WCN7850
    (bsc#1227149).
  - commit 087627b
  - wifi: ath11k: use kstrtoul_from_user() where appropriate
    (bsc#1227149).
  - wifi: ath11k: remove unused members of 'struct ath11k_base'
    (bsc#1227149).
  - wifi: ath11k: drop redundant check in
    ath11k_dp_rx_mon_dest_process() (bsc#1227149).
  - wifi: ath11k: drop NULL pointer check in
    ath11k_update_per_peer_tx_stats() (bsc#1227149).
  - wifi: ath10k: drop HTT_DATA_TX_STATUS_DOWNLOAD_FAIL
    (bsc#1227149).
  - wifi: ath10k: Annotate struct ath10k_ce_ring with __counted_by
    (bsc#1227149).
  - wifi: wcn36xx: Annotate struct wcn36xx_hal_ind_msg with
    __counted_by (bsc#1227149).
  - wifi: ath12k: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath10k: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath6kl: remove unnecessary (void*) conversions
    (bsc#1227149).
  - commit 3f20dbc
  - wifi: ath5k: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: wcn36xx: remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ar5523: Remove unnecessary (void*) conversions
    (bsc#1227149).
  - wifi: ath9k: clean up function ath9k_hif_usb_resume
    (bsc#1227149).
  - wifi: ath11k: add chip id board name while searching board-2.bin
    for WCN6855 (bsc#1227149).
  - wifi: ath12k: change to initialize recovery variables earlier
    in ath12k_core_reset() (bsc#1227149).
  - wifi: ath12k: enable 320 MHz bandwidth for 6 GHz band in EHT
    PHY capability for WCN7850 (bsc#1227149).
  - wifi: ath9k: use u32 for txgain indexes (bsc#1227149).
  - wifi: ath9k: simplify ar9003_hw_process_ini() (bsc#1227149).
  - wifi: ath12k: fix radar detection in 160 MHz (bsc#1227149).
  - commit 0b35606
  - wifi: ath12k: fix WARN_ON during ath12k_mac_update_vif_chan
    (bsc#1227149).
  - wifi: ath11k: fix tid bitmap is 0 in peer rx mu stats
    (bsc#1227149).
  - wifi: ath11k: move references from rsvd2 to info fields
    (bsc#1227149).
  - wifi: ath11k: mhi: add a warning message for MHI_CB_EE_RDDM
    crash (bsc#1227149).
  - wifi: ath: Use is_multicast_ether_addr() to check multicast
    Ether address (bsc#1227149).
  - wifi: ath12k: Remove unused declarations (bsc#1227149).
  - wifi: ath5k: ath5k_hw_get_median_noise_floor(): use swap()
    (bsc#1227149).
  - wifi: ath: remove unused-but-set parameter (bsc#1227149).
  - wifi: ath11k: Remove unused declarations (bsc#1227149).
  - wifi: ath10k: fix Wvoid-pointer-to-enum-cast warning
    (bsc#1227149).
  - commit 1f3c3b8
  - wifi: ath11k: fix Wvoid-pointer-to-enum-cast warning
    (bsc#1227149).
  - wifi: ath11k: simplify the code with module_platform_driver
    (bsc#1227149).
  - wifi: ath12k: Fix a few spelling errors (bsc#1227149).
  - wifi: ath11k: Fix a few spelling errors (bsc#1227149).
  - wifi: ath10k: Fix a few spelling errors (bsc#1227149).
  - wifi: ath11k: Consistently use ath11k_vif_to_arvif()
    (bsc#1227149).
  - wifi: ath9k: Remove unused declarations (bsc#1227149).
  - wifi: ath9k: Remove unnecessary ternary operators (bsc#1227149).
  - wifi: ath9k: consistently use kstrtoX_from_user() functions
    (bsc#1227149).
  - wifi: ath9k: fix parameter check in ath9k_init_debug()
    (bsc#1227149).
  - commit 6c737fb
  - wifi: ath5k: Remove redundant dev_err() (bsc#1227149).
  - wifi: ath12k: avoid deadlock by change ieee80211_queue_work
    for regd_update_work (bsc#1227149).
  - wifi: ath12k: add handler for scan event WMI_SCAN_EVENT_DEQUEUED
    (bsc#1227149).
  - wifi: ath12k: relax list iteration in ath12k_mac_vif_unref()
    (bsc#1227149).
  - wifi: ath12k: configure puncturing bitmap (bsc#1227149).
  - wifi: ath12k: parse WMI service ready ext2 event (bsc#1227149).
  - wifi: ath12k: add MLO header in peer association (bsc#1227149).
  - wifi: ath12k: peer assoc for 320 MHz (bsc#1227149).
  - wifi: ath12k: add WMI support for EHT peer (bsc#1227149).
  - wifi: ath12k: prepare EHT peer assoc parameters (bsc#1227149).
  - commit 3191784
  - wifi: ath12k: add EHT PHY modes (bsc#1227149).
  - wifi: ath12k: propagate EHT capabilities to userspace
    (bsc#1227149).
  - wifi: ath12k: WMI support to process EHT capabilities
    (bsc#1227149).
  - wifi: ath12k: move HE capabilities processing to a new function
    (bsc#1227149).
  - commit 7fb64df
  - wifi: ath12k: rename HE capabilities setup/copy functions
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-annotate-iftype_data-pointer-with-spar.patch.
  - commit ddfeb0d
  - wifi: ath12k: change to use dynamic memory for channel list
    of scan (bsc#1227149).
  - wifi: ath12k: trigger station disconnect on hardware restart
    (bsc#1227149).
  - wifi: ath12k: Use pdev_id rather than mac_id to get pdev
    (bsc#1227149).
  - wifi: ath12k: correct the data_type from QMI_OPT_FLAG to
    QMI_UNSIGNED_1_BYTE for mlo_capable (bsc#1227149).
  - wifi: ath11k: Remove cal_done check during probe (bsc#1227149).
  - commit e204950
  - wifi: ath11k: simplify
    ath11k_mac_validate_vht_he_fixed_rate_settings() (bsc#1227149).
  - wifi: ath6kl: Remove error checking for debugfs_create_dir()
    (bsc#1227149).
  - wifi: ath5k: remove phydir check from ath5k_debug_init_device()
    (bsc#1227149).
  - wifi: drivers: Explicitly include correct DT includes
    (bsc#1227149).
  - wifi: ath10k: improve structure padding (bsc#1227149).
  - wifi: ath12k: fix conf_mutex in
    ath12k_mac_op_unassign_vif_chanctx() (bsc#1227149).
  - wifi: ath11k: debug: add ATH11K_DBG_CE (bsc#1227149).
  - commit 3345b7e
  - wifi: ath11k: htc: cleanup debug messages (bsc#1227149).
  - wifi: ath11k: don't use %pK (bsc#1227149).
  - wifi: ath11k: hal: cleanup debug message (bsc#1227149).
  - wifi: ath11k: debug: use all upper case in ATH11k_DBG_HAL
    (bsc#1227149).
  - wifi: ath11k: dp: cleanup debug message (bsc#1227149).
  - wifi: ath11k: pci: cleanup debug logging (bsc#1227149).
  - wifi: ath11k: wmi: add unified command debug messages
    (bsc#1227149).
  - wifi: ath11k: wmi: use common error handling style
    (bsc#1227149).
  - wifi: ath11k: wmi: cleanup error handling in
    ath11k_wmi_send_init_country_cmd() (bsc#1227149).
  - wifi: ath11k: remove unsupported event handlers (bsc#1227149).
  - commit 37105bd
  - wifi: ath11k: add WMI event debug messages (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-gtk-offload-status-event-locking.patch.
  - Refresh
    patches.suse/wifi-ath11k-fix-temperature-event-locking.patch.
  - commit 572fd2c
  - wifi: ath11k: remove manual mask names from debug messages
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-gtk-offload-status-event-locking.patch.
  - commit a7ae7bf
  - wifi: ath11k: print debug level in debug messages (bsc#1227149).
  - wifi: ath11k: debug: remove unused ATH11K_DBG_ANY (bsc#1227149).
  - wifi: ath12k: delete the timer rx_replenish_retry during rmmod
    (bsc#1227149).
  - wifi: ath12k: Use msdu_end to check MCBC (bsc#1227149).
  - wifi: ath12k: check hardware major version for WCN7850
    (bsc#1227149).
  - wifi: ath11k: update proper pdev/vdev id for testmode command
    (bsc#1227149).
  - wifi: atk10k: Don't opencode ath10k_pci_priv() in
    ath10k_ahb_priv() (bsc#1227149).
  - wifi: ath10k: Convert to platform remove callback returning void
    (bsc#1227149).
  - commit cafd8ed
  - wifi: ath10k: Drop checks that are always false (bsc#1227149).
  - wifi: ath10k: Drop cleaning of driver data from probe error
    path and remove (bsc#1227149).
  - wifi: ath11k: Add HTT stats for PHY reset case (bsc#1227149).
  - commit dde2040
  - wifi: ath11k: Allow ath11k to boot without caldata in ftm mode
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-do-not-dump-SRNG-statistics-during-resum.patch.
  - commit adbddfc
  - wifi: ath11k: factory test mode support (bsc#1227149).
  - Refresh
    patches.suse/wifi-ath11k-fix-warning-on-DMA-ring-capabilities-eve.patch.
  - Refresh
    patches.suse/wifi-ath11k-rearrange-IRQ-enable-disable-in-reset-pa.patch.
  - Refresh patches.suse/wifi-ath11k-support-hibernation.patch.
  - commit 030f59a
  - wifi: ath11k: remove unused function ath11k_tm_event_wmi()
    (bsc#1227149).
  - wifi: ath12k: Add support to parse new WMI event for 6 GHz
    regulatory (bsc#1227149).
  - wifi: wil6210: wmi: Replace zero-length array with
    DECLARE_FLEX_ARRAY() helper (bsc#1227149).
  - wifi: wil6210: fw: Replace zero-length arrays with
    DECLARE_FLEX_ARRAY() helper (bsc#1227149).
  - wifi: ath11k: Send HT fixed rate in WMI peer fixed param
    (bsc#1227149).
  - wifi: ath11k: Relocate the func
    ath11k_mac_bitrate_mask_num_ht_rates() and change hweight16
    to hweight8 (bsc#1227149).
  - wifi: ath12k: increase vdev setup timeout (bsc#1227149).
  - wifi: ath11k: EMA beacon support (bsc#1227149).
  - wifi: ath11k: MBSSID beacon support (bsc#1227149).
  - wifi: ath11k: refactor vif parameter configurations
    (bsc#1227149).
  - wifi: ath11k: MBSSID parameter configuration in AP mode
    (bsc#1227149).
  - wifi: ath11k: rename MBSSID fields in wmi_vdev_up_cmd
    (bsc#1227149).
  - wifi: ath11k: MBSSID configuration during vdev create/start
    (bsc#1227149).
  - wifi: ath11k: driver settings for MBSSID and EMA (bsc#1227149).
  - wifi: ath: work around false-positive stringop-overread warning
    (bsc#1227149).
  - wifi: ath11k: Use list_count_nodes() (bsc#1227149).
  - wifi: ath10k: Use list_count_nodes() (bsc#1227149).
  - wifi: ath12k: fix potential wmi_mgmt_tx_queue race condition
    (bsc#1227149).
  - wifi: ath12k: add wait operation for tx management packets
    for flush from mac80211 (bsc#1227149).
  - wifi: ath12k: Remove some dead code (bsc#1227149).
  - wifi: ath12k: send WMI_PEER_REORDER_QUEUE_SETUP_CMDID when
    ADDBA session starts (bsc#1227149).
  - wifi: ath12k: set PERST pin no pull request for WCN7850
    (bsc#1227149).
  - wifi: ath12k: add qmi_cnss_feature_bitmap field to hardware
    parameters (bsc#1227149).
  - wifi: ath10/11/12k: Use alloc_ordered_workqueue() to create
    ordered workqueues (bsc#1227149).
  - commit 1763ceb
  - net: phy: microchip: lan87xx: reinit PHY after cable test
    (git-fixes).
  - i2c: pnx: Fix potential deadlock warning from del_timer_sync()
    call in isr (git-fixes).
  - drm/amdgpu/atomfirmware: silence UBSAN warning (stable-fixes).
  - drm: panel-orientation-quirks: Add quirk for Valve Galileo
    (stable-fixes).
  - nilfs2: add missing check for inode numbers on directory entries
    (stable-fixes).
  - nilfs2: fix inode number range checks (stable-fixes).
  - drm/amdgpu: silence UBSAN warning (stable-fixes).
  - spi: cadence: Ensure data lines set to low during dummy-cycle
    period (stable-fixes).
  - regmap-i2c: Subtract reg size from max_write (stable-fixes).
  - platform/x86: touchscreen_dmi: Add info for the EZpad 6s Pro
    (stable-fixes).
  - platform/x86: touchscreen_dmi: Add info for GlobalSpace SolT
    IVW 11.6" tablet (stable-fixes).
  - nfc/nci: Add the inconsistency check between the input data
    length and count (stable-fixes).
  - Input: ff-core - prefer struct_size over open coded arithmetic
    (stable-fixes).
  - cdrom: rearrange last_media_change check to avoid unintentional
    overflow (stable-fixes).
  - serial: imx: Raise TX trigger level to 8 (stable-fixes).
  - usb: xhci: prevent potential failure in handle_tx_event()
    for Transfer events without TRB (stable-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Check NULL ptr on
    lvts_data (stable-fixes).
  - firmware: dmi: Stop decoding on broken entry (stable-fixes).
  - i2c: i801: Annotate apanel_addr as __ro_after_init
    (stable-fixes).
  - media: dvb-frontends: tda10048: Fix integer overflow
    (stable-fixes).
  - media: s2255: Use refcount_t instead of atomic_t for
    num_channels (stable-fixes).
  - media: dvb-frontends: tda18271c2dd: Remove casting during div
    (stable-fixes).
  - media: dw2102: fix a potential buffer overflow (git-fixes).
  - media: dw2102: Don't translate i2c read into write
    (stable-fixes).
  - media: dvb-usb: dib0700_devices: Add missing release_firmware()
    (stable-fixes).
  - media: dvb: as102-fe: Fix as10x_register_addr packing
    (stable-fixes).
  - drm/amdgpu: fix the warning about the expression (int)size -
    len (stable-fixes).
  - drm/amdgpu: fix uninitialized scalar variable warning
    (stable-fixes).
  - drm/amd/display: Fix uninitialized variables in DM
    (stable-fixes).
  - drm/amd/display: Skip finding free audio for unknown engine_id
    (stable-fixes).
  - drm/amd/display: Check pipe offset before setting vblank
    (stable-fixes).
  - drm/amd/display: Check index msg_id before read or write
    (stable-fixes).
  - drm/amdgpu: Initialize timestamp for some legacy SOCs
    (stable-fixes).
  - drm/amdgpu: Using uninitialized value *size when calling
    amdgpu_vce_cs_reloc (stable-fixes).
  - drm/amdgpu: Fix uninitialized variable warnings (stable-fixes).
  - drm/lima: fix shared irq handling on driver remove
    (stable-fixes).
  - wifi: mt76: mt7996: add sanity checks for background radar
    trigger (stable-fixes).
  - wifi: mt76: replace skb_put with skb_put_zero (stable-fixes).
  - crypto: aead,cipher - zeroize key buffer after use
    (stable-fixes).
  - crypto: hisilicon/debugfs - Fix debugfs uninit process issue
    (stable-fixes).
  - commit 240e65e

++++ less:

  - Update to 661:
    * fix crash - buffer overflow by one in fexpand
    * fix free(): double free detected in tcache 2
    * fix segmentation fault on line-num-width & -N

++++ newt:

  - Add -D_GNU_SOURCE to compilation flags because it is a required
    feature macro for function setlinebuf to be declared. [boo#1225864]

++++ polkit:

  - Add -Wno-error=implicit-function-declaration to %optflags to
    work-around an issue in mocklibc (which has been meanwhile removed
    by upstream) with exactly this kind of issue.

++++ liburing:

  - Fix buf-ring-nommap.t test failure
    * test-buf-ring-nommap-zero-the-ringbuf-memory.patch

++++ xmlsec1:

  - Update to 1.2.40
    The legacy XML Security Library 1.2.40 release includes the following changes:
    * (xmlsec-core) Fixed functions deprecated in LibXML2 2.13.1 (including disabling HTTP support by default).
    * (xmlsec-nss) Increased keys size in all tests to support NSS 3.101.
    * (windows) Added "ftp" and "http" flags in 'configure.js' (both are disabled by default).
    * Several other small fixes (more details).
  - Update to 1.2.39
    The legacy XML Security Library 1.2.39 release includes the following changes:
    * Added options to enable/disable local files, HTTP, and FTP support. FTP is disabled by default.
    * Several other small fixes (more details).
  - Remove upstreamed xmlsec1-gcc14.patch

++++ openSUSE-repos-LeapMicro:

  - Update to version 20240712.dd8c2eb:
    * use cdn.opensuse.org for leap16
  - Update to version 20240712.d0ece36:
    * Update opensuse-leap16-repoindex.xml to use distribution (#71)

++++ runc:

  - Update to runc v1.2.0~rc2. Upstream changelog is available from
    <https://github.com/opencontainers/runc/releases/tag/v1.2.0-rc.2>.
  - Re-allow Go 1.22 builds for >= 1.22.4.

------------------------------------------------------------------
------------------  2024-7-11  -  Jul 11 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Added integration test for SUSE agama installer
    This integration test builds a self-install ISO image which
    drops the SUSE Agama installer into a ramdisk for performing
    an interactive installation procedure to test Agama
  - Add --set-type-attr and --set-release-version
    Allow to set/overwrite type section attributes via the cmdline.
    Allow to set/add the release-version element via the cmdline.
    This Fixes #2478 and Fixes #2588

++++ gtk3:

  - Update to version 3.24.43:
    + Stop looking for modules in cwd (bsc#1228120 CVE-2024-6655).
    + Updated translations.

++++ haproxy:

  - refreshed patches:
    haproxy-1.6.0-makefile_lib.patch
    haproxy-1.6.0-sec-options.patch
  - Update to version 3.0.3+git0.95a607c4b:
    * [RELEASE] Released version 3.0.3
    * BUG/MEDIUM: bwlim: Be sure to never set the analyze expiration date in past
    * DEV: flags/quic: decode quic_conn flags
    * BUG/MEDIUM: spoe: Be sure to create a SPOE applet if none on the current thread
    * BUG/MEDIUM: h1: Reject empty Transfer-encoding header
    * BUG/MINOR: h1: Reject empty coding name as last transfer-encoding value
    * BUG/MINOR: h1: Fail to parse empty transfer coding names
    * BUG/MINOR: jwt: fix variable initialisation
    * Revert "MEDIUM: init: set default for fd_hard_limit via DEFAULT_MAXFD"
    * BUG/MEDIUM: peers: Fix crash when syncing learn state of a peer without appctx
    * DOC: configuration: update maxconn description
    * MEDIUM: init: set default for fd_hard_limit via DEFAULT_MAXFD
    * BUG/MINOR: jwt: don't try to load files with HMAC algorithm
    * BUG/MEDIUM: server: fix race on server_atomic_sync()
    * DOC: configuration: more details about the master-worker mode
    * BUG/MEDIUM: hlua/cli: Fix lua CLI commands to work with applet's buffers
    * BUG/MINOR: promex: Remove Help prefix repeated twice for each metric
    * BUG/MEDIUM: quic: fix possible exit from qc_check_dcid() without unlocking
    * BUG/MINOR: quic: fix race-condition on trace for CID retrieval
    * BUG/MINOR: quic: fix race condition in qc_check_dcid()
    * BUG/MEDIUM: quic: fix race-condition in quic_get_cid_tid()
    * BUG/MEDIUM: h3: ensure the ":scheme" pseudo header is totally valid
    * BUG/MEDIUM: h3: ensure the ":method" pseudo header is totally valid
    * BUG/MEDIUM: server/dns: prevent DOWN/UP flap upon resolution timeout or error
    * MINOR: activity: make the memory profiling hash size configurable at build time
    * BUG/MINOR: server: fix first server template name lookup UAF
    * DOC: configuration: add details about crt-store in bind "crt" keyword
    * BUG/MEDIUM: stick-table: Decrement the ref count inside lock to kill a session
    * BUG/MINOR: hlua: report proper context upon error in hlua_cli_io_handler_fct()
    * DEV: flags/show-fd-to-flags: adapt to recent versions
    * BUG/MINOR: quic: fix BUG_ON() on Tx pkt alloc failure
    * BUG/MINOR: h3: fix BUG_ON() crash on control stream alloc failure
    * BUG/MINOR: mux-quic: fix crash on qcs SD alloc failure
    * BUG/MINOR: h3: fix crash on STOP_SENDING receive after GOAWAY emission
    * DOC: api/event_hdl: small updates, fix an example and add some precisions
    * SCRIPTS: git-show-backports: do not truncate git-show output
    * BUG/MAJOR: quic: fix padding with short packets
    * DOC: management: document ptr lookup for table commands
    * DOC: configuration: fix alphabetical order of bind options
    * BUG/MEDIUM: proxy: fix email-alert invalid free
    * REGTESTS: ssl: fix some regtests 'feature cmd' start condition
    * DEBUG: hlua: distinguish burst timeout errors from exec timeout errors
    * BUG/MINOR: log: fix broken '+bin' logformat node option

++++ irqbalance:

  - removed ProtectKernelTunables=yes from irqbalance.service to
    fix "Cannot change IRQ %d affinity: Read-only file system" errors.
    See https://github.com/Irqbalance/irqbalance/issues/308

++++ kernel-default:

  - Refresh patches.kabi/wireless-kabi-workaround.patch (bsc#1227149)
    More fixes for 6.9 API updates
  - commit 25eb11c
  - wifi: iwlwifi: mvm: fix ROC version check (bsc#1227149).
  - wifi: iwlwifi: mvm: fix a crash on 7265 (bsc#1227149).
  - wifi: iwlwifi: Use request_module_nowait (bsc#1227149).
  - wifi: iwlwifi: mvm: don't always disable EMLSR due to BT coex
    (bsc#1227149).
  - wifi: iwlwifi: mvm: calculate EMLSR mode after connection
    (bsc#1227149).
  - wifi: iwlwifi: mvm: introduce esr_disable_reason (bsc#1227149).
  - wifi: iwlwifi: mvm: Do not warn on invalid link on scan complete
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support iwl_dev_tx_power_cmd_v8
    (bsc#1227149).
  - commit 74beb0b
  - net: mana: Fix possible double free in error handling path
    (git-fixes).
  - RDMA/mana_ib: Ignore optional access flags for MRs (git-fixes).
  - net: mana: Fix the extra HZ in mana_hwc_send_request
    (git-fixes).
  - commit cb4a2bd
  - wifi: iwlwifi: mvm: fix link ID management (bsc#1227149).
  - Revert "wifi: iwlwifi: bump FW API to 90 for BZ/SC devices"
    (bsc#1227149).
  - wifi: iwlwifi: mvm: handle debugfs names more carefully
    (bsc#1227149).
  - commit 1b2b558
  - wifi: iwlwifi: mvm: Configure the link mapping for non-MLD FW
    (bsc#1227149).
  - wifi: iwlwifi: mvm: consider having one active link
    (bsc#1227149).
  - wifi: iwlwifi: mvm: pick the version of SESSION_PROTECTION_NOTIF
    (bsc#1227149).
  - wifi: iwlwifi: mvm: disable MLO for the time being
    (bsc#1227149).
  - wifi: cfg80211: add a flag to disable wireless extensions
    (bsc#1227149).
  - iwlwifi: mvm: Use for_each_thermal_trip() for walking trip
    points (bsc#1227149).
  - iwlwifi: mvm: Populate trip table before registering thermal
    zone (bsc#1227149).
  - iwlwifi: mvm: Drop unused fw_trips_index[] from
    iwl_mvm_thermal_device (bsc#1227149).
  - commit 53ce28e
  - wifi: mac80211: add link id to ieee80211_gtk_rekey_add()
    (bsc#1227149).
  - wifi: iwlwifi: load b0 version of ucode for HR1/HR2
    (bsc#1227149).
  - wifi: iwlwifi: handle per-phy statistics from fw (bsc#1227149).
  - wifi: iwlwifi: iwl-fh.h: fix kernel-doc issues (bsc#1227149).
  - wifi: iwlwifi: api: fix kernel-doc reference (bsc#1227149).
  - wifi: iwlwifi: mvm: unlock mvm if there is no primary link
    (bsc#1227149).
  - wifi: iwlwifi: mvm: partially support PHY context version 6
    (bsc#1227149).
  - commit 590b6b6
  - wifi: iwlwifi: cancel session protection only if there is one
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove IWL_MVM_STATUS_NEED_FLUSH_P2P
    (bsc#1227149).
  - wifi: iwlwifi: mvm: check own capabilities for EMLSR
    (bsc#1227149).
  - wifi: iwlwifi: iwl-trans.h: clean up kernel-doc (bsc#1227149).
  - wifi: iwlwifi: fw: file: clean up kernel-doc (bsc#1227149).
  - wifi: iwlwifi: api: dbg-tlv: fix up kernel-doc (bsc#1227149).
  - wifi: iwlwifi: error-dump: fix kernel-doc issues (bsc#1227149).
  - commit b9417e2
  - wifi: iwlwifi: mvm: fix thermal kernel-doc (bsc#1227149).
  - wifi: iwlwifi: don't use TRUE/FALSE with bool (bsc#1227149).
  - wifi: iwlwifi: api: fix constant version to match FW
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Extend support for P2P service discovery
    (bsc#1227149).
  - wifi: iwlwifi: mvm: work around A-MSDU size problem
    (bsc#1227149).
  - wifi: iwlwifi: nvm: parse the VLP/AFC bit from regulatory
    (bsc#1227149).
  - wifi: iwlwifi: iwlmvm: handle unprotected deauth/disassoc in d3
    (bsc#1227149).
  - wifi: iwlwifi: fix #ifdef CONFIG_ACPI check (bsc#1227149).
  - wifi: iwlwifi: queue: improve warning for no skb in reclaim
    (bsc#1227149).
  - wifi: iwlwifi: mvm: move BA notif messages before action
    (bsc#1227149).
  - commit da274a5
  - wifi: cfg80211: report unprotected deauth/disassoc in wowlan
    (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 8a7655b
  - wifi: nl80211: allow reporting wakeup for unprot deauth/disassoc
    (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit e91caa5
  - wifi: cfg80211: rename UHB to 6 GHz (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 72d3017
  - wifi: iwlwifi: mvm: show skb_mac_gso_segment() failure reason
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove flags for enable/disable beacon
    filter (bsc#1227149).
  - wifi: iwlwifi: pcie: Add new PCI device id and CNVI
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't send the smart fifo command if not
    needed (bsc#1227149).
  - wifi: iwlwifi: fw: allow vmalloc for PNVM image (bsc#1227149).
  - wifi: iwlwifi: mvm: don't do duplicate detection for nullfunc
    packets (bsc#1227149).
  - wifi: iwlwifi: mvm: avoid garbage iPN (bsc#1227149).
  - wifi: iwlwifi: mvm: always update keys in D3 exit (bsc#1227149).
  - wifi: iwlwifi: mvm: limit pseudo-D3 to 60 seconds (bsc#1227149).
  - wifi: iwlwifi: mvm: combine condition/warning (bsc#1227149).
  - commit 9013bb7
  - wifi: iwlwifi: mvm: fix the key PN index (bsc#1227149).
  - wifi: iwlwifi: mvm: Keep connection in case of missed beacons
    during RX (bsc#1227149).
  - wifi: iwlwifi: properly check if link is active (bsc#1227149).
  - wifi: iwlwifi: take SGOM and UATS code out of ACPI ifdef
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't abort queue sync in CT-kill
    (bsc#1227149).
  - wifi: iwlwifi: mvm: define RX queue sync timeout as a macro
    (bsc#1227149).
  - wifi: iwlwifi: mvm: expand queue sync warning messages
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Declare support for secure LTF measurement
    (bsc#1227149).
  - wifi: iwlwifi: mvm: advertise support for protected ranging
    negotiation (bsc#1227149).
  - wifi: iwlwifi: mvm: remove one queue sync on BA session stop
    (bsc#1227149).
  - commit d32b4ac
  - wifi: iwlwifi: mvm: don't support reduced tx power on ack for
    new devices (bsc#1227149).
  - wifi: iwlwifi: use system_unbound_wq for debug dump
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove EHT code from mac80211.c
    (bsc#1227149).
  - wifi: iwlwifi: read mac step from aux register (bsc#1227149).
  - wifi: iwlwifi: adjust rx_phyinfo debugfs to MLO (bsc#1227149).
  - wifi: iwlwifi: mvm: const-ify chandef pointers (bsc#1227149).
  - wifi: iwlwifi: Add support for PPAG cmd v5 and PPAG revision 3
    (bsc#1227149).
  - wifi: iwlwifi: pcie: don't allow hw-rfkill to stop device on
    gen2 (bsc#1227149).
  - wifi: iwlwifi: add HONOR to PPAG approved list (bsc#1227149).
  - commit 6501846
  - wifi: mac80211: update beacon counters per link basis
    (bsc#1227149).
  - wifi: iwlwifi: return negative -EINVAL instead of positive
    EINVAL (bsc#1227149).
  - wifi: iwlwifi: fw: fix compiler warning for NULL string print
    (bsc#1227149).
  - wifi: iwlwifi: mvm: make functions public (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 88 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't send BT_COEX_CI command on new devices
    (bsc#1227149).
  - wifi: iwlwifi: read DSM functions from UEFI (bsc#1227149).
  - commit 4b3d0a2
  - wifi: iwlwifi: prepare for reading DSM from UEFI (bsc#1227149).
  - wifi: iwlwifi: simplify getting DSM from ACPI (bsc#1227149).
  - wifi: iwlwifi: take send-DSM-to-FW flows out of ACPI ifdef
    (bsc#1227149).
  - wifi: iwlwifi: rfi: use a single DSM function for all RFI
    configurations (bsc#1227149).
  - wifi: iwlwifi: read ECKV table from UEFI (bsc#1227149).
  - wifi: iwlwifi: read WRDD table from UEFI (bsc#1227149).
  - wifi: iwlwifi: support link command version 2 (bsc#1227149).
  - wifi: iwlwifi: mvm: use fast balance scan in case of an active
    P2P GO (bsc#1227149).
  - wifi: iwlwifi: mvm: don't send NDPs for new tx devices
    (bsc#1227149).
  - wifi: iwlwifi: read SPLC from UEFI (bsc#1227149).
  - commit 10d0457
  - wifi: iwlwifi: prepare for reading SPLC from UEFI (bsc#1227149).
  - wifi: iwlwifi: api: clean up some kernel-doc/typos
    (bsc#1227149).
  - wifi: iwlwifi: remove unused function prototype (bsc#1227149).
  - iwlwifi: fw: fix more kernel-doc warnings (bsc#1227149).
  - wifi: iwlwifi: read WTAS table from UEFI (bsc#1227149).
  - commit edb7009
  - wifi: iwlwifi: separate TAS 'read-from-BIOS' and 'send-to-FW'
    flows (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-warnings-from-dmi_get_system_in.patch.
  - commit cbe5734
  - wifi: iwlwifi: prepare for reading TAS table from UEFI
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-warnings-from-dmi_get_system_in.patch.
  - commit 37ff9f0
  - wifi: iwlwifi: don't check TAS block list size twice
    (bsc#1227149).
  - wifi: iwlwifi: read PPAG table from UEFI (bsc#1227149).
  - wifi: iwlwifi: validate PPAG table when sent to FW
    (bsc#1227149).
  - commit aab6534
  - wifi: iwlwifi: prepare for reading PPAG table from UEFI
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-fw-fix-compile-w-o-CONFIG_ACPI.patch.
  - commit b317fc2
  - wifi: iwlwifi: small cleanups in PPAG table flows (bsc#1227149).
  - wifi: iwlwifi: read SAR tables from UEFI (bsc#1227149).
  - wifi: iwlwifi: cleanup sending PER_CHAIN_LIMIT_OFFSET_CMD
    (bsc#1227149).
  - wifi: iwlwifi: prepare for reading SAR tables from UEFI
    (bsc#1227149).
  - wifi: iwlwifi: mvm: check AP supports EMLSR (bsc#1227149).
  - wifi: iwlwifi: mvm: d3: implement suspend with MLO
    (bsc#1227149).
  - wifi: iwlwifi: mvm: refactor duplicate chanctx condition
    (bsc#1227149).
  - wifi: iwlwifi: mvm: log dropped packets due to MIC error
    (bsc#1227149).
  - commit ab26861
  - wifi: iwlwifi: mvm: support SPP A-MSDUs (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-don-t-set-the-MFP-flag-for-the-GTK.patch.
  - commit d834590
  - wifi: mac80211: add support for SPP A-MSDUs (bsc#1227149).
  - commit 265cdf6
  - wifi: cfg80211: add support for SPP A-MSDUs (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit f498490
  - wifi: iwlwifi: implement GLAI ACPI table loading (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-fw-fix-compile-w-o-CONFIG_ACPI.patch.
  - commit 85303bc
  - wifi: iwlwifi: remove Gl A-step remnants (bsc#1227149).
  - wifi: iwlwifi: mvm: Fix FTM initiator flags (bsc#1227149).
  - wifi: iwlwifi: always have 'uats_enabled' (bsc#1227149).
  - wifi: iwlwifi: mvm: don't set trigger frame padding in AP mode
    (bsc#1227149).
  - wifi: iwlwifi: Fix spelling mistake "SESION" -> "SESSION"
    (bsc#1227149).
  - wifi: iwlwifi: mvm: add support for TID to link mapping neg
    request (bsc#1227149).
  - wifi: iwlwifi: cleanup uefi variables loading (bsc#1227149).
  - wifi: iwlwifi: mvm: disconnect station vifs if recovery failed
    (bsc#1227149).
  - wifi: iwlwifi: fw: dbg: ensure correct config name sizes
    (bsc#1227149).
  - commit ff842c3
  - wifi: ieee80211: add definitions for negotiated TID to Link map
    (bsc#1227149).
  - commit b1d66f3
  - wifi: mac80211: process and save negotiated TID to Link mapping
    request (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 32a5092
  - wifi: cfg80211: add RNR with reporting AP information
    (bsc#1227149).
  - commit 8fede1e
  - wifi: iwlwifi: implement can_activate_links callback
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-active-link-counting-during-rec.patch.
  - commit 7e399ce
  - wifi: iwlwifi: remove retry loops in start (bsc#1227149).
  - commit 3c4f0f3
  - wifi: iwlwifi: dbg-tlv: use struct_size() for allocation
    (bsc#1227149).
  - wifi: iwlwifi: dbg-tlv: avoid extra allocation/copy
    (bsc#1227149).
  - wifi: iwlwifi: fix some kernel-doc issues (bsc#1227149).
  - wifi: iwlwifi: mvm: d3: disconnect on GTK rekey failure
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Add support for removing responder TKs
    (bsc#1227149).
  - wifi: iwlwifi: disable eSR when BT is active (bsc#1227149).
  - wifi: iwlwifi: add support for a wiphy_work rx handler
    (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 87 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: mvm: introduce PHY_CONTEXT_CMD_API_VER_5
    (bsc#1227149).
  - wifi: iwlwifi: skip affinity setting on non-SMP (bsc#1227149).
  - wifi: iwlwifi: nvm-parse: advertise common packet padding
    (bsc#1227149).
  - wifi: iwlwifi: change link id in time event to s8 (bsc#1227149).
  - wifi: iwlwifi: mvm: limit EHT 320 MHz MCS for STEP URM
    (bsc#1227149).
  - wifi: iwlwifi: disable 160 MHz based on subsystem device ID
    (bsc#1227149).
  - wifi: iwlwifi: make TB reallocation a debug message
    (bsc#1227149).
  - wifi: iwlwifi: Add support for new 802.11be device
    (bsc#1227149).
  - commit 6617b64
  - pmdomain: imx8mp-blk-ctrl: imx8mp_blk: Add fdcc clock to
    hdmimix domain (CVE-2024-35942 bsc#1224589).
  - commit cf74548
  - platform/x86: toshiba_acpi: Fix array out-of-bounds access
    (git-fixes).
  - ACPI: processor_idle: Fix invalid comparison with insertion
    sort for latency (git-fixes).
  - commit ec2c4bc
  - KVM: SEV-ES: Delegate LBR virtualization to the processor
    (git-fixes).
  - commit ca0a7e8

++++ kernel-rt:

  - Refresh patches.kabi/wireless-kabi-workaround.patch (bsc#1227149)
    More fixes for 6.9 API updates
  - commit 25eb11c
  - wifi: iwlwifi: mvm: fix ROC version check (bsc#1227149).
  - wifi: iwlwifi: mvm: fix a crash on 7265 (bsc#1227149).
  - wifi: iwlwifi: Use request_module_nowait (bsc#1227149).
  - wifi: iwlwifi: mvm: don't always disable EMLSR due to BT coex
    (bsc#1227149).
  - wifi: iwlwifi: mvm: calculate EMLSR mode after connection
    (bsc#1227149).
  - wifi: iwlwifi: mvm: introduce esr_disable_reason (bsc#1227149).
  - wifi: iwlwifi: mvm: Do not warn on invalid link on scan complete
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support iwl_dev_tx_power_cmd_v8
    (bsc#1227149).
  - commit 74beb0b
  - net: mana: Fix possible double free in error handling path
    (git-fixes).
  - RDMA/mana_ib: Ignore optional access flags for MRs (git-fixes).
  - net: mana: Fix the extra HZ in mana_hwc_send_request
    (git-fixes).
  - commit cb4a2bd
  - wifi: iwlwifi: mvm: fix link ID management (bsc#1227149).
  - Revert "wifi: iwlwifi: bump FW API to 90 for BZ/SC devices"
    (bsc#1227149).
  - wifi: iwlwifi: mvm: handle debugfs names more carefully
    (bsc#1227149).
  - commit 1b2b558
  - wifi: iwlwifi: mvm: Configure the link mapping for non-MLD FW
    (bsc#1227149).
  - wifi: iwlwifi: mvm: consider having one active link
    (bsc#1227149).
  - wifi: iwlwifi: mvm: pick the version of SESSION_PROTECTION_NOTIF
    (bsc#1227149).
  - wifi: iwlwifi: mvm: disable MLO for the time being
    (bsc#1227149).
  - wifi: cfg80211: add a flag to disable wireless extensions
    (bsc#1227149).
  - iwlwifi: mvm: Use for_each_thermal_trip() for walking trip
    points (bsc#1227149).
  - iwlwifi: mvm: Populate trip table before registering thermal
    zone (bsc#1227149).
  - iwlwifi: mvm: Drop unused fw_trips_index[] from
    iwl_mvm_thermal_device (bsc#1227149).
  - commit 53ce28e
  - wifi: mac80211: add link id to ieee80211_gtk_rekey_add()
    (bsc#1227149).
  - wifi: iwlwifi: load b0 version of ucode for HR1/HR2
    (bsc#1227149).
  - wifi: iwlwifi: handle per-phy statistics from fw (bsc#1227149).
  - wifi: iwlwifi: iwl-fh.h: fix kernel-doc issues (bsc#1227149).
  - wifi: iwlwifi: api: fix kernel-doc reference (bsc#1227149).
  - wifi: iwlwifi: mvm: unlock mvm if there is no primary link
    (bsc#1227149).
  - wifi: iwlwifi: mvm: partially support PHY context version 6
    (bsc#1227149).
  - commit 590b6b6
  - wifi: iwlwifi: cancel session protection only if there is one
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove IWL_MVM_STATUS_NEED_FLUSH_P2P
    (bsc#1227149).
  - wifi: iwlwifi: mvm: check own capabilities for EMLSR
    (bsc#1227149).
  - wifi: iwlwifi: iwl-trans.h: clean up kernel-doc (bsc#1227149).
  - wifi: iwlwifi: fw: file: clean up kernel-doc (bsc#1227149).
  - wifi: iwlwifi: api: dbg-tlv: fix up kernel-doc (bsc#1227149).
  - wifi: iwlwifi: error-dump: fix kernel-doc issues (bsc#1227149).
  - commit b9417e2
  - wifi: iwlwifi: mvm: fix thermal kernel-doc (bsc#1227149).
  - wifi: iwlwifi: don't use TRUE/FALSE with bool (bsc#1227149).
  - wifi: iwlwifi: api: fix constant version to match FW
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Extend support for P2P service discovery
    (bsc#1227149).
  - wifi: iwlwifi: mvm: work around A-MSDU size problem
    (bsc#1227149).
  - wifi: iwlwifi: nvm: parse the VLP/AFC bit from regulatory
    (bsc#1227149).
  - wifi: iwlwifi: iwlmvm: handle unprotected deauth/disassoc in d3
    (bsc#1227149).
  - wifi: iwlwifi: fix #ifdef CONFIG_ACPI check (bsc#1227149).
  - wifi: iwlwifi: queue: improve warning for no skb in reclaim
    (bsc#1227149).
  - wifi: iwlwifi: mvm: move BA notif messages before action
    (bsc#1227149).
  - commit da274a5
  - wifi: cfg80211: report unprotected deauth/disassoc in wowlan
    (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 8a7655b
  - wifi: nl80211: allow reporting wakeup for unprot deauth/disassoc
    (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit e91caa5
  - wifi: cfg80211: rename UHB to 6 GHz (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 72d3017
  - wifi: iwlwifi: mvm: show skb_mac_gso_segment() failure reason
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove flags for enable/disable beacon
    filter (bsc#1227149).
  - wifi: iwlwifi: pcie: Add new PCI device id and CNVI
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't send the smart fifo command if not
    needed (bsc#1227149).
  - wifi: iwlwifi: fw: allow vmalloc for PNVM image (bsc#1227149).
  - wifi: iwlwifi: mvm: don't do duplicate detection for nullfunc
    packets (bsc#1227149).
  - wifi: iwlwifi: mvm: avoid garbage iPN (bsc#1227149).
  - wifi: iwlwifi: mvm: always update keys in D3 exit (bsc#1227149).
  - wifi: iwlwifi: mvm: limit pseudo-D3 to 60 seconds (bsc#1227149).
  - wifi: iwlwifi: mvm: combine condition/warning (bsc#1227149).
  - commit 9013bb7
  - wifi: iwlwifi: mvm: fix the key PN index (bsc#1227149).
  - wifi: iwlwifi: mvm: Keep connection in case of missed beacons
    during RX (bsc#1227149).
  - wifi: iwlwifi: properly check if link is active (bsc#1227149).
  - wifi: iwlwifi: take SGOM and UATS code out of ACPI ifdef
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't abort queue sync in CT-kill
    (bsc#1227149).
  - wifi: iwlwifi: mvm: define RX queue sync timeout as a macro
    (bsc#1227149).
  - wifi: iwlwifi: mvm: expand queue sync warning messages
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Declare support for secure LTF measurement
    (bsc#1227149).
  - wifi: iwlwifi: mvm: advertise support for protected ranging
    negotiation (bsc#1227149).
  - wifi: iwlwifi: mvm: remove one queue sync on BA session stop
    (bsc#1227149).
  - commit d32b4ac
  - wifi: iwlwifi: mvm: don't support reduced tx power on ack for
    new devices (bsc#1227149).
  - wifi: iwlwifi: use system_unbound_wq for debug dump
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove EHT code from mac80211.c
    (bsc#1227149).
  - wifi: iwlwifi: read mac step from aux register (bsc#1227149).
  - wifi: iwlwifi: adjust rx_phyinfo debugfs to MLO (bsc#1227149).
  - wifi: iwlwifi: mvm: const-ify chandef pointers (bsc#1227149).
  - wifi: iwlwifi: Add support for PPAG cmd v5 and PPAG revision 3
    (bsc#1227149).
  - wifi: iwlwifi: pcie: don't allow hw-rfkill to stop device on
    gen2 (bsc#1227149).
  - wifi: iwlwifi: add HONOR to PPAG approved list (bsc#1227149).
  - commit 6501846
  - wifi: mac80211: update beacon counters per link basis
    (bsc#1227149).
  - wifi: iwlwifi: return negative -EINVAL instead of positive
    EINVAL (bsc#1227149).
  - wifi: iwlwifi: fw: fix compiler warning for NULL string print
    (bsc#1227149).
  - wifi: iwlwifi: mvm: make functions public (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 88 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't send BT_COEX_CI command on new devices
    (bsc#1227149).
  - wifi: iwlwifi: read DSM functions from UEFI (bsc#1227149).
  - commit 4b3d0a2
  - wifi: iwlwifi: prepare for reading DSM from UEFI (bsc#1227149).
  - wifi: iwlwifi: simplify getting DSM from ACPI (bsc#1227149).
  - wifi: iwlwifi: take send-DSM-to-FW flows out of ACPI ifdef
    (bsc#1227149).
  - wifi: iwlwifi: rfi: use a single DSM function for all RFI
    configurations (bsc#1227149).
  - wifi: iwlwifi: read ECKV table from UEFI (bsc#1227149).
  - wifi: iwlwifi: read WRDD table from UEFI (bsc#1227149).
  - wifi: iwlwifi: support link command version 2 (bsc#1227149).
  - wifi: iwlwifi: mvm: use fast balance scan in case of an active
    P2P GO (bsc#1227149).
  - wifi: iwlwifi: mvm: don't send NDPs for new tx devices
    (bsc#1227149).
  - wifi: iwlwifi: read SPLC from UEFI (bsc#1227149).
  - commit 10d0457
  - wifi: iwlwifi: prepare for reading SPLC from UEFI (bsc#1227149).
  - wifi: iwlwifi: api: clean up some kernel-doc/typos
    (bsc#1227149).
  - wifi: iwlwifi: remove unused function prototype (bsc#1227149).
  - iwlwifi: fw: fix more kernel-doc warnings (bsc#1227149).
  - wifi: iwlwifi: read WTAS table from UEFI (bsc#1227149).
  - commit edb7009
  - wifi: iwlwifi: separate TAS 'read-from-BIOS' and 'send-to-FW'
    flows (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-warnings-from-dmi_get_system_in.patch.
  - commit cbe5734
  - wifi: iwlwifi: prepare for reading TAS table from UEFI
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-warnings-from-dmi_get_system_in.patch.
  - commit 37ff9f0
  - wifi: iwlwifi: don't check TAS block list size twice
    (bsc#1227149).
  - wifi: iwlwifi: read PPAG table from UEFI (bsc#1227149).
  - wifi: iwlwifi: validate PPAG table when sent to FW
    (bsc#1227149).
  - commit aab6534
  - wifi: iwlwifi: prepare for reading PPAG table from UEFI
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-fw-fix-compile-w-o-CONFIG_ACPI.patch.
  - commit b317fc2
  - wifi: iwlwifi: small cleanups in PPAG table flows (bsc#1227149).
  - wifi: iwlwifi: read SAR tables from UEFI (bsc#1227149).
  - wifi: iwlwifi: cleanup sending PER_CHAIN_LIMIT_OFFSET_CMD
    (bsc#1227149).
  - wifi: iwlwifi: prepare for reading SAR tables from UEFI
    (bsc#1227149).
  - wifi: iwlwifi: mvm: check AP supports EMLSR (bsc#1227149).
  - wifi: iwlwifi: mvm: d3: implement suspend with MLO
    (bsc#1227149).
  - wifi: iwlwifi: mvm: refactor duplicate chanctx condition
    (bsc#1227149).
  - wifi: iwlwifi: mvm: log dropped packets due to MIC error
    (bsc#1227149).
  - commit ab26861
  - wifi: iwlwifi: mvm: support SPP A-MSDUs (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-don-t-set-the-MFP-flag-for-the-GTK.patch.
  - commit d834590
  - wifi: mac80211: add support for SPP A-MSDUs (bsc#1227149).
  - commit 265cdf6
  - wifi: cfg80211: add support for SPP A-MSDUs (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit f498490
  - wifi: iwlwifi: implement GLAI ACPI table loading (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-fw-fix-compile-w-o-CONFIG_ACPI.patch.
  - commit 85303bc
  - wifi: iwlwifi: remove Gl A-step remnants (bsc#1227149).
  - wifi: iwlwifi: mvm: Fix FTM initiator flags (bsc#1227149).
  - wifi: iwlwifi: always have 'uats_enabled' (bsc#1227149).
  - wifi: iwlwifi: mvm: don't set trigger frame padding in AP mode
    (bsc#1227149).
  - wifi: iwlwifi: Fix spelling mistake "SESION" -> "SESSION"
    (bsc#1227149).
  - wifi: iwlwifi: mvm: add support for TID to link mapping neg
    request (bsc#1227149).
  - wifi: iwlwifi: cleanup uefi variables loading (bsc#1227149).
  - wifi: iwlwifi: mvm: disconnect station vifs if recovery failed
    (bsc#1227149).
  - wifi: iwlwifi: fw: dbg: ensure correct config name sizes
    (bsc#1227149).
  - commit ff842c3
  - wifi: ieee80211: add definitions for negotiated TID to Link map
    (bsc#1227149).
  - commit b1d66f3
  - wifi: mac80211: process and save negotiated TID to Link mapping
    request (bsc#1227149).
  - Refresh patches.kabi/wireless-kabi-workaround.patch.
  - commit 32a5092
  - wifi: cfg80211: add RNR with reporting AP information
    (bsc#1227149).
  - commit 8fede1e
  - wifi: iwlwifi: implement can_activate_links callback
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-active-link-counting-during-rec.patch.
  - commit 7e399ce
  - wifi: iwlwifi: remove retry loops in start (bsc#1227149).
  - commit 3c4f0f3
  - wifi: iwlwifi: dbg-tlv: use struct_size() for allocation
    (bsc#1227149).
  - wifi: iwlwifi: dbg-tlv: avoid extra allocation/copy
    (bsc#1227149).
  - wifi: iwlwifi: fix some kernel-doc issues (bsc#1227149).
  - wifi: iwlwifi: mvm: d3: disconnect on GTK rekey failure
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Add support for removing responder TKs
    (bsc#1227149).
  - wifi: iwlwifi: disable eSR when BT is active (bsc#1227149).
  - wifi: iwlwifi: add support for a wiphy_work rx handler
    (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 87 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: mvm: introduce PHY_CONTEXT_CMD_API_VER_5
    (bsc#1227149).
  - wifi: iwlwifi: skip affinity setting on non-SMP (bsc#1227149).
  - wifi: iwlwifi: nvm-parse: advertise common packet padding
    (bsc#1227149).
  - wifi: iwlwifi: change link id in time event to s8 (bsc#1227149).
  - wifi: iwlwifi: mvm: limit EHT 320 MHz MCS for STEP URM
    (bsc#1227149).
  - wifi: iwlwifi: disable 160 MHz based on subsystem device ID
    (bsc#1227149).
  - wifi: iwlwifi: make TB reallocation a debug message
    (bsc#1227149).
  - wifi: iwlwifi: Add support for new 802.11be device
    (bsc#1227149).
  - commit 6617b64
  - pmdomain: imx8mp-blk-ctrl: imx8mp_blk: Add fdcc clock to
    hdmimix domain (CVE-2024-35942 bsc#1224589).
  - commit cf74548
  - platform/x86: toshiba_acpi: Fix array out-of-bounds access
    (git-fixes).
  - ACPI: processor_idle: Fix invalid comparison with insertion
    sort for latency (git-fixes).
  - commit ec2c4bc
  - KVM: SEV-ES: Delegate LBR virtualization to the processor
    (git-fixes).
  - commit ca0a7e8

++++ libselinux:

  - Fix segfault caused by upstream changes in selabel_open():
    libselinux-set-free-d-data-to-NULL.patch
    Can be removed once it is upstream.

++++ libsolv:

  - removed dependency on external find program in the repo2solv tool
  - bindings: fix return value of repodata.add_solv()
  - new SOLVER_FLAG_FOCUS_NEW flag
  - bump version to 0.7.30

++++ sssd:

  - Revert the change dropping the default configuration file. If
    /usr/etc exists will be installed there, otherwise in /etc.
    (bsc#1226157);

++++ systemd:

  - Make sure systemd-sysvcompat replaces systemd-sysvinit on upgrades (bsc#1218110)

++++ microos-tools:

  - Update to version 2.21+git13:
    * Don't run in the zipl initrd "initgrub" mode

++++ nvidia-open-driver-G06-signed:

  - Update to version 555.42.06 for CUDA. This tag has become
    available in github, now.

++++ python-MarkupSafe:

  - add buildignores to break buildcycle over
    p11-kit/dbus-1/systemd:mini/python-MarkupSafe

++++ python-Pygments:

  - add buildignores to avoid bootstrap buildcycle
    p11-kit/gtk-doc/python-Pygments which comes via
    pip/ca-certificates

++++ python-jsonschema:

  - update to 4.23.0:
    * Add some typing to the exceptions.py module by @DanielNoord in
    [#1019]
    * Declare support for 3.13 by @rominf in #1282

------------------------------------------------------------------
------------------  2024-7-10  -  Jul 10 2024  -------------------
------------------------------------------------------------------

++++ container-selinux:

  - Update to version 2.232.1:
    * Bump to v2.232.1
    * TMT: fix srpm download syntax on rawhide
    * Bump to 2.232.0
    * Packit: remove `update_release` key from downstream jobs (#313)
    * Update container-selinux.8 man page
    * Add ownership of /usr/share/udica (#312)
    * Packit/TMT: upstream maintenance of downstream gating tests
    * extend container_engine_t again
    * Allow spc_t to use localectl
    * Allow spc_t to use timedatectl
    * introduce container_use_xserver_devices boolean to allow GPU access

++++ python-kiwi:

  - Update integration test for eficsm
    Update the type of the Secure profile of the live image integration
    test as well as the type of the simple-disk test to make use of the
    eficsm="false" attribute to switch off CSM mode and test an EFI only
    layout.
  - Add new eficsm type attribute
    Allow to produce EFI/UEFI images without hybrid CSM
    capabilities. This Fixes #2407
  - kiwi_plugin_architecture.rst
  - Revise kiwi_from_python.rst
  - Wait for loop device detach to complete
    Detaching a loop device via 'losetup -d' is an async operation.
    Once the command returns the loop can still be associated with
    the block special. Therefore this commit waits until the block
    device got released or a timeout is hit. This Fixes #2580

++++ ipmitool:

  - Added ipmitool-fix_init_from_incompat_ptr_type.patch fixing a type
    which led to assignment from incompatible pointer type which is an
    error in GCC 14 [boo#1225992]

++++ kernel-default:

  - KVM: x86: Always sync PIR to IRR prior to scanning I/O APIC
    routes (git-fixes).
  - commit 6653b01
  - KVM: SEV-ES: Disallow SEV-ES guests when X86_FEATURE_LBRV is
    absent (git-fixes).
  - commit 1094992
  - KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked
    (git-fixes).
  - commit 2cc4a9c
  - drivers/xen: Improve the late XenStore init protocol
    (git-fixes).
  - commit cb805fb
  - xen/x86: add extra pages to unpopulated-alloc if available
    (git-fixes).
  - commit d9de7d9
  - kunit: Fix checksum tests on big endian CPUs (git-fixed).
  - commit 91a58a6
  - KVM: arm64: Fix circular locking dependency (bsc#1222463 CVE-2024-26691).
  - commit 3273efe
  - Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted (bsc#1225744, CVE-2024-36909).
  - uio_hv_generic: Don't free decrypted memory (bsc#1225717, CVE-2024-36910).
  - hv_netvsc: Don't free decrypted memory (bsc#1225745, CVE-2024-36911).
  - Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl (bsc#1225752, CVE-2024-36912).
  - Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails (bsc#1225753, CVE-2024-36913).
  - commit a78a9db
  - x86/speculation, objtool: Use absolute relocations for annotations (git-fixes).
  - commit 14e0989
  - x86/head/64: Move the __head definition to <asm/init.h> (git-fixes).
  - commit 36d1750
  - x86/csum: Remove unnecessary odd handling (git-fixes).
  - commit 439ef62
  - x86/csum: Fix clang -Wuninitialized in csum_partial() (git-fixes).
  - commit 98db437
  - x86/csum: Improve performance of `csum_partial` (git-fixes).
  - commit 131cca3
  - x86/boot: Ignore NMIs during very early boot (git-fixes).
  - commit 3c94948
  - x86/asm: Fix build of UML with KASAN (git-fixes).
  - commit 89fc5d7
  - tunnels: fix out of bounds access when building IPv6 PMTU error (bsc#1222328 CVE-2024-26665).
  - commit f28b881
  - SUNRPC: avoid soft lockup when transmitting UDP to reachable
    server (bsc#1225272).
  - commit 3fc313b

++++ kernel-rt:

  - KVM: x86: Always sync PIR to IRR prior to scanning I/O APIC
    routes (git-fixes).
  - commit 6653b01
  - KVM: SEV-ES: Disallow SEV-ES guests when X86_FEATURE_LBRV is
    absent (git-fixes).
  - commit 1094992
  - KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked
    (git-fixes).
  - commit 2cc4a9c
  - drivers/xen: Improve the late XenStore init protocol
    (git-fixes).
  - commit cb805fb
  - xen/x86: add extra pages to unpopulated-alloc if available
    (git-fixes).
  - commit d9de7d9
  - kunit: Fix checksum tests on big endian CPUs (git-fixed).
  - commit 91a58a6
  - KVM: arm64: Fix circular locking dependency (bsc#1222463 CVE-2024-26691).
  - commit 3273efe
  - Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted (bsc#1225744, CVE-2024-36909).
  - uio_hv_generic: Don't free decrypted memory (bsc#1225717, CVE-2024-36910).
  - hv_netvsc: Don't free decrypted memory (bsc#1225745, CVE-2024-36911).
  - Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl (bsc#1225752, CVE-2024-36912).
  - Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails (bsc#1225753, CVE-2024-36913).
  - commit a78a9db
  - x86/speculation, objtool: Use absolute relocations for annotations (git-fixes).
  - commit 14e0989
  - x86/head/64: Move the __head definition to <asm/init.h> (git-fixes).
  - commit 36d1750
  - x86/csum: Remove unnecessary odd handling (git-fixes).
  - commit 439ef62
  - x86/csum: Fix clang -Wuninitialized in csum_partial() (git-fixes).
  - commit 98db437
  - x86/csum: Improve performance of `csum_partial` (git-fixes).
  - commit 131cca3
  - x86/boot: Ignore NMIs during very early boot (git-fixes).
  - commit 3c94948
  - x86/asm: Fix build of UML with KASAN (git-fixes).
  - commit 89fc5d7
  - tunnels: fix out of bounds access when building IPv6 PMTU error (bsc#1222328 CVE-2024-26665).
  - commit f28b881
  - SUNRPC: avoid soft lockup when transmitting UDP to reachable
    server (bsc#1225272).
  - commit 3fc313b

++++ libesmtp:

  - Added libesmtp-c99.patch which adds a required feature macro
    definition so that strlcpy function is properly declared in the
    standard header file.  [boo#1225800]

++++ mozilla-nss:

  - Added nss-fips-safe-memset.patch, fixing bsc#1222811.
  - Removed some dead code from nss-fips-constructor-self-tests.patch.
  - Rebased nss-fips-approved-crypto-non-ec.patch on above changes.
  - Added nss-fips-aes-gcm-restrict.patch, fixing bsc#1222830.
  - Updated nss-fips-approved-crypto-non-ec.patch, fixing bsc#1222813,
    bsc#1222814, bsc#1222821, bsc#1222822, bsc#1224118.
  - Updated nss-fips-approved-crypto-non-ec.patch and
    nss-fips-constructor-self-tests.patch, fixing bsc#1222807,
    bsc#1222828, bsc#1222834.
  - Updated nss-fips-approved-crypto-non-ec.patch, fixing bsc#1222804,
    bsc#1222826, bsc#1222833, bsc#1224113, bsc#1224115, bsc#1224116.
  - update to NSS 3.101.1
    * bmo#1901932 - missing sqlite header.
    * bmo#1901080 - GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.
  - update to NSS 3.101
    * bmo#1900413 - add diagnostic assertions for SFTKObject refcount.
    * bmo#1899759 - freeing the slot in DeleteCertAndKey if authentication failed
    * bmo#1899883 - fix formatting issues.
    * bmo#1889671 - Add Firmaprofesional CA Root-A Web to NSS.
    * bmo#1899593 - remove invalid acvp fuzz test vectors.
    * bmo#1898830 - pad short P-384 and P-521 signatures gtests.
    * bmo#1898627 - remove unused FreeBL ECC code.
    * bmo#1898830 - pad short P-384 and P-521 signatures.
    * bmo#1898825 - be less strict about ECDSA private key length.
    * bmo#1854439 - Integrate HACL* P-521.
    * bmo#1854438 - Integrate HACL* P-384.
    * bmo#1898074 - memory leak in create_objects_from_handles.
    * bmo#1898858 - ensure all input is consumed in a few places in mozilla::pkix
    * bmo#1884444 - SMIME/CMS and PKCS #12 do not integrate with modern NSS policy
    * bmo#1748105 - clean up escape handling
    * bmo#1896353 - Use lib::pkix as default validator instead of the old-one
    * bmo#1827444 - Need to add high level support for PQ signing.
    * bmo#1548723 - Certificate Compression: changing the allocation/freeing of buffer + Improving the documentation
    * bmo#1884444 - SMIME/CMS and PKCS #12 do not integrate with modern NSS policy
    * bmo#1893404 - Allow for non-full length ecdsa signature when using softoken
    * bmo#1830415 - Modification of .taskcluster.yml due to mozlint indent defects
    * bmo#1793811 - Implement support for PBMAC1 in PKCS#12
    * bmo#1897487 - disable VLA warnings for fuzz builds.
    * bmo#1895032 - remove redundant AllocItem implementation.
    * bmo#1893334 - add PK11_ReadDistrustAfterAttribute.
    * bmo#215997  - Clang-formatting of SEC_GetMgfTypeByOidTag update
    * bmo#1895012 - Set SEC_ERROR_LIBRARY_FAILURE on self-test failure
    * bmo#1894572 - sftk_getParameters(): Fix fallback to default variable after error with configfile.
    * bmo#1830415 - Switch to the mozillareleases/image_builder image
  - Follow upstream changes in nss-fips-constructor-self-tests.patch (switch from ec_field_GFp to ec_field_plain)
  - Remove part of nss-fips-zeroization.patch that got removed upstream
  - update to NSS 3.100
  - bmo#1893029 - merge pk11_kyberSlotList into pk11_ecSlotList for
    faster Xyber operations.
  - bmo#1893752 - remove ckcapi.
  - bmo#1893162 - avoid a potential PK11GenericObject memory leak.
  - bmo#671060  - Remove incomplete ESDH code.
  - bmo#215997  - Decrypt RSA OAEP encrypted messages.
  - bmo#1887996 - Fix certutil CRLDP URI code.
  - bmo#1890069 - Don't set CKA_DERIVE for CKK_EC_EDWARDS private keys.
  - bmo#676118  - Add ability to encrypt and decrypt CMS messages using ECDH.
  - bmo#676100  - Correct Templates for key agreement in smime/cmsasn.c.
  - bmo#1548723 - Moving the decodedCert allocation to NSS.
  - bmo#1885404 - Allow developers to speed up repeated local execution
    of NSS tests that depend on certificates.
  - update to NSS 3.99
    * Removing check for message len in ed25519 (bmo#1325335)
    * add ed25519 to SECU_ecName2params. (bmo#1884276)
    * add EdDSA wycheproof tests. (bmo#1325335)
    * nss/lib layer code for EDDSA. (bmo#1325335)
    * Adding EdDSA implementation. (bmo#1325335)
    * Exporting Certificate Compression types (bmo#1881027)
    * Updating ACVP docker to rust 1.74 (bmo#1880857)
    * Updating HACL* to 0f136f28935822579c244f287e1d2a1908a7e552 (bmo#1325335)
    * Add NSS_CMSRecipient_IsSupported. (bmo#1877730)
  - update to NSS 3.98
    * bmo#1780432 - (CVE-2023-5388) Timing attack against RSA decryption
    in TLS
    * bmo#1879513 - Certificate Compression: enabling the check that
    the compression was advertised
    * bmo#1831552 - Move Windows workers to nss-1/b-win2022-alpha
    * bmo#1879945 - Remove Email trust bit from OISTE WISeKey
    Global Root GC CA
    * bmo#1877344 - Replace `distutils.spawn.find_executable` with
    `shutil.which` within `mach` in `nss`
    * bmo#1548723 - Certificate Compression: Updating nss_bogo_shim to
    support Certificate compression
    * bmo#1548723 - TLS Certificate Compression (RFC 8879) Implementation
    * bmo#1875356 - Add valgrind annotations to freebl kyber operations
    for constant-time execution tests
    * bmo#1870673 - Set nssckbi version number to 2.66
    * bmo#1874017 - Add Telekom Security roots
    * bmo#1873095 - Add D-Trust 2022 S/MIME roots
    * bmo#1865450 - Remove expired Security Communication RootCA1 root
    * bmo#1876179 - move keys to a slot that supports concatenation in
    PK11_ConcatSymKeys
    * bmo#1876800 - remove unmaintained tls-interop tests
    * bmo#1874937 - bogo: add support for the -ipv6 and -shim-id shim
    flags
    * bmo#1874937 - bogo: add support for the -curves shim flag and
    update Kyber expectations
    * bmo#1874937 - bogo: adjust expectation for a key usage bit test
    * bmo#1757758 - mozpkix: add option to ignore invalid subject
    alternative names
    * bmo#1841029 - Fix selfserv not stripping `publicname:` from -X value
    * bmo#1876390 - take ownership of ecckilla shims
    * bmo#1874458 - add valgrind annotations to freebl/ec.c
    * bmo#864039  - PR_INADDR_ANY needs PR_htonl before assignment to inet.ip
    * bmo#1875965 - Update zlib to 1.3.1
  - Use %patch -P N instead of deprecated %patchN.
  - update to NSS 3.97
    * bmo#1875506 - make Xyber768d00 opt-in by policy
    * bmo#1871631 - add libssl support for xyber768d00
    * bmo#1871630 - add PK11_ConcatSymKeys
    * bmo#1775046 - add Kyber and a PKCS#11 KEM interface to softoken
    * bmo#1871152 - add a FreeBL API for Kyber
    * bmo#1826451 - part 2: vendor github.com/pq-crystals/kyber/commit/e0d1c6ff
    * bmo#1826451 - part 1: add a script for vendoring kyber from pq-crystals repo
    * bmo#1835828 - Removing the calls to RSA Blind from loader.*
    * bmo#1874111 - fix worker type for level3 mac tasks
    * bmo#1835828 - RSA Blind implementation
    * bmo#1869642 - Remove DSA selftests
    * bmo#1873296 - read KWP testvectors from JSON
    * bmo#1822450 - Backed out changeset dcb174139e4f
    * bmo#1822450 - Fix CKM_PBE_SHA1_DES2_EDE_CBC derivation
    * bmo#1871219 - Wrap CC shell commands in gyp expansions
  - update to NSS 3.96.1
    * bmo#1869408 - Use pypi dependencies for MacOS worker in ./build_gyp.sh
    * bmo#1830978 - p7sign: add -a hash and -u certusage (also p7verify cleanups)
    * bmo#1867408 - add a defensive check for large ssl_DefSend return values
    * bmo#1869378 - Add dependency to the taskcluster script for Darwin
    * bmo#1869378 - Upgrade version of the MacOS worker for the CI
  - add nss-allow-slow-tests-s390x.patch: "certutil dump keys with
    explicit default trust flags" test needs longer than the allowed
    6 seconds on s390x
  - update to NSS 3.95
    * bmo#1842932 - Bump builtins version number.
    * bmo#1851044 - Remove Email trust bit from Autoridad de Certificacion
    Firmaprofesional CIF A62634068 root cert.
    * bmo#1855318 - Remove 4 DigiCert (Symantec/Verisign) Root Certificates
    * bmo#1851049 - Remove 3 TrustCor Root Certificates from NSS.
    * bmo#1850982 - Remove Camerfirma root certificates from NSS.
    * bmo#1842935 - Remove old Autoridad de Certificacion Firmaprofesional
    Certificate.
    * bmo#1860670 - Add four Commscope root certificates to NSS.
    * bmo#1850598 - Add TrustAsia Global Root CA G3 and G4 root certificates.
    * bmo#1863605 - Include P-384 and P-521 Scalar Validation from HACL*
    * bmo#1861728 - Include P-256 Scalar Validation from HACL*.
    * bmo#1861265 - After the HACL 256 ECC patch, NSS incorrectly encodes
    256 ECC without DER wrapping at the softoken level
    * bmo#1837987 - Add means to provide library parameters to C_Initialize
    * bmo#1573097 - clang format
    * bmo#1854795 - add OSXSAVE and XCR0 tests to AVX2 detection.
    * bmo#1858241 - Typo in ssl3_AppendHandshakeNumber
    * bmo#1858241 - Introducing input check of ssl3_AppendHandshakeNumber
    * bmo#1573097 - Fix Invalid casts in instance.c
  - update to NSS 3.94
    * bmo#1853737 - Updated code and commit ID for HACL*
    * bmo#1840510 - update ACVP fuzzed test vector: refuzzed with
    current NSS
    * bmo#1827303 - Softoken C_ calls should use system FIPS setting
    to select NSC_ or FC_ variants
    * bmo#1774659 - NSS needs a database tool that can dump the low level
    representation of the database
    * bmo#1852179 - declare string literals using char in pkixnames_tests.cpp
    * bmo#1852179 - avoid implicit conversion for ByteString
    * bmo#1818766 - update rust version for acvp docker
    * bmo#1852011 - Moving the init function of the mpi_ints before
    clean-up in ec.c
    * bmo#1615555 - P-256 ECDH and ECDSA from HACL*
    * bmo#1840510 - Add ACVP test vectors to the repository
    * bmo#1849077 - Stop relying on std::basic_string<uint8_t>
    * bmo#1847845 - Transpose the PPC_ABI check from Makefile to gyp
  - rebased patches
  - added nss-fips-test.patch to fix broken test
  - Update to NSS 3.93:
    * bmo#1849471 - Update zlib in NSS to 1.3.
    * bmo#1848183 - softoken: iterate hashUpdate calls for long inputs.
    * bmo#1813401 - regenerate NameConstraints test certificates (boo#1214980).
  - Rebase nss-fips-pct-pubkeys.patch.
  - update to NSS 3.92
    * bmo#1822935 - Set nssckbi version number to 2.62
    * bmo#1833270 - Add 4 Atos TrustedRoot Root CA certificates to NSS
    * bmo#1839992 - Add 4 SSL.com Root CA certificates
    * bmo#1840429 - Add Sectigo E46 and R46 Root CA certificates
    * bmo#1840437 - Add LAWtrust Root CA2 (4096)
    * bmo#1822936 - Remove E-Tugra Certification Authority root
    * bmo#1827224 - Remove Camerfirma Chambers of Commerce Root.
    * bmo#1840505 - Remove Hongkong Post Root CA 1
    * bmo#1842928 - Remove E-Tugra Global Root CA ECC v3 and RSA v3
    * bmo#1842937 - Avoid redefining BYTE_ORDER on hppa Linux
  - update to NSS 3.91
    * bmo#1837431 - Implementation of the HW support check for ADX instruction
    * bmo#1836925 - Removing the support of Curve25519
    * bmo#1839795 - Fix comment about the addition of ticketSupportsEarlyData
    * bmo#1839327 - Adding args to enable-legacy-db build
    * bmo#1835357 - dbtests.sh failure in "certutil dump keys with explicit
    default trust flags"
    * bmo#1837617 - Initialize flags in slot structures
    * bmo#1835425 - Improve the length check of RSA input to avoid heap overflow
    * bmo#1829112 - Followup Fixes
    * bmo#1784253 - avoid processing unexpected inputs by checking for
    m_exptmod base sign
    * bmo#1826652 - add a limit check on order_k to avoid infinite loop
    * bmo#1834851 - Update HACL* to commit 5f6051d2
    * bmo#1753026 - add SHA3 to cryptohi and softoken
    * bmo#1753026 - HACL SHA3
    * bmo#1836781 - Disabling ASM C25519 for A but X86_64
  - removed upstreamed patch nss-fix-bmo1836925.patch
  - update to NSS 3.90.3
    * bmo#1901080 - GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME.
    * bmo#1748105 - clean up escape handling.
    * bmo#1895032 - remove redundant AllocItem implementation.
    * bmo#1836925 - Disable ASM support for Curve25519.
    * bmo#1836781 - Disable ASM support for Curve25519 for all but X86_64.
  - remove upstreamed nss-fix-bmo1836925.patch

++++ openSUSE-repos-LeapMicro:

  - Update to version 20240710.603d305 boo#1227625:
    * Fix missing quote in opensuse-leap16-repoindex.xml (#68)

++++ supermin:

  - Update to version 5.3.4 (jsc#PED-8910)
    * Add support for OCaml 5
    * Add kylinsecos support
    * rpm: Detect dnf5 and omit missing options
    * ocamlc: Use -output-complete-exe instead of -custom
    * Fix kernel filtering for aarch64 architecture
    * Uncompress kernel on RISC-V
  - Drop patches contained in new tarball
    001-Improved-debugging-of-the-supermin-if-newer-calculation.patch
    002-Fix-if-newer-copy-kernel.patch
    003-Fix-kernel-filtering-for-aarch64-architecture.patch
    004-Use-output-complete-exe-instead-of-custom.patch
    005-Only-supply-output-complete-exe-to-final-link.patch
    006-Rename-function-file-kernel.patch
    007-Uncompress-kernel-on-RISC-V.patch
    008-Fix-link-to-renamed-kernel-documentation.patch
    009-New-mailing-list-email-address.patch

++++ suseconnect-ng:

  - Update version to 1.11
  - Added uname as collector
  - Added SAP workload detection
  - Added detection of container runtimes
  - Multiple fixes on ARM64 detection
  - Use `read_values` for the CPU collector on Z
  - Fixed data collection for ppc64le
  - Grab the home directory from /etc/passwd if needed (bsc#1226128)

++++ tar:

  - Updated tar-fix-extract-unlink.patch
    * Replace patch with an equivalent upstreamed commit
    * Fixes bsc#1225407

++++ yast2:

  - Re-added missing error class (bsc#1227580)
  - 5.0.9

------------------------------------------------------------------
------------------  2024-7-9  -  Jul 9 2024  -------------------
------------------------------------------------------------------

++++ coreutils:

  - coreutils-i18n.patch: fold(1): fix exit code for non-existent file.
    The exit code of fold(1) was zero for non-existent file:
    $ fold badfile; echo $?
    fold: badfile: No such file or directory
    0
    The bug was introduced by the downstrean I18N patch. (rhbz#2296201)

++++ coreutils-systemd:

  - coreutils-i18n.patch: fold(1): fix exit code for non-existent file.
    The exit code of fold(1) was zero for non-existent file:
    $ fold badfile; echo $?
    fold: badfile: No such file or directory
    0
    The bug was introduced by the downstrean I18N patch. (rhbz#2296201)

++++ python-kiwi:

  - Update requires for kiwi-systemdeps-disk-images
    On Tumbleweed several changes caused tools like strings
    or the codepage for mtools to be missing in a standard
    installation. For building disk images especially EFI
    capable ones with vendor information kiwi needs the above
    tool. This commit adds the packages providing them on
    Tumbleweed to the meta systemdeps for disk images.
    This Fixes #2585

++++ kernel-default:

  - Move upstreamed turbostat patch into sorted section
  - commit 768422e
  - Move out-of-tree patch to the right section
  - commit a3dba46
  - powerpc/pseries: Fix scv instruction crash with kexec
    (bsc#1194869).
  - commit 245b529
  - powerpc/prom: Add CPU info to hardware description string later
    (bsc#1215199).
  - commit 75358e1
  - kernel-binary: vdso: Own module_dir
  - commit ff69986
  - enic: Validate length of nl attributes in enic_set_vf_port
    (CVE-2024-38659 bsc#1226883).
  - commit 82dab70
  - wifi: wilc1000: fix ies_len type in connect path (git-fixes).
  - commit 857b40a

++++ kernel-rt:

  - Move upstreamed turbostat patch into sorted section
  - commit 768422e
  - Move out-of-tree patch to the right section
  - commit a3dba46
  - powerpc/pseries: Fix scv instruction crash with kexec
    (bsc#1194869).
  - commit 245b529
  - powerpc/prom: Add CPU info to hardware description string later
    (bsc#1215199).
  - commit 75358e1
  - kernel-binary: vdso: Own module_dir
  - commit ff69986
  - enic: Validate length of nl attributes in enic_set_vf_port
    (CVE-2024-38659 bsc#1226883).
  - commit 82dab70
  - wifi: wilc1000: fix ies_len type in connect path (git-fixes).
  - commit 857b40a

++++ libzypp:

  - Keep UrlResolverPlugin API public (fixes #560)
  - Blacklist /snap executables for 'zypper ps' (bsc#1226014)
  - Fix handling of buddies when applying locks (bsc#1225267)
    Buddy pairs (like -release package and product) internally share
    the same status object. When applying locks from query results
    the locked bit must be set if either item is locked.
  - version 17.35.2 (35)

++++ nvidia-open-driver-G06-signed:

  - Update to 550.100 (boo#1227575)
    * Fixed a bug that caused OpenGL triple buffering to behave like
    double buffering.

++++ python-certifi:

  - Refresh patches python-certifi-shipped-requests-cabundle.patch and
    two-basic-unit-tests.patch
  - Remove executable bit from core.py file
  - Update to 2024.7.4 (CVE-2024-39689, bsc#1227519):
    Removed certs:
    * Subject: CN=GLOBALTRUST 2020 O=e-commerce monitoring GmbH
  - 2024.06.02
    Added certs:
    * Subject: CN=FIRMAPROFESIONAL CA ROOT-A WEB O=Firmaprofesional SA
  - 2024.02.02
    Added certs:
    * Subject: CN=Telekom Security TLS ECC Root 2020 O=Deutsche Telekom Security GmbH
    * Subject: CN=Telekom Security TLS RSA Root 2023 O=Deutsche Telekom Security GmbH
    Removed certs:
    * Subject: O=SECOM Trust.net OU=Security Communication RootCA1
    * Fix leaking certificate issue

------------------------------------------------------------------
------------------  2024-7-8  -  Jul 8 2024  -------------------
------------------------------------------------------------------

++++ ca-certificates-mozilla:

  - Updated to 2.68 state of Mozilla SSL root CAs (bsc#1227525)
  - Added: FIRMAPROFESIONAL CA ROOT-A WEB
  - Distrust: GLOBALTRUST 2020

++++ containerized-data-importer:

  - Update to version 1.59.0
    Release notes https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.59.0
    Release notes https://github.com/kubevirt/containerized-data-importer/releases/tag/v1.58.1

++++ cups:

  - Replaced avoid_C99_mode_for_loop_initial_declarations.patch
    which is now the upstream fix
    https://github.com/OpenPrinting/cups/commit/a2b8872ea95564e065e3a08e2aa12a15515bc993
    see https://github.com/OpenPrinting/cups/issues/1000
    and https://github.com/OpenPrinting/cups/pull/1004

++++ dracut:

  - Update to version 059+suse.586.ge0294756:
    * feat(crypt): force the inclusion of crypttab entries with x-initrd.attach (bsc#1226529)
    * fix(mdraid): try to assemble the missing raid device (bsc#1226412)
    * feat(ifcfg): minimize s390-specific network configuration aspects
    * refactor(ifcfg): delete code duplication using iface_get_subchannels()
    * fix(znet): append to udev rules so each rd.znet_ifname is effective
    * feat(qeth_rules): remove qeth handling consolidated in 95znet
    * docs(dracut.cmdline): generalize description of rd.znet
    * feat(znet): use zdev for consolidated device configuration
    * feat(dasd): minimize dasd handling consolidated in s390-tools
    * feat(dasd_mod): minimize dasd handling consolidated in s390-tools
    * feat(dasd_rules): remove dasd handling consolidated in s390-tools
    * feat(zfcp): minimize zfcp handling consolidated in s390-tools
    * feat(zfcp_rules): remove zfcp handling consolidated in s390-tools
    * refactor(cms): remove now unnecessary inclusion of full s390utils-base
    * refactor(cms): use consolidated network config with zdev from s390-tools
    * refactor(cms): use consolidated dasd config with zdev from s390-tools
    * refactor(cms): use consolidated zfcp config with zdev from s390-tools
    * refactor(cms): use zdev to simplify handling CMSDASD=... boot option
    * fix(github): update format of labeler
    * fix(dracut-install): continue parsing if ldd prints "cannot be preloaded" (bsc#1208690)

++++ python-kiwi:

  - Supplements are not understood by Debian/Ubuntu

++++ glib2:

  - Update to version 2.80.4:
    + Bugs fixed:
  - GLib unit tests fail on macOS runner due to localhost being
    out of addresses
  - Random failures to build glib 2.80.3
  - Backport !4111 “gioerror: Map EADDRNOTAVAIL to
    G_IO_ERROR_CONNECTION_REFUSED” to glib-2-80
  - Backport !3373 and !4117 “Handle files >4GB in
    g_file_load_contents()“ to glib-2-80
  - Backport !4020 and !4122: fixes to GIR install locations and
    build race fixes
  - Backport !4110 “gthreadedresolver: ref-sink returned records
    in lookup_records()” to glib-2-80

++++ kernel-default:

  - net/dcb: check for detached device before executing callbacks
    (bsc#1215587).
  - commit c563440
  - Update patches.suse/atm-Fix-Use-After-Free-in-do_vcc_ioctl.patch
    (git-fixes bsc#1218730 CVE-2023-51780).
  - commit 93588a3
  - powerpc/64s/radix/kfence: map __kfence_pool at page granularity
    (bsc#1223570 ltc#205770).
  - commit d4edfeb
  - crypto/ecdsa: make ecdsa_ecc_ctx_deinit() to zeroize the public
    key (bsc#1222768).
  - commit 817f8be
  - crypto/ecdh: make ecdh_compute_value() to zeroize the public
    key (bsc#1222768).
  - commit 3f5391b
  - PCI: Do not wait for disconnected devices when resuming
    (git-fixes).
  - commit f7f9960
  - powerpc/rtas: Prevent Spectre v1 gadget construction in
    sys_rtas() (bsc#1227487).
  - commit 42da489
  - Enable CONFIG_SCHED_CLUSTER=y on arm64 (jsc#PED-8701).
  - commit 9157a3d
  - clk: qcom: clk-alpha-pll: set ALPHA_EN bit for Stromer Plus PLLs
    (git-fixes).
  - clk: qcom: gcc-sm6350: Fix gpll6* & gpll7 parents (git-fixes).
  - clk: mediatek: mt8183: Only enable runtime PM on mt8183-mfgcfg
    (git-fixes).
  - commit 1a2b239
  - nfs: drop the incorrect assertion in nfs_swap_rw() (git-fixes).
  - NFS: add barriers when testing for NFS_FSDATA_BLOCKED
    (git-fixes).
  - SUNRPC: return proper error from gss_wrap_req_priv (git-fixes).
  - NFSv4.1 enforce rootpath check in fs_location query (git-fixes).
  - SUNRPC: Fix loop termination condition in
    gss_free_in_token_pages() (git-fixes).
  - nfs: fix undefined behavior in nfs_block_bits() (git-fixes).
  - pNFS/filelayout: fixup pNfs allocation modes (git-fixes).
  - rpcrdma: fix handling for RDMA_CM_EVENT_DEVICE_REMOVAL
    (git-fixes).
  - NFS: Fix READ_PLUS when server doesn't support OP_READ_PLUS
    (git-fixes).
  - sunrpc: fix NFSACL RPC retry on soft mount (git-fixes).
  - nfs: keep server info for remounts (git-fixes).
  - NFSv4: Fixup smatch warning for ambiguous return (git-fixes).
  - SUNRPC: Fix gss_free_in_token_pages() (git-fixes).
  - knfsd: LOOKUP can return an illegal error value (git-fixes).
  - nfs: Handle error of rpc_proc_register() in nfs_net_init()
    (git-fixes).
  - nfsd: hold a lighter-weight client reference over CB_RECALL_ANY
    (git-fixes).
  - NFSD: Fix checksum mismatches in the duplicate reply cache
    (git-fixes).
  - commit e019385
  - Update
    patches.suse/ALSA-hda-intel-sdw-acpi-fix-usage-of-device_get_name.patch
    (git-fixes CVE-2024-36955 bsc#1225810).
  - Update
    patches.suse/ASoC-SOF-ipc4-topology-Fix-input-format-query-of-pro.patch
    (git-fixes CVE-2024-39473 bsc#1227433).
  - Update
    patches.suse/Bluetooth-qca-fix-firmware-check-error-path.patch
    (git-fixes CVE-2024-36942 bsc#1225843).
  - Update
    patches.suse/Reapply-drm-qxl-simplify-qxl_fence_wait.patch
    (stable-fixes CVE-2024-36944 bsc#1225847).
  - Update
    patches.suse/amd-amdkfd-sync-all-devices-to-wait-all-processes-be.patch
    (stable-fixes CVE-2024-36949 bsc#1225894).
  - Update
    patches.suse/drm-amdkfd-range-check-cp-bad-op-exception-interrupt.patch
    (stable-fixes CVE-2024-36951 bsc#1225896).
  - Update patches.suse/drm-i915-hwmon-Get-rid-of-devm.patch
    (stable-fixes CVE-2024-39479 bsc#1227443).
  - Update
    patches.suse/fbdev-savage-Handle-err-return-when-savagefb_check_v.patch
    (git-fixes CVE-2024-39475 bsc#1227435).
  - Update
    patches.suse/firewire-ohci-mask-bus-reset-interrupts-between-ISR-.patch
    (stable-fixes CVE-2024-36950 bsc#1225895).
  - Update
    patches.suse/media-mc-Fix-graph-walk-in-media_pipeline_start.patch
    (git-fixes CVE-2024-39481 bsc#1227446).
  - Update
    patches.suse/pinctrl-core-delete-incorrect-free-in-pinctrl_enable.patch
    (git-fixes CVE-2024-36940 bsc#1225840).
  - Update
    patches.suse/pinctrl-devicetree-fix-refcount-leak-in-pinctrl_dt_t.patch
    (git-fixes CVE-2024-36959 bsc#1225839).
  - Update patches.suse/qibfs-fix-dentry-leak.patch (git-fixes
    CVE-2024-36947 bsc#1225856).
  - Update
    patches.suse/spi-fix-null-pointer-dereference-within-spi_sync.patch
    (git-fixes CVE-2024-36930 bsc#1225830).
  - Update
    patches.suse/wifi-iwlwifi-read-txq-read_ptr-under-lock.patch
    (stable-fixes CVE-2024-36922 bsc#1225805).
  - Update
    patches.suse/wifi-nl80211-don-t-free-NULL-coalescing-rule.patch
    (git-fixes CVE-2024-36941 bsc#1225835).
  - commit ffdc766
  - Update
    patches.suse/crypto-rsa-add-a-check-for-allocation-failure.patch
    (bsc#1222775 CVE-2023-52472 bsc#1220430 bsc#1220427).
  - commit 7754b95

++++ kernel-rt:

  - net/dcb: check for detached device before executing callbacks
    (bsc#1215587).
  - commit c563440
  - Update patches.suse/atm-Fix-Use-After-Free-in-do_vcc_ioctl.patch
    (git-fixes bsc#1218730 CVE-2023-51780).
  - commit 93588a3
  - powerpc/64s/radix/kfence: map __kfence_pool at page granularity
    (bsc#1223570 ltc#205770).
  - commit d4edfeb
  - crypto/ecdsa: make ecdsa_ecc_ctx_deinit() to zeroize the public
    key (bsc#1222768).
  - commit 817f8be
  - crypto/ecdh: make ecdh_compute_value() to zeroize the public
    key (bsc#1222768).
  - commit 3f5391b
  - PCI: Do not wait for disconnected devices when resuming
    (git-fixes).
  - commit f7f9960
  - powerpc/rtas: Prevent Spectre v1 gadget construction in
    sys_rtas() (bsc#1227487).
  - commit 42da489
  - Enable CONFIG_SCHED_CLUSTER=y on arm64 (jsc#PED-8701).
  - commit 9157a3d
  - clk: qcom: clk-alpha-pll: set ALPHA_EN bit for Stromer Plus PLLs
    (git-fixes).
  - clk: qcom: gcc-sm6350: Fix gpll6* & gpll7 parents (git-fixes).
  - clk: mediatek: mt8183: Only enable runtime PM on mt8183-mfgcfg
    (git-fixes).
  - commit 1a2b239
  - nfs: drop the incorrect assertion in nfs_swap_rw() (git-fixes).
  - NFS: add barriers when testing for NFS_FSDATA_BLOCKED
    (git-fixes).
  - SUNRPC: return proper error from gss_wrap_req_priv (git-fixes).
  - NFSv4.1 enforce rootpath check in fs_location query (git-fixes).
  - SUNRPC: Fix loop termination condition in
    gss_free_in_token_pages() (git-fixes).
  - nfs: fix undefined behavior in nfs_block_bits() (git-fixes).
  - pNFS/filelayout: fixup pNfs allocation modes (git-fixes).
  - rpcrdma: fix handling for RDMA_CM_EVENT_DEVICE_REMOVAL
    (git-fixes).
  - NFS: Fix READ_PLUS when server doesn't support OP_READ_PLUS
    (git-fixes).
  - sunrpc: fix NFSACL RPC retry on soft mount (git-fixes).
  - nfs: keep server info for remounts (git-fixes).
  - NFSv4: Fixup smatch warning for ambiguous return (git-fixes).
  - SUNRPC: Fix gss_free_in_token_pages() (git-fixes).
  - knfsd: LOOKUP can return an illegal error value (git-fixes).
  - nfs: Handle error of rpc_proc_register() in nfs_net_init()
    (git-fixes).
  - nfsd: hold a lighter-weight client reference over CB_RECALL_ANY
    (git-fixes).
  - NFSD: Fix checksum mismatches in the duplicate reply cache
    (git-fixes).
  - commit e019385
  - Update
    patches.suse/ALSA-hda-intel-sdw-acpi-fix-usage-of-device_get_name.patch
    (git-fixes CVE-2024-36955 bsc#1225810).
  - Update
    patches.suse/ASoC-SOF-ipc4-topology-Fix-input-format-query-of-pro.patch
    (git-fixes CVE-2024-39473 bsc#1227433).
  - Update
    patches.suse/Bluetooth-qca-fix-firmware-check-error-path.patch
    (git-fixes CVE-2024-36942 bsc#1225843).
  - Update
    patches.suse/Reapply-drm-qxl-simplify-qxl_fence_wait.patch
    (stable-fixes CVE-2024-36944 bsc#1225847).
  - Update
    patches.suse/amd-amdkfd-sync-all-devices-to-wait-all-processes-be.patch
    (stable-fixes CVE-2024-36949 bsc#1225894).
  - Update
    patches.suse/drm-amdkfd-range-check-cp-bad-op-exception-interrupt.patch
    (stable-fixes CVE-2024-36951 bsc#1225896).
  - Update patches.suse/drm-i915-hwmon-Get-rid-of-devm.patch
    (stable-fixes CVE-2024-39479 bsc#1227443).
  - Update
    patches.suse/fbdev-savage-Handle-err-return-when-savagefb_check_v.patch
    (git-fixes CVE-2024-39475 bsc#1227435).
  - Update
    patches.suse/firewire-ohci-mask-bus-reset-interrupts-between-ISR-.patch
    (stable-fixes CVE-2024-36950 bsc#1225895).
  - Update
    patches.suse/media-mc-Fix-graph-walk-in-media_pipeline_start.patch
    (git-fixes CVE-2024-39481 bsc#1227446).
  - Update
    patches.suse/pinctrl-core-delete-incorrect-free-in-pinctrl_enable.patch
    (git-fixes CVE-2024-36940 bsc#1225840).
  - Update
    patches.suse/pinctrl-devicetree-fix-refcount-leak-in-pinctrl_dt_t.patch
    (git-fixes CVE-2024-36959 bsc#1225839).
  - Update patches.suse/qibfs-fix-dentry-leak.patch (git-fixes
    CVE-2024-36947 bsc#1225856).
  - Update
    patches.suse/spi-fix-null-pointer-dereference-within-spi_sync.patch
    (git-fixes CVE-2024-36930 bsc#1225830).
  - Update
    patches.suse/wifi-iwlwifi-read-txq-read_ptr-under-lock.patch
    (stable-fixes CVE-2024-36922 bsc#1225805).
  - Update
    patches.suse/wifi-nl80211-don-t-free-NULL-coalescing-rule.patch
    (git-fixes CVE-2024-36941 bsc#1225835).
  - commit ffdc766
  - Update
    patches.suse/crypto-rsa-add-a-check-for-allocation-failure.patch
    (bsc#1222775 CVE-2023-52472 bsc#1220430 bsc#1220427).
  - commit 7754b95

++++ kubevirt:

  - Update to version 1.2.2
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.2.2
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.2.1
    Release notes https://github.com/kubevirt/kubevirt/releases/tag/v1.2.0
  - Drop patches
    0001-tests-Adapt-VM-phase-expectation.patch
    0002-Update-tls-error-string-in-migration-test.patch
    0003-tests-Expect-PendingPopulation-phase.patch
    0004-Improve-the-handling-of-ordinal-pod-interface-name-for-upgrade.patch
    0005-Collect-component-Role-rules-under-operator-Role-ins.patch
  - Add patch
    0001-Collect-component-Role-rules-under-operator-Role-ins.patch
  - Pack configuration files for libvirt

++++ ncurses:

  - Add ncurses patch 20240706
    + update configure script to use macro changes from dialog.
    + modify CF_NCURSES_PTHREADS to avoid equating package and library
    names.

++++ shadow:

  - Disable flushing sssd caches. The sssd's files provider is no
    longer available.

++++ systemd:

  - Import commit bd8b5ee3cf0466b6b78e167967468cf6f93ec807 (merge of v256.2)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/dd15bf4f6430d8646e546ee0b980448c7d0c9699...bd8b5ee3cf0466b6b78e167967468cf6f93ec807

++++ nvidia-open-driver-G06-signed:

  - Use macro which is set during build but not when running
    `osc service run download_files` to make sure both source versions
    are visible for download. This way, only the correct source
    tarball will be included in the source package of its respective
    flavor but both can be downloaded (updated) simultaniously.

++++ osinfo-db:

  - Update the release dates in the definitions for the following
    products
    openSUSE leap 15.6, SLE 15-SP6, SLEM 5.5, SLEM 6.0

------------------------------------------------------------------
------------------  2024-7-7  -  Jul 7 2024  -------------------
------------------------------------------------------------------

++++ harfbuzz:

  - update to version 9.0.0:
    + Speed up “AAT” shaping for short words by up to 4%
    + Ignore unknown “CFF” operators
    + “hb_subset_input_keep_everything()” now keeps also non-unicode
    “name” table records.
    + Update the IANA and OpenType language tag registries
    + Support composite glyphs with very large number of points in
    hb-draw API
    + Various build fixes

++++ python-maturin:

  - Update to 1.7.0
    * Expose env variable to suppress build backend warning
    gh#PyO3/maturin#2099
    * Canonicalize base executable path in PEP 517 build
    gh#PyO3/maturin#2100
    * Initial iOS support
    gh#PyO3/maturin#2102
    * Remove old import hook
    gh#PyO3/maturin#2105
    * Bump MSRV to 1.74.0
    gh#PyO3/maturin#2108
    * Upgrade pyo3 to 0.22.0, uniffi to 0.28.0
    gh#PyO3/maturin#2121
    * Override wheel tag with _PYTHON_HOST_PLATFORM
    gh#PyO3/maturin#2122
    * Update cargo-xwin to 0.16.5
    gh#PyO3/maturin#2123
    * Don't add duplicate files
    gh#PyO3/maturin#2125
    * Docs: Fix Typo in Verb Conjugation
    gh#PyO3/maturin#2129
    * pep517: only use base python when
    MATURIN_PEP517_USE_BASE_PYTHON env var is set
    gh#PyO3/maturin#2134

++++ rt-tests:

  - Update to version 2.7:
    https://lore.kernel.org/linux-rt-users/20240507144229.42909-1-jkacur@redhat.com/
  - Start using xz tarball (instead of gz)

------------------------------------------------------------------
------------------  2024-7-6  -  Jul 6 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/fbdev-generic: Fix framebuffer on big endian devices
    (git-fixes).
  - drm/nouveau: fix null pointer dereference in
    nouveau_connector_get_modes (git-fixes).
  - usb: dwc3: core: Workaround for CSR read timeout (stable-fixes).
  - usb: gadget: printer: SS+ support (stable-fixes).
  - drm/amdgpu: avoid using null object of framebuffer
    (stable-fixes).
  - drm/amd/display: Send DP_TOTAL_LTTPR_CNT during detection if
    LTTPR is present (stable-fixes).
  - drm/amdgpu/atomfirmware: fix parsing of vram_info
    (stable-fixes).
  - drm/nouveau/dispnv04: fix null pointer dereference in
    nv17_tv_get_ld_modes (stable-fixes).
  - drm/nouveau/dispnv04: fix null pointer dereference in
    nv17_tv_get_hd_modes (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for
    EliteBook 645/665 G11 (stable-fixes).
  - usb: typec: ucsi: Ack also failed Get Error commands
    (git-fixes).
  - iio: pressure: bmp280: Fix BMP580 temperature reading
    (stable-fixes).
  - usb: typec: ucsi: Never send a lone connector change ack
    (stable-fixes).
  - mtd: partitions: redboot: Added conversion of operands to a
    larger type (stable-fixes).
  - media: dvbdev: Initialize sbuf (stable-fixes).
  - ALSA: emux: improve patch ioctl data validation (stable-fixes).
  - drm/radeon/radeon_display: Decrease the size of allocated memory
    (stable-fixes).
  - drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers
    that sleep (stable-fixes).
  - wifi: ieee80211: check for NULL in ieee80211_mle_size_ok()
    (stable-fixes).
  - crypto: ecdh - explicitly zeroize private_key (stable-fixes).
  - soc: ti: wkup_m3_ipc: Send NULL dummy message instead of
    pointer message (stable-fixes).
  - usb: dwc3: core: Add DWC31 version 2.00a controller
    (stable-fixes).
  - iio: pressure: fix some word spelling errors (stable-fixes).
  - commit 42cf83f
  - Drop amd-pstate patch that caused a regression on 6.6.x stable
  - commit d3672a6
  - RDMA/restrack: Fix potential invalid address access (git-fixes)
  - commit 91e323d

++++ kernel-rt:

  - drm/fbdev-generic: Fix framebuffer on big endian devices
    (git-fixes).
  - drm/nouveau: fix null pointer dereference in
    nouveau_connector_get_modes (git-fixes).
  - usb: dwc3: core: Workaround for CSR read timeout (stable-fixes).
  - usb: gadget: printer: SS+ support (stable-fixes).
  - drm/amdgpu: avoid using null object of framebuffer
    (stable-fixes).
  - drm/amd/display: Send DP_TOTAL_LTTPR_CNT during detection if
    LTTPR is present (stable-fixes).
  - drm/amdgpu/atomfirmware: fix parsing of vram_info
    (stable-fixes).
  - drm/nouveau/dispnv04: fix null pointer dereference in
    nv17_tv_get_ld_modes (stable-fixes).
  - drm/nouveau/dispnv04: fix null pointer dereference in
    nv17_tv_get_hd_modes (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for
    EliteBook 645/665 G11 (stable-fixes).
  - usb: typec: ucsi: Ack also failed Get Error commands
    (git-fixes).
  - iio: pressure: bmp280: Fix BMP580 temperature reading
    (stable-fixes).
  - usb: typec: ucsi: Never send a lone connector change ack
    (stable-fixes).
  - mtd: partitions: redboot: Added conversion of operands to a
    larger type (stable-fixes).
  - media: dvbdev: Initialize sbuf (stable-fixes).
  - ALSA: emux: improve patch ioctl data validation (stable-fixes).
  - drm/radeon/radeon_display: Decrease the size of allocated memory
    (stable-fixes).
  - drm/panel: ilitek-ili9881c: Fix warning with GPIO controllers
    that sleep (stable-fixes).
  - wifi: ieee80211: check for NULL in ieee80211_mle_size_ok()
    (stable-fixes).
  - crypto: ecdh - explicitly zeroize private_key (stable-fixes).
  - soc: ti: wkup_m3_ipc: Send NULL dummy message instead of
    pointer message (stable-fixes).
  - usb: dwc3: core: Add DWC31 version 2.00a controller
    (stable-fixes).
  - iio: pressure: fix some word spelling errors (stable-fixes).
  - commit 42cf83f
  - Drop amd-pstate patch that caused a regression on 6.6.x stable
  - commit d3672a6
  - RDMA/restrack: Fix potential invalid address access (git-fixes)
  - commit 91e323d

++++ mdadm:

  - util.c: change devnm to const in mdmon functions (bsc#1225307)
    0006-util.c-change-devnm-to-const-in-mdmon-functions.patch
  - Wait for mdmon when it is stared via systemd (bsc#1225307)
    0007-Wait-for-mdmon-when-it-is-stared-via-systemd.patch

------------------------------------------------------------------
------------------  2024-7-5  -  Jul 5 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Update to version 1.48.4:
    + Support matching a OVS system interface by MAC address.
    + When looking up the system hostname from the reverse DNS lookup
    of addresses configured on interfaces, NetworkManager now takes
    into account the content of /etc/hosts.

++++ python-kiwi:

  - Add new builder for enclaves
    Add new EnclaveBuilder class which allows to build initrd-only
    image types. The first enclave implementation covers aws-nitro
    images produced via the eif_build tooling.

++++ grub2:

  - Fix error if dash shell script is used (bsc#1226453)
    * 0007-grub-switch-to-blscfg-adapt-to-openSUSE.patch
    * 0009-10_linux-Some-refinement-for-BLS.patch
  - Fix input handling in ppc64le grub2 has high latency (bsc#1223535)
    * 0001-net-drivers-ieee1275-ofnet-Remove-200-ms-timeout-in-.patch

++++ kernel-default:

  - smb: client: fix use-after-free in smb2_query_info_compound()
    (bsc#1225489, CVE-2023-52751).
  - Refresh
    patches.suse/smb-client-fix-potential-OOBs-in-smb2_parse_contexts-.patch.
  - commit fed05d1
  - smb: client: prevent new fids from being removed by laundromat
    (git-fixes, bsc#1225172).
  - commit b3d54ea
  - smb: client: make laundromat a delayed worker (git-fixes,
    bsc#1225172).
  - commit 97932f6
  - smb3: allow controlling length of time directory entries are
    cached with dir leases (git-fixes, bsc#1225172).
  - commit c39c365
  - smb: client: do not start laundromat thread on nohandlecache
    (git-fixes, bsc#1225172).
  - commit b320db3
  - smb3: allow controlling maximum number of cached directories
    (git-fixes, bsc#1225172).
  - commit e5e6d01
  - smb3: do not start laundromat thread when dir leases disabled
    (git-fixes, bsc#1225172).
  - commit b758cab
  - cifs: Add a laundromat thread for cached directories (git-fixes,
    bsc#1225172).
  - commit b1876e3
  - bcache: fix variable length array abuse in btree_iter
    (CVE-2024-39482 bsc#1227447).
  - commit 3d0cfa1
  - mm/vmalloc: fix vmalloc which may return null if called with
    __GFP_NOFAIL (CVE-2024-39474 bsc#1227434).
  - commit 13add8a
  - selftests: make order checking verbose in msg_zerocopy selftest
    (git-fixes).
  - selftests: fix OOM in msg_zerocopy selftest (git-fixes).
  - can: kvaser_usb: Explicitly initialize family in leafimx
    driver_info struct (git-fixes).
  - bluetooth/hci: disallow setting handle bigger than
    HCI_CONN_HANDLE_MAX (git-fixes).
  - Bluetooth: ISO: Check socket flag instead of hcon (git-fixes).
  - Bluetooth: Ignore too large handle values in BIG (git-fixes).
  - Bluetooth: qca: Fix BT enable failure again for QCA6390 after
    warm reboot (git-fixes).
  - Bluetooth: hci_event: Fix setting of unicast qos interval
    (git-fixes).
  - Bluetooth: hci_bcm4377: Fix msgid release (git-fixes).
  - mac802154: fix time calculation in
    ieee802154_configure_durations() (git-fixes).
  - net: phy: phy_device: Fix PHY LED blinking code comment
    (git-fixes).
  - wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values
    (git-fixes).
  - platform/x86: toshiba_acpi: Fix quickstart quirk handling
    (git-fixes).
  - commit 3db85da

++++ kernel-rt:

  - smb: client: fix use-after-free in smb2_query_info_compound()
    (bsc#1225489, CVE-2023-52751).
  - Refresh
    patches.suse/smb-client-fix-potential-OOBs-in-smb2_parse_contexts-.patch.
  - commit fed05d1
  - smb: client: prevent new fids from being removed by laundromat
    (git-fixes, bsc#1225172).
  - commit b3d54ea
  - smb: client: make laundromat a delayed worker (git-fixes,
    bsc#1225172).
  - commit 97932f6
  - smb3: allow controlling length of time directory entries are
    cached with dir leases (git-fixes, bsc#1225172).
  - commit c39c365
  - smb: client: do not start laundromat thread on nohandlecache
    (git-fixes, bsc#1225172).
  - commit b320db3
  - smb3: allow controlling maximum number of cached directories
    (git-fixes, bsc#1225172).
  - commit e5e6d01
  - smb3: do not start laundromat thread when dir leases disabled
    (git-fixes, bsc#1225172).
  - commit b758cab
  - cifs: Add a laundromat thread for cached directories (git-fixes,
    bsc#1225172).
  - commit b1876e3
  - bcache: fix variable length array abuse in btree_iter
    (CVE-2024-39482 bsc#1227447).
  - commit 3d0cfa1
  - mm/vmalloc: fix vmalloc which may return null if called with
    __GFP_NOFAIL (CVE-2024-39474 bsc#1227434).
  - commit 13add8a
  - selftests: make order checking verbose in msg_zerocopy selftest
    (git-fixes).
  - selftests: fix OOM in msg_zerocopy selftest (git-fixes).
  - can: kvaser_usb: Explicitly initialize family in leafimx
    driver_info struct (git-fixes).
  - bluetooth/hci: disallow setting handle bigger than
    HCI_CONN_HANDLE_MAX (git-fixes).
  - Bluetooth: ISO: Check socket flag instead of hcon (git-fixes).
  - Bluetooth: Ignore too large handle values in BIG (git-fixes).
  - Bluetooth: qca: Fix BT enable failure again for QCA6390 after
    warm reboot (git-fixes).
  - Bluetooth: hci_event: Fix setting of unicast qos interval
    (git-fixes).
  - Bluetooth: hci_bcm4377: Fix msgid release (git-fixes).
  - mac802154: fix time calculation in
    ieee802154_configure_durations() (git-fixes).
  - net: phy: phy_device: Fix PHY LED blinking code comment
    (git-fixes).
  - wifi: cfg80211: restrict NL80211_ATTR_TXQ_QUANTUM values
    (git-fixes).
  - platform/x86: toshiba_acpi: Fix quickstart quirk handling
    (git-fixes).
  - commit 3db85da

++++ libksba:

  - Update to 1.6.7:
    * Allow for an empty Subject in certs.  [T7171]
    * Release-info: https://dev.gnupg.org/T7173
    * Rebase libksba-nobetasuffix.patch

++++ snapper:

  - handle content-length of stomp in zypper plugin
    (gh#openSUSE/snapper#918)
  - version 0.11.1

++++ nvidia-open-driver-G06-signed:

  - make buildservice happy; all sources need to be mentioned as such
    in specfile

++++ openssh:

  - Add patch from upstream to fix proxy multiplexing mode:
    * 0001-upstream-fix-proxy-multiplexing-mode_-broken-when-keystroke.patch
  - Add patch from upstream to restore correctly sigprocmask
    * 0001-upstream-correctly-restore-sigprocmask-around-ppoll.patch
  - Add patch from upstream to fix a logic error in
    ObscureKeystrokeTiming that rendered this feature ineffective,
    allowing a passive observer to detect which network packets
    contained real keystrokes (bsc#1227318, CVE-2024-39894):
    * 0001-upstream-when-sending-ObscureKeystrokeTiming-chaff-packets_.patch

------------------------------------------------------------------
------------------  2024-7-4  -  Jul 4 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to bugfix release 24.1.3
  - -> https://docs.mesa3d.org/relnotes/24.1.3
  - supersedes the following patches:
    * u_dri-Fix-BGR-format-exclusion.patch
    * u_egl-gbm-Enable-RGBA-configs.patch
    * u_egl-surfaceless-Enable-RGBA-configs.patch
    * boo1226725-test-fix1.patch
  - use gcc-13 on SLE 15/Leap 15.x in order to fix build; credits
    go to "Friedrich Haubensak" <hsk17@mail.de> to figure this out!

++++ Mesa-drivers:

  - Update to bugfix release 24.1.3
  - -> https://docs.mesa3d.org/relnotes/24.1.3
  - supersedes the following patches:
    * u_dri-Fix-BGR-format-exclusion.patch
    * u_egl-gbm-Enable-RGBA-configs.patch
    * u_egl-surfaceless-Enable-RGBA-configs.patch
    * boo1226725-test-fix1.patch
  - use gcc-13 on SLE 15/Leap 15.x in order to fix build; credits
    go to "Friedrich Haubensak" <hsk17@mail.de> to figure this out!

++++ btrfsprogs:

  - update to 6.9.2
    * subvol list: fix accidental trimming of subvolume name
    * check: revert checking file extent item 'ram_bytes'
    * libbtrfsutil:
    * patchlevel version update 1.3.2
    * fix accidentally closing fd passed to subvolume iterator
  - update to 6.9.1
    * fix detection of intermediate super block flags (e.g. csum change and
    other conversions)
    * raid-stripe-tree support (still experimental):
    * moved under experimental build flags (mkfs, convert)
    * format change, removed encoding type; backward incompatible
    * receive dump: escape special chars in xattr names and values, and clone
    source path
    * tune change csum: fix reservation size when starting a transaction
    * other:
    * new and updated tests
    * updated CI images, new reference build targets
    * cleanups and refactoring

++++ dpdk:

  - Drop leftover Sphinx doctrees to make package build reproducible

++++ python-kiwi:

  - Split out bash completion into a sub-package
    Per review of the SUSE packaging team we should split out
    the bash completion into its own sub-package to give users
    better control over the completion feature.
  - Bump version: 10.0.22 → 10.0.23
  - package: Add fully qualified provides for python3-kiwi in spec
    On SUSE distributions, currently the expectation is that packages
    built against the Python interpreter should have fully qualified
    names in the form of pythonXY-<modulename>. Additionally, all other
    Linux distributions prefer something similar in the form of
    pythonX.Y-<modulename>.
    This ensures we have those names so that distribution dependency
    generation works as expected.
  - Add support for arch selector on volumes
    The optional <volume ... arch=""/> attribute allows to create
    the volume only if it matches the specified host architecture.
    Multiple architecture names can be specified as comma separated
    list.

++++ transactional-update:

  - Version 4.7.0
  - Add plugin mechanism
    It's now possible to hook into API functions with custom
    plugins; see doc/tukit-plugins.md for details.
    [gh#openSUSE/transactional-update#122]
  - Fix missing libdir replacement for status command

++++ kernel-default:

  - jfs: xattr: fix buffer overflow for invalid xattr
    (bsc#1227383).
  - commit ae2a0d9
  - iommu/arm-smmu-v3: Free MSIs in case of ENOMEM (git-fixes).
  - commit 2fb4aa0
  - Update
    patches.suse/arm64-mm-Batch-dsb-and-isb-when-populating-pgtables.patch
    (jsc#PED-8688 bsc#1226202).
  - Update
    patches.suse/arm64-mm-Don-t-remap-pgtables-for-allocate-vs-populate.patch
    (jsc#PED-8688 bsc#1226202).
  - Update
    patches.suse/arm64-mm-Don-t-remap-pgtables-per-cont-pte-pmd-block.patch
    (jsc#PED-8688 bsc#1226202).
  - Update
    patches.suse/net-ena-Fix-redundant-device-NUMA-node-override.patch
    (jsc#PED-8688 bsc#1226202).
  - commit 584efba
  - Update
    patches.suse/usb-gadget-printer-fix-races-against-disable.patch
    (CVE-2024-25741 bsc#1219832).
  - commit 4a6f084
  - llc: make llc_ui_sendmsg() more robust against bonding changes
    (CVE-2024-26636 bsc#1221659).
  - commit 1bb1c76
  - llc: Drop support for ETH_P_TR_802_2 (CVE-2024-26635
    bsc#1221656).
  - commit 6a42a8d
  - PCI: vmd: Create domain symlink before pci_bus_add_devices()
    (bsc#1227363).
  - commit 3666715
  - md: fix resync softlockup when bitmap size is less than array
    size (CVE-2024-38598, bsc#1226757).
  - commit 43087c7

++++ kernel-rt:

  - jfs: xattr: fix buffer overflow for invalid xattr
    (bsc#1227383).
  - commit ae2a0d9
  - iommu/arm-smmu-v3: Free MSIs in case of ENOMEM (git-fixes).
  - commit 2fb4aa0
  - Update
    patches.suse/arm64-mm-Batch-dsb-and-isb-when-populating-pgtables.patch
    (jsc#PED-8688 bsc#1226202).
  - Update
    patches.suse/arm64-mm-Don-t-remap-pgtables-for-allocate-vs-populate.patch
    (jsc#PED-8688 bsc#1226202).
  - Update
    patches.suse/arm64-mm-Don-t-remap-pgtables-per-cont-pte-pmd-block.patch
    (jsc#PED-8688 bsc#1226202).
  - Update
    patches.suse/net-ena-Fix-redundant-device-NUMA-node-override.patch
    (jsc#PED-8688 bsc#1226202).
  - commit 584efba
  - Update
    patches.suse/usb-gadget-printer-fix-races-against-disable.patch
    (CVE-2024-25741 bsc#1219832).
  - commit 4a6f084
  - llc: make llc_ui_sendmsg() more robust against bonding changes
    (CVE-2024-26636 bsc#1221659).
  - commit 1bb1c76
  - llc: Drop support for ETH_P_TR_802_2 (CVE-2024-26635
    bsc#1221656).
  - commit 6a42a8d
  - PCI: vmd: Create domain symlink before pci_bus_add_devices()
    (bsc#1227363).
  - commit 3666715
  - md: fix resync softlockup when bitmap size is less than array
    size (CVE-2024-38598, bsc#1226757).
  - commit 43087c7

++++ samba:

  - Fix named crash when using samba's DLZ plugin; (bsc#1224003);
    (bso#15643);
  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang macro, [bsc#1212476]

++++ python313-core:

  - Stop using %%defattr, it seems to be breaking proper executable
    attributes on /usr/bin/ scripts (bsc#1227378).

++++ systemd:

  - varlinkctl is no more considered as experimental and has been moved to the
    main package.
  - Upgrade to v256.1 (commit dd15bf4f6430d8646e546ee0b980448c7d0c9699)
    See https://github.com/openSUSE/systemd/blob/SUSE/v256/NEWS for details.
  - This includes the following bug fixes:
  - commit 3b2e7dc5a285edbbb1bf6aed2d88b889d801613f (bsc#1234015)
  - commit c072860593329293e19580b337504adb52248462 (bsc#1229518)
  - commit cfbf7538d87023840c5574fa5b0452e5b0f42149 (bsc#1229228)
  - commit 3c85d3fda50f71755aa276cfa60807c315bfc04b (bsc#1236886)
  - Added pam.systemd-run0

++++ nvidia-open-driver-G06-signed:

  - To avoid issues with missing dependencies when no CUDA repo
    is present make the dependecy to nvidia-compute-G06 conditional.
  - CUDA is not available for Tumbleweed, exclude the build of the
    cuda flavor.
  - preamble: let the -cuda flavor KMP require the -cuda flavor
    firmware

++++ openSUSE-repos-LeapMicro:

  - Update to version 20240704.2072b16:
    * Working Leap 16 repoindex with standard + product repo (#67)
    * Add ports non-oss non-oss/sources for TW (#65) boo#1226763

++++ passt:

  - BuildRequire selinux-policy-targeted explicitly to allow building
    on SELinux-enabled projects e.g. SLFO.

++++ python313:

  - Stop using %%defattr, it seems to be breaking proper executable
    attributes on /usr/bin/ scripts (bsc#1227378).

++++ toolbox:

  - Update to version 2.3+git20240704.84ec25e:
    * toolbox: use correct container state tense in msg

------------------------------------------------------------------
------------------  2024-7-3  -  Jul 3 2024  -------------------
------------------------------------------------------------------

++++ cockpit:

  - new version 320:
    * pam-ssh-add: Fix insecure killing of session ssh-agent
    (bsc#1226040, CVE-2024-6126)
  - changes in older versions:
    * Storage: Btrfs snapshots
    * Podman: Add image pull action
    * Files: Bookmark support
    * webserver: System user changes
    * Metrics: Grafana setup now prefers Valkey
  - 0001-users-Support-for-watching-lastlog2.patch,
    0002-users-Support-for-watching-lastlog2-and-wutmp-on-overview-page.patch
    removed, upstreamed
  - fix suse_docs.patch causing invalid json against the storaged manifest bsc#1227299

++++ kernel-default:

  - ice: fix LAG and VF lock dependency in ice_reset_vf()
    (CVE-2024-36003 bsc#1224544).
  - commit 0af15ab
  - Refresh
    patches.suse/nvme-tcp-strict-pdu-pacing-to-avoid-send-stalls-on-T.patch.
  - commit a27eef2
  - block: refine the EOF check in blkdev_iomap_begin (bsc#1226866
    CVE-2024-38604).
  - commit 9e332c1
  - kabi/severities: ignore amd pds internal symbols
  - commit 3a9ca76
  - ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()
    (CVE-2024-26641 bsc#1221654).
  - commit 5bd1138
  - hsr: Fix uninit-value access in hsr_get_node() (bsc#1223021
    CVE-2024-26863).
  - commit 21d04a8
  - ip6_tunnel: fix NEXTHDR_FRAGMENT handling in
    ip6_tnl_parse_tlv_enc_lim() (CVE-2024-26633 bsc#1221647).
  - commit 78e628d
  - pds_core: Prevent race issues involving the adminq (bsc#1221057
    CVE-2024-26623).
  - commit 94351ab
  - iommufd: Fix protection fault in iommufd_test_syz_conv_iova
    (bsc#1222779 CVE-2024-26785).
  - commit 5644693
  - devlink: fix possible use-after-free and memory leaks in
    devlink_init() (bsc#1222438 CVE-2024-26734).
  - commit d3a3753
  - dm snapshot: fix lockup in dm_exception_table_exit (bsc#1224743,
    CVE-2024-35805).
  - commit ba12566

++++ kernel-rt:

  - ice: fix LAG and VF lock dependency in ice_reset_vf()
    (CVE-2024-36003 bsc#1224544).
  - commit 0af15ab
  - Refresh
    patches.suse/nvme-tcp-strict-pdu-pacing-to-avoid-send-stalls-on-T.patch.
  - commit a27eef2
  - block: refine the EOF check in blkdev_iomap_begin (bsc#1226866
    CVE-2024-38604).
  - commit 9e332c1
  - kabi/severities: ignore amd pds internal symbols
  - commit 3a9ca76
  - ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()
    (CVE-2024-26641 bsc#1221654).
  - commit 5bd1138
  - hsr: Fix uninit-value access in hsr_get_node() (bsc#1223021
    CVE-2024-26863).
  - commit 21d04a8
  - ip6_tunnel: fix NEXTHDR_FRAGMENT handling in
    ip6_tnl_parse_tlv_enc_lim() (CVE-2024-26633 bsc#1221647).
  - commit 78e628d
  - pds_core: Prevent race issues involving the adminq (bsc#1221057
    CVE-2024-26623).
  - commit 94351ab
  - iommufd: Fix protection fault in iommufd_test_syz_conv_iova
    (bsc#1222779 CVE-2024-26785).
  - commit 5644693
  - devlink: fix possible use-after-free and memory leaks in
    devlink_init() (bsc#1222438 CVE-2024-26734).
  - commit d3a3753
  - dm snapshot: fix lockup in dm_exception_table_exit (bsc#1224743,
    CVE-2024-35805).
  - commit ba12566

++++ libva:

  - Update to version 2.22.0:
    * va:Add VVC decode LibVA interface.
    * va: fix --version-script detection for lld >= 17
    * wayland: add support for linux-dmabuf
    * meson:remove autogen.sh from the meson script
    * trace: Add bit_depth capturing in trace log

++++ nvidia-open-driver-G06-signed:

  - Add a second flavor for building the kernel module versions
    used by CUDA. The kmp targetting CUDA contains '-cuda' in
    its name to track its versions separately from the graphics
    kmp. (bsc#1227417)
  - Provide the meta package nv-prefer-signed-open-driver to
    make sure the latest available SUSE-build open driver is
    installed - independent of the latest available open driver
    version in he CUDA repository.
    Rationale:
    The package cuda-runtime provides the link between CUDA and
    the kernel driver version through a
    Requires: cuda-drivers >= %version
    This implies that a CUDA version will run withany kernel driver
    version equal or higher than a base version.
    nvidia-compute-G06 provides the glue layer between CUDA and
    a specific version of he kernel driver both by providing
    a set of base libraries and by requiring a specific kernel
    version. 'cuda-drivers' (provided by nvidia-compute-utils-G06)
    requires an unversioned nvidia-compute-G06. With this, the
    resolver will install the latest available and applicable
    nvidia-compute-G06.
    nv-prefer-signed-open-driver then represents the latest available
    open driver version and restricts the nvidia-compute-G06 version
    to it. (bsc#1227419)

++++ openssh:

  - Add obsoletes for openssh-server-config-rootlogin since that
    package existed for a brief period of time during SLE 15 SP6/
    Leap 15.6 development but even if it was removed from the
    repositories before GM, some users might have it in their
    systems from having tried a beta/RC release (boo#1227350).

++++ perl:

  - Insert manual provide for perl(Getopt::Long) until new version
    transition is done

++++ suse-module-tools:

  - Update to version 16.0.47:
    * rpm scriptlets: fix shellcheck warnings
  - Update to version 16.0.46:
    * Support for bootloaders that follow the boot loader specification
    in particular systemd-boot (bsc#1226122)
    * Spec file: obsolete sdbootutil-rpm-scriptlets, the scriptlets
    in suse-module-tools-scriptlets have modified to support the
    systemd-boot / sdbootutil use case, too

++++ velociraptor-client:

  - Update to version 0.7.0.4.git97.675e45f9:
    * kafka-humio-gateway: update go version and dependency list
    * kafka-humio-gateway: specific mTLS cert paths in config.yml
    * docker-compose: set kafka replication factor and min ISRs
    * kafka-humio-gateway: add http post retry mechanism
    * kafka-humio-gateway: add pprof debugging option
    * kafka-humio-gateway: format with gofmt
    * kafka-humio-gateway: fix go-staticcheck issues
    * kafka-humio-gateway: fix sendEvents() never exiting
    * Kafka.Events.Client: Update to use new artifactset type
    * docker-compose: add optional Kafka cluser
    * kafka-humio-gateway: add mTLS support
    * contrib/kafka-humio-gateway: add new debug option for noisy events
    * contrib/kafka-humio-gateway: backoff and retry for metadata
    * kafka-humio-gateway: add sample config file
    * kafka-humio-gateway: update sarama and dependencies
    * Add Kafka-Humio Gateway [Depends on PR#10] (#8)
    * vql/server/kafka: connect sarama logging to velociraptor logging
    * vql/server/kafka: add exponential backoff (limited to 30s) for metadata retries
    * vql/server/kafka: set appropriate ClientID
    * Add a Kafka export plugin
  - Use llvm17 when available

------------------------------------------------------------------
------------------  2024-7-2  -  Jul 2 2024  -------------------
------------------------------------------------------------------

++++ cloud-regionsrv-client:

  - Update to version 10.3.0 (bsc#1227308, bsc#1222985)
    + Add support for sidecar registry
    Podman and rootless Docker support to set up the necessary
    configuration for the container engines to run as defined
    + Add running command as root through sudoers file

++++ cups:

  - Version upgrade to 2.4.10:
    See https://github.com/openprinting/cups/releases
    CUPS 2.4.10 brings two fixes:
    * Fixed error handling when reading a mixed 1setOf attribute.
    * Fixed scheduler start if there is only domain socket
    to listen on (Issue #985) which is fix for regression
    after fix for CVE-2024-35235 in scenarios where is
    no other listeners in cupsd.conf than domain socket
    created on demand by systemd, launchd or upstart.
    Issues are those at https://github.com/OpenPrinting/cups/issues
  - Version upgrade to 2.4.9:
    See https://github.com/openprinting/cups/releases
    CUPS 2.4.9 brings security fix for CVE-2024-35235 and
    several bug fixes regarding CUPS Web User Interface,
    PPD generation and HTTP protocol implementation.
    Detailed list (from CHANGES.md):
    * Fixed domain socket handling (CVE-2024-35235)
    * Fixed creating of `cupsUrfSupported` PPD keyword
    (Issue #952)
    * Fixed searching for destinations in web ui (Issue #954)
    * Fixed TLS negotiation using OpenSSL with servers
    that require the TLS SNI extension.
    * Really raised `cups_enum_dests()` timeout for listing
    available IPP printers (Issue #751)...
    * Fixed `Host` header regression (Issue #967)
    * Fixed DNS-SD lookups of local services with Avahi
    (Issue #970)
    * Fixed listing jobs in destinations in web ui.
    (Apple issue #6204)
    * Fixed showing search query in web ui help page.
    (Issue #977)
    Issues are those at https://github.com/OpenPrinting/cups/issues
    Apple issues are those at https://github.com/apple/cups/issues
  - Adapted downgrade-autoconf-requirement.patch for CUPS 2.4.10
  - Removed cups-2.4.8-CVE-2024-35235.patch : fixed upstream
    see the above CUPS 2.4.9 changes
  - avoid_C99_mode_for_loop_initial_declarations.patch avoids error
    "'for' loop initial declarations are only allowed in C99 mode"
    that happens when building for SLE12
    in scheduler/client.c at "for (char *start = ..." since
    https://github.com/OpenPrinting/cups/commit/a7eda84da73126e40400e05dd27d57f8c92d5b0d
    see https://github.com/OpenPrinting/cups/issues/1000

++++ kernel-default:

  - io_uring/rsrc: fix incorrect assignment of iter->nr_segs in
    io_import_fixed (git-fixes).
  - io_uring/rsrc: don't lock while !TASK_RUNNING (git-fixes).
  - io_uring/io-wq: avoid garbage value of 'match' in
    io_wq_enqueue() (git-fixes).
  - commit 7d3e252
  - io_uring: check for non-NULL file pointer in io_file_can_poll()
    (bsc#1226990 CVE-2024-39371).
  - io_uring/io-wq: Use set_bit() and test_bit() at worker->flags
    (git-fixes).
  - io_uring/sqpoll: work around a potential audit memory leak
    (git-fixes).
  - commit 24603fc
  - io_uring: Fix io_cqring_wait() not restoring sigmask on
    get_timespec64() failure (git-fixes).
  - commit e640a65
  - hsr: Prevent use after free in prp_create_tagged_frame()
    (CVE-2023-52846 bsc#1225098).
  - commit cf63988
  - drivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()
    (CVE-2024-38610 bsc#1226758).
  - commit 7069ac2
  - virt: acrn: stop using follow_pfn (CVE-2024-38610 bsc#1226758).
  - commit c2ea51b
  - btrfs: fix crash on racing fsync and size-extending write into
    prealloc (bsc#1227101 CVE-2024-37354).
  - commit 1d355af
  - blk-mq: add helper for checking if one CPU is mapped to
    specified hctx (bsc#1223600).
  - blk-mq: don't schedule block kworker on isolated CPUs
    (bsc#1223600).
  - commit 2b67848
  - kernel-doc: fix struct_group_tagged() parsing (git-fixes).
  - commit e3a2a2e
  - mtd: rawnand: rockchip: ensure NVDDR timings are rejected
    (git-fixes).
  - mtd: rawnand: Bypass a couple of sanity checks during NAND
    identification (git-fixes).
  - mtd: rawnand: Fix the nand_read_data_op() early check
    (git-fixes).
  - mtd: rawnand: Ensure ECC configuration is propagated to upper
    layers (git-fixes).
  - commit e545951
  - Correct SCSI patch references (bsc#1225767 CVE-2024-36919 bsc#1226785 CVE-2024-38559)
  - commit e8ea587
  - gfs2: Fix potential glock use-after-free on unmount (bsc#1226775
    CVE-2024-38570).
  - gfs2: Rename sd_{ glock => kill }_wait (bsc#1226775
    CVE-2024-38570).
  - commit f3adbca

++++ kernel-rt:

  - io_uring/rsrc: fix incorrect assignment of iter->nr_segs in
    io_import_fixed (git-fixes).
  - io_uring/rsrc: don't lock while !TASK_RUNNING (git-fixes).
  - io_uring/io-wq: avoid garbage value of 'match' in
    io_wq_enqueue() (git-fixes).
  - commit 7d3e252
  - io_uring: check for non-NULL file pointer in io_file_can_poll()
    (bsc#1226990 CVE-2024-39371).
  - io_uring/io-wq: Use set_bit() and test_bit() at worker->flags
    (git-fixes).
  - io_uring/sqpoll: work around a potential audit memory leak
    (git-fixes).
  - commit 24603fc
  - io_uring: Fix io_cqring_wait() not restoring sigmask on
    get_timespec64() failure (git-fixes).
  - commit e640a65
  - hsr: Prevent use after free in prp_create_tagged_frame()
    (CVE-2023-52846 bsc#1225098).
  - commit cf63988
  - drivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()
    (CVE-2024-38610 bsc#1226758).
  - commit 7069ac2
  - virt: acrn: stop using follow_pfn (CVE-2024-38610 bsc#1226758).
  - commit c2ea51b
  - btrfs: fix crash on racing fsync and size-extending write into
    prealloc (bsc#1227101 CVE-2024-37354).
  - commit 1d355af
  - blk-mq: add helper for checking if one CPU is mapped to
    specified hctx (bsc#1223600).
  - blk-mq: don't schedule block kworker on isolated CPUs
    (bsc#1223600).
  - commit 2b67848
  - kernel-doc: fix struct_group_tagged() parsing (git-fixes).
  - commit e3a2a2e
  - mtd: rawnand: rockchip: ensure NVDDR timings are rejected
    (git-fixes).
  - mtd: rawnand: Bypass a couple of sanity checks during NAND
    identification (git-fixes).
  - mtd: rawnand: Fix the nand_read_data_op() early check
    (git-fixes).
  - mtd: rawnand: Ensure ECC configuration is propagated to upper
    layers (git-fixes).
  - commit e545951
  - Correct SCSI patch references (bsc#1225767 CVE-2024-36919 bsc#1226785 CVE-2024-38559)
  - commit e8ea587
  - gfs2: Fix potential glock use-after-free on unmount (bsc#1226775
    CVE-2024-38570).
  - gfs2: Rename sd_{ glock => kill }_wait (bsc#1226775
    CVE-2024-38570).
  - commit f3adbca

++++ openssl-3:

  - FIPS: Deny SHA-1 signature verification in FIPS provider [bsc#1221365]
    * SHA-1 is not allowed anymore in FIPS 186-5 for signature
    verification operations. After 12/31/2030, NIST will disallow
    SHA-1 for all of its usages.
    * Add openssl-3-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch

++++ libzypp:

  - Install zypp/APIConfig.h legacy include (fixes #557)
  - version 17.35.1 (35)

++++ osinfo-db:

  - Update to database version 20240701
    osinfo-db-20240701.tar.xz

++++ zypper:

  - Show rpm install size before installing (bsc#1224771)
    If filesystem snapshots are taken before the installation (e.g.
    by snapper) no disk space is freed by removing old packages. In
    this case the install size of all packages is a hint how much
    additional disk space is needed by the new packages static
    content.
  - version 1.14.76
  - Fix readline setup to handle Ctrl-C and Ctrl-D corrrectly
    (bsc#1227205)
  - version 1.14.75

------------------------------------------------------------------
------------------  2024-7-1  -  Jul 1 2024  -------------------
------------------------------------------------------------------

++++ checkpolicy:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    * User-visible changes:
    * checkpolicy: support CIDR notation for nodecon statements
    * checkpolicy: provide more descriptive error messages and improve error handling
    * Bugfixes:
    * checkpolicy: handle unprintable token
    * checkpolicy: avoid assigning garbage values
    * checkpolicy: free temporary bounds type
    * checkpolicy: perform contiguous check in host byte order
    * checkpolicy: include <ctype.h> for isprint(3)
    * oss-fuzz fixes:
    * checkpolicy: add libfuzz based fuzzer
    * checkpolicy: free complete role_allow_rule on error
    * checkpolicy: free identifiers on invalid typebounds
    * checkpolicy: return YYerror on invalid character
    * checkpolicy: clone level only once

++++ dhcpcd:

  - Initial packaging @ 10.0.8

++++ kernel-default:

  - X.509: Fix the parser of extended key usage for length
    (bsc#1218820).
  - commit a9df6a7
  - tcp: Use refcount_inc_not_zero() in tcp_twsk_unique()
    (CVE-2024-36904 bsc#1225732).
  - commit d578dcc
  - Update
    patches.suse/1352-drm-amdgpu-Fix-possible-null-pointer-dereference.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52883
    bsc#1226630).
  - Update
    patches.suse/9p-add-missing-locking-around-taking-dentry-fid-list.patch
    (git-fixes CVE-2024-39463 bsc#1227090).
  - Update
    patches.suse/ALSA-Fix-deadlocks-with-kctl-removals-at-disconnecti.patch
    (stable-fixes CVE-2024-38600 bsc#1226864).
  - Update
    patches.suse/ALSA-core-Fix-NULL-module-pointer-assignment-at-card.patch
    (git-fixes CVE-2024-38605 bsc#1226740).
  - Update
    patches.suse/ALSA-hda-Fix-possible-null-ptr-deref-when-assigning-.patch
    (git-fixes CVE-2023-52806 bsc#1225554).
  - Update
    patches.suse/ALSA-hda-cs_dsp_ctl-Use-private_free-for-control-cle.patch
    (git-fixes CVE-2024-38388 bsc#1226890).
  - Update
    patches.suse/ALSA-timer-Set-lower-bound-of-start-tick-time.patch
    (stable-fixes git-fixes CVE-2024-38618 bsc#1226754).
  - Update
    patches.suse/ASoC-kirkwood-Fix-potential-NULL-dereference.patch
    (git-fixes CVE-2024-38550 bsc#1226633).
  - Update
    patches.suse/ASoC-mediatek-Assign-dummy-when-codec-not-specified-.patch
    (git-fixes CVE-2024-38551 bsc#1226761).
  - Update
    patches.suse/Bluetooth-btusb-Add-date-evt_skb-is-NULL-check.patch
    (git-fixes CVE-2023-52833 bsc#1225595).
  - Update
    patches.suse/Bluetooth-hci_core-Fix-possible-buffer-overflow.patch
    (git-fixes CVE-2024-26889).
  - Update
    patches.suse/HID-uclogic-Fix-user-memory-access-bug-in-uclogic_pa.patch
    (git-fixes CVE-2023-52866 bsc#1225120).
  - Update
    patches.suse/IB-mlx5-Fix-init-stage-error-handling-to-avoid-doubl.patch
    (jsc#PED-6864 CVE-2023-52851 bsc#1225587).
  - Update
    patches.suse/Input-cyapa-add-missing-input-core-locking-to-suspen.patch
    (git-fixes CVE-2023-52884 bsc#1226764).
  - Update
    patches.suse/Input-synaptics-rmi4-fix-use-after-free-in-rmi_unreg.patch
    (git-fixes CVE-2023-52840 bsc#1224928).
  - Update
    patches.suse/KEYS-trusted-Do-not-use-WARN-when-encode-fails.patch
    (git-fixes CVE-2024-36975 bsc#1226520).
  - Update
    patches.suse/KEYS-trusted-Fix-memory-leak-in-tpm2_key_encode.patch
    (git-fixes CVE-2024-36967 bsc#1226131).
  - Update
    patches.suse/RDMA-cma-Fix-kmemleak-in-rdma_core-observed-during-b.patch
    (git-fixes CVE-2024-38539 bsc#1226608).
  - Update patches.suse/RDMA-hns-Fix-UAF-for-cq-async-event.patch
    (git-fixes CVE-2024-38545 bsc#1226595).
  - Update
    patches.suse/RDMA-hns-Fix-deadlock-on-SRQ-async-events.patch
    (git-fixes CVE-2024-38591 bsc#1226738).
  - Update
    patches.suse/RDMA-hns-Modify-the-print-level-of-CQE-error.patch
    (git-fixes CVE-2024-38590 bsc#1226839).
  - Update
    patches.suse/RDMA-rxe-Fix-seg-fault-in-rxe_comp_queue_pkt.patch
    (git-fixes CVE-2024-38544 bsc#1226597).
  - Update
    patches.suse/SUNRPC-Fix-RPC-client-cleaned-up-the-freed-pipefs-de.patch
    (git-fixes CVE-2023-52803 bsc#1225008).
  - Update patches.suse/af_unix-Clear-stale-u-oob_skb.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-35970 bsc#1224584).
  - Update
    patches.suse/af_unix-Drop-oob_skb-ref-before-purging-queue-in-GC.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-26750 bsc#1222617).
  - Update
    patches.suse/af_unix-Fix-task-hung-while-purging-oob_skb-in-GC.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-26780 bsc#1222588).
  - Update
    patches.suse/af_unix-Update-unix_sk-sk-oob_skb-under-sk_receive_queue-lock.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-36972 bsc#1226163).
  - Update
    patches.suse/arm64-Restrict-CPU_BIG_ENDIAN-to-GNU-as-or-LLVM-IAS-.patch
    (git-fixes CVE-2023-52750 bsc#1225485).
  - Update
    patches.suse/atl1c-Work-around-the-DMA-RX-overflow-issue.patch
    (git-fixes CVE-2023-52834 bsc#1225599).
  - Update
    patches.suse/ax25-Fix-reference-count-leak-issue-of-net_device.patch
    (git-fixes CVE-2024-38554 bsc#1226742).
  - Update
    patches.suse/ax25-Fix-reference-count-leak-issues-of-ax25_dev.patch
    (git-fixes CVE-2024-38602 bsc#1226613).
  - Update
    patches.suse/blk-cgroup-fix-list-corruption-from-reorder-of-WRITE-lqueued.patch
    (bsc#1225605 CVE-2024-38384 bsc#1226938).
  - Update
    patches.suse/blk-cgroup-fix-list-corruption-from-resetting-io-stat.patch
    (bsc#1225605 CVE-2024-38663 bsc#1226939).
  - Update
    patches.suse/bnxt_re-avoid-shift-undefined-behavior-in-bnxt_qplib.patch
    (git-fixes CVE-2024-38540 bsc#1226582).
  - Update
    patches.suse/bonding-stop-the-device-in-bond_setup_by_slave.patch
    (git-fixes CVE-2023-52784 bsc#1224946).
  - Update
    patches.suse/can-dev-can_put_echo_skb-don-t-crash-kernel-if-can_p.patch
    (git-fixes CVE-2023-52878 bsc#1225000).
  - Update
    patches.suse/clk-mediatek-clk-mt2701-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52875 bsc#1225096).
  - Update
    patches.suse/clk-mediatek-clk-mt6765-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52870 bsc#1224937).
  - Update
    patches.suse/clk-mediatek-clk-mt6779-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52873 bsc#1225589).
  - Update
    patches.suse/clk-mediatek-clk-mt6797-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52865 bsc#1225086).
  - Update
    patches.suse/clk-mediatek-clk-mt7629-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52858 bsc#1225566).
  - Update
    patches.suse/clk-mediatek-clk-mt7629-eth-Add-check-for-mtk_alloc_.patch
    (git-fixes CVE-2023-52876 bsc#1225036).
  - Update
    patches.suse/cppc_cpufreq-Fix-possible-null-pointer-dereference.patch
    (git-fixes CVE-2024-38573 bsc#1226739).
  - Update patches.suse/cpufreq-exit-callback-is-optional.patch
    (git-fixes CVE-2024-38615 bsc#1226592).
  - Update patches.suse/crypto-bcm-Fix-pointer-arithmetic.patch
    (git-fixes CVE-2024-38579 bsc#1226637).
  - Update
    patches.suse/crypto-pcrypt-Fix-hungtask-for-PADATA_RESET.patch
    (git-fixes CVE-2023-52813 bsc#1225527).
  - Update patches.suse/cxl-mem-Fix-shutdown-order.patch (git-fixes
    CVE-2023-52849 bsc#1224949).
  - Update
    patches.suse/cxl-region-Do-not-try-to-cleanup-after-cxl_region_se.patch
    (git-fixes CVE-2023-52792 bsc#1225477).
  - Update patches.suse/cxl-region-Fix-cxlr_pmem-leaks.patch
    (git-fixes CVE-2024-38391 bsc#1226894).
  - Update
    patches.suse/dma-buf-sw-sync-don-t-enable-IRQ-from-sync_print_obj.patch
    (git-fixes CVE-2024-38780 bsc#1226886).
  - Update
    patches.suse/dma-mapping-benchmark-fix-node-id-validation.patch
    (git-fixes CVE-2024-34777 bsc#1226796).
  - Update
    patches.suse/dma-mapping-benchmark-handle-NUMA_NO_NODE-correctly.patch
    (git-fixes CVE-2024-39277 bsc#1226909).
  - Update
    patches.suse/dmaengine-idxd-Avoid-unnecessary-destruction-of-file.patch
    (git-fixes CVE-2024-38629 bsc#1226905).
  - Update
    patches.suse/drm-amd-Fix-UBSAN-array-index-out-of-bounds-for-Pola.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52819
    bsc#1225532).
  - Update
    patches.suse/drm-amd-Fix-UBSAN-array-index-out-of-bounds-for-SMU7.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52818
    bsc#1225530).
  - Update
    patches.suse/drm-amd-check-num-of-link-levels-when-update-pcie-pa.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52812
    bsc#1225564).
  - Update
    patches.suse/drm-amd-display-Avoid-NULL-dereference-of-timing-gen.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52753
    bsc#1225478).
  - Update
    patches.suse/drm-amd-display-Fix-division-by-zero-in-setup_dsc_co.patch
    (stable-fixes CVE-2024-36969 bsc#1226155).
  - Update
    patches.suse/drm-amd-display-Fix-null-pointer-dereference-in-erro.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52862
    bsc#1225015).
  - Update
    patches.suse/drm-amd-display-Fix-potential-index-out-of-bounds-in.patch
    (git-fixes CVE-2024-38552 bsc#1226767).
  - Update
    patches.suse/drm-amd-display-fix-a-NULL-pointer-dereference-in-am.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52773
    bsc#1225041).
  - Update
    patches.suse/drm-amd-display-fixed-integer-types-and-null-check-l.patch
    (git-fixes CVE-2024-26767).
  - Update
    patches.suse/drm-amdgpu-Fix-a-null-pointer-access-when-the-smc_rr.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52817
    bsc#1225569).
  - Update
    patches.suse/drm-amdgpu-Fix-buffer-size-in-gfx_v9_4_3_init_-cp_co.patch
    (git-fixes CVE-2024-39291 bsc#1226934).
  - Update
    patches.suse/drm-amdgpu-Fix-potential-null-pointer-derefernce.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52814
    bsc#1225565).
  - Update
    patches.suse/drm-amdgpu-add-error-handle-to-avoid-out-of-bounds.patch
    (stable-fixes CVE-2024-39471 bsc#1227096).
  - Update
    patches.suse/drm-amdgpu-mes-fix-use-after-free-issue.patch
    (stable-fixes CVE-2024-38581 bsc#1226657).
  - Update
    patches.suse/drm-amdgpu-vkms-fix-a-possible-null-pointer-derefere.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52815
    bsc#1225568).
  - Update
    patches.suse/drm-amdkfd-Fix-a-race-condition-of-vram-buffer-unref.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52825
    bsc#1225076).
  - Update
    patches.suse/drm-amdkfd-Fix-shift-out-of-bounds-issue.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52816
    bsc#1225529).
  - Update
    patches.suse/drm-bridge-cdns-mhdp8546-Fix-possible-null-pointer-d.patch
    (git-fixes CVE-2024-38548).
  - Update
    patches.suse/drm-bridge-it66121-Fix-invalid-connector-dereference.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52861
    bsc#1224941).
  - Update
    patches.suse/drm-bridge-lt8912b-Fix-crash-on-bridge-detach.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52856
    bsc#1224932).
  - Update
    patches.suse/drm-mediatek-Add-0-size-check-to-mtk_drm_gem_obj.patch
    (git-fixes CVE-2024-38549 bsc#1226735).
  - Update
    patches.suse/drm-mediatek-Fix-coverity-issue-with-unintentional-i.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52857
    bsc#1225581).
  - Update
    patches.suse/drm-mediatek-Init-ddp_comp-with-devm_kcalloc.patch
    (git-fixes CVE-2024-38592 bsc#1226844).
  - Update
    patches.suse/drm-msm-a6xx-Avoid-a-nullptr-dereference-when-speedb.patch
    (git-fixes CVE-2024-38390 bsc#1226891).
  - Update
    patches.suse/drm-msm-dpu-Add-callback-function-pointer-check-befo.patch
    (git-fixes CVE-2024-38622 bsc#1226856).
  - Update
    patches.suse/drm-panel-fix-a-possible-null-pointer-dereference.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52821
    bsc#1225022).
  - Update
    patches.suse/drm-panel-panel-tpo-tpg110-fix-a-possible-null-point.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52826
    bsc#1225077).
  - Update patches.suse/drm-radeon-possible-buffer-overflow.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52867
    bsc#1225009).
  - Update
    patches.suse/drm-vc4-Fix-possible-null-pointer-dereference.patch
    (git-fixes CVE-2024-38546 bsc#1226593).
  - Update
    patches.suse/drm-vmwgfx-Fix-invalid-reads-in-fence-signaled-event.patch
    (git-fixes CVE-2024-36960 bsc#1225872).
  - Update
    patches.suse/drm-zynqmp_dpsub-Always-register-bridge.patch
    (git-fixes CVE-2024-38664 bsc#1226941).
  - Update
    patches.suse/e1000e-change-usleep_range-to-udelay-in-PHY-mdic-acc.patch
    (CVE-2024-39296 bsc#1226989 CVE-2024-36887 bsc#1225731).
  - Update
    patches.suse/ecryptfs-Fix-buffer-size-for-tag-66-packet.patch
    (git-fixes CVE-2024-38578 bsc#1226634).
  - Update
    patches.suse/efi-libstub-only-free-priv.runtime_map-when-allocate.patch
    (git-fixes CVE-2024-33619 bsc#1226768).
  - Update
    patches.suse/fbdev-imsttfb-fix-a-resource-leak-in-probe.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52838
    bsc#1225031).
  - Update
    patches.suse/fs-9p-only-translate-RWX-permissions-for-plain-9P200.patch
    (git-fixes CVE-2024-36964 bsc#1225866).
  - Update
    patches.suse/fs-jfs-Add-check-for-negative-db_l2nbperpage.patch
    (git-fixes CVE-2023-52810 bsc#1225557).
  - Update
    patches.suse/fs-jfs-Add-validity-check-for-db_maxag-and-db_agpref.patch
    (git-fixes CVE-2023-52804 bsc#1225550).
  - Update
    patches.suse/ftrace-Fix-possible-use-after-free-issue-in-ftrace_location.patch
    (git-fixes CVE-2024-38588 bsc#1226837).
  - Update
    patches.suse/genirq-irqdesc-Prevent-use-after-free-in-irq_find_at.patch
    (git-fixes CVE-2024-38385 bsc#1227085).
  - Update patches.suse/gfs2-ignore-negated-quota-changes.patch
    (git-fixes CVE-2023-52759 bsc#1225560).
  - Update
    patches.suse/hid-cp2112-Fix-duplicate-workqueue-initialization.patch
    (git-fixes CVE-2023-52853 bsc#1224988).
  - Update
    patches.suse/hwmon-axi-fan-control-Fix-possible-NULL-pointer-dere.patch
    (git-fixes CVE-2023-52863 bsc#1225586).
  - Update
    patches.suse/i2c-acpi-Unbind-mux-adapters-before-delete.patch
    (git-fixes CVE-2024-39362 bsc#1226995).
  - Update
    patches.suse/i2c-core-Run-atomic-i2c-xfer-when-preemptible.patch
    (git-fixes CVE-2023-52791 bsc#1225108).
  - Update
    patches.suse/i3c-master-mipi-i3c-hci-Fix-a-kernel-panic-for-acces.patch
    (git-fixes CVE-2023-52763 bsc#1225570).
  - Update
    patches.suse/i3c-mipi-i3c-hci-Fix-out-of-bounds-access-in-hci_dma.patch
    (git-fixes CVE-2023-52766).
  - Update
    patches.suse/i915-perf-Fix-NULL-deref-bugs-with-drm_dbg-calls.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52788
    bsc#1225106).
  - Update
    patches.suse/igb-Fix-string-truncation-warnings-in-igb_set_fw_ver.patch
    (git-fixes CVE-2024-36010 bsc#1225594).
  - Update
    patches.suse/iommu-vt-d-Fix-WARN_ON-in-iommu-probe-path.patch
    (git-fixes CVE-2024-35957 bsc#1224673).
  - Update
    patches.suse/iommufd-Fix-missing-update-of-domains_itree-after-splitting-iopt
    (jsc#PED-7779 jsc#PED-7780 CVE-2023-52801 bsc#1225006).
  - Update
    patches.suse/ipvlan-add-ipvlan_route_v6_outbound-helper.patch
    (git-fixes CVE-2023-52796 bsc#1224930).
  - Update
    patches.suse/jffs2-prevent-xattr-node-from-overflowing-the-eraseblock.patch
    (git-fixes CVE-2024-38599 bsc#1226848).
  - Update
    patches.suse/jfs-fix-array-index-out-of-bounds-in-dbFindLeaf.patch
    (git-fixes CVE-2023-52799 bsc#1225472).
  - Update
    patches.suse/jfs-fix-array-index-out-of-bounds-in-diAlloc.patch
    (git-fixes CVE-2023-52805 bsc#1225553).
  - Update
    patches.suse/kunit-fortify-Fix-mismatched-kvalloc-vfree-usage.patch
    (git-fixes CVE-2024-38617 bsc#1226859).
  - Update
    patches.suse/lib-generic-radix-tree.c-Don-t-overflow-in-peek.patch
    (git-fixes CVE-2021-47432 bsc#1225391).
  - Update
    patches.suse/lib-test_hmm.c-handle-src_pfns-and-dst_pfns-allocati.patch
    (git-fixes CVE-2024-38543 bsc#1226594).
  - Update
    patches.suse/locking-ww_mutex-test-Fix-potential-workqueue-corrup.patch
    (bsc#1219953 CVE-2023-52836 bsc#1225609).
  - Update
    patches.suse/md-Don-t-ignore-suspended-array-in-md_check_recovery-1baa.patch
    (bsc#1219596 CVE-2024-26758).
  - Update
    patches.suse/media-atomisp-ssh_css-Fix-a-null-pointer-dereference.patch
    (git-fixes CVE-2024-38547 bsc#1226632).
  - Update
    patches.suse/media-bttv-fix-use-after-free-error-due-to-btv-timeo.patch
    (git-fixes CVE-2023-52847 bsc#1225588).
  - Update
    patches.suse/media-gspca-cpia1-shift-out-of-bounds-in-set_flicker.patch
    (git-fixes CVE-2023-52764 bsc#1225571).
  - Update
    patches.suse/media-hantro-Check-whether-reset-op-is-defined-befor.patch
    (git-fixes CVE-2023-52850 bsc#1225014).
  - Update
    patches.suse/media-i2c-et8ek8-Don-t-strip-remove-function-when-dr.patch
    (git-fixes CVE-2024-38611 bsc#1226760).
  - Update
    patches.suse/media-imon-fix-access-to-invalid-resource-for-the-se.patch
    (git-fixes CVE-2023-52754 bsc#1225490).
  - Update
    patches.suse/media-lgdt3306a-Add-a-check-against-null-pointer-def.patch
    (stable-fixes CVE-2022-48772 bsc#1226976).
  - Update
    patches.suse/media-stk1160-fix-bounds-checking-in-stk1160_copy_vi.patch
    (git-fixes CVE-2024-38621 bsc#1226895).
  - Update
    patches.suse/media-vidtv-mux-Add-check-and-kfree-for-kstrdup.patch
    (git-fixes CVE-2023-52841 bsc#1225592).
  - Update patches.suse/media-vidtv-psi-Add-check-for-kstrdup.patch
    (git-fixes CVE-2023-52844 bsc#1225590).
  - Update
    patches.suse/mfd-qcom-spmi-pmic-Fix-revid-implementation.patch
    (git-fixes CVE-2023-52765 bsc#1225029).
  - Update
    patches.suse/misc-microchip-pci1xxxx-fix-double-free-in-the-error.patch
    (git-fixes CVE-2024-36973 bsc#1226457).
  - Update
    patches.suse/net-hns3-fix-out-of-bounds-access-may-occur-when-coa.patch
    (git-fixes CVE-2023-52807 bsc#1225097).
  - Update
    patches.suse/net-ks8851-Queue-RX-packets-in-IRQ-handler-instead-o.patch
    (git-fixes CVE-2024-36962 bsc#1225827).
  - Update
    patches.suse/net-mlx5-Fix-peer-devlink-set-for-SF-representor-dev.patch
    (git-fixes CVE-2024-38595 bsc#1226741).
  - Update
    patches.suse/net-mlx5e-Track-xmit-submission-to-PTP-WQ-after-popu.patch
    (jsc#PED-3311 CVE-2023-52782 bsc#1225103).
  - Update
    patches.suse/net-mvneta-fix-calls-to-page_pool_get_stats.patch
    (git-fixes CVE-2023-52780 bsc#1224933).
  - Update
    patches.suse/net-wangxun-fix-kernel-panic-due-to-null-pointer.patch
    (git-fixes CVE-2023-52783 bsc#1225104).
  - Update
    patches.suse/netfilter-complete-validation-of-user-input.patch
    (git-fixes CVE-2024-35896 bsc#1224662 CVE-2024-35962
    bsc#1224583).
  - Update
    patches.suse/nfc-nci-Fix-uninit-value-in-nci_rx_work.patch
    (git-fixes CVE-2024-38381 bsc#1226878).
  - Update
    patches.suse/nilfs2-fix-nilfs_empty_dir-misjudgment-and-long-loop.patch
    (git-fixes CVE-2024-39469 bsc#1226992).
  - Update
    patches.suse/nilfs2-fix-potential-hang-in-nilfs_detach_log_writer.patch
    (git-fixes CVE-2024-38582 bsc#1226658).
  - Update
    patches.suse/nilfs2-fix-use-after-free-of-timer-for-log-writer-th.patch
    (git-fixes CVE-2024-38583 bsc#1226777).
  - Update
    patches.suse/of-module-add-buffer-overflow-check-in-of_modalias.patch
    (git-fixes CVE-2024-38541 bsc#1226587).
  - Update
    patches.suse/padata-Fix-refcnt-handling-in-padata_free_shell.patch
    (git-fixes CVE-2023-52854 bsc#1225584).
  - Update
    patches.suse/perf-core-Bail-out-early-if-the-request-AUX-area-is-out-of-bound.patch
    (git-fixes CVE-2023-52835 bsc#1225602).
  - Update
    patches.suse/platform-x86-wmi-Fix-opening-of-char-device.patch
    (git-fixes CVE-2023-52864 bsc#1225132).
  - Update
    patches.suse/powerpc-pseries-iommu-LPAR-panics-during-boot-up-wit.patch
    (bsc#1222011 ltc#205900 CVE-2024-36926 bsc#1225829).
  - Update patches.suse/pstore-platform-Add-check-for-kstrdup.patch
    (git-fixes CVE-2023-52869 bsc#1225050).
  - Update
    patches.suse/remoteproc-mediatek-Make-sure-IPI-buffer-fits-in-L2T.patch
    (git-fixes CVE-2024-36965 bsc#1226149).
  - Update
    patches.suse/ring-buffer-Fix-a-race-between-readers-and-resize-checks.patch
    (git-fixes CVE-2024-38601 bsc#1226876).
  - Update
    patches.suse/s390-dasd-protect-device-queue-against-concurrent-access.patch
    (git-fixes bsc#1217481 CVE-2023-52774 bsc#1225572).
  - Update
    patches.suse/scsi-hisi_sas-Set-debugfs_dir-pointer-to-NULL-after-removing-debugfs.patch
    (git-fixes CVE-2023-52808 bsc#1225555).
  - Update
    patches.suse/scsi-ibmvfc-Remove-BUG_ON-in-the-case-of-an-empty-ev.patch
    (bsc#1209834 ltc#202097 CVE-2023-52811 bsc#1225559).
  - Update
    patches.suse/scsi-libfc-Fix-potential-NULL-pointer-dereference-in-fc_lport_ptp_setup.patch
    (git-fixes CVE-2023-52809 bsc#1225556).
  - Update
    patches.suse/scsi-lpfc-Move-NPIV-s-transport-unregistration-to-af.patch
    (bsc#1221777 CVE-2024-36952 bsc#1225898).
  - Update
    patches.suse/scsi-lpfc-Release-hbalock-before-calling-lpfc_worker.patch
    (bsc#1221777 CVE-2024-36924 bsc#1225820).
  - Update
    patches.suse/serial-max3100-Lock-port-lock-when-calling-uart_hand.patch
    (git-fixes CVE-2024-38634 bsc#1226868).
  - Update
    patches.suse/serial-max3100-Update-uart_driver_registered-on-driv.patch
    (git-fixes CVE-2024-38633 bsc#1226867).
  - Update
    patches.suse/soc-qcom-llcc-Handle-a-second-device-without-data-co.patch
    (git-fixes CVE-2023-52871 bsc#1225534).
  - Update
    patches.suse/soundwire-cadence-fix-invalid-PDI-offset.patch
    (stable-fixes CVE-2024-38635 bsc#1226863).
  - Update patches.suse/speakup-Fix-sizeof-vs-ARRAY_SIZE-bug.patch
    (git-fixes CVE-2024-38587 bsc#1226780).
  - Update patches.suse/spi-Fix-null-dereference-on-suspend.patch
    (git-fixes CVE-2023-52749 bsc#1225476).
  - Update
    patches.suse/thermal-core-prevent-potential-string-overflow.patch
    (git-fixes CVE-2023-52868 bsc#1225044).
  - Update
    patches.suse/thermal-drivers-qcom-lmh-Check-for-SCM-availability-.patch
    (git-fixes CVE-2024-39466 bsc#1227089).
  - Update
    patches.suse/thermal-drivers-tsens-Fix-null-pointer-dereference.patch
    (git-fixes CVE-2024-38571 bsc#1226737).
  - Update
    patches.suse/thermal-intel-powerclamp-fix-mismatch-in-get-functio.patch
    (git-fixes CVE-2023-52794 bsc#1225028).
  - Update
    patches.suse/tls-fix-NULL-deref-on-tls_sw_splice_eof-with-empty-r.patch
    (jsc#PED-6831 CVE-2023-52767 bsc#1224998).
  - Update
    patches.suse/tpm_tis_spi-Account-for-SPI-header-when-allocating-T.patch
    (git-fixes CVE-2024-36477 bsc#1226840).
  - Update
    patches.suse/tracing-Have-trace_event_file-have-ref-counters.patch
    (git-fixes CVE-2023-52879 bsc#1225101).
  - Update
    patches.suse/tracing-trigger-Fix-to-return-error-if-failed-to-alloc-snapshot.patch
    (git-fixes CVE-2024-26920).
  - Update
    patches.suse/tty-n_gsm-fix-race-condition-in-status-line-change-o.patch
    (git-fixes CVE-2023-52872 bsc#1225591).
  - Update
    patches.suse/tty-n_gsm-require-CAP_NET_ADMIN-to-attach-N_GSM0710-.patch
    (bsc#1222619 CVE-2023-52880).
  - Update
    patches.suse/tty-vcc-Add-check-for-kstrdup-in-vcc_probe.patch
    (git-fixes CVE-2023-52789 bsc#1225180).
  - Update
    patches.suse/usb-config-fix-iteration-issue-in-usb_get_bos_descri.patch
    (git-fixes CVE-2023-52781 bsc#1225092).
  - Update
    patches.suse/usb-dwc3-Wait-unconditionally-after-issuing-EndXfer-.patch
    (git-fixes CVE-2024-36977 bsc#1226513).
  - Update
    patches.suse/usb-gadget-u_audio-Fix-race-condition-use-of-control.patch
    (git-fixes CVE-2024-38628 bsc#1226911).
  - Update
    patches.suse/usb-storage-alauda-Check-whether-the-media-is-initia.patch
    (git-fixes CVE-2024-38619 bsc#1226861).
  - Update
    patches.suse/usb-typec-tcpm-Fix-NULL-pointer-dereference-in-tcpm_.patch
    (git-fixes CVE-2023-52877 bsc#1224944).
  - Update
    patches.suse/vhost-vdpa-fix-use-after-free-in-vhost_vdpa_probe.patch
    (jsc#PED-3311 CVE-2023-52795 bsc#1225085).
  - Update
    patches.suse/virtio-blk-fix-implicit-overflow-on-virtio_max_dma_s.patch
    (git-fixes CVE-2023-52762 bsc#1225573).
  - Update
    patches.suse/virtio-vsock-Fix-uninit-value-in-virtio_transport_re.patch
    (jsc#PED-5505 CVE-2023-52842 bsc#1225025).
  - Update
    patches.suse/watchdog-cpu5wdt.c-Fix-use-after-free-bug-caused-by-.patch
    (git-fixes CVE-2024-38630 bsc#1226908).
  - Update
    patches.suse/wifi-ar5523-enable-proper-endpoint-verification.patch
    (git-fixes CVE-2024-38565 bsc#1226747).
  - Update
    patches.suse/wifi-ath11k-fix-dfs-radar-event-locking.patch
    (git-fixes CVE-2023-52798 bsc#1224947).
  - Update
    patches.suse/wifi-ath11k-fix-gtk-offload-status-event-locking.patch
    (git-fixes CVE-2023-52777 bsc#1224992).
  - Update patches.suse/wifi-ath11k-fix-htt-pktlog-locking.patch
    (git-fixes CVE-2023-52800).
  - Update
    patches.suse/wifi-ath12k-fix-dfs-radar-and-temperature-event-lock.patch
    (git-fixes CVE-2023-52776 bsc#1225090).
  - Update
    patches.suse/wifi-ath12k-fix-htt-mlo-offset-event-locking.patch
    (git-fixes CVE-2023-52769 bsc#1225001).
  - Update
    patches.suse/wifi-ath12k-fix-out-of-bound-access-of-qmi_invoke_ha.patch
    (git-fixes CVE-2024-38572 bsc#1226776).
  - Update
    patches.suse/wifi-ath12k-fix-possible-out-of-bound-read-in-ath12k.patch
    (git-fixes CVE-2023-52827 bsc#1225078).
  - Update
    patches.suse/wifi-ath12k-fix-possible-out-of-bound-write-in-ath12.patch
    (git-fixes CVE-2023-52829 bsc#1225081).
  - Update
    patches.suse/wifi-brcmfmac-pcie-handle-randbuf-allocation-failure.patch
    (git-fixes CVE-2024-38575 bsc#1226612).
  - Update
    patches.suse/wifi-carl9170-add-a-proper-sanity-check-for-endpoint.patch
    (git-fixes CVE-2024-38567 bsc#1226769).
  - Update
    patches.suse/wifi-carl9170-re-fix-fortified-memset-warning.patch
    (git-fixes CVE-2024-38616 bsc#1226852).
  - Update
    patches.suse/wifi-mac80211-don-t-return-unset-power-in-ieee80211_.patch
    (git-fixes CVE-2023-52832 bsc#1225577).
  - Update
    patches.suse/wifi-nl80211-Avoid-address-calculations-via-out-of-b.patch
    (git-fixes CVE-2024-38562 bsc#1226788).
  - Update
    patches.suse/wifi-wilc1000-use-vmm_table-as-array-in-wilc-struct.patch
    (git-fixes CVE-2023-52768 bsc#1225004).
  - Update
    patches.suse/x86-tdx-Zero-out-the-missing-RSI-in-TDX_HYPERCALL-macro.patch
    (jsc#PED-5824 CVE-2023-52874 bsc#1225049).
  - commit 33efdc4
  - tcp: do not accept ACK of bytes we never sent (CVE-2023-52881
    bsc#1225611).
  - commit 16404a6
  - net: ena: Fix redundant device NUMA node override
    (jsc#PED-8688).
  - commit 6ad6684
  - ata: ahci: Clean up sysfs file on error (git-fixes).
  - ata: libata-core: Fix double free on error (git-fixes).
  - ata,scsi: libata-core: Do not leak memory for ata_port struct
    members (git-fixes).
  - ata: libata-core: Fix null pointer dereference on error
    (git-fixes).
  - kbuild: Fix build target deb-pkg: ln: failed to create hard link
    (git-fixes).
  - kbuild: doc: Update default INSTALL_MOD_DIR from extra to
    updates (git-fixes).
  - kbuild: Install dtb files as 0644 in Makefile.dtbinst
    (git-fixes).
  - counter: ti-eqep: enable clock at probe (git-fixes).
  - iio: chemical: bme680: Fix sensor data read operation
    (git-fixes).
  - iio: chemical: bme680: Fix overflows in compensate() functions
    (git-fixes).
  - iio: chemical: bme680: Fix calibration data variable
    (git-fixes).
  - iio: chemical: bme680: Fix pressure value output (git-fixes).
  - iio: accel: fxls8962af: select IIO_BUFFER & IIO_KFIFO_BUF
    (git-fixes).
  - iio: adc: ad7266: Fix variable checking bug (git-fixes).
  - iio: xilinx-ams: Don't include ams_ctrl_channels in scan_mask
    (git-fixes).
  - serial: bcm63xx-uart: fix tx after conversion to
    uart_port_tx_limited() (git-fixes).
  - serial: core: introduce uart_port_tx_limited_flags()
    (git-fixes).
  - Revert "serial: core: only stop transmit when HW fifo is empty"
    (git-fixes).
  - tty: mcf: MCF54418 has 10 UARTS (git-fixes).
  - usb: gadget: aspeed_udc: fix device address configuration
    (git-fixes).
  - usb: dwc3: core: remove lock of otg mode during gadget
    suspend/resume to avoid deadlock (git-fixes).
  - usb: typec: ucsi: glink: fix child node release in probe
    function (git-fixes).
  - usb: musb: da8xx: fix a resource leak in probe() (git-fixes).
  - usb: atm: cxacru: fix endpoint checking in cxacru_bind()
    (git-fixes).
  - usb: gadget: printer: fix races against disable (git-fixes).
  - PCI/MSI: Fix UAF in msi_capability_init (git-fixes).
  - commit a2ea5a9

++++ kernel-rt:

  - X.509: Fix the parser of extended key usage for length
    (bsc#1218820).
  - commit a9df6a7
  - tcp: Use refcount_inc_not_zero() in tcp_twsk_unique()
    (CVE-2024-36904 bsc#1225732).
  - commit d578dcc
  - Update
    patches.suse/1352-drm-amdgpu-Fix-possible-null-pointer-dereference.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52883
    bsc#1226630).
  - Update
    patches.suse/9p-add-missing-locking-around-taking-dentry-fid-list.patch
    (git-fixes CVE-2024-39463 bsc#1227090).
  - Update
    patches.suse/ALSA-Fix-deadlocks-with-kctl-removals-at-disconnecti.patch
    (stable-fixes CVE-2024-38600 bsc#1226864).
  - Update
    patches.suse/ALSA-core-Fix-NULL-module-pointer-assignment-at-card.patch
    (git-fixes CVE-2024-38605 bsc#1226740).
  - Update
    patches.suse/ALSA-hda-Fix-possible-null-ptr-deref-when-assigning-.patch
    (git-fixes CVE-2023-52806 bsc#1225554).
  - Update
    patches.suse/ALSA-hda-cs_dsp_ctl-Use-private_free-for-control-cle.patch
    (git-fixes CVE-2024-38388 bsc#1226890).
  - Update
    patches.suse/ALSA-timer-Set-lower-bound-of-start-tick-time.patch
    (stable-fixes git-fixes CVE-2024-38618 bsc#1226754).
  - Update
    patches.suse/ASoC-kirkwood-Fix-potential-NULL-dereference.patch
    (git-fixes CVE-2024-38550 bsc#1226633).
  - Update
    patches.suse/ASoC-mediatek-Assign-dummy-when-codec-not-specified-.patch
    (git-fixes CVE-2024-38551 bsc#1226761).
  - Update
    patches.suse/Bluetooth-btusb-Add-date-evt_skb-is-NULL-check.patch
    (git-fixes CVE-2023-52833 bsc#1225595).
  - Update
    patches.suse/Bluetooth-hci_core-Fix-possible-buffer-overflow.patch
    (git-fixes CVE-2024-26889).
  - Update
    patches.suse/HID-uclogic-Fix-user-memory-access-bug-in-uclogic_pa.patch
    (git-fixes CVE-2023-52866 bsc#1225120).
  - Update
    patches.suse/IB-mlx5-Fix-init-stage-error-handling-to-avoid-doubl.patch
    (jsc#PED-6864 CVE-2023-52851 bsc#1225587).
  - Update
    patches.suse/Input-cyapa-add-missing-input-core-locking-to-suspen.patch
    (git-fixes CVE-2023-52884 bsc#1226764).
  - Update
    patches.suse/Input-synaptics-rmi4-fix-use-after-free-in-rmi_unreg.patch
    (git-fixes CVE-2023-52840 bsc#1224928).
  - Update
    patches.suse/KEYS-trusted-Do-not-use-WARN-when-encode-fails.patch
    (git-fixes CVE-2024-36975 bsc#1226520).
  - Update
    patches.suse/KEYS-trusted-Fix-memory-leak-in-tpm2_key_encode.patch
    (git-fixes CVE-2024-36967 bsc#1226131).
  - Update
    patches.suse/RDMA-cma-Fix-kmemleak-in-rdma_core-observed-during-b.patch
    (git-fixes CVE-2024-38539 bsc#1226608).
  - Update patches.suse/RDMA-hns-Fix-UAF-for-cq-async-event.patch
    (git-fixes CVE-2024-38545 bsc#1226595).
  - Update
    patches.suse/RDMA-hns-Fix-deadlock-on-SRQ-async-events.patch
    (git-fixes CVE-2024-38591 bsc#1226738).
  - Update
    patches.suse/RDMA-hns-Modify-the-print-level-of-CQE-error.patch
    (git-fixes CVE-2024-38590 bsc#1226839).
  - Update
    patches.suse/RDMA-rxe-Fix-seg-fault-in-rxe_comp_queue_pkt.patch
    (git-fixes CVE-2024-38544 bsc#1226597).
  - Update
    patches.suse/SUNRPC-Fix-RPC-client-cleaned-up-the-freed-pipefs-de.patch
    (git-fixes CVE-2023-52803 bsc#1225008).
  - Update patches.suse/af_unix-Clear-stale-u-oob_skb.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-35970 bsc#1224584).
  - Update
    patches.suse/af_unix-Drop-oob_skb-ref-before-purging-queue-in-GC.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-26750 bsc#1222617).
  - Update
    patches.suse/af_unix-Fix-task-hung-while-purging-oob_skb-in-GC.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-26780 bsc#1222588).
  - Update
    patches.suse/af_unix-Update-unix_sk-sk-oob_skb-under-sk_receive_queue-lock.patch
    (CVE-2024-26676 bsc#1222380 CVE-2024-36972 bsc#1226163).
  - Update
    patches.suse/arm64-Restrict-CPU_BIG_ENDIAN-to-GNU-as-or-LLVM-IAS-.patch
    (git-fixes CVE-2023-52750 bsc#1225485).
  - Update
    patches.suse/atl1c-Work-around-the-DMA-RX-overflow-issue.patch
    (git-fixes CVE-2023-52834 bsc#1225599).
  - Update
    patches.suse/ax25-Fix-reference-count-leak-issue-of-net_device.patch
    (git-fixes CVE-2024-38554 bsc#1226742).
  - Update
    patches.suse/ax25-Fix-reference-count-leak-issues-of-ax25_dev.patch
    (git-fixes CVE-2024-38602 bsc#1226613).
  - Update
    patches.suse/blk-cgroup-fix-list-corruption-from-reorder-of-WRITE-lqueued.patch
    (bsc#1225605 CVE-2024-38384 bsc#1226938).
  - Update
    patches.suse/blk-cgroup-fix-list-corruption-from-resetting-io-stat.patch
    (bsc#1225605 CVE-2024-38663 bsc#1226939).
  - Update
    patches.suse/bnxt_re-avoid-shift-undefined-behavior-in-bnxt_qplib.patch
    (git-fixes CVE-2024-38540 bsc#1226582).
  - Update
    patches.suse/bonding-stop-the-device-in-bond_setup_by_slave.patch
    (git-fixes CVE-2023-52784 bsc#1224946).
  - Update
    patches.suse/can-dev-can_put_echo_skb-don-t-crash-kernel-if-can_p.patch
    (git-fixes CVE-2023-52878 bsc#1225000).
  - Update
    patches.suse/clk-mediatek-clk-mt2701-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52875 bsc#1225096).
  - Update
    patches.suse/clk-mediatek-clk-mt6765-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52870 bsc#1224937).
  - Update
    patches.suse/clk-mediatek-clk-mt6779-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52873 bsc#1225589).
  - Update
    patches.suse/clk-mediatek-clk-mt6797-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52865 bsc#1225086).
  - Update
    patches.suse/clk-mediatek-clk-mt7629-Add-check-for-mtk_alloc_clk_.patch
    (git-fixes CVE-2023-52858 bsc#1225566).
  - Update
    patches.suse/clk-mediatek-clk-mt7629-eth-Add-check-for-mtk_alloc_.patch
    (git-fixes CVE-2023-52876 bsc#1225036).
  - Update
    patches.suse/cppc_cpufreq-Fix-possible-null-pointer-dereference.patch
    (git-fixes CVE-2024-38573 bsc#1226739).
  - Update patches.suse/cpufreq-exit-callback-is-optional.patch
    (git-fixes CVE-2024-38615 bsc#1226592).
  - Update patches.suse/crypto-bcm-Fix-pointer-arithmetic.patch
    (git-fixes CVE-2024-38579 bsc#1226637).
  - Update
    patches.suse/crypto-pcrypt-Fix-hungtask-for-PADATA_RESET.patch
    (git-fixes CVE-2023-52813 bsc#1225527).
  - Update patches.suse/cxl-mem-Fix-shutdown-order.patch (git-fixes
    CVE-2023-52849 bsc#1224949).
  - Update
    patches.suse/cxl-region-Do-not-try-to-cleanup-after-cxl_region_se.patch
    (git-fixes CVE-2023-52792 bsc#1225477).
  - Update patches.suse/cxl-region-Fix-cxlr_pmem-leaks.patch
    (git-fixes CVE-2024-38391 bsc#1226894).
  - Update
    patches.suse/dma-buf-sw-sync-don-t-enable-IRQ-from-sync_print_obj.patch
    (git-fixes CVE-2024-38780 bsc#1226886).
  - Update
    patches.suse/dma-mapping-benchmark-fix-node-id-validation.patch
    (git-fixes CVE-2024-34777 bsc#1226796).
  - Update
    patches.suse/dma-mapping-benchmark-handle-NUMA_NO_NODE-correctly.patch
    (git-fixes CVE-2024-39277 bsc#1226909).
  - Update
    patches.suse/dmaengine-idxd-Avoid-unnecessary-destruction-of-file.patch
    (git-fixes CVE-2024-38629 bsc#1226905).
  - Update
    patches.suse/drm-amd-Fix-UBSAN-array-index-out-of-bounds-for-Pola.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52819
    bsc#1225532).
  - Update
    patches.suse/drm-amd-Fix-UBSAN-array-index-out-of-bounds-for-SMU7.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52818
    bsc#1225530).
  - Update
    patches.suse/drm-amd-check-num-of-link-levels-when-update-pcie-pa.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52812
    bsc#1225564).
  - Update
    patches.suse/drm-amd-display-Avoid-NULL-dereference-of-timing-gen.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52753
    bsc#1225478).
  - Update
    patches.suse/drm-amd-display-Fix-division-by-zero-in-setup_dsc_co.patch
    (stable-fixes CVE-2024-36969 bsc#1226155).
  - Update
    patches.suse/drm-amd-display-Fix-null-pointer-dereference-in-erro.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52862
    bsc#1225015).
  - Update
    patches.suse/drm-amd-display-Fix-potential-index-out-of-bounds-in.patch
    (git-fixes CVE-2024-38552 bsc#1226767).
  - Update
    patches.suse/drm-amd-display-fix-a-NULL-pointer-dereference-in-am.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52773
    bsc#1225041).
  - Update
    patches.suse/drm-amd-display-fixed-integer-types-and-null-check-l.patch
    (git-fixes CVE-2024-26767).
  - Update
    patches.suse/drm-amdgpu-Fix-a-null-pointer-access-when-the-smc_rr.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52817
    bsc#1225569).
  - Update
    patches.suse/drm-amdgpu-Fix-buffer-size-in-gfx_v9_4_3_init_-cp_co.patch
    (git-fixes CVE-2024-39291 bsc#1226934).
  - Update
    patches.suse/drm-amdgpu-Fix-potential-null-pointer-derefernce.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52814
    bsc#1225565).
  - Update
    patches.suse/drm-amdgpu-add-error-handle-to-avoid-out-of-bounds.patch
    (stable-fixes CVE-2024-39471 bsc#1227096).
  - Update
    patches.suse/drm-amdgpu-mes-fix-use-after-free-issue.patch
    (stable-fixes CVE-2024-38581 bsc#1226657).
  - Update
    patches.suse/drm-amdgpu-vkms-fix-a-possible-null-pointer-derefere.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52815
    bsc#1225568).
  - Update
    patches.suse/drm-amdkfd-Fix-a-race-condition-of-vram-buffer-unref.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52825
    bsc#1225076).
  - Update
    patches.suse/drm-amdkfd-Fix-shift-out-of-bounds-issue.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52816
    bsc#1225529).
  - Update
    patches.suse/drm-bridge-cdns-mhdp8546-Fix-possible-null-pointer-d.patch
    (git-fixes CVE-2024-38548).
  - Update
    patches.suse/drm-bridge-it66121-Fix-invalid-connector-dereference.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52861
    bsc#1224941).
  - Update
    patches.suse/drm-bridge-lt8912b-Fix-crash-on-bridge-detach.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52856
    bsc#1224932).
  - Update
    patches.suse/drm-mediatek-Add-0-size-check-to-mtk_drm_gem_obj.patch
    (git-fixes CVE-2024-38549 bsc#1226735).
  - Update
    patches.suse/drm-mediatek-Fix-coverity-issue-with-unintentional-i.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52857
    bsc#1225581).
  - Update
    patches.suse/drm-mediatek-Init-ddp_comp-with-devm_kcalloc.patch
    (git-fixes CVE-2024-38592 bsc#1226844).
  - Update
    patches.suse/drm-msm-a6xx-Avoid-a-nullptr-dereference-when-speedb.patch
    (git-fixes CVE-2024-38390 bsc#1226891).
  - Update
    patches.suse/drm-msm-dpu-Add-callback-function-pointer-check-befo.patch
    (git-fixes CVE-2024-38622 bsc#1226856).
  - Update
    patches.suse/drm-panel-fix-a-possible-null-pointer-dereference.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52821
    bsc#1225022).
  - Update
    patches.suse/drm-panel-panel-tpo-tpg110-fix-a-possible-null-point.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52826
    bsc#1225077).
  - Update patches.suse/drm-radeon-possible-buffer-overflow.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52867
    bsc#1225009).
  - Update
    patches.suse/drm-vc4-Fix-possible-null-pointer-dereference.patch
    (git-fixes CVE-2024-38546 bsc#1226593).
  - Update
    patches.suse/drm-vmwgfx-Fix-invalid-reads-in-fence-signaled-event.patch
    (git-fixes CVE-2024-36960 bsc#1225872).
  - Update
    patches.suse/drm-zynqmp_dpsub-Always-register-bridge.patch
    (git-fixes CVE-2024-38664 bsc#1226941).
  - Update
    patches.suse/e1000e-change-usleep_range-to-udelay-in-PHY-mdic-acc.patch
    (CVE-2024-39296 bsc#1226989 CVE-2024-36887 bsc#1225731).
  - Update
    patches.suse/ecryptfs-Fix-buffer-size-for-tag-66-packet.patch
    (git-fixes CVE-2024-38578 bsc#1226634).
  - Update
    patches.suse/efi-libstub-only-free-priv.runtime_map-when-allocate.patch
    (git-fixes CVE-2024-33619 bsc#1226768).
  - Update
    patches.suse/fbdev-imsttfb-fix-a-resource-leak-in-probe.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52838
    bsc#1225031).
  - Update
    patches.suse/fs-9p-only-translate-RWX-permissions-for-plain-9P200.patch
    (git-fixes CVE-2024-36964 bsc#1225866).
  - Update
    patches.suse/fs-jfs-Add-check-for-negative-db_l2nbperpage.patch
    (git-fixes CVE-2023-52810 bsc#1225557).
  - Update
    patches.suse/fs-jfs-Add-validity-check-for-db_maxag-and-db_agpref.patch
    (git-fixes CVE-2023-52804 bsc#1225550).
  - Update
    patches.suse/ftrace-Fix-possible-use-after-free-issue-in-ftrace_location.patch
    (git-fixes CVE-2024-38588 bsc#1226837).
  - Update
    patches.suse/genirq-irqdesc-Prevent-use-after-free-in-irq_find_at.patch
    (git-fixes CVE-2024-38385 bsc#1227085).
  - Update patches.suse/gfs2-ignore-negated-quota-changes.patch
    (git-fixes CVE-2023-52759 bsc#1225560).
  - Update
    patches.suse/hid-cp2112-Fix-duplicate-workqueue-initialization.patch
    (git-fixes CVE-2023-52853 bsc#1224988).
  - Update
    patches.suse/hwmon-axi-fan-control-Fix-possible-NULL-pointer-dere.patch
    (git-fixes CVE-2023-52863 bsc#1225586).
  - Update
    patches.suse/i2c-acpi-Unbind-mux-adapters-before-delete.patch
    (git-fixes CVE-2024-39362 bsc#1226995).
  - Update
    patches.suse/i2c-core-Run-atomic-i2c-xfer-when-preemptible.patch
    (git-fixes CVE-2023-52791 bsc#1225108).
  - Update
    patches.suse/i3c-master-mipi-i3c-hci-Fix-a-kernel-panic-for-acces.patch
    (git-fixes CVE-2023-52763 bsc#1225570).
  - Update
    patches.suse/i3c-mipi-i3c-hci-Fix-out-of-bounds-access-in-hci_dma.patch
    (git-fixes CVE-2023-52766).
  - Update
    patches.suse/i915-perf-Fix-NULL-deref-bugs-with-drm_dbg-calls.patch
    (jsc#PED-3527 jsc#PED-5475 jsc#PED-6068 jsc#PED-6070
    jsc#PED-6116 jsc#PED-6120 jsc#PED-5065 jsc#PED-5477 jsc#PED-5511
    jsc#PED-6041 jsc#PED-6069 jsc#PED-6071 CVE-2023-52788
    bsc#1225106).
  - Update
    patches.suse/igb-Fix-string-truncation-warnings-in-igb_set_fw_ver.patch
    (git-fixes CVE-2024-36010 bsc#1225594).
  - Update
    patches.suse/iommu-vt-d-Fix-WARN_ON-in-iommu-probe-path.patch
    (git-fixes CVE-2024-35957 bsc#1224673).
  - Update
    patches.suse/iommufd-Fix-missing-update-of-domains_itree-after-splitting-iopt
    (jsc#PED-7779 jsc#PED-7780 CVE-2023-52801 bsc#1225006).
  - Update
    patches.suse/ipvlan-add-ipvlan_route_v6_outbound-helper.patch
    (git-fixes CVE-2023-52796 bsc#1224930).
  - Update
    patches.suse/jffs2-prevent-xattr-node-from-overflowing-the-eraseblock.patch
    (git-fixes CVE-2024-38599 bsc#1226848).
  - Update
    patches.suse/jfs-fix-array-index-out-of-bounds-in-dbFindLeaf.patch
    (git-fixes CVE-2023-52799 bsc#1225472).
  - Update
    patches.suse/jfs-fix-array-index-out-of-bounds-in-diAlloc.patch
    (git-fixes CVE-2023-52805 bsc#1225553).
  - Update
    patches.suse/kunit-fortify-Fix-mismatched-kvalloc-vfree-usage.patch
    (git-fixes CVE-2024-38617 bsc#1226859).
  - Update
    patches.suse/lib-generic-radix-tree.c-Don-t-overflow-in-peek.patch
    (git-fixes CVE-2021-47432 bsc#1225391).
  - Update
    patches.suse/lib-test_hmm.c-handle-src_pfns-and-dst_pfns-allocati.patch
    (git-fixes CVE-2024-38543 bsc#1226594).
  - Update
    patches.suse/locking-ww_mutex-test-Fix-potential-workqueue-corrup.patch
    (bsc#1219953 CVE-2023-52836 bsc#1225609).
  - Update
    patches.suse/md-Don-t-ignore-suspended-array-in-md_check_recovery-1baa.patch
    (bsc#1219596 CVE-2024-26758).
  - Update
    patches.suse/media-atomisp-ssh_css-Fix-a-null-pointer-dereference.patch
    (git-fixes CVE-2024-38547 bsc#1226632).
  - Update
    patches.suse/media-bttv-fix-use-after-free-error-due-to-btv-timeo.patch
    (git-fixes CVE-2023-52847 bsc#1225588).
  - Update
    patches.suse/media-gspca-cpia1-shift-out-of-bounds-in-set_flicker.patch
    (git-fixes CVE-2023-52764 bsc#1225571).
  - Update
    patches.suse/media-hantro-Check-whether-reset-op-is-defined-befor.patch
    (git-fixes CVE-2023-52850 bsc#1225014).
  - Update
    patches.suse/media-i2c-et8ek8-Don-t-strip-remove-function-when-dr.patch
    (git-fixes CVE-2024-38611 bsc#1226760).
  - Update
    patches.suse/media-imon-fix-access-to-invalid-resource-for-the-se.patch
    (git-fixes CVE-2023-52754 bsc#1225490).
  - Update
    patches.suse/media-lgdt3306a-Add-a-check-against-null-pointer-def.patch
    (stable-fixes CVE-2022-48772 bsc#1226976).
  - Update
    patches.suse/media-stk1160-fix-bounds-checking-in-stk1160_copy_vi.patch
    (git-fixes CVE-2024-38621 bsc#1226895).
  - Update
    patches.suse/media-vidtv-mux-Add-check-and-kfree-for-kstrdup.patch
    (git-fixes CVE-2023-52841 bsc#1225592).
  - Update patches.suse/media-vidtv-psi-Add-check-for-kstrdup.patch
    (git-fixes CVE-2023-52844 bsc#1225590).
  - Update
    patches.suse/mfd-qcom-spmi-pmic-Fix-revid-implementation.patch
    (git-fixes CVE-2023-52765 bsc#1225029).
  - Update
    patches.suse/misc-microchip-pci1xxxx-fix-double-free-in-the-error.patch
    (git-fixes CVE-2024-36973 bsc#1226457).
  - Update
    patches.suse/net-hns3-fix-out-of-bounds-access-may-occur-when-coa.patch
    (git-fixes CVE-2023-52807 bsc#1225097).
  - Update
    patches.suse/net-ks8851-Queue-RX-packets-in-IRQ-handler-instead-o.patch
    (git-fixes CVE-2024-36962 bsc#1225827).
  - Update
    patches.suse/net-mlx5-Fix-peer-devlink-set-for-SF-representor-dev.patch
    (git-fixes CVE-2024-38595 bsc#1226741).
  - Update
    patches.suse/net-mlx5e-Track-xmit-submission-to-PTP-WQ-after-popu.patch
    (jsc#PED-3311 CVE-2023-52782 bsc#1225103).
  - Update
    patches.suse/net-mvneta-fix-calls-to-page_pool_get_stats.patch
    (git-fixes CVE-2023-52780 bsc#1224933).
  - Update
    patches.suse/net-wangxun-fix-kernel-panic-due-to-null-pointer.patch
    (git-fixes CVE-2023-52783 bsc#1225104).
  - Update
    patches.suse/netfilter-complete-validation-of-user-input.patch
    (git-fixes CVE-2024-35896 bsc#1224662 CVE-2024-35962
    bsc#1224583).
  - Update
    patches.suse/nfc-nci-Fix-uninit-value-in-nci_rx_work.patch
    (git-fixes CVE-2024-38381 bsc#1226878).
  - Update
    patches.suse/nilfs2-fix-nilfs_empty_dir-misjudgment-and-long-loop.patch
    (git-fixes CVE-2024-39469 bsc#1226992).
  - Update
    patches.suse/nilfs2-fix-potential-hang-in-nilfs_detach_log_writer.patch
    (git-fixes CVE-2024-38582 bsc#1226658).
  - Update
    patches.suse/nilfs2-fix-use-after-free-of-timer-for-log-writer-th.patch
    (git-fixes CVE-2024-38583 bsc#1226777).
  - Update
    patches.suse/of-module-add-buffer-overflow-check-in-of_modalias.patch
    (git-fixes CVE-2024-38541 bsc#1226587).
  - Update
    patches.suse/padata-Fix-refcnt-handling-in-padata_free_shell.patch
    (git-fixes CVE-2023-52854 bsc#1225584).
  - Update
    patches.suse/perf-core-Bail-out-early-if-the-request-AUX-area-is-out-of-bound.patch
    (git-fixes CVE-2023-52835 bsc#1225602).
  - Update
    patches.suse/platform-x86-wmi-Fix-opening-of-char-device.patch
    (git-fixes CVE-2023-52864 bsc#1225132).
  - Update
    patches.suse/powerpc-pseries-iommu-LPAR-panics-during-boot-up-wit.patch
    (bsc#1222011 ltc#205900 CVE-2024-36926 bsc#1225829).
  - Update patches.suse/pstore-platform-Add-check-for-kstrdup.patch
    (git-fixes CVE-2023-52869 bsc#1225050).
  - Update
    patches.suse/remoteproc-mediatek-Make-sure-IPI-buffer-fits-in-L2T.patch
    (git-fixes CVE-2024-36965 bsc#1226149).
  - Update
    patches.suse/ring-buffer-Fix-a-race-between-readers-and-resize-checks.patch
    (git-fixes CVE-2024-38601 bsc#1226876).
  - Update
    patches.suse/s390-dasd-protect-device-queue-against-concurrent-access.patch
    (git-fixes bsc#1217481 CVE-2023-52774 bsc#1225572).
  - Update
    patches.suse/scsi-hisi_sas-Set-debugfs_dir-pointer-to-NULL-after-removing-debugfs.patch
    (git-fixes CVE-2023-52808 bsc#1225555).
  - Update
    patches.suse/scsi-ibmvfc-Remove-BUG_ON-in-the-case-of-an-empty-ev.patch
    (bsc#1209834 ltc#202097 CVE-2023-52811 bsc#1225559).
  - Update
    patches.suse/scsi-libfc-Fix-potential-NULL-pointer-dereference-in-fc_lport_ptp_setup.patch
    (git-fixes CVE-2023-52809 bsc#1225556).
  - Update
    patches.suse/scsi-lpfc-Move-NPIV-s-transport-unregistration-to-af.patch
    (bsc#1221777 CVE-2024-36952 bsc#1225898).
  - Update
    patches.suse/scsi-lpfc-Release-hbalock-before-calling-lpfc_worker.patch
    (bsc#1221777 CVE-2024-36924 bsc#1225820).
  - Update
    patches.suse/serial-max3100-Lock-port-lock-when-calling-uart_hand.patch
    (git-fixes CVE-2024-38634 bsc#1226868).
  - Update
    patches.suse/serial-max3100-Update-uart_driver_registered-on-driv.patch
    (git-fixes CVE-2024-38633 bsc#1226867).
  - Update
    patches.suse/soc-qcom-llcc-Handle-a-second-device-without-data-co.patch
    (git-fixes CVE-2023-52871 bsc#1225534).
  - Update
    patches.suse/soundwire-cadence-fix-invalid-PDI-offset.patch
    (stable-fixes CVE-2024-38635 bsc#1226863).
  - Update patches.suse/speakup-Fix-sizeof-vs-ARRAY_SIZE-bug.patch
    (git-fixes CVE-2024-38587 bsc#1226780).
  - Update patches.suse/spi-Fix-null-dereference-on-suspend.patch
    (git-fixes CVE-2023-52749 bsc#1225476).
  - Update
    patches.suse/thermal-core-prevent-potential-string-overflow.patch
    (git-fixes CVE-2023-52868 bsc#1225044).
  - Update
    patches.suse/thermal-drivers-qcom-lmh-Check-for-SCM-availability-.patch
    (git-fixes CVE-2024-39466 bsc#1227089).
  - Update
    patches.suse/thermal-drivers-tsens-Fix-null-pointer-dereference.patch
    (git-fixes CVE-2024-38571 bsc#1226737).
  - Update
    patches.suse/thermal-intel-powerclamp-fix-mismatch-in-get-functio.patch
    (git-fixes CVE-2023-52794 bsc#1225028).
  - Update
    patches.suse/tls-fix-NULL-deref-on-tls_sw_splice_eof-with-empty-r.patch
    (jsc#PED-6831 CVE-2023-52767 bsc#1224998).
  - Update
    patches.suse/tpm_tis_spi-Account-for-SPI-header-when-allocating-T.patch
    (git-fixes CVE-2024-36477 bsc#1226840).
  - Update
    patches.suse/tracing-Have-trace_event_file-have-ref-counters.patch
    (git-fixes CVE-2023-52879 bsc#1225101).
  - Update
    patches.suse/tracing-trigger-Fix-to-return-error-if-failed-to-alloc-snapshot.patch
    (git-fixes CVE-2024-26920).
  - Update
    patches.suse/tty-n_gsm-fix-race-condition-in-status-line-change-o.patch
    (git-fixes CVE-2023-52872 bsc#1225591).
  - Update
    patches.suse/tty-n_gsm-require-CAP_NET_ADMIN-to-attach-N_GSM0710-.patch
    (bsc#1222619 CVE-2023-52880).
  - Update
    patches.suse/tty-vcc-Add-check-for-kstrdup-in-vcc_probe.patch
    (git-fixes CVE-2023-52789 bsc#1225180).
  - Update
    patches.suse/usb-config-fix-iteration-issue-in-usb_get_bos_descri.patch
    (git-fixes CVE-2023-52781 bsc#1225092).
  - Update
    patches.suse/usb-dwc3-Wait-unconditionally-after-issuing-EndXfer-.patch
    (git-fixes CVE-2024-36977 bsc#1226513).
  - Update
    patches.suse/usb-gadget-u_audio-Fix-race-condition-use-of-control.patch
    (git-fixes CVE-2024-38628 bsc#1226911).
  - Update
    patches.suse/usb-storage-alauda-Check-whether-the-media-is-initia.patch
    (git-fixes CVE-2024-38619 bsc#1226861).
  - Update
    patches.suse/usb-typec-tcpm-Fix-NULL-pointer-dereference-in-tcpm_.patch
    (git-fixes CVE-2023-52877 bsc#1224944).
  - Update
    patches.suse/vhost-vdpa-fix-use-after-free-in-vhost_vdpa_probe.patch
    (jsc#PED-3311 CVE-2023-52795 bsc#1225085).
  - Update
    patches.suse/virtio-blk-fix-implicit-overflow-on-virtio_max_dma_s.patch
    (git-fixes CVE-2023-52762 bsc#1225573).
  - Update
    patches.suse/virtio-vsock-Fix-uninit-value-in-virtio_transport_re.patch
    (jsc#PED-5505 CVE-2023-52842 bsc#1225025).
  - Update
    patches.suse/watchdog-cpu5wdt.c-Fix-use-after-free-bug-caused-by-.patch
    (git-fixes CVE-2024-38630 bsc#1226908).
  - Update
    patches.suse/wifi-ar5523-enable-proper-endpoint-verification.patch
    (git-fixes CVE-2024-38565 bsc#1226747).
  - Update
    patches.suse/wifi-ath11k-fix-dfs-radar-event-locking.patch
    (git-fixes CVE-2023-52798 bsc#1224947).
  - Update
    patches.suse/wifi-ath11k-fix-gtk-offload-status-event-locking.patch
    (git-fixes CVE-2023-52777 bsc#1224992).
  - Update patches.suse/wifi-ath11k-fix-htt-pktlog-locking.patch
    (git-fixes CVE-2023-52800).
  - Update
    patches.suse/wifi-ath12k-fix-dfs-radar-and-temperature-event-lock.patch
    (git-fixes CVE-2023-52776 bsc#1225090).
  - Update
    patches.suse/wifi-ath12k-fix-htt-mlo-offset-event-locking.patch
    (git-fixes CVE-2023-52769 bsc#1225001).
  - Update
    patches.suse/wifi-ath12k-fix-out-of-bound-access-of-qmi_invoke_ha.patch
    (git-fixes CVE-2024-38572 bsc#1226776).
  - Update
    patches.suse/wifi-ath12k-fix-possible-out-of-bound-read-in-ath12k.patch
    (git-fixes CVE-2023-52827 bsc#1225078).
  - Update
    patches.suse/wifi-ath12k-fix-possible-out-of-bound-write-in-ath12.patch
    (git-fixes CVE-2023-52829 bsc#1225081).
  - Update
    patches.suse/wifi-brcmfmac-pcie-handle-randbuf-allocation-failure.patch
    (git-fixes CVE-2024-38575 bsc#1226612).
  - Update
    patches.suse/wifi-carl9170-add-a-proper-sanity-check-for-endpoint.patch
    (git-fixes CVE-2024-38567 bsc#1226769).
  - Update
    patches.suse/wifi-carl9170-re-fix-fortified-memset-warning.patch
    (git-fixes CVE-2024-38616 bsc#1226852).
  - Update
    patches.suse/wifi-mac80211-don-t-return-unset-power-in-ieee80211_.patch
    (git-fixes CVE-2023-52832 bsc#1225577).
  - Update
    patches.suse/wifi-nl80211-Avoid-address-calculations-via-out-of-b.patch
    (git-fixes CVE-2024-38562 bsc#1226788).
  - Update
    patches.suse/wifi-wilc1000-use-vmm_table-as-array-in-wilc-struct.patch
    (git-fixes CVE-2023-52768 bsc#1225004).
  - Update
    patches.suse/x86-tdx-Zero-out-the-missing-RSI-in-TDX_HYPERCALL-macro.patch
    (jsc#PED-5824 CVE-2023-52874 bsc#1225049).
  - commit 33efdc4
  - tcp: do not accept ACK of bytes we never sent (CVE-2023-52881
    bsc#1225611).
  - commit 16404a6
  - net: ena: Fix redundant device NUMA node override
    (jsc#PED-8688).
  - commit 6ad6684
  - ata: ahci: Clean up sysfs file on error (git-fixes).
  - ata: libata-core: Fix double free on error (git-fixes).
  - ata,scsi: libata-core: Do not leak memory for ata_port struct
    members (git-fixes).
  - ata: libata-core: Fix null pointer dereference on error
    (git-fixes).
  - kbuild: Fix build target deb-pkg: ln: failed to create hard link
    (git-fixes).
  - kbuild: doc: Update default INSTALL_MOD_DIR from extra to
    updates (git-fixes).
  - kbuild: Install dtb files as 0644 in Makefile.dtbinst
    (git-fixes).
  - counter: ti-eqep: enable clock at probe (git-fixes).
  - iio: chemical: bme680: Fix sensor data read operation
    (git-fixes).
  - iio: chemical: bme680: Fix overflows in compensate() functions
    (git-fixes).
  - iio: chemical: bme680: Fix calibration data variable
    (git-fixes).
  - iio: chemical: bme680: Fix pressure value output (git-fixes).
  - iio: accel: fxls8962af: select IIO_BUFFER & IIO_KFIFO_BUF
    (git-fixes).
  - iio: adc: ad7266: Fix variable checking bug (git-fixes).
  - iio: xilinx-ams: Don't include ams_ctrl_channels in scan_mask
    (git-fixes).
  - serial: bcm63xx-uart: fix tx after conversion to
    uart_port_tx_limited() (git-fixes).
  - serial: core: introduce uart_port_tx_limited_flags()
    (git-fixes).
  - Revert "serial: core: only stop transmit when HW fifo is empty"
    (git-fixes).
  - tty: mcf: MCF54418 has 10 UARTS (git-fixes).
  - usb: gadget: aspeed_udc: fix device address configuration
    (git-fixes).
  - usb: dwc3: core: remove lock of otg mode during gadget
    suspend/resume to avoid deadlock (git-fixes).
  - usb: typec: ucsi: glink: fix child node release in probe
    function (git-fixes).
  - usb: musb: da8xx: fix a resource leak in probe() (git-fixes).
  - usb: atm: cxacru: fix endpoint checking in cxacru_bind()
    (git-fixes).
  - usb: gadget: printer: fix races against disable (git-fixes).
  - PCI/MSI: Fix UAF in msi_capability_init (git-fixes).
  - commit a2ea5a9

++++ krb5:

  - Update to 1.21.3
    * Fix vulnerabilities in GSS message token handling:
    * CVE-2024-37370, bsc#1227186
    * CVE-2024-37371, bsc#1227187
    * Fix a potential bad pointer free in krb5_cccol_have_contents()
    * Fix a memory leak in the macOS ccache type
  - Update patch 0009-Fix-three-memory-leaks.patch

++++ ncurses:

  - Add ncurses patch 20240629
    + build-fix for ncurses-examples with newer PDCurses, which no longer
    has stubs for unimplemented features.
    + add help-popup for test_instr.c, test_inwstr.c
    + modify checks in delwin to avoid checking if the window is a pad
    until first checking if it is still on the active window-list
    (cf: 20211115).
    + improve -t option of test/gdc.c, allowing hours only, or hours and
    minutes only.
  - Update to tack 1.10 (patch 20240501)
    * init.c, edit.c: gcc warning (NetBSD)
    * edit.c:
    check to avoid printing a non-printable character, per Coverity
    * tack.c: initialize variables, per Coverity
    * tack.1: change limit for SGR tool to allow for aixterm's colors
    * ansi.c: change the SGR tool to show up to 120 (past aixterm's 108)
    * color.c:
    when reloading the colors 0-7, use the index for the named color rather than
    just the array-index (fixing an interchanged red/blue for instance).
    Also, initialize the palette using the ANSI codes if the terminal supports
    setaf/setab.
    * color.c, charset.c, ansi.c, edit.c, crum.c, pad.c, tack.c, tack.h:
    use "const" in a few places reported by cppcheck
    * tack.1: improve formatting/style

++++ openssl-3:

  - FIPS: RSA keygen PCT requirements.
    * Skip the rsa_keygen_pairwise_test() PCT in rsa_keygen() as the
    self-test requirements are covered by do_rsa_pct() for both
    RSA-OAEP and RSA signatures [bsc#1221760]
    * Enforce error state if rsa_keygen PCT is run and fails [bsc#1221753]
    * Add openssl-3-FIPS-PCT_rsa_keygen.patch

++++ libselinux:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    * User-visible changes
    * libselinux/utils/selabel_digest: drop unsupported option -d
    * libselinux/utils: improve compute_av output
    * libselinux: fail selabel_open(3) on invalid option
    * Improved man pages
    * Improvements
    * libselinux, libsepol: Add CFLAGS and LDFLAGS to Makefile checks
    * libselinux: enable usage with pedantic UB sanitizers
    * libselinux: support huge passwd/group entries
    * Bugfixes:
    * libselinux/utils/selabel_digest: avoid buffer overflow
    * libselinux: avoid pointer dereference before check
    * libselinux/utils/selabel_digest: pass BASEONLY only for file backend
    * libselinux: free empty scandir(3) result
    * libselinux: free data on selabel open failure
    * libselinux: use reentrant strtok_r(3)

++++ libsemanage:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    * Bugfixes:
    * libsemanage: support huge passwd entries

++++ libsepol:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    * User-visible changes:
    * libsepol: improve policy lookup failure message
    * libsepol: include prefix for module policy versions
    * libsepol: validate type-attribute-map for old policies
    * libsepol: only exempt gaps checking for kernel policies
    * Bugfixes:
    * libsepol/src/Makefile: fix reallocarray detection
    * libsepol/cil: Fix detected RESOURCE_LEAK (CWE-772)
    * libsepol: ensure transitivity in compare functions
    * oss-fuzz fixes:
    * libsepol: check scope permissions refer to valid class
    * libsepol: validate attribute-type maps
    * libsepol: reject self flag in type rules in old policies
    * libsepol: validate class permissions
    * libsepol: validate access vector permissions
    * libsepol: reject MLS support in pre-MLS policies
    * libsepol: Fix buffer overflow when using sepol_av_to_string()
    * libsepol: Use a dynamic buffer in sepol_av_to_string()

++++ systemd:

  - Import commit 5a8eadd0c021758337a020c423f25a353bdb9b3c (merge of v255.8)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/603cd1d4d81147d4f2eccd5e352064a4215119b4...5a8eadd0c021758337a020c423f25a353bdb9b3c
  - Drop 5003-Revert-run-pass-the-pty-slave-fd-to-transient-servic.patch as v255.8
    contains the workaround (commit 639c922ede9485) for the broken commit
    28459ba1f4df.

++++ libvirt:

  - Update to libvirt 10.5.0
  - Introduce SEV-SNP support
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v10-5-0-2024-07-01

++++ open-vm-tools:

  - Update to 12.4.5 (build 23787635) (boo#1227181)
  - There are no new features in the open-vm-tools 12.4.5 release. This is
    primarily a maintenance release that addresses a few critical problems,
    including:
  - A Github pull request and associated issue has been handled. Please
    see the Resolved Issues section of the Release Notes.
  - A number of issues flagged by Coverity and ShellCheck have been
    addressed.
  - A vmtoolsd process hang related to nested logging from an RPC Channel
    error has been fixed.
    For a more complete list of issues resolved in this release, see the
    Resolved Issues section of the Release Notes.
    For complete details, see: https://github.com/vmware/open-vm-tools/releases/tag/stable-12.4.5
    Release Notes are available at: https://github.com/vmware/open-vm-tools/blob/stable-12.4.5/ReleaseNotes.md
    The granular changes that have gone into the 12.4.5 release are in the ChangeLog at: https://github.com/vmware/open-vm-tools/blob/stable-12.4.5/open-vm-tools/ChangeLog

++++ openssh:

  - Add patch to fix a race condition in a signal handler by removing
    the async-signal-unsafe code (CVE-2024-6387, bsc#1226642):
    * fix-CVE-2024-6387.patch

++++ osinfo-db:

  - Adjust some default hardware requirements (bsc#1227231)
    adjust-tumbleweed-hardware-requirements.patch
    add-opensuse-leap-15.6-support.patch
    add-sle15sp6-support.patch

++++ policycoreutils:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    User-visible changes:
    * audit2allow -C for CIL output mode
    * sepolgen: adjust parse for refpolicy
    * Bugfixes:
    * fixfiles: drop unnecessary \ line endings
    * setfiles: avoid unsigned integer underflow
    * python/semanage: Do not sort local fcontext definitions
    * python/semanage: Allow modifying records on "add"
  - Refresh get_os_version.patch

++++ python-PyYAML:

  - add build-with-cython3.patch from 6.0.2rc1 to build with
    cython3 (needed for python 3.13+)

++++ python-libvirt-python:

  - Update to 10.5.0
  - Add all new APIs and constants in libvirt 10.5.0

++++ libselinux-bindings:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    * User-visible changes
    * libselinux/utils/selabel_digest: drop unsupported option -d
    * libselinux/utils: improve compute_av output
    * libselinux: fail selabel_open(3) on invalid option
    * Improved man pages
    * Improvements
    * libselinux, libsepol: Add CFLAGS and LDFLAGS to Makefile checks
    * libselinux: enable usage with pedantic UB sanitizers
    * libselinux: support huge passwd/group entries
    * Bugfixes:
    * libselinux/utils/selabel_digest: avoid buffer overflow
    * libselinux: avoid pointer dereference before check
    * libselinux/utils/selabel_digest: pass BASEONLY only for file backend
    * libselinux: free empty scandir(3) result
    * libselinux: free data on selabel open failure
    * libselinux: use reentrant strtok_r(3)

++++ python-semanage:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    * Bugfixes:
    * libsemanage: support huge passwd entries

++++ restorecond:

  - Update to version 3.7
    https://github.com/SELinuxProject/selinux/releases/tag/3.7
    * no changes from 3.6, only version changed to 3.7

++++ sysuser-tools:

  - Allow setting of UID:GID for as defined in sysusers.d

------------------------------------------------------------------
------------------  2024-6-30  -  Jun 30 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - crypto: deflate - Add aliases to deflate (bsc#1227190).
  - commit 27ffd92
  - crypto: iaa - Account for cpu-less numa nodes (bsc#1227190).
  - commit cd600aa
  - i2c: testunit: discard write requests while old command is
    running (git-fixes).
  - i2c: testunit: don't erase registers after STOP (git-fixes).
  - mmc: sdhci: Do not lock spinlock around mmc_gpio_get_ro()
    (git-fixes).
  - mmc: sdhci: Do not invert write-protect twice (git-fixes).
  - mmc: sdhci-brcmstb: check R1_STATUS for erase/trim/discard
    (git-fixes).
  - mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
    (git-fixes).
  - commit 448487d

++++ kernel-rt:

  - crypto: deflate - Add aliases to deflate (bsc#1227190).
  - commit 27ffd92
  - crypto: iaa - Account for cpu-less numa nodes (bsc#1227190).
  - commit cd600aa
  - i2c: testunit: discard write requests while old command is
    running (git-fixes).
  - i2c: testunit: don't erase registers after STOP (git-fixes).
  - mmc: sdhci: Do not lock spinlock around mmc_gpio_get_ro()
    (git-fixes).
  - mmc: sdhci: Do not invert write-protect twice (git-fixes).
  - mmc: sdhci-brcmstb: check R1_STATUS for erase/trim/discard
    (git-fixes).
  - mmc: sdhci-pci: Convert PCIBIOS_* return codes to errnos
    (git-fixes).
  - commit 448487d

++++ llvm19:

  - Update to version 18.1.8.
    * Fix a regression from the 18.1.6 release, which could result in
    compiler crashes in the PPCMergeStringPool pass when compiling
    for PowerPC targets.
    * Fixes clang-format regressions (since 18.1.1) on breaking
    before a stream insertion operator (<<) when both operands are
    string literals.
    * Fixes a clang-format regression (since 17.0.6) on formatting
    goto labels in macro definitions.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ fribidi:

  - update to 1.0.15:
    * Fixed the bad tarball from 1.0.14 with stall include files.
    There are no other changes

++++ pciutils:

  - update to 3.13.0:
    * lspci decodes CXL 1.1 device link status information.
    * Further development of the pcilmr (the link margining
    utility)
    * Dump parsing supports 6-digit domain numbers.
    * Bug fixes in PCIe link state reporting.
    * Decode more fields in PCIe AER capability.
    * Fixed build on Linux systems with musl libc.
    * Updated pci.ids.

++++ pcre2:

  - update to 10.44:
    * This is mostly a bug-fix and tidying release. There is one
    new function, to set a maximum size for a compiled pattern.
    The maximum name length for groups is increased to 128.
    * Some auxiliary files for building under VMS are added.

++++ python313-core:

  - move pathlib to -base
  - move _pyrepl to -base (used by pydoc which is in base)
  - fix import-mapping

++++ pinentry:

  - update to 1.3.0:
    * qt: Add new Qt6 frontend.  [rP1e79123c38]
    * qt: Set parent window on Wayland.  [T6930]
    * qt: Fix capslock detection on Wayland.  [rP7dfc60a70d]
    * qt: Fix window icon on Wayland.  [T6887]
    * qt: Add support for external password manager with libsecret.
    * qt: Remove focus indication by text selection.  [T5863]
    * qt: Use same focus indication for labels as Kleopatra.
    * qt: Improve accessibility.  [T5863]
    * gnome3: Prefer gcr-4.  [rP069c219223]
    * curses: Fix timeout handling.  [rP08408498b3]
    * curses: Add SETREPEATOK and quality bar colors.
    * curses: Add password quality meter.  [rP2923707e75]
    * curses,tty: Upon SIGINT, let pinentry exit gracefully.
    * w32: Fix non-focused window and simplify code.
    * Disable secret storage integration when running on KDE
    Plasma.
    * The Windows CE support has been removed.

++++ pv:

  - update to 1.8.10:
    * feature: new "`--output`" option to write to a file instead
    of standard output (pull request #90) supplied by xmort

++++ python313:

  - move pathlib to -base
  - move _pyrepl to -base (used by pydoc which is in base)
  - fix import-mapping

++++ python-cffi:

  - add py313-compat.patch
    py313-use-format-unraisable.patch
    py313-use-hashpointer.patch: add upstream patches for py3.13
    support

------------------------------------------------------------------
------------------  2024-6-29  -  Jun 29 2024  -------------------
------------------------------------------------------------------

++++ bolt:

  - Edit license: LGPL-2.1-or-later
  - Add BuildRequires: asciidoc to produce manpages:
    * boltd.8 boltctl.1
  - Switch dependencies to provided pkgconfig
  - Update meson required version 0.60
  - Use autosetup

++++ boost-base:

  - add patch boost-1.85.0-python-numpy-2.patch from upstream

++++ kernel-default:

  - gpiolib: cdev: Disallow reconfiguration without direction
    (uAPI v1) (git-fixes).
  - gpio: davinci: Validate the obtained number of IRQs (git-fixes).
  - commit 919ebd1

++++ kernel-rt:

  - gpiolib: cdev: Disallow reconfiguration without direction
    (uAPI v1) (git-fixes).
  - gpio: davinci: Validate the obtained number of IRQs (git-fixes).
  - commit 919ebd1

++++ python-setuptools:

  - update to 70.1.1:
    * Improve error message when pkg_resources.ZipProvider tries to
    extract resources with a missing Egg
    Added variables and parameter type annotations to
    pkg_resources to be nearly on par with typeshed.*
    * Improve error message when pkg_resources.ZipProvider tries to
    extract resources with a missing Egg
    * Added variables and parameter type annotations to
    pkg_resources to be nearly on par with typeshed.*
    * Migrated Setuptools' own config to pyproject.toml
    * Prevent a TypeError: 'NoneType' object is not callable when
    shutil_rmtree is called without an onexc parameter on
    Python<=3.11
    * Replace use of mktemp with can_symlink from the stdlib test
    suite.
    * Improvement for attr: directives in configuration to handle
    more edge cases related to complex package_dir.
    * Fix accidental implicit string concatenation.

++++ virt-manager:

  - bsc#1227116 - osinfo still uses deprecated SL-Micro name
    virtinst-add-slem60-detection-support.patch
    Dropped virtinst-add-slm-detection-support.patch

------------------------------------------------------------------
------------------  2024-6-28  -  Jun 28 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - boo1226725-test-fix1.patch
    * another try to fix coloring on s390x and other platforms
  - re-enabled patches only applied on s390x with previous change
    on all platforms again

++++ Mesa-drivers:

  - boo1226725-test-fix1.patch
    * another try to fix coloring on s390x and other platforms
  - re-enabled patches only applied on s390x with previous change
    on all platforms again

++++ kernel-default:

  - wifi: iwlwifi: mvm: fix the TXF mapping for BZ devices
    (bsc#1227149).
  - wifi: iwlwifi: clear link_id in time_event (bsc#1227149).
  - wifi: iwlwifi: mvm: fix a battery life regression (bsc#1227149).
  - wifi: iwlwifi: remove extra kernel-doc (bsc#1227149).
  - wifi: iwlwifi: mvm: skip adding debugfs symlink for reconfig
    (bsc#1227149).
  - wifi: iwlwifi: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: iwlwifi: mvm: use the new command to clear the internal
    buffer (bsc#1227149).
  - commit acd03db
  - wifi: iwlwifi: mvm: add US/Canada MCC to API (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-warnings-from-dmi_get_system_in.patch.
  - commit 70a9591
  - wifi: iwlwifi: mvm: disallow puncturing in US/Canada
    (bsc#1227149).
  - wifi: iwlwifi: Add rf_mapping of new wifi7 devices
    (bsc#1227149).
  - wifi: iwlwifi: cleanup BT Shared Single Antenna code
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Do not warn if valid link pair was not found
    (bsc#1227149).
  - wifi: iwlwifi: mvm: d3: avoid intermediate/early mutex unlock
    (bsc#1227149).
  - wifi: iwlwifi: Don't mark DFS channels as NO-IR (bsc#1227149).
  - wifi: iwlwifi: mvm: Allow DFS concurrent operation
    (bsc#1227149).
  - wifi: iwlwifi: mvm: do not send STA_DISABLE_TX_CMD for newer
    firmware (bsc#1227149).
  - wifi: iwlwifi: remove async command callback (bsc#1227149).
  - commit 0205124
  - wifi: iwlwifi: fw: file: don't use [0] for variable arrays
    (bsc#1227149).
  - wifi: iwlwifi: pcie: get_crf_id() can be void (bsc#1227149).
  - wifi: iwlwifi: pcie: dump CSRs before removal (bsc#1227149).
  - wifi: iwlwifi: pcie: clean up device removal work (bsc#1227149).
  - wifi: iwlwifi: mvm: add a debugfs hook to clear the monitor data
    (bsc#1227149).
  - wifi: iwlwifi: refactor RX tracing (bsc#1227149).
  - wifi: iwlwifi: mvm: Correctly report TSF data in scan complete
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Use the link ID provided in scan request
    (bsc#1227149).
  - wifi: iwlwifi: fw: replace deprecated strncpy with strscpy_pad
    (bsc#1227149).
  - wifi: iwlwifi: fix system commands group ordering (bsc#1227149).
  - commit 6cae420
  - wifi: iwlwifi: drop NULL pointer check in
    iwl_mvm_tzone_set_trip_temp() (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 86 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: read DSM func 2 for specific RF types
    (bsc#1227149).
  - wifi: iwlwifi: mvm: show dump even for pldr_sync (bsc#1227149).
  - wifi: iwlwifi: mvm: cycle FW link on chanctx removal
    (bsc#1227149).
  - wifi: iwlwifi: trace full frames with TX status request
    (bsc#1227149).
  - wifi: iwlwifi: fw: Add support for UATS table in UHB
    (bsc#1227149).
  - wifi: iwlwifi: mvm: add a print when sending RLC command
    (bsc#1227149).
  - wifi: iwlwifi: mvm: debugfs for fw system stats (bsc#1227149).
  - wifi: iwlwifi: mvm: implement new firmware API for statistics
    (bsc#1227149).
  - commit ed6b54f
  - wifi: iwlwifi: disable multi rx queue for 9000 (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-include-link-ID-when-releasing-fram.patch.
  - commit 9866ec0
  - wifi: iwlwifi: mvm: fix regdb initialization (bsc#1227149).
  - wifi: iwlwifi: mvm: simplify the reorder buffer (bsc#1227149).
  - wifi: iwlwifi: mvm: Return success if link could not be removed
    (bsc#1227149).
  - wifi: iwlwifi: add support for SNPS DPHYIP region type
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove set_tim callback for MLD ops
    (bsc#1227149).
  - wifi: iwlwifi: api: fix center_freq label in PHY diagram
    (bsc#1227149).
  - wifi: iwlwifi: support link id in SESSION_PROTECTION_NOTIF
    (bsc#1227149).
  - wifi: iwlwifi: support link_id in SESSION_PROTECTION cmd
    (bsc#1227149).
  - wifi: iwlwifi: make time_events MLO aware (bsc#1227149).
  - commit 1ea0f35
  - wifi: iwlwifi: add support for activating UNII-1 in WW via BIOS
    (bsc#1227149).
  - wifi: iwlwifi: mvm: extend alive timeout to 2 seconds
    (bsc#1227149).
  - wifi: iwlwifi: mvm: fix the PHY context resolution for p2p
    device (bsc#1227149).
  - wifi: iwlwifi: mvm: fold the ref++ into iwl_mvm_phy_ctxt_add
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't add dummy phy context (bsc#1227149).
  - wifi: iwlwifi: mvm: cleanup MLO and non-MLO unification code
    (bsc#1227149).
  - wifi: iwlwifi: mvm: implement ROC version 3 (bsc#1227149).
  - wifi: iwlwifi: send EDT table to FW (bsc#1227149).
  - wifi: iwlmvm: fw: Add new OEM vendor to tas approved list
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Fix unreachable code path (bsc#1227149).
  - commit 50ebcaa
  - wifi: iwlwifi: mvm: advertise support for SCS traffic
    description (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-do-not-announce-EPCS-support.patch.
  - commit 7208326
  - wifi: iwlwifi: add new RF support for wifi7 (bsc#1227149).
  - wifi: iwlwifi: fw: increase fw_version string size
    (bsc#1227149).
  - wifi: iwlwifi: check for kmemdup() return value in
    iwl_parse_tlv_firmware() (bsc#1227149).
  - wifi: iwlwifi: fix the rf step and flavor bits range
    (bsc#1227149).
  - wifi: iwlwifi: fw: Fix debugfs command sending (bsc#1227149).
  - wifi: iwlwifi: mvm: add start mac ctdp sum calculation debugfs
    handler (bsc#1227149).
  - wifi: iwlwifi: abort scan when rfkill on but device enabled
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Add basic link selection logic
    (bsc#1227149).
  - wifi: iwlwifi: mei: return error from register when not built
    (bsc#1227149).
  - commit fddf9eb
  - wifi: iwlwifi: mvm: fix SB CFG check (bsc#1227149).
  - wifi: iwlwifi: mvm: add a per-link debugfs (bsc#1227149).
  - wifi: iwlwifi: mvm: rework debugfs handling (bsc#1227149).
  - wifi: iwlwifi: add support for new ini region types
    (bsc#1227149).
  - wifi: iwlwifi: Extract common prph mac/phy regions data dump
    logic (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 84 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: mvm: offload IGTK in AP if BIGTK is supported
    (bsc#1227149).
  - wifi: iwlwifi: pcie: clean up WFPM control bits (bsc#1227149).
  - wifi: iwlwifi: fix opmode start/stop race (bsc#1227149).
  - wifi: iwlwifi: skip opmode start retries on dead transport
    (bsc#1227149).
  - commit 36551d1
  - wifi: iwlwifi: mvm: add support for new wowlan_info_notif
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-d3-fix-IPN-byte-order.patch.
  - commit 0b379ae
  - wifi: iwlwifi: pcie: propagate iwl_pcie_gen2_apm_init() error
    (bsc#1227149).
  - wifi: iwlwifi: add mapping of a periphery register crf for WH RF
    (bsc#1227149).
  - wifi: iwlwifi: mvm: check for iwl_mvm_mld_update_sta() errors
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support injection antenna control
    (bsc#1227149).
  - wifi: iwlwifi: mvm: refactor TX rate handling (bsc#1227149).
  - wifi: iwlwifi: mvm: make pldr_sync AX210 specific (bsc#1227149).
  - wifi: iwlwifi: fail NIC access fast on dead NIC (bsc#1227149).
  - wifi: iwlwifi: pcie: (re-)assign BAR0 on driver bind
    (bsc#1227149).
  - commit 0882d6d
  - wifi: iwlwifi: implement enable/disable for China 2022
    regulatory (bsc#1227149).
  - wifi: iwlwifi: mvm: handle link-STA allocation in restart
    (bsc#1227149).
  - wifi: iwlwifi: mvm: iterate active links for STA queues
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support set_antenna() (bsc#1227149).
  - wifi: iwlwifi: mvm: add a debug print when we get a BAR
    (bsc#1227149).
  - wifi: iwlwifi: mvm: move listen interval to constants
    (bsc#1227149).
  - wifi: iwlwifi: no power save during transition to D3
    (bsc#1227149).
  - wifi: iwlwifi: update context info structure definitions
    (bsc#1227149).
  - wifi: iwlwifi: mvm: fix recovery flow in CSA (bsc#1227149).
  - wifi: iwlwifi: mvm: enable FILS DF Tx on non-PSC channel
    (bsc#1227149).
  - commit 5c7efaf
  - wifi: iwlwifi: mvm: make "pldr_sync" mode effective
    (bsc#1227149).
  - wifi: iwlwifi: mvm: log dropped frames (bsc#1227149).
  - wifi: iwlwifi: fw: disable firmware debug asserts (bsc#1227149).
  - wifi: iwlwifi: remove dead-code (bsc#1227149).
  - wifi: iwlwifi: pcie: enable TOP fatal error interrupt
    (bsc#1227149).
  - wifi: iwlwifi: pcie: give up mem read if HW is dead
    (bsc#1227149).
  - wifi: iwlwifi: pcie: rescan bus if no parent (bsc#1227149).
  - wifi: iwlwifi: mvm: reduce maximum RX A-MPDU size (bsc#1227149).
  - wifi: iwlwifi: mvm: check link more carefully (bsc#1227149).
  - wifi: iwlwifi: mvm: move RU alloc B2 placement (bsc#1227149).
  - commit 8aa4ff8
  - virtio: delete vq in vp_find_vqs_msix() when request_irq()
    fails (CVE-2024-37353 bsc#1226875).
  - commit 4591439
  - wifi: iwlwifi: mvm: fix kernel-doc (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-ensure-offloading-TID-queue-exists.patch.
  - commit 68376c9
  - wifi: iwlwifi: pcie: fix kernel-doc issues (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-pcie-fix-RB-status-reading.patch.
  - commit f106797
  - wifi: iwlwifi: fw: reconstruct the API/CAPA enum number
    (bsc#1227149).
  - wifi: iwlwifi: dvm: remove kernel-doc warnings (bsc#1227149).
  - wifi: iwlwifi: queue: fix kernel-doc (bsc#1227149).
  - wifi: iwlwifi: fix some kernel-doc issues (bsc#1227149).
  - wifi: iwlwifi: mvm: disconnect long CSA only w/o alternative
    (bsc#1227149).
  - wifi: iwlwifi: mvm: increase session protection after CSA
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support CSA with MLD (bsc#1227149).
  - wifi: iwlmei: don't send nic info with invalid mac address
    (bsc#1227149).
  - commit 85cbe83
  - wifi: iwlwifi: mvm: support flush on AP interfaces
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-change-iwl_mvm_flush_sta-API.patch.
  - commit 908ff7c
  - wifi: iwlmei: send driver down SAP message only if wiamt is
    enabled (bsc#1227149).
  - wifi: iwlmei: send HOST_GOES_DOWN message even if wiamt is
    disabled (bsc#1227149).
  - wifi: iwlmei: don't send SAP messages if AMT is disabled
    (bsc#1227149).
  - wifi: iwlwifi: remove memory check for LMAC error address
    (bsc#1227149).
  - wifi: iwlwifi: mvm: enable HE TX/RX <242 tone RU on new RFs
    (bsc#1227149).
  - wifi: iwlwifi: add Razer to ppag approved list (bsc#1227149).
  - wifi: iwlwifi: pcie: point invalid TFDs to invalid data
    (bsc#1227149).
  - wifi: iwlwifi: queue: move iwl_txq_gen2_set_tb() up
    (bsc#1227149).
  - wifi: iwlwifi: pcie: move gen1 TB handling to header
    (bsc#1227149).
  - commit 92ab309
  - wifi: iwlwifi: remove 'def_rx_queue' struct member
    (bsc#1227149).
  - wifi: iwlwifi: pcie: clean up gen1/gen2 TFD unmap (bsc#1227149).
  - wifi: iwlwifi: remove WARN from read_mem32() (bsc#1227149).
  - wifi: iwlwifi: api: fix a small upper/lower-case typo
    (bsc#1227149).
  - wifi: iwlwifi: mvm: advertise MLO only if EHT is enabled
    (bsc#1227149).
  - commit aa9a391
  - Add alt-commit to iwlwifi patches
  - commit 865aa7a
  - wifi: mac80211: fix unsolicited broadcast probe config
    (bsc#1227149).
  - wifi: mac80211: initialize SMPS mode correctly (bsc#1227149).
  - wifi: mac80211: fix driver debugfs for vif type change
    (bsc#1227149).
  - wifi: mac80211: improve CSA/ECSA connection refusal
    (bsc#1227149).
  - wifi: cfg80211: detect stuck ECSA element in probe resp
    (bsc#1227149).
  - wifi: mac80211: add/remove driver debugfs entries as appropriate
    (bsc#1227149).
  - wifi: mac80211: do not re-add debugfs entries during resume
    (bsc#1227149).
  - commit 769161a
  - wifi: mac80211: remove redundant ML element check (bsc#1227149).
  - wifi: cfg80211: Update the default DSCP-to-UP mapping
    (bsc#1227149).
  - wifi: mac80211: fix spelling typo in comment (bsc#1227149).
  - wifi: mac80211: add a driver callback to check active_links
    (bsc#1227149).
  - wifi: mac80211: fix advertised TTLM scheduling (bsc#1227149).
  - wifi: cfg80211: avoid double free if updating BSS fails
    (bsc#1227149).
  - commit e8bab13
  - wifi: cfg80211: handle UHB AP and STA power type (bsc#1227149).
  - commit 6021aa4
  - wifi: cfg80211: ensure cfg80211_bss_update frees IEs on error
    (bsc#1227149).
  - wifi: mac80211: allow 64-bit radiotap timestamps (bsc#1227149).
  - wifi: mac80211: rework RX timestamp flags (bsc#1227149).
  - wifi: mac80211: Schedule regulatory channels check on bandwith
    change (bsc#1227149).
  - wifi: cfg80211: Schedule regulatory check on BSS STA channel
    change (bsc#1227149).
  - wifi: cfg80211: reg: Support P2P operation on DFS channels
    (bsc#1227149).
  - wifi: mac80211: Skip association timeout update after comeback
    rejection (bsc#1227149).
  - wifi: mac80211: address some kerneldoc warnings (bsc#1227149).
  - wifi: cfg80211: address several kerneldoc warnings
    (bsc#1227149).
  - commit bc44e06
  - wifi: cfg80211: generate an ML element for per-STA profiles
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-parse-all-ML-elements-in-an-ML-probe-r.patch.
  - commit d924102
  - wifi: cfg80211: introduce cfg80211_ssid_eq() (bsc#1227149).
  - wifi: mac80211: sta_info.c: fix sentence grammar (bsc#1227149).
  - wifi: mac80211: rx.c: fix sentence grammar (bsc#1227149).
  - wifi: cfg80211: fix spelling & punctutation (bsc#1227149).
  - wifi: cfg80211: sort certificates in build (bsc#1227149).
  - wifi: mac80211: drop spurious WARN_ON() in
    ieee80211_ibss_csa_beacon() (bsc#1227149).
  - wifi: mac80211: don't set ESS capab bit in assoc request
    (bsc#1227149).
  - wifi: cfg80211: consume both probe response and beacon IEs
    (bsc#1227149).
  - wifi: cfg80211: Replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - commit 5e5ecdb
  - wifi: cfg80211: OWE DH IE handling offload (bsc#1227149).
  - commit 58c8e33
  - wifi: cfg80211: add BSS usage reporting (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-parse-all-ML-elements-in-an-ML-probe-r.patch.
  - commit 5b2693d
  - wifi: mac80211: Replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: mac80211: add a flag to disallow puncturing (bsc#1227149).
  - wifi: cfg80211: Add support for setting TID to link mapping
    (bsc#1227149).
  - wifi: mac80211: update some locking documentation (bsc#1227149).
  - wifi: nl80211: Extend del pmksa support for SAE and OWE security
    (bsc#1227149).
  - wifi: mac80211: cleanup airtime arithmetic with
    ieee80211_sta_keep_active() (bsc#1227149).
  - wifi: cfg80211: expose nl80211_chan_width_to_mhz for wide
    sharing (bsc#1227149).
  - wifi: cfg80211: make RX assoc data const (bsc#1227149).
  - commit e4b61c4
  - wifi: cfg80211: Extend support for scanning while MLO connected
    (bsc#1227149).
  - commit b4c9412
  - wifi: cfg80211: hold wiphy mutex for send_interface
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-fix-missing-interfaces-when-dumping.patch.
  - commit 2123690
  - wifi: cfg80211: fix CQM for non-range use (bsc#1227149).
  - commit 3c8ba48
  - wifi: nl80211: refactor nl80211_send_mlme_event() arguments
    (bsc#1227149).
  - wifi: mac80211: Extend support for scanning while MLO connected
    (bsc#1227149).
  - wifi: mac80211: use wiphy locked debugfs for sdata/link
    (bsc#1227149).
  - wifi: mac80211: use wiphy locked debugfs helpers for agg_status
    (bsc#1227149).
  - wifi: cfg80211: add locked debugfs wrappers (bsc#1227149).
  - wifi: mac80211: drop robust action frames before assoc
    (bsc#1227149).
  - wifi: cfg80211: Allow AP/P2PGO to indicate port authorization
    to peer STA/P2PClient (bsc#1227149).
  - commit 03e12a0
  - wifi: mac80211: fix another key installation error path
    (bsc#1227149).
  - wifi: mac80211: rename struct cfg80211_rx_assoc_resp to
    cfg80211_rx_assoc_resp_data (bsc#1227149).
  - wifi: mac80211: rename ieee80211_tx_status() to
    ieee80211_tx_status_skb() (bsc#1227149).
  - wifi: mac80211: fix change_address deadlock during unregister
    (bsc#1227149).
  - wifi: mac80211: Add __counted_by for struct ieee802_11_elems
    and use struct_size() (bsc#1227149).
  - wifi: remove unused argument of ieee80211_get_tdls_action()
    (bsc#1227149).
  - wifi: mac80211: fix header kernel-doc typos (bsc#1227149).
  - wifi: cfg80211: fix header kernel-doc typos (bsc#1227149).
  - wifi: mac80211: add link id to mgd_prepare_tx() (bsc#1227149).
  - wifi: mac80211: Check if we had first beacon with relevant links
    (bsc#1227149).
  - commit fa14599
  - kABI fix of KVM: x86/pmu: Prioritize VMX interception over
  - commit 1f1d114
  - wifi: mac80211: flush STA queues on unauthorization
    (bsc#1227149).
  - wifi: mac80211: purge TX queues in flush_queues flow
    (bsc#1227149).
  - wifi: cfg80211: wext: convert return value to kernel-doc
    (bsc#1227149).
  - wifi: mac80211: fix a expired vs. cancel race in roc
    (bsc#1227149).
  - wifi: mac80211: make mgd_protect_tdls_discover MLO-aware
    (bsc#1227149).
  - wifi: cfg80211: Fix typo in documentation (bsc#1227149).
  - wifi: cfg80211: Handle specific BSSID in 6GHz scanning
    (bsc#1227149).
  - wifi: mac80211: mesh: fix some kdoc warnings (bsc#1227149).
  - wifi: cfg80211: Include operating class 137 in 6GHz band
    (bsc#1227149).
  - wifi: mac80211: Rename and update
    IEEE80211_VIF_DISABLE_SMPS_OVERRIDE (bsc#1227149).
  - commit 585676b
  - wifi: mac80211: split ieee80211_drop_unencrypted_mgmt() return
    value (bsc#1227149).
  - commit 3835ef2
  - wifi: mac80211: fix error path key leak (bsc#1227149).
  - Refresh patches.suse/wifi-mac80211-remove-key_mtx.patch.
  - commit 3b93fe9
  - wifi: mac80211: fix potential key leak (bsc#1227149).
  - Refresh patches.suse/wifi-mac80211-remove-key_mtx.patch.
  - commit 9fa5ec3
  - wifi: mac80211: handle debugfs when switching to/from MLO
    (bsc#1227149).
  - wifi: mac80211: add a driver callback to add vif debugfs
    (bsc#1227149).
  - wifi: mac80211: cleanup auth_data only if association continues
    (bsc#1227149).
  - wifi: mac80211: add back SPDX identifier (bsc#1227149).
  - wifi: mac80211: fix ieee80211_drop_unencrypted_mgmt return
    type/value (bsc#1227149).
  - wifi: mac80211: expand __ieee80211_data_to_8023() status
    (bsc#1227149).
  - wifi: mac80211: remove RX_DROP_UNUSABLE (bsc#1227149).
  - commit e0a6a5e
  - wifi: cfg80211: add local_state_change to deauth trace
    (bsc#1227149).
  - wifi: mac80211: reject MLO channel configuration if not
    supported (bsc#1227149).
  - wifi: mac80211: report per-link error during association
    (bsc#1227149).
  - wifi: cfg80211: report per-link errors during association
    (bsc#1227149).
  - wifi: mac80211: support antenna control in injection
    (bsc#1227149).
  - wifi: mac80211: support handling of advertised TID-to-link
    mapping (bsc#1227149).
  - wifi: mac80211: add support for parsing TID to Link mapping
    element (bsc#1227149).
  - wifi: mac80211: Notify the low level driver on change in MLO
    valid links (bsc#1227149).
  - wifi: mac80211: describe return values in kernel-doc
    (bsc#1227149).
  - wifi: cfg80211: reg: describe return values in kernel-doc
    (bsc#1227149).
  - commit df6c84a
  - wifi: mac80211: allow for_each_sta_active_link() under RCU
    (bsc#1227149).
  - wifi: mac80211: relax RCU check in for_each_vif_active_link()
    (bsc#1227149).
  - wifi: mac80211: don't connect to an AP while it's in a CSA
    process (bsc#1227149).
  - wifi: mac80211: update the rx_chains after set_antenna()
    (bsc#1227149).
  - wifi: mac80211: use bandwidth indication element for CSA
    (bsc#1227149).
  - wifi: cfg80211: split struct cfg80211_ap_settings (bsc#1227149).
  - wifi: mac80211: ethtool: always hold wiphy mutex (bsc#1227149).
  - wifi: cfg80211: make read-only array centers_80mhz static const
    (bsc#1227149).
  - wifi: cfg80211: save power spectral density(psd) of regulatory
    rule (bsc#1227149).
  - wifi: cfg80211: fix kernel-doc for wiphy_delayed_work_flush()
    (bsc#1227149).
  - commit 7f3b9af
  - wifi: mac80211: Sanity check tx bitrate if not provided by
    driver (bsc#1227149).
  - wifi: cfg80211: export DFS CAC time and usable state helper
    functions (bsc#1227149).
  - wifi: cfg80211: call reg_call_notifier on beacon hints
    (bsc#1227149).
  - wifi: cfg80211: allow reg update by driver even if wiphy->regd
    is set (bsc#1227149).
  - wifi: mac80211: additions to change_beacon() (bsc#1227149).
  - wifi: nl80211: additions to NL80211_CMD_SET_BEACON
    (bsc#1227149).
  - wifi: cfg80211: modify prototype for change_beacon
    (bsc#1227149).
  - wifi: mac80211: fixes in FILS discovery updates (bsc#1227149).
  - wifi: nl80211: fixes to FILS discovery updates (bsc#1227149).
  - wifi: lib80211: remove unused variables iv32 and iv16
    (bsc#1227149).
  - commit 67ccb18
  - wifi: mac80211: fix various kernel-doc issues (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-track-capability-opmode-NSS-separately.patch.
  - commit b1c042f
  - wifi: mac80211: remove shifted rate support (bsc#1227149).
  - wifi: cfg80211: remove scan_width support (bsc#1227149).
  - wifi: wext: avoid extra calls to strlen() in ieee80211_bss()
    (bsc#1227149).
  - wifi: mac80211: fix channel switch link data (bsc#1227149).
  - wifi: mac80211: Do not force off-channel for management Tx
    with MLO (bsc#1227149).
  - wifi: mac80211: take MBSSID/EHT data also from probe resp
    (bsc#1227149).
  - wifi: mac80211: Print local link address during authentication
    (bsc#1227149).
  - wifi: cfg80211: reg: fix various kernel-doc issues
    (bsc#1227149).
  - wifi: mac80211: remove unnecessary struct forward declaration
    (bsc#1227149).
  - commit 5936128
  - wifi: cfg80211: annotate iftype_data pointer with sparse
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-fix-wiphy-delayed-work-queueing.patch.
  - commit 031b8a7
  - wifi: mac80211: add more warnings about inserting sta info
    (bsc#1227149).
  - wifi: mac80211: add support for mld in ieee80211_chswitch_done
    (bsc#1227149).
  - wifi: mac80211: fix BA session teardown race (bsc#1227149).
  - wifi: mac80211: fix TXQ error path and cleanup (bsc#1227149).
  - commit 8e5b425
  - wifi: cfg80211: remove wdev mutex (bsc#1227149).
  - commit 4d7cf99
  - wifi: mac80211: set wiphy for virtual monitors (bsc#1227149).
  - commit 6022030
  - iommu/amd: Fix sysfs leak in iommu init (git-fixes).
  - commit 5b11e2a
  - wifi: mac80211: remove key_mtx (bsc#1227149).
  - commit 36d4ad3
  - iommu: Return right value in iommu_sva_bind_device()
    (git-fixes).
  - commit 769b149
  - wifi: mac80211: remove sta_mtx (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-check-if-the-existing-link-config-rema.patch.
  - Refresh
    patches.suse/wifi-mac80211-don-t-re-add-debugfs-during-reconfig.patch.
  - commit 5b967e8
  - wifi: mac80211: reduce iflist_mtx (bsc#1227149).
  - wifi: mac80211: remove local->mtx (bsc#1227149).
  - wifi: mac80211: remove ampdu_mlme.mtx (bsc#1227149).
  - wifi: mac80211: remove chanctx_mtx (bsc#1227149).
  - wifi: mac80211: take wiphy lock for MAC addr change
    (bsc#1227149).
  - wifi: mac80211: extend wiphy lock in interface removal
    (bsc#1227149).
  - wifi: mac80211: hold wiphy_lock around concurrency checks
    (bsc#1227149).
  - wifi: mac80211: ethtool: hold wiphy mutex (bsc#1227149).
  - commit b3dacec
  - wifi: mac80211: check wiphy mutex in ops (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-do-not-pass-AP_VLAN-vif-pointer-to-dri.patch.
  - commit 3b00636
  - wifi: cfg80211: check wiphy mutex is held for wdev mutex
    (bsc#1227149).
  - wifi: cfg80211: hold wiphy lock in
    cfg80211_any_wiphy_oper_chan() (bsc#1227149).
  - wifi: cfg80211: sme: hold wiphy lock for wdev iteration
    (bsc#1227149).
  - wifi: cfg80211: reg: hold wiphy mutex for wdev iteration
    (bsc#1227149).
  - wifi: mac80211: move color change finalize to wiphy work
    (bsc#1227149).
  - wifi: mac80211: move CSA finalize to wiphy work (bsc#1227149).
  - wifi: mac80211: move filter reconfig to wiphy work
    (bsc#1227149).
  - wifi: mac80211: move tspec work to wiphy work (bsc#1227149).
  - wifi: mac80211: move key tailroom work to wiphy work
    (bsc#1227149).
  - commit d930910
  - wifi: mac80211: move dynamic PS to wiphy work (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-move-sched-scan-stop-work-to-wiphy-wor.patch.
  - commit 6350819
  - wifi: mac80211: move DFS CAC work to wiphy work (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-move-radar-detect-work-to-wiphy-work.patch.
  - commit 46fc728
  - wifi: mac80211: move TDLS work to wiphy work (bsc#1227149).
  - wifi: mac80211: move link activation work to wiphy work
    (bsc#1227149).
  - wifi: mac80211: lock wiphy in IP address notifier (bsc#1227149).
  - wifi: mac80211: move monitor work to wiphy work (bsc#1227149).
  - wifi: mac80211: add more ops assertions (bsc#1227149).
  - wifi: mac80211: convert A-MPDU work to wiphy work (bsc#1227149).
  - wifi: mac80211: flush wiphy work where appropriate
    (bsc#1227149).
  - wifi: cfg80211: check RTNL when iterating devices (bsc#1227149).
  - commit 425f8ad
  - wifi: mac80211: lock wiphy for aggregation debugfs
    (bsc#1227149).
  - wifi: mac80211: hold wiphy lock in netdev/link debugfs
    (bsc#1227149).
  - wifi: mac80211: debugfs: lock wiphy instead of RTNL
    (bsc#1227149).
  - wifi: mac80211: fix SMPS status handling (bsc#1227149).
  - wifi: mac80211: Fix SMPS handling in the context of MLO
    (bsc#1227149).
  - wifi: mac80211: rework ack_frame_id handling a bit
    (bsc#1227149).
  - wifi: mac80211: tx: clarify conditions in if statement
    (bsc#1227149).
  - wifi: mac80211: Do not include crypto/algapi.h (bsc#1227149).
  - wifi: cfg80211: improve documentation for flag fields
    (bsc#1227149).
  - wifi: nl80211: Remove unused declaration
    nl80211_pmsr_dump_results() (bsc#1227149).
  - commit 75d4c97
  - wifi: mac80211: mesh: Remove unused function declaration
    mesh_ids_set_default() (bsc#1227149).
  - commit b3033c6
  - wifi: mac80211: Remove unused function declarations
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-move-radar-detect-work-to-wiphy-work.patch.
  - commit 343f020
  - x86/tsc: Trust initial offset in architectural TSC-adjust MSRs
    (bsc#1222015 bsc#1226962).
  - commit ba98363
  - KVM: x86/pmu: Prioritize VMX interception over #GP on RDPMC
    due to bad index (bsc#1226158).
  - commit fdb5ce1
  - net/9p: fix uninit-value in p9_client_rpc() (CVE-2024-39301
    bsc#1226994).
  - commit d8af728
  - arm64/io: add constant-argument check (bsc#1226502 git-fixes)
  - commit 45e8b78
  - struct acpi_ec kABI workaround (git-fixes).
  - commit 3605f74
  - wifi: mt76: mt7921s: fix potential hung tasks during chip
    recovery (stable-fixes).
  - commit d9504b4
  - drm/drm_file: Fix pid refcounting race (git-fixes).
  - drm/i915/gt: Fix potential UAF by revoke of fence registers
    (git-fixes).
  - drm/amdgpu: Fix pci state save during mode-1 reset (git-fixes).
  - drm/panel: simple: Add missing display timing flags for KOE
    TX26D202VM0BWA (git-fixes).
  - drm/fbdev-dma: Only set smem_start is enable per module option
    (git-fixes).
  - net: usb: ax88179_178a: improve link status logs (git-fixes).
  - net: phy: micrel: add Microchip KSZ 9477 to the device table
    (git-fixes).
  - batman-adv: Don't accept TT entries for out-of-spec VIDs
    (git-fixes).
  - can: mcp251xfd: fix infinite loop when xmit fails (git-fixes).
  - net: can: j1939: recover socket queue on CAN bus error during
    BAM transmission (git-fixes).
  - net: can: j1939: Initialize unused data in j1939_send_one()
    (git-fixes).
  - net: can: j1939: enhanced error handling for tightly received
    RTS messages in xtp_rx_rts_session_new (git-fixes).
  - ASoC: fsl-asoc-card: set priv->pdev before using it (git-fixes).
  - ASoC: amd: acp: remove i2s configuration check in
    acp_i2s_probe() (git-fixes).
  - ASoC: amd: acp: add a null check for chip_pdev structure
    (git-fixes).
  - ASoC: q6apm-lpass-dai: close graph on prepare errors
    (git-fixes).
  - ASoC: rockchip: i2s-tdm: Fix trcm mode by setting clock on
    right mclk (git-fixes).
  - ALSA: seq: Fix missing MSB in MIDI2 SPP conversion (git-fixes).
  - ALSA: hda/realtek: Fix conflicting quirk for PCI SSID 17aa:3820
    (git-fixes).
  - ALSA: seq: Fix missing channel at encoding RPN/NRPN MIDI2
    messages (git-fixes).
  - drm/amdgpu: fix UBSAN warning in kv_dpm.c (stable-fixes).
  - drm/radeon: fix UBSAN warning in kv_dpm.c (stable-fixes).
  - ACPI: EC: Evaluate orphan _REG under EC device (git-fixes).
  - serial: exar: adding missing CTI and Exar PCI ids
    (stable-fixes).
  - serial: imx: Introduce timeout when waiting on transmitter empty
    (stable-fixes).
  - usb: gadget: function: Remove usage of the deprecated
    ida_simple_xx() API (stable-fixes).
  - usb: typec: ucsi_glink: drop special handling for CCI_BUSY
    (stable-fixes).
  - usb: dwc3: pci: Don't set "linux,phy_charger_detect" property
    on Lenovo Yoga Tab2 1380 (stable-fixes).
  - usb: misc: uss720: check for incompatible versions of the
    Belkin F5U002 (stable-fixes).
  - usb: gadget: uvc: configfs: ensure guid to be valid before set
    (stable-fixes).
  - cpufreq: amd-pstate: fix memory leak on CPU EPP exit
    (stable-fixes).
  - ACPI: EC: Install address space handler at the namespace root
    (stable-fixes).
  - PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
    (stable-fixes).
  - power: supply: cros_usbpd: provide ID table for avoiding
    fallback match (stable-fixes).
  - platform/x86: toshiba_acpi: Add quirk for buttons on Z830
    (stable-fixes).
  - ASoC: Intel: sof-sdw: really remove FOUR_SPEAKER quirk
    (git-fixes).
  - ASoC: Intel: sof_sdw: add quirk for Dell SKU 0C0F
    (stable-fixes).
  - ASoC: Intel: sof_sdw: add JD2 quirk for HP Omen 14
    (stable-fixes).
  - drm/lima: mask irqs in timeout path before hard reset
    (stable-fixes).
  - drm/lima: add mask irq callback to gp and pp (stable-fixes).
  - drm/amd/display: revert Exit idle optimizations before HDCP
    execution (stable-fixes).
  - drm/amd/display: Exit idle optimizations before HDCP execution
    (stable-fixes).
  - Bluetooth: ath3k: Fix multiple issues reported by checkpatch.pl
    (stable-fixes).
  - batman-adv: bypass empty buckets in batadv_purge_orig_ref()
    (stable-fixes).
  - ssb: Fix potential NULL pointer dereference in
    ssb_device_uevent() (stable-fixes).
  - HID: Add quirk for Logitech Casa touchpad (stable-fixes).
  - ACPI: x86: Add PNP_UART1_SKIP quirk for Lenovo Blade2 tablets
    (stable-fixes).
  - crypto: hisilicon/qm - Add the err memory release process to
    qm uninit (stable-fixes).
  - crypto: hisilicon/sec - Fix memory leak for sec resource release
    (stable-fixes).
  - commit bbedf42

++++ kernel-rt:

  - wifi: iwlwifi: mvm: fix the TXF mapping for BZ devices
    (bsc#1227149).
  - wifi: iwlwifi: clear link_id in time_event (bsc#1227149).
  - wifi: iwlwifi: mvm: fix a battery life regression (bsc#1227149).
  - wifi: iwlwifi: remove extra kernel-doc (bsc#1227149).
  - wifi: iwlwifi: mvm: skip adding debugfs symlink for reconfig
    (bsc#1227149).
  - wifi: iwlwifi: replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: iwlwifi: mvm: use the new command to clear the internal
    buffer (bsc#1227149).
  - commit acd03db
  - wifi: iwlwifi: mvm: add US/Canada MCC to API (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-fix-warnings-from-dmi_get_system_in.patch.
  - commit 70a9591
  - wifi: iwlwifi: mvm: disallow puncturing in US/Canada
    (bsc#1227149).
  - wifi: iwlwifi: Add rf_mapping of new wifi7 devices
    (bsc#1227149).
  - wifi: iwlwifi: cleanup BT Shared Single Antenna code
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Do not warn if valid link pair was not found
    (bsc#1227149).
  - wifi: iwlwifi: mvm: d3: avoid intermediate/early mutex unlock
    (bsc#1227149).
  - wifi: iwlwifi: Don't mark DFS channels as NO-IR (bsc#1227149).
  - wifi: iwlwifi: mvm: Allow DFS concurrent operation
    (bsc#1227149).
  - wifi: iwlwifi: mvm: do not send STA_DISABLE_TX_CMD for newer
    firmware (bsc#1227149).
  - wifi: iwlwifi: remove async command callback (bsc#1227149).
  - commit 0205124
  - wifi: iwlwifi: fw: file: don't use [0] for variable arrays
    (bsc#1227149).
  - wifi: iwlwifi: pcie: get_crf_id() can be void (bsc#1227149).
  - wifi: iwlwifi: pcie: dump CSRs before removal (bsc#1227149).
  - wifi: iwlwifi: pcie: clean up device removal work (bsc#1227149).
  - wifi: iwlwifi: mvm: add a debugfs hook to clear the monitor data
    (bsc#1227149).
  - wifi: iwlwifi: refactor RX tracing (bsc#1227149).
  - wifi: iwlwifi: mvm: Correctly report TSF data in scan complete
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Use the link ID provided in scan request
    (bsc#1227149).
  - wifi: iwlwifi: fw: replace deprecated strncpy with strscpy_pad
    (bsc#1227149).
  - wifi: iwlwifi: fix system commands group ordering (bsc#1227149).
  - commit 6cae420
  - wifi: iwlwifi: drop NULL pointer check in
    iwl_mvm_tzone_set_trip_temp() (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 86 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: read DSM func 2 for specific RF types
    (bsc#1227149).
  - wifi: iwlwifi: mvm: show dump even for pldr_sync (bsc#1227149).
  - wifi: iwlwifi: mvm: cycle FW link on chanctx removal
    (bsc#1227149).
  - wifi: iwlwifi: trace full frames with TX status request
    (bsc#1227149).
  - wifi: iwlwifi: fw: Add support for UATS table in UHB
    (bsc#1227149).
  - wifi: iwlwifi: mvm: add a print when sending RLC command
    (bsc#1227149).
  - wifi: iwlwifi: mvm: debugfs for fw system stats (bsc#1227149).
  - wifi: iwlwifi: mvm: implement new firmware API for statistics
    (bsc#1227149).
  - commit ed6b54f
  - wifi: iwlwifi: disable multi rx queue for 9000 (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-include-link-ID-when-releasing-fram.patch.
  - commit 9866ec0
  - wifi: iwlwifi: mvm: fix regdb initialization (bsc#1227149).
  - wifi: iwlwifi: mvm: simplify the reorder buffer (bsc#1227149).
  - wifi: iwlwifi: mvm: Return success if link could not be removed
    (bsc#1227149).
  - wifi: iwlwifi: add support for SNPS DPHYIP region type
    (bsc#1227149).
  - wifi: iwlwifi: mvm: remove set_tim callback for MLD ops
    (bsc#1227149).
  - wifi: iwlwifi: api: fix center_freq label in PHY diagram
    (bsc#1227149).
  - wifi: iwlwifi: support link id in SESSION_PROTECTION_NOTIF
    (bsc#1227149).
  - wifi: iwlwifi: support link_id in SESSION_PROTECTION cmd
    (bsc#1227149).
  - wifi: iwlwifi: make time_events MLO aware (bsc#1227149).
  - commit 1ea0f35
  - wifi: iwlwifi: add support for activating UNII-1 in WW via BIOS
    (bsc#1227149).
  - wifi: iwlwifi: mvm: extend alive timeout to 2 seconds
    (bsc#1227149).
  - wifi: iwlwifi: mvm: fix the PHY context resolution for p2p
    device (bsc#1227149).
  - wifi: iwlwifi: mvm: fold the ref++ into iwl_mvm_phy_ctxt_add
    (bsc#1227149).
  - wifi: iwlwifi: mvm: don't add dummy phy context (bsc#1227149).
  - wifi: iwlwifi: mvm: cleanup MLO and non-MLO unification code
    (bsc#1227149).
  - wifi: iwlwifi: mvm: implement ROC version 3 (bsc#1227149).
  - wifi: iwlwifi: send EDT table to FW (bsc#1227149).
  - wifi: iwlmvm: fw: Add new OEM vendor to tas approved list
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Fix unreachable code path (bsc#1227149).
  - commit 50ebcaa
  - wifi: iwlwifi: mvm: advertise support for SCS traffic
    description (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-do-not-announce-EPCS-support.patch.
  - commit 7208326
  - wifi: iwlwifi: add new RF support for wifi7 (bsc#1227149).
  - wifi: iwlwifi: fw: increase fw_version string size
    (bsc#1227149).
  - wifi: iwlwifi: check for kmemdup() return value in
    iwl_parse_tlv_firmware() (bsc#1227149).
  - wifi: iwlwifi: fix the rf step and flavor bits range
    (bsc#1227149).
  - wifi: iwlwifi: fw: Fix debugfs command sending (bsc#1227149).
  - wifi: iwlwifi: mvm: add start mac ctdp sum calculation debugfs
    handler (bsc#1227149).
  - wifi: iwlwifi: abort scan when rfkill on but device enabled
    (bsc#1227149).
  - wifi: iwlwifi: mvm: Add basic link selection logic
    (bsc#1227149).
  - wifi: iwlwifi: mei: return error from register when not built
    (bsc#1227149).
  - commit fddf9eb
  - wifi: iwlwifi: mvm: fix SB CFG check (bsc#1227149).
  - wifi: iwlwifi: mvm: add a per-link debugfs (bsc#1227149).
  - wifi: iwlwifi: mvm: rework debugfs handling (bsc#1227149).
  - wifi: iwlwifi: add support for new ini region types
    (bsc#1227149).
  - wifi: iwlwifi: Extract common prph mac/phy regions data dump
    logic (bsc#1227149).
  - wifi: iwlwifi: bump FW API to 84 for AX/BZ/SC devices
    (bsc#1227149).
  - wifi: iwlwifi: mvm: offload IGTK in AP if BIGTK is supported
    (bsc#1227149).
  - wifi: iwlwifi: pcie: clean up WFPM control bits (bsc#1227149).
  - wifi: iwlwifi: fix opmode start/stop race (bsc#1227149).
  - wifi: iwlwifi: skip opmode start retries on dead transport
    (bsc#1227149).
  - commit 36551d1
  - wifi: iwlwifi: mvm: add support for new wowlan_info_notif
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-d3-fix-IPN-byte-order.patch.
  - commit 0b379ae
  - wifi: iwlwifi: pcie: propagate iwl_pcie_gen2_apm_init() error
    (bsc#1227149).
  - wifi: iwlwifi: add mapping of a periphery register crf for WH RF
    (bsc#1227149).
  - wifi: iwlwifi: mvm: check for iwl_mvm_mld_update_sta() errors
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support injection antenna control
    (bsc#1227149).
  - wifi: iwlwifi: mvm: refactor TX rate handling (bsc#1227149).
  - wifi: iwlwifi: mvm: make pldr_sync AX210 specific (bsc#1227149).
  - wifi: iwlwifi: fail NIC access fast on dead NIC (bsc#1227149).
  - wifi: iwlwifi: pcie: (re-)assign BAR0 on driver bind
    (bsc#1227149).
  - commit 0882d6d
  - wifi: iwlwifi: implement enable/disable for China 2022
    regulatory (bsc#1227149).
  - wifi: iwlwifi: mvm: handle link-STA allocation in restart
    (bsc#1227149).
  - wifi: iwlwifi: mvm: iterate active links for STA queues
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support set_antenna() (bsc#1227149).
  - wifi: iwlwifi: mvm: add a debug print when we get a BAR
    (bsc#1227149).
  - wifi: iwlwifi: mvm: move listen interval to constants
    (bsc#1227149).
  - wifi: iwlwifi: no power save during transition to D3
    (bsc#1227149).
  - wifi: iwlwifi: update context info structure definitions
    (bsc#1227149).
  - wifi: iwlwifi: mvm: fix recovery flow in CSA (bsc#1227149).
  - wifi: iwlwifi: mvm: enable FILS DF Tx on non-PSC channel
    (bsc#1227149).
  - commit 5c7efaf
  - wifi: iwlwifi: mvm: make "pldr_sync" mode effective
    (bsc#1227149).
  - wifi: iwlwifi: mvm: log dropped frames (bsc#1227149).
  - wifi: iwlwifi: fw: disable firmware debug asserts (bsc#1227149).
  - wifi: iwlwifi: remove dead-code (bsc#1227149).
  - wifi: iwlwifi: pcie: enable TOP fatal error interrupt
    (bsc#1227149).
  - wifi: iwlwifi: pcie: give up mem read if HW is dead
    (bsc#1227149).
  - wifi: iwlwifi: pcie: rescan bus if no parent (bsc#1227149).
  - wifi: iwlwifi: mvm: reduce maximum RX A-MPDU size (bsc#1227149).
  - wifi: iwlwifi: mvm: check link more carefully (bsc#1227149).
  - wifi: iwlwifi: mvm: move RU alloc B2 placement (bsc#1227149).
  - commit 8aa4ff8
  - virtio: delete vq in vp_find_vqs_msix() when request_irq()
    fails (CVE-2024-37353 bsc#1226875).
  - commit 4591439
  - wifi: iwlwifi: mvm: fix kernel-doc (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-ensure-offloading-TID-queue-exists.patch.
  - commit 68376c9
  - wifi: iwlwifi: pcie: fix kernel-doc issues (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-pcie-fix-RB-status-reading.patch.
  - commit f106797
  - wifi: iwlwifi: fw: reconstruct the API/CAPA enum number
    (bsc#1227149).
  - wifi: iwlwifi: dvm: remove kernel-doc warnings (bsc#1227149).
  - wifi: iwlwifi: queue: fix kernel-doc (bsc#1227149).
  - wifi: iwlwifi: fix some kernel-doc issues (bsc#1227149).
  - wifi: iwlwifi: mvm: disconnect long CSA only w/o alternative
    (bsc#1227149).
  - wifi: iwlwifi: mvm: increase session protection after CSA
    (bsc#1227149).
  - wifi: iwlwifi: mvm: support CSA with MLD (bsc#1227149).
  - wifi: iwlmei: don't send nic info with invalid mac address
    (bsc#1227149).
  - commit 85cbe83
  - wifi: iwlwifi: mvm: support flush on AP interfaces
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-iwlwifi-mvm-change-iwl_mvm_flush_sta-API.patch.
  - commit 908ff7c
  - wifi: iwlmei: send driver down SAP message only if wiamt is
    enabled (bsc#1227149).
  - wifi: iwlmei: send HOST_GOES_DOWN message even if wiamt is
    disabled (bsc#1227149).
  - wifi: iwlmei: don't send SAP messages if AMT is disabled
    (bsc#1227149).
  - wifi: iwlwifi: remove memory check for LMAC error address
    (bsc#1227149).
  - wifi: iwlwifi: mvm: enable HE TX/RX <242 tone RU on new RFs
    (bsc#1227149).
  - wifi: iwlwifi: add Razer to ppag approved list (bsc#1227149).
  - wifi: iwlwifi: pcie: point invalid TFDs to invalid data
    (bsc#1227149).
  - wifi: iwlwifi: queue: move iwl_txq_gen2_set_tb() up
    (bsc#1227149).
  - wifi: iwlwifi: pcie: move gen1 TB handling to header
    (bsc#1227149).
  - commit 92ab309
  - wifi: iwlwifi: remove 'def_rx_queue' struct member
    (bsc#1227149).
  - wifi: iwlwifi: pcie: clean up gen1/gen2 TFD unmap (bsc#1227149).
  - wifi: iwlwifi: remove WARN from read_mem32() (bsc#1227149).
  - wifi: iwlwifi: api: fix a small upper/lower-case typo
    (bsc#1227149).
  - wifi: iwlwifi: mvm: advertise MLO only if EHT is enabled
    (bsc#1227149).
  - commit aa9a391
  - Add alt-commit to iwlwifi patches
  - commit 865aa7a
  - wifi: mac80211: fix unsolicited broadcast probe config
    (bsc#1227149).
  - wifi: mac80211: initialize SMPS mode correctly (bsc#1227149).
  - wifi: mac80211: fix driver debugfs for vif type change
    (bsc#1227149).
  - wifi: mac80211: improve CSA/ECSA connection refusal
    (bsc#1227149).
  - wifi: cfg80211: detect stuck ECSA element in probe resp
    (bsc#1227149).
  - wifi: mac80211: add/remove driver debugfs entries as appropriate
    (bsc#1227149).
  - wifi: mac80211: do not re-add debugfs entries during resume
    (bsc#1227149).
  - commit 769161a
  - wifi: mac80211: remove redundant ML element check (bsc#1227149).
  - wifi: cfg80211: Update the default DSCP-to-UP mapping
    (bsc#1227149).
  - wifi: mac80211: fix spelling typo in comment (bsc#1227149).
  - wifi: mac80211: add a driver callback to check active_links
    (bsc#1227149).
  - wifi: mac80211: fix advertised TTLM scheduling (bsc#1227149).
  - wifi: cfg80211: avoid double free if updating BSS fails
    (bsc#1227149).
  - commit e8bab13
  - wifi: cfg80211: handle UHB AP and STA power type (bsc#1227149).
  - commit 6021aa4
  - wifi: cfg80211: ensure cfg80211_bss_update frees IEs on error
    (bsc#1227149).
  - wifi: mac80211: allow 64-bit radiotap timestamps (bsc#1227149).
  - wifi: mac80211: rework RX timestamp flags (bsc#1227149).
  - wifi: mac80211: Schedule regulatory channels check on bandwith
    change (bsc#1227149).
  - wifi: cfg80211: Schedule regulatory check on BSS STA channel
    change (bsc#1227149).
  - wifi: cfg80211: reg: Support P2P operation on DFS channels
    (bsc#1227149).
  - wifi: mac80211: Skip association timeout update after comeback
    rejection (bsc#1227149).
  - wifi: mac80211: address some kerneldoc warnings (bsc#1227149).
  - wifi: cfg80211: address several kerneldoc warnings
    (bsc#1227149).
  - commit bc44e06
  - wifi: cfg80211: generate an ML element for per-STA profiles
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-parse-all-ML-elements-in-an-ML-probe-r.patch.
  - commit d924102
  - wifi: cfg80211: introduce cfg80211_ssid_eq() (bsc#1227149).
  - wifi: mac80211: sta_info.c: fix sentence grammar (bsc#1227149).
  - wifi: mac80211: rx.c: fix sentence grammar (bsc#1227149).
  - wifi: cfg80211: fix spelling & punctutation (bsc#1227149).
  - wifi: cfg80211: sort certificates in build (bsc#1227149).
  - wifi: mac80211: drop spurious WARN_ON() in
    ieee80211_ibss_csa_beacon() (bsc#1227149).
  - wifi: mac80211: don't set ESS capab bit in assoc request
    (bsc#1227149).
  - wifi: cfg80211: consume both probe response and beacon IEs
    (bsc#1227149).
  - wifi: cfg80211: Replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - commit 5e5ecdb
  - wifi: cfg80211: OWE DH IE handling offload (bsc#1227149).
  - commit 58c8e33
  - wifi: cfg80211: add BSS usage reporting (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-parse-all-ML-elements-in-an-ML-probe-r.patch.
  - commit 5b2693d
  - wifi: mac80211: Replace ENOTSUPP with EOPNOTSUPP (bsc#1227149).
  - wifi: mac80211: add a flag to disallow puncturing (bsc#1227149).
  - wifi: cfg80211: Add support for setting TID to link mapping
    (bsc#1227149).
  - wifi: mac80211: update some locking documentation (bsc#1227149).
  - wifi: nl80211: Extend del pmksa support for SAE and OWE security
    (bsc#1227149).
  - wifi: mac80211: cleanup airtime arithmetic with
    ieee80211_sta_keep_active() (bsc#1227149).
  - wifi: cfg80211: expose nl80211_chan_width_to_mhz for wide
    sharing (bsc#1227149).
  - wifi: cfg80211: make RX assoc data const (bsc#1227149).
  - commit e4b61c4
  - wifi: cfg80211: Extend support for scanning while MLO connected
    (bsc#1227149).
  - commit b4c9412
  - wifi: cfg80211: hold wiphy mutex for send_interface
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-fix-missing-interfaces-when-dumping.patch.
  - commit 2123690
  - wifi: cfg80211: fix CQM for non-range use (bsc#1227149).
  - commit 3c8ba48
  - wifi: nl80211: refactor nl80211_send_mlme_event() arguments
    (bsc#1227149).
  - wifi: mac80211: Extend support for scanning while MLO connected
    (bsc#1227149).
  - wifi: mac80211: use wiphy locked debugfs for sdata/link
    (bsc#1227149).
  - wifi: mac80211: use wiphy locked debugfs helpers for agg_status
    (bsc#1227149).
  - wifi: cfg80211: add locked debugfs wrappers (bsc#1227149).
  - wifi: mac80211: drop robust action frames before assoc
    (bsc#1227149).
  - wifi: cfg80211: Allow AP/P2PGO to indicate port authorization
    to peer STA/P2PClient (bsc#1227149).
  - commit 03e12a0
  - wifi: mac80211: fix another key installation error path
    (bsc#1227149).
  - wifi: mac80211: rename struct cfg80211_rx_assoc_resp to
    cfg80211_rx_assoc_resp_data (bsc#1227149).
  - wifi: mac80211: rename ieee80211_tx_status() to
    ieee80211_tx_status_skb() (bsc#1227149).
  - wifi: mac80211: fix change_address deadlock during unregister
    (bsc#1227149).
  - wifi: mac80211: Add __counted_by for struct ieee802_11_elems
    and use struct_size() (bsc#1227149).
  - wifi: remove unused argument of ieee80211_get_tdls_action()
    (bsc#1227149).
  - wifi: mac80211: fix header kernel-doc typos (bsc#1227149).
  - wifi: cfg80211: fix header kernel-doc typos (bsc#1227149).
  - wifi: mac80211: add link id to mgd_prepare_tx() (bsc#1227149).
  - wifi: mac80211: Check if we had first beacon with relevant links
    (bsc#1227149).
  - commit fa14599
  - kABI fix of KVM: x86/pmu: Prioritize VMX interception over
  - commit 1f1d114
  - wifi: mac80211: flush STA queues on unauthorization
    (bsc#1227149).
  - wifi: mac80211: purge TX queues in flush_queues flow
    (bsc#1227149).
  - wifi: cfg80211: wext: convert return value to kernel-doc
    (bsc#1227149).
  - wifi: mac80211: fix a expired vs. cancel race in roc
    (bsc#1227149).
  - wifi: mac80211: make mgd_protect_tdls_discover MLO-aware
    (bsc#1227149).
  - wifi: cfg80211: Fix typo in documentation (bsc#1227149).
  - wifi: cfg80211: Handle specific BSSID in 6GHz scanning
    (bsc#1227149).
  - wifi: mac80211: mesh: fix some kdoc warnings (bsc#1227149).
  - wifi: cfg80211: Include operating class 137 in 6GHz band
    (bsc#1227149).
  - wifi: mac80211: Rename and update
    IEEE80211_VIF_DISABLE_SMPS_OVERRIDE (bsc#1227149).
  - commit 585676b
  - wifi: mac80211: split ieee80211_drop_unencrypted_mgmt() return
    value (bsc#1227149).
  - commit 3835ef2
  - wifi: mac80211: fix error path key leak (bsc#1227149).
  - Refresh patches.suse/wifi-mac80211-remove-key_mtx.patch.
  - commit 3b93fe9
  - wifi: mac80211: fix potential key leak (bsc#1227149).
  - Refresh patches.suse/wifi-mac80211-remove-key_mtx.patch.
  - commit 9fa5ec3
  - wifi: mac80211: handle debugfs when switching to/from MLO
    (bsc#1227149).
  - wifi: mac80211: add a driver callback to add vif debugfs
    (bsc#1227149).
  - wifi: mac80211: cleanup auth_data only if association continues
    (bsc#1227149).
  - wifi: mac80211: add back SPDX identifier (bsc#1227149).
  - wifi: mac80211: fix ieee80211_drop_unencrypted_mgmt return
    type/value (bsc#1227149).
  - wifi: mac80211: expand __ieee80211_data_to_8023() status
    (bsc#1227149).
  - wifi: mac80211: remove RX_DROP_UNUSABLE (bsc#1227149).
  - commit e0a6a5e
  - wifi: cfg80211: add local_state_change to deauth trace
    (bsc#1227149).
  - wifi: mac80211: reject MLO channel configuration if not
    supported (bsc#1227149).
  - wifi: mac80211: report per-link error during association
    (bsc#1227149).
  - wifi: cfg80211: report per-link errors during association
    (bsc#1227149).
  - wifi: mac80211: support antenna control in injection
    (bsc#1227149).
  - wifi: mac80211: support handling of advertised TID-to-link
    mapping (bsc#1227149).
  - wifi: mac80211: add support for parsing TID to Link mapping
    element (bsc#1227149).
  - wifi: mac80211: Notify the low level driver on change in MLO
    valid links (bsc#1227149).
  - wifi: mac80211: describe return values in kernel-doc
    (bsc#1227149).
  - wifi: cfg80211: reg: describe return values in kernel-doc
    (bsc#1227149).
  - commit df6c84a
  - wifi: mac80211: allow for_each_sta_active_link() under RCU
    (bsc#1227149).
  - wifi: mac80211: relax RCU check in for_each_vif_active_link()
    (bsc#1227149).
  - wifi: mac80211: don't connect to an AP while it's in a CSA
    process (bsc#1227149).
  - wifi: mac80211: update the rx_chains after set_antenna()
    (bsc#1227149).
  - wifi: mac80211: use bandwidth indication element for CSA
    (bsc#1227149).
  - wifi: cfg80211: split struct cfg80211_ap_settings (bsc#1227149).
  - wifi: mac80211: ethtool: always hold wiphy mutex (bsc#1227149).
  - wifi: cfg80211: make read-only array centers_80mhz static const
    (bsc#1227149).
  - wifi: cfg80211: save power spectral density(psd) of regulatory
    rule (bsc#1227149).
  - wifi: cfg80211: fix kernel-doc for wiphy_delayed_work_flush()
    (bsc#1227149).
  - commit 7f3b9af
  - wifi: mac80211: Sanity check tx bitrate if not provided by
    driver (bsc#1227149).
  - wifi: cfg80211: export DFS CAC time and usable state helper
    functions (bsc#1227149).
  - wifi: cfg80211: call reg_call_notifier on beacon hints
    (bsc#1227149).
  - wifi: cfg80211: allow reg update by driver even if wiphy->regd
    is set (bsc#1227149).
  - wifi: mac80211: additions to change_beacon() (bsc#1227149).
  - wifi: nl80211: additions to NL80211_CMD_SET_BEACON
    (bsc#1227149).
  - wifi: cfg80211: modify prototype for change_beacon
    (bsc#1227149).
  - wifi: mac80211: fixes in FILS discovery updates (bsc#1227149).
  - wifi: nl80211: fixes to FILS discovery updates (bsc#1227149).
  - wifi: lib80211: remove unused variables iv32 and iv16
    (bsc#1227149).
  - commit 67ccb18
  - wifi: mac80211: fix various kernel-doc issues (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-track-capability-opmode-NSS-separately.patch.
  - commit b1c042f
  - wifi: mac80211: remove shifted rate support (bsc#1227149).
  - wifi: cfg80211: remove scan_width support (bsc#1227149).
  - wifi: wext: avoid extra calls to strlen() in ieee80211_bss()
    (bsc#1227149).
  - wifi: mac80211: fix channel switch link data (bsc#1227149).
  - wifi: mac80211: Do not force off-channel for management Tx
    with MLO (bsc#1227149).
  - wifi: mac80211: take MBSSID/EHT data also from probe resp
    (bsc#1227149).
  - wifi: mac80211: Print local link address during authentication
    (bsc#1227149).
  - wifi: cfg80211: reg: fix various kernel-doc issues
    (bsc#1227149).
  - wifi: mac80211: remove unnecessary struct forward declaration
    (bsc#1227149).
  - commit 5936128
  - wifi: cfg80211: annotate iftype_data pointer with sparse
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-cfg80211-fix-wiphy-delayed-work-queueing.patch.
  - commit 031b8a7
  - wifi: mac80211: add more warnings about inserting sta info
    (bsc#1227149).
  - wifi: mac80211: add support for mld in ieee80211_chswitch_done
    (bsc#1227149).
  - wifi: mac80211: fix BA session teardown race (bsc#1227149).
  - wifi: mac80211: fix TXQ error path and cleanup (bsc#1227149).
  - commit 8e5b425
  - wifi: cfg80211: remove wdev mutex (bsc#1227149).
  - commit 4d7cf99
  - wifi: mac80211: set wiphy for virtual monitors (bsc#1227149).
  - commit 6022030
  - iommu/amd: Fix sysfs leak in iommu init (git-fixes).
  - commit 5b11e2a
  - wifi: mac80211: remove key_mtx (bsc#1227149).
  - commit 36d4ad3
  - iommu: Return right value in iommu_sva_bind_device()
    (git-fixes).
  - commit 769b149
  - wifi: mac80211: remove sta_mtx (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-check-if-the-existing-link-config-rema.patch.
  - Refresh
    patches.suse/wifi-mac80211-don-t-re-add-debugfs-during-reconfig.patch.
  - commit 5b967e8
  - wifi: mac80211: reduce iflist_mtx (bsc#1227149).
  - wifi: mac80211: remove local->mtx (bsc#1227149).
  - wifi: mac80211: remove ampdu_mlme.mtx (bsc#1227149).
  - wifi: mac80211: remove chanctx_mtx (bsc#1227149).
  - wifi: mac80211: take wiphy lock for MAC addr change
    (bsc#1227149).
  - wifi: mac80211: extend wiphy lock in interface removal
    (bsc#1227149).
  - wifi: mac80211: hold wiphy_lock around concurrency checks
    (bsc#1227149).
  - wifi: mac80211: ethtool: hold wiphy mutex (bsc#1227149).
  - commit b3dacec
  - wifi: mac80211: check wiphy mutex in ops (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-do-not-pass-AP_VLAN-vif-pointer-to-dri.patch.
  - commit 3b00636
  - wifi: cfg80211: check wiphy mutex is held for wdev mutex
    (bsc#1227149).
  - wifi: cfg80211: hold wiphy lock in
    cfg80211_any_wiphy_oper_chan() (bsc#1227149).
  - wifi: cfg80211: sme: hold wiphy lock for wdev iteration
    (bsc#1227149).
  - wifi: cfg80211: reg: hold wiphy mutex for wdev iteration
    (bsc#1227149).
  - wifi: mac80211: move color change finalize to wiphy work
    (bsc#1227149).
  - wifi: mac80211: move CSA finalize to wiphy work (bsc#1227149).
  - wifi: mac80211: move filter reconfig to wiphy work
    (bsc#1227149).
  - wifi: mac80211: move tspec work to wiphy work (bsc#1227149).
  - wifi: mac80211: move key tailroom work to wiphy work
    (bsc#1227149).
  - commit d930910
  - wifi: mac80211: move dynamic PS to wiphy work (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-move-sched-scan-stop-work-to-wiphy-wor.patch.
  - commit 6350819
  - wifi: mac80211: move DFS CAC work to wiphy work (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-move-radar-detect-work-to-wiphy-work.patch.
  - commit 46fc728
  - wifi: mac80211: move TDLS work to wiphy work (bsc#1227149).
  - wifi: mac80211: move link activation work to wiphy work
    (bsc#1227149).
  - wifi: mac80211: lock wiphy in IP address notifier (bsc#1227149).
  - wifi: mac80211: move monitor work to wiphy work (bsc#1227149).
  - wifi: mac80211: add more ops assertions (bsc#1227149).
  - wifi: mac80211: convert A-MPDU work to wiphy work (bsc#1227149).
  - wifi: mac80211: flush wiphy work where appropriate
    (bsc#1227149).
  - wifi: cfg80211: check RTNL when iterating devices (bsc#1227149).
  - commit 425f8ad
  - wifi: mac80211: lock wiphy for aggregation debugfs
    (bsc#1227149).
  - wifi: mac80211: hold wiphy lock in netdev/link debugfs
    (bsc#1227149).
  - wifi: mac80211: debugfs: lock wiphy instead of RTNL
    (bsc#1227149).
  - wifi: mac80211: fix SMPS status handling (bsc#1227149).
  - wifi: mac80211: Fix SMPS handling in the context of MLO
    (bsc#1227149).
  - wifi: mac80211: rework ack_frame_id handling a bit
    (bsc#1227149).
  - wifi: mac80211: tx: clarify conditions in if statement
    (bsc#1227149).
  - wifi: mac80211: Do not include crypto/algapi.h (bsc#1227149).
  - wifi: cfg80211: improve documentation for flag fields
    (bsc#1227149).
  - wifi: nl80211: Remove unused declaration
    nl80211_pmsr_dump_results() (bsc#1227149).
  - commit 75d4c97
  - wifi: mac80211: mesh: Remove unused function declaration
    mesh_ids_set_default() (bsc#1227149).
  - commit b3033c6
  - wifi: mac80211: Remove unused function declarations
    (bsc#1227149).
  - Refresh
    patches.suse/wifi-mac80211-move-radar-detect-work-to-wiphy-work.patch.
  - commit 343f020
  - x86/tsc: Trust initial offset in architectural TSC-adjust MSRs
    (bsc#1222015 bsc#1226962).
  - commit ba98363
  - KVM: x86/pmu: Prioritize VMX interception over #GP on RDPMC
    due to bad index (bsc#1226158).
  - commit fdb5ce1
  - net/9p: fix uninit-value in p9_client_rpc() (CVE-2024-39301
    bsc#1226994).
  - commit d8af728
  - arm64/io: add constant-argument check (bsc#1226502 git-fixes)
  - commit 45e8b78
  - struct acpi_ec kABI workaround (git-fixes).
  - commit 3605f74
  - wifi: mt76: mt7921s: fix potential hung tasks during chip
    recovery (stable-fixes).
  - commit d9504b4
  - drm/drm_file: Fix pid refcounting race (git-fixes).
  - drm/i915/gt: Fix potential UAF by revoke of fence registers
    (git-fixes).
  - drm/amdgpu: Fix pci state save during mode-1 reset (git-fixes).
  - drm/panel: simple: Add missing display timing flags for KOE
    TX26D202VM0BWA (git-fixes).
  - drm/fbdev-dma: Only set smem_start is enable per module option
    (git-fixes).
  - net: usb: ax88179_178a: improve link status logs (git-fixes).
  - net: phy: micrel: add Microchip KSZ 9477 to the device table
    (git-fixes).
  - batman-adv: Don't accept TT entries for out-of-spec VIDs
    (git-fixes).
  - can: mcp251xfd: fix infinite loop when xmit fails (git-fixes).
  - net: can: j1939: recover socket queue on CAN bus error during
    BAM transmission (git-fixes).
  - net: can: j1939: Initialize unused data in j1939_send_one()
    (git-fixes).
  - net: can: j1939: enhanced error handling for tightly received
    RTS messages in xtp_rx_rts_session_new (git-fixes).
  - ASoC: fsl-asoc-card: set priv->pdev before using it (git-fixes).
  - ASoC: amd: acp: remove i2s configuration check in
    acp_i2s_probe() (git-fixes).
  - ASoC: amd: acp: add a null check for chip_pdev structure
    (git-fixes).
  - ASoC: q6apm-lpass-dai: close graph on prepare errors
    (git-fixes).
  - ASoC: rockchip: i2s-tdm: Fix trcm mode by setting clock on
    right mclk (git-fixes).
  - ALSA: seq: Fix missing MSB in MIDI2 SPP conversion (git-fixes).
  - ALSA: hda/realtek: Fix conflicting quirk for PCI SSID 17aa:3820
    (git-fixes).
  - ALSA: seq: Fix missing channel at encoding RPN/NRPN MIDI2
    messages (git-fixes).
  - drm/amdgpu: fix UBSAN warning in kv_dpm.c (stable-fixes).
  - drm/radeon: fix UBSAN warning in kv_dpm.c (stable-fixes).
  - ACPI: EC: Evaluate orphan _REG under EC device (git-fixes).
  - serial: exar: adding missing CTI and Exar PCI ids
    (stable-fixes).
  - serial: imx: Introduce timeout when waiting on transmitter empty
    (stable-fixes).
  - usb: gadget: function: Remove usage of the deprecated
    ida_simple_xx() API (stable-fixes).
  - usb: typec: ucsi_glink: drop special handling for CCI_BUSY
    (stable-fixes).
  - usb: dwc3: pci: Don't set "linux,phy_charger_detect" property
    on Lenovo Yoga Tab2 1380 (stable-fixes).
  - usb: misc: uss720: check for incompatible versions of the
    Belkin F5U002 (stable-fixes).
  - usb: gadget: uvc: configfs: ensure guid to be valid before set
    (stable-fixes).
  - cpufreq: amd-pstate: fix memory leak on CPU EPP exit
    (stable-fixes).
  - ACPI: EC: Install address space handler at the namespace root
    (stable-fixes).
  - PCI/PM: Avoid D3cold for HP Pavilion 17 PC/1972 PCIe Ports
    (stable-fixes).
  - power: supply: cros_usbpd: provide ID table for avoiding
    fallback match (stable-fixes).
  - platform/x86: toshiba_acpi: Add quirk for buttons on Z830
    (stable-fixes).
  - ASoC: Intel: sof-sdw: really remove FOUR_SPEAKER quirk
    (git-fixes).
  - ASoC: Intel: sof_sdw: add quirk for Dell SKU 0C0F
    (stable-fixes).
  - ASoC: Intel: sof_sdw: add JD2 quirk for HP Omen 14
    (stable-fixes).
  - drm/lima: mask irqs in timeout path before hard reset
    (stable-fixes).
  - drm/lima: add mask irq callback to gp and pp (stable-fixes).
  - drm/amd/display: revert Exit idle optimizations before HDCP
    execution (stable-fixes).
  - drm/amd/display: Exit idle optimizations before HDCP execution
    (stable-fixes).
  - Bluetooth: ath3k: Fix multiple issues reported by checkpatch.pl
    (stable-fixes).
  - batman-adv: bypass empty buckets in batadv_purge_orig_ref()
    (stable-fixes).
  - ssb: Fix potential NULL pointer dereference in
    ssb_device_uevent() (stable-fixes).
  - HID: Add quirk for Logitech Casa touchpad (stable-fixes).
  - ACPI: x86: Add PNP_UART1_SKIP quirk for Lenovo Blade2 tablets
    (stable-fixes).
  - crypto: hisilicon/qm - Add the err memory release process to
    qm uninit (stable-fixes).
  - crypto: hisilicon/sec - Fix memory leak for sec resource release
    (stable-fixes).
  - commit bbedf42

++++ python313-core:

  - Update to 3.13.0~b2:
    * Core and Builtins
  - gh-119462: Make sure that invariants of type versioning are
    maintained:
    * Superclasses always have their version number assigned
    before subclasses
    * The version tag is always zero if the tag is not valid.
    * The version tag is always non-zero if the tag is valid.
  - gh-120437: Fix _CHECK_STACK_SPACE optimization problems
    introduced in gh-118322.
  - gh-120722: Correctly set the bytecode position on return
    instructions within lambdas. Patch by Jelle Zijlstra.
  - gh-120367: Fix bug where compiler creates a redundant
    jump during pseudo-op replacement. Can only happen with
    a synthetic AST that has a try on the same line as the
    instruction following the exception handler.
  - gh-113993: Strings interned with sys.intern() are again
    garbage-collected when no longer used, as per the
    documentation. Strings interned with the C function
    PyUnicode_InternInPlace() are still immortal. Internals of
    the string interning mechanism have been changed. This may
    affect performance and identities of str objects.
  - gh-120384: Fix an array out of bounds crash in
    list_ass_subscript, which could be invoked via some
    specificly tailored input: including concurrent
    modification of a list object, where one thread assigns a
    slice and another clears it.
  - gh-120367: Fix crash in compiler on code with redundant
    NOPs and JUMPs which show up after exception handlers are
    moved to the end of the code.
  - gh-120400: Support Linux perf profiler to see Python calls
    on RISC-V architecture.
  - gh-120221: Deliver real signals on Ctrl-C and Ctrl-Z in the
    new REPL. Patch by Pablo Galindo
  - gh-120346: Respect PYTHON_BASIC_REPL when running in
    interative inspect mode (python -i). Patch by Pablo Galindo
  - gh-93691: Fix source locations of instructions generated
    for the iterator of a for statement.
  - gh-120198: Fix a crash when multiple threads read and write
    to the same __class__ of an object concurrently.
  - gh-120298: Fix use-after free in list_richcompare_impl
    which can be invoked via some specificly tailored evil
    input.
  - gh-119666: Fix a compiler crash in the case where two
    comprehensions in class scope both reference __class__.
  - gh-120225: Fix crash in compiler on empty block at end of
    exception handler.
  - gh-119933: Improve SyntaxError messages for invalid
    expressions in a type parameters bound, a type parameter
    constraint tuple or a default type parameter. Patch by
    Bénédikt Tran
  - bpo-24766: Fix handling of doc argument to subclasses of
    property
    * Library
  - gh-119614: Fix truncation of strings with embedded null
    characters in some internal operations in tkinter.
  - gh-120910: When reading installed files from an egg, use
    relative_to(walk_up=True) to honor files installed outside
    of the installation root.
  - gh-101830: Accessing the tkinter object’s string
    representation no longer converts the underlying Tcl object
    to a string on Windows.
  - gh-120811: Fix possible memory leak in
    contextvars.Context.run().
  - gh-120769: Make empty line in pdb repeats the last command
    even when the command is from cmdqueue.
  - gh-120732: Fix name passing to unittest.mock.Mock object
    when using unittest.mock.create_autospec().
  - gh-120683: Fix an error in logging.LogRecord, when the
    integer part of the timestamp is rounded up, while the
    millisecond calculation truncates, causing the log
    timestamp to be wrong by up to 999 ms (affected roughly 1
    in 8 million timestamps).
  - gh-120633: Move scrollbar and remove tear-off menus in
    turtledemo.
  - gh-120541: Improve the prompt in the “less” pager when
    help() is called with non-string argument.
  - gh-120495: Fix incorrect exception handling in Tab
    Nanny. Patch by Wulian233.
  - gh-120381: Correct inspect.ismethoddescriptor() to
    check also for the lack of __delete__(). Patch by Jan
    Kaliszewski.
  - gh-90425: The OS byte in gzip headers is now always set to
    255 when using gzip.compress().
  - gh-120343: Fix column offset reporting for tokens that come
    after multiline f-strings in the tokenize module.
  - gh-119600: Fix unittest.mock.patch() to not read attributes
    of the target when new_callable is set. Patch by Robert
    Collins.
  - gh-114053: Fix erroneous NameError when calling
    inspect.get_annotations() with eval_str=True` on a class
    that made use of PEP 695 type parameters in a module that
    had from __future__ import annotations at the top of the
    file. Patch by Alex Waygood.
  - gh-120268: Prohibit passing None to pure-Python
    datetime.date.fromtimestamp() to achieve consistency with
    C-extension implementation.
  - gh-120244: Fix memory leak in re.sub() when the replacement
    string contains backreferences.
  - gh-120211: Fix tkinter.ttk with Tcl/Tk 9.0.
  - gh-71587: Fix crash in C version of
    datetime.datetime.strptime() when called again on the
    restarted interpreter.
  - gh-120161: datetime no longer crashes in certain complex
    reference cycle situations.
  - gh-119698: Fix symtable.Class.get_methods() and document
    its behaviour. Patch by Bénédikt Tran.
  - gh-120121: Add concurrent.futures.InvalidStateError to
    module’s __all__.
  - gh-119933: Add the symtable.SymbolTableType
    enumeration to represent the possible outputs of the
    symtable.SymbolTable.get_type method. Patch by Bénédikt
    Tran.
  - gh-120108: Fix calling copy.deepcopy() on ast trees
    that have been modified to have references to parent
    nodes. Patch by Jelle Zijlstra.
  - gh-112672: Support building tkinter with Tcl 9.0.
  - gh-65454: unittest.mock.Mock.attach_mock() no longer
    triggers a call to a PropertyMock being attached.
  - gh-81936: help() and showtopic() methods now respect a
    configured output argument to pydoc.Helper and not use the
    pager in such cases. Patch by Enrico Tröger.
  - gh-119577: The DeprecationWarning emitted when testing
    the truth value of an xml.etree.ElementTree.Element now
    describes unconditionally returning True in a future
    version rather than raising an exception in Python 3.14.
  - gh-118908: Limit exposed globals from internal imports and
    definitions on new REPL startup. Patch by Eugene Triguba
    and Pablo Galindo.
  - gh-119506: Fix io.TextIOWrapper.write() method breaks
    internal buffer when the method is called again during
    flushing internal buffer.
    * Build
  - gh-120671: Fix failing configure tests due to a missing
    space when appending to CFLAGS.
  - gh-120602: Correctly handle LLVM installs
    with LLVM_VERSION_SUFFIX when building with
  - -enable-experimental-jit.
  - gh-120326: On Windows, fix build error when --disable-gil
    and --experimental-jit options are combined.
  - gh-120291: Make the python-config shell script compatible
    with non-bash shells.
    * C API
  - gh-120858: PyDict_Next() no longer locks the dictionary in
    the free-threaded build. The locking needs to be done by
    the caller around the entire iteration loop.
  - gh-119344: The critical section API is now public as part
    of the non-limited C API.
  - gh-118789: Add
    PyUnstable_Object_ClearWeakRefsNoCallbacks(), which clears
    weakrefs without calling their callbacks.
  - gh-117511: Make the PyMutex public in the non-limited C
    API.
  - Readjust patches:
  - F00251-change-user-install-location.patch
  - bpo-31046_ensurepip_honours_prefix.patch
  - fix_configure_rst.patch
  - python-3.3.0b1-fix_date_time_compiler.patch
  - subprocess-raise-timeout.patch

++++ liburing:

  - Update to 2.6:
    * Add getsockopt and setsockopt socket commands
    * Add test cases to test/hardlink
    * Man page fixes
    * Add futex support, and test cases
    * Add waitid support, and test cases
    * Add read multishot, and test cases
    * Add support for IORING_SETUP_NO_SQARRAY
    * Use IORING_SETUP_NO_SQARRAY as the default
    * Add support for IORING_OP_FIXED_FD_INSTALL
    * Add io_uring_prep_fixed_fd_install() helper
    * Support for napi busy polling
    * Improve/add test cases
    * Man page fixes
    * Add sample 'proxy' example
  - Remove (they are upstream)
    * test-no-mmap-inval-0-return-is-fine-too.patch
    * test-recv-multishot-wait-for-the-right-amount-of-CQE.patch
  - exclude buf-ring-nommap.t test (crashes)

++++ libzypp:

  - Update soname due to RepoManager refactoring and cleanup.
  - version 17.35.0 (35)

++++ osinfo-db:

  - bsc#1227116 - osinfo still uses deprecated SL-Micro name
    Reverse prior decision to drop the use of "Enterprise" in the
    name of the SUSE Linux Micro product.
    add-slem6.0-support.patch
    Drop add-slm6.0-support.patch

++++ python313:

  - Update to 3.13.0~b2:
    * Core and Builtins
  - gh-119462: Make sure that invariants of type versioning are
    maintained:
    * Superclasses always have their version number assigned
    before subclasses
    * The version tag is always zero if the tag is not valid.
    * The version tag is always non-zero if the tag is valid.
  - gh-120437: Fix _CHECK_STACK_SPACE optimization problems
    introduced in gh-118322.
  - gh-120722: Correctly set the bytecode position on return
    instructions within lambdas. Patch by Jelle Zijlstra.
  - gh-120367: Fix bug where compiler creates a redundant
    jump during pseudo-op replacement. Can only happen with
    a synthetic AST that has a try on the same line as the
    instruction following the exception handler.
  - gh-113993: Strings interned with sys.intern() are again
    garbage-collected when no longer used, as per the
    documentation. Strings interned with the C function
    PyUnicode_InternInPlace() are still immortal. Internals of
    the string interning mechanism have been changed. This may
    affect performance and identities of str objects.
  - gh-120384: Fix an array out of bounds crash in
    list_ass_subscript, which could be invoked via some
    specificly tailored input: including concurrent
    modification of a list object, where one thread assigns a
    slice and another clears it.
  - gh-120367: Fix crash in compiler on code with redundant
    NOPs and JUMPs which show up after exception handlers are
    moved to the end of the code.
  - gh-120400: Support Linux perf profiler to see Python calls
    on RISC-V architecture.
  - gh-120221: Deliver real signals on Ctrl-C and Ctrl-Z in the
    new REPL. Patch by Pablo Galindo
  - gh-120346: Respect PYTHON_BASIC_REPL when running in
    interative inspect mode (python -i). Patch by Pablo Galindo
  - gh-93691: Fix source locations of instructions generated
    for the iterator of a for statement.
  - gh-120198: Fix a crash when multiple threads read and write
    to the same __class__ of an object concurrently.
  - gh-120298: Fix use-after free in list_richcompare_impl
    which can be invoked via some specificly tailored evil
    input.
  - gh-119666: Fix a compiler crash in the case where two
    comprehensions in class scope both reference __class__.
  - gh-120225: Fix crash in compiler on empty block at end of
    exception handler.
  - gh-119933: Improve SyntaxError messages for invalid
    expressions in a type parameters bound, a type parameter
    constraint tuple or a default type parameter. Patch by
    Bénédikt Tran
  - bpo-24766: Fix handling of doc argument to subclasses of
    property
    * Library
  - gh-119614: Fix truncation of strings with embedded null
    characters in some internal operations in tkinter.
  - gh-120910: When reading installed files from an egg, use
    relative_to(walk_up=True) to honor files installed outside
    of the installation root.
  - gh-101830: Accessing the tkinter object’s string
    representation no longer converts the underlying Tcl object
    to a string on Windows.
  - gh-120811: Fix possible memory leak in
    contextvars.Context.run().
  - gh-120769: Make empty line in pdb repeats the last command
    even when the command is from cmdqueue.
  - gh-120732: Fix name passing to unittest.mock.Mock object
    when using unittest.mock.create_autospec().
  - gh-120683: Fix an error in logging.LogRecord, when the
    integer part of the timestamp is rounded up, while the
    millisecond calculation truncates, causing the log
    timestamp to be wrong by up to 999 ms (affected roughly 1
    in 8 million timestamps).
  - gh-120633: Move scrollbar and remove tear-off menus in
    turtledemo.
  - gh-120541: Improve the prompt in the “less” pager when
    help() is called with non-string argument.
  - gh-120495: Fix incorrect exception handling in Tab
    Nanny. Patch by Wulian233.
  - gh-120381: Correct inspect.ismethoddescriptor() to
    check also for the lack of __delete__(). Patch by Jan
    Kaliszewski.
  - gh-90425: The OS byte in gzip headers is now always set to
    255 when using gzip.compress().
  - gh-120343: Fix column offset reporting for tokens that come
    after multiline f-strings in the tokenize module.
  - gh-119600: Fix unittest.mock.patch() to not read attributes
    of the target when new_callable is set. Patch by Robert
    Collins.
  - gh-114053: Fix erroneous NameError when calling
    inspect.get_annotations() with eval_str=True` on a class
    that made use of PEP 695 type parameters in a module that
    had from __future__ import annotations at the top of the
    file. Patch by Alex Waygood.
  - gh-120268: Prohibit passing None to pure-Python
    datetime.date.fromtimestamp() to achieve consistency with
    C-extension implementation.
  - gh-120244: Fix memory leak in re.sub() when the replacement
    string contains backreferences.
  - gh-120211: Fix tkinter.ttk with Tcl/Tk 9.0.
  - gh-71587: Fix crash in C version of
    datetime.datetime.strptime() when called again on the
    restarted interpreter.
  - gh-120161: datetime no longer crashes in certain complex
    reference cycle situations.
  - gh-119698: Fix symtable.Class.get_methods() and document
    its behaviour. Patch by Bénédikt Tran.
  - gh-120121: Add concurrent.futures.InvalidStateError to
    module’s __all__.
  - gh-119933: Add the symtable.SymbolTableType
    enumeration to represent the possible outputs of the
    symtable.SymbolTable.get_type method. Patch by Bénédikt
    Tran.
  - gh-120108: Fix calling copy.deepcopy() on ast trees
    that have been modified to have references to parent
    nodes. Patch by Jelle Zijlstra.
  - gh-112672: Support building tkinter with Tcl 9.0.
  - gh-65454: unittest.mock.Mock.attach_mock() no longer
    triggers a call to a PropertyMock being attached.
  - gh-81936: help() and showtopic() methods now respect a
    configured output argument to pydoc.Helper and not use the
    pager in such cases. Patch by Enrico Tröger.
  - gh-119577: The DeprecationWarning emitted when testing
    the truth value of an xml.etree.ElementTree.Element now
    describes unconditionally returning True in a future
    version rather than raising an exception in Python 3.14.
  - gh-118908: Limit exposed globals from internal imports and
    definitions on new REPL startup. Patch by Eugene Triguba
    and Pablo Galindo.
  - gh-119506: Fix io.TextIOWrapper.write() method breaks
    internal buffer when the method is called again during
    flushing internal buffer.
    * Build
  - gh-120671: Fix failing configure tests due to a missing
    space when appending to CFLAGS.
  - gh-120602: Correctly handle LLVM installs
    with LLVM_VERSION_SUFFIX when building with
  - -enable-experimental-jit.
  - gh-120326: On Windows, fix build error when --disable-gil
    and --experimental-jit options are combined.
  - gh-120291: Make the python-config shell script compatible
    with non-bash shells.
    * C API
  - gh-120858: PyDict_Next() no longer locks the dictionary in
    the free-threaded build. The locking needs to be done by
    the caller around the entire iteration loop.
  - gh-119344: The critical section API is now public as part
    of the non-limited C API.
  - gh-118789: Add
    PyUnstable_Object_ClearWeakRefsNoCallbacks(), which clears
    weakrefs without calling their callbacks.
  - gh-117511: Make the PyMutex public in the non-limited C
    API.
  - Readjust patches:
  - F00251-change-user-install-location.patch
  - bpo-31046_ensurepip_honours_prefix.patch
  - fix_configure_rst.patch
  - python-3.3.0b1-fix_date_time_compiler.patch
  - subprocess-raise-timeout.patch

++++ qemu:

  - Update to latest stable release (9.0.1).
    Full list of backports here:
    https://lore.kernel.org/qemu-devel/1718081053.366429.1238758.nullmailer@tls.msk.ru/
    A selection of them is reported here too:
    Update version for 9.0.1 release
    target/loongarch: fix a wrong print in cpu dump
    ui/sdl2: Allow host to power down screen
    virtio-gpu: fix v2 migration
    target/i386: fix SSE and SSE2 feature check
    target/i386: fix xsave.flat from kvm-unit-tests
    disas/riscv: Decode all of the pmpcfg and pmpaddr CSRs
    riscv, gdbstub.c: fix reg_width in ricsv_gen_dynamic_vector_feature()
    target/riscv/kvm.c: Fix the hart bit setting of AIA
    target/riscv: rvzicbo: Fixup CBO extension register calculation
    target/riscv: do not set mtval2 for non guest-page faults
    target/riscv: prioritize pmp errors in raise_mmu_exception()
    target/riscv: rvv: Remove redudant SEW checking for vector fp narrow/widen instructions
    target/riscv: rvv: Check single width operator for vfncvt.rod.f.f.w
    target/riscv: rvv: Check single width operator for vector fp widen instructions
    target/riscv: rvv: Fix Zvfhmin checking for vfwcvt.f.f.v and vfncvt.f.f.w instructions
    target/riscv/cpu.c: fix Zvkb extension config
    target/riscv: Fix the element agnostic function problem
    target/riscv/kvm: tolerate KVM disable ext errors
    target/riscv/kvm: Fix exposure of Zkr
    hw/intc/riscv_aplic: APLICs should add child earlier than realize
    iotests: test NBD+TLS+iothread
    qio: Inherit follow_coroutine_ctx across TLS
    ...

------------------------------------------------------------------
------------------  2024-6-27  -  Jun 27 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - apply patches below to get GL on s390x working again only on
    s390x, because they break colors during YaST installation
    also on x86_64 platform (QT/GTK using GL backend?) (boo#1226725)

++++ Mesa-drivers:

  - apply patches below to get GL on s390x working again only on
    s390x, because they break colors during YaST installation
    also on x86_64 platform (QT/GTK using GL backend?) (boo#1226725)

++++ gstreamer:

  - Update to version 1.24.5:
    + Highlighted bugfixes:
  - webrtcsink: Support for AV1 via nvav1enc, av1enc or rav1enc
    encoders
  - AV1 RTP payloader/depayloader fixes to work correctly with
    Chrome and Pion WebRTC
  - av1parse, av1dec error handling/robustness improvements
  - av1enc: Handle force-keyunit events properly for WebRTC
  - decodebin3: selection and collection handling improvements
  - hlsdemux2: Various fixes for discontinuities, variant
    switching, playlist updates
  - qml6glsink: fix RGB format support
  - rtspsrc: more control URL handling fixes
  - v4l2src: Interpret V4L2 report of sync loss as video signal
    loss
  - d3d12 encoder, memory and videosink fixes
  - vtdec: more robust error handling, fix regression
  - ndi: support for NDI SDK v6
  - Various bug fixes, memory leak fixes, and other stability and
    reliability improvements
  - Please see https://gstreamer.freedesktop.org/releases/1.24/ for
    changes between 1.24.0 and this version and even more in-depth
    info.
  - Refresh patches with quilt.
  - Drop 0001-Canonicalize-the-library-path-returned-by-dladdr.patch
    and 0001-ptp-Dont-install-test-executable.patch: Fixed upstream.

++++ gstreamer-plugins-base:

  - Update to version 1.24.5:
    + Highlighted bugfixes:
  - webrtcsink: Support for AV1 via nvav1enc, av1enc or rav1enc
    encoders
  - AV1 RTP payloader/depayloader fixes to work correctly with
    Chrome and Pion WebRTC
  - av1parse, av1dec error handling/robustness improvements
  - av1enc: Handle force-keyunit events properly for WebRTC
  - decodebin3: selection and collection handling improvements
  - hlsdemux2: Various fixes for discontinuities, variant
    switching, playlist updates
  - qml6glsink: fix RGB format support
  - rtspsrc: more control URL handling fixes
  - v4l2src: Interpret V4L2 report of sync loss as video signal
    loss
  - d3d12 encoder, memory and videosink fixes
  - vtdec: more robust error handling, fix regression
  - ndi: support for NDI SDK v6
  - Various bug fixes, memory leak fixes, and other stability and
    reliability improvements
  - Please see https://gstreamer.freedesktop.org/releases/1.24/ for
    changes between 1.24.0 and this version and even more in-depth
    info.
  - Refresh patches with quilt.
  - Drop gst-plugins-base-audiobasesink-gap.patch and
    gstreamer-plugins-base-CVE-2024-4453.patch: Fixed upstream.

++++ kernel-default:

  - net/mlx5: Fix MTMP register capability offset in MCAM register
    (git-fixes).
  - bonding: fix oops during rmmod (CVE-2024-39296 bsc#1226989).
  - e1000e: change usleep_range to udelay in PHY mdic access
    (CVE-2024-39296 bsc#1226989).
  - dpll: spec: use proper enum for pin capabilities attribute
    (git-fixes).
  - tools: ynl: fix handling of multiple mcast groups (git-fixes).
  - tools: ynl: don't leak mcast_groups on init error (git-fixes).
  - tools: ynl: make sure we always pass yarg to mnl_cb_run
    (git-fixes).
  - commit 164182f
  - iommu/vt-d: Fix WARN_ON in iommu probe path (git-fixes).
  - iommu/vt-d: Use device rbtree in iopf reporting path
    (bsc#1224751 CVE-2024-35843).
  - iommu/vt-d: Use rbtree to track iommu probed devices
    (git-fixes).
  - commit 5f366a7
  - nilfs2: fix potential kernel bug due to lack of writeback flag
    waiting (bsc#1227066 CVE-2024-37078).
  - commit bd6df7f
  - kABI workaround for FPGA changes (CVE-2024-35247 bsc#1226948
    CVE-2024-36479 bsc#1226949 CVE-2024-37021 bsc#1226950).
  - commit 4b32e86
  - fpga: region: add owner module and take its refcount
    (CVE-2024-35247 bsc#1226948).
  - Refresh patches.suse/fpga-add-kABI-padding.patch.
  - commit 670051c
  - fpga: manager: add owner module and take its refcount
    (CVE-2024-37021 bsc#1226950).
  - Refresh patches.suse/fpga-add-kABI-padding.patch.
  - commit 34a2533
  - fpga: bridge: add owner module and take its refcount
    (CVE-2024-36479 bsc#1226949).
  - commit 545627b
  - Fix build failure on powerpc
    Refresh
    patches.suse/powerpc-uaccess-Use-YZ-asm-constraint-for-ld.patch.
  - commit 4cafc95
  - kabi: Use __iowriteXX_copy_inlined for in-kernel modules (bsc#1226502)
  - commit 54c3656
  - net: hns3: Remove io_stop_wc() calls after __iowrite64_copy() (bsc#1226502)
  - commit 5ea0ed2
  - arm64/io: Provide a WC friendly __iowriteXX_copy() (bsc#1226502)
  - commit a39a193
  - s390: Stop using weak symbols for __iowrite64_copy() (bsc#1226502)
  - commit 4a798a5
  - s390: Implement __iowrite32_copy() (bsc#1226502)
  - commit 80e689b
  - x86: Stop using weak symbols for __iowrite32_copy() (bsc#1226502)
  - commit 894aede
  - net/mlx5: Use mlx5_ipsec_rx_status_destroy to correctly delete
    status rules (CVE-2024-36281 bsc#1226799).
  - commit a7197fd

++++ kernel-rt:

  - net/mlx5: Fix MTMP register capability offset in MCAM register
    (git-fixes).
  - bonding: fix oops during rmmod (CVE-2024-39296 bsc#1226989).
  - e1000e: change usleep_range to udelay in PHY mdic access
    (CVE-2024-39296 bsc#1226989).
  - dpll: spec: use proper enum for pin capabilities attribute
    (git-fixes).
  - tools: ynl: fix handling of multiple mcast groups (git-fixes).
  - tools: ynl: don't leak mcast_groups on init error (git-fixes).
  - tools: ynl: make sure we always pass yarg to mnl_cb_run
    (git-fixes).
  - commit 164182f
  - iommu/vt-d: Fix WARN_ON in iommu probe path (git-fixes).
  - iommu/vt-d: Use device rbtree in iopf reporting path
    (bsc#1224751 CVE-2024-35843).
  - iommu/vt-d: Use rbtree to track iommu probed devices
    (git-fixes).
  - commit 5f366a7
  - nilfs2: fix potential kernel bug due to lack of writeback flag
    waiting (bsc#1227066 CVE-2024-37078).
  - commit bd6df7f
  - kABI workaround for FPGA changes (CVE-2024-35247 bsc#1226948
    CVE-2024-36479 bsc#1226949 CVE-2024-37021 bsc#1226950).
  - commit 4b32e86
  - fpga: region: add owner module and take its refcount
    (CVE-2024-35247 bsc#1226948).
  - Refresh patches.suse/fpga-add-kABI-padding.patch.
  - commit 670051c
  - fpga: manager: add owner module and take its refcount
    (CVE-2024-37021 bsc#1226950).
  - Refresh patches.suse/fpga-add-kABI-padding.patch.
  - commit 34a2533
  - fpga: bridge: add owner module and take its refcount
    (CVE-2024-36479 bsc#1226949).
  - commit 545627b
  - Fix build failure on powerpc
    Refresh
    patches.suse/powerpc-uaccess-Use-YZ-asm-constraint-for-ld.patch.
  - commit 4cafc95
  - kabi: Use __iowriteXX_copy_inlined for in-kernel modules (bsc#1226502)
  - commit 54c3656
  - net: hns3: Remove io_stop_wc() calls after __iowrite64_copy() (bsc#1226502)
  - commit 5ea0ed2
  - arm64/io: Provide a WC friendly __iowriteXX_copy() (bsc#1226502)
  - commit a39a193
  - s390: Stop using weak symbols for __iowrite64_copy() (bsc#1226502)
  - commit 4a798a5
  - s390: Implement __iowrite32_copy() (bsc#1226502)
  - commit 80e689b
  - x86: Stop using weak symbols for __iowrite32_copy() (bsc#1226502)
  - commit 894aede
  - net/mlx5: Use mlx5_ipsec_rx_status_destroy to correctly delete
    status rules (CVE-2024-36281 bsc#1226799).
  - commit a7197fd

++++ libndp:

  - Add libndp-CVE-2024-5564.patch: add a check on the route
    information option length field (bsc#1225771 CVE-2024-5564).

------------------------------------------------------------------
------------------  2024-6-26  -  Jun 26 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - u_egl-gbm-Enable-RGBA-configs.patch,
    u_egl-surfaceless-Enable-RGBA-configs.patch
    * these are needed now after applying previous patch
    u_dri-Fix-BGR-format-exclusion.patch also on other platforms
    than s390x? (boo#1226725)

++++ Mesa-drivers:

  - u_egl-gbm-Enable-RGBA-configs.patch,
    u_egl-surfaceless-Enable-RGBA-configs.patch
    * these are needed now after applying previous patch
    u_dri-Fix-BGR-format-exclusion.patch also on other platforms
    than s390x? (boo#1226725)

++++ lvm2-device-mapper:

  - add rpm dependency in spec file for aligning new DM udev rules (bsc#1225783)
    * update lvm2.spec for multipath-tools

++++ python-kiwi:

  - Add rd.kiwi.oem.force_resize boot option
    Forces the disk resize process on an OEM disk image.
    If set, no sanity check for unpartitioned/free space
    is performed and also an eventually configured
    <oem-resize-once> configuration from the image description
    will not be taken into account. This Fixes bsc#1224389

++++ kernel-default:

  - ceph: switch to use cap_delay_lock for the unlink delay list
    (bsc#1226022).
  - ceph: break the check delayed cap loop every 5s (bsc#1226022).
  - ceph: add ceph_cap_unlink_work to fire check_caps() immediately
    (bsc#1226022).
  - ceph: always queue a writeback when revoking the Fb caps
    (bsc#1226022).
  - ceph: always check dir caps asynchronously (bsc#1226022).
  - commit 7eb372a
  - arm64: mm: Don't remap pgtables for allocate vs populate
    (jsc#PED-8688).
  - arm64: mm: Batch dsb and isb when populating pgtables
    (jsc#PED-8688).
  - arm64: mm: Don't remap pgtables per-cont(pte|pmd) block
    (jsc#PED-8688).
  - commit fdec960
  - epoll: be better about file lifetimes (bsc#1226610
    CVE-2024-38580).
  - commit 4ff3c13
  - null_blk: Fix return value of nullb_device_power_store()
    (bsc#1226841 CVE-2024-36478).
  - commit f213a2a
  - f2fs: multidev: fix to recognize valid zero block address (bsc#1226879, CVE-2024-38636).
  - commit ec1ded3
  - s390/cpacf: Make use of invalid opcode produce a link error
    (git-fixes bsc#1227072).
  - commit 24c76d1
  - s390/ap: Fix crash in AP internal function modify_bitmap()
    (CVE-2024-38661 bsc#1226996 git-fixes).
  - commit 456a41d
  - selftests/bpf: Add sockopt case to verify prog_type (bsc#1226789
    CVE-2024-38564).
  - selftests/bpf: Extend sockopt tests to use BPF_LINK_CREATE
    (bsc#1226789 CVE-2024-38564).
  - bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in
    BPF_LINK_CREATE (bsc#1226789 CVE-2024-38564).
  - commit 2f12314
  - bpf: Fix verifier assumptions about socket->sk (bsc#1226790
    CVE-2024-38566).
  - commit dc586b3

++++ kernel-firmware-all:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-amdgpu:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-ath10k:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-ath11k:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-ath12k:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-atheros:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-bluetooth:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-bnx2:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-brcm:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-chelsio:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-dpaa2:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-i915:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-intel:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-iwlwifi:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-liquidio:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-marvell:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-media:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-mediatek:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-mellanox:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-mwifiex:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-network:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-nfp:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-nvidia:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-platform:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-prestera:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-qcom:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-qlogic:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-radeon:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-realtek:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-serial:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-sound:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-ti:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-ueagle:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-firmware-usb-network:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ kernel-rt:

  - ceph: switch to use cap_delay_lock for the unlink delay list
    (bsc#1226022).
  - ceph: break the check delayed cap loop every 5s (bsc#1226022).
  - ceph: add ceph_cap_unlink_work to fire check_caps() immediately
    (bsc#1226022).
  - ceph: always queue a writeback when revoking the Fb caps
    (bsc#1226022).
  - ceph: always check dir caps asynchronously (bsc#1226022).
  - commit 7eb372a
  - arm64: mm: Don't remap pgtables for allocate vs populate
    (jsc#PED-8688).
  - arm64: mm: Batch dsb and isb when populating pgtables
    (jsc#PED-8688).
  - arm64: mm: Don't remap pgtables per-cont(pte|pmd) block
    (jsc#PED-8688).
  - commit fdec960
  - epoll: be better about file lifetimes (bsc#1226610
    CVE-2024-38580).
  - commit 4ff3c13
  - null_blk: Fix return value of nullb_device_power_store()
    (bsc#1226841 CVE-2024-36478).
  - commit f213a2a
  - f2fs: multidev: fix to recognize valid zero block address (bsc#1226879, CVE-2024-38636).
  - commit ec1ded3
  - s390/cpacf: Make use of invalid opcode produce a link error
    (git-fixes bsc#1227072).
  - commit 24c76d1
  - s390/ap: Fix crash in AP internal function modify_bitmap()
    (CVE-2024-38661 bsc#1226996 git-fixes).
  - commit 456a41d
  - selftests/bpf: Add sockopt case to verify prog_type (bsc#1226789
    CVE-2024-38564).
  - selftests/bpf: Extend sockopt tests to use BPF_LINK_CREATE
    (bsc#1226789 CVE-2024-38564).
  - bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in
    BPF_LINK_CREATE (bsc#1226789 CVE-2024-38564).
  - commit 2f12314
  - bpf: Fix verifier assumptions about socket->sk (bsc#1226790
    CVE-2024-38566).
  - commit dc586b3

++++ libdrm:

  - update to 2.4.122
    * fix FTBS on FreeBSD (or non-Linux in general)
    * freedreno: fix FTBS on non-Linux platforms (unused header)
    * etnaviv: fix FTBS on undefined linux/* headers on non-Linux platforms.
    * ci: upgrade debian container to bookworm
    * ci: upgrade FreeBSD VM to 14.1
    * Remove libm in libdrm dependencies
    * Sync headers with drm-next

++++ lvm2:

  - add rpm dependency in spec file for aligning new DM udev rules (bsc#1225783)
    * update lvm2.spec for multipath-tools

++++ ucode-amd:

  - Update to version 20240622 (git commit 7d931f8afa51):
    * linux-firmware: mediatek: Update MT8173 VPU firmware to v1.2.0
    * qcom: Add AIC100 firmware files

++++ zypper:

  - Let_readline_abort_on_Ctrl-C (bsc#1226493)
  - packages: add '--system' to show @System packages (bsc#222971)
  - version 1.14.74

------------------------------------------------------------------
------------------  2024-6-25  -  Jun 25 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - u_dri-Fix-BGR-format-exclusion.patch
    * fixes glxinfo/eglxinfo on s390x (boo#1226725, comment#6)

++++ Mesa-drivers:

  - u_dri-Fix-BGR-format-exclusion.patch
    * fixes glxinfo/eglxinfo on s390x (boo#1226725, comment#6)

++++ python-kiwi:

  - Fixed leap integration tests
    For whatever reason procps is not longer pulled in by the
    core dependencies. Thus we have to explicitly request it

++++ kernel-default:

  - scsi: qedf: Ensure the copied buf is NUL terminated (bsc#1226758
    CVE-2024-38559).
  - scsi: bfa: Ensure the copied buf is NUL terminated (bsc#1226786
    CVE-2024-38560).
  - scsi: bnx2fc: Remove spin_lock_bh while releasing resources
    after upload (bsc#1224767 CVE-2024-36919).
  - commit 3cabc93
  - nvme: do not retry authentication failures (bsc#1186716).
  - nvme-fabrics: short-circuit reconnect retries (bsc#1186716).
  - nvme: return kernel error codes for admin queue connect
    (bsc#1186716).
  - nvmet: return DHCHAP status codes from nvmet_setup_auth()
    (bsc#1186716).
  - nvmet: lock config semaphore when accessing DH-HMAC-CHAP key
    (bsc#1186716).
  - commit ac2b954
  - net: sched: sch_multiq: fix possible OOB write in multiq_tune()
    (CVE-2024-36978 bsc#1226514).
  - commit 3b6fd26
  - nvmet: prevent sprintf() overflow in nvmet_subsys_nsid_exists()
    (git-fixes).
  - commit 556ea4a
  - null_blk: fix null-ptr-dereference while configuring 'power'
    and 'submit_queues' (bsc#1226841 CVE-2024-36478).
  - commit d0b4b2a
  - block: fix overflow in blk_ioctl_discard() (bsc#1225770
    CVE-2024-36917).
  - commit bbdd816
  - mm: Avoid overflows in dirty throttling logic (bsc#1222364
    CVE-2024-26720).
  - commit 77e301c
  - net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
    (CVE-2024-36974 bsc#1226519).
  - commit f911add
  - PCI: Clear Secondary Status errors after enumeration (bsc#1226928)
  - commit 606f4e7
  - nvmet-passthru: propagate status from id override functions
    (git-fixes).
  - nvme: fix nvme_pr_* status code parsing (git-fixes).
  - nvmet: fix nvme status code when namespace is disabled
    (git-fixes).
  - nvmet-tcp: fix possible memory leak when tearing down a
    controller (git-fixes).
  - nvmet-auth: replace pr_debug() with pr_err() to report an error
    (git-fixes).
  - nvmet-auth: return the error code to the nvmet_auth_host_hash()
    callers (git-fixes).
  - nvme: find numa distance only if controller has valid numa id
    (git-fixes).
  - commit 3709ef4
  - nvme: cancel pending I/O if nvme controller is in terminal state
    (bsc#1226503).
    Refresh:
  - patches.suse/nvme-multipath-fix-io-accounting-on-failover.patch
  - commit 7dbf1d4
  - stm class: Fix a double free in stm_register_device()
    (CVE-2024-38627 bsc#1226857).
  - commit ef5c589
  - Input: ili210x - fix ili251x_read_touch_data() return value
    (git-fixes).
  - pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
    (git-fixes).
  - pinctrl: rockchip: use dedicated pinctrl type for RK3328
    (git-fixes).
  - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
    (git-fixes).
  - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
    (git-fixes).
  - pinctrl: fix deadlock in create_pinctrl() when handling
  - EPROBE_DEFER (git-fixes).
  - pinctrl: qcom: spmi-gpio: drop broken pm8008 support
    (git-fixes).
  - commit a1b46e3
  - drivers/perf: hisi: hns3: Actually use
    devm_add_action_or_reset() (CVE-2024-38603 bsc#1226842).
  - commit 4db6ba6
  - NFSv4.x: by default serialize open/close operations (bsc#1223863 bsc#1227362).
  - commit 6ed2498

++++ kernel-rt:

  - scsi: qedf: Ensure the copied buf is NUL terminated (bsc#1226758
    CVE-2024-38559).
  - scsi: bfa: Ensure the copied buf is NUL terminated (bsc#1226786
    CVE-2024-38560).
  - scsi: bnx2fc: Remove spin_lock_bh while releasing resources
    after upload (bsc#1224767 CVE-2024-36919).
  - commit 3cabc93
  - nvme: do not retry authentication failures (bsc#1186716).
  - nvme-fabrics: short-circuit reconnect retries (bsc#1186716).
  - nvme: return kernel error codes for admin queue connect
    (bsc#1186716).
  - nvmet: return DHCHAP status codes from nvmet_setup_auth()
    (bsc#1186716).
  - nvmet: lock config semaphore when accessing DH-HMAC-CHAP key
    (bsc#1186716).
  - commit ac2b954
  - net: sched: sch_multiq: fix possible OOB write in multiq_tune()
    (CVE-2024-36978 bsc#1226514).
  - commit 3b6fd26
  - nvmet: prevent sprintf() overflow in nvmet_subsys_nsid_exists()
    (git-fixes).
  - commit 556ea4a
  - null_blk: fix null-ptr-dereference while configuring 'power'
    and 'submit_queues' (bsc#1226841 CVE-2024-36478).
  - commit d0b4b2a
  - block: fix overflow in blk_ioctl_discard() (bsc#1225770
    CVE-2024-36917).
  - commit bbdd816
  - mm: Avoid overflows in dirty throttling logic (bsc#1222364
    CVE-2024-26720).
  - commit 77e301c
  - net/sched: taprio: always validate TCA_TAPRIO_ATTR_PRIOMAP
    (CVE-2024-36974 bsc#1226519).
  - commit f911add
  - PCI: Clear Secondary Status errors after enumeration (bsc#1226928)
  - commit 606f4e7
  - nvmet-passthru: propagate status from id override functions
    (git-fixes).
  - nvme: fix nvme_pr_* status code parsing (git-fixes).
  - nvmet: fix nvme status code when namespace is disabled
    (git-fixes).
  - nvmet-tcp: fix possible memory leak when tearing down a
    controller (git-fixes).
  - nvmet-auth: replace pr_debug() with pr_err() to report an error
    (git-fixes).
  - nvmet-auth: return the error code to the nvmet_auth_host_hash()
    callers (git-fixes).
  - nvme: find numa distance only if controller has valid numa id
    (git-fixes).
  - commit 3709ef4
  - nvme: cancel pending I/O if nvme controller is in terminal state
    (bsc#1226503).
    Refresh:
  - patches.suse/nvme-multipath-fix-io-accounting-on-failover.patch
  - commit 7dbf1d4
  - stm class: Fix a double free in stm_register_device()
    (CVE-2024-38627 bsc#1226857).
  - commit ef5c589
  - Input: ili210x - fix ili251x_read_touch_data() return value
    (git-fixes).
  - pinctrl: rockchip: fix pinmux reset in rockchip_pmx_set
    (git-fixes).
  - pinctrl: rockchip: use dedicated pinctrl type for RK3328
    (git-fixes).
  - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO3-B pins
    (git-fixes).
  - pinctrl: rockchip: fix pinmux bits for RK3328 GPIO2-B pins
    (git-fixes).
  - pinctrl: fix deadlock in create_pinctrl() when handling
  - EPROBE_DEFER (git-fixes).
  - pinctrl: qcom: spmi-gpio: drop broken pm8008 support
    (git-fixes).
  - commit a1b46e3
  - drivers/perf: hisi: hns3: Actually use
    devm_add_action_or_reset() (CVE-2024-38603 bsc#1226842).
  - commit 4db6ba6
  - NFSv4.x: by default serialize open/close operations (bsc#1223863 bsc#1227362).
  - commit 6ed2498

++++ multipath-tools:

  - Update to version 0.9.9+90+suse.f1d2f20:
    * Fix unit tests on Tumbleweed/armv7l
  - Update to 0.9.9 upstream (see NEWS.md for details)
    * Update udev rules to be compliant with device-mapper udev
    rules update in LVM2 >= 2.03.24.
    * Limit real-time scheduling priority to 10 by default. This
    can now be configured in multipathd.service using "LimitRTPRIO="
    * Set max_sectors_kb only on map creation, or when a new path
    is added, to avoid IO errors
    * The configuration option "flush_on_last_del" now takes the
    values "always" (="yes"), "unused" (="no"), and "never". "yes"
    and "no" are still supported
    * Add wildcard %k for max_sectors_kb for CLI commands like
    "multipath show {paths,maps} format"
    * Accept WWID value in CLI commands that take a map name, like
    "resize map $map"
    * Removed support for CLI wildcards for pathgroups, which were
    not function anyway.
    * Fix map failure count for no_path_retry > 0

++++ spirv-tools:

  - Update to release 2024.3
    * Optimizer:
    * Do not fold MUL and ADDs to generate FMAs
    * Add AliasedPointer decoration
    * Add support for vulkan-shader-profiler external passes
    * Validator:
    * Add support for OpExtInstWithForwardRefs
    * Disassembler:
    * Add decorations to comments
    * Add --nested-indent and --reorder-blocks

++++ rdma-core:

  - Update to rdma-core v52.0
  - No release notes available
  - Add upstream patch Added-suffix-libdrm-to-CMakeLists.txt-for-drm.patch
    to fix libdrm detection.

++++ openSUSE-repos-LeapMicro:

  - Update to version 20240625.f75b6e5:
    * initial leap 16 repoindex
    * Update README.md
  - Handle Leap 16 similar to LEAPM 5 vs 6

++++ passt:

  - Update to version 20240624.1ee2eca:
    * udp: Reduce scope of rport in udp_invert_portmap()
    * Revert "udp: Make rport calculation more local"
    * log: Don't report syslog failures to stderr after initialisation
    * conf, passt: Don't call __openlog() if a log file is used
    * treewide: Replace strerror() calls
    * treewide: Replace perror() calls with calls to logging functions
    * log: Add _perror() logging function variants
    * log, passt: Always print to stderr before initialisation is complete
    * conf, log: Instead of abusing log levels, add log_conf_parsed flag
    * conf, passt: Make --stderr do nothing, and deprecate it
    * conf, passt: Don't try to log to stderr after we close it
    * conf: Accept duplicate and conflicting options, the last one wins
    * netlink: Strip nexthop identifiers when duplicating routes
    * passt.1, qrap.1: align license description with SPDX identifier
    * netlink: Ignore EHOSTUNREACH failures when duplicating routes
    * netlink: With no default route, pick the first interface with a route
    * tcp: Don't rely on bind() to fail to decide that connection target is valid
    * siphash: Remove stale prototypes
    * udp: Move management of udp[46]_localname into udp_splice_send()
    * udp: Rework how we divide queued datagrams between sending methods
    * udp: Fold checking of splice flag into udp_mmh_splice_port()
    * util: Split construction of bind socket address from the rest of sock_l4()
    * tap: use in->buf_size rather than sizeof(pkt_buf)
    * iov: remove iov_copy()
    * vhost-user: compare mode MODE_PASTA and not MODE_PASST
    * udp: rename udp_sock_handler() to udp_buf_sock_handler()
    * udp: refactor UDP header update functions
    * tap: refactor packets handling functions
    * tcp: move buffers management functions to their own file
    * tcp: extract buffer management from tcp_send_flag()
    * cppcheck: Suppress constParameterCallback errors

------------------------------------------------------------------
------------------  2024-6-24  -  Jun 24 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Update to version 1.48.2:
    + Support matching a OVS system interface by MAC address.
    + Fix port reactivation when the controller is reactivating.
    + Save connection timestamps when shutting down, so that the
    right connection autoactivates after restart.
    + Fix handling of VPN secrets for 2-factor authentication.

++++ containerd:

  - Revert noarch for devel subpackage for SLE 15
    Switching to noarch causes issues on SLES maintenance updates, reverting it
    fixes our image builds

++++ docker:

  - Rebase patches:
    * 0001-SECRETS-daemon-allow-directory-creation-in-run-secre.patch
    * 0002-SECRETS-SUSE-implement-SUSE-container-secrets.patch
    * 0003-BUILD-SLE12-revert-graphdriver-btrfs-use-kernel-UAPI.patch
    * 0004-bsc1073877-apparmor-clobber-docker-default-profile-o.patch
    * 0005-SLE12-revert-apparmor-remove-version-conditionals-fr.patch
  - Fix BuildKit's symlink resolution logic to correctly handle non-lexical
    symlinks. Backport of <https://github.com/moby/buildkit/pull/4896> and
    <https://github.com/moby/buildkit/pull/5060>. bsc#1221916
    + 0006-bsc1221916-update-to-patched-buildkit-version-to-fix.patch
  - Write volume options atomically so sudden system crashes won't result in
    future Docker starts failing due to empty files. Backport of
    <https://github.com/moby/moby/pull/48034>. bsc#1214855
    + 0007-bsc1214855-volume-use-AtomicWriteFile-to-save-volume.patch

++++ docker-compose:

  - Update to version 2.28.1:
    * Remove `console.Terminal` check and use `IsTerminal` from
    `streams.Out`

++++ kernel-default:

  - work around gcc bugs with 'asm goto' with outputs (git-fixes).
  - Refresh
    patches.suse/powerpc-uaccess-Fix-build-errors-seen-with-GCC-13-14.patch.
  - Refresh
    patches.suse/powerpc-uaccess-Use-YZ-asm-constraint-for-ld.patch.
  - commit eac0f3f
  - x86/asm: Remove the __iomem annotation of movdir64b()'s dst argument (git-fixes).
  - commit 8a8a749
  - x86/tdx: Preserve shared bit on mprotect() (git-fixes).
  - commit ea4a8f6
  - x86/sev: Fix position dependent variable references in startup code (git-fixes).
  - Refresh
    patches.suse/x86-coco-Require-seeding-RNG-with-RDRAND-on-CoCo-systems.patch.
  - commit 2efccd0
  - x86/mce: Mark fatal MCE's page as poison to avoid panic in the kdump  kernel (git-fixes).
  - Refresh
    patches.suse/x86-mce-Differentiate-real-hardware-MCs-from-TDX-erratum-o.patch.
  - commit d75f0fd
  - x86/kexec: Fix bug with call depth tracking (git-fixes).
  - commit 926155d
  - x86/nmi: Drop unused declaration of proc_nmi_enabled() (git-fixes).
  - commit 3441c2e
  - x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map (git-fixes).
  - commit 820085a
  - x86/uaccess: Fix missed zeroing of ia32 u64 get_user() range checking (git-fixes).
  - commit 1c4403a
  - net: fec: remove .ndo_poll_controller to avoid deadlocks
    (CVE-2024-38553 bsc#1226744).
  - net/mlx5: Discard command completions in internal error
    (CVE-2024-38555 bsc#1226607).
  - net/mlx5: Add a timeout to acquire the command queue semaphore
    (CVE-2024-38556 bsc#1226774).
  - net/mlx5: Reload only IB representors upon lag disable/enable
    (CVE-2024-38557 bsc#1226781).
  - net/mlx5e: Fix netif state handling (CVE-2024-38608
    bsc#1226746).
  - eth: sungem: remove .ndo_poll_controller to avoid deadlocks
    (CVE-2024-38597 bsc#1226749).
  - net: stmmac: move the EST lock to struct stmmac_priv
    (CVE-2024-38594 bsc#1226734).
  - commit d6f20aa
  - i2c: ocores: set IACK bit after core is enabled (git-fixes).
  - commit dc04936

++++ kernel-rt:

  - work around gcc bugs with 'asm goto' with outputs (git-fixes).
  - Refresh
    patches.suse/powerpc-uaccess-Fix-build-errors-seen-with-GCC-13-14.patch.
  - Refresh
    patches.suse/powerpc-uaccess-Use-YZ-asm-constraint-for-ld.patch.
  - commit eac0f3f
  - x86/asm: Remove the __iomem annotation of movdir64b()'s dst argument (git-fixes).
  - commit 8a8a749
  - x86/tdx: Preserve shared bit on mprotect() (git-fixes).
  - commit ea4a8f6
  - x86/sev: Fix position dependent variable references in startup code (git-fixes).
  - Refresh
    patches.suse/x86-coco-Require-seeding-RNG-with-RDRAND-on-CoCo-systems.patch.
  - commit 2efccd0
  - x86/mce: Mark fatal MCE's page as poison to avoid panic in the kdump  kernel (git-fixes).
  - Refresh
    patches.suse/x86-mce-Differentiate-real-hardware-MCs-from-TDX-erratum-o.patch.
  - commit d75f0fd
  - x86/kexec: Fix bug with call depth tracking (git-fixes).
  - commit 926155d
  - x86/nmi: Drop unused declaration of proc_nmi_enabled() (git-fixes).
  - commit 3441c2e
  - x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map (git-fixes).
  - commit 820085a
  - x86/uaccess: Fix missed zeroing of ia32 u64 get_user() range checking (git-fixes).
  - commit 1c4403a
  - net: fec: remove .ndo_poll_controller to avoid deadlocks
    (CVE-2024-38553 bsc#1226744).
  - net/mlx5: Discard command completions in internal error
    (CVE-2024-38555 bsc#1226607).
  - net/mlx5: Add a timeout to acquire the command queue semaphore
    (CVE-2024-38556 bsc#1226774).
  - net/mlx5: Reload only IB representors upon lag disable/enable
    (CVE-2024-38557 bsc#1226781).
  - net/mlx5e: Fix netif state handling (CVE-2024-38608
    bsc#1226746).
  - eth: sungem: remove .ndo_poll_controller to avoid deadlocks
    (CVE-2024-38597 bsc#1226749).
  - net: stmmac: move the EST lock to struct stmmac_priv
    (CVE-2024-38594 bsc#1226734).
  - commit d6f20aa
  - i2c: ocores: set IACK bit after core is enabled (git-fixes).
  - commit dc04936

++++ libcontainers-common:

  - While migrating config files from /etc/containers/ to /usr/share/containers/,
    preserve config files *if* modified by the user (fixes bsc#1226825).
  - update storage.conf & containers.conf to latest versions from upstream
    The only functional changes are in storage.conf:
    * change storage.options.pull_options.enable_partial_images from false to true
    * change storage.options.overlay.mount_options from `mountopt =
    "nodev,metacopy=on"` to `mountopt = "nodev"`
  - add download_files service to fetch the latest config on `osc service mr`
  - add storage-conf-prio-list.patch that modifies the upstream storage.conf to
    add our storage driver priority list

++++ ncurses:

  - Add ncurses patch 20240622
    + improve test/gdc.c (patch by Branden Robinson).
    + improve formatting/style of manpages (patches by Branden Robinson).
    + adjust naming of mingw *-config scripts to match the pkg-config names
    + widen pattern in pc/*-config scripts to disallow more linker options
    + add --cflags-only-I and --cflags-only-other options to
    misc/ncurses-config.in
    + revert change to CF_BUILD_CC macro (report by Vassili Courzakis,
    cf: 20240518).
  - Port patch ncurses-6.4.dif
  - Port edit.sed script to new ncurses-config

++++ shadow:

  - bsc#1226850: Drop incorrect econf patch (until time to fix it)
    Drop shadow-4.16.0-econf.patch

++++ systemd:

  - Don't automatically clean unmodified config files up (bsc#1226415)
    Relying on the presence of .rpmsave for detecting unmodified main config files
    couldn't work as it created a time window in which some of the systemd
    services were restarted with no config file. That had the bad side effect to
    restart them with the upstream defaults, ignoring any user's customization.

++++ libzypp:

  - Workaround broken libsolv-tools-base requirements (fixes
    openSUSE/zypper#551)
  - Strip ssl_clientkey from repo urls (bsc#1226030)
  - Remove protobuf build dependency.
  - Lazily attach medium during refresh workflows (bsc#1223094)
  - Refactor RepoManager and add Service workflows.
  - version 17.34.2 (34)

++++ openSUSE-repos-LeapMicro:

  - Ensure that refresh-services / refs is called after addservice
  - Update to version 20240621.6fd1ef2:
    * Update README.md
    * use osc service mr for update
    * Disable source and debug repos by default for Tumbleweed ports
    * Use cdn.opensuse.org for Tumbleweed ports

++++ suse-module-tools:

  - Update to version 16.0.45:
    * udevrules: activate CPUs on hotplug for s390, too (bsc#1224400)

------------------------------------------------------------------
------------------  2024-6-23  -  Jun 23 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Specfile cleanup
    * copy rust crate sources into subprojects folder
    * remove supplements. nvk is still new
  - Specfile changes for Rust crates. Also added this to README-suse-maintenance.md
    * Since Rust crates are not installed or discouraged to be installed
    as system dependencies because of the maintenance burden of being the
    next crates.io, we will have to download the following crates as vendored
    dependencies. Hence, do not be scared if the dependencies are done like
    this To check new crates or update the versions, just go to the subprojects
    folder and run `grep -r crates .` then set versions appropriately.

++++ Mesa-drivers:

  - Specfile cleanup
    * copy rust crate sources into subprojects folder
    * remove supplements. nvk is still new
  - Specfile changes for Rust crates. Also added this to README-suse-maintenance.md
    * Since Rust crates are not installed or discouraged to be installed
    as system dependencies because of the maintenance burden of being the
    next crates.io, we will have to download the following crates as vendored
    dependencies. Hence, do not be scared if the dependencies are done like
    this To check new crates or update the versions, just go to the subprojects
    folder and run `grep -r crates .` then set versions appropriately.

++++ kernel-default:

  - regulator: bd71815: fix ramp values (git-fixes).
  - regulator: core: Fix modpost error "regulator_get_regmap"
    undefined (git-fixes).
  - spi: stm32: qspi: Clamp stm32_qspi_get_mode() output to
    CCR_BUSWIDTH_4 (git-fixes).
  - spi: stm32: qspi: Fix dual flash mode sanity test in
    stm32_qspi_setup() (git-fixes).
  - firmware: psci: Fix return value from psci_system_suspend()
    (git-fixes).
  - commit 5c1d1d7

++++ kernel-rt:

  - regulator: bd71815: fix ramp values (git-fixes).
  - regulator: core: Fix modpost error "regulator_get_regmap"
    undefined (git-fixes).
  - spi: stm32: qspi: Clamp stm32_qspi_get_mode() output to
    CCR_BUSWIDTH_4 (git-fixes).
  - spi: stm32: qspi: Fix dual flash mode sanity test in
    stm32_qspi_setup() (git-fixes).
  - firmware: psci: Fix return value from psci_system_suspend()
    (git-fixes).
  - commit 5c1d1d7

++++ vim:

  - Update to 9.1.0512:
    * Mode message for spell completion doesn't match allowed keys
    * CursorMovedC triggered wrongly with setcmdpos()
    * update runtime files
    * CI: test_gettext fails on MacOS14 + MSVC Win
    * not possible to translate Vim script messages
    * termdebug plugin can be further improved
    * add gomod filetype plugin
    * hard to detect cursor movement in the command line
    * Optionally highlight parameterised types
    * filetype: .envrc & .prettierignore not recognized
    * filetype: Faust files are not recognized
    * inner-tag textobject confused about ">" in attributes
    * cannot use fuzzy keyword completion
    * Remove the group exclusion list from @javaTop
    * wrong return type for execute() function
    * MS-Windows: too much legacy code
    * too complicated mapping restore in termdebug
    * simplify mapping
    * cannot switch buffer in a popup
    * MS-Windows: doesn't handle symlinks properly
    * getcmdcompltype() interferes with cmdline completion
    * termdebug can be further improved
    * update htmldjango detection
    * Improve Turkish documentation
    * include a simple csv filetype and syntax plugin
    * include the the simple nohlsearch package
    * matched text is highlighted case-sensitively
    * Matched text isn't highlighted in cmdline pum
    * Fix typos in several documents
    * clarify when text properties are cleared
    * improve the vim-shebang example
    * revert unintended formatting changes for termdebug
    * Add a config variable for commonly used compiler options
    * Wrong matched text highlighted in pum with 'rightleft'
    * bump length of character references in syntax script
    * properly check mapping variables using null_dict
    * fix KdlIndent and kdlComment in indent script
    * Test for patch 9.1.0489 doesn't fail without the fix
    * Fold multi-line comments with the syntax kind of &fdm
    * using wrong type for PlaceSign()
    * filetype: Vim-script files not detected by shebang line
    * revert unintended change to zip#Write()
    * add another tag for vim-shebang feature
    * Cmdline pum doesn't work properly with 'rightleft'
    * minor style problems with patch 9.1.0487
    * default completion may break with fuzzy
    * Wrong padding for pum "kind" with 'rightleft'
    * Update base-syntax, match shebang lines
    * MS-Windows: handle files with spaces properly
    * Restore HTML syntax file tests
    * completed item not update on fuzzy completion
    * filetype: Snakemake files are not recognized
    * make TermDebugSendCommand() a global function again
    * close all buffers in the same way
    * Matched text shouldn't be highlighted in "kind" and "menu"
    * fix wrong helptag for :defer
    * Update base-syntax, match :sleep arg
    * include Georgian keymap
    * Sorting of completeopt+=fuzzy is not stable
    * correctly test for windows in NetrwGlob()
    * glob() on windows fails with [] in directory name
    * rewrite mkdir() doc and simplify {flags} meaning
    * glob() not sufficiently tested
    * update return type for job_info()
    * termdebug plugin needs more love
    * correct return types for job_start() and job_status()
    * Update base-syntax, match :catch and :throw args
    * Include element values in non-marker annotations
    * Vim9: term_getjob() throws an exception on error
    * fuzzy string matching executed when not needed
    * fuzzy_match_str_with_pos() does unnecessary list operations
    * restore description of "$" in col() and virtcol()
    * deduplicate getpos(), line(), col(), virtcol()
    * Update g:vimsyn_comment_strings dump file tests
    * Use string interpolation instead of string concat
    * potential deref of NULL pointer in fuzzy_match_str_with_pos
    * block_editing errors out when using <enter>
    * Update base-syntax, configurable comment string highlighting
    * fix typos in syntax.txt
    * Cannot see matched text in popup menu
    * Update base-syntax, match multiline continued comments
    * clarify documentation for "v" position at line()
    * cmod_split modifier is always reset in term_start()
    * remove line-continuation characters
    * use shiftwidth() instead of &tabstop in indent script
    * Remove orphaned screen dump files
    * include syntax, indent and ftplugin files
    * CI: Test_ColonEight() fails on github runners
    * add missing Enabled field in syntax script
    * basic svelte ftplugin file
    * term_start() does not clear vertical modifier
    * fix mousemodel restoration by comparing against null_string
    * Added definitions of Vim scripts and plugins
    * Exclude lambda expressions from _when_ _switch-case_ label clauses
    * Fix saved_mousemodel check
    * Inconsistencies between functions for option flags
    * Crash when using autocmd_get() after removing event inside autocmd
    * Fix small style issues
    * add return type info for Vim function descriptions
    * Update Italian Vim manpage
    * disable the q mapping
    * Change 'cms' for C++ to '// %s'
    * fix type mismatch error
    * Fix wrong email address
    * convert termdebug plugin to Vim9 script

------------------------------------------------------------------
------------------  2024-6-22  -  Jun 22 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - RDMA/mlx5: Add check for srq max_sge attribute (git-fixes)
  - commit 5a7a44c
  - RDMA/mlx5: Fix unwind flow as part of mlx5_ib_stage_init_init (git-fixes)
  - commit a73b3cb
  - RDMA/mlx5: Ensure created mkeys always have a populated rb_key (git-fixes)
  - commit 194920a
  - RDMA/mlx5: Follow rb_key.ats when creating new mkeys (git-fixes)
  - commit 93d4abb
  - RDMA/mlx5: Remove extra unlock on error path (git-fixes)
  - commit 662ecd8
  - RDMA/rxe: Fix responder length checking for UD request packets (git-fixes)
  - commit 77ecb50
  - RDMA/rxe: Fix data copy for IB_SEND_INLINE (git-fixes)
  - commit 9ec1cd9
  - RDMA/bnxt_re: Fix the max msix vectors macro (git-fixes)
  - commit 19f32fe
  - drm/i915/mso: using joiner is not possible with eDP MSO
    (git-fixes).
  - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14AHP9
    (stable-fixes).
  - ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your
    kernel is fine." (git-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Return error in case
    of invalid efuse data (git-fixes).
  - dmaengine: ioatdma: Fix missing kmem_cache_destroy()
    (git-fixes).
  - dmaengine: ioatdma: Fix kmemleak in ioat_pci_probe()
    (git-fixes).
  - dmaengine: ioatdma: Fix error path in ioat3_dma_probe()
    (git-fixes).
  - dmaengine: ioatdma: Fix leaking on version mismatch (git-fixes).
  - dmaengine: idxd: Fix possible Use-After-Free in
    irq_process_work_list (git-fixes).
  - xhci: Apply broken streams quirk to Etron EJ188 xHCI host
    (stable-fixes).
  - xhci: Apply reset resume quirk to Etron EJ188 xHCI host
    (stable-fixes).
  - xhci: Set correct transferred length for cancelled bulk
    transfers (stable-fixes).
  - drm/exynos/vidi: fix memory leak in .get_modes() (stable-fixes).
  - ACPI: x86: Force StorageD3Enable on more products
    (stable-fixes).
  - nilfs2: fix nilfs_empty_dir() misjudgment and long loop on
    I/O errors (git-fixes).
  - kheaders: explicitly define file modes for archived headers
    (stable-fixes).
  - intel_th: pci: Add Lunar Lake support (stable-fixes).
  - intel_th: pci: Add Meteor Lake-S support (stable-fixes).
  - intel_th: pci: Add Sapphire Rapids SOC support (stable-fixes).
  - intel_th: pci: Add Granite Rapids SOC support (stable-fixes).
  - intel_th: pci: Add Granite Rapids support (stable-fixes).
  - clkdev: Update clkdev id usage to allow for longer names
    (stable-fixes).
  - nilfs2: return the mapped address from nilfs_get_page()
    (stable-fixes).
  - commit 8bec8e0

++++ kernel-rt:

  - RDMA/mlx5: Add check for srq max_sge attribute (git-fixes)
  - commit 5a7a44c
  - RDMA/mlx5: Fix unwind flow as part of mlx5_ib_stage_init_init (git-fixes)
  - commit a73b3cb
  - RDMA/mlx5: Ensure created mkeys always have a populated rb_key (git-fixes)
  - commit 194920a
  - RDMA/mlx5: Follow rb_key.ats when creating new mkeys (git-fixes)
  - commit 93d4abb
  - RDMA/mlx5: Remove extra unlock on error path (git-fixes)
  - commit 662ecd8
  - RDMA/rxe: Fix responder length checking for UD request packets (git-fixes)
  - commit 77ecb50
  - RDMA/rxe: Fix data copy for IB_SEND_INLINE (git-fixes)
  - commit 9ec1cd9
  - RDMA/bnxt_re: Fix the max msix vectors macro (git-fixes)
  - commit 19f32fe
  - drm/i915/mso: using joiner is not possible with eDP MSO
    (git-fixes).
  - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14AHP9
    (stable-fixes).
  - ACPICA: Revert "ACPICA: avoid Info: mapping multiple BARs. Your
    kernel is fine." (git-fixes).
  - thermal/drivers/mediatek/lvts_thermal: Return error in case
    of invalid efuse data (git-fixes).
  - dmaengine: ioatdma: Fix missing kmem_cache_destroy()
    (git-fixes).
  - dmaengine: ioatdma: Fix kmemleak in ioat_pci_probe()
    (git-fixes).
  - dmaengine: ioatdma: Fix error path in ioat3_dma_probe()
    (git-fixes).
  - dmaengine: ioatdma: Fix leaking on version mismatch (git-fixes).
  - dmaengine: idxd: Fix possible Use-After-Free in
    irq_process_work_list (git-fixes).
  - xhci: Apply broken streams quirk to Etron EJ188 xHCI host
    (stable-fixes).
  - xhci: Apply reset resume quirk to Etron EJ188 xHCI host
    (stable-fixes).
  - xhci: Set correct transferred length for cancelled bulk
    transfers (stable-fixes).
  - drm/exynos/vidi: fix memory leak in .get_modes() (stable-fixes).
  - ACPI: x86: Force StorageD3Enable on more products
    (stable-fixes).
  - nilfs2: fix nilfs_empty_dir() misjudgment and long loop on
    I/O errors (git-fixes).
  - kheaders: explicitly define file modes for archived headers
    (stable-fixes).
  - intel_th: pci: Add Lunar Lake support (stable-fixes).
  - intel_th: pci: Add Meteor Lake-S support (stable-fixes).
  - intel_th: pci: Add Sapphire Rapids SOC support (stable-fixes).
  - intel_th: pci: Add Granite Rapids SOC support (stable-fixes).
  - intel_th: pci: Add Granite Rapids support (stable-fixes).
  - clkdev: Update clkdev id usage to allow for longer names
    (stable-fixes).
  - nilfs2: return the mapped address from nilfs_get_page()
    (stable-fixes).
  - commit 8bec8e0

++++ tuned:

  - Update to version 2.23.0.2+git.5d5dbfc:
    * chore: remove use of deprecated Logger.warn()
    * new release (2.23.0)
    * Disk plugin: make hdparm device checks lazy
    * Revert "Video plugin: make hdparm device checks lazy"
    * Video plugin: make hdparm device checks lazy
    * Do not check for x86_energy_perf_policy if it won't be used
    * Check that writes are necessary if they may cause redundant IPIs
    * Add an option to skip `write_to_file` if the content would not change
    * Turn on amdgpu panel power savings in balanced-battery
    * Modify the video plugin for tuning of the amdgpu `panel_power_savings` attribute
    * video: Don't show error when trying to read radeon files
    * video: make missing radeon_powersave files quieter
    * video: Rename _radeon_powersave_files to _files
    * feat: add plugin_irq
    * throughput-performance: dropped unused AMD related variable
    * ppd: Adjust the detection of 'performance-degraded'
    * ppd: Fix hold releasing
    * ppd: Add debug logs when changing base profile
    * Re-check dbus when (re)starting TuneD from tuned-adm profile
    * functions: added 'log' which helps with debugging
    * Simplify reading/writing from/to sysctl by using existing functions
    * Fix logs in `commands.read_file`
    * plugin_cpu: decrease the severity of _has_pm_qos==False
    * sap-netweaver: increased vm.max_map_count
    * daemon: buffer sighup signal
    * tuned-ppd: Detect battery change events
    * Migrate profiles to /etc/tuned/profiles/ and /usr/lib/tuned/profiles/
    * Propagate unexpected exceptions in the wait exception handler
    * Add an option to configure profile directories
    * Use get_list to parse unix_socket_signal_path
    * Add a function to parse lists in the global configuration
    * Added intel_recommended_pstate builtin function.
    * dbus: add commands to dynamically create/destroy instances
    * dbus: ensure that hotplug operations only work on hotplug plugins
    * instance: add priority as a property
    * monitor_net: fixed traceback if stats cannot be read
    * plugin_net: do not read monitors if dynamic tuning is disabled
    * Allow equal characters in parameter value

------------------------------------------------------------------
------------------  2024-6-21  -  Jun 21 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update baselibs.conf
  - Build requires rust-cbindgen >= 0.25. However, this means
    we cannot build libvulkan_nouveau on Leap.
  - Enable libvulkan_nouveau including the following depencencies
    * add rust crate paste-1.0.14.tar.gz
    * add rust crate proc-macro2-1.0.70.tar.gz
    * add rust crate quote-1.0.33.tar.gz
    * add rust crate syn-2.0.39.tar.gz
    * add rust crate unicode-ident-1.0.12.tar.gz

++++ Mesa-drivers:

  - Update baselibs.conf
  - Build requires rust-cbindgen >= 0.25. However, this means
    we cannot build libvulkan_nouveau on Leap.
  - Enable libvulkan_nouveau including the following depencencies
    * add rust crate paste-1.0.14.tar.gz
    * add rust crate proc-macro2-1.0.70.tar.gz
    * add rust crate quote-1.0.33.tar.gz
    * add rust crate syn-2.0.39.tar.gz
    * add rust crate unicode-ident-1.0.12.tar.gz

++++ aaa_base:

  - Update to version 84.87+git20240620.57ee9e1:
    * Remove legacy-actions support [jsc#PED-264]

++++ btrfsprogs:

  - Let btrfsprogs-bash-completion require btrfsprogs with same version
    as there is a file conflict with the bash completion scripts
    still being bundled with btrfsprogs in older versions shipped with 15.6

++++ docker-compose:

  - Update to version 2.28.0:
    * go.mod: github.com/compose-spec/compose-go v2.1.3
    * go.mod: docker/docker and docker/cli v27.0.1-rc.1
  - Update to version 2.27.3:
    * build(deps): bump github.com/spf13/cobra from 1.8.0 to 1.8.1
    * build(deps): bump github.com/docker/buildx from 0.15.0 to
    0.15.1
  - Update to version 2.27.2:
    * using as flag of the up command, watch was blocking process
    shutdown This happened when sunsetting the application from
    docker compose down command
    * Add open watch docs in up menu
    * bump buildkit to v0.14.0 and buildx to v0.15.0
    * stop watch process when associated up process is stopped
    * build(deps): bump github.com/docker/docker
    * build(deps): bump github.com/containerd/containerd from 1.7.17
    to 1.7.18
    * build(deps): bump golang.org/x/sys from 0.20.0 to 0.21.0
    * build(deps): bump github.com/hashicorp/go-version from 1.6.0 to
    1.7.0
    * build: replace uses of archive.CanonicalTarNameForPath
    * update gh actions versions, update engine matrix, bump golang
    to 1.21.11
    * enforce keyboard.Close is always executed to restore terminal
    * config --environment
    * Readd event
    * remove unreachable code
    * Fix dot env file to define COMPOSE_* variables
    * return an error when --detach and --watch are used together in
    up command
    * Correct 'cancellation' typo in comment
    * Fix: change append to use slice index in ps.go
    * COMPOSE_PROFILES can be set by .env file
    * prevent concurrent map write relying on project immutability

++++ kernel-default:

  - drivers/perf: hisi_pcie: Fix out-of-bound access when valid
    event group (CVE-2024-38569 bsc#1226772).
  - commit 6715b52
  - drivers/perf: hisi: hns3: Fix out-of-bound access when valid
    event group (CVE-2024-38568 bsc#1226771).
  - commit 33d69e0
  - sched/core: Fix incorrect initialization of the 'burst'
    parameter in cpu_max_write() (bsc#1226791).
  - commit 6b67975
  - virtio_net: checksum offloading handling fix (git-fixes).
  - commit d283709
  - virtio_net: avoid data-races on dev->stats fields (git-fixes).
  - commit 50373fb
  - vfio/fsl-mc: Block calling interrupt handler without trigger
    (bsc#1222810 CVE-2024-26814).
  - commit b1aee55
  - vfio/platform: Create persistent IRQ handlers (bsc#1222809
    CVE-2024-26813).
  - commit 28ae90e
  - ALSA: hda/realtek: Add more codec ID to no shutup pins list
    (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14ARP8
    (stable-fixes).
  - ALSA: hda/realtek: Support Lenovo Thinkbook 13x Gen 4
    (stable-fixes).
  - ALSA: hda/realtek: Support Lenovo Thinkbook 16P Gen 5
    (stable-fixes).
  - ALSA: hda: cs35l41: Support Lenovo Thinkbook 13x Gen 4
    (stable-fixes).
  - ALSA: hda: cs35l41: Support Lenovo Thinkbook 16P Gen 5
    (stable-fixes).
  - ALSA: hda/realtek: Limit mic boost on N14AP7 (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for ProBook
    445/465 G11 (stable-fixes).
  - ALSA: hda: cs35l56: Fix lifecycle of codec pointer
    (stable-fixes).
  - commit 3c2cbdc
  - net: usb: rtl8150 fix unintiatilzed variables in
    rtl8150_get_link_ksettings (git-fixes).
  - net: usb: ax88179_178a: improve reset check (git-fixes).
  - net: phy: mxl-gpy: Remove interrupt mask clearing from
    config_init (git-fixes).
  - net: lan743x: Support WOL at both the PHY and MAC appropriately
    (git-fixes).
  - net: lan743x: disable WOL upon resume to restore full data
    path operation (git-fixes).
  - ALSA: hda/realtek: Enable headset mic on IdeaPad 330-17IKB 81DM
    (git-fixes).
  - ALSA: hda: tas2781: Component should be unbound before
    deconstruction (git-fixes).
  - ALSA: hda: cs35l41: Component should be unbound before
    deconstruction (git-fixes).
  - ALSA: hda: cs35l56: Component should be unbound before
    deconstruction (git-fixes).
  - ALSA/hda: intel-dsp-config: Document AVS as dsp_driver option
    (git-fixes).
  - ALSA: hda/realtek: Remove Framework Laptop 16 from quirks
    (git-fixes).
  - ALSA: seq: ump: Fix missing System Reset message handling
    (git-fixes).
  - ALSA: hda: cs35l41: Possible null pointer dereference in
    cs35l41_hda_unbind() (git-fixes).
  - commit 045593b
  - tcp: Dump bound-only sockets in inet_diag (bsc#1204562).
  - commit ff006da

++++ kernel-rt:

  - drivers/perf: hisi_pcie: Fix out-of-bound access when valid
    event group (CVE-2024-38569 bsc#1226772).
  - commit 6715b52
  - drivers/perf: hisi: hns3: Fix out-of-bound access when valid
    event group (CVE-2024-38568 bsc#1226771).
  - commit 33d69e0
  - sched/core: Fix incorrect initialization of the 'burst'
    parameter in cpu_max_write() (bsc#1226791).
  - commit 6b67975
  - virtio_net: checksum offloading handling fix (git-fixes).
  - commit d283709
  - virtio_net: avoid data-races on dev->stats fields (git-fixes).
  - commit 50373fb
  - vfio/fsl-mc: Block calling interrupt handler without trigger
    (bsc#1222810 CVE-2024-26814).
  - commit b1aee55
  - vfio/platform: Create persistent IRQ handlers (bsc#1222809
    CVE-2024-26813).
  - commit 28ae90e
  - ALSA: hda/realtek: Add more codec ID to no shutup pins list
    (stable-fixes).
  - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14ARP8
    (stable-fixes).
  - ALSA: hda/realtek: Support Lenovo Thinkbook 13x Gen 4
    (stable-fixes).
  - ALSA: hda/realtek: Support Lenovo Thinkbook 16P Gen 5
    (stable-fixes).
  - ALSA: hda: cs35l41: Support Lenovo Thinkbook 13x Gen 4
    (stable-fixes).
  - ALSA: hda: cs35l41: Support Lenovo Thinkbook 16P Gen 5
    (stable-fixes).
  - ALSA: hda/realtek: Limit mic boost on N14AP7 (stable-fixes).
  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for ProBook
    445/465 G11 (stable-fixes).
  - ALSA: hda: cs35l56: Fix lifecycle of codec pointer
    (stable-fixes).
  - commit 3c2cbdc
  - net: usb: rtl8150 fix unintiatilzed variables in
    rtl8150_get_link_ksettings (git-fixes).
  - net: usb: ax88179_178a: improve reset check (git-fixes).
  - net: phy: mxl-gpy: Remove interrupt mask clearing from
    config_init (git-fixes).
  - net: lan743x: Support WOL at both the PHY and MAC appropriately
    (git-fixes).
  - net: lan743x: disable WOL upon resume to restore full data
    path operation (git-fixes).
  - ALSA: hda/realtek: Enable headset mic on IdeaPad 330-17IKB 81DM
    (git-fixes).
  - ALSA: hda: tas2781: Component should be unbound before
    deconstruction (git-fixes).
  - ALSA: hda: cs35l41: Component should be unbound before
    deconstruction (git-fixes).
  - ALSA: hda: cs35l56: Component should be unbound before
    deconstruction (git-fixes).
  - ALSA/hda: intel-dsp-config: Document AVS as dsp_driver option
    (git-fixes).
  - ALSA: hda/realtek: Remove Framework Laptop 16 from quirks
    (git-fixes).
  - ALSA: seq: ump: Fix missing System Reset message handling
    (git-fixes).
  - ALSA: hda: cs35l41: Possible null pointer dereference in
    cs35l41_hda_unbind() (git-fixes).
  - commit 045593b
  - tcp: Dump bound-only sockets in inet_diag (bsc#1204562).
  - commit ff006da

++++ openSUSE-build-key:

  - Ensure that SLM 6.0 key is installed on Leap Micro and Leap 16
  - install SLFO / SLM 6.0 key and SLES 15 SP6+ key by default

++++ patterns-container:

  - Add obsoletes for libcontainers-sles-mounts to allow migration from 5.X
    boo#1226722

------------------------------------------------------------------
------------------  2024-6-20  -  Jun 20 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to bugfix release 24.1.2
  - -> https://docs.mesa3d.org/relnotes/24.1.2

++++ Mesa-drivers:

  - Update to bugfix release 24.1.2
  - -> https://docs.mesa3d.org/relnotes/24.1.2

++++ avahi:

  - Add avahi-filter-bogus-services.patch: no longer supply bogus
    services to callbacks (bsc#1226586).

++++ curl:

  - add multibuild for minimal libcurl flavored build (useful for
    container environments)
  - split zsh and fish completion into subpackages to have
    proper supplements

++++ dpdk:

  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang and %python3_fix_shebang_path macros
    [bsc#1212476]

++++ python-kiwi:

  - Fix potential race condition in loop detach
    The call to 'losetup -d' is in fact an async operation. Once
    the command returns the loop can still be associated with the
    former file because it gets lazy unbound and releases later.
    Prior re-use of the same loop device it is therefore required
    to wait until the kernel event queue is processed.

++++ health-checker:

  - Remove rchealth-checker symlink [jsc#PED-264]

++++ kernel-default:

  - cachefiles: remove requests from xarray during flushing requests
    (bsc#1226588).
  - commit b238f81
  - net/smc: fix neighbour and rtable leak in smc_ib_find_route()
    (git-fixes bsc#1225823 CVE-2024-36945 bsc#1226547).
  - commit d4aa573
  - selftests/bpf: test case for callback_depth states pruning logic
    (bsc#1225903).
  - bpf: check bpf_func_state->callback_depth when pruning states
    (bsc#1225903).
  - commit 6632e43

++++ kernel-rt:

  - cachefiles: remove requests from xarray during flushing requests
    (bsc#1226588).
  - commit b238f81
  - net/smc: fix neighbour and rtable leak in smc_ib_find_route()
    (git-fixes bsc#1225823 CVE-2024-36945 bsc#1226547).
  - commit d4aa573
  - selftests/bpf: test case for callback_depth states pruning logic
    (bsc#1225903).
  - bpf: check bpf_func_state->callback_depth when pruning states
    (bsc#1225903).
  - commit 6632e43

++++ kubevirt:

  - Collect component Role rules under operator Role instead of
    ClusterRole (bsc#1223965, CVE-2024-33394)
    0005-Collect-component-Role-rules-under-operator-Role-ins.patch

++++ libarchive:

  - Update lib-suffix.patch
    * Add LIB_SUFFIX to libdir path in the pkg-config file

++++ libassuan:

  - Update to 3.0.0:
    * API change: For new code, which uses libassuan with nPTH, please
    use gpgrt_get_syscall_clamp and assuan_control, instead of the
    system_hooks API.  Use of ASSUAN_SYSTEM_NPTH is deprecated with new
    API version 3. If it's really needed to keep using old
    implementation of ASSUAN_SYSTEM_NPTH, you need to change your your
    application code, to define
    ASSUAN_REALLY_REQUIRE_V2_NPTH_SYSTEM_HOOKS before including
    <assuan.h>.  For an application which uses version 2 API
    (NEED_LIBASSUAN_API=2 in its configure.ac), use of
    ASSUAN_SYSTEM_NPTH is still supported. [T5914]
    * New function assuan_control. [T6625]
    * New function assuan_sock_accept. [T5925]
    * New functions assuan_pipe_wait_server_termination and
    assuan_pipe_kill_server to support abstraction of process. [T6487]
    * Windows support for sendfd/recvfd. [T6236]
    * Implement timeout in assuan_sock_connect_byname. [T3302]
    * No support for WindowsCE, any more. [T6170]
    * New socket flags "linger" and "reuseaddr". [rA87f92fe962]
    * Interface changes relative to the 2.5.0 release:
  - assuan_sock_accept                  NEW.
  - assuan_pipe_wait_server_termination NEW.
  - assuan_pipe_kill_server             NEW.
  - assuan_sock_set_flag                EXTENDED.
  - assuan_sock_get_flag                EXTENDED.
    * Release-info: https://dev.gnupg.org/T7163

++++ libgcrypt:

  - Update to 1.11.0:
    * New and extended interfaces:
  - Add an API for Key Encapsulation Mechanism (KEM). [T6755]
  - Add Streamlined NTRU Prime sntrup761 algorithm. [rCcf9923e1a5]
  - Add Kyber algorithm according to FIPS 203 ipd 2023-08-24. [rC18e5c0d268]
  - Add Classic McEliece algorithm. [rC003367b912]
  - Add One-Step KDF with hash and MAC. [T5964]
  - Add KDF algorithm HKDF of RFC-5869. [T5964]
  - Add KDF algorithm X963KDF for use in CMS. [rC3abac420b3]
  - Add GMAC-SM4 and Poly1305-SM4. [rCd1ccc409d4]
  - Add ARIA block cipher algorithm. [rC316c6d7715]
  - Add explicit FIPS indicators for MD and MAC algorithms. [T6376]
  - Add support for SHAKE as MGF in RSA. [T6557]
  - Add gcry_md_read support for SHAKE algorithms. [T6539]
  - Add gcry_md_hash_buffers_ext function. [T7035]
  - Add cSHAKE hash algorithm. [rC065b3f4e02]
  - Support internal generation of IV for AEAD cipher mode. [T4873]
    * Performance:
  - Add SM3 ARMv8/AArch64/CE assembly implementation. [rCfe891ff4a3]
  - Add SM4 ARMv8/AArch64 assembly implementation. [rCd8825601f1]
  - Add SM4 GFNI/AVX2 and GFI/AVX512 implementation. [rC5095d60af4,rCeaed633c16]
  - Add SM4 ARMv9 SVE CE assembly implementation. [rC2dc2654006]
  - Add PowerPC vector implementation of SM4. [rC0b2da804ee]
  - Optimize ChaCha20 and Poly1305 for PPC P10 LE. [T6006]
  - Add CTR32LE bulk acceleration for AES on PPC. [rC84f2e2d0b5]
  - Add generic bulk acceleration for CTR32LE mode (GCM-SIV) for SM4
    and Camellia. [rCcf956793af]
  - Add GFNI/AVX2 implementation of Camellia. [rC4e6896eb9f]
  - Add AVX2 and AVX512 accelerated implementations for GHASH (GCM)
    and POLYVAL (GCM-SIV). [rCd857e85cb4, rCe6f3600193]
  - Add AVX512 implementation for SHA512. [rC089223aa3b]
  - Add AVX512 implementation for Serpent. [rCce95b6ec35]
  - Add AVX512 implementation for Poly1305 and ChaCha20. [rCcd3ed49770, rC9a63cfd617]
  - Add AVX512 accelerated implementation for SHA3 and Blake2. [rCbeaad75f46,rC909daa700e]
  - Add VAES/AVX2 accelerated i386 implementation for AES. [rC4a42a042bc]
  - Add bulk processing for XTS mode of Camellia and SM4. [rC32b18cdb87, rCaad3381e93]
  - Accelerate XTS and ECB modes for Twofish and Serpent. [rCd078a928f5,rC8a1fe5f78f]
  - Add AArch64 crypto/SHA512 extension implementation for SHA512. [rCe51d3b8330]
  - Add AArch64 crypto-extension implementation for Camellia. [rC898c857206]
  - Accelerate OCB authentication on AMD with AVX2. [rC6b47e85d65]
    * Bug fixes:
  - For PowerPC check for missing optimization level for vector register usage. [T5785]
  - Fix EdDSA secret key check. [T6511]
  - Fix decoding of PKCS#1-v1.5 and OAEP padding. [rC34c2042792]
  - Allow use of PKCS#1-v1.5 with SHA3 algorithms. [T6976]
  - Fix AESWRAP padding length check. [T7130]
    * Other:
  - Allow empty password for Argon2 KDF. [rCa20700c55f]
  - Various constant time operation imporvements.
  - Add "bp256", "bp384", "bp512" aliases for Brainpool curves.
  - Support for the random server has been removed. [T5811]
  - The control code GCRYCTL_ENABLE_M_GUARD is deprecated and not
    supported any more.  Please use valgrind or other tools. [T5822]
  - Logging is now done via the libgpg-error logging functions. [rCab0bdc72c7]
    * Remove patches fixed upstream:
  - libgcrypt-no-deprecated-grep-alias.patch
  - libgcrypt-Chacha20-poly1305-Optimized-chacha20-poly1305.patch
  - libgcrypt-ppc-enable-P10-assembly-with-ENABLE_FORCE_SOF.patch
    * Rebase patches:
  - libgcrypt-FIPS-jitter-errorcodes.patch
  - libgcrypt-FIPS-jitter-whole-entropy.patch

++++ libgpg-error:

  - Update to 1.50:
    * New set of process spawn functions. [T6249]
    * Fixed return type for gpgrt_b64dec_proc and gpgrt_b64dec_finish
    to gpg_err_code_t.  This enum return type is in almost all cases
    compatible to the formerly used gpg_error_t (i.e. unsigned int).
    * Interface changes relative to the 1.49 release:
    gpgrt_process_t                     CHANGED (never used).
    gpgrt_spawn_actions_t               NEW type.
    gpgrt_process_requests              NEW enum.
    gpgrt_process_spawn                 NEW.
    gpgrt_process_terminate             NEW.
    gpgrt_process_get_streams           NEW.
    gpgrt_process_ctl                   NEW.
    gpgrt_process_wait                  NEW.
    gpgrt_process_release               NEW.
    gpgrt_spawn_actions_new             NEW.
    gpgrt_spawn_actions_release         NEW.
    gpgrt_spawn_actions_set_redirect    NEW.
    gpgrt_spawn_actions_set_environ     NEW (posix only).
    gpgrt_spawn_actions_set_inherit_fds NEW (posix only).
    gpgrt_spawn_actions_set_atfork      NEW (posix only).
    gpgrt_spawn_actions_set_envvars     NEW (w32 only).
    gpgrt_spawn_actions_set_inherit_handles NEW (w32 only).
    GPGRT_PROCESS_DETACHED              NEW.
    GPGRT_PROCESS_NO_CONSOLE            NEW.
    GPGRT_PROCESS_NO_EUID_CHECK         NEW.
    GPGRT_PROCESS_STDIN_PIPE            NEW.
    GPGRT_PROCESS_STDOUT_PIPE           NEW.
    GPGRT_PROCESS_STDERR_PIPE           NEW.
    GPGRT_PROCESS_STDINOUT_SOCKETPAIR   NEW.
    GPGRT_PROCESS_STDIN_KEEP            NEW.
    GPGRT_PROCESS_STDOUT_KEEP           NEW.
    GPGRT_PROCESS_STDERR_KEEP           NEW.
    GPGRT_PROCESS_STDFDS_SETTING        NEW.
    GPGRT_SPAWN_INHERIT_FILE            REMOVED (never used).
    GPGRT_SPAWN_NONBLOCK                REMOVED (never used).
    GPGRT_SPAWN_RUN_ASFW                REMOVED (never used).
    GPGRT_SPAWN_DETACHED                REMOVED (never used).
    GPGRT_SPAWN_KEEP_STDIN              REMOVED (never used).
    GPGRT_SPAWN_KEEP_STDOUT             REMOVED (never used).
    GPGRT_SPAWN_KEEP_STDERR             REMOVED (never used).
    * Release-info: https://dev.gnupg.org/T7102

++++ wayland:

  - Update to release 1.23.0
    * A mechanism to set the size of the internal connection buffer used by
    libwayland
    * An enum-header mode for wayland-scanner to generate headers with only enums
    * wayland-scanner now generates validator functions for enums on the server
    side
    * Protocols can now indicate with a "deprecated-since" XML attribute that a
    request, event or enum entry is deprecated
    * An API to set a name for a queue to aid debugging
    * wl_client_get_user_data() and wl_client_set_user_data() to more easily attach
    custom data to a client
    * OpenBSD support
    * A wl_shm.release request for proper cleanup of this global

++++ openSUSE-repos-LeapMicro:

  - Ensure package gets removed on migration to commmercial products
    Issue #62 on gh
  - Update _service file's set_version and obs_scm to manual
    spec will be now updated by running osc service mr

++++ pam-config:

  - Update to version 2.11+git.20240620:
    * Call pam_fscrypt/pam_ecryptfs as first session module
    [bsc#1226452]

++++ python-dnspython:

  - Update to version 2.6.1
    * The Tudoor fix ate legitimate Truncated exceptions, preventing
    the resolver from failing over to TCP and causing the query to
    timeout.
  - Update to version 2.6.0
    * As mentioned in the “TuDoor” paper and the associated
    CVE-2023-29483, the dnspython stub resolver is vulnerable to a
    potential DoS if a bad-in-some-way response from the right
    address and port forged by an attacker arrives before a
    legitimate one on the UDP port dnspython is using for that
    query.
    This release addresses the issue by adopting the recommended
    mitigation, which is ignoring the bad packets and continuing to
    listen for a legitimate response until the timeout for the
    query has expired.
    * Added support for the NSID EDNS option.
    * Dnspython now looks for version metadata for optional packages
    and will not use them if they are too old. This prevents
    possible exceptions when a feature like DoH is not desired in
    dnspython, but an old httpx is installed along with
    dnspython for some other purpose.
    * The DoHNameserver class now allows GET to be used instead of
    the default POST, and also passes source and source_port
    correctly to the underlying query methods.
  - Update to version 2.5.0
    * Dnspython now uses hatchling for builds.
    * Cython is no longer supported due to various typing issues.
    * Dnspython now explicitly canonicalizes IPv4 and IPv6 addresses.
    Previously it was possible for non-canonical IPv6 forms to be
    stored in a AAAA address, which would work correctly but
    possibly cause problmes if the address were used as a key in a
    dictionary.
    * The number of messages in a section can be retrieved with
    section_count().
    * Truncation preferences for messages can be specified.
    * The length of a message can be automatically prepended when
    rendering.
    * dns.message.create_response() automatically adds padding when
    required by RFC 8467.
    * The TLS verify parameter is now supported by dns.query.tls(),
    and the DoH and DoT Nameserver subclasses.
    * The MutableMapping used to store content in a zone may now be
    specified by a factory when subclassing. Factories may also be
    provided for writable verisons and immutable versions.
    * dns.name.Name now has predecessor() and successor() methods
    implementing RFC 4471.
    * QUIC has had a number of bug fixes and also now supports
    session tickets for faster session resumption.
    * The NSEC3 class now has a next_name() method for retrieving the
    next name as a dns.name.Name.

++++ python-packaging:

  - update to 24.1:
    * No unreleased changes.

++++ virt-manager:

  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang macro, [bsc#1212476]

------------------------------------------------------------------
------------------  2024-6-19  -  Jun 19 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Disable LTO on %ix86/x86_64 due to rendering bugs on Radeon
    graphics (boo#1226462)

++++ Mesa-drivers:

  - Disable LTO on %ix86/x86_64 due to rendering bugs on Radeon
    graphics (boo#1226462)

++++ accountsservice:

  - Update accountsservice-sysconfig.patch: work with SELinux policy
    (bsc#1222978).

++++ btrfsprogs:

  - update to 6.9
    * mkfs:
    * if --force used, don't continue if the mount status cannot be
    determined (e.g. due to permissions)
    * fix minimum size calculation on zoned devices, make it work with option -b
    * check:
    * option --clear-ino-cache removed (functionality still provided in
    'rescue' command group)
    * detect and repair wrong file extent item ram_bytes value
    * qgroup clear-stale:
    * sync the filesystem before search to read the up to date state
    * handle cases where qgroup cannot be deleted due to uncleaned subvolume
    or when squota is enabled
    * qgroup show: display status of qgroup regarding the cleaning of the
    subvolume or if it's squota
    * receive: fix stream parsing on strict alignment hosts (e.g. ARM v5 or v6)
    * tune change-csum: fix check of dev-replace status item, continue if no
    dev-replace in progress
    * dump-tree: print contents of dev-replace status item
    * convert: fix extent iteration to handle prealloc/unwritten extents
    * libbtrfsutil:
    * patchlevel version update 1.3.1
    * fix potentially unaligned access to send stream
    * create library links to all version levels
    * libbtrfs:
    * patchlevel version update 0.1.3
    * fix potentially unaligned access to send stream
    * create library links to all version levels
    * build:
    * fix compatibility with e2fsprogs 1.47.1
    * fix header file dependency tracking
    * other:
    * documentation updates

++++ python-kiwi:

  - Fixed repository include to image with dnf
    When specifying a repository element with imageinclude="true",
    kiwi permanently adds the repo file inside of the image.
    The distribution standard path is used to store the repo
    file in this case. With dnf a package manager exists that is
    primarily used on Fedora and RHEL systems. Thus the standard
    path for the repo files is set to "/etc/yum.repos.d".
    However, dnf can also be used for other rpm based distributions
    e.g SUSE. On such a system the default path does not exist
    or is different because another package manager is the
    default. This commit makes sure that the expected path is
    created prior adding any repo files.

++++ drbd:

  - drbd: fix build error against kernel v6.9.3 (boo#1226510)
    * add patch
    + bsc1226510-fix-build-err-against-6.9.3.patch

++++ kdump:

  - upgrade to version 2.0.7
    * set KDUMP_CPUs to 0 (all CPUs) by default
    * fadump: use fadump=nocma when user data not filtered out (bsc#1224214)

++++ kernel-default:

  - supported.conf: Add APM X-Gene SoC hardware monitoring driver (jsc#PED-8649)
    Module is marked supported because of merge from SP6, but lets add
    reference to SLM6.0 maintenance task.
  - commit d270c07
  - gpio: tqmx86: introduce shadow register for GPIO output value
    (git-fixes).
  - Refresh
    patches.suse/gpio-tqmx86-store-IRQ-trigger-type-and-unmask-status.patch.
  - commit 559245f
  - efi/x86: Free EFI memory map only when installing a new one
    (git-fixes).
  - gpio: lpc32xx: fix module autoloading (stable-fixes).
  - commit d39df35
  - Move upstreamed NFS patch into sorted section
  - commit 19c3986
  - nfsd: optimise recalculate_deny_mode() for a common case
    (bsc#1217912).
  - commit 882d2ff
  - NFS: avoid infinite loop in pnfs_update_layout (bsc#1219633
    bsc#1226226).
  - commit b98e69a
  - NFS: abort nfs_atomic_open_v23 if name is too long
    (bsc#1219847).
  - NFS: add atomic_open for NFSv3 to handle O_TRUNC correctly
    (bsc#1219847).
  - commit 772961e

++++ kernel-rt:

  - supported.conf: Add APM X-Gene SoC hardware monitoring driver (jsc#PED-8649)
    Module is marked supported because of merge from SP6, but lets add
    reference to SLM6.0 maintenance task.
  - commit d270c07
  - gpio: tqmx86: introduce shadow register for GPIO output value
    (git-fixes).
  - Refresh
    patches.suse/gpio-tqmx86-store-IRQ-trigger-type-and-unmask-status.patch.
  - commit 559245f
  - efi/x86: Free EFI memory map only when installing a new one
    (git-fixes).
  - gpio: lpc32xx: fix module autoloading (stable-fixes).
  - commit d39df35
  - Move upstreamed NFS patch into sorted section
  - commit 19c3986
  - nfsd: optimise recalculate_deny_mode() for a common case
    (bsc#1217912).
  - commit 882d2ff
  - NFS: avoid infinite loop in pnfs_update_layout (bsc#1219633
    bsc#1226226).
  - commit b98e69a
  - NFS: abort nfs_atomic_open_v23 if name is too long
    (bsc#1219847).
  - NFS: add atomic_open for NFSv3 to handle O_TRUNC correctly
    (bsc#1219847).
  - commit 772961e

++++ samba:

  - Update to 4.20.2
    * vfs_widelinks with DFS shares breaks case insensitivity;
    (bso#15662); (bsc#1213607).
    * Samba build is not reproducible; (bso#13213).
    * ldb qsort might r/w out of bounds with an intransitive
    compare function; (bso#15569).
    * Many qsort() comparison functions are non-transitive, which
    can lead to out-of-bounds access in some circumstances;
    (bso#15625).
    * Need to change gitlab-ci.yml tags in all branches to avoid CI
    bill; (bso#15638).
    * We have added new options --vendor-name and --vendor-patch-
    revision arguments to ./configure to allow distributions and
    packagers to put their name in the Samba version string so
    that when debugging Samba the source of the binary is
    obvious; (bso#15654).
    * CTDB RADOS mutex helper misses namespace support;
    (bso#15665).
    * Dynamic DNS updates with the internal DNS are not working;
    (bso#13019).
    * netr_LogonSamLogonEx returns NR_STATUS_ACCESS_DENIED with
    SysvolReady=0; (bso#14981).
    * Anonymous smb3 signing/encryption should be allowed (similar
    to Windows Server 2022); (bso#15412).
    * Panic in dreplsrv_op_pull_source_apply_changes_trigger;
    (bso#15573).
    * s4:nbt_server: does not provide unexpected handling, so
    winbindd can't use nmb requests instead cldap; (bso#15620).
    * winbindd, net ads join and other things don't work on an ipv6
    only host; (bso#15642).
    * Segmentation fault when deleting files in vfs_recycle;
    (bso#15659).
    * Panic in vfs_offload_token_db_fetch_fsp(); (bso#15664).
    * "client use kerberos" and --use-kerberos is ignored for the
    machine account; (bso#15666).
    * Regression DFS not working with widelinks = true;
    (bso#15435).
    * samba-gpupdate - Invalid NtVer in netlogon_samlogon_response;
    (bso#15633).
    * idmap_ad creates an incorrect local krb5.conf in case of
    trusted domain lookups; (bso#15653).
    * The images don't build after the git security release and
    CentOS 8 Stream is EOL; (bso#15660).

++++ openssl-3:

  - FIPS: Check that the fips provider is available before setting
    it as the default provider in FIPS mode. [bsc#1220523]
    * Rebase openssl-Force-FIPS.patch

++++ libproxy-client:

  - Update to version 0.5.7:
    + Handle empty ignore settings.

++++ libproxy-backend:

  - Update to version 0.5.7:
    + Handle empty ignore settings.

++++ shadow:

  - Update to 4.16.0:
    * The shadow implementations of id(1) and groups(1) are deprecated
    in favor of the GNU coreutils and binutils versions.
    They will be removed in 4.17.0.
    * The rlogind implementation has been removed.
    * The libsubid major version has been bumped, since it now requires
    specification of the module's free() implementation.
  - Update shadow-login_defs-suse.patch
  - Add shadow-4.16.0-econf.patch:
    Replace deprecated econf_readDirs with econf_readConfig

++++ ppp:

  - drop support for PPPoATM and the dependency on linux-atm-devel

------------------------------------------------------------------
------------------  2024-6-18  -  Jun 18 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - BuildRequire python3-pycparser when building drivers on ARM:
    etnaviv drm module requires this module to build.

++++ Mesa-drivers:

  - BuildRequire python3-pycparser when building drivers on ARM:
    etnaviv drm module requires this module to build.

++++ conntrack-tools:

  - Remove rc* symlinks

++++ lvm2-device-mapper:

  - change BuildRequires due to corosync devel package rename
    * update lvm2.spec, use pkgconfig(corosync)

++++ python-kiwi:

  - Bump version: 10.0.21 → 10.0.22

++++ issue-generator:

  - Remove rc* symlinks [jsc#PED-266]

++++ kernel-default:

  - fs/9p: fix uninitialized values during inode evict (bsc#1225815
    CVE-2024-36923).
  - commit b349473
  - x86/mce: Dynamically size space for machine check records
    (bsc#1222241).
  - commit 2d0d4b2
  - nvme-tcp: Export the nvme_tcp_wq to sysfs (bsc#1224049).
  - Refresh
    patches.suse/nvme-tcp-Add-wq_unbound-modparam-for-nvme_tcp_wq.patch.
  - commit 099b967
  - net: preserve kabi for struct dst_ops (CVE-2024-36971
    bsc#1226145).
  - commit 6d764b6
  - kcov: don't lose track of remote references during softirqs
    (git-fixes).
  - commit fc5abf0
  - rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back
    (CVE-2024-27414 bsc#1224439).
  - commit 6651625
  - netfilter: nf_tables: reject new basechain after table flag update
    (CVE-2024-35900 bsc#1224497).
  - commit ef2c4d5
  - net: fix __dst_negative_advice() race (CVE-2024-36971
    bsc#1226145).
  - commit 604ed28
  - ipv6: Fix infinite recursion in fib6_dump_done() (CVE-2024-35886
    bsc#1224670).
  - commit ba91bc1

++++ kernel-firmware-all:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-amdgpu:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-ath10k:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-ath11k:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-ath12k:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-atheros:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-bluetooth:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-bnx2:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-brcm:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-chelsio:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-dpaa2:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-i915:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-intel:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-iwlwifi:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-liquidio:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-marvell:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-media:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-mediatek:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-mellanox:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-mwifiex:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-network:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-nfp:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-nvidia:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-platform:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-prestera:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-qcom:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-qlogic:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-radeon:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-realtek:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-serial:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-sound:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-ti:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-ueagle:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-firmware-usb-network:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ kernel-rt:

  - fs/9p: fix uninitialized values during inode evict (bsc#1225815
    CVE-2024-36923).
  - commit b349473
  - x86/mce: Dynamically size space for machine check records
    (bsc#1222241).
  - commit 2d0d4b2
  - nvme-tcp: Export the nvme_tcp_wq to sysfs (bsc#1224049).
  - Refresh
    patches.suse/nvme-tcp-Add-wq_unbound-modparam-for-nvme_tcp_wq.patch.
  - commit 099b967
  - net: preserve kabi for struct dst_ops (CVE-2024-36971
    bsc#1226145).
  - commit 6d764b6
  - kcov: don't lose track of remote references during softirqs
    (git-fixes).
  - commit fc5abf0
  - rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back
    (CVE-2024-27414 bsc#1224439).
  - commit 6651625
  - netfilter: nf_tables: reject new basechain after table flag update
    (CVE-2024-35900 bsc#1224497).
  - commit ef2c4d5
  - net: fix __dst_negative_advice() race (CVE-2024-36971
    bsc#1226145).
  - commit 604ed28
  - ipv6: Fix infinite recursion in fib6_dump_done() (CVE-2024-35886
    bsc#1224670).
  - commit ba91bc1

++++ c-ares:

  - c-ares 1.31.0
    Changes:
    * Enable Query Cache by default. [PR #786]
    Bugfixes:
    * Enhance Windows DNS configuration change detection to also
    detect manual DNS configuration changes. [PR #785]
    * Various legacy MacOS Build fixes. [Issue #782]
    * Ndots value of zero in resolv.conf was not being honored. [852a60a]
    * Watt-32 build support had been broken for some time. [PR #781]
    * Distribute `ares_dns_rec_type_tostr` manpage. [PR #778]

++++ libcontainers-common:

  - Move the following distro configs files to /usr/share/containers/:
    * /etc/containers/mounts.json
    * /etc/containers/storage.conf
    * /etc/containers/seccomp.json
  - New release 20240618
  - bump bundled c/common to 0.59.1
  - bump bundled c/image to 5.31.0
  - bump bundled c/storage to 1.54.0

++++ lvm2:

  - change BuildRequires due to corosync devel package rename
    * update lvm2.spec, use pkgconfig(corosync)

++++ systemd:

  - testsuite: move a misplaced %endif
  - Merge systemd-coredump back into the main package (bsc#1091684)
  - testsuite: only require the devel packages when pulling the dlopen'd
    dependencies (the libraries are dependencies of the devel packages).

++++ openSUSE-repos-LeapMicro:

  - Add Leap Micro 6.X 5.X handling
    * no dedicated update repo for slem updates.
    * oss repo will now always include slem 6.X updates
  - Update to version 20240618.8c4e429:
    * keep micro5 in micro5 repoindex
  - Update to version 20240618.727f0a2:
    * Use new path names for micro 6.0
    * use 6.0 for leap-micro6 repoindex
    * Add repoindex for Micro 6
    * Update README.md with openqa reference
    * Update README.md with --gpg-auto-import-keys
    * Remove reference to undefined substitution

++++ python-urllib3:

  - Add CVE-2024-37891.patch (bsc#1226469)

++++ socat:

  - 0004-udp-listen-bind4.patch: fixed a UDP listen error (bsc#1226459)

++++ ucode-amd:

  - Update to version 20240618 (git commit 7d931f8afa51):
    * amlogic: Update bluetooth firmware binary
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Pulsar core
    * rtl_bt: Update RTL8822C BT UART firmware to 0xB5D6_6DCB
    * rtl_bt: Update RTL8822C BT USB firmware to 0xAED6_6DCB
    * amdgpu: update DMCUB to v0.0.222.0 for DCN314
    * iwlwifi: add ty/So/Ma firmwares for core88-87 release
    * iwlwifi: update cc/Qu/QuZ firmwares for core88-87 release
    * linux-firmware: add new cc33xx firmware for cc33xx chips
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for ASUS UM5606 laptop
    * cirrus: cs35l56: Update firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware for Lenovo Thinkbooks
    * amdgpu: update yellow carp firmware
    * amdgpu: update VCN 4.0.4 firmware
    * amdgpu: update SDMA 6.0.2 firmware
    * amdgpu: update PSP 13.0.7 firmware
    * amdgpu: update GC 11.0.2 firmware
    * amdgpu: update navi10 firmware
    * amdgpu: update raven2 firmware
    * amdgpu: update raven firmware
    * amdgpu: update SMU 13.0.10 firmware
    * amdgpu: update SDMA 6.0.3 firmware
    * amdgpu: update PSP 13.0.10 firmware
    * amdgpu: update GC 11.0.3 firmware
    * amdgpu: update VCN 3.1.2 firmware
    * amdgpu: update PSP 13.0.5 firmware
    * amdgpu: update psp 13.0.8 firmware
    * amdgpu: update vega20 firmware
    * amdgpu: update vega12 firmware
    * amdgpu: update vega10 firmware
    * amdgpu: update VCN 4.0.0 firmware
    * amdgpu: update smu 13.0.0 firmware
    * amdgpu: update SDMA 6.0.0 firmware
    * amdgpu: update PSP 13.0.0 firmware
    * amdgpu: update GC 11.0.0 firmware
    * amdgpu: update picasso firmware
    * amdgpu: update beige goby firmware
    * amdgpu: update vangogh firmware
    * amdgpu: update dimgrey cavefish firmware
    * amdgpu: update green sardine firmware
    * amdgpu: update navy flounder firmware
    * amdgpu: update PSP 13.0.11 firmware
    * amdgpu: update GC 11.0.4 firmware
    * amdgpu: update VCN 4.0.2 firmware
    * amdgpu: update SDMA 6.0.1 firmware
    * amdgpu: update PSP 13.0.4 firmware
    * amdgpu: update GC 11.0.1 firmware
    * amdgpu: update sienna cichlid firmware
    * amdgpu: update VCN 4.0.5 firmware
    * amdgpu: update PSP 14.0.0 firmware
    * amdgpu: update GC 11.5.0 firmware
    * amdgpu: update navi14 firmware
    * amdgpu: update SMU 13.0.6 firmware
    * amdgpu: update PSP 13.0.6 firmware
    * amdgpu: update GC 9.4.3 firmware
    * amdgpu: update renoir firmware
    * amdgpu: update navi12 firmware
    * amdgpu: update aldebaran firmware
    * amdgpu: add support for PSP 14.0.1
    * amdgpu: add support for VPE 6.1.1
    * amdgpu: add support for VCN 4.0.6
    * amdgpu: add support for SDMA 6.1.1
    * amdgpu: add support for GC 11.5.1
    * amdgpu: Add support for DCN 3.5.1
    * QCA: Update Bluetooth QCA2066 firmware to 2.1.0-00639
    * cnm: update chips&media wave521c firmware.
    * linux-firmware: Add ordinary firmware for RTL8821AU device

++++ virt-manager:

  - Skip some tests that fail under Pytest 8.x.

++++ wget:

  - Fix mishandled semicolons in the userinfo subcomponent could lead to an
    insecure behavior in which data that was supposed to be in the userinfo
    subcomponent is misinterpreted to be part of the host subcomponent.
    [bsc#1226419, CVE-2024-38428, properly-re-implement-userinfo-parsing.patch]

------------------------------------------------------------------
------------------  2024-6-17  -  Jun 17 2024  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20240617.f5ff27f:
    * add /usr/bin/nu to etc/shells for nushell

++++ curl:

  - remove mozilla-nss code (unsupported since 8.3.0)

++++ python-kiwi:

  - Fixed selinux labels for boot files
    When kiwi calls the bootloader config and installation modules
    several files gets created as unlabeled_t because the labeling
    happened earlier. This commit ensures that setfiles gets called
    after BootLoaderConfig and/or BootLoaderInstall has done its
    job. This Fixes #2568
  - Add bash to package requirements
    If there are script evaluations that does not specify
    an interpreter, kiwi uses bash for it. The same applies
    for sub-process invocations using shell pipelines. Thus
    the bash shell is a required tool for kiwi under certain
    circumstances. Further details in Issue #2567

++++ hwdata:

  - update to 0.383:
    * Update pci and vendor ids

++++ kernel-default:

  - drm/amd/display: Disable idle reallow as part of command/gpint (bsc#1225702 CVE-2024-36024)
  - commit 6d53e8c
  - RAS/AMD/ATL: Use system settings for MI300 DRAM to normalized
    address translation (bsc#1225300).
  - RAS/AMD/ATL: Fix MI300 bank hash (bsc#1225300).
  - commit 82b08f9
  - i2c: designware: Fix the functionality flags of the slave-only
    interface (git-fixes).
  - i2c: at91: Fix the functionality flags of the slave-only
    interface (git-fixes).
  - USB: class: cdc-wdm: Fix CPU lockup caused by excessive log
    messages (git-fixes).
  - xhci: Handle TD clearing for multiple streams case (git-fixes).
  - thunderbolt: debugfs: Fix margin debugfs node creation condition
    (git-fixes).
  - usb-storage: alauda: Check whether the media is initialized
    (git-fixes).
  - usb: typec: tcpm: Ignore received Hard Reset in TOGGLING state
    (git-fixes).
  - usb: typec: tcpm: fix use-after-free case in
    tcpm_register_source_caps (git-fixes).
  - USB: xen-hcd: Traverse host/ when CONFIG_USB_XEN_HCD is selected
    (git-fixes).
  - tty: n_tty: Fix buffer offsets when lookahead is used
    (git-fixes).
  - drivers: core: synchronize really_probe() and dev_uevent()
    (git-fixes).
  - iio: imu: inv_icm42600: delete unneeded update watermark call
    (git-fixes).
  - iio: dac: ad5592r: fix temperature channel scaling value
    (git-fixes).
  - iio: adc: ad9467: fix scan type sign (git-fixes).
  - misc: microchip: pci1xxxx: Fix a memory leak in the error
    handling of gp_aux_bus_probe() (git-fixes).
  - misc: microchip: pci1xxxx: fix double free in the error handling
    of gp_aux_bus_probe() (git-fixes).
  - mei: me: release irq in mei_me_pci_resume error path
    (git-fixes).
  - ax25: Fix refcount imbalance on inbound connections (git-fixes).
  - tpm_tis: Do *not* flush uninitialized work (git-fixes).
  - selftests/mm: fix build warnings on ppc64 (stable-fixes).
  - selftests/mm: compaction_test: fix incorrect write of zero to
    nr_hugepages (git-fixes).
  - genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after()
    (git-fixes).
  - drm/amdgpu/atomfirmware: add intergrated info v2.3 table
    (stable-fixes).
  - intel_th: pci: Add Meteor Lake-S CPU support (stable-fixes).
  - mmc: sdhci-acpi: Add quirk to enable pull-up on the card-detect
    GPIO on Asus T100TA (git-fixes).
  - mmc: sdhci-acpi: Disable write protect detection on Toshiba
    WT10-A (stable-fixes).
  - mmc: sdhci-acpi: Fix Lenovo Yoga Tablet 2 Pro 1380 sdcard slot
    not working (stable-fixes).
  - mmc: sdhci-acpi: Sort DMI quirks alphabetically (stable-fixes).
  - mmc: sdhci: Add support for "Tuning Error" interrupts
    (stable-fixes).
  - mmc: core: Add mmc_gpiod_set_cd_config() function
    (stable-fixes).
  - media: mxl5xx: Move xpt structures off stack (stable-fixes).
  - media: lgdt3306a: Add a check against null-pointer-def
    (stable-fixes).
  - media: v4l2-core: hold videodev_lock until dev reg, finishes
    (stable-fixes).
  - drm/amdgpu: add error handle to avoid out-of-bounds
    (stable-fixes).
  - drm/i915/hwmon: Get rid of devm (stable-fixes).
  - wifi: rtw89: correct aSIFSTime for 6GHz band (stable-fixes).
  - wifi: rtlwifi: rtl8192de: Fix endianness issue in RX path
    (stable-fixes).
  - wifi: rtlwifi: rtl8192de: Fix low speed with WPA3-SAE
    (stable-fixes).
  - wifi: rtlwifi: rtl8192de: Fix 5 GHz TX power (stable-fixes).
  - wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
    (stable-fixes).
  - ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
    (stable-fixes).
  - crypto: ecrdsa - Fix module auto-load on add_key (stable-fixes).
  - drm/sun4i: hdmi: Move mode_set into enable (stable-fixes).
  - drm/sun4i: hdmi: Convert encoder to atomic (stable-fixes).
  - mmc: core: Do not force a retune before RPMB switch
    (stable-fixes).
  - commit 8df97c4
  - nvme/tcp: Add wq_unbound modparam for nvme_tcp_wq (bsc#1224049).
  - commit 7af7bce

++++ kernel-rt:

  - drm/amd/display: Disable idle reallow as part of command/gpint (bsc#1225702 CVE-2024-36024)
  - commit 6d53e8c
  - RAS/AMD/ATL: Use system settings for MI300 DRAM to normalized
    address translation (bsc#1225300).
  - RAS/AMD/ATL: Fix MI300 bank hash (bsc#1225300).
  - commit 82b08f9
  - i2c: designware: Fix the functionality flags of the slave-only
    interface (git-fixes).
  - i2c: at91: Fix the functionality flags of the slave-only
    interface (git-fixes).
  - USB: class: cdc-wdm: Fix CPU lockup caused by excessive log
    messages (git-fixes).
  - xhci: Handle TD clearing for multiple streams case (git-fixes).
  - thunderbolt: debugfs: Fix margin debugfs node creation condition
    (git-fixes).
  - usb-storage: alauda: Check whether the media is initialized
    (git-fixes).
  - usb: typec: tcpm: Ignore received Hard Reset in TOGGLING state
    (git-fixes).
  - usb: typec: tcpm: fix use-after-free case in
    tcpm_register_source_caps (git-fixes).
  - USB: xen-hcd: Traverse host/ when CONFIG_USB_XEN_HCD is selected
    (git-fixes).
  - tty: n_tty: Fix buffer offsets when lookahead is used
    (git-fixes).
  - drivers: core: synchronize really_probe() and dev_uevent()
    (git-fixes).
  - iio: imu: inv_icm42600: delete unneeded update watermark call
    (git-fixes).
  - iio: dac: ad5592r: fix temperature channel scaling value
    (git-fixes).
  - iio: adc: ad9467: fix scan type sign (git-fixes).
  - misc: microchip: pci1xxxx: Fix a memory leak in the error
    handling of gp_aux_bus_probe() (git-fixes).
  - misc: microchip: pci1xxxx: fix double free in the error handling
    of gp_aux_bus_probe() (git-fixes).
  - mei: me: release irq in mei_me_pci_resume error path
    (git-fixes).
  - ax25: Fix refcount imbalance on inbound connections (git-fixes).
  - tpm_tis: Do *not* flush uninitialized work (git-fixes).
  - selftests/mm: fix build warnings on ppc64 (stable-fixes).
  - selftests/mm: compaction_test: fix incorrect write of zero to
    nr_hugepages (git-fixes).
  - genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after()
    (git-fixes).
  - drm/amdgpu/atomfirmware: add intergrated info v2.3 table
    (stable-fixes).
  - intel_th: pci: Add Meteor Lake-S CPU support (stable-fixes).
  - mmc: sdhci-acpi: Add quirk to enable pull-up on the card-detect
    GPIO on Asus T100TA (git-fixes).
  - mmc: sdhci-acpi: Disable write protect detection on Toshiba
    WT10-A (stable-fixes).
  - mmc: sdhci-acpi: Fix Lenovo Yoga Tablet 2 Pro 1380 sdcard slot
    not working (stable-fixes).
  - mmc: sdhci-acpi: Sort DMI quirks alphabetically (stable-fixes).
  - mmc: sdhci: Add support for "Tuning Error" interrupts
    (stable-fixes).
  - mmc: core: Add mmc_gpiod_set_cd_config() function
    (stable-fixes).
  - media: mxl5xx: Move xpt structures off stack (stable-fixes).
  - media: lgdt3306a: Add a check against null-pointer-def
    (stable-fixes).
  - media: v4l2-core: hold videodev_lock until dev reg, finishes
    (stable-fixes).
  - drm/amdgpu: add error handle to avoid out-of-bounds
    (stable-fixes).
  - drm/i915/hwmon: Get rid of devm (stable-fixes).
  - wifi: rtw89: correct aSIFSTime for 6GHz band (stable-fixes).
  - wifi: rtlwifi: rtl8192de: Fix endianness issue in RX path
    (stable-fixes).
  - wifi: rtlwifi: rtl8192de: Fix low speed with WPA3-SAE
    (stable-fixes).
  - wifi: rtlwifi: rtl8192de: Fix 5 GHz TX power (stable-fixes).
  - wifi: rtl8xxxu: Fix the TX power of RTL8192CU, RTL8723AU
    (stable-fixes).
  - ACPI: resource: Do IRQ override on TongFang GXxHRXx and GMxHGxx
    (stable-fixes).
  - crypto: ecrdsa - Fix module auto-load on add_key (stable-fixes).
  - drm/sun4i: hdmi: Move mode_set into enable (stable-fixes).
  - drm/sun4i: hdmi: Convert encoder to atomic (stable-fixes).
  - mmc: core: Do not force a retune before RPMB switch
    (stable-fixes).
  - commit 8df97c4
  - nvme/tcp: Add wq_unbound modparam for nvme_tcp_wq (bsc#1224049).
  - commit 7af7bce

++++ libnettle:

  - Update to 3.10:
    * Bug fixes:
  - Add missing hash functions sha512_224 and sha512_256 to the
    nettle_get_hashes() list. The name values in the
    corresponding nettle_hash structs also changed to use
    underscore instead of dash, for consistency.
  - Fix a few cases of formally undefined calls to memcpy(dst,
    NULL, 0), resulting from valid calls to, e.g.,
    sha256_update(ctx, 0, NULL).
    * New features:
  - Support RSA-OAEP encryption. Contributed by Nicolas Mora and Daiki Ueno.
  - New function sha3_256_shake_output, new functions
    sha3_128_init, sha3_128_update, sha3_128_shake,
    sha3_128_shake_output. Contributed by Daiki Ueno.
  - Added DRBG-CTR with AES256, contributed by Simon Josefsson.
    * Optimizations:
  - New combined gcm-aes assembly for powerpc64, contributed by Danny Tsen.
  - New sha256 assembly for powerpc64, contributed by Eric Richter.
  - Improved performance for powerpc64 AES decrypt, by skipping
    subkey transformations that don't suit the vncipher instructions.
  - Add arm64 CPU feature detection for Android and for Apple systems,
    contributed by Foolbar and Tim Kosse, prespectively.
    * Miscellaneous:
  - New tests for side-channel silence, based on valgrind.
  - Delete all md5 assembly code. Delete all sparc32 assembly code.

++++ ncurses:

  - Add ncurses patch 20240615
    + improve formatting/style of manpages (patches by Branden Robinson).
    + review/update modules files.
    + improve install-rules in Ada95 makefiles (report by Branden Robinson).
    + improve formatting/style of manpages in test-directory.

++++ nghttp2:

  - update to 1.62.1:
    * nghttpx: Fix batch UDP QUIC packet dropped on GRO read
  - update to 1.62.0:
    * nghttpx: Fix QUIC stateless reset stack buffer overflow
    * Require c-ares >= 1.16.0 for ares_getaddrinfo
    * Require C++20 compiler
    * Adopt std::to_array and remove make_array
    * nghttpx: Define APIEndpoints separately
    * nghttpx: Do not send error/status body when method is HEAD
    * nghttpx: Fix alignment issues in BlockAllocator
    * nghttpx: Simplify parameter declaration for ipc_fd functions
    * nghttpx: Add extent to ipc_fd explicitly
    * Make make_byte_ref return std::span
    * Make util::decode_hex return std::span
    * Rewrite util::parse_uint
    * Let base64::decode return std::span
    * Refactor StringRef
    * Stringref refactor c str and str
    * Add StringRef literal operator and remove StringRef::from_lit
    * Make StringRef(const std::string&) implicit
    * Add http2::make_field family functions
    * Remove std::string conversion operator from StringRef
    * Optimize StringRef comparisons against c-string
    * Pack more quic pkt
    * nghttpx: Dynamic GSO failover
    * Refactor ImmutableString
    * nghttpx: Refactor QUIC data path
    * nghttpx: Fix inherited TCP port comparison
    * make_websocket_accept_token: Lesser conversions
    * Add http3::make_field family functions
    * Remove unnecessary namespace qualifications
    * Refactor http utils
    * Refactor streq
    * Remove util::streq and let StringRef operator== deal with it
    * Update the link for the Prefix.pdf document. fix #2178
    * Introduce typed nghttp2_min and nghttp2_max
  - drop gcc7.patch (obsolete, we require C++20 now)

++++ passt:

  - Update to version 20240607.8a83b53:
    * selinux: Allow access to user_devpts
    * tcp, flow: Fix some error paths which didn't clean up flows properly
    * util: Use 'long' to represent millisecond durations
    * lineread: Use ssize_t for line lengths
    * conf: Safer parsing of MAC addresses
    * util: Use unsigned indices for bits in bitmaps
    * clang-tidy: Enable the bugprone-macro-parentheses check
    * Remove pointless macro parameters in CALL_PROTO_HANDLER
    * udp: Make rport calculation more local
    * tcp: Make pointer const in tcp_revert_seq
    * log: Remove log_to_stdout option
    * conf: Don't print usage via the logging subsystem
    * conf: Remove unhelpful usage() wrapper
    * tcp: move seq_to_tap update to when frame is queued

++++ perl:

  - move UNIVERSAL.pm into perl-base

------------------------------------------------------------------
------------------  2024-6-16  -  Jun 16 2024  -------------------
------------------------------------------------------------------

++++ haproxy:

  - Update to version 3.0.2+git0.a45a8e623:
    * [RELEASE] Released version 3.0.2
    * DOC: management: rename show stats domain cli "dns" to "resolvers"
    * DOC/MINOR: management: add -dZ option
    * DOC/MINOR: management: add missed -dR and -dv options
    * BUG/MINOR: quic: fix padding of INITIAL packets
    * BUG/MAJOR: mux-h1: Prevent any UAF on H1 connection after draining a request
    * CLEANUP: log/proxy: fix comment in proxy_free_common()
    * BUG/MEDIUM: proxy: fix UAF with {tcp,http}checks logformat expressions
    * MINOR: proxy: add proxy_free_common() helper function
    * BUG/MINOR: promex: Skip resolvers metrics when there is no resolver section
    * DOC: config: add missing context hint for new server and proxy keywords
    * DOC: config: add missing section hint for "guid" proxy keyword
    * DOC: config: move "hash-key" from proxy to server options
    * BUG/MEDIUM: log: fix lf_expr_postcheck() behavior with default section
    * BUG/MINOR: proxy: fix header_unique_id leak on deinit()
    * BUG/MINOR: proxy: fix source interface and usesrc leaks on deinit()
    * BUG/MINOR: proxy: fix dyncookie_key leak on deinit()
    * BUG/MINOR: proxy: fix check_{command,path} leak on deinit()
    * BUG/MINOR: proxy: fix email-alert leak on deinit()
    * BUG/MINOR: proxy: fix log_tag leak on deinit()
    * BUG/MINOR: proxy: fix server_id_hdr_name leak on deinit()
    * MINOR: log: fix "http-send-name-header" ignore warning message

++++ kernel-default:

  - ocfs2: fix sparse warnings (bsc#1219224).
  - ocfs2: speed up chain-list searching (bsc#1219224).
  - ocfs2: adjust enabling place for la window (bsc#1219224).
  - ocfs2: improve write IO performance when fragmentation is high
    (bsc#1219224).
  - commit 98a3adb

++++ kernel-rt:

  - ocfs2: fix sparse warnings (bsc#1219224).
  - ocfs2: speed up chain-list searching (bsc#1219224).
  - ocfs2: adjust enabling place for la window (bsc#1219224).
  - ocfs2: improve write IO performance when fragmentation is high
    (bsc#1219224).
  - commit 98a3adb

------------------------------------------------------------------
------------------  2024-6-15  -  Jun 15 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - drm/exynos: hdmi: report safe 640x480 mode as a fallback when
    no EDID found (git-fixes).
  - drm/nouveau: don't attempt to schedule hpd_work on headless
    cards (git-fixes).
  - drm/bridge/panel: Fix runtime warning on panel bridge release
    (git-fixes).
  - drm/komeda: check for error-valued pointer (git-fixes).
  - commit b393dd7

++++ kernel-rt:

  - drm/exynos: hdmi: report safe 640x480 mode as a fallback when
    no EDID found (git-fixes).
  - drm/nouveau: don't attempt to schedule hpd_work on headless
    cards (git-fixes).
  - drm/bridge/panel: Fix runtime warning on panel bridge release
    (git-fixes).
  - drm/komeda: check for error-valued pointer (git-fixes).
  - commit b393dd7

------------------------------------------------------------------
------------------  2024-6-14  -  Jun 14 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to bugfix release 24.1.1
  - -> https://docs.mesa3d.org/relnotes/24.1.1
  - Update to new feature release 24.1.0
  - -> https://docs.mesa3d.org/relnotes/24.1.0
  - Some interesting highlights include:
    * NVIDIA Vulkan driver NVK is now considered ready for prime time.
    Distro packagers are now recommended to include `nouveau` in the
    `vulkan-drivers` list so that their users can have the option of using it
    instead of the proprietary NVIDIA driver.
    * Intel Vulkan driver Anv switched to truly asynchronous VM bind, and Xe
    support for error dump to debug GPU hangs was added.
    * Apple OpenGL driver Asahi has reached OpenGL 4.6 and OpenGL ES 3.2
    support.
    * Broadcom Vulkan driver V3DV gained support for VK_KHR_dynamic_rendering.
    * Arm Mali OpenGL driver Panfrost was prepared for Gen10 (Gxxx), and
    Vulkan driver PanVK was modernised for better Midgard (Txxx) and
    Bifrost (Gxxx) support.
    * All Vulkan drivers have gained support for explicit synchronisation on
    Wayland and X11.
  - adjusted patches:
    * n_stop-iris-flicker.patch
    * python36-buildfix1.patch
  - supersedes patches:
    * 0001-loader-delete-unused-param-from-pipe_loader_sw_probe.patch
    * 0002-glx-fix-some-indentation.patch
    * 0003-glx-add-an-implicit-param-to-createScreen.patch
    * 0004-glx-pass-implicit-load-param-through-allocation.patch
    * 0005-dri-plumb-a-implicit-param-through-createNewScreen-i.patch
    * 0006-gbm-plumb-an-implicit-param-through-device-creation.patch
    * 0007-frontends-dri-plumb-an-implicit-param-through-screen.patch
    * 0008-pipe-loader-plumb-a-flag-for-implicit-driver-load-th.patch
    * 0009-zink-don-t-print-error-messages-when-failing-an-impl.patch
    * 0010-glx-silence-more-implicit-load-zink-errors.patch
  - added libvdpau_d3d12 package
  - small cleanup in specfile

++++ Mesa-drivers:

  - Update to bugfix release 24.1.1
  - -> https://docs.mesa3d.org/relnotes/24.1.1
  - Update to new feature release 24.1.0
  - -> https://docs.mesa3d.org/relnotes/24.1.0
  - Some interesting highlights include:
    * NVIDIA Vulkan driver NVK is now considered ready for prime time.
    Distro packagers are now recommended to include `nouveau` in the
    `vulkan-drivers` list so that their users can have the option of using it
    instead of the proprietary NVIDIA driver.
    * Intel Vulkan driver Anv switched to truly asynchronous VM bind, and Xe
    support for error dump to debug GPU hangs was added.
    * Apple OpenGL driver Asahi has reached OpenGL 4.6 and OpenGL ES 3.2
    support.
    * Broadcom Vulkan driver V3DV gained support for VK_KHR_dynamic_rendering.
    * Arm Mali OpenGL driver Panfrost was prepared for Gen10 (Gxxx), and
    Vulkan driver PanVK was modernised for better Midgard (Txxx) and
    Bifrost (Gxxx) support.
    * All Vulkan drivers have gained support for explicit synchronisation on
    Wayland and X11.
  - adjusted patches:
    * n_stop-iris-flicker.patch
    * python36-buildfix1.patch
  - supersedes patches:
    * 0001-loader-delete-unused-param-from-pipe_loader_sw_probe.patch
    * 0002-glx-fix-some-indentation.patch
    * 0003-glx-add-an-implicit-param-to-createScreen.patch
    * 0004-glx-pass-implicit-load-param-through-allocation.patch
    * 0005-dri-plumb-a-implicit-param-through-createNewScreen-i.patch
    * 0006-gbm-plumb-an-implicit-param-through-device-creation.patch
    * 0007-frontends-dri-plumb-an-implicit-param-through-screen.patch
    * 0008-pipe-loader-plumb-a-flag-for-implicit-driver-load-th.patch
    * 0009-zink-don-t-print-error-messages-when-failing-an-impl.patch
    * 0010-glx-silence-more-implicit-load-zink-errors.patch
  - added libvdpau_d3d12 package
  - small cleanup in specfile

++++ aaa_base:

  - Update to version 84.87+git20240614.332933e:
    * Do not save/restore cursor for foot at status line
    * Add tmux and others to DIR_COLORS (Issue #116)
    * Remove kernel.pid_max limit (bsc#1219038)
    * Add subpackge to enable ptrace

++++ cloud-init:

  - remove dependency on /usr/bin/python3 via using the macros (bsc#1212476)

++++ transactional-update:

  - Enable soft-reboot by default again as announced in
    https://microos.opensuse.org/blog/2024-06-13-soft-reboot/

++++ firewalld:

  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang macro, [bsc#1212476]

++++ fwupd:

  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang_path macro, [bsc#1212476]
  - Update to version 1.9.21:
    + This release adds the following features:
  - Add a fwupd.conf option to ignore CHID requirements for
    development.
    + This release fixes the following bugs:
  - Allow loading Wacom device flags from metadata.
  - Check for needs-shutdown like we do needs-reboot.
  - Fix updating the Aerox 3 Wireless Mouse.
    + This release adds support for the following hardware:
  - Synaptics Carrera devices.
  - Wacom Movink devices.

++++ kernel-default:

  - smb: client: fix use-after-free bug in
    cifs_debug_data_proc_show() (bsc#1225487, CVE-2023-52752).
  - commit c4e1b53
  - Temporarily drop KVM patch that caused a regression (bsc#1226158)
    Delete patches.suse/KVM-x86-pmu-Prioritize-VMX-interception-over-GP-on-R.patch
  - commit 33f31da
  - kABI: bpf: verifier kABI workaround
    (bsc#1225903).
  - commit 726091c
  - bpf: keep track of max number of bpf_loop callback iterations
    (bsc#1225903).
  - selftests/bpf: test widening for iterating callbacks
    (bsc#1225903).
  - bpf: widening for callback iterators (bsc#1225903).
  - selftests/bpf: tests for iterating callbacks (bsc#1225903).
  - bpf: verify callbacks as if they are called unknown number of
    times (bsc#1225903).
  - bpf: extract setup_func_entry() utility function (bsc#1225903).
  - bpf: extract __check_reg_arg() utility function (bsc#1225903).
  - selftests/bpf: track string payload offset as scalar in
    strobemeta (bsc#1225903).
  - selftests/bpf: track tcp payload offset as scalar in
    xdp_synproxy (bsc#1225903).
  - bpf: print full verifier states on infinite loop detection
    (bsc#1225903).
  - selftests/bpf: test if state loops are detected in a tricky case
    (bsc#1225903).
  - bpf: correct loop detection for iterators convergence
    (bsc#1225903).
  - selftests/bpf: tests with delayed read/precision makrs in loop
    body (bsc#1225903).
  - bpf: exact states comparison for iterator convergence checks
    (bsc#1225903).
  - bpf: extract same_callsites() as utility function (bsc#1225903).
  - bpf: move explored_state() closer to the beginning of verifier.c
    (bsc#1225903).
  - commit 63dfc45
  - ipv6: Fix potential uninit-value access in __ip6_make_skb()
    (CVE-2024-36903 bsc#1225741).
  - commit f510672
  - Update references
  - commit 36a2563
  - drm/amd/display: Skip on writeback when it's not applicable (CVE-2024-36914 bsc#1225757).
  - commit e1ad803
  - cpufreq: amd-pstate: Fix the inconsistency in max frequency
    units (git-fixes).
  - commit 9dd9a2b
  - gpiolib: cdev: Fix use after free in lineinfo_changed_notify
    (bsc#1225737 CVE-2024-36899).
  - commit 24144db
  - nouveau: report byte usage in VRAM usage (git-fixes).
  - Refresh
    patches.suse/drm-nouveau-use-tile_mode-and-pte_kind-for-VM_BIND-b.patch.
  - commit 5638f93
  - nouveau: add an ioctl to report vram usage (stable-fixes).
  - Refresh
    patches.suse/drm-nouveau-use-tile_mode-and-pte_kind-for-VM_BIND-b.patch.
  - commit 7ea88ac
  - nouveau: add an ioctl to return vram bar size (stable-fixes).
  - Refresh
    patches.suse/drm-nouveau-use-tile_mode-and-pte_kind-for-VM_BIND-b.patch.
  - commit 07ddfce
  - platform/x86: dell-smbios: Fix wrong token data in sysfs
    (git-fixes).
  - net: phy: Micrel KSZ8061: fix errata solution not taking effect
    problem (git-fixes).
  - wifi: ath10k: fix QCOM_RPROC_COMMON dependency (git-fixes).
  - wifi: mac80211: correctly parse Spatial Reuse Parameter Set
    element (git-fixes).
  - wifi: iwlwifi: mvm: don't read past the mfuart notifcation
    (git-fixes).
  - wifi: iwlwifi: mvm: check n_ssids before accessing the ssids
    (git-fixes).
  - wifi: iwlwifi: dbg_ini: move iwl_dbg_tlv_free outside of
    debugfs ifdef (git-fixes).
  - wifi: iwlwifi: mvm: set properly mac header (git-fixes).
  - wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
    (git-fixes).
  - wifi: iwlwifi: mvm: don't initialize csa_work twice (git-fixes).
  - wifi: cfg80211: pmsr: use correct nla_get_uX functions
    (git-fixes).
  - wifi: cfg80211: Lock wiphy in cfg80211_get_station (git-fixes).
  - wifi: cfg80211: fully move wiphy work to unbound workqueue
    (git-fixes).
  - wifi: mac80211: Fix deadlock in
    ieee80211_sta_ps_deliver_wakeup() (git-fixes).
  - wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects
    (git-fixes).
  - net: phy: micrel: fix KSZ9477 PHY issues after suspend/resume
    (git-fixes).
  - module: don't ignore sysfs_create_link() failures (git-fixes).
  - soundwire: cadence: fix invalid PDI offset (stable-fixes).
  - platform/x86/intel/tpmi: Handle error from tpmi_process_info()
    (stable-fixes).
  - platform/x86: thinkpad_acpi: Take hotkey_mutex during
    hotkey_exit() (git-fixes).
  - media: radio-shark2: Avoid led_names truncations (git-fixes).
  - wifi: nl80211: Avoid address calculations via out of bounds
    array indexing (git-fixes).
  - selftests: mptcp: add ms units for tc-netem delay
    (stable-fixes).
  - pwm: sti: Simplify probe function using devm functions
    (git-fixes).
  - regulator: vqmmc-ipq4019: fix module autoloading (stable-fixes).
  - regulator: irq_helpers: duplicate IRQ name (stable-fixes).
  - platform/x86: ISST: Add Grand Ridge to HPM CPU list
    (stable-fixes).
  - selftests: sud_test: return correct emulated syscall value on
    RISC-V (stable-fixes).
  - wifi: cfg80211: fix the order of arguments for trace events
    of the tx_rx_evt class (stable-fixes).
  - wifi: mac80211: ensure beacon is non-S1G prior to extracting
    the beacon timestamp field (stable-fixes).
  - wifi: mac80211: don't use rate mask for scanning (stable-fixes).
  - pwm: sti: Prepare removing pwm_chip from driver data
    (stable-fixes).
  - commit d252b95
  - HID: logitech-dj: Fix memory leak in
    logi_dj_recv_switch_to_dj_mode() (git-fixes).
  - HID: core: remove unnecessary WARN_ON() in implement()
    (git-fixes).
  - kconfig: doc: fix a typo in the note about 'imply' (git-fixes).
  - gpio: tqmx86: fix broken IRQ_TYPE_EDGE_BOTH interrupt type
    (git-fixes).
  - gpio: tqmx86: store IRQ trigger type and unmask status
    separately (git-fixes).
  - gpio: tqmx86: fix typo in Kconfig label (git-fixes).
  - drm/vmwgfx: Don't memcmp equivalent pointers (git-fixes).
  - drm/vmwgfx: 3D disabled should not effect STDU memory limits
    (git-fixes).
  - drm/vmwgfx: Filter modes which exceed graphics memory
    (git-fixes).
  - drm/panel: sitronix-st7789v: Add check for
    of_drm_get_panel_orientation (git-fixes).
  - drm/amd: Fix shutdown (again) on some SMU v13.0.4/11 platforms
    (git-fixes).
  - kconfig: fix comparison to constant symbols, 'm', 'n'
    (git-fixes).
  - drm/amdgpu: Fix buffer size in gfx_v9_4_3_init_
    cp_compute_microcode() and rlc_microcode() (git-fixes).
  - drm/amdgpu: init microcode chip name from ip versions
    (stable-fixes).
  - fpga: dfl-pci: add PCI subdevice ID for Intel D5005 card
    (stable-fixes).
  - iio: accel: mxc4005: Reset chip on probe() and resume()
    (stable-fixes).
  - drm/amdkfd: Flush the process wq before creating a kfd_process
    (stable-fixes).
  - drm/amd/display: Disable seamless boot on 128b/132b encoding
    (stable-fixes).
  - drm/amd/display: Fix DC mode screen flickering on DCN321
    (stable-fixes).
  - drm/amd/display: Add VCO speed parameter for DCN31 FPU
    (stable-fixes).
  - drm/amd/display: Allocate zero bw after bw alloc enable
    (stable-fixes).
  - drm/amd/display: Add dtbclk access to dcn315 (stable-fixes).
  - drm/amdgpu: Fix VRAM memory accounting (stable-fixes).
  - drm/etnaviv: fix tx clock gating on some GC7000 variants
    (stable-fixes).
  - HID: mcp-2221: cancel delayed_work only when CONFIG_IIO is
    enabled (stable-fixes).
  - iio: adc: ad9467: use chip_info variables instead of array
    (stable-fixes).
  - iio: adc: ad9467: use spi_get_device_match_data()
    (stable-fixes).
  - iio: accel: mxc4005: allow module autoloading via OF compatible
    (stable-fixes).
  - commit 4e48378
  - kABI workaround for sof_ipc_pcm_ops (git-fixes).
  - commit 070cfe5
  - Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
    (git-fixes).
  - cxl/region: Fix memregion leaks in devm_cxl_add_region()
    (git-fixes).
  - cxl/test: Add missing vmalloc.h for tools/testing/cxl/test/mem.c
    (git-fixes).
  - cxl/region: Fix cxlr_pmem leaks (git-fixes).
  - cxl/trace: Correct DPA field masks for general_media & dram
    events (git-fixes).
  - ASoC: SOF: pcm: Restrict DSP D0i3 during S0ix to IPC3
    (stable-fixes).
  - drm/amdgpu/mes: fix use-after-free issue (stable-fixes).
  - drm/amdgpu: Fix the ring buffer size for queue VM flush
    (stable-fixes).
  - drm/amdkfd: Add VRAM accounting for SVM migration
    (stable-fixes).
  - drm/amd/pm: Restore config space after reset (stable-fixes).
  - drm/amdgpu: Update BO eviction priorities (stable-fixes).
  - drm/amd/display: Set color_mgmt_changed to true on unsuspend
    (stable-fixes).
  - drm/amd/display: Revert Remove pixle rate limit for subvp
    (stable-fixes).
  - drm/amd/display: Remove pixle rate limit for subvp
    (stable-fixes).
  - Bluetooth: hci_event: Remove code to removed CONFIG_BT_HS
    (stable-fixes).
  - Bluetooth: Remove usage of the deprecated ida_simple_xx() API
    (stable-fixes).
  - ASoC: Intel: common: add ACPI matching tables for Arrow Lake
    (stable-fixes).
  - Bluetooth: ISO: Fix BIS cleanup (stable-fixes).
  - commit b6ffdb9
  - KVM: arm64: Use local TLBI on permission relaxation
    (bsc#1219478).
  - Refresh
    patches.suse/KVM-arm64-Always-invalidate-TLB-for-stage-2-permission-faults.
  - commit c414679

++++ kernel-rt:

  - smb: client: fix use-after-free bug in
    cifs_debug_data_proc_show() (bsc#1225487, CVE-2023-52752).
  - commit c4e1b53
  - Temporarily drop KVM patch that caused a regression (bsc#1226158)
    Delete patches.suse/KVM-x86-pmu-Prioritize-VMX-interception-over-GP-on-R.patch
  - commit 33f31da
  - kABI: bpf: verifier kABI workaround
    (bsc#1225903).
  - commit 726091c
  - bpf: keep track of max number of bpf_loop callback iterations
    (bsc#1225903).
  - selftests/bpf: test widening for iterating callbacks
    (bsc#1225903).
  - bpf: widening for callback iterators (bsc#1225903).
  - selftests/bpf: tests for iterating callbacks (bsc#1225903).
  - bpf: verify callbacks as if they are called unknown number of
    times (bsc#1225903).
  - bpf: extract setup_func_entry() utility function (bsc#1225903).
  - bpf: extract __check_reg_arg() utility function (bsc#1225903).
  - selftests/bpf: track string payload offset as scalar in
    strobemeta (bsc#1225903).
  - selftests/bpf: track tcp payload offset as scalar in
    xdp_synproxy (bsc#1225903).
  - bpf: print full verifier states on infinite loop detection
    (bsc#1225903).
  - selftests/bpf: test if state loops are detected in a tricky case
    (bsc#1225903).
  - bpf: correct loop detection for iterators convergence
    (bsc#1225903).
  - selftests/bpf: tests with delayed read/precision makrs in loop
    body (bsc#1225903).
  - bpf: exact states comparison for iterator convergence checks
    (bsc#1225903).
  - bpf: extract same_callsites() as utility function (bsc#1225903).
  - bpf: move explored_state() closer to the beginning of verifier.c
    (bsc#1225903).
  - commit 63dfc45
  - ipv6: Fix potential uninit-value access in __ip6_make_skb()
    (CVE-2024-36903 bsc#1225741).
  - commit f510672
  - Update references
  - commit 36a2563
  - drm/amd/display: Skip on writeback when it's not applicable (CVE-2024-36914 bsc#1225757).
  - commit e1ad803
  - cpufreq: amd-pstate: Fix the inconsistency in max frequency
    units (git-fixes).
  - commit 9dd9a2b
  - gpiolib: cdev: Fix use after free in lineinfo_changed_notify
    (bsc#1225737 CVE-2024-36899).
  - commit 24144db
  - nouveau: report byte usage in VRAM usage (git-fixes).
  - Refresh
    patches.suse/drm-nouveau-use-tile_mode-and-pte_kind-for-VM_BIND-b.patch.
  - commit 5638f93
  - nouveau: add an ioctl to report vram usage (stable-fixes).
  - Refresh
    patches.suse/drm-nouveau-use-tile_mode-and-pte_kind-for-VM_BIND-b.patch.
  - commit 7ea88ac
  - nouveau: add an ioctl to return vram bar size (stable-fixes).
  - Refresh
    patches.suse/drm-nouveau-use-tile_mode-and-pte_kind-for-VM_BIND-b.patch.
  - commit 07ddfce
  - platform/x86: dell-smbios: Fix wrong token data in sysfs
    (git-fixes).
  - net: phy: Micrel KSZ8061: fix errata solution not taking effect
    problem (git-fixes).
  - wifi: ath10k: fix QCOM_RPROC_COMMON dependency (git-fixes).
  - wifi: mac80211: correctly parse Spatial Reuse Parameter Set
    element (git-fixes).
  - wifi: iwlwifi: mvm: don't read past the mfuart notifcation
    (git-fixes).
  - wifi: iwlwifi: mvm: check n_ssids before accessing the ssids
    (git-fixes).
  - wifi: iwlwifi: dbg_ini: move iwl_dbg_tlv_free outside of
    debugfs ifdef (git-fixes).
  - wifi: iwlwifi: mvm: set properly mac header (git-fixes).
  - wifi: iwlwifi: mvm: revert gen2 TX A-MPDU size to 64
    (git-fixes).
  - wifi: iwlwifi: mvm: don't initialize csa_work twice (git-fixes).
  - wifi: cfg80211: pmsr: use correct nla_get_uX functions
    (git-fixes).
  - wifi: cfg80211: Lock wiphy in cfg80211_get_station (git-fixes).
  - wifi: cfg80211: fully move wiphy work to unbound workqueue
    (git-fixes).
  - wifi: mac80211: Fix deadlock in
    ieee80211_sta_ps_deliver_wakeup() (git-fixes).
  - wifi: mac80211: mesh: Fix leak of mesh_preq_queue objects
    (git-fixes).
  - net: phy: micrel: fix KSZ9477 PHY issues after suspend/resume
    (git-fixes).
  - module: don't ignore sysfs_create_link() failures (git-fixes).
  - soundwire: cadence: fix invalid PDI offset (stable-fixes).
  - platform/x86/intel/tpmi: Handle error from tpmi_process_info()
    (stable-fixes).
  - platform/x86: thinkpad_acpi: Take hotkey_mutex during
    hotkey_exit() (git-fixes).
  - media: radio-shark2: Avoid led_names truncations (git-fixes).
  - wifi: nl80211: Avoid address calculations via out of bounds
    array indexing (git-fixes).
  - selftests: mptcp: add ms units for tc-netem delay
    (stable-fixes).
  - pwm: sti: Simplify probe function using devm functions
    (git-fixes).
  - regulator: vqmmc-ipq4019: fix module autoloading (stable-fixes).
  - regulator: irq_helpers: duplicate IRQ name (stable-fixes).
  - platform/x86: ISST: Add Grand Ridge to HPM CPU list
    (stable-fixes).
  - selftests: sud_test: return correct emulated syscall value on
    RISC-V (stable-fixes).
  - wifi: cfg80211: fix the order of arguments for trace events
    of the tx_rx_evt class (stable-fixes).
  - wifi: mac80211: ensure beacon is non-S1G prior to extracting
    the beacon timestamp field (stable-fixes).
  - wifi: mac80211: don't use rate mask for scanning (stable-fixes).
  - pwm: sti: Prepare removing pwm_chip from driver data
    (stable-fixes).
  - commit d252b95
  - HID: logitech-dj: Fix memory leak in
    logi_dj_recv_switch_to_dj_mode() (git-fixes).
  - HID: core: remove unnecessary WARN_ON() in implement()
    (git-fixes).
  - kconfig: doc: fix a typo in the note about 'imply' (git-fixes).
  - gpio: tqmx86: fix broken IRQ_TYPE_EDGE_BOTH interrupt type
    (git-fixes).
  - gpio: tqmx86: store IRQ trigger type and unmask status
    separately (git-fixes).
  - gpio: tqmx86: fix typo in Kconfig label (git-fixes).
  - drm/vmwgfx: Don't memcmp equivalent pointers (git-fixes).
  - drm/vmwgfx: 3D disabled should not effect STDU memory limits
    (git-fixes).
  - drm/vmwgfx: Filter modes which exceed graphics memory
    (git-fixes).
  - drm/panel: sitronix-st7789v: Add check for
    of_drm_get_panel_orientation (git-fixes).
  - drm/amd: Fix shutdown (again) on some SMU v13.0.4/11 platforms
    (git-fixes).
  - kconfig: fix comparison to constant symbols, 'm', 'n'
    (git-fixes).
  - drm/amdgpu: Fix buffer size in gfx_v9_4_3_init_
    cp_compute_microcode() and rlc_microcode() (git-fixes).
  - drm/amdgpu: init microcode chip name from ip versions
    (stable-fixes).
  - fpga: dfl-pci: add PCI subdevice ID for Intel D5005 card
    (stable-fixes).
  - iio: accel: mxc4005: Reset chip on probe() and resume()
    (stable-fixes).
  - drm/amdkfd: Flush the process wq before creating a kfd_process
    (stable-fixes).
  - drm/amd/display: Disable seamless boot on 128b/132b encoding
    (stable-fixes).
  - drm/amd/display: Fix DC mode screen flickering on DCN321
    (stable-fixes).
  - drm/amd/display: Add VCO speed parameter for DCN31 FPU
    (stable-fixes).
  - drm/amd/display: Allocate zero bw after bw alloc enable
    (stable-fixes).
  - drm/amd/display: Add dtbclk access to dcn315 (stable-fixes).
  - drm/amdgpu: Fix VRAM memory accounting (stable-fixes).
  - drm/etnaviv: fix tx clock gating on some GC7000 variants
    (stable-fixes).
  - HID: mcp-2221: cancel delayed_work only when CONFIG_IIO is
    enabled (stable-fixes).
  - iio: adc: ad9467: use chip_info variables instead of array
    (stable-fixes).
  - iio: adc: ad9467: use spi_get_device_match_data()
    (stable-fixes).
  - iio: accel: mxc4005: allow module autoloading via OF compatible
    (stable-fixes).
  - commit 4e48378
  - kABI workaround for sof_ipc_pcm_ops (git-fixes).
  - commit 070cfe5
  - Bluetooth: L2CAP: Fix rejecting L2CAP_CONN_PARAM_UPDATE_REQ
    (git-fixes).
  - cxl/region: Fix memregion leaks in devm_cxl_add_region()
    (git-fixes).
  - cxl/test: Add missing vmalloc.h for tools/testing/cxl/test/mem.c
    (git-fixes).
  - cxl/region: Fix cxlr_pmem leaks (git-fixes).
  - cxl/trace: Correct DPA field masks for general_media & dram
    events (git-fixes).
  - ASoC: SOF: pcm: Restrict DSP D0i3 during S0ix to IPC3
    (stable-fixes).
  - drm/amdgpu/mes: fix use-after-free issue (stable-fixes).
  - drm/amdgpu: Fix the ring buffer size for queue VM flush
    (stable-fixes).
  - drm/amdkfd: Add VRAM accounting for SVM migration
    (stable-fixes).
  - drm/amd/pm: Restore config space after reset (stable-fixes).
  - drm/amdgpu: Update BO eviction priorities (stable-fixes).
  - drm/amd/display: Set color_mgmt_changed to true on unsuspend
    (stable-fixes).
  - drm/amd/display: Revert Remove pixle rate limit for subvp
    (stable-fixes).
  - drm/amd/display: Remove pixle rate limit for subvp
    (stable-fixes).
  - Bluetooth: hci_event: Remove code to removed CONFIG_BT_HS
    (stable-fixes).
  - Bluetooth: Remove usage of the deprecated ida_simple_xx() API
    (stable-fixes).
  - ASoC: Intel: common: add ACPI matching tables for Arrow Lake
    (stable-fixes).
  - Bluetooth: ISO: Fix BIS cleanup (stable-fixes).
  - commit b6ffdb9
  - KVM: arm64: Use local TLBI on permission relaxation
    (bsc#1219478).
  - Refresh
    patches.suse/KVM-arm64-Always-invalidate-TLB-for-stage-2-permission-faults.
  - commit c414679

++++ libeconf:

  - Update to version 0.7.2:
    * Do not check errno while float conversion. This is a false
    alarm for S390 and PPC (#210)

++++ libvisual:

  - Imported C99 compatibility fixes from Fedora project:
    https://src.fedoraproject.org/rpms/libvisual/c/bcffd8eddbbcab5b00f930805396be5fdb55c5a7?branch=rawhide
    it fixes build error when using GCC14 (boo#1225859)
    (added libvisual-configure-c99.patch and libvisual-c99.patch).

++++ python-lxml:

  - Remove not needed patch skip-test-under-libexpat-2.6.0.patch
  - Update to 5.2.2:
  - GH#417: The test_feed_parser test could fail if lxml_html_clean
    was not installed.  It is now skipped in that case.
  - LP#2059910: The minimum CPU architecture for the Linux x86 binary
    wheels was set back to "core2", without SSE 4.2.
  - If libxml2 uses iconv, the compile time version is available as
    etree.ICONV_COMPILED_VERSION.
  - 5.2.1
  - LP#2059910: The minimum CPU architecture for the Linux x86 binary
    wheels was set back to "core2", but with SSE 4.2 enabled.
  - LP#2059977: ``Element.iterfind("//absolute_path")`` failed with a
    ``SyntaxError`` where it should have issued a warning.
  - GH#416: The documentation build was using the non-standard
    ``which`` command.  Patch by Michał Górny.
  - 5.2.0
  - LP#1958539: The ``lxml.html.clean`` implementation suffered from
    several (only if used) security issues in the past and was now
    extracted into a separate library:
    https://github.com/fedora-python/lxml_html_clean
    Projects that use lxml without "lxml.html.clean" will not notice
    any difference, except that they won't have potentially vulnerable
    code installed.  The module is available as an "extra" setuptools
    dependency "lxml[html_clean]", so that Projects that need
    "lxml.html.clean" will need to switch their requirements from
    "lxml" to "lxml[html_clean]", or install the new library
    themselves.
  - The minimum CPU architecture for the Linux x86 binary wheels was
    upgraded to "sandybridge" (launched 2011), and glibc 2.28 / gcc 12
    (manylinux_2_28) wheels were added.
  - Built with Cython 3.0.10.
  - 5.1.2
  - LP#2059977: ``Element.iterfind("//absolute_path")`` failed with a
    ``SyntaxError`` where it should have issued a warning.
  - 5.1.1
  - LP#2048920: ``iterlinks()`` in ``lxml.html`` rejected ``bytes``
    input in 5.1.0.
  - High source line numbers from the parser are no longer truncated
    (up to a C ``long``) when using libxml2 2.11 or later.
  - GH#407: A compatibility test was adapted to recent expat versions.
    Patch by Miro Hrončok.
  - Binary wheels use the library versions libxml2 2.12.6 and libxslt
    1.1.39.
  - Windows binary wheels use the library versions libxml2 2.11.7 and
    libxslt 1.1.39.
  - Built with Cython 3.0.9.

++++ rust-keylime:

  - Update to version 0.2.6~0:
    * Bump version to 0.2.6
    * build(deps): bump libc from 0.2.153 to 0.2.155
    * build(deps): bump serde from 1.0.196 to 1.0.203
    * rpm/fedora: Update rust macro usage
    * config: Support hostnames in registrar_ip option
    * added use of persisted IAK and IDevID and authorisation values
    * config changes
    * Adding /agent/info API to agent
    * Fix leftover 'unnecessary qualification' warnings on tests

------------------------------------------------------------------
------------------  2024-6-13  -  Jun 13 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to bugfix release 24.0.9
  - -> https://docs.mesa3d.org/relnotes/24.0.9.html
    * This is the last release of the 24.0 series. Users are encouraged
    to switch to the 24.1 series to continue receiving bugfixes.

++++ Mesa-drivers:

  - Update to bugfix release 24.0.9
  - -> https://docs.mesa3d.org/relnotes/24.0.9.html
    * This is the last release of the 24.0 series. Users are encouraged
    to switch to the 24.1 series to continue receiving bugfixes.

++++ cifs-utils:

  - remove dependency on /usr/bin/python3 (bsc#1212476)

++++ cockpit:

  - disable selinux on leap versions without selinux
  - set libexec dir to %_libexecdir (bsc#1223533)

++++ kernel-default:

  - KVM: x86: Don't advertise guest.MAXPHYADDR as host.MAXPHYADDR
    in CPUID (git-fixes).
  - commit 001738e
  - cgroup: preserve KABI of cgroup_root (bsc#1222254).
  - commit d652cd6
  - cgroup: Add annotation for holding namespace_sem in
    current_cgns_cgroup_from_root() (bsc#1222254).
  - cgroup: Eliminate the need for cgroup_mutex in
    proc_cgroup_show() (bsc#1222254).
  - cgroup: Make operations on the cgroup root_list RCU safe
    (bsc#1222254).
  - cgroup: Remove unnecessary list_empty() (bsc#1222254).
  - commit 8dc654b
  - net: usb: qmi_wwan: add Telit FN920C04 compositions (git-fixes).
  - commit 49f5909
  - Replace the inhouse patch with following upstream patch
    (bsc#1221097, bsc#1224572, CVE-2024-35979)
    patches.suse/raid1-fix-use-after-free-for-original-bio-in-raid1_-fcf3.patch.
  - commit 03ae28a
  - supported.conf: mark ufs as unsupported
    UFS is an unsupported filesystem, mark it as such. We still keep it
    around (not marking as optional), to accommodate any potential
    migrations from BSD systems.
  - commit 5192abd
  - supported.conf: mark orangefs as optional
    We don't support orangefs at all (and it is already marked as such), but
    since there are no SLE consumers of it, mark it as optional.
  - commit 264e3d2
  - nilfs2: fix potential hang in nilfs_detach_log_writer()
    (git-fixes).
  - commit 181df2f
  - rpm/kernel-obs-build.spec.in: Add iso9660 (bsc#1226212)
    Some builds don't just create an iso9660 image, but also mount it during
    build.
  - commit aaee141
  - Input: xpad - add support for ASUS ROG RAIKIRI (git-fixes).
  - commit 9d3a015

++++ kernel-rt:

  - KVM: x86: Don't advertise guest.MAXPHYADDR as host.MAXPHYADDR
    in CPUID (git-fixes).
  - commit 001738e
  - cgroup: preserve KABI of cgroup_root (bsc#1222254).
  - commit d652cd6
  - cgroup: Add annotation for holding namespace_sem in
    current_cgns_cgroup_from_root() (bsc#1222254).
  - cgroup: Eliminate the need for cgroup_mutex in
    proc_cgroup_show() (bsc#1222254).
  - cgroup: Make operations on the cgroup root_list RCU safe
    (bsc#1222254).
  - cgroup: Remove unnecessary list_empty() (bsc#1222254).
  - commit 8dc654b
  - net: usb: qmi_wwan: add Telit FN920C04 compositions (git-fixes).
  - commit 49f5909
  - Replace the inhouse patch with following upstream patch
    (bsc#1221097, bsc#1224572, CVE-2024-35979)
    patches.suse/raid1-fix-use-after-free-for-original-bio-in-raid1_-fcf3.patch.
  - commit 03ae28a
  - supported.conf: mark ufs as unsupported
    UFS is an unsupported filesystem, mark it as such. We still keep it
    around (not marking as optional), to accommodate any potential
    migrations from BSD systems.
  - commit 5192abd
  - supported.conf: mark orangefs as optional
    We don't support orangefs at all (and it is already marked as such), but
    since there are no SLE consumers of it, mark it as optional.
  - commit 264e3d2
  - nilfs2: fix potential hang in nilfs_detach_log_writer()
    (git-fixes).
  - commit 181df2f
  - rpm/kernel-obs-build.spec.in: Add iso9660 (bsc#1226212)
    Some builds don't just create an iso9660 image, but also mount it during
    build.
  - commit aaee141
  - Input: xpad - add support for ASUS ROG RAIKIRI (git-fixes).
  - commit 9d3a015

++++ alsa:

  - Update to alsa-lib 1.2.12:
    * pcm: plug support for iec958 subframe samples
    * pcm: ladspa - Skip missing ladspa directories
    * topology: correct version script path
    * ucm: define and describe Syntax 7
    * async handler cleanup fix
    * conf updates
    For details, see:
    https://www.alsa-project.org/wiki/Changes_v1.2.11_v1.2.12#alsa-lib

------------------------------------------------------------------
------------------  2024-6-12  -  Jun 12 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - test-image-live: add shadow package
    Fixes:
    KiwiCommandError: chroot: stderr: /usr/bin/chroot: failed to run command ‘usermod’: No such file or directory

++++ kernel-default:

  - ext4: correct offset of gdb backup in non meta_bg group to
    update_backups (bsc#1224735 CVE-2024-35807).
  - commit 68779d8
  - ext4: remove unnecessary check from alloc_flex_gd() (bsc#1222080
    CVE-2023-52622).
  - commit 2e6ec2e
  - llc: verify mac len before reading mac header
    (CVE-2023-52843 bsc#1224951).
  - commit ea955e6
  - netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get()
    (CVE-2024-35898 bsc#1224498).
  - commit 47a49f0
  - nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies
    (CVE-2024-36915 bsc#1225758).
  - commit 0955416
  - net: add copy_safe_from_sockptr() helper
    (git-fixes prerequisite CVE-2024-36915 bsc#1225758).
  - commit e4ca26d
  - rpm/kernel-obs-build.spec.in: Add networking modules for docker
    (bsc#1226211)
    docker needs more networking modules, even legacy iptable_nat and _filter.
  - commit 415e132

++++ kernel-rt:

  - ext4: correct offset of gdb backup in non meta_bg group to
    update_backups (bsc#1224735 CVE-2024-35807).
  - commit 68779d8
  - ext4: remove unnecessary check from alloc_flex_gd() (bsc#1222080
    CVE-2023-52622).
  - commit 2e6ec2e
  - llc: verify mac len before reading mac header
    (CVE-2023-52843 bsc#1224951).
  - commit ea955e6
  - netfilter: nf_tables: Fix potential data-race in __nft_flowtable_type_get()
    (CVE-2024-35898 bsc#1224498).
  - commit 47a49f0
  - nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies
    (CVE-2024-36915 bsc#1225758).
  - commit 0955416
  - net: add copy_safe_from_sockptr() helper
    (git-fixes prerequisite CVE-2024-36915 bsc#1225758).
  - commit e4ca26d
  - rpm/kernel-obs-build.spec.in: Add networking modules for docker
    (bsc#1226211)
    docker needs more networking modules, even legacy iptable_nat and _filter.
  - commit 415e132

++++ dav1d:

  - Update to version 1.4.3
    * AArch64: Fix potential out of bounds access in DotProd H/HV
    filters
    * cli: Prevent buffer over-read

++++ libpng16:

  - Backport patch to fix PAC/BTI support on aarch64:
    * 563.patch

++++ libxml2:

  - Update to version 2.12.8:
    + parser: Fix performance regression when parsing namespaces.

++++ python-anyio:

  - update to 4.4.0:
    * Added the BlockingPortalProvider class to aid with
    constructing synchronous counterparts to asynchronous
    interfaces that would otherwise require multiple blocking
    portals
    * Added __slots__ to AsyncResource so that child classes can
    use __slots__
    * Added the TaskInfo.has_pending_cancellation() method
    * Fixed erroneous RuntimeError: called 'started' twice on the
    same task status when cancelling a task in a TaskGroup
    created with the start() method before the first checkpoint
    is reached after calling task_status.started()
    * Fixed two bugs with TaskGroup.start() on asyncio: Fixed
    erroneous RuntimeError: called 'started' twice on the same
    task status when cancelling a task in a TaskGroup created
    with the start() method before the first checkpoint is
    reached after calling task_status.started() (#706; PR by
    Dominik Schwabe) Fixed the entire task group being cancelled
    if a TaskGroup.start() call gets cancelled (#685, #710)
    * Fixed erroneous RuntimeError: called 'started' twice on the
    same task status when cancelling a task in a TaskGroup
    created with the start() method before the first checkpoint
    is reached after calling task_status.started()
    * Fixed the entire task group being cancelled if a
    TaskGroup.start() call gets cancelled
    * Fixed a race condition that caused crashes when multiple
    event loops of the same backend were running in separate
    threads and simultaneously attempted to use AnyIO for their
    first time
    * Fixed cancellation delivery on asyncio incrementing the wrong
    cancel scope's cancellation counter when cascading a cancel
    operation to a child scope, thus failing to uncancel the host
    task
    * Fixed erroneous TypedAttributeLookupError if a typed
    attribute getter raises KeyError
    * Fixed the asyncio backend not respecting the
    PYTHONASYNCIODEBUG environment variable when setting the
    debug flag in anyio.run()
    * Fixed SocketStream.receive() not detecting EOF on asyncio if
    there is also data in the read buffer
    * Fixed MemoryObjectStream dropping an item if the item is
    delivered to a recipient that is waiting to receive an item
    but has a cancellation pending
    * Emit a ResourceWarning for MemoryObjectReceiveStream and
    MemoryObjectSendStream that were garbage collected without
    being closed (PR by Andrey Kazantcev)
    * Fixed MemoryObjectSendStream.send() not raising
    BrokenResourceError when the last corresponding
    MemoryObjectReceiveStream is closed while waiting to send a
    falsey item

++++ libxml2-python:

  - Update to version 2.12.8:
    + parser: Fix performance regression when parsing namespaces.

------------------------------------------------------------------
------------------  2024-6-11  -  Jun 11 2024  -------------------
------------------------------------------------------------------

++++ cups:

  - cups-2.4.8-CVE-2024-35235.patch is derived
    from the upstream patch against master (CUPS 2.5)
    to apply to CUPS 2.4.8 in openSUSE Factory to fix CVE-2024-35235
    "cupsd Listen port arbitrary chmod 0140777"
    https://github.com/OpenPrinting/cups/security/advisories/GHSA-vvwp-mv6j-hw6f
    bsc#1225365

++++ python-kiwi:

  - Fix displaying the image verification failure dialog
    Kiwi must wait for the previous dialog to finish before showing another
    one as it's the same systemd service behind it.

++++ glib2:

  - Update to version 2.80.3:
    + Bugs fixed:
  - g_socket_client_connect_to_host_async leaks memory when
    target host doesn't respond to ARP.
  - gi_repository_find_by_gtype is nondeterministic.
  - Crash in error path of g_dbus_connection_export_menu_model().
  - Backport !4057 “gdbusmessage: Clean the cached arg0 when
    setting the message body” to glib-2-80.
  - Backport !4058 “Tests: Build fixes when running `meson test`
    without previous builds“ to glib-2-80
  - Partially backport !4059 “tests: Fix various memory leaks and
    valgrind / ASAN errors” to glib-2-80
  - Backport !4066 “Fix several GCC 14 warnings to please
    msys2-mingw32 CI” to glib-2-80
  - Backport !4065 “girepository: Don't assume a bitfield has a
    fixed size” to glib-2-80
  - Backport !4073 “gmenuexporter: Fix a NULL pointer dereference
    on an error handling path” to glib-2-80
  - Backport !4078 “tests: Fix clang compilation failure due to
    unrecognised option in pragma” to glib-2-80.
  - Backport !4033 “girepository: Keep an ordered list of the
    loaded typelibs” to glib-2-80
  - Backport !4104 “gsocketclient: Fix a leak of the task data on
    an error path” to glib-2-80
    + Updated translations.

++++ kernel-default:

  - rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation
    (CVE-2024-36017 bsc#1225681).
  - commit 349b81e
  - mm: use memalloc_nofs_save() in page_cache_ra_order()
    (bsc#1225723 CVE-2024-36882).
  - commit 858537f
  - blk-iocost: avoid out of bounds shift (bsc#1225759
    CVE-2024-36916).
  - commit 9e35e70
  - netfilter: complete validation of user input
    (git-fixes CVE-2024-35896 bsc#1224662).
  - commit a54ae57
  - net: hns3: fix kernel crash when devlink reload during
    initialization (CVE-2024-36900 bsc#1225726).
  - net: hns3: release PTP resources if pf initialization failed
    (CVE-2024-36900 bsc#1225726).
  - commit ad59124
  - blk-mq: make sure active queue usage is held for
    bio_integrity_prep() (bsc#1225105 CVE-2023-52787).
  - commit 6131890
  - block: prevent division by zero in blk_rq_stat_sum()
    (bsc#1224661 CVE-2024-35925).
  - commit 7339ca3
  - Update refs for patches.suse/nbd-fix-uaf-in-nbd_open.patch (bsc#1216436
    bsc#1224935 CVE-2023-52837).
  - commit 95ff8cb
  - netfilter: validate user input for expected length
    (CVE-2024-35896 bsc#1224662).
  - commit 6a29de4
  - ext4: fix corruption during on-line resize (bsc#1224735
    CVE-2024-35807).
  - commit 751677a
  - ext4: fix racy may inline data check in dio write (bsc#1224939
    CVE-2023-52786).
  - commit 742009f
  - ext4: avoid online resizing failures due to oversized flex bg
    (bsc#1222080 CVE-2023-52622).
  - commit 817510d
  - arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
    (git-fixes).
  - commit d2efb00
  - net: mana: Enable MANA driver on ARM64 with 4K page size
    (jsc#PED-8491).
  - Update config files.
  - commit 5211306
  - bna: ensure the copied buf is NUL terminated (CVE-2024-36934
    bsc#1225760).
  - ice: ensure the copied buf is NUL terminated (CVE-2024-36935
    bsc#1225763).
  - commit ab36d7d
  - xdp: use flags field to disambiguate broadcast redirect
    (bsc#1225834 CVE-2024-36937).
  - commit de0720c
  - fs/pipe: move check to pipe_has_watch_queue() (bsc#1224614
    CVE-2023-52672).
  - commit 66a9a3f

++++ kernel-rt:

  - rtnetlink: Correct nested IFLA_VF_VLAN_LIST attribute validation
    (CVE-2024-36017 bsc#1225681).
  - commit 349b81e
  - mm: use memalloc_nofs_save() in page_cache_ra_order()
    (bsc#1225723 CVE-2024-36882).
  - commit 858537f
  - blk-iocost: avoid out of bounds shift (bsc#1225759
    CVE-2024-36916).
  - commit 9e35e70
  - netfilter: complete validation of user input
    (git-fixes CVE-2024-35896 bsc#1224662).
  - commit a54ae57
  - net: hns3: fix kernel crash when devlink reload during
    initialization (CVE-2024-36900 bsc#1225726).
  - net: hns3: release PTP resources if pf initialization failed
    (CVE-2024-36900 bsc#1225726).
  - commit ad59124
  - blk-mq: make sure active queue usage is held for
    bio_integrity_prep() (bsc#1225105 CVE-2023-52787).
  - commit 6131890
  - block: prevent division by zero in blk_rq_stat_sum()
    (bsc#1224661 CVE-2024-35925).
  - commit 7339ca3
  - Update refs for patches.suse/nbd-fix-uaf-in-nbd_open.patch (bsc#1216436
    bsc#1224935 CVE-2023-52837).
  - commit 95ff8cb
  - netfilter: validate user input for expected length
    (CVE-2024-35896 bsc#1224662).
  - commit 6a29de4
  - ext4: fix corruption during on-line resize (bsc#1224735
    CVE-2024-35807).
  - commit 751677a
  - ext4: fix racy may inline data check in dio write (bsc#1224939
    CVE-2023-52786).
  - commit 742009f
  - ext4: avoid online resizing failures due to oversized flex bg
    (bsc#1222080 CVE-2023-52622).
  - commit 817510d
  - arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
    (git-fixes).
  - commit d2efb00
  - net: mana: Enable MANA driver on ARM64 with 4K page size
    (jsc#PED-8491).
  - Update config files.
  - commit 5211306
  - bna: ensure the copied buf is NUL terminated (CVE-2024-36934
    bsc#1225760).
  - ice: ensure the copied buf is NUL terminated (CVE-2024-36935
    bsc#1225763).
  - commit ab36d7d
  - xdp: use flags field to disambiguate broadcast redirect
    (bsc#1225834 CVE-2024-36937).
  - commit de0720c
  - fs/pipe: move check to pipe_has_watch_queue() (bsc#1224614
    CVE-2023-52672).
  - commit 66a9a3f

++++ bluez:

  - Fix python3 shebang from test files (bsc#1212476)

++++ perl:

  - update to 5.40.0
    * New __CLASS__ Keyword
    * :reader attribute for field variables
    * Permit a space in -M command-line option
    * Restrictions to use VERSION declarations
    * New builtin::inf and builtin::nan functions (experimental)
    * New ^^ logical xor operator
    * try/catch feature is no longer experimental
    * for iterating over multiple values at a time is no longer experimental
    * builtin module is no longer experimental
    * The :5.40 feature bundle adds try
    * use v5.40; imports builtin functions
    * CVE-2023-47038 - Write past buffer end via illegal user-defined Unicode property
    * CVE-2023-47039 - Perl for Windows binary hijacking vulnerability
    * reset EXPR now calls set-magic on scalars
    * Calling the import method of an unknown package produces a warning
    * return no longer allows an indirect object
    * Class barewords no longer resolved as file handles in method calls
    under no feature "bareword_filehandles"
    * Using goto to jump from an outer scope into an inner scope is
    deprecated and will be removed completely in Perl 5.42. [GH #21601]
    * The negation OPs have been modified to support the generic TARGMY
    optimization. [GH #21442]
  - Refresh perl-5.38.0.diff
  - Drop perl-5.18.2-overflow.diff (no longer applicable)
  - Drop perl-locale-backport.diff (proper fix in new version)
  - Drop old manual package name based perl provides

++++ virt-manager:

  - bsc#1226173 - virt-manager: Browse local does not work anymore
    090-db1b2fbc-Use-GtkFileChooserNative.patch
    Renamed 090-uitests-Fix-with-GtkFileChooserNative.patch to
    091-uitests-Fix-with-GtkFileChooserNative.patch

------------------------------------------------------------------
------------------  2024-6-10  -  Jun 10 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Allow to customize the path of the isoscan cowfile
    Added rd.live.cowfile.path option to specify the cowfile at
    any path below the isoscan-loop-mount. This Fixes #2554
  - Better error handling on grub vendor dir lookup
    The strings command is used to lookup the in-efi binary encoded
    vendor path. However, if the strings or bash command is not availabe
    on the build host, the command silently failed and moved into the
    standard (non vendored) EFI boot path. This can lead to a broken
    boot for those distros and image targets which requires a vendor
    directory and should lead to an error message instead of a
    successful image build. This Fixes #2565
  - Fixed profile variable settings for preferences
    It's allowed to have multiple preferences sections. If those
    sections provides the same value multiple times, e.g keytable,
    the last one in the row will win. The setup of the variables
    in .profile environment file for the preferences elements is
    not following this rule and used the first section not the
    last. This commit fixes the profile variables to match the
    actual setup and Fixes #2560

++++ haproxy:

  - Update to version 3.0.1+git0.471a1b2f1:
    * [RELEASE] Released version 3.0.1
    * BUG/MINOR: mux-h1: Use the right variable to set NEGO_FF_FL_EXACT_SIZE flag
    * BUG/MAJOR: mux-h1:  Properly copy chunked input data during zero-copy nego
    * BUG/MEDIUM: stconn/mux-h1: Fix suspect change causing timeouts
    * BUG/MINOR: quic: ensure Tx buf is always purged
    * BUG/MINOR: quic: fix computed length of emitted STREAM frames
    * BUG/MEDIUM: ssl: bad auth selection with TLS1.2 and WolfSSL
    * BUG/MEDIUM: ssl: wrong priority whem limiting ECDSA ciphers in ECDSA+RSA configuration
    * BUG/MEDIUM: mux-quic: Don't unblock zero-copy fwding if blocked during nego
    * CLEANUP: hlua: simplify ambiguous lua_insert() usage in hlua_ctx_resume()
    * BUG/MINOR: hlua: fix leak in hlua_ckch_set() error path
    * BUG/MINOR: hlua: prevent LJMP in hlua_traceback()
    * BUG/MINOR: hlua: fix unsafe hlua_pusherror() usage
    * BUG/MINOR: hlua: don't use lua_pushfstring() when we don't expect LJMP
    * CLEANUP: hlua: use hlua_pusherror() where relevant
    * BUG/MINOR: quic: prevent crash on qc_kill_conn()
    * BUG/MEDIUM: mux-quic: Unblock zero-copy forwarding if the txbuf can be released
    * MEDIUM: stconn: Be able to unblock zero-copy data forwarding from done_fastfwd
    * BUG/MEDIUM: h1-htx: Don't state interim responses are bodyless
    * BUG/MINOR: hlua: use CertCache.set() from various hlua contexts
    * DOC: configuration: add an example for keywords from crt-store
    * BUG/MINOR: tools: fix possible null-deref in env_expand() on out-of-memory
    * BUG/MINOR: tcpcheck: report correct error in tcp-check rule parser
    * BUG/MINOR: cfgparse: remove the correct option on httpcheck send-state warning

++++ ignition:

  - Update to version 2.19.0:
    * Support LUKS encryption using IBM CEX secure keys on s390x
    * providers: add "akamai" provider
  - Adding %check section
  - Build scripts are executable by themselves now, remove explicit
    Bash call

++++ kernel-default:

  - tipc: Change nla_policy for bearer-related names to NLA_NUL_STRING
    (CVE-2023-52845 bsc#1225585).
  - commit a73a0ca
  - pipe: wakeup wr_wait after setting max_usage (bsc#1224614
    CVE-2023-52672).
  - commit 333fe30
  - netfilter: nf_tables: honor table dormant flag from netdev release event path
    (CVE-2024-36005 bsc#1224539).
  - commit 5b08b61

++++ kernel-rt:

  - tipc: Change nla_policy for bearer-related names to NLA_NUL_STRING
    (CVE-2023-52845 bsc#1225585).
  - commit a73a0ca
  - pipe: wakeup wr_wait after setting max_usage (bsc#1224614
    CVE-2023-52672).
  - commit 333fe30
  - netfilter: nf_tables: honor table dormant flag from netdev release event path
    (CVE-2024-36005 bsc#1224539).
  - commit 5b08b61

++++ util-linux-systemd:

  - disable libmagic in more(1) for binary detection (bsc#1225197)

++++ util-linux:

  - disable libmagic in more(1) for binary detection (bsc#1225197)

++++ c-ares:

  - c-ares 1.30.0
    Features:
    * Basic support for SIG RR record (RFC 2931 / RFC 2535) [PR #773]
    Changes:
    * Validation that DNS strings can only consist of printable ascii characters
    otherwise will trigger a parse failure. [75de16c] and [40fb125]
    Bugfixes:
    * QueryCache: Fix issue where purging on server changes wasn't working. [a6c8fe6]
  - updated dowload URLs to point to github
  - updated keyring to include Brad House DA7D64E4C82C6294CB73A20E22E3D13B5411B7CA

++++ libeconf:

  - Update to version 0.7.1:
    * Improved error handling while parsing values with the wrong format.
    Added new return value ECONF_VALUE_CONVERSION_ERROR.
    * Setting parsing options via econf_file struct.
    see econf_newKeyFile_with_options. These options will be used by
    econf_readConfig and econf_readConfigWithCallback.
    Following options are supported:
    JOIN_SAME_ENTRIES  (default 0)
    Parsed entries with the same name will not be replaces but
    will be joined to one entry.
    PYTHON_STYLE  (default 0)
    E.G. Identations will be handled like multiline entries.
    PARSING_DIRS (default /usr/etc/:/run:/etc)
    List of directories from which the configuration files have to be parsed.
    The list is a string, divides by ":". The last entry has the highest
    priority. E.g.: "PARSING_DIRS=/usr/etc/:/run:/etc"
    CONFIG_DIRS (default <empty>)
    List of directory structures (with order) which describes the directories
    in which the files have to be parsed.
    The list is a string, divides by ":". The last entry has the highest
    priority. E.g. with the given list: "CONFIG_DIRS=.conf.d:.d" files in
    following directories will be parsed:
    "<default_dirs>/<config_name>.conf.d/"
    "<default_dirs>/<config_name>.d/"
    "<default_dirs>/<config_name>/"
    * CAUTION: From now on every econf_file element MUST be intialized if
    econf_readConfig and econf_readConfigWithCallback is used.
    Either with NULL or:
    econf_file *key_file = NULL;
    if (error = econf_newKeyFile_with_options(&key_file, "PYTHON_STYLE=1"))
    {
    fprintf (stderr, "ERROR: couldn't create new key file: %s\n",
    econf_errString(error));
    return 1;
    }
    error = econf_readConfig (&key_file,
    "foo",
    "/usr/lib",
    "example",
    "conf",
    "=", "#");

++++ ncurses:

  - Add ncurses patch 20240608
    + change winwstr to return wide character count instead of OK (patch
    by Branden Robinson).
    + improve formatting/style of manpages (patches by Branden Robinson).
    + rename testing dpkg's for ncurses6 to resolve a naming conflict with
    Debian's ncurses packages.

++++ openssl-3:

  - FIPS: Port openssl to use jitterentropy [bsc#1220523]
    * Set the module in error state if the jitter RNG fails either on
    initialization or entropy gathering because health tests failed.
    * Add jitterentropy as a seeding source output also in crypto/info.c
    * Move the jitter entropy collector and the associated lock out
    of the header file to avoid redefinitions.
    * Add the fips_local.cnf symlink to the spec file. This simlink
    points to the openssl_fips.config file that is provided by the
    crypto-policies package.
    * Rebase openssl-3-jitterentropy-3.4.0.patch
    * Rebase openssl-FIPS-enforce-EMS-support.patch

++++ pango:

  - Update to version 1.54.0:
    + Build fixes.
    + Memory leak fixes.
    + Drop the install-tests build option.
    + Add build-examples and build-tests build options.
    + Require meson 0.63.
    + Add pango_item_get_char_offset.
    + Update to Unicode 15.1.
    + Fix wrong use of GWeakRef, leading to crashes.
  - Drop -Dinstall-tests meson parameter: no longer supported.

++++ openssh:

  - Add #include <stdlib.h> in some files added by the ldap patch to
    fix build with gcc14 (boo#1225904).
    * openssh-7.7p1-ldap.patch

------------------------------------------------------------------
------------------  2024-6-9  -  Jun 9 2024  -------------------
------------------------------------------------------------------

++++ pciutils:

  - update to 3.12.0:
    * lspci decodes the IDE (Integrity & Data Encryption) and
    TEE-IO extended capabilities.
    * Optimization flags used for compiling individual object files
    should be the same as optimization flags for linking the final
    executable to make link-time optimization possible.
    * no longer look up subsystems in the HWDB
    * Updated pci.ids
  - include changes from 3.11:
    * update-pciids now supports XZ compression
    * update-pciids now sends itself as the User-Agent.
    * Added a pcilmr utility for PCIe lane margining
    * ECAM back-end now scans ACPI and BIOS memory faster.
    * Linux systems without pread/pwrite are no longer supported
    * Improved decoding of PCIe control and status registers.
    * Decoding of CXL capabilities now supports up to CXL 3.0.
    * lspci now displays interrupt message numbers consistently across
    different capabilities.
    * Cache of IDs resolved via DNS, which was located in ~/.pci-ids
    by default, is now stored according to the XDG base directory
    specification in $XDG_CACHE_HOME/pci-ids.
    * All source files now have SPDX license identifiers.
    * various minor bug fixes and updated pci.ids.

------------------------------------------------------------------
------------------  2024-6-8  -  Jun 8 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - scsi: target: core: Add TMF to tmr_list handling (bsc#1223018
    CVE-2024-26845).
  - commit 6b81c05

++++ kernel-rt:

  - scsi: target: core: Add TMF to tmr_list handling (bsc#1223018
    CVE-2024-26845).
  - commit 6b81c05

++++ python-cryptography:

  - update to 42.0.8:
    * Updated Windows, macOS, and Linux wheels to be compiled with
    OpenSSL 3.2.2.

++++ python-typing_extensions:

  - update to 4.12.2:
    * Fix regression in v4.12.0 where specialization of certain
    * generics with an overridden `__eq__` method would raise
    errors.
    * Fix tests so they pass on 3.13.0b2
    * Preliminary changes for compatibility with the draft
    implementation of PEP 649 in Python 3.14.
    * Fix regression in v4.12.0 where nested `Annotated` types
    would cause `TypeError` to be raised if the nested
    `Annotated` type had unhashable metadata.
    * Fix incorrect behaviour of `typing_extensions.ParamSpec` on
    Python 3.8 and 3.9 that meant that
    `isinstance(typing_extensions.ParamSpec("P"),
    typing.TypeVar)` would have a different result in some
    situations depending on whether or not a profiling
    function had been set using `sys.setprofile`.
    * This release focuses on compatibility with the upcoming
    release of Python 3.13. Most changes are related to the
    implementation of type parameter defaults (PEP 696).

++++ xkeyboard-config:

  - update to 2.42:
    * Translations updated

------------------------------------------------------------------
------------------  2024-6-7  -  Jun 7 2024  -------------------
------------------------------------------------------------------

++++ fde-tools:

  - Update fde-tools-bsc1220160-conditional-requires.patch to
    check fde-tpm-helper in %post and %posttrans

++++ grub2:

  - Add blscfg support
    * 0001-blscfg-add-blscfg-module-to-parse-Boot-Loader-Specif.patch
    * 0002-Add-BLS-support-to-grub-mkconfig.patch
    * 0003-Add-grub2-switch-to-blscfg.patch
    * 0004-blscfg-Don-t-root-device-in-emu-builds.patch
    * 0005-blscfg-check-for-mounted-boot-in-emu.patch
    * 0006-Follow-the-device-where-blscfg-is-discovered.patch
    * 0007-grub-switch-to-blscfg-adapt-to-openSUSE.patch
    * 0008-blscfg-reading-bls-fragments-if-boot-present.patch
    * 0009-10_linux-Some-refinement-for-BLS.patch

++++ kernel-default:

  - iommu: mtk: fix module autoloading (git-fixes).
  - commit 50334e4
  - iommu/amd: Enhance def_domain_type to handle untrusted device
    (git-fixes).
  - commit 9d0dd7f
  - iommu: Undo pasid attachment only for the devices that have
    succeeded (git-fixes).
  - commit 4de170c
  - net/sched: fix lockdep splat in qdisc_tree_reduce_backlog()
    (CVE-2024-35892 bsc#1224515).
  - commit e8fcaf3
  - eeprom: at24: fix memory corruption race condition (bsc#1224612
    CVE-2024-35848).
  - commit 269cd6c
  - udp: do not accept non-tunnel GSO skbs landing in a tunnel
    (CVE-2024-35884 bsc#1224520).
  - commit 78d5dd0
  - Kabi workaround for icmp: prevent possible NULL dereferences from
    icmp_build_probe() (CVE-2024-35857 bsc#1224619).
  - icmp: prevent possible NULL dereferences from icmp_build_probe()
    (CVE-2024-35857 bsc#1224619).
  - commit fa789e3

++++ kernel-rt:

  - iommu: mtk: fix module autoloading (git-fixes).
  - commit 50334e4
  - iommu/amd: Enhance def_domain_type to handle untrusted device
    (git-fixes).
  - commit 9d0dd7f
  - iommu: Undo pasid attachment only for the devices that have
    succeeded (git-fixes).
  - commit 4de170c
  - net/sched: fix lockdep splat in qdisc_tree_reduce_backlog()
    (CVE-2024-35892 bsc#1224515).
  - commit e8fcaf3
  - eeprom: at24: fix memory corruption race condition (bsc#1224612
    CVE-2024-35848).
  - commit 269cd6c
  - udp: do not accept non-tunnel GSO skbs landing in a tunnel
    (CVE-2024-35884 bsc#1224520).
  - commit 78d5dd0
  - Kabi workaround for icmp: prevent possible NULL dereferences from
    icmp_build_probe() (CVE-2024-35857 bsc#1224619).
  - icmp: prevent possible NULL dereferences from icmp_build_probe()
    (CVE-2024-35857 bsc#1224619).
  - commit fa789e3

++++ openssl-3:

  - FIPS: Block non-Approved Elliptic Curves [bsc#1221786]
    * Add patches
  - openssl-Add-changes-to-ectest-and-eccurve.patch
  - openssl-Remove-EC-curves.patch
  - openssl-Disable-explicit-ec.patch
  - openssl-skipped-tests-EC-curves.patch
  - openssl-FIPS-services-minimize.patch
  - FIPS: Service Level Indicator [bsc#1221365]
    * Add patches:
  - openssl-FIPS-Expose-a-FIPS-indicator.patch
  - openssl-FIPS-Remove-X9.31-padding-from-FIPS-prov.patch
  - openssl-FIPS-Use-digest_sign-digest_verify-in-self-test.patch
  - openssl-FIPS-RSA-disable-shake.patch
  - openssl-FIPS-signature-Add-indicator-for-PSS-salt-length.patch
  - openssl-FIPS-Add-explicit-indicator-for-key-length.patch
  - openssl-FIPS-limit-rsa-encrypt.patch
  - openssl-FIPS-enforce-EMS-support.patch
  - openssl-3-FIPS-GCM-Implement-explicit-indicator-for-IV-gen.patch
  - openssl-FIPS-services-minimize.patch
  - openssl-Add-FIPS-indicator-parameter-to-HKDF.patch
  - openssl-rand-Forbid-truncated-hashes-SHA-3-in-FIPS-prov.patch
  - openssl-FIPS-enforce-security-checks-during-initialization.patch
  - TODO: incomplete
  - FIPS: Output the FIPS-validation name and module version which uniquely
    identify the FIPS validated module. [bsc#1221751]
    * Add openssl-FIPS-release_num_in_version_string.patch
  - FIPS: Add required selftests: [bsc#1221760]
    * Add patches
  - openssl-FIPS-Use-digest_sign-digest_verify-in-self-test.patch
  - openssl-FIPS-Use-FFDHE2048-in-self-test.patch
  - openssl-FIPS-early-KATS.patch
  - openssl-FIPS-Use-OAEP-in-KATs-support-fixed-OAEP-seed.patch
  - openssl-FIPS-140-3-keychecks.patch
  - FIPS: DH: Disable FIPS 186-4 Domain Parameters [bsc#1221821]
    Add openssl-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch
  - FIPS: Recommendation for Password-Based Key Derivation [bsc#1221827]
    * Add additional check required by FIPS 140-3. Minimum value for
    PBKDF2 password is 20 characters.
    * Add patches:
  - openssl-pbkdf2-Set-minimum-password-length-of-8-bytes.patch
  - openssl-pbkdf2-Set-indicator-if-pkcs5-param-disabled-checks.patch
  - FIPS: Zeroization is required [bsc#1221752]
    * Add openssl-FIPS-140-3-zeroization.patch
  - FIPS: Reseed DRBG [bsc#1220690, bsc#1220693, bsc#1220696]
    * Enable prediction resistance for primary DRBG
    * Add oversampling of the noise source to comply with requirements of
    NIST SP 800-90C
    * Change CRNG buf size to align with output size of the Jitter RNG
    * Add openssl-FIPS-140-3-DRBG.patch
  - FIPS: NIST SP 800-56Brev2 [bsc#1221824]
    * Add patches:
  - openssl-FIPS-limit-rsa-encrypt.patch
  - openssl-FIPS-RSA-encapsulate.patch
  - openssl-FIPS-Add-SP800-56Br2-6.4.1.2.1-3.c-check.patch
  - FIPS: Approved Modulus Sizes for RSA Digital Signature for FIPS 186-4 [bsc#1221787]
    * Add patches:
  - openssl-FIPS-services-minimize.patch
  - openssl-Revert-Improve-FIPS-RSA-keygen-performance.patch
  - openssl-Allow-disabling-of-SHA1-signatures.patch
  - openssl-Allow-SHA1-in-seclevel-2-if-rh-allow-sha1-signatures.patch
  - FIPS: Port openssl to use jitterentropy [bsc#1220523]
    * Add openssl-3-jitterentropy-3.4.0.patch
    * Add build dependency on jitterentropy-devel >= 3.4.0 and
    libjitterentropy3 >= 3.4.0
  - FIPS: NIST SP 800-56Arev3 [bsc#1221822]
    * Add openssl-FIPS-140-3-keychecks.patch
  - FIPS: Error state has to be enforced [bsc#1221753]
    * Add patches:
  - openssl-FIPS-140-3-keychecks.patch
  - openssl-FIPS-Enforce-error-state.patch

++++ libsolv:

  - add a conflict to older libsolv-tools to libsolv-tools-base
  - report unsupported compression in solv_xfopen() with errno
  - fix return value of repodata.add_solv() in the bindings
  - fix SHA-224 oid in solv_pgpvrfy

++++ sysstat:

  - version update to 12.7.5
    2023/12/17: Version 12.7.5 - Sebastien Godard (sysstat <at> orange.fr)
    * [Quan quan Cao]: sar/sadc: Add new metrics pgprom/s and pgdem/s.
    * sar: Remove %vmeff metric.
    * sadf: Update various output formats to take into account metrics
    that have been added or removed.
    * Update DTD and XSD documents.
    * Update sar manual page.
    * sar: Add a cron entry and a new systemd service and timer to rotate
    daily data file at midnight.
    * Option -V with sysstat commands also displays environment contents.
    * [Sam Morris]: Use correct encoding to produce hyphen-minus when
    rendering man pages.
    * Add UMASK variable definition to sysstat(5) manual page.
    * Update non regression tests.
    * Add --getenv option to commands that didn't have it.
    * Update README file for Debian-based distros.
    * Update link to my personal web page in README and manual pages.
    * NLS: Translations updated.
    2023/06/18: Version 12.7.4 - Sebastien Godard (sysstat <at> orange.fr)
    * Makefile.in: Fix installation error.
    * Makefile.in: Remove gcc warning displayed in LTO mode.
    2023/06/16: Version 12.7.3 - Sebastien Godard (sysstat <at> orange.fr)
    * sar: Add new option '-x' used to display extended reports.
    * [Pavel Kopylov]: Fix an overflow which is still possible for
    some values.
    * [Jan Kurik]: Fix export of PSI metrics to a PCP archive.
    * [Lukáš Zaoral]: Tools that take `--dec=X` option should only accept
    digits.
    * common.c: Fix an overflow which was still possible for some values.
    * iostat: Try to avoid displaying negative values.
    * Free pointer if realloc() fails.
    * Don't check if unsigned expressions are less than zero.
    * Declare parameters with "const" when possible.
    * Remove conditions which are always true.
    * Reduce variables scope when relevant.
    * Don't assign values that are never used.
    * Fix types used in format strings.
    * Split large functions into smaller ones.
    * Specify field width when using sscanf() function.
    * search_list_item(): Return position in list instead of a boolean.
    * add_list_item(): Also return item position in list.
    * svg_stats.c: Ignore negative values for fields position.
    * svg_stats.c: Reuse buffers pointers definition.
    * svg_stats.c: Reuse intermediate calculations.
    * svg_stats.c: Don't repeat test on DISPLAY_CPU_DEF().
    * sa_common.c: Don't use (void *) pointer in calculation.
    * iostat.c: Clarify calculation precedence for '+' and '?'.
    * sar/sadf: Refactor buffer allocation functions.
    * sar/sadf: Add a check on file's records header data.
    * sar/sadf: Stop when invalid data are read in records header.
    * sar/sadf: Check upper bounds of value read from file.
    * sadf_misc.c: Fix indentation in code.
    * activity.c: Init item_list even for other commands than sadf.
    * sa_conv.c: Reallocate buffers only when needed.
    * sa_conv.c: Fix untrusted allocation size.
    * pr_stats.c: Remove some dead code.
    * sar.c: Make sure buffer is null terminated.
    * do_test: Add several new options.
    * do_test: Don't strip binaries when in TEST mode.
    * Update non regression tests.
    * simtest: Change default _unix_time value.
    * Makefile.in: Simplify dependencies.
    * Makefile_in: Small update made to copyyear target.
    * sadf: XML: Update DTD and XSD documents.
    * sadf: XML: Remove references to my personal web site.
    * Restore mode for iconfig file.
    * Fix typo in sar's manual page. Sar manual page updated.
    * Other manual pages updated.
    2023/01/29: Version 12.7.2 - Sebastien Godard (sysstat <at> orange.fr)
    * All commands: Avoid displaying healthy metrics values in "red".
    * sar/sadf: Add new activity: Battery statistics (A_PWR_BAT).
    * [Kevin Stubbings]: Add CodeQL workflow.
    * sar: Make sure timestamps are always displayed in local time.
    * sar/sadf: Starting and ending times used with options -s/-e can now
    be entered as a number of seconds since the epoch.
    * sar/sadf: Strengthen tests made on arguments given to options -s/-e.
    * sadf: PCP: Fix pmiID used for two USB metrics [12.6.2].
    * [Nathanael P Wilson]: sadf: Fix extra space when no TZ printed.
    * sadc: Add another overflow check [12.6.2].
    * DTD and XSD documents updated.
    * Makefile: Fix dependencies.
    * NLS translations updated. New Belarusian translation added.
    * Remove LGTM links from README file.
    * Manual pages updated.
    * Non regression tests updated.
    2022/11/06: Version 12.7.1 - Sebastien Godard (sysstat <at> orange.fr)
    * Fix possible overflow in sa_common.c (GHSL-2022-074) [12.6.1].
    * sadf: Add support for option -t with SVG output to make it possible
    to display timestamps in the same locale as that of the file creator.
    * sadf: Print timezone instead of UTC in true time mode. Timezone is
    also displayed in local time.
    * sadf: PCP: Fix timestamps written to PCP archive file.
    * sar: Add new environment variable S_REPEAT_HEADER.
    * pidstat: Return exit code of the process that was monitored with option
  - e.
    * mpstat: Add option -H to handle vCPU physical hotplug.
    * Add local, xlocal and debug targets to iconfig script.
    * Turn off gcc's tree-slp-vectorize option which was making sadf crash
    in some situations.
    * sa_conv.c: Make size of statistics structures from older sysstat
    versions immutable [12.6.1].
    * [Bernhard M. Wiedemann]: Declare sadc dependency on libsyscom.a
    [12.6.1].
    * [Steve Kay]: Fix gcc v11.2 warnings [12.6.1].
    * [Steve Kay]: Various cosmetic fixes [12.6.1].
    * [Jan Christoph Uhde]: sar: Remove `-I int_list` from man-page and
    help [12.6.1].
    * [Frank Dana]: Consolidate systemctl commands in README file [12.6.1].
    * [Rong Tao]: Remove whitespace characters at the end of lines
    [12.6.1].
    * Update configure file to deal with newer autoconf version. configure.in
    file is renamed to configure.ac.
    * Update DTD and XSD documents.
    * sar and sysstat manual pages updated.
    * NLS updated. Add new Georgian translation.
    * Non regression tests updated.
  - modified patches
    % sysstat-8.0.4-pagesize.diff (refreshed)
    % sysstat-8.1.6-sa1sa2lock.diff (refreshed)
  - deleted patches
  - sysstat-CVE-2023-33204.patch (upstreamed)

------------------------------------------------------------------
------------------  2024-6-6  -  Jun 6 2024  -------------------
------------------------------------------------------------------

++++ docker:

  - Update to Docker 26.1.4-ce. See upstream changelog online at
    <https://docs.docker.com/engine/release-notes/26.1/#2614>
  - Rebase patches:
    * cli-0001-docs-include-required-tools-in-source-tree.patch

++++ python-kiwi:

  - Revise users.rst
  - REvise systemdeps.rst
  - Revise shell_scripts.rst
  - Add initrd boot option rd.kiwi.allow_plymouth
    By default kiwi stops plymouth if present and active in the
    initrd. Setting rd.kiwi.allow_plymouth will keep plymouth
    active in the initrd including all effects that might have
    to the available consoles. This is related to bsc#1214824
  - Drop use of obsolete tool isconsole
    isconsole was provided with the dropped kiwi-tools package.
    It was a simple C application that checked the capabilities
    of the current console. In the context of fbiterm it was just
    used to provide proper error messages which fbiterm on its
    own did not show. As also fbiterm is on its way to become
    obsolete and isconsole is already no longer present, it's ok
    to just drop that extra check and therefore keep the fbiterm
    mode functional if one manages to include fbiterm and its
    fonts into the initrd

++++ gettext-runtime:

  - Fix envsubst-mini:
    + Conflicts with the 'full' envsubst
    + Require 'this-is-only-for-build-envs': ensure this does not
    find it's way out of OBS onto installations.

++++ kernel-default:

  - io_uring/net: correct the type of variable (git-fixes).
  - commit 91963e3
  - sock_map: avoid race between sock_map_close and sk_psock_put
    (bsc#1225475 CVE-2023-52735).
  - commit 71eeba4
  - Update
    patches.suse/usb-dwc2-fix-possible-NULL-pointer-dereference-cause.patch
    (CVE-2023-52855 bsc#1225583).
    Adding references
  - commit 4b5e987
  - net: preserve kabi for sk_buff (CVE-2024-26921 bsc#1223138).
  - commit 7bf5961
  - inet: inet_defrag: prevent sk release while still in use
    (CVE-2024-26921 bsc#1223138).
  - commit 2016faf
  - perf ui browser: Avoid SEGV on title (git fixes).
  - commit 1578c22

++++ kernel-rt:

  - io_uring/net: correct the type of variable (git-fixes).
  - commit 91963e3
  - sock_map: avoid race between sock_map_close and sk_psock_put
    (bsc#1225475 CVE-2023-52735).
  - commit 71eeba4
  - Update
    patches.suse/usb-dwc2-fix-possible-NULL-pointer-dereference-cause.patch
    (CVE-2023-52855 bsc#1225583).
    Adding references
  - commit 4b5e987
  - net: preserve kabi for sk_buff (CVE-2024-26921 bsc#1223138).
  - commit 7bf5961
  - inet: inet_defrag: prevent sk release while still in use
    (CVE-2024-26921 bsc#1223138).
  - commit 2016faf
  - perf ui browser: Avoid SEGV on title (git fixes).
  - commit 1578c22

++++ openssl-3:

  - Apply "openssl-CVE-2024-4741.patch" to fix a use-after-free
    security vulnerability. Calling the function SSL_free_buffers()
    potentially caused memory to be accessed that was previously
    freed in some situations and a malicious attacker could attempt
    to engineer a stituation where this occurs to facilitate a
    denial-of-service attack. [CVE-2024-4741, bsc#1225551]

++++ python313-core:

  - Build experimental package python313-base-nogil with
  - -disable-gil option.
  - Fix doc package build
    gh#python/cpython#120150
  - Update to 3.13.0b2:
  - Security
  - gh-118773: Fixes creation of ACLs in os.mkdir() on Windows to
    work correctly on non-English machines.
  - gh-118486: os.mkdir() on Windows now accepts mode of 0o700 to
    restrict the new directory to the current user. This fixes
    CVE-2024-4030 affecting tempfile.mkdtemp() in scenarios where
    the base temporary directory is more permissive than the
    default.
  - Core and Builtins
  - gh-119724: Reverted improvements to error messages for elif/else
    statements not matching any valid statements, which made in hard
    to locate the syntax errors inside those elif/else blocks.
  - gh-119842: Honor PyOS_InputHook() in the new REPL. Patch by
    Pablo Galindo
  - gh-119821: Fix execution of annotation scopes within classes
    when globals is set to a non-dict. Patch by Jelle Zijlstra.
  - gh-119548: Add a clear command to the REPL. Patch by Pablo
    Galindo
  - gh-111999: Fix the signature of str.format_map().
  - gh-119560: An invalid assert in beta 1 has been removed. The
    assert would fail if PyState_FindModule() was used in an
    extension module’s init function before the module def had been
    initialized.
  - gh-119369: Fix deadlock during thread deletion in free-threaded
    build, which could occur when the GIL was enabled at runtime.
  - gh-119525: Fix deadlock involving _PyType_Lookup() cache in the
    free-threaded build when the GIL is dynamically enabled at
    runtime.
  - gh-119311: Fix bug where names are unexpectedly mangled in the
    bases of generic classes.
  - gh-119395: Fix bug where names appearing after a generic class
    are mangled as if they are in the generic class.
  - gh-119213: Non-builtin modules built with argument clinic were
    crashing if used in a subinterpreter before the main
    interpreter. The objects that were causing the problem by
    leaking between interpreters carelessly have been fixed.
  - gh-119011: Fixes type.__type_params__ to return an empty tuple
    instead of a descriptor.
  - gh-118692: Avoid creating unnecessary StopIteration instances
    for monitoring.
  - gh-119049: Fix displaying the source line for warnings created
    by the C API if the warnings module had not yet been imported.
  - gh-118844: Fix build failures when configuring with both
  - -disable-gil and --enable-experimental-jit.
  - gh-118921: Add copy() method for FrameLocalsProxy which returns
    a snapshot dict for local variables.
  - gh-117657: Fix data races on the field that stores a pointer to
    the interpreter’s main thread that occur in free-threaded
    builds.
  - gh-118507: Speedup os.path.isjunction() and os.path.lexists() on
    Windows with a native implementation.
  - gh-118561: Fix race condition in free-threaded build where
    list.extend() could expose uninitialised memory to concurrent
    readers.
  - gh-118263: Speed up os.path.splitroot() & os.path.normpath()
    with a direct C call.
  - gh-117195: Avoid assertion failure for debug builds when calling
    object.__sizeof__(1)
  - Library
  - gh-119819: Fix regression to allow logging configuration with
    multiprocessing queue types.
  - gh-117142: The ctypes module may now be imported in all
    subinterpreters, including those that have their own GIL.
  - gh-118835: Fix _pyrepl crash when using custom prompt with ANSI
    escape codes.
  - gh-117398: The _datetime module (C implementation for datetime)
    now supports being imported in multiple interpreters.
  - gh-89727: Fix issue with shutil.rmtree() where a RecursionError
    is raised on deep directory trees.
  - gh-89727: Partially fix issue with shutil.rmtree() where a
    RecursionError is raised on deep directory trees. A recursion
    error is no longer raised when rmtree.avoids_symlink_attacks is
    false.
  - gh-119118: Fix performance regression in the tokenize module by
    caching the line token attribute and calculating the column
    offset more efficiently.
  - gh-89727: Fix issue with os.fwalk() where a RecursionError was
    raised on deep directory trees by adjusting the implementation
    to be iterative instead of recursive.
  - gh-119588: zipfile.Path.is_symlink now assesses if the given
    path is a symlink.
  - gh-119555: Catch SyntaxError from compile() in the runsource()
    method of the InteractiveColoredConsole. Patch by Sergey B
    Kirpichev.
  - gh-113892: Now, the method sock_connect of
    asyncio.ProactorEventLoop raises a ValueError if given socket is
    not in non-blocking mode, as well as in other loop
    implementations.
  - gh-119443: The interactive REPL no longer runs with from
    __future__ import annotations enabled. Patch by Jelle Zijlstra.
  - gh-117398: Objects in the datetime C-API are now all statically
    allocated, which means better memory safety, especially when the
    module is reloaded. This should be transparent to users.
  - gh-118894: asyncio REPL now has the same capabilities as PyREPL.
  - gh-118911: In PyREPL, updated maybe-accept’s logic so that if
    the user hits Enter twice, they are able to terminate the block
    even if there’s trailing whitespace. Also, now when the user
    hits arrow up, the cursor is on the last functional line. This
    matches IPython’s behavior. Patch by Aya Elsayed.
  - gh-111201: Remove dependency to readline from the new Python
    REPL.
  - gh-119174: Fix high DPI causes turtledemo(turtle-graphics
    examples) windows blurry Patch by Wulian233 and Terry Jan Reedy
  - gh-119121: Fix a NameError happening in
    asyncio.staggered.staggered_race. This function is now tested.
  - gh-119113: Fix issue where pathlib.PurePath.with_suffix() didn’t
    raise TypeError when given None as a suffix.
  - gh-118643: Fix an AttributeError in the email module when
    re-fold a long address list. Also fix more cases of incorrect
    encoding of the address separator in the address list.
  - gh-58933: Make pdb return to caller frame correctly when f_trace
    of the caller frame is not set
  - gh-118895: Setting attributes on typing.NoDefault now raises
    AttributeError instead of TypeError.
  - gh-118868: Fixed issue where kwargs were no longer passed to the
    logging handler QueueHandler
  - gh-118851: ctx arguments to the constructors of ast node classes
    now default to ast.Load(). Patch by Jelle Zijlstra.
  - gh-118760: Restore the default value of tkiter.wantobjects to 1.
  - gh-118760: Fix errors in calling Tkinter bindings on Windows.
  - gh-118772: Allow typing.TypeVar instances without a default to
    follow instances without a default in some cases. Patch by Jelle
    Zijlstra.
  - gh-110863: os.path.realpath() now suppresses any OSError from
    os.readlink() when strict mode is disabled (the default).
  - gh-118033: Fix dataclasses.dataclass() not creating a
    __weakref__ slot when subclassing typing.Generic.
  - gh-106531: In importlib.resources, sync with importlib_resources
    6.3.2, including: MultiplexedPath now expects Traversable paths,
    deprecating string arguments to MultiplexedPath; Enabled support
    for resources in namespace packages in zip files; Fixed
    NotADirectoryError when calling files on a subdirectory of a
    namespace package.
  - gh-113978: Ignore warnings on text completion inside REPL.
  - gh-103956: Fix lack of newline characters in trace module output
    when line tracing is enabled but source code line for current
    frame is not available.
  - gh-92081: Fix missing spaces in email headers when the spaces
    are mixed with encoded 8-bit characters.
  - gh-103194: Prepare Tkinter for C API changes in Tcl 8.7/9.0 to
    avoid _tkinter.Tcl_Obj being unexpectedly returned instead of
    bool, str, bytearray, or int.
  - gh-87106: Fixed handling in inspect.Signature.bind() of keyword
    arguments having the same name as positional-only arguments when
    a variadic keyword argument (e.g. **kwargs) is present.
  - bpo-45767: Fix integer conversion in os.major(), os.minor(), and
    os.makedev(). Support device numbers larger than 2**63-1.
    Support non-existent device number (NODEV).
  - gh-67693: Fix urllib.parse.urlunparse() and
    urllib.parse.urlunsplit() for URIs with path starting with
    multiple slashes and no authority. Based on patch by Ashwin
    Ramaswami.
  - Tests
  - gh-119050: regrtest test runner: Add XML support to the refleak
    checker (-R option). Patch by Victor Stinner.  Buil- d
  - gh-119729: On POSIX systems, the pkg-config (.pc) filenames now
    include the ABI flags, which may include debug (“d”) and
    free-threaded (“t”). For example: * python-3.14.pc (default,
    non-debug build) * python-3.14d.pc (default, debug build) *
    python-3.14t.pc (free-threaded build)
  - gh-115119: Fall back to the bundled libmpdec if a system version
    cannot be found.
  - gh-119132: Update sys.version to identify whether the build is
    default build or free-threading build. Patch By Donghee Na.
  - gh-118836: Fix an AssertionError when building with
  - -enable-experimental-jit and the compiler emits a SHT_NOTE
    section.
  - gh-118943: Fix a possible race condition affecting parallel
    builds configured with --enable-experimental-jit, in which
    compilation errors could be caused by an incompletely-generated
    header file.
  - Windows
  - gh-119679: Ensures correct import libraries are included in
    Windows installs.
  - gh-119690: Adds Unicode support and fixes audit events for
    _winapi.CreateNamedPipe.
  - gh-111201: Add support for new pyrepl on Windows
  - gh-119070: Fixes py.exe handling of shebangs like /usr/bin/env
    python3.12, which were previously interpreted as python3.exe
    instead of python3.12.exe.
  - gh-117505: Fixes an issue with the Windows installer not running
    ensurepip in a fully isolated environment. This could cause
    unexpected interactions with the user site-packages.
  - gh-118209: Avoid crashing in mmap on Windows when the mapped
    memory is inaccessible due to file system errors or access
    violations.
  - gh-116145: Updated bundled Tcl/Tk to 8.6.14.
  - C API
  - gh-119585: Fix crash when a thread state that was created by
    PyGILState_Ensure() calls a destructor that during
    PyThreadState_Clear() that calls back into PyGILState_Ensure()
    and PyGILState_Release(). This might occur when in the
    free-threaded build or when using thread-local variables whose
    destructors call PyGILState_Ensure().
  - gh-119336: Restore the removed _PyLong_NumBits() function. It is
    used by the pywin32 project. Patch by Ethan Smith
  - gh-119247: Added Py_BEGIN_CRITICAL_SECTION_SEQUENCE_FAST and
    Py_END_CRITICAL_SECTION_SEQUENCE_FAST macros to make it possible
    to use PySequence_Fast APIs safely when free-threaded, and
    update str.join to work without the GIL using them.
  - gh-111389: Add PyHASH_MULTIPLIER constant: prime multiplier used
    in string and various other hashes. Patch by Victor Stinner.
  - gh-116984: Make mimalloc includes relative to the current file
    to avoid embedders or extensions needing to include
    Internal/mimalloc if they are already including internal CPython
    headers.
  - gh-118789: Restore _PyWeakref_ClearRef that was previously
    removed in Python 3.13 alpha 1.

++++ systemd:

  - Add 5003-Revert-run-pass-the-pty-slave-fd-to-transient-servic.patch
    This revert the backport of the broken commit 28459ba1f4df until a fix is
    released in the v255-stable tree (see pr#33216).

++++ python313:

  - Build experimental package python313-base-nogil with
  - -disable-gil option.
  - Fix doc package build
    gh#python/cpython#120150
  - Update to 3.13.0b2:
  - Security
  - gh-118773: Fixes creation of ACLs in os.mkdir() on Windows to
    work correctly on non-English machines.
  - gh-118486: os.mkdir() on Windows now accepts mode of 0o700 to
    restrict the new directory to the current user. This fixes
    CVE-2024-4030 affecting tempfile.mkdtemp() in scenarios where
    the base temporary directory is more permissive than the
    default.
  - Core and Builtins
  - gh-119724: Reverted improvements to error messages for elif/else
    statements not matching any valid statements, which made in hard
    to locate the syntax errors inside those elif/else blocks.
  - gh-119842: Honor PyOS_InputHook() in the new REPL. Patch by
    Pablo Galindo
  - gh-119821: Fix execution of annotation scopes within classes
    when globals is set to a non-dict. Patch by Jelle Zijlstra.
  - gh-119548: Add a clear command to the REPL. Patch by Pablo
    Galindo
  - gh-111999: Fix the signature of str.format_map().
  - gh-119560: An invalid assert in beta 1 has been removed. The
    assert would fail if PyState_FindModule() was used in an
    extension module’s init function before the module def had been
    initialized.
  - gh-119369: Fix deadlock during thread deletion in free-threaded
    build, which could occur when the GIL was enabled at runtime.
  - gh-119525: Fix deadlock involving _PyType_Lookup() cache in the
    free-threaded build when the GIL is dynamically enabled at
    runtime.
  - gh-119311: Fix bug where names are unexpectedly mangled in the
    bases of generic classes.
  - gh-119395: Fix bug where names appearing after a generic class
    are mangled as if they are in the generic class.
  - gh-119213: Non-builtin modules built with argument clinic were
    crashing if used in a subinterpreter before the main
    interpreter. The objects that were causing the problem by
    leaking between interpreters carelessly have been fixed.
  - gh-119011: Fixes type.__type_params__ to return an empty tuple
    instead of a descriptor.
  - gh-118692: Avoid creating unnecessary StopIteration instances
    for monitoring.
  - gh-119049: Fix displaying the source line for warnings created
    by the C API if the warnings module had not yet been imported.
  - gh-118844: Fix build failures when configuring with both
  - -disable-gil and --enable-experimental-jit.
  - gh-118921: Add copy() method for FrameLocalsProxy which returns
    a snapshot dict for local variables.
  - gh-117657: Fix data races on the field that stores a pointer to
    the interpreter’s main thread that occur in free-threaded
    builds.
  - gh-118507: Speedup os.path.isjunction() and os.path.lexists() on
    Windows with a native implementation.
  - gh-118561: Fix race condition in free-threaded build where
    list.extend() could expose uninitialised memory to concurrent
    readers.
  - gh-118263: Speed up os.path.splitroot() & os.path.normpath()
    with a direct C call.
  - gh-117195: Avoid assertion failure for debug builds when calling
    object.__sizeof__(1)
  - Library
  - gh-119819: Fix regression to allow logging configuration with
    multiprocessing queue types.
  - gh-117142: The ctypes module may now be imported in all
    subinterpreters, including those that have their own GIL.
  - gh-118835: Fix _pyrepl crash when using custom prompt with ANSI
    escape codes.
  - gh-117398: The _datetime module (C implementation for datetime)
    now supports being imported in multiple interpreters.
  - gh-89727: Fix issue with shutil.rmtree() where a RecursionError
    is raised on deep directory trees.
  - gh-89727: Partially fix issue with shutil.rmtree() where a
    RecursionError is raised on deep directory trees. A recursion
    error is no longer raised when rmtree.avoids_symlink_attacks is
    false.
  - gh-119118: Fix performance regression in the tokenize module by
    caching the line token attribute and calculating the column
    offset more efficiently.
  - gh-89727: Fix issue with os.fwalk() where a RecursionError was
    raised on deep directory trees by adjusting the implementation
    to be iterative instead of recursive.
  - gh-119588: zipfile.Path.is_symlink now assesses if the given
    path is a symlink.
  - gh-119555: Catch SyntaxError from compile() in the runsource()
    method of the InteractiveColoredConsole. Patch by Sergey B
    Kirpichev.
  - gh-113892: Now, the method sock_connect of
    asyncio.ProactorEventLoop raises a ValueError if given socket is
    not in non-blocking mode, as well as in other loop
    implementations.
  - gh-119443: The interactive REPL no longer runs with from
    __future__ import annotations enabled. Patch by Jelle Zijlstra.
  - gh-117398: Objects in the datetime C-API are now all statically
    allocated, which means better memory safety, especially when the
    module is reloaded. This should be transparent to users.
  - gh-118894: asyncio REPL now has the same capabilities as PyREPL.
  - gh-118911: In PyREPL, updated maybe-accept’s logic so that if
    the user hits Enter twice, they are able to terminate the block
    even if there’s trailing whitespace. Also, now when the user
    hits arrow up, the cursor is on the last functional line. This
    matches IPython’s behavior. Patch by Aya Elsayed.
  - gh-111201: Remove dependency to readline from the new Python
    REPL.
  - gh-119174: Fix high DPI causes turtledemo(turtle-graphics
    examples) windows blurry Patch by Wulian233 and Terry Jan Reedy
  - gh-119121: Fix a NameError happening in
    asyncio.staggered.staggered_race. This function is now tested.
  - gh-119113: Fix issue where pathlib.PurePath.with_suffix() didn’t
    raise TypeError when given None as a suffix.
  - gh-118643: Fix an AttributeError in the email module when
    re-fold a long address list. Also fix more cases of incorrect
    encoding of the address separator in the address list.
  - gh-58933: Make pdb return to caller frame correctly when f_trace
    of the caller frame is not set
  - gh-118895: Setting attributes on typing.NoDefault now raises
    AttributeError instead of TypeError.
  - gh-118868: Fixed issue where kwargs were no longer passed to the
    logging handler QueueHandler
  - gh-118851: ctx arguments to the constructors of ast node classes
    now default to ast.Load(). Patch by Jelle Zijlstra.
  - gh-118760: Restore the default value of tkiter.wantobjects to 1.
  - gh-118760: Fix errors in calling Tkinter bindings on Windows.
  - gh-118772: Allow typing.TypeVar instances without a default to
    follow instances without a default in some cases. Patch by Jelle
    Zijlstra.
  - gh-110863: os.path.realpath() now suppresses any OSError from
    os.readlink() when strict mode is disabled (the default).
  - gh-118033: Fix dataclasses.dataclass() not creating a
    __weakref__ slot when subclassing typing.Generic.
  - gh-106531: In importlib.resources, sync with importlib_resources
    6.3.2, including: MultiplexedPath now expects Traversable paths,
    deprecating string arguments to MultiplexedPath; Enabled support
    for resources in namespace packages in zip files; Fixed
    NotADirectoryError when calling files on a subdirectory of a
    namespace package.
  - gh-113978: Ignore warnings on text completion inside REPL.
  - gh-103956: Fix lack of newline characters in trace module output
    when line tracing is enabled but source code line for current
    frame is not available.
  - gh-92081: Fix missing spaces in email headers when the spaces
    are mixed with encoded 8-bit characters.
  - gh-103194: Prepare Tkinter for C API changes in Tcl 8.7/9.0 to
    avoid _tkinter.Tcl_Obj being unexpectedly returned instead of
    bool, str, bytearray, or int.
  - gh-87106: Fixed handling in inspect.Signature.bind() of keyword
    arguments having the same name as positional-only arguments when
    a variadic keyword argument (e.g. **kwargs) is present.
  - bpo-45767: Fix integer conversion in os.major(), os.minor(), and
    os.makedev(). Support device numbers larger than 2**63-1.
    Support non-existent device number (NODEV).
  - gh-67693: Fix urllib.parse.urlunparse() and
    urllib.parse.urlunsplit() for URIs with path starting with
    multiple slashes and no authority. Based on patch by Ashwin
    Ramaswami.
  - Tests
  - gh-119050: regrtest test runner: Add XML support to the refleak
    checker (-R option). Patch by Victor Stinner.  Buil- d
  - gh-119729: On POSIX systems, the pkg-config (.pc) filenames now
    include the ABI flags, which may include debug (“d”) and
    free-threaded (“t”). For example: * python-3.14.pc (default,
    non-debug build) * python-3.14d.pc (default, debug build) *
    python-3.14t.pc (free-threaded build)
  - gh-115119: Fall back to the bundled libmpdec if a system version
    cannot be found.
  - gh-119132: Update sys.version to identify whether the build is
    default build or free-threading build. Patch By Donghee Na.
  - gh-118836: Fix an AssertionError when building with
  - -enable-experimental-jit and the compiler emits a SHT_NOTE
    section.
  - gh-118943: Fix a possible race condition affecting parallel
    builds configured with --enable-experimental-jit, in which
    compilation errors could be caused by an incompletely-generated
    header file.
  - Windows
  - gh-119679: Ensures correct import libraries are included in
    Windows installs.
  - gh-119690: Adds Unicode support and fixes audit events for
    _winapi.CreateNamedPipe.
  - gh-111201: Add support for new pyrepl on Windows
  - gh-119070: Fixes py.exe handling of shebangs like /usr/bin/env
    python3.12, which were previously interpreted as python3.exe
    instead of python3.12.exe.
  - gh-117505: Fixes an issue with the Windows installer not running
    ensurepip in a fully isolated environment. This could cause
    unexpected interactions with the user site-packages.
  - gh-118209: Avoid crashing in mmap on Windows when the mapped
    memory is inaccessible due to file system errors or access
    violations.
  - gh-116145: Updated bundled Tcl/Tk to 8.6.14.
  - C API
  - gh-119585: Fix crash when a thread state that was created by
    PyGILState_Ensure() calls a destructor that during
    PyThreadState_Clear() that calls back into PyGILState_Ensure()
    and PyGILState_Release(). This might occur when in the
    free-threaded build or when using thread-local variables whose
    destructors call PyGILState_Ensure().
  - gh-119336: Restore the removed _PyLong_NumBits() function. It is
    used by the pywin32 project. Patch by Ethan Smith
  - gh-119247: Added Py_BEGIN_CRITICAL_SECTION_SEQUENCE_FAST and
    Py_END_CRITICAL_SECTION_SEQUENCE_FAST macros to make it possible
    to use PySequence_Fast APIs safely when free-threaded, and
    update str.join to work without the GIL using them.
  - gh-111389: Add PyHASH_MULTIPLIER constant: prime multiplier used
    in string and various other hashes. Patch by Victor Stinner.
  - gh-116984: Make mimalloc includes relative to the current file
    to avoid embedders or extensions needing to include
    Internal/mimalloc if they are already including internal CPython
    headers.
  - gh-118789: Restore _PyWeakref_ClearRef that was previously
    removed in Python 3.13 alpha 1.

++++ python-requests:

  - update to 2.32.3:
    * Fixed bug breaking the ability to specify custom SSLContexts
    in sub-classes of HTTPAdapter.
    * Fixed issue where Requests started failing to run on Python
    versions compiled without the `ssl` module.

++++ vim:

  - Update to 9.1.0470:
    * tests Test_ColonEight_MultiByte() fails sporadically
    * Cannot have buffer-local value for 'completeopt'
    * GvimExt does not consult HKEY_CURRENT_USER
    * typos in some comments
    * runtime(vim): Update base-syntax, allow whitespace before
    :substitute pattern
    * Missing comments for fuzzy completion
    * runtime(man): update Vim manpage
    * runtime(comment): clarify the usage of 'commentstring' option
    value
    * runtime(doc): clarify how fuzzy 'completeopt' should work
    * runtime(netrw): prevent accidental data loss
    * missing filecopy() function
    * no whitespace padding in commentstring option in ftplugins
    * no fuzzy-matching support for insert-completion
    * eval5() and eval7 are too complex
    * too many strlen() calls in drawline.c
    * filetype lintstagedrc files are not recognized
    * Vim9 import autoload does not work with symlink
    * Coverity complains about division by zero
    * tests test_gui fails on Wayland
    * Left shift is incorrect with vartabstop and shiftwidth=0
    * runtime(doc): clarify 'shortmess' flag "S"
    * MS-Windows compiler warning for size_t to int conversion
    * runtime(doc): include some vim9 script examples in the help
    * minor issues in test_filetype with rasi test
    * filetype rasi files are not recognized
    * runtime(java): Improve the matching of lambda expressions
    * Configure checks for libelf unnecessarily
    * No test for escaping '<' with shellescape()
    * check.vim complains about overlong comment lines
    * translation(it): Update Italian translation
    * evalc. code too complex
    * MS-Windows Compiler warnings

------------------------------------------------------------------
------------------  2024-6-5  -  Jun 5 2024  -------------------
------------------------------------------------------------------

++++ NetworkManager:

  - Update to version 1.48.0:
    + Building with autotools is now deprecated and will be
    completely removed in the next development cycle.
    + Support changing the OpenSSL ciphers for 802.1X authentication
    via connection property "802-1x.openssl-ciphers".
    + The reason why a device is unmanaged is now properly set in the
    "StateReason" property of the "Device" D-Bus object. The
    property is visible in nmcli via "nmcli -f all device show
    $DEV".
    + Deprecated 802-11-wireless and 802-11-wired property
    'mac-address-blacklist' and introduced the
    'mac-address-denylist' property.
    + Properly restore in-memory connection profiles during the
    rollback of a checkpoint.
    + Fix detection of 6 GHz band capability for WiFi devices.
    + Allow IPv6 SLAAC and static IPv6 DNS server assignment for
    modem broadband when IPv6 device address was not explicitly
    passed on by ModemManager.
    + Fix a performance issue that was leading to 100% CPU usage by
    NetworkManager if external programs were doing a big amount of
    routes updates.
    + Patch-level development releases (i.e. 1.48.1-dev) won't be
    used anymore.
  - Changes from version 1.46
    + Support dynamic value "${NETWORK_SSID}" for
    connection.stable-id to generate the stable ID based on the
    Wi-Fi's SSID.
    + Support new value "wifi.cloned-mac-address=stable-ssid" for
    randomizing the MAC address based on the Wi-Fi network.
    + Change internal ABI of NMSetting types and NMSimpleConnection.
    + Honor udev property ID_NET_AUTO_LINK_LOCAL_ONLY=1 for enabling
    link local addresses on default wired connection.
    + Honor udev property ID_NET_MANAGED_BY to only manage an
    interface when set to "org.freedesktop.NetworkManager".
    + D-Bus methods StartFind() and StopFind() on interface
    "org.freedesktop.NetworkManager.Device.WifiP2P" now require the
    "org.freedesktop.NetworkManager.wifi.scan" Polkit permission.
    + Drop build support with Python2. Python3 is now required.
    + nmcli: limit number of printed addresses/routes in `nmcli`
    overview to 10.
    + Limit number of exported IP addresses/routes on D-Bus to 100 to
    reduce performance cost. Also, D-Bus updates for
    addresses/routes are now rate limited to 3 per second.
    + cloud-setup: enable more sandboxing options in systemd service
    file.
    + nmcli: show WiFi bandwidth.
    + Internal improvements and bugfixes.
    + Man page now show the format and accepted values of all
    properties.
    + Added the 'dns-change' dispatcher event.
    + Show WiFi devices capability to work on the 6GHz band.
    + Allow to set dhcp-client-id to none.
    + Support configuring ethtool channels property to configure NIC
    multiqueue.
    + Don't attempt to use IPv6 if it's disabled in kernel.
    + Fix handling of OVS interfaces with netdev datapath and cloned
    MAC.
    + Support for old systemd has been droped, at least systemd v200
    is required.
    + Support Ethtool EEE (Energy Efficient Ethernet) settings.
    + Add options to prevent edns0 and trust-ad being automatically
    added to DNS configuration.
    + Implement fwmark property for IP tunnels.
    + Add support to HSR/PRP interfaces.
    + Deprecated connection.* properties master, slave-type,
    autoconnect-slaves
    + Allow configuring static routes also when addresses is empty.
    + VPN: accept pref-src for IPv6 routes from VPN plugins.
    + nmcli: show global metered state.
    + Support modifying the DSCP header field for DHCP packets, and
    change the default to CS0.
    + Enable IPv4 DAD (Duplicate Address Detection) by default.
    + vpn: support 2FA authentication from VPN plugins.
    + nmtui: allow adding a bond as bridge port.
    + sriov: add support to configure the NIC's eswitch settings via
    Devlink.
    + ndisc: fix IPv6 address lifetimes computation.
    + Support the MACsec offload mode.
    + Support creating generic devices via external "device-handler"
    dispatcher.
    + Documentation improvements.
    + Many internal improvements and bug fixes.
  - Drop nm-runstatedir.patch: no longer needed.

++++ kernel-default:

  - perf pmu: Count sys and cpuid JSON events separately (git
    fixes).
  - perf stat: Don't display metric header for non-leader uncore
    events (git-fixes).
  - perf daemon: Fix file leak in daemon_session__control
    (git-fixes).
  - perf symbols: Fix ownership of string in dso__load_vmlinux()
    (git-fixes).
  - perf thread: Fixes to thread__new() related to initializing comm
    (git-fixes).
  - perf report: Avoid SEGV in report__setup_sample_type()
    (git-fixes).
  - perf ui browser: Don't save pointer to stack memory (git-fixes).
  - perf bench internals inject-build-id: Fix trap divide when
    collecting just one DSO (git-fixes).
  - perf intel-pt: Fix unassigned instruction op (discovered by
    MemorySanitizer) (git-fixes).
  - perf test shell arm_coresight: Increase buffer size for
    Coresight basic tests (git-fixes).
  - perf docs: Document bpf event modifier (git-fixes).
  - perf bench uprobe: Remove lib64 from libc.so.6 binary path
    (git-fixes).
  - perf record: Fix debug message placement for test consumption
    (git-fixes).
  - perf tests: Apply attributes to all events in object code
    reading test (git-fixes).
  - perf tests: Make "test data symbol" more robust on Neoverse N1
    (git-fixes).
  - perf annotate: Fix annotation_calc_lines() to pass correct
    address to get_srcline() (git-fixes).
  - perf stat: Do not fail on metrics on s390 z/VM systems
    (git-fixes).
  - perf sched timehist: Fix -g/--call-graph option failure
    (git-fixes).
  - perf annotate: Get rid of duplicate --group option item
    (git-fixes).
  - perf probe: Add missing libgen.h header needed for using
    basename() (git-fixes).
  - perf record: Delete session after stopping sideband thread
    (git-fixes).
  - perf auxtrace: Fix multiple use of --itrace option (git-fixes).
  - perf script: Show also errors for --insn-trace option
    (git-fixes).
  - perf lock contention: Add a missing NULL check (git-fixes).
  - perf vendor events amd: Fix Zen 4 cache latency events
    (git-fixes).
  - libperf evlist: Avoid out-of-bounds access (git-fixes).
  - perf pmu: Fix a potential memory leak in perf_pmu__lookup()
    (git-fixes).
  - perf print-events: make is_event_supported() more robust
    (git-fixes).
  - perf list: fix short description for some cache events
    (git-fixes).
  - perf metric: Don't remove scale from counts (git-fixes).
  - perf stat: Avoid metric-only segv (git-fixes).
  - perf expr: Fix "has_event" function for metric style events
    (git-fixes).
  - perf srcline: Add missed addr2line closes (git-fixes).
  - perf thread_map: Free strlist on normal path in
    thread_map__new_by_tid_str() (git-fixes).
  - perf bpf: Clean up the generated/copied vmlinux.h (git-fixes).
  - perf jevents: Drop or simplify small integer values (git-fixes).
  - perf evsel: Fix duplicate initialization of data->id in
    evsel__parse_sample() (git-fixes).
  - perf pmu: Treat the msr pmu as software (git-fixes).
  - perf record: Check conflict between '--timestamp-filename'
    option and pipe mode before recording (git-fixes).
  - perf record: Fix possible incorrect free in
    record__switch_output() (git-fixes).
  - perf vendor events amd: Add Zen 4 memory controller events
    (git-fixes).
  - perf top: Uniform the event name for the hybrid machine
    (git-fixes).
  - perf top: Use evsel's cpus to replace user_requested_cpus
    (git-fixes).
  - commit a1f9340
  - nfs: Bump default write congestion size (bsc#1218442).
  - commit 563bd84
  - nfs: Avoid flushing many pages with NFS_FILE_SYNC (bsc#1218442).
  - commit 1092c12
  - blacklist.conf: remove fix for CVE-2024-35956 bsc#1224674, not applicable
  - Delete patches.suse/btrfs-qgroup-fix-qgroup-prealloc-rsv-leak-in-subvolu.patch.
    Quoting bsc#1225945#c11:
    "So the upstream 6.5 kernel commit (1b53e51a4a8f ("btrfs: don't commit
    transaction for every subvol create")
    ) was never backported to SLE, so that fix eb96e221937a ("btrfs: fix
    unwritten extent buffer after snapshotting a new subvolume") was never
    backported."
  - commit d947258
  - crypto: iaa - Fix async_disable descriptor leak (CVE-2024-35926
    bsc#1224655).
  - commit c5d6a9b
  - xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
    (bsc#1224575 CVE-2024-35976).
  - commit 794d5e8
  - bpf, skmsg: Fix NULL pointer dereference in
    sk_psock_skb_ingress_enqueue (bsc#1225761 CVE-2024-36938).
  - commit 2f2e817
  - ipv4: check for NULL idev in ip_route_use_hint()
    (CVE-2024-36008 bsc#1224540)
  - commit d751eb5

++++ kernel-rt:

  - perf pmu: Count sys and cpuid JSON events separately (git
    fixes).
  - perf stat: Don't display metric header for non-leader uncore
    events (git-fixes).
  - perf daemon: Fix file leak in daemon_session__control
    (git-fixes).
  - perf symbols: Fix ownership of string in dso__load_vmlinux()
    (git-fixes).
  - perf thread: Fixes to thread__new() related to initializing comm
    (git-fixes).
  - perf report: Avoid SEGV in report__setup_sample_type()
    (git-fixes).
  - perf ui browser: Don't save pointer to stack memory (git-fixes).
  - perf bench internals inject-build-id: Fix trap divide when
    collecting just one DSO (git-fixes).
  - perf intel-pt: Fix unassigned instruction op (discovered by
    MemorySanitizer) (git-fixes).
  - perf test shell arm_coresight: Increase buffer size for
    Coresight basic tests (git-fixes).
  - perf docs: Document bpf event modifier (git-fixes).
  - perf bench uprobe: Remove lib64 from libc.so.6 binary path
    (git-fixes).
  - perf record: Fix debug message placement for test consumption
    (git-fixes).
  - perf tests: Apply attributes to all events in object code
    reading test (git-fixes).
  - perf tests: Make "test data symbol" more robust on Neoverse N1
    (git-fixes).
  - perf annotate: Fix annotation_calc_lines() to pass correct
    address to get_srcline() (git-fixes).
  - perf stat: Do not fail on metrics on s390 z/VM systems
    (git-fixes).
  - perf sched timehist: Fix -g/--call-graph option failure
    (git-fixes).
  - perf annotate: Get rid of duplicate --group option item
    (git-fixes).
  - perf probe: Add missing libgen.h header needed for using
    basename() (git-fixes).
  - perf record: Delete session after stopping sideband thread
    (git-fixes).
  - perf auxtrace: Fix multiple use of --itrace option (git-fixes).
  - perf script: Show also errors for --insn-trace option
    (git-fixes).
  - perf lock contention: Add a missing NULL check (git-fixes).
  - perf vendor events amd: Fix Zen 4 cache latency events
    (git-fixes).
  - libperf evlist: Avoid out-of-bounds access (git-fixes).
  - perf pmu: Fix a potential memory leak in perf_pmu__lookup()
    (git-fixes).
  - perf print-events: make is_event_supported() more robust
    (git-fixes).
  - perf list: fix short description for some cache events
    (git-fixes).
  - perf metric: Don't remove scale from counts (git-fixes).
  - perf stat: Avoid metric-only segv (git-fixes).
  - perf expr: Fix "has_event" function for metric style events
    (git-fixes).
  - perf srcline: Add missed addr2line closes (git-fixes).
  - perf thread_map: Free strlist on normal path in
    thread_map__new_by_tid_str() (git-fixes).
  - perf bpf: Clean up the generated/copied vmlinux.h (git-fixes).
  - perf jevents: Drop or simplify small integer values (git-fixes).
  - perf evsel: Fix duplicate initialization of data->id in
    evsel__parse_sample() (git-fixes).
  - perf pmu: Treat the msr pmu as software (git-fixes).
  - perf record: Check conflict between '--timestamp-filename'
    option and pipe mode before recording (git-fixes).
  - perf record: Fix possible incorrect free in
    record__switch_output() (git-fixes).
  - perf vendor events amd: Add Zen 4 memory controller events
    (git-fixes).
  - perf top: Uniform the event name for the hybrid machine
    (git-fixes).
  - perf top: Use evsel's cpus to replace user_requested_cpus
    (git-fixes).
  - commit a1f9340
  - nfs: Bump default write congestion size (bsc#1218442).
  - commit 563bd84
  - nfs: Avoid flushing many pages with NFS_FILE_SYNC (bsc#1218442).
  - commit 1092c12
  - blacklist.conf: remove fix for CVE-2024-35956 bsc#1224674, not applicable
  - Delete patches.suse/btrfs-qgroup-fix-qgroup-prealloc-rsv-leak-in-subvolu.patch.
    Quoting bsc#1225945#c11:
    "So the upstream 6.5 kernel commit (1b53e51a4a8f ("btrfs: don't commit
    transaction for every subvol create")
    ) was never backported to SLE, so that fix eb96e221937a ("btrfs: fix
    unwritten extent buffer after snapshotting a new subvolume") was never
    backported."
  - commit d947258
  - crypto: iaa - Fix async_disable descriptor leak (CVE-2024-35926
    bsc#1224655).
  - commit c5d6a9b
  - xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING
    (bsc#1224575 CVE-2024-35976).
  - commit 794d5e8
  - bpf, skmsg: Fix NULL pointer dereference in
    sk_psock_skb_ingress_enqueue (bsc#1225761 CVE-2024-36938).
  - commit 2f2e817
  - ipv4: check for NULL idev in ip_route_use_hint()
    (CVE-2024-36008 bsc#1224540)
  - commit d751eb5

++++ pcsc-ccid:

  - Version 1.6.0
  - uses meson build system now
  - Add support of
  - Aladdin R.D. JCR SecurBio
  - AvidCard CAC Smart Card Reader
  - FujitsuTechnologySolutions GmbH Dual Smartcard Reader D321
  - Ledger Stax
  - NXP Pegoda 3
  - authenton #1- CTAP2.1
  - provide files for meson build tool (replaces autoconf/automake)
  - Add possibility to set/get NAD on T=1 for MEP
  - multi-slots readers
  - Better handling of reader removal
  - Use CLOCK_MONOTONIC for timeouts
  - Some other minor improvements

------------------------------------------------------------------
------------------  2024-6-4  -  Jun 4 2024  -------------------
------------------------------------------------------------------

++++ chrony:

  - bsc#1225362, chrony-124-tai.patch: make 124-tai more reliable

++++ python-kiwi:

  - Bump version: 10.0.20 → 10.0.21

++++ gettext-runtime:

  - add optional -mini suffix to envsubst package

++++ kernel-default:

  - smb3: fix lock ordering potential deadlock in
    cifs_sync_mid_result (bsc#1225172, bsc#1224549, CVE-2024-35998).
  - commit 98bfec0
  - smb: client: fix potential deadlock when releasing mids
    (bsc#1225172, bsc#1225548, CVE-2023-52757).
  - commit 1b322a8
  - octeontx2-af: avoid off-by-one read from userspace (bsc#1225762 CVE-2024-36957)
  - commit d3dcfbb

++++ kernel-rt:

  - smb3: fix lock ordering potential deadlock in
    cifs_sync_mid_result (bsc#1225172, bsc#1224549, CVE-2024-35998).
  - commit 98bfec0
  - smb: client: fix potential deadlock when releasing mids
    (bsc#1225172, bsc#1225548, CVE-2023-52757).
  - commit 1b322a8
  - octeontx2-af: avoid off-by-one read from userspace (bsc#1225762 CVE-2024-36957)
  - commit d3dcfbb

++++ libbpf:

  - update to 1.4.3:
    * Fix libbpf unintentionally dropping FD_CLOEXEC flag when (internally)
    duping FDs

++++ libeconf:

  - Update to version 0.7.0:
    * Defining manual parsing directories (#209)
    * parsing config files in python style
    * econf_readConfig: set usr_subdir to empty string if it is NULL
    * Fix static analyzer detected issues (#202)
    * comment string can be in the parsed value which is defined with quotes (#207)
    * tst-comments2: comment sign in quoted string (#205)
    * Setting options via new econf_newKeyFile_with_options. (#206)

++++ openvswitch:

  - GCC 14 started to advertise c_atomic extension, older versions
    didn't do that.  Add check for __clang__, so GCC doesn't include
    headers designed for Clang
    (openvswitch-2.17.8-gcc14-build-fix.patch) [boo#1225906]

++++ man:

  - Update to 2.12.1 (5 April 2024)
    * Fix excessive cleanup of `/var/cache/man` by `systemd-tmpfiles`.
    * `man` matches the display width more accurately to the configured width.
    * Upgrade to Gnulib `stable-202401`.
    * Mention `groff`'s `pdf` device in `man(1)`.
    * Speed up `seccomp` filter slightly.
    * Document how to format pages using italic rather than underlined text.
    * Remove the obsolete `chconfig` tool for converting man-db configuration
    files to the FHS.  This transition took place almost 25 years ago (at
    least in Debian), so it's not worth keeping it around now.
  - Remove patch man-db-2.9.4-alternitive.dif now upstream
  - Port the patches
    * man-db-2.6.3-listall.dif
    * man-db-2.7.1-zio.dif
    * man-db-2.9.4.patch
    * man-propose-online.patch

++++ nvidia-open-driver-G06-signed:

  - Security Update 550.90.07 (boo#1223356) [CVE-2024-0090,
    CVE-2024-0091, CVE-2024-0092]

++++ python-maturin:

  - Update to 1.6.0
    * Add pypi name validation
    gh#PyO3/maturin#2007
    * Add JSON schema generation
    gh#PyO3/maturin#2005
    * Detect compiling from Linux gnu to Linux musl as cross compiling
    gh#PyO3/maturin#2010
    * Upgrade uniffi to 0.27.0
    gh#PyO3/maturin#2021
    * Add instrumentation support for develop
    gh#PyO3/maturin#2019
    * Make tracing-subscriber mandatory
    gh#PyO3/maturin#2022
    * Import hook upgrade
    gh#PyO3/maturin#2024
    * Add uv as develop backend command
    gh#PyO3/maturin#2015
    * Also try uv in PATH in develop --uv
    gh#PyO3/maturin#2026
    * docs: update pyo3 to match tutorial
    gh#PyO3/maturin#2029
    * Add support for AIX
    gh#PyO3/maturin#2030
    * Remove rust-cpython from project init/new template
    gh#PyO3/maturin#2034
    * Only run uv tests on platforms that has wheel on PyPI or when uv bina…
    gh#PyO3/maturin#2037
    * Install cffi and uv on demand in test_develop
    gh#PyO3/maturin#2043
    * Add support for wasm32-wasip1 and wasm32-wasip2 targets
    gh#PyO3/maturin#2054
    * fix: windows exit code with python
    gh#PyO3/maturin#2055
    * Remove rust-cpython support from documentation
    gh#PyO3/maturin#2057
    * docs: Add bleuscore in examples
    gh#PyO3/maturin#2061
    * Fix new clippy warnings on Rust 1.78.0
    gh#PyO3/maturin#2065
    * Allows to use Maturin with ziglang 0.11 and 0.12
    gh#PyO3/maturin#2067
    * Show full path in missing readme error message
    gh#PyO3/maturin#2074
    * Update cargo mock deps
    gh#PyO3/maturin#2075
    * Ban std::fs trough clippy
    gh#PyO3/maturin#2076
    * Preserve file permission when copying
    gh#PyO3/maturin#2069
    * Detect target based on interpreter for pep517 build-wheel
    gh#PyO3/maturin#2088
    * Add a global verbose option
    gh#PyO3/maturin#2080
    * Use base executable when possible in PEP 517 build
    gh#PyO3/maturin#2094
    * Remove support for rust-cpython
    gh#PyO3/maturin#2044

++++ selinux-policy:

  - Update to version 20240604+git0.ee0114f1:
    * allow firewalld access to /dev/random and write HW acceleration logs

------------------------------------------------------------------
------------------  2024-6-3  -  Jun 3 2024  -------------------
------------------------------------------------------------------

++++ aardvark-dns:

  - Remove redundant source: cargo_config
  - Update to version 1.11.0:
    * Release v1.11.0
    * v1.11.0 release notes
    * run cargo update
    * chore(deps): update dependency containers/automation_images to v20240529
    * Internal networks cannot make external DNS requests
    * fix(deps): update rust crate anyhow to 1.0.86
    * fix(deps): update rust crate nix to 0.29.0
    * [skip-ci] RPM: use default __cargo macro across all envs
    * chore(deps): update dependency containers/automation_images to v20240513
    * fix(deps): update rust crate anyhow to 1.0.83
    * [skip-ci] Packit: separate `packages` key for rhel jobs
    * fix(deps): update rust crate libc to 0.2.154
    * [skip-ci] Packit: enable rhel10, c10s tests and c10s downstream sync
    * [skip-ci] Packit: Remove EL8 jobs
    * fix(deps): update rust crate syslog to ^6.1.1
    * fix reverse ipv6 lookup test flake
    * fix(deps): update hickory-dns monorepo to 0.24.1
    * chore(deps): update rust crate chrono to 0.4.38
    * Don't tear down all server threads on SIGHUP (bsc#1224167)
    * fix(deps): update rust crate anyhow to 1.0.82
    * fix(deps): update rust crate tokio to 1.37.0
    * Update to nix-0.28.0
    * update chrono package
    * chore(deps): update dependency containers/automation_images to v20240320
    * fix(deps): update rust crate anyhow to 1.0.81
    * tests: check queried domain name in reverse lookup tests
    * fix: set name for answers in reverse lookups
    * chore: fix typo in runner script
    * chore: fix log message when doing reverse lookup
    * fix(deps): update rust crate log to 0.4.21
    * fix(deps): update rust crate anyhow to 1.0.80
    * chore(deps): update rust crate chrono to 0.4.34
    * fix(deps): update rust crate async-broadcast to 0.7.0
    * fix(deps): update rust crate tokio to 1.36.0
    * [CI:DOCS] Packit: disable bodhi tasks
    * chore(deps): update rust crate chrono to 0.4.33
    * Bump to 1.11.0-dev

++++ cloud-init:

  - Add cloud-init-skip-rename.patch (bsc#1219680)
    + Brute force approach to skip renames if the device is already present

++++ python-kiwi:

  - Add missing write_meta_data method to BLS base
    The standard bootloader interface class provided a method
    named write_meta_data which is expected to be implemented
    in the specialized bootloader implementation. For BLS
    bootloaders this method was missing in the BLS base class.
    write_meta_data can provide additional cmdline options
    for booting. If not covered some boot options might be
    missing. This patch fixes it
  - Fix TW integration test to build outside OBS
  - Make sure BootLoaderConfig fixes are effective
    The BootLoaderConfigGrub2 class has methods to fix the grub-mkconfig
    generated files. It does that by mounting the system and changing the
    respective files after the mkconfig call. However, after the change
    the class instance stays open in combination with BootLoaderInstallGrub2
    instance which itself under certain circumstances also mounts the
    system to call grub-install. At the time grub-install is called it
    cannot be guaranteed that all changes has been written unless an
    explicit umount in the BootLoaderConfigGrub2 class instance happened.
    This commit address the potential race condition.
  - Bump version: 10.0.19 → 10.0.20
  - Update rawhide integration test
    Use new arch attribute for testing in the repository
    element of the rawhide/test-image-live-disk integration
    test.

++++ glibc:

  - Also provide glibc-locale-base-<targettype> from
    glibc-gconv-modules-extra-<targettype>: the package was merged in the
    baselibs.conf case, so the capability is there. Steam for one has a
    requires on the symbol (boo#1225809).

++++ kernel-default:

  - kabi/severities: Ignore io_uring internal symbols
  - commit 0e91c09
  - perf/x86: Fix out of range data (git-fixes).
  - perf/x86/intel/ds: Don't clear ->pebs_data_cfg for the last
    PEBS event (git-fixes).
  - perf/x86/amd/lbr: Discard erroneous branch entries (git-fixes).
  - commit 664d77f
  - cifs: failure to add channel on iface should bump up weight
    (git-fixes, bsc#1225172).
  - commit 007b237
  - smb: client: fix parsing of SMB3.1.1 POSIX create context
    (git-fixes, bsc#1225172).
  - commit 5f27f69
  - Revert "cifs: reconnect work should have reference on server
    struct" (git-fixes, bsc#1225172).
  - commit 3ca4c0c
  - cifs: fix leak of iface for primary channel (git-fixes,
    bsc#1225172).
  - commit b7eb8e8
  - smb: client: fix mount when dns_resolver key is not available
    (git-fixes, bsc#1225172).
  - commit 28edb5c
  - scsi: lpfc: Copyright updates for 14.4.0.2 patches
    (bsc#1225842).
  - scsi: lpfc: Update lpfc version to 14.4.0.2 (bsc#1225842).
  - scsi: lpfc: Add support for 32 byte CDBs (bsc#1225842).
  - scsi: lpfc: Change lpfc_hba hba_flag member into a bitmask
    (bsc#1225842).
    Refresh:
  - patches.suse/lpfc-reintroduce-old-irq-probe-logic.patch
  - scsi: lpfc: Introduce rrq_list_lock to protect active_rrq_list
    (bsc#1225842).
  - scsi: lpfc: Clear deferred RSCN processing flag when driver
    is unloading (bsc#1225842).
  - scsi: lpfc: Update logging of protection type for T10 DIF I/O
    (bsc#1225842).
  - scsi: lpfc: Change default logging level for unsolicited CT
    MIB commands (bsc#1225842).
  - commit 5a56384
  - nvmet: fix ns enable/disable possible hang (git-fixes).
  - nvme-multipath: fix io accounting on failover (git-fixes).
  - nvme: fix multipath batched completion accounting (git-fixes).
  - commit ed3b392
  - Update
    patches.suse/ALSA-hda-intel-sdw-acpi-fix-usage-of-device_get_name.patch
    (git-fixes CVE-2024-36955).
  - Update
    patches.suse/ARM-9381-1-kasan-clear-stale-stack-poison.patch
    (git-fixes bsc#1225715 CVE-2024-36906).
  - Update
    patches.suse/Bluetooth-HCI-Fix-potential-null-ptr-deref.patch
    (git-fixes bsc#1225579 CVE-2024-36011).
  - Update
    patches.suse/Bluetooth-L2CAP-Fix-slab-use-after-free-in-l2cap_con.patch
    (git-fixes bsc#1225578 CVE-2024-36013).
  - Update
    patches.suse/Bluetooth-msft-fix-slab-use-after-free-in-msft_do_cl.patch
    (git-fixes bsc#1225502 CVE-2024-36012).
  - Update
    patches.suse/Bluetooth-qca-add-missing-firmware-sanity-checks.patch
    (git-fixes bsc#1225722 CVE-2024-36880).
  - Update
    patches.suse/Bluetooth-qca-fix-firmware-check-error-path.patch
    (git-fixes CVE-2024-36942).
  - Update
    patches.suse/Bluetooth-qca-fix-info-leak-when-fetching-fw-build-i.patch
    (git-fixes bsc#1225720 CVE-2024-36032).
  - Update
    patches.suse/KVM-x86-mmu-Write-protect-L2-SPTEs-in-TDP-MMU-when-c.patch
    (git-fixes bsc#1223749 CVE-2024-26990).
  - Update
    patches.suse/KVM-x86-pmu-Disable-support-for-adaptive-PEBS.patch
    (git-fixes bsc#1223692 CVE-2024-26992).
  - Update
    patches.suse/Reapply-drm-qxl-simplify-qxl_fence_wait.patch
    (stable-fixes CVE-2024-36944).
  - Update
    patches.suse/USB-core-Fix-access-violation-during-port-device-rem.patch
    (git-fixes bsc#1225734 CVE-2024-36896).
  - Update
    patches.suse/amd-amdkfd-sync-all-devices-to-wait-all-processes-be.patch
    (stable-fixes CVE-2024-36949).
  - Update patches.suse/bpf-Check-bloom-filter-map-value-size.patch
    (bsc#1224488 CVE-2024-35905 bsc#1225766 CVE-2024-36918).
  - Update
    patches.suse/clk-sunxi-ng-h6-Reparent-CPUX-during-PLL-CPUX-rate-c.patch
    (git-fixes bsc#1225692 CVE-2023-52882).
  - Update
    patches.suse/cxl-pci-Fix-disabling-memory-if-DVSEC-CXL-Range-does.patch
    (git-fixes CVE-2024-26761).
  - Update
    patches.suse/drm-amd-display-Atom-Integrated-System-Info-v2_2-for.patch
    (stable-fixes bsc#1225735 CVE-2024-36897).
  - Update
    patches.suse/drm-amd-pm-fixes-a-random-hang-in-S4-for-SMU-v13.0.4.patch
    (stable-fixes bsc#1225705 CVE-2024-36026).
  - Update
    patches.suse/drm-amdkfd-range-check-cp-bad-op-exception-interrupt.patch
    (stable-fixes CVE-2024-36951).
  - Update
    patches.suse/drm-arm-malidp-fix-a-possible-null-pointer-dereferen.patch
    (git-fixes bsc#1225593 CVE-2024-36014).
  - Update
    patches.suse/drm-nouveau-firmware-Fix-SG_DEBUG-error-with-nvkm_fi.patch
    (stable-fixes bsc#1225728 CVE-2024-36885).
  - Update
    patches.suse/efi-unaccepted-touch-soft-lockup-during-memory-accept.patch
    (git-fixes bsc#1225773 CVE-2024-36936).
  - Update
    patches.suse/firewire-ohci-mask-bus-reset-interrupts-between-ISR-.patch
    (stable-fixes CVE-2024-36950).
  - Update patches.suse/gpiolib-cdev-fix-uninitialised-kfifo.patch
    (git-fixes bsc#1225736 CVE-2024-36898).
  - Update
    patches.suse/i40e-fix-vf-may-be-used-uninitialized-in-this-functi.patch
    (git-fixes bsc#1225698 CVE-2024-36020).
  - Update
    patches.suse/maple_tree-fix-mas_empty_area_rev-null-pointer-deref.patch
    (git-fixes bsc#1225710 CVE-2024-36891).
  - Update
    patches.suse/mm-slab-make-__free-kfree-accept-error-pointers.patch
    (git-fixes bsc#1225714 CVE-2024-36890).
  - Update
    patches.suse/mmc-sdhci-msm-pervent-access-to-suspended-controller.patch
    (git-fixes bsc#1225708 CVE-2024-36029).
  - Update
    patches.suse/net-hns3-fix-kernel-crash-when-devlink-reload-during.patch
    (git-fixes bsc#1225699 CVE-2024-36021).
  - Update
    patches.suse/nouveau-dmem-handle-kcalloc-allocation-failure.patch
    (git-fixes CVE-2024-26943).
  - Update
    patches.suse/nouveau-uvmm-fix-addr-range-calcs-for-remap-operatio.patch
    (git-fixes bsc#1225694 CVE-2024-36018).
  - Update
    patches.suse/pinctrl-core-delete-incorrect-free-in-pinctrl_enable.patch
    (git-fixes CVE-2024-36940).
  - Update
    patches.suse/pinctrl-devicetree-fix-refcount-leak-in-pinctrl_dt_t.patch
    (git-fixes CVE-2024-36959).
  - Update
    patches.suse/ppdev-Add-an-error-check-in-register_device.patch
    (git-fixes bsc#1225640 CVE-2024-36015).
  - Update patches.suse/qibfs-fix-dentry-leak.patch (git-fixes
    CVE-2024-36947).
  - Update
    patches.suse/regmap-maple-Fix-cache-corruption-in-regcache_maple_.patch
    (git-fixes bsc#1225695 CVE-2024-36019).
  - Update
    patches.suse/s390-cio-Ensure-the-copied-buf-is-NUL-terminated.patch
    (git-fixes bsc#1223869 bsc#1225747 CVE-2024-36931).
  - Update
    patches.suse/s390-qeth-Fix-kernel-panic-after-setting-hsuid.patch
    (git-fixes bsc#1223874 bsc#1225775 CVE-2024-36928).
  - Update
    patches.suse/scsi-qla2xxx-Fix-off-by-one-in-qla_edif_app_getstats.patch
    (git-fixes bsc#1225704 CVE-2024-36025).
  - Update
    patches.suse/spi-fix-null-pointer-dereference-within-spi_sync.patch
    (git-fixes CVE-2024-36930).
  - Update
    patches.suse/swiotlb-Fix-double-allocation-of-slots-due-to-broken-alignment-handling.patch
    (bsc#1224331 bsc#1224602 CVE-2024-35814).
  - Update
    patches.suse/tty-n_gsm-fix-possible-out-of-bounds-in-gsm0_receive.patch
    (git-fixes bsc#1225642 CVE-2024-36016).
  - Update
    patches.suse/usb-gadget-f_fs-Fix-race-between-aio_cancel-and-AIO-.patch
    (git-fixes bsc#1225749 CVE-2024-36894).
  - Update
    patches.suse/usb-gadget-uvc-use-correct-buffer-size-when-parsing-.patch
    (git-fixes bsc#1225750 CVE-2024-36895).
  - Update
    patches.suse/usb-typec-tcpm-Check-for-port-partner-validity-befor.patch
    (git-fixes bsc#1225748 CVE-2024-36893).
  - Update
    patches.suse/wifi-iwlwifi-mvm-guard-against-invalid-STA-ID-on-rem.patch
    (stable-fixes bsc#1225769 CVE-2024-36921).
  - Update
    patches.suse/wifi-iwlwifi-read-txq-read_ptr-under-lock.patch
    (stable-fixes CVE-2024-36922).
  - Update
    patches.suse/wifi-nl80211-don-t-free-NULL-coalescing-rule.patch
    (git-fixes CVE-2024-36941).
  - Update
    patches.suse/x86-efistub-Call-mixed-mode-boot-services-on-the-firmware-.patch
    (git-fixes bsc#1224742 CVE-2024-35803).
  - commit 539780f
  - powerpc/pseries/lparcfg: drop error message from guest name
    lookup (bsc#1187716 ltc#193451 git-fixes).
  - commit ceab637
  - powerpc/uaccess: Use YZ asm constraint for ld (bsc#1194869).
  - powerpc/uaccess: Fix build errors seen with GCC 13/14
    (bsc#1194869).
  - commit 46b5d84
  - Add reference to L3 bsc#1225765 in BPF control flow graph and precision backtrack fixes (bsc#1225756)
    The L3 bsc#1225765 was created seperately since our customer requires
    PTF.
  - Update patches.suse/bpf-fix-precision-backtracking-instruction-iteration.patch
  - Update patches.suse/bpf-handle-ldimm64-properly-in-check_cfg.patch
  - Update patches.suse/selftests-bpf-add-edge-case-backtracking-logic-test.patch
  - Update patches.suse/selftests-bpf-precision-tracking-test-for-BPF_NEG-an.patch
  - commit 054635e
  - netfilter: nf_tables: release mutex after nft_gc_seq_end from
    abort path (CVE-2024-26925 bsc#1223390).
  - commit 578a709
  - series.conf: cleanup
    Fix subsection header to silence series_insert error.
  - commit 4628dc3

++++ kernel-rt:

  - kabi/severities: Ignore io_uring internal symbols
  - commit 0e91c09
  - perf/x86: Fix out of range data (git-fixes).
  - perf/x86/intel/ds: Don't clear ->pebs_data_cfg for the last
    PEBS event (git-fixes).
  - perf/x86/amd/lbr: Discard erroneous branch entries (git-fixes).
  - commit 664d77f
  - cifs: failure to add channel on iface should bump up weight
    (git-fixes, bsc#1225172).
  - commit 007b237
  - smb: client: fix parsing of SMB3.1.1 POSIX create context
    (git-fixes, bsc#1225172).
  - commit 5f27f69
  - Revert "cifs: reconnect work should have reference on server
    struct" (git-fixes, bsc#1225172).
  - commit 3ca4c0c
  - cifs: fix leak of iface for primary channel (git-fixes,
    bsc#1225172).
  - commit b7eb8e8
  - smb: client: fix mount when dns_resolver key is not available
    (git-fixes, bsc#1225172).
  - commit 28edb5c
  - scsi: lpfc: Copyright updates for 14.4.0.2 patches
    (bsc#1225842).
  - scsi: lpfc: Update lpfc version to 14.4.0.2 (bsc#1225842).
  - scsi: lpfc: Add support for 32 byte CDBs (bsc#1225842).
  - scsi: lpfc: Change lpfc_hba hba_flag member into a bitmask
    (bsc#1225842).
    Refresh:
  - patches.suse/lpfc-reintroduce-old-irq-probe-logic.patch
  - scsi: lpfc: Introduce rrq_list_lock to protect active_rrq_list
    (bsc#1225842).
  - scsi: lpfc: Clear deferred RSCN processing flag when driver
    is unloading (bsc#1225842).
  - scsi: lpfc: Update logging of protection type for T10 DIF I/O
    (bsc#1225842).
  - scsi: lpfc: Change default logging level for unsolicited CT
    MIB commands (bsc#1225842).
  - commit 5a56384
  - nvmet: fix ns enable/disable possible hang (git-fixes).
  - nvme-multipath: fix io accounting on failover (git-fixes).
  - nvme: fix multipath batched completion accounting (git-fixes).
  - commit ed3b392
  - Update
    patches.suse/ALSA-hda-intel-sdw-acpi-fix-usage-of-device_get_name.patch
    (git-fixes CVE-2024-36955).
  - Update
    patches.suse/ARM-9381-1-kasan-clear-stale-stack-poison.patch
    (git-fixes bsc#1225715 CVE-2024-36906).
  - Update
    patches.suse/Bluetooth-HCI-Fix-potential-null-ptr-deref.patch
    (git-fixes bsc#1225579 CVE-2024-36011).
  - Update
    patches.suse/Bluetooth-L2CAP-Fix-slab-use-after-free-in-l2cap_con.patch
    (git-fixes bsc#1225578 CVE-2024-36013).
  - Update
    patches.suse/Bluetooth-msft-fix-slab-use-after-free-in-msft_do_cl.patch
    (git-fixes bsc#1225502 CVE-2024-36012).
  - Update
    patches.suse/Bluetooth-qca-add-missing-firmware-sanity-checks.patch
    (git-fixes bsc#1225722 CVE-2024-36880).
  - Update
    patches.suse/Bluetooth-qca-fix-firmware-check-error-path.patch
    (git-fixes CVE-2024-36942).
  - Update
    patches.suse/Bluetooth-qca-fix-info-leak-when-fetching-fw-build-i.patch
    (git-fixes bsc#1225720 CVE-2024-36032).
  - Update
    patches.suse/KVM-x86-mmu-Write-protect-L2-SPTEs-in-TDP-MMU-when-c.patch
    (git-fixes bsc#1223749 CVE-2024-26990).
  - Update
    patches.suse/KVM-x86-pmu-Disable-support-for-adaptive-PEBS.patch
    (git-fixes bsc#1223692 CVE-2024-26992).
  - Update
    patches.suse/Reapply-drm-qxl-simplify-qxl_fence_wait.patch
    (stable-fixes CVE-2024-36944).
  - Update
    patches.suse/USB-core-Fix-access-violation-during-port-device-rem.patch
    (git-fixes bsc#1225734 CVE-2024-36896).
  - Update
    patches.suse/amd-amdkfd-sync-all-devices-to-wait-all-processes-be.patch
    (stable-fixes CVE-2024-36949).
  - Update patches.suse/bpf-Check-bloom-filter-map-value-size.patch
    (bsc#1224488 CVE-2024-35905 bsc#1225766 CVE-2024-36918).
  - Update
    patches.suse/clk-sunxi-ng-h6-Reparent-CPUX-during-PLL-CPUX-rate-c.patch
    (git-fixes bsc#1225692 CVE-2023-52882).
  - Update
    patches.suse/cxl-pci-Fix-disabling-memory-if-DVSEC-CXL-Range-does.patch
    (git-fixes CVE-2024-26761).
  - Update
    patches.suse/drm-amd-display-Atom-Integrated-System-Info-v2_2-for.patch
    (stable-fixes bsc#1225735 CVE-2024-36897).
  - Update
    patches.suse/drm-amd-pm-fixes-a-random-hang-in-S4-for-SMU-v13.0.4.patch
    (stable-fixes bsc#1225705 CVE-2024-36026).
  - Update
    patches.suse/drm-amdkfd-range-check-cp-bad-op-exception-interrupt.patch
    (stable-fixes CVE-2024-36951).
  - Update
    patches.suse/drm-arm-malidp-fix-a-possible-null-pointer-dereferen.patch
    (git-fixes bsc#1225593 CVE-2024-36014).
  - Update
    patches.suse/drm-nouveau-firmware-Fix-SG_DEBUG-error-with-nvkm_fi.patch
    (stable-fixes bsc#1225728 CVE-2024-36885).
  - Update
    patches.suse/efi-unaccepted-touch-soft-lockup-during-memory-accept.patch
    (git-fixes bsc#1225773 CVE-2024-36936).
  - Update
    patches.suse/firewire-ohci-mask-bus-reset-interrupts-between-ISR-.patch
    (stable-fixes CVE-2024-36950).
  - Update patches.suse/gpiolib-cdev-fix-uninitialised-kfifo.patch
    (git-fixes bsc#1225736 CVE-2024-36898).
  - Update
    patches.suse/i40e-fix-vf-may-be-used-uninitialized-in-this-functi.patch
    (git-fixes bsc#1225698 CVE-2024-36020).
  - Update
    patches.suse/maple_tree-fix-mas_empty_area_rev-null-pointer-deref.patch
    (git-fixes bsc#1225710 CVE-2024-36891).
  - Update
    patches.suse/mm-slab-make-__free-kfree-accept-error-pointers.patch
    (git-fixes bsc#1225714 CVE-2024-36890).
  - Update
    patches.suse/mmc-sdhci-msm-pervent-access-to-suspended-controller.patch
    (git-fixes bsc#1225708 CVE-2024-36029).
  - Update
    patches.suse/net-hns3-fix-kernel-crash-when-devlink-reload-during.patch
    (git-fixes bsc#1225699 CVE-2024-36021).
  - Update
    patches.suse/nouveau-dmem-handle-kcalloc-allocation-failure.patch
    (git-fixes CVE-2024-26943).
  - Update
    patches.suse/nouveau-uvmm-fix-addr-range-calcs-for-remap-operatio.patch
    (git-fixes bsc#1225694 CVE-2024-36018).
  - Update
    patches.suse/pinctrl-core-delete-incorrect-free-in-pinctrl_enable.patch
    (git-fixes CVE-2024-36940).
  - Update
    patches.suse/pinctrl-devicetree-fix-refcount-leak-in-pinctrl_dt_t.patch
    (git-fixes CVE-2024-36959).
  - Update
    patches.suse/ppdev-Add-an-error-check-in-register_device.patch
    (git-fixes bsc#1225640 CVE-2024-36015).
  - Update patches.suse/qibfs-fix-dentry-leak.patch (git-fixes
    CVE-2024-36947).
  - Update
    patches.suse/regmap-maple-Fix-cache-corruption-in-regcache_maple_.patch
    (git-fixes bsc#1225695 CVE-2024-36019).
  - Update
    patches.suse/s390-cio-Ensure-the-copied-buf-is-NUL-terminated.patch
    (git-fixes bsc#1223869 bsc#1225747 CVE-2024-36931).
  - Update
    patches.suse/s390-qeth-Fix-kernel-panic-after-setting-hsuid.patch
    (git-fixes bsc#1223874 bsc#1225775 CVE-2024-36928).
  - Update
    patches.suse/scsi-qla2xxx-Fix-off-by-one-in-qla_edif_app_getstats.patch
    (git-fixes bsc#1225704 CVE-2024-36025).
  - Update
    patches.suse/spi-fix-null-pointer-dereference-within-spi_sync.patch
    (git-fixes CVE-2024-36930).
  - Update
    patches.suse/swiotlb-Fix-double-allocation-of-slots-due-to-broken-alignment-handling.patch
    (bsc#1224331 bsc#1224602 CVE-2024-35814).
  - Update
    patches.suse/tty-n_gsm-fix-possible-out-of-bounds-in-gsm0_receive.patch
    (git-fixes bsc#1225642 CVE-2024-36016).
  - Update
    patches.suse/usb-gadget-f_fs-Fix-race-between-aio_cancel-and-AIO-.patch
    (git-fixes bsc#1225749 CVE-2024-36894).
  - Update
    patches.suse/usb-gadget-uvc-use-correct-buffer-size-when-parsing-.patch
    (git-fixes bsc#1225750 CVE-2024-36895).
  - Update
    patches.suse/usb-typec-tcpm-Check-for-port-partner-validity-befor.patch
    (git-fixes bsc#1225748 CVE-2024-36893).
  - Update
    patches.suse/wifi-iwlwifi-mvm-guard-against-invalid-STA-ID-on-rem.patch
    (stable-fixes bsc#1225769 CVE-2024-36921).
  - Update
    patches.suse/wifi-iwlwifi-read-txq-read_ptr-under-lock.patch
    (stable-fixes CVE-2024-36922).
  - Update
    patches.suse/wifi-nl80211-don-t-free-NULL-coalescing-rule.patch
    (git-fixes CVE-2024-36941).
  - Update
    patches.suse/x86-efistub-Call-mixed-mode-boot-services-on-the-firmware-.patch
    (git-fixes bsc#1224742 CVE-2024-35803).
  - commit 539780f
  - powerpc/pseries/lparcfg: drop error message from guest name
    lookup (bsc#1187716 ltc#193451 git-fixes).
  - commit ceab637
  - powerpc/uaccess: Use YZ asm constraint for ld (bsc#1194869).
  - powerpc/uaccess: Fix build errors seen with GCC 13/14
    (bsc#1194869).
  - commit 46b5d84
  - Add reference to L3 bsc#1225765 in BPF control flow graph and precision backtrack fixes (bsc#1225756)
    The L3 bsc#1225765 was created seperately since our customer requires
    PTF.
  - Update patches.suse/bpf-fix-precision-backtracking-instruction-iteration.patch
  - Update patches.suse/bpf-handle-ldimm64-properly-in-check_cfg.patch
  - Update patches.suse/selftests-bpf-add-edge-case-backtracking-logic-test.patch
  - Update patches.suse/selftests-bpf-precision-tracking-test-for-BPF_NEG-an.patch
  - commit 054635e
  - netfilter: nf_tables: release mutex after nft_gc_seq_end from
    abort path (CVE-2024-26925 bsc#1223390).
  - commit 578a709
  - series.conf: cleanup
    Fix subsection header to silence series_insert error.
  - commit 4628dc3

++++ libdrm:

  - update to 2.4.121
    * meson: make build system happy by replacing deprecated feature
    * include poll.h instead of sys/poll.h
    * amdgpu: Make amdgpu_device_deinitialize thread-safe
    * Revert "xf86drm: ignore symlinks in process_device()"
    * xf86drm: Don't consider node names longer than the maximum allowed
    * tests/amdgpu: fix compile warning with the guard enum value
    * tests/amdgpu: fix compile error with gcc7.5
    * tests/amdgpu: fix compile error with gcc14
    * tests/util: add tidss driver
    * meson: Replace usages of deprecated ExternalProgram.path()
    * meson: Fix broken str.format usage
    * amdgpu: add marketing names from Adrenalin 23.11.1
    * amdgpu: add marketing names from PRO Edition for W7700
    * amdgpu: add marketing names from Windows Steam Deck OLED APU driver
    * amdgpu: add marketing names from amd-6.0
    * amdgpu: add marketing name for Radeon RX 6550M
    * amdgpu: add marketing names from amd-6.0.1
    * amdgpu: Make amdgpu_cs_signal_semaphore() thread-safe
    * amdgpu: sync amdgpu_drm.h
    * symbols-check: Add _GLOBAL_OFFSET_TABLE_
    * symbols-check: Add _fbss, _fdata, _ftext
    * amdgpu: expose amdgpu_va_manager publicly
    * amdgpu: add amdgpu_va_range_alloc2
    * amdgpu: add amdgpu_device_initialize2
    * amdgpu: fix deinit logic
    * ci: build with meson --fatal-meson-warnings
    * ci: use "meson setup" sub-command
    * xf86drm: document drmDevicesEqual()
    * xf86drm: ignore symlinks in process_device()

++++ freeipmi:

  - use %autosetup
  - apply patches with -p1

++++ samba:

  - Fix non deterministic builds; (bsc#1225754); (bso#13213);

++++ ncurses:

  - Add ncurses patch 20240601
    + improve formatting/style of manpages (patches by Branden Robinson).
    + change Ada95/configure to use --with-screen option rather than
  - -enable-widec, to provide more choices of underlying curses library

++++ libvirt:

  - Update to libvirt 10.4.0
  - network: use nftables to setup virtual network firewall rules
    boo#1201510
  - Many incremental improvements and bug fixes, see
    https://libvirt.org/news.html#v10-4-0-2024-06-03

++++ netavark:

  - Remove redundant source: cargo_config
  - Update to version 1.11.0:
    * Release v1.11.0
    * Update release notes for 1.11.0
    * update netlink-packet-route to 0.20.0
    * run cargo update
    * fix: remove extra / in make install and uninstall
    * chore(deps): update dependency containers/automation_images to v20240529
    * fix(deps): update rust crate nix to 0.29.0
    * fix(deps): update rust crate nispor to 1.2.19
    * fix(deps): update rust crate anyhow to 1.0.86
    * fix(deps): update rust crate anyhow to 1.0.85
    * [skip-ci] Packit: do not create dup jobs on podman-next
    * fix(deps): update rust crate anyhow to 1.0.84
    * [skip-ci] RPM: use default __cargo macro across all envs
    * [skip-ci] RPM: switch default firewall to nftables on EL10+
    * chore(deps): update dependency containers/automation_images to v20240513
    * Add conditional compilation of default firewall driver
    * fix(deps): update rust crate serde_json to 1.0.117
    * fix new clippy warnings
    * Update CI image to fedora 40
    * fix ncat sctp tests
    * fix(deps): update rust crate anyhow to 1.0.83
    * build(deps): bump h2 from 0.3.25 to 0.3.26
    * [skip-ci] Packit: distinct `-rhel` packages value
    * [skip-ci] Packit: enable c10s downstream sync
    * fix(deps): update rust crate libc to 0.2.154
    * fix(deps): update rust crate ipnet to 2.9.0
    * fix(deps): update rust crate tower to 0.4.13
    * fix(deps): update rust crate tokio-stream to 0.1.15
    * fix(deps): update rust crate prost to 0.12.4
    * fix(deps): update rust crate iptables to 0.5.1
    * [skip-ci] Packit: remove el8 jobs
    * fix(deps): update rust crate anyhow to 1.0.82
    * fix(deps): update rust crate serde to 1.0.199
    * Add suffix to Aardvark internal network filenames
    * fix port forward with strict RPF and multi networks
    * renovate: stop rebasing PRs automatically
    * chore(deps): update rust crate chrono to 0.4.38
    * fix(deps): update rust crate serde_json to 1.0.116
    * fix(deps): update rust crate netlink-sys to 0.8.6
    * nftables: only dump netavark table rules
    * update nftables to 0.4
    * fix aardvark-dns netns check
    * fix(deps): update rust crate tokio to 1.37
    * fix(deps): update rust crate netlink-packet-route to 0.19.0
    * Update to nix-0.28.0
    * fix(deps): update rust crate mozim to 0.2.3
    * fix(deps): update rust crate nispor to 1.2.18
    * Update chrono
    * fix(deps): update rust crate serde_json to 1.0.115
    * build(deps): bump mio from 0.8.9 to 0.8.11
    * [skip-ci] rpm: aardvark-dns is a hard dep across the board
    * Update Rust crate env_logger to 0.11.3
    * Update Rust crate serde to 1.0.197
    * Update Rust crate tempfile to 3.10.1
    * Update Rust crate log to 0.4.21
    * Update Rust crate zbus to 3.15.2
    * Update Rust crate serde_json to 1.0.114
    * Update Rust crate env_logger to 0.11.2
    * Update Rust crate chrono to 0.4.34
    * Update Rust crate tonic-build to 0.11
    * Update Rust crate tonic to 0.11
    * fix netavark update to not start a new aardvark-dns
    * Update Rust crate tempfile to 3.10.0
    * Update Rust crate zbus to 3.15.0
    * Update Rust crate tokio to 1.36
    * Update Rust crate chrono to 0.4.33
    * Do not perform network namespace detection on AV update
    * [CI:BUILD] Packit/rpm: fix aardvark-dns handling
    * Update Rust crate serde_json to 1.0.113
    * Update Rust crate serde_json to 1.0.112
    * Update Rust crate env_logger to 0.11.1
    * update README with nftables support
    * Bump to v1.11.0-dev
    * perf-netavark: accept fw driver as argument
    * perf-netavark: fix missing --config arg

++++ python-libvirt-python:

  - Update to 10.4.0
  - Add all new APIs and constants in libvirt 10.4.0

------------------------------------------------------------------
------------------  2024-6-2  -  Jun 2 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Restrict all internal depencency version to match the exact Mesa build,
    so that users won't install Mesa packages partly from other repos and
    make the system broken.

++++ Mesa-drivers:

  - Restrict all internal depencency version to match the exact Mesa build,
    so that users won't install Mesa packages partly from other repos and
    make the system broken.

++++ c-ares:

  - c-ares 1.29.0
    Features:
    * When using ARES_OPT_EVENT_THREAD, automatically reload
    system configuration when network conditions change.
    [PR #759]
    * Apple: reimplement DNS configuration reading to more
    accurately pull DNS settings. [PR #750]
    * Add observability into DNS server health via a server state
    callback, invoked whenever a query finishes. [PR #744]
    * Add server failover retry behavior, where failed servers are
    retried with small probability after a minimum delay.
    [PR #731]
    Changes:
    * Mark ares_channel_t * as const in more places in the public
    API. [PR #758]
    Bugfixes:
    * Due to a logic flaw dns name compression writing was not
    properly implemented which would result in the name prefix not
    being written for a partial match. This could cause issues in
    various record types such as MX records when using the
    deprecated API. Regression introduced in 1.28.0. [Issue #757]
    * Revert OpenBSD SOCK_DNS flag, it doesn't do what the docs say
    it does and causes c-ares to become non-functional. [PR #754]
    * ares_getnameinfo(): loosen validation on salen parameter.
    [Issue #752]
    * cmake: Android requires C99. [PR #748]
    * ares_queue_wait_empty() does not honor timeout_ms >= 0.
    [Issue #742]

------------------------------------------------------------------
------------------  2024-6-1  -  Jun 1 2024  -------------------
------------------------------------------------------------------

++++ lvm2-device-mapper:

  - add rpm dependency in spec file for aligning new DM udev rules (bsc#1225783)
    * update lvm2.spec

++++ python-kiwi:

  - Add support for arch attr in repository element
    Allow to provide different repository sections per architecture

++++ findutils:

  - Update to 4.10.0.
    Announcement: https://savannah.gnu.org/news/?id=10638
  - findutils-xautofs.patch: Refresh.

++++ kernel-default:

  - ASoC: wm_adsp: Add missing MODULE_DESCRIPTION() (git-fixes).
  - ALSA: ump: Set default protocol when not given explicitly
    (git-fixes).
  - ALSA/hda: intel-dsp-config: reduce log verbosity (git-fixes).
  - ALSA: core: Remove debugfs at disconnection (git-fixes).
  - commit f8e0906
  - drm/panel: sitronix-st7789v: fix display size for
    jt240mhqs_hwt_ek_e3 panel (git-fixes).
  - drm/panel: sitronix-st7789v: tweak timing for
    jt240mhqs_hwt_ek_e3 panel (git-fixes).
  - drm/panel: sitronix-st7789v: fix timing for jt240mhqs_hwt_ek_e3
    panel (git-fixes).
  - dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
    (git-fixes).
  - Revert "drm/amdkfd: fix gfx_target_version for certain 11.0.3
    devices" (stable-fixes).
  - drm/amd/display: Enable colorspace property for MST connectors
    (git-fixes).
  - drm/i915: Fix audio component initialization (git-fixes).
  - drm/i915/dpt: Make DPT object unshrinkable (git-fixes).
  - drm/i915/gt: Fix CCS id's calculation for CCS mode setting
    (git-fixes).
  - drm/i915/guc: avoid FIELD_PREP warning (git-fixes).
  - drm/i915/gt: Disarm breadcrumbs if engines are already idle
    (git-fixes).
  - drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE)
    (git-fixes).
  - hwmon: (shtc1) Fix property misspelling (git-fixes).
  - hwmon: (intel-m10-bmc-hwmon) Fix multiplier for N6000 board
    power sensor (git-fixes).
  - spi: stm32: Don't warn about spurious interrupts (git-fixes).
  - spi: Don't mark message DMA mapped when no transfer in it is
    (git-fixes).
  - dma-mapping: benchmark: handle NUMA_NO_NODE correctly
    (git-fixes).
  - dma-mapping: benchmark: fix node id validation (git-fixes).
  - ALSA: seq: ump: Fix swapped song position pointer data
    (git-fixes).
  - ASoC: SOF: ipc4-topology: Fix input format query of process
    modules without base extension (git-fixes).
  - ALSA: seq: Fix yet another spot for system message conversion
    (git-fixes).
  - ALSA: ump: Don't accept an invalid UMP protocol number
    (git-fixes).
  - ALSA: ump: Don't clear bank selection after sending a program
    change (git-fixes).
  - ALSA: seq: Fix incorrect UMP type for system messages
    (git-fixes).
  - ALSA: seq: Don't clear bank selection at event -> UMP MIDI2
    conversion (git-fixes).
  - ALSA: seq: Fix missing bank setup between MIDI1/MIDI2 UMP
    conversion (git-fixes).
  - ALSA: hda/realtek: Adjust G814JZR to use SPI init for amp
    (git-fixes).
  - docs: netdev: Fix typo in Signed-off-by tag (git-fixes).
  - net: usb: smsc95xx: fix changing LED_SEL bit value updated
    from EEPROM (git-fixes).
  - net: phy: micrel: set soft_reset callback to genphy_soft_reset
    for KSZ8061 (git-fixes).
  - commit e5505a5
  - Add alt-commit to a nouveau patch
  - commit 0024d10

++++ kernel-rt:

  - ASoC: wm_adsp: Add missing MODULE_DESCRIPTION() (git-fixes).
  - ALSA: ump: Set default protocol when not given explicitly
    (git-fixes).
  - ALSA/hda: intel-dsp-config: reduce log verbosity (git-fixes).
  - ALSA: core: Remove debugfs at disconnection (git-fixes).
  - commit f8e0906
  - drm/panel: sitronix-st7789v: fix display size for
    jt240mhqs_hwt_ek_e3 panel (git-fixes).
  - drm/panel: sitronix-st7789v: tweak timing for
    jt240mhqs_hwt_ek_e3 panel (git-fixes).
  - drm/panel: sitronix-st7789v: fix timing for jt240mhqs_hwt_ek_e3
    panel (git-fixes).
  - dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
    (git-fixes).
  - Revert "drm/amdkfd: fix gfx_target_version for certain 11.0.3
    devices" (stable-fixes).
  - drm/amd/display: Enable colorspace property for MST connectors
    (git-fixes).
  - drm/i915: Fix audio component initialization (git-fixes).
  - drm/i915/dpt: Make DPT object unshrinkable (git-fixes).
  - drm/i915/gt: Fix CCS id's calculation for CCS mode setting
    (git-fixes).
  - drm/i915/guc: avoid FIELD_PREP warning (git-fixes).
  - drm/i915/gt: Disarm breadcrumbs if engines are already idle
    (git-fixes).
  - drm/shmem-helper: Fix BUG_ON() on mmap(PROT_WRITE, MAP_PRIVATE)
    (git-fixes).
  - hwmon: (shtc1) Fix property misspelling (git-fixes).
  - hwmon: (intel-m10-bmc-hwmon) Fix multiplier for N6000 board
    power sensor (git-fixes).
  - spi: stm32: Don't warn about spurious interrupts (git-fixes).
  - spi: Don't mark message DMA mapped when no transfer in it is
    (git-fixes).
  - dma-mapping: benchmark: handle NUMA_NO_NODE correctly
    (git-fixes).
  - dma-mapping: benchmark: fix node id validation (git-fixes).
  - ALSA: seq: ump: Fix swapped song position pointer data
    (git-fixes).
  - ASoC: SOF: ipc4-topology: Fix input format query of process
    modules without base extension (git-fixes).
  - ALSA: seq: Fix yet another spot for system message conversion
    (git-fixes).
  - ALSA: ump: Don't accept an invalid UMP protocol number
    (git-fixes).
  - ALSA: ump: Don't clear bank selection after sending a program
    change (git-fixes).
  - ALSA: seq: Fix incorrect UMP type for system messages
    (git-fixes).
  - ALSA: seq: Don't clear bank selection at event -> UMP MIDI2
    conversion (git-fixes).
  - ALSA: seq: Fix missing bank setup between MIDI1/MIDI2 UMP
    conversion (git-fixes).
  - ALSA: hda/realtek: Adjust G814JZR to use SPI init for amp
    (git-fixes).
  - docs: netdev: Fix typo in Signed-off-by tag (git-fixes).
  - net: usb: smsc95xx: fix changing LED_SEL bit value updated
    from EEPROM (git-fixes).
  - net: phy: micrel: set soft_reset callback to genphy_soft_reset
    for KSZ8061 (git-fixes).
  - commit e5505a5
  - Add alt-commit to a nouveau patch
  - commit 0024d10

++++ lvm2:

  - add rpm dependency in spec file for aligning new DM udev rules (bsc#1225783)
    * update lvm2.spec

------------------------------------------------------------------
------------------  2024-5-31  -  May 31 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Add --list-profiles to image info
    Allow to list available profiles from the processed image
    description

++++ git:

  - Compat stub for %python3_fix_shebang_path
  - only call the %python3_fix_shebang_path if it is actually
    defined. This fixes the build on 15.x
  - update to 2.45.2:
    * Revert "defense in depth" fixes from 2.45.1 broke 'git lfs' and
    'git annex'

++++ haproxy:

  - AppArmor: allow haproxy to read the files needed for the
    "p post_mortem" support

++++ kernel-default:

  - 9p: add missing locking around taking dentry fid list (git-fixes)
  - commit 581af2d
  - ecryptfs: Fix buffer size for tag 66 packet (git-fixes)
  - commit 17aae28
  - llc: call sock_orphan() at release time
    (CVE-2024-26625 bsc#1221086)
  - commit fe6bd4d
  - fs/9p: translate O_TRUNC into OTRUNC (git-fixes)
  - commit e03e9a5
  - bpf: Fix precision tracking for BPF_ALU | BPF_TO_BE | BPF_END
    (git-fixes).
  - commit e824dba
  - fs/9p: only translate RWX permissions for plain 9P2000 (git-fixes)
  - commit ebd0dc6
  - selftests/bpf: precision tracking test for BPF_NEG and BPF_END
    (bsc#1225756).
  - commit a410d73
  - selftests/bpf: add edge case backtracking logic test
    (bsc#1225756).
  - bpf: fix precision backtracking instruction iteration
    (bsc#1225756).
  - bpf: handle ldimm64 properly in check_cfg() (bsc#1225756).
  - commit 9cbb99b
  - fs: indicate request originates from old mount API (git-fixes)
  - commit 0754468
  - locks: fix KASAN: use-after-free in trace_event_raw_event_filelock_lock (git-fixes)
  - commit 4c48f9f
  - fs: Fix error checking for d_hash_and_lookup() (git-fixes)
  - commit c90513f
  - nvme-pci: Add quirk for broken MSIs (git-fixes).
  - nvme: fix warn output about shared namespaces without
    CONFIG_NVME_MULTIPATH (git-fixes).
  - drivers/nvme: Add quirks for device 126f:2262 (git-fixes).
  - commit fff60eb
  - Update
    patches.suse/nvme-ensure-disabling-pairs-with-unquiesce.patch
    (jsc#PED-6252 jsc#PED-5728 jsc#PED-5062 jsc#PED-3535
    bsc#1224534).
  - commit d9497f3
  - octeontx2-af: fix the double free in rvu_npc_freemem() (bsc#1225712 CVE-2024-36030)
  - commit 294ca99
  - idpf: extend tx watchdog timeout (bsc#1224137).
  - commit fbf0ed6
  - kABI fix of KVM: x86/pmu: Allow programming events that match
    unsupported arch events (bsc#1225696).
  - Refresh
    patches.suse/KVM-x86-pmu-Allow-programming-events-that-match-unsu.patch.
  - commit 0e4ccf5

++++ kernel-rt:

  - 9p: add missing locking around taking dentry fid list (git-fixes)
  - commit 581af2d
  - ecryptfs: Fix buffer size for tag 66 packet (git-fixes)
  - commit 17aae28
  - llc: call sock_orphan() at release time
    (CVE-2024-26625 bsc#1221086)
  - commit fe6bd4d
  - fs/9p: translate O_TRUNC into OTRUNC (git-fixes)
  - commit e03e9a5
  - bpf: Fix precision tracking for BPF_ALU | BPF_TO_BE | BPF_END
    (git-fixes).
  - commit e824dba
  - fs/9p: only translate RWX permissions for plain 9P2000 (git-fixes)
  - commit ebd0dc6
  - selftests/bpf: precision tracking test for BPF_NEG and BPF_END
    (bsc#1225756).
  - commit a410d73
  - selftests/bpf: add edge case backtracking logic test
    (bsc#1225756).
  - bpf: fix precision backtracking instruction iteration
    (bsc#1225756).
  - bpf: handle ldimm64 properly in check_cfg() (bsc#1225756).
  - commit 9cbb99b
  - fs: indicate request originates from old mount API (git-fixes)
  - commit 0754468
  - locks: fix KASAN: use-after-free in trace_event_raw_event_filelock_lock (git-fixes)
  - commit 4c48f9f
  - fs: Fix error checking for d_hash_and_lookup() (git-fixes)
  - commit c90513f
  - nvme-pci: Add quirk for broken MSIs (git-fixes).
  - nvme: fix warn output about shared namespaces without
    CONFIG_NVME_MULTIPATH (git-fixes).
  - drivers/nvme: Add quirks for device 126f:2262 (git-fixes).
  - commit fff60eb
  - Update
    patches.suse/nvme-ensure-disabling-pairs-with-unquiesce.patch
    (jsc#PED-6252 jsc#PED-5728 jsc#PED-5062 jsc#PED-3535
    bsc#1224534).
  - commit d9497f3
  - octeontx2-af: fix the double free in rvu_npc_freemem() (bsc#1225712 CVE-2024-36030)
  - commit 294ca99
  - idpf: extend tx watchdog timeout (bsc#1224137).
  - commit fbf0ed6
  - kABI fix of KVM: x86/pmu: Allow programming events that match
    unsupported arch events (bsc#1225696).
  - Refresh
    patches.suse/KVM-x86-pmu-Allow-programming-events-that-match-unsu.patch.
  - commit 0e4ccf5

++++ systemd:

  - Rename PAM config file 'systemd-user' into 'pam.systemd-user'.
  - Import commit 603cd1d4d81147d4f2eccd5e352064a4215119b4 (merge of v255.7)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/b9c17562f612ab2cd8cfee1960714c58d0a6c593...603cd1d4d81147d4f2eccd5e352064a4215119b4
  - Import commit b9c17562f612ab2cd8cfee1960714c58d0a6c593
    b9c17562f6 99-systemd.rules: rework SYSTEMD_READY logic for device mapper
    c5003fc15e pcrlock: add make_pcrlock_record_from_stream

++++ libzypp:

  - zypp-tui: Make sure translated texts use the correct textdomain
    (fixes #551)
  - Skip libproxy1 requires for tumbleweed.
  - version 17.34.1 (34)

++++ patterns-base:

  - require openSUSE-build key on openSUSE

++++ ovmf:

  - Remove unused openSUSE-UEFI-SIGN-Certificate-2048.crt
  - Use virt-fw-vars to create varstores with enrolled keys instead
    of using QEMU + generated .iso images:
    * Includes newer 2023 certs from Microsoft
    * Remove now unused files:
    + gen-key-enrollment-iso.sh
    + ovmf-set-fixed-enroll-time.patch
    + ovmf-build-funcs.sh
    * No longer build and package EnrollDefaultKeys.efi and Shell.efi

------------------------------------------------------------------
------------------  2024-5-30  -  May 30 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Bump version: 10.0.18 → 10.0.19

++++ fde-tools:

  - Fix fde-tools-change-rpm-macro-dir.patch which didn't set
    RPM_MACRO_DIR correctly

++++ kernel-default:

  - swiotlb: extend buffer pre-padding to alloc_align_mask if necessary (bsc#1224331)
  - commit c148fd3
  - calipso: fix memory leak in netlbl_calipso_add_pass()
    (CVE-2023-52698 bsc#1224621)
  - commit 5fc90b9
  - kabi/severities: ignore IMS functions
    They were dropped in previous patches. Noone is supposed to use them.
  - commit 494909c
  - smb: client: set correct id, uid and cruid for multiuser
    automounts (bsc#1223011, CVE-2024-26822).
  - commit 6fce785
  - smb: client: fix potential OOBs in smb2_parse_contexts()
    (bsc#1220148, CVE-2023-52434).
  - commit a00a7f6

++++ kernel-rt:

  - swiotlb: extend buffer pre-padding to alloc_align_mask if necessary (bsc#1224331)
  - commit c148fd3
  - calipso: fix memory leak in netlbl_calipso_add_pass()
    (CVE-2023-52698 bsc#1224621)
  - commit 5fc90b9
  - kabi/severities: ignore IMS functions
    They were dropped in previous patches. Noone is supposed to use them.
  - commit 494909c
  - smb: client: set correct id, uid and cruid for multiuser
    automounts (bsc#1223011, CVE-2024-26822).
  - commit 6fce785
  - smb: client: fix potential OOBs in smb2_parse_contexts()
    (bsc#1220148, CVE-2023-52434).
  - commit a00a7f6

++++ xz:

  - Update to 5.6.2:
    * Remove the backdoor (CVE-2024-3094).
    * Not changed: Memory sanitizer (MSAN) has a false positive
    in the CRC CLMUL code which also makes OSS Fuzz unhappy.
    Valgrind is smarter and doesn't complain.
    A revision to the CLMUL code is coming anyway and this issue
    will be cleaned up as part of it. It won't be backported to
    5.6.x or 5.4.x because the old code isn't wrong. There is
    no reason to risk introducing regressions in old branches
    just to silence a false positive.
    * liblzma:
  - lzma_index_decoder() and lzma_index_buffer_decode(): Fix
    a missing output pointer initialization (*i = NULL) if the
    functions are called with invalid arguments. The API docs
    say that such an initialization is always done. In practice
    this matters very little because the problem can only occur
    if the calling application has a bug and these functions
    return LZMA_PROG_ERROR.
  - lzma_str_to_filters(): Fix a missing output pointer
    initialization (*error_pos = 0). This is very similar
    to the fix above.
  - Fix C standard conformance with function pointer types.
  - Remove GNU indirect function (IFUNC) support. This is *NOT*
    done for security reasons even though the backdoor relied on
    this code. The performance benefits of IFUNC are too tiny in
    this project to make the extra complexity worth it.
  - FreeBSD on ARM64: Add error checking to CRC32 instruction
    support detection.
  - Fix building with NVIDIA HPC SDK.
    * xz:
  - Fix a C standard conformance issue in --block-list parsing
    (arithmetic on a null pointer).
  - Fix a warning from GNU groff when processing the man page:
    "warning: cannot select font 'CW'"
    * xzdec: Add support for Linux Landlock ABI version 4. xz already
    had the v3-to-v4 change but it had been forgotten from xzdec.

++++ ndctl:

  - Update to version 79
    * New cxl-wait-sanitize and cxl-set-alert-config commands
    * Support for QOS Class in cxl-create-region

++++ python-azuremetadata:

  - Replace python3-azuremetadata with universal packaging
    (https://trello.com/c/fupyiTVo/168-python3-packages-in-factory).
  - Rename to python-azuremetadata.

++++ python-ec2metadata:

  - Replace python3-ec2metadata with universal packaging
    (https://trello.com/c/fupyiTVo/168-python3-packages-in-factory).
  - Rename to python-ec2metadata.

++++ python-gcemetadata:

  - Replace python3-gcemetadata with universal packaging
    (https://trello.com/c/fupyiTVo/168-python3-packages-in-factory).
  - Rename to python-gcemetadata.

------------------------------------------------------------------
------------------  2024-5-29  -  May 29 2024  -------------------
------------------------------------------------------------------

++++ cups:

  - Update to version 2.4.8:
    See https://github.com/openprinting/cups/releases
    CUPS 2.4.8 brings many bug fixes which aggregated over the last
    half a year. It brings the important fix for race conditions
    and errors which can happen when installing permanent
    IPP Everywhere printer, support for PAM modules password-auth
    and system-auth and new option for lpstat which can show only
    the successful jobs.
    Detailed list (from CHANGES.md):
    * Added warning if the device has to be asked for
    'all,media-col-database' separately (Issue #829)
    * Added new value for 'lpstat' option '-W' - successfull - for
    getting successfully printed jobs (Issue #830)
    * Added support for PAM modules password-auth
    and system-auth (Issue #892)
    * Updated IPP Everywhere printer creation error
    reporting (Issue #347)
    * Updated and documented the MIME typing buffering
    limit (Issue #925)
    * Raised 'cups_enum_dests()' timeout for listing
    available IPP printers (Issue #751)
    * Now report an error for temporary printer defaults
    with lpadmin (Issue #237)
    * Fixed mapping of PPD InputSlot, MediaType,
    and OutputBin values (Issue #238)
    * Fixed "document-unprintable-error" handling (Issue #391)
    * Fixed the web interface not showing an error
    for a non-existent printer (Issue #423)
    * Fixed printing of jobs with job name longer than 255 chars
    on older printers (Issue #644)
    * Really backported fix for Issue #742
    * Fixed 'cupsCopyDestInfo' device connection
    detection (Issue #586)
    * Fixed "Upgrade" header handling when there is
    no TLS support (Issue #775)
    * Fixed memory leak when unloading a job (Issue #813)
    * Fixed memory leak when creating color profiles (Issue #815)
    * Fixed a punch finishing bug in the IPP Everywhere
    support (Issue #821)
    * Fixed crash in 'scan_ps()' if incoming argument
    is NULL (Issue #831)
    * Fixed setting job state reasons for successful
    jobs (Issue #832)
    * Fixed infinite loop in IPP backend if hostname
    is IP address with Kerberos (Issue #838)
    * Added additional check on socket if 'revents' from 'poll()'
    returns POLLHUP together with POLLIN or POLLOUT
    in 'httpAddrConnect2()' (Issue #839)
    * Fixed crash in 'ppdEmitString()' if 'size' is NULL (Issue #850)
    * Fixed reporting 'media-source-supported' when
    sharing printer  which has numbers as strings instead of
    keywords as 'InputSlot' values (Issue #859)
    * Fixed IPP backend to support the "print-scaling" option
    with IPP printers (Issue #862)
    * Fixed potential race condition for the creation
    of temporary queues (Issue #871)
    * Fixed 'httpGets' timeout handling (Issue #879)
    * Fixed checking for required attributes during
    PPD generation (Issue #890)
    * Fixed encoding of IPv6 addresses in HTTP requests (Issue #903)
    * Fixed sending response headers to client (Issue #927)
    * Fixed CGI program initialization and validation
    of form checkbox and text fields.
    Issues are those at https://github.com/OpenPrinting/cups/issues
  - Adapted downgrade-autoconf-requirement.patch for CUPS 2.4.8

++++ python-kiwi:

  - package: Always include patches and number all sources and patches
    This ensures that stuff is applied reliably and all sources and patches
    are included as expected.
    Then the added kiwi-revert-bls-default-for-suse.patch is applied
    conditionally for SUSE distributions.
  - Bump version: 10.0.17 → 10.0.18
  - package: adjust openSUSE patch
  - Bump version: 10.0.16 → 10.0.17
  - Fixed box plugin documentation
    The provided example was no longer correct according to
    changes on the image description referenced in the example

++++ haproxy:

  - Update to version 3.0.0+git0.5590ada47:
    https://www.haproxy.com/blog/announcing-haproxy-3-0
    https://www.mail-archive.com/haproxy@formilux.org/msg44993.html

++++ kernel-default:

  - dm-integrity: fix a memory leak when rechecking the data
    (bsc#1223077, CVE-2024-26860).
  - commit 29984e7
  - btrfs: zoned: don't skip block groups with 100% zone unusable
    (bsc#1220120).
  - btrfs: don't refill whole delayed refs block reserve when
    starting transaction (bsc#1220120).
  - btrfs: add new unused block groups to the list of unused block
    groups (bsc#1220120).
  - btrfs: do not delete unused block group if it may be used soon
    (bsc#1220120).
  - btrfs: add and use helper to check if block group is used
    (bsc#1220120).
  - btrfs: always reserve space for delayed refs when starting
    transaction (bsc#1220120).
  - btrfs: stop doing excessive space reservation for csum deletion
    (bsc#1220120).
  - btrfs: remove pointless initialization at
    btrfs_delayed_refs_rsv_release() (bsc#1220120).
  - btrfs: reserve space for delayed refs on a per ref basis
    (bsc#1220120).
  - btrfs: allow to run delayed refs by bytes to be released
    instead of count (bsc#1220120).
  - btrfs: simplify check for extent item overrun at
    lookup_inline_extent_backref() (bsc#1220120).
  - btrfs: return -EUCLEAN if extent item is missing when searching
    inline backref (bsc#1220120).
  - btrfs: use a single variable for return value at
    lookup_inline_extent_backref() (bsc#1220120).
  - btrfs: use a single variable for return value at
    run_delayed_extent_op() (bsc#1220120).
  - btrfs: remove pointless 'ref_root' variable from
    run_delayed_data_ref() (bsc#1220120).
  - btrfs: initialize key where it's used when running delayed
    data ref (bsc#1220120).
  - btrfs: remove refs_to_drop argument from __btrfs_free_extent()
    (bsc#1220120).
  - btrfs: remove refs_to_add argument from __btrfs_inc_extent_ref()
    (bsc#1220120).
  - btrfs: remove the refcount warning/check at
    btrfs_put_delayed_ref() (bsc#1220120).
  - btrfs: remove unnecessary logic when running new delayed
    references (bsc#1220120).
  - btrfs: pass a space_info argument to
    btrfs_reserve_metadata_bytes() (bsc#1220120).
  - btrfs: log message if extent item not found when running
    delayed extent op (bsc#1220120).
  - btrfs: remove redundant BUG_ON() from __btrfs_inc_extent_ref()
    (bsc#1220120).
  - btrfs: move btrfs_free_excluded_extents() into block-group.c
    (bsc#1220120).
  - btrfs: open code trivial btrfs_add_excluded_extent()
    (bsc#1220120).
  - btrfs: make find_first_extent_bit() return a boolean
    (bsc#1220120).
  - btrfs: make btrfs_destroy_pinned_extent() return void
    (bsc#1220120).
  - btrfs: make btrfs_destroy_marked_extents() return void
    (bsc#1220120).
  - btrfs: rename add_new_free_space() to btrfs_add_new_free_space()
    (bsc#1220120).
  - btrfs: update documentation for add_new_free_space()
    (bsc#1220120).
  - commit 37b05cd
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch (bsc#1222771).
    In preparation of enabling CONFIG_FIPS_SIGNATURE_SELFTEST, amend the
    missing 'usage' argument in the pkcs7_validate_trust() invocation
    from  the PKCS#7 selftest.
  - commit cfa0827
  - printk: Let no_printk() use _printk() (bsc#1225618).
  - commit 2abd745
  - printk: Update @console_may_schedule in
    console_trylock_spinning() (bsc#1225616).
  - commit e5e7ac5
  - af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock
    (CVE-2024-26676 bsc#1222380).
  - af_unix: Don't peek OOB data without MSG_OOB (CVE-2024-26676 bsc#1222380).
  - af_unix: Clear stale u->oob_skb (CVE-2024-26676 bsc#1222380).
  - commit 7722c8d
  - af_unix: fix use-after-free in unix_stream_read_actor()
    (CVE-2023-52772 bsc#1224989).
  - commit 0f5ff3f
  - certs: Add ECDSA signature verification self-test (bsc#1222777).
  - Port "certs: Add ECDSA signature verification self-test".
  - Enable new CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA.
  - Refresh
    0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch:
    trivial context update to Kconfig
  - commit 7338b2e
  - dump_stack: Do not get cpu_sync for panic CPU (bsc#1225607).
  - commit 3d953e1
  - printk: Avoid non-panic CPUs writing to ringbuffer
    (bsc#1225607).
  - commit 9a41cad
  - certs: Move RSA self-test data to separate file (bsc#1222777).
  - Port "certs: Move RSA self-test data to separate file".
  - Enable new CONFIG_FIPS_SIGNATURE_SELFTEST_RSA.
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch:
  - trivial context update to Kconfig,
  - account for changed pkcs7_validate_trust() callsite amended by
    this refreshed patch.
  - commit 248ad2a
  - printk: Disable passing console lock owner completely during
    panic() (bsc#1225607).
  - commit a31a4d6
  - printk: ringbuffer: Skip non-finalized records in panic
    (bsc#1225607).
  - commit 8be42db
  - Enable CONFIG_FIPS_SIGNATURE_SELFTEST (bsc#1222771)
  - commit 4ade1c7
  - printk: Wait for all reserved records with pr_flush()
    (bsc#1225607).
  - commit 4a07b6c
  - printk: ringbuffer: Cleanup reader terminology (bsc#1225607).
  - commit b3f2a50
  - printk: Add this_cpu_in_panic() (bsc#1225607).
  - commit 8afb830
  - printk: For @suppress_panic_printk check for other CPU in panic
    (bsc#1225607).
  - commit f2045e0
  - printk: ringbuffer: Clarify special lpos values (bsc#1225607).
  - commit d1338d8
  - printk: ringbuffer: Do not skip non-finalized records with
    prb_next_seq() (bsc#1225607).
  - commit 1ea687c
  - prctl: generalize PR_SET_MDWE support check to be per-arch
    (bsc#1225610).
  - commit b86afe4
  - printk: Use prb_first_seq() as base for 32bit seq macros
    (bsc#1225607).
  - commit ea93856
  - printk: Adjust mapping for 32bit seq macros (bsc#1225607).
  - commit e9e690d
  - blk-cgroup: fix list corruption from reorder of WRITE ->lqueued
    (bsc#1225605).
  - blk-cgroup: fix list corruption from resetting io stat
    (bsc#1225605).
  - commit c132bd3
  - printk: nbcon: Relocate 32bit seq macros (bsc#1225607).
  - commit 6293dd4
  - printk: Rename abandon_console_lock_in_panic() to
    other_cpu_in_panic() (bsc#1225607).
  - commit 74aec78
  - printk: Consolidate console deferred printing (bsc#1225607).
  - commit c45374f
  - printk: Do not take console lock for console_flush_on_panic()
    (bsc#1225607).
  - commit ca5038f
  - printk: Keep non-panic-CPUs out of console lock (bsc#1225607).
  - commit 2d7bf36
  - printk: Reduce console_unblank() usage in unsafe scenarios
    (bsc#1225607).
  - commit 54eafaa
  - livepatch: Fix missing newline character in
    klp_resolve_symbols() (bsc#1223539).
  - commit af0f908
  - cpumap: Zero-initialise xdp_rxq_info struct before running
    XDP program (bsc#1224718 CVE-2024-27431).
  - commit fb7728a
  - kABI: bpf: struct bpf_link and bpf_link_ops kABI workaround
    (bsc#1224531 CVE-2024-35860).
  - commit 7744489
  - Revert "PCI/MSI: Provide IMS (Interrupt Message Store) support"
    (git-fixes).
  - Revert "PCI/MSI: Provide pci_ims_alloc/free_irq()" (git-fixes).
  - Revert "PCI/MSI: Provide stubs for IMS functions" (git-fixes).
  - commit 0dc394b
  - ppdev: Add an error check in register_device (git-fixes).
  - commit cfdb6a2
  - bpf: support deferring bpf_link dealloc to after RCU grace
    period (bsc#1224531 CVE-2024-35860).
  - bpf: put uprobe link's path and task in release callback
    (bsc#1224531 CVE-2024-35860).
  - commit a95dd44
  - Bluetooth: ISO: Fix not validating setsockopt user input
    (bsc#1224581 CVE-2024-35964).
  - commit 9d49d44
  - Bluetooth: ISO: Add support for BT_PKT_STATUS (bsc#1224581
    CVE-2024-35964).
  - commit cadac48
  - Bluetooth: af_bluetooth: Make BT_PKT_STATUS generic (bsc#1224581
    CVE-2024-35964).
  - Refresh
    patches.suse/Bluetooth-SCO-Fix-not-validating-setsockopt-user-inp.patch.
  - commit 774d916
  - bpf, sockmap: Prevent lock inversion deadlock in map delete elem
    (bsc#1209657 CVE-2023-0160 bsc#1224511 CVE-2024-35895).
  - commit fa3fb92
  - tpm_tis_spi: Account for SPI header when allocating TPM SPI
    xfer buffer (git-fixes).
  - commit 6d124e2

++++ kernel-rt:

  - dm-integrity: fix a memory leak when rechecking the data
    (bsc#1223077, CVE-2024-26860).
  - commit 29984e7
  - btrfs: zoned: don't skip block groups with 100% zone unusable
    (bsc#1220120).
  - btrfs: don't refill whole delayed refs block reserve when
    starting transaction (bsc#1220120).
  - btrfs: add new unused block groups to the list of unused block
    groups (bsc#1220120).
  - btrfs: do not delete unused block group if it may be used soon
    (bsc#1220120).
  - btrfs: add and use helper to check if block group is used
    (bsc#1220120).
  - btrfs: always reserve space for delayed refs when starting
    transaction (bsc#1220120).
  - btrfs: stop doing excessive space reservation for csum deletion
    (bsc#1220120).
  - btrfs: remove pointless initialization at
    btrfs_delayed_refs_rsv_release() (bsc#1220120).
  - btrfs: reserve space for delayed refs on a per ref basis
    (bsc#1220120).
  - btrfs: allow to run delayed refs by bytes to be released
    instead of count (bsc#1220120).
  - btrfs: simplify check for extent item overrun at
    lookup_inline_extent_backref() (bsc#1220120).
  - btrfs: return -EUCLEAN if extent item is missing when searching
    inline backref (bsc#1220120).
  - btrfs: use a single variable for return value at
    lookup_inline_extent_backref() (bsc#1220120).
  - btrfs: use a single variable for return value at
    run_delayed_extent_op() (bsc#1220120).
  - btrfs: remove pointless 'ref_root' variable from
    run_delayed_data_ref() (bsc#1220120).
  - btrfs: initialize key where it's used when running delayed
    data ref (bsc#1220120).
  - btrfs: remove refs_to_drop argument from __btrfs_free_extent()
    (bsc#1220120).
  - btrfs: remove refs_to_add argument from __btrfs_inc_extent_ref()
    (bsc#1220120).
  - btrfs: remove the refcount warning/check at
    btrfs_put_delayed_ref() (bsc#1220120).
  - btrfs: remove unnecessary logic when running new delayed
    references (bsc#1220120).
  - btrfs: pass a space_info argument to
    btrfs_reserve_metadata_bytes() (bsc#1220120).
  - btrfs: log message if extent item not found when running
    delayed extent op (bsc#1220120).
  - btrfs: remove redundant BUG_ON() from __btrfs_inc_extent_ref()
    (bsc#1220120).
  - btrfs: move btrfs_free_excluded_extents() into block-group.c
    (bsc#1220120).
  - btrfs: open code trivial btrfs_add_excluded_extent()
    (bsc#1220120).
  - btrfs: make find_first_extent_bit() return a boolean
    (bsc#1220120).
  - btrfs: make btrfs_destroy_pinned_extent() return void
    (bsc#1220120).
  - btrfs: make btrfs_destroy_marked_extents() return void
    (bsc#1220120).
  - btrfs: rename add_new_free_space() to btrfs_add_new_free_space()
    (bsc#1220120).
  - btrfs: update documentation for add_new_free_space()
    (bsc#1220120).
  - commit 37b05cd
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch (bsc#1222771).
    In preparation of enabling CONFIG_FIPS_SIGNATURE_SELFTEST, amend the
    missing 'usage' argument in the pkcs7_validate_trust() invocation
    from  the PKCS#7 selftest.
  - commit cfa0827
  - printk: Let no_printk() use _printk() (bsc#1225618).
  - commit 2abd745
  - printk: Update @console_may_schedule in
    console_trylock_spinning() (bsc#1225616).
  - commit e5e7ac5
  - af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock
    (CVE-2024-26676 bsc#1222380).
  - af_unix: Don't peek OOB data without MSG_OOB (CVE-2024-26676 bsc#1222380).
  - af_unix: Clear stale u->oob_skb (CVE-2024-26676 bsc#1222380).
  - commit 7722c8d
  - af_unix: fix use-after-free in unix_stream_read_actor()
    (CVE-2023-52772 bsc#1224989).
  - commit 0f5ff3f
  - certs: Add ECDSA signature verification self-test (bsc#1222777).
  - Port "certs: Add ECDSA signature verification self-test".
  - Enable new CONFIG_FIPS_SIGNATURE_SELFTEST_ECDSA.
  - Refresh
    0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch:
    trivial context update to Kconfig
  - commit 7338b2e
  - dump_stack: Do not get cpu_sync for panic CPU (bsc#1225607).
  - commit 3d953e1
  - printk: Avoid non-panic CPUs writing to ringbuffer
    (bsc#1225607).
  - commit 9a41cad
  - certs: Move RSA self-test data to separate file (bsc#1222777).
  - Port "certs: Move RSA self-test data to separate file".
  - Enable new CONFIG_FIPS_SIGNATURE_SELFTEST_RSA.
  - Refresh
    patches.suse/0002-PKCS-7-Check-codeSigning-EKU-for-kernel-module-and-k.patch:
  - trivial context update to Kconfig,
  - account for changed pkcs7_validate_trust() callsite amended by
    this refreshed patch.
  - commit 248ad2a
  - printk: Disable passing console lock owner completely during
    panic() (bsc#1225607).
  - commit a31a4d6
  - printk: ringbuffer: Skip non-finalized records in panic
    (bsc#1225607).
  - commit 8be42db
  - Enable CONFIG_FIPS_SIGNATURE_SELFTEST (bsc#1222771)
  - commit 4ade1c7
  - printk: Wait for all reserved records with pr_flush()
    (bsc#1225607).
  - commit 4a07b6c
  - printk: ringbuffer: Cleanup reader terminology (bsc#1225607).
  - commit b3f2a50
  - printk: Add this_cpu_in_panic() (bsc#1225607).
  - commit 8afb830
  - printk: For @suppress_panic_printk check for other CPU in panic
    (bsc#1225607).
  - commit f2045e0
  - printk: ringbuffer: Clarify special lpos values (bsc#1225607).
  - commit d1338d8
  - printk: ringbuffer: Do not skip non-finalized records with
    prb_next_seq() (bsc#1225607).
  - commit 1ea687c
  - prctl: generalize PR_SET_MDWE support check to be per-arch
    (bsc#1225610).
  - commit b86afe4
  - printk: Use prb_first_seq() as base for 32bit seq macros
    (bsc#1225607).
  - commit ea93856
  - printk: Adjust mapping for 32bit seq macros (bsc#1225607).
  - commit e9e690d
  - blk-cgroup: fix list corruption from reorder of WRITE ->lqueued
    (bsc#1225605).
  - blk-cgroup: fix list corruption from resetting io stat
    (bsc#1225605).
  - commit c132bd3
  - printk: nbcon: Relocate 32bit seq macros (bsc#1225607).
  - commit 6293dd4
  - printk: Rename abandon_console_lock_in_panic() to
    other_cpu_in_panic() (bsc#1225607).
  - commit 74aec78
  - printk: Consolidate console deferred printing (bsc#1225607).
  - commit c45374f
  - printk: Do not take console lock for console_flush_on_panic()
    (bsc#1225607).
  - commit ca5038f
  - printk: Keep non-panic-CPUs out of console lock (bsc#1225607).
  - commit 2d7bf36
  - printk: Reduce console_unblank() usage in unsafe scenarios
    (bsc#1225607).
  - commit 54eafaa
  - livepatch: Fix missing newline character in
    klp_resolve_symbols() (bsc#1223539).
  - commit af0f908
  - cpumap: Zero-initialise xdp_rxq_info struct before running
    XDP program (bsc#1224718 CVE-2024-27431).
  - commit fb7728a
  - kABI: bpf: struct bpf_link and bpf_link_ops kABI workaround
    (bsc#1224531 CVE-2024-35860).
  - commit 7744489
  - Revert "PCI/MSI: Provide IMS (Interrupt Message Store) support"
    (git-fixes).
  - Revert "PCI/MSI: Provide pci_ims_alloc/free_irq()" (git-fixes).
  - Revert "PCI/MSI: Provide stubs for IMS functions" (git-fixes).
  - commit 0dc394b
  - ppdev: Add an error check in register_device (git-fixes).
  - commit cfdb6a2
  - bpf: support deferring bpf_link dealloc to after RCU grace
    period (bsc#1224531 CVE-2024-35860).
  - bpf: put uprobe link's path and task in release callback
    (bsc#1224531 CVE-2024-35860).
  - commit a95dd44
  - Bluetooth: ISO: Fix not validating setsockopt user input
    (bsc#1224581 CVE-2024-35964).
  - commit 9d49d44
  - Bluetooth: ISO: Add support for BT_PKT_STATUS (bsc#1224581
    CVE-2024-35964).
  - commit cadac48
  - Bluetooth: af_bluetooth: Make BT_PKT_STATUS generic (bsc#1224581
    CVE-2024-35964).
  - Refresh
    patches.suse/Bluetooth-SCO-Fix-not-validating-setsockopt-user-inp.patch.
  - commit 774d916
  - bpf, sockmap: Prevent lock inversion deadlock in map delete elem
    (bsc#1209657 CVE-2023-0160 bsc#1224511 CVE-2024-35895).
  - commit fa3fb92
  - tpm_tis_spi: Account for SPI header when allocating TPM SPI
    xfer buffer (git-fixes).
  - commit 6d124e2

++++ openssl-3:

  - Fix HDKF key derivation (bsc#1225291, gh#openssl/openssl#23448,
    gh#openssl/openssl#23456)
    * Add openssl-Fix-EVP_PKEY_CTX_add1_hkdf_info-behavior.patch
    * Add openssl-Handle-empty-param-in-EVP_PKEY_CTX_add1_hkdf_info.patch

++++ vim:

  - Update to 9.1.0448:
    * compiler warning in eval.c
    * remove remaining css code
    * Add ft_hare.txt to Reference Manual TOC
    * re-generate vim syntax from generator
    * fix syntax vim bug
    * completion may be wrong when deleting all chars
    * getregionpos() inconsistent for partly-selected multibyte char
    * fix highlighting nested and escaped quotes in string props
    * remove the indent plugin since it has too many issues
    * update Debian runtime files
    * Coverity warning after 9.1.0440
    * Not enough tests for getregion() with multibyte chars
    * Can't use blockwise selection with width for getregion()
    * update outdated syntax files
    * fix floating_modifier highlight
    * hare runtime files outdated
    * getregionpos() can't properly indicate positions beyond eol
    * function get_lval() is too long
    * Cannot filter the history
    * Wrong Ex command executed when :g uses '?' as delimiter
    * support floating_modifier none; revert broken highlighting
    * Motif requires non-const char pointer for XPM  data
    * Crash when using '?' as separator for :s
    * filetype: cygport files are not recognized
    * make errors trying to access autoload/zig
    * Wrong yanking with exclusive selection and ve=all
    * add missing help tags file
    * Ancient XPM preprocessor hack may cause build errors
    * include basic rescript ftplugin file
    * eval.c is too long
    * getregionpos() doesn't handle one char selection
    * check for gdb file/dir before using as buffer name
    * refactor zig ftplugin, remove auto format
    * Coverity complains about eval.c refactor
    * Tag guessing leaves wrong search history with very short names
    * some issues with termdebug mapping test
    * update matchit plugin to v1.20
    * too many strlen() calls in search.c
    * set commentstring option
    * update vb indent plugin as vim9script
    * filetype: purescript files are not recognized
    * filetype: slint files are not recognized
    * basic nim ftplugin file for comments
    * Add Arduino ftplugin and indent files
    * include basic typst ftplugin file
    * include basic prisma ftplugin file
    * include basic v ftplugin for comment support
    * getregionpos() wrong with blockwise mode and multibyte
    * function echo_string_core() is too long
    * hyprlang files are not recognized
    * add basic dart ftplugin file
    * basic ftplugin file for graphql
    * mention comment plugin at :h 'commentstring'
    * set commentstring for sql files in ftplugin
    * :browse oldfiles prompts even with single entry
    * eval.c not sufficiently tested
    * clarify why E195 is returned
    * clarify temporary file clean up
    * fix :NoMatchParen not working
    * Cannot move to previous/next rare word
    * add basic ftplugin file for sshdconfig
    * if_py: find_module has been removed in Python 3.12.0a7
    * some screen dump tests can be improved
    * Some functions are not tested
    * clarify instal instructions for comment package
    * Unable to leave long line with 'smoothscroll' and 'scrolloff'
    * fix typo in vim9script help file
    * Remove trailing spaces
    * clarify {special} argument for shellescape()

------------------------------------------------------------------
------------------  2024-5-28  -  May 28 2024  -------------------
------------------------------------------------------------------

++++ glibc:

  - Obsolete glibc-locale-base-<targettype> from glibc-<targettype>

++++ kernel-default:

  - smb: client: fix potential UAF in cifs_debug_files_proc_show()
    (bsc#1225172, bsc#1223532, CVE-2024-26928).
  - commit 1089c4a
  - smb3: missing lock when picking channel (bsc#1225172,
    bsc#1224550, CVE-2024-35999).
  - commit d7be3a1
  - smb: client: fix potential UAF in
    cifs_signal_cifsd_for_reconnect() (bsc#1225172, bsc#1224766,
    CVE-2024-35861).
  - commit 0d45a76
  - smb: client: fix potential UAF in smb2_is_network_name_deleted()
    (bsc#1225172, bsc#1224764, CVE-2024-35862).
  - commit 6632102
  - smb: client: fix potential UAF in is_valid_oplock_break()
    (bsc#1225172, bsc#1224763, CVE-2024-35863).
  - commit 06c348c
  - smb: client: fix potential UAF in smb2_is_valid_oplock_break()
    (bsc#1225172, bsc#1224668, CVE-2024-35865).
  - commit 60bea5b
  - smb: client: fix potential UAF in smb2_is_valid_lease_break()
    (bsc#1225172, bsc#1224765, CVE-2024-35864).
  - commit 52cc8d8
  - smb: client: fix potential UAF in cifs_stats_proc_show()
    (bsc#1225172, bsc#1224664, CVE-2024-35867).
  - commit 3a82d6a
  - smb: client: fix potential UAF in cifs_stats_proc_write()
    (bsc#1225172, bsc#1224678, CVE-2024-35868).
  - commit fb4bf4e
  - smb: client: fix potential UAF in cifs_dump_full_key()
    (bsc#1225172, bsc#1224667, CVE-2024-35866).
  - commit b0961fe
  - smb: client: guarantee refcounted children from parent session
    (bsc#1225172, bsc#1224679, CVE-2024-35869).
  - commit 97642d2
  - smb: client: fix UAF in smb2_reconnect_server() (bsc#1225172,
    bsc#1224672, CVE-2024-35870).
  - commit e205efa
  - smb: Fix regression in writes when non-standard maximum write
    size negotiated (bsc#1222464, CVE-2024-26692).
  - commit 761be1f
  - cifs: Fix writeback data corruption (bsc#1225172,
    bsc#1223810, CVE-2024-27036).
  - commit 75108cc
  - cifs: Don't use certain unnecessary folio_*() functions
    (bsc#1225172).
  - commit 3ddf86f
  - x86/bpf: Fix IP after emitting call depth accounting (bsc#1224493 CVE-2024-35903).
  - commit 1c0fa71
  - drm/amdgpu: Skip do PCI error slot reset during RAS recovery (CVE-2024-35931 bsc#1224652).
  - commit 1dec1c9
  - kabi/severities: ignore TAS2781 symbol drop, it's only locally used
  - commit f367fdb
  - ASoC: tas2781: Fix wrong loading calibrated data sequence
    (git-fixes).
  - commit 5851e36
  - mm: page_owner: fix wrong information in dump_page_owner
    (git-fixes).
  - ALSA: scarlett2: Add missing error check to
    scarlett2_config_save() (git-fixes).
  - commit 4b2ccd1
  - x86/mm/pat: fix VM_PAT handling in COW mappings (bsc#1224525
    CVE-2024-35877).
  - commit 24cc941
  - io_uring: fail NOP if non-zero op flags is passed in
    (git-fixes).
  - io_uring/net: fix sendzc lazy wake polling (git-fixes).
  - io-wq: write next_work before dropping acct_lock (git-fixes).
  - io_uring: use the right type for work_llist empty check
    (git-fixes).
  - io_uring/net: restore msg_control on sendzc retry (git-fixes).
  - commit 92fcddd
  - io_uring/kbuf: hold io_buffer_list reference over mmap
    (git-fixes bsc#1224523 CVE-2024-35880).
  - io_uring/kbuf: protect io_buffer_list teardown with a reference
    (git-fixes).
    Reuses a padding space in the structure.
  - io_uring/kbuf: get rid of bl->is_ready (git-fixes).
  - io_uring/kbuf: get rid of lower BGID lists (git-fixes).
    Including kabi preservation patch.
  - io_uring/kbuf: rename is_mapped (git-fixes).
  - commit 3037746
  - io_uring: use private workqueue for exit work (git-fixes).
  - io_uring/rw: don't allow multishot reads without NOWAIT support
    (git-fixes).
  - io_uring: clear opcode specific data for an early failure
    (git-fixes).
  - io_uring: fix poll_remove stalled req completion (git-fixes).
  - io_uring: Fix release of pinned pages when __io_uaddr_map fails
    (git-fixes bsc#1224698 CVE-2024-35831).
  - io_uring: clean rings on NO_MMAP alloc fail (git-fixes).
  - io_uring/rw: return IOU_ISSUE_SKIP_COMPLETE for multishot retry
    (git-fixes).
  - io_uring: don't save/restore iowait state (git-fixes).
  - commit 289cc2c
  - io_uring: fix mshot io-wq checks (git-fixes).
  - io_uring/net: correctly handle multishot recvmsg retry setup
    (git-fixes).
  - io_uring: fix io_queue_proc modifying req->flags (git-fixes).
  - commit 78dda9b

++++ kernel-rt:

  - smb: client: fix potential UAF in cifs_debug_files_proc_show()
    (bsc#1225172, bsc#1223532, CVE-2024-26928).
  - commit 1089c4a
  - smb3: missing lock when picking channel (bsc#1225172,
    bsc#1224550, CVE-2024-35999).
  - commit d7be3a1
  - smb: client: fix potential UAF in
    cifs_signal_cifsd_for_reconnect() (bsc#1225172, bsc#1224766,
    CVE-2024-35861).
  - commit 0d45a76
  - smb: client: fix potential UAF in smb2_is_network_name_deleted()
    (bsc#1225172, bsc#1224764, CVE-2024-35862).
  - commit 6632102
  - smb: client: fix potential UAF in is_valid_oplock_break()
    (bsc#1225172, bsc#1224763, CVE-2024-35863).
  - commit 06c348c
  - smb: client: fix potential UAF in smb2_is_valid_oplock_break()
    (bsc#1225172, bsc#1224668, CVE-2024-35865).
  - commit 60bea5b
  - smb: client: fix potential UAF in smb2_is_valid_lease_break()
    (bsc#1225172, bsc#1224765, CVE-2024-35864).
  - commit 52cc8d8
  - smb: client: fix potential UAF in cifs_stats_proc_show()
    (bsc#1225172, bsc#1224664, CVE-2024-35867).
  - commit 3a82d6a
  - smb: client: fix potential UAF in cifs_stats_proc_write()
    (bsc#1225172, bsc#1224678, CVE-2024-35868).
  - commit fb4bf4e
  - smb: client: fix potential UAF in cifs_dump_full_key()
    (bsc#1225172, bsc#1224667, CVE-2024-35866).
  - commit b0961fe
  - smb: client: guarantee refcounted children from parent session
    (bsc#1225172, bsc#1224679, CVE-2024-35869).
  - commit 97642d2
  - smb: client: fix UAF in smb2_reconnect_server() (bsc#1225172,
    bsc#1224672, CVE-2024-35870).
  - commit e205efa
  - smb: Fix regression in writes when non-standard maximum write
    size negotiated (bsc#1222464, CVE-2024-26692).
  - commit 761be1f
  - cifs: Fix writeback data corruption (bsc#1225172,
    bsc#1223810, CVE-2024-27036).
  - commit 75108cc
  - cifs: Don't use certain unnecessary folio_*() functions
    (bsc#1225172).
  - commit 3ddf86f
  - x86/bpf: Fix IP after emitting call depth accounting (bsc#1224493 CVE-2024-35903).
  - commit 1c0fa71
  - drm/amdgpu: Skip do PCI error slot reset during RAS recovery (CVE-2024-35931 bsc#1224652).
  - commit 1dec1c9
  - kabi/severities: ignore TAS2781 symbol drop, it's only locally used
  - commit f367fdb
  - ASoC: tas2781: Fix wrong loading calibrated data sequence
    (git-fixes).
  - commit 5851e36
  - mm: page_owner: fix wrong information in dump_page_owner
    (git-fixes).
  - ALSA: scarlett2: Add missing error check to
    scarlett2_config_save() (git-fixes).
  - commit 4b2ccd1
  - x86/mm/pat: fix VM_PAT handling in COW mappings (bsc#1224525
    CVE-2024-35877).
  - commit 24cc941
  - io_uring: fail NOP if non-zero op flags is passed in
    (git-fixes).
  - io_uring/net: fix sendzc lazy wake polling (git-fixes).
  - io-wq: write next_work before dropping acct_lock (git-fixes).
  - io_uring: use the right type for work_llist empty check
    (git-fixes).
  - io_uring/net: restore msg_control on sendzc retry (git-fixes).
  - commit 92fcddd
  - io_uring/kbuf: hold io_buffer_list reference over mmap
    (git-fixes bsc#1224523 CVE-2024-35880).
  - io_uring/kbuf: protect io_buffer_list teardown with a reference
    (git-fixes).
    Reuses a padding space in the structure.
  - io_uring/kbuf: get rid of bl->is_ready (git-fixes).
  - io_uring/kbuf: get rid of lower BGID lists (git-fixes).
    Including kabi preservation patch.
  - io_uring/kbuf: rename is_mapped (git-fixes).
  - commit 3037746
  - io_uring: use private workqueue for exit work (git-fixes).
  - io_uring/rw: don't allow multishot reads without NOWAIT support
    (git-fixes).
  - io_uring: clear opcode specific data for an early failure
    (git-fixes).
  - io_uring: fix poll_remove stalled req completion (git-fixes).
  - io_uring: Fix release of pinned pages when __io_uaddr_map fails
    (git-fixes bsc#1224698 CVE-2024-35831).
  - io_uring: clean rings on NO_MMAP alloc fail (git-fixes).
  - io_uring/rw: return IOU_ISSUE_SKIP_COMPLETE for multishot retry
    (git-fixes).
  - io_uring: don't save/restore iowait state (git-fixes).
  - commit 289cc2c
  - io_uring: fix mshot io-wq checks (git-fixes).
  - io_uring/net: correctly handle multishot recvmsg retry setup
    (git-fixes).
  - io_uring: fix io_queue_proc modifying req->flags (git-fixes).
  - commit 78dda9b

++++ policycoreutils:

  - Rework packaging to modern python packaging as we need
    policycoreutils-python-tools as build dependency for python311-setools
  - General:
  - python version for scripts is now set to python311, deprecating python3.6
    on 15.4 + 15.5
  - replaced python3 dependencies with corresponding dependencies
  - moved %{_localstatedir}/lib/selinux out of the python-policycoreutils
    rpm and into policycoreutils-python-utils as it does not belong
    into a module and causes conflicts when module is built for multiple
    python versions
  - Factory-specific changes:
  - python-policycoreutils module is now built for python310, python311,
    python312 instead of python3
  - added %python3_fix_shebang to set the shebang to the current python
  - 15.4 and 15.5 specific changes
  - python-policycoreutils module is now built for python311 instead
    of python3
  - added %python311_fix_shebang to set the shebang to python311, this
    is currently a dirty hack since the python3_fix_shebang_path macro
    does not exist in <=15.5 so far
  - 15.4 specific changes
  - policycoreutils-devel requires python3-distro still, as there
    is no python311-distro package

++++ python-semanage:

  - Build python-semanage for python311 in 15.4 and 15.5 instead of
    python3.6 to fix build dependencies

++++ setools:

  - Rework packaging to modern python packaging
  - python-setools module now builds for python310, python311, python312
    for tw and builds for python311 in 15.4 + 15.5
  - setools-console scripts will use python311 as default in factory, 15.4
    and 15.5
  - moved %dir %{_docdir}/%{name}/ and %{_docdir}/%{name}/* out of the
    python-setools module into setools-console as it does not belong in there
    and causes conflicts between python versions
  - moved %{python_sitearch}/setoolsgui from setools-gui into the
    python-setools module for multiversion build

++++ python-setuptools:

  - Update to 70.0.0:
    * Features
    + Emit a warning when [tools.setuptools] is present in pyproject.toml and
    will be ignored.
    + Improved AttributeError error message if pkg_resources.EntryPoint.require
    is called without extras or distribution Gracefully "do nothing" when
    trying to activate a pkg_resources.Distribution with a None location,
    rather than raising a TypeError.
    + Refresh unpinned vendored dependencies.
    + Updated vendored packaging to version 24.0.
    + Merged with pypa/distutils@55982565e.
    + Support PEP 625 by canonicalizing package name and version in filenames.
    + Explicitly use encoding="locale" for .pth files whenever possible, to
    reduce EncodingWarnings.
    + Updated and removed obsolete Python < 3.8 code and comments.
    + Updated pkg_resources to use stdlib importlib.machinery instead of
    importlib_machinery.
    + Modernized and refactored VCS handling in package_index.
    (bsc#1228105, CVE-2024-6345)
    * Bugfixes
    + In install command, use super to call the superclass methods. Avoids
    race conditions when monkeypatching from _distutils_system_mod occurs
    late.
    + Fix finder template for lenient editable installs of implicit nested
    namespaces constructed by using package_dir to reorganise directory
    structure.
    + Remove attempt to canonicalize the version. It's already canonical
    enough.
    + Clarify some pkg_resources methods return bytes, not str. Also return an
    empty bytes in EmptyProvider._get.
    + Return an empty list by default in
    pkg_resources.ResourceManager.cleanup_resources.
    + Made pkg_resoursces.NullProvider's has_metadata and metadata_isdir
    methods return actual booleans like all other Providers.
    + In tests, rely on pytest-home for reusable fixture.
    + Explicitely marked as Protocol and fixed missing self argument in
    interfaces pkg_resources.IMetadataProvider and
    pkg_resources.IResourceProvider.
    + Restored expectation that egg-link files would be named with dash
    separators for compatibility with pip prior to version 24.
  - Refresh patch sort-for-reproducibility.patch

++++ velociraptor-client:

  - Patches changes:
    * Change CVE-2024-28849-follow-redirects-drop-proxy-authorization.patch
    to update the follow-redirects package instead of patching directly.
    * Added CVE-2022-25883-npm-watch-semver-deps.patch (bsc#1212572)
  - Add a package-lock.json to the package

------------------------------------------------------------------
------------------  2024-5-27  -  May 27 2024  -------------------
------------------------------------------------------------------

++++ chrony:

  - Update clknetsim to snapshot 0a11a35.

++++ librsvg:

  - Update to version 2.58.1:
    + Fix failing test with Pango 1.52.1.

++++ git:

  - remove dependency on /usr/bin/python3 using
    %python3_fix_shebang_path macro, [bsc#1212476]

++++ kernel-default:

  - io_uring: fix mshot read defer taskrun cqe posting (git-fixes).
  - commit de73141
  - ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
    (CVE-2024-35969 bsc#1224580)
  - commit f419c6d
  - mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash
    work (CVE-2024-35852 bsc#1224502).
  - mlxsw: spectrum_acl_tcam: Fix incorrect list API usage
    (CVE-2024-36006 bsc#1224541).
  - mlxsw: spectrum_acl_tcam: Fix warning during rehash
    (CVE-2024-36007 bsc#1224543).
  - commit 88a980b
  - Revert "iommu/vt-d: Enable PCI/IMS" (git-fixes).
  - commit f424462
  - Revert "iommu/amd: Enable PCI/IMS" (git-fixes).
  - commit 278bf80
  - iommufd: Add missing IOMMUFD_DRIVER kconfig for the selftest
    (git-fixes).
  - commit 481f9bd
  - btrfs: avoid start and commit empty transaction when flushing
    qgroups (bsc#1220120).
  - btrfs: avoid start and commit empty transaction when starting
    qgroup rescan (bsc#1220120).
  - btrfs: avoid starting and committing empty transaction when
    flushing space (bsc#1220120).
  - btrfs: avoid starting new transaction when flushing delayed
    items and refs (bsc#1220120).
  - btrfs: merge find_free_dev_extent() and
    find_free_dev_extent_start() (bsc#1220120).
  - btrfs: make find_free_dev_extent() static (bsc#1220120).
  - btrfs: make btrfs_cleanup_fs_roots() static (bsc#1220120).
  - btrfs: fail priority metadata ticket with real fs error
    (bsc#1220120).
  - btrfs: return real error when orphan cleanup fails due to a
    transaction abort (bsc#1220120).
  - btrfs: store the error that turned the fs into error state
    (bsc#1220120).
  - btrfs: don't steal space from global rsv after a transaction
    abort (bsc#1220120).
  - btrfs: print available space across all block groups when
    dumping space info (bsc#1220120).
  - btrfs: print available space for a block group when dumping
    a space info (bsc#1220120).
  - btrfs: print block group super and delalloc bytes when dumping
    space info (bsc#1220120).
  - btrfs: print target number of bytes when dumping free space
    (bsc#1220120).
  - btrfs: update comment for btrfs_join_transaction_nostart()
    (bsc#1220120).
  - commit b4554d4
  - mm/secretmem: fix GUP-fast succeeding on secretmem folios
    (CVE-2024-35872 bsc#1224530).
  - commit 42a2f6f
  - cifs: fix charset issue in reconnection (bsc#1225172).
  - commit b4ea103
  - btrfs: make btrfs_destroy_delayed_refs() return void
    (bsc#1220120).
  - btrfs: remove unnecessary prototype declarations at disk-io.c
    (bsc#1220120).
  - btrfs: use a single switch statement when initializing delayed
    ref head (bsc#1220120).
  - btrfs: use bool type for delayed ref head fields that are used
    as booleans (bsc#1220120).
  - btrfs: assert correct lock is held at btrfs_select_ref_head()
    (bsc#1220120).
  - btrfs: get rid of label and goto at insert_delayed_ref()
    (bsc#1220120).
  - btrfs: make insert_delayed_ref() return a bool instead of an
    int (bsc#1220120).
  - btrfs: use a bool to track qgroup record insertion when adding
    ref head (bsc#1220120).
  - btrfs: remove pointless in_tree field from struct
    btrfs_delayed_ref_node (bsc#1220120).
  - btrfs: remove unused is_head field from struct
    btrfs_delayed_ref_node (bsc#1220120).
  - btrfs: reorder some members of struct btrfs_delayed_ref_head
    (bsc#1220120).
  - commit 2e19466
  - btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations (CVE-2024-35956 bsc#1224674)
  - commit 9bb0c20
  - Update patches.suse/btrfs-send-handle-path-ref-underflow-in-header-itera.patch (CVE-2024-35935 bsc#1224645)
  - commit 5aa2b5a
  - btrfs: make error messages more clear when getting a chunk map (git-fixes)
  - commit 47ecf55
  - btrfs: compare the correct fsid/metadata_uuid in btrfs_validate_super (git-fixes)
  - commit 907e740
  - tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
    (git-fixes).
  - commit 113163c
  - btrfs: use the correct superblock to compare fsid in btrfs_validate_super (git-fixes)
  - commit 4318f3e
  - ring-buffer: Fix a race between readers and resize checks
    (git-fixes).
  - commit 568ebcf
  - btrfs: add a helper to read the superblock metadata_uuid (git-fixes)
  - commit 543d7b8
  - ftrace: Fix possible use-after-free issue in ftrace_location()
    (git-fixes).
  - commit 4cf7fca
  - tracing: hide unused ftrace_event_id_fops (git-fixes).
  - commit 61c90c7
  - x86/retpoline: Do the necessary fixup to the Zen3/4 srso return thunk  for !SRSO (git-fixes).
  - commit 1340b2d
  - x86/efistub: Add missing boot_params for mixed mode compat entry (git-fixes).
  - commit 12dcb3a
  - x86/efistub: Call mixed mode boot services on the firmware's stack (git-fixes).
  - commit 9d83518
  - x86/pm: Work around false positive kmemleak report in msr_build_context() (git-fixes).
  - commit 2e5a312
  - x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y (git-fixes).
  - commit 453faa5
  - x86/mce: Make sure to grab mce_sysfs_mutex in set_bank() (git-fixes).
  - commit e894262
  - mm/slab: make __free(kfree) accept error pointers (git-fixes).
  - commit 8b5f449
  - x86/Kconfig: Remove CONFIG_AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT (git-fixes).
  - commit fa1d89a
  - Update
    patches.suse/virtio_net-Do-not-send-RSS-key-if-it-is-not-supporte.patch
    (bsc#1224565, CVE-2024-35981).
  - commit 50a448d
  - Update
    patches.suse/KVM-x86-Mark-target-gfn-of-emulated-atomic-instructi.patch
    (bsc#1224638, CVE-2024-35804).
  - commit aac65c3
  - Update
    patches.suse/KVM-SVM-Flush-pages-under-kvm-lock-to-fix-UAF-in-svm.patch
    (bsc#1224725, CVE-2024-35791).
  - commit 80eb8d1
  - cxl/port: Fix delete_endpoint() vs parent unregistration race
    (CVE-2023-52771 bsc#1225007).
  - commit b115e15

++++ kernel-rt:

  - io_uring: fix mshot read defer taskrun cqe posting (git-fixes).
  - commit de73141
  - ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
    (CVE-2024-35969 bsc#1224580)
  - commit f419c6d
  - mlxsw: spectrum_acl_tcam: Fix memory leak when canceling rehash
    work (CVE-2024-35852 bsc#1224502).
  - mlxsw: spectrum_acl_tcam: Fix incorrect list API usage
    (CVE-2024-36006 bsc#1224541).
  - mlxsw: spectrum_acl_tcam: Fix warning during rehash
    (CVE-2024-36007 bsc#1224543).
  - commit 88a980b
  - Revert "iommu/vt-d: Enable PCI/IMS" (git-fixes).
  - commit f424462
  - Revert "iommu/amd: Enable PCI/IMS" (git-fixes).
  - commit 278bf80
  - iommufd: Add missing IOMMUFD_DRIVER kconfig for the selftest
    (git-fixes).
  - commit 481f9bd
  - btrfs: avoid start and commit empty transaction when flushing
    qgroups (bsc#1220120).
  - btrfs: avoid start and commit empty transaction when starting
    qgroup rescan (bsc#1220120).
  - btrfs: avoid starting and committing empty transaction when
    flushing space (bsc#1220120).
  - btrfs: avoid starting new transaction when flushing delayed
    items and refs (bsc#1220120).
  - btrfs: merge find_free_dev_extent() and
    find_free_dev_extent_start() (bsc#1220120).
  - btrfs: make find_free_dev_extent() static (bsc#1220120).
  - btrfs: make btrfs_cleanup_fs_roots() static (bsc#1220120).
  - btrfs: fail priority metadata ticket with real fs error
    (bsc#1220120).
  - btrfs: return real error when orphan cleanup fails due to a
    transaction abort (bsc#1220120).
  - btrfs: store the error that turned the fs into error state
    (bsc#1220120).
  - btrfs: don't steal space from global rsv after a transaction
    abort (bsc#1220120).
  - btrfs: print available space across all block groups when
    dumping space info (bsc#1220120).
  - btrfs: print available space for a block group when dumping
    a space info (bsc#1220120).
  - btrfs: print block group super and delalloc bytes when dumping
    space info (bsc#1220120).
  - btrfs: print target number of bytes when dumping free space
    (bsc#1220120).
  - btrfs: update comment for btrfs_join_transaction_nostart()
    (bsc#1220120).
  - commit b4554d4
  - mm/secretmem: fix GUP-fast succeeding on secretmem folios
    (CVE-2024-35872 bsc#1224530).
  - commit 42a2f6f
  - cifs: fix charset issue in reconnection (bsc#1225172).
  - commit b4ea103
  - btrfs: make btrfs_destroy_delayed_refs() return void
    (bsc#1220120).
  - btrfs: remove unnecessary prototype declarations at disk-io.c
    (bsc#1220120).
  - btrfs: use a single switch statement when initializing delayed
    ref head (bsc#1220120).
  - btrfs: use bool type for delayed ref head fields that are used
    as booleans (bsc#1220120).
  - btrfs: assert correct lock is held at btrfs_select_ref_head()
    (bsc#1220120).
  - btrfs: get rid of label and goto at insert_delayed_ref()
    (bsc#1220120).
  - btrfs: make insert_delayed_ref() return a bool instead of an
    int (bsc#1220120).
  - btrfs: use a bool to track qgroup record insertion when adding
    ref head (bsc#1220120).
  - btrfs: remove pointless in_tree field from struct
    btrfs_delayed_ref_node (bsc#1220120).
  - btrfs: remove unused is_head field from struct
    btrfs_delayed_ref_node (bsc#1220120).
  - btrfs: reorder some members of struct btrfs_delayed_ref_head
    (bsc#1220120).
  - commit 2e19466
  - btrfs: qgroup: fix qgroup prealloc rsv leak in subvolume operations (CVE-2024-35956 bsc#1224674)
  - commit 9bb0c20
  - Update patches.suse/btrfs-send-handle-path-ref-underflow-in-header-itera.patch (CVE-2024-35935 bsc#1224645)
  - commit 5aa2b5a
  - btrfs: make error messages more clear when getting a chunk map (git-fixes)
  - commit 47ecf55
  - btrfs: compare the correct fsid/metadata_uuid in btrfs_validate_super (git-fixes)
  - commit 907e740
  - tracing: Add MODULE_DESCRIPTION() to preemptirq_delay_test
    (git-fixes).
  - commit 113163c
  - btrfs: use the correct superblock to compare fsid in btrfs_validate_super (git-fixes)
  - commit 4318f3e
  - ring-buffer: Fix a race between readers and resize checks
    (git-fixes).
  - commit 568ebcf
  - btrfs: add a helper to read the superblock metadata_uuid (git-fixes)
  - commit 543d7b8
  - ftrace: Fix possible use-after-free issue in ftrace_location()
    (git-fixes).
  - commit 4cf7fca
  - tracing: hide unused ftrace_event_id_fops (git-fixes).
  - commit 61c90c7
  - x86/retpoline: Do the necessary fixup to the Zen3/4 srso return thunk  for !SRSO (git-fixes).
  - commit 1340b2d
  - x86/efistub: Add missing boot_params for mixed mode compat entry (git-fixes).
  - commit 12dcb3a
  - x86/efistub: Call mixed mode boot services on the firmware's stack (git-fixes).
  - commit 9d83518
  - x86/pm: Work around false positive kmemleak report in msr_build_context() (git-fixes).
  - commit 2e5a312
  - x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y (git-fixes).
  - commit 453faa5
  - x86/mce: Make sure to grab mce_sysfs_mutex in set_bank() (git-fixes).
  - commit e894262
  - mm/slab: make __free(kfree) accept error pointers (git-fixes).
  - commit 8b5f449
  - x86/Kconfig: Remove CONFIG_AMD_MEM_ENCRYPT_ACTIVE_BY_DEFAULT (git-fixes).
  - commit fa1d89a
  - Update
    patches.suse/virtio_net-Do-not-send-RSS-key-if-it-is-not-supporte.patch
    (bsc#1224565, CVE-2024-35981).
  - commit 50a448d
  - Update
    patches.suse/KVM-x86-Mark-target-gfn-of-emulated-atomic-instructi.patch
    (bsc#1224638, CVE-2024-35804).
  - commit aac65c3
  - Update
    patches.suse/KVM-SVM-Flush-pages-under-kvm-lock-to-fix-UAF-in-svm.patch
    (bsc#1224725, CVE-2024-35791).
  - commit 80eb8d1
  - cxl/port: Fix delete_endpoint() vs parent unregistration race
    (CVE-2023-52771 bsc#1225007).
  - commit b115e15

++++ less:

  - Update to 656:
    * Add ^O^N, ^O^P, ^O^L and ^O^O commands and mouse clicks (with --mouse) to find and open OSC8 hyperlinks (github #251).
    * Add --match-shift option.
    * Add --lesskey-content option (github #447).
    * Add LESSKEY_CONTENT environment variable (github #447).
    * Add --no-search-header-lines and --no-search-header-columns options (github #397).
    * Add ctrl-L search modifier (github #367).
    * A ctrl-P at the start of a shell command suppresses the "done" message (github #462).
    * Add attribute characters ('*', '~', '_', '&') to --color parameter (github #471).
    * Allow expansion of environment variables in lesskey files.
    * Add LESSSECURE_ALLOW environment variable (github #449).
    * Add LESS_UNSUPPORT environment variable.
    * Add line number parameter to --header option (github #436).
    * Mouse right-click jumps to position marked by left-click (github #390).
    * Ensure that the target line is not obscured by a header line set by --header (github #444).
    * Change default character set to "utf-8", except remains "dos" on MS-DOS.
    * Add message when search with ^W wraps (github #459).
    * UCRT builds on Windows 10 and later now support Unicode file names (github #438).
    * Improve behavior of interrupt while reading non-terminated pipe (github #414).
    * Improve parsing of -j, -x and -# options (github #393).
    * Support files larger than 4GB on Windows (github #417).
    * Support entry of Unicode chars larger than U+FFFF on Windows (github #391).
    * Improve colors of bold, underline and standout text on Windows.
    * Allow --rscroll to accept non-ASCII characters (github #483).
    * Allow the parameter to certain options to be terminated with a space (--color, --quotes, --rscroll, --search-options and --intr) (github #495).
    * Fix bug where # substitution failed after viewing help (github #420).
    * Fix crash if files are deleted while less is viewing them (github #404).
    * Workaround unreliable ReadConsoleInputW behavior on Windows with non-ASCII input.
    * Fix -J display when searching for non-ASCII characters (github #422).
    * Don't filter header lines via the & command (github #423).
    * Fix bug when horizontally shifting long lines (github #425).
    * Add -x and -D options to lesstest, to make it easier to diagnose a failed lesstest run.
    * Fix bug searching long lines with --incsearch and -S (github #428).
    * Fix bug that made ESC-} fail if top line on screen was empty (github #429).
    * Fix bug with --mouse on Windows when used with pipes (github #440).
    * Fix bug in --+OPTION command line syntax.
    * Fix display bug when using -w with an empty line with a CR/LF line ending (github #474).
    * When substituting '#' or '%' with a filename, quote the filename if it contains a space (github #480).
    * Fix wrong sleep time when system has usleep but not nanosleep (github #489).
    * Fix bug when file name contains a newline (CVE-2024-32487, bsc#1222849).
    * Fix bug when file name contains nonprintable characters (github #503).
    * Fix DJGPP build (github #497).
    * Update Unicode tables.
  - Refresh less-429-shell.patch

++++ ncurses:

  - Add ncurses patch 20240525
    + build-fix for configure option --disable-ext-funcs
    + improve formatting/style of manpages (patches by Branden Robinson).
    + review/update iTerm2 for 3.5.0 -TD
  - Add ncurses patch 20240519
    + update Ada95/configure to match change for -DTRACE
    + revert change to include/ncurses_defs, which caused build failure if
    tracing was not enabled (report by Branden Robinson).
  - Add ncurses patch 20240518
    + improve formatting/style of manpages (patches by Branden Robinson).
    + move makefile's -DTRACE into include/ncurses_cfg.h, to simplify use
    of CFLAGS/CPPFLAGS.
    + improve check for clock_gettime(), from xterm.
    + modify configure script to work around broken gnatgcc script found in
    gcc-13 builds.
  - Port patch ncurses-6.4.dif

++++ pam-config:

  - Update to version 2.11+git.20240527:
    * Move ecryptfs/fscrypt earlier in session list [bsc#1225290]

++++ psmisc:

  - Update to 23.7
    * build-sys: Make disable-statx work
    * fuser: Fallback to stat() if no statx() Debian 1030747 #48
    * fuser: silently ignore EACCES when scanning proc directories
    * killall: small formatting fixes Debian #1037231
    * pstree: Do not assume root PID #49
    * pslog: include config.h #51 !36
    * misc: Update gettext to 0.21
  - Add patch from upstream 0001-killall,pstree-use-clock_gettime-not-uptime.patch
  - Port the patches
    * 0001-Use-mountinfo-to-be-able-to-use-the-mount-identity.patch
    * psmisc-22.21-pstree.patch
  - Port patch psmisc-v23.6.dif and rename it to psmisc-v23.7.dif

------------------------------------------------------------------
------------------  2024-5-26  -  May 26 2024  -------------------
------------------------------------------------------------------

++++ lvm2-device-mapper:

  - Update lvm2 from LVM2.2.03.22 to LVM2.2.03.24
    * ** WHATS_NEW from 2.03.22 to 2.03.24 ***
    Version 2.03.24 - 16th May 2024
    ===============================
    Lvconvert supports VDO options for thin-pool with vdo conversion.
    Improve placement to .data.rel.ro and .rodata sections.
    Fix support for -y and -W when creating thinpool with vdo.
    Bettter support for runtime valgrind detection.
    Allow command interruption when communicating with dmeventd.
    Fix resize of VDO volume used for thin pool data volume.
    Use -Wl,-z,now and -Wl,--as-needed for compilation by default.
    Require 3.7 as minimal version for sanlock.
    Share code for closing opened desriptors on program startup.
    Fix memleak in lvmcache.
    Add configure --with-default-event-activation=ON setting.
    Fix return value from reporter function when hitting internal error.
    Skip checking of pools for lvremove and vgremove commands.
    VDO modprobes dm-vdo for 6.9 kernel and kvdo for older kernel version.
    Fix lvs reporting for VDO volumes with new upstream kernel driver.
    Don't import DM_UDEV_DISABLE_OTHER_RULES_FLAG in LVM rules, DM rules cover it.
    Fix table line generation for cache snapshots using cachevol.
    Enhance lvconvert support for external origins stacking.
    When swapping LV names also swap properties like hostname, time and data.
    Fix removal of stacked external origins.
    Lock filesystem when converting volume to read-only external origin.
    Support external origin between different thin-pool.
    Improve validation of acceptable volumes for external origins.
    Reduce amount of preloaded devices for complex device trees.
    Avoid logging problems from monitoring snapshots with inactive origins.
    Check for cache policy module presence in kernel's builtin modules file.
    Add configure --with-modulesdir to select kernel modules directory.
    Support creation of thin-pool with VDO use for its data volume.
    Version 2.03.23 - 21st November 2023
    ====================================
    Set the first lv_attr flag for raid integrity images to i or I.
    Add -A option for pvs and pvscan to show PVs outside devices file.
    Improve searched_devnames temp file usage to prevent redundant scanning.
    Change default search_for_devnames from auto to all.
    Add lvmdevices --refresh to search for missing PVIDs on all devices.
    Add comparison between old and new entries in lvmdevices --check.
    Fix device_id matching order - match non-devname first.
    Fix "lvconvert -m 0" when there is other than first in-sync leg.
    Use system.devices as default for dmeventd when dmeventd.devices is undefined.
    Accept WWIDs containing QEMU HARDDISK for device_id.
    Improve handling of non-standard WWID prefixes used for device_id.
    Configure automatically enables cmdlib for dmeventd and notify-dbus for dbus.
    Fix hint calculation for pools with zero or error segment.
    Configure supports --disable-shared to build only static binaries.
    Configure supports --without-{blkid|systemd|udev} for easier static build.
    Refresh device ids if the system changes.
    Fix pvmove when specifying raid components as moved LVs.
    Enhance error detection for lvm_import_vdo.
    Support PV lists with thin lvconvert.
    Fix support for lvm_import_vdo with SCSI VDO volumes.
    Fix locking issue leading to hanging concurrent vgchange --refresh.
    Recognize lvm.conf report/headings=2 for full column names in report headings.
    Add --headings none|abbrev|full cmd line option to set report headings type.
    Fix conversion to thin pool using lvmlockd.
    Fix conversion from thick into thin volume using lvmlockd.
    Require writable LV for conversion to vdo pool.
    Fix return value from lvconvert integrity remove.
    Preserve UUID for pool metadata spare.
    Preserve UUID for swapped pool metadata.
    Rewrite validation of device name entries used as device_id.
    * ** WHATS_NEW_DM from 1.02.196 to 1.02.198 ***
    Version 1.02.198 - 16th May 2024
    ================================
    Fix static only compilation of libdevmapper.a and dmsetup tool.
    Use better code for closing opened descriptors when starting dmeventd.
    Correct dmeventd -R for systemd environment.
    Restart of dmeventd -R checks pid file to detect running dmeventd first.
    Query with dmeventd -i quickly ends when there is no running dmeventd.
    Enhance dm_get_status_raid to handle mismatching status or reported legs.
    Create /dev/disk/by-label symlinks for DM devs that have crypto as next layer.
    Persist udev db for DM devs on cleanup used in initrd to rootfs transition.
    Process synthetic udev events other than 'add/change' as 'change' events.
    Increase DM_UDEV_RULES_VSN to 3 to indicate changed udev rules.
    Rename DM_NOSCAN to .DM_NOSCAN so it's not stored in udev db.
    Rename DM_SUSPENDED to .DM_SUSPENDED so it's not stored in udev db.
    Do not import DM_UDEV_DISABLE_OTHER_RULES_FLAG from db in 10-dm-disk.rules.
    Test DISK_RO after importing properties from db in 10-dm.rules.
    Also import ID_FS_TYPE in 13-dm-disk.rules from db if needed.
    Version 1.02.197 - 21st November 2023
    =====================================
    Fix invalid JSON report if using DM_REPORT_OUTPUT_MULTIPLE_TIMES and selection.
    Propagate ioctl errno from dm_task_run when creating new table line.
    Add support for group aliases in dmstats.
    Add support for exit-on file for dmeventd to reduce shutdown delays.
    Add configure option --with-dmeventd-exit-on-path to specify default path.
    Add dmsetup --headings none|abbrev|full to set report headings type.
    Add DM_REPORT_OUTPUT_FIELD_IDS_IN_HEADINGS to provide alternative headings.
  - Drop patches that have been merged into upstream
  - 0001-lvconvert-swapmetadata-fix-lvmlockd-locking.patch
  - 0002-lvconvert-fix-ret-values-fro-integrity-remove.patch
  - 0003-lvconvert-fix-regresion-from-integrity-check.patch
  - 0004-gcc-cleanup-warnings.patch
  - 0005-lvmlockd-fix-thick-to-thin-lv-conversion.patch
  - 0006-lvmlockd-let-lockd_init_lv_args-set-lock_args.patch
  - 0007-lvmlockd-fix-lvconvert-to-thin-pool.patch
  - 0008-lvconvert-run-error-path-code-only-for-shared-VG.patch
  - 0009-vgchange-acquire-an-exclusive-VG-lock-for-refresh.patch
  - 0010-lvmlockd-client-mutex-ordering.patch
  - 0011-filesystem-move-stat-after-open-check.patch
  - 0012-tests-check-for-writecache.patch
  - 0013-lvresize-fix-32-bit-overflow-in-size-calculation.patch
  - 0014-gcc-fix-warnings-for-x32-architecture.patch
  - 0015-gcc-warning-missing-braces-around-initializer.patch
  - 0016-test-improve-aux-teardown.patch
  - 0017-tests-aux-try-with-extra-sleep.patch
  - 0018-tests-aux-using-singl-lvmconf-call.patch
  - 0019-tests-missing-to-check-for-writecache-support.patch
  - 0020-tests-pvmove-large-disk-area.patch
  - 0021-tests-enforce-full-fs-check.patch
  - 0022-tests-update-for-work-in-fake-dev-environment.patch
  - 0023-tests-skip-test-when-lvmdbusd-runs-on-the-system.patch
  - 0024-tests-better-slowdown.patch
  - Update patch
  - bug-1184687_Add-nolvm-for-kernel-cmdline.patch

++++ kernel-default:

  - i3c: master: svc: change ENXIO to EAGAIN when IBI occurs during
    start frame (git-fixes).
  - commit cc09a8e
  - kselftest: Add a ksft_perror() helper (stable-fixes).
  - Refresh
    patches.suse/selftests-timers-posix_timers-Reimplement-check_time.patch.
  - commit f14f41c
  - nilfs2: fix unexpected freezing of nilfs_segctor_sync()
    (git-fixes).
  - nilfs2: fix use-after-free of timer for log writer thread
    (git-fixes).
  - kasan, fortify: properly rename memintrinsics (git-fixes).
  - i3c: master: svc: fix invalidate IBI type and miss call client
    IBI handler (git-fixes).
  - serial: kgdboc: Fix NMI-safety problems from keyboard reset code
    (stable-fixes).
  - drm/amd/display: Fix division by zero in setup_dsc_config
    (stable-fixes).
  - docs: kernel_include.py: Cope with docutils 0.21 (stable-fixes).
  - mmc: core: Add HS400 tuning in HS400es initialization
    (stable-fixes).
  - commit 0b2962b
  - Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()
    (git-fixes).
  - commit 3e2fb47

++++ kernel-rt:

  - i3c: master: svc: change ENXIO to EAGAIN when IBI occurs during
    start frame (git-fixes).
  - commit cc09a8e
  - kselftest: Add a ksft_perror() helper (stable-fixes).
  - Refresh
    patches.suse/selftests-timers-posix_timers-Reimplement-check_time.patch.
  - commit f14f41c
  - nilfs2: fix unexpected freezing of nilfs_segctor_sync()
    (git-fixes).
  - nilfs2: fix use-after-free of timer for log writer thread
    (git-fixes).
  - kasan, fortify: properly rename memintrinsics (git-fixes).
  - i3c: master: svc: fix invalidate IBI type and miss call client
    IBI handler (git-fixes).
  - serial: kgdboc: Fix NMI-safety problems from keyboard reset code
    (stable-fixes).
  - drm/amd/display: Fix division by zero in setup_dsc_config
    (stable-fixes).
  - docs: kernel_include.py: Cope with docutils 0.21 (stable-fixes).
  - mmc: core: Add HS400 tuning in HS400es initialization
    (stable-fixes).
  - commit 0b2962b
  - Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()
    (git-fixes).
  - commit 3e2fb47

++++ lvm2:

  - Update lvm2 from LVM2.2.03.22 to LVM2.2.03.24
    * ** WHATS_NEW from 2.03.22 to 2.03.24 ***
    Version 2.03.24 - 16th May 2024
    ===============================
    Lvconvert supports VDO options for thin-pool with vdo conversion.
    Improve placement to .data.rel.ro and .rodata sections.
    Fix support for -y and -W when creating thinpool with vdo.
    Bettter support for runtime valgrind detection.
    Allow command interruption when communicating with dmeventd.
    Fix resize of VDO volume used for thin pool data volume.
    Use -Wl,-z,now and -Wl,--as-needed for compilation by default.
    Require 3.7 as minimal version for sanlock.
    Share code for closing opened desriptors on program startup.
    Fix memleak in lvmcache.
    Add configure --with-default-event-activation=ON setting.
    Fix return value from reporter function when hitting internal error.
    Skip checking of pools for lvremove and vgremove commands.
    VDO modprobes dm-vdo for 6.9 kernel and kvdo for older kernel version.
    Fix lvs reporting for VDO volumes with new upstream kernel driver.
    Don't import DM_UDEV_DISABLE_OTHER_RULES_FLAG in LVM rules, DM rules cover it.
    Fix table line generation for cache snapshots using cachevol.
    Enhance lvconvert support for external origins stacking.
    When swapping LV names also swap properties like hostname, time and data.
    Fix removal of stacked external origins.
    Lock filesystem when converting volume to read-only external origin.
    Support external origin between different thin-pool.
    Improve validation of acceptable volumes for external origins.
    Reduce amount of preloaded devices for complex device trees.
    Avoid logging problems from monitoring snapshots with inactive origins.
    Check for cache policy module presence in kernel's builtin modules file.
    Add configure --with-modulesdir to select kernel modules directory.
    Support creation of thin-pool with VDO use for its data volume.
    Version 2.03.23 - 21st November 2023
    ====================================
    Set the first lv_attr flag for raid integrity images to i or I.
    Add -A option for pvs and pvscan to show PVs outside devices file.
    Improve searched_devnames temp file usage to prevent redundant scanning.
    Change default search_for_devnames from auto to all.
    Add lvmdevices --refresh to search for missing PVIDs on all devices.
    Add comparison between old and new entries in lvmdevices --check.
    Fix device_id matching order - match non-devname first.
    Fix "lvconvert -m 0" when there is other than first in-sync leg.
    Use system.devices as default for dmeventd when dmeventd.devices is undefined.
    Accept WWIDs containing QEMU HARDDISK for device_id.
    Improve handling of non-standard WWID prefixes used for device_id.
    Configure automatically enables cmdlib for dmeventd and notify-dbus for dbus.
    Fix hint calculation for pools with zero or error segment.
    Configure supports --disable-shared to build only static binaries.
    Configure supports --without-{blkid|systemd|udev} for easier static build.
    Refresh device ids if the system changes.
    Fix pvmove when specifying raid components as moved LVs.
    Enhance error detection for lvm_import_vdo.
    Support PV lists with thin lvconvert.
    Fix support for lvm_import_vdo with SCSI VDO volumes.
    Fix locking issue leading to hanging concurrent vgchange --refresh.
    Recognize lvm.conf report/headings=2 for full column names in report headings.
    Add --headings none|abbrev|full cmd line option to set report headings type.
    Fix conversion to thin pool using lvmlockd.
    Fix conversion from thick into thin volume using lvmlockd.
    Require writable LV for conversion to vdo pool.
    Fix return value from lvconvert integrity remove.
    Preserve UUID for pool metadata spare.
    Preserve UUID for swapped pool metadata.
    Rewrite validation of device name entries used as device_id.
    * ** WHATS_NEW_DM from 1.02.196 to 1.02.198 ***
    Version 1.02.198 - 16th May 2024
    ================================
    Fix static only compilation of libdevmapper.a and dmsetup tool.
    Use better code for closing opened descriptors when starting dmeventd.
    Correct dmeventd -R for systemd environment.
    Restart of dmeventd -R checks pid file to detect running dmeventd first.
    Query with dmeventd -i quickly ends when there is no running dmeventd.
    Enhance dm_get_status_raid to handle mismatching status or reported legs.
    Create /dev/disk/by-label symlinks for DM devs that have crypto as next layer.
    Persist udev db for DM devs on cleanup used in initrd to rootfs transition.
    Process synthetic udev events other than 'add/change' as 'change' events.
    Increase DM_UDEV_RULES_VSN to 3 to indicate changed udev rules.
    Rename DM_NOSCAN to .DM_NOSCAN so it's not stored in udev db.
    Rename DM_SUSPENDED to .DM_SUSPENDED so it's not stored in udev db.
    Do not import DM_UDEV_DISABLE_OTHER_RULES_FLAG from db in 10-dm-disk.rules.
    Test DISK_RO after importing properties from db in 10-dm.rules.
    Also import ID_FS_TYPE in 13-dm-disk.rules from db if needed.
    Version 1.02.197 - 21st November 2023
    =====================================
    Fix invalid JSON report if using DM_REPORT_OUTPUT_MULTIPLE_TIMES and selection.
    Propagate ioctl errno from dm_task_run when creating new table line.
    Add support for group aliases in dmstats.
    Add support for exit-on file for dmeventd to reduce shutdown delays.
    Add configure option --with-dmeventd-exit-on-path to specify default path.
    Add dmsetup --headings none|abbrev|full to set report headings type.
    Add DM_REPORT_OUTPUT_FIELD_IDS_IN_HEADINGS to provide alternative headings.
  - Drop patches that have been merged into upstream
  - 0001-lvconvert-swapmetadata-fix-lvmlockd-locking.patch
  - 0002-lvconvert-fix-ret-values-fro-integrity-remove.patch
  - 0003-lvconvert-fix-regresion-from-integrity-check.patch
  - 0004-gcc-cleanup-warnings.patch
  - 0005-lvmlockd-fix-thick-to-thin-lv-conversion.patch
  - 0006-lvmlockd-let-lockd_init_lv_args-set-lock_args.patch
  - 0007-lvmlockd-fix-lvconvert-to-thin-pool.patch
  - 0008-lvconvert-run-error-path-code-only-for-shared-VG.patch
  - 0009-vgchange-acquire-an-exclusive-VG-lock-for-refresh.patch
  - 0010-lvmlockd-client-mutex-ordering.patch
  - 0011-filesystem-move-stat-after-open-check.patch
  - 0012-tests-check-for-writecache.patch
  - 0013-lvresize-fix-32-bit-overflow-in-size-calculation.patch
  - 0014-gcc-fix-warnings-for-x32-architecture.patch
  - 0015-gcc-warning-missing-braces-around-initializer.patch
  - 0016-test-improve-aux-teardown.patch
  - 0017-tests-aux-try-with-extra-sleep.patch
  - 0018-tests-aux-using-singl-lvmconf-call.patch
  - 0019-tests-missing-to-check-for-writecache-support.patch
  - 0020-tests-pvmove-large-disk-area.patch
  - 0021-tests-enforce-full-fs-check.patch
  - 0022-tests-update-for-work-in-fake-dev-environment.patch
  - 0023-tests-skip-test-when-lvmdbusd-runs-on-the-system.patch
  - 0024-tests-better-slowdown.patch
  - Update patch
  - bug-1184687_Add-nolvm-for-kernel-cmdline.patch

++++ libosinfo:

  - Add upstream change:
    * 0001-osinfo-Make-xmlError-struct-constant-in-propagate_li.patch

------------------------------------------------------------------
------------------  2024-5-25  -  May 25 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for ProBook
    440/460 G11 (stable-fixes).
  - ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with
    ALC897 (stable-fixes).
  - ALSA: usb-audio: Fix for sampling rates support for Mbox3
    (stable-fixes).
  - ALSA: timer: Set lower bound of start tick time (stable-fixes).
  - ALSA: usb-audio: Add sampling rates support for Mbox3
    (stable-fixes).
  - commit ae40914
  - drm/nouveau: use tile_mode and pte_kind for VM_BIND bo
    allocations (git-fixes).
  - Input: cyapa - add missing input core locking to suspend/resume
    functions (git-fixes).
  - Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation
    (git-fixes).
  - Input: ims-pcu - fix printf string overflow (git-fixes).
  - ASoC: tas2552: Add TX path for capturing AUDIO-OUT data
    (git-fixes).
  - ALSA: core: Fix NULL module pointer assignment at card init
    (git-fixes).
  - speakup: Fix sizeof() vs ARRAY_SIZE() bug (git-fixes).
  - serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using
    prescaler (git-fixes).
  - serial: 8250_bcm7271: use default_mux_rate if possible
    (git-fixes).
  - serial: 8520_mtk: Set RTS on shutdown for Rx in-band wakeup
    (git-fixes).
  - tty: n_gsm: fix missing receive state reset after mode switch
    (git-fixes).
  - tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
    (git-fixes).
  - commit be92dbc
  - io_uring/net: fix overflow check in io_recvmsg_mshot_prep()
    (git-fixes CVE-2024-35827 bsc#1224606).
  - commit e6510ec
  - io_uring/net: move receive multishot out of the generic msghdr
    path (git-fixes).
  - commit 98302d6
  - io_uring/net: unify how recvmsg and sendmsg copy in the msghdr
    (git-fixes).
  - commit 8bed9be
  - cifs: handle cases where multiple sessions share connection
    (bsc#1225172).
  - commit 6704757
  - smb3: show beginning time for per share stats (bsc#1225172).
  - commit 9dab491
  - cifs: cifs_chan_is_iface_active should be called with chan_lock
    held (bsc#1225172).
  - commit 7f878c6
  - cifs: do not pass cifs_sb when trying to add channels
    (bsc#1225172).
  - commit b48e89f
  - smb: client: remove extra @chan_count check in
    __cifs_put_smb_ses() (bsc#1225172).
  - commit 58e3272
  - cifs: reconnect work should have reference on server struct
    (bsc#1225172).
  - commit f1bff59
  - cifs: handle cases where a channel is closed (bsc#1225172).
  - commit c305501
  - smb: client: reduce stack usage in cifs_try_adding_channels()
    (bsc#1225172).
  - commit 16a3d64
  - smb: client: get rid of dfs code dep in namespace.c
    (bsc#1225172).
  - commit 658ebd6
  - smb: client: get rid of dfs naming in automount code
    (bsc#1225172).
  - commit b47e685
  - smb: client: rename cifs_dfs_ref.c to namespace.c (bsc#1225172).
  - commit 429bc2d
  - smb: client: ensure to try all targets when finding nested links
    (bsc#1225172).
  - commit b03bac4
  - smb: client: introduce DFS_CACHE_TGT_LIST() (bsc#1225172).
  - commit f066846
  - cifs: account for primary channel in the interface list
    (bsc#1225172).
  - commit 28558fb
  - cifs: distribute channels across interfaces based on speed
    (bsc#1225172).
  - commit 66db7c6
  - io_uring: remove unconditional looping in local task_work
    handling (git-fixes).
  - commit 1df83aa
  - io_uring: remove looping around handling traditional task_work
    (git-fixes).
  - commit 6bdc394

++++ kernel-rt:

  - ALSA: hda/realtek: fix mute/micmute LEDs don't work for ProBook
    440/460 G11 (stable-fixes).
  - ALSA: hda/realtek: Enable headset mic of JP-IK LEAP W502 with
    ALC897 (stable-fixes).
  - ALSA: usb-audio: Fix for sampling rates support for Mbox3
    (stable-fixes).
  - ALSA: timer: Set lower bound of start tick time (stable-fixes).
  - ALSA: usb-audio: Add sampling rates support for Mbox3
    (stable-fixes).
  - commit ae40914
  - drm/nouveau: use tile_mode and pte_kind for VM_BIND bo
    allocations (git-fixes).
  - Input: cyapa - add missing input core locking to suspend/resume
    functions (git-fixes).
  - Input: pm8xxx-vibrator - correct VIB_MAX_LEVELS calculation
    (git-fixes).
  - Input: ims-pcu - fix printf string overflow (git-fixes).
  - ASoC: tas2552: Add TX path for capturing AUDIO-OUT data
    (git-fixes).
  - ALSA: core: Fix NULL module pointer assignment at card init
    (git-fixes).
  - speakup: Fix sizeof() vs ARRAY_SIZE() bug (git-fixes).
  - serial: sc16is7xx: fix bug in sc16is7xx_set_baud() when using
    prescaler (git-fixes).
  - serial: 8250_bcm7271: use default_mux_rate if possible
    (git-fixes).
  - serial: 8520_mtk: Set RTS on shutdown for Rx in-band wakeup
    (git-fixes).
  - tty: n_gsm: fix missing receive state reset after mode switch
    (git-fixes).
  - tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
    (git-fixes).
  - commit be92dbc
  - io_uring/net: fix overflow check in io_recvmsg_mshot_prep()
    (git-fixes CVE-2024-35827 bsc#1224606).
  - commit e6510ec
  - io_uring/net: move receive multishot out of the generic msghdr
    path (git-fixes).
  - commit 98302d6
  - io_uring/net: unify how recvmsg and sendmsg copy in the msghdr
    (git-fixes).
  - commit 8bed9be
  - cifs: handle cases where multiple sessions share connection
    (bsc#1225172).
  - commit 6704757
  - smb3: show beginning time for per share stats (bsc#1225172).
  - commit 9dab491
  - cifs: cifs_chan_is_iface_active should be called with chan_lock
    held (bsc#1225172).
  - commit 7f878c6
  - cifs: do not pass cifs_sb when trying to add channels
    (bsc#1225172).
  - commit b48e89f
  - smb: client: remove extra @chan_count check in
    __cifs_put_smb_ses() (bsc#1225172).
  - commit 58e3272
  - cifs: reconnect work should have reference on server struct
    (bsc#1225172).
  - commit f1bff59
  - cifs: handle cases where a channel is closed (bsc#1225172).
  - commit c305501
  - smb: client: reduce stack usage in cifs_try_adding_channels()
    (bsc#1225172).
  - commit 16a3d64
  - smb: client: get rid of dfs code dep in namespace.c
    (bsc#1225172).
  - commit 658ebd6
  - smb: client: get rid of dfs naming in automount code
    (bsc#1225172).
  - commit b47e685
  - smb: client: rename cifs_dfs_ref.c to namespace.c (bsc#1225172).
  - commit 429bc2d
  - smb: client: ensure to try all targets when finding nested links
    (bsc#1225172).
  - commit b03bac4
  - smb: client: introduce DFS_CACHE_TGT_LIST() (bsc#1225172).
  - commit f066846
  - cifs: account for primary channel in the interface list
    (bsc#1225172).
  - commit 28558fb
  - cifs: distribute channels across interfaces based on speed
    (bsc#1225172).
  - commit 66db7c6
  - io_uring: remove unconditional looping in local task_work
    handling (git-fixes).
  - commit 1df83aa
  - io_uring: remove looping around handling traditional task_work
    (git-fixes).
  - commit 6bdc394

++++ libcap:

  - update to 2.70:
    * setcap changes to make it harder to set invalid file capabilities
    * Lots of documentation fixes
    * Fix c89 compilation syntax for the C code in the libraries
    * libpam has deprecated providing the _pam_overwrite() function,
    so use memset() instead

++++ dav1d:

  - Update to version 1.4.2
    * AVX2 optimizations for 8-tap and new variants for 6-tap
    * AVX-512 optimizations for 8-tap and new variants for 6-tap
    * Improve entropy decoding on ARM64
    * New ARM64 optimizations for convolutions based on DotProd
    extension
    * New ARM64 optimizations for convolutions based on i8mm
    extension
    * New ARM64 optimizations for subpel and prep filters for i8mm
    * Misc improvements on existing ARM64 optimizations, notably
    for put/prep
    * New PowerPC9 optimizations for loopfilter
    * Support for macOS kperf API for benchmarking

++++ pkgconf:

  - update to 2.2.0:
    * Significant solver rework to flatten both requires and
    requires.private dependencies in a single pass.  Improves
    performance slightly and ensures proper dependency order.
    * Improve --digraph output to reflect more of the solver's state
    in the rendered dependency graph.
    * Do not reference the graph root by name when presenting error
    messages about directly requested dependency nodes.

------------------------------------------------------------------
------------------  2024-5-24  -  May 24 2024  -------------------
------------------------------------------------------------------

++++ aaa_base:

  - Update to version 84.87+git20240523.10a5692:
    * Add tmpfiles.d/soft-reboot-cleanup.conf

++++ curl:

  - Fix make install for curl-config.1
    * docs/Makefile.am: make curl-config.1 install
    * Fixed upstream in: github.com/curl/curl/pull/13741
    * Add curl-make-install-curl-config.patch

++++ dhcp:

  - Drop initscripts-legacy support [jsc#PED264]
  - Drop rc<service> symlinks [jsc#PED-264], [jsc#PED-266]

++++ docker-compose:

  - Update to version 2.27.1:
    * build(deps): bump github.com/containerd/containerd from 1.7.16
    to 1.7.17
    * build(deps): bump github.com/docker/buildx from 0.14.0 to
    0.14.1
    * drop COMPOSE_EXPERIMENTAL_OTEL as docker/cli has opentelemetry
    in
    * add gui/composeview as part of available commands
    * fix opentelemetry
    * bump compose-go to version v2.1.1
    * Set endpoint-specific DriverOpts
    * Bump compose-go version to latest main
    * Backport OpenBSD patches
    * add new navigation menu to open Compose app configuration in
    Docker Desktop
    * build(deps): bump github.com/fsnotify/fsevents from 0.1.1 to
    0.2.0
    * build(deps): bump golang.org/x/sys from 0.19.0 to 0.20.0
    * fix --resolve-image-digests
    * allow a local .env file to override compose.yaml sibling .env
    * Bump docker engine and cli to version 26.1.3
    * Bump docker to v26.1.2
    * Add documentation for --menu up option and COMPOSE_MENU
    environemnt variable
    * chore(deps): bump docker to v26.1.1 (#11794)

++++ firewalld:

  - Keep English 'translations' (en_US, en_GB) in the main package:
    do not force the lang package on plain English systems.

++++ iptables:

  - Edit iptables-batch-lock.patch, cure use of implicit function,
    fix it to make gcc14 happy.

++++ jeos-firstboot:

  - Update to version 1.4.3:
    * Use UTC as default TZ if there was no locale selection dialog (boo#1224212)

++++ kernel-default:

  - dmaengine: dw-edma: eDMA: Add sync read before starting the
    DMA transfer in remote setup (CVE-2024-27408 bsc#1224430).
  - commit 26ca7a6
  - pmdomain: ti: Add a null pointer check to the
    omap_prm_domain_init (CVE-2024-35943 bsc#1224649).
  - commit 4abda58
  - media: mediatek: vcodec: Fix oops when HEVC init fails
    (CVE-2024-35921 bsc#1224477).
  - commit 7226612
  - drivers/perf: hisi: use cpuhp_state_remove_instance_nocalls()
    for hisi_hns3_pmu uninit process (CVE-2023-52860 bsc#1224936).
  - commit f0f6842
  - kABI workaround for struct idxd_evl (CVE-2024-35991
    bsc#1224553).
  - commit 4c82821
  - dmaengine: idxd: Convert spinlock to mutex to lock evl workqueue
    (CVE-2024-35991 bsc#1224553).
  - commit bba26d6
  - sched/topology: Optimize topology_span_sane() (bsc#1225053).
  - cpumask: Add for_each_cpu_from() (bsc#1225053).
  - commit a6ca3d0
  - mlxsw: spectrum_acl_tcam: Fix possible use-after-free during
    rehash (CVE-2024-35854 bsc#1224636).
  - commit 2a8bef6
  - net: mctp: take ownership of skb in mctp_local_output
    (CVE-2024-27418 bsc#1224720)
  - commit afb99d9
  - ipv6: fix potential "struct net" leak in inet6_rtm_getaddr()
    (CVE-2024-27417 bsc#1224721)
  - commit 4e68c84
  - regulator: bd71828: Don't overwrite runtime voltages
    (git-fixes).
  - nfc: nci: Fix handling of zero-length payload packets in
    nci_rx_work() (git-fixes).
  - nfc: nci: Fix uninit-value in nci_rx_work (git-fixes).
  - selftests: net: kill smcrouted in the cleanup logic in amt.sh
    (git-fixes).
  - tools/latency-collector: Fix -Wformat-security compile warns
    (git-fixes).
  - commit 3a26e1a
  - bpf: Protect against int overflow for stack access size
    (bsc#1224488 CVE-2024-35905).
  - bpf: Check bloom filter map value size (bsc#1224488
    CVE-2024-35905).
  - commit 5fa3c11
  - io_uring: drop any code related to SCM_RIGHTS (git-fixes
    CVE-2023-52656 bsc#1224187).
  - io_uring/unix: drop usage of io_uring socket (git-fixes).
  - Refresh
    patches.suse/fs-Rename-anon_inode_getfile_secure-and-anon_inode_getfd_secure.
    Commit together because this required explicit merging with the
    anonymous inode creation function change. Incldues kabi fix up.
  - commit b304b67
  - autofs: use wake_up() instead of wake_up_interruptible(()
    (bsc#1224166).
  - commit eb57c74

++++ kernel-rt:

  - dmaengine: dw-edma: eDMA: Add sync read before starting the
    DMA transfer in remote setup (CVE-2024-27408 bsc#1224430).
  - commit 26ca7a6
  - pmdomain: ti: Add a null pointer check to the
    omap_prm_domain_init (CVE-2024-35943 bsc#1224649).
  - commit 4abda58
  - media: mediatek: vcodec: Fix oops when HEVC init fails
    (CVE-2024-35921 bsc#1224477).
  - commit 7226612
  - drivers/perf: hisi: use cpuhp_state_remove_instance_nocalls()
    for hisi_hns3_pmu uninit process (CVE-2023-52860 bsc#1224936).
  - commit f0f6842
  - kABI workaround for struct idxd_evl (CVE-2024-35991
    bsc#1224553).
  - commit 4c82821
  - dmaengine: idxd: Convert spinlock to mutex to lock evl workqueue
    (CVE-2024-35991 bsc#1224553).
  - commit bba26d6
  - sched/topology: Optimize topology_span_sane() (bsc#1225053).
  - cpumask: Add for_each_cpu_from() (bsc#1225053).
  - commit a6ca3d0
  - mlxsw: spectrum_acl_tcam: Fix possible use-after-free during
    rehash (CVE-2024-35854 bsc#1224636).
  - commit 2a8bef6
  - net: mctp: take ownership of skb in mctp_local_output
    (CVE-2024-27418 bsc#1224720)
  - commit afb99d9
  - ipv6: fix potential "struct net" leak in inet6_rtm_getaddr()
    (CVE-2024-27417 bsc#1224721)
  - commit 4e68c84
  - regulator: bd71828: Don't overwrite runtime voltages
    (git-fixes).
  - nfc: nci: Fix handling of zero-length payload packets in
    nci_rx_work() (git-fixes).
  - nfc: nci: Fix uninit-value in nci_rx_work (git-fixes).
  - selftests: net: kill smcrouted in the cleanup logic in amt.sh
    (git-fixes).
  - tools/latency-collector: Fix -Wformat-security compile warns
    (git-fixes).
  - commit 3a26e1a
  - bpf: Protect against int overflow for stack access size
    (bsc#1224488 CVE-2024-35905).
  - bpf: Check bloom filter map value size (bsc#1224488
    CVE-2024-35905).
  - commit 5fa3c11
  - io_uring: drop any code related to SCM_RIGHTS (git-fixes
    CVE-2023-52656 bsc#1224187).
  - io_uring/unix: drop usage of io_uring socket (git-fixes).
  - Refresh
    patches.suse/fs-Rename-anon_inode_getfile_secure-and-anon_inode_getfd_secure.
    Commit together because this required explicit merging with the
    anonymous inode creation function change. Incldues kabi fix up.
  - commit b304b67
  - autofs: use wake_up() instead of wake_up_interruptible(()
    (bsc#1224166).
  - commit eb57c74

++++ libxslt:

  - Add upstream build fix:
    * 0001-tests-Fix-build-with-older-libxml2.patch

++++ mozilla-nss:

  - Adding nss-fips-bsc1223724.patch to fix startup crash of Firefox
    when using FIPS-mode (bsc#1223724).

++++ xmlsec1:

  - Added patch:
    * xmlsec1-gcc14.patch
    + add missing include and fix gcc14 build

++++ passt:

  - Update to version 20240523.765eb0b:
    * apparmor: Fix comments after PID file and AF_UNIX socket creation refactoring
    * conf, passt.h: Rename pid_file in struct ctx to pidfile
    * conf, passt, tap: Open socket and PID files before switching UID/GID
    * passt, util: Move opening of PID file to its own function
    * util: Rename write_pidfile() to pidfile_write()
    * tap: Split tap_sock_unix_init() into opening and listening parts
    * passt, tap: Don't use -1 as uninitialised value for fd_tap_listen
    * tap: Move all-ones initialisation of mac_guest to tap_sock_init()
    * conf: Don't lecture user about starting us as root
    * netlink, test: Ignore deprecated addresses
    * tcp: Remove interim 'tapside' field from connection
    * flow: Record the pifs for each side of each flow
    * flow: Make side 0 always be the initiating side
    * flow: Clarify and enforce flow state transitions
    * inany: Better helpers for using inany and specific family addrs together
    * flow: Properly type callbacks to protocol specific handlers
    * util, tcp: Add helper to display socket addresses
    * apparmor: Fix passt abstraction
    * apparmor: allow netns paths on /tmp
    * clang-tidy: Suppress macro to enum conversion warnings
    * conf: Fix clang-tidy warning about using an undefined enum value
    * passt.c: explicitly include libgen.h for basename
    * netlink: Don't duplicate routes referring to unrelated host interfaces

++++ permissions:

  - Update to version 1699_20240522:
    * man pages: minor corrections (bsc#1224822)

++++ rebootmgr:

  - Update to version 2.4+git20240524.30e5383:
    * Move tmpfiles.d/soft-reboot-cleanup.conf to aaa_base

------------------------------------------------------------------
------------------  2024-5-23  -  May 23 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Update to bugfix release 24.0.8
  - -> https://docs.mesa3d.org/relnotes/24.0.8.html
  - refreshed 0008-pipe-loader-plumb-a-flag-for-implicit-driver-load-th.patch

++++ Mesa-drivers:

  - Update to bugfix release 24.0.8
  - -> https://docs.mesa3d.org/relnotes/24.0.8.html
  - refreshed 0008-pipe-loader-plumb-a-flag-for-implicit-driver-load-th.patch

++++ ethtool:

  - update to upstream release 6.9
    * Feature: support for rx-flow-hash gtp (-N)
    * Feature: support for RSS input transformation (-X)
    * Fix: typo in coalescing output (-c)
    * Fix: document all debugging flags in man page

++++ glibc:

  - Add workaround for invalid use of libc_nonshared.a with non-SUSE libc
    (bsc#1221482)

++++ kernel-default:

  - Update patches.suse/scsi-qedf-Wait-for-stag-work-during-unload.patch (bsc#1214852)
  - Update patches.suse/scsi-qedf-Don-t-process-stag-work-during-unload.patch (bsc#1214852)
  - commit 4cb5fde
  - Remove NTFSv3 from configs (bsc#1224429)
    References: bsc#1224429 comment#3
    We only support fuse version of the NTFS-3g driver. Disable NTFSv3 from
    all configs.
    This was enabled in
    d016c04d731 ("Bump to 6.4 kernel (jsc#PED-4593)")
  - commit b4be251
  - s390/ipl: Fix incorrect initialization of len fields in nvme
    reipl block (git-fixes bsc#1225136).
  - commit 273e6f4
  - s390/ipl: Fix incorrect initialization of nvme dump block
    (git-fixes bsc#1225134).
  - commit 955c716
  - s390/cpacf: Split and rework cpacf query functions (git-fixes
    bsc#1225133).
  - commit ee9583e
  - s390/bpf: Fix bpf_plt pointer arithmetic (git-fixes bsc#1224481
    CVE-2024-35917).
  - commit 34e1a55
  - Move upstreamed mm patches into sorted section
  - commit e3937f1
  - Move upstreamed powerpc patches into sorted section
  - commit fdb5fa6
  - kABI workaround for cs35l56 (git-fixes).
  - commit 331f8f7
  - ASoC: SOF: Intel: mtl: call dsp dump when boot retry fails
    (stable-fixes).
  - Refresh
    patches.suse/ASoC-SOF-Intel-mtl-Implement-firmware-boot-state-che.patch.
  - commit 8e475f5
  - ASoC: SOF: Intel: mtl: Disable interrupts when firmware boot
    failed (git-fixes).
  - ASoC: cs35l56: Prevent overwriting firmware ASP config
    (git-fixes).
  - commit 1a7f82c
  - ALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put()
    (CVE-2023-52674 bsc#1224727).
  - ALSA: scarlett2: Add missing error checks to *_ctl_get()
    (CVE-2023-52680 bsc#1224608).
  - ALSA: scarlett2: Add missing error check to
    scarlett2_usb_set_config() (CVE-2023-52692 bsc#1224628).
  - commit fff59c9
  - vmci: prevent speculation leaks by sanitizing event in
    event_deliver() (git-fixes).
  - VMCI: Fix an error handling path in vmci_guest_probe_device()
    (git-fixes).
  - VMCI: Fix possible memcpy() run-time warning in
    vmci_datagram_invoke_guest_handler() (stable-fixes).
  - VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host()
    (stable-fixes CVE-2024-35944 bsc#1224648).
  - commit d9694ad
  - spmi: hisi-spmi-controller: Do not override device identifier
    (git-fixes).
  - extcon: max8997: select IRQ_DOMAIN instead of depending on it
    (git-fixes).
  - interconnect: qcom: qcm2290: Fix mas_snoc_bimc QoS port
    assignment (git-fixes).
  - iio: pressure: dps310: support negative temperature values
    (git-fixes).
  - iio: adc: stm32: Fixing err code to not indicate success
    (git-fixes).
  - iio: core: Leave private pointer NULL when no private data
    supplied (git-fixes).
  - counter: linux/counter.h: fix Excess kernel-doc description
    warning (git-fixes).
  - staging: vt6655: Remove unused declaration of
    RFbAL7230SelectChannelPostProcess() (git-fixes).
  - serial: sh-sci: protect invalidating RXDMA on shutdown
    (git-fixes).
  - serial: sc16is7xx: add proper sched.h include for
    sched_set_fifo() (git-fixes).
  - serial: max3100: Fix bitwise types (git-fixes).
  - serial: max3100: Update uart_driver_registered on driver removal
    (git-fixes).
  - serial: max3100: Lock port->lock when calling
    uart_handle_cts_change() (git-fixes).
  - usb: fotg210: Add missing kernel doc description (git-fixes).
  - usb: typec: tipd: fix event checking for tps6598x (git-fixes).
  - usb: typec: ucsi: displayport: Fix potential deadlock
    (git-fixes).
  - usb: dwc3: Wait unconditionally after issuing EndXfer command
    (git-fixes).
  - usb: gadget: u_audio: Clear uac pointer when freed (git-fixes).
  - usb: gadget: u_audio: Fix race condition use of controls after
    free during gadget unbind (git-fixes).
  - usb: typec: ucsi: simplify partner's PD caps registration
    (git-fixes).
  - usb: typec: ucsi: always register a link to USB PD device
    (git-fixes).
  - leds: pwm: Disable PWM when going to suspend (git-fixes).
  - commit 0d08462

++++ kernel-rt:

  - Update patches.suse/scsi-qedf-Wait-for-stag-work-during-unload.patch (bsc#1214852)
  - Update patches.suse/scsi-qedf-Don-t-process-stag-work-during-unload.patch (bsc#1214852)
  - commit 4cb5fde
  - Remove NTFSv3 from configs (bsc#1224429)
    References: bsc#1224429 comment#3
    We only support fuse version of the NTFS-3g driver. Disable NTFSv3 from
    all configs.
    This was enabled in
    d016c04d731 ("Bump to 6.4 kernel (jsc#PED-4593)")
  - commit b4be251
  - s390/ipl: Fix incorrect initialization of len fields in nvme
    reipl block (git-fixes bsc#1225136).
  - commit 273e6f4
  - s390/ipl: Fix incorrect initialization of nvme dump block
    (git-fixes bsc#1225134).
  - commit 955c716
  - s390/cpacf: Split and rework cpacf query functions (git-fixes
    bsc#1225133).
  - commit ee9583e
  - s390/bpf: Fix bpf_plt pointer arithmetic (git-fixes bsc#1224481
    CVE-2024-35917).
  - commit 34e1a55
  - Move upstreamed mm patches into sorted section
  - commit e3937f1
  - Move upstreamed powerpc patches into sorted section
  - commit fdb5fa6
  - kABI workaround for cs35l56 (git-fixes).
  - commit 331f8f7
  - ASoC: SOF: Intel: mtl: call dsp dump when boot retry fails
    (stable-fixes).
  - Refresh
    patches.suse/ASoC-SOF-Intel-mtl-Implement-firmware-boot-state-che.patch.
  - commit 8e475f5
  - ASoC: SOF: Intel: mtl: Disable interrupts when firmware boot
    failed (git-fixes).
  - ASoC: cs35l56: Prevent overwriting firmware ASP config
    (git-fixes).
  - commit 1a7f82c
  - ALSA: scarlett2: Add clamp() in scarlett2_mixer_ctl_put()
    (CVE-2023-52674 bsc#1224727).
  - ALSA: scarlett2: Add missing error checks to *_ctl_get()
    (CVE-2023-52680 bsc#1224608).
  - ALSA: scarlett2: Add missing error check to
    scarlett2_usb_set_config() (CVE-2023-52692 bsc#1224628).
  - commit fff59c9
  - vmci: prevent speculation leaks by sanitizing event in
    event_deliver() (git-fixes).
  - VMCI: Fix an error handling path in vmci_guest_probe_device()
    (git-fixes).
  - VMCI: Fix possible memcpy() run-time warning in
    vmci_datagram_invoke_guest_handler() (stable-fixes).
  - VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host()
    (stable-fixes CVE-2024-35944 bsc#1224648).
  - commit d9694ad
  - spmi: hisi-spmi-controller: Do not override device identifier
    (git-fixes).
  - extcon: max8997: select IRQ_DOMAIN instead of depending on it
    (git-fixes).
  - interconnect: qcom: qcm2290: Fix mas_snoc_bimc QoS port
    assignment (git-fixes).
  - iio: pressure: dps310: support negative temperature values
    (git-fixes).
  - iio: adc: stm32: Fixing err code to not indicate success
    (git-fixes).
  - iio: core: Leave private pointer NULL when no private data
    supplied (git-fixes).
  - counter: linux/counter.h: fix Excess kernel-doc description
    warning (git-fixes).
  - staging: vt6655: Remove unused declaration of
    RFbAL7230SelectChannelPostProcess() (git-fixes).
  - serial: sh-sci: protect invalidating RXDMA on shutdown
    (git-fixes).
  - serial: sc16is7xx: add proper sched.h include for
    sched_set_fifo() (git-fixes).
  - serial: max3100: Fix bitwise types (git-fixes).
  - serial: max3100: Update uart_driver_registered on driver removal
    (git-fixes).
  - serial: max3100: Lock port->lock when calling
    uart_handle_cts_change() (git-fixes).
  - usb: fotg210: Add missing kernel doc description (git-fixes).
  - usb: typec: tipd: fix event checking for tps6598x (git-fixes).
  - usb: typec: ucsi: displayport: Fix potential deadlock
    (git-fixes).
  - usb: dwc3: Wait unconditionally after issuing EndXfer command
    (git-fixes).
  - usb: gadget: u_audio: Clear uac pointer when freed (git-fixes).
  - usb: gadget: u_audio: Fix race condition use of controls after
    free during gadget unbind (git-fixes).
  - usb: typec: ucsi: simplify partner's PD caps registration
    (git-fixes).
  - usb: typec: ucsi: always register a link to USB PD device
    (git-fixes).
  - leds: pwm: Disable PWM when going to suspend (git-fixes).
  - commit 0d08462

++++ sqlite3:

  - Update to release 3.46.0:
    * https://sqlite.org/releaselog/3_46_0.html
    * Enhance PRAGMA optimize in multiple ways.
    * Enhancements to the date and time functions.
    * Add support for underscore ("_") characters between digits in
    numeric literals.
    * Add the json_pretty() SQL function.
    * Query planner improvements.
    * Allocate additional memory from the heap for the SQL parser
    stack if that stack overflows, rather than reporting a "parser
    stack overflow" error.
    * Allow ASCII control characters within JSON5 string literals.
    * Fix the -> and ->> JSON operators so that when the right-hand
    side operand is a string that looks like an integer it is still
    treated as a string, because that is what PostgreSQL does.
    * Obsoletes sqlite3-float-i586.patch.

++++ rsync:

  - Correcly enable SIMD in x64: the flag was renamed from
  - -enable-simd to -enable-roll-simd in 3.2.4
  - Remove leftovers from previous versions:
    * rsync-patches-3.2.7.tar.gz
    * rsync-patches-3.2.7.tar.gz.asc

++++ suseconnect-ng:

  - Update version to 1.10.0
    * Build zypper-migration and zypper-packages-search as standalone
    binaries rather then one single binary
    * Add --gpg-auto-import-keys flag before action in zypper command (bsc#1219004)
    * Include /etc/products.d in directories whose content are backed
    up and restored if a zypper-migration rollback happens. (bsc#1219004)
    * Add the ability to upload the system uptime logs, produced by the
    suse-uptime-tracker daemon, to SCC/RMT as part of keepalive report.
    (jsc#PED-7982) (jsc#PED-8018)
    * Add support for third party packages in SUSEConnect
    * Refactor existing system information collection implementation

++++ virt-manager:

  - Upstream bug fixes (bsc#1027942) (jsc#PED-6305)
    088-tests-Fix-host-copy-XML-with-libvirt-10.1.0.patch
    089-hostdev-Fix-error-when-mdev-type_id-is-missing.patch
    090-uitests-Fix-with-GtkFileChooserNative.patch

------------------------------------------------------------------
------------------  2024-5-22  -  May 22 2024  -------------------
------------------------------------------------------------------

++++ containerd:

  - Update to containerd v1.7.17. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.17>
  - Switch back to using tar_scm service. Aside from obs_scm using more bandwidth
    and storage than a locally-compressed tar.xz, it seems there's some weird
    issue with paths in obscpio that break our SLE-12-only patch.
  - Rebase patches:
    * 0001-BUILD-SLE12-revert-btrfs-depend-on-kernel-UAPI-inste.patch
  - Update to containerd v1.7.16. Upstream release notes:
    <https://github.com/containerd/containerd/releases/tag/v1.7.16>
    CVE-2023-45288 bsc#1221400

++++ curl:

  - Update to 8.8.0:
    * Changes:
  - curl_version_info: provide librtmp version
  - file: add support for directory listings
  - lib: add curl_multi_waitfds
  - NTLM_WB: drop support
  - TLS: add support for ECH (Encrypted Client Hello)
  - urlapi: add CURLU_GET_EMPTY for empty queries and fragments
    * Bugfixes:
  - build: prefer "USE_IPV6" macro internally (was: "ENABLE_IPV6")
  - cd2nroff/manage: use UTC when SOURCE_DATE_EPOCH is set
  - cf-socket: don't try getting local IP without socket
  - cf-socket: remove references to l_ip, l_port
  - configure: make --disable-docs imply --disable-manual
  - curl.h: change CURL_SSLVERSION_* from enum to defines
  - curl_path: make Curl_get_pathname use dynbuf
  - curl_sha512_256: do not use workaround for NetBSD when not needed
  - curl_sha512_256: fix detection of OpenSSL 1.1.1 or later
  - curl_url_get.md: clarify queries and fragments and CURLU_GET_EMPTY
  - DEPRECATE.md: TLS libraries without 1.3 support
  - digest: replace strcpy for empty string with simple assignment
  - doc: pytest "--repeat" -> "--count"
  - docs/cmdline-opts: mention STARTTLS for --ssl and --ssl-reqd
  - dynbuf: fix returncode on memory error
  - ftp: add tracing support
  - ftp: fix socket leak on rare error
  - gnutls: lazy init the trust settings
  - hsts: explicitly skip blank lines
  - http2 + ngtcp2: pass CURLcode errors from callbacks
  - http2, http3: decouple stream state from easy handle
  - http2: emit RST when client write fails
  - http: HEAD response body tolerance
  - http: reject HTTP major version switch mid connection
  - http: with chunked POST forced, disable length check on read callback
  - idn: make Curl_idnconvert_hostname() use Curl_idn_decode()
  - if2ip: make the buf_size arg a size_t
  - krb5: use dynbuf
  - lib/cf-h1-proxy: silence compiler warnings (gcc 14)
  - lib: add trace support for client reads and writes
  - lib: bump hash sizes to "size_t"
  - lib: clear the easy handle's saved errno before transfer
  - lib: make protocol handlers store scheme name lowercase
  - lib: merge "ENABLE_QUIC" C macro into "USE_HTTP3"
  - libssh2: set length to 0 if strdup failed
  - openssl: do not set SSL_MODE_RELEASE_BUFFERS
  - openssl: revert keylog_callback support for LibreSSL
  - OS400: fix shellcheck warnings in scripts
  - quiche: expire all active transfers on connection close
  - quiche: trust its timeout handling
  - tls: use shared init code for TCP+QUIC
  - tool_cfgable: free {proxy_}cipher13_list on exit
  - url: do not URL decode proxy crendentials
  - url: fix use of an uninitialized variable
  - url: make parse_login_details use memdup0
  - urlapi: allow setting port number zero
  - version: use msnprintf instead of strncpy
  - vtls: TLS session storage overhaul
  - wakeup_create: use FD_CLOEXEC/SOCK_CLOEXEC
  - websocket: avoid memory leak in error path
  - Add split-provides for libcurl-devel -> libcurl-devel-doc.

++++ gstreamer-plugins-base:

  - Add gstreamer-plugins-base-CVE-2024-4453.patch:
    Backporting e68eccff from upstream, Prevent integer overflows
    and out of bounds reads when handling undefined tags.
    (CVE-2024-4453 ZDI-24-467 ZDI-CAN-23896 bsc#1224806)

++++ kernel-default:

  - af_unix: Suppress false-positive lockdep splat for spin_lock()
    in __unix_gc() (CVE-2024-26923 bsc#1223384).
  - af_unix: fix lockdep positive in sk_diag_dump_icons()
    (CVE-2024-26923 bsc#1223384).
  - commit a652e3a
  - Update
    patches.suse/ACPI-CPPC-Use-access_width-over-bit_width-for-system.patch
    (stable-fixes CVE-2024-35995 bsc#1224557).
  - Update
    patches.suse/ALSA-usb-audio-Stop-parsing-channels-bits-when-all-c.patch
    (git-fixes CVE-2024-27436 bsc#1224803).
  - Update
    patches.suse/ASoC-SOF-ipc4-pcm-Workaround-for-crashed-firmware-on.patch
    (stable-fixes CVE-2024-27057 bsc#1223831).
  - Update
    patches.suse/ASoC-mediatek-sof-common-Add-NULL-check-for-normal_l.patch
    (git-fixes CVE-2024-35842 bsc#1224688).
  - Update
    patches.suse/Bluetooth-Fix-memory-leak-in-hci_req_sync_complete.patch
    (git-fixes CVE-2024-35978 bsc#1224571).
  - Update
    patches.suse/Bluetooth-Fix-use-after-free-bugs-caused-by-sco_sock.patch
    (git-fixes CVE-2024-27398 bsc#1224174).
  - Update
    patches.suse/Bluetooth-L2CAP-Fix-not-validating-setsockopt-user-i.patch
    (git-fixes CVE-2024-35965 bsc#1224579).
  - Update
    patches.suse/Bluetooth-RFCOMM-Fix-not-validating-setsockopt-user-.patch
    (git-fixes CVE-2024-35966 bsc#1224576).
  - Update
    patches.suse/Bluetooth-SCO-Fix-not-validating-setsockopt-user-inp.patch
    (git-fixes CVE-2024-35967 bsc#1224587).
  - Update
    patches.suse/Bluetooth-btintel-Fix-null-ptr-deref-in-btintel_read.patch
    (stable-fixes CVE-2024-35933 bsc#1224640).
  - Update
    patches.suse/Bluetooth-hci_event-Fix-handling-of-HCI_EV_IO_CAPA_R.patch
    (git-fixes CVE-2024-27416 bsc#1224723).
  - Update
    patches.suse/Bluetooth-hci_sock-Fix-not-validating-setsockopt-use.patch
    (git-fixes CVE-2024-35963 bsc#1224582).
  - Update
    patches.suse/Bluetooth-l2cap-fix-null-ptr-deref-in-l2cap_chan_tim.patch
    (git-fixes CVE-2024-27399 bsc#1224177).
  - Update
    patches.suse/Bluetooth-qca-fix-NULL-deref-on-non-serdev-setup.patch
    (git-fixes CVE-2024-35850 bsc#1224600).
  - Update
    patches.suse/Bluetooth-qca-fix-NULL-deref-on-non-serdev-suspend.patch
    (git-fixes CVE-2024-35851 bsc#1224509).
  - Update
    patches.suse/Bluetooth-rfcomm-Fix-null-ptr-deref-in-rfcomm_check_.patch
    (bsc#1219170 CVE-2024-22099 CVE-2024-26903 bsc#1223187).
  - Update
    patches.suse/HID-i2c-hid-remove-I2C_HID_READ_PENDING-flag-to-prev.patch
    (git-fixes CVE-2024-35997 bsc#1224552).
  - Update
    patches.suse/NFS-Fix-nfs_netfs_issue_read-xarray-locking-for-writ.patch
    (git-fixes CVE-2024-27031 bsc#1223805).
  - Update
    patches.suse/NFSv4.2-fix-nfs4_listxattr-kernel-BUG-at-mm-usercopy.patch
    (git-fixes CVE-2024-26870 bsc#1223113).
  - Update
    patches.suse/PCI-PM-Drain-runtime-idle-callbacks-before-driver-re.patch
    (stable-fixes CVE-2024-35809 bsc#1224738).
  - Update
    patches.suse/SUNRPC-fix-some-memleaks-in-gssx_dec_option_array.patch
    (git-fixes CVE-2024-27388 bsc#1223744).
  - Update
    patches.suse/USB-core-Fix-deadlock-in-usb_deauthorize_interface.patch
    (git-fixes CVE-2024-26934 bsc#1223671).
  - Update patches.suse/accel-ivpu-Fix-deadlock-in-context_xa.patch
    (git-fixes CVE-2024-35953 bsc#1224704).
  - Update
    patches.suse/arm64-hibernate-Fix-level3-translation-fault-in-swsu.patch
    (git-fixes CVE-2024-26989 bsc#1223748).
  - Update patches.suse/ax25-Fix-netdev-refcount-issue.patch
    (git-fixes CVE-2024-36009 bsc#1224542).
  - Update
    patches.suse/ax25-fix-use-after-free-bugs-caused-by-ax25_ds_del_t.patch
    (git-fixes CVE-2024-35887 bsc#1224663).
  - Update
    patches.suse/batman-adv-Avoid-infinite-loop-trying-to-resize-loca.patch
    (git-fixes CVE-2024-35982 bsc#1224566).
  - Update
    patches.suse/block-fix-q-blkg_list-corruption-during-disk-rebind.patch
    (bsc#1223591 CVE-2024-35974 bsc#1224573).
  - Update
    patches.suse/bnxt_en-Fix-possible-memory-leak-in-bnxt_rdma_aux_de.patch
    (git-fixes CVE-2024-35972 bsc#1224577).
  - Update
    patches.suse/bootconfig-use-memblock_free_late-to-free-xbc-memory.patch
    (git-fixes CVE-2024-26983 bsc#1223637).
  - Update
    patches.suse/btrfs-fix-deadlock-with-fiemap-and-extent-locking.patch
    (bsc#1223285 CVE-2024-35784 bsc#1224804).
  - Update
    patches.suse/btrfs-fix-information-leak-in-btrfs_ioctl_logical_to.patch
    (git-fixes CVE-2024-35849 bsc#1224733).
  - Update
    patches.suse/btrfs-fix-race-between-ordered-extent-completion-and.patch
    (bsc#1223285 CVE-2024-26794 bsc#1222426).
  - Update
    patches.suse/btrfs-fix-race-when-detecting-delalloc-ranges-during.patch
    (bsc#1223285 CVE-2024-27080 bsc#1223782).
  - Update
    patches.suse/btrfs-handle-chunk-tree-lookup-error-in-btrfs_reloca.patch
    (git-fixes CVE-2024-35936 bsc#1224644).
  - Update
    patches.suse/clk-Get-runtime-PM-before-walking-tree-during-disabl.patch
    (git-fixes CVE-2024-27004 bsc#1223762).
  - Update
    patches.suse/clk-Get-runtime-PM-before-walking-tree-for-clk_summa.patch
    (git-fixes CVE-2024-27003 bsc#1223761).
  - Update
    patches.suse/clk-mediatek-Do-a-runtime-PM-get-on-controllers-duri.patch
    (git-fixes CVE-2024-27002 bsc#1223759).
  - Update
    patches.suse/comedi-vmk80xx-fix-incomplete-endpoint-checking.patch
    (git-fixes CVE-2024-27001 bsc#1223698).
  - Update
    patches.suse/dm-raid-really-frozen-sync_thread-during-suspend-16c4.patch
    (jsc#PED-7542 CVE-2024-35794 bsc#1224706).
  - Update
    patches.suse/dm-raid456-md-raid456-fix-a-deadlock-for-dm-raid456-4142.patch
    (bsc#1219596 CVE-2024-26962 bsc#1223654).
  - Update
    patches.suse/dma-buf-Fix-NULL-pointer-dereference-in-sanitycheck.patch
    (git-fixes CVE-2024-35916 bsc#1224480).
  - Update patches.suse/dma-xilinx_dpdma-Fix-locking.patch
    (git-fixes CVE-2024-35990 bsc#1224559).
  - Update
    patches.suse/dmaengine-fsl-qdma-Fix-a-memory-leak-related-to-the--3aa58cb.patch
    (git-fixes CVE-2024-35833 bsc#1224632).
  - Update
    patches.suse/dmaengine-idxd-Fix-oops-during-rmmod-on-single-CPU-p.patch
    (git-fixes CVE-2024-35989 bsc#1224558).
  - Update
    patches.suse/dpll-fix-dpll_pin_on_pin_register-for-multiple-paren.patch
    (CVE-2024-27027 bsc#1223787 CVE-2024-36002 bsc#1224546).
  - Update
    patches.suse/dpll-fix-pin-dump-crash-for-rebound-module.patch
    (jsc#PED-6079 CVE-2024-35836 bsc#1224633).
  - Update
    patches.suse/drm-Check-output-polling-initialized-before-disablin.patch
    (stable-fixes CVE-2024-35927 bsc#1224654).
  - Update
    patches.suse/drm-amd-amdgpu-Fix-potential-ioremap-memory-leaks-in.patch
    (stable-fixes CVE-2024-35928 bsc#1224653).
  - Update
    patches.suse/drm-amd-display-Fix-bounds-check-for-dcn35-DcfClocks.patch
    (git-fixes CVE-2024-35788 bsc#1224709).
  - Update
    patches.suse/drm-amd-display-Prevent-crash-when-disable-stream.patch
    (stable-fixes CVE-2024-35799 bsc#1224740).
  - Update
    patches.suse/drm-amdgpu-amdgpu_ttm_gart_bind-set-gtt-bound-flag.patch
    (stable-fixes CVE-2024-35817 bsc#1224736).
  - Update
    patches.suse/drm-amdgpu-fix-deadlock-while-reading-mqd-from-debug.patch
    (git-fixes CVE-2024-35795 bsc#1224634).
  - Update
    patches.suse/drm-amdgpu-fix-mmhub-client-id-out-of-bounds-access.patch
    (git-fixes CVE-2024-27029 bsc#1223789).
  - Update
    patches.suse/drm-amdgpu-once-more-fix-the-call-oder-in-amdgpu_ttm.patch
    (git-fixes CVE-2024-27400 bsc#1224180).
  - Update
    patches.suse/drm-amdgpu-pm-Fix-NULL-pointer-dereference-when-get-.patch
    (git-fixes CVE-2024-26949 bsc#1223665).
  - Update
    patches.suse/drm-amdgpu-validate-the-parameters-of-bo-mapping-ope.patch
    (git-fixes CVE-2024-26922 bsc#1223315).
  - Update
    patches.suse/drm-amdkfd-Fix-memory-leak-in-create_process-failure.patch
    (git-fixes CVE-2024-26986 bsc#1223728).
  - Update patches.suse/drm-ast-Fix-soft-lockup.patch (git-fixes
    CVE-2024-35952 bsc#1224705).
  - Update
    patches.suse/drm-client-Fully-protect-modes-with-dev-mode_config..patch
    (stable-fixes CVE-2024-35950 bsc#1224703).
  - Update
    patches.suse/drm-i915-bios-Tolerate-devdata-NULL-in-intel_bios_en.patch
    (stable-fixes CVE-2024-26938 bsc#1223678).
  - Update
    patches.suse/drm-i915-gt-Reset-queue_priority_hint-on-parking.patch
    (git-fixes CVE-2024-26937 bsc#1223677).
  - Update
    patches.suse/drm-lima-fix-a-memleak-in-lima_heap_alloc.patch
    (git-fixes CVE-2024-35829 bsc#1224707).
  - Update
    patches.suse/drm-nouveau-fix-stale-locked-mutex-in-nouveau_gem_io.patch
    (git-fixes CVE-2024-35786 bsc#1224714).
  - Update
    patches.suse/drm-nouveau-keep-DMA-buffers-required-for-suspend-re.patch
    (git-fixes CVE-2024-27411 bsc#1224433).
  - Update patches.suse/drm-nv04-Fix-out-of-bounds-access.patch
    (git-fixes CVE-2024-27008 bsc#1223802).
  - Update
    patches.suse/drm-panfrost-Fix-the-error-path-in-panfrost_mmu_map_.patch
    (git-fixes CVE-2024-35951 bsc#1224701).
  - Update
    patches.suse/drm-vc4-don-t-check-if-plane-state-fb-state-fb.patch
    (stable-fixes CVE-2024-35932 bsc#1224650).
  - Update
    patches.suse/drm-vmwgfx-Create-debugfs-ttm_resource_manager-entry.patch
    (git-fixes CVE-2024-26940 bsc#1223718).
  - Update
    patches.suse/drm-vmwgfx-Fix-the-lifetime-of-the-bo-cursor-memory.patch
    (git-fixes CVE-2024-35810 bsc#1224626).
  - Update
    patches.suse/dyndbg-fix-old-BUG_ON-in-control-parser.patch
    (stable-fixes CVE-2024-35947 bsc#1224647).
  - Update
    patches.suse/efi-capsule-loader-fix-incorrect-allocation-size.patch
    (git-fixes CVE-2024-27413 bsc#1224438).
  - Update patches.suse/efi-fix-panic-in-kdump-kernel.patch
    (git-fixes CVE-2024-35800 bsc#1224507).
  - Update
    patches.suse/fat-fix-uninitialized-field-in-nostale-filehandles.patch
    (git-fixes CVE-2024-26973 bsc#1223641).
  - Update
    patches.suse/fbmon-prevent-division-by-zero-in-fb_videomode_from_.patch
    (stable-fixes CVE-2024-35922 bsc#1224660).
  - Update
    patches.suse/fs-aio-Check-IOCB_AIO_RW-before-the-struct-aio_kiocb.patch
    (bsc#1222721 CVE-2024-26764 CVE-2024-35815 bsc#1224685).
  - Update
    patches.suse/geneve-fix-header-validation-in-geneve-6-_xmit_skb.patch
    (git-fixes CVE-2024-35973 bsc#1224586).
  - Update
    patches.suse/geneve-make-sure-to-pull-inner-header-in-geneve_rx.patch
    (git-fixes CVE-2024-26857 bsc#1223058).
  - Update
    patches.suse/i2c-smbus-fix-NULL-function-pointer-dereference.patch
    (git-fixes CVE-2024-35984 bsc#1224567).
  - Update
    patches.suse/ice-fix-memory-corruption-bug-with-suspend-and-rebui.patch
    (git-fixes CVE-2024-35911 bsc#1224486).
  - Update
    patches.suse/ice-fix-uninitialized-dplls-mutex-usage.patch
    (git-fixes CVE-2024-26854 bsc#1223039).
  - Update
    patches.suse/idpf-fix-kernel-panic-on-unknown-packet-types.patch
    (git-fixes CVE-2024-35889 bsc#1224517).
  - Update
    patches.suse/igc-avoid-returning-frame-twice-in-XDP_REDIRECT.patch
    (git-fixes CVE-2024-26853 bsc#1223061).
  - Update
    patches.suse/init-main.c-Fix-potential-static_command_line-memory.patch
    (git-fixes CVE-2024-26988 bsc#1223747).
  - Update
    patches.suse/iommufd-Fix-iopt_access_list_id-overwrite-bug.patch
    (git-fixes CVE-2024-26786 bsc#1222780).
  - Update
    patches.suse/irqchip-gic-v3-its-Prevent-double-free-on-error.patch
    (git-fixes CVE-2024-35847 bsc#1224697).
  - Update
    patches.suse/kprobes-Fix-possible-use-after-free-issue-on-kprobe-registration.patch
    (git-fixes CVE-2024-35955 bsc#1224676).
  - Update
    patches.suse/mac802154-fix-llsec-key-resources-release-in-mac8021.patch
    (git-fixes CVE-2024-26961 bsc#1223652).
  - Update
    patches.suse/md-dm-raid-don-t-call-md_reap_sync_thread-directly-cd32.patch
    (jsc#PED-7542 CVE-2024-35808 bsc#1224623).
  - Update patches.suse/md-fix-kmemleak-of-rdev-serial-6cf3.patch
    (jsc#PED-7542 CVE-2024-26900 bsc#1223046).
  - Update
    patches.suse/media-tc358743-register-v4l2-async-device-only-after.patch
    (git-fixes CVE-2024-35830 bsc#1224680).
  - Update
    patches.suse/misc-lis3lv02d_i2c-Fix-regulators-getting-en-dis-abl.patch
    (git-fixes CVE-2024-35824 bsc#1224609).
  - Update
    patches.suse/mlxbf_gige-call-request_irq-after-NAPI-initialized.patch
    (git-fixes CVE-2024-35907 bsc#1224492).
  - Update
    patches.suse/mlxbf_gige-stop-interface-during-shutdown.patch
    (git-fixes CVE-2024-35885 bsc#1224519).
  - Update
    patches.suse/mmc-core-Avoid-negative-index-with-array-access.patch
    (git-fixes CVE-2024-35813 bsc#1224618).
  - Update
    patches.suse/msft-hv-2971-net-mana-Fix-Rx-DMA-datasize-and-skb_over_panic.patch
    (git-fixes CVE-2024-35901 bsc#1224495).
  - Update
    patches.suse/net-ena-Fix-incorrect-descriptor-free-behavior.patch
    (git-fixes CVE-2024-35958 bsc#1224677).
  - Update
    patches.suse/net-ethernet-mtk_eth_soc-fix-PPE-hanging-issue.patch
    (git-fixes CVE-2024-27432 bsc#1224716).
  - Update
    patches.suse/net-hns3-fix-kernel-crash-when-1588-is-received-on-H.patch
    (git-fixes CVE-2024-26881 bsc#1223041).
  - Update
    patches.suse/net-ice-Fix-potential-NULL-pointer-dereference-in-ic.patch
    (git-fixes CVE-2024-26855 bsc#1223051).
  - Update
    patches.suse/net-ks8851-Handle-softirqs-at-the-end-of-IRQ-thread-.patch
    (git-fixes CVE-2024-35971 bsc#1224578).
  - Update
    patches.suse/net-ll_temac-platform_get_resource-replaced-by-wrong.patch
    (git-fixes CVE-2024-35796 bsc#1224615).
  - Update
    patches.suse/net-mlx5-Properly-link-new-fs-rules-into-the-tree.patch
    (git-fixes CVE-2024-35960 bsc#1224588).
  - Update
    patches.suse/net-mlx5-Register-devlink-first-under-devlink-lock.patch
    (git-fixes CVE-2024-35961 bsc#1224585).
  - Update
    patches.suse/net-mlx5e-Fix-mlx5e_priv_init-cleanup-flow.patch
    (git-fixes CVE-2024-35959 bsc#1224666).
  - Update
    patches.suse/net-mlx5e-Use-a-memory-barrier-to-enforce-PTP-WQ-xmi.patch
    (git-fixes CVE-2024-26858 bsc#1223020).
  - Update
    patches.suse/net-mlx5e-fix-a-double-free-in-arfs_create_groups.patch
    (jsc#PED-3311 CVE-2024-35835 bsc#1224605).
  - Update
    patches.suse/net-mvpp2-clear-BM-pool-before-initialization.patch
    (git-fixes CVE-2024-35837 bsc#1224500).
  - Update
    patches.suse/net-phy-micrel-Fix-potential-null-pointer-dereferenc.patch
    (git-fixes CVE-2024-35891 bsc#1224513).
  - Update
    patches.suse/net-phy-phy_device-Prevent-nullptr-exceptions-on-ISR.patch
    (stable-fixes CVE-2024-35945 bsc#1224639).
  - Update
    patches.suse/net-sparx5-Fix-use-after-free-inside-sparx5_del_mact.patch
    (git-fixes CVE-2024-26856 bsc#1223052).
  - Update patches.suse/net-tls-fix-WARNIING-in-__sk_msg_free.patch
    (bsc#1221858 CVE-2024-35841 bsc#1224687).
  - Update
    patches.suse/net-wwan-t7xx-Split-64bit-accesses-to-fix-alignment-.patch
    (git-fixes CVE-2024-35909 bsc#1224491).
  - Update
    patches.suse/nfc-nci-Fix-uninit-value-in-nci_dev_up-and-nci_ntf_p.patch
    (git-fixes CVE-2024-35915 bsc#1224479).
  - Update
    patches.suse/nfp-flower-handle-acti_netdevs-allocation-failure.patch
    (git-fixes CVE-2024-27046 bsc#1223827).
  - Update
    patches.suse/nfs-fix-panic-when-nfs4_ff_layout_prepare_ds-fails.patch
    (git-fixes CVE-2024-26868 bsc#1223038).
  - Update
    patches.suse/nfsd-Fix-error-cleanup-path-in-nfsd_rename.patch
    (bsc#1221044 CVE-2023-52591 CVE-2024-35914 bsc#1224482).
  - Update
    patches.suse/nouveau-fix-instmem-race-condition-around-ptr-stores.patch
    (git-fixes CVE-2024-26984 bsc#1223633).
  - Update patches.suse/nouveau-lock-the-client-object-tree.patch
    (stable-fixes CVE-2024-27062 bsc#1223834).
  - Update
    patches.suse/nvme-fc-do-not-wait-in-vain-when-unloading-module.patch
    (git-fixes CVE-2024-26846 bsc#1223023).
  - Update
    patches.suse/nvme-fix-reconnection-fail-due-to-reserved-tag-alloc.patch
    (git-fixes CVE-2024-27435 bsc#1224717).
  - Update
    patches.suse/octeontx2-af-Use-separate-handlers-for-interrupts.patch
    (git-fixes CVE-2024-27030 bsc#1223790).
  - Update
    patches.suse/octeontx2-pf-Fix-transmit-scheduler-resource-leak.patch
    (git-fixes CVE-2024-35975 bsc#1224569).
  - Update
    patches.suse/of-dynamic-Synchronize-of_changeset_destroy-with-the.patch
    (git-fixes CVE-2024-35879 bsc#1224524).
  - Update
    patches.suse/of-module-prevent-NULL-pointer-dereference-in-vsnpri.patch
    (stable-fixes CVE-2024-35878 bsc#1224671).
  - Update
    patches.suse/phy-marvell-a3700-comphy-Fix-out-of-bounds-read.patch
    (git-fixes CVE-2024-35992 bsc#1224555).
  - Update
    patches.suse/phy-ti-tusb1210-Resolve-charger-det-crash-if-charger.patch
    (git-fixes CVE-2024-35986 bsc#1224562).
  - Update
    patches.suse/platform-chrome-cros_ec_uart-properly-fix-race-condi.patch
    (git-fixes CVE-2024-35977 bsc#1224568).
  - Update
    patches.suse/power-supply-bq27xxx-i2c-Do-not-free-non-existing-IR.patch
    (git-fixes CVE-2024-27412 bsc#1224437).
  - Update
    patches.suse/pstore-inode-Only-d_invalidate-is-needed.patch
    (git-fixes CVE-2024-27389 bsc#1223705).
  - Update
    patches.suse/pstore-zone-Add-a-null-pointer-check-to-the-psz_kmsg.patch
    (stable-fixes CVE-2024-35940 bsc#1224537).
  - Update
    patches.suse/s390-zcrypt-fix-reference-counting-on-zcrypt-card-objects.patch
    (git-fixes bsc#1223592 CVE-2024-26957 bsc#1223666).
  - Update
    patches.suse/scsi-core-Fix-unremoved-procfs-host-directory-regression.patch
    (git-fixes CVE-2024-26935 bsc#1223675).
  - Update
    patches.suse/scsi-lpfc-Fix-possible-memory-leak-in-lpfc_rcv_padis.patch
    (bsc#1220021 CVE-2024-35930 bsc#1224651).
  - Update patches.suse/scsi-sg-Avoid-sg-device-teardown-race.patch
    (git-fixes CVE-2024-35954 bsc#1224675).
  - Update
    patches.suse/scsi-smartpqi-Fix-disable_managed_interrupts.patch
    (git-fixes CVE-2024-26742 bsc#1222608).
  - Update
    patches.suse/selinux-avoid-dereference-of-garbage-after-mount-fai.patch
    (git-fixes CVE-2024-35904 bsc#1224494).
  - Update
    patches.suse/serial-mxs-auart-add-spinlock-around-changing-cts-st.patch
    (git-fixes CVE-2024-27000 bsc#1223757).
  - Update
    patches.suse/serial-pmac_zilog-Remove-flawed-mitigation-for-rx-ir.patch
    (git-fixes CVE-2024-26999 bsc#1223754).
  - Update
    patches.suse/soc-fsl-qbman-Always-disable-interrupts-when-taking-.patch
    (git-fixes CVE-2024-35806 bsc#1224699).
  - Update
    patches.suse/soc-fsl-qbman-Use-raw-spinlock-for-cgr_lock.patch
    (git-fixes CVE-2024-35819 bsc#1224683).
  - Update patches.suse/speakup-Avoid-crash-on-very-long-word.patch
    (git-fixes CVE-2024-26994 bsc#1223750).
  - Update
    patches.suse/spi-lpspi-Avoid-potential-use-after-free-in-probe.patch
    (git-fixes CVE-2024-26866 bsc#1223024).
  - Update
    patches.suse/spi-mchp-pci1xxx-Fix-a-possible-null-pointer-derefer.patch
    (git-fixes CVE-2024-35883 bsc#1224521).
  - Update
    patches.suse/spi-spi-mt65xx-Fix-NULL-pointer-access-in-interrupt-.patch
    (git-fixes CVE-2024-27028 bsc#1223788).
  - Update
    patches.suse/ubifs-Set-page-uptodate-in-the-correct-place.patch
    (git-fixes CVE-2024-35821 bsc#1224629).
  - Update
    patches.suse/usb-cdc-wdm-close-race-between-read-and-workqueue.patch
    (git-fixes CVE-2024-35812 bsc#1224624).
  - Update
    patches.suse/usb-dwc2-host-Fix-dereference-issue-in-DDMA-completi.patch
    (git-fixes CVE-2024-26997 bsc#1223741).
  - Update
    patches.suse/usb-dwc3-am62-fix-module-unload-reload-behavior.patch
    (git-fixes CVE-2024-26963 bsc#1223651).
  - Update
    patches.suse/usb-gadget-f_ncm-Fix-UAF-ncm-object-at-re-bind-after.patch
    (stable-fixes CVE-2024-26996 bsc#1223752).
  - Update
    patches.suse/usb-gadget-ncm-Avoid-dropping-datagrams-of-properly-.patch
    (git-fixes CVE-2024-27405 bsc#1224423).
  - Update
    patches.suse/usb-gadget-ncm-Fix-handling-of-zero-block-length-pac.patch
    (git-fixes CVE-2024-35825 bsc#1224681).
  - Update
    patches.suse/usb-typec-altmodes-displayport-create-sysfs-nodes-as.patch
    (git-fixes CVE-2024-35790 bsc#1224712).
  - Update
    patches.suse/usb-typec-tcpm-Correct-the-PDO-counting-in-pd_set.patch
    (git-fixes CVE-2024-26995 bsc#1223696).
  - Update
    patches.suse/usb-typec-tcpm-fix-double-free-issue-in-tcpm_port_un.patch
    (git-fixes CVE-2024-26932 bsc#1223649).
  - Update patches.suse/usb-typec-ucsi-Limit-read-size-on-v1.2.patch
    (stable-fixes CVE-2024-35924 bsc#1224657).
  - Update
    patches.suse/usb-udc-remove-warning-when-queue-disabled-ep.patch
    (stable-fixes CVE-2024-35822 bsc#1224739).
  - Update
    patches.suse/usb-xhci-Add-error-handling-in-xhci_map_urb_for_dma.patch
    (git-fixes CVE-2024-26964 bsc#1223650).
  - Update
    patches.suse/vt-fix-unicode-buffer-corruption-when-deleting-chara.patch
    (git-fixes CVE-2024-35823 bsc#1224692).
  - Update
    patches.suse/wifi-ath11k-decrease-MHI-channel-buffer-length-to-8K.patch
    (bsc#1207948 CVE-2024-35938 bsc#1224643).
  - Update
    patches.suse/wifi-brcmfmac-Fix-use-after-free-bug-in-brcmf_cfg802.patch
    (CVE-2023-47233 bsc#1216702 CVE-2024-35811 bsc#1224592).
  - Update
    patches.suse/wifi-cfg80211-check-A-MSDU-format-more-carefully.patch
    (stable-fixes CVE-2024-35937 bsc#1224526).
  - Update
    patches.suse/wifi-iwlwifi-dbg-tlv-ensure-NUL-termination.patch
    (git-fixes CVE-2024-35845 bsc#1224731).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-set-the-MFP-flag-for-the-GTK.patch
    (git-fixes CVE-2024-27434 bsc#1224710).
  - Update
    patches.suse/wifi-iwlwifi-mvm-rfi-fix-potential-response-leaks.patch
    (git-fixes CVE-2024-35912 bsc#1224487).
  - Update
    patches.suse/wifi-libertas-fix-some-memleaks-in-lbs_allocate_cmd_.patch
    (git-fixes CVE-2024-35828 bsc#1224622).
  - Update
    patches.suse/wifi-mac80211-check-clear-fast-rx-for-non-4addr-sta-.patch
    (stable-fixes CVE-2024-35789 bsc#1224749).
  - Update
    patches.suse/wifi-mac80211-fix-potential-sta-link-leak.patch
    (git-fixes CVE-2024-35838 bsc#1224613).
  - Update
    patches.suse/wifi-nl80211-reject-iftype-change-with-mesh-ID-chang.patch
    (git-fixes CVE-2024-27410 bsc#1224432).
  - Update
    patches.suse/wifi-rtw89-fix-null-pointer-access-when-abort-scan.patch
    (stable-fixes CVE-2024-35946 bsc#1224646).
  - Update
    patches.suse/wireguard-netlink-access-device-through-ctx-instead-.patch
    (git-fixes CVE-2024-26950 bsc#1223661).
  - Update
    patches.suse/wireguard-netlink-check-for-dangling-peer-via-is_dea.patch
    (git-fixes CVE-2024-26951 bsc#1223660).
  - Update
    patches.suse/wireguard-receive-annotate-data-race-around-receivin.patch
    (git-fixes CVE-2024-26861 bsc#1223076).
  - Update
    patches.suse/x86-coco-Require-seeding-RNG-with-RDRAND-on-CoCo-systems.patch
    (git-fixes CVE-2024-35875 bsc#1224665).
  - Update
    patches.suse/x86-fpu-Keep-xfd_state-in-sync-with-MSR_IA32_XFD.patch
    (git-fixes CVE-2024-35801 bsc#1224732).
  - Update
    patches.suse/xen-evtchn-avoid-WARN-when-unbinding-an-event-channe.patch
    (git-fixes CVE-2024-27067 bsc#1223739).
  - Update
    patches.suse/xsk-recycle-buffer-in-case-Rx-queue-was-full.patch
    (bsc#1221303 CVE-2024-26611 CVE-2024-35834 bsc#1224620).
  - commit 005afc6
  - Update
    patches.suse/ACPI-LPIT-Avoid-u32-multiplication-overflow.patch
    (git-fixes CVE-2023-52683 bsc#1224627).
  - Update
    patches.suse/ACPI-video-check-for-error-while-searching-for-backl.patch
    (git-fixes CVE-2023-52693 bsc#1224686).
  - Update
    patches.suse/ASoC-Intel-sof_sdw_rt_sdca_jack_common-ctx-headset_c.patch
    (git-fixes CVE-2023-52697 bsc#1224596).
  - Update
    patches.suse/ASoC-SOF-amd-Fix-memory-leak-in-amd_sof_acp_probe.patch
    (git-fixes CVE-2023-52663 bsc#1224630).
  - Update
    patches.suse/Revert-drm-amd-pm-resolve-reboot-exception-for-si-ol.patch
    (git-fixes CVE-2023-52657 bsc#1224722).
  - Update
    patches.suse/Revert-net-mlx5-Block-entering-switchdev-mode-with-n.patch
    (git-fixes CVE-2023-52658 bsc#1224719).
  - Update
    patches.suse/SUNRPC-fix-a-memleak-in-gss_import_v2_context.patch
    (git-fixes CVE-2023-52653 bsc#1223712).
  - Update
    patches.suse/bpf-Guard-stack-limits-against-32bit-overflow.patch
    (git-fixes CVE-2023-52676 bsc#1224730).
  - Update
    patches.suse/crypto-rsa-add-a-check-for-allocation-failure.patch
    (bsc#1222775 CVE-2023-52472 bsc#1220430).
  - Update
    patches.suse/crypto-s390-aes-Fix-buffer-overread-in-CTR-mode.patch
    (git-fixes CVE-2023-52669 bsc#1224637).
  - Update
    patches.suse/crypto-safexcel-Add-error-handling-for-dma_map_sg-ca.patch
    (git-fixes CVE-2023-52687 bsc#1224501).
  - Update
    patches.suse/drm-amd-display-Check-writeback-connectors-in-create.patch
    (git-fixes CVE-2023-52695 bsc#1224506).
  - Update
    patches.suse/drm-amd-display-Fix-a-debugfs-null-pointer-error.patch
    (git-fixes CVE-2023-52673 bsc#1224741).
  - Update
    patches.suse/drm-amd-display-Fix-hang-underflow-when-transitionin.patch
    (git-fixes CVE-2023-52671 bsc#1224729).
  - Update
    patches.suse/drm-amd-pm-fix-a-double-free-in-si_dpm_init.patch
    (git-fixes CVE-2023-52691 bsc#1224607).
  - Update
    patches.suse/drm-amdkfd-Confirm-list-is-non-empty-before-utilizin.patch
    (git-fixes CVE-2023-52678 bsc#1224617).
  - Update
    patches.suse/drm-bridge-tpd12s015-Drop-buggy-__exit-annotation-fo.patch
    (git-fixes CVE-2023-52694 bsc#1224598).
  - Update
    patches.suse/drm-tegra-rgb-Fix-missing-clk_put-in-the-error-handl.patch
    (git-fixes CVE-2023-52661 bsc#1224445).
  - Update
    patches.suse/drm-vmwgfx-fix-a-memleak-in-vmw_gmrid_man_get_node.patch
    (git-fixes CVE-2023-52662 bsc#1224449).
  - Update patches.suse/efivarfs-Free-s_fs_info-on-unmount.patch
    (bsc#1220328 CVE-2023-52463 CVE-2023-52681 bsc#1224505).
  - Update
    patches.suse/media-rkisp1-Fix-IRQ-handling-due-to-shared-interrup.patch
    (stable-fixes CVE-2023-52660 bsc#1224443).
  - Update
    patches.suse/net-atlantic-eliminate-double-free-in-error-handling.patch
    (git-fixes CVE-2023-52664 bsc#1224747).
  - Update
    patches.suse/net-mlx5e-fix-a-potential-double-free-in-fs_any_crea.patch
    (jsc#PED-3311 CVE-2023-52667 bsc#1224603).
  - Update
    patches.suse/of-Fix-double-free-in-of_parse_phandle_with_args_map.patch
    (git-fixes CVE-2023-52679 bsc#1224508).
  - Update
    patches.suse/powerpc-imc-pmu-Add-a-null-pointer-check-in-update_events_in_group.patch
    (git-fixes CVE-2023-52675 bsc#1224504).
  - Update
    patches.suse/powerpc-powernv-Add-a-null-pointer-check-in-opal_eve.patch
    (bsc#1065729 CVE-2023-52686 bsc#1224682).
  - Update
    patches.suse/powerpc-powernv-Add-a-null-pointer-check-in-opal_pow.patch
    (bsc#1181674 ltc#189159 git-fixes CVE-2023-52696 bsc#1224601).
  - Update
    patches.suse/powerpc-powernv-Add-a-null-pointer-check-to-scom_deb.patch
    (bsc#1194869 CVE-2023-52690 bsc#1224611).
  - Update
    patches.suse/pstore-ram_core-fix-possible-overflow-in-persistent_.patch
    (git-fixes CVE-2023-52685 bsc#1224728).
  - Update
    patches.suse/rpmsg-virtio-Free-driver_override-when-rpmsg_remove.patch
    (git-fixes CVE-2023-52670 bsc#1224696).
  - commit 578211b
  - vhost: Add smp_rmb() in vhost_enable_notify() (git-fixes).
  - commit 2e20e2c
  - vhost: Add smp_rmb() in vhost_vq_avail_empty() (git-fixes).
  - commit 936d53e
  - virtio_net: Do not send RSS key if it is not supported
    (git-fixes).
  - commit cc7c4a0
  - vsock/virtio: fix packet delivery to tap device (git-fixes).
  - commit dfd8673
  - virtio-blk: Ensure no requests in virtqueues before deleting
    vqs (git-fixes).
  - commit 966a23e
  - KVM: VMX: Disable LBR virtualization if the CPU doesn't support
    LBR callstacks (git-fixes).
  - commit f941b05
  - efi/unaccepted: do not let /proc/vmcore try to access unaccepted memory (git-fixes).
  - commit c99f198
  - proc/kcore: do not try to access unaccepted memory (git-fixes).
  - commit 2daf00c
  - efi/unaccepted: touch soft lockup during memory accept (git-fixes).
  - commit 45ed7cb
  - x86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type (bsc#1224442 CVE-2023-52659).
  - commit dad72fd
  - kabi fix of perf/x86/intel: Expose existence of callback support to KVM
    (git fixes).
  - commit 5db441c
  - perf/x86/intel: Expose existence of callback support to KVM
    (git-fixes).
  - commit b24b5fc
  - kABI fix of KVM: x86: Snapshot if a vCPU's vendor model is AMD vs.
    Intel compatible (git-fixes).
  - commit 38bcaaa
  - ceph: redirty page before returning AOP_WRITEPAGE_ACTIVATE
    (bsc#1224866).
  - commit 6a4b4a1
  - supported.conf: Add APM X-Gene SoC hardware monitoring driver (bsc#1223265 jsc#PED-8570)
  - commit 4b0eeb3
  - remoteproc: k3-r5: Jump to error handling labels in start/stop
    errors (git-fixes).
  - commit 6f545f8
  - libsubcmd: Fix parse-options memory leak (git-fixes).
  - dmaengine: idxd: Avoid unnecessary destruction of file_ida
    (git-fixes).
  - dmaengine: axi-dmac: fix possible race in remove() (git-fixes).
  - dmaengine: idma64: Add check for dma_set_max_seg_size
    (git-fixes).
  - remoteproc: k3-r5: Do not allow core1 to power up before core0
    via sysfs (git-fixes).
  - remoteproc: k3-r5: Wait for core0 power-up before powering up
    core1 (git-fixes).
  - remoteproc: mediatek: Make sure IPI buffer fits in L2TCM
    (git-fixes).
  - PCI: tegra194: Fix probe path for Endpoint mode (git-fixes).
  - PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
    (git-fixes).
  - PCI: dwc: ep: Fix DBI access failure for drivers requiring
    refclk from host (git-fixes).
  - PCI/EDR: Align EDR_PORT_LOCATE_DSM with PCI Firmware r3.3
    (git-fixes).
  - PCI/EDR: Align EDR_PORT_DPC_ENABLE_DSM with PCI Firmware r3.3
    (git-fixes).
  - KEYS: trusted: Do not use WARN when encode fails (git-fixes).
  - KEYS: trusted: Fix memory leak in tpm2_key_encode() (git-fixes).
  - commit d7da373

++++ kernel-rt:

  - af_unix: Suppress false-positive lockdep splat for spin_lock()
    in __unix_gc() (CVE-2024-26923 bsc#1223384).
  - af_unix: fix lockdep positive in sk_diag_dump_icons()
    (CVE-2024-26923 bsc#1223384).
  - commit a652e3a
  - Update
    patches.suse/ACPI-CPPC-Use-access_width-over-bit_width-for-system.patch
    (stable-fixes CVE-2024-35995 bsc#1224557).
  - Update
    patches.suse/ALSA-usb-audio-Stop-parsing-channels-bits-when-all-c.patch
    (git-fixes CVE-2024-27436 bsc#1224803).
  - Update
    patches.suse/ASoC-SOF-ipc4-pcm-Workaround-for-crashed-firmware-on.patch
    (stable-fixes CVE-2024-27057 bsc#1223831).
  - Update
    patches.suse/ASoC-mediatek-sof-common-Add-NULL-check-for-normal_l.patch
    (git-fixes CVE-2024-35842 bsc#1224688).
  - Update
    patches.suse/Bluetooth-Fix-memory-leak-in-hci_req_sync_complete.patch
    (git-fixes CVE-2024-35978 bsc#1224571).
  - Update
    patches.suse/Bluetooth-Fix-use-after-free-bugs-caused-by-sco_sock.patch
    (git-fixes CVE-2024-27398 bsc#1224174).
  - Update
    patches.suse/Bluetooth-L2CAP-Fix-not-validating-setsockopt-user-i.patch
    (git-fixes CVE-2024-35965 bsc#1224579).
  - Update
    patches.suse/Bluetooth-RFCOMM-Fix-not-validating-setsockopt-user-.patch
    (git-fixes CVE-2024-35966 bsc#1224576).
  - Update
    patches.suse/Bluetooth-SCO-Fix-not-validating-setsockopt-user-inp.patch
    (git-fixes CVE-2024-35967 bsc#1224587).
  - Update
    patches.suse/Bluetooth-btintel-Fix-null-ptr-deref-in-btintel_read.patch
    (stable-fixes CVE-2024-35933 bsc#1224640).
  - Update
    patches.suse/Bluetooth-hci_event-Fix-handling-of-HCI_EV_IO_CAPA_R.patch
    (git-fixes CVE-2024-27416 bsc#1224723).
  - Update
    patches.suse/Bluetooth-hci_sock-Fix-not-validating-setsockopt-use.patch
    (git-fixes CVE-2024-35963 bsc#1224582).
  - Update
    patches.suse/Bluetooth-l2cap-fix-null-ptr-deref-in-l2cap_chan_tim.patch
    (git-fixes CVE-2024-27399 bsc#1224177).
  - Update
    patches.suse/Bluetooth-qca-fix-NULL-deref-on-non-serdev-setup.patch
    (git-fixes CVE-2024-35850 bsc#1224600).
  - Update
    patches.suse/Bluetooth-qca-fix-NULL-deref-on-non-serdev-suspend.patch
    (git-fixes CVE-2024-35851 bsc#1224509).
  - Update
    patches.suse/Bluetooth-rfcomm-Fix-null-ptr-deref-in-rfcomm_check_.patch
    (bsc#1219170 CVE-2024-22099 CVE-2024-26903 bsc#1223187).
  - Update
    patches.suse/HID-i2c-hid-remove-I2C_HID_READ_PENDING-flag-to-prev.patch
    (git-fixes CVE-2024-35997 bsc#1224552).
  - Update
    patches.suse/NFS-Fix-nfs_netfs_issue_read-xarray-locking-for-writ.patch
    (git-fixes CVE-2024-27031 bsc#1223805).
  - Update
    patches.suse/NFSv4.2-fix-nfs4_listxattr-kernel-BUG-at-mm-usercopy.patch
    (git-fixes CVE-2024-26870 bsc#1223113).
  - Update
    patches.suse/PCI-PM-Drain-runtime-idle-callbacks-before-driver-re.patch
    (stable-fixes CVE-2024-35809 bsc#1224738).
  - Update
    patches.suse/SUNRPC-fix-some-memleaks-in-gssx_dec_option_array.patch
    (git-fixes CVE-2024-27388 bsc#1223744).
  - Update
    patches.suse/USB-core-Fix-deadlock-in-usb_deauthorize_interface.patch
    (git-fixes CVE-2024-26934 bsc#1223671).
  - Update patches.suse/accel-ivpu-Fix-deadlock-in-context_xa.patch
    (git-fixes CVE-2024-35953 bsc#1224704).
  - Update
    patches.suse/arm64-hibernate-Fix-level3-translation-fault-in-swsu.patch
    (git-fixes CVE-2024-26989 bsc#1223748).
  - Update patches.suse/ax25-Fix-netdev-refcount-issue.patch
    (git-fixes CVE-2024-36009 bsc#1224542).
  - Update
    patches.suse/ax25-fix-use-after-free-bugs-caused-by-ax25_ds_del_t.patch
    (git-fixes CVE-2024-35887 bsc#1224663).
  - Update
    patches.suse/batman-adv-Avoid-infinite-loop-trying-to-resize-loca.patch
    (git-fixes CVE-2024-35982 bsc#1224566).
  - Update
    patches.suse/block-fix-q-blkg_list-corruption-during-disk-rebind.patch
    (bsc#1223591 CVE-2024-35974 bsc#1224573).
  - Update
    patches.suse/bnxt_en-Fix-possible-memory-leak-in-bnxt_rdma_aux_de.patch
    (git-fixes CVE-2024-35972 bsc#1224577).
  - Update
    patches.suse/bootconfig-use-memblock_free_late-to-free-xbc-memory.patch
    (git-fixes CVE-2024-26983 bsc#1223637).
  - Update
    patches.suse/btrfs-fix-deadlock-with-fiemap-and-extent-locking.patch
    (bsc#1223285 CVE-2024-35784 bsc#1224804).
  - Update
    patches.suse/btrfs-fix-information-leak-in-btrfs_ioctl_logical_to.patch
    (git-fixes CVE-2024-35849 bsc#1224733).
  - Update
    patches.suse/btrfs-fix-race-between-ordered-extent-completion-and.patch
    (bsc#1223285 CVE-2024-26794 bsc#1222426).
  - Update
    patches.suse/btrfs-fix-race-when-detecting-delalloc-ranges-during.patch
    (bsc#1223285 CVE-2024-27080 bsc#1223782).
  - Update
    patches.suse/btrfs-handle-chunk-tree-lookup-error-in-btrfs_reloca.patch
    (git-fixes CVE-2024-35936 bsc#1224644).
  - Update
    patches.suse/clk-Get-runtime-PM-before-walking-tree-during-disabl.patch
    (git-fixes CVE-2024-27004 bsc#1223762).
  - Update
    patches.suse/clk-Get-runtime-PM-before-walking-tree-for-clk_summa.patch
    (git-fixes CVE-2024-27003 bsc#1223761).
  - Update
    patches.suse/clk-mediatek-Do-a-runtime-PM-get-on-controllers-duri.patch
    (git-fixes CVE-2024-27002 bsc#1223759).
  - Update
    patches.suse/comedi-vmk80xx-fix-incomplete-endpoint-checking.patch
    (git-fixes CVE-2024-27001 bsc#1223698).
  - Update
    patches.suse/dm-raid-really-frozen-sync_thread-during-suspend-16c4.patch
    (jsc#PED-7542 CVE-2024-35794 bsc#1224706).
  - Update
    patches.suse/dm-raid456-md-raid456-fix-a-deadlock-for-dm-raid456-4142.patch
    (bsc#1219596 CVE-2024-26962 bsc#1223654).
  - Update
    patches.suse/dma-buf-Fix-NULL-pointer-dereference-in-sanitycheck.patch
    (git-fixes CVE-2024-35916 bsc#1224480).
  - Update patches.suse/dma-xilinx_dpdma-Fix-locking.patch
    (git-fixes CVE-2024-35990 bsc#1224559).
  - Update
    patches.suse/dmaengine-fsl-qdma-Fix-a-memory-leak-related-to-the--3aa58cb.patch
    (git-fixes CVE-2024-35833 bsc#1224632).
  - Update
    patches.suse/dmaengine-idxd-Fix-oops-during-rmmod-on-single-CPU-p.patch
    (git-fixes CVE-2024-35989 bsc#1224558).
  - Update
    patches.suse/dpll-fix-dpll_pin_on_pin_register-for-multiple-paren.patch
    (CVE-2024-27027 bsc#1223787 CVE-2024-36002 bsc#1224546).
  - Update
    patches.suse/dpll-fix-pin-dump-crash-for-rebound-module.patch
    (jsc#PED-6079 CVE-2024-35836 bsc#1224633).
  - Update
    patches.suse/drm-Check-output-polling-initialized-before-disablin.patch
    (stable-fixes CVE-2024-35927 bsc#1224654).
  - Update
    patches.suse/drm-amd-amdgpu-Fix-potential-ioremap-memory-leaks-in.patch
    (stable-fixes CVE-2024-35928 bsc#1224653).
  - Update
    patches.suse/drm-amd-display-Fix-bounds-check-for-dcn35-DcfClocks.patch
    (git-fixes CVE-2024-35788 bsc#1224709).
  - Update
    patches.suse/drm-amd-display-Prevent-crash-when-disable-stream.patch
    (stable-fixes CVE-2024-35799 bsc#1224740).
  - Update
    patches.suse/drm-amdgpu-amdgpu_ttm_gart_bind-set-gtt-bound-flag.patch
    (stable-fixes CVE-2024-35817 bsc#1224736).
  - Update
    patches.suse/drm-amdgpu-fix-deadlock-while-reading-mqd-from-debug.patch
    (git-fixes CVE-2024-35795 bsc#1224634).
  - Update
    patches.suse/drm-amdgpu-fix-mmhub-client-id-out-of-bounds-access.patch
    (git-fixes CVE-2024-27029 bsc#1223789).
  - Update
    patches.suse/drm-amdgpu-once-more-fix-the-call-oder-in-amdgpu_ttm.patch
    (git-fixes CVE-2024-27400 bsc#1224180).
  - Update
    patches.suse/drm-amdgpu-pm-Fix-NULL-pointer-dereference-when-get-.patch
    (git-fixes CVE-2024-26949 bsc#1223665).
  - Update
    patches.suse/drm-amdgpu-validate-the-parameters-of-bo-mapping-ope.patch
    (git-fixes CVE-2024-26922 bsc#1223315).
  - Update
    patches.suse/drm-amdkfd-Fix-memory-leak-in-create_process-failure.patch
    (git-fixes CVE-2024-26986 bsc#1223728).
  - Update patches.suse/drm-ast-Fix-soft-lockup.patch (git-fixes
    CVE-2024-35952 bsc#1224705).
  - Update
    patches.suse/drm-client-Fully-protect-modes-with-dev-mode_config..patch
    (stable-fixes CVE-2024-35950 bsc#1224703).
  - Update
    patches.suse/drm-i915-bios-Tolerate-devdata-NULL-in-intel_bios_en.patch
    (stable-fixes CVE-2024-26938 bsc#1223678).
  - Update
    patches.suse/drm-i915-gt-Reset-queue_priority_hint-on-parking.patch
    (git-fixes CVE-2024-26937 bsc#1223677).
  - Update
    patches.suse/drm-lima-fix-a-memleak-in-lima_heap_alloc.patch
    (git-fixes CVE-2024-35829 bsc#1224707).
  - Update
    patches.suse/drm-nouveau-fix-stale-locked-mutex-in-nouveau_gem_io.patch
    (git-fixes CVE-2024-35786 bsc#1224714).
  - Update
    patches.suse/drm-nouveau-keep-DMA-buffers-required-for-suspend-re.patch
    (git-fixes CVE-2024-27411 bsc#1224433).
  - Update patches.suse/drm-nv04-Fix-out-of-bounds-access.patch
    (git-fixes CVE-2024-27008 bsc#1223802).
  - Update
    patches.suse/drm-panfrost-Fix-the-error-path-in-panfrost_mmu_map_.patch
    (git-fixes CVE-2024-35951 bsc#1224701).
  - Update
    patches.suse/drm-vc4-don-t-check-if-plane-state-fb-state-fb.patch
    (stable-fixes CVE-2024-35932 bsc#1224650).
  - Update
    patches.suse/drm-vmwgfx-Create-debugfs-ttm_resource_manager-entry.patch
    (git-fixes CVE-2024-26940 bsc#1223718).
  - Update
    patches.suse/drm-vmwgfx-Fix-the-lifetime-of-the-bo-cursor-memory.patch
    (git-fixes CVE-2024-35810 bsc#1224626).
  - Update
    patches.suse/dyndbg-fix-old-BUG_ON-in-control-parser.patch
    (stable-fixes CVE-2024-35947 bsc#1224647).
  - Update
    patches.suse/efi-capsule-loader-fix-incorrect-allocation-size.patch
    (git-fixes CVE-2024-27413 bsc#1224438).
  - Update patches.suse/efi-fix-panic-in-kdump-kernel.patch
    (git-fixes CVE-2024-35800 bsc#1224507).
  - Update
    patches.suse/fat-fix-uninitialized-field-in-nostale-filehandles.patch
    (git-fixes CVE-2024-26973 bsc#1223641).
  - Update
    patches.suse/fbmon-prevent-division-by-zero-in-fb_videomode_from_.patch
    (stable-fixes CVE-2024-35922 bsc#1224660).
  - Update
    patches.suse/fs-aio-Check-IOCB_AIO_RW-before-the-struct-aio_kiocb.patch
    (bsc#1222721 CVE-2024-26764 CVE-2024-35815 bsc#1224685).
  - Update
    patches.suse/geneve-fix-header-validation-in-geneve-6-_xmit_skb.patch
    (git-fixes CVE-2024-35973 bsc#1224586).
  - Update
    patches.suse/geneve-make-sure-to-pull-inner-header-in-geneve_rx.patch
    (git-fixes CVE-2024-26857 bsc#1223058).
  - Update
    patches.suse/i2c-smbus-fix-NULL-function-pointer-dereference.patch
    (git-fixes CVE-2024-35984 bsc#1224567).
  - Update
    patches.suse/ice-fix-memory-corruption-bug-with-suspend-and-rebui.patch
    (git-fixes CVE-2024-35911 bsc#1224486).
  - Update
    patches.suse/ice-fix-uninitialized-dplls-mutex-usage.patch
    (git-fixes CVE-2024-26854 bsc#1223039).
  - Update
    patches.suse/idpf-fix-kernel-panic-on-unknown-packet-types.patch
    (git-fixes CVE-2024-35889 bsc#1224517).
  - Update
    patches.suse/igc-avoid-returning-frame-twice-in-XDP_REDIRECT.patch
    (git-fixes CVE-2024-26853 bsc#1223061).
  - Update
    patches.suse/init-main.c-Fix-potential-static_command_line-memory.patch
    (git-fixes CVE-2024-26988 bsc#1223747).
  - Update
    patches.suse/iommufd-Fix-iopt_access_list_id-overwrite-bug.patch
    (git-fixes CVE-2024-26786 bsc#1222780).
  - Update
    patches.suse/irqchip-gic-v3-its-Prevent-double-free-on-error.patch
    (git-fixes CVE-2024-35847 bsc#1224697).
  - Update
    patches.suse/kprobes-Fix-possible-use-after-free-issue-on-kprobe-registration.patch
    (git-fixes CVE-2024-35955 bsc#1224676).
  - Update
    patches.suse/mac802154-fix-llsec-key-resources-release-in-mac8021.patch
    (git-fixes CVE-2024-26961 bsc#1223652).
  - Update
    patches.suse/md-dm-raid-don-t-call-md_reap_sync_thread-directly-cd32.patch
    (jsc#PED-7542 CVE-2024-35808 bsc#1224623).
  - Update patches.suse/md-fix-kmemleak-of-rdev-serial-6cf3.patch
    (jsc#PED-7542 CVE-2024-26900 bsc#1223046).
  - Update
    patches.suse/media-tc358743-register-v4l2-async-device-only-after.patch
    (git-fixes CVE-2024-35830 bsc#1224680).
  - Update
    patches.suse/misc-lis3lv02d_i2c-Fix-regulators-getting-en-dis-abl.patch
    (git-fixes CVE-2024-35824 bsc#1224609).
  - Update
    patches.suse/mlxbf_gige-call-request_irq-after-NAPI-initialized.patch
    (git-fixes CVE-2024-35907 bsc#1224492).
  - Update
    patches.suse/mlxbf_gige-stop-interface-during-shutdown.patch
    (git-fixes CVE-2024-35885 bsc#1224519).
  - Update
    patches.suse/mmc-core-Avoid-negative-index-with-array-access.patch
    (git-fixes CVE-2024-35813 bsc#1224618).
  - Update
    patches.suse/msft-hv-2971-net-mana-Fix-Rx-DMA-datasize-and-skb_over_panic.patch
    (git-fixes CVE-2024-35901 bsc#1224495).
  - Update
    patches.suse/net-ena-Fix-incorrect-descriptor-free-behavior.patch
    (git-fixes CVE-2024-35958 bsc#1224677).
  - Update
    patches.suse/net-ethernet-mtk_eth_soc-fix-PPE-hanging-issue.patch
    (git-fixes CVE-2024-27432 bsc#1224716).
  - Update
    patches.suse/net-hns3-fix-kernel-crash-when-1588-is-received-on-H.patch
    (git-fixes CVE-2024-26881 bsc#1223041).
  - Update
    patches.suse/net-ice-Fix-potential-NULL-pointer-dereference-in-ic.patch
    (git-fixes CVE-2024-26855 bsc#1223051).
  - Update
    patches.suse/net-ks8851-Handle-softirqs-at-the-end-of-IRQ-thread-.patch
    (git-fixes CVE-2024-35971 bsc#1224578).
  - Update
    patches.suse/net-ll_temac-platform_get_resource-replaced-by-wrong.patch
    (git-fixes CVE-2024-35796 bsc#1224615).
  - Update
    patches.suse/net-mlx5-Properly-link-new-fs-rules-into-the-tree.patch
    (git-fixes CVE-2024-35960 bsc#1224588).
  - Update
    patches.suse/net-mlx5-Register-devlink-first-under-devlink-lock.patch
    (git-fixes CVE-2024-35961 bsc#1224585).
  - Update
    patches.suse/net-mlx5e-Fix-mlx5e_priv_init-cleanup-flow.patch
    (git-fixes CVE-2024-35959 bsc#1224666).
  - Update
    patches.suse/net-mlx5e-Use-a-memory-barrier-to-enforce-PTP-WQ-xmi.patch
    (git-fixes CVE-2024-26858 bsc#1223020).
  - Update
    patches.suse/net-mlx5e-fix-a-double-free-in-arfs_create_groups.patch
    (jsc#PED-3311 CVE-2024-35835 bsc#1224605).
  - Update
    patches.suse/net-mvpp2-clear-BM-pool-before-initialization.patch
    (git-fixes CVE-2024-35837 bsc#1224500).
  - Update
    patches.suse/net-phy-micrel-Fix-potential-null-pointer-dereferenc.patch
    (git-fixes CVE-2024-35891 bsc#1224513).
  - Update
    patches.suse/net-phy-phy_device-Prevent-nullptr-exceptions-on-ISR.patch
    (stable-fixes CVE-2024-35945 bsc#1224639).
  - Update
    patches.suse/net-sparx5-Fix-use-after-free-inside-sparx5_del_mact.patch
    (git-fixes CVE-2024-26856 bsc#1223052).
  - Update patches.suse/net-tls-fix-WARNIING-in-__sk_msg_free.patch
    (bsc#1221858 CVE-2024-35841 bsc#1224687).
  - Update
    patches.suse/net-wwan-t7xx-Split-64bit-accesses-to-fix-alignment-.patch
    (git-fixes CVE-2024-35909 bsc#1224491).
  - Update
    patches.suse/nfc-nci-Fix-uninit-value-in-nci_dev_up-and-nci_ntf_p.patch
    (git-fixes CVE-2024-35915 bsc#1224479).
  - Update
    patches.suse/nfp-flower-handle-acti_netdevs-allocation-failure.patch
    (git-fixes CVE-2024-27046 bsc#1223827).
  - Update
    patches.suse/nfs-fix-panic-when-nfs4_ff_layout_prepare_ds-fails.patch
    (git-fixes CVE-2024-26868 bsc#1223038).
  - Update
    patches.suse/nfsd-Fix-error-cleanup-path-in-nfsd_rename.patch
    (bsc#1221044 CVE-2023-52591 CVE-2024-35914 bsc#1224482).
  - Update
    patches.suse/nouveau-fix-instmem-race-condition-around-ptr-stores.patch
    (git-fixes CVE-2024-26984 bsc#1223633).
  - Update patches.suse/nouveau-lock-the-client-object-tree.patch
    (stable-fixes CVE-2024-27062 bsc#1223834).
  - Update
    patches.suse/nvme-fc-do-not-wait-in-vain-when-unloading-module.patch
    (git-fixes CVE-2024-26846 bsc#1223023).
  - Update
    patches.suse/nvme-fix-reconnection-fail-due-to-reserved-tag-alloc.patch
    (git-fixes CVE-2024-27435 bsc#1224717).
  - Update
    patches.suse/octeontx2-af-Use-separate-handlers-for-interrupts.patch
    (git-fixes CVE-2024-27030 bsc#1223790).
  - Update
    patches.suse/octeontx2-pf-Fix-transmit-scheduler-resource-leak.patch
    (git-fixes CVE-2024-35975 bsc#1224569).
  - Update
    patches.suse/of-dynamic-Synchronize-of_changeset_destroy-with-the.patch
    (git-fixes CVE-2024-35879 bsc#1224524).
  - Update
    patches.suse/of-module-prevent-NULL-pointer-dereference-in-vsnpri.patch
    (stable-fixes CVE-2024-35878 bsc#1224671).
  - Update
    patches.suse/phy-marvell-a3700-comphy-Fix-out-of-bounds-read.patch
    (git-fixes CVE-2024-35992 bsc#1224555).
  - Update
    patches.suse/phy-ti-tusb1210-Resolve-charger-det-crash-if-charger.patch
    (git-fixes CVE-2024-35986 bsc#1224562).
  - Update
    patches.suse/platform-chrome-cros_ec_uart-properly-fix-race-condi.patch
    (git-fixes CVE-2024-35977 bsc#1224568).
  - Update
    patches.suse/power-supply-bq27xxx-i2c-Do-not-free-non-existing-IR.patch
    (git-fixes CVE-2024-27412 bsc#1224437).
  - Update
    patches.suse/pstore-inode-Only-d_invalidate-is-needed.patch
    (git-fixes CVE-2024-27389 bsc#1223705).
  - Update
    patches.suse/pstore-zone-Add-a-null-pointer-check-to-the-psz_kmsg.patch
    (stable-fixes CVE-2024-35940 bsc#1224537).
  - Update
    patches.suse/s390-zcrypt-fix-reference-counting-on-zcrypt-card-objects.patch
    (git-fixes bsc#1223592 CVE-2024-26957 bsc#1223666).
  - Update
    patches.suse/scsi-core-Fix-unremoved-procfs-host-directory-regression.patch
    (git-fixes CVE-2024-26935 bsc#1223675).
  - Update
    patches.suse/scsi-lpfc-Fix-possible-memory-leak-in-lpfc_rcv_padis.patch
    (bsc#1220021 CVE-2024-35930 bsc#1224651).
  - Update patches.suse/scsi-sg-Avoid-sg-device-teardown-race.patch
    (git-fixes CVE-2024-35954 bsc#1224675).
  - Update
    patches.suse/scsi-smartpqi-Fix-disable_managed_interrupts.patch
    (git-fixes CVE-2024-26742 bsc#1222608).
  - Update
    patches.suse/selinux-avoid-dereference-of-garbage-after-mount-fai.patch
    (git-fixes CVE-2024-35904 bsc#1224494).
  - Update
    patches.suse/serial-mxs-auart-add-spinlock-around-changing-cts-st.patch
    (git-fixes CVE-2024-27000 bsc#1223757).
  - Update
    patches.suse/serial-pmac_zilog-Remove-flawed-mitigation-for-rx-ir.patch
    (git-fixes CVE-2024-26999 bsc#1223754).
  - Update
    patches.suse/soc-fsl-qbman-Always-disable-interrupts-when-taking-.patch
    (git-fixes CVE-2024-35806 bsc#1224699).
  - Update
    patches.suse/soc-fsl-qbman-Use-raw-spinlock-for-cgr_lock.patch
    (git-fixes CVE-2024-35819 bsc#1224683).
  - Update patches.suse/speakup-Avoid-crash-on-very-long-word.patch
    (git-fixes CVE-2024-26994 bsc#1223750).
  - Update
    patches.suse/spi-lpspi-Avoid-potential-use-after-free-in-probe.patch
    (git-fixes CVE-2024-26866 bsc#1223024).
  - Update
    patches.suse/spi-mchp-pci1xxx-Fix-a-possible-null-pointer-derefer.patch
    (git-fixes CVE-2024-35883 bsc#1224521).
  - Update
    patches.suse/spi-spi-mt65xx-Fix-NULL-pointer-access-in-interrupt-.patch
    (git-fixes CVE-2024-27028 bsc#1223788).
  - Update
    patches.suse/ubifs-Set-page-uptodate-in-the-correct-place.patch
    (git-fixes CVE-2024-35821 bsc#1224629).
  - Update
    patches.suse/usb-cdc-wdm-close-race-between-read-and-workqueue.patch
    (git-fixes CVE-2024-35812 bsc#1224624).
  - Update
    patches.suse/usb-dwc2-host-Fix-dereference-issue-in-DDMA-completi.patch
    (git-fixes CVE-2024-26997 bsc#1223741).
  - Update
    patches.suse/usb-dwc3-am62-fix-module-unload-reload-behavior.patch
    (git-fixes CVE-2024-26963 bsc#1223651).
  - Update
    patches.suse/usb-gadget-f_ncm-Fix-UAF-ncm-object-at-re-bind-after.patch
    (stable-fixes CVE-2024-26996 bsc#1223752).
  - Update
    patches.suse/usb-gadget-ncm-Avoid-dropping-datagrams-of-properly-.patch
    (git-fixes CVE-2024-27405 bsc#1224423).
  - Update
    patches.suse/usb-gadget-ncm-Fix-handling-of-zero-block-length-pac.patch
    (git-fixes CVE-2024-35825 bsc#1224681).
  - Update
    patches.suse/usb-typec-altmodes-displayport-create-sysfs-nodes-as.patch
    (git-fixes CVE-2024-35790 bsc#1224712).
  - Update
    patches.suse/usb-typec-tcpm-Correct-the-PDO-counting-in-pd_set.patch
    (git-fixes CVE-2024-26995 bsc#1223696).
  - Update
    patches.suse/usb-typec-tcpm-fix-double-free-issue-in-tcpm_port_un.patch
    (git-fixes CVE-2024-26932 bsc#1223649).
  - Update patches.suse/usb-typec-ucsi-Limit-read-size-on-v1.2.patch
    (stable-fixes CVE-2024-35924 bsc#1224657).
  - Update
    patches.suse/usb-udc-remove-warning-when-queue-disabled-ep.patch
    (stable-fixes CVE-2024-35822 bsc#1224739).
  - Update
    patches.suse/usb-xhci-Add-error-handling-in-xhci_map_urb_for_dma.patch
    (git-fixes CVE-2024-26964 bsc#1223650).
  - Update
    patches.suse/vt-fix-unicode-buffer-corruption-when-deleting-chara.patch
    (git-fixes CVE-2024-35823 bsc#1224692).
  - Update
    patches.suse/wifi-ath11k-decrease-MHI-channel-buffer-length-to-8K.patch
    (bsc#1207948 CVE-2024-35938 bsc#1224643).
  - Update
    patches.suse/wifi-brcmfmac-Fix-use-after-free-bug-in-brcmf_cfg802.patch
    (CVE-2023-47233 bsc#1216702 CVE-2024-35811 bsc#1224592).
  - Update
    patches.suse/wifi-cfg80211-check-A-MSDU-format-more-carefully.patch
    (stable-fixes CVE-2024-35937 bsc#1224526).
  - Update
    patches.suse/wifi-iwlwifi-dbg-tlv-ensure-NUL-termination.patch
    (git-fixes CVE-2024-35845 bsc#1224731).
  - Update
    patches.suse/wifi-iwlwifi-mvm-don-t-set-the-MFP-flag-for-the-GTK.patch
    (git-fixes CVE-2024-27434 bsc#1224710).
  - Update
    patches.suse/wifi-iwlwifi-mvm-rfi-fix-potential-response-leaks.patch
    (git-fixes CVE-2024-35912 bsc#1224487).
  - Update
    patches.suse/wifi-libertas-fix-some-memleaks-in-lbs_allocate_cmd_.patch
    (git-fixes CVE-2024-35828 bsc#1224622).
  - Update
    patches.suse/wifi-mac80211-check-clear-fast-rx-for-non-4addr-sta-.patch
    (stable-fixes CVE-2024-35789 bsc#1224749).
  - Update
    patches.suse/wifi-mac80211-fix-potential-sta-link-leak.patch
    (git-fixes CVE-2024-35838 bsc#1224613).
  - Update
    patches.suse/wifi-nl80211-reject-iftype-change-with-mesh-ID-chang.patch
    (git-fixes CVE-2024-27410 bsc#1224432).
  - Update
    patches.suse/wifi-rtw89-fix-null-pointer-access-when-abort-scan.patch
    (stable-fixes CVE-2024-35946 bsc#1224646).
  - Update
    patches.suse/wireguard-netlink-access-device-through-ctx-instead-.patch
    (git-fixes CVE-2024-26950 bsc#1223661).
  - Update
    patches.suse/wireguard-netlink-check-for-dangling-peer-via-is_dea.patch
    (git-fixes CVE-2024-26951 bsc#1223660).
  - Update
    patches.suse/wireguard-receive-annotate-data-race-around-receivin.patch
    (git-fixes CVE-2024-26861 bsc#1223076).
  - Update
    patches.suse/x86-coco-Require-seeding-RNG-with-RDRAND-on-CoCo-systems.patch
    (git-fixes CVE-2024-35875 bsc#1224665).
  - Update
    patches.suse/x86-fpu-Keep-xfd_state-in-sync-with-MSR_IA32_XFD.patch
    (git-fixes CVE-2024-35801 bsc#1224732).
  - Update
    patches.suse/xen-evtchn-avoid-WARN-when-unbinding-an-event-channe.patch
    (git-fixes CVE-2024-27067 bsc#1223739).
  - Update
    patches.suse/xsk-recycle-buffer-in-case-Rx-queue-was-full.patch
    (bsc#1221303 CVE-2024-26611 CVE-2024-35834 bsc#1224620).
  - commit 005afc6
  - Update
    patches.suse/ACPI-LPIT-Avoid-u32-multiplication-overflow.patch
    (git-fixes CVE-2023-52683 bsc#1224627).
  - Update
    patches.suse/ACPI-video-check-for-error-while-searching-for-backl.patch
    (git-fixes CVE-2023-52693 bsc#1224686).
  - Update
    patches.suse/ASoC-Intel-sof_sdw_rt_sdca_jack_common-ctx-headset_c.patch
    (git-fixes CVE-2023-52697 bsc#1224596).
  - Update
    patches.suse/ASoC-SOF-amd-Fix-memory-leak-in-amd_sof_acp_probe.patch
    (git-fixes CVE-2023-52663 bsc#1224630).
  - Update
    patches.suse/Revert-drm-amd-pm-resolve-reboot-exception-for-si-ol.patch
    (git-fixes CVE-2023-52657 bsc#1224722).
  - Update
    patches.suse/Revert-net-mlx5-Block-entering-switchdev-mode-with-n.patch
    (git-fixes CVE-2023-52658 bsc#1224719).
  - Update
    patches.suse/SUNRPC-fix-a-memleak-in-gss_import_v2_context.patch
    (git-fixes CVE-2023-52653 bsc#1223712).
  - Update
    patches.suse/bpf-Guard-stack-limits-against-32bit-overflow.patch
    (git-fixes CVE-2023-52676 bsc#1224730).
  - Update
    patches.suse/crypto-rsa-add-a-check-for-allocation-failure.patch
    (bsc#1222775 CVE-2023-52472 bsc#1220430).
  - Update
    patches.suse/crypto-s390-aes-Fix-buffer-overread-in-CTR-mode.patch
    (git-fixes CVE-2023-52669 bsc#1224637).
  - Update
    patches.suse/crypto-safexcel-Add-error-handling-for-dma_map_sg-ca.patch
    (git-fixes CVE-2023-52687 bsc#1224501).
  - Update
    patches.suse/drm-amd-display-Check-writeback-connectors-in-create.patch
    (git-fixes CVE-2023-52695 bsc#1224506).
  - Update
    patches.suse/drm-amd-display-Fix-a-debugfs-null-pointer-error.patch
    (git-fixes CVE-2023-52673 bsc#1224741).
  - Update
    patches.suse/drm-amd-display-Fix-hang-underflow-when-transitionin.patch
    (git-fixes CVE-2023-52671 bsc#1224729).
  - Update
    patches.suse/drm-amd-pm-fix-a-double-free-in-si_dpm_init.patch
    (git-fixes CVE-2023-52691 bsc#1224607).
  - Update
    patches.suse/drm-amdkfd-Confirm-list-is-non-empty-before-utilizin.patch
    (git-fixes CVE-2023-52678 bsc#1224617).
  - Update
    patches.suse/drm-bridge-tpd12s015-Drop-buggy-__exit-annotation-fo.patch
    (git-fixes CVE-2023-52694 bsc#1224598).
  - Update
    patches.suse/drm-tegra-rgb-Fix-missing-clk_put-in-the-error-handl.patch
    (git-fixes CVE-2023-52661 bsc#1224445).
  - Update
    patches.suse/drm-vmwgfx-fix-a-memleak-in-vmw_gmrid_man_get_node.patch
    (git-fixes CVE-2023-52662 bsc#1224449).
  - Update patches.suse/efivarfs-Free-s_fs_info-on-unmount.patch
    (bsc#1220328 CVE-2023-52463 CVE-2023-52681 bsc#1224505).
  - Update
    patches.suse/media-rkisp1-Fix-IRQ-handling-due-to-shared-interrup.patch
    (stable-fixes CVE-2023-52660 bsc#1224443).
  - Update
    patches.suse/net-atlantic-eliminate-double-free-in-error-handling.patch
    (git-fixes CVE-2023-52664 bsc#1224747).
  - Update
    patches.suse/net-mlx5e-fix-a-potential-double-free-in-fs_any_crea.patch
    (jsc#PED-3311 CVE-2023-52667 bsc#1224603).
  - Update
    patches.suse/of-Fix-double-free-in-of_parse_phandle_with_args_map.patch
    (git-fixes CVE-2023-52679 bsc#1224508).
  - Update
    patches.suse/powerpc-imc-pmu-Add-a-null-pointer-check-in-update_events_in_group.patch
    (git-fixes CVE-2023-52675 bsc#1224504).
  - Update
    patches.suse/powerpc-powernv-Add-a-null-pointer-check-in-opal_eve.patch
    (bsc#1065729 CVE-2023-52686 bsc#1224682).
  - Update
    patches.suse/powerpc-powernv-Add-a-null-pointer-check-in-opal_pow.patch
    (bsc#1181674 ltc#189159 git-fixes CVE-2023-52696 bsc#1224601).
  - Update
    patches.suse/powerpc-powernv-Add-a-null-pointer-check-to-scom_deb.patch
    (bsc#1194869 CVE-2023-52690 bsc#1224611).
  - Update
    patches.suse/pstore-ram_core-fix-possible-overflow-in-persistent_.patch
    (git-fixes CVE-2023-52685 bsc#1224728).
  - Update
    patches.suse/rpmsg-virtio-Free-driver_override-when-rpmsg_remove.patch
    (git-fixes CVE-2023-52670 bsc#1224696).
  - commit 578211b
  - vhost: Add smp_rmb() in vhost_enable_notify() (git-fixes).
  - commit 2e20e2c
  - vhost: Add smp_rmb() in vhost_vq_avail_empty() (git-fixes).
  - commit 936d53e
  - virtio_net: Do not send RSS key if it is not supported
    (git-fixes).
  - commit cc7c4a0
  - vsock/virtio: fix packet delivery to tap device (git-fixes).
  - commit dfd8673
  - virtio-blk: Ensure no requests in virtqueues before deleting
    vqs (git-fixes).
  - commit 966a23e
  - KVM: VMX: Disable LBR virtualization if the CPU doesn't support
    LBR callstacks (git-fixes).
  - commit f941b05
  - efi/unaccepted: do not let /proc/vmcore try to access unaccepted memory (git-fixes).
  - commit c99f198
  - proc/kcore: do not try to access unaccepted memory (git-fixes).
  - commit 2daf00c
  - efi/unaccepted: touch soft lockup during memory accept (git-fixes).
  - commit 45ed7cb
  - x86/mm: Ensure input to pfn_to_kaddr() is treated as a 64-bit type (bsc#1224442 CVE-2023-52659).
  - commit dad72fd
  - kabi fix of perf/x86/intel: Expose existence of callback support to KVM
    (git fixes).
  - commit 5db441c
  - perf/x86/intel: Expose existence of callback support to KVM
    (git-fixes).
  - commit b24b5fc
  - kABI fix of KVM: x86: Snapshot if a vCPU's vendor model is AMD vs.
    Intel compatible (git-fixes).
  - commit 38bcaaa
  - ceph: redirty page before returning AOP_WRITEPAGE_ACTIVATE
    (bsc#1224866).
  - commit 6a4b4a1
  - supported.conf: Add APM X-Gene SoC hardware monitoring driver (bsc#1223265 jsc#PED-8570)
  - commit 4b0eeb3
  - remoteproc: k3-r5: Jump to error handling labels in start/stop
    errors (git-fixes).
  - commit 6f545f8
  - libsubcmd: Fix parse-options memory leak (git-fixes).
  - dmaengine: idxd: Avoid unnecessary destruction of file_ida
    (git-fixes).
  - dmaengine: axi-dmac: fix possible race in remove() (git-fixes).
  - dmaengine: idma64: Add check for dma_set_max_seg_size
    (git-fixes).
  - remoteproc: k3-r5: Do not allow core1 to power up before core0
    via sysfs (git-fixes).
  - remoteproc: k3-r5: Wait for core0 power-up before powering up
    core1 (git-fixes).
  - remoteproc: mediatek: Make sure IPI buffer fits in L2TCM
    (git-fixes).
  - PCI: tegra194: Fix probe path for Endpoint mode (git-fixes).
  - PCI: rockchip-ep: Remove wrong mask on subsys_vendor_id
    (git-fixes).
  - PCI: dwc: ep: Fix DBI access failure for drivers requiring
    refclk from host (git-fixes).
  - PCI/EDR: Align EDR_PORT_LOCATE_DSM with PCI Firmware r3.3
    (git-fixes).
  - PCI/EDR: Align EDR_PORT_DPC_ENABLE_DSM with PCI Firmware r3.3
    (git-fixes).
  - KEYS: trusted: Do not use WARN when encode fails (git-fixes).
  - KEYS: trusted: Fix memory leak in tpm2_key_encode() (git-fixes).
  - commit d7da373

++++ libarchive:

  - Fix bsdunzip test failing due to a locale issue
    * fix-bsdunzip-test.patch

++++ snapper:

  - fixed error message (gh#openSUSE/snapper#907)

++++ systemd:

  - systemd.spec: introduce %{meson_extra_configure_options} to allow passing
    extra meson configure options.

++++ python-requests:

  - Update to 2.32.2
    * To provide a more stable migration for custom HTTPAdapters impacted by the CVE changes in 2.32.0,
    we've renamed _get_connection to a new public API, get_connection_with_tls_context. Existing
    custom HTTPAdapters will need to migrate their code to use this new API. get_connection is
    considered deprecated in all versions of Requests>=2.32.0.

++++ suse-module-tools:

  - Update to version 16.0.44:
    * Include unblacklist in initramfs (bsc#1224320)
    * regenerate-initrd-posttrans: run update-bootloader --refresh for XEN
    (bsc#1223278)

------------------------------------------------------------------
------------------  2024-5-21  -  May 21 2024  -------------------
------------------------------------------------------------------

++++ lvm2-device-mapper:

  - Use %patch -P N instead of deprecated %patchN syntax.

++++ elfutils:

  - Add "-g" to %optflags, so that the tests work in all repos,
    with or without globally enabled debuginfo creation.

++++ gettext-runtime:

  - Require glibc-gconv-modules-extra by the gettext-tools packages

++++ fwupd:

  - Update to version 1.9.20:
    + This release adds the following features:
  - Add some API to allow uploading reports for use in
    gnome-firmware
  - Allow the user to upload the entire devicelist to the LVFS
    + This release fixes the following bugs:
  - Correctly detect Synaptics Cayenne and Spyder firmware
  - Do not offer the UEFI DBX update on Lenovo ideacentre
    300-20ISH
  - Explicitly enable shadow stack support in fwupd.service
  - Fix a potential buffer overread when reading the algoltek-usb
    version number
  - Fix the CET HSI test by rewriting it in assembly
  - Fix using --verbose in fwupdmgr
  - Ignore --p2p when downloading the metadata signature
    + This release adds support for the following hardware:
  - FPC FF2 fingerprint devices

++++ glibc:

  - Move essential (Latin-1 and UTF based) gconv modules to main glibc
    package, other modules to new package glibc-gconv-modules-extra

++++ kernel-default:

  - KVM: x86: Only set APICV_INHIBIT_REASON_ABSENT if APICv is
    enabled (git-fixes).
  - commit 7d13726
  - KVM: x86: Allow, don't ignore, same-value writes to immutable
    MSRs (git-fixes).
  - commit e25e965
  - KVM: nVMX: Clear EXIT_QUALIFICATION when injecting an EPT
    Misconfig (git-fixes).
  - commit 21a74db
  - KVM: x86/mmu: Don't force emulation of L2 accesses to non-APIC
    internal slots (git-fixes).
  - commit b2d6429
  - KVM: x86/mmu: Move private vs. shared check above slot validity
    checks (git-fixes).
  - commit 2108d3a
  - KVM: x86: Fully re-initialize supported_mce_cap on vendor
    module load (git-fixes).
  - commit 52160e6
  - KVM: x86/mmu: Write-protect L2 SPTEs in TDP MMU when clearing
    dirty status (git-fixes).
  - commit 7bdd69f
  - drm/nouveau/disp: Fix missing backlight control on Macbook 5,
    1 (bsc#1223838).
  - commit 07ffc12
  - iommu/dma: Force swiotlb_max_mapping_size on an untrusted device (bsc#1224331)
  - commit 55fb87b
  - swiotlb: Fix alignment checks when both allocation and DMA masks are (bsc#1224331)
  - commit 8bebd77
  - swiotlb: Honour dma_alloc_coherent() alignment in swiotlb_alloc() (bsc#1224331)
  - commit fcf796a
  - swiotlb: Fix double-allocation of slots due to broken alignment (bsc#1224331)
  - commit c65bb03
  - KVM: x86/pmu: Set enable bits for GP counters in
    PERF_GLOBAL_CTRL at "RESET" (git-fixes).
  - commit 1ba62ae
  - KVM: x86/pmu: Disable support for adaptive PEBS (git-fixes).
  - commit 9862bdd
  - KVM: x86/pmu: Do not mask LVTPC when handling a PMI on AMD
    platforms (git-fixes).
  - commit 5f8077d
  - KVM: x86: Snapshot if a vCPU's vendor model is AMD vs. Intel
    compatible (git-fixes).
  - commit c9c8902
  - x86/kvm/Kconfig: Have KVM_AMD_SEV select ARCH_HAS_CC_PLATFORM
    (git-fixes).
  - commit f882a8e
  - KVM: x86: Use actual kvm_cpuid.base for clearing
    KVM_FEATURE_PV_UNHALT (git-fixes).
  - commit 80b67d0
  - s390/cio: fix tracepoint subchannel type field (git-fixes
    bsc#1224793).
  - commit f1aa928
  - s390/bpf: Emit a barrier for BPF_FETCH instructions (git-fixes
    bsc#1224792).
  - commit d08e4ce
  - KVM: s390: Check kvm pointer when testing KVM_CAP_S390_HPAGE_1M
    (git-fixes bsc#1224790).
  - commit b0b1c22
  - KVM: x86: Introduce __kvm_get_hypervisor_cpuid() helper
    (git-fixes).
  - commit 652c188
  - rpm/kernel-obs-build.spec.in: remove reiserfs from OBS initrd
    We disabled the FS in bug 1202309. And we actively blacklist it in:
    /usr/lib/modprobe.d/60-blacklist_fs-reiserfs.conf
    This, as a side-effect, fixes obs-build's warning:
    dracut-pre-udev[1463]: sh: line 1: /usr/lib/module-init-tools/unblacklist: No such file or directory
    Exactly due to the above 60-blacklist_fs-reiserfs.conf trying to call the
    above unblacklist.
    We should likely drop ext2+ext3 from the list too, as we don't build
    them at all. But that's a different story.
  - commit 9e1a078
  - KVM: SVM: Add support for allowing zero SEV ASIDs (git-fixes).
  - commit 9327154
  - KVM: SVM: Use unsigned integers when dealing with ASIDs
    (git-fixes).
  - commit b0fec37
  - tools/power turbostat: Expand probe_intel_uncore_frequency()
    (bsc#1221765).
  - commit 7c0d70f
  - KVM: x86/xen: fix recursive deadlock in timer injection
    (git-fixes).
  - commit 389ea84
  - KVM: x86/xen: remove WARN_ON_ONCE() with false positives in
    evtchn delivery (git-fixes).
  - commit d63a8c9
  - KVM: x86/xen: inject vCPU upcall vector when local APIC is
    enabled (git-fixes).
  - commit 538dcab
  - KVM: x86/xen: improve accuracy of Xen timers (git-fixes).
  - commit 921d76d
  - KVM: x86/pmu: Explicitly check NMI from guest to reducee false
    positives (git-fixes).
  - commit be2edf0
  - KVM: x86/pmu: Zero out PMU metadata on AMD if PMU is disabled
    (git-fixes).
  - commit fe18eef
  - KVM: x86/pmu: Disallow "fast" RDPMC for architectural Intel PMUs
    (git-fixes).
  - commit 406de6b
  - KVM: x86/pmu: Apply "fast" RDPMC only to Intel PMUs (git-fixes).
  - commit dd1520f
  - KVM: x86/pmu: Prioritize VMX interception over #GP on RDPMC
    due to bad index (git-fixes).
  - commit b2e9cf1
  - KVM: x86/pmu: Don't ignore bits 31:30 for RDPMC index on AMD
    (git-fixes).
  - commit fd656b7
  - KVM: x86/pmu: Allow programming events that match unsupported
    arch events (git-fixes).
  - commit 60f57dc
  - firmware: dmi-id: add a release callback function (git-fixes).
  - watchdog: sa1100: Fix PTR_ERR_OR_ZERO() vs NULL check in
    sa1100dog_probe() (git-fixes).
  - watchdog: rti_wdt: Set min_hw_heartbeat_ms to accommodate a
    safety margin (git-fixes).
  - watchdog: bd9576: Drop "always-running" property (git-fixes).
  - watchdog: cpu5wdt.c: Fix use-after-free bug caused by
    cpu5wdt_trigger (git-fixes).
  - i2c: acpi: Unbind mux adapters before delete (git-fixes).
  - i2c: synquacer: Fix an error handling path in
    synquacer_i2c_probe() (git-fixes).
  - i2c: cadence: Avoid fifo clear after start (git-fixes).
  - pinctrl: qcom: pinctrl-sm7150: Fix sdc1 and ufs special pins
    regs (git-fixes).
  - pinctrl: armada-37xx: remove an unused variable (git-fixes).
  - crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak (git-fixes).
  - commit 60d82a4
  - KVM: x86/pmu: Always treat Fixed counters as available when
    supported (git-fixes).
  - commit c4b0d18
  - KVM: VMX: Report up-to-date exit qualification to userspace
    (git-fixes).
  - commit d6b020d
  - KVM: x86: Fix broken debugregs ABI for 32 bit kernels
    (git-fixes).
  - commit 69a1ee8
  - SEV: disable SEV-ES DebugSwap by default (git-fixes).
  - commit dcaff2f
  - KVM: x86/mmu: Restrict KVM_SW_PROTECTED_VM to the TDP MMU
    (git-fixes).
  - commit c561279
  - KVM: x86: Update KVM_SW_PROTECTED_VM docs to make it clear
    they're a WIP (git-fixes).
  - commit aba16e8
  - KVM: x86: Mark target gfn of emulated atomic instruction as
    dirty (git-fixes).
  - commit 303882a
  - KVM: SVM: Flush pages under kvm->lock to fix UAF in
    svm_register_enc_region() (git-fixes).
  - commit 4382f8a

++++ kernel-firmware-all:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-amdgpu:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-ath10k:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-ath11k:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-ath12k:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-atheros:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-bluetooth:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-bnx2:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-brcm:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-chelsio:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-dpaa2:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-i915:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-intel:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-iwlwifi:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-liquidio:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-marvell:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-media:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-mediatek:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-mellanox:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-mwifiex:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-network:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-nfp:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-nvidia:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-platform:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-prestera:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-qcom:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-qlogic:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-radeon:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-realtek:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-serial:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-sound:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-ti:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-ueagle:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-firmware-usb-network:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

++++ kernel-rt:

  - KVM: x86: Only set APICV_INHIBIT_REASON_ABSENT if APICv is
    enabled (git-fixes).
  - commit 7d13726
  - KVM: x86: Allow, don't ignore, same-value writes to immutable
    MSRs (git-fixes).
  - commit e25e965
  - KVM: nVMX: Clear EXIT_QUALIFICATION when injecting an EPT
    Misconfig (git-fixes).
  - commit 21a74db
  - KVM: x86/mmu: Don't force emulation of L2 accesses to non-APIC
    internal slots (git-fixes).
  - commit b2d6429
  - KVM: x86/mmu: Move private vs. shared check above slot validity
    checks (git-fixes).
  - commit 2108d3a
  - KVM: x86: Fully re-initialize supported_mce_cap on vendor
    module load (git-fixes).
  - commit 52160e6
  - KVM: x86/mmu: Write-protect L2 SPTEs in TDP MMU when clearing
    dirty status (git-fixes).
  - commit 7bdd69f
  - drm/nouveau/disp: Fix missing backlight control on Macbook 5,
    1 (bsc#1223838).
  - commit 07ffc12
  - iommu/dma: Force swiotlb_max_mapping_size on an untrusted device (bsc#1224331)
  - commit 55fb87b
  - swiotlb: Fix alignment checks when both allocation and DMA masks are (bsc#1224331)
  - commit 8bebd77
  - swiotlb: Honour dma_alloc_coherent() alignment in swiotlb_alloc() (bsc#1224331)
  - commit fcf796a
  - swiotlb: Fix double-allocation of slots due to broken alignment (bsc#1224331)
  - commit c65bb03
  - KVM: x86/pmu: Set enable bits for GP counters in
    PERF_GLOBAL_CTRL at "RESET" (git-fixes).
  - commit 1ba62ae
  - KVM: x86/pmu: Disable support for adaptive PEBS (git-fixes).
  - commit 9862bdd
  - KVM: x86/pmu: Do not mask LVTPC when handling a PMI on AMD
    platforms (git-fixes).
  - commit 5f8077d
  - KVM: x86: Snapshot if a vCPU's vendor model is AMD vs. Intel
    compatible (git-fixes).
  - commit c9c8902
  - x86/kvm/Kconfig: Have KVM_AMD_SEV select ARCH_HAS_CC_PLATFORM
    (git-fixes).
  - commit f882a8e
  - KVM: x86: Use actual kvm_cpuid.base for clearing
    KVM_FEATURE_PV_UNHALT (git-fixes).
  - commit 80b67d0
  - s390/cio: fix tracepoint subchannel type field (git-fixes
    bsc#1224793).
  - commit f1aa928
  - s390/bpf: Emit a barrier for BPF_FETCH instructions (git-fixes
    bsc#1224792).
  - commit d08e4ce
  - KVM: s390: Check kvm pointer when testing KVM_CAP_S390_HPAGE_1M
    (git-fixes bsc#1224790).
  - commit b0b1c22
  - KVM: x86: Introduce __kvm_get_hypervisor_cpuid() helper
    (git-fixes).
  - commit 652c188
  - rpm/kernel-obs-build.spec.in: remove reiserfs from OBS initrd
    We disabled the FS in bug 1202309. And we actively blacklist it in:
    /usr/lib/modprobe.d/60-blacklist_fs-reiserfs.conf
    This, as a side-effect, fixes obs-build's warning:
    dracut-pre-udev[1463]: sh: line 1: /usr/lib/module-init-tools/unblacklist: No such file or directory
    Exactly due to the above 60-blacklist_fs-reiserfs.conf trying to call the
    above unblacklist.
    We should likely drop ext2+ext3 from the list too, as we don't build
    them at all. But that's a different story.
  - commit 9e1a078
  - KVM: SVM: Add support for allowing zero SEV ASIDs (git-fixes).
  - commit 9327154
  - KVM: SVM: Use unsigned integers when dealing with ASIDs
    (git-fixes).
  - commit b0fec37
  - tools/power turbostat: Expand probe_intel_uncore_frequency()
    (bsc#1221765).
  - commit 7c0d70f
  - KVM: x86/xen: fix recursive deadlock in timer injection
    (git-fixes).
  - commit 389ea84
  - KVM: x86/xen: remove WARN_ON_ONCE() with false positives in
    evtchn delivery (git-fixes).
  - commit d63a8c9
  - KVM: x86/xen: inject vCPU upcall vector when local APIC is
    enabled (git-fixes).
  - commit 538dcab
  - KVM: x86/xen: improve accuracy of Xen timers (git-fixes).
  - commit 921d76d
  - KVM: x86/pmu: Explicitly check NMI from guest to reducee false
    positives (git-fixes).
  - commit be2edf0
  - KVM: x86/pmu: Zero out PMU metadata on AMD if PMU is disabled
    (git-fixes).
  - commit fe18eef
  - KVM: x86/pmu: Disallow "fast" RDPMC for architectural Intel PMUs
    (git-fixes).
  - commit 406de6b
  - KVM: x86/pmu: Apply "fast" RDPMC only to Intel PMUs (git-fixes).
  - commit dd1520f
  - KVM: x86/pmu: Prioritize VMX interception over #GP on RDPMC
    due to bad index (git-fixes).
  - commit b2e9cf1
  - KVM: x86/pmu: Don't ignore bits 31:30 for RDPMC index on AMD
    (git-fixes).
  - commit fd656b7
  - KVM: x86/pmu: Allow programming events that match unsupported
    arch events (git-fixes).
  - commit 60f57dc
  - firmware: dmi-id: add a release callback function (git-fixes).
  - watchdog: sa1100: Fix PTR_ERR_OR_ZERO() vs NULL check in
    sa1100dog_probe() (git-fixes).
  - watchdog: rti_wdt: Set min_hw_heartbeat_ms to accommodate a
    safety margin (git-fixes).
  - watchdog: bd9576: Drop "always-running" property (git-fixes).
  - watchdog: cpu5wdt.c: Fix use-after-free bug caused by
    cpu5wdt_trigger (git-fixes).
  - i2c: acpi: Unbind mux adapters before delete (git-fixes).
  - i2c: synquacer: Fix an error handling path in
    synquacer_i2c_probe() (git-fixes).
  - i2c: cadence: Avoid fifo clear after start (git-fixes).
  - pinctrl: qcom: pinctrl-sm7150: Fix sdc1 and ufs special pins
    regs (git-fixes).
  - pinctrl: armada-37xx: remove an unused variable (git-fixes).
  - crypto: qat - Fix ADF_DEV_RESET_SYNC memory leak (git-fixes).
  - commit 60d82a4
  - KVM: x86/pmu: Always treat Fixed counters as available when
    supported (git-fixes).
  - commit c4b0d18
  - KVM: VMX: Report up-to-date exit qualification to userspace
    (git-fixes).
  - commit d6b020d
  - KVM: x86: Fix broken debugregs ABI for 32 bit kernels
    (git-fixes).
  - commit 69a1ee8
  - SEV: disable SEV-ES DebugSwap by default (git-fixes).
  - commit dcaff2f
  - KVM: x86/mmu: Restrict KVM_SW_PROTECTED_VM to the TDP MMU
    (git-fixes).
  - commit c561279
  - KVM: x86: Update KVM_SW_PROTECTED_VM docs to make it clear
    they're a WIP (git-fixes).
  - commit aba16e8
  - KVM: x86: Mark target gfn of emulated atomic instruction as
    dirty (git-fixes).
  - commit 303882a
  - KVM: SVM: Flush pages under kvm->lock to fix UAF in
    svm_register_enc_region() (git-fixes).
  - commit 4382f8a

++++ llvm19:

  - Update to version 18.1.6.
    * Fixes issues where LLVM is either generating the incorrect thunk
    for a function with aligned parameters or didn't correctly pass
    through the return value when StructRet was used.
    * `-Xclang -target-feature -Xclang +unaligned-scalar-mem` can be
    used to enable unaligned scalar memory accesses for CPUs that
    do not support unaligned vector accesses. `-mno-strict-align`
    will enable unaligned scalar and vector memory accesses.
    * Don't replace an aliasee with an alias that has weak linkage.
    This avoids incorrect linkage that can lead to using the wrong
    symbols during linking time.
    * Fixes build failures when compiling AVX512 code using
    `-march=native` on machines without AVX512. The problem was
    introduced in LLVM 18.1.5.
    * Fixes crash in AArch64 backend when having `true` or `false` as
    operand for `fcmp` instruction on IR level.
    * Fixes compiler crash when user specifies `-mno-evex512` with
    AVX512 features but no AVX512VL.
    * Fixes a bug that tries to do VBROADCAST_LOAD for `f16` without
    AVX2.
  - Rebase llvm-do-not-install-static-libraries.patch.

++++ libbpf:

  - Fix null pointer dereference in bpf_object__collect_prog_relos()
    (bsc#1221101)
    * Add libbpf-Fix-NULL-pointer-dereference-in-bpf_object__c.patch

++++ lvm2:

  - Use %patch -P N instead of deprecated %patchN syntax.

++++ libslirp:

  - Update to version 4.8.0+2:
    * Fix actually linking the library
    * Use simpler test linker script for detectiong --version-script option
    * Release v4.8.0
    * Explicit that -Dstatic=True is not meant for distributing a static library
    * icmp6: Add echo request forwarding support
    * fuzz: Fix icmp6 matching and checksum computation
    * fuzz: Drop debugging
    * fuzz: Drop debugging
    * fuzz: Add ARP and NDP cases
    * fuzz: Add IPv6 cases
    * mbuf: Do not reallocate when the requested size already fits exactly
    * mbuf: Fix copying headers
    * oss-fuzz: Fix udp-h and tcp-h corpuses
    * fuzz: comment coherency
    * fuzz: Simplify TCP checksum code
    * Note changes that can probably be security issues
    * Add changelog for next release
    * eth: pad ethernet frames to 60 bytes
    * udp: Make cleanup loop clearer
    * fuzz: Fix tftp fuzz actually receiving a file
    * tftp: cleanup sessions remaining at slirp shutdown
    * tftp: Fix use-after-free
    * Add fuzzing CI
    * fuzz: Add ip filtering
    * tcp: hack syn/ack
    * fuzzing: Increase coverage
    * First attempt at fuzzing with libFuzzer based on @elmarco work
    * Start some fuzzing test
    * tcp: Fix testing for last fragment
    * icmp: Fix msg duplication for debugging
    * tcp: Fix allocating room
    * mbuf: Be extra careful with freed pointer
    * mbuf: remove '#define if*' member accessors
    * m_cleanup_list: Fix missing cleanup packets from the same session
    * tcp-input: inline TCP_REASS
    * ip: remove second argument from ip_stripoptions()
    * Document endianness of slirp_add_hostfwd parameters

++++ permissions:

  - Update to version 1699_20240521:
    * permctl: return special exit code in --warn mode if entries need fixing

++++ python-requests:

  - Update to 2.32.1
    * Fixed an issue where setting verify=False on the first request from a Session
    will cause subsequent requests to the same origin to also ignore cert verification,
    regardless of the value of verify. (bsc#1224788, CVE-2024-35195)
    * verify=True now reuses a global SSLContext which should improve request time
    variance between first and subsequent requests.
    * Requests now supports optional use of character detection (chardet or charset_normalizer)
    when repackaged or vendored. This enables pip and other projects to minimize their
    vendoring surface area.
    * Requests has officially added support for CPython 3.12 and dropped support for CPython 3.7.
    * Starting in Requests 2.33.0, Requests will migrate to a PEP 517 build system using hatchling.

++++ ucode-amd:

  - Update to version 20240519 (git commit aae8224390e2):
    * amdgpu: add new ISP 4.1.1 firmware

------------------------------------------------------------------
------------------  2024-5-20  -  May 20 2024  -------------------
------------------------------------------------------------------

++++ curl:

  - Spin documentation off to libcurl-devel-doc, this saves buildroots
    495 files and time (mandb is run in %posttrans).

++++ grub2:

  - Only enable grub-protect for EFI systems
    * 0001-util-enable-grub-protect-only-for-EFI-systems.patch

++++ kernel-default:

  - sysv: don't call sb_bread() with pointers_lock held
    (bsc#1224659 CVE-2023-52699).
  - commit 6cad3fd
  - Update
    patches.suse/scsi-smartpqi-Fix-disable_managed_interrupts.patch
    (git-fixes bsc#1222608 CVE-2024-26742).
  - commit 950259c
  - btrfs: always clear PERTRANS metadata during commit (git-fixes)
  - commit f24386b
  - btrfs: record delayed inode root in transaction (git-fixes)
  - commit 3382370
  - btrfs: send: handle path ref underflow in header iterate_inode_ref() (git-fixes)
  - commit 21cfc26
  - btrfs: export: handle invalid inode or root reference in btrfs_get_parent() (git-fixes)
  - commit a357818
  - btrfs: fix kvcalloc() arguments order in btrfs_ioctl_send() (git-fixes)
  - commit 3227c75
  - btrfs: sysfs: validate scrub_speed_max value (git-fixes)
  - commit 333b480
  - btrfs: prevent transaction block reserve underflow when starting transaction (git-fixes)
  - commit e1ff84f
  - btrfs: fix race when refilling delayed refs block reserve (git-fixes)
  - commit f241886
  - btrfs: assert delayed node locked when removing delayed item (git-fixes)
  - commit 7298484
  - btrfs: check for BTRFS_FS_ERROR in pending ordered assert (git-fixes)
  - commit f5815af
  - btrfs: output extra debug info if we failed to find an inline backref (git-fixes)
  - commit 92fba41
  - btrfs: set page extent mapped after read_folio in relocate_one_page (git-fixes)
  - commit 446041f
  - btrfs: handle errors properly in update_inline_extent_backref() (git-fixes)
  - commit ca5b7a2
  - RDMA/cma: Fix kmemleak in rdma_core observed during blktests nvme/rdma use siw (git-fixes)
  - commit 4bdc550
  - RDMA/IPoIB: Fix format truncation compilation errors (git-fixes)
  - commit 6d737b0
  - bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq (git-fixes)
  - commit 3e0bec3
  - IB/mlx5: Use __iowrite64_copy() for write combining stores (git-fixes)
  - commit 9a3847d
  - RDMA/rxe: Fix incorrect rxe_put in error path (git-fixes)
  - commit c50f3b5
  - RDMA/rxe: Allow good work requests to be executed (git-fixes)
  - commit b36653a
  - RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt (git-fixes)
  - commit ba9e71d
  - RDMA/hns: Modify the print level of CQE error (git-fixes)
  - commit 12a2ba5
  - RDMA/hns: Use complete parentheses in macros (git-fixes)
  - commit 7a9c544
  - RDMA/hns: Fix GMV table pagesize (git-fixes)
  - commit fb0321b
  - RDMA/hns: Fix UAF for cq async event (git-fixes)
  - commit 8ea7fea
  - RDMA/hns: Fix deadlock on SRQ async events. (git-fixes)
  - commit fb64efc
  - RDMA/hns: Add max_ah and cq moderation capacities in query_device() (git-fixes)
  - commit 6c2f69b
  - RDMA/hns: Fix return value in hns_roce_map_mr_sg (git-fixes)
  - commit 60cadbc
  - RDMA/mlx5: Adding remote atomic access flag to updatable flags (git-fixes)
  - commit dacefcf
  - RDMA/mlx5: Change check for cacheable mkeys (git-fixes)
  - commit c838c29
  - RDMA/mlx5: Uncacheable mkey has neither rb_key or cache_ent (git-fixes)
  - commit 3012f2a
  - qibfs: fix dentry leak (git-fixes)
  - commit 3dd0249
  - RDMA/mlx5: Fix port number for counter query in multi-port configuration (git-fixes)
  - commit 52028fd
  - RDMA/cm: Print the old state when cm_destroy_id gets timeout (git-fixes)
  - commit 1a1a1ef
  - RDMA/rxe: Fix the problem "mutex_destroy missing" (git-fixes)
  - commit 0a73f85
  - arm64: dts: microchip: sparx5: fix mdio reg (git-fixes)
  - commit 88132f5
  - arm64: dts: hi3798cv200: fix the size of GICR (git-fixes)
  - commit 366d274
  - arm64: tegra: Correct Tegra132 I2C alias (git-fixes)
  - commit da1130e
  - arm64: dts: allwinner: h616: Fix I2C0 pins (git-fixes)
  - commit eee423c
  - arm64: dts: allwinner: Pine H64: correctly remove reg_gmac_3v3 (git-fixes)
  - commit 7d432cc
  - arm64: dts: rockchip: Add enable-strobe-pulldown to emmc phy on ROCK (git-fixes)
  - commit d52e38e
  - arm64: dts: rockchip: Add enable-strobe-pulldown to emmc phy on ROCK (git-fixes)
  - commit 029788f
  - arm64: dts: rockchip: fix alphabetical ordering RK3399 puma (git-fixes)
    Refresh patches.suse/arm64-dts-rockchip-enable-internal-pull-up-on-PCIE_WAKE-for-RK3399-Puma.patch
  - commit aeac8db
  - dt-bindings: clock: qcom: Add missing UFS QREF clocks (git-fixes)
  - commit 4e403e4
  - selftests/kcmp: remove unused open mode (git-fixes).
  - nilfs2: make superblock data array index computation sparse
    friendly (git-fixes).
  - Docs/admin-guide/mm/damon/usage: fix wrong example of DAMOS
    filter matching sysfs file (git-fixes).
  - lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure
    (git-fixes).
  - commit 7902091
  - powerpc/pseries/vio: Don't return ENODEV if node or compatible
    missing (bsc#1220783).
  - commit 19e446b

++++ kernel-rt:

  - sysv: don't call sb_bread() with pointers_lock held
    (bsc#1224659 CVE-2023-52699).
  - commit 6cad3fd
  - Update
    patches.suse/scsi-smartpqi-Fix-disable_managed_interrupts.patch
    (git-fixes bsc#1222608 CVE-2024-26742).
  - commit 950259c
  - btrfs: always clear PERTRANS metadata during commit (git-fixes)
  - commit f24386b
  - btrfs: record delayed inode root in transaction (git-fixes)
  - commit 3382370
  - btrfs: send: handle path ref underflow in header iterate_inode_ref() (git-fixes)
  - commit 21cfc26
  - btrfs: export: handle invalid inode or root reference in btrfs_get_parent() (git-fixes)
  - commit a357818
  - btrfs: fix kvcalloc() arguments order in btrfs_ioctl_send() (git-fixes)
  - commit 3227c75
  - btrfs: sysfs: validate scrub_speed_max value (git-fixes)
  - commit 333b480
  - btrfs: prevent transaction block reserve underflow when starting transaction (git-fixes)
  - commit e1ff84f
  - btrfs: fix race when refilling delayed refs block reserve (git-fixes)
  - commit f241886
  - btrfs: assert delayed node locked when removing delayed item (git-fixes)
  - commit 7298484
  - btrfs: check for BTRFS_FS_ERROR in pending ordered assert (git-fixes)
  - commit f5815af
  - btrfs: output extra debug info if we failed to find an inline backref (git-fixes)
  - commit 92fba41
  - btrfs: set page extent mapped after read_folio in relocate_one_page (git-fixes)
  - commit 446041f
  - btrfs: handle errors properly in update_inline_extent_backref() (git-fixes)
  - commit ca5b7a2
  - RDMA/cma: Fix kmemleak in rdma_core observed during blktests nvme/rdma use siw (git-fixes)
  - commit 4bdc550
  - RDMA/IPoIB: Fix format truncation compilation errors (git-fixes)
  - commit 6d737b0
  - bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq (git-fixes)
  - commit 3e0bec3
  - IB/mlx5: Use __iowrite64_copy() for write combining stores (git-fixes)
  - commit 9a3847d
  - RDMA/rxe: Fix incorrect rxe_put in error path (git-fixes)
  - commit c50f3b5
  - RDMA/rxe: Allow good work requests to be executed (git-fixes)
  - commit b36653a
  - RDMA/rxe: Fix seg fault in rxe_comp_queue_pkt (git-fixes)
  - commit ba9e71d
  - RDMA/hns: Modify the print level of CQE error (git-fixes)
  - commit 12a2ba5
  - RDMA/hns: Use complete parentheses in macros (git-fixes)
  - commit 7a9c544
  - RDMA/hns: Fix GMV table pagesize (git-fixes)
  - commit fb0321b
  - RDMA/hns: Fix UAF for cq async event (git-fixes)
  - commit 8ea7fea
  - RDMA/hns: Fix deadlock on SRQ async events. (git-fixes)
  - commit fb64efc
  - RDMA/hns: Add max_ah and cq moderation capacities in query_device() (git-fixes)
  - commit 6c2f69b
  - RDMA/hns: Fix return value in hns_roce_map_mr_sg (git-fixes)
  - commit 60cadbc
  - RDMA/mlx5: Adding remote atomic access flag to updatable flags (git-fixes)
  - commit dacefcf
  - RDMA/mlx5: Change check for cacheable mkeys (git-fixes)
  - commit c838c29
  - RDMA/mlx5: Uncacheable mkey has neither rb_key or cache_ent (git-fixes)
  - commit 3012f2a
  - qibfs: fix dentry leak (git-fixes)
  - commit 3dd0249
  - RDMA/mlx5: Fix port number for counter query in multi-port configuration (git-fixes)
  - commit 52028fd
  - RDMA/cm: Print the old state when cm_destroy_id gets timeout (git-fixes)
  - commit 1a1a1ef
  - RDMA/rxe: Fix the problem "mutex_destroy missing" (git-fixes)
  - commit 0a73f85
  - arm64: dts: microchip: sparx5: fix mdio reg (git-fixes)
  - commit 88132f5
  - arm64: dts: hi3798cv200: fix the size of GICR (git-fixes)
  - commit 366d274
  - arm64: tegra: Correct Tegra132 I2C alias (git-fixes)
  - commit da1130e
  - arm64: dts: allwinner: h616: Fix I2C0 pins (git-fixes)
  - commit eee423c
  - arm64: dts: allwinner: Pine H64: correctly remove reg_gmac_3v3 (git-fixes)
  - commit 7d432cc
  - arm64: dts: rockchip: Add enable-strobe-pulldown to emmc phy on ROCK (git-fixes)
  - commit d52e38e
  - arm64: dts: rockchip: Add enable-strobe-pulldown to emmc phy on ROCK (git-fixes)
  - commit 029788f
  - arm64: dts: rockchip: fix alphabetical ordering RK3399 puma (git-fixes)
    Refresh patches.suse/arm64-dts-rockchip-enable-internal-pull-up-on-PCIE_WAKE-for-RK3399-Puma.patch
  - commit aeac8db
  - dt-bindings: clock: qcom: Add missing UFS QREF clocks (git-fixes)
  - commit 4e403e4
  - selftests/kcmp: remove unused open mode (git-fixes).
  - nilfs2: make superblock data array index computation sparse
    friendly (git-fixes).
  - Docs/admin-guide/mm/damon/usage: fix wrong example of DAMOS
    filter matching sysfs file (git-fixes).
  - lib/test_hmm.c: handle src_pfns and dst_pfns allocation failure
    (git-fixes).
  - commit 7902091
  - powerpc/pseries/vio: Don't return ENODEV if node or compatible
    missing (bsc#1220783).
  - commit 19e446b

++++ libcap-ng:

  - Update to version 0.8.5:
    * Remove python global exception handler since it's deprecated
    * Make the utilities link against just built libraries
    * Remove unused macro in cap-ng.h
  - Remove libcap-ng.rpmlintrc, it doesn't seem to be used any more.

++++ openssl-3:

  - Security fix: [bsc#1224388, CVE-2024-4603]
    * Check DSA parameters for excessive sizes before validating
    * Add openssl-CVE-2024-4603.patch

++++ openSUSE-repos-LeapMicro:

  - Fix macro reference

++++ skopeo:

  - Update to version 1.15.1:
    * [release-1.15] Bump to v1.15.1
    * [release-1.15] Freeze the fedora-minimal image reference
    * [release-1.15] CVE-2024-3727 (bsc#1224123)

------------------------------------------------------------------
------------------  2024-5-19  -  May 19 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - clk: qcom: clk-alpha-pll: fix rate setting for Stromer PLLs
    (git-fixes).
  - clk: qcom: mmcc-msm8998: fix venus clock issue (git-fixes).
  - clk: qcom: dispcc-sm8550: fix DisplayPort clocks (git-fixes).
  - clk: qcom: dispcc-sm6350: fix DisplayPort clocks (git-fixes).
  - clk: qcom: dispcc-sm8450: fix DisplayPort clocks (git-fixes).
  - clk: qcom: clk-alpha-pll: remove invalid Stromer register offset
    (git-fixes).
  - clk: samsung: exynosautov9: fix wrong pll clock id value
    (git-fixes).
  - clk: renesas: r9a07g043: Add clock and reset entry for PLIC
    (git-fixes).
  - clk: renesas: r8a779a0: Fix CANFD parent clock (git-fixes).
  - clk: rs9: fix wrong default value for clock amplitude
    (git-fixes).
  - clk: mediatek: mt8365-mm: fix DPI0 parent (git-fixes).
  - clk: mediatek: pllfh: Don't log error for missing fhctl node
    (git-fixes).
  - commit 8bfa411

++++ kernel-rt:

  - clk: qcom: clk-alpha-pll: fix rate setting for Stromer PLLs
    (git-fixes).
  - clk: qcom: mmcc-msm8998: fix venus clock issue (git-fixes).
  - clk: qcom: dispcc-sm8550: fix DisplayPort clocks (git-fixes).
  - clk: qcom: dispcc-sm6350: fix DisplayPort clocks (git-fixes).
  - clk: qcom: dispcc-sm8450: fix DisplayPort clocks (git-fixes).
  - clk: qcom: clk-alpha-pll: remove invalid Stromer register offset
    (git-fixes).
  - clk: samsung: exynosautov9: fix wrong pll clock id value
    (git-fixes).
  - clk: renesas: r9a07g043: Add clock and reset entry for PLIC
    (git-fixes).
  - clk: renesas: r8a779a0: Fix CANFD parent clock (git-fixes).
  - clk: rs9: fix wrong default value for clock amplitude
    (git-fixes).
  - clk: mediatek: mt8365-mm: fix DPI0 parent (git-fixes).
  - clk: mediatek: pllfh: Don't log error for missing fhctl node
    (git-fixes).
  - commit 8bfa411

++++ shim:

  -- Update to version 15.8
  - Various CVE fixes are already merged into this version
    mok: fix LogError() invocation (bsc#1215099,CVE-2023-40546)
    avoid incorrectly trusting HTTP headers (bsc#1215098,CVE-2023-40547)
    Fix integer overflow on SBAT section size on 32-bit system (bsc#1215100,CVE-2023-40548)
    Authenticode: verify that the signature header is in bounds (bsc#1215101,CVE-2023-40549)
    pe: Fix an out-of-bound read in verify_buffer_sbat() (bsc#1215102,CVE-2023-40550)
    pe-relocate: Fix bounds check for MZ binaries (bsc#1215103,CVE-2023-40551)
  - remove shim-Enable-the-NX-compatibility-flag-by-default.patch
    The codes in this patch are already existing in shim-15.8
    The NX flag is disable which is same as the default value of shim-15.8,
    hence, not need to enable it by this patch now.
  - Patches (git log --oneline --reverse 15.7..15.8)
    657b248 Make sbat_var.S parse right with buggy gcc/binutils
    7c76425 Enable the NX compatibility flag by default.
    89972ae CryptoPkg/BaseCryptLib: Fix buffer overflow issue in realloc wrapper
    c7b3051 pe: Align section size up to page size for mem attrs
    e4f40ae pe: Add IS_PAGE_ALIGNED macro
    f23883c Don't loop forever in load_certs() with buggy firmware
    1f38cb3 Optionally allow to keep shim protocol installed
    102a658 Drop invalid calls to `CRYPTO_set_mem_functions`
    aae3df0 test-sbat: Fix exit code
    cca3933 Block Debian grub binaries with SBAT < 4
    cf59f34 Further improve load_certs() for non-compliant drivers/firmwares
    0601f44 SBAT-related documents formatting and spelling
    0640e13 Add a security contact email address in README.md
    0bfc397 Work around malformed path delimiters in file paths from DHCP
    a8b0b60 pe: only process RelocDir->Size of reloc section
    f7a4338 Skip testing msleep()
    549d346 Rename 'msecs' to 'usecs' to avoid potential confusion
    908c388 Change type of fallback_verbose_wait from int to unsigned long
    05eae92 Add SbatLevel_Variable.txt to document the various revocations
    243f125 Use -Wno-unused-but-set-variable for Cryptlib and OpenSSL
    89d25a1 Add a make rule for compile_commands.json
    118ff87 Add gnu-stack notes
    f132655 test: Make our fake dprintf be a statement.
    be00279 Remove CentOS 7 test builds.
    9964960 Split pe.c up even more.
    569270d Test (and fix) ImageAddress()
    61e9894 Verify signature before verifying sbat levels
    1578b55 Add libFuzzer support for csv.c
    a0673e3 Fix a 1-byte memory leak in .sbat parsing.
    e246812 Add libFuzzer support to the .sbat parser.
    fd43eda Work around ImageAddress() usage mistake
    1e985a3 Correctly free memory allocated in handle_image()
    dbbe3c8 mok: Avoid underflow in maximum variable size calculation
    04111d4 Make some of the static analysis tools a little easier to run
    7ba7440 compile_commands.json: remove stuff clang doesn't like
    66e6579 CVE-2023-40546 mok: fix LogError() invocation
    f271826 Add primitives for overflow-checked arithmetic operations.
    8372147 pe-relocate: Add a fuzzer for read_header()
    5a5147d CVE-2023-40551: pe-relocate: Fix bounds check for MZ binaries
    e912071 pe-relocate: make read_header() use checked arithmetic operations.
    93ce255 CVE-2023-40550 pe: Fix an out-of-bound read in verify_buffer_sbat()
    e7f5fdf pe-relocate: Ensure nothing else implements CVE-2023-40550
    afdc503 CVE-2023-40549 Authenticode: verify that the signature header is in bounds.
    96dccc2 CVE-2023-40548 Fix integer overflow on SBAT section size on 32-bit system
    dae82f6 Further mitigations against CVE-2023-40546 as a class
    ea0f9df Allow SbatLevel data from external binary
    b078ef2 Always clear SbatLevel when Secure Boot is disabled
    7dfb687 BS Variables for bootmgr revocations
    a967c0e shim should not self revoke
    577cedd Print message when refusing to apply SbatLevel
    e801b0d sbat revocations: check the full section name
    0226b56 CVE-2023-40547 - avoid incorrectly trusting HTTP headers
    6f0c8d2 Print errors when setting/clearing memory attrs
    57c0eed Updated Revocations for January 2024 CVEs
    49c6d95 Fix some minor ia32 build issues.
    be8ff7c post-process-pe: Don't set the NX_COMPAT flag by default after all.
    13abd9f pe-relocate: Avoid __builtin_add_overflow() on GCC < 5
    c46c975 Suppress "Failed to open <..>\revocations.efi" when file does not exist
    30a4f37 Rename "previous" revocations to "automatic"
    6f395c2 Build time selectable automatic SBATLevel revocations
    a23e2f0 netboot read_image() should not hardcode DEFAULT_LOADER
    993a345 Try to load revocations.efi even if directory read fails
    1770a03 gitmodules: use shim-15.8 for gnu-efi branch
    5914984 (HEAD -> main, tag: latest-release, tag: 15.8, origin/main, origin/HEAD) Bump version to 15.8

------------------------------------------------------------------
------------------  2024-5-18  -  May 18 2024  -------------------
------------------------------------------------------------------

++++ kernel-default:

  - selftests: net: bridge: increase IGMP/MLD exclude timeout
    membership interval (git-fixes).
  - of: module: add buffer overflow check in of_modalias()
    (git-fixes).
  - selftests/powerpc/dexcr: Add -no-pie to hashchk tests
    (git-fixes).
  - firmware: raspberrypi: Use correct device for DMA mappings
    (git-fixes).
  - Revert "drm/nouveau/firmware: Fix SG_DEBUG error with
    nvkm_firmware_ctor()" (stable-fixes).
  - drm/i915/audio: Fix audio time stamp programming for DP
    (stable-fixes).
  - gpiolib: cdev: fix uninitialised kfifo (git-fixes).
  - selftests: test_bridge_neigh_suppress.sh: Fix failures due to
    duplicate MAC (git-fixes).
  - Bluetooth: qca: fix firmware check error path (git-fixes).
  - dyndbg: fix old BUG_ON in >control parser (stable-fixes).
  - mei: me: add lunar lake point M DID (stable-fixes).
  - usb: xhci-plat: Don't include xhci.h (stable-fixes).
  - ASoC: meson: axg-fifo: use threaded irq to check periods
    (git-fixes).
  - drm/nouveau/firmware: Fix SG_DEBUG error with
    nvkm_firmware_ctor() (stable-fixes).
  - drm/amd/display: Fix incorrect DSC instance for MST
    (stable-fixes).
  - drm/amd/display: Atom Integrated System Info v2_2 for DCN35
    (stable-fixes).
  - drm/amd/display: Handle Y carry-over in VCP X.Y calculation
    (stable-fixes).
  - clk: Don't hold prepare_lock when calling kref_put()
    (stable-fixes).
  - drm/nouveau/dp: Don't probe eDP ports twice harder
    (stable-fixes).
  - drm/radeon: silence UBSAN warning (v3) (stable-fixes).
  - net:usb:qmi_wwan: support Rolling modules (stable-fixes).
  - gpio: crystalcove: Use -ENOTSUPP consistently (stable-fixes).
  - gpio: wcove: Use -ENOTSUPP consistently (stable-fixes).
  - platform/x86: ISST: Add Granite Rapids-D to HPM CPU list
    (stable-fixes).
  - selftests: timers: Fix valid-adjtimex signed left-shift
    undefined behavior (stable-fixes).
  - gpu: host1x: Do not setup DMA for virtual devices
    (stable-fixes).
  - amd/amdkfd: sync all devices to wait all processes being evicted
    (stable-fixes).
  - drm/amdgpu: Fix VCN allocation in CPX partition (stable-fixes).
  - drm/amdgpu: implement IRQ_STATE_ENABLE for SDMA v4.4.2
    (stable-fixes).
  - drm/amdgpu: Refine IB schedule error logging (stable-fixes).
  - firewire: ohci: mask bus reset interrupts between ISR and
    bottom half (stable-fixes).
  - regulator: tps65132: Add of_match table (stable-fixes).
  - ata: sata_gemini: Check clk_enable() result (stable-fixes).
  - ASoC: SOF: Intel: hda-dsp: Skip IMR boot on ACE platforms in
    case of S3 suspend (stable-fixes).
  - ALSA: line6: Zero-initialize message buffers (stable-fixes).
  - vboxsf: explicitly deny setlease attempts (stable-fixes).
  - drm/amdkfd: range check cp bad op exception interrupts
    (stable-fixes).
  - drm/amdkfd: Check cgroup when returning DMABuf info
    (stable-fixes).
  - selftests/ftrace: Fix event filter target_func selection
    (stable-fixes).
  - wifi: iwlwifi: mvm: guard against invalid STA ID on removal
    (stable-fixes).
  - wifi: iwlwifi: read txq->read_ptr under lock (stable-fixes).
  - wifi: mac80211: fix prep_connection error path (stable-fixes).
  - wifi: cfg80211: fix rdev_dump_mpp() arguments order
    (stable-fixes).
  - wifi: mac80211: fix ieee80211_bss_*_flags kernel-doc
    (stable-fixes).
  - ASoC: meson: axg-fifo: use FIELD helpers (stable-fixes).
  - gpiolib: cdev: relocate debounce_period_us from struct gpio_desc
    (stable-fixes).
  - selftests/net: convert test_bridge_neigh_suppress.sh to run
    it in unique namespace (stable-fixes).
  - commit 2872089

++++ kernel-rt:

  - selftests: net: bridge: increase IGMP/MLD exclude timeout
    membership interval (git-fixes).
  - of: module: add buffer overflow check in of_modalias()
    (git-fixes).
  - selftests/powerpc/dexcr: Add -no-pie to hashchk tests
    (git-fixes).
  - firmware: raspberrypi: Use correct device for DMA mappings
    (git-fixes).
  - Revert "drm/nouveau/firmware: Fix SG_DEBUG error with
    nvkm_firmware_ctor()" (stable-fixes).
  - drm/i915/audio: Fix audio time stamp programming for DP
    (stable-fixes).
  - gpiolib: cdev: fix uninitialised kfifo (git-fixes).
  - selftests: test_bridge_neigh_suppress.sh: Fix failures due to
    duplicate MAC (git-fixes).
  - Bluetooth: qca: fix firmware check error path (git-fixes).
  - dyndbg: fix old BUG_ON in >control parser (stable-fixes).
  - mei: me: add lunar lake point M DID (stable-fixes).
  - usb: xhci-plat: Don't include xhci.h (stable-fixes).
  - ASoC: meson: axg-fifo: use threaded irq to check periods
    (git-fixes).
  - drm/nouveau/firmware: Fix SG_DEBUG error with
    nvkm_firmware_ctor() (stable-fixes).
  - drm/amd/display: Fix incorrect DSC instance for MST
    (stable-fixes).
  - drm/amd/display: Atom Integrated System Info v2_2 for DCN35
    (stable-fixes).
  - drm/amd/display: Handle Y carry-over in VCP X.Y calculation
    (stable-fixes).
  - clk: Don't hold prepare_lock when calling kref_put()
    (stable-fixes).
  - drm/nouveau/dp: Don't probe eDP ports twice harder
    (stable-fixes).
  - drm/radeon: silence UBSAN warning (v3) (stable-fixes).
  - net:usb:qmi_wwan: support Rolling modules (stable-fixes).
  - gpio: crystalcove: Use -ENOTSUPP consistently (stable-fixes).
  - gpio: wcove: Use -ENOTSUPP consistently (stable-fixes).
  - platform/x86: ISST: Add Granite Rapids-D to HPM CPU list
    (stable-fixes).
  - selftests: timers: Fix valid-adjtimex signed left-shift
    undefined behavior (stable-fixes).
  - gpu: host1x: Do not setup DMA for virtual devices
    (stable-fixes).
  - amd/amdkfd: sync all devices to wait all processes being evicted
    (stable-fixes).
  - drm/amdgpu: Fix VCN allocation in CPX partition (stable-fixes).
  - drm/amdgpu: implement IRQ_STATE_ENABLE for SDMA v4.4.2
    (stable-fixes).
  - drm/amdgpu: Refine IB schedule error logging (stable-fixes).
  - firewire: ohci: mask bus reset interrupts between ISR and
    bottom half (stable-fixes).
  - regulator: tps65132: Add of_match table (stable-fixes).
  - ata: sata_gemini: Check clk_enable() result (stable-fixes).
  - ASoC: SOF: Intel: hda-dsp: Skip IMR boot on ACE platforms in
    case of S3 suspend (stable-fixes).
  - ALSA: line6: Zero-initialize message buffers (stable-fixes).
  - vboxsf: explicitly deny setlease attempts (stable-fixes).
  - drm/amdkfd: range check cp bad op exception interrupts
    (stable-fixes).
  - drm/amdkfd: Check cgroup when returning DMABuf info
    (stable-fixes).
  - selftests/ftrace: Fix event filter target_func selection
    (stable-fixes).
  - wifi: iwlwifi: mvm: guard against invalid STA ID on removal
    (stable-fixes).
  - wifi: iwlwifi: read txq->read_ptr under lock (stable-fixes).
  - wifi: mac80211: fix prep_connection error path (stable-fixes).
  - wifi: cfg80211: fix rdev_dump_mpp() arguments order
    (stable-fixes).
  - wifi: mac80211: fix ieee80211_bss_*_flags kernel-doc
    (stable-fixes).
  - ASoC: meson: axg-fifo: use FIELD helpers (stable-fixes).
  - gpiolib: cdev: relocate debounce_period_us from struct gpio_desc
    (stable-fixes).
  - selftests/net: convert test_bridge_neigh_suppress.sh to run
    it in unique namespace (stable-fixes).
  - commit 2872089

------------------------------------------------------------------
------------------  2024-5-17  -  May 17 2024  -------------------
------------------------------------------------------------------

++++ conmon:

  - New upstream release 2.1.12
    * Packit: enable downstream sync to CentOS Stream 10
    * Make 'docs' target not depend on 'install.tools' if GOMD2MAN is set

++++ python-kiwi:

  - Add procps to Tumbleweed integration tests

++++ kdump:

  - upgrade to version 2.0.5
    * spec: differentiate between uninstall and upgrade in postun/preun (bsc#1191410)
    * spec: return success from pre, post, preun and postun scriplets (bsc#1222228)
    * add a note to README.txt about the flattened format (bsc#1221374)
    * use the same persistent device links as dracut (bsc#1222009, bsc#1219471)
    * remove dracut parse-root.sh hook (bsc#1221288)
    * always use nr_cpus, not maxcpus (bsc#1218180)
    * prevent mounting root in fadump (bsc#1219958)
    * update calibrate values

++++ kernel-default:

  - af_unix: Fix garbage collector racing against connect()
    (CVE-2024-26923 bsc#1223384).
  - af_unix: Replace BUG_ON() with WARN_ON_ONCE() (CVE-2024-26923
    bsc#1223384).
  - af_unix: Do not use atomic ops for unix_sk(sk)->inflight
    (CVE-2024-26923 bsc#1223384).
  - commit a683abb
  - dm-multipath: dont't attempt SG_IO on non-SCSI-disks
    (bsc#1223575).
  - commit 2f6779f
  - btrfs: qgroup: convert PREALLOC to PERTRANS after record_root_in_trans (git-fixes)
  - commit b85295a
  - btrfs: don't arbitrarily slow down delalloc if we're committing (git-fixes)
  - commit d9b2223
  - btrfs: reset destination buffer when read_extent_buffer() gets invalid range (git-fixes)
  - commit 7ef02d5
  - btrfs: return -EUCLEAN for delayed tree ref with a ref count not equals to 1 (git-fixes)
  - commit e6b51c1
  - btrfs: file_remove_privs needs an exclusive lock in direct io write (git-fixes)
  - commit 0bc88db
  - btrfs: don't start transaction when joining with TRANS_JOIN_NOSTART (git-fixes)
  - commit 74fcad3
  - btrfs: fix start transaction qgroup rsv double free (git-fixes)
  - commit 272247e
  - btrfs: free qgroup rsv on io failure (git-fixes)
  - commit 384dac4
  - netfilter: nf_tables: disable toggling dormant table state
    more than once (git-fixes).
  - commit 76bebd5
  - mptcp: process pending subflow error on close (git-fixes).
  - commit ef629c5
  - mptcp: move __mptcp_error_report in protocol.c (git-fixes).
  - commit a777e91
  - mptcp: fix bogus receive window shrinkage with multiple subflows
    (git-fixes).
  - commit deea9a0
  - netfilter: nft_set_rbtree: use read spinlock to avoid datapath
    contention (git-fixes).
  - commit ddc952e
  - net/smc: use smc_lgr_list.lock to protect smc_lgr_list.list
    iterate in smcr_port_add (git-fixes).
  - commit 2d7895b
  - net/smc: bugfix for smcr v2 server connect success statistic
    (git-fixes).
  - commit e746f6b
  - netfilter: nf_tables: uapi: Describe NFTA_RULE_CHAIN_ID
    (git-fixes).
  - commit ec5b855
  - net: annotate data-races around sk->sk_bind_phc (git-fixes).
  - commit 16b7a1e
  - net: annotate data-races around sk->sk_tsflags (git-fixes).
  - commit b028530
  - arm64: Add the arm64.no32bit_el0 command line option
    (jsc#PED-3184).
    Please note that some adjustments were needed since the upstream commit
    is based on kernel 6.9 which has idreg-override.c moved under
    arch/arm64/kernel/pi/.
  - commit 4fba46a
  - af_unix: Drop oob_skb ref before purging queue in GC
    (CVE-2024-26676 bsc#1222380).
  - commit 57acc3a
  - af_unix: Fix task hung while purging oob_skb in GC
    (CVE-2024-26676 bsc#1222380).
  - commit 3af3fbb
  - af_unix: Call kfree_skb() for dead unix_(sk)->oob_skb in GC
    (CVE-2024-26676 bsc#1222380).
  - commit 7728cdc
  - platform/x86/intel-uncore-freq: Don't present root domain on
    error (git-fixes).
  - tools/arch/x86/intel_sdsi: Fix meter_certificate decoding
    (git-fixes).
  - tools/arch/x86/intel_sdsi: Fix meter_show display (git-fixes).
  - tools/arch/x86/intel_sdsi: Fix maximum meter bundle length
    (git-fixes).
  - platform/x86: xiaomi-wmi: Fix race condition when reporting
    key events (git-fixes).
  - mtd: rawnand: hynix: fixed typo (git-fixes).
  - mtd: core: Report error if first mtd_otp_size() call fails in
    mtd_otp_nvmem_add() (git-fixes).
  - mmc: davinci: Don't strip remove function when driver is builtin
    (git-fixes).
  - mmc: sdhci_am654: Fix ITAPDLY for HS400 timing (git-fixes).
  - mmc: sdhci_am654: Add ITAPDLYSEL in sdhci_j721e_4bit_set_clock
    (git-fixes).
  - mmc: sdhci_am654: Add OTAP/ITAP delay enable (git-fixes).
  - mmc: sdhci_am654: Write ITAPDLY for DDR52 timing (git-fixes).
  - mmc: sdhci_am654: Add tuning algorithm for delay chain
    (git-fixes).
  - media: sunxi: a83-mips-csi2: also select GENERIC_PHY
    (git-fixes).
  - media: flexcop-usb: fix sanity check of bNumEndpoints
    (git-fixes).
  - media: stk1160: fix bounds checking in stk1160_copy_video()
    (git-fixes).
  - media: uvcvideo: Add quirk for Logitech Rally Bar (git-fixes).
  - media: v4l: Don't turn on privacy LED if streamon fails
    (git-fixes).
  - media: mc: mark the media devnode as registered from the,
    start (git-fixes).
  - media: atomisp: ssh_css: Fix a null-pointer dereference in
    load_video_binaries (git-fixes).
  - media: v4l2-subdev: Fix stream handling for crop API
    (git-fixes).
  - media: mc: Fix graph walk in media_pipeline_start (git-fixes).
  - media: i2c: et8ek8: Don't strip remove function when driver
    is builtin (git-fixes).
  - media: dt-bindings: ovti,ov2680: Fix the power supply names
    (git-fixes).
  - media: ipu3-cio2: Request IRQ earlier (git-fixes).
  - media: rcar-vin: work around -Wenum-compare-conditional warning
    (git-fixes).
  - media: ngene: Add dvb_ca_en50221_init return value check
    (git-fixes).
  - commit ceb1555
  - Move upstreamed media patches into sorted section
  - commit 521e539

++++ kernel-rt:

  - af_unix: Fix garbage collector racing against connect()
    (CVE-2024-26923 bsc#1223384).
  - af_unix: Replace BUG_ON() with WARN_ON_ONCE() (CVE-2024-26923
    bsc#1223384).
  - af_unix: Do not use atomic ops for unix_sk(sk)->inflight
    (CVE-2024-26923 bsc#1223384).
  - commit a683abb
  - dm-multipath: dont't attempt SG_IO on non-SCSI-disks
    (bsc#1223575).
  - commit 2f6779f
  - btrfs: qgroup: convert PREALLOC to PERTRANS after record_root_in_trans (git-fixes)
  - commit b85295a
  - btrfs: don't arbitrarily slow down delalloc if we're committing (git-fixes)
  - commit d9b2223
  - btrfs: reset destination buffer when read_extent_buffer() gets invalid range (git-fixes)
  - commit 7ef02d5
  - btrfs: return -EUCLEAN for delayed tree ref with a ref count not equals to 1 (git-fixes)
  - commit e6b51c1
  - btrfs: file_remove_privs needs an exclusive lock in direct io write (git-fixes)
  - commit 0bc88db
  - btrfs: don't start transaction when joining with TRANS_JOIN_NOSTART (git-fixes)
  - commit 74fcad3
  - btrfs: fix start transaction qgroup rsv double free (git-fixes)
  - commit 272247e
  - btrfs: free qgroup rsv on io failure (git-fixes)
  - commit 384dac4
  - netfilter: nf_tables: disable toggling dormant table state
    more than once (git-fixes).
  - commit 76bebd5
  - mptcp: process pending subflow error on close (git-fixes).
  - commit ef629c5
  - mptcp: move __mptcp_error_report in protocol.c (git-fixes).
  - commit a777e91
  - mptcp: fix bogus receive window shrinkage with multiple subflows
    (git-fixes).
  - commit deea9a0
  - netfilter: nft_set_rbtree: use read spinlock to avoid datapath
    contention (git-fixes).
  - commit ddc952e
  - net/smc: use smc_lgr_list.lock to protect smc_lgr_list.list
    iterate in smcr_port_add (git-fixes).
  - commit 2d7895b
  - net/smc: bugfix for smcr v2 server connect success statistic
    (git-fixes).
  - commit e746f6b
  - netfilter: nf_tables: uapi: Describe NFTA_RULE_CHAIN_ID
    (git-fixes).
  - commit ec5b855
  - net: annotate data-races around sk->sk_bind_phc (git-fixes).
  - commit 16b7a1e
  - net: annotate data-races around sk->sk_tsflags (git-fixes).
  - commit b028530
  - arm64: Add the arm64.no32bit_el0 command line option
    (jsc#PED-3184).
    Please note that some adjustments were needed since the upstream commit
    is based on kernel 6.9 which has idreg-override.c moved under
    arch/arm64/kernel/pi/.
  - commit 4fba46a
  - af_unix: Drop oob_skb ref before purging queue in GC
    (CVE-2024-26676 bsc#1222380).
  - commit 57acc3a
  - af_unix: Fix task hung while purging oob_skb in GC
    (CVE-2024-26676 bsc#1222380).
  - commit 3af3fbb
  - af_unix: Call kfree_skb() for dead unix_(sk)->oob_skb in GC
    (CVE-2024-26676 bsc#1222380).
  - commit 7728cdc
  - platform/x86/intel-uncore-freq: Don't present root domain on
    error (git-fixes).
  - tools/arch/x86/intel_sdsi: Fix meter_certificate decoding
    (git-fixes).
  - tools/arch/x86/intel_sdsi: Fix meter_show display (git-fixes).
  - tools/arch/x86/intel_sdsi: Fix maximum meter bundle length
    (git-fixes).
  - platform/x86: xiaomi-wmi: Fix race condition when reporting
    key events (git-fixes).
  - mtd: rawnand: hynix: fixed typo (git-fixes).
  - mtd: core: Report error if first mtd_otp_size() call fails in
    mtd_otp_nvmem_add() (git-fixes).
  - mmc: davinci: Don't strip remove function when driver is builtin
    (git-fixes).
  - mmc: sdhci_am654: Fix ITAPDLY for HS400 timing (git-fixes).
  - mmc: sdhci_am654: Add ITAPDLYSEL in sdhci_j721e_4bit_set_clock
    (git-fixes).
  - mmc: sdhci_am654: Add OTAP/ITAP delay enable (git-fixes).
  - mmc: sdhci_am654: Write ITAPDLY for DDR52 timing (git-fixes).
  - mmc: sdhci_am654: Add tuning algorithm for delay chain
    (git-fixes).
  - media: sunxi: a83-mips-csi2: also select GENERIC_PHY
    (git-fixes).
  - media: flexcop-usb: fix sanity check of bNumEndpoints
    (git-fixes).
  - media: stk1160: fix bounds checking in stk1160_copy_video()
    (git-fixes).
  - media: uvcvideo: Add quirk for Logitech Rally Bar (git-fixes).
  - media: v4l: Don't turn on privacy LED if streamon fails
    (git-fixes).
  - media: mc: mark the media devnode as registered from the,
    start (git-fixes).
  - media: atomisp: ssh_css: Fix a null-pointer dereference in
    load_video_binaries (git-fixes).
  - media: v4l2-subdev: Fix stream handling for crop API
    (git-fixes).
  - media: mc: Fix graph walk in media_pipeline_start (git-fixes).
  - media: i2c: et8ek8: Don't strip remove function when driver
    is builtin (git-fixes).
  - media: dt-bindings: ovti,ov2680: Fix the power supply names
    (git-fixes).
  - media: ipu3-cio2: Request IRQ earlier (git-fixes).
  - media: rcar-vin: work around -Wenum-compare-conditional warning
    (git-fixes).
  - media: ngene: Add dvb_ca_en50221_init return value check
    (git-fixes).
  - commit ceb1555
  - Move upstreamed media patches into sorted section
  - commit 521e539

++++ lsof:

  - replace:
    0002-tests-fix-for-kernel-6.9.patch
    by upstream proposed:
    0002-linux-Maintain-original-output-for-pidfd-in-linux-6..patch

++++ openssh:

  - Remove the recommendation for openssh-server-config-rootlogin
    from openssh-server. Since the default for that config option
    was changed in SLE it's not needed anymore in SLE nor in TW
    (boo#1224392).

++++ python-attrs:

  - Add patch pytest8.patch to adapt the tests to the new pytest

++++ python-tornado6:

  - Add patch support-pytest-8.2.patch:
    * Support pytest >= 8.2 changes.

++++ qemu:

  - Update to version 9.0.0:
    Full changelog here:
    https://wiki.qemu.org/ChangeLog/9.0
    Highlights include:
    * block: virtio-blk now supports multiqueue where different queues of a
    single disk can be processed by different I/O threads
    * gdbstub: various improvements such as catching syscalls in user-mode,
    support for fork-follow modes, and support for siginfo:read
    * memory: preallocation of memory backends can now be handled
    concurrently using multiple threads in some cases
    * migration: support for "mapped-ram" capability allowing for more
    efficient VM snapshots, improved support for zero-page detection, and
    checkpoint-restart support for VFIO
    * ARM: architectural feature support for ECV (Enhanced Counter Virtualization),
    NV (Nested Virtualization), and NV2 (Enhanced Nested
    Virtualization)
    * ARM: board support for B-L475E-IOT01A IoT node, mp3-an536 (MPS3 dev board
    + AN536 firmware), and raspi4b (Raspberry Pi 4 Model B)
    * ARM: additional IO/disk/USB/SPI/ethernet controller and timer support for
    Freescale i.MX6, Allwinner R40, Banana Pi, npcm7xxx, and virt boards
    * HPPA: numerous bug fixes and SeaBIOS-hppa firmware updated to version 16
    * LoongArch: KVM acceleration support, including LSX/LASX vector
    extensions
    * RISC-V: ISA/extension support for Zacas, amocas, RVA22 profiles,
    Zaamo, Zalrsc, Ztso, and more
    * RISC-V: SMBIOS support for RISC-V virt machine, ACPI support for
    SRAT, SLIT, AIA, PLIC and updated RHCT table support, and numerous fixes
    * s390x: Emulation support for CVDG, CVB, CVBY and CVBG instructions,
    and fixes for LAE (Load Address Extended) emulation
    * and lots more...

++++ xfsprogs:

  - update to 6.8.0
  - xfs_repair: Dump both inode details in Phase 6 duplicate file check
  - libxfs: print the device name if flush-on-close fails
  - xfs_db: fix leak in flist_find_ftyp()
  - xfs_repair: support more than INT_MAX block maps
  - xfs_repair: constrain attr fork extent count
  - xfs_repair: support more than 2^32 owners per physical block
  - xfs_repair: support more than 2^32 rmapbt records per AG
  - xfs_db: add a bmbt inflation command
  - xfs_scrub: scan whole-fs metadata files in parallel
  - mkfs: allow sizing internal logs for concurrency
  - mkfs: allow sizing allocation groups for concurrency
  - mkfs: use a sensible log sector size default
  - xfs_io: add linux madvise advice codes
  - xfs_scrub: fix threadcount estimates for phase 6
  - xfs_db: improve number extraction in getbitval
  - xfs_repair: adjust btree bulkloading slack computations to match online repair
  - xfs: make rextslog computation consistent with mkfs
  - mkfs: fix log sunit rounding when external logs are in use
  - libxfs: kernel sync

------------------------------------------------------------------
------------------  2024-5-16  -  May 16 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  -  Update to bugfix release 24.0.7
  - -> https://docs.mesa3d.org/relnotes/24.0.7.html
  - Update to bugfix release 24.0.6
  - -> https://docs.mesa3d.org/relnotes/24.0.6.html

++++ Mesa-drivers:

  -  Update to bugfix release 24.0.7
  - -> https://docs.mesa3d.org/relnotes/24.0.7.html
  - Update to bugfix release 24.0.6
  - -> https://docs.mesa3d.org/relnotes/24.0.6.html

++++ bolt:

  - update to 0.9.8:
    * A new NHI for REMBRANDT.
    * CI fixes.
    * Don't install an empty DB directory.
    * Fixed: Determine the string length before writing file.
    * Fixed: Free on error to prevent resource leak.

++++ cockpit:

  - new version 316:
    * cockpit.js API: Fix format_bytes() units
  - add 0001-users-Support-for-watching-lastlog2.patch (bsc#1220551)
  - add 0002-users-Support-for-watching-lastlog2-and-wutmp-on-overview-page.patch (bsc#1220551)

++++ python-kiwi:

  - Add procps to Tumbleweed integration tests

++++ gdk-pixbuf:

  - Enable test suite on x86_64 (other arches seem too flaky for now):
    + Add %check section and call %meson_test
    + Add gdk-pixbuf-jpeg-slow.patch: allow pixbuf-jpeg to run for
    more than 30s, by marking it as a slow test
    (glgo#GNOME/gdk-pixbuf!174).
  - Migrate package to a regular obs_scm service, no longer password
    protecting a zip file. The originally reported bsc#1159337 seems
    no longer be applicable and we prefer the easier route.
  - Drop unzip BuildRequires and pre_checkin.sh script.

++++ gtk3:

  - Update to version 3.24.42:
    + GtkFileChooser:
  - Avoid warnings about floating refs.
  - Improve performance of recursive search.
  - Populate search model in an idle.
    + GtkGLArea: Fix a regression in transparency handling.
    + Printing: Avoid accessing freed printers.
    + Accessibility: Drop support for the deprecated
    atk_focus_tracker.
    + Wayland:
  - Fix monitor sizes.
  - Fix a crash related to tablet removal.
  - Infer resizable edges for tiled windows.
  - Always commit soon after acking a configure.
    + gdk:
  - Use css cursor names as far as possible.
  - Sync DND cursor use with GTK4.
    + build: Allow building against sysprof-capture-4.
    + Updated translations.

++++ kernel-default:

  - dmaengine: idxd: move safety flag to struct ends (bsc#1223625
    CVE-2024-21823).
  - dmaengine: idxd: add a write() method for applications to
    submit work (bsc#1223625 CVE-2024-21823).
  - dmaengine: idxd: add a new security check to deal with a
    hardware erratum (bsc#1223625 CVE-2024-21823).
  - VFIO: Add the SPR_DSA and SPR_IAX devices to the denylist
    (bsc#1223625 CVE-2024-21823).
  - commit 8718675
  - Update
    patches.suse/io_uring-af_unix-disable-sending-io_uring-over-socke.patch
    (bsc#1218447 CVE-2023-6531 CVE-2023-52654 bsc#1224099).
  - Update
    patches.suse/usb-aqc111-check-packet-for-fixup-for-true-limit.patch
    (git-fixes CVE-2023-52655 bsc#1217169).
  - commit 07c8bc1
  - octeontx2-pf: fix FLOW_DIS_IS_FRAGMENT implementation
    (git-fixes).
  - commit 78ec58d
  - net/mlx5: Fix peer devlink set for SF representor devlink port
    (git-fixes).
  - commit 6a691b6
  - net/mlx5: Lag, restore buckets number to default after hash
    LAG deactivation (git-fixes).
  - commit 19da0bb
  - net: sparx5: flower: fix fragment flags handling (git-fixes).
  - commit 5fd27e9
  - net: ena: Set tx_info->xdpf value to NULL (git-fixes).
  - commit 7d1d83a
  - net: ena: Fix incorrect descriptor free behavior (git-fixes).
  - commit 69577fd
  - net: ena: Wrong missing IO completions check order (git-fixes).
  - commit fbbd86e
  - net: ena: Fix potential sign extension issue (git-fixes).
  - commit b3cc5f8
  - net: dsa: mt7530: trap link-local frames regardless of ST Port
    State (git-fixes).
  - commit 726080b
  - net: sparx5: fix wrong config being used when reconfiguring PCS
    (git-fixes).
  - commit d2d1229
  - net/mlx5e: RSS, Block XOR hash with over 128 channels
    (git-fixes).
  - commit 40b1ccb
  - net/mlx5: Restore mistakenly dropped parts in register devlink
    flow (git-fixes).
  - commit dfb4099
  - btrfs: defrag: avoid unnecessary defrag caused by incorrect extent size (git-fixes)
  - commit a1c6e8c
  - btrfs: don't warn if discard range is not aligned to sector (git-fixes)
  - commit f239c2a
  - btrfs: tree-checker: fix inline ref size in error messages (git-fixes)
  - commit a304971
  - btrfs: defrag: reject unknown flags of btrfs_ioctl_defrag_range_args (git-fixes)
  - commit 81a1329
  - btrfs: do not allow non subvolume root targets for snapshot (git-fixes)
  - commit d495a4b
  - btrfs: send: ensure send_fd is writable (git-fixes)
  - commit 5055583
  - btrfs: free the allocated memory if btrfs_alloc_page_array() fails (git-fixes)
  - commit 532ad3c
  - btrfs: fix 64bit compat send ioctl arguments not initializing version member (git-fixes)
  - commit 2c30d15
  - btrfs: fix off-by-one when checking chunk map includes logical address (git-fixes)
  - commit e5842bb
  - btrfs: use u64 for buffer sizes in the tree search ioctls (git-fixes)
  - commit a1c6ed1
  - btrfs: error out when reallocating block for defrag using a stale transaction (git-fixes)
  - commit e6bb34b
  - btrfs: error when COWing block from a root that is being deleted (git-fixes)
  - commit 78a2694
  - btrfs: error out when COWing block using a stale transaction (git-fixes)
  - commit 850d86f
  - s390/cpum_cf: make crypto counters upward compatible across
    machine types (bsc#1224348).
  - commit 36c1e09
  - btrfs: always print transaction aborted messages with an error level (git-fixes)
  - commit 26fa5ae
  - net/mlx5e: Do not produce metadata freelist entries in Tx port
    ts WQE xmit (git-fixes).
  - commit 287b501
  - net/mlx5e: HTB, Fix inconsistencies with QoS SQs number
    (git-fixes).
  - commit 0085432
  - net/mlx5e: Fix mlx5e_priv_init() cleanup flow (git-fixes).
  - commit 01134b3
  - net/mlx5e: RSS, Block changing channels number when RXFH is
    configured (git-fixes).
  - commit c93a7d5
  - net/mlx5: Correctly compare pkt reformat ids (git-fixes).
  - commit 76a7159
  - net/mlx5: Properly link new fs rules into the tree (git-fixes).
  - commit 7272c33
  - net/mlx5: offset comp irq index in name by one (git-fixes).
  - commit 56809e4
  - net/mlx5: Register devlink first under devlink lock (git-fixes).
  - commit 3162538
  - net/mlx5: E-switch, store eswitch pointer before registering
    devlink_param (git-fixes).
  - commit d6f7fd4
  - ALSA: hda/realtek - fixed headset Mic not show (stable-fixes).
  - ALSA: hda: hda_cs_dsp_ctl: Remove notification of driver write
    (stable-fixes).
  - ALSA: Fix deadlocks with kctl removals at disconnection
    (stable-fixes).
  - ALSA: hda: clarify Copyright information (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS Zenbook 2024 HN7306W
    (stable-fixes).
  - ALSA: hda/realtek: Fix internal speakers for Legion Y9000X
    2022 IAH7 (stable-fixes).
  - ALSA: hda: Add Intel BMG PCI ID and HDMI codec vid
    (stable-fixes).
  - ALSA: hda: cs35l41: Add support for ASUS ROG 2024 Laptops
    (stable-fixes).
  - ALSA: hda: cs35l41: Ignore errors when configuring IRQs
    (stable-fixes).
  - ALSA: hda/realtek: Add quirks for Lenovo 13X (stable-fixes).
  - ALSA: hda: cs35l41: Support Lenovo 13X laptop without _DSD
    (stable-fixes).
  - ALSA: hda: cs35l41: Remove redundant argument to
    cs35l41_request_firmware_file() (stable-fixes).
  - ALSA: hda: cs35l41: Update DSP1RX5/6 Sources for DSP config
    (stable-fixes).
  - ALSA: hda/realtek: Add quirks for HP Omen models using CS35L41
    (stable-fixes).
  - ALSA: hda: cs35l41: Support HP Omen models without _DSD
    (stable-fixes).
  - ALSA: hda: cs35l41: Set the max PCM Gain using tuning setting
    (stable-fixes).
  - commit bd5e5fc
  - Add cherry-picked patch references to amdgpu patches
  - commit fb4ef8e
  - ALSA: hda/realtek: Drop doubly quirk entry for 103c:8a2e
    (git-fixes).
  - ASoC: tas2781: Fix a warning reported by robot kernel test
    (git-fixes).
  - ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value
    (git-fixes).
  - ASoC: Intel: avs: Test result of avs_get_module_entry()
    (git-fixes).
  - ASoC: Intel: avs: Fix potential integer overflow (git-fixes).
  - ASoC: Intel: avs: Fix ASRC module initialization (git-fixes).
  - ASoC: SOF: Intel: mtl: Implement firmware boot state check
    (git-fixes).
  - ASoC: SOF: Intel: lnl: Correct rom_status_reg (git-fixes).
  - ASoC: SOF: Intel: mtl: Correct rom_status_reg (git-fixes).
  - Revert "ASoC: SOF: Intel: hda-dai-ops: only allocate/release
    streams for first CPU DAI" (stable-fixes).
  - Revert "ASoC: SOF: Intel: hda-dai-ops: reset device count for
    SoundWire DAIs" (stable-fixes).
  - ASoC: kirkwood: Fix potential NULL dereference (git-fixes).
  - ASoC: Intel: avs: ssm4567: Do not ignore route checks
    (git-fixes).
  - ASoC: Intel: Disable route checks for Skylake boards
    (git-fixes).
  - ASoC: mediatek: Assign dummy when codec not specified for a
    DAI link (git-fixes).
  - ASoC: mediatek: mt8192: fix register configuration for tdm
    (git-fixes).
  - ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance (git-fixes).
  - ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup
    (git-fixes).
  - ALSA: hda: cs35l41: Remove Speaker ID for Lenovo Legion slim
    7 16ARHA7 (git-fixes).
  - fbdev: savage: Handle err return when savagefb_check_var failed
    (git-fixes).
  - fbdev: sh7760fb: allow modular build (git-fixes).
  - fbdev: sisfb: hide unused variables (git-fixes).
  - fbdev: shmobile: fix snprintf truncation (git-fixes).
  - drm: zynqmp_dpsub: Always register bridge (git-fixes).
  - Revert "drm/bridge: ti-sn65dsi83: Fix enable error path"
    (git-fixes).
  - drm/fbdev-generic: Do not set physical framebuffer address
    (git-fixes).
  - drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting
    fails (git-fixes).
  - drm/msm/adreno: fix CP cycles stat retrieval on a7xx
    (git-fixes).
  - drm/msm/dpu: Add callback function pointer check before its call
    (git-fixes).
  - drm/msm/dpu: Allow configuring multiple active DSC blocks
    (git-fixes).
  - drm/msm/dpu: Always flush the slave INTF on the CTL (git-fixes).
  - drm/msm/dsi: Print dual-DSI-adjusted pclk instead of original
    mode pclk (git-fixes).
  - drm/msm/dp: Avoid a long timeout for AUX transfer if nothing
    connected (git-fixes).
  - drm/msm/dp: allow voltage swing / pre emphasis of 3 (git-fixes).
  - drm/mediatek: dp: Fix mtk_dp_aux_transfer return value
    (git-fixes).
  - drm/mediatek: Init `ddp_comp` with devm_kcalloc() (git-fixes).
  - drm/mediatek: Add 0 size check to mtk_drm_gem_obj (git-fixes).
  - drm/bridge: tc358775: fix support for jeida-18 and jeida-24
    (git-fixes).
  - drm/meson: gate px_clk when setting rate (git-fixes).
  - drm/rockchip: vop2: Do not divide height twice for YUV
    (git-fixes).
  - drm/panel: simple: Add missing Innolux G121X1-L03 format,
    flags, connector (git-fixes).
  - drm/bridge: anx7625: Update audio status while detecting
    (git-fixes).
  - drm/panel: novatek-nt35950: Don't log an error when DSI host
    can't be found (git-fixes).
  - drm/bridge: dpc3433: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: tc358775: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: lt9611uxc: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: lt9611: Don't log an error when DSI host can't be
    found (git-fixes).
  - drm/bridge: lt8912b: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: icn6211: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: anx7625: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm: vc4: Fix possible null pointer dereference (git-fixes).
  - drm/arm/malidp: fix a possible null pointer dereference
    (git-fixes).
  - drm/amd/display: Remove redundant condition in
    dcn35_calc_blocks_to_gate() (git-fixes).
  - drm/amd/display: Fix potential index out of bounds in color
    transformation function (git-fixes).
  - drm: bridge: cdns-mhdp8546: Fix possible null pointer
    dereference (git-fixes).
  - drm/meson: vclk: fix calculation of 59.94 fractional rates
    (git-fixes).
  - drm/panel: ltk050h3146w: drop duplicate commands from
    LTK050H3148W init (git-fixes).
  - drm/panel: ltk050h3146w: add MIPI_DSI_MODE_VIDEO to LTK050H3148W
    flags (git-fixes).
  - drm/lcdif: Do not disable clocks on already suspended hardware
    (git-fixes).
  - drm/omapdrm: Fix console by implementing fb_dirty (git-fixes).
  - drm/nouveau/dp: Fix incorrect return code in r535_dp_aux_xfer()
    (git-fixes).
  - drm/ci: update device type for volteer devices (git-fixes).
  - drm/bridge: Fix improper bridge init order with
    pre_enable_prev_first (git-fixes).
  - commit e7d2777
  - Revert "selinux: introduce an initial SID for early boot processes" (bsc#1208593)
    It caused a regression on ALP-current branch, kernel-obs-qa build failed.
  - commit 35271c3

++++ kernel-firmware-all:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-amdgpu:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-ath10k:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-ath11k:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-ath12k:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-atheros:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-bluetooth:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-bnx2:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-brcm:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-chelsio:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-dpaa2:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-i915:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-intel:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-iwlwifi:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-liquidio:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-marvell:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-media:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-mediatek:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-mellanox:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-mwifiex:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-network:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-nfp:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-nvidia:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-platform:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-prestera:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-qcom:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-qlogic:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-radeon:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-realtek:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-serial:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-sound:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-ti:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-ueagle:

  - Update aliases from 6.9 TW kernels

++++ kernel-firmware-usb-network:

  - Update aliases from 6.9 TW kernels

++++ kernel-rt:

  - dmaengine: idxd: move safety flag to struct ends (bsc#1223625
    CVE-2024-21823).
  - dmaengine: idxd: add a write() method for applications to
    submit work (bsc#1223625 CVE-2024-21823).
  - dmaengine: idxd: add a new security check to deal with a
    hardware erratum (bsc#1223625 CVE-2024-21823).
  - VFIO: Add the SPR_DSA and SPR_IAX devices to the denylist
    (bsc#1223625 CVE-2024-21823).
  - commit 8718675
  - Update
    patches.suse/io_uring-af_unix-disable-sending-io_uring-over-socke.patch
    (bsc#1218447 CVE-2023-6531 CVE-2023-52654 bsc#1224099).
  - Update
    patches.suse/usb-aqc111-check-packet-for-fixup-for-true-limit.patch
    (git-fixes CVE-2023-52655 bsc#1217169).
  - commit 07c8bc1
  - octeontx2-pf: fix FLOW_DIS_IS_FRAGMENT implementation
    (git-fixes).
  - commit 78ec58d
  - net/mlx5: Fix peer devlink set for SF representor devlink port
    (git-fixes).
  - commit 6a691b6
  - net/mlx5: Lag, restore buckets number to default after hash
    LAG deactivation (git-fixes).
  - commit 19da0bb
  - net: sparx5: flower: fix fragment flags handling (git-fixes).
  - commit 5fd27e9
  - net: ena: Set tx_info->xdpf value to NULL (git-fixes).
  - commit 7d1d83a
  - net: ena: Fix incorrect descriptor free behavior (git-fixes).
  - commit 69577fd
  - net: ena: Wrong missing IO completions check order (git-fixes).
  - commit fbbd86e
  - net: ena: Fix potential sign extension issue (git-fixes).
  - commit b3cc5f8
  - net: dsa: mt7530: trap link-local frames regardless of ST Port
    State (git-fixes).
  - commit 726080b
  - net: sparx5: fix wrong config being used when reconfiguring PCS
    (git-fixes).
  - commit d2d1229
  - net/mlx5e: RSS, Block XOR hash with over 128 channels
    (git-fixes).
  - commit 40b1ccb
  - net/mlx5: Restore mistakenly dropped parts in register devlink
    flow (git-fixes).
  - commit dfb4099
  - btrfs: defrag: avoid unnecessary defrag caused by incorrect extent size (git-fixes)
  - commit a1c6e8c
  - btrfs: don't warn if discard range is not aligned to sector (git-fixes)
  - commit f239c2a
  - btrfs: tree-checker: fix inline ref size in error messages (git-fixes)
  - commit a304971
  - btrfs: defrag: reject unknown flags of btrfs_ioctl_defrag_range_args (git-fixes)
  - commit 81a1329
  - btrfs: do not allow non subvolume root targets for snapshot (git-fixes)
  - commit d495a4b
  - btrfs: send: ensure send_fd is writable (git-fixes)
  - commit 5055583
  - btrfs: free the allocated memory if btrfs_alloc_page_array() fails (git-fixes)
  - commit 532ad3c
  - btrfs: fix 64bit compat send ioctl arguments not initializing version member (git-fixes)
  - commit 2c30d15
  - btrfs: fix off-by-one when checking chunk map includes logical address (git-fixes)
  - commit e5842bb
  - btrfs: use u64 for buffer sizes in the tree search ioctls (git-fixes)
  - commit a1c6ed1
  - btrfs: error out when reallocating block for defrag using a stale transaction (git-fixes)
  - commit e6bb34b
  - btrfs: error when COWing block from a root that is being deleted (git-fixes)
  - commit 78a2694
  - btrfs: error out when COWing block using a stale transaction (git-fixes)
  - commit 850d86f
  - s390/cpum_cf: make crypto counters upward compatible across
    machine types (bsc#1224348).
  - commit 36c1e09
  - btrfs: always print transaction aborted messages with an error level (git-fixes)
  - commit 26fa5ae
  - net/mlx5e: Do not produce metadata freelist entries in Tx port
    ts WQE xmit (git-fixes).
  - commit 287b501
  - net/mlx5e: HTB, Fix inconsistencies with QoS SQs number
    (git-fixes).
  - commit 0085432
  - net/mlx5e: Fix mlx5e_priv_init() cleanup flow (git-fixes).
  - commit 01134b3
  - net/mlx5e: RSS, Block changing channels number when RXFH is
    configured (git-fixes).
  - commit c93a7d5
  - net/mlx5: Correctly compare pkt reformat ids (git-fixes).
  - commit 76a7159
  - net/mlx5: Properly link new fs rules into the tree (git-fixes).
  - commit 7272c33
  - net/mlx5: offset comp irq index in name by one (git-fixes).
  - commit 56809e4
  - net/mlx5: Register devlink first under devlink lock (git-fixes).
  - commit 3162538
  - net/mlx5: E-switch, store eswitch pointer before registering
    devlink_param (git-fixes).
  - commit d6f7fd4
  - ALSA: hda/realtek - fixed headset Mic not show (stable-fixes).
  - ALSA: hda: hda_cs_dsp_ctl: Remove notification of driver write
    (stable-fixes).
  - ALSA: Fix deadlocks with kctl removals at disconnection
    (stable-fixes).
  - ALSA: hda: clarify Copyright information (stable-fixes).
  - ALSA: hda/realtek: Add support for ASUS Zenbook 2024 HN7306W
    (stable-fixes).
  - ALSA: hda/realtek: Fix internal speakers for Legion Y9000X
    2022 IAH7 (stable-fixes).
  - ALSA: hda: Add Intel BMG PCI ID and HDMI codec vid
    (stable-fixes).
  - ALSA: hda: cs35l41: Add support for ASUS ROG 2024 Laptops
    (stable-fixes).
  - ALSA: hda: cs35l41: Ignore errors when configuring IRQs
    (stable-fixes).
  - ALSA: hda/realtek: Add quirks for Lenovo 13X (stable-fixes).
  - ALSA: hda: cs35l41: Support Lenovo 13X laptop without _DSD
    (stable-fixes).
  - ALSA: hda: cs35l41: Remove redundant argument to
    cs35l41_request_firmware_file() (stable-fixes).
  - ALSA: hda: cs35l41: Update DSP1RX5/6 Sources for DSP config
    (stable-fixes).
  - ALSA: hda/realtek: Add quirks for HP Omen models using CS35L41
    (stable-fixes).
  - ALSA: hda: cs35l41: Support HP Omen models without _DSD
    (stable-fixes).
  - ALSA: hda: cs35l41: Set the max PCM Gain using tuning setting
    (stable-fixes).
  - commit bd5e5fc
  - Add cherry-picked patch references to amdgpu patches
  - commit fb4ef8e
  - ALSA: hda/realtek: Drop doubly quirk entry for 103c:8a2e
    (git-fixes).
  - ASoC: tas2781: Fix a warning reported by robot kernel test
    (git-fixes).
  - ASoC: tracing: Export SND_SOC_DAPM_DIR_OUT to its value
    (git-fixes).
  - ASoC: Intel: avs: Test result of avs_get_module_entry()
    (git-fixes).
  - ASoC: Intel: avs: Fix potential integer overflow (git-fixes).
  - ASoC: Intel: avs: Fix ASRC module initialization (git-fixes).
  - ASoC: SOF: Intel: mtl: Implement firmware boot state check
    (git-fixes).
  - ASoC: SOF: Intel: lnl: Correct rom_status_reg (git-fixes).
  - ASoC: SOF: Intel: mtl: Correct rom_status_reg (git-fixes).
  - Revert "ASoC: SOF: Intel: hda-dai-ops: only allocate/release
    streams for first CPU DAI" (stable-fixes).
  - Revert "ASoC: SOF: Intel: hda-dai-ops: reset device count for
    SoundWire DAIs" (stable-fixes).
  - ASoC: kirkwood: Fix potential NULL dereference (git-fixes).
  - ASoC: Intel: avs: ssm4567: Do not ignore route checks
    (git-fixes).
  - ASoC: Intel: Disable route checks for Skylake boards
    (git-fixes).
  - ASoC: mediatek: Assign dummy when codec not specified for a
    DAI link (git-fixes).
  - ASoC: mediatek: mt8192: fix register configuration for tdm
    (git-fixes).
  - ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance (git-fixes).
  - ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup
    (git-fixes).
  - ALSA: hda: cs35l41: Remove Speaker ID for Lenovo Legion slim
    7 16ARHA7 (git-fixes).
  - fbdev: savage: Handle err return when savagefb_check_var failed
    (git-fixes).
  - fbdev: sh7760fb: allow modular build (git-fixes).
  - fbdev: sisfb: hide unused variables (git-fixes).
  - fbdev: shmobile: fix snprintf truncation (git-fixes).
  - drm: zynqmp_dpsub: Always register bridge (git-fixes).
  - Revert "drm/bridge: ti-sn65dsi83: Fix enable error path"
    (git-fixes).
  - drm/fbdev-generic: Do not set physical framebuffer address
    (git-fixes).
  - drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting
    fails (git-fixes).
  - drm/msm/adreno: fix CP cycles stat retrieval on a7xx
    (git-fixes).
  - drm/msm/dpu: Add callback function pointer check before its call
    (git-fixes).
  - drm/msm/dpu: Allow configuring multiple active DSC blocks
    (git-fixes).
  - drm/msm/dpu: Always flush the slave INTF on the CTL (git-fixes).
  - drm/msm/dsi: Print dual-DSI-adjusted pclk instead of original
    mode pclk (git-fixes).
  - drm/msm/dp: Avoid a long timeout for AUX transfer if nothing
    connected (git-fixes).
  - drm/msm/dp: allow voltage swing / pre emphasis of 3 (git-fixes).
  - drm/mediatek: dp: Fix mtk_dp_aux_transfer return value
    (git-fixes).
  - drm/mediatek: Init `ddp_comp` with devm_kcalloc() (git-fixes).
  - drm/mediatek: Add 0 size check to mtk_drm_gem_obj (git-fixes).
  - drm/bridge: tc358775: fix support for jeida-18 and jeida-24
    (git-fixes).
  - drm/meson: gate px_clk when setting rate (git-fixes).
  - drm/rockchip: vop2: Do not divide height twice for YUV
    (git-fixes).
  - drm/panel: simple: Add missing Innolux G121X1-L03 format,
    flags, connector (git-fixes).
  - drm/bridge: anx7625: Update audio status while detecting
    (git-fixes).
  - drm/panel: novatek-nt35950: Don't log an error when DSI host
    can't be found (git-fixes).
  - drm/bridge: dpc3433: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: tc358775: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: lt9611uxc: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: lt9611: Don't log an error when DSI host can't be
    found (git-fixes).
  - drm/bridge: lt8912b: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: icn6211: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm/bridge: anx7625: Don't log an error when DSI host can't
    be found (git-fixes).
  - drm: vc4: Fix possible null pointer dereference (git-fixes).
  - drm/arm/malidp: fix a possible null pointer dereference
    (git-fixes).
  - drm/amd/display: Remove redundant condition in
    dcn35_calc_blocks_to_gate() (git-fixes).
  - drm/amd/display: Fix potential index out of bounds in color
    transformation function (git-fixes).
  - drm: bridge: cdns-mhdp8546: Fix possible null pointer
    dereference (git-fixes).
  - drm/meson: vclk: fix calculation of 59.94 fractional rates
    (git-fixes).
  - drm/panel: ltk050h3146w: drop duplicate commands from
    LTK050H3148W init (git-fixes).
  - drm/panel: ltk050h3146w: add MIPI_DSI_MODE_VIDEO to LTK050H3148W
    flags (git-fixes).
  - drm/lcdif: Do not disable clocks on already suspended hardware
    (git-fixes).
  - drm/omapdrm: Fix console by implementing fb_dirty (git-fixes).
  - drm/nouveau/dp: Fix incorrect return code in r535_dp_aux_xfer()
    (git-fixes).
  - drm/ci: update device type for volteer devices (git-fixes).
  - drm/bridge: Fix improper bridge init order with
    pre_enable_prev_first (git-fixes).
  - commit e7d2777
  - Revert "selinux: introduce an initial SID for early boot processes" (bsc#1208593)
    It caused a regression on ALP-current branch, kernel-obs-qa build failed.
  - commit 35271c3

++++ util-linux-systemd:

  - add support for pidfs in kernel 6.9 (bsc#1224285)
    * 0001-include-Include-unistd.h-in-pidfd-utils.h-for-syscal.patch
    * 0002-lsfd-Refactor-the-pidfd-logic-into-lsfd-pidfd.c.patch
    * 0003-lsfd-Support-pidfs.patch
    * 0004-lsfd-test-Adapt-test-cases-for-pidfs.patch

++++ ledmon:

  - Re-arrange spec files block to be in line with all other openSUSE
    spec files.

++++ util-linux:

  - add support for pidfs in kernel 6.9 (bsc#1224285)
    * 0001-include-Include-unistd.h-in-pidfd-utils.h-for-syscal.patch
    * 0002-lsfd-Refactor-the-pidfd-logic-into-lsfd-pidfd.c.patch
    * 0003-lsfd-Support-pidfs.patch
    * 0004-lsfd-test-Adapt-test-cases-for-pidfs.patch

++++ libguestfs:

  - Update to version 1.52.1 bug fix release (jsc#PED-6305)
    * There are no upstream release notes for verion 1.52.x
    * Several python fixes
    * Rework Std_utils.Option so it works like the OCaml stdlib module
    * Update common submodule to latest
  - Drop patches contained in new tarball
    Split-chown-parameter-on-character.patch
    Initialise-bar-fp-as-NULL.patch

++++ harfbuzz:

  - update to version 8.5.0:
    + API for partial instancing is now stable and have been promoted
    out of experimental APIs.
    + Support instancing “BASE” table
    + Speedup AAT shaping by 13–30%
    + Various subsetter and instancer fixes

++++ samba:

  - Update to 4.20.1
    * dns update debug message is too noisy; (bso#15630);
    * Do not fail PAC validation for RFC8009 checksums types; (bso#15635);
    * Improve performance of lookup_groupmem() in idmap_ad; (bso#15605);
    * Smbcacls incorrectly propagates inheritance with Inherit-Only flag; (bso#15636);
    * http library doesn't support 'chunked transfer encoding'; (bso#15611);
    * Provide a systemd service file for the background queue daemon; (bso#15600);
  - Update to 4.20.0
    New features:
    * samba-tool user getpassword / syncpasswords ;rounds= change
    * Group Managed service account client-side features
    * New Windows Search Protocol Client
    * Allow 'smbcacls' to save/restore DACLs to file
    * Samba-tool extensions for AD Claims, Authentication Policies and Silos
    * AD DC support for Authentication Silos and Authentication Policies
    * Conditional ACEs and Resource Attribute ACEs
    * Service Witness Protocol [MS-SWN]
    Removed features:
    * Get locally logged on users from utmp
    Fixed bugs:
    * Avoid null-dereference with bad claims; (bso#15606);
    * ndr_pull_security_ace can leave resource attribute ACE coda
    claim struct undefined; (bso#15613);
    * fd_handle_destructor() panics within an smbd_smb2_close() if
    vfs_stat_fsp() fails in fd_close(); (bso#15527);
    * set_nt_acl sometimes fails with NT_STATUS_INVALID_PARAMETER -
    openat() EACCES; (bso#15583);
    * libgpo: Segfault in python bindings; (bso#15599);
    * Samba AD is missing some authentication policy tests;
    (bso#15607);
    * samba-gpupdate: Correctly implement site support; (bso#15588);
    * Remove unsupported "Final" keyword missing from Python 3.6;
    (bso#15575);
    * Additional witness backports for 4.20.0; (bso#15577);
    * Error output with wspsearch; (bso#15579);
    * Packet marshalling push support missing for
    CTDB_CONTROL_TCP_CLIENT_DISCONNECTED and
    CTDB_CONTROL_TCP_CLIENT_PASSED; (bso#15580);
    * Performance regression for NDR parsing of security
    descriptors; (bso#15574);
    * Build and install man page for wspsearch client utility;
    (bso#15565);

++++ sssd:

  - Update to release 2.9.5
    * Added failover_primary_timout configuration option. This can
    be used to configure how often SSSD tries to reconnect to a
    primary server after a successful connection to a backup
    server. This was previously hardcoded to 31 seconds which is
    kept as the default value.

++++ systemd:

  - systemd.spec: enable unit tests during build
  - Import commit 3ea0e1dff3d7ca74c072cdcc8b371034125803d6
    3ea0e1dff3 test/test-rpm-macros.sh: add build directory to pkg-config search path
    1cbf1c82b5 libsystemd-network: skip dhcp server test in case of EAFNOSUPPORT
    38f7ac60db sd-event: increase test-event timeout to 120s

++++ talloc:

  - Update to 2.4.2
    * build with Python 3.12 (bso#15513)
    * documentation fixes
    * Update patch talloc-python3.5-fix-soabi_name.patch

++++ tdb:

  - Update to 1.4.10
    * build with Python 3.12 (bso#15513)
    * documentation fixes
    * minor build fixes

++++ tevent:

  - Update to version 0.16.1
    * build with Python 3.12 (bso#15513)
    * documentation fixes

++++ vulkan-loader:

  - Update to release SDK-1.3.283.0
    * Bugfixes for Windows

++++ lsof:

  - add (bsc#1224285):
    * 0001-tests-eliminate-use-of-fgrep.patch
    * 0002-tests-fix-for-kernel-6.9.patch

++++ openSUSE-repos-LeapMicro:

  - Update to version 20240516.5431918:
    * Update README.md
    * ci: Use bash for repo_checks to not rely on shebang
    * t: Add diagnostic to leap test
    * Add ci
    * Add basic url_checker
    * repo_checks: Add handling for Leap and Leap Micro
    * Drop Leap armv7hl debug repo definitions boo#1224217
    * Use Leap source repo for Leap 15 ports
    * Fix urls for leap-ports (32 bit arm)
    * Create repo_checks.yml
    * rename url_checker to repo_checks
    * Drop leap16 definitions for now to get url_checker working

++++ osinfo-db:

  - Update to database version 20240510
    osinfo-db-20240510.tar.xz

++++ qemu:

  - Update to version 8.2.4. Full changelog/backports here:
    https://lore.kernel.org/qemu-devel/1715632914.382233.1013785.nullmailer@tls.msk.ru/
    Some of the upstream backports are:
    target/sh4: Fix SUBV opcode
    target/sh4: Fix ADDV opcode
    hw/arm/npcm7xx: Store derivative OTP fuse key in little endian
    hw/dmax/xlnx_dpdma: fix handling of address_extension descriptor fields
    hw/ufs: Fix buffer overflow bug
    tests/avocado: update sunxi kernel from armbian to 6.6.16
    target/loongarch/cpu.c: typo fix: expection
    backends/cryptodev-builtin: Fix local_error leaks
    nbd/server: Mark negotiation functions as coroutine_fn
    nbd/server: do not poll within a coroutine context
    linux-user: do_setsockopt: fix SOL_ALG.ALG_SET_KEY
    target/riscv/kvm: change timer regs size to u64
    target/riscv/kvm: change KVM_REG_RISCV_FP_D to u64
    target/riscv/kvm: change KVM_REG_RISCV_FP_F to u32
    ...

++++ rust-keylime:

  - Update to version 0.2.5~4:
    * Fix 'unnecessary qualification' warnings
    * fix IAK template to match IDevID
    * rpm: fix COPR RPMs build for centos-stream-10
    * Build COPR RPMs for centos-stream-10

++++ ucode-amd:

  - Update aliases from 6.9 TW kernels

++++ vim:

  - update to 9.1.0413
    * smoothscroll may cause infinite loop
    * add missing entries for the keys CTRL-W g<Tab> and <C-Tab>
    * update vi_diff.txt: add default value for 'flash'
    * typo in regexp_bt.c in DEBUG code
    * allow indented commands
    * Fix wrong define regex in ftplugin
    * Filter out non-Latin-1 characters for syntax tests
    * prefer scp over pscp
    * fix typo in usr_52.txt
    * too long functions in eval.c
    * warning about uninitialized variable
    * too many strlen() calls in the regexp engine
    * E16 fix, async keyword support for define
    * Stuck with long line and half-page scrolling
    * Divide by zero with getmousepos() and 'smoothscroll'
    * update and remove  some invalid links
    * update translation of xxd manpage
    * Recursively delete directories by default with netrw delete command
    * Strive to remain compatible for at least Vim 7.0
    * tests: xxd buffer overflow fails on 32-bit
    * Stop handpicking syntax groups for @javaTop
    * [security] xxd: buffer-overflow with specific flags
    * Vim9: not able to import file from start dir
    * filetype: mdd files detected as zsh filetype
    * filetype: zsh module files are not recognized
    * Remove hardcoded private.ppk logic from netrw
    * Vim9: confusing error message for unknown type
    * block_editing errors out when using del
    * add new items to scripts section in syntax plugin
    * Vim9: imported vars are not properly type checked
    * Wrong display with 'smoothscroll' when changing quickfix list
    * filetype: jj files are not recognized
    * getregionpos() may leak memory on error
    * The CODEOWNERS File is not useful
    * Remove and cleanup Win9x legacy from netrw
    * add MsgArea to 'highlight' option description
    * Cannot get a list of positions describing a region
    * Fix digit separator in syntax script for octals and floats
    * Update link to Wikipedia Vi page
    * clear $MANPAGER in ftplugin before shelling out
    * Fix typos in help documents
    * 'viewdir' not respecting $XDG_CONFIG_HOME
    * tests: Vim9 debug tests may be flaky
    * correct getscriptinfo() example
    * Vim9: could improve testing
    * test_sound fails on macos-12
    * update Serbian menu
    * update Slovak menu
    * update Slovenian menu
    * update Portuguese menu
    * update Dutch menu
    * update Korean menu
    * update Icelandic menu
    * update Czech menu
    * update Afrikaans menu
    * update German menu
    * filetype: inko files are not recognized
    * filetype: templ files are not recognized
    * cursor() and getregion() don't handle v:maxcol well
    * Vim9: null value tests not sufficient
    * update Catalan menu
    * filetype: stylus files not recognized
    * update spanish menu localization
    * regenerate helptags
    * Vim9: crash with null_class and null_object
    * Add tags about lazyloading of menu
    * tests: vt420 terminfo entry may not be found
    * filetype: .out files recognized as tex files
    * filetype: Kbuild files are not recognized
    * cbuffer and similar commands don't accept a range
    * Improve the recognition of the "indent" method declarations
    * Fix a typo in usr_30.txt
    * remove undefined var s:save_cpoptions and add include setting
    * missing setlocal in indent plugin
    * Calculating line height for unnecessary amount of lines
    * improve syntax file performance
    * There are a few typos
    * Vim9: no comments allowed after class vars
    * CI: remove trailing white space in documentation
    * Formatting text wrong when 'breakindent' is set
    * Add oracular (24.10) as Ubuntu release name
    * Vim9: Trailing commands after class/enum keywords ignored
    * tests: 1-second delay after Test_BufEnter_botline()
    * update helptags for jq syntax
    * include syntax, ftplugin and compiler plugin
    * fix typo synconcealend -> synconcealed
    * include a simple comment toggling plugin
    * wrong botline in BufEnter
    * clarify syntax vs matching mechanism
    * fix undefined variable in indent plugin
    * ops.c code uses too many strlen() calls
    * Calling CLEAR_FIELD() on the same struct twice
    * Vim9: compile_def_function() still too long
    * Update Serbian messages
    * clarify the effect of setting the shell to powershell
    * Improve the recognition of the "style" method declarations
    * Vim9: problem when importing autoloaded scripts
    * compile_def_function is too long
    * filetype: ondir files are not recognized
    * Crash when typing many keys with D- modifier
    * tests: test_vim9_builtin is a bit slow
    * update documentation
    * change the download URL of "libsodium"
    * tests: test_winfixbuf is a bit slow
    * Add filetype, syntax and indent plugin for Astro
    * expanding rc config files does not work well
    * Vim9: vim9type.c is too complicated
    * Vim9: does not handle autoloaded variables well
    * minor spell fix in starting.txt
    * wrong drawing in GUI with setcellwidth()
    * Add include and suffixesadd
    * Page scrolling should place cursor at window boundaries
    * align command line table
    * minor fixes to starting.txt
    * fix comment definition in filetype plugin
    * filetype: flake.lock files are not recognized
    * runtime(uci): No support for uci file types
    * Support "g:ftplugin_java_source_path" with archived files
    * tests: Test_autoload_import_relative_compiled fails on Windows
    * Finding cmd modifiers and cmdline-specials is inefficient
    * No test that completing a partial mapping clears 'showcmd'
    * tests: test_vim9_dissamble may fail
    * Vim9: need static type for typealias
    * X11 does not ignore smooth scroll event
    * A few typos in test_xdg when testing gvimrc
    * Patch v9.1.0338 fixed sourcing a script with import
    * Problem: gvimrc not sourced from XDG_CONFIG_HOME
    * Cursor wrong after using setcellwidth() in terminal
    * 'showcmd' wrong for partial mapping with multibyte
    * tests: test_taglist fails when 'helplang' contains non-english
    * Problem: a few memory leaks are found
    * Problem: Error with matchaddpos() and empty list
    * tests: xdg test uses screen dumps
    * Vim9: import through symlinks not correctly handled
    * Missing entry for XDG vimrc file in :version
    * tests: typo in test_xdg
    * runtime(i3config/swayconfig): update syntax scripts
    * document pandoc compiler and enable configuring arguments
    * String interpolation fails for List type
    * No test for highlight behavior with 'ambiwidth'
    * tests: test_xdg fails on the appimage repo
    * tests: some assert_equal() calls have wrong order of args
    * make install does not install all files
    * runtime(doc): fix typos in starting.txt

++++ virt-manager:

  - Upstream bug fixes (bsc#1027942) (jsc#PED-6305)
    063-Support-creating-sparse-volumes-on-ZFS-pools.patch
    064-domain-rename-handle-firmware-ending-with-.qcow2.patch
    065-testdriver-Add-portgroups-example-to-test-many-devices.patch
    066-netlist-Fix-UI-error-when-virtual-network-doesnt-exist.patch
    067-ui-details-fix-Applications-width.patch
    068-ui-details-Increased-scrolledview6s-height-request.patch
    069-uitests-Fix-walkUI-flakyness.patch
    070-uitests-Handle-slow-app-launch-on-fedora-39.patch
    071-createvm-Replace-deprecated-pkgutil.find_loader.patch
    072-Fix-pylint-3.1.0-issues.patch
    073-console-Move-embeddable_graphics-to-console.py.patch
    074-domain-Add-idx-parameter-to-open_graphics_fd.patch
    075-console-Select-the-first-embeddable-graphics-device-as-graphical-console.patch
    076-console-Cleanup-and-improve-console-menu-handling.patch
    077-cli-add-show-systray-option.patch
    078-man-document-show-systray-option.patch
    079-baseclass-Avoid-glib-Source-ID-XX-not-found-at-app-shutdown.patch
    080-uitests-More-handling-for-slow-startup-on-f39.patch
    081-systray-Cleanups-and-improvements-for-show-systray.patch
    082-virtinst-add-external-snapshot-capability.patch
    083-virtinst-snapshot-add-memory-file-attribute.patch
    084-virtManager-domain-allow-disk-only-snapshots.patch
    085-virtManager-add-support-to-create-external-snapshots.patch
    086-virtManager-ignore-agen-livecycle-event-for-shutoff-VMs.patch
    087-Allow-serial-console-resize-to-beyond-80-columns.patch
  - Modifications to the Categories in virt-install.desktop and
    virtman-desktop.patch

------------------------------------------------------------------
------------------  2024-5-15  -  May 15 2024  -------------------
------------------------------------------------------------------

++++ gdk-pixbuf:

  - Update to version 2.42.12:
    + Fix a build failure,
    + Fix occasional build failures,
    + ani: Reject files with multiple INA or IART chunks,
    + ani: Reject files with multiple anih chunks (CVE-2022-48622),
    + ani: validate chunk size,
    + Updated translations.
  - Drop 238893d8cd6f9c2616a05ab521a29651a17a38c2.patch: fixed
    upstream.

++++ grub2:

  - Update to the latest upstreaming TPM2 patches
    * 0001-key_protector-Add-key-protectors-framework.patch
  - Replace 0001-protectors-Add-key-protectors-framework.patch
    * 0002-tpm2-Add-TPM-Software-Stack-TSS.patch
  - Merge other TSS patches
    * 0001-tpm2-Add-TPM2-types-structures-and-command-constants.patch
    * 0002-tpm2-Add-more-marshal-unmarshal-functions.patch
    * 0003-tpm2-Implement-more-TPM2-commands.patch
    * 0003-key_protector-Add-TPM2-Key-Protector.patch
  - Replace 0003-protectors-Add-TPM2-Key-Protector.patch
    * 0004-cryptodisk-Support-key-protectors.patch
    * 0005-util-grub-protect-Add-new-tool.patch
    * 0001-tpm2-Support-authorized-policy.patch
  - Replace 0004-tpm2-Support-authorized-policy.patch
    * 0001-tpm2-Add-extra-RSA-SRK-types.patch
    * 0001-tpm2-Implement-NV-index.patch
  - Replace 0001-protectors-Implement-NV-index.patch
    * 0002-cryptodisk-Fallback-to-passphrase.patch
    * 0003-cryptodisk-wipe-out-the-cached-keys-from-protectors.patch
    * 0004-diskfilter-look-up-cryptodisk-devices-first.patch
  - Refresh affected patches
    * 0001-Improve-TPM-key-protection-on-boot-interruptions.patch
    * grub2-bsc1220338-key_protector-implement-the-blocklist.patch
  - New manpage for grub2-protect
  - Fix error in /etc/grub.d/20_linux_xen: file_is_not_sym not found, renamed to
    file_is_not_xen_garbage (bsc#1224226)
    * grub2-fix-menu-in-xen-host-server.patch

++++ hwdata:

  - update to 0.382:
    * Update pci, usb and vendor ids

++++ kernel-default:

  - powerpc/eeh: Permanently disable the removed device (bsc#1223991
    ltc#205740).
  - commit b9c2f2f
  - fat: fix uninitialized field in nostale filehandles (git-fixes)
  - commit f1e1fd7
  - net: ks8851: Queue RX packets in IRQ handler instead of
    disabling BHs (git-fixes).
  - commit cc9313f
  - Move upstreamed ACPI patch into sorted section
  - commit 6c48aae
  - fs: relax mount_setattr() permission checks (git-fixes)
  - commit 3b377cf
  - bpf, arm64: Fix incorrect runtime stats (git-fixes)
  - commit c30a258
  - fast_dput(): handle underflows gracefully (git-fixes)
  - commit 7a48807
  - ecryptfs: Reject casefold directory inodes (git-fixes)
  - commit bc23622
  - fsverity: skip PKCS#7 parser when keyring is empty (git-fixes)
  - commit 97f203b
  - cifs: fix underflow in parse_server_interfaces() (CVE-2024-26828 bsc#1223084).
  - commit 40aba68
  - octeontx2-af: Fix NIX SQ mode and BP config (git-fixes).
  - commit 6fa6e4e
  - net: ks8851: Handle softirqs at the end of IRQ thread to fix
    hang (git-fixes).
  - commit 871b504
  - net: ks8851: Inline ks8851_rx_skb() (git-fixes).
  - commit 0fafe3f
  - bnxt_en: Reset PTP tx_avail after possible firmware reset
    (git-fixes).
  - commit 9421aa8
  - bnxt_en: Fix error recovery for RoCE ulp client (git-fixes).
  - commit a747a74
  - bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init()
    (git-fixes).
  - commit 6a62a82
  - geneve: fix header validation in geneve[6]_xmit_skb (git-fixes).
  - commit d4d699c
  - octeontx2-pf: Fix transmit scheduler resource leak (git-fixes).
  - commit 9beffaf
  - net/mlx5: SF, Stop waiting for FW as teardown was called
    (git-fixes).
  - commit 2583247
  - mlxsw: Use refcount_t for reference counting (git-fixes).
  - commit 5be65d6
  - net: ena: Use tx_ring instead of xdp_ring for XDP channel TX
    (git-fixes).
  - commit d4b3628
  - net: ena: Pass ena_adapter instead of net_device to
    ena_xmit_common() (git-fixes).
  - commit c080c13
  - net: ena: Move XDP code to its new files (git-fixes).
  - commit 7cd4a35
  - net: openvswitch: Fix Use-After-Free in ovs_ct_exit (bsc#1224098
    CVE-2024-27395).
  - commit a237c4c
  - selinux: introduce an initial SID for early boot processes
    (bsc#1208593).
  - commit a82f05c
  - mctp: perform route lookups under a RCU read-side lock
    (CVE-2023-52483 bsc#1220738).
  - commit 659b74f
  - net: gtp: Fix Use-After-Free in gtp_dellink (bsc#1224096
    CVE-2024-27396).
  - commit 7f59223
  - Move upstreamed patches into sorted section
  - commit 25085d6
  - wifi: iwlwifi: mvm: fix check in iwl_mvm_sta_fw_id_mask
    (git-fixes).
  - commit 61c5310
  - ax25: Fix reference count leak issue of net_device (git-fixes).
  - ax25: Fix reference count leak issues of ax25_dev (git-fixes).
  - net: usb: ax88179_178a: fix link status when link is set to
    down/up (git-fixes).
  - selftests: net: move amt to socat for better compatibility
    (git-fixes).
  - Bluetooth: qca: Fix error code in qca_read_fw_build_info()
    (git-fixes).
  - net: usb: smsc95xx: stop lying about skb->truesize (git-fixes).
  - wifi: mwl8k: initialize cmd->addr[] properly (git-fixes).
  - wifi: rtw89: pci: correct TX resource checking for PCI DMA
    channel of firmware command (git-fixes).
  - wifi: ar5523: enable proper endpoint verification (git-fixes).
  - wifi: carl9170: add a proper sanity check for endpoints
    (git-fixes).
  - wifi: ath10k: populate board data for WCN3990 (git-fixes).
  - wifi: ath10k: Fix an error code problem in
    ath10k_dbg_sta_write_peer_debug_trigger() (git-fixes).
  - wifi: ath12k: fix out-of-bound access of qmi_invoke_handler()
    (git-fixes).
  - wifi: carl9170: re-fix fortified-memset warning (git-fixes).
  - wifi: mt76: mt7603: add wpdma tx eof flag for PSE client reset
    (git-fixes).
  - wifi: mt76: mt7603: fix tx queue of loopback packets
    (git-fixes).
  - net: usb: sr9700: stop lying about skb->truesize (git-fixes).
  - usb: aqc111: stop lying about skb->truesize (git-fixes).
  - wifi: iwlwifi: mvm: init vif works only once (git-fixes).
  - net: nfc: remove inappropriate attrs check (stable-fixes).
  - wifi: ath11k: don't force enable power save on non-running vdevs
    (git-fixes).
  - wifi: ath10k: poll service ready message before failing
    (git-fixes).
  - wifi: iwlwifi: reconfigure TLC during HW restart (git-fixes).
  - wifi: iwlwifi: mvm: select STA mask only for active links
    (git-fixes).
  - wifi: iwlwifi: mvm: fix active link counting during recovery
    (git-fixes).
  - wifi: iwlwifi: mvm: allocate STA links only for active links
    (git-fixes).
  - wifi: ieee80211: fix ieee80211_mle_basic_sta_prof_size_ok()
    (git-fixes).
  - wifi: mt76: mt7915: workaround too long expansion sparse
    warnings (git-fixes).
  - wifi: brcmfmac: pcie: handle randbuf allocation failure
    (git-fixes).
  - bitops: add missing prototype check (git-fixes).
  - ata: pata_legacy: make legacy_exit() work again (git-fixes).
  - efi: libstub: only free priv.runtime_map when allocated
    (git-fixes).
  - HID: amd_sfh: Handle "no sensors" in PM operations (git-fixes).
  - HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors
    (git-fixes).
  - hwmon: (lm70) fix links in doc and comments (git-fixes).
  - spi: xilinx: Fix kernel documentation in the xilinx_spi.h
    (git-fixes).
  - ACPI: LPSS: Advertise number of chip selects via property
    (git-fixes).
  - ACPI: bus: Indicate support for IRQ ResourceSource thru _OSC
    (git-fixes).
  - ACPI: Fix Generic Initiator Affinity _OSC bit (git-fixes).
  - ACPI: bus: Indicate support for the Generic Event Device thru
    _OSC (git-fixes).
  - ACPI: bus: Indicate support for _TFP thru _OSC (git-fixes).
  - ACPI: disable -Wstringop-truncation (git-fixes).
  - cpufreq: brcmstb-avs-cpufreq: ISO C90 forbids mixed declarations
    (git-fixes).
  - cppc_cpufreq: Fix possible null pointer dereference (git-fixes).
  - cpufreq: exit() callback is optional (git-fixes).
  - thermal/drivers/tsens: Fix null pointer dereference (git-fixes).
  - thermal/drivers/qcom/lmh: Check for SCM availability at probe
    (git-fixes).
  - selftests: default to host arch for LLVM builds (git-fixes).
  - selftests/resctrl: fix clang build failure: use LOCAL_HDRS
    (git-fixes).
  - selftests/binderfs: use the Makefile's rules, not Make's
    implicit rules (git-fixes).
  - irqchip/loongson-pch-msi: Fix off-by-one on allocation error
    path (git-fixes).
  - irqchip/alpine-msi: Fix off-by-one in allocation error path
    (git-fixes).
  - commit ea6926d

++++ kernel-rt:

  - powerpc/eeh: Permanently disable the removed device (bsc#1223991
    ltc#205740).
  - commit b9c2f2f
  - fat: fix uninitialized field in nostale filehandles (git-fixes)
  - commit f1e1fd7
  - net: ks8851: Queue RX packets in IRQ handler instead of
    disabling BHs (git-fixes).
  - commit cc9313f
  - Move upstreamed ACPI patch into sorted section
  - commit 6c48aae
  - fs: relax mount_setattr() permission checks (git-fixes)
  - commit 3b377cf
  - bpf, arm64: Fix incorrect runtime stats (git-fixes)
  - commit c30a258
  - fast_dput(): handle underflows gracefully (git-fixes)
  - commit 7a48807
  - ecryptfs: Reject casefold directory inodes (git-fixes)
  - commit bc23622
  - fsverity: skip PKCS#7 parser when keyring is empty (git-fixes)
  - commit 97f203b
  - cifs: fix underflow in parse_server_interfaces() (CVE-2024-26828 bsc#1223084).
  - commit 40aba68
  - octeontx2-af: Fix NIX SQ mode and BP config (git-fixes).
  - commit 6fa6e4e
  - net: ks8851: Handle softirqs at the end of IRQ thread to fix
    hang (git-fixes).
  - commit 871b504
  - net: ks8851: Inline ks8851_rx_skb() (git-fixes).
  - commit 0fafe3f
  - bnxt_en: Reset PTP tx_avail after possible firmware reset
    (git-fixes).
  - commit 9421aa8
  - bnxt_en: Fix error recovery for RoCE ulp client (git-fixes).
  - commit a747a74
  - bnxt_en: Fix possible memory leak in bnxt_rdma_aux_device_init()
    (git-fixes).
  - commit 6a62a82
  - geneve: fix header validation in geneve[6]_xmit_skb (git-fixes).
  - commit d4d699c
  - octeontx2-pf: Fix transmit scheduler resource leak (git-fixes).
  - commit 9beffaf
  - net/mlx5: SF, Stop waiting for FW as teardown was called
    (git-fixes).
  - commit 2583247
  - mlxsw: Use refcount_t for reference counting (git-fixes).
  - commit 5be65d6
  - net: ena: Use tx_ring instead of xdp_ring for XDP channel TX
    (git-fixes).
  - commit d4b3628
  - net: ena: Pass ena_adapter instead of net_device to
    ena_xmit_common() (git-fixes).
  - commit c080c13
  - net: ena: Move XDP code to its new files (git-fixes).
  - commit 7cd4a35
  - net: openvswitch: Fix Use-After-Free in ovs_ct_exit (bsc#1224098
    CVE-2024-27395).
  - commit a237c4c
  - selinux: introduce an initial SID for early boot processes
    (bsc#1208593).
  - commit a82f05c
  - mctp: perform route lookups under a RCU read-side lock
    (CVE-2023-52483 bsc#1220738).
  - commit 659b74f
  - net: gtp: Fix Use-After-Free in gtp_dellink (bsc#1224096
    CVE-2024-27396).
  - commit 7f59223
  - Move upstreamed patches into sorted section
  - commit 25085d6
  - wifi: iwlwifi: mvm: fix check in iwl_mvm_sta_fw_id_mask
    (git-fixes).
  - commit 61c5310
  - ax25: Fix reference count leak issue of net_device (git-fixes).
  - ax25: Fix reference count leak issues of ax25_dev (git-fixes).
  - net: usb: ax88179_178a: fix link status when link is set to
    down/up (git-fixes).
  - selftests: net: move amt to socat for better compatibility
    (git-fixes).
  - Bluetooth: qca: Fix error code in qca_read_fw_build_info()
    (git-fixes).
  - net: usb: smsc95xx: stop lying about skb->truesize (git-fixes).
  - wifi: mwl8k: initialize cmd->addr[] properly (git-fixes).
  - wifi: rtw89: pci: correct TX resource checking for PCI DMA
    channel of firmware command (git-fixes).
  - wifi: ar5523: enable proper endpoint verification (git-fixes).
  - wifi: carl9170: add a proper sanity check for endpoints
    (git-fixes).
  - wifi: ath10k: populate board data for WCN3990 (git-fixes).
  - wifi: ath10k: Fix an error code problem in
    ath10k_dbg_sta_write_peer_debug_trigger() (git-fixes).
  - wifi: ath12k: fix out-of-bound access of qmi_invoke_handler()
    (git-fixes).
  - wifi: carl9170: re-fix fortified-memset warning (git-fixes).
  - wifi: mt76: mt7603: add wpdma tx eof flag for PSE client reset
    (git-fixes).
  - wifi: mt76: mt7603: fix tx queue of loopback packets
    (git-fixes).
  - net: usb: sr9700: stop lying about skb->truesize (git-fixes).
  - usb: aqc111: stop lying about skb->truesize (git-fixes).
  - wifi: iwlwifi: mvm: init vif works only once (git-fixes).
  - net: nfc: remove inappropriate attrs check (stable-fixes).
  - wifi: ath11k: don't force enable power save on non-running vdevs
    (git-fixes).
  - wifi: ath10k: poll service ready message before failing
    (git-fixes).
  - wifi: iwlwifi: reconfigure TLC during HW restart (git-fixes).
  - wifi: iwlwifi: mvm: select STA mask only for active links
    (git-fixes).
  - wifi: iwlwifi: mvm: fix active link counting during recovery
    (git-fixes).
  - wifi: iwlwifi: mvm: allocate STA links only for active links
    (git-fixes).
  - wifi: ieee80211: fix ieee80211_mle_basic_sta_prof_size_ok()
    (git-fixes).
  - wifi: mt76: mt7915: workaround too long expansion sparse
    warnings (git-fixes).
  - wifi: brcmfmac: pcie: handle randbuf allocation failure
    (git-fixes).
  - bitops: add missing prototype check (git-fixes).
  - ata: pata_legacy: make legacy_exit() work again (git-fixes).
  - efi: libstub: only free priv.runtime_map when allocated
    (git-fixes).
  - HID: amd_sfh: Handle "no sensors" in PM operations (git-fixes).
  - HID: intel-ish-hid: ipc: Add check for pci_alloc_irq_vectors
    (git-fixes).
  - hwmon: (lm70) fix links in doc and comments (git-fixes).
  - spi: xilinx: Fix kernel documentation in the xilinx_spi.h
    (git-fixes).
  - ACPI: LPSS: Advertise number of chip selects via property
    (git-fixes).
  - ACPI: bus: Indicate support for IRQ ResourceSource thru _OSC
    (git-fixes).
  - ACPI: Fix Generic Initiator Affinity _OSC bit (git-fixes).
  - ACPI: bus: Indicate support for the Generic Event Device thru
    _OSC (git-fixes).
  - ACPI: bus: Indicate support for _TFP thru _OSC (git-fixes).
  - ACPI: disable -Wstringop-truncation (git-fixes).
  - cpufreq: brcmstb-avs-cpufreq: ISO C90 forbids mixed declarations
    (git-fixes).
  - cppc_cpufreq: Fix possible null pointer dereference (git-fixes).
  - cpufreq: exit() callback is optional (git-fixes).
  - thermal/drivers/tsens: Fix null pointer dereference (git-fixes).
  - thermal/drivers/qcom/lmh: Check for SCM availability at probe
    (git-fixes).
  - selftests: default to host arch for LLVM builds (git-fixes).
  - selftests/resctrl: fix clang build failure: use LOCAL_HDRS
    (git-fixes).
  - selftests/binderfs: use the Makefile's rules, not Make's
    implicit rules (git-fixes).
  - irqchip/loongson-pch-msi: Fix off-by-one on allocation error
    path (git-fixes).
  - irqchip/alpine-msi: Fix off-by-one in allocation error path
    (git-fixes).
  - commit ea6926d

++++ lzo:

  - Use %autosetup macro: allows us to eliminate usage of deprecated
    %patchN syntax.

++++ systemd:

  - systemd.spec: update the minimal required version of dracut. Also drop
    conflicts with mkinitrd: this package has been removed since quite some time
    now.

++++ python-pyudev:

  - Update to 0.24.3:
    * Tidies and Maintenance fixes
  - Switch to pyproject macros.
  - No more greedy globs in %files.
  - Add patch support-pytest-8.patch:
    * Support pytest 8 changes.

++++ ovmf:

  - Removed ovmf-UefiCpuPkg-BaseXApicX2ApicLib-fix-CPUID_V2_EXTENDED_.patch
    file which is merged to edk2-stable202311:
  - 170d4ce8e90a UefiCpuPkg/BaseXApicX2ApicLib: fix CPUID_V2_EXTENDED_TOPOLOGY detection

++++ strace:

  - Update to strace 6.9
    * Implemented --always-show-pid option.
    * The --user|-u option has learned to recognize numeric UID:GID pair, allowing
    e.g. statically-built strace to be used without invoking nss plugins.
    * Implemented decoding of IORING_REGISTER_SYNC_CANCEL,
    IORING_REGISTER_FILE_ALLOC_RANGE, IORING_REGISTER_PBUF_STATUS,
    IORING_REGISTER_NAPI, and IORING_UNREGISTER_NAPI opcodes of
    io_uring_register syscall.
    * Implemented decoding of BPF_TOKEN_CREATE bpf syscall command.
    * Updated decoding of io_uring_register and pidfd_send_signal syscalls.
    * Updated lists of BPF_*, CAN_*, IORING_*, KEY_*, LSM_*, MPOL_*, NT_*, RWF_*,
    PIDFD_*, PTP_*, TCP_*, and *_MAGIC constants.
    * Updated lists of ioctl commands from Linux 6.9.

++++ ucode-intel:

  - Intel CPU Microcode was updated to the 20240514 release (bsc#1224277)
  - CVE-2023-45733: Security updates for  INTEL-SA-01051 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01051.html
  - CVE-2023-46103: Security updates for  INTEL-SA-01052 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01052.html
  - CVE-2023-45745,CVE-2023-47855: Security updates for INTEL-SA-01036 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html
  - Update for functional issues. Refer to 5th Gen Intel Xeon Processor Scalable Family https://cdrdv2.intel.com/v1/dl/getContent/793902 for details.
  - Update for functional issues. Refer to 4th Gen Intel Xeon Scalable Processors Specification Update https://cdrdv2.intel.com/v1/dl/getContent/772415 for details.
  - Update for functional issues. Refer to 14th & 13th Generation Intel Core Processor Specification Update https://cdrdv2.intel.com/v1/dl/getContent/740518 for details.
  - Update for functional issues. Refer to 12th Generation Intel Cor™ Processor Family https://cdrdv2.intel.com/v1/dl/getContent/682436 for details.
  - Update for functional issues. Refer to Intel Processors and Intel Core i3 N-Series https://cdrdv2.intel.com/v1/dl/getContent/764616 for details.
  - Updated Platforms:
    | Processor      | Stepping | F-M-S/PI    | Old Ver  | New Ver  | Products
    |:---------------|:---------|:------------|:---------|:---------|:---------
    | ADL            | C0       | 06-97-02/07 | 00000034 | 00000035 | Core Gen12
    | ADL            | H0       | 06-97-05/07 | 00000034 | 00000035 | Core Gen12
    | ADL            | L0       | 06-9a-03/80 | 00000432 | 00000433 | Core Gen12
    | ADL            | R0       | 06-9a-04/80 | 00000432 | 00000433 | Core Gen12
    | ADL-N          | N0       | 06-be-00/11 | 00000015 | 00000017 | Core i3-N305/N300, N50/N97/N100/N200, Atom x7211E/x7213E/x7425E
    | AZB            | A0       | 06-9a-04/40 | 00000005 | 00000007 | Intel(R) Atom(R) C1100
    | AZB            | R0       | 06-9a-04/40 | 00000005 | 00000007 | Intel(R) Atom(R) C1100
    | EMR-SP         | A0      | 06-cf-01/87 | 21000200 | 21000230 | Xeon Scalable Gen5
    | EMR-SP         | A1      | 06-cf-02/87 | 21000200 | 21000230 | Xeon Scalable Gen5
    | RPL-E/HX/S     | B0       | 06-b7-01/32 | 00000122 | 00000123 | Core Gen13/Gen14
    | RPL-HX/S       | C0       | 06-bf-02/07 | 00000034 | 00000035 | Core Gen13/Gen14
    | RPL-S          | H0       | 06-bf-05/07 | 00000034 | 00000035 | Core Gen13/Gen14
    | SPR-HBM        | Bx       | 06-8f-08/10 | 2c000290 | 2c000390 | Xeon Max
    | SPR-SP         | E2       | 06-8f-05/87 | 2b000590 | 2b0005c0 | Xeon Scalable Gen4
    | SPR-SP         | E3       | 06-8f-06/87 | 2b000590 | 2b0005c0 | Xeon Scalable Gen4
    | SPR-SP         | E4/S2    | 06-8f-07/87 | 2b000590 | 2b0005c0 | Xeon Scalable Gen4
    | SPR-SP         | E5/S3    | 06-8f-08/87 | 2b000590 | 2b0005c0 | Xeon Scalable Gen4

------------------------------------------------------------------
------------------  2024-5-14  -  May 14 2024  -------------------
------------------------------------------------------------------

++++ Mesa:

  - Enable libvulkan_intel on arm

++++ Mesa-drivers:

  - Enable libvulkan_intel on arm

++++ containerized-data-importer:

  - Bump github.com/containers/image/v5 (bsc#1224119, CVE-2024-3727)
    0001-Bump-github.com-containers-image-v5-to-v5.30.1.patch

++++ gettext-runtime:

  - Split out envsubst into a separate package
    This allows us to pull in envsubst into containers without enlarging them
    substantially. Additionally, this binary is standalone and useful outside of
    the context of gettext.

++++ git:

  - update to 2.45.1:
    * CVE-2024-32002: recursive clones on case-insensitive
    filesystems that support symbolic links are susceptible to case
    confusion (boo#1224168)
    * CVE-2024-32004: arbitrary code execution during local clones
    (boo#1224170)
    * CVE-2024-32020: file overwriting vulnerability during local
    clones (boo#1224171)
    * CVE-2024-32021: git may create hardlinks to arbitrary user-
    readable files (boo#1224172)
    * CVE-2024-32465: arbitrary code execution during clone operations
    (boo#1224173)

++++ kernel-default:

  - block: Fix iterating over an empty bio with
    bio_for_each_folio_all (bsc#1221635 CVE-2024-26632).
  - commit a419383
  - iomap: clear the per-folio dirty bits on all writeback failures (git-fixes)
  - commit cfedccd
  - x86/retpoline: Add NOENDBR annotation to the SRSO dummy return thunk (git-fixes).
  - commit 431e388
  - kabi/severities: Remove mitigation-related symbols
    Those are used by the core kernel to implement CPU vulnerabilities
    mitigation and are not expected to be consumed by 3rd party users.
  - commit 8d79889
  - Update
    patches.suse/Bluetooth-hci_sync-Don-t-double-print-name-in-add-re.patch
    (bsc#1216358).
    Added bugzilla reference
  - commit 3985fb5
  - Update patches.suse/usb-ulpi-Fix-debugfs-directory-leak.patch
    (bsc#1223847 CVE-2024-26919).
    Added bugzilla ID and CVE
  - commit 44b677b
  - xfs: fix perag leak when growfs fails (git-fixes).
  - commit 111377b
  - xfs: add lock protection when remove perag from radix tree
    (git-fixes).
  - commit fdadeb0
  - xfs: force all buffers to be written during btree bulk load
    (git-fixes).
  - commit bcc67e9
  - xfs: recompute growfsrtfree transaction reservation while
    growing rt volume (git-fixes).
  - commit 0ef8d73
  - xfs: make xchk_iget safer in the presence of corrupt inode
    btrees (git-fixes).
  - commit 3312038
  - xfs: transfer recovered intent item ownership in ->iop_recover
    (git-fixes).
  - commit 9cdf2ef
  - xfs: pass the xfs_defer_pending object to iop_recover
    (git-fixes).
  - commit c4d4eda
  - xfs: use xfs_defer_pending objects to recover intent items
    (git-fixes).
  - commit 4e8f44d
  - jffs2: prevent xattr node from overflowing the eraseblock
    (git-fixes).
  - commit bb15e9c
  - x86/cpu: Add model number for Intel Arrow Lake mobile processor (git-fixes).
  - commit 7c55ce6
  - x86/bugs: Fix the SRSO mitigation on Zen3/4 (git-fixes).
  - commit b73f38c
  - x86/calldepth: Rename __x86_return_skl() to call_depth_return_thunk() (git-fixes).
  - commit 5ad2192
  - x86/nospec: Refactor UNTRAIN_RET[_*] (git-fixes).
  - commit 653bafb
  - x86/rethunk: Use SYM_CODE_START[_LOCAL]_NOALIGN macros (git-fixes).
  - commit 3e5de92
  - x86/srso: Disentangle rethunk-dependent options (git-fixes).
  - Refresh
    patches.suse/x86-bugs-Cache-the-value-of-MSR_IA32_ARCH_CAPABILITIES.patch.
  - commit 4761d61
  - x86/bugs: Remove default case for fully switched enums (git-fixes).
  - commit caa1a64
  - x86/srso: Remove 'pred_cmd' label (git-fixes).
  - commit d2d0e6a
  - x86/srso: Unexport untraining functions (git-fixes).
  - commit f855258
  - x86/srso: Improve i-cache locality for alias mitigation (git-fixes).
  - commit 8ffea3d
  - x86/srso: Fix unret validation dependencies (git-fixes).
  - commit 95452af
  - x86/srso: Print actual mitigation if requested mitigation isn't  possible (git-fixes).
  - Refresh
    patches.suse/x86-srso-fix-vulnerability-reporting-for-missing-microcode.patch.
  - commit 3afb908
  - x86/coco: Require seeding RNG with RDRAND on CoCo systems (git-fixes).
  - commit 9588be6
  - x86/nmi: Fix the inverse "in NMI handler" check (git-fixes).
  - commit 3b9c9ee
  - x86/purgatory: Switch to the position-independent small code model (git-fixes).
  - commit 57ab7d5
  - x86/CPU/AMD: Add models 0x10-0x1f to the Zen5 range (git-fixes).
  - commit f043bca
  - Move upstreamed patches into sorted section
  - commit 96e6c4c
  - soc: qcom: pmic_glink: Make client-lock non-sleeping
    (git-fixes).
  - commit 410217d
  - soc: qcom: rpmh-rsc: Enhance check for VRM in-flight request
    (git-fixes).
  - commit 2c41b82
  - crypto: qat - specify firmware files for 402xx (git-fixes).
  - crypto: qat - improve error logging to be consistent across
    features (git-fixes).
  - crypto: x86/sha512-avx2 - add missing vzeroupper (git-fixes).
  - crypto: x86/sha256-avx2 - add missing vzeroupper (git-fixes).
  - crypto: x86/nh-avx2 - add missing vzeroupper (git-fixes).
  - crypto: ccp - drop platform ifdef checks (git-fixes).
  - crypto: bcm - Fix pointer arithmetic (git-fixes).
  - crypto: ecdsa - Fix module auto-load on add-key (git-fixes).
  - kunit/fortify: Fix mismatched kvalloc()/vfree() usage
    (git-fixes).
  - nilfs2: fix out-of-range warning (git-fixes).
  - admin-guide/hw-vuln/core-scheduling: fix return type of
    PR_SCHED_CORE_GET (git-fixes).
  - soc: mediatek: cmdq: Fix typo of CMDQ_JUMP_RELATIVE (git-fixes).
  - soc: qcom: pmic_glink: notify clients about the current state
    (git-fixes).
  - soc: qcom: pmic_glink: don't traverse clients list without a
    lock (git-fixes).
  - commit 7da1cbc

++++ kernel-rt:

  - block: Fix iterating over an empty bio with
    bio_for_each_folio_all (bsc#1221635 CVE-2024-26632).
  - commit a419383
  - iomap: clear the per-folio dirty bits on all writeback failures (git-fixes)
  - commit cfedccd
  - x86/retpoline: Add NOENDBR annotation to the SRSO dummy return thunk (git-fixes).
  - commit 431e388
  - kabi/severities: Remove mitigation-related symbols
    Those are used by the core kernel to implement CPU vulnerabilities
    mitigation and are not expected to be consumed by 3rd party users.
  - commit 8d79889
  - Update
    patches.suse/Bluetooth-hci_sync-Don-t-double-print-name-in-add-re.patch
    (bsc#1216358).
    Added bugzilla reference
  - commit 3985fb5
  - Update patches.suse/usb-ulpi-Fix-debugfs-directory-leak.patch
    (bsc#1223847 CVE-2024-26919).
    Added bugzilla ID and CVE
  - commit 44b677b
  - xfs: fix perag leak when growfs fails (git-fixes).
  - commit 111377b
  - xfs: add lock protection when remove perag from radix tree
    (git-fixes).
  - commit fdadeb0
  - xfs: force all buffers to be written during btree bulk load
    (git-fixes).
  - commit bcc67e9
  - xfs: recompute growfsrtfree transaction reservation while
    growing rt volume (git-fixes).
  - commit 0ef8d73
  - xfs: make xchk_iget safer in the presence of corrupt inode
    btrees (git-fixes).
  - commit 3312038
  - xfs: transfer recovered intent item ownership in ->iop_recover
    (git-fixes).
  - commit 9cdf2ef
  - xfs: pass the xfs_defer_pending object to iop_recover
    (git-fixes).
  - commit c4d4eda
  - xfs: use xfs_defer_pending objects to recover intent items
    (git-fixes).
  - commit 4e8f44d
  - jffs2: prevent xattr node from overflowing the eraseblock
    (git-fixes).
  - commit bb15e9c
  - x86/cpu: Add model number for Intel Arrow Lake mobile processor (git-fixes).
  - commit 7c55ce6
  - x86/bugs: Fix the SRSO mitigation on Zen3/4 (git-fixes).
  - commit b73f38c
  - x86/calldepth: Rename __x86_return_skl() to call_depth_return_thunk() (git-fixes).
  - commit 5ad2192
  - x86/nospec: Refactor UNTRAIN_RET[_*] (git-fixes).
  - commit 653bafb
  - x86/rethunk: Use SYM_CODE_START[_LOCAL]_NOALIGN macros (git-fixes).
  - commit 3e5de92
  - x86/srso: Disentangle rethunk-dependent options (git-fixes).
  - Refresh
    patches.suse/x86-bugs-Cache-the-value-of-MSR_IA32_ARCH_CAPABILITIES.patch.
  - commit 4761d61
  - x86/bugs: Remove default case for fully switched enums (git-fixes).
  - commit caa1a64
  - x86/srso: Remove 'pred_cmd' label (git-fixes).
  - commit d2d0e6a
  - x86/srso: Unexport untraining functions (git-fixes).
  - commit f855258
  - x86/srso: Improve i-cache locality for alias mitigation (git-fixes).
  - commit 8ffea3d
  - x86/srso: Fix unret validation dependencies (git-fixes).
  - commit 95452af
  - x86/srso: Print actual mitigation if requested mitigation isn't  possible (git-fixes).
  - Refresh
    patches.suse/x86-srso-fix-vulnerability-reporting-for-missing-microcode.patch.
  - commit 3afb908
  - x86/coco: Require seeding RNG with RDRAND on CoCo systems (git-fixes).
  - commit 9588be6
  - x86/nmi: Fix the inverse "in NMI handler" check (git-fixes).
  - commit 3b9c9ee
  - x86/purgatory: Switch to the position-independent small code model (git-fixes).
  - commit 57ab7d5
  - x86/CPU/AMD: Add models 0x10-0x1f to the Zen5 range (git-fixes).
  - commit f043bca
  - Move upstreamed patches into sorted section
  - commit 96e6c4c
  - soc: qcom: pmic_glink: Make client-lock non-sleeping
    (git-fixes).
  - commit 410217d
  - soc: qcom: rpmh-rsc: Enhance check for VRM in-flight request
    (git-fixes).
  - commit 2c41b82
  - crypto: qat - specify firmware files for 402xx (git-fixes).
  - crypto: qat - improve error logging to be consistent across
    features (git-fixes).
  - crypto: x86/sha512-avx2 - add missing vzeroupper (git-fixes).
  - crypto: x86/sha256-avx2 - add missing vzeroupper (git-fixes).
  - crypto: x86/nh-avx2 - add missing vzeroupper (git-fixes).
  - crypto: ccp - drop platform ifdef checks (git-fixes).
  - crypto: bcm - Fix pointer arithmetic (git-fixes).
  - crypto: ecdsa - Fix module auto-load on add-key (git-fixes).
  - kunit/fortify: Fix mismatched kvalloc()/vfree() usage
    (git-fixes).
  - nilfs2: fix out-of-range warning (git-fixes).
  - admin-guide/hw-vuln/core-scheduling: fix return type of
    PR_SCHED_CORE_GET (git-fixes).
  - soc: mediatek: cmdq: Fix typo of CMDQ_JUMP_RELATIVE (git-fixes).
  - soc: qcom: pmic_glink: notify clients about the current state
    (git-fixes).
  - soc: qcom: pmic_glink: don't traverse clients list without a
    lock (git-fixes).
  - commit 7da1cbc

++++ ledmon:

  - Enable building libled.

++++ ncurses:

  - Add ncurses patch 20240511
    + improve formatting/style of manpages (patches by Branden Robinson).
    + limit value from ESCDELAY environment variable to 30 seconds, like
    other delay limits.
    + limit values from LINES and COLUMNS environment variables to 512
    (report by Miroslav Lichvar).
  - Port patch ncurses-6.4.dif

++++ systemd:

  - systemd.spec: some of the meson options have been converted to meson features.

++++ tcpd:

  - build with gcc14
  - added patches
    + tcp_wrappers_7.6-gcc14.patch

++++ libxml2:

  - Update to version 2.12.7:
    + Fix buffer overread with `xmllint --htmlout` (CVE-2024-34459, bsc#1224282).
    + xmllint: Fix --pedantic option.
    + save: Handle invalid parent pointers in xhtmlNodeDumpOutput.

++++ libzypp:

  - don't require libproxy1 on tumbleweed, it is optional now
  - version 17.34.0 (34)
  - Fix versioning scheme

++++ makedumpfile:

  - Update to 1.7.5:
    * Support for kernels up to v6.8 (x86_64)
    * Support for printk caller_id by --dump-dmesg option
    * [PATCH] ppc64: get vmalloc start address from vmcoreinfo
    * [PATCH] ppc64: read cur_mmu_type from vmcoreinfo
    * [PATCH] add PRINTK_CALLER id support to --dump-dmesg option
    * [PATCH v2 2/2] s390x: uncouple virtual and physical address spaces
    * [PATCH 1/2] s390x: fix virtual vs physical address confusion
    Regenerated the content of the makedumpfile-ppc64-VA-range-SUSE.patch
    file based on version 1.7.5 of the code

++++ openssh:

  - Add a warning in %post of openssh-clients, openssh-server and
    openssh-server-config-disallow-rootlogin to warn the user if
    the /etc/ssh/(ssh_config.d|sshd_config.d) directories are not
    being used (bsc#1223486).

++++ libxml2-python:

  - Update to version 2.12.7:
    + Fix buffer overread with `xmllint --htmlout` (CVE-2024-34459, bsc#1224282).
    + xmllint: Fix --pedantic option.
    + save: Handle invalid parent pointers in xhtmlNodeDumpOutput.

------------------------------------------------------------------
------------------  2024-5-13  -  May 13 2024  -------------------
------------------------------------------------------------------

++++ glib2:

  - Update to version 2.80.2:
    + Fix a regression with IBus caused by the fix for
    CVE-2024-34397.
    + Fix installation directory of the GVariant specification.
    + Bugs fixed:
  - GVariant specification installed in wrong directory.
  - Backport "gdbusconnection: Fix test signal subscription
    ordering" to glib-2-80.
  - Backport “Correct installation directory of GVariant
    specification” to glib-2-80.
  - Backport “gdbusconnection: Allow name owners to have the
    syntax of a well-known name” to glib-2-80.
  - Changes from version 2.80.1
    + Fix CVE-2024-34397: GDBus signal subscriptions for well-known
    names are vulnerable to unicast spoofing (boo#1224044).
    + Updated translations.

++++ glibc:

  - glibc-CVE-2024-33599-nscd-Stack-based-buffer-overflow-in-n.patch:
    nscd: Stack-based buffer overflow in netgroup cache
    (CVE-2024-33599, bsc#1223423, BZ #31677)
  - glibc-CVE-2024-33600-nscd-Avoid-null-pointer-crashes-after.patch:
    nscd: Avoid null pointer crashes after notfound response
    (CVE-2024-33600, bsc#1223424, BZ #31678)
  - glibc-CVE-2024-33600-nscd-Do-not-send-missing-not-found-re.patch:
    nscd: Do not send missing not-found response in addgetnetgrentX
    (CVE-2024-33600, bsc#1223424, BZ #31678)
  - glibc-CVE-2024-33601-CVE-2024-33602-nscd-netgroup-Use-two.patch:
    netgroup: Use two buffers in addgetnetgrentX (CVE-2024-33601,
    CVE-2024-33602, bsc#1223425, BZ #31680)
  - nscd-netgroup-cache-timeout.patch: Use time_t for return type of
    addgetnetgrentX (CVE-2024-33602, bsc#1223425)
  - glibc-fix-cve-2024-33599.patch: renamed

++++ kernel-default:

  - btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks() (git-fixes)
  - commit 8bc326a
  - btrfs: fix wrong block_start calculation for btrfs_drop_extent_map_range() (git-fixes)
    Dropped hunk in selftests (test_case_7), 92e1229b204d6.
  - commit 8dcf7c1
  - btrfs: fix information leak in btrfs_ioctl_logical_to_ino() (git-fixes)
  - commit 622d549
  - btrfs: handle chunk tree lookup error in btrfs_relocate_sys_chunks() (git-fixes)
  - commit 84f4309
  - btrfs: reject encoded write if inode has nodatasum flag set (git-fixes)
  - commit bbc649d
  - btrfs: send: return EOPNOTSUPP on unknown flags (git-fixes)
  - commit 8ef1c53
  - btrfs: fix lockdep splat and potential deadlock after failure running delayed items (git-fixes)
  - commit a6f28a6
  - btrfs: release path before inode lookup during the ino lookup ioctl (git-fixes)
  - commit 4b7ba54
  - firewire: nosy: ensure user_length is taken into account when
    fetching packet contents (CVE-2024-27401 bsc#1224181).
  - commit 5441039
  - Update
    patches.suse/usb-aqc111-check-packet-for-fixup-for-true-limit.patch
    (bsc#1217169 CVE-2023-52655).
    Added bugzilla and CVE
  - commit 20db8f9
  - btrfs: fix off-by-one chunk length calculation at contains_pending_extent() (git-fixes)
  - commit 9ec1333
  - crypto: rsa - add a check for allocation failure (bsc#1222775).
  - commit 8c6c396
  - kABI workaround for of driver changes (git-fixes).
  - commit ef08885
  - aoe: avoid potential deadlock at set_capacity (CVE-2024-26775,
    bsc#1222627).
  - commit fd6e05d
  - crypto: testmgr - remove unused xts4096 and xts512 algorithms
    from testmgr.c (bsc#1222769).
  - commit 0de6756
  - crypto: rsa - allow only odd e and restrict value in FIPS mode
    (bsc#1222775).
  - commit c5ca0e4
  - of: module: prevent NULL pointer dereference in vsnprintf()
    (stable-fixes).
  - of: dynamic: Synchronize of_changeset_destroy() with the
    devlink removals (git-fixes).
  - of: property: fw_devlink: Fix stupid bug in remote-endpoint
    parsing (git-fixes).
  - of: property: Add in-ports/out-ports support to
    of_graph_get_port_parent() (stable-fixes).
  - of: property: Improve finding the supplier of a remote-endpoint
    property (git-fixes).
  - of: property: Improve finding the consumer of a remote-endpoint
    property (git-fixes).
  - of: unittest: Fix compile in the non-dynamic case (git-fixes).
  - of: property: fix typo in io-channels (git-fixes).
  - commit 7743bc7
  - crypto: ecc - update ecc_gen_privkey for FIPS 186-5
    (bsc#1222782).
  - commit bcc0381
  - selftests/pidfd: Fix config for pidfd_setns_test (git-fixes).
  - EDAC/synopsys: Fix ECC status and IRQ control race condition
    (git-fixes).
  - commit 85ce9d3
  - nfs: fix UAF in direct writes (bsc#1223653 CVE-2024-26958).
  - commit 9b53f23

++++ kernel-firmware-all:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-amdgpu:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-ath10k:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-ath11k:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-ath12k:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-atheros:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-bluetooth:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-bnx2:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-brcm:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-chelsio:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-dpaa2:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-i915:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-intel:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-iwlwifi:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-liquidio:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-marvell:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-media:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-mediatek:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-mellanox:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-mwifiex:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-network:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-nfp:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-nvidia:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-platform:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-prestera:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-qcom:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-qlogic:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-radeon:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-realtek:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-serial:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-sound:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-ti:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-ueagle:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-firmware-usb-network:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

++++ kernel-rt:

  - btrfs: add missing mutex_unlock in btrfs_relocate_sys_chunks() (git-fixes)
  - commit 8bc326a
  - btrfs: fix wrong block_start calculation for btrfs_drop_extent_map_range() (git-fixes)
    Dropped hunk in selftests (test_case_7), 92e1229b204d6.
  - commit 8dcf7c1
  - btrfs: fix information leak in btrfs_ioctl_logical_to_ino() (git-fixes)
  - commit 622d549
  - btrfs: handle chunk tree lookup error in btrfs_relocate_sys_chunks() (git-fixes)
  - commit 84f4309
  - btrfs: reject encoded write if inode has nodatasum flag set (git-fixes)
  - commit bbc649d
  - btrfs: send: return EOPNOTSUPP on unknown flags (git-fixes)
  - commit 8ef1c53
  - btrfs: fix lockdep splat and potential deadlock after failure running delayed items (git-fixes)
  - commit a6f28a6
  - btrfs: release path before inode lookup during the ino lookup ioctl (git-fixes)
  - commit 4b7ba54
  - firewire: nosy: ensure user_length is taken into account when
    fetching packet contents (CVE-2024-27401 bsc#1224181).
  - commit 5441039
  - Update
    patches.suse/usb-aqc111-check-packet-for-fixup-for-true-limit.patch
    (bsc#1217169 CVE-2023-52655).
    Added bugzilla and CVE
  - commit 20db8f9
  - btrfs: fix off-by-one chunk length calculation at contains_pending_extent() (git-fixes)
  - commit 9ec1333
  - crypto: rsa - add a check for allocation failure (bsc#1222775).
  - commit 8c6c396
  - kABI workaround for of driver changes (git-fixes).
  - commit ef08885
  - aoe: avoid potential deadlock at set_capacity (CVE-2024-26775,
    bsc#1222627).
  - commit fd6e05d
  - crypto: testmgr - remove unused xts4096 and xts512 algorithms
    from testmgr.c (bsc#1222769).
  - commit 0de6756
  - crypto: rsa - allow only odd e and restrict value in FIPS mode
    (bsc#1222775).
  - commit c5ca0e4
  - of: module: prevent NULL pointer dereference in vsnprintf()
    (stable-fixes).
  - of: dynamic: Synchronize of_changeset_destroy() with the
    devlink removals (git-fixes).
  - of: property: fw_devlink: Fix stupid bug in remote-endpoint
    parsing (git-fixes).
  - of: property: Add in-ports/out-ports support to
    of_graph_get_port_parent() (stable-fixes).
  - of: property: Improve finding the supplier of a remote-endpoint
    property (git-fixes).
  - of: property: Improve finding the consumer of a remote-endpoint
    property (git-fixes).
  - of: unittest: Fix compile in the non-dynamic case (git-fixes).
  - of: property: fix typo in io-channels (git-fixes).
  - commit 7743bc7
  - crypto: ecc - update ecc_gen_privkey for FIPS 186-5
    (bsc#1222782).
  - commit bcc0381
  - selftests/pidfd: Fix config for pidfd_setns_test (git-fixes).
  - EDAC/synopsys: Fix ECC status and IRQ control race condition
    (git-fixes).
  - commit 85ce9d3
  - nfs: fix UAF in direct writes (bsc#1223653 CVE-2024-26958).
  - commit 9b53f23

++++ krb5:

  - Enable the LMDB backend for KDB

++++ libftdi1:

  - Update to version 1.5.42+git.de9f01e:
    * CMake: bump the minimal required version to 3.5
    * python: move from distutils to sysconfig
    * CMake: use ${PC_LIBUSB_LIBRARIES} instead of a library name
    * CMake: fix multiarch support
    * CMake: make the project compatible with building as a subproject
    * ftdipp/CMakeLists.txt: remove VIM modline settings
    * CMake: rework subdirectory handling
    * CMake: rework findlibusb module
    * CMake: report CMake version
    * CMake: use dedicated recipe for documentation generation
    D 0001-Fix-race-during-build-of-python-bindings.patch
    Patch got integrated mainline

++++ numactl:

  - Update to version 2.0.18.5.g4bfdcc6:
    * numactl: Add documentation for weighted interleave
    * numactl: Fix RESOURCE_LEAK in show()
    * numademo: Fix the using of the uninitialized value
    * Add `-w` and `--weighted-interleave` for weighted interleave mode
    * Fix fallback for set_mempolicy_home_node syscall

++++ systemd:

  - Import commit a3dccacb97e94ed91f1c41ce82ef13bfe8fa1a79 (merge of v255.6)
    For a complete list of changes, visit:
    https://github.com/openSUSE/systemd/compare/49fb09fa18a7b81f6b3c3c15aca47fd00940430e...a3dccacb97e94ed91f1c41ce82ef13bfe8fa1a79

++++ libzypp:

  - version 17.33.4 (35)

++++ mcelog:

  - Update to version 198:
    * Remove obsolete on disk dimm database code
    * page.c: Disable gcc warnings
    * page.c: Remove obsolete comment
    * mcelog: Fix clang warnings
    * mcelog: mempage_replace missing initialization of mempage fields
    * mcelog: Add third model number for Arrowlake
  - Refresh patches according to mainline:
    M    add-f10h-support.patch
    M    email.patch
    M    fix_setgroups_missing_call.patch
    M    mcelog_invert_prefill_db_warning.patch
  - jsc#PED-10212

++++ openssh:

  - Only for SLE15, restore the patch file removed in
    Thu Feb 18 13:54:44 UTC 2021 to restore the previous behaviour
    from SP5 of having root password login allowed by default
    (fixes bsc#1223486, related to bsc#1173067):
    * openssh-7.7p1-allow_root_password_login.patch
  - Since the default value for this config option is now set to
    permit root to use password logins in SLE15, the
    openssh-server-config-rootlogin subpackage isn't useful there so
    we now create an openssh-server-config-disallow-rootlogin
    subpackage that sets the configuration the other way around
    than openssh-server-config-rootlogin.

++++ passt:

  - Update to version 20240510.7288448:
    * apparmor: allow read access on /tmp for pasta
    * tcp_splice: Set OUT_WAIT_ flag whenever pipe isn't emptied
    * udp: Single buffer for IPv4, IPv6 headers and metadata
    * udp: Use the same buffer for the L2 header for all frames
    * udp: Share payload buffers between IPv4 and IPv6
    * udp: Explicitly set checksum in guest-bound UDP headers
    * udp: Combine initialisation of IPv4 and IPv6 iovs
    * udp: Split tap-bound UDP packets into multiple buffers using io vector
    * test: Allow sftp via vsock-ssh in tests
    * tcp: Update tap specific header too in tcp_fill_headers[46]()
    * iov: Helper macro to construct iovs covering existing variables or fields
    * tap, tcp: (Re-)abstract TAP specific header handling
    * tcp: Simplify packet length calculation when preparing headers
    * treewide: Standardise variable names for various packet lengths
    * checksum: Make csum_ip4_header() take a host endian length
    * treewide: Remove misleading and redundant endianness notes
    * tap: Remove unused structs tap_msg, tap_l4_msg
    * tap: Split tap specific and L2 (ethernet) headers
    * checksum: Use proto_ipv6_header_psum() for ICMPv6 as well
    * netlink: Fix iterations over nexthop objects

++++ permissions:

  - rename chkstat package to permctl to match the new binary names. Establish
    Provides/Obsoletes to keep dependencies and old package cleanup in working
    order, see:
    https://en.opensuse.org/openSUSE:Package_dependencies#Renaming_a_package
  - add BuildRequires for acl programs for tests to succeed. Still keep %check
    disabled, because the new ACL test fails without /etc/subuid, /etc/subgid
    setup.
  - Update to version 1699_20240513:
    * chkstat: has been renamed to permctl to better reflect its purpose. A
    symlink for backward compatibility will remain in place.
    * documentation: updated man pages
    * ACL support: permctl (formerly chkstat) now supports an additional `+acl`
    syntax to support assigning ACLs to files similar to the already existing
    support for file based capabilities.

++++ ucode-amd:

  - Update to version 20240510 (git commit 7c2303328d8e):
    * linux-firmware: Amphion: Update vpu firmware
    * linux-firmware: Update firmware file for Intel BlazarU core
    * linux-firmware: Update firmware file for Intel Bluetooth Magnetor core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * linux-firmware: Update firmware file for Intel Bluetooth Solar core
    * i915: Add BMG DMC v2.06
    * linux-firmware: Add CS35L41 HDA Firmware for Asus HN7306
    * linux-firmware: Update firmware tuning for HP Consumer Laptop
    * amdgpu: DMCUB updates for various AMDGPU ASICs
    * rtl_bt: Update RTL8822C BT UART firmware to 0x0FD6_407B
    * rtl_bt: Update RTL8822C BT USB firmware to 0x0ED6_407B
    * cirrus: cs35l56: Add firmware for Cirrus CS35L56 for various ASUS laptops
    * linux-firmware: Add firmware and tuning for Lenovo Y770S

------------------------------------------------------------------
------------------  2024-5-12  -  May 12 2024  -------------------
------------------------------------------------------------------

++++ python-kiwi:

  - Fix sdist upstream tarball contents
    The .virtualenv.dev-requirements.txt file is referenced by tox.ini
    but not put into the sdist tarball and therefore missing in the
    pypi upstream data.

